netwerk/srtp/src/crypto/rng/ctr_prng.c

Wed, 31 Dec 2014 06:09:35 +0100

author
Michael Schloh von Bennewitz <michael@schloh.com>
date
Wed, 31 Dec 2014 06:09:35 +0100
changeset 0
6474c204b198
permissions
-rw-r--r--

Cloned upstream origin tor-browser at tor-browser-31.3.0esr-4.5-1-build1
revision ID fc1c9ff7c1b2defdbc039f12214767608f46423f for hacking purpose.

michael@0 1 /*
michael@0 2 * ctr_prng.c
michael@0 3 *
michael@0 4 * counter mode based pseudorandom source
michael@0 5 *
michael@0 6 * David A. McGrew
michael@0 7 * Cisco Systems, Inc.
michael@0 8 */
michael@0 9 /*
michael@0 10 *
michael@0 11 * Copyright(c) 2001-2006 Cisco Systems, Inc.
michael@0 12 * All rights reserved.
michael@0 13 *
michael@0 14 * Redistribution and use in source and binary forms, with or without
michael@0 15 * modification, are permitted provided that the following conditions
michael@0 16 * are met:
michael@0 17 *
michael@0 18 * Redistributions of source code must retain the above copyright
michael@0 19 * notice, this list of conditions and the following disclaimer.
michael@0 20 *
michael@0 21 * Redistributions in binary form must reproduce the above
michael@0 22 * copyright notice, this list of conditions and the following
michael@0 23 * disclaimer in the documentation and/or other materials provided
michael@0 24 * with the distribution.
michael@0 25 *
michael@0 26 * Neither the name of the Cisco Systems, Inc. nor the names of its
michael@0 27 * contributors may be used to endorse or promote products derived
michael@0 28 * from this software without specific prior written permission.
michael@0 29 *
michael@0 30 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
michael@0 31 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
michael@0 32 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
michael@0 33 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
michael@0 34 * COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
michael@0 35 * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
michael@0 36 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
michael@0 37 * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
michael@0 38 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
michael@0 39 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
michael@0 40 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
michael@0 41 * OF THE POSSIBILITY OF SUCH DAMAGE.
michael@0 42 *
michael@0 43 */
michael@0 44
michael@0 45
michael@0 46 #include "prng.h"
michael@0 47
michael@0 48 /* single, global prng structure */
michael@0 49
michael@0 50 ctr_prng_t ctr_prng;
michael@0 51
michael@0 52 err_status_t
michael@0 53 ctr_prng_init(rand_source_func_t random_source) {
michael@0 54 uint8_t tmp_key[32];
michael@0 55 err_status_t status;
michael@0 56
michael@0 57 /* initialize output count to zero */
michael@0 58 ctr_prng.octet_count = 0;
michael@0 59
michael@0 60 /* set random source */
michael@0 61 ctr_prng.rand = random_source;
michael@0 62
michael@0 63 /* initialize secret key from random source */
michael@0 64 status = random_source(tmp_key, 32);
michael@0 65 if (status)
michael@0 66 return status;
michael@0 67
michael@0 68 /* initialize aes ctr context with random key */
michael@0 69 status = aes_icm_context_init(&ctr_prng.state, tmp_key, 30);
michael@0 70 if (status)
michael@0 71 return status;
michael@0 72
michael@0 73 return err_status_ok;
michael@0 74 }
michael@0 75
michael@0 76 err_status_t
michael@0 77 ctr_prng_get_octet_string(void *dest, uint32_t len) {
michael@0 78 err_status_t status;
michael@0 79
michael@0 80 /*
michael@0 81 * if we need to re-initialize the prng, do so now
michael@0 82 *
michael@0 83 * avoid 32-bit overflows by subtracting instead of adding
michael@0 84 */
michael@0 85 if (ctr_prng.octet_count > MAX_PRNG_OUT_LEN - len) {
michael@0 86 status = ctr_prng_init(ctr_prng.rand);
michael@0 87 if (status)
michael@0 88 return status;
michael@0 89 }
michael@0 90 ctr_prng.octet_count += len;
michael@0 91
michael@0 92 /*
michael@0 93 * write prng output
michael@0 94 */
michael@0 95 status = aes_icm_output(&ctr_prng.state, (uint8_t*)dest, len);
michael@0 96 if (status)
michael@0 97 return status;
michael@0 98
michael@0 99 return err_status_ok;
michael@0 100 }
michael@0 101
michael@0 102 err_status_t
michael@0 103 ctr_prng_deinit(void) {
michael@0 104
michael@0 105 /* nothing */
michael@0 106
michael@0 107 return err_status_ok;
michael@0 108 }

mercurial