Rust CI / cargo clippy (push) Successful in 1m23s
Rust CI / cargo fmt (push) Successful in 3s
Rust CI / test (1.90.0 / no backend / no frontend) (push) Successful in 2m24s
Publish / publish (release) Successful in 57s
Rust CI / test (stable / no backend / no frontend) (push) Successful in 2m24s
Rust CI / test (1.90.0 / no backend / --features serde) (push) Successful in 2m51s
Rust CI / test (1.90.0 / no backend / --features argon2) (push) Successful in 2m32s
Rust CI / test (stable / no backend / --features argon2) (push) Successful in 2m33s
Rust CI / test (1.90.0 / --features curve25519 / no frontend) (push) Successful in 2m30s
Rust CI / test (stable / no backend / --features serde) (push) Successful in 2m53s
Rust CI / test (stable / --features curve25519 / no frontend) (push) Successful in 2m28s
Rust CI / test (1.90.0 / --features curve25519 / --features argon2) (push) Successful in 2m35s
Rust CI / test (stable / --features curve25519 / --features argon2) (push) Successful in 2m37s
Rust CI / test (1.90.0 / --features curve25519 / --features serde) (push) Successful in 2m57s
Rust CI / test (stable / --features curve25519 / --features serde) (push) Successful in 2m58s
Rust CI / test (1.90.0 / --features ecdsa / no frontend) (push) Successful in 2m50s
Rust CI / test (stable / --features ecdsa / no frontend) (push) Successful in 2m49s
Rust CI / test (1.90.0 / --features ecdsa / --features argon2) (push) Successful in 2m58s
Rust CI / test (stable / --features ecdsa / --features serde) (push) Successful in 3m20s
Rust CI / test (stable / --features ecdsa / --features argon2) (push) Successful in 2m59s
Rust CI / test (1.90.0 / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ed25519 / no frontend) (push) Successful in 2m52s
Rust CI / test (1.90.0 / --features ed25519 / --features argon2) (push) Successful in 2m58s
Rust CI / test (stable / --features ed25519 / no frontend) (push) Successful in 2m53s
Rust CI / test (stable / --features ed25519 / --features argon2) (push) Successful in 3m0s
Rust CI / test (1.90.0 / --features ed25519 / --features serde) (push) Successful in 3m20s
Rust CI / test (stable / --features ed25519 / --features serde) (push) Successful in 3m18s
Rust CI / test (1.90.0 / --features ristretto255 / no frontend) (push) Successful in 2m59s
Rust CI / test (stable / --features ristretto255 / no frontend) (push) Successful in 3m3s
Rust CI / test (1.90.0 / --features ristretto255 / --features argon2) (push) Successful in 3m8s
Rust CI / test (stable / --features ristretto255 / --features argon2) (push) Successful in 3m13s
Rust CI / test (1.90.0 / --features ristretto255 / --features serde) (push) Successful in 3m28s
Rust CI / test (stable / --features ristretto255 / --features serde) (push) Successful in 3m32s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m20s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m9s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m29s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m12s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m53s
Rust CI / test (1.90.0 / --features ristretto255,kem / no frontend) (push) Successful in 3m54s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m45s
Rust CI / test (stable / --features ristretto255,kem / no frontend) (push) Successful in 3m51s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features argon2) (push) Successful in 4m1s
Rust CI / test (stable / --features ristretto255,kem / --features argon2) (push) Successful in 3m58s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features serde) (push) Successful in 4m25s
Rust CI / test (stable / --features ristretto255,kem / --features serde) (push) Successful in 4m23s
Rust CI / test simple_login example (push) Successful in 18s
Rust CI / test digital_locker example (push) Successful in 17s
Rust CI / cargo bench compilation () (push) Successful in 1m44s
Rust CI / cargo bench compilation (--features ristretto255) (push) Successful in 1m54s
Rust CI / cargo bench compilation (--features ristretto255,kem) (push) Successful in 2m28s
Rust CI / cargo audit (push) Successful in 8s
Rust CI / no-std (wasm32-unknown-unknown / curve25519) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ed25519) (push) Successful in 30s
Rust CI / no-std (wasm32-unknown-unknown / ed25519) (push) Successful in 29s
Rust CI / no-std (thumbv6m-none-eabi / no backend) (push) Successful in 17s
Rust CI / no-std (wasm32-unknown-unknown / ecdsa) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 19s
Rust CI / no-std (thumbv6m-none-eabi / curve25519) (push) Successful in 27s
Rust CI / no-std (wasm32-unknown-unknown / no backend) (push) Successful in 19s
Rust CI / no-std (thumbv6m-none-eabi / ecdsa) (push) Successful in 27s
- Add ZeroizeOnDrop bound to Hash trait - Replace manual Drop impls on Ke2Builder and KemKe2Builder with derive_where - Migrate KEM decapsulation key serialization from expanded form to 64-byte seed (KeyInit/KeyExport) - Fix voprf deserialization to pass exact-length slices - Bump voprf-vx to 1.0.0-rc.1 - Regenerate test vectors Reviewed-on: #7 Co-authored-by: UneBaguette <[email protected]> Co-committed-by: UneBaguette <[email protected]>
87 lines
3.6 KiB
Markdown
87 lines
3.6 KiB
Markdown
## The OPAQUE key exchange protocol
|
|
|
|
[OPAQUE](https://eprint.iacr.org/2018/163.pdf) is an augmented password-authenticated key exchange protocol. It allows a
|
|
client to authenticate to a server using a password, without ever having to expose the plaintext password to the server.
|
|
|
|
This implementation is based on [RFC 9807](https://datatracker.ietf.org/doc/rfc9807/).
|
|
|
|
This is a fork of [facebook/opaque-ke](https://github.com/facebook/opaque-ke) maintained
|
|
by [VexaHub](https://github.com/vexahub), targeting the latest **RustCrypto ecosystem**.
|
|
|
|
Background
|
|
----------
|
|
|
|
Augmented Password Authenticated Key Exchange (aPAKE) protocols are designed to provide password authentication and
|
|
mutually authenticated key exchange without relying on PKI (except during user/password registration) and without
|
|
disclosing passwords to servers or other entities other than the client machine.
|
|
|
|
OPAQUE is a PKI-free aPAKE that is secure against pre-computation attacks and capable of using a secret salt.
|
|
|
|
Documentation
|
|
-------------
|
|
|
|
The API can be found [here](https://docs.rs/opaque-vx/) along with an example for usage. More examples can be found
|
|
in
|
|
the [examples](./examples) directory.
|
|
|
|
Installation
|
|
------------
|
|
|
|
Add the following line to the dependencies of your `Cargo.toml`:
|
|
|
|
```
|
|
opaque-vx = "1.0.0-rc.0"
|
|
```
|
|
|
|
### Minimum Supported Rust Version
|
|
|
|
Rust **1.90** or higher.
|
|
|
|
Audit
|
|
-----
|
|
|
|
This library was audited by NCC Group in June of 2021. The audit was sponsored by WhatsApp for its use
|
|
in [enabling end-to-end encrypted backups](https://engineering.fb.com/2021/09/10/security/whatsapp-e2ee-backups/).
|
|
|
|
The audit found issues in release `v0.5.0`, and the fixes were subsequently incorporated into release `v1.2.0`. See
|
|
the [full audit report here](https://research.nccgroup.com/2021/12/13/public-report-whatsapp-opaque-ke-cryptographic-implementation-review/).
|
|
|
|
Resources
|
|
---------
|
|
|
|
- [OPAQUE academic publication](https://eprint.iacr.org/2018/163.pdf), including formal definitions and a proof of
|
|
security
|
|
- [RFC 9807](https://datatracker.ietf.org/doc/rfc9807/), containing a detailed (byte-level) specification for OPAQUE
|
|
- ["Let's talk about PAKE"](https://blog.cryptographyengineering.com/2018/10/19/lets-talk-about-pake/), an introductory
|
|
blog post written by Matthew Green that covers OPAQUE
|
|
- [@serenity-kit/opaque](https://github.com/serenity-kit/opaque), a WebAssembly package for this library
|
|
- [opaque-wasm](https://github.com/marucjmar/opaque-wasm), a WebAssembly package for this library. A comparison between
|
|
`@serenity-kit/opaque` and `opaque-wasm` can be
|
|
found [here](https://opaque-documentation.netlify.app/docs/faq#how-does-it-compare-to-opaque-wasm)
|
|
- [react-native-opaque](https://github.com/serenity-kit/react-native-opaque), a React Native package for this library
|
|
matching the API of `@serenity-kit/opaque`
|
|
|
|
Contributors
|
|
------------
|
|
|
|
This fork is maintained by [VexaHub](https://github.com/vexahub).
|
|
|
|
The original authors are Kevin Lewi ([@kevinlewi](https://github.com/kevinlewi)) and François
|
|
Garillot ([@huitseeker](https://github.com/huitseeker)).
|
|
To learn more about contributing to this project, [see this document](./CONTRIBUTING.md).
|
|
|
|
#### Acknowledgments
|
|
|
|
Special thanks go to Hugo Krawczyk and Chris Wood for helping to clarify discrepancies and making suggestions for
|
|
improving
|
|
this implementation. Additional credit goes to @daxpedda for adding no_std support, p256 support, and making other
|
|
general
|
|
improvements to the library.
|
|
|
|
License
|
|
-------
|
|
|
|
This project is dual-licensed under either the [MIT license](./LICENSE-MIT)
|
|
or the [Apache License, Version 2.0](./LICENSE-APACHE).
|
|
You may select, at your option, one of the above-listed licenses.
|