Non puoi selezionare più di 25 argomenti Gli argomenti devono iniziare con una lettera o un numero, possono includere trattini ('-') e possono essere lunghi fino a 35 caratteri.

464 righe
11 KiB

  1. #include <stdint.h>
  2. #include <string.h>
  3. #include "params.h"
  4. int xmss_str_to_oid(uint32_t *oid, const char *s)
  5. {
  6. if (!strcmp(s, "XMSS-SHA2_10_256")) {
  7. *oid = 0x01000001;
  8. }
  9. else if (!strcmp(s, "XMSS-SHA2_16_256")) {
  10. *oid = 0x02000002;
  11. }
  12. else if (!strcmp(s, "XMSS-SHA2_20_256")) {
  13. *oid = 0x03000003;
  14. }
  15. else if (!strcmp(s, "XMSS-SHA2_10_512")) {
  16. *oid = 0x04000004;
  17. }
  18. else if (!strcmp(s, "XMSS-SHA2_16_512")) {
  19. *oid = 0x05000005;
  20. }
  21. else if (!strcmp(s, "XMSS-SHA2_20_512")) {
  22. *oid = 0x06000006;
  23. }
  24. else if (!strcmp(s, "XMSS-SHAKE_10_256")) {
  25. *oid = 0x07000007;
  26. }
  27. else if (!strcmp(s, "XMSS-SHAKE_16_256")) {
  28. *oid = 0x08000008;
  29. }
  30. else if (!strcmp(s, "XMSS-SHAKE_20_256")) {
  31. *oid = 0x09000009;
  32. }
  33. else if (!strcmp(s, "XMSS-SHAKE_10_512")) {
  34. *oid = 0x0a00000a;
  35. }
  36. else if (!strcmp(s, "XMSS-SHAKE_16_512")) {
  37. *oid = 0x0b00000b;
  38. }
  39. else if (!strcmp(s, "XMSS-SHAKE_20_512")) {
  40. *oid = 0x0c00000c;
  41. }
  42. else {
  43. return -1;
  44. }
  45. return 0;
  46. }
  47. int xmssmt_str_to_oid(uint32_t *oid, const char *s)
  48. {
  49. if (!strcmp(s, "XMSSMT-SHA2_20/2_256")) {
  50. *oid = 0x01000001;
  51. }
  52. else if (!strcmp(s, "XMSSMT-SHA2_20/4_256")) {
  53. *oid = 0x02000002;
  54. }
  55. else if (!strcmp(s, "XMSSMT-SHA2_40/2_256")) {
  56. *oid = 0x03000003;
  57. }
  58. else if (!strcmp(s, "XMSSMT-SHA2_40/4_256")) {
  59. *oid = 0x04000004;
  60. }
  61. else if (!strcmp(s, "XMSSMT-SHA2_40/8_256")) {
  62. *oid = 0x05000005;
  63. }
  64. else if (!strcmp(s, "XMSSMT-SHA2_60/3_256")) {
  65. *oid = 0x06000006;
  66. }
  67. else if (!strcmp(s, "XMSSMT-SHA2_60/6_256")) {
  68. *oid = 0x07000007;
  69. }
  70. else if (!strcmp(s, "XMSSMT-SHA2_60/12_256")) {
  71. *oid = 0x08000008;
  72. }
  73. else if (!strcmp(s, "XMSSMT-SHA2_20/2_512")) {
  74. *oid = 0x09000009;
  75. }
  76. else if (!strcmp(s, "XMSSMT-SHA2_20/4_512")) {
  77. *oid = 0x0a00000a;
  78. }
  79. else if (!strcmp(s, "XMSSMT-SHA2_40/2_512")) {
  80. *oid = 0x0b00000b;
  81. }
  82. else if (!strcmp(s, "XMSSMT-SHA2_40/4_512")) {
  83. *oid = 0x0c00000c;
  84. }
  85. else if (!strcmp(s, "XMSSMT-SHA2_40/8_512")) {
  86. *oid = 0x0d00000d;
  87. }
  88. else if (!strcmp(s, "XMSSMT-SHA2_60/3_512")) {
  89. *oid = 0x0e00000e;
  90. }
  91. else if (!strcmp(s, "XMSSMT-SHA2_60/6_512")) {
  92. *oid = 0x0f00000f;
  93. }
  94. else if (!strcmp(s, "XMSSMT-SHA2_60/12_512")) {
  95. *oid = 0x01010101;
  96. }
  97. else if (!strcmp(s, "XMSSMT-SHAKE_20/2_256")) {
  98. *oid = 0x02010102;
  99. }
  100. else if (!strcmp(s, "XMSSMT-SHAKE_20/4_256")) {
  101. *oid = 0x03010103;
  102. }
  103. else if (!strcmp(s, "XMSSMT-SHAKE_40/2_256")) {
  104. *oid = 0x04010104;
  105. }
  106. else if (!strcmp(s, "XMSSMT-SHAKE_40/4_256")) {
  107. *oid = 0x05010105;
  108. }
  109. else if (!strcmp(s, "XMSSMT-SHAKE_40/8_256")) {
  110. *oid = 0x06010106;
  111. }
  112. else if (!strcmp(s, "XMSSMT-SHAKE_60/3_256")) {
  113. *oid = 0x07010107;
  114. }
  115. else if (!strcmp(s, "XMSSMT-SHAKE_60/6_256")) {
  116. *oid = 0x08010108;
  117. }
  118. else if (!strcmp(s, "XMSSMT-SHAKE_60/12_256")) {
  119. *oid = 0x09010109;
  120. }
  121. else if (!strcmp(s, "XMSSMT-SHAKE_20/2_512")) {
  122. *oid = 0x0a01010a;
  123. }
  124. else if (!strcmp(s, "XMSSMT-SHAKE_20/4_512")) {
  125. *oid = 0x0b01010b;
  126. }
  127. else if (!strcmp(s, "XMSSMT-SHAKE_40/2_512")) {
  128. *oid = 0x0c01010c;
  129. }
  130. else if (!strcmp(s, "XMSSMT-SHAKE_40/4_512")) {
  131. *oid = 0x0d01010d;
  132. }
  133. else if (!strcmp(s, "XMSSMT-SHAKE_40/8_512")) {
  134. *oid = 0x0e01010e;
  135. }
  136. else if (!strcmp(s, "XMSSMT-SHAKE_60/3_512")) {
  137. *oid = 0x0f01010f;
  138. }
  139. else if (!strcmp(s, "XMSSMT-SHAKE_60/6_512")) {
  140. *oid = 0x01020201;
  141. }
  142. else if (!strcmp(s, "XMSSMT-SHAKE_60/12_512")) {
  143. *oid = 0x02020202;
  144. }
  145. else {
  146. return -1;
  147. }
  148. return 0;
  149. }
  150. int xmss_parse_oid(xmss_params *params, const uint32_t oid)
  151. {
  152. switch (oid) {
  153. case 0x01000001:
  154. case 0x02000002:
  155. case 0x03000003:
  156. case 0x04000004:
  157. case 0x05000005:
  158. case 0x06000006:
  159. params->func = XMSS_SHA2;
  160. break;
  161. case 0x07000007:
  162. case 0x08000008:
  163. case 0x09000009:
  164. case 0x0a00000a:
  165. case 0x0b00000b:
  166. case 0x0c00000c:
  167. params->func = XMSS_SHAKE;
  168. break;
  169. default:
  170. return 1;
  171. }
  172. switch (oid) {
  173. case 0x01000001:
  174. case 0x02000002:
  175. case 0x03000003:
  176. case 0x07000007:
  177. case 0x08000008:
  178. case 0x09000009:
  179. params->n = 32;
  180. break;
  181. case 0x04000004:
  182. case 0x05000005:
  183. case 0x06000006:
  184. case 0x0a00000a:
  185. case 0x0b00000b:
  186. case 0x0c00000c:
  187. params->n = 64;
  188. break;
  189. default:
  190. return 1;
  191. }
  192. switch (oid) {
  193. case 0x01000001:
  194. case 0x04000004:
  195. case 0x07000007:
  196. case 0x0a00000a:
  197. params->full_height = 10;
  198. break;
  199. case 0x02000002:
  200. case 0x05000005:
  201. case 0x08000008:
  202. case 0x0b00000b:
  203. params->full_height = 16;
  204. break;
  205. case 0x03000003:
  206. case 0x06000006:
  207. case 0x09000009:
  208. case 0x0c00000c:
  209. params->full_height = 20;
  210. break;
  211. default:
  212. return 1;
  213. }
  214. params->d = 1;
  215. params->tree_height = params->full_height / params->d;
  216. params->wots_w = 16;
  217. params->wots_log_w = 4;
  218. params->wots_len1 = 8 * params->n / params->wots_log_w;
  219. /* len_2 = floor(log(len_1 * (w - 1)) / log(w)) + 1 */
  220. params->wots_len2 = 3;
  221. params->wots_len = params->wots_len1 + params->wots_len2;
  222. params->wots_sig_bytes = params->wots_len * params->n;
  223. params->index_bytes = 4;
  224. params->sig_bytes = (params->index_bytes + params->n
  225. + params->d * params->wots_sig_bytes
  226. + params->full_height * params->n);
  227. params->pk_bytes = 2 * params->n;
  228. params->sk_bytes = 4 * params->n + params->index_bytes;
  229. // TODO figure out sensible and legal values for this based on the above
  230. params->bds_k = 0;
  231. return 0;
  232. }
  233. int xmssmt_parse_oid(xmss_params *params, const uint32_t oid)
  234. {
  235. switch (oid) {
  236. case 0x01000001:
  237. case 0x02000002:
  238. case 0x03000003:
  239. case 0x04000004:
  240. case 0x05000005:
  241. case 0x06000006:
  242. case 0x07000007:
  243. case 0x08000008:
  244. case 0x09000009:
  245. case 0x0a00000a:
  246. case 0x0b00000b:
  247. case 0x0c00000c:
  248. case 0x0d00000d:
  249. case 0x0e00000e:
  250. case 0x0f00000f:
  251. case 0x01010101:
  252. params->func = XMSS_SHA2;
  253. break;
  254. case 0x02010102:
  255. case 0x03010103:
  256. case 0x04010104:
  257. case 0x05010105:
  258. case 0x06010106:
  259. case 0x07010107:
  260. case 0x08010108:
  261. case 0x09010109:
  262. case 0x0a01010a:
  263. case 0x0b01010b:
  264. case 0x0c01010c:
  265. case 0x0d01010d:
  266. case 0x0e01010e:
  267. case 0x0f01010f:
  268. case 0x01020201:
  269. case 0x02020202:
  270. params->func = XMSS_SHAKE;
  271. break;
  272. default:
  273. return 1;
  274. }
  275. switch (oid) {
  276. case 0x01000001:
  277. case 0x02000002:
  278. case 0x03000003:
  279. case 0x04000004:
  280. case 0x05000005:
  281. case 0x06000006:
  282. case 0x07000007:
  283. case 0x08000008:
  284. case 0x02010102:
  285. case 0x03010103:
  286. case 0x04010104:
  287. case 0x05010105:
  288. case 0x06010106:
  289. case 0x07010107:
  290. case 0x08010108:
  291. case 0x09010109:
  292. params->n = 32;
  293. break;
  294. case 0x09000009:
  295. case 0x0a00000a:
  296. case 0x0b00000b:
  297. case 0x0c00000c:
  298. case 0x0d00000d:
  299. case 0x0e00000e:
  300. case 0x0f00000f:
  301. case 0x01010101:
  302. case 0x0a01010a:
  303. case 0x0b01010b:
  304. case 0x0c01010c:
  305. case 0x0d01010d:
  306. case 0x0e01010e:
  307. case 0x0f01010f:
  308. case 0x01020201:
  309. case 0x02020202:
  310. params->n = 64;
  311. break;
  312. default:
  313. return 1;
  314. }
  315. switch (oid) {
  316. case 0x01000001:
  317. case 0x02000002:
  318. case 0x09000009:
  319. case 0x0a00000a:
  320. case 0x02010102:
  321. case 0x03010103:
  322. case 0x0a01010a:
  323. case 0x0b01010b:
  324. params->full_height = 20;
  325. break;
  326. case 0x03000003:
  327. case 0x04000004:
  328. case 0x05000005:
  329. case 0x0b00000b:
  330. case 0x0c00000c:
  331. case 0x0d00000d:
  332. case 0x04010104:
  333. case 0x05010105:
  334. case 0x06010106:
  335. case 0x0c01010c:
  336. case 0x0d01010d:
  337. case 0x0e01010e:
  338. params->full_height = 40;
  339. break;
  340. case 0x06000006:
  341. case 0x07000007:
  342. case 0x08000008:
  343. case 0x0e00000e:
  344. case 0x0f00000f:
  345. case 0x01010101:
  346. case 0x07010107:
  347. case 0x08010108:
  348. case 0x09010109:
  349. case 0x0f01010f:
  350. case 0x01020201:
  351. case 0x02020202:
  352. params->full_height = 60;
  353. break;
  354. default:
  355. return 1;
  356. }
  357. switch (oid) {
  358. case 0x01000001:
  359. case 0x03000003:
  360. case 0x09000009:
  361. case 0x0b00000b:
  362. case 0x02010102:
  363. case 0x04010104:
  364. case 0x0a01010a:
  365. case 0x0c01010c:
  366. params->d = 2;
  367. break;
  368. case 0x02000002:
  369. case 0x04000004:
  370. case 0x0a00000a:
  371. case 0x0c00000c:
  372. case 0x03010103:
  373. case 0x05010105:
  374. case 0x0b01010b:
  375. case 0x0d01010d:
  376. params->d = 4;
  377. break;
  378. case 0x05000005:
  379. case 0x0d00000d:
  380. case 0x06010106:
  381. case 0x0e01010e:
  382. params->d = 8;
  383. break;
  384. case 0x06000006:
  385. case 0x0e00000e:
  386. case 0x07010107:
  387. case 0x0f01010f:
  388. params->d = 3;
  389. break;
  390. case 0x07000007:
  391. case 0x0f00000f:
  392. case 0x08010108:
  393. case 0x01020201:
  394. params->d = 6;
  395. break;
  396. case 0x08000008:
  397. case 0x01010101:
  398. case 0x09010109:
  399. case 0x02020202:
  400. params->d = 12;
  401. break;
  402. default:
  403. return 1;
  404. }
  405. params->tree_height = params->full_height / params->d;
  406. params->wots_w = 16;
  407. params->wots_log_w = 4;
  408. params->wots_len1 = 8 * params->n / params->wots_log_w;
  409. /* len_2 = floor(log(len_1 * (w - 1)) / log(w)) + 1 */
  410. params->wots_len2 = 3;
  411. params->wots_len = params->wots_len1 + params->wots_len2;
  412. params->wots_sig_bytes = params->wots_len * params->n;
  413. /* Round index_bytes up to nearest byte. */
  414. params->index_bytes = (params->full_height + 7) / 8;
  415. params->sig_bytes = (params->index_bytes + params->n
  416. + params->d * params->wots_sig_bytes
  417. + params->full_height * params->n);
  418. params->pk_bytes = 2 * params->n;
  419. params->sk_bytes = 4 * params->n + params->index_bytes;
  420. // TODO figure out sensible and legal values for this based on the above
  421. params->bds_k = 0;
  422. return 0;
  423. }