Struct ocb::Context [-] [+] [src]

pub struct Context {
    // some fields omitted
}

An OCB encryption/decryption context.

Methods

impl Context

fn new(key: Key) -> Result<Context>

Initialize an OCB context with the given key.

fn encrypt<N>(&mut self, nonce_stream: &mut N, plaintext: &[u8], assoc_data: &[u8]) -> Result<(Nonce, Vec<u8>)> where N: Iterator<Item=Nonce>

Encrypt and authenticate a message.

The nonce_stream iterator is used to obtain a nonce, a "number used once", just for this encryption. You must not encrypt two messages using the same key and nonce. This will fatally compromise security. Take extra care when using the same key in multiple processes or on multiple machines. It's often better for each direction of communication to have its own key.

The nonce is not secret. It's usually transmitted along with the message, and it's needed at the receiving end. The nonce is allowed to be predictable, as well. A simple counter is a good source of unique nonces, so long as it's reset only when the key changes. The type Counter implements such a nonce source, but you can use any Iterator<Item=Nonce>, so long as it never produces the same value twice (for the same key).

The "associated data" is authenticated as well, but it is not encrypted or copied into the output. In other words, decryption will succeed if and only if the receiver supplies the same associated data. For example, it could be transmitted in the clear alongside the encrypted message.

Many applications don't need associated data and can pass an empty slice.

fn decrypt(&mut self, nonce: Nonce, ciphertext: &[u8], assoc_data: &[u8]) -> Result<Vec<u8>>

Decrypt and verify a message.

If the ciphertext was generated correctly, using the specified nonce and associated data, with the key stored in this context, then decrypt will return the original plaintext. Otherwise, you get an error saying what went wrong.

Trait Implementations

impl Drop for Context

fn drop(&mut self)