mirror of
https://github.com/taigrr/arduinolibs
synced 2025-01-18 04:33:12 -08:00
319 lines
39 KiB
HTML
319 lines
39 KiB
HTML
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
|
<html xmlns="http://www.w3.org/1999/xhtml">
|
|
<head>
|
|
<meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/>
|
|
<meta http-equiv="X-UA-Compatible" content="IE=9"/>
|
|
<meta name="generator" content="Doxygen 1.8.6"/>
|
|
<title>Arduino Cryptography Library: ChaCha.cpp Source File</title>
|
|
<link href="tabs.css" rel="stylesheet" type="text/css"/>
|
|
<script type="text/javascript" src="jquery.js"></script>
|
|
<script type="text/javascript" src="dynsections.js"></script>
|
|
<link href="search/search.css" rel="stylesheet" type="text/css"/>
|
|
<script type="text/javascript" src="search/search.js"></script>
|
|
<script type="text/javascript">
|
|
$(document).ready(function() { searchBox.OnSelectItem(0); });
|
|
</script>
|
|
<link href="doxygen.css" rel="stylesheet" type="text/css" />
|
|
</head>
|
|
<body>
|
|
<div id="top"><!-- do not remove this div, it is closed by doxygen! -->
|
|
<div id="titlearea">
|
|
<table cellspacing="0" cellpadding="0">
|
|
<tbody>
|
|
<tr style="height: 56px;">
|
|
<td style="padding-left: 0.5em;">
|
|
<div id="projectname">Arduino Cryptography Library
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
</div>
|
|
<!-- end header part -->
|
|
<!-- Generated by Doxygen 1.8.6 -->
|
|
<script type="text/javascript">
|
|
var searchBox = new SearchBox("searchBox", "search",false,'Search');
|
|
</script>
|
|
<div id="navrow1" class="tabs">
|
|
<ul class="tablist">
|
|
<li><a href="index.html"><span>Main Page</span></a></li>
|
|
<li><a href="pages.html"><span>Related Pages</span></a></li>
|
|
<li><a href="annotated.html"><span>Classes</span></a></li>
|
|
<li class="current"><a href="files.html"><span>Files</span></a></li>
|
|
<li>
|
|
<div id="MSearchBox" class="MSearchBoxInactive">
|
|
<span class="left">
|
|
<img id="MSearchSelect" src="search/mag_sel.png"
|
|
onmouseover="return searchBox.OnSearchSelectShow()"
|
|
onmouseout="return searchBox.OnSearchSelectHide()"
|
|
alt=""/>
|
|
<input type="text" id="MSearchField" value="Search" accesskey="S"
|
|
onfocus="searchBox.OnSearchFieldFocus(true)"
|
|
onblur="searchBox.OnSearchFieldFocus(false)"
|
|
onkeyup="searchBox.OnSearchFieldChange(event)"/>
|
|
</span><span class="right">
|
|
<a id="MSearchClose" href="javascript:searchBox.CloseResultsWindow()"><img id="MSearchCloseImg" border="0" src="search/close.png" alt=""/></a>
|
|
</span>
|
|
</div>
|
|
</li>
|
|
</ul>
|
|
</div>
|
|
<div id="navrow2" class="tabs2">
|
|
<ul class="tablist">
|
|
<li><a href="files.html"><span>File List</span></a></li>
|
|
</ul>
|
|
</div>
|
|
<!-- window showing the filter options -->
|
|
<div id="MSearchSelectWindow"
|
|
onmouseover="return searchBox.OnSearchSelectShow()"
|
|
onmouseout="return searchBox.OnSearchSelectHide()"
|
|
onkeydown="return searchBox.OnSearchSelectKey(event)">
|
|
<a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(0)"><span class="SelectionMark"> </span>All</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(1)"><span class="SelectionMark"> </span>Classes</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(2)"><span class="SelectionMark"> </span>Files</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(3)"><span class="SelectionMark"> </span>Functions</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(4)"><span class="SelectionMark"> </span>Variables</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(5)"><span class="SelectionMark"> </span>Enumerations</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(6)"><span class="SelectionMark"> </span>Enumerator</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(7)"><span class="SelectionMark"> </span>Pages</a></div>
|
|
|
|
<!-- iframe showing the search results (closed by default) -->
|
|
<div id="MSearchResultsWindow">
|
|
<iframe src="javascript:void(0)" frameborder="0"
|
|
name="MSearchResults" id="MSearchResults">
|
|
</iframe>
|
|
</div>
|
|
|
|
<div id="nav-path" class="navpath">
|
|
<ul>
|
|
<li class="navelem"><a class="el" href="dir_bc0718b08fb2015b8e59c47b2805f60c.html">libraries</a></li><li class="navelem"><a class="el" href="dir_e2ce51835550ba18edf07a8311722290.html">Crypto</a></li> </ul>
|
|
</div>
|
|
</div><!-- top -->
|
|
<div class="header">
|
|
<div class="headertitle">
|
|
<div class="title">ChaCha.cpp</div> </div>
|
|
</div><!--header-->
|
|
<div class="contents">
|
|
<div class="fragment"><div class="line"><a name="l00001"></a><span class="lineno"> 1</span> <span class="comment">/*</span></div>
|
|
<div class="line"><a name="l00002"></a><span class="lineno"> 2</span> <span class="comment"> * Copyright (C) 2015 Southern Storm Software, Pty Ltd.</span></div>
|
|
<div class="line"><a name="l00003"></a><span class="lineno"> 3</span> <span class="comment"> *</span></div>
|
|
<div class="line"><a name="l00004"></a><span class="lineno"> 4</span> <span class="comment"> * Permission is hereby granted, free of charge, to any person obtaining a</span></div>
|
|
<div class="line"><a name="l00005"></a><span class="lineno"> 5</span> <span class="comment"> * copy of this software and associated documentation files (the "Software"),</span></div>
|
|
<div class="line"><a name="l00006"></a><span class="lineno"> 6</span> <span class="comment"> * to deal in the Software without restriction, including without limitation</span></div>
|
|
<div class="line"><a name="l00007"></a><span class="lineno"> 7</span> <span class="comment"> * the rights to use, copy, modify, merge, publish, distribute, sublicense,</span></div>
|
|
<div class="line"><a name="l00008"></a><span class="lineno"> 8</span> <span class="comment"> * and/or sell copies of the Software, and to permit persons to whom the</span></div>
|
|
<div class="line"><a name="l00009"></a><span class="lineno"> 9</span> <span class="comment"> * Software is furnished to do so, subject to the following conditions:</span></div>
|
|
<div class="line"><a name="l00010"></a><span class="lineno"> 10</span> <span class="comment"> *</span></div>
|
|
<div class="line"><a name="l00011"></a><span class="lineno"> 11</span> <span class="comment"> * The above copyright notice and this permission notice shall be included</span></div>
|
|
<div class="line"><a name="l00012"></a><span class="lineno"> 12</span> <span class="comment"> * in all copies or substantial portions of the Software.</span></div>
|
|
<div class="line"><a name="l00013"></a><span class="lineno"> 13</span> <span class="comment"> *</span></div>
|
|
<div class="line"><a name="l00014"></a><span class="lineno"> 14</span> <span class="comment"> * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS</span></div>
|
|
<div class="line"><a name="l00015"></a><span class="lineno"> 15</span> <span class="comment"> * OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,</span></div>
|
|
<div class="line"><a name="l00016"></a><span class="lineno"> 16</span> <span class="comment"> * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE</span></div>
|
|
<div class="line"><a name="l00017"></a><span class="lineno"> 17</span> <span class="comment"> * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER</span></div>
|
|
<div class="line"><a name="l00018"></a><span class="lineno"> 18</span> <span class="comment"> * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING</span></div>
|
|
<div class="line"><a name="l00019"></a><span class="lineno"> 19</span> <span class="comment"> * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER</span></div>
|
|
<div class="line"><a name="l00020"></a><span class="lineno"> 20</span> <span class="comment"> * DEALINGS IN THE SOFTWARE.</span></div>
|
|
<div class="line"><a name="l00021"></a><span class="lineno"> 21</span> <span class="comment"> */</span></div>
|
|
<div class="line"><a name="l00022"></a><span class="lineno"> 22</span> </div>
|
|
<div class="line"><a name="l00023"></a><span class="lineno"> 23</span> <span class="preprocessor">#include "ChaCha.h"</span></div>
|
|
<div class="line"><a name="l00024"></a><span class="lineno"> 24</span> <span class="preprocessor">#include "Crypto.h"</span></div>
|
|
<div class="line"><a name="l00025"></a><span class="lineno"> 25</span> <span class="preprocessor">#include "utility/RotateUtil.h"</span></div>
|
|
<div class="line"><a name="l00026"></a><span class="lineno"> 26</span> <span class="preprocessor">#include "utility/EndianUtil.h"</span></div>
|
|
<div class="line"><a name="l00027"></a><span class="lineno"> 27</span> <span class="preprocessor">#include "utility/ProgMemUtil.h"</span></div>
|
|
<div class="line"><a name="l00028"></a><span class="lineno"> 28</span> <span class="preprocessor">#include <string.h></span></div>
|
|
<div class="line"><a name="l00029"></a><span class="lineno"> 29</span> </div>
|
|
<div class="line"><a name="l00047"></a><span class="lineno"><a class="line" href="classChaCha.html#a5831811b705d3c80e97f0242597f0c7e"> 47</a></span> <a class="code" href="classChaCha.html#a5831811b705d3c80e97f0242597f0c7e">ChaCha::ChaCha</a>(uint8_t numRounds)</div>
|
|
<div class="line"><a name="l00048"></a><span class="lineno"> 48</span>  : rounds(numRounds)</div>
|
|
<div class="line"><a name="l00049"></a><span class="lineno"> 49</span>  , posn(64)</div>
|
|
<div class="line"><a name="l00050"></a><span class="lineno"> 50</span> {</div>
|
|
<div class="line"><a name="l00051"></a><span class="lineno"> 51</span> }</div>
|
|
<div class="line"><a name="l00052"></a><span class="lineno"> 52</span> </div>
|
|
<div class="line"><a name="l00053"></a><span class="lineno"> 53</span> ChaCha::~ChaCha()</div>
|
|
<div class="line"><a name="l00054"></a><span class="lineno"> 54</span> {</div>
|
|
<div class="line"><a name="l00055"></a><span class="lineno"> 55</span>  clean(block);</div>
|
|
<div class="line"><a name="l00056"></a><span class="lineno"> 56</span>  clean(stream);</div>
|
|
<div class="line"><a name="l00057"></a><span class="lineno"> 57</span> }</div>
|
|
<div class="line"><a name="l00058"></a><span class="lineno"> 58</span> </div>
|
|
<div class="line"><a name="l00059"></a><span class="lineno"><a class="line" href="classChaCha.html#af286083291fab2bd36dc7ad1f54d5cd7"> 59</a></span> <span class="keywordtype">size_t</span> <a class="code" href="classChaCha.html#af286083291fab2bd36dc7ad1f54d5cd7">ChaCha::keySize</a>()<span class="keyword"> const</span></div>
|
|
<div class="line"><a name="l00060"></a><span class="lineno"> 60</span> <span class="keyword"></span>{</div>
|
|
<div class="line"><a name="l00061"></a><span class="lineno"> 61</span>  <span class="comment">// Default key size is 256-bit, but any key size is allowed.</span></div>
|
|
<div class="line"><a name="l00062"></a><span class="lineno"> 62</span>  <span class="keywordflow">return</span> 32;</div>
|
|
<div class="line"><a name="l00063"></a><span class="lineno"> 63</span> }</div>
|
|
<div class="line"><a name="l00064"></a><span class="lineno"> 64</span> </div>
|
|
<div class="line"><a name="l00065"></a><span class="lineno"><a class="line" href="classChaCha.html#afaa3df343a7d07976bd7e03a0c1bf43c"> 65</a></span> <span class="keywordtype">size_t</span> <a class="code" href="classChaCha.html#afaa3df343a7d07976bd7e03a0c1bf43c">ChaCha::ivSize</a>()<span class="keyword"> const</span></div>
|
|
<div class="line"><a name="l00066"></a><span class="lineno"> 66</span> <span class="keyword"></span>{</div>
|
|
<div class="line"><a name="l00067"></a><span class="lineno"> 67</span>  <span class="comment">// We return 8 but we also support 12-byte nonces in setIV().</span></div>
|
|
<div class="line"><a name="l00068"></a><span class="lineno"> 68</span>  <span class="keywordflow">return</span> 8;</div>
|
|
<div class="line"><a name="l00069"></a><span class="lineno"> 69</span> }</div>
|
|
<div class="line"><a name="l00070"></a><span class="lineno"> 70</span> </div>
|
|
<div class="line"><a name="l00087"></a><span class="lineno"><a class="line" href="classChaCha.html#a6b2bdffbd3705e388bb458edb2f40c90"> 87</a></span> <span class="keywordtype">bool</span> <a class="code" href="classChaCha.html#a6b2bdffbd3705e388bb458edb2f40c90">ChaCha::setKey</a>(<span class="keyword">const</span> uint8_t *key, <span class="keywordtype">size_t</span> len)</div>
|
|
<div class="line"><a name="l00088"></a><span class="lineno"> 88</span> {</div>
|
|
<div class="line"><a name="l00089"></a><span class="lineno"> 89</span>  <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">char</span> tag128[] PROGMEM = <span class="stringliteral">"expand 16-byte k"</span>;</div>
|
|
<div class="line"><a name="l00090"></a><span class="lineno"> 90</span>  <span class="keyword">static</span> <span class="keyword">const</span> <span class="keywordtype">char</span> tag256[] PROGMEM = <span class="stringliteral">"expand 32-byte k"</span>;</div>
|
|
<div class="line"><a name="l00091"></a><span class="lineno"> 91</span>  <span class="keywordflow">if</span> (len <= 16) {</div>
|
|
<div class="line"><a name="l00092"></a><span class="lineno"> 92</span>  memcpy_P(block, tag128, 16);</div>
|
|
<div class="line"><a name="l00093"></a><span class="lineno"> 93</span>  memcpy(block + 16, key, len);</div>
|
|
<div class="line"><a name="l00094"></a><span class="lineno"> 94</span>  memcpy(block + 32, key, len);</div>
|
|
<div class="line"><a name="l00095"></a><span class="lineno"> 95</span>  <span class="keywordflow">if</span> (len < 16) {</div>
|
|
<div class="line"><a name="l00096"></a><span class="lineno"> 96</span>  memset(block + 16 + len, 0, 16 - len);</div>
|
|
<div class="line"><a name="l00097"></a><span class="lineno"> 97</span>  memset(block + 32 + len, 0, 16 - len);</div>
|
|
<div class="line"><a name="l00098"></a><span class="lineno"> 98</span>  }</div>
|
|
<div class="line"><a name="l00099"></a><span class="lineno"> 99</span>  } <span class="keywordflow">else</span> {</div>
|
|
<div class="line"><a name="l00100"></a><span class="lineno"> 100</span>  <span class="keywordflow">if</span> (len > 32)</div>
|
|
<div class="line"><a name="l00101"></a><span class="lineno"> 101</span>  len = 32;</div>
|
|
<div class="line"><a name="l00102"></a><span class="lineno"> 102</span>  memcpy_P(block, tag256, 16);</div>
|
|
<div class="line"><a name="l00103"></a><span class="lineno"> 103</span>  memcpy(block + 16, key, len);</div>
|
|
<div class="line"><a name="l00104"></a><span class="lineno"> 104</span>  <span class="keywordflow">if</span> (len < 32)</div>
|
|
<div class="line"><a name="l00105"></a><span class="lineno"> 105</span>  memset(block + 16 + len, 0, 32 - len);</div>
|
|
<div class="line"><a name="l00106"></a><span class="lineno"> 106</span>  }</div>
|
|
<div class="line"><a name="l00107"></a><span class="lineno"> 107</span>  posn = 64;</div>
|
|
<div class="line"><a name="l00108"></a><span class="lineno"> 108</span>  <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
|
<div class="line"><a name="l00109"></a><span class="lineno"> 109</span> }</div>
|
|
<div class="line"><a name="l00110"></a><span class="lineno"> 110</span> </div>
|
|
<div class="line"><a name="l00111"></a><span class="lineno"><a class="line" href="classChaCha.html#a734f3246b1e6810c63637b8cda26b259"> 111</a></span> <span class="keywordtype">bool</span> <a class="code" href="classChaCha.html#a734f3246b1e6810c63637b8cda26b259">ChaCha::setIV</a>(<span class="keyword">const</span> uint8_t *iv, <span class="keywordtype">size_t</span> len)</div>
|
|
<div class="line"><a name="l00112"></a><span class="lineno"> 112</span> {</div>
|
|
<div class="line"><a name="l00113"></a><span class="lineno"> 113</span>  <span class="comment">// From draft-nir-cfrg-chacha20-poly1305-10.txt, we can use either</span></div>
|
|
<div class="line"><a name="l00114"></a><span class="lineno"> 114</span>  <span class="comment">// 64-bit or 96-bit nonces. The 96-bit nonce consists of the high</span></div>
|
|
<div class="line"><a name="l00115"></a><span class="lineno"> 115</span>  <span class="comment">// word of the counter prepended to a regular 64-bit nonce for ChaCha.</span></div>
|
|
<div class="line"><a name="l00116"></a><span class="lineno"> 116</span>  <span class="keywordflow">if</span> (len == 8) {</div>
|
|
<div class="line"><a name="l00117"></a><span class="lineno"> 117</span>  memset(block + 48, 0, 8);</div>
|
|
<div class="line"><a name="l00118"></a><span class="lineno"> 118</span>  memcpy(block + 56, iv, len);</div>
|
|
<div class="line"><a name="l00119"></a><span class="lineno"> 119</span>  posn = 64;</div>
|
|
<div class="line"><a name="l00120"></a><span class="lineno"> 120</span>  <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
|
<div class="line"><a name="l00121"></a><span class="lineno"> 121</span>  } <span class="keywordflow">else</span> <span class="keywordflow">if</span> (len == 12) {</div>
|
|
<div class="line"><a name="l00122"></a><span class="lineno"> 122</span>  memset(block + 48, 0, 4);</div>
|
|
<div class="line"><a name="l00123"></a><span class="lineno"> 123</span>  memcpy(block + 52, iv, len);</div>
|
|
<div class="line"><a name="l00124"></a><span class="lineno"> 124</span>  posn = 64;</div>
|
|
<div class="line"><a name="l00125"></a><span class="lineno"> 125</span>  <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
|
<div class="line"><a name="l00126"></a><span class="lineno"> 126</span>  } <span class="keywordflow">else</span> {</div>
|
|
<div class="line"><a name="l00127"></a><span class="lineno"> 127</span>  <span class="keywordflow">return</span> <span class="keyword">false</span>;</div>
|
|
<div class="line"><a name="l00128"></a><span class="lineno"> 128</span>  }</div>
|
|
<div class="line"><a name="l00129"></a><span class="lineno"> 129</span> }</div>
|
|
<div class="line"><a name="l00130"></a><span class="lineno"> 130</span> </div>
|
|
<div class="line"><a name="l00145"></a><span class="lineno"><a class="line" href="classChaCha.html#acab9109b7189ea88d9e5417a3a209eac"> 145</a></span> <span class="keywordtype">bool</span> <a class="code" href="classChaCha.html#acab9109b7189ea88d9e5417a3a209eac">ChaCha::setCounter</a>(<span class="keyword">const</span> uint8_t *counter, <span class="keywordtype">size_t</span> len)</div>
|
|
<div class="line"><a name="l00146"></a><span class="lineno"> 146</span> {</div>
|
|
<div class="line"><a name="l00147"></a><span class="lineno"> 147</span>  <span class="comment">// Normally both the IV and the counter are 8 bytes in length.</span></div>
|
|
<div class="line"><a name="l00148"></a><span class="lineno"> 148</span>  <span class="comment">// However, if the IV was 12 bytes, then a 4 byte counter can be used.</span></div>
|
|
<div class="line"><a name="l00149"></a><span class="lineno"> 149</span>  <span class="keywordflow">if</span> (len == 4 || len == 8) {</div>
|
|
<div class="line"><a name="l00150"></a><span class="lineno"> 150</span>  memcpy(block + 48, counter, len);</div>
|
|
<div class="line"><a name="l00151"></a><span class="lineno"> 151</span>  posn = 64;</div>
|
|
<div class="line"><a name="l00152"></a><span class="lineno"> 152</span>  <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
|
<div class="line"><a name="l00153"></a><span class="lineno"> 153</span>  } <span class="keywordflow">else</span> {</div>
|
|
<div class="line"><a name="l00154"></a><span class="lineno"> 154</span>  <span class="keywordflow">return</span> <span class="keyword">false</span>;</div>
|
|
<div class="line"><a name="l00155"></a><span class="lineno"> 155</span>  }</div>
|
|
<div class="line"><a name="l00156"></a><span class="lineno"> 156</span> }</div>
|
|
<div class="line"><a name="l00157"></a><span class="lineno"> 157</span> </div>
|
|
<div class="line"><a name="l00158"></a><span class="lineno"><a class="line" href="classChaCha.html#acd4fff140b8871c233d9a31abf753ed8"> 158</a></span> <span class="keywordtype">void</span> <a class="code" href="classChaCha.html#acd4fff140b8871c233d9a31abf753ed8">ChaCha::encrypt</a>(uint8_t *output, <span class="keyword">const</span> uint8_t *input, <span class="keywordtype">size_t</span> len)</div>
|
|
<div class="line"><a name="l00159"></a><span class="lineno"> 159</span> {</div>
|
|
<div class="line"><a name="l00160"></a><span class="lineno"> 160</span>  <span class="keywordflow">while</span> (len > 0) {</div>
|
|
<div class="line"><a name="l00161"></a><span class="lineno"> 161</span>  <span class="keywordflow">if</span> (posn >= 64) {</div>
|
|
<div class="line"><a name="l00162"></a><span class="lineno"> 162</span>  <span class="comment">// Generate a new encrypted counter block.</span></div>
|
|
<div class="line"><a name="l00163"></a><span class="lineno"> 163</span>  <a class="code" href="classChaCha.html#a41ac3262e52ff49dcd916d0b3b2e2038">hashCore</a>((uint32_t *)stream, (<span class="keyword">const</span> uint32_t *)block, rounds);</div>
|
|
<div class="line"><a name="l00164"></a><span class="lineno"> 164</span>  posn = 0;</div>
|
|
<div class="line"><a name="l00165"></a><span class="lineno"> 165</span> </div>
|
|
<div class="line"><a name="l00166"></a><span class="lineno"> 166</span>  <span class="comment">// Increment the counter, taking care not to reveal</span></div>
|
|
<div class="line"><a name="l00167"></a><span class="lineno"> 167</span>  <span class="comment">// any timing information about the starting value.</span></div>
|
|
<div class="line"><a name="l00168"></a><span class="lineno"> 168</span>  <span class="comment">// We iterate through the entire counter region even</span></div>
|
|
<div class="line"><a name="l00169"></a><span class="lineno"> 169</span>  <span class="comment">// if we could stop earlier because a byte is non-zero.</span></div>
|
|
<div class="line"><a name="l00170"></a><span class="lineno"> 170</span>  uint16_t temp = 1;</div>
|
|
<div class="line"><a name="l00171"></a><span class="lineno"> 171</span>  uint8_t index = 48;</div>
|
|
<div class="line"><a name="l00172"></a><span class="lineno"> 172</span>  <span class="keywordflow">while</span> (index < 56) {</div>
|
|
<div class="line"><a name="l00173"></a><span class="lineno"> 173</span>  temp += block[index];</div>
|
|
<div class="line"><a name="l00174"></a><span class="lineno"> 174</span>  block[index] = (uint8_t)temp;</div>
|
|
<div class="line"><a name="l00175"></a><span class="lineno"> 175</span>  temp >>= 8;</div>
|
|
<div class="line"><a name="l00176"></a><span class="lineno"> 176</span>  ++index;</div>
|
|
<div class="line"><a name="l00177"></a><span class="lineno"> 177</span>  }</div>
|
|
<div class="line"><a name="l00178"></a><span class="lineno"> 178</span>  }</div>
|
|
<div class="line"><a name="l00179"></a><span class="lineno"> 179</span>  uint8_t templen = 64 - posn;</div>
|
|
<div class="line"><a name="l00180"></a><span class="lineno"> 180</span>  <span class="keywordflow">if</span> (templen > len)</div>
|
|
<div class="line"><a name="l00181"></a><span class="lineno"> 181</span>  templen = len;</div>
|
|
<div class="line"><a name="l00182"></a><span class="lineno"> 182</span>  len -= templen;</div>
|
|
<div class="line"><a name="l00183"></a><span class="lineno"> 183</span>  <span class="keywordflow">while</span> (templen > 0) {</div>
|
|
<div class="line"><a name="l00184"></a><span class="lineno"> 184</span>  *output++ = *input++ ^ stream[posn++];</div>
|
|
<div class="line"><a name="l00185"></a><span class="lineno"> 185</span>  --templen;</div>
|
|
<div class="line"><a name="l00186"></a><span class="lineno"> 186</span>  }</div>
|
|
<div class="line"><a name="l00187"></a><span class="lineno"> 187</span>  }</div>
|
|
<div class="line"><a name="l00188"></a><span class="lineno"> 188</span> }</div>
|
|
<div class="line"><a name="l00189"></a><span class="lineno"> 189</span> </div>
|
|
<div class="line"><a name="l00190"></a><span class="lineno"><a class="line" href="classChaCha.html#a1f54b2b51b59428010f81a6c4dc4e42c"> 190</a></span> <span class="keywordtype">void</span> <a class="code" href="classChaCha.html#a1f54b2b51b59428010f81a6c4dc4e42c">ChaCha::decrypt</a>(uint8_t *output, <span class="keyword">const</span> uint8_t *input, <span class="keywordtype">size_t</span> len)</div>
|
|
<div class="line"><a name="l00191"></a><span class="lineno"> 191</span> {</div>
|
|
<div class="line"><a name="l00192"></a><span class="lineno"> 192</span>  <a class="code" href="classChaCha.html#acd4fff140b8871c233d9a31abf753ed8">encrypt</a>(output, input, len);</div>
|
|
<div class="line"><a name="l00193"></a><span class="lineno"> 193</span> }</div>
|
|
<div class="line"><a name="l00194"></a><span class="lineno"> 194</span> </div>
|
|
<div class="line"><a name="l00207"></a><span class="lineno"> 207</span> <span class="keywordtype">void</span> ChaCha::keystreamBlock(uint32_t *output)</div>
|
|
<div class="line"><a name="l00208"></a><span class="lineno"> 208</span> {</div>
|
|
<div class="line"><a name="l00209"></a><span class="lineno"> 209</span>  <span class="comment">// Generate the hash output directly into the caller-supplied buffer.</span></div>
|
|
<div class="line"><a name="l00210"></a><span class="lineno"> 210</span>  <a class="code" href="classChaCha.html#a41ac3262e52ff49dcd916d0b3b2e2038">hashCore</a>(output, (<span class="keyword">const</span> uint32_t *)block, rounds);</div>
|
|
<div class="line"><a name="l00211"></a><span class="lineno"> 211</span>  posn = 64;</div>
|
|
<div class="line"><a name="l00212"></a><span class="lineno"> 212</span> </div>
|
|
<div class="line"><a name="l00213"></a><span class="lineno"> 213</span>  <span class="comment">// Increment the lowest counter byte. We are assuming that the caller</span></div>
|
|
<div class="line"><a name="l00214"></a><span class="lineno"> 214</span>  <span class="comment">// is ChaChaPoly::setKey() and that the previous counter value was zero.</span></div>
|
|
<div class="line"><a name="l00215"></a><span class="lineno"> 215</span>  block[48] = 1;</div>
|
|
<div class="line"><a name="l00216"></a><span class="lineno"> 216</span> }</div>
|
|
<div class="line"><a name="l00217"></a><span class="lineno"> 217</span> </div>
|
|
<div class="line"><a name="l00218"></a><span class="lineno"><a class="line" href="classChaCha.html#af533905f679066c41f4d6cd76bddb4cb"> 218</a></span> <span class="keywordtype">void</span> <a class="code" href="classChaCha.html#af533905f679066c41f4d6cd76bddb4cb">ChaCha::clear</a>()</div>
|
|
<div class="line"><a name="l00219"></a><span class="lineno"> 219</span> {</div>
|
|
<div class="line"><a name="l00220"></a><span class="lineno"> 220</span>  clean(block);</div>
|
|
<div class="line"><a name="l00221"></a><span class="lineno"> 221</span>  clean(stream);</div>
|
|
<div class="line"><a name="l00222"></a><span class="lineno"> 222</span>  posn = 64;</div>
|
|
<div class="line"><a name="l00223"></a><span class="lineno"> 223</span> }</div>
|
|
<div class="line"><a name="l00224"></a><span class="lineno"> 224</span> </div>
|
|
<div class="line"><a name="l00225"></a><span class="lineno"> 225</span> <span class="comment">// Perform a ChaCha quarter round operation.</span></div>
|
|
<div class="line"><a name="l00226"></a><span class="lineno"> 226</span> <span class="preprocessor">#define quarterRound(a, b, c, d) \</span></div>
|
|
<div class="line"><a name="l00227"></a><span class="lineno"> 227</span> <span class="preprocessor"> do { \</span></div>
|
|
<div class="line"><a name="l00228"></a><span class="lineno"> 228</span> <span class="preprocessor"> uint32_t _b = (b); \</span></div>
|
|
<div class="line"><a name="l00229"></a><span class="lineno"> 229</span> <span class="preprocessor"> uint32_t _a = (a) + _b; \</span></div>
|
|
<div class="line"><a name="l00230"></a><span class="lineno"> 230</span> <span class="preprocessor"> uint32_t _d = leftRotate((d) ^ _a, 16); \</span></div>
|
|
<div class="line"><a name="l00231"></a><span class="lineno"> 231</span> <span class="preprocessor"> uint32_t _c = (c) + _d; \</span></div>
|
|
<div class="line"><a name="l00232"></a><span class="lineno"> 232</span> <span class="preprocessor"> _b = leftRotate12(_b ^ _c); \</span></div>
|
|
<div class="line"><a name="l00233"></a><span class="lineno"> 233</span> <span class="preprocessor"> _a += _b; \</span></div>
|
|
<div class="line"><a name="l00234"></a><span class="lineno"> 234</span> <span class="preprocessor"> (d) = _d = leftRotate(_d ^ _a, 8); \</span></div>
|
|
<div class="line"><a name="l00235"></a><span class="lineno"> 235</span> <span class="preprocessor"> _c += _d; \</span></div>
|
|
<div class="line"><a name="l00236"></a><span class="lineno"> 236</span> <span class="preprocessor"> (a) = _a; \</span></div>
|
|
<div class="line"><a name="l00237"></a><span class="lineno"> 237</span> <span class="preprocessor"> (b) = leftRotate7(_b ^ _c); \</span></div>
|
|
<div class="line"><a name="l00238"></a><span class="lineno"> 238</span> <span class="preprocessor"> (c) = _c; \</span></div>
|
|
<div class="line"><a name="l00239"></a><span class="lineno"> 239</span> <span class="preprocessor"> } while (0)</span></div>
|
|
<div class="line"><a name="l00240"></a><span class="lineno"> 240</span> <span class="preprocessor"></span></div>
|
|
<div class="line"><a name="l00253"></a><span class="lineno"><a class="line" href="classChaCha.html#a41ac3262e52ff49dcd916d0b3b2e2038"> 253</a></span> <span class="keywordtype">void</span> <a class="code" href="classChaCha.html#a41ac3262e52ff49dcd916d0b3b2e2038">ChaCha::hashCore</a>(uint32_t *output, <span class="keyword">const</span> uint32_t *input, uint8_t rounds)</div>
|
|
<div class="line"><a name="l00254"></a><span class="lineno"> 254</span> {</div>
|
|
<div class="line"><a name="l00255"></a><span class="lineno"> 255</span>  uint8_t posn;</div>
|
|
<div class="line"><a name="l00256"></a><span class="lineno"> 256</span> </div>
|
|
<div class="line"><a name="l00257"></a><span class="lineno"> 257</span>  <span class="comment">// Copy the input buffer to the output prior to the first round</span></div>
|
|
<div class="line"><a name="l00258"></a><span class="lineno"> 258</span>  <span class="comment">// and convert from little-endian to host byte order.</span></div>
|
|
<div class="line"><a name="l00259"></a><span class="lineno"> 259</span>  <span class="keywordflow">for</span> (posn = 0; posn < 16; ++posn)</div>
|
|
<div class="line"><a name="l00260"></a><span class="lineno"> 260</span>  output[posn] = le32toh(input[posn]);</div>
|
|
<div class="line"><a name="l00261"></a><span class="lineno"> 261</span> </div>
|
|
<div class="line"><a name="l00262"></a><span class="lineno"> 262</span>  <span class="comment">// Perform the ChaCha rounds in sets of two.</span></div>
|
|
<div class="line"><a name="l00263"></a><span class="lineno"> 263</span>  <span class="keywordflow">for</span> (; rounds >= 2; rounds -= 2) {</div>
|
|
<div class="line"><a name="l00264"></a><span class="lineno"> 264</span>  <span class="comment">// Column round.</span></div>
|
|
<div class="line"><a name="l00265"></a><span class="lineno"> 265</span>  quarterRound(output[0], output[4], output[8], output[12]);</div>
|
|
<div class="line"><a name="l00266"></a><span class="lineno"> 266</span>  quarterRound(output[1], output[5], output[9], output[13]);</div>
|
|
<div class="line"><a name="l00267"></a><span class="lineno"> 267</span>  quarterRound(output[2], output[6], output[10], output[14]);</div>
|
|
<div class="line"><a name="l00268"></a><span class="lineno"> 268</span>  quarterRound(output[3], output[7], output[11], output[15]);</div>
|
|
<div class="line"><a name="l00269"></a><span class="lineno"> 269</span> </div>
|
|
<div class="line"><a name="l00270"></a><span class="lineno"> 270</span>  <span class="comment">// Diagonal round.</span></div>
|
|
<div class="line"><a name="l00271"></a><span class="lineno"> 271</span>  quarterRound(output[0], output[5], output[10], output[15]);</div>
|
|
<div class="line"><a name="l00272"></a><span class="lineno"> 272</span>  quarterRound(output[1], output[6], output[11], output[12]);</div>
|
|
<div class="line"><a name="l00273"></a><span class="lineno"> 273</span>  quarterRound(output[2], output[7], output[8], output[13]);</div>
|
|
<div class="line"><a name="l00274"></a><span class="lineno"> 274</span>  quarterRound(output[3], output[4], output[9], output[14]);</div>
|
|
<div class="line"><a name="l00275"></a><span class="lineno"> 275</span>  }</div>
|
|
<div class="line"><a name="l00276"></a><span class="lineno"> 276</span> </div>
|
|
<div class="line"><a name="l00277"></a><span class="lineno"> 277</span>  <span class="comment">// Add the original input to the final output, convert back to</span></div>
|
|
<div class="line"><a name="l00278"></a><span class="lineno"> 278</span>  <span class="comment">// little-endian, and return the result.</span></div>
|
|
<div class="line"><a name="l00279"></a><span class="lineno"> 279</span>  <span class="keywordflow">for</span> (posn = 0; posn < 16; ++posn)</div>
|
|
<div class="line"><a name="l00280"></a><span class="lineno"> 280</span>  output[posn] = htole32(output[posn] + le32toh(input[posn]));</div>
|
|
<div class="line"><a name="l00281"></a><span class="lineno"> 281</span> }</div>
|
|
<div class="ttc" id="classChaCha_html_afaa3df343a7d07976bd7e03a0c1bf43c"><div class="ttname"><a href="classChaCha.html#afaa3df343a7d07976bd7e03a0c1bf43c">ChaCha::ivSize</a></div><div class="ttdeci">size_t ivSize() const </div><div class="ttdoc">Size of the initialization vector for this cipher, in bytes. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00065">ChaCha.cpp:65</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_a6b2bdffbd3705e388bb458edb2f40c90"><div class="ttname"><a href="classChaCha.html#a6b2bdffbd3705e388bb458edb2f40c90">ChaCha::setKey</a></div><div class="ttdeci">bool setKey(const uint8_t *key, size_t len)</div><div class="ttdoc">Sets the key to use for future encryption and decryption operations. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00087">ChaCha.cpp:87</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_af286083291fab2bd36dc7ad1f54d5cd7"><div class="ttname"><a href="classChaCha.html#af286083291fab2bd36dc7ad1f54d5cd7">ChaCha::keySize</a></div><div class="ttdeci">size_t keySize() const </div><div class="ttdoc">Default size of the key for this cipher, in bytes. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00059">ChaCha.cpp:59</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_a734f3246b1e6810c63637b8cda26b259"><div class="ttname"><a href="classChaCha.html#a734f3246b1e6810c63637b8cda26b259">ChaCha::setIV</a></div><div class="ttdeci">bool setIV(const uint8_t *iv, size_t len)</div><div class="ttdoc">Sets the initialization vector to use for future encryption and decryption operations. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00111">ChaCha.cpp:111</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_acab9109b7189ea88d9e5417a3a209eac"><div class="ttname"><a href="classChaCha.html#acab9109b7189ea88d9e5417a3a209eac">ChaCha::setCounter</a></div><div class="ttdeci">bool setCounter(const uint8_t *counter, size_t len)</div><div class="ttdoc">Sets the starting counter for encryption. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00145">ChaCha.cpp:145</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_a5831811b705d3c80e97f0242597f0c7e"><div class="ttname"><a href="classChaCha.html#a5831811b705d3c80e97f0242597f0c7e">ChaCha::ChaCha</a></div><div class="ttdeci">ChaCha(uint8_t numRounds=20)</div><div class="ttdoc">Constructs a new ChaCha stream cipher. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00047">ChaCha.cpp:47</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_a1f54b2b51b59428010f81a6c4dc4e42c"><div class="ttname"><a href="classChaCha.html#a1f54b2b51b59428010f81a6c4dc4e42c">ChaCha::decrypt</a></div><div class="ttdeci">void decrypt(uint8_t *output, const uint8_t *input, size_t len)</div><div class="ttdoc">Decrypts an input buffer and writes the plaintext to an output buffer. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00190">ChaCha.cpp:190</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_acd4fff140b8871c233d9a31abf753ed8"><div class="ttname"><a href="classChaCha.html#acd4fff140b8871c233d9a31abf753ed8">ChaCha::encrypt</a></div><div class="ttdeci">void encrypt(uint8_t *output, const uint8_t *input, size_t len)</div><div class="ttdoc">Encrypts an input buffer and writes the ciphertext to an output buffer. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00158">ChaCha.cpp:158</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_af533905f679066c41f4d6cd76bddb4cb"><div class="ttname"><a href="classChaCha.html#af533905f679066c41f4d6cd76bddb4cb">ChaCha::clear</a></div><div class="ttdeci">void clear()</div><div class="ttdoc">Clears all security-sensitive state from this cipher. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00218">ChaCha.cpp:218</a></div></div>
|
|
<div class="ttc" id="classChaCha_html_a41ac3262e52ff49dcd916d0b3b2e2038"><div class="ttname"><a href="classChaCha.html#a41ac3262e52ff49dcd916d0b3b2e2038">ChaCha::hashCore</a></div><div class="ttdeci">static void hashCore(uint32_t *output, const uint32_t *input, uint8_t rounds)</div><div class="ttdoc">Executes the ChaCha hash core on an input memory block. </div><div class="ttdef"><b>Definition:</b> <a href="ChaCha_8cpp_source.html#l00253">ChaCha.cpp:253</a></div></div>
|
|
</div><!-- fragment --></div><!-- contents -->
|
|
<!-- start footer part -->
|
|
<hr class="footer"/><address class="footer"><small>
|
|
Generated on Fri Apr 27 2018 12:01:32 for Arduino Cryptography Library by  <a href="http://www.doxygen.org/index.html">
|
|
<img class="footer" src="doxygen.png" alt="doxygen"/>
|
|
</a> 1.8.6
|
|
</small></address>
|
|
</body>
|
|
</html>
|