CCM — AES CCM mode encryption

Cipher block chaining - message authentication code (CCM) mode is an authenticated encryption algorithm designed to provide both authentication and confidentiality during data transfer. CCM combines counter mode encryption and CBC-MAC authentication. The CCM terminology "Message authentication code (MAC)" is called the "Message integrity check (MIC)" in Bluetooth terminology and also in this document.

The CCM block generates an encrypted keystream that is applied to input data using the XOR operation and generates the 4 byte MIC field in one operation. The CCM and radio can be configured to work synchronously. The CCM will encrypt in time for transmission and decrypt after receiving bytes into memory from the radio. All operations can complete within the packet RX or TX time. CCM on this device is implemented according to Bluetooth requirements and the algorithm as defined in IETF RFC3610, and depends on the AES-128 block cipher. A description of the CCM algorithm can also be found in NIST Special Publication 800-38C. The Bluetooth specification describes the configuration of counter mode blocks and encryption blocks to implement compliant encryption for BLE.

The CCM block uses EasyDMA to load key, counter mode blocks (including the nonce required), and to read/write plain text and cipher text.

The AES CCM supports three operations: key-stream generation, packet encryption, and packet decryption. All these operations are done in compliance with the Bluetooth specification.1

Figure 1. Key-stream generation followed by encryption or decryption. The shortcut is optional.
Key-stream generation followed by encryption or decryption and an optional shortcut.

Key-steam generation

A new key-stream needs to be generated before a new packet encryption or packet decryption operation can be started.

A key-stream is generated by triggering the KSGEN task and an ENDKSGEN event will be generated when the key-stream has been generated.

Key-stream generation, packet encryption, and packet decryption operations utilize the configuration specified in the data structure pointed to by CNFPTR. It is necessary to configure this pointer and its underlying data structure, and the MODE register before the KSGEN task is triggered.

The key-stream will be stored in the AES CCM’s temporary memory area, specified by the SCRATCHPTR, where it will be used in subsequent encryption and decryption operations.

For default length packets (MODE.LENGTH = Default) the size of the generated key-stream is 27 bytes. When using extended length packets (MODE.LENGTH = Extended) the MAXPACKETSIZE register specifies the length of the key-stream to be generated. The length of the generated key-stream must be greater or equal to the length of the subsequent packet payload to be encrypted or decrypted. The maximum length of the key-stream in extended mode is 251 bytes, which means that the maximum packet payload size is 251.

If a shortcut is used between ENDKSGEN event and CRYPT task, the INPTR pointer and the OUTPTR pointers must also be configured before the KSGEN task is triggered.

Encryption

During packet encryption, the AES CCM will read the unencrypted packet located in RAM at the address specified in the INPTR pointer, encrypt the packet and append a four byte long Message Integrity Check (MIC) field to the packet.

Encryption is started by triggering the CRYPT task with the MODE register set to ENCRYPTION. An ENDCRYPT event will be generated when packet encryption is completed

The AES CCM will also modify the length field of the packet to adjust for the appended MIC field, that is, add four bytes to the length, and store the resulting packet back into RAM at the address specified in the OUTPTR pointer, see Encryption.

Empty packets (length field is set to 0) will not be encrypted but instead moved unmodified through the AES CCM.

The CCM supports different widths of the LENGTH field in the data structure for encrypted packets. This is configured in the MODE register.

Figure 2. Encryption
AES CCM packet encryption

Decryption

During packet decryption, the AES CCM will read the encrypted packet located in RAM at the address specified in the INPTR pointer, decrypt the packet, authenticate the packet’s MIC field and generate the appropriate MIC status.

Decryption is started by triggering the CRYPT task with the MODE register set to DECRYPTION. An ENDCRYPT event will be generated when packet decryption is completed

The AES CCM will also modify the length field of the packet to adjust for the MIC field, that is, subtract four bytes from the length, and then store the decrypted packet into RAM at the address pointed to by the OUTPTR pointer, see Decryption.

The CCM is only able to decrypt packet payloads that are at least 5 bytes long, that is, 1 byte or more encrypted payload (EPL) and 4 bytes of MIC. The CCM will therefore generate a MIC error for packets where the length field is set to 1, 2, 3 or 4.

Empty packets (length field is set to 0) will not be decrypted but instead moved unmodified through the AES CCM, these packets will always pass the MIC check.

The CCM supports different widths of the LENGTH field in the data structure for decrypted packets. This is configured in the MODE register.

Figure 3. Decryption
AES CCM packet decryption

AES CCM and RADIO concurrent operation

The CCM module is able to encrypt/decrypt data synchronously to data being transmitted or received on the radio.

In order for the CCM module to run synchronously with the radio, the data rate setting in the MODE register needs to match the radio data rate. The settings in this register apply whenever either the KSGEN or CRYPT tasks are triggered.

The data rate setting of the MODE register can also be overridden on-the-fly during an ongoing encrypt/decrypt operation by the contents of the RATEOVERRIDE register. The data rate setting in this register applies whenever the RATEOVERRIDE task is triggered. This feature can be useful in cases where the radio data rate is changed during an ongoing packet transaction.

Encrypting packets on-the-fly in radio transmit mode

When the AES CCM is encrypting a packet on-the-fly at the same time as the radio is transmitting it, the radio must read the encrypted packet from the same memory location as the AES CCM is writing to.

The OUTPTR pointer in the AES CCM must therefore point to the same memory location as the PACKETPTR pointer in the radio, see Configuration of on-the-fly encryption.

Figure 4. Configuration of on-the-fly encryption
The OUTPTR pointer in the AES CCM pointing to the same memory location as the PACKETPTR pointer in the RADIO

In order to match the RADIO’s timing, the KSGEN task must be triggered early enough to allow the key-stream generation to complete before the encryption of the packet shall start.

For short packets (MODE.LENGTH = Default) the KSGEN task must be triggered no later than when the START task in the RADIO is triggered. In addition the shortcut between the ENDKSGEN event and the CRYPT task must be enabled. This use-case is illustrated in On-the-fly encryption of short packets (MODE.LENGTH = Default) using a PPI connection using a PPI connection between the READY event in the RADIO and the KSGEN task in the AES CCM.

For long packets (MODE.LENGTH = Extended) the key-stream generation will need to be started even earlier, for example at the time when the TXEN task in the RADIO is triggered.

Important: Refer to Timing specification for information about the time needed for generating a key-stream.
Figure 5. On-the-fly encryption of short packets (MODE.LENGTH = Default) using a PPI connection
KSGEN task triggered not later than triggering of the START task in the RADIO. The shortcut between the ENDKSGEN event and the CRYPT task enabled.

Decrypting packets on-the-fly in radio receive mode

When the AES CCM is decrypting a packet on-the-fly at the same time as the RADIO is receiving it, the AES CCM must read the encrypted packet from the same memory location as the RADIO is writing to.

The INPTR pointer in the AES CCM must therefore point to the same memory location as the PACKETPTR pointer in the RADIO, see Configuration of on-the-fly decryption.

Figure 6. Configuration of on-the-fly decryption
The INPTR pointer in the AES CCM pointing to the same memory location as the PACKETPTR pointer in the RADIO

In order to match the RADIO’s timing, the KSGEN task must be triggered early enough to allow the key-stream generation to complete before the decryption of the packet shall start.

For short packets (MODE.LENGTH = Default) the KSGEN task must be triggered no later than when the START task in the RADIO is triggered. In addition, the CRYPT task must be triggered no earlier than when the ADDRESS event is generated by the RADIO.

If the CRYPT task is triggered exactly at the same time as the ADDRESS event is generated by the RADIO, the AES CCM will guarantee that the decryption is completed no later than when the END event in the RADIO is generated.

This use-case is illustrated in On-the-fly decryption of short packets (MODE.LENGTH = Default) using a PPI connection using a PPI connection between the ADDRESS event in the RADIO and the CRYPT task in the AES CCM. The KSGEN task is triggered from the READY event in the RADIO through a PPI connection.

For long packets (MODE.LENGTH = Extended) the key-stream generation will need to be started even earlier, for example at the time when the RXEN task in the RADIO is triggered.

Important: Refer to Timing specification for information about the time needed for generating a key-stream.
Figure 7. On-the-fly decryption of short packets (MODE.LENGTH = Default) using a PPI connection
The CRYPT task triggered at the same time as the ADDRESS event generated by the RADIO. Decryption completed no later than the END event in the RADIO.

CCM data structure

The CCM data structure is located in Data RAM at the memory location specified by the CNFPTR pointer register.

Table 1. CCM data structure overview
PropertyAddress offsetDescription
KEY016 byte AES key
PKTCTR16Octet0 (LSO) of packet counter
 17Octet1 of packet counter
 18Octet2 of packet counter
 19Octet3 of packet counter
 20Bit 6 – Bit 0: Octet4 (7 most significant bits of packet counter, with Bit 6 being the most significant bit) Bit7: Ignored
 21Ignored
 22Ignored
 23Ignored
 24Bit 0: Direction bit Bit 7 – Bit 1: Zero padded
IV258 byte initialization vector (IV) Octet0 (LSO) of IV, Octet1 of IV, … , Octet7 (MSO) of IV

The NONCE vector (as specified by the Bluetooth Core Specification) will be generated by hardware based on the information specified in the CCM data structure from CCM data structure overview .

Table 2. Data structure for unencrypted packet
PropertyAddress offsetDescription
HEADER0Packet Header
LENGTH1Number of bytes in unencrypted payload
RFU2Reserved Future Use
PAYLOAD3Unencrypted payload
Table 3. Data structure for encrypted packet
PropertyAddress offsetDescription
HEADER0Packet Header
LENGTH1Number of bytes in encrypted payload including length of MIC
Important: LENGTH will be 0 for empty packets since the MIC is not added to empty packets
RFU2Reserved Future Use
PAYLOAD3Encrypted payload
MIC3 + payload lengthENCRYPT: 4 bytes encrypted MIC
Important: MIC is not added to empty packets

EasyDMA and ERROR event

The CCM implements an EasyDMA mechanism for reading and writing to the RAM.

In cases where the CPU and other EasyDMA enabled peripherals are accessing the same RAM block at the same time, a high level of bus collisions may cause too slow operation for correct on the fly encryption. In this case the ERROR event will be generated.

The EasyDMA will have finished accessing the RAM when the ENDKSGEN and ENDCRYPT events are generated.

If the CNFPTR, SCRATCHPTR, INPTR and the OUTPTR are not pointing to the Data RAM region, an EasyDMA transfer may result in a HardFault or RAM corruption. See Memory for more information about the different memory regions.

Registers

Table 4. Instances
Base addressPeripheralInstanceDescriptionConfiguration
0x4000F000CCMCCM

AES CCM mode encryption

  
Table 5. Register overview
RegisterOffsetDescription
TASKS_KSGEN0x000

Start generation of key-stream. This operation will stop by itself when completed.

 
TASKS_CRYPT0x004

Start encryption/decryption. This operation will stop by itself when completed.

 
TASKS_STOP0x008

Stop encryption/decryption

 
TASKS_RATEOVERRIDE0x00C

Override DATARATE setting in MODE register with the contents of the RATEOVERRIDE register for any ongoing encryption/decryption

 
EVENTS_ENDKSGEN0x100

Key-stream generation complete

 
EVENTS_ENDCRYPT0x104

Encrypt/decrypt complete

 
EVENTS_ERROR0x108

CCM error event

Deprecated

SHORTS0x200

Shortcuts between local events and tasks

 
INTENSET0x304

Enable interrupt

 
INTENCLR0x308

Disable interrupt

 
MICSTATUS0x400

MIC check result

 
ENABLE0x500

Enable

 
MODE0x504

Operation mode

 
CNFPTR0x508

Pointer to data structure holding AES key and NONCE vector

 
INPTR0x50C

Input pointer

 
OUTPTR0x510

Output pointer

 
SCRATCHPTR0x514

Pointer to data area used for temporary storage

 
MAXPACKETSIZE0x518

Length of key-stream generated when MODE.LENGTH = Extended.

 
RATEOVERRIDE0x51C

Data rate override setting.

 

TASKS_KSGEN

Address offset: 0x000

Start generation of key-stream. This operation will stop by itself when completed.

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
AW

TASKS_KSGEN

  

Start generation of key-stream. This operation will stop by itself when completed.

   

Trigger

1

Trigger task

TASKS_CRYPT

Address offset: 0x004

Start encryption/decryption. This operation will stop by itself when completed.

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
AW

TASKS_CRYPT

  

Start encryption/decryption. This operation will stop by itself when completed.

   

Trigger

1

Trigger task

TASKS_STOP

Address offset: 0x008

Stop encryption/decryption

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
AW

TASKS_STOP

  

Stop encryption/decryption

   

Trigger

1

Trigger task

TASKS_RATEOVERRIDE

Address offset: 0x00C

Override DATARATE setting in MODE register with the contents of the RATEOVERRIDE register for any ongoing encryption/decryption

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
AW

TASKS_RATEOVERRIDE

  

Override DATARATE setting in MODE register with the contents of the RATEOVERRIDE register for any ongoing encryption/decryption

   

Trigger

1

Trigger task

EVENTS_ENDKSGEN

Address offset: 0x100

Key-stream generation complete

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

EVENTS_ENDKSGEN

  

Key-stream generation complete

   

NotGenerated

0

Event not generated

   

Generated

1

Event generated

EVENTS_ENDCRYPT

Address offset: 0x104

Encrypt/decrypt complete

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

EVENTS_ENDCRYPT

  

Encrypt/decrypt complete

   

NotGenerated

0

Event not generated

   

Generated

1

Event generated

EVENTS_ERROR ( Deprecated )

Address offset: 0x108

CCM error event

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

EVENTS_ERROR

  

CCM error event

Deprecated

   

NotGenerated

0

Event not generated

   

Generated

1

Event generated

SHORTS

Address offset: 0x200

Shortcuts between local events and tasks

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

ENDKSGEN_CRYPT

  

Shortcut between event ENDKSGEN and task CRYPT

   

Disabled

0

Disable shortcut

   

Enabled

1

Enable shortcut

INTENSET

Address offset: 0x304

Enable interrupt

Bit number313029282726252423222120191817161514131211109876543210
ID                             CBA
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

ENDKSGEN

  

Write '1' to enable interrupt for event ENDKSGEN

   

Set

1

Enable

   

Disabled

0

Read: Disabled

   

Enabled

1

Read: Enabled

BRW

ENDCRYPT

  

Write '1' to enable interrupt for event ENDCRYPT

   

Set

1

Enable

   

Disabled

0

Read: Disabled

   

Enabled

1

Read: Enabled

CRW

ERROR

  

Write '1' to enable interrupt for event ERROR

Deprecated

   

Set

1

Enable

   

Disabled

0

Read: Disabled

   

Enabled

1

Read: Enabled

INTENCLR

Address offset: 0x308

Disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
ID                             CBA
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

ENDKSGEN

  

Write '1' to disable interrupt for event ENDKSGEN

   

Clear

1

Disable

   

Disabled

0

Read: Disabled

   

Enabled

1

Read: Enabled

BRW

ENDCRYPT

  

Write '1' to disable interrupt for event ENDCRYPT

   

Clear

1

Disable

   

Disabled

0

Read: Disabled

   

Enabled

1

Read: Enabled

CRW

ERROR

  

Write '1' to disable interrupt for event ERROR

Deprecated

   

Clear

1

Disable

   

Disabled

0

Read: Disabled

   

Enabled

1

Read: Enabled

MICSTATUS

Address offset: 0x400

MIC check result

Bit number313029282726252423222120191817161514131211109876543210
ID                               A
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
AR

MICSTATUS

  

The result of the MIC check performed during the previous decryption operation

   

CheckFailed

0

MIC check failed

   

CheckPassed

1

MIC check passed

ENABLE

Address offset: 0x500

Enable

Bit number313029282726252423222120191817161514131211109876543210
ID                              AA
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

ENABLE

  

Enable or disable CCM

   

Disabled

0

Disable

   

Enabled

2

Enable

MODE

Address offset: 0x504

Operation mode

Bit number313029282726252423222120191817161514131211109876543210
ID       C      BB              A
Reset 0x0000000100000000000000000000000000000001
IDAccessFieldValue IDValueDescription
ARW

MODE

  

The mode of operation to be used. The settings in this register apply whenever either the KSGEN or CRYPT tasks are triggered.

   

Encryption

0

AES CCM packet encryption mode

   

Decryption

1

AES CCM packet decryption mode

BRW

DATARATE

  

Radio data rate that the CCM shall run synchronous with

   

1Mbit

0

1 Mbps

   

2Mbit

1

2 Mbps

   

125Kbps

2

125 Kbps

   

500Kbps

3

500 Kbps

CRW

LENGTH

  

Packet length configuration

   

Default

0

Default length. Effective length of LENGTH field in encrypted/decrypted packet is 5 bits. A key-stream for packet payloads up to 27 bytes will be generated.

   

Extended

1

Extended length. Effective length of LENGTH field in encrypted/decrypted packet is 8 bits. A key-stream for packet payloads up to MAXPACKETSIZE bytes will be generated.

CNFPTR

Address offset: 0x508

Pointer to data structure holding AES key and NONCE vector

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

CNFPTR

  

Pointer to the data structure holding the AES key and the CCM NONCE vector (see Table 1 CCM data structure overview)

INPTR

Address offset: 0x50C

Input pointer

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

INPTR

  

Input pointer

OUTPTR

Address offset: 0x510

Output pointer

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

OUTPTR

  

Output pointer

SCRATCHPTR

Address offset: 0x514

Pointer to data area used for temporary storage

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

SCRATCHPTR

  

Pointer to a scratch data area used for temporary storage during key-stream generation, MIC generation and encryption/decryption.

The scratch area is used for temporary storage of data during key-stream generation and encryption.

When MODE.LENGTH = Default, a space of 43 bytes is required for this temporary storage. MODE.LENGTH = Extended (16 + MAXPACKETSIZE) bytes of storage is required.

MAXPACKETSIZE

Address offset: 0x518

Length of key-stream generated when MODE.LENGTH = Extended.

Bit number313029282726252423222120191817161514131211109876543210
ID                        AAAAAAAA
Reset 0x000000FB00000000000000000000000011111011
IDAccessFieldValue IDValueDescription
ARW

MAXPACKETSIZE

 

[0x001B..0x00FB]

Length of key-stream generated when MODE.LENGTH = Extended. This value must be greater or equal to the subsequent packet payload to be encrypted/decrypted.

RATEOVERRIDE

Address offset: 0x51C

Data rate override setting.

Override value to be used instead of the setting of MODE.DATARATE. This override value applies when the RATEOVERRIDE task is triggered.

Bit number313029282726252423222120191817161514131211109876543210
ID                              AA
Reset 0x0000000000000000000000000000000000000000
IDAccessFieldValue IDValueDescription
ARW

RATEOVERRIDE

  

Data rate override setting.

   

1Mbit

0

1 Mbps

   

2Mbit

1

2 Mbps

   

125Kbps

2

125 Kbps

   

500Kbps

3

500 Kbps

Electrical specification

Timing specification

SymbolDescriptionMin.Typ.Max.Units
tkgen

Time needed for key-stream generation (given priority access to destination RAM block).

......µs
1 Bluetooth AES CCM 128 bit block encryption, see Bluetooth Core specification Version 4.0.