Orion is a cryptography library written in pure Rust. It aims to provide easy and usable crypto while trying to minimize the use of unsafe code. You can read more about Orion in the wiki.
Currently supports:
- AEAD: (X)ChaCha20-Poly1305.
- Hashing: BLAKE2b, SHA2, SHA3.
- XOF: SHAKE128, SHAKE256.
- KDF: HKDF, PBKDF2, Argon2i.
- Key exchange: X25519.
- MAC: HMAC, Poly1305.
- Stream ciphers: (X)ChaCha20.
- KEM: DHKEM(X25519, HKDF-SHA256).
Experimental support (with experimental
feature enabled):
- Committing AEAD: (X)ChaCha20-Poly1305-BLAKE2b.
This library has not undergone any third-party security audit. Usage is at own risk.
Orion uses formally verified arithmetic, generated by Fiat Crypto, for the X25519 and Poly1305 implementations.
See the SECURITY.md regarding recommendations on correct use, reporting security issues and more. Additional information about security regarding Orion is available in the wiki.
Rust 1.80 or later is supported however, the majority of testing happens with latest stable Rust.
MSRV may be changed at any point and will not be considered a SemVer breaking change.
default
/safe_api
: All functionality, requiresstd
.serde
: Requires eitheralloc
ordefault
/safe_api
.alloc
: Argon2i inhazardous
whendefault
/safe_api
is not available.no_std
: Implicit feature that represents no heap allocations. Enabled by disabling default features and not selecting any additional features.experimental
: These APIs may contain breaking changes in any non SemVer-breaking crate releases.
More detailed explanation of the features in the wiki.
Can be viewed here or built with:
RUSTDOCFLAGS='--cfg docsrs' cargo +nightly doc --no-deps --all-features
The wiki has details on how Orion is tested. To run all tests:
cargo test
Fuzzing is done using honggfuzz-rs in orion-fuzz. See orion-fuzz on how to start fuzzing Orion.
Constant-time execution tests can be found at orion-dudect and orion-sidefuzz.
An overview of the performance that can be expected from Orion can be seen here.
The library can be benchmarked with Criterion as below. All benchmarking tests are located in benches/
.
cargo bench
Please refer to the CHANGELOG.md list.
Please refer to the guidelines in CONTRIBUTING.md for information on how to contribute to Orion.
Orion is licensed under the MIT license. See the LICENSE
file for more information.