A command-line tool for quantum-safe file signing, encryption, and decryption using post-quantum cryptographic algorithms from the Open Quantum Safe (OQS) library.
Rust Seal provides quantum-resistant cryptographic operations for files, including:
- File Signing: Create and verify digital signatures using post-quantum signature algorithms
- File Encryption/Decryption: Encrypt files using Key Encapsulation Mechanisms (KEM) with symmetric encryption
- Key Management: Generate and manage cryptographic keys for various algorithms
This tool uses the liboqs library to provide resistance against both classical and quantum computer attacks.
This will make a vendored liboqs build for this project
- Install dependencies
sudo apt update
sudo apt install build-essential clang libclang-dev pkg-config
sudo apt install astyle cmake gcc ninja-build libssl-dev python3-pytest python3-pytest-xdist unzip xsltproc doxygen graphviz python3-yaml valgrindYou can also have a look into the install dependencies section of the liboqs documenation.
Alternatively, you can install liboqs locally and let rust-seal use that.
-
change the
LIBOQS_NO_VENDORenvironment variable value to"1"in.cargo/config.tml -
install liboqs locally. To do that follow the setup documentation
If you installed liboqs (either vendored or non-vendored) you can build and install rust-seal:
cargo install --path .Before using rust-seal, you need to generate key pairs for the algorithms you want to use.
rust-seal init sig --signature-algorithm <ALGORITHM>rust-seal init kem --kem-algorithm <ALGORITHM>Examples:
rust-seal init sig --signature-algorithm Dilithium2
rust-seal init kem --kem-algorithm Kyber512rust-seal sign <FILE_PATH> --signature-algorithm <ALGORITHM>Arguments:
<FILE_PATH>: Path to the file you want to sign--signature-algorithm, -s: Signature algorithm to use (required)
Example:
rust-seal sign document.txt --signature-algorithm Dilithium2This creates a signature file document.txt.sig alongside your original file.
rust-seal verify <FILE_PATH> --signature-algorithm <ALGORITHM> [OPTIONS]Arguments:
<FILE_PATH>: Path to the file to verify--signature-algorithm, -s: Signature algorithm used for signing (required)
Options:
--sig-path: Path to signature file (default:<FILE_PATH>.sig)--pub-path: Path to public key file (uses configured key if not specified)
Example:
rust-seal verify document.txt --signature-algorithm Dilithium2
rust-seal verify document.txt --signature-algorithm Dilithium2 --sig-path custom.sigrust-seal encrypt-file <FILE_PATH> --kem-algorithm <ALGORITHM> [OPTIONS]Arguments:
<FILE_PATH>: Path to the file you want to encrypt--kem-algorithm, -k: KEM algorithm to use (required)
Options:
--pub-path: Path to recipient's public key file
Example:
rust-seal encrypt-file secret.txt --kem-algorithm Kyber512This creates:
secret.txt.cipher: The encrypted filesecret.txt.ciphertext: The encapsulated key
rust-seal decrypt-file <FILE_PATH> --kem-algorithm <ALGORITHM> [OPTIONS]Arguments:
<FILE_PATH>: Path to the encrypted file (.cipherfile)--kem-algorithm, -k: KEM algorithm used for encryption (required)
Options:
--cipher-path: Path to ciphertext file (default: derived from file path)
Example:
rust-seal decrypt-file secret.txt.cipher --kem-algorithm Kyber512The decrypted file will be saved with the original name (e.g., secret.txt). If the file already exists, -decrypt will be appended to avoid overwriting.
Rust Seal stores configuration and generated keys in:
- Configuration file:
rust-seal.config.json - Keys directory:
keys/
The configuration file tracks initialized algorithms and their corresponding key file paths.
- BIKE-L1, BIKE-L3, BIKE-L5
- Classic-McEliece-348864, Classic-McEliece-348864f
- Classic-McEliece-460896, Classic-McEliece-460896f
- Classic-McEliece-6688128, Classic-McEliece-6688128f
- Classic-McEliece-6960119, Classic-McEliece-6960119f
- Classic-McEliece-8192128, Classic-McEliece-8192128f
- HQC-128, HQC-192, HQC-256
- Kyber512, Kyber768, Kyber1024
- ML-KEM-512, ML-KEM-768, ML-KEM-1024
- sntrup761
- FrodoKEM-640-AES, FrodoKEM-640-SHAKE
- FrodoKEM-976-AES, FrodoKEM-976-SHAKE
- FrodoKEM-1344-AES, FrodoKEM-1344-SHAKE
- cross-rsdp-128-balanced, cross-rsdp-128-fast, cross-rsdp-128-small
- cross-rsdp-192-balanced, cross-rsdp-192-fast, cross-rsdp-192-small
- cross-rsdp-256-balanced, cross-rsdp-256-fast, cross-rsdp-256-small
- cross-rsdpg-128-balanced, cross-rsdpg-128-fast, cross-rsdpg-128-small
- cross-rsdpg-192-balanced, cross-rsdpg-192-fast, cross-rsdpg-192-small
- cross-rsdpg-256-balanced, cross-rsdpg-256-fast, cross-rsdpg-256-small
- Dilithium2, Dilithium3, Dilithium5
- Falcon-512, Falcon-1024
- MAYO-1, MAYO-2, MAYO-3, MAYO-5
- ML-DSA-44, ML-DSA-65, ML-DSA-87
- SPHINCS+-SHA2-128f-simple, SPHINCS+-SHA2-128s-simple
- SPHINCS+-SHA2-192f-simple, SPHINCS+-SHA2-192s-simple
- SPHINCS+-SHA2-256f-simple, SPHINCS+-SHA2-256s-simple
- SPHINCS+-SHAKE-128f-simple, SPHINCS+-SHAKE-128s-simple
- SPHINCS+-SHAKE-192f-simple, SPHINCS+-SHAKE-192s-simple
- SPHINCS+-SHAKE-256f-simple, SPHINCS+-SHAKE-256s-simple
- OV-Is, OV-Ip, OV-III, OV-V
- OV-Is-pkc, OV-Ip-pkc, OV-III-pkc, OV-V-pkc
- OV-Is-pkc-skc, OV-Ip-pkc-skc, OV-III-pkc-skc, OV-V-pkc-skc
-
Initialize a signature algorithm:
rust-seal init sig --signature-algorithm Dilithium2
-
Sign your document:
rust-seal sign important-document.pdf --signature-algorithm Dilithium2
-
Verify the signature:
rust-seal verify important-document.pdf --signature-algorithm Dilithium2
-
Initialize a KEM algorithm:
rust-seal init kem --kem-algorithm Kyber512
-
Encrypt a file:
rust-seal encrypt-file confidential.txt --kem-algorithm Kyber512
-
Decrypt the file:
rust-seal decrypt-file confidential.txt.dec --kem-algorithm Kyber512
- Keep your private keys secure and never share them
- Public keys can be safely shared with others for verification and encryption
- Always verify signatures from untrusted sources
- Choose appropriate algorithm security levels based on your threat model
- replace
oqs.rswith a new version ofoqswherealgorithmenums have aFromStrimplementation-
$\to$ see open-quantum-safe/liboqs-rust#292
-
- add cli hints when typing algorithms
-
$\to$ clap-complete
-
- add a command to verify own public key (via certificate) and save that instead of the plain pub key
-
$\to$ while verifying the signature it can be assured that the public key was not altered -
$\to$ makes sure that the whole verifying process is trustable!
-