Botan 3.13.0
Crypto and TLS for C&
chacha.cpp
Go to the documentation of this file.
1/*
2* ChaCha
3* (C) 2014,2018,2023 Jack Lloyd
4*
5* Botan is released under the Simplified BSD License (see license.txt)
6*/
7
8#include <botan/internal/chacha.h>
9
10#include <botan/exceptn.h>
11#include <botan/internal/fmt.h>
12#include <botan/internal/loadstor.h>
13#include <botan/internal/rotate.h>
14
15#if defined(BOTAN_HAS_CPUID)
16 #include <botan/internal/cpuid.h>
17#endif
18
19namespace Botan {
20
21namespace {
22
23/*
24* RFC 8439 defines ChaCha with 96-bit nonces by stealing one of the
25* words used for the block counter. With 64-bit nonces, the block
26* counter is also 64 bits and practically not exhaustible.
27*/
28constexpr uint64_t chacha_96bit_nonce_cap = uint64_t{1} << 38;
29
30inline void chacha_quarter_round(uint32_t& a, uint32_t& b, uint32_t& c, uint32_t& d) {
31 a += b;
32 d ^= a;
33 d = rotl<16>(d);
34 c += d;
35 b ^= c;
36 b = rotl<12>(b);
37 a += b;
38 d ^= a;
39 d = rotl<8>(d);
40 c += d;
41 b ^= c;
42 b = rotl<7>(b);
43}
44
45/*
46* Generate HChaCha cipher stream (for XChaCha IV setup)
47*/
48void hchacha(uint32_t output[8], const uint32_t input[16], size_t rounds) {
49 BOTAN_ASSERT(rounds % 2 == 0, "Valid rounds");
50
51 uint32_t x00 = input[0];
52 uint32_t x01 = input[1];
53 uint32_t x02 = input[2];
54 uint32_t x03 = input[3];
55 uint32_t x04 = input[4];
56 uint32_t x05 = input[5];
57 uint32_t x06 = input[6];
58 uint32_t x07 = input[7];
59 uint32_t x08 = input[8];
60 uint32_t x09 = input[9];
61 uint32_t x10 = input[10];
62 uint32_t x11 = input[11];
63 uint32_t x12 = input[12];
64 uint32_t x13 = input[13];
65 uint32_t x14 = input[14];
66 uint32_t x15 = input[15];
67
68 for(size_t i = 0; i != rounds / 2; ++i) {
69 chacha_quarter_round(x00, x04, x08, x12);
70 chacha_quarter_round(x01, x05, x09, x13);
71 chacha_quarter_round(x02, x06, x10, x14);
72 chacha_quarter_round(x03, x07, x11, x15);
73
74 chacha_quarter_round(x00, x05, x10, x15);
75 chacha_quarter_round(x01, x06, x11, x12);
76 chacha_quarter_round(x02, x07, x08, x13);
77 chacha_quarter_round(x03, x04, x09, x14);
78 }
79
80 output[0] = x00;
81 output[1] = x01;
82 output[2] = x02;
83 output[3] = x03;
84 output[4] = x12;
85 output[5] = x13;
86 output[6] = x14;
87 output[7] = x15;
88}
89
90} // namespace
91
92ChaCha::ChaCha(size_t rounds) : m_rounds(rounds) {
93 BOTAN_ARG_CHECK(m_rounds == 8 || m_rounds == 12 || m_rounds == 20, "ChaCha only supports 8, 12 or 20 rounds");
94}
95
96size_t ChaCha::parallelism() {
97#if defined(BOTAN_HAS_CHACHA_AVX512)
99 return 16;
100 }
101#endif
102
103#if defined(BOTAN_HAS_CHACHA_AVX2)
105 return 8;
106 }
107#endif
108
109 return 4;
110}
111
112std::string ChaCha::provider() const {
113#if defined(BOTAN_HAS_CHACHA_AVX512)
114 if(auto feat = CPUID::check(CPUID::Feature::AVX512)) {
115 return *feat;
116 }
117#endif
118
119#if defined(BOTAN_HAS_CHACHA_AVX2)
120 if(auto feat = CPUID::check(CPUID::Feature::AVX2)) {
121 return *feat;
122 }
123#endif
124
125#if defined(BOTAN_HAS_CHACHA_SIMD32)
126 if(auto feat = CPUID::check(CPUID::Feature::SIMD_4X32)) {
127 return *feat;
128 }
129#endif
130
131 return "base";
132}
133
134void ChaCha::chacha(uint8_t output[], size_t output_blocks, uint32_t state[16], size_t rounds) {
135 BOTAN_ASSERT(rounds % 2 == 0, "Valid rounds");
136
137#if defined(BOTAN_HAS_CHACHA_AVX512)
139 while(output_blocks >= 16) {
140 ChaCha::chacha_avx512_x16(output, state, rounds);
141 output += 16 * 64;
142 output_blocks -= 16;
143 }
144 }
145#endif
146
147#if defined(BOTAN_HAS_CHACHA_AVX2)
149 while(output_blocks >= 8) {
150 ChaCha::chacha_avx2_x8(output, state, rounds);
151 output += 8 * 64;
152 output_blocks -= 8;
153 }
154 }
155#endif
156
157#if defined(BOTAN_HAS_CHACHA_SIMD32)
159 while(output_blocks >= 4) {
160 ChaCha::chacha_simd32_x4(output, state, rounds);
161 output += 4 * 64;
162 output_blocks -= 4;
163 }
164 }
165#endif
166
167 // TODO interleave rounds
168 for(size_t i = 0; i != output_blocks; ++i) {
169 uint32_t x00 = state[0];
170 uint32_t x01 = state[1];
171 uint32_t x02 = state[2];
172 uint32_t x03 = state[3];
173 uint32_t x04 = state[4];
174 uint32_t x05 = state[5];
175 uint32_t x06 = state[6];
176 uint32_t x07 = state[7];
177 uint32_t x08 = state[8];
178 uint32_t x09 = state[9];
179 uint32_t x10 = state[10];
180 uint32_t x11 = state[11];
181 uint32_t x12 = state[12];
182 uint32_t x13 = state[13];
183 uint32_t x14 = state[14];
184 uint32_t x15 = state[15];
185
186 for(size_t r = 0; r != rounds / 2; ++r) {
187 chacha_quarter_round(x00, x04, x08, x12);
188 chacha_quarter_round(x01, x05, x09, x13);
189 chacha_quarter_round(x02, x06, x10, x14);
190 chacha_quarter_round(x03, x07, x11, x15);
191
192 chacha_quarter_round(x00, x05, x10, x15);
193 chacha_quarter_round(x01, x06, x11, x12);
194 chacha_quarter_round(x02, x07, x08, x13);
195 chacha_quarter_round(x03, x04, x09, x14);
196 }
197
198 x00 += state[0];
199 x01 += state[1];
200 x02 += state[2];
201 x03 += state[3];
202 x04 += state[4];
203 x05 += state[5];
204 x06 += state[6];
205 x07 += state[7];
206 x08 += state[8];
207 x09 += state[9];
208 x10 += state[10];
209 x11 += state[11];
210 x12 += state[12];
211 x13 += state[13];
212 x14 += state[14];
213 x15 += state[15];
214
215 store_le(x00, output + 64 * i + 4 * 0);
216 store_le(x01, output + 64 * i + 4 * 1);
217 store_le(x02, output + 64 * i + 4 * 2);
218 store_le(x03, output + 64 * i + 4 * 3);
219 store_le(x04, output + 64 * i + 4 * 4);
220 store_le(x05, output + 64 * i + 4 * 5);
221 store_le(x06, output + 64 * i + 4 * 6);
222 store_le(x07, output + 64 * i + 4 * 7);
223 store_le(x08, output + 64 * i + 4 * 8);
224 store_le(x09, output + 64 * i + 4 * 9);
225 store_le(x10, output + 64 * i + 4 * 10);
226 store_le(x11, output + 64 * i + 4 * 11);
227 store_le(x12, output + 64 * i + 4 * 12);
228 store_le(x13, output + 64 * i + 4 * 13);
229 store_le(x14, output + 64 * i + 4 * 14);
230 store_le(x15, output + 64 * i + 4 * 15);
231
232 state[12]++;
233 if(state[12] == 0) {
234 state[13] += 1;
235 }
236 }
237}
238
239/*
240* Combine cipher stream with message
241*/
242void ChaCha::cipher_bytes(const uint8_t in[], uint8_t out[], size_t length) {
244
245 if(m_iv_length == 12) {
246 if(length > m_bytes_remaining) {
247 throw Invalid_State("ChaCha 96-bit nonce keystream exhausted");
248 }
249 m_bytes_remaining -= length;
250 }
251
252 while(length >= m_buffer.size() - m_position) {
253 const size_t available = m_buffer.size() - m_position;
254
255 xor_buf(out, in, &m_buffer[m_position], available);
256 chacha(m_buffer.data(), m_buffer.size() / 64, m_state.data(), m_rounds);
257
258 length -= available;
259 in += available;
260 out += available;
261 m_position = 0;
262 }
263
264 xor_buf(out, in, &m_buffer[m_position], length);
265
266 m_position += length;
267}
268
269void ChaCha::generate_keystream(uint8_t out[], size_t length) {
271
272 if(m_iv_length == 12) {
273 if(length > m_bytes_remaining) {
274 throw Invalid_State("ChaCha 96-bit nonce keystream exhausted");
275 }
276 m_bytes_remaining -= length;
277 }
278
279 while(length >= m_buffer.size() - m_position) {
280 const size_t available = m_buffer.size() - m_position;
281
282 // TODO: this could write directly to the output buffer
283 // instead of bouncing it through m_buffer first
284 copy_mem(out, &m_buffer[m_position], available);
285 chacha(m_buffer.data(), m_buffer.size() / 64, m_state.data(), m_rounds);
286
287 length -= available;
288 out += available;
289 m_position = 0;
290 }
291
292 copy_mem(out, &m_buffer[m_position], length);
293
294 m_position += length;
295}
296
297void ChaCha::initialize_state() {
298 static const uint32_t TAU[] = {0x61707865, 0x3120646e, 0x79622d36, 0x6b206574};
299
300 static const uint32_t SIGMA[] = {0x61707865, 0x3320646e, 0x79622d32, 0x6b206574};
301
302 m_state[4] = m_key[0];
303 m_state[5] = m_key[1];
304 m_state[6] = m_key[2];
305 m_state[7] = m_key[3];
306
307 if(m_key.size() == 4) {
308 m_state[0] = TAU[0];
309 m_state[1] = TAU[1];
310 m_state[2] = TAU[2];
311 m_state[3] = TAU[3];
312
313 m_state[8] = m_key[0];
314 m_state[9] = m_key[1];
315 m_state[10] = m_key[2];
316 m_state[11] = m_key[3];
317 } else {
318 m_state[0] = SIGMA[0];
319 m_state[1] = SIGMA[1];
320 m_state[2] = SIGMA[2];
321 m_state[3] = SIGMA[3];
322
323 m_state[8] = m_key[4];
324 m_state[9] = m_key[5];
325 m_state[10] = m_key[6];
326 m_state[11] = m_key[7];
327 }
328
329 m_state[12] = 0;
330 m_state[13] = 0;
331 m_state[14] = 0;
332 m_state[15] = 0;
333
334 m_position = 0;
335}
336
338 return !m_state.empty();
339}
340
341size_t ChaCha::buffer_size() const {
342 return 64;
343}
344
345/*
346* ChaCha Key Schedule
347*/
348void ChaCha::key_schedule(std::span<const uint8_t> key) {
349 m_key.resize(key.size() / 4);
350 load_le<uint32_t>(m_key.data(), key.data(), m_key.size());
351
352 m_state.resize(16);
353
354 const size_t chacha_block = 64;
355 m_buffer.resize(parallelism() * chacha_block);
356
357 set_iv(nullptr, 0);
358}
359
361 return 24;
362}
363
367
368std::unique_ptr<StreamCipher> ChaCha::new_object() const {
369 return std::make_unique<ChaCha>(m_rounds);
370}
371
372bool ChaCha::valid_iv_length(size_t iv_len) const {
373 return (iv_len == 0 || iv_len == 8 || iv_len == 12 || iv_len == 24);
374}
375
376void ChaCha::set_iv_bytes(const uint8_t iv[], size_t length) {
378
379 if(!valid_iv_length(length)) {
380 throw Invalid_IV_Length(name(), length);
381 }
382
383 initialize_state();
384
385 if(length == 0) {
386 // Treat zero length IV same as an all-zero IV
387 m_state[14] = 0;
388 m_state[15] = 0;
389 } else if(length == 8) {
390 m_state[14] = load_le<uint32_t>(iv, 0);
391 m_state[15] = load_le<uint32_t>(iv, 1);
392 } else if(length == 12) {
393 m_state[13] = load_le<uint32_t>(iv, 0);
394 m_state[14] = load_le<uint32_t>(iv, 1);
395 m_state[15] = load_le<uint32_t>(iv, 2);
396 } else if(length == 24) {
397 m_state[12] = load_le<uint32_t>(iv, 0);
398 m_state[13] = load_le<uint32_t>(iv, 1);
399 m_state[14] = load_le<uint32_t>(iv, 2);
400 m_state[15] = load_le<uint32_t>(iv, 3);
401
403 hchacha(hc.data(), m_state.data(), m_rounds);
404
405 m_state[4] = hc[0];
406 m_state[5] = hc[1];
407 m_state[6] = hc[2];
408 m_state[7] = hc[3];
409 m_state[8] = hc[4];
410 m_state[9] = hc[5];
411 m_state[10] = hc[6];
412 m_state[11] = hc[7];
413 m_state[12] = 0;
414 m_state[13] = 0;
415 m_state[14] = load_le<uint32_t>(iv, 4);
416 m_state[15] = load_le<uint32_t>(iv, 5);
417 }
418
419 m_iv_length = length;
420 m_state13_post_iv = m_state[13];
421 if(length == 12) {
422 m_bytes_remaining = chacha_96bit_nonce_cap;
423 }
424
425 chacha(m_buffer.data(), m_buffer.size() / 64, m_state.data(), m_rounds);
426 m_position = 0;
427}
428
430 zap(m_key);
431 zap(m_state);
432 zap(m_buffer);
433 m_position = 0;
434 m_iv_length = 0;
435 m_state13_post_iv = 0;
436 m_bytes_remaining = 0;
437}
438
439std::optional<uint64_t> ChaCha::remaining_keystream_bytes() const {
440 if(!has_keying_material() || m_iv_length != 12) {
441 return std::nullopt;
442 }
443 return m_bytes_remaining;
444}
445
446std::string ChaCha::name() const {
447 return fmt("ChaCha({})", m_rounds);
448}
449
450void ChaCha::seek(uint64_t offset) {
452
453 const uint64_t block = offset / 64;
454
455 if(m_iv_length == 12) {
456 // 96 bit nonce implies a 32-bit counter; prevent seeking beyond that
457 if((block >> 32) != 0) {
458 throw Invalid_Argument("ChaCha::seek with 96-bit nonce limited to 2^32 blocks (256 GiB)");
459 }
460 m_state[12] = static_cast<uint32_t>(block);
461 m_state[13] = m_state13_post_iv;
462 m_bytes_remaining = chacha_96bit_nonce_cap - offset;
463 } else {
464 // 64-bit block counter spanning state words 12 and 13.
465 m_state[12] = static_cast<uint32_t>(block);
466 m_state[13] = m_state13_post_iv + static_cast<uint32_t>(block >> 32);
467 }
468
469 chacha(m_buffer.data(), m_buffer.size() / 64, m_state.data(), m_rounds);
470 m_position = offset % 64;
471}
472} // namespace Botan
#define BOTAN_ARG_CHECK(expr, msg)
Definition assert.h:33
#define BOTAN_ASSERT(expr, assertion_made)
Definition assert.h:62
static std::optional< std::string > check(CPUID::Feature feat)
Definition cpuid.h:67
static bool has(CPUID::Feature feat)
Definition cpuid.h:94
void clear() override
Definition chacha.cpp:429
std::string name() const override
Definition chacha.cpp:446
size_t buffer_size() const override
Definition chacha.cpp:341
std::optional< uint64_t > remaining_keystream_bytes() const override
Definition chacha.cpp:439
std::unique_ptr< StreamCipher > new_object() const override
Definition chacha.cpp:368
Key_Length_Specification key_spec() const override
Definition chacha.cpp:364
bool valid_iv_length(size_t iv_len) const override
Definition chacha.cpp:372
size_t default_iv_length() const override
Definition chacha.cpp:360
std::string provider() const override
Definition chacha.cpp:112
ChaCha(size_t rounds=20)
Definition chacha.cpp:92
bool has_keying_material() const override
Definition chacha.cpp:337
void seek(uint64_t offset) override
Definition chacha.cpp:450
void set_iv(const uint8_t iv[], size_t iv_len)
void assert_key_material_set() const
Definition sym_algo.h:180
void zap(std::vector< T, Alloc > &vec)
Definition secmem.h:261
std::string fmt(std::string_view format, const T &... args)
Definition fmt.h:53
constexpr void copy_mem(T *out, const T *in, size_t n)
Definition mem_ops.h:144
constexpr auto store_le(ParamTs &&... params)
Definition loadstor.h:736
BOTAN_FORCE_INLINE constexpr T rotl(T input)
Definition rotate.h:23
constexpr auto load_le(ParamTs &&... params)
Definition loadstor.h:495
constexpr void xor_buf(ranges::contiguous_output_range< uint8_t > auto &&out, ranges::contiguous_range< uint8_t > auto &&in)
Definition mem_ops.h:403
std::vector< T, secure_allocator< T > > secure_vector
Definition secmem.h:128