This release is a pre-release and may not be stable for production use.
Swarmauri Crypto Paramiko
Paramiko-backed crypto provider implementing the ICrypto contract via
CryptoBase. Built on top of paramiko and
cryptography, it exposes an asynchronous API for
several cryptographic primitives using OpenSSH-formatted public keys and
PEM-encoded private keys supplied through KeyRef objects.
Features
- AES-256-GCM symmetric encrypt/decrypt (16/24/32 byte keys)
- RSA-OAEP(SHA-256) wrap/unwrap for OpenSSH RSA key pairs
- AES-256-GCM key wrap/unwrap when the KEK is symmetric
- RSA-OAEP(SHA-256) sealing for small payloads
- Multi-recipient hybrid envelopes using OpenSSH public keys
Keys are represented by KeyRef objects. Public keys should be provided in
OpenSSH format via KeyRef.public, while private keys are supplied as
PEM-encoded bytes in KeyRef.material. RSA sealing is limited to inputs no
larger than the modulus-dependent RSA-OAEP bound (`modulus_bytes - 2 * hash_len
- 2`). For larger payloads use the hybrid envelope mode instead.
Installation
Choose the tool that matches your workflow:
# pip
pip install swarmauri_crypto_paramiko
# Poetry
poetry add swarmauri_crypto_paramiko
# uv
uv add swarmauri_crypto_paramiko
Usage
Symmetric AEAD Encryption
from swarmauri_crypto_paramiko import ParamikoCrypto
from swarmauri_core.crypto.types import KeyRef, KeyType, KeyUse, ExportPolicy
crypto = ParamikoCrypto()
sym = KeyRef(
kid="sym1",
version=1,
type=KeyType.SYMMETRIC,
uses=(KeyUse.ENCRYPT, KeyUse.DECRYPT),
export_policy=ExportPolicy.SECRET_WHEN_ALLOWED,
material=b"\x00" * 32,
)
ct = await crypto.encrypt(sym, b"hello")
pt = await crypto.decrypt(sym, ct)
RSA Key Wrapping/Unwrapping
import paramiko
from cryptography.hazmat.primitives import serialization
from swarmauri_core.crypto.types import KeyRef, KeyType, KeyUse, ExportPolicy
crypto = ParamikoCrypto()
key = paramiko.RSAKey.generate(2048)
pub_line = f"{key.get_name()} {key.get_base64()}\n".encode()
priv_pem = key.key.private_bytes(
encoding=serialization.Encoding.PEM,
format=serialization.PrivateFormat.PKCS8,
encryption_algorithm=serialization.NoEncryption(),
)
recipient = KeyRef(
kid="rsa1",
version=1,
type=KeyType.RSA,
uses=(KeyUse.WRAP, KeyUse.UNWRAP),
export_policy=ExportPolicy.PUBLIC_ONLY,
public=pub_line,
material=priv_pem,
)
wrapped = await crypto.wrap(recipient)
unwrapped = await crypto.unwrap(recipient, wrapped)
To wrap with a symmetric key-encryption key instead, provide the AES key bytes
in KeyRef.material and set wrap_alg="AES-256-GCM":
sym_kek = KeyRef(
kid="kek1",
version=1,
type=KeyType.SYMMETRIC,
uses=(KeyUse.WRAP, KeyUse.UNWRAP),
export_policy=ExportPolicy.SECRET_WHEN_ALLOWED,
material=b"\x01" * 32,
)
wrapped = await crypto.wrap(sym_kek, wrap_alg="AES-256-GCM")
plaintext_key = await crypto.unwrap(sym_kek, wrapped)
RSA Sealing for Small Payloads
# Using the `recipient` defined above
sealed = await crypto.seal(recipient, b"tiny secret")
plaintext = await crypto.unseal(recipient, sealed)
Hybrid Envelope for Multiple Recipients
env = await crypto.encrypt_for_many([recipient], b"secret")
Calling encrypt_for_many without overrides produces an AES-256-GCM ciphertext
shared by every recipient, while env.recipients holds RSA-OAEP-wrapped
session keys. Use enc_alg="RSA-OAEP-SHA256-SEAL" to emit individual RSA-OAEP
sealed payloads instead of a shared ciphertext when the plaintext fits within
the sealing size limit.
Entry point
The provider is registered under the swarmauri.cryptos entry-point as ParamikoCrypto.
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_crypto_paramiko 0.11.0.dev2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_crypto_paramiko-0.11.0.dev2.tar.gz | 11.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_crypto_paramiko-0.11.0.dev2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 23.3 kB
Release files / swarmauri_crypto_paramiko-0.11.0.dev2.tar.gz
| Download URL | swarmauri_crypto_paramiko-0.11.0.dev2.tar.gz |
|---|---|
| Size | 11.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
069d08dc2ff193e8862b6d5ba19741a02034ad5cb304098403a46a1b247234f6
|
|
BLAKE2b-256 checksum How to use checksums |
e765f929171ed0ec6803eb1ea83b69179852bd0cc57917a1c685cbdc31beec15
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_crypto_paramiko-0.11.0.dev2-py3-none-any.whl
| Download URL | swarmauri_crypto_paramiko-0.11.0.dev2-py3-none-any.whl |
|---|---|
| Size | 12.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7b4209422a9fdf886e18e9d7ff38d44ddc7755eda67cd16d00b127e4cf540f41
|
|
BLAKE2b-256 checksum How to use checksums |
2c146c6547855f4095fa0dd481371e869069fe30feccb227384bb6ab954ecbde
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|