EDA.Voice.Dave.FrameCrypto (EDA v0.3.0)

Copy Markdown View Source

Per-frame AES-128-GCM encryption for the DAVE (Discord Audio Video E2EE) protocol.

For Opus audio, the first byte (TOC byte) remains unencrypted (authenticated only). The supplemental data is appended at the end of the frame.

Frame format (output):

[unencrypted ranges (clear, authenticated)]
[ciphertext (encrypted)]
--- supplemental bytes ---
[truncated GCM tag (8 bytes)]
[nonce (LEB128 varint)]
[unencrypted ranges descriptor (LEB128 pairs)]
[supplemental_bytes_size (1 byte)]
[magic marker 0xFA 0xFA (2 bytes)]

Note: In production, the NIF (EDA.Voice.Dave.Native.encrypt_opus/2) handles encryption/decryption via the davey Rust crate. This module provides a pure Elixir implementation for testing and reference.

Summary

Functions

Decrypts a DAVE-encrypted frame using AES-128-GCM.

Encrypts an Opus frame using AES-128-GCM for DAVE E2EE.

Functions

decrypt(encrypted_frame, sender_key)

@spec decrypt(binary(), binary()) :: {:ok, binary()} | :error

Decrypts a DAVE-encrypted frame using AES-128-GCM.

Returns {:ok, opus_frame} or :error if decryption/parsing fails.

encrypt(opus_frame, sender_key, nonce)

@spec encrypt(binary(), binary(), non_neg_integer()) :: binary()

Encrypts an Opus frame using AES-128-GCM for DAVE E2EE.

For Opus, the first byte (TOC) stays unencrypted but is used as AAD.