round.h 1.08 KB
Newer Older
Martin Schläffer committed
1 2 3 4 5 6
#ifndef ROUND_H_
#define ROUND_H_

#include "ascon.h"
#include "printstate.h"

Martin Schläffer committed
7 8
forceinline void ROUND(state_t* s, uint64_t C) {
  uint64_t xtemp;
Martin Schläffer committed
9
  /* round constant */
Martin Schläffer committed
10
  s->x[2] ^= C;
Martin Schläffer committed
11
  /* s-box layer */
Martin Schläffer committed
12 13 14 15 16 17 18 19 20 21 22 23
  s->x[0] ^= s->x[4];
  s->x[4] ^= s->x[3];
  s->x[2] ^= s->x[1];
  xtemp = s->x[0] & ~s->x[4];
  s->x[0] ^= s->x[2] & ~s->x[1];
  s->x[2] ^= s->x[4] & ~s->x[3];
  s->x[4] ^= s->x[1] & ~s->x[0];
  s->x[1] ^= s->x[3] & ~s->x[2];
  s->x[3] ^= xtemp;
  s->x[1] ^= s->x[0];
  s->x[3] ^= s->x[2];
  s->x[0] ^= s->x[4];
Martin Schläffer committed
24
  /* linear layer */
Martin Schläffer committed
25 26 27 28 29 30 31 32 33 34 35
  xtemp = s->x[0] ^ ROR(s->x[0], 28 - 19);
  s->x[0] ^= ROR(xtemp, 19);
  xtemp = s->x[1] ^ ROR(s->x[1], 61 - 39);
  s->x[1] ^= ROR(xtemp, 39);
  xtemp = s->x[2] ^ ROR(s->x[2], 6 - 1);
  s->x[2] ^= ROR(xtemp, 1);
  xtemp = s->x[3] ^ ROR(s->x[3], 17 - 10);
  s->x[3] ^= ROR(xtemp, 10);
  xtemp = s->x[4] ^ ROR(s->x[4], 41 - 7);
  s->x[4] ^= ROR(xtemp, 7);
  s->x[2] = ~s->x[2];
Martin Schläffer committed
36 37 38
  printstate(" round output", s);
}

Martin Schläffer committed
39 40 41 42 43 44 45 46
forceinline void PROUNDS(state_t* s, int nr) {
  int i = START(nr);
  do {
    ROUND(s, RC(i));
    i += INC;
  } while (i != END);
}

Martin Schläffer committed
47
#endif /* ROUND_H_ */