Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 18 additions & 4 deletions src/encryption/core.rs
Original file line number Diff line number Diff line change
Expand Up @@ -283,12 +283,11 @@ impl ZeroKnowledgeEncryptor {
true
}

// Runtime detection for AArch64 crypto extensions
// NEON is default on every aarch64 target, so a cfg!(target_feature = "neon")
// check is const true and says nothing about AES (Cortex-A72 / Pi 3-4: NEON, no AES).
#[cfg(not(target_feature = "aes"))]
{
// ARM crypto extensions are usually available on modern ARM64
// ring library will use them automatically if available
return cfg!(target_feature = "neon");
std::arch::is_aarch64_feature_detected!("aes")
}
}

Expand Down Expand Up @@ -605,6 +604,21 @@ impl ZeroKnowledgeEncryptor {
mod tests {
use super::*;

// Both probes fold to const true under compile-time aes, so the cfg short-circuit is pinned too.
#[cfg(any(target_arch = "x86", target_arch = "x86_64", target_arch = "aarch64"))]
#[test]
fn test_hardware_acceleration_matches_platform_probe() {
let reported = ZeroKnowledgeEncryptor::new()
.unwrap()
.hardware_acceleration_enabled();

#[cfg(any(target_arch = "x86", target_arch = "x86_64"))]
assert_eq!(reported, std::arch::is_x86_feature_detected!("aes"));

#[cfg(target_arch = "aarch64")]
assert_eq!(reported, std::arch::is_aarch64_feature_detected!("aes"));
}

#[test]
fn test_encrypt_decrypt_roundtrip() {
let encryptor = ZeroKnowledgeEncryptor::new().unwrap();
Expand Down
2 changes: 1 addition & 1 deletion src/encryption/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
//! # Features
//! - **AES-256-GCM. Not configurable by design.** Authenticated encryption with ring library
//! - HKDF-SHA256 key derivation with domain separation (RFC 5869)
//! - Hardware acceleration detection and usage (AES-NI)
//! - Hardware acceleration capability detection (AES-NI / Armv8 Crypto Extension)
//! - Per-tenant key isolation with cryptographic guarantees
//! - Zero-knowledge guarantees: storage never sees plaintext or keys

Expand Down
3 changes: 2 additions & 1 deletion src/metrics.rs
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,8 @@ pub struct OperationMetrics {
/// Encryption operation time in microseconds (None if not performed)
pub encryption_time_micros: Option<u64>,

/// Whether hardware acceleration was used (for SHA, AES, etc.)
/// Whether the CPU reports AES hardware (AES-NI / Armv8 Crypto Extension).
/// Informational only: the crypto backend dispatches on its own detection.
pub hardware_accelerated: bool,
}

Expand Down
Loading