|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Ephemeral Diffie-Hellman state for one SSH connection. More...
#include <transport.h>
Public Attributes | |
| protocore_bignum * | y |
| Server ephemeral private DH scalar (SENSITIVE - wiped after KEX). | |
| protocore_bignum * | f |
| Server DH public value = g^y mod p (sent to client). | |
| protocore_bignum * | K |
| Shared DH secret = e^y mod p (SENSITIVE - wiped after key derivation). | |
Ephemeral Diffie-Hellman state for one SSH connection.
The three protocore_bignum fields (y, f, K) together hold 768 bytes of sensitive material. The entire struct is wiped by ssh_dh_wipe() immediately after session keys are derived from K.
FIELD LIFETIME: y - generated by ssh_dh_generate(); zeroed in ssh_dh_wipe(). f - computed in ssh_dh_generate() as g^y mod p; sent in KEXDH_REPLY; zeroed in ssh_dh_wipe(). K - computed in ssh_dh_finish() as e^y mod p; used for key derivation; zeroed in ssh_dh_wipe() AFTER keys are installed.
Definition at line 704 of file transport.h.
| protocore_bignum* SshDhState::y |
Server ephemeral private DH scalar (SENSITIVE - wiped after KEX).
Definition at line 706 of file transport.h.
| protocore_bignum* SshDhState::f |
Server DH public value = g^y mod p (sent to client).
Definition at line 707 of file transport.h.
| protocore_bignum* SshDhState::K |
Shared DH secret = e^y mod p (SENSITIVE - wiped after key derivation).
Definition at line 708 of file transport.h.