|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
AES-128-CMAC (RFC 4493 / NIST SP800-38B) - one-shot MAC. More...
#include "protocore_config.h"Go to the source code of this file.
Classes | |
| struct | AesCmacNs |
| Dispatch table. Addressed by offset, so the layout is asserted below. More... | |
Macros | |
| #define | PROTOCORE_AES_CMAC_LEN 16 |
| AES-128-CMAC output length (one AES block). | |
Functions | |
| PROTOCORE_NS_LAYOUT (AesCmacNs, mac) | |
| proto_bool | protocore_aes_cmac_mac (uint8_t *work, const uint8_t *key, const uint8_t *msg, size_t msg_len, uint8_t *out) |
| Derive K1/K2, CBC-MAC the message, write the 16 bytes out. | |
Variables | |
| PROTOCORE_NS AesCmacNs AesCmac | PROTOCORE_UNUSED = {.mac = protocore_aes_cmac_mac} |
| Module namespace. | |
AES-128-CMAC (RFC 4493 / NIST SP800-38B) - one-shot MAC.
The CMAC construction over the AES-128 block cipher: derive two subkeys K1/K2 from AES-128(key, 0^128), CBC-MAC the message, and XOR the final block with K1 (message a whole number of blocks) or the 10*-padded last block with K2. SMB 3.x uses it as the message-signing MAC when the negotiated signing algorithm is AES-CMAC (MS-SMB2 ยง3.1.4.1, dialects 3.0 / 3.0.2 / 3.1.1); it is a general primitive, not SMB-specific.
The entry below is one surface over both arms: a part with an AES peripheral encrypts a block on it, a part without runs the FIPS 197 rounds.
work is PROTOCORE_AES_CMAC_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. The borrow carries the round-key schedule and both subkeys, so two MACs are two borrows and never collide.
Definition in file aes_cmac.h.
| #define PROTOCORE_AES_CMAC_LEN 16 |
AES-128-CMAC output length (one AES block).
Definition at line 35 of file aes_cmac.h.
| PROTOCORE_NS_LAYOUT | ( | AesCmacNs | , |
| mac | |||
| ) |
| proto_bool protocore_aes_cmac_mac | ( | uint8_t * | work, |
| const uint8_t * | key, | ||
| const uint8_t * | msg, | ||
| size_t | msg_len, | ||
| uint8_t * | out | ||
| ) |
Derive K1/K2, CBC-MAC the message, write the 16 bytes out.
| work | PROTOCORE_AES_CMAC_BORROW bytes the caller took. Not held past the call. |
| key | the 16-byte AES-128 key |
| msg | the message; null iff msg_len is 0 |
| msg_len | message length in bytes; 0 is the empty-message CMAC |
| out | PROTOCORE_AES_CMAC_LEN bytes |
| PROTOCORE_NS AesCmacNs AesCmac PROTOCORE_UNUSED = {.mac = protocore_aes_cmac_mac} |
Module namespace.
Definition at line 56 of file aes_cmac.h.