adiantum.h revision 1.1 1 /* $NetBSD: adiantum.h,v 1.1 2020/06/29 23:44:01 riastradh Exp $ */
2
3 /*-
4 * Copyright (c) 2020 The NetBSD Foundation, Inc.
5 * All rights reserved.
6 *
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
9 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
15 *
16 * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
17 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
18 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
19 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
20 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
21 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
22 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
23 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
24 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
25 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
26 * POSSIBILITY OF SUCH DAMAGE.
27 */
28
29 #ifndef _CRYPTO_ADIANTUM_ADIANTUM_H
30 #define _CRYPTO_ADIANTUM_ADIANTUM_H
31
32 #include <sys/types.h>
33
34 #ifdef _KERNEL
35 #include <crypto/aes/aes.h>
36 #endif
37
38 struct adiantum {
39 uint8_t ks[32]; /* XChaCha12 key */
40
41 /* BEGIN XCHACHA12 OUTPUT -- DO NOT REORDER */
42 uint8_t kk[32]; /* AES key */
43 uint8_t kt[16]; /* Poly1305 tweak key */
44 uint8_t kl[16]; /* Poly1305 message key */
45 uint32_t kn[268]; /* NH key */
46 /* END XCHACHA12 OUTPUT */
47
48 struct aesenc kk_enc; /* expanded AES key */
49 struct aesdec kk_dec;
50 };
51
52 #define ADIANTUM_KEYBYTES 32
53 #define ADIANTUM_BLOCKBYTES 16 /* size must be positive multiple of this */
54
55 void adiantum_init(struct adiantum *, const uint8_t[static ADIANTUM_KEYBYTES]);
56 void adiantum_enc(void *, const void *, size_t, const void *, size_t,
57 const struct adiantum *);
58 void adiantum_dec(void *, const void *, size_t, const void *, size_t,
59 const struct adiantum *);
60
61 int adiantum_selftest(void);
62
63 #endif /* _CRYPTO_ADIANTUM_ADIANTUM_H */
64