File syn_aes.c¶
Go to the source code of this file
Unified AES block cipher & AEAD implementation (128/192/256-bit keys, ECB, CBC, CTR, GCM).
#include "syn_aes.h"#include <string.h>
Public Static Attributes¶
| Type | Name |
|---|---|
| const uint8_t | rcon = {0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36} |
| const uint8_t | rsbox = /* multi line expression */ |
| const uint8_t | sbox = /* multi line expression */ |
Public Functions¶
| Type | Name |
|---|---|
| SYN_Status | syn_aes_cbc_decrypt (const SYN_AES_Context * ctx, const uint8_t iv, const uint8_t * in, size_t in_len, uint8_t * out, size_t out_capacity, size_t * out_len) Decrypt data using AES-CBC with PKCS#7 unpadding. |
| SYN_Status | syn_aes_cbc_encrypt (const SYN_AES_Context * ctx, const uint8_t iv, const uint8_t * in, size_t in_len, uint8_t * out, size_t out_capacity, size_t * out_len) Encrypt data using AES-CBC with PKCS#7 padding. |
| SYN_Status | syn_aes_ccm_decrypt (const SYN_AES_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, const uint8_t * tag, size_t tag_len, uint8_t * out) AES-CCM authenticated decryption and tag verification (NIST SP 800-38C / RFC 3610). |
| SYN_Status | syn_aes_ccm_encrypt (const SYN_AES_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, uint8_t * tag, size_t tag_len) AES-CCM authenticated encryption (NIST SP 800-38C / RFC 3610). |
| SYN_Status | syn_aes_ctr (const SYN_AES_Context * ctx, const uint8_t nonce, const uint8_t * in, size_t len, uint8_t * out) Encrypt/decrypt arbitrary length data using AES-CTR stream mode (NIST SP 800-38A). |
| void | syn_aes_decrypt_block (const SYN_AES_Context * ctx, const uint8_t in, uint8_t out) Decrypt a single 16-byte block (ECB mode). |
| void | syn_aes_encrypt_block (const SYN_AES_Context * ctx, const uint8_t in, uint8_t out) Encrypt a single 16-byte block (ECB mode). |
| SYN_Status | syn_aes_gcm_decrypt (const SYN_AES_GCM_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, const uint8_t tag) AES-GCM authenticated decryption and tag verification (NIST SP 800-38D). |
| SYN_Status | syn_aes_gcm_encrypt (const SYN_AES_GCM_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, uint8_t tag) AES-GCM authenticated encryption (NIST SP 800-38D). |
| SYN_Status | syn_aes_gcm_init (SYN_AES_GCM_Context * ctx, const uint8_t * key, size_t key_len) Initialize AES-GCM AEAD context (expands key and computes GHASH subkey H). |
| void | syn_aes_ghash_mult (const uint8_t x, const uint8_t h, uint8_t out) Multiply 16-byte block by GHASH subkey H in GF(2^128). |
| SYN_Status | syn_aes_init (SYN_AES_Context * ctx, const uint8_t * key, size_t key_len) Initialize AES context and perform key expansion for 128/192/256-bit key. |
Public Static Functions¶
| Type | Name |
|---|---|
| SYN_Status | ccm_compute_mac (const SYN_AES_Context * ctx, const uint8_t * nonce, size_t nonce_len, size_t L, const uint8_t * aad, size_t aad_len, const uint8_t * data, size_t data_len, size_t tag_len, uint8_t mac) Compute NIST SP 800-38C / RFC 3610 CBC-MAC tag over header and payload. |
| void | ccm_format_ctr (uint8_t a, const uint8_t * nonce, size_t nonce_len, size_t L, uint64_t counter) Format counter block Ai for AES-CCM CTR mode. |
| void | ccm_mac_feed (const SYN_AES_Context * ctx, uint8_t mac, uint8_t * blk, size_t * blk_len, const uint8_t * data, size_t len) Feed data into AES-CCM CBC-MAC accumulator. |
| void | ccm_mac_pad_zero (const SYN_AES_Context * ctx, uint8_t mac, uint8_t * blk, size_t * blk_len) Pad partial block with zeros and finish block encryption in CBC-MAC. |
| void | gcm_compute_j0 (const SYN_AES_GCM_Context * ctx, const uint8_t * nonce, size_t nonce_len, uint8_t j0) Compute initial J0 counter block for GCM. |
| void | ghash_mult_bit (const uint8_t x, const uint8_t y, uint8_t out) Bitwise GHASH field multiplication in GF(2^128). |
| void | ghash_process_blocks (const SYN_AES_GCM_Context * ctx, const uint8_t * data, size_t len, uint8_t y) Process data blocks through GHASH. |
| uint8_t | gmult (uint8_t a, uint8_t b) General multiplication in GF(2^8). |
| uint8_t | gmult2 (uint8_t a) Multiply byte by 2 in GF(2^8) modulo x^8 + x^4 + x^3 + x + 1. |
| void | inc128 (uint8_t counter) Increment 128-bit big-endian counter. |
| void | inc32 (uint8_t block) Increment rightmost 32 bits of 128-bit counter. |
| void | put_be64 (uint8_t out, uint64_t val) Write 64-bit value big-endian. |
Public Static Attributes Documentation¶
variable rcon¶
Round constants
variable rsbox¶
Inverse Substitution Box (RS-Box)
variable sbox¶
Forward Substitution Box (S-Box)
Public Functions Documentation¶
function syn_aes_cbc_decrypt¶
Decrypt data using AES-CBC with PKCS#7 unpadding.
SYN_Status syn_aes_cbc_decrypt (
const SYN_AES_Context * ctx,
const uint8_t iv,
const uint8_t * in,
size_t in_len,
uint8_t * out,
size_t out_capacity,
size_t * out_len
)
Parameters:
ctxInitialized AES context.iv16-byte initialization vector.inCiphertext buffer (must be non-empty multiple of 16 bytes).in_lenCiphertext length in bytes.outPlaintext output buffer.out_capacityCapacity of plaintext output buffer.out_lenNumber of plaintext bytes written.
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on invalid padding or parameters.
function syn_aes_cbc_encrypt¶
Encrypt data using AES-CBC with PKCS#7 padding.
SYN_Status syn_aes_cbc_encrypt (
const SYN_AES_Context * ctx,
const uint8_t iv,
const uint8_t * in,
size_t in_len,
uint8_t * out,
size_t out_capacity,
size_t * out_len
)
Parameters:
ctxInitialized AES context.iv16-byte initialization vector.inPlaintext buffer (may be NULL if in_len is 0).in_lenPlaintext length in bytes.outCiphertext output buffer.out_capacityMaximum capacity of output buffer (must be >= in_len + PKCS#7 pad).out_lenNumber of ciphertext bytes written.
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on failure.
function syn_aes_ccm_decrypt¶
AES-CCM authenticated decryption and tag verification (NIST SP 800-38C / RFC 3610).
SYN_Status syn_aes_ccm_decrypt (
const SYN_AES_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
const uint8_t * aad,
size_t aad_len,
const uint8_t * in,
size_t in_len,
const uint8_t * tag,
size_t tag_len,
uint8_t * out
)
Decrypts ciphertext in CTR mode and verifies CBC-MAC authentication tag in constant time. If verification fails, plaintext buffer is zeroed (if out != in) and SYN_ERROR is returned.
Parameters:
ctxInitialized AES context.nonceNonce buffer (length must be 7..13 bytes).nonce_lenNonce length in bytes (7 to 13).aadAdditional authenticated data (may be NULL if aad_len is 0).aad_lenAAD length in bytes.inCiphertext buffer to decrypt (may be NULL if in_len is 0).in_lenCiphertext length in bytes.tagAuthentication tag to verify against.tag_lenLength of authentication tag in bytes (4, 6, 8, 10, 12, 14, or 16).outPlaintext output buffer (must be at least in_len bytes).
Returns:
SYN_OK on success, SYN_ERROR on tag mismatch, or SYN_INVALID_PARAM on invalid params.
function syn_aes_ccm_encrypt¶
AES-CCM authenticated encryption (NIST SP 800-38C / RFC 3610).
SYN_Status syn_aes_ccm_encrypt (
const SYN_AES_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
const uint8_t * aad,
size_t aad_len,
const uint8_t * in,
size_t in_len,
uint8_t * out,
uint8_t * tag,
size_t tag_len
)
Computes CBC-MAC authentication tag and encrypts payload in CTR mode.
Parameters:
ctxInitialized AES context.nonceNonce buffer (length must be 7..13 bytes).nonce_lenNonce length in bytes (7 to 13).aadAdditional authenticated data (may be NULL if aad_len is 0).aad_lenAAD length in bytes.inPlaintext buffer to encrypt (may be NULL if in_len is 0).in_lenPlaintext length in bytes.outCiphertext output buffer (must be at least in_len bytes).tagAuthentication tag output buffer.tag_lenLength of authentication tag in bytes (4, 6, 8, 10, 12, 14, or 16).
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on invalid parameters.
function syn_aes_ctr¶
Encrypt/decrypt arbitrary length data using AES-CTR stream mode (NIST SP 800-38A).
SYN_Status syn_aes_ctr (
const SYN_AES_Context * ctx,
const uint8_t nonce,
const uint8_t * in,
size_t len,
uint8_t * out
)
Parameters:
ctxInitialized AES context.nonce16-byte initial counter block (incremented as 128-bit big-endian).inInput data buffer (plaintext for encrypt, ciphertext for decrypt).lenLength of input and output data in bytes.outOutput data buffer.
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on NULL pointers.
function syn_aes_decrypt_block¶
Decrypt a single 16-byte block (ECB mode).
Parameters:
ctxInitialized AES context.in16-byte ciphertext input block.out16-byte plaintext output block.
function syn_aes_encrypt_block¶
Encrypt a single 16-byte block (ECB mode).
Parameters:
ctxInitialized AES context.in16-byte plaintext input block.out16-byte ciphertext output block.
function syn_aes_gcm_decrypt¶
AES-GCM authenticated decryption and tag verification (NIST SP 800-38D).
SYN_Status syn_aes_gcm_decrypt (
const SYN_AES_GCM_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
const uint8_t * aad,
size_t aad_len,
const uint8_t * in,
size_t in_len,
uint8_t * out,
const uint8_t tag
)
Decrypts ciphertext and verifies the authentication tag in constant time. If authentication fails, plaintext output is zeroed and SYN_AUTH_FAILED is returned.
Parameters:
ctxInitialized AES-GCM context.nonceInitialization vector / nonce buffer.nonce_lenNonce length in bytes.aadAdditional authenticated data (may be NULL if aad_len is 0).aad_lenAAD length in bytes.inCiphertext buffer to decrypt (may be NULL if in_len is 0).in_lenCiphertext length in bytes.outPlaintext output buffer (must be at least in_len bytes).tag16-byte expected authentication tag to verify against.
Returns:
SYN_OK on successful verification, SYN_ERROR on tag mismatch, or SYN_INVALID_PARAM on invalid parameters.
function syn_aes_gcm_encrypt¶
AES-GCM authenticated encryption (NIST SP 800-38D).
SYN_Status syn_aes_gcm_encrypt (
const SYN_AES_GCM_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
const uint8_t * aad,
size_t aad_len,
const uint8_t * in,
size_t in_len,
uint8_t * out,
uint8_t tag
)
Parameters:
ctxInitialized AES-GCM context.nonceInitialization vector / nonce buffer.nonce_lenNonce length in bytes (standard is 12 bytes).aadAdditional authenticated data (may be NULL if aad_len is 0).aad_lenAAD length in bytes.inPlaintext buffer to encrypt (may be NULL if in_len is 0).in_lenPlaintext length in bytes.outCiphertext output buffer (must be at least in_len bytes).tag16-byte authentication tag output buffer.
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on NULL pointers or invalid params.
function syn_aes_gcm_init¶
Initialize AES-GCM AEAD context (expands key and computes GHASH subkey H).
Parameters:
ctxPointer to GCM context to initialize.keySecret key buffer.key_lenLength of secret key in bytes (16, 24, or 32).
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on failure.
function syn_aes_ghash_mult¶
Multiply 16-byte block by GHASH subkey H in GF(2^128).
Parameters:
xInput 16-byte field element.hInput 16-byte GHASH subkey H.outOutput 16-byte product block.
function syn_aes_init¶
Initialize AES context and perform key expansion for 128/192/256-bit key.
Parameters:
ctxPointer to AES context to initialize.keySecret key buffer.key_lenLength of secret key in bytes (16, 24, or 32).
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on invalid key size or NULL pointers.
Public Static Functions Documentation¶
function ccm_compute_mac¶
Compute NIST SP 800-38C / RFC 3610 CBC-MAC tag over header and payload.
static SYN_Status ccm_compute_mac (
const SYN_AES_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
size_t L,
const uint8_t * aad,
size_t aad_len,
const uint8_t * data,
size_t data_len,
size_t tag_len,
uint8_t mac
)
Parameters:
ctxAES context.nonceNonce buffer.nonce_lenNonce length in bytes.LLength parameter (15 - nonce_len).aadAssociated data buffer.aad_lenAssociated data length in bytes.dataPayload data buffer.data_lenPayload data length in bytes.tag_lenDesired MAC tag length in bytes.mac16-byte raw CBC-MAC output buffer.
Returns:
SYN_Status SYN_OK on success, error code otherwise.
function ccm_format_ctr¶
Format counter block Ai for AES-CCM CTR mode.
static void ccm_format_ctr (
uint8_t a,
const uint8_t * nonce,
size_t nonce_len,
size_t L,
uint64_t counter
)
Parameters:
a16-byte formatted counter output block.noncePointer to nonce buffer.nonce_lenLength of nonce in bytes.LLength parameter (15 - nonce_len).counterBig-endian counter integer.
function ccm_mac_feed¶
Feed data into AES-CCM CBC-MAC accumulator.
static void ccm_mac_feed (
const SYN_AES_Context * ctx,
uint8_t mac,
uint8_t * blk,
size_t * blk_len,
const uint8_t * data,
size_t len
)
Parameters:
ctxAES context.macRunning CBC-MAC accumulator block.blkPartial block staging buffer.blk_lenPointer to length of valid bytes in staging buffer.dataInput byte buffer to feed into MAC.lenNumber of bytes in input data buffer.
function ccm_mac_pad_zero¶
Pad partial block with zeros and finish block encryption in CBC-MAC.
static void ccm_mac_pad_zero (
const SYN_AES_Context * ctx,
uint8_t mac,
uint8_t * blk,
size_t * blk_len
)
Parameters:
ctxAES context.macRunning CBC-MAC accumulator block.blkPartial block staging buffer.blk_lenPointer to length of valid bytes in staging buffer.
function gcm_compute_j0¶
Compute initial J0 counter block for GCM.
static void gcm_compute_j0 (
const SYN_AES_GCM_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
uint8_t j0
)
Parameters:
ctxGCM context.nonceNonce buffer.nonce_lenNonce length in bytes.j0Output 16-byte J0 block.
function ghash_mult_bit¶
Bitwise GHASH field multiplication in GF(2^128).
Parameters:
xFirst 16-byte block.ySecond 16-byte block.outOutput 16-byte block product.
function ghash_process_blocks¶
Process data blocks through GHASH.
static void ghash_process_blocks (
const SYN_AES_GCM_Context * ctx,
const uint8_t * data,
size_t len,
uint8_t y
)
Parameters:
ctxGCM context.dataInput data buffer.lenData length in bytes.yIn/out 16-byte GHASH state accumulator.
function gmult¶
General multiplication in GF(2^8).
Parameters:
aFirst operand.bSecond operand.
Returns:
Product in GF(2^8).
function gmult2¶
Multiply byte by 2 in GF(2^8) modulo x^8 + x^4 + x^3 + x + 1.
Parameters:
aInput byte.
Returns:
Multiplied byte.
function inc128¶
Increment 128-bit big-endian counter.
Parameters:
counter16-byte counter block to increment in place.
function inc32¶
Increment rightmost 32 bits of 128-bit counter.
Parameters:
block16-byte block whose last 4 bytes are incremented.
function put_be64¶
Write 64-bit value big-endian.
Parameters:
out8-byte buffer.val64-bit integer.
The documentation for this class was generated from the following file src/syntropic/crypto/syn_aes.c