2.6. Cryptographic primitives

Native OpenSSL cryptographic primitives. Enable dasCrypto with OpenSSL 3 or newer; this module is unavailable in Emscripten. Byte inputs are bounded to 16 MiB unless a narrower limit is stated. Output-producing functions clear their output on failure and allow output/input aliasing. Callers own key storage and protocol validation.

2.6.1. Randomness and comparison

crypto_equal(a: array<uint8>; b: array<uint8> ): bool

Compares equal-length byte arrays in constant time. Returns false for unequal lengths or inputs over 16 MiB; the length is not secret.

Arguments:
  • a : array<uint8> implicit

  • b : array<uint8> implicit

crypto_random_bytes(count: int; output: array<uint8> ): bool

Fills output with count cryptographically secure random bytes. Count must be between 0 and 4096 inclusive. Returns false and clears output on invalid count or generator failure.

Arguments:
  • count : int

  • output : array<uint8> implicit

2.6.2. Message authentication

crypto_hmac_sha1(key: array<uint8>; message: array<uint8>; output: array<uint8> ): bool

Computes a 20-byte HMAC-SHA1 for protocols requiring it, such as TOTP. Returns false and clears output for oversized input or cryptographic failure.

Arguments:
  • key : array<uint8> implicit

  • message : array<uint8> implicit

  • output : array<uint8> implicit

crypto_hmac_sha256(key: array<uint8>; message: array<uint8>; output: array<uint8> ): bool

Computes a 32-byte HMAC-SHA256 from key and message. Returns false and clears output for oversized input or cryptographic failure.

Arguments:
  • key : array<uint8> implicit

  • message : array<uint8> implicit

  • output : array<uint8> implicit

2.6.3. Authenticated encryption

crypto_aes256_gcm_open(key: array<uint8>; nonce: array<uint8>; ciphertext: array<uint8>; aad: array<uint8>; output: array<uint8> ): bool

Authenticates and decrypts ciphertext followed by its 16-byte AES-256-GCM tag. Key is 32 bytes and nonce is 12 bytes. Returns false and clears output for invalid sizes, tag or AAD; unauthenticated plaintext is never published.

Arguments:
  • key : array<uint8> implicit

  • nonce : array<uint8> implicit

  • ciphertext : array<uint8> implicit

  • aad : array<uint8> implicit

  • output : array<uint8> implicit

crypto_aes256_gcm_seal(key: array<uint8>; nonce: array<uint8>; plain: array<uint8>; aad: array<uint8>; output: array<uint8> ): bool

Encrypts and authenticates plain with AES-256-GCM. Key is 32 bytes and nonce is 12 bytes; never reuse a nonce with the same key. Output contains ciphertext followed by a 16-byte tag. AAD is authenticated but not encrypted. Returns false and clears output on failure.

Arguments:
  • key : array<uint8> implicit

  • nonce : array<uint8> implicit

  • plain : array<uint8> implicit

  • aad : array<uint8> implicit

  • output : array<uint8> implicit

2.6.4. Signature verification

crypto_verify_rsa_sha256(modulus: array<uint8>; exponent: array<uint8>; message: array<uint8>; signature: array<uint8> ): bool

Verifies an RSA PKCS#1 v1.5 SHA-256 signature. Modulus and exponent are unsigned big-endian bytes; modulus is 2048–8192 bits and exponent is at most 8 bytes. Signature length equals the modulus byte length. Returns false for invalid inputs or signature. This does not parse certificates or establish trust in the supplied key.

Arguments:
  • modulus : array<uint8> implicit

  • exponent : array<uint8> implicit

  • message : array<uint8> implicit

  • signature : array<uint8> implicit