atomvm_gleam/crypto
Types
AEAD ciphers for crypto_one_time_aead.
pub type CipherAead {
Aes128Gcm
Aes192Gcm
Aes256Gcm
Aes128Ccm
Aes192Ccm
Aes256Ccm
Chacha20Poly1305
}
Constructors
-
Aes128Gcm -
Aes192Gcm -
Aes256Gcm -
Aes128Ccm -
Aes192Ccm -
Aes256Ccm -
Chacha20Poly1305
IV ciphers for crypto_one_time_iv.
pub type CipherIv {
Aes128Cbc
Aes192Cbc
Aes256Cbc
Aes128Cfb128
Aes192Cfb128
Aes256Cfb128
Aes128Ctr
Aes192Ctr
Aes256Ctr
Aes128Ofb
Aes192Ofb
Aes256Ofb
}
Constructors
-
Aes128Cbc -
Aes192Cbc -
Aes256Cbc -
Aes128Cfb128 -
Aes192Cfb128 -
Aes256Cfb128 -
Aes128Ctr -
Aes192Ctr -
Aes256Ctr -
Aes128Ofb -
Aes192Ofb -
Aes256Ofb
ECB ciphers for crypto_one_time (no IV).
pub type CipherNoIv {
Aes128Ecb
Aes192Ecb
Aes256Ecb
}
Constructors
-
Aes128Ecb -
Aes192Ecb -
Aes256Ecb
Opaque streaming cipher state (crypto_state()).
Unlike hash/MAC state, this handle is mutated in place by
crypto_update and crypto_final.
pub type CipherState
AES CBC/ECB subtypes for CMAC. Mapped to upstream cipher atoms in FFI.
pub type CmacCipher {
CmacAes128Cbc
CmacAes128Ecb
CmacAes192Cbc
CmacAes192Ecb
CmacAes256Cbc
CmacAes256Ecb
}
Constructors
-
CmacAes128Cbc -
CmacAes128Ecb -
CmacAes192Cbc -
CmacAes192Ecb -
CmacAes256Cbc -
CmacAes256Ecb
Encrypt/decrypt options for one-shot ciphers.
pub type CryptoOpts {
CryptoOpts(encrypt: Bool, padding: option.Option(Padding))
}
Constructors
-
CryptoOpts(encrypt: Bool, padding: option.Option(Padding))
Named curves for ECDH / ECDSA (plus X25519 for ECDH/EDDH).
pub type EcCurve {
Secp256k1
Secp256r1
Secp384r1
Secp521r1
BrainpoolP256r1
BrainpoolP384r1
BrainpoolP512r1
X25519
}
Constructors
-
Secp256k1 -
Secp256r1 -
Secp384r1 -
Secp521r1 -
BrainpoolP256r1 -
BrainpoolP384r1 -
BrainpoolP512r1 -
X25519
Errors from :crypto NIFs and helpers.
pub type Error {
Failed
NotSupported
Badarg
Timeout
Other(String)
}
Constructors
-
Failed -
NotSupported -
Badarg -
Timeout -
Other(String)
Hash algorithms for hash, streaming hash, HMAC, and PBKDF2.
pub type HashAlgorithm {
Md5
Sha
Sha224
Sha256
Sha384
Sha512
}
Constructors
-
Md5 -
Sha -
Sha224 -
Sha256 -
Sha384 -
Sha512
Library entry from info_lib.
pub type LibInfo {
LibInfo(
name: BitArray,
version_num: Int,
version_str: BitArray,
)
}
Constructors
-
LibInfo(name: BitArray, version_num: Int, version_str: BitArray)
Values
pub fn compute_key_ecdh(
curve: EcCurve,
other_public_key: BitArray,
my_private_key: BitArray,
) -> Result(BitArray, Error)
ECDH shared secret.
See crypto:compute_key/4.
pub fn compute_key_eddh(
other_public_key: BitArray,
my_private_key: BitArray,
) -> Result(BitArray, Error)
X25519 EDDH shared secret.
See crypto:compute_key/4.
pub fn crypto_final(
state: CipherState,
) -> Result(BitArray, Error)
Finalize a streaming cipher and return any remaining bytes.
After this call the state must not be reused on AtomVM (badarg).
pub fn crypto_init(
cipher: CipherNoIv,
key: BitArray,
opts: CryptoOpts,
) -> Result(CipherState, Error)
Start a streaming cipher for ciphers that do not use an IV (ECB).
Equivalent to upstream crypto_init(Cipher, Key, <<>>, FlagOrOptions).
See crypto:crypto_init/3.
pub fn crypto_init_iv(
cipher: CipherIv,
key: BitArray,
iv: BitArray,
opts: CryptoOpts,
) -> Result(CipherState, Error)
Start a streaming cipher for ciphers that use an IV.
PKCS padding is supported only with CBC ciphers on AtomVM.
See crypto:crypto_init/4.
pub fn crypto_one_time(
cipher: CipherNoIv,
key: BitArray,
data: BitArray,
opts: CryptoOpts,
) -> Result(BitArray, Error)
One-shot encrypt/decrypt for ciphers that do not use an IV (ECB).
pub fn crypto_one_time_aead_decrypt(
cipher: CipherAead,
key: BitArray,
iv: BitArray,
ciphertext: BitArray,
aad: BitArray,
tag: BitArray,
) -> Result(BitArray, Error)
AEAD decrypt; authentication failure becomes Error(Failed).
pub fn crypto_one_time_aead_encrypt(
cipher: CipherAead,
key: BitArray,
iv: BitArray,
plaintext: BitArray,
aad: BitArray,
) -> Result(#(BitArray, BitArray), Error)
AEAD encrypt with the default tag length.
Returns #(ciphertext, tag).
pub fn crypto_one_time_aead_encrypt_tag_length(
cipher: CipherAead,
key: BitArray,
iv: BitArray,
plaintext: BitArray,
aad: BitArray,
tag_length: Int,
) -> Result(#(BitArray, BitArray), Error)
AEAD encrypt with an explicit tag length in bytes.
Returns #(ciphertext, tag).
pub fn crypto_one_time_iv(
cipher: CipherIv,
key: BitArray,
iv: BitArray,
data: BitArray,
opts: CryptoOpts,
) -> Result(BitArray, Error)
One-shot encrypt/decrypt for ciphers that use an IV.
pub fn crypto_update(
state: CipherState,
data: BitArray,
) -> Result(BitArray, Error)
Feed data into a streaming cipher; returns ciphertext/plaintext produced
so far. Mutates state in place.
pub fn decrypt_opts() -> CryptoOpts
Default decrypt options (no explicit padding entry).
pub fn encrypt_opts() -> CryptoOpts
Default encrypt options (no explicit padding entry).
pub fn generate_key_ecdh(
curve: EcCurve,
) -> Result(#(BitArray, BitArray), Error)
Generate an ECDH key pair for curve. Returns #(public, private).
pub fn generate_key_eddh() -> Result(#(BitArray, BitArray), Error)
Generate an X25519 EDDH key pair. Returns #(public, private).
pub fn generate_key_eddsa() -> Result(
#(BitArray, BitArray),
Error,
)
Generate an Ed25519 key pair (libsodium build). Returns #(public, private).
pub fn hash(
algorithm: HashAlgorithm,
data: BitArray,
) -> Result(BitArray, Error)
Hash data with algorithm.
See crypto:hash/2.
pub fn hash_equals(
a: BitArray,
b: BitArray,
) -> Result(Bool, Error)
Constant-time equality for equal-length MAC/hash binaries.
See crypto:hash_equals/2.
pub fn hash_final(state: HashState) -> Result(BitArray, Error)
Finalize a streaming hash and return the digest.
See crypto:hash_final/1.
pub fn hash_init(
algorithm: HashAlgorithm,
) -> Result(HashState, Error)
Start a streaming hash.
See crypto:hash_init/1.
pub fn hash_update(
state: HashState,
data: BitArray,
) -> Result(HashState, Error)
Fold data into a streaming hash (returns a new state).
See crypto:hash_update/2.
pub fn info_lib() -> Result(List(LibInfo), Error)
Crypto library name/version tuples from the runtime.
See crypto:info_lib/0.
pub fn mac_cmac(
cipher: CmacCipher,
key: BitArray,
data: BitArray,
) -> Result(BitArray, Error)
One-shot CMAC over an AES CBC/ECB subtype.
See crypto:mac/4.
pub fn mac_final(state: MacState) -> Result(BitArray, Error)
Finalize a streaming MAC.
See crypto:mac_final/1.
pub fn mac_final_n(
state: MacState,
mac_length: Int,
) -> Result(BitArray, Error)
Finalize a streaming MAC, truncating to mac_length bytes.
See crypto:mac_finalN/2.
pub fn mac_hmac(
digest: HashAlgorithm,
key: BitArray,
data: BitArray,
) -> Result(BitArray, Error)
One-shot HMAC.
See crypto:mac/4.
pub fn mac_hmac_ripemd160(
key: BitArray,
data: BitArray,
) -> Result(BitArray, Error)
One-shot HMAC-RIPEMD160 (accepted by AtomVM mac/4 beyond hash/2 digests).
See crypto:mac/4.
pub fn mac_init_cmac(
cipher: CmacCipher,
key: BitArray,
) -> Result(MacState, Error)
Start a streaming CMAC.
See crypto:mac_init/3.
pub fn mac_init_hmac(
digest: HashAlgorithm,
key: BitArray,
) -> Result(MacState, Error)
Start a streaming HMAC.
See crypto:mac_init/3.
pub fn mac_init_hmac_ripemd160(
key: BitArray,
) -> Result(MacState, Error)
Start a streaming HMAC-RIPEMD160.
See crypto:mac_init/3.
pub fn mac_update(
state: MacState,
data: BitArray,
) -> Result(MacState, Error)
Add data to a streaming MAC.
See crypto:mac_update/2.
pub fn pbkdf2_hmac(
digest: HashAlgorithm,
password: BitArray,
salt: BitArray,
iterations: Int,
key_len: Int,
) -> Result(BitArray, Error)
PBKDF2-HMAC key derivation (RFC 8018 §5.2).
See crypto:pbkdf2_hmac/5.
pub fn sign_ecdsa(
digest: HashAlgorithm,
msg: BitArray,
private_key: BitArray,
curve: EcCurve,
) -> Result(BitArray, Error)
ECDSA sign. curve must be a Weierstrass curve (not X25519).
See crypto:sign/4.
pub fn sign_eddsa(
msg: BitArray,
private_key: BitArray,
) -> Result(BitArray, Error)
Ed25519 sign (DigestType = none; libsodium build).
See crypto:sign/4.
pub fn strong_rand_bytes(n: Int) -> Result(BitArray, Error)
Cryptographically secure random bytes (preferred over deprecated
atomvm:rand_bytes/1).
pub fn verify_ecdsa(
digest: HashAlgorithm,
msg: BitArray,
signature: BitArray,
public_key: BitArray,
curve: EcCurve,
) -> Result(Bool, Error)
ECDSA verify. Invalid signatures return Ok(False).
See crypto:verify/5.
pub fn verify_eddsa(
msg: BitArray,
signature: BitArray,
public_key: BitArray,
) -> Result(Bool, Error)
Ed25519 verify. Invalid signatures return Ok(False).
See crypto:verify/5.