Crypto Lib
    Preparing search index...

    Function hpkeOpen

    • Decrypt (open) an HPKE ciphertext.

      Decapsulates the shared secret using the recipient's private key, re-derives the AEAD key material, and decrypts the ciphertext.

      Parameters

      • options: {
            recipientPrivateKey: string;
            encapsulatedKey: string;
            ciphertext: string;
            info?: string;
            aad?: string;
            suite?: HpkeSuiteOptions;
            psk?: HpkePskOptions;
        }

        Open options.

        • recipientPrivateKey: string

          Hex-encoded recipient private key.

        • encapsulatedKey: string

          Hex-encoded encapsulated key (from seal).

        • ciphertext: string

          Hex-encoded ciphertext (from seal).

        • Optionalinfo?: string

          Hex-encoded info string (must match seal).

        • Optionalaad?: string

          Hex-encoded additional authenticated data (must match seal).

        • Optionalsuite?: HpkeSuiteOptions

          Cipher suite selection (must match seal).

        • Optionalpsk?: HpkePskOptions

          Pre-shared key options (must match seal).

      Returns HpkeOpenResult

      Hex-encoded plaintext.

      const kp = hpkeGenerateKeyPair();
      const sealed = hpkeSeal({
      recipientPublicKey: kp.publicKey,
      plaintext: "48656c6c6f",
      });
      const opened = hpkeOpen({
      recipientPrivateKey: kp.privateKey,
      encapsulatedKey: sealed.encapsulatedKey,
      ciphertext: sealed.ciphertext,
      });
      console.log(opened.plaintext); // "48656c6c6f"