breakingbread
71df1ee49a
feat: upgrade crypto ecosystem to latest RustCrypto stack ( #1 )
...
Rust CI / cargo audit (push) Successful in 6s
Rust CI / cargo fmt (push) Successful in 4s
Rust CI / test (1.90.0 / no backend / no frontend) (push) Successful in 2m25s
Rust CI / test (stable / no backend / no frontend) (push) Successful in 2m27s
Rust CI / cargo clippy (push) Successful in 1m25s
Rust CI / test (1.90.0 / no backend / --features argon2) (push) Successful in 2m35s
Rust CI / test (stable / no backend / --features argon2) (push) Successful in 2m34s
Rust CI / test (stable / no backend / --features serde) (push) Successful in 2m55s
Rust CI / test (stable / --features curve25519 / no frontend) (push) Successful in 2m31s
Rust CI / test (1.90.0 / no backend / --features serde) (push) Successful in 2m52s
Rust CI / test (1.90.0 / --features curve25519 / no frontend) (push) Successful in 2m29s
Rust CI / test (1.90.0 / --features curve25519 / --features argon2) (push) Successful in 2m37s
Rust CI / test (stable / --features curve25519 / --features argon2) (push) Successful in 2m36s
Rust CI / test (1.90.0 / --features curve25519 / --features serde) (push) Successful in 2m59s
Rust CI / test (stable / --features curve25519 / --features serde) (push) Successful in 3m1s
Rust CI / test (1.90.0 / --features ecdsa / no frontend) (push) Successful in 2m52s
Rust CI / test (stable / --features ecdsa / no frontend) (push) Successful in 2m51s
Rust CI / test (1.90.0 / --features ecdsa / --features argon2) (push) Successful in 2m57s
Rust CI / test (stable / --features ecdsa / --features argon2) (push) Successful in 2m58s
Rust CI / test (1.90.0 / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ristretto255 / no frontend) (push) Successful in 3m2s
Rust CI / test (stable / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ed25519 / no frontend) (push) Successful in 2m53s
Rust CI / test (stable / --features ed25519 / no frontend) (push) Successful in 2m54s
Rust CI / test (1.90.0 / --features ed25519 / --features argon2) (push) Successful in 3m3s
Rust CI / test (stable / --features ed25519 / --features argon2) (push) Successful in 3m0s
Rust CI / test (1.90.0 / --features ed25519 / --features serde) (push) Successful in 3m22s
Rust CI / test (stable / --features ed25519 / --features serde) (push) Successful in 3m22s
Rust CI / test (1.90.0 / --features ristretto255 / --features argon2) (push) Successful in 3m9s
Rust CI / test (stable / --features ristretto255 / no frontend) (push) Successful in 3m4s
Rust CI / test (stable / --features ristretto255 / --features argon2) (push) Successful in 3m11s
Rust CI / test (1.90.0 / --features ristretto255 / --features serde) (push) Successful in 3m28s
Rust CI / test (stable / --features ristretto255 / --features serde) (push) Successful in 3m32s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m26s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m17s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m27s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m43s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m20s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 6m1s
Rust CI / test (stable / --features ristretto255,kem / no frontend) (push) Successful in 4m0s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features argon2) (push) Successful in 4m5s
Rust CI / test (1.90.0 / --features ristretto255,kem / no frontend) (push) Successful in 4m2s
Rust CI / test (stable / --features ristretto255,kem / --features argon2) (push) Successful in 4m3s
Rust CI / test (stable / --features ristretto255,kem / --features serde) (push) Successful in 4m32s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features serde) (push) Successful in 4m31s
Rust CI / test simple_login example (push) Successful in 19s
Rust CI / test digital_locker example (push) Successful in 18s
Rust CI / cargo bench compilation () (push) Successful in 1m47s
Rust CI / cargo bench compilation (--features ristretto255) (push) Successful in 1m55s
Rust CI / cargo bench compilation (--features ristretto255,kem) (push) Successful in 2m35s
Rust CI / no-std (thumbv6m-none-eabi / no backend) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / no backend) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / curve25519) (push) Successful in 18s
Rust CI / no-std (wasm32-unknown-unknown / curve25519) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ecdsa) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ecdsa) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ed25519) (push) Successful in 30s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 19s
Upgrade all core cryptographic dependencies to their latest versions:
Dependencies:
- digest: 0.10 to 0.11
- elliptic-curve: 0.13 to 0.14
- hkdf: 0.12 to 0.13
- hmac: 0.12 to 0.13
- rand: 0.8 to 0.10
- rand_chacha: 0.3 to 0.10
- sha2: 0.10 to 0.11
- getrandom: 0.2 to 0.4 (WASM)
- ml-kem: 0.3.0-rc.0 to 0.3
- ecdsa: 0.16 to 0.17.0-rc.23
- rfc6979: 0.4 to 0.6 (now internal to ecdsa)
- p256/p384/p521: 0.13 to 0.14.0-rc.15
- curve25519-dalek: 4 to 5.0.0-rc
- ed25519-dalek: 2 to 3.0.0-rc
- cryptoki: 0.9 to 0.12
- rustyline: 17 to 18
- scrypt: 0.11 to 0.12
- voprf replaced by voprf-vx 1.0.0-pre.0
Migration changes:
- generic-array 0.14 to 1.4 with hybrid-array 0.4 interop
- ArrayLength<u8> to ArrayLength (generic-array 1.x)
- Added ConcatExt trait to disambiguate from [T]::concat
- Replaced Hmac with SimpleHmac for digest 0.11 compatibility
- Added OutputSize<H>: ArrayLength bounds throughout Hash trait
- Converted hybrid_array::Array between GenericArray at API boundaries
- Updated GroupEncoding Repr bound to hybrid_array::Array
- ECDSA sign now uses ecdsa::hazmat::sign_prehashed_rfc6979
- Removed direct rfc6979 dependency (handled by ecdsa internally)
- Replaced bincode with postcard for no_std serialization
- Re-exported hybrid_array from crate root
Other changes:
- Renamed crate to opaque-vx
- Increased MSRV to 1.89
- Added cryptography to Cargo.toml categories
- Removed Facebook-specific contributions from CONTRIBUTING.md
- Removed v3 to v4 migration test
- Removed unstable rustfmt configurations for stable compatibility
Reviewed-on: #1
Co-authored-by: UneBaguette <[email protected] >
Co-committed-by: UneBaguette <[email protected] >
2026-07-01 11:52:12 +02:00
daxpedda
8f9d7ec125
Update to Clippy v1.89 ( #385 )
2025-09-08 04:08:23 -07:00
daxpedda
c04fb97b5c
Remove Zeroize Tests ( #381 )
...
* Remove Zeroize tests
* Remove `Zeroize` requirements from `Group::Pk`
* Remove `Copy` requirements from `Group::Pk`
* Change to `ZeroizeOnDrop` requirements for `Group::Sk`
* Add note why we don't use `elliptic_curve::PublicKey`
2025-07-17 13:15:30 -07:00
daxpedda
1b6633cdcc
Move Serde De/Serialization to Group Implementation ( #380 )
...
* Move Serde De/Serialization to `Group` implementation
* Clean up Serde formats
* Fix typo
2025-07-14 19:54:43 -07:00
daxpedda
8ee35498ea
Publicly Expose trait KeyExchange ( #379 )
...
* Clean up types used in `trait KeyExchange`
* Expose `trait KeyExchange` publicly
2025-06-24 15:17:29 -07:00
daxpedda
3777ee680a
Only store dummy public key ( #374 )
2025-05-20 12:49:11 -07:00
daxpedda
bebd2c605b
SIGMA-I Key Exchange ( #378 )
...
* Move `KeGroup` to `KeyExchange::Group`
- Introduce `KeyExchange::Hash`, which separates the OPRF hash from the one used in `KeyExchange`.
- Remove `De/Serialize` requirement on key exchange messages and states, which forced a lot of where bounds on downstream users.
- Rename `KeGroup` to `Group`.
- Replace `D` generic for hash with `H`.
* Use `voprf::derive_key()` directly
* Implement SIGMA-I key exchange
* Improve `KeyExchange` for SIGMA-I and Ed25519
* Implement EdDSA
* Un-qualify some method calls
* SIGMA-I: only include client identity in client mac
* SIGMA-I: include server mac in client signature
* Expose key exchange types in `crate` & move modules
* Implement Ed25519ph
* Document `ed25519` crate feature
* Remove `ristretto255-voprf` crate feature
* Adjust CI crate feature testing
* Fix Rustdoc
* Remove unnecessary generic parameters from SIGMA-I
* Properly mark to-do's with TODO
* Assorted fixes
* SIGMA-I: include context in signature
* SIGMA-I: include identifiers in signature
* Merge `ServerLoginStart/FinishParameters`
* Re-export more necessary types
* More carefully expose types
* Add ECDSA test
* SIGMA-I: share context hashing
* De-duplicate client static public key storage
* Hide `KeyExchange` better
* Use the correct hash in the root documentation
* Bump `derive-where`
* Format documentation examples a bit further
* Add remote OPRF seed documentation
* Rename `deserialize_key_pair` to `deserialize_take_key_pair`
* Add more key tests
* Remove `SharedSecret` trait
* SIGMA-I refactor message API
* Share more implementation between 3DH and SIGMA-I
* Remove unnecessary zero scalar check for Curve25519
* Use correct hash in test
* Add some more TODOs
* Exclude `tests` folder from Cargo publishing
* Enable missing dependencies
* Use right crate for testing Ed25519
* Remove unnecessary `Sized` constraints
* Remove unnecessary `ecdsa` crate features
* Move signature de/serialization to trait methods
* Nit: move import to appropriate location
* Add warning to SIGMA-I
2025-05-19 13:56:25 -07:00
daxpedda
58b4d746c0
Enable remote OPRF seed support ( #373 )
2025-05-05 04:12:54 -07:00
daxpedda
560de5b718
Always create dummy record ( #376 )
2025-04-28 12:47:39 -07:00
daxpedda
d324584d79
Rework SecretKey API to facilitate async ( #371 )
...
* Rework `SecretKey` API to facilitate async
* Remove left-over constraints
2025-04-22 00:08:17 -07:00
daxpedda
6b69e93dc9
Bump MSRV to v1.83 ( #370 )
...
* Fix Clippy warnings for Rust v1.86
* Bump MSRV to v1.83
2025-04-15 13:31:37 -07:00
Kevin Lewi
066f88f434
Updating dependencies ( #360 )
2024-09-16 18:01:45 -07:00
daxpedda
47b37779d4
Add clippy::doc_markdown ( #346 )
2023-10-08 12:48:43 -07:00
Kevin Lewi
ead80ad892
Clarifying the persisting of server setup ( #344 )
2023-10-04 20:53:07 -07:00
Kevin Lewi
deb7ca3dc0
Update keypair generation to use derive_auth_keypair ( #326 )
2023-05-27 17:39:04 -05:00
Kevin Lewi
a88373722e
Updating dual-license language ( #324 )
2023-05-22 23:04:26 -07:00
daxpedda
09489ddf8b
Only use explicit crate features ( #306 )
2023-02-04 13:25:41 -08:00
daxpedda
a0cab10663
Update dependencies ( #288 )
...
* Fix Clippy
* Update dependencies
2022-12-10 21:30:05 -08:00
Kevin Lewi
3fe6bbb80f
Updating to version 08 ( #271 )
2022-04-17 16:23:31 -07:00
daxpedda
384207acbb
General Improvements ( #268 )
...
* Move `elliptic-curve` implementation to points to allow `Zeroize`
* Simplify `Ristretto255::random_scalar` implementation
* Fix `Ristretto255` deserialization
* Remove unnecessary check in `Ristretto255::random_scalar`
* Base `X25519` implementation on `curve25519-dalek`
* Constrain public and secret key to `Copy`
* Replace manual `ZeroizeOnDrop` implementation with `derive`
* Update dependencies
* Add `warn(unused_crate_dependencies)`
* Sync crate feature naming with `voprf`
* Remove unnecessary dependency crate features
* Never produce a zero scalar
* Rename `OprfGroup` to `OprfCs`
* Rename `TripleDH` to `TripleDh`
* Remove `slow-hash` crate feature
* Rename `NoOpHash` to `Identity`
* Rename `SlowHash` to `Ksf`
* Move `KeyExchange` type definitions down
* Deserialize secret and public keys from slices
* Remove `PrivateKey::from_bytes`
* Rename `From/ToBytes` to `De/Serialize`
* Re-export `serde_` as `serde`
* Custom `De/Serialize` implementation for keys
* Remove custom `De/Serialize` implementation
* Run Taplo v0.6
2022-04-01 16:10:00 -07:00
daxpedda
b2f10858e0
Group revamp ( #261 )
...
* Revamp `KeGroup` trait
* Update dependencies
* Fix `hash_to_scalar` using `OprfGroup` instead of `KeGroup`
* Relax constraints on associated types of `KeGroup`
* Improve `KeGroup` implementation on `Curve`
* Improve `KeyExchange` trait
* Fix new Clippy 1.59 warnings
2022-02-24 22:13:22 -08:00
daxpedda
47a26a19c5
Format ( #257 )
...
* Add Rustfmt
* Add Taplo
2022-01-05 21:19:02 -08:00
daxpedda
36f0a55518
Voprf update ( #255 )
...
* Update to latest voprf
* Upgrade to Rust edition 2021
* Fix Clippy
* Remove all allocations
* Remove unnecessary `allow(type_alias_bounds)`
* Make all serialization infallible
* Remove self-dependency
* Update rustyline
2022-01-05 15:10:57 -08:00
daxpedda
82e4436d39
General improvements ( #250 )
...
* Remove unnecessary constraints on hash
* Remove unnecessary `Result` on `KeyPair::generate_random`
* Fix de-serialization issue on `Ke1State`
* Fix rustfmt
* Remove allocations in `envelope`
* Run Clippy for tests and rustdoc lints too
* Fix `Debug` implementation
* Fix missing constraints on `ClientRegistration`
* Fix de-serialization
* Pin temporary dependency
* Update dependencies
* Replace macro with derive-where
* Remove unnecessary installation of Rust components
* Improve macro naming
* Implement `Copy`, `Debug`, `Ord` and `PartialOrd` for high-level items
* Add `rust-version` field to `Cargo.toml`
* Remove unnecessary allocations
* Fix MSRV
* Fix no_std
* Remove unnecessary allocations
* Remove unnecessary allocations
* Not importing items from voprf helps readability
* Fix rustdoc
* Remove unnecessary allocations
* Remove unnecessary allocations
* Replace `Vec` from `diffie_hellman` with `GenericArray`
* Remove unnecessary allocations
* Remove unnecessary allocations
* Remove `cfg(feature = bench)` guard for `missing_docs`
* Fix documentation
* Remove all remaining allocations from `KeyExchange`
* Improve type-safety
* Remove all remaining allocations in `keypair`
* Remove last remaining allocations except `NonVerifiableClient` input
* Remove base64 encoding in Serde implementation
* Remove unnecessary Serde `alloc` feature
* Make curve25519-dalek optional
* Rename `serialize` crate feature to `serde`
* Switch `KeGroup` implementations to higher-level libraries
- Fixes missing clamping in X25519
- X25519 is now a separate crate feature
* Fix typo
2022-01-03 15:50:40 -08:00
Kevin Lewi
adbd50f523
Updating to dual-license ( #252 )
2021-12-03 14:38:11 -08:00
Kevin Lewi
29b2ebef1b
Using voprf as a dependency ( #248 )
...
* Using voprf as a dependency
* Adding back x25519 and KeGroup
* Addressing comments
2021-10-25 02:54:32 -07:00
Kevin Lewi
65a0c2f98d
General cleanups and reorganizing code ( #236 )
2021-09-25 16:36:00 -07:00
daxpedda and Kevin Lewi
d1dfee9a65
Add SlowHash configuration ( #234 )
...
* Add `SlowHash` configuration
* Use a reference
* Changing generic argument to be CipherSuite instead of SlowHash
Co-authored-by: Kevin Lewi <[email protected] >
2021-09-02 02:28:21 -07:00
Kevin Lewi
aee4b5d50e
Simplifying error handling ( #232 )
2021-08-22 12:28:19 -07:00
daxpedda
6c7840514d
Fix no_std support ( #229 )
2021-08-16 20:11:53 -07:00
daxpedda and Kevin Lewi
8a7bcf9097
no_std support (#225 )
...
* No std implementation
* Run tests with std
* Adding wasm32-unknown-unknown target
Co-authored-by: Kevin Lewi <[email protected] >
2021-08-11 21:25:07 -07:00
daxpedda
88673d8e05
Separate AKE from OPRF take 2 ( #222 )
...
* Separate AKE from OPRF
Introduce X25519 implementation
* Rename `AkeGroup` to `KeGroup` and `Group` to `OprfGroup`
* Add documentation to "Overview"
2021-08-04 12:24:46 -07:00
daxpedda
10a38bc58b
Merge GroupWithMapToCurve into Group ( #219 )
...
* Merge `GroupWithMapToCurve` into `Group`
* Remove `hash_to_curve`
* Ristretto improvements
* P-256 improvements
2021-08-01 17:48:56 -07:00
dAxpeDDa
db4e07811e
Implement oprf_key test
2021-07-30 14:45:27 -07:00
dAxpeDDa
a5b9330b63
Improve types and documentation
2021-07-30 14:45:27 -07:00
dAxpeDDa
3f6b6d4afe
Implement client_mac_key test
2021-07-30 14:45:27 -07:00
dAxpeDDa
ec528eb4d9
Implement server_mac_key test
2021-07-30 14:45:27 -07:00
dAxpeDDa
4298deadff
Implement handshake_secret test
2021-07-30 14:45:27 -07:00
dAxpeDDa
49dc5b9050
Implement auth_key test
2021-07-30 14:45:27 -07:00
dAxpeDDa
dcaedc278c
Fix randomized_pwd
2021-07-30 14:45:27 -07:00
dAxpeDDa
460e2aef1c
Fix rustfmt
2021-07-30 14:45:27 -07:00
dAxpeDDa
b90163a007
Add randomized_pwd tests
2021-07-30 14:45:27 -07:00
daxpedda
77461b640d
Add custom ServerSetup construction
2021-07-23 15:23:10 -07:00
daxpedda
4ce61acc6e
Implement custom error type
2021-07-23 15:23:10 -07:00
daxpedda
3d01a605df
Move PrivateKey from CipherSuite to ServerSetup
2021-07-23 15:23:10 -07:00
daxpedda
124d64c9ca
Fix 1.41 compilation
2021-07-23 15:23:10 -07:00
daxpedda
d61e2d0b5c
Introduce PrivateKey associated type to CipherSuite
2021-07-23 15:23:10 -07:00
Kevin Lewi
b4882f8810
Adding reflected value check on client side
2021-07-14 18:10:35 -07:00
Kevin Lewi
8de2f37235
Updating VOPRF dependency
2021-07-12 15:16:08 -07:00
Kevin Lewi
e6b5a5dcf6
Adding i2osp error checking condition
2021-07-08 19:38:30 -07:00