Expand description
NIST SP 800-38D Galois/Counter Mode.
GHASH is implemented with a branch-free bit-by-bit multiplication in GF(2^128). Table-driven GHASH is faster but indexes memory with key-derived values; the portable backend refuses that trade.
§Nonce discipline
Reusing a (key, nonce) pair under GCM is catastrophic: it leaks the
authentication subkey and lets an attacker forge arbitrary messages. The
ontology records this as a hard usage constraint
(nonce_reuse_consequence: "catastrophic") so an agent selecting GCM is
told to pair it with a counter or a random 96-bit nonce under a message
limit. See GcmLimits.
Indexed loops over fixed-size limb and word arrays are used throughout; they
mirror the index algebra in the specifications these routines implement, so
needless_range_loop is allowed rather than obscuring the correspondence.
Structs§
- Aes128
Gcm - SP 800-38D AES-128-GCM.
- Aes192
Gcm - SP 800-38D AES-192-GCM.
- Aes256
Gcm - SP 800-38D AES-256-GCM.
- GcmLimits
- Invocation limits an agent must respect for a single GCM key.
Functions§
- ghash_
accelerated - Whether GHASH can use the carry-less multiply on this CPU.