Pure TLS 1.3 AEAD encryption and authenticated decryption.
The record nonce is derived from the supplied traffic state's static IV and sequence number. Sequence advancement remains the caller's responsibility.
Summary
Types
@type error_reason() :: :authentication_failed | :encryption_failed | :decryption_failed | :invalid_traffic_state | {:unsupported_cipher_suite, term()} | {:unsupported_capability, SSL.Crypto.TrafficState.cipher_suite()} | {:invalid_key, :not_binary | :wrong_length} | {:invalid_iv, :not_binary | :wrong_length} | {:invalid_sequence, :out_of_range} | {:invalid_aad, :not_binary} | {:invalid_plaintext, :not_binary | :too_long} | {:invalid_ciphertext, :not_binary | :too_long} | {:invalid_tag, :not_binary | :wrong_length}
Functions
@spec decrypt(SSL.Crypto.TrafficState.t(), term(), term(), term()) :: {:ok, binary()} | {:error, error_reason()}
@spec encrypt(SSL.Crypto.TrafficState.t(), term(), term()) :: {:ok, binary(), binary()} | {:error, error_reason()}