|
Zephyr Project API 4.4.99
A Scalable Open Source RTOS
|
The AEAD ITS transform module API. More...
Go to the source code of this file.
Macros | |
| #define | SECURE_STORAGE_ITS_TRANSFORM_AEAD_TAG_SIZE |
| ITS transform AEAD tag size. | |
Functions | |
| psa_status_t | secure_storage_its_transform_aead_crypt (psa_key_usage_t operation, secure_storage_its_uid_t uid, const uint8_t nonce[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE], size_t add_data_len, const uint8_t *add_data, size_t input_len, const uint8_t *input, size_t output_size, uint8_t *output, size_t *output_len) |
| Encrypts or decrypts an ITS entry. | |
| void | secure_storage_its_transform_aead_get_scheme (psa_key_type_t *key_type, psa_algorithm_t *alg) |
| Returns the key type and algorithm to use for the AEAD operations. | |
| psa_status_t | secure_storage_its_transform_aead_get_key (secure_storage_its_uid_t uid, uint8_t key[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_KEY_SIZE]) |
| Returns the encryption key to use for an ITS entry's AEAD operations. | |
| psa_status_t | secure_storage_its_transform_aead_get_nonce (uint8_t nonce[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE]) |
| Generates a nonce for an AEAD operation. | |
The AEAD ITS transform module API.
The functions declared in this header allow customization of the AEAD implementation of the ITS transform module. They are not meant to be called directly other than by the AEAD ITS transform module. This header file may and must be included when providing a custom implementation of one or more of these functions (@kconfig_regex{CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_.*_CUSTOM}).
| #define SECURE_STORAGE_ITS_TRANSFORM_AEAD_TAG_SIZE |
ITS transform AEAD tag size.
| psa_status_t secure_storage_its_transform_aead_crypt | ( | psa_key_usage_t | operation, |
| secure_storage_its_uid_t | uid, | ||
| const uint8_t | nonce[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE], | ||
| size_t | add_data_len, | ||
| const uint8_t * | add_data, | ||
| size_t | input_len, | ||
| const uint8_t * | input, | ||
| size_t | output_size, | ||
| uint8_t * | output, | ||
| size_t * | output_len ) |
Encrypts or decrypts an ITS entry.
| [in] | operation | The operation to perform (PSA_KEY_USAGE_{ENCRYPT,DECRYPT}). |
| [in] | uid | The UID of the ITS entry to process. |
| [in] | nonce | The nonce to use in the AEAD operation. |
| [in] | add_data_len | The size of add_data in bytes. |
| [in] | add_data | The additional data to authenticate. |
| [in] | input_len | The size of input in bytes. |
| [in] | input | The plaintext (when encrypting) or the ciphertext (when decrypting). |
| [in] | output_size | The size of the output buffer in bytes. |
| [out] | output | The ciphertext (when encrypting) or the plaintext (when decrypting). |
| [out] | output_len | On success, the size of output in bytes. |
On encryption, output_len must be exactly input_len plus the tag size, i.e. CONFIG_SECURE_STORAGE_ITS_TRANSFORM_OUTPUT_OVERHEAD minus CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE; decryption must remove the same expansion.
| psa_status_t secure_storage_its_transform_aead_get_key | ( | secure_storage_its_uid_t | uid, |
| uint8_t | key[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_KEY_SIZE] ) |
Returns the encryption key to use for an ITS entry's AEAD operations.
| [in] | uid | The UID of the ITS entry for which the key is used. |
| [out] | key | The encryption key. |
| psa_status_t secure_storage_its_transform_aead_get_nonce | ( | uint8_t | nonce[static CONFIG_SECURE_STORAGE_ITS_TRANSFORM_AEAD_NONCE_SIZE] | ) |
Generates a nonce for an AEAD operation.
| [out] | nonce | The generated nonce. |
| void secure_storage_its_transform_aead_get_scheme | ( | psa_key_type_t * | key_type, |
| psa_algorithm_t * | alg ) |
Returns the key type and algorithm to use for the AEAD operations.
| [out] | key_type | The key type to use. |
| [out] | alg | The algorithm to use. |