Zephyr Project API 4.4.99
A Scalable Open Source RTOS
Loading...
Searching...
No Matches
aead.h File Reference

The AEAD ITS transform module API. More...

#include <zephyr/secure_storage/its/common.h>
#include <psa/crypto_types.h>

Go to the source code of this file.

Macros

#define SECURE_STORAGE_ITS_TRANSFORM_AEAD_TAG_SIZE
 ITS transform AEAD tag size.

Functions

psa_status_t secure_storage_its_transform_aead_crypt (psa_key_usage_t operation, secure_storage_its_uid_t uid, const uint8_t nonce[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE], size_t add_data_len, const uint8_t *add_data, size_t input_len, const uint8_t *input, size_t output_size, uint8_t *output, size_t *output_len)
 Encrypts or decrypts an ITS entry.
void secure_storage_its_transform_aead_get_scheme (psa_key_type_t *key_type, psa_algorithm_t *alg)
 Returns the key type and algorithm to use for the AEAD operations.
psa_status_t secure_storage_its_transform_aead_get_key (secure_storage_its_uid_t uid, uint8_t key[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_KEY_SIZE])
 Returns the encryption key to use for an ITS entry's AEAD operations.
psa_status_t secure_storage_its_transform_aead_get_nonce (uint8_t nonce[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE])
 Generates a nonce for an AEAD operation.

Detailed Description

The AEAD ITS transform module API.

The functions declared in this header allow customization of the AEAD implementation of the ITS transform module. They are not meant to be called directly other than by the AEAD ITS transform module. This header file may and must be included when providing a custom implementation of one or more of these functions (@kconfig_regex{CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_.*_CUSTOM}).

Macro Definition Documentation

◆ SECURE_STORAGE_ITS_TRANSFORM_AEAD_TAG_SIZE

#define SECURE_STORAGE_ITS_TRANSFORM_AEAD_TAG_SIZE
Value:
(CONFIG_SECURE_STORAGE_ITS_TRANSFORM_OUTPUT_OVERHEAD \
- CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE)

ITS transform AEAD tag size.

Function Documentation

◆ secure_storage_its_transform_aead_crypt()

psa_status_t secure_storage_its_transform_aead_crypt ( psa_key_usage_t operation,
secure_storage_its_uid_t uid,
const uint8_t nonce[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE],
size_t add_data_len,
const uint8_t * add_data,
size_t input_len,
const uint8_t * input,
size_t output_size,
uint8_t * output,
size_t * output_len )

Encrypts or decrypts an ITS entry.

Parameters
[in]operationThe operation to perform (PSA_KEY_USAGE_{ENCRYPT,DECRYPT}).
[in]uidThe UID of the ITS entry to process.
[in]nonceThe nonce to use in the AEAD operation.
[in]add_data_lenThe size of add_data in bytes.
[in]add_dataThe additional data to authenticate.
[in]input_lenThe size of input in bytes.
[in]inputThe plaintext (when encrypting) or the ciphertext (when decrypting).
[in]output_sizeThe size of the output buffer in bytes.
[out]outputThe ciphertext (when encrypting) or the plaintext (when decrypting).
[out]output_lenOn success, the size of output in bytes.

On encryption, output_len must be exactly input_len plus the tag size, i.e. CONFIG_SECURE_STORAGE_ITS_TRANSFORM_OUTPUT_OVERHEAD minus CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE; decryption must remove the same expansion.

Returns
PSA_SUCCESS on success, anything else on failure.

◆ secure_storage_its_transform_aead_get_key()

psa_status_t secure_storage_its_transform_aead_get_key ( secure_storage_its_uid_t uid,
uint8_t key[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_KEY_SIZE] )

Returns the encryption key to use for an ITS entry's AEAD operations.

Parameters
[in]uidThe UID of the ITS entry for which the key is used.
[out]keyThe encryption key.
Returns
PSA_SUCCESS on success, anything else on failure.

◆ secure_storage_its_transform_aead_get_nonce()

psa_status_t secure_storage_its_transform_aead_get_nonce ( uint8_t nonce[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE])

Generates a nonce for an AEAD operation.

Parameters
[out]nonceThe generated nonce.
Returns
PSA_SUCCESS on success, anything else on failure.

◆ secure_storage_its_transform_aead_get_scheme()

void secure_storage_its_transform_aead_get_scheme ( psa_key_type_t * key_type,
psa_algorithm_t * alg )

Returns the key type and algorithm to use for the AEAD operations.

Parameters
[out]key_typeThe key type to use.
[out]algThe algorithm to use.