1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
|
/* chacha-core-internal.c
*
* Core functionality of the ChaCha stream cipher.
* Heavily based on the Salsa20 implementation in Nettle.
*
*/
/* nettle, low-level cryptographics library
*
* Copyright (C) 2013 Joachim Strömbergson
* Copyright (C) 2012 Simon Josefsson, Niels Möller
*
* The nettle library is free software; you can redistribute it and/or modify
* it under the terms of the GNU Lesser General Public License as published by
* the Free Software Foundation; either version 2.1 of the License, or (at your
* option) any later version.
*
* The nettle library is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public
* License for more details.
*
* You should have received a copy of the GNU Lesser General Public License
* along with the nettle library; see the file COPYING.LIB. If not, write to
* the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,
* MA 02111-1301, USA.
*/
/* Based on:
chacha-ref.c version 2008.01.20.
D. J. Bernstein
Public domain.
*/
#if HAVE_CONFIG_H
# include "config.h"
#endif
#include <assert.h>
#include <string.h>
#include "chacha.h"
#include "macros.h"
#ifndef CHACHA_DEBUG
# define CHACHA_DEBUG 0
#endif
#if CHACHA_DEBUG
# include <stdio.h>
# define DEBUG(i) do { \
unsigned debug_j; \
for (debug_j = 0; debug_j < 16; debug_j++) \
{ \
if (debug_j == 0) \
fprintf(stderr, "%2d:", (i)); \
else if (debug_j % 4 == 0) \
fprintf(stderr, "\n "); \
fprintf(stderr, " %8x", x[debug_j]); \
} \
fprintf(stderr, "\n"); \
} while (0)
#else
# define DEBUG(i)
#endif
#ifdef WORDS_BIGENDIAN
#define LE_SWAP32(v) \
((ROTL32(8, v) & 0x00FF00FFUL) | \
(ROTL32(24, v) & 0xFF00FF00UL))
#else
#define LE_SWAP32(v) (v)
#endif
#define QROUND(x0, x1, x2, x3) do { \
x0 = x0 + x1; x3 = ROTL32(16, (x0 ^ x3)); \
x2 = x2 + x3; x1 = ROTL32(12, (x1 ^ x2)); \
x0 = x0 + x1; x3 = ROTL32(8, (x0 ^ x3)); \
x2 = x2 + x3; x1 = ROTL32(7, (x1 ^ x2)); \
} while(0)
void
_chacha_core(uint32_t *dst, const uint32_t *src, unsigned rounds)
{
uint32_t x[_CHACHA_STATE_LENGTH];
unsigned i;
assert ( (rounds & 1) == 0);
memcpy (x, src, sizeof(x));
for (i = 0; i < rounds;i += 2)
{
DEBUG (i);
QROUND(x[0], x[4], x[8], x[12]);
QROUND(x[1], x[5], x[9], x[13]);
QROUND(x[2], x[6], x[10], x[14]);
QROUND(x[3], x[7], x[11], x[15]);
DEBUG (i+1);
QROUND(x[0], x[5], x[10], x[15]);
QROUND(x[1], x[6], x[11], x[12]);
QROUND(x[2], x[7], x[8], x[13]);
QROUND(x[3], x[4], x[9], x[14]);
}
DEBUG (i);
for (i = 0; i < _CHACHA_STATE_LENGTH; i++)
{
uint32_t t = x[i] + src[i];
dst[i] = LE_SWAP32 (t);
}
}
|