Skip to main content
  • Home
  • Development
  • Documentation
  • Donate
  • Operational login
  • Browse the archive

swh logo
SoftwareHeritage
Software
Heritage
Archive
Features
  • Search

  • Downloads

  • Save code now

  • Add forge now

  • Help

Revision 81a0bf97e2012c369f800f26e2e3d3651cde7a35 authored by Matthias J. Kannwischer on 29 July 2021, 07:22:18 UTC, committed by Matthias J. Kannwischer on 02 August 2021, 03:06:46 UTC
Update NTRU Prime; add new round 3 parameter sets
1 parent 819f906
  • Files
  • Changes
  • b53fadd
  • /
  • crypto_sign
  • /
  • sphincs-sha256-256s-simple
  • /
  • avx2
  • /
  • hash_sha256.c
Raw File Download
Permalinks

To reference or cite the objects present in the Software Heritage archive, permalinks based on SoftWare Hash IDentifiers (SWHIDs) must be used.
Select below a type of object currently browsed in order to display its associated SWHID and permalink.

  • revision
  • directory
  • content
revision badge
swh:1:rev:81a0bf97e2012c369f800f26e2e3d3651cde7a35
directory badge Iframe embedding
swh:1:dir:ab81f3fad3967085d8b65454dca3064986c432c8
content badge Iframe embedding
swh:1:cnt:4a48a99ed608f5ef5f9941ff6d2f5dabe447e3ee
Citations

This interface enables to generate software citations, provided that the root directory of browsed objects contains a citation.cff or codemeta.json file.
Select below a type of object currently browsed in order to generate citations for them.

  • revision
  • directory
  • content
Generate software citation in BibTex format (requires biblatex-software package)
Generating citation ...
Generate software citation in BibTex format (requires biblatex-software package)
Generating citation ...
Generate software citation in BibTex format (requires biblatex-software package)
Generating citation ...
hash_sha256.c
#include <stdint.h>
#include <string.h>

#include "address.h"
#include "hash.h"
#include "params.h"
#include "utils.h"

#include "sha2.h"
#include "sha256.h"
#include "sha256x8.h"

/**
 * Initializes the hash function states
 */
void PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_initialize_hash_function(
    hash_state *hash_state_seeded,
    const unsigned char *pub_seed, const unsigned char *sk_seed) {
    PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_seed_state(&hash_state_seeded->x1, pub_seed);
    PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_seed_statex8(&hash_state_seeded->x8, pub_seed);
    (void)sk_seed; /* Suppress an 'unused parameter' warning. */
}

/**
 * Cleans up the hash function states
 */
void PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_destroy_hash_function(hash_state *hash_state_seeded) {
    sha256_inc_ctx_release(&hash_state_seeded->x1);
}

/*
 * Computes PRF(key, addr), given a secret key of PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N bytes and an address
 */
void PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_prf_addr(unsigned char *out, const unsigned char *key, const uint32_t addr[8],
        const hash_state *hash_state_seeded) {
    unsigned char buf[PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_ADDR_BYTES];
    unsigned char outbuf[PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_OUTPUT_BYTES];

    memcpy(buf, key, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);
    PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_compress_address(buf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N, addr);

    sha256(outbuf, buf, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_ADDR_BYTES);
    memcpy(out, outbuf, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);

    (void)hash_state_seeded; /* Prevent unused parameter warning. */
}

/**
 * Computes the message-dependent randomness R, using a secret seed as a key
 * for HMAC, and an optional randomization value prefixed to the message.
 * This requires m to have at least PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N space
 * available in front of the pointer, i.e. before the message to use for the
 * prefix. This is necessary to prevent having to move the message around (and
 * allocate memory for it).
 */
void PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_gen_message_random(
    unsigned char *R,
    const unsigned char *sk_prf, const unsigned char *optrand,
    const unsigned char *m, size_t mlen, const hash_state *hash_state_seeded) {
    unsigned char buf[PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_OUTPUT_BYTES];
    sha256ctx state;
    int i;

    /* This implements HMAC-SHA256 */
    for (i = 0; i < PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N; i++) {
        buf[i] = 0x36 ^ sk_prf[i];
    }
    memset(buf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N, 0x36, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);

    sha256_inc_init(&state);
    sha256_inc_blocks(&state, buf, 1);

    memcpy(buf, optrand, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);

    /* If optrand + message cannot fill up an entire block */
    if (PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N + mlen < PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES) {
        memcpy(buf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N, m, mlen);
        sha256_inc_finalize(buf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES, &state,
                            buf, mlen + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);
    }
    /* Otherwise first fill a block, so that finalize only uses the message */
    else {
        memcpy(buf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N, m, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);
        sha256_inc_blocks(&state, buf, 1);

        m += PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N;
        mlen -= PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N;
        sha256_inc_finalize(buf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES, &state, m, mlen);
    }

    for (i = 0; i < PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N; i++) {
        buf[i] = 0x5c ^ sk_prf[i];
    }
    memset(buf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N, 0x5c, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);

    sha256(buf, buf, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_OUTPUT_BYTES);
    memcpy(R, buf, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);

    (void)hash_state_seeded; /* Prevent unused parameter warning. */
}

/**
 * Computes the message hash using R, the public key, and the message.
 * Outputs the message digest and the index of the leaf. The index is split in
 * the tree index and the leaf index, for convenient copying to an address.
 */
void PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_hash_message(
    unsigned char *digest, uint64_t *tree, uint32_t *leaf_idx,
    const unsigned char *R, const unsigned char *pk,
    const unsigned char *m, size_t mlen,
    const hash_state *hash_state_seeded) {
#define PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_BITS (PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_HEIGHT * (PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_D - 1))
#define PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_BYTES ((PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_BITS + 7) / 8)
#define PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_LEAF_BITS PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_HEIGHT
#define PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_LEAF_BYTES ((PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_LEAF_BITS + 7) / 8)
#define PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_DGST_BYTES (PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_FORS_MSG_BYTES + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_BYTES + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_LEAF_BYTES)

    unsigned char seed[PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_OUTPUT_BYTES + 4];

    /* Round to nearest multiple of PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES */
#define PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_INBLOCKS (((PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - 1) & \
        -PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES) / PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES)
    unsigned char inbuf[PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_INBLOCKS * PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES];

    unsigned char buf[PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_DGST_BYTES];
    unsigned char *bufp = buf;
    sha256ctx state;

    sha256_inc_init(&state);

    memcpy(inbuf, R, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N);
    memcpy(inbuf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N, pk, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES);

    /* If R + pk + message cannot fill up an entire block */
    if (PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES + mlen < PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_INBLOCKS * PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES) {
        memcpy(inbuf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES, m, mlen);
        sha256_inc_finalize(seed, &state, inbuf, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES + mlen);
    }
    /* Otherwise first fill a block, so that finalize only uses the message */
    else {
        memcpy(inbuf + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N + PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES, m,
               PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_INBLOCKS * PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES);
        sha256_inc_blocks(&state, inbuf, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_INBLOCKS);

        m += PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_INBLOCKS * PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES;
        mlen -= PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_INBLOCKS * PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_BLOCK_BYTES - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_N - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_PK_BYTES;
        sha256_inc_finalize(seed, &state, m, mlen);
    }

    /* By doing this in two steps, we prevent hashing the message twice;
       otherwise each iteration in MGF1 would hash the message again. */
    PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_mgf1(bufp, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_DGST_BYTES, seed, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_SHA256_OUTPUT_BYTES);

    memcpy(digest, bufp, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_FORS_MSG_BYTES);
    bufp += PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_FORS_MSG_BYTES;

    *tree = PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_bytes_to_ull(bufp, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_BYTES);
    *tree &= (~(uint64_t)0) >> (64 - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_BITS);
    bufp += PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_TREE_BYTES;

    *leaf_idx = (uint32_t)PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_bytes_to_ull(
                    bufp, PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_LEAF_BYTES);
    *leaf_idx &= (~(uint32_t)0) >> (32 - PQCLEAN_SPHINCSSHA256256SSIMPLE_AVX2_LEAF_BITS);

    (void)hash_state_seeded; /* Prevent unused parameter warning. */
}
The diff you're trying to view is too large. Only the first 1000 changed files have been loaded.
Showing with 0 additions and 0 deletions (0 / 0 diffs computed)
swh spinner

Computing file changes ...

back to top

Software Heritage — Copyright (C) 2015–2025, The Software Heritage developers. License: GNU AGPLv3+.
The source code of Software Heritage itself is available on our development forge.
The source code files archived by Software Heritage are available under their own copyright and licenses.
Terms of use: Archive access, API— Contact— JavaScript license information— Web API