
rscrypto v0.7.8
Rust crypto w/ zero default deps: BLAKE3, Ed25519/X25519, hashes, MACs, KDFs, AEADs, and checksums w/ full SIMD/ASM acceleration
rscrypto
rscrypto puts cryptographic primitives, cryptographic and fast hashes, password hashing,
and checksums behind one feature model.
Target-gated SIMD and assembly accelerate portable Rust backends without a production C/FFI,
OpenSSL, or system-library dependency.
rscrypto is a primitives crate, not a TLS stack, PKI toolkit, key store, or protocol implementation.
Measured performance
Performance claims are limited to exact retained campaigns and equivalent workloads. The corrected September 2026 campaign contains 19,614 completed cases, including corrected ML-KEM and Argon2 comparisons, but no replacement aggregate scorecard has been curated. Older aggregates that mixed entropy, key preparation, output representation, or salt lengths remain historical records and are not current performance claims.
The benchmark overview records the campaigns, target-specific results, and remaining limits.
The comparison contracts define equivalent ML-KEM and Argon2 workloads.
Assurance
Security claims fail closed: missing or stale evidence removes the claim rather than weakening the gate.
- Correctness evidence combines NIST, RFC, upstream, and Wycheproof vectors with separate implementations, properties, negative tests, and Miri.
- Fuzz targets exercise production implementations across primitive, parser, state-machine, and trait boundaries. Minimized seeds replay as tests, with a separate sanitizer lane.
- Portable-versus-accelerated differential tests cover lengths, alignments, tails, state transitions, dispatch, and fallback behavior on native targets.
- The constant-time harness inventories exact operations in
ct.tomland combines optimized linked-binary inspection, BINSEC proofs for declared fixed-shape kernels, and DudeCT timing tests for declared end-to-end cases. - Secret owners redact
Debugand clear initialized storage on drop. Duplication rules vary by type: keyed BLAKE2/BLAKE3 state supportsClone. The ownership inventory lists these boundaries. Verification failures are opaque; failed AEAD opens clear unauthenticated plaintext.
A constant-time claim exists only when evidence for the required target, feature, compiler, profile, and operation passes. Source that looks branchless is not treated as proof.
Inspect the test evidence, constant-time model, secret lifecycle, and threat model.
The remaining independent-review gap is a third-party security audit.
The project cannot currently fund one.
Automated evidence does not replace that review, so rscrypto does not claim to be audited,
FIPS 140-3 validated, formally verified, or constant time as a whole crate.
Report suspected vulnerabilities through GitHub Private Vulnerability Reporting under the
SECURITY.md process, not a public issue.
Install only what you use
Minimal no_std SHA-2 build:
[dependencies]
rscrypto = { version = "0.10", default-features = false, features = ["sha2"] }
Full primitive stack with OS randomness enabled:
[dependencies]
rscrypto = { version = "0.10", features = ["full", "getrandom"] }
The default feature is std; default-features = false removes it.
Enable getrandom only for APIs that obtain salts, keys, nonces,
or RSA key-generation entropy from the operating system.
The feature guide explains build selection; Cargo.toml owns the exact feature graph.
Quick start
use rscrypto::Sha256;
let one_shot = Sha256::digest(b"hello world");
let mut hasher = Sha256::new();
hasher.update(b"hello ");
hasher.update(b"world");
assert_eq!(hasher.finalize(), one_shot);
Hash APIs support one-shot and streaming use.
Runnable workflows for AEAD, signatures, RSA, P-256 and P-384 ECDH, X25519, ML-KEM, password hashing,
and backend introspection are in examples/README.md.
Primitive and feature map
| Family | Included | Enable |
|---|---|---|
| Checksums | CRC-16, CRC-24, CRC-32, CRC-32C, CRC-64/XZ, CRC-64/NVMe | checksums or leaf features |
| Cryptographic hashes | SHA-2, SHA-3, SHAKE, cSHAKE, BLAKE2, BLAKE3, Ascon-Hash/XOF/CXOF | crypto-hashes or leaf features |
| Fast hashes | XXH3-64/128, RapidHash V3-64 | fast-hashes or leaf features |
| MACs and KDFs | HMAC-SHA-2/SHA-3, KMAC128/256, Poly1305, HKDF-SHA-2, PBKDF2-HMAC-SHA-2 | macs, kdfs, or leaf features |
| Password hashing | Argon2d/i/id, scrypt, bounded PHC password records | password-hashing or leaf features |
| Signatures and RSA | ECDSA P-256/P-384, Ed25519, ML-DSA-44/65/87, RSA signing, verification, encryption, and key generation | signatures or leaf features |
| Key exchange and KEMs | P-256 ECDH, P-384 ECDH, X25519, ML-KEM-512/768/1024 | key-exchange or leaf features |
| AEADs | AES-GCM, AES-GCM-SIV, AES-SIV-CMAC, ChaCha20-Poly1305, XChaCha20-Poly1305, AEGIS-256, Ascon-AEAD128 | aead or leaf features |
The compatibility-only WebSocket accept digest requires websocket-sha1,
which is excluded from full and every other umbrella feature.
Use docs.rs for exact types and methods.
Platforms and dispatch
The portable Rust implementation is the byte-for-byte authority.
Compile-time target support and, with std,
detected runtime CPU capabilities select eligible SIMD or assembly kernels.
Unsupported acceleration falls back to portable Rust.
The platform guide explains the supported target catalog, dispatch, no_std coverage,
and the limits of portable-only.
Project
The guides and examples describe the accompanying source. Use the matching version of the API documentation for a published dependency.
Read CONTRIBUTING.md before changing code.
Published changes live in CHANGELOG.md.
License
Dual-licensed under Apache-2.0 or MIT, at your option.