Skip to content

std.crypto: add AES-SIV and AES-GCM-SIV - #25249

Merged
andrewrk merged 3 commits into
ziglang:masterfrom
jedisct1:siv
Sep 18, 2025
Merged

andrewrk merged 3 commits into
ziglang:masterfrom
jedisct1:siv

Conversation

@jedisct1

Copy link
Copy Markdown
Contributor

The Zig standard library was missing schemes that are resistant to nonce reuse.

AES-SIV and AES-GCM-SIV are the standard solutions for this.

AES-GCM-SIV is particularly useful when Zig is targeting embedded systems, while AES-SIV is especially valuable for key wrapping.

I also took this as an opportunity to add a set of test vectors to modes.ctr and to ensure it works with block ciphers whose block size is not 16.

The Zig standard library lacked schemes that resist nonce reuse.

AES-SIV and AES-GCM-SIV are the standard options for this.

AES-GCM-SIV can be very useful when Zig is used to target embedded
systems, and AES-SIV is especially useful for key wrapping.

Also take it as an opportunity to add a bunch of test vectors to
modes.ctr and make sure it works with block ciphers whose size is
not 16.
@andrewrk andrewrk added the release notes This PR should be mentioned in the release notes. label Sep 18, 2025
@andrewrk
andrewrk merged commit b782cdb into ziglang:master Sep 18, 2025
16 checks passed
@jedisct1
jedisct1 deleted the siv branch September 18, 2025 08:04
@alexrp alexrp removed the release notes This PR should be mentioned in the release notes. label Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants