mirror of
https://github.com/apache/nuttx.git
synced 2026-08-01 20:28:58 +00:00
crypto: add CRYPTO_CHACHA20_DJB variant (64-bit counter/nonce)
CRYPTO_CHACHA20 implements the RFC 8439/IETF parameterization (32-bit counter + 96-bit nonce). SSH's chacha20-poly1305@openssh.com uses the original DJB construction instead: a 64-bit block counter in state words 12..13 and a 64-bit nonce in words 14..15 (libtomcrypt's chacha_ivctr64). The two layouts produce different keystreams for the same key, so an SSH server cannot interoperate with OpenSSH clients through the IETF variant. Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
This commit is contained in:
parent
6d62533e4d
commit
5e2ce6190d
7 changed files with 49 additions and 1 deletions
|
|
@ -84,6 +84,32 @@ void chachapoly_reinit(caddr_t key, FAR uint8_t *iv)
|
||||||
chacha_ivsetup((FAR chacha_ctx *)ctx->block, iv, ctx->nonce);
|
chacha_ivsetup((FAR chacha_ctx *)ctx->block, iv, ctx->nonce);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
int chacha20_djb_setkey(FAR void *sched, FAR uint8_t *key, int len)
|
||||||
|
{
|
||||||
|
FAR struct chacha20_ctx *ctx = (FAR struct chacha20_ctx *)sched;
|
||||||
|
|
||||||
|
if (len != CHACHA20_KEYSIZE)
|
||||||
|
{
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
chacha_keysetup((FAR chacha_ctx *)ctx->block, key, CHACHA20_KEYSIZE * 8);
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
void chacha20_djb_reinit(caddr_t key, FAR uint8_t *iv)
|
||||||
|
{
|
||||||
|
FAR struct chacha20_ctx *ctx = (FAR struct chacha20_ctx *)key;
|
||||||
|
|
||||||
|
/* Original DJB ChaCha20 layout, as used by chacha20-poly1305@openssh.com
|
||||||
|
* (libtomcrypt chacha_ivctr64): the 16-byte IV is loaded verbatim into
|
||||||
|
* state words 12..15 as a 64-bit little-endian block counter followed by
|
||||||
|
* a 64-bit nonce.
|
||||||
|
*/
|
||||||
|
|
||||||
|
chacha_ivsetup((FAR chacha_ctx *)ctx->block, iv + 4, iv);
|
||||||
|
}
|
||||||
|
|
||||||
void chacha20_poly1305_init(FAR void *xctx)
|
void chacha20_poly1305_init(FAR void *xctx)
|
||||||
{
|
{
|
||||||
FAR CHACHA20_POLY1305_CTX *ctx = xctx;
|
FAR CHACHA20_POLY1305_CTX *ctx = xctx;
|
||||||
|
|
|
||||||
|
|
@ -237,6 +237,7 @@ static int cryptof_ioctl(FAR struct file *filep,
|
||||||
case CRYPTO_AES_CFB_8:
|
case CRYPTO_AES_CFB_8:
|
||||||
case CRYPTO_AES_CFB_128:
|
case CRYPTO_AES_CFB_128:
|
||||||
case CRYPTO_CHACHA20:
|
case CRYPTO_CHACHA20:
|
||||||
|
case CRYPTO_CHACHA20_DJB:
|
||||||
case CRYPTO_CHACHA20_POLY1305:
|
case CRYPTO_CHACHA20_POLY1305:
|
||||||
case CRYPTO_NULL:
|
case CRYPTO_NULL:
|
||||||
txform = true;
|
txform = true;
|
||||||
|
|
|
||||||
|
|
@ -1645,6 +1645,9 @@ int swcr_newsession(FAR uint32_t *sid, FAR struct cryptoini *cri)
|
||||||
case CRYPTO_CHACHA20:
|
case CRYPTO_CHACHA20:
|
||||||
txf = &enc_xform_chacha20;
|
txf = &enc_xform_chacha20;
|
||||||
goto enccommon;
|
goto enccommon;
|
||||||
|
case CRYPTO_CHACHA20_DJB:
|
||||||
|
txf = &enc_xform_chacha20_djb;
|
||||||
|
goto enccommon;
|
||||||
case CRYPTO_CHACHA20_POLY1305:
|
case CRYPTO_CHACHA20_POLY1305:
|
||||||
txf = &enc_xform_chacha20_poly1305;
|
txf = &enc_xform_chacha20_poly1305;
|
||||||
goto enccommon;
|
goto enccommon;
|
||||||
|
|
@ -1908,6 +1911,7 @@ int swcr_freesession(uint64_t tid)
|
||||||
case CRYPTO_AES_CFB_8:
|
case CRYPTO_AES_CFB_8:
|
||||||
case CRYPTO_AES_CFB_128:
|
case CRYPTO_AES_CFB_128:
|
||||||
case CRYPTO_CHACHA20:
|
case CRYPTO_CHACHA20:
|
||||||
|
case CRYPTO_CHACHA20_DJB:
|
||||||
case CRYPTO_CHACHA20_POLY1305:
|
case CRYPTO_CHACHA20_POLY1305:
|
||||||
case CRYPTO_NULL:
|
case CRYPTO_NULL:
|
||||||
txf = swd->sw_exf;
|
txf = swd->sw_exf;
|
||||||
|
|
@ -2047,6 +2051,7 @@ int swcr_process(struct cryptop *crp)
|
||||||
case CRYPTO_AES_CFB_8:
|
case CRYPTO_AES_CFB_8:
|
||||||
case CRYPTO_AES_CFB_128:
|
case CRYPTO_AES_CFB_128:
|
||||||
case CRYPTO_CHACHA20:
|
case CRYPTO_CHACHA20:
|
||||||
|
case CRYPTO_CHACHA20_DJB:
|
||||||
txf = sw->sw_exf;
|
txf = sw->sw_exf;
|
||||||
|
|
||||||
if (crp->crp_iv)
|
if (crp->crp_iv)
|
||||||
|
|
@ -2452,6 +2457,7 @@ void swcr_init(void)
|
||||||
algs[CRYPTO_AES_CFB_8] = CRYPTO_ALG_FLAG_SUPPORTED;
|
algs[CRYPTO_AES_CFB_8] = CRYPTO_ALG_FLAG_SUPPORTED;
|
||||||
algs[CRYPTO_AES_CFB_128] = CRYPTO_ALG_FLAG_SUPPORTED;
|
algs[CRYPTO_AES_CFB_128] = CRYPTO_ALG_FLAG_SUPPORTED;
|
||||||
algs[CRYPTO_CHACHA20] = CRYPTO_ALG_FLAG_SUPPORTED;
|
algs[CRYPTO_CHACHA20] = CRYPTO_ALG_FLAG_SUPPORTED;
|
||||||
|
algs[CRYPTO_CHACHA20_DJB] = CRYPTO_ALG_FLAG_SUPPORTED;
|
||||||
algs[CRYPTO_CHACHA20_POLY1305] = CRYPTO_ALG_FLAG_SUPPORTED;
|
algs[CRYPTO_CHACHA20_POLY1305] = CRYPTO_ALG_FLAG_SUPPORTED;
|
||||||
algs[CRYPTO_CHACHA20_POLY1305_MAC] = CRYPTO_ALG_FLAG_SUPPORTED;
|
algs[CRYPTO_CHACHA20_POLY1305_MAC] = CRYPTO_ALG_FLAG_SUPPORTED;
|
||||||
algs[CRYPTO_MD5] = CRYPTO_ALG_FLAG_SUPPORTED;
|
algs[CRYPTO_MD5] = CRYPTO_ALG_FLAG_SUPPORTED;
|
||||||
|
|
|
||||||
|
|
@ -318,6 +318,17 @@ const struct enc_xform enc_xform_chacha20 =
|
||||||
chacha20_reinit
|
chacha20_reinit
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const struct enc_xform enc_xform_chacha20_djb =
|
||||||
|
{
|
||||||
|
CRYPTO_CHACHA20_DJB, "CHACHA20-DJB",
|
||||||
|
64, 16, 32, 32,
|
||||||
|
sizeof(struct chacha20_ctx),
|
||||||
|
chacha20_crypt,
|
||||||
|
chacha20_crypt,
|
||||||
|
chacha20_djb_setkey,
|
||||||
|
chacha20_djb_reinit
|
||||||
|
};
|
||||||
|
|
||||||
const struct enc_xform enc_xform_chacha20_poly1305 =
|
const struct enc_xform enc_xform_chacha20_poly1305 =
|
||||||
{
|
{
|
||||||
CRYPTO_CHACHA20_POLY1305, "CHACHA20-POLY1305",
|
CRYPTO_CHACHA20_POLY1305, "CHACHA20-POLY1305",
|
||||||
|
|
|
||||||
|
|
@ -36,6 +36,8 @@ int chacha20_setkey(FAR void *, FAR uint8_t *, int);
|
||||||
void chacha20_reinit(caddr_t, FAR uint8_t *);
|
void chacha20_reinit(caddr_t, FAR uint8_t *);
|
||||||
void chacha20_crypt(caddr_t, FAR uint8_t *, size_t);
|
void chacha20_crypt(caddr_t, FAR uint8_t *, size_t);
|
||||||
void chachapoly_reinit(caddr_t, FAR uint8_t *);
|
void chachapoly_reinit(caddr_t, FAR uint8_t *);
|
||||||
|
int chacha20_djb_setkey(FAR void *, FAR uint8_t *, int);
|
||||||
|
void chacha20_djb_reinit(caddr_t, FAR uint8_t *);
|
||||||
|
|
||||||
#define POLY1305_KEYLEN 64
|
#define POLY1305_KEYLEN 64
|
||||||
#define POLY1305_TAGLEN 16
|
#define POLY1305_TAGLEN 16
|
||||||
|
|
|
||||||
|
|
@ -141,7 +141,8 @@
|
||||||
#define CRYPTO_ESN 40 /* Support for Extended Sequence Numbers */
|
#define CRYPTO_ESN 40 /* Support for Extended Sequence Numbers */
|
||||||
#define CRYPTO_SHA2_224_HMAC 41
|
#define CRYPTO_SHA2_224_HMAC 41
|
||||||
#define CRYPTO_CHACHA20 42
|
#define CRYPTO_CHACHA20 42
|
||||||
#define CRYPTO_ALGORITHM_MAX 42 /* Keep updated */
|
#define CRYPTO_CHACHA20_DJB 43
|
||||||
|
#define CRYPTO_ALGORITHM_MAX 43 /* Keep updated */
|
||||||
|
|
||||||
/* Algorithm flags */
|
/* Algorithm flags */
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -113,6 +113,7 @@ extern const struct enc_xform enc_xform_aes_ofb;
|
||||||
extern const struct enc_xform enc_xform_aes_cfb_8;
|
extern const struct enc_xform enc_xform_aes_cfb_8;
|
||||||
extern const struct enc_xform enc_xform_aes_cfb_128;
|
extern const struct enc_xform enc_xform_aes_cfb_128;
|
||||||
extern const struct enc_xform enc_xform_chacha20;
|
extern const struct enc_xform enc_xform_chacha20;
|
||||||
|
extern const struct enc_xform enc_xform_chacha20_djb;
|
||||||
extern const struct enc_xform enc_xform_chacha20_poly1305;
|
extern const struct enc_xform enc_xform_chacha20_poly1305;
|
||||||
extern const struct enc_xform enc_xform_null;
|
extern const struct enc_xform enc_xform_null;
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue