Course update: lessons, CTF 0x0011a_cb, and documentation

- 0x0011a_cb (Operation Dark Vector): nation-state CTF redesign with an
  AES-128-ECB sealed target and a plaintext launch origin; RP2350 firmware with
  bearing-driven servo, tri-color LEDs, GSV stats, and a realistic no-fix path
- docs: story-driven classified brief, GDB and Ghidra tutorials with deep
  step-throughs, regenerated artifacts and PDFs
- scripts: docstring standard, AES per-student randomizer, telemetry monitor
- week 3 to week 5 lessons: Ghidra patching tutorial, CMSIS-SVD hardware RE,
  double floating-point and GPIO architecture chapters, README structure
This commit is contained in:
Kevin Thomas committed 2026-09-27 14:18:56 -04:00
1 parent 5201ee4b6b
commit 35eacd2c0e
162 files changed
+125658 -232

No files matched your search

+143
View File
@@ -0,0 +1,143 @@
// MIT License
//
// Copyright (c) 2026 Kevin Thomas
//
// Permission is hereby granted, free of charge, to any person obtaining a copy
// of this software and associated documentation files (the "Software"), to deal
// in the Software without restriction, including without limitation the rights
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
// copies of the Software, and to permit persons to whom the Software is
// furnished to do so, subject to the following conditions:
//
// The above copyright notice and this permission notice shall be included in all
// copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
// SOFTWARE.
//
// Author: Kevin Thomas
// Email: kevin@mytechnotalent.com
// GitHub: https://github.com/mytechnotalent/encryption-c-rp2350
// File: auth.h
// Desc: Declares the Ouroboros authentication engine API for RP2350 firmware.
// Created: 2026
#ifndef AUTH_H
#define AUTH_H
#include <stdbool.h>
#include <stddef.h>
#include <stdint.h>
/**
* @brief Onboard LED GPIO pin number.
*
* The RP2350 Pico 2 onboard LED is connected to GPIO 25. Driven high
* on successful authentication and low on failure or idle.
*/
#define AUTH_LED_PIN 25u
/**
* @brief Maximum accepted terminal passphrase length in bytes.
*
* The CLI accepts interactive human-entered passphrases up to 512 bytes,
* matching the hardened host demo boundary before policy validation.
*/
#define AUTH_PASSPHRASE_MAX_LEN 512u
/**
* @brief Required number of lowercase words in the hardened passphrase.
*
* The embedded hardened workflow matches the host-side policy exactly:
* twelve lowercase ASCII words separated by whitespace.
*/
#define AUTH_REQUIRED_WORDS 12u
/**
* @brief Hardened Argon2id salt size in bytes.
*
* Every demo artifact carries a per-ciphertext random 128-bit salt.
*/
#define AUTH_SALT_SIZE 16u
/**
* @brief Hardened XChaCha20 nonce size in bytes.
*
* XChaCha20-Poly1305 consumes a 192-bit nonce in the outer construction.
*/
#define AUTH_NONCE_SIZE 24u
/**
* @brief Subkey size in bytes derived from Argon2id.
*
* The AEAD key size is 256 bits.
*/
#define AUTH_KEY_SIZE 32u
/**
* @brief AEAD authentication tag size in bytes.
*
* XChaCha20-Poly1305 appends a 128-bit authentication tag.
*/
#define AUTH_TAG_SIZE 16u
/**
* @brief Plaintext payload size in bytes.
*
* The fixed dispatch payload is 48 bytes: LED state, UART bytes,
* and trailing reserved bytes matching the Rust hardened demo layout.
*/
#define AUTH_PAYLOAD_SIZE 48u
/**
* @brief Full ciphertext-plus-tag artifact size in bytes.
*
* The encrypted payload is 48 bytes followed by a 16-byte tag.
*/
#define AUTH_CIPHERTEXT_SIZE (AUTH_PAYLOAD_SIZE + AUTH_TAG_SIZE)
/**
* @brief Authentication result codes returned by the hardened engine.
*
* These values let the CLI distinguish policy failures from
* cryptographic authentication failures without guessing.
*/
typedef enum auth_result {
AUTH_RESULT_SUCCESS = 0,
AUTH_RESULT_POLICY_VIOLATION = 1,
AUTH_RESULT_AUTHENTICATION_FAILED = 2,
AUTH_RESULT_INTERNAL_ERROR = 3,
} auth_result_t;
/**
* @brief Initialize the Ouroboros authentication module.
*
* Configures the onboard LED GPIO and marks the hardened engine as ready
* for passphrase authentication.
*
* @param None.
* @return bool true when initialization is successful, else false.
*/
bool auth_init(void);
/**
* @brief Execute the hardened Ouroboros authentication pipeline.
*
* Validates the strict 12-word lowercase passphrase policy, derives the
* 256-bit AEAD key with Argon2id using artifact parameters, decrypts the
* embedded XChaCha20-Poly1305 ciphertext, and dispatches GPIO25/UART
* payload bytes on success.
*
* @param passphrase Pointer to passphrase bytes.
* @param passphrase_len Number of passphrase bytes.
* @return auth_result_t Detailed authentication outcome for the caller.
*/
auth_result_t auth_execute(const uint8_t *passphrase,
size_t passphrase_len);
#endif // AUTH_H
+59
View File
@@ -0,0 +1,59 @@
// MIT License
//
// Copyright (c) 2026 Kevin Thomas
//
// Permission is hereby granted, free of charge, to any person obtaining a copy
// of this software and associated documentation files (the "Software"), to deal
// in the Software without restriction, including without limitation the rights
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
// copies of the Software, and to permit persons to whom the Software is
// furnished to do so, subject to the following conditions:
//
// The above copyright notice and this permission notice shall be included in all
// copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
// SOFTWARE.
//
// Author: Kevin Thomas
// Email: kevin@mytechnotalent.com
// GitHub: https://github.com/mytechnotalent
// File: cli.h
// Desc: Declares the CLI UART passphrase input interface for Ouroboros.
// Created: 2026
#ifndef CLI_H
#define CLI_H
#include <stddef.h>
/**
* @brief Print the UART passphrase prompt.
*
* Emits a minimal shell-style prompt followed by a space so the
* terminal clearly indicates that hardened passphrase input is expected.
*
* @param None.
* @return None.
*/
void print_prompt(void);
/**
* @brief Service one UART polling step for passphrase input.
*
* Polls stdio for a character, dispatches backspace or newline
* handling, and appends printable characters to the passphrase
* buffer. Call repeatedly from the main loop.
*
* @param buf Pointer to mutable passphrase buffer.
* @param idx Pointer to current buffer length.
* @return None.
*/
void service_uart(char *buf, size_t *idx);
#endif // CLI_H
+60
View File
@@ -0,0 +1,60 @@
// MIT License
//
// Copyright (c) 2026 Kevin Thomas
//
// Permission is hereby granted, free of charge, to any person
// obtaining a copy of this software and associated documentation
// files (the "Software"), to deal in the Software without
// restriction, including without limitation the rights to use,
// copy, modify, merge, publish, distribute, sublicense, and/or
// sell copies of the Software, and to permit persons to whom the
// Software is furnished to do so, subject to the following
// conditions:
//
// The above copyright notice and this permission notice shall be
// included in all copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
// EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES
// OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
// NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
// HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
// WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
// DEALINGS IN THE SOFTWARE.
//
// This file is generated by scripts/dec.py. Do not edit by hand.
#ifndef DEMO_ARTIFACT_H
#define DEMO_ARTIFACT_H
#include <stdint.h>
#define DEMO_ARTIFACT_FORMAT "ouroboros-hardened-demo-v1"
#define DEMO_MEMORY_KIB 64u
#define DEMO_ITERATIONS 3u
#define DEMO_PARALLELISM 1u
static const uint8_t DEMO_SALT[16] = {
0xF2u, 0xD5u, 0x18u, 0x63u, 0x9Au, 0x82u, 0x01u, 0x9Du,
0xC2u, 0xD7u, 0xAFu, 0xA5u, 0xCDu, 0xB6u, 0xD8u, 0x71u
};
static const uint8_t DEMO_NONCE[24] = {
0x1Cu, 0xEFu, 0x79u, 0x0Du, 0x77u, 0x9Eu, 0x7Cu, 0x04u,
0xE7u, 0xF0u, 0x66u, 0xDDu, 0x90u, 0xD0u, 0x80u, 0x70u,
0x87u, 0x97u, 0x67u, 0x1Fu, 0x79u, 0xEFu, 0xC4u, 0xE4u
};
static const uint8_t DEMO_CIPHERTEXT_AND_TAG[64] = {
0x2Cu, 0x23u, 0xB2u, 0x7Eu, 0x95u, 0x62u, 0xB8u, 0xEDu,
0x9Eu, 0x08u, 0xE0u, 0x6Du, 0xD9u, 0x9Du, 0xB4u, 0x91u,
0x3Eu, 0x81u, 0x9Au, 0x77u, 0x8Bu, 0xB4u, 0x7Bu, 0x71u,
0xBCu, 0x66u, 0x1Eu, 0x6Eu, 0x73u, 0x1Au, 0x81u, 0x54u,
0xCDu, 0xB5u, 0x36u, 0xA4u, 0x76u, 0x7Eu, 0x9Bu, 0xF8u,
0x53u, 0x3Eu, 0x03u, 0x1Du, 0xB8u, 0xE5u, 0xAEu, 0x7Au,
0xADu, 0xB4u, 0x31u, 0xCFu, 0x12u, 0xD9u, 0xF9u, 0xC4u,
0x5Fu, 0xA9u, 0xB9u, 0x4Bu, 0x80u, 0xDCu, 0xBBu, 0xDEu
};
#endif // DEMO_ARTIFACT_H
+39
View File
@@ -0,0 +1,39 @@
// MIT License
//
// Copyright (c) 2026 Kevin Thomas
//
// Permission is hereby granted, free of charge, to any person obtaining a copy
// of this software and associated documentation files (the "Software"), to deal
// in the Software without restriction, including without limitation the rights
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
// copies of the Software, and to permit persons to whom the Software is
// furnished to do so, subject to the following conditions:
//
// The above copyright notice and this permission notice shall be included in all
// copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
// SOFTWARE.
//
// Author: Kevin Thomas
// Email: kevin@mytechnotalent.com
// GitHub: https://github.com/mytechnotalent
// File: mbedtls_config.h
// Desc: Configures the minimal mbedTLS cryptographic features required by
// the Ouroboros AEAD engine on RP2350.
// Created: 2026
#ifndef MBEDTLS_CONFIG_H
#define MBEDTLS_CONFIG_H
#define MBEDTLS_CHACHA20_C
#define MBEDTLS_CHACHAPOLY_C
#define MBEDTLS_POLY1305_C
#define MBEDTLS_PLATFORM_C
#endif // MBEDTLS_CONFIG_H