|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
IKEv2 (RFC 7296): the message and payload codec, the key schedule, and the handshake driver. More...
#include "protocore_config.h"Go to the source code of this file.
IKEv2 (RFC 7296): the message and payload codec, the key schedule, and the handshake driver.
RFC 7296 sec 3.1: a message begins with the 28-octet IKE header - IKE SA Initiator's SPI, IKE SA Responder's SPI, Next Payload, MjVer/MnVer, Exchange Type, Flags, Message ID, Length - and every multi-octet field is big endian. RFC 7296 sec 3.2: every payload begins with the generic payload header - Next Payload, the Critical bit, RESERVED, Payload Length - so the chain is walked forward from the header's Next Payload until a Next Payload of zero.
The codec frames the Security Association payload (sec 3.3) with its Proposal (sec 3.3.1) and Transform (sec 3.3.2) substructures and the Key Length attribute (sec 3.3.5), Key Exchange (sec 3.4), Identification (sec 3.5), Certificate and Certificate Request (sec 3.6, 3.7), Authentication (sec 3.8), Nonce (sec 3.9), Notify (sec 3.10), Delete (sec 3.11), Traffic Selector (sec 3.13), Encrypted (sec 3.14), Configuration (sec 3.15), and the Encrypted Fragment payload of RFC 7383 sec 2.5.
On the codec sits the crypto: prf+ (sec 2.13), the SKEYSEED / SK_* schedule (sec 2.14), the IKE SA rekey schedule (sec 2.18), Child SA KEYMAT (sec 2.17), the authenticated encryption that protects the Encrypted payload (RFC 5282 sec 3, 4 and 5.1: AES-GCM with a 16-octet ICV, ENCR transform id 20 per RFC 5282 sec 7.2), the Curve25519 key exchange (Diffie-Hellman Group Num 31, RFC 8031 sec 3), pre-shared key and digital-signature authentication (sec 2.15, RFC 7427 sec 3), and the stateless COOKIE (sec 2.6).
On the crypto sits the handshake driver: both roles run IKE_SA_INIT then IKE_AUTH (sec 1.2) to IKE_ST_ESTABLISHED with mutual pre-shared key authentication, then INFORMATIONAL (sec 1.4) and CREATE_CHILD_SA (sec 1.3) exchanges over the established SA.
The PRF is HMAC-SHA2-256, PRF transform id 5 (RFC 4868 sec 4), whose preferred key length fixes SK_d, SK_pi and SK_pr (sec 2.13); the integrity transform, when one is negotiated, is AUTH_HMAC_SHA2_256_128, id 12 (RFC 4868 sec 4), keyed with the 32-octet hash output (RFC 4868 sec 2.1.1). An AEAD cipher carries its own integrity, so SK_ai and SK_ar are then zero octets (RFC 5282 sec 7.1).
The module exports one symbol, Ike. Everything in ikev2.c has internal linkage. A caller sets the members a call takes, invokes it through ::Ike, and reads the outcome off the same handle.
Definition in file ikev2.h.