encrypt.c 1.81 KB
Newer Older
lwc-tester committed
1
#include "api.h"
Martin Schläffer committed
2
#include "ascon.h"
lwc-tester committed
3
#include "permutations.h"
Martin Schläffer committed
4
#include "printstate.h"
Martin Schläffer committed
5
#include "word.h"
lwc-tester committed
6

Martin Schläffer committed
7 8 9 10 11 12
int crypto_aead_encrypt(uint8_t* c, uint64_t* clen, const uint8_t* m,
                        uint64_t mlen, const uint8_t* ad, uint64_t adlen,
                        const uint8_t* nsec, const uint8_t* npub,
                        const uint8_t* k) {
  uint64_t K0, K1, K2, N0, N1;
  state_t s;
lwc-tester committed
13 14
  (void)nsec;

Martin Schläffer committed
15
  /* set ciphertext size */
lwc-tester committed
16 17
  *clen = mlen + CRYPTO_ABYTES;

Martin Schläffer committed
18
  /* load key and nonce */
Martin Schläffer committed
19 20 21 22 23
  K0 = LOADBYTES(k + 0, 4) >> 32;
  K1 = LOADBYTES(k + 4, 8);
  K2 = LOADBYTES(k + 12, 8);
  N0 = LOADBYTES(npub, 8);
  N1 = LOADBYTES(npub + 8, 8);
Martin Schläffer committed
24 25 26

  /* initialization */
  s.x0 = ASCON_80PQ_IV | K0;
lwc-tester committed
27 28 29 30 31 32 33 34
  s.x1 = K1;
  s.x2 = K2;
  s.x3 = N0;
  s.x4 = N1;
  P12(&s);
  s.x2 ^= K0;
  s.x3 ^= K1;
  s.x4 ^= K2;
Martin Schläffer committed
35
  printstate("initialization", &s);
lwc-tester committed
36

Martin Schläffer committed
37
  /* process associated data */
lwc-tester committed
38
  if (adlen) {
Martin Schläffer committed
39
    while (adlen >= ASCON_128_RATE) {
Martin Schläffer committed
40
      s.x0 ^= LOADBYTES(ad, 8);
lwc-tester committed
41
      P6(&s);
Martin Schläffer committed
42 43
      ad += ASCON_128_RATE;
      adlen -= ASCON_128_RATE;
lwc-tester committed
44
    }
Martin Schläffer committed
45
    /* final associated data block */
Martin Schläffer committed
46
    s.x0 ^= LOADBYTES(ad, adlen);
Martin Schläffer committed
47
    s.x0 ^= PAD(adlen);
lwc-tester committed
48 49 50
    P6(&s);
  }
  s.x4 ^= 1;
Martin Schläffer committed
51
  printstate("process associated data", &s);
lwc-tester committed
52

Martin Schläffer committed
53 54
  /* process plaintext */
  while (mlen >= ASCON_128_RATE) {
Martin Schläffer committed
55 56
    s.x0 ^= LOADBYTES(m, 8);
    STOREBYTES(c, s.x0, 8);
lwc-tester committed
57
    P6(&s);
Martin Schläffer committed
58 59 60
    m += ASCON_128_RATE;
    c += ASCON_128_RATE;
    mlen -= ASCON_128_RATE;
lwc-tester committed
61
  }
Martin Schläffer committed
62
  /* final plaintext block */
Martin Schläffer committed
63 64
  s.x0 ^= LOADBYTES(m, mlen);
  STOREBYTES(c, s.x0, mlen);
Martin Schläffer committed
65
  s.x0 ^= PAD(mlen);
lwc-tester committed
66
  c += mlen;
Martin Schläffer committed
67
  printstate("process plaintext", &s);
lwc-tester committed
68

Martin Schläffer committed
69
  /* finalization */
lwc-tester committed
70 71 72 73 74 75
  s.x1 ^= K0 << 32 | K1 >> 32;
  s.x2 ^= K1 << 32 | K2 >> 32;
  s.x3 ^= K2 << 32;
  P12(&s);
  s.x3 ^= K1;
  s.x4 ^= K2;
Martin Schläffer committed
76
  printstate("finalization", &s);
lwc-tester committed
77

Martin Schläffer committed
78
  /* set tag */
Martin Schläffer committed
79 80
  STOREBYTES(c, s.x3, 8);
  STOREBYTES(c + 8, s.x4, 8);
lwc-tester committed
81 82 83

  return 0;
}