|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Streamlined NTRU Prime sntrup761 KEM - keygen, encapsulation, decapsulation. More...
#include "protocore_config.h"Go to the source code of this file.
Classes | |
| struct | Sntrup761Ns |
| Dispatch table. Addressed by offset, so the layout is asserted below. More... | |
Macros | |
| #define | PROTOCORE_SNTRUP761_PK_BYTES 1158 |
| public key (Rq-encoded h) | |
| #define | PROTOCORE_SNTRUP761_SK_BYTES 1763 |
| secret key (f, 1/g, pk, rho, cache) | |
| #define | PROTOCORE_SNTRUP761_CT_BYTES 1039 |
| ciphertext (Rounded-encoded c || 32-byte Confirm) | |
| #define | PROTOCORE_SNTRUP761_SS_BYTES 32 |
| shared secret (session key) | |
| #define | PROTOCORE_SNTRUP761_SK_PK_OFFSET 382 |
| the public key is embedded in sk at this offset (2*Small_bytes); the KEM initiator reconstructs/*#end#*/ | |
Functions | |
| PROTOCORE_NS_LAYOUT (Sntrup761Ns, keypair, enc, dec) | |
| proto_bool | protocore_sntrup761_keypair (uint8_t *work, uint8_t *pk, uint8_t *sk) |
| Generate a keypair: send pk, hold sk until the peer's ciphertext arrives. | |
| proto_bool | protocore_sntrup761_enc (uint8_t *work, const uint8_t *pk, uint8_t *ct, uint8_t *ss) |
| Draw a short polynomial, encrypt it under pk, derive the session key. | |
| proto_bool | protocore_sntrup761_dec (uint8_t *work, const uint8_t *sk, const uint8_t *ct, uint8_t *ss) |
| Recover the session key from the peer's ciphertext under sk. | |
Variables | |
| PROTOCORE_NS Sntrup761Ns Sntrup761 | PROTOCORE_UNUSED |
| Module namespace. | |
Streamlined NTRU Prime sntrup761 KEM - keygen, encapsulation, decapsulation.
The second post-quantum KEM OpenSSH ships (alongside ML-KEM-768), used by the sntru.nosp@m.p761.nosp@m.x2551.nosp@m.9-sh.nosp@m.a512@.nosp@m.open.nosp@m.ssh.c.nosp@m.om hybrid key exchange. Both KEM roles are provided:
Streamlined NTRU Prime, parameter set sntrup761 (p=761, q=4591, w=286): a lattice KEM over the ring Z_q[x]/(x^761 - x - 1). The algorithm and the byte encodings match OpenSSH's embedded sntrup761 reference (public domain; D. J. Bernstein et al.) so the ciphertext this produces decapsulates byte-for-byte on a real OpenSSH peer. Zero heap; SHA-512 through Sha512Ns, randomness through protocore_rand_fill() (crypto/rng).
Sntrup761Ns::dec is implicit-rejection (FO): a ciphertext that fails the re-encrypt check yields a deterministic pseudo-random secret rather than an error, so Sntrup761Ns::ok is true for any well-formed call.
work is PROTOCORE_SNTRUP761_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. That is what keeps the hashed key material in it from outliving the caller.
Definition in file sntrup761.h.
| #define PROTOCORE_SNTRUP761_PK_BYTES 1158 |
public key (Rq-encoded h)
Definition at line 41 of file sntrup761.h.
| #define PROTOCORE_SNTRUP761_SK_BYTES 1763 |
secret key (f, 1/g, pk, rho, cache)
Definition at line 42 of file sntrup761.h.
| #define PROTOCORE_SNTRUP761_CT_BYTES 1039 |
ciphertext (Rounded-encoded c || 32-byte Confirm)
Definition at line 43 of file sntrup761.h.
| #define PROTOCORE_SNTRUP761_SS_BYTES 32 |
shared secret (session key)
Definition at line 44 of file sntrup761.h.
| #define PROTOCORE_SNTRUP761_SK_PK_OFFSET 382 |
the public key is embedded in sk at this offset (2*Small_bytes); the KEM initiator reconstructs/*#end#*/
Definition at line 46 of file sntrup761.h.
| PROTOCORE_NS_LAYOUT | ( | Sntrup761Ns | , |
| keypair | , | ||
| enc | , | ||
| dec | |||
| ) |
| proto_bool protocore_sntrup761_keypair | ( | uint8_t * | work, |
| uint8_t * | pk, | ||
| uint8_t * | sk | ||
| ) |
Generate a keypair: send pk, hold sk until the peer's ciphertext arrives.
| work | PROTOCORE_SNTRUP761_BORROW bytes the caller took. Not held past the call. |
| pk | PROTOCORE_SNTRUP761_PK_BYTES bytes |
| sk | PROTOCORE_SNTRUP761_SK_BYTES bytes |
| proto_bool protocore_sntrup761_enc | ( | uint8_t * | work, |
| const uint8_t * | pk, | ||
| uint8_t * | ct, | ||
| uint8_t * | ss | ||
| ) |
Draw a short polynomial, encrypt it under pk, derive the session key.
| work | PROTOCORE_SNTRUP761_BORROW bytes the caller took. Not held past the call. |
| pk | the peer's public key, PROTOCORE_SNTRUP761_PK_BYTES bytes |
| ct | PROTOCORE_SNTRUP761_CT_BYTES bytes |
| ss | PROTOCORE_SNTRUP761_SS_BYTES bytes |
| proto_bool protocore_sntrup761_dec | ( | uint8_t * | work, |
| const uint8_t * | sk, | ||
| const uint8_t * | ct, | ||
| uint8_t * | ss | ||
| ) |
Recover the session key from the peer's ciphertext under sk.
| work | PROTOCORE_SNTRUP761_BORROW bytes the caller took. Not held past the call. |
| sk | this side's secret key, PROTOCORE_SNTRUP761_SK_BYTES bytes |
| ct | the peer's ciphertext, PROTOCORE_SNTRUP761_CT_BYTES bytes |
| ss | PROTOCORE_SNTRUP761_SS_BYTES bytes |
| PROTOCORE_NS Sntrup761Ns Sntrup761 PROTOCORE_UNUSED |
Module namespace.
Definition at line 85 of file sntrup761.h.