xref: /openbsd/usr.bin/ssh/xmss_fast.h (revision 9f90fd23)
1*9f90fd23Sdtucker /* $OpenBSD: xmss_fast.h,v 1.2 2018/02/26 03:56:44 dtucker Exp $ */
2a6be8e7cSmarkus /*
3a6be8e7cSmarkus xmss_fast.h version 20160722
4a6be8e7cSmarkus Andreas Hülsing
5a6be8e7cSmarkus Joost Rijneveld
6a6be8e7cSmarkus Public domain.
7a6be8e7cSmarkus */
8a6be8e7cSmarkus 
9a6be8e7cSmarkus #include "xmss_wots.h"
10a6be8e7cSmarkus 
11a6be8e7cSmarkus #ifndef XMSS_H
12a6be8e7cSmarkus #define XMSS_H
13a6be8e7cSmarkus typedef struct{
14a6be8e7cSmarkus   unsigned int level;
15a6be8e7cSmarkus   unsigned long long subtree;
16a6be8e7cSmarkus   unsigned int subleaf;
17a6be8e7cSmarkus } leafaddr;
18a6be8e7cSmarkus 
19a6be8e7cSmarkus typedef struct{
20a6be8e7cSmarkus   wots_params wots_par;
21a6be8e7cSmarkus   unsigned int n;
22a6be8e7cSmarkus   unsigned int h;
23a6be8e7cSmarkus   unsigned int k;
24a6be8e7cSmarkus } xmss_params;
25a6be8e7cSmarkus 
26a6be8e7cSmarkus typedef struct{
27a6be8e7cSmarkus   xmss_params xmss_par;
28a6be8e7cSmarkus   unsigned int n;
29a6be8e7cSmarkus   unsigned int h;
30a6be8e7cSmarkus   unsigned int d;
31a6be8e7cSmarkus   unsigned int index_len;
32a6be8e7cSmarkus } xmssmt_params;
33a6be8e7cSmarkus 
34a6be8e7cSmarkus typedef struct{
35a6be8e7cSmarkus   unsigned int h;
36a6be8e7cSmarkus   unsigned int next_idx;
37a6be8e7cSmarkus   unsigned int stackusage;
38a6be8e7cSmarkus   unsigned char completed;
39a6be8e7cSmarkus   unsigned char *node;
40a6be8e7cSmarkus } treehash_inst;
41a6be8e7cSmarkus 
42a6be8e7cSmarkus typedef struct {
43a6be8e7cSmarkus   unsigned char *stack;
44a6be8e7cSmarkus   unsigned int stackoffset;
45a6be8e7cSmarkus   unsigned char *stacklevels;
46a6be8e7cSmarkus   unsigned char *auth;
47a6be8e7cSmarkus   unsigned char *keep;
48a6be8e7cSmarkus   treehash_inst *treehash;
49a6be8e7cSmarkus   unsigned char *retain;
50a6be8e7cSmarkus   unsigned int next_leaf;
51a6be8e7cSmarkus } bds_state;
52a6be8e7cSmarkus 
53a6be8e7cSmarkus /**
54a6be8e7cSmarkus  * Initialize BDS state struct
55a6be8e7cSmarkus  * parameter names are the same as used in the description of the BDS traversal
56a6be8e7cSmarkus  */
57a6be8e7cSmarkus void xmss_set_bds_state(bds_state *state, unsigned char *stack, int stackoffset, unsigned char *stacklevels, unsigned char *auth, unsigned char *keep, treehash_inst *treehash, unsigned char *retain, int next_leaf);
58a6be8e7cSmarkus /**
59a6be8e7cSmarkus  * Initializes parameter set.
60a6be8e7cSmarkus  * Needed, for any of the other methods.
61a6be8e7cSmarkus  */
62a6be8e7cSmarkus int xmss_set_params(xmss_params *params, int n, int h, int w, int k);
63a6be8e7cSmarkus /**
64a6be8e7cSmarkus  * Initialize xmssmt_params struct
65a6be8e7cSmarkus  * parameter names are the same as in the draft
66a6be8e7cSmarkus  *
67a6be8e7cSmarkus  * Especially h is the total tree height, i.e. the XMSS trees have height h/d
68a6be8e7cSmarkus  */
69a6be8e7cSmarkus int xmssmt_set_params(xmssmt_params *params, int n, int h, int d, int w, int k);
70a6be8e7cSmarkus /**
71a6be8e7cSmarkus  * Generates a XMSS key pair for a given parameter set.
72a6be8e7cSmarkus  * Format sk: [(32bit) idx || SK_SEED || SK_PRF || PUB_SEED || root]
73a6be8e7cSmarkus  * Format pk: [root || PUB_SEED] omitting algo oid.
74a6be8e7cSmarkus  */
75a6be8e7cSmarkus int xmss_keypair(unsigned char *pk, unsigned char *sk, bds_state *state, xmss_params *params);
76a6be8e7cSmarkus /**
77a6be8e7cSmarkus  * Signs a message.
78a6be8e7cSmarkus  * Returns
79a6be8e7cSmarkus  * 1. an array containing the signature followed by the message AND
80a6be8e7cSmarkus  * 2. an updated secret key!
81a6be8e7cSmarkus  *
82a6be8e7cSmarkus  */
83a6be8e7cSmarkus int xmss_sign(unsigned char *sk, bds_state *state, unsigned char *sig_msg, unsigned long long *sig_msg_len, const unsigned char *msg,unsigned long long msglen, const xmss_params *params);
84a6be8e7cSmarkus /**
85a6be8e7cSmarkus  * Verifies a given message signature pair under a given public key.
86a6be8e7cSmarkus  *
87a6be8e7cSmarkus  * Note: msg and msglen are pure outputs which carry the message in case verification succeeds. The (input) message is assumed to be within sig_msg which has the form (sig||msg).
88a6be8e7cSmarkus  */
89a6be8e7cSmarkus int xmss_sign_open(unsigned char *msg,unsigned long long *msglen, const unsigned char *sig_msg,unsigned long long sig_msg_len, const unsigned char *pk, const xmss_params *params);
90a6be8e7cSmarkus 
91a6be8e7cSmarkus /*
92a6be8e7cSmarkus  * Generates a XMSSMT key pair for a given parameter set.
93a6be8e7cSmarkus  * Format sk: [(ceil(h/8) bit) idx || SK_SEED || SK_PRF || PUB_SEED || root]
94a6be8e7cSmarkus  * Format pk: [root || PUB_SEED] omitting algo oid.
95a6be8e7cSmarkus  */
96a6be8e7cSmarkus int xmssmt_keypair(unsigned char *pk, unsigned char *sk, bds_state *states, unsigned char *wots_sigs, xmssmt_params *params);
97a6be8e7cSmarkus /**
98a6be8e7cSmarkus  * Signs a message.
99a6be8e7cSmarkus  * Returns
100a6be8e7cSmarkus  * 1. an array containing the signature followed by the message AND
101a6be8e7cSmarkus  * 2. an updated secret key!
102a6be8e7cSmarkus  *
103a6be8e7cSmarkus  */
104a6be8e7cSmarkus int xmssmt_sign(unsigned char *sk, bds_state *state, unsigned char *wots_sigs, unsigned char *sig_msg, unsigned long long *sig_msg_len, const unsigned char *msg, unsigned long long msglen, const xmssmt_params *params);
105a6be8e7cSmarkus /**
106a6be8e7cSmarkus  * Verifies a given message signature pair under a given public key.
107a6be8e7cSmarkus  */
108a6be8e7cSmarkus int xmssmt_sign_open(unsigned char *msg, unsigned long long *msglen, const unsigned char *sig_msg, unsigned long long sig_msg_len, const unsigned char *pk, const xmssmt_params *params);
109a6be8e7cSmarkus #endif
110a6be8e7cSmarkus 
111