83d1939edd8eda44a58d67aa540e1be6a79a54f4
[strongswan.git] / src / libstrongswan / plugins / ntru / ntru_trits.c
1 /*
2 * Copyright (C) 2013-2014 Andreas Steffen
3 * HSR Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "ntru_trits.h"
17 #include "ntru_convert.h"
18
19 #include <crypto/mgf1/mgf1.h>
20 #include <utils/debug.h>
21 #include <utils/test.h>
22
23 typedef struct private_ntru_trits_t private_ntru_trits_t;
24
25 /**
26 * Private data of an ntru_trits_t object.
27 */
28 struct private_ntru_trits_t {
29
30 /**
31 * Public ntru_trits_t interface.
32 */
33 ntru_trits_t public;
34
35 /**
36 * Size of the trits array
37 */
38 size_t trits_len;
39
40 /**
41 * Array containing a trit per octet
42 */
43 uint8_t *trits;
44
45 };
46
47 METHOD(ntru_trits_t, get_size, size_t,
48 private_ntru_trits_t *this)
49 {
50 return this->trits_len;
51 }
52
53 METHOD(ntru_trits_t, get_trits, uint8_t*,
54 private_ntru_trits_t *this)
55 {
56 return this->trits;
57 }
58
59 METHOD(ntru_trits_t, destroy, void,
60 private_ntru_trits_t *this)
61 {
62 memwipe(this->trits, this->trits_len);
63 free(this->trits);
64 free(this);
65 }
66
67 /*
68 * Described in header.
69 */
70 ntru_trits_t *ntru_trits_create(size_t len, hash_algorithm_t alg, chunk_t seed)
71 {
72 private_ntru_trits_t *this;
73 uint8_t octets[HASH_SIZE_SHA512], buf[5], *trits;
74 size_t hash_len, octet_count = 0, trits_needed, i;
75 mgf1_t *mgf1;
76
77 DBG2(DBG_LIB, "MGF1 is seeded with %u bytes", seed.len);
78 mgf1 = mgf1_create(alg, seed, TRUE);
79 if (!mgf1)
80 {
81 return NULL;
82 }
83 i = hash_len = mgf1->get_hash_size(mgf1);
84
85 INIT(this,
86 .public = {
87 .get_size = _get_size,
88 .get_trits = _get_trits,
89 .destroy = _destroy,
90 },
91 .trits_len = len,
92 .trits = malloc(len),
93 );
94
95 trits = this->trits;
96 trits_needed = this->trits_len;
97
98 while (trits_needed > 0)
99 {
100 if (i == hash_len)
101 {
102 /* get another block from MGF1 */
103 if (!mgf1->get_mask(mgf1, hash_len, octets))
104 {
105 mgf1->destroy(mgf1);
106 destroy(this);
107 return NULL;
108 }
109 octet_count += hash_len;
110 i = 0;
111 }
112 if (octets[i] < 243) /* 243 = 3^5 */
113 {
114 ntru_octet_2_trits(octets[i], (trits_needed < 5) ? buf : trits);
115 if (trits_needed < 5)
116 {
117 memcpy(trits, buf, trits_needed);
118 break;
119 }
120 trits += 5;
121 trits_needed -= 5;
122 }
123 i++;
124 }
125 DBG2(DBG_LIB, "MGF1 generates %u octets to extract %u trits",
126 octet_count, len);
127 mgf1->destroy(mgf1);
128
129 return &this->public;
130 }
131
132 EXPORT_FUNCTION_FOR_TESTS(ntru, ntru_trits_create);