all repos — TinyCrypT @ 15791d38c8f011a16648742e77b25435ee93ab76

Short and sweet classical cryptographic primitives

tinycrypt/chacha20_poly1305.h (view raw)

 1
 2
 3
 4
 5
 6
 7
 8
 9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
#ifndef TNT_CC20_P1305_H
#define TNT_CC20_P1305_H

#include <stdbool.h>
#include <stdint.h>

/// Implements the AEAD-ChaCha20-Poly1305 encryption and MAC algorithm defined
/// in RFC 8439
void tct_aead_chacha20_poly1305_encrypt (
    const uint8_t *aad, const uint64_t aad_len, const uint8_t *key,
    const uint8_t *nonce, const uint8_t *plaintext,
    const uint64_t plaintext_len, uint8_t *cipher_out, uint8_t *mac_out);

/// Decrypts and verifies an AEAD-ChaCha20-Poly1305 frame
bool tct_aead_chacha20_poly1305_decrypt_and_verify (
    const uint8_t *aad, const uint64_t aad_len, const uint8_t *key,
    const uint8_t *nonce, const uint8_t *frame, const uint64_t ciphertext_len,
    uint8_t *plaintext_out);

/// Seals an SSH packet with the [email protected] cipher (RFC-
/// incompatible; matches OpenSSH's PROTOCOL.chacha20poly1305).
///
/// \param seqnr       8-byte packet sequence number (the ChaCha20 nonce).
/// \param key         64-byte key: K_2 = key[0..32) encrypts the payload and
///                    derives the Poly1305 key, K_1 = key[32..64) encrypts the
///                    4-byte length field.
/// \param packet      4-byte packet length followed by \p payload_len bytes.
/// \param payload_len number of payload bytes after the length field.
/// \param out         receives 4 + \p payload_len ciphertext bytes followed by
///                    a 16-byte Poly1305 tag.
void tct_chacha20_poly1305_openssh_seal (const uint8_t *seqnr,
                                         const uint8_t *key,
                                         const uint8_t *packet,
                                         uint32_t payload_len, uint8_t *out);

/// Decrypts only the 4-byte encrypted length field (with K_1), so a reader can
/// size the packet before authenticating it.
void tct_chacha20_poly1305_openssh_decrypt_length (const uint8_t *seqnr,
                                                   const uint8_t *key,
                                                   const uint8_t *enc_len,
                                                   uint8_t *len_out);

/// Verifies the tag and opens a [email protected] packet.
///
/// \param frame       4-byte encrypted length, \p payload_len encrypted payload
///                    bytes, then the 16-byte tag.
/// \param payload_len payload length (obtain via
///                    tct_chacha20_poly1305_openssh_decrypt_length).
/// \param packet_out  on success receives 4 + \p payload_len plaintext bytes
///                    (length field followed by payload).
/// \return true and writes \p packet_out on success; false (writing nothing) if
///         authentication fails.
bool tct_chacha20_poly1305_openssh_open (const uint8_t *seqnr,
                                         const uint8_t *key,
                                         const uint8_t *frame,
                                         uint32_t payload_len,
                                         uint8_t *packet_out);

#endif