Skip to content

File syn_hmac_drbg.c

FileList > crypto > syn_hmac_drbg.c

Go to the source code of this file

NIST SP 800-90A HMAC-DRBG (Deterministic Random Bit Generator) implementation.

  • #include "../util/syn_assert.h"
  • #include "syn_hmac_drbg.h"
  • #include <string.h>

Public Functions

Type Name
SYN_Status syn_hmac_drbg_generate (SYN_HMAC_DRBG * ctx, uint8_t * out, size_t out_len, const uint8_t * add_input, size_t add_len)
Generate pseudorandom bytes from the HMAC-DRBG.
SYN_Status syn_hmac_drbg_generate_pr (SYN_HMAC_DRBG * ctx, uint8_t * out, size_t out_len, const uint8_t * entropy, size_t ent_len, const uint8_t * add_input, size_t add_len)
Generate pseudorandom bytes with Prediction Resistance (PR).
SYN_Status syn_hmac_drbg_init (SYN_HMAC_DRBG * ctx, const uint8_t * entropy, size_t ent_len, const uint8_t * nonce, size_t nonce_len, const uint8_t * pers_str, size_t pers_len)
Instantiate the HMAC-DRBG state with initial entropy, nonce, and optional personalization.
SYN_Status syn_hmac_drbg_reseed (SYN_HMAC_DRBG * ctx, const uint8_t * entropy, size_t ent_len, const uint8_t * add_input, size_t add_len)
Reseed the HMAC-DRBG with fresh entropy and optional additional input.
void syn_hmac_drbg_set_reseed_interval (SYN_HMAC_DRBG * ctx, uint32_t interval)
Set the maximum reseed interval for the DRBG instance.
void syn_hmac_drbg_wipe (SYN_HMAC_DRBG * ctx)
Securely wipe internal working key, state vector, and counters.

Public Static Functions

Type Name
void drbg_update (SYN_HMAC_DRBG * ctx, const uint8_t * c1, size_t l1, const uint8_t * c2, size_t l2, const uint8_t * c3, size_t l3)
Internal HMAC-DRBG state update function per NIST SP 800-90A Rev 1 Section 10.1.2.2.

Public Functions Documentation

function syn_hmac_drbg_generate

Generate pseudorandom bytes from the HMAC-DRBG.

SYN_Status syn_hmac_drbg_generate (
    SYN_HMAC_DRBG * ctx,
    uint8_t * out,
    size_t out_len,
    const uint8_t * add_input,
    size_t add_len
) 

Implements NIST SP 800-90A Rev 1 Section 10.1.2.5 without prediction resistance.

Parameters:

  • ctx Pointer to initialized DRBG context.
  • out [out] Destination buffer for generated random bytes.
  • out_len Number of random bytes to generate (<= 65536).
  • add_input Optional additional input buffer (can be NULL).
  • add_len Length of additional input in bytes.

Returns:

SYN_OK on success, SYN_ERROR if reseed interval is exceeded (reseed required), SYN_INVALID_PARAM if parameters or state are invalid.


function syn_hmac_drbg_generate_pr

Generate pseudorandom bytes with Prediction Resistance (PR).

SYN_Status syn_hmac_drbg_generate_pr (
    SYN_HMAC_DRBG * ctx,
    uint8_t * out,
    size_t out_len,
    const uint8_t * entropy,
    size_t ent_len,
    const uint8_t * add_input,
    size_t add_len
) 

Reseeds the DRBG with fresh entropy before generating pseudorandom bytes.

Parameters:

  • ctx Pointer to initialized DRBG context.
  • out [out] Destination buffer for generated random bytes.
  • out_len Number of random bytes to generate (<= 65536).
  • entropy Fresh entropy for prediction resistance (must be >= 32 bytes).
  • ent_len Length of entropy in bytes (must be >= 32).
  • add_input Optional additional input buffer (can be NULL).
  • add_len Length of additional input in bytes.

Returns:

SYN_OK on success, SYN_INVALID_PARAM on invalid inputs.


function syn_hmac_drbg_init

Instantiate the HMAC-DRBG state with initial entropy, nonce, and optional personalization.

SYN_Status syn_hmac_drbg_init (
    SYN_HMAC_DRBG * ctx,
    const uint8_t * entropy,
    size_t ent_len,
    const uint8_t * nonce,
    size_t nonce_len,
    const uint8_t * pers_str,
    size_t pers_len
) 

Implements NIST SP 800-90A Rev 1 Section 10.1.2.3.

Parameters:

  • ctx Pointer to caller-allocated DRBG context.
  • entropy Initial entropy input buffer (must be at least 32 bytes).
  • ent_len Length of entropy in bytes (must be >= 32).
  • nonce Nonce buffer (can be NULL if ent_len includes extra entropy).
  • nonce_len Length of nonce in bytes.
  • pers_str Optional personalization string (can be NULL).
  • pers_len Length of personalization string in bytes.

Returns:

SYN_OK on success, SYN_INVALID_PARAM if inputs are invalid.


function syn_hmac_drbg_reseed

Reseed the HMAC-DRBG with fresh entropy and optional additional input.

SYN_Status syn_hmac_drbg_reseed (
    SYN_HMAC_DRBG * ctx,
    const uint8_t * entropy,
    size_t ent_len,
    const uint8_t * add_input,
    size_t add_len
) 

Implements NIST SP 800-90A Rev 1 Section 10.1.2.4.

Parameters:

  • ctx Pointer to initialized DRBG context.
  • entropy Fresh entropy input buffer (must be at least 32 bytes).
  • ent_len Length of entropy in bytes (must be >= 32).
  • add_input Optional additional input buffer (can be NULL).
  • add_len Length of additional input in bytes.

Returns:

SYN_OK on success, SYN_INVALID_PARAM if inputs or state are invalid.


function syn_hmac_drbg_set_reseed_interval

Set the maximum reseed interval for the DRBG instance.

void syn_hmac_drbg_set_reseed_interval (
    SYN_HMAC_DRBG * ctx,
    uint32_t interval
) 

Parameters:

  • ctx Pointer to DRBG context.
  • interval Maximum number of generate calls before reseed is required (default: 10000).

function syn_hmac_drbg_wipe

Securely wipe internal working key, state vector, and counters.

void syn_hmac_drbg_wipe (
    SYN_HMAC_DRBG * ctx
) 

Parameters:

  • ctx Pointer to DRBG context.

Public Static Functions Documentation

function drbg_update

Internal HMAC-DRBG state update function per NIST SP 800-90A Rev 1 Section 10.1.2.2.

static void drbg_update (
    SYN_HMAC_DRBG * ctx,
    const uint8_t * c1,
    size_t l1,
    const uint8_t * c2,
    size_t l2,
    const uint8_t * c3,
    size_t l3
) 

Parameters:

  • ctx Pointer to DRBG context.
  • c1 First chunk of provided data (or NULL).
  • l1 Length of first chunk.
  • c2 Second chunk of provided data (or NULL).
  • l2 Length of second chunk.
  • c3 Third chunk of provided data (or NULL).
  • l3 Length of third chunk.


The documentation for this class was generated from the following file src/syntropic/crypto/syn_hmac_drbg.c