Received: by 2002:ac0:a5a7:0:0:0:0:0 with SMTP id m36-v6csp4039917imm; Mon, 6 Aug 2018 15:37:30 -0700 (PDT) X-Google-Smtp-Source: AAOMgpdNdW5T9am5I8JNSFLP3UK8FuKWwvrIQC6wzEN+bSicA+D9ouVYcHaAm+07K7GA1ZXgVL1h X-Received: by 2002:a62:e0d5:: with SMTP id d82-v6mr18921651pfm.59.1533595050024; Mon, 06 Aug 2018 15:37:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1533595049; cv=none; d=google.com; s=arc-20160816; b=jVP6uQ/xITZJabyu8LowDqkY3dVhH6yRcze0CP6YkxVvJDkaBL8OiiU+GikkATp02x tRglAFEm8JP8quV1KAjUu4KuCIi+EElnKxICr5aih913NlxLQAjzIL3fMakHpVdeszGa fpTXbIkIxPTE0GLKqMdctfGlU/+wpBrJn7KrG2YJk5+KzXek8WSywOrXpzqNiVJH47A9 cknNIepsdH+zmaVfazue5mJQl/2BIuhKXDiQZFYWpx/DDH8uxe8os4YU7Yl6yJtSvhdf HfU2fiJvm6eFD7knI9czgIwXNi83k1Imc1h2Kqdv6sSlmS1PpqxpPNNUddErYqInlmDK 3BoA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature:arc-authentication-results; bh=zgdqHURt4rJpYl4Hdm4vQoOUgPxfX+u9uCdAKtrMQKY=; b=GPOWAZx9kZRTQSFDahiMUncqJw/vLPQGKEUbgwWhvEApfmUlVGFcUiLZpwwLXc5DzI gjsmy3yJdrCqyAA/xo4w+Hi689GsvIkGhJtrnu35gX7HmH6yOGkXjaLDfeQK8iUjSwO6 4xNJPovIZxymRFSvNp1s0UO3SFXCdGxUO4F13/9SS3NjuyS/y3SNGi5NlRvbdRyXSXk7 /7olcyBP0l+TcuGJ9emFnsXGZl0ZzwPOM5mKymaXnMksenNoxzdBu80gZG7aRxdNHqC2 PDXWn/Et2Bj8eG9zCeL7ya95OCLmJQHmahOJBel/pmdWI0JuNc78aAraxQApsALmYFRn VFHg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=UXT719cC; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id t67-v6si13633558pfd.364.2018.08.06.15.37.15; Mon, 06 Aug 2018 15:37:29 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=UXT719cC; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732281AbeHGAqM (ORCPT + 99 others); Mon, 6 Aug 2018 20:46:12 -0400 Received: from mail.kernel.org ([198.145.29.99]:45080 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1730888AbeHGAqL (ORCPT ); Mon, 6 Aug 2018 20:46:11 -0400 Received: from ebiggers-linuxstation.kir.corp.google.com (unknown [104.132.51.88]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id D7CA221A60; Mon, 6 Aug 2018 22:34:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1533594898; bh=ptypddly68/mtHqA6v40Ih3M31L4+1CcEXAXZZcxVnE=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=UXT719cCSAbwUGAv0lSoPy+Q8J5cK9Ab77ULuzcu0O24m96cXC9ROZOt4v/h8cSqo OiWRc35V+Zvv2utpKlL/DRs9kbgkr1us0pIu0s8Wm/CABahqUdo7HPB/hJ9OQxgfkS GMsWwiFIXGgSooEqhkcC3MHRTHHTXTAOuFuBiqQk= From: Eric Biggers To: linux-crypto@vger.kernel.org Cc: linux-fscrypt@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Herbert Xu , Paul Crowley , Greg Kaiser , Michael Halcrow , "Jason A . Donenfeld" , Samuel Neves , Tomer Ashur , Eric Biggers Subject: [RFC PATCH 1/9] crypto: chacha20-generic - add HChaCha20 library function Date: Mon, 6 Aug 2018 15:32:52 -0700 Message-Id: <20180806223300.113891-2-ebiggers@kernel.org> X-Mailer: git-send-email 2.18.0.597.ga71716f1ad-goog In-Reply-To: <20180806223300.113891-1-ebiggers@kernel.org> References: <20180806223300.113891-1-ebiggers@kernel.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Eric Biggers Refactor the unkeyed permutation part of chacha20_block() into its own function, then add hchacha20_block() which is the ChaCha equivalent of HSalsa20 and is an intermediate step towards XChaCha20 (see https://cr.yp.to/snuffle/xsalsa-20081128.pdf). HChaCha20 skips the final addition of the initial state, and outputs only certain words of the state. It should not be used for streaming directly. Signed-off-by: Eric Biggers --- include/crypto/chacha20.h | 2 ++ lib/chacha20.c | 52 +++++++++++++++++++++++++++++++++------ 2 files changed, 47 insertions(+), 7 deletions(-) diff --git a/include/crypto/chacha20.h b/include/crypto/chacha20.h index b83d66073db0..f00052137942 100644 --- a/include/crypto/chacha20.h +++ b/include/crypto/chacha20.h @@ -20,6 +20,8 @@ struct chacha20_ctx { }; void chacha20_block(u32 *state, u32 *stream); +void hchacha20_block(const u32 *in, u32 *out); + void crypto_chacha20_init(u32 *state, struct chacha20_ctx *ctx, u8 *iv); int crypto_chacha20_setkey(struct crypto_skcipher *tfm, const u8 *key, unsigned int keysize); diff --git a/lib/chacha20.c b/lib/chacha20.c index c1cc50fb68c9..13a0bdcb1604 100644 --- a/lib/chacha20.c +++ b/lib/chacha20.c @@ -1,5 +1,5 @@ /* - * ChaCha20 256-bit cipher algorithm, RFC7539 + * The "hash function" used as the core of the ChaCha20 stream cipher (RFC7539) * * Copyright (C) 2015 Martin Willi * @@ -16,14 +16,10 @@ #include #include -void chacha20_block(u32 *state, u32 *stream) +static void chacha20_permute(u32 *x) { - u32 x[16], *out = stream; int i; - for (i = 0; i < ARRAY_SIZE(x); i++) - x[i] = state[i]; - for (i = 0; i < 20; i += 2) { x[0] += x[4]; x[12] = rol32(x[12] ^ x[0], 16); x[1] += x[5]; x[13] = rol32(x[13] ^ x[1], 16); @@ -65,10 +61,52 @@ void chacha20_block(u32 *state, u32 *stream) x[8] += x[13]; x[7] = rol32(x[7] ^ x[8], 7); x[9] += x[14]; x[4] = rol32(x[4] ^ x[9], 7); } +} + +/** + * chacha20_block - generate one keystream block and increment block counter + * @state: input state matrix (16 32-bit words) + * @stream: output keystream block (64 bytes) + * + * This is the ChaCha20 core, a function from 64-byte strings to 64-byte + * strings. The caller has already converted the endianness of the input. This + * function also handles incrementing the block counter in the input matrix. + */ +void chacha20_block(u32 *state, u32 *stream) +{ + u32 x[16]; + int i; + + memcpy(x, state, 64); + + chacha20_permute(x); for (i = 0; i < ARRAY_SIZE(x); i++) - out[i] = cpu_to_le32(x[i] + state[i]); + stream[i] = cpu_to_le32(x[i] + state[i]); state[12]++; } EXPORT_SYMBOL(chacha20_block); + +/** + * hchacha20_block - abbreviated ChaCha20 core, for XChaCha20 + * @in: input state matrix (16 32-bit words) + * @out: output (8 32-bit words) + * + * HChaCha20 is the ChaCha equivalent of HSalsa20 and is an intermediate step + * towards XChaCha20 (see https://cr.yp.to/snuffle/xsalsa-20081128.pdf). + * HChaCha20 skips the final addition of the initial state, and outputs only + * certain words of the state. It should not be used for streaming directly. + */ +void hchacha20_block(const u32 *in, u32 *out) +{ + u32 x[16]; + + memcpy(x, in, 64); + + chacha20_permute(x); + + memcpy(&out[0], &x[0], 16); + memcpy(&out[4], &x[12], 16); +} +EXPORT_SYMBOL(hchacha20_block); -- 2.18.0.597.ga71716f1ad-goog