ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
aes_cmac.h
Go to the documentation of this file.
1// ProtoCore v1.0.16 - Copyright (C) 2026 Douglas Quigg (dstroy0) <dquigg123@gmail.com>
2// SPDX-License-Identifier: AGPL-3.0-or-later
3
4#ifndef PROTOCORE_AES_CMAC_H
5#define PROTOCORE_AES_CMAC_H
6
7#include "protocore_config.h" // the entry point: protocore_types.h for the widths
8
10
11/**
12 * @file aes_cmac.h
13 * @brief AES-128-CMAC (RFC 4493 / NIST SP800-38B) - one-shot MAC.
14 *
15 * The CMAC construction over the AES-128 block cipher: derive two subkeys K1/K2 from
16 * AES-128(key, 0^128), CBC-MAC the message, and XOR the final block with K1 (message a whole
17 * number of blocks) or the 10*-padded last block with K2. SMB 3.x uses it as the message-signing
18 * MAC when the negotiated signing algorithm is AES-CMAC (MS-SMB2 ยง3.1.4.1, dialects 3.0 / 3.0.2 /
19 * 3.1.1); it is a general primitive, not SMB-specific.
20 *
21 * The entry below is one surface over both arms: a part with an AES peripheral encrypts a block on
22 * it, a part without runs the FIPS 197 rounds.
23 *
24 * @c work is PROTOCORE_AES_CMAC_BORROW secure bytes the CALLER took, at an address it knows. It
25 * is not held past the call, so nothing here aliases it. The caller releases
26 * it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes
27 * it. The borrow carries the round-key schedule and both subkeys, so two MACs are two borrows and
28 * never collide.
29 *
30 * @author Douglas Quigg (dstroy0)
31 * @date 2026
32 */
33
34/** @brief AES-128-CMAC output length (one AES block). */
35#define PROTOCORE_AES_CMAC_LEN 16
36
37/** @brief Dispatch table. Addressed by offset, so the layout is asserted below. */
38typedef struct
39{
40 proto_bool (*mac)(uint8_t *, const uint8_t *, const uint8_t *, size_t, uint8_t *);
41} AesCmacNs;
43
44/**
45 * @brief Derive K1/K2, CBC-MAC the message, write the 16 bytes out.
46 * @param work PROTOCORE_AES_CMAC_BORROW bytes the caller took. Not held past the call.
47 * @param key the 16-byte AES-128 key
48 * @param msg the message; null iff msg_len is 0
49 * @param msg_len message length in bytes; 0 is the empty-message CMAC
50 * @param out PROTOCORE_AES_CMAC_LEN bytes
51 * @return PROTO_TRUE on success.
52 */
53proto_bool protocore_aes_cmac_mac(uint8_t *work, const uint8_t *key, const uint8_t *msg, size_t msg_len, uint8_t *out);
54
55/** @brief Module namespace. */
57
59
60#endif // PROTOCORE_AES_CMAC_H
proto_bool protocore_aes_cmac_mac(uint8_t *work, const uint8_t *key, const uint8_t *msg, size_t msg_len, uint8_t *out)
Derive K1/K2, CBC-MAC the message, write the 16 bytes out.
PROTOCORE_NS AesCmacNs AesCmac PROTOCORE_UNUSED
Module namespace.
Definition aes_cmac.h:56
#define PROTOCORE_NS_LAYOUT(T,...)
Pin every dispatch slot of a table that is nothing but function pointers.
#define PROTOCORE_NS
Storage for a dispatch table. The const is load bearing.
Dispatch table. Addressed by offset, so the layout is asserted below.
Definition aes_cmac.h:39
proto_bool(* mac)(uint8_t *, const uint8_t *, const uint8_t *, size_t, uint8_t *)
Definition aes_cmac.h:40
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
Definition types.h:96
_Bool proto_bool
The truth value.
Definition types.h:64
#define PROTOCORE_END_DECLS
Definition types.h:97