10 #include <openssl/crypto.h> 11 #include <openssl/evp.h> 12 #include <openssl/rand.h> 33 : AesGcmEncryptorComponentBase(compName),
35 m_bufferState(BufferOwnershipState::OWNED),
41 this->m_cipher = EVP_CIPHER_fetch(
nullptr,
"AES-256-GCM",
nullptr);
43 this->m_ctx = EVP_CIPHER_CTX_new();
46 int status = EVP_EncryptInit_ex(this->m_ctx, this->m_cipher,
nullptr,
nullptr,
nullptr);
47 FW_ASSERT(status == 1, static_cast<FwAssertArgType>(status));
48 status = EVP_CIPHER_CTX_ctrl(this->m_ctx, EVP_CTRL_GCM_SET_IVLEN, static_cast<int>(
GCM_IV_LEN),
nullptr);
49 FW_ASSERT(status == 1, static_cast<FwAssertArgType>(status));
53 EVP_CIPHER_CTX_free(this->m_ctx);
54 EVP_CIPHER_free(this->m_cipher);
61 void AesGcmEncryptor ::encryptIn_handler(
FwIndexType portNum,
62 U16 securityAssociationIndex,
71 if (this->m_bufferState != BufferOwnershipState::OWNED) {
72 this->log_WARNING_HI_OutputBufferBusy();
91 U8*
const iv = this->m_outBuf;
95 if (RAND_bytes(iv, static_cast<int>(
GCM_IV_LEN)) != 1) {
104 if ((vcId != this->m_aadVcId) || (securityAssociationIndex != this->m_aadSaIndex)) {
106 this->m_aadVcId = vcId;
107 this->m_aadSaIndex = securityAssociationIndex;
113 bool encryptSucceeded =
114 (EVP_EncryptInit_ex(this->m_ctx,
nullptr,
nullptr, key.
getBuffAddr(), iv) == 1) &&
115 (EVP_EncryptUpdate(this->m_ctx,
nullptr, &len, this->m_aad.
bytes,
116 static_cast<int>(
sizeof(this->m_aad.bytes))) == 1) &&
117 (EVP_EncryptUpdate(this->m_ctx, ciphertext, &len, data.
getData(),
static_cast<int>(data.
getSize())) == 1);
121 if (encryptSucceeded) {
123 encryptSucceeded = (EVP_EncryptFinal_ex(this->m_ctx, ciphertext + cipherLen, &len) == 1);
125 if (encryptSucceeded) {
128 encryptSucceeded = (EVP_CIPHER_CTX_ctrl(this->m_ctx, EVP_CTRL_GCM_GET_TAG, static_cast<int>(
GCM_TAG_LEN),
129 ciphertext + cipherLen) == 1);
132 if (!encryptSucceeded) {
142 this->m_bufferState = BufferOwnershipState::NOT_OWNED;
145 this->bufferReturnOut_out(0, data, context);
149 void AesGcmEncryptor ::encryptReturnIn_handler(
FwIndexType portNum,
158 FW_ASSERT(this->m_bufferState == BufferOwnershipState::NOT_OWNED,
159 static_cast<FwAssertArgType>(this->m_bufferState));
160 this->m_bufferState = BufferOwnershipState::OWNED;
169 this->bufferReturnOut_out(0, data, context);
173 this->encryptOut_out(0, status, empty, context);
AesGcmEncryptor(const char *const compName)
Construct AesGcmEncryptor object.
PlatformSizeType FwSizeType
Serializable::SizeType getSize() const override
Get current buffer size.
static constexpr U32 GCM_IV_LEN
Length of the AES-GCM initialization vector, in bytes.
Serializable::SizeType getCapacity() const override
Get buffer capacity.
Status of an SDLS (Space Data Link Security) encryption/decryption request.
static constexpr FwSizeType AES_256_KEY_LEN
Length of an AES-256 key, in bytes.
U8 * getBuffAddr()
Get buffer address for data filling (non-const version)
U8 get_vcId() const
Get member vcId.
Encryption operation failed.
~AesGcmEncryptor()
Destroy AesGcmEncryptor object.
static constexpr U32 GCM_TAG_LEN
Length of the AES-GCM authentication tag (the SDLS MAC), in bytes.
uint8_t U8
8-bit unsigned integer
FwSizeType getSize() const
PlatformIndexType FwIndexType
Type used to pass context info between components during framing/deframing.
RateGroupDivider component implementation.
static constexpr FwSizeType MAX_OUTPUT_SIZE
Largest output frame the downstream chain carries: the TM data field less the 2-byte SA index...
Request completed successfully.