Crate cbc

source ·
Expand description

Cipher Block Chaining (CBC) mode.

Mode functionality is accessed using traits from re-exported cipher crate.

§⚠️ Security Warning: Hazmat!

This crate does not ensure ciphertexts are authentic! Thus ciphertext integrity is not verified, which can lead to serious vulnerabilities! [AEADs][] provide simple authenticated encryption, which is much less error-prone than manual integrity verification.


use aes::cipher::{block_padding::Pkcs7, BlockModeEncrypt, BlockModeDecrypt, KeyIvInit};
use hex_literal::hex;

type Aes128CbcEnc = cbc::Encryptor<aes::Aes128>;
type Aes128CbcDec = cbc::Decryptor<aes::Aes128>;

let key = [0x42; 16];
let iv = [0x24; 16];
let plaintext = *b"hello world! this is my plaintext.";
let ciphertext = hex!(

// encrypt/decrypt in-place
// buffer must be big enough for padded plaintext
let mut buf = [0u8; 48];
let pt_len = plaintext.len();
let ct = Aes128CbcEnc::new(&key.into(), &iv.into())
    .encrypt_padded::<Pkcs7>(&mut buf, pt_len)
assert_eq!(ct, &ciphertext[..]);

let pt = Aes128CbcDec::new(&key.into(), &iv.into())
    .decrypt_padded::<Pkcs7>(&mut buf)
assert_eq!(pt, &plaintext);

// encrypt/decrypt from buffer to buffer
let mut buf = [0u8; 48];
let ct = Aes128CbcEnc::new(&key.into(), &iv.into())
    .encrypt_padded_b2b::<Pkcs7>(&plaintext, &mut buf)
assert_eq!(ct, &ciphertext[..]);

let mut buf = [0u8; 48];
let pt = Aes128CbcDec::new(&key.into(), &iv.into())
    .decrypt_padded_b2b::<Pkcs7>(&ct, &mut buf)
assert_eq!(pt, &plaintext);

With enabled alloc (or std) feature you also can use allocating convenience methods:

let res = Aes128CbcEnc::new(&key.into(), &iv.into())
assert_eq!(res[..], ciphertext[..]);
let res = Aes128CbcDec::new(&key.into(), &iv.into())
assert_eq!(res[..], plaintext[..]);

