|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
AES-256-GCM AEAD (RFC 5116) - keyed, detached tag. More...
#include "protocore_config.h"Go to the source code of this file.
AES-256-GCM AEAD (RFC 5116) - keyed, detached tag.
The shared AES-256-GCM primitive for the whole library (SSH aes25.nosp@m.6-gc.nosp@m.m@ope.nosp@m.nssh.nosp@m..com per RFC 5647, and SMB 3.x transport encryption). The entries below are one surface over both arms: the GCM construction and the table GHASH run in software on both, and only the AES-256 block under them changes arm - the part's AES accelerator where it carries one, software AES-256 where it does not.
The entries are keyed: AesGcmNs::key_init once from the 32-byte key, then AesGcmNs::seal or AesGcmNs::open per record against it. There is no raw-key one-shot; key_init binds the key, derives H = E(K, 0^128) and builds the 4-bit GHASH table, a per-key cost every record would otherwise repeat.
The tag is detached: seal writes the ciphertext and the 16 tag bytes to separate destinations, which is where the SSH packet and the SMB2 TRANSFORM_HEADER Signature field each want them. No nonce state is kept or advanced by a seal or an open; AesGcmNs::iv_increment advances the caller's.
Host-tested byte-exact against the NIST/McGrew AES-256-GCM vectors.
Definition in file aesgcm.h.