NskeyProvider class

Layer 2 of the nskey data path: conveys a symmetric content key.

A value routed here is a sealed CK — the <ckKid>.__ck.<ns>@<owner> record. encrypt takes the CK's base64 bytes and returns the pqSeal envelope; decrypt opens it with the namespace's nskey private and caches the CK, so the at/symmetric/AES/GCM provider can resolve it by ckKid when the data value arrives.

Application data never passes through this provider — an nskey encapsulates content keys and nothing else.

Implemented types

Constructors

NskeyProvider({required NskeyKeyRing keyRing, required ContentKeyCache cache, String keyAlgo = SecretSharingAlgos.xWing, AtKemAlgorithm? kem})

Properties

cache → ContentKeyCache
final
hashCode → int
The hash code for this object.
no setterinherited
id → String
Stable wire id, stamped into appMetadata.providerId.
no setteroverride
keyAlgo → String
The key-establishment algorithm this instance conveys under. One instance per KEM, each with its own id, so a record routes back to the one that can open it.
final
keyRing → NskeyKeyRing
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

canHandle(AtKey atKey) → bool
The nskey data path is scoped to (owner, namespace) throughout — the key ring, the CK cache and the HPKE binding all take a namespace — so a key without one cannot be served here at all.
override
decrypt(CryptoContext context, AtKey atKey, String ciphertext) → Future<String>
Decrypt wire ciphertext for atKey, returning the plaintext.
override
encrypt(CryptoContext context, AtKey atKey, String plaintext) → Future<String>
Seals the CK in plaintext into atKey's conveyance record.
override
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited