From 184110ccc56d2e65d67c3ab38c9b74c9af4e6093 Mon Sep 17 00:00:00 2001 From: Frank Denis Date: Sat, 26 Nov 2016 21:06:23 +0100 Subject: [PATCH] + crypto_box_curve25519xchacha20poly1305_* --- src/libsodium/Makefile.am | 6 + .../box_curve25519xchacha20poly1305_api.c | 41 ++++ .../box_curve25519xchacha20poly1305_easy.c | 138 ++++++++++++++ .../after_curve25519xchacha20poly1305.c | 22 +++ .../before_curve25519xchacha20poly1305.c | 18 ++ .../sodium/box_curve25519xchacha20poly1305.c | 42 +++++ .../keypair_curve25519xchacha20poly1305.c | 30 +++ src/libsodium/include/Makefile.am | 1 + src/libsodium/include/sodium.h | 1 + .../crypto_box_curve25519xchacha20poly1305.h | 175 ++++++++++++++++++ 10 files changed, 474 insertions(+) create mode 100644 src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_api.c create mode 100644 src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_easy.c create mode 100644 src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/after_curve25519xchacha20poly1305.c create mode 100644 src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/before_curve25519xchacha20poly1305.c create mode 100644 src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/box_curve25519xchacha20poly1305.c create mode 100644 src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/keypair_curve25519xchacha20poly1305.c create mode 100644 src/libsodium/include/sodium/crypto_box_curve25519xchacha20poly1305.h diff --git a/src/libsodium/Makefile.am b/src/libsodium/Makefile.am index 7591972b..31b04534 100644 --- a/src/libsodium/Makefile.am +++ b/src/libsodium/Makefile.am @@ -169,6 +169,12 @@ endif if !MINIMAL libsodium_la_SOURCES += \ + crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_api.c \ + crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_easy.c \ + crypto_box/curve25519xchacha20poly1305/sodium/after_curve25519xchacha20poly1305.c \ + crypto_box/curve25519xchacha20poly1305/sodium/before_curve25519xchacha20poly1305.c \ + crypto_box/curve25519xchacha20poly1305/sodium/box_curve25519xchacha20poly1305.c \ + crypto_box/curve25519xchacha20poly1305/sodium/keypair_curve25519xchacha20poly1305.c \ crypto_core/hchacha20/core_hchacha20.c \ crypto_core/hchacha20/core_hchacha20.h \ crypto_core/salsa2012/ref/core_salsa2012.c \ diff --git a/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_api.c b/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_api.c new file mode 100644 index 00000000..0942398b --- /dev/null +++ b/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_api.c @@ -0,0 +1,41 @@ +#include "crypto_box_curve25519xchacha20poly1305.h" + +size_t +crypto_box_curve25519xchacha20poly1305_seedbytes(void) { + return crypto_box_curve25519xchacha20poly1305_SEEDBYTES; +} + +size_t +crypto_box_curve25519xchacha20poly1305_publickeybytes(void) { + return crypto_box_curve25519xchacha20poly1305_PUBLICKEYBYTES; +} + +size_t +crypto_box_curve25519xchacha20poly1305_secretkeybytes(void) { + return crypto_box_curve25519xchacha20poly1305_SECRETKEYBYTES; +} + +size_t +crypto_box_curve25519xchacha20poly1305_beforenmbytes(void) { + return crypto_box_curve25519xchacha20poly1305_BEFORENMBYTES; +} + +size_t +crypto_box_curve25519xchacha20poly1305_noncebytes(void) { + return crypto_box_curve25519xchacha20poly1305_NONCEBYTES; +} + +size_t +crypto_box_curve25519xchacha20poly1305_zerobytes(void) { + return crypto_box_curve25519xchacha20poly1305_ZEROBYTES; +} + +size_t +crypto_box_curve25519xchacha20poly1305_boxzerobytes(void) { + return crypto_box_curve25519xchacha20poly1305_BOXZEROBYTES; +} + +size_t +crypto_box_curve25519xchacha20poly1305_macbytes(void) { + return crypto_box_curve25519xchacha20poly1305_MACBYTES; +} diff --git a/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_easy.c b/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_easy.c new file mode 100644 index 00000000..0a550ced --- /dev/null +++ b/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305_easy.c @@ -0,0 +1,138 @@ + +#include +#include +#include + +#include "crypto_box_curve25519xchacha20poly1305.h" +#include "crypto_secretbox_xchacha20poly1305.h" +#include "utils.h" + +int +crypto_box_curve25519xchacha20poly1305_detached_afternm(unsigned char *c, + unsigned char *mac, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *k) +{ + return crypto_secretbox_xchacha20poly1305_detached(c, mac, m, mlen, n, k); +} + +int +crypto_box_curve25519xchacha20poly1305_detached(unsigned char *c, + unsigned char *mac, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) +{ + unsigned char k[crypto_box_curve25519xchacha20poly1305_BEFORENMBYTES]; + int ret; + + (void)sizeof(int[crypto_box_curve25519xchacha20poly1305_BEFORENMBYTES + >= crypto_secretbox_xchacha20poly1305_KEYBYTES ? + 1 : -1]); + if (crypto_box_curve25519xchacha20poly1305_beforenm(k, pk, sk) != 0) { + return -1; + } + ret = crypto_box_curve25519xchacha20poly1305_detached_afternm(c, mac, m, + mlen, n, k); + sodium_memzero(k, sizeof k); + + return ret; +} + +int +crypto_box_curve25519xchacha20poly1305_easy_afternm(unsigned char *c, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *k) +{ + if (mlen > SIZE_MAX - crypto_box_curve25519xchacha20poly1305_MACBYTES) { + return -1; + } + return crypto_box_curve25519xchacha20poly1305_detached_afternm( + c + crypto_box_curve25519xchacha20poly1305_MACBYTES, c, m, mlen, n, k); +} + +int +crypto_box_curve25519xchacha20poly1305_easy(unsigned char *c, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) +{ + if (mlen > SIZE_MAX - crypto_box_curve25519xchacha20poly1305_MACBYTES) { + return -1; + } + return crypto_box_curve25519xchacha20poly1305_detached( + c + crypto_box_curve25519xchacha20poly1305_MACBYTES, c, m, mlen, n, pk, + sk); +} + +int +crypto_box_curve25519xchacha20poly1305_open_detached_afternm(unsigned char *m, + const unsigned char *c, + const unsigned char *mac, + unsigned long long clen, + const unsigned char *n, + const unsigned char *k) +{ + return crypto_secretbox_xchacha20poly1305_open_detached(m, c, mac, clen, n, k); +} + +int +crypto_box_curve25519xchacha20poly1305_open_detached(unsigned char *m, + const unsigned char *c, + const unsigned char *mac, + unsigned long long clen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) +{ + unsigned char k[crypto_box_curve25519xchacha20poly1305_BEFORENMBYTES]; + int ret; + + if (crypto_box_curve25519xchacha20poly1305_beforenm(k, pk, sk) != 0) { + return -1; + } + ret = crypto_box_curve25519xchacha20poly1305_open_detached_afternm( + m, c, mac, clen, n, k); + sodium_memzero(k, sizeof k); + + return ret; +} + +int +crypto_box_curve25519xchacha20poly1305_open_easy_afternm(unsigned char *m, + const unsigned char *c, + unsigned long long clen, + const unsigned char *n, + const unsigned char *k) +{ + if (clen < crypto_box_curve25519xchacha20poly1305_MACBYTES) { + return -1; + } + return crypto_box_curve25519xchacha20poly1305_open_detached_afternm( + m, c + crypto_box_curve25519xchacha20poly1305_MACBYTES, c, + clen - crypto_box_curve25519xchacha20poly1305_MACBYTES, n, k); +} + +int +crypto_box_curve25519xchacha20poly1305_open_easy(unsigned char *m, + const unsigned char *c, + unsigned long long clen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) +{ + if (clen < crypto_box_curve25519xchacha20poly1305_MACBYTES) { + return -1; + } + return crypto_box_curve25519xchacha20poly1305_open_detached( + m, c + crypto_box_curve25519xchacha20poly1305_MACBYTES, c, + clen - crypto_box_curve25519xchacha20poly1305_MACBYTES, n, pk, sk); +} diff --git a/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/after_curve25519xchacha20poly1305.c b/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/after_curve25519xchacha20poly1305.c new file mode 100644 index 00000000..16ee6026 --- /dev/null +++ b/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/after_curve25519xchacha20poly1305.c @@ -0,0 +1,22 @@ +#include "crypto_box_curve25519xchacha20poly1305.h" +#include "crypto_secretbox_xchacha20poly1305.h" + +int +crypto_box_curve25519xchacha20poly1305_afternm(unsigned char *c, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *k) +{ + return crypto_secretbox_xchacha20poly1305(c, m, mlen, n, k); +} + +int +crypto_box_curve25519xchacha20poly1305_open_afternm(unsigned char *m, + const unsigned char *c, + unsigned long long clen, + const unsigned char *n, + const unsigned char *k) +{ + return crypto_secretbox_xchacha20poly1305_open(m, c, clen, n, k); +} diff --git a/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/before_curve25519xchacha20poly1305.c b/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/before_curve25519xchacha20poly1305.c new file mode 100644 index 00000000..bfcaf532 --- /dev/null +++ b/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/before_curve25519xchacha20poly1305.c @@ -0,0 +1,18 @@ +#include "crypto_box_curve25519xchacha20poly1305.h" +#include "crypto_core_hchacha20.h" +#include "crypto_scalarmult_curve25519.h" + +static const unsigned char n[16] = { 0 }; + +int +crypto_box_curve25519xchacha20poly1305_beforenm(unsigned char *k, + const unsigned char *pk, + const unsigned char *sk) +{ + unsigned char s[32]; + + if (crypto_scalarmult_curve25519(s, sk, pk) != 0) { + return -1; + } + return crypto_core_hchacha20(k, n, s, NULL); +} diff --git a/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/box_curve25519xchacha20poly1305.c b/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/box_curve25519xchacha20poly1305.c new file mode 100644 index 00000000..6bd6bc40 --- /dev/null +++ b/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/box_curve25519xchacha20poly1305.c @@ -0,0 +1,42 @@ +#include "crypto_box_curve25519xchacha20poly1305.h" +#include "utils.h" + +int +crypto_box_curve25519xchacha20poly1305(unsigned char *c, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) +{ + unsigned char k[crypto_box_curve25519xchacha20poly1305_BEFORENMBYTES]; + int ret; + + if (crypto_box_curve25519xchacha20poly1305_beforenm(k, pk, sk) != 0) { + return -1; + } + ret = crypto_box_curve25519xchacha20poly1305_afternm(c, m, mlen, n, k); + sodium_memzero(k, sizeof k); + + return ret; +} + +int +crypto_box_curve25519xchacha20poly1305_open(unsigned char *m, + const unsigned char *c, + unsigned long long clen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) +{ + unsigned char k[crypto_box_curve25519xchacha20poly1305_BEFORENMBYTES]; + int ret; + + if (crypto_box_curve25519xchacha20poly1305_beforenm(k, pk, sk) != 0) { + return -1; + } + ret = crypto_box_curve25519xchacha20poly1305_open_afternm(m, c, clen, n, k); + sodium_memzero(k, sizeof k); + + return ret; +} diff --git a/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/keypair_curve25519xchacha20poly1305.c b/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/keypair_curve25519xchacha20poly1305.c new file mode 100644 index 00000000..2fc7ece4 --- /dev/null +++ b/src/libsodium/crypto_box/curve25519xchacha20poly1305/sodium/keypair_curve25519xchacha20poly1305.c @@ -0,0 +1,30 @@ +#include + +#include "crypto_box_curve25519xchacha20poly1305.h" +#include "crypto_hash_sha512.h" +#include "crypto_scalarmult_curve25519.h" +#include "randombytes.h" +#include "utils.h" + +int +crypto_box_curve25519xchacha20poly1305_seed_keypair(unsigned char *pk, + unsigned char *sk, + const unsigned char *seed) +{ + unsigned char hash[64]; + + crypto_hash_sha512(hash, seed, 32); + memmove(sk, hash, 32); + sodium_memzero(hash, sizeof hash); + + return crypto_scalarmult_curve25519_base(pk, sk); +} + +int +crypto_box_curve25519xchacha20poly1305_keypair(unsigned char *pk, + unsigned char *sk) +{ + randombytes_buf(sk, 32); + + return crypto_scalarmult_curve25519_base(pk, sk); +} diff --git a/src/libsodium/include/Makefile.am b/src/libsodium/include/Makefile.am index 3d062ffe..a333d142 100644 --- a/src/libsodium/include/Makefile.am +++ b/src/libsodium/include/Makefile.am @@ -9,6 +9,7 @@ SODIUM_EXPORT = \ sodium/crypto_auth_hmacsha512.h \ sodium/crypto_auth_hmacsha512256.h \ sodium/crypto_box.h \ + sodium/crypto_box_curve25519xchacha20poly1305.h \ sodium/crypto_box_curve25519xsalsa20poly1305.h \ sodium/crypto_core_hchacha20.h \ sodium/crypto_core_hsalsa20.h \ diff --git a/src/libsodium/include/sodium.h b/src/libsodium/include/sodium.h index b7388ad0..2f0db1dc 100644 --- a/src/libsodium/include/sodium.h +++ b/src/libsodium/include/sodium.h @@ -10,6 +10,7 @@ #include "sodium/crypto_auth_hmacsha512.h" #include "sodium/crypto_auth_hmacsha512256.h" #include "sodium/crypto_box.h" +#include "sodium/crypto_box_curve25519xchacha20poly1305.h" #include "sodium/crypto_box_curve25519xsalsa20poly1305.h" #include "sodium/crypto_core_hsalsa20.h" #include "sodium/crypto_core_hchacha20.h" diff --git a/src/libsodium/include/sodium/crypto_box_curve25519xchacha20poly1305.h b/src/libsodium/include/sodium/crypto_box_curve25519xchacha20poly1305.h new file mode 100644 index 00000000..0382c092 --- /dev/null +++ b/src/libsodium/include/sodium/crypto_box_curve25519xchacha20poly1305.h @@ -0,0 +1,175 @@ + +#ifndef crypto_box_curve25519xchacha20poly1305_H +#define crypto_box_curve25519xchacha20poly1305_H + +#include +#include "export.h" + +#ifdef __cplusplus +# ifdef __GNUC__ +# pragma GCC diagnostic ignored "-Wlong-long" +# endif +extern "C" { +#endif + +#define crypto_box_curve25519xchacha20poly1305_SEEDBYTES 32U +SODIUM_EXPORT +size_t crypto_box_curve25519xchacha20poly1305_seedbytes(void); + +#define crypto_box_curve25519xchacha20poly1305_PUBLICKEYBYTES 32U +SODIUM_EXPORT +size_t crypto_box_curve25519xchacha20poly1305_publickeybytes(void); + +#define crypto_box_curve25519xchacha20poly1305_SECRETKEYBYTES 32U +SODIUM_EXPORT +size_t crypto_box_curve25519xchacha20poly1305_secretkeybytes(void); + +#define crypto_box_curve25519xchacha20poly1305_BEFORENMBYTES 32U +SODIUM_EXPORT +size_t crypto_box_curve25519xchacha20poly1305_beforenmbytes(void); + +#define crypto_box_curve25519xchacha20poly1305_NONCEBYTES 24U +SODIUM_EXPORT +size_t crypto_box_curve25519xchacha20poly1305_noncebytes(void); + +#define crypto_box_curve25519xchacha20poly1305_MACBYTES 16U +SODIUM_EXPORT +size_t crypto_box_curve25519xchacha20poly1305_macbytes(void); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_seed_keypair(unsigned char *pk, + unsigned char *sk, + const unsigned char *seed); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_keypair(unsigned char *pk, + unsigned char *sk); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_easy(unsigned char *c, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) + __attribute__ ((warn_unused_result)); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_open_easy(unsigned char *m, + const unsigned char *c, + unsigned long long clen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) + __attribute__ ((warn_unused_result)); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_detached(unsigned char *c, + unsigned char *mac, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) + __attribute__ ((warn_unused_result)); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_open_detached(unsigned char *m, + const unsigned char *c, + const unsigned char *mac, + unsigned long long clen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) + __attribute__ ((warn_unused_result)); + +/* -- Precomputation interface -- */ + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_beforenm(unsigned char *k, + const unsigned char *pk, + const unsigned char *sk) + __attribute__ ((warn_unused_result)); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_easy_afternm(unsigned char *c, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *k); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_open_easy_afternm(unsigned char *m, + const unsigned char *c, + unsigned long long clen, + const unsigned char *n, + const unsigned char *k) + __attribute__ ((warn_unused_result)); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_detached_afternm(unsigned char *c, + unsigned char *mac, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *k); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_open_detached_afternm(unsigned char *m, + const unsigned char *c, + const unsigned char *mac, + unsigned long long clen, + const unsigned char *n, + const unsigned char *k) + __attribute__ ((warn_unused_result)); + +/* -- NaCl-style interface ; Requires padding -- */ + +#define crypto_box_curve25519xchacha20poly1305_BOXZEROBYTES 16U +SODIUM_EXPORT +size_t crypto_box_curve25519xchacha20poly1305_boxzerobytes(void); + +#define crypto_box_curve25519xchacha20poly1305_ZEROBYTES \ + (crypto_box_curve25519xchacha20poly1305_BOXZEROBYTES + \ + crypto_box_curve25519xchacha20poly1305_MACBYTES) +SODIUM_EXPORT +size_t crypto_box_curve25519xchacha20poly1305_zerobytes(void); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305(unsigned char *c, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) + __attribute__ ((warn_unused_result)); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_open(unsigned char *m, + const unsigned char *c, + unsigned long long clen, + const unsigned char *n, + const unsigned char *pk, + const unsigned char *sk) + __attribute__ ((warn_unused_result)); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_afternm(unsigned char *c, + const unsigned char *m, + unsigned long long mlen, + const unsigned char *n, + const unsigned char *k); + +SODIUM_EXPORT +int crypto_box_curve25519xchacha20poly1305_open_afternm(unsigned char *m, + const unsigned char *c, + unsigned long long clen, + const unsigned char *n, + const unsigned char *k) + __attribute__ ((warn_unused_result)); + +#ifdef __cplusplus +} +#endif + +#endif