mirror of
https://github.com/taigrr/arduinolibs
synced 2025-01-18 04:33:12 -08:00
Update docs
This commit is contained in:
@@ -147,212 +147,208 @@ var searchBox = new SearchBox("searchBox", "search",false,'Search');
|
||||
<div class="line"><a name="l00077"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a397c5dddde828c59eb63367385aec562"> 77</a></span> <span class="keywordtype">bool</span> <a class="code" href="classGCMCommon.html#a397c5dddde828c59eb63367385aec562">GCMCommon::setKey</a>(<span class="keyword">const</span> uint8_t *key, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00078"></a><span class="lineno"> 78</span> {</div>
|
||||
<div class="line"><a name="l00079"></a><span class="lineno"> 79</span>  <span class="comment">// Set the encryption key for the block cipher.</span></div>
|
||||
<div class="line"><a name="l00080"></a><span class="lineno"> 80</span>  <span class="keywordflow">if</span> (!blockCipher-><a class="code" href="classBlockCipher.html#a9a05307664469777592799c8f77397c4">setKey</a>(key, len))</div>
|
||||
<div class="line"><a name="l00081"></a><span class="lineno"> 81</span>  <span class="keywordflow">return</span> <span class="keyword">false</span>;</div>
|
||||
<div class="line"><a name="l00080"></a><span class="lineno"> 80</span>  <span class="keywordflow">return</span> blockCipher-><a class="code" href="classBlockCipher.html#a9a05307664469777592799c8f77397c4">setKey</a>(key, len);</div>
|
||||
<div class="line"><a name="l00081"></a><span class="lineno"> 81</span> }</div>
|
||||
<div class="line"><a name="l00082"></a><span class="lineno"> 82</span> </div>
|
||||
<div class="line"><a name="l00083"></a><span class="lineno"> 83</span>  <span class="comment">// Construct the hashing key by encrypting a zero block.</span></div>
|
||||
<div class="line"><a name="l00084"></a><span class="lineno"> 84</span>  memset(state.nonce, 0, 16);</div>
|
||||
<div class="line"><a name="l00085"></a><span class="lineno"> 85</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.nonce, state.nonce);</div>
|
||||
<div class="line"><a name="l00086"></a><span class="lineno"> 86</span>  ghash.<a class="code" href="classGHASH.html#a479a3e8c37e320bf99f54b95bf5f4c55">reset</a>(state.nonce);</div>
|
||||
<div class="line"><a name="l00087"></a><span class="lineno"> 87</span>  <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
||||
<div class="line"><a name="l00088"></a><span class="lineno"> 88</span> }</div>
|
||||
<div class="line"><a name="l00089"></a><span class="lineno"> 89</span> </div>
|
||||
<div class="line"><a name="l00090"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a2545135fe42c832e40e057b603824524"> 90</a></span> <span class="keywordtype">bool</span> <a class="code" href="classGCMCommon.html#a2545135fe42c832e40e057b603824524">GCMCommon::setIV</a>(<span class="keyword">const</span> uint8_t *iv, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00091"></a><span class="lineno"> 91</span> {</div>
|
||||
<div class="line"><a name="l00092"></a><span class="lineno"> 92</span>  <span class="comment">// Note: We assume that setKey() has already been called to</span></div>
|
||||
<div class="line"><a name="l00093"></a><span class="lineno"> 93</span>  <span class="comment">// set the hashing key in the "ghash" object and that the</span></div>
|
||||
<div class="line"><a name="l00094"></a><span class="lineno"> 94</span>  <span class="comment">// hashing key itself is still stored in "state.nonce".</span></div>
|
||||
<div class="line"><a name="l00095"></a><span class="lineno"> 95</span> </div>
|
||||
<div class="line"><a name="l00096"></a><span class="lineno"> 96</span>  <span class="comment">// Format the counter block from the IV.</span></div>
|
||||
<div class="line"><a name="l00097"></a><span class="lineno"> 97</span>  <span class="keywordflow">if</span> (len == 12) {</div>
|
||||
<div class="line"><a name="l00098"></a><span class="lineno"> 98</span>  <span class="comment">// IV's of exactly 96 bits are used directly as the counter block.</span></div>
|
||||
<div class="line"><a name="l00099"></a><span class="lineno"> 99</span>  memcpy(state.counter, iv, 12);</div>
|
||||
<div class="line"><a name="l00100"></a><span class="lineno"> 100</span>  state.counter[12] = 0;</div>
|
||||
<div class="line"><a name="l00101"></a><span class="lineno"> 101</span>  state.counter[13] = 0;</div>
|
||||
<div class="line"><a name="l00102"></a><span class="lineno"> 102</span>  state.counter[14] = 0;</div>
|
||||
<div class="line"><a name="l00103"></a><span class="lineno"> 103</span>  state.counter[15] = 1;</div>
|
||||
<div class="line"><a name="l00104"></a><span class="lineno"> 104</span>  } <span class="keywordflow">else</span> {</div>
|
||||
<div class="line"><a name="l00105"></a><span class="lineno"> 105</span>  <span class="comment">// IV's of other sizes are hashed to produce the counter block.</span></div>
|
||||
<div class="line"><a name="l00106"></a><span class="lineno"> 106</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(iv, len);</div>
|
||||
<div class="line"><a name="l00107"></a><span class="lineno"> 107</span>  ghash.<a class="code" href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">pad</a>();</div>
|
||||
<div class="line"><a name="l00108"></a><span class="lineno"> 108</span>  uint64_t sizes[2] = {0, htobe64(((uint64_t)len) * 8)};</div>
|
||||
<div class="line"><a name="l00109"></a><span class="lineno"> 109</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(sizes, <span class="keyword">sizeof</span>(sizes));</div>
|
||||
<div class="line"><a name="l00110"></a><span class="lineno"> 110</span>  clean(sizes);</div>
|
||||
<div class="line"><a name="l00111"></a><span class="lineno"> 111</span>  ghash.<a class="code" href="classGHASH.html#ab221298ca69c9612bfbfd3dedcb28307">finalize</a>(state.counter, 16);</div>
|
||||
<div class="line"><a name="l00112"></a><span class="lineno"> 112</span>  ghash.<a class="code" href="classGHASH.html#a479a3e8c37e320bf99f54b95bf5f4c55">reset</a>(state.nonce);</div>
|
||||
<div class="line"><a name="l00113"></a><span class="lineno"> 113</span>  }</div>
|
||||
<div class="line"><a name="l00114"></a><span class="lineno"> 114</span> </div>
|
||||
<div class="line"><a name="l00115"></a><span class="lineno"> 115</span>  <span class="comment">// Reset the GCM object ready to process auth or payload data.</span></div>
|
||||
<div class="line"><a name="l00116"></a><span class="lineno"> 116</span>  state.authSize = 0;</div>
|
||||
<div class="line"><a name="l00117"></a><span class="lineno"> 117</span>  state.dataSize = 0;</div>
|
||||
<div class="line"><a name="l00118"></a><span class="lineno"> 118</span>  state.dataStarted = <span class="keyword">false</span>;</div>
|
||||
<div class="line"><a name="l00119"></a><span class="lineno"> 119</span>  state.posn = 16;</div>
|
||||
<div class="line"><a name="l00120"></a><span class="lineno"> 120</span> </div>
|
||||
<div class="line"><a name="l00121"></a><span class="lineno"> 121</span>  <span class="comment">// Replace the hash key in "nonce" with the encrypted counter.</span></div>
|
||||
<div class="line"><a name="l00122"></a><span class="lineno"> 122</span>  <span class="comment">// This value will be XOR'ed with the final authentication hash</span></div>
|
||||
<div class="line"><a name="l00123"></a><span class="lineno"> 123</span>  <span class="comment">// value in computeTag().</span></div>
|
||||
<div class="line"><a name="l00124"></a><span class="lineno"> 124</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.nonce, state.counter);</div>
|
||||
<div class="line"><a name="l00125"></a><span class="lineno"> 125</span>  <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
||||
<div class="line"><a name="l00126"></a><span class="lineno"> 126</span> }</div>
|
||||
<div class="line"><a name="l00127"></a><span class="lineno"> 127</span> </div>
|
||||
<div class="line"><a name="l00133"></a><span class="lineno"> 133</span> <span class="keyword">static</span> <span class="keyword">inline</span> <span class="keywordtype">void</span> increment(uint8_t counter[16])</div>
|
||||
<div class="line"><a name="l00134"></a><span class="lineno"> 134</span> {</div>
|
||||
<div class="line"><a name="l00135"></a><span class="lineno"> 135</span>  uint16_t carry = 1;</div>
|
||||
<div class="line"><a name="l00136"></a><span class="lineno"> 136</span>  carry += counter[15];</div>
|
||||
<div class="line"><a name="l00137"></a><span class="lineno"> 137</span>  counter[15] = (uint8_t)carry;</div>
|
||||
<div class="line"><a name="l00138"></a><span class="lineno"> 138</span>  carry = (carry >> 8) + counter[14];</div>
|
||||
<div class="line"><a name="l00139"></a><span class="lineno"> 139</span>  counter[14] = (uint8_t)carry;</div>
|
||||
<div class="line"><a name="l00140"></a><span class="lineno"> 140</span>  carry = (carry >> 8) + counter[13];</div>
|
||||
<div class="line"><a name="l00141"></a><span class="lineno"> 141</span>  counter[13] = (uint8_t)carry;</div>
|
||||
<div class="line"><a name="l00142"></a><span class="lineno"> 142</span>  carry = (carry >> 8) + counter[12];</div>
|
||||
<div class="line"><a name="l00143"></a><span class="lineno"> 143</span>  counter[12] = (uint8_t)carry;</div>
|
||||
<div class="line"><a name="l00144"></a><span class="lineno"> 144</span> }</div>
|
||||
<div class="line"><a name="l00145"></a><span class="lineno"> 145</span> </div>
|
||||
<div class="line"><a name="l00146"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a01ac69afe3d9fc4d72b2ea5dc242e55c"> 146</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#a01ac69afe3d9fc4d72b2ea5dc242e55c">GCMCommon::encrypt</a>(uint8_t *output, <span class="keyword">const</span> uint8_t *input, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00147"></a><span class="lineno"> 147</span> {</div>
|
||||
<div class="line"><a name="l00148"></a><span class="lineno"> 148</span>  <span class="comment">// Finalize the authenticated data if necessary.</span></div>
|
||||
<div class="line"><a name="l00149"></a><span class="lineno"> 149</span>  <span class="keywordflow">if</span> (!state.dataStarted) {</div>
|
||||
<div class="line"><a name="l00150"></a><span class="lineno"> 150</span>  ghash.<a class="code" href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">pad</a>();</div>
|
||||
<div class="line"><a name="l00151"></a><span class="lineno"> 151</span>  state.dataStarted = <span class="keyword">true</span>;</div>
|
||||
<div class="line"><a name="l00152"></a><span class="lineno"> 152</span>  }</div>
|
||||
<div class="line"><a name="l00153"></a><span class="lineno"> 153</span> </div>
|
||||
<div class="line"><a name="l00154"></a><span class="lineno"> 154</span>  <span class="comment">// Encrypt the plaintext using the block cipher in counter mode.</span></div>
|
||||
<div class="line"><a name="l00155"></a><span class="lineno"> 155</span>  uint8_t *out = output;</div>
|
||||
<div class="line"><a name="l00156"></a><span class="lineno"> 156</span>  <span class="keywordtype">size_t</span> size = len;</div>
|
||||
<div class="line"><a name="l00157"></a><span class="lineno"> 157</span>  <span class="keywordflow">while</span> (size > 0) {</div>
|
||||
<div class="line"><a name="l00158"></a><span class="lineno"> 158</span>  <span class="comment">// Create a new keystream block if necessary.</span></div>
|
||||
<div class="line"><a name="l00159"></a><span class="lineno"> 159</span>  <span class="keywordflow">if</span> (state.posn >= 16) {</div>
|
||||
<div class="line"><a name="l00160"></a><span class="lineno"> 160</span>  increment(state.counter);</div>
|
||||
<div class="line"><a name="l00161"></a><span class="lineno"> 161</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.stream, state.counter);</div>
|
||||
<div class="line"><a name="l00162"></a><span class="lineno"> 162</span>  state.posn = 0;</div>
|
||||
<div class="line"><a name="l00163"></a><span class="lineno"> 163</span>  }</div>
|
||||
<div class="line"><a name="l00164"></a><span class="lineno"> 164</span> </div>
|
||||
<div class="line"><a name="l00165"></a><span class="lineno"> 165</span>  <span class="comment">// Encrypt as many bytes as we can using the keystream block.</span></div>
|
||||
<div class="line"><a name="l00166"></a><span class="lineno"> 166</span>  uint8_t temp = 16 - state.posn;</div>
|
||||
<div class="line"><a name="l00167"></a><span class="lineno"> 167</span>  <span class="keywordflow">if</span> (temp > size)</div>
|
||||
<div class="line"><a name="l00168"></a><span class="lineno"> 168</span>  temp = size;</div>
|
||||
<div class="line"><a name="l00169"></a><span class="lineno"> 169</span>  uint8_t *stream = state.stream + state.posn;</div>
|
||||
<div class="line"><a name="l00170"></a><span class="lineno"> 170</span>  state.posn += temp;</div>
|
||||
<div class="line"><a name="l00171"></a><span class="lineno"> 171</span>  size -= temp;</div>
|
||||
<div class="line"><a name="l00172"></a><span class="lineno"> 172</span>  <span class="keywordflow">while</span> (temp > 0) {</div>
|
||||
<div class="line"><a name="l00173"></a><span class="lineno"> 173</span>  *out++ = *input++ ^ *stream++;</div>
|
||||
<div class="line"><a name="l00174"></a><span class="lineno"> 174</span>  --temp;</div>
|
||||
<div class="line"><a name="l00175"></a><span class="lineno"> 175</span>  }</div>
|
||||
<div class="line"><a name="l00176"></a><span class="lineno"> 176</span>  }</div>
|
||||
<div class="line"><a name="l00177"></a><span class="lineno"> 177</span> </div>
|
||||
<div class="line"><a name="l00178"></a><span class="lineno"> 178</span>  <span class="comment">// Feed the ciphertext into the hash.</span></div>
|
||||
<div class="line"><a name="l00179"></a><span class="lineno"> 179</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(output, len);</div>
|
||||
<div class="line"><a name="l00180"></a><span class="lineno"> 180</span>  state.dataSize += len;</div>
|
||||
<div class="line"><a name="l00181"></a><span class="lineno"> 181</span> }</div>
|
||||
<div class="line"><a name="l00182"></a><span class="lineno"> 182</span> </div>
|
||||
<div class="line"><a name="l00183"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a60912d3ab5766aa68dc9b3111ac2c0d7"> 183</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#a60912d3ab5766aa68dc9b3111ac2c0d7">GCMCommon::decrypt</a>(uint8_t *output, <span class="keyword">const</span> uint8_t *input, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00184"></a><span class="lineno"> 184</span> {</div>
|
||||
<div class="line"><a name="l00185"></a><span class="lineno"> 185</span>  <span class="comment">// Finalize the authenticated data if necessary.</span></div>
|
||||
<div class="line"><a name="l00186"></a><span class="lineno"> 186</span>  <span class="keywordflow">if</span> (!state.dataStarted) {</div>
|
||||
<div class="line"><a name="l00187"></a><span class="lineno"> 187</span>  ghash.<a class="code" href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">pad</a>();</div>
|
||||
<div class="line"><a name="l00188"></a><span class="lineno"> 188</span>  state.dataStarted = <span class="keyword">true</span>;</div>
|
||||
<div class="line"><a name="l00189"></a><span class="lineno"> 189</span>  }</div>
|
||||
<div class="line"><a name="l00083"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a2545135fe42c832e40e057b603824524"> 83</a></span> <span class="keywordtype">bool</span> <a class="code" href="classGCMCommon.html#a2545135fe42c832e40e057b603824524">GCMCommon::setIV</a>(<span class="keyword">const</span> uint8_t *iv, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00084"></a><span class="lineno"> 84</span> {</div>
|
||||
<div class="line"><a name="l00085"></a><span class="lineno"> 85</span>  <span class="comment">// Format the counter block from the IV.</span></div>
|
||||
<div class="line"><a name="l00086"></a><span class="lineno"> 86</span>  <span class="keywordflow">if</span> (len == 12) {</div>
|
||||
<div class="line"><a name="l00087"></a><span class="lineno"> 87</span>  <span class="comment">// IV's of exactly 96 bits are used directly as the counter block.</span></div>
|
||||
<div class="line"><a name="l00088"></a><span class="lineno"> 88</span>  memcpy(state.counter, iv, 12);</div>
|
||||
<div class="line"><a name="l00089"></a><span class="lineno"> 89</span>  state.counter[12] = 0;</div>
|
||||
<div class="line"><a name="l00090"></a><span class="lineno"> 90</span>  state.counter[13] = 0;</div>
|
||||
<div class="line"><a name="l00091"></a><span class="lineno"> 91</span>  state.counter[14] = 0;</div>
|
||||
<div class="line"><a name="l00092"></a><span class="lineno"> 92</span>  state.counter[15] = 1;</div>
|
||||
<div class="line"><a name="l00093"></a><span class="lineno"> 93</span>  } <span class="keywordflow">else</span> {</div>
|
||||
<div class="line"><a name="l00094"></a><span class="lineno"> 94</span>  <span class="comment">// IV's of other sizes are hashed to produce the counter block.</span></div>
|
||||
<div class="line"><a name="l00095"></a><span class="lineno"> 95</span>  memset(state.nonce, 0, 16);</div>
|
||||
<div class="line"><a name="l00096"></a><span class="lineno"> 96</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.nonce, state.nonce);</div>
|
||||
<div class="line"><a name="l00097"></a><span class="lineno"> 97</span>  ghash.<a class="code" href="classGHASH.html#a479a3e8c37e320bf99f54b95bf5f4c55">reset</a>(state.nonce);</div>
|
||||
<div class="line"><a name="l00098"></a><span class="lineno"> 98</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(iv, len);</div>
|
||||
<div class="line"><a name="l00099"></a><span class="lineno"> 99</span>  ghash.<a class="code" href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">pad</a>();</div>
|
||||
<div class="line"><a name="l00100"></a><span class="lineno"> 100</span>  uint64_t sizes[2] = {0, htobe64(((uint64_t)len) * 8)};</div>
|
||||
<div class="line"><a name="l00101"></a><span class="lineno"> 101</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(sizes, <span class="keyword">sizeof</span>(sizes));</div>
|
||||
<div class="line"><a name="l00102"></a><span class="lineno"> 102</span>  clean(sizes);</div>
|
||||
<div class="line"><a name="l00103"></a><span class="lineno"> 103</span>  ghash.<a class="code" href="classGHASH.html#ab221298ca69c9612bfbfd3dedcb28307">finalize</a>(state.counter, 16);</div>
|
||||
<div class="line"><a name="l00104"></a><span class="lineno"> 104</span>  }</div>
|
||||
<div class="line"><a name="l00105"></a><span class="lineno"> 105</span> </div>
|
||||
<div class="line"><a name="l00106"></a><span class="lineno"> 106</span>  <span class="comment">// Reset the GCM object ready to process auth or payload data.</span></div>
|
||||
<div class="line"><a name="l00107"></a><span class="lineno"> 107</span>  state.authSize = 0;</div>
|
||||
<div class="line"><a name="l00108"></a><span class="lineno"> 108</span>  state.dataSize = 0;</div>
|
||||
<div class="line"><a name="l00109"></a><span class="lineno"> 109</span>  state.dataStarted = <span class="keyword">false</span>;</div>
|
||||
<div class="line"><a name="l00110"></a><span class="lineno"> 110</span>  state.posn = 16;</div>
|
||||
<div class="line"><a name="l00111"></a><span class="lineno"> 111</span> </div>
|
||||
<div class="line"><a name="l00112"></a><span class="lineno"> 112</span>  <span class="comment">// Construct the hashing key by encrypting a zero block.</span></div>
|
||||
<div class="line"><a name="l00113"></a><span class="lineno"> 113</span>  memset(state.nonce, 0, 16);</div>
|
||||
<div class="line"><a name="l00114"></a><span class="lineno"> 114</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.nonce, state.nonce);</div>
|
||||
<div class="line"><a name="l00115"></a><span class="lineno"> 115</span>  ghash.<a class="code" href="classGHASH.html#a479a3e8c37e320bf99f54b95bf5f4c55">reset</a>(state.nonce);</div>
|
||||
<div class="line"><a name="l00116"></a><span class="lineno"> 116</span> </div>
|
||||
<div class="line"><a name="l00117"></a><span class="lineno"> 117</span>  <span class="comment">// Replace the hash key in "nonce" with the encrypted counter.</span></div>
|
||||
<div class="line"><a name="l00118"></a><span class="lineno"> 118</span>  <span class="comment">// This value will be XOR'ed with the final authentication hash</span></div>
|
||||
<div class="line"><a name="l00119"></a><span class="lineno"> 119</span>  <span class="comment">// value in computeTag().</span></div>
|
||||
<div class="line"><a name="l00120"></a><span class="lineno"> 120</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.nonce, state.counter);</div>
|
||||
<div class="line"><a name="l00121"></a><span class="lineno"> 121</span>  <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
||||
<div class="line"><a name="l00122"></a><span class="lineno"> 122</span> }</div>
|
||||
<div class="line"><a name="l00123"></a><span class="lineno"> 123</span> </div>
|
||||
<div class="line"><a name="l00129"></a><span class="lineno"> 129</span> <span class="keyword">static</span> <span class="keyword">inline</span> <span class="keywordtype">void</span> increment(uint8_t counter[16])</div>
|
||||
<div class="line"><a name="l00130"></a><span class="lineno"> 130</span> {</div>
|
||||
<div class="line"><a name="l00131"></a><span class="lineno"> 131</span>  uint16_t carry = 1;</div>
|
||||
<div class="line"><a name="l00132"></a><span class="lineno"> 132</span>  carry += counter[15];</div>
|
||||
<div class="line"><a name="l00133"></a><span class="lineno"> 133</span>  counter[15] = (uint8_t)carry;</div>
|
||||
<div class="line"><a name="l00134"></a><span class="lineno"> 134</span>  carry = (carry >> 8) + counter[14];</div>
|
||||
<div class="line"><a name="l00135"></a><span class="lineno"> 135</span>  counter[14] = (uint8_t)carry;</div>
|
||||
<div class="line"><a name="l00136"></a><span class="lineno"> 136</span>  carry = (carry >> 8) + counter[13];</div>
|
||||
<div class="line"><a name="l00137"></a><span class="lineno"> 137</span>  counter[13] = (uint8_t)carry;</div>
|
||||
<div class="line"><a name="l00138"></a><span class="lineno"> 138</span>  carry = (carry >> 8) + counter[12];</div>
|
||||
<div class="line"><a name="l00139"></a><span class="lineno"> 139</span>  counter[12] = (uint8_t)carry;</div>
|
||||
<div class="line"><a name="l00140"></a><span class="lineno"> 140</span> }</div>
|
||||
<div class="line"><a name="l00141"></a><span class="lineno"> 141</span> </div>
|
||||
<div class="line"><a name="l00142"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a01ac69afe3d9fc4d72b2ea5dc242e55c"> 142</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#a01ac69afe3d9fc4d72b2ea5dc242e55c">GCMCommon::encrypt</a>(uint8_t *output, <span class="keyword">const</span> uint8_t *input, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00143"></a><span class="lineno"> 143</span> {</div>
|
||||
<div class="line"><a name="l00144"></a><span class="lineno"> 144</span>  <span class="comment">// Finalize the authenticated data if necessary.</span></div>
|
||||
<div class="line"><a name="l00145"></a><span class="lineno"> 145</span>  <span class="keywordflow">if</span> (!state.dataStarted) {</div>
|
||||
<div class="line"><a name="l00146"></a><span class="lineno"> 146</span>  ghash.<a class="code" href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">pad</a>();</div>
|
||||
<div class="line"><a name="l00147"></a><span class="lineno"> 147</span>  state.dataStarted = <span class="keyword">true</span>;</div>
|
||||
<div class="line"><a name="l00148"></a><span class="lineno"> 148</span>  }</div>
|
||||
<div class="line"><a name="l00149"></a><span class="lineno"> 149</span> </div>
|
||||
<div class="line"><a name="l00150"></a><span class="lineno"> 150</span>  <span class="comment">// Encrypt the plaintext using the block cipher in counter mode.</span></div>
|
||||
<div class="line"><a name="l00151"></a><span class="lineno"> 151</span>  uint8_t *out = output;</div>
|
||||
<div class="line"><a name="l00152"></a><span class="lineno"> 152</span>  <span class="keywordtype">size_t</span> size = len;</div>
|
||||
<div class="line"><a name="l00153"></a><span class="lineno"> 153</span>  <span class="keywordflow">while</span> (size > 0) {</div>
|
||||
<div class="line"><a name="l00154"></a><span class="lineno"> 154</span>  <span class="comment">// Create a new keystream block if necessary.</span></div>
|
||||
<div class="line"><a name="l00155"></a><span class="lineno"> 155</span>  <span class="keywordflow">if</span> (state.posn >= 16) {</div>
|
||||
<div class="line"><a name="l00156"></a><span class="lineno"> 156</span>  increment(state.counter);</div>
|
||||
<div class="line"><a name="l00157"></a><span class="lineno"> 157</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.stream, state.counter);</div>
|
||||
<div class="line"><a name="l00158"></a><span class="lineno"> 158</span>  state.posn = 0;</div>
|
||||
<div class="line"><a name="l00159"></a><span class="lineno"> 159</span>  }</div>
|
||||
<div class="line"><a name="l00160"></a><span class="lineno"> 160</span> </div>
|
||||
<div class="line"><a name="l00161"></a><span class="lineno"> 161</span>  <span class="comment">// Encrypt as many bytes as we can using the keystream block.</span></div>
|
||||
<div class="line"><a name="l00162"></a><span class="lineno"> 162</span>  uint8_t temp = 16 - state.posn;</div>
|
||||
<div class="line"><a name="l00163"></a><span class="lineno"> 163</span>  <span class="keywordflow">if</span> (temp > size)</div>
|
||||
<div class="line"><a name="l00164"></a><span class="lineno"> 164</span>  temp = size;</div>
|
||||
<div class="line"><a name="l00165"></a><span class="lineno"> 165</span>  uint8_t *stream = state.stream + state.posn;</div>
|
||||
<div class="line"><a name="l00166"></a><span class="lineno"> 166</span>  state.posn += temp;</div>
|
||||
<div class="line"><a name="l00167"></a><span class="lineno"> 167</span>  size -= temp;</div>
|
||||
<div class="line"><a name="l00168"></a><span class="lineno"> 168</span>  <span class="keywordflow">while</span> (temp > 0) {</div>
|
||||
<div class="line"><a name="l00169"></a><span class="lineno"> 169</span>  *out++ = *input++ ^ *stream++;</div>
|
||||
<div class="line"><a name="l00170"></a><span class="lineno"> 170</span>  --temp;</div>
|
||||
<div class="line"><a name="l00171"></a><span class="lineno"> 171</span>  }</div>
|
||||
<div class="line"><a name="l00172"></a><span class="lineno"> 172</span>  }</div>
|
||||
<div class="line"><a name="l00173"></a><span class="lineno"> 173</span> </div>
|
||||
<div class="line"><a name="l00174"></a><span class="lineno"> 174</span>  <span class="comment">// Feed the ciphertext into the hash.</span></div>
|
||||
<div class="line"><a name="l00175"></a><span class="lineno"> 175</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(output, len);</div>
|
||||
<div class="line"><a name="l00176"></a><span class="lineno"> 176</span>  state.dataSize += len;</div>
|
||||
<div class="line"><a name="l00177"></a><span class="lineno"> 177</span> }</div>
|
||||
<div class="line"><a name="l00178"></a><span class="lineno"> 178</span> </div>
|
||||
<div class="line"><a name="l00179"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a60912d3ab5766aa68dc9b3111ac2c0d7"> 179</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#a60912d3ab5766aa68dc9b3111ac2c0d7">GCMCommon::decrypt</a>(uint8_t *output, <span class="keyword">const</span> uint8_t *input, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00180"></a><span class="lineno"> 180</span> {</div>
|
||||
<div class="line"><a name="l00181"></a><span class="lineno"> 181</span>  <span class="comment">// Finalize the authenticated data if necessary.</span></div>
|
||||
<div class="line"><a name="l00182"></a><span class="lineno"> 182</span>  <span class="keywordflow">if</span> (!state.dataStarted) {</div>
|
||||
<div class="line"><a name="l00183"></a><span class="lineno"> 183</span>  ghash.<a class="code" href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">pad</a>();</div>
|
||||
<div class="line"><a name="l00184"></a><span class="lineno"> 184</span>  state.dataStarted = <span class="keyword">true</span>;</div>
|
||||
<div class="line"><a name="l00185"></a><span class="lineno"> 185</span>  }</div>
|
||||
<div class="line"><a name="l00186"></a><span class="lineno"> 186</span> </div>
|
||||
<div class="line"><a name="l00187"></a><span class="lineno"> 187</span>  <span class="comment">// Feed the ciphertext into the hash before we decrypt it.</span></div>
|
||||
<div class="line"><a name="l00188"></a><span class="lineno"> 188</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(input, len);</div>
|
||||
<div class="line"><a name="l00189"></a><span class="lineno"> 189</span>  state.dataSize += len;</div>
|
||||
<div class="line"><a name="l00190"></a><span class="lineno"> 190</span> </div>
|
||||
<div class="line"><a name="l00191"></a><span class="lineno"> 191</span>  <span class="comment">// Feed the ciphertext into the hash before we decrypt it.</span></div>
|
||||
<div class="line"><a name="l00192"></a><span class="lineno"> 192</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(input, len);</div>
|
||||
<div class="line"><a name="l00193"></a><span class="lineno"> 193</span>  state.dataSize += len;</div>
|
||||
<div class="line"><a name="l00194"></a><span class="lineno"> 194</span> </div>
|
||||
<div class="line"><a name="l00195"></a><span class="lineno"> 195</span>  <span class="comment">// Decrypt the plaintext using the block cipher in counter mode.</span></div>
|
||||
<div class="line"><a name="l00196"></a><span class="lineno"> 196</span>  <span class="keywordflow">while</span> (len > 0) {</div>
|
||||
<div class="line"><a name="l00197"></a><span class="lineno"> 197</span>  <span class="comment">// Create a new keystream block if necessary.</span></div>
|
||||
<div class="line"><a name="l00198"></a><span class="lineno"> 198</span>  <span class="keywordflow">if</span> (state.posn >= 16) {</div>
|
||||
<div class="line"><a name="l00199"></a><span class="lineno"> 199</span>  increment(state.counter);</div>
|
||||
<div class="line"><a name="l00200"></a><span class="lineno"> 200</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.stream, state.counter);</div>
|
||||
<div class="line"><a name="l00201"></a><span class="lineno"> 201</span>  state.posn = 0;</div>
|
||||
<div class="line"><a name="l00202"></a><span class="lineno"> 202</span>  }</div>
|
||||
<div class="line"><a name="l00203"></a><span class="lineno"> 203</span> </div>
|
||||
<div class="line"><a name="l00204"></a><span class="lineno"> 204</span>  <span class="comment">// Decrypt as many bytes as we can using the keystream block.</span></div>
|
||||
<div class="line"><a name="l00205"></a><span class="lineno"> 205</span>  uint8_t temp = 16 - state.posn;</div>
|
||||
<div class="line"><a name="l00206"></a><span class="lineno"> 206</span>  <span class="keywordflow">if</span> (temp > len)</div>
|
||||
<div class="line"><a name="l00207"></a><span class="lineno"> 207</span>  temp = len;</div>
|
||||
<div class="line"><a name="l00208"></a><span class="lineno"> 208</span>  uint8_t *stream = state.stream + state.posn;</div>
|
||||
<div class="line"><a name="l00209"></a><span class="lineno"> 209</span>  state.posn += temp;</div>
|
||||
<div class="line"><a name="l00210"></a><span class="lineno"> 210</span>  len -= temp;</div>
|
||||
<div class="line"><a name="l00211"></a><span class="lineno"> 211</span>  <span class="keywordflow">while</span> (temp > 0) {</div>
|
||||
<div class="line"><a name="l00212"></a><span class="lineno"> 212</span>  *output++ = *input++ ^ *stream++;</div>
|
||||
<div class="line"><a name="l00213"></a><span class="lineno"> 213</span>  --temp;</div>
|
||||
<div class="line"><a name="l00214"></a><span class="lineno"> 214</span>  }</div>
|
||||
<div class="line"><a name="l00215"></a><span class="lineno"> 215</span>  }</div>
|
||||
<div class="line"><a name="l00216"></a><span class="lineno"> 216</span> }</div>
|
||||
<div class="line"><a name="l00217"></a><span class="lineno"> 217</span> </div>
|
||||
<div class="line"><a name="l00218"></a><span class="lineno"><a class="line" href="classGCMCommon.html#ad926e980ae2d61c10c9bf82813154a25"> 218</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#ad926e980ae2d61c10c9bf82813154a25">GCMCommon::addAuthData</a>(<span class="keyword">const</span> <span class="keywordtype">void</span> *data, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00219"></a><span class="lineno"> 219</span> {</div>
|
||||
<div class="line"><a name="l00220"></a><span class="lineno"> 220</span>  <span class="keywordflow">if</span> (!state.dataStarted) {</div>
|
||||
<div class="line"><a name="l00221"></a><span class="lineno"> 221</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(data, len);</div>
|
||||
<div class="line"><a name="l00222"></a><span class="lineno"> 222</span>  state.authSize += len;</div>
|
||||
<div class="line"><a name="l00223"></a><span class="lineno"> 223</span>  }</div>
|
||||
<div class="line"><a name="l00224"></a><span class="lineno"> 224</span> }</div>
|
||||
<div class="line"><a name="l00225"></a><span class="lineno"> 225</span> </div>
|
||||
<div class="line"><a name="l00226"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a444634bd4469bb5d404ac882d1d8fdf4"> 226</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#a444634bd4469bb5d404ac882d1d8fdf4">GCMCommon::computeTag</a>(<span class="keywordtype">void</span> *tag, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00227"></a><span class="lineno"> 227</span> {</div>
|
||||
<div class="line"><a name="l00228"></a><span class="lineno"> 228</span>  <span class="comment">// Pad the hashed data and add the sizes.</span></div>
|
||||
<div class="line"><a name="l00229"></a><span class="lineno"> 229</span>  ghash.<a class="code" href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">pad</a>();</div>
|
||||
<div class="line"><a name="l00230"></a><span class="lineno"> 230</span>  uint64_t sizes[2] = {</div>
|
||||
<div class="line"><a name="l00231"></a><span class="lineno"> 231</span>  htobe64(state.authSize * 8),</div>
|
||||
<div class="line"><a name="l00232"></a><span class="lineno"> 232</span>  htobe64(state.dataSize * 8)</div>
|
||||
<div class="line"><a name="l00233"></a><span class="lineno"> 233</span>  };</div>
|
||||
<div class="line"><a name="l00234"></a><span class="lineno"> 234</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(sizes, <span class="keyword">sizeof</span>(sizes));</div>
|
||||
<div class="line"><a name="l00235"></a><span class="lineno"> 235</span>  clean(sizes);</div>
|
||||
<div class="line"><a name="l00236"></a><span class="lineno"> 236</span> </div>
|
||||
<div class="line"><a name="l00237"></a><span class="lineno"> 237</span>  <span class="comment">// Get the finalized hash, encrypt it with the nonce, and return the tag.</span></div>
|
||||
<div class="line"><a name="l00238"></a><span class="lineno"> 238</span>  ghash.<a class="code" href="classGHASH.html#ab221298ca69c9612bfbfd3dedcb28307">finalize</a>(state.stream, 16);</div>
|
||||
<div class="line"><a name="l00239"></a><span class="lineno"> 239</span>  <span class="keywordflow">for</span> (uint8_t posn = 0; posn < 16; ++posn)</div>
|
||||
<div class="line"><a name="l00240"></a><span class="lineno"> 240</span>  state.stream[posn] ^= state.nonce[posn];</div>
|
||||
<div class="line"><a name="l00241"></a><span class="lineno"> 241</span>  if (len > 16)</div>
|
||||
<div class="line"><a name="l00242"></a><span class="lineno"> 242</span>  len = 16;</div>
|
||||
<div class="line"><a name="l00243"></a><span class="lineno"> 243</span>  memcpy(tag, state.stream, len);</div>
|
||||
<div class="line"><a name="l00244"></a><span class="lineno"> 244</span> }</div>
|
||||
<div class="line"><a name="l00245"></a><span class="lineno"> 245</span> </div>
|
||||
<div class="line"><a name="l00246"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a70229be2fe2274c4109fe7511481075a"> 246</a></span> <span class="keywordtype">bool</span> <a class="code" href="classGCMCommon.html#a70229be2fe2274c4109fe7511481075a">GCMCommon::checkTag</a>(<span class="keyword">const</span> <span class="keywordtype">void</span> *tag, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00247"></a><span class="lineno"> 247</span> {</div>
|
||||
<div class="line"><a name="l00248"></a><span class="lineno"> 248</span>  <span class="comment">// Can never match if the expected tag length is too long.</span></div>
|
||||
<div class="line"><a name="l00249"></a><span class="lineno"> 249</span>  <span class="keywordflow">if</span> (len > 16)</div>
|
||||
<div class="line"><a name="l00250"></a><span class="lineno"> 250</span>  <span class="keywordflow">return</span> <span class="keyword">false</span>;</div>
|
||||
<div class="line"><a name="l00251"></a><span class="lineno"> 251</span> </div>
|
||||
<div class="line"><a name="l00252"></a><span class="lineno"> 252</span>  <span class="comment">// Compute the tag and check it.</span></div>
|
||||
<div class="line"><a name="l00253"></a><span class="lineno"> 253</span>  <a class="code" href="classGCMCommon.html#a444634bd4469bb5d404ac882d1d8fdf4">computeTag</a>(state.counter, 16);</div>
|
||||
<div class="line"><a name="l00254"></a><span class="lineno"> 254</span>  <span class="keywordflow">return</span> secure_compare(state.counter, tag, len);</div>
|
||||
<div class="line"><a name="l00255"></a><span class="lineno"> 255</span> }</div>
|
||||
<div class="line"><a name="l00256"></a><span class="lineno"> 256</span> </div>
|
||||
<div class="line"><a name="l00257"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a06868ebd67a571aa68d88d5d072cece9"> 257</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#a06868ebd67a571aa68d88d5d072cece9">GCMCommon::clear</a>()</div>
|
||||
<div class="line"><a name="l00258"></a><span class="lineno"> 258</span> {</div>
|
||||
<div class="line"><a name="l00259"></a><span class="lineno"> 259</span>  blockCipher-><a class="code" href="classBlockCipher.html#a6f27d46e9dfa7761d014d828ad5f955b">clear</a>();</div>
|
||||
<div class="line"><a name="l00260"></a><span class="lineno"> 260</span>  ghash.<a class="code" href="classGHASH.html#a4b1ee789debf56f7f24807960ef0556e">clear</a>();</div>
|
||||
<div class="line"><a name="l00261"></a><span class="lineno"> 261</span>  clean(state);</div>
|
||||
<div class="line"><a name="l00262"></a><span class="lineno"> 262</span>  state.posn = 16;</div>
|
||||
<div class="line"><a name="l00263"></a><span class="lineno"> 263</span> }</div>
|
||||
<div class="line"><a name="l00264"></a><span class="lineno"> 264</span> </div>
|
||||
<div class="ttc" id="classGCMCommon_html_a444634bd4469bb5d404ac882d1d8fdf4"><div class="ttname"><a href="classGCMCommon.html#a444634bd4469bb5d404ac882d1d8fdf4">GCMCommon::computeTag</a></div><div class="ttdeci">void computeTag(void *tag, size_t len)</div><div class="ttdoc">Finalizes the encryption process and computes the authentication tag. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00226">GCM.cpp:226</a></div></div>
|
||||
<div class="line"><a name="l00191"></a><span class="lineno"> 191</span>  <span class="comment">// Decrypt the plaintext using the block cipher in counter mode.</span></div>
|
||||
<div class="line"><a name="l00192"></a><span class="lineno"> 192</span>  <span class="keywordflow">while</span> (len > 0) {</div>
|
||||
<div class="line"><a name="l00193"></a><span class="lineno"> 193</span>  <span class="comment">// Create a new keystream block if necessary.</span></div>
|
||||
<div class="line"><a name="l00194"></a><span class="lineno"> 194</span>  <span class="keywordflow">if</span> (state.posn >= 16) {</div>
|
||||
<div class="line"><a name="l00195"></a><span class="lineno"> 195</span>  increment(state.counter);</div>
|
||||
<div class="line"><a name="l00196"></a><span class="lineno"> 196</span>  blockCipher-><a class="code" href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">encryptBlock</a>(state.stream, state.counter);</div>
|
||||
<div class="line"><a name="l00197"></a><span class="lineno"> 197</span>  state.posn = 0;</div>
|
||||
<div class="line"><a name="l00198"></a><span class="lineno"> 198</span>  }</div>
|
||||
<div class="line"><a name="l00199"></a><span class="lineno"> 199</span> </div>
|
||||
<div class="line"><a name="l00200"></a><span class="lineno"> 200</span>  <span class="comment">// Decrypt as many bytes as we can using the keystream block.</span></div>
|
||||
<div class="line"><a name="l00201"></a><span class="lineno"> 201</span>  uint8_t temp = 16 - state.posn;</div>
|
||||
<div class="line"><a name="l00202"></a><span class="lineno"> 202</span>  <span class="keywordflow">if</span> (temp > len)</div>
|
||||
<div class="line"><a name="l00203"></a><span class="lineno"> 203</span>  temp = len;</div>
|
||||
<div class="line"><a name="l00204"></a><span class="lineno"> 204</span>  uint8_t *stream = state.stream + state.posn;</div>
|
||||
<div class="line"><a name="l00205"></a><span class="lineno"> 205</span>  state.posn += temp;</div>
|
||||
<div class="line"><a name="l00206"></a><span class="lineno"> 206</span>  len -= temp;</div>
|
||||
<div class="line"><a name="l00207"></a><span class="lineno"> 207</span>  <span class="keywordflow">while</span> (temp > 0) {</div>
|
||||
<div class="line"><a name="l00208"></a><span class="lineno"> 208</span>  *output++ = *input++ ^ *stream++;</div>
|
||||
<div class="line"><a name="l00209"></a><span class="lineno"> 209</span>  --temp;</div>
|
||||
<div class="line"><a name="l00210"></a><span class="lineno"> 210</span>  }</div>
|
||||
<div class="line"><a name="l00211"></a><span class="lineno"> 211</span>  }</div>
|
||||
<div class="line"><a name="l00212"></a><span class="lineno"> 212</span> }</div>
|
||||
<div class="line"><a name="l00213"></a><span class="lineno"> 213</span> </div>
|
||||
<div class="line"><a name="l00214"></a><span class="lineno"><a class="line" href="classGCMCommon.html#ad926e980ae2d61c10c9bf82813154a25"> 214</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#ad926e980ae2d61c10c9bf82813154a25">GCMCommon::addAuthData</a>(<span class="keyword">const</span> <span class="keywordtype">void</span> *data, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00215"></a><span class="lineno"> 215</span> {</div>
|
||||
<div class="line"><a name="l00216"></a><span class="lineno"> 216</span>  <span class="keywordflow">if</span> (!state.dataStarted) {</div>
|
||||
<div class="line"><a name="l00217"></a><span class="lineno"> 217</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(data, len);</div>
|
||||
<div class="line"><a name="l00218"></a><span class="lineno"> 218</span>  state.authSize += len;</div>
|
||||
<div class="line"><a name="l00219"></a><span class="lineno"> 219</span>  }</div>
|
||||
<div class="line"><a name="l00220"></a><span class="lineno"> 220</span> }</div>
|
||||
<div class="line"><a name="l00221"></a><span class="lineno"> 221</span> </div>
|
||||
<div class="line"><a name="l00222"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a444634bd4469bb5d404ac882d1d8fdf4"> 222</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#a444634bd4469bb5d404ac882d1d8fdf4">GCMCommon::computeTag</a>(<span class="keywordtype">void</span> *tag, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00223"></a><span class="lineno"> 223</span> {</div>
|
||||
<div class="line"><a name="l00224"></a><span class="lineno"> 224</span>  <span class="comment">// Pad the hashed data and add the sizes.</span></div>
|
||||
<div class="line"><a name="l00225"></a><span class="lineno"> 225</span>  ghash.<a class="code" href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">pad</a>();</div>
|
||||
<div class="line"><a name="l00226"></a><span class="lineno"> 226</span>  uint64_t sizes[2] = {</div>
|
||||
<div class="line"><a name="l00227"></a><span class="lineno"> 227</span>  htobe64(state.authSize * 8),</div>
|
||||
<div class="line"><a name="l00228"></a><span class="lineno"> 228</span>  htobe64(state.dataSize * 8)</div>
|
||||
<div class="line"><a name="l00229"></a><span class="lineno"> 229</span>  };</div>
|
||||
<div class="line"><a name="l00230"></a><span class="lineno"> 230</span>  ghash.<a class="code" href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">update</a>(sizes, <span class="keyword">sizeof</span>(sizes));</div>
|
||||
<div class="line"><a name="l00231"></a><span class="lineno"> 231</span>  clean(sizes);</div>
|
||||
<div class="line"><a name="l00232"></a><span class="lineno"> 232</span> </div>
|
||||
<div class="line"><a name="l00233"></a><span class="lineno"> 233</span>  <span class="comment">// Get the finalized hash, encrypt it with the nonce, and return the tag.</span></div>
|
||||
<div class="line"><a name="l00234"></a><span class="lineno"> 234</span>  ghash.<a class="code" href="classGHASH.html#ab221298ca69c9612bfbfd3dedcb28307">finalize</a>(state.stream, 16);</div>
|
||||
<div class="line"><a name="l00235"></a><span class="lineno"> 235</span>  <span class="keywordflow">for</span> (uint8_t posn = 0; posn < 16; ++posn)</div>
|
||||
<div class="line"><a name="l00236"></a><span class="lineno"> 236</span>  state.stream[posn] ^= state.nonce[posn];</div>
|
||||
<div class="line"><a name="l00237"></a><span class="lineno"> 237</span>  if (len > 16)</div>
|
||||
<div class="line"><a name="l00238"></a><span class="lineno"> 238</span>  len = 16;</div>
|
||||
<div class="line"><a name="l00239"></a><span class="lineno"> 239</span>  memcpy(tag, state.stream, len);</div>
|
||||
<div class="line"><a name="l00240"></a><span class="lineno"> 240</span> }</div>
|
||||
<div class="line"><a name="l00241"></a><span class="lineno"> 241</span> </div>
|
||||
<div class="line"><a name="l00242"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a70229be2fe2274c4109fe7511481075a"> 242</a></span> <span class="keywordtype">bool</span> <a class="code" href="classGCMCommon.html#a70229be2fe2274c4109fe7511481075a">GCMCommon::checkTag</a>(<span class="keyword">const</span> <span class="keywordtype">void</span> *tag, <span class="keywordtype">size_t</span> len)</div>
|
||||
<div class="line"><a name="l00243"></a><span class="lineno"> 243</span> {</div>
|
||||
<div class="line"><a name="l00244"></a><span class="lineno"> 244</span>  <span class="comment">// Can never match if the expected tag length is too long.</span></div>
|
||||
<div class="line"><a name="l00245"></a><span class="lineno"> 245</span>  <span class="keywordflow">if</span> (len > 16)</div>
|
||||
<div class="line"><a name="l00246"></a><span class="lineno"> 246</span>  <span class="keywordflow">return</span> <span class="keyword">false</span>;</div>
|
||||
<div class="line"><a name="l00247"></a><span class="lineno"> 247</span> </div>
|
||||
<div class="line"><a name="l00248"></a><span class="lineno"> 248</span>  <span class="comment">// Compute the tag and check it.</span></div>
|
||||
<div class="line"><a name="l00249"></a><span class="lineno"> 249</span>  <a class="code" href="classGCMCommon.html#a444634bd4469bb5d404ac882d1d8fdf4">computeTag</a>(state.counter, 16);</div>
|
||||
<div class="line"><a name="l00250"></a><span class="lineno"> 250</span>  <span class="keywordflow">return</span> secure_compare(state.counter, tag, len);</div>
|
||||
<div class="line"><a name="l00251"></a><span class="lineno"> 251</span> }</div>
|
||||
<div class="line"><a name="l00252"></a><span class="lineno"> 252</span> </div>
|
||||
<div class="line"><a name="l00253"></a><span class="lineno"><a class="line" href="classGCMCommon.html#a06868ebd67a571aa68d88d5d072cece9"> 253</a></span> <span class="keywordtype">void</span> <a class="code" href="classGCMCommon.html#a06868ebd67a571aa68d88d5d072cece9">GCMCommon::clear</a>()</div>
|
||||
<div class="line"><a name="l00254"></a><span class="lineno"> 254</span> {</div>
|
||||
<div class="line"><a name="l00255"></a><span class="lineno"> 255</span>  blockCipher-><a class="code" href="classBlockCipher.html#a6f27d46e9dfa7761d014d828ad5f955b">clear</a>();</div>
|
||||
<div class="line"><a name="l00256"></a><span class="lineno"> 256</span>  ghash.<a class="code" href="classGHASH.html#a4b1ee789debf56f7f24807960ef0556e">clear</a>();</div>
|
||||
<div class="line"><a name="l00257"></a><span class="lineno"> 257</span>  clean(state);</div>
|
||||
<div class="line"><a name="l00258"></a><span class="lineno"> 258</span>  state.posn = 16;</div>
|
||||
<div class="line"><a name="l00259"></a><span class="lineno"> 259</span> }</div>
|
||||
<div class="line"><a name="l00260"></a><span class="lineno"> 260</span> </div>
|
||||
<div class="ttc" id="classGCMCommon_html_a444634bd4469bb5d404ac882d1d8fdf4"><div class="ttname"><a href="classGCMCommon.html#a444634bd4469bb5d404ac882d1d8fdf4">GCMCommon::computeTag</a></div><div class="ttdeci">void computeTag(void *tag, size_t len)</div><div class="ttdoc">Finalizes the encryption process and computes the authentication tag. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00222">GCM.cpp:222</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a397c5dddde828c59eb63367385aec562"><div class="ttname"><a href="classGCMCommon.html#a397c5dddde828c59eb63367385aec562">GCMCommon::setKey</a></div><div class="ttdeci">bool setKey(const uint8_t *key, size_t len)</div><div class="ttdoc">Sets the key to use for future encryption and decryption operations. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00077">GCM.cpp:77</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a935f343858e98ee331706daf43e34805"><div class="ttname"><a href="classGCMCommon.html#a935f343858e98ee331706daf43e34805">GCMCommon::tagSize</a></div><div class="ttdeci">size_t tagSize() const </div><div class="ttdoc">Returns the size of the authentication tag. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00072">GCM.cpp:72</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a01ac69afe3d9fc4d72b2ea5dc242e55c"><div class="ttname"><a href="classGCMCommon.html#a01ac69afe3d9fc4d72b2ea5dc242e55c">GCMCommon::encrypt</a></div><div class="ttdeci">void encrypt(uint8_t *output, const uint8_t *input, size_t len)</div><div class="ttdoc">Encrypts an input buffer and writes the ciphertext to an output buffer. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00146">GCM.cpp:146</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a06868ebd67a571aa68d88d5d072cece9"><div class="ttname"><a href="classGCMCommon.html#a06868ebd67a571aa68d88d5d072cece9">GCMCommon::clear</a></div><div class="ttdeci">void clear()</div><div class="ttdoc">Clears all security-sensitive state from this cipher. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00257">GCM.cpp:257</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a70229be2fe2274c4109fe7511481075a"><div class="ttname"><a href="classGCMCommon.html#a70229be2fe2274c4109fe7511481075a">GCMCommon::checkTag</a></div><div class="ttdeci">bool checkTag(const void *tag, size_t len)</div><div class="ttdoc">Finalizes the decryption process and checks the authentication tag. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00246">GCM.cpp:246</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a01ac69afe3d9fc4d72b2ea5dc242e55c"><div class="ttname"><a href="classGCMCommon.html#a01ac69afe3d9fc4d72b2ea5dc242e55c">GCMCommon::encrypt</a></div><div class="ttdeci">void encrypt(uint8_t *output, const uint8_t *input, size_t len)</div><div class="ttdoc">Encrypts an input buffer and writes the ciphertext to an output buffer. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00142">GCM.cpp:142</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a06868ebd67a571aa68d88d5d072cece9"><div class="ttname"><a href="classGCMCommon.html#a06868ebd67a571aa68d88d5d072cece9">GCMCommon::clear</a></div><div class="ttdeci">void clear()</div><div class="ttdoc">Clears all security-sensitive state from this cipher. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00253">GCM.cpp:253</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a70229be2fe2274c4109fe7511481075a"><div class="ttname"><a href="classGCMCommon.html#a70229be2fe2274c4109fe7511481075a">GCMCommon::checkTag</a></div><div class="ttdeci">bool checkTag(const void *tag, size_t len)</div><div class="ttdoc">Finalizes the decryption process and checks the authentication tag. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00242">GCM.cpp:242</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a01cff072505e861fd20f6cfee1e10fb2"><div class="ttname"><a href="classGCMCommon.html#a01cff072505e861fd20f6cfee1e10fb2">GCMCommon::ivSize</a></div><div class="ttdeci">size_t ivSize() const </div><div class="ttdoc">Size of the initialization vector for this cipher, in bytes. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00066">GCM.cpp:66</a></div></div>
|
||||
<div class="ttc" id="classGHASH_html_ab221298ca69c9612bfbfd3dedcb28307"><div class="ttname"><a href="classGHASH.html#ab221298ca69c9612bfbfd3dedcb28307">GHASH::finalize</a></div><div class="ttdeci">void finalize(void *token, size_t len)</div><div class="ttdoc">Finalizes the authentication process and returns the token. </div><div class="ttdef"><b>Definition:</b> <a href="GHASH_8cpp_source.html#l00121">GHASH.cpp:121</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_ad926e980ae2d61c10c9bf82813154a25"><div class="ttname"><a href="classGCMCommon.html#ad926e980ae2d61c10c9bf82813154a25">GCMCommon::addAuthData</a></div><div class="ttdeci">void addAuthData(const void *data, size_t len)</div><div class="ttdoc">Adds extra data that will be authenticated but not encrypted. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00218">GCM.cpp:218</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_ad926e980ae2d61c10c9bf82813154a25"><div class="ttname"><a href="classGCMCommon.html#ad926e980ae2d61c10c9bf82813154a25">GCMCommon::addAuthData</a></div><div class="ttdeci">void addAuthData(const void *data, size_t len)</div><div class="ttdoc">Adds extra data that will be authenticated but not encrypted. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00214">GCM.cpp:214</a></div></div>
|
||||
<div class="ttc" id="classGHASH_html_a235edb14c6ed1ec55ddda595816ef1c7"><div class="ttname"><a href="classGHASH.html#a235edb14c6ed1ec55ddda595816ef1c7">GHASH::update</a></div><div class="ttdeci">void update(const void *data, size_t len)</div><div class="ttdoc">Updates the message authenticator with more data. </div><div class="ttdef"><b>Definition:</b> <a href="GHASH_8cpp_source.html#l00085">GHASH.cpp:85</a></div></div>
|
||||
<div class="ttc" id="classBlockCipher_html_aed0788b25f6bb2f1bd47d5a5f0c5db33"><div class="ttname"><a href="classBlockCipher.html#aed0788b25f6bb2f1bd47d5a5f0c5db33">BlockCipher::encryptBlock</a></div><div class="ttdeci">virtual void encryptBlock(uint8_t *output, const uint8_t *input)=0</div><div class="ttdoc">Encrypts a single block using this cipher. </div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a60912d3ab5766aa68dc9b3111ac2c0d7"><div class="ttname"><a href="classGCMCommon.html#a60912d3ab5766aa68dc9b3111ac2c0d7">GCMCommon::decrypt</a></div><div class="ttdeci">void decrypt(uint8_t *output, const uint8_t *input, size_t len)</div><div class="ttdoc">Decrypts an input buffer and writes the plaintext to an output buffer. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00183">GCM.cpp:183</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a60912d3ab5766aa68dc9b3111ac2c0d7"><div class="ttname"><a href="classGCMCommon.html#a60912d3ab5766aa68dc9b3111ac2c0d7">GCMCommon::decrypt</a></div><div class="ttdeci">void decrypt(uint8_t *output, const uint8_t *input, size_t len)</div><div class="ttdoc">Decrypts an input buffer and writes the plaintext to an output buffer. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00179">GCM.cpp:179</a></div></div>
|
||||
<div class="ttc" id="classBlockCipher_html_a9a05307664469777592799c8f77397c4"><div class="ttname"><a href="classBlockCipher.html#a9a05307664469777592799c8f77397c4">BlockCipher::setKey</a></div><div class="ttdeci">virtual bool setKey(const uint8_t *key, size_t len)=0</div><div class="ttdoc">Sets the key to use for future encryption and decryption operations. </div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a1b05ff393e8c20db30cb991e875aab19"><div class="ttname"><a href="classGCMCommon.html#a1b05ff393e8c20db30cb991e875aab19">GCMCommon::GCMCommon</a></div><div class="ttdeci">GCMCommon()</div><div class="ttdoc">Constructs a new cipher in GCM mode. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00044">GCM.cpp:44</a></div></div>
|
||||
<div class="ttc" id="classGHASH_html_a8c38ee9313605f1d8b12dca7cd43e4ad"><div class="ttname"><a href="classGHASH.html#a8c38ee9313605f1d8b12dca7cd43e4ad">GHASH::pad</a></div><div class="ttdeci">void pad()</div><div class="ttdoc">Pads the input stream with zero bytes to a multiple of 16. </div><div class="ttdef"><b>Definition:</b> <a href="GHASH_8cpp_source.html#l00137">GHASH.cpp:137</a></div></div>
|
||||
<div class="ttc" id="classBlockCipher_html_a6f27d46e9dfa7761d014d828ad5f955b"><div class="ttname"><a href="classBlockCipher.html#a6f27d46e9dfa7761d014d828ad5f955b">BlockCipher::clear</a></div><div class="ttdeci">virtual void clear()=0</div><div class="ttdoc">Clears all security-sensitive state from this block cipher. </div></div>
|
||||
<div class="ttc" id="classGHASH_html_a4b1ee789debf56f7f24807960ef0556e"><div class="ttname"><a href="classGHASH.html#a4b1ee789debf56f7f24807960ef0556e">GHASH::clear</a></div><div class="ttdeci">void clear()</div><div class="ttdoc">Clears the authenticator's state, removing all sensitive data. </div><div class="ttdef"><b>Definition:</b> <a href="GHASH_8cpp_source.html#l00150">GHASH.cpp:150</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a0d3e1525d91adbbdcd5ac27793817112"><div class="ttname"><a href="classGCMCommon.html#a0d3e1525d91adbbdcd5ac27793817112">GCMCommon::~GCMCommon</a></div><div class="ttdeci">virtual ~GCMCommon()</div><div class="ttdoc">Destroys this cipher object after clearing sensitive information. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00056">GCM.cpp:56</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a2545135fe42c832e40e057b603824524"><div class="ttname"><a href="classGCMCommon.html#a2545135fe42c832e40e057b603824524">GCMCommon::setIV</a></div><div class="ttdeci">bool setIV(const uint8_t *iv, size_t len)</div><div class="ttdoc">Sets the initialization vector to use for future encryption and decryption operations. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00090">GCM.cpp:90</a></div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a2545135fe42c832e40e057b603824524"><div class="ttname"><a href="classGCMCommon.html#a2545135fe42c832e40e057b603824524">GCMCommon::setIV</a></div><div class="ttdeci">bool setIV(const uint8_t *iv, size_t len)</div><div class="ttdoc">Sets the initialization vector to use for future encryption and decryption operations. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00083">GCM.cpp:83</a></div></div>
|
||||
<div class="ttc" id="classBlockCipher_html_afde6004a859e015d877eab3c37042a0f"><div class="ttname"><a href="classBlockCipher.html#afde6004a859e015d877eab3c37042a0f">BlockCipher::keySize</a></div><div class="ttdeci">virtual size_t keySize() const =0</div><div class="ttdoc">Default size of the key for this block cipher, in bytes. </div></div>
|
||||
<div class="ttc" id="classGCMCommon_html_a134ba35e740a18bee3c45502b4149eae"><div class="ttname"><a href="classGCMCommon.html#a134ba35e740a18bee3c45502b4149eae">GCMCommon::keySize</a></div><div class="ttdeci">size_t keySize() const </div><div class="ttdoc">Default size of the key for this cipher, in bytes. </div><div class="ttdef"><b>Definition:</b> <a href="GCM_8cpp_source.html#l00061">GCM.cpp:61</a></div></div>
|
||||
<div class="ttc" id="classGHASH_html_a479a3e8c37e320bf99f54b95bf5f4c55"><div class="ttname"><a href="classGHASH.html#a479a3e8c37e320bf99f54b95bf5f4c55">GHASH::reset</a></div><div class="ttdeci">void reset(const void *key)</div><div class="ttdoc">Resets the GHASH message authenticator for a new session. </div><div class="ttdef"><b>Definition:</b> <a href="GHASH_8cpp_source.html#l00067">GHASH.cpp:67</a></div></div>
|
||||
</div><!-- fragment --></div><!-- contents -->
|
||||
<!-- start footer part -->
|
||||
<hr class="footer"/><address class="footer"><small>
|
||||
Generated on Sat Apr 7 2018 10:23:43 for Arduino Cryptography Library by  <a href="http://www.doxygen.org/index.html">
|
||||
Generated on Thu Apr 26 2018 06:55:48 for Arduino Cryptography Library by  <a href="http://www.doxygen.org/index.html">
|
||||
<img class="footer" src="doxygen.png" alt="doxygen"/>
|
||||
</a> 1.8.6
|
||||
</small></address>
|
||||
|
||||
Reference in New Issue
Block a user