Oregami
Repositories/oxedyne/fe2o3

oxedyne/fe2o3/fe2o3_crypto/src/c/SABER_indcpa.c

2.6 KiB, 1 run

created by r1870400018:171, which is this file's identity for as long as the history lasts, whatever it is later renamed to

download · who wrote it · its history

1#include <string.h>
2#include <stdint.h>
3#include "SABER_indcpa.h"
4#include "poly.h"
5#include "pack_unpack.h"
6#include "poly_mul.c"
7#include "rng.h"
8#include "fips202.h"
9#include "SABER_params.h"
10
11#define h1 (1 << (SABER_EQ - SABER_EP - 1))
12#define h2 ((1 << (SABER_EP - 2)) - (1 << (SABER_EP - SABER_ET - 1)) + (1 << (SABER_EQ - SABER_EP - 1)))
13
14void indcpa_kem_keypair(uint8_t pk[SABER_INDCPA_PUBLICKEYBYTES], uint8_t sk[SABER_INDCPA_SECRETKEYBYTES])
15{
16 uint16_t A[SABER_L][SABER_L][SABER_N];
17 uint16_t s[SABER_L][SABER_N];
18 uint16_t b[SABER_L][SABER_N] = {0};
19
20 uint8_t seed_A[SABER_SEEDBYTES];
21 uint8_t seed_s[SABER_NOISE_SEEDBYTES];
22 int i, j, k;
23
24 randombytes(seed_A, SABER_SEEDBYTES);
25
26 saber_shake128(seed_A, SABER_SEEDBYTES, seed_A, SABER_SEEDBYTES); // for not revealing system RNG state
27 randombytes(seed_s, SABER_NOISE_SEEDBYTES);
28
29 GenMatrix(A, seed_A);
30 GenSecret(s, seed_s);
31 MatrixVectorMul(A, s, b, 1);
32
33 for (i = 0; i < SABER_L; i++)
34 {
35 for (j = 0; j < SABER_N; j++)
36 {
37 b[i][j] = (b[i][j] + h1) >> (SABER_EQ - SABER_EP);
38 }
39 }
40
41 POLVECq2BS(sk, s);
42 POLVECp2BS(pk, b);
43 memcpy(pk + SABER_POLYVECCOMPRESSEDBYTES, seed_A, sizeof(seed_A));
44}
45
46void indcpa_kem_enc(const uint8_t m[SABER_KEYBYTES], const uint8_t seed_sp[SABER_NOISE_SEEDBYTES], const uint8_t pk[SABER_INDCPA_PUBLICKEYBYTES], uint8_t ciphertext[SABER_BYTES_CCA_DEC])
47{
48 uint16_t A[SABER_L][SABER_L][SABER_N];
49 uint16_t sp[SABER_L][SABER_N];
50 uint16_t bp[SABER_L][SABER_N] = {0};
51 uint16_t vp[SABER_N] = {0};
52 uint16_t mp[SABER_N];
53 uint16_t b[SABER_L][SABER_N];
54 int i, j;
55 const uint8_t *seed_A = pk + SABER_POLYVECCOMPRESSEDBYTES;
56
57 GenMatrix(A, seed_A);
58 GenSecret(sp, seed_sp);
59 MatrixVectorMul(A, sp, bp, 0);
60
61 for (i = 0; i < SABER_L; i++)
62 {
63 for (j = 0; j < SABER_N; j++)
64 {
65 bp[i][j] = (bp[i][j] + h1) >> (SABER_EQ - SABER_EP);
66 }
67 }
68
69 POLVECp2BS(ciphertext, bp);
70 BS2POLVECp(pk, b);
71 InnerProd(b, sp, vp);
72
73 BS2POLmsg(m, mp);
74
75 for (j = 0; j < SABER_N; j++)
76 {
77 vp[j] = (vp[j] - (mp[j] << (SABER_EP - 1)) + h1) >> (SABER_EP - SABER_ET);
78 }
79
80 POLT2BS(ciphertext + SABER_POLYVECCOMPRESSEDBYTES, vp);
81}
82
83void indcpa_kem_dec(const uint8_t sk[SABER_INDCPA_SECRETKEYBYTES], const uint8_t ciphertext[SABER_BYTES_CCA_DEC], uint8_t m[SABER_KEYBYTES])
84{
85
86 uint16_t s[SABER_L][SABER_N];
87 uint16_t b[SABER_L][SABER_N];
88 uint16_t v[SABER_N] = {0};
89 uint16_t cm[SABER_N];
90 int i;
91
92 BS2POLVECq(sk, s);
93 BS2POLVECp(ciphertext, b);
94 InnerProd(b, s, v);
95 BS2POLT(ciphertext + SABER_POLYVECCOMPRESSEDBYTES, cm);
96
97 for (i = 0; i < SABER_N; i++)
98 {
99 v[i] = (v[i] + h2 - (cm[i] << (SABER_EP - SABER_ET))) >> (SABER_EP - 1);
100 }
101
102 POLmsg2BS(m, v);
103}