This release is a pre-release and may not be stable for production use.
swarmauri_crypto_ecdh_es_a128kw
ECDH-ES+A128KW key wrapping provider for Swarmauri.
Highlights
- Implements the JSON Web Encryption ECDH-ES key agreement combined with AES Key Wrap using a 128-bit KEK (
ECDH-ES+A128KW). - Accepts
KeyRefobjects whosepublicattribute carries an EC public key in PEM format for wrapping and whosematerialattribute provides the corresponding private key for unwrapping. - Derives a one-time key-encryption key via Concat KDF with SHA-256 and serializes results as JSON containing the ephemeral public key (
epk) and wrapped DEK (kw), both Base64URL encoded. - Generates a fresh 16-byte DEK when one is not provided so you can delegate symmetric key generation to the provider.
Installation
Choose the tool that matches your workflow:
# pip
pip install swarmauri_crypto_ecdh_es_a128kw
# Poetry
poetry add swarmauri_crypto_ecdh_es_a128kw
# uv
uv add swarmauri_crypto_ecdh_es_a128kw
Quickstart
The example below creates a recipient EC key pair, wraps a deterministic 128-bit DEK, and then unwraps it again to demonstrate the round trip. Run it with python quickstart.py or paste it into a REPL.
import asyncio
from cryptography.hazmat.primitives import serialization
from cryptography.hazmat.primitives.asymmetric import ec
from swarmauri_core.crypto.types import ExportPolicy, KeyRef, KeyType, KeyUse
from swarmauri_crypto_ecdh_es_a128kw import ECDHESA128KWCrypto
def make_recipient_key() -> KeyRef:
private_key = ec.generate_private_key(ec.SECP256R1())
public_key = private_key.public_key()
return KeyRef(
kid="recipient-key",
version=1,
type=KeyType.EC,
uses=(KeyUse.WRAP, KeyUse.UNWRAP),
export_policy=ExportPolicy.SECRET_WHEN_ALLOWED,
material=private_key.private_bytes(
encoding=serialization.Encoding.PEM,
format=serialization.PrivateFormat.PKCS8,
encryption_algorithm=serialization.NoEncryption(),
),
public=public_key.public_bytes(
encoding=serialization.Encoding.PEM,
format=serialization.PublicFormat.SubjectPublicKeyInfo,
),
)
async def main() -> None:
crypto = ECDHESA128KWCrypto()
recipient = make_recipient_key()
dek = b"0123456789ABCDEF" # 16 byte content encryption key
wrapped = await crypto.wrap(recipient, dek=dek)
recovered = await crypto.unwrap(recipient, wrapped)
print("Wrapped payload:", wrapped.wrapped.decode("utf-8"))
assert recovered == dek
if __name__ == "__main__":
asyncio.run(main())
What to expect
wrapderives an ephemeral ECDH shared secret with the recipient public key, hashes it with Concat KDF (SHA-256) to produce a 128-bit KEK, and AES-KW wraps the provided DEK.- The returned
WrappedKeystores a JSON document containing the ephemeral public key (epk) and the wrapped DEK (kw), both Base64URL encoded. unwraprepeats the derivation using the recipient private key (KeyRef.material) and returns the original DEK bytes.
License
swarmauri_crypto_ecdh_es_a128kw is licensed under the Apache License 2.0. See the LICENSE file for details.
Entry point
The provider is registered under the swarmauri.cryptos entry point as ECDHESA128KWCrypto.
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_crypto_ecdh_es_a128kw 0.11.0.dev2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_crypto_ecdh_es_a128kw-0.11.0.dev2.tar.gz | 8.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_crypto_ecdh_es_a128kw-0.11.0.dev2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.0 kB
Release files / swarmauri_crypto_ecdh_es_a128kw-0.11.0.dev2.tar.gz
| Download URL | swarmauri_crypto_ecdh_es_a128kw-0.11.0.dev2.tar.gz |
|---|---|
| Size | 8.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7ec499a8951834280743751d89157ffbeefb3f4f623cf79198679fc8b6d9b9eb
|
|
BLAKE2b-256 checksum How to use checksums |
16767e83e4674fc44aaffd94ffc4c3bb264a3db025c5b0af7b0196ada551bceb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_crypto_ecdh_es_a128kw-0.11.0.dev2-py3-none-any.whl
| Download URL | swarmauri_crypto_ecdh_es_a128kw-0.11.0.dev2-py3-none-any.whl |
|---|---|
| Size | 9.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1610a2fd673c8cc8350e45064d4eec22127f3a17c6ad6cb4e3f6e30ae879eaf1
|
|
BLAKE2b-256 checksum How to use checksums |
a5f67b0f975048dc306e70203a81dea46d5c702172fa254e81241c5bcf24a3f8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|