xform_poly1305.c 2.1 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192
  1. /* This file is in the public domain. */
  2. #include <sys/cdefs.h>
  3. __FBSDID("$FreeBSD$");
  4. #include <opencrypto/xform_auth.h>
  5. #include <opencrypto/xform_poly1305.h>
  6. #include <sodium/crypto_onetimeauth_poly1305.h>
  7. struct poly1305_xform_ctx {
  8. struct crypto_onetimeauth_poly1305_state state;
  9. };
  10. CTASSERT(sizeof(union authctx) >= sizeof(struct poly1305_xform_ctx));
  11. CTASSERT(POLY1305_KEY_LEN == crypto_onetimeauth_poly1305_KEYBYTES);
  12. CTASSERT(POLY1305_HASH_LEN == crypto_onetimeauth_poly1305_BYTES);
  13. void
  14. Poly1305_Init(void *polyctx)
  15. {
  16. /* Nop */
  17. }
  18. void
  19. Poly1305_Setkey(struct poly1305_xform_ctx *polyctx,
  20. const uint8_t key[__min_size(POLY1305_KEY_LEN)], size_t klen)
  21. {
  22. int rc;
  23. if (klen != POLY1305_KEY_LEN)
  24. panic("%s: Bogus keylen: %u bytes", __func__, (unsigned)klen);
  25. rc = crypto_onetimeauth_poly1305_init(&polyctx->state, key);
  26. if (rc != 0)
  27. panic("%s: Invariant violated: %d", __func__, rc);
  28. }
  29. static void
  30. xform_Poly1305_Setkey(void *ctx, const uint8_t *key, u_int klen)
  31. {
  32. Poly1305_Setkey(ctx, key, klen);
  33. }
  34. int
  35. Poly1305_Update(struct poly1305_xform_ctx *polyctx, const void *data,
  36. size_t len)
  37. {
  38. int rc;
  39. rc = crypto_onetimeauth_poly1305_update(&polyctx->state, data, len);
  40. if (rc != 0)
  41. panic("%s: Invariant violated: %d", __func__, rc);
  42. return (0);
  43. }
  44. static int
  45. xform_Poly1305_Update(void *ctx, const void *data, u_int len)
  46. {
  47. return (Poly1305_Update(ctx, data, len));
  48. }
  49. void
  50. Poly1305_Final(uint8_t digest[__min_size(POLY1305_HASH_LEN)],
  51. struct poly1305_xform_ctx *polyctx)
  52. {
  53. int rc;
  54. rc = crypto_onetimeauth_poly1305_final(&polyctx->state, digest);
  55. if (rc != 0)
  56. panic("%s: Invariant violated: %d", __func__, rc);
  57. }
  58. static void
  59. xform_Poly1305_Final(uint8_t *digest, void *ctx)
  60. {
  61. Poly1305_Final(digest, ctx);
  62. }
  63. struct auth_hash auth_hash_poly1305 = {
  64. .type = CRYPTO_POLY1305,
  65. .name = "Poly-1305",
  66. .keysize = POLY1305_KEY_LEN,
  67. .hashsize = POLY1305_HASH_LEN,
  68. .ctxsize = sizeof(struct poly1305_xform_ctx),
  69. .blocksize = crypto_onetimeauth_poly1305_BYTES,
  70. .Init = Poly1305_Init,
  71. .Setkey = xform_Poly1305_Setkey,
  72. .Update = xform_Poly1305_Update,
  73. .Final = xform_Poly1305_Final,
  74. };