summaryrefslogtreecommitdiffstats
path: root/poc/spike1_crypto.py
diff options
context:
space:
mode:
Diffstat (limited to 'poc/spike1_crypto.py')
-rw-r--r--poc/spike1_crypto.py18
1 files changed, 11 insertions, 7 deletions
diff --git a/poc/spike1_crypto.py b/poc/spike1_crypto.py
index 335758c..4006506 100644
--- a/poc/spike1_crypto.py
+++ b/poc/spike1_crypto.py
@@ -4,17 +4,20 @@ MeshBay — Spike 1: Crypto Primitives
Validates the full cryptographic stack needed for MeshBay.
"""
-import os, time, base64, sys
+import base64
+import os
+import sys
+import time
+import blake3
+import jwt
+from cryptography.hazmat.primitives import hashes, serialization
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
from cryptography.hazmat.primitives.asymmetric.x25519 import X25519PrivateKey
+from cryptography.hazmat.primitives.ciphers import Cipher, algorithms, modes
from cryptography.hazmat.primitives.ciphers.aead import ChaCha20Poly1305
-from cryptography.hazmat.primitives.kdf.hkdf import HKDF
from cryptography.hazmat.primitives.kdf.argon2 import Argon2id
-from cryptography.hazmat.primitives import hashes, serialization
-from cryptography.hazmat.primitives.ciphers import Cipher, algorithms, modes
-import blake3
-import jwt
+from cryptography.hazmat.primitives.kdf.hkdf import HKDF
PASS = "✓"
FAIL = "✗"
@@ -240,7 +243,8 @@ print("\n=== Test 7: AES-256-GCM — Keystore encryption ===")
def test_aes_gcm_keystore():
# Derive an AES key from Argon2id (as done for keystore unlock)
salt = os.urandom(16)
- aes_key = Argon2id(salt=salt, length=32, iterations=3, lanes=4, memory_cost=65536).derive(b"password")
+ aes_key = Argon2id(salt=salt, length=32, iterations=3, lanes=4,
+ memory_cost=65536).derive(b"password")
# Encrypt a mock keystore blob
keystore_data = b'{"sk_user": "base64...", "sk_group": "base64..."}'