preprint Open access

dcrypt: A Modern, High-Assurance Cryptographic Library in Rust

  • Zenodo (CERN European Organization for Nuclear Research)
  • European Organization for Nuclear Research
Research footprint

At a glance

Citations
0
References
0
Comments
0
Paper overview

Abstract

The emergence of quantum computing threatens the security of widely deployed public-key cryptosystems, necessitating a transition to post-quantum cryptography (PQC). We present dcrypt, a comprehensive cryptographic library implemented entirely in safe Rust that provides both classical and NIST-standardized post-quantum algorithms alongside novel hybrid constructions. dcrypt is the first publicly released, production-ready implementation of the complete CRYSTALS-Dilithium / ML-DSA signature scheme in pure Rust with zero unsafe code, zero FFI dependencies, and full constant-time execution. It is also the first pure-Rust library to provide native hybrid key encapsulation mechanisms (ECDH + Kyber) and hybrid digital signatures (ECDSA + Dilithium) as composable cryptographic primitives. The library's architecture enforces memory safety through Rust's ownership model, eliminates entire classes of vulnerabilities common in C/C++ cryptographic implementations, and maintains constant-time execution verified through an integrated constant-time verification suite. Performance benchmarks demonstrate that pure-Rust post-quantum cryptography achieves production-grade speeds, with hybrid constructions introducing less than 10% overhead compared to post-quantum–only implementations. dcrypt provides a high-assurance foundation for quantum-resistant applications across embedded systems, enterprise infrastructure, and decentralized networks.

Record transparency

Publication details

DOI
10.5281/zenodo.17675035
OpenAlex
W7106330409
Document type
preprint
Language
EN
Source
Zenodo (CERN European Organization for Nuclear Research)
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.