ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
aes128gcm.h File Reference

AEAD_AES_128_GCM (RFC 5116) - keyed, detached tag - and the AES-128 block it is built on. More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

AEAD_AES_128_GCM (RFC 5116) - keyed, detached tag - and the AES-128 block it is built on.

The shared 128-bit AES primitives for the whole library: the AEAD, and one 16-byte ECB block under a key of its own (QUIC header protection per RFC 9001 sec 5.4, the DTLS 1.3 sequence-number mask). Consumed by QUIC Initial packet protection (RFC 9001 sec 5.3/5.4), the DTLS 1.3 record layer, the TLS 1.3 record layer, and SMB 3.x transport encryption. The entries below are one surface over both arms: the GCM construction (GCTR and a table GHASH) is software on both, and only the AES-128 block under it changes, the part's AES accelerator where there is one and software AES-128 where there is not.

The entries are keyed: Aes128GcmNs::key_init once from the 16-byte key, then Aes128GcmNs::seal or Aes128GcmNs::open per record against it. There is no raw-key one-shot, so the key schedule and the GHASH table are built once per key rather than once per record. Aes128GcmNs::block_init keys the single block the same way, off its own part of the same borrow, so a caller holding one direction's key material holds one pointer.

The tag is detached: seal writes the ciphertext and the 16 tag bytes to separate destinations, which is where the SMB2 TRANSFORM_HEADER Signature field wants them. A wire format that carries the tag immediately after the ciphertext (QUIC, DTLS) passes ct_out + pt_len as tag_out and the tag lands in place.

Host-tested against the NIST GCM vectors and RFC 9001 Appendix A.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file aes128gcm.h.