encrypt.c 2.32 KB
Newer Older
lwc-tester committed
1
#include "api.h"
Martin Schläffer committed
2
#include "ascon.h"
Enrico Pozzobon committed
3
#include "crypto_aead.h"
lwc-tester committed
4
#include "permutations.h"
Martin Schläffer committed
5
#include "printstate.h"
Martin Schläffer committed
6
#include "word.h"
lwc-tester committed
7

Enrico Pozzobon committed
8 9 10 11 12
int crypto_aead_encrypt(unsigned char* c, unsigned long long* clen,
                        const unsigned char* m, unsigned long long mlen,
                        const unsigned char* ad, unsigned long long adlen,
                        const unsigned char* nsec, const unsigned char* npub,
                        const unsigned char* k) {
lwc-tester committed
13 14
  (void)nsec;

Martin Schläffer committed
15
  /* set ciphertext size */
lwc-tester committed
16 17
  *clen = mlen + CRYPTO_ABYTES;

Martin Schläffer committed
18
  /* load key and nonce */
Enrico Pozzobon committed
19 20 21 22
  const uint64_t K0 = LOADBYTES(k, 8);
  const uint64_t K1 = LOADBYTES(k + 8, 8);
  const uint64_t N0 = LOADBYTES(npub, 8);
  const uint64_t N1 = LOADBYTES(npub + 8, 8);
Martin Schläffer committed
23

Enrico Pozzobon committed
24 25
  /* initialize */
  state_t s;
Martin Schläffer committed
26
  s.x0 = ASCON_128A_IV;
lwc-tester committed
27 28 29 30 31 32 33
  s.x1 = K0;
  s.x2 = K1;
  s.x3 = N0;
  s.x4 = N1;
  P12(&s);
  s.x3 ^= K0;
  s.x4 ^= K1;
Martin Schläffer committed
34
  printstate("initialization", &s);
lwc-tester committed
35 36

  if (adlen) {
Enrico Pozzobon committed
37
    /* full associated data blocks */
Martin Schläffer committed
38
    while (adlen >= ASCON_128A_RATE) {
Martin Schläffer committed
39 40
      s.x0 ^= LOADBYTES(ad, 8);
      s.x1 ^= LOADBYTES(ad + 8, 8);
lwc-tester committed
41
      P8(&s);
Martin Schläffer committed
42 43
      ad += ASCON_128A_RATE;
      adlen -= ASCON_128A_RATE;
lwc-tester committed
44
    }
Martin Schläffer committed
45
    /* final associated data block */
lwc-tester committed
46
    if (adlen >= 8) {
Martin Schläffer committed
47 48
      s.x0 ^= LOADBYTES(ad, 8);
      s.x1 ^= LOADBYTES(ad + 8, adlen - 8);
Martin Schläffer committed
49
      s.x1 ^= PAD(adlen - 8);
lwc-tester committed
50
    } else {
Martin Schläffer committed
51
      s.x0 ^= LOADBYTES(ad, adlen);
Martin Schläffer committed
52
      s.x0 ^= PAD(adlen);
lwc-tester committed
53 54 55
    }
    P8(&s);
  }
Enrico Pozzobon committed
56
  /* domain separation */
lwc-tester committed
57
  s.x4 ^= 1;
Martin Schläffer committed
58
  printstate("process associated data", &s);
lwc-tester committed
59

Enrico Pozzobon committed
60
  /* full plaintext blocks */
Martin Schläffer committed
61
  while (mlen >= ASCON_128A_RATE) {
Martin Schläffer committed
62 63 64 65
    s.x0 ^= LOADBYTES(m, 8);
    s.x1 ^= LOADBYTES(m + 8, 8);
    STOREBYTES(c, s.x0, 8);
    STOREBYTES(c + 8, s.x1, 8);
lwc-tester committed
66
    P8(&s);
Martin Schläffer committed
67 68 69
    m += ASCON_128A_RATE;
    c += ASCON_128A_RATE;
    mlen -= ASCON_128A_RATE;
lwc-tester committed
70
  }
Martin Schläffer committed
71
  /* final plaintext block */
lwc-tester committed
72
  if (mlen >= 8) {
Martin Schläffer committed
73 74 75 76
    s.x0 ^= LOADBYTES(m, 8);
    s.x1 ^= LOADBYTES(m + 8, mlen - 8);
    STOREBYTES(c, s.x0, 8);
    STOREBYTES(c + 8, s.x1, mlen - 8);
Martin Schläffer committed
77
    s.x1 ^= PAD(mlen - 8);
lwc-tester committed
78
  } else {
Martin Schläffer committed
79 80
    s.x0 ^= LOADBYTES(m, mlen);
    STOREBYTES(c, s.x0, mlen);
Martin Schläffer committed
81
    s.x0 ^= PAD(mlen);
lwc-tester committed
82 83
  }
  c += mlen;
Martin Schläffer committed
84
  printstate("process plaintext", &s);
lwc-tester committed
85

Enrico Pozzobon committed
86
  /* finalize */
lwc-tester committed
87 88 89 90 91
  s.x2 ^= K0;
  s.x3 ^= K1;
  P12(&s);
  s.x3 ^= K0;
  s.x4 ^= K1;
Martin Schläffer committed
92
  printstate("finalization", &s);
lwc-tester committed
93

Martin Schläffer committed
94
  /* set tag */
Martin Schläffer committed
95 96
  STOREBYTES(c, s.x3, 8);
  STOREBYTES(c + 8, s.x4, 8);
lwc-tester committed
97 98 99

  return 0;
}