From 90f5b55a0afe8c0fda185aa2bc701bbc279aacd3 Mon Sep 17 00:00:00 2001 From: Frank Denis Date: Fri, 6 Oct 2017 22:01:06 +0200 Subject: [PATCH] Move computation of synthetic nonces to a dedicated function for clarity --- .../crypto_sign/ed25519/ref10/sign.c | 58 +++++++++++-------- 1 file changed, 34 insertions(+), 24 deletions(-) diff --git a/src/libsodium/crypto_sign/ed25519/ref10/sign.c b/src/libsodium/crypto_sign/ed25519/ref10/sign.c index edf6af81..7aeb07f2 100644 --- a/src/libsodium/crypto_sign/ed25519/ref10/sign.c +++ b/src/libsodium/crypto_sign/ed25519/ref10/sign.c @@ -32,6 +32,38 @@ _crypto_sign_ed25519_clamp(unsigned char k[32]) k[31] |= 64; } +#ifdef ED25519_NONDETERMINISTIC +/* r = hash(B || empty_labelset || Z || pad1 || k || pad2 || empty_labelset || K || extra || M) (mod q) */ +static void +_crypto_sign_ed25519_synthetic_r_hv(crypto_hash_sha512_state *hs, + unsigned char nonce[64], + unsigned char sk_copy[64], + const unsigned char sk[64]) +{ + static const unsigned char B[32] = { + 0x58, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, + 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, + 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, + 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, + }; + static const unsigned char zeros[16] = { 0x00 }; + static const unsigned char empty_labelset[3] = { 0x02, 0x00, 0x00 }; + + memcpy(sk_copy, sk, 32); + _crypto_sign_ed25519_clamp(sk_copy); + crypto_hash_sha512_update(hs, B, 32); + crypto_hash_sha512_update(hs, empty_labelset, 3); + randombytes_buf(nonce, 32); + crypto_hash_sha512_update(hs, nonce, 32); + crypto_hash_sha512_update(hs, zeros, 16 - (32 + 3 + 32) % 16); + crypto_hash_sha512_update(hs, sk_copy, 32); + /* empty pad2 */ + crypto_hash_sha512_update(hs, empty_labelset, 3); + crypto_hash_sha512_update(hs, sk + 32, 32); + /* empty extra */ +} +#endif + int _crypto_sign_ed25519_detached(unsigned char *sig, unsigned long long *siglen_p, const unsigned char *m, unsigned long long mlen, @@ -44,30 +76,8 @@ _crypto_sign_ed25519_detached(unsigned char *sig, unsigned long long *siglen_p, ge_p3 R; #ifdef ED25519_NONDETERMINISTIC - { - static const unsigned char B[32] = { - 0x58, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - }; - static const unsigned char zeros[16] = { 0x00 }; - static const unsigned char empty_labelset[3] = { 0x02, 0x00, 0x00 }; - - memcpy(az, sk, 32); - _crypto_sign_ed25519_clamp(az); - _crypto_sign_ed25519_ref10_hinit(&hs, prehashed); - crypto_hash_sha512_update(&hs, B, 32); - crypto_hash_sha512_update(&hs, empty_labelset, 3); - randombytes_buf(nonce, 32); - crypto_hash_sha512_update(&hs, nonce, 32); - crypto_hash_sha512_update(&hs, zeros, 16 - (32 + 3 + 32) % 16); - crypto_hash_sha512_update(&hs, az, 32); - /* empty pad2 */ - crypto_hash_sha512_update(&hs, empty_labelset, 3); - crypto_hash_sha512_update(&hs, sk + 32, 32); - /* empty extra */ - } + _crypto_sign_ed25519_ref10_hinit(&hs, prehashed); + _crypto_sign_ed25519_synthetic_r_hv(&hs, nonce, az, sk); #else crypto_hash_sha512(az, sk, 32); _crypto_sign_ed25519_clamp(az);