Expand description
Symmetric crypto engines: AES, hash and ChaCha.
The three engines share one DMA, so only one of them runs at a time. They are owned
together through the CRYPTO_SYMMETRIC peripheral and the Symmetric driver.
The state of every operation lives in a context object outside the driver. Any number of operations of any kind can be in progress at once, and their calls can be interleaved.
§AES
| Mode | Authenticated | nRF52840, nRF91 | nRF5340 | nRF54L |
|---|---|---|---|---|
| ECB | No | ✓ | ✓ | ✓ |
| CBC | No | ✓ | ✓ | ✓ |
| CTR | No | ✓ | ✓ | ✓ |
| CMAC | MAC only | ✓ | ✓ | ✓ |
| CCM | Yes | ✓ | ✓ | ✓ |
| GCM | Yes | ✗ | ✓ | ✓ |
128-bit keys are supported on all chips. 192-bit and 256-bit keys are supported on nRF5340 and nRF54L.
To run a cipher operation:
- Start it with
Symmetric::aes_start. This returns anAesContext. - Feed additional authenticated data with
Symmetric::aes_blocking_aad(authenticated modes only). - Feed the payload with
Symmetric::aes_blocking_payload. - Finish with
Symmetric::aes_blocking_finish. For MAC and AEAD modes this returns the authentication tag.
§Hash and HMAC
| Algorithm | nRF52840, nRF91, nRF5340 | nRF54L |
|---|---|---|
| SHA-1 | ✓ | ✓ |
| SHA-224 | ✓ | ✓ |
| SHA-256 | ✓ | ✓ |
| SHA-384 | ✗ | ✓ |
| SHA-512 | ✗ | ✓ |
| SHA-512/224 | ✗ | ✓ |
| SHA-512/256 | ✗ | ✓ |
HMAC is available for every supported algorithm.
To compute a digest:
- Start with
Symmetric::hash_startorSymmetric::hmac_start. - Feed data with
Symmetric::hash_blocking_update. - Finish with
Symmetric::hash_blocking_finish.
§ChaCha and ChaCha-Poly1305
Both follow RFC 8439: a 256-bit key, a 96-bit nonce and a 32-bit block counter. The
ChaChaVariant selects the number of rounds: ChaCha20 everywhere, and also the
reduced-round ChaCha12 and ChaCha8 on the CryptoCell.
- The plain keystream is started with
Symmetric::chacha_startand applied withSymmetric::chacha_blocking_apply_keystream. - The AEAD is started with
Symmetric::chachapoly_startand then driven like an AES AEAD, with thechachapoly_blocking_*methods.
The CryptoCell has no Poly1305 engine. There, the authenticator runs in software.
Input data may be anywhere in memory, including flash.
Structs§
- AesCbc
- AES in CBC (cipher block chaining) mode.
- AesCcm
- AES in CCM (counter with CBC-MAC) authenticated mode, as in NIST SP 800-38C.
- AesCmac
- AES-CMAC message authentication code, as in NIST SP 800-38B.
- AesContext
- State of an AES operation in progress. Created by
Symmetric::aes_start. - AesCtr
- AES in CTR (counter) mode, as in NIST SP 800-38A.
- AesEcb
- AES in ECB (electronic codebook) mode.
- ChaCha
Context - State of a ChaCha keystream in progress. Created by
Symmetric::chacha_start. - ChaCha
Poly Context - State of an in-progress ChaCha-Poly1305 operation, created by
Symmetric::chachapoly_start. - Hash
Context - State of a hash computation in progress. Created by
Symmetric::hash_start. - Hmac
Context - State of an HMAC computation in progress. Created by
Symmetric::hmac_start. - Sha1
- SHA-1.
- Sha224
- SHA-224.
- Sha256
- SHA-256.
- Symmetric
- Driver for the symmetric crypto engines: AES, hash and ChaCha.
Enums§
- ChaCha
Variant - Number of rounds of the ChaCha block function.
- Direction
- Cipher direction.
- Error
- Symmetric crypto error.
Constants§
- AES_
BLOCK_ LEN - AES block length in bytes.
- CHACHA_
BLOCK_ LEN - ChaCha20 block length in bytes.
- CHACHA_
KEY_ LEN - ChaCha20 key length in bytes.
- CHACHA_
NONCE_ LEN - ChaCha20 nonce length in bytes.
Traits§
- Authenticated
Cipher - AES cipher mode that accepts additional authenticated data. Implemented by
AesCcmandAesGcm. - Buffer
- Fixed-size byte buffer. Implemented for
[u8; N]. - Cipher
- AES cipher mode. Implemented by
AesEcb,AesCbc,AesCtr,AesCmac,AesCcmandAesGcm. - Digest
Context - A hash or HMAC context. Implemented by
HashContextandHmacContext. - Hash
Algorithm - Hash algorithm. Implemented by
Sha1,Sha224,Sha256and, on CRACEN, the SHA-512 family.