feat: replace deprecated ExpandedKeyEncoding with seed serialization, derive ZeroizeOnDrop (#7)
Rust CI / cargo clippy (push) Successful in 1m23s
Rust CI / cargo fmt (push) Successful in 3s
Rust CI / test (1.90.0 / no backend / no frontend) (push) Successful in 2m24s
Publish / publish (release) Successful in 57s
Rust CI / test (stable / no backend / no frontend) (push) Successful in 2m24s
Rust CI / test (1.90.0 / no backend / --features serde) (push) Successful in 2m51s
Rust CI / test (1.90.0 / no backend / --features argon2) (push) Successful in 2m32s
Rust CI / test (stable / no backend / --features argon2) (push) Successful in 2m33s
Rust CI / test (1.90.0 / --features curve25519 / no frontend) (push) Successful in 2m30s
Rust CI / test (stable / no backend / --features serde) (push) Successful in 2m53s
Rust CI / test (stable / --features curve25519 / no frontend) (push) Successful in 2m28s
Rust CI / test (1.90.0 / --features curve25519 / --features argon2) (push) Successful in 2m35s
Rust CI / test (stable / --features curve25519 / --features argon2) (push) Successful in 2m37s
Rust CI / test (1.90.0 / --features curve25519 / --features serde) (push) Successful in 2m57s
Rust CI / test (stable / --features curve25519 / --features serde) (push) Successful in 2m58s
Rust CI / test (1.90.0 / --features ecdsa / no frontend) (push) Successful in 2m50s
Rust CI / test (stable / --features ecdsa / no frontend) (push) Successful in 2m49s
Rust CI / test (1.90.0 / --features ecdsa / --features argon2) (push) Successful in 2m58s
Rust CI / test (stable / --features ecdsa / --features serde) (push) Successful in 3m20s
Rust CI / test (stable / --features ecdsa / --features argon2) (push) Successful in 2m59s
Rust CI / test (1.90.0 / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ed25519 / no frontend) (push) Successful in 2m52s
Rust CI / test (1.90.0 / --features ed25519 / --features argon2) (push) Successful in 2m58s
Rust CI / test (stable / --features ed25519 / no frontend) (push) Successful in 2m53s
Rust CI / test (stable / --features ed25519 / --features argon2) (push) Successful in 3m0s
Rust CI / test (1.90.0 / --features ed25519 / --features serde) (push) Successful in 3m20s
Rust CI / test (stable / --features ed25519 / --features serde) (push) Successful in 3m18s
Rust CI / test (1.90.0 / --features ristretto255 / no frontend) (push) Successful in 2m59s
Rust CI / test (stable / --features ristretto255 / no frontend) (push) Successful in 3m3s
Rust CI / test (1.90.0 / --features ristretto255 / --features argon2) (push) Successful in 3m8s
Rust CI / test (stable / --features ristretto255 / --features argon2) (push) Successful in 3m13s
Rust CI / test (1.90.0 / --features ristretto255 / --features serde) (push) Successful in 3m28s
Rust CI / test (stable / --features ristretto255 / --features serde) (push) Successful in 3m32s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m20s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m9s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m29s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m12s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m53s
Rust CI / test (1.90.0 / --features ristretto255,kem / no frontend) (push) Successful in 3m54s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m45s
Rust CI / test (stable / --features ristretto255,kem / no frontend) (push) Successful in 3m51s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features argon2) (push) Successful in 4m1s
Rust CI / test (stable / --features ristretto255,kem / --features argon2) (push) Successful in 3m58s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features serde) (push) Successful in 4m25s
Rust CI / test (stable / --features ristretto255,kem / --features serde) (push) Successful in 4m23s
Rust CI / test simple_login example (push) Successful in 18s
Rust CI / test digital_locker example (push) Successful in 17s
Rust CI / cargo bench compilation () (push) Successful in 1m44s
Rust CI / cargo bench compilation (--features ristretto255) (push) Successful in 1m54s
Rust CI / cargo bench compilation (--features ristretto255,kem) (push) Successful in 2m28s
Rust CI / cargo audit (push) Successful in 8s
Rust CI / no-std (wasm32-unknown-unknown / curve25519) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ed25519) (push) Successful in 30s
Rust CI / no-std (wasm32-unknown-unknown / ed25519) (push) Successful in 29s
Rust CI / no-std (thumbv6m-none-eabi / no backend) (push) Successful in 17s
Rust CI / no-std (wasm32-unknown-unknown / ecdsa) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 19s
Rust CI / no-std (thumbv6m-none-eabi / curve25519) (push) Successful in 27s
Rust CI / no-std (wasm32-unknown-unknown / no backend) (push) Successful in 19s
Rust CI / no-std (thumbv6m-none-eabi / ecdsa) (push) Successful in 27s

- Add ZeroizeOnDrop bound to Hash trait
- Replace manual Drop impls on Ke2Builder and KemKe2Builder with derive_where
- Migrate KEM decapsulation key serialization from expanded form to 64-byte seed (KeyInit/KeyExport)
- Fix voprf deserialization to pass exact-length slices
- Bump voprf-vx to 1.0.0-rc.1
- Regenerate test vectors

Reviewed-on: #7
Co-authored-by: UneBaguette <[email protected]>
Co-committed-by: UneBaguette <[email protected]>
This commit was merged in pull request #7.
This commit is contained in:
2026-07-03 13:06:30 +02:00
committed by breakingbread
parent b9b8699ee7
commit 09286d34fc
10 changed files with 588 additions and 631 deletions
+12 -49
View File
@@ -24,15 +24,12 @@ use digest::block_api::{CoreProxy, SmallBlockSizeUser};
use generic_array::typenum::{Cmp, IsLess, Le, NonZero, Sum, U256};
use generic_array::{ArrayLength, GenericArray};
use hybrid_array::ArraySize;
#[allow(deprecated)]
use ml_kem::ExpandedKeyEncoding;
use ml_kem::kem::{
Ciphertext as MlKemCiphertext, Decapsulate, Encapsulate, Kem as MlKemTrait, KeyExport,
Ciphertext as MlKemCiphertext, Decapsulate, Encapsulate, Kem as MlKemTrait, KeyExport, KeyInit,
KeySizeUser, TryKeyInit,
};
use rand::{CryptoRng, Rng};
use subtle::{ConstantTimeEq, CtOption};
use zeroize::{Zeroize, ZeroizeOnDrop};
use super::shared::{self, Ke1Message, Ke1State, NonceLen};
use super::{
@@ -55,7 +52,7 @@ pub trait KemCoreWrapper {
type EncapsulationKey: Clone;
/// Secret key type used for decapsulation operations.
type DecapsulationKey: Clone + ZeroizeOnDrop;
type DecapsulationKey: Clone + zeroize::ZeroizeOnDrop;
/// Length (in bytes) of the serialized public key.
type EncapsulationKeyLen: ArrayLength + ArraySize;
@@ -136,18 +133,16 @@ impl<R: Rng> rand::rand_core::TryRng for RngCompat<'_, R> {
impl<R: Rng + CryptoRng> rand::rand_core::TryCryptoRng for RngCompat<'_, R> {}
type RcEncapsulationKeyLen<K> = <<K as MlKemTrait>::EncapsulationKey as KeySizeUser>::KeySize;
#[allow(deprecated)]
type RcDecapsulationKeyLen<K> =
<<K as MlKemTrait>::DecapsulationKey as ExpandedKeyEncoding>::EncodedSize;
type RcDecapsulationKeyLen<K> = <<K as MlKemTrait>::DecapsulationKey as KeySizeUser>::KeySize;
type RcCiphertextLen<K> = <K as MlKemTrait>::CiphertextSize;
type RcSharedSecretLen<K> = <K as MlKemTrait>::SharedKeySize;
#[allow(deprecated)]
impl<K> KemCoreWrapper for K
where
K: MlKemTrait,
K::EncapsulationKey: Encapsulate<Kem = K> + KeyExport + TryKeyInit + Clone,
K::DecapsulationKey: Decapsulate<Kem = K> + ExpandedKeyEncoding + Clone + ZeroizeOnDrop,
K::DecapsulationKey:
Decapsulate<Kem = K> + KeyExport + KeyInit + Clone + zeroize::ZeroizeOnDrop,
RcEncapsulationKeyLen<K>: ArrayLength + ArraySize,
RcDecapsulationKeyLen<K>: ArrayLength + ArraySize,
RcCiphertextLen<K>: ArrayLength + ArraySize,
@@ -185,7 +180,7 @@ where
fn serialize_decapsulation_key(
key: &Self::DecapsulationKey,
) -> GenericArray<u8, Self::DecapsulationKeyLen> {
GenericArray::from_slice(key.to_expanded_bytes().as_slice()).clone()
GenericArray::from_slice(key.to_bytes().as_slice()).clone()
}
fn deserialize_decapsulation_key(
@@ -193,10 +188,9 @@ where
) -> Result<Self::DecapsulationKey, ProtocolError> {
let bytes: GenericArray<u8, RcDecapsulationKeyLen<K>> =
input.take_array("kem decapsulation key")?;
let key = ml_kem::array::Array::try_from(bytes.as_slice())
let seed = ml_kem::array::Array::try_from(bytes.as_slice())
.map_err(|_| ProtocolError::SerializationError)?;
K::DecapsulationKey::from_expanded_bytes(&key)
.map_err(|_| ProtocolError::SerializationError)
Ok(KeyInit::new(&seed))
}
fn encapsulate<R: Rng + CryptoRng>(
@@ -289,7 +283,7 @@ where
/// Server builder placeholder capturing the data needed to finish the KEM
/// exchange.
#[derive_where(Clone)]
#[derive_where(Clone, ZeroizeOnDrop)]
pub struct KemKe2Builder<G: Group, H: Hash, K: KemCoreWrapper>
where
H::Core: ProxyHash,
@@ -300,10 +294,13 @@ where
{
server_nonce: GenericArray<u8, NonceLen>,
transcript_hasher: H,
#[derive_where(skip(Zeroize))]
client_e_pk: PublicKey<G>,
#[derive_where(skip(Zeroize))]
server_e_pk: PublicKey<G>,
shared_secret_1: GenericArray<u8, G::PkLen>,
shared_secret_3: GenericArray<u8, G::PkLen>,
#[derive_where(skip(Zeroize))]
kem_encapsulation_key: GenericArray<u8, K::EncapsulationKeyLen>,
kem_ciphertext: GenericArray<u8, K::CiphertextLen>,
kem_shared_secret: GenericArray<u8, K::SharedSecretLen>,
@@ -335,40 +332,6 @@ where
/// Third message remains the same as `TripleDH`.
pub type KemKe3Message<H> = super::tripledh::Ke3Message<H>;
impl<G, H, K> Drop for KemKe2Builder<G, H, K>
where
G: Group,
H: Hash,
H::Core: ProxyHash,
<<H as CoreProxy>::Core as SmallBlockSizeUser>::_BlockSize: IsLess<U256>,
Le<<<H as CoreProxy>::Core as SmallBlockSizeUser>::_BlockSize, U256>: NonZero,
<<H as CoreProxy>::Core as SmallBlockSizeUser>::_BlockSize: Cmp<U256>,
OutputSize<H>: ArrayLength,
K: KemCoreWrapper,
{
fn drop(&mut self) {
self.server_nonce.zeroize();
digest::Digest::reset(&mut self.transcript_hasher);
self.shared_secret_1.zeroize();
self.shared_secret_3.zeroize();
self.kem_shared_secret.zeroize();
self.kem_ciphertext.zeroize();
}
}
impl<G, H, K> ZeroizeOnDrop for KemKe2Builder<G, H, K>
where
G: Group,
H: Hash,
H::Core: ProxyHash,
<<H as CoreProxy>::Core as SmallBlockSizeUser>::_BlockSize: IsLess<U256>,
Le<<<H as CoreProxy>::Core as SmallBlockSizeUser>::_BlockSize, U256>: NonZero,
<<H as CoreProxy>::Core as SmallBlockSizeUser>::_BlockSize: Cmp<U256>,
OutputSize<H>: ArrayLength,
K: KemCoreWrapper,
{
}
impl<G, H, K> KeyExchange for TripleDhKem<G, H, K>
where
G: Group + 'static,