An AEAD construction per RFC7539
Project description
About
RFC7539 is an IETF specification for an authenticated encryption algorithm that will be incorporated into TLSv1.3. It is comprised of a stream cipher (ChaCha20) and a MAC (Poly1305), both written by Daniel J. Bernstein. The C implementations for both of these primitives are taken from the NSS library (the reason being that openSSL has license incompatibilities and also requires the openSSL headers which is more overhead than we need to implement these fairly basic primitives). The NSS code has been slightly modified to account for the 96 bit nonce and 32 bit counter specified in the RFC.
Installation
Method 1
pip install rfc7539
Method 2
git clone https://github.com/AntonKueltz/rfc7539.git
cd rfc7539
python setup.py install
Usage
You should use the authenticated encryption mode unless you really need to use one of the primitives by itself:
from rfc7539 import aead
from os import urandom
key = urandom(32) # key is 32 bytes
nonce = b'thisisanonce' # nonce is 12 bytes (DO NOT REUSE A NONCE WITH THE SAME KEY)
message = b'Some message to be encrypted'
additional_data = b'Some additional data' # this will not be encrypted but will be verified for integrity
# encryption
ciphertext, mac = aead.encrypt_and_tag(key, nonce, message, additional_data)
# decryption (which yields plaintext == message)
plaintext = aead.verify_and_decrypt(key, nonce, ciphertext, mac, additional_data)
Note that all operations in this package work on bytes. You’ll need to call e.g. encode()
on strings
before passing them as arguments.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distributions
Hashes for rfc7539-2.0.0-cp38-cp38-macosx_10_14_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | bb4e96404fa61020590182b82060887f717c16e87b1e670de99a4a19c294fcc8 |
|
MD5 | 15e5956168d2f6d2e49552d7c249e295 |
|
BLAKE2b-256 | 72a45baa2f66e84b480733840737e32b4fe88c9c6e6703fc71c8024ccc9f3945 |
Hashes for rfc7539-2.0.0-cp37-cp37m-macosx_10_14_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 0d8a055d11032c6a167821b28a86bb3e50c150c4560a765a7fecadd984afbf4e |
|
MD5 | 10605413a02a57665058c3c839578814 |
|
BLAKE2b-256 | 4c27df5c3bcfb816c9a1286d8a779ff7b6dfa25c6e6b674e74664e00e0a9d781 |
Hashes for rfc7539-2.0.0-cp36-cp36m-macosx_10_14_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 1bc1c2e3ef7cadfca4d8c4b9cee6b130f758e4ebd3549d50a47eb8286ff0ff10 |
|
MD5 | 525e751580913a74e866ae8fbd755c95 |
|
BLAKE2b-256 | 9e2ddb28cbda65da8007a979197a09cb5ae694e6259e3313a6009b92b9573e68 |
Hashes for rfc7539-2.0.0-cp35-cp35m-macosx_10_14_x86_64.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | fe2f6038dddd300f42412c305a09f645a26e1317517c6de190200357d2110892 |
|
MD5 | af95380e9451e680d55499c10d8cb34e |
|
BLAKE2b-256 | 104d7709a9ff06d5120d43369a26bf4f2a5baebcdc7b6bfcddb0ed6206c7a6c5 |