mirror of
https://github.com/open-quantum-safe/liboqs.git
synced 2025-10-04 00:02:01 -04:00
* Integrates pqcrystals (ref and avx2) with liboqs common AES code (for Kyber-90s and Dilithium-AES). * Extends libOQS AES-CTR with Incremental API: OQS_AES256_CTR_inc_init, OQS_AES256_CTR_inc_iv, OQS_AES256_CTR_inc_ivu64, OQS_AES256_CTR_inc_stream_iv, OQS_AES256_CTR_inc_stream_blks. * Adds some AES-CTR shim API. * Faster AESNI CTR code (improved iv handling, 4x interleaved blocks for higher throughput). * OpenSSL AES supporting CTR API. * Updated pqcrystals patches (API, context releases). * Removes redundant AES implementations from Kyber and Dilithium. * Copy-from-upstream with updated patches. * Uses internal AES on x86_64 (dist & AES) because of increased performance with the internal AESNI code. * Adds AES-CTR benchmarks to speed_common * Update CONFIGURE.md
91 lines
3.6 KiB
Diff
91 lines
3.6 KiB
Diff
47bee8a95b1d9446c27e667efbd8f82ac2733bef
|
|
diff --git a/ref/indcpa.c b/ref/indcpa.c
|
|
index 60f4059..96022ea 100644
|
|
--- a/ref/indcpa.c
|
|
+++ b/ref/indcpa.c
|
|
@@ -167,6 +167,7 @@ void gen_matrix(polyvec *a, const uint8_t seed[KYBER_SYMBYTES], int transposed)
|
|
unsigned int buflen, off;
|
|
uint8_t buf[GEN_MATRIX_NBLOCKS*XOF_BLOCKBYTES+2];
|
|
xof_state state;
|
|
+ xof_init(&state, seed);
|
|
|
|
for(i=0;i<KYBER_K;i++) {
|
|
for(j=0;j<KYBER_K;j++) {
|
|
@@ -189,6 +190,7 @@ void gen_matrix(polyvec *a, const uint8_t seed[KYBER_SYMBYTES], int transposed)
|
|
}
|
|
}
|
|
}
|
|
+ xof_release(&state);
|
|
}
|
|
|
|
/*************************************************
|
|
diff --git a/ref/symmetric-shake.c b/ref/symmetric-shake.c
|
|
index 4d9560a..2317c06 100644
|
|
--- a/ref/symmetric-shake.c
|
|
+++ b/ref/symmetric-shake.c
|
|
@@ -15,7 +15,7 @@
|
|
* - uint8_t i: additional byte of input
|
|
* - uint8_t j: additional byte of input
|
|
**************************************************/
|
|
-void kyber_shake128_absorb(keccak_state *state,
|
|
+void kyber_shake128_absorb(shake128incctx *state,
|
|
const uint8_t seed[KYBER_SYMBYTES],
|
|
uint8_t x,
|
|
uint8_t y)
|
|
diff --git a/ref/symmetric-shake.c b/ref/symmetric-aes.c
|
|
index 4d9560a..2317c06 100644
|
|
--- a/ref/symmetric-aes.c
|
|
+++ b/ref/symmetric-aes.c
|
|
@@ -6,10 +6,11 @@
|
|
|
|
void kyber_aes256xof_absorb(aes256ctr_ctx *state, const uint8_t seed[32], uint8_t x, uint8_t y)
|
|
{
|
|
+ (void) seed;
|
|
uint8_t expnonce[12] = {0};
|
|
expnonce[0] = x;
|
|
expnonce[1] = y;
|
|
- aes256ctr_init(state, seed, expnonce);
|
|
+ aes256ctr_init_iv(state, expnonce);
|
|
}
|
|
|
|
void kyber_aes256ctr_prf(uint8_t *out, size_t outlen, const uint8_t key[32], uint8_t nonce)
|
|
diff --git a/ref/symmetric.h b/ref/symmetric.h
|
|
index 28339e6..bb8086f 100644
|
|
--- a/ref/symmetric.h
|
|
+++ b/ref/symmetric.h
|
|
@@ -26,8 +26,10 @@ void kyber_aes256ctr_prf(uint8_t *out, size_t outlen, const uint8_t key[32], uin
|
|
|
|
#define hash_h(OUT, IN, INBYTES) sha256(OUT, IN, INBYTES)
|
|
#define hash_g(OUT, IN, INBYTES) sha512(OUT, IN, INBYTES)
|
|
+#define xof_init(STATE, SEED) aes256ctr_init_key(STATE, SEED)
|
|
#define xof_absorb(STATE, SEED, X, Y) kyber_aes256xof_absorb(STATE, SEED, X, Y)
|
|
#define xof_squeezeblocks(OUT, OUTBLOCKS, STATE) aes256ctr_squeezeblocks(OUT, OUTBLOCKS, STATE)
|
|
+#define xof_release(STATE) aes256_ctx_release(STATE)
|
|
#define prf(OUT, OUTBYTES, KEY, NONCE) kyber_aes256ctr_prf(OUT, OUTBYTES, KEY, NONCE)
|
|
#define kdf(OUT, IN, INBYTES) sha256(OUT, IN, INBYTES)
|
|
|
|
@@ -35,10 +37,10 @@ void kyber_aes256ctr_prf(uint8_t *out, size_t outlen, const uint8_t key[32], uin
|
|
|
|
#include "fips202.h"
|
|
|
|
-typedef keccak_state xof_state;
|
|
+typedef shake128incctx xof_state;
|
|
|
|
#define kyber_shake128_absorb KYBER_NAMESPACE(kyber_shake128_absorb)
|
|
-void kyber_shake128_absorb(keccak_state *s,
|
|
+void kyber_shake128_absorb(shake128incctx *s,
|
|
const uint8_t seed[KYBER_SYMBYTES],
|
|
uint8_t x,
|
|
uint8_t y);
|
|
@@ -50,8 +52,10 @@ void kyber_shake256_prf(uint8_t *out, size_t outlen, const uint8_t key[KYBER_SYM
|
|
|
|
#define hash_h(OUT, IN, INBYTES) sha3_256(OUT, IN, INBYTES)
|
|
#define hash_g(OUT, IN, INBYTES) sha3_512(OUT, IN, INBYTES)
|
|
+#define xof_init(STATE, SEED) shake128_inc_init(STATE)
|
|
#define xof_absorb(STATE, SEED, X, Y) kyber_shake128_absorb(STATE, SEED, X, Y)
|
|
#define xof_squeezeblocks(OUT, OUTBLOCKS, STATE) shake128_squeezeblocks(OUT, OUTBLOCKS, STATE)
|
|
+#define xof_release(STATE) shake128_inc_ctx_release(STATE)
|
|
#define prf(OUT, OUTBYTES, KEY, NONCE) kyber_shake256_prf(OUT, OUTBYTES, KEY, NONCE)
|
|
#define kdf(OUT, IN, INBYTES) shake256(OUT, KYBER_SSBYTES, IN, INBYTES)
|
|
|