kbkdf.c
Go to the documentation of this file.
1 /**
2  * @file kbkdf.c
3  * @brief SP 800-108 key derivation function
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2026 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @section Description
28  *
29  * KBKDF is a key derivation function defined by NIST SP 800-108 revision 1,
30  * section 4
31  *
32  * @author Oryx Embedded SARL (www.oryx-embedded.com)
33  * @version 2.6.6
34  **/
35 
36 //Switch to the appropriate trace level
37 #define TRACE_LEVEL CRYPTO_TRACE_LEVEL
38 
39 //Dependencies
40 #include "core/crypto.h"
41 #include "kdf/kbkdf.h"
42 #include "mac/mac_algorithms.h"
43 
44 //Check crypto library configuration
45 #if (KBKDF_SUPPORT == ENABLED)
46 
47 
48 /**
49  * @brief KBKDF key derivation function (counter mode with HMAC)
50  * @param[in] hashAlgo Underlying hash function
51  * @param[in] r Length of the binary encoding of the counter, in bits
52  * @param[in] ki Key-derivation key KI
53  * @param[in] kiLen Length of the key-derivation key, in bytes
54  * @param[in] fixedData Fixed input data
55  * @param[in] fixedDataLen Length of the fixed input data, in bytes
56  * @param[out] ko Derived keying material
57  * @param[in] koLen Length of the keying material to be generated, in bytes
58  * @return Error code
59  **/
60 
61 error_t kbkdfCounterHmac(const HashAlgo *hashAlgo, uint_t r, const uint8_t *ki,
62  size_t kiLen, const uint8_t *fixedData, size_t fixedDataLen, uint8_t *ko,
63  size_t koLen)
64 
65 {
66 #if (HMAC_SUPPORT == ENABLED)
67  size_t n;
68  uint32_t i;
69  uint8_t counter[4];
70  uint8_t digest[MAX_HASH_DIGEST_SIZE];
71 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
72  HmacContext *hmacContext;
73 #else
74  HmacContext hmacContext[1];
75 #endif
76 
77  //Check parameters
78  if(hashAlgo == NULL || ki == NULL || ko == NULL)
80 
81  //The fixed input data is optional
82  if(fixedData == NULL && fixedDataLen != 0)
84 
85  //The implementation only supports 8, 16, 24, and 32-bit counters
86  if(r != 8 && r != 16 && r != 24 && r != 32)
88 
89  //Determine how many blocks of keying material are needed
90  n = (koLen + hashAlgo->digestSize - 1) / hashAlgo->digestSize;
91 
92  //The number of blocks must not exceed the range of the counter
93  if(r < 32 && n >= (1U << r))
95 
96  //Determine the length, in bytes, of the binary encoding of the counter
97  r /= 8;
98 
99 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
100  //Allocate a memory buffer to hold the HMAC context
101  hmacContext = cryptoAllocMem(sizeof(HmacContext));
102  //Failed to allocate memory?
103  if(hmacContext == NULL)
104  return ERROR_OUT_OF_MEMORY;
105 #endif
106 
107  //Derive the keying material
108  for(i = 1; koLen > 0; i++)
109  {
110  //Number of octets in the current block
111  n = MIN(koLen, hashAlgo->digestSize);
112 
113  //Encode the counter as a 32-bit big-endian string
114  STORE32BE(i, counter);
115 
116  //Compute K(i) = PRF(KI, [i] || FixedInput)
117  hmacInit(hmacContext, hashAlgo, ki, kiLen);
118  hmacUpdate(hmacContext, counter + 4 - r, r);
119  hmacUpdate(hmacContext, fixedData, fixedDataLen);
120  hmacFinal(hmacContext, digest);
121 
122  //Save the resulting block
123  osMemcpy(ko, digest, n);
124 
125  //Point to the next block
126  ko += n;
127  koLen -= n;
128  }
129 
130 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
131  //Free previously allocated memory
132  cryptoFreeMem(hmacContext);
133 #endif
134 
135  //Successful processing
136  return NO_ERROR;
137 #else
138  //HMAC PRF is not implemented
139  return ERROR_NOT_IMPLEMENTED;
140 #endif
141 }
142 
143 
144 /**
145  * @brief KBKDF key derivation function (counter mode with CMAC)
146  * @param[in] cipherAlgo Underlying cipher algorithm
147  * @param[in] r Length of the binary encoding of the counter, in bits
148  * @param[in] ki Key-derivation key KI
149  * @param[in] kiLen Length of the key-derivation key, in bytes
150  * @param[in] fixedData Fixed input data
151  * @param[in] fixedDataLen Length of the fixed input data, in bytes
152  * @param[out] ko Derived keying material
153  * @param[in] koLen Length of the keying material to be generated, in bytes
154  * @return Error code
155  **/
156 
158  const uint8_t *ki, size_t kiLen, const uint8_t *fixedData,
159  size_t fixedDataLen, uint8_t *ko, size_t koLen)
160 {
161 #if (CMAC_SUPPORT == ENABLED)
162  error_t error;
163  size_t n;
164  uint32_t i;
165  uint8_t counter[4];
166 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
167  CmacContext *cmacContext;
168 #else
169  CmacContext cmacContext[1];
170 #endif
171 
172  //Check parameters
173  if(cipherAlgo == NULL || ki == NULL || ko == NULL)
175 
176  //The fixed input data is optional
177  if(fixedData == NULL && fixedDataLen != 0)
179 
180  //The implementation only supports 8, 16, 24, and 32-bit counters
181  if(r != 8 && r != 16 && r != 24 && r != 32)
183 
184  //Determine how many blocks of keying material are needed
185  n = (koLen + cipherAlgo->blockSize - 1) / cipherAlgo->blockSize;
186 
187  //The number of blocks must not exceed the range of the counter
188  if(r < 32 && n >= (1U << r))
190 
191  //Determine the length, in bytes, of the binary encoding of the counter
192  r /= 8;
193 
194 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
195  //Allocate a memory buffer to hold the CMAC context
196  cmacContext = cryptoAllocMem(sizeof(CmacContext));
197  //Failed to allocate memory?
198  if(cmacContext == NULL)
199  return ERROR_OUT_OF_MEMORY;
200 #endif
201 
202  //Initialize status code
203  error = NO_ERROR;
204 
205  //Derive the keying material
206  for(i = 1; koLen > 0 && !error; i++)
207  {
208  //Number of octets in the current block
209  n = MIN(koLen, cipherAlgo->blockSize);
210 
211  //Initialize CMAC calculation
212  error = cmacInit(cmacContext, cipherAlgo, ki, kiLen);
213 
214  //Check status code
215  if(!error)
216  {
217  //Encode the counter as a 32-bit big-endian string
218  STORE32BE(i, counter);
219 
220  //Compute K(i) = PRF(KI, [i] || FixedInput)
221  cmacUpdate(cmacContext, counter + 4 - r, r);
222  cmacUpdate(cmacContext, fixedData, fixedDataLen);
223 
224  //Finalize CMAC calculation
225  error = cmacFinal(cmacContext, ko, n);
226  }
227 
228  //Point to the next block
229  ko += n;
230  koLen -= n;
231  }
232 
233 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
234  //Free previously allocated memory
235  cryptoFreeMem(cmacContext);
236 #endif
237 
238  //Return status code
239  return error;
240 #else
241  //CMAC PRF is not implemented
242  return ERROR_NOT_IMPLEMENTED;
243 #endif
244 }
245 
246 
247 /**
248  * @brief KBKDF key derivation function (feedback mode with HMAC)
249  * @param[in] hashAlgo Underlying hash function
250  * @param[in] r Length of the binary encoding of the counter, in bits
251  * @param[in] ki Key-derivation key KI
252  * @param[in] kiLen Length of the key-derivation key, in bytes
253  * @param[in] iv Initialization vector
254  * @param[in] ivLen Length of the initialization vector, in bytes
255  * @param[in] fixedData Fixed input data
256  * @param[in] fixedDataLen Length of the fixed input data, in bytes
257  * @param[out] ko Derived keying material
258  * @param[in] koLen Length of the keying material to be generated, in bytes
259  * @return Error code
260  **/
261 
262 error_t kbkdfFeedbackHmac(const HashAlgo *hashAlgo, uint_t r, const uint8_t *ki,
263  size_t kiLen, const uint8_t *iv, size_t ivLen, const uint8_t *fixedData,
264  size_t fixedDataLen, uint8_t *ko, size_t koLen)
265 {
266 #if (HMAC_SUPPORT == ENABLED)
267  size_t n;
268  uint32_t i;
269  size_t prevLen;
270  const uint8_t *prev;
271  uint8_t counter[4];
272  uint8_t digest[MAX_HASH_DIGEST_SIZE];
273 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
274  HmacContext *hmacContext;
275 #else
276  HmacContext hmacContext[1];
277 #endif
278 
279  //Check parameters
280  if(hashAlgo == NULL || ki == NULL || ko == NULL)
282 
283  //The initialization vector is optional
284  if(iv == NULL && ivLen != 0)
286 
287  //The fixed input data is optional
288  if(fixedData == NULL && fixedDataLen != 0)
290 
291  //The implementation only supports 8, 16, 24, and 32-bit counters
292  if(r != 0 && r != 8 && r != 16 && r != 24 && r != 32)
294 
295  //Determine the length, in bytes, of the binary encoding of the counter
296  r /= 8;
297 
298 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
299  //Allocate a memory buffer to hold the HMAC context
300  hmacContext = cryptoAllocMem(sizeof(HmacContext));
301  //Failed to allocate memory?
302  if(hmacContext == NULL)
303  return ERROR_OUT_OF_MEMORY;
304 #endif
305 
306  //K(0) is the initialization vector
307  prev = iv;
308  prevLen = ivLen;
309 
310  //Derive the keying material
311  for(i = 1; koLen > 0; i++)
312  {
313  //Number of octets in the current block
314  n = MIN(koLen, hashAlgo->digestSize);
315 
316  //Encode the counter as a 32-bit big-endian string
317  STORE32BE(i, counter);
318 
319  //Compute K(i) = PRF(KI, K(i-1) || [i] || FixedInput)
320  hmacInit(hmacContext, hashAlgo, ki, kiLen);
321  hmacUpdate(hmacContext, prev, prevLen);
322  hmacUpdate(hmacContext, counter + 4 - r, r);
323  hmacUpdate(hmacContext, fixedData, fixedDataLen);
324  hmacFinal(hmacContext, digest);
325 
326  //Save the resulting block
327  osMemcpy(ko, digest, n);
328 
329  //K(i) becomes the feedback value for the next iteration
330  prev = digest;
331  prevLen = hashAlgo->digestSize;
332 
333  //Point to the next block
334  ko += n;
335  koLen -= n;
336  }
337 
338 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
339  //Free previously allocated memory
340  cryptoFreeMem(hmacContext);
341 #endif
342 
343  //Successful processing
344  return NO_ERROR;
345 #else
346  //HMAC PRF is not implemented
347  return ERROR_NOT_IMPLEMENTED;
348 #endif
349 }
350 
351 
352 /**
353  * @brief KBKDF key derivation function (feedback mode with CMAC)
354  * @param[in] cipherAlgo Underlying cipher algorithm
355  * @param[in] r Length of the binary encoding of the counter, in bits
356  * @param[in] ki Key-derivation key KI
357  * @param[in] kiLen Length of the key-derivation key, in bytes
358  * @param[in] iv Initialization vector
359  * @param[in] ivLen Length of the initialization vector, in bytes
360  * @param[in] fixedData Fixed input data
361  * @param[in] fixedDataLen Length of the fixed input data, in bytes
362  * @param[out] ko Derived keying material
363  * @param[in] koLen Length of the keying material to be generated, in bytes
364  * @return Error code
365  **/
366 
368  const uint8_t *ki, size_t kiLen, const uint8_t *iv, size_t ivLen,
369  const uint8_t *fixedData, size_t fixedDataLen, uint8_t *ko, size_t koLen)
370 {
371 #if (CMAC_SUPPORT == ENABLED)
372  error_t error;
373  size_t n;
374  uint32_t i;
375  size_t prevLen;
376  const uint8_t *prev;
377  uint8_t counter[4];
378 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
379  CmacContext *cmacContext;
380 #else
381  CmacContext cmacContext[1];
382 #endif
383 
384  //Check parameters
385  if(cipherAlgo == NULL || ki == NULL || ko == NULL)
387 
388  //The initialization vector is optional
389  if(iv == NULL && ivLen != 0)
391 
392  //The fixed input data is optional
393  if(fixedData == NULL && fixedDataLen != 0)
395 
396  //The implementation only supports 8, 16, 24, and 32-bit counters
397  if(r != 0 && r != 8 && r != 16 && r != 24 && r != 32)
399 
400  //Determine the length, in bytes, of the binary encoding of the counter
401  r /= 8;
402 
403 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
404  //Allocate a memory buffer to hold the CMAC context
405  cmacContext = cryptoAllocMem(sizeof(CmacContext));
406  //Failed to allocate memory?
407  if(cmacContext == NULL)
408  return ERROR_OUT_OF_MEMORY;
409 #endif
410 
411  //Initialize status code
412  error = NO_ERROR;
413 
414  //K(0) is the initialization vector
415  prev = iv;
416  prevLen = ivLen;
417 
418  //Derive the keying material
419  for(i = 1; koLen > 0 && !error; i++)
420  {
421  //Number of octets in the current block
422  n = MIN(koLen, cipherAlgo->blockSize);
423 
424  //Initialize CMAC calculation
425  error = cmacInit(cmacContext, cipherAlgo, ki, kiLen);
426 
427  //Check status code
428  if(!error)
429  {
430  //Encode the counter as a 32-bit big-endian string
431  STORE32BE(i, counter);
432 
433  //Compute K(i) = PRF(KI, K(i-1) || [i] || FixedInput)
434  cmacUpdate(cmacContext, prev, prevLen);
435  cmacUpdate(cmacContext, counter + 4 - r, r);
436  cmacUpdate(cmacContext, fixedData, fixedDataLen);
437 
438  //Finalize CMAC calculation
439  error = cmacFinal(cmacContext, ko, n);
440  }
441 
442  //K(i) becomes the feedback value for the next iteration
443  prev = ko;
444  prevLen = n;
445 
446  //Point to the next block
447  ko += n;
448  koLen -= n;
449  }
450 
451 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
452  //Free previously allocated memory
453  cryptoFreeMem(cmacContext);
454 #endif
455 
456  //Return status code
457  return error;
458 #else
459  //CMAC PRF is not implemented
460  return ERROR_NOT_IMPLEMENTED;
461 #endif
462 }
463 
464 
465 /**
466  * @brief KBKDF key derivation function (double-pipeline mode with HMAC)
467  * @param[in] hashAlgo Underlying hash function
468  * @param[in] r Length of the binary encoding of the counter, in bits
469  * @param[in] ki Key-derivation key KI
470  * @param[in] kiLen Length of the key-derivation key, in bytes
471  * @param[in] fixedData Fixed input data
472  * @param[in] fixedDataLen Length of the fixed input data, in bytes
473  * @param[out] ko Derived keying material
474  * @param[in] koLen Length of the keying material to be generated, in bytes
475  * @return Error code
476  **/
477 
479  const uint8_t *ki, size_t kiLen, const uint8_t *fixedData,
480  size_t fixedDataLen, uint8_t *ko, size_t koLen)
481 
482 {
483 #if (HMAC_SUPPORT == ENABLED)
484  size_t n;
485  uint32_t i;
486  size_t prevLen;
487  const uint8_t *prev;
488  uint8_t counter[4];
489  uint8_t a[MAX_HASH_DIGEST_SIZE];
490  uint8_t digest[MAX_HASH_DIGEST_SIZE];
491 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
492  HmacContext *hmacContext;
493 #else
494  HmacContext hmacContext[1];
495 #endif
496 
497  //Check parameters
498  if(hashAlgo == NULL || ki == NULL || ko == NULL)
500 
501  //The fixed input data is optional
502  if(fixedData == NULL && fixedDataLen != 0)
504 
505  //The implementation only supports 8, 16, 24, and 32-bit counters
506  if(r != 0 && r != 8 && r != 16 && r != 24 && r != 32)
508 
509  //Determine the length, in bytes, of the binary encoding of the counter
510  r /= 8;
511 
512 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
513  //Allocate a memory buffer to hold the HMAC context
514  hmacContext = cryptoAllocMem(sizeof(HmacContext));
515  //Failed to allocate memory?
516  if(hmacContext == NULL)
517  return ERROR_OUT_OF_MEMORY;
518 #endif
519 
520  //A(0) is the fixed input data
521  prev = fixedData;
522  prevLen = fixedDataLen;
523 
524  //Derive the keying material
525  for(i = 1; koLen > 0; i++)
526  {
527  //Number of octets in the current block
528  n = MIN(koLen, hashAlgo->digestSize);
529 
530  //Encode the counter as a 32-bit big-endian string
531  STORE32BE(i, counter);
532 
533  //Compute A(i) = PRF(KI, A(i-1))
534  hmacInit(hmacContext, hashAlgo, ki, kiLen);
535  hmacUpdate(hmacContext, prev, prevLen);
536  hmacFinal(hmacContext, a);
537 
538  //Compute K(i) = PRF(KI, A(i) || [i] || FixedInput)
539  hmacInit(hmacContext, hashAlgo, ki, kiLen);
540  hmacUpdate(hmacContext, a, hashAlgo->digestSize);
541  hmacUpdate(hmacContext, counter + 4 - r, r);
542  hmacUpdate(hmacContext, fixedData, fixedDataLen);
543  hmacFinal(hmacContext, digest);
544 
545  //Save the resulting block
546  osMemcpy(ko, digest, n);
547 
548  //A(i) is used in the next iteration
549  prev = a;
550  prevLen = hashAlgo->digestSize;
551 
552  //Point to the next block
553  ko += n;
554  koLen -= n;
555  }
556 
557 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
558  //Free previously allocated memory
559  cryptoFreeMem(hmacContext);
560 #endif
561 
562  //Successful processing
563  return NO_ERROR;
564 #else
565  //HMAC PRF is not implemented
566  return ERROR_NOT_IMPLEMENTED;
567 #endif
568 }
569 
570 
571 /**
572  * @brief KBKDF key derivation function (double-pipeline mode with CMAC)
573  * @param[in] cipherAlgo Underlying cipher algorithm
574  * @param[in] r Length of the binary encoding of the counter, in bits
575  * @param[in] ki Key-derivation key KI
576  * @param[in] kiLen Length of the key-derivation key, in bytes
577  * @param[in] fixedData Fixed input data
578  * @param[in] fixedDataLen Length of the fixed input data, in bytes
579  * @param[out] ko Derived keying material
580  * @param[in] koLen Length of the keying material to be generated, in bytes
581  * @return Error code
582  **/
583 
585  const uint8_t *ki, size_t kiLen, const uint8_t *fixedData,
586  size_t fixedDataLen, uint8_t *ko, size_t koLen)
587 {
588 #if (CMAC_SUPPORT == ENABLED)
589  error_t error;
590  size_t n;
591  uint32_t i;
592  size_t prevLen;
593  const uint8_t *prev;
594  uint8_t counter[4];
595  uint8_t a[MAX_CIPHER_BLOCK_SIZE];
596 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
597  CmacContext *cmacContext;
598 #else
599  CmacContext cmacContext[1];
600 #endif
601 
602  //Check parameters
603  if(cipherAlgo == NULL || ki == NULL || ko == NULL)
605 
606  //The fixed input data is optional
607  if(fixedData == NULL && fixedDataLen != 0)
609 
610  //The implementation only supports 8, 16, 24, and 32-bit counters
611  if(r != 0 && r != 8 && r != 16 && r != 24 && r != 32)
613 
614  //Determine the length, in bytes, of the binary encoding of the counter
615  r /= 8;
616 
617 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
618  //Allocate a memory buffer to hold the CMAC context
619  cmacContext = cryptoAllocMem(sizeof(CmacContext));
620  //Failed to allocate memory?
621  if(cmacContext == NULL)
622  return ERROR_OUT_OF_MEMORY;
623 #endif
624 
625  //Initialize status code
626  error = NO_ERROR;
627 
628  //A(0) is the fixed input data
629  prev = fixedData;
630  prevLen = fixedDataLen;
631 
632  //Derive the keying material
633  for(i = 1; koLen > 0 && !error; i++)
634  {
635  //Number of octets in the current block
636  n = MIN(koLen, cipherAlgo->blockSize);
637 
638  //Initialize CMAC calculation (first iteration pipeline)
639  error = cmacInit(cmacContext, cipherAlgo, ki, kiLen);
640 
641  //Check status code
642  if(!error)
643  {
644  //Compute A(i) = PRF(KI, A(i-1))
645  cmacUpdate(cmacContext, prev, prevLen);
646 
647  //Finalize CMAC calculation (first iteration pipeline)
648  error = cmacFinal(cmacContext, a, cipherAlgo->blockSize);
649  }
650 
651  //Check status code
652  if(!error)
653  {
654  //Initialize CMAC calculation (second iteration pipeline)
655  error = cmacInit(cmacContext, cipherAlgo, ki, kiLen);
656  }
657 
658  //Check status code
659  if(!error)
660  {
661  //Encode the counter as a 32-bit big-endian string
662  STORE32BE(i, counter);
663 
664  //Compute K(i) = PRF(KI, A(i) || [i] || FixedInput)
665  cmacUpdate(cmacContext, a, cipherAlgo->blockSize);
666  cmacUpdate(cmacContext, counter + 4 - r, r);
667  cmacUpdate(cmacContext, fixedData, fixedDataLen);
668 
669  //Finalize CMAC calculation (second iteration pipeline)
670  error = cmacFinal(cmacContext, ko, n);
671  }
672 
673  //A(i) is used in the next iteration
674  prev = a;
675  prevLen = cipherAlgo->blockSize;
676 
677  //Point to the next block
678  ko += n;
679  koLen -= n;
680  }
681 
682 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
683  //Free previously allocated memory
684  cryptoFreeMem(cmacContext);
685 #endif
686 
687  //Return status code
688  return error;
689 #else
690  //CMAC PRF is not implemented
691  return ERROR_NOT_IMPLEMENTED;
692 #endif
693 }
694 
695 
696 /**
697  * @brief KBKDF key derivation function (using KMAC)
698  * @param[in] strength Number of bits of security (128 for KMAC128 and
699  * 256 for KMAC256)
700  * @param[in] ki Key-derivation key KI
701  * @param[in] kiLen Length of the key-derivation key, in bytes
702  * @param[in] context Context-specific information
703  * @param[in] contextLen Length of the context, in bytes
704  * @param[in] label Customization string (optional parameter)
705  * @param[in] labelLen Length of the customization string, in bytes
706  * @param[out] ko Derived keying material
707  * @param[in] koLen Length of the keying material to be generated, in bytes
708  * @return Error code
709  **/
710 
711 error_t kbkdfKmac(uint_t strength, const uint8_t *ki, size_t kiLen,
712  const uint8_t *context, size_t contextLen, const char_t *label,
713  size_t labelLen, uint8_t *ko, size_t koLen)
714 {
715 #if (KMAC_SUPPORT == ENABLED)
716  //Compute KO = KMAC(KI, Context, L, Label)
717  return kmacCompute(strength, ki, kiLen, context, contextLen, label, labelLen,
718  ko, koLen);
719 #else
720  //KMAC PRF is not implemented
721  return ERROR_NOT_IMPLEMENTED;
722 #endif
723 }
724 
725 #endif
HMAC algorithm context.
Definition: hmac.h:59
error_t kbkdfKmac(uint_t strength, const uint8_t *ki, size_t kiLen, const uint8_t *context, size_t contextLen, const char_t *label, size_t labelLen, uint8_t *ko, size_t koLen)
KBKDF key derivation function (using KMAC)
Definition: kbkdf.c:711
uint8_t a
Definition: ndp.h:411
@ ERROR_NOT_IMPLEMENTED
Definition: error.h:66
size_t digestSize
Definition: crypto.h:1249
size_t blockSize
Definition: crypto.h:1289
@ ERROR_OUT_OF_MEMORY
Definition: error.h:63
error_t kbkdfCounterHmac(const HashAlgo *hashAlgo, uint_t r, const uint8_t *ki, size_t kiLen, const uint8_t *fixedData, size_t fixedDataLen, uint8_t *ko, size_t koLen)
KBKDF key derivation function (counter mode with HMAC)
Definition: kbkdf.c:61
error_t kmacCompute(uint_t strength, const void *key, size_t keyLen, const void *data, size_t dataLen, const char_t *custom, size_t customLen, uint8_t *mac, size_t macLen)
Compute KMAC message authentication code.
Definition: kmac.c:68
uint8_t r
Definition: ndp.h:346
#define MAX_CIPHER_BLOCK_SIZE
#define MAX_HASH_DIGEST_SIZE
@ ERROR_INVALID_PARAMETER
Invalid parameter.
Definition: error.h:47
error_t kbkdfDoublePipelineCmac(const CipherAlgo *cipherAlgo, uint_t r, const uint8_t *ki, size_t kiLen, const uint8_t *fixedData, size_t fixedDataLen, uint8_t *ko, size_t koLen)
KBKDF key derivation function (double-pipeline mode with CMAC)
Definition: kbkdf.c:584
#define osMemcpy(dest, src, length)
Definition: os_port.h:147
error_t
Error codes.
Definition: error.h:43
General definitions for cryptographic algorithms.
uint8_t iv[]
Definition: ike.h:1695
SP 800-108 key derivation function.
#define MIN(a, b)
Definition: os_port.h:63
error_t kbkdfFeedbackCmac(const CipherAlgo *cipherAlgo, uint_t r, const uint8_t *ki, size_t kiLen, const uint8_t *iv, size_t ivLen, const uint8_t *fixedData, size_t fixedDataLen, uint8_t *ko, size_t koLen)
KBKDF key derivation function (feedback mode with CMAC)
Definition: kbkdf.c:367
CMAC algorithm context.
Definition: cmac.h:54
__weak_func void hmacUpdate(HmacContext *context, const void *data, size_t length)
Update the HMAC context with a portion of the message being hashed.
Definition: hmac.c:201
char char_t
Definition: compiler_port.h:55
uint8_t n
__weak_func void hmacFinal(HmacContext *context, uint8_t *digest)
Finish the HMAC calculation.
Definition: hmac.c:218
#define cryptoFreeMem(p)
Definition: crypto.h:966
Common interface for encryption algorithms.
Definition: crypto.h:1285
error_t cmacInit(CmacContext *context, const CipherAlgo *cipher, const void *key, size_t keyLen)
Initialize CMAC calculation.
Definition: cmac.c:107
#define cryptoAllocMem(size)
Definition: crypto.h:961
void cmacUpdate(CmacContext *context, const void *data, size_t dataLen)
Update the CMAC context with a portion of the message being hashed.
Definition: cmac.c:191
Collection of MAC algorithms.
Common interface for hash algorithms.
Definition: crypto.h:1243
error_t kbkdfCounterCmac(const CipherAlgo *cipherAlgo, uint_t r, const uint8_t *ki, size_t kiLen, const uint8_t *fixedData, size_t fixedDataLen, uint8_t *ko, size_t koLen)
KBKDF key derivation function (counter mode with CMAC)
Definition: kbkdf.c:157
unsigned int uint_t
Definition: compiler_port.h:57
__weak_func error_t hmacInit(HmacContext *context, const HashAlgo *hash, const void *key, size_t keyLen)
Initialize HMAC calculation.
Definition: hmac.c:140
error_t kbkdfFeedbackHmac(const HashAlgo *hashAlgo, uint_t r, const uint8_t *ki, size_t kiLen, const uint8_t *iv, size_t ivLen, const uint8_t *fixedData, size_t fixedDataLen, uint8_t *ko, size_t koLen)
KBKDF key derivation function (feedback mode with HMAC)
Definition: kbkdf.c:262
error_t cmacFinal(CmacContext *context, uint8_t *mac, size_t macLen)
Finish the CMAC calculation.
Definition: cmac.c:237
#define STORE32BE(a, p)
Definition: cpu_endian.h:286
@ NO_ERROR
Success.
Definition: error.h:44
error_t kbkdfDoublePipelineHmac(const HashAlgo *hashAlgo, uint_t r, const uint8_t *ki, size_t kiLen, const uint8_t *fixedData, size_t fixedDataLen, uint8_t *ko, size_t koLen)
KBKDF key derivation function (double-pipeline mode with HMAC)
Definition: kbkdf.c:478