HKDS: Heirarchal Key Derivation System 1.0.0.2 (A2)
A fast post-quantum secure replacement for DUKPT
hkds_client.h
Go to the documentation of this file.
1/* 2025 Quantum Resistant Cryptographic Solutions Corporation
2 * All Rights Reserved.
3 *
4 * NOTICE: This software and all accompanying materials are the exclusive
5 * property of Quantum Resistant Cryptographic Solutions Corporation (QRCS).
6 * The intellectual and technical concepts contained within this implementation
7 * are proprietary to QRCS and its authorized licensors and are protected under
8 * applicable U.S. and international copyright, patent, and trade secret laws.
9 *
10 * CRYPTOGRAPHIC STANDARDS:
11 * - This software includes implementations of cryptographic algorithms such as
12 * SHA3, AES, and others. These algorithms are public domain or standardized
13 * by organizations such as NIST and are NOT the property of QRCS.
14 * - However, all source code, optimizations, and implementations in this library
15 * are original works of QRCS and are protected under this license.
16 *
17 * RESTRICTIONS:
18 * - Redistribution, modification, or unauthorized distribution of this software,
19 * in whole or in part, is strictly prohibited.
20 * - This software is provided for non-commercial, educational, and research
21 * purposes only. Commercial use in any form is expressly forbidden.
22 * - Licensing and authorized distribution are solely at the discretion of QRCS.
23 * - Any use of this software implies acceptance of these restrictions.
24 *
25 * DISCLAIMER:
26 * This software is provided "as is," without warranty of any kind, express or
27 * implied, including but not limited to warranties of merchantability or fitness
28 * for a particular purpose. QRCS disclaims all liability for any direct, indirect,
29 * incidental, or consequential damages resulting from the use or misuse of this software.
30 *
31 * FULL LICENSE:
32 * This software is subject to the **Quantum Resistant Cryptographic Solutions
33 * Proprietary License (QRCS-PL)**. The complete license terms are included
34 * in the LICENSE.txt file distributed with this software.
35 *
36 * Written by: John G. Underhill
37 * Contact: john.underhill@protonmail.com
38 */
39
40#ifndef HKDS_CLIENT_H
41#define HKDS_CLIENT_H
42
43#include "hkds_config.h"
44
71
84HKDS_EXPORT_API typedef struct
85{
86 uint8_t edk[HKDS_EDK_SIZE];
87 uint8_t ksn[HKDS_KSN_SIZE];
89 bool cache_empty;
91
113HKDS_EXPORT_API bool hkds_client_decrypt_token(hkds_client_state* state, const uint8_t* etok, uint8_t* token);
114
134HKDS_EXPORT_API bool hkds_client_encrypt_message(hkds_client_state* state, const uint8_t* plaintext, uint8_t* ciphertext);
135
157HKDS_EXPORT_API bool hkds_client_encrypt_authenticate_message(hkds_client_state* state, const uint8_t* plaintext, const uint8_t* data, size_t datalen, uint8_t* ciphertext);
158
175HKDS_EXPORT_API void hkds_client_generate_cache(hkds_client_state* state, const uint8_t* token);
176
193HKDS_EXPORT_API void hkds_client_initialize_state(hkds_client_state* state, const uint8_t* edk, const uint8_t* did);
194
195
196#endif
HKDS_EXPORT_API void hkds_client_generate_cache(hkds_client_state *state, const uint8_t *token)
Generate the transaction key cache (TKC) for the client.
Definition hkds_client.c:163
HKDS_EXPORT_API bool hkds_client_decrypt_token(hkds_client_state *state, const uint8_t *etok, uint8_t *token)
Decrypt an encrypted token key received from the server.
Definition hkds_client.c:30
HKDS_EXPORT_API bool hkds_client_encrypt_message(hkds_client_state *state, const uint8_t *plaintext, uint8_t *ciphertext)
Encrypt a message to be sent to the server.
Definition hkds_client.c:94
HKDS_EXPORT_API void hkds_client_initialize_state(hkds_client_state *state, const uint8_t *edk, const uint8_t *did)
Initialize the HKDS client state.
Definition hkds_client.c:190
HKDS_EXPORT_API bool hkds_client_encrypt_authenticate_message(hkds_client_state *state, const uint8_t *plaintext, const uint8_t *data, size_t datalen, uint8_t *ciphertext)
Encrypt a message and append an authentication tag.
Definition hkds_client.c:117
HKDS configuration definitions.
#define HKDS_MESSAGE_SIZE
The encrypted message size in bytes.
Definition hkds_config.h:302
#define HKDS_EDK_SIZE
The Embedded Device Key size for SHAKE-256 in bytes.
Definition hkds_config.h:391
#define HKDS_CACHE_SIZE
The size of the transaction key cache.
Definition hkds_config.h:484
#define HKDS_KSN_SIZE
The Key Serial Number (KSN) size in bytes.
Definition hkds_config.h:296
Contains the HKDS client state.
Definition hkds_client.h:85