ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
sntrup761.h File Reference

Streamlined NTRU Prime sntrup761 KEM - keygen, encapsulation, decapsulation. More...

#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  Sntrup761Ns
 Dispatch table. Addressed by offset, so the layout is asserted below. More...
 

Macros

#define PROTOCORE_SNTRUP761_PK_BYTES   1158
 public key (Rq-encoded h)
 
#define PROTOCORE_SNTRUP761_SK_BYTES   1763
 secret key (f, 1/g, pk, rho, cache)
 
#define PROTOCORE_SNTRUP761_CT_BYTES   1039
 ciphertext (Rounded-encoded c || 32-byte Confirm)
 
#define PROTOCORE_SNTRUP761_SS_BYTES   32
 shared secret (session key)
 
#define PROTOCORE_SNTRUP761_SK_PK_OFFSET    382
 the public key is embedded in sk at this offset (2*Small_bytes); the KEM initiator reconstructs/*#end#*‍/
 

Functions

 PROTOCORE_NS_LAYOUT (Sntrup761Ns, keypair, enc, dec)
 
proto_bool protocore_sntrup761_keypair (uint8_t *work, uint8_t *pk, uint8_t *sk)
 Generate a keypair: send pk, hold sk until the peer's ciphertext arrives.
 
proto_bool protocore_sntrup761_enc (uint8_t *work, const uint8_t *pk, uint8_t *ct, uint8_t *ss)
 Draw a short polynomial, encrypt it under pk, derive the session key.
 
proto_bool protocore_sntrup761_dec (uint8_t *work, const uint8_t *sk, const uint8_t *ct, uint8_t *ss)
 Recover the session key from the peer's ciphertext under sk.
 

Variables

PROTOCORE_NS Sntrup761Ns Sntrup761 PROTOCORE_UNUSED
 Module namespace.
 

Detailed Description

Streamlined NTRU Prime sntrup761 KEM - keygen, encapsulation, decapsulation.

The second post-quantum KEM OpenSSH ships (alongside ML-KEM-768), used by the sntru.nosp@m.p761.nosp@m.x2551.nosp@m.9-sh.nosp@m.a512@.nosp@m.open.nosp@m.ssh.c.nosp@m.om hybrid key exchange. Both KEM roles are provided:

  • Encapsulation (SSH server / responder): given the peer's public key, produce a ciphertext and a shared secret.
  • KeyGen + Decapsulation (the reverse-SSH client / initiator): generate a keypair, send the public key, then recover the shared secret from the server's ciphertext.

Streamlined NTRU Prime, parameter set sntrup761 (p=761, q=4591, w=286): a lattice KEM over the ring Z_q[x]/(x^761 - x - 1). The algorithm and the byte encodings match OpenSSH's embedded sntrup761 reference (public domain; D. J. Bernstein et al.) so the ciphertext this produces decapsulates byte-for-byte on a real OpenSSH peer. Zero heap; SHA-512 through Sha512Ns, randomness through protocore_rand_fill() (crypto/rng).

Sntrup761Ns::dec is implicit-rejection (FO): a ciphertext that fails the re-encrypt check yields a deterministic pseudo-random secret rather than an error, so Sntrup761Ns::ok is true for any well-formed call.

work is PROTOCORE_SNTRUP761_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. That is what keeps the hashed key material in it from outliving the caller.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file sntrup761.h.

Macro Definition Documentation

◆ PROTOCORE_SNTRUP761_PK_BYTES

#define PROTOCORE_SNTRUP761_PK_BYTES   1158

public key (Rq-encoded h)

Definition at line 41 of file sntrup761.h.

◆ PROTOCORE_SNTRUP761_SK_BYTES

#define PROTOCORE_SNTRUP761_SK_BYTES   1763

secret key (f, 1/g, pk, rho, cache)

Definition at line 42 of file sntrup761.h.

◆ PROTOCORE_SNTRUP761_CT_BYTES

#define PROTOCORE_SNTRUP761_CT_BYTES   1039

ciphertext (Rounded-encoded c || 32-byte Confirm)

Definition at line 43 of file sntrup761.h.

◆ PROTOCORE_SNTRUP761_SS_BYTES

#define PROTOCORE_SNTRUP761_SS_BYTES   32

shared secret (session key)

Definition at line 44 of file sntrup761.h.

◆ PROTOCORE_SNTRUP761_SK_PK_OFFSET

#define PROTOCORE_SNTRUP761_SK_PK_OFFSET    382

the public key is embedded in sk at this offset (2*Small_bytes); the KEM initiator reconstructs/*#end#*‍/

Definition at line 46 of file sntrup761.h.

Function Documentation

◆ PROTOCORE_NS_LAYOUT()

PROTOCORE_NS_LAYOUT ( Sntrup761Ns  ,
keypair  ,
enc  ,
dec   
)

◆ protocore_sntrup761_keypair()

proto_bool protocore_sntrup761_keypair ( uint8_t *  work,
uint8_t *  pk,
uint8_t *  sk 
)

Generate a keypair: send pk, hold sk until the peer's ciphertext arrives.

Parameters
workPROTOCORE_SNTRUP761_BORROW bytes the caller took. Not held past the call.
pkPROTOCORE_SNTRUP761_PK_BYTES bytes
skPROTOCORE_SNTRUP761_SK_BYTES bytes
Returns
PROTO_TRUE on success.

◆ protocore_sntrup761_enc()

proto_bool protocore_sntrup761_enc ( uint8_t *  work,
const uint8_t *  pk,
uint8_t *  ct,
uint8_t *  ss 
)

Draw a short polynomial, encrypt it under pk, derive the session key.

Parameters
workPROTOCORE_SNTRUP761_BORROW bytes the caller took. Not held past the call.
pkthe peer's public key, PROTOCORE_SNTRUP761_PK_BYTES bytes
ctPROTOCORE_SNTRUP761_CT_BYTES bytes
ssPROTOCORE_SNTRUP761_SS_BYTES bytes
Returns
PROTO_TRUE on success.

◆ protocore_sntrup761_dec()

proto_bool protocore_sntrup761_dec ( uint8_t *  work,
const uint8_t *  sk,
const uint8_t *  ct,
uint8_t *  ss 
)

Recover the session key from the peer's ciphertext under sk.

Parameters
workPROTOCORE_SNTRUP761_BORROW bytes the caller took. Not held past the call.
skthis side's secret key, PROTOCORE_SNTRUP761_SK_BYTES bytes
ctthe peer's ciphertext, PROTOCORE_SNTRUP761_CT_BYTES bytes
ssPROTOCORE_SNTRUP761_SS_BYTES bytes
Returns
PROTO_TRUE on success.

Variable Documentation

◆ PROTOCORE_UNUSED

PROTOCORE_NS Sntrup761Ns Sntrup761 PROTOCORE_UNUSED
Initial value:
= {
proto_bool protocore_sntrup761_enc(uint8_t *work, const uint8_t *pk, uint8_t *ct, uint8_t *ss)
Draw a short polynomial, encrypt it under pk, derive the session key.
proto_bool protocore_sntrup761_dec(uint8_t *work, const uint8_t *sk, const uint8_t *ct, uint8_t *ss)
Recover the session key from the peer's ciphertext under sk.
proto_bool protocore_sntrup761_keypair(uint8_t *work, uint8_t *pk, uint8_t *sk)
Generate a keypair: send pk, hold sk until the peer's ciphertext arrives.

Module namespace.

Definition at line 85 of file sntrup761.h.