− | This encrypts the input data with [[PS:EncryptSignDecryptVerifyAesCcm|AES-CCM]] using keytype2, when the input noncesize is <12 the low 2-bits are cleared in the noncesize. The 12-byte nonce buffer used by NS is cleared to all-zero, then the nonce from inputbuf+blocksize with the noncesize is copied to this nonce buffer. NS then copies the data at inputbuf+0 to outbuf+noncesize, with the blocksize. | + | This encrypts the input data with [[PS:EncryptSignDecryptVerifyAesCcm|AES-CCM]] using keytype2, when the input noncesize is <12 the low 2-bits are cleared in the noncesize. The 12-byte nonce buffer used by NS is cleared to all-zero, then the nonce from inputbuf+nonceoffset with the noncesize is copied to this nonce buffer. NS then copies the data at inputbuf+0 to outbuf+noncesize, with the nonceoffset. |
− | NS then copies the data at inbuf+blocksize+noncesize to outbuf+blocksize+noncesize, with size inputbuffersize-blocksize-noncesize. NS then uses [[PS:EncryptSignDecryptVerifyAesCcm]] with keytype2 and with the above nonce buffer, where the input/output buffer ptrs are outbuf+noncesize, with size blocksize+(inputbuffersize-blocksize-noncesize). NS then copies the the nonce from the nonce-buffer with the noncesize, to outbuf+0. | + | NS then copies the data at inbuf+nonceoffset+noncesize to outbuf+nonceoffset+noncesize, with size inputbuffersize-nonceoffset-noncesize. NS then uses [[PS:EncryptSignDecryptVerifyAesCcm]] with keytype2 and with the above nonce buffer, where the input/output buffer ptrs are outbuf+noncesize, with size nonceoffset+(inputbuffersize-nonceoffset-noncesize). NS then copies the the nonce from the nonce-buffer with the noncesize, to outbuf+0. |
| + | In other words, the nonce with noncesize located at nonceoffset in the input buffer is copied to the beginning of the output buffer. The rest of the input data are concatenated, encrypted via [[PS:EncryptSignDecryptVerifyAesCcm]] using the said nonce (padded or capped to 12 bytes), and then written to outbuf+noncesize. |