NskeyProvider class
Layer 2 of the nskey data path: conveys a symmetric content key.
A value routed here is a sealed CK — the <ckKid>.__ck.<ns>@<owner>
record. encrypt takes the CK's base64 bytes and returns the pqSeal
envelope; decrypt opens it with the namespace's nskey private and
caches the CK, so the at/symmetric/AES/GCM provider can resolve it by
ckKid when the data value arrives.
Application data never passes through this provider — an nskey encapsulates content keys and nothing else.
- Implemented types
Constructors
- NskeyProvider({required NskeyKeyRing keyRing, required ContentKeyCache cache, String keyAlgo = SecretSharingAlgos.xWing, AtKemAlgorithm? kem})
Properties
- cache → ContentKeyCache
-
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- id → String
-
Stable wire id, stamped into
appMetadata.providerId.no setteroverride - keyAlgo → String
-
The key-establishment algorithm this instance conveys under. One instance
per KEM, each with its own id, so a record routes back to the one that
can open it.
final
- keyRing → NskeyKeyRing
-
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
Methods
-
canHandle(
AtKey atKey) → bool -
The nskey data path is scoped to
(owner, namespace)throughout — the key ring, the CK cache and the HPKE binding all take a namespace — so a key without one cannot be served here at all.override -
decrypt(
CryptoContext context, AtKey atKey, String ciphertext) → Future< String> -
Decrypt wire
ciphertextforatKey, returning the plaintext.override -
encrypt(
CryptoContext context, AtKey atKey, String plaintext) → Future< String> -
Seals the CK in
plaintextintoatKey's conveyance record.override -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited