4#ifndef PROTOCORE_DTLS_RECORD_H
5#define PROTOCORE_DTLS_RECORD_H
50#define PROTOCORE_DTLS_CT_CHANGE_CIPHER_SPEC 20
51#define PROTOCORE_DTLS_CT_ALERT 21
52#define PROTOCORE_DTLS_CT_HANDSHAKE 22
53#define PROTOCORE_DTLS_CT_APPLICATION_DATA 23
54#define PROTOCORE_DTLS_CT_ACK 26
58#define PROTOCORE_DTLS_LEGACY_VERSION 0xFEFD
61#define PROTOCORE_DTLS_PLAINTEXT_HDR_LEN 13
64#define PROTOCORE_DTLS_TAG_LEN 16
69#define PROTOCORE_DTLS_CID_MAX 8
125 size_t (*plaintext_build)(uint8_t *, uint8_t, uint16_t, uint64_t,
const uint8_t *, size_t, uint8_t *, size_t);
126 size_t (*plaintext_parse)(uint8_t *,
const uint8_t *, size_t,
DtlsPlaintext *);
127 size_t (*protect)(uint8_t *,
DtlsRecordKeys *, uint64_t, uint8_t,
const uint8_t *, size_t, uint8_t *, size_t,
128 const uint8_t *, size_t);
136 replay_check, replay_mark);
147 const uint8_t *secret);
161 const uint8_t *fragment,
size_t frag_len, uint8_t *out,
size_t out_cap);
186 const uint8_t *plaintext,
size_t pt_len, uint8_t *out,
size_t out_cap,
187 const uint8_t *cid,
size_t cid_len);
203 size_t rec_len, uint8_t *out,
size_t out_cap,
DtlsCiphertext *info,
204 const uint8_t *expected_cid,
size_t expected_cid_len);
PROTO_ENUM_PACKED
Application protocol spoken on a listener port or connection slot.
enum PROTO_ENUM_PACKED DtlsCipher
Record-layer AEAD suites (phase 1: AEAD_AES_128_GCM with SHA-256).
void protocore_dtls_record_replay_mark(uint8_t *work, DtlsReplayWindow *w, uint64_t seq)
Record seq as accepted and advance the window; only after a .
void protocore_dtls_record_replay_init(uint8_t *work, DtlsReplayWindow *w)
Reset a replay window to empty.
PROTOCORE_NS DtlsRecordNs DtlsRecord PROTOCORE_UNUSED
Module namespace.
size_t protocore_dtls_record_protect(uint8_t *work, DtlsRecordKeys *keys, uint64_t seq, uint8_t content_type, const uint8_t *plaintext, size_t pt_len, uint8_t *out, size_t out_cap, const uint8_t *cid, size_t cid_len)
Seal one record (RFC 9147 sec 4.2): the unified header, the .
size_t protocore_dtls_record_plaintext_build(uint8_t *work, uint8_t content_type, uint16_t epoch, uint64_t seq, const uint8_t *fragment, size_t frag_len, uint8_t *out, size_t out_cap)
A DTLSPlaintext record; bytes written (13 + frag_len), or 0 on .
proto_bool protocore_dtls_record_replay_check(uint8_t *work, const DtlsReplayWindow *w, uint64_t seq)
Whether seq is new and inside the window, rather than a replay or .
proto_bool protocore_dtls_record_unprotect(uint8_t *work, DtlsRecordKeys *keys, uint64_t next_seq, const uint8_t *rec, size_t rec_len, uint8_t *out, size_t out_cap, DtlsCiphertext *info, const uint8_t *expected_cid, size_t expected_cid_len)
Open one received record: decrypt the sequence number, rebuild the .
@ DTLS_CIPHER_AES_128_GCM_SHA256
size_t protocore_dtls_record_plaintext_parse(uint8_t *work, const uint8_t *rec, size_t rec_len, DtlsPlaintext *out)
The same record back, validating legacy_version and the length .
void protocore_dtls_record_keys_derive(uint8_t *work, DtlsRecordKeys *out, DtlsCipher cipher, uint16_t epoch, const uint8_t *secret)
Derive one direction's record keys from a 32-byte TLS 1.3 traffic .
#define PROTOCORE_AES128GCM_BORROW
#define PROTOCORE_NS_LAYOUT(T,...)
Pin every dispatch slot of a table that is nothing but function pointers.
#define PROTOCORE_NS
Storage for a dispatch table. The const is load bearing.
Result of a successful protocore_dtls_ciphertext_unprotect.
uint64_t seq
reconstructed full sequence number
size_t pt_len
plaintext bytes written to out
uint16_t epoch
epoch of keys (its low 2 bits matched the header)
uint8_t content_type
recovered inner content type (last non-zero byte of the inner plaintext)
Parsed view of a DTLSPlaintext record (fields point into the caller's buffer).
uint64_t seq
48-bit record sequence number
const uint8_t * fragment
into the input buffer
One direction's record-protection keys for one epoch (RFC 9147 §4).
DtlsCipher cipher
negotiated AEAD (phase 1: AES-128-GCM)
uint16_t epoch
this epoch number; its low 2 bits appear in the unified header
Dispatch table. Addressed by offset, so the layout is asserted below.
void(* keys_derive)(uint8_t *, DtlsRecordKeys *, DtlsCipher, uint16_t, const uint8_t *)
64-record sliding replay window over the highest sequence number accepted in an epoch.
uint64_t highest
highest accepted sequence number (bit 0 of bitmap)
uint64_t bitmap
bit i set => (highest - i) has been accepted
proto_bool seeded
false until the first record is accepted
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
_Bool proto_bool
The truth value.
#define PROTOCORE_END_DECLS