Upgrade all core cryptographic dependencies to their latest versions: Dependencies: - digest: 0.10 to 0.11 - elliptic-curve: 0.13 to 0.14 - hkdf: 0.12 to 0.13 - hmac: 0.12 to 0.13 - rand: 0.8 to 0.10 - rand_chacha: 0.3 to 0.10 - sha2: 0.10 to 0.11 - getrandom: 0.2 to 0.4 (WASM) - ml-kem: 0.3.0-rc.0 to 0.3 - ecdsa: 0.16 to 0.17.0-rc.23 - rfc6979: 0.4 to 0.6 (now internal to ecdsa) - p256/p384/p521: 0.13 to 0.14.0-rc.15 - curve25519-dalek: 4 to 5.0.0-rc - ed25519-dalek: 2 to 3.0.0-rc - cryptoki: 0.9 to 0.12 - rustyline: 17 to 18 - scrypt: 0.11 to 0.12 - voprf replaced by voprf-vx 1.0.0-pre.0 Migration changes: - generic-array 0.14 to 1.4 with hybrid-array 0.4 interop - ArrayLength<u8> to ArrayLength (generic-array 1.x) - Added ConcatExt trait to disambiguate from [T]::concat - Replaced Hmac with SimpleHmac for digest 0.11 compatibility - Added OutputSize<H>: ArrayLength bounds throughout Hash trait - Converted hybrid_array::Array between GenericArray at API boundaries - Updated GroupEncoding Repr bound to hybrid_array::Array - ECDSA sign now uses ecdsa::hazmat::sign_prehashed_rfc6979 - Removed direct rfc6979 dependency (handled by ecdsa internally) - Replaced bincode with postcard for no_std serialization - Re-exported hybrid_array from crate root Other changes: - Renamed crate to opaque-vx - Increased MSRV to 1.89 - Added cryptography to Cargo.toml categories - Removed Facebook-specific contributions from CONTRIBUTING.md - Removed v3 to v4 migration test - Removed unstable rustfmt configurations for stable compatibility Reviewed-on: #1 Co-authored-by: UneBaguette <[email protected]> Co-committed-by: UneBaguette <[email protected]>
The OPAQUE key exchange protocol
OPAQUE is an augmented password-authenticated key exchange protocol. It allows a client to authenticate to a server using a password, without ever having to expose the plaintext password to the server.
This implementation is based on RFC 9807.
This is a fork of facebook/opaque-ke maintained by VexaHub, targeting the latest RustCrypto ecosystem.
Background
Augmented Password Authenticated Key Exchange (aPAKE) protocols are designed to provide password authentication and mutually authenticated key exchange without relying on PKI (except during user/password registration) and without disclosing passwords to servers or other entities other than the client machine.
OPAQUE is a PKI-free aPAKE that is secure against pre-computation attacks and capable of using a secret salt.
Documentation
The API can be found here along with an example for usage. More examples can be found in the examples directory.
Installation
Add the following line to the dependencies of your Cargo.toml:
opaque-ke = { package = "opaque-ke-vx", version = "1.0.0-pre.0" }
Minimum Supported Rust Version
Rust 1.89 or higher.
Audit
This library was audited by NCC Group in June of 2021. The audit was sponsored by WhatsApp for its use in enabling end-to-end encrypted backups.
The audit found issues in release v0.5.0, and the fixes were subsequently incorporated into release v1.2.0. See
the full audit report here.
Resources
- OPAQUE academic publication, including formal definitions and a proof of security
- RFC 9807, containing a detailed (byte-level) specification for OPAQUE
- "Let's talk about PAKE", an introductory blog post written by Matthew Green that covers OPAQUE
- @serenity-kit/opaque, a WebAssembly package for this library
- opaque-wasm, a WebAssembly package for this library. A comparison between
@serenity-kit/opaqueandopaque-wasmcan be found here - react-native-opaque, a React Native package for this library
matching the API of
@serenity-kit/opaque
Contributors
This fork is maintained by VexaHub.
The original authors are Kevin Lewi (@kevinlewi) and François Garillot (@huitseeker). To learn more about contributing to this project, see this document.
Acknowledgments
Special thanks go to Hugo Krawczyk and Chris Wood for helping to clarify discrepancies and making suggestions for improving this implementation. Additional credit goes to @daxpedda for adding no_std support, p256 support, and making other general improvements to the library.
License
This project is dual-licensed under either the MIT license or the Apache License, Version 2.0. You may select, at your option, one of the above-listed licenses.