summaryrefslogtreecommitdiff
path: root/src/ref/lilliput-i.c
diff options
context:
space:
mode:
Diffstat (limited to 'src/ref/lilliput-i.c')
-rw-r--r--src/ref/lilliput-i.c26
1 files changed, 10 insertions, 16 deletions
diff --git a/src/ref/lilliput-i.c b/src/ref/lilliput-i.c
index 97c2117..3ba7ea2 100644
--- a/src/ref/lilliput-i.c
+++ b/src/ref/lilliput-i.c
@@ -35,32 +35,26 @@ static const uint8_t _0n[BLOCK_BYTES] = {
static void _fill_msg_tweak(
uint8_t prefix,
const uint8_t N[NONCE_BYTES],
- uint64_t block_nb,
+ size_t block_index,
uint8_t tweak[TWEAK_BYTES]
)
{
- /* The 192-bit tweak is filled as follows:
+ /* With an s-bit block index, the t-bit tweak is filled as follows:
*
- * - bits 1- 68: block number
- * 1- 64: actual 64-bit block number
- * 64- 68: 0-padding
- * - bits 67-188: nonce
- * - bits 189-192: constant 4-bit prefix
+ * - bits [ 1, t-|N|-4]: block index
+ * [ 1, s]: actual 64-bit block index
+ * [ s+1, t-|N|-4]: 0-padding
+ * - bits [t-|N|-4, t-4]: nonce
+ * - bits [ t-3, t]: 4-bit prefix
*/
- for (size_t i=0; i<sizeof(block_nb); i++)
- {
- uint64_t mask = (uint64_t)0xff << 8*i;
- uint8_t b = (mask & block_nb) >> 8*i;
-
- tweak[i] = b;
- }
+ copy_block_index(block_index, tweak);
- tweak[sizeof(block_nb)] = lower_nibble(N[0]) << 4;
+ tweak[sizeof(block_index)] = lower_nibble(N[0]) << 4;
for (size_t i=1; i<NONCE_BYTES; i++)
{
- tweak[sizeof(block_nb)+i] = lower_nibble(N[i]) << 4 ^ upper_nibble(N[i-1]);
+ tweak[sizeof(block_index)+i] = lower_nibble(N[i]) << 4 ^ upper_nibble(N[i-1]);
}
tweak[TWEAK_BYTES-1] = prefix << 4 ^ upper_nibble(N[NONCE_BYTES-1]);