ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
aes_block.h File Reference

Table-free software AES key schedule and single-block encrypt (FIPS 197). More...

#include "crypto/cipher/aes_sbox/aes_sbox.h"
#include "memoria_operor/memoria_operor.h"
#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  AesBlockNs
 Dispatch table. Addressed by offset, so the layout is asserted below. More...
 

Functions

PROTOCORE_INLINE uint8_t protocore_aes_xtime (uint8_t a)
 GF(2^8) multiply-by-2 (xtime) for the AES MixColumns step.
 
PROTOCORE_INLINE uint32_t protocore_aes_sub_word (uint32_t w)
 AES SubWord (FIPS 197 sec 5.2): apply the S-box to each of the four bytes of a 32-bit word.
 
PROTOCORE_INLINE uint32_t protocore_aes_rot_word (uint32_t w)
 AES RotWord (FIPS 197 sec 5.2): cyclically rotate a 32-bit word one byte left.
 
PROTOCORE_INLINE void protocore_aes_key_expand (const uint8_t *key, int nk, uint32_t *rk)
 AES key expansion (FIPS 197 sec 5.2). nk key words (4=AES-128, 8=AES-256); rk receives 4*(nk + 7) round-key words (44 for AES-128, 60 for AES-256).
 
PROTOCORE_INLINE void protocore_aes_encrypt_block (const uint32_t *rk, int nr, const uint8_t in[16], uint8_t out[16])
 AES single-block encrypt (FIPS 197 sec 5.1), nr rounds (10=AES-128, 14=AES-256). State is column-major: s[col*4 + row]. rk is the schedule from protocore_aes_key_expand.
 
 PROTOCORE_NS_LAYOUT (AesBlockNs, key_expand, encrypt_block)
 
proto_bool protocore_aes_block_key_expand (uint8_t *work, const uint8_t *key, int nk, uint32_t *rk)
 Expand a key into 4 * (nk + 7) round-key words.
 
proto_bool protocore_aes_block_encrypt_block (uint8_t *work, const uint32_t *rk, int nr, const uint8_t *in, uint8_t *out)
 Encrypt one 16-byte block under that schedule.
 

Variables

PROTOCORE_NS AesBlockNs AesBlock PROTOCORE_UNUSED
 Module namespace.
 

Detailed Description

Table-free software AES key schedule and single-block encrypt (FIPS 197).

The shared software AES primitive for the whole library: the key expansion of FIPS 197 sec 5.2 and the SubBytes/ShiftRows/MixColumns/AddRoundKey block of sec 5.1, parameterized on nk (key words: 4 for AES-128, 8 for AES-256) and nr (rounds: 10 or 14), so one implementation serves both key sizes. The software arms of AES-256-CTR, AES-256-GCM, AES-CCM and AES-CMAC run on it.

Only the S-box (PROTOCORE_AES_SBOX from aes_sbox.h) and the GF(2^8) xtime are used, no large T-tables: a table-indexed S-box and no secret-dependent branch. The five functions below stay inline in this header, where the per-block loops of those arms call them; ::AesBlock reaches the same key expansion and the same block through the namespace.

The round-key schedule and the block are the CALLER's: both entries write into the buffers its args name and hold neither past the call. work arrives goes unread: nothing is carried from one call to the next, so this module states no borrow and neither takes those bytes, holds them, releases them, nor wipes them.

The five functions above are the same key expansion and the same block plus the three one-liners they are built from, reached without the namespace, for a caller whose per-block loop inlines them.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file aes_block.h.

Function Documentation

◆ protocore_aes_xtime()

PROTOCORE_INLINE uint8_t protocore_aes_xtime ( uint8_t  a)

GF(2^8) multiply-by-2 (xtime) for the AES MixColumns step.

Definition at line 40 of file aes_block.h.

Referenced by protocore_aes_encrypt_block().

◆ protocore_aes_sub_word()

PROTOCORE_INLINE uint32_t protocore_aes_sub_word ( uint32_t  w)

AES SubWord (FIPS 197 sec 5.2): apply the S-box to each of the four bytes of a 32-bit word.

Definition at line 46 of file aes_block.h.

Referenced by protocore_aes_key_expand().

◆ protocore_aes_rot_word()

PROTOCORE_INLINE uint32_t protocore_aes_rot_word ( uint32_t  w)

AES RotWord (FIPS 197 sec 5.2): cyclically rotate a 32-bit word one byte left.

Definition at line 53 of file aes_block.h.

Referenced by protocore_aes_key_expand().

◆ protocore_aes_key_expand()

PROTOCORE_INLINE void protocore_aes_key_expand ( const uint8_t *  key,
int  nk,
uint32_t *  rk 
)

AES key expansion (FIPS 197 sec 5.2). nk key words (4=AES-128, 8=AES-256); rk receives 4*(nk + 7) round-key words (44 for AES-128, 60 for AES-256).

Definition at line 62 of file aes_block.h.

References protocore_aes_rot_word(), and protocore_aes_sub_word().

◆ protocore_aes_encrypt_block()

PROTOCORE_INLINE void protocore_aes_encrypt_block ( const uint32_t *  rk,
int  nr,
const uint8_t  in[16],
uint8_t  out[16] 
)

AES single-block encrypt (FIPS 197 sec 5.1), nr rounds (10=AES-128, 14=AES-256). State is column-major: s[col*4 + row]. rk is the schedule from protocore_aes_key_expand.

Definition at line 92 of file aes_block.h.

References protocore_aes_xtime().

◆ PROTOCORE_NS_LAYOUT()

PROTOCORE_NS_LAYOUT ( AesBlockNs  ,
key_expand  ,
encrypt_block   
)

◆ protocore_aes_block_key_expand()

proto_bool protocore_aes_block_key_expand ( uint8_t *  work,
const uint8_t *  key,
int  nk,
uint32_t *  rk 
)

Expand a key into 4 * (nk + 7) round-key words.

Parameters
workPROTOCORE_AES_BLOCK_BORROW bytes the caller took. Not held past the call.
key4 * nk key bytes
nkkey words: 4 for AES-128, 8 for AES-256
rk4 * (nk + 7) round-key words
Returns
PROTO_TRUE on success.

◆ protocore_aes_block_encrypt_block()

proto_bool protocore_aes_block_encrypt_block ( uint8_t *  work,
const uint32_t *  rk,
int  nr,
const uint8_t *  in,
uint8_t *  out 
)

Encrypt one 16-byte block under that schedule.

Parameters
workPROTOCORE_AES_BLOCK_BORROW bytes the caller took. Not held past the call.
rkthe schedule AesBlockNs::key_expand wrote
nrrounds: 10 for AES-128, 14 for AES-256
in16 input bytes
out16 output bytes; may alias in
Returns
PROTO_TRUE on success.

Variable Documentation

◆ PROTOCORE_UNUSED

PROTOCORE_NS AesBlockNs AesBlock PROTOCORE_UNUSED
Initial value:
proto_bool protocore_aes_block_key_expand(uint8_t *work, const uint8_t *key, int nk, uint32_t *rk)
Expand a key into 4 * (nk + 7) round-key words.
proto_bool protocore_aes_block_encrypt_block(uint8_t *work, const uint32_t *rk, int nr, const uint8_t *in, uint8_t *out)
Encrypt one 16-byte block under that schedule.

Module namespace.

Definition at line 205 of file aes_block.h.