package hpke

  1. Overview
  2. Docs
Idiomatic RFC 9180 Hybrid Public Key Encryption for OCaml

Install

dune-project
 Dependency

Authors

Maintainers

Sources

v0.4.0.tar.gz
md5=af35c94697402d005548f08f797328f2
sha512=5caedd58fcd45e81fc089a4970697af1b8e282ab2c01b5a2b28d567d034b266b47786203a319f2f0efb3f5a97f55e73de2c0ad880739a3d2d3fce1f6a6245ae7

doc/hpke.for_testing/Hpke_for_testing/index.html

Module Hpke_for_testingSource

Deterministic RFC 9180 entry points for known-answer testing only.

RFC 9180 requires the sender's ephemeral key to be fresh and secret for every context. The functions here let the caller choose it instead, so that published test vectors which fix skE can be reproduced byte for byte, including those of protocols layered on HPKE such as RFC 9458. Reusing or disclosing an ephemeral key breaks the confidentiality of every message sealed under it, so this library must not be used by production protocols. Use Hpke.Rfc9180 instead.

ML-KEM and the PQ/T hybrid KEMs encapsulate from randomness and have no ephemeral key of their own KEM, so with such a suite setup_base_sender and setup_psk_sender return Hpke.Error.t.Invalid_private_key. setup_auth_sender and setup_auth_psk_sender return Hpke.Error.t.Unsupported_mode there, as the ordinary Auth and AuthPSK setup functions do: those KEMs have neither mode. To reproduce a vector that fixes that randomness, pass a generator that returns it as ~rng to the ordinary Hpke.Rfc9180 setup function.

Sourceval setup_base_sender : 'capability Hpke.Suite.t -> ephemeral:Hpke.Private_key.t -> recipient:Hpke.Public_key.t -> info:string -> ('capability Hpke.Rfc9180.sender_setup, Hpke.Error.t) result

setup_base_sender suite ~ephemeral ~recipient ~info is Hpke.Rfc9180.setup_base_sender with ephemeral as skE in place of a freshly generated key. The encapsulated key is the public key of ephemeral. Returns Hpke.Error.t.Key_mismatch unless the suite, the ephemeral key, and the recipient key share one KEM.

Sourceval setup_psk_sender : 'capability Hpke.Suite.t -> ephemeral:Hpke.Private_key.t -> recipient:Hpke.Public_key.t -> psk:Hpke.Psk.t -> info:string -> ('capability Hpke.Rfc9180.sender_setup, Hpke.Error.t) result

The PSK-mode counterpart of setup_base_sender.

Sourceval setup_auth_sender : 'capability Hpke.Suite.t -> ephemeral:Hpke.Private_key.t -> recipient:Hpke.Public_key.t -> sender:Hpke.Private_key.t -> info:string -> ('capability Hpke.Rfc9180.sender_setup, Hpke.Error.t) result

The Auth-mode counterpart of setup_base_sender: Hpke.Rfc9180.setup_auth_sender with ephemeral as skE. sender is the sender's static key skS, as there. Returns Hpke.Error.t.Unsupported_mode if the suite's KEM has no Auth mode, and otherwise Hpke.Error.t.Key_mismatch unless the suite and all three keys share one KEM.

Sourceval setup_auth_psk_sender : 'capability Hpke.Suite.t -> ephemeral:Hpke.Private_key.t -> recipient:Hpke.Public_key.t -> sender:Hpke.Private_key.t -> psk:Hpke.Psk.t -> info:string -> ('capability Hpke.Rfc9180.sender_setup, Hpke.Error.t) result

The AuthPSK-mode counterpart of setup_auth_sender, with its errors.