|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
The two USM transforms: key localization and the privacy cipher (PROTOCORE_ENABLE_SNMP_V3). More...
#include "protocore_config.h"Go to the source code of this file.
The two USM transforms: key localization and the privacy cipher (PROTOCORE_ENABLE_SNMP_V3).
Exactly what the User-based Security Model needs, and nothing more.
Key localization. RFC 3414 sec 2.6 defines a localized key as one derived from a user's secret and the authoritative snmpEngineID, so a key that leaks reaches one engine only. RFC 7860 sec 5 says that localization for the HMAC-SHA-2 protocols "SHALL be performed according to [RFC3414] using the same SHA-2 hash function as in the HMAC-SHA-2 authentication protocol", and RFC 7860 sec 9.3 states the password-to-key derivation: the password is repeated to a 1,048,576 octet string and hashed to digest1, then digest1, snmpEngineID and digest1 again are hashed to the localized key. It is the RFC 3414 password-to-key algorithm with SHA-256 in place of MD5. The same procedure produces the authentication key and the privacy key, each from its own password.
Privacy. RFC 3826 defines usmAesCfb128Protocol: CFB128-AES-128. The cipher is AES (FIPS 197, not an RFC) and the mode is CFB with a 128-bit feedback segment (NIST SP 800-38A, not an RFC). RFC 3826 sec 3.1.2.1 states the 16-octet IV: snmpEngineBoots big-endian, then snmpEngineTime big-endian, then the 8-octet msgPrivacyParameters salt. The privacy key is the first 16 octets of the localized key.
CFB is a stream mode, so the output length equals the input length and no padding is added, and decryption is the same construction with the feedback taken from the ciphertext. The transform is safe in place. SHA-256 and HMAC-SHA-256 come from the shared hash and MAC modules. This software AES is not constant time.
Definition in file snmp_crypto.h.