|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
HMAC-SHA2-512 (RFC 2104 + FIPS 198-1) - streaming context and one-shot API. More...
#include "protocore_config.h"Go to the source code of this file.
Classes | |
| struct | HmacSha512Ns |
| Dispatch table. Addressed by offset, so the layout is asserted below. More... | |
Macros | |
| #define | PROTOCORE_HMAC_SHA512_LEN 64 |
| HMAC-SHA2-512 output length in bytes. | |
Functions | |
| PROTOCORE_NS_LAYOUT (HmacSha512Ns, init, update, final, mac) | |
| proto_bool | protocore_hmac_sha512_init (uint8_t *work, const uint8_t *key, size_t key_len) |
| Start a MAC under HmacSha512Ns::key_args. | |
| proto_bool | protocore_hmac_sha512_update (uint8_t *work, const uint8_t *data, size_t len) |
| Feed the running MAC a chunk. | |
| proto_bool | protocore_hmac_sha512_final (uint8_t *work, uint8_t *out) |
| Finish, writing the 64 bytes out. | |
| proto_bool | protocore_hmac_sha512_mac (uint8_t *work, const uint8_t *key, size_t key_len, const uint8_t *data, size_t len, uint8_t *out) |
| Init, update and final in one call, for a message already whole. | |
Variables | |
| PROTOCORE_NS HmacSha512Ns HmacSha512 | PROTOCORE_UNUSED |
| Module namespace. | |
HMAC-SHA2-512 (RFC 2104 + FIPS 198-1) - streaming context and one-shot API.
The shared HMAC-SHA512 primitive. Backs the SSH hmac-sha2-512 / hmac-.nosp@m.sha2.nosp@m.-512-.nosp@m.etm@.nosp@m.opens.nosp@m.sh.c.nosp@m.om integrity algorithms. Built over the Sha512Ns entries, so which arm compresses the inner hash is not visible here. SSH-derived MAC keys are 64 bytes (<= the 128-byte block), so the key is zero-padded, not pre-hashed.
RFC 2104 construction: HMAC(K, m) = H((K XOR opad) || H((K XOR ipad) || m)), H = SHA-512.
SECURITY NOTE - a MAC must be verified before the covered plaintext is acted upon; that ordering guarantee lives in each protocol's packet layer, not here. These functions are pure crypto.
For a MAC assembled from separate pieces - the SSH packet MAC over (uint32_be(seq_num) || plaintext_packet):
work is PROTOCORE_HMAC_SHA512_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. A connection takes those bytes once for its slot and passes them on every packet.
Definition in file hmac_sha512.h.
| #define PROTOCORE_HMAC_SHA512_LEN 64 |
HMAC-SHA2-512 output length in bytes.
Definition at line 38 of file hmac_sha512.h.
| PROTOCORE_NS_LAYOUT | ( | HmacSha512Ns | , |
| init | , | ||
| update | , | ||
| final | , | ||
| mac | |||
| ) |
| proto_bool protocore_hmac_sha512_init | ( | uint8_t * | work, |
| const uint8_t * | key, | ||
| size_t | key_len | ||
| ) |
Start a MAC under HmacSha512Ns::key_args.
| work | PROTOCORE_HMAC_SHA512_BORROW bytes the caller took. Not held past the call. |
| key | MAC key bytes |
| key_len | key length; > 128 is pre-hashed (RFC 2104), shorter is zero-padded to the block |
| proto_bool protocore_hmac_sha512_update | ( | uint8_t * | work, |
| const uint8_t * | data, | ||
| size_t | len | ||
| ) |
Feed the running MAC a chunk.
| work | PROTOCORE_HMAC_SHA512_BORROW bytes the caller took. Not held past the call. |
| data | the bytes |
| len | how many |
| proto_bool protocore_hmac_sha512_final | ( | uint8_t * | work, |
| uint8_t * | out | ||
| ) |
Finish, writing the 64 bytes out.
| work | PROTOCORE_HMAC_SHA512_BORROW bytes the caller took. Not held past the call. |
| out | PROTOCORE_HMAC_SHA512_LEN bytes |
| proto_bool protocore_hmac_sha512_mac | ( | uint8_t * | work, |
| const uint8_t * | key, | ||
| size_t | key_len, | ||
| const uint8_t * | data, | ||
| size_t | len, | ||
| uint8_t * | out | ||
| ) |
Init, update and final in one call, for a message already whole.
| work | PROTOCORE_HMAC_SHA512_BORROW bytes the caller took. Not held past the call. |
| key | MAC key bytes |
| key_len | key length |
| data | the message |
| len | its length |
| out | PROTOCORE_HMAC_SHA512_LEN bytes |
| PROTOCORE_NS HmacSha512Ns HmacSha512 PROTOCORE_UNUSED |
Module namespace.
Definition at line 87 of file hmac_sha512.h.