box_curve25519xsalsa20poly1305.c 4.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156
  1. #include <string.h>
  2. #include "crypto_box_curve25519xsalsa20poly1305.h"
  3. #include "crypto_core_hsalsa20.h"
  4. #include "crypto_hash_sha512.h"
  5. #include "crypto_scalarmult_curve25519.h"
  6. #include "crypto_secretbox_xsalsa20poly1305.h"
  7. #include "randombytes.h"
  8. #include "utils.h"
  9. int
  10. crypto_box_curve25519xsalsa20poly1305_seed_keypair(unsigned char *pk,
  11. unsigned char *sk,
  12. const unsigned char *seed)
  13. {
  14. unsigned char hash[64];
  15. crypto_hash_sha512(hash, seed, 32);
  16. memcpy(sk, hash, 32);
  17. sodium_memzero(hash, sizeof hash);
  18. return crypto_scalarmult_curve25519_base(pk, sk);
  19. }
  20. int
  21. crypto_box_curve25519xsalsa20poly1305_keypair(unsigned char *pk,
  22. unsigned char *sk)
  23. {
  24. randombytes_buf(sk, 32);
  25. return crypto_scalarmult_curve25519_base(pk, sk);
  26. }
  27. int
  28. crypto_box_curve25519xsalsa20poly1305_beforenm(unsigned char *k,
  29. const unsigned char *pk,
  30. const unsigned char *sk)
  31. {
  32. static const unsigned char zero[16] = { 0 };
  33. unsigned char s[32];
  34. if (crypto_scalarmult_curve25519(s, sk, pk) != 0) {
  35. return -1;
  36. }
  37. return crypto_core_hsalsa20(k, zero, s, NULL);
  38. }
  39. int
  40. crypto_box_curve25519xsalsa20poly1305_afternm(unsigned char *c,
  41. const unsigned char *m,
  42. unsigned long long mlen,
  43. const unsigned char *n,
  44. const unsigned char *k)
  45. {
  46. return crypto_secretbox_xsalsa20poly1305(c, m, mlen, n, k);
  47. }
  48. int
  49. crypto_box_curve25519xsalsa20poly1305_open_afternm(unsigned char *m,
  50. const unsigned char *c,
  51. unsigned long long clen,
  52. const unsigned char *n,
  53. const unsigned char *k)
  54. {
  55. return crypto_secretbox_xsalsa20poly1305_open(m, c, clen, n, k);
  56. }
  57. int
  58. crypto_box_curve25519xsalsa20poly1305(unsigned char *c, const unsigned char *m,
  59. unsigned long long mlen,
  60. const unsigned char *n,
  61. const unsigned char *pk,
  62. const unsigned char *sk)
  63. {
  64. unsigned char k[crypto_box_curve25519xsalsa20poly1305_BEFORENMBYTES];
  65. int ret;
  66. if (crypto_box_curve25519xsalsa20poly1305_beforenm(k, pk, sk) != 0) {
  67. return -1;
  68. }
  69. ret = crypto_box_curve25519xsalsa20poly1305_afternm(c, m, mlen, n, k);
  70. sodium_memzero(k, sizeof k);
  71. return ret;
  72. }
  73. int
  74. crypto_box_curve25519xsalsa20poly1305_open(
  75. unsigned char *m, const unsigned char *c, unsigned long long clen,
  76. const unsigned char *n, const unsigned char *pk, const unsigned char *sk)
  77. {
  78. unsigned char k[crypto_box_curve25519xsalsa20poly1305_BEFORENMBYTES];
  79. int ret;
  80. if (crypto_box_curve25519xsalsa20poly1305_beforenm(k, pk, sk) != 0) {
  81. return -1;
  82. }
  83. ret = crypto_box_curve25519xsalsa20poly1305_open_afternm(m, c, clen, n, k);
  84. sodium_memzero(k, sizeof k);
  85. return ret;
  86. }
  87. size_t
  88. crypto_box_curve25519xsalsa20poly1305_seedbytes(void)
  89. {
  90. return crypto_box_curve25519xsalsa20poly1305_SEEDBYTES;
  91. }
  92. size_t
  93. crypto_box_curve25519xsalsa20poly1305_publickeybytes(void)
  94. {
  95. return crypto_box_curve25519xsalsa20poly1305_PUBLICKEYBYTES;
  96. }
  97. size_t
  98. crypto_box_curve25519xsalsa20poly1305_secretkeybytes(void)
  99. {
  100. return crypto_box_curve25519xsalsa20poly1305_SECRETKEYBYTES;
  101. }
  102. size_t
  103. crypto_box_curve25519xsalsa20poly1305_beforenmbytes(void)
  104. {
  105. return crypto_box_curve25519xsalsa20poly1305_BEFORENMBYTES;
  106. }
  107. size_t
  108. crypto_box_curve25519xsalsa20poly1305_noncebytes(void)
  109. {
  110. return crypto_box_curve25519xsalsa20poly1305_NONCEBYTES;
  111. }
  112. size_t
  113. crypto_box_curve25519xsalsa20poly1305_zerobytes(void)
  114. {
  115. return crypto_box_curve25519xsalsa20poly1305_ZEROBYTES;
  116. }
  117. size_t
  118. crypto_box_curve25519xsalsa20poly1305_boxzerobytes(void)
  119. {
  120. return crypto_box_curve25519xsalsa20poly1305_BOXZEROBYTES;
  121. }
  122. size_t
  123. crypto_box_curve25519xsalsa20poly1305_macbytes(void)
  124. {
  125. return crypto_box_curve25519xsalsa20poly1305_MACBYTES;
  126. }
  127. size_t
  128. crypto_box_curve25519xsalsa20poly1305_messagebytes_max(void)
  129. {
  130. return crypto_box_curve25519xsalsa20poly1305_MESSAGEBYTES_MAX;
  131. }