Skip to content

feat: add AES-256-CTR-HMAC-SHA512 cipher suites from draft-barnes-sframe-iana-256 - #98

Merged
pabuhler merged 1 commit into
cisco:mainfrom
k-wasniowski:feat-support-draft-barness-extra-cipher-suites
Sep 23, 2026
Merged

pabuhler merged 1 commit into
cisco:mainfrom
k-wasniowski:feat-support-draft-barness-extra-cipher-suites

Conversation

@k-wasniowski

Copy link
Copy Markdown
Contributor

Add AES-256-CTR-HMAC-SHA512 cipher suites

Summary

Implements the three cipher suites registered in draft-barnes-sframe-iana-256, which extend the SFrame CTR+HMAC compound AEAD construction (Section 4.5.1 of RFC 9605) to the 256-bit security level:

Value Name Nh Nka Nk Nn Nt
0x0006 AES_256_CTR_HMAC_SHA512_80 64 32 96 12 10
0x0007 AES_256_CTR_HMAC_SHA512_64 64 32 96 12 8
0x0008 AES_256_CTR_HMAC_SHA512_32 64 32 96 12 4

Motivation

The CTR+HMAC construction was only defined for AES-128 / HMAC-SHA256. Deployments that require a 256-bit security level but cannot use AES-GCM (e.g. because they need short authentication tags) had no usable suite. The construction itself is unchanged apart from field lengths, so this is a small, mechanical extension.

Changes

Public API

  • include/sframe/sframe.h: added AES_256_CTR_HMAC_SHA512_80 / _64 / _32 to CipherSuite.
  • KeyRecord::max_key_size raised from 48 to 96 bytes to hold a 32-byte AES-256 key plus a 64-byte HMAC-SHA512 key. This is a build-time size constant, so pre-built binaries must be rebuilt in lockstep with consumers (as already documented for SFRAME_MAX_KEYS / SFRAME_EPOCH_BITS).

Cipher suite parameters

  • src/crypto.cpp: registered Nh, Nka, Nk, Nn and Nt for the new suites in cipher_digest_size, cipher_key_size, cipher_enc_key_size, cipher_nonce_size and cipher_overhead.

Crypto backends

All three backends map the new suites to AES-256-CTR + SHA-512 and route seal/open through the existing CTR+HMAC path:

  • src/crypto_openssl3.cpp (EVP_aes_256_ctr(), OSSL_DIGEST_NAME_SHA2_512)
  • src/crypto_openssl11.cpp (EVP_aes_256_ctr(), EVP_sha512())
  • src/crypto_boringssl.cpp (EVP_aes_256_ctr(), EVP_sha512())

HKDF buffer sizing

  • src/crypto.h: max_hkdf_expand_size raised from 64 to 96 so derive_key_salt can produce the 96-byte key. max_hkdf_extract_size stays at 64 (the largest hash output).
  • The three backends previously had the max_hkdf_extract_size / max_hkdf_expand_size return types swapped relative to the declarations in crypto.h. This was harmless while both constants were 64, but became a compile error once they diverged, so the definitions now match the declarations.
  • src/crypto_openssl11.cpp: the size guard in hkdf_expand now bounds against max_hkdf_expand_size. The surrounding loop already iterates over HKDF blocks, so deriving 96 bytes from SHA-512 (two blocks) works without further change.
  • src/sframe.cpp: MLSContext::EpochKeys::base_key narrows the hkdf_expand result to the 64-byte epoch secret buffer explicitly; the derived value is still hash-sized, so no truncation occurs.

Testing

  • test/test-vectors.json: added the three official SFrame known-answer vectors from the draft (test-vectors-aes256.json), verified verbatim by the existing SFrame Test Vectors case.
  • test/sframe.cpp: the new suites are exercised by SFrame Round-Trip, MLS Round-Trip and MLS Round-Trip with context.
  • fuzz/fuzz_unprotect.cpp: the suite selector now spans all 8 registered code points.

All 13 tests pass against system OpenSSL 3 with -DTESTING=ON -DCMAKE_BUILD_TYPE=Debug, with no new compiler warnings.

Compatibility

  • No behavior change for existing cipher suites; wire format and key derivation for suites 1-5 are untouched.
  • KeyRecord grows by 48 bytes, which increases the footprint of Context::keys in NO_ALLOC builds (SFRAME_MAX_KEYS entries).

Copilot AI lite review requested due to automatic review settings September 23, 2026 06:51

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues remain, and the supplied readiness assessments support approval.

Review effort: Lite
Findings: None

What changed in this PR

Adds three AES-256-CTR-HMAC-SHA512 SFrame cipher suites (IDs 6–8) with backend support, expanded key sizing, tests, and fuzz coverage.

Changes:

  • Registers suite parameters and AES-256/SHA-512 implementations.
  • Expands key and HKDF buffers for 96-byte derived keys.
  • Adds official vectors, round-trip tests, and fuzz-suite coverage.
File Description
test/​test-vectors.json Adds official AES-256 known-answer vectors.
test/​sframe.cpp Adds round-trip coverage for the new suites.
src/​sframe.cpp Adapts MLS key derivation sizing.
src/​crypto.h Expands HKDF output capacity.
src/​crypto.cpp Registers suite parameters.
src/​crypto_openssl3.cpp Adds OpenSSL 3 AES-256/SHA-512 support.
src/​crypto_openssl11.cpp Adds OpenSSL 1.1 AES-256/SHA-512 support.
src/​crypto_boringssl.cpp Adds BoringSSL AES-256/SHA-512 support.
include/​sframe/​sframe.h Adds suite identifiers and increases key capacity.
fuzz/​fuzz_unprotect.cpp Includes all eight suite IDs in fuzzing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI review requested due to automatic review settings September 23, 2026 07:03
@k-wasniowski
k-wasniowski force-pushed the feat-support-draft-barness-extra-cipher-suites branch from 9e19f76 to 20ba966 Compare September 23, 2026 07:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The cryptographic, key-derivation, and cross-backend changes require final human review.

Review effort: Lite
Findings: None

@k-wasniowski
k-wasniowski force-pushed the feat-support-draft-barness-extra-cipher-suites branch from 20ba966 to 87ce14f Compare September 23, 2026 07:12
Copilot AI review requested due to automatic review settings September 23, 2026 07:12

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved approval-blocking issues were identified.

Review effort: Lite
Findings: None

@k-wasniowski
k-wasniowski force-pushed the feat-support-draft-barness-extra-cipher-suites branch from 87ce14f to 630c278 Compare September 23, 2026 07:27
Copilot AI review requested due to automatic review settings September 23, 2026 07:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cryptographic and key-derivation changes require final human review.

Review effort: Lite
Findings: None

@k-wasniowski
k-wasniowski marked this pull request as ready for review September 23, 2026 09:12
@pabuhler
pabuhler merged commit 6a37f06 into cisco:main Sep 23, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants