package ohttp

  1. Overview
  2. Docs
Oblivious HTTP (RFC 9458) for OCaml

Install

dune-project
 Dependency

Authors

Maintainers

Sources

v0.1.2.tar.gz
md5=6a31dba01d9ee06d1b0115516439d8b0
sha512=c2739c32cf8d44b36ca565052f6b14feaf99a029115e8d94dcd469bd363f7dacd8e401a4ca07c0a3555f0fe5572a37516b489ddd945ee9acae4ceafc29e7dadb

doc/ohttp/Ohttp/Encapsulation/index.html

Module Ohttp.EncapsulationSource

The byte layout and key schedule of encapsulated messages (RFC 9458 Sections 4.1 to 4.4).

These are the pure functions that Client and Gateway are built from. They take every secret and every random value as an argument, so each step can be checked against published intermediate values. Applications should use Client and Gateway.

Sourcetype labels = {
  1. request : string;
  2. response : string;
}

The strings that bind a message to its media type. RFC 9458 Section 4.6 lets another protocol reuse the encapsulation with labels of its own.

Sourceval bhttp_labels : labels

"message/bhttp request" and "message/bhttp response".

Sourceval header_length : int

7.

Sourceval header : key_id:int -> Suite.t -> string

hdr: the key identifier, then the KEM, KDF, and AEAD identifiers.

Sourceval parse_header : string -> (int * int * int * int, Error.t) result

The key, KEM, KDF, and AEAD identifiers at the start of an Encapsulated Request.

Sourceval info : label:string -> header:string -> string

The info of the HPKE context: the label, a zero byte, and the header.

Sourcetype response_keys = {
  1. salt : string;
  2. prk : string;
  3. key : string;
  4. nonce : string;
}
Sourceval response_keys : Suite.t -> enc:string -> secret:string -> response_nonce:string -> (response_keys, Error.t) result

The key and nonce of a response, with the intermediate values that lead to them:

salt = concat(enc, response_nonce)
prk = Extract(salt, secret)
aead_key = Expand(prk, "key", Nk)
aead_nonce = Expand(prk, "nonce", Nn)

Extract and Expand are the plain HKDF functions of the suite, without the labels that HPKE adds inside its own key schedule. secret is what the HPKE context exports for the response label.

Sourceval seal_response : Suite.t -> enc:string -> secret:string -> response_nonce:string -> string -> (string, Error.t) result

An Encapsulated Response: response_nonce followed by the sealed response. response_nonce must be fresh, uniformly random, and Suite.response_nonce_length bytes long.

Sourceval open_response : Suite.t -> enc:string -> secret:string -> string -> (string, Error.t) result

The response inside an Encapsulated Response, or Error.t.Decapsulation_failed.