LrtcCodec class

Encrypts/decrypts the LRTC format: AES-256-GCM with the envelope header as additional authenticated data.

Backed by BoringSSL through package:webcrypto (dart:ffi), so AES and GHASH run on the CPU's crypto instructions where they exist — which is every ARMv8 phone. The whole seal/open is a single native call.

The format version was bumped to 2 over the switch from the pure-Dart 0.1.0 engine (AES-CTR + HMAC-SHA256); v1 files must be re-encrypted.

The working key is derived from the caller's 32-byte key with HKDF-SHA256, mixing in the envelope's label so that each model gets its own working key. Derived key bytes are zeroed as soon as they are used; the caller's key buffer is left untouched (see wipe to clear it yourself). The BoringSSL-side key schedule lives in native memory until the key object is garbage collected — that copy is out of our hands, which the README's threat model already concedes for anything in process memory.

Properties

hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

decrypt(Uint8List bytes, Uint8List key) → Future<Uint8List>
Decrypts LRTC-formatted bytes and returns the plaintext.
decryptEnvelope(LrtcEnvelope envelope, Uint8List key) → Future<Uint8List>
Decrypts an already-parsed envelope.
encrypt(Uint8List plain, Uint8List key, {int keyId = 0, String label = ''}) → Future<Uint8List>
Encrypts plain and returns LRTC-formatted bytes.
wipe(Uint8List bytes) → void
Overwrites bytes with zeros.

Constants

keyLength → const int
Required length of the master key supplied by a KeyProvider.