Back to updates
New releaseAug 7, 2026

rscrypto v0.8.0

Rust crypto w/ zero default deps: BLAKE3, Ed25519/X25519, hashes, MACs, KDFs, AEADs, and checksums w/ full SIMD/ASM acceleration

Share

rscrypto

Crates.io Docs.rs MSRV 1.100.0 License: MIT OR Apache-2.0

rscrypto puts cryptographic primitives, cryptographic and fast hashes, password hashing, and checksums behind one feature model. Target-gated SIMD and assembly accelerate portable Rust backends without a production C/FFI, OpenSSL, or system-library dependency.

rscrypto is a primitives crate, not a TLS stack, PKI toolkit, key store, or protocol implementation.

Measured performance

Performance claims are limited to exact retained campaigns and equivalent workloads. The corrected September 2026 campaign contains 19,614 completed cases, including corrected ML-KEM and Argon2 comparisons, but no replacement aggregate scorecard has been curated. Older aggregates that mixed entropy, key preparation, output representation, or salt lengths remain historical records and are not current performance claims.

The benchmark overview records the campaigns, target-specific results, and remaining limits. The comparison contracts define equivalent ML-KEM and Argon2 workloads.

Assurance

Security claims fail closed: missing or stale evidence removes the claim rather than weakening the gate.

  • Correctness evidence combines NIST, RFC, upstream, and Wycheproof vectors with separate implementations, properties, negative tests, and Miri.
  • Fuzz targets exercise production implementations across primitive, parser, state-machine, and trait boundaries. Minimized seeds replay as tests, with a separate sanitizer lane.
  • Portable-versus-accelerated differential tests cover lengths, alignments, tails, state transitions, dispatch, and fallback behavior on native targets.
  • The constant-time harness inventories exact operations in ct.toml and combines optimized linked-binary inspection, BINSEC proofs for declared fixed-shape kernels, and DudeCT timing tests for declared end-to-end cases.
  • Secret owners redact Debug and clear initialized storage on drop. Duplication rules vary by type: keyed BLAKE2/BLAKE3 state supports Clone. The ownership inventory lists these boundaries. Verification failures are opaque; failed AEAD opens clear unauthenticated plaintext.

A constant-time claim exists only when evidence for the required target, feature, compiler, profile, and operation passes. Source that looks branchless is not treated as proof.

Inspect the test evidence, constant-time model, secret lifecycle, and threat model.

The remaining independent-review gap is a third-party security audit. The project cannot currently fund one. Automated evidence does not replace that review, so rscrypto does not claim to be audited, FIPS 140-3 validated, formally verified, or constant time as a whole crate.

Report suspected vulnerabilities through GitHub Private Vulnerability Reporting under the SECURITY.md process, not a public issue.

Install only what you use

Minimal no_std SHA-2 build:

[dependencies]
rscrypto = { version = "0.10", default-features = false, features = ["sha2"] }

Full primitive stack with OS randomness enabled:

[dependencies]
rscrypto = { version = "0.10", features = ["full", "getrandom"] }

The default feature is std; default-features = false removes it. Enable getrandom only for APIs that obtain salts, keys, nonces, or RSA key-generation entropy from the operating system. The feature guide explains build selection; Cargo.toml owns the exact feature graph.

Quick start

use rscrypto::Sha256;

let one_shot = Sha256::digest(b"hello world");

let mut hasher = Sha256::new();
hasher.update(b"hello ");
hasher.update(b"world");

assert_eq!(hasher.finalize(), one_shot);

Hash APIs support one-shot and streaming use. Runnable workflows for AEAD, signatures, RSA, P-256 and P-384 ECDH, X25519, ML-KEM, password hashing, and backend introspection are in examples/README.md.

Primitive and feature map

FamilyIncludedEnable
ChecksumsCRC-16, CRC-24, CRC-32, CRC-32C, CRC-64/XZ, CRC-64/NVMechecksums or leaf features
Cryptographic hashesSHA-2, SHA-3, SHAKE, cSHAKE, BLAKE2, BLAKE3, Ascon-Hash/XOF/CXOFcrypto-hashes or leaf features
Fast hashesXXH3-64/128, RapidHash V3-64fast-hashes or leaf features
MACs and KDFsHMAC-SHA-2/SHA-3, KMAC128/256, Poly1305, HKDF-SHA-2, PBKDF2-HMAC-SHA-2macs, kdfs, or leaf features
Password hashingArgon2d/i/id, scrypt, bounded PHC password recordspassword-hashing or leaf features
Signatures and RSAECDSA P-256/P-384, Ed25519, ML-DSA-44/65/87, RSA signing, verification, encryption, and key generationsignatures or leaf features
Key exchange and KEMsP-256 ECDH, P-384 ECDH, X25519, ML-KEM-512/768/1024key-exchange or leaf features
AEADsAES-GCM, AES-GCM-SIV, AES-SIV-CMAC, ChaCha20-Poly1305, XChaCha20-Poly1305, AEGIS-256, Ascon-AEAD128aead or leaf features

The compatibility-only WebSocket accept digest requires websocket-sha1, which is excluded from full and every other umbrella feature.

Use docs.rs for exact types and methods.

Platforms and dispatch

The portable Rust implementation is the byte-for-byte authority. Compile-time target support and, with std, detected runtime CPU capabilities select eligible SIMD or assembly kernels. Unsupported acceleration falls back to portable Rust.

The platform guide explains the supported target catalog, dispatch, no_std coverage, and the limits of portable-only.

Project

The guides and examples describe the accompanying source. Use the matching version of the API documentation for a published dependency.

Read CONTRIBUTING.md before changing code. Published changes live in CHANGELOG.md.

License

Dual-licensed under Apache-2.0 or MIT, at your option.

Categories