KRYONOS
Math, Security & Services

Hardware Cryptography

Hardware-accelerated cryptographic API reference for SHA-256 hashing, HMAC signatures, AES-128/256-CBC encryption, and secure entropy in KryonOS.

Hardware Cryptography: Crypto

The Crypto (or System.crypto) object leverages the ESP32's on-chip hardware cryptographic acceleration unit. It performs SHA-256 hashing, AES symmetric encryption, and secure key derivation in hardware registers without loading CPU cores.

Security architectures and source drivers are located on the KryonOS GitHub Repository.


1. Hash & Digest Algorithms

Crypto.sha256(data)

Generates a 256-bit SHA-256 hash using the hardware acceleration engine.

  • Parameters: data (String, ArrayBuffer, or Uint8Array).
  • Returns: String (64-character lowercase hexadecimal hash).
var digest = Crypto.sha256("KryonOS-Secure-Payload");
System.print("SHA-256: " + digest);

Crypto.hmacSha256(key, message)

Generates an HMAC-SHA256 signature for API token validation and wireless mesh authentication.

  • Parameters:
    • key (String): Secret key string.
    • message (String): Payload message.
  • Returns: String (64-character hexadecimal signature).

2. Symmetric AES Encryption / Decryption

KryonOS provides hardware-accelerated AES-CBC (Cipher Block Chaining) with support for 128-bit and 256-bit keys and PKCS#7 padding.

Crypto.aesEncrypt(plainText, keyHex, ivHex)

Encrypts a plaintext string into a hex ciphertext.

  • Parameters:
    • plainText (String): Text to encrypt.
    • keyHex (String): 32-char (AES-128) or 64-char (AES-256) hex string.
    • ivHex (String): 32-char (16-byte) initialization vector hex string.
  • Returns: String (Hexadecimal ciphertext).

Crypto.aesDecrypt(cipherTextHex, keyHex, ivHex)

Decrypts an AES-CBC ciphertext back to the original string.

  • Parameters:
    • cipherTextHex (String)
    • keyHex (String)
    • ivHex (String)
  • Returns: String (Decrypted plaintext string) or null if decryption fails.
var key = "000102030405060708090a0b0c0d0e0f"; // 128-bit key
var iv  = "101112131415161718191a1b1c1d1e1f"; // 16-byte IV

var message = "Confidential Device Secret";
var encrypted = Crypto.aesEncrypt(message, key, iv);
System.print("Ciphertext: " + encrypted);

var decrypted = Crypto.aesDecrypt(encrypted, key, iv);
System.print("Decrypted: " + decrypted);

3. Cryptographic Entropy & Random Bytes

Crypto.randomBytes(length)

Generates an array of cryptographically secure random bytes directly from the RF/thermal noise hardware TRNG generator.

  • Parameters: length (Integer): Number of random bytes requested.
  • Returns: Uint8Array containing raw entropy bytes.

On this page