ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
poly1305.h File Reference

Poly1305 one-time authenticator (D. J. Bernstein; RFC 8439 Section 2.5). More...

#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  Poly1305Ns
 Dispatch table. Addressed by offset, so the layout is asserted below. More...
 

Macros

#define PROTOCORE_POLY1305_KEY_LEN   32
 Poly1305 one-time key length in bytes (r || s).
 
#define PROTOCORE_POLY1305_TAG_LEN   16
 Poly1305 tag length in bytes.
 

Functions

 PROTOCORE_NS_LAYOUT (Poly1305Ns, mac)
 
proto_bool protocore_poly1305_mac (uint8_t *work, const uint8_t *key, const uint8_t *msg, size_t len, uint8_t *out)
 Take the 16-byte tag over the whole message under the one-time key.
 

Variables

PROTOCORE_NS Poly1305Ns Poly1305 PROTOCORE_UNUSED = {.mac = protocore_poly1305_mac}
 Module namespace.
 

Detailed Description

Poly1305 one-time authenticator (D. J. Bernstein; RFC 8439 Section 2.5).

A one-time MAC over a message under a 32-byte key (r || s). Used by the chach.nosp@m.a20-.nosp@m.poly1.nosp@m.305@.nosp@m.opens.nosp@m.sh.c.nosp@m.om cipher, where the key is the first 32 bytes of the ChaCha20 block-0 keystream for the packet. 130-bit modular arithmetic in 5 x 26-bit limbs (poly1305-donna layout). Pure, no heap; the caller must use each key exactly once.

work is PROTOCORE_POLY1305_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. The borrow IS the accumulator, so a tag taken under a caller whose own borrow is still live is a second borrow and the two never collide.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file poly1305.h.

Macro Definition Documentation

◆ PROTOCORE_POLY1305_KEY_LEN

#define PROTOCORE_POLY1305_KEY_LEN   32

Poly1305 one-time key length in bytes (r || s).

Definition at line 31 of file poly1305.h.

◆ PROTOCORE_POLY1305_TAG_LEN

#define PROTOCORE_POLY1305_TAG_LEN   16

Poly1305 tag length in bytes.

Definition at line 34 of file poly1305.h.

Function Documentation

◆ PROTOCORE_NS_LAYOUT()

PROTOCORE_NS_LAYOUT ( Poly1305Ns  ,
mac   
)

◆ protocore_poly1305_mac()

proto_bool protocore_poly1305_mac ( uint8_t *  work,
const uint8_t *  key,
const uint8_t *  msg,
size_t  len,
uint8_t *  out 
)

Take the 16-byte tag over the whole message under the one-time key.

Parameters
workPROTOCORE_POLY1305_BORROW bytes the caller took. Not held past the call.
keyPROTOCORE_POLY1305_KEY_LEN bytes, used exactly once
msgthe message
lenits length
outPROTOCORE_POLY1305_TAG_LEN bytes
Returns
PROTO_TRUE on success.

Variable Documentation

◆ PROTOCORE_UNUSED

PROTOCORE_NS Poly1305Ns Poly1305 PROTOCORE_UNUSED = {.mac = protocore_poly1305_mac}

Module namespace.

Definition at line 55 of file poly1305.h.