atomvm_gleam/crypto

Types

AEAD ciphers for crypto_one_time_aead.

pub type CipherAead {
  Aes128Gcm
  Aes192Gcm
  Aes256Gcm
  Aes128Ccm
  Aes192Ccm
  Aes256Ccm
  Chacha20Poly1305
}

Constructors

  • Aes128Gcm
  • Aes192Gcm
  • Aes256Gcm
  • Aes128Ccm
  • Aes192Ccm
  • Aes256Ccm
  • Chacha20Poly1305

IV ciphers for crypto_one_time_iv.

pub type CipherIv {
  Aes128Cbc
  Aes192Cbc
  Aes256Cbc
  Aes128Cfb128
  Aes192Cfb128
  Aes256Cfb128
  Aes128Ctr
  Aes192Ctr
  Aes256Ctr
  Aes128Ofb
  Aes192Ofb
  Aes256Ofb
}

Constructors

  • Aes128Cbc
  • Aes192Cbc
  • Aes256Cbc
  • Aes128Cfb128
  • Aes192Cfb128
  • Aes256Cfb128
  • Aes128Ctr
  • Aes192Ctr
  • Aes256Ctr
  • Aes128Ofb
  • Aes192Ofb
  • Aes256Ofb

ECB ciphers for crypto_one_time (no IV).

pub type CipherNoIv {
  Aes128Ecb
  Aes192Ecb
  Aes256Ecb
}

Constructors

  • Aes128Ecb
  • Aes192Ecb
  • Aes256Ecb

Opaque streaming cipher state (crypto_state()).

Unlike hash/MAC state, this handle is mutated in place by crypto_update and crypto_final.

pub type CipherState

AES CBC/ECB subtypes for CMAC. Mapped to upstream cipher atoms in FFI.

pub type CmacCipher {
  CmacAes128Cbc
  CmacAes128Ecb
  CmacAes192Cbc
  CmacAes192Ecb
  CmacAes256Cbc
  CmacAes256Ecb
}

Constructors

  • CmacAes128Cbc
  • CmacAes128Ecb
  • CmacAes192Cbc
  • CmacAes192Ecb
  • CmacAes256Cbc
  • CmacAes256Ecb

Encrypt/decrypt options for one-shot ciphers.

pub type CryptoOpts {
  CryptoOpts(encrypt: Bool, padding: option.Option(Padding))
}

Constructors

Named curves for ECDH / ECDSA (plus X25519 for ECDH/EDDH).

pub type EcCurve {
  Secp256k1
  Secp256r1
  Secp384r1
  Secp521r1
  BrainpoolP256r1
  BrainpoolP384r1
  BrainpoolP512r1
  X25519
}

Constructors

  • Secp256k1
  • Secp256r1
  • Secp384r1
  • Secp521r1
  • BrainpoolP256r1
  • BrainpoolP384r1
  • BrainpoolP512r1
  • X25519

Errors from :crypto NIFs and helpers.

pub type Error {
  Failed
  NotSupported
  Badarg
  Timeout
  Other(String)
}

Constructors

  • Failed
  • NotSupported
  • Badarg
  • Timeout
  • Other(String)

Hash algorithms for hash, streaming hash, HMAC, and PBKDF2.

pub type HashAlgorithm {
  Md5
  Sha
  Sha224
  Sha256
  Sha384
  Sha512
}

Constructors

  • Md5
  • Sha
  • Sha224
  • Sha256
  • Sha384
  • Sha512

Opaque streaming hash state (hash_state()).

pub type HashState

Library entry from info_lib.

pub type LibInfo {
  LibInfo(
    name: BitArray,
    version_num: Int,
    version_str: BitArray,
  )
}

Constructors

  • LibInfo(name: BitArray, version_num: Int, version_str: BitArray)

Opaque streaming MAC state (mac_state()).

pub type MacState

Padding for crypto_one_time option lists.

AtomVM supports pkcs_padding only with CBC ciphers (not ECB).

pub type Padding {
  NoPadding
  PkcsPadding
}

Constructors

  • NoPadding
  • PkcsPadding

Values

pub fn compute_key_ecdh(
  curve: EcCurve,
  other_public_key: BitArray,
  my_private_key: BitArray,
) -> Result(BitArray, Error)

ECDH shared secret.

See crypto:compute_key/4.

pub fn compute_key_eddh(
  other_public_key: BitArray,
  my_private_key: BitArray,
) -> Result(BitArray, Error)

X25519 EDDH shared secret.

See crypto:compute_key/4.

pub fn crypto_final(
  state: CipherState,
) -> Result(BitArray, Error)

Finalize a streaming cipher and return any remaining bytes.

After this call the state must not be reused on AtomVM (badarg).

See crypto:crypto_final/1.

pub fn crypto_init(
  cipher: CipherNoIv,
  key: BitArray,
  opts: CryptoOpts,
) -> Result(CipherState, Error)

Start a streaming cipher for ciphers that do not use an IV (ECB).

Equivalent to upstream crypto_init(Cipher, Key, <<>>, FlagOrOptions).

See crypto:crypto_init/3.

pub fn crypto_init_iv(
  cipher: CipherIv,
  key: BitArray,
  iv: BitArray,
  opts: CryptoOpts,
) -> Result(CipherState, Error)

Start a streaming cipher for ciphers that use an IV.

PKCS padding is supported only with CBC ciphers on AtomVM.

See crypto:crypto_init/4.

pub fn crypto_one_time(
  cipher: CipherNoIv,
  key: BitArray,
  data: BitArray,
  opts: CryptoOpts,
) -> Result(BitArray, Error)

One-shot encrypt/decrypt for ciphers that do not use an IV (ECB).

See crypto:crypto_one_time/4.

pub fn crypto_one_time_aead_decrypt(
  cipher: CipherAead,
  key: BitArray,
  iv: BitArray,
  ciphertext: BitArray,
  aad: BitArray,
  tag: BitArray,
) -> Result(BitArray, Error)

AEAD decrypt; authentication failure becomes Error(Failed).

See crypto:crypto_one_time_aead/7.

pub fn crypto_one_time_aead_encrypt(
  cipher: CipherAead,
  key: BitArray,
  iv: BitArray,
  plaintext: BitArray,
  aad: BitArray,
) -> Result(#(BitArray, BitArray), Error)

AEAD encrypt with the default tag length.

Returns #(ciphertext, tag).

See crypto:crypto_one_time_aead/6.

pub fn crypto_one_time_aead_encrypt_tag_length(
  cipher: CipherAead,
  key: BitArray,
  iv: BitArray,
  plaintext: BitArray,
  aad: BitArray,
  tag_length: Int,
) -> Result(#(BitArray, BitArray), Error)

AEAD encrypt with an explicit tag length in bytes.

Returns #(ciphertext, tag).

See crypto:crypto_one_time_aead/7.

pub fn crypto_one_time_iv(
  cipher: CipherIv,
  key: BitArray,
  iv: BitArray,
  data: BitArray,
  opts: CryptoOpts,
) -> Result(BitArray, Error)

One-shot encrypt/decrypt for ciphers that use an IV.

See crypto:crypto_one_time/5.

pub fn crypto_update(
  state: CipherState,
  data: BitArray,
) -> Result(BitArray, Error)

Feed data into a streaming cipher; returns ciphertext/plaintext produced so far. Mutates state in place.

See crypto:crypto_update/2.

pub fn decrypt_opts() -> CryptoOpts

Default decrypt options (no explicit padding entry).

pub fn encrypt_opts() -> CryptoOpts

Default encrypt options (no explicit padding entry).

pub fn error_to_string(error: Error) -> String

Format an Error for logging.

pub fn generate_key_ecdh(
  curve: EcCurve,
) -> Result(#(BitArray, BitArray), Error)

Generate an ECDH key pair for curve. Returns #(public, private).

See crypto:generate_key/2.

pub fn generate_key_eddh() -> Result(#(BitArray, BitArray), Error)

Generate an X25519 EDDH key pair. Returns #(public, private).

See crypto:generate_key/2.

pub fn generate_key_eddsa() -> Result(
  #(BitArray, BitArray),
  Error,
)

Generate an Ed25519 key pair (libsodium build). Returns #(public, private).

See crypto:generate_key/2.

pub fn hash(
  algorithm: HashAlgorithm,
  data: BitArray,
) -> Result(BitArray, Error)

Hash data with algorithm.

See crypto:hash/2.

pub fn hash_equals(
  a: BitArray,
  b: BitArray,
) -> Result(Bool, Error)

Constant-time equality for equal-length MAC/hash binaries.

See crypto:hash_equals/2.

pub fn hash_final(state: HashState) -> Result(BitArray, Error)

Finalize a streaming hash and return the digest.

See crypto:hash_final/1.

pub fn hash_init(
  algorithm: HashAlgorithm,
) -> Result(HashState, Error)

Start a streaming hash.

See crypto:hash_init/1.

pub fn hash_update(
  state: HashState,
  data: BitArray,
) -> Result(HashState, Error)

Fold data into a streaming hash (returns a new state).

See crypto:hash_update/2.

pub fn info_lib() -> Result(List(LibInfo), Error)

Crypto library name/version tuples from the runtime.

See crypto:info_lib/0.

pub fn mac_cmac(
  cipher: CmacCipher,
  key: BitArray,
  data: BitArray,
) -> Result(BitArray, Error)

One-shot CMAC over an AES CBC/ECB subtype.

See crypto:mac/4.

pub fn mac_final(state: MacState) -> Result(BitArray, Error)

Finalize a streaming MAC.

See crypto:mac_final/1.

pub fn mac_final_n(
  state: MacState,
  mac_length: Int,
) -> Result(BitArray, Error)

Finalize a streaming MAC, truncating to mac_length bytes.

See crypto:mac_finalN/2.

pub fn mac_hmac(
  digest: HashAlgorithm,
  key: BitArray,
  data: BitArray,
) -> Result(BitArray, Error)

One-shot HMAC.

See crypto:mac/4.

pub fn mac_hmac_ripemd160(
  key: BitArray,
  data: BitArray,
) -> Result(BitArray, Error)

One-shot HMAC-RIPEMD160 (accepted by AtomVM mac/4 beyond hash/2 digests).

See crypto:mac/4.

pub fn mac_init_cmac(
  cipher: CmacCipher,
  key: BitArray,
) -> Result(MacState, Error)

Start a streaming CMAC.

See crypto:mac_init/3.

pub fn mac_init_hmac(
  digest: HashAlgorithm,
  key: BitArray,
) -> Result(MacState, Error)

Start a streaming HMAC.

See crypto:mac_init/3.

pub fn mac_init_hmac_ripemd160(
  key: BitArray,
) -> Result(MacState, Error)

Start a streaming HMAC-RIPEMD160.

See crypto:mac_init/3.

pub fn mac_update(
  state: MacState,
  data: BitArray,
) -> Result(MacState, Error)

Add data to a streaming MAC.

See crypto:mac_update/2.

pub fn pbkdf2_hmac(
  digest: HashAlgorithm,
  password: BitArray,
  salt: BitArray,
  iterations: Int,
  key_len: Int,
) -> Result(BitArray, Error)

PBKDF2-HMAC key derivation (RFC 8018 §5.2).

See crypto:pbkdf2_hmac/5.

pub fn sign_ecdsa(
  digest: HashAlgorithm,
  msg: BitArray,
  private_key: BitArray,
  curve: EcCurve,
) -> Result(BitArray, Error)

ECDSA sign. curve must be a Weierstrass curve (not X25519).

See crypto:sign/4.

pub fn sign_eddsa(
  msg: BitArray,
  private_key: BitArray,
) -> Result(BitArray, Error)

Ed25519 sign (DigestType = none; libsodium build).

See crypto:sign/4.

pub fn strong_rand_bytes(n: Int) -> Result(BitArray, Error)

Cryptographically secure random bytes (preferred over deprecated atomvm:rand_bytes/1).

See crypto:strong_rand_bytes/1.

pub fn verify_ecdsa(
  digest: HashAlgorithm,
  msg: BitArray,
  signature: BitArray,
  public_key: BitArray,
  curve: EcCurve,
) -> Result(Bool, Error)

ECDSA verify. Invalid signatures return Ok(False).

See crypto:verify/5.

pub fn verify_eddsa(
  msg: BitArray,
  signature: BitArray,
  public_key: BitArray,
) -> Result(Bool, Error)

Ed25519 verify. Invalid signatures return Ok(False).

See crypto:verify/5.

✨ Search Document