Botan  2.11.0
Crypto and TLS for C++11
chacha.h
Go to the documentation of this file.
1 /*
2 * ChaCha20
3 * (C) 2014,2018 Jack Lloyd
4 *
5 * Botan is released under the Simplified BSD License (see license.txt)
6 */
7 
8 #ifndef BOTAN_CHACHA_H_
9 #define BOTAN_CHACHA_H_
10 
11 #include <botan/stream_cipher.h>
12 
13 namespace Botan {
14 
15 /**
16 * DJB's ChaCha (https://cr.yp.to/chacha.html)
17 */
18 class BOTAN_PUBLIC_API(2,0) ChaCha final : public StreamCipher
19  {
20  public:
21  /**
22  * @param rounds number of rounds
23  * @note Currently only 8, 12 or 20 rounds are supported, all others
24  * will throw an exception
25  */
26  explicit ChaCha(size_t rounds = 20);
27 
28  std::string provider() const override;
29 
30  void cipher(const uint8_t in[], uint8_t out[], size_t length) override;
31 
32  void write_keystream(uint8_t out[], size_t len) override;
33 
34  void set_iv(const uint8_t iv[], size_t iv_len) override;
35 
36  /*
37  * ChaCha accepts 0, 8, 12 or 24 byte IVs.
38  * The default IV is a 8 zero bytes.
39  * An IV of length 0 is treated the same as the default zero IV.
40  * An IV of length 24 selects XChaCha mode
41  */
42  bool valid_iv_length(size_t iv_len) const override;
43 
44  size_t default_iv_length() const override;
45 
46  Key_Length_Specification key_spec() const override;
47 
48  void clear() override;
49 
50  StreamCipher* clone() const override;
51 
52  std::string name() const override;
53 
54  void seek(uint64_t offset) override;
55 
56  private:
57  void key_schedule(const uint8_t key[], size_t key_len) override;
58 
59  void initialize_state();
60 
61  void chacha_x8(uint8_t output[64*8], uint32_t state[16], size_t rounds);
62 
63 #if defined(BOTAN_HAS_CHACHA_SIMD32)
64  void chacha_simd32_x4(uint8_t output[64*4], uint32_t state[16], size_t rounds);
65 #endif
66 
67 #if defined(BOTAN_HAS_CHACHA_AVX2)
68  void chacha_avx2_x8(uint8_t output[64*8], uint32_t state[16], size_t rounds);
69 #endif
70 
71  size_t m_rounds;
72  secure_vector<uint32_t> m_key;
73  secure_vector<uint32_t> m_state;
74  secure_vector<uint8_t> m_buffer;
75  size_t m_position = 0;
76  };
77 
78 }
79 
80 #endif
std::string size_t len
Definition: pk_keys.h:305
bool BigInt BigInt size_t size_t const std::vector< uint8_t > size_t offset
Definition: numthry.h:271
int(* final)(unsigned char *, CTX *)
void const uint8_t in[]
Definition: mgf1.h:26
char * name
Definition: ffi.h:330
void BlockCipher * cipher
Definition: package.h:29
class BOTAN_PUBLIC_API(2, 11) Argon2 final class BOTAN_PUBLIC_API(2, 11) Argon2_Family final void size_t const char size_t const uint8_t size_t const uint8_t key[]
Definition: argon2.h:87
Definition: alg_id.cpp:13
uint8_t out[]
Definition: pbkdf2.h:19
class BOTAN_PUBLIC_API(2, 0) AlgorithmIdentifier final bool BOTAN_PUBLIC_API(2, 0) operator
Name Constraints.
Definition: asn1_obj.h:66
void BlockCipher const uint8_t size_t uint8_t output[]
Definition: package.h:29
class BOTAN_PUBLIC_API(2, 11) Argon2 final class BOTAN_PUBLIC_API(2, 11) Argon2_Family final void size_t const char size_t const uint8_t size_t const uint8_t size_t key_len
Definition: argon2.h:87
const RSA_PrivateKey & m_key
Definition: rsa.cpp:296