Skip to main content

Module kx

Module kx 

Source
Expand description

§Key exchange functions

Session implements libsodium’s client/server key-exchange construction. A client and server use their own secret key and the other party’s public key to derive two shared session keys: one for receiving and one for sending.

Use these session keys with a shared-key encryption API. The exchange does not encrypt messages by itself. Public keys must be authenticated through a trusted channel; otherwise an attacker can replace them and sit between the two parties.

§Rustaceous API example

use dryoc::kx::*;

// Generate random client/server keypairs
let client_keypair = StackKeyPair::generate();
let server_keypair = StackKeyPair::generate();

// Compute the client's receive and transmit keys.
let client_session_keys = StackSession::new_client(&client_keypair, &server_keypair.public_key)
    .expect("compute client failed");

// Compute the server's receive and transmit keys.
let server_session_keys = StackSession::new_server(&server_keypair, &client_keypair.public_key)
    .expect("compute server failed");

let (client_rx, client_tx) = client_session_keys.into_parts();
let (server_rx, server_tx) = server_session_keys.into_parts();

// Each transmit key matches the other party's receive key.
assert_eq!(client_rx, server_tx);
assert_eq!(client_tx, server_rx);

§Additional resources

Modules§

protectedprotected
Protected memory type aliases for Session

Structs§

Session
Key derivation implementation based on Curve25519, Diffie-Hellman, and Blake2b. Compatible with libsodium’s crypto_kx_* functions.

Type Aliases§

PublicKey
Stack-allocated public key type alias
SecretKey
Stack-allocated secret key type alias
SessionKey
Stack-allocated session key type alias
StackKeyPair
Stack-allocated keypair type alias
StackSession
Stack-allocated type alias for Session. Provided for convenience.