ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
poly1305.h
Go to the documentation of this file.
1// ProtoCore v1.0.16 - Copyright (C) 2026 Douglas Quigg (dstroy0) <dquigg123@gmail.com>
2// SPDX-License-Identifier: AGPL-3.0-or-later
3
4#ifndef PROTOCORE_POLY1305_H
5#define PROTOCORE_POLY1305_H
6
7#include "protocore_config.h" // the entry point: protocore_types.h for the widths
8
10
11/**
12 * @file poly1305.h
13 * @brief Poly1305 one-time authenticator (D. J. Bernstein; RFC 8439 Section 2.5).
14 *
15 * A one-time MAC over a message under a 32-byte key (r || s). Used by the
16 * chacha20-poly1305@openssh.com cipher, where the key is the first 32 bytes of the ChaCha20
17 * block-0 keystream for the packet. 130-bit modular arithmetic in 5 x 26-bit limbs (poly1305-donna
18 * layout). Pure, no heap; the caller must use each key exactly once.
19 *
20 * @c work is PROTOCORE_POLY1305_BORROW secure bytes the CALLER took, at an address it knows. It
21 * is not held past the call, so nothing here aliases it. The caller releases
22 * it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes
23 * it. The borrow IS the accumulator, so a tag taken under a caller whose own borrow is still live is
24 * a second borrow and the two never collide.
25 *
26 * @author Douglas Quigg (dstroy0)
27 * @date 2026
28 */
29
30/** @brief Poly1305 one-time key length in bytes (r || s). */
31#define PROTOCORE_POLY1305_KEY_LEN 32
32
33/** @brief Poly1305 tag length in bytes. */
34#define PROTOCORE_POLY1305_TAG_LEN 16
35
36/** @brief Dispatch table. Addressed by offset, so the layout is asserted below. */
37typedef struct
38{
39 proto_bool (*mac)(uint8_t *, const uint8_t *, const uint8_t *, size_t, uint8_t *);
42
43/**
44 * @brief Take the 16-byte tag over the whole message under the one-time key.
45 * @param work PROTOCORE_POLY1305_BORROW bytes the caller took. Not held past the call.
46 * @param key PROTOCORE_POLY1305_KEY_LEN bytes, used exactly once
47 * @param msg the message
48 * @param len its length
49 * @param out PROTOCORE_POLY1305_TAG_LEN bytes
50 * @return PROTO_TRUE on success.
51 */
52proto_bool protocore_poly1305_mac(uint8_t *work, const uint8_t *key, const uint8_t *msg, size_t len, uint8_t *out);
53
54/** @brief Module namespace. */
56
58
59#endif // PROTOCORE_POLY1305_H
#define PROTOCORE_NS_LAYOUT(T,...)
Pin every dispatch slot of a table that is nothing but function pointers.
#define PROTOCORE_NS
Storage for a dispatch table. The const is load bearing.
PROTOCORE_NS Poly1305Ns Poly1305 PROTOCORE_UNUSED
Module namespace.
Definition poly1305.h:55
proto_bool protocore_poly1305_mac(uint8_t *work, const uint8_t *key, const uint8_t *msg, size_t len, uint8_t *out)
Take the 16-byte tag over the whole message under the one-time key.
Dispatch table. Addressed by offset, so the layout is asserted below.
Definition poly1305.h:38
proto_bool(* mac)(uint8_t *, const uint8_t *, const uint8_t *, size_t, uint8_t *)
Definition poly1305.h:39
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
Definition types.h:96
_Bool proto_bool
The truth value.
Definition types.h:64
#define PROTOCORE_END_DECLS
Definition types.h:97