Expand description
Sanctuary lane cryptography.
This module derives 48 bytes of key material from a user PIN, splits it into a 32-byte AEAD key plus a 16-byte volume tweak, and performs zero-heap encryption and decryption using deterministic, domain-separated nonces.
Structs§
- Sanctuary
KeyMaterial - Derived sanctuary key material.
Enums§
Constants§
- ARGO
N2_ M_ COST_ KIB - Argon2id defaults (memory-hard KDF; ADR D1). 64 MiB, 3 passes, 1 lane. Memory-hardness is what PBKDF2 lacks — it blunts GPU/ASIC offline brute-force of a weak PIN, the vault’s real weak link.
- ARGO
N2_ P_ COST - ARGO
N2_ T_ COST - DEFAULT_
PBKD F2_ ITERATIONS - SANCTUARY_
CIPHER_ KEY_ BYTES - SANCTUARY_
GCM_ NONCE_ BYTES - SANCTUARY_
KEY_ MATERIAL_ BYTES - SANCTUARY_
TAG_ BYTES - SANCTUARY_
TWEAK_ BYTES - SANCTUARY_
XCHACHA_ NONCE_ BYTES
Functions§
- decrypt_
sanctuary_ chunk - Copy ciphertext into a caller-supplied output buffer, then decrypt in place.
- decrypt_
sanctuary_ chunk_ in_ place - Decrypt the caller-owned buffer in place without heap allocation.
- derive_
chacha_ nonce - Derive a 96-bit nonce for ChaCha20-Poly1305.
- derive_
chunk_ nonce - Derive a 96-bit nonce for AES-256-GCM.
- derive_
lane_ cipher_ key - Convenience wrapper for call sites that only need the 32-byte cipher key.
- derive_
sanctuary_ key_ material - Derive 48 bytes of sanctuary key material from a PIN and salt.
- derive_
sanctuary_ key_ material_ argon2 - Derive the 48-byte sanctuary key material with Argon2id (memory-hard), same output layout as
derive_sanctuary_key_material:[0..32]cipher key,[32..48]volume tweak. - derive_
xchacha_ nonce - Derive a 192-bit nonce for XChaCha20-Poly1305.
- encrypt_
sanctuary_ chunk - Copy plaintext into a caller-supplied output buffer, then encrypt in place.
- encrypt_
sanctuary_ chunk_ in_ place - Encrypt the caller-owned buffer in place without heap allocation.