Hardware Cryptography
Hardware-accelerated cryptographic API reference for SHA-256 hashing, HMAC signatures, AES-128/256-CBC encryption, and secure entropy in KryonOS.
Hardware Cryptography: Crypto
The Crypto (or System.crypto) object leverages the ESP32's on-chip hardware cryptographic acceleration unit. It performs SHA-256 hashing, AES symmetric encryption, and secure key derivation in hardware registers without loading CPU cores.
Security architectures and source drivers are located on the KryonOS GitHub Repository.
1. Hash & Digest Algorithms
Crypto.sha256(data)
Generates a 256-bit SHA-256 hash using the hardware acceleration engine.
- Parameters:
data(String,ArrayBuffer, orUint8Array). - Returns:
String(64-character lowercase hexadecimal hash).
var digest = Crypto.sha256("KryonOS-Secure-Payload");
System.print("SHA-256: " + digest);
Crypto.hmacSha256(key, message)
Generates an HMAC-SHA256 signature for API token validation and wireless mesh authentication.
- Parameters:
key(String): Secret key string.message(String): Payload message.
- Returns:
String(64-character hexadecimal signature).
2. Symmetric AES Encryption / Decryption
KryonOS provides hardware-accelerated AES-CBC (Cipher Block Chaining) with support for 128-bit and 256-bit keys and PKCS#7 padding.
Crypto.aesEncrypt(plainText, keyHex, ivHex)
Encrypts a plaintext string into a hex ciphertext.
- Parameters:
plainText(String): Text to encrypt.keyHex(String): 32-char (AES-128) or 64-char (AES-256) hex string.ivHex(String): 32-char (16-byte) initialization vector hex string.
- Returns:
String(Hexadecimal ciphertext).
Crypto.aesDecrypt(cipherTextHex, keyHex, ivHex)
Decrypts an AES-CBC ciphertext back to the original string.
- Parameters:
cipherTextHex(String)keyHex(String)ivHex(String)
- Returns:
String(Decrypted plaintext string) ornullif decryption fails.
var key = "000102030405060708090a0b0c0d0e0f"; // 128-bit key
var iv = "101112131415161718191a1b1c1d1e1f"; // 16-byte IV
var message = "Confidential Device Secret";
var encrypted = Crypto.aesEncrypt(message, key, iv);
System.print("Ciphertext: " + encrypted);
var decrypted = Crypto.aesDecrypt(encrypted, key, iv);
System.print("Decrypted: " + decrypted);
3. Cryptographic Entropy & Random Bytes
Crypto.randomBytes(length)
Generates an array of cryptographically secure random bytes directly from the RF/thermal noise hardware TRNG generator.
- Parameters:
length(Integer): Number of random bytes requested. - Returns:
Uint8Arraycontaining raw entropy bytes.