2.6. Cryptographic primitives
Native OpenSSL cryptographic primitives. Enable dasCrypto with OpenSSL 3 or newer; this module is unavailable in Emscripten. Byte inputs are bounded to 16 MiB unless a narrower limit is stated. Output-producing functions clear their output on failure and allow output/input aliasing. Callers own key storage and protocol validation.
2.6.1. Randomness and comparison
- crypto_equal(a: array<uint8>; b: array<uint8> ): bool
Compares equal-length byte arrays in constant time. Returns false for unequal lengths or inputs over 16 MiB; the length is not secret.
- Arguments:
a : array<uint8> implicit
b : array<uint8> implicit
- crypto_random_bytes(count: int; output: array<uint8> ): bool
Fills output with count cryptographically secure random bytes. Count must be between 0 and 4096 inclusive. Returns false and clears output on invalid count or generator failure.
- Arguments:
count : int
output : array<uint8> implicit
2.6.2. Message authentication
- crypto_hmac_sha1(key: array<uint8>; message: array<uint8>; output: array<uint8> ): bool
Computes a 20-byte HMAC-SHA1 for protocols requiring it, such as TOTP. Returns false and clears output for oversized input or cryptographic failure.
- Arguments:
key : array<uint8> implicit
message : array<uint8> implicit
output : array<uint8> implicit
- crypto_hmac_sha256(key: array<uint8>; message: array<uint8>; output: array<uint8> ): bool
Computes a 32-byte HMAC-SHA256 from key and message. Returns false and clears output for oversized input or cryptographic failure.
- Arguments:
key : array<uint8> implicit
message : array<uint8> implicit
output : array<uint8> implicit
2.6.3. Authenticated encryption
- crypto_aes256_gcm_open(key: array<uint8>; nonce: array<uint8>; ciphertext: array<uint8>; aad: array<uint8>; output: array<uint8> ): bool
Authenticates and decrypts ciphertext followed by its 16-byte AES-256-GCM tag. Key is 32 bytes and nonce is 12 bytes. Returns false and clears output for invalid sizes, tag or AAD; unauthenticated plaintext is never published.
- Arguments:
key : array<uint8> implicit
nonce : array<uint8> implicit
ciphertext : array<uint8> implicit
aad : array<uint8> implicit
output : array<uint8> implicit
- crypto_aes256_gcm_seal(key: array<uint8>; nonce: array<uint8>; plain: array<uint8>; aad: array<uint8>; output: array<uint8> ): bool
Encrypts and authenticates plain with AES-256-GCM. Key is 32 bytes and nonce is 12 bytes; never reuse a nonce with the same key. Output contains ciphertext followed by a 16-byte tag. AAD is authenticated but not encrypted. Returns false and clears output on failure.
- Arguments:
key : array<uint8> implicit
nonce : array<uint8> implicit
plain : array<uint8> implicit
aad : array<uint8> implicit
output : array<uint8> implicit
2.6.4. Signature verification
- crypto_verify_rsa_sha256(modulus: array<uint8>; exponent: array<uint8>; message: array<uint8>; signature: array<uint8> ): bool
Verifies an RSA PKCS#1 v1.5 SHA-256 signature. Modulus and exponent are unsigned big-endian bytes; modulus is 2048–8192 bits and exponent is at most 8 bytes. Signature length equals the modulus byte length. Returns false for invalid inputs or signature. This does not parse certificates or establish trust in the supplied key.
- Arguments:
modulus : array<uint8> implicit
exponent : array<uint8> implicit
message : array<uint8> implicit
signature : array<uint8> implicit