HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulelibsodium-bindings-0.0.1.1Haskell2010

LibSodium.Bindings.SealedBoxes

  • 5 values

Introduction

0 declarations

Sealed boxes are designed to anonymously send messages to a recipient given their public key.

Only the recipient can decrypt these messages using their secret key. While the recipient can verify the integrity of the message, they cannot verify the identity of the sender.

A message is encrypted using an ephemeral key pair, with the secret key being erased right after the encryption process.

Without knowing the secret key used for a given message, the sender cannot decrypt the message later. Furthermore, without additional data, a message cannot be correlated with the identity of its sender.

Functions

4 declarations
valuecryptoBoxSeal
  1. :: Ptr CUChar

    Buffer that will hold the encrypted message of size (size of original message + cryptoBoxSealbytes) bytes

  2. -> Ptr CUChar

    Buffer that holds the plaintext message

  3. -> CULLong

    Length of the plaintext message

  4. -> Ptr CUChar

    Buffer that holds public key of size cryptoBoxPublicKeyBytes bytes.

  5. -> IO CInt

    Returns 0 on success and -1 on error.

#

cryptoBoxSeal creates a new key pair for each message and attaches the public key to the ciphertext. The secret key is overwritten and is not accessible after this function returns.

See: crypto_box_seal()

valuecryptoBoxSealOpen
  1. :: Ptr CUChar

    Buffer that will hold the plaintext message of size (size of original message - cryptoBoxSealbytes) bytes

  2. -> Ptr CUChar

    Buffer that holds the encrypted message.

  3. -> CULLong

    Length of the encrypted message

  4. -> Ptr CUChar

    Buffer that holds public key of size cryptoBoxPublicKeyBytes bytes.

  5. -> Ptr CUChar

    Buffer that holds secret key of size cryptoBoxSecretKeyBytes bytes.

  6. -> IO CInt

    Returns 0 on success and -1 on error.

#

cryptoBoxSealOpen doesn't require passing the public key of the sender as the ciphertext already includes this information.

Key pairs are compatible with operations from LibSodium.Bindings.CryptoBox module and can be created using cryptoBoxKeyPair or cryptoBoxSeedKeyPair.

See: crypto_box_seal_open()

Constants

1 declaration

Size diff in bytes between encrypted and plaintext messages, i.e. cryptoBoxSealbytes = length encryptedMsg - length plaintextMsg