Poly1305 (RFC 8439 §2.5) — 128-bit one-time MAC, companion to ChaCha20.

Module poly1305 | Source packages/front/fw/src/crypto/hash/poly1305.js | Deps none | Worker-safe yes

One-time MAC: the same key (one-time-key) MUST NEVER be reused for 2 messages — otherwise the key can be recovered. Used in chacha20poly1305 which derives a fresh polyKey per message via ChaCha20 block 0.

Resolve

const poly1305 = runtime.resolve('poly1305');
// Returns: { mac, verify }

API

Method Signature Returns
mac (key: Uint8Array(32), msg: Uint8Array) => Uint8Array(16) 128-bit tag
verify (key, msg, expectedTag) => boolean Constant-time comparison

Examples

const { poly1305, hex } = fw.runtime.resolveAll(['poly1305', 'hex']);

const key = hex.toBytes('85d6be7857556d337f4452fe42d506a80103808afb0db2fd4abff6af4149f51b');
const msg = new TextEncoder().encode('Cryptographic Forum Research Group');
const tag = poly1305.mac(key, msg);
hex.fromBytes(tag);
// "a8061dc1305136c6c22b8baf0c0127a9"

Constant-time verify

const ok = poly1305.verify(key, msg, expectedTag);   // false if modified

Worker Usage

const worker = fw.createWorker(
    function ({ libs, args }) {
        self.postMessage(libs.poly1305.mac(args[0], args[1]));
    },
    { dependencies: ['poly1305'], args: [key, msg] }
);

Notes

  • One-time key: NEVER reuse the same key for 2 distinct messages.
  • Fixed 128-bit tag; no truncation (unlike HMAC/CMAC).
  • Outside NIST: no FIPS, validation = RFC 8439 §2.5.2 + §A.3 (11 vectors incl. carry single/multi-block + crossing 2¹³⁰).

See also