关于在libsodium与OpenSSL中使用无认证ChaCha20的技术咨询
I was recently experimenting with unauthenticated ChaCha20 encryption, and ran into some library-specific quirks worth sharing:
Libsodium Doesn't Support Unauthenticated ChaCha20
First off, libsodium doesn't expose an API for using ChaCha20 without authentication. All its ChaCha20-related functionality is tied directly to the authenticated ChaCha20-Poly1305 construction—you can't use the stream cipher on its own without the Poly1305 integrity check baked in.
OpenSSL Offers Low-Level Support (But No Ready-Made Encrypt/Decrypt Wrappers)
OpenSSL does allow for unauthenticated ChaCha20 usage, but only via a low-level counter-mode function:
void ChaCha20_ctr32(unsigned char *out, const unsigned char *inp, size_t len, const unsigned char *key, const unsigned char *nonce, size_t counter)
This function handles the core ChaCha20 stream generation and XOR operation with your input data, but it's a bare-bones utility. There are no higher-level "encrypt" or "decrypt" functions here—you'll have to implement all surrounding logic yourself, including:
- Ensuring unique nonces for every encryption operation (this is critical for ChaCha20 security)
- Managing the counter value correctly
- Remembering that encryption and decryption are identical operations (both just XOR the target data with the generated ChaCha20 stream)
A quick note: since there's no authentication layer, you'll want to add your own integrity check (like a hash or HMAC) if you need to verify your data hasn't been tampered with—otherwise you're only getting confidentiality, not integrity.
内容的提问来源于stack exchange,提问作者fraiser

