+ {`contentKey = randomBytes(32) # 256 bits
+nonce = randomBytes(24) # 192 bits
+ciphertext = XChaCha20-Poly1305(
+ key = contentKey,
+ nonce = nonce,
+ plaintext = UTF8(message)
+)`}
+
+ -
+
+ {`messageSecret = contentKey || nonce
+ephemeral = secp256k1.randomKeyPair()
+sharedPoint = ECDH(ephemeral.private, recipient.public)
+wrappingKey = sharedPoint.x[0..31]
+keyEnvelope = Base64(iv || AES-CBC(wrappingKey, messageSecret) || ephemeral.public)`}
+
+
+
+ RAC2 || salt[16] || iv[12] || AES-256-GCM-ciphertext-and-tag
+
+
+ {`input
+ → DEFLATE compression
+ → PBKDF2(password, "rosetta", 1,000 iterations)
+ → AES-CBC with random 16-byte IV
+ → Base64(iv) : Base64(ciphertext)`}
+
+ -
+
-
+