crys_aesccm.h 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315
  1. /**************************************************************************************
  2. * Copyright (c) 2016-2017, ARM Limited or its affiliates. All rights reserved *
  3. * *
  4. * This file and the related binary are licensed under the following license: *
  5. * *
  6. * ARM Object Code and Header Files License, v1.0 Redistribution. *
  7. * *
  8. * Redistribution and use of object code, header files, and documentation, without *
  9. * modification, are permitted provided that the following conditions are met: *
  10. * *
  11. * 1) Redistributions must reproduce the above copyright notice and the *
  12. * following disclaimer in the documentation and/or other materials *
  13. * provided with the distribution. *
  14. * *
  15. * 2) Unless to the extent explicitly permitted by law, no reverse *
  16. * engineering, decompilation, or disassembly of is permitted. *
  17. * *
  18. * 3) Redistribution and use is permitted solely for the purpose of *
  19. * developing or executing applications that are targeted for use *
  20. * on an ARM-based product. *
  21. * *
  22. * DISCLAIMER. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND *
  23. * CONTRIBUTORS "AS IS." ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT *
  24. * NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT, *
  25. * AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE *
  26. * COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, *
  27. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED *
  28. * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR *
  29. * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF *
  30. * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING *
  31. * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS *
  32. * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. *
  33. **************************************************************************************/
  34. #ifndef CRYS_AESCCM_H
  35. #define CRYS_AESCCM_H
  36. #include "ssi_pal_types.h"
  37. #include "crys_error.h"
  38. #include "ssi_aes.h"
  39. #ifdef __cplusplus
  40. extern "C"
  41. {
  42. #endif
  43. /*!
  44. @file
  45. @brief This file contains all of the enums and definitions that are used for the CRYS AESCCM APIs, as well as the APIs themselves.
  46. The API supports AES-CCM and AES-CCM* as defined in ieee-802.15.4.
  47. @defgroup crys_aesccm CryptoCell AES-CCM APIs
  48. @{
  49. @ingroup cryptocell_api
  50. @note
  51. Regarding the AES-CCM*, the API supports only AES-CCM* as defined in ieee-802.15.4-2011; With the instantiations as defined in B.3.2 and the nonce as defined in 7.3.2.
  52. in case of AES-CCM* the flow should be as follows:
  53. <ul><li>AES-CCM* integrated</li>
  54. <ul><li>CRYS_AESCCMStar_NonceGenerate</li>
  55. <li>CRYS_AESCCMStar</li></ul></ul>
  56. <ul><li>AES-CCM* non-integrated</li>
  57. <ul><li>CRYS_AESCCMStar_NonceGenerate</li>
  58. <li>CRYS_AESCCMStar_Init</li>
  59. <li>CRYS_AESCCM_BlockAdata</li>
  60. <li>CRYS_AESCCM_BlockTextData</li>
  61. <li>CRYS_AESCCM_Finish</li></ul></ul>
  62. */
  63. /************************ Defines ******************************/
  64. /*! AES CCM context size in words.*/
  65. #define CRYS_AESCCM_USER_CTX_SIZE_IN_WORDS (152/4)
  66. /*! AES CCM maximal key size in words. */
  67. #define CRYS_AESCCM_KEY_SIZE_WORDS 8
  68. /* nonce and AESCCM-MAC sizes definitions */
  69. /*! AES CCM NONCE minimal size in bytes. */
  70. #define CRYS_AESCCM_NONCE_MIN_SIZE_BYTES 7
  71. /*! AES CCM NONCE maximal size in bytes. */
  72. #define CRYS_AESCCM_NONCE_MAX_SIZE_BYTES 13
  73. /*! AES CCM MAC minimal size in bytes..*/
  74. #define CRYS_AESCCM_MAC_MIN_SIZE_BYTES 4
  75. /*! AES CCM MAC maximal size in bytes. */
  76. #define CRYS_AESCCM_MAC_MAX_SIZE_BYTES 16
  77. /*! AES CCM star NONCE size in bytes. */
  78. #define CRYS_AESCCM_STAR_NONCE_SIZE_BYTES 13
  79. /*! AES CCM star source address size in bytes. */
  80. #define CRYS_AESCCM_STAR_SOURCE_ADDRESS_SIZE_BYTES 8
  81. /*! AES CCM mode - CCM. */
  82. #define CRYS_AESCCM_MODE_CCM 0
  83. /*! AES CCM mode - CCM STAR. */
  84. #define CRYS_AESCCM_MODE_STAR 1
  85. /************************ Typedefs ****************************/
  86. /*! AES CCM key sizes. */
  87. typedef enum {
  88. /*! Key size 128 bits. */
  89. CRYS_AES_Key128BitSize = 0,
  90. /*! Key size 192 bits. */
  91. CRYS_AES_Key192BitSize = 1,
  92. /*! Key size 256 bits. */
  93. CRYS_AES_Key256BitSize = 2,
  94. /*! Key size 512 bits. */
  95. CRYS_AES_Key512BitSize = 3,
  96. /*! Number of optional key sizes. */
  97. CRYS_AES_KeySizeNumOfOptions,
  98. /*! Reserved. */
  99. CRYS_AES_KeySizeLast = 0x7FFFFFFF,
  100. }CRYS_AESCCM_KeySize_t;
  101. /*! AES_CCM key buffer definition.*/
  102. typedef uint8_t CRYS_AESCCM_Key_t[CRYS_AESCCM_KEY_SIZE_WORDS * sizeof(uint32_t)];
  103. /*! AES_CCM MAC buffer definition.*/
  104. typedef uint8_t CRYS_AESCCM_Mac_Res_t[SASI_AES_BLOCK_SIZE_IN_BYTES];
  105. /*! AES_CCM_STAR source address buffer defintion. */
  106. typedef uint8_t CRYS_AESCCMStar_SourceAddress_t[CRYS_AESCCM_STAR_SOURCE_ADDRESS_SIZE_BYTES];
  107. /*! AES_CCM_STAR Nonce buffer defintion. */
  108. typedef uint8_t CRYS_AESCCMStar_Nonce_t[CRYS_AESCCM_STAR_NONCE_SIZE_BYTES];
  109. /******************* Context Structure ***********************/
  110. /*! The user's context structure - the argument type that is passed by the user to the AES CCM APIs */
  111. typedef struct CRYS_AESCCM_UserContext_t
  112. {
  113. /*! AES CCM context buffer for internal usage. */
  114. uint32_t buff[CRYS_AESCCM_USER_CTX_SIZE_IN_WORDS];
  115. }CRYS_AESCCM_UserContext_t;
  116. /************************ Public Functions **********************/
  117. /*!
  118. @brief This function initializes the AES CCM context.
  119. It formats of the input data, calculates AES-MAC value for the formatted B0 block containing control information and
  120. CCM unique value (Nonce), and initializes the AES context structure including the initial CTR0 value.
  121. @return CRYS_OK on success.
  122. @return A non-zero value on failure as defined crys_aesccm_error.h.
  123. */
  124. CRYSError_t CC_AESCCM_Init(
  125. CRYS_AESCCM_UserContext_t *ContextID_ptr, /*!< [in] Pointer to the AES context buffer that is allocated by the user and is used for
  126. the AES operation. */
  127. SaSiAesEncryptMode_t EncrDecrMode, /*!< [in] Flag specifying whether Encrypt (::SASI_AES_ENCRYPT) or Decrypt
  128. (::SASI_AES_DECRYPT) operation should be performed. */
  129. CRYS_AESCCM_Key_t CCM_Key, /*!< [in] Pointer to the AES-CCM key. */
  130. CRYS_AESCCM_KeySize_t KeySizeId, /*!< [in] Enumerator defining the key size (only 128 bit is valid). */
  131. uint32_t AdataSize, /*!< [in] Full byte length of additional (associated) data. If set to zero,
  132. calling ::CRYS_AESCCM_BlockAdata on the same context would return an error. */
  133. uint32_t TextSizeQ, /*!< [in] Full length of plain text data. */
  134. uint8_t *N_ptr, /*!< [in] Pointer to the Nonce. */
  135. uint8_t SizeOfN, /*!< [in] Nonce byte size. The valid values depend on the ccm mode:
  136. <ul><li>CCM: valid values = [7 .. 13].</li>
  137. <li>CCM*: valid values = [13].</li></ul> */
  138. uint8_t SizeOfT, /*!< [in] AES-CCM MAC (tag) byte size. The valid values depend on the ccm mode:
  139. <ul><li>CCM: valid values = [4, 6, 8, 10, 12, 14, 16].</li>
  140. <li>CCM*: valid values = [0, 4, 8, 16].</li></ul>*/
  141. uint32_t ccmMode /*!< [in] Flag specifying whether AES-CCM or AES-CCM* should be performed. */
  142. );
  143. /*! Macro defintion for CRYS_AESCCM_Init (AES CCM non-star implementation). */
  144. #define CRYS_AESCCM_Init(ContextID_ptr, EncrDecrMode, CCM_Key, KeySizeId, AdataSize, TextSizeQ, N_ptr, SizeOfN, SizeOfT) \
  145. CC_AESCCM_Init(ContextID_ptr, EncrDecrMode, CCM_Key, KeySizeId, AdataSize, TextSizeQ, N_ptr, SizeOfN, SizeOfT, CRYS_AESCCM_MODE_CCM)
  146. /*! Macro defintion CRYS_AESCCMStar_Init (AES CCM star implementation). */
  147. #define CRYS_AESCCMStar_Init(ContextID_ptr, EncrDecrMode, CCM_Key, KeySizeId, AdataSize, TextSizeQ, N_ptr, SizeOfN, SizeOfT) \
  148. CC_AESCCM_Init(ContextID_ptr, EncrDecrMode, CCM_Key, KeySizeId, AdataSize, TextSizeQ, N_ptr, SizeOfN, SizeOfT, CRYS_AESCCM_MODE_STAR)
  149. /*!
  150. @brief This function receives a CCM context and a block of additional data, and adds it to the AES MAC
  151. calculation.
  152. This API can be called only once per operation context. It should not be called in case AdataSize was set to
  153. zero in ::CC_AESCCM_Init.
  154. @return CRYS_OK on success.
  155. @return A non-zero value on failure as defined crys_aesccm_error.h.
  156. */
  157. CRYSError_t CRYS_AESCCM_BlockAdata(
  158. CRYS_AESCCM_UserContext_t *ContextID_ptr, /*!< [in] Pointer to the context buffer. */
  159. uint8_t *DataIn_ptr, /*!< [in] Pointer to the additional input data. The buffer must be contiguous. */
  160. uint32_t DataInSize /*!< [in] Byte size of the additional data. Must match AdataSize parameter provided to
  161. ::CRYS_AESCCM_Init. */
  162. );
  163. /*!
  164. @brief This function can be invoked for any block of Text data whose size is a multiple of 16 bytes,
  165. excluding the last block that must be processed by ::CRYS_AESCCM_Finish.
  166. <ul><li> If encrypting:
  167. Continues calculation of the intermediate AES_MAC value of the text data, while simultaneously encrypting the text data using AES_CTR,
  168. starting from CTR value = CTR0+1.</li>
  169. <li>If decrypting:
  170. Continues decryption of the text data, while calculating the intermediate AES_MAC value of decrypted data.</li></ul>
  171. @return CRYS_OK on success.
  172. @return A non-zero value on failure as defined crys_aesccm_error.h.
  173. */
  174. CRYSError_t CRYS_AESCCM_BlockTextData(
  175. CRYS_AESCCM_UserContext_t *ContextID_ptr, /*!< [in] Pointer to the context buffer. */
  176. uint8_t *DataIn_ptr, /*!< [in] Pointer to the additional input data. The buffer must be contiguous. */
  177. uint32_t DataInSize, /*!< [in] Byte size of the text data block. Must be a multiple of 16 bytes. */
  178. uint8_t *DataOut_ptr /*!< [out] Pointer to the output data. The size of the output buffer must be at least DataInSize.
  179. The buffer must be contiguous. */
  180. );
  181. /*!
  182. @brief This function must be the last to be called on the text data.
  183. It can either be called on the entire text data (if transferred as one block), or on the last block of the text data,
  184. even if total size of text data is equal to 0.
  185. It performs the same operations as ::CRYS_AESCCM_BlockTextData, but additionally:
  186. <ul><li> If encrypting: </li>
  187. <ul><li>If the size of text data is not in multiples of 16 bytes, it pads the remaining bytes with zeros to a full 16-bytes block and
  188. processes the data using AES_MAC and AES_CTR algorithms.</li>
  189. <li> Encrypts the AES_MAC result with AES_CTR using the CTR0 value saved in the context and places the SizeOfT bytes of MAC (tag)
  190. at the end.</li></ul></ul>
  191. <ul><li> If decrypting: </li>
  192. <ul><li>Processes the text data, except for the last SizeOfT bytes (tag), using AES_CTR and then AES_MAC algorithms.</li>
  193. <li>Encrypts the calculated MAC using AES_CTR based on the saved CTR0 value, and compares it with SizeOfT last bytes of input data (i.e.
  194. tag value).</li>
  195. <li>The function saves the validation result (Valid/Invalid) in the context.</li>
  196. <li>Returns (as the error code) the final CCM-MAC verification result.</li></ul></ul>
  197. @return CRYS_OK on success.
  198. @return A non-zero value on failure as defined crys_aesccm_error.h.
  199. */
  200. CEXPORT_C CRYSError_t CRYS_AESCCM_Finish(
  201. CRYS_AESCCM_UserContext_t *ContextID_ptr, /*!< [in] Pointer to the context buffer. */
  202. uint8_t *DataIn_ptr, /*!< [in] Pointer to the last input data. The buffer must be contiguous. */
  203. uint32_t DataInSize, /*!< [in] Byte size of the last text data block. Can be zero. */
  204. uint8_t *DataOut_ptr, /*!< [in] Pointer to the output (cipher or plain text data) data. The buffer must
  205. be contiguous. If DataInSize = 0, output buffer is not required. */
  206. CRYS_AESCCM_Mac_Res_t MacRes, /*!< [in] MAC result buffer pointer. */
  207. uint8_t *SizeOfT /*!< [out] AES-CCM MAC byte size as defined in CRYS_AESCCM_Init. */
  208. );
  209. /****************************************************************************************************/
  210. /******** AESCCM FUNCTION ******/
  211. /****************************************************************************************************/
  212. /*!
  213. @brief AES CCM combines Counter mode encryption with CBC-MAC authentication.
  214. Input to CCM includes the following elements:
  215. <ul><li> Payload - text data that is both authenticated and encrypted.</li>
  216. <li> Associated data (Adata) - data that is authenticated but not encrypted, e.g., a header.</li>
  217. <li> Nonce - A unique value that is assigned to the payload and the associated data.</li></ul>
  218. @return CRYS_OK on success.
  219. @return A non-zero value on failure as defined crys_aesccm_error.h.
  220. */
  221. CIMPORT_C CRYSError_t CC_AESCCM(
  222. SaSiAesEncryptMode_t EncrDecrMode, /*!< [in] A flag specifying whether an AES Encrypt (::SASI_AES_ENCRYPT) or Decrypt
  223. (::SASI_AES_DECRYPT) operation should be performed. */
  224. CRYS_AESCCM_Key_t CCM_Key, /*!< [in] Pointer to AES-CCM key. */
  225. CRYS_AESCCM_KeySize_t KeySizeId, /*!< [in] Enumerator defining the key size (only 128 bit is valid). */
  226. uint8_t *N_ptr, /*!< [in] Pointer to the Nonce. */
  227. uint8_t SizeOfN, /*!< [in] Nonce byte size. The valid values depend on the ccm mode:
  228. <ul><li>CCM: valid values = [7 .. 13].</li>
  229. <li>CCM*: valid values = [13].</li></ul> */
  230. uint8_t *ADataIn_ptr, /*!< [in] Pointer to the additional input data. The buffer must be contiguous. */
  231. uint32_t ADataInSize, /*!< [in] Byte size of the additional data. */
  232. uint8_t *TextDataIn_ptr, /*!< [in] Pointer to the plain-text data for encryption or cipher-text data for decryption.
  233. The buffer must be contiguous. */
  234. uint32_t TextDataInSize, /*!< [in] Byte size of the full text data. */
  235. uint8_t *TextDataOut_ptr, /*!< [out] Pointer to the output (cipher or plain text data according to encrypt-decrypt mode)
  236. data. The buffer must be contiguous. */
  237. uint8_t SizeOfT, /*!< [in] AES-CCM MAC (tag) byte size. The valid values depend on the ccm mode:
  238. <ul><li>CCM: valid values = [4, 6, 8, 10, 12, 14, 16].</li>
  239. <li>CCM*: valid values = [0, 4, 8, 16].</li></ul>*/
  240. CRYS_AESCCM_Mac_Res_t Mac_Res, /*!< [in/out] Pointer to the MAC result buffer. */
  241. uint32_t ccmMode /*!< [in] Flag specifying whether AES-CCM or AES-CCM* should be performed. */
  242. );
  243. /*! Macro defintion for CRYS_AESCCM (AES CCM non-star implementation). */
  244. #define CRYS_AESCCM(EncrDecrMode, CCM_Key, KeySizeId, N_ptr, SizeOfN, ADataIn_ptr, ADataInSize, TextDataIn_ptr, TextDataInSize, TextDataOut_ptr, SizeOfT, Mac_Res) \
  245. CC_AESCCM(EncrDecrMode, CCM_Key, KeySizeId, N_ptr, SizeOfN, ADataIn_ptr, ADataInSize, TextDataIn_ptr, TextDataInSize, TextDataOut_ptr, SizeOfT, Mac_Res, CRYS_AESCCM_MODE_CCM)
  246. /*! Macro defintion for CRYS_AESCCMStar (AES CCM star implementation). */
  247. #define CRYS_AESCCMStar(EncrDecrMode, CCM_Key, KeySizeId, N_ptr, SizeOfN, ADataIn_ptr, ADataInSize, TextDataIn_ptr, TextDataInSize, TextDataOut_ptr, SizeOfT, Mac_Res) \
  248. CC_AESCCM(EncrDecrMode, CCM_Key, KeySizeId, N_ptr, SizeOfN, ADataIn_ptr, ADataInSize, TextDataIn_ptr, TextDataInSize, TextDataOut_ptr, SizeOfT, Mac_Res, CRYS_AESCCM_MODE_STAR)
  249. /*!
  250. @brief This function receives the MAC source address, the frame counter and the MAC size
  251. and returns the required nonce for AES-CCM* as defined in ieee-802.15.4.
  252. This API should be called before CRYS_AESCCMStar and CRYS_AESCCMStar_Init,
  253. and the generated nonce should be provided to these functions.
  254. @return CRYS_OK on success.
  255. @return A non-zero value on failure as defined crys_aesccm_error.h.
  256. */
  257. CRYSError_t CRYS_AESCCMStar_NonceGenerate(
  258. CRYS_AESCCMStar_SourceAddress_t srcAddr, /*!< [in] The MAC address in EUI-64 format. */
  259. uint32_t FrameCounter, /*!< [in] The MAC frame counter. */
  260. uint8_t SizeOfT, /*!< [in] AES-CCM* MAC (tag) byte size. Valid values = [0,4,8,16]. */
  261. CRYS_AESCCMStar_Nonce_t nonce /*!< [out] The required nonce for AES-CCM*. */
  262. );
  263. #ifdef __cplusplus
  264. }
  265. #endif
  266. /**
  267. @}
  268. */
  269. #endif /*#ifndef CRYS_AESCCM_H*/