Uses new Rust 2021
|1.5.2||Aug 23, 2022|
|1.5.1||Jun 27, 2022|
|1.5.0||Mar 30, 2022|
|1.3.3||Dec 29, 2021|
#37 in Cryptography
787,759 downloads per month
Used in 545 crates (24 directly)
RustCrypto: Constant-Time Base64
Pure Rust implementation of Base64 (RFC 4648).
Implements multiple Base64 alphabets without data-dependent branches or lookup tables, thereby providing portable "best effort" constant-time operation.
no_std environments and avoids heap allocations in the core API
(but also provides optional
alloc support for convenience).
This crate implements several Base64 alphabets in constant-time for sidechannel
resistance, aimed at purposes like encoding/decoding the "PEM" format used to
store things like cryptographic private keys (i.e. in the
The paper Util::Lookup: Exploiting key decoding in cryptographic libraries demonstrates how the leakage from non-constant-time Base64 parsers can be used to practically extract RSA private keys from SGX enclaves.
The padded variants require (
=) padding. Unpadded variants expressly
reject such padding.
Supported Base64 variants
- Standard Base64:
- URL-safe Base64:
- bcrypt Base64:
Minimum Supported Rust Version
This crate requires Rust 1.56 at a minimum.
We may change the MSRV in the future, but it will be accompanied by a minor version bump.
Licensed under either of:
at your option.
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.