Skip to main content

Module crypto_xof

Module crypto_xof 

Source
Expand description

§Extendable-output functions

Implements libsodium’s crypto_xof_shake128_*, crypto_xof_shake256_*, crypto_xof_turboshake128_* and crypto_xof_turboshake256_* functions.

An extendable-output function (XOF) hashes input of any length into output of any length. SHAKE is specified in FIPS 202; TurboSHAKE (RFC 9861) uses 12 Keccak rounds instead of 24 and is about twice as fast.

Absorb input with update, then call squeeze as many times as needed: the calls continue one output stream. Once squeezing has started, update returns an error and leaves the state unchanged. init_with_domain selects a custom domain byte in 0x01..=0x7f.

libsodium documents the same rules but does not enforce them: it accepts any domain byte, and an update after squeezing returns -1 after resetting the state and absorbing the input anyway. dryoc returns an error in both cases instead.

use dryoc::classic::crypto_xof::*;

let mut digest = [0u8; 32];
crypto_xof_turboshake128(&mut digest, b"Arbitrary data to hash");

let mut state = crypto_xof_shake256_init();
crypto_xof_shake256_update(&mut state, b"Arbitrary data to hash").expect("update failed");
let (mut key1, mut key2) = ([0u8; 32], [0u8; 32]);
crypto_xof_shake256_squeeze(&mut state, &mut key1);
crypto_xof_shake256_squeeze(&mut state, &mut key2);
assert_ne!(key1, key2);

Structs§

Shake128State
Incremental SHAKE128 state.
Shake256State
Incremental SHAKE256 state.
TurboShake128State
Incremental TurboSHAKE128 state.
TurboShake256State
Incremental TurboSHAKE256 state.

Functions§

crypto_xof_shake128
Computes SHAKE128 of input, filling output.
crypto_xof_shake256
Computes SHAKE256 of input, filling output.
crypto_xof_shake128_init
Initializes SHAKE128 with the standard domain.
crypto_xof_shake128_init_with_domain
Initializes SHAKE128 with a custom domain byte.
crypto_xof_shake128_squeeze
Fills output with the next bytes of the SHAKE128 output stream, finishing absorption on the first call.
crypto_xof_shake128_update
Absorbs input into the SHAKE128 state.
crypto_xof_shake256_init
Initializes SHAKE256 with the standard domain.
crypto_xof_shake256_init_with_domain
Initializes SHAKE256 with a custom domain byte.
crypto_xof_shake256_squeeze
Fills output with the next bytes of the SHAKE256 output stream, finishing absorption on the first call.
crypto_xof_shake256_update
Absorbs input into the SHAKE256 state.
crypto_xof_turboshake128
Computes TurboSHAKE128 of input, filling output.
crypto_xof_turboshake256
Computes TurboSHAKE256 of input, filling output.
crypto_xof_turboshake128_init
Initializes TurboSHAKE128 with the standard domain.
crypto_xof_turboshake128_init_with_domain
Initializes TurboSHAKE128 with a custom domain byte.
crypto_xof_turboshake128_squeeze
Fills output with the next bytes of the TurboSHAKE128 output stream, finishing absorption on the first call.
crypto_xof_turboshake128_update
Absorbs input into the TurboSHAKE128 state.
crypto_xof_turboshake256_init
Initializes TurboSHAKE256 with the standard domain.
crypto_xof_turboshake256_init_with_domain
Initializes TurboSHAKE256 with a custom domain byte.
crypto_xof_turboshake256_squeeze
Fills output with the next bytes of the TurboSHAKE256 output stream, finishing absorption on the first call.
crypto_xof_turboshake256_update
Absorbs input into the TurboSHAKE256 state.