1*9f90fd23Sdtucker /* $OpenBSD: xmss_fast.h,v 1.2 2018/02/26 03:56:44 dtucker Exp $ */ 2a6be8e7cSmarkus /* 3a6be8e7cSmarkus xmss_fast.h version 20160722 4a6be8e7cSmarkus Andreas Hülsing 5a6be8e7cSmarkus Joost Rijneveld 6a6be8e7cSmarkus Public domain. 7a6be8e7cSmarkus */ 8a6be8e7cSmarkus 9a6be8e7cSmarkus #include "xmss_wots.h" 10a6be8e7cSmarkus 11a6be8e7cSmarkus #ifndef XMSS_H 12a6be8e7cSmarkus #define XMSS_H 13a6be8e7cSmarkus typedef struct{ 14a6be8e7cSmarkus unsigned int level; 15a6be8e7cSmarkus unsigned long long subtree; 16a6be8e7cSmarkus unsigned int subleaf; 17a6be8e7cSmarkus } leafaddr; 18a6be8e7cSmarkus 19a6be8e7cSmarkus typedef struct{ 20a6be8e7cSmarkus wots_params wots_par; 21a6be8e7cSmarkus unsigned int n; 22a6be8e7cSmarkus unsigned int h; 23a6be8e7cSmarkus unsigned int k; 24a6be8e7cSmarkus } xmss_params; 25a6be8e7cSmarkus 26a6be8e7cSmarkus typedef struct{ 27a6be8e7cSmarkus xmss_params xmss_par; 28a6be8e7cSmarkus unsigned int n; 29a6be8e7cSmarkus unsigned int h; 30a6be8e7cSmarkus unsigned int d; 31a6be8e7cSmarkus unsigned int index_len; 32a6be8e7cSmarkus } xmssmt_params; 33a6be8e7cSmarkus 34a6be8e7cSmarkus typedef struct{ 35a6be8e7cSmarkus unsigned int h; 36a6be8e7cSmarkus unsigned int next_idx; 37a6be8e7cSmarkus unsigned int stackusage; 38a6be8e7cSmarkus unsigned char completed; 39a6be8e7cSmarkus unsigned char *node; 40a6be8e7cSmarkus } treehash_inst; 41a6be8e7cSmarkus 42a6be8e7cSmarkus typedef struct { 43a6be8e7cSmarkus unsigned char *stack; 44a6be8e7cSmarkus unsigned int stackoffset; 45a6be8e7cSmarkus unsigned char *stacklevels; 46a6be8e7cSmarkus unsigned char *auth; 47a6be8e7cSmarkus unsigned char *keep; 48a6be8e7cSmarkus treehash_inst *treehash; 49a6be8e7cSmarkus unsigned char *retain; 50a6be8e7cSmarkus unsigned int next_leaf; 51a6be8e7cSmarkus } bds_state; 52a6be8e7cSmarkus 53a6be8e7cSmarkus /** 54a6be8e7cSmarkus * Initialize BDS state struct 55a6be8e7cSmarkus * parameter names are the same as used in the description of the BDS traversal 56a6be8e7cSmarkus */ 57a6be8e7cSmarkus void xmss_set_bds_state(bds_state *state, unsigned char *stack, int stackoffset, unsigned char *stacklevels, unsigned char *auth, unsigned char *keep, treehash_inst *treehash, unsigned char *retain, int next_leaf); 58a6be8e7cSmarkus /** 59a6be8e7cSmarkus * Initializes parameter set. 60a6be8e7cSmarkus * Needed, for any of the other methods. 61a6be8e7cSmarkus */ 62a6be8e7cSmarkus int xmss_set_params(xmss_params *params, int n, int h, int w, int k); 63a6be8e7cSmarkus /** 64a6be8e7cSmarkus * Initialize xmssmt_params struct 65a6be8e7cSmarkus * parameter names are the same as in the draft 66a6be8e7cSmarkus * 67a6be8e7cSmarkus * Especially h is the total tree height, i.e. the XMSS trees have height h/d 68a6be8e7cSmarkus */ 69a6be8e7cSmarkus int xmssmt_set_params(xmssmt_params *params, int n, int h, int d, int w, int k); 70a6be8e7cSmarkus /** 71a6be8e7cSmarkus * Generates a XMSS key pair for a given parameter set. 72a6be8e7cSmarkus * Format sk: [(32bit) idx || SK_SEED || SK_PRF || PUB_SEED || root] 73a6be8e7cSmarkus * Format pk: [root || PUB_SEED] omitting algo oid. 74a6be8e7cSmarkus */ 75a6be8e7cSmarkus int xmss_keypair(unsigned char *pk, unsigned char *sk, bds_state *state, xmss_params *params); 76a6be8e7cSmarkus /** 77a6be8e7cSmarkus * Signs a message. 78a6be8e7cSmarkus * Returns 79a6be8e7cSmarkus * 1. an array containing the signature followed by the message AND 80a6be8e7cSmarkus * 2. an updated secret key! 81a6be8e7cSmarkus * 82a6be8e7cSmarkus */ 83a6be8e7cSmarkus int xmss_sign(unsigned char *sk, bds_state *state, unsigned char *sig_msg, unsigned long long *sig_msg_len, const unsigned char *msg,unsigned long long msglen, const xmss_params *params); 84a6be8e7cSmarkus /** 85a6be8e7cSmarkus * Verifies a given message signature pair under a given public key. 86a6be8e7cSmarkus * 87a6be8e7cSmarkus * Note: msg and msglen are pure outputs which carry the message in case verification succeeds. The (input) message is assumed to be within sig_msg which has the form (sig||msg). 88a6be8e7cSmarkus */ 89a6be8e7cSmarkus int xmss_sign_open(unsigned char *msg,unsigned long long *msglen, const unsigned char *sig_msg,unsigned long long sig_msg_len, const unsigned char *pk, const xmss_params *params); 90a6be8e7cSmarkus 91a6be8e7cSmarkus /* 92a6be8e7cSmarkus * Generates a XMSSMT key pair for a given parameter set. 93a6be8e7cSmarkus * Format sk: [(ceil(h/8) bit) idx || SK_SEED || SK_PRF || PUB_SEED || root] 94a6be8e7cSmarkus * Format pk: [root || PUB_SEED] omitting algo oid. 95a6be8e7cSmarkus */ 96a6be8e7cSmarkus int xmssmt_keypair(unsigned char *pk, unsigned char *sk, bds_state *states, unsigned char *wots_sigs, xmssmt_params *params); 97a6be8e7cSmarkus /** 98a6be8e7cSmarkus * Signs a message. 99a6be8e7cSmarkus * Returns 100a6be8e7cSmarkus * 1. an array containing the signature followed by the message AND 101a6be8e7cSmarkus * 2. an updated secret key! 102a6be8e7cSmarkus * 103a6be8e7cSmarkus */ 104a6be8e7cSmarkus int xmssmt_sign(unsigned char *sk, bds_state *state, unsigned char *wots_sigs, unsigned char *sig_msg, unsigned long long *sig_msg_len, const unsigned char *msg, unsigned long long msglen, const xmssmt_params *params); 105a6be8e7cSmarkus /** 106a6be8e7cSmarkus * Verifies a given message signature pair under a given public key. 107a6be8e7cSmarkus */ 108a6be8e7cSmarkus int xmssmt_sign_open(unsigned char *msg, unsigned long long *msglen, const unsigned char *sig_msg, unsigned long long sig_msg_len, const unsigned char *pk, const xmssmt_params *params); 109a6be8e7cSmarkus #endif 110a6be8e7cSmarkus 111