pub struct DryocStream<M> { /* private fields */ }Expand description
Secret-key authenticated encrypted streams
Implementations§
Source§impl<M> DryocStream<M>
impl<M> DryocStream<M>
Sourcepub fn rekey(&mut self)
pub fn rekey(&mut self)
Rekeys the stream immediately. The sender and receiver must rekey at the same position.
Manual rekeying is unnecessary when the sender uses Tag::Rekey or
Tag::Final, because those tags rekey after the message. The stream
also rekeys if its internal counter wraps. See the
libsodium documentation
for details.
Source§impl DryocStream<Push>
impl DryocStream<Push>
Sourcepub fn init_push<Header: NewByteArray<CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES>, Key: ByteArray<CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_KEYBYTES>>(
key: &Key,
) -> (Self, Header)
pub fn init_push<Header: NewByteArray<CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES>, Key: ByteArray<CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_KEYBYTES>>( key: &Key, ) -> (Self, Header)
Returns a new push stream, initialized from key.
Sourcepub fn push<Output: NewBytes + ResizableBytes, Input: Bytes + ?Sized>(
&mut self,
message: &Input,
associated_data: Option<&[u8]>,
tag: Tag,
) -> Result<Output, Error>
pub fn push<Output: NewBytes + ResizableBytes, Input: Bytes + ?Sized>( &mut self, message: &Input, associated_data: Option<&[u8]>, tag: Tag, ) -> Result<Output, Error>
Encrypts message for this stream with associated_data and tag,
returning the ciphertext.
§Errors
Returns an error if the message exceeds the stream’s maximum message length, or the output storage does not resize to exactly the required ciphertext length.
Sourcepub fn push_to_vec<Input: Bytes + ?Sized>(
&mut self,
message: &Input,
associated_data: Option<&[u8]>,
tag: Tag,
) -> Result<Vec<u8>, Error>
Available on crate feature alloc only.
pub fn push_to_vec<Input: Bytes + ?Sized>( &mut self, message: &Input, associated_data: Option<&[u8]>, tag: Tag, ) -> Result<Vec<u8>, Error>
alloc only.Encrypts message for this stream with associated_data and tag,
returning the ciphertext.
§Errors
Returns an error if the message exceeds the stream’s maximum message length.
Source§impl DryocStream<Pull>
impl DryocStream<Pull>
Sourcepub fn init_pull<Key: ByteArray<CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_KEYBYTES>, Header: ByteArray<CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES>>(
key: &Key,
header: &Header,
) -> Self
pub fn init_pull<Key: ByteArray<CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_KEYBYTES>, Header: ByteArray<CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES>>( key: &Key, header: &Header, ) -> Self
Returns a new pull stream, initialized from key and header.
Sourcepub fn pull<Output: NewBytes + ResizableBytes, Input: Bytes + ?Sized>(
&mut self,
ciphertext: &Input,
associated_data: Option<&[u8]>,
) -> Result<(Output, Tag), Error>
pub fn pull<Output: NewBytes + ResizableBytes, Input: Bytes + ?Sized>( &mut self, ciphertext: &Input, associated_data: Option<&[u8]>, ) -> Result<(Output, Tag), Error>
Decrypts ciphertext for this stream with associated_data, returning
the decrypted message and tag.
§Errors
Returns an error if the ciphertext is too short or too long, the output
storage cannot hold the plaintext, or authentication fails.
Authentication fails for a wrong key or header, mismatched associated
data, modified ciphertext, or messages processed out of order.
An authenticated tag byte that is not one of the four Tag values is
also rejected without advancing the stream.
Sourcepub fn pull_to_vec<Input: Bytes + ?Sized>(
&mut self,
ciphertext: &Input,
associated_data: Option<&[u8]>,
) -> Result<(Vec<u8>, Tag), Error>
Available on crate feature alloc only.
pub fn pull_to_vec<Input: Bytes + ?Sized>( &mut self, ciphertext: &Input, associated_data: Option<&[u8]>, ) -> Result<(Vec<u8>, Tag), Error>
alloc only.Decrypts ciphertext for this stream with associated_data, returning
the decrypted message and tag into a Vec.
§Errors
Returns an error if the ciphertext is too short or too long, or
authentication fails because the key, header, associated data, stream
position, or ciphertext does not match. An authenticated tag byte that
is not one of the four Tag values is also rejected without
advancing the stream.