Security News
Oracle Drags Its Feet in the JavaScript Trademark Dispute
Oracle seeks to dismiss fraud claims in the JavaScript trademark dispute, delaying the case and avoiding questions about its right to the name.
@oasisprotocol/deoxysii
Advanced tools
This package provides a pure-JavaScript implementation of the Deoxys-II-256-128 v1.43 algorithm from the final CAESAR portfolio.
Deoxys is an authenticated encryption scheme based on a 128-bit lightweight ad-hoc tweakable block cipher. It may be used in two modes to handle nonce-respecting users (Deoxys-I) or nonce-reusing user (Deoxys-II).
It has been designed by Jérémy Jean, Ivica Nikolić, Thomas Peyrin and Yannick Seurin.
Install the package as a dependency of your project:
npm add '@oasisprotocol/deoxysii'
The AEAD
class can then be used to encrypt and decrypt, with an optional
authenticated data field which can be very useful when constructing protocols.
import { AEAD, KeySize, NonceSize } from '@oasisprotocol/deoxysii';
// Define a key (ensure the size matches requirements)
const key = crypto.getRandomValues(new Uint8Array(KeySize));
const aead = new AEAD(key);
// Encryption
const nonce = crypto.getRandomValues(new Uint8Array(NonceSize));
const plaintext = new TextEncoder().encode("Hello World");
const associatedData = new Uint8Array([0x1, 0x2, 0x3]);
const encrypted = aead.encrypt(nonce, plaintext, associatedData);
console.log('Encrypted:', encrypted);
// Decryption
try {
const decrypted = aead.decrypt(nonce, encrypted, associatedData);
console.log('Decrypted:', new TextDecoder().decode(decrypted));
} catch (error) {
console.error('Decryption failed:', error);
}
[!WARNING] It is unclear what the various JavaScript implementations will do to the
ct32
code or the underlying bitsliced AES round function, and it is quite possible that it may be vulnerable to side channels.Users that require a more performant and secure implementation are suggested to investigate WebAssembly, or (even better) calling native code.
gh act
- run GitHub actions locallyThis project is released under the MIT License.
This project utilizes modified code originally developed by Franz X Antesberger.
The original code for uint32.js
is available at fxa/uint32.js. We have
adapted this code for TypeScript. We appreciate the contributions of Franz X
Antesberger to the open-source community.
FAQs
Deoxys-II-256-128
The npm package @oasisprotocol/deoxysii receives a total of 509 weekly downloads. As such, @oasisprotocol/deoxysii popularity was classified as not popular.
We found that @oasisprotocol/deoxysii demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Oracle seeks to dismiss fraud claims in the JavaScript trademark dispute, delaying the case and avoiding questions about its right to the name.
Security News
The Linux Foundation is warning open source developers that compliance with global sanctions is mandatory, highlighting legal risks and restrictions on contributions.
Security News
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.