From 4dcf6e9afb6e30a94f1f88102975627cf7edbc84 Mon Sep 17 00:00:00 2001 From: Kévin Le Gouguec Date: Mon, 17 Dec 2018 15:26:12 +0100 Subject: Organisation des différentes implémentations MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Au passage, officialisation de la version "i applications successives de M pour calculer Mⁱ" du key schedule. --- src/ref/lilliput-ae-ii.c | 160 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 160 insertions(+) create mode 100644 src/ref/lilliput-ae-ii.c (limited to 'src/ref/lilliput-ae-ii.c') diff --git a/src/ref/lilliput-ae-ii.c b/src/ref/lilliput-ae-ii.c new file mode 100644 index 0000000..26885e5 --- /dev/null +++ b/src/ref/lilliput-ae-ii.c @@ -0,0 +1,160 @@ +#include +#include +#include + +#include "ae-common.h" +#include "cipher.h" +#include "lilliput-ae.h" + + +static void _init_msg_tweak(const uint8_t tag[TAG_BYTES], uint8_t tweak[TWEAK_BYTES]) +{ + /* The t-bit tweak is filled as follows: + * + * - bits [ 1, t-1]: tag + block index + * [ 1, 64]: tag[ 1.. 64] XOR block index + * [ 65, t-1]: tag[65..t-1] + * - bit t: 1 + */ + + memcpy(tweak+sizeof(uint64_t), tag+sizeof(uint64_t), TAG_BYTES-sizeof(uint64_t)); + tweak[TWEAK_BYTES-1] |= 0x80; +} + +static void _fill_msg_tweak(const uint8_t tag[TAG_BYTES], uint64_t block_index, uint8_t tweak[TWEAK_BYTES]) +{ + /* Assume bits 65 to t-1 are set. */ + for (size_t i=0; i> i*8 & 0xff; + tweak[i] = tag[i] ^ index_i; + } +} + +static void _fill_tag_tweak(const uint8_t N[NONCE_BYTES], uint8_t tweak[TWEAK_BYTES]) +{ + /* The t-bit tweak is filled as follows: + * + * - bits [ 1, t-7]: N + * - bits [t-7, t]: 0001||0^4 + */ + + memcpy(tweak, N, TWEAK_BYTES-1); + tweak[TWEAK_BYTES-1] = 0x10; +} + +static void _generate_tag( + const uint8_t key[KEY_BYTES], + size_t M_len, + const uint8_t M[M_len], + const uint8_t N[NONCE_BYTES], + const uint8_t Auth[BLOCK_BYTES], + uint8_t tag[TAG_BYTES] +) +{ + uint8_t Ek_Mj[BLOCK_BYTES]; + uint8_t tag_tmp[TAG_BYTES]; + uint8_t tweak[TWEAK_BYTES]; + + memset(tweak, 0, TWEAK_BYTES); + memcpy(tag_tmp, Auth, TAG_BYTES); + + size_t l = M_len / BLOCK_BYTES; + size_t rest = M_len % BLOCK_BYTES; + + for (size_t j=0; j