OapCrypto

Per-asset encryption for OAP blobs (spec §5.2). Encryption is applied to the already-compressed bytes and is its own inverse for every supported codec, so a single Apply call performs both encryption and decryption.

Remarks

The key is supplied by the application and is never stored in the package, so the asset bytes cannot be recovered from the file alone. This deters casual extraction; it is not DRM and does not defend against an attacker who controls the running process.

Fields

KeyLength (int) = 32: Length of an OAP encryption key, in bytes (256 bits).

NonceLength (int) = 12: Length of the per-asset nonce, in bytes.

Public Methods

DeriveKey

public static byte[] DeriveKey(string passphrase)

Derives a 256-bit key from an arbitrary passphrase with SHA-256. Not salted — suitable for the lightweight-protection use case, not for password storage.

Parameters:

  • passphrase (string): The passphrase.

Returns: byte[]

  • A 32-byte key.

NonceFor

public static byte[] NonceFor(ReadOnlySpan<byte> assetId, uint contentCrc32)

Derives the deterministic per-asset nonce: the first 12 bytes of SHA-256(asset_id ‖ content_crc32), where content_crc32 is the little-endian 4-byte index field. Both inputs are known to a reader before decryption, and the pair is unique per asset within a package.

Parameters:

  • assetId (ReadOnlySpan): The 16 raw asset-id bytes (big-endian, as stored).
  • contentCrc32 (uint): The plaintext CRC-32 from the index entry.

Returns: byte[]

  • A 12-byte nonce.

Apply

public static void Apply(OapEncryption codec, ReadOnlySpan<byte> key, ReadOnlySpan<byte> assetId, uint contentCrc32, Span<byte> buffer)

Encrypts or decrypts buffer in place with codec. A no-op for None.

Parameters:

  • codec (OapEncryption): The cipher to apply.
  • key (ReadOnlySpan): The 32-byte key.
  • assetId (ReadOnlySpan): The 16 raw asset-id bytes.
  • contentCrc32 (uint): The plaintext CRC-32 from the index entry.
  • buffer (Span): The bytes to transform in place.