2017-10-21 10:59:09 +08:00
|
|
|
=pod
|
|
|
|
|
|
|
|
=head1 NAME
|
|
|
|
|
|
|
|
EVP_chacha20,
|
|
|
|
EVP_chacha20_poly1305
|
|
|
|
- EVP ChaCha20 stream cipher
|
|
|
|
|
|
|
|
=head1 SYNOPSIS
|
|
|
|
|
|
|
|
#include <openssl/evp.h>
|
|
|
|
|
2020-07-15 16:26:35 +08:00
|
|
|
const EVP_CIPHER *EVP_chacha20(void);
|
|
|
|
const EVP_CIPHER *EVP_chacha20_poly1305(void);
|
2017-10-21 10:59:09 +08:00
|
|
|
|
|
|
|
=head1 DESCRIPTION
|
|
|
|
|
|
|
|
The ChaCha20 stream cipher for EVP.
|
|
|
|
|
|
|
|
=over 4
|
|
|
|
|
|
|
|
=item EVP_chacha20()
|
|
|
|
|
2019-04-18 17:54:58 +08:00
|
|
|
The ChaCha20 stream cipher. The key length is 256 bits, the IV is 128 bits long.
|
2023-06-01 07:51:46 +08:00
|
|
|
The first 64 bits consists of a counter in little-endian order followed by a 64
|
2019-04-18 17:54:58 +08:00
|
|
|
bit nonce. For example a nonce of:
|
|
|
|
|
2023-06-01 07:51:46 +08:00
|
|
|
0000000000000002
|
2019-04-18 17:54:58 +08:00
|
|
|
|
|
|
|
With an initial counter of 42 (2a in hex) would be expressed as:
|
|
|
|
|
|
|
|
2a000000000000000000000000000002
|
2017-10-21 10:59:09 +08:00
|
|
|
|
|
|
|
=item EVP_chacha20_poly1305()
|
|
|
|
|
|
|
|
Authenticated encryption with ChaCha20-Poly1305. Like EVP_chacha20(), the key
|
|
|
|
is 256 bits and the IV is 96 bits. This supports additional authenticated data
|
|
|
|
(AAD) and produces a 128-bit authentication tag. See the
|
|
|
|
L<EVP_EncryptInit(3)/AEAD Interface> section for more information.
|
|
|
|
|
|
|
|
=back
|
|
|
|
|
2023-02-22 08:11:33 +08:00
|
|
|
=head1 NOTES
|
|
|
|
|
|
|
|
Developers should be aware of the negative performance implications of
|
|
|
|
calling these functions multiple times and should consider using
|
|
|
|
L<EVP_CIPHER_fetch(3)> instead.
|
|
|
|
See L<crypto(7)/Performance> for further information.
|
|
|
|
|
2023-06-01 07:51:46 +08:00
|
|
|
L<RFC 7539|https://www.rfc-editor.org/rfc/rfc7539.html#section-2.4>
|
|
|
|
uses a 32 bit counter and a 96 bit nonce for the IV.
|
|
|
|
|
2017-10-21 10:59:09 +08:00
|
|
|
=head1 RETURN VALUES
|
|
|
|
|
|
|
|
These functions return an B<EVP_CIPHER> structure that contains the
|
|
|
|
implementation of the symmetric cipher. See L<EVP_CIPHER_meth_new(3)> for
|
|
|
|
details of the B<EVP_CIPHER> structure.
|
|
|
|
|
|
|
|
=head1 SEE ALSO
|
|
|
|
|
|
|
|
L<evp(7)>,
|
|
|
|
L<EVP_EncryptInit(3)>,
|
|
|
|
L<EVP_CIPHER_meth_new(3)>
|
|
|
|
|
|
|
|
=head1 COPYRIGHT
|
|
|
|
|
2023-09-07 16:59:15 +08:00
|
|
|
Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.
|
2017-10-21 10:59:09 +08:00
|
|
|
|
2018-12-06 21:04:44 +08:00
|
|
|
Licensed under the Apache License 2.0 (the "License"). You may not use
|
2017-10-21 10:59:09 +08:00
|
|
|
this file except in compliance with the License. You can obtain a copy
|
|
|
|
in the file LICENSE in the source distribution or at
|
|
|
|
L<https://www.openssl.org/source/license.html>.
|
|
|
|
|
|
|
|
=cut
|
|
|
|
|