HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulecrypton-1.0.4Haskell2010

Crypto.Cipher.ChaChaPoly1305

A simple AEAD scheme using ChaCha20 and Poly1305. See RFC 7539.

The State is not modified in place, so each function changing the State, returns a new State.

Authenticated Data need to be added before any call to encrypt or decrypt, and once all the data has been added, then finalizeAAD need to be called.

Once finalizeAAD has been called, no further appendAAD call should be make.

import Data.ByteString.Char8 as B
import Data.ByteArray
import Crypto.Error
import Crypto.Cipher.ChaChaPoly1305 as C

encrypt
    :: ByteString -- nonce (12 random bytes)
    -> ByteString -- symmetric key
    -> ByteString -- optional associated data (won't be encrypted)
    -> ByteString -- input plaintext to be encrypted
    -> CryptoFailable ByteString -- ciphertext with a 128-bit tag attached
encrypt nonce key header plaintext = do
    st1 <- C.nonce12 nonce >>= C.initialize key
    let
        st2 = C.finalizeAAD $ C.appendAAD header st1
        (out, st3) = C.encrypt plaintext st2
        auth = C.finalize st3
    return $ out `B.append` Data.ByteArray.convert auth
  • 4 types
  • 12 values
  • Packagecrypton-1.0.4
  • Exports16
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceChaChaPoly1305.hs

AEAD

2 declarations

Low level

14 declarations
datadata State
#

A ChaChaPoly1305 State.

The state is immutable, and only new state can be created

newtypenewtype XNonce
#

Extended nonce for XChaChaPoly1305.

Instances1ByteArrayAccess
valueencrypt :: ByteArray ba => ba -> State -> (ba, State)
#

Encrypt a piece of data and returns the encrypted Data and the updated State.

valuedecrypt :: ByteArray ba => ba -> State -> (ba, State)
#

Decrypt a piece of data and returns the decrypted Data and the updated State.