AesCtrFfiCipher class final

Incremental AES-CTR, backed by OpenSSL 3 via Dart FFI, for encrypting a byte stream whose chunk boundaries are not under the caller's control.

One instance owns one EVP_CIPHER_CTX for its whole life. EVP_aes_*_ctr reports a block size of 1, so update emits exactly as many bytes as it is given and the keystream offset within the current counter block is carried in the context. Chunks may therefore be any size, including sizes that straddle a block boundary.

This is raw CTR: no padding, no authentication tag, no framing. That is deliberately unlike AesCtrFfiAlgo and AESEncryptionAlgo, the one-shot pair, which PKCS7-pad for compatibility with data already on the wire. Do not mix the two on one channel.

Encryption and decryption are the same operation in CTR, so there is one class and one direction per instance. The instance that decrypts a stream takes the same key and IV as the one that encrypted it.

A duplex channel is two streams, and each needs its own IV. Running both directions of a tunnel from one (key, IV) pair XORs the two plaintexts together under a single keystream, which recovers both from the ciphertext alone. Derive or transmit a separate IV per direction.

Ownership

The context is a native resource whose lifetime outlives any single method call, which nothing else in at_chops has. The caller must call dispose — on the error and cancellation paths as much as the happy one. A stream adapter wrapping this class belongs in a try/finally, not a bare map. dispose is idempotent; update after it throws a StateError.

A Finalizer is attached as a backstop for an instance the caller drops without disposing. It is a safety net and not a mechanism: GC timing is unspecified, and a leak of one context per connection will outrun it.

Constructors

AesCtrFfiCipher.fromLib(DynamicLibrary lib, AESKey aesKey, InitialisationVector iv)
Creates a cipher over aesKey starting from counter block iv.
factory

Properties

hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

dispose() → void
Releases the context and every scratch buffer. Safe to call repeatedly.
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited
update(Uint8List input) → Uint8List
Transforms input and returns the result, advancing the keystream.
updateView(Uint8List input) → Uint8List
Transforms input like update, but returns a view directly onto the native output buffer instead of copying it — no per-chunk allocation.

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Constants

ivLength → const int
CTR's IV is the initial counter block, so it is always one AES block.