Refactor cipher modes onto shared base classes; harden key wiping - #165
Merged
Conversation
Consolidate the BlockCipher modes and AEAD modes behind abstract base classes, deduplicating the surface each mode previously reimplemented while keeping every tuned hot path (SIMD/fused kernels, bulk batching, tag-lookahead buffering) in the concrete mode. Base classes - TAbstractBlockCipherMode: base for CBC, CFB, OFB, ECB, SIC and OpenPGP-CFB. Owns the underlying-cipher / algorithm-name / block-size accessors and one overflow-safe bulk bounds check (via TCheck). - TAbstractAeadCipher + TAbstractAeadBlockCipher: bases for GCM, EAX, OCB, CCM, GCM-SIV and ChaCha20-Poly1305. Own GetMac, constant-time tag verification, the encrypt-side nonce-reuse guard, MAC-size validation, the unified MAC-check-failed error, the output-size template and a guaranteed key-wiping destructor. - TGaloisFieldUtilities: single home for the GF(2^128) x-doubling that CMAC, EAX and OCB each duplicated. MulX moves into TGcmUtilities and ClpGcmSivUtilities is retired. Security hardening - Zeroize key-derived material on teardown for EAX, OCB, CCM, GCM-SIV and ChaCha20-Poly1305 (previously only GCM did). Notably, ChaCha's 256-bit key is now wiped. Behavioural changes (intentional) - GCM-SIV.GetMac now returns the stored tag instead of raising. - The MAC-failure message is unified across all AEAD modes. Tests - Add an OpenPGP-CFB test: an independent first-block known-answer vector plus multi-length round-trips. All cipher outputs remain byte-identical.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Consolidate the BlockCipher modes and AEAD modes behind abstract base classes, deduplicating the surface each mode previously reimplemented while keeping every tuned hot path (SIMD/fused kernels, bulk batching, tag-lookahead buffering) in the concrete mode.
Base classes
Security hardening
Behavioural changes (intentional)
Tests
All cipher outputs remain byte-identical.