1*e7b1675dSTing-Kang Chang // Copyright 2022 Google LLC 2*e7b1675dSTing-Kang Chang // 3*e7b1675dSTing-Kang Chang // Licensed under the Apache License, Version 2.0 (the "License"); 4*e7b1675dSTing-Kang Chang // you may not use this file except in compliance with the License. 5*e7b1675dSTing-Kang Chang // You may obtain a copy of the License at 6*e7b1675dSTing-Kang Chang // 7*e7b1675dSTing-Kang Chang // http://www.apache.org/licenses/LICENSE-2.0 8*e7b1675dSTing-Kang Chang // 9*e7b1675dSTing-Kang Chang // Unless required by applicable law or agreed to in writing, software 10*e7b1675dSTing-Kang Chang // distributed under the License is distributed on an "AS IS" BASIS, 11*e7b1675dSTing-Kang Chang // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12*e7b1675dSTing-Kang Chang // See the License for the specific language governing permissions and 13*e7b1675dSTing-Kang Chang // limitations under the License. 14*e7b1675dSTing-Kang Chang // 15*e7b1675dSTing-Kang Chang //////////////////////////////////////////////////////////////////////////////// 16*e7b1675dSTing-Kang Chang 17*e7b1675dSTing-Kang Chang #ifndef TINK_MAC_AES_CMAC_PARAMETERS_H_ 18*e7b1675dSTing-Kang Chang #define TINK_MAC_AES_CMAC_PARAMETERS_H_ 19*e7b1675dSTing-Kang Chang 20*e7b1675dSTing-Kang Chang #include <memory> 21*e7b1675dSTing-Kang Chang 22*e7b1675dSTing-Kang Chang #include "tink/mac/mac_parameters.h" 23*e7b1675dSTing-Kang Chang #include "tink/util/statusor.h" 24*e7b1675dSTing-Kang Chang 25*e7b1675dSTing-Kang Chang namespace crypto { 26*e7b1675dSTing-Kang Chang namespace tink { 27*e7b1675dSTing-Kang Chang 28*e7b1675dSTing-Kang Chang // Describes the parameters of an `AesCmacKey`. 29*e7b1675dSTing-Kang Chang class AesCmacParameters : public MacParameters { 30*e7b1675dSTing-Kang Chang public: 31*e7b1675dSTing-Kang Chang // Describes the details of a MAC computation. 32*e7b1675dSTing-Kang Chang // 33*e7b1675dSTing-Kang Chang // The usual AES-CMAC key is used for variant `NO_PREFIX`. Other variants 34*e7b1675dSTing-Kang Chang // slightly change how the MAC is computed, or add a prefix to every 35*e7b1675dSTing-Kang Chang // computation depending on the key id. 36*e7b1675dSTing-Kang Chang enum class Variant : int { 37*e7b1675dSTing-Kang Chang // Prepends '0x01<big endian key id>' to tag. 38*e7b1675dSTing-Kang Chang kTink = 1, 39*e7b1675dSTing-Kang Chang // Prepends '0x00<big endian key id>' to tag. 40*e7b1675dSTing-Kang Chang kCrunchy = 2, 41*e7b1675dSTing-Kang Chang // Appends a 0-byte to input message BEFORE computing the tag, then 42*e7b1675dSTing-Kang Chang // prepends '0x00<big endian key id>' to tag. 43*e7b1675dSTing-Kang Chang kLegacy = 3, 44*e7b1675dSTing-Kang Chang // Does not prepend any prefix (i.e., keys must have no ID requirement). 45*e7b1675dSTing-Kang Chang kNoPrefix = 4, 46*e7b1675dSTing-Kang Chang // Added to guard from failures that may be caused by future expansions. 47*e7b1675dSTing-Kang Chang kDoNotUseInsteadUseDefaultWhenWritingSwitchStatements = 20, 48*e7b1675dSTing-Kang Chang }; 49*e7b1675dSTing-Kang Chang 50*e7b1675dSTing-Kang Chang // Copyable and movable. 51*e7b1675dSTing-Kang Chang AesCmacParameters(const AesCmacParameters& other) = default; 52*e7b1675dSTing-Kang Chang AesCmacParameters& operator=(const AesCmacParameters& other) = default; 53*e7b1675dSTing-Kang Chang AesCmacParameters(AesCmacParameters&& other) = default; 54*e7b1675dSTing-Kang Chang AesCmacParameters& operator=(AesCmacParameters&& other) = default; 55*e7b1675dSTing-Kang Chang 56*e7b1675dSTing-Kang Chang // Creates a new AES-CMAC parameters object unless an error occurs. An error 57*e7b1675dSTing-Kang Chang // occurs under one of the following conditions: 58*e7b1675dSTing-Kang Chang // 1. `key_size_in_bytes` is a value other than 16 or 32 59*e7b1675dSTing-Kang Chang // 2. `cryptographic_tag_size_in_bytes` falls outside [10,...,16] 60*e7b1675dSTing-Kang Chang static util::StatusOr<AesCmacParameters> Create( 61*e7b1675dSTing-Kang Chang int key_size_in_bytes, int cryptographic_tag_size_in_bytes, 62*e7b1675dSTing-Kang Chang Variant variant); 63*e7b1675dSTing-Kang Chang GetVariant()64*e7b1675dSTing-Kang Chang Variant GetVariant() const { return variant_; } 65*e7b1675dSTing-Kang Chang KeySizeInBytes()66*e7b1675dSTing-Kang Chang int KeySizeInBytes() const { return key_size_in_bytes_; } 67*e7b1675dSTing-Kang Chang 68*e7b1675dSTing-Kang Chang // Returns the size of the tag, which is computed cryptographically from the 69*e7b1675dSTing-Kang Chang // message. Note that this may differ from the total size of the tag, as for 70*e7b1675dSTing-Kang Chang // some keys, Tink prefixes the tag with a key dependent output prefix. CryptographicTagSizeInBytes()71*e7b1675dSTing-Kang Chang int CryptographicTagSizeInBytes() const { 72*e7b1675dSTing-Kang Chang return cryptographic_tag_size_in_bytes_; 73*e7b1675dSTing-Kang Chang } 74*e7b1675dSTing-Kang Chang 75*e7b1675dSTing-Kang Chang // Returns the size of the cryptographic tag plus the size of the prefix with 76*e7b1675dSTing-Kang Chang // which this key prefixes every cryptographic tag. 77*e7b1675dSTing-Kang Chang int TotalTagSizeInBytes() const; 78*e7b1675dSTing-Kang Chang HasIdRequirement()79*e7b1675dSTing-Kang Chang bool HasIdRequirement() const override { 80*e7b1675dSTing-Kang Chang return variant_ != Variant::kNoPrefix; 81*e7b1675dSTing-Kang Chang } 82*e7b1675dSTing-Kang Chang 83*e7b1675dSTing-Kang Chang bool operator==(const Parameters& other) const override; 84*e7b1675dSTing-Kang Chang 85*e7b1675dSTing-Kang Chang private: AesCmacParameters(int key_size_in_bytes,int cryptographic_tag_size_in_bytes,Variant variant)86*e7b1675dSTing-Kang Chang AesCmacParameters(int key_size_in_bytes, int cryptographic_tag_size_in_bytes, 87*e7b1675dSTing-Kang Chang Variant variant) 88*e7b1675dSTing-Kang Chang : key_size_in_bytes_(key_size_in_bytes), 89*e7b1675dSTing-Kang Chang cryptographic_tag_size_in_bytes_(cryptographic_tag_size_in_bytes), 90*e7b1675dSTing-Kang Chang variant_(variant) {} 91*e7b1675dSTing-Kang Chang 92*e7b1675dSTing-Kang Chang int key_size_in_bytes_; 93*e7b1675dSTing-Kang Chang int cryptographic_tag_size_in_bytes_; 94*e7b1675dSTing-Kang Chang Variant variant_; 95*e7b1675dSTing-Kang Chang }; 96*e7b1675dSTing-Kang Chang 97*e7b1675dSTing-Kang Chang } // namespace tink 98*e7b1675dSTing-Kang Chang } // namespace crypto 99*e7b1675dSTing-Kang Chang 100*e7b1675dSTing-Kang Chang #endif // TINK_MAC_AES_CMAC_PARAMETERS_H_ 101