pub struct EncryptionKey(/* private fields */);Expand description
A public-encryption.encryption-key: the public half of asymmetric
encryption — encryption and wrapping, secret-free to hold.
Operations take and return whole byte buffers rather than
DataSources: the plaintext is bounded by the key (for RSA-OAEP, the
modulus length minus the padding overhead), so there is nothing
unbounded to stream. Encryption is randomized — encrypting one
plaintext twice yields different ciphertexts, and both decrypt.
Implementations§
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub fn from_raw(raw: EncryptionKey) -> Self
pub fn from_raw(raw: EncryptionKey) -> Self
Wrap a raw encryption-key resource.
Sourcepub fn as_raw(&self) -> &EncryptionKey
pub fn as_raw(&self) -> &EncryptionKey
Borrow the raw encryption-key resource.
Sourcepub fn into_raw(self) -> EncryptionKey
pub fn into_raw(self) -> EncryptionKey
Unwrap into the raw encryption-key resource.
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub async fn encrypt(
&self,
label: Option<&[u8]>,
plaintext: impl Into<Vec<u8>>,
) -> Result<Vec<u8>, Error>
pub async fn encrypt( &self, label: Option<&[u8]>, plaintext: impl Into<Vec<u8>>, ) -> Result<Vec<u8>, Error>
Encrypt a plaintext bounded by the key. label is optional context
bound into the padding: decryption succeeds only under the same
label (WebCrypto’s RsaOaepParams.label). A plaintext above the
key’s bound fails Error::Extension (origin "polymorph:webcrypto",
name "message-too-long") — the signal to switch to hybrid
wrapping: encrypt a symmetric key, wrap the payload under it.
Sourcepub fn algorithm_name(&self) -> String
pub fn algorithm_name(&self) -> String
The registry name of the key’s algorithm family, e.g. "RSA-OAEP"
— WebCrypto’s KeyAlgorithm.name.
Sourcepub fn algorithm_hash(&self) -> Option<String>
pub fn algorithm_hash(&self) -> Option<String>
The registry name of the digest bound at mint, e.g. "SHA-256".
Sourcepub fn algorithm_length(&self) -> Option<u32>
pub fn algorithm_length(&self) -> Option<u32>
The key’s length in bits for algorithms parameterized by one — the
RSA modulus length (WebCrypto’s RsaKeyAlgorithm.modulusLength).
Sourcepub fn algorithm_public_exponent(&self) -> Option<Vec<u8>>
pub fn algorithm_public_exponent(&self) -> Option<Vec<u8>>
The public exponent’s big-endian bytes (WebCrypto’s
RsaKeyAlgorithm.publicExponent; [1, 0, 1] for 65537).
Sourcepub async fn export_key_raw(&self) -> Result<Vec<u8>, Error>
pub async fn export_key_raw(&self) -> Result<Vec<u8>, Error>
The public key material, in the minting interface’s documented
public format. Algorithms without a raw public form (the RSA
family) fail Error::Unsupported.
There is no extractability gate on public material, so this never
fails Error::NotExtractable — but it can fail Error::Other:
a provider may hold the key as a handle it can use but not read
(see VerifyingKey::export_key_raw).
Sourcepub async fn export_key_spki(&self) -> Result<Vec<u8>, Error>
pub async fn export_key_spki(&self) -> Result<Vec<u8>, Error>
The public key as an X.509 SubjectPublicKeyInfo (DER), with the
same handle-not-bytes fallibility as
export_key_raw.
Sourcepub async fn export_key_jwk(&self) -> Result<String, Error>
pub async fn export_key_jwk(&self) -> Result<String, Error>
The public key as a JWK (JSON text), with the same fallibility as
export_key_raw.