You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

159 lines
4.2 KiB

  1. /*
  2. wots.c version 20160210
  3. Andreas Hülsing
  4. Joost Rijneveld
  5. Public domain.
  6. */
  7. #include "math.h"
  8. #include "stdio.h"
  9. #include "xmss_commons.h"
  10. //#include "params.h"
  11. #include "prg.h"
  12. #include "hash.h"
  13. #include "wots.h"
  14. #include "hash_address.h"
  15. void wots_set_params(wots_params *params, int m, int n, int w)
  16. {
  17. params->m = m;
  18. params->n = n;
  19. params->w = w;
  20. params->log_w = (int) log2(w);
  21. params->len_1 = (int) ceil(((8*m) / params->log_w));
  22. params->len_2 = (int) floor(log2(params->len_1*(w-1)) / params->log_w) + 1;
  23. params->len = params->len_1 + params->len_2;
  24. params->keysize = params->len*params->n;
  25. }
  26. /**
  27. * Helper method for pseudorandom key generation
  28. * Expands an n-byte array into a len*n byte array
  29. * this is done using chacha20 with nonce 0 and counter 0
  30. */
  31. static void expand_seed(unsigned char *outseeds, const unsigned char *inseed, const wots_params *params)
  32. {
  33. prg(outseeds, params->keysize, inseed, params->n);
  34. }
  35. /**
  36. * Computes the chaining function.
  37. * out and in have to be n-byte arrays
  38. *
  39. * interpretes in as start-th value of the chain
  40. * addr has to contain the address of the chain
  41. */
  42. static void gen_chain(unsigned char *out, const unsigned char *in, unsigned int start, unsigned int steps, const wots_params *params, const unsigned char *pub_seed, unsigned char addr[16])
  43. {
  44. unsigned int i, j;
  45. for (j = 0; j < params->n; j++)
  46. out[j] = in[j];
  47. for (i = start; i < (start+steps) && i < params->w; i++) {
  48. SET_HASH_ADDRESS(addr, i);
  49. hash_n_n(out, out, pub_seed, addr, params->n);
  50. }
  51. }
  52. /**
  53. * base_w algorithm as described in draft.
  54. *
  55. *
  56. */
  57. static void base_w(int *output, const unsigned char *input, int in_len, const wots_params *params)
  58. {
  59. int in = 0;
  60. int out = 0;
  61. int total = 0;
  62. int bits = 0;
  63. int consumed = 0;
  64. for (consumed = 0; consumed < 8 * in_len; consumed += params->log_w) {
  65. if (bits == 0) {
  66. total = input[in_len - 1 - in];
  67. in++;
  68. bits += 8;
  69. }
  70. bits -= params->log_w;
  71. output[out] = (total >> bits) & (params->w - 1);
  72. out++;
  73. }
  74. }
  75. void wots_pkgen(unsigned char *pk, const unsigned char *sk, const wots_params *params, const unsigned char *pub_seed, unsigned char addr[16])
  76. {
  77. unsigned int i;
  78. expand_seed(pk, sk, params);
  79. for (i=0; i < params->len; i++) {
  80. SET_CHAIN_ADDRESS(addr, i);
  81. gen_chain(pk+i*params->n, pk+i*params->n, 0, params->w-1, params, pub_seed, addr);
  82. }
  83. }
  84. void wots_sign(unsigned char *sig, const unsigned char *msg, const unsigned char *sk, const wots_params *params, const unsigned char *pub_seed, unsigned char addr[16])
  85. {
  86. int basew[params->len];
  87. int csum = 0;
  88. unsigned int i = 0;
  89. base_w(basew, msg, params->m, params);
  90. for (i=0; i < params->len_1; i++) {
  91. csum += params->w - 1 - basew[i];
  92. }
  93. csum = csum << (8 - ((params->len_2 * params->log_w) % 8));
  94. int len_2_bytes = ((params->len_2 * params->log_w) + 7) / 8;
  95. unsigned char csum_bytes[len_2_bytes];
  96. to_byte(csum_bytes, csum, len_2_bytes);
  97. int csum_basew[len_2_bytes / params->log_w];
  98. base_w(csum_basew, csum_bytes, len_2_bytes, params);
  99. for (i = 0; i < params->len_2; i++) {
  100. basew[params->len_1 + i] = csum_basew[i];
  101. }
  102. expand_seed(sig, sk, params);
  103. for (i = 0; i < params->len; i++) {
  104. SET_CHAIN_ADDRESS(addr, i);
  105. gen_chain(sig+i*params->n, sig+i*params->n, 0, basew[i], params, pub_seed, addr);
  106. }
  107. }
  108. void wots_pkFromSig(unsigned char *pk, const unsigned char *sig, const unsigned char *msg, const wots_params *params, const unsigned char *pub_seed, unsigned char addr[16])
  109. {
  110. int basew[params->len];
  111. int csum = 0;
  112. unsigned int i = 0;
  113. base_w(basew, msg, params->m, params);
  114. for (i=0; i < params->len_1; i++) {
  115. csum += params->w - 1 - basew[i];
  116. }
  117. csum = csum << (8 - ((params->len_2 * params->log_w) % 8));
  118. int len_2_bytes = ((params->len_2 * params->log_w) + 7) / 8;
  119. unsigned char csum_bytes[len_2_bytes];
  120. to_byte(csum_bytes, csum, len_2_bytes);
  121. int csum_basew[len_2_bytes / params->log_w];
  122. base_w(csum_basew, csum_bytes, len_2_bytes, params);
  123. for (i = 0; i < params->len_2; i++) {
  124. basew[params->len_1 + i] = csum_basew[i];
  125. }
  126. for (i=0; i < params->len; i++) {
  127. SET_CHAIN_ADDRESS(addr, i);
  128. gen_chain(pk+i*params->n, sig+i*params->n, basew[i], params->w-1-basew[i], params, pub_seed, addr);
  129. }
  130. }