This release is a pre-release and may not be stable for production use.
Swarmauri Crypto NaCl PKCS#11
swarmauri_crypto_nacl_pkcs11 is a hybrid crypto provider that combines PyNaCl for X25519 sealed-box operations with python-pkcs11 for AES key wrapping. The provider implements the CryptoBase contract and is discoverable via the swarmauri.cryptos entry-point as NaClPkcs11Crypto.
Supported operations
- AES-GCM authenticated encryption via
encrypt/decryptusing symmetricKeyRefmaterial that is exactly 16, 24, or 32 bytes long. - AES Key Wrap (AES-KW) via
wrap/unwrapagainst an HSM-protected key. The PKCS#11 session is resolved from theKeyRef.tags(module,slot_label,user_pin,label) or the environment variablesPKCS11_MODULE,PKCS11_SLOT_LABEL,PKCS11_USER_PIN, andPKCS11_KEK_LABEL. - X25519 sealed boxes via
seal/unsealandencrypt_for_many, enabling single or multi-recipient payload distribution. When additional authenticated data (AAD) is supplied the envelope is rebound with AES-GCM before delivery.
Installation
Choose the workflow that matches your project:
pip install swarmauri_crypto_nacl_pkcs11
poetry add swarmauri_crypto_nacl_pkcs11
uv add swarmauri_crypto_nacl_pkcs11
Usage
All cryptographic methods are asynchronous. The quick-start example below performs an AES-GCM round trip using a 256-bit symmetric key.
import asyncio
from swarmauri_crypto_nacl_pkcs11 import NaClPkcs11Crypto
from swarmauri_core.crypto.types import ExportPolicy, KeyRef, KeyType, KeyUse
async def main() -> None:
crypto = NaClPkcs11Crypto()
symmetric_key = KeyRef(
kid="sym1",
version=1,
type=KeyType.SYMMETRIC,
uses=(KeyUse.ENCRYPT, KeyUse.DECRYPT),
export_policy=ExportPolicy.SECRET_WHEN_ALLOWED,
material=b"\x00" * 32,
)
ciphertext = await crypto.encrypt(symmetric_key, b"hello")
plaintext = await crypto.decrypt(symmetric_key, ciphertext)
assert plaintext == b"hello"
asyncio.run(main())
Sealed box key exchange
seal and encrypt_for_many expect X25519 KeyRef instances. Provide the public key bytes via KeyRef.public for recipients and the private key bytes via KeyRef.material for unsealing. Each recipient receives an opaque sealed payload generated with nacl.public.SealedBox.
PKCS#11-backed key wrapping
wrap and unwrap require a key-encryption-key (KEK) stored in the configured PKCS#11 slot. Supply connection details through KeyRef.tags or environment variables as described above. The wrapped material is returned as a WrappedKey using the AES-KW algorithm.
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_crypto_nacl_pkcs11 0.11.0.dev2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_crypto_nacl_pkcs11-0.11.0.dev2.tar.gz | 9.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_crypto_nacl_pkcs11-0.11.0.dev2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 20.0 kB
Release files / swarmauri_crypto_nacl_pkcs11-0.11.0.dev2.tar.gz
| Download URL | swarmauri_crypto_nacl_pkcs11-0.11.0.dev2.tar.gz |
|---|---|
| Size | 9.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6a311e8192ebf3f6f92ff8b2feb0192a7551a8c0a9f74aaffaca428f50507cfe
|
|
BLAKE2b-256 checksum How to use checksums |
fb4e424626daf909b1484c698aa0f1b8f90e77947f17fe75c8273f1e1be8160d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_crypto_nacl_pkcs11-0.11.0.dev2-py3-none-any.whl
| Download URL | swarmauri_crypto_nacl_pkcs11-0.11.0.dev2-py3-none-any.whl |
|---|---|
| Size | 10.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
44a075f55656947496ff8e15c64da390598f5ed9f515a80a39a4b062c2bb4c11
|
|
BLAKE2b-256 checksum How to use checksums |
b38768b1969ab1b4048464d2fff7d7c82498b6b5021576e6f7849077b97b8ba6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|