ausimian

ausimian

Decibel - An Elixir implementation of the Noise Protocol Framework

Decibel is an Elixir implementation of the Noise Protocol Framework.

Noise is a framework for building crypto protocols. Noise protocols support mutual and optional authentication, identity hiding, forward secrecy, zero round-trip encryption, and other advanced features.

Decibel supports all the handshakes listed in r34 of the specification, including fundamental, deferred and one-way handshakes. In addition it has support for fallback protocols and multiple pre-shared symmetric keys.

It’s test-suite includes the cacophony and snow test vectors, totalling over 1300 tests.

It’s currently at 0.1.0, but at this point I don’t anticipate any breaking api changes, rather just improvements to documentation before going to 1.0.0.

First 6 of 6 Posts Switch mode

the_wildgoose

the_wildgoose

# Somehow send this message to the responder and get the response
magically_send_msg(rsp_proc, msg1)
msg2 = magically_recv_msg(rsp_proc)

Is there any chance you could also release this library!
:smile:

Oh, question: It’s not immediately clear, but can I use this for an unreliable channel, or where messages will arrive out of order? Think UDP alike datagrams?

ausimian

ausimian OP

Oh, question: It’s not immediately clear, but can I use this for an unreliable channel, or where messages will arrive out of order? Think UDP alike datagrams?

The simplest thing would be to sequence the messages yourself and re-assemble them at the other end, feeding only contiguously-sequenced packets into the decryption. This should just work.

In theory it’s even possible to decrypt out-of-order messages - but 0.1.0 does not currently support getting/setting the n value of the internal CipherState object through the public api, although I intend to address this before 1.0.0.

ausimian

ausimian OP

I pushed 0.1.1 (decibel | Hex) which allows to read and write the current n value of either the inbound or outbound channel (CipherState) of the current session. I added a test to show how to decrypt messages if they arrive out of order, by setting the n value.

A couple of notes:

  1. This assumes that the n value travels in the clear with each ciphertext, which is a requirement already outlined in the spec. In addition, I used a byte representation of that sequence number as the AAD.
  2. You still have to solve any unreliability of the handshake itself.
the_wildgoose

the_wildgoose

Hi, but does that mean the protocol cannot tolerate a completely missing message? Needs to re-initialise the handshake? (presumably anything sent between the missing message and the new handshake cannot be decrypted?)

I was under the impression there were noise modes which were tolerant of missing messages?

ausimian

ausimian OP

Once the handshake is complete and the session established, it absolutely can tolerate missing messages.

Providing every packet contains the nonce value alongside the encrypted data, the recipient reads both, and sets the nonce before decrypting.

ausimian

ausimian OP

Decibel 0.2.0 has been released.

This release was mainly focused on proving support for Compound Protocols, in particular Noise Pipes:

  • AEAD decryption failures raise Decibel.DecryptionError rather than RuntimeError.
  • Additional test-cases for fallback protocols, using vectors from noise-c
  • Improved documentation around Noise Pipes including examples
  • Improved documentation around Connectionless Transports
— All posts loaded —

Where Next?

Trending in Announcing Top

bluzky
You may know https://ui.shadcn.com/, a UI component library for React. I really love it’s design style and components. I’ve built some co...
387 14960 120
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
shahryarjb
The Chelekom project is a library of Phoenix and LiveView components generated via Mix tasks to fit developer needs seamlessly. One of i...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve. They are GUI (Emerge) and State management (S...
New
ausimian
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New
wintermeyer
There are three potential reasons for members of this forum to have a look at https://vutuv.de You are tired or annoyed of LinkedIn. Yo...
New

Other Trending Topics Top

type1fool
I just stumbled on a newly redesigned elixir-lang.org. :tada: It looks like @Software_Mansion did the work, and I think it is generally a...
New
akoutmos
@hugobarauna and I (Alex Koutmos) have been hard at work on writing a book on Nerves that takes you from simply blinking LEDs to building...
New
juhalehtonen
There has been a thread to discuss the Stack Overflow Developer Survey on this forum every year since 2018, so here’s yet another one for...
New
bjorng
We want to introduce a new native datatype to Erlang: native records. Although replacing all tuple records with native records is not our...
New
spammy
I’m looking to build a personal workflow to quickly deploy web applications written in elixir/phoenix, for local consumption (ie not on t...
New
alexslade
Fly’s CEO posted this recently - Turn And Face The Strange · The Fly Blog It says that Fly is going all-in on sprites, which is a worry ...
New

We're in Beta

About us Mission Statement