1 /* $NetBSD: adiantum.h,v 1.1 2020/06/29 23:44:01 riastradh Exp $ */ 2 3 /*- 4 * Copyright (c) 2020 The NetBSD Foundation, Inc. 5 * All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 16 * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS 17 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED 18 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 19 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS 20 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 21 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 22 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 23 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 24 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 25 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 26 * POSSIBILITY OF SUCH DAMAGE. 27 */ 28 29 #ifndef _CRYPTO_ADIANTUM_ADIANTUM_H 30 #define _CRYPTO_ADIANTUM_ADIANTUM_H 31 32 #include <sys/types.h> 33 34 #ifdef _KERNEL 35 #include <crypto/aes/aes.h> 36 #endif 37 38 struct adiantum { 39 uint8_t ks[32]; /* XChaCha12 key */ 40 41 /* BEGIN XCHACHA12 OUTPUT -- DO NOT REORDER */ 42 uint8_t kk[32]; /* AES key */ 43 uint8_t kt[16]; /* Poly1305 tweak key */ 44 uint8_t kl[16]; /* Poly1305 message key */ 45 uint32_t kn[268]; /* NH key */ 46 /* END XCHACHA12 OUTPUT */ 47 48 struct aesenc kk_enc; /* expanded AES key */ 49 struct aesdec kk_dec; 50 }; 51 52 #define ADIANTUM_KEYBYTES 32 53 #define ADIANTUM_BLOCKBYTES 16 /* size must be positive multiple of this */ 54 55 void adiantum_init(struct adiantum *, const uint8_t[static ADIANTUM_KEYBYTES]); 56 void adiantum_enc(void *, const void *, size_t, const void *, size_t, 57 const struct adiantum *); 58 void adiantum_dec(void *, const void *, size_t, const void *, size_t, 59 const struct adiantum *); 60 61 int adiantum_selftest(void); 62 63 #endif /* _CRYPTO_ADIANTUM_ADIANTUM_H */ 64