Files
opaque-vx/Cargo.toml
T
François Garillot 29ba1b93b5 Check for small subgroup components when using the EdwardsPoint group for the OPRF
A malicious attacker sending a small point could lead the server / user to leak private information.

The check avoiding mixed order points (rather than just small) is prohibitively expensive, and I don't know how an attacker would extract any data from that => we focus on a small order check.

Fixes #34.
2020-08-24 14:50:29 -04:00

47 lines
1.2 KiB
TOML

[package]
name = "opaque-ke"
version = "0.1.0"
repository = "https://github.com/novifinancial/opaque-ke"
keywords = ["cryptography", "crypto", "opaque", "passwords", "authentication"]
description = "An implementation of the OPAQUE password-authenticated key exchange protocol"
authors = ["Kevin Lewi <[email protected]>", "François Garillot <[email protected]>"]
license = "MIT"
edition = "2018"
readme = "README.md"
[features]
default = ["u64_backend"]
slow-hash = ["scrypt"]
bench = []
u64_backend = ["curve25519-dalek/u64_backend", "x25519-dalek/u64_backend"]
u32_backend = ["curve25519-dalek/u32_backend", "x25519-dalek/u32_backend"]
[dependencies]
curve25519-dalek = { version = "2.1.0", default-features = false, features = ["std"]}
digest = "0.9.0"
displaydoc = "0.1.7"
generic-array = "0.14.3"
hkdf = "0.9.0"
hmac = "0.8.1"
rand_core = "0.5.1"
scrypt = { version = "0.3.1", optional = true }
sha2 = "0.9.1"
thiserror = "1.0.20"
x25519-dalek = { version = "0.6.0", default-features = false, features = ["std"]}
zeroize = "1.1"
[dev-dependencies]
anyhow = "1.0.32"
base64 = "0.12.3"
criterion = "0.3.3"
hex = "0.4.2"
lazy_static = "1.4.0"
serde_json = "1.0.56"
proptest = "0.10.0"
rand = "0.7"
[[bench]]
name = "oprf"
harness = false
required-features = ["bench"]