{"id":37083379,"url":"https://github.com/kpdemetriou/spectral-aead","last_synced_at":"2026-01-14T10:10:09.197Z","repository":{"id":57469743,"uuid":"138607311","full_name":"kpdemetriou/spectral-aead","owner":"kpdemetriou","description":"An algorithm for authenticated encryption with associated data using Speck and HMAC-SHA256.","archived":false,"fork":false,"pushed_at":"2018-06-30T09:55:39.000Z","size":1363,"stargazers_count":2,"open_issues_count":0,"forks_count":1,"subscribers_count":0,"default_branch":"master","last_synced_at":"2025-11-02T21:19:34.367Z","etag":null,"topics":["cffi","cipher","ciphers","cryptography","decryption","encryption","hash","hash-functions","hmac","message-authentication-code","python","sha256","speck"],"latest_commit_sha":null,"homepage":"https://pypi.org/project/spectral-aead/","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kpdemetriou.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2018-06-25T14:36:37.000Z","updated_at":"2024-03-02T14:58:04.000Z","dependencies_parsed_at":"2022-09-19T09:50:42.387Z","dependency_job_id":null,"html_url":"https://github.com/kpdemetriou/spectral-aead","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/kpdemetriou/spectral-aead","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kpdemetriou%2Fspectral-aead","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kpdemetriou%2Fspectral-aead/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kpdemetriou%2Fspectral-aead/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kpdemetriou%2Fspectral-aead/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kpdemetriou","download_url":"https://codeload.github.com/kpdemetriou/spectral-aead/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kpdemetriou%2Fspectral-aead/sbom","scorecard":{"id":568931,"data":{"date":"2025-08-11","repo":{"name":"github.com/kpdemetriou/spectral-aead","commit":"08c4705af74223832afe947ba9e20bf5bb9d6487"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/1 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}}]},"last_synced_at":"2025-08-20T15:47:20.517Z","repository_id":57469743,"created_at":"2025-08-20T15:47:20.517Z","updated_at":"2025-08-20T15:47:20.517Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28416626,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T08:38:59.149Z","status":"ssl_error","status_checked_at":"2026-01-14T08:38:43.588Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cffi","cipher","ciphers","cryptography","decryption","encryption","hash","hash-functions","hmac","message-authentication-code","python","sha256","speck"],"created_at":"2026-01-14T10:10:08.480Z","updated_at":"2026-01-14T10:10:09.187Z","avatar_url":"https://github.com/kpdemetriou.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Spectral AEAD\n\nSpectral is algorithm for authenticated encryption with associated data; it uses [Speck](https://csrc.nist.gov/csrc/media/events/lightweight-cryptography-workshop-2015/documents/papers/session1-shors-paper.pdf) in [CTR mode](https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf) as the underlying cipher (with a 128-bit block size and a 128-bit key size) along with [HMAC](https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.198-1.pdf)-[SHA256](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf) in an [Encrypt-then-MAC](https://www.iso.org/standard/46345.html) construction.\n\nThis package provides tested, performant **Python 3** CFFI bindings to an implementation of Spectral, including abstractions for simplified encryption and decryption.\n\n# Installation\n\nYou can install this package using `pip` or the included `setup.py` script:\n\n    # Using pip\n    pip install spectral-aead\n    \n    # Using setup.py\n    python setup.py install\n\n# Usage\n\n```python\nfrom spectral import *\n\n# Demonstration key, nonce, plaintext and associated data\nkey = b\"\\0\" * spectral.KEY_SIZE\nnonce = b\"\\0\" * spectral.NONCE_SIZE\nplaintext = b\"\\0\" * 16\nassociated = b\"\\0\" * 16\n\n# Spectral simplified encryption\nencrypted = encrypt(key, plaintext, associated)  # Associated data is optional\n\n# Spectral simplified decryption\ncomputed_plaintext = decrypt(key, encrypted, associated)  # Raises RuntimeError if any parameter has been tampered with\nassert plaintext == computed_plaintext\n\n# Spectral disjoint encryption\nciphertext, mac = encrypt_disjoint(key, nonce, plaintext, associated)  # Associated data is optional\n\n# Spectral disjoint decryption\ncomputed_plaintext = decrypt_disjoint(key, nonce, ciphertext, mac, associated)  # Raises RuntimeError if any parameter has been tampered with\nassert plaintext == computed_plaintext\n```\n\n# License\n```text\nBSD 3-Clause License\n\nCopyright (c) 2018, Phil Demetriou\nAll rights reserved.\n\nRedistribution and use in source and binary forms, with or without\nmodification, are permitted provided that the following conditions are met:\n\n* Redistributions of source code must retain the above copyright notice, this\n  list of conditions and the following disclaimer.\n\n* Redistributions in binary form must reproduce the above copyright notice,\n  this list of conditions and the following disclaimer in the documentation\n  and/or other materials provided with the distribution.\n\n* Neither the name of the copyright holder nor the names of its\n  contributors may be used to endorse or promote products derived from\n  this software without specific prior written permission.\n\nTHIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS \"AS IS\"\nAND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE\nIMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE\nDISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE\nFOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL\nDAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR\nSERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER\nCAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,\nOR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE\nOF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.\n```","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkpdemetriou%2Fspectral-aead","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkpdemetriou%2Fspectral-aead","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkpdemetriou%2Fspectral-aead/lists"}