ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
ghash.h File Reference

GHASH (the GF(2^128) universal hash under AES-GCM, NIST SP 800-38D sec 6.3), 4-bit table. More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

GHASH (the GF(2^128) universal hash under AES-GCM, NIST SP 800-38D sec 6.3), 4-bit table.

The shared GHASH primitive for the whole library (AES-256-GCM, AES-128-GCM, DTLS 1.3). The textbook GHASH is a 128-iteration bitwise GF(2^128) multiply per 16-byte block, which makes AES-GCM the throughput floor of every AEAD record layer. There is no hardware GF-multiply on any die in the list, so the lever is algorithmic: the 4-bit table method (Shoup) builds a 16-entry table of i*H once per key, then folds four bits of the accumulator per step.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file ghash.h.