Poly1305 (RFC 8439 §2.5) — 128-bit one-time MAC, companion to ChaCha20.
Module poly1305 | Source packages/front/fw/src/crypto/hash/poly1305.js | Deps none | Worker-safe yes
One-time MAC: the same key (one-time-key) MUST NEVER be reused for 2 messages — otherwise the key can be recovered. Used in chacha20poly1305 which derives a fresh polyKey per message via ChaCha20 block 0.
Resolve
const poly1305 = runtime.resolve('poly1305');
// Returns: { mac, verify }
API
| Method | Signature | Returns |
|---|---|---|
mac |
(key: Uint8Array(32), msg: Uint8Array) => Uint8Array(16) |
128-bit tag |
verify |
(key, msg, expectedTag) => boolean |
Constant-time comparison |
Examples
const { poly1305, hex } = fw.runtime.resolveAll(['poly1305', 'hex']);
const key = hex.toBytes('85d6be7857556d337f4452fe42d506a80103808afb0db2fd4abff6af4149f51b');
const msg = new TextEncoder().encode('Cryptographic Forum Research Group');
const tag = poly1305.mac(key, msg);
hex.fromBytes(tag);
// "a8061dc1305136c6c22b8baf0c0127a9"
Constant-time verify
const ok = poly1305.verify(key, msg, expectedTag); // false if modified
Worker Usage
const worker = fw.createWorker(
function ({ libs, args }) {
self.postMessage(libs.poly1305.mac(args[0], args[1]));
},
{ dependencies: ['poly1305'], args: [key, msg] }
);
Notes
- One-time key: NEVER reuse the same key for 2 distinct messages.
- Fixed 128-bit tag; no truncation (unlike HMAC/CMAC).
- Outside NIST: no FIPS, validation = RFC 8439 §2.5.2 + §A.3 (11 vectors incl. carry single/multi-block + crossing 2¹³⁰).
See also
- chacha20poly1305 — full AEAD using
poly1305 - chacha20 — for deriving a fresh
polyKeyper message - Conformance poly1305.acvp.md