<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/> <meta http-equiv="X-UA-Compatible" content="IE=9"/> <meta name="generator" content="Doxygen 1.8.5"/> <title>PolarSSL v1.3.8: ccm.c Source File</title> <link href="tabs.css" rel="stylesheet" type="text/css"/> <script type="text/javascript" src="jquery.js"></script> <script type="text/javascript" src="dynsections.js"></script> <link href="doxygen.css" rel="stylesheet" type="text/css" /> </head> <body> <div id="top"><!-- do not remove this div, it is closed by doxygen! --> <div id="titlearea"> <table cellspacing="0" cellpadding="0"> <tbody> <tr style="height: 56px;"> <td style="padding-left: 0.5em;"> <div id="projectname">PolarSSL v1.3.8 </div> </td> </tr> </tbody> </table> </div> <!-- end header part --> <!-- Generated by Doxygen 1.8.5 --> <div id="navrow1" class="tabs"> <ul class="tablist"> <li><a href="index.html"><span>Main Page</span></a></li> <li><a href="modules.html"><span>Modules</span></a></li> <li><a href="annotated.html"><span>Data Structures</span></a></li> <li class="current"><a href="files.html"><span>Files</span></a></li> </ul> </div> <div id="navrow2" class="tabs2"> <ul class="tablist"> <li><a href="files.html"><span>File List</span></a></li> <li><a href="globals.html"><span>Globals</span></a></li> </ul> </div> <div id="nav-path" class="navpath"> <ul> <li class="navelem"><a class="el" href="dir_4478130ea462cc4195c75f9e6ba20061.html">library</a></li> </ul> </div> </div><!-- top --> <div class="header"> <div class="headertitle"> <div class="title">ccm.c</div> </div> </div><!--header--> <div class="contents"> <a href="ccm_8c.html">Go to the documentation of this file.</a><div class="fragment"><div class="line"><a name="l00001"></a><span class="lineno"> 1</span> <span class="comment">/*</span></div> <div class="line"><a name="l00002"></a><span class="lineno"> 2</span> <span class="comment"> * NIST SP800-38C compliant CCM implementation</span></div> <div class="line"><a name="l00003"></a><span class="lineno"> 3</span> <span class="comment"> *</span></div> <div class="line"><a name="l00004"></a><span class="lineno"> 4</span> <span class="comment"> * Copyright (C) 2014, Brainspark B.V.</span></div> <div class="line"><a name="l00005"></a><span class="lineno"> 5</span> <span class="comment"> *</span></div> <div class="line"><a name="l00006"></a><span class="lineno"> 6</span> <span class="comment"> * This file is part of PolarSSL (http://www.polarssl.org)</span></div> <div class="line"><a name="l00007"></a><span class="lineno"> 7</span> <span class="comment"> * Lead Maintainer: Paul Bakker <polarssl_maintainer at polarssl.org></span></div> <div class="line"><a name="l00008"></a><span class="lineno"> 8</span> <span class="comment"> *</span></div> <div class="line"><a name="l00009"></a><span class="lineno"> 9</span> <span class="comment"> * All rights reserved.</span></div> <div class="line"><a name="l00010"></a><span class="lineno"> 10</span> <span class="comment"> *</span></div> <div class="line"><a name="l00011"></a><span class="lineno"> 11</span> <span class="comment"> * This program is free software; you can redistribute it and/or modify</span></div> <div class="line"><a name="l00012"></a><span class="lineno"> 12</span> <span class="comment"> * it under the terms of the GNU General Public License as published by</span></div> <div class="line"><a name="l00013"></a><span class="lineno"> 13</span> <span class="comment"> * the Free Software Foundation; either version 2 of the License, or</span></div> <div class="line"><a name="l00014"></a><span class="lineno"> 14</span> <span class="comment"> * (at your option) any later version.</span></div> <div class="line"><a name="l00015"></a><span class="lineno"> 15</span> <span class="comment"> *</span></div> <div class="line"><a name="l00016"></a><span class="lineno"> 16</span> <span class="comment"> * This program is distributed in the hope that it will be useful,</span></div> <div class="line"><a name="l00017"></a><span class="lineno"> 17</span> <span class="comment"> * but WITHOUT ANY WARRANTY; without even the implied warranty of</span></div> <div class="line"><a name="l00018"></a><span class="lineno"> 18</span> <span class="comment"> * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the</span></div> <div class="line"><a name="l00019"></a><span class="lineno"> 19</span> <span class="comment"> * GNU General Public License for more details.</span></div> <div class="line"><a name="l00020"></a><span class="lineno"> 20</span> <span class="comment"> *</span></div> <div class="line"><a name="l00021"></a><span class="lineno"> 21</span> <span class="comment"> * You should have received a copy of the GNU General Public License along</span></div> <div class="line"><a name="l00022"></a><span class="lineno"> 22</span> <span class="comment"> * with this program; if not, write to the Free Software Foundation, Inc.,</span></div> <div class="line"><a name="l00023"></a><span class="lineno"> 23</span> <span class="comment"> * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.</span></div> <div class="line"><a name="l00024"></a><span class="lineno"> 24</span> <span class="comment"> */</span></div> <div class="line"><a name="l00025"></a><span class="lineno"> 25</span> </div> <div class="line"><a name="l00026"></a><span class="lineno"> 26</span> <span class="comment">/*</span></div> <div class="line"><a name="l00027"></a><span class="lineno"> 27</span> <span class="comment"> * Definition of CCM:</span></div> <div class="line"><a name="l00028"></a><span class="lineno"> 28</span> <span class="comment"> * http://csrc.nist.gov/publications/nistpubs/800-38C/SP800-38C_updated-July20_2007.pdf</span></div> <div class="line"><a name="l00029"></a><span class="lineno"> 29</span> <span class="comment"> * RFC 3610 "Counter with CBC-MAC (CCM)"</span></div> <div class="line"><a name="l00030"></a><span class="lineno"> 30</span> <span class="comment"> *</span></div> <div class="line"><a name="l00031"></a><span class="lineno"> 31</span> <span class="comment"> * Related:</span></div> <div class="line"><a name="l00032"></a><span class="lineno"> 32</span> <span class="comment"> * RFC 5116 "An Interface and Algorithms for Authenticated Encryption"</span></div> <div class="line"><a name="l00033"></a><span class="lineno"> 33</span> <span class="comment"> */</span></div> <div class="line"><a name="l00034"></a><span class="lineno"> 34</span> </div> <div class="line"><a name="l00035"></a><span class="lineno"> 35</span> <span class="preprocessor">#if !defined(POLARSSL_CONFIG_FILE)</span></div> <div class="line"><a name="l00036"></a><span class="lineno"> 36</span> <span class="preprocessor"></span><span class="preprocessor">#include "<a class="code" href="config_8h.html">polarssl/config.h</a>"</span></div> <div class="line"><a name="l00037"></a><span class="lineno"> 37</span> <span class="preprocessor">#else</span></div> <div class="line"><a name="l00038"></a><span class="lineno"> 38</span> <span class="preprocessor"></span><span class="preprocessor">#include POLARSSL_CONFIG_FILE</span></div> <div class="line"><a name="l00039"></a><span class="lineno"> 39</span> <span class="preprocessor"></span><span class="preprocessor">#endif</span></div> <div class="line"><a name="l00040"></a><span class="lineno"> 40</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00041"></a><span class="lineno"> 41</span> <span class="preprocessor">#if defined(POLARSSL_CCM_C)</span></div> <div class="line"><a name="l00042"></a><span class="lineno"> 42</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00043"></a><span class="lineno"> 43</span> <span class="preprocessor">#include "<a class="code" href="ccm_8h.html">polarssl/ccm.h</a>"</span></div> <div class="line"><a name="l00044"></a><span class="lineno"> 44</span> </div> <div class="line"><a name="l00045"></a><span class="lineno"> 45</span> <span class="comment">/* Implementation that should never be optimized out by the compiler */</span></div> <div class="line"><a name="l00046"></a><span class="lineno"> 46</span> <span class="keyword">static</span> <span class="keywordtype">void</span> polarssl_zeroize( <span class="keywordtype">void</span> *v, <span class="keywordtype">size_t</span> n ) {</div> <div class="line"><a name="l00047"></a><span class="lineno"> 47</span>  <span class="keyword">volatile</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *p = v; <span class="keywordflow">while</span>( n-- ) *p++ = 0;</div> <div class="line"><a name="l00048"></a><span class="lineno"> 48</span> }</div> <div class="line"><a name="l00049"></a><span class="lineno"> 49</span> </div> <div class="line"><a name="l00050"></a><span class="lineno"> 50</span> <span class="preprocessor">#define CCM_ENCRYPT 0</span></div> <div class="line"><a name="l00051"></a><span class="lineno"> 51</span> <span class="preprocessor"></span><span class="preprocessor">#define CCM_DECRYPT 1</span></div> <div class="line"><a name="l00052"></a><span class="lineno"> 52</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00053"></a><span class="lineno"> 53</span> <span class="comment">/*</span></div> <div class="line"><a name="l00054"></a><span class="lineno"> 54</span> <span class="comment"> * Initialize context</span></div> <div class="line"><a name="l00055"></a><span class="lineno"> 55</span> <span class="comment"> */</span></div> <div class="line"><a name="l00056"></a><span class="lineno"> 56</span> <span class="keywordtype">int</span> <a class="code" href="ccm_8h.html#aeea3832a1d2ee9eb264e3cd9013900d8">ccm_init</a>( <a class="code" href="structccm__context.html">ccm_context</a> *ctx, <a class="code" href="cipher_8h.html#a373f5d3a0a42c77ff4f5fe4fe7da0560">cipher_id_t</a> cipher,</div> <div class="line"><a name="l00057"></a><span class="lineno"> 57</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *key, <span class="keywordtype">unsigned</span> <span class="keywordtype">int</span> keysize )</div> <div class="line"><a name="l00058"></a><span class="lineno"> 58</span> {</div> <div class="line"><a name="l00059"></a><span class="lineno"> 59</span>  <span class="keywordtype">int</span> ret;</div> <div class="line"><a name="l00060"></a><span class="lineno"> 60</span>  <span class="keyword">const</span> <a class="code" href="structcipher__info__t.html">cipher_info_t</a> *cipher_info;</div> <div class="line"><a name="l00061"></a><span class="lineno"> 61</span> </div> <div class="line"><a name="l00062"></a><span class="lineno"> 62</span>  memset( ctx, 0, <span class="keyword">sizeof</span>( <a class="code" href="structccm__context.html">ccm_context</a> ) );</div> <div class="line"><a name="l00063"></a><span class="lineno"> 63</span> </div> <div class="line"><a name="l00064"></a><span class="lineno"> 64</span>  <a class="code" href="cipher_8h.html#a6a719708dc3b2f0d0e7beadccf871f4f">cipher_init</a>( &ctx-><a class="code" href="structccm__context.html#a91e58dba6b94b59dd8fdce63bc2491fa">cipher_ctx</a> );</div> <div class="line"><a name="l00065"></a><span class="lineno"> 65</span> </div> <div class="line"><a name="l00066"></a><span class="lineno"> 66</span>  cipher_info = <a class="code" href="cipher_8h.html#a68fd6a4ea2c236dc4abcad76d73d5cac">cipher_info_from_values</a>( cipher, keysize, <a class="code" href="cipher_8h.html#af65d0bd9b5c3504fd010cf54955b179caaefd6ed34c1992d638129e161b28084a">POLARSSL_MODE_ECB</a> );</div> <div class="line"><a name="l00067"></a><span class="lineno"> 67</span>  <span class="keywordflow">if</span>( cipher_info == NULL )</div> <div class="line"><a name="l00068"></a><span class="lineno"> 68</span>  <span class="keywordflow">return</span>( <a class="code" href="ccm_8h.html#a511bce4dba4b1934174a199e716ed37d">POLARSSL_ERR_CCM_BAD_INPUT</a> );</div> <div class="line"><a name="l00069"></a><span class="lineno"> 69</span> </div> <div class="line"><a name="l00070"></a><span class="lineno"> 70</span>  <span class="keywordflow">if</span>( cipher_info-><a class="code" href="structcipher__info__t.html#a7e21795685c79613b5125ca608b0c63b">block_size</a> != 16 )</div> <div class="line"><a name="l00071"></a><span class="lineno"> 71</span>  <span class="keywordflow">return</span>( <a class="code" href="ccm_8h.html#a511bce4dba4b1934174a199e716ed37d">POLARSSL_ERR_CCM_BAD_INPUT</a> );</div> <div class="line"><a name="l00072"></a><span class="lineno"> 72</span> </div> <div class="line"><a name="l00073"></a><span class="lineno"> 73</span>  <span class="keywordflow">if</span>( ( ret = <a class="code" href="cipher_8h.html#adc7c37e925193805884085ca87587f64">cipher_init_ctx</a>( &ctx-><a class="code" href="structccm__context.html#a91e58dba6b94b59dd8fdce63bc2491fa">cipher_ctx</a>, cipher_info ) ) != 0 )</div> <div class="line"><a name="l00074"></a><span class="lineno"> 74</span>  <span class="keywordflow">return</span>( ret );</div> <div class="line"><a name="l00075"></a><span class="lineno"> 75</span> </div> <div class="line"><a name="l00076"></a><span class="lineno"> 76</span>  <span class="keywordflow">if</span>( ( ret = <a class="code" href="cipher_8h.html#a77355bddf2d69f68d55e2bd2374e9257">cipher_setkey</a>( &ctx-><a class="code" href="structccm__context.html#a91e58dba6b94b59dd8fdce63bc2491fa">cipher_ctx</a>, key, keysize,</div> <div class="line"><a name="l00077"></a><span class="lineno"> 77</span>  <a class="code" href="cipher_8h.html#a76a810650461f2062938ee9b82666b36ad8e41c0d381b23d7835dd322e511564f">POLARSSL_ENCRYPT</a> ) ) != 0 )</div> <div class="line"><a name="l00078"></a><span class="lineno"> 78</span>  {</div> <div class="line"><a name="l00079"></a><span class="lineno"> 79</span>  <span class="keywordflow">return</span>( ret );</div> <div class="line"><a name="l00080"></a><span class="lineno"> 80</span>  }</div> <div class="line"><a name="l00081"></a><span class="lineno"> 81</span> </div> <div class="line"><a name="l00082"></a><span class="lineno"> 82</span>  <span class="keywordflow">return</span>( 0 );</div> <div class="line"><a name="l00083"></a><span class="lineno"> 83</span> }</div> <div class="line"><a name="l00084"></a><span class="lineno"> 84</span> </div> <div class="line"><a name="l00085"></a><span class="lineno"> 85</span> <span class="comment">/*</span></div> <div class="line"><a name="l00086"></a><span class="lineno"> 86</span> <span class="comment"> * Free context</span></div> <div class="line"><a name="l00087"></a><span class="lineno"> 87</span> <span class="comment"> */</span></div> <div class="line"><a name="l00088"></a><span class="lineno"> 88</span> <span class="keywordtype">void</span> <a class="code" href="ccm_8h.html#a884657cd0c69f0870e8ecc92dbdb9dd3">ccm_free</a>( <a class="code" href="structccm__context.html">ccm_context</a> *ctx )</div> <div class="line"><a name="l00089"></a><span class="lineno"> 89</span> {</div> <div class="line"><a name="l00090"></a><span class="lineno"> 90</span>  <a class="code" href="cipher_8h.html#af27f8e4cd1fab59615c3d73c69d136c8">cipher_free</a>( &ctx-><a class="code" href="structccm__context.html#a91e58dba6b94b59dd8fdce63bc2491fa">cipher_ctx</a> );</div> <div class="line"><a name="l00091"></a><span class="lineno"> 91</span>  polarssl_zeroize( ctx, <span class="keyword">sizeof</span>( <a class="code" href="structccm__context.html">ccm_context</a> ) );</div> <div class="line"><a name="l00092"></a><span class="lineno"> 92</span> }</div> <div class="line"><a name="l00093"></a><span class="lineno"> 93</span> </div> <div class="line"><a name="l00094"></a><span class="lineno"> 94</span> <span class="comment">/*</span></div> <div class="line"><a name="l00095"></a><span class="lineno"> 95</span> <span class="comment"> * Macros for common operations.</span></div> <div class="line"><a name="l00096"></a><span class="lineno"> 96</span> <span class="comment"> * Results in smaller compiled code than static inline functions.</span></div> <div class="line"><a name="l00097"></a><span class="lineno"> 97</span> <span class="comment"> */</span></div> <div class="line"><a name="l00098"></a><span class="lineno"> 98</span> </div> <div class="line"><a name="l00099"></a><span class="lineno"> 99</span> <span class="comment">/*</span></div> <div class="line"><a name="l00100"></a><span class="lineno"> 100</span> <span class="comment"> * Update the CBC-MAC state in y using a block in b</span></div> <div class="line"><a name="l00101"></a><span class="lineno"> 101</span> <span class="comment"> * (Always using b as the source helps the compiler optimise a bit better.)</span></div> <div class="line"><a name="l00102"></a><span class="lineno"> 102</span> <span class="comment"> */</span></div> <div class="line"><a name="l00103"></a><span class="lineno"> 103</span> <span class="preprocessor">#define UPDATE_CBC_MAC \</span></div> <div class="line"><a name="l00104"></a><span class="lineno"> 104</span> <span class="preprocessor"> for( i = 0; i < 16; i++ ) \</span></div> <div class="line"><a name="l00105"></a><span class="lineno"> 105</span> <span class="preprocessor"> y[i] ^= b[i]; \</span></div> <div class="line"><a name="l00106"></a><span class="lineno"> 106</span> <span class="preprocessor"> \</span></div> <div class="line"><a name="l00107"></a><span class="lineno"> 107</span> <span class="preprocessor"> if( ( ret = cipher_update( &ctx->cipher_ctx, y, 16, y, &olen ) ) != 0 ) \</span></div> <div class="line"><a name="l00108"></a><span class="lineno"> 108</span> <span class="preprocessor"> return( ret );</span></div> <div class="line"><a name="l00109"></a><span class="lineno"> 109</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00110"></a><span class="lineno"> 110</span> <span class="comment">/*</span></div> <div class="line"><a name="l00111"></a><span class="lineno"> 111</span> <span class="comment"> * Encrypt or decrypt a partial block with CTR</span></div> <div class="line"><a name="l00112"></a><span class="lineno"> 112</span> <span class="comment"> * Warning: using b for temporary storage! src and dst must not be b!</span></div> <div class="line"><a name="l00113"></a><span class="lineno"> 113</span> <span class="comment"> * This avoids allocating one more 16 bytes buffer while allowing src == dst.</span></div> <div class="line"><a name="l00114"></a><span class="lineno"> 114</span> <span class="comment"> */</span></div> <div class="line"><a name="l00115"></a><span class="lineno"> 115</span> <span class="preprocessor">#define CTR_CRYPT( dst, src, len ) \</span></div> <div class="line"><a name="l00116"></a><span class="lineno"> 116</span> <span class="preprocessor"> if( ( ret = cipher_update( &ctx->cipher_ctx, ctr, 16, b, &olen ) ) != 0 ) \</span></div> <div class="line"><a name="l00117"></a><span class="lineno"> 117</span> <span class="preprocessor"> return( ret ); \</span></div> <div class="line"><a name="l00118"></a><span class="lineno"> 118</span> <span class="preprocessor"> \</span></div> <div class="line"><a name="l00119"></a><span class="lineno"> 119</span> <span class="preprocessor"> for( i = 0; i < len; i++ ) \</span></div> <div class="line"><a name="l00120"></a><span class="lineno"> 120</span> <span class="preprocessor"> dst[i] = src[i] ^ b[i];</span></div> <div class="line"><a name="l00121"></a><span class="lineno"> 121</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00122"></a><span class="lineno"> 122</span> <span class="comment">/*</span></div> <div class="line"><a name="l00123"></a><span class="lineno"> 123</span> <span class="comment"> * Authenticated encryption or decryption</span></div> <div class="line"><a name="l00124"></a><span class="lineno"> 124</span> <span class="comment"> */</span></div> <div class="line"><a name="l00125"></a><span class="lineno"> 125</span> <span class="keyword">static</span> <span class="keywordtype">int</span> ccm_auth_crypt( <a class="code" href="structccm__context.html">ccm_context</a> *ctx, <span class="keywordtype">int</span> mode, <span class="keywordtype">size_t</span> length,</div> <div class="line"><a name="l00126"></a><span class="lineno"> 126</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *iv, <span class="keywordtype">size_t</span> iv_len,</div> <div class="line"><a name="l00127"></a><span class="lineno"> 127</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *add, <span class="keywordtype">size_t</span> add_len,</div> <div class="line"><a name="l00128"></a><span class="lineno"> 128</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *input, <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *output,</div> <div class="line"><a name="l00129"></a><span class="lineno"> 129</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *tag, <span class="keywordtype">size_t</span> tag_len )</div> <div class="line"><a name="l00130"></a><span class="lineno"> 130</span> {</div> <div class="line"><a name="l00131"></a><span class="lineno"> 131</span>  <span class="keywordtype">int</span> ret;</div> <div class="line"><a name="l00132"></a><span class="lineno"> 132</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> i;</div> <div class="line"><a name="l00133"></a><span class="lineno"> 133</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> q = 16 - 1 - iv_len;</div> <div class="line"><a name="l00134"></a><span class="lineno"> 134</span>  <span class="keywordtype">size_t</span> len_left, olen;</div> <div class="line"><a name="l00135"></a><span class="lineno"> 135</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> b[16];</div> <div class="line"><a name="l00136"></a><span class="lineno"> 136</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> y[16];</div> <div class="line"><a name="l00137"></a><span class="lineno"> 137</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> ctr[16];</div> <div class="line"><a name="l00138"></a><span class="lineno"> 138</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *src;</div> <div class="line"><a name="l00139"></a><span class="lineno"> 139</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *dst;</div> <div class="line"><a name="l00140"></a><span class="lineno"> 140</span> </div> <div class="line"><a name="l00141"></a><span class="lineno"> 141</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00142"></a><span class="lineno"> 142</span> <span class="comment"> * Check length requirements: SP800-38C A.1</span></div> <div class="line"><a name="l00143"></a><span class="lineno"> 143</span> <span class="comment"> * Additional requirement: a < 2^16 - 2^8 to simplify the code.</span></div> <div class="line"><a name="l00144"></a><span class="lineno"> 144</span> <span class="comment"> * 'length' checked later (when writing it to the first block)</span></div> <div class="line"><a name="l00145"></a><span class="lineno"> 145</span> <span class="comment"> */</span></div> <div class="line"><a name="l00146"></a><span class="lineno"> 146</span>  <span class="keywordflow">if</span>( tag_len < 4 || tag_len > 16 || tag_len % 2 != 0 )</div> <div class="line"><a name="l00147"></a><span class="lineno"> 147</span>  <span class="keywordflow">return</span>( <a class="code" href="ccm_8h.html#a511bce4dba4b1934174a199e716ed37d">POLARSSL_ERR_CCM_BAD_INPUT</a> );</div> <div class="line"><a name="l00148"></a><span class="lineno"> 148</span> </div> <div class="line"><a name="l00149"></a><span class="lineno"> 149</span>  <span class="comment">/* Also implies q is within bounds */</span></div> <div class="line"><a name="l00150"></a><span class="lineno"> 150</span>  <span class="keywordflow">if</span>( iv_len < 7 || iv_len > 13 )</div> <div class="line"><a name="l00151"></a><span class="lineno"> 151</span>  <span class="keywordflow">return</span>( <a class="code" href="ccm_8h.html#a511bce4dba4b1934174a199e716ed37d">POLARSSL_ERR_CCM_BAD_INPUT</a> );</div> <div class="line"><a name="l00152"></a><span class="lineno"> 152</span> </div> <div class="line"><a name="l00153"></a><span class="lineno"> 153</span>  <span class="keywordflow">if</span>( add_len > 0xFF00 )</div> <div class="line"><a name="l00154"></a><span class="lineno"> 154</span>  <span class="keywordflow">return</span>( <a class="code" href="ccm_8h.html#a511bce4dba4b1934174a199e716ed37d">POLARSSL_ERR_CCM_BAD_INPUT</a> );</div> <div class="line"><a name="l00155"></a><span class="lineno"> 155</span> </div> <div class="line"><a name="l00156"></a><span class="lineno"> 156</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00157"></a><span class="lineno"> 157</span> <span class="comment"> * First block B_0:</span></div> <div class="line"><a name="l00158"></a><span class="lineno"> 158</span> <span class="comment"> * 0 .. 0 flags</span></div> <div class="line"><a name="l00159"></a><span class="lineno"> 159</span> <span class="comment"> * 1 .. iv_len nonce (aka iv)</span></div> <div class="line"><a name="l00160"></a><span class="lineno"> 160</span> <span class="comment"> * iv_len+1 .. 15 length</span></div> <div class="line"><a name="l00161"></a><span class="lineno"> 161</span> <span class="comment"> *</span></div> <div class="line"><a name="l00162"></a><span class="lineno"> 162</span> <span class="comment"> * With flags as (bits):</span></div> <div class="line"><a name="l00163"></a><span class="lineno"> 163</span> <span class="comment"> * 7 0</span></div> <div class="line"><a name="l00164"></a><span class="lineno"> 164</span> <span class="comment"> * 6 add present?</span></div> <div class="line"><a name="l00165"></a><span class="lineno"> 165</span> <span class="comment"> * 5 .. 3 (t - 2) / 2</span></div> <div class="line"><a name="l00166"></a><span class="lineno"> 166</span> <span class="comment"> * 2 .. 0 q - 1</span></div> <div class="line"><a name="l00167"></a><span class="lineno"> 167</span> <span class="comment"> */</span></div> <div class="line"><a name="l00168"></a><span class="lineno"> 168</span>  b[0] = 0;</div> <div class="line"><a name="l00169"></a><span class="lineno"> 169</span>  b[0] |= ( add_len > 0 ) << 6;</div> <div class="line"><a name="l00170"></a><span class="lineno"> 170</span>  b[0] |= ( ( tag_len - 2 ) / 2 ) << 3;</div> <div class="line"><a name="l00171"></a><span class="lineno"> 171</span>  b[0] |= q - 1;</div> <div class="line"><a name="l00172"></a><span class="lineno"> 172</span> </div> <div class="line"><a name="l00173"></a><span class="lineno"> 173</span>  memcpy( b + 1, iv, iv_len );</div> <div class="line"><a name="l00174"></a><span class="lineno"> 174</span> </div> <div class="line"><a name="l00175"></a><span class="lineno"> 175</span>  <span class="keywordflow">for</span>( i = 0, len_left = length; i < q; i++, len_left >>= 8 )</div> <div class="line"><a name="l00176"></a><span class="lineno"> 176</span>  b[15-i] = (<span class="keywordtype">unsigned</span> <span class="keywordtype">char</span>)( len_left & 0xFF );</div> <div class="line"><a name="l00177"></a><span class="lineno"> 177</span> </div> <div class="line"><a name="l00178"></a><span class="lineno"> 178</span>  <span class="keywordflow">if</span>( len_left > 0 )</div> <div class="line"><a name="l00179"></a><span class="lineno"> 179</span>  <span class="keywordflow">return</span>( <a class="code" href="ccm_8h.html#a511bce4dba4b1934174a199e716ed37d">POLARSSL_ERR_CCM_BAD_INPUT</a> );</div> <div class="line"><a name="l00180"></a><span class="lineno"> 180</span> </div> <div class="line"><a name="l00181"></a><span class="lineno"> 181</span> </div> <div class="line"><a name="l00182"></a><span class="lineno"> 182</span>  <span class="comment">/* Start CBC-MAC with first block */</span></div> <div class="line"><a name="l00183"></a><span class="lineno"> 183</span>  memset( y, 0, 16 );</div> <div class="line"><a name="l00184"></a><span class="lineno"> 184</span>  UPDATE_CBC_MAC;</div> <div class="line"><a name="l00185"></a><span class="lineno"> 185</span> </div> <div class="line"><a name="l00186"></a><span class="lineno"> 186</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00187"></a><span class="lineno"> 187</span> <span class="comment"> * If there is additional data, update CBC-MAC with</span></div> <div class="line"><a name="l00188"></a><span class="lineno"> 188</span> <span class="comment"> * add_len, add, 0 (padding to a block boundary)</span></div> <div class="line"><a name="l00189"></a><span class="lineno"> 189</span> <span class="comment"> */</span></div> <div class="line"><a name="l00190"></a><span class="lineno"> 190</span>  <span class="keywordflow">if</span>( add_len > 0 )</div> <div class="line"><a name="l00191"></a><span class="lineno"> 191</span>  {</div> <div class="line"><a name="l00192"></a><span class="lineno"> 192</span>  <span class="keywordtype">size_t</span> use_len;</div> <div class="line"><a name="l00193"></a><span class="lineno"> 193</span>  len_left = add_len;</div> <div class="line"><a name="l00194"></a><span class="lineno"> 194</span>  src = add;</div> <div class="line"><a name="l00195"></a><span class="lineno"> 195</span> </div> <div class="line"><a name="l00196"></a><span class="lineno"> 196</span>  memset( b, 0, 16 );</div> <div class="line"><a name="l00197"></a><span class="lineno"> 197</span>  b[0] = (<span class="keywordtype">unsigned</span> char)( ( add_len >> 8 ) & 0xFF );</div> <div class="line"><a name="l00198"></a><span class="lineno"> 198</span>  b[1] = (<span class="keywordtype">unsigned</span> char)( ( add_len ) & 0xFF );</div> <div class="line"><a name="l00199"></a><span class="lineno"> 199</span> </div> <div class="line"><a name="l00200"></a><span class="lineno"> 200</span>  use_len = len_left < 16 - 2 ? len_left : 16 - 2;</div> <div class="line"><a name="l00201"></a><span class="lineno"> 201</span>  memcpy( b + 2, src, use_len );</div> <div class="line"><a name="l00202"></a><span class="lineno"> 202</span>  len_left -= use_len;</div> <div class="line"><a name="l00203"></a><span class="lineno"> 203</span>  src += use_len;</div> <div class="line"><a name="l00204"></a><span class="lineno"> 204</span> </div> <div class="line"><a name="l00205"></a><span class="lineno"> 205</span>  UPDATE_CBC_MAC;</div> <div class="line"><a name="l00206"></a><span class="lineno"> 206</span> </div> <div class="line"><a name="l00207"></a><span class="lineno"> 207</span>  <span class="keywordflow">while</span>( len_left > 0 )</div> <div class="line"><a name="l00208"></a><span class="lineno"> 208</span>  {</div> <div class="line"><a name="l00209"></a><span class="lineno"> 209</span>  use_len = len_left > 16 ? 16 : len_left;</div> <div class="line"><a name="l00210"></a><span class="lineno"> 210</span> </div> <div class="line"><a name="l00211"></a><span class="lineno"> 211</span>  memset( b, 0, 16 );</div> <div class="line"><a name="l00212"></a><span class="lineno"> 212</span>  memcpy( b, src, use_len );</div> <div class="line"><a name="l00213"></a><span class="lineno"> 213</span>  UPDATE_CBC_MAC;</div> <div class="line"><a name="l00214"></a><span class="lineno"> 214</span> </div> <div class="line"><a name="l00215"></a><span class="lineno"> 215</span>  len_left -= use_len;</div> <div class="line"><a name="l00216"></a><span class="lineno"> 216</span>  src += use_len;</div> <div class="line"><a name="l00217"></a><span class="lineno"> 217</span>  }</div> <div class="line"><a name="l00218"></a><span class="lineno"> 218</span>  }</div> <div class="line"><a name="l00219"></a><span class="lineno"> 219</span> </div> <div class="line"><a name="l00220"></a><span class="lineno"> 220</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00221"></a><span class="lineno"> 221</span> <span class="comment"> * Prepare counter block for encryption:</span></div> <div class="line"><a name="l00222"></a><span class="lineno"> 222</span> <span class="comment"> * 0 .. 0 flags</span></div> <div class="line"><a name="l00223"></a><span class="lineno"> 223</span> <span class="comment"> * 1 .. iv_len nonce (aka iv)</span></div> <div class="line"><a name="l00224"></a><span class="lineno"> 224</span> <span class="comment"> * iv_len+1 .. 15 counter (initially 1)</span></div> <div class="line"><a name="l00225"></a><span class="lineno"> 225</span> <span class="comment"> *</span></div> <div class="line"><a name="l00226"></a><span class="lineno"> 226</span> <span class="comment"> * With flags as (bits):</span></div> <div class="line"><a name="l00227"></a><span class="lineno"> 227</span> <span class="comment"> * 7 .. 3 0</span></div> <div class="line"><a name="l00228"></a><span class="lineno"> 228</span> <span class="comment"> * 2 .. 0 q - 1</span></div> <div class="line"><a name="l00229"></a><span class="lineno"> 229</span> <span class="comment"> */</span></div> <div class="line"><a name="l00230"></a><span class="lineno"> 230</span>  ctr[0] = q - 1;</div> <div class="line"><a name="l00231"></a><span class="lineno"> 231</span>  memcpy( ctr + 1, iv, iv_len );</div> <div class="line"><a name="l00232"></a><span class="lineno"> 232</span>  memset( ctr + 1 + iv_len, 0, q );</div> <div class="line"><a name="l00233"></a><span class="lineno"> 233</span>  ctr[15] = 1;</div> <div class="line"><a name="l00234"></a><span class="lineno"> 234</span> </div> <div class="line"><a name="l00235"></a><span class="lineno"> 235</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00236"></a><span class="lineno"> 236</span> <span class="comment"> * Authenticate and {en,de}crypt the message.</span></div> <div class="line"><a name="l00237"></a><span class="lineno"> 237</span> <span class="comment"> *</span></div> <div class="line"><a name="l00238"></a><span class="lineno"> 238</span> <span class="comment"> * The only difference between encryption and decryption is</span></div> <div class="line"><a name="l00239"></a><span class="lineno"> 239</span> <span class="comment"> * the respective order of authentication and {en,de}cryption.</span></div> <div class="line"><a name="l00240"></a><span class="lineno"> 240</span> <span class="comment"> */</span></div> <div class="line"><a name="l00241"></a><span class="lineno"> 241</span>  len_left = length;</div> <div class="line"><a name="l00242"></a><span class="lineno"> 242</span>  src = input;</div> <div class="line"><a name="l00243"></a><span class="lineno"> 243</span>  dst = output;</div> <div class="line"><a name="l00244"></a><span class="lineno"> 244</span> </div> <div class="line"><a name="l00245"></a><span class="lineno"> 245</span>  <span class="keywordflow">while</span>( len_left > 0 )</div> <div class="line"><a name="l00246"></a><span class="lineno"> 246</span>  {</div> <div class="line"><a name="l00247"></a><span class="lineno"> 247</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> use_len = len_left > 16 ? 16 : len_left;</div> <div class="line"><a name="l00248"></a><span class="lineno"> 248</span> </div> <div class="line"><a name="l00249"></a><span class="lineno"> 249</span>  <span class="keywordflow">if</span>( mode == CCM_ENCRYPT )</div> <div class="line"><a name="l00250"></a><span class="lineno"> 250</span>  {</div> <div class="line"><a name="l00251"></a><span class="lineno"> 251</span>  memset( b, 0, 16 );</div> <div class="line"><a name="l00252"></a><span class="lineno"> 252</span>  memcpy( b, src, use_len );</div> <div class="line"><a name="l00253"></a><span class="lineno"> 253</span>  UPDATE_CBC_MAC;</div> <div class="line"><a name="l00254"></a><span class="lineno"> 254</span>  }</div> <div class="line"><a name="l00255"></a><span class="lineno"> 255</span> </div> <div class="line"><a name="l00256"></a><span class="lineno"> 256</span>  CTR_CRYPT( dst, src, use_len );</div> <div class="line"><a name="l00257"></a><span class="lineno"> 257</span> </div> <div class="line"><a name="l00258"></a><span class="lineno"> 258</span>  <span class="keywordflow">if</span>( mode == CCM_DECRYPT )</div> <div class="line"><a name="l00259"></a><span class="lineno"> 259</span>  {</div> <div class="line"><a name="l00260"></a><span class="lineno"> 260</span>  memset( b, 0, 16 );</div> <div class="line"><a name="l00261"></a><span class="lineno"> 261</span>  memcpy( b, dst, use_len );</div> <div class="line"><a name="l00262"></a><span class="lineno"> 262</span>  UPDATE_CBC_MAC;</div> <div class="line"><a name="l00263"></a><span class="lineno"> 263</span>  }</div> <div class="line"><a name="l00264"></a><span class="lineno"> 264</span> </div> <div class="line"><a name="l00265"></a><span class="lineno"> 265</span>  dst += use_len;</div> <div class="line"><a name="l00266"></a><span class="lineno"> 266</span>  src += use_len;</div> <div class="line"><a name="l00267"></a><span class="lineno"> 267</span>  len_left -= use_len;</div> <div class="line"><a name="l00268"></a><span class="lineno"> 268</span> </div> <div class="line"><a name="l00269"></a><span class="lineno"> 269</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00270"></a><span class="lineno"> 270</span> <span class="comment"> * Increment counter.</span></div> <div class="line"><a name="l00271"></a><span class="lineno"> 271</span> <span class="comment"> * No need to check for overflow thanks to the length check above.</span></div> <div class="line"><a name="l00272"></a><span class="lineno"> 272</span> <span class="comment"> */</span></div> <div class="line"><a name="l00273"></a><span class="lineno"> 273</span>  <span class="keywordflow">for</span>( i = 0; i < q; i++ )</div> <div class="line"><a name="l00274"></a><span class="lineno"> 274</span>  <span class="keywordflow">if</span>( ++ctr[15-i] != 0 )</div> <div class="line"><a name="l00275"></a><span class="lineno"> 275</span>  <span class="keywordflow">break</span>;</div> <div class="line"><a name="l00276"></a><span class="lineno"> 276</span>  }</div> <div class="line"><a name="l00277"></a><span class="lineno"> 277</span> </div> <div class="line"><a name="l00278"></a><span class="lineno"> 278</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00279"></a><span class="lineno"> 279</span> <span class="comment"> * Authentication: reset counter and crypt/mask internal tag</span></div> <div class="line"><a name="l00280"></a><span class="lineno"> 280</span> <span class="comment"> */</span></div> <div class="line"><a name="l00281"></a><span class="lineno"> 281</span>  <span class="keywordflow">for</span>( i = 0; i < q; i++ )</div> <div class="line"><a name="l00282"></a><span class="lineno"> 282</span>  ctr[15-i] = 0;</div> <div class="line"><a name="l00283"></a><span class="lineno"> 283</span> </div> <div class="line"><a name="l00284"></a><span class="lineno"> 284</span>  CTR_CRYPT( y, y, 16 );</div> <div class="line"><a name="l00285"></a><span class="lineno"> 285</span>  memcpy( tag, y, tag_len );</div> <div class="line"><a name="l00286"></a><span class="lineno"> 286</span> </div> <div class="line"><a name="l00287"></a><span class="lineno"> 287</span>  <span class="keywordflow">return</span>( 0 );</div> <div class="line"><a name="l00288"></a><span class="lineno"> 288</span> }</div> <div class="line"><a name="l00289"></a><span class="lineno"> 289</span> </div> <div class="line"><a name="l00290"></a><span class="lineno"> 290</span> <span class="comment">/*</span></div> <div class="line"><a name="l00291"></a><span class="lineno"> 291</span> <span class="comment"> * Authenticated encryption</span></div> <div class="line"><a name="l00292"></a><span class="lineno"> 292</span> <span class="comment"> */</span></div> <div class="line"><a name="l00293"></a><span class="lineno"> 293</span> <span class="keywordtype">int</span> <a class="code" href="ccm_8h.html#a4e501cc42e38bf5e6f9b51920213d4bd">ccm_encrypt_and_tag</a>( <a class="code" href="structccm__context.html">ccm_context</a> *ctx, <span class="keywordtype">size_t</span> length,</div> <div class="line"><a name="l00294"></a><span class="lineno"> 294</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *iv, <span class="keywordtype">size_t</span> iv_len,</div> <div class="line"><a name="l00295"></a><span class="lineno"> 295</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *add, <span class="keywordtype">size_t</span> add_len,</div> <div class="line"><a name="l00296"></a><span class="lineno"> 296</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *input, <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *output,</div> <div class="line"><a name="l00297"></a><span class="lineno"> 297</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *tag, <span class="keywordtype">size_t</span> tag_len )</div> <div class="line"><a name="l00298"></a><span class="lineno"> 298</span> {</div> <div class="line"><a name="l00299"></a><span class="lineno"> 299</span>  <span class="keywordflow">return</span>( ccm_auth_crypt( ctx, CCM_ENCRYPT, length, iv, iv_len,</div> <div class="line"><a name="l00300"></a><span class="lineno"> 300</span>  add, add_len, input, output, tag, tag_len ) );</div> <div class="line"><a name="l00301"></a><span class="lineno"> 301</span> }</div> <div class="line"><a name="l00302"></a><span class="lineno"> 302</span> </div> <div class="line"><a name="l00303"></a><span class="lineno"> 303</span> <span class="comment">/*</span></div> <div class="line"><a name="l00304"></a><span class="lineno"> 304</span> <span class="comment"> * Authenticated decryption</span></div> <div class="line"><a name="l00305"></a><span class="lineno"> 305</span> <span class="comment"> */</span></div> <div class="line"><a name="l00306"></a><span class="lineno"> 306</span> <span class="keywordtype">int</span> <a class="code" href="ccm_8h.html#a3cabbc9a5e7f023d25b1e9a7e7583506">ccm_auth_decrypt</a>( <a class="code" href="structccm__context.html">ccm_context</a> *ctx, <span class="keywordtype">size_t</span> length,</div> <div class="line"><a name="l00307"></a><span class="lineno"> 307</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *iv, <span class="keywordtype">size_t</span> iv_len,</div> <div class="line"><a name="l00308"></a><span class="lineno"> 308</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *add, <span class="keywordtype">size_t</span> add_len,</div> <div class="line"><a name="l00309"></a><span class="lineno"> 309</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *input, <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *output,</div> <div class="line"><a name="l00310"></a><span class="lineno"> 310</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *tag, <span class="keywordtype">size_t</span> tag_len )</div> <div class="line"><a name="l00311"></a><span class="lineno"> 311</span> {</div> <div class="line"><a name="l00312"></a><span class="lineno"> 312</span>  <span class="keywordtype">int</span> ret;</div> <div class="line"><a name="l00313"></a><span class="lineno"> 313</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> check_tag[16];</div> <div class="line"><a name="l00314"></a><span class="lineno"> 314</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> i;</div> <div class="line"><a name="l00315"></a><span class="lineno"> 315</span>  <span class="keywordtype">int</span> diff;</div> <div class="line"><a name="l00316"></a><span class="lineno"> 316</span> </div> <div class="line"><a name="l00317"></a><span class="lineno"> 317</span>  <span class="keywordflow">if</span>( ( ret = ccm_auth_crypt( ctx, CCM_DECRYPT, length,</div> <div class="line"><a name="l00318"></a><span class="lineno"> 318</span>  iv, iv_len, add, add_len,</div> <div class="line"><a name="l00319"></a><span class="lineno"> 319</span>  input, output, check_tag, tag_len ) ) != 0 )</div> <div class="line"><a name="l00320"></a><span class="lineno"> 320</span>  {</div> <div class="line"><a name="l00321"></a><span class="lineno"> 321</span>  <span class="keywordflow">return</span>( ret );</div> <div class="line"><a name="l00322"></a><span class="lineno"> 322</span>  }</div> <div class="line"><a name="l00323"></a><span class="lineno"> 323</span> </div> <div class="line"><a name="l00324"></a><span class="lineno"> 324</span>  <span class="comment">/* Check tag in "constant-time" */</span></div> <div class="line"><a name="l00325"></a><span class="lineno"> 325</span>  <span class="keywordflow">for</span>( diff = 0, i = 0; i < tag_len; i++ )</div> <div class="line"><a name="l00326"></a><span class="lineno"> 326</span>  diff |= tag[i] ^ check_tag[i];</div> <div class="line"><a name="l00327"></a><span class="lineno"> 327</span> </div> <div class="line"><a name="l00328"></a><span class="lineno"> 328</span>  <span class="keywordflow">if</span>( diff != 0 )</div> <div class="line"><a name="l00329"></a><span class="lineno"> 329</span>  {</div> <div class="line"><a name="l00330"></a><span class="lineno"> 330</span>  polarssl_zeroize( output, length );</div> <div class="line"><a name="l00331"></a><span class="lineno"> 331</span>  <span class="keywordflow">return</span>( <a class="code" href="ccm_8h.html#a51ba7afc7f66aa40e849813869c5d402">POLARSSL_ERR_CCM_AUTH_FAILED</a> );</div> <div class="line"><a name="l00332"></a><span class="lineno"> 332</span>  }</div> <div class="line"><a name="l00333"></a><span class="lineno"> 333</span> </div> <div class="line"><a name="l00334"></a><span class="lineno"> 334</span>  <span class="keywordflow">return</span>( 0 );</div> <div class="line"><a name="l00335"></a><span class="lineno"> 335</span> }</div> <div class="line"><a name="l00336"></a><span class="lineno"> 336</span> </div> <div class="line"><a name="l00337"></a><span class="lineno"> 337</span> </div> <div class="line"><a name="l00338"></a><span class="lineno"> 338</span> <span class="preprocessor">#if defined(POLARSSL_SELF_TEST) && defined(POLARSSL_AES_C)</span></div> <div class="line"><a name="l00339"></a><span class="lineno"> 339</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00340"></a><span class="lineno"> 340</span> <span class="preprocessor">#if defined(POLARSSL_PLATFORM_C)</span></div> <div class="line"><a name="l00341"></a><span class="lineno"> 341</span> <span class="preprocessor"></span><span class="preprocessor">#include "<a class="code" href="platform_8h.html">polarssl/platform.h</a>"</span></div> <div class="line"><a name="l00342"></a><span class="lineno"> 342</span> <span class="preprocessor">#else</span></div> <div class="line"><a name="l00343"></a><span class="lineno"> 343</span> <span class="preprocessor"></span><span class="preprocessor">#include <stdio.h></span></div> <div class="line"><a name="l00344"></a><span class="lineno"> 344</span> <span class="preprocessor">#define polarssl_printf printf</span></div> <div class="line"><a name="l00345"></a><span class="lineno"> 345</span> <span class="preprocessor"></span><span class="preprocessor">#endif</span></div> <div class="line"><a name="l00346"></a><span class="lineno"> 346</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00347"></a><span class="lineno"> 347</span> <span class="comment">/*</span></div> <div class="line"><a name="l00348"></a><span class="lineno"> 348</span> <span class="comment"> * Examples 1 to 3 from SP800-38C Appendix C</span></div> <div class="line"><a name="l00349"></a><span class="lineno"> 349</span> <span class="comment"> */</span></div> <div class="line"><a name="l00350"></a><span class="lineno"> 350</span> </div> <div class="line"><a name="l00351"></a><span class="lineno"> 351</span> <span class="preprocessor">#define NB_TESTS 3</span></div> <div class="line"><a name="l00352"></a><span class="lineno"> 352</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00353"></a><span class="lineno"> 353</span> <span class="comment">/*</span></div> <div class="line"><a name="l00354"></a><span class="lineno"> 354</span> <span class="comment"> * The data is the same for all tests, only the used length changes</span></div> <div class="line"><a name="l00355"></a><span class="lineno"> 355</span> <span class="comment"> */</span></div> <div class="line"><a name="l00356"></a><span class="lineno"> 356</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> key[] = {</div> <div class="line"><a name="l00357"></a><span class="lineno"> 357</span>  0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47,</div> <div class="line"><a name="l00358"></a><span class="lineno"> 358</span>  0x48, 0x49, 0x4a, 0x4b, 0x4c, 0x4d, 0x4e, 0x4f</div> <div class="line"><a name="l00359"></a><span class="lineno"> 359</span> };</div> <div class="line"><a name="l00360"></a><span class="lineno"> 360</span> </div> <div class="line"><a name="l00361"></a><span class="lineno"> 361</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> iv[] = {</div> <div class="line"><a name="l00362"></a><span class="lineno"> 362</span>  0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,</div> <div class="line"><a name="l00363"></a><span class="lineno"> 363</span>  0x18, 0x19, 0x1a, 0x1b</div> <div class="line"><a name="l00364"></a><span class="lineno"> 364</span> };</div> <div class="line"><a name="l00365"></a><span class="lineno"> 365</span> </div> <div class="line"><a name="l00366"></a><span class="lineno"> 366</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> ad[] = {</div> <div class="line"><a name="l00367"></a><span class="lineno"> 367</span>  0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,</div> <div class="line"><a name="l00368"></a><span class="lineno"> 368</span>  0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,</div> <div class="line"><a name="l00369"></a><span class="lineno"> 369</span>  0x10, 0x11, 0x12, 0x13</div> <div class="line"><a name="l00370"></a><span class="lineno"> 370</span> };</div> <div class="line"><a name="l00371"></a><span class="lineno"> 371</span> </div> <div class="line"><a name="l00372"></a><span class="lineno"> 372</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> msg[] = {</div> <div class="line"><a name="l00373"></a><span class="lineno"> 373</span>  0x20, 0x21, 0x22, 0x23, 0x24, 0x25, 0x26, 0x27,</div> <div class="line"><a name="l00374"></a><span class="lineno"> 374</span>  0x28, 0x29, 0x2a, 0x2b, 0x2c, 0x2d, 0x2e, 0x2f,</div> <div class="line"><a name="l00375"></a><span class="lineno"> 375</span>  0x30, 0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37,</div> <div class="line"><a name="l00376"></a><span class="lineno"> 376</span> };</div> <div class="line"><a name="l00377"></a><span class="lineno"> 377</span> </div> <div class="line"><a name="l00378"></a><span class="lineno"> 378</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">size_t</span> iv_len [NB_TESTS] = { 7, 8, 12 };</div> <div class="line"><a name="l00379"></a><span class="lineno"> 379</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">size_t</span> add_len[NB_TESTS] = { 8, 16, 20 };</div> <div class="line"><a name="l00380"></a><span class="lineno"> 380</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">size_t</span> msg_len[NB_TESTS] = { 4, 16, 24 };</div> <div class="line"><a name="l00381"></a><span class="lineno"> 381</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">size_t</span> tag_len[NB_TESTS] = { 4, 6, 8 };</div> <div class="line"><a name="l00382"></a><span class="lineno"> 382</span> </div> <div class="line"><a name="l00383"></a><span class="lineno"> 383</span> <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> res[NB_TESTS][32] = {</div> <div class="line"><a name="l00384"></a><span class="lineno"> 384</span>  { 0x71, 0x62, 0x01, 0x5b, 0x4d, 0xac, 0x25, 0x5d },</div> <div class="line"><a name="l00385"></a><span class="lineno"> 385</span>  { 0xd2, 0xa1, 0xf0, 0xe0, 0x51, 0xea, 0x5f, 0x62,</div> <div class="line"><a name="l00386"></a><span class="lineno"> 386</span>  0x08, 0x1a, 0x77, 0x92, 0x07, 0x3d, 0x59, 0x3d,</div> <div class="line"><a name="l00387"></a><span class="lineno"> 387</span>  0x1f, 0xc6, 0x4f, 0xbf, 0xac, 0xcd },</div> <div class="line"><a name="l00388"></a><span class="lineno"> 388</span>  { 0xe3, 0xb2, 0x01, 0xa9, 0xf5, 0xb7, 0x1a, 0x7a,</div> <div class="line"><a name="l00389"></a><span class="lineno"> 389</span>  0x9b, 0x1c, 0xea, 0xec, 0xcd, 0x97, 0xe7, 0x0b,</div> <div class="line"><a name="l00390"></a><span class="lineno"> 390</span>  0x61, 0x76, 0xaa, 0xd9, 0xa4, 0x42, 0x8a, 0xa5,</div> <div class="line"><a name="l00391"></a><span class="lineno"> 391</span>  0x48, 0x43, 0x92, 0xfb, 0xc1, 0xb0, 0x99, 0x51 }</div> <div class="line"><a name="l00392"></a><span class="lineno"> 392</span> };</div> <div class="line"><a name="l00393"></a><span class="lineno"> 393</span> </div> <div class="line"><a name="l00394"></a><span class="lineno"> 394</span> <span class="keywordtype">int</span> <a class="code" href="ccm_8h.html#aec9358c27a327452ef89a3d1e1392eee">ccm_self_test</a>( <span class="keywordtype">int</span> verbose )</div> <div class="line"><a name="l00395"></a><span class="lineno"> 395</span> {</div> <div class="line"><a name="l00396"></a><span class="lineno"> 396</span>  <a class="code" href="structccm__context.html">ccm_context</a> ctx;</div> <div class="line"><a name="l00397"></a><span class="lineno"> 397</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> out[32];</div> <div class="line"><a name="l00398"></a><span class="lineno"> 398</span>  <span class="keywordtype">size_t</span> i;</div> <div class="line"><a name="l00399"></a><span class="lineno"> 399</span>  <span class="keywordtype">int</span> ret;</div> <div class="line"><a name="l00400"></a><span class="lineno"> 400</span> </div> <div class="line"><a name="l00401"></a><span class="lineno"> 401</span>  <span class="keywordflow">if</span>( <a class="code" href="ccm_8h.html#aeea3832a1d2ee9eb264e3cd9013900d8">ccm_init</a>( &ctx, <a class="code" href="cipher_8h.html#a373f5d3a0a42c77ff4f5fe4fe7da0560a7f2185b07190a2ea88e864155bbec21d">POLARSSL_CIPHER_ID_AES</a>, key, 8 * <span class="keyword">sizeof</span> key ) != 0 )</div> <div class="line"><a name="l00402"></a><span class="lineno"> 402</span>  {</div> <div class="line"><a name="l00403"></a><span class="lineno"> 403</span>  <span class="keywordflow">if</span>( verbose != 0 )</div> <div class="line"><a name="l00404"></a><span class="lineno"> 404</span>  <a class="code" href="test__suite__aes_8cbc_8c.html#afc6a7362c0f0c9cfa8fc76b3281e2b37">polarssl_printf</a>( <span class="stringliteral">" CCM: setup failed"</span> );</div> <div class="line"><a name="l00405"></a><span class="lineno"> 405</span> </div> <div class="line"><a name="l00406"></a><span class="lineno"> 406</span>  <span class="keywordflow">return</span>( 1 );</div> <div class="line"><a name="l00407"></a><span class="lineno"> 407</span>  }</div> <div class="line"><a name="l00408"></a><span class="lineno"> 408</span> </div> <div class="line"><a name="l00409"></a><span class="lineno"> 409</span>  <span class="keywordflow">for</span>( i = 0; i < NB_TESTS; i++ )</div> <div class="line"><a name="l00410"></a><span class="lineno"> 410</span>  {</div> <div class="line"><a name="l00411"></a><span class="lineno"> 411</span>  <span class="keywordflow">if</span>( verbose != 0 )</div> <div class="line"><a name="l00412"></a><span class="lineno"> 412</span>  <a class="code" href="test__suite__aes_8cbc_8c.html#afc6a7362c0f0c9cfa8fc76b3281e2b37">polarssl_printf</a>( <span class="stringliteral">" CCM-AES #%u: "</span>, (<span class="keywordtype">unsigned</span> <span class="keywordtype">int</span>) i + 1 );</div> <div class="line"><a name="l00413"></a><span class="lineno"> 413</span> </div> <div class="line"><a name="l00414"></a><span class="lineno"> 414</span>  ret = <a class="code" href="ccm_8h.html#a4e501cc42e38bf5e6f9b51920213d4bd">ccm_encrypt_and_tag</a>( &ctx, msg_len[i],</div> <div class="line"><a name="l00415"></a><span class="lineno"> 415</span>  iv, iv_len[i], ad, add_len[i],</div> <div class="line"><a name="l00416"></a><span class="lineno"> 416</span>  msg, out,</div> <div class="line"><a name="l00417"></a><span class="lineno"> 417</span>  out + msg_len[i], tag_len[i] );</div> <div class="line"><a name="l00418"></a><span class="lineno"> 418</span> </div> <div class="line"><a name="l00419"></a><span class="lineno"> 419</span>  <span class="keywordflow">if</span>( ret != 0 ||</div> <div class="line"><a name="l00420"></a><span class="lineno"> 420</span>  memcmp( out, res[i], msg_len[i] + tag_len[i] ) != 0 )</div> <div class="line"><a name="l00421"></a><span class="lineno"> 421</span>  {</div> <div class="line"><a name="l00422"></a><span class="lineno"> 422</span>  <span class="keywordflow">if</span>( verbose != 0 )</div> <div class="line"><a name="l00423"></a><span class="lineno"> 423</span>  <a class="code" href="test__suite__aes_8cbc_8c.html#afc6a7362c0f0c9cfa8fc76b3281e2b37">polarssl_printf</a>( <span class="stringliteral">"failed\n"</span> );</div> <div class="line"><a name="l00424"></a><span class="lineno"> 424</span> </div> <div class="line"><a name="l00425"></a><span class="lineno"> 425</span>  <span class="keywordflow">return</span>( 1 );</div> <div class="line"><a name="l00426"></a><span class="lineno"> 426</span>  }</div> <div class="line"><a name="l00427"></a><span class="lineno"> 427</span> </div> <div class="line"><a name="l00428"></a><span class="lineno"> 428</span>  ret = <a class="code" href="ccm_8h.html#a3cabbc9a5e7f023d25b1e9a7e7583506">ccm_auth_decrypt</a>( &ctx, msg_len[i],</div> <div class="line"><a name="l00429"></a><span class="lineno"> 429</span>  iv, iv_len[i], ad, add_len[i],</div> <div class="line"><a name="l00430"></a><span class="lineno"> 430</span>  res[i], out,</div> <div class="line"><a name="l00431"></a><span class="lineno"> 431</span>  res[i] + msg_len[i], tag_len[i] );</div> <div class="line"><a name="l00432"></a><span class="lineno"> 432</span> </div> <div class="line"><a name="l00433"></a><span class="lineno"> 433</span>  <span class="keywordflow">if</span>( ret != 0 ||</div> <div class="line"><a name="l00434"></a><span class="lineno"> 434</span>  memcmp( out, msg, msg_len[i] ) != 0 )</div> <div class="line"><a name="l00435"></a><span class="lineno"> 435</span>  {</div> <div class="line"><a name="l00436"></a><span class="lineno"> 436</span>  <span class="keywordflow">if</span>( verbose != 0 )</div> <div class="line"><a name="l00437"></a><span class="lineno"> 437</span>  <a class="code" href="test__suite__aes_8cbc_8c.html#afc6a7362c0f0c9cfa8fc76b3281e2b37">polarssl_printf</a>( <span class="stringliteral">"failed\n"</span> );</div> <div class="line"><a name="l00438"></a><span class="lineno"> 438</span> </div> <div class="line"><a name="l00439"></a><span class="lineno"> 439</span>  <span class="keywordflow">return</span>( 1 );</div> <div class="line"><a name="l00440"></a><span class="lineno"> 440</span>  }</div> <div class="line"><a name="l00441"></a><span class="lineno"> 441</span> </div> <div class="line"><a name="l00442"></a><span class="lineno"> 442</span>  <span class="keywordflow">if</span>( verbose != 0 )</div> <div class="line"><a name="l00443"></a><span class="lineno"> 443</span>  <a class="code" href="test__suite__aes_8cbc_8c.html#afc6a7362c0f0c9cfa8fc76b3281e2b37">polarssl_printf</a>( <span class="stringliteral">"passed\n"</span> );</div> <div class="line"><a name="l00444"></a><span class="lineno"> 444</span>  }</div> <div class="line"><a name="l00445"></a><span class="lineno"> 445</span> </div> <div class="line"><a name="l00446"></a><span class="lineno"> 446</span>  <a class="code" href="ccm_8h.html#a884657cd0c69f0870e8ecc92dbdb9dd3">ccm_free</a>( &ctx );</div> <div class="line"><a name="l00447"></a><span class="lineno"> 447</span> </div> <div class="line"><a name="l00448"></a><span class="lineno"> 448</span>  <span class="keywordflow">if</span>( verbose != 0 )</div> <div class="line"><a name="l00449"></a><span class="lineno"> 449</span>  <a class="code" href="test__suite__aes_8cbc_8c.html#afc6a7362c0f0c9cfa8fc76b3281e2b37">polarssl_printf</a>( <span class="stringliteral">"\n"</span> );</div> <div class="line"><a name="l00450"></a><span class="lineno"> 450</span> </div> <div class="line"><a name="l00451"></a><span class="lineno"> 451</span>  <span class="keywordflow">return</span>( 0 );</div> <div class="line"><a name="l00452"></a><span class="lineno"> 452</span> }</div> <div class="line"><a name="l00453"></a><span class="lineno"> 453</span> </div> <div class="line"><a name="l00454"></a><span class="lineno"> 454</span> <span class="preprocessor">#endif </span><span class="comment">/* POLARSSL_SELF_TEST && POLARSSL_AES_C */</span><span class="preprocessor"></span></div> <div class="line"><a name="l00455"></a><span class="lineno"> 455</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00456"></a><span class="lineno"> 456</span> <span class="preprocessor">#endif </span><span class="comment">/* POLARSSL_CCM_C */</span><span class="preprocessor"></span></div> <div class="ttc" id="ccm_8h_html_a511bce4dba4b1934174a199e716ed37d"><div class="ttname"><a href="ccm_8h.html#a511bce4dba4b1934174a199e716ed37d">POLARSSL_ERR_CCM_BAD_INPUT</a></div><div class="ttdeci">#define POLARSSL_ERR_CCM_BAD_INPUT</div><div class="ttdoc">Bad input parameters to function. </div><div class="ttdef"><b>Definition:</b> <a href="ccm_8h_source.html#l00032">ccm.h:32</a></div></div> <div class="ttc" id="test__suite__aes_8cbc_8c_html_afc6a7362c0f0c9cfa8fc76b3281e2b37"><div class="ttname"><a href="test__suite__aes_8cbc_8c.html#afc6a7362c0f0c9cfa8fc76b3281e2b37">polarssl_printf</a></div><div class="ttdeci">#define polarssl_printf</div><div class="ttdef"><b>Definition:</b> <a href="test__suite__aes_8cbc_8c_source.html#l00309">test_suite_aes.cbc.c:309</a></div></div> <div class="ttc" id="cipher_8h_html_a6a719708dc3b2f0d0e7beadccf871f4f"><div class="ttname"><a href="cipher_8h.html#a6a719708dc3b2f0d0e7beadccf871f4f">cipher_init</a></div><div class="ttdeci">void cipher_init(cipher_context_t *ctx)</div><div class="ttdoc">Initialize a cipher_context (as NONE) </div></div> <div class="ttc" id="cipher_8h_html_af65d0bd9b5c3504fd010cf54955b179caaefd6ed34c1992d638129e161b28084a"><div class="ttname"><a href="cipher_8h.html#af65d0bd9b5c3504fd010cf54955b179caaefd6ed34c1992d638129e161b28084a">POLARSSL_MODE_ECB</a></div><div class="ttdef"><b>Definition:</b> <a href="cipher_8h_source.html#l00136">cipher.h:136</a></div></div> <div class="ttc" id="structcipher__info__t_html"><div class="ttname"><a href="structcipher__info__t.html">cipher_info_t</a></div><div class="ttdoc">Cipher information. </div><div class="ttdef"><b>Definition:</b> <a href="cipher_8h_source.html#l00226">cipher.h:226</a></div></div> <div class="ttc" id="config_8h_html"><div class="ttname"><a href="config_8h.html">config.h</a></div><div class="ttdoc">Configuration options (set of defines) </div></div> <div class="ttc" id="platform_8h_html"><div class="ttname"><a href="platform_8h.html">platform.h</a></div><div class="ttdoc">PolarSSL Platform abstraction layer. </div></div> <div class="ttc" id="ccm_8h_html_a3cabbc9a5e7f023d25b1e9a7e7583506"><div class="ttname"><a href="ccm_8h.html#a3cabbc9a5e7f023d25b1e9a7e7583506">ccm_auth_decrypt</a></div><div class="ttdeci">int ccm_auth_decrypt(ccm_context *ctx, size_t length, const unsigned char *iv, size_t iv_len, const unsigned char *add, size_t add_len, const unsigned char *input, unsigned char *output, const unsigned char *tag, size_t tag_len)</div><div class="ttdoc">CCM buffer authenticated decryption. </div></div> <div class="ttc" id="structccm__context_html"><div class="ttname"><a href="structccm__context.html">ccm_context</a></div><div class="ttdoc">CCM context structure. </div><div class="ttdef"><b>Definition:</b> <a href="ccm_8h_source.html#l00042">ccm.h:42</a></div></div> <div class="ttc" id="cipher_8h_html_a76a810650461f2062938ee9b82666b36ad8e41c0d381b23d7835dd322e511564f"><div class="ttname"><a href="cipher_8h.html#a76a810650461f2062938ee9b82666b36ad8e41c0d381b23d7835dd322e511564f">POLARSSL_ENCRYPT</a></div><div class="ttdef"><b>Definition:</b> <a href="cipher_8h_source.html#l00157">cipher.h:157</a></div></div> <div class="ttc" id="ccm_8h_html_aeea3832a1d2ee9eb264e3cd9013900d8"><div class="ttname"><a href="ccm_8h.html#aeea3832a1d2ee9eb264e3cd9013900d8">ccm_init</a></div><div class="ttdeci">int ccm_init(ccm_context *ctx, cipher_id_t cipher, const unsigned char *key, unsigned int keysize)</div><div class="ttdoc">CCM initialization (encryption and decryption) </div></div> <div class="ttc" id="ccm_8h_html_aec9358c27a327452ef89a3d1e1392eee"><div class="ttname"><a href="ccm_8h.html#aec9358c27a327452ef89a3d1e1392eee">ccm_self_test</a></div><div class="ttdeci">int ccm_self_test(int verbose)</div><div class="ttdoc">Checkup routine. </div></div> <div class="ttc" id="cipher_8h_html_a373f5d3a0a42c77ff4f5fe4fe7da0560a7f2185b07190a2ea88e864155bbec21d"><div class="ttname"><a href="cipher_8h.html#a373f5d3a0a42c77ff4f5fe4fe7da0560a7f2185b07190a2ea88e864155bbec21d">POLARSSL_CIPHER_ID_AES</a></div><div class="ttdef"><b>Definition:</b> <a href="cipher_8h_source.html#l00074">cipher.h:74</a></div></div> <div class="ttc" id="cipher_8h_html_a373f5d3a0a42c77ff4f5fe4fe7da0560"><div class="ttname"><a href="cipher_8h.html#a373f5d3a0a42c77ff4f5fe4fe7da0560">cipher_id_t</a></div><div class="ttdeci">cipher_id_t</div><div class="ttdef"><b>Definition:</b> <a href="cipher_8h_source.html#l00071">cipher.h:71</a></div></div> <div class="ttc" id="cipher_8h_html_af27f8e4cd1fab59615c3d73c69d136c8"><div class="ttname"><a href="cipher_8h.html#af27f8e4cd1fab59615c3d73c69d136c8">cipher_free</a></div><div class="ttdeci">void cipher_free(cipher_context_t *ctx)</div><div class="ttdoc">Free and clear the cipher-specific context of ctx. </div></div> <div class="ttc" id="cipher_8h_html_adc7c37e925193805884085ca87587f64"><div class="ttname"><a href="cipher_8h.html#adc7c37e925193805884085ca87587f64">cipher_init_ctx</a></div><div class="ttdeci">int cipher_init_ctx(cipher_context_t *ctx, const cipher_info_t *cipher_info)</div><div class="ttdoc">Initialises and fills the cipher context structure with the appropriate values. </div></div> <div class="ttc" id="cipher_8h_html_a77355bddf2d69f68d55e2bd2374e9257"><div class="ttname"><a href="cipher_8h.html#a77355bddf2d69f68d55e2bd2374e9257">cipher_setkey</a></div><div class="ttdeci">int cipher_setkey(cipher_context_t *ctx, const unsigned char *key, int key_length, const operation_t operation)</div><div class="ttdoc">Set the key to use with the given context. </div></div> <div class="ttc" id="ccm_8h_html_a884657cd0c69f0870e8ecc92dbdb9dd3"><div class="ttname"><a href="ccm_8h.html#a884657cd0c69f0870e8ecc92dbdb9dd3">ccm_free</a></div><div class="ttdeci">void ccm_free(ccm_context *ctx)</div><div class="ttdoc">Free a CCM context and underlying cipher sub-context. </div></div> <div class="ttc" id="ccm_8h_html_a4e501cc42e38bf5e6f9b51920213d4bd"><div class="ttname"><a href="ccm_8h.html#a4e501cc42e38bf5e6f9b51920213d4bd">ccm_encrypt_and_tag</a></div><div class="ttdeci">int ccm_encrypt_and_tag(ccm_context *ctx, size_t length, const unsigned char *iv, size_t iv_len, const unsigned char *add, size_t add_len, const unsigned char *input, unsigned char *output, unsigned char *tag, size_t tag_len)</div><div class="ttdoc">CCM buffer encryption. </div></div> <div class="ttc" id="structccm__context_html_a91e58dba6b94b59dd8fdce63bc2491fa"><div class="ttname"><a href="structccm__context.html#a91e58dba6b94b59dd8fdce63bc2491fa">ccm_context::cipher_ctx</a></div><div class="ttdeci">cipher_context_t cipher_ctx</div><div class="ttdef"><b>Definition:</b> <a href="ccm_8h_source.html#l00043">ccm.h:43</a></div></div> <div class="ttc" id="structcipher__info__t_html_a7e21795685c79613b5125ca608b0c63b"><div class="ttname"><a href="structcipher__info__t.html#a7e21795685c79613b5125ca608b0c63b">cipher_info_t::block_size</a></div><div class="ttdeci">unsigned int block_size</div><div class="ttdoc">block size, in bytes </div><div class="ttdef"><b>Definition:</b> <a href="cipher_8h_source.html#l00248">cipher.h:248</a></div></div> <div class="ttc" id="ccm_8h_html_a51ba7afc7f66aa40e849813869c5d402"><div class="ttname"><a href="ccm_8h.html#a51ba7afc7f66aa40e849813869c5d402">POLARSSL_ERR_CCM_AUTH_FAILED</a></div><div class="ttdeci">#define POLARSSL_ERR_CCM_AUTH_FAILED</div><div class="ttdoc">Authenticated decryption failed. </div><div class="ttdef"><b>Definition:</b> <a href="ccm_8h_source.html#l00033">ccm.h:33</a></div></div> <div class="ttc" id="cipher_8h_html_a68fd6a4ea2c236dc4abcad76d73d5cac"><div class="ttname"><a href="cipher_8h.html#a68fd6a4ea2c236dc4abcad76d73d5cac">cipher_info_from_values</a></div><div class="ttdeci">const cipher_info_t * cipher_info_from_values(const cipher_id_t cipher_id, int key_length, const cipher_mode_t mode)</div><div class="ttdoc">Returns the cipher information structure associated with the given cipher id, key size and mode...</div></div> <div class="ttc" id="ccm_8h_html"><div class="ttname"><a href="ccm_8h.html">ccm.h</a></div><div class="ttdoc">Counter with CBC-MAC (CCM) for 128-bit block ciphers. </div></div> </div><!-- fragment --></div><!-- contents --> <!-- start footer part --> <hr class="footer"/><address class="footer"><small> Generated on Thu Jul 31 2014 11:35:51 for PolarSSL v1.3.8 by  <a href="http://www.doxygen.org/index.html"> <img class="footer" src="doxygen.png" alt="doxygen"/> </a> 1.8.5 </small></address> </body> </html>