Skip to main content

PqdsaKeyPair

Struct PqdsaKeyPair 

Source
pub struct PqdsaKeyPair {
    algorithm: &'static PqdsaSigningAlgorithm,
    evp_pkey: ManagedPointer<*mut EVP_PKEY>,
    pubkey: PublicKey,
}
Expand description

A PQDSA (Post-Quantum Digital Signature Algorithm) key pair, used for signing and verification.

Fields§

§algorithm: &'static PqdsaSigningAlgorithm§evp_pkey: ManagedPointer<*mut EVP_PKEY>§pubkey: PublicKey

Implementations§

Source§

impl PqdsaKeyPair

Source

pub fn generate( algorithm: &'static PqdsaSigningAlgorithm, ) -> Result<Self, Unspecified>

Generates a new PQDSA key pair for the specified algorithm.

§Errors

Returns Unspecified if the key generation fails.

Source

pub fn from_pkcs8( algorithm: &'static PqdsaSigningAlgorithm, pkcs8: &[u8], ) -> Result<Self, KeyRejected>

Constructs a key pair from the parsing of PKCS#8.

This accepts either the seed or expanded private key encodings. If both are present in the input, they are validated to agree with each other.

§Errors

Returns Unspecified if the key is not valid for the specified signing algorithm.

Source

pub fn from_raw_private_key( algorithm: &'static PqdsaSigningAlgorithm, raw_private_key: &[u8], ) -> Result<Self, KeyRejected>

Constructs a key pair from raw private key bytes.

This expects the expanded form of the raw private key bytes.

§Errors

Returns Unspecified if the key is not valid for the specified signing algorithm.

Source

pub fn from_seed( algorithm: &'static PqdsaSigningAlgorithm, seed: &[u8], ) -> Result<Self, KeyRejected>

Constructs a key pair deterministically from a 32-byte seed.

Per FIPS 204, the same seed always produces the same key pair. This enables reproducible key generation for testing, ACVP validation, and interoperability with implementations that store seeds rather than expanded private keys.

algorithm is the PqdsaSigningAlgorithm to be associated with the key pair.

seed is the 32-byte seed from which the key pair is deterministically derived. All ML-DSA variants (ML-DSA-44, ML-DSA-65, ML-DSA-87) use 32-byte seeds.

§Security Considerations

The seed is the root secret. Compromise of the seed is equivalent to compromise of the private key. Callers are responsible for generating seeds from a cryptographically secure random source and protecting them accordingly.

The seed should be produced from random entropy such as through crate::rand::fill. However, for users requiring FIPS, the seed must be produced from Self::generate. The Self::to_pkcs8v1 method serializes the private key in seed form. AWS-LC keeps the seed in the internal representation when possible, but if PqdsaKeyPair is constructed from the expanded form (via Self::from_raw_private_key) the seed cannot be obtained and Self::to_pkcs8v1 will fail.

This method expands the seed into the full private key internally. The expanded private key can be retrieved via Self::private_key and serialized via PqdsaPrivateKey::as_raw_bytes.

§Errors

Returns KeyRejected::too_small() if seed.len() < 32.

Returns KeyRejected::too_large() if seed.len() > 32.

Returns KeyRejected::unspecified() if the underlying cryptographic operation fails.

Source

pub fn to_pkcs8v1(&self) -> Result<Document, Unspecified>

Serializes the private key to PKCS#8 v1 DER.

This currently serializes the seed. If the seed is not available (for example when this PqdsaKeyPair was constructed from the expanded private key via Self::from_raw_private_key), serialization fails and this currently returns an error. A future implementation may encode the expanded form of the key instead.

§Errors

Returns Unspecified if serialization fails.

Source

pub fn sign( &self, msg: &[u8], signature: &mut [u8], ) -> Result<usize, Unspecified>

Uses this key to sign the message provided. The signature is written to the signature slice provided, which must be at least PqdsaSigningAlgorithm::signature_len bytes long. It returns the length of the signature on success.

§Errors

Returns Unspecified if signature is too small or if signing fails.

Source

pub fn algorithm(&self) -> &'static PqdsaSigningAlgorithm

Returns the signing algorithm associated with this key pair.

Source

pub fn private_key(&self) -> PqdsaPrivateKey<'_>

Returns the private key associated with this key pair.

Trait Implementations§

Source§

impl Debug for PqdsaKeyPair

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl KeyPair for PqdsaKeyPair

Source§

type PublicKey = PublicKey

The type of the public key.
Source§

fn public_key(&self) -> &Self::PublicKey

The public key for the key pair.
Source§

impl Send for PqdsaKeyPair

Source§

impl Sync for PqdsaKeyPair

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.