comparison sysoptions.h @ 1672:3a97f14c0235

Add Chacha20-Poly1305, AES128-GCM and AES256-GCM support (#93) * Add Chacha20-Poly1305 authenticated encryption * Add general AEAD approach. * Add [email protected] algo using LibTomCrypt chacha and poly1305 routines. Chacha20-Poly1305 is generally faster than AES256 on CPU w/o dedicated AES instructions, having the same key size. Compiling in will add ~5,5kB to binary size on x86-64. function old new delta chacha_crypt - 1397 +1397 _poly1305_block - 608 +608 poly1305_done - 595 +595 dropbear_chachapoly_crypt - 457 +457 .rodata 26976 27392 +416 poly1305_process - 290 +290 poly1305_init - 221 +221 chacha_setup - 218 +218 encrypt_packet 1068 1270 +202 dropbear_chachapoly_getlength - 147 +147 decrypt_packet 756 897 +141 chacha_ivctr64 - 137 +137 read_packet 543 637 +94 dropbear_chachapoly_start - 94 +94 read_kex_algos 792 880 +88 chacha_keystream - 69 +69 dropbear_mode_chachapoly - 48 +48 sshciphers 280 320 +40 dropbear_mode_none 24 48 +24 dropbear_mode_ctr 24 48 +24 dropbear_mode_cbc 24 48 +24 dropbear_chachapoly_mac - 24 +24 dropbear_chachapoly - 24 +24 gen_new_keys 848 854 +6 ------------------------------------------------------------------------------ (add/remove: 14/0 grow/shrink: 10/0 up/down: 5388/0) Total: 5388 bytes * Add AES128-GCM and AES256-GCM authenticated encryption * Add general AES-GCM mode. * Add [email protected] and [email protected] algo using LibTomCrypt gcm routines. AES-GCM is combination of AES CTR mode and GHASH, slower than AES-CTR on CPU w/o dedicated AES/GHASH instructions therefore disabled by default. Compiling in will add ~6kB to binary size on x86-64. function old new delta gcm_process - 1060 +1060 .rodata 26976 27808 +832 gcm_gf_mult - 820 +820 gcm_add_aad - 660 +660 gcm_shift_table - 512 +512 gcm_done - 471 +471 gcm_add_iv - 384 +384 gcm_init - 347 +347 dropbear_gcm_crypt - 309 +309 encrypt_packet 1068 1270 +202 decrypt_packet 756 897 +141 gcm_reset - 118 +118 read_packet 543 637 +94 read_kex_algos 792 880 +88 sshciphers 280 360 +80 gcm_mult_h - 80 +80 dropbear_gcm_start - 62 +62 dropbear_mode_gcm - 48 +48 dropbear_mode_none 24 48 +24 dropbear_mode_ctr 24 48 +24 dropbear_mode_cbc 24 48 +24 dropbear_ghash - 24 +24 dropbear_gcm_getlength - 24 +24 gen_new_keys 848 854 +6 ------------------------------------------------------------------------------ (add/remove: 14/0 grow/shrink: 10/0 up/down: 6434/0) Total: 6434 bytes
author Vladislav Grishenko <themiron@users.noreply.github.com>
date Mon, 25 May 2020 20:50:25 +0500
parents d32bcb5c557d
children 41bf8f216644
comparison
equal deleted inserted replaced
1671:5c8913b7464c 1672:3a97f14c0235
90 90
91 #define SHA1_HASH_SIZE 20 91 #define SHA1_HASH_SIZE 20
92 #define MD5_HASH_SIZE 16 92 #define MD5_HASH_SIZE 16
93 #define MAX_HASH_SIZE 64 /* sha512 */ 93 #define MAX_HASH_SIZE 64 /* sha512 */
94 94
95 #if DROPBEAR_CHACHA20POLY1305
96 #define MAX_KEY_LEN 64 /* 2 x 256 bits for chacha20 */
97 #else
95 #define MAX_KEY_LEN 32 /* 256 bits for aes256 etc */ 98 #define MAX_KEY_LEN 32 /* 256 bits for aes256 etc */
99 #endif
96 #define MAX_IV_LEN 20 /* must be same as max blocksize, */ 100 #define MAX_IV_LEN 20 /* must be same as max blocksize, */
97 101
98 #if DROPBEAR_SHA2_512_HMAC 102 #if DROPBEAR_SHA2_512_HMAC
99 #define MAX_MAC_LEN 64 103 #define MAX_MAC_LEN 64
100 #elif DROPBEAR_SHA2_256_HMAC 104 #elif DROPBEAR_SHA2_256_HMAC
205 209
206 #define DROPBEAR_AES ((DROPBEAR_AES256) || (DROPBEAR_AES128)) 210 #define DROPBEAR_AES ((DROPBEAR_AES256) || (DROPBEAR_AES128))
207 211
208 #define DROPBEAR_TWOFISH ((DROPBEAR_TWOFISH256) || (DROPBEAR_TWOFISH128)) 212 #define DROPBEAR_TWOFISH ((DROPBEAR_TWOFISH256) || (DROPBEAR_TWOFISH128))
209 213
214 #define DROPBEAR_AEAD_MODE ((DROPBEAR_CHACHA20POLY1305) || (DROPBEAR_ENABLE_GCM_MODE))
215
210 #define DROPBEAR_CLI_ANYTCPFWD ((DROPBEAR_CLI_REMOTETCPFWD) || (DROPBEAR_CLI_LOCALTCPFWD)) 216 #define DROPBEAR_CLI_ANYTCPFWD ((DROPBEAR_CLI_REMOTETCPFWD) || (DROPBEAR_CLI_LOCALTCPFWD))
211 217
212 #define DROPBEAR_TCP_ACCEPT ((DROPBEAR_CLI_LOCALTCPFWD) || (DROPBEAR_SVR_REMOTETCPFWD)) 218 #define DROPBEAR_TCP_ACCEPT ((DROPBEAR_CLI_LOCALTCPFWD) || (DROPBEAR_SVR_REMOTETCPFWD))
213 219
214 #define DROPBEAR_LISTENERS \ 220 #define DROPBEAR_LISTENERS \
247 #if (DROPBEAR_PLUGIN && !DROPBEAR_SVR_PUBKEY_AUTH) 253 #if (DROPBEAR_PLUGIN && !DROPBEAR_SVR_PUBKEY_AUTH)
248 #error "You must define DROPBEAR_SVR_PUBKEY_AUTH in order to use plugins" 254 #error "You must define DROPBEAR_SVR_PUBKEY_AUTH in order to use plugins"
249 #endif 255 #endif
250 256
251 #if !(DROPBEAR_AES128 || DROPBEAR_3DES || DROPBEAR_AES256 || DROPBEAR_BLOWFISH \ 257 #if !(DROPBEAR_AES128 || DROPBEAR_3DES || DROPBEAR_AES256 || DROPBEAR_BLOWFISH \
252 || DROPBEAR_TWOFISH256 || DROPBEAR_TWOFISH128) 258 || DROPBEAR_TWOFISH256 || DROPBEAR_TWOFISH128 || DROPBEAR_CHACHA20POLY1305)
253 #error "At least one encryption algorithm must be enabled. AES128 is recommended." 259 #error "At least one encryption algorithm must be enabled. AES128 is recommended."
254 #endif 260 #endif
255 261
256 #if !(DROPBEAR_RSA || DROPBEAR_DSS || DROPBEAR_ECDSA || DROPBEAR_ED25519) 262 #if !(DROPBEAR_RSA || DROPBEAR_DSS || DROPBEAR_ECDSA || DROPBEAR_ED25519)
257 #error "At least one hostkey or public-key algorithm must be enabled; RSA is recommended." 263 #error "At least one hostkey or public-key algorithm must be enabled; RSA is recommended."