-
Notifications
You must be signed in to change notification settings - Fork 12
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
remove randombytes.c and add notrandombytes.c
This removes our current randombytes() implementation and replaces it with a deterministic randombytes() based on surf (https://cr.yp.to/hash.html#surf). Resolves #260. As per pq-code-package/tsc#86, the consensus of the PQCP TCP is that a secure implementation of randombytes() should be provided by the software consuming code from the PQCP. For testing, we should use a deterministic randombytes() that no one is going to put into a production system. I propose to use the popular implementation by Daniel J. Bernstein based on surf (https://cr.yp.to/hash.html#surf). This implementation is clearly not secure which hopefully decreases the risk of someone just taking it. I called it notrandombytes.c and moved it into the test folder to decrease the risk of misuse. Signed-off-by: Matthias J. Kannwischer <[email protected]>
- Loading branch information
1 parent
ae85852
commit f359556
Showing
4 changed files
with
80 additions
and
93 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,78 @@ | ||
// SPDX-License-Identifier: LicenseRef-PD-hp OR CC0-1.0 OR 0BSD OR MIT-0 OR MIT | ||
// Based on https://cr.yp.to/papers.html#surf by Daniel. J. Bernstein | ||
|
||
/** | ||
* WARNING | ||
* | ||
* The randombytes() implementation in this file is for TESTING ONLY. | ||
* You MUST NOT use this implementation outside of testing. | ||
* | ||
*/ | ||
|
||
#include <stdint.h> | ||
#include "randombytes.h" | ||
|
||
static uint32_t seed[32] = {3, 1, 4, 1, 5, 9, 2, 6, 5, 3, 5, 8, 9, 7, 9, 3, | ||
2, 3, 8, 4, 6, 2, 6, 4, 3, 3, 8, 3, 2, 7, 9, 5}; | ||
static uint32_t in[12]; | ||
static uint32_t out[8]; | ||
static int32_t outleft = 0; | ||
|
||
#define ROTATE(x, b) (((x) << (b)) | ((x) >> (32 - (b)))) | ||
#define MUSH(i, b) x = t[i] += (((x ^ seed[i]) + sum) ^ ROTATE(x, b)); | ||
|
||
static void surf(void) { | ||
uint32_t t[12]; | ||
uint32_t x; | ||
uint32_t sum = 0; | ||
int32_t r; | ||
int32_t i; | ||
int32_t loop; | ||
|
||
for (i = 0; i < 12; ++i) { | ||
t[i] = in[i] ^ seed[12 + i]; | ||
} | ||
for (i = 0; i < 8; ++i) { | ||
out[i] = seed[24 + i]; | ||
} | ||
x = t[11]; | ||
for (loop = 0; loop < 2; ++loop) { | ||
for (r = 0; r < 16; ++r) { | ||
sum += 0x9e3779b9; | ||
MUSH(0, 5) | ||
MUSH(1, 7) | ||
MUSH(2, 9) | ||
MUSH(3, 13) | ||
MUSH(4, 5) | ||
MUSH(5, 7) | ||
MUSH(6, 9) | ||
MUSH(7, 13) | ||
MUSH(8, 5) | ||
MUSH(9, 7) | ||
MUSH(10, 9) | ||
MUSH(11, 13) | ||
} | ||
for (i = 0; i < 8; ++i) { | ||
out[i] ^= t[i + 4]; | ||
} | ||
} | ||
} | ||
|
||
void randombytes(uint8_t *buf, size_t n) { | ||
while (n > 0) { | ||
if (!outleft) { | ||
if (!++in[0]) { | ||
if (!++in[1]) { | ||
if (!++in[2]) { | ||
++in[3]; | ||
} | ||
} | ||
} | ||
surf(); | ||
outleft = 8; | ||
} | ||
*buf = (uint8_t)out[--outleft]; | ||
++buf; | ||
--n; | ||
} | ||
} |
File renamed without changes.