John M. Schanck
0ff7886b08
narrowing warnings
2020-09-11 17:02:19 -04:00
John M. Schanck
906b3ca175
more endianness fixes
2020-09-11 13:36:03 -04:00
John M. Schanck
e95daec1dd
remove unused function
2020-09-11 12:47:03 -04:00
John M. Schanck
4aab2dcb23
Rename log and exp to gf_log and gf_exp
2020-09-11 12:38:08 -04:00
John M. Schanck
04f7375c32
Some MS compiler fixes
2020-09-10 19:30:03 -04:00
John M. Schanck
cc7eae7ce7
typo and more endianness fixes
2020-09-10 17:15:55 -04:00
John M. Schanck
de4e3b49ab
remove spaces before semicolons
2020-09-10 17:02:22 -04:00
John M. Schanck
2a261a3f36
Fix endianness issues
2020-09-10 16:27:12 -04:00
John M. Schanck
1309009b59
compiler warnings
2020-09-10 16:26:03 -04:00
John M. Schanck
23238dbed5
Initialize arrays in fft.c and fix a few compiler warnings
2020-09-10 10:26:30 -04:00
John M. Schanck
859522e1c4
Fix left shift overflow for MASK_N2
2020-09-09 17:20:11 -04:00
John M. Schanck
b3a651aebe
Remove BITMASK macro
2020-09-09 16:52:51 -04:00
John M. Schanck
8dc9f8fa89
Remove old HQC implementations
2020-09-09 16:10:44 -04:00
John M. Schanck
834f546349
Avoid ==, !=, etc in arithmetic expressions. Some compilers will produce non-constant time code.
2020-09-09 16:07:20 -04:00
John M. Schanck
f0940f92f2
Avoid using log(a) to check if a==0
2020-09-09 16:05:44 -04:00
John M. Schanck
8b6b9ddbb6
Satisfy linter
2020-09-09 10:03:19 -04:00
John M. Schanck
4a301f1896
Simplify hqc-rmrs*/clean/reed_muller.c and fix potentially non-constant time behavior.
2020-09-09 09:44:31 -04:00
John M. Schanck
57282fe962
Fix an avx2/gf2x.c buffer overflow
2020-09-08 10:23:00 -04:00
John M. Schanck
9113313eab
Replace avx2 'reduce' in gf2x
2020-09-07 17:39:21 -04:00
John M. Schanck
c2083e13d7
New HQC and HQC-RMRS from upstream
2020-09-07 16:10:13 -04:00
John M. Schanck
bf15d518ea
NTRU: remove unused .s file
2020-09-02 13:05:51 -04:00
John M. Schanck
c433b8274d
NTRU: inline the one call that needed @plt
2020-09-02 12:54:00 -04:00
John M. Schanck
db7fad1232
ntruhrss701/avx2: fix non-PIC call
2020-08-27 11:05:07 -04:00
John M. Schanck
268b62f3ce
NTRU: Move crypto_sort_int32.h include to top of sample.c
2020-08-25 07:57:26 -04:00
John M. Schanck
146a3195e9
NTRU: more explicit casts for MS compiler
2020-08-24 10:56:18 -04:00
John M. Schanck
f49d18a75b
NTRU: add explicit cast for MS compiler
2020-08-24 10:43:44 -04:00
John M. Schanck
1d26f6a582
Update NTRU and add AVX2 NTRU implementations
2020-08-24 09:47:30 -04:00
John Schanck
4ea4b478ba
Update NTRU ( #311 )
...
* Update NTRU
version: https://github.com/jschanck/ntru/tree/485dde03
* Fixed ntruhrss701/clean/Makefile.Microsoft_nmake
2020-08-15 14:26:25 -04:00
Sofía Celi
534e7a1277
Fix overflow in multiplication in Saber
2020-08-11 10:47:55 -05:00
Matthias J. Kannwischer
9fbfb230a9
remove threebears, ledakem, newhope, mqdss, qtesla
...
NIST announced the Round 3 finalists and alternate candidates today:
https://groups.google.com/a/list.nist.gov/d/msg/pqc-forum/0ieuPB-b8eg/Cl7Ji8TpCwAJ
Some of the schemes in PQClean did not make it to Round 3 and this commit
removes them.
2020-07-23 14:08:09 +08:00
Douglas Stebila
ae1530d192
Fix timing leak in decapsulation.
...
As identified in: Qian Guo, Thomas Johansson, Alexander Nilsson. A
key-recovery timing attack on post-quantum primitives using the
Fujisaki-Okamoto transformation and its application on FrodoKEM. In
CRYPTO 2020.
Based on
155c24c3df
2020-06-19 13:15:13 -04:00
Thom Wiggers
f7c7af5155
Merge pull request #297 from PQClean/fix-kyber-meta
...
Kyber768 and Kyber1024 don't need -maes (see #296 )
2020-06-02 09:41:14 +02:00
Ko-
25b15e5791
Fix whitespace to satisfy test_duplicate_consistency
2020-05-29 18:54:15 +02:00
Ko-
bca4250d1f
Update KAT values
2020-05-29 18:50:37 +02:00
Ko-
4883f2ce89
Add domain separation to NewHope
...
NewHope announced a new version of their specification that adds
explicit domain separation. This is a port of
https://github.com/newhopecrypto/newhope/commit/607a9d3
2020-05-29 16:41:41 +02:00
Thom Wiggers
75416c93f0
Kyber768 and Kyber1024 don't need -maes (see #296 )
2020-05-29 10:01:44 +02:00
Thom Wiggers
db0d5800c5
Merge pull request #279 from PQClean/ds-aes-keyexp
...
Split aes*_keyexp up into ecb and ctr variants
2020-04-03 10:00:50 +02:00
Sebastian
33232a0343
HQC submission ( #202 )
...
* Sebastian's HQC merge request
* Clean up changes to common infrastructure
* Fix Bitmask macro
It assumed that ``unsigned long`` was 64 bit
* Remove maxlen from nistseedexpander
It's a complicated thing to handle because the value is larger than size_t supports on 32-bit platforms
* Initialize buffers to help linter
* Add Nistseedexpander test
* Resolve UB in gf2x.c
Some of the shifts could be larger than WORD_SIZE_BITS, ie. larger than
the width of uint64_t. This apparently on Intel gets interpreted as the
shift mod 64, but on ARM something else happened.
* Fix Windows complaints
* rename log, exp which appear to be existing functions on MS
* Solve endianness problems
* remove all spaces before ';'
* Fix duplicate consistency
* Fix duplicate consistency
* Fix complaints by MSVC about narrowing int
* Add nistseedexpander.obj to COMMON_OBJECTS_NOPATH
* astyle format util.[ch]
* add util.h to makefile
* Sort includes in util.h
* Fix more Windows MSVC complaints
Co-authored-by: Sebastian Verschoor <sebastian@zeroknowledge.me>
Co-authored-by: Thom Wiggers <thom@thomwiggers.nl>
2020-04-01 13:57:21 +08:00
mergify[bot]
da46a96aca
Merge branch 'master' into fix_ub
2020-03-27 23:13:26 +00:00
Douglas Stebila
ce4bd09860
Use the right AES CTX
2020-03-26 21:11:07 -04:00
Douglas Stebila
585a001fda
Split aes*_keyexp up into ecb and ctr variants
2020-03-26 20:18:02 -04:00
Thom Wiggers
35e4b0faa1
fixup! Fix uint8_t to uint16_t upcast in Frodo
2020-03-13 16:30:01 -04:00
Thom Wiggers
5436ec0476
Fix uint8_t to uint16_t upcast in Frodo
2020-03-13 15:58:15 -04:00
Thom Wiggers
85de23bdfe
Fix too-large shift in mceliece*f
2020-03-13 13:27:02 -04:00
Thom Wiggers
ef38541c6e
Clean up SABER
2020-03-13 13:00:57 -04:00
Thom Wiggers
bc86182b93
Fix overflowing mults in NTRUHRSS701
2020-03-09 18:02:44 -04:00
Thom Wiggers
39fa1ccfc7
Fix reduce.c's overflowing multiplication
2020-03-09 17:57:43 -04:00
Matthias J. Kannwischer
85c6605bbf
fix MSVS warning
2020-03-09 15:45:20 -04:00
Matthias J. Kannwischer
de5cda4d7b
Fix NewHope verify
...
https://github.com/mupq/pqm4/issues/132 repoorted that the NewHope verify function does not actually return 0 or 1, but 0 or -1, which consequenctly breaks the cmov in the FO transform.
This bug was introduced when I integrated this into PQClean.
2020-03-09 15:45:19 -04:00
Thom Wiggers
8c2f5994b9
Fix duplicate consistency
2020-03-03 10:15:57 -05:00