選択できるのは25トピックまでです。 トピックは、先頭が英数字で、英数字とダッシュ('-')を使用した35文字以内のものにしてください。

params.c 11 KiB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467
  1. #include <stdint.h>
  2. #include <string.h>
  3. #include "params.h"
  4. #include "xmss_core.h"
  5. int xmss_str_to_oid(uint32_t *oid, const char *s)
  6. {
  7. if (!strcmp(s, "XMSS-SHA2_10_256")) {
  8. *oid = 0x00000001;
  9. }
  10. else if (!strcmp(s, "XMSS-SHA2_16_256")) {
  11. *oid = 0x00000002;
  12. }
  13. else if (!strcmp(s, "XMSS-SHA2_20_256")) {
  14. *oid = 0x00000003;
  15. }
  16. else if (!strcmp(s, "XMSS-SHA2_10_512")) {
  17. *oid = 0x00000004;
  18. }
  19. else if (!strcmp(s, "XMSS-SHA2_16_512")) {
  20. *oid = 0x00000005;
  21. }
  22. else if (!strcmp(s, "XMSS-SHA2_20_512")) {
  23. *oid = 0x00000006;
  24. }
  25. else if (!strcmp(s, "XMSS-SHAKE_10_256")) {
  26. *oid = 0x00000007;
  27. }
  28. else if (!strcmp(s, "XMSS-SHAKE_16_256")) {
  29. *oid = 0x00000008;
  30. }
  31. else if (!strcmp(s, "XMSS-SHAKE_20_256")) {
  32. *oid = 0x00000009;
  33. }
  34. else if (!strcmp(s, "XMSS-SHAKE_10_512")) {
  35. *oid = 0x0000000a;
  36. }
  37. else if (!strcmp(s, "XMSS-SHAKE_16_512")) {
  38. *oid = 0x0000000b;
  39. }
  40. else if (!strcmp(s, "XMSS-SHAKE_20_512")) {
  41. *oid = 0x0000000c;
  42. }
  43. else {
  44. return -1;
  45. }
  46. return 0;
  47. }
  48. int xmssmt_str_to_oid(uint32_t *oid, const char *s)
  49. {
  50. if (!strcmp(s, "XMSSMT-SHA2_20/2_256")) {
  51. *oid = 0x00000001;
  52. }
  53. else if (!strcmp(s, "XMSSMT-SHA2_20/4_256")) {
  54. *oid = 0x00000002;
  55. }
  56. else if (!strcmp(s, "XMSSMT-SHA2_40/2_256")) {
  57. *oid = 0x00000003;
  58. }
  59. else if (!strcmp(s, "XMSSMT-SHA2_40/4_256")) {
  60. *oid = 0x00000004;
  61. }
  62. else if (!strcmp(s, "XMSSMT-SHA2_40/8_256")) {
  63. *oid = 0x00000005;
  64. }
  65. else if (!strcmp(s, "XMSSMT-SHA2_60/3_256")) {
  66. *oid = 0x00000006;
  67. }
  68. else if (!strcmp(s, "XMSSMT-SHA2_60/6_256")) {
  69. *oid = 0x00000007;
  70. }
  71. else if (!strcmp(s, "XMSSMT-SHA2_60/12_256")) {
  72. *oid = 0x00000008;
  73. }
  74. else if (!strcmp(s, "XMSSMT-SHA2_20/2_512")) {
  75. *oid = 0x00000009;
  76. }
  77. else if (!strcmp(s, "XMSSMT-SHA2_20/4_512")) {
  78. *oid = 0x0000000a;
  79. }
  80. else if (!strcmp(s, "XMSSMT-SHA2_40/2_512")) {
  81. *oid = 0x0000000b;
  82. }
  83. else if (!strcmp(s, "XMSSMT-SHA2_40/4_512")) {
  84. *oid = 0x0000000c;
  85. }
  86. else if (!strcmp(s, "XMSSMT-SHA2_40/8_512")) {
  87. *oid = 0x0000000d;
  88. }
  89. else if (!strcmp(s, "XMSSMT-SHA2_60/3_512")) {
  90. *oid = 0x0000000e;
  91. }
  92. else if (!strcmp(s, "XMSSMT-SHA2_60/6_512")) {
  93. *oid = 0x0000000f;
  94. }
  95. else if (!strcmp(s, "XMSSMT-SHA2_60/12_512")) {
  96. *oid = 0x00000010;
  97. }
  98. else if (!strcmp(s, "XMSSMT-SHAKE_20/2_256")) {
  99. *oid = 0x00000011;
  100. }
  101. else if (!strcmp(s, "XMSSMT-SHAKE_20/4_256")) {
  102. *oid = 0x00000012;
  103. }
  104. else if (!strcmp(s, "XMSSMT-SHAKE_40/2_256")) {
  105. *oid = 0x00000013;
  106. }
  107. else if (!strcmp(s, "XMSSMT-SHAKE_40/4_256")) {
  108. *oid = 0x00000014;
  109. }
  110. else if (!strcmp(s, "XMSSMT-SHAKE_40/8_256")) {
  111. *oid = 0x00000015;
  112. }
  113. else if (!strcmp(s, "XMSSMT-SHAKE_60/3_256")) {
  114. *oid = 0x00000016;
  115. }
  116. else if (!strcmp(s, "XMSSMT-SHAKE_60/6_256")) {
  117. *oid = 0x00000017;
  118. }
  119. else if (!strcmp(s, "XMSSMT-SHAKE_60/12_256")) {
  120. *oid = 0x00000018;
  121. }
  122. else if (!strcmp(s, "XMSSMT-SHAKE_20/2_512")) {
  123. *oid = 0x00000019;
  124. }
  125. else if (!strcmp(s, "XMSSMT-SHAKE_20/4_512")) {
  126. *oid = 0x0000001a;
  127. }
  128. else if (!strcmp(s, "XMSSMT-SHAKE_40/2_512")) {
  129. *oid = 0x0000001b;
  130. }
  131. else if (!strcmp(s, "XMSSMT-SHAKE_40/4_512")) {
  132. *oid = 0x0000001c;
  133. }
  134. else if (!strcmp(s, "XMSSMT-SHAKE_40/8_512")) {
  135. *oid = 0x0000001d;
  136. }
  137. else if (!strcmp(s, "XMSSMT-SHAKE_60/3_512")) {
  138. *oid = 0x0000001e;
  139. }
  140. else if (!strcmp(s, "XMSSMT-SHAKE_60/6_512")) {
  141. *oid = 0x0000001f;
  142. }
  143. else if (!strcmp(s, "XMSSMT-SHAKE_60/12_512")) {
  144. *oid = 0x00000020;
  145. }
  146. else {
  147. return -1;
  148. }
  149. return 0;
  150. }
  151. int xmss_parse_oid(xmss_params *params, const uint32_t oid)
  152. {
  153. switch (oid) {
  154. case 0x00000001:
  155. case 0x00000002:
  156. case 0x00000003:
  157. case 0x00000004:
  158. case 0x00000005:
  159. case 0x00000006:
  160. params->func = XMSS_SHA2;
  161. break;
  162. case 0x00000007:
  163. case 0x00000008:
  164. case 0x00000009:
  165. case 0x0000000a:
  166. case 0x0000000b:
  167. case 0x0000000c:
  168. params->func = XMSS_SHAKE;
  169. break;
  170. default:
  171. return -1;
  172. }
  173. switch (oid) {
  174. case 0x00000001:
  175. case 0x00000002:
  176. case 0x00000003:
  177. case 0x00000007:
  178. case 0x00000008:
  179. case 0x00000009:
  180. params->n = 32;
  181. break;
  182. case 0x00000004:
  183. case 0x00000005:
  184. case 0x00000006:
  185. case 0x0000000a:
  186. case 0x0000000b:
  187. case 0x0000000c:
  188. params->n = 64;
  189. break;
  190. default:
  191. return -1;
  192. }
  193. switch (oid) {
  194. case 0x00000001:
  195. case 0x00000004:
  196. case 0x00000007:
  197. case 0x0000000a:
  198. params->full_height = 10;
  199. break;
  200. case 0x00000002:
  201. case 0x00000005:
  202. case 0x00000008:
  203. case 0x0000000b:
  204. params->full_height = 16;
  205. break;
  206. case 0x00000003:
  207. case 0x00000006:
  208. case 0x00000009:
  209. case 0x0000000c:
  210. params->full_height = 20;
  211. break;
  212. default:
  213. return -1;
  214. }
  215. params->d = 1;
  216. params->tree_height = params->full_height / params->d;
  217. params->wots_w = 16;
  218. params->wots_log_w = 4;
  219. params->wots_len1 = 8 * params->n / params->wots_log_w;
  220. /* len_2 = floor(log(len_1 * (w - 1)) / log(w)) + 1 */
  221. params->wots_len2 = 3;
  222. params->wots_len = params->wots_len1 + params->wots_len2;
  223. params->wots_sig_bytes = params->wots_len * params->n;
  224. params->index_bytes = 4;
  225. params->sig_bytes = (params->index_bytes + params->n
  226. + params->d * params->wots_sig_bytes
  227. + params->full_height * params->n);
  228. // TODO figure out sensible and legal values for this based on the above
  229. params->bds_k = 0;
  230. params->pk_bytes = 2 * params->n;
  231. params->sk_bytes = xmss_core_sk_bytes(params);
  232. return 0;
  233. }
  234. int xmssmt_parse_oid(xmss_params *params, const uint32_t oid)
  235. {
  236. switch (oid) {
  237. case 0x00000001:
  238. case 0x00000002:
  239. case 0x00000003:
  240. case 0x00000004:
  241. case 0x00000005:
  242. case 0x00000006:
  243. case 0x00000007:
  244. case 0x00000008:
  245. case 0x00000009:
  246. case 0x0000000a:
  247. case 0x0000000b:
  248. case 0x0000000c:
  249. case 0x0000000d:
  250. case 0x0000000e:
  251. case 0x0000000f:
  252. case 0x00000010:
  253. params->func = XMSS_SHA2;
  254. break;
  255. case 0x00000011:
  256. case 0x00000012:
  257. case 0x00000013:
  258. case 0x00000014:
  259. case 0x00000015:
  260. case 0x00000016:
  261. case 0x00000017:
  262. case 0x00000018:
  263. case 0x00000019:
  264. case 0x0000001a:
  265. case 0x0000001b:
  266. case 0x0000001c:
  267. case 0x0000001e:
  268. case 0x0000001d:
  269. case 0x0000001f:
  270. case 0x00000020:
  271. params->func = XMSS_SHAKE;
  272. break;
  273. default:
  274. return -1;
  275. }
  276. switch (oid) {
  277. case 0x00000001:
  278. case 0x00000002:
  279. case 0x00000003:
  280. case 0x00000004:
  281. case 0x00000005:
  282. case 0x00000006:
  283. case 0x00000007:
  284. case 0x00000008:
  285. case 0x00000011:
  286. case 0x00000012:
  287. case 0x00000013:
  288. case 0x00000014:
  289. case 0x00000015:
  290. case 0x00000016:
  291. case 0x00000017:
  292. case 0x00000018:
  293. params->n = 32;
  294. break;
  295. case 0x00000009:
  296. case 0x0000000a:
  297. case 0x0000000b:
  298. case 0x0000000c:
  299. case 0x0000000d:
  300. case 0x0000000e:
  301. case 0x0000000f:
  302. case 0x00000010:
  303. case 0x00000019:
  304. case 0x0000001a:
  305. case 0x0000001b:
  306. case 0x0000001c:
  307. case 0x0000001d:
  308. case 0x0000001e:
  309. case 0x0000001f:
  310. case 0x00000020:
  311. params->n = 64;
  312. break;
  313. default:
  314. return -1;
  315. }
  316. switch (oid) {
  317. case 0x00000001:
  318. case 0x00000002:
  319. case 0x00000009:
  320. case 0x0000000a:
  321. case 0x00000011:
  322. case 0x00000012:
  323. case 0x00000019:
  324. case 0x0000001a:
  325. params->full_height = 20;
  326. break;
  327. case 0x00000003:
  328. case 0x00000004:
  329. case 0x00000005:
  330. case 0x0000000b:
  331. case 0x0000000c:
  332. case 0x0000000d:
  333. case 0x00000013:
  334. case 0x00000014:
  335. case 0x00000015:
  336. case 0x0000001b:
  337. case 0x0000001c:
  338. case 0x0000001d:
  339. params->full_height = 40;
  340. break;
  341. case 0x00000006:
  342. case 0x00000007:
  343. case 0x00000008:
  344. case 0x0000000e:
  345. case 0x0000000f:
  346. case 0x00000010:
  347. case 0x00000016:
  348. case 0x00000017:
  349. case 0x00000018:
  350. case 0x0000001e:
  351. case 0x0000001f:
  352. case 0x00000020:
  353. params->full_height = 60;
  354. break;
  355. default:
  356. return -1;
  357. }
  358. switch (oid) {
  359. case 0x00000001:
  360. case 0x00000003:
  361. case 0x00000009:
  362. case 0x0000000b:
  363. case 0x00000011:
  364. case 0x00000013:
  365. case 0x00000019:
  366. case 0x0000001b:
  367. params->d = 2;
  368. break;
  369. case 0x00000002:
  370. case 0x00000004:
  371. case 0x0000000a:
  372. case 0x0000000c:
  373. case 0x00000012:
  374. case 0x00000014:
  375. case 0x0000001a:
  376. case 0x0000001c:
  377. params->d = 4;
  378. break;
  379. case 0x00000005:
  380. case 0x0000000d:
  381. case 0x00000015:
  382. case 0x0000001d:
  383. params->d = 8;
  384. break;
  385. case 0x00000006:
  386. case 0x0000000e:
  387. case 0x00000016:
  388. case 0x0000001e:
  389. params->d = 3;
  390. break;
  391. case 0x00000007:
  392. case 0x0000000f:
  393. case 0x00000017:
  394. case 0x0000001f:
  395. params->d = 6;
  396. break;
  397. case 0x00000008:
  398. case 0x00000010:
  399. case 0x00000018:
  400. case 0x00000020:
  401. params->d = 12;
  402. break;
  403. default:
  404. return -1;
  405. }
  406. params->tree_height = params->full_height / params->d;
  407. params->wots_w = 16;
  408. params->wots_log_w = 4;
  409. params->wots_len1 = 8 * params->n / params->wots_log_w;
  410. /* len_2 = floor(log(len_1 * (w - 1)) / log(w)) + 1 */
  411. params->wots_len2 = 3;
  412. params->wots_len = params->wots_len1 + params->wots_len2;
  413. params->wots_sig_bytes = params->wots_len * params->n;
  414. /* Round index_bytes up to nearest byte. */
  415. params->index_bytes = (params->full_height + 7) / 8;
  416. params->sig_bytes = (params->index_bytes + params->n
  417. + params->d * params->wots_sig_bytes
  418. + params->full_height * params->n);
  419. // TODO figure out sensible and legal values for this based on the above
  420. params->bds_k = 0;
  421. params->pk_bytes = 2 * params->n;
  422. params->sk_bytes = xmssmt_core_sk_bytes(params);
  423. return 0;
  424. }