|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
chach.nosp@m.a20-.nosp@m.poly1.nosp@m.305@.nosp@m.opens.nosp@m.sh.c.nosp@m.om AEAD cipher (OpenSSH PROTOCOL.chacha20poly1305). More...
#include "protocore_config.h"Go to the source code of this file.
chach.nosp@m.a20-.nosp@m.poly1.nosp@m.305@.nosp@m.opens.nosp@m.sh.c.nosp@m.om AEAD cipher (OpenSSH PROTOCOL.chacha20poly1305).
OpenSSH's authenticated cipher for the SSH binary packet. The 512-bit key is split into two 256-bit ChaCha20 keys: K_main = key[0..32] encrypts the packet payload, K_header = key[32..64] encrypts the 4-byte packet-length field separately (so a receiver can size the packet before it has the whole thing). The nonce for both is the packet sequence number as a big-endian uint64.
On decrypt the tag is verified (constant-time) before any plaintext is produced. Pure, no heap.
Definition in file chachapoly.h.