mirror of
https://github.com/apache/nuttx.git
synced 2026-09-13 06:00:17 +00:00
The existing CRYPTO_AES_CTR is the RFC 3686 profile: the last 4 bytes of the key are a nonce, the IV is 8 bytes and only the low 32 bits of the counter block are incremented. SSH aes128/192/256-ctr (RFC 4344) instead uses the key as-is (no embedded nonce) and treats the whole 16-byte IV as the initial counter block, incremented as a 128-bit big-endian integer, with the first keystream block being E(IV). Add CRYPTO_AES_CTR_SSH as a new enc_xform mirroring the CRYPTO_CHACHA20_DJB addition. It reuses struct aes_ctr_ctx and the AES block; only setkey (full key, no nonce), reinit (full 16-byte counter) and crypt (encrypt-then- increment over all 16 bytes) differ from the RFC 3686 variant. Keystream validated against `openssl enc -aes-128-ctr`, including a counter that carries across byte boundaries and a non-block-aligned tail. Signed-off-by: Felipe Moura <moura.fmo@gmail.com> |
||
|---|---|---|
| .. | ||
| aes.c | ||
| blake2s.c | ||
| blf.c | ||
| bn.c | ||
| cast.c | ||
| castsb.h | ||
| chacha_private.h | ||
| chachapoly.c | ||
| cmac.c | ||
| CMakeLists.txt | ||
| crypto.c | ||
| cryptodev.c | ||
| cryptosoft.c | ||
| curve25519.c | ||
| des_locl.h | ||
| ecb3_enc.c | ||
| ecb_enc.c | ||
| ecc.c | ||
| gmac.c | ||
| hmac.c | ||
| hmac_buff.c | ||
| idgen.c | ||
| Kconfig | ||
| key_wrap.c | ||
| Makefile | ||
| md5.c | ||
| podd.h | ||
| poly1305.c | ||
| random_pool.c | ||
| rijndael.c | ||
| rmd160.c | ||
| set_key.c | ||
| sha1.c | ||
| sha2.c | ||
| siphash.c | ||
| sk.h | ||
| spr.h | ||
| testmngr.c | ||
| testmngr.h | ||
| xform.c | ||