ReactOS 0.4.17-dev-1005-g171e1de
aescmac.c
Go to the documentation of this file.
1//
2// aescmac.c Implementation of the AES-CMAC block cipher mode
3//
4// Copyright (c) Microsoft Corporation. Licensed under the MIT license.
5//
6
7#include "precomp.h"
8
17 NULL,
18 0,
19};
20
22
23VOID
27{
28 SIZE_T carry = 0;
29 SIZE_T tmp;
30 int i;
31
32 for( i=15; i>=0; i-- )
33 {
34 tmp = buf[i];
35 buf[i] = ((tmp << 1) | carry) & 0xff;
36 carry = tmp >> 7;
37 }
38
39 buf[15] ^= (0 - carry) & 0x87; // This is the R_128 value from SP 800-38B 5.3
40}
41
48{
49 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
51
52 scError = SymCryptAesExpandKey( &pExpandedKey->aesKey, pbKey, cbKey );
53 if( scError != SYMCRYPT_NO_ERROR )
54 {
55 goto cleanup;
56 }
57
58 SymCryptWipeKnownSize( buf, sizeof( buf ) );
59
61
63 memcpy( &pExpandedKey->K1, buf, sizeof( buf ) );
65 memcpy( &pExpandedKey->K2, buf, sizeof( buf ) );
66
67 SymCryptWipeKnownSize( buf, sizeof( buf ) );
68
70
72
73 return scError;
74}
75
76
77VOID
82{
84 SymCryptAesKeyCopy( &pSrc->aesKey, &pDst->aesKey );
85 memcpy( pDst->K1, pSrc->K1, sizeof( pDst->K1 ) );
86 memcpy( pDst->K2, pSrc->K2, sizeof( pDst->K2 ) );
87 SYMCRYPT_SET_MAGIC( pDst );
88}
89
90
91VOID
98{
100
104
105 SymCryptWipeKnownSize( &state, sizeof( state ) );
106}
107
108
109VOID
115{
116 SYMCRYPT_CHECK_MAGIC( pSrc );
117 *pDst = *pSrc;
118
119 if( pExpandedKey == NULL )
120 {
121 SYMCRYPT_CHECK_MAGIC( pSrc->pKey );
122 pDst->pKey = pSrc->pKey;
123 }
124 else
125 {
127 pDst->pKey = pExpandedKey;
128 }
129
130 SYMCRYPT_SET_MAGIC( pDst );
131}
132
133VOID
138{
140
141 pState->bytesInBuf = 0;
142 SymCryptWipeKnownSize( pState->chain, sizeof( pState->chain ) );
143 pState->pKey = pExpandedKey;
144
146}
147
148VOID
153 SIZE_T cbData )
154{
155
157
158 if( pState->bytesInBuf != 0 )
159 {
160 SIZE_T freeInBuf = SYMCRYPT_AES_BLOCK_SIZE - pState->bytesInBuf;
162
163 if( cbData <= freeInBuf )
164 {
165 // Do nothing.
166 // the data will be copied into the buf at the end of this function
167 //
168 }
169 else
170 {
171 memcpy( &pState->buf[pState->bytesInBuf], pbData, freeInBuf );
172 pbData += freeInBuf;
173 cbData -= freeInBuf;
174 SymCryptAesCbcMac( &pState->pKey->aesKey, &pState->chain[0], &pState->buf[0], SYMCRYPT_AES_BLOCK_SIZE );
175 pState->bytesInBuf = 0;
176 }
177 }
178
179 //
180 // At this point, either pState->bytesInBuf == 0, or it is !=0 but cbData is small enough that all the
181 // data will still fit in the buffer without further processing.
182 //
183
185 {
186 SIZE_T bytesToDo = (cbData-1) & ~(SIZE_T)(SYMCRYPT_AES_BLOCK_SIZE - 1);
187 SymCryptAesCbcMac( &pState->pKey->aesKey, &pState->chain[0], pbData, bytesToDo );
188 pbData += bytesToDo;
189 cbData -= bytesToDo;
190 }
191
192 if( cbData > 0 )
193 {
194 memcpy( &pState->buf[pState->bytesInBuf], pbData, cbData );
195 pState->bytesInBuf += cbData;
196 }
197}
198
199
200VOID
205{
207
208 if( pState->bytesInBuf < SYMCRYPT_AES_BLOCK_SIZE )
209 {
210 SymCryptWipe( &pState->buf[pState->bytesInBuf + 1], SYMCRYPT_AES_BLOCK_SIZE - pState->bytesInBuf - 1 );
211 pState->buf[pState->bytesInBuf] = 0x80;
212 SymCryptXorBytes( &pState->buf[0], &pState->pKey->K2[0], &pState->buf[0], SYMCRYPT_AES_BLOCK_SIZE );
213 }
214 else
215 {
216 SymCryptXorBytes( &pState->buf[0], &pState->pKey->K1[0], &pState->buf[0], SYMCRYPT_AES_BLOCK_SIZE );
217 }
218
219 SymCryptAesCbcMac( &pState->pKey->aesKey, &pState->chain[0], &pState->buf[0], SYMCRYPT_AES_BLOCK_SIZE );
221
222 //
223 // Put the state back in the original starting state,
224 // and wipe any traces of the data.
225 //
226 pState->bytesInBuf = 0;
227 SymCryptWipeKnownSize( pState->chain, sizeof( pState->chain ) );
228 SymCryptWipeKnownSize( pState->buf, sizeof( pState->buf ) );
229}
230
231
232
234 0x0a, 0x54, 0xa6, 0xa4, 0x25, 0xd4, 0x84, 0x38, 0xc3, 0xf8, 0xbb, 0xe0, 0x9b, 0xf9, 0x44, 0xcc,
235};
236
237
238VOID
241{
244
247
248 SymCryptInjectError( res, sizeof( res ) );
249 if( memcmp( res, aesCmacKat, sizeof( res ) ) != 0 )
250 {
251 SymCryptFatal( 'hsh5' );
252 }
253
254 //
255 // Normally we would wipe the expanded key structure here,
256 // but as this is a selftest with known data this is not needed.
257 //
258}
VOID SYMCRYPT_CALL SymCryptCmacMunge(_Inout_updates_bytes_(SYMCRYPT_AES_BLOCK_SIZE) BYTE buf[SYMCRYPT_AES_BLOCK_SIZE])
Definition: aescmac.c:25
VOID SYMCRYPT_CALL SymCryptAesCmacInit(_Out_ PSYMCRYPT_AES_CMAC_STATE pState, _In_ PCSYMCRYPT_AES_CMAC_EXPANDED_KEY pExpandedKey)
Definition: aescmac.c:135
VOID SYMCRYPT_CALL SymCryptAesCmac(_In_ PSYMCRYPT_AES_CMAC_EXPANDED_KEY pExpandedKey, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_AES_CMAC_RESULT_SIZE) PBYTE pbResult)
Definition: aescmac.c:93
VOID SYMCRYPT_CALL SymCryptAesCmacAppend(_Inout_ PSYMCRYPT_AES_CMAC_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: aescmac.c:150
static const BYTE aesCmacKat[SYMCRYPT_AES_CMAC_RESULT_SIZE]
Definition: aescmac.c:233
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesCmacExpandKey(_Out_ PSYMCRYPT_AES_CMAC_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
Definition: aescmac.c:44
VOID SYMCRYPT_CALL SymCryptAesCmacSelftest(void)
Definition: aescmac.c:240
VOID SYMCRYPT_CALL SymCryptAesCmacResult(_Inout_ PSYMCRYPT_AES_CMAC_STATE pState, _Out_writes_(SYMCRYPT_AES_CMAC_RESULT_SIZE) PBYTE pbResult)
Definition: aescmac.c:202
const SYMCRYPT_MAC SymCryptAesCmacAlgorithm_fast
Definition: aescmac.c:9
const PCSYMCRYPT_MAC SymCryptAesCmacAlgorithm
Definition: aescmac.c:21
VOID SYMCRYPT_CALL SymCryptAesCmacStateCopy(_In_ PCSYMCRYPT_AES_CMAC_STATE pSrc, _In_opt_ PCSYMCRYPT_AES_CMAC_EXPANDED_KEY pExpandedKey, _Out_ PSYMCRYPT_AES_CMAC_STATE pDst)
Definition: aescmac.c:111
VOID SYMCRYPT_CALL SymCryptAesCmacKeyCopy(_In_ PCSYMCRYPT_AES_CMAC_EXPANDED_KEY pSrc, _Out_ PSYMCRYPT_AES_CMAC_EXPANDED_KEY pDst)
Definition: aescmac.c:79
static int state
Definition: maze.c:121
#define NULL
Definition: types.h:112
static void cleanup(void)
Definition: main.c:1335
_ACRTIMP int __cdecl memcmp(const void *, const void *, size_t)
Definition: string.c:2807
GLuint res
Definition: glext.h:9613
GLenum GLuint GLenum GLsizei const GLchar * buf
Definition: glext.h:7751
GLsizei GLenum const GLvoid GLsizei GLenum GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLint GLint GLint GLshort GLshort GLshort GLubyte GLubyte GLubyte GLuint GLuint GLuint GLushort GLushort GLushort GLbyte GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLfloat GLint GLint GLint GLint GLshort GLshort GLshort GLshort GLubyte GLubyte GLubyte GLubyte GLuint GLuint GLuint GLuint GLushort GLushort GLushort GLushort GLboolean const GLdouble const GLfloat const GLint const GLshort const GLbyte const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLdouble const GLfloat const GLfloat const GLint const GLint const GLshort const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort GLenum GLenum GLenum GLfloat GLenum GLint GLenum GLenum GLenum GLfloat GLenum GLenum GLint GLenum GLfloat GLenum GLint GLint GLushort GLenum GLenum GLfloat GLenum GLenum GLint GLfloat const GLubyte GLenum GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLint GLint GLsizei GLsizei GLint GLenum GLenum const GLvoid GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLenum const GLdouble GLenum GLenum const GLfloat GLenum GLenum const GLint GLsizei GLuint GLfloat GLuint GLbitfield GLfloat GLint GLuint GLboolean GLenum GLfloat GLenum GLbitfield GLenum GLfloat GLfloat GLint GLint const GLfloat GLenum GLfloat GLfloat GLint GLint GLfloat GLfloat GLint GLint const GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat const GLdouble const GLfloat const GLdouble const GLfloat GLint i
Definition: glfuncs.h:248
#define memcpy(s1, s2, n)
Definition: mkisofs.h:878
#define _In_reads_(s)
Definition: no_sal2.h:168
#define _Inout_
Definition: no_sal2.h:162
#define _Out_writes_(s)
Definition: no_sal2.h:176
#define _Out_
Definition: no_sal2.h:160
#define _In_
Definition: no_sal2.h:158
#define _In_opt_
Definition: no_sal2.h:212
#define _Inout_updates_bytes_(s)
Definition: no_sal2.h:184
BYTE * PBYTE
Definition: pedump.c:66
VOID SYMCRYPT_CALL SymCryptInjectError(PBYTE pbData, SIZE_T cbData)
const BYTE SymCryptTestKey32[32]
Definition: selftest.c:10
const BYTE SymCryptTestMsg3[3]
Definition: selftest.c:8
static const BYTE pbResult[]
#define SYMCRYPT_ASSERT(_x)
Definition: symcrypt.h:10807
FORCEINLINE VOID SYMCRYPT_CALL SymCryptWipeKnownSize(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
VOID SYMCRYPT_CALL SymCryptWipe(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
Definition: libmain.c:137
_Analysis_noreturn_ VOID SYMCRYPT_CALL SymCryptFatal(UINT32 fatalCode)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKey(_Out_ PSYMCRYPT_AES_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
Definition: aes-key.c:219
VOID SYMCRYPT_CALL SymCryptAesEncrypt(_In_ PCSYMCRYPT_AES_EXPANDED_KEY pExpandedKey, _In_reads_(SYMCRYPT_AES_BLOCK_SIZE) PCBYTE pbSrc, _Out_writes_(SYMCRYPT_AES_BLOCK_SIZE) PBYTE pbDst)
Definition: aes-default.c:95
#define SYMCRYPT_AES_CMAC_RESULT_SIZE
Definition: symcrypt.h:3441
VOID SYMCRYPT_CALL SymCryptXorBytes(_In_reads_(cbBytes) PCBYTE pbSrc1, _In_reads_(cbBytes) PCBYTE pbSrc2, _Out_writes_(cbBytes) PBYTE pbResult, SIZE_T cbBytes)
Definition: libmain.c:236
#define SYMCRYPT_AES_BLOCK_SIZE
Definition: symcrypt.h:4255
VOID SYMCRYPT_CALL SymCryptAesCbcMac(_In_ PCSYMCRYPT_AES_EXPANDED_KEY pExpandedKey, _Inout_updates_(SYMCRYPT_AES_BLOCK_SIZE) PBYTE pbChainingValue, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: aes-default.c:317
VOID SYMCRYPT_CALL SymCryptAesKeyCopy(_In_ PCSYMCRYPT_AES_EXPANDED_KEY pSrc, _Out_ PSYMCRYPT_AES_EXPANDED_KEY pDst)
Definition: aes-key.c:240
SYMCRYPT_ERROR
Definition: symcrypt.h:227
#define SYMCRYPT_ALIGN
#define SYMCRYPT_CALL
const SYMCRYPT_AES_CMAC_EXPANDED_KEY * PCSYMCRYPT_AES_CMAC_EXPANDED_KEY
PCBYTE pbKey
SYMCRYPT_MAGIC_FIELD * PSYMCRYPT_AES_CMAC_STATE
PCBYTE SIZE_T cbKey
PCBYTE PBYTE SIZE_T cbData
#define SYMCRYPT_SET_MAGIC(p)
const SYMCRYPT_AES_CMAC_STATE * PCSYMCRYPT_AES_CMAC_STATE
SYMCRYPT_MAGIC_FIELD * PSYMCRYPT_AES_CMAC_EXPANDED_KEY
PSYMCRYPT_COMMON_HASH_STATE pState
const BYTE * PCBYTE
SYMCRYPT_MAGIC_FIELD SYMCRYPT_AES_CMAC_STATE
SYMCRYPT_MAGIC_FIELD SYMCRYPT_AES_CMAC_EXPANDED_KEY
PCBYTE pbData
#define SYMCRYPT_CHECK_MAGIC(p)
PCVOID pExpandedKey
ULONG_PTR SIZE_T
Definition: typedefs.h:80
unsigned char BYTE
Definition: xxhash.c:193