|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Poly1305 one-time authenticator (D. J. Bernstein; RFC 8439 Section 2.5). More...
#include "protocore_config.h"Go to the source code of this file.
Classes | |
| struct | Poly1305Ns |
| Dispatch table. Addressed by offset, so the layout is asserted below. More... | |
Macros | |
| #define | PROTOCORE_POLY1305_KEY_LEN 32 |
| Poly1305 one-time key length in bytes (r || s). | |
| #define | PROTOCORE_POLY1305_TAG_LEN 16 |
| Poly1305 tag length in bytes. | |
Functions | |
| PROTOCORE_NS_LAYOUT (Poly1305Ns, mac) | |
| proto_bool | protocore_poly1305_mac (uint8_t *work, const uint8_t *key, const uint8_t *msg, size_t len, uint8_t *out) |
| Take the 16-byte tag over the whole message under the one-time key. | |
Variables | |
| PROTOCORE_NS Poly1305Ns Poly1305 | PROTOCORE_UNUSED = {.mac = protocore_poly1305_mac} |
| Module namespace. | |
Poly1305 one-time authenticator (D. J. Bernstein; RFC 8439 Section 2.5).
A one-time MAC over a message under a 32-byte key (r || s). Used by the chach.nosp@m.a20-.nosp@m.poly1.nosp@m.305@.nosp@m.opens.nosp@m.sh.c.nosp@m.om cipher, where the key is the first 32 bytes of the ChaCha20 block-0 keystream for the packet. 130-bit modular arithmetic in 5 x 26-bit limbs (poly1305-donna layout). Pure, no heap; the caller must use each key exactly once.
work is PROTOCORE_POLY1305_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. The borrow IS the accumulator, so a tag taken under a caller whose own borrow is still live is a second borrow and the two never collide.
Definition in file poly1305.h.
| #define PROTOCORE_POLY1305_KEY_LEN 32 |
Poly1305 one-time key length in bytes (r || s).
Definition at line 31 of file poly1305.h.
| #define PROTOCORE_POLY1305_TAG_LEN 16 |
Poly1305 tag length in bytes.
Definition at line 34 of file poly1305.h.
| PROTOCORE_NS_LAYOUT | ( | Poly1305Ns | , |
| mac | |||
| ) |
| proto_bool protocore_poly1305_mac | ( | uint8_t * | work, |
| const uint8_t * | key, | ||
| const uint8_t * | msg, | ||
| size_t | len, | ||
| uint8_t * | out | ||
| ) |
Take the 16-byte tag over the whole message under the one-time key.
| work | PROTOCORE_POLY1305_BORROW bytes the caller took. Not held past the call. |
| key | PROTOCORE_POLY1305_KEY_LEN bytes, used exactly once |
| msg | the message |
| len | its length |
| out | PROTOCORE_POLY1305_TAG_LEN bytes |
| PROTOCORE_NS Poly1305Ns Poly1305 PROTOCORE_UNUSED = {.mac = protocore_poly1305_mac} |
Module namespace.
Definition at line 55 of file poly1305.h.