ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
kdf.h
Go to the documentation of this file.
1// ProtoCore v1.0.16 - Copyright (C) 2026 Douglas Quigg (dstroy0) <dquigg123@gmail.com>
2// SPDX-License-Identifier: AGPL-3.0-or-later
3
4#ifndef PROTOCORE_KDF_H
5#define PROTOCORE_KDF_H
6
7#include "protocore_config.h" // the entry point: protocore_types.h for the widths
8
10
11/**
12 * @file kdf.h
13 * @brief SP800-108 counter-mode key derivation (HMAC-SHA256 PRF).
14 *
15 * The shared NIST SP800-108 §5.1 counter-mode KDF. SMB 3.x uses it to derive its signing and
16 * encryption keys (MS-SMB2 §3.1.4.2); the caller assembles the fixed input, keeping this independent
17 * of any protocol's label/context choices. Verified against the NIST CAVP KBKDF (KDFCTR) vectors.
18 * Built over the @ref HmacSha256Ns entries, so which arm compresses the PRF is not visible here.
19 *
20 * K(i) = HMAC-SHA256(Ki, [i]_32be || fixed); the blocks are concatenated for i = 1, 2, ... and the
21 * result truncated to @ref KdfCtrArgs::out_len bytes.
22 *
23 * @c work is PROTOCORE_KDF_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call,
24 * so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it,
25 * holds it, releases it, nor wipes it. That is what keeps K(i), which is derived from Ki, from outliving the caller.
26 *
27 * @author Douglas Quigg (dstroy0)
28 * @date 2026
29 */
30
31/** @brief Dispatch table. Addressed by offset, so the layout is asserted below. */
32typedef struct
33{
34 proto_bool (*ctr_hmac_sha256)(uint8_t *, const uint8_t *, size_t, const uint8_t *, size_t, uint8_t *, size_t);
35} KdfNs;
36PROTOCORE_NS_LAYOUT(KdfNs, ctr_hmac_sha256);
37
38/**
39 * @brief Derive out_len bytes, counter mode, HMAC-SHA256 PRF.
40 * @param work PROTOCORE_KDF_BORROW bytes the caller took. Not held past the call.
41 * @param ki the key-derivation key (e.g. the SMB 3.x session key)
42 * @param ki_len its length in bytes
43 * @param fixed the fixed input, `Label || 0x00 || Context || [L]`
44 * @param fixed_len its length in bytes
45 * @param out receives out_len derived bytes
46 * @param out_len number of output bytes, >= 1; the caller encodes L = out_len * 8 into fixed
47 * @return PROTO_TRUE on success.
48 */
49proto_bool protocore_kdf_ctr_hmac_sha256(uint8_t *work, const uint8_t *ki, size_t ki_len, const uint8_t *fixed,
50 size_t fixed_len, uint8_t *out, size_t out_len);
51
52/** @brief Module namespace. */
54
56
57#endif // PROTOCORE_KDF_H
PROTOCORE_NS KdfNs Kdf PROTOCORE_UNUSED
Module namespace.
Definition kdf.h:53
proto_bool protocore_kdf_ctr_hmac_sha256(uint8_t *work, const uint8_t *ki, size_t ki_len, const uint8_t *fixed, size_t fixed_len, uint8_t *out, size_t out_len)
Derive out_len bytes, counter mode, HMAC-SHA256 PRF.
#define PROTOCORE_NS_LAYOUT(T,...)
Pin every dispatch slot of a table that is nothing but function pointers.
#define PROTOCORE_NS
Storage for a dispatch table. The const is load bearing.
Dispatch table. Addressed by offset, so the layout is asserted below.
Definition kdf.h:33
proto_bool(* ctr_hmac_sha256)(uint8_t *, const uint8_t *, size_t, const uint8_t *, size_t, uint8_t *, size_t)
Definition kdf.h:34
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
Definition types.h:96
_Bool proto_bool
The truth value.
Definition types.h:64
#define PROTOCORE_END_DECLS
Definition types.h:97