1import{d as l}from"./crypto-libs-bzyQcwC4.js";const K=6e5,m=64,h=12,p=new TextEncoder().encode("confible-ml-kem-1024-key-envelope-v1"),w=new TextEncoder().encode("confible-ml-kem-1024-seed-v1"),g="ML-KEM-1024-FIPS-203",s=new Map,y=new Map;function E(...e){const n=new Uint8Array(e.reduce((t,i)=>t+i.length,0));let r=0;for(const t of e)n.set(t,r),r+=t.length;return n}function o(e){return e.buffer.slice(e.byteOffset,e.byteOffset+e.byteLength)}async function d(e,n){const r=await crypto.subtle.digest("SHA-256",o(n)),t=await crypto.subtle.importKey("raw",o(e),"HKDF",!1,["deriveKey"]);return crypto.subtle.deriveKey({name:"HKDF",hash:"SHA-256",salt:r,info:o(p)},t,{name:"AES-GCM",length:256},!1,["encrypt","decrypt"])}async function u(e){const n=await crypto.subtle.digest("SHA-256",o(e));return Array.from(new Uint8Array(n),r=>r.toString(16).padStart(2,"0")).join("")}async function M(e,n){const r=await crypto.subtle.importKey("raw",new TextEncoder().encode(e),"PBKDF2",!1,["deriveBits"]),t=E(n,w),i=await crypto.subtle.deriveBits({name:"PBKDF2",salt:o(t),iterations:K,hash:"SHA-256"},r,m*8),c=new Uint8Array(i);try{const a=l.keygen(c);return{publicKey:a.publicKey,secretKey:a.secretKey}}finally{c.fill(0)}}async function S(e,n){const r=await u(n);let t=s.get(r);if(!t){const{cipherText:a,sharedSecret:f}=l.encapsulate(n);try{t={wrappingKey:await d(f,a),kemCiphertext:new Uint8Array(a)},s.set(r,t)}finally{f.fill(0)}}const i=crypto.getRandomValues(new Uint8Array(h)),c=await crypto.subtle.encrypt({name:"AES-GCM",iv:i,additionalData:o(p),tagLength:128},t.wrappingKey,e);return{ciphertext:new Uint8Array(c),iv:i,kemCiphertext:new Uint8Array(t.kemCiphertext),publicKeyFingerprint:r}}async function T(e,n){const r=await u(n.publicKey);if(r!==e.publicKeyFingerprint)throw new Error("POST_QUANTUM_KEY_MISMATCH");const t=Array.from(e.kemCiphertext,a=>a.toString(16).padStart(2,"0")).join(""),i=`${r}:${t}`;let c=y.get(i);try{if(!c){const a=l.decapsulate(e.kemCiphertext,n.secretKey);try{c=await d(a,e.kemCiphertext),y.set(i,c)}finally{a.fill(0)}}return await crypto.subtle.decrypt({name:"AES-GCM",iv:e.iv,additionalData:o(p),tagLength:128},c,e.ciphertext)}catch{throw new Error("POST_QUANTUM_ENVELOPE_AUTHENTICATION_FAILED")}}function _(){s.clear(),y.clear()}function b(e){e?.secretKey.fill(0)}export{g as POST_QUANTUM_KEM_ALGORITHM,b as clearMlKem1024SecretKey,_ as clearPostQuantumEnvelopeCache,M as deriveMlKem1024KeyPair,u as fingerprintMlKemPublicKey,S as protectKeyWithMlKem1024,T as recoverKeyWithMlKem1024};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.