Struct ocb::Context
[-] [+]
[src]
pub struct Context {
// some fields omitted
}An OCB encryption/decryption context.
Methods
impl Context
fn new(key: Key) -> Result<Context>
Initialize an OCB context with the given key.
fn encrypt<N>(&mut self, nonce_stream: &mut N, plaintext: &[u8], assoc_data: &[u8]) -> Result<(Nonce, Vec<u8>)> where N: Iterator<Item=Nonce>
Encrypt and authenticate a message.
The nonce_stream iterator is used to obtain a nonce, a "number used
once", just for this encryption. You must not encrypt two messages
using the same key and nonce. This will fatally compromise security.
Take extra care when using the same key in multiple processes or on
multiple machines. It's often better for each direction of
communication to have its own key.
The nonce is not secret. It's usually transmitted along with the
message, and it's needed at the receiving end. The nonce is allowed to
be predictable, as well. A simple counter is a good source of unique
nonces, so long as it's reset only when the key changes. The type
Counter implements such a nonce source, but you can use any
Iterator<Item=Nonce>, so long as it never produces the same value
twice (for the same key).
The "associated data" is authenticated as well, but it is not encrypted or copied into the output. In other words, decryption will succeed if and only if the receiver supplies the same associated data. For example, it could be transmitted in the clear alongside the encrypted message.
Many applications don't need associated data and can pass an empty slice.
fn decrypt(&mut self, nonce: Nonce, ciphertext: &[u8], assoc_data: &[u8]) -> Result<Vec<u8>>
Decrypt and verify a message.
If the ciphertext was generated correctly, using the specified nonce and
associated data, with the key stored in this context, then decrypt will
return the original plaintext. Otherwise, you get an error saying what
went wrong.