tls_ticket.h
Go to the documentation of this file.
1 /**
2  * @file tls_ticket.h
3  * @brief TLS session tickets
4  *
5  * @section License
6  *
7  * Copyright (C) 2010-2018 Oryx Embedded SARL. All rights reserved.
8  *
9  * This file is part of CycloneSSL Open.
10  *
11  * This program is free software; you can redistribute it and/or
12  * modify it under the terms of the GNU General Public License
13  * as published by the Free Software Foundation; either version 2
14  * of the License, or (at your option) any later version.
15  *
16  * This program is distributed in the hope that it will be useful,
17  * but WITHOUT ANY WARRANTY; without even the implied warranty of
18  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19  * GNU General Public License for more details.
20  *
21  * You should have received a copy of the GNU General Public License
22  * along with this program; if not, write to the Free Software Foundation,
23  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
24  *
25  * @author Oryx Embedded SARL (www.oryx-embedded.com)
26  * @version 1.9.0
27  **/
28 
29 #ifndef _TLS_TICKET_H
30 #define _TLS_TICKET_H
31 
32 //Dependencies
33 #include "tls.h"
34 #include "cipher/aes.h"
35 #include "aead/gcm.h"
36 
37 //Size of ticket key names
38 #ifndef TLS_TICKET_KEY_NAME_SIZE
39  #define TLS_TICKET_KEY_NAME_SIZE 16
40 #elif (TLS_TICKET_KEY_NAME_SIZE < 1)
41  #error TLS_TICKET_KEY_NAME_SIZE parameter is not valid
42 #endif
43 
44 //Size of ticket keys
45 #ifndef TLS_TICKET_KEY_SIZE
46  #define TLS_TICKET_KEY_SIZE 32
47 #elif (TLS_TICKET_KEY_SIZE < 1)
48  #error TLS_TICKET_KEY_SIZE parameter is not valid
49 #endif
50 
51 //Size of ticket IVs
52 #ifndef TLS_TICKET_IV_SIZE
53  #define TLS_TICKET_IV_SIZE 12
54 #elif (TLS_TICKET_IV_SIZE < 1)
55  #error TLS_TICKET_IV_SIZE parameter is not valid
56 #endif
57 
58 //Size of ticket authentication tags
59 #ifndef TLS_TICKET_TAG_SIZE
60  #define TLS_TICKET_TAG_SIZE 16
61 #elif (TLS_TICKET_TAG_SIZE < 1)
62  #error TLS_TICKET_TAG_SIZE parameter is not valid
63 #endif
64 
65 //C++ guard
66 #ifdef __cplusplus
67  extern "C" {
68 #endif
69 
70 
71 /**
72  * @brief Session ticket encryption state
73  **/
74 
75 typedef struct
76 {
77  bool_t valid; ///<Valid set of keys
78  systime_t timestamp; ///<Generation time
79  uint8_t keyName[TLS_TICKET_KEY_NAME_SIZE]; ///<Key identifier
80  uint8_t key[TLS_TICKET_KEY_SIZE]; ///<Encryption key
82 
83 
84 /**
85  * @brief Session ticket encryption context
86  **/
87 
88 typedef struct
89 {
90  OsMutex mutex; ///<Mutex preventing simultaneous access to the context
91  TlsTicketEncryptionState encryptionState; ///<Current set of keys
93  AesContext aesContext; ///<AES context
94  GcmContext gcmContext; ///<GCM context
96 
97 
98 //TLS related functions
100 
101 error_t tlsEncryptTicket(TlsContext *context, const uint8_t *plaintext,
102  size_t plaintextLen, uint8_t *ciphertext, size_t *ciphertextLen, void *param);
103 
104 error_t tlsDecryptTicket(TlsContext *context, const uint8_t *ciphertext,
105  size_t ciphertextLen, uint8_t *plaintext, size_t *plaintextLen, void *param);
106 
108  const PrngAlgo *prngAlgo, void *prngContext);
109 
111 
112 bool_t tlsCompareTicketKeyName(const uint8_t *ticket, size_t ticketLen,
113  const TlsTicketEncryptionState *state);
114 
115 void tlsFreeTicketContext(TlsTicketContext *ticketContext);
116 
117 //C++ guard
118 #ifdef __cplusplus
119  }
120 #endif
121 
122 #endif
TLS (Transport Layer Security)
#define TLS_TICKET_KEY_SIZE
Definition: tls_ticket.h:46
error_t tlsGenerateTicketKeys(TlsTicketContext *ticketContext, const PrngAlgo *prngAlgo, void *prngContext)
Generate a new set of keys.
Definition: tls_ticket.c:310
uint32_t systime_t
Definition: compiler_port.h:44
AES algorithm context.
Definition: aes.h:50
error_t tlsDecryptTicket(TlsContext *context, const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *plaintext, size_t *plaintextLen, void *param)
Session ticket decryption.
Definition: tls_ticket.c:203
bool_t tlsCompareTicketKeyName(const uint8_t *ticket, size_t ticketLen, const TlsTicketEncryptionState *state)
Key name comparison.
Definition: tls_ticket.c:378
GcmContext gcmContext
GCM context.
Definition: tls_ticket.h:94
bool_t valid
Valid set of keys.
Definition: tls_ticket.h:77
error_t tlsInitTicketContext(TlsTicketContext *ticketContext)
Initialize ticket encryption context.
Definition: tls_ticket.c:48
GCM context.
Definition: gcm.h:45
OsMutex mutex
Mutex preventing simultaneous access to the context.
Definition: tls_ticket.h:90
Session ticket encryption context.
Definition: tls_ticket.h:88
AES (Advanced Encryption Standard)
AesContext aesContext
AES context.
Definition: tls_ticket.h:93
TlsTicketEncryptionState encryptionState
Current set of keys.
Definition: tls_ticket.h:91
systime_t timestamp
Generation time.
Definition: tls_ticket.h:78
error_t
Error codes.
Definition: error.h:40
error_t tlsEncryptTicket(TlsContext *context, const uint8_t *plaintext, size_t plaintextLen, uint8_t *ciphertext, size_t *ciphertextLen, void *param)
Session ticket encryption.
Definition: tls_ticket.c:80
Common interface for pseudo-random number generators.
Definition: crypto.h:1091
Galois/Counter Mode (GCM)
Mutex object.
void tlsFreeTicketContext(TlsTicketContext *ticketContext)
Properly dispose ticket encryption context.
Definition: tls_ticket.c:412
#define TLS_TICKET_KEY_NAME_SIZE
Definition: tls_ticket.h:39
TlsTicketEncryptionState prevEncryptionState
Previous set of keys.
Definition: tls_ticket.h:92
void tlsCheckTicketKeyLifetime(TlsTicketEncryptionState *state)
Check the validity of a given set of keys.
Definition: tls_ticket.c:351
#define TlsContext
Definition: tls.h:34
int bool_t
Definition: compiler_port.h:47
Session ticket encryption state.
Definition: tls_ticket.h:75