You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

170 lines
4.5 KiB

  1. /*
  2. wots.c version 20151120
  3. Andreas Hülsing
  4. Public domain.
  5. */
  6. #include "math.h"
  7. #include "stdio.h"
  8. #include "xmss_commons.h"
  9. //#include "params.h"
  10. #include "prg.h"
  11. #include "hash.h"
  12. #include "wots.h"
  13. /**
  14. * Macros used to manipulate the respective fields
  15. * in the 16byte hash address
  16. */
  17. #define SET_HASH_ADDRESS(a, v) {\
  18. a[15] = (a[15] & 1) | ((v << 1) & 254);\
  19. a[14] = (a[14] & 254) | ((v >> 7) & 1);}
  20. #define SET_CHAIN_ADDRESS(a, v) {\
  21. a[14] = (a[14] & 1) | ((v << 1) & 254);\
  22. a[13] = (v >> 7) & 255;\
  23. a[12] = (a[12] & 254) | ((v >> 15) & 1);}
  24. void wots_set_params(wots_params *params, int m, int n, int w)
  25. {
  26. params->m = m;
  27. params->n = n;
  28. params->w = w;
  29. params->log_w = (int) log2(w);
  30. params->len_1 = (int) ceil(((8*m) / params->log_w));
  31. params->len_2 = (int) floor(log2(params->len_1*(w-1)) / params->log_w) + 1;
  32. params->len = params->len_1 + params->len_2;
  33. params->keysize = params->len*params->n;
  34. }
  35. /**
  36. * Helper method for pseudorandom key generation
  37. * Expands an n-byte array into a len*n byte array
  38. * this is done using chacha20 with nonce 0 and counter 0
  39. */
  40. static void expand_seed(unsigned char *outseeds, const unsigned char *inseed, const wots_params *params)
  41. {
  42. prg(outseeds, params->keysize, inseed, params->n);
  43. }
  44. /**
  45. * Computes the chaining function.
  46. * out and in have to be n-byte arrays
  47. *
  48. * interpretes in as start-th value of the chain
  49. * addr has to contain the address of the chain
  50. */
  51. static void gen_chain(unsigned char *out, const unsigned char *in, unsigned int start, unsigned int steps, const wots_params *params, const unsigned char *pub_seed, unsigned char addr[16])
  52. {
  53. unsigned int i, j;
  54. for (j = 0; j < params->n; j++)
  55. out[j] = in[j];
  56. for (i = start; i < (start+steps) && i < params->w; i++) {
  57. SET_HASH_ADDRESS(addr, i);
  58. hash_n_n(out, out, pub_seed, addr, params->n);
  59. }
  60. }
  61. /**
  62. * base_w algorithm as described in draft.
  63. *
  64. *
  65. */
  66. static void base_w(int *output, const unsigned char *input, int in_len, const wots_params *params)
  67. {
  68. int in = 0;
  69. int out = 0;
  70. int total = 0;
  71. int bits = 0;
  72. int consumed = 0;
  73. for (consumed = 0; consumed < 8 * in_len; consumed += params->log_w) {
  74. if (bits == 0) {
  75. total = input[in_len - 1 - in];
  76. in++;
  77. bits += 8;
  78. }
  79. bits -= params->log_w;
  80. output[out] = (total >> bits) & (params->w - 1);
  81. out++;
  82. }
  83. }
  84. void wots_pkgen(unsigned char *pk, const unsigned char *sk, const wots_params *params, const unsigned char *pub_seed, unsigned char addr[16])
  85. {
  86. unsigned int i;
  87. expand_seed(pk, sk, params);
  88. for (i=0; i < params->len; i++) {
  89. SET_CHAIN_ADDRESS(addr, i);
  90. gen_chain(pk+i*params->n, pk+i*params->n, 0, params->w-1, params, pub_seed, addr);
  91. }
  92. }
  93. void wots_sign(unsigned char *sig, const unsigned char *msg, const unsigned char *sk, const wots_params *params, const unsigned char *pub_seed, unsigned char addr[16])
  94. {
  95. int basew[params->len];
  96. int csum = 0;
  97. unsigned int i = 0;
  98. base_w(basew, msg, params->m, params);
  99. for (i=0; i < params->len_1; i++) {
  100. csum += params->w - 1 - basew[i];
  101. }
  102. csum = csum << (8 - ((params->len_2 * params->log_w) % 8));
  103. int len_2_bytes = ((params->len_2 * params->log_w) + 7) / 8;
  104. unsigned char csum_bytes[len_2_bytes];
  105. to_byte(csum_bytes, csum, len_2_bytes);
  106. int csum_basew[len_2_bytes / params->log_w];
  107. base_w(csum_basew, csum_bytes, len_2_bytes, params);
  108. for (i = 0; i < params->len_2; i++) {
  109. basew[params->len_1 + i] = csum_basew[i];
  110. }
  111. expand_seed(sig, sk, params);
  112. for (i = 0; i < params->len; i++) {
  113. SET_CHAIN_ADDRESS(addr, i);
  114. gen_chain(sig+i*params->n, sig+i*params->n, 0, basew[i], params, pub_seed, addr);
  115. }
  116. }
  117. void wots_pkFromSig(unsigned char *pk, const unsigned char *sig, const unsigned char *msg, const wots_params *params, const unsigned char *pub_seed, unsigned char addr[16])
  118. {
  119. int basew[params->len];
  120. int csum = 0;
  121. unsigned int i = 0;
  122. base_w(basew, msg, params->m, params);
  123. for (i=0; i < params->len_1; i++) {
  124. csum += params->w - 1 - basew[i];
  125. }
  126. csum = csum << (8 - ((params->len_2 * params->log_w) % 8));
  127. int len_2_bytes = ((params->len_2 * params->log_w) + 7) / 8;
  128. unsigned char csum_bytes[len_2_bytes];
  129. to_byte(csum_bytes, csum, len_2_bytes);
  130. int csum_basew[len_2_bytes / params->log_w];
  131. base_w(csum_basew, csum_bytes, len_2_bytes, params);
  132. for (i = 0; i < params->len_2; i++) {
  133. basew[params->len_1 + i] = csum_basew[i];
  134. }
  135. for (i=0; i < params->len; i++) {
  136. SET_CHAIN_ADDRESS(addr, i);
  137. gen_chain(pk+i*params->n, sig+i*params->n, basew[i], params->w-1-basew[i], params, pub_seed, addr);
  138. }
  139. }