Skip to content

File syn_hmac_drbg.h

FileList > crypto > syn_hmac_drbg.h

Go to the source code of this file

NIST SP 800-90A HMAC-DRBG (Deterministic Random Bit Generator) with SHA-256. More...

  • #include "../common/syn_defs.h"
  • #include "syn_hmac.h"
  • #include <stdbool.h>
  • #include <stddef.h>
  • #include <stdint.h>

Classes

Type Name
struct SYN_HMAC_DRBG
HMAC-DRBG state context (NIST SP 800-90A).

Public Functions

Type Name
SYN_Status syn_hmac_drbg_generate (SYN_HMAC_DRBG * ctx, uint8_t * out, size_t out_len, const uint8_t * add_input, size_t add_len)
Generate pseudorandom bytes from the HMAC-DRBG.
SYN_Status syn_hmac_drbg_generate_pr (SYN_HMAC_DRBG * ctx, uint8_t * out, size_t out_len, const uint8_t * entropy, size_t ent_len, const uint8_t * add_input, size_t add_len)
Generate pseudorandom bytes with Prediction Resistance (PR).
SYN_Status syn_hmac_drbg_init (SYN_HMAC_DRBG * ctx, const uint8_t * entropy, size_t ent_len, const uint8_t * nonce, size_t nonce_len, const uint8_t * pers_str, size_t pers_len)
Instantiate the HMAC-DRBG state with initial entropy, nonce, and optional personalization.
SYN_Status syn_hmac_drbg_reseed (SYN_HMAC_DRBG * ctx, const uint8_t * entropy, size_t ent_len, const uint8_t * add_input, size_t add_len)
Reseed the HMAC-DRBG with fresh entropy and optional additional input.
void syn_hmac_drbg_set_reseed_interval (SYN_HMAC_DRBG * ctx, uint32_t interval)
Set the maximum reseed interval for the DRBG instance.
void syn_hmac_drbg_wipe (SYN_HMAC_DRBG * ctx)
Securely wipe internal working key, state vector, and counters.

Macros

Type Name
define SYN_HMAC_DRBG_DEFAULT_RESEED_INTERVAL 10000U
Default maximum number of generate requests before a reseed is required.
define SYN_HMAC_DRBG_MAX_REQUEST_BYTES 65536U
Maximum output bytes allowed per generate request (2^19 bits = 64 KiB).
define SYN_HMAC_DRBG_MIN_ENTROPY_LEN 32U
Minimum entropy length in bytes for 256-bit security strength (32 bytes).

Detailed Description

Implements a cryptographically secure pseudo-random number generator conforming to NIST SP 800-90A Rev. 1 Section 10.1.2.

Features: * HMAC-SHA256 PRF: 256-bit maximum security strength. * Deterministic Instantiation: Supports entropy input, nonce, and personalization string. * Reseeding: Allows periodic re-injection of entropy and additional input. * Prediction Resistance (PR): Optional on-demand reseeding per generate request. * Zero Dynamic Allocation: 72-byte caller-owned context. * Secure Zeroization: Explicit memory wipe to scrub cryptographic material.

** **

SYN_HMAC_DRBG drbg;
const uint8_t entropy[32] = { ... 256 bits of hardware entropy ... };
const uint8_t nonce[16]   = { ... 128 bits unique nonce ... };

// 1. Instantiate
syn_hmac_drbg_init(&drbg, entropy, sizeof(entropy), nonce, sizeof(nonce), NULL, 0);

// 2. Generate Random Bytes
uint8_t random_bytes[32];
syn_hmac_drbg_generate(&drbg, random_bytes, sizeof(random_bytes), NULL, 0);

// 3. Wipe When Done
syn_hmac_drbg_wipe(&drbg);

Public Functions Documentation

function syn_hmac_drbg_generate

Generate pseudorandom bytes from the HMAC-DRBG.

SYN_Status syn_hmac_drbg_generate (
    SYN_HMAC_DRBG * ctx,
    uint8_t * out,
    size_t out_len,
    const uint8_t * add_input,
    size_t add_len
) 

Implements NIST SP 800-90A Rev 1 Section 10.1.2.5 without prediction resistance.

Parameters:

  • ctx Pointer to initialized DRBG context.
  • out [out] Destination buffer for generated random bytes.
  • out_len Number of random bytes to generate (<= 65536).
  • add_input Optional additional input buffer (can be NULL).
  • add_len Length of additional input in bytes.

Returns:

SYN_OK on success, SYN_ERROR if reseed interval is exceeded (reseed required), SYN_INVALID_PARAM if parameters or state are invalid.


function syn_hmac_drbg_generate_pr

Generate pseudorandom bytes with Prediction Resistance (PR).

SYN_Status syn_hmac_drbg_generate_pr (
    SYN_HMAC_DRBG * ctx,
    uint8_t * out,
    size_t out_len,
    const uint8_t * entropy,
    size_t ent_len,
    const uint8_t * add_input,
    size_t add_len
) 

Reseeds the DRBG with fresh entropy before generating pseudorandom bytes.

Parameters:

  • ctx Pointer to initialized DRBG context.
  • out [out] Destination buffer for generated random bytes.
  • out_len Number of random bytes to generate (<= 65536).
  • entropy Fresh entropy for prediction resistance (must be >= 32 bytes).
  • ent_len Length of entropy in bytes (must be >= 32).
  • add_input Optional additional input buffer (can be NULL).
  • add_len Length of additional input in bytes.

Returns:

SYN_OK on success, SYN_INVALID_PARAM on invalid inputs.


function syn_hmac_drbg_init

Instantiate the HMAC-DRBG state with initial entropy, nonce, and optional personalization.

SYN_Status syn_hmac_drbg_init (
    SYN_HMAC_DRBG * ctx,
    const uint8_t * entropy,
    size_t ent_len,
    const uint8_t * nonce,
    size_t nonce_len,
    const uint8_t * pers_str,
    size_t pers_len
) 

Implements NIST SP 800-90A Rev 1 Section 10.1.2.3.

Parameters:

  • ctx Pointer to caller-allocated DRBG context.
  • entropy Initial entropy input buffer (must be at least 32 bytes).
  • ent_len Length of entropy in bytes (must be >= 32).
  • nonce Nonce buffer (can be NULL if ent_len includes extra entropy).
  • nonce_len Length of nonce in bytes.
  • pers_str Optional personalization string (can be NULL).
  • pers_len Length of personalization string in bytes.

Returns:

SYN_OK on success, SYN_INVALID_PARAM if inputs are invalid.


function syn_hmac_drbg_reseed

Reseed the HMAC-DRBG with fresh entropy and optional additional input.

SYN_Status syn_hmac_drbg_reseed (
    SYN_HMAC_DRBG * ctx,
    const uint8_t * entropy,
    size_t ent_len,
    const uint8_t * add_input,
    size_t add_len
) 

Implements NIST SP 800-90A Rev 1 Section 10.1.2.4.

Parameters:

  • ctx Pointer to initialized DRBG context.
  • entropy Fresh entropy input buffer (must be at least 32 bytes).
  • ent_len Length of entropy in bytes (must be >= 32).
  • add_input Optional additional input buffer (can be NULL).
  • add_len Length of additional input in bytes.

Returns:

SYN_OK on success, SYN_INVALID_PARAM if inputs or state are invalid.


function syn_hmac_drbg_set_reseed_interval

Set the maximum reseed interval for the DRBG instance.

void syn_hmac_drbg_set_reseed_interval (
    SYN_HMAC_DRBG * ctx,
    uint32_t interval
) 

Parameters:

  • ctx Pointer to DRBG context.
  • interval Maximum number of generate calls before reseed is required (default: 10000).

function syn_hmac_drbg_wipe

Securely wipe internal working key, state vector, and counters.

void syn_hmac_drbg_wipe (
    SYN_HMAC_DRBG * ctx
) 

Parameters:

  • ctx Pointer to DRBG context.

Macro Definition Documentation

define SYN_HMAC_DRBG_DEFAULT_RESEED_INTERVAL

Default maximum number of generate requests before a reseed is required.

#define SYN_HMAC_DRBG_DEFAULT_RESEED_INTERVAL `10000U`


define SYN_HMAC_DRBG_MAX_REQUEST_BYTES

Maximum output bytes allowed per generate request (2^19 bits = 64 KiB).

#define SYN_HMAC_DRBG_MAX_REQUEST_BYTES `65536U`


define SYN_HMAC_DRBG_MIN_ENTROPY_LEN

Minimum entropy length in bytes for 256-bit security strength (32 bytes).

#define SYN_HMAC_DRBG_MIN_ENTROPY_LEN `32U`



The documentation for this class was generated from the following file src/syntropic/crypto/syn_hmac_drbg.h