ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
aes256ctr.h File Reference

AES-256-CTR stream cipher (aes256-ctr, RFC 4344 §4). More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

AES-256-CTR stream cipher (aes256-ctr, RFC 4344 §4).

The mandatory cipher for this SSH implementation. CTR mode turns AES into a stream cipher: each 16-byte counter block is AES-ECB encrypted into a keystream block and the data is XOR'd with it, so encrypt and decrypt are the identical operation. The entries below are one surface over both arms: a part with an AES peripheral runs the block on it, a part without runs the FIPS 197 rounds.

The two things that persist across packets are the caller's: the 32-byte key and the 16-byte counter, passed in on every call. The counter advances in place by ceil(len / 16) blocks, so successive calls continue the same stream.

COUNTER FORMAT (RFC 4344 §4) The 16-byte counter increments as a big-endian 128-bit integer after each 16-byte keystream block. The initial counter is the IV from the key exchange (RFC 4253 §7.2, labels 'A'/'B').

Note
The SSH binary packet is always a whole number of cipher blocks, so every call is block-aligned and the counter alone is sufficient state. A non-block-aligned length is permitted only as the final call of a stream (any leftover keystream in the last block is discarded, not carried).
Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file aes256ctr.h.