This release is a pre-release and may not be stable for production use.
Swarmauri Cipher Suites YubiKey
YubiKeyCipherSuite models a conservative YubiKey configuration that focuses on
PIV-backed signing and key transport. It exposes the algorithms commonly
available on non-FIPS YubiKey models without promising token-side bulk
encryption.
Features
- Normalizes YubiKey signing (
sign/verify) and key wrap (wrap/unwrap) operations. - Provides policy defaults for RSA-PSS and ECDSA, including default hash coupling and salt lengths.
- Surfaces dialect metadata so crypto providers can route requests to the PIV
driver (
piv:<alg>), including optional slot tagging. - Documents token policy (allowed curves, hash functions, attestation expectations) in a single place.
Installation
pip
pip install swarmauri_cipher_suite_yubikey
uv (dependency)
uv add swarmauri_cipher_suite_yubikey
uv (environment)
uv pip install swarmauri_cipher_suite_yubikey
Usage
1. Instantiate the suite
from swarmauri_cipher_suite_yubikey import YubiKeyCipherSuite
suite = YubiKeyCipherSuite(name="piv-default")
The suite accepts a friendly name so you can register multiple policy variants if you run different tokens.
2. Normalize a signing request
from swarmauri_cipher_suite_yubikey import YubiKeyCipherSuite
from swarmauri_core.cipher_suites.types import KeyRef
suite = YubiKeyCipherSuite(name="piv-default")
key = KeyRef(kid="sig-slot-9c", slot="9c")
descriptor = suite.normalize(op="sign", alg="ES256", key=key)
print(descriptor["mapped"]["provider"]) # -> "piv:ES256:slot=9c"
print(descriptor["params"]["hash"]) # -> "SHA256" (defaulted)
normalize returns a dictionary with the canonical algorithm, provider
identifier, defaulted parameter set, and suite policy. Crypto providers can
forward these values directly to the PIV driver without re-implementing
YubiKey-specific logic.
3. Wrap a key for transport
from swarmauri_cipher_suite_yubikey import YubiKeyCipherSuite
suite = YubiKeyCipherSuite(name="piv-default")
transport_descriptor = suite.normalize(op="wrap")
print(transport_descriptor["mapped"]["provider"]) # -> "piv:RSA-OAEP-256"
print(transport_descriptor["params"]) # -> {"mgf1Hash": "SHA256"}
When no algorithm is supplied, the suite picks sensible defaults (ES256 for
signing, RSA-OAEP-256 for key wrap) while still respecting the policy limits.
4. Inspect supported algorithms and features
from swarmauri_cipher_suite_yubikey import YubiKeyCipherSuite
suite = YubiKeyCipherSuite(name="piv-default")
for op, algs in suite.supports().items():
print(op, sorted(algs))
print(suite.features()["notes"][0])
These helpers allow orchestration layers to discover the token capabilities, render documentation, or validate client requests before invoking the hardware.
Entry Point
The suite registers under the swarmauri.cipher_suites entry point as
YubiKeyCipherSuite.
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_cipher_suite_yubikey 0.11.0.dev2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_cipher_suite_yubikey-0.11.0.dev2.tar.gz | 8.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_cipher_suite_yubikey-0.11.0.dev2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 17.8 kB
Release files / swarmauri_cipher_suite_yubikey-0.11.0.dev2.tar.gz
| Download URL | swarmauri_cipher_suite_yubikey-0.11.0.dev2.tar.gz |
|---|---|
| Size | 8.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e962577d186e973b33a2035d28841a85564aeba3af46c56cdd13486c64469d9f
|
|
BLAKE2b-256 checksum How to use checksums |
473c4f4d3d8d7d956870bcf4d6804027f704b0c672fbf4e361a9ca93d462733f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_cipher_suite_yubikey-0.11.0.dev2-py3-none-any.whl
| Download URL | swarmauri_cipher_suite_yubikey-0.11.0.dev2-py3-none-any.whl |
|---|---|
| Size | 9.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5459ad6503a8b59fec5b001b286b837936020f26299ded74e1d301b3380fbf47
|
|
BLAKE2b-256 checksum How to use checksums |
6ca9c376c1ad2fcf24c702d4cb0939e6b6ce1fe75afbed1c2cd686eeed7c219a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|