|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
AES-256-CTR + HMAC-SHA2-256 session keys for one SSH connection. More...
#include <transport.h>
Public Attributes | |
| uint8_t * | aes_key_c2s |
| PROTOCORE_AES256CTR_KEY_LEN: AES key C→S (server decrypts inbound). | |
| uint8_t * | aes_key_s2c |
| PROTOCORE_AES256CTR_KEY_LEN: AES key S→C (server encrypts outbound). | |
| uint8_t * | aes_iv_c2s |
| PROTOCORE_AES256CTR_CTR_LEN: AES IV C→S (CTR counter / GCM nonce); advances per packet. | |
| uint8_t * | aes_iv_s2c |
| PROTOCORE_AES256CTR_CTR_LEN: AES IV S→C (CTR counter / GCM nonce); advances per packet. | |
| uint8_t * | mac_key_c2s |
| 64B: HMAC key, client-to-server (aes mode); 32 bytes for SHA-256, 64 for SHA-512. | |
| uint8_t * | mac_key_s2c |
| 64B: HMAC key, server-to-client (aes mode). | |
| uint8_t | mac_mode_c2s |
| SSH_MAC_* client-to-server (aes256-ctr only). | |
| uint8_t | mac_mode_s2c |
| SSH_MAC_* server-to-client (aes256-ctr only). | |
| uint8_t | cipher_mode_c2s |
| SSH_CIPHER_* client-to-server. | |
| uint8_t | cipher_mode_s2c |
| SSH_CIPHER_* server-to-client. | |
| uint8_t * | chacha_key_c2s |
| PROTOCORE_CHACHAPOLY_KEY_LEN: client-to-server, used only in chacha mode. | |
| uint8_t * | chacha_key_s2c |
| PROTOCORE_CHACHAPOLY_KEY_LEN: server-to-client, used only in chacha mode. | |
| uint8_t * | gcm_ctx_c2s |
| PROTOCORE_AESGCM_BORROW: keyed GCM context C→S (server opens inbound). | |
| uint8_t * | gcm_ctx_s2c |
| PROTOCORE_AESGCM_BORROW: keyed GCM context S→C (server seals outbound). | |
| proto_bool | active |
| True once keys are installed after successful KEX. | |
AES-256-CTR + HMAC-SHA2-256 session keys for one SSH connection.
This struct occupies a separate BSS symbol (ssh_keys[]) from the packet receive buffer (ssh_pool[].pkt_buf). See the security model at the top of this file for why that separation matters.
Key derivation follows RFC 4253 §7.2. After the DH exchange hash H is known and K is available, six values are derived:
IV_c2s = SHA256(K || H || "A" || session_id) [16 bytes] IV_s2c = SHA256(K || H || "B" || session_id) [16 bytes] key_c2s = SHA256(K || H || "C" || session_id) [32 bytes] key_s2c = SHA256(K || H || "D" || session_id) [32 bytes] mac_c2s = SHA256(K || H || "E" || session_id) [32 bytes] mac_s2c = SHA256(K || H || "F" || session_id) [32 bytes]
aes_key/aes_ctr C→S are the client-to-server key + counter (server decrypts inbound); S→C are the reverse (server encrypts outbound).
Definition at line 632 of file transport.h.
| uint8_t* SshKeyMat::aes_key_c2s |
PROTOCORE_AES256CTR_KEY_LEN: AES key C→S (server decrypts inbound).
Definition at line 642 of file transport.h.
| uint8_t* SshKeyMat::aes_key_s2c |
PROTOCORE_AES256CTR_KEY_LEN: AES key S→C (server encrypts outbound).
Definition at line 643 of file transport.h.
| uint8_t* SshKeyMat::aes_iv_c2s |
PROTOCORE_AES256CTR_CTR_LEN: AES IV C→S (CTR counter / GCM nonce); advances per packet.
Definition at line 644 of file transport.h.
| uint8_t* SshKeyMat::aes_iv_s2c |
PROTOCORE_AES256CTR_CTR_LEN: AES IV S→C (CTR counter / GCM nonce); advances per packet.
Definition at line 645 of file transport.h.
| uint8_t* SshKeyMat::mac_key_c2s |
64B: HMAC key, client-to-server (aes mode); 32 bytes for SHA-256, 64 for SHA-512.
Definition at line 647 of file transport.h.
| uint8_t* SshKeyMat::mac_key_s2c |
64B: HMAC key, server-to-client (aes mode).
Definition at line 648 of file transport.h.
| uint8_t SshKeyMat::mac_mode_c2s |
SSH_MAC_* client-to-server (aes256-ctr only).
Definition at line 651 of file transport.h.
| uint8_t SshKeyMat::mac_mode_s2c |
SSH_MAC_* server-to-client (aes256-ctr only).
Definition at line 652 of file transport.h.
| uint8_t SshKeyMat::cipher_mode_c2s |
SSH_CIPHER_* client-to-server.
Definition at line 653 of file transport.h.
| uint8_t SshKeyMat::cipher_mode_s2c |
SSH_CIPHER_* server-to-client.
Definition at line 654 of file transport.h.
| uint8_t* SshKeyMat::chacha_key_c2s |
PROTOCORE_CHACHAPOLY_KEY_LEN: client-to-server, used only in chacha mode.
Definition at line 656 of file transport.h.
| uint8_t* SshKeyMat::chacha_key_s2c |
PROTOCORE_CHACHAPOLY_KEY_LEN: server-to-client, used only in chacha mode.
Definition at line 657 of file transport.h.
| uint8_t* SshKeyMat::gcm_ctx_c2s |
PROTOCORE_AESGCM_BORROW: keyed GCM context C→S (server opens inbound).
Definition at line 668 of file transport.h.
| uint8_t* SshKeyMat::gcm_ctx_s2c |
PROTOCORE_AESGCM_BORROW: keyed GCM context S→C (server seals outbound).
Definition at line 669 of file transport.h.
| proto_bool SshKeyMat::active |
True once keys are installed after successful KEX.
Definition at line 671 of file transport.h.