Dmitry Shmidt | 8d520ff | 2011-05-09 14:06:53 -0700 | [diff] [blame] | 1 | /* |
Dmitry Shmidt | fe31a9a | 2016-11-09 13:43:31 -0800 | [diff] [blame^] | 2 | * AES-128 CTR |
Dmitry Shmidt | 8d520ff | 2011-05-09 14:06:53 -0700 | [diff] [blame] | 3 | * |
| 4 | * Copyright (c) 2003-2007, Jouni Malinen <j@w1.fi> |
| 5 | * |
Dmitry Shmidt | c5ec7f5 | 2012-03-06 16:33:24 -0800 | [diff] [blame] | 6 | * This software may be distributed under the terms of the BSD license. |
| 7 | * See README for more details. |
Dmitry Shmidt | 8d520ff | 2011-05-09 14:06:53 -0700 | [diff] [blame] | 8 | */ |
| 9 | |
| 10 | #include "includes.h" |
| 11 | |
| 12 | #include "common.h" |
| 13 | #include "aes.h" |
| 14 | #include "aes_wrap.h" |
| 15 | |
| 16 | /** |
Dmitry Shmidt | fe31a9a | 2016-11-09 13:43:31 -0800 | [diff] [blame^] | 17 | * aes_128_ctr_encrypt - AES-128 CTR mode encryption |
| 18 | * @key: Key for encryption (16 bytes) |
Dmitry Shmidt | 8d520ff | 2011-05-09 14:06:53 -0700 | [diff] [blame] | 19 | * @nonce: Nonce for counter mode (16 bytes) |
| 20 | * @data: Data to encrypt in-place |
| 21 | * @data_len: Length of data in bytes |
| 22 | * Returns: 0 on success, -1 on failure |
| 23 | */ |
Dmitry Shmidt | fe31a9a | 2016-11-09 13:43:31 -0800 | [diff] [blame^] | 24 | int aes_128_ctr_encrypt(const u8 *key, const u8 *nonce, |
| 25 | u8 *data, size_t data_len) |
Dmitry Shmidt | 8d520ff | 2011-05-09 14:06:53 -0700 | [diff] [blame] | 26 | { |
| 27 | void *ctx; |
| 28 | size_t j, len, left = data_len; |
| 29 | int i; |
| 30 | u8 *pos = data; |
| 31 | u8 counter[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; |
| 32 | |
Dmitry Shmidt | fe31a9a | 2016-11-09 13:43:31 -0800 | [diff] [blame^] | 33 | ctx = aes_encrypt_init(key, 16); |
Dmitry Shmidt | 8d520ff | 2011-05-09 14:06:53 -0700 | [diff] [blame] | 34 | if (ctx == NULL) |
| 35 | return -1; |
| 36 | os_memcpy(counter, nonce, AES_BLOCK_SIZE); |
| 37 | |
| 38 | while (left > 0) { |
| 39 | aes_encrypt(ctx, counter, buf); |
| 40 | |
| 41 | len = (left < AES_BLOCK_SIZE) ? left : AES_BLOCK_SIZE; |
| 42 | for (j = 0; j < len; j++) |
| 43 | pos[j] ^= buf[j]; |
| 44 | pos += len; |
| 45 | left -= len; |
| 46 | |
| 47 | for (i = AES_BLOCK_SIZE - 1; i >= 0; i--) { |
| 48 | counter[i]++; |
| 49 | if (counter[i]) |
| 50 | break; |
| 51 | } |
| 52 | } |
| 53 | aes_encrypt_deinit(ctx); |
| 54 | return 0; |
| 55 | } |