File syn_aes.h¶
Go to the source code of this file
Unified AES cipher engine (128/192/256-bit keys, ECB, CBC, CTR, and GCM AEAD). More...
#include "../common/syn_defs.h"#include <stdbool.h>#include <stddef.h>#include <stdint.h>
Classes¶
| Type | Name |
|---|---|
| struct | SYN_AES_Context AES context containing expanded round keys. |
| struct | SYN_AES_GCM_Context AES-GCM AEAD context — wraps AES key schedule and GHASH subkey/tables. |
Public Functions¶
| Type | Name |
|---|---|
| SYN_Status | syn_aes_cbc_decrypt (const SYN_AES_Context * ctx, const uint8_t iv, const uint8_t * in, size_t in_len, uint8_t * out, size_t out_capacity, size_t * out_len) Decrypt data using AES-CBC with PKCS#7 unpadding. |
| SYN_Status | syn_aes_cbc_encrypt (const SYN_AES_Context * ctx, const uint8_t iv, const uint8_t * in, size_t in_len, uint8_t * out, size_t out_capacity, size_t * out_len) Encrypt data using AES-CBC with PKCS#7 padding. |
| SYN_Status | syn_aes_ccm_decrypt (const SYN_AES_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, const uint8_t * tag, size_t tag_len, uint8_t * out) AES-CCM authenticated decryption and tag verification (NIST SP 800-38C / RFC 3610). |
| SYN_Status | syn_aes_ccm_encrypt (const SYN_AES_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, uint8_t * tag, size_t tag_len) AES-CCM authenticated encryption (NIST SP 800-38C / RFC 3610). |
| SYN_Status | syn_aes_ctr (const SYN_AES_Context * ctx, const uint8_t nonce, const uint8_t * in, size_t len, uint8_t * out) Encrypt/decrypt arbitrary length data using AES-CTR stream mode (NIST SP 800-38A). |
| void | syn_aes_decrypt_block (const SYN_AES_Context * ctx, const uint8_t in, uint8_t out) Decrypt a single 16-byte block (ECB mode). |
| void | syn_aes_encrypt_block (const SYN_AES_Context * ctx, const uint8_t in, uint8_t out) Encrypt a single 16-byte block (ECB mode). |
| SYN_Status | syn_aes_gcm_decrypt (const SYN_AES_GCM_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, const uint8_t tag) AES-GCM authenticated decryption and tag verification (NIST SP 800-38D). |
| SYN_Status | syn_aes_gcm_encrypt (const SYN_AES_GCM_Context * ctx, const uint8_t * nonce, size_t nonce_len, const uint8_t * aad, size_t aad_len, const uint8_t * in, size_t in_len, uint8_t * out, uint8_t tag) AES-GCM authenticated encryption (NIST SP 800-38D). |
| SYN_Status | syn_aes_gcm_init (SYN_AES_GCM_Context * ctx, const uint8_t * key, size_t key_len) Initialize AES-GCM AEAD context (expands key and computes GHASH subkey H). |
| void | syn_aes_ghash_mult (const uint8_t x, const uint8_t h, uint8_t out) Multiply 16-byte block by GHASH subkey H in GF(2^128). |
| SYN_Status | syn_aes_init (SYN_AES_Context * ctx, const uint8_t * key, size_t key_len) Initialize AES context and perform key expansion for 128/192/256-bit key. |
Macros¶
| Type | Name |
|---|---|
| define | SYN_AES_BLOCK_SIZE 16UAES cipher block size in bytes (16 bytes / 128 bits). |
| define | SYN_AES_GCM_IV_DEFAULT_SIZE 12URecommended GCM initialization vector size in bytes (12 bytes / 96 bits). |
| define | SYN_AES_GCM_TABLE 0GCM GHASH acceleration table strategy. 0 = bit-by-bit Shoup (0 bytes table, low footprint), 4 = 4-bit nibble table (256 bytes per GCM context), 8 = 8-bit byte table (4096 bytes per GCM context). |
| define | SYN_AES_GCM_TAG_SIZE 16UStandard GCM authentication tag size in bytes (16 bytes / 128 bits). |
| define | SYN_AES_KEY_SIZE_128 16UAES-128 key size in bytes (16 bytes / 128 bits). |
| define | SYN_AES_KEY_SIZE_192 24UAES-192 key size in bytes (24 bytes / 192 bits). |
| define | SYN_AES_KEY_SIZE_256 32UAES-256 key size in bytes (32 bytes / 256 bits). |
| define | SYN_AES_MAX_EXPANDED_KEY 240UMaximum expanded round keys storage size in bytes. |
| define | SYN_AES_MAX_KEY_BITS 256Maximum key size in bits (128, 192, or 256). Controls context RAM footprint. |
| define | SYN_AES_MAX_ROUNDS 14UMaximum rounds for configured key size. |
| define | SYN_USE_AES_CBC 1Enable CBC mode encryption and decryption with PKCS#7 padding. |
| define | SYN_USE_AES_CTR 1Enable CTR stream cipher mode. |
| define | SYN_USE_AES_DECRYPT 1Enable ECB and CBC decryption functions (pulls rsbox, +256B Flash). |
| define | SYN_USE_AES_GCM 1Enable GCM AEAD authenticated encryption and decryption. |
Detailed Description¶
Zero-heap, constant-time implementation supporting AES-128, AES-192, and AES-256 with configurable compile-time memory footprint guardrails.
Public Functions Documentation¶
function syn_aes_cbc_decrypt¶
Decrypt data using AES-CBC with PKCS#7 unpadding.
SYN_Status syn_aes_cbc_decrypt (
const SYN_AES_Context * ctx,
const uint8_t iv,
const uint8_t * in,
size_t in_len,
uint8_t * out,
size_t out_capacity,
size_t * out_len
)
Parameters:
ctxInitialized AES context.iv16-byte initialization vector.inCiphertext buffer (must be non-empty multiple of 16 bytes).in_lenCiphertext length in bytes.outPlaintext output buffer.out_capacityCapacity of plaintext output buffer.out_lenNumber of plaintext bytes written.
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on invalid padding or parameters.
function syn_aes_cbc_encrypt¶
Encrypt data using AES-CBC with PKCS#7 padding.
SYN_Status syn_aes_cbc_encrypt (
const SYN_AES_Context * ctx,
const uint8_t iv,
const uint8_t * in,
size_t in_len,
uint8_t * out,
size_t out_capacity,
size_t * out_len
)
Parameters:
ctxInitialized AES context.iv16-byte initialization vector.inPlaintext buffer (may be NULL if in_len is 0).in_lenPlaintext length in bytes.outCiphertext output buffer.out_capacityMaximum capacity of output buffer (must be >= in_len + PKCS#7 pad).out_lenNumber of ciphertext bytes written.
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on failure.
function syn_aes_ccm_decrypt¶
AES-CCM authenticated decryption and tag verification (NIST SP 800-38C / RFC 3610).
SYN_Status syn_aes_ccm_decrypt (
const SYN_AES_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
const uint8_t * aad,
size_t aad_len,
const uint8_t * in,
size_t in_len,
const uint8_t * tag,
size_t tag_len,
uint8_t * out
)
Decrypts ciphertext in CTR mode and verifies CBC-MAC authentication tag in constant time. If verification fails, plaintext buffer is zeroed (if out != in) and SYN_ERROR is returned.
Parameters:
ctxInitialized AES context.nonceNonce buffer (length must be 7..13 bytes).nonce_lenNonce length in bytes (7 to 13).aadAdditional authenticated data (may be NULL if aad_len is 0).aad_lenAAD length in bytes.inCiphertext buffer to decrypt (may be NULL if in_len is 0).in_lenCiphertext length in bytes.tagAuthentication tag to verify against.tag_lenLength of authentication tag in bytes (4, 6, 8, 10, 12, 14, or 16).outPlaintext output buffer (must be at least in_len bytes).
Returns:
SYN_OK on success, SYN_ERROR on tag mismatch, or SYN_INVALID_PARAM on invalid params.
function syn_aes_ccm_encrypt¶
AES-CCM authenticated encryption (NIST SP 800-38C / RFC 3610).
SYN_Status syn_aes_ccm_encrypt (
const SYN_AES_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
const uint8_t * aad,
size_t aad_len,
const uint8_t * in,
size_t in_len,
uint8_t * out,
uint8_t * tag,
size_t tag_len
)
Computes CBC-MAC authentication tag and encrypts payload in CTR mode.
Parameters:
ctxInitialized AES context.nonceNonce buffer (length must be 7..13 bytes).nonce_lenNonce length in bytes (7 to 13).aadAdditional authenticated data (may be NULL if aad_len is 0).aad_lenAAD length in bytes.inPlaintext buffer to encrypt (may be NULL if in_len is 0).in_lenPlaintext length in bytes.outCiphertext output buffer (must be at least in_len bytes).tagAuthentication tag output buffer.tag_lenLength of authentication tag in bytes (4, 6, 8, 10, 12, 14, or 16).
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on invalid parameters.
function syn_aes_ctr¶
Encrypt/decrypt arbitrary length data using AES-CTR stream mode (NIST SP 800-38A).
SYN_Status syn_aes_ctr (
const SYN_AES_Context * ctx,
const uint8_t nonce,
const uint8_t * in,
size_t len,
uint8_t * out
)
Parameters:
ctxInitialized AES context.nonce16-byte initial counter block (incremented as 128-bit big-endian).inInput data buffer (plaintext for encrypt, ciphertext for decrypt).lenLength of input and output data in bytes.outOutput data buffer.
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on NULL pointers.
function syn_aes_decrypt_block¶
Decrypt a single 16-byte block (ECB mode).
Parameters:
ctxInitialized AES context.in16-byte ciphertext input block.out16-byte plaintext output block.
function syn_aes_encrypt_block¶
Encrypt a single 16-byte block (ECB mode).
Parameters:
ctxInitialized AES context.in16-byte plaintext input block.out16-byte ciphertext output block.
function syn_aes_gcm_decrypt¶
AES-GCM authenticated decryption and tag verification (NIST SP 800-38D).
SYN_Status syn_aes_gcm_decrypt (
const SYN_AES_GCM_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
const uint8_t * aad,
size_t aad_len,
const uint8_t * in,
size_t in_len,
uint8_t * out,
const uint8_t tag
)
Decrypts ciphertext and verifies the authentication tag in constant time. If authentication fails, plaintext output is zeroed and SYN_AUTH_FAILED is returned.
Parameters:
ctxInitialized AES-GCM context.nonceInitialization vector / nonce buffer.nonce_lenNonce length in bytes.aadAdditional authenticated data (may be NULL if aad_len is 0).aad_lenAAD length in bytes.inCiphertext buffer to decrypt (may be NULL if in_len is 0).in_lenCiphertext length in bytes.outPlaintext output buffer (must be at least in_len bytes).tag16-byte expected authentication tag to verify against.
Returns:
SYN_OK on successful verification, SYN_ERROR on tag mismatch, or SYN_INVALID_PARAM on invalid parameters.
function syn_aes_gcm_encrypt¶
AES-GCM authenticated encryption (NIST SP 800-38D).
SYN_Status syn_aes_gcm_encrypt (
const SYN_AES_GCM_Context * ctx,
const uint8_t * nonce,
size_t nonce_len,
const uint8_t * aad,
size_t aad_len,
const uint8_t * in,
size_t in_len,
uint8_t * out,
uint8_t tag
)
Parameters:
ctxInitialized AES-GCM context.nonceInitialization vector / nonce buffer.nonce_lenNonce length in bytes (standard is 12 bytes).aadAdditional authenticated data (may be NULL if aad_len is 0).aad_lenAAD length in bytes.inPlaintext buffer to encrypt (may be NULL if in_len is 0).in_lenPlaintext length in bytes.outCiphertext output buffer (must be at least in_len bytes).tag16-byte authentication tag output buffer.
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on NULL pointers or invalid params.
function syn_aes_gcm_init¶
Initialize AES-GCM AEAD context (expands key and computes GHASH subkey H).
Parameters:
ctxPointer to GCM context to initialize.keySecret key buffer.key_lenLength of secret key in bytes (16, 24, or 32).
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on failure.
function syn_aes_ghash_mult¶
Multiply 16-byte block by GHASH subkey H in GF(2^128).
Parameters:
xInput 16-byte field element.hInput 16-byte GHASH subkey H.outOutput 16-byte product block.
function syn_aes_init¶
Initialize AES context and perform key expansion for 128/192/256-bit key.
Parameters:
ctxPointer to AES context to initialize.keySecret key buffer.key_lenLength of secret key in bytes (16, 24, or 32).
Returns:
SYN_OK on success, or SYN_INVALID_PARAM on invalid key size or NULL pointers.
Macro Definition Documentation¶
define SYN_AES_BLOCK_SIZE¶
AES cipher block size in bytes (16 bytes / 128 bits).
define SYN_AES_GCM_IV_DEFAULT_SIZE¶
Recommended GCM initialization vector size in bytes (12 bytes / 96 bits).
define SYN_AES_GCM_TABLE¶
GCM GHASH acceleration table strategy. 0 = bit-by-bit Shoup (0 bytes table, low footprint), 4 = 4-bit nibble table (256 bytes per GCM context), 8 = 8-bit byte table (4096 bytes per GCM context).
define SYN_AES_GCM_TAG_SIZE¶
Standard GCM authentication tag size in bytes (16 bytes / 128 bits).
define SYN_AES_KEY_SIZE_128¶
AES-128 key size in bytes (16 bytes / 128 bits).
define SYN_AES_KEY_SIZE_192¶
AES-192 key size in bytes (24 bytes / 192 bits).
define SYN_AES_KEY_SIZE_256¶
AES-256 key size in bytes (32 bytes / 256 bits).
define SYN_AES_MAX_EXPANDED_KEY¶
Maximum expanded round keys storage size in bytes.
define SYN_AES_MAX_KEY_BITS¶
Maximum key size in bits (128, 192, or 256). Controls context RAM footprint.
define SYN_AES_MAX_ROUNDS¶
Maximum rounds for configured key size.
define SYN_USE_AES_CBC¶
Enable CBC mode encryption and decryption with PKCS#7 padding.
define SYN_USE_AES_CTR¶
Enable CTR stream cipher mode.
define SYN_USE_AES_DECRYPT¶
Enable ECB and CBC decryption functions (pulls rsbox, +256B Flash).
define SYN_USE_AES_GCM¶
Enable GCM AEAD authenticated encryption and decryption.
The documentation for this class was generated from the following file src/syntropic/crypto/syn_aes.h