ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
hmac_sha384.h
Go to the documentation of this file.
1// ProtoCore v1.0.16 - Copyright (C) 2026 Douglas Quigg (dstroy0) <dquigg123@gmail.com>
2// SPDX-License-Identifier: AGPL-3.0-or-later
3
4#ifndef PROTOCORE_HMAC_SHA384_H
5#define PROTOCORE_HMAC_SHA384_H
6
7#include "protocore_config.h" // the entry point: protocore_types.h for the widths
8
10
11/**
12 * @file hmac_sha384.h
13 * @brief HMAC-SHA2-384 (RFC 2104 + FIPS 198-1) - streaming context and one-shot API.
14 *
15 * The shared HMAC-SHA384 primitive. Backs the HKDF the TLS 1.3 SHA-384 cipher suites run their key
16 * schedule on, and the Finished MAC under them. Built over the @ref Sha384Ns entries, so which arm
17 * compresses the inner hash is not visible here. TLS 1.3 keys a Finished MAC with a 48-byte secret
18 * (<= the 128-byte block), so the key is zero-padded, not pre-hashed.
19 *
20 * RFC 2104 construction: HMAC(K, m) = H((K XOR opad) || H((K XOR ipad) || m)), H = SHA-384. The block
21 * is SHA-512's 128 octets, not the 48-octet digest, so the pads are 128 wide (RFC 4231 sec 2 tabulates
22 * the published HMAC-SHA-384 vectors on that block).
23 *
24 * SECURITY NOTE - a MAC must be verified before the covered plaintext is acted upon; that ordering
25 * guarantee lives in each protocol's packet layer, not here. These functions are pure crypto.
26 *
27 * For a MAC assembled from separate pieces - an HKDF-Expand block over (T(i-1) || info || i):
28 *
29 * @c work is PROTOCORE_HMAC_SHA384_BORROW secure bytes the CALLER took, at an address it knows. It
30 * is not held past the call, so nothing here aliases it. The caller releases
31 * it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes
32 * it. A connection takes those bytes once for its slot and passes them on every record.
33 *
34 * @author Douglas Quigg (dstroy0)
35 * @date 2026
36 */
37
38/** @brief HMAC-SHA2-384 output length in bytes. */
39#define PROTOCORE_HMAC_SHA384_LEN 48
40
41/** @brief Dispatch table. Addressed by offset, so the layout is asserted below. */
42typedef struct
43{
44 proto_bool (*init)(uint8_t *, const uint8_t *, size_t);
45 proto_bool (*update)(uint8_t *, const uint8_t *, size_t);
46 proto_bool (*final)(uint8_t *, uint8_t *);
47 proto_bool (*mac)(uint8_t *, const uint8_t *, size_t, const uint8_t *, size_t, uint8_t *);
49PROTOCORE_NS_LAYOUT(HmacSha384Ns, init, update, final, mac);
50
51/**
52 * @brief Start a MAC under HmacSha384Ns::key_args.
53 * @param work PROTOCORE_HMAC_SHA384_BORROW bytes the caller took. Not held past the call.
54 * @param key MAC key bytes
55 * @param key_len key length; > 128 is pre-hashed (RFC 2104), shorter is zero-padded to the block
56 * @return PROTO_TRUE on success.
57 */
58proto_bool protocore_hmac_sha384_init(uint8_t *work, const uint8_t *key, size_t key_len);
59/**
60 * @brief Feed the running MAC a chunk.
61 * @param work PROTOCORE_HMAC_SHA384_BORROW bytes the caller took. Not held past the call.
62 * @param data the bytes
63 * @param len how many
64 * @return PROTO_TRUE on success.
65 */
66proto_bool protocore_hmac_sha384_update(uint8_t *work, const uint8_t *data, size_t len);
67/**
68 * @brief Finish, writing the 48 bytes out.
69 * @param work PROTOCORE_HMAC_SHA384_BORROW bytes the caller took. Not held past the call.
70 * @param out PROTOCORE_HMAC_SHA384_LEN bytes
71 * @return PROTO_TRUE on success.
72 */
73proto_bool protocore_hmac_sha384_final(uint8_t *work, uint8_t *out);
74/**
75 * @brief Init, update and final in one call, for a message already whole.
76 * @param work PROTOCORE_HMAC_SHA384_BORROW bytes the caller took. Not held past the call.
77 * @param key MAC key bytes
78 * @param key_len key length
79 * @param data the message
80 * @param len its length
81 * @param out PROTOCORE_HMAC_SHA384_LEN bytes
82 * @return PROTO_TRUE on success.
83 */
84proto_bool protocore_hmac_sha384_mac(uint8_t *work, const uint8_t *key, size_t key_len, const uint8_t *data, size_t len,
85 uint8_t *out);
86
87/** @brief Module namespace. */
92
94
95#endif // PROTOCORE_HMAC_SHA384_H
proto_bool protocore_hmac_sha384_mac(uint8_t *work, const uint8_t *key, size_t key_len, const uint8_t *data, size_t len, uint8_t *out)
Init, update and final in one call, for a message already whole.
PROTOCORE_NS HmacSha384Ns HmacSha384 PROTOCORE_UNUSED
Module namespace.
Definition hmac_sha384.h:88
proto_bool protocore_hmac_sha384_update(uint8_t *work, const uint8_t *data, size_t len)
Feed the running MAC a chunk.
proto_bool protocore_hmac_sha384_init(uint8_t *work, const uint8_t *key, size_t key_len)
Start a MAC under HmacSha384Ns::key_args.
proto_bool protocore_hmac_sha384_final(uint8_t *work, uint8_t *out)
Finish, writing the 48 bytes out.
#define PROTOCORE_NS_LAYOUT(T,...)
Pin every dispatch slot of a table that is nothing but function pointers.
#define PROTOCORE_NS
Storage for a dispatch table. The const is load bearing.
Dispatch table. Addressed by offset, so the layout is asserted below.
Definition hmac_sha384.h:43
proto_bool(* init)(uint8_t *, const uint8_t *, size_t)
Definition hmac_sha384.h:44
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
Definition types.h:96
_Bool proto_bool
The truth value.
Definition types.h:64
#define PROTOCORE_END_DECLS
Definition types.h:97