Radar · Go · Archive · Week 47 · Nov 17 – 23, 2025
crypto/hpke: new package
Nice to knowstdlib
- What changed
- A new
crypto/hpkepackage has been added, providing the base mode of the HPKE IETF standard. - Production impact
- The source does not say.
- Try it
- Import
crypto/hpkeand callNewSenderto create an HPKE sender. - Source
- github.com/golang/go/issues/75300
Understand it, then run it
A new crypto/hpke package has been added to the Go standard library. It implements the base mode of the HPKE IETF standard, which is a hybrid encryption scheme that combines a public‑key key‑encapsulation mechanism (KEM) with a symmetric key‑derivation function (KDF) and an authenticated encryption algorithm (AEAD). Before this change Go had no built‑in support for HPKE; developers had to use third‑party libraries or roll their own. With the new package you can now create a sender and a recipient, encrypt data with Seal, and decrypt it with Open, all using the same ciphersuite.
Run it now
// This program demonstrates the new crypto/hpke package in Go 1.27.1.
// It generates a DHKEM key pair, encrypts a message, then decrypts it.
package main
import (
"crypto/ecdh"
"crypto/hpke"
"fmt"
)
func main() {
// Choose the X25519 curve for the KEM.
kem := hpke.DHKEM(ecdh.X25519())
// Generate a key pair.
priv, err := kem.GenerateKey()
if err != nil {
panic(err)
}
pub := priv.PublicKey()
// Define the ciphersuite: use the same KEM, HKDF-SHA256, and AES-128-GCM.
kdf := hpke.HKDFSHA256()
aead := hpke.AES128GCM()
// Sender side: create a context and seal a message.
enc, sender, err := hpke.NewSender(pub, kdf, aead, []byte("info"))
if err != nil {
panic(err)
}
plaintext := []byte("Hello, HPKE!")
ciphertext, err := sender.Seal(nil, plaintext)
if err != nil {
panic(err)
}
fmt.Printf("Ciphertext: %x\n", ciphertext)
// Recipient side: create a context and open the ciphertext.
recipient, err := hpke.NewRecipient(enc, priv, kdf, aead, []byte("info"))
if err != nil {
panic(err)
}
decrypted, err := recipient.Open(nil, ciphertext)
if err != nil {
panic(err)
}
fmt.Printf("Decrypted: %s\n", decrypted)
}
What it printed when we ran it on Go 1.27.1
Ciphertext: ba604d358860c4cc33ef72b25e46b34ef4d7b178bd2d3d1ca2e44faa Decrypted: Hello, HPKE!
After the change ships
go · the proposal's code; it does not compile until the change ships
// This code uses the new crypto/hpke package. It will not compile until
// the package is available in the Go release.
package main
import (
"crypto/hpke"
"crypto/ecdh"
"fmt"
)
func main() {
kem := hpke.DHKEM(ecdh.X25519)
priv, _ := kem.GenerateKey()
pub := priv.PublicKey()
info := []byte("example context")
enc, sender, _ := hpke.NewSender(pub, hpke.HKDFSHA256(), hpke.AES128GCM(), info)
plaintext := []byte("Hello, HPKE!")
ciphertext, _ := sender.Seal(nil, plaintext)
recipient, _ := hpke.NewRecipient(enc, priv, hpke.HKDFSHA256(), hpke.AES128GCM(), info)
decrypted, _ := recipient.Open(nil, ciphertext)
fmt.Printf("Decrypted: %s\n", decrypted)
}
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed