diff options
| author | Kévin Le Gouguec <kevin.legouguec@airbus.com> | 2018-11-27 10:37:56 +0100 |
|---|---|---|
| committer | Kévin Le Gouguec <kevin.legouguec@airbus.com> | 2018-11-27 10:37:56 +0100 |
| commit | 4fefe35fd63842b827016acecfadae891d0da953 (patch) | |
| tree | 48eb48e8bc2fdfc77b9158438733d1bd98f29e45 /src/ae-common.h | |
| parent | ef8bf4acd51c5eba9d205506b36e66da7a7bbc8b (diff) | |
| download | lilliput-ae-implem-4fefe35fd63842b827016acecfadae891d0da953.tar.xz | |
Extraction du traitement des données authentifiées
Commun à ΘCB3 et SCT-2.
Diffstat (limited to 'src/ae-common.h')
| -rw-r--r-- | src/ae-common.h | 61 |
1 files changed, 61 insertions, 0 deletions
diff --git a/src/ae-common.h b/src/ae-common.h index 6343f98..da5d04d 100644 --- a/src/ae-common.h +++ b/src/ae-common.h @@ -65,5 +65,66 @@ static inline void pad10(size_t X_len, const uint8_t X[X_len], uint8_t padded[BL } } +static inline void _fill_ad_tweak( + uint8_t prefix, + uint64_t block_nb, + uint8_t tweak[TWEAK_BYTES] +) +{ + /* The t-bit tweak is filled as follows: + * + * - bits [ 1, t-4]: block number + * [ 1, 64]: actual 64-bit block number + * [ 65, t-4]: 0-padding + * - bits [t-3, t]: constant 4-bit prefix + */ + + for (size_t i=0; i<sizeof(block_nb); i++) + { + uint64_t mask = (uint64_t)0xff << 8*i; + uint8_t b = (mask & block_nb) >> 8*i; + + tweak[i] = b; + } + + /* Assume padding bytes have already been memset to 0. */ + + tweak[TWEAK_BYTES-1] |= prefix << 4; +} + +static void process_associated_data( + const uint8_t key[KEY_BYTES], + size_t A_len, + const uint8_t A[A_len], + uint8_t Auth[BLOCK_BYTES] +) +{ + uint8_t Ek_Ai[BLOCK_BYTES]; + uint8_t tweak[TWEAK_BYTES]; + + memset(tweak, 0, TWEAK_BYTES); + memset(Auth, 0, BLOCK_BYTES); + + size_t l_a = A_len / BLOCK_BYTES; + size_t rest = A_len % BLOCK_BYTES; + + for (size_t i=0; i<l_a; i++) + { + _fill_ad_tweak(0x2, i, tweak); + encrypt(key, tweak, &A[i*BLOCK_BYTES], Ek_Ai); + xor_into(Auth, Ek_Ai); + } + + if (rest != 0) + { + uint8_t A_rest[BLOCK_BYTES]; + pad10(rest, &A[l_a*BLOCK_BYTES], A_rest); + _fill_ad_tweak(0x6, l_a, tweak); + encrypt(key, tweak, A_rest, Ek_Ai); + xor_into(Auth, Ek_Ai); + } +} + + #endif /* AE_COMMON_H */ |
