mirror of
https://github.com/mytechnotalent/Embedded-Hacking.git
synced 2026-10-01 13:40:32 +02:00
Course update: lessons, CTF 0x0011a_cb, and documentation
- 0x0011a_cb (Operation Dark Vector): nation-state CTF redesign with an AES-128-ECB sealed target and a plaintext launch origin; RP2350 firmware with bearing-driven servo, tri-color LEDs, GSV stats, and a realistic no-fix path - docs: story-driven classified brief, GDB and Ghidra tutorials with deep step-throughs, regenerated artifacts and PDFs - scripts: docstring standard, AES per-student randomizer, telemetry monitor - week 3 to week 5 lessons: Ghidra patching tutorial, CMSIS-SVD hardware RE, double floating-point and GPIO architecture chapters, README structure
This commit is contained in:
1 parent
5201ee4b6b
commit
35eacd2c0e
162 files changed
+125658
-232
No files matched your search
@@ -0,0 +1,143 @@
|
||||
// MIT License
|
||||
//
|
||||
// Copyright (c) 2026 Kevin Thomas
|
||||
//
|
||||
// Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
// of this software and associated documentation files (the "Software"), to deal
|
||||
// in the Software without restriction, including without limitation the rights
|
||||
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
// copies of the Software, and to permit persons to whom the Software is
|
||||
// furnished to do so, subject to the following conditions:
|
||||
//
|
||||
// The above copyright notice and this permission notice shall be included in all
|
||||
// copies or substantial portions of the Software.
|
||||
//
|
||||
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
// SOFTWARE.
|
||||
//
|
||||
// Author: Kevin Thomas
|
||||
// Email: kevin@mytechnotalent.com
|
||||
// GitHub: https://github.com/mytechnotalent/encryption-c-rp2350
|
||||
// File: auth.h
|
||||
// Desc: Declares the Ouroboros authentication engine API for RP2350 firmware.
|
||||
// Created: 2026
|
||||
|
||||
#ifndef AUTH_H
|
||||
#define AUTH_H
|
||||
|
||||
#include <stdbool.h>
|
||||
#include <stddef.h>
|
||||
#include <stdint.h>
|
||||
|
||||
/**
|
||||
* @brief Onboard LED GPIO pin number.
|
||||
*
|
||||
* The RP2350 Pico 2 onboard LED is connected to GPIO 25. Driven high
|
||||
* on successful authentication and low on failure or idle.
|
||||
*/
|
||||
#define AUTH_LED_PIN 25u
|
||||
|
||||
/**
|
||||
* @brief Maximum accepted terminal passphrase length in bytes.
|
||||
*
|
||||
* The CLI accepts interactive human-entered passphrases up to 512 bytes,
|
||||
* matching the hardened host demo boundary before policy validation.
|
||||
*/
|
||||
#define AUTH_PASSPHRASE_MAX_LEN 512u
|
||||
|
||||
/**
|
||||
* @brief Required number of lowercase words in the hardened passphrase.
|
||||
*
|
||||
* The embedded hardened workflow matches the host-side policy exactly:
|
||||
* twelve lowercase ASCII words separated by whitespace.
|
||||
*/
|
||||
#define AUTH_REQUIRED_WORDS 12u
|
||||
|
||||
/**
|
||||
* @brief Hardened Argon2id salt size in bytes.
|
||||
*
|
||||
* Every demo artifact carries a per-ciphertext random 128-bit salt.
|
||||
*/
|
||||
#define AUTH_SALT_SIZE 16u
|
||||
|
||||
/**
|
||||
* @brief Hardened XChaCha20 nonce size in bytes.
|
||||
*
|
||||
* XChaCha20-Poly1305 consumes a 192-bit nonce in the outer construction.
|
||||
*/
|
||||
#define AUTH_NONCE_SIZE 24u
|
||||
|
||||
/**
|
||||
* @brief Subkey size in bytes derived from Argon2id.
|
||||
*
|
||||
* The AEAD key size is 256 bits.
|
||||
*/
|
||||
#define AUTH_KEY_SIZE 32u
|
||||
|
||||
/**
|
||||
* @brief AEAD authentication tag size in bytes.
|
||||
*
|
||||
* XChaCha20-Poly1305 appends a 128-bit authentication tag.
|
||||
*/
|
||||
#define AUTH_TAG_SIZE 16u
|
||||
|
||||
/**
|
||||
* @brief Plaintext payload size in bytes.
|
||||
*
|
||||
* The fixed dispatch payload is 48 bytes: LED state, UART bytes,
|
||||
* and trailing reserved bytes matching the Rust hardened demo layout.
|
||||
*/
|
||||
#define AUTH_PAYLOAD_SIZE 48u
|
||||
|
||||
/**
|
||||
* @brief Full ciphertext-plus-tag artifact size in bytes.
|
||||
*
|
||||
* The encrypted payload is 48 bytes followed by a 16-byte tag.
|
||||
*/
|
||||
#define AUTH_CIPHERTEXT_SIZE (AUTH_PAYLOAD_SIZE + AUTH_TAG_SIZE)
|
||||
|
||||
/**
|
||||
* @brief Authentication result codes returned by the hardened engine.
|
||||
*
|
||||
* These values let the CLI distinguish policy failures from
|
||||
* cryptographic authentication failures without guessing.
|
||||
*/
|
||||
typedef enum auth_result {
|
||||
AUTH_RESULT_SUCCESS = 0,
|
||||
AUTH_RESULT_POLICY_VIOLATION = 1,
|
||||
AUTH_RESULT_AUTHENTICATION_FAILED = 2,
|
||||
AUTH_RESULT_INTERNAL_ERROR = 3,
|
||||
} auth_result_t;
|
||||
|
||||
/**
|
||||
* @brief Initialize the Ouroboros authentication module.
|
||||
*
|
||||
* Configures the onboard LED GPIO and marks the hardened engine as ready
|
||||
* for passphrase authentication.
|
||||
*
|
||||
* @param None.
|
||||
* @return bool true when initialization is successful, else false.
|
||||
*/
|
||||
bool auth_init(void);
|
||||
|
||||
/**
|
||||
* @brief Execute the hardened Ouroboros authentication pipeline.
|
||||
*
|
||||
* Validates the strict 12-word lowercase passphrase policy, derives the
|
||||
* 256-bit AEAD key with Argon2id using artifact parameters, decrypts the
|
||||
* embedded XChaCha20-Poly1305 ciphertext, and dispatches GPIO25/UART
|
||||
* payload bytes on success.
|
||||
*
|
||||
* @param passphrase Pointer to passphrase bytes.
|
||||
* @param passphrase_len Number of passphrase bytes.
|
||||
* @return auth_result_t Detailed authentication outcome for the caller.
|
||||
*/
|
||||
auth_result_t auth_execute(const uint8_t *passphrase,
|
||||
size_t passphrase_len);
|
||||
|
||||
#endif // AUTH_H
|
||||
@@ -0,0 +1,59 @@
|
||||
// MIT License
|
||||
//
|
||||
// Copyright (c) 2026 Kevin Thomas
|
||||
//
|
||||
// Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
// of this software and associated documentation files (the "Software"), to deal
|
||||
// in the Software without restriction, including without limitation the rights
|
||||
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
// copies of the Software, and to permit persons to whom the Software is
|
||||
// furnished to do so, subject to the following conditions:
|
||||
//
|
||||
// The above copyright notice and this permission notice shall be included in all
|
||||
// copies or substantial portions of the Software.
|
||||
//
|
||||
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
// SOFTWARE.
|
||||
//
|
||||
// Author: Kevin Thomas
|
||||
// Email: kevin@mytechnotalent.com
|
||||
// GitHub: https://github.com/mytechnotalent
|
||||
// File: cli.h
|
||||
// Desc: Declares the CLI UART passphrase input interface for Ouroboros.
|
||||
// Created: 2026
|
||||
|
||||
#ifndef CLI_H
|
||||
#define CLI_H
|
||||
|
||||
#include <stddef.h>
|
||||
|
||||
/**
|
||||
* @brief Print the UART passphrase prompt.
|
||||
*
|
||||
* Emits a minimal shell-style prompt followed by a space so the
|
||||
* terminal clearly indicates that hardened passphrase input is expected.
|
||||
*
|
||||
* @param None.
|
||||
* @return None.
|
||||
*/
|
||||
void print_prompt(void);
|
||||
|
||||
/**
|
||||
* @brief Service one UART polling step for passphrase input.
|
||||
*
|
||||
* Polls stdio for a character, dispatches backspace or newline
|
||||
* handling, and appends printable characters to the passphrase
|
||||
* buffer. Call repeatedly from the main loop.
|
||||
*
|
||||
* @param buf Pointer to mutable passphrase buffer.
|
||||
* @param idx Pointer to current buffer length.
|
||||
* @return None.
|
||||
*/
|
||||
void service_uart(char *buf, size_t *idx);
|
||||
|
||||
#endif // CLI_H
|
||||
@@ -0,0 +1,60 @@
|
||||
// MIT License
|
||||
//
|
||||
// Copyright (c) 2026 Kevin Thomas
|
||||
//
|
||||
// Permission is hereby granted, free of charge, to any person
|
||||
// obtaining a copy of this software and associated documentation
|
||||
// files (the "Software"), to deal in the Software without
|
||||
// restriction, including without limitation the rights to use,
|
||||
// copy, modify, merge, publish, distribute, sublicense, and/or
|
||||
// sell copies of the Software, and to permit persons to whom the
|
||||
// Software is furnished to do so, subject to the following
|
||||
// conditions:
|
||||
//
|
||||
// The above copyright notice and this permission notice shall be
|
||||
// included in all copies or substantial portions of the Software.
|
||||
//
|
||||
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||||
// EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES
|
||||
// OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
|
||||
// NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
|
||||
// HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
|
||||
// WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
|
||||
// DEALINGS IN THE SOFTWARE.
|
||||
//
|
||||
// This file is generated by scripts/dec.py. Do not edit by hand.
|
||||
|
||||
#ifndef DEMO_ARTIFACT_H
|
||||
#define DEMO_ARTIFACT_H
|
||||
|
||||
#include <stdint.h>
|
||||
|
||||
#define DEMO_ARTIFACT_FORMAT "ouroboros-hardened-demo-v1"
|
||||
#define DEMO_MEMORY_KIB 64u
|
||||
#define DEMO_ITERATIONS 3u
|
||||
#define DEMO_PARALLELISM 1u
|
||||
|
||||
static const uint8_t DEMO_SALT[16] = {
|
||||
0xF2u, 0xD5u, 0x18u, 0x63u, 0x9Au, 0x82u, 0x01u, 0x9Du,
|
||||
0xC2u, 0xD7u, 0xAFu, 0xA5u, 0xCDu, 0xB6u, 0xD8u, 0x71u
|
||||
};
|
||||
|
||||
static const uint8_t DEMO_NONCE[24] = {
|
||||
0x1Cu, 0xEFu, 0x79u, 0x0Du, 0x77u, 0x9Eu, 0x7Cu, 0x04u,
|
||||
0xE7u, 0xF0u, 0x66u, 0xDDu, 0x90u, 0xD0u, 0x80u, 0x70u,
|
||||
0x87u, 0x97u, 0x67u, 0x1Fu, 0x79u, 0xEFu, 0xC4u, 0xE4u
|
||||
};
|
||||
|
||||
static const uint8_t DEMO_CIPHERTEXT_AND_TAG[64] = {
|
||||
0x2Cu, 0x23u, 0xB2u, 0x7Eu, 0x95u, 0x62u, 0xB8u, 0xEDu,
|
||||
0x9Eu, 0x08u, 0xE0u, 0x6Du, 0xD9u, 0x9Du, 0xB4u, 0x91u,
|
||||
0x3Eu, 0x81u, 0x9Au, 0x77u, 0x8Bu, 0xB4u, 0x7Bu, 0x71u,
|
||||
0xBCu, 0x66u, 0x1Eu, 0x6Eu, 0x73u, 0x1Au, 0x81u, 0x54u,
|
||||
0xCDu, 0xB5u, 0x36u, 0xA4u, 0x76u, 0x7Eu, 0x9Bu, 0xF8u,
|
||||
0x53u, 0x3Eu, 0x03u, 0x1Du, 0xB8u, 0xE5u, 0xAEu, 0x7Au,
|
||||
0xADu, 0xB4u, 0x31u, 0xCFu, 0x12u, 0xD9u, 0xF9u, 0xC4u,
|
||||
0x5Fu, 0xA9u, 0xB9u, 0x4Bu, 0x80u, 0xDCu, 0xBBu, 0xDEu
|
||||
};
|
||||
|
||||
#endif // DEMO_ARTIFACT_H
|
||||
@@ -0,0 +1,39 @@
|
||||
// MIT License
|
||||
//
|
||||
// Copyright (c) 2026 Kevin Thomas
|
||||
//
|
||||
// Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
// of this software and associated documentation files (the "Software"), to deal
|
||||
// in the Software without restriction, including without limitation the rights
|
||||
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
// copies of the Software, and to permit persons to whom the Software is
|
||||
// furnished to do so, subject to the following conditions:
|
||||
//
|
||||
// The above copyright notice and this permission notice shall be included in all
|
||||
// copies or substantial portions of the Software.
|
||||
//
|
||||
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
// SOFTWARE.
|
||||
//
|
||||
// Author: Kevin Thomas
|
||||
// Email: kevin@mytechnotalent.com
|
||||
// GitHub: https://github.com/mytechnotalent
|
||||
// File: mbedtls_config.h
|
||||
// Desc: Configures the minimal mbedTLS cryptographic features required by
|
||||
// the Ouroboros AEAD engine on RP2350.
|
||||
// Created: 2026
|
||||
|
||||
#ifndef MBEDTLS_CONFIG_H
|
||||
#define MBEDTLS_CONFIG_H
|
||||
|
||||
#define MBEDTLS_CHACHA20_C
|
||||
#define MBEDTLS_CHACHAPOLY_C
|
||||
#define MBEDTLS_POLY1305_C
|
||||
#define MBEDTLS_PLATFORM_C
|
||||
|
||||
#endif // MBEDTLS_CONFIG_H
|
||||
Reference in new issue
Block a user