Skip to content

File syn_aes.c

FileList > crypto > syn_aes.c

Go to the source code of this file

Unified AES block cipher & AEAD implementation (128/192/256-bit keys, ECB, CBC, CTR, GCM).

  • #include "syn_aes.h"
  • #include <string.h>

Public Static Attributes

Type Name
const uint8_t rcon = {0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36}
const uint8_t rsbox = /* multi line expression */
const uint8_t sbox = /* multi line expression */

Public Functions

Type Name
SYN_Status syn_aes_cbc_decrypt (const SYN_AES_Context * ctx, const uint8_t iv, const uint8_t * in, size_t in_len, uint8_t * out, size_t out_capacity, size_t * out_len)
Decrypt data using AES-CBC with PKCS#7 unpadding.
SYN_Status syn_aes_cbc_encrypt (const SYN_AES_Context * ctx, const uint8_t iv, const uint8_t * in, size_t in_len, uint8_t * out, size_t out_capacity, size_t * out_len)
Encrypt data using AES-CBC with PKCS#7 padding.
SYN_Status syn_aes_ccm_decrypt (const SYN_AES_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, const uint8_t * tag, size_t tag_len, uint8_t * out)
AES-CCM authenticated decryption and tag verification (NIST SP 800-38C / RFC 3610).
SYN_Status syn_aes_ccm_encrypt (const SYN_AES_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, uint8_t * tag, size_t tag_len)
AES-CCM authenticated encryption (NIST SP 800-38C / RFC 3610).
SYN_Status syn_aes_ctr (const SYN_AES_Context * ctx, const uint8_t nonce, const uint8_t * in, size_t len, uint8_t * out)
Encrypt/decrypt arbitrary length data using AES-CTR stream mode (NIST SP 800-38A).
void syn_aes_decrypt_block (const SYN_AES_Context * ctx, const uint8_t in, uint8_t out)
Decrypt a single 16-byte block (ECB mode).
void syn_aes_encrypt_block (const SYN_AES_Context * ctx, const uint8_t in, uint8_t out)
Encrypt a single 16-byte block (ECB mode).
SYN_Status syn_aes_gcm_decrypt (const SYN_AES_GCM_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, const uint8_t tag)
AES-GCM authenticated decryption and tag verification (NIST SP 800-38D).
SYN_Status syn_aes_gcm_encrypt (const SYN_AES_GCM_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, uint8_t tag)
AES-GCM authenticated encryption (NIST SP 800-38D).
SYN_Status syn_aes_gcm_init (SYN_AES_GCM_Context * ctx, const uint8_t * key, size_t key_len)
Initialize AES-GCM AEAD context (expands key and computes GHASH subkey H).
void syn_aes_ghash_mult (const uint8_t x, const uint8_t h, uint8_t out)
Multiply 16-byte block by GHASH subkey H in GF(2^128).
SYN_Status syn_aes_init (SYN_AES_Context * ctx, const uint8_t * key, size_t key_len)
Initialize AES context and perform key expansion for 128/192/256-bit key.

Public Static Functions

Type Name
SYN_Status ccm_compute_mac (const SYN_AES_Context * ctx, const uint8_t * nonce, size_t nonce_len, size_t L, const uint8_t * aad, size_t aad_len, const uint8_t * data, size_t data_len, size_t tag_len, uint8_t mac)
Compute NIST SP 800-38C / RFC 3610 CBC-MAC tag over header and payload.
void ccm_format_ctr (uint8_t a, const uint8_t * nonce, size_t nonce_len, size_t L, uint64_t counter)
Format counter block Ai for AES-CCM CTR mode.
void ccm_mac_feed (const SYN_AES_Context * ctx, uint8_t mac, uint8_t * blk, size_t * blk_len, const uint8_t * data, size_t len)
Feed data into AES-CCM CBC-MAC accumulator.
void ccm_mac_pad_zero (const SYN_AES_Context * ctx, uint8_t mac, uint8_t * blk, size_t * blk_len)
Pad partial block with zeros and finish block encryption in CBC-MAC.
void gcm_compute_j0 (const SYN_AES_GCM_Context * ctx, const uint8_t * nonce, size_t nonce_len, uint8_t j0)
Compute initial J0 counter block for GCM.
void ghash_mult_bit (const uint8_t x, const uint8_t y, uint8_t out)
Bitwise GHASH field multiplication in GF(2^128).
void ghash_process_blocks (const SYN_AES_GCM_Context * ctx, const uint8_t * data, size_t len, uint8_t y)
Process data blocks through GHASH.
uint8_t gmult (uint8_t a, uint8_t b)
General multiplication in GF(2^8).
uint8_t gmult2 (uint8_t a)
Multiply byte by 2 in GF(2^8) modulo x^8 + x^4 + x^3 + x + 1.
void inc128 (uint8_t counter)
Increment 128-bit big-endian counter.
void inc32 (uint8_t block)
Increment rightmost 32 bits of 128-bit counter.
void put_be64 (uint8_t out, uint64_t val)
Write 64-bit value big-endian.

Public Static Attributes Documentation

variable rcon

const uint8_t rcon[11];

Round constants


variable rsbox

const uint8_t rsbox[256];

Inverse Substitution Box (RS-Box)


variable sbox

const uint8_t sbox[256];

Forward Substitution Box (S-Box)


Public Functions Documentation

function syn_aes_cbc_decrypt

Decrypt data using AES-CBC with PKCS#7 unpadding.

SYN_Status syn_aes_cbc_decrypt (
    const SYN_AES_Context * ctx,
    const uint8_t iv,
    const uint8_t * in,
    size_t in_len,
    uint8_t * out,
    size_t out_capacity,
    size_t * out_len
) 

Parameters:

  • ctx Initialized AES context.
  • iv 16-byte initialization vector.
  • in Ciphertext buffer (must be non-empty multiple of 16 bytes).
  • in_len Ciphertext length in bytes.
  • out Plaintext output buffer.
  • out_capacity Capacity of plaintext output buffer.
  • out_len Number of plaintext bytes written.

Returns:

SYN_OK on success, or SYN_INVALID_PARAM on invalid padding or parameters.


function syn_aes_cbc_encrypt

Encrypt data using AES-CBC with PKCS#7 padding.

SYN_Status syn_aes_cbc_encrypt (
    const SYN_AES_Context * ctx,
    const uint8_t iv,
    const uint8_t * in,
    size_t in_len,
    uint8_t * out,
    size_t out_capacity,
    size_t * out_len
) 

Parameters:

  • ctx Initialized AES context.
  • iv 16-byte initialization vector.
  • in Plaintext buffer (may be NULL if in_len is 0).
  • in_len Plaintext length in bytes.
  • out Ciphertext output buffer.
  • out_capacity Maximum capacity of output buffer (must be >= in_len + PKCS#7 pad).
  • out_len Number of ciphertext bytes written.

Returns:

SYN_OK on success, or SYN_INVALID_PARAM on failure.


function syn_aes_ccm_decrypt

AES-CCM authenticated decryption and tag verification (NIST SP 800-38C / RFC 3610).

SYN_Status syn_aes_ccm_decrypt (
    const SYN_AES_Context * ctx,
    const uint8_t * nonce,
    size_t nonce_len,
    const uint8_t * aad,
    size_t aad_len,
    const uint8_t * in,
    size_t in_len,
    const uint8_t * tag,
    size_t tag_len,
    uint8_t * out
) 

Decrypts ciphertext in CTR mode and verifies CBC-MAC authentication tag in constant time. If verification fails, plaintext buffer is zeroed (if out != in) and SYN_ERROR is returned.

Parameters:

  • ctx Initialized AES context.
  • nonce Nonce buffer (length must be 7..13 bytes).
  • nonce_len Nonce length in bytes (7 to 13).
  • aad Additional authenticated data (may be NULL if aad_len is 0).
  • aad_len AAD length in bytes.
  • in Ciphertext buffer to decrypt (may be NULL if in_len is 0).
  • in_len Ciphertext length in bytes.
  • tag Authentication tag to verify against.
  • tag_len Length of authentication tag in bytes (4, 6, 8, 10, 12, 14, or 16).
  • out Plaintext output buffer (must be at least in_len bytes).

Returns:

SYN_OK on success, SYN_ERROR on tag mismatch, or SYN_INVALID_PARAM on invalid params.


function syn_aes_ccm_encrypt

AES-CCM authenticated encryption (NIST SP 800-38C / RFC 3610).

SYN_Status syn_aes_ccm_encrypt (
    const SYN_AES_Context * ctx,
    const uint8_t * nonce,
    size_t nonce_len,
    const uint8_t * aad,
    size_t aad_len,
    const uint8_t * in,
    size_t in_len,
    uint8_t * out,
    uint8_t * tag,
    size_t tag_len
) 

Computes CBC-MAC authentication tag and encrypts payload in CTR mode.

Parameters:

  • ctx Initialized AES context.
  • nonce Nonce buffer (length must be 7..13 bytes).
  • nonce_len Nonce length in bytes (7 to 13).
  • aad Additional authenticated data (may be NULL if aad_len is 0).
  • aad_len AAD length in bytes.
  • in Plaintext buffer to encrypt (may be NULL if in_len is 0).
  • in_len Plaintext length in bytes.
  • out Ciphertext output buffer (must be at least in_len bytes).
  • tag Authentication tag output buffer.
  • tag_len Length of authentication tag in bytes (4, 6, 8, 10, 12, 14, or 16).

Returns:

SYN_OK on success, or SYN_INVALID_PARAM on invalid parameters.


function syn_aes_ctr

Encrypt/decrypt arbitrary length data using AES-CTR stream mode (NIST SP 800-38A).

SYN_Status syn_aes_ctr (
    const SYN_AES_Context * ctx,
    const uint8_t nonce,
    const uint8_t * in,
    size_t len,
    uint8_t * out
) 

Parameters:

  • ctx Initialized AES context.
  • nonce 16-byte initial counter block (incremented as 128-bit big-endian).
  • in Input data buffer (plaintext for encrypt, ciphertext for decrypt).
  • len Length of input and output data in bytes.
  • out Output data buffer.

Returns:

SYN_OK on success, or SYN_INVALID_PARAM on NULL pointers.


function syn_aes_decrypt_block

Decrypt a single 16-byte block (ECB mode).

void syn_aes_decrypt_block (
    const SYN_AES_Context * ctx,
    const uint8_t in,
    uint8_t out
) 

Parameters:

  • ctx Initialized AES context.
  • in 16-byte ciphertext input block.
  • out 16-byte plaintext output block.

function syn_aes_encrypt_block

Encrypt a single 16-byte block (ECB mode).

void syn_aes_encrypt_block (
    const SYN_AES_Context * ctx,
    const uint8_t in,
    uint8_t out
) 

Parameters:

  • ctx Initialized AES context.
  • in 16-byte plaintext input block.
  • out 16-byte ciphertext output block.

function syn_aes_gcm_decrypt

AES-GCM authenticated decryption and tag verification (NIST SP 800-38D).

SYN_Status syn_aes_gcm_decrypt (
    const SYN_AES_GCM_Context * ctx,
    const uint8_t * nonce,
    size_t nonce_len,
    const uint8_t * aad,
    size_t aad_len,
    const uint8_t * in,
    size_t in_len,
    uint8_t * out,
    const uint8_t tag
) 

Decrypts ciphertext and verifies the authentication tag in constant time. If authentication fails, plaintext output is zeroed and SYN_AUTH_FAILED is returned.

Parameters:

  • ctx Initialized AES-GCM context.
  • nonce Initialization vector / nonce buffer.
  • nonce_len Nonce length in bytes.
  • aad Additional authenticated data (may be NULL if aad_len is 0).
  • aad_len AAD length in bytes.
  • in Ciphertext buffer to decrypt (may be NULL if in_len is 0).
  • in_len Ciphertext length in bytes.
  • out Plaintext output buffer (must be at least in_len bytes).
  • tag 16-byte expected authentication tag to verify against.

Returns:

SYN_OK on successful verification, SYN_ERROR on tag mismatch, or SYN_INVALID_PARAM on invalid parameters.


function syn_aes_gcm_encrypt

AES-GCM authenticated encryption (NIST SP 800-38D).

SYN_Status syn_aes_gcm_encrypt (
    const SYN_AES_GCM_Context * ctx,
    const uint8_t * nonce,
    size_t nonce_len,
    const uint8_t * aad,
    size_t aad_len,
    const uint8_t * in,
    size_t in_len,
    uint8_t * out,
    uint8_t tag
) 

Parameters:

  • ctx Initialized AES-GCM context.
  • nonce Initialization vector / nonce buffer.
  • nonce_len Nonce length in bytes (standard is 12 bytes).
  • aad Additional authenticated data (may be NULL if aad_len is 0).
  • aad_len AAD length in bytes.
  • in Plaintext buffer to encrypt (may be NULL if in_len is 0).
  • in_len Plaintext length in bytes.
  • out Ciphertext output buffer (must be at least in_len bytes).
  • tag 16-byte authentication tag output buffer.

Returns:

SYN_OK on success, or SYN_INVALID_PARAM on NULL pointers or invalid params.


function syn_aes_gcm_init

Initialize AES-GCM AEAD context (expands key and computes GHASH subkey H).

SYN_Status syn_aes_gcm_init (
    SYN_AES_GCM_Context * ctx,
    const uint8_t * key,
    size_t key_len
) 

Parameters:

  • ctx Pointer to GCM context to initialize.
  • key Secret key buffer.
  • key_len Length of secret key in bytes (16, 24, or 32).

Returns:

SYN_OK on success, or SYN_INVALID_PARAM on failure.


function syn_aes_ghash_mult

Multiply 16-byte block by GHASH subkey H in GF(2^128).

void syn_aes_ghash_mult (
    const uint8_t x,
    const uint8_t h,
    uint8_t out
) 

Parameters:

  • x Input 16-byte field element.
  • h Input 16-byte GHASH subkey H.
  • out Output 16-byte product block.

function syn_aes_init

Initialize AES context and perform key expansion for 128/192/256-bit key.

SYN_Status syn_aes_init (
    SYN_AES_Context * ctx,
    const uint8_t * key,
    size_t key_len
) 

Parameters:

  • ctx Pointer to AES context to initialize.
  • key Secret key buffer.
  • key_len Length of secret key in bytes (16, 24, or 32).

Returns:

SYN_OK on success, or SYN_INVALID_PARAM on invalid key size or NULL pointers.


Public Static Functions Documentation

function ccm_compute_mac

Compute NIST SP 800-38C / RFC 3610 CBC-MAC tag over header and payload.

static SYN_Status ccm_compute_mac (
    const SYN_AES_Context * ctx,
    const uint8_t * nonce,
    size_t nonce_len,
    size_t L,
    const uint8_t * aad,
    size_t aad_len,
    const uint8_t * data,
    size_t data_len,
    size_t tag_len,
    uint8_t mac
) 

Parameters:

  • ctx AES context.
  • nonce Nonce buffer.
  • nonce_len Nonce length in bytes.
  • L Length parameter (15 - nonce_len).
  • aad Associated data buffer.
  • aad_len Associated data length in bytes.
  • data Payload data buffer.
  • data_len Payload data length in bytes.
  • tag_len Desired MAC tag length in bytes.
  • mac 16-byte raw CBC-MAC output buffer.

Returns:

SYN_Status SYN_OK on success, error code otherwise.


function ccm_format_ctr

Format counter block Ai for AES-CCM CTR mode.

static void ccm_format_ctr (
    uint8_t a,
    const uint8_t * nonce,
    size_t nonce_len,
    size_t L,
    uint64_t counter
) 

Parameters:

  • a 16-byte formatted counter output block.
  • nonce Pointer to nonce buffer.
  • nonce_len Length of nonce in bytes.
  • L Length parameter (15 - nonce_len).
  • counter Big-endian counter integer.

function ccm_mac_feed

Feed data into AES-CCM CBC-MAC accumulator.

static void ccm_mac_feed (
    const SYN_AES_Context * ctx,
    uint8_t mac,
    uint8_t * blk,
    size_t * blk_len,
    const uint8_t * data,
    size_t len
) 

Parameters:

  • ctx AES context.
  • mac Running CBC-MAC accumulator block.
  • blk Partial block staging buffer.
  • blk_len Pointer to length of valid bytes in staging buffer.
  • data Input byte buffer to feed into MAC.
  • len Number of bytes in input data buffer.

function ccm_mac_pad_zero

Pad partial block with zeros and finish block encryption in CBC-MAC.

static void ccm_mac_pad_zero (
    const SYN_AES_Context * ctx,
    uint8_t mac,
    uint8_t * blk,
    size_t * blk_len
) 

Parameters:

  • ctx AES context.
  • mac Running CBC-MAC accumulator block.
  • blk Partial block staging buffer.
  • blk_len Pointer to length of valid bytes in staging buffer.

function gcm_compute_j0

Compute initial J0 counter block for GCM.

static void gcm_compute_j0 (
    const SYN_AES_GCM_Context * ctx,
    const uint8_t * nonce,
    size_t nonce_len,
    uint8_t j0
) 

Parameters:

  • ctx GCM context.
  • nonce Nonce buffer.
  • nonce_len Nonce length in bytes.
  • j0 Output 16-byte J0 block.

function ghash_mult_bit

Bitwise GHASH field multiplication in GF(2^128).

static void ghash_mult_bit (
    const uint8_t x,
    const uint8_t y,
    uint8_t out
) 

Parameters:

  • x First 16-byte block.
  • y Second 16-byte block.
  • out Output 16-byte block product.

function ghash_process_blocks

Process data blocks through GHASH.

static void ghash_process_blocks (
    const SYN_AES_GCM_Context * ctx,
    const uint8_t * data,
    size_t len,
    uint8_t y
) 

Parameters:

  • ctx GCM context.
  • data Input data buffer.
  • len Data length in bytes.
  • y In/out 16-byte GHASH state accumulator.

function gmult

General multiplication in GF(2^8).

static inline uint8_t gmult (
    uint8_t a,
    uint8_t b
) 

Parameters:

  • a First operand.
  • b Second operand.

Returns:

Product in GF(2^8).


function gmult2

Multiply byte by 2 in GF(2^8) modulo x^8 + x^4 + x^3 + x + 1.

static inline uint8_t gmult2 (
    uint8_t a
) 

Parameters:

  • a Input byte.

Returns:

Multiplied byte.


function inc128

Increment 128-bit big-endian counter.

static void inc128 (
    uint8_t counter
) 

Parameters:

  • counter 16-byte counter block to increment in place.

function inc32

Increment rightmost 32 bits of 128-bit counter.

static void inc32 (
    uint8_t block
) 

Parameters:

  • block 16-byte block whose last 4 bytes are incremented.

function put_be64

Write 64-bit value big-endian.

static void put_be64 (
    uint8_t out,
    uint64_t val
) 

Parameters:

  • out 8-byte buffer.
  • val 64-bit integer.


The documentation for this class was generated from the following file src/syntropic/crypto/syn_aes.c