
Perl 암호화 툴킷으로, 번들된 LibTomCrypt 라이브러리를 통해 대칭 암호, AEAD 모드, 해시 함수, MAC, 공개키 암호화, 키 파생 및 안전한 난수 생성을 제공합니다.
CryptX - 암호화 툴킷
CryptX는 배포판의 진입점입니다. 일반적인 코드에서는 아래에 나열된 구체적인 모듈 중 하나를 로드합니다.
## one-shot hashing
use Crypt::Digest qw(digest_data_hex);
my $sha256 = digest_data_hex('SHA256', 'hello world');
## classic AES-CBC encryption with padding
use Crypt::Mode::CBC;
my $cbc = Crypt::Mode::CBC->new('AES');
my $iv = random_bytes(16); # 16-byte AES block-size IV
my $cbc_ciphertext = $cbc->encrypt('hello world', $key, $iv);
## authenticated encryption (AEAD) with AES
use Crypt::AuthEnc::GCM qw(gcm_encrypt_authenticate);
my $key = random_bytes(32); # 32-byte AES-256 key
my $nonce = random_bytes(12); # 12-byte unique nonce
my ($ciphertext, $tag) = gcm_encrypt_authenticate('AES', $key, $nonce, 'header', 'hello world');
## message authentication
use Crypt::Mac::HMAC qw(hmac_hex);
my $mac = hmac_hex('SHA256', $key, 'hello world');
## secure random data + UUID helpers
use Crypt::PRNG qw(random_bytes random_string);
use Crypt::Misc qw(random_v4uuid random_v7uuid);
my $salt = random_bytes(16);
my $token = random_string(24);
my $uuid4 = random_v4uuid();
my $uuid7 = random_v7uuid();
## classic password-based key derivation
use Crypt::KeyDerivation qw(pbkdf2);
my $dk = pbkdf2('password', $salt, 100_000, 'SHA256', 32);
## bare stream cipher (authenticate separately)
use Crypt::Stream::ChaCha;
my $stream = Crypt::Stream::ChaCha->new($key, $nonce);
my $stream_ciphertext = $stream->crypt('hello world');
## modern signatures
use Crypt::PK::Ed25519;
my $signer = Crypt::PK::Ed25519->new->generate_key;
my $sig = $signer->sign_message('hello world');
my $ok = $signer->verify_message($sig, 'hello world');
## key agreement
use Crypt::PK::X25519;
my $alice = Crypt::PK::X25519->new->generate_key;
my $bob = Crypt::PK::X25519->new->generate_key;
my $shared_secret = $alice->shared_secret($bob);
번들로 포함된 LibTomCrypt 라이브러리를 기반으로 구축된 Perl 암호화 모듈입니다. 이 배포판에는 LibTomCrypt가 내부적으로 사용하는 번들 LibTomMath 라이브러리를 기반으로 구축된 Math::BigInt 백엔드인 Math::BigInt::LTM도 포함되어 있습니다.
이 모듈은 주로 최상위 배포/문서 페이지 역할을 합니다. 실제 작업에는 아래에 나열된 구체적인 모듈 중 하나를 사용하세요.
새로운 설계에서는 단순 암호 모드보다 인증 암호화(AEAD)를 선호하세요:
random_bytes, random_bytes_hex, random_bytes_b64, random_bytes_b64u, random_string, random_string_from은 대부분의 사용 사례를 충족합니다. OO API와 알고리즘별 래퍼(Crypt::PRNG::ChaCha20, Crypt::PRNG::Fortuna 등)는 주로 결정적 스트림 또는 특정 PRNG와의 상호 운용성을 위한 것입니다.random_v4uuid를 사용하세요. 밀리초 단위의 생성 시간순으로 정렬되는 대략적인 시간 순서 식별자가 필요하면 random_v7uuid를 사용하세요. UUID는 식별자이지 비밀 난수 바이트를 대체하는 것이 아닙니다.스트림 암호는 블록 패딩 없이 데이터를 바이트 단위로 암호화합니다. 대부분의 애플리케이션에서는 암호화와 인증을 함께 제공하는 AEAD 모드(위 참조)를 선호하세요. 단순 스트림 암호는 인증을 별도로 처리할 때만 사용하세요.
인증을 별도로 처리하거나 인증이 필요 없는 경우에만 사용하세요:
개별 Crypt::Cipher::AES, Crypt::Cipher::Twofish 등의 모듈은 원시 단일 블록 암호화를 구현하며 직접 사용되는 경우는 드뭅니다. 거의 모든 경우 AEAD 모드(Crypt::AuthEnc::GCM, Crypt::AuthEnc::CCM) 또는 블록 암호 모드(Crypt::Mode::CBC, Crypt::Mode::CTR)를 통해 사용해야 합니다. 암호를 선택할 때 AES가 기본값이며, 대부분의 최신 CPU에서 하드웨어 가속을 지원합니다.