Skip to content

wasm-v26.1.22

Choose a tag to compare

@github-actions github-actions released this 04 Feb 22:30
· 193 commits to master since this release
Add nonce incrementor for per-field encryption

Implement 96-bit nonce derivation to prevent nonce reuse in AES-CTR mode.
Each field gets a unique nonce via: nonceStart + (recordIndex * 65536 + fieldId)

Breaking changes:
- EncryptionHeader.iv replaced with nonceStart (12 bytes)
- Header version bumped to 2
- EncryptionContext now requires nonceStart parameter

New APIs:
- generateNonceStart() - CSPRNG 12-byte nonce generation
- deriveNonce(nonceStart, recordIndex) - 96-bit big-endian addition
- EncryptionContext: getNonceStart(), getRecordIndex(), setRecordIndex(),
  nextRecordIndex(), deriveFieldNonce()

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>