Umbral
Installation
npm install umbral
Initialization
The module must be initialized with a sodium instance.
await _sodium.ready; ;
Public Interfaces
IKey
Dictionary of {id: key} key-value pairs, where the id
identifies the options counselor the key belongs to. This assumes that each options counselor can be identified by an uuid.
/** * Dictionary of {id: key} */
IMalformed
Object for storing errors in either the encryption or decryption workflow. Within encryption, the id
serves to notify the input that an error occurred on. For decryption, the id
corresponds to a particular IEncryptedData
, described below. For both workflows the error field contains exact errors produced.
/** * Object for storing errors */
IEncryptedData
Object containing the ciphertext resulting from encryption using a single perpId and a single OC's public key. The number of IEncryptedData
objects at the end of the encryption worfklow should equal the number of perpetrator IDs submitted multiplied by the number of OCs.
/** * Encrypted data object */
IOCDataMap
A dictionary mapping each options counselor, identified through an id, to an array of encrypted data objects that have all been encrypted under the OC's public key.
/** * Mapping of OC id to matching records */
IEncryptedMap
Dictionary represents the mapping of a matching index to all the records that have the same matching index encrypted under each options counselor's public key.
/** * Mapping of matching index to all matching records under a specific OC */
IEncrypted
At the end of the encryption workflow, a single object will be returned in the following form. The encryptedMap should contain as many matching indices as submitted perpIds. Corresponding to each matching index is the IOCDataMap
for each options counselor, containing their corresponding ciphertexts.
/** * Data object returned from encryption workflow */
IDecrypted
Decryption returns the following object containing an array of user records and an array of malformed objects where decryption did not properly occur.
/** * Data returned from decryption workflow */
Encryption
This function must be provided with a dictionary of public keys in the form of IKey
key-value pairs (pkOCs). It will return all of the encrypted data in IEncrypted
form.
/** * Encryption workflow * @param randIds - array of all randIds corresponding to each perpId submitted * @param userId - user's uuid * @param data - record information * @param pkOCs - dictionary of all OC public keys * @param userPassPhrase - user's passphrase for use in encrypting for editing * @returns */ public encryptDatarandIds: Uint8Array, userId: string, data: string, pkOCs: IKey, userPassPhrase: Uint8Array: IEncrypted
Decryption
The function should be provided with matched encrypted records encrypted under a specific OC's public key.
/** * Decryption workflow * @param * @param pkOC - public key of an options counselor * @param skOC - secret key of an options counselor * @returns {IDecrypted]} object containing decrypted records and errors */ public decryptDataencryptedData: IEncryptedData, pkOC: Uint8Array, skOC: Uint8Array: IDecrypted
End-to-End Example
The following example involves two users and two options counselors.
; await _sodium.ready; ; ; ; ; ; ; updateDictencryptedDict, encryptedDataA.encryptedMap; ; updateDictencryptedDict, encryptedDataB.encryptedMap; for in encryptedDict
Additional examples can be found under test/tests.ts