Skip to main content

Cryptographic utilities for ONDC protocol - signing, verification, encryption and authorization header management

Project description

ONDC Cryptic Utils

A Python library providing cryptographic utilities for the Open Network for Digital Commerce (ONDC) protocol. This library implements the cryptographic operations required for secure communication within the ONDC ecosystem, including message signing, signature verification, encryption/decryption, and authorization header management.

Features

Core Cryptographic Operations

  • Ed25519 Digital Signatures: Generate and verify digital signatures using Ed25519 algorithm
  • X25519 Key Exchange: Implement key exchange for secure communication
  • AES Encryption: Message encryption and decryption using AES in ECB mode
  • BLAKE2b Hashing: Generate message digests using BLAKE2b-512

ONDC Protocol Support

  • Key Pair Generation: Generate Ed25519 signing keys and X25519 encryption keys
  • Authorization Headers: Create and verify ONDC-compliant authorization headers
  • Message Signing: Sign request payloads according to ONDC specifications
  • Signature Verification: Validate incoming signed messages and headers
  • Timestamp Validation: Verify message freshness using created/expires timestamps

Installation

Install the package using pip:

pip install ondc-cryptic-utils

Or install in development mode:

pip install -e .

Quick Start

Basic Usage

from ondc_cryptic_utils import OndcCrypticUtil, OndcAuthUtil

# Initialize the cryptographic utility
crypto_util = OndcCrypticUtil(
    signing_private_key="your_signing_private_key",
    signing_public_key="your_signing_public_key",
    encryption_private_key="your_encryption_private_key",
    encryption_public_key="your_encryption_public_key"
)

# Generate new key pairs
key_pairs = OndcCrypticUtil.generate_key_pairs()
print("Generated keys:", key_pairs)

Creating Authorization Headers

from ondc_cryptic_utils import OndcAuthUtil
import json

# Initialize auth utility
auth_util = OndcAuthUtil()

# Create authorization header for a request
message = {"context": {"action": "search"}, "message": {}}
subscriber_id = "your_subscriber_id"
unique_key_id = "your_unique_key_id"

auth_header = auth_util.create_authorization_header(
    subscriber_id=subscriber_id,
    unique_key_id=unique_key_id,
    message=message,
    expires=3600  # Optional: expires in seconds
)

print("Authorization header:", auth_header)

Verifying Authorization Headers

# Verify an incoming authorization header
auth_header = 'Signature keyId="subscriber|key|ed25519",...'
request_body = {"context": {"action": "search"}}

is_valid, message = auth_util.verify_authorisation_header(auth_header, request_body)
if is_valid:
    print("Authorization verified successfully")
else:
    print(f"Authorization failed: {message}")

Message Encryption and Decryption

# Encrypt a message
message = "Hello, ONDC!"
encrypted = crypto_util.encrypt_message(message)
print("Encrypted:", encrypted)

# Decrypt the message
decrypted = crypto_util.decrypt_message(
    encrypted,
    encryption_private_key="recipient_private_key",
    encryption_public_key="sender_public_key"
)
print("Decrypted:", decrypted)

Configuration

The library uses a settings class for default key configuration:

class settings:
    ONDC_SIGNING_PUBLIC_KEY = "your_default_signing_public_key"
    ONDC_SIGNING_PRIVATE_KEY = "your_default_signing_private_key"
    ONDC_ENCRYPTION_PUBLIC_KEY = "your_default_encryption_public_key"
    ONDC_ENCRYPTION_PRIVATE_KEY = "your_default_encryption_private_key"

You can override these by passing keys directly to the OndcCrypticUtil constructor.

Dependencies

  • pycryptodomex: AES encryption/decryption operations
  • cryptography: X25519 key exchange and serialization
  • PyNaCl: Ed25519 signing, BLAKE2b hashing, and Base64 encoding

Compliance

This library is based on the official ONDC reference implementation for cryptographic utilities and follows the ONDC protocol specifications for:

  • Digital signature format and verification
  • Authorization header structure
  • Message encryption standards
  • Key generation and management

Testing

To run the tests, install the package in development mode and run:

python3 -m unittest discover tests

Contributing

Contributions are welcome! Please ensure all changes maintain compatibility with the ONDC protocol specifications.

License

This project is licensed under the MIT License.

References

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ondc_cryptic_utils-0.0.1.tar.gz (8.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ondc_cryptic_utils-0.0.1-py3-none-any.whl (7.3 kB view details)

Uploaded Python 3

File details

Details for the file ondc_cryptic_utils-0.0.1.tar.gz.

File metadata

  • Download URL: ondc_cryptic_utils-0.0.1.tar.gz
  • Upload date:
  • Size: 8.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.7

File hashes

Hashes for ondc_cryptic_utils-0.0.1.tar.gz
Algorithm Hash digest
SHA256 899563143a0afa30f7ef9affdfb17648333ed9e438f745392afc67e9410c92ae
MD5 e7dcb75f758b0cd959a62f92e9eeac79
BLAKE2b-256 0ad80f9e502688fee5f370099809546b0f7a51194cd4cc515c32bb228a063ce9

See more details on using hashes here.

File details

Details for the file ondc_cryptic_utils-0.0.1-py3-none-any.whl.

File metadata

File hashes

Hashes for ondc_cryptic_utils-0.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 134b6754017c0f54b3acb7851ee1b7c3202b28936848b3e16e60d44e16650583
MD5 df6a96f1c409fa33c2ca6ca458d6c717
BLAKE2b-256 d5ad4249ce3f485ce24fdcffee74fffbfcb6604b7fae1f93b57405a19cf79efe

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page