lilliput-ae-reference-implementation

Implementations of Lilliput-AE submitted to the NIST LWC standardization process
git clone https://git.kevinlegouguec.net/lilliput-ae-reference-implementation
Log | Files | Refs | README

commit bfafd1b3323ac543cae2d34f43e02b8b4373c36f
parent 35935f0a2ac2df9d71aa767cadbf5ae23396ad2d
Author: Kévin Le Gouguec <kevin.legouguec@airbus.com>
Date:   Tue,  5 Feb 2019 09:00:43 +0100

Renommage de ae-common.h en lilliput-ae-utils.h

Diffstat:
MREADME.md | 2+-
Mnist/make-package.sh | 3+--
Dsrc/add_tweakeyloop/ae-common.h | 2--
Asrc/add_tweakeyloop/lilliput-ae-utils.h | 2++
Dsrc/add_tweakeysequences/ae-common.h | 2--
Asrc/add_tweakeysequences/lilliput-ae-utils.h | 2++
Dsrc/ref/ae-common.h | 127-------------------------------------------------------------------------------
Msrc/ref/lilliput-ae-i.c | 2+-
Msrc/ref/lilliput-ae-ii.c | 2+-
Asrc/ref/lilliput-ae-utils.h | 127+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mtest/check-implementation.sh | 3+--
Mtraces/traces-ae.patch | 10+++++-----
12 files changed, 141 insertions(+), 143 deletions(-)

diff --git a/README.md b/README.md @@ -24,7 +24,7 @@ Each implementation folder contains: - `lilliput-ae.h`: main API - `lilliput-ae-i.c`: implementation of Lilliput-Ⅰ (ΘCB3-based) - `lilliput-ae-ii.c`: implementation of Lilliput-Ⅱ (SCT-2-based) -- `ae-common.h`: internal helper functions used by both AE schemes +- `lilliput-ae-utils.h`: helper functions used by both AE schemes - `tweakey.*`: implementation of Lilliput-TBC's tweakey schedule - `cipher.*`: implementation of the tweakable block-cipher Lilliput-TBC diff --git a/nist/make-package.sh b/nist/make-package.sh @@ -44,10 +44,9 @@ add-variant () mkdir -p ${dest} source_files=( - ae-common.h cipher.{c,h} constants.h - lilliput-ae{.h,-${mode}.c} + lilliput-ae{.h,-utils.h,-${mode}.c} tweakey.{c,h} ) diff --git a/src/add_tweakeyloop/ae-common.h b/src/add_tweakeyloop/ae-common.h @@ -1 +0,0 @@ -../ref/ae-common.h -\ No newline at end of file diff --git a/src/add_tweakeyloop/lilliput-ae-utils.h b/src/add_tweakeyloop/lilliput-ae-utils.h @@ -0,0 +1 @@ +../ref/lilliput-ae-utils.h +\ No newline at end of file diff --git a/src/add_tweakeysequences/ae-common.h b/src/add_tweakeysequences/ae-common.h @@ -1 +0,0 @@ -../ref/ae-common.h -\ No newline at end of file diff --git a/src/add_tweakeysequences/lilliput-ae-utils.h b/src/add_tweakeysequences/lilliput-ae-utils.h @@ -0,0 +1 @@ +../ref/lilliput-ae-utils.h +\ No newline at end of file diff --git a/src/ref/ae-common.h b/src/ref/ae-common.h @@ -1,127 +0,0 @@ -#ifndef AE_COMMON_H -#define AE_COMMON_H - -#include <stddef.h> -#include <stdint.h> -#include <string.h> - -#include "cipher.h" -#include "constants.h" - - -static inline uint8_t upper_nibble(uint8_t i) -{ - return i >> 4; -} - -static inline uint8_t lower_nibble(uint8_t i) -{ - return i & 0x0f; -} - -static inline void encrypt(const uint8_t K[KEY_BYTES], - const uint8_t T[TWEAK_BYTES], - const uint8_t M[BLOCK_BYTES], - uint8_t C[BLOCK_BYTES]) -{ - lilliput_tbc_encrypt(K, T, M, C); -} - -static inline void decrypt(const uint8_t K[KEY_BYTES], - const uint8_t T[TWEAK_BYTES], - const uint8_t C[BLOCK_BYTES], - uint8_t M[BLOCK_BYTES]) -{ - lilliput_tbc_decrypt(K, T, C, M); -} - -static inline void xor_into(uint8_t dest[BLOCK_BYTES], const uint8_t src[BLOCK_BYTES]) -{ - for (size_t i=0; i<BLOCK_BYTES; i++) - dest[i] ^= src[i]; -} - -static inline void xor_arrays(size_t len, uint8_t out[len], const uint8_t a[len], const uint8_t b[len]) -{ - for (size_t i=0; i<len; i++) - out[i] = a[i] ^ b[i]; -} - -static inline void pad10(size_t X_len, const uint8_t X[X_len], uint8_t padded[BLOCK_BYTES]) -{ - /* pad10*(X) = X || 1 || 0^{n-|X|-1} */ - - /* Assume that len<BLOCK_BYTES. */ - - size_t pad_len = BLOCK_BYTES-X_len; - - memcpy(padded+pad_len, X, X_len); - - padded[pad_len-1] = 0x80; - - if (pad_len > 1) - { - memset(padded, 0, pad_len-1); - } -} - -static inline void fill_index_tweak( - uint8_t prefix, - uint64_t block_index, - uint8_t tweak[TWEAK_BYTES] -) -{ - /* The t-bit tweak is filled as follows: - * - * - bits [ 1, t-4]: block index - * [ 1, 64]: actual 64-bit block index - * [ 65, t-4]: 0-padding - * - bits [t-3, t]: constant 4-bit prefix - */ - - for (size_t i=0; i<sizeof(block_index); i++) - { - tweak[i] = block_index >> 8*i & 0xff; - } - - /* Assume padding bytes have already been memset to 0. */ - - tweak[TWEAK_BYTES-1] |= prefix << 4; -} - -static void process_associated_data( - const uint8_t key[KEY_BYTES], - size_t A_len, - const uint8_t A[A_len], - uint8_t Auth[BLOCK_BYTES] -) -{ - uint8_t Ek_Ai[BLOCK_BYTES]; - uint8_t tweak[TWEAK_BYTES]; - - memset(tweak, 0, TWEAK_BYTES); - memset(Auth, 0, BLOCK_BYTES); - - size_t l_a = A_len / BLOCK_BYTES; - size_t rest = A_len % BLOCK_BYTES; - - for (size_t i=0; i<l_a; i++) - { - fill_index_tweak(0x2, i, tweak); - encrypt(key, tweak, &A[i*BLOCK_BYTES], Ek_Ai); - xor_into(Auth, Ek_Ai); - } - - if (rest != 0) - { - uint8_t A_rest[BLOCK_BYTES]; - pad10(rest, &A[l_a*BLOCK_BYTES], A_rest); - fill_index_tweak(0x6, l_a, tweak); - encrypt(key, tweak, A_rest, Ek_Ai); - xor_into(Auth, Ek_Ai); - } -} - - - -#endif /* AE_COMMON_H */ diff --git a/src/ref/lilliput-ae-i.c b/src/ref/lilliput-ae-i.c @@ -2,7 +2,7 @@ #include <stdint.h> #include <string.h> -#include "ae-common.h" +#include "lilliput-ae-utils.h" #include "cipher.h" #include "lilliput-ae.h" diff --git a/src/ref/lilliput-ae-ii.c b/src/ref/lilliput-ae-ii.c @@ -2,7 +2,7 @@ #include <stdint.h> #include <string.h> -#include "ae-common.h" +#include "lilliput-ae-utils.h" #include "cipher.h" #include "lilliput-ae.h" diff --git a/src/ref/lilliput-ae-utils.h b/src/ref/lilliput-ae-utils.h @@ -0,0 +1,127 @@ +#ifndef LILLIPUT_AE_UTILS_H +#define LILLIPUT_AE_UTILS_H + +#include <stddef.h> +#include <stdint.h> +#include <string.h> + +#include "cipher.h" +#include "constants.h" + + +static inline uint8_t upper_nibble(uint8_t i) +{ + return i >> 4; +} + +static inline uint8_t lower_nibble(uint8_t i) +{ + return i & 0x0f; +} + +static inline void encrypt(const uint8_t K[KEY_BYTES], + const uint8_t T[TWEAK_BYTES], + const uint8_t M[BLOCK_BYTES], + uint8_t C[BLOCK_BYTES]) +{ + lilliput_tbc_encrypt(K, T, M, C); +} + +static inline void decrypt(const uint8_t K[KEY_BYTES], + const uint8_t T[TWEAK_BYTES], + const uint8_t C[BLOCK_BYTES], + uint8_t M[BLOCK_BYTES]) +{ + lilliput_tbc_decrypt(K, T, C, M); +} + +static inline void xor_into(uint8_t dest[BLOCK_BYTES], const uint8_t src[BLOCK_BYTES]) +{ + for (size_t i=0; i<BLOCK_BYTES; i++) + dest[i] ^= src[i]; +} + +static inline void xor_arrays(size_t len, uint8_t out[len], const uint8_t a[len], const uint8_t b[len]) +{ + for (size_t i=0; i<len; i++) + out[i] = a[i] ^ b[i]; +} + +static inline void pad10(size_t X_len, const uint8_t X[X_len], uint8_t padded[BLOCK_BYTES]) +{ + /* pad10*(X) = X || 1 || 0^{n-|X|-1} */ + + /* Assume that len<BLOCK_BYTES. */ + + size_t pad_len = BLOCK_BYTES-X_len; + + memcpy(padded+pad_len, X, X_len); + + padded[pad_len-1] = 0x80; + + if (pad_len > 1) + { + memset(padded, 0, pad_len-1); + } +} + +static inline void fill_index_tweak( + uint8_t prefix, + uint64_t block_index, + uint8_t tweak[TWEAK_BYTES] +) +{ + /* The t-bit tweak is filled as follows: + * + * - bits [ 1, t-4]: block index + * [ 1, 64]: actual 64-bit block index + * [ 65, t-4]: 0-padding + * - bits [t-3, t]: constant 4-bit prefix + */ + + for (size_t i=0; i<sizeof(block_index); i++) + { + tweak[i] = block_index >> 8*i & 0xff; + } + + /* Assume padding bytes have already been memset to 0. */ + + tweak[TWEAK_BYTES-1] |= prefix << 4; +} + +static void process_associated_data( + const uint8_t key[KEY_BYTES], + size_t A_len, + const uint8_t A[A_len], + uint8_t Auth[BLOCK_BYTES] +) +{ + uint8_t Ek_Ai[BLOCK_BYTES]; + uint8_t tweak[TWEAK_BYTES]; + + memset(tweak, 0, TWEAK_BYTES); + memset(Auth, 0, BLOCK_BYTES); + + size_t l_a = A_len / BLOCK_BYTES; + size_t rest = A_len % BLOCK_BYTES; + + for (size_t i=0; i<l_a; i++) + { + fill_index_tweak(0x2, i, tweak); + encrypt(key, tweak, &A[i*BLOCK_BYTES], Ek_Ai); + xor_into(Auth, Ek_Ai); + } + + if (rest != 0) + { + uint8_t A_rest[BLOCK_BYTES]; + pad10(rest, &A[l_a*BLOCK_BYTES], A_rest); + fill_index_tweak(0x6, l_a, tweak); + encrypt(key, tweak, A_rest, Ek_Ai); + xor_into(Auth, Ek_Ai); + } +} + + + +#endif /* LILLIPUT_AE_UTILS_H */ diff --git a/test/check-implementation.sh b/test/check-implementation.sh @@ -25,10 +25,9 @@ run-genkat () local genkat=${genkat_dir}/genkat local source_files=( - ae-common.h cipher.{c,h} constants.h - lilliput-ae{.h,-${mode}.c} + lilliput-ae{.h,-utils.h,-${mode}.c} tweakey.{c,h} ) diff --git a/traces/traces-ae.patch b/traces/traces-ae.patch @@ -1,12 +1,12 @@ -diff --git a/SOUMISSION_NIST/REFERENCE_IMPLEMENTATION/src/ref/ae-common.h b/SOUMISSION_NIST/REFERENCE_IMPLEMENTATION/src/ref/ae-common.h +diff --git a/SOUMISSION_NIST/REFERENCE_IMPLEMENTATION/src/ref/lilliput-ae-utils.h b/SOUMISSION_NIST/REFERENCE_IMPLEMENTATION/src/ref/lilliput-ae-utils.h index 561854e..397dac0 100644 ---- a/SOUMISSION_NIST/REFERENCE_IMPLEMENTATION/src/ref/ae-common.h -+++ b/SOUMISSION_NIST/REFERENCE_IMPLEMENTATION/src/ref/ae-common.h +--- a/SOUMISSION_NIST/REFERENCE_IMPLEMENTATION/src/ref/lilliput-ae-utils.h ++++ b/SOUMISSION_NIST/REFERENCE_IMPLEMENTATION/src/ref/lilliput-ae-utils.h @@ -1,3 +1,5 @@ +#include "debug.h" + - #ifndef AE_COMMON_H - #define AE_COMMON_H + #ifndef LILLIPUT_AE_UTILS_H + #define LILLIPUT_AE_UTILS_H @@ -105,20 +107,45 @@ static void process_associated_data( size_t l_a = A_len / BLOCK_BYTES;