ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
chachapoly.h File Reference

chach.nosp@m.a20-.nosp@m.poly1.nosp@m.305@.nosp@m.opens.nosp@m.sh.c.nosp@m.om AEAD cipher (OpenSSH PROTOCOL.chacha20poly1305). More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

chach.nosp@m.a20-.nosp@m.poly1.nosp@m.305@.nosp@m.opens.nosp@m.sh.c.nosp@m.om AEAD cipher (OpenSSH PROTOCOL.chacha20poly1305).

OpenSSH's authenticated cipher for the SSH binary packet. The 512-bit key is split into two 256-bit ChaCha20 keys: K_main = key[0..32] encrypts the packet payload, K_header = key[32..64] encrypts the 4-byte packet-length field separately (so a receiver can size the packet before it has the whole thing). The nonce for both is the packet sequence number as a big-endian uint64.

  • Poly1305 key = first 32 bytes of ChaCha20(K_main, seqnr, counter 0)
  • encrypted length = ChaCha20(K_header, seqnr, counter 0) XOR length
  • encrypted payload = ChaCha20(K_main, seqnr, counter 1) XOR payload
  • tag = Poly1305(encrypted_length || encrypted_payload) (16 bytes, appended)

On decrypt the tag is verified (constant-time) before any plaintext is produced. Pure, no heap.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file chachapoly.h.