Botan 3.6.1
Crypto and TLS for C&
Botan::Kyber_KEM_Encryptor Class Referencefinal

#include <kyber_round3_impl.h>

Inheritance diagram for Botan::Kyber_KEM_Encryptor:
Botan::Kyber_KEM_Encryptor_Base Botan::PK_Ops::KEM_Encryption_with_KDF Botan::Kyber_KEM_Operation_Base Botan::PK_Ops::KEM_Encryption

Public Member Functions

size_t encapsulated_key_length () const override
 
void kem_encrypt (std::span< uint8_t > out_encapsulated_key, std::span< uint8_t > out_shared_key, RandomNumberGenerator &rng, size_t desired_shared_key_len, std::span< const uint8_t > salt) final
 
 Kyber_KEM_Encryptor (std::shared_ptr< const Kyber_PublicKeyInternal > key, std::string_view kdf)
 
void raw_kem_encrypt (std::span< uint8_t > out_encapsulated_key, std::span< uint8_t > out_shared_key, RandomNumberGenerator &rng) final
 
size_t raw_kem_shared_key_length () const override
 
size_t shared_key_length (size_t desired_shared_key_len) const final
 

Protected Member Functions

void encapsulate (StrongSpan< KyberCompressedCiphertext > out_encapsulated_key, StrongSpan< KyberSharedSecret > out_shared_key, RandomNumberGenerator &rng) override
 
const KyberConstantsmode () const override
 
const KyberPolyMatprecomputed_matrix_At () const
 

Detailed Description

Definition at line 20 of file kyber_round3_impl.h.

Constructor & Destructor Documentation

◆ Kyber_KEM_Encryptor()

Botan::Kyber_KEM_Encryptor::Kyber_KEM_Encryptor ( std::shared_ptr< const Kyber_PublicKeyInternal > key,
std::string_view kdf )
inline

Definition at line 22 of file kyber_round3_impl.h.

22 :
23 Kyber_KEM_Encryptor_Base(kdf, *key), m_public_key(std::move(key)) {}
Kyber_KEM_Encryptor_Base(std::string_view kdf, const Kyber_PublicKeyInternal &pk)

Member Function Documentation

◆ encapsulate()

void Botan::Kyber_KEM_Encryptor::encapsulate ( StrongSpan< KyberCompressedCiphertext > out_encapsulated_key,
StrongSpan< KyberSharedSecret > out_shared_key,
RandomNumberGenerator & rng )
overrideprotectedvirtual

Crystals Kyber (Version 3.01), Algorithm 8 (Kyber.CCAKEM.Enc())

Implements Botan::Kyber_KEM_Encryptor_Base.

Definition at line 22 of file kyber_round3_impl.cpp.

24 {
25 const auto& sym = m_public_key->mode().symmetric_primitives();
26
27 const auto seed_m = rng.random_vec<KyberMessage>(KyberConstants::SEED_BYTES);
28 CT::poison(seed_m);
29
30 const auto m = sym.H(seed_m);
31 const auto [K_bar, r] = sym.G(m, m_public_key->H_public_key_bits_raw());
32 m_public_key->indcpa_encrypt(out_encapsulated_key, m, r, precomputed_matrix_At());
33
34 sym.KDF(out_shared_key, K_bar, sym.H(out_encapsulated_key));
35 CT::unpoison_all(out_shared_key, out_encapsulated_key);
36}
static constexpr size_t SEED_BYTES
const KyberPolyMat & precomputed_matrix_At() const
constexpr void unpoison_all(Ts &&... ts)
Definition ct_utils.h:201
constexpr void poison(const T *p, size_t n)
Definition ct_utils.h:53
Strong< secure_vector< uint8_t >, struct KyberMessage_ > KyberMessage
Random message value to be encrypted by the CPA-secure Kyber encryption scheme.
Definition kyber_types.h:45

References Botan::CT::poison(), Botan::Kyber_KEM_Operation_Base::precomputed_matrix_At(), Botan::RandomNumberGenerator::random_vec(), Botan::KyberConstants::SEED_BYTES, and Botan::CT::unpoison_all().

◆ encapsulated_key_length()

size_t Botan::Kyber_KEM_Encryptor_Base::encapsulated_key_length ( ) const
inlineoverridevirtualinherited

Implements Botan::PK_Ops::KEM_Encryption.

Definition at line 37 of file kyber_encaps_base.h.

37{ return mode().ciphertext_bytes(); }
size_t ciphertext_bytes() const
byte length of an encoded ciphertext
virtual const KyberConstants & mode() const =0

References Botan::KyberConstants::ciphertext_bytes(), and Botan::Kyber_KEM_Encryptor_Base::mode().

◆ kem_encrypt()

void Botan::PK_Ops::KEM_Encryption_with_KDF::kem_encrypt ( std::span< uint8_t > out_encapsulated_key,
std::span< uint8_t > out_shared_key,
RandomNumberGenerator & rng,
size_t desired_shared_key_len,
std::span< const uint8_t > salt )
finalvirtualinherited

Implements Botan::PK_Ops::KEM_Encryption.

Definition at line 184 of file pk_ops.cpp.

188 {
189 BOTAN_ARG_CHECK(salt.empty() || m_kdf, "PK_KEM_Encryptor::encrypt requires a KDF to use a salt");
190 BOTAN_ASSERT_NOMSG(out_encapsulated_key.size() == encapsulated_key_length());
191
192 if(m_kdf) {
194 out_shared_key.size(), desired_shared_key_len, "KDF output length and shared key length match");
195
197 this->raw_kem_encrypt(out_encapsulated_key, raw_shared, rng);
198 m_kdf->derive_key(out_shared_key, raw_shared, salt, {});
199 } else {
200 BOTAN_ASSERT_EQUAL(out_shared_key.size(), raw_kem_shared_key_length(), "Shared key has raw KEM output length");
201 this->raw_kem_encrypt(out_encapsulated_key, out_shared_key, rng);
202 }
203}
#define BOTAN_ASSERT_NOMSG(expr)
Definition assert.h:59
#define BOTAN_ASSERT_EQUAL(expr1, expr2, assertion_made)
Definition assert.h:68
#define BOTAN_ARG_CHECK(expr, msg)
Definition assert.h:29
virtual size_t raw_kem_shared_key_length() const =0
virtual void raw_kem_encrypt(std::span< uint8_t > out_encapsulated_key, std::span< uint8_t > out_raw_shared_key, RandomNumberGenerator &rng)=0
virtual size_t encapsulated_key_length() const =0
std::vector< T, secure_allocator< T > > secure_vector
Definition secmem.h:61

References BOTAN_ARG_CHECK, BOTAN_ASSERT_EQUAL, and BOTAN_ASSERT_NOMSG.

◆ mode()

const KyberConstants & Botan::Kyber_KEM_Encryptor::mode ( ) const
inlineoverrideprotectedvirtual

Implements Botan::Kyber_KEM_Encryptor_Base.

Definition at line 30 of file kyber_round3_impl.h.

30{ return m_public_key->mode(); }

◆ precomputed_matrix_At()

const KyberPolyMat & Botan::Kyber_KEM_Operation_Base::precomputed_matrix_At ( ) const
inlineprotectedinherited

◆ raw_kem_encrypt()

void Botan::Kyber_KEM_Encryptor_Base::raw_kem_encrypt ( std::span< uint8_t > out_encapsulated_key,
std::span< uint8_t > out_shared_key,
RandomNumberGenerator & rng )
inlinefinalvirtualinherited

Implements Botan::PK_Ops::KEM_Encryption_with_KDF.

Definition at line 39 of file kyber_encaps_base.h.

41 {
42 encapsulate(StrongSpan<KyberCompressedCiphertext>(out_encapsulated_key),
43 StrongSpan<KyberSharedSecret>(out_shared_key),
44 rng);
45 }
virtual void encapsulate(StrongSpan< KyberCompressedCiphertext > out_encapsulated_key, StrongSpan< KyberSharedSecret > out_shared_key, RandomNumberGenerator &rng)=0

References Botan::Kyber_KEM_Encryptor_Base::encapsulate().

◆ raw_kem_shared_key_length()

size_t Botan::Kyber_KEM_Encryptor_Base::raw_kem_shared_key_length ( ) const
inlineoverridevirtualinherited

Implements Botan::PK_Ops::KEM_Encryption_with_KDF.

Definition at line 35 of file kyber_encaps_base.h.

35{ return mode().shared_key_bytes(); }
constexpr size_t shared_key_bytes() const
byte length of the shared key

References Botan::Kyber_KEM_Encryptor_Base::mode(), and Botan::KyberConstants::shared_key_bytes().

◆ shared_key_length()

size_t Botan::PK_Ops::KEM_Encryption_with_KDF::shared_key_length ( size_t desired_shared_key_len) const
finalvirtualinherited

Implements Botan::PK_Ops::KEM_Encryption.

Definition at line 176 of file pk_ops.cpp.

176 {
177 if(m_kdf) {
178 return desired_shared_key_len;
179 } else {
180 return this->raw_kem_shared_key_length();
181 }
182}

The documentation for this class was generated from the following files: