From dad6412c0d224ec883a26ee279ac1e58feb296c6 Mon Sep 17 00:00:00 2001 From: Duc Tri Nguyen Date: Tue, 2 Apr 2024 10:24:18 -0400 Subject: [PATCH 01/68] Initial addition of sig_stfl API and dummy XMSS variant Signed-off-by: Duc Tri Nguyen --- .CMake/alg_support.cmake | 25 ++- CMakeLists.txt | 6 +- src/CMakeLists.txt | 8 + src/oqs.h | 1 + src/oqsconfig.h.cmake | 3 + src/sig_stfl/sig_stfl.c | 93 +++++++++++ src/sig_stfl/sig_stfl.h | 199 +++++++++++++++++++++++ src/sig_stfl/xmss/CMakeLists.txt | 5 + src/sig_stfl/xmss/sig_stfl_xmss.h | 23 +++ src/sig_stfl/xmss/sig_stfl_xmss_sha256.c | 43 +++++ 10 files changed, 404 insertions(+), 2 deletions(-) create mode 100644 src/sig_stfl/sig_stfl.c create mode 100644 src/sig_stfl/sig_stfl.h create mode 100644 src/sig_stfl/xmss/CMakeLists.txt create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss.h create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_sha256.c diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index 3bdb103af7..2bc0079b0d 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -495,7 +495,30 @@ if(OQS_DIST_X86_64_BUILD OR (OQS_USE_AVX2_INSTRUCTIONS)) endif() endif() -##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ENABLE_BY_ALG_CONDITIONAL_END +##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ENABLE_BY_ALG_END + +option(OQS_ENABLE_SIG_STFL_XMSS "Enable XMSS algorithm family" ON) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) + +if((OQS_MINIMAL_BUILD STREQUAL "ON")) + message(FATAL_ERROR "OQS_MINIMAL_BUILD option ${OQS_MINIMAL_BUILD} no longer supported") +endif() + +if(NOT DEFINED OQS_ALGS_ENABLED OR OQS_ALGS_ENABLED STREQUAL "") + set(OQS_ALGS_ENABLED "All") +endif() + +if(NOT ((OQS_MINIMAL_BUILD STREQUAL "") OR (OQS_MINIMAL_BUILD STREQUAL "OFF"))) + filter_algs("${OQS_MINIMAL_BUILD}") +elseif (${OQS_ALGS_ENABLED} STREQUAL "STD") +##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_LIST_STANDARDIZED_ALGS_START + filter_algs("KEM_kyber_512;KEM_kyber_768;KEM_kyber_1024;SIG_dilithium_2;SIG_dilithium_3;SIG_dilithium_5;SIG_falcon_512;SIG_falcon_1024;SIG_sphincs_sha2_128f_simple;SIG_sphincs_sha2_128s_simple;SIG_sphincs_sha2_192f_simple;SIG_sphincs_sha2_192s_simple;SIG_sphincs_sha2_256f_simple;SIG_sphincs_sha2_256s_simple;SIG_sphincs_shake_128f_simple;SIG_sphincs_shake_128s_simple;SIG_sphincs_shake_192f_simple;SIG_sphincs_shake_192s_simple;SIG_sphincs_shake_256f_simple;SIG_sphincs_shake_256s_simple") +##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_LIST_STANDARDIZED_ALGS_END +elseif(${OQS_ALGS_ENABLED} STREQUAL "NIST_R4") + filter_algs("KEM_classic_mceliece_348864;KEM_classic_mceliece_348864f;KEM_classic_mceliece_460896;KEM_classic_mceliece_460896f;KEM_classic_mceliece_6688128;KEM_classic_mceliece_6688128f;KEM_classic_mceliece_6960119;KEM_classic_mceliece_6960119f;KEM_classic_mceliece_8192128;KEM_classic_mceliece_8192128f;KEM_hqc_128;KEM_hqc_192;KEM_hqc_256;KEM_bike_l1;KEM_bike_l3") +else() + message(STATUS "Alg enablement unchanged") +endif() # Set XKCP (Keccak) required for Sphincs AVX2 code even if OpenSSL3 SHA3 is used: if (${OQS_ENABLE_SIG_SPHINCS} OR NOT ${OQS_USE_SHA3_OPENSSL}) diff --git a/CMakeLists.txt b/CMakeLists.txt index d0ca5543ed..f95809e9df 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -153,7 +153,8 @@ set(PUBLIC_HEADERS ${PROJECT_SOURCE_DIR}/src/oqs.h ${PROJECT_SOURCE_DIR}/src/common/common.h ${PROJECT_SOURCE_DIR}/src/common/rand/rand.h ${PROJECT_SOURCE_DIR}/src/kem/kem.h - ${PROJECT_SOURCE_DIR}/src/sig/sig.h) + ${PROJECT_SOURCE_DIR}/src/sig/sig.h + ${PROJECT_SOURCE_DIR}/src/sig_stfl/sig_stfl.h) set(INTERNAL_HEADERS ${PROJECT_SOURCE_DIR}/src/common/aes/aes.h ${PROJECT_SOURCE_DIR}/src/common/rand/rand_nist.h @@ -195,6 +196,9 @@ endif() if(OQS_ENABLE_SIG_SPHINCS) set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/sphincs/sig_sphincs.h) endif() +if(OQS_ENABLE_SIG_STFL_XMSS) + set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig_stfl/xmss/sig_stfl_xmss.h) +endif() ##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_INCLUDE_HEADERS_END execute_process(COMMAND ${CMAKE_COMMAND} -E make_directory ${PROJECT_BINARY_DIR}/include/oqs) execute_process(COMMAND ${CMAKE_COMMAND} -E copy ${PUBLIC_HEADERS} ${PROJECT_BINARY_DIR}/include/oqs) diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt index d0dfb6f043..e6e6ce6f07 100644 --- a/src/CMakeLists.txt +++ b/src/CMakeLists.txt @@ -8,6 +8,7 @@ add_subdirectory(common) # initialize KEM|SIG_OBJS for --warn-uninitialized set(KEM_OBJS "") set(SIG_OBJS "") +set(SIG_STFL_OBJS "") if(${OQS_ENABLE_KEM_BIKE}) add_subdirectory(kem/bike) @@ -56,10 +57,17 @@ if(OQS_ENABLE_SIG_SPHINCS) endif() ##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ALG_OBJECTS_END +if(OQS_ENABLE_SIG_STFL_XMSS) + add_subdirectory(sig_stfl/xmss) + set(SIG_STFL_OBJS ${SIG_STFL_OBJS} ${XMSS_OBJS}) +endif() + add_library(oqs kem/kem.c ${KEM_OBJS} sig/sig.c ${SIG_OBJS} + sig_stfl/sig_stfl.c + ${SIG_STFL_OBJS} ${COMMON_OBJS}) # Internal library to be used only by test programs diff --git a/src/oqs.h b/src/oqs.h index 3acedd11bf..6d1923c78b 100644 --- a/src/oqs.h +++ b/src/oqs.h @@ -17,5 +17,6 @@ #include #include #include +#include #endif // OQS_H diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index f3b2e7c425..4e0ecc0875 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -190,3 +190,6 @@ #cmakedefine OQS_ENABLE_SIG_sphincs_shake_256s_simple 1 #cmakedefine OQS_ENABLE_SIG_sphincs_shake_256s_simple_avx2 1 ///// OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ALG_ENABLE_DEFINES_END + +#cmakedefine OQS_ENABLE_SIG_STFL_XMSS 1 +#cmakedefine OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 1 diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c new file mode 100644 index 0000000000..f33540f8e4 --- /dev/null +++ b/src/sig_stfl/sig_stfl.c @@ -0,0 +1,93 @@ +// SPDX-License-Identifier: MIT + +#include +#include +#if defined(_WIN32) +#include +#define strcasecmp _stricmp +#else +#include +#endif + +#include + +OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { + + const char *a[OQS_SIG_algs_length] = { + OQS_SIG_STFL_alg_xmss_sha256_h10, + }; + + if (i >= OQS_SIG_STFL_algs_length) { + return NULL; + } else { + return a[i]; + } +} + + +OQS_API int OQS_SIG_STFL_alg_count(void) { + return OQS_SIG_STFL_algs_length; +} + + +OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name) { + assert(method_name != NULL); + + if (0) { + + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 + return 1; +#else + return 0; +#endif + } else { + return 0; + } +} + + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { + assert(method_name != NULL); + + if (0) { + + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 + return OQS_SIG_STFL_alg_xmss_sha256_h10_new(); +#else + return NULL; +#endif + } else { + return NULL; + } +} + + +OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, uint8_t *secret_key) { + if (sig == NULL || sig->keypair == NULL || sig->keypair(public_key, secret_key) != 0) { + return OQS_ERROR; + } else { + return OQS_SUCCESS; + } +} + +OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key) { + if (sig == NULL || sig->sign == NULL || sig->sign(signature, signature_len, message, message_len, secret_key) != 0) { + return OQS_ERROR; + } else { + return OQS_SUCCESS; + } +} + +OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + if (sig == NULL || sig->verify == NULL || sig->verify(message, message_len, signature, signature_len, public_key) != 0) { + return OQS_ERROR; + } else { + return OQS_SUCCESS; + } +} + +OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig) { + OQS_MEM_insecure_free(sig); +} diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h new file mode 100644 index 0000000000..4e1a0679b1 --- /dev/null +++ b/src/sig_stfl/sig_stfl.h @@ -0,0 +1,199 @@ +/** + * \file sig_stfl.h + * \brief Stateful Signature schemes + * + * The file `tests/example_sig_stfl.c` contains an example on using the OQS_SIG_STFL API. + * + * SPDX-License-Identifier: MIT + */ + +#ifndef OQS_SIG_STATEFUL_H +#define OQS_SIG_STATEFUL_H + +#include +#include +#include + +#include + +#if defined(__cplusplus) +extern "C" { +#endif + +/* Algorithm identifier for XMSS-SHA2_10_256 */ +#define OQS_SIG_STFL_alg_xmss_sha256_h10 "XMSS-SHA2_10_256" + +#define OQS_SIG_STFL_algs_length 1 + +/** + * Returns identifiers for available signature schemes in liboqs. Used with OQS_SIG_STFL_new. + * + * Note that algorithm identifiers are present in this list even when the algorithm is disabled + * at compile time. + * + * @param[in] i Index of the algorithm identifier to return, 0 <= i < OQS_SIG_algs_length + * @return Algorithm identifier as a string, or NULL. + */ +OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i); + +/** + * Returns the number of signature mechanisms in liboqs. They can be enumerated with + * OQS_SIG_STFL_alg_identifier. + * + * Note that some mechanisms may be disabled at compile time. + * + * @return The number of signature mechanisms. + */ +OQS_API int OQS_SIG_STFL_alg_count(void); + +/** + * Indicates whether the specified algorithm was enabled at compile-time or not. + * + * @param[in] method_name Name of the desired algorithm; one of the names in `OQS_SIG_STFL_algs`. + * @return 1 if enabled, 0 if disabled or not found + */ +OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name); + +/** + * Stateful signature scheme object + */ +typedef struct OQS_SIG_STFL { + + /** A local ordinal representing the LMS parameter of the signature scheme. */ + uint32_t oid; + + /** Printable string representing the name of the signature scheme. */ + const char *method_name; + + /** + * Printable string representing the version of the cryptographic algorithm. + * + * Implementations with the same method_name and same alg_version will be interoperable. + * See README.md for information about algorithm compatibility. + */ + const char *alg_version; + + /** Whether the signature offers EUF-CMA security (TRUE) or not (FALSE). */ + bool euf_cma; + + /** The (maximum) length, in bytes, of public keys for this signature scheme. */ + size_t length_public_key; + /** The (maximum) length, in bytes, of signatures for this signature scheme. */ + size_t length_signature; + + + /** + * Keypair generation algorithm. + * + * Caller is responsible for allocating sufficient memory for `public_key` + * based on the `length_*` members in this object or the per-scheme + * compile-time macros `OQS_SIG_STFL_*_length_*`. + * + * @param[out] public_key The public key represented as a byte string. + * @param[out] secret_key The secret key represented as a byt string + * @return OQS_SUCCESS or OQS_ERROR + */ + OQS_STATUS (*keypair)(uint8_t *public_key, uint8_t *secret_key); + + /** + * Signature generation algorithm. + * + * Caller is responsible for allocating sufficient memory for `signature`, + * based on the `length_*` members in this object or the per-scheme + * compile-time macros `OQS_SIG_STFL_*_length_*`. + * + * @param[out] signature The signature on the message represented as a byte string. + * @param[out] signature_len The length of the signature. + * @param[in] message The message to sign represented as a byte string. + * @param[in] message_len The length of the message to sign. + * @param[in] secret_key The secret key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ + OQS_STATUS (*sign)(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); + + /** + * Signature verification algorithm. + * + * @param[in] message The message represented as a byte string. + * @param[in] message_len The length of the message. + * @param[in] signature The signature on the message represented as a byte string. + * @param[in] signature_len The length of the signature. + * @param[in] public_key The public key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ + OQS_STATUS (*verify)(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); + +} OQS_SIG_STFL; + +/** + * Constructs an OQS_SIG_STFL object for a particular algorithm. + * + * Callers should always check whether the return value is `NULL`, which indicates either than an + * invalid algorithm name was provided, or that the requested algorithm was disabled at compile-time. + * + * @param[in] method_name Name of the desired algorithm; one of the names in `OQS_SIG_STFL_algs`. + * @return An OQS_SIG_STFL for the particular algorithm, or `NULL` if the algorithm has been disabled at compile-time. + */ +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name); + +/** + * Keypair generation algorithm. + * + * Caller is responsible for allocating sufficient memory for `public_key` based + * on the `length_*` members in this object or the per-scheme compile-time macros + * `OQS_SIG_STFL_*_length_*`. Caller is also responsible for initializing + * `secret_key` using the OQS_SECRET_KEY(*) function + * + * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. + * @param[out] public_key The public key represented as a byte string. + * @param[out] secret_key The secret key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ +OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *pk, uint8_t *sk); + +/** + * Signature generation algorithm. + * + * Caller is responsible for allocating sufficient memory for `signature`, + * based on the `length_*` members in this object or the per-scheme + * compile-time macros `OQS_SIG_STFL_*_length_*`. + * + * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. + * @param[out] signature The signature on the message represented as a byte string. + * @param[out] signature_len The length of the signature. + * @param[in] message The message to sign represented as a byte string. + * @param[in] message_len The length of the message to sign. + * @param[in] secret_key The secret key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ +OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); + +/** + * Signature verification algorithm. + * + * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. + * @param[in] message The message represented as a byte string. + * @param[in] message_len The length of the message. + * @param[in] signature The signature on the message represented as a byte string. + * @param[in] signature_len The length of the signature. + * @param[in] public_key The public key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ +OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); + +/** + * Frees an OQS_SIG_STFL object that was constructed by OQS_SIG_STFL_new. + * + * @param[in] sig The OQS_SIG_STFL object to free. + */ +OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig); + +#if defined(__cplusplus) +} // extern "C" +#endif + +#ifdef OQS_ENABLE_SIG_STFL_XMSS +#include +#endif // OQS_ENABLE_SIG_STFL_XMSS + +#endif /* OQS_SIG_STATEFUL_H */ diff --git a/src/sig_stfl/xmss/CMakeLists.txt b/src/sig_stfl/xmss/CMakeLists.txt new file mode 100644 index 0000000000..ff9db48a29 --- /dev/null +++ b/src/sig_stfl/xmss/CMakeLists.txt @@ -0,0 +1,5 @@ +# SPDX-License-Identifier: MIT +set(SRCS sig_stfl_xmss_sha256.c +) + +add_library(xmss OBJECT ${SRCS}) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h new file mode 100644 index 0000000000..fbde5af4de --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -0,0 +1,23 @@ +// SPDX-License-Identifier: MIT + +#ifndef OQS_SIG_STFL_XMSS_H +#define OQS_SIG_STFL_XMSS_H + +#include + +#define XMSS_OID_LEN 4 + +#ifdef OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 + +#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature 2500 +#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk 64 + XMSS_OID_LEN +#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk 2047 + XMSS_OID_LEN + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); + +#endif + +#endif /* OQS_SIG_STFL_XMSS_H */ diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c new file mode 100644 index 0000000000..b2a84fb75c --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c @@ -0,0 +1,43 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +// ======================== XMSS10-SHA256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHA2_10_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h10_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_sha256_h10_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_sha256_h10_verify; + + return sig; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, uint8_t *secret_key) { + return OQS_ERROR; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key) { + return OQS_ERROR; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_ERROR; +} From b0c06fa966360bad2c128b5b37255ced1266d9e3 Mon Sep 17 00:00:00 2001 From: Douglas Stebila Date: Mon, 8 May 2023 10:04:28 -0400 Subject: [PATCH 02/68] Fix API and build issues --- src/sig_stfl/sig_stfl.h | 2 ++ src/sig_stfl/xmss/CMakeLists.txt | 5 +++++ src/sig_stfl/xmss/sig_stfl_xmss_sha256.c | 13 ++++++++++--- 3 files changed, 17 insertions(+), 3 deletions(-) diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 4e1a0679b1..b75be58ea1 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -78,6 +78,8 @@ typedef struct OQS_SIG_STFL { /** The (maximum) length, in bytes, of public keys for this signature scheme. */ size_t length_public_key; + /** The (maximum) length, in bytes, of secret keys for this signature scheme. */ + size_t length_secret_key; /** The (maximum) length, in bytes, of signatures for this signature scheme. */ size_t length_signature; diff --git a/src/sig_stfl/xmss/CMakeLists.txt b/src/sig_stfl/xmss/CMakeLists.txt index ff9db48a29..896618b167 100644 --- a/src/sig_stfl/xmss/CMakeLists.txt +++ b/src/sig_stfl/xmss/CMakeLists.txt @@ -1,5 +1,10 @@ # SPDX-License-Identifier: MIT + +set(_XMSS_OBJS "") + set(SRCS sig_stfl_xmss_sha256.c ) add_library(xmss OBJECT ${SRCS}) +set(_XMSS_OBJS ${_XMSS_OBJS} $) +set(XMSS_OBJS ${_XMSS_OBJS} PARENT_SCOPE) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c index b2a84fb75c..ce50e4493c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c @@ -6,6 +6,12 @@ #include #include "sig_stfl_xmss.h" +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + // ======================== XMSS10-SHA256 ======================== // OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { @@ -21,6 +27,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { sig->euf_cma = true; sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk; sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h10_keypair; @@ -30,14 +37,14 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { return sig; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { return OQS_ERROR; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(XMSS_UNUSED_ATT uint8_t *signature, XMSS_UNUSED_ATT size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { return OQS_ERROR; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT const uint8_t *signature, XMSS_UNUSED_ATT size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { return OQS_ERROR; } From 7b591542e3455b9407be44a54e0a67ffb455eb97 Mon Sep 17 00:00:00 2001 From: Douglas Stebila Date: Mon, 8 May 2023 10:04:45 -0400 Subject: [PATCH 03/68] Add SIG_STFL to tests/dump_alg_info --- tests/dump_alg_info.c | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/tests/dump_alg_info.c b/tests/dump_alg_info.c index 6b07b40155..3bee2d2737 100644 --- a/tests/dump_alg_info.c +++ b/tests/dump_alg_info.c @@ -54,6 +54,25 @@ int main(void) { printf(" length-signature: %zu\n", sig->length_signature); OQS_SIG_free(sig); } + + // iterate through stateful signature schemes and print info + printf("SIG_STFLs:\n"); + for (size_t i = 0; i < OQS_SIG_STFL_algs_length; i++) { + const char *sig_name = OQS_SIG_STFL_alg_identifier(i); + printf(" %s:\n", sig_name); + OQS_SIG_STFL *sig = OQS_SIG_STFL_new(sig_name); + if (sig == NULL) { + printf(" isnull: true\n"); + continue; + } + printf(" isnull: false\n"); + printf(" claimed-security: %s\n", sig->euf_cma ? "EUF-CMA" : "none"); + printf(" length-public-key: %zu\n", sig->length_public_key); + printf(" length-secret-key: %zu\n", sig->length_secret_key); + printf(" length-signature: %zu\n", sig->length_signature); + OQS_SIG_STFL_free(sig); + } + OQS_destroy(); } From 8e1dd5ce0f6efbf221f3eb1ead8c295f72ab460e Mon Sep 17 00:00:00 2001 From: Douglas Stebila Date: Mon, 8 May 2023 21:08:51 -0400 Subject: [PATCH 04/68] Update sig_stfl dummy scheme and add basic test program --- .CMake/alg_support.cmake | 2 +- src/oqsconfig.h.cmake | 2 +- src/sig_stfl/sig_stfl.c | 4 +- src/sig_stfl/xmss/sig_stfl_xmss.h | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256.c | 17 +- tests/CMakeLists.txt | 8 + tests/helpers.py | 33 +++ tests/test_cmdline.py | 8 + tests/test_sig_stfl.c | 247 +++++++++++++++++++++++ 9 files changed, 313 insertions(+), 10 deletions(-) create mode 100644 tests/test_sig_stfl.c diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index 2bc0079b0d..c2c498bf54 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -498,7 +498,7 @@ endif() ##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ENABLE_BY_ALG_END option(OQS_ENABLE_SIG_STFL_XMSS "Enable XMSS algorithm family" ON) -cmake_dependent_option(OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha256_h10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) if((OQS_MINIMAL_BUILD STREQUAL "ON")) message(FATAL_ERROR "OQS_MINIMAL_BUILD option ${OQS_MINIMAL_BUILD} no longer supported") diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index 4e0ecc0875..3496e1a5f2 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -192,4 +192,4 @@ ///// OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ALG_ENABLE_DEFINES_END #cmakedefine OQS_ENABLE_SIG_STFL_XMSS 1 -#cmakedefine OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_sha256_h10 1 diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index f33540f8e4..10b34293d8 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -36,7 +36,7 @@ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name) { if (0) { } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h10)) { -#ifdef OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 return 1; #else return 0; @@ -53,7 +53,7 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { if (0) { } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h10)) { -#ifdef OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 return OQS_SIG_STFL_alg_xmss_sha256_h10_new(); #else return NULL; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index fbde5af4de..93dcd57bba 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -7,7 +7,7 @@ #define XMSS_OID_LEN 4 -#ifdef OQS_ENABLE_SIG_STFL_XMSS_SHA256_H10 +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 #define OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature 2500 #define OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk 64 + XMSS_OID_LEN diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c index ce50e4493c..186fba20f8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c @@ -38,13 +38,20 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { - return OQS_ERROR; + return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(XMSS_UNUSED_ATT uint8_t *signature, XMSS_UNUSED_ATT size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { - return OQS_ERROR; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + memset(signature, 0, OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature); + *signature_len = OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; + return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT const uint8_t *signature, XMSS_UNUSED_ATT size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - return OQS_ERROR; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + for (size_t i = 0; i < OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; i++) { + if (signature[i] != 0) { + return OQS_ERROR; + } + } + return OQS_SUCCESS; } diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt index 3468dfc550..ada020f51a 100644 --- a/tests/CMakeLists.txt +++ b/tests/CMakeLists.txt @@ -110,6 +110,14 @@ target_link_libraries(speed_sig PRIVATE ${TEST_DEPS}) set(SIG_TESTS example_sig kat_sig test_sig test_sig_mem speed_sig vectors_sig) +# SIG_STFL API tests +add_executable(test_sig_stfl test_sig_stfl.c) +if((CMAKE_C_COMPILER_ID MATCHES "Clang") OR (CMAKE_C_COMPILER_ID STREQUAL "GNU")) + target_link_libraries(test_sig_stfl PRIVATE ${API_TEST_DEPS} Threads::Threads) +else () + target_link_libraries(test_sig_stfl PRIVATE ${API_TEST_DEPS}) +endif() + add_executable(dump_alg_info dump_alg_info.c) target_link_libraries(dump_alg_info PRIVATE ${TEST_DEPS}) diff --git a/tests/helpers.py b/tests/helpers.py index fc22ef809f..58f0834511 100644 --- a/tests/helpers.py +++ b/tests/helpers.py @@ -108,6 +108,39 @@ def is_sig_enabled_by_name(name): return True return False +def available_sig_stfls_by_name(): + available_names = [] + with open(os.path.join('src', 'sig_stfl', 'sig_stfl.h')) as fh: + for line in fh: + if line.startswith("#define OQS_SIG_STFL_alg_"): + sig_stfl_name = line.split(' ')[2] + sig_stfl_name = sig_stfl_name[1:-2] + available_names.append(sig_stfl_name) + return available_names + +def is_sig_stfl_enabled_by_name(name): + symbol = None + with open(os.path.join('src', 'sig_stfl', 'sig_stfl.h')) as fh: + for line in fh: + if line.startswith("#define OQS_SIG_STFL_alg_"): + sig_stfl_symbol = line.split(' ')[1] + sig_stfl_symbol = sig_stfl_symbol[len("OQS_SIG_STFL_alg_"):] + sig_stfl_name = line.split(' ')[2] + sig_stfl_name = sig_stfl_name[1:-2] + if sig_stfl_name == name: + symbol = sig_stfl_symbol + break + if symbol == None: return False + header = os.path.join(get_current_build_dir_name(), 'include', 'oqs', 'oqsconfig.h') + with open(header) as fh: + for line in fh: + if line.startswith("#define OQS_ENABLE_SIG_STFL_"): + sig_stfl_symbol = line.split(' ')[1] + sig_stfl_symbol = sig_stfl_symbol[len("OQS_ENABLE_SIG_STFL_"):].rstrip() + if sig_stfl_symbol == symbol: + return True + return False + def filtered_test(func): funcname = func.__name__[len("test_"):] diff --git a/tests/test_cmdline.py b/tests/test_cmdline.py index 5575fd4ffd..66962cd98c 100644 --- a/tests/test_cmdline.py +++ b/tests/test_cmdline.py @@ -28,6 +28,14 @@ def test_sig(sig_name): [helpers.path_to_executable('test_sig'), sig_name], ) +@helpers.filtered_test +@pytest.mark.parametrize('sig_stfl_name', helpers.available_sig_stfls_by_name()) +def test_sig_stfl(sig_stfl_name): + if not(helpers.is_sig_stfl_enabled_by_name(sig_stfl_name)): pytest.skip('Not enabled') + helpers.run_subprocess( + [helpers.path_to_executable('test_sig_stfl'), sig_stfl_name], + ) + if __name__ == "__main__": import sys pytest.main(sys.argv) diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c new file mode 100644 index 0000000000..405def1754 --- /dev/null +++ b/tests/test_sig_stfl.c @@ -0,0 +1,247 @@ +// SPDX-License-Identifier: MIT + +#if defined(_WIN32) +#pragma warning(disable : 4244 4293) +#endif + +#include +#include +#include + +#include + +#if OQS_USE_PTHREADS_IN_TESTS +#include +#endif + +#ifdef OQS_ENABLE_TEST_CONSTANT_TIME +#include +#define OQS_TEST_CT_CLASSIFY(addr, len) VALGRIND_MAKE_MEM_UNDEFINED(addr, len) +#define OQS_TEST_CT_DECLASSIFY(addr, len) VALGRIND_MAKE_MEM_DEFINED(addr, len) +#else +#define OQS_TEST_CT_CLASSIFY(addr, len) +#define OQS_TEST_CT_DECLASSIFY(addr, len) +#endif + +#include "system_info.c" + +typedef struct magic_s { + uint8_t val[31]; +} magic_t; + +static OQS_STATUS sig_stfl_test_correctness(const char *method_name) { + + OQS_SIG_STFL *sig = NULL; + uint8_t *public_key = NULL; + uint8_t *secret_key = NULL; + uint8_t *message = NULL; + size_t message_len = 100; + uint8_t *signature = NULL; + size_t signature_len; + OQS_STATUS rc, ret = OQS_ERROR; + + //The magic numbers are random values. + //The length of the magic number was chosen to be 31 to break alignment + magic_t magic; + OQS_randombytes(magic.val, sizeof(magic_t)); + + sig = OQS_SIG_STFL_new(method_name); + if (sig == NULL) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_new failed\n"); + goto err; + } + + printf("================================================================================\n"); + printf("Sample computation for stateful signature %s\n", sig->method_name); + printf("================================================================================\n"); + + public_key = malloc(sig->length_public_key + 2 * sizeof(magic_t)); + secret_key = malloc(sig->length_secret_key + 2 * sizeof(magic_t)); + message = malloc(message_len + 2 * sizeof(magic_t)); + signature = malloc(sig->length_signature + 2 * sizeof(magic_t)); + + if ((public_key == NULL) || (secret_key == NULL) || (message == NULL) || (signature == NULL)) { + fprintf(stderr, "ERROR: malloc failed\n"); + goto err; + } + + //Set the magic numbers before + memcpy(public_key, magic.val, sizeof(magic_t)); + memcpy(secret_key, magic.val, sizeof(magic_t)); + memcpy(message, magic.val, sizeof(magic_t)); + memcpy(signature, magic.val, sizeof(magic_t)); + + public_key += sizeof(magic_t); + secret_key += sizeof(magic_t); + message += sizeof(magic_t); + signature += sizeof(magic_t); + + // and after + memcpy(public_key + sig->length_public_key, magic.val, sizeof(magic_t)); + memcpy(secret_key + sig->length_secret_key, magic.val, sizeof(magic_t)); + memcpy(message + message_len, magic.val, sizeof(magic_t)); + memcpy(signature + sig->length_signature, magic.val, sizeof(magic_t)); + + OQS_randombytes(message, message_len); + OQS_TEST_CT_DECLASSIFY(message, message_len); + + rc = OQS_SIG_STFL_keypair(sig, public_key, secret_key); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_keypair failed\n"); + goto err; + } + + rc = OQS_SIG_STFL_sign(sig, signature, &signature_len, message, message_len, secret_key); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_sign failed\n"); + goto err; + } + + OQS_TEST_CT_DECLASSIFY(public_key, sig->length_public_key); + OQS_TEST_CT_DECLASSIFY(signature, signature_len); + rc = OQS_SIG_STFL_verify(sig, message, message_len, signature, signature_len, public_key); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_verify failed\n"); + goto err; + } + + /* modify the signature to invalidate it */ + OQS_randombytes(signature, signature_len); + OQS_TEST_CT_DECLASSIFY(signature, signature_len); + rc = OQS_SIG_STFL_verify(sig, message, message_len, signature, signature_len, public_key); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_ERROR) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_verify should have failed!\n"); + goto err; + } + +#ifndef OQS_ENABLE_TEST_CONSTANT_TIME + /* check magic values */ + int rv = memcmp(public_key + sig->length_public_key, magic.val, sizeof(magic_t)); + rv |= memcmp(secret_key + sig->length_secret_key, magic.val, sizeof(magic_t)); + rv |= memcmp(message + message_len, magic.val, sizeof(magic_t)); + rv |= memcmp(signature + sig->length_signature, magic.val, sizeof(magic_t)); + rv |= memcmp(public_key - sizeof(magic_t), magic.val, sizeof(magic_t)); + rv |= memcmp(secret_key - sizeof(magic_t), magic.val, sizeof(magic_t)); + rv |= memcmp(message - sizeof(magic_t), magic.val, sizeof(magic_t)); + rv |= memcmp(signature - sizeof(magic_t), magic.val, sizeof(magic_t)); + if (rv) { + fprintf(stderr, "ERROR: Magic numbers do not mtach\n"); + goto err; + } +#endif + + printf("verification passes as expected\n"); + ret = OQS_SUCCESS; + goto cleanup; + +err: + ret = OQS_ERROR; + +cleanup: + if (secret_key) { + OQS_MEM_secure_free(secret_key - sizeof(magic_t), sig->length_secret_key + 2 * sizeof(magic_t)); + } + if (public_key) { + OQS_MEM_insecure_free(public_key - sizeof(magic_t)); + } + if (message) { + OQS_MEM_insecure_free(message - sizeof(magic_t)); + } + if (signature) { + OQS_MEM_insecure_free(signature - sizeof(magic_t)); + } + OQS_SIG_STFL_free(sig); + + return ret; +} + +#ifdef OQS_ENABLE_TEST_CONSTANT_TIME +static void TEST_SIG_STFL_randombytes(uint8_t *random_array, size_t bytes_to_read) { + // We can't make direct calls to the system randombytes on some platforms, + // so we have to swap out the OQS_randombytes provider. + OQS_randombytes_switch_algorithm("system"); + OQS_randombytes(random_array, bytes_to_read); + OQS_randombytes_custom_algorithm(&TEST_SIG_STFL_randombytes); + + // OQS_TEST_CT_CLASSIFY tells Valgrind's memcheck tool to issue a warning if + // the program branches on any byte that depends on random_array. This helps us + // identify timing side-channels, as these bytes often contain secret data. + OQS_TEST_CT_CLASSIFY(random_array, bytes_to_read); +} +#endif + +#if OQS_USE_PTHREADS_IN_TESTS +struct thread_data { + char *alg_name; + OQS_STATUS rc; +}; + +void *test_wrapper(void *arg) { + struct thread_data *td = arg; + td->rc = sig_stfl_test_correctness(td->alg_name); + return NULL; +} +#endif + +int main(int argc, char **argv) { + OQS_init(); + + printf("Testing stateful signature algorithms using liboqs version %s\n", OQS_version()); + + if (argc != 2) { + fprintf(stderr, "Usage: test_sig_stfl algname\n"); + fprintf(stderr, " algname: "); + for (size_t i = 0; i < OQS_SIG_STFL_algs_length; i++) { + if (i > 0) { + fprintf(stderr, ", "); + } + fprintf(stderr, "%s", OQS_SIG_STFL_alg_identifier(i)); + } + fprintf(stderr, "\n"); + OQS_destroy(); + return EXIT_FAILURE; + } + + print_system_info(); + + char *alg_name = argv[1]; + if (!OQS_SIG_STFL_alg_is_enabled(alg_name)) { + printf("Stateful signature algorithm %s not enabled!\n", alg_name); + OQS_destroy(); + return EXIT_FAILURE; + } + +#ifdef OQS_ENABLE_TEST_CONSTANT_TIME + OQS_randombytes_custom_algorithm(&TEST_SIG_STFL_randombytes); +#else + OQS_randombytes_switch_algorithm("system"); +#endif + + OQS_STATUS rc; +#if OQS_USE_PTHREADS_IN_TESTS +#define MAX_LEN_SIG_NAME_ 64 + pthread_t thread; + struct thread_data td; + td.alg_name = alg_name; + int trc = pthread_create(&thread, NULL, test_wrapper, &td); + if (trc) { + fprintf(stderr, "ERROR: Creating pthread\n"); + OQS_destroy(); + return EXIT_FAILURE; + } + pthread_join(thread, NULL); + rc = td.rc; +#else + rc = sig_stfl_test_correctness(alg_name); +#endif + if (rc != OQS_SUCCESS) { + OQS_destroy(); + return EXIT_FAILURE; + } + OQS_destroy(); + return EXIT_SUCCESS; +} From 244288f8acdab63813fbb9514f85b5bf6f8d372c Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Thu, 1 Jun 2023 18:41:58 -0400 Subject: [PATCH 05/68] Add XMSS parameter xmss_sha256_h10 (#1482) * init external and parameters * fix the size of pk and sk * add cmakelist for xmss_sha256_h10 * add comment * fix format err * fix compiler warning of size_t * update to match local * add remain and total API * add sigs_remaining and sigs_total * add const to API * add kat_sig_stfl * to pass the format test * fix typo * verbose error * let's see if this work * use UINT64_MAX constant * goto err to avoid memory leaks * safe arithmetic using unsigned int and initialize lengths array * fix iteration type to match its comparison * using unsigned int instead of uint32_t to match with comparison * use memset to initialize default value * convert to unsigned int * propagate unsigned int * clean up * remove randombytes, use OQS_randombytes instead. * use calloc instead of malloc for secret_key memory initialization * remove randombytes from CMakeLists.txt * remove makefile * using namespace to separate core_hash.c * rename katfile * add test and kats for test_kat.py * add compile definition for core_hash.c * add type for t * fix typo --- src/sig_stfl/sig_stfl.c | 16 + src/sig_stfl/sig_stfl.h | 38 + src/sig_stfl/xmss/CMakeLists.txt | 16 +- src/sig_stfl/xmss/external/core_hash.c | 14 + src/sig_stfl/xmss/external/hash.c | 142 +++ src/sig_stfl/xmss/external/hash.h | 47 + src/sig_stfl/xmss/external/hash_address.c | 66 ++ src/sig_stfl/xmss/external/hash_address.h | 48 + src/sig_stfl/xmss/external/namespace.h | 14 + src/sig_stfl/xmss/external/params.c | 753 +++++++++++++ src/sig_stfl/xmss/external/params.h | 78 ++ src/sig_stfl/xmss/external/sign.c | 139 +++ src/sig_stfl/xmss/external/sign.h | 90 ++ src/sig_stfl/xmss/external/sign_params.h | 142 +++ src/sig_stfl/xmss/external/utils.c | 30 + src/sig_stfl/xmss/external/utils.h | 19 + src/sig_stfl/xmss/external/wots.c | 180 ++++ src/sig_stfl/xmss/external/wots.h | 40 + src/sig_stfl/xmss/external/xmss.c | 287 +++++ src/sig_stfl/xmss/external/xmss.h | 93 ++ src/sig_stfl/xmss/external/xmss_commons.c | 216 ++++ src/sig_stfl/xmss/external/xmss_commons.h | 36 + src/sig_stfl/xmss/external/xmss_core.c | 277 +++++ src/sig_stfl/xmss/external/xmss_core.h | 85 ++ src/sig_stfl/xmss/external/xmss_core_fast.c | 988 ++++++++++++++++++ src/sig_stfl/xmss/sig_stfl_xmss.h | 6 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256.c | 57 - src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 112 ++ tests/CMakeLists.txt | 11 +- tests/KATs/sig_stfl/kats.json | 3 + tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp | 182 ++++ tests/helpers.py | 19 +- tests/kat_sig_stfl.c | 289 +++++ tests/test_helpers.h | 1 + tests/test_kat.py | 16 + tests/test_sig.c | 2 +- tests/test_sig_stfl.c | 2 +- 37 files changed, 4484 insertions(+), 70 deletions(-) create mode 100644 src/sig_stfl/xmss/external/core_hash.c create mode 100644 src/sig_stfl/xmss/external/hash.c create mode 100644 src/sig_stfl/xmss/external/hash.h create mode 100644 src/sig_stfl/xmss/external/hash_address.c create mode 100644 src/sig_stfl/xmss/external/hash_address.h create mode 100644 src/sig_stfl/xmss/external/namespace.h create mode 100644 src/sig_stfl/xmss/external/params.c create mode 100644 src/sig_stfl/xmss/external/params.h create mode 100644 src/sig_stfl/xmss/external/sign.c create mode 100644 src/sig_stfl/xmss/external/sign.h create mode 100644 src/sig_stfl/xmss/external/sign_params.h create mode 100644 src/sig_stfl/xmss/external/utils.c create mode 100644 src/sig_stfl/xmss/external/utils.h create mode 100644 src/sig_stfl/xmss/external/wots.c create mode 100644 src/sig_stfl/xmss/external/wots.h create mode 100644 src/sig_stfl/xmss/external/xmss.c create mode 100644 src/sig_stfl/xmss/external/xmss.h create mode 100644 src/sig_stfl/xmss/external/xmss_commons.c create mode 100644 src/sig_stfl/xmss/external/xmss_commons.h create mode 100644 src/sig_stfl/xmss/external/xmss_core.c create mode 100644 src/sig_stfl/xmss/external/xmss_core.h create mode 100644 src/sig_stfl/xmss/external/xmss_core_fast.c delete mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_sha256.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c create mode 100644 tests/KATs/sig_stfl/kats.json create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp create mode 100644 tests/kat_sig_stfl.c diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 10b34293d8..9ee29a9736 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -88,6 +88,22 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m } } +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, size_t *remain, const uint8_t *secret_key) { + if (sig == NULL || sig->sigs_remaining == NULL || sig->sigs_remaining(remain, secret_key) != 0) { + return OQS_ERROR; + } else { + return OQS_SUCCESS; + } +} + +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, size_t *max, const uint8_t *secret_key) { + if (sig == NULL || sig->sigs_total == NULL || sig->sigs_total(max, secret_key) != 0) { + return OQS_ERROR; + } else { + return OQS_SUCCESS; + } +} + OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig) { OQS_MEM_insecure_free(sig); } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index b75be58ea1..67604f5b9d 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -125,6 +125,24 @@ typedef struct OQS_SIG_STFL { */ OQS_STATUS (*verify)(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); + /** + * Query number of remaining signatures + * + * @param[out] remain The number of remaining signatures + * @param[in] secret_key The secret key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ + OQS_STATUS (*sigs_remaining)(size_t *remain, const uint8_t *secret_key); + + /** + * Total number of signatures + * + * @param[out] total The total number of signatures + * @param[in] secret_key The secret key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ + OQS_STATUS (*sigs_total)(size_t *total, const uint8_t *secret_key); + } OQS_SIG_STFL; /** @@ -183,6 +201,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature */ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +/** + * Query number of remaining signatures + * + * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. + * @param[out] remain The number of remaining signatures + * @param[in] secret_key The secret key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, size_t *remain, const uint8_t *secret_key); + +/** + * * Total number of signatures + * + * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. + * @param[out] max The number of remaining signatures + * @param[in] secret_key The secret key represented as a byte string. + * @return OQS_SUCCESS or OQS_ERROR + */ +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, size_t *max, const uint8_t *secret_key); + /** * Frees an OQS_SIG_STFL object that was constructed by OQS_SIG_STFL_new. * diff --git a/src/sig_stfl/xmss/CMakeLists.txt b/src/sig_stfl/xmss/CMakeLists.txt index 896618b167..83bfc2be5e 100644 --- a/src/sig_stfl/xmss/CMakeLists.txt +++ b/src/sig_stfl/xmss/CMakeLists.txt @@ -2,8 +2,20 @@ set(_XMSS_OBJS "") -set(SRCS sig_stfl_xmss_sha256.c -) +set(SRCS external/hash.c + external/hash_address.c + external/params.c + external/utils.c + external/wots.c + external/xmss.c + external/xmss_commons.c + ) + +if (OQS_ENABLE_SIG_STFL_xmss_sha256_h10) + add_compile_definitions(OQS_ENABLE_SIG_STFL_xmss_sha256_h10) + set (SRCS ${SRCS} sig_stfl_xmss_sha256_h10.c external/core_hash.c external/xmss_core.c) +endif() + add_library(xmss OBJECT ${SRCS}) set(_XMSS_OBJS ${_XMSS_OBJS} $) diff --git a/src/sig_stfl/xmss/external/core_hash.c b/src/sig_stfl/xmss/external/core_hash.c new file mode 100644 index 0000000000..5df78cb998 --- /dev/null +++ b/src/sig_stfl/xmss/external/core_hash.c @@ -0,0 +1,14 @@ +#include +#include +#include "hash.h" + +int core_hash(const xmss_params *params, + unsigned char *out, + const unsigned char *in, unsigned long long inlen) +{ +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 + (void)params; + OQS_SHA2_sha256(out, in, inlen); + return 0; +#endif +} diff --git a/src/sig_stfl/xmss/external/hash.c b/src/sig_stfl/xmss/external/hash.c new file mode 100644 index 0000000000..c335d7d680 --- /dev/null +++ b/src/sig_stfl/xmss/external/hash.c @@ -0,0 +1,142 @@ +#include +#include + +#include +#include + +#include "hash_address.h" +#include "utils.h" +#include "params.h" +#include "hash.h" + +#define XMSS_HASH_PADDING_F 0 +#define XMSS_HASH_PADDING_H 1 +#define XMSS_HASH_PADDING_HASH 2 +#define XMSS_HASH_PADDING_PRF 3 +#define XMSS_HASH_PADDING_PRF_KEYGEN 4 + +void addr_to_bytes(unsigned char *bytes, const uint32_t addr[8]) +{ + int i; + for (i = 0; i < 8; i++) { + ull_to_bytes(bytes + i*4, 4, addr[i]); + } +} + +/* + * Computes PRF(key, in), for a key of params->n bytes, and a 32-byte input. + */ +int prf(const xmss_params *params, + unsigned char *out, const unsigned char in[32], + const unsigned char *key) +{ + unsigned char buf[params->padding_len + params->n + 32]; + + ull_to_bytes(buf, params->padding_len, XMSS_HASH_PADDING_PRF); + memcpy(buf + params->padding_len, key, params->n); + memcpy(buf + params->padding_len + params->n, in, 32); + + return core_hash(params, out, buf, params->padding_len + params->n + 32); +} + +/* + * Computes PRF_keygen(key, in), for a key of params->n bytes, and an input + * of 32 + params->n bytes + */ +int prf_keygen(const xmss_params *params, + unsigned char *out, const unsigned char *in, + const unsigned char *key) +{ + unsigned char buf[params->padding_len + 2*params->n + 32]; + + ull_to_bytes(buf, params->padding_len, XMSS_HASH_PADDING_PRF_KEYGEN); + memcpy(buf + params->padding_len, key, params->n); + memcpy(buf + params->padding_len + params->n, in, params->n + 32); + + return core_hash(params, out, buf, params->padding_len + 2*params->n + 32); +} + +/* + * Computes the message hash using R, the public root, the index of the leaf + * node, and the message. Notably, it requires m_with_prefix to have 3*n plus + * the length of the padding as free space available before the message, + * to use for the prefix. This is necessary to prevent having to move the + * message around (and thus allocate memory for it). + */ +int hash_message(const xmss_params *params, unsigned char *out, + const unsigned char *R, const unsigned char *root, + unsigned long long idx, + unsigned char *m_with_prefix, unsigned long long mlen) +{ + /* We're creating a hash using input of the form: + toByte(X, 32) || R || root || index || M */ + ull_to_bytes(m_with_prefix, params->padding_len, XMSS_HASH_PADDING_HASH); + memcpy(m_with_prefix + params->padding_len, R, params->n); + memcpy(m_with_prefix + params->padding_len + params->n, root, params->n); + ull_to_bytes(m_with_prefix + params->padding_len + 2*params->n, params->n, idx); + + return core_hash(params, out, m_with_prefix, mlen + params->padding_len + 3*params->n); +} + +/** + * We assume the left half is in in[0]...in[n-1] + */ +int thash_h(const xmss_params *params, + unsigned char *out, const unsigned char *in, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + unsigned char buf[params->padding_len + 3 * params->n]; + unsigned char bitmask[2 * params->n]; + unsigned char addr_as_bytes[32]; + unsigned int i; + + /* Set the function padding. */ + ull_to_bytes(buf, params->padding_len, XMSS_HASH_PADDING_H); + + /* Generate the n-byte key. */ + set_key_and_mask(addr, 0); + addr_to_bytes(addr_as_bytes, addr); + prf(params, buf + params->padding_len, addr_as_bytes, pub_seed); + + /* Generate the 2n-byte mask. */ + set_key_and_mask(addr, 1); + addr_to_bytes(addr_as_bytes, addr); + prf(params, bitmask, addr_as_bytes, pub_seed); + + set_key_and_mask(addr, 2); + addr_to_bytes(addr_as_bytes, addr); + prf(params, bitmask + params->n, addr_as_bytes, pub_seed); + + for (i = 0; i < 2 * params->n; i++) { + buf[params->padding_len + params->n + i] = in[i] ^ bitmask[i]; + } + return core_hash(params, out, buf, params->padding_len + 3 * params->n); +} + +int thash_f(const xmss_params *params, + unsigned char *out, const unsigned char *in, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + unsigned char buf[params->padding_len + 2 * params->n]; + unsigned char bitmask[params->n]; + unsigned char addr_as_bytes[32]; + unsigned int i; + + /* Set the function padding. */ + ull_to_bytes(buf, params->padding_len, XMSS_HASH_PADDING_F); + + /* Generate the n-byte key. */ + set_key_and_mask(addr, 0); + addr_to_bytes(addr_as_bytes, addr); + prf(params, buf + params->padding_len, addr_as_bytes, pub_seed); + + /* Generate the n-byte mask. */ + set_key_and_mask(addr, 1); + addr_to_bytes(addr_as_bytes, addr); + prf(params, bitmask, addr_as_bytes, pub_seed); + + for (i = 0; i < params->n; i++) { + buf[params->padding_len + params->n + i] = in[i] ^ bitmask[i]; + } + return core_hash(params, out, buf, params->padding_len + 2 * params->n); +} diff --git a/src/sig_stfl/xmss/external/hash.h b/src/sig_stfl/xmss/external/hash.h new file mode 100644 index 0000000000..5a3d750b07 --- /dev/null +++ b/src/sig_stfl/xmss/external/hash.h @@ -0,0 +1,47 @@ +#ifndef XMSS_HASH_H +#define XMSS_HASH_H + +#include +#include "params.h" + +#define addr_to_bytes XMSS_INNER_NAMESPACE(addr_to_bytes) +void addr_to_bytes(unsigned char *bytes, const uint32_t addr[8]); + +#define core_hash XMSS_INNER_NAMESPACE(core_hash) +int core_hash(const xmss_params *params, + unsigned char *out, + const unsigned char *in, unsigned long long inlen); + +#define prf XMSS_INNER_NAMESPACE(prf) +int prf(const xmss_params *params, + unsigned char *out, const unsigned char in[32], + const unsigned char *key); + +#define prf_keygen XMSS_INNER_NAMESPACE(prf_keygen) +int prf_keygen(const xmss_params *params, + unsigned char *out, const unsigned char *in, + const unsigned char *key); + +#define h_msg XMSS_INNER_NAMESPACE(h_msg) +int h_msg(const xmss_params *params, + unsigned char *out, + const unsigned char *in, unsigned long long inlen, + const unsigned char *key, const unsigned int keylen); + +#define thash_h XMSS_INNER_NAMESPACE(thash_h) +int thash_h(const xmss_params *params, + unsigned char *out, const unsigned char *in, + const unsigned char *pub_seed, uint32_t addr[8]); + +#define thash_f XMSS_INNER_NAMESPACE(thash_f) +int thash_f(const xmss_params *params, + unsigned char *out, const unsigned char *in, + const unsigned char *pub_seed, uint32_t addr[8]); + +#define hash_message XMSS_INNER_NAMESPACE(hash_message) +int hash_message(const xmss_params *params, unsigned char *out, + const unsigned char *R, const unsigned char *root, + unsigned long long idx, + unsigned char *m_with_prefix, unsigned long long mlen); + +#endif diff --git a/src/sig_stfl/xmss/external/hash_address.c b/src/sig_stfl/xmss/external/hash_address.c new file mode 100644 index 0000000000..7aacee5a58 --- /dev/null +++ b/src/sig_stfl/xmss/external/hash_address.c @@ -0,0 +1,66 @@ +#include +#include "hash_address.h" + +void set_layer_addr(uint32_t addr[8], uint32_t layer) +{ + addr[0] = layer; +} + +void set_tree_addr(uint32_t addr[8], uint64_t tree) +{ + addr[1] = (uint32_t) (tree >> 32); + addr[2] = (uint32_t) tree; +} + +void set_type(uint32_t addr[8], uint32_t type) +{ + addr[3] = type; +} + +void set_key_and_mask(uint32_t addr[8], uint32_t key_and_mask) +{ + addr[7] = key_and_mask; +} + +void copy_subtree_addr(uint32_t out[8], const uint32_t in[8]) +{ + out[0] = in[0]; + out[1] = in[1]; + out[2] = in[2]; +} + +/* These functions are used for OTS addresses. */ + +void set_ots_addr(uint32_t addr[8], uint32_t ots) +{ + addr[4] = ots; +} + +void set_chain_addr(uint32_t addr[8], uint32_t chain) +{ + addr[5] = chain; +} + +void set_hash_addr(uint32_t addr[8], uint32_t hash) +{ + addr[6] = hash; +} + +/* This function is used for L-tree addresses. */ + +void set_ltree_addr(uint32_t addr[8], uint32_t ltree) +{ + addr[4] = ltree; +} + +/* These functions are used for hash tree addresses. */ + +void set_tree_height(uint32_t addr[8], uint32_t tree_height) +{ + addr[5] = tree_height; +} + +void set_tree_index(uint32_t addr[8], uint32_t tree_index) +{ + addr[6] = tree_index; +} diff --git a/src/sig_stfl/xmss/external/hash_address.h b/src/sig_stfl/xmss/external/hash_address.h new file mode 100644 index 0000000000..50ad17885e --- /dev/null +++ b/src/sig_stfl/xmss/external/hash_address.h @@ -0,0 +1,48 @@ +#ifndef XMSS_HASH_ADDRESS_H +#define XMSS_HASH_ADDRESS_H + +#include +#include "namespace.h" + +#define XMSS_ADDR_TYPE_OTS 0 +#define XMSS_ADDR_TYPE_LTREE 1 +#define XMSS_ADDR_TYPE_HASHTREE 2 + +#define set_layer_addr XMSS_INNER_NAMESPACE(set_layer_addr) +void set_layer_addr(uint32_t addr[8], uint32_t layer); + +#define set_tree_addr XMSS_INNER_NAMESPACE(set_tree_addr) +void set_tree_addr(uint32_t addr[8], uint64_t tree); + +#define set_type XMSS_INNER_NAMESPACE(set_type) +void set_type(uint32_t addr[8], uint32_t type); + +#define set_key_and_mask XMSS_INNER_NAMESPACE(set_key_and_mask) +void set_key_and_mask(uint32_t addr[8], uint32_t key_and_mask); + +/* Copies the layer and tree part of one address into the other */ +#define copy_subtree_addr XMSS_INNER_NAMESPACE(copy_subtree_addr) +void copy_subtree_addr(uint32_t out[8], const uint32_t in[8]); + +/* These functions are used for OTS addresses. */ +#define set_ots_addr XMSS_INNER_NAMESPACE(set_ots_addr) +void set_ots_addr(uint32_t addr[8], uint32_t ots); + +#define set_chain_addr XMSS_INNER_NAMESPACE(set_chain_addr) +void set_chain_addr(uint32_t addr[8], uint32_t chain); + +#define set_hash_addr XMSS_INNER_NAMESPACE(set_hash_addr) +void set_hash_addr(uint32_t addr[8], uint32_t hash); + +/* This function is used for L-tree addresses. */ +#define set_ltree_addr XMSS_INNER_NAMESPACE(set_ltree_addr) +void set_ltree_addr(uint32_t addr[8], uint32_t ltree); + +/* These functions are used for hash tree addresses. */ +#define set_tree_height XMSS_INNER_NAMESPACE(set_tree_height) +void set_tree_height(uint32_t addr[8], uint32_t tree_height); + +#define set_tree_index XMSS_INNER_NAMESPACE(set_tree_index) +void set_tree_index(uint32_t addr[8], uint32_t tree_index); + +#endif diff --git a/src/sig_stfl/xmss/external/namespace.h b/src/sig_stfl/xmss/external/namespace.h new file mode 100644 index 0000000000..d593a85c53 --- /dev/null +++ b/src/sig_stfl/xmss/external/namespace.h @@ -0,0 +1,14 @@ +#ifndef XMSS_NAMESPACE_H +#define XMSS_NAMESPACE_H + + +#define XMSS_PARAMS oqs_sig_stfl_xmss +#define XMSS_PARAMS_INNER oqs_sig_stfl_xmss_inner + +#define XMSS_NAMESPACE(funcname) XMSS_(XMSS_PARAMS, funcname) +#define XMSS_INNER_NAMESPACE(funcname) XMSS_(XMSS_PARAMS_INNER, funcname) +#define XMSS_(prefix, funcname) XMSS__(prefix, funcname) +#define XMSS__(prefix, funcname) prefix ## _ ## funcname + + +#endif diff --git a/src/sig_stfl/xmss/external/params.c b/src/sig_stfl/xmss/external/params.c new file mode 100644 index 0000000000..fdb9c76f2c --- /dev/null +++ b/src/sig_stfl/xmss/external/params.c @@ -0,0 +1,753 @@ +#include +#include + +#include "params.h" +#include "xmss_core.h" + +int xmss_str_to_oid(uint32_t *oid, const char *s) +{ + if (!strcmp(s, "XMSS-SHA2_10_256")) { + *oid = 0x00000001; + } + else if (!strcmp(s, "XMSS-SHA2_16_256")) { + *oid = 0x00000002; + } + else if (!strcmp(s, "XMSS-SHA2_20_256")) { + *oid = 0x00000003; + } + else if (!strcmp(s, "XMSS-SHA2_10_512")) { + *oid = 0x00000004; + } + else if (!strcmp(s, "XMSS-SHA2_16_512")) { + *oid = 0x00000005; + } + else if (!strcmp(s, "XMSS-SHA2_20_512")) { + *oid = 0x00000006; + } + else if (!strcmp(s, "XMSS-SHAKE_10_256")) { + *oid = 0x00000007; + } + else if (!strcmp(s, "XMSS-SHAKE_16_256")) { + *oid = 0x00000008; + } + else if (!strcmp(s, "XMSS-SHAKE_20_256")) { + *oid = 0x00000009; + } + else if (!strcmp(s, "XMSS-SHAKE_10_512")) { + *oid = 0x0000000a; + } + else if (!strcmp(s, "XMSS-SHAKE_16_512")) { + *oid = 0x0000000b; + } + else if (!strcmp(s, "XMSS-SHAKE_20_512")) { + *oid = 0x0000000c; + } + else if (!strcmp(s, "XMSS-SHA2_10_192")) { + *oid = 0x0000000d; + } + else if (!strcmp(s, "XMSS-SHA2_16_192")) { + *oid = 0x0000000e; + } + else if (!strcmp(s, "XMSS-SHA2_20_192")) { + *oid = 0x0000000f; + } + else if (!strcmp(s, "XMSS-SHAKE256_10_256")) { + *oid = 0x00000010; + } + else if (!strcmp(s, "XMSS-SHAKE256_16_256")) { + *oid = 0x00000011; + } + else if (!strcmp(s, "XMSS-SHAKE256_20_256")) { + *oid = 0x00000012; + } + else if (!strcmp(s, "XMSS-SHAKE256_10_192")) { + *oid = 0x00000013; + } + else if (!strcmp(s, "XMSS-SHAKE256_16_192")) { + *oid = 0x00000014; + } + else if (!strcmp(s, "XMSS-SHAKE256_20_192")) { + *oid = 0x00000015; + } + else { + return -1; + } + return 0; +} + +int xmssmt_str_to_oid(uint32_t *oid, const char *s) +{ + if (!strcmp(s, "XMSSMT-SHA2_20/2_256")) { + *oid = 0x00000001; + } + else if (!strcmp(s, "XMSSMT-SHA2_20/4_256")) { + *oid = 0x00000002; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/2_256")) { + *oid = 0x00000003; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/4_256")) { + *oid = 0x00000004; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/8_256")) { + *oid = 0x00000005; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/3_256")) { + *oid = 0x00000006; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/6_256")) { + *oid = 0x00000007; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/12_256")) { + *oid = 0x00000008; + } + else if (!strcmp(s, "XMSSMT-SHA2_20/2_512")) { + *oid = 0x00000009; + } + else if (!strcmp(s, "XMSSMT-SHA2_20/4_512")) { + *oid = 0x0000000a; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/2_512")) { + *oid = 0x0000000b; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/4_512")) { + *oid = 0x0000000c; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/8_512")) { + *oid = 0x0000000d; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/3_512")) { + *oid = 0x0000000e; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/6_512")) { + *oid = 0x0000000f; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/12_512")) { + *oid = 0x00000010; + } + else if (!strcmp(s, "XMSSMT-SHAKE_20/2_256")) { + *oid = 0x00000011; + } + else if (!strcmp(s, "XMSSMT-SHAKE_20/4_256")) { + *oid = 0x00000012; + } + else if (!strcmp(s, "XMSSMT-SHAKE_40/2_256")) { + *oid = 0x00000013; + } + else if (!strcmp(s, "XMSSMT-SHAKE_40/4_256")) { + *oid = 0x00000014; + } + else if (!strcmp(s, "XMSSMT-SHAKE_40/8_256")) { + *oid = 0x00000015; + } + else if (!strcmp(s, "XMSSMT-SHAKE_60/3_256")) { + *oid = 0x00000016; + } + else if (!strcmp(s, "XMSSMT-SHAKE_60/6_256")) { + *oid = 0x00000017; + } + else if (!strcmp(s, "XMSSMT-SHAKE_60/12_256")) { + *oid = 0x00000018; + } + else if (!strcmp(s, "XMSSMT-SHAKE_20/2_512")) { + *oid = 0x00000019; + } + else if (!strcmp(s, "XMSSMT-SHAKE_20/4_512")) { + *oid = 0x0000001a; + } + else if (!strcmp(s, "XMSSMT-SHAKE_40/2_512")) { + *oid = 0x0000001b; + } + else if (!strcmp(s, "XMSSMT-SHAKE_40/4_512")) { + *oid = 0x0000001c; + } + else if (!strcmp(s, "XMSSMT-SHAKE_40/8_512")) { + *oid = 0x0000001d; + } + else if (!strcmp(s, "XMSSMT-SHAKE_60/3_512")) { + *oid = 0x0000001e; + } + else if (!strcmp(s, "XMSSMT-SHAKE_60/6_512")) { + *oid = 0x0000001f; + } + else if (!strcmp(s, "XMSSMT-SHAKE_60/12_512")) { + *oid = 0x00000020; + } + else if (!strcmp(s, "XMSSMT-SHA2_20/2_192")) { + *oid = 0x00000021; + } + else if (!strcmp(s, "XMSSMT-SHA2_20/4_192")) { + *oid = 0x00000022; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/2_192")) { + *oid = 0x00000023; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/4_192")) { + *oid = 0x00000024; + } + else if (!strcmp(s, "XMSSMT-SHA2_40/8_192")) { + *oid = 0x00000025; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/3_192")) { + *oid = 0x00000026; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/6_192")) { + *oid = 0x00000027; + } + else if (!strcmp(s, "XMSSMT-SHA2_60/12_192")) { + *oid = 0x00000028; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_20/2_256")) { + *oid = 0x00000029; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_20/4_256")) { + *oid = 0x0000002a; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_40/2_256")) { + *oid = 0x0000002b; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_40/4_256")) { + *oid = 0x0000002c; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_40/8_256")) { + *oid = 0x0000002d; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_60/3_256")) { + *oid = 0x0000002e; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_60/6_256")) { + *oid = 0x0000002f; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_60/12_256")) { + *oid = 0x00000030; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_20/2_192")) { + *oid = 0x00000031; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_20/4_192")) { + *oid = 0x00000032; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_40/2_192")) { + *oid = 0x00000033; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_40/4_192")) { + *oid = 0x00000034; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_40/8_192")) { + *oid = 0x00000035; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_60/3_192")) { + *oid = 0x00000036; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_60/6_192")) { + *oid = 0x00000037; + } + else if (!strcmp(s, "XMSSMT-SHAKE256_60/12_192")) { + *oid = 0x00000038; + } + else { + return -1; + } + return 0; +} + +int xmss_parse_oid(xmss_params *params, const uint32_t oid) +{ + switch (oid) { + case 0x00000001: + case 0x00000002: + case 0x00000003: + case 0x00000004: + case 0x00000005: + case 0x00000006: + + case 0x0000000d: + case 0x0000000e: + case 0x0000000f: + params->func = XMSS_SHA2; + break; + + case 0x00000007: + case 0x00000008: + case 0x00000009: + params->func = XMSS_SHAKE128; + break; + + case 0x0000000a: + case 0x0000000b: + case 0x0000000c: + + case 0x00000010: + case 0x00000011: + case 0x00000012: + case 0x00000013: + case 0x00000014: + case 0x00000015: + params->func = XMSS_SHAKE256; + break; + + default: + return -1; + } + switch (oid) { + case 0x0000000d: + case 0x0000000e: + case 0x0000000f: + + case 0x00000013: + case 0x00000014: + case 0x00000015: + params->n = 24; + params->padding_len = 4; + break; + + case 0x00000001: + case 0x00000002: + case 0x00000003: + + case 0x00000007: + case 0x00000008: + case 0x00000009: + + case 0x00000010: + case 0x00000011: + case 0x00000012: + params->n = 32; + params->padding_len = 32; + break; + + case 0x00000004: + case 0x00000005: + case 0x00000006: + + case 0x0000000a: + case 0x0000000b: + case 0x0000000c: + params->n = 64; + params->padding_len = 64; + break; + + default: + return -1; + } + switch (oid) { + case 0x00000001: + case 0x00000004: + case 0x00000007: + case 0x0000000a: + case 0x0000000d: + case 0x00000010: + case 0x00000013: + params->full_height = 10; + break; + + case 0x00000002: + case 0x00000005: + case 0x00000008: + case 0x0000000b: + case 0x0000000e: + case 0x00000011: + case 0x00000014: + params->full_height = 16; + break; + + case 0x00000003: + case 0x00000006: + case 0x00000009: + case 0x0000000c: + case 0x0000000f: + case 0x00000012: + case 0x00000015: + params->full_height = 20; + + break; + default: + return -1; + } + + params->d = 1; + params->wots_w = 16; + + // TODO figure out sensible and legal values for this based on the above + params->bds_k = 0; + + return xmss_xmssmt_initialize_params(params); +} + +int xmssmt_parse_oid(xmss_params *params, const uint32_t oid) +{ + switch (oid) { + case 0x00000001: + case 0x00000002: + case 0x00000003: + case 0x00000004: + case 0x00000005: + case 0x00000006: + case 0x00000007: + case 0x00000008: + case 0x00000009: + case 0x0000000a: + case 0x0000000b: + case 0x0000000c: + case 0x0000000d: + case 0x0000000e: + case 0x0000000f: + case 0x00000010: + + case 0x00000021: + case 0x00000022: + case 0x00000023: + case 0x00000024: + case 0x00000025: + case 0x00000026: + case 0x00000027: + case 0x00000028: + params->func = XMSS_SHA2; + break; + + case 0x00000011: + case 0x00000012: + case 0x00000013: + case 0x00000014: + case 0x00000015: + case 0x00000016: + case 0x00000017: + case 0x00000018: + params->func = XMSS_SHAKE128; + break; + + case 0x00000019: + case 0x0000001a: + case 0x0000001b: + case 0x0000001c: + case 0x0000001e: + case 0x0000001d: + case 0x0000001f: + case 0x00000020: + + case 0x00000029: + case 0x0000002a: + case 0x0000002b: + case 0x0000002c: + case 0x0000002d: + case 0x0000002e: + case 0x0000002f: + case 0x00000030: + case 0x00000031: + case 0x00000032: + case 0x00000033: + case 0x00000034: + case 0x00000035: + case 0x00000036: + case 0x00000037: + case 0x00000038: + params->func = XMSS_SHAKE256; + break; + + default: + return -1; + } + switch (oid) { + case 0x00000021: + case 0x00000022: + case 0x00000023: + case 0x00000024: + case 0x00000025: + case 0x00000026: + case 0x00000027: + case 0x00000028: + + case 0x00000031: + case 0x00000032: + case 0x00000033: + case 0x00000034: + case 0x00000035: + case 0x00000036: + case 0x00000037: + case 0x00000038: + params->n = 24; + params->padding_len = 4; + break; + + case 0x00000001: + case 0x00000002: + case 0x00000003: + case 0x00000004: + case 0x00000005: + case 0x00000006: + case 0x00000007: + case 0x00000008: + + case 0x00000011: + case 0x00000012: + case 0x00000013: + case 0x00000014: + case 0x00000015: + case 0x00000016: + case 0x00000017: + case 0x00000018: + + case 0x00000029: + case 0x0000002a: + case 0x0000002b: + case 0x0000002c: + case 0x0000002d: + case 0x0000002e: + case 0x0000002f: + case 0x00000030: + params->n = 32; + params->padding_len = 32; + break; + + case 0x00000009: + case 0x0000000a: + case 0x0000000b: + case 0x0000000c: + case 0x0000000d: + case 0x0000000e: + case 0x0000000f: + case 0x00000010: + + case 0x00000019: + case 0x0000001a: + case 0x0000001b: + case 0x0000001c: + case 0x0000001d: + case 0x0000001e: + case 0x0000001f: + case 0x00000020: + params->n = 64; + params->padding_len = 64; + break; + + default: + return -1; + } + switch (oid) { + case 0x00000001: + case 0x00000002: + + case 0x00000009: + case 0x0000000a: + + case 0x00000011: + case 0x00000012: + + case 0x00000019: + case 0x0000001a: + + case 0x00000021: + case 0x00000022: + + case 0x00000029: + case 0x0000002a: + + case 0x00000031: + case 0x00000032: + params->full_height = 20; + break; + + case 0x00000003: + case 0x00000004: + case 0x00000005: + + case 0x0000000b: + case 0x0000000c: + case 0x0000000d: + + case 0x00000013: + case 0x00000014: + case 0x00000015: + + case 0x0000001b: + case 0x0000001c: + case 0x0000001d: + + case 0x00000023: + case 0x00000024: + case 0x00000025: + + case 0x0000002b: + case 0x0000002c: + case 0x0000002d: + + case 0x00000033: + case 0x00000034: + case 0x00000035: + params->full_height = 40; + break; + + case 0x00000006: + case 0x00000007: + case 0x00000008: + + case 0x0000000e: + case 0x0000000f: + case 0x00000010: + + case 0x00000016: + case 0x00000017: + case 0x00000018: + + case 0x0000001e: + case 0x0000001f: + case 0x00000020: + + case 0x00000026: + case 0x00000027: + case 0x00000028: + + case 0x0000002e: + case 0x0000002f: + case 0x00000030: + + case 0x00000036: + case 0x00000037: + case 0x00000038: + params->full_height = 60; + break; + + default: + return -1; + } + switch (oid) { + case 0x00000001: + case 0x00000003: + case 0x00000009: + case 0x0000000b: + case 0x00000011: + case 0x00000013: + case 0x00000019: + case 0x0000001b: + case 0x00000021: + case 0x00000023: + case 0x00000029: + case 0x0000002b: + case 0x00000031: + case 0x00000033: + params->d = 2; + break; + + case 0x00000002: + case 0x00000004: + case 0x0000000a: + case 0x0000000c: + case 0x00000012: + case 0x00000014: + case 0x0000001a: + case 0x0000001c: + case 0x00000022: + case 0x00000024: + case 0x0000002a: + case 0x0000002c: + case 0x00000032: + case 0x00000034: + params->d = 4; + break; + + case 0x00000005: + case 0x0000000d: + case 0x00000015: + case 0x0000001d: + case 0x00000025: + case 0x0000002d: + case 0x00000035: + params->d = 8; + break; + + case 0x00000006: + case 0x0000000e: + case 0x00000016: + case 0x0000001e: + case 0x00000026: + case 0x0000002e: + case 0x00000036: + params->d = 3; + break; + + case 0x00000007: + case 0x0000000f: + case 0x00000017: + case 0x0000001f: + case 0x00000027: + case 0x0000002f: + case 0x00000037: + params->d = 6; + break; + + case 0x00000008: + case 0x00000010: + case 0x00000018: + case 0x00000020: + case 0x00000028: + case 0x00000030: + case 0x00000038: + params->d = 12; + break; + + default: + return -1; + } + + params->wots_w = 16; + + // TODO figure out sensible and legal values for this based on the above + params->bds_k = 0; + + return xmss_xmssmt_initialize_params(params); +} + +/** + * Given a params struct where the following properties have been initialized; + * - full_height; the height of the complete (hyper)tree + * - n; the number of bytes of hash function output + * - d; the number of layers (d > 1 implies XMSSMT) + * - func; one of {XMSS_SHA2, XMSS_SHAKE128, XMSS_SHAKE256} + * - wots_w; the Winternitz parameter + * - optionally, bds_k; the BDS traversal trade-off parameter, + * this function initializes the remainder of the params structure. + */ +int xmss_xmssmt_initialize_params(xmss_params *params) +{ + params->tree_height = params->full_height / params->d; + if (params->wots_w == 4) { + params->wots_log_w = 2; + params->wots_len1 = 8 * params->n / params->wots_log_w; + /* len_2 = floor(log(len_1 * (w - 1)) / log(w)) + 1 */ + params->wots_len2 = 5; + } + else if (params->wots_w == 16) { + params->wots_log_w = 4; + params->wots_len1 = 8 * params->n / params->wots_log_w; + /* len_2 = floor(log(len_1 * (w - 1)) / log(w)) + 1 */ + params->wots_len2 = 3; + } + else if (params->wots_w == 256) { + params->wots_log_w = 8; + params->wots_len1 = 8 * params->n / params->wots_log_w; + /* len_2 = floor(log(len_1 * (w - 1)) / log(w)) + 1 */ + params->wots_len2 = 2; + } + else { + return -1; + } + params->wots_len = params->wots_len1 + params->wots_len2; + params->wots_sig_bytes = params->wots_len * params->n; + + if (params->d == 1) { // Assume this is XMSS, not XMSS^MT + /* In XMSS, always use fixed 4 bytes for index_bytes */ + params->index_bytes = 4; + } + else { + /* In XMSS^MT, round index_bytes up to nearest byte. */ + params->index_bytes = (params->full_height + 7) / 8; + } + params->sig_bytes = (params->index_bytes + params->n + + params->d * params->wots_sig_bytes + + params->full_height * params->n); + + params->pk_bytes = 2 * params->n; + params->sk_bytes = xmss_xmssmt_core_sk_bytes(params); + + return 0; +} diff --git a/src/sig_stfl/xmss/external/params.h b/src/sig_stfl/xmss/external/params.h new file mode 100644 index 0000000000..59b86d3da6 --- /dev/null +++ b/src/sig_stfl/xmss/external/params.h @@ -0,0 +1,78 @@ +#ifndef XMSS_PARAMS_H +#define XMSS_PARAMS_H + +#include +#include "namespace.h" + +/* These are merely internal identifiers for the supported hash functions. */ +#define XMSS_SHA2 0 +#define XMSS_SHAKE128 1 +#define XMSS_SHAKE256 2 + +/* This is a result of the OID definitions in the draft; needed for parsing. */ +#define XMSS_OID_LEN 4 + +/* This structure will be populated when calling xmss[mt]_parse_oid. */ +typedef struct { + unsigned int func; + unsigned int n; + unsigned int padding_len; + unsigned int wots_w; + unsigned int wots_log_w; + unsigned int wots_len1; + unsigned int wots_len2; + unsigned int wots_len; + unsigned int wots_sig_bytes; + unsigned int full_height; + unsigned int tree_height; + unsigned int d; + unsigned int index_bytes; + unsigned int sig_bytes; + unsigned int pk_bytes; + unsigned long long sk_bytes; + unsigned int bds_k; +} xmss_params; + +/** + * Accepts strings such as "XMSS-SHA2_10_256" + * and outputs OIDs such as 0x01000001. + * Returns -1 when the parameter set is not found, 0 otherwise + */ +#define xmss_str_to_oid XMSS_NAMESPACE(xmss_str_to_oid) +int xmss_str_to_oid(uint32_t *oid, const char *s); + +/** + * Accepts takes strings such as "XMSSMT-SHA2_20/2_256" + * and outputs OIDs such as 0x01000001. + * Returns -1 when the parameter set is not found, 0 otherwise + */ +#define xmssmt_str_to_oid XMSS_NAMESPACE(xmssmt_str_to_oid) +int xmssmt_str_to_oid(uint32_t *oid, const char *s); + +/** + * Accepts OIDs such as 0x01000001, and configures params accordingly. + * Returns -1 when the OID is not found, 0 otherwise. + */ +#define xmss_parse_oid XMSS_NAMESPACE(xmss_parse_oid) +int xmss_parse_oid(xmss_params *params, const uint32_t oid); + +/** + * Accepts OIDs such as 0x01000001, and configures params accordingly. + * Returns -1 when the OID is not found, 0 otherwise. + */ +#define xmssmt_parse_oid XMSS_NAMESPACE(xmssmt_parse_oid) +int xmssmt_parse_oid(xmss_params *params, const uint32_t oid); + + +/* Given a params struct where the following properties have been initialized; + - full_height; the height of the complete (hyper)tree + - n; the number of bytes of hash function output + - d; the number of layers (d > 1 implies XMSSMT) + - func; one of {XMSS_SHA2, XMSS_SHAKE128, XMSS_SHAKE256} + - wots_w; the Winternitz parameter + - optionally, bds_k; the BDS traversal trade-off parameter, + this function initializes the remainder of the params structure. */ +#define xmss_xmssmt_initialize_params XMSS_NAMESPACE(xmss_xmssmt_initialize_params) +int xmss_xmssmt_initialize_params(xmss_params *params); + +#endif diff --git a/src/sig_stfl/xmss/external/sign.c b/src/sig_stfl/xmss/external/sign.c new file mode 100644 index 0000000000..8bffc7f516 --- /dev/null +++ b/src/sig_stfl/xmss/external/sign.c @@ -0,0 +1,139 @@ +/*============================================================================= + * Copyright (c) 2022 by SandboxAQ Inc + * Author: Duc Tri Nguyen (ductri.nguyen@sandboxaq.com) + * SPDX-License-Identifier: MIT +=============================================================================*/ +#include +#include + +#include "sign.h" +#include "sign_params.h" + +/************************************************* + * Name: XMSS_crypto_sign_keypair + * + * Description: Generates public and private key. + * + * Arguments: - uint8_t *pk: pointer to output public key (allocated + * array of CRYPTO_PUBLICKEYBYTES bytes) + * - uint8_t *sk: pointer to output private key (allocated + * array of CRYPTO_SECRETKEYBYTES bytes) + * + * Returns 0 (success), -1 otherwise + **************************************************/ +int crypto_sign_keypair(unsigned char *pk, unsigned char *sk) +{ + xmss_params params; + uint32_t oid; + int ret = 0; + + ret |= XMSS_STR_TO_OID(&oid, XMSS_OID); + if (ret) + { + return OQS_ERROR; + } + + ret |= XMSS_PARSE_OID(¶ms, oid); + if (ret) + { + return OQS_ERROR; + } + + // TODO: set OID directly here + ret |= XMSS_KEYPAIR(pk, sk, oid); + if (ret) + { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +/************************************************* + * Name: XMSS_crypto_sign + * + * Description: Computes signature. + * + * Arguments: - uint8_t *sm: pointer to output signature (of length CRYPTO_BYTES) + * - uint64_t *smlen: pointer to output length of signature + * - uint8_t *m: pointer to message to be signed + * - uint64_t mlen: length of message + * - uint8_t *sk: pointer to bit-packed secret key + * + * Returns 0 (success), -1 otherwise + **************************************************/ +int crypto_sign(unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen, unsigned char *sk) +{ + int ret = XMSS_SIGN(sk, sm, smlen, m, mlen); + if (ret) + { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +/************************************************* + * Name: XMSS_crypto_sign_open + * + * Description: Verify signed message. + * + * Arguments: + * - uint8_t *m: pointer to output message (allocated + * array with smlen bytes), can be equal to sm + * - uint64_t *mlen: pointer to output length of message + * - uint8_t *sm: pointer to signed message + * - uint64_t smlen: length of signed message + * - uint8_t *pk: pointer to bit-packed public key + * + * Returns 0 if signed message could be verified correctly and -1 otherwise + **************************************************/ +int crypto_sign_open(const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, const unsigned char *pk) +{ + if (XMSS_SIGN_OPEN(m, mlen, sm, smlen, pk)) + { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +/************************************************* + * Name: XMSS_crypto_remaining_signatures + * + * Description: Return number of remaining signatures + * + * Arguments: - uint64_t *remain: remaining signatures + * - uint8_t *sk: pointer to bit-packed private key + * + * Returns 0 (sucess), -1 otherwise + **************************************************/ +int crypto_remaining_signatures(unsigned long long *remain, const unsigned char *sk) +{ + if (XMSS_REMAINING_SIG(remain, sk)) + { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +/************************************************* + * Name: XMSS_crypto_total_signatures + * + * Description: Return number of total signatures + * + * Arguments: - uint64_t *max: maximum number of signatures + * - uint8_t *sk: pointer to bit-packed private key + * + * Returns 0 (sucess), -1 otherwise + **************************************************/ +int crypto_total_signatures(unsigned long long *max, const unsigned char *sk) +{ + if (XMSS_TOTAL_SIG(max, sk)) + { + return OQS_ERROR; + } + return OQS_SUCCESS; +} diff --git a/src/sig_stfl/xmss/external/sign.h b/src/sig_stfl/xmss/external/sign.h new file mode 100644 index 0000000000..df2c2fb7ca --- /dev/null +++ b/src/sig_stfl/xmss/external/sign.h @@ -0,0 +1,90 @@ +/*============================================================================= + * Copyright (c) 2022 by SandboxAQ Inc + * Author: Duc Tri Nguyen (ductri.nguyen@sandboxaq.com) + * SPDX-License-Identifier: MIT +=============================================================================*/ +#ifndef API_H +#define API_H + +#include +#include "namespace.h" +/************************************************* + * Name: XMSS_crypto_sign_keypair + * + * Description: Generates public and private key. + * + * Arguments: - uint8_t *pk: pointer to output public key (allocated + * array of CRYPTO_PUBLICKEYBYTES bytes) + * - uint8_t *sk: pointer to output private key (allocated + * array of CRYPTO_SECRETKEYBYTES bytes) + * + * Returns 0 (success), -1 otherwise + **************************************************/ +#define crypto_sign_keypair XMSS_NAMESPACE(crypto_sign_keypair) +int crypto_sign_keypair(unsigned char *pk, unsigned char *sk); + +/************************************************* + * Name: XMSS_crypto_sign + * + * Description: Computes signature. + * + * Arguments: - uint8_t *sm: pointer to output signature (of length CRYPTO_BYTES) + * - uint64_t *smlen: pointer to output length of signature + * - uint8_t *m: pointer to message to be signed + * - uint64_t mlen: length of message + * - uint8_t *sk: pointer to bit-packed secret key + * + * Returns 0 (success), -1 otherwise + **************************************************/ +#define crypto_sign XMSS_NAMESPACE(crypto_sign) +int crypto_sign(unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen, unsigned char *sk); + +/************************************************* + * Name: XMSS_crypto_sign_open + * + * Description: Verify signed message. + * + * Arguments: + * - uint8_t *m: pointer to output message (allocated + * array with smlen bytes), can be equal to sm + * - uint64_t *mlen: pointer to output length of message + * - uint8_t *sm: pointer to signed message + * - uint64_t smlen: length of signed message + * - uint8_t *pk: pointer to bit-packed public key + * + * Returns 0 if signed message could be verified correctly and -1 otherwise + **************************************************/ +#define crypto_sign_open XMSS_NAMESPACE(crypto_sign_open) +int crypto_sign_open(const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, const unsigned char *pk); + +/************************************************* + * Name: XMSS_crypto_remaining_signatures + * + * Description: Return number of signatures left + * + * Arguments: - uint64_t *remain: remaining signatures + * - uint8_t *sk: pointer to bit-packed private key + * + * Returns 0 (sucess), -1 otherwise + **************************************************/ +#define crypto_remaining_signatures XMSS_NAMESPACE(crypto_remaining_signatures) +int crypto_remaining_signatures(unsigned long long *remain, const unsigned char *sk); + + +/************************************************* + * Name: XMSS_crypto_total_signatures + * + * Description: Return number of total signatures + * + * Arguments: - uint64_t *max: maximum number of signatures + * - uint8_t *sk: pointer to bit-packed private key + * + * Returns 0 (sucess), -1 otherwise + **************************************************/ +#define crypto_total_signatures XMSS_NAMESPACE(crypto_total_signatures) +int crypto_total_signatures(unsigned long long *max, const unsigned char *sk); + +#endif + diff --git a/src/sig_stfl/xmss/external/sign_params.h b/src/sig_stfl/xmss/external/sign_params.h new file mode 100644 index 0000000000..d9dce53e42 --- /dev/null +++ b/src/sig_stfl/xmss/external/sign_params.h @@ -0,0 +1,142 @@ +#ifndef NIST_PARAM_H +#define NIST_PARAM_H + +#include "params.h" +#include "xmss.h" + +#ifndef TREE_LEVEL +#define TREE_LEVEL 0 +#endif + +#ifndef XMSSMT +#define XMSSMT 0 +#endif + +#if XMSSMT == 0 + /* + * Maximum signatures: 2^h - 1 = 2^10 - 1 + */ + #if TREE_LEVEL == 0 + + #define XMSS_OID "XMSS-SHA2_10_256" + + #define XMSS_PUBLICKEYBYTES 64 + #define XMSS_SECRETKEYBYTES_SMALL 132 + #define XMSS_SECRETKEYBYTES 1373 + + #define XMSS_SIGNBYTES 2500 + + /* + * Maximum signatures: 2^h - 1 = 2^16 - 1 + */ + #elif TREE_LEVEL == 1 + + #define XMSS_OID "XMSS-SHA2_16_256" + + #define XMSS_PUBLICKEYBYTES 64 + #define XMSS_SECRETKEYBYTES_SMALL 132 + #define XMSS_SECRETKEYBYTES 2093 + + #define XMSS_SIGNBYTES 2692 + + /* + * Maximum signatures: 2^h - 1 = 2^20 - 1 + */ + #elif TREE_LEVEL == 2 + + #define XMSS_OID "XMSS-SHA2_20_256" + + #define XMSS_PUBLICKEYBYTES 64 + #define XMSS_SECRETKEYBYTES_SMALL 132 + #define XMSS_SECRETKEYBYTES 2573 + + #define XMSS_SIGNBYTES 2820 + + + #else + + #error "Unspecified TREE_LEVEL {0,1,2}" + + #endif +#else + /* + * Maximum signatures: 2^h - 1 = 2^20 - 1 + * XMSS^MT has bigger signature and secret key (secret is not transfer), but better speed + */ + #if TREE_LEVEL == 0 + + #define XMSS_OID "XMSSMT-SHA2_20/2_256" + + #define XMSS_PUBLICKEYBYTES 64 + #define XMSS_SECRETKEYBYTES_SMALL 131 + #define XMSS_SECRETKEYBYTES 5998 + + #define XMSS_SIGNBYTES 4963 + + /* + * Maximum signatures: 2^h - 1 = 2^40 - 1 + * XMSS^MT has bigger signature and secret key (secret is not transfer), but better speed + */ + #elif TREE_LEVEL == 1 + + #define XMSS_OID "XMSSMT-SHA2_40/2_256" + + #define XMSS_PUBLICKEYBYTES 64 + #define XMSS_SECRETKEYBYTES_SMALL 133 + #define XMSS_SECRETKEYBYTES 9600 + + #define XMSS_SIGNBYTES 5605 + + /* + * Maximum signatures: 2^h - 1 = 2^60 - 1 + * XMSS^MT has bigger signature and secret key (secret is not transfer), but better speed + */ + #elif TREE_LEVEL == 2 + + #define XMSS_OID "XMSSMT-SHA2_60/3_256" + + #define XMSS_PUBLICKEYBYTES 64 + #define XMSS_SECRETKEYBYTES_SMALL 136 + #define XMSS_SECRETKEYBYTES 16629 + + #define XMSS_SIGNBYTES 8392 + + + #else + + #error "Unspecified TREE_LEVEL {0,1,2}" + + #endif + +#endif + +#if XMSSMT == 1 + #define XMSS_PARSE_OID xmssmt_parse_oid + #define XMSS_STR_TO_OID xmssmt_str_to_oid + #define XMSS_KEYPAIR xmssmt_keypair + #define XMSS_SIGN xmssmt_sign + #define XMSS_SIGN_OPEN xmssmt_sign_open + #define XMSS_REMAINING_SIG xmssmt_remaining_signatures + #define XMSS_TOTAL_SIG xmssmt_total_signatures +#else + #define XMSS_PARSE_OID xmss_parse_oid + #define XMSS_STR_TO_OID xmss_str_to_oid + #define XMSS_KEYPAIR xmss_keypair + #define XMSS_SIGN xmss_sign + #define XMSS_SIGN_OPEN xmss_sign_open + #define XMSS_REMAINING_SIG xmss_remaining_signatures + #define XMSS_TOTAL_SIG xmss_total_signatures +#endif + +#if XMSS_SECRETKEYBYTES_SMALL_ENABLE +#define CRYPTO_SECRETKEYBYTES (XMSS_SECRETKEYBYTES_SMALL + XMSS_OID_LEN) +#define CRYPTO_ALGNAME XMSS_OID +#else +#define CRYPTO_SECRETKEYBYTES (XMSS_SECRETKEYBYTES + XMSS_OID_LEN) +#define CRYPTO_ALGNAME (XMSS_OID "_fast") +#endif + +#define CRYPTO_PUBLICKEYBYTES (XMSS_PUBLICKEYBYTES + XMSS_OID_LEN) +#define CRYPTO_BYTES XMSS_SIGNBYTES + +#endif diff --git a/src/sig_stfl/xmss/external/utils.c b/src/sig_stfl/xmss/external/utils.c new file mode 100644 index 0000000000..855f63654d --- /dev/null +++ b/src/sig_stfl/xmss/external/utils.c @@ -0,0 +1,30 @@ +#include "utils.h" + +/** + * Converts the value of 'in' to 'outlen' bytes in big-endian byte order. + */ +void ull_to_bytes(unsigned char *out, unsigned int outlen, + unsigned long long in) +{ + int i; + + /* Iterate over out in decreasing order, for big-endianness. */ + for (i = outlen - 1; i >= 0; i--) { + out[i] = in & 0xff; + in = in >> 8; + } +} + +/** + * Converts the inlen bytes in 'in' from big-endian byte order to an integer. + */ +unsigned long long bytes_to_ull(const unsigned char *in, unsigned int inlen) +{ + unsigned long long retval = 0; + unsigned int i; + + for (i = 0; i < inlen; i++) { + retval |= ((unsigned long long)in[i]) << (8*(inlen - 1 - i)); + } + return retval; +} diff --git a/src/sig_stfl/xmss/external/utils.h b/src/sig_stfl/xmss/external/utils.h new file mode 100644 index 0000000000..0cdf79475a --- /dev/null +++ b/src/sig_stfl/xmss/external/utils.h @@ -0,0 +1,19 @@ +#ifndef XMSS_UTILS_H +#define XMSS_UTILS_H + +#include "namespace.h" + +/** + * Converts the value of 'in' to 'outlen' bytes in big-endian byte order. + */ +#define ull_to_bytes XMSS_INNER_NAMESPACE(ull_to_bytes) +void ull_to_bytes(unsigned char *out, unsigned int outlen, + unsigned long long in); + +/** + * Converts the inlen bytes in 'in' from big-endian byte order to an integer. + */ +#define bytes_to_ull XMSS_INNER_NAMESPACE(bytes_to_ull) +unsigned long long bytes_to_ull(const unsigned char *in, unsigned int inlen); + +#endif diff --git a/src/sig_stfl/xmss/external/wots.c b/src/sig_stfl/xmss/external/wots.c new file mode 100644 index 0000000000..90a6bd74d0 --- /dev/null +++ b/src/sig_stfl/xmss/external/wots.c @@ -0,0 +1,180 @@ +#include +#include + +#include "utils.h" +#include "hash.h" +#include "wots.h" +#include "hash_address.h" +#include "params.h" + +/** + * Helper method for pseudorandom key generation. + * Expands an n-byte array into a len*n byte array using the `prf_keygen` function. + */ +static void expand_seed(const xmss_params *params, + unsigned char *outseeds, const unsigned char *inseed, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + unsigned int i; + unsigned char buf[params->n + 32]; + + set_hash_addr(addr, 0); + set_key_and_mask(addr, 0); + memcpy(buf, pub_seed, params->n); + for (i = 0; i < params->wots_len; i++) { + set_chain_addr(addr, i); + addr_to_bytes(buf + params->n, addr); + prf_keygen(params, outseeds + i*params->n, buf, inseed); + } +} + +/** + * Computes the chaining function. + * out and in have to be n-byte arrays. + * + * Interprets in as start-th value of the chain. + * addr has to contain the address of the chain. + */ +static void gen_chain(const xmss_params *params, + unsigned char *out, const unsigned char *in, + unsigned int start, unsigned int steps, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + unsigned int i; + + /* Initialize out with the value at position 'start'. */ + memcpy(out, in, params->n); + + /* Iterate 'steps' calls to the hash function. */ + for (i = start; i < (start+steps) && i < params->wots_w; i++) { + set_hash_addr(addr, i); + thash_f(params, out, out, pub_seed, addr); + } +} + +/** + * base_w algorithm as described in draft. + * Interprets an array of bytes as integers in base w. + * This only works when log_w is a divisor of 8. + */ +static void base_w(const xmss_params *params, + unsigned int *output, const unsigned int out_len, const unsigned char *input) +{ + unsigned int in = 0; + unsigned int out = 0; + unsigned char total; + unsigned int bits = 0; + unsigned int consumed; + + for (consumed = 0; consumed < out_len; consumed++) { + if (bits == 0) { + total = input[in]; + in++; + bits += 8; + } + bits -= params->wots_log_w; + output[out] = (total >> bits) & (params->wots_w - 1); + out++; + } +} + +/* Computes the WOTS+ checksum over a message (in base_w). */ +static void wots_checksum(const xmss_params *params, + unsigned int *csum_base_w, const unsigned int *msg_base_w) +{ + int csum = 0; + unsigned char csum_bytes[(params->wots_len2 * params->wots_log_w + 7) / 8]; + unsigned int i; + + /* Compute checksum. */ + for (i = 0; i < params->wots_len1; i++) { + csum += params->wots_w - 1 - msg_base_w[i]; + } + + /* Convert checksum to base_w. */ + /* Make sure expected empty zero bits are the least significant bits. */ + csum = csum << (8 - ((params->wots_len2 * params->wots_log_w) % 8)); + ull_to_bytes(csum_bytes, sizeof(csum_bytes), csum); + base_w(params, csum_base_w, params->wots_len2, csum_bytes); +} + +/* Takes a message and derives the matching chain lengths. */ +static void chain_lengths(const xmss_params *params, + unsigned int *lengths, const unsigned char *msg) +{ + base_w(params, lengths, params->wots_len1, msg); + wots_checksum(params, lengths + params->wots_len1, lengths); +} + +/** + * WOTS key generation. Takes a 32 byte seed for the private key, expands it to + * a full WOTS private key and computes the corresponding public key. + * It requires the seed pub_seed (used to generate bitmasks and hash keys) + * and the address of this WOTS key pair. + * + * Writes the computed public key to 'pk'. + */ +void wots_pkgen(const xmss_params *params, + unsigned char *pk, const unsigned char *seed, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + unsigned int i; + + /* The WOTS+ private key is derived from the seed. */ + expand_seed(params, pk, seed, pub_seed, addr); + + for (i = 0; i < params->wots_len; i++) { + set_chain_addr(addr, i); + gen_chain(params, pk + i*params->n, pk + i*params->n, + 0, params->wots_w - 1, pub_seed, addr); + } +} + +/** + * Takes a n-byte message and the 32-byte seed for the private key to compute a + * signature that is placed at 'sig'. + */ +void wots_sign(const xmss_params *params, + unsigned char *sig, const unsigned char *msg, + const unsigned char *seed, const unsigned char *pub_seed, + uint32_t addr[8]) +{ + unsigned int lengths[params->wots_len]; + unsigned int i; + + memset(lengths, 0, sizeof(unsigned int)*params->wots_len); + + chain_lengths(params, lengths, msg); + + /* The WOTS+ private key is derived from the seed. */ + expand_seed(params, sig, seed, pub_seed, addr); + + for (i = 0; i < params->wots_len; i++) { + set_chain_addr(addr, i); + gen_chain(params, sig + i*params->n, sig + i*params->n, + 0, lengths[i], pub_seed, addr); + } +} + +/** + * Takes a WOTS signature and an n-byte message, computes a WOTS public key. + * + * Writes the computed public key to 'pk'. + */ +void wots_pk_from_sig(const xmss_params *params, unsigned char *pk, + const unsigned char *sig, const unsigned char *msg, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + unsigned int lengths[params->wots_len]; + unsigned int i; + + memset(lengths, 0, sizeof(unsigned int)*params->wots_len); + + chain_lengths(params, lengths, msg); + + for (i = 0; i < params->wots_len; i++) { + set_chain_addr(addr, i); + gen_chain(params, pk + i*params->n, sig + i*params->n, + lengths[i], params->wots_w - 1 - lengths[i], pub_seed, addr); + } +} diff --git a/src/sig_stfl/xmss/external/wots.h b/src/sig_stfl/xmss/external/wots.h new file mode 100644 index 0000000000..0ee55b5b10 --- /dev/null +++ b/src/sig_stfl/xmss/external/wots.h @@ -0,0 +1,40 @@ +#ifndef XMSS_WOTS_H +#define XMSS_WOTS_H + +#include +#include "params.h" + +/** + * WOTS key generation. Takes a 32 byte seed for the private key, expands it to + * a full WOTS private key and computes the corresponding public key. + * It requires the seed pub_seed (used to generate bitmasks and hash keys) + * and the address of this WOTS key pair. + * + * Writes the computed public key to 'pk'. + */ +#define wots_pkgen XMSS_INNER_NAMESPACE(wots_pkgen) +void wots_pkgen(const xmss_params *params, + unsigned char *pk, const unsigned char *seed, + const unsigned char *pub_seed, uint32_t addr[8]); + +/** + * Takes a n-byte message and the 32-byte seed for the private key to compute a + * signature that is placed at 'sig'. + */ +#define wots_sign XMSS_INNER_NAMESPACE(wots_sign) +void wots_sign(const xmss_params *params, + unsigned char *sig, const unsigned char *msg, + const unsigned char *seed, const unsigned char *pub_seed, + uint32_t addr[8]); + +/** + * Takes a WOTS signature and an n-byte message, computes a WOTS public key. + * + * Writes the computed public key to 'pk'. + */ +#define wots_pk_from_sig XMSS_INNER_NAMESPACE(wots_pk_from_sig) +void wots_pk_from_sig(const xmss_params *params, unsigned char *pk, + const unsigned char *sig, const unsigned char *msg, + const unsigned char *pub_seed, uint32_t addr[8]); + +#endif diff --git a/src/sig_stfl/xmss/external/xmss.c b/src/sig_stfl/xmss/external/xmss.c new file mode 100644 index 0000000000..401e0deebe --- /dev/null +++ b/src/sig_stfl/xmss/external/xmss.c @@ -0,0 +1,287 @@ +#include + +#include "params.h" +#include "xmss_core.h" +#include "utils.h" +#include "xmss.h" + +/* This file provides wrapper functions that take keys that include OIDs to +identify the parameter set to be used. After setting the parameters accordingly +it falls back to the regular XMSS core functions. */ + +/** + * The function generates a public-private key pair for the XMSS signature scheme using the specified + * OID. + * + * @param pk Pointer to the public key buffer where the generated public key will be stored. + * @param sk sk is a pointer to an unsigned char array that will hold the secret key generated by the + * XMSS key pair generation function. The secret key is used for signing messages and should be kept + * confidential. + * @param oid The `oid` parameter is an identifier for the XMSS variant to be used. It is used to + * determine the parameters for the XMSS algorithm, such as the tree height and the number of signature + * iterations. The `oid` value is typically encoded as a 32-bit integer + * + * @return an integer value. If the function executes successfully, it will return 0. If there is an + * error, it will return -1. + */ +int xmss_keypair(unsigned char *pk, unsigned char *sk, const uint32_t oid) +{ + xmss_params params; + unsigned int i; + + if (xmss_parse_oid(¶ms, oid)) { + return -1; + } + for (i = 0; i < XMSS_OID_LEN; i++) { + pk[XMSS_OID_LEN - i - 1] = (oid >> (8 * i)) & 0xFF; + /* For an implementation that uses runtime parameters, it is crucial + that the OID is part of the secret key as well; + i.e. not just for interoperability, but also for internal use. */ + sk[XMSS_OID_LEN - i - 1] = (oid >> (8 * i)) & 0xFF; + } + return xmss_core_keypair(¶ms, pk + XMSS_OID_LEN, sk + XMSS_OID_LEN); +} + +/** + * This function parses the XMSS OID from a secret key, uses it to determine the XMSS parameters, and + * then calls the core signing function with those parameters. + * + * @param sk The secret key used for signing the message. + * @param sm A pointer to the buffer where the signed message will be stored. + * @param smlen A pointer to a 64-bit unsigned integer that will be used to store the length of the + * signed message (sm) after signing. The length is in bytes. + * @param m The message to be signed, represented as an array of unsigned characters. + * @param mlen The length of the message to be signed, in bytes. + * + * @return an integer value. If the function executes successfully, it will return 0. If there is an + * error, it will return -1. + */ +int xmss_sign(unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen) +{ + xmss_params params; + uint32_t oid = 0; + unsigned int i; + + for (i = 0; i < XMSS_OID_LEN; i++) { + oid |= sk[XMSS_OID_LEN - i - 1] << (i * 8); + } + if (xmss_parse_oid(¶ms, oid)) { + return -1; + } + return xmss_core_sign(¶ms, sk + XMSS_OID_LEN, sm, smlen, m, mlen); +} + +/** + * The function xmss_sign_open verifies a signature and retrieves the original message using the XMSS + * signature scheme. + * + * @param m Pointer to the buffer where the message will be stored after verification. + * @param mlen A pointer to a 64-bit unsigned integer that will be used to store the length of the + * message that is recovered during the signature verification process. + * @param sm The signature to be verified. It is a byte array of length smlen. + * @param smlen smlen is the length of the signature in bytes. + * @param pk pk is a pointer to the public key used for verifying the signature. + * + * @return The function `xmss_sign_open` returns an integer value. If the function is successful, it + * returns 0. If there is an error, it returns -1. + */ +int xmss_sign_open(const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk) +{ + xmss_params params; + uint32_t oid = 0; + unsigned int i; + + for (i = 0; i < XMSS_OID_LEN; i++) { + oid |= pk[XMSS_OID_LEN - i - 1] << (i * 8); + } + if (xmss_parse_oid(¶ms, oid)) { + return -1; + } + return xmss_core_sign_open(¶ms, m, mlen, sm, smlen, pk + XMSS_OID_LEN); +} + +/** + * The function calculates the remaining number of signatures that can be generated using a given XMSS + * private key. + * + * @param remain a pointer to a uint64_t variable that will store the number of remaining signatures + * that can be generated with the given secret key. + * @param sk The `sk` parameter is a pointer to an array of unsigned characters representing the secret + * key used in the XMSS signature scheme. + * + * @return This function returns an integer value. If the function executes successfully, it returns 0. + * If there is an error, it returns -1. + */ +int xmss_remaining_signatures(unsigned long long *remain, const unsigned char *sk) +{ + xmss_params params; + uint32_t oid = 0; + unsigned int i; + unsigned long long idx, max; + + for (i = 0; i < XMSS_OID_LEN; i++) { + oid |= sk[XMSS_OID_LEN - i - 1] << (i * 8); + } + + if (xmss_parse_oid(¶ms, oid)) { + *remain = 0; + return -1; + } + + idx = bytes_to_ull(sk + XMSS_OID_LEN, params.index_bytes); + max = ((1ULL << params.full_height) - 1); + + *remain = max - idx; + + return 0; +} + +/** + * The function calculates the maximum number of signatures that can be generated for a given XMSS private key. + * + * @param max a pointer to an unsigned long long variable that will store the maximum number of + * signatures that can be generated with the given XMSS private key. + * @param sk The secret key used for XMSS signature scheme. It is a pointer to an array of unsigned + * characters. + * + * @return an integer value. If the XMSS OID cannot be parsed, it returns -1. Otherwise, it sets the + * value of the variable pointed to by the "max" parameter to the maximum number of signatures that can + * be generated with the given XMSS private key and returns 0. + */ +int xmss_total_signatures(unsigned long long *max, const unsigned char *sk) +{ + xmss_params params; + uint32_t oid = 0; + + for (unsigned i = 0; i < XMSS_OID_LEN; i++) { + oid |= sk[XMSS_OID_LEN - i - 1] << (i * 8); + } + + if (xmss_parse_oid(¶ms, oid)) { + *max = 0; + return -1; + } + + *max = ((1ULL << params.full_height) - 1); + + return 0; +} + +int xmssmt_keypair(unsigned char *pk, unsigned char *sk, const uint32_t oid) +{ + xmss_params params; + unsigned int i; + + if (xmssmt_parse_oid(¶ms, oid)) { + return -1; + } + for (i = 0; i < XMSS_OID_LEN; i++) { + pk[XMSS_OID_LEN - i - 1] = (oid >> (8 * i)) & 0xFF; + sk[XMSS_OID_LEN - i - 1] = (oid >> (8 * i)) & 0xFF; + } + return xmssmt_core_keypair(¶ms, pk + XMSS_OID_LEN, sk + XMSS_OID_LEN); +} + +int xmssmt_sign(unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen) +{ + xmss_params params; + uint32_t oid = 0; + unsigned int i; + + for (i = 0; i < XMSS_OID_LEN; i++) { + oid |= sk[XMSS_OID_LEN - i - 1] << (i * 8); + } + if (xmssmt_parse_oid(¶ms, oid)) { + return -1; + } + return xmssmt_core_sign(¶ms, sk + XMSS_OID_LEN, sm, smlen, m, mlen); +} + +int xmssmt_sign_open(const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk) +{ + xmss_params params; + uint32_t oid = 0; + unsigned int i; + + for (i = 0; i < XMSS_OID_LEN; i++) { + oid |= pk[XMSS_OID_LEN - i - 1] << (i * 8); + } + if (xmssmt_parse_oid(¶ms, oid)) { + return -1; + } + return xmssmt_core_sign_open(¶ms, m, mlen, sm, smlen, pk + XMSS_OID_LEN); +} + + +/** + * The function calculates the remaining number of signatures that can be generated using a given + * XMSSMT private key. + * + * @param remain a pointer to an unsigned long long variable that will store the number of remaining + * signatures that can be generated using the given secret key. + * @param sk The `sk` parameter is a pointer to an array of unsigned characters representing the secret + * key used in the XMSSMT signature scheme. + * + * @return This function returns an integer value. If the function executes successfully, it returns 0. + * If there is an error, it returns -1. + */ +int xmssmt_remaining_signatures(unsigned long long *remain, const unsigned char *sk) +{ + xmss_params params; + uint32_t oid = 0; + unsigned int i; + unsigned long long idx, max; + + for (i = 0; i < XMSS_OID_LEN; i++) { + oid |= sk[XMSS_OID_LEN - i - 1] << (i * 8); + } + + if (xmssmt_parse_oid(¶ms, oid)) { + *remain = 0; + return -1; + } + + idx = bytes_to_ull(sk + XMSS_OID_LEN, params.index_bytes); + max = ((1ULL << params.full_height) - 1); + + *remain = max - idx; + + return 0; +} + +/** + * The function calculates the maximum number of signatures that can be generated for a given XMSSMT private key. + * + * @param max a pointer to an unsigned long long variable that will store the maximum number of + * signatures that can be generated with the given secret key. + * @param sk The `sk` parameter is a pointer to an array of unsigned characters representing the secret + * key used in the XMSS signature scheme. + * + * @return an integer value. If the XMSS OID cannot be parsed, it returns -1. Otherwise, it returns 0. + */ +int xmssmt_total_signatures(unsigned long long *max, const unsigned char *sk) +{ + xmss_params params; + uint32_t oid = 0; + + for (unsigned i = 0; i < XMSS_OID_LEN; i++) { + oid |= sk[XMSS_OID_LEN - i - 1] << (i * 8); + } + + if (xmss_parse_oid(¶ms, oid)) { + *max = 0; + return -1; + } + + *max = ((1ULL << params.full_height) - 1); + + return 0; +} diff --git a/src/sig_stfl/xmss/external/xmss.h b/src/sig_stfl/xmss/external/xmss.h new file mode 100644 index 0000000000..b21db845d3 --- /dev/null +++ b/src/sig_stfl/xmss/external/xmss.h @@ -0,0 +1,93 @@ +#ifndef XMSS_H +#define XMSS_H + +#include +#include "namespace.h" + +/** + * Generates a XMSS key pair for a given parameter set. + * Format sk: [OID || (32bit) idx || SK_SEED || SK_PRF || PUB_SEED || root] + * Format pk: [OID || root || PUB_SEED] + */ +#define xmss_keypair XMSS_NAMESPACE(xmss_keypair) +int xmss_keypair(unsigned char *pk, unsigned char *sk, const uint32_t oid); + +/** + * Signs a message using an XMSS secret key. + * Returns + * 1. an array containing the signature followed by the message AND + * 2. an updated secret key! + */ +#define xmss_sign XMSS_NAMESPACE(xmss_sign) +int xmss_sign(unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen); + +/** + * Verifies a given message signature pair using a given public key. + * + * Note: m and mlen are pure outputs which carry the message in case + * verification succeeds. The (input) message is assumed to be contained in sm + * which has the form [signature || message]. + */ +#define xmss_sign_open XMSS_NAMESPACE(xmss_sign_open) +int xmss_sign_open(const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk); + +/* + * Write number of remaining signature to `remain` variable given `sk` + */ +#define xmss_remaining_signatures XMSS_NAMESPACE(xmss_remaining_signatures) +int xmss_remaining_signatures(unsigned long long *remain, const unsigned char *sk); + +/* + * Write number of maximum signature to `max` variable given `sk` + */ +#define xmss_total_signatures XMSS_NAMESPACE(xmss_total_signatures) +int xmss_total_signatures(unsigned long long *max, const unsigned char *sk); + +/* + * Generates a XMSSMT key pair for a given parameter set. + * Format sk: [OID || (ceil(h/8) bit) idx || SK_SEED || SK_PRF || PUB_SEED || root] + * Format pk: [OID || root || PUB_SEED] + */ +#define xmssmt_keypair XMSS_NAMESPACE(xmssmt_keypair) +int xmssmt_keypair(unsigned char *pk, unsigned char *sk, const uint32_t oid); + +/** + * Signs a message using an XMSSMT secret key. + * Returns + * 1. an array containing the signature followed by the message AND + * 2. an updated secret key! + */ +#define xmssmt_sign XMSS_NAMESPACE(xmssmt_sign) +int xmssmt_sign(unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen); + +/** + * Verifies a given message signature pair using a given public key. + * + * Note: m and mlen are pure outputs which carry the message in case + * verification succeeds. The (input) message is assumed to be contained in sm + * which has the form [signature || message]. + */ +#define xmssmt_sign_open XMSS_NAMESPACE(xmssmt_sign_open) +int xmssmt_sign_open(const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk); + +/* + * Write number of remaining signature to `remain` variable given `sk` + */ +#define xmssmt_remaining_signatures XMSS_NAMESPACE(xmssmt_remaining_signatures) +int xmssmt_remaining_signatures(unsigned long long *remain, const unsigned char *sk); + +/* + * Write number of maximum signature to `max` variable given `sk` + */ +#define xmssmt_total_signatures XMSS_NAMESPACE(xmssmt_total_signatures) +int xmssmt_total_signatures(unsigned long long *max, const unsigned char *sk); + +#endif diff --git a/src/sig_stfl/xmss/external/xmss_commons.c b/src/sig_stfl/xmss/external/xmss_commons.c new file mode 100644 index 0000000000..882a3e39d6 --- /dev/null +++ b/src/sig_stfl/xmss/external/xmss_commons.c @@ -0,0 +1,216 @@ +#include +#include +#include + +#include "hash.h" +#include "hash_address.h" +#include "params.h" +#include "wots.h" +#include "utils.h" +#include "xmss_commons.h" + +/** + * Computes a leaf node from a WOTS public key using an L-tree. + * Note that this destroys the used WOTS public key. + */ +static void l_tree(const xmss_params *params, + unsigned char *leaf, unsigned char *wots_pk, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + unsigned int l = params->wots_len; + unsigned int parent_nodes; + uint32_t i; + uint32_t height = 0; + + set_tree_height(addr, height); + + while (l > 1) { + parent_nodes = l >> 1; + for (i = 0; i < parent_nodes; i++) { + set_tree_index(addr, i); + /* Hashes the nodes at (i*2)*params->n and (i*2)*params->n + 1 */ + thash_h(params, wots_pk + i*params->n, + wots_pk + (i*2)*params->n, pub_seed, addr); + } + /* If the row contained an odd number of nodes, the last node was not + hashed. Instead, we pull it up to the next layer. */ + if (l & 1) { + memcpy(wots_pk + (l >> 1)*params->n, + wots_pk + (l - 1)*params->n, params->n); + l = (l >> 1) + 1; + } + else { + l = l >> 1; + } + height++; + set_tree_height(addr, height); + } + memcpy(leaf, wots_pk, params->n); +} + +/** + * Computes a root node given a leaf and an auth path + */ +static void compute_root(const xmss_params *params, unsigned char *root, + const unsigned char *leaf, unsigned long leafidx, + const unsigned char *auth_path, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + uint32_t i; + unsigned char buffer[2*params->n]; + + /* If leafidx is odd (last bit = 1), current path element is a right child + and auth_path has to go left. Otherwise it is the other way around. */ + if (leafidx & 1) { + memcpy(buffer + params->n, leaf, params->n); + memcpy(buffer, auth_path, params->n); + } + else { + memcpy(buffer, leaf, params->n); + memcpy(buffer + params->n, auth_path, params->n); + } + auth_path += params->n; + + for (i = 0; i < params->tree_height - 1; i++) { + set_tree_height(addr, i); + leafidx >>= 1; + set_tree_index(addr, leafidx); + + /* Pick the right or left neighbor, depending on parity of the node. */ + if (leafidx & 1) { + thash_h(params, buffer + params->n, buffer, pub_seed, addr); + memcpy(buffer, auth_path, params->n); + } + else { + thash_h(params, buffer, buffer, pub_seed, addr); + memcpy(buffer + params->n, auth_path, params->n); + } + auth_path += params->n; + } + + /* The last iteration is exceptional; we do not copy an auth_path node. */ + set_tree_height(addr, params->tree_height - 1); + leafidx >>= 1; + set_tree_index(addr, leafidx); + thash_h(params, root, buffer, pub_seed, addr); +} + + +/** + * Computes the leaf at a given address. First generates the WOTS key pair, + * then computes leaf using l_tree. As this happens position independent, we + * only require that addr encodes the right ltree-address. + */ +void gen_leaf_wots(const xmss_params *params, unsigned char *leaf, + const unsigned char *sk_seed, const unsigned char *pub_seed, + uint32_t ltree_addr[8], uint32_t ots_addr[8]) +{ + unsigned char pk[params->wots_sig_bytes]; + + wots_pkgen(params, pk, sk_seed, pub_seed, ots_addr); + + l_tree(params, leaf, pk, pub_seed, ltree_addr); +} + + +/** + * Verifies a given message signature pair under a given public key. + * Note that this assumes a pk without an OID, i.e. [root || PUB_SEED] + */ +int xmss_core_sign_open(const xmss_params *params, + const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk) +{ + /* XMSS signatures are fundamentally an instance of XMSSMT signatures. + For d=1, as is the case with XMSS, some of the calls in the XMSSMT + routine become vacuous (i.e. the loop only iterates once, and address + management can be simplified a bit).*/ + return xmssmt_core_sign_open(params, m, mlen, sm, smlen, pk); +} + +/** + * Verifies a given message signature pair under a given public key. + * Note that this assumes a pk without an OID, i.e. [root || PUB_SEED] + */ +int xmssmt_core_sign_open(const xmss_params *params, + const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk) +{ + const unsigned char *pub_root = pk; + const unsigned char *pub_seed = pk + params->n; + unsigned char wots_pk[params->wots_sig_bytes]; + unsigned char leaf[params->n]; + unsigned char root[params->n]; + + unsigned long long prefix_length = params->padding_len + 3*params->n; + unsigned char m_with_prefix[mlen + prefix_length]; + + unsigned char *mhash = root; + unsigned long long idx = 0; + unsigned int i; + uint32_t idx_leaf; + + uint32_t ots_addr[8] = {0}; + uint32_t ltree_addr[8] = {0}; + uint32_t node_addr[8] = {0}; + + set_type(ots_addr, XMSS_ADDR_TYPE_OTS); + set_type(ltree_addr, XMSS_ADDR_TYPE_LTREE); + set_type(node_addr, XMSS_ADDR_TYPE_HASHTREE); + + // Unused since smlen is a constant + (void) smlen; + + /* Convert the index bytes from the signature to an integer. */ + idx = bytes_to_ull(sm, params->index_bytes); + + /* Put the message at the m_with_prefix buffer, so that we can + * prepend the required other inputs for the hash function. */ + memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); + memcpy(m_with_prefix + prefix_length, m, mlen); + + /* Compute the message hash. */ + hash_message(params, mhash, sm + params->index_bytes, pk, idx, + m_with_prefix, + mlen); + sm += params->index_bytes + params->n; + + /* For each subtree.. */ + for (i = 0; i < params->d; i++) { + idx_leaf = (idx & ((1 << params->tree_height)-1)); + idx = idx >> params->tree_height; + + set_layer_addr(ots_addr, i); + set_layer_addr(ltree_addr, i); + set_layer_addr(node_addr, i); + + set_tree_addr(ltree_addr, idx); + set_tree_addr(ots_addr, idx); + set_tree_addr(node_addr, idx); + + /* The WOTS public key is only correct if the signature was correct. */ + set_ots_addr(ots_addr, idx_leaf); + /* Initially, root = mhash, but on subsequent iterations it is the root + of the subtree below the currently processed subtree. */ + wots_pk_from_sig(params, wots_pk, sm, root, pub_seed, ots_addr); + sm += params->wots_sig_bytes; + + /* Compute the leaf node using the WOTS public key. */ + set_ltree_addr(ltree_addr, idx_leaf); + l_tree(params, leaf, wots_pk, pub_seed, ltree_addr); + + /* Compute the root node of this subtree. */ + compute_root(params, root, leaf, idx_leaf, sm, pub_seed, node_addr); + sm += params->tree_height*params->n; + } + + /* Check if the root node equals the root node in the public key. */ + if (memcmp(root, pub_root, params->n)) { + /* If not, return fail */ + return -1; + } + + return 0; +} diff --git a/src/sig_stfl/xmss/external/xmss_commons.h b/src/sig_stfl/xmss/external/xmss_commons.h new file mode 100644 index 0000000000..dbe841c6bf --- /dev/null +++ b/src/sig_stfl/xmss/external/xmss_commons.h @@ -0,0 +1,36 @@ +#ifndef XMSS_COMMONS_H +#define XMSS_COMMONS_H + +#include +#include "params.h" + +/** + * Computes the leaf at a given address. First generates the WOTS key pair, + * then computes leaf using l_tree. As this happens position independent, we + * only require that addr encodes the right ltree-address. + */ +#define gen_leaf_wots XMSS_INNER_NAMESPACE(gen_leaf_wots) +void gen_leaf_wots(const xmss_params *params, unsigned char *leaf, + const unsigned char *sk_seed, const unsigned char *pub_seed, + uint32_t ltree_addr[8], uint32_t ots_addr[8]); + +/** + * Verifies a given message signature pair under a given public key. + * Note that this assumes a pk without an OID, i.e. [root || PUB_SEED] + */ +#define xmss_core_sign_open XMSS_INNER_NAMESPACE(xmss_core_sign_open) +int xmss_core_sign_open(const xmss_params *params, + const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk); + +/** + * Verifies a given message signature pair under a given public key. + * Note that this assumes a pk without an OID, i.e. [root || PUB_SEED] + */ +#define xmssmt_core_sign_open XMSS_INNER_NAMESPACE(xmssmt_core_sign_open) +int xmssmt_core_sign_open(const xmss_params *params, + const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk); +#endif diff --git a/src/sig_stfl/xmss/external/xmss_core.c b/src/sig_stfl/xmss/external/xmss_core.c new file mode 100644 index 0000000000..daaf6aa6e4 --- /dev/null +++ b/src/sig_stfl/xmss/external/xmss_core.c @@ -0,0 +1,277 @@ +#include +#include +#include +#include + +#include "hash.h" +#include "hash_address.h" +#include "params.h" +#include "wots.h" +#include "utils.h" +#include "xmss_commons.h" +#include "xmss_core.h" + +/** + * For a given leaf index, computes the authentication path and the resulting + * root node using Merkle's TreeHash algorithm. + * Expects the layer and tree parts of subtree_addr to be set. + */ +static void treehash(const xmss_params *params, + unsigned char *root, unsigned char *auth_path, + const unsigned char *sk_seed, + const unsigned char *pub_seed, + uint32_t leaf_idx, const uint32_t subtree_addr[8]) +{ + unsigned char stack[(params->tree_height+1)*params->n]; + unsigned int heights[params->tree_height+1]; + unsigned int offset = 0; + + /* The subtree has at most 2^20 leafs, so uint32_t suffices. */ + uint32_t idx; + uint32_t tree_idx; + + /* We need all three types of addresses in parallel. */ + uint32_t ots_addr[8] = {0}; + uint32_t ltree_addr[8] = {0}; + uint32_t node_addr[8] = {0}; + + /* Select the required subtree. */ + copy_subtree_addr(ots_addr, subtree_addr); + copy_subtree_addr(ltree_addr, subtree_addr); + copy_subtree_addr(node_addr, subtree_addr); + + set_type(ots_addr, XMSS_ADDR_TYPE_OTS); + set_type(ltree_addr, XMSS_ADDR_TYPE_LTREE); + set_type(node_addr, XMSS_ADDR_TYPE_HASHTREE); + + for (idx = 0; idx < (uint32_t)(1 << params->tree_height); idx++) { + /* Add the next leaf node to the stack. */ + set_ltree_addr(ltree_addr, idx); + set_ots_addr(ots_addr, idx); + gen_leaf_wots(params, stack + offset*params->n, + sk_seed, pub_seed, ltree_addr, ots_addr); + offset++; + heights[offset - 1] = 0; + + /* If this is a node we need for the auth path.. */ + if ((leaf_idx ^ 0x1) == idx) { + memcpy(auth_path, stack + (offset - 1)*params->n, params->n); + } + + /* While the top-most nodes are of equal height.. */ + while (offset >= 2 && heights[offset - 1] == heights[offset - 2]) { + /* Compute index of the new node, in the next layer. */ + tree_idx = (idx >> (heights[offset - 1] + 1)); + + /* Hash the top-most nodes from the stack together. */ + /* Note that tree height is the 'lower' layer, even though we use + the index of the new node on the 'higher' layer. This follows + from the fact that we address the hash function calls. */ + set_tree_height(node_addr, heights[offset - 1]); + set_tree_index(node_addr, tree_idx); + thash_h(params, stack + (offset-2)*params->n, + stack + (offset-2)*params->n, pub_seed, node_addr); + offset--; + /* Note that the top-most node is now one layer higher. */ + heights[offset - 1]++; + + /* If this is a node we need for the auth path.. */ + if (((leaf_idx >> heights[offset - 1]) ^ 0x1) == tree_idx) { + memcpy(auth_path + heights[offset - 1]*params->n, + stack + (offset - 1)*params->n, params->n); + } + } + } + memcpy(root, stack, params->n); +} + +/** + * Given a set of parameters, this function returns the size of the secret key. + * This is implementation specific, as varying choices in tree traversal will + * result in varying requirements for state storage. + */ +unsigned long long xmss_xmssmt_core_sk_bytes(const xmss_params *params) +{ + return params->index_bytes + 4 * params->n; +} + +/* + * Generates a XMSS key pair for a given parameter set. + * Format sk: [(32bit) index || SK_SEED || SK_PRF || root || PUB_SEED] + * Format pk: [root || PUB_SEED], omitting algorithm OID. + */ +int xmss_core_keypair(const xmss_params *params, + unsigned char *pk, unsigned char *sk) +{ + /* The key generation procedure of XMSS and XMSSMT is exactly the same. + The only important detail is that the right subtree must be selected; + this requires us to correctly set the d=1 parameter for XMSS. */ + return xmssmt_core_keypair(params, pk, sk); +} + +/** + * Signs a message. Returns an array containing the signature followed by the + * message and an updated secret key. + */ +int xmss_core_sign(const xmss_params *params, + unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen) +{ + /* XMSS signatures are fundamentally an instance of XMSSMT signatures. + For d=1, as is the case with XMSS, some of the calls in the XMSSMT + routine become vacuous (i.e. the loop only iterates once, and address + management can be simplified a bit).*/ + return xmssmt_core_sign(params, sk, sm, smlen, m, mlen); +} + +/* + * Derives a XMSSMT key pair for a given parameter set. + * Seed must be 3*n long. + * Format sk: [(ceil(h/8) bit) index || SK_SEED || SK_PRF || root || PUB_SEED] + * Format pk: [root || PUB_SEED] omitting algorithm OID. + */ +int xmssmt_core_seed_keypair(const xmss_params *params, + unsigned char *pk, unsigned char *sk, + unsigned char *seed) +{ + /* We do not need the auth path in key generation, but it simplifies the + code to have just one treehash routine that computes both root and path + in one function. */ + unsigned char auth_path[params->tree_height * params->n]; + uint32_t top_tree_addr[8] = {0}; + set_layer_addr(top_tree_addr, params->d - 1); + + /* Initialize index to 0. */ + memset(sk, 0, params->index_bytes); + sk += params->index_bytes; + + /* Initialize SK_SEED and SK_PRF. */ + memcpy(sk, seed, 2 * params->n); + + /* Initialize PUB_SEED. */ + memcpy(sk + 3 * params->n, seed + 2 * params->n, params->n); + memcpy(pk + params->n, sk + 3*params->n, params->n); + + /* Compute root node of the top-most subtree. */ + treehash(params, pk, auth_path, sk, pk + params->n, 0, top_tree_addr); + memcpy(sk + 2*params->n, pk, params->n); + + return 0; +} + +/* + * Generates a XMSSMT key pair for a given parameter set. + * Format sk: [(ceil(h/8) bit) index || SK_SEED || SK_PRF || root || PUB_SEED] + * Format pk: [root || PUB_SEED] omitting algorithm OID. + */ +int xmssmt_core_keypair(const xmss_params *params, + unsigned char *pk, unsigned char *sk) +{ + unsigned char seed[3 * params->n]; + + OQS_randombytes(seed, 3 * params->n); + xmssmt_core_seed_keypair(params, pk, sk, seed); + + return 0; +} + +/** + * Signs a message. Returns an array containing the signature followed by the + * message and an updated secret key. + */ +int xmssmt_core_sign(const xmss_params *params, + unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen) +{ + const unsigned char *sk_seed = sk + params->index_bytes; + const unsigned char *sk_prf = sk + params->index_bytes + params->n; + const unsigned char *pub_root = sk + params->index_bytes + 2*params->n; + const unsigned char *pub_seed = sk + params->index_bytes + 3*params->n; + + unsigned long long prefix_length = params->padding_len + 3*params->n; + unsigned char m_with_prefix[mlen + prefix_length]; + + unsigned char root[params->n]; + unsigned char *mhash = root; + unsigned long long idx; + unsigned char idx_bytes_32[32]; + unsigned int i; + uint32_t idx_leaf; + + uint32_t ots_addr[8] = {0}; + set_type(ots_addr, XMSS_ADDR_TYPE_OTS); + + /* Already put the message in the right place, to make it easier to prepend + * things when computing the hash over the message. */ + memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); + memcpy(m_with_prefix + prefix_length, m, mlen); + *smlen = params->sig_bytes; + + /* Read and use the current index from the secret key. */ + idx = (unsigned long)bytes_to_ull(sk, params->index_bytes); + + /* Check if we can still sign with this sk. + * If not, return -2 + * + * If this is the last possible signature (because the max index value + * is reached), production implementations should delete the secret key + * to prevent accidental further use. + * + * For the case of total tree height of 64 we do not use the last signature + * to be on the safe side (there is no index value left to indicate that the + * key is finished, hence external handling would be necessary) + */ + if (idx >= ((1ULL << params->full_height) - 1)) { + // Delete secret key here. We only do this in memory, production code + // has to make sure that this happens on disk. + memset(sk, 0xFF, params->index_bytes); + memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); + if (idx > ((1ULL << params->full_height) - 1)) + return -2; // We already used all one-time keys + if ((params->full_height == 64) && (idx == UINT64_MAX)) + return -2; // We already used all one-time keys + } + + memcpy(sm, sk, params->index_bytes); + + /************************************************************************* + * THIS IS WHERE PRODUCTION IMPLEMENTATIONS WOULD UPDATE THE SECRET KEY. * + *************************************************************************/ + /* Increment the index in the secret key. */ + ull_to_bytes(sk, params->index_bytes, idx + 1); + + /* Compute the digest randomization value. */ + ull_to_bytes(idx_bytes_32, 32, idx); + prf(params, sm + params->index_bytes, idx_bytes_32, sk_prf); + + /* Compute the message hash. */ + hash_message(params, mhash, sm + params->index_bytes, pub_root, idx, + m_with_prefix, + mlen); + sm += params->index_bytes + params->n; + + set_type(ots_addr, XMSS_ADDR_TYPE_OTS); + + for (i = 0; i < params->d; i++) { + idx_leaf = (idx & ((1 << params->tree_height)-1)); + idx = idx >> params->tree_height; + + set_layer_addr(ots_addr, i); + set_tree_addr(ots_addr, idx); + set_ots_addr(ots_addr, idx_leaf); + + /* Compute a WOTS signature. */ + /* Initially, root = mhash, but on subsequent iterations it is the root + of the subtree below the currently processed subtree. */ + wots_sign(params, sm, root, sk_seed, pub_seed, ots_addr); + sm += params->wots_sig_bytes; + + /* Compute the authentication path for the used WOTS leaf. */ + treehash(params, root, sm, sk_seed, pub_seed, idx_leaf, ots_addr); + sm += params->tree_height*params->n; + } + + return 0; +} diff --git a/src/sig_stfl/xmss/external/xmss_core.h b/src/sig_stfl/xmss/external/xmss_core.h new file mode 100644 index 0000000000..bed99862c5 --- /dev/null +++ b/src/sig_stfl/xmss/external/xmss_core.h @@ -0,0 +1,85 @@ +#ifndef XMSS_CORE_H +#define XMSS_CORE_H + +#include "params.h" + +/** + * Given a set of parameters, this function returns the size of the secret key. + * This is implementation specific, as varying choices in tree traversal will + * result in varying requirements for state storage. + * + * This function handles both XMSS and XMSSMT parameter sets. + */ +#define xmss_xmssmt_core_sk_bytes XMSS_INNER_NAMESPACE(xmss_xmssmt_core_sk_bytes) +unsigned long long xmss_xmssmt_core_sk_bytes(const xmss_params *params); + +/* + * Generates a XMSS key pair for a given parameter set. + * Format sk: [(32bit) index || SK_SEED || SK_PRF || PUB_SEED || root] + * Format pk: [root || PUB_SEED], omitting algorithm OID. + */ +#define xmss_core_keypair XMSS_INNER_NAMESPACE(xmss_core_keypair) +int xmss_core_keypair(const xmss_params *params, + unsigned char *pk, unsigned char *sk); + +/** + * Signs a message. Returns an array containing the signature followed by the + * message and an updated secret key. + */ +#define xmss_core_sign XMSS_INNER_NAMESPACE(xmss_core_sign) +int xmss_core_sign(const xmss_params *params, + unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen); + +/** + * Verifies a given message signature pair under a given public key. + * Note that this assumes a pk without an OID, i.e. [root || PUB_SEED] + */ +#define xmss_core_sign_open XMSS_INNER_NAMESPACE(xmss_core_sign_open) +int xmss_core_sign_open(const xmss_params *params, + const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk); + +/* + * Generates a XMSSMT key pair for a given parameter set. + * Format sk: [(ceil(h/8) bit) index || SK_SEED || SK_PRF || PUB_SEED || root] + * Format pk: [root || PUB_SEED] omitting algorithm OID. + */ +#define xmssmt_core_keypair XMSS_INNER_NAMESPACE(xmssmt_core_keypair) +int xmssmt_core_keypair(const xmss_params *params, + unsigned char *pk, unsigned char *sk); + +/* + * Derives a XMSSMT key pair for a given parameter set. + * Seed must be 3*n long. + * Format sk: [(ceil(h/8) bit) index || SK_SEED || SK_PRF || root || PUB_SEED] + * Format pk: [root || PUB_SEED] omitting algorithm OID. + */ +#define xmssmt_core_seed_keypair XMSS_INNER_NAMESPACE(xmssmt_core_seed_keypair) +int xmssmt_core_seed_keypair(const xmss_params *params, + unsigned char *pk, unsigned char *sk, + unsigned char *seed); + +/** + * Signs a message. Returns an array containing the signature followed by the + * message and an updated secret key. + */ +#define xmssmt_core_sign XMSS_INNER_NAMESPACE(xmssmt_core_sign) +int xmssmt_core_sign(const xmss_params *params, + unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen); + +/** + * Verifies a given message signature pair under a given public key. + * Note that this assumes a pk without an OID, i.e. [root || PUB_SEED] + */ +#define xmssmt_core_sign_open XMSS_INNER_NAMESPACE(xmssmt_core_sign_open) +int xmssmt_core_sign_open(const xmss_params *params, + const unsigned char *m, unsigned long long mlen, + const unsigned char *sm, unsigned long long smlen, + const unsigned char *pk); + +#endif diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c new file mode 100644 index 0000000000..c0517cbb29 --- /dev/null +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -0,0 +1,988 @@ +#include +#include +#include +#include + +#include "hash.h" +#include "hash_address.h" +#include "params.h" +#include "wots.h" +#include "utils.h" +#include "xmss_commons.h" +#include "xmss_core.h" + +typedef struct{ + unsigned char h; + unsigned long next_idx; + unsigned char stackusage; + unsigned char completed; + unsigned char *node; +} treehash_inst; + +typedef struct { + unsigned char *stack; + unsigned int stackoffset; + unsigned char *stacklevels; + unsigned char *auth; + unsigned char *keep; + treehash_inst *treehash; + unsigned char *retain; + unsigned int next_leaf; +} bds_state; + +/* These serialization functions provide a transition between the current + way of storing the state in an exposed struct, and storing it as part of the + byte array that is the secret key. + They will probably be refactored in a non-backwards-compatible way, soon. */ + +static void xmssmt_serialize_state(const xmss_params *params, + unsigned char *sk, bds_state *states) +{ + unsigned int i, j; + + /* Skip past the 'regular' sk */ + sk += params->index_bytes + 4*params->n; + + for (i = 0; i < 2*params->d - 1; i++) { + sk += (params->tree_height + 1) * params->n; /* stack */ + + ull_to_bytes(sk, 4, states[i].stackoffset); + sk += 4; + + sk += params->tree_height + 1; /* stacklevels */ + sk += params->tree_height * params->n; /* auth */ + sk += (params->tree_height >> 1) * params->n; /* keep */ + + for (j = 0; j < params->tree_height - params->bds_k; j++) { + ull_to_bytes(sk, 1, states[i].treehash[j].h); + sk += 1; + + ull_to_bytes(sk, 4, states[i].treehash[j].next_idx); + sk += 4; + + ull_to_bytes(sk, 1, states[i].treehash[j].stackusage); + sk += 1; + + ull_to_bytes(sk, 1, states[i].treehash[j].completed); + sk += 1; + + sk += params->n; /* node */ + } + + /* retain */ + sk += ((1 << params->bds_k) - params->bds_k - 1) * params->n; + + ull_to_bytes(sk, 4, states[i].next_leaf); + sk += 4; + } +} + +static void xmssmt_deserialize_state(const xmss_params *params, + bds_state *states, + unsigned char **wots_sigs, + unsigned char *sk) +{ + unsigned int i, j; + + /* Skip past the 'regular' sk */ + sk += params->index_bytes + 4*params->n; + + // TODO These data sizes follow from the (former) test xmss_core_fast.c + // TODO They should be reconsidered / motivated more explicitly + + for (i = 0; i < 2*params->d - 1; i++) { + states[i].stack = sk; + sk += (params->tree_height + 1) * params->n; + + states[i].stackoffset = bytes_to_ull(sk, 4); + sk += 4; + + states[i].stacklevels = sk; + sk += params->tree_height + 1; + + states[i].auth = sk; + sk += params->tree_height * params->n; + + states[i].keep = sk; + sk += (params->tree_height >> 1) * params->n; + + for (j = 0; j < params->tree_height - params->bds_k; j++) { + states[i].treehash[j].h = bytes_to_ull(sk, 1); + sk += 1; + + states[i].treehash[j].next_idx = bytes_to_ull(sk, 4); + sk += 4; + + states[i].treehash[j].stackusage = bytes_to_ull(sk, 1); + sk += 1; + + states[i].treehash[j].completed = bytes_to_ull(sk, 1); + sk += 1; + + states[i].treehash[j].node = sk; + sk += params->n; + } + + states[i].retain = sk; + sk += ((1 << params->bds_k) - params->bds_k - 1) * params->n; + + states[i].next_leaf = bytes_to_ull(sk, 4); + sk += 4; + } + + if (params->d > 1) { + *wots_sigs = sk; + } +} + +static void xmss_serialize_state(const xmss_params *params, + unsigned char *sk, bds_state *state) +{ + xmssmt_serialize_state(params, sk, state); +} + +static void xmss_deserialize_state(const xmss_params *params, + bds_state *state, unsigned char *sk) +{ + xmssmt_deserialize_state(params, state, NULL, sk); +} + +static void memswap(void *a, void *b, void *t, unsigned long long len) +{ + memcpy(t, a, len); + memcpy(a, b, len); + memcpy(b, t, len); +} + +/** + * Swaps the content of two bds_state objects, swapping actual memory rather + * than pointers. + * As we're mapping memory chunks in the secret key to bds state objects, + * it is now necessary to make swaps 'real swaps'. This could be done in the + * serialization function as well, but that causes more overhead + */ +// TODO this should not be necessary if we keep better track of the states +static void deep_state_swap(const xmss_params *params, + bds_state *a, bds_state *b) +{ + // TODO this is extremely ugly and should be refactored + // TODO right now, this ensures that both 'stack' and 'retain' fit + unsigned char t[ + ((params->tree_height + 1) > ((1 << params->bds_k) - params->bds_k - 1) + ? (params->tree_height + 1) + : ((1 << params->bds_k) - params->bds_k - 1)) + * params->n]; + unsigned int i; + + memswap(a->stack, b->stack, t, (params->tree_height + 1) * params->n); + memswap(&a->stackoffset, &b->stackoffset, t, sizeof(a->stackoffset)); + memswap(a->stacklevels, b->stacklevels, t, params->tree_height + 1); + memswap(a->auth, b->auth, t, params->tree_height * params->n); + memswap(a->keep, b->keep, t, (params->tree_height >> 1) * params->n); + + for (i = 0; i < params->tree_height - params->bds_k; i++) { + memswap(&a->treehash[i].h, &b->treehash[i].h, t, sizeof(a->treehash[i].h)); + memswap(&a->treehash[i].next_idx, &b->treehash[i].next_idx, t, sizeof(a->treehash[i].next_idx)); + memswap(&a->treehash[i].stackusage, &b->treehash[i].stackusage, t, sizeof(a->treehash[i].stackusage)); + memswap(&a->treehash[i].completed, &b->treehash[i].completed, t, sizeof(a->treehash[i].completed)); + memswap(a->treehash[i].node, b->treehash[i].node, t, params->n); + } + + memswap(a->retain, b->retain, t, ((1 << params->bds_k) - params->bds_k - 1) * params->n); + memswap(&a->next_leaf, &b->next_leaf, t, sizeof(a->next_leaf)); +} + +static int treehash_minheight_on_stack(const xmss_params *params, + bds_state *state, + const treehash_inst *treehash) +{ + unsigned int r = params->tree_height, i; + + for (i = 0; i < treehash->stackusage; i++) { + if (state->stacklevels[state->stackoffset - i - 1] < r) { + r = state->stacklevels[state->stackoffset - i - 1]; + } + } + return r; +} + +/** + * Merkle's TreeHash algorithm. The address only needs to initialize the first 78 bits of addr. Everything else will be set by treehash. + * Currently only used for key generation. + * + */ +static void treehash_init(const xmss_params *params, + unsigned char *node, int height, int index, + bds_state *state, const unsigned char *sk_seed, + const unsigned char *pub_seed, const uint32_t addr[8]) +{ + unsigned int idx = index; + // use three different addresses because at this point we use all three formats in parallel + uint32_t ots_addr[8] = {0}; + uint32_t ltree_addr[8] = {0}; + uint32_t node_addr[8] = {0}; + // only copy layer and tree address parts + copy_subtree_addr(ots_addr, addr); + // type = ots + set_type(ots_addr, 0); + copy_subtree_addr(ltree_addr, addr); + set_type(ltree_addr, 1); + copy_subtree_addr(node_addr, addr); + set_type(node_addr, 2); + + uint32_t lastnode, i; + unsigned char stack[(height+1)*params->n]; + unsigned int stacklevels[height+1]; + unsigned int stackoffset=0; + unsigned int nodeh; + + lastnode = idx+(1<tree_height-params->bds_k; i++) { + state->treehash[i].h = i; + state->treehash[i].completed = 1; + state->treehash[i].stackusage = 0; + } + + i = 0; + for (; idx < lastnode; idx++) { + set_ltree_addr(ltree_addr, idx); + set_ots_addr(ots_addr, idx); + gen_leaf_wots(params, stack+stackoffset*params->n, sk_seed, pub_seed, ltree_addr, ots_addr); + stacklevels[stackoffset] = 0; + stackoffset++; + if (params->tree_height - params->bds_k > 0 && i == 3) { + memcpy(state->treehash[0].node, stack+stackoffset*params->n, params->n); + } + while (stackoffset>1 && stacklevels[stackoffset-1] == stacklevels[stackoffset-2]) { + nodeh = stacklevels[stackoffset-1]; + if (i >> nodeh == 1) { + memcpy(state->auth + nodeh*params->n, stack+(stackoffset-1)*params->n, params->n); + } + else { + if (nodeh < params->tree_height - params->bds_k && i >> nodeh == 3) { + memcpy(state->treehash[nodeh].node, stack+(stackoffset-1)*params->n, params->n); + } + else if (nodeh >= params->tree_height - params->bds_k) { + memcpy(state->retain + ((1 << (params->tree_height - 1 - nodeh)) + nodeh - params->tree_height + (((i >> nodeh) - 3) >> 1)) * params->n, stack+(stackoffset-1)*params->n, params->n); + } + } + set_tree_height(node_addr, stacklevels[stackoffset-1]); + set_tree_index(node_addr, (idx >> (stacklevels[stackoffset-1]+1))); + thash_h(params, stack+(stackoffset-2)*params->n, stack+(stackoffset-2)*params->n, pub_seed, node_addr); + stacklevels[stackoffset-2]++; + stackoffset--; + } + i++; + } + + for (i = 0; i < params->n; i++) { + node[i] = stack[i]; + } +} + +static void treehash_update(const xmss_params *params, + treehash_inst *treehash, bds_state *state, + const unsigned char *sk_seed, + const unsigned char *pub_seed, + const uint32_t addr[8]) +{ + uint32_t ots_addr[8] = {0}; + uint32_t ltree_addr[8] = {0}; + uint32_t node_addr[8] = {0}; + // only copy layer and tree address parts + copy_subtree_addr(ots_addr, addr); + // type = ots + set_type(ots_addr, 0); + copy_subtree_addr(ltree_addr, addr); + set_type(ltree_addr, 1); + copy_subtree_addr(node_addr, addr); + set_type(node_addr, 2); + + set_ltree_addr(ltree_addr, treehash->next_idx); + set_ots_addr(ots_addr, treehash->next_idx); + + unsigned char nodebuffer[2 * params->n]; + unsigned int nodeheight = 0; + gen_leaf_wots(params, nodebuffer, sk_seed, pub_seed, ltree_addr, ots_addr); + while (treehash->stackusage > 0 && state->stacklevels[state->stackoffset-1] == nodeheight) { + memcpy(nodebuffer + params->n, nodebuffer, params->n); + memcpy(nodebuffer, state->stack + (state->stackoffset-1)*params->n, params->n); + set_tree_height(node_addr, nodeheight); + set_tree_index(node_addr, (treehash->next_idx >> (nodeheight+1))); + thash_h(params, nodebuffer, nodebuffer, pub_seed, node_addr); + nodeheight++; + treehash->stackusage--; + state->stackoffset--; + } + if (nodeheight == treehash->h) { // this also implies stackusage == 0 + memcpy(treehash->node, nodebuffer, params->n); + treehash->completed = 1; + } + else { + memcpy(state->stack + state->stackoffset*params->n, nodebuffer, params->n); + treehash->stackusage++; + state->stacklevels[state->stackoffset] = nodeheight; + state->stackoffset++; + treehash->next_idx++; + } +} + +/** + * Performs treehash updates on the instance that needs it the most. + * Returns the updated number of available updates. + **/ +static char bds_treehash_update(const xmss_params *params, + bds_state *state, unsigned int updates, + const unsigned char *sk_seed, + unsigned char *pub_seed, + const uint32_t addr[8]) +{ + uint32_t i, j; + unsigned int level, l_min, low; + unsigned int used = 0; + + for (j = 0; j < updates; j++) { + l_min = params->tree_height; + level = params->tree_height - params->bds_k; + for (i = 0; i < params->tree_height - params->bds_k; i++) { + if (state->treehash[i].completed) { + low = params->tree_height; + } + else if (state->treehash[i].stackusage == 0) { + low = i; + } + else { + low = treehash_minheight_on_stack(params, state, &(state->treehash[i])); + } + if (low < l_min) { + level = i; + l_min = low; + } + } + if (level == params->tree_height - params->bds_k) { + break; + } + treehash_update(params, &(state->treehash[level]), state, sk_seed, pub_seed, addr); + used++; + } + return updates - used; +} + +/** + * Updates the state (typically NEXT_i) by adding a leaf and updating the stack + * Returns -1 if all leaf nodes have already been processed + **/ +static char bds_state_update(const xmss_params *params, + bds_state *state, const unsigned char *sk_seed, + const unsigned char *pub_seed, + const uint32_t addr[8]) +{ + uint32_t ltree_addr[8] = {0}; + uint32_t node_addr[8] = {0}; + uint32_t ots_addr[8] = {0}; + + unsigned int nodeh; + int idx = state->next_leaf; + if (idx == 1 << params->tree_height) { + return -1; + } + + // only copy layer and tree address parts + copy_subtree_addr(ots_addr, addr); + // type = ots + set_type(ots_addr, 0); + copy_subtree_addr(ltree_addr, addr); + set_type(ltree_addr, 1); + copy_subtree_addr(node_addr, addr); + set_type(node_addr, 2); + + set_ots_addr(ots_addr, idx); + set_ltree_addr(ltree_addr, idx); + + gen_leaf_wots(params, state->stack+state->stackoffset*params->n, sk_seed, pub_seed, ltree_addr, ots_addr); + + state->stacklevels[state->stackoffset] = 0; + state->stackoffset++; + if (params->tree_height - params->bds_k > 0 && idx == 3) { + memcpy(state->treehash[0].node, state->stack+state->stackoffset*params->n, params->n); + } + while (state->stackoffset>1 && state->stacklevels[state->stackoffset-1] == state->stacklevels[state->stackoffset-2]) { + nodeh = state->stacklevels[state->stackoffset-1]; + if (idx >> nodeh == 1) { + memcpy(state->auth + nodeh*params->n, state->stack+(state->stackoffset-1)*params->n, params->n); + } + else { + if (nodeh < params->tree_height - params->bds_k && idx >> nodeh == 3) { + memcpy(state->treehash[nodeh].node, state->stack+(state->stackoffset-1)*params->n, params->n); + } + else if (nodeh >= params->tree_height - params->bds_k) { + memcpy(state->retain + ((1 << (params->tree_height - 1 - nodeh)) + nodeh - params->tree_height + (((idx >> nodeh) - 3) >> 1)) * params->n, state->stack+(state->stackoffset-1)*params->n, params->n); + } + } + set_tree_height(node_addr, state->stacklevels[state->stackoffset-1]); + set_tree_index(node_addr, (idx >> (state->stacklevels[state->stackoffset-1]+1))); + thash_h(params, state->stack+(state->stackoffset-2)*params->n, state->stack+(state->stackoffset-2)*params->n, pub_seed, node_addr); + + state->stacklevels[state->stackoffset-2]++; + state->stackoffset--; + } + state->next_leaf++; + return 0; +} + +/** + * Returns the auth path for node leaf_idx and computes the auth path for the + * next leaf node, using the algorithm described by Buchmann, Dahmen and Szydlo + * in "Post Quantum Cryptography", Springer 2009. + */ +static void bds_round(const xmss_params *params, + bds_state *state, const unsigned long leaf_idx, + const unsigned char *sk_seed, + const unsigned char *pub_seed, uint32_t addr[8]) +{ + unsigned int i; + unsigned int tau = params->tree_height; + unsigned int startidx; + unsigned int offset, rowidx; + unsigned char buf[2 * params->n]; + + uint32_t ots_addr[8] = {0}; + uint32_t ltree_addr[8] = {0}; + uint32_t node_addr[8] = {0}; + + // only copy layer and tree address parts + copy_subtree_addr(ots_addr, addr); + // type = ots + set_type(ots_addr, 0); + copy_subtree_addr(ltree_addr, addr); + set_type(ltree_addr, 1); + copy_subtree_addr(node_addr, addr); + set_type(node_addr, 2); + + for (i = 0; i < params->tree_height; i++) { + if (! ((leaf_idx >> i) & 1)) { + tau = i; + break; + } + } + + if (tau > 0) { + memcpy(buf, state->auth + (tau-1) * params->n, params->n); + // we need to do this before refreshing state->keep to prevent overwriting + memcpy(buf + params->n, state->keep + ((tau-1) >> 1) * params->n, params->n); + } + if (!((leaf_idx >> (tau + 1)) & 1) && (tau < params->tree_height - 1)) { + memcpy(state->keep + (tau >> 1)*params->n, state->auth + tau*params->n, params->n); + } + if (tau == 0) { + set_ltree_addr(ltree_addr, leaf_idx); + set_ots_addr(ots_addr, leaf_idx); + gen_leaf_wots(params, state->auth, sk_seed, pub_seed, ltree_addr, ots_addr); + } + else { + set_tree_height(node_addr, (tau-1)); + set_tree_index(node_addr, leaf_idx >> tau); + thash_h(params, state->auth + tau * params->n, buf, pub_seed, node_addr); + for (i = 0; i < tau; i++) { + if (i < params->tree_height - params->bds_k) { + memcpy(state->auth + i * params->n, state->treehash[i].node, params->n); + } + else { + offset = (1 << (params->tree_height - 1 - i)) + i - params->tree_height; + rowidx = ((leaf_idx >> i) - 1) >> 1; + memcpy(state->auth + i * params->n, state->retain + (offset + rowidx) * params->n, params->n); + } + } + + for (i = 0; i < ((tau < params->tree_height - params->bds_k) ? tau : (params->tree_height - params->bds_k)); i++) { + startidx = leaf_idx + 1 + 3 * (1 << i); + if (startidx < 1U << params->tree_height) { + state->treehash[i].h = i; + state->treehash[i].next_idx = startidx; + state->treehash[i].completed = 0; + state->treehash[i].stackusage = 0; + } + } + } +} + +/** + * Given a set of parameters, this function returns the size of the secret key. + * This is implementation specific, as varying choices in tree traversal will + * result in varying requirements for state storage. + * + * This function handles both XMSS and XMSSMT parameter sets. + */ +unsigned long long xmss_xmssmt_core_sk_bytes(const xmss_params *params) +{ + return params->index_bytes + 4 * params->n + + (2 * params->d - 1) * ( + (params->tree_height + 1) * params->n + + 4 + + params->tree_height + 1 + + params->tree_height * params->n + + (params->tree_height >> 1) * params->n + + (params->tree_height - params->bds_k) * (7 + params->n) + + ((1 << params->bds_k) - params->bds_k - 1) * params->n + + 4 + ) + + (params->d - 1) * params->wots_sig_bytes; +} + +/* + * Generates a XMSS key pair for a given parameter set. + * Format sk: [(32bit) idx || SK_SEED || SK_PRF || root || PUB_SEED] + * Format pk: [root || PUB_SEED] omitting algo oid. + */ +int xmss_core_keypair(const xmss_params *params, + unsigned char *pk, unsigned char *sk) +{ + uint32_t addr[8] = {0}; + + // TODO refactor BDS state not to need separate treehash instances + bds_state state; + treehash_inst treehash[params->tree_height - params->bds_k]; + state.treehash = treehash; + + xmss_deserialize_state(params, &state, sk); + + state.stackoffset = 0; + state.next_leaf = 0; + + // Set idx = 0 + sk[0] = 0; + sk[1] = 0; + sk[2] = 0; + sk[3] = 0; + // Init SK_SEED (n byte) and SK_PRF (n byte) + OQS_randombytes(sk + params->index_bytes, 2*params->n); + + // Init PUB_SEED (n byte) + OQS_randombytes(sk + params->index_bytes + 3*params->n, params->n); + // Copy PUB_SEED to public key + memcpy(pk + params->n, sk + params->index_bytes + 3*params->n, params->n); + + // Compute root + treehash_init(params, pk, params->tree_height, 0, &state, sk + params->index_bytes, sk + params->index_bytes + 3*params->n, addr); + // copy root to sk + memcpy(sk + params->index_bytes + 2*params->n, pk, params->n); + + /* Write the BDS state into sk. */ + xmss_serialize_state(params, sk, &state); + + return 0; +} + +/** + * Signs a message. + * Returns + * 1. an array containing the signature followed by the message AND + * 2. an updated secret key! + * + */ +int xmss_core_sign(const xmss_params *params, + unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen) +{ + const unsigned char *pub_root = sk + params->index_bytes + 2*params->n; + + uint16_t i = 0; + + // TODO refactor BDS state not to need separate treehash instances + bds_state state; + treehash_inst treehash[params->tree_height - params->bds_k]; + state.treehash = treehash; + + /* Load the BDS state from sk. */ + xmss_deserialize_state(params, &state, sk); + + // Extract SK + unsigned long idx = ((unsigned long)sk[0] << 24) | ((unsigned long)sk[1] << 16) | ((unsigned long)sk[2] << 8) | sk[3]; + + /* Check if we can still sign with this sk. + * If not, return -2 + * + * If this is the last possible signature (because the max index value + * is reached), production implementations should delete the secret key + * to prevent accidental further use. + * + * For the case of total tree height of 64 we do not use the last signature + * to be on the safe side (there is no index value left to indicate that the + * key is finished, hence external handling would be necessary) + */ + if (idx >= ((1ULL << params->full_height) - 1)) { + // Delete secret key here. We only do this in memory, production code + // has to make sure that this happens on disk. + memset(sk, 0xFF, params->index_bytes); + memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); + if (idx > ((1ULL << params->full_height) - 1)) + return -2; // We already used all one-time keys + if ((params->full_height == 64) && (idx == ((1ULL << params->full_height) - 1))) + return -2; // We already used all one-time keys + } + + unsigned char sk_seed[params->n]; + memcpy(sk_seed, sk + params->index_bytes, params->n); + unsigned char sk_prf[params->n]; + memcpy(sk_prf, sk + params->index_bytes + params->n, params->n); + unsigned char pub_seed[params->n]; + memcpy(pub_seed, sk + params->index_bytes + 3*params->n, params->n); + + // index as 32 bytes string + unsigned char idx_bytes_32[32]; + ull_to_bytes(idx_bytes_32, 32, idx); + + // Update SK + sk[0] = ((idx + 1) >> 24) & 255; + sk[1] = ((idx + 1) >> 16) & 255; + sk[2] = ((idx + 1) >> 8) & 255; + sk[3] = (idx + 1) & 255; + // Secret key for this non-forward-secure version is now updated. + // A production implementation should consider using a file handle instead, + // and write the updated secret key at this point! + + // Init working params + unsigned char R[params->n]; + unsigned char msg_h[params->n]; + uint32_t ots_addr[8] = {0}; + + // --------------------------------- + // Message Hashing + // --------------------------------- + + // Message Hash: + // First compute pseudorandom value + prf(params, R, idx_bytes_32, sk_prf); + + /* Already put the message in the right place, to make it easier to prepend + * things when computing the hash over the message. */ + unsigned long long prefix_length = params->padding_len + 3*params->n; + unsigned char m_with_prefix[mlen + prefix_length]; + memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); + memcpy(m_with_prefix + prefix_length, m, mlen); + + /* Compute the message hash. */ + hash_message(params, msg_h, R, pub_root, idx, + m_with_prefix, + mlen); + + // Start collecting signature + *smlen = 0; + + // Copy index to signature + sm[0] = (idx >> 24) & 255; + sm[1] = (idx >> 16) & 255; + sm[2] = (idx >> 8) & 255; + sm[3] = idx & 255; + + sm += 4; + *smlen += 4; + + // Copy R to signature + for (i = 0; i < params->n; i++) { + sm[i] = R[i]; + } + + sm += params->n; + *smlen += params->n; + + // ---------------------------------- + // Now we start to "really sign" + // ---------------------------------- + + // Prepare Address + set_type(ots_addr, 0); + set_ots_addr(ots_addr, idx); + + // Compute WOTS signature + wots_sign(params, sm, msg_h, sk_seed, pub_seed, ots_addr); + + sm += params->wots_sig_bytes; + *smlen += params->wots_sig_bytes; + + // the auth path was already computed during the previous round + memcpy(sm, state.auth, params->tree_height*params->n); + + if (idx < (1U << params->tree_height) - 1) { + bds_round(params, &state, idx, sk_seed, pub_seed, ots_addr); + bds_treehash_update(params, &state, (params->tree_height - params->bds_k) >> 1, sk_seed, pub_seed, ots_addr); + } + + sm += params->tree_height*params->n; + *smlen += params->tree_height*params->n; + + /* Write the updated BDS state back into sk. */ + xmss_serialize_state(params, sk, &state); + + return 0; +} + +/* + * Generates a XMSSMT key pair for a given parameter set. + * Format sk: [(ceil(h/8) bit) idx || SK_SEED || SK_PRF || root || PUB_SEED] + * Format pk: [root || PUB_SEED] omitting algo oid. + */ +int xmssmt_core_keypair(const xmss_params *params, + unsigned char *pk, unsigned char *sk) +{ + uint32_t addr[8] = {0}; + unsigned int i; + unsigned char *wots_sigs; + + // TODO refactor BDS state not to need separate treehash instances + bds_state states[2*params->d - 1]; + treehash_inst treehash[(2*params->d - 1) * (params->tree_height - params->bds_k)]; + for (i = 0; i < 2*params->d - 1; i++) { + states[i].treehash = treehash + i * (params->tree_height - params->bds_k); + } + + xmssmt_deserialize_state(params, states, &wots_sigs, sk); + + for (i = 0; i < 2 * params->d - 1; i++) { + states[i].stackoffset = 0; + states[i].next_leaf = 0; + } + + // Set idx = 0 + for (i = 0; i < params->index_bytes; i++) { + sk[i] = 0; + } + // Init SK_SEED (params->n byte) and SK_PRF (params->n byte) + OQS_randombytes(sk+params->index_bytes, 2*params->n); + + // Init PUB_SEED (params->n byte) + OQS_randombytes(sk+params->index_bytes + 3*params->n, params->n); + // Copy PUB_SEED to public key + memcpy(pk+params->n, sk+params->index_bytes+3*params->n, params->n); + + // Start with the bottom-most layer + set_layer_addr(addr, 0); + // Set up state and compute wots signatures for all but topmost tree root + for (i = 0; i < params->d - 1; i++) { + // Compute seed for OTS key pair + treehash_init(params, pk, params->tree_height, 0, states + i, sk+params->index_bytes, pk+params->n, addr); + set_layer_addr(addr, (i+1)); + wots_sign(params, wots_sigs + i*params->wots_sig_bytes, pk, sk + params->index_bytes, pk+params->n, addr); + } + // Address now points to the single tree on layer d-1 + treehash_init(params, pk, params->tree_height, 0, states + i, sk+params->index_bytes, pk+params->n, addr); + memcpy(sk + params->index_bytes + 2*params->n, pk, params->n); + + xmssmt_serialize_state(params, sk, states); + + return 0; +} + +/** + * Signs a message. + * Returns + * 1. an array containing the signature followed by the message AND + * 2. an updated secret key! + * + */ +int xmssmt_core_sign(const xmss_params *params, + unsigned char *sk, + unsigned char *sm, unsigned long long *smlen, + const unsigned char *m, unsigned long long mlen) +{ + const unsigned char *pub_root = sk + params->index_bytes + 2*params->n; + + uint64_t idx_tree; + uint32_t idx_leaf; + uint64_t i, j; + int needswap_upto = -1; + unsigned int updates; + + unsigned char sk_seed[params->n]; + unsigned char sk_prf[params->n]; + unsigned char pub_seed[params->n]; + // Init working params + unsigned char R[params->n]; + unsigned char msg_h[params->n]; + uint32_t addr[8] = {0}; + uint32_t ots_addr[8] = {0}; + unsigned char idx_bytes_32[32]; + + unsigned char *wots_sigs; + + // TODO refactor BDS state not to need separate treehash instances + bds_state states[2*params->d - 1]; + treehash_inst treehash[(2*params->d - 1) * (params->tree_height - params->bds_k)]; + for (i = 0; i < 2*params->d - 1; i++) { + states[i].treehash = treehash + i * (params->tree_height - params->bds_k); + } + + xmssmt_deserialize_state(params, states, &wots_sigs, sk); + + // Extract SK + unsigned long long idx = 0; + for (i = 0; i < params->index_bytes; i++) { + idx |= ((unsigned long long)sk[i]) << 8*(params->index_bytes - 1 - i); + } + + /* Check if we can still sign with this sk. + * If not, return -2 + * + * If this is the last possible signature (because the max index value + * is reached), production implementations should delete the secret key + * to prevent accidental further use. + * + * For the case of total tree height of 64 we do not use the last signature + * to be on the safe side (there is no index value left to indicate that the + * key is finished, hence external handling would be necessary) + */ + if (idx >= ((1ULL << params->full_height) - 1)) { + // Delete secret key here. We only do this in memory, production code + // has to make sure that this happens on disk. + memset(sk, 0xFF, params->index_bytes); + memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); + if (idx > ((1ULL << params->full_height) - 1)) + return -2; // We already used all one-time keys + if ((params->full_height == 64) && (idx == ((1ULL << params->full_height) - 1))) + return -2; // We already used all one-time keys + } + + memcpy(sk_seed, sk+params->index_bytes, params->n); + memcpy(sk_prf, sk+params->index_bytes+params->n, params->n); + memcpy(pub_seed, sk+params->index_bytes+3*params->n, params->n); + + // Update SK + for (i = 0; i < params->index_bytes; i++) { + sk[i] = ((idx + 1) >> 8*(params->index_bytes - 1 - i)) & 255; + } + // Secret key for this non-forward-secure version is now updated. + // A production implementation should consider using a file handle instead, + // and write the updated secret key at this point! + + // --------------------------------- + // Message Hashing + // --------------------------------- + + // Message Hash: + // First compute pseudorandom value + ull_to_bytes(idx_bytes_32, 32, idx); + prf(params, R, idx_bytes_32, sk_prf); + + /* Already put the message in the right place, to make it easier to prepend + * things when computing the hash over the message. */ + unsigned long long prefix_length = params->padding_len + 3*params->n; + unsigned char m_with_prefix[mlen + prefix_length]; + memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); + memcpy(m_with_prefix + prefix_length, m, mlen); + + /* Compute the message hash. */ + hash_message(params, msg_h, R, pub_root, idx, + m_with_prefix, + mlen); + + // Start collecting signature + *smlen = 0; + + // Copy index to signature + for (i = 0; i < params->index_bytes; i++) { + sm[i] = (idx >> 8*(params->index_bytes - 1 - i)) & 255; + } + + sm += params->index_bytes; + *smlen += params->index_bytes; + + // Copy R to signature + for (i = 0; i < params->n; i++) { + sm[i] = R[i]; + } + + sm += params->n; + *smlen += params->n; + + // ---------------------------------- + // Now we start to "really sign" + // ---------------------------------- + + // Handle lowest layer separately as it is slightly different... + + // Prepare Address + set_type(ots_addr, 0); + idx_tree = idx >> params->tree_height; + idx_leaf = (idx & ((1 << params->tree_height)-1)); + set_layer_addr(ots_addr, 0); + set_tree_addr(ots_addr, idx_tree); + set_ots_addr(ots_addr, idx_leaf); + + // Compute WOTS signature + wots_sign(params, sm, msg_h, sk_seed, pub_seed, ots_addr); + + sm += params->wots_sig_bytes; + *smlen += params->wots_sig_bytes; + + memcpy(sm, states[0].auth, params->tree_height*params->n); + sm += params->tree_height*params->n; + *smlen += params->tree_height*params->n; + + // prepare signature of remaining layers + for (i = 1; i < params->d; i++) { + // put WOTS signature in place + memcpy(sm, wots_sigs + (i-1)*params->wots_sig_bytes, params->wots_sig_bytes); + + sm += params->wots_sig_bytes; + *smlen += params->wots_sig_bytes; + + // put AUTH nodes in place + memcpy(sm, states[i].auth, params->tree_height*params->n); + sm += params->tree_height*params->n; + *smlen += params->tree_height*params->n; + } + + updates = (params->tree_height - params->bds_k) >> 1; + + set_tree_addr(addr, (idx_tree + 1)); + // mandatory update for NEXT_0 (does not count towards h-k/2) if NEXT_0 exists + if ((1 + idx_tree) * (1 << params->tree_height) + idx_leaf < (1ULL << params->full_height)) { + bds_state_update(params, &states[params->d], sk_seed, pub_seed, addr); + } + + for (i = 0; i < params->d; i++) { + // check if we're not at the end of a tree + if (! (((idx + 1) & ((1ULL << ((i+1)*params->tree_height)) - 1)) == 0)) { + idx_leaf = (idx >> (params->tree_height * i)) & ((1 << params->tree_height)-1); + idx_tree = (idx >> (params->tree_height * (i+1))); + set_layer_addr(addr, i); + set_tree_addr(addr, idx_tree); + if (i == (unsigned int) (needswap_upto + 1)) { + bds_round(params, &states[i], idx_leaf, sk_seed, pub_seed, addr); + } + updates = bds_treehash_update(params, &states[i], updates, sk_seed, pub_seed, addr); + set_tree_addr(addr, (idx_tree + 1)); + // if a NEXT-tree exists for this level; + if ((1 + idx_tree) * (1 << params->tree_height) + idx_leaf < (1ULL << (params->full_height - params->tree_height * i))) { + if (i > 0 && updates > 0 && states[params->d + i].next_leaf < (1ULL << params->full_height)) { + bds_state_update(params, &states[params->d + i], sk_seed, pub_seed, addr); + updates--; + } + } + } + else if (idx < (1ULL << params->full_height) - 1) { + deep_state_swap(params, states+params->d + i, states + i); + + set_layer_addr(ots_addr, (i+1)); + set_tree_addr(ots_addr, ((idx + 1) >> ((i+2) * params->tree_height))); + set_ots_addr(ots_addr, (((idx >> ((i+1) * params->tree_height)) + 1) & ((1 << params->tree_height)-1))); + + wots_sign(params, wots_sigs + i*params->wots_sig_bytes, states[i].stack, sk_seed, pub_seed, ots_addr); + + states[params->d + i].stackoffset = 0; + states[params->d + i].next_leaf = 0; + + updates--; // WOTS-signing counts as one update + needswap_upto = i; + for (j = 0; j < params->tree_height-params->bds_k; j++) { + states[i].treehash[j].completed = 1; + } + } + } + + xmssmt_serialize_state(params, sk, states); + + return 0; +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index 93dcd57bba..1dd0139e5f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -10,13 +10,15 @@ #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 #define OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature 2500 -#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk 64 + XMSS_OID_LEN -#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk 2047 + XMSS_OID_LEN +#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk (132 + XMSS_OID_LEN) OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(size_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(size_t *total, const uint8_t *secret_key); #endif diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c deleted file mode 100644 index 186fba20f8..0000000000 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256.c +++ /dev/null @@ -1,57 +0,0 @@ -// SPDX-License-Identifier: MIT - -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif - -// ======================== XMSS10-SHA256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->method_name = "XMSS-SHA2_10_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h10_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_sha256_h10_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_sha256_h10_verify; - - return sig; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { - memset(signature, 0, OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature); - *signature_len = OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - for (size_t i = 0; i < OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; i++) { - if (signature[i] != 0) { - return OQS_ERROR; - } - } - return OQS_SUCCESS; -} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c new file mode 100644 index 0000000000..8e50828095 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -0,0 +1,112 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHA2_10_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHA2_10_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h10_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_sha256_h10_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_sha256_h10_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total; + + return sig; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_sha256_h10_oid = 0x00000001; + if (oqs_sig_stfl_xmss_xmss_keypair(public_key, secret_key, xmss_sha256_h10_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (oqs_sig_stfl_xmss_xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_xmss_xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(size_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long remaining_signatures = 0; + if (oqs_sig_stfl_xmss_xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (size_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(size_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long total_signatures = 0; + if (oqs_sig_stfl_xmss_xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (size_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt index ada020f51a..22c26a053a 100644 --- a/tests/CMakeLists.txt +++ b/tests/CMakeLists.txt @@ -99,6 +99,9 @@ if(CMAKE_SYSTEM_NAME STREQUAL "Windows" AND BUILD_SHARED_LIBS) endif() endif() +add_executable(kat_sig_stfl kat_sig_stfl.c test_helpers.c) +target_link_libraries(kat_sig_stfl PRIVATE ${TEST_DEPS}) + add_executable(test_sig test_sig.c) target_link_libraries(test_sig PRIVATE ${TEST_DEPS}) @@ -113,11 +116,13 @@ set(SIG_TESTS example_sig kat_sig test_sig test_sig_mem speed_sig vectors_sig) # SIG_STFL API tests add_executable(test_sig_stfl test_sig_stfl.c) if((CMAKE_C_COMPILER_ID MATCHES "Clang") OR (CMAKE_C_COMPILER_ID STREQUAL "GNU")) - target_link_libraries(test_sig_stfl PRIVATE ${API_TEST_DEPS} Threads::Threads) + target_link_libraries(test_sig_stfl PRIVATE ${TEST_DEPS} Threads::Threads) else () - target_link_libraries(test_sig_stfl PRIVATE ${API_TEST_DEPS}) + target_link_libraries(test_sig_stfl PRIVATE ${TEST_DEPS}) endif() +set(SIG_STFL_TESTS kat_sig_stfl test_sig_stfl) + add_executable(dump_alg_info dump_alg_info.c) target_link_libraries(dump_alg_info PRIVATE ${TEST_DEPS}) @@ -158,5 +163,5 @@ add_custom_target( # skip long KAT tests COMMAND ${CMAKE_COMMAND} -E env OQS_BUILD_DIR=${CMAKE_BINARY_DIR} ${PYTHON3_EXEC} -m pytest --verbose --numprocesses=auto --ignore=scripts/copy_from_upstream/repos --ignore=tests/test_kat_all.py WORKING_DIRECTORY ${CMAKE_SOURCE_DIR} - DEPENDS oqs dump_alg_info ${KEM_TESTS} ${SIG_TESTS} ${UNIX_TESTS} + DEPENDS oqs dump_alg_info ${KEM_TESTS} ${SIG_TESTS} ${SIG_STFL_TESTS} ${UNIX_TESTS} USES_TERMINAL) diff --git a/tests/KATs/sig_stfl/kats.json b/tests/KATs/sig_stfl/kats.json new file mode 100644 index 0000000000..8be3ea457f --- /dev/null +++ b/tests/KATs/sig_stfl/kats.json @@ -0,0 +1,3 @@ +{ + "XMSS-SHA2_10_256": "e71e6a390fe09c275e0fa0996d938d554d01548da229fe159ccab48e6525ae8b" +} \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp new file mode 100644 index 0000000000..5641aa1e9c --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp @@ -0,0 +1,182 @@ +# XMSS-SHA2_10_256 + +pk = 0000000157A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +sk = 0000000100000000061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD + + +count = 0 +seed = D260779A680342EFB7D244B1333C2FC9884B85CDB7B96F8EEEAF5FC7FBDBABF9A0AA3F0E7238F97142BCF1C561731CFE +mlen = 33 +msg = BBCB0A3E0F49152C2D8022F5AAB8AD5E80E81934BC66D468AB76F141D4E741937D +smlen = 2500 +smsklen = 136 +sk = 0000000100000001061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1022 +max = 1023 + +count = 1 +seed = 4AF2A48BFB8912E1209AE0B00C0B52CD84183E9D2B0D63E1C9DC7E3B2920874CBBABDEBD47BF4CAA5E19B4C6BEB96D8D +mlen = 66 +msg = B81C782E781F6D005B891EAF89527B7AF65AEE14E0B668EAB7A1EC5AE188B391A733B7707E42A7AF3699ECAF1A43453C2CFE0ED61233CFF68F35F4A84ADA949812FC +smlen = 2500 +sm = 0000000196122FAE790CF4FA6D9055E159003D223857F44B3EF248882A415D76FA26BFD2892B42C27F464D13FE2026F5F1CC11B7BEC39DDB84E55A8D02733F9DE45D12F0F78174CE816C9BF2021400FFFB8A957696D2C91B8EE32984C1A7FED7D76B76E3C3877DBD912B9D53681EC0E601947D7AF1F4285EC10CEDB10156CF3B5DBE57C29056EFA6C16B9C3AFFA2835DC3395DBB7962BE6E9FDFF0D4EEAA5A7C40126638D443E00E6282A0278BCB076FB14AE295627CC9D4CB0E4C48A3D9D9394EC889363EAA2382263BE9D1B8C50D744212910B83F4180FEFE601102F1AD9AD3E592BEC45B42789D9C5949A6178226C21581388ABACDDCB988F2FFC0AD98A21DB0D728EE8F7E4E19111DF2EB74436E3CB14792B4C3FE691C27889337D984F82BBBBDB9D2A54B78CF70BE8057908959247FB5A84596DE7ABB1DA1B28BB787064F79A5270A249DE499C6FE8F6DB84B93A12C93563B658527E99786306CB3C32465127497C42E38DAD8F7E592B8585EE77AFB3E70D7F188D1AB0C9873E5005FFB4C360FA74FF8E0A6E3493EE7407D8CE5EA12310F6F51BFBDDB7290BDE558FB6A2F5317F4D11412FA7FFEF45465012D531D90EDC3A62E2EFA07CF58B3B45B5BD8431E7DBCEE38783F5D4757A0AC26D4E5C7F6A94F71BA1AC2F4DD8E9927D0A06792AFF259C2A413B678CFE937A0F3D166761DC7A6F3EFB029C8D4CC735878178BF5E97D06ACBEFC607649F48131D8C35A23278C61A333C969DB3E938011B5FF54A5A46A11392127736DC233186381B84A4A3F7B88D88A5F6519DC83F049F7C57E8CFA439187BC89CEF18CE0E53F6B79BE3DC9575DE0F16EEEFA2619D53A2D2D09078B1D03C0034D8BACFC6B329AC9969B3702AFFE04A94607324D40EFAFC0FA6AD7F0A14D8DD252583D34916D83F927DFBDA6ECDBBEB1D6ED96E881A931D7A6582394A06A53429FD4A6D0E155B533FDC73F2C8A7C7408E56CF3F318CDEA142480A95F6C398BBDF900FA09B386B096391D060F5CF6BCD2614F61E40B3E84AC0BC08FD2AC9D7AFDBC5CEF821810ECB9DF964E3391A6C869DBC59BC75575C11B75CA9C106D76D3AE2636F240B7D25F71772829307F80F6FA5C8000BFD3693407F367A7BD122EFB12493C558A4FC17DF46B892CA14B2D696AC154DA1BF51A274A35E55A8D94A0A8052AAE2C1944347CB57ADEEA0429FDD5D846F9258226A7E3B298F3E687A04B2686C740EDE8DC7A1E447A0792FF49139C33BA99A42A0E760225BFC882DD5BBD1F517126309B438F6813D411048FCE5F2C997E321CA9B6C3B16779034416B1718D962D0CF187E15FA6FBC668C7FFCFA6398D0B58E7FB4504D7623F465E6B657A8A2C4FC8FA01C94F54A3D3E5A29341248885B570B4E4D3900F82C21457782B08AE1C7798405A1CC0EC2CD22120B3EF25F41714804ECD9DB406B0D509D064888E8A2FD3DABCCE5675A3FEE01F4D4F22D0F071AD6E4D907EAB25B0E4C7C5DEF8A5B977012298F6969B9D0F515FA241701B390C605FE982BFF2A5D1375ED026686835769E1B988706A3168AD81C3FF4B394E178999FAF7E711EA6F72CE64CB7CE3ED5E557515F6C0D135401B70C687F97445AB03F49EAD2F911A5C1C21C2DDA9FB2D4A8001F698DD5C54693A515E3FD9205FFF4CDB297FE3D82CFCE9077261758798C7E31B2661E4919572822216A14496F65D6318458C1D758C413A84D4909B1D330E37B8D6CDE30DAFDDA5966559C35D1E79DB90B8B5D0D64B6B74F4781A15E34B0CFFCAE7655CD9C5FDCBD855E1A597A22F82152CE18463F1F71B5E343032BDAA71C3DD5EE7F3E5EE157390DCF4AEE17C7F204B548B0D15412B03AFE4A0E733C3D0CBEE8B2B23854DCC6D98FC7D9FF63E841210541946A048127763FB4D7BFA43EE2FDA7C52A07F1EB2A7CB3E06D8E98CAD68E1AF7C60672C35C410EBC0B7CED72E6C88FF5B2FCFD1AECDD459BB472D0CB20B4CB53102F979F5743E1F1949E30C3DC04A91625844E5780DE2E9D855EE0E03850F123BB8A092D6F4F11E9303354AA49758438C653D52EBDF36EB20FB6B2678E756907ED51879A13A4E233D61BE862DC85D8C8CD04643F783030BD4798C1BD1DFB54706E79FAE2DE8D2FC28469F74B141A571ED0C1950DBBE941965D0EE3B17DE0BC0AE16F98A72CE97B51A37C0132E051E7B2AD221926D68851F3342BD398AA5CD779AA91F1642CED4F81520255B2AF51F6941EC7CE3732553AB201756563DEBED7F6A567306E93B2263CB7B6895863ED6F1120069218A9A2BEFB5AACE3B87B5701E5CD6785E8D0D1E9B5AF7E3D312E4DF0051946B8F29655725F018A9A6315EFD2478B3AC2DA543E347A83A672A7D1C0EF91B31C154E8B57AC643D1BF4A787B53D5FB34240F0072B44E86F8BAB01335AA56D21B3F9DFBFCD10BDF2E51D0B56C1811CAED5B1F8EC8226C54EACE2EAB841B9CD9C4CF876ACD6F7030D9A6BAD21FF3D6316429B2A1AF4552576716AD3C3A8FD36CB54B6C395E43EDE8B5DF0F24927A2A46D209A5B595F4CF60F487B7C138BF59D1265AE0A40F476FBE9D4A49EE24944D5999C748E2291DF06379BA1A1B372566A19F0A3188CB1F5F66821C3B8B974CBEB27BDD80AF162ACFA954BC2207A825A4086ACD0110C677B06653F3E8D34024A01810087E55740AC10EED1E104A839EC2ADF4627FA659F4988238F25AE00B756BFCB2660A0F840DD96EC3093B3AEBCDF20EA99345FD75AE8609C4332B1A436C93B1CCA940C523FF3CA2C4C22B1E60FB7778301FC9A6D0107475433F96D086E3AF105660F7AACE01CB697BC2F495C71ABEF7B3077C75F4AEE329EB5BF9E8AFF82261C0676734C1D85312E9CC0559E26FFC2382C2E123E680F7A22F3AE9A508B856333E36155B5706A7D94596CD131AFF869168D93E45632C9F04E96479532273069D838618B606712A6BBAC7F28275B4636A32D20E677BBA12BA75286545DBE61A9D1DF7AECEBA0896017E9129CE5364A76C1E9EC4AED8E903DA3599BCE44EE44C9E3CEB67870D7D3F815B1B83E8E655A57A167C9AC6AF4B36601C726D78E1A6AA7B3A73F81CC0C8543E67883AA525DA0B828D91ED510E6EEB29AD92649947FAA463EAAB93583CE2BEFF1308D4B1125892F02AEBEDD1AB9A7611C4FEE5ACBB9BA8634169DB9AC73BB0704D1F8F6098CA76F2FA504D8825564A30A1D7E6E12690DE34C0521FE70D15714626DEBC8008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 0000000100000002061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1021 +max = 1023 + +count = 2 +seed = E7D9E1A1D2B81EFE0556C01A7386489B692F4669717A09BB491A7DEC9893F44D2758E633658AB5479168CC719711E2ED +mlen = 99 +msg = 955F970C4CEA3EDFBA0CDCA55FBF59EDF24663E837973E11658FCDD8307A9101FA2E13C4CB23F588EFF1A5201C77E9F734EAB8C76A7C5DF78A6DD8DC5F17DCFBEEED73C7B940F6D4B711CB8856B2E1653D246506DAFD05EE812D6476B53C920E0ADB6F +smlen = 2500 +sm = 00000002C8299416D392EA9885BC2583B1AC67F96AD84D563D0C301C02EA868E744C7BA3C1C7DCB7ACD5DAB40839E3945B0784FF1AD07B1E52812722E7E525CFA0B0615721FCE84472139AFAA7E03AB9D43D62C1C9F71FF0B83EE68E13E96E2D61F27BAFA1FBF91365E6E2AE524E2781040BD0040AE61C59F2BD111C6A67F4F348F25710EA652F452FFDD770306DCF94AAB169F987EAE7F7FB2617A492F9DA54BEE07689400BA5C77FBF6EA54D933F8B84D82664CBCA37FA896294DD3CB06165DCC1CC71083D74D6EEB4C0CC84864C038A52E7BCECBA7E026E4F1ABD3AD53A24F4A0F6A56DF3E0A45AF1F015FB39B04D695ABD9767EEE724D542DE41C23CE1360A69C6A0AECBBB5FA37B67777B066276DD82EF020ADCDEDE2087999C418351EFC54FC1787855C75DE7041402F8EE569D5AE49DADC3E7501F4FC1D9C7AA685E9647BEA04075EC25C3D1C4DDAE1DAB5DBC54A403B7B8B1BBB96751953B33275CFD3B1EB733292E94B32648E31BD4C6591E9705A09598C9C3F9B1FFCDEB10FC9A47C6D4B6B5E45493CC706FE39F27EA164F88DF41E164A16AE2B248E547F4198BD08A5530B5E54089FD91B6F93C533AADC2FE8C1833C8C364A047809E733036A632A91B9EE037FFDAB49021952A3808C4B8E3AD4CCCC7DD28B61C51897E4A5E0A99EC095900D5AD1A2C15685A9D8F56059AC53EAF595374DBA8E2AD2929F8ED6E1C6304831A9D6E3BE0AA1B5681C04D2E8A0300231C121CC1E92B9526D8E797822A7C5718399AFDC5306A868C20BC0F54DBEB95FA711EC79E53F0E1320FAC24BFADCEBA31B956370596A49A071C7A766EBE2118D73F2E39EB59E78BE49F74765FA0134C9B73DCA1A839FB9CC70388FE51E18922B67CF4D08765084E11CE5D45AAF87DD932AE5647C5AC2F88CBCE3FAF67C6035F40781D219C01B84A6728BD4DCD1B173C91FC69798EF1E6EC4F6E8C48A1ED68B917B7D35F3DDC88553F816A4C0F084F56E7D245430F13902459AD609E2EE59B0CDBFC46B823B0922EE41373AF43702E9F093972EE41CAD6F128317B718E87E1FA6185ADFD4C1AFEC61083E3BA5A0D22CE367FD25B98BD3A660399CD4D8A7F608C4BC0CDDE993E57EF92C1FD6EECA542D94FDD77BB0A4B1B99CE7D7E53347B7CCCE13FDA6F8F458DED1B91CAE8CED28FF8D7E39C4F144832E3223E874507BE3AB9718F6240DE0A18CF2DDCD2786940DA86517B3CBE792D5095707ACC08758CBBC307A263FA31A736F6E61EB09EF6BFF82BA7A3273B619878568D62E21D1F15A758E1E83DDCAE6BDE013494DA308A55B5B1E2FFEAF690E04BF725A3C998250067D6320A9A61B3156A5F2A4B4D53BECD0169A0C10BCC0494C2B51BA2C4904CB6A36F7D302810829CBD03E11A8BEDFE4A1ED70FF1E28992B0BBAB3BB43EDD2BBEC8C943E9382B47E24E442264060C61A826EE9812EF305EF83DFA429B7BB0DAAD700AFD47C91F01D046B398B877FF896B437DEB2D4489016CAC266D5B970013229EA33C93909B75ED6755F2FE72E1E3C90613866F85862E70227320B98A4183C4D5C04135A54987088FB17B56D1868102D1B928FC2801ABAF7B05EF137427317EA41BC44564C7BA0A4D7B1A11E494FA15D2915C5AF412AC1CE800A713528774E7B3A74FE03B83F4E30E85570F8BDA6274CF673819B6D43A4B5723B6F06E5B4C55A0D87A424816817AF489E51E8ABDBE6401FAF4732EAAC864E4A6CDD22976BE385E2EE95613FDC2743A7F9A1D60B57C364A58F4F49D414C419671852CE004CF21A2A612BA8157FD0BB2A8A2B630583AC660AF8D220C628BDEAE4973CA3BD6ACCE2193EC091E5F39B7BF0F6AE5CDCC606DBDE2FB25C81106D1B9096D22BC5562B1FD0459BF4DDB6DA835C4C63056D93EF434A55A09CF08053F05FC36FB05425A34E0203B17652B243A2330EAF2F3643EF9A38E3148D71A6B1DA95E4ABCB40376E606FA666623A2597D537B30B0846CD393CFFEF276D91656137FB596E9D9906265764B37DF4725C2BCF0E6E3BD3CFEA76CE098151FACD13AF3D43DBF1E0046ECEEC801CB1FDFB9DF6EBC5117199D98E8C60C5693D629B52334342A4605CF12C7DA172C094E6A48A74A1601F057B3DBE7D5EFB8699339A0EA6DE835507F830C3F36F5B7BAF338E3CBDFAA42E79DA29CBE2C64431890592D97485BCE2608E8B34788A17914CD59B485FFE5297BD2860AA661EB69456862EC5C68C9F5E365F90C1E42BA3B0AFDF3AF05859929EE65DEFE3C54117C05931164C42C6598C85F48D46F0AD243E59EAF0165439D934A56AAA3EEC4B123178BB2828C4F1A19484D3B832E1D376A3BCBBBB13DF1F792CF11BA16E2AC13A000431B48050E581D31696F40D1BFB3C17E98E240F2F8A49D0407E42C80169D19B37EC4046D3D60A15310DC58781060C0B53380667B7B0A13128789C0A9C83486C25F244C1549E80C7769ED738F3E00ED937CB5910B8DCF67F9EB7AED39FAB6F5C7EE9FA05CDED2148CA9E3DF2DF81B9643DF4538FD888A1BF99BEEA7378EA6B6EB86868514A9EF808FF1071FFF8D5D48A2BE6AE9D2404D9AC87D394B3A533CCE8C4A656DC649975BA1CB7F631F210BD285B0FF1BB6874B2B81A9848AED264BA8224889D65C0C64FAA546A6ECD9BC5674FAFC959C1418C0A3662A7DFAE6BDE9DCCEA5B5BDAD952DFC7FB1B969078189F691578B0F5F30343311CF6C1E629CC292A1746104BF422EC21422C15283525D9A3ACDCC9014366F20E2E17BB6D3039DCD8395C61905C23B540F4BB01E817E23FC3723E4AC95FF04BDBDBDC7D70AA1621E7C3AA13E9AC66F057EC0DC6CCF460F969CEEA3002206B2BF88093E28C24F70F1704FAE79F6521951C5B714AA2F0837A179D7B6B49C438D4CE5A8DFC8D660735C1FFF405E406ADF6EEB8D01172B4CCBA596DCCA0C1C92E50AC42D6C5F2E440D25C796456B756D4C857B0E46EDFCA5B5B648A9662C16AF94EFBCB1511027721DBE0537176E4808FDFA6A226E5552A279DE132C70DE7504A5B61A036A86A67EF126FF6F609A4887B589F12FD447180A82EE1BB355DC3216777E0A698D7BF588226E4D442E50847743F3E300BFC9EECC8C8888F69FECF8E95A015A5998F0E1BC3B4948C0EEA76004F507747FA63CDF4A10E802DC40928F4192B84EC2A9FB98D7DBD6AA556098CA76F2FA504D8825564A30A1D7E6E12690DE34C0521FE70D15714626DEBC8008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 0000000100000003061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1020 +max = 1023 + +count = 3 +seed = A344668712D7FF31F511B249BAD15D46C184C9D38442540190DD21E5E784989C56CFB7CDA3336E290F1344AC5AFFFCD1 +mlen = 132 +msg = 3472BE99A4F7CD9261B7F97B0A846790A252CF5A53035D4A6A31B5425F0852F0A63E630D97CC57A455EEF0FA171F7A06C0454D8D3713D47638C01BDB4855DE167C33019780B5EAB0D521E80F536D354756DB0D253A83674F74BE657B0B5681E0696C4294C80B712743EF9AFEC9AE6424C8C8A1810D4BB010F47FEC835AF7F65B40586CFC +smlen = 2500 +sm = 0000000368D0AF9AB3B4981A5A3687839F654ED9958EA0B19666AB0A0D13C7ACA213DB148F827E8E20518BCCBA7D22ABE71110838318A6A5FAB7278330DEFEE172F470802774094D528C66BF6CF628E256721F18E998AC89E94F4CC64B87D4A7B33CBD2EF85DC2FEC2584EA9B7A65C674917AA475663107C608FBF993520F53E87966D52C2C13C93E7B84AF63F2ADA035DADC96B0E4B3FCFA8C1C4F9C3C96866D0ACA6C7942A9C15EC1D25754A12E86B88E4903A1922D10C6378DCFE38CC7ADEB898384718ED44C328936A0C0254B76D6B6E2BEF0175B1C1CB700E724DC4CADEDFAFD35C7D054E351B7AF0E82762710952790318BE12D2D860E8635E7803A1222D4ABF87EA0D656B659D634F0454A730BB92D5E80CA6446BD798021D6B6D19FFF79859BB30D70D77144591CB86ECFC91F3236AD24176B2E8FD36DE8FED94344B3D6DCE6C136830E439ADB5C558B5DB23F5531C07DDE74EB158774D566B086EECCC5C5A7EC0EA44F1996FE3A9D3B8C39990CFED6E9D9A29B8360672B0B9F3D1B50F66775868B7EB8E94FDC741D21B7DF68E9404188EAA65965944F2036EB61F41F504D3796A154024CA4CEE846F948D67A13F820F045B4F92576749BC63692A1C184F20544C301255510F4F869721362B71D46A1B3FC103C97D16139770A8FC3A5304D7B0A82BF68518B8F6246DB32F6A73E787C6DA515D788951132F3DA9C6854599F0B97612F0D26A0AC31B0F28C87509FCD1B044E60322181263AA54DB4E2DAD046D81973EA7FD836A66D2826947DAEF5BB7C9646605E245F4AE8C331D39C585E5912D09A596D5EB66B9DBCF3765E9DF7F79BCE194FB3788A24E22210171FB985E573FE67488A941D7141B041038EA1A1E2DA34898EB8C0D79290657222ADEB49B5696D0211B9B748FEF3CF99FDF7F9FA234F5ED38BCAC44A716AD831D1085CD7CED7AE5C24B2A3C28FBF0970B4C367FF65D650234E1ADCB9BF8D874C66B66AD48DD35D01703F8FDAFEB791574750946C6BEFE20E3BB291294153BBC0D4FDBB05801BB271C4E5D67E7CBE825F03C458065B60C4E30F645BCB7700EBD90400C80843D83F5C70E3B0A6F53BD12C6525D3E37AC18274714D5CA4F9FF0D5A199A679C1B361E845427623375CC168C626D7770F23FFD26BC8121F1F37914D9C6F7758D06CA02129433945C4C975BA76FEDC0EFEB4E447B81D9333145EB86212387381C20A8AD70209008A2EAD4B56A0BDC84B706FEC1ABE2C60A096B83E345405B64EADD4786238C59303E195C5C8DE499696CCE53CD1A469E06EEE0916EB84A04B46B7809A92B6664F97483091B3F239E14D947190CEEAC71B270A1CB730886490CD8847053B9DF24F82D7A857DA3DBE952349556469BB4AD4AD70156BD1D64AC13D822F43DBA949C54CB47B0E75D116E96CFE87BB0E5B21D643B45D143F5977AB27F53BF4724B3CAEC8DF9B158A2013943BB524D1956DDBFEEC65B49CBA2306CDC188A0F18D38728E44C13ED3D309FDF4E8D33F33308273B955620686B057BA2C84BCDECF0AD37C19B4960C5B1B06D89F151E437E8963627EB667D41DF5A1BB89B271E3A5DC2DA0541B13B1212FB2578EF75013B1BFA40944D685041E82958A195475E95132C8B17BF2A090D54B00558773964B2BFC8B1EF89FEB193F0A0646C32FF4CFF26B3EFC3770662A75C3BD7D93FC58C68FE89CEBDE9B4E8C522A81E9DFA925ADCD471E27315BE08E3FD414A558ACB91D0C8BFAD659F1C45D2BE45B1B62CCECDC048EAA7B386F90244E3C2473DD550A3FDF5E1EA3DA65E789065918F8C920586AE31B8DEB3BF6442DC9FC09186CA79221850E4CA7D42CA426DBE5544E0CDA7CC27DFE210739C5D2D5A0AAD80C0F3BFFF0805F71805B5C668CFED02443CDA7A36F8FD317D8E24FEDC58385E31CB94BE00B84F5CCD188A6F0762E4F2CFE25DF4136F70892CAF5AE197556EC733C161661DABF09C3C3CA9F600E23DC9FCD9C843EA4412B2A6E0C5FAA0E67755453FC72DB4024F6A6C09ECEC00FEAF0E8AADA220317902A734CA430C84E5699DE750674A9F7CAB447DBB937E431018A050ADF6D526246767F7CB0DDF8D63BF122831FDC1686670825CA16A261534A48E712D0A5E0E68A77265EFAD238D63310B616E036C198F73D88EE6FAA0A7352A108695DC86C0CB4FEEE07719B876DCB7604C180416F6057E32455A0D7C8920DFEC3B91B9BC873629CA3D001467059D66C9E2EF4F31E2C92178C27CF24B9722FFE355C32A14951B75D53D8ED8FFA99693BD41AAD51964F7E44AD6477F9D2CE0DA2DF930AEE3904338222C51133132B0FC497A1F0B822CFB2DFC449E10F7D5B080B89920B486518FEA8AC14CF572D373A823EBC0733206DCCE604450000CA95838163BC0DB200509110E1A877221F3CDFD74DCB4895AD12AE02F30352627DA55CE4FCC0752BC84D0D88C702A030952D6A7BB43FA817D2DDABC20E5D49E8B165F2A828E1E8A0CD2E65A56287083F88F11E6D6FA76255EC84E8554E607B7F427E408A5BDF93436F9F45C2C5E850E521E12ACE3CE6964859EC4EF0B3193C3FEAF199B7B1C52EFC3617231425954F781AD53472D1312ED78A9B53C2948C2CC281E74EA8FD843265D296A0053F28EC6EE9D02BA1634A3E0A7A62C316E691CA98D5948880EF1A4210030964892AFF3E326AC29526AAA79AD83A65590F223B7E102CB44F49A2BD383887385D9FC294E5FACF72E7D358E212819DCD08AA6C0CBC366CA970DB76EE5F2FDBD89F84FA7766BAA12105E26645E9AA93DA0015C16A8C67D8C53263E83D276770C393F8807C2FDA9000F3237D50A0C246EDFEEF87157AAE7173344B0E562A10C62F252AD8B31C25EBAB7BD44F51A70FE560D6391374ACD07BFD372EF6FA019CFD1F938AAA6A243942809F13952161094F08DCA33C02F988217392F69DF32B4F8EE75AD6BF0EEB02C9A8EA177DC6C87B51B59E4CDB39C1C8E7269444E362B3755BEE8D8F9FE6D87E68B2452B2CE2B06A25FECD41D92EBB2C8F98C2548623DB4E4B37C486C85EA8F078772D5A679D6F08CC187675911260EB42DB4EEDB7D7B0C385EB20D612A9B8A8A9A515C8D5BDDEDBA678A89F26DEEC24B5AA0C071B27554573250CEEA76004F507747FA63CDF4A10E802DC40928F4192B84EC2A9FB98D7DBD6AA556098CA76F2FA504D8825564A30A1D7E6E12690DE34C0521FE70D15714626DEBC8008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 0000000100000004061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1019 +max = 1023 + +count = 4 +seed = 2629FBED0B88DCD29C3E7553B2B8C209455EEFFF7E8A3EDBA39BB1C2B4F3F1B0DAB5D1CE55060B1FAD562F945433DDC4 +mlen = 165 +msg = 1911306403C3C794EE57605D2FE311F4509324371103F69724087A7247687CD25FDD0C97319D6315E262EA581BB61987D5AAB33F331C7A7B260E92285C168DCECFC70D164D7A23110A165F456F22256A77AB7F0C5E5A69C91D7551ED437ABCB9B3101B8BD794D1939F372BEA8C5586BA15528BC4E4FEEBDD9904DF943513AA0E01FE67DF25E8F3075FC2EECB775DD2BE8D9D3EDFAD05762DD0BF1C228252BF2BFC7AD6A8A4 +smlen = 2500 +smsklen = 136 +sk = 0000000100000005061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1018 +max = 1023 + +count = 5 +seed = 13E884A522FABD17D2E055694A6D931C6459A17FDFA40131E19788DC572A47056670439565685510E54B3BB94D67226D +mlen = 198 +msg = 3A46A3D825C949B1E8E68F01B523B88347F0F249F6BDC0129A11CD46F11DAB4C11CB14FCD062A67A76C0EF2798D3586968EFBC619DD949ECBA08099B3A55F6917DD922DF985F769BBC53AA03D93E029DDE2B19FC02147BFE4B4756A560C75DEF13DB7104D5A6A238ABD0364A3B3EFB7A50754528D75E47FD8349B0D88569FCAF3382FB8C6C23CC52BB87B75454A0AFBAEC15F2A19EAEAD8C8FC15668CE37C8C1BBAA75F705B9804F2C942880C01C170D8CAA3C3743A91D569837DD84B50569F52302F8066600 +smlen = 2500 +sm = 0000000549F101925AB0FD811DF00BE2C75202021F2CD6DFBC82A8B38FB3A288863E316D4089B9994A97AE8AFC236A3C6B933AA82BF624CDFC8275E3D738E9F8B70B9F28705F444E6BA204F90AE9765DF09D51F8FD493B16385FB50C264D7FBEFC02912CBB280C74523E42361691E4415E749A27F3DB2F9E7145E9FA37A41E31316D5AE4AA386427D27F0C6989EAA280FBED66B67B3BFE1FE40F4C2B3C6829EFB834F0194E36A6D5B827747380A96C03FC8D21BE870FD98865BC822DB92A43413511AA3A0AB5EB2873A5E59764F5314677CDAF139B586A0FBD262A9C1672784156CDE6D5B933E36A67995B12FEE129EF362057ADD48C9F1B99251EA903975CA2D25036E74DC518F519A5182961B92256C810890595A156372328DD4DB4BA457A4CA4CF38B2F88AFB1420B5B63D295D38ADA7D44D7C818F7726CF566E5211E421B8DDCB20C265AEEB830AAFD60ED271067EF5B551A448CA78BBA817067D97D83A0696BCFEB6AAF5DAF64856CB08228CB09EC185C4ED7D6B331D49AE6AC8CB359D93B0C4AA7818C9B53B5B3DC7D08F4706EDEB62777707C0F322065B9A8AB683171115821677D85ECC1E7ABFEB6FDD609A7D1CE0CA13564E5723908FC997EB8B2D5C020EBCC82A09F3A03A49D2514003EAF26BEE005699C461069C7248DC80B903949B4652347FFE0361400DEC51D4513E48D4CA655A72B42633200259FFD2C00FF686F9A3678ED5BE780A1273CDF2DE1CE1BDD2EC627289D2407C7883A50BD752193944D927F9AAE86831475BCB5C933F053C46CC441A8007F4461397AD391F0E5BF9C40545FE403A7C2B82E25FB43578941554BB92BF47858AE719435DFCB6E34BFF2D018BF92C0A5F4DF75DB6F0BCB1E46B68F7ACB514CFBE11D2093DD8E966180EE009FEF7DC83B9E7D6126CBFE1172D32A74C9214D8FA7BB438B8225D213939151FCD463FE7AA412B0E5764359E43F2C8844D56B04ECE2CD254094DC351A8063FD892F4C04916DE2FF996E91F9C3AB7591F16ECAA108890F5AA4907BE6A99E5537DB234B5CA31927AE36835FA74F596A0E81D52DAC70E10AA0E5405D49136EDAF38838C37F2F76C195F7B3550E609FE6C8BB34038C0105EFC2469E367437F9BAA60B6B34D50584B4BD45AE85944A639734DC8D7FA21CCBED43811F9C593DBFE64DE8D7BBFEF68AD641137B40BCA3077EB58A632A09BB5EDA3C27EDBDB54E5AB1D7F430C9748C700BF4DC00E8820EC4CD825D899E1CFFC8428DF6698C0BA957281BF123A3EEA5F4110B32C36DFD114F54F3C89EC0475C46BE27A72D049D5F959457852BE47D7D88F91D5364C0DBA8A18AFF9CE8D7329562C1E89A7EB7AEA5E8F0039D89CEFED8A3E4BF04A201522C6EE71C17CAB5A93A063EDC4A3065372F089D7E41B435738F61C0B2E5F93DFE69B83F2BA25E2625DD27EE25D2777BB5472ACE985A4294D6A6496E3A99F02E0475F9A3ADB55E58A5B9F4B8345D931CC0119AA1820AE167DDD88423D632A563DBB0B22BF72105879594E5B09152324803258E981EFD9083FADD7E581F42AA9FBB109D63DDD83FD5635C58B9B8F3A53B8A2278BC7E8435CCF8C7E713552AD0A92854137F2F564CC9D659168CD8FF073623843957A342C9A78B4964A22DE1B1D72625F9B9F2F6C74FCA632FC09EDD8EDD2A5B846CDEE8ECB9CD932F16D6E3F23C0CA047A3F3E53B0BC18F442656AA1E271CF61C8A13A0CFBA7641A5A09713D75DC732CF9B29A73CFD5BCDD8F8ED2E8F3A1688AFB539CFF010D49641D753CBEB055985369F362C6D310C5FCDD2A270A2445E9CD5C8990BEB3A34C7C5BDD350CFE136E165C21BD7BF78FA4CB9174AA23F925D9824C2505E08A1FBE1D090E366D1BCD42978C6B48E855EB4A9693A3AE93C22B673695519976560C84188D3353C2EB5C864B71A3C66489DD368D3A83376ECA99AA7FA83709A12EF6FC1E6B82FB70FA258E7171761D963F2CC8CD2A4D30A1FBE73BFB606CA6114AE3F9D038FE259FDC1E5C552E49C21694D378EA54351313DD8740CAD5E6140526AA7EEC0627ADB8DCC5096425270CB32618FE5C6F068E934EC222248F80AB1718AF9E0E737588C1BF08F7B602ED635E060809F02F76238A7743774FCB1E6361FE16D4EE275F70A518FCDB1DEB675AD29873C78A651018B125FE05B61A124A336739CC0A5033A3E83FA87785FBC3C0BB14BDD143465505BDBF9FD96F3FFC6BEE0999CA1D857DCF6C6CBCE8520E7A5D095DB288FFF07D9B98F579DA18A374C1CE1C59A73AA409A8BE98B90415168FB55EFDD97EDEF5AEFD8B3B78F98565F1964CDBE714D1006F97F3D0DB5463974AF951DE47059C5F1215C7CA8ECFC34C9AEAC679C849E39AD4FF2C55D9917AEA1802E326B59D46538841333E6B3BC210D8217F4CA0F6D27695ECFC02EA7D24A04A10373FE455FC22B805147592954131E2F898B04CEC953DA2284DB98AEE5C19B4F9F527D8172A63AD650BACB3EB29097A171C1CC63CF98D01F0A36A3B2B74B683F9F5D14390A864461D1DD8E5E125C76C367A6FA5102C2DBC2250874DC395DF8D2B94B5627EF2C4242D067006F44544763F30A76D956B9E34EF0BA9FA7AACE7E15941DDEB407CE208AC58C82681BB9308CE30BA4F0D1CBE55174771EF0ABE277FD38C0C5506625D7F5B0CD361BA4BFEFFAFE08B9283A00267F71F5689F0D7F1D281C63A06003718881FBD01F425D7719393653D22882F039656D33EDDC4AFB3B15921D85D5896CC2C50085874D62AFE96FE98830A294F102768CE4D22548AB1C8E854783243A88C401402D7643C091CFD48CF6112E056AF6A9AEECC897F6B9FE951547CC633AE8C3A60C7C1DFAEE5A11908BAF8C77BBC92D851B52A7F49C5AEE0A3AB47FB65F49EB80E5E93453A022B0DF239BB99070BFCD354E2F7490841785AAA58F4655A1837E30A710BD43BB7DFB1A390D53E7D557E2630256989B4B945DA4A4FE88FACD5BABDBF179A7543C366E07BB0C77280613105CC9AAC4093E8A277130907AD172CFF1DC09C00BDB99687EBC2D59076E8E23E9CAA773C686AB2BAADE15865663C4D94834171FBE5A670FEE2FE269FA8394841FF6C2A3227E8EDE85215C74AB6A8C66DCB3B1C709614F01DE3EF6AE6F751B0A3F7C0F30D15B08B42EB0D30A5C1B528078FA366959BC1D592D86E3555A4820740E272AA2CD85C8E05202C13B89A93260496DED8FCD03F614D953E978008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 0000000100000006061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1017 +max = 1023 + +count = 6 +seed = 473EE54361C6786036B3540D9307B3C09FA9C85FA8A210CA9FBAA3690FCD7A0D9E64793F20E9D2D40F6426C0C7B7CC3A +mlen = 231 +msg = 8A2290A20898F46A2F922A0F9E2565C7E5AF20868E6C18D7D4F659C10F0A3FA2FC4BFB6BB19E9E09DADBAEE668F8A2FBD29B1591AB80738BA63EEEC291073B9DE0F5D44B53952C940DBECC8CFEAEC7B598135BEEAAEB2A0DFD8D55F9F51A10BEFCEFF594E74BF6FDB972BF4B9B514A03A5954C6FB09FB0640CD854ED6A9E62B4E98291C3DB7D2E19EB730A865CA6239869868F512BB38C4020FEB9554B9F5631E5A5ED00562B6A665CEA045CB66A5B7437EA4E2E55EF70656A9BE301CA3577CE909BA413A8A78371A493FAB5E89FB8D836E90F560857670E3761430A9364ACC32D7005543D8541 +smlen = 2500 +sm = 00000006EE07C35A8551A62496DE1C658EA679C4EB861964165B282F6BE686038253E3AB824C03BDFE794D985AF23AF4FE2C7D99E7B937CE00A56EEF7FB838EDD55B8B6F0F2351ED5A4BCA9A6069484DA843D459877DFDFF32CDF084A375C0AF4652683D10E44DEBF3C18F1DCC249934E0D3820BB77879ECB9569C4DDC24ED1AD4F7E8C8F3EA59866C2B1CA98BA038C06EBB90AD8D55C54D55C494DBC18B6CD68A92FD6250535E0470B9EB2BAAAEB5E138FDBED73008F6D78CA8AAC316BACCD9D26BB3D438C8E92E702F6DCF48B8BC696D633DBA5DC00683E55C823B14FEA4B3B515A78FCAAAF5E4ABABE932375B23F22F63128A331320E773B713A26C2F60787A82001DD43CD62E536F48B3EC2057E543D5A4269152FBE28B8DCEDD7D7E0619A29E17CAC3CD37B0FA7578739680E529225F1F339F4728145BAB14C18DC46C0AD95F20B9655DEF9749F7CFDD61B9B463A113082C3CC27524DED08D7E973CA017A6A783AA6B6593ED9BAA72026CD8F448D4568EDA5B5356EA1FA7383E6BE65C1C99506763CC75BDAC698537D492C6125A1898F336D4783337446A90DD492AB708FE436B28C94666C9575345B6E624E08D037240E93624C07B2A8A8D00A126783ADC599ED686332C26D8CE020490B8FF89DBDA3D922E30011436454AE5B56925BF0577BDCC9FA13DF431B2DD67E465CEB310470188850C4974CB29C49AE1DCAFEC474371973D863790FE4B5FCD5D1B6385F8A2E4D89D0B4F0C1B66F614633CA1C70E6B965FB35E287FEEE7C75C49EE8E779A3163C9088089D490E4F5499C5E7645253A193FE04FECD5DF49C1773EEFFD87C8D8E27C6807F66A1FB2F39A130B92281F37A0F5FA33D948E02EFA3F95AECA8E30E69F81AC0184E79715FBECA388468ECD41F93E518888ABF3F889617B27701D6A90B8C4C316E01821FDA25C675683AE08BDCB221D7D07E8F5886DDCFB8EA909A140B0EC9532170885AA44D8431A6AF7278B00F4BDA9E361592A552BA719C8C2D8B4789B4D7032DBC1BAEC2D54B58AA294926EFF7897A17DCF62C17CA8AADDE2CA9D535E17C45941F570371B0FC251B71668BDA3DF52F974E8D39E9588A3EFB5D67FD81E120E2FEEE49DDFBEA48C792E427A5BC2E31BA4486BAA224AFD29F8B44C4460D34F5ACE470B11830361102A0676D4F367716F4C337E33F599E6B109B0106E74C4F458AF084C47E52583239386656E9FAC487EFFBE24539F83B398D643BDE10E38F399C45C5768748D1D56DFA4958A33B0DF1C853DDCAFD31E4CCE279102297B3834A26BF59AF85285A6032BFCB9C47F11FAD42111FBD3BB84D283EB72B2484FD6FB10751444E10ADE45FF2FF2684D332080DA03A2B9C7E60D0BF3386DB98EBD745273EA8A4BFE54DD1021C2547568A4C4EC8E217147A6E4291BAC5643962B5D61105568E50A2A068422B2D555EFCCB2D940DEA1E0C675B910B799635F7C492F53BFE784094B43156632994123B197B1F616BD776A205600D43F65AEC6564AEFA1490D1FA688AA10111CEEAD764E4068BD720D9F6F18A78A99FD5AF3936252BE3DCCDB6A23B44713C5BB5F0CE37E32B114C86A2D507CC6AE84A1AD7AE601D4711BC4E249D34533A291E6FD309DD2CD9AB11CFA8269F7A1F898C3FB54AFC0E889A477E8FF06FCAB49039FFB0DC278820C1B51F7E3C57A2D5C23D832EDFC0D7C744876CD001E8E21CD4B286F0EFCADE9763B810DFFF6293387B07D52BD5375F2851D9BA3BA1A9DC61EB70245B4E9AF46E271D9BD896D1178FC22D37A0DC42ADF4326A4F72D2A77F796944F32D667C4F943F14CB764E68734D4F0BB8F99B13948539BF208228027F38C0CEC77C3ADE11FF923D55314245A8CDEC403A86351001EB1E1BEBCD967F2AACAEEDD7E35B67F0F21BE2FA970B6D26EEA7E3C0C1CAB7CEB667DFCF98EA04926B2A537CC6057EB2B87F95E8AB2104B0F0EEFC7B987033C83884FC1E6D29B4225EDB6A927DBD431B38BFF224D25D5CDAF99640F2EC6B68E93CDCF7ADB26309F76CA9361D07C7192FD3DE39F7A2767D55A32FB2BBDA1FE11A432BF156B3EFBF3B621665C01F2209CDA6F2F6AC96C7C11E335C54BBE223D241A7EA222BB901FDCE1D013BB65127A4B7F3CF582A2806EB91A2A04FD0B358F3D4440D92029AAE45A3F5E4D421EACE412EA318493238E05221716F5B540130B57EB0DEC4ADE20A973EFCB39358B1AF7991EFD5A64E36F49FE66E85AFAEB5D109B39450B6E2F7A30208DAC21B5207930ECF97D6B4145DA66D97B720F10B1893BF2EC59FB1A4A9B3F27ACF7ADD9523357F4BDF58BF6927089A45906AC41666FF9D07C5F01BCB6AAFB1F143785BD4757BFFD595870973C0EDF20CB138398D4D2FB3C6BFAD43094B4D54E304B2589036F56CAFAF88B6E2DA1D2DBCB6B9836A2C4FE0AFE5740A26DEE961FEF5127E6314B22CC61ED2629A65F75453C79937600DBF35F0D617D7915BAA4315702A01AC6ECA674642A5CC4B9C9F0DB03C5E4BD0A81EC25A45103DB65A8645259FAF50EAC96DE2338AA4716C5F90281EADB561F14C8E5FFFB31AC72BEDC927111EA074A607292D2A1BE66DDB1DF86BFCD22731BDD08F2E74AF0B501C25EB78A499E5A0D8EFD8162D2F971B8905209C257A82B2A1EFFA3A71217A2D81726D27F3168573D4845633D39CC9D8C6BCC7E9E5A6526D304B115EA9EE7F9DE39E3E5C37E4B66C88AED0FDB581D9D02B86353CC7BB1D9033B4D68AC47340548E6B3765691EF0B08C6396218D196479E8A481CEB342C2AA117BED03120634C0BC0A851EC74BD8E0EB5771966C2425FF6D071AEE103686C3CB97EDB304863A1B7A2EB65AE0914051582D8F1566B65ED24EF89D3E77E72E3347B04F625C95AC5C171F475A3224F971F642503C86EF42ED2625E80F5DEBCD6F6A42317197FC85B7ADCA648BE20140CA76D6983616EF1E4C6B3F7D7546663527AE4CD6AA2DA20B2330CCDC0C19C002CE42767065F53B59D196F5EFEB930C4F575ED9BF16B75F6FE0AE739A129122CE1AD8DA6DCFC0C095D2188633C8F6B2F56593A0A4894EA8F7468B5DB974CC4FC52028602378DB8A0048A871DDF234D0795FBB5F90571D976650ED1AF81B7DF18DB27D59E76D5458129C80F3C1100AD9366CED92297A33CE6FDCB5C59A66A40AF9D17F670CA861BDC8555A4820740E272AA2CD85C8E05202C13B89A93260496DED8FCD03F614D953E978008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 0000000100000007061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1016 +max = 1023 + +count = 7 +seed = 55897A15824CE06473EC510179AF2AD3CA03B55B7B654EC9AEC393C34BF05660AFBF6B553D3412A59C7E6C8D2F9B1DA8 +mlen = 264 +msg = 962F0F7A3A6771C64F3A6A1E12200A2F73D884FFCF600456D8BAFA0181F67E807971005B2CB81328151570971CE98FB1AC42CD1A2DE020FFE42ECA9C2008873074272042E6C8CEBFAEDCA2687D7721AE9FB94C692FC344015AA917224CCD579913BC415E4412E713C0D75594E414AF8008A27B5465771C2C134C326FC902FDDE7DF59CE13D4AC1DEC6CBEDFD49F03FBE569A3D8895E93A5CC222818400DFB40F3213C4D4CA879C9B8BBC5C511095E9AE15284988826604F48A9CED36519FA903D617CEB821F5B2BE249CBC9AAEDBDA3C62CB9B0E351C95BE8DE05D934F7AF3E336308D9D3F550A8A755BE060815F8CD070F1E7A3220B0C05BF7429081033E09C2101177698BFB515 +smlen = 2500 +sm = 000000075FF58A8D31442A261E6AC66AA4135E434F09ED7F1B7BEA9060438E4FFE7550B11731FEFFAE1F7670606B1B808BDE9EF5CE855A3BC0A876B9BB0BAAD32FC65A945F106F07023485956255F8A8C53166427FB74F73F8A2E54B44F54035993CED96088A7BC0E02A9F6D48BE225FBE7E4F0DDDA995C2E674A51F3C23F6FBD14509E6E88DDDA39E7668EE9C269F94A582B7C874EB415B85F90E37B5A6F0588287732CDC59010F052B59036CD379582562E27753A24093E0805C4C0FB9D7886328BC1ACEAFD216EA7B9D38FA97F71EB3217F4E67771F8599E4152CD25B64DF752AD2CA78D8047A8C3A7BA0A1ADFB0B36BD7C70B53E68BC8DBEEF70E255A613058D1228D3A66E210783230E3396944BB5265CBBD9FBF280BA65259CFEFFD2C1A73AFC24C06BACE7A0F391943EC311989FC54C2A48D001F8017727C6A1CF686B983AA10E60B1667FB0F05434285F24AD37F702C5270555A772AB7FD63D81CC2DCD2A088BFED73E4F705140ABA5F16BE1A5E3ADF0D57E1C0973916ABE4C6B87CADFDC6C20803BA6BE08E06E2EA2AFB2C409F864937A3A1F11E2E74CE0C2E9395F57B9F2F8A45DB9F6CBB29E8302AED637B8583C35539AF80CFE945B7B42533ED2AC67A23FC8327056BB50063140286585475289EC61815B73AF54834C2BD016745EBF78140EC5A1F2A20790871960A3C3E5DD3C006052BF3062762207369CF4420E6E10AD46C2EEB6DDF685185CADF5BFF8C0A624AC2BD0B253A7AFCDFE7EF58A74D31D9E22C922367B5EB709BF0DEA0D2100D99B9C45C9047C181B00977FDDDC61828C3CBF486F9740CF834C73AEF270974AC1C6A1DD064B7D0E592E408ADFD89C1703A505FF612AA6336C48F8A313BC3B7F0C5A7E2EAA53C5921A8CF7E785AC969B9E6A270277407FBBCC4E12BFC2FA475597EA2DF27FFCD4B3FB13D5F0A7A6FC7EDFDDA60EAFAF1D6010E20D775E49A6331D1AA90DFF0A9C6DBE9A7295F06B33965FCFDD65C5D5009670116E6FC2665865CAFA4614745F91B00EAFD4CAD0E5B60134BECFDE85074181E7E5D6E88EF6372B54145CAFE0D749114F67F4F6CE9892CC463CBB41D28E6B00DBEA29167E67FD10CB66F5A86AE6B240375293A61D31FAD2A9CD83B4372052DEE199983C7EA605574AFE235F512E8A369D6803C744B271477C42666C1F6D7F62B8796AFD2B20E881A250750EAFC85C9B9D878FDAD7D213B06CBA1606F6F9E757E25656A36E8649BA1CF23F66D3455D000B6690A3150AFBA8A246F14E934D670050A792973B42C49866CF4D9D1E02477D3A6F30C2D8861B46C3082941A77211F89ECEC545CD10241911E383FF05F65C0293E0F5F7D459339954E522F01CC219BDB80EB87DB871B426BB2D8D9A2FB71BB31AF9A9565DBFF52D27CA5C500628865255028093066F928463BB78C24B039F9C77520621FBAF880148A25F9FF262AD73FE1195B32C9CAC4C11E4B794D606577C32C58AEE7EA0BED17FEF0AC62CD9D5C3CD26AC00CB72455E37D6E9D0CD953BA2C055A6C9EDE3177E38194B9D8ABBDEA35B563E4FECBC7586FC065A6E69D18915CAB3912A9E41850FB837D31B2080EAFF8599FF759DBF67B8B236AECFD2EA7377D7D1C33EB9235158D1CDE56113736156792BA04BCF40AAB95A386D7D40AC57231B769EEDAE23FFA35DE8C0D86E6A45D08CA10B376EA95B4D41C5AB9F7E83E874C438147B0BA166146825A98525CE012F0D1448D064259BF17B3D1048F0E21934FB8723410466358DF677832693CA1E70531A960196436D7188597572B4D45B0657ED0393E02BBA2B4B1FBD1E182AE57E289F3BDEBF716B83825C1691CF5C45A9CAC1F7EAFBA71883777703AF3441B1E3EB5F18D1F952155B4550B9A5C7811F7A4D99AF6F76EAD52E89D8C8A67CBB330F4796A08CBC26EAD8EB9EFDDFBA6D24C51E2B14963AECE698264AAF3B7568F5F408B4D3F3E958C3EBAB5687B31298E92802ABB3FDDAEC811CDFAAD8A255D454C3D16BE06ED4A9A508A3C1208B3B711C02090227FC1597328B211A7017ED46AF836FAC35901B58F6E0AE7164071837C5DBF536EC40CCE73D062E13AB8E420A073CCA65A908CD64E62C5ABEEDDF49C83782C120F8D5EAB3C9940D8A5A27D72C62E2EDAD8D34E9A6E28C4EF88AA6BBB4BC530B9F6D48678D63DBCC817626A0BB5ED1A7FC2B039928D4879732A5C6E3BE506008DA61F7BDC2535356FAD462B28604A2DF5F93B56B76E799017A0D652E7CD1B76A7AF256AE56E9F1B2DD8177457A204EA51C2165DA70A262D3291E5B500249114E5D4EAADCE28E43AFDE8D923219426DA704A32F3C490203353F143196D0F76D6C3BC5D2B8679982E9DF6AB1A69FF0A48C94579679A6898A42E3B902467FD3F90ED13F8F34172FDA06550DF19EBDF355E35DD192611E09C16414702A6BABC3A46D210D39B216F65F22A3EEEC77DF45919755A1C27AAB1C985C66CFF36C2A83FBC21DDE858C530F519459982D5D6F3A283876DEFC2994FD13E53A227941FF0803603A0D68E95472BC442F147CAE9CB0DBC3490265A9CA4A93415BEE3CCB3012ADA9A2B54B2770C948D30F02BB71B5D8D3A149FB93A848459CE42E65F00D71AAF3CE838DD97153BCACF4512ABDDFB3157FA091F4C92461F3CA79459E188727316A5FBF3C1824C4155DE949657162BDFEB664ECFC5D079561589A44D2EA95202D8C06C77EB87C0D9CF59EB9FCA86EFA805F9536857997FEC12E9F212A121E25F11706DC4497963306B9F30707A9DF5D80C4D3FE92CA9DE57A81D0E3A93C494B9A681B5AEC35298FB6273B9D9860ADD35C90A3AEE088746FACC13178382795D46352FD7A59D02108B83D40CC143FC6A950520A1231ECCB8012D97449CCE14836FFA75C19D20B6A948E0CB6EE2F75328056BA00D5EFE28C107541403D881284A7D920C43EBC8B1134572B7ED6CABB97D282B693BA678D3A397D29961169A00D2F0D2036E83A9635E17944EE4922CA3B28DE5B3D3244754A9FC8B5DF913EADC8ECF573013D2E483B404DAC46A85F664A3D482614B3D504E1D1F3D83BC18759C78855D256799807DC2F4338AA29720392864A3CA81CDB32C8A1120D3E2D0815F6D77F7A00AA5ACA394AE30BDB9FC80F3C1100AD9366CED92297A33CE6FDCB5C59A66A40AF9D17F670CA861BDC8555A4820740E272AA2CD85C8E05202C13B89A93260496DED8FCD03F614D953E978008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 0000000100000008061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1015 +max = 1023 + +count = 8 +seed = 798BB062FA12450D432D9692C51C6A9A837AEF567604F01A67935E28CA16434B5DB2A5B74D45661491CC0495440FA989 +mlen = 297 +msg = 289AFDBFA80F8CA4613060AF98810A2184FD3ED165F4E0AF7FF0FA6E830493C99055DB441377C1FEE9FC7D0920A77BAC8650DA3B9A35D4306C2367B3D482EFFF21C28CBA4E2F7A89CAE8A25D5AB269DB6E43E791074999039589E5B38925EA263733B97D9EC5EA4F8C411EB2ADF10B22F3A65E1FBCBEECBCF13B877BA8A7FFE187807D222C73ACD352EADBB59176F9F0EBC7DF20CA7E46F5CFC9330A68B6F45A71A553096165D70DCF2398EFB4D8005B3701D6DF4ADFDBDAD30CBA98FC8254D7A1A0DAF653BFF68B6CB72AA2633F7539772F0872348759AE0D45571CBD3621EF06F1151F18578CC04FF6B7E3E938DA1F50D6E6C82DD0C6ACD4C36E84BCCBF5A4629942BC20434DE8B6E68315A5C62DFC2357F75911634C40E2B9B4DA89F515F9280EF86620939B369F +smlen = 2500 +sm = 0000000842B446CDF177CCD300BCEFAFB8133B67EE9F6DF02088082EB873B63125391DFDE96DDF21B58DDF08B1E0E813D21723DE5861C656C71D87290B1287B9B22F0CFFD5F63BF17A33F7D4DBD56ADFF47C06B9CB73B39B867D7075B92FFD38E38990EE4E29CF5EA9EFF96FB792E2D8031D60F422748B2DE49260C0D34E93C315E19264C6A0487438A3D1073FDFD74EC015D051D4384DEEFE689D7880BFA573EEAE2E3A7CFA65477167BAD6D2FE3FBEAA431FAB155275498D72533121800E2F231A662FC1F439303F05295328BFA0AB68B196414311629461F6BAA615B0A0E92350063BF58827C14F47B1D18606DCD093571965306A7628851D1A653B64E1463FA7BA83F468676371DC39F1F27F13C41AF42814F6409C00B7C4693AFA77F01537A286970F8A0A59800F827FE8541E70C27872EFA23DB0641713454D1A3C9E595F3E74C733F1180EAAD48D1A19FAF95B88A0561A05D296374273AF651DA94C4F852185D957E308672C760E8D08027DA54B47E7F38F215D85D43C515F8F19628B505D37F37AA5174549D57F6F3D42B6A5C51BA7EBC7FE0DE9B7935982E91AEB697D952499DDB4BA855A2F9215A72235DD9449C7F1CC4B4E646ACA12E0204476146618A0E4BD8DC7434016CE03A7430BE1E8EA827A381486F50F680409AE081EA67B8C703878A5445FBD0CAF5DACE16B9CF90C62A257392B20A44806EE3E8B60025A817BCB674E8D2FD2E6BF4BB320EDDB4007EDFDF0FB62892548D310218D39C974E12064EA28920F0016A6E2636BF6D524E0912E2B64DC3EC7636ADD0A20C81CAE6C3BD62CB872634523C7D6CA8DDED004A967CE50795687E4CC41335E9A8AC976C95A270317DB7D96E6CB596D9FE594E669C0604798E453CB5A9CF36E4F4974DF1660CFE562CB63B96ED122A9A9B3C38E5015E64CC3AD37CED7C2192AFFD1A4A6BE234C6E60EFEB7F33F25A33FF5A7A332657CE759EF5B81CA28C1E497FF9E4CFA1F003B8F5F1E8FCC07E8ED6DAC6C06D2DFBBF86A463E9B71F2D1552DFFBB05755CE4AD2289EB1BA4B9AE3E56395509A65DD521EE58F06D0B4E40C772B702747F36E7DBE6CE7EEE4A1E79065E590EF37A2CF6E1CE3A88909701A70765BB1CCBFA94AE20BBBB96167BD93DA33D79DB3815319DC3F38486E64AC42E371E6EF0CCF14FB4B2B6205E89F66FE2A572ECCCF85881E6363271B58F434E38FEA4B15013C95B8F5867A09AF06D592939FABDB5B96ADD3A179D366F99150E3DFF63185569F2D862D412073B9DD13655B8AF0D87DE06B2809191D1EC754FA7342D5383EB2C7E702080A133B51B7C630CBCABA758AC54A015D53DAB9D3ED19C4ADCA361F153CF8C4CCA568FCF0367A8CC348B6C2AD139859443F6F0CEE2B6B354727265CA14F0AA2271A96F4ABD72B8954E103AD1402FDEA2390C07D1830C142A0AC4CD4583B31D54AE3A64F668FB194767EEA716AEECCFB8951419E328201F781382A198C9635400A52FAC59710273FDE792994308B7E3856C21C5F1227A3438FF54A40F4D9A29918BE7639C83D06341FACF62FDDDA8AEF74FEC6FA3F09433E6C3C5D0A5316178DC70441E38A12D8BA742FF49F5B8D3971A0276C53DA416FC6ACAA94BFAA1B73C5FBD59057E553BC71A7DD537CCD02FB22C9AD9EC122AF040C7F8F28A53686F841C84F0630E1F694872EAF34C80390D28F934A9D47E6E5FC367B187E74F2E698569A484244645F4A714500890B0B9FCC4E1130DA1D4F03F7550D625C3680335C2882D188DF4F6835B9549F1A4D33AB7B028561B43A860F4094CAEC30C81E1F073E9A1483B846B0642FB037CCCFD505065D855EFA681EBDAE286B337B8C472ACB6C310BC608C1637B01D3A1578C2B9FE032B263EF2E0C42190EEE09FCDCB555803566473114D1B05DBA7ADD15813F6023FD82AA25AA1F6AB1EBABBFFCD62FE98F83A17D7DBA719041CFC155C09B05B1E0D3D8909B1A892542FA5B31F90839AFCB68A80070DCADCAB8249B0BAF81E8D0466D9F6CB118DA6B80697F4366153FE94A53600361DF10D11D1937182F02E5832E4AC2B95AEDE0418736BBB16A285BE7B9473BDA4EB2B2665E255C6EA18A8B07111F09E9B057D5F9176BFCFDBF3E3E073143BB33A6744DB9E973130A7D7BF99F148A526630964617E4D600EA5E1A27277AF646C909AEDA2BE16BBFE7CBF037562819C4DE2AEA88CD6BFD18F69D86D37F2321AE06324D5248956964ABBF93F9B0E106C692319DD7742406F98550E5B31CF170D6EFCE0CA28465258A2D76559663F1B7BA77C340B7FE06C45988A5CE8B7B1EEBB2411F1ED856ADD6E7EAA8BE6895534D3D0BE1CE385CC416F06EB27F5C6C69D01EF1A81F4E3BB6EFF9B0F3992D490EDCBC6960F5DAB0081557D385821D08BDEDE73CDF33A9AB3207F72C85B9BA229546724DF96C87AACEC40CE3A89D414A4C2DB9F9950843F05473C6BF0A69A7AC5A366F6B4F612D71A71669A8BF4E3668003F2CF25E0C1297F5B8293598E6A7FA1299E3A5E383215A3F41BDFEC4CB9163BE8741EF08DA132A934F84164D05F4175122BC5152CD651D697AAEF291F8D1A18DD49AE8622D0DC49EC77FA23FA51B3760F6E684AAC5B949729DCE376553B16082C70BD43848584A56F136D01BE3B80B4AEB9B4BAC518F17CF44ADF14B618DD04059F55D666A7BC0AD6747E2F64C8B25F55A4DC0B178FA14E80EB6A8C6CDBBC5FAEA9BF0750E6463E3C1262E3EEE072EC95EC3AC8939DE5F4111F734FB0347D743F1EAA67DD4189B92BD8F37B2B62EA00636F48ECA262BFAF0238DE48D2D0EE04865979682741E96C05DCF28BBC40D9A7A95EF2AF8040BA3F44E72FD6E04887937055AAA644A073CC82782214A8B9948ED942283FADE73D3E3E7F14105AE3FD1613DF6BE5CBBA99008E5E4A61EB0D57400FAA7A150CD1F690C3C3FF1CC695CEF8FC746DD836025EEF5523960E786F7DA022C9E4FDD6F810DA35C9A71BA26B8BE68BB33814A5D5B47088559D4CE3C910B1A70435755466E86B74E8FAE08AC7910F177D5142FC7742BBF0A738BF76E9E72FCD7C2957CC74F299285CF21B8A71015182678FFA04F377490152E9B4BA60D4B220F04EE5A38902E62627C12B696360CBFF4C016C2896B09E62DA088FA83B58F5C0F0D645FCFF2AAA1305F5A46036716C1464372A0437EC5E25D80AC6815CAD5B7EF29F71AC68263246E725C21DEF39E6DD1316C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 0000000100000009061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1014 +max = 1023 + +count = 9 +seed = BC4285C7804C15AAAA7FBF25D494E763DDA04B15414E1EC6461BBE0B7C6962A625F087B9DA019F277CC038FACA1CDBD8 +mlen = 330 +msg = 8FFC13A7F7C0C6C20ED56AAD2FD44C9C053DFEAC4FA62446A6FA4CE691F347C89D0BACF62C54DF754CBA2591209EC1619960E6AC2612EAAFAD3D343ED32AC1233DC00FCD88CA2AA8152F13B1FF530840B6E10C7BCB4E1022BFE82F468458A45967834E141709019361BC4F6AB67326884FCAB2E3EE3DFA174B9862C078218F8BCB5718784B36725ADF2907901147AF25B621DED9521FFBB2270F2A3C98EA901EA9BCE0764968EAD9D4FC027515B478B670841A4B61DCE9FE882242FE22F3830A9BE0B546287F6E0CEAEA92002654E7BB73FAF673D4041B5880584E1FC566F90FB2FABCB3DBB2CB30D66610B73EDFF23C89F20B6BB1B3BC71C17133F64966FF9A8404CA350D2DC953736B731D63E204F50B1D5F44F27E255F8FB508892A369F9F8272078A1E988C6C105C9D37F44619CC46E7430759C67AA7B131D23B2D405C3ACE8076EDFBF21783D2E4 +smlen = 2500 +sm = 000000094E8205284069747FA1B604DAAC8F1E8BECE4756454AD65441B745B5948618129E48E5AD2C080DD21C422723EA55CAC647B30EF0A0ADD4A68ED6CF5F1AE68EEC8A5BF69C4922F886D35EC8575F036FE13253B2C2433399BC92FB4805B108CF0B810E10CE31E16808A7643AF1DC74CF71BBB9065507148629CF9246CBD6D17ECB5F12D59E88410F0F6F04CEE6F87795DB6FFC1B78D43AA1C90C54FD44B7FADD9F76C93B1FFA7EFB8185ECDC6D11A1742BE67637C90B73073DB977FA393F50B48491F03A34E9811B87116EF3F91A563F7D0799AA6962B0BF216FF3C20B86062AD1F37ABE3CB927731541F9EC9ECCC74206E1B7A42F8BD8622E92914B221C2FE884EF67E56DF122DFEBC8F3703ABBC9E038A5CC8FA5B67DAD5F5942F9CD17067B06D28669A5FFBC4A05FFC0A771BA537F922F08DE9F8EB42B28032887494D4FE03E8668F6B6F919E681F5880A273C855A073EA44890B1A410334EF24C0D25B3EEA3305EEC8793BA12EB6B076CF52F8A86DD9100F984D700969EB78ECF034DF14E3AFC9C1C2A9A37346F89480D540F72AE127E7476E95641581474966AA07B76092548FF20E4170235D597E149F0B44F17B751BF082AC74E1EC74C4CD9474E37FD587B7C50A8451EF651079B7C8FD9BEEA5BB4D6C58C6EF6C5F6D12F6868C355753C9606837AC660D3C54E9113E0DE0FB750D1C86801346B1B89F06710D531319D2D49385C7080BC6321AF6F6F89FBD36399E2E3B82BE93B0DE483712DC5D84C2DE999BA81CC850721ECE18BC31C8F39DA690D338B24927124D0F2C40C1AA5E50FC0C22D52BF200283A153E146E82C1F583BD291A3AC3B07FDFFAE57B3E4AE9CE2A4679BE9602DB5B666089359C4540D2FB8AE0031D5D8064E45FC9083B03112EEE7370676863752BED12C48E167C9FF0AB1DB5D30F2DA3C6866FE436406A7793270A6BA7BC9C859808BFD5C642C592AF045793E9FD64E5744E51E043D288AEEE79CDEBDCDAE181F3E93A3B202596754CDDF4D18F8E6DCB1414345893C8C634430CE5C3F3AAB7F02BA0BFFE16C775D062F04A43412C0C380C823427605EBDD6726FE33F43DE8FFED4BD73ABA600E550B0E710F77D8B0B158AF3957D19E2A70605227F5C13BF7367BB4A6456667F5F580F6B303536F29D70362CA4DD30DAA727F8E74006F4397482EFBF1A6C30641F720B1D772231D706B4DE2A72F1EEE2D31573238A995C22F2EB2EC5B7CE61084C88063808C4C1D3499038D7CEBF37F6C5EB9710872F24C9806BD5DFF7E079537DDC64CBAA9EA208ABE23F7EDC5A7791CF7600A6F85780B70EE9412165FFE815F02F74896ACA1EDA0DCB593B74D6D48CC6E1053B5372D767D03B4B5B4041686BDAEC4F42F2C202649CCA404572228DABA2D04604AFF5BAF85EB871B8B5C82E03BD992FA2569DC8E1E4CA9041B755A94B9E4F06F7A662EE53D8A0B019D05497FD6032D9E95C05BB59E9F9458B4389000CB46F4190A19472C4CB51D873AA1A6FF6CA591E938E25E4C898319D850E0FB8C0DB6E983155297734F0243B9DE56F880D8DCB191EB9F9CFF45CFB9E1BBC92FEDD297A3811FE691D8674B82F437891F8AF6054AC87AB48EFE883FFDCFAE21F26E1BE134B53AB544F6E9DBE06938C0C466CBAF170FBFA7EAB618357635A83411E2CDCA0BB9323EF54CCD4128D639D80B127E7729ABDC04989B06EFEFB7C87BAE7D48EA599B7EA627B98A6317BE3D70824C25747FE3D2347E01B0CF7D3F389434DD167D703291DA0CE89097F339806CE37D526B7859FEB93E6E176ACE8F6A038AFB424BE1384422278141BD3EBBF890F3E9028CC7B770B9E8928ABD210ACDE38A31D38D11DBB6B9921D915C61616B9014170AC5124B2E4CC6C66F94906682D29946577EFF47053D28BD6488640C65ABE97C8AC8F9603E1EA89E082CAB6BD13C0D010DFD8E69211CAF3FAAAAC255365E928C47C88FAEEF61A27312C50FE10F21C719445389B00E7DBB32863F90D1E13014C6267B1FEAA1D3615F30AA72CB6905A5A9E78A9F406CB1774C5BB413D73D183B3C3DDDF7D608AF61C1459DAF34C99191A3A9FB3D99F3C45DAA3DD6CE8D4FB4991F367C00540BCC233AB6545BC7BAE87B319A1CBA5A8C17D2F3EBAE53008BDB896ADA1105B17B340E28940900865DEC2FEE01652B9FF9261A1660D8B2BD82044B4F224FC3281CB8DEAF17B7B06D5398467D9655AB3A0A77EB7C3FAD129C16037B0FD3750AA356106D26B11E9ABFB1A73DD9C36BA2346B38ECB00535EEBEE63A3C0436CF70C974D26FF28C580C88509907F68AE6332461880F839644B37D8999E16418E2D0152925CC0F0D63C87F612D30404FDBB347A932432037384FE00A6D0E9B0B97A99063FE2BFCE1FF51AF5CD593F6E4A2F82845A44F174FD8647774260944DDF0D006ECF6EBB9FCA61FE5B5D6EECEF44E4187EA3E9AC8C17294740E5B016C7DCB10E603FEC2C3960F3A83B41B84E14705129894B682AC1A52FC190CA10CA3218C5BA67A6A0314F6F059435A6D3B6E347219243E33808FE0E12F188BC30DE394F5AD725421DDA0EF686282DA121461BBCD039EEE6D500BA10BA92078BD4A3A44B9389F7778114BD126FFABB724ACEA754DB959624D8167A8FBB90BA4F38BCDBE3CD172F4972B189F1D08548C4AF7F14D9C405FC5831BFE59D13716CB9B1941DA438EF93E6770DDE04386DFCED416B3BB9A911DAA57423E0DACA2B93A2839AF26F1D3B49587A46BCB694A4323B08E8DAB4FC80E94B80319EC849445530339BABDFC4131275444636526496420453C5E917894C9F6459492D6F7F24728C83FD45D0F2BCDFBBBDD718768D8B83BE2DCC2CE080F3E48973BBE6AA1577858C9AFD2AC2FF2066562C4EB88ABED1F284A6D40982F4F3A2C2CC9A34FF7F30BA1FFD4F629EB8A3434FE46C523F903FBF457860F50F2D0ACE9A4D7E2FDF5E6EE7036C5DE8EF9CB7270E93D5F84E5A097417C2194BB54534B66D1A1761B165B6549EC8D7AAA2BAD5775C3C5CA78FCC38D738772746666765F8909B8327D3427F0F8BCB815D5BCAB5621B4FFD0AFD5F2DC983DCBCBBEE1622FFCB09748081B59F493821B467DF8B22B2652F4E3D112C38A15CE733E4610833DF3F16C2896B09E62DA088FA83B58F5C0F0D645FCFF2AAA1305F5A46036716C1464372A0437EC5E25D80AC6815CAD5B7EF29F71AC68263246E725C21DEF39E6DD1316C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 000000010000000A061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1013 +max = 1023 + +count = 10 +seed = BEEC566BC26E2DC13FBA54ACFB667A5C77FEC1BFFEFDC42F9131F1524FB0F71AABFDAEFF6894DBEAC6B89CE3ED236239 +mlen = 363 +msg = E24DC9F0A986B4F5A349DD1567A80B7C1170C980444F715998681BFFC2417661BF0B503E11D2BCA8D135968E6F07FF0144308AE69E55F4CD663A3CEC5C5D84D00E5C0FB2E458CE22C7E41761852CDA6EC268A8FC06E76D1E4F03A90A6FA9D1502F6F21295106F3485C9B3A1DC6C40C8E304DBC55AB2B90F6E6DDB404D8487D736E5466243F0B055B060287DF589D66B88C6DCF6D2FC8E88DC20BC9D693BE9B9744C31D181558289C3F2406BDA3CD3FFEE90249D95214C7D77E1A9927123335573E952FFF9A8D3BD66E020AC1FFFE5C1921DD7FF6B48295B6D2496376AE1E98CDEA032BCB8662A915301FBD014224CB7D899CAE2889FE0D673E0B55F4A56C914DE868D61775D3DC92366524F606C9E279ED231B0662ADC50A4161C19149830305B9BB38AA2606DA23830C3951386E63DA6DC2176F48B2ABB26619833074E95391323F0EE3B6151B2FF463EA3CF3BE55C2875EA93586AFF0CDB4B43DC7E8A156510B74E566233066EAAAF845 +smlen = 2500 +smsklen = 136 +sk = 000000010000000B061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1012 +max = 1023 + +count = 11 +seed = 66638FA3A92FACE1BA5B311362842ECE73B6EBE5637EDB3E16B0EBABAAC6BA9335BD63DA0253518A6B9648BA490AD60A +mlen = 396 +msg = 942D9CEE1FC9325A8E6456194FF3E1ED7562E19AF59C7A0F7569911EFC22A89EEAE8831E66B528797A6DED2E0AFF50933AE425245953BF95637826F3483F1E8E12E12BA8D6A42D320235405E422ED3522F25F630AEB0A63635AD70A51CBFEF6DA246562A10529B3DAC58C50BB08F88469987DB5EF8B3E37BC07639E56058B93DDDD88E9735B3632E37B3DC0146E3EE9A55F29DF71DA5DAF7A14CDD8276F363F3E1E4C6DEE2BF623DE44F0C96DD03AB00BE02D5BB90C61B870E3CCB41ACE1D1FB5902FB1FB2F866E92CBEB41117C5C5C0D367D20D797BF09E0C8EE934209351A149A306E34A62DFF428687C6285FB3682F94FE3C6B1C28F1F0537A60B4C9D71E2B01DB08DB7A033E426C73C86A061345B0596CDC6FFFFA005CCCA8C7807BC293D3E14D5881D6099103C98449640AA2E806592D345781D81D6EEF1CBA823E0DA1858C3647CAE811D7FF87B9E08C7AA1E2EF8ED615AD32B744CA253B6F172636A964A1E2719CF7DCCADC61569DAE0BB1A37F4A942EE17762586BB9A9BDE8B66671D50ABB592947337AA71D35EE1 +smlen = 2500 +sm = 0000000B455CEF8ADB9FA246879773E4AED4C367473AD23FB89C5BCAFB1BAF65F9615D4408268EB928B66B1709C9A932AD9A450B20263301918FE23671583B5674AF03A96A38194A098992E96D278B8B68F9B56451652E5C7B90F3A8FD0DE39BE575675EF6D1ED6655052DF350B420E90A070CE2592CE4B832969A07B513E3C7A8F3AA8F025A596591F339E09EFF624D89F97C65E131E0289DD0B34286DC38AB98A56B09AFC9B14A5A2DFEBAD49D476A2F8829E881591EA506C3AA5B1A91F7830127437078E74288A6237956BB16E90BD69079E19792A01CCFF507DF31D99CC6AB1D654A133CFB22A9DF43D1C427B2079EEFA43EE6F2858683E90440ADD529EB1965298EABA124DF53A0C4B1E41FA0C0FBCA4E52ADE2D0D19EA2090390F4608518EE8B3B9FB051C9466F601684B6109B2533A6A3E2CB7530F49EC9F1E1271210C90CB3F4B798ADD65CF9033077CC4DD74549FC87D2744B1303F3C7406330A40E4546BD76B979E9EEB8AE22DDEF7A2B2A3F5EC9E8289466FE038C1EB224ED4CC8248BAA09827E2A8E08ED2E64B233EBAA973D459DE59ECD7A4E47A36D12CC86EEAC6D2DE57AFC79BB41177F6E7E0853F8E2D43DD9E206F242501794E73F049A046522434E35FC255BE32996A9A67188440C78F39309060FE62121D5FFC0CD8DC91F220403049390212DC9A0BF50D1D58A3D4E5ABBD1CC6D50020FBBD7AE31683E01648F71828594311B45C60EC2272144C6D8548777E74D79B5F83C4AB3E26F1C05F99A3CF59F8E63CBEE6E5BB2A10F7B9512D6BDED02314516526854DAC0349897B9DFA3FAABE9A886C6AE8281FFBA9E71FC4D35DE35B7B456C7C6B95BD4BA0DCCE93323F055890226E95F267F03B166509C3788184BAF6B3236BC674190B2D3ABF2876717D90324B6A7715CA39B77CDE920E7E39F2DBED6A4FE6AF3C5AF8BCF555B0F77FD63F9FC15E622323F8D0BEE79450F367250B5E77568C5E650B06346AD938FF4345833B98CDE075CA1D4F36EED5A0CEC89F6A2E33D22B64D0A4C39780E62A21E4106DFDC3CCA753F659F3CCB9FFA760EE79FB6D6ACE22B8FBFDEF1F1D297860E07D726C667BB13653A391A839AD24DA7FC889C194879D4AA22E3CA7F7929040F8325FFEFD805B769B02F39042B03B04B4DAFCB23C360A4811F70E7F95DC20CF5E0FE8D5567A96D95896BA67938E5458685527636DC1CC38389A25A1EF8A44D04ADB2113613323637478C6992466AA02BA69462D85F8FAD94F3228A9374B26FD050BF0BDBB18502C5507C74C40850FCC6BBD9A771FEA0772B5FDD7EA346867A444AFACBF6F2FA4C781E8C49A1FC4B3CA4068F737FBADF261C25B264C2FD8B9623E55941534EF53933BBD2E8628CC0DE5C60B472170B204867623AF8441F84486240114D164C54F316A6DB6EFC6A35BC7FC1A06A17E9E5B410E26C67E78857BFC6FBD8A4F71F9F81D8DD85958B486EF132E983BFFA0EE4E2F2D13600A51C331FE58EB164F58757A0649F0D0A0CE7665A6A099856EFE3150C3AA79299DC1DD4DFFB0E939611A74B69D821E33CECD5FA2F012F2D40E494085CC3DEFED33E101E5240F7C2116BE78D3843EA1ACB017D27888D76E17654A3F0C9CE653D4910C09F883B8D4A7A6DA7BE70B3356EE4F253C583C086A6ED94B0E87CA9BC0DEF3AD297C76FE001EF31B028DFB7A1D430B7F569EFB8EABFEEB09063F0ABCCB87A66D58230D947EC0D3F233457FA206FEA765837168525F5B70095EBE76CF3F5FD69CB65F7DF3917BEC3D843F39B65789A28ECE4ECF35FD54F9D5881CFAECEEC601589C17C227477836EB11989474CE24B64956022E16ED7275FB32833E22AEDA33E89E2810F479E886F2B42DCBB1D4F7D662BEE7AAA6C942C38AFFA6BE24EDC48E2F47131D7CBCAD87C639969B2E58E71005393294A1FB75CECE19DBB87F309D9989D3F1D98744608AA73B53887660E22BFA6087678F52A636F5A0DD00EE1A40D721ABFFAC571852F5301A71F23DA7F2D21B49B36C4D0E85D3BA7A9D15A5364B799F696EE31701A6F53F22D2111F025D4919C6B305304AA180FC6551F7A9997D9A5A242692DC8C146B282FCB864062119C89050DD8952C563D336A2D00560A5C5EA5A1DFDC8273CEE2B9546813198F011D9C7D640A7D75CF036445E58E566A2434CEB19EF8870E190E9451D537E0B5E4471446366834DB65649F58DB535152061A5BD598F9D940F299B42775290719DEEDC87CE332EE592DD40E687B5D6A19E68CB24293F3AAECA1B0059CE264562190DA057A230C98222A0664741B63D570B195A510B5DFFEE9831C7CDB05936F0EBF0A9339324D1E42BC9157216D5F61C177D08C620E2F997259C7323143F0B968EDD22EA9A003C8CB3A74C2481B3596E64B261129B96F345B4927F144C6F1D744D88FCCCE76368B915C75D09089D9542C0CFB45A770A0EE5E03F6C4AF3C49735317136E25197C589958D0155F97DA3BC054CBCDEC2730A8B4D680CA67C358B887285BFF3EBBB3EB6379EE79E2BA86C7887C8EB4983833E48C9D1BD56E1013969C7E040196E9AD08980284760CD737FD46AA537D8B1274DD8267CC7F82889B1AB9B2F6CE75FDDEEBB7315B710A1A2BC6D286832E2FA6E0AE88B6AEB5CC99E99567E5CB106FED3747D132F1AE277DF8FDAD615328E2C7F3CE2BF4B1D75B9E6E6B68758FF634158D3CA893C49070FCB5F5D0C491334537BF3D33723E09996843177A77BA37A268D63CC95B36AD8F53BD9CA859345DC7A2535E488BC4D5C2B889F1CBCF242C35181121C8997734A0E614038FF6ECC1C15F9BC6B1F4B3F40DF1D612A1633485AD2A8040401F1915405565F4716A5CA159B7B6EB09A7EBAADDE2E5DA3D936B2CE5847CC9BFF737A2978F92AF3C5B907B370E49133D6E162B89BFCFF176965497A24EE4A6C0C6FE05C544A4C00D5352F6DE408D34DA24248EA94601201E6C0EA92B2562E030B16AD3E3C391445D3EC63591470D2E9896E07C7A17FBCCF45D69B1C9BB1BA07B6311FF2B97C620CD0AA0E500222E7F17C816BF5EA50F85302F198830A7E4B47A80896290F8DDDBE63E1646947C7EF5ADA43249E35DA580A61AD34EA9DE90785B144564C936090F2C725C86246723B5750C2CD15888F03DED5904065F4CB00EC42F7106F41F11E69246E59737AD06772A0437EC5E25D80AC6815CAD5B7EF29F71AC68263246E725C21DEF39E6DD1316C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 000000010000000C061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1011 +max = 1023 + +count = 12 +seed = 495AC157AF18D1563D6A03CCFF53807D532FD46AC67A624D433DAE418CD1E0F5FB76789EEBE1FE0A50279D28E411CFFC +mlen = 429 +msg = 0FF7A2C1D92BE47802CFA7186033B611FFC9C4C385F016D1762A79ADE356C85E9D81F35F5B3095927B855C194DA184B90A54B6241B8915A5F989130248E28A92C9A7EB5A1C6FCC96432C4DB091C75923BECA9C4666320D955EA2AEC268E47DB6735CF0297B9BC6E4A033D413A3CA7B7BC6B8393268AC91DAD4DA427DBDB14A20F16CFDC9CA0E7C904EA182F060BF6458147ABBDBBAF69C631B9DF27330F8AF63122F32D0099F5CAE7FE0DC3AF91E8FBAC3591B5A8B5ABDFCCD714F6643D4D3D65C6CE7C73194A8A3193FF8DD2AA8ED8113548C0BBBBE4C68F96BEC93D799B64149B010EF776B191E6246498B19286B8D53D67CE09D5CAC398917B46D8530EE55B67BF8D4D00164A519288D9112309713B9EEDEAB11346264221FAF4BADCA7E6578B3EDDE6F37EE9CE2C2CCA03FD61383213C2252D35178918476B7A1B9E6FBEFDCDF1B3F02BA60562EDC5B68C6AC6FADFC1CAE6E9C267DEDED7ECFA507F277C18F80FE0A9E160654F1F4234E5EFCA51D9754C12CA0C5E96395835F3465E6AF793ACA81DC57EA044D43DED72BEFC8806DCFBEC917E89DD816A48CC726A39EA8EDA3917744EB45C6B4C09A08636D +smlen = 2500 +smsklen = 136 +sk = 000000010000000D061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1010 +max = 1023 + +count = 13 +seed = 21905954F5B96B48D223480BE10EED13A16F59C175072AFC3FBF0B6A69939917E07EA5D998523CBED0993F9D5C5F603D +mlen = 462 +msg = DE4F0CEFC7B6A7A83AF41268C268EBDDFD5C01366509402723283AC6BF6EBB5330CF62190E4ED61F8C232C9DD0DABE0628782029CD7BFC67765EA0167294CBC6EDD7C63829ACD5D09447AF5B13AB605FC51CA16044336DC888AEF43C7312E38BEA5E4378E7B260E01A9566FE2A8B2893429BF5B4F5A755EF901EB19BB2E6365FA83F11BC1CC5BDFE57E2A009340A034644AD8A72B467430D42AF7DEE753572E00A41886D971D4145A8D0B7540A63D26BFAA06BAFBA4C46FC5672047C56D7D5BE1E12F50AB0B3430A815B43901FA2BB1921956492692A6943E6035099D509CFA0CCA8077329786962ABD134909643BBD89D7A5F81A8F96CAA93E80BCC35BD75AB6F7CC43F1563EAC9FBCC697061C7FBC391E55AB545105B70555490F10C86D0B0ACBE5758B06132530E90D9F35B3E23C1E42F46405BB54D485B8A78264EA8E612A4332FCC46EA04938465B94298900129231E974159CF5359C6BEDBD7CC4CFCF0E79DAFD0738307105590AFC8F076AE6F026B9FCE281727D1DA9D3064BD534810EF08E05181F1496B0F014F7F895D67465781A905F3B90CD203C78442EC4F289DB7814763473FFB29B60645FDDD910C35F5D3AFAAAF516AB5060CE9AD57C616D15D90F8277ED658A6D2089535E437 +smlen = 2500 +smsklen = 136 +sk = 000000010000000E061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1009 +max = 1023 + +count = 14 +seed = 5B9F2A1DFD877CBE4E30BCB6F022FE142E1611189F83AE628D64EBB329AB0D9C66461CB73EE17E69F5B637CF4886BDD0 +mlen = 495 +msg = 971DA327D2195078632898AF79691F8F5F93189EF0807714096D27480E82B1F0B884AD43FEB3151AB6B7261A501416AB982BF9F2234B8199F89EDDCD56E160E1825E79365625A979FE157E9FA937926E7F12C4B5091EE6572CF8D4FB9FB8E1090BEABCED73AC36B35A5020EAE0134A3291CB10A05C3EF778038702843739E59ADA2C3CEBA6353B482C5F80E751E10BF13DDACFC6C0E3FDD09B21710ECE846ACFA1305074ED4328B90E65B1FBABC53ADFD964A4527CB1B8101C30A41804A5EAB9A00D135C38C52EB5149B6655B60D5A1AF50E3D0DBDF63A035924102495B46327A063292503F4D72BEAE063B577B57226175AD58DB98AB164521EA9C21A78D2BFADCC109B78082FA4AB1FF3FAA2B768BE3FDB1F929B67010944DC3AE6941877F599B478B03F0C267616AEE949197CF7D230EFE0930CD01D6D4E0A6A628068C6006B06C75F2DACF6027D5A2721B34A232A73DADA62A1721F2903983A5A04EF8ACC4C5E29114A9BED0BBE492C1972212DF08D3D2D8041E5658A42442821044AC7A8151F621BC88A56B53E84B5F342154C1109716BDF877A631EDF7BD64E5FE45A0DD40BB58C91F9DD5005736DB32DB3B57B9DAAC0ECCB66860689F5C1F6BF9D5115544601260F22A90EF77B340DE9B4C7F38250528D57140EA5FFDDCCA4C4254252CAA34A4DBB9F643B18ED950DC89A06 +smlen = 2500 +sm = 0000000EC2BDBED877538AEAC597717A7AFBEA0D0954ABE8A2E303FD5386BE09B9145B0C4F5203CC3771E11D3EBF99F8CDB84B8B59940B570676EA55FDF6996BF8A8EBC5293080B32CEFD214031A7CE6C9A239751D15738EF36195812AE0553CA5054C8DACBBCBF686C371801CC80544E9BE47B1E01090090D7BB51B52DF71D91417FB922D6235B34464CB75D6357A9FD3FB19789C78A1B5445265157A8F58C97083C9A3F77E1CB62F400722ECF9EA9607872D3C6A12925EA7F4D0FAE1359D3CAD5B84BAC51B5E18DC6F915D9D3877248331E841CA5E2A9E5E22ED89FF387200E50F52CCEABD27D6826EB2287DB82D7EE520391FD597B6E73139D84BE3C1378B822898C4A8EC07FC922FFBF9DA07B3A08A3CEA274606F312AAE564D581E8E2E7DFC83C26D7FB29C88996A6363BFDA2115931D23AFA9E1345B9D8DE542FBB8AE1A883EA2C3DD893029D9DDB7320E0B8CCD1E864D04FB2A0F88F8974FC26841D212F70F7714EA7676B20C0EDB14F3551FEDF6A6F9A81C06F5409791E02B2152E90B3647D326890361887E005819E758367695243C60DF2CA9611B9836478290A82E471494336FA2D40D2C5768047EE8B2837D82E232F8A52A5F28D79A5E0EDF59E8FB27FE189BB5B0F3E8F2112955DEA9435CD0E8DC59671930528016B04B05864D309080A6A142F0ADA36AABBF0A7565F08B7AE8F893D0E724DA5DDEE68CF6EB05DD8ED5BF327B3F681FCDB708F47894072B5A60C1FC4DA918A8BF40E01A1B85D546A9CCD65CA4C45EC66B81D15BEEC0BB1114CC87C8768EE0C1787EFAEF0B623754DF068A9530EEF7E4A19434BE78605C5230F8351AFB855920EB056BE2A3C38AA1130479E653E93869E556170CD10F9A9820E6B6A17BCAD164A16E0AFD1F57FC7C517AEE878241675E44B8F85ABD1404E4C55F17B05C4D3E3E6C7197B1B90CC1C770758BDBA381E61BBDC0E4BA9E36FCD992EC1FD2A8E598CBB9F6374A3665E10DFD38E1087998DA2875594CD5712639D28F4614C3A5238FB611ABAA56ECD0D80CA77AC229B6B7CF9F0678A4C9ACB41E232B29BE6A7C3973364801E1DF151E9B947F768CB76FF97E4C7F00902FCA4D83DCFB51359F01C68314BE71B7311F4A93AD651014F35BA773E27EE81E38018FF840FB5456120021B04B9CD5503D5829A7394EB0FAB8E211BEB08DD5063CE686B34CFCDF0101F29CA63D1A6AFCE6ED512B3D4E06DEF655C1E70C09072911F6ED8E75B35A466941CD98B91927A59F89D4E417B4457FF686CB305BE08A9FCA46AE7B3D0515374A3A15CEDCF67BC0ADFB84605471C5D17141D89B4930B8D16309FC3FE1B4BE671671C67761A2A65565ADFC7BBA5EBA03D46675DC407511A8AF49055628E47BB8148F69A0DD542AF9A8ACAE95042D2173FF559AB30689BF2DD6CE2E9BC177DCC38954F5019B7F9CC6D9B6966D6B5F3ADEDB3CE772A017DC98CFE1C3EEEC6CEA804D9A862CA7CBA4F3CE71D27647784840F22DB7DC1D24FFCFCC73CD086AC0C2F5CF6F090CF508BF802C397A53EB393B6A8E3B890615C690AC84C7111BDA73D772AAC3D3A85A23A10299C98D8CF31A96F75E69B00A1C7E73A5DF7F5E5156315D60A26D2620720EB7D2D1218328BA7CEA44C0E4F67F5390CD395DE53A2A1284B643BD496D4622739BE6D6D20967E6D295ED74753859E43762105686FE56BAE2BB7D7DFE92148123BE34FC191A3A095ABEB7D62D9276986F6A6E5E491707750CD9397315A8E0A116E730EF0DC1F872DD3CE6C7EAEEB299016940A49D6D858E1130B4BC0DBEEB28DCC45507477E149AA8F89165494D20DB95960788B7056F3C300664C51B6E57AFFB185760E7CFEA4E0950A6087327FE90B85525EAAA477EE77A3E5CDDC7BD7BCF2E0527B04BBEE19531131335F280406CF18AD9755ED995F5D7DFF50C2843719A8A65626F978D15F738019C5CF0E9C83639EED862E518F29FB0D70D80A3C36E565AAE7BBB04BA42809C591002BA8D1B7FF8579A1D50761A10A0CCC32219784A7C79DAC25CF1495B2409D5743D93CC3371BBBB66D1CC54CA6B5FDFF6F55AF6439CE48B2B54420214147E247AD6AFE0612556F092C9A3009DCD78D322374D111B8097AB516402CB129CF3CDB02EC6F86D85B67B8E3C46637A20CD853E0419DA7351803B6B716B143636C6B67E911508FBA163FD126C895E916FDA1E61652AD18B5F875CD954CB401820DD4B33D42F6AC6EEEF32FC6F002F93A02DA8B94996676D189C1EC49DC3B50883300654904C3FF42EE2204AFC09F10FD31840DFC03C6F1DB94E9B4717A81BA75EA6414E25EAF1EBB07EB10A06DC8F6E998C8BD2B4FC11B0A39132787BCF8EF204325CD749CA55C0C0F181C860506422AD1533DF054CE2C4A14336CFC2F491D8898881C7BDEA290F03B592F41803DBFA4242B36A00AD5679A4B399F6BFE5CAD3651C20864278C1E21108FC5C931DD609DF0C862DD5580D143122B31752EC50166449897AB37CBD781A38FBAA8AEC433CFE069375345000C149664AD80A49A42D63E6ABA5EF18A7D5BF3DB41A2AC6F37EEBE6EB51D6A33DCD0D8696060CCE1588E4F5FFFC9FDD71D77841C999E305A89FCC77FA47DBEF546787A18D5BD3B245069E12BFD01EB979D661194A65B9F63B2B618A924BF6EDA90F10457A10F90BD0D8EC793ABD8826A7858691A600BDCB889CABAC8D6DE95D68A2AFC1B6A7D62286302D6C639BAF3BB56CC040D33B0187220708B7B9FB9B61EDB2919585F39171A084EBA668007357DBED95E8A9F4E19B91CCFEE25DCFD85CFAFA286A77451934373B5F100621C794E375F6E69F6DFFAF61B9375EC5B5EBC8F0AECA1E2AA2437D0DA7331207270FFDFD83CD40C3EAB2A4BD452DD5567FE4794C74509A840815F12EF9CD26DBD164B677FA61C06CE7280C7A1A9D2570081161C15CE3F39183F8D7DEA87966BF87E191261E810A4E476A29E8FBAC4C51BEBB86630CE74538E9161F05E001E7AB2DEDF2C4E85957B0E9DB53E2190CAA2513CFBEAE419499E68303810DD604475B2DDE732DCC42FA8BD29FECD128393E422E35D9ACC7BC70F43787A4F755BE4A04D21DB18559FCE2F8C54EF3BFF39348DA5E63456B063063786637ADA04174AB9B37257E6024EB56767E439125B55B23CB29B00820BF6C9F81CFE63392A76BD3DC57C574540C6BD3EEDE15DF113D2E8492260FEEAA8049ADE7A99AF98CFBB7C67F06C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 000000010000000F061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1008 +max = 1023 + +count = 15 +seed = 6F41B5F7648FBC1B70F35CED64B3EA95E04EF08CA2C96D8AA264D85F1556C15B295E98699431B072AB2EB621390B6BC1 +mlen = 528 +msg = B0B98E653197404F869906E4E247A0C65C485EDB719D0F24508F55E2E6B2F10247C431B7D02E7107375D6E3DE9F289993C5C082026EC982D0B3998448E4E82610A7EAC8ADB3C2BB1FA3FDCA3ED8151CA94DEEDCDBC6022FCC2E89C2CE89D3C3DDFF2BF86C3AA47FDB7992E1DFED195E2AD2DC46D8E8D67DF6C7157B85E941DA8A703040741DEAAA88FD97642B546C40A135E5D184403A218EF425069D698D9D2B765FC7DBDE46661644F616DDEA73FF9E0ABDBACE39A00DF1802BADE7059DEF4E2FD622DA13154612DE5A74EE2B38EC29D3F4C8AD96EFB347B29B77902E0020919C32E698EDF88816F4D8E55F6EB84B273B879D51AF6DFEFDCEC72113EA9947E7448C2D15A56E748D389FA84C94F8F67DD52B5AE6393EF4B48ACE2B45F4A47007F33CF1C40F0DD043D964B403104290FDCDF56AC39DD3BD28F7AB3EE8BB455CDB0E9AC9129363E8979B53E34320C6516F6861D70AD47A605A13D00E59506A6FD48D8DDFCFBAEFA0A3FC6A1D4B8599D440EE71AECF85F3456098F361C3BCD1562C8537CDA207B1911E33C58CDA460A7A349528DDF8B2AD41E979C858FEA5BE70F2147316FC92103D6786A75D1B3D3B5B18C9DC0A702710D3E4EF0AC9BE325CD0E8F1AE09ACFB0CDE162153CA8E894AEE6B9059AF9BB37150FFA76C532122531B3DBD4D323BCC10F3D0FC7E814C6074B9C5D9328510415D7DD236D478D3F349D5338DDA8D4BB273C8D0290664D6661080B +smlen = 2500 +sm = 0000000F6380E9DD17D8D82C80034710AFF3D2405CDE036AE70A8708C52A514783B2DD9212717E6AD1CD1A850658EDA7D055CF04648DD80D6DA435DBBD4140B90DE079C064D1FD5611B0F5810264A148DECD4E62A8554FE38D50E43CE5F8E1D72723C12134BDFA3105F5D90C8D21FACC87EFF761589B23AAB9DA9154E7E252ED30AA186221D640903E2A7D2328629B8E7C2BDC9CA34886171ADA9E8533C983738A84A2982797D8E200BF43FC145B4F4897D06F3BFA36D57146777A34ED9A331BF33028A1CA92C0B24E849A3217EA488BD91743A44700928532C0953C227CB2D55589A8F340AE7ADB2C032A35B79E35C718CAE4BC28B3DE25C031116DB97C9542E3782AD56511A9D5403A93A06482A84469362E83F35EA57660602E3E0A37F0173CE0DF978678609AAE4EF9A413E09A78B1F29534CDB9087B494AF99ED2FABDADDD2341EE50B9CDB3F70C3C04225599FC5BEABE0E4F1643685E5F2D9DFCD239E40E9F26AE5BCB355845BF3803B7A4FDCAA5CE632740C32B6988B8EEDFF960F9489C4A45CB5147A69658D73B1591B6C6867BE801E95EAA2F6881370EF61D17CA8FEEAB89C3914C7095AF2F119820585193CBB91F70D5408A623C518B6EC2468937C3D9960E217B79BA016809ED28604DE75C9FCC65F77503FC95CBFE6415F4C06B6750A88387F8AF1825C982369AC1B97CDA8B96CAAB4EEA9C4A1771427A64DF8F9F8E2C1DD9A2106D16216D1411D8F3FE17C191729A75075AF3001721472A311810E26471832BA89143A762DF88E00C3F958DF6DB414602AEB08E97A4FCE7219362EF3800EC2B3BDC1E2B936D8F4B1E4F2F65F2A40B404E397765181CC40D0BE334793D827F5151A66CA637E5914ACE7B72C7DF2E20841CB2CC3DAB8D00C30E7392F146B55770D4AD23365373C4FF113255C9DB98319A2ECD5B2CA74216B623F1E3AC2351B322C2F8296677E5A1C6E499019087B2AED8B8F7634F4BF74454B65DF2CEE89C3BF4458A240F2CDE6E5D6598607303746F22A5813DD284E458C1875A23738D2D061F738C45875CF1C09895424AF5B16C444935DA630958D036FBE7E8112307027410012162EF755B11A9A717FCE491597659C1C7D613917A3EE153C0DA747BA30979A75DABC39CE1C4DAFC9B8CA4B9CAD9389759564DBF6E5C44338DA26AB20BB89884ACE11C23C80C772F338026D679BA493BA54B43EEBC894FCFCB82037CA9B87610C3CDB6B40FE2A4D0D994736E41BFCD52B1E353DCD1F6A936D46A088658F29AEF70E52CB10B7C9913161D534DEDB19F3052642B2FBE3B7F13A9DFC90ED2F31CB13E40851E63477EBCA17AE8DD57162DBD50229E53CE2F7BE182BFDAFB1CBF7411BF81A6347D36EF370A80C214BD810DCC51AF6D41339450967BB1D64C83D291F6A83A34DFE75F8EAD9BCE44A1C35D63B5052DC6D1453BEA470CC4A305353E5AC54316FAFDE70CA0DA16DE0558F99ADAE0817EF389DB33520A86E1BA5AEB53F9AECC98ADEF00D191EF7366F35A95FA5875D9E9328B8B60E7F55B49BF8D813CCDD1ABD4D06F44B09819A2E8EFC61EE12DC83A5D46A2B673A8B985F763CD7D1A396F7E0ECEC0BFC0D4916946B68C6CAFE5F2B45F345ADD145ED25BA9BBDAF5DDB7EA6BE3B8E89D7A9837BB55851AC5DE3F0ADE35A3C5E1E39561FB850D238ACA632997059755FC1F5C9B7A58479CCED5251F39811885AB916CBAAE4698E8F6CC67D14071317FA79DABF2F3C9098438BFCE22F64EDCD49EBF75FCB7CF0D5804821B1892F7F417FF77B2C61020A1DBF66561B351503E8DED31427B50CA896A2BA37627477F33FC50CB0E51107ADD6391C5290C9CEB0AEFB837EE3BAE99FAE78C2215CFD10E008BD0F26490DD5A1ACC9727405EEFCE6CCACFC4F291D9CCFD726957477487E3B64200EC4FABB79A38BF7E1F4B00FEDE43C28D1E7A0EEF3B8E1639436DE69B53A13EF5267837A28B1E0788E736F08C5DE95BCF030F9B24DA8616218B983D22C20C6A5C4436EF236C6DBD6AED69D86F5BEEF250FE21FE4F75630C2D77D39FF35C205363A40A7461B12E2A52BF0BDF70FB8C6879D2A00B8CC6B44DB4F7FB8806DC5D80CE9AA2F72268BFC256848618F25C46260D013D3F0B0D2139B63829F1D616CF4D47749CFEA5E5336539214FA73F1048C0E012CB702B4D1C0407DEE769A4AD046480EC020E90622A2BF1BB6480E52E8CD6EA4AAB9F861FB3B9F2C8853F3FBB397BF7F58ED6EC2033FE0579ECD921C24B03A446ED3BC2F7C8B93D59E52EBC8CA571A6DA8AD8C4B2DA83C0A3EB19B5439235097CF87710D9378FAAA12EC6BF5AE6E36D3DDF2A4809CCAAE552E41F404006785C9BF30A7EAB3AA5CC9C9FBF7F8DFE93A356993D3752FE88C77E9FA9B40A2B5272855B8C7307119946E5577037E2382EC700F57B8B962DECDCD2AC7D6C4EE1887EB9EAD542753548A60BFE6FF83F8F9D8950B82C4642FAFB58C152D69F5E993F762A86CB9A13290F07AE77CF788361E5013B3D1EAF5174D4184AE7BF8711EA50B04163CB4CC7EF645A2822BD5ADFA0DEB85D6E1CFF105B1BC96F2C0644DD375E5078B8E3F7A0962C54BD89121DE087243ECF73588938F487F163CF333E5B5212EE3E71264D21A3965785F09CD97737CF0FD3206347A33DC95A7A31BBB2FDB52C0988A35AA3EF74EE257C3096FB0AC40CF11DCB91C09E1A19B86F57E20FC6C1B868D10B990BEFB03C975A0E010D131344557C8CB49BD1351E166B712B351771D7935E5A26BA1DCBC7832D467F6B8D2BDC69078E1AA40D236700EFEC54E7E7D26C67B2167DBE76C9F529F28CB8C2078EBFDB364886686DD3D251C6F060C1971504984D33AAFA4503043339A494FA48165B42CF153DF2DFB6B5ABC2716DFA6FFCCDC60C49C82D27773B0D7E6194BD5840ECCCDD59C776501F7C2793F726FBB79C7E174689BDD5D47E50DEE6B1FC2DBFD7A968A57DFFB2D646192DFF2B4AB63A284A9FC4583FBCD0128BF3831F579BE0F2000E31C7C98C43104304CBC168F60AFF77E65DE4BFB716B9F3619688945BEB34ED112E619B017A744A9AE1624A3DFF9E935E639D9DBF5700D99575A8681F83BF86EE67ED1D9E75F03622149FBAE8E916A1DAF2255304CC3676687257E6024EB56767E439125B55B23CB29B00820BF6C9F81CFE63392A76BD3DC57C574540C6BD3EEDE15DF113D2E8492260FEEAA8049ADE7A99AF98CFBB7C67F06C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 +sklen = 136 +sk = 0000000100000010061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +remain = 1007 +max = 1023 + diff --git a/tests/helpers.py b/tests/helpers.py index 58f0834511..f050f83366 100644 --- a/tests/helpers.py +++ b/tests/helpers.py @@ -12,6 +12,7 @@ kats = {} kats["kem"] = None kats["sig"] = None +kats["sig_stfl"] = None def run_subprocess(command, working_dir='.', env=None, expected_returncode=0, input=None, ignore_returncode=False): """ @@ -192,10 +193,20 @@ def is_use_option_enabled_by_name(name): return name in available_use_options_by_name() def get_kats(t): - if kats[t] is None: - with open(os.path.join('tests', 'KATs', t, 'kats.json'), 'r') as fp: - kats[t] = json.load(fp) - return kats[t] + if kats[t] is None: + with open(os.path.join('tests', 'KATs', t, 'kats.json'), 'r') as fp: + kats[t] = json.load(fp) + return kats[t] + +def get_katfile(t: str, sig_stfl_name: str) -> str: + algo_dir = '' + if "XMSS" in sig_stfl_name: + algo_dir = 'xmss' + if not algo_dir: + return '' + kat_filename = f"{sig_stfl_name}.rsp" + katfile = os.path.join('tests', 'KATs', t, algo_dir, kat_filename) + return katfile @functools.lru_cache() def get_valgrind_version(): diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c new file mode 100644 index 0000000000..9685265902 --- /dev/null +++ b/tests/kat_sig_stfl.c @@ -0,0 +1,289 @@ +// SPDX-License-Identifier: MIT + +// This KAT test only generates a subset of the NIST KAT files. +// To extract the subset from a submission file, use the command: +// cat PQCsignKAT_XMSS-SHA2_10_256.rsp | head -n 16 | tail -n 14 + +#include +#include +#include +#include +#include +#include +#include +#include + +#include + +#include "test_helpers.h" + +#include "system_info.c" + +#define MAX_MARKER_LEN 50 + +// +// ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) +// +int +FindMarker(FILE *infile, const char *marker) { + char line[MAX_MARKER_LEN]; + int i, len; + int curr_line; + + len = (int)strlen(marker); + if ( len > MAX_MARKER_LEN - 1 ) { + len = MAX_MARKER_LEN - 1; + } + + for ( i = 0; i < len; i++ ) { + curr_line = fgetc(infile); + line[i] = curr_line; + if (curr_line == EOF ) { + return 0; + } + } + line[len] = '\0'; + + while ( 1 ) { + if ( !strncmp(line, marker, len) ) { + return 1; + } + + for ( i = 0; i < len - 1; i++ ) { + line[i] = line[i + 1]; + } + curr_line = fgetc(infile); + line[len - 1] = curr_line; + if (curr_line == EOF ) { + return 0; + } + line[len] = '\0'; + } + + // shouldn't get here + return 0; +} + +// +// ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) +// +int +ReadHex(FILE *infile, unsigned char *a, int Length, char *str) { + int i, ch, started; + unsigned char ich; + + if ( Length == 0 ) { + a[0] = 0x00; + return 1; + } + memset(a, 0x00, Length); + started = 0; + if ( FindMarker(infile, str) ) + while ( (ch = fgetc(infile)) != EOF ) { + if ( !isxdigit(ch) ) { + if ( !started ) { + if ( ch == '\n' ) { + break; + } else { + continue; + } + } else { + break; + } + } + started = 1; + if ( (ch >= '0') && (ch <= '9') ) { + ich = ch - '0'; + } else if ( (ch >= 'A') && (ch <= 'F') ) { + ich = ch - 'A' + 10; + } else if ( (ch >= 'a') && (ch <= 'f') ) { + ich = ch - 'a' + 10; + } else { // shouldn't ever get here + ich = 0; + } + + for ( i = 0; i < Length - 1; i++ ) { + a[i] = (a[i] << 4) | (a[i + 1] >> 4); + } + a[Length - 1] = (a[Length - 1] << 4) | ich; + } else { + return 0; + } + + return 1; +} + +static inline uint16_t UINT16_TO_BE(const uint16_t x) { + union { + uint16_t val; + uint8_t bytes[2]; + } y; + y.bytes[0] = (x >> 8) & 0xFF; + y.bytes[1] = x & 0xFF; + return y.val; +} + +OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { + + uint8_t entropy_input[48]; + uint8_t seed[48]; + FILE *fh = NULL; + FILE *fp_rsp = NULL; + OQS_SIG_STFL *sig = NULL; + uint8_t *msg = NULL; + size_t msg_len = 0; + uint8_t *public_key = NULL; + uint8_t *secret_key = NULL; + uint8_t *signature = NULL; + uint8_t *signed_msg = NULL; + size_t signature_len = 0; + size_t signed_msg_len = 0; + size_t sigs_remain = 0; + size_t sigs_maximum = 0; + OQS_STATUS rc, ret = OQS_ERROR; + OQS_KAT_PRNG *prng = NULL; + + prng = OQS_KAT_PRNG_new(method_name); + if (prng == NULL) { + goto err; + } + + sig = OQS_SIG_STFL_new(method_name); + if (sig == NULL) { + printf("[sig_stfl_kat] %s was not enabled at compile-time.\n", method_name); + goto algo_not_enabled; + } + + if ( (fp_rsp = fopen(katfile, "r")) == NULL ) { + printf("Couldn't open <%s> for read\n", katfile); + return OQS_ERROR; + } + + // Grab the pk and sk from KAT file + public_key = malloc(sig->length_public_key); + secret_key = calloc(sig->length_secret_key, sizeof(uint8_t)); + signature = malloc(sig->length_signature); + + if ((public_key == NULL) || (secret_key == NULL) || (signature == NULL)) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: malloc failed!\n", method_name); + goto err; + } + + if (!ReadHex(fp_rsp, public_key, sig->length_public_key, "pk = ")) { + printf("ERROR: unable to read 'pk' from <%s>\n", katfile); + goto err; + } + + if (!ReadHex(fp_rsp, secret_key, sig->length_secret_key, "sk = ")) { + printf("ERROR: unable to read 'sk' from <%s>\n", katfile); + goto err; + } + + fh = stdout; + fprintf(fh, "# %s\n\n", sig->method_name); + + OQS_fprintBstr(fh, "pk = ", public_key, sig->length_public_key); + OQS_fprintBstr(fh, "sk = ", secret_key, sig->length_secret_key); + fprintf(fh, "\n\n"); + + fprintf(fh, "count = 0\n"); + if ( !ReadHex(fp_rsp, seed, 48, "seed = ") ) { + printf("ERROR: unable to read 'seed' from <%s>\n", katfile); + goto err; + } + + OQS_fprintBstr(fh, "seed = ", seed, 48); + OQS_KAT_PRNG_seed(prng, seed, NULL); + + msg_len = 33 * (0 + 1); + fprintf(fh, "mlen = %zu\n", msg_len); + + msg = malloc(msg_len); + OQS_randombytes(msg, msg_len); + OQS_fprintBstr(fh, "msg = ", msg, msg_len); + + rc = OQS_SIG_STFL_sign(sig, signature, &signature_len, msg, msg_len, secret_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sign failed!\n", method_name); + goto err; + } + + fprintf(fh, "smlen = %zu\n", signature_len); + OQS_fprintBstr(fh, "sm = ", signature, signature_len); + + rc = OQS_SIG_STFL_verify(sig, msg, msg_len, signature, signature_len, public_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_verify failed!\n", method_name); + goto err; + } + + // print sklen and sk to check the updated secret key + fprintf(fh, "sklen = %zu\n", sig->length_secret_key); + OQS_fprintBstr(fh, "sk = ", secret_key, sig->length_secret_key); + + rc = OQS_SIG_STFL_sigs_remaining(sig, &sigs_remain, secret_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_remaining failed!\n", method_name); + goto err; + } + fprintf(fh, "remain = %zu\n", sigs_remain); + + rc = OQS_SIG_STFL_sigs_total(sig, &sigs_maximum, secret_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_total failed!\n", method_name); + goto err; + } + fprintf(fh, "max = %zu\n", sigs_maximum); + + ret = OQS_SUCCESS; + goto cleanup; + +err: + ret = OQS_ERROR; + goto cleanup; + +algo_not_enabled: + ret = OQS_SUCCESS; + +cleanup: + if (sig != NULL) { + OQS_MEM_secure_free(secret_key, sig->length_secret_key); + OQS_MEM_secure_free(signed_msg, signed_msg_len); + } + OQS_MEM_insecure_free(public_key); + OQS_MEM_insecure_free(signature); + OQS_MEM_insecure_free(msg); + OQS_SIG_STFL_free(sig); + OQS_KAT_PRNG_free(prng); + return ret; +} + +int main(int argc, char **argv) { + OQS_init(); + + if (argc != 3) { + fprintf(stderr, "Usage: kat_stfl_sig algname katfile\n"); + fprintf(stderr, " algname: "); + for (size_t i = 0; i < OQS_SIG_STFL_algs_length; i++) { + if (i > 0) { + fprintf(stderr, ", "); + } + fprintf(stderr, "%s", OQS_SIG_STFL_alg_identifier(i)); + } + fprintf(stderr, "\n"); + printf("\n"); + print_system_info(); + OQS_destroy(); + return EXIT_FAILURE; + } + + char *alg_name = argv[1]; + char *katfile = argv[2]; + OQS_STATUS rc = sig_stfl_kat(alg_name, katfile); + if (rc != OQS_SUCCESS) { + OQS_destroy(); + return EXIT_FAILURE; + } + OQS_destroy(); + return EXIT_SUCCESS; +} diff --git a/tests/test_helpers.h b/tests/test_helpers.h index 5b1c17d7bc..a4ab668c2a 100644 --- a/tests/test_helpers.h +++ b/tests/test_helpers.h @@ -7,6 +7,7 @@ #include #include +#include typedef union { OQS_SHA3_shake256_inc_ctx hqc_state; diff --git a/tests/test_kat.py b/tests/test_kat.py index 2ce19d3593..c69f76c981 100644 --- a/tests/test_kat.py +++ b/tests/test_kat.py @@ -35,6 +35,22 @@ def test_sig(sig_name): assert(kats[sig_name]['single'] == h256.hexdigest()) +@helpers.filtered_test +@pytest.mark.parametrize('sig_stfl_name', helpers.available_sig_stfls_by_name()) +def test_sig_stfl(sig_stfl_name): + kats = helpers.get_kats("sig_stfl") + if not(helpers.is_sig_stfl_enabled_by_name(sig_stfl_name)): pytest.skip('Not enabled') + katfile = helpers.get_katfile("sig_stfl", sig_stfl_name) + if not katfile: pytest.skip("KATs file is missing") + output = helpers.run_subprocess( + [helpers.path_to_executable('kat_sig_stfl'), sig_stfl_name, katfile], + ) + output = output.replace("\r\n", "\n") + h256 = sha256() + h256.update(output.encode()) + + assert(kats[sig_stfl_name] == h256.hexdigest()) + if __name__ == "__main__": import sys pytest.main(sys.argv) diff --git a/tests/test_sig.c b/tests/test_sig.c index eb3ab0af12..90990adad2 100644 --- a/tests/test_sig.c +++ b/tests/test_sig.c @@ -129,7 +129,7 @@ static OQS_STATUS sig_test_correctness(const char *method_name) { rv |= memcmp(message - sizeof(magic_t), magic.val, sizeof(magic_t)); rv |= memcmp(signature - sizeof(magic_t), magic.val, sizeof(magic_t)); if (rv) { - fprintf(stderr, "ERROR: Magic numbers do not mtach\n"); + fprintf(stderr, "ERROR: Magic numbers do not match\n"); goto err; } #endif diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 405def1754..e80aface60 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -129,7 +129,7 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name) { rv |= memcmp(message - sizeof(magic_t), magic.val, sizeof(magic_t)); rv |= memcmp(signature - sizeof(magic_t), magic.val, sizeof(magic_t)); if (rv) { - fprintf(stderr, "ERROR: Magic numbers do not mtach\n"); + fprintf(stderr, "ERROR: Magic numbers do not match\n"); goto err; } #endif From c9c3835c577e52d5da0fdf3c83334d59594fcfa8 Mon Sep 17 00:00:00 2001 From: Douglas Stebila Date: Wed, 12 Jul 2023 09:09:02 -0400 Subject: [PATCH 06/68] Re-add OQS_SECRET_KEY (#1493) * Re-add OQS_SECRET_KEY * Updates per review and formating changes * Set function callback for 'free'. * Address escaped PR comment * fix formatting * Update src/sig_stfl/sig_stfl.h Co-authored-by: Douglas Stebila --------- Co-authored-by: Norman Ashley --- src/sig_stfl/sig_stfl.c | 33 +++++++ src/sig_stfl/sig_stfl.h | 96 +++++++++++++++++++- src/sig_stfl/xmss/sig_stfl_xmss.h | 2 + src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 35 ++++++- tests/test_sig_stfl.c | 37 +++++++- 5 files changed, 199 insertions(+), 4 deletions(-) diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 9ee29a9736..2b68e6dd94 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -107,3 +107,36 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, size_t *max, OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig) { OQS_MEM_insecure_free(sig); } + + + +// ================================= OQS_SIG_STFL_SECRET_KEY FUNCTION =============================================== + + +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_name) { + assert(method_name != NULL); + + if (0) { + + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 + return OQS_SECRET_KEY_XMSS_SHA256_H10_new(); +#else + return NULL; +#endif + } else { + return NULL; + } +} + +OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return; + } + + /* Call object specif free */ + if (sk->free_key) { + sk->free_key(sk); + } + OQS_MEM_secure_free(sk, sizeof(sk)); +} diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 67604f5b9d..6beeb8c24d 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -145,6 +145,81 @@ typedef struct OQS_SIG_STFL { } OQS_SIG_STFL; +/** + * @brief OQS_SIG_STFL_SECRET_KEY object for stateful signature schemes + */ +typedef struct OQS_SIG_STFL_SECRET_KEY OQS_SIG_STFL_SECRET_KEY; + +typedef struct OQS_SIG_STFL_SECRET_KEY { + + /** Associated signature object */ + OQS_SIG_STFL *sig; + + /* The (maximum) length, in bytes, of secret keys for this signature scheme. */ + size_t length_secret_key; + + /* The variant specific secret key data */ + void *secret_key_data; + + /* Function that returns the total number of signatures for the secret key */ + unsigned long long (*sigs_total)(const OQS_SIG_STFL_SECRET_KEY *secret_key); + + /* Function that returns the number of signatures left for the secret key */ + unsigned long long (*sigs_left)(const OQS_SIG_STFL_SECRET_KEY *secret_key); + + /** + * Secret Key retrieval Function + * + * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @param[out] key_len length of the returned byte string + * @returns newly created pointer to ley byte string if none-zero length. Caller + * deletes the buffer. + */ + uint8_t *(*serialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len); + + /** + * set Secret Key to internal structure Function + * + * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @param[out] key_len length of the returned byte string + * @returns newly created pointer to ley byte string if none-zero length. Caller + * deletes the buffer. + */ + uint8_t *(*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, uint8_t *sk_key); + + /** + * Secret Key Locking Function + * + * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @return OQS_SUCCESS or OQS_ERROR + */ + OQS_STATUS (*lock_key)(OQS_SIG_STFL_SECRET_KEY *sk); + + /** + * Secret Key Unlocking / Releasing Function + * + * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @return OQS_SUCCESS or OQS_ERROR + */ + OQS_STATUS (*unlock_key)(OQS_SIG_STFL_SECRET_KEY *sk); + + /** + * Secret Key Saving Function + * + * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @return OQS_SUCCESS or OQS_ERROR + */ + OQS_STATUS (*save_secret_key)(const OQS_SIG_STFL_SECRET_KEY *sk); + + /** + * Secret Key free internal variant specific data + * + * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @return none + */ + void (*free_key)(OQS_SIG_STFL_SECRET_KEY *sk); +} OQS_SIG_STFL_SECRET_KEY; + /** * Constructs an OQS_SIG_STFL object for a particular algorithm. * @@ -162,7 +237,7 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name); * Caller is responsible for allocating sufficient memory for `public_key` based * on the `length_*` members in this object or the per-scheme compile-time macros * `OQS_SIG_STFL_*_length_*`. Caller is also responsible for initializing - * `secret_key` using the OQS_SECRET_KEY(*) function + * `secret_key` using the OQS_SIG_STFL_SECRET_KEY(*) function * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. * @param[out] public_key The public key represented as a byte string. @@ -228,6 +303,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, size_t *max, */ OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig); +/** + * Constructs an OQS_SIG_STFL_SECRET_KEY object for a particular algorithm. + * + * Callers should always check whether the return value is `NULL`, which indicates either than an + * invalid algorithm name was provided, or that the requested algorithm was disabled at compile-time. + * + * @param[in] method_name Name of the desired algorithm; one of the names in `OQS_SIG_STFL_algs`. + * @return An OQS_SIG_STFL_SECRET_KEY for the particular algorithm, or `NULL` if the algorithm has been disabled at compile-time. + */ +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_name); + +/** + * Frees an OQS_SIG_STFL_SECRET_KEY object that was constructed by OQS_SECRET_KEY_new. + * + * @param[in] sig The OQS_SIG_STFL_SECRET_KEY object to free. + * @return OQS_SUCCESS if successful, or OQS_ERROR if the object could not be freed. + */ +OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk); + #if defined(__cplusplus) } // extern "C" #endif diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index 1dd0139e5f..e932f3f063 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -6,6 +6,7 @@ #include #define XMSS_OID_LEN 4 +void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 @@ -14,6 +15,7 @@ #define OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk (132 + XMSS_OID_LEN) OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index 8e50828095..cfb6899af6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -41,6 +41,30 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { return sig; } +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { if (public_key == NULL || secret_key == NULL) { @@ -109,4 +133,13 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(size_t *total, co *total = (size_t) total_signatures; return OQS_SUCCESS; -} \ No newline at end of file +} + +void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return; + } + + OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); + sk->secret_key_data = NULL; +} diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index e80aface60..45f700608b 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -159,6 +159,35 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name) { return ret; } +static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { + OQS_STATUS rc = OQS_SUCCESS; + OQS_SIG_STFL_SECRET_KEY *sk = NULL; + + sk = OQS_SIG_STFL_SECRET_KEY_new(method_name); + if (sk == NULL) { + fprintf(stderr, "ERROR: OQS_SECRET_KEY_new failed\n"); + goto err; + } + + printf("================================================================================\n"); + printf("Create for statefull Secret Key %s\n", method_name); + printf("================================================================================\n"); + + if (!sk->secret_key_data) { + fprintf(stderr, "ERROR: OQS_SECRET_KEY_new incomplete.\n"); + goto err; + } + + OQS_SIG_STFL_SECRET_KEY_free(sk); + printf("Secret Key created as expected.\n"); + goto end_it; + +err: + rc = OQS_ERROR; +end_it: + return rc; +} + #ifdef OQS_ENABLE_TEST_CONSTANT_TIME static void TEST_SIG_STFL_randombytes(uint8_t *random_array, size_t bytes_to_read) { // We can't make direct calls to the system randombytes on some platforms, @@ -178,11 +207,13 @@ static void TEST_SIG_STFL_randombytes(uint8_t *random_array, size_t bytes_to_rea struct thread_data { char *alg_name; OQS_STATUS rc; + OQS_STATUS rc1; }; void *test_wrapper(void *arg) { struct thread_data *td = arg; td->rc = sig_stfl_test_correctness(td->alg_name); + td->rc1 = sig_stfl_test_secret_key(td->alg_name); return NULL; } #endif @@ -221,7 +252,7 @@ int main(int argc, char **argv) { OQS_randombytes_switch_algorithm("system"); #endif - OQS_STATUS rc; + OQS_STATUS rc, rc1; #if OQS_USE_PTHREADS_IN_TESTS #define MAX_LEN_SIG_NAME_ 64 pthread_t thread; @@ -235,10 +266,12 @@ int main(int argc, char **argv) { } pthread_join(thread, NULL); rc = td.rc; + rc1 = td.rc1; #else rc = sig_stfl_test_correctness(alg_name); + rc1 = sig_stfl_test_secret_key(alg_name); #endif - if (rc != OQS_SUCCESS) { + if ((rc != OQS_SUCCESS) || (rc1 != OQS_SUCCESS)) { OQS_destroy(); return EXIT_FAILURE; } From e356ebf33167f7514466ce4c44c90a46e6f213bd Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Thu, 13 Jul 2023 14:26:03 -0400 Subject: [PATCH 07/68] Na lms (#1486) * Add base LMS library * ignore use of free() by adding // IGNORE free-check * ignore use of free() by adding // IGNORE free-check --- src/sig_stfl/lms/external/common_defs.h | 178 ++++ src/sig_stfl/lms/external/config.h | 36 + src/sig_stfl/lms/external/endian.c | 23 + src/sig_stfl/lms/external/endian.h | 9 + src/sig_stfl/lms/external/hash.c | 119 +++ src/sig_stfl/lms/external/hash.h | 57 ++ src/sig_stfl/lms/external/hss.c | 169 ++++ src/sig_stfl/lms/external/hss.h | 417 ++++++++ src/sig_stfl/lms/external/hss_alloc.c | 555 +++++++++++ src/sig_stfl/lms/external/hss_aux.c | 355 +++++++ src/sig_stfl/lms/external/hss_aux.h | 59 ++ src/sig_stfl/lms/external/hss_common.c | 48 + src/sig_stfl/lms/external/hss_common.h | 22 + src/sig_stfl/lms/external/hss_compute.c | 174 ++++ src/sig_stfl/lms/external/hss_derive.c | 325 ++++++ src/sig_stfl/lms/external/hss_derive.h | 74 ++ src/sig_stfl/lms/external/hss_generate.c | 932 ++++++++++++++++++ src/sig_stfl/lms/external/hss_internal.h | 243 +++++ src/sig_stfl/lms/external/hss_keygen.c | 368 +++++++ src/sig_stfl/lms/external/hss_param.c | 153 +++ src/sig_stfl/lms/external/hss_reserve.c | 194 ++++ src/sig_stfl/lms/external/hss_reserve.h | 21 + src/sig_stfl/lms/external/hss_sign.c | 736 ++++++++++++++ src/sig_stfl/lms/external/hss_sign_inc.c | 218 ++++ src/sig_stfl/lms/external/hss_sign_inc.h | 81 ++ src/sig_stfl/lms/external/hss_thread.h | 135 +++ .../lms/external/hss_thread_pthread.c | 298 ++++++ src/sig_stfl/lms/external/hss_thread_single.c | 63 ++ src/sig_stfl/lms/external/hss_verify.c | 196 ++++ src/sig_stfl/lms/external/hss_verify.h | 23 + src/sig_stfl/lms/external/hss_verify_inc.c | 203 ++++ src/sig_stfl/lms/external/hss_verify_inc.h | 82 ++ src/sig_stfl/lms/external/hss_zeroize.c | 49 + src/sig_stfl/lms/external/hss_zeroize.h | 10 + src/sig_stfl/lms/external/lm_common.c | 79 ++ src/sig_stfl/lms/external/lm_common.h | 20 + src/sig_stfl/lms/external/lm_ots.h | 64 ++ src/sig_stfl/lms/external/lm_ots_common.c | 99 ++ src/sig_stfl/lms/external/lm_ots_common.h | 16 + src/sig_stfl/lms/external/lm_ots_sign.c | 168 ++++ src/sig_stfl/lms/external/lm_ots_verify.c | 122 +++ src/sig_stfl/lms/external/lm_ots_verify.h | 23 + src/sig_stfl/lms/external/lm_verify.c | 107 ++ src/sig_stfl/lms/external/lm_verify.h | 12 + src/sig_stfl/lms/external/sha256.c | 183 ++++ src/sig_stfl/lms/external/sha256.h | 43 + 46 files changed, 7561 insertions(+) create mode 100644 src/sig_stfl/lms/external/common_defs.h create mode 100644 src/sig_stfl/lms/external/config.h create mode 100644 src/sig_stfl/lms/external/endian.c create mode 100644 src/sig_stfl/lms/external/endian.h create mode 100644 src/sig_stfl/lms/external/hash.c create mode 100644 src/sig_stfl/lms/external/hash.h create mode 100644 src/sig_stfl/lms/external/hss.c create mode 100644 src/sig_stfl/lms/external/hss.h create mode 100644 src/sig_stfl/lms/external/hss_alloc.c create mode 100644 src/sig_stfl/lms/external/hss_aux.c create mode 100644 src/sig_stfl/lms/external/hss_aux.h create mode 100644 src/sig_stfl/lms/external/hss_common.c create mode 100644 src/sig_stfl/lms/external/hss_common.h create mode 100644 src/sig_stfl/lms/external/hss_compute.c create mode 100644 src/sig_stfl/lms/external/hss_derive.c create mode 100644 src/sig_stfl/lms/external/hss_derive.h create mode 100644 src/sig_stfl/lms/external/hss_generate.c create mode 100644 src/sig_stfl/lms/external/hss_internal.h create mode 100644 src/sig_stfl/lms/external/hss_keygen.c create mode 100644 src/sig_stfl/lms/external/hss_param.c create mode 100644 src/sig_stfl/lms/external/hss_reserve.c create mode 100644 src/sig_stfl/lms/external/hss_reserve.h create mode 100644 src/sig_stfl/lms/external/hss_sign.c create mode 100644 src/sig_stfl/lms/external/hss_sign_inc.c create mode 100644 src/sig_stfl/lms/external/hss_sign_inc.h create mode 100644 src/sig_stfl/lms/external/hss_thread.h create mode 100644 src/sig_stfl/lms/external/hss_thread_pthread.c create mode 100644 src/sig_stfl/lms/external/hss_thread_single.c create mode 100644 src/sig_stfl/lms/external/hss_verify.c create mode 100644 src/sig_stfl/lms/external/hss_verify.h create mode 100644 src/sig_stfl/lms/external/hss_verify_inc.c create mode 100644 src/sig_stfl/lms/external/hss_verify_inc.h create mode 100644 src/sig_stfl/lms/external/hss_zeroize.c create mode 100644 src/sig_stfl/lms/external/hss_zeroize.h create mode 100644 src/sig_stfl/lms/external/lm_common.c create mode 100644 src/sig_stfl/lms/external/lm_common.h create mode 100644 src/sig_stfl/lms/external/lm_ots.h create mode 100644 src/sig_stfl/lms/external/lm_ots_common.c create mode 100644 src/sig_stfl/lms/external/lm_ots_common.h create mode 100644 src/sig_stfl/lms/external/lm_ots_sign.c create mode 100644 src/sig_stfl/lms/external/lm_ots_verify.c create mode 100644 src/sig_stfl/lms/external/lm_ots_verify.h create mode 100644 src/sig_stfl/lms/external/lm_verify.c create mode 100644 src/sig_stfl/lms/external/lm_verify.h create mode 100644 src/sig_stfl/lms/external/sha256.c create mode 100644 src/sig_stfl/lms/external/sha256.h diff --git a/src/sig_stfl/lms/external/common_defs.h b/src/sig_stfl/lms/external/common_defs.h new file mode 100644 index 0000000000..83739949ee --- /dev/null +++ b/src/sig_stfl/lms/external/common_defs.h @@ -0,0 +1,178 @@ +#if !defined( COMMON_DEFS_H_ ) +#define COMMON_DEFS_H_ + +/* + * These are defintions for the LMS implementation that are common throughout + * the system (and so are collected in one place) + */ + +#include +#include + +#define MAX_HASH 32 /* Length of the largest hash we support */ + +/* The I (Merkle tree identifier) value is 16 bytes long */ +#define I_LEN 16 + +/* The maximum height of a Merkle tree */ +#define MAX_MERKLE_HEIGHT 25 + +/* The mininum height of a Merkle tree. Some of our update logic assumes */ +/* this isn't too small */ +#define MIN_MERKLE_HEIGHT 5 + +/* The minimum/maximum number of levels of Merkle trees within an HSS trees */ +#define MIN_HSS_LEVELS 1 /* Minumum levels we allow */ +#define MAX_HSS_LEVELS 8 /* Maximum levels we allow */ + +/* This is the length of our internal seed values */ +#define SEED_LEN 32 /* Enough to make Grover's infeasible */ + +/* Here are some internal types used within the code. They are listed more */ +/* for documentation ("this is what this variable is expected to be") rather */ +/* than to let the compiler do any sort of type checking */ + + /* This is an index into a Merkle tree */ + /* Used for both the leaf index (0..N-1) and the node number (1..2*N-1), */ + /* where N is the size 2**h of the tre */ +#if MAX_MERKLE_HEIGHT > 31 + /* We need to express more than 32 bits in this type */ +typedef uint_fast64_t merkle_index_t; +#error We need to extend the id we place within a hash to more than 4 bytes +#else +typedef uint_fast32_t merkle_index_t; +#endif + + /* This is the name of a parameter set */ + /* Used for both an OTS parameter set or an LM parameter set */ + /* Both are 32 bits */ +typedef uint_fast32_t param_set_t; + + /* This is a sequence number over an HSS tree */ + /* This means we can never generate more than 2**64 signatures from a */ + /* private key (even if the parameter set would, in theory, allow us */ + /* to do more) */ +typedef uint_fast64_t sequence_t; + +/* Defined LM parameter sets */ +#define LMS_SHA256_N32_H5 0x00000005 +#define LMS_SHA256_N32_H10 0x00000006 +#define LMS_SHA256_N32_H15 0x00000007 +#define LMS_SHA256_N32_H20 0x00000008 +#define LMS_SHA256_N32_H25 0x00000009 + +/* LM-OTS registry */ +#define LMOTS_SHA256_N32_W1 0x00000001 +#define LMOTS_SHA256_N32_W2 0x00000002 +#define LMOTS_SHA256_N32_W4 0x00000003 +#define LMOTS_SHA256_N32_W8 0x00000004 + +/* + * Internal formats of various hashes + * + * We do a number of different hashes as a part of this package; some + * specified by the draft, some specific to us. + * For each such hash, we list the values being hashed, and the offset + * from the start where they go. We treat them as indicies into unsigned char + * arrays, and not structs, to avoid any potential padding issues with structs + * + * For a hash of type XXXX, XXXX_Z is the offset where component Z goes, + * XXXX_LEN(hash_len) is the length being hashed (assuming that hash length), + * XXXX_MAXLEN is the maximum length it can be (for allocation), and D_XXXX + * is the hash distinguisher (the value that makes it different from any other + * hash) + */ + +/* The initial message hashing */ +#define MESG_I 0 +#define MESG_Q 16 +#define MESG_D 20 /* The fixed D_MESG value */ +#define MESG_C 22 +#define MESG_PREFIX_LEN(n) (MESG_C + (n)) /* Length not counting the actual */ + /* message being signed */ +#define MESG_PREFIX_MAXLEN MESG_PREFIX_LEN(MAX_HASH) +#define D_MESG 0x8181 + +/* The Winternitz iteration hashes */ +#define ITER_I 0 +#define ITER_Q 16 +#define ITER_K 20 /* The RFC uses i here */ +#define ITER_J 22 +#define ITER_PREV 23 /* Hash from previous iteration; RFC uses tmp */ +#define ITER_LEN(hash_len) (ITER_PREV + (hash_len)) +#define ITER_MAX_LEN ITER_LEN(MAX_HASH) + +/* Hashing the OTS public key */ +#define PBLC_I 0 +#define PBLC_Q 16 +#define PBLC_D 20 /* The fixed D_PBLC value */ +#define PBLC_PREFIX_LEN 22 /* Not counting the OTS public keys */ +#define D_PBLC 0x8080 + +/* Hashing Merkle tree leaf nodes */ +#define LEAF_I 0 +#define LEAF_R 16 +#define LEAF_D 20 +#define LEAF_PK 22 +#define LEAF_LEN(root_len) (LEAF_PK + (root_len)) +#define LEAF_MAX_LEN LEAF_LEN(MAX_HASH) +#define D_LEAF 0x8282 + +/* Hashing Merkle tree internal nodes */ +#define INTR_I 0 +#define INTR_R 16 +#define INTR_D 20 +#define INTR_PK 22 +#define INTR_LEN(root_len) (INTR_PK + 2 * (root_len)) +#define INTR_MAX_LEN INTR_LEN(MAX_HASH) +#define D_INTR 0x8383 + +/* The determanistic key generation */ +/* Also used to generate subkeys in the j-tree hierarchy */ +/* As we'll always do either one or the other, we can reuse the structure */ +/* for both purposes */ +#define PRG_I 0 +#define PRG_Q 16 +#define PRG_J 20 +#define PRG_FF 22 /* A fixed 0xff goes here */ +#define PRG_SEED 23 +#define PRG_LEN(seed_len) (23 + (seed_len)) +#define PRG_MAX_LEN PRG_LEN(MAX_HASH) + +/* The below are hash formats that the draft does not list, but we */ +/* implement ourselves (largely because we need to be determanistic */ +/* based on the seed) */ + +/* Hash used to generate subkeys in the q tree hierarchy */ +#define QTREE_I 0 +#define QTREE_Q 16 +#define QTREE_D 20 /* D_QTREE goes here */ +#define QTREE_SEED 22 +#define QTREE_LEN (22 + 32) /* We assume a fixed length seed */ +#define QTREE_MAX_LEN QTREE_LEN +#define D_QTREE 0xffff + +/* Hash used to generate the master seed for the top level Merkle tree */ +#define TOPSEED_I 0 /* 16 0's here (we don't have an I value) */ +#define TOPSEED_Q 16 /* 0's here (as we don't have a Q value) */ +#define TOPSEED_D 20 /* D_TOPSEED */ +#define TOPSEED_WHICH 22 /* 0 -> Gen Master seed (used as seed for */ + /* the next two) */ + /* 1 -> Create top level seed */ + /* 2 -> Create top level I */ +#define TOPSEED_SEED 23 /* 32 bytes long */ +#define TOPSEED_LEN (TOPSEED_SEED + 32) +#define D_TOPSEED 0xfefe + +/* Hash used to generate the key used for the authenticating the aux values */ +#define DAUX_I 0 /* 16 0's here (no I value) */ +#define DAUX_Q 16 /* 4 more 0's here (no Q value) */ +#define DAUX_D 20 /* D_AUX_SEED_DERIVE */ +#define DAUX_PREFIX_LEN 22 /* Not counting the seed value */ +#define D_DAUX 0xfdfd + +/* Macro to set the D_XXXX value to the XXXX_D offset */ +#define SET_D(p, value) (void)(((p)[0] = (value) >> 8), \ + ((p)[1] = (value) & 0xff)) + +#endif /* COMMON_DEFS_H_ */ diff --git a/src/sig_stfl/lms/external/config.h b/src/sig_stfl/lms/external/config.h new file mode 100644 index 0000000000..e23d19fa9a --- /dev/null +++ b/src/sig_stfl/lms/external/config.h @@ -0,0 +1,36 @@ +#if !defined( CONFIG_H_ ) +#define CONFIG_H_ + +#define LMS_UNUSED(x) (void)(x) + +/* + * This file has #define's that specify how this package operates, and + * are designed to be tweaked by the user. + * + * These can be adjusted to be appropriate for what the application and + * the operating environment needs + */ + +/* + * This modifies which seed generation logic we use + * Note that changing these parameters will change the mapping + * between private keys. + * + * 0 -> We generate seeds using the process defined in Appendix A of the draft + * This is slightly faster + * 1 -> We use a side channel resistant process, never using any single secret + * seed in more than a defined number of distinct hashes + * 2 -> We generate seeds and secrets in a way which is compatible with ACVP + */ +#define SECRET_METHOD 2 + +/* + * If we're using the side channel resistant method, this defines the max + * number of times we'll use a single secret. Note that this is the log2 + * of the max number of times, and so 3 means 'no more than 8 times' + * Reducing SECRET_MAX is a bit more costly; however I don't know that if + * it is significant + */ +#define SECRET_MAX 4 /* Never use a seed more than 16 times */ + +#endif /* CONFIG_H_ */ diff --git a/src/sig_stfl/lms/external/endian.c b/src/sig_stfl/lms/external/endian.c new file mode 100644 index 0000000000..709dc7bf98 --- /dev/null +++ b/src/sig_stfl/lms/external/endian.c @@ -0,0 +1,23 @@ +#include "endian.h" + +void put_bigendian( void *target, unsigned long long value, size_t bytes ) { + unsigned char *b = target; + int i; + + for (i = bytes-1; i >= 0; i--) { + b[i] = value & 0xff; + value >>= 8; + } +} + +unsigned long long get_bigendian( const void *target, size_t bytes ) { + const unsigned char *b = target; + unsigned long long result = 0; + size_t i; + + for (i=0; i + +void put_bigendian( void *target, unsigned long long value, size_t bytes ); +unsigned long long get_bigendian( const void *target, size_t bytes ); + +#endif /* ENDIAN_H_ */ diff --git a/src/sig_stfl/lms/external/hash.c b/src/sig_stfl/lms/external/hash.c new file mode 100644 index 0000000000..dffcdaf6a6 --- /dev/null +++ b/src/sig_stfl/lms/external/hash.c @@ -0,0 +1,119 @@ +#include +#include "hash.h" +#include "sha256.h" +#include "hss_zeroize.h" + +#define ALLOW_VERBOSE 0 /* 1 -> we allow the dumping of intermediate */ + /* states. Useful for debugging; horrid */ + /* for security */ + +/* + * This is the file that implements the hashing APIs we use internally. + * At the present, our parameter sets support only one hash function + * (SHA-256, using full 256 bit output), however, that is likely to change + * in the future + */ + +#if ALLOW_VERBOSE +#include +#include +/* + * Debugging flag; if this is set, we chat about what we're hashing, and what + * the result is it's useful when debugging; however we probably don't want to + * do this if we're multithreaded... + */ +bool hss_verbose = false; +#endif + +/* + * This will hash the message, given the hash type. It assumes that the result + * buffer is large enough for the hash + */ +void hss_hash_ctx(void *result, int hash_type, union hash_context *ctx, + const void *message, size_t message_len) { +#if ALLOW_VERBOSE + if (hss_verbose) { + int i; for (i=0; i< message_len; i++) printf( " %02x%s", ((unsigned char*)message)[i], (i%16 == 15) ? "\n" : "" ); + } +#endif + + switch (hash_type) { + case HASH_SHA256: { + SHA256_Init(&ctx->sha256); + SHA256_Update(&ctx->sha256, message, message_len); + SHA256_Final(result, &ctx->sha256); +#if ALLOW_VERBOSE + if (hss_verbose) { + printf( " ->" ); + int i; for (i=0; i<32; i++) printf( " %02x", ((unsigned char *)result)[i] ); printf( "\n" ); + } +#endif + break; + } + } +} + +void hss_hash(void *result, int hash_type, + const void *message, size_t message_len) { + union hash_context ctx; + hss_hash_ctx(result, hash_type, &ctx, message, message_len); + hss_zeroize(&ctx, sizeof ctx); +} + + +/* + * This provides an API to do incremental hashing. We use it when hashing the + * message; since we don't know how long it could be, we don't want to + * allocate a buffer that's long enough for that, plus the decoration we add + */ +void hss_init_hash_context(int h, union hash_context *ctx) { + switch (h) { + case HASH_SHA256: + SHA256_Init( &ctx->sha256 ); + break; + } +} + +void hss_update_hash_context(int h, union hash_context *ctx, + const void *msg, size_t len_msg) { +#if ALLOW_VERBOSE + if (hss_verbose) { + int i; for (i=0; isha256, msg, len_msg); + break; + } +} + +void hss_finalize_hash_context(int h, union hash_context *ctx, void *buffer) { + switch (h) { + case HASH_SHA256: + SHA256_Final(buffer, &ctx->sha256); +#if ALLOW_VERBOSE + if (hss_verbose) { + printf( " -->" ); + int i; for (i=0; i<32; i++) printf( " %02x", ((unsigned char*)buffer)[i] ); + printf( "\n" ); + } +#endif + break; + } +} + + +unsigned hss_hash_length(int hash_type) { + switch (hash_type) { + case HASH_SHA256: return 32; + } + return 0; +} + +unsigned hss_hash_blocksize(int hash_type) { + switch (hash_type) { + case HASH_SHA256: return 64; + } + return 0; +} diff --git a/src/sig_stfl/lms/external/hash.h b/src/sig_stfl/lms/external/hash.h new file mode 100644 index 0000000000..a61f9f5039 --- /dev/null +++ b/src/sig_stfl/lms/external/hash.h @@ -0,0 +1,57 @@ +#if !defined( HASH_H__ ) +#define HASH_H__ +#include "sha256.h" +#include +#include + +/* + * This defines the hash interface used within HSS. + * All globals are prefixed with hss_ to avoid name conflicts + * Gee, C++ namespaces would be nice... + */ + +/* + * Hash types + */ +enum { + HASH_SHA256 = 1, /* SHA256 */ +}; + +union hash_context { + SHA256_CTX sha256; + /* Any other hash contexts would go here */ +}; + +/* Hash the message */ +void hss_hash(void *result, int hash_type, + const void *message, size_t message_len); + +/* Does the same, but with the passed hash context (which isn't zeroized) */ +/* This is here to save time; let the caller use the same ctx for multiple */ +/* hashes, and then finally zeroize it if necessary */ +void hss_hash_ctx(void *result, int hash_type, union hash_context *ctx, + const void *message, size_t message_len); + +/* + * This is a debugging flag; turning this on will cause the system to dump + * the inputs and the outputs of all hash functions. It only works if + * debugging is allowed in hash.c (it's off by default), and it is *real* + * chatty; however sometimes you really need it for debugging + */ +extern bool hss_verbose; + +/* + * This constant has migrated to common_defs.h + */ +/* #define MAX_HASH 32 */ /* Length of the largest hash we support */ + +unsigned hss_hash_length(int hash_type); +unsigned hss_hash_blocksize(int hash_type); + +void hss_init_hash_context( int h, union hash_context *ctx ); +void hss_update_hash_context( int h, union hash_context *ctx, + const void *msg, size_t len_msg ); +void hss_finalize_hash_context( int h, union hash_context *ctx, + void *buffer); + +#endif /* HASH_H__ */ diff --git a/src/sig_stfl/lms/external/hss.c b/src/sig_stfl/lms/external/hss.c new file mode 100644 index 0000000000..c38455daed --- /dev/null +++ b/src/sig_stfl/lms/external/hss.c @@ -0,0 +1,169 @@ +/* + * This is an implementation of the HSS signature scheme from LMS + * This is designed to be full-featured + * + * Currently, this file consists of functions that don't have a better home + */ +#include +#include +#include "common_defs.h" +#include "hss.h" +#include "hash.h" +#include "endian.h" +#include "hss_internal.h" +#include "hss_aux.h" +#include "hss_derive.h" +#include "config.h" +#include "lm_ots_common.h" + +/* + * Allocate and load an ephemeral key + */ +struct hss_working_key *hss_load_private_key( + bool (*read_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + size_t memory_target, + const unsigned char *aux_data, size_t len_aux_data, + struct hss_extra_info *info ) { + + /* Step 1: determine the parameter set */ + unsigned levels; + param_set_t lm[ MAX_HSS_LEVELS ]; + param_set_t ots[ MAX_HSS_LEVELS ]; + if (!hss_get_parameter_set( &levels, lm, ots, read_private_key, context)) { + /* Can't read private key, or private key invalid */ + return 0; + } + + /* Step 2: allocate the ephemeral key */ + struct hss_working_key *w = allocate_working_key(levels, lm, ots, + memory_target, info); + if (!w) { + /* Memory allocation failure, most likely (we've already vetted */ + /* the parameter sets) */ + return 0; + } + + /* Step 3: load the ephemeral key */ + if (! hss_generate_working_key( read_private_key, context, + aux_data, len_aux_data, w, info )) { + /* About the only thing I can see failing here is perhaps */ + /* attempting to reread the private key failed the second time; */ + /* seems unlikely, but not impossible */ + hss_free_working_key( w ); + return 0; + } + + /* Success! */ + return w; +} + +/* + * Internal function to generate the root seed and I value (based on the + * private seed). We do this (rather than select seed, I at random) so that + * we don't need to store it in our private key; we can recompute them + */ +bool hss_generate_root_seed_I_value(unsigned char *seed, unsigned char *I, + const unsigned char *master_seed) { +#if SECRET_METHOD == 2 + /* In ACVP mode, we use the master seed as the source for both the */ + /* root seed, and the root I value */ + memcpy( seed, master_seed, SEED_LEN ); + memcpy( I, master_seed + SEED_LEN, I_LEN ); +#else + /* + * We use a two-level hashing scheme so that we end up using the master + * seed only twice throughout the system (once here, once to generate the + * aux hmac key) + */ + unsigned char hash_preimage[ TOPSEED_LEN ]; + unsigned char hash_postimage[ MAX_HASH ]; + + memset( hash_preimage + TOPSEED_I, 0, I_LEN ); + memset( hash_preimage + TOPSEED_Q, 0, 4 ); + SET_D( hash_preimage + TOPSEED_D, D_TOPSEED ); + hash_preimage[TOPSEED_WHICH] = 0x00; + memcpy( hash_preimage + TOPSEED_SEED, master_seed, SEED_LEN ); + + /* We use a fixed SHA256 hash; we don't care about interoperability */ + /* so we don't need to worry about what parameter set the */ + /* user specified */ +#if I_LEN > 32 || SEED_LEN != 32 +#error This logic needs to be reworked +#endif + union hash_context ctx; + + hss_hash_ctx(hash_postimage, HASH_SHA256, &ctx, hash_preimage, + TOPSEED_LEN ); + memcpy( hash_preimage + TOPSEED_SEED, hash_postimage, SEED_LEN ); + + /* Now compute the top level seed */ + hash_preimage[TOPSEED_WHICH] = 0x01; + hss_hash_ctx(seed, HASH_SHA256, &ctx, hash_preimage, TOPSEED_LEN ); + + /* Now compute the top level I value */ + hash_preimage[TOPSEED_WHICH] = 0x02; + hss_hash_ctx(hash_postimage, HASH_SHA256, &ctx, hash_preimage, + TOPSEED_LEN ); + memcpy( I, hash_postimage, I_LEN ); + + hss_zeroize( hash_preimage, sizeof hash_preimage ); /* There's keying */ + /* data here */ + hss_zeroize( &ctx, sizeof ctx ); +#endif + return true; +} + +/* + * Internal function to generate the child I value (based on the parent's + * I value). While this needs to be determanistic (so that we can create the + * same I values between reboots), there's no requirement for interoperability. + * So we use a fixed SHA256; when we support a hash function other than SHA256, + * we needn't update this. + */ +bool hss_generate_child_seed_I_value( unsigned char *seed, unsigned char *I, + const unsigned char *parent_seed, + const unsigned char *parent_I, + merkle_index_t index, + param_set_t lm, param_set_t ots) { + struct seed_derive derive; + if (!hss_seed_derive_init( &derive, lm, ots, parent_I, parent_seed )) { + return false; + } + + hss_seed_derive_set_q( &derive, index ); + + /* Compute the child seed value */ + hss_seed_derive_set_j( &derive, SEED_CHILD_SEED ); + hss_seed_derive( seed, &derive, true ); + /* True sets the j value to SEED_CHILD_I */ + + /* Compute the child I value; with increment_j set to true in the */ + /* above call, derive has been set to the SEED_CHILD_I position */ + unsigned char postimage[ SEED_LEN ]; + hss_seed_derive( postimage, &derive, false ); + memcpy( I, postimage, I_LEN ); + + hss_seed_derive_done( &derive ); + + return true; +} + +void hss_init_extra_info( struct hss_extra_info *p ) { + if (p) memset( p, 0, sizeof *p ); +} + +void hss_extra_info_set_threads( struct hss_extra_info *p, int num_threads ) { + if (p) p->num_threads = num_threads; +} + +bool hss_extra_info_test_last_signature( struct hss_extra_info *p ) { + if (!p) return false; + return p->last_signature; +} + +enum hss_error_code hss_extra_info_test_error_code( struct hss_extra_info *p ) { + if (!p) return hss_error_got_null; + return p->error_code; +} diff --git a/src/sig_stfl/lms/external/hss.h b/src/sig_stfl/lms/external/hss.h new file mode 100644 index 0000000000..b4e5e1698d --- /dev/null +++ b/src/sig_stfl/lms/external/hss.h @@ -0,0 +1,417 @@ +#if !defined(HSS_H_) +#define HSS_H_ + +#include +#include +#include "common_defs.h" + +/* + * This is intended to be a usable (nontoy) implementation of the LMS + * signature scheme. The public data (public keys, signatures) are + * precisely the same as the standard LMS implmentation; however it + * strives to be more usable, in the following ways: + * + * - During signature generation time, it incrementally computes the next + * trees; that means that it doesn't need to generate the next Merkle tree + * from scratch on the 1025th signature. + * - It doesn't try to hold the entire Merkle tree in memory; hence a level + * 25 Merkle tree doesn't need to save 2**25 internal node values. This + * does increase the time to generate the next siganture (as we will need + * to recompute some internal nodes); however by only a small constant factor + * - It divides the private key into three parts, only one of which needs to + * be kept secret, and updated dynamically; the other parts are a working + * copy (that can be kept in RAM, and can be dynamically regenerated as + * needed), and some optional static (nonprivate) data (which can speed up + * the regeneration process) + * - API to explicitly reserve the next N signatures (so that we don't need + * to update the secure storage copy quite as often) + * + * + * We use a nonflat memory structure for the working_key. Part of the reason + * we use a flat representation elsewhere is so that they can be written (and + * later read) to/from disk as required; we specifically assume that the + * working_key is never written to disk. And, being able to use C structures + * makes this rather nontrivial structure a bit more transparent + * + * Here is the intended order of usage: + * Step 1: generate the private/public keypair: + * The API to do this is hss_generate_private_key; this is done once per + * private key; and you should write the private key to secure storage + * (which the passed update_private_key function could do) + * + * Step 2: (which you can do per restart): + * Load the private keypair into memory: hss_load_private_key + * + * Step 3: generate signatures (which you can do lots of time after you've + * loaded the key into memory): + * The API to do this is hss_generate_signature. Note that this needs + * to update the private key state; the update_private_key function pointer + * can be useful here + * + * Step 4: (when you're done with the loaded private key; optional) + * Free the ephemeral copy (hss_free_working_key). Note that this is not + * required for correctness; this just does a free() + * + * + * One can also verify signatures at any time; all that needs is a public + * key, a signature and a message; it's not a part of the intended order + * of usage + */ + +struct hss_extra_info; + +/* + * This will generate a fresh (unadorned) private key, with the selected + * parameter set, the corresponding public key, and (optionally) the aux_data + * that is associated with the private key. + * + * The generate_random function will be called when this function needs + * random values; it is assumed to generate cryptographically secure ones. + * We ask you to pass a function, rather than an array of random values, + * to emphasize that we really do need fresh random data here; the security + * of this entire system depends on it. + * + * levels, lm_type, lm_ots_type is the parameter set for the new key. + * levels is the number of levels in the HSS hierarchy (1-8), while + * lm_type[], lm_ots_type[] are arrays giving the parameter set of each + * individual level; level i of the hierarchy will have LMS parameter set + * lm_type[i] and OTS parameter set lm_ots_type[i] (where i=0 is the topmost + * Merkle tree. + * + * The update_private_key function will be called when the private key is + * generated; it is expected to write the private key to secure storage (and + * the context pointer is a value that is passed to the update_private_key + * function; it can be used to tell the update_private_key function where + * in the secure storage to place the key). If the passed update_private_key + * function pointer is NULL, the private will will be written to the context + * pointer (which is expected to hold 48 bytes of data) + * + * public_key is where the freshly generated public key will be placed, and + * len_public_key is the size of the array (and this will generate an error + * if the public key is larger than the array). See the hss_get_public_key_len + * function for the expected length of the public key + * + * aux_data is where to place internal nodes of the Merkle tree, and + * len_aux_data is the length of the provided buffer. This aux_data + * is optional (pass in a NULL if it's not being used), but does significantly + * speed the generate_working_key process. It's envisioned use is to write + * this aux_data to disk, and reread it when it's time to regenerate the + * ephemeral key; it need not be kept in secure storage; revealing it doesn't + * help an attacker to generate forgeries, and if an attacker does manage to + * corrupt it, the regeneration process will detect the corruption and ignore + * it. Also, even if writing it to disk is not possible, passing in a + * small array here and passing that to the initial regeneration call will + * speed that up (and later ones can omit it; those will go slow, but at + * least you got the speed up benefit the first time). + * + * One slightly tricky thing about aux data is that the required length of the + * aux data; there are several different possible time/memory trade-offs. + * Depending on the length, we'll automatically pick the fastest option that + * fits. If we have N bytes available total, see hss_get_aux_data_len for + * the amount of data we'll actually use (and so the amount you need to write + * to disk) + */ +bool hss_generate_private_key( + bool (*generate_random)(void *output, size_t length), + unsigned levels, + const param_set_t *lm_type, const param_set_t *lm_ots_type, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + unsigned char *public_key, size_t len_public_key, + unsigned char *aux_data, size_t len_aux_data, + struct hss_extra_info *info); + +/* + * This is the routine to load a private key into memory, and + * initialize the working data structures; these data structures + * allow us to generate signtures quickly + * + * The read_private_key is a function to read the private key from secure + * storage, with context being a value passed to that function. + * If the read_private_key pointer is NULL, we assume that the context + * pointer points to the private key. + * This assumes that the key has already been generated by + * hss_generate_private_key + * + * memory_target is a value which gives a goal for the amount of memory (in + * bytes) that this structure should take up. There are a number of + * time/memory trade-offs possible; the function uses this parameter as a + * guide as to what trade-offs it should take. This structure tries to + * allocate no more than memory_target bytes; however it is considered + * advisatory; this function will never fail beccause memory_target was too + * small (so passing 0 will work, and will minimize the memory used) + * + * aux_data points to a buffer containing the auxiliary data generated + * during the key generation process, with len_aux_data being the length + * of the buffer. Passing it a NULL means that we're not providing that + * data (which is fine; it just means this will take longer) + * + * On success, this malloc's the ephemeral key (struct hss_working_key*) and + * retursn it. Because it mallocs it, it asssumes that the caller will + * eventually free it (via the hss_free_working_key function, don't try + * calling free() yourself) + */ +struct hss_working_key; +struct hss_working_key *hss_load_private_key( + bool (*read_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + size_t memory_target, + const unsigned char *aux_data, size_t len_aux_data, /* Optional */ + struct hss_extra_info *info); + +/* + * Corresponding function to free the working key + */ +void hss_free_working_key( struct hss_working_key * ); + +/* + * This will actually generate a signature + * + * working_key is the key that has been allocated by allocate_working_key and + * initialied by hss_generate_working_key + * + * The update_private_key function will be called when the private key is + * updated; it is expected to write the private key to secure storage (and the + * context pointer is a value that is passed to the update_private_key + * function; it can be used to tell the update_private_key function where + * in the secure storage to place the key). And, if it is NULL, the context + * is expected to point to a copy of the private_key in RAM. + * One distinction is that, on an update, len_private_key will be 8; + * the update_private_key can choose to update only the first 8 bytes + * of the private key (the rest will be unchanged), or write all + * 48 bytes (private_key will point to the full 48 byte value) + * + * message, message_len are the message being signed + * + * signature is where the signature will be written, with signature_len being + * the length of the buffer. See the hss_get_signature_len function for the + * expected signature length for this parameter set; if signature_len is too + * short for the signature to fit, this will fail. + */ +bool hss_generate_signature( + struct hss_working_key *working_key, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + const void *message, size_t message_len, + unsigned char *signature, size_t signature_len, + struct hss_extra_info *info); + +/* + * See hss_verify.h for the signature verfication routine; it's in a + * separate file for those programs that only need to verify a signature + */ +#include "hss_verify.h" + +/* + * Lower level routines to allocate and initialize a working key. + * + * hss_load_working_key will do the work of the below routines; these are + * provided separately in case you need more control (e.g. reuse an already + * allocated working key) + * + * First, the routine to allocate (but not initialize) a working key. + * + * The levels/lm_type/lm_ots_type are the same parameter sets as in the + * generate public/private keypair call; the parameter set must match the + * values for the private key. + * + * memory_target is a value which gives a goal for the amount of memory that + * this structure should take up. There are a number of time/memory trade-offs + * possible; the function uses this parameter as a guide as to what trade-offs + * it should take. This structure tries to allocate no more than memory_target + * bytes; however it is considered advisatory; this function will never fail + * beccause memory_target was too small (so passing 0 will work, and will + * minimize the memory used) + */ +struct hss_working_key *allocate_working_key( + unsigned levels, + const param_set_t *lm_type, const param_set_t *lm_ots_type, + size_t memory_target, + struct hss_extra_info *info); + +/* + * This is called on reload (or initial key generation), it'll take the + * working key that's been allocated by allocate_working_key, and initialize + * it based on the private key; this working key is what we need to actually + * generate signatures. + * + * The read_private_key is a function to read the private key from secure + * storage, with context being a value passed to that function. + * If NULL, we assume that the context pointer points to the private key + * + * aux_data points to a buffer containing the auxiliary data generated + * during the key generation process, with len_aux_data being the length + * of the buffer. Passing it a NULL means that we're not providing that + * data (which is fine; it just means this will take longer) + * + * working_key is a pointer to the allocated working key + */ +bool hss_generate_working_key( + bool (*read_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + const unsigned char *aux_data, size_t len_aux_data, /* Optional */ + struct hss_working_key *working_key, + struct hss_extra_info *info); + +/* + * This will make sure that (at least) N signatures are reserved; that is, we + * won't need to actually call the update function for the next N signatures + * generated + * + * This can be useful if the update_private_key function is expensive. + * + * Note that if, N (or more) signatures are already reserved, this won't do + * anything. + */ +bool hss_reserve_signature( + struct hss_working_key *w, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + unsigned sigs_to_reserve, + struct hss_extra_info *info); + +/* + * This will set the autoreserve, so that when the signing process runs out, + * it will automatically reserve N more signatures (in addition to the one + * that is being used for the current signature) + * + * This can be useful if the update_private_key function is expensive, + * setting sigs_to_autoreserve=99 means will actually update the private + * key once every 100 signatures + */ +bool hss_set_autoreserve( + struct hss_working_key *w, + unsigned sigs_to_autoreserve, + struct hss_extra_info *info); + +/* + * This returns the required lengths for the various objects we export + * + * This is the length of the private key (which is written to secure storage) + */ +size_t hss_get_private_key_len(unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type); +#define HSS_MAX_PRIVATE_KEY_LEN (8 + 8 + SEED_LEN + 16) + +/* + * This include file has the functions that contains the lengths of the other + * public objects + */ +#include "hss_common.h" + +/* + * Get the signature length. We don't put this in hss_common because we + * assume we have a loaded private key + * Returns 0 on error + */ +size_t hss_get_signature_len_from_working_key( + struct hss_working_key *working_key); + +/* + * This returns the amount of aux data we use + * This is slightly different from the above routines; given the bound on the + * amount of data the aux_data is allowed to take (max_length), this returns + * the amount of data we'll actually use + */ +size_t hss_get_aux_data_len(size_t max_length, + unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type); + +/* + * This returns the parameter set for a given private key. + * This is here to solve a chicken-and-egg problem: the hss_working_key + * must be initialized to the same parameter set as the private key, + * but (other than this function, or somehow remembering it) there's + * no way to retreive the parameter set. + * + * read_private_key/context will read the private key (if read_private_key is + * NULL, context is assumed to point to the private key) + * + * On success, *levels will be set to the number of levels, and lm_type[] + * and lm_ots_type[] will be set to the lm/ots parameter sets + * + * On success, this returns true; on failure (can't read the private key, or + * the * private key is invalid), returns false + */ +bool hss_get_parameter_set( unsigned *levels, + param_set_t lm_type[ MAX_HSS_LEVELS ], + param_set_t lm_ots_type[ MAX_HSS_LEVELS ], + bool (*read_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context); + +enum hss_error_code { + hss_error_none = 0, /* I don't know nothing about any error */ + + hss_range_normal_failures, /* There errors happen during normal use */ + /* of the signature scheme */ + hss_error_bad_signature, /* Invalid signature */ + hss_error_private_key_expired, /* This private key has generated all */ + /* the signatures it is allowed */ + hss_error_not_that_many_sigs_left, /* Reservation request failed */ + /* because the key couldn't do that many */ + /* signatures */ + + hss_range_bad_parameters, /* These errors are cause by the */ + /* application passing in a bad parameter */ + hss_error_no_randomness, /* No RNG supplied */ + hss_error_bad_param_set, /* Application asked for an illegal parmaeter */ + /* set */ + hss_error_buffer_overflow, /* Buffer provide not big enough */ + hss_error_got_null, /* Application passed in a NULL pointer */ + hss_error_bad_aux, /* Error with provided aux buffer */ + hss_error_no_private_buffer, /* Application didn't provide a place */ + /* to put the private key */ + hss_error_incompatible_param_set, /* The parameter set of the working */ + /* set didn't agree with the private key */ + hss_error_key_uninitialized, /* The working key used had never been */ + /* initialized with a private key */ + hss_error_key_mismatch, /* The working set and the private key */ + /* do not correspond */ + hss_error_ctx_uninitialized, /* The incremental ctx wasn't initialized */ + /* properly */ + hss_error_ctx_already_used, /* The ctx has already been used */ + hss_error_bad_public_key, /* Somehow, we got an invalid public key */ + + hss_range_processing_error, /* These errors are cause by an */ + /* error while processing */ + hss_error_bad_randomness, /* The RNG claimed failure */ + hss_error_private_key_write_failed, /* The write of the private key */ + /* to NVRAM failed */ + hss_error_private_key_read_failed, /* The read of the private key */ + /* from NVRAM failed */ + hss_error_out_of_memory, /* A malloc failure caused us to fail */ + + hss_range_my_problem, /* These are caused by internal errors */ + /* within the HSS implementation */ + hss_error_internal, /* Some internal assertion failed (should */ + /* never happen) */ +}; + +/* + * This is the structure that allows us to pass noncritical information + * to and from the above routines (without requiring us to add each + * one as an additional parameter + */ +struct hss_extra_info { + int num_threads; /* Number of threads we're allowed to ues */ + bool last_signature; /* Set if we just signed the last signature */ + /* allowed by this private key */ + enum hss_error_code error_code; /* The more recent error detected */ +}; + +/* Accessor APIs in case someone doesn't feel comfortable about reaching */ +/* into the structure */ +void hss_init_extra_info( struct hss_extra_info * ); +void hss_extra_info_set_threads( struct hss_extra_info *, int ); +bool hss_extra_info_test_last_signature( struct hss_extra_info * ); +enum hss_error_code hss_extra_info_test_error_code( struct hss_extra_info * ); + +#endif /* HSS_H_ */ diff --git a/src/sig_stfl/lms/external/hss_alloc.c b/src/sig_stfl/lms/external/hss_alloc.c new file mode 100644 index 0000000000..8f7cf6054b --- /dev/null +++ b/src/sig_stfl/lms/external/hss_alloc.c @@ -0,0 +1,555 @@ +/* + * This is the code which allocates a working key (and initializes the fields + * that are independent of the key) + */ +#include +#include +#include +#include "hss.h" +#include "hss_internal.h" +#include "lm_common.h" + +#define MALLOC_OVERHEAD 8 /* Our simplistic model about the overhead */ + /* that malloc takes up is that it adds 8 */ + /* bytes to any request we make. This isn't */ + /* precise (especially if we consider external */ + /* fragmentation), it's just a guideline */ + +/* + * Function to estimate the amount of memory we'd use at a particular level, + * if we went with a particular subtree size + * - i is which tree in the scheme we're talking about; 0 is the root tree + * We have this because we allocate less for the root tree + * - subtree_size is the size of the subtrees we're considering + * - total_length is the size of the trees + * - size_hash is the length of the hash output (always 32 currently) + * - if psubtree_levels is non-NULL, we'll return the number of subtree levels + * here + * - if pstack_total is non-NULL, we'll return the bytes of stack space needed + * by the subtrees of this level here + * The value returned is the amount of space used by the merkle + * level structures, the subtree structures, plus the additional stack + * space required + */ +static size_t compute_level_memory_usage(int i, unsigned subtree_size, + unsigned total_height, unsigned size_hash, + unsigned *psubtree_levels, + size_t *pstack_total) { + /* Compute the number of subtree levels we'd have */ + unsigned subtree_levels = (total_height + subtree_size - 1) / subtree_size; + unsigned top_subtree_size = total_height - (subtree_levels-1)*subtree_size; + /* The top level tree has no next subtrees */ + int have_next_subtree = (i == 0) ? 0 : 1; + size_t stack_total = 0; + + /* Compute the memory this would use */ + size_t memory_used = sizeof(struct merkle_level) + MALLOC_OVERHEAD; + unsigned j; + for (j=0; j 2 +#error We assume that a subtree of size 2 is allowed +#endif + return 2; +} + +/* + * This allocates a working key for a particular parameter set, and sets up + * the data fields that are key independent; it doesn't set anything that + * does depend on the key. memory_target is used to guide time/memory + * trade-offs; it's the target memory budget that we try to stay below if + * possible + */ +struct hss_working_key *allocate_working_key( + unsigned levels, + const param_set_t *lm_type, const param_set_t *lm_ots_type, + size_t memory_target, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 }; + if (!info) info = &temp_info; + + if (levels < MIN_HSS_LEVELS || levels > MAX_HSS_LEVELS) { + info->error_code = hss_error_bad_param_set; + return 0; + } + + /* Assign the memory target to a *signed* variable; signed so that it */ + /* can take on negative values meaningfully (to account for cases where */ + /* we are "overbudget") */ + unsigned long mem_target; + if (memory_target > LONG_MAX) { + mem_target = LONG_MAX; + } else { + mem_target = memory_target; + } +#if 0 +signed long initial_mem_target = mem_target; /* DEBUG HACK */ +#endif + + struct hss_working_key *w = malloc( sizeof *w ); + if (!w) { + info->error_code = hss_error_out_of_memory; + return NULL; + } + mem_target -= sizeof(*w) + MALLOC_OVERHEAD; + unsigned i; + w->levels = levels; + w->status = hss_error_key_uninitialized; /* Not usable until we see a */ + /* private key */ + w->autoreserve = 0; + + /* Initialize all the allocated data structures to NULL */ + /* We do this up front so that if we hit an error in the middle, we can */ + /* just free everything */ + for (i=0; isigned_pk[i] = NULL; + } + for (i=0; itree[i] = NULL; + } + w->stack = NULL; + + /* Allocate all the memory for the level signatures */ + size_t signature_len = 4; /* At the same time, ocmpute the sig length */ + for (i=0; i < levels; i++) { + w->siglen[i] = lm_get_signature_len( lm_type[i], lm_ots_type[i] ); + signature_len += w->siglen[i]; + /* Size of this level's Merkle public key */ + size_t pklen = lm_get_public_key_len(lm_type[i]); + if (i != 0) signature_len += pklen; + if (w->siglen[i] == 0) { + hss_free_working_key(w); + info->error_code = hss_error_bad_param_set; + return 0; + } + /* We don't need a allocate a signature for the topmost */ + if (i == 0) continue; + + w->signed_pk_len[i] = w->siglen[i-1] + pklen; + + w->signed_pk[i] = malloc( w->signed_pk_len[i] ); + if (!w->signed_pk[i]) { + hss_free_working_key(w); + info->error_code = hss_error_out_of_memory; + return 0; + } + mem_target -= w->signed_pk_len[i] + MALLOC_OVERHEAD; + } + w->signature_len = signature_len; + + /* Also account for the overhead for the stack allocation (the memory */ + /* used by the stack will be accounted as a part of the tree level size */ + mem_target -= MALLOC_OVERHEAD; + + /* + * Plot out how many subtree sizes we have at each level. We start by + * computing how much memory we'd use if we minimize each level + */ + unsigned subtree_size[MAX_HSS_LEVELS]; + unsigned subtree_levels[MAX_HSS_LEVELS]; + unsigned level_hash[MAX_HSS_LEVELS]; + unsigned level_height[MAX_HSS_LEVELS]; + unsigned hash_size[MAX_HSS_LEVELS]; + unsigned total_height = 0; + + /* Parse the parameter sets */ + for (i=0; ierror_code = hss_error_bad_param_set; + return 0; + } + + total_height += level_height[i]; /* Also track the number of */ + /* signatures we can generate with this parm set */ + } + + /* + * Select which subtree sizes that is faster, and fit within the memory + * we've been given. For the nonbottom levels, we always use what's the + * smallest for that particular tree height; there's no point in wasting + * extra memory to make them faster (in that each one can be done during + * the time the bottom level BUILDING subtrees don't need updating). + */ + size_t stack_usage = 0; + for (i=0; i mem_target) { + /* This would use more memory than we'd like; accept it if */ + /* either we have no solution, or it uses less memory than what */ + /* we've seen */ + if (search_status != nothing_yet && mem > best_mem) continue; + + /* This solution is the best so far (however, it doesn't fit) */ + search_status = found_overbudget; + } else { + /* This is within our budget; accept it if we haven't seen a */ + /* previous solution within our budget, or this uses fewer */ + /* levels than the previous solution */ + if (search_status == found_plenty_memory) { + if (sub_levels > best_levels) { + /* We've already seen a faster solution */ + continue; + } + if (sub_levels == best_levels && mem > best_mem) { + /* We've already seen an equally fast solution that */ + /* uses less memory */ + continue; + } + } + + /* This solution is the best so far (and it fits) */ + search_status = found_plenty_memory; + } + /* This is the best option so far; record it */ + best_j = j; + best_mem = mem; + best_levels = sub_levels; + best_stack_used = stack_used; + } + + if (search_status == nothing_yet) { + /* This can't really happen */ + hss_free_working_key(w); + info->error_code = hss_error_internal; + return 0; + } +#if 0 +printf( "Allocation = %ld\n", initial_mem_target - mem_target + best_mem ); /* DEBUG HACK */ +#endif + + subtree_size[i] = best_j; + subtree_levels[i] = (level_height[i] + best_j - 1) / best_j; + stack_usage += best_stack_used; + + unsigned char *stack; + if (stack_usage == 0) { + stack = NULL; /* Hey! No stack required */ + /* Avoid the malloc, as malloc(0) is allowed to fail */ + } else { + stack = malloc(stack_usage); + if (!stack) { + hss_free_working_key(w); + info->error_code = hss_error_out_of_memory; + return 0; + } + } + w->stack = stack; + size_t stack_index = 0; + + /* + * Ok, we've figured out the sizes for everything; now do the actual + * allocations + */ + for (i = 0; ierror_code = hss_error_out_of_memory; + return 0; + } + unsigned h0 = level_height[i]; + tree->level = h0; + tree->h = level_hash[i]; + tree->hash_size = hash_size[i]; + tree->lm_type = lm_type[i]; + tree->lm_ots_type = lm_ots_type[i]; + /* We'll initialize current_index from the private key */ + tree->max_index = (1L << tree->level) - 1; + tree->sublevels = subtree_levels[i]; + tree->subtree_size = subtree_size[i]; + unsigned top_subtree_size = h0 - (subtree_levels[i]-1)*subtree_size[i]; + tree->top_subtree_size = top_subtree_size; + + unsigned k; + for (j=0; jsubtree[j][k] = NULL; + w->tree[i] = tree; + + unsigned subtree_level = 0; + unsigned levels_below = h0; + for (j=0; jerror_code = hss_error_out_of_memory; + return 0; + } + + s->level = subtree_level; + s->levels_below = levels_below; + tree->subtree[j][k] = s; + if (k == ACTIVE_TREE) { + /* Active trees don't need no stack */ + s->stack = NULL; + } else if (levels_below == 0) { + /* Bottom level subtrees don't need no stack */ + s->stack = NULL; + } else { + s->stack = &stack[stack_index]; + stack_index += hash_size[i] * levels_below; + } + } + + subtree_level += height; + } + } + +/* SANITY CHECK */ + if (stack_index != stack_usage) { + hss_free_working_key(w); + info->error_code = hss_error_internal; + return 0; + } +/* SANITY CHECK */ + + /* Compute the max number of signatures we can generate */ + if (total_height > 64) total_height = 64; /* (bounded by 2**64) */ + w->max_count = ((sequence_t)2 << (total_height-1)) - 1; /* height-1 so */ + /* we don't try to shift by 64, and hit undefined behavior */ + + /* We use the count 0xffff..ffff to signify 'we've used up all our */ + /* signatures'. Make sure that is above max_count, even for */ + /* parameter sets that can literally generate 2**64 signatures (by */ + /* letting them generate only 2**64-1) */ + if (total_height == 64) w->max_count--; + + return w; +} + +void hss_free_working_key(struct hss_working_key *w) { + int i; + if (!w) return; + for (i=0; itree[i]; + if (tree) { + unsigned j, k; + for (j=0; jsubtree[j][k]); // IGNORE free-check + hss_zeroize( tree, sizeof *tree ); /* We have seeds here */ + } + free(tree); // IGNORE free-check + } + for (i=0; isigned_pk[i]); // IGNORE free-check + } + free(w->stack); // IGNORE free-check + hss_zeroize( w, sizeof *w ); /* We have secret information here */ + free(w); // IGNORE free-check +} diff --git a/src/sig_stfl/lms/external/hss_aux.c b/src/sig_stfl/lms/external/hss_aux.c new file mode 100644 index 0000000000..5817b76c81 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_aux.c @@ -0,0 +1,355 @@ +/* + * This is the implementation of the aux data within the HSS tree + */ + +#include +#include "hss_aux.h" +#include "hss_internal.h" +#include "common_defs.h" +#include "lm_common.h" +#include "endian.h" +#include "hash.h" +#include "hss_zeroize.h" + +/* + * The structure of aux data + * + * The current format of the file is: + * [4 bytes of marker]: + * - bit 31 is set (to indicate that the aux data is nonempty; a 0 first byte + * indicates that, yes, we have no bananas); because we store the marker + * in bigendian format, this bit 31 is in the first byte. + * - bit i is set if we have the hashes for intermediate level i + * For each set bit i (in ascending sequence): + * - 1<= len_this_level) { + /* This level fits; add it */ + max_length -= len_this_level; + /* We also set the MSBit to signify that we're saving something */ + aux_level |= 0x80000000UL | ((aux_level_t)1<>= 1) { + if (aux_level & 1) { + temp->data[h] = (void *)aux_data; + aux_data += (size_t)size_hash << h; + } else { + temp->data[h] = 0; /* No data at this level */ + } + } + + /* Now, check if the data is valid */ + if (w) { + /* Check to see if the data is valid */ + size_t expected_len = (aux_data - orig_aux_data) + size_hash; + if (expected_len > len_aux_data) { + /* Either the first 4 bytes were messed up, or the file was */ + /* truncated */ + return 0; + } + if (len_aux_data < 4 + size_hash) return 0; + + /* Now, MAC the entire aux file */ + union hash_context ctx; + unsigned char key[ MAX_HASH ]; + compute_seed_derive( key, w->tree[0]->h, w->working_key_seed, &ctx ); + unsigned char expected_mac[ MAX_HASH ]; + compute_hmac( expected_mac, w->tree[0]->h, size_hash, &ctx, key, + orig_aux_data, aux_data - orig_aux_data ); + hss_zeroize( key, size_hash ); + hss_zeroize( &ctx, sizeof ctx ); + if (0 != memcmp_consttime( expected_mac, aux_data, size_hash)) { + /* The MAC did not agree; ignore the aux data */ + return 0; + } + } + return temp; +} + +/* + * This returns the amount of aux data we would use, given the maximum bound + * on how much aux data we are allowed, and the parameter sets + */ +size_t hss_get_aux_data_len(size_t max_length, + unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type) { + size_t len = 0; + LMS_UNUSED(levels); + if (!hss_optimal_aux_level( max_length, lm_type, lm_ots_type, &len )) { + return 1; /* 1 byte marker to say 'we're not using it */ + } + + return len; +} + +/* + * Save the marker within the aux data + */ +void hss_store_aux_marker( unsigned char *aux_data, aux_level_t aux_level ) { + if (aux_level == 0) { + /* Aux data doesn't help; mark it as unused */ + aux_data[AUX_DATA_MARKER] = NO_AUX_DATA; + } else { + put_bigendian( &aux_data[AUX_DATA_MARKER], aux_level, 4 ); + } +} + +/* + * This is called while we are building the initial top level Merkle tree (to + * compute the root). This is called for each internal node, and allows the + * aux data a chance to save the intermediate value + */ +void hss_save_aux_data( struct expanded_aux_data *data, unsigned level, + unsigned size_hash, merkle_index_t q, + const unsigned char *cur_val ) { + if (!data) return; /* We're not recording anything */ + if (!data->data[level]) return; /* We're not recording anything for */ + /* this level */ + + /* We are recording it; save a copy in the aux data */ + memcpy( data->data[level] + size_hash * q, cur_val, size_hash ); +} + +/* + * This generates the derived value that we'll use as a key the authenticate + * the aux data. We pass the ctx (rather than using a local one) so we have + * one less thing to zeroize + * + * We use a derived key (rather than using the seed directly) because the + * outer hash within the HMAC don't use the diversification factors that every + * other hash within this packet does; hence for HMAC, we use a key that + * is independent of every other hash used + */ +static void compute_seed_derive( unsigned char *result, unsigned hash, + const unsigned char *seed, union hash_context *ctx) { + hss_init_hash_context( hash, ctx ); + unsigned char prefix[ DAUX_PREFIX_LEN ]; + memset( prefix, 0, DAUX_D ); + SET_D( prefix + DAUX_D, D_DAUX ); + hss_update_hash_context( hash, ctx, prefix, sizeof prefix ); + hss_update_hash_context( hash, ctx, seed, SEED_LEN ); + hss_finalize_hash_context( hash, ctx, result ); + + hss_zeroize( &ctx, sizeof ctx ); +} + +static void xor_key( unsigned char *key, unsigned xor_val, unsigned len_key) { + unsigned i; + for (i = 0; idata[i]) { + total_length += (size_t)size_hash << i; + if (!aux) { + aux = data->data[i] - 4; + } + } + } + if (aux) { + compute_hmac( aux+total_length, hash, size_hash, &ctx, aux_seed, + aux, total_length ); + } + + hss_zeroize( &ctx, sizeof ctx ); + hss_zeroize( aux_seed, size_hash ); +} + +/* + * This is called when we need to use aux data; it checks to see if we've + * stored the nodes within the aux data; if we have, it extracts them, + * and returns true + */ +bool hss_extract_aux_data(const struct expanded_aux_data *aux, unsigned level, + const struct hss_working_key *w, unsigned char *dest, + merkle_index_t node_offset, /* Offset of node on this level */ + merkle_index_t node_count) { /* # of nodes to restore */ + if (!aux) return false; /* No aux data */ + if (!aux->data[level]) return false; /* We don't have that specific */ + /* level saved */ + unsigned hash_size = w->tree[0]->hash_size; + + /* We do have the data; copy it to the destination */ + memcpy( dest, + aux->data[level] + node_offset*hash_size, + node_count * hash_size ); + + return true; +} diff --git a/src/sig_stfl/lms/external/hss_aux.h b/src/sig_stfl/lms/external/hss_aux.h new file mode 100644 index 0000000000..634df88684 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_aux.h @@ -0,0 +1,59 @@ +#if !defined( HSS_AUX_H_ ) +#define HSS_AUX_H_ + +/* + * This is the internal API to the subsystem that deals with aux data + * This should not be included by files outside this subsystem + */ + +#include "common_defs.h" +#include +#include + +struct hss_working_key; + +/* This is a bitmap that lists which aux levels we have */ +typedef uint_fast32_t aux_level_t; + +/* This is the expanded version of the aux data */ +struct expanded_aux_data { + unsigned char *data[ MAX_MERKLE_HEIGHT+1 ]; +}; + +/* + * These are some internal routines that handle aux data + */ +/* Internal function used to compute the optimal aux level */ +aux_level_t hss_optimal_aux_level( size_t max_length, + const param_set_t *lm_type, + const param_set_t *lm_ots_type, + size_t *actual_len ); + +/* Generate pointers into a saved aux data */ +/* If w is provided, we do sanity checking on the data within aux_data */ +struct expanded_aux_data *hss_expand_aux_data( const unsigned char *aux_data, + size_t len_aux_data, + struct expanded_aux_data *temp, unsigned size_hash, + struct hss_working_key *w ); + +/* + * Save the marker within the aux data + */ +void hss_store_aux_marker( unsigned char *aux_data, aux_level_t aux_level ); + +/* Save an intermediate node */ +void hss_save_aux_data( struct expanded_aux_data *data, unsigned level, + unsigned size_hash, merkle_index_t q, + const unsigned char *cur_val ); + +/* Do the final touches on the aux data */ +void hss_finalize_aux_data(struct expanded_aux_data *data, + unsigned size_hash, unsigned hash, + const unsigned char *seed); + +/* Get a set of intermediate nodes from the aux data */ +bool hss_extract_aux_data(const struct expanded_aux_data *aux, unsigned level, + const struct hss_working_key *w, unsigned char *dest, + merkle_index_t node_offset, merkle_index_t node_count); + +#endif /* HSS_AUX_H_ */ diff --git a/src/sig_stfl/lms/external/hss_common.c b/src/sig_stfl/lms/external/hss_common.c new file mode 100644 index 0000000000..d07261dd26 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_common.c @@ -0,0 +1,48 @@ +/* + * This is the code that is common between an HSS verifier, and a full HSS + * implementation that both signs and verifies + */ +#include +#include "common_defs.h" +#include "hss_common.h" +#include "lm_common.h" +#include "config.h" +/* + * Get the length of the public key, given this particular parameter set + */ +size_t hss_get_public_key_len(unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type) { + LMS_UNUSED(lm_ots_type); + if (levels < MIN_HSS_LEVELS || levels > MAX_HSS_LEVELS) return 0; + + size_t first_pubkey = lm_get_public_key_len(lm_type[0]); + if (first_pubkey == 0) return 0; + + return 4 + first_pubkey; +} + +/* + * Get the length of a signature, given this particular parameter set + */ +size_t hss_get_signature_len(unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type) { + if (levels < MIN_HSS_LEVELS || levels > MAX_HSS_LEVELS) return 0; + + unsigned i; + size_t tot_len = 4; + for (i=0; i 0 */ + if (i > 0) { + size_t next_pub_len = lm_get_public_key_len(lm_type[i]); + if (next_pub_len == 0) return 0; + tot_len += next_pub_len; + } + } + return tot_len; +} diff --git a/src/sig_stfl/lms/external/hss_common.h b/src/sig_stfl/lms/external/hss_common.h new file mode 100644 index 0000000000..c455b9af5e --- /dev/null +++ b/src/sig_stfl/lms/external/hss_common.h @@ -0,0 +1,22 @@ +#if !defined( HSS_COMMON_H_ ) +#define HSS_COMMON_H_ + +#include +#include "common_defs.h" + +/* + * This returns the length of the public key for the given parameter set + */ +size_t hss_get_public_key_len(unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type); +#define HSS_MAX_PUBLIC_KEY_LEN (4 + 8 + ((I_LEN+3) & ~3) + MAX_HASH) + +/* + * This returns the length of the signature for the given parameter set + */ +size_t hss_get_signature_len(unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type); + +#endif /* HSS_COMMON_H_ */ diff --git a/src/sig_stfl/lms/external/hss_compute.c b/src/sig_stfl/lms/external/hss_compute.c new file mode 100644 index 0000000000..353ec939fb --- /dev/null +++ b/src/sig_stfl/lms/external/hss_compute.c @@ -0,0 +1,174 @@ +/* + * This includes some computation methods that are shared between different + * subsystems of the HSS signature package + */ + +#include +#include "hss_internal.h" +#include "hss.h" +#include "hash.h" +#include "hss_thread.h" +#include "lm_ots_common.h" +#include "lm_ots.h" +#include "endian.h" +#include "hss_derive.h" + +/* Count the number of 1 bits at the end (lsbits) of the integer */ +/* Do it in the obvious way; straightline code may be faster (no */ +/* unpredictable jumps, which are costly), but that would be less scrutable */ +/* (and this code is "fast enough") */ +static int trailing_1_bits(merkle_index_t n) { + int i; + for (i=0; n&1; n>>=1, i++) + ; + return i; +} + +/* + * Compute the value of an internal node within a Merkle tree + */ +static enum hss_error_code hss_compute_internal_node( unsigned char *dest, + merkle_index_t node_num, + const unsigned char *seed, + param_set_t lm_type, + param_set_t lm_ots_type, + unsigned h, + unsigned leaf_level, + const unsigned char *I) { + unsigned hash_size = hss_hash_length(h); + + /* We're store intermediate nodes here */ + unsigned char stack[ MAX_HASH * MAX_MERKLE_HEIGHT]; + + merkle_index_t tree_size = (merkle_index_t)1 << leaf_level; + merkle_index_t r = node_num; + int levels_to_bottom = 0; + if (r == 0) return hss_error_internal; /* So no to infinite loops */ + while (r < tree_size) { + r <<= 1; + levels_to_bottom++; + } + merkle_index_t q = r - tree_size; + + merkle_index_t i; + unsigned ots_len = lm_ots_get_public_key_len(lm_ots_type); + unsigned char pub_key[ LEAF_MAX_LEN ]; + memcpy( pub_key + LEAF_I, I, I_LEN ); + SET_D( pub_key + LEAF_D, D_LEAF ); + + struct seed_derive derive; + if (!hss_seed_derive_init( &derive, lm_type, lm_ots_type, + I, seed)) { + return hss_error_bad_param_set; + } + + for (i=0;; i++, r++, q++) { + /* Generate the next OTS public key */ + hss_seed_derive_set_q( &derive, q ); + if (!lm_ots_generate_public_key(lm_ots_type, I, + q, &derive, pub_key + LEAF_PK, ots_len)) { + return hss_error_bad_param_set; /* The only reason the above */ + /* could fail */ + } + + /* + * For the subtree which this leaf node forms the final piece, put the + * destination to where we'll want it, either on the stack, or if this + * is the final piece, to where the caller specified + */ + unsigned char *current_buf; + int stack_offset = trailing_1_bits( i ); + if (stack_offset == levels_to_bottom) { + current_buf = dest; + } else { + current_buf = &stack[stack_offset * hash_size ]; + } + + /* Hash it to form the leaf node */ + put_bigendian( pub_key + LEAF_R, r, 4); + union hash_context ctx; + hss_hash_ctx( current_buf, h, &ctx, pub_key, LEAF_LEN(hash_size) ); + + /* Work up the stack, combining right nodes with the left nodes */ + /* that we've already computed */ + int sp; + for (sp = 1; sp <= stack_offset; sp++) { + hss_combine_internal_nodes( current_buf, + &stack[(sp-1) * hash_size], current_buf, + h, I, hash_size, + r >> sp ); + } + + /* We're not at a left branch, or at the target node */ + + /* Because we've set current_buf to point to where we want to place */ + /* the result of this loop, we don't need to memcpy it */ + + /* Check if this was the last leaf (and so we've just computed the */ + /* target node) */ + if (stack_offset == levels_to_bottom) { + /* We're at the target node; the node we were asked to compute */ + /* We've already placed the value into dest, so we're all done */ + break; + } + } + + hss_seed_derive_done( &derive ); + + return hss_error_none; +} + +/* + * Combine adjacent left and right nodes within the Merkle tree + * together + */ +void hss_combine_internal_nodes( unsigned char *dest, + const unsigned char *left_node, const unsigned char *right_node, + int h, const unsigned char *I, unsigned hash_size, + merkle_index_t node_num) { + unsigned char hash_val[ INTR_MAX_LEN ]; + memcpy( hash_val + INTR_I, I, I_LEN ); + put_bigendian( hash_val + INTR_R, node_num, 4 ); + SET_D( hash_val + INTR_D, D_INTR ); + + memcpy( hash_val + INTR_PK, left_node, hash_size ); + memcpy( hash_val + INTR_PK + hash_size, right_node, hash_size ); + union hash_context ctx; + hss_hash_ctx( dest, h, &ctx, hash_val, INTR_LEN(hash_size) ); +} + +/* + * This computes an array of intermediate Merkle nodes given by data + * This may be run in a worker (non-main) thread + */ +void hss_gen_intermediate_tree(const void *data, + struct thread_collection *col) { + const struct intermed_tree_detail *d = data; + unsigned hash_len = hss_hash_length(d->h); + unsigned i; + + for (i=0; inode_count; i++) { + unsigned char result[ MAX_HASH ]; + enum hss_error_code status = hss_compute_internal_node( result, + d->node_num + i, + d->seed, + d->lm_type, + d->lm_ots_type, + d->h, + d->tree_height, + d->I); + + /* Report the results */ + hss_thread_before_write(col); + if (status == hss_error_none) { + /* Copy out the resulting hash */ + memcpy( d->dest + i*hash_len, result, hash_len ); + } else { + /* Something went wrong; report the bad news */ + *d->got_error = status; + hss_thread_after_write(col); /* No point in working more */ + return; + } + hss_thread_after_write(col); + } +} diff --git a/src/sig_stfl/lms/external/hss_derive.c b/src/sig_stfl/lms/external/hss_derive.c new file mode 100644 index 0000000000..fc8833594a --- /dev/null +++ b/src/sig_stfl/lms/external/hss_derive.c @@ -0,0 +1,325 @@ +/* + * This is the file that contains the routines that generate various 'random' + * values from the master seed. + * + * Values generated by this routine: + * - OTS private keys + * - Message randomizers (the random value we hash with the message when we + * sign it) + * - I values + * - SEED values (which are the secret to derive all the above for a specific + * LMS tree) + * + * We do things determanisticly, rather than picking things from random, so + * that if we reload from scratch, the values we use after the reload are + * consistent with what we used previously + * + * This provides several different possible derivation methods; they can be + * selected by setting SECRET_METHOD in config.h + */ +#include +#include "hss_derive.h" +#include "hss_internal.h" +#include "hash.h" +#include "endian.h" +#include "config.h" + +#if SECRET_METHOD == 2 + /* We use a hash function based on the parameter set */ +#include "lm_common.h" /* To get the prototype for the parameter set -> */ + /* hash function mapping */ +#else +#if SEED_LEN == 32 +#define HASH HASH_SHA256 /* We always use SHA-256 to derive seeds */ +#else +#error We need to define a hash function for this seed length +#endif +#endif + +#if SECRET_METHOD == 0 || SECRET_METHOD == 2 +/* + * This is the method of deriving LM-OTS keys that conforms to the + * Appendix A method + * As you can see, it's fairly simple + */ + +/* This creates a seed derivation object */ +bool hss_seed_derive_init( struct seed_derive *derive, + param_set_t lm, param_set_t ots, + const unsigned char *I, const unsigned char *seed ) { + derive->I = I; + derive->master_seed = seed; + LMS_UNUSED(ots); + /* q, j will be set later */ +#if SECRET_METHOD == 2 + /* Grab the hash function to use */ + if (!lm_look_up_parameter_set(lm, &derive->hash, &derive->m, 0)) { + return false; + } + + /* Note: currently, this assumes that the hash length is always 256 */ + /* bits; error out if that isn't the case */ + if (derive->m != SEED_LEN) { + return false; + } +#endif + + return true; +} + +/* This sets the internal 'q' value for seed derivation object */ +void hss_seed_derive_set_q( struct seed_derive *derive, merkle_index_t q ) { + derive->q = q; +} + +/* This sets the internal 'j' value for seed derivation object */ +void hss_seed_derive_set_j( struct seed_derive *derive, unsigned j ) { + derive->j = j; +} + + +/* This derives the current seed value. If increment_j is set, it'll then */ +/* reset the object to the next j value */ +void hss_seed_derive( unsigned char *seed, struct seed_derive *derive, + bool increment_j ) { + unsigned char buffer[ PRG_MAX_LEN ]; + memcpy( buffer + PRG_I, derive->I, I_LEN ); + put_bigendian( buffer + PRG_Q, derive->q, 4 ); + put_bigendian( buffer + PRG_J, derive->j, 2 ); + buffer[PRG_FF] = 0xff; + memcpy( buffer + PRG_SEED, derive->master_seed, SEED_LEN ); + +#if SECRET_METHOD == 2 + int hash = derive->hash; /* Our the parameter set's hash function */ +#else + int hash = HASH; /* Use our standard one */ +#endif + + hss_hash( seed, hash, buffer, PRG_LEN(SEED_LEN) ); + + hss_zeroize( buffer, PRG_LEN(SEED_LEN) ); + + if (increment_j) derive->j += 1; +} + +/* This is called when we're done with a seed derivation object */ +void hss_seed_derive_done( struct seed_derive *derive ) { + /* No secrets here */ + LMS_UNUSED(derive); +} + +#elif SECRET_METHOD == 1 +/* + * This is a method of deriving LM-OTS keys that tries to be more + * side-channel resistant; in particular, we never include any + * specific secret value in more than 2**SECRET_MAX distinct + * hashes. + * We do this by deriving subseeds using a tree-based structure; + * each node in the tree has up to 2**SECRET_MAX children, and we use any + * seed within the node (including the root) in no other hash. + * We actually have two levels of trees; one based on q (Merkle tree index), + * the other based on j (Winternitz digit); we could design a single level + * tree that could incorporate both, but it'd be more complex + * + * Much of the complexity that does exist is there to avoid recomputation + */ +#include "lm_common.h" +#include "lm_ots_common.h" +static unsigned my_log2(merkle_index_t n); + +/* This creates a seed derivation object */ +bool hss_seed_derive_init( struct seed_derive *derive, + param_set_t lm, param_set_t ots, + const unsigned char *I, const unsigned char *seed ) { + derive->I = I; + derive->master_seed = seed; + + /* These parameter sets will define the size of the trees we'll use */ + unsigned height, p; + if (!lm_look_up_parameter_set(lm, 0, 0, &height) || + !lm_ots_look_up_parameter_set(ots, 0, 0, 0, &p, 0)) { + return false; + } + + p += NUM_ARTIFICIAL_SEEDS; /* We use one artifical value for the */ + /* randomizer and two artificial values to generate seed, I */ + /* for child trees */ + + /* Compute the number of r-levels we have */ + derive->q_levels = (height + SECRET_MAX - 1)/SECRET_MAX; + + /* And which bit to set when converting 'q' to 'r' */ + derive->r_mask = (merkle_index_t)1 << height; + + /* Compute the number of j-levels we have */ + unsigned j_height = my_log2(p); + derive->j_levels = (j_height + SECRET_MAX - 1)/SECRET_MAX; + + /* And which bit to set when writing q values into the hash */ + derive->j_mask = 1 << j_height; + + /* We reset the current 'q' value to am impossible value; we do this so */ + /* that the initial 'q' value given to use by the application will */ + /* rebuild the entire path through the tree */ + derive->q = derive->r_mask; + + return true; +} + +/* This sets the internal 'q' value for seed derivation object */ +/* This also updates our internal q-path (the q_index/q_seed arrays) */ +/* to reflect the new 'q' value, while minimizing the number of hashes */ +/* done (by reusing as much of the previous path as possible) */ +void hss_seed_derive_set_q( struct seed_derive *derive, merkle_index_t q ) { + merkle_index_t change = q ^ derive->q; + derive->q = q; + unsigned bits_change = my_log2(change); + unsigned q_levels = derive->q_levels; + + /* levels_change will be the number of levels of the q-tree we'll */ + /* need to recompute */ + unsigned levels_change = (bits_change + SECRET_MAX - 1) / SECRET_MAX; + if (levels_change > q_levels) levels_change = q_levels; + + int i; + union hash_context ctx; + unsigned char buffer[ QTREE_MAX_LEN ]; + merkle_index_t r = q | derive->r_mask; + + for (i = levels_change; i > 0; i--) { + int j = q_levels - i; + int shift = (i-1) * SECRET_MAX; + + memcpy( buffer + QTREE_I, derive->I, I_LEN ); + put_bigendian( buffer + QTREE_Q, r >> shift, 4 ); + SET_D( buffer + QTREE_D, D_QTREE ); + if (j == 0) { + memcpy( buffer + QTREE_SEED, derive->master_seed, SEED_LEN ); + } else { + memcpy( buffer + QTREE_SEED, derive->q_seed[j-1], SEED_LEN ); + } + + hss_hash_ctx( derive->q_seed[j], HASH, &ctx, buffer, QTREE_LEN ); + } + + hss_zeroize( buffer, PRG_LEN(SEED_LEN) ); + hss_zeroize( &ctx, sizeof ctx ); +} + +/* Helper function to recompute the j_seed[i] value, based on the */ +/* j_value[i] already set */ +/* ctx, buffer are passed are areas this function can use; we reuse those */ +/* areas so we need to zeroize those buffers only once */ +static void set_j_seed( struct seed_derive *derive, int i, + union hash_context *ctx, unsigned char *buffer) { + + memcpy( buffer + PRG_I, derive->I, I_LEN ); + put_bigendian( buffer + PRG_Q, derive->q, 4 ); + put_bigendian( buffer + PRG_J, derive->j_value[i], 2 ); + buffer[PRG_FF] = 0xff; + if (i == 0) { + /* The root of this tree; it gets its seed from the bottom level */ + /* of the q-tree */ + memcpy( buffer + PRG_SEED, derive->q_seed[ derive->q_levels-1], + SEED_LEN ); + } else { + /* Non-root node; it gets its seed from its parent */ + memcpy( buffer + PRG_SEED, derive->j_seed[i-1], SEED_LEN ); + } + + hss_hash_ctx( derive->j_seed[i], HASH, ctx, buffer, PRG_LEN(SEED_LEN) ); +} + +/* This sets the internal 'j' value for seed derivation object */ +/* This computes the entire path to the 'j' value. Because this is used */ +/* immediately after resetting the q value, we don't try to reuse the */ +/* previous hashes (as there won't be anything there we could reuse) */ +/* Note that we don't try to take advantage of any preexisting hashes */ +/* in the j_seed array; we don't bother because this function is typically */ +/* used only immediately after a set_q call, and so there aren't any */ +/* hashes we could take advantage of */ +void hss_seed_derive_set_j( struct seed_derive *derive, unsigned j ) { + int i; + unsigned j_levels = derive->j_levels; + unsigned shift = SECRET_MAX * j_levels; + + unsigned j_mask = derive->j_mask; + j &= j_mask-1; /* Set the high-order bit; clear any bits above that */ + j |= j_mask; /* This ensures that when we do the hashes, that the */ + /* prefix for the hashes at two different levels of the */ + /* tree are distinct */ + + union hash_context ctx; + unsigned char buffer[ PRG_MAX_LEN ]; + + for (i = 0; ij_value[i] = (j >> shift); + set_j_seed( derive, i, &ctx, buffer ); + } + + hss_zeroize( &ctx, sizeof ctx ); + hss_zeroize( buffer, PRG_LEN(SEED_LEN) ); +} + +/* This derives the current seed value (actually, we've already computed */ +/* it); we just need to copy it to the buffer) */ +/* If increment_j is set, it'll then reset the object to the next j value */ +/* (which means incrementally computing that path) */ +void hss_seed_derive( unsigned char *seed, struct seed_derive *derive, + bool increment_j ) { + memcpy( seed, derive->j_seed[ derive->j_levels - 1], SEED_LEN ); + + if (increment_j) { + int i; + + /* Update the j_values, and figure out which hashes we'll need */ + /* to recompute */ + for (i = derive->j_levels-1;; i--) { + unsigned index = derive->j_value[i]; + index += 1; + derive->j_value[i] = index; + if (0 != (index & SECRET_MAX_MASK)) { + /* The increment didn't cause a carry to the next level; */ + /* we can stop propogating the increment here (and we */ + /* also know this is the top level that we need to */ + /* recompute the hashes */ + break; + } + if (i == 0) { + /* This is the top level; stop here */ + break; + } + } + + /* Recompute the hashes that need updating; we need to do it */ + /* top-down, as each hash depends on the previous one */ + union hash_context ctx; + unsigned char buffer[ PRG_MAX_LEN ]; + for (; i < derive->j_levels; i++) { + set_j_seed( derive, i, &ctx, buffer ); + } + hss_zeroize( &ctx, sizeof ctx ); + hss_zeroize( buffer, PRG_LEN(SEED_LEN) ); + } +} + +/* This is called when we're done with a seed derivation object */ +/* This makes sure any secret values are zeroized */ +void hss_seed_derive_done( struct seed_derive *derive ) { + /* These values are secret, and should never be leaked */ + hss_zeroize( derive->q_seed, sizeof derive->q_seed ); + hss_zeroize( derive->j_seed, sizeof derive->j_seed ); +} + +static unsigned my_log2(merkle_index_t n) { + unsigned lg; + for (lg = 0; n > 0; lg++) n >>= 1; + return lg; +} + +#else + +#error Unknown secret method + +#endif diff --git a/src/sig_stfl/lms/external/hss_derive.h b/src/sig_stfl/lms/external/hss_derive.h new file mode 100644 index 0000000000..ee47eb6cfc --- /dev/null +++ b/src/sig_stfl/lms/external/hss_derive.h @@ -0,0 +1,74 @@ +#if !defined( HSS_DERIVE_H_ ) +#define HSS_DERIVE_H_ + +#include "common_defs.h" + +#include "config.h" + +#if SECRET_MAX > 31 +#error The code is not designed for a SECRET_MAX that high +#endif +#define SECRET_MAX_MASK (((merkle_index_t)1 << SECRET_MAX) - 1) + +struct seed_derive { + const unsigned char *I; + const unsigned char *master_seed; + merkle_index_t q; + unsigned j; +#if SECRET_METHOD == 2 + unsigned hash; /* Hash function to use */ + unsigned m; /* Length of hash function */ +#endif + +#if SECRET_METHOD == 1 + unsigned q_levels, j_levels; + merkle_index_t r_mask; + unsigned j_mask; +#define MAX_Q_HEIGHT ((MAX_MERKLE_HEIGHT + SECRET_MAX - 1) / SECRET_MAX) +#define MAX_J_HEIGHT (( 9 + SECRET_MAX - 1) / SECRET_MAX) + /* '9' is the number of bits a maximum 'p' can take up */ + + unsigned j_value[MAX_J_HEIGHT]; /* these are the values we insert */ + /* into the hash. The lower SECRET_MAX bits are which child of */ + /* the parent it is; the higher bits indicate the parents' */ + /* identities */ + + unsigned char q_seed[MAX_Q_HEIGHT][SEED_LEN]; + unsigned char j_seed[MAX_Q_HEIGHT][SEED_LEN]; +#endif +}; + +bool hss_seed_derive_init( struct seed_derive *derive, + param_set_t lm, param_set_t ots, + const unsigned char *I, const unsigned char *seed ); + +/* This sets the internal 'q' value */ +/* If we've already have a 'q' value set, it'll try to minimize the number */ +/* of hashes done */ +/* Once you've done that, you'll need to reset the 'h' */ +void hss_seed_derive_set_q( struct seed_derive *derive, merkle_index_t q ); + +/* This sets the internal 'j' value */ +void hss_seed_derive_set_j( struct seed_derive *derive, unsigned j ); + +#define NUM_ARTIFICIAL_SEEDS 3 /* 3 seeds are listed below */ + /* This is the j value used when we're deriving the seed value */ + /* for child Merkle trees */ +#define SEED_CHILD_SEED (~1) + /* This is the j value used when we're deriving the I value */ + /* used; either in the context of the parent tree, or of this tree */ +#define SEED_CHILD_I (SEED_CHILD_SEED + 1) + /* This is the j value used when we're asking for the randomizer C */ + /* for signing a message */ +#define SEED_RANDOMIZER_INDEX (~2) + +/* This generates the current seed. If increment_j is set, this will set */ +/* up for the next j value */ +void hss_seed_derive( unsigned char *seed, struct seed_derive *derive, + bool increment_j ); + +/* This needs to be called when we done with a seed_derive */ +/* That structure contains keying data, this makes sure those are cleaned */ +void hss_seed_derive_done( struct seed_derive *derive ); + +#endif /* HSS_DERIVE_H_ */ diff --git a/src/sig_stfl/lms/external/hss_generate.c b/src/sig_stfl/lms/external/hss_generate.c new file mode 100644 index 0000000000..b604ab3593 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_generate.c @@ -0,0 +1,932 @@ +/* + * This is the routine that generates the ephemeral ("working") key from the + * short private value. It builds all the various current, building and + * next subtrees for the various levels (to at least the extent required + * for the current count within the key). + * + * The code is made considerably more complex because we try to take + * advantage of parallelism. To do this, we explicitly list the parts + * of the subtrees we need to build (which is most of the computation), and + * have different worker threads build the various parts, + * + * However, it turns out that this is sometimes insufficient; sometimes, + * the work consists of one or two expensive nodes (perhaps the top level + * subtree), and a lot of comparatively cheap ones; in this case, we'd have + * most of our threads go through the cheap ones quickly, and have one or + * two threads working on the expensive one, and everyone will end up waiting + * for that. To mitigate that, we attempt to subdivide the most expensive + * requests; instead of having a single thread computing the expensive node, + * we may issue four or eight threads to compute the nodes two or three + * levels below (and have the main thread do the final computation when + * all the threads are completed). + * + * This works out pretty good; however man does add complexity :-( + */ +#include +#include +#include "hss.h" +#include "hss_internal.h" +#include "hss_aux.h" +#include "hash.h" +#include "hss_thread.h" +#include "hss_reserve.h" +#include "lm_ots_common.h" +#include "endian.h" + +#define DO_FLOATING_POINT 1 /* If clear, we avoid floating point operations */ + /* You can turn this off for two reasons: */ + /* - Your platform doesn't implement floating point */ + /* - Your platform is single threaded (we use floating point to figure */ + /* out how to split up tasks between threads; if the same thread */ + /* will do all the work, dividing it cleverly doesn't buy anything */ + /* (and that's a quite a bit of code that gets eliminated) */ + /* On the other hand, if you are threaded, you'd really want this if */ + /* at all possible; without this, one thread ends up doing the bulk of */ + /* the work, and so we end up going not that much faster than single */ + /* threaded mode */ + +/* + * This routine assumes that we have filled in the bottom node_count nodes of + * the subtree; it tries to compute as many internal nodes as possible + */ +static void fill_subtree(const struct merkle_level *tree, + struct subtree *subtree, + merkle_index_t node_count, + const unsigned char *I) { + if (node_count <= 1) return; /* If we can't compute any more nodes, */ + /* don't bother trying */ + unsigned h_subtree = (subtree->level == 0) ? tree->top_subtree_size : + tree->subtree_size; + + /* Index into the node array where we're starting */ + merkle_index_t lower_index = ((merkle_index_t)1 << h_subtree) - 1; + + unsigned hash_size = tree->hash_size; + + /* The node identier (initially of the bottom left node of the */ + /* subtree */ + merkle_index_t node_id = (((merkle_index_t)1 << tree->level) + + subtree->left_leaf) + >> subtree->levels_below; + + /* Fill in as many levels of internal nodes as possible */ + int sublevel; + for (sublevel = h_subtree-1; sublevel >= 0; sublevel--) { + node_count >>= 1; + if (node_count == 0) break; /* Can't do any more */ + merkle_index_t prev_lower_index = lower_index; + lower_index >>= 1; + node_id >>= 1; + + merkle_index_t i; + for (i=0; inodes[ hash_size *(lower_index + i)], + &subtree->nodes[ hash_size *(prev_lower_index + 2*i)], + &subtree->nodes[ hash_size *(prev_lower_index + 2*i+1)], + tree->h, I, hash_size, + node_id + i); + } + } +} + +/* + * This routine takes the 2**num_level hashes, and computes up num_level's, + * returning the value of the top node. This is sort of like fill_tree, + * except that it returns only the top node, not the intermediate ones + * One warning: this does modify the passed value of hashes; our current + * caller doesn't care about that. + */ +static void hash_subtree( unsigned char *dest, + unsigned char *hashes, + unsigned num_level, merkle_index_t node_index, + unsigned hash_size, + int h, const unsigned char *I) { + + /* Combine the nodes to form the tree, until we get to the two top nodes */ + /* This will overwrite the hashes array; that's OK, because we don't */ + /* need those anymore */ + for (; num_level > 1; num_level--) { + unsigned i; + merkle_index_t this_level_node_index = node_index << (num_level-1); + for (i = 0; i < ((unsigned)1<<(num_level-1)); i++) { + hss_combine_internal_nodes( + &hashes[ hash_size * i ], + &hashes[ hash_size * (2*i) ], + &hashes[ hash_size * (2*i + 1) ], + h, I, hash_size, + this_level_node_index + i); + } + } + + /* Combine the top two nodes to form our actual target */ + hss_combine_internal_nodes( + dest, + &hashes[ 0 ], + &hashes[ hash_size ], + h, I, hash_size, + node_index); +} + +#if DO_FLOATING_POINT +/* + * This structure is a note reminding us that we've decided to split this + * init_order into several requests, which can be run on independent threads + */ +struct sub_order { + unsigned num_hashes; /* The number of hashes this suborder is */ + /* split up into */ + unsigned level; /* Levels deep into the tree we go */ + merkle_index_t node_num_first_target; /* The node number of the left */ + /* most hash that we're standing in for */ + unsigned char h[1]; /* The hashes go here; we'll malloc */ + /* enough space to let them fit */ +}; +#endif + +/* + * This is an internal request to compute the bottom N nodes (starting from the + * left) of a subtree (and to contruct the internal nodes that based solely on + * those N leaf nodes) + */ +struct init_order { + const struct merkle_level *tree; + struct subtree *subtree; + merkle_index_t count_nodes; /* # of bottom level nodes we need to */ + /* generate */ + const unsigned char *prev_node; /* For nonbottom subtrees, sometimes one */ + /* of the nodes is the root of the */ + /* next level subtree that we compute in */ + /* its entirety. If so, this is a pointer */ + /* to where we will find the precomputed */ + /* value. This allows us to avoid */ + /* computing that specific node */ + merkle_index_t prev_index; /* This is the index of the */ + /* precomputed node, where 0 is the */ + /* leftmost bottom node of this subtree */ + char next_tree; /* If clear, we do this on the current */ + /* tree level (seed, I values); if set, */ + /* we do this on the next */ + char already_computed_lower; /* If set, we've already computed the */ + /* lower nodes (and all we need to do is */ + /* fill the upper); no need to ask the */ + /* threads do do anything */ + /* We may still need to build the */ + /* interiors of the subtrees, of course */ +#if DO_FLOATING_POINT + float cost; /* Approximate number of hash compression */ + /* operations per node */ + struct sub_order *sub; /* If non-NULL, this gives details on how */ + /* we want to subdivide the order between */ + /* different threads */ +#endif +}; + +#if DO_FLOATING_POINT + /* This comparison function sorts the most expensive orders first */ +static int compare_order_by_cost(const void *a, const void *b) { + const struct init_order *p = a; + const struct init_order *q = b; + + if (p->cost > q->cost) return -1; + if (p->cost < q->cost) return 1; + + return 0; +} +#else + /* This comparison function sorts the higher level subtrees first */ +static int compare_order_by_subtree_level(const void *a, const void *b) { + const struct init_order *p = a; + unsigned p_subtree = p->subtree->level; + const struct init_order *q = b; + unsigned q_subtree = q->subtree->level; + + if (p_subtree < q_subtree) return -1; + if (p_subtree > q_subtree) return 1; + + return 0; +} +#endif + +#if DO_FLOATING_POINT +static float estimate_total_cost(struct init_order *order, + unsigned count_order); + +/* + * This is a simple minded log function, returning an int. Yes, using the + * built-in log() function would be easier, however I don't want to pull in + * the -lm library just for this + */ +static unsigned my_log2(float f) { +#define MAX_LOG 10 + unsigned n; + for (n=1; f > 2 && n < MAX_LOG; n++) + f /= 2; + return n; +} +#endif + +/* + * This is the point of this entire file. + * + * It fills in an already allocated working key, based on the private key + */ +bool hss_generate_working_key( + bool (*read_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + const unsigned char *aux_data, size_t len_aux_data, /* Optional */ + struct hss_working_key *w, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 }; + if (!info) info = &temp_info; + + if (!w) { + info->error_code = hss_error_got_null; + return false; + } + w->status = hss_error_key_uninitialized; /* In case we detect an */ + /* error midway */ + + if (!read_private_key && !context) { + info->error_code = hss_error_no_private_buffer; + return false; + } + + /* Read the private key */ + unsigned char private_key[ PRIVATE_KEY_LEN ]; + if (read_private_key) { + if (!read_private_key( private_key, PRIVATE_KEY_LEN, context)) { + info->error_code = hss_error_private_key_read_failed; + goto failed; + } + } else { + memcpy( private_key, context, PRIVATE_KEY_LEN ); + } + + /* + * Make sure that the private key and the allocated working key are + * compatible; that the working_key was initialized with the same + * parameter set + */ + { + if (w->levels > MAX_HSS_LEVELS) { + info->error_code = hss_error_internal; + goto failed; + } + unsigned char compressed[PRIVATE_KEY_PARAM_SET_LEN]; + param_set_t lm_type[MAX_HSS_LEVELS], lm_ots_type[MAX_HSS_LEVELS]; + unsigned i; + for (i=0; ilevels; i++) { + lm_type[i] = w->tree[i]->lm_type; + lm_ots_type[i] = w->tree[i]->lm_ots_type; + } + + if (!hss_compress_param_set( compressed, w->levels, + lm_type, lm_ots_type, + sizeof compressed )) { + /* We're passed an unsupported param set */ + info->error_code = hss_error_internal; + goto failed; + } + if (0 != memcmp( private_key + PRIVATE_KEY_PARAM_SET, compressed, + PRIVATE_KEY_PARAM_SET_LEN )) { + /* The working set was initiallized with a different parmset */ + info->error_code = hss_error_incompatible_param_set; + goto failed; + } + } + + sequence_t current_count = get_bigendian( + private_key + PRIVATE_KEY_INDEX, PRIVATE_KEY_INDEX_LEN ); + if (current_count > w->max_count) { + info->error_code = hss_error_private_key_expired; /* Hey! We */ + goto failed; /* can't generate any more signatures */ + } + hss_set_reserve_count(w, current_count); + + memcpy( w->private_key, private_key, PRIVATE_KEY_LEN ); + + /* Initialize all the levels of the tree */ + + /* Initialize the current count for each level (from the bottom-up) */ + sequence_t i; + sequence_t count = current_count; + for (i = w->levels; i >= 1 ; i--) { + struct merkle_level *tree = w->tree[i-1]; + unsigned index = count & tree->max_index; + count >>= tree->level; + tree->current_index = index; + } + + /* Initialize the I values */ + for (i = 0; i < w->levels; i++) { + struct merkle_level *tree = w->tree[i]; + + /* Initialize the I, I_next elements */ + if (i == 0) { + /* The root seed, I value is derived from the secret key */ + hss_generate_root_seed_I_value( tree->seed, tree->I, + private_key+PRIVATE_KEY_SEED ); + /* We don't use the I_next value */ + } else { + /* The seed, I is derived from the parent's values */ + + /* Where we are in the Merkle tree */ + struct merkle_level *parent = w->tree[i-1]; + merkle_index_t index = parent->current_index; + + hss_generate_child_seed_I_value( tree->seed, tree->I, + parent->seed, parent->I, + index, parent->lm_type, + parent->lm_ots_type ); + /* The next seed, I is derived from either the parent's I */ + /* or the parent's next value */ + if (index == tree->max_index) { + hss_generate_child_seed_I_value( tree->seed_next, tree->I_next, + parent->seed_next, parent->I_next, + 0, parent->lm_type, + parent->lm_ots_type); + } else { + hss_generate_child_seed_I_value( tree->seed_next, tree->I_next, + parent->seed, parent->I, + index+1, parent->lm_type, + parent->lm_ots_type); + } + } + } + + /* Generate the expanded aux data structure (or NULL if we don't have a */ + /* viable aux structure */ + struct expanded_aux_data *expanded_aux, temp_aux; + expanded_aux = hss_expand_aux_data( aux_data, len_aux_data, &temp_aux, + w->tree[0]->hash_size, w ); + + /* + * Now, build all the subtrees within the tree + * + * We initialize the various data structures, and create a list of + * the nodes on the bottom levels of the subtrees that need to be + * initialized + */ + /* There are enough structures in this array to handle the maximum */ + /* number of orders we'll ever see */ + struct init_order order[MAX_HSS_LEVELS * MAX_SUBLEVELS * NUM_SUBTREE]; + struct init_order *p_order = order; + int count_order = 0; + + /* Step through the levels, and for each Merkle tree, compile a list of */ + /* the orders to initialize the bottoms of the subtrees that we'll need */ + for (i = w->levels; i >= 1 ; i--) { + struct merkle_level *tree = w->tree[i-1]; + unsigned hash_size = tree->hash_size; + /* The current count within this tree */ + merkle_index_t tree_count = tree->current_index; + /* The index of the leaf we're on */ + merkle_index_t leaf_index = tree_count; + + /* Generate the active subtrees */ + int j; + /*int bot_level_subtree = (int)tree->level;*/ /* The level of the bottom of */ + /* the subtree */ + unsigned char *active_prev_node = 0; + unsigned char *next_prev_node = 0; + for (j=tree->sublevels-1; j>=0; j--) { + /* The height of this subtree */ + int h_subtree = (j == 0) ? tree->top_subtree_size : + tree->subtree_size; + + /* Initialize the active tree */ + struct subtree *active = tree->subtree[j][ACTIVE_TREE]; + + /* Total number of leaf nodes below this subtree */ + merkle_index_t size_subtree = (merkle_index_t)1 << + (h_subtree + active->levels_below); + /* Fill in the leaf index that's on the left side of this subtree */ + /* This is the index of the leaf that we did when we first */ + /* entered the active subtree */ + merkle_index_t left_leaf = leaf_index & ~(size_subtree - 1); + /* This is the number of leaves we've done in this subtree */ + merkle_index_t subtree_count = leaf_index - left_leaf; + /* If we're not in the bottom tree, it's possible that the */ + /* update process will miss the very first update before we */ + /* need to sign. To account for that, generate one more */ + /* node than what our current count would suggest */ + if (i != w->levels - 1) { + subtree_count++; + } + active->current_index = 0; + active->left_leaf = left_leaf; + merkle_index_t num_bottom_nodes = (merkle_index_t)1 << h_subtree; + + /* Check if we have aux data at this level */ + int already_computed_lower = 0; + if (i == 0) { + merkle_index_t lower_index = num_bottom_nodes-1; + merkle_index_t node_offset = active->left_leaf>>active->levels_below; + if (hss_extract_aux_data(expanded_aux, active->level+h_subtree, + w, &active->nodes[ hash_size * lower_index ], + node_offset, num_bottom_nodes)) { + /* We do have it precomputed in our aux data */ + already_computed_lower = 1; + } + } + /* No aux data at this level; schedule the bottom row to be computed */ + /* Schedule the creation of the entire active tree */ + p_order->tree = tree; + p_order->subtree = active; + p_order->count_nodes = (merkle_index_t)1 << h_subtree; /* All */ + /* the nodes in this subtree */ + p_order->next_tree = 0; + /* Mark the root we inherented from the subtree just below us */ + p_order->prev_node = already_computed_lower ? NULL : active_prev_node; + p_order->prev_index = (tree->current_index >> active->levels_below) & (num_bottom_nodes-1); + + p_order->already_computed_lower = already_computed_lower; + p_order++; count_order++; + + /* For the next subtree, here's where our root will be */ + active_prev_node = &active->nodes[0]; + + /* And initialize the building tree, assuming there is one, and */ + /* assuming that the active subtree isn't at the right edge of */ + /* the Merkle tree */ + if (j > 0 && (leaf_index + size_subtree <= tree->max_index )) { + struct subtree *building = tree->subtree[j][BUILDING_TREE]; + + /* The number of leaves that make up one bottom node */ + /* of this subtree */ + merkle_index_t size_below_tree = (merkle_index_t)1 << building->levels_below; + /* We need to initialize the building tree current index */ + /* to a value at least as large as subtree_count */ + /* We'd prefer not to have to specificallly initialize */ + /* the stack, and so we round up to the next place the */ + /* stack is empty */ + merkle_index_t building_count = + (subtree_count + size_below_tree - 1) & + ~(size_below_tree - 1); + /* # of bottom level nodes we've building right now */ + merkle_index_t num_nodes = building_count >> building->levels_below; + building->left_leaf = left_leaf + size_subtree; + building->current_index = building_count; + + /* Check if this is already in the aux data */ + already_computed_lower = 0; + if (i == 0) { + merkle_index_t lower_index = num_bottom_nodes-1; + merkle_index_t node_offset = building->left_leaf>>building->levels_below; + if (hss_extract_aux_data(expanded_aux, building->level+h_subtree, + w, &building->nodes[ hash_size * lower_index ], + node_offset, num_nodes)) { + /* We do have it precomputed in our aux data */ + already_computed_lower = 1; + } + } + + /* Schedule the creation of the subset of the building tree */ + p_order->tree = tree; + p_order->subtree = building; + /* # of nodes to construct */ + p_order->count_nodes = num_nodes; + p_order->next_tree = 0; + /* We generally can't use the prev_node optimization */ + p_order->prev_node = NULL; + p_order->prev_index = 0; + + p_order->already_computed_lower = already_computed_lower; + p_order++; count_order++; + } else if (j > 0) { + tree->subtree[j][BUILDING_TREE]->current_index = 0; + } + + /* And the NEXT_TREE (which is always left-aligned) */ + if ((i-1) > 0) { + struct subtree *next = tree->subtree[j][NEXT_TREE]; + next->left_leaf = 0; + merkle_index_t leaf_size = + (merkle_index_t)1 << next->levels_below; + + merkle_index_t next_index = tree_count; + /* If we're not in the bottom tree, it's possible that the */ + /* update process will miss the very first update before we */ + /* need to sign. To account for that, potetially generate */ + /* one more node than what our current count would suggest */ + if ((i-1) != w->levels - 1) { + next_index++; + } + + /* Make next_index the # of leaves we'll need to process to */ + /* forward this NEXT subtree to this state */ + next_index = (next_index + leaf_size - 1)/leaf_size; + + /* This is set if we have a previous subtree */ + merkle_index_t prev_subtree = (next->levels_below ? 1 : 0); + merkle_index_t num_nodes; + unsigned char *next_next_node = 0; + + /* If next_index == 1, then if we're on a nonbottom subtree */ + /* the previous subtree is still building (and so we */ + /* needn't do anything). The exception is if we're on the */ + /* bottom level, then there is no subtree, and so we still */ + /* need to build the initial left leaf */ + if (next_index <= prev_subtree) { + /* We're not started on this subtree yet */ + next->current_index = 0; + num_nodes = 0; + } else if (next_index < num_bottom_nodes) { + /* We're in the middle of building this tree */ + next->current_index = next_index << next->levels_below; + num_nodes = next_index; + } else { + /* We've completed building this tree */ + /* How we note "we've generated this entire subtree" */ + next->current_index = MAX_SUBINDEX; + num_nodes = num_bottom_nodes; + /* We've generated this entire tree; allow it to */ + /* be inhereited for the next one */ + next_next_node = &next->nodes[0]; + } + if (num_nodes > 0) { + /* Schedule the creation of these nodes */ + p_order->tree = tree; + p_order->subtree = next; + /* # of nodes to construct */ + p_order->count_nodes = num_nodes; + p_order->next_tree = 1; + p_order->prev_node = next_prev_node; + p_order->prev_index = 0; + + p_order->already_computed_lower = 0; + p_order++; count_order++; + } + next_prev_node = next_next_node; + } + +// bot_level_subtree -= h_subtree; + if (j == 0) break; //This is a single level tree + } + if (i == 0) break; //This is a single level tree + } + +#if DO_FLOATING_POINT + /* Fill in the cost estimates */ + for (i=0; i<(sequence_t)count_order; i++) { + p_order = &order[i]; + + /* + * While we're here, NULL out all the suborders; we'll fill them in + * later if necessary + */ + p_order->sub = 0; + if (p_order->already_computed_lower) { + /* If we pulled the data from the aux, no work required */ + p_order->cost = 0; + continue; + } + unsigned winternitz = 8; + unsigned p = 128; + (void)lm_ots_look_up_parameter_set(p_order->tree->lm_ots_type, 0, 0, + &winternitz, &p, 0); + + struct subtree *subtree = p_order->subtree; + unsigned levels_below = subtree->levels_below; + + /* + * Estimate the number of hashes that we'll need to compute to compute + * one node; this is the number of leaf nodes times the number of + * hashes used during a winternitz computation. This ignores a few + * other hashes, but gets the vast bulk of them + */ + p_order->cost = (float)((merkle_index_t)1<num_threads); + if (num_tracks == 0) num_tracks = 4; /* Divide by 0; just say no */ + float est_max_per_work_item = est_total / num_tracks; + + /* Scan through the items, and see which ones should be subdivided */ + for (i=0; i<(sequence_t)count_order; i++) { + p_order = &order[i]; + if (p_order->cost <= est_max_per_work_item) { + break; /* Break because once we hit this point, the rest of the */ + /* items will be cheaper */ + } + + /* Try to subdivide each item into subdiv pieces */ + unsigned subdiv = my_log2(p_order->cost / est_max_per_work_item); + struct subtree *subtree = p_order->subtree; + /* Make sure we don't try to subdivide lower than what the */ + /* Merkle tree structure allows */ + if (subdiv > subtree->levels_below) subdiv = subtree->levels_below; + if (subdiv == 0) continue; + merkle_index_t max_subdiv = (merkle_index_t)1 << subtree->levels_below; + if (subdiv > max_subdiv) subdiv = max_subdiv; + if (subdiv <= 1) continue; + + const struct merkle_level *tree = p_order->tree; + size_t hash_len = tree->hash_size; + merkle_index_t count_nodes = p_order->count_nodes; + size_t total_hash = (hash_len * count_nodes) << subdiv; + unsigned h_subtree = (subtree->level == 0) ? tree->top_subtree_size : + tree->subtree_size; + struct sub_order *sub = malloc( sizeof *sub + total_hash ); + if (!sub) continue; /* On malloc failure, don't bother trying */ + /* to subdivide */ + + /* Fill in the details of this suborder */ + sub->level = subdiv; + sub->num_hashes = 1 << subdiv; + sub->node_num_first_target = + (subtree->left_leaf >> subtree->levels_below) + + ((merkle_index_t)1 << (h_subtree + subtree->level)); + p_order->sub = sub; + } +#endif + + /* Now, generate all the nodes we've listed in parallel */ + struct thread_collection *col = hss_thread_init(info->num_threads); + enum hss_error_code got_error = hss_error_none; + + /* We use this to decide the granularity of the requests we make */ +#if DO_FLOATING_POINT + unsigned core_target = 5 * hss_thread_num_tracks(info->num_threads); + float prev_cost = 0; +#endif + + for (i=0; i<(sequence_t)count_order; i++) { + p_order = &order[i]; + if (p_order->already_computed_lower) continue; /* If it's already */ + /* done, we needn't bother */ + /* If this work order is cheaper than what we've issued, allow */ + /* for a greater amount of consolidation */ +#if DO_FLOATING_POINT + if (prev_cost > 0) { + if (p_order->cost <= 2 * prev_cost) { + /* The cost per node has decreased by a factor of 2 (at */ + /* least); allow a single core to do more of the work */ + float ratio = prev_cost / p_order->cost; + if (ratio > 1000) { + core_target = 1; + } else { + core_target = core_target / ratio; + if (core_target == 0) core_target = 1; + } + prev_cost = p_order->cost; + } + } else { + prev_cost = p_order->cost; + } +#endif + + const struct merkle_level *tree = p_order->tree; + struct subtree *subtree = p_order->subtree; + unsigned h_subtree = (subtree->level == 0) ? tree->top_subtree_size : + tree->subtree_size; + merkle_index_t lower_index = ((merkle_index_t)1 << h_subtree) - 1; + unsigned hash_size = tree->hash_size; +#if DO_FLOATING_POINT + unsigned max_per_request = p_order->count_nodes / core_target; + if (max_per_request == 0) max_per_request = 1; +#else + unsigned max_per_request = UINT_MAX; +#endif + + /* If we're skipping a value, make sure we compute up to there */ + merkle_index_t right_side = p_order->count_nodes; + if (p_order->prev_node && right_side > p_order->prev_index) { + right_side = p_order->prev_index; + } + + merkle_index_t n; + struct intermed_tree_detail detail; + + detail.seed = (p_order->next_tree ? tree->seed_next : tree->seed); + detail.lm_type = tree->lm_type; + detail.lm_ots_type = tree->lm_ots_type; + detail.h = tree->h; + detail.tree_height = tree->level; + detail.I = (p_order->next_tree ? tree->I_next : tree->I); + detail.got_error = &got_error; + +#if DO_FLOATING_POINT + /* Check if we're actually doing a suborder */ + struct sub_order *sub = p_order->sub; + if (sub) { + /* Issue all the orders separately */ + unsigned hash_len = tree->hash_size; + for (n = 0; n < p_order->count_nodes; n++ ) { + if (n == right_side) continue; /* Skip the omitted value */ + unsigned char *dest = &sub->h[ n * sub->num_hashes * hash_len ]; + merkle_index_t node_num = (sub->node_num_first_target+n) << sub->level; + unsigned k; + for (k=0; k < sub->num_hashes; k++) { + detail.dest = dest; + dest += hash_len; + detail.node_num = node_num; + node_num++; + detail.node_count = 1; + + hss_thread_issue_work(col, hss_gen_intermediate_tree, + &detail, sizeof detail ); + } + } + continue; + } +#endif + { + /* We're not doing a suborder; issue the request in as large of */ + /* a chunk as we're allowed */ + for (n = 0; n < p_order->count_nodes; ) { + merkle_index_t this_req = right_side - n; + if (this_req > max_per_request) this_req = max_per_request; + if (this_req == 0) { + /* We hit the value we're skipping; skip it, and go on to */ + /* the real right side */ + n++; + right_side = p_order->count_nodes; + continue; + } + + /* Issue a work order for the next this_req elements */ + detail.dest = &subtree->nodes[ hash_size * (lower_index + n)]; + detail.node_num = (subtree->left_leaf >> subtree->levels_below) + + n + ((merkle_index_t)1 << (h_subtree + subtree->level)); + detail.node_count = this_req; + + hss_thread_issue_work(col, hss_gen_intermediate_tree, + &detail, sizeof detail ); + + n += this_req; + } + } + } + + /* We've issued all the order; now wait until all the work is done */ + hss_thread_done(col); + if (got_error != hss_error_none) { + /* One of the worker threads detected an error */ +#if DO_FLOATING_POINT + /* Don't leak suborders on an intermediate error */ + for (i=0; i<(sequence_t)count_order; i++) { + free( order[i].sub ); // IGNORE free-check + } +#endif + info->error_code = got_error; + goto failed; + } + +#if DO_FLOATING_POINT + /* + * Now, if we did have suborders, recombine them into what was actually + * wanted + */ + for (i=0; i<(sequence_t)count_order; i++) { + p_order = &order[i]; + struct sub_order *sub = p_order->sub; + if (!sub) continue; /* This order wasn't subdivided */ + + const struct merkle_level *tree = p_order->tree; + const unsigned char *I = (p_order->next_tree ? tree->I_next : tree->I); + struct subtree *subtree = p_order->subtree; + unsigned hash_size = tree->hash_size; + unsigned h_subtree = (subtree->level == 0) ? tree->top_subtree_size : + tree->subtree_size; + merkle_index_t lower_index = ((merkle_index_t)1 << h_subtree) - 1; + + merkle_index_t n; + for (n = 0; n < p_order->count_nodes; n++ ) { + if (p_order->prev_node && n == p_order->prev_index) continue; + + hash_subtree( &subtree->nodes[ hash_size * (lower_index + n)], + &sub->h[ hash_size * sub->num_hashes * n ], + sub->level, sub->node_num_first_target + n, + hash_size, tree->h, I); + } + + free( sub ); // IGNORE free-check + p_order->sub = 0; + } +#endif + + /* + * Now we have generated the lower level nodes of the subtrees; go back and + * fill in the higher level nodes. + * We do this in backwards order, so that we do the lower levels of the trees + * first (as lower levels are cheaper, they'll be listed later in the + * array; that's how we sorted, them, remember?). + * That means if any subtrees inherit the root values of lower trees, + * we compute those root values first + */ + for (i=count_order; i>0; i--) { + p_order = &order[i-1]; + const struct merkle_level *tree = p_order->tree; + const unsigned char *I = (p_order->next_tree ? tree->I_next : tree->I); + struct subtree *subtree = p_order->subtree; + + if (p_order->prev_node) { + /* This subtree did have a bottom node that was the root node */ + /* of a lower subtree; fill it in */ + unsigned hash_size = tree->hash_size; + unsigned h_subtree = (subtree->level == 0) ? tree->top_subtree_size : + tree->subtree_size; + merkle_index_t lower_index = ((merkle_index_t)1 << h_subtree) - 1; + + /* Where in the subtree we place the previous root */ + unsigned set_index = (lower_index + p_order->prev_index) * hash_size; + memcpy( &subtree->nodes[ set_index ], p_order->prev_node, hash_size ); + } + + /* Now, fill in all the internal nodes of the subtree */ + fill_subtree(tree, subtree, p_order->count_nodes, I); + } + + /* + * Hey; we've initialized all the subtrees (at least, as far as what + * they'd be expected to be given the current count); hurray! + */ + + /* + * Now, create all the signed public keys + * Again, we could parallelize this; it's also fast enough not to be worth + * the complexity + */ + for (i = 1; i < w->levels; i++) { + if (!hss_create_signed_public_key( w->signed_pk[i], w->siglen[i-1], + w->tree[i], w->tree[i-1], w )) { + info->error_code = hss_error_internal; /* Really shouldn't */ + /* happen */ + goto failed; + } + } + hss_zeroize( private_key, sizeof private_key ); + + /* + * And, we make each level as not needing an update from below (as we've + * initialized them as already having the first update) + */ + for (i = 0; i < w->levels - 1; i++) { + w->tree[i]->update_count = UPDATE_DONE; + } + + w->status = hss_error_none; /* This working key has been officially */ + /* initialized, and now can be used */ + return true; + +failed: + hss_zeroize( private_key, sizeof private_key ); + return false; +} + +#if DO_FLOATING_POINT +/* + * This goes through the order, and estimates the total amount + * This assumes that the highest cost element is listed first + * + * It returns the estimated number of hash compression operations total + * + * We use floating point because the number of hash compression functions can + * vary a *lot*; floating point has great dynamic range. + */ +static float estimate_total_cost( struct init_order *order, + unsigned count_order ) { + if (count_order == 0) return 0; + float total_cost = 0; + + unsigned i; + + for (i=0; i +#include "common_defs.h" +#include "hss.h" +#include "config.h" + +/* + * This is the central internal include file for the functions that make up + * this subsystem. It should not be used by applications + */ + +#define PARAM_SET_COMPRESS_LEN 1 /* We assume that we can compress the */ + /* lm_type and the lm_ots type for a */ + /* single level into 1 byte */ + +#define PARM_SET_END 0xff /* We set this marker in the parameter set */ + /* when fewer than the maximum levels are used */ + + +/* + * The internal structure of a private key + */ +#define PRIVATE_KEY_INDEX 0 +#define PRIVATE_KEY_INDEX_LEN 8 /* 2**64 signatures should be enough for */ + /* everyone */ +#define PRIVATE_KEY_PARAM_SET (PRIVATE_KEY_INDEX + PRIVATE_KEY_INDEX_LEN) +#define PRIVATE_KEY_PARAM_SET_LEN (PARAM_SET_COMPRESS_LEN * MAX_HSS_LEVELS) +#define PRIVATE_KEY_SEED (PRIVATE_KEY_PARAM_SET + PRIVATE_KEY_PARAM_SET_LEN) +#if SECRET_METHOD == 2 +#define PRIVATE_KEY_SEED_LEN (SEED_LEN + I_LEN) +#else +#define PRIVATE_KEY_SEED_LEN SEED_LEN +#endif +#define PRIVATE_KEY_LEN (PRIVATE_KEY_SEED + PRIVATE_KEY_SEED_LEN) /* That's */ + /* 48 bytes */ + +struct merkle_level; +struct hss_working_key { + unsigned levels; + enum hss_error_code status; /* What is the status of this key */ + /* hss_error_none if everything looks ok */ + /* Otherwise, the error code we report if */ + /* we try to use this key to sign */ + sequence_t reserve_count; /* The value written to the private key */ + /* Will be higher than the 'current count' */ + /* if some signaures are 'reserved' */ + sequence_t max_count; /* The maximum count we can ever have */ + unsigned autoreserve; /* How many signatures to attempt to */ + /* reserve if the signing process hits */ + /* the end of the current reservation */ + + size_t signature_len; /* The length of the HSS signature */ + + unsigned char *stack; /* The stack memory used by the subtrees */ + + /* The private key (in its entirety) */ + unsigned char private_key[PRIVATE_KEY_LEN]; + /* The pointer to the seed (contained within the private key) */ + /* Warning: nonsyntaxic macro; need to be careful how we use this */ +#define working_key_seed private_key + PRIVATE_KEY_SEED + + size_t siglen[MAX_HSS_LEVELS]; /* The lengths of the signatures */ + /* generated by the various levels */ + size_t signed_pk_len[MAX_HSS_LEVELS]; /* The lengths of the signed */ + /* public keys for the various levels */ + unsigned char *signed_pk[MAX_HSS_LEVELS]; /* The current signed public */ + /* keys for the nontop levels */ + /* Each array element is that level's */ + /* current root value, signed by the */ + /* previous level. Unused for the */ + /* topmost level */ + struct merkle_level *tree[MAX_HSS_LEVELS]; /* The structures that manage */ + /* each individual level */ +}; + +#define MIN_SUBTREE 2 /* All subtrees (other than the root subtree) have */ + /* at least 2 levels */ +#define MAX_SUBLEVELS ((MAX_MERKLE_HEIGHT + MIN_SUBTREE - 1) / MIN_SUBTREE) +#if MAX_SUBLEVELS > (1 << (MIN_MERKLE_HEIGHT-1)) - 2 +#error We need to rethink our parent tree update logic, as there is a +#error possibility we do not give the tree enough updates between signatures +/* One possible fix would be to increase the subtree size for extremely */ +/* tall trees */ +#endif + +struct merkle_level { + unsigned level; /* Total number of levels */ + unsigned h, hash_size; /* Hash function, width */ + param_set_t lm_type; + param_set_t lm_ots_type; /* OTS parameter */ + merkle_index_t current_index; /* The number of signatures this tree has */ + /* generated so far */ + merkle_index_t max_index; /* 1<levels) */ + unsigned level; /* The level that the root of this subtree */ + /* is within the larger Merkle tree */ + unsigned levels_below; /* The number of levels below this subtree */ + /* in the Merkle tree */ + unsigned char *stack; /* Pointer to the stack used when */ + /* generating nodes; will be a pointer */ + /* into the hss_working_key::stack array */ + /* Used to incrementally compute bottom */ + /* node values */ + unsigned char nodes[1]; /* The actual subtree node values */ + /* 2*(1< +#include +#include "common_defs.h" +#include "hss.h" +#include "hss_internal.h" +#include "hss_aux.h" +#include "endian.h" +#include "hash.h" +#include "hss_thread.h" +#include "lm_common.h" +#include "lm_ots_common.h" + +/* Count the number of 1 bits at the end (lsbits) of the integer */ +/* Do it in the obvious way; straightline code may be faster (no */ +/* unpredictable jumps, which are costly), but that would be less scrutable */ +static int trailing_1_bits(merkle_index_t n) { + int i; + for (i=0; n&1; n>>=1, i++) + ; + return i; +} + +/* + * This creates a private key (and the correspond public key, and optionally + * the aux data for that key) + * Parameters: + * generate_random - the function to be called to generate randomness. This + * is assumed to be a pointer to a cryptographically secure rng, + * otherwise all security is lost. This function is expected to fill + * output with 'length' uniformly distributed bits, and return 1 on + * success, 0 if something went wrong + * levels - the number of levels for the key pair (2-8) + * lm_type - an array of the LM registry entries for the various levels; + * entry 0 is the topmost + * lm_ots_type - an array of the LM-OTS registry entries for the various + * levels; again, entry 0 is the topmost + * update_private_key, context - the function that is called when the + * private key is generated; it is expected to store it to secure NVRAM + * If this is NULL, then the context pointer is reinterpretted to mean + * where in RAM the private key is expected to be placed + * public_key - where to store the public key + * len_public_key - length of the above buffer; see hss_get_public_key_len + * if you need a hint. + * aux_data - where to store the optional aux data. This is not required, but + * if provided, can be used to speed up the hss_generate_working_key + * process; + * len_aux_data - the length of the above buffer. This is not fixed length; + * the function will run different time/memory trade-offs based on the + * length provided + * + * This returns true on success, false on failure + */ +bool hss_generate_private_key( + bool (*generate_random)(void *output, size_t length), + unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + unsigned char *public_key, size_t len_public_key, + unsigned char *aux_data, size_t len_aux_data, + struct hss_extra_info *info) { + + struct hss_extra_info info_temp = { 0 }; + if (!info) info = &info_temp; + + if (!generate_random) { + /* We *really* need random numbers */ + info->error_code = hss_error_no_randomness; + return false; + } + if (levels < MIN_HSS_LEVELS || levels > MAX_HSS_LEVELS) { + /* parameter out of range */ + info->error_code = hss_error_bad_param_set; + return false; + } + + unsigned h0; /* The height of the root tree */ + unsigned h; /* The hash function used */ + unsigned size_hash; /* The size of each hash that would appear in the */ + /* aux data */ + if (!lm_look_up_parameter_set(lm_type[0], &h, &size_hash, &h0)) { + info->error_code = hss_error_bad_param_set; + return false; + } + + /* Check the public_key_len */ + if (4 + 4 + 4 + I_LEN + size_hash > len_public_key) { + info->error_code = hss_error_buffer_overflow; + /* public key won't fit in the buffer we're given */ + return false; + } + + /* If you provide an aux_data buffer, we have to write something */ + /* into it (at least, enough to mark it as 'we're not really using */ + /* aux data) */ + if (aux_data && len_aux_data == 0) { + /* not enough aux data buffer to mark it as 'not really used' */ + info->error_code = hss_error_bad_aux; + return false; + } + + unsigned len_ots_pub = lm_ots_get_public_key_len(lm_ots_type[0]); + if (len_ots_pub == 0) { + info->error_code = hss_error_bad_param_set; + return false; + } + + unsigned char private_key[ PRIVATE_KEY_LEN ]; + + /* First step: format the private key */ + put_bigendian( private_key + PRIVATE_KEY_INDEX, 0, + PRIVATE_KEY_INDEX_LEN ); + if (!hss_compress_param_set( private_key + PRIVATE_KEY_PARAM_SET, + levels, lm_type, lm_ots_type, + PRIVATE_KEY_PARAM_SET_LEN )) { + info->error_code = hss_error_bad_param_set; + return false; + } + if (!(*generate_random)( private_key + PRIVATE_KEY_SEED, + PRIVATE_KEY_SEED_LEN )) { + info->error_code = hss_error_bad_randomness; + return false; + } + + /* Now make sure that the private key is written to NVRAM */ + if (update_private_key) { + if (!(*update_private_key)( private_key, PRIVATE_KEY_LEN, context)) { + /* initial write of private key didn't take */ + info->error_code = hss_error_private_key_write_failed; + hss_zeroize( private_key, sizeof private_key ); + return false; + } + } else { + if (context == 0) { + /* We weren't given anywhere to place the private key */ + info->error_code = hss_error_no_private_buffer; + hss_zeroize( private_key, sizeof private_key ); + return false; + } + memcpy( context, private_key, PRIVATE_KEY_LEN ); + } + + /* Figure out what would be the best trade-off for the aux level */ + struct expanded_aux_data *expanded_aux_data = 0, aux_data_storage; + if (aux_data != NULL) { + aux_level_t aux_level = hss_optimal_aux_level( len_aux_data, lm_type, + lm_ots_type, NULL ); + hss_store_aux_marker( aux_data, aux_level ); + + /* Set up the aux data pointers */ + expanded_aux_data = hss_expand_aux_data( aux_data, len_aux_data, + &aux_data_storage, size_hash, 0 ); + } + + unsigned char I[I_LEN]; + unsigned char seed[SEED_LEN]; + if (!hss_generate_root_seed_I_value( seed, I, private_key+PRIVATE_KEY_SEED)) { + info->error_code = hss_error_internal; + hss_zeroize( private_key, sizeof private_key ); + return false; + } + + /* Now, it's time to generate the public key, which means we need to */ + /* compute the entire top level Merkle tree */ + + /* First of all, figure out the appropriate level to compute up to */ + /* in parallel. We'll do the lower of the bottom-most level that */ + /* appears in the aux data, and 4*log2 of the number of core we have */ + unsigned num_cores = hss_thread_num_tracks(info->num_threads); + unsigned level; + unsigned char *dest = 0; /* The area we actually write to */ + void *temp_buffer = 0; /* The buffer we need to free when done */ + for (level = h0-1; level > 2; level--) { + /* If our bottom-most aux data is at this level, we want it */ + if (expanded_aux_data && expanded_aux_data->data[level]) { + /* Write directly into the aux area */ + dest = expanded_aux_data->data[level]; + break; + } + + /* If going to a higher levels would mean that we wouldn't */ + /* effectively use all the cores we have, use this level */ + if (((unsigned)1<num_threads); + + struct intermed_tree_detail details; + /* Set the values in the details structure that are constant */ + details.seed = seed; + details.lm_type = lm_type[0]; + details.lm_ots_type = lm_ots_type[0]; + details.h = h; + details.tree_height = h0; + details.I = I; + enum hss_error_code got_error = hss_error_none; /* This flag is set */ + /* on an error */ + details.got_error = &got_error; + + merkle_index_t j; + /* # of nodes at this level */ + merkle_index_t level_nodes = (merkle_index_t)1 << level; + /* the index of the node we're generating right now */ + merkle_index_t node_num = level_nodes; + /* + * We'd prefer not to issue a separate work item for every node; we + * might be doing millions of node (if we have a large aux data space) + * and we end up malloc'ing a large structure for every work order. + * So, if we do have a large number of requires, aggregate them + */ + merkle_index_t increment = level_nodes / (10 * num_cores); +#define MAX_INCREMENT 20000 + if (increment > MAX_INCREMENT) increment = MAX_INCREMENT; + if (increment == 0) increment = 1; + for (j=0; j < level_nodes; ) { + unsigned this_increment; + if (level_nodes - j < increment) { + this_increment = level_nodes - j; + } else { + this_increment = increment; + } + + /* Set the particulars of this specific work item */ + details.dest = dest + j*size_hash; + details.node_num = node_num; + details.node_count = this_increment; + + /* Issue a separate work request for every node at this level */ + hss_thread_issue_work(col, hss_gen_intermediate_tree, + &details, sizeof details ); + + j += this_increment; + node_num += this_increment; + } + /* Now wait for all those work items to complete */ + hss_thread_done(col); + + hss_zeroize( seed, sizeof seed ); + + /* Check if something went wrong. It really shouldn't have, however if */ + /* something returns an error code, we really should try to handle it */ + if (got_error != hss_error_none) { + /* We failed; give up */ + info->error_code = got_error; + hss_zeroize( private_key, sizeof private_key ); + if (update_private_key) { + (void)(*update_private_key)(private_key, PRIVATE_KEY_LEN, context); + } else { + hss_zeroize( context, PRIVATE_KEY_LEN ); + } + free(temp_buffer); // IGNORE free-check + return false; + } + + /* Now, we complete the rest of the tree. This is actually fairly fast */ + /* (one hash per node) so we don't bother to parallelize it */ + + unsigned char stack[ MAX_HASH * (MAX_MERKLE_HEIGHT+1) ]; + unsigned char root_hash[ MAX_HASH ]; + + /* Generate the top levels of the tree, ending with the root node */ + merkle_index_t r, leaf_node; + for (r=level_nodes, leaf_node = 0; leaf_node < level_nodes; r++, leaf_node++) { + + /* Walk up the stack, combining the current node with what's on */ + /* the atack */ + merkle_index_t q = leaf_node; + + /* + * For the subtree which this leaf node forms the final piece, put the + * destination to where we'll want it, either on the stack, or if this + * is the final piece, to where the caller specified + */ + unsigned char *current_buf; + unsigned stack_offset = trailing_1_bits( leaf_node ); + if (stack_offset == level) { + current_buf = root_hash; + } else { + current_buf = &stack[stack_offset * size_hash ]; + } + memcpy( current_buf, dest + leaf_node * size_hash, size_hash ); + + unsigned sp; + unsigned cur_lev = level; + for (sp = 1;; sp++, cur_lev--, q >>= 1) { + /* Give the aux data routines a chance to save the */ + /* intermediate value. Note that we needn't check for the */ + /* bottommost level; if we're saving aux data at that level, */ + /* we've already placed it there */ + if (sp > 1) { + hss_save_aux_data( expanded_aux_data, cur_lev, + size_hash, q, current_buf ); + } + + if (sp > stack_offset) break; + + + hss_combine_internal_nodes( current_buf, + &stack[(sp-1) * size_hash], current_buf, + h, I, size_hash, + r >> sp ); + } + } + /* The top entry in the stack is the root value (aka the public key) */ + + /* Complete the computation of the aux data */ + hss_finalize_aux_data( expanded_aux_data, size_hash, h, + private_key+PRIVATE_KEY_SEED ); + + /* We have the root value; now format the public key */ + put_bigendian( public_key, levels, 4 ); + public_key += 4; len_public_key -= 4; + put_bigendian( public_key, lm_type[0], 4 ); + public_key += 4; len_public_key -= 4; + put_bigendian( public_key, lm_ots_type[0], 4 ); + public_key += 4; len_public_key -= 4; + memcpy( public_key, I, I_LEN ); + public_key += I_LEN; len_public_key -= I_LEN; + memcpy( public_key, root_hash, size_hash ); + public_key += size_hash; len_public_key -= size_hash; + + /* Hey, what do you know -- it all worked! */ + hss_zeroize( private_key, sizeof private_key ); /* Zeroize local copy of */ + /* the private key */ + free(temp_buffer); // IGNORE free-check + return true; +} + +/* + * The length of the private key + */ +size_t hss_get_private_key_len(unsigned levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type) { + /* A private key is a 'public object'? Yes, in the sense that we */ + /* export it outside this module */ + LMS_UNUSED(levels); + LMS_UNUSED(lm_type); + LMS_UNUSED(lm_ots_type); + return PRIVATE_KEY_LEN; +} diff --git a/src/sig_stfl/lms/external/hss_param.c b/src/sig_stfl/lms/external/hss_param.c new file mode 100644 index 0000000000..a1c20ab14c --- /dev/null +++ b/src/sig_stfl/lms/external/hss_param.c @@ -0,0 +1,153 @@ +#include +#include "hss.h" +#include "hss_internal.h" +#include "endian.h" +#include "hss_zeroize.h" + +/* + * Convert a parameter set into the compressed version we use within a private + * key. This is the private key that'll end up being updated constantly, and + * so we try to make it as small as possible + */ +bool hss_compress_param_set( unsigned char *compressed, + int levels, + const param_set_t *lm_type, + const param_set_t *lm_ots_type, + size_t len_compressed ) { + int i; + + for (i=0; i 0x0e || b > 0x0e) return false; + /* Make sure the parm sets are supported */ + switch (a) { + case LMS_SHA256_N32_H5: case LMS_SHA256_N32_H10: + case LMS_SHA256_N32_H15: case LMS_SHA256_N32_H20: + case LMS_SHA256_N32_H25: + break; + default: + return false; + } + switch (b) { + case LMOTS_SHA256_N32_W1: case LMOTS_SHA256_N32_W2: + case LMOTS_SHA256_N32_W4: case LMOTS_SHA256_N32_W8: + break; + default: + return false; + } + + *compressed++ = (a<<4) + b; + len_compressed--; + } + + while (len_compressed) { + *compressed++ = PARM_SET_END; + len_compressed--; + } + + return true; +} + +/* + * This returns the parameter set for a given private key. + * This is here to solve a chicken-and-egg problem: the hss_working_key + * must be initialized to the same parameter set as the private key, + * but (other than this function, or somehow remembering it) there's + * no way to retreive the parameter set. + * + * read_private_key/context will read the private key (if read_private_key is + * NULL, context is assumed to point to the private key) + * + * On success, *levels will be set to the number of levels, and lm_type[] + * and lm_ots_type[] will be set to the lm/ots parameter sets + * + * On success, this returns true; on failure (can't read the private key, or + * the private key is invalid), returns false + */ +bool hss_get_parameter_set( unsigned *levels, + param_set_t lm_type[ MAX_HSS_LEVELS ], + param_set_t lm_ots_type[ MAX_HSS_LEVELS ], + bool (*read_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context) { + unsigned char private_key[ PRIVATE_KEY_LEN ]; + bool success = false; + + if (read_private_key) { + if (!read_private_key( private_key, PRIVATE_KEY_SEED, context )) { + goto failed; + } + } else { + if (!context) return false; + memcpy( private_key, context, PRIVATE_KEY_SEED ); + } + + /* Scan through the private key to recover the parameter sets */ + unsigned total_height = 0; + unsigned level; + for (level=0; level < MAX_HSS_LEVELS; level++) { + unsigned char c = private_key[PRIVATE_KEY_PARAM_SET + level]; + if (c == PARM_SET_END) break; + /* Decode this level's parameter set */ + param_set_t lm = (c >> 4); + param_set_t ots = (c & 0x0f); + /* Make sure both are supported */ + /* While we're here, add up the total Merkle height */ + switch (lm) { + case LMS_SHA256_N32_H5: total_height += 5; break; + case LMS_SHA256_N32_H10: total_height += 10; break; + case LMS_SHA256_N32_H15: total_height += 15; break; + case LMS_SHA256_N32_H20: total_height += 20; break; + case LMS_SHA256_N32_H25: total_height += 25; break; + default: goto failed; + } + switch (ots) { + case LMOTS_SHA256_N32_W1: + case LMOTS_SHA256_N32_W2: + case LMOTS_SHA256_N32_W4: + case LMOTS_SHA256_N32_W8: + break; + default: goto failed; + } + lm_type[level] = lm; + lm_ots_type[level] = ots; + } + + if (level < MIN_HSS_LEVELS || level > MAX_HSS_LEVELS) goto failed; + + *levels = level; + + /* Make sure that the rest of the private key has PARM_SET_END */ + unsigned i; + for (i = level+1; i 64) total_height = 64; /* (bounded by 2**64) */ + sequence_t max_count = ((sequence_t)2 << (total_height-1)) - 1; + /* height-1 so we don't try to shift by 64, and hit U.B. */ + + /* We use the count 0xffff..ffff to signify 'we've used up all our */ + /* signatures'. Make sure that is above max_count, even for */ + /* parameter sets that can literally generate 2**64 signatures (by */ + /* letting them generate only 2**64-1) */ + if (total_height == 64) max_count--; + sequence_t current_count = get_bigendian( + private_key + PRIVATE_KEY_INDEX, PRIVATE_KEY_INDEX_LEN ); + + if (current_count > max_count) goto failed; /* Private key expired */ + + success = true; /* It worked! */ +failed: + /* There might be private keying material here */ + hss_zeroize( private_key, sizeof private_key ); + return success; +} diff --git a/src/sig_stfl/lms/external/hss_reserve.c b/src/sig_stfl/lms/external/hss_reserve.c new file mode 100644 index 0000000000..7ef8585560 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_reserve.c @@ -0,0 +1,194 @@ +#include +#include "common_defs.h" +#include "hss_internal.h" +#include "hss_reserve.h" +#include "endian.h" + +/* + * Initialize the reservation count to the given value + */ +void hss_set_reserve_count(struct hss_working_key *w, sequence_t count) { + w->reserve_count = count; +} + +/* + * Set the autoreserve count + */ +bool hss_set_autoreserve(struct hss_working_key *w, + unsigned sigs_to_autoreserve, struct hss_extra_info *info) { + if (!w) { + if (info) info->error_code = hss_error_got_null; + return false; + } + + /* Note: we do not check if the working key is in a usable state */ + /* There are a couple of odd-ball scenarios (e.g. when they've */ + /* manually allocated the key, but haven't loaded it yet) that we */ + /* don't have a good reason to disallow */ + + w->autoreserve = sigs_to_autoreserve; + return true; +} + +/* + * This is called when we generate a signature; it checks if we need + * to write out a new private key (and advance the reservation); if it + * decides it needs to write out a new private key, it also decides how + * far it needs to advance it + */ +bool hss_advance_count(struct hss_working_key *w, sequence_t cur_count, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + struct hss_extra_info *info, bool *trash_private_key) { + + if (cur_count == w->max_count) { + /* We hit the end of the root; this will be the last signature */ + /* this private key can do */ + w->status = hss_error_private_key_expired; /* Fail if they try to */ + /* sign any more */ + info->last_signature = true; + /* Make sure we zeroize the private key */ + *trash_private_key = true; /* We can't trash our copy of the */ + /* private key until after we've generated the signature */ + /* We can trash the copy in secure storage, though */ + if (update_private_key) { + unsigned char private_key[PRIVATE_KEY_LEN]; + memset( private_key, PARM_SET_END, PRIVATE_KEY_LEN ); + if (!update_private_key(private_key, PRIVATE_KEY_LEN, context)) { + info->error_code = hss_error_private_key_write_failed; + return false; + } + } else { + memset( context, PARM_SET_END, PRIVATE_KEY_LEN ); + } + return true; + } + sequence_t new_count = cur_count + 1; + + if (new_count > w->reserve_count) { + /* We need to advance the reservation */ + + /* Check if we have enough space to do the entire autoreservation */ + if (w->max_count - new_count > w->autoreserve) { + new_count += w->autoreserve; + } else { + /* If we don't have enough space, reserve what we can */ + new_count = w->max_count; + } + + put_bigendian( w->private_key + PRIVATE_KEY_INDEX, new_count, + PRIVATE_KEY_INDEX_LEN ); + if (update_private_key) { + if (!update_private_key(w->private_key, PRIVATE_KEY_INDEX_LEN, + context)) { + /* Oops, we couldn't write the private key; undo the */ + /* reservation advance (and return an error) */ + info->error_code = hss_error_private_key_write_failed; + put_bigendian( w->private_key + PRIVATE_KEY_INDEX, + w->reserve_count, PRIVATE_KEY_INDEX_LEN ); + return false; + } + } else { + put_bigendian( context, new_count, PRIVATE_KEY_INDEX_LEN ); + } + w->reserve_count = new_count; + } + + return true; +} + +/* + * This will make sure that (at least) N signatures are reserved; that is, we + * won't need to actually call the update function for the next N signatures + * generated + * + * This can be useful if the update_private_key function is expensive. + * + * Note that if, N (or more) signatures are already reserved, this won't do + * anything. + */ +bool hss_reserve_signature( + struct hss_working_key *w, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + unsigned sigs_to_reserve, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 }; + if (!info) info = &temp_info; + if (!w) { + info->error_code = hss_error_got_null; + return false; + } + if (w->status != hss_error_none) { + info->error_code = w->status;; + return false; + } + + if (sigs_to_reserve > w->max_count) { + info->error_code = hss_error_not_that_many_sigs_left; + return false; /* Very funny */ + } + + /* + * If we're given a raw private key, make sure it's the one we're + * thinking of. + * I have no idea why someone would reserve signatures if they have + * a raw private key (which is cheap to update), however there's no + * reason we shouldn't support it + */ + if (!update_private_key) { + if (0 != memcmp( context, w->private_key, PRIVATE_KEY_LEN)) { + info->error_code = hss_error_key_mismatch; + return false; /* Private key mismatch */ + } + } + + /* Figure out what the current count is */ + sequence_t current_count = 0; + unsigned i; + for (i = 0; ilevels; i++) { + struct merkle_level *tree = w->tree[i]; + /* -1 because the current_index counts the signatures to the */ + /* current next level */ + current_count = (current_count << tree->level) + + tree->current_index - 1; + } + current_count += 1; /* The bottom-most tree isn't advanced */ + + sequence_t new_reserve_count; /* This is what the new reservation */ + /* setting would be (if we accept the reservation) */ + if (current_count > w->max_count - sigs_to_reserve) { + /* Not that many sigantures left */ + /* Reserve as many as we can */ + new_reserve_count = w->max_count; + } else { + new_reserve_count = current_count + sigs_to_reserve; + } + + if (new_reserve_count <= w->reserve_count) { + /* We already have (at least) that many reserved; do nothing */ + return true; + } + + /* Attempt to update the count in the private key */ + put_bigendian( w->private_key + PRIVATE_KEY_INDEX, new_reserve_count, + PRIVATE_KEY_INDEX_LEN ); + /* Update the copy in NV storage */ + if (update_private_key) { + if (!update_private_key(w->private_key, PRIVATE_KEY_INDEX_LEN, + context)) { + /* Oops, couldn't update it */ + put_bigendian( w->private_key + PRIVATE_KEY_INDEX, + w->reserve_count, PRIVATE_KEY_INDEX_LEN ); + info->error_code = hss_error_private_key_write_failed; + return false; + } + } else { + memcpy( context, w->private_key, PRIVATE_KEY_INDEX_LEN ); + } + w->reserve_count = new_reserve_count; + + return true; +} diff --git a/src/sig_stfl/lms/external/hss_reserve.h b/src/sig_stfl/lms/external/hss_reserve.h new file mode 100644 index 0000000000..3b101c1130 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_reserve.h @@ -0,0 +1,21 @@ +#if !defined( HSS_RESERVE_H_ ) +#define HSS_RESERVE_H_ + +/* + * This is the internal include file for the reservation functions for this + * subsystem. It should not be used by applications + */ + +#include "common_defs.h" + +struct hss_working_key; + +void hss_set_reserve_count(struct hss_working_key *w, sequence_t count); + +bool hss_advance_count(struct hss_working_key *w, sequence_t new_count, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + struct hss_extra_info *info, bool *trash_private_key); + +#endif /* HSS_RESERVE_H_ */ diff --git a/src/sig_stfl/lms/external/hss_sign.c b/src/sig_stfl/lms/external/hss_sign.c new file mode 100644 index 0000000000..359e59df7b --- /dev/null +++ b/src/sig_stfl/lms/external/hss_sign.c @@ -0,0 +1,736 @@ +/* + * This is an implementation of the HSS signature scheme from LMS + * This is the part that actually generates the signature + */ +#include +#include +#include "common_defs.h" +#include "hss.h" +#include "hash.h" +#include "endian.h" +#include "hss_internal.h" +#include "hss_aux.h" +#include "hss_thread.h" +#include "hss_reserve.h" +#include "lm_ots.h" +#include "lm_ots_common.h" +#include "hss_derive.h" + +/* + * This adds one leaf to the building and next subtree. + */ +enum subtree_build_status { + subtree_got_error, /* Oops, something broke */ + subtree_more_to_do, /* Processed node, still more to do */ + subtree_did_last_node, /* Processed last node */ + subtree_all_done /* We're good */ +}; +static enum subtree_build_status subtree_add_next_node( + struct subtree *subtree, + struct merkle_level *tree, + int next_tree, + struct thread_collection *col) { + unsigned subtree_size = (subtree->level>0 ? tree->subtree_size : + tree->top_subtree_size); + unsigned log_leafs = subtree_size + subtree->levels_below; + merkle_index_t max_index = (merkle_index_t)1 << log_leafs; + /* Check if there is anything more to do */ + if (subtree->current_index == max_index) return subtree_all_done; + unsigned hash_size = tree->hash_size; + unsigned char cur_val[MAX_HASH]; + + /* Compute the leaf node */ + merkle_index_t i; + unsigned ots_len = lm_ots_get_public_key_len(tree->lm_ots_type); + unsigned char pub_key[ LEAF_MAX_LEN ]; + const unsigned char *I = (next_tree ? tree->I_next : tree->I); + memcpy( pub_key + LEAF_I, I, I_LEN ); + SET_D( pub_key + LEAF_D, D_LEAF ); + merkle_index_t r = subtree->left_leaf + subtree->current_index; + merkle_index_t q = r | ((merkle_index_t)1 << tree->level); + put_bigendian( pub_key + LEAF_R, q, 4); + + const unsigned char *seed = (next_tree ? tree->seed_next : tree->seed); + struct seed_derive derive; + if (!hss_seed_derive_init( &derive, tree->lm_type, tree->lm_ots_type, + I, seed )) return subtree_got_error; + hss_seed_derive_set_q(&derive, r); + if (!lm_ots_generate_public_key(tree->lm_ots_type, I, + r, &derive, pub_key + LEAF_PK, ots_len)) { + hss_seed_derive_done(&derive); + return subtree_got_error; + } + hss_seed_derive_done(&derive); + + /* Hash it to form the leaf node */ + union hash_context ctx; + hss_hash_ctx( cur_val, tree->h, &ctx, pub_key, LEAF_LEN(hash_size)); + + /* Where in the subtree we store the values */ + merkle_index_t subtree_index = subtree->current_index + + ((merkle_index_t)1 << log_leafs); + enum subtree_build_status status = subtree_more_to_do; + + /* Walk up the stack, and then up the tree */ + for (i=0;; i++) { + if (i >= subtree->levels_below) { + /* This node is within the subtree; save it */ + memcpy( &subtree->nodes[ (subtree_index-1) * hash_size ], cur_val, hash_size ); + } + if (subtree_index == 1) { /* Hit the root */ + status = subtree_did_last_node; + break; + } + if ((q & 1) == 0) break; /* Hit a left node */ + q >>= 1; + + /* This is a right node; combine it with the left node */ + unsigned char *left_node; + if (i >= subtree->levels_below) { + /* The left node is in the tree */ + left_node = &subtree->nodes[ (subtree_index-2) * hash_size ]; + } else { + /* The left node is on the stack */ + left_node = subtree->stack + (i * hash_size); + } + hss_combine_internal_nodes( cur_val, + left_node, cur_val, + tree->h, I, hash_size, + q); + subtree_index >>= 1; + } + + /* If we haven't got out of the stack, put the value there */ + if (i < subtree->levels_below) { + if (col) hss_thread_before_write(col); + memcpy( subtree->stack + (i * hash_size), cur_val, hash_size ); + if (col) hss_thread_after_write(col); + } + + /* Ok, we've done another node */ + subtree->current_index += 1; + + return status; +} + +/* + * This steps the next tree by one. We need to do this 2**tree->level times, + * and then the next tree will be ready + */ +static int hss_step_next_tree (struct merkle_level *tree, + const struct hss_working_key *w, + struct thread_collection *col) { + struct subtree *prev_subtree = 0; + struct subtree *subtree = 0; + int j; + + LMS_UNUSED(w); + /* Search for the subtree to update */ + for (j = tree->sublevels-1; j>=0; j--) { + subtree = tree->subtree[j][NEXT_TREE]; + if (subtree->current_index < MAX_SUBINDEX) break; + prev_subtree = subtree; + } + unsigned height_subtree = (j == 0) ? tree->top_subtree_size : + tree->subtree_size; + if (j >= 0) { + /* For subtrees other than the bottom one, we get the first */ + /* node 'for free' (as it's the root of the previous subtree */ + if (subtree->current_index == 0 && prev_subtree) { + /* For the initial node of the subtree, reuse the root */ + /* of the previous one */ + unsigned hash_size = tree->hash_size; + memcpy( &subtree->nodes[ hash_size * (((merkle_index_t)1<nodes[ 0 ], + hash_size ); + subtree->current_index = ((merkle_index_t)1 << subtree->levels_below); + } + + /* Add the next node */ + switch (subtree_add_next_node( subtree, tree, 1, col )) { + case subtree_got_error: default: return 0; /* Huh? */ + case subtree_more_to_do: + break; + case subtree_did_last_node: + case subtree_all_done: + /* Mark this subtree as 'all processed' */ + subtree->current_index = MAX_SUBINDEX; + break; + } + } + + return 1; +} + +/* + * Generate the next Merkle signature for a given level + */ +static int generate_merkle_signature( + unsigned char *signature, unsigned signature_len, + struct merkle_level *tree, + const struct hss_working_key *w, + const void *message, size_t message_len) { + /* First off, write the index value */ + LMS_UNUSED(w); + if (signature_len < 4) return 0; + merkle_index_t current_index = tree->current_index; + put_bigendian( signature, current_index, 4 ); + signature += 4; signature_len -= 4; + + /* Write the OTS signature */ + size_t ots_sig_size = lm_ots_get_signature_len( tree->lm_ots_type ); + if (ots_sig_size == 0 || ots_sig_size > signature_len) return 0; + if (message == NULL) { + /* Internal interface: if message = NULL, we're supposed to */ + /* generate everything *except* the OTS signature */ + memset( signature, 0, ots_sig_size ); + } else { + struct seed_derive derive; + if (!hss_seed_derive_init( &derive, + tree->lm_type, tree->lm_ots_type, + tree->I, tree->seed )) return 0; + hss_seed_derive_set_q(&derive, current_index); + bool success = lm_ots_generate_signature( tree->lm_ots_type, tree->I, + current_index, &derive, + message, message_len, false, + signature, ots_sig_size); + hss_seed_derive_done(&derive); + if (!success) return 0; + } + signature += ots_sig_size; signature_len -= ots_sig_size; + + /* Write the LM parameter set */ + if (signature_len < 4) return 0; + put_bigendian( signature, tree->lm_type, 4 ); + signature += 4; signature_len -= 4; + + /* Now, write the authentication path */ + int i, j; + merkle_index_t index = current_index; + unsigned n = tree->hash_size; + for (i = tree->sublevels-1; i>=0; i--) { + int height = (i == 0) ? tree->top_subtree_size : tree->subtree_size; + struct subtree *subtree = tree->subtree[i][ACTIVE_TREE]; + merkle_index_t subtree_index = (index & + (((merkle_index_t)1 << height) - 1)) + + ((merkle_index_t)1 << height); + for (j = height-1; j>=0; j--) { + if (signature_len < n) return 0; + memcpy( signature, subtree->nodes + n * ((subtree_index^1) - 1), n ); + signature += n; signature_len -= n; + subtree_index >>= 1; + } + index >>= height; + } + + /* Mark that we've generated a signature */ + tree->current_index = current_index + 1; + + return 1; +} + +/* + * This signed the root of tree with the parent; it places both the signature + * and the public key into signed_key + */ +bool hss_create_signed_public_key(unsigned char *signed_key, + size_t len_signature, + struct merkle_level *tree, + struct merkle_level *parent, + struct hss_working_key *w) { + /* Where we place the public key */ + unsigned char *public_key = signed_key + len_signature; + + /* Place the public key there */ + put_bigendian( public_key + 0, tree->lm_type, 4 ); + put_bigendian( public_key + 4, tree->lm_ots_type, 4 ); + memcpy( public_key + 8, tree->I, I_LEN ); + unsigned hash_size = tree->hash_size; + /* This is where the root hash is */ + memcpy( public_key + 8 + I_LEN, + tree->subtree[0][ACTIVE_TREE]->nodes, + hash_size ); + unsigned len_public_key = 8 + I_LEN + hash_size; + + /* Now, generate the signature */ + if (!generate_merkle_signature( signed_key, len_signature, + parent, w, public_key, len_public_key)) { + return false; + } + + parent->update_count = UPDATE_NEXT; /* The parent has generated a */ + /* signature; it's now eligible for another */ + /* round of updates */ + + return true; +} + +struct gen_sig_detail { + unsigned char *signature; + size_t signature_len; + const unsigned char *message; + size_t message_len; + struct hss_working_key *w; + enum hss_error_code *got_error; +}; +/* This does the actual signature generation */ +/* It is (potentially) run within a thread */ +static void do_gen_sig( const void *detail, struct thread_collection *col) { + const struct gen_sig_detail *d = detail; + size_t signature_len = d->signature_len; + unsigned char *signature = d->signature; + struct hss_working_key *w = d->w; + unsigned levels = w->levels; + + /* The number of signed public keys */ + if (signature_len < 4) goto failed; + put_bigendian( signature, levels - 1, 4 ); + signature += 4; signature_len -= 4; + /* The signed public keys */ + unsigned i; + for (i=1; isigned_pk_len[i]; + if (signature_len < len_signed_pk) goto failed; + memcpy( signature, w->signed_pk[i], len_signed_pk ); + signature += len_signed_pk; signature_len -= len_signed_pk; + } + /* And finally the signature of the actual message */ + if (signature_len < w->siglen[levels-1]) goto failed; /* Oops, not enough room */ + + const unsigned char *message = d->message; + size_t message_len = d->message_len; + + if (!generate_merkle_signature(signature, signature_len, + w->tree[ levels-1 ], w, message, message_len)) { + goto failed; + } + + /* Success! */ + return; + +failed: + /* Report failure */ + hss_thread_before_write(col); + *d->got_error = hss_error_internal; + hss_thread_after_write(col); +} + +struct step_next_detail { + struct hss_working_key *w; + struct merkle_level *tree; + enum hss_error_code *got_error; +}; +/* This steps the next tree */ +/* It is (potentially) run within a thread */ +static void do_step_next( const void *detail, struct thread_collection *col) { + const struct step_next_detail *d = detail; + struct hss_working_key *w = d->w; + struct merkle_level *tree = d->tree; + + if (!hss_step_next_tree( tree, w, col )) { + /* Report failure */ + hss_thread_before_write(col); + *d->got_error = hss_error_internal; + hss_thread_after_write(col); + } +} + +struct step_building_detail { + struct merkle_level *tree; + struct subtree *subtree; + enum hss_error_code *got_error; +}; +/* This steps the building tree */ +/* It is (potentially) run within a thread */ +static void do_step_building( const void *detail, + struct thread_collection *col) { + const struct step_building_detail *d = detail; + struct merkle_level *tree = d->tree; + struct subtree *subtree = d->subtree; + + switch (subtree_add_next_node( subtree, tree, 0, col )) { + case subtree_got_error: default: + /* Huh? Report failure */ + hss_thread_before_write(col); + *d->got_error = hss_error_internal; + hss_thread_after_write(col); + break; + case subtree_more_to_do: + case subtree_did_last_node: + case subtree_all_done: + break; + } +} + +struct update_parent_detail { + struct hss_working_key *w; + enum hss_error_code *got_error; +}; +/* + * This gives an update to the parent (non-bottom Merkle trees) + */ +static void do_update_parent( const void *detail, + struct thread_collection *col) { + const struct update_parent_detail *d = detail; + struct hss_working_key *w = d->w; + unsigned levels = w->levels; + unsigned current_level = levels - 2; /* We start with the first */ + /* non-bottom level */ + for (;;) { + struct merkle_level *tree = w->tree[current_level]; + switch (tree->update_count) { + case UPDATE_DONE: return; /* No more updates needed */ + case UPDATE_NEXT: /* Our job is to update the next tree */ + tree->update_count = UPDATE_PARENT; + if (current_level == 0) return; /* No next tree to update */ + if (!hss_step_next_tree( tree, w, col )) goto failed; + return; + case UPDATE_PARENT: /* Our job is to update our parent */ + tree->update_count = UPDATE_BUILDING + 0; + if (current_level == 0) return; /* No parent to update */ + current_level -= 1; + continue; + default: { + /* Which building tree we need to update */ + unsigned level_to_update = + (tree->update_count - UPDATE_BUILDING) + 1; + if (level_to_update >= tree->sublevels) { + /* We've completed all the updates we need to do (until */ + /* the next time we need to sign something) */ + tree->update_count = UPDATE_DONE; + return; + } + + /* Next time, update the next BUILDING subtree */ + tree->update_count += 1; + + struct subtree *subtree = + tree->subtree[level_to_update][BUILDING_TREE]; + + /* The number of leaves in this tree */ + merkle_index_t tree_leaves = (merkle_index_t)1 << tree->level; + + /* Check if we'd actually use the building tree */ + if (subtree->left_leaf >= tree_leaves) { + /* We'll never use it; don't bother updating it */ + return; + } + + /* We'll use the BUILDING_TREE, actually add a node */ + switch (subtree_add_next_node( subtree, tree, 0, col )) { + case subtree_got_error: default: goto failed; /* Huh? */ + case subtree_did_last_node: + case subtree_all_done: + case subtree_more_to_do: + /* We're done everything we need to do for this step */ + return; + } + } + } + } + +failed: + /* Huh? Report failure */ + hss_thread_before_write(col); + *d->got_error = hss_error_internal; + hss_thread_after_write(col); +} + +/* + * Code to actually generate the signature + */ +bool hss_generate_signature( + struct hss_working_key *w, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + const void *message, size_t message_len, + unsigned char *signature, size_t signature_buf_len, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 }; + if (!info) info = &temp_info; + unsigned i; + bool trash_private_key = false; + + info->last_signature = false; + + if (!w) { + info->error_code = hss_error_got_null; + goto failed; + } + if (w->status != hss_error_none) { + info->error_code = w->status; + goto failed; + } + + /* If we're given a raw private key, make sure it's the one we're */ + /* thinking of */ + if (!update_private_key) { + if (0 != memcmp( context, w->private_key, PRIVATE_KEY_LEN)) { + info->error_code = hss_error_key_mismatch; + return false; /* Private key mismatch */ + } + } + + /* Check if the buffer we were given is too short */ + if (w->signature_len > signature_buf_len) { + /* The signature would overflow the buffer */ + info->error_code = hss_error_buffer_overflow; + goto failed; + } + + unsigned levels = w->levels; + /* + * Compile the current count + */ + sequence_t current_count = 0; + for (i=0; i < levels; i++) { + struct merkle_level *tree = w->tree[i]; + current_count <<= tree->level; + /* We subtract 1 because the nonbottom trees are already advanced */ + current_count += (sequence_t)tree->current_index - 1; + } + current_count += 1; /* Bottom most tree isn't already advanced */ + + /* Ok, try to advance the private key */ + if (!hss_advance_count(w, current_count, + update_private_key, context, info, + &trash_private_key)) { + /* hss_advance_count fills in the error reason */ + goto failed; + } + + /* Ok, now actually generate the signature */ + + /* We'll be doing several things in parallel */ + struct thread_collection *col = hss_thread_init(info->num_threads); + enum hss_error_code got_error = hss_error_none; + + /* Generate the signature */ + { + struct gen_sig_detail gen_detail; + gen_detail.signature = signature; + gen_detail.signature_len = w->signature_len; + gen_detail.message = message; + gen_detail.message_len = message_len; + gen_detail.w = w; + gen_detail.got_error = &got_error; + + hss_thread_issue_work(col, do_gen_sig, &gen_detail, sizeof gen_detail); + } + + /* Update the bottom level next tree */ + if (levels > 1) { + struct step_next_detail step_detail; + step_detail.w = w; + step_detail.tree = w->tree[levels-1]; + step_detail.got_error = &got_error; + + hss_thread_issue_work(col, do_step_next, &step_detail, sizeof step_detail); + } + + /* Issue orders to step each of the building subtrees in the bottom tree */ + int skipped_a_level = 0; /* Set if the below issued didn't issue an */ + /* order for at least one level */ + { + struct merkle_level *tree = w->tree[levels-1]; + merkle_index_t updates_before_end = tree->max_index - tree->current_index + 1; + int h_subtree = tree->subtree_size; + for (i=1; isublevels; i++) { + struct subtree *subtree = tree->subtree[i][BUILDING_TREE]; + /* Check if there is a building tree */ + if (updates_before_end < (merkle_index_t)1 << + (subtree->levels_below + h_subtree)) { + /* No; we're at the last subtree within this tree */ + skipped_a_level = 1; + continue; + } + struct step_building_detail step_detail; + step_detail.tree = tree; + step_detail.subtree = subtree; + step_detail.got_error = &got_error; + + hss_thread_issue_work(col, do_step_building, &step_detail, sizeof step_detail); + + } + /* If there's only one sublevel, act as if we always skipped a sublevel */ + if (tree->sublevels == 1) skipped_a_level = 1; + } + + /* + * And, if we're allowed to give the parent a chance to update, and + * there's a parent with some updating that needs to be done, schedule + * that to be done + */ + if (skipped_a_level && + levels > 1 && w->tree[levels-2]->update_count != UPDATE_DONE) { + struct update_parent_detail detail; + detail.w = w; + detail.got_error = &got_error; + hss_thread_issue_work(col, do_update_parent, &detail, sizeof detail); + } + + /* Wait for all of them to finish */ + hss_thread_done(col); + + /* Check if any of them reported a failure */ + if (got_error != hss_error_none) { + info->error_code = got_error; + goto failed; + } + + current_count += 1; /* The new count is one more than what is */ + /* implied by the initial state of the Merkle trees */ + + /* + * Now, we scan to see if we exhausted a Merkle tree, and need to update it + * At the same time, we check to see if we need to advance the subtrees + */ + sequence_t cur_count = current_count; + unsigned merkle_levels_below = 0; + int switch_merkle = w->levels; + struct merkle_level *tree; + for (i = w->levels; i>=1; i--, merkle_levels_below += tree->level) { + tree = w->tree[i-1]; + + if (0 == (cur_count & (((sequence_t)1 << (merkle_levels_below + tree->level))-1))) { + /* We exhausted this tree */ + if ((i-1) == 0) { + /* We've run out of signatures; we've already caught this */ + /* above; just make *sure* we've marked the key as */ + /* unusable, and give up */ + w->status = hss_error_private_key_expired; + break; + } + + /* Remember we'll need to switch to the NEXT_TREE */ + switch_merkle = i-1; + continue; + } + + /* Check if we need to advance any of the subtrees */ + unsigned subtree_levels_below = 0; + unsigned j; + for (j = tree->sublevels-1; j>0; j--) { + subtree_levels_below += tree->subtree_size; + if (0 != (cur_count & (((sequence_t)1 << (merkle_levels_below + subtree_levels_below))-1))) { + /* We're in the middle of this subtree */ + goto done_advancing; + } + + /* Switch to the building subtree */ + struct subtree *next = tree->subtree[j][BUILDING_TREE]; + struct subtree *prev = tree->subtree[j][ACTIVE_TREE]; + unsigned char *stack = next->stack; /* Stack stays with */ + /* building tree */ + tree->subtree[j][ACTIVE_TREE] = next; + /* We need to reset the parameters on the new building subtree */ + prev->current_index = 0; + prev->left_leaf += (merkle_index_t)2 << subtree_levels_below; + tree->subtree[j][BUILDING_TREE] = prev; + next->stack = NULL; + prev->stack = stack; + } + } +done_advancing: + /* Check if we used up any Merkle trees; if we have, switch to the */ + /* NEXT_TREE (which we've built in our spare time) */ + for (i = switch_merkle; i < w->levels; i++) { + struct merkle_level *tree_l = w->tree[i]; + struct merkle_level *parent = w->tree[i-1]; + unsigned j; + + /* Rearrange the subtrees */ + for (j=0; jsublevels; j++) { + /* Make the NEXT_TREE active; replace it with the current active */ + struct subtree *active = tree_l->subtree[j][NEXT_TREE]; + struct subtree *next = tree_l->subtree[j][ACTIVE_TREE]; + unsigned char *stack = active->stack; /* Stack stays with */ + /* next tree */ + + active->left_leaf = 0; + next->current_index = 0; + next->left_leaf = 0; + tree_l->subtree[j][ACTIVE_TREE] = active; + tree_l->subtree[j][NEXT_TREE] = next; + active->stack = NULL; + next->stack = stack; + if (j > 0) { + /* Also reset the building tree */ + struct subtree *building = tree->subtree[j][BUILDING_TREE]; + building->current_index = 0; + merkle_index_t size_subtree = (merkle_index_t)1 << + (tree->subtree_size + building->levels_below); + building->left_leaf = size_subtree; + } + } + + /* Copy in the value of seed, I we'll use for the new tree */ + memcpy( tree_l->seed, tree->seed_next, SEED_LEN ); + memcpy( tree_l->I, tree->I_next, I_LEN ); + + /* Compute the new next I, which is derived from either the parent's */ + /* I or the parent's I_next value */ + merkle_index_t index = parent->current_index; + if (index == parent->max_index) { + hss_generate_child_seed_I_value(tree->seed_next, tree->I_next, + parent->seed_next, parent->I_next, 0, + parent->lm_type, + parent->lm_ots_type); + } else { + hss_generate_child_seed_I_value( tree->seed_next, tree->I_next, + parent->seed, parent->I, index+1, + parent->lm_type, + parent->lm_ots_type); + } + + tree_l->current_index = 0; /* We're starting this from scratch */ + + /* Generate the signature of the new level */ + if (!hss_create_signed_public_key( w->signed_pk[i], w->siglen[i-1], + tree_l, parent, w )) { + info->error_code = hss_error_internal; + goto failed; + } + } + + /* And we've set things up for the next signature... */ + + if (trash_private_key) { + memset( w->private_key, PARM_SET_END, PRIVATE_KEY_LEN ); + } + + return true; + +failed: + + if (trash_private_key) { + memset( w->private_key, PARM_SET_END, PRIVATE_KEY_LEN ); + } + + /* On failure, make sure that we don't return anything that might be */ + /* misconstrued as a real signature */ + memset( signature, 0, signature_buf_len ); + return false; +} + +/* + * Get the signature length + */ +size_t hss_get_signature_len_from_working_key(struct hss_working_key *w) { + if (!w || w->status != hss_error_none) return 0; + + int levels = w->levels; + if (levels > MAX_HSS_LEVELS) return 0; + param_set_t lm[MAX_HSS_LEVELS], ots[MAX_HSS_LEVELS]; + int i; + for (i=0; itree[i]->lm_type; + ots[i] = w->tree[i]->lm_ots_type; + } + + return hss_get_signature_len(levels, lm, ots); +} diff --git a/src/sig_stfl/lms/external/hss_sign_inc.c b/src/sig_stfl/lms/external/hss_sign_inc.c new file mode 100644 index 0000000000..e455b5cd2b --- /dev/null +++ b/src/sig_stfl/lms/external/hss_sign_inc.c @@ -0,0 +1,218 @@ +/* + * This is the code that implements the hierarchical part of the LMS hash + * based signatures; in this case, incremental signing + */ +#include +#include "hss.h" +#include "common_defs.h" +#include "hss_verify_inc.h" +#include "lm_verify.h" +#include "lm_common.h" +#include "lm_ots.h" +#include "lm_ots_verify.h" +#include "hash.h" +#include "endian.h" +#include "hss_internal.h" +#include "hss_sign_inc.h" +#include "hss_derive.h" + +/* + * Start the process of creating an HSS signature incrementally. Parameters: + * ctx - The state we'll use to track the incremental signature + * working_key - the in-memory version of the in-memory private key + * update_private_key - function to call to update the master private key + * context - context pointer for above + * siganture - the buffer to hold the signature + * signature_len - the length of the buffer + * this_is_the_last_signature - if non-NULL, this will be set if this + * signature is the last for this private key + */ +bool hss_sign_init( + struct hss_sign_inc *ctx, + struct hss_working_key *w, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + unsigned char *signature, size_t signature_len, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 };; + if (!info) info = &temp_info; + + if (!ctx) { + info->error_code = hss_error_got_null; + return false; + } + ctx->status = hss_error_ctx_uninitialized; /* Until we hear otherwise, */ + /* we got a failure */ + + if (!w) { + info->error_code = hss_error_got_null; + return false; + } + if (w->status != hss_error_none) { + info->error_code = w->status; + return false; + } + + struct merkle_level *bottom = w->tree[ w->levels - 1 ]; + + unsigned char I[I_LEN]; + memcpy( I, bottom->I, I_LEN ); + + /* Compute the value of C we'll use */ + merkle_index_t q = bottom->current_index; + ctx->q = q; + int h = bottom->h; + ctx->h = h; + + struct seed_derive derive; + if (!hss_seed_derive_init( &derive, bottom->lm_type, bottom->lm_ots_type, + bottom->I, bottom->seed )) return false; + hss_seed_derive_set_q(&derive, q); + lm_ots_generate_randomizer( ctx->c, bottom->hash_size, &derive ); + hss_seed_derive_done(&derive); + + /* + * Ask the signature generation process to do everything *except* + * the bottom level OTS signature + */ + bool success = hss_generate_signature( w, + update_private_key, context, + NULL, 0, /* <--- we don't have the message yet */ + signature, signature_len, info ); + if (!success) { + /* On failure, hss_generate_signature fills in the failure reason */ + ctx->status = info->error_code; + hss_zeroize( &ctx->c, sizeof ctx->c ); /* People don't get to */ + /* learn what randomizer we would have used */ + return false; + } + + /* Now, initialize the context */ + hss_init_hash_context( h, &ctx->hash_ctx ); + { + unsigned char prefix[ MESG_PREFIX_MAXLEN ]; + memcpy( prefix + MESG_I, I, I_LEN ); + unsigned q_bin[4]; put_bigendian( q_bin, q, 4 ); + memcpy( prefix + MESG_Q, q_bin, 4 ); /* q */ + SET_D( prefix + MESG_D, D_MESG ); + int n = bottom->hash_size; + memcpy( prefix + MESG_C, ctx->c, n ); /* C */ + hss_update_hash_context(h, &ctx->hash_ctx, prefix, MESG_PREFIX_LEN(n) ); + } + + /* It succeeded so far... */ + ctx->status = hss_error_none; + return true; +} + +/* This adds another piece of the message to validate */ +bool hss_sign_update( + struct hss_sign_inc *ctx, + const void *message_segment, + size_t len_message_segment) { + if (!ctx || ctx->status != hss_error_none) return false; + + hss_update_hash_context(ctx->h, &ctx->hash_ctx, + message_segment, len_message_segment ); + + return true; +} + +/* We've added all the pieces of the messages, now do the validation */ +bool hss_sign_finalize( + struct hss_sign_inc *ctx, + const struct hss_working_key *working_key, + unsigned char *signature, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 }; + if (!info) info = &temp_info; + + if (!ctx) { + info->error_code = hss_error_got_null; + return false; + } + if (ctx->status != hss_error_none) { + info->error_code = ctx->status; + return false; + } + + /* Success or fail, we can't use the context any more */ + ctx->status = hss_error_ctx_already_used; + + int L = working_key->levels; + + /* Step through the signature, looking for the place to put the OTS */ + /* signature, and (while we're at it) recovering the I and seed values */ + const unsigned char *I = working_key->tree[0]->I; + const unsigned char *seed = working_key->tree[0]->seed; + /* Note: we alternate buffers during generation in case */ + /* hss_generate_child_seed_I_value doesn't allow new values to */ + /* overwrite old ones */ + unsigned char I_buff[2][I_LEN]; + unsigned char seed_buff[2][SEED_LEN]; + + /* Q: should we double check the various fixed fields of the signatures */ + /* (e.g. the number of signed keys, the parameter sets? */ + + signature += 4; + + int i; + for (i=0; i working_key->tree[i]->max_index) { + hss_zeroize( seed_buff, sizeof seed_buff ); + return 0; + } + if (!hss_generate_child_seed_I_value( seed_buff[i&1], I_buff[i&1], + seed, I, q, + working_key->tree[i]->lm_type, + working_key->tree[i]->lm_ots_type )) { + hss_zeroize( seed_buff, sizeof seed_buff ); + info->error_code = hss_error_internal; + return false; + } + + seed = seed_buff[i&1]; + I = I_buff[i&1]; + + /* Step to the end of this signed key */ + signature += lm_get_signature_len( working_key->tree[i]->lm_type, + working_key->tree[i]->lm_ots_type); + signature += lm_get_public_key_len(working_key->tree[i+1]->lm_type); + } + + /* Now, signature points to where the bottom LMS signature should go */ + /* It starts with the q value */ + put_bigendian( signature, ctx->q, 4 ); + signature += 4; + /* And then the LM-OTS signature */ + + /* Copy in the C value into the signature */ + memcpy( signature+4, ctx->c, 32 ); + + /* Generate the final hash */ + unsigned char hash[ MAX_HASH ]; + hss_finalize_hash_context( ctx->h, &ctx->hash_ctx, hash ); + + /* And the final OTS signature based on that hash */ + param_set_t lm_type = working_key->tree[i]->lm_type; + param_set_t ots_type = working_key->tree[i]->lm_ots_type; + struct seed_derive derive; + bool success = hss_seed_derive_init( &derive, lm_type, ots_type, + I, seed ); + if (success) { + hss_seed_derive_set_q( &derive, ctx->q ); + success = lm_ots_generate_signature( + ots_type, I, ctx->q, &derive, hash, 0, true, + signature, lm_ots_get_signature_len( ots_type )); + + hss_seed_derive_done( &derive ); + } + if (!success) { + info->error_code = hss_error_internal; + } + + hss_zeroize( seed_buff, sizeof seed_buff ); + return success; +} diff --git a/src/sig_stfl/lms/external/hss_sign_inc.h b/src/sig_stfl/lms/external/hss_sign_inc.h new file mode 100644 index 0000000000..426d271abd --- /dev/null +++ b/src/sig_stfl/lms/external/hss_sign_inc.h @@ -0,0 +1,81 @@ +#if !defined( HSS_SIGN_INC_H_ ) +#define HSS_SIGN_INC_H_ +#include +#include +#include "hash.h" +#include "common_defs.h" + +/* + * These are the functions to sign a message incrementally. + * That is, we assume that we don't have the entire message at + * once, instead, we have it in pieces (for example, the signature + * is of a multigigabyte file) + * + * Usage: + * struct hss_sign_inc ctx; + * bool success = hss_sign_init( &ctx, working_key, + * update_private_key, private_key_context, + * signature, signature_buffer_len, + * &lsat_signature ); + * hss_sign_update( &ctx, message_part_1, len_1 ); + * hss_sign_update( &ctx, message_part_2, len_2 ); + * hss_sign_update( &ctx, message_part_3, len_3 ); + * success = hss_sign_finalize( &ctx, working_key, signature ); + * if (success) printf( "We generated the signature\n" ); + * + * This is in its own include file because we need to import some + * 'not-generally-for-general-consumption' include files to make + * it work (as they're in the hss_sign_inc structure) + */ + +/* + * This is the context structure that holds the intermedate results of an + * in-process signature + * It's a application-visible structure for ease of use: the application can + * allocate it as an automatic, and if the application aborts in the middle of + * signing, it doesn't cause a memory leak + */ +struct hss_sign_inc { + enum hss_error_code status; /* Either hss_error_none if we're in */ + /* process, or the reason why we'd fail */ + + int h; /* The hash function */ + merkle_index_t q; /* The index of the bottom level signature */ + union hash_context hash_ctx; /* For the running hash we use */ + + unsigned char c[MAX_HASH]; /* The C value we used */ +}; + +struct hss_extra_info; + +/* Starts off the process of incrementally signing a message */ +/* If it detects a failure, this returns false */ +/* Handing the return code is optional; if this fails, the finalization */ +/* step will fail too */ +bool hss_sign_init( + struct hss_sign_inc *ctx, + struct hss_working_key *working_key, + bool (*update_private_key)(unsigned char *private_key, + size_t len_private_key, void *context), + void *context, + unsigned char *signature, size_t signature_len, + struct hss_extra_info *info); + +/* This adds another piece of the message to sign */ +/* Again, the result code is optional */ +bool hss_sign_update( + struct hss_sign_inc *ctx, + const void *message_segment, + size_t len_message_segment); + +/* This finalizes the signature generation */ +/* This returns true if the signature was generated properly */ +/* We ask the caller to pass in the working key again, we need to review */ +/* the private key (we don't want to place it in the context) */ +bool hss_sign_finalize( + struct hss_sign_inc *ctx, + const struct hss_working_key *working_key, + unsigned char *signature, + struct hss_extra_info *info); + +#endif /* HSS_SIGN_INC_H_ */ diff --git a/src/sig_stfl/lms/external/hss_thread.h b/src/sig_stfl/lms/external/hss_thread.h new file mode 100644 index 0000000000..fbf572ad4b --- /dev/null +++ b/src/sig_stfl/lms/external/hss_thread.h @@ -0,0 +1,135 @@ +#if !defined( HSS_THREAD_H_ ) +#define HSS_THREAD_H_ +/* + * This is our internal abstraction of multithreading; this allows the + * "application" (in this case, the HSS code) to issue multiple requests that + * can potentially run on different threads, in a way that doesn't depend on + * the actual threading capability of the OS. If we don't actually have + * multiple threads avaiable (either because the OS doesn't provide us with + * multiple threads, or we hit an internal error trying to generate new + * threads), this will just have the main thread do all the work (and hence + * the application doesn't have to worry its pretty little head about error + * handling, or whether we actually implement threads in the first place) + * + * This is designed to handle this sort of task: we have a series of + * computational problems to do; each can be done independently of the others, + * and each problem results in a fairly short answer. All the children do is + * computation; there's no I/O or any other interaction with the OS at all. + * + * The general paradigm is: + * - The main thread generates a thread collection (via the hss_thread_init + * call) + * - The main thread then issues a series of tasks (via the + * hss_thread_issue_work call). This may spawn off other threads (which + * will then call the function passed); alternatively, the main thread may + * call the function. + * - The main thread then waits for all the tasks to be done (via the + * hss_thread_done call) + * The function(s) passed to the hss_thread_issue_work call will be completed + * by the time hss_thread_done returns + */ +#include + +/* This is our abstract object that stands for a set of threads */ +struct thread_collection; + +/* + * This is called to initialize a set of threads, and returns the identifier. + * Note that this cannot fail; if it returns 0, it's not a failure; instead, + * it's a valid return (which essentially means we're running in nonthreaded + * mode) + * The integer passed is a recommendation on the number of threads + */ +struct thread_collection *hss_thread_init(int); + +/* + * This issues another work item to our collection of threads. At some point + * (between when hss_thread_issue_work is called and when hss_thread_done + * returns), we'll have function called, with a pointer to a copy of the detail + * structure. function may be called by this thread, or it may be called by a + * different one. + * + * The passed detail structure will not be referenced after this returns, and + * hence it is safe if the caller modifies (or frees) it afterwards. If the + * function isn't completed by the time hss_thread_issue_work returns, we'll + * squirrel away a copy of detail (which is why we ask the caller to + * pass size_detail_structure; so we know how much to copy) + * + * We suggest that the application issue the work orders in largest-to-smallest + * order. The ordering doesn't matter for correctness (the API makes no + * guarrantees about when the requests will be completed), however we suggest + * this for expected performance reasons. hss_thread_done will not return + * until all threads are done; what we want to avoid is scenarios where all but + * one of the threads are done, and that last thread is working on an expensive + * function; that would slow things down, and the entire point of this thread + * library is to speed things up. Assigning work items to threads optimally is + * an NP-hard problem, however the simple heuristic of packing 'largest first' + * works fairly well in practice (and is easy to implement). The thread library + * does try to make a best effort attempt to preserve the issue order (assuming + * no intermediate malloc or thread spawn issues; in those cases, the library + * prioritizes correctness over efficiency) + */ +void hss_thread_issue_work(struct thread_collection *col, + void (*function)(const void *detail, + struct thread_collection *col), + const void *detail, size_t size_detail_structure); + +/* + * This waits for all the work items we have issued (via hss_thread_issue_work) + * to be completed (that is, 'function' has returned, and cleans up the + * collection + * + * col must not be used after this; if it was malloc'ed, this will free it + */ +void hss_thread_done(struct thread_collection *col); + +/* + * This should be called before a thread writes to common data + * + * We do this because we sometimes have different threads write data to + * adjacent memory locations; if the compiler has the CPU do a + * read/modify/write to the entire word (or however the CPU has memory + * organized), this could cause a race condition. Forcing those writes to be + * serialized avoids the issue; such a race condition would actually be fairly + * unlikely, but would be a *really* difficult bug to track down if it did + * occur, so it makes sense to go the extra mile to avoid the possibility + * + * Doing this locking also means that the working thread can safely do things + * such as incrementing a global [1] counter to report its results, should + * that be appropriate + * + * We don't bother doing this if we're writing into a malloc'ed region, *if* + * we're the only thread that will be writing into that specific region; we + * assume that the malloc infrastructure will separate distinct malloc'ed + * regions enough to avoid such race conditions + * + * [1] actually, automatic to the main thread; there are no literal globals + * in this package, apart from the verbose debugging flag + */ +void hss_thread_before_write(struct thread_collection *collect); + +/* + * This should be called after a thread writes to common data; it releases + * the lock + */ +void hss_thread_after_write(struct thread_collection *collect); + +/* + * This gives the application guidance for how many worker threads we have + * available, that is, how many work items we can expect to run at once + * + * This is used to decide the level of granularity we need; we we have only 2 + * cores, there's no point is splitting the job up to 50 separate requests; + * however if there are 100 cores, we want (if possible) to do at least 100 + * + * The issue with having not enough requests is that we will have idle threads + * (which could potentially do useful work, if we are able to divide the work + * further). The issue with having too many requests is that the requests use + * up some memory, and we'd prefer not to use up too much memory (we don't + * fail on malloc failure, however we do drop back to a single threaded model) + * + * The value passed is the value we'll pass to hss_thread_init + */ +unsigned hss_thread_num_tracks(int num_threads); + +#endif /* HSS_THREAD_H_ */ diff --git a/src/sig_stfl/lms/external/hss_thread_pthread.c b/src/sig_stfl/lms/external/hss_thread_pthread.c new file mode 100644 index 0000000000..b5f64d3764 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_thread_pthread.c @@ -0,0 +1,298 @@ +#include "hss_thread.h" + +#include +#include + +/* + * This is an implementation of our threaded abstraction using the + * POSIX pthread API + * + * C11 has a similar (but not precisely identical) API to the one that POSIX + * defines (at least for what we do; all we need is thread create/join and + * mutex's, which *any* thread library should provide). I'd code up the + * support for that API as well (using the same base logic, with typedef's and + * helper inlines to isolate the differences), however I don't have a C11 + * implementation handy to test it + */ + +#define MAX_THREAD 16 /* Number try to create more than 16 threads, no */ + /* matter what the application tries to tell us */ +#define DEFAULT_THREAD 16 /* The number of threads to run if the */ + /* application doesn't tell us otherwise (e.g. */ + /* passes in 0) */ + +#define MIN_DETAIL 16 /* So the alignment kludge we do doesn't waste space */ + +/* The information we track about a thread we may have launched */ +struct thread_state { + pthread_t thread_id; + enum { never_was, alive, dead } state; +}; + +struct work_item { + struct work_item *link; /* They're in a linked list */ + + void (*function)(const void *detail, /* Function to call */ + struct thread_collection *col); + + /* These two items are used to pass the thread state to the thread */ + /* if this is the first work item for the thread to process */ + struct thread_collection *col; /* The parent thread_collection */ + struct thread_state *state; /* The pointer into the thread collection */ + /* state for the state of this thread */ + + /* The detail structure that we pass to the function */ + /* We'll malloc enough space to hold the entire structure */ + union { /* union here so that the detail array is */ + void *align1; /* correctly aligned for various datatypes */ + long long align2; + void (*align3)(void); + unsigned char detail[MIN_DETAIL]; + } x; +}; + +struct thread_collection { + pthread_mutex_t lock; /* Must be locked before this structure is */ + /* accessed if there might be a thread */ + pthread_mutex_t write_lock; /* Must be locked before common user data is */ + /* written */ + + unsigned num_thread; + unsigned current_ptr; /* There two are here to avoid O(N) table */ + unsigned num_alive; /* scanning in the most common scenarios */ + + /* Information about the worker threads we may have created */ + struct thread_state threads[MAX_THREAD]; + + /* + * Queue (FIFO) of work items submitted, and which can't be processed + * immedately. We do a FIFO, rather than a stack, so that we perform + * the requests in the order they were issued (which isn't something + * the interface guarantees; however it doesn't interfere with the + * request ordering we ask applications to make) + */ + struct work_item *top_work_queue; + struct work_item *end_work_queue; +}; + +/* + * Allocate a thread control structure + */ +struct thread_collection *hss_thread_init(int num_thread) { + if (num_thread == 0) num_thread = DEFAULT_THREAD; + if (num_thread <= 1) return 0; /* Not an error: an indication to run */ + /* single threaded */ + if (num_thread > MAX_THREAD) num_thread = MAX_THREAD; + + struct thread_collection *col = malloc( sizeof *col ); + if (!col) return 0; /* On malloc failure, run single threaded */ + + col->num_thread = num_thread; + + if (0 != pthread_mutex_init( &col->lock, 0 )) { + free(col); // IGNORE free-check + return 0; + } + + if (0 != pthread_mutex_init( &col->write_lock, 0 )) { + pthread_mutex_destroy( &col->lock ); + free(col); // IGNORE free-check + return 0; + } + + col->current_ptr = 0; + col->num_alive = 0; + int i; + for (i=0; ithreads[i].state = never_was; + } + col->top_work_queue = 0; + col->end_work_queue = 0; + + return col; +} + +/* + * This is the base routine that a worker thread runs + */ +static void *worker_thread( void *arg ) { + struct work_item *w = arg; /* The initial work item */ + struct thread_collection *col = w->col; + struct thread_state *state = w->state; + + for (;;) { + /* Perform the work item in front of us */ + (w->function)(w->x.detail, col); + + /* Ok, we did that */ + free(w); // IGNORE free-check + + /* Check if there's anything else to do */ + pthread_mutex_lock( &col->lock ); + + w = col->top_work_queue; + if (w) { + /* More work; pull it off the queue */ + col->top_work_queue = w->link; + if (w == col->end_work_queue) col->end_work_queue = 0; + + /* And go handle it */ + pthread_mutex_unlock( &col->lock ); + continue; + } + + /* No more work for us to do; post our obituary */ + state->state = dead; + col->num_alive -= 1; + pthread_mutex_unlock( &col->lock ); + + /* And that's all folks */ + return 0; + } +} + +/* + * This adds function/details to the list of things that need to be done + * It either creates a thread to do it, or (if we're maxed out) add it to + * our honey-do list (or, as last resort, just does it itself) + */ +void hss_thread_issue_work(struct thread_collection *col, + void (*function)(const void *detail, + struct thread_collection *col), + const void *detail, size_t size_detail_structure) { + + /* If we're running in single-threaded mode */ + if (!col) { + function( detail, col ); + return; + } + + /* Allocate a work structure to hold this request */ + size_t extra_space; + if (size_detail_structure < MIN_DETAIL) extra_space = 0; + else extra_space = size_detail_structure - MIN_DETAIL; + struct work_item *w = malloc(sizeof *w + extra_space); + + if (!w) { + /* Can't allocate the work structure; fall back to single-threaded */ + function( detail, col ); + return; + } + w->col = col; + w->function = function; + memcpy( w->x.detail, detail, size_detail_structure ); + + unsigned num_thread = col->num_thread; + + pthread_mutex_lock( &col->lock ); + + /* Check if we can spawn a new thread */ + if (col->num_alive < num_thread) { + /* There's supposed to be room for another */ + /* Look for the empty slot */ + unsigned i, j; + j = col->current_ptr; /* Do round-robin (so we don't bang on */ + /* slot 0 whenever we try to start a thread) */ + for (i=0; ithreads[j]; + switch (p->state) { + case alive: continue; /* This one's busy */ + case dead: + { + /* This one just died; grab its status (not that we care, */ + /* however that'll tell the thread library it can clean up) */ + pthread_t thread_id = p->thread_id; + void *status; /* Ignored, but we need to place thread */ + /* status somewhere */ + pthread_mutex_unlock( &col->lock ); + pthread_join( thread_id, &status ); + pthread_mutex_lock( &col->lock ); + p->state = never_was; + } + /* FALL THROUGH */ + case never_was: + /* Now, we can spawn a new thread */ + w->state = p; + if (0 != pthread_create( &p->thread_id, + NULL, worker_thread, w )) { + /* Hmmm, couldn't spawn it; fall back */ + default: /* On error condition */ + pthread_mutex_unlock( &col->lock ); + free(w); // IGNORE free-check + function( detail, col ); + return; + } + + /* We've kicked off the thread */ + p->state = alive; + col->num_alive += 1; + /* For the next request, start scanning at the next */ + /* thread object */ + col->current_ptr = (j+1) % num_thread; + pthread_mutex_unlock( &col->lock ); + return; + } + } + col->num_alive = num_thread; /* Hmmmm, everything was alive??? */ + } + + /* We can't create any more threads; enqueue this (and someone will get */ + /* to it) */ + w->link = 0; + if (col->end_work_queue) { + col->end_work_queue->link = w; + } + col->end_work_queue = w; + if (!col->top_work_queue) col->top_work_queue = w; + + pthread_mutex_unlock( &col->lock ); +} + +/* + * This will wait for all the work items we'e issued to complete + */ +void hss_thread_done(struct thread_collection *col) { + if (!col) return; + + unsigned i; + pthread_mutex_lock( &col->lock ); + for (i=0; inum_thread; i++) { + /* + * Wait for each thread that we have spawned. + * We're the only one that will spawn them, and so we don't have to + * worry about any new ones appearing while we scan through the list + */ + if (col->threads[i].state != never_was) { + void *status; + pthread_t thread_id = col->threads[i].thread_id; + pthread_mutex_unlock( &col->lock ); + pthread_join( thread_id, &status ); + pthread_mutex_lock( &col->lock ); + } + } + pthread_mutex_unlock( &col->lock ); + + /* Ok, all the threads have finished; tear things down */ + + pthread_mutex_destroy( &col->lock ); + pthread_mutex_destroy( &col->write_lock ); + free(col); // IGNORE free-check +} + +void hss_thread_before_write(struct thread_collection *col) { + if (!col) return; + pthread_mutex_lock( &col->write_lock ); +} + +void hss_thread_after_write(struct thread_collection *col) { + if (!col) return; + pthread_mutex_unlock( &col->write_lock ); +} + + +unsigned hss_thread_num_tracks(int num_thread) { + if (num_thread == 0) num_thread = DEFAULT_THREAD; + if (num_thread <= 1) return 1; + if (num_thread >= MAX_THREAD) return MAX_THREAD; + return num_thread; +} diff --git a/src/sig_stfl/lms/external/hss_thread_single.c b/src/sig_stfl/lms/external/hss_thread_single.c new file mode 100644 index 0000000000..d844385293 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_thread_single.c @@ -0,0 +1,63 @@ +#include "hss_thread.h" +#include "config.h" + +/* + * This is a trivial implementation of our threading abstraction. + * It's used if we don't have any threading support + */ + +/* + * This requests that an object that tracks the threads be created. We have + * no threads, hence we don't need such an object + */ +struct thread_collection *hss_thread_init(int num_thread) { + LMS_UNUSED(num_thread); + return 0; +} + +/* + * This asks that function be called sometime between now, and when + * hss_thread_done is called. We just go ahead, and do it now + */ +void hss_thread_issue_work(struct thread_collection *collect, + void (*function)(const void *detail, + struct thread_collection *col), + const void *detail, size_t size_detail_structure) { + LMS_UNUSED(size_detail_structure); + /* If we were asked to make sure something is done, just do it */ + function( detail, collect ); +} + +/* + * This asks for all the work requests we've issued to completed, and that + * the collection object be freed. We did all the work when it was + * requested, and we never allocated a collection object in the first place + */ +void hss_thread_done(struct thread_collection *collect) { + LMS_UNUSED(collect); +} + +/* + * A thread calls this when it will write into a common area (so that no + * other thread will access it at the same time). No threads means that + * there is no need to lock + */ +void hss_thread_before_write(struct thread_collection *collect) { + LMS_UNUSED(collect); +} + +/* + * This releases the above lock + */ +void hss_thread_after_write(struct thread_collection *collect) { + LMS_UNUSED(collect); +} + +/* + * This tells the application that we really have only one thread + * (the main one) + */ +unsigned hss_thread_num_tracks(int num_thread) { + LMS_UNUSED(num_thread); + return 1; +} diff --git a/src/sig_stfl/lms/external/hss_verify.c b/src/sig_stfl/lms/external/hss_verify.c new file mode 100644 index 0000000000..089bdbd1ef --- /dev/null +++ b/src/sig_stfl/lms/external/hss_verify.c @@ -0,0 +1,196 @@ +/* + * This is the code that implements the hierarchical part of the LMS hash + * based signatures + */ +#include +#include "common_defs.h" +#include "hss_verify.h" +#include "lm_verify.h" +#include "lm_common.h" +#include "lm_ots_verify.h" +#include "hash.h" +#include "endian.h" +#include "hss_thread.h" +#include "hss_internal.h" +#include "hss.h" + +/* The HSS public key consists of: */ +/* Number of levels (1-8) (4 bytes) */ +/* The top level LM public key */ + +/* The HSS signature consists of: */ +/* A word giving the number of levels - 1 == L-1 */ +/* L-1 iterations of (i = 1..L-1): */ +/* - LMS Signature of public key i (signed by the pub key of level i-1) */ +/* - LMS Public key (of level i) */ +/* - LMS Signature of the message, signed by the bottomost pub key */ + +/* This is the routine that runs on a thread to validate an LMS signature */ +void validate_internal_sig(const void *data, + struct thread_collection *col) { + const struct verify_detail *d = data; + + bool success = lm_validate_signature(d->public_key, + d->message, d->message_len, false, + d->signature, d->signature_len); + + if (!success) { + /* Drat, it failed; call the failure in */ + hss_thread_before_write(col); + *d->got_error = hss_error_bad_signature; + hss_thread_after_write(col); + } +} + +/* + * Validate an HSS signature, using a public key. Parameters: + * public_key - pointer to the public key + * message - the mmessage that was supposedly signed + * message_len - the size of the message + * siganture - the signature we're checking + * signature_len - the length of the signature + * + * This returns true if everything checks out and the signature verifies + * false on error (whether the error is because the signature didn't verify, + * or we hit some sort of error on the way) + */ +bool hss_validate_signature( + const unsigned char *public_key, + const void *message, size_t message_len, + const unsigned char *signature, size_t signature_len, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 }; + if (!info) info = &temp_info; + unsigned i; + + /* Get the number of levels the signature claims */ + if (signature_len < 4) { + info->error_code = hss_error_bad_signature; + return false; + } + uint_fast32_t levels = get_bigendian( signature, 4 ) + 1; + /* +1 because what's in the signature is levels-1 */ + signature += 4; signature_len -= 4; + if (levels < MIN_HSS_LEVELS || levels > MAX_HSS_LEVELS || + levels != get_bigendian( public_key, 4 )) { + info->error_code = hss_error_bad_signature; + return false; + } + + /* Compare that to what the public key says */ + uint_fast32_t pub_levels = get_bigendian( public_key, 4 ); + if (levels != pub_levels) { + /* Signature and public key don't agree */ + info->error_code = hss_error_bad_signature; + return false; + } + /* We'll use the LMS public key embedded in the HSS public key as the */ + /* key to use to validate the top level signature */ + public_key += 4; + + struct thread_collection *col = hss_thread_init(info->num_threads); + enum hss_error_code got_error = hss_error_none; + struct verify_detail detail; + detail.got_error = &got_error; + + /* Parse through the signature, kicking off the tasks to validate */ + /* individual LMS signatures within it as we go */ + for (i=0; i + * where: + * - Signature A is the LMS signature of Public Key B + * - Public Key B is the message we're verifying (and will be + * interpreted as a public key in the next iteration) + * public_key points to Public Key A, which is the public key that + * we use to verify Signature A + */ + + /* Get the length of Signature A */ + param_set_t lm_type = get_bigendian( public_key, 4 ); + param_set_t lm_ots_type = get_bigendian( public_key+4, 4 ); + unsigned l_siglen = lm_get_signature_len(lm_type, lm_ots_type); + if (l_siglen == 0 || l_siglen > signature_len) { + info->error_code = hss_error_bad_signature; + goto failed; + } + + /* Retain a pointer to Signature A, and advance the current */ + /* pointer to Public Key B */ + const unsigned char *l_sig = signature; + signature += l_siglen; signature_len -= l_siglen; + + /* The next thing is the next level public key (Public Key B) */ + /* which we need to validate) */ + if (signature_len < 4) { + info->error_code = hss_error_bad_signature; + goto failed; + } + /* + * Get how long Public Key B would be, assuming it is a valid + * public key. If it's not a valid public key (that is, if + * someone other than the valid signer modified it), then + * Signature A will not validate, and so we'll catch that + */ + lm_type = get_bigendian( signature, 4 ); + unsigned l_pubkeylen = lm_get_public_key_len(lm_type); + if (l_pubkeylen == 0 || l_pubkeylen > signature_len) { + info->error_code = hss_error_bad_signature; + goto failed; + } + + /* Retain a pointer to Public Key B, and advance the current */ + /* pointer past it (to the data the next iteration cares about) */ + const unsigned char *l_pubkey = signature; + signature += l_pubkeylen; signature_len -= l_pubkeylen; + + /* Now, schedule the validation of Signature A */ + detail.public_key = public_key; /* Public key A */ + detail.message = l_pubkey; /* Public key B, that is, */ + /* the message to validate */ + detail.message_len = l_pubkeylen; + detail.signature = l_sig; /* Signature A */ + detail.signature_len = l_siglen; + hss_thread_issue_work( col, validate_internal_sig, + &detail, sizeof detail ); + + /* We validated this level's public key (or, at least, scheduled */ + /* it, if it turns out not to validate, we'll catch it below) */ + /* Use the current Public Key B as the next level's Public Key A */ + public_key = l_pubkey; + } + + /* + * We're at the bottom level; now, the current position in the signature + * looks like (or, rather, is *supposed to look like*) this: + * + * where: + * - Signature A is the bottom signature, which signs the actual + * message + * public_key points to the bottom level public key, which is used to + * validate the signature + * + * Just go ahead and schedule the validation + */ + detail.public_key = public_key; /* Public key to use */ + detail.message = message; /* The user's message that needs */ + detail.message_len = message_len; /* validation */ + detail.signature = signature; /* Bottom level LMS signature */ + detail.signature_len = signature_len; + hss_thread_issue_work( col, validate_internal_sig, + &detail, sizeof detail ); + + /* Wait for all the threads to complete */ + hss_thread_done(col); + + /* It succeeded if none of the threads reported an error */ + if (got_error == hss_error_none) return true; + info->error_code = got_error; + return false; + +failed: /* If we get an intermediate failure */ + hss_thread_done(col); + return false; +} diff --git a/src/sig_stfl/lms/external/hss_verify.h b/src/sig_stfl/lms/external/hss_verify.h new file mode 100644 index 0000000000..7a29deb275 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_verify.h @@ -0,0 +1,23 @@ +#if !defined( HSS_VERIFY_H_ ) +#define HSS_VERIFY_H_ + +#include + +struct hss_extra_info; +/* + * This is the function to validate a signature; return true if it validates, + * false if it doesn't + * + * public_key is the pointer to the public key + * + * message, message_len is the message to validate + * + * signature, signature_len is the signature to validate + */ +bool hss_validate_signature( + const unsigned char *public_key, + const void *message, size_t message_len, + const unsigned char *signature, size_t signature_len, + struct hss_extra_info *info); + +#endif /* HSS_VERIFY_H_ */ diff --git a/src/sig_stfl/lms/external/hss_verify_inc.c b/src/sig_stfl/lms/external/hss_verify_inc.c new file mode 100644 index 0000000000..451082f8de --- /dev/null +++ b/src/sig_stfl/lms/external/hss_verify_inc.c @@ -0,0 +1,203 @@ +/* + * This is the code that implements the hierarchical part of the LMS hash + * based signatures; in this case, incremental verification + */ +#include +#include "common_defs.h" +#include "hss_verify_inc.h" +#include "lm_verify.h" +#include "lm_common.h" +#include "lm_ots_verify.h" +#include "hash.h" +#include "endian.h" +#include "hss_thread.h" +#include "hss_internal.h" +#include "lm_ots_common.h" +#include "hss.h" + +/* + * Start the process of validating an HSS signature incrementally. Parameters: + * ctx - The state we'll use to track the incremental validation + * public_key - pointer to the public key + * siganture - the signature we're checking + * signature_len - the length of the signature + */ +bool hss_validate_signature_init( + struct hss_validate_inc *ctx, + const unsigned char *public_key, + const unsigned char *signature, size_t signature_len, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 }; + if (!info) info = &temp_info; + unsigned i; + if (!ctx) { + info->error_code = hss_error_got_null; + return false; + } + ctx->status = hss_error_ctx_uninitialized; /* Until we hear otherwise, */ + /* we got a failure */ + + const unsigned char *orig_signature = signature; +; + /* Get the number of levels the signature claims */ + if (signature_len < 4) { + ctx->status = info->error_code = hss_error_bad_signature; + return false; + } + uint_fast32_t levels = get_bigendian( signature, 4 ) + 1; + /* +1 because what's in the signature is levels-1 */ + signature += 4; signature_len -= 4; + if (levels < MIN_HSS_LEVELS || levels > MAX_HSS_LEVELS || + levels != get_bigendian( public_key, 4 )) { + ctx->status = info->error_code = hss_error_bad_signature; + return false; + } + uint_fast32_t pub_levels = get_bigendian( public_key, 4 ); + if (levels != pub_levels) { + /* Signature and public key don't agree */ + ctx->status = info->error_code = hss_error_bad_signature; + return false; + } + public_key += 4; + + /* Validate the upper levels of the signature */ + struct thread_collection *col = NULL; + if (levels > 1) { + col = hss_thread_init(info->num_threads); + enum hss_error_code got_error = hss_error_none; + struct verify_detail detail; + detail.got_error = &got_error; + + /* Scan through the signature, kicking off the tasks to validate it */ + /* as we go. Note that we don't validate the bottom level yet */ + for (i=0; i signature_len) goto failed; + const unsigned char *l_sig = signature; + signature += l_siglen; signature_len -= l_siglen; + + /* The next thing is the next level public key (which we need */ + /* to validate) */ + if (signature_len < 4) goto failed; + lm_type = get_bigendian( signature, 4 ); + unsigned l_pubkeylen = lm_get_public_key_len(lm_type); + if (l_pubkeylen == 0 || l_pubkeylen > signature_len) goto failed; + const unsigned char *l_pubkey = signature; + signature += l_pubkeylen; signature_len -= l_pubkeylen; + + /* Validate the signature of this level's public key */ + detail.public_key = public_key; + detail.message = l_pubkey; + detail.message_len = l_pubkeylen; + detail.signature = l_sig; + detail.signature_len = l_siglen; + hss_thread_issue_work( col, validate_internal_sig, + &detail, sizeof detail ); + + /* We validated this level's public key (or, at least, */ + /* scheduled it, if it turns out not to validate, we'll catch */ + /* it below), use it to validate the next level */ + public_key = l_pubkey; + } + + /* Wait for all the threads to complete */ + hss_thread_done(col); + col = NULL; + + if (got_error != hss_error_none) { + ctx->status = info->error_code = got_error; + return false; + } + } + + ctx->signature_offset = signature - orig_signature; + ctx->signature_len = signature_len; + + /* We have the public key in front of us; stash a copy */ + /* Right now, we have a fixed length public key */ + /* If that changes, we'll need to investigate the parmaeter set */ + memcpy( ctx->final_public_key, public_key, 8 + I_LEN + MAX_HASH ); + + /* Now, initialize the context */ + param_set_t ots_type = get_bigendian( public_key+4, 4 ); + + unsigned h, n; + if (!lm_ots_look_up_parameter_set(ots_type, &h, &n, NULL, NULL, NULL)) { + /* Because we're checking in parallel, this may be caused by */ + /* a bad signature */ + ctx->status = info->error_code = hss_error_bad_signature; + return false; + } + ctx->h = h; + hss_init_hash_context( h, &ctx->hash_ctx ); + { + unsigned char prefix[ MESG_PREFIX_MAXLEN ]; + memcpy( prefix + MESG_I, ctx->final_public_key+8, I_LEN ); + memcpy( prefix + MESG_Q, signature, 4 ); /* q */ + SET_D( prefix + MESG_D, D_MESG ); + memcpy( prefix + MESG_C, signature+8, n ); /* C */ + hss_update_hash_context(h, &ctx->hash_ctx, prefix, MESG_PREFIX_LEN(n) ); + } + + /* It succeeded so far... */ + ctx->status = hss_error_none; + return true; + +failed: /* If we get an intermediate failure */ + if (col) hss_thread_done(col); + ctx->status = info->error_code = hss_error_bad_signature; + return false; +} + +/* This adds another piece of the message to validate */ +bool hss_validate_signature_update( + struct hss_validate_inc *ctx, + const void *message_segment, + size_t len_message_segment) { + if (!ctx || ctx->status != hss_error_none) return false; + + hss_update_hash_context(ctx->h, &ctx->hash_ctx, + message_segment, len_message_segment ); + + return true; +} + +/* We've added all the pieces of the messages, now do the validation */ +bool hss_validate_signature_finalize( + struct hss_validate_inc *ctx, + const unsigned char *signature, + struct hss_extra_info *info) { + struct hss_extra_info temp_info = { 0 }; + if (!info) info = &temp_info; + + if (!ctx) { + info->error_code = hss_error_got_null; + return false; + } + if (ctx->status != hss_error_none) { + info->error_code = ctx->status; + return false; + } + + /* Success or fail, we can't use the context any more */ + ctx->status = hss_error_ctx_already_used; + + /* Generate the final hash */ + unsigned char hash[ MAX_HASH ]; + unsigned h = ctx->h; + hss_finalize_hash_context( h, &ctx->hash_ctx, hash ); + + /* It passes iff the final signature validates */ + if (lm_validate_signature( + ctx->final_public_key, + hash, sizeof hash, true, + signature + ctx->signature_offset, ctx->signature_len)) { + return true; + } + + info->error_code = hss_error_bad_signature; + return false; +} diff --git a/src/sig_stfl/lms/external/hss_verify_inc.h b/src/sig_stfl/lms/external/hss_verify_inc.h new file mode 100644 index 0000000000..147308b23c --- /dev/null +++ b/src/sig_stfl/lms/external/hss_verify_inc.h @@ -0,0 +1,82 @@ +#if !defined( HSS_VERIFY_INC_H_ ) +#define HSS_VERIFY_INC_H_ +#include +#include +#include "hash.h" +#include "common_defs.h" +#include "hss.h" + +/* + * These are the functions to validate a signature incrementally. + * That is, we assume that we don't have the entire message at + * once, instead, we have it in pieces (for example, the signature + * is of a multigigabyte file) + * + * Usage: + * struct hss_validate_inc ctx; + * bool success = hss_validate_init( &ctx, public_key, signature ); + * hss_validate_update( &ctx, message_part_1, len_1 ); + * hss_validate_update( &ctx, message_part_2, len_2 ); + * hss_validate_update( &ctx, message_part_3, len_3 ); + * success = hss_validate_finalize( &ctx, signature ); + * if (success) printf( "The signature validated\n" ); + * + * This is in its own include file because we need to import some + * 'not-generally-for-general-consumption' include files to make + * it work (as they're in the hss_validate_inc structure) + */ + +/* + * This is the context structure that holds the intermedate results of an + * in-process validation + * It's a application-visible structure for ease of use: the application can + * allocate it as an automatic, and if the application aborts in the middle of + * the validation, it doesn't cause a memory leak + */ +struct hss_validate_inc { + enum hss_error_code status; /* Either hss_error_none if we're in */ + /* process, or the reason why we'd fail */ + size_t signature_offset; /* Offset of the final signature within the */ + /* HSS signature */ + size_t signature_len; /* Length of the final signature */ + + unsigned h; /* Hash function used */ + + /* The final public key. We need this at finalization time, */ + /* however they might not be in the signature (L=1 case) */ + unsigned char final_public_key[8 + I_LEN + MAX_HASH]; + + union hash_context hash_ctx; /* For the running hash we use */ +}; + +struct hss_extra_info; + +/* Starts off the process of incrementally validating a signature */ +/* If it detects a failure, this returns false */ +/* Handing the return code is optional; if this fails, the finalization */ +/* step will fail too */ +bool hss_validate_signature_init( + struct hss_validate_inc *ctx, + const unsigned char *public_key, + const unsigned char *signature, size_t signature_len, + struct hss_extra_info *info); + +/* This adds another piece of the message to validate */ +/* Again, the result code is optional */ +bool hss_validate_signature_update( + struct hss_validate_inc *ctx, + const void *message_segment, + size_t len_message_segment); + +/* This finalizes the signature validation */ +/* This returns true if the signature validates (and we didn't detect any */ +/* intermediate failures) */ +/* We ask the caller to pass in the signature again, because we'd prefer */ +/* not having to place the final LMS signature in the ctx structure; that'd */ +/* make it larger than we'd like */ +bool hss_validate_signature_finalize( + struct hss_validate_inc *ctx, + const unsigned char *signature, + struct hss_extra_info *info); + +#endif /* HSS_VERIFY_INC_H_ */ diff --git a/src/sig_stfl/lms/external/hss_zeroize.c b/src/sig_stfl/lms/external/hss_zeroize.c new file mode 100644 index 0000000000..f2bd334903 --- /dev/null +++ b/src/sig_stfl/lms/external/hss_zeroize.c @@ -0,0 +1,49 @@ +#include "hss_zeroize.h" +#include + +/* + * This is a function to zeroize a section of memory + * + * We do this because when we release a section of memory (either because it's + * a local variable going out of scope, or we free it), it's possible that + * the memory will retain its contents after another allocation (possibly + * done by someone outside this module). So, to avoid this potential security + * issue, we scrub the memory (at least, the parts that have data that would + * make it possible to forge if it leaked) before releasing it. + * + * Now, there's a bunch of things we don't mind being exposed (e.g. internal + * node values of Merkle trees), so we don't use this everywhere; only where + * it is needed + * + * We use this, rather than having routines simply call memset, to avoid + * potential problems with overenthusiastic optimizers. Generally, we zeroize + * an area immediately before it goes out of scope or we free it, however an + * optimizer might conclude "they're about to release the memory, there's no + * need to write to it first" + * + * For similar reasons, this function is in its own source file (so that a + * compiler optimizer who doesn't examine more than one source at a time can't + * eliminate it). If we are worried about optimizers who can be even more + * enthusiastic, there are other things we can try; however we're not going to + * worry about that right now + */ +void hss_zeroize( void *area, size_t len ) { +#if defined( __STDC_LIB_EXT1__ ) + /* + * C11 defines a version of memset that does precisely what we want, and is + * guaranteed not to be molested by the optimizer + * Note that the first 'len' is supposed to be the length of the buffer + * we're cleaning and the second 'len' is the area to clear. Since we + * expect the caller to ask us to clear the entire area (and hence gives + * us only one length), we use the same for both + */ + memset_s( area, len, 0, len ); +#else + /* + * Fallback code for pre-C11 versions + */ + volatile unsigned char *p = area; + + while (len--) *p++ = 0; +#endif +} diff --git a/src/sig_stfl/lms/external/hss_zeroize.h b/src/sig_stfl/lms/external/hss_zeroize.h new file mode 100644 index 0000000000..702d91137b --- /dev/null +++ b/src/sig_stfl/lms/external/hss_zeroize.h @@ -0,0 +1,10 @@ +#if !defined( HSS_ZEROIZE_H_ ) +#define HSS_ZEROIZE_H_ + +#include + +/* Zeroize an area, that is, scrub it from holding any potentially secret */ +/* information */ +void hss_zeroize( void *area, size_t len ); + +#endif /* HSS_ZEROIZE_H_ */ diff --git a/src/sig_stfl/lms/external/lm_common.c b/src/sig_stfl/lms/external/lm_common.c new file mode 100644 index 0000000000..e3eb56f0f0 --- /dev/null +++ b/src/sig_stfl/lms/external/lm_common.c @@ -0,0 +1,79 @@ +/* + * This is the code that implements the tree part of the LMS hash + * based signatures + */ +#include +#include "lm_common.h" +#include "hash.h" +#include "common_defs.h" +#include "lm_ots_common.h" + +/* + * Internal utility to convert encoded parameter sets into what they represent + */ +bool lm_look_up_parameter_set(param_set_t parameter_set, + unsigned *h, unsigned *n, unsigned *height) { + unsigned v_h, v_n, v_height; + switch (parameter_set) { + case LMS_SHA256_N32_H5: + v_h = HASH_SHA256; v_n = 32; v_height = 5; break; + case LMS_SHA256_N32_H10: + v_h = HASH_SHA256; v_n = 32; v_height = 10; break; + case LMS_SHA256_N32_H15: + v_h = HASH_SHA256; v_n = 32; v_height = 15; break; + case LMS_SHA256_N32_H20: + v_h = HASH_SHA256; v_n = 32; v_height = 20; break; + case LMS_SHA256_N32_H25: + v_h = HASH_SHA256; v_n = 32; v_height = 25; break; + default: return false; + } + + if (h) *h = v_h; + if (n) *n = v_n; + if (height) *height = v_height; + + return true; +} + +/* The LM public key consists of: */ +#define LM_PUB_PARM_SET 0 /* The parameter set (4 bytes) */ +#define LM_PUB_OTS_PARM_SET 4 /* The OTS parameter set (4 bytes) */ +#define LM_PUB_I 8 /* Our nonce (I) value (16 bytes) */ +/* The root value comes here */ + +/* + * XDR requires us to pad the I value out to a multiple of 4 + * This computes how long the field will be after padding + * That is, it rounds len_I up to the next multiple of 4 + */ +#define padded_length(len_I) (((len_I) + 3) & ~3) + +/* The public key just consists of the parameter sets, plus I, plus root hash */ +size_t lm_get_public_key_len(param_set_t lm_type) { + unsigned n; + if (!lm_look_up_parameter_set( lm_type, 0, &n, 0)) + return 0; + + return LM_PUB_I + padded_length(I_LEN) + n; +} + +/* + * The amount of space we use for signature + */ +size_t lm_get_signature_len(param_set_t lm_type, + param_set_t lm_ots_type) { + unsigned n, height; + if (!lm_look_up_parameter_set( lm_type, 0, &n, &height )) + return 0; + + int ots_sig_len = lm_ots_get_signature_len(lm_ots_type); + if (ots_sig_len == 0) + return 0; + + /* + * The LM signature consists of the type code, the diversification factor, + * the LM-OTS signature (which includes the OTS type code), and the + * authentication path (which is an array of height hashes) + */ + return 4 + 4 + ots_sig_len + n*height; +} diff --git a/src/sig_stfl/lms/external/lm_common.h b/src/sig_stfl/lms/external/lm_common.h new file mode 100644 index 0000000000..027eda2214 --- /dev/null +++ b/src/sig_stfl/lms/external/lm_common.h @@ -0,0 +1,20 @@ +#if !defined(LM_COMMON_H_) +#define LM_COMMON_H_ + +#include +#include "common_defs.h" + +size_t lm_get_public_key_len(param_set_t lm_type); +size_t lm_get_signature_len(param_set_t lm_type, + param_set_t lm_ots_type); + +bool lm_look_up_parameter_set(param_set_t parameter_set, + unsigned *h, unsigned *n, unsigned *height); + +/* The format of an LM public key; it consists of: */ +#define LM_PUB_PARM_SET 0 /* The parameter set (4 bytes) */ +#define LM_PUB_OTS_PARM_SET 4 /* The OTS parameter set (4 bytes) */ +#define LM_PUB_I 8 /* Our nonce (I) value (32 or 64 bytes) */ +/* The root value comes here */ + +#endif /* LM_COMMON_H_ */ diff --git a/src/sig_stfl/lms/external/lm_ots.h b/src/sig_stfl/lms/external/lm_ots.h new file mode 100644 index 0000000000..4fcf690342 --- /dev/null +++ b/src/sig_stfl/lms/external/lm_ots.h @@ -0,0 +1,64 @@ +#if !defined( LM_OTS_H_ ) +#define LM_OTS_H_ + +#include "common_defs.h" +#include + +/* + * These are routines that implement the OTS signature scheme. These routines + * never actually form a "private key"; instead, the signer passes the 'seed' + * (and public data) to form the public key and to do the actual signature. + * We do this because the LM routines are actually better suited for doing + * seed management. + */ +struct seed_derive; + +/* + * Compute the public key. Note that it doesn't compute a 'private key'; + * the signature algorithm gets that data when we pass the parameters again + * Parameters: + * lm_ots_type - The parameter set + * I - The I public identifier to use + * q - The diversification string, passed as a 4 byte integer + * seed - The structure used to generate seeds + * public_key - Where to place the public key + * public_key_len - The length of the above buffer + * This returns true on success + */ +bool lm_ots_generate_public_key( + param_set_t lm_ots_type, + const unsigned char *I, /* Public key identifier */ + merkle_index_t q, /* Diversification string, 4 bytes value */ + struct seed_derive *seed, + unsigned char *public_key, size_t public_key_len); + +/* + * Sign a message. Warning: the caller is expected to make sure that it signs + * only one message with a given seed/I/q set + * Parameters: + * lm_ots_type - The parameter set + * I - The I public identifier to use + * q - The diversification string, passed as a 4 byte integer + * seed - The structure used to generate seeds + * message - Message to sign + * message_len - Length of the message + * prehashed - Set if the message hashing has already taken place + * signature - Where to place the signature + * signature_len - The length of the above buffer + * This returns true on success + */ +bool lm_ots_generate_signature( + param_set_t lm_ots_type, + const unsigned char *I, + merkle_index_t q, + struct seed_derive *seed, + const void *message, size_t message_len, bool prehashed, + unsigned char *signature, size_t signature_len); + +/* The include file for the verification routine */ +#include "lm_ots_verify.h" + +/* The include file for the common access routines */ +#include "lm_ots_common.h" + +#endif /* LM_OTS_H_ */ diff --git a/src/sig_stfl/lms/external/lm_ots_common.c b/src/sig_stfl/lms/external/lm_ots_common.c new file mode 100644 index 0000000000..45672e18b2 --- /dev/null +++ b/src/sig_stfl/lms/external/lm_ots_common.c @@ -0,0 +1,99 @@ +/* + * This is the code that implements the one-time-signature part of the LMS hash + * based signatures + */ +#include "lm_ots_common.h" +#include "common_defs.h" +#include "hash.h" + +/* + * Convert the external name of a parameter set into the set of values we care + * about + */ +bool lm_ots_look_up_parameter_set(param_set_t parameter_set, + unsigned *h, unsigned *n, unsigned *w, unsigned *p, unsigned *ls) { + unsigned v_h, v_n, v_w, v_p, v_ls; + switch (parameter_set) { + case LMOTS_SHA256_N32_W1: + v_h = HASH_SHA256; v_n = 32; v_w = 1; v_p = 265; v_ls = 7; break; + case LMOTS_SHA256_N32_W2: + v_h = HASH_SHA256; v_n = 32; v_w = 2; v_p = 133; v_ls = 6; break; + case LMOTS_SHA256_N32_W4: + v_h = HASH_SHA256; v_n = 32; v_w = 4; v_p = 67; v_ls = 4; break; + case LMOTS_SHA256_N32_W8: + v_h = HASH_SHA256; v_n = 32; v_w = 8; v_p = 34; v_ls = 0; break; + default: return false; + } + + if (h) *h = v_h; + if (n) *n = v_n; + if (w) *w = v_w; + if (p) *p = v_p; + if (ls) *ls = v_ls; + + return true; +} + +/* The public key just consists of the bare hash */ +size_t lm_ots_get_public_key_len(param_set_t lm_ots_type) { + unsigned n; + if (!lm_ots_look_up_parameter_set( lm_ots_type, 0, &n, 0, 0, 0 )) + return 0; + + return n; +} + +/* Return the length of a signature */ +size_t lm_ots_get_signature_len(param_set_t lm_ots_type) { + unsigned n, p; + + if (!lm_ots_look_up_parameter_set( lm_ots_type, 0, &n, 0, &p, 0 )) + return 0; + + return 4 + n + p*n; +} + +/* Return the number of hashes we need to compute to generate a public key */ +unsigned lm_ots_hashes_per_public_key(param_set_t lm_ots_type) { + unsigned wint, num_dig; + if (!lm_ots_look_up_parameter_set(lm_ots_type, + NULL, NULL, &wint, &num_dig, NULL)) { + return 0; + } + + /* Total number of hash invocations: + * For each digit, we expand the seed (1), and then perform (2**wint-1) + * haashes to obtain the end of the chain + * Then, we hash all the ends of the chains together + * If we were to return the number of hash compression operations, + * the final 1 would be a bit larger + */ + return num_dig * (1 << wint) + 1; +} + +/* Todo: some of these values depend only on w; why do we need to recompute */ +/* them each time??? */ +unsigned lm_ots_coef(const unsigned char *Q, unsigned i, unsigned w) { + unsigned index = (i * w) / 8; /* Which byte holds the coefficient */ + /* we want */ + unsigned digits_per_byte = 8/w; + unsigned shift = w * (~i & (digits_per_byte-1)); /* Where in the byte */ + /* the coefficient is */ + unsigned mask = (1<> shift) & mask; +} + +/* This returns the Winternitz checksum to append to the hash */ +unsigned lm_ots_compute_checksum(const unsigned char *Q, unsigned Q_len, + unsigned w, unsigned ls) { + unsigned sum = 0; + unsigned i; + unsigned u = 8 * Q_len / w; + unsigned max_digit = (1< +#include "common_defs.h" + +bool lm_ots_look_up_parameter_set(param_set_t parameter_set, + unsigned *h, unsigned *n, unsigned *w, unsigned *p, unsigned *ls); +size_t lm_ots_get_public_key_len(param_set_t lm_ots_type); +size_t lm_ots_get_signature_len(param_set_t lm_ots_type); +unsigned lm_ots_hashes_per_public_key(param_set_t lm_ots_type); +unsigned lm_ots_compute_checksum(const unsigned char *Q, unsigned Q_len, + unsigned w, unsigned ls); +unsigned lm_ots_coef(const unsigned char *Q, unsigned i, unsigned w); + +#endif /* LM_OTS_COMMON_H_ */ diff --git a/src/sig_stfl/lms/external/lm_ots_sign.c b/src/sig_stfl/lms/external/lm_ots_sign.c new file mode 100644 index 0000000000..ee8f56b0a2 --- /dev/null +++ b/src/sig_stfl/lms/external/lm_ots_sign.c @@ -0,0 +1,168 @@ +/* + * This is the code that implements the one-time-signature part of the LMS hash + * based signatures + */ +#include +#include "common_defs.h" +#include "lm_ots.h" +#include "lm_ots_common.h" +#include "hash.h" +#include "endian.h" +#include "hss_zeroize.h" +#include "hss_derive.h" +#include "hss_internal.h" + +bool lm_ots_generate_public_key( + param_set_t lm_ots_type, + const unsigned char *I, /* Public key identifier */ + merkle_index_t q, /* Diversification string, 4 bytes value */ + struct seed_derive *seed, + unsigned char *public_key, size_t public_key_len) { + + /* Look up the parameter set */ + unsigned h, n, w, p, ls; + LMS_UNUSED(public_key_len); + if (!lm_ots_look_up_parameter_set( lm_ots_type, &h, &n, &w, &p, &ls )) + return false; + + /* Start the hash that computes the final value */ + union hash_context public_ctx; + hss_init_hash_context(h, &public_ctx); + { + unsigned char prehash_prefix[ PBLC_PREFIX_LEN ]; + memcpy( prehash_prefix + PBLC_I, I, I_LEN ); + put_bigendian( prehash_prefix + PBLC_Q, q, 4 ); + SET_D( prehash_prefix + PBLC_D, D_PBLC ); + hss_update_hash_context(h, &public_ctx, prehash_prefix, + PBLC_PREFIX_LEN ); + } + + /* Now generate the public key */ + /* This is where we spend the majority of the time during key gen and */ + /* signing operations; it would make sense to attempt to try to take */ + /* advantage of parallel (SIMD) hardware; even if we use it nowhere */ + /* else, we'd get a significant speed up */ + unsigned i, j; + + unsigned char buf[ ITER_MAX_LEN ]; + memcpy( buf + ITER_I, I, I_LEN ); + put_bigendian( buf + ITER_Q, q, 4 ); + union hash_context ctx; + + hss_seed_derive_set_j( seed, 0 ); + + for (i=0; i +#include "lm_ots_verify.h" +#include "lm_ots_common.h" +#include "hash.h" +#include "endian.h" +#include "common_defs.h" + +/* + * This validate a OTS signature for a message. It doesn't actually use the + * public key explicitly; instead, it just produces the root key, based on the + * message; the caller is assumed to compare it to the expected value + * Parameters: + * - computed_public_key - where to place the reconstructed root. It is + * assumed that the caller has allocated enough space + * - I: the nonce value ("I") to use + * - q: diversification string + * - message - the message to verify + * - message_len - the length of the message + * - message_prehashed - true if the message has already undergone the initial + * (D_MESG) hash + * - signature - the signature + * - signature_len - the length of the signature + * - parameter_set - what we expect the parameter set to be + * + * This returns true on successfully recomputing a root value; whether it is + * the right one is something the caller would need to verify + */ +bool lm_ots_validate_signature_compute( + unsigned char *computed_public_key, + const unsigned char *I, merkle_index_t q, + const void *message, size_t message_len, bool message_prehashed, + const unsigned char *signature, size_t signature_len, + param_set_t expected_parameter_set) { + if (signature_len < 4) return false; /* Ha, ha, very funny... */ + + /* We don't trust the parameter set that's in the signature; verify it */ + param_set_t parameter_set = get_bigendian( signature, 4 ); + if (parameter_set != expected_parameter_set) { + return false; + } + + unsigned h, n, w, p, ls; + if (!lm_ots_look_up_parameter_set( parameter_set, &h, &n, &w, &p, &ls )) + return false; + + if (signature_len != 4 + n * (p+1)) return false; + + const unsigned char *C = signature + 4; + const unsigned char *y = C + n; + + unsigned char Q[MAX_HASH + 2]; + if (message_prehashed) { + memcpy( Q, message, n ); + } else { + union hash_context ctx; + /* Compute the initial hash */ + hss_init_hash_context(h, &ctx); + /* Hash the message prefix */ + { + unsigned char prefix[ MESG_PREFIX_MAXLEN ]; + memcpy( prefix + MESG_I, I, I_LEN ); + put_bigendian( prefix + MESG_Q, q, 4 ); + SET_D( prefix + MESG_D, D_MESG ); + memcpy( prefix + MESG_C, C, n ); + hss_update_hash_context(h, &ctx, prefix, MESG_PREFIX_LEN(n) ); + } + /* Then, the message */ + hss_update_hash_context(h, &ctx, message, message_len ); + + hss_finalize_hash_context( h, &ctx, Q ); + } + + /* Append the checksum to the randomized hash */ + put_bigendian( &Q[n], lm_ots_compute_checksum(Q, n, w, ls), 2 ); + + /* And, start building the parts for the final hash */ + union hash_context final_ctx; + hss_init_hash_context(h, &final_ctx); + { + unsigned char prehash_prefix[ PBLC_PREFIX_LEN ]; + memcpy( prehash_prefix + PBLC_I, I, I_LEN ); + put_bigendian( prehash_prefix + PBLC_Q, q, 4 ); + SET_D( prehash_prefix + PBLC_D, D_PBLC ); + hss_update_hash_context(h, &final_ctx, prehash_prefix, + PBLC_PREFIX_LEN ); + } + + unsigned i; + unsigned char tmp[ITER_MAX_LEN]; + + /* Preset the parts of tmp that don't change */ + memcpy( tmp + ITER_I, I, I_LEN ); + put_bigendian( tmp + ITER_Q, q, 4 ); + + unsigned max_digit = (1< +#include "common_defs.h" + +/* + * This validates an OTS signature, but instead of producing a SUCCESS/FAILURE + * return, it generates the root value (which the caller is expected to check). + * It can return false (failure), for things such as unrecognized parameter + * set It also makes sure that the parameter set of the signature is that + * value (as we need to make sure that the attacker didn't substitute a + * weaker one) + */ +bool lm_ots_validate_signature_compute( + unsigned char *computed_public_key, + const unsigned char *I, + merkle_index_t q, /* Diversification string, 4 bytes value */ + const void *message, size_t message_len, bool prehashed, + const unsigned char *signature, size_t signature_len, + param_set_t expected_parameter_set); + +#endif /* LM_OTS_VERIFY_H_ */ diff --git a/src/sig_stfl/lms/external/lm_verify.c b/src/sig_stfl/lms/external/lm_verify.c new file mode 100644 index 0000000000..46b3627885 --- /dev/null +++ b/src/sig_stfl/lms/external/lm_verify.c @@ -0,0 +1,107 @@ +/* + * This is the code that implements the tree part of the LMS hash + * based signatures + */ +#include +#include "lm_verify.h" +#include "lm_common.h" +#include "lm_ots_common.h" +#include "lm_ots_verify.h" +#include "hash.h" +#include "endian.h" +#include "common_defs.h" + +/* + * XDR requires us to pad the I value out to a multiple of 4 + * This computes how long the field will be after padding + * That is, it rounds len_I up to the next multiple of 4 + */ +#define padded_length(len_I) (((len_I) + 3) & ~3) + +/* + * This validate an LM signature for a message. It does take an XDR-encoded + * signature, and verify against it. + * Parameters: + * - public_key - the XDR-encoded public ley + * - message - the message to verify + * - message_len - the length of the message + * - signature - the signature + * - signature_len - the length of the signature + * + * This returns true if the signature verifies + */ +bool lm_validate_signature( + const unsigned char *public_key, + const void *message, size_t message_len, bool prehashed, + const unsigned char *signature, size_t signature_len) { + union hash_context ctx; + + param_set_t lm_type = get_bigendian( public_key + LM_PUB_PARM_SET, 4 ); + param_set_t ots_type = get_bigendian( public_key + LM_PUB_OTS_PARM_SET, 4 ); + + unsigned h, n, height; + if (!lm_look_up_parameter_set(lm_type, &h, &n, &height)) return false; + + unsigned char computed_public_key[MAX_HASH]; + + const unsigned char *I = public_key + LM_PUB_I; + + if (signature_len < 8) return false; + merkle_index_t count = get_bigendian( signature, 4 ); + signature += 4; signature_len -= 4; /* 4 bytes, rather then 8 */ + /* the OTS type is expected to be a part of the OTS signature, */ + /* which lm_ots_validate_signature_compute will expect */ + + /* Compute the OTS root */ + size_t ots_publen = lm_ots_get_public_key_len(ots_type); + size_t ots_siglen = lm_ots_get_signature_len(ots_type); + if (ots_publen == 0 || ots_siglen == 0) return false; + if (signature_len < ots_siglen) return false; + + unsigned char ots_sig[LEAF_MAX_LEN]; + if (!lm_ots_validate_signature_compute(ots_sig + LEAF_PK, I, count, + message, message_len, prehashed, + signature, ots_siglen, ots_type)) return false; + signature += ots_siglen; signature_len -= ots_siglen; + + /* Get the parameter set declared in the sigature; make sure it matches */ + /* what we expect */ + if (signature_len < 4) return false; + param_set_t parameter_set = get_bigendian( signature, 4 ); + if (parameter_set != lm_type) return false; + signature += 4; signature_len -= 4; + + merkle_index_t count_nodes = (merkle_index_t)1 << height; + + if (signature_len != n * height) return false; /* We expect the auth */ + /* path to be there as the last element */ + if (count >= count_nodes) return false; /* Index out of range */ + merkle_index_t node_num = count + count_nodes; + + memcpy( ots_sig + LEAF_I, I, I_LEN ); + put_bigendian( ots_sig + LEAF_R, node_num, 4 ); + SET_D( ots_sig + LEAF_D, D_LEAF ); + hss_hash_ctx( computed_public_key, h, &ctx, ots_sig, LEAF_LEN(n) ); + + unsigned char prehash[ INTR_MAX_LEN ]; + memcpy( prehash + INTR_I, I, I_LEN ); + SET_D( prehash + INTR_D, D_INTR ); + while (node_num > 1) { + if (node_num % 2) { + memcpy( prehash + INTR_PK + 0, signature, n ); + memcpy( prehash + INTR_PK + n, computed_public_key, n ); + } else { + memcpy( prehash + INTR_PK + 0, computed_public_key, n ); + memcpy( prehash + INTR_PK + n, signature, n ); + } + signature += n; + node_num /= 2; + put_bigendian( prehash + INTR_R, node_num, 4 ); + hss_hash_ctx( computed_public_key, h, &ctx, prehash, INTR_LEN(n) ); + } + + /* Now, check to see if the root we computed matches the root we should have */ + unsigned offset = LM_PUB_I + padded_length(I_LEN); + + return 0 == memcmp( computed_public_key, public_key + offset, n ); +} diff --git a/src/sig_stfl/lms/external/lm_verify.h b/src/sig_stfl/lms/external/lm_verify.h new file mode 100644 index 0000000000..7f48767fcb --- /dev/null +++ b/src/sig_stfl/lms/external/lm_verify.h @@ -0,0 +1,12 @@ +#if !defined(LM_VERIFY_H_) +#define LM_VERIFY_H_ + +#include +#include + +bool lm_validate_signature( + const unsigned char *public_key, + const void *message, size_t message_len, bool prehashed, + const unsigned char *signature, size_t signature_len); + +#endif /* LM_VERIFY_H_ */ diff --git a/src/sig_stfl/lms/external/sha256.c b/src/sig_stfl/lms/external/sha256.c new file mode 100644 index 0000000000..fb18892a31 --- /dev/null +++ b/src/sig_stfl/lms/external/sha256.c @@ -0,0 +1,183 @@ +/* + * SHA-256 + * Implementation derived from LibTomCrypt (Tom St Denis) + * + * LibTomCrypt is a library that provides various cryptographic + * algorithms in a highly modular and flexible manner. + * + * The library is free for all purposes without any express + * guarantee it works. + * + * Tom St Denis, tomstdenis@gmail.com, http://libtomcrypt.org + */ + +#include +#include "sha256.h" +#include "endian.h" + +#if !USE_OPENSSL && !defined(EXT_SHA256_H) + +/* If we don't have OpenSSL, here's a SHA256 implementation */ +#define SHA256_FINALCOUNT_SIZE 8 +#define SHA256_K_SIZE 64 +static const unsigned long K[SHA256_K_SIZE] = { + 0x428a2f98UL, 0x71374491UL, 0xb5c0fbcfUL, 0xe9b5dba5UL, 0x3956c25bUL, + 0x59f111f1UL, 0x923f82a4UL, 0xab1c5ed5UL, 0xd807aa98UL, 0x12835b01UL, + 0x243185beUL, 0x550c7dc3UL, 0x72be5d74UL, 0x80deb1feUL, 0x9bdc06a7UL, + 0xc19bf174UL, 0xe49b69c1UL, 0xefbe4786UL, 0x0fc19dc6UL, 0x240ca1ccUL, + 0x2de92c6fUL, 0x4a7484aaUL, 0x5cb0a9dcUL, 0x76f988daUL, 0x983e5152UL, + 0xa831c66dUL, 0xb00327c8UL, 0xbf597fc7UL, 0xc6e00bf3UL, 0xd5a79147UL, + 0x06ca6351UL, 0x14292967UL, 0x27b70a85UL, 0x2e1b2138UL, 0x4d2c6dfcUL, + 0x53380d13UL, 0x650a7354UL, 0x766a0abbUL, 0x81c2c92eUL, 0x92722c85UL, + 0xa2bfe8a1UL, 0xa81a664bUL, 0xc24b8b70UL, 0xc76c51a3UL, 0xd192e819UL, + 0xd6990624UL, 0xf40e3585UL, 0x106aa070UL, 0x19a4c116UL, 0x1e376c08UL, + 0x2748774cUL, 0x34b0bcb5UL, 0x391c0cb3UL, 0x4ed8aa4aUL, 0x5b9cca4fUL, + 0x682e6ff3UL, 0x748f82eeUL, 0x78a5636fUL, 0x84c87814UL, 0x8cc70208UL, + 0x90befffaUL, 0xa4506cebUL, 0xbef9a3f7UL, 0xc67178f2UL +}; + +/* Various logical functions */ + +/* Rotate x right by rot bits */ +static unsigned long RORc(unsigned long x, int rot) { + rot &= 31; if (rot == 0) return x; + unsigned long right = ((x&0xFFFFFFFFUL)>>rot ); + unsigned long left = ((x&0xFFFFFFFFUL)<<(32-rot) ); + return (right|left) & 0xFFFFFFFFUL; +} +#define Ch(x,y,z) (z ^ (x & (y ^ z))) +#define Maj(x,y,z) (((x | y) & z) | (x & y)) +#define S(x, n) RORc((x),(n)) +#define R(x, n) (((x)&0xFFFFFFFFUL)>>(n)) +#define Sigma0(x) (S(x, 2) ^ S(x, 13) ^ S(x, 22)) +#define Sigma1(x) (S(x, 6) ^ S(x, 11) ^ S(x, 25)) +#define Gamma0(x) (S(x, 7) ^ S(x, 18) ^ R(x, 3)) +#define Gamma1(x) (S(x, 17) ^ S(x, 19) ^ R(x, 10)) + +static void sha256_compress (SHA256_CTX * ctx, const void *buf) +{ + unsigned long S0, S1, S2, S3, S4, S5, S6, S7, W[SHA256_K_SIZE], t0, t1, t; + int i; + const unsigned char *p; + + /* copy state into S */ + S0 = ctx->h[0]; + S1 = ctx->h[1]; + S2 = ctx->h[2]; + S3 = ctx->h[3]; + S4 = ctx->h[4]; + S5 = ctx->h[5]; + S6 = ctx->h[6]; + S7 = ctx->h[7]; + + /* + * We've been asked to perform the hash computation on this 512-bit string. + * SHA256 interprets that as an array of 16 bigendian 32 bit numbers; copy + * it, and convert it into 16 unsigned long's of the CPU's native format + */ + p = buf; + for (i=0; i<16; i++) { + W[i] = get_bigendian( p, 4 ); + p += 4; + } + + /* fill W[16..63] */ + for (i = 16; i < SHA256_K_SIZE; i++) { + W[i] = Gamma1(W[i - 2]) + W[i - 7] + Gamma0(W[i - 15]) + W[i - 16]; + } + + /* Compress */ +#define RND(a,b,c,d,e,f,g,h,i) \ + t0 = h + Sigma1(e) + Ch(e, f, g) + K[i] + W[i]; \ + t1 = Sigma0(a) + Maj(a, b, c); \ + d += t0; \ + h = t0 + t1; + + for (i = 0; i < SHA256_K_SIZE; ++i) { + RND(S0,S1,S2,S3,S4,S5,S6,S7,i); + t = S7; S7 = S6; S6 = S5; S5 = S4; + S4 = S3; S3 = S2; S2 = S1; S1 = S0; S0 = t; + } +#undef RND + + /* feedback */ + ctx->h[0] += S0; + ctx->h[1] += S1; + ctx->h[2] += S2; + ctx->h[3] += S3; + ctx->h[4] += S4; + ctx->h[5] += S5; + ctx->h[6] += S6; + ctx->h[7] += S7; +} + +void SHA256_Init (SHA256_CTX *ctx) +{ + ctx->Nl = 0; + ctx->Nh = 0; + ctx->num = 0; + ctx->h[0] = 0x6A09E667UL; + ctx->h[1] = 0xBB67AE85UL; + ctx->h[2] = 0x3C6EF372UL; + ctx->h[3] = 0xA54FF53AUL; + ctx->h[4] = 0x510E527FUL; + ctx->h[5] = 0x9B05688CUL; + ctx->h[6] = 0x1F83D9ABUL; + ctx->h[7] = 0x5BE0CD19UL; +} + +void SHA256_Update (SHA256_CTX *ctx, const void *src, unsigned int count) +{ + unsigned new_count = (ctx->Nl + (count << 3)) & 0xffffffff; + if (new_count < ctx->Nl) { + ctx->Nh += 1; + } + ctx->Nl = new_count; + + while (count) { + unsigned int this_step = 64 - ctx->num; + if (this_step > count) this_step = count; + memcpy( ctx->data + ctx->num, src, this_step); + + if (this_step + ctx->num < 64) { + ctx->num += this_step; + break; + } + + src = (const unsigned char *)src + this_step; + count -= this_step; + ctx->num = 0; + + sha256_compress( ctx, ctx->data ); + } +} + +/* + * Add padding and return the message digest. + */ +void SHA256_Final (unsigned char *digest, SHA256_CTX *ctx) +{ + unsigned int i; + unsigned char finalcount[SHA256_FINALCOUNT_SIZE]; + + put_bigendian( &finalcount[0], ctx->Nh, 4 ); + put_bigendian( &finalcount[4], ctx->Nl, 4 ); + + SHA256_Update(ctx, "\200", 1); + + if (ctx->num > 56) { + SHA256_Update(ctx, "\0\0\0\0\0\0\0\0", 8); + } + memset( ctx->data + ctx->num, 0, 56 - ctx->num ); + ctx->num = 56; + SHA256_Update(ctx, finalcount, SHA256_FINALCOUNT_SIZE); /* Should cause a sha256_compress() */ + + /* + * The final state is an array of unsigned long's; place them as a series + * of bigendian 4-byte words onto the output + */ + for (i=0; i<8; i++) { + put_bigendian( digest + 4*i, ctx->h[i], 4 ); + } +} +#endif diff --git a/src/sig_stfl/lms/external/sha256.h b/src/sig_stfl/lms/external/sha256.h new file mode 100644 index 0000000000..a5de21c014 --- /dev/null +++ b/src/sig_stfl/lms/external/sha256.h @@ -0,0 +1,43 @@ +#if !defined(SHA256_H_) +#define SHA256_H_ + +#if defined( EXT_SHA256_H ) +#include EXT_SHA256_H +#else + +#define USE_OPENSSL 0 /* We use the OpenSSL implementation for SHA-256 */ + /* (which is quite a bit faster than our portable */ + /* C version) */ + +#if USE_OPENSSL + +#include + +#else + +/* SHA256 context. */ +typedef struct { + unsigned long int h[8]; /* state; this is in the CPU native format */ + unsigned long Nl, Nh; /* number of bits processed so far */ + unsigned num; /* number of bytes within the below */ + /* buffer */ + unsigned char data[64]; /* input buffer. This is in byte vector format */ +} SHA256_CTX; + +void SHA256_Init(SHA256_CTX *); /* context */ + +void SHA256_Update(SHA256_CTX *, /* context */ + const void *, /* input block */ + unsigned int);/* length of input block */ + +void SHA256_Final(unsigned char *, + SHA256_CTX *); +#endif + +#endif /* EXT_SHA256_H */ + +#if !defined( SHA256_LEN ) +#define SHA256_LEN 32 /* The length of a SHA256 hash output */ +#endif + +#endif /* ifdef(SHA256_H_) */ From a7e26d95451a5386b7726a614337a2db7045f24e Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Sun, 23 Jul 2023 22:10:34 -0400 Subject: [PATCH 08/68] Add 12 XMSS and 16 XMSSMT parameters. (#1489) * populate all 28 XMSS parameters * clean up * remove wanrings in scanbuild * change free to OQS_MEM_insecure_free * fix build warning * fix integer in i386 platforms * proper type for sigs_remain and sig_maximum * remove size_t in signature remain and total * make scan-build happy --- .CMake/alg_support.cmake | 28 + src/oqsconfig.h.cmake | 27 + src/sig_stfl/sig_stfl.c | 530 +++++++++++++++++- src/sig_stfl/sig_stfl.h | 51 +- src/sig_stfl/xmss/CMakeLists.txt | 180 +++++- src/sig_stfl/xmss/external/core_hash.c | 40 +- src/sig_stfl/xmss/external/core_hash.h | 23 + src/sig_stfl/xmss/external/hash.h | 6 +- src/sig_stfl/xmss/external/namespace.h | 14 +- src/sig_stfl/xmss/external/xmss.c | 2 +- src/sig_stfl/xmss/external/xmss_core_fast.c | 65 ++- src/sig_stfl/xmss/sig_stfl_xmss.h | 478 +++++++++++++++- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 32 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 136 +++++ src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 136 +++++ src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 136 +++++ src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 136 +++++ src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 136 +++++ .../xmss/sig_stfl_xmss_shake128_h10.c | 136 +++++ .../xmss/sig_stfl_xmss_shake128_h16.c | 136 +++++ .../xmss/sig_stfl_xmss_shake128_h20.c | 136 +++++ .../xmss/sig_stfl_xmss_shake256_h10.c | 136 +++++ .../xmss/sig_stfl_xmss_shake256_h16.c | 136 +++++ .../xmss/sig_stfl_xmss_shake256_h20.c | 136 +++++ .../xmss/sig_stfl_xmssmt_sha256_h20_2.c | 136 +++++ .../xmss/sig_stfl_xmssmt_sha256_h20_4.c | 136 +++++ .../xmss/sig_stfl_xmssmt_sha256_h40_2.c | 136 +++++ .../xmss/sig_stfl_xmssmt_sha256_h40_4.c | 136 +++++ .../xmss/sig_stfl_xmssmt_sha256_h40_8.c | 136 +++++ .../xmss/sig_stfl_xmssmt_sha256_h60_12.c | 136 +++++ .../xmss/sig_stfl_xmssmt_sha256_h60_3.c | 136 +++++ .../xmss/sig_stfl_xmssmt_sha256_h60_6.c | 136 +++++ .../xmss/sig_stfl_xmssmt_shake128_h20_2.c | 136 +++++ .../xmss/sig_stfl_xmssmt_shake128_h20_4.c | 136 +++++ .../xmss/sig_stfl_xmssmt_shake128_h40_2.c | 136 +++++ .../xmss/sig_stfl_xmssmt_shake128_h40_4.c | 136 +++++ .../xmss/sig_stfl_xmssmt_shake128_h40_8.c | 136 +++++ .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 136 +++++ .../xmss/sig_stfl_xmssmt_shake128_h60_3.c | 136 +++++ .../xmss/sig_stfl_xmssmt_shake128_h60_6.c | 136 +++++ tests/KATs/sig_stfl/kats.json | 29 +- tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp | 180 +----- tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp | 14 + tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp | 14 + tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp | 14 + tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp | 14 + tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp | 14 + .../KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp | 14 + .../KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp | 14 + .../KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp | 14 + .../KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp | 14 + .../KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp | 14 + .../KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp | 14 + .../sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp | 14 + tests/helpers.py | 4 +- tests/kat_sig_stfl.c | 141 +++-- tests/test_cmdline.py | 14 +- tests/test_sig_stfl.c | 242 +++++++- 73 files changed, 5812 insertions(+), 324 deletions(-) create mode 100644 src/sig_stfl/xmss/external/core_hash.h create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp create mode 100644 tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index c2c498bf54..aaf8ea6fef 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -499,6 +499,34 @@ endif() option(OQS_ENABLE_SIG_STFL_XMSS "Enable XMSS algorithm family" ON) cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha256_h10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha256_h16 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha256_h20 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_shake128_h10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_shake128_h16 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_shake128_h20 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha512_h10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha512_h16 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha512_h20 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_shake256_h10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_shake256_h16 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_shake256_h20 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) + if((OQS_MINIMAL_BUILD STREQUAL "ON")) message(FATAL_ERROR "OQS_MINIMAL_BUILD option ${OQS_MINIMAL_BUILD} no longer supported") diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index 3496e1a5f2..aef6c427aa 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -193,3 +193,30 @@ #cmakedefine OQS_ENABLE_SIG_STFL_XMSS 1 #cmakedefine OQS_ENABLE_SIG_STFL_xmss_sha256_h10 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_sha256_h16 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_sha256_h20 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_shake128_h10 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_shake128_h16 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_shake128_h20 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_sha512_h10 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_sha512_h16 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_sha512_h20 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_shake256_h10 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_shake256_h16 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmss_shake256_h20 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 1 +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 1 \ No newline at end of file diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 2b68e6dd94..20bf641b95 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -13,8 +13,35 @@ OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { - const char *a[OQS_SIG_algs_length] = { + const char *a[OQS_SIG_STFL_algs_length] = { OQS_SIG_STFL_alg_xmss_sha256_h10, + OQS_SIG_STFL_alg_xmss_sha256_h16, + OQS_SIG_STFL_alg_xmss_sha256_h20, + OQS_SIG_STFL_alg_xmss_shake128_h10, + OQS_SIG_STFL_alg_xmss_shake128_h16, + OQS_SIG_STFL_alg_xmss_shake128_h20, + OQS_SIG_STFL_alg_xmss_sha512_h10, + OQS_SIG_STFL_alg_xmss_sha512_h16, + OQS_SIG_STFL_alg_xmss_sha512_h20, + OQS_SIG_STFL_alg_xmss_shake256_h10, + OQS_SIG_STFL_alg_xmss_shake256_h16, + OQS_SIG_STFL_alg_xmss_shake256_h20, + OQS_SIG_STFL_alg_xmssmt_sha256_h20_2, + OQS_SIG_STFL_alg_xmssmt_sha256_h20_4, + OQS_SIG_STFL_alg_xmssmt_sha256_h40_2, + OQS_SIG_STFL_alg_xmssmt_sha256_h40_4, + OQS_SIG_STFL_alg_xmssmt_sha256_h40_8, + OQS_SIG_STFL_alg_xmssmt_sha256_h60_3, + OQS_SIG_STFL_alg_xmssmt_sha256_h60_6, + OQS_SIG_STFL_alg_xmssmt_sha256_h60_12, + OQS_SIG_STFL_alg_xmssmt_shake128_h20_2, + OQS_SIG_STFL_alg_xmssmt_shake128_h20_4, + OQS_SIG_STFL_alg_xmssmt_shake128_h40_2, + OQS_SIG_STFL_alg_xmssmt_shake128_h40_4, + OQS_SIG_STFL_alg_xmssmt_shake128_h40_8, + OQS_SIG_STFL_alg_xmssmt_shake128_h60_3, + OQS_SIG_STFL_alg_xmssmt_shake128_h60_6, + OQS_SIG_STFL_alg_xmssmt_shake128_h60_12, }; if (i >= OQS_SIG_STFL_algs_length) { @@ -40,6 +67,168 @@ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name) { return 1; #else return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h10 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h10 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h10 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_8)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_6)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_12)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_8)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 + return 1; +#else + return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 + return 1; +#else + return 0; #endif } else { return 0; @@ -57,6 +246,168 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { return OQS_SIG_STFL_alg_xmss_sha256_h10_new(); #else return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + return OQS_SIG_STFL_alg_xmss_sha256_h16_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + return OQS_SIG_STFL_alg_xmss_sha256_h20_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h10 + return OQS_SIG_STFL_alg_xmss_shake128_h10_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + return OQS_SIG_STFL_alg_xmss_shake128_h16_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + return OQS_SIG_STFL_alg_xmss_shake128_h20_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h10 + return OQS_SIG_STFL_alg_xmss_sha512_h10_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + return OQS_SIG_STFL_alg_xmss_sha512_h16_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + return OQS_SIG_STFL_alg_xmss_sha512_h20_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h10 + return OQS_SIG_STFL_alg_xmss_shake256_h10_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + return OQS_SIG_STFL_alg_xmss_shake256_h16_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + return OQS_SIG_STFL_alg_xmss_shake256_h20_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2 + return OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4 + return OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + return OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4 + return OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_8)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8 + return OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + return OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_6)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6 + return OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_12)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12 + return OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2 + return OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4 + return OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + return OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4 + return OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_8)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8 + return OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + return OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 + return OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 + return OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_new(); +#else + return NULL; #endif } else { return NULL; @@ -88,7 +439,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m } } -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, size_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, uint64_t *remain, const uint8_t *secret_key) { if (sig == NULL || sig->sigs_remaining == NULL || sig->sigs_remaining(remain, secret_key) != 0) { return OQS_ERROR; } else { @@ -96,7 +447,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, size_t * } } -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, size_t *max, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, uint64_t *max, const uint8_t *secret_key) { if (sig == NULL || sig->sigs_total == NULL || sig->sigs_total(max, secret_key) != 0) { return OQS_ERROR; } else { @@ -123,18 +474,189 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_ return OQS_SECRET_KEY_XMSS_SHA256_H10_new(); #else return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + return OQS_SECRET_KEY_XMSS_SHA256_H16_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + return OQS_SECRET_KEY_XMSS_SHA256_H20_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h10 + return OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + return OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + return OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h10 + return OQS_SECRET_KEY_XMSS_SHA512_H10_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + return OQS_SECRET_KEY_XMSS_SHA512_H16_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + return OQS_SECRET_KEY_XMSS_SHA512_H20_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h10)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h10 + return OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + return OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + return OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2 + return OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4 + return OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + return OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4 + return OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_8)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8 + return OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + return OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_6)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6 + return OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_12)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12 + return OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2 + return OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4 + return OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + return OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_4)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4 + return OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_8)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8 + return OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + return OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 + return OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(); +#else + return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12)) { +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 + return OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(); +#else + return NULL; #endif } else { return NULL; } } +void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return; + } + + OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); + sk->secret_key_data = NULL; +} + OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk) { if (sk == NULL) { return; } - /* Call object specif free */ + /* Call object specific free */ if (sk->free_key) { sk->free_key(sk); } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 6beeb8c24d..b2955d78ba 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -22,8 +22,35 @@ extern "C" { /* Algorithm identifier for XMSS-SHA2_10_256 */ #define OQS_SIG_STFL_alg_xmss_sha256_h10 "XMSS-SHA2_10_256" - -#define OQS_SIG_STFL_algs_length 1 +#define OQS_SIG_STFL_alg_xmss_sha256_h16 "XMSS-SHA2_16_256" +#define OQS_SIG_STFL_alg_xmss_sha256_h20 "XMSS-SHA2_20_256" +#define OQS_SIG_STFL_alg_xmss_shake128_h10 "XMSS-SHAKE_10_256" +#define OQS_SIG_STFL_alg_xmss_shake128_h16 "XMSS-SHAKE_16_256" +#define OQS_SIG_STFL_alg_xmss_shake128_h20 "XMSS-SHAKE_20_256" +#define OQS_SIG_STFL_alg_xmss_sha512_h10 "XMSS-SHA2_10_512" +#define OQS_SIG_STFL_alg_xmss_sha512_h16 "XMSS-SHA2_16_512" +#define OQS_SIG_STFL_alg_xmss_sha512_h20 "XMSS-SHA2_20_512" +#define OQS_SIG_STFL_alg_xmss_shake256_h10 "XMSS-SHAKE_10_512" +#define OQS_SIG_STFL_alg_xmss_shake256_h16 "XMSS-SHAKE_16_512" +#define OQS_SIG_STFL_alg_xmss_shake256_h20 "XMSS-SHAKE_20_512" +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_2 "XMSSMT-SHA2_20/2_256" +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_4 "XMSSMT-SHA2_20/4_256" +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_2 "XMSSMT-SHA2_40/2_256" +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_4 "XMSSMT-SHA2_40/4_256" +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_8 "XMSSMT-SHA2_40/8_256" +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_3 "XMSSMT-SHA2_60/3_256" +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_6 "XMSSMT-SHA2_60/6_256" +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_12 "XMSSMT-SHA2_60/12_256" +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_2 "XMSSMT-SHAKE_20/2_256" +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_4 "XMSSMT-SHAKE_20/4_256" +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_2 "XMSSMT-SHAKE_40/2_256" +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_4 "XMSSMT-SHAKE_40/4_256" +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_8 "XMSSMT-SHAKE_40/8_256" +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_3 "XMSSMT-SHAKE_60/3_256" +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6 "XMSSMT-SHAKE_60/6_256" +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12 "XMSSMT-SHAKE_60/12_256" + +#define OQS_SIG_STFL_algs_length 28 /** * Returns identifiers for available signature schemes in liboqs. Used with OQS_SIG_STFL_new. @@ -132,7 +159,7 @@ typedef struct OQS_SIG_STFL { * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*sigs_remaining)(size_t *remain, const uint8_t *secret_key); + OQS_STATUS (*sigs_remaining)(uint64_t *remain, const uint8_t *secret_key); /** * Total number of signatures @@ -141,7 +168,7 @@ typedef struct OQS_SIG_STFL { * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*sigs_total)(size_t *total, const uint8_t *secret_key); + OQS_STATUS (*sigs_total)(uint64_t *total, const uint8_t *secret_key); } OQS_SIG_STFL; @@ -162,10 +189,10 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { void *secret_key_data; /* Function that returns the total number of signatures for the secret key */ - unsigned long long (*sigs_total)(const OQS_SIG_STFL_SECRET_KEY *secret_key); + uint64_t (*sigs_total)(const OQS_SIG_STFL_SECRET_KEY *secret_key); /* Function that returns the number of signatures left for the secret key */ - unsigned long long (*sigs_left)(const OQS_SIG_STFL_SECRET_KEY *secret_key); + uint64_t (*sigs_left)(const OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Secret Key retrieval Function @@ -284,7 +311,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, size_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, uint64_t *remain, const uint8_t *secret_key); /** * * Total number of signatures @@ -294,7 +321,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, size_t * * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, size_t *max, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, uint64_t *max, const uint8_t *secret_key); /** * Frees an OQS_SIG_STFL object that was constructed by OQS_SIG_STFL_new. @@ -314,6 +341,14 @@ OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig); */ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_name); +/** + * Frees an OQS_SIG_STFL_SECRET_KEY **inner** data that was constructed by OQS_SECRET_KEY_new. + * + * @param[in] sig The OQS_SIG_STFL_SECRET_KEY object to free. + * @return OQS_SUCCESS if successful, or OQS_ERROR if the object could not be freed. + */ +void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); + /** * Frees an OQS_SIG_STFL_SECRET_KEY object that was constructed by OQS_SECRET_KEY_new. * diff --git a/src/sig_stfl/xmss/CMakeLists.txt b/src/sig_stfl/xmss/CMakeLists.txt index 83bfc2be5e..b4b3038c69 100644 --- a/src/sig_stfl/xmss/CMakeLists.txt +++ b/src/sig_stfl/xmss/CMakeLists.txt @@ -2,21 +2,183 @@ set(_XMSS_OBJS "") -set(SRCS external/hash.c +set(SRCS external/core_hash.c + external/hash.c external/hash_address.c external/params.c - external/utils.c - external/wots.c + external/utils.c + external/wots.c external/xmss.c external/xmss_commons.c - ) - + external/xmss_core_fast.c +) + if (OQS_ENABLE_SIG_STFL_xmss_sha256_h10) - add_compile_definitions(OQS_ENABLE_SIG_STFL_xmss_sha256_h10) - set (SRCS ${SRCS} sig_stfl_xmss_sha256_h10.c external/core_hash.c external/xmss_core.c) + add_library(xmss_sha256_h10 OBJECT sig_stfl_xmss_sha256_h10.c ${SRCS}) + target_compile_options(xmss_sha256_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha256_h10 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_sha256_h16) + add_library(xmss_sha256_h16 OBJECT sig_stfl_xmss_sha256_h16.c ${SRCS}) + target_compile_options(xmss_sha256_h16 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha256_h16 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_sha256_h20) + add_library(xmss_sha256_h20 OBJECT sig_stfl_xmss_sha256_h20.c ${SRCS}) + target_compile_options(xmss_sha256_h20 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha256_h20 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_shake128_h10) + add_library(xmss_shake128_h10 OBJECT sig_stfl_xmss_shake128_h10.c ${SRCS}) + target_compile_options(xmss_shake128_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake128_h10 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_shake128_h16) + add_library(xmss_shake128_h16 OBJECT sig_stfl_xmss_shake128_h16.c ${SRCS}) + target_compile_options(xmss_shake128_h16 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake128_h16 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_shake128_h20) + add_library(xmss_shake128_h20 OBJECT sig_stfl_xmss_shake128_h20.c ${SRCS}) + target_compile_options(xmss_shake128_h20 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake128_h20 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_sha512_h10) + add_library(xmss_sha512_h10 OBJECT sig_stfl_xmss_sha512_h10.c ${SRCS}) + target_compile_options(xmss_sha512_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha512_h10 -DHASH=6) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_sha512_h16) + add_library(xmss_sha512_h16 OBJECT sig_stfl_xmss_sha512_h16.c ${SRCS}) + target_compile_options(xmss_sha512_h16 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha512_h16 -DHASH=6) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_sha512_h20) + add_library(xmss_sha512_h20 OBJECT sig_stfl_xmss_sha512_h20.c ${SRCS}) + target_compile_options(xmss_sha512_h20 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha512_h20 -DHASH=6) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_shake256_h10) + add_library(xmss_shake256_h10 OBJECT sig_stfl_xmss_shake256_h10.c ${SRCS}) + target_compile_options(xmss_shake256_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake256_h10 -DHASH=7) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_shake256_h16) + add_library(xmss_shake256_h16 OBJECT sig_stfl_xmss_shake256_h16.c ${SRCS}) + target_compile_options(xmss_shake256_h16 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake256_h16 -DHASH=7) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmss_shake256_h20) + add_library(xmss_shake256_h20 OBJECT sig_stfl_xmss_shake256_h20.c ${SRCS}) + target_compile_options(xmss_shake256_h20 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake256_h20 -DHASH=7) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2) + add_library(xmssmt_sha256_h20_2 OBJECT sig_stfl_xmssmt_sha256_h20_2.c ${SRCS}) + target_compile_options(xmssmt_sha256_h20_2 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h20_2 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4) + add_library(xmssmt_sha256_h20_4 OBJECT sig_stfl_xmssmt_sha256_h20_4.c ${SRCS}) + target_compile_options(xmssmt_sha256_h20_4 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h20_4 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() +if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2) + add_library(xmssmt_sha256_h40_2 OBJECT sig_stfl_xmssmt_sha256_h40_2.c ${SRCS}) + target_compile_options(xmssmt_sha256_h40_2 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h40_2 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4) + add_library(xmssmt_sha256_h40_4 OBJECT sig_stfl_xmssmt_sha256_h40_4.c ${SRCS}) + target_compile_options(xmssmt_sha256_h40_4 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h40_4 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8) + add_library(xmssmt_sha256_h40_8 OBJECT sig_stfl_xmssmt_sha256_h40_8.c ${SRCS}) + target_compile_options(xmssmt_sha256_h40_8 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h40_8 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3) + add_library(xmssmt_sha256_h60_3 OBJECT sig_stfl_xmssmt_sha256_h60_3.c ${SRCS}) + target_compile_options(xmssmt_sha256_h60_3 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h60_3 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6) + add_library(xmssmt_sha256_h60_6 OBJECT sig_stfl_xmssmt_sha256_h60_6.c ${SRCS}) + target_compile_options(xmssmt_sha256_h60_6 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h60_6 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12) + add_library(xmssmt_sha256_h60_12 OBJECT sig_stfl_xmssmt_sha256_h60_12.c ${SRCS}) + target_compile_options(xmssmt_sha256_h60_12 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h60_12 -DHASH=3) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2) + add_library(xmssmt_shake128_h20_2 OBJECT sig_stfl_xmssmt_shake128_h20_2.c ${SRCS}) + target_compile_options(xmssmt_shake128_h20_2 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h20_2 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4) + add_library(xmssmt_shake128_h20_4 OBJECT sig_stfl_xmssmt_shake128_h20_4.c ${SRCS}) + target_compile_options(xmssmt_shake128_h20_4 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h20_4 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2) + add_library(xmssmt_shake128_h40_2 OBJECT sig_stfl_xmssmt_shake128_h40_2.c ${SRCS}) + target_compile_options(xmssmt_shake128_h40_2 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h40_2 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4) + add_library(xmssmt_shake128_h40_4 OBJECT sig_stfl_xmssmt_shake128_h40_4.c ${SRCS}) + target_compile_options(xmssmt_shake128_h40_4 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h40_4 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8) + add_library(xmssmt_shake128_h40_8 OBJECT sig_stfl_xmssmt_shake128_h40_8.c ${SRCS}) + target_compile_options(xmssmt_shake128_h40_8 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h40_8 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3) + add_library(xmssmt_shake128_h60_3 OBJECT sig_stfl_xmssmt_shake128_h60_3.c ${SRCS}) + target_compile_options(xmssmt_shake128_h60_3 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h60_3 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6) + add_library(xmssmt_shake128_h60_6 OBJECT sig_stfl_xmssmt_shake128_h60_6.c ${SRCS}) + target_compile_options(xmssmt_shake128_h60_6 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h60_6 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() + +if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12) + add_library(xmssmt_shake128_h60_12 OBJECT sig_stfl_xmssmt_shake128_h60_12.c ${SRCS}) + target_compile_options(xmssmt_shake128_h60_12 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h60_12 -DHASH=4) + set(_XMSS_OBJS ${_XMSS_OBJS} $) +endif() -add_library(xmss OBJECT ${SRCS}) -set(_XMSS_OBJS ${_XMSS_OBJS} $) set(XMSS_OBJS ${_XMSS_OBJS} PARENT_SCOPE) diff --git a/src/sig_stfl/xmss/external/core_hash.c b/src/sig_stfl/xmss/external/core_hash.c index 5df78cb998..565e571e36 100644 --- a/src/sig_stfl/xmss/external/core_hash.c +++ b/src/sig_stfl/xmss/external/core_hash.c @@ -1,14 +1,38 @@ #include #include -#include "hash.h" +#include "core_hash.h" +#include int core_hash(const xmss_params *params, unsigned char *out, - const unsigned char *in, unsigned long long inlen) -{ -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 - (void)params; - OQS_SHA2_sha256(out, in, inlen); - return 0; + const unsigned char *in, unsigned long long inlen) { + + (void)params; +#if HASH == XMSS_CORE_HASH_SHA256_N24 + unsigned char buf[32]; + OQS_SHA2_sha256(buf, in, inlen); + memcpy(out, buf, 24); + +#elif HASH == XMSS_CORE_HASH_SHAKE256_N24 + OQS_SHA3_shake256(out, 24, in, inlen); + +#elif HASH == XMSS_CORE_HASH_SHA256_N32 + OQS_SHA2_sha256(out, in, inlen); + +#elif HASH == XMSS_CORE_HASH_SHAKE128_N32 + OQS_SHA3_shake128(out, 32, in, inlen); + +#elif HASH == XMSS_CORE_HASH_SHAKE256_N32 + OQS_SHA3_shake256(out, 32, in, inlen); + +#elif HASH == XMSS_CORE_HASH_SHA512_N64 + OQS_SHA2_sha512(out, in, inlen); + +#elif HASH == XMSS_CORE_HASH_SHAKE256_N64 + OQS_SHA3_shake256(out, 64, in, inlen); +#else + return -1; #endif -} + + return 0; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/external/core_hash.h b/src/sig_stfl/xmss/external/core_hash.h new file mode 100644 index 0000000000..f350857d14 --- /dev/null +++ b/src/sig_stfl/xmss/external/core_hash.h @@ -0,0 +1,23 @@ +#ifndef CORE_HASH +#define CORE_HASH + +#include "namespace.h" +#include "params.h" + +// N = 24 +#define XMSS_CORE_HASH_SHA256_N24 1 +#define XMSS_CORE_HASH_SHAKE256_N24 2 +// N = 32 +#define XMSS_CORE_HASH_SHA256_N32 3 +#define XMSS_CORE_HASH_SHAKE128_N32 4 +#define XMSS_CORE_HASH_SHAKE256_N32 5 +// N = 64 +#define XMSS_CORE_HASH_SHA512_N64 6 +#define XMSS_CORE_HASH_SHAKE256_N64 7 + +#define core_hash XMSS_PARAMS_INNER_CORE_HASH(core_hash) +int core_hash(const xmss_params *params, + unsigned char *out, + const unsigned char *in, unsigned long long inlen); + +#endif diff --git a/src/sig_stfl/xmss/external/hash.h b/src/sig_stfl/xmss/external/hash.h index 5a3d750b07..076b3b56ec 100644 --- a/src/sig_stfl/xmss/external/hash.h +++ b/src/sig_stfl/xmss/external/hash.h @@ -3,15 +3,11 @@ #include #include "params.h" +#include "core_hash.h" #define addr_to_bytes XMSS_INNER_NAMESPACE(addr_to_bytes) void addr_to_bytes(unsigned char *bytes, const uint32_t addr[8]); -#define core_hash XMSS_INNER_NAMESPACE(core_hash) -int core_hash(const xmss_params *params, - unsigned char *out, - const unsigned char *in, unsigned long long inlen); - #define prf XMSS_INNER_NAMESPACE(prf) int prf(const xmss_params *params, unsigned char *out, const unsigned char in[32], diff --git a/src/sig_stfl/xmss/external/namespace.h b/src/sig_stfl/xmss/external/namespace.h index d593a85c53..468388aa3b 100644 --- a/src/sig_stfl/xmss/external/namespace.h +++ b/src/sig_stfl/xmss/external/namespace.h @@ -1,14 +1,18 @@ #ifndef XMSS_NAMESPACE_H #define XMSS_NAMESPACE_H +#define XMSS__(prefix, funcname) prefix##_##funcname +#define XMSS_(prefix, funcname) XMSS__(prefix, funcname) +#define __XMSS(funcname, postfix) funcname##_##postfix +#define _XMSS(funcname, postfix) __XMSS(funcname, postfix) + +#define XMSS_PARAMS _XMSS(oqs_sig_stfl, XMSS_PARAMS_NAMESPACE) +#define XMSS_PARAMS_INNER _XMSS(_XMSS(oqs_sig_stfl, XMSS_PARAMS_NAMESPACE), inner) +#define XMSS_PARAMS_INNER_CORE _XMSS(_XMSS(oqs_sig_stfl, XMSS_PARAMS_NAMESPACE), inner) -#define XMSS_PARAMS oqs_sig_stfl_xmss -#define XMSS_PARAMS_INNER oqs_sig_stfl_xmss_inner +#define XMSS_PARAMS_INNER_CORE_HASH(funcname) XMSS_(XMSS_PARAMS_INNER_CORE, funcname) #define XMSS_NAMESPACE(funcname) XMSS_(XMSS_PARAMS, funcname) #define XMSS_INNER_NAMESPACE(funcname) XMSS_(XMSS_PARAMS_INNER, funcname) -#define XMSS_(prefix, funcname) XMSS__(prefix, funcname) -#define XMSS__(prefix, funcname) prefix ## _ ## funcname - #endif diff --git a/src/sig_stfl/xmss/external/xmss.c b/src/sig_stfl/xmss/external/xmss.c index 401e0deebe..53ea10c24a 100644 --- a/src/sig_stfl/xmss/external/xmss.c +++ b/src/sig_stfl/xmss/external/xmss.c @@ -276,7 +276,7 @@ int xmssmt_total_signatures(unsigned long long *max, const unsigned char *sk) oid |= sk[XMSS_OID_LEN - i - 1] << (i * 8); } - if (xmss_parse_oid(¶ms, oid)) { + if (xmssmt_parse_oid(¶ms, oid)) { *max = 0; return -1; } diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c index c0517cbb29..b3de5f17f0 100644 --- a/src/sig_stfl/xmss/external/xmss_core_fast.c +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -165,6 +165,9 @@ static void memswap(void *a, void *b, void *t, unsigned long long len) static void deep_state_swap(const xmss_params *params, bds_state *a, bds_state *b) { + if (a->stack == NULL || b->stack == NULL) { + return; + } // TODO this is extremely ugly and should be refactored // TODO right now, this ensures that both 'stack' and 'retain' fit unsigned char t[ @@ -231,7 +234,7 @@ static void treehash_init(const xmss_params *params, set_type(node_addr, 2); uint32_t lastnode, i; - unsigned char stack[(height+1)*params->n]; + unsigned char *stack = calloc((height+1)*params->n, sizeof(unsigned char)); unsigned int stacklevels[height+1]; unsigned int stackoffset=0; unsigned int nodeh; @@ -279,6 +282,8 @@ static void treehash_init(const xmss_params *params, for (i = 0; i < params->n; i++) { node[i] = stack[i]; } + + OQS_MEM_insecure_free(stack); } static void treehash_update(const xmss_params *params, @@ -378,6 +383,10 @@ static char bds_state_update(const xmss_params *params, const unsigned char *pub_seed, const uint32_t addr[8]) { + if (state == NULL || state->stacklevels == NULL) { + return -1; + } + uint32_t ltree_addr[8] = {0}; uint32_t node_addr[8] = {0}; uint32_t ots_addr[8] = {0}; @@ -586,6 +595,11 @@ int xmss_core_sign(const xmss_params *params, unsigned char *sm, unsigned long long *smlen, const unsigned char *m, unsigned long long mlen) { + if (params->full_height > 60) { + // Unsupport Tree height + return -2; + } + const unsigned char *pub_root = sk + params->index_bytes + 2*params->n; uint16_t i = 0; @@ -599,8 +613,8 @@ int xmss_core_sign(const xmss_params *params, xmss_deserialize_state(params, &state, sk); // Extract SK - unsigned long idx = ((unsigned long)sk[0] << 24) | ((unsigned long)sk[1] << 16) | ((unsigned long)sk[2] << 8) | sk[3]; - + unsigned long long idx = ((unsigned long long)sk[0] << 24) | ((unsigned long long)sk[1] << 16) | ((unsigned long long)sk[2] << 8) | sk[3]; + /* Check if we can still sign with this sk. * If not, return -2 * @@ -619,8 +633,6 @@ int xmss_core_sign(const xmss_params *params, memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); if (idx > ((1ULL << params->full_height) - 1)) return -2; // We already used all one-time keys - if ((params->full_height == 64) && (idx == ((1ULL << params->full_height) - 1))) - return -2; // We already used all one-time keys } unsigned char sk_seed[params->n]; @@ -710,7 +722,6 @@ int xmss_core_sign(const xmss_params *params, bds_treehash_update(params, &state, (params->tree_height - params->bds_k) >> 1, sk_seed, pub_seed, ots_addr); } - sm += params->tree_height*params->n; *smlen += params->tree_height*params->n; /* Write the updated BDS state back into sk. */ @@ -787,6 +798,11 @@ int xmssmt_core_sign(const xmss_params *params, unsigned char *sm, unsigned long long *smlen, const unsigned char *m, unsigned long long mlen) { + if (params == NULL || params->full_height > 60) { + // Unsupport parameter + return -1; + } + const unsigned char *pub_root = sk + params->index_bytes + 2*params->n; uint64_t idx_tree; @@ -805,13 +821,23 @@ int xmssmt_core_sign(const xmss_params *params, uint32_t ots_addr[8] = {0}; unsigned char idx_bytes_32[32]; - unsigned char *wots_sigs; + unsigned char *wots_sigs = NULL; + unsigned long long prefix_length = params->padding_len + 3*params->n; + unsigned char m_with_prefix[mlen + prefix_length]; + int ret = 0; // TODO refactor BDS state not to need separate treehash instances - bds_state states[2*params->d - 1]; + bds_state *states = calloc(2*params->d - 1, sizeof(bds_state)); treehash_inst treehash[(2*params->d - 1) * (params->tree_height - params->bds_k)]; for (i = 0; i < 2*params->d - 1; i++) { + states[i].stack = NULL; + states[i].stackoffset = 0; + states[i].stacklevels = NULL; + states[i].auth = NULL; + states[i].keep = NULL; states[i].treehash = treehash + i * (params->tree_height - params->bds_k); + states[i].retain = NULL; + states[i].next_leaf = 0; } xmssmt_deserialize_state(params, states, &wots_sigs, sk); @@ -838,10 +864,11 @@ int xmssmt_core_sign(const xmss_params *params, // has to make sure that this happens on disk. memset(sk, 0xFF, params->index_bytes); memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); - if (idx > ((1ULL << params->full_height) - 1)) - return -2; // We already used all one-time keys - if ((params->full_height == 64) && (idx == ((1ULL << params->full_height) - 1))) - return -2; // We already used all one-time keys + if (idx > ((1ULL << params->full_height) - 1)) { + // We already used all one-time keys + ret = -2; + goto cleanup; + } } memcpy(sk_seed, sk+params->index_bytes, params->n); @@ -867,8 +894,6 @@ int xmssmt_core_sign(const xmss_params *params, /* Already put the message in the right place, to make it easier to prepend * things when computing the hash over the message. */ - unsigned long long prefix_length = params->padding_len + 3*params->n; - unsigned char m_with_prefix[mlen + prefix_length]; memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); memcpy(m_with_prefix + prefix_length, m, mlen); @@ -929,6 +954,10 @@ int xmssmt_core_sign(const xmss_params *params, *smlen += params->wots_sig_bytes; // put AUTH nodes in place + if (states[i].auth == NULL) { + ret = -1; + goto cleanup; + } memcpy(sm, states[i].auth, params->tree_height*params->n); sm += params->tree_height*params->n; *smlen += params->tree_height*params->n; @@ -963,7 +992,7 @@ int xmssmt_core_sign(const xmss_params *params, } } else if (idx < (1ULL << params->full_height) - 1) { - deep_state_swap(params, states+params->d + i, states + i); + deep_state_swap(params, &states[params->d + i], &states[i]); set_layer_addr(ots_addr, (i+1)); set_tree_addr(ots_addr, ((idx + 1) >> ((i+2) * params->tree_height))); @@ -983,6 +1012,10 @@ int xmssmt_core_sign(const xmss_params *params, } xmssmt_serialize_state(params, sk, states); + goto cleanup; - return 0; +cleanup: + OQS_MEM_insecure_free(states); + + return ret; } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index e932f3f063..1fbc305b29 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -8,19 +8,489 @@ #define XMSS_OID_LEN 4 void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); +/* + * | Algorithms | oid | sk | pk | sig | n | + * |-------------------------------|------|--------|-----|------|----| + * | XMSS-SHA2_10_256 | 0x01 | 1373 | 64 | 2500 | 32 | + * | XMSS-SHA2_16_256 | 0x02 | 2093 | 64 | 2692 | 32 | + * | XMSS-SHA2_20_256 | 0x03 | 2573 | 64 | 2820 | 32 | + * + * | XMSS-SHAKE_10_256 | 0x07 | 1373 | 64 | 2500 | 32 | + * | XMSS-SHAKE_16_256 | 0x08 | 2093 | 64 | 2692 | 32 | + * | XMSS-SHAKE_20_256 | 0x09 | 2573 | 64 | 2820 | 32 | + * + * | XMSS-SHA2_10_512 | 0x04 | 2653 | 128 | 9092 | 64 | + * | XMSS-SHA2_16_512 | 0x05 | 4045 | 128 | 9476 | 64 | + * | XMSS-SHA2_20_512 | 0x06 | 4973 | 128 | 9732 | 64 | + * + * | XMSS-SHAKE_10_512 | 0x0a | 2653 | 128 | 9092 | 64 | + * | XMSS-SHAKE_16_512 | 0x0b | 4045 | 128 | 9476 | 64 | + * | XMSS-SHAKE_20_512 | 0x0c | 4973 | 128 | 9732 | 64 | + * + * | XMSSMT-SHA2_20/2_256 | 0x01 | 5998 | 64 | 4963 | 32 | + * | XMSSMT-SHA2_20/4_256 | 0x02 | 10938 | 64 | 9251 | 32 | + * | XMSSMT-SHA2_40/2_256 | 0x03 | 9600 | 64 | 5605 | 32 | + * | XMSSMT-SHA2_40/4_256 | 0x04 | 15252 | 64 | 9893 | 32 | + * | XMSSMT-SHA2_40/8_256 | 0x05 | 24516 | 64 | 18469 | 32 | + * | XMSSMT-SHA2_60/3_256 | 0x06 | 16629 | 64 | 8392 | 32 | + * | XMSSMT-SHA2_60/6_256 | 0x07 | 24507 | 64 | 14824 | 32 | + * | XMSSMT-SHA2_60/12_256 | 0x08 | 38095 | 64 | 27688 | 32 | + * + * | XMSSMT-SHAKE_20/2_256 | 0x11 | 5998 | 64 | 4963 | 32 | + * | XMSSMT-SHAKE_20/4_256 | 0x12 | 10938 | 64 | 9251 | 32 | + * | XMSSMT-SHAKE_40/2_256 | 0x13 | 9600 | 64 | 5605 | 32 | + * | XMSSMT-SHAKE_40/4_256 | 0x14 | 15252 | 64 | 9893 | 32 | + * | XMSSMT-SHAKE_40/8_256 | 0x15 | 24516 | 64 | 18469 | 32 | + * | XMSSMT-SHAKE_60/3_256 | 0x16 | 16629 | 64 | 8392 | 32 | + * | XMSSMT-SHAKE_60/6_256 | 0x17 | 24507 | 64 | 14824 | 32 | + * | XMSSMT-SHAKE_60/12_256 | 0x18 | 38095 | 64 | 27688 | 32 | + */ + #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 -#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature 2500 +#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk (1373 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk (64 + XMSS_OID_LEN) -#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk (132 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature 2500 OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(size_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(size_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + +#define OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk (2093 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha256_h16_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha256_h16_length_signature 2692 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h16_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + +#define OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk (2573 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha256_h20_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha256_h20_length_signature 2820 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h20_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h10 + +#define OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk (1373 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake128_h10_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake128_h10_length_signature 2500 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h10_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + +#define OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk (2093 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake128_h16_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake128_h16_length_signature 2692 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h16_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + +#define OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk (2573 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake128_h20_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake128_h20_length_signature 2820 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h20_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h10 + +#define OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk (2653 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha512_h10_length_pk (128 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha512_h10_length_signature 9092 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h10_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + +#define OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk (4045 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha512_h16_length_pk (128 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha512_h16_length_signature 9476 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h16_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + +#define OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk (4973 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha512_h20_length_pk (128 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_sha512_h20_length_signature 9732 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h20_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h10 + +#define OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk (2653 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake256_h10_length_pk (128 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake256_h10_length_signature 9092 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h10_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + +#define OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk (4045 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake256_h16_length_pk (128 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake256_h16_length_signature 9476 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h16_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + +#define OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk (4973 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake256_h20_length_pk (128 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmss_shake256_h20_length_signature 9732 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h20_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2 + +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk (5998 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_signature 4963 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4 + +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk (10938 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_signature 9251 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk (9600 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_signature 5605 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4 + +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk (15252 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_signature 9893 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8 + +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk (24516 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_signature 18469 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk (16629 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_signature 8392 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6 + +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk (24507 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_signature 14824 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12 + +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk (38095 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_signature 27688 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2 + +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk (5998 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_signature 4963 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4 + +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk (10938 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_signature 9251 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk (9600 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_signature 5605 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4 + +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk (15252 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_signature 9893 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8 + +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk (24516 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_signature 18469 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk (16629 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_signature 8392 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 + +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk (24507 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_signature 14824 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(uint64_t *total, const uint8_t *secret_key); + +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 + +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk (38095 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_pk (64 + XMSS_OID_LEN) +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_signature 27688 + +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(uint64_t *total, const uint8_t *secret_key); #endif diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index cfb6899af6..aa812bd22c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -71,8 +71,8 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint return OQS_ERROR; } - const uint32_t xmss_sha256_h10_oid = 0x00000001; - if (oqs_sig_stfl_xmss_xmss_keypair(public_key, secret_key, xmss_sha256_h10_oid)) { + const uint32_t xmss_sha256_h10_oid = 0x01; + if (xmss_keypair(public_key, secret_key, xmss_sha256_h10_oid)) { return OQS_ERROR; } @@ -86,7 +86,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, siz } unsigned long long sig_length = 0; - if (oqs_sig_stfl_xmss_xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -100,46 +100,38 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const return OQS_ERROR; } - if (oqs_sig_stfl_xmss_xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(size_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - unsigned long long remaining_signatures = 0; - if (oqs_sig_stfl_xmss_xmss_remaining_signatures(&remaining_signatures, secret_key)) { + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { return OQS_ERROR; } - *remain = (size_t) remaining_signatures; + *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(size_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(uint64_t *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - unsigned long long total_signatures = 0; - if (oqs_sig_stfl_xmss_xmss_total_signatures(&total_signatures, secret_key)) { + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { return OQS_ERROR; } - *total = (size_t) total_signatures; + *total = (uint64_t) total_signatures; return OQS_SUCCESS; } -void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk) { - if (sk == NULL) { - return; - } - - OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); - sk->secret_key_data = NULL; -} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c new file mode 100644 index 0000000000..d613a4f9c0 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHA2_16_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h16_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHA2_16_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h16_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h16_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h16_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_sha256_h16_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_sha256_h16_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_sha256_h16_oid = 0x02; + if (xmss_keypair(public_key, secret_key, xmss_sha256_h16_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c new file mode 100644 index 0000000000..5d40092b9c --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHA2_16_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h20_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHA2_20_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h20_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h20_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h20_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_sha256_h20_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_sha256_h20_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_sha256_h20_oid = 0x03; + if (xmss_keypair(public_key, secret_key, xmss_sha256_h20_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c new file mode 100644 index 0000000000..81a1b85c5f --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHA2_10_512 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h10_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHA2_10_512"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha512_h10_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_sha512_h10_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_sha512_h10_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_sha512_h10_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_sha512_h10_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_sha512_h10_oid = 0x04; + if (xmss_keypair(public_key, secret_key, xmss_sha512_h10_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c new file mode 100644 index 0000000000..b99b429fbd --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHA2_16_512 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h16_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHA2_16_512"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha512_h16_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_sha512_h16_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_sha512_h16_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_sha512_h16_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_sha512_h16_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_sha512_h16_oid = 0x05; + if (xmss_keypair(public_key, secret_key, xmss_sha512_h16_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c new file mode 100644 index 0000000000..8c618b8bd7 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHA2_20_512 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h20_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHA2_20_512"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha512_h20_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_sha512_h20_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_sha512_h20_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_sha512_h20_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_sha512_h20_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_sha512_h20_oid = 0x06; + if (xmss_keypair(public_key, secret_key, xmss_sha512_h20_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c new file mode 100644 index 0000000000..efc4c6ed5d --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHAKE_10_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h10_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHAKE_10_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake128_h10_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_shake128_h10_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_shake128_h10_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_shake128_h10_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_shake128_h10_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_shake128_h10_oid = 0x07; + if (xmss_keypair(public_key, secret_key, xmss_shake128_h10_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c new file mode 100644 index 0000000000..948e29b597 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHAKE_10_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h16_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHAKE_16_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake128_h16_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_shake128_h16_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_shake128_h16_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_shake128_h16_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_shake128_h16_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_shake128_h16_oid = 0x08; + if (xmss_keypair(public_key, secret_key, xmss_shake128_h16_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c new file mode 100644 index 0000000000..9e9d330da7 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHAKE_10_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h20_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHAKE_20_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake128_h20_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_shake128_h20_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_shake128_h20_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_shake128_h20_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_shake128_h20_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_shake128_h20_oid = 0x09; + if (xmss_keypair(public_key, secret_key, xmss_shake128_h20_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c new file mode 100644 index 0000000000..e96c5da22a --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHAKE_10_512 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h10_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHAKE_10_512"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake256_h10_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_shake256_h10_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_shake256_h10_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_shake256_h10_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_shake256_h10_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_shake256_h10_oid = 0x0a; + if (xmss_keypair(public_key, secret_key, xmss_shake256_h10_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c new file mode 100644 index 0000000000..b90fe2cc79 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHAKE_16_512 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h16_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHAKE_16_512"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake256_h16_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_shake256_h16_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_shake256_h16_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_shake256_h16_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_shake256_h16_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_shake256_h16_oid = 0x0b; + if (xmss_keypair(public_key, secret_key, xmss_shake256_h16_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c new file mode 100644 index 0000000000..53a88db04b --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSS-SHAKE_20_512 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h20_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSS-SHAKE_20_512"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake256_h20_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmss_shake256_h20_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmss_shake256_h20_keypair; + sig->sign = OQS_SIG_STFL_alg_xmss_shake256_h20_sign; + sig->verify = OQS_SIG_STFL_alg_xmss_shake256_h20_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmss_shake256_h20_oid = 0x0c; + if (xmss_keypair(public_key, secret_key, xmss_shake256_h20_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmss_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c new file mode 100644 index 0000000000..b5c1df16af --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHA2_20/2_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHA2_20/2_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_sha256_h20_2_oid = 0x01; + if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h20_2_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c new file mode 100644 index 0000000000..2bad4a33a2 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHA2_20/4_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHA2_20/4_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_sha256_h20_4_oid = 0x02; + if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h20_4_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c new file mode 100644 index 0000000000..c1a0243e96 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHA2_40/2_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHA2_40/2_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_sha256_h40_2_oid = 0x03; + if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h40_2_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c new file mode 100644 index 0000000000..9835724a5c --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHA2_40/4_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHA2_40/4_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_sha256_h40_4_oid = 0x04; + if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h40_4_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c new file mode 100644 index 0000000000..ed223acdd7 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHA2_40/8_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHA2_40/8_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_sha256_h40_8_oid = 0x05; + if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h40_8_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c new file mode 100644 index 0000000000..de9253552d --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHA2_60/12_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHA2_60/12_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_sha256_h60_12_oid = 0x08; + if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h60_12_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c new file mode 100644 index 0000000000..7e54ff760c --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHA2_60/3_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHA2_60/3_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_sha256_h60_3_oid = 0x06; + if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h60_3_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c new file mode 100644 index 0000000000..49d870dec0 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHA2_60/6_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHA2_60/6_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_sha256_h60_6_oid = 0x07; + if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h60_6_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c new file mode 100644 index 0000000000..5a66fc4e96 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHAKE_20/2_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHAKE_20/2_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_shake128_h20_2_oid = 0x11; + if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h20_2_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c new file mode 100644 index 0000000000..163689fc33 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHAKE_20/4_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHAKE_20/4_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_shake128_h20_4_oid = 0x12; + if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h20_4_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c new file mode 100644 index 0000000000..9e59b72d19 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHAKE_40/2_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHAKE_40/2_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_shake128_h40_2_oid = 0x13; + if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h40_2_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c new file mode 100644 index 0000000000..4dbd11f836 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHAKE_40/4_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHAKE_40/4_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_shake128_h40_4_oid = 0x14; + if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h40_4_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c new file mode 100644 index 0000000000..91223579b6 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHAKE_40/8_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHAKE_40/8_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_shake128_h40_8_oid = 0x15; + if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h40_8_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c new file mode 100644 index 0000000000..e480d2d5e7 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHAKE_60/12_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHAKE_60/12_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_shake128_h60_12_oid = 0x18; + if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h60_12_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c new file mode 100644 index 0000000000..3904bd43b5 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHAKE_60/3_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHAKE_60/3_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_shake128_h60_3_oid = 0x16; + if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h60_3_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c new file mode 100644 index 0000000000..b6cf53cfe0 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -0,0 +1,136 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +// ======================== XMSSMT-SHAKE_60/6_256 ======================== // + +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->method_name = "XMSSMT-SHAKE_60/6_256"; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_pk; + sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk; + sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_signature; + + sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair; + sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign; + sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify; + sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining; + sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk; + + // Assign the sigs_left and sigs_max functions + sk->sigs_left = NULL; + sk->sigs_total = NULL; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + memset(sk->secret_key_data, 0, sk->length_secret_key); + + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (public_key == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + const uint32_t xmssmt_shake128_h60_6_oid = 0x17; + if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h60_6_oid)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + unsigned long long sig_length = 0; + if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + return OQS_ERROR; + } + *signature_len = (size_t) sig_length; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t remaining_signatures = 0; + if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + return OQS_ERROR; + } + *remain = (uint64_t) remaining_signatures; + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(uint64_t *total, const uint8_t *secret_key) { + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + uint64_t total_signatures = 0; + if (xmssmt_total_signatures(&total_signatures, secret_key)) { + return OQS_ERROR; + } + *total = (uint64_t) total_signatures; + + return OQS_SUCCESS; +} \ No newline at end of file diff --git a/tests/KATs/sig_stfl/kats.json b/tests/KATs/sig_stfl/kats.json index 8be3ea457f..7ed8350ad1 100644 --- a/tests/KATs/sig_stfl/kats.json +++ b/tests/KATs/sig_stfl/kats.json @@ -1,3 +1,30 @@ { - "XMSS-SHA2_10_256": "e71e6a390fe09c275e0fa0996d938d554d01548da229fe159ccab48e6525ae8b" + "XMSS-SHA2_10_256": "4ff9ea00bec98f790a5b5e96ddb8441d58e646d679a47f02db21085c35a006f4", + "XMSS-SHA2_16_256": "398ef810276efaeabc84780816950a9243be0b37122f33db556010a5ec606a8d", + "XMSS-SHA2_20_256": "d695061163e3a5124222a6d3202f1e397cde65733b84d700196a9c55b7d721a2", + "XMSS-SHAKE_10_256": "b5ec13a0eceb7cc1bd14f2288557b7dcb431c3c930ed8eb2d09be32eca52f722", + "XMSS-SHAKE_16_256": "2875eafcdad20e964c6abf4d90bdb73e1ab47fd2e636ed949502fff9f77ea94f", + "XMSS-SHAKE_20_256": "7e78a5792165d0ba1484f4cca60985373be475fbf1047e58997798b2048f5048", + "XMSS-SHA2_10_512": "791840f9f015bad6df9138d2ced1690daea746f65d54826ce85a6ba38211d16c", + "XMSS-SHA2_16_512": "c060814c9e029d9272c8942bb3f9a5ca46cf361e59c16bf70065476243095196", + "XMSS-SHA2_20_512": "c5684bba5d53983cf3c52b45ca0b443a38102573cae4aeab5e4a911b02b0fe47", + "XMSS-SHAKE_10_512": "edd6ff8923afdefa3ad7b5158f2adc90eb58c377b847c5c35508546a7ea2ca3c", + "XMSS-SHAKE_16_512": "537540146232f6647c215e32ae057fc9cf3e83932a6447953c7f9ac5d38eccf0", + "XMSS-SHAKE_20_512": "e803f3af92cea3f8004a94484f8f666b306fa353c3b09e9e0763b63f7f9b20d6", + "XMSSMT-SHA2_20/2_256": "da52ae24ebd6fb3ef85a80d83357835164a292fd8c0e83a32c21d386969d5c0b", + "XMSSMT-SHA2_20/4_256": "eb5a0afd967f660714b1b9bb6a214f348cfeb06e474048c94d6e08de183b78fe", + "XMSSMT-SHA2_40/2_256": "0cb74272d179eaefc180303cfaaaed13093268ead2b6e3d066228b64077609ee", + "XMSSMT-SHA2_40/4_256": "16a7047724db2ff45999a4e95048bae3bac5d645986d6670014c53478412b4f1", + "XMSSMT-SHA2_40/8_256": "fff5c6a02f8995342199155052ac5115af6340ff9e729a1609c815c891797111", + "XMSSMT-SHA2_60/12_256": "2e5869150c17da8c13094b66a94a94342d62d035fa63bd972757f3eda2c9c248", + "XMSSMT-SHA2_60/3_256": "04b10f0320cd77b8094b1116d67085b38a0d68f02aa9b0ec5938a511ece1ef6f", + "XMSSMT-SHA2_60/6_256": "0ea5be22f851a84e1bbbc21a84dfb5c5a5d2f5d636dbae49e1e092e6ec5833f9", + "XMSSMT-SHAKE_20/2_256": "5893c3acc4ab1448510888ca6c6f483d1ed247028900752d11d2ec9dea77356d", + "XMSSMT-SHAKE_20/4_256": "eece12452652dc37d1600b39e4bf589ac12bee6d5e5025845bc06c7e5321669e", + "XMSSMT-SHAKE_40/2_256" : "c5a539dc3cd7af4710362c3e9962137e33e4061099bb2dd0a03eff862c9cd01d", + "XMSSMT-SHAKE_40/4_256" : "b25c826e97d442ade70dff6e7008e95c099d7cde6f533fb9059299d9e1ff200c", + "XMSSMT-SHAKE_40/8_256" : "cf301b7d978d5c0afcdf3300ba97d829e2e5f737cb449968b19b45f05b987591", + "XMSSMT-SHAKE_60/3_256" : "09d26df5e911e98e71ef73a1ab6f224964d4a7beacd8071b4c7f7d1930a537bd", + "XMSSMT-SHAKE_60/6_256" : "0692a32e318d5c3ac8631120910b783edfed4cb7ed69e3ffa29f83aaa34e27d5", + "XMSSMT-SHAKE_60/12_256" : "1a05ff4a4fea850a5fe5c9e976006577335eab0494e1759fe217c2f33f5a84e6" } \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp index 5641aa1e9c..ea0bef3312 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp @@ -1,182 +1,14 @@ # XMSS-SHA2_10_256 -pk = 0000000157A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -sk = 0000000100000000061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +pk = 00000001B901B8D9332FE458EB6DE87AF74655D0B5AD936A66FDB6AC9D1B8CF25BB6DB8404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 -seed = D260779A680342EFB7D244B1333C2FC9884B85CDB7B96F8EEEAF5FC7FBDBABF9A0AA3F0E7238F97142BCF1C561731CFE +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 mlen = 33 -msg = BBCB0A3E0F49152C2D8022F5AAB8AD5E80E81934BC66D468AB76F141D4E741937D +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 2500 -sm = 00000000404DFF9B9F3931FE6158FFF355A8EE715C9BC6A87FE6627928F3CA1055FA70105CAE69218E377931AC690634219BE00AE5320712465A2B736772BA10311D81DD6E16DE90489D3963F80022BCA055736187CA55BE285B83537CE987CFECF1401D6B7DFFDA5087F9586D35A22FC8B42A3FA29A2A5F4BE53E17A9CB8D42942B5E187796E96704F8CC77119F33BAEB06B1140A484E881C4385C31F5D7D16C842E348320D1CE3556DEDB800385B782AC949821203199969DBC2F2652C256E91157096E07E49BE3133DCDD305CBB4F2077D5DE4D29C431A2968F50AB5501512524666CA7B2268C159CB047FC54ED490A963C2A7A4E936C407176C1DE9142CF8BC0CD4FE2AC3C011F531564A1B93D4BB59867CF655C9F170C5BDC6A62D93562168EF99760160982B28667681DE3D81832DA109CE5D6D3E919C459063AAA6C58D1AF2616C4198F41A8969C0F2F67DE6417390E170912482D75E5E18EB1CCA84E6914765546E3452E1219F438FDCC57D3AF82DCE3DD8B69E58FAA28B1983BDA064CE1DBA6886F23C77B2FE6F6A1427FE94649C25E1366079C5008F7E6E9DE0EFD7E8792BF1EF0948B621D309BA771BECA0592BD5D4D23AA8BD0C469D5C7D5DF396D1D75C17F8C5D632A753C32CDCCB1A3896C2C54172D1871737319A3C326AF497D7216A6CB1DF7AAA231912F2AEC85392DE82D4648B27970075EEAE2BD1A6A8A7A49B51A973B852799338E04C136EC1CB3F84825C35A7CDE243C5025B36ABD240D4698438E9323E310E320EF0833677E35A6D02DF5838C26277241C354ED9130BA6086E333168D84664AC66BDF26A3ACBC4B4D67312564FA30E94B3B7C22A1D9F4A2DF2F8458B0715E3670EBEA3B6F3CABEF3C4282E821A2BA2F2B21D16F1D130F56BBAA8CC6F5EDCC37148BB069D3404288D2BFF211193A839ABCBFEFA3069F6101A45595AAF5CDCF3F2565C14BD5AEB26642608E029600F5F973EA4952EBB78C74E0A6D5B9BCD4CE7C9A3BFD982083885AD7F92B3ED09BA1EF566A1640DA41F49325320727B0D0ED87B3EF4ACA88E3C698627C67D9E9EA656F3D66E369320CFF7D2958E9F66CB5379F66C8E69DBEE19350CD95A84055592D46C2C42606EF6B4EF63B31269665A7F2B5A00B492D60C9FAEC0FF5057D9D50D858DB86B85D902681FC873F8F865CAD7358B5EE4169CDDAC13307900AC1CB241225283861E0B871D1A56B2F433367341F7718C80AF69ABA1C359C91B4271E7A46E86522180DBD9ECB3842AF76F7757F50F243748E7F13246533B1D90CBFAD3185B781B5388C2FC0C36D08CEEAC757245ECFB9BEF58AE28F535601FB4379DEF650FB39E1C00C072E8E51BF8BE96CD88C66F2EDABF4DD04263A0B02B56196DB9106A62D98C284C839B1B4D19C8FF0FFAFAFEB732CDFFF7B5D7D65E5D4DD3D84C631439CB133033A27561C1271EA45A509AF7995511A09F2E294E8B33CE0B64EA29322E55004A7E4FEF5EF089080BDB3C2DD2AF979F46C4715E0602DFC16E8EA9FB7DD1E47A872900903B214EE7A1595C3C254F598B7460DB51FA12204A97B280E83AD0F796757D6C9E7CC6BC53F8E17DF6AC34F8450566E9E4DBD4FF2FAA4755577DFB8E90229F5B15F418C3E290AF21754336F25254BAE436E9C6839D07E45D56A0821110DBF193E1E95448A43EACE60B461F47937072A051B4C3C0D17489E393B47F2290269F171E22C571364B7F906B79C69668BA0AF81DF30C3D4AB906F5E47B50C0AB0143E9BEDF247A0EB562DB0898C104A6CCECE457033784C2640FFBC073E01E354BF068D3416B2FCC5837309FE2019CDB053F42E63EA1B1683898C506B89C6B2D390F745D3A14FFDAF9AFF26F73AE79CBA225D9A5FDCFE9CA7041D38D991064AA5D32D5CEB0A97DB58F3B5FE894FCC983F71662F4EBB6C067AF9FCA95222229AA497F8E1F9BCDDE0C59216068B0B284F148306974E3E8D785615CDD5002357D423103F02F490D3CBE413D0C9A5108444FBC85048D14AFECBD57FCD6A863155D62D6B4061F5941E989F1C10869047F82BDA5FAA6BAE01359F5CDAA5474B2EF78C4A3499D95FA85106849AF8A80F439B30DEA0D60D187F49BB5C26B05A14822D8F257C4110A2684FA444630777D6610AD8E6B08D0ECD0433B9077DA8853E9F567358300FE457B521C03B89C7B77CFBA948DB2A6BF87FDC39F1C349EFC00C17356298DDA38FD48095BAAF5B346DE3B1CCF91018785869FDD98EF8F7C12189DC13D473458228851B48725130D439AE5AD57CC700A27B51ED54380D80D80E5A770EDF368A56762E7CB037D59E73D311572411A466B7934E9B9292332F73407951CF9294CD541D4ADBC9CB624C3ED57FA33F67A72BA1AA9BB8DC95FF10B8DB6F23F996A31CA87D5DC0086BE4FA7BC7EEDFCC1D32D6D84A99618B6998FCB4A791FF9EE0855A4A7C6B5C4796E9E213C2DA5B205D5255C71B6F97D5067E5A8A579664AF2C73D5A949FCD43B36DC423E34BCBD72575D2E74DE56A97A5440F84BC2408F10E8DE519C3685D4AE28F395C52615B3B03F5D4C45D9D2C207B74734CAFA0C924822DC3E495B496C892C7556446F14BCE82DC2AAD295A65A7E6C4358311B04882FCD05B066A46B6A98FB3C2AEC438247683AD2A2DF295EC5D42B638F91E9E67DFC4B4A33831BAFE5D1C8CD6AB95A431A16D3FAF05080B1DC25B8B882BD29E2F8BDDC1407E493C5D5DB11423AC490954C66A924ADAD04842DE902ECFC37436DC6A736BB2004784599EE80ECB66B2EA06224C5961E5DB97AEF1EE4CE7D0A70C61BAF568023479601A7CAD8CDD2AE929D0C1AFA811FDEAEC6216E74516036E7E9E0E2A1E169DE38221869E46E6EE4325D37102ABE9709356223F80A4D259F45AD260AEFD801B8052A55E9848F9976497A14475D98DF3F1EB9EAC832F44C0981BA49037C116F6CDBDCF0FF043B96D225DFDF54CD890408F824CDE256CE8788601AE0705140253EFF336F060DA6855A3403EE9833C898A9E602401EF67C593A8AAE02C5BBBF8383E68C71BE4583B423CEC8E3D7CCE0C4652A9FE6097AAD64C5FC1588AC9CCDEBA3C6E435AF86E29F25399BD4EC118F665E4CC9D59327F129CECA4F359EB0547BEC24FC3E7D74B1125892F02AEBEDD1AB9A7611C4FEE5ACBB9BA8634169DB9AC73BB0704D1F8F6098CA76F2FA504D8825564A30A1D7E6E12690DE34C0521FE70D15714626DEBC8008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 0000000100000001061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD +sm = 00000000404DFF9B9F3931FE6158FFF355A8EE715C9BC6A87FE6627928F3CA1055FA7010C534B0D4C6FFDF4DBFE00E72405EFE83BBCF19AA2030A8CB163808482B6376FF8CE01FB8090F4842896A1EA5E9282F35CACD245A4B9DE9FE84E9315851D68A72B3ECB9F440937C8BA4AC3F0429246CBC2777E8B92D84F4BA49FAB89465FCB0FC8017E582746F531B4697925154A22E2D6A0F1B81913438000C295153D7ADCA8F852C50D360F65F887479E9631A2CA30FE3AD92E7BF648643835F4F8CC081A6C951B83B77608A08C021821DA61962CFCC8E97D75441921D39C5AD537543EFBAF0345DC70826E6E950929570C72E51619600C58D932A72657B19AF163E0B8F7AAF2949A5EB26C517909E0E663E36753491182975206009107509DFFC898D308B903E84A8B29718BF7125397AFF5467D53CF8F36EB945B6B98D48E81C0174A0E03541D24369CF8EDDA4288FFA615D16FBC7355CFC0966BA9256E5B8A44DA95760DFB61301B10FD3E82436E267DB089773E43B984297D1E0D395DCC77FCFECCEFEBD4B80B3F241872EA251DA466CA6C5324346F4B5E6886654A86592641A8C32AC554261B2D9130462C976B039E593F873AD1712820FF3E723FE57F137751AB3CA8B5B20D28D1B9384DF1D710AC39FAF699989418B7856C2034C695A693ECC336EB472DE5049C743089529695B028F2F72BE0893E59169E9A2376C64BC5CCAC5482E5A6E9C88D710A3FF8F23C206B09D314BF50568228B1BACF1CE330D529BD3793D7C7CD9EC770C111D9681D6F1B97D908CBBD436444853FEB47F234D31F5E92B9E0465D67AC0FE48859126BEFA7F7D121A67C2C2970B37B8081B4E73C5A21A41F60160A61FAFBD48649A3D2032C1679A67F348E3E25275FCD9AF650937FEB0A30F25878CEED7D6CA693518B5A2F5418135EA9316EFFDECDB1DFFC9EE3A62EFF0E66F3D05BD9D5F8679B536BB6D39792B28DF2481A6EECB9BEE40B11A10D39A90EA1AAC47BF956FBFE9B0427B599B9BC024F326515E71615419423FEC3F19F621D49B6EED59F129A6B1411B7B1AFCF073095D57B03F25A16F946ED716BF705F567A151BE85B8E8195CC2F070BFD482702182B8A4A43ED942F6BD3CBF9DE7E8AEB17C41E1C009C94FF4A2050E3731088B75474B38DC52BADF53C7DCD3FB98D023649FC4799CE060ADDACEC7CD4E656074E631C1CB8AEF88EFEE0817C2E3D79E287F4510E48DFB7E23CB49D6FCA39A1E0F471F16A8BB65AF02150D059036D00386DD287BEA4D52FB263B57AE5ADD901CADE838B1D7347D9E47EAF6456148C6C4E44B0FA3DFCF5C9CEC2D80AD509A65AEF0E3E663B7F31BCA437311BA799D4C2ACC138F85D73CB40792FF03F8F20427D951444990CA3976A71368A7DC1455E880722F06F02163BC712E852A914F22E5675EB9B1C6C8B7FD20A8880AD2EEF97982C065C937BD3639357E4C7450CBDA0B51CCA8E3E078DC760FD99EBF646B82369576539B2BD5B2C866ED5AE94423A5CE18C685352398D01C983F080D7BEB8A9243AAA9AC1DDCC1B058B92BEAD301E8F3B8F5EF71EEE7966302B44D2E26D2A02393713E5D4D3FEF42196FAA368274C78C2932D22840ECA6018CE7D16B19A0727CB1966EB28B57D137C5264CC2E627F24A3BAD50EA4F75C7BD8998709C01ED5ACFFF0891934E94DA2CACCA212FB48BE3F9EAA310547E73C388D881F36AE21EFEDD23744F6B07C5D6D2776C191ED41E607316F61BBEF7A20E1A03150AE833D18952AE35188FBFDFA55C12A388836717BB2BDD97E89121C56C3B53E8198242315C9E438512E0C8354A3E599CB7217AE688647A72985606BBD0720F6FA5C5B6F70E88234EE54C6DB0A41106C866564650829FE4B232635B06B18240C9F86369C75B2F7D237211A380C43F95D362E0680D9EA2CA47E1DC8C49703E22650B765F847AD86BE25A3B7630D640A0097632DF13F600E8A025DD9A1FC67B0EB09C1CA9FA3923896927DEE1E3CC0C81F4B82E43B89CACC69C9B8ADCA1670F7D4E50DB7BCD94C2115E75F2BFD2336DA5A304D0F3455927360BF5040E95D1454106F2A8A7CD27D5510E7B5BE7B5B9EDEFDC3D4249D655C51F4C1DBA0F359BE4769AB66EDBC802824E9AB866E8EEAA2FEB1CC855F0A745AAC84A610DF0238112C6519F8E7346C45331A6036F84D5B6250F4B5BC0A2A6A31DAF9C60EB13C20CC649A18E27A6C98B82F08E21706A8BDF338CC69C1679D25ECFF733A721211C1F6DD28091AAA9C93B047EFCD2C8A55F2DA65E616F07DCC0F44081D4E359C1688A00F062EC925D24432862B547BB70F2AF126A3DABA5C918B224DE444B8733E6FA601B3D349307E94583D0EC976AEDA2B90972324B3ACE8C7B79A67723AEA037E12DA9EFA9CA9668A4F5FDADFB9EEE13398921F5023E354A6894825431DBA7317E6A6F69F0E77294BCD02D7616E75AC31EC528FC070B8C34027C4E9CD0672903412FCA6B723650D56AF562069312FC7EF1891A77E1A3F29D810C205EE212E75863F3B8B1ED216DF888ADD07AFF45F1B5C01196329311414797CD5F67FFC54AAD04C803FF7E83C2E8BA224CE83695BB7916AC42B1861F5CB527FDBCD82DBFA31C5ACF981D8414203837504263C96A0015841FBCC721F96D50A86D6E096AB54AF9980F06CEE6341C78D6583F6BAE8081B3C44B0F10FB7300874B5011FF0F97C52F975A31355884C2F12B6FFEE20E8371D38183C9D04977BFA037C9BD4DD7F7CE203FD7FAD3852B3C2AE9D078ADEC70DB1A7140EF1114EBB03E8DE03237E0A27FF510015AC76FCEFE4EBD4C3A1B6C67DB2A82FE2B1BF18723DB0F29FE4AD47B2EEF22AC3C6661CFA7DA7476D23B470FA2E0441B6473EBD291791F09B4ADA70A5286EB05167BD59BFD8C46427413D60692382EFB7882F60DC53AAAFDF2014CA7D27F8FA93C187A8371B41796557AE739912E5991C713532E81FA57F9BA562E1D3026D2D2D7373D99871BC62768AD70D3DB184EABED83E30C11C9BC62F3340923A0082B987EC45CC7BD1DB4B2B15E8AD3EAD74E96D8C20D85617BBEDC0BDAF8ED48B7EE8D7C42990028EC0669AFC0861C22F2E9109F9BB35426BDDB4A69EB8F45CD5B226F92E8026F1E62DE1DE435A4FC0CAEDA91C38A88F0037BDB296CD7B07FF040B1E08F02711E946B307A5A38487F53070985B8E28BE6CCE809F34100F0CA780996CD38E91BA7773BB632D0BE7978F3AF3A92B961BD3A8759590726D6C1811F9E0BCA87377334E7C1F12FE37401CA0200823938C816ED98981521470F7F2CCDD69D85E7530EBF39E3A592B1C09BC6C352C3FDB108FB26E7ACD3D5A4FC0442962E2C09651AC0D026E370F1EE1A8219C4833D70793D6E581FD25B0E95FAB1EDA67232C2FA12C4E379A6627E75AD408C1D2526005F2567CED8608E88CF53064FCDC58007198ADFA860F9FED1DF80EFACC768A0A063E1AFEE6DF1BE3483105B1C45EB50BF7863B4278422CEBA9001EA00299AC0415BF28A9C49CC2E92FC15565B547538A027886C6EB0D83B71138CE1A remain = 1022 -max = 1023 - -count = 1 -seed = 4AF2A48BFB8912E1209AE0B00C0B52CD84183E9D2B0D63E1C9DC7E3B2920874CBBABDEBD47BF4CAA5E19B4C6BEB96D8D -mlen = 66 -msg = B81C782E781F6D005B891EAF89527B7AF65AEE14E0B668EAB7A1EC5AE188B391A733B7707E42A7AF3699ECAF1A43453C2CFE0ED61233CFF68F35F4A84ADA949812FC -smlen = 2500 -smsklen = 136 -sk = 0000000100000002061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1021 -max = 1023 - -count = 2 -seed = E7D9E1A1D2B81EFE0556C01A7386489B692F4669717A09BB491A7DEC9893F44D2758E633658AB5479168CC719711E2ED -mlen = 99 -msg = 955F970C4CEA3EDFBA0CDCA55FBF59EDF24663E837973E11658FCDD8307A9101FA2E13C4CB23F588EFF1A5201C77E9F734EAB8C76A7C5DF78A6DD8DC5F17DCFBEEED73C7B940F6D4B711CB8856B2E1653D246506DAFD05EE812D6476B53C920E0ADB6F -smlen = 2500 -sm = 00000002C8299416D392EA9885BC2583B1AC67F96AD84D563D0C301C02EA868E744C7BA3C1C7DCB7ACD5DAB40839E3945B0784FF1AD07B1E52812722E7E525CFA0B0615721FCE84472139AFAA7E03AB9D43D62C1C9F71FF0B83EE68E13E96E2D61F27BAFA1FBF91365E6E2AE524E2781040BD0040AE61C59F2BD111C6A67F4F348F25710EA652F452FFDD770306DCF94AAB169F987EAE7F7FB2617A492F9DA54BEE07689400BA5C77FBF6EA54D933F8B84D82664CBCA37FA896294DD3CB06165DCC1CC71083D74D6EEB4C0CC84864C038A52E7BCECBA7E026E4F1ABD3AD53A24F4A0F6A56DF3E0A45AF1F015FB39B04D695ABD9767EEE724D542DE41C23CE1360A69C6A0AECBBB5FA37B67777B066276DD82EF020ADCDEDE2087999C418351EFC54FC1787855C75DE7041402F8EE569D5AE49DADC3E7501F4FC1D9C7AA685E9647BEA04075EC25C3D1C4DDAE1DAB5DBC54A403B7B8B1BBB96751953B33275CFD3B1EB733292E94B32648E31BD4C6591E9705A09598C9C3F9B1FFCDEB10FC9A47C6D4B6B5E45493CC706FE39F27EA164F88DF41E164A16AE2B248E547F4198BD08A5530B5E54089FD91B6F93C533AADC2FE8C1833C8C364A047809E733036A632A91B9EE037FFDAB49021952A3808C4B8E3AD4CCCC7DD28B61C51897E4A5E0A99EC095900D5AD1A2C15685A9D8F56059AC53EAF595374DBA8E2AD2929F8ED6E1C6304831A9D6E3BE0AA1B5681C04D2E8A0300231C121CC1E92B9526D8E797822A7C5718399AFDC5306A868C20BC0F54DBEB95FA711EC79E53F0E1320FAC24BFADCEBA31B956370596A49A071C7A766EBE2118D73F2E39EB59E78BE49F74765FA0134C9B73DCA1A839FB9CC70388FE51E18922B67CF4D08765084E11CE5D45AAF87DD932AE5647C5AC2F88CBCE3FAF67C6035F40781D219C01B84A6728BD4DCD1B173C91FC69798EF1E6EC4F6E8C48A1ED68B917B7D35F3DDC88553F816A4C0F084F56E7D245430F13902459AD609E2EE59B0CDBFC46B823B0922EE41373AF43702E9F093972EE41CAD6F128317B718E87E1FA6185ADFD4C1AFEC61083E3BA5A0D22CE367FD25B98BD3A660399CD4D8A7F608C4BC0CDDE993E57EF92C1FD6EECA542D94FDD77BB0A4B1B99CE7D7E53347B7CCCE13FDA6F8F458DED1B91CAE8CED28FF8D7E39C4F144832E3223E874507BE3AB9718F6240DE0A18CF2DDCD2786940DA86517B3CBE792D5095707ACC08758CBBC307A263FA31A736F6E61EB09EF6BFF82BA7A3273B619878568D62E21D1F15A758E1E83DDCAE6BDE013494DA308A55B5B1E2FFEAF690E04BF725A3C998250067D6320A9A61B3156A5F2A4B4D53BECD0169A0C10BCC0494C2B51BA2C4904CB6A36F7D302810829CBD03E11A8BEDFE4A1ED70FF1E28992B0BBAB3BB43EDD2BBEC8C943E9382B47E24E442264060C61A826EE9812EF305EF83DFA429B7BB0DAAD700AFD47C91F01D046B398B877FF896B437DEB2D4489016CAC266D5B970013229EA33C93909B75ED6755F2FE72E1E3C90613866F85862E70227320B98A4183C4D5C04135A54987088FB17B56D1868102D1B928FC2801ABAF7B05EF137427317EA41BC44564C7BA0A4D7B1A11E494FA15D2915C5AF412AC1CE800A713528774E7B3A74FE03B83F4E30E85570F8BDA6274CF673819B6D43A4B5723B6F06E5B4C55A0D87A424816817AF489E51E8ABDBE6401FAF4732EAAC864E4A6CDD22976BE385E2EE95613FDC2743A7F9A1D60B57C364A58F4F49D414C419671852CE004CF21A2A612BA8157FD0BB2A8A2B630583AC660AF8D220C628BDEAE4973CA3BD6ACCE2193EC091E5F39B7BF0F6AE5CDCC606DBDE2FB25C81106D1B9096D22BC5562B1FD0459BF4DDB6DA835C4C63056D93EF434A55A09CF08053F05FC36FB05425A34E0203B17652B243A2330EAF2F3643EF9A38E3148D71A6B1DA95E4ABCB40376E606FA666623A2597D537B30B0846CD393CFFEF276D91656137FB596E9D9906265764B37DF4725C2BCF0E6E3BD3CFEA76CE098151FACD13AF3D43DBF1E0046ECEEC801CB1FDFB9DF6EBC5117199D98E8C60C5693D629B52334342A4605CF12C7DA172C094E6A48A74A1601F057B3DBE7D5EFB8699339A0EA6DE835507F830C3F36F5B7BAF338E3CBDFAA42E79DA29CBE2C64431890592D97485BCE2608E8B34788A17914CD59B485FFE5297BD2860AA661EB69456862EC5C68C9F5E365F90C1E42BA3B0AFDF3AF05859929EE65DEFE3C54117C05931164C42C6598C85F48D46F0AD243E59EAF0165439D934A56AAA3EEC4B123178BB2828C4F1A19484D3B832E1D376A3BCBBBB13DF1F792CF11BA16E2AC13A000431B48050E581D31696F40D1BFB3C17E98E240F2F8A49D0407E42C80169D19B37EC4046D3D60A15310DC58781060C0B53380667B7B0A13128789C0A9C83486C25F244C1549E80C7769ED738F3E00ED937CB5910B8DCF67F9EB7AED39FAB6F5C7EE9FA05CDED2148CA9E3DF2DF81B9643DF4538FD888A1BF99BEEA7378EA6B6EB86868514A9EF808FF1071FFF8D5D48A2BE6AE9D2404D9AC87D394B3A533CCE8C4A656DC649975BA1CB7F631F210BD285B0FF1BB6874B2B81A9848AED264BA8224889D65C0C64FAA546A6ECD9BC5674FAFC959C1418C0A3662A7DFAE6BDE9DCCEA5B5BDAD952DFC7FB1B969078189F691578B0F5F30343311CF6C1E629CC292A1746104BF422EC21422C15283525D9A3ACDCC9014366F20E2E17BB6D3039DCD8395C61905C23B540F4BB01E817E23FC3723E4AC95FF04BDBDBDC7D70AA1621E7C3AA13E9AC66F057EC0DC6CCF460F969CEEA3002206B2BF88093E28C24F70F1704FAE79F6521951C5B714AA2F0837A179D7B6B49C438D4CE5A8DFC8D660735C1FFF405E406ADF6EEB8D01172B4CCBA596DCCA0C1C92E50AC42D6C5F2E440D25C796456B756D4C857B0E46EDFCA5B5B648A9662C16AF94EFBCB1511027721DBE0537176E4808FDFA6A226E5552A279DE132C70DE7504A5B61A036A86A67EF126FF6F609A4887B589F12FD447180A82EE1BB355DC3216777E0A698D7BF588226E4D442E50847743F3E300BFC9EECC8C8888F69FECF8E95A015A5998F0E1BC3B4948C0EEA76004F507747FA63CDF4A10E802DC40928F4192B84EC2A9FB98D7DBD6AA556098CA76F2FA504D8825564A30A1D7E6E12690DE34C0521FE70D15714626DEBC8008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 0000000100000003061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1020 -max = 1023 - -count = 3 -seed = A344668712D7FF31F511B249BAD15D46C184C9D38442540190DD21E5E784989C56CFB7CDA3336E290F1344AC5AFFFCD1 -mlen = 132 -msg = 3472BE99A4F7CD9261B7F97B0A846790A252CF5A53035D4A6A31B5425F0852F0A63E630D97CC57A455EEF0FA171F7A06C0454D8D3713D47638C01BDB4855DE167C33019780B5EAB0D521E80F536D354756DB0D253A83674F74BE657B0B5681E0696C4294C80B712743EF9AFEC9AE6424C8C8A1810D4BB010F47FEC835AF7F65B40586CFC -smlen = 2500 -sm = 0000000368D0AF9AB3B4981A5A3687839F654ED9958EA0B19666AB0A0D13C7ACA213DB148F827E8E20518BCCBA7D22ABE71110838318A6A5FAB7278330DEFEE172F470802774094D528C66BF6CF628E256721F18E998AC89E94F4CC64B87D4A7B33CBD2EF85DC2FEC2584EA9B7A65C674917AA475663107C608FBF993520F53E87966D52C2C13C93E7B84AF63F2ADA035DADC96B0E4B3FCFA8C1C4F9C3C96866D0ACA6C7942A9C15EC1D25754A12E86B88E4903A1922D10C6378DCFE38CC7ADEB898384718ED44C328936A0C0254B76D6B6E2BEF0175B1C1CB700E724DC4CADEDFAFD35C7D054E351B7AF0E82762710952790318BE12D2D860E8635E7803A1222D4ABF87EA0D656B659D634F0454A730BB92D5E80CA6446BD798021D6B6D19FFF79859BB30D70D77144591CB86ECFC91F3236AD24176B2E8FD36DE8FED94344B3D6DCE6C136830E439ADB5C558B5DB23F5531C07DDE74EB158774D566B086EECCC5C5A7EC0EA44F1996FE3A9D3B8C39990CFED6E9D9A29B8360672B0B9F3D1B50F66775868B7EB8E94FDC741D21B7DF68E9404188EAA65965944F2036EB61F41F504D3796A154024CA4CEE846F948D67A13F820F045B4F92576749BC63692A1C184F20544C301255510F4F869721362B71D46A1B3FC103C97D16139770A8FC3A5304D7B0A82BF68518B8F6246DB32F6A73E787C6DA515D788951132F3DA9C6854599F0B97612F0D26A0AC31B0F28C87509FCD1B044E60322181263AA54DB4E2DAD046D81973EA7FD836A66D2826947DAEF5BB7C9646605E245F4AE8C331D39C585E5912D09A596D5EB66B9DBCF3765E9DF7F79BCE194FB3788A24E22210171FB985E573FE67488A941D7141B041038EA1A1E2DA34898EB8C0D79290657222ADEB49B5696D0211B9B748FEF3CF99FDF7F9FA234F5ED38BCAC44A716AD831D1085CD7CED7AE5C24B2A3C28FBF0970B4C367FF65D650234E1ADCB9BF8D874C66B66AD48DD35D01703F8FDAFEB791574750946C6BEFE20E3BB291294153BBC0D4FDBB05801BB271C4E5D67E7CBE825F03C458065B60C4E30F645BCB7700EBD90400C80843D83F5C70E3B0A6F53BD12C6525D3E37AC18274714D5CA4F9FF0D5A199A679C1B361E845427623375CC168C626D7770F23FFD26BC8121F1F37914D9C6F7758D06CA02129433945C4C975BA76FEDC0EFEB4E447B81D9333145EB86212387381C20A8AD70209008A2EAD4B56A0BDC84B706FEC1ABE2C60A096B83E345405B64EADD4786238C59303E195C5C8DE499696CCE53CD1A469E06EEE0916EB84A04B46B7809A92B6664F97483091B3F239E14D947190CEEAC71B270A1CB730886490CD8847053B9DF24F82D7A857DA3DBE952349556469BB4AD4AD70156BD1D64AC13D822F43DBA949C54CB47B0E75D116E96CFE87BB0E5B21D643B45D143F5977AB27F53BF4724B3CAEC8DF9B158A2013943BB524D1956DDBFEEC65B49CBA2306CDC188A0F18D38728E44C13ED3D309FDF4E8D33F33308273B955620686B057BA2C84BCDECF0AD37C19B4960C5B1B06D89F151E437E8963627EB667D41DF5A1BB89B271E3A5DC2DA0541B13B1212FB2578EF75013B1BFA40944D685041E82958A195475E95132C8B17BF2A090D54B00558773964B2BFC8B1EF89FEB193F0A0646C32FF4CFF26B3EFC3770662A75C3BD7D93FC58C68FE89CEBDE9B4E8C522A81E9DFA925ADCD471E27315BE08E3FD414A558ACB91D0C8BFAD659F1C45D2BE45B1B62CCECDC048EAA7B386F90244E3C2473DD550A3FDF5E1EA3DA65E789065918F8C920586AE31B8DEB3BF6442DC9FC09186CA79221850E4CA7D42CA426DBE5544E0CDA7CC27DFE210739C5D2D5A0AAD80C0F3BFFF0805F71805B5C668CFED02443CDA7A36F8FD317D8E24FEDC58385E31CB94BE00B84F5CCD188A6F0762E4F2CFE25DF4136F70892CAF5AE197556EC733C161661DABF09C3C3CA9F600E23DC9FCD9C843EA4412B2A6E0C5FAA0E67755453FC72DB4024F6A6C09ECEC00FEAF0E8AADA220317902A734CA430C84E5699DE750674A9F7CAB447DBB937E431018A050ADF6D526246767F7CB0DDF8D63BF122831FDC1686670825CA16A261534A48E712D0A5E0E68A77265EFAD238D63310B616E036C198F73D88EE6FAA0A7352A108695DC86C0CB4FEEE07719B876DCB7604C180416F6057E32455A0D7C8920DFEC3B91B9BC873629CA3D001467059D66C9E2EF4F31E2C92178C27CF24B9722FFE355C32A14951B75D53D8ED8FFA99693BD41AAD51964F7E44AD6477F9D2CE0DA2DF930AEE3904338222C51133132B0FC497A1F0B822CFB2DFC449E10F7D5B080B89920B486518FEA8AC14CF572D373A823EBC0733206DCCE604450000CA95838163BC0DB200509110E1A877221F3CDFD74DCB4895AD12AE02F30352627DA55CE4FCC0752BC84D0D88C702A030952D6A7BB43FA817D2DDABC20E5D49E8B165F2A828E1E8A0CD2E65A56287083F88F11E6D6FA76255EC84E8554E607B7F427E408A5BDF93436F9F45C2C5E850E521E12ACE3CE6964859EC4EF0B3193C3FEAF199B7B1C52EFC3617231425954F781AD53472D1312ED78A9B53C2948C2CC281E74EA8FD843265D296A0053F28EC6EE9D02BA1634A3E0A7A62C316E691CA98D5948880EF1A4210030964892AFF3E326AC29526AAA79AD83A65590F223B7E102CB44F49A2BD383887385D9FC294E5FACF72E7D358E212819DCD08AA6C0CBC366CA970DB76EE5F2FDBD89F84FA7766BAA12105E26645E9AA93DA0015C16A8C67D8C53263E83D276770C393F8807C2FDA9000F3237D50A0C246EDFEEF87157AAE7173344B0E562A10C62F252AD8B31C25EBAB7BD44F51A70FE560D6391374ACD07BFD372EF6FA019CFD1F938AAA6A243942809F13952161094F08DCA33C02F988217392F69DF32B4F8EE75AD6BF0EEB02C9A8EA177DC6C87B51B59E4CDB39C1C8E7269444E362B3755BEE8D8F9FE6D87E68B2452B2CE2B06A25FECD41D92EBB2C8F98C2548623DB4E4B37C486C85EA8F078772D5A679D6F08CC187675911260EB42DB4EEDB7D7B0C385EB20D612A9B8A8A9A515C8D5BDDEDBA678A89F26DEEC24B5AA0C071B27554573250CEEA76004F507747FA63CDF4A10E802DC40928F4192B84EC2A9FB98D7DBD6AA556098CA76F2FA504D8825564A30A1D7E6E12690DE34C0521FE70D15714626DEBC8008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 0000000100000004061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1019 -max = 1023 - -count = 4 -seed = 2629FBED0B88DCD29C3E7553B2B8C209455EEFFF7E8A3EDBA39BB1C2B4F3F1B0DAB5D1CE55060B1FAD562F945433DDC4 -mlen = 165 -msg = 1911306403C3C794EE57605D2FE311F4509324371103F69724087A7247687CD25FDD0C97319D6315E262EA581BB61987D5AAB33F331C7A7B260E92285C168DCECFC70D164D7A23110A165F456F22256A77AB7F0C5E5A69C91D7551ED437ABCB9B3101B8BD794D1939F372BEA8C5586BA15528BC4E4FEEBDD9904DF943513AA0E01FE67DF25E8F3075FC2EECB775DD2BE8D9D3EDFAD05762DD0BF1C228252BF2BFC7AD6A8A4 -smlen = 2500 -smsklen = 136 -sk = 0000000100000005061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1018 -max = 1023 - -count = 5 -seed = 13E884A522FABD17D2E055694A6D931C6459A17FDFA40131E19788DC572A47056670439565685510E54B3BB94D67226D -mlen = 198 -msg = 3A46A3D825C949B1E8E68F01B523B88347F0F249F6BDC0129A11CD46F11DAB4C11CB14FCD062A67A76C0EF2798D3586968EFBC619DD949ECBA08099B3A55F6917DD922DF985F769BBC53AA03D93E029DDE2B19FC02147BFE4B4756A560C75DEF13DB7104D5A6A238ABD0364A3B3EFB7A50754528D75E47FD8349B0D88569FCAF3382FB8C6C23CC52BB87B75454A0AFBAEC15F2A19EAEAD8C8FC15668CE37C8C1BBAA75F705B9804F2C942880C01C170D8CAA3C3743A91D569837DD84B50569F52302F8066600 -smlen = 2500 -sm = 0000000549F101925AB0FD811DF00BE2C75202021F2CD6DFBC82A8B38FB3A288863E316D4089B9994A97AE8AFC236A3C6B933AA82BF624CDFC8275E3D738E9F8B70B9F28705F444E6BA204F90AE9765DF09D51F8FD493B16385FB50C264D7FBEFC02912CBB280C74523E42361691E4415E749A27F3DB2F9E7145E9FA37A41E31316D5AE4AA386427D27F0C6989EAA280FBED66B67B3BFE1FE40F4C2B3C6829EFB834F0194E36A6D5B827747380A96C03FC8D21BE870FD98865BC822DB92A43413511AA3A0AB5EB2873A5E59764F5314677CDAF139B586A0FBD262A9C1672784156CDE6D5B933E36A67995B12FEE129EF362057ADD48C9F1B99251EA903975CA2D25036E74DC518F519A5182961B92256C810890595A156372328DD4DB4BA457A4CA4CF38B2F88AFB1420B5B63D295D38ADA7D44D7C818F7726CF566E5211E421B8DDCB20C265AEEB830AAFD60ED271067EF5B551A448CA78BBA817067D97D83A0696BCFEB6AAF5DAF64856CB08228CB09EC185C4ED7D6B331D49AE6AC8CB359D93B0C4AA7818C9B53B5B3DC7D08F4706EDEB62777707C0F322065B9A8AB683171115821677D85ECC1E7ABFEB6FDD609A7D1CE0CA13564E5723908FC997EB8B2D5C020EBCC82A09F3A03A49D2514003EAF26BEE005699C461069C7248DC80B903949B4652347FFE0361400DEC51D4513E48D4CA655A72B42633200259FFD2C00FF686F9A3678ED5BE780A1273CDF2DE1CE1BDD2EC627289D2407C7883A50BD752193944D927F9AAE86831475BCB5C933F053C46CC441A8007F4461397AD391F0E5BF9C40545FE403A7C2B82E25FB43578941554BB92BF47858AE719435DFCB6E34BFF2D018BF92C0A5F4DF75DB6F0BCB1E46B68F7ACB514CFBE11D2093DD8E966180EE009FEF7DC83B9E7D6126CBFE1172D32A74C9214D8FA7BB438B8225D213939151FCD463FE7AA412B0E5764359E43F2C8844D56B04ECE2CD254094DC351A8063FD892F4C04916DE2FF996E91F9C3AB7591F16ECAA108890F5AA4907BE6A99E5537DB234B5CA31927AE36835FA74F596A0E81D52DAC70E10AA0E5405D49136EDAF38838C37F2F76C195F7B3550E609FE6C8BB34038C0105EFC2469E367437F9BAA60B6B34D50584B4BD45AE85944A639734DC8D7FA21CCBED43811F9C593DBFE64DE8D7BBFEF68AD641137B40BCA3077EB58A632A09BB5EDA3C27EDBDB54E5AB1D7F430C9748C700BF4DC00E8820EC4CD825D899E1CFFC8428DF6698C0BA957281BF123A3EEA5F4110B32C36DFD114F54F3C89EC0475C46BE27A72D049D5F959457852BE47D7D88F91D5364C0DBA8A18AFF9CE8D7329562C1E89A7EB7AEA5E8F0039D89CEFED8A3E4BF04A201522C6EE71C17CAB5A93A063EDC4A3065372F089D7E41B435738F61C0B2E5F93DFE69B83F2BA25E2625DD27EE25D2777BB5472ACE985A4294D6A6496E3A99F02E0475F9A3ADB55E58A5B9F4B8345D931CC0119AA1820AE167DDD88423D632A563DBB0B22BF72105879594E5B09152324803258E981EFD9083FADD7E581F42AA9FBB109D63DDD83FD5635C58B9B8F3A53B8A2278BC7E8435CCF8C7E713552AD0A92854137F2F564CC9D659168CD8FF073623843957A342C9A78B4964A22DE1B1D72625F9B9F2F6C74FCA632FC09EDD8EDD2A5B846CDEE8ECB9CD932F16D6E3F23C0CA047A3F3E53B0BC18F442656AA1E271CF61C8A13A0CFBA7641A5A09713D75DC732CF9B29A73CFD5BCDD8F8ED2E8F3A1688AFB539CFF010D49641D753CBEB055985369F362C6D310C5FCDD2A270A2445E9CD5C8990BEB3A34C7C5BDD350CFE136E165C21BD7BF78FA4CB9174AA23F925D9824C2505E08A1FBE1D090E366D1BCD42978C6B48E855EB4A9693A3AE93C22B673695519976560C84188D3353C2EB5C864B71A3C66489DD368D3A83376ECA99AA7FA83709A12EF6FC1E6B82FB70FA258E7171761D963F2CC8CD2A4D30A1FBE73BFB606CA6114AE3F9D038FE259FDC1E5C552E49C21694D378EA54351313DD8740CAD5E6140526AA7EEC0627ADB8DCC5096425270CB32618FE5C6F068E934EC222248F80AB1718AF9E0E737588C1BF08F7B602ED635E060809F02F76238A7743774FCB1E6361FE16D4EE275F70A518FCDB1DEB675AD29873C78A651018B125FE05B61A124A336739CC0A5033A3E83FA87785FBC3C0BB14BDD143465505BDBF9FD96F3FFC6BEE0999CA1D857DCF6C6CBCE8520E7A5D095DB288FFF07D9B98F579DA18A374C1CE1C59A73AA409A8BE98B90415168FB55EFDD97EDEF5AEFD8B3B78F98565F1964CDBE714D1006F97F3D0DB5463974AF951DE47059C5F1215C7CA8ECFC34C9AEAC679C849E39AD4FF2C55D9917AEA1802E326B59D46538841333E6B3BC210D8217F4CA0F6D27695ECFC02EA7D24A04A10373FE455FC22B805147592954131E2F898B04CEC953DA2284DB98AEE5C19B4F9F527D8172A63AD650BACB3EB29097A171C1CC63CF98D01F0A36A3B2B74B683F9F5D14390A864461D1DD8E5E125C76C367A6FA5102C2DBC2250874DC395DF8D2B94B5627EF2C4242D067006F44544763F30A76D956B9E34EF0BA9FA7AACE7E15941DDEB407CE208AC58C82681BB9308CE30BA4F0D1CBE55174771EF0ABE277FD38C0C5506625D7F5B0CD361BA4BFEFFAFE08B9283A00267F71F5689F0D7F1D281C63A06003718881FBD01F425D7719393653D22882F039656D33EDDC4AFB3B15921D85D5896CC2C50085874D62AFE96FE98830A294F102768CE4D22548AB1C8E854783243A88C401402D7643C091CFD48CF6112E056AF6A9AEECC897F6B9FE951547CC633AE8C3A60C7C1DFAEE5A11908BAF8C77BBC92D851B52A7F49C5AEE0A3AB47FB65F49EB80E5E93453A022B0DF239BB99070BFCD354E2F7490841785AAA58F4655A1837E30A710BD43BB7DFB1A390D53E7D557E2630256989B4B945DA4A4FE88FACD5BABDBF179A7543C366E07BB0C77280613105CC9AAC4093E8A277130907AD172CFF1DC09C00BDB99687EBC2D59076E8E23E9CAA773C686AB2BAADE15865663C4D94834171FBE5A670FEE2FE269FA8394841FF6C2A3227E8EDE85215C74AB6A8C66DCB3B1C709614F01DE3EF6AE6F751B0A3F7C0F30D15B08B42EB0D30A5C1B528078FA366959BC1D592D86E3555A4820740E272AA2CD85C8E05202C13B89A93260496DED8FCD03F614D953E978008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 0000000100000006061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1017 -max = 1023 - -count = 6 -seed = 473EE54361C6786036B3540D9307B3C09FA9C85FA8A210CA9FBAA3690FCD7A0D9E64793F20E9D2D40F6426C0C7B7CC3A -mlen = 231 -msg = 8A2290A20898F46A2F922A0F9E2565C7E5AF20868E6C18D7D4F659C10F0A3FA2FC4BFB6BB19E9E09DADBAEE668F8A2FBD29B1591AB80738BA63EEEC291073B9DE0F5D44B53952C940DBECC8CFEAEC7B598135BEEAAEB2A0DFD8D55F9F51A10BEFCEFF594E74BF6FDB972BF4B9B514A03A5954C6FB09FB0640CD854ED6A9E62B4E98291C3DB7D2E19EB730A865CA6239869868F512BB38C4020FEB9554B9F5631E5A5ED00562B6A665CEA045CB66A5B7437EA4E2E55EF70656A9BE301CA3577CE909BA413A8A78371A493FAB5E89FB8D836E90F560857670E3761430A9364ACC32D7005543D8541 -smlen = 2500 -sm = 00000006EE07C35A8551A62496DE1C658EA679C4EB861964165B282F6BE686038253E3AB824C03BDFE794D985AF23AF4FE2C7D99E7B937CE00A56EEF7FB838EDD55B8B6F0F2351ED5A4BCA9A6069484DA843D459877DFDFF32CDF084A375C0AF4652683D10E44DEBF3C18F1DCC249934E0D3820BB77879ECB9569C4DDC24ED1AD4F7E8C8F3EA59866C2B1CA98BA038C06EBB90AD8D55C54D55C494DBC18B6CD68A92FD6250535E0470B9EB2BAAAEB5E138FDBED73008F6D78CA8AAC316BACCD9D26BB3D438C8E92E702F6DCF48B8BC696D633DBA5DC00683E55C823B14FEA4B3B515A78FCAAAF5E4ABABE932375B23F22F63128A331320E773B713A26C2F60787A82001DD43CD62E536F48B3EC2057E543D5A4269152FBE28B8DCEDD7D7E0619A29E17CAC3CD37B0FA7578739680E529225F1F339F4728145BAB14C18DC46C0AD95F20B9655DEF9749F7CFDD61B9B463A113082C3CC27524DED08D7E973CA017A6A783AA6B6593ED9BAA72026CD8F448D4568EDA5B5356EA1FA7383E6BE65C1C99506763CC75BDAC698537D492C6125A1898F336D4783337446A90DD492AB708FE436B28C94666C9575345B6E624E08D037240E93624C07B2A8A8D00A126783ADC599ED686332C26D8CE020490B8FF89DBDA3D922E30011436454AE5B56925BF0577BDCC9FA13DF431B2DD67E465CEB310470188850C4974CB29C49AE1DCAFEC474371973D863790FE4B5FCD5D1B6385F8A2E4D89D0B4F0C1B66F614633CA1C70E6B965FB35E287FEEE7C75C49EE8E779A3163C9088089D490E4F5499C5E7645253A193FE04FECD5DF49C1773EEFFD87C8D8E27C6807F66A1FB2F39A130B92281F37A0F5FA33D948E02EFA3F95AECA8E30E69F81AC0184E79715FBECA388468ECD41F93E518888ABF3F889617B27701D6A90B8C4C316E01821FDA25C675683AE08BDCB221D7D07E8F5886DDCFB8EA909A140B0EC9532170885AA44D8431A6AF7278B00F4BDA9E361592A552BA719C8C2D8B4789B4D7032DBC1BAEC2D54B58AA294926EFF7897A17DCF62C17CA8AADDE2CA9D535E17C45941F570371B0FC251B71668BDA3DF52F974E8D39E9588A3EFB5D67FD81E120E2FEEE49DDFBEA48C792E427A5BC2E31BA4486BAA224AFD29F8B44C4460D34F5ACE470B11830361102A0676D4F367716F4C337E33F599E6B109B0106E74C4F458AF084C47E52583239386656E9FAC487EFFBE24539F83B398D643BDE10E38F399C45C5768748D1D56DFA4958A33B0DF1C853DDCAFD31E4CCE279102297B3834A26BF59AF85285A6032BFCB9C47F11FAD42111FBD3BB84D283EB72B2484FD6FB10751444E10ADE45FF2FF2684D332080DA03A2B9C7E60D0BF3386DB98EBD745273EA8A4BFE54DD1021C2547568A4C4EC8E217147A6E4291BAC5643962B5D61105568E50A2A068422B2D555EFCCB2D940DEA1E0C675B910B799635F7C492F53BFE784094B43156632994123B197B1F616BD776A205600D43F65AEC6564AEFA1490D1FA688AA10111CEEAD764E4068BD720D9F6F18A78A99FD5AF3936252BE3DCCDB6A23B44713C5BB5F0CE37E32B114C86A2D507CC6AE84A1AD7AE601D4711BC4E249D34533A291E6FD309DD2CD9AB11CFA8269F7A1F898C3FB54AFC0E889A477E8FF06FCAB49039FFB0DC278820C1B51F7E3C57A2D5C23D832EDFC0D7C744876CD001E8E21CD4B286F0EFCADE9763B810DFFF6293387B07D52BD5375F2851D9BA3BA1A9DC61EB70245B4E9AF46E271D9BD896D1178FC22D37A0DC42ADF4326A4F72D2A77F796944F32D667C4F943F14CB764E68734D4F0BB8F99B13948539BF208228027F38C0CEC77C3ADE11FF923D55314245A8CDEC403A86351001EB1E1BEBCD967F2AACAEEDD7E35B67F0F21BE2FA970B6D26EEA7E3C0C1CAB7CEB667DFCF98EA04926B2A537CC6057EB2B87F95E8AB2104B0F0EEFC7B987033C83884FC1E6D29B4225EDB6A927DBD431B38BFF224D25D5CDAF99640F2EC6B68E93CDCF7ADB26309F76CA9361D07C7192FD3DE39F7A2767D55A32FB2BBDA1FE11A432BF156B3EFBF3B621665C01F2209CDA6F2F6AC96C7C11E335C54BBE223D241A7EA222BB901FDCE1D013BB65127A4B7F3CF582A2806EB91A2A04FD0B358F3D4440D92029AAE45A3F5E4D421EACE412EA318493238E05221716F5B540130B57EB0DEC4ADE20A973EFCB39358B1AF7991EFD5A64E36F49FE66E85AFAEB5D109B39450B6E2F7A30208DAC21B5207930ECF97D6B4145DA66D97B720F10B1893BF2EC59FB1A4A9B3F27ACF7ADD9523357F4BDF58BF6927089A45906AC41666FF9D07C5F01BCB6AAFB1F143785BD4757BFFD595870973C0EDF20CB138398D4D2FB3C6BFAD43094B4D54E304B2589036F56CAFAF88B6E2DA1D2DBCB6B9836A2C4FE0AFE5740A26DEE961FEF5127E6314B22CC61ED2629A65F75453C79937600DBF35F0D617D7915BAA4315702A01AC6ECA674642A5CC4B9C9F0DB03C5E4BD0A81EC25A45103DB65A8645259FAF50EAC96DE2338AA4716C5F90281EADB561F14C8E5FFFB31AC72BEDC927111EA074A607292D2A1BE66DDB1DF86BFCD22731BDD08F2E74AF0B501C25EB78A499E5A0D8EFD8162D2F971B8905209C257A82B2A1EFFA3A71217A2D81726D27F3168573D4845633D39CC9D8C6BCC7E9E5A6526D304B115EA9EE7F9DE39E3E5C37E4B66C88AED0FDB581D9D02B86353CC7BB1D9033B4D68AC47340548E6B3765691EF0B08C6396218D196479E8A481CEB342C2AA117BED03120634C0BC0A851EC74BD8E0EB5771966C2425FF6D071AEE103686C3CB97EDB304863A1B7A2EB65AE0914051582D8F1566B65ED24EF89D3E77E72E3347B04F625C95AC5C171F475A3224F971F642503C86EF42ED2625E80F5DEBCD6F6A42317197FC85B7ADCA648BE20140CA76D6983616EF1E4C6B3F7D7546663527AE4CD6AA2DA20B2330CCDC0C19C002CE42767065F53B59D196F5EFEB930C4F575ED9BF16B75F6FE0AE739A129122CE1AD8DA6DCFC0C095D2188633C8F6B2F56593A0A4894EA8F7468B5DB974CC4FC52028602378DB8A0048A871DDF234D0795FBB5F90571D976650ED1AF81B7DF18DB27D59E76D5458129C80F3C1100AD9366CED92297A33CE6FDCB5C59A66A40AF9D17F670CA861BDC8555A4820740E272AA2CD85C8E05202C13B89A93260496DED8FCD03F614D953E978008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 0000000100000007061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1016 -max = 1023 - -count = 7 -seed = 55897A15824CE06473EC510179AF2AD3CA03B55B7B654EC9AEC393C34BF05660AFBF6B553D3412A59C7E6C8D2F9B1DA8 -mlen = 264 -msg = 962F0F7A3A6771C64F3A6A1E12200A2F73D884FFCF600456D8BAFA0181F67E807971005B2CB81328151570971CE98FB1AC42CD1A2DE020FFE42ECA9C2008873074272042E6C8CEBFAEDCA2687D7721AE9FB94C692FC344015AA917224CCD579913BC415E4412E713C0D75594E414AF8008A27B5465771C2C134C326FC902FDDE7DF59CE13D4AC1DEC6CBEDFD49F03FBE569A3D8895E93A5CC222818400DFB40F3213C4D4CA879C9B8BBC5C511095E9AE15284988826604F48A9CED36519FA903D617CEB821F5B2BE249CBC9AAEDBDA3C62CB9B0E351C95BE8DE05D934F7AF3E336308D9D3F550A8A755BE060815F8CD070F1E7A3220B0C05BF7429081033E09C2101177698BFB515 -smlen = 2500 -sm = 000000075FF58A8D31442A261E6AC66AA4135E434F09ED7F1B7BEA9060438E4FFE7550B11731FEFFAE1F7670606B1B808BDE9EF5CE855A3BC0A876B9BB0BAAD32FC65A945F106F07023485956255F8A8C53166427FB74F73F8A2E54B44F54035993CED96088A7BC0E02A9F6D48BE225FBE7E4F0DDDA995C2E674A51F3C23F6FBD14509E6E88DDDA39E7668EE9C269F94A582B7C874EB415B85F90E37B5A6F0588287732CDC59010F052B59036CD379582562E27753A24093E0805C4C0FB9D7886328BC1ACEAFD216EA7B9D38FA97F71EB3217F4E67771F8599E4152CD25B64DF752AD2CA78D8047A8C3A7BA0A1ADFB0B36BD7C70B53E68BC8DBEEF70E255A613058D1228D3A66E210783230E3396944BB5265CBBD9FBF280BA65259CFEFFD2C1A73AFC24C06BACE7A0F391943EC311989FC54C2A48D001F8017727C6A1CF686B983AA10E60B1667FB0F05434285F24AD37F702C5270555A772AB7FD63D81CC2DCD2A088BFED73E4F705140ABA5F16BE1A5E3ADF0D57E1C0973916ABE4C6B87CADFDC6C20803BA6BE08E06E2EA2AFB2C409F864937A3A1F11E2E74CE0C2E9395F57B9F2F8A45DB9F6CBB29E8302AED637B8583C35539AF80CFE945B7B42533ED2AC67A23FC8327056BB50063140286585475289EC61815B73AF54834C2BD016745EBF78140EC5A1F2A20790871960A3C3E5DD3C006052BF3062762207369CF4420E6E10AD46C2EEB6DDF685185CADF5BFF8C0A624AC2BD0B253A7AFCDFE7EF58A74D31D9E22C922367B5EB709BF0DEA0D2100D99B9C45C9047C181B00977FDDDC61828C3CBF486F9740CF834C73AEF270974AC1C6A1DD064B7D0E592E408ADFD89C1703A505FF612AA6336C48F8A313BC3B7F0C5A7E2EAA53C5921A8CF7E785AC969B9E6A270277407FBBCC4E12BFC2FA475597EA2DF27FFCD4B3FB13D5F0A7A6FC7EDFDDA60EAFAF1D6010E20D775E49A6331D1AA90DFF0A9C6DBE9A7295F06B33965FCFDD65C5D5009670116E6FC2665865CAFA4614745F91B00EAFD4CAD0E5B60134BECFDE85074181E7E5D6E88EF6372B54145CAFE0D749114F67F4F6CE9892CC463CBB41D28E6B00DBEA29167E67FD10CB66F5A86AE6B240375293A61D31FAD2A9CD83B4372052DEE199983C7EA605574AFE235F512E8A369D6803C744B271477C42666C1F6D7F62B8796AFD2B20E881A250750EAFC85C9B9D878FDAD7D213B06CBA1606F6F9E757E25656A36E8649BA1CF23F66D3455D000B6690A3150AFBA8A246F14E934D670050A792973B42C49866CF4D9D1E02477D3A6F30C2D8861B46C3082941A77211F89ECEC545CD10241911E383FF05F65C0293E0F5F7D459339954E522F01CC219BDB80EB87DB871B426BB2D8D9A2FB71BB31AF9A9565DBFF52D27CA5C500628865255028093066F928463BB78C24B039F9C77520621FBAF880148A25F9FF262AD73FE1195B32C9CAC4C11E4B794D606577C32C58AEE7EA0BED17FEF0AC62CD9D5C3CD26AC00CB72455E37D6E9D0CD953BA2C055A6C9EDE3177E38194B9D8ABBDEA35B563E4FECBC7586FC065A6E69D18915CAB3912A9E41850FB837D31B2080EAFF8599FF759DBF67B8B236AECFD2EA7377D7D1C33EB9235158D1CDE56113736156792BA04BCF40AAB95A386D7D40AC57231B769EEDAE23FFA35DE8C0D86E6A45D08CA10B376EA95B4D41C5AB9F7E83E874C438147B0BA166146825A98525CE012F0D1448D064259BF17B3D1048F0E21934FB8723410466358DF677832693CA1E70531A960196436D7188597572B4D45B0657ED0393E02BBA2B4B1FBD1E182AE57E289F3BDEBF716B83825C1691CF5C45A9CAC1F7EAFBA71883777703AF3441B1E3EB5F18D1F952155B4550B9A5C7811F7A4D99AF6F76EAD52E89D8C8A67CBB330F4796A08CBC26EAD8EB9EFDDFBA6D24C51E2B14963AECE698264AAF3B7568F5F408B4D3F3E958C3EBAB5687B31298E92802ABB3FDDAEC811CDFAAD8A255D454C3D16BE06ED4A9A508A3C1208B3B711C02090227FC1597328B211A7017ED46AF836FAC35901B58F6E0AE7164071837C5DBF536EC40CCE73D062E13AB8E420A073CCA65A908CD64E62C5ABEEDDF49C83782C120F8D5EAB3C9940D8A5A27D72C62E2EDAD8D34E9A6E28C4EF88AA6BBB4BC530B9F6D48678D63DBCC817626A0BB5ED1A7FC2B039928D4879732A5C6E3BE506008DA61F7BDC2535356FAD462B28604A2DF5F93B56B76E799017A0D652E7CD1B76A7AF256AE56E9F1B2DD8177457A204EA51C2165DA70A262D3291E5B500249114E5D4EAADCE28E43AFDE8D923219426DA704A32F3C490203353F143196D0F76D6C3BC5D2B8679982E9DF6AB1A69FF0A48C94579679A6898A42E3B902467FD3F90ED13F8F34172FDA06550DF19EBDF355E35DD192611E09C16414702A6BABC3A46D210D39B216F65F22A3EEEC77DF45919755A1C27AAB1C985C66CFF36C2A83FBC21DDE858C530F519459982D5D6F3A283876DEFC2994FD13E53A227941FF0803603A0D68E95472BC442F147CAE9CB0DBC3490265A9CA4A93415BEE3CCB3012ADA9A2B54B2770C948D30F02BB71B5D8D3A149FB93A848459CE42E65F00D71AAF3CE838DD97153BCACF4512ABDDFB3157FA091F4C92461F3CA79459E188727316A5FBF3C1824C4155DE949657162BDFEB664ECFC5D079561589A44D2EA95202D8C06C77EB87C0D9CF59EB9FCA86EFA805F9536857997FEC12E9F212A121E25F11706DC4497963306B9F30707A9DF5D80C4D3FE92CA9DE57A81D0E3A93C494B9A681B5AEC35298FB6273B9D9860ADD35C90A3AEE088746FACC13178382795D46352FD7A59D02108B83D40CC143FC6A950520A1231ECCB8012D97449CCE14836FFA75C19D20B6A948E0CB6EE2F75328056BA00D5EFE28C107541403D881284A7D920C43EBC8B1134572B7ED6CABB97D282B693BA678D3A397D29961169A00D2F0D2036E83A9635E17944EE4922CA3B28DE5B3D3244754A9FC8B5DF913EADC8ECF573013D2E483B404DAC46A85F664A3D482614B3D504E1D1F3D83BC18759C78855D256799807DC2F4338AA29720392864A3CA81CDB32C8A1120D3E2D0815F6D77F7A00AA5ACA394AE30BDB9FC80F3C1100AD9366CED92297A33CE6FDCB5C59A66A40AF9D17F670CA861BDC8555A4820740E272AA2CD85C8E05202C13B89A93260496DED8FCD03F614D953E978008662075DC657270C6763E95569B87A7AF41D07585CE0E5A95DBACC5384E3131D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 0000000100000008061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1015 -max = 1023 - -count = 8 -seed = 798BB062FA12450D432D9692C51C6A9A837AEF567604F01A67935E28CA16434B5DB2A5B74D45661491CC0495440FA989 -mlen = 297 -msg = 289AFDBFA80F8CA4613060AF98810A2184FD3ED165F4E0AF7FF0FA6E830493C99055DB441377C1FEE9FC7D0920A77BAC8650DA3B9A35D4306C2367B3D482EFFF21C28CBA4E2F7A89CAE8A25D5AB269DB6E43E791074999039589E5B38925EA263733B97D9EC5EA4F8C411EB2ADF10B22F3A65E1FBCBEECBCF13B877BA8A7FFE187807D222C73ACD352EADBB59176F9F0EBC7DF20CA7E46F5CFC9330A68B6F45A71A553096165D70DCF2398EFB4D8005B3701D6DF4ADFDBDAD30CBA98FC8254D7A1A0DAF653BFF68B6CB72AA2633F7539772F0872348759AE0D45571CBD3621EF06F1151F18578CC04FF6B7E3E938DA1F50D6E6C82DD0C6ACD4C36E84BCCBF5A4629942BC20434DE8B6E68315A5C62DFC2357F75911634C40E2B9B4DA89F515F9280EF86620939B369F -smlen = 2500 -sm = 0000000842B446CDF177CCD300BCEFAFB8133B67EE9F6DF02088082EB873B63125391DFDE96DDF21B58DDF08B1E0E813D21723DE5861C656C71D87290B1287B9B22F0CFFD5F63BF17A33F7D4DBD56ADFF47C06B9CB73B39B867D7075B92FFD38E38990EE4E29CF5EA9EFF96FB792E2D8031D60F422748B2DE49260C0D34E93C315E19264C6A0487438A3D1073FDFD74EC015D051D4384DEEFE689D7880BFA573EEAE2E3A7CFA65477167BAD6D2FE3FBEAA431FAB155275498D72533121800E2F231A662FC1F439303F05295328BFA0AB68B196414311629461F6BAA615B0A0E92350063BF58827C14F47B1D18606DCD093571965306A7628851D1A653B64E1463FA7BA83F468676371DC39F1F27F13C41AF42814F6409C00B7C4693AFA77F01537A286970F8A0A59800F827FE8541E70C27872EFA23DB0641713454D1A3C9E595F3E74C733F1180EAAD48D1A19FAF95B88A0561A05D296374273AF651DA94C4F852185D957E308672C760E8D08027DA54B47E7F38F215D85D43C515F8F19628B505D37F37AA5174549D57F6F3D42B6A5C51BA7EBC7FE0DE9B7935982E91AEB697D952499DDB4BA855A2F9215A72235DD9449C7F1CC4B4E646ACA12E0204476146618A0E4BD8DC7434016CE03A7430BE1E8EA827A381486F50F680409AE081EA67B8C703878A5445FBD0CAF5DACE16B9CF90C62A257392B20A44806EE3E8B60025A817BCB674E8D2FD2E6BF4BB320EDDB4007EDFDF0FB62892548D310218D39C974E12064EA28920F0016A6E2636BF6D524E0912E2B64DC3EC7636ADD0A20C81CAE6C3BD62CB872634523C7D6CA8DDED004A967CE50795687E4CC41335E9A8AC976C95A270317DB7D96E6CB596D9FE594E669C0604798E453CB5A9CF36E4F4974DF1660CFE562CB63B96ED122A9A9B3C38E5015E64CC3AD37CED7C2192AFFD1A4A6BE234C6E60EFEB7F33F25A33FF5A7A332657CE759EF5B81CA28C1E497FF9E4CFA1F003B8F5F1E8FCC07E8ED6DAC6C06D2DFBBF86A463E9B71F2D1552DFFBB05755CE4AD2289EB1BA4B9AE3E56395509A65DD521EE58F06D0B4E40C772B702747F36E7DBE6CE7EEE4A1E79065E590EF37A2CF6E1CE3A88909701A70765BB1CCBFA94AE20BBBB96167BD93DA33D79DB3815319DC3F38486E64AC42E371E6EF0CCF14FB4B2B6205E89F66FE2A572ECCCF85881E6363271B58F434E38FEA4B15013C95B8F5867A09AF06D592939FABDB5B96ADD3A179D366F99150E3DFF63185569F2D862D412073B9DD13655B8AF0D87DE06B2809191D1EC754FA7342D5383EB2C7E702080A133B51B7C630CBCABA758AC54A015D53DAB9D3ED19C4ADCA361F153CF8C4CCA568FCF0367A8CC348B6C2AD139859443F6F0CEE2B6B354727265CA14F0AA2271A96F4ABD72B8954E103AD1402FDEA2390C07D1830C142A0AC4CD4583B31D54AE3A64F668FB194767EEA716AEECCFB8951419E328201F781382A198C9635400A52FAC59710273FDE792994308B7E3856C21C5F1227A3438FF54A40F4D9A29918BE7639C83D06341FACF62FDDDA8AEF74FEC6FA3F09433E6C3C5D0A5316178DC70441E38A12D8BA742FF49F5B8D3971A0276C53DA416FC6ACAA94BFAA1B73C5FBD59057E553BC71A7DD537CCD02FB22C9AD9EC122AF040C7F8F28A53686F841C84F0630E1F694872EAF34C80390D28F934A9D47E6E5FC367B187E74F2E698569A484244645F4A714500890B0B9FCC4E1130DA1D4F03F7550D625C3680335C2882D188DF4F6835B9549F1A4D33AB7B028561B43A860F4094CAEC30C81E1F073E9A1483B846B0642FB037CCCFD505065D855EFA681EBDAE286B337B8C472ACB6C310BC608C1637B01D3A1578C2B9FE032B263EF2E0C42190EEE09FCDCB555803566473114D1B05DBA7ADD15813F6023FD82AA25AA1F6AB1EBABBFFCD62FE98F83A17D7DBA719041CFC155C09B05B1E0D3D8909B1A892542FA5B31F90839AFCB68A80070DCADCAB8249B0BAF81E8D0466D9F6CB118DA6B80697F4366153FE94A53600361DF10D11D1937182F02E5832E4AC2B95AEDE0418736BBB16A285BE7B9473BDA4EB2B2665E255C6EA18A8B07111F09E9B057D5F9176BFCFDBF3E3E073143BB33A6744DB9E973130A7D7BF99F148A526630964617E4D600EA5E1A27277AF646C909AEDA2BE16BBFE7CBF037562819C4DE2AEA88CD6BFD18F69D86D37F2321AE06324D5248956964ABBF93F9B0E106C692319DD7742406F98550E5B31CF170D6EFCE0CA28465258A2D76559663F1B7BA77C340B7FE06C45988A5CE8B7B1EEBB2411F1ED856ADD6E7EAA8BE6895534D3D0BE1CE385CC416F06EB27F5C6C69D01EF1A81F4E3BB6EFF9B0F3992D490EDCBC6960F5DAB0081557D385821D08BDEDE73CDF33A9AB3207F72C85B9BA229546724DF96C87AACEC40CE3A89D414A4C2DB9F9950843F05473C6BF0A69A7AC5A366F6B4F612D71A71669A8BF4E3668003F2CF25E0C1297F5B8293598E6A7FA1299E3A5E383215A3F41BDFEC4CB9163BE8741EF08DA132A934F84164D05F4175122BC5152CD651D697AAEF291F8D1A18DD49AE8622D0DC49EC77FA23FA51B3760F6E684AAC5B949729DCE376553B16082C70BD43848584A56F136D01BE3B80B4AEB9B4BAC518F17CF44ADF14B618DD04059F55D666A7BC0AD6747E2F64C8B25F55A4DC0B178FA14E80EB6A8C6CDBBC5FAEA9BF0750E6463E3C1262E3EEE072EC95EC3AC8939DE5F4111F734FB0347D743F1EAA67DD4189B92BD8F37B2B62EA00636F48ECA262BFAF0238DE48D2D0EE04865979682741E96C05DCF28BBC40D9A7A95EF2AF8040BA3F44E72FD6E04887937055AAA644A073CC82782214A8B9948ED942283FADE73D3E3E7F14105AE3FD1613DF6BE5CBBA99008E5E4A61EB0D57400FAA7A150CD1F690C3C3FF1CC695CEF8FC746DD836025EEF5523960E786F7DA022C9E4FDD6F810DA35C9A71BA26B8BE68BB33814A5D5B47088559D4CE3C910B1A70435755466E86B74E8FAE08AC7910F177D5142FC7742BBF0A738BF76E9E72FCD7C2957CC74F299285CF21B8A71015182678FFA04F377490152E9B4BA60D4B220F04EE5A38902E62627C12B696360CBFF4C016C2896B09E62DA088FA83B58F5C0F0D645FCFF2AAA1305F5A46036716C1464372A0437EC5E25D80AC6815CAD5B7EF29F71AC68263246E725C21DEF39E6DD1316C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 0000000100000009061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1014 -max = 1023 - -count = 9 -seed = BC4285C7804C15AAAA7FBF25D494E763DDA04B15414E1EC6461BBE0B7C6962A625F087B9DA019F277CC038FACA1CDBD8 -mlen = 330 -msg = 8FFC13A7F7C0C6C20ED56AAD2FD44C9C053DFEAC4FA62446A6FA4CE691F347C89D0BACF62C54DF754CBA2591209EC1619960E6AC2612EAAFAD3D343ED32AC1233DC00FCD88CA2AA8152F13B1FF530840B6E10C7BCB4E1022BFE82F468458A45967834E141709019361BC4F6AB67326884FCAB2E3EE3DFA174B9862C078218F8BCB5718784B36725ADF2907901147AF25B621DED9521FFBB2270F2A3C98EA901EA9BCE0764968EAD9D4FC027515B478B670841A4B61DCE9FE882242FE22F3830A9BE0B546287F6E0CEAEA92002654E7BB73FAF673D4041B5880584E1FC566F90FB2FABCB3DBB2CB30D66610B73EDFF23C89F20B6BB1B3BC71C17133F64966FF9A8404CA350D2DC953736B731D63E204F50B1D5F44F27E255F8FB508892A369F9F8272078A1E988C6C105C9D37F44619CC46E7430759C67AA7B131D23B2D405C3ACE8076EDFBF21783D2E4 -smlen = 2500 -sm = 000000094E8205284069747FA1B604DAAC8F1E8BECE4756454AD65441B745B5948618129E48E5AD2C080DD21C422723EA55CAC647B30EF0A0ADD4A68ED6CF5F1AE68EEC8A5BF69C4922F886D35EC8575F036FE13253B2C2433399BC92FB4805B108CF0B810E10CE31E16808A7643AF1DC74CF71BBB9065507148629CF9246CBD6D17ECB5F12D59E88410F0F6F04CEE6F87795DB6FFC1B78D43AA1C90C54FD44B7FADD9F76C93B1FFA7EFB8185ECDC6D11A1742BE67637C90B73073DB977FA393F50B48491F03A34E9811B87116EF3F91A563F7D0799AA6962B0BF216FF3C20B86062AD1F37ABE3CB927731541F9EC9ECCC74206E1B7A42F8BD8622E92914B221C2FE884EF67E56DF122DFEBC8F3703ABBC9E038A5CC8FA5B67DAD5F5942F9CD17067B06D28669A5FFBC4A05FFC0A771BA537F922F08DE9F8EB42B28032887494D4FE03E8668F6B6F919E681F5880A273C855A073EA44890B1A410334EF24C0D25B3EEA3305EEC8793BA12EB6B076CF52F8A86DD9100F984D700969EB78ECF034DF14E3AFC9C1C2A9A37346F89480D540F72AE127E7476E95641581474966AA07B76092548FF20E4170235D597E149F0B44F17B751BF082AC74E1EC74C4CD9474E37FD587B7C50A8451EF651079B7C8FD9BEEA5BB4D6C58C6EF6C5F6D12F6868C355753C9606837AC660D3C54E9113E0DE0FB750D1C86801346B1B89F06710D531319D2D49385C7080BC6321AF6F6F89FBD36399E2E3B82BE93B0DE483712DC5D84C2DE999BA81CC850721ECE18BC31C8F39DA690D338B24927124D0F2C40C1AA5E50FC0C22D52BF200283A153E146E82C1F583BD291A3AC3B07FDFFAE57B3E4AE9CE2A4679BE9602DB5B666089359C4540D2FB8AE0031D5D8064E45FC9083B03112EEE7370676863752BED12C48E167C9FF0AB1DB5D30F2DA3C6866FE436406A7793270A6BA7BC9C859808BFD5C642C592AF045793E9FD64E5744E51E043D288AEEE79CDEBDCDAE181F3E93A3B202596754CDDF4D18F8E6DCB1414345893C8C634430CE5C3F3AAB7F02BA0BFFE16C775D062F04A43412C0C380C823427605EBDD6726FE33F43DE8FFED4BD73ABA600E550B0E710F77D8B0B158AF3957D19E2A70605227F5C13BF7367BB4A6456667F5F580F6B303536F29D70362CA4DD30DAA727F8E74006F4397482EFBF1A6C30641F720B1D772231D706B4DE2A72F1EEE2D31573238A995C22F2EB2EC5B7CE61084C88063808C4C1D3499038D7CEBF37F6C5EB9710872F24C9806BD5DFF7E079537DDC64CBAA9EA208ABE23F7EDC5A7791CF7600A6F85780B70EE9412165FFE815F02F74896ACA1EDA0DCB593B74D6D48CC6E1053B5372D767D03B4B5B4041686BDAEC4F42F2C202649CCA404572228DABA2D04604AFF5BAF85EB871B8B5C82E03BD992FA2569DC8E1E4CA9041B755A94B9E4F06F7A662EE53D8A0B019D05497FD6032D9E95C05BB59E9F9458B4389000CB46F4190A19472C4CB51D873AA1A6FF6CA591E938E25E4C898319D850E0FB8C0DB6E983155297734F0243B9DE56F880D8DCB191EB9F9CFF45CFB9E1BBC92FEDD297A3811FE691D8674B82F437891F8AF6054AC87AB48EFE883FFDCFAE21F26E1BE134B53AB544F6E9DBE06938C0C466CBAF170FBFA7EAB618357635A83411E2CDCA0BB9323EF54CCD4128D639D80B127E7729ABDC04989B06EFEFB7C87BAE7D48EA599B7EA627B98A6317BE3D70824C25747FE3D2347E01B0CF7D3F389434DD167D703291DA0CE89097F339806CE37D526B7859FEB93E6E176ACE8F6A038AFB424BE1384422278141BD3EBBF890F3E9028CC7B770B9E8928ABD210ACDE38A31D38D11DBB6B9921D915C61616B9014170AC5124B2E4CC6C66F94906682D29946577EFF47053D28BD6488640C65ABE97C8AC8F9603E1EA89E082CAB6BD13C0D010DFD8E69211CAF3FAAAAC255365E928C47C88FAEEF61A27312C50FE10F21C719445389B00E7DBB32863F90D1E13014C6267B1FEAA1D3615F30AA72CB6905A5A9E78A9F406CB1774C5BB413D73D183B3C3DDDF7D608AF61C1459DAF34C99191A3A9FB3D99F3C45DAA3DD6CE8D4FB4991F367C00540BCC233AB6545BC7BAE87B319A1CBA5A8C17D2F3EBAE53008BDB896ADA1105B17B340E28940900865DEC2FEE01652B9FF9261A1660D8B2BD82044B4F224FC3281CB8DEAF17B7B06D5398467D9655AB3A0A77EB7C3FAD129C16037B0FD3750AA356106D26B11E9ABFB1A73DD9C36BA2346B38ECB00535EEBEE63A3C0436CF70C974D26FF28C580C88509907F68AE6332461880F839644B37D8999E16418E2D0152925CC0F0D63C87F612D30404FDBB347A932432037384FE00A6D0E9B0B97A99063FE2BFCE1FF51AF5CD593F6E4A2F82845A44F174FD8647774260944DDF0D006ECF6EBB9FCA61FE5B5D6EECEF44E4187EA3E9AC8C17294740E5B016C7DCB10E603FEC2C3960F3A83B41B84E14705129894B682AC1A52FC190CA10CA3218C5BA67A6A0314F6F059435A6D3B6E347219243E33808FE0E12F188BC30DE394F5AD725421DDA0EF686282DA121461BBCD039EEE6D500BA10BA92078BD4A3A44B9389F7778114BD126FFABB724ACEA754DB959624D8167A8FBB90BA4F38BCDBE3CD172F4972B189F1D08548C4AF7F14D9C405FC5831BFE59D13716CB9B1941DA438EF93E6770DDE04386DFCED416B3BB9A911DAA57423E0DACA2B93A2839AF26F1D3B49587A46BCB694A4323B08E8DAB4FC80E94B80319EC849445530339BABDFC4131275444636526496420453C5E917894C9F6459492D6F7F24728C83FD45D0F2BCDFBBBDD718768D8B83BE2DCC2CE080F3E48973BBE6AA1577858C9AFD2AC2FF2066562C4EB88ABED1F284A6D40982F4F3A2C2CC9A34FF7F30BA1FFD4F629EB8A3434FE46C523F903FBF457860F50F2D0ACE9A4D7E2FDF5E6EE7036C5DE8EF9CB7270E93D5F84E5A097417C2194BB54534B66D1A1761B165B6549EC8D7AAA2BAD5775C3C5CA78FCC38D738772746666765F8909B8327D3427F0F8BCB815D5BCAB5621B4FFD0AFD5F2DC983DCBCBBEE1622FFCB09748081B59F493821B467DF8B22B2652F4E3D112C38A15CE733E4610833DF3F16C2896B09E62DA088FA83B58F5C0F0D645FCFF2AAA1305F5A46036716C1464372A0437EC5E25D80AC6815CAD5B7EF29F71AC68263246E725C21DEF39E6DD1316C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 000000010000000A061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1013 -max = 1023 - -count = 10 -seed = BEEC566BC26E2DC13FBA54ACFB667A5C77FEC1BFFEFDC42F9131F1524FB0F71AABFDAEFF6894DBEAC6B89CE3ED236239 -mlen = 363 -msg = E24DC9F0A986B4F5A349DD1567A80B7C1170C980444F715998681BFFC2417661BF0B503E11D2BCA8D135968E6F07FF0144308AE69E55F4CD663A3CEC5C5D84D00E5C0FB2E458CE22C7E41761852CDA6EC268A8FC06E76D1E4F03A90A6FA9D1502F6F21295106F3485C9B3A1DC6C40C8E304DBC55AB2B90F6E6DDB404D8487D736E5466243F0B055B060287DF589D66B88C6DCF6D2FC8E88DC20BC9D693BE9B9744C31D181558289C3F2406BDA3CD3FFEE90249D95214C7D77E1A9927123335573E952FFF9A8D3BD66E020AC1FFFE5C1921DD7FF6B48295B6D2496376AE1E98CDEA032BCB8662A915301FBD014224CB7D899CAE2889FE0D673E0B55F4A56C914DE868D61775D3DC92366524F606C9E279ED231B0662ADC50A4161C19149830305B9BB38AA2606DA23830C3951386E63DA6DC2176F48B2ABB26619833074E95391323F0EE3B6151B2FF463EA3CF3BE55C2875EA93586AFF0CDB4B43DC7E8A156510B74E566233066EAAAF845 -smlen = 2500 -smsklen = 136 -sk = 000000010000000B061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1012 -max = 1023 - -count = 11 -seed = 66638FA3A92FACE1BA5B311362842ECE73B6EBE5637EDB3E16B0EBABAAC6BA9335BD63DA0253518A6B9648BA490AD60A -mlen = 396 -msg = 942D9CEE1FC9325A8E6456194FF3E1ED7562E19AF59C7A0F7569911EFC22A89EEAE8831E66B528797A6DED2E0AFF50933AE425245953BF95637826F3483F1E8E12E12BA8D6A42D320235405E422ED3522F25F630AEB0A63635AD70A51CBFEF6DA246562A10529B3DAC58C50BB08F88469987DB5EF8B3E37BC07639E56058B93DDDD88E9735B3632E37B3DC0146E3EE9A55F29DF71DA5DAF7A14CDD8276F363F3E1E4C6DEE2BF623DE44F0C96DD03AB00BE02D5BB90C61B870E3CCB41ACE1D1FB5902FB1FB2F866E92CBEB41117C5C5C0D367D20D797BF09E0C8EE934209351A149A306E34A62DFF428687C6285FB3682F94FE3C6B1C28F1F0537A60B4C9D71E2B01DB08DB7A033E426C73C86A061345B0596CDC6FFFFA005CCCA8C7807BC293D3E14D5881D6099103C98449640AA2E806592D345781D81D6EEF1CBA823E0DA1858C3647CAE811D7FF87B9E08C7AA1E2EF8ED615AD32B744CA253B6F172636A964A1E2719CF7DCCADC61569DAE0BB1A37F4A942EE17762586BB9A9BDE8B66671D50ABB592947337AA71D35EE1 -smlen = 2500 -sm = 0000000B455CEF8ADB9FA246879773E4AED4C367473AD23FB89C5BCAFB1BAF65F9615D4408268EB928B66B1709C9A932AD9A450B20263301918FE23671583B5674AF03A96A38194A098992E96D278B8B68F9B56451652E5C7B90F3A8FD0DE39BE575675EF6D1ED6655052DF350B420E90A070CE2592CE4B832969A07B513E3C7A8F3AA8F025A596591F339E09EFF624D89F97C65E131E0289DD0B34286DC38AB98A56B09AFC9B14A5A2DFEBAD49D476A2F8829E881591EA506C3AA5B1A91F7830127437078E74288A6237956BB16E90BD69079E19792A01CCFF507DF31D99CC6AB1D654A133CFB22A9DF43D1C427B2079EEFA43EE6F2858683E90440ADD529EB1965298EABA124DF53A0C4B1E41FA0C0FBCA4E52ADE2D0D19EA2090390F4608518EE8B3B9FB051C9466F601684B6109B2533A6A3E2CB7530F49EC9F1E1271210C90CB3F4B798ADD65CF9033077CC4DD74549FC87D2744B1303F3C7406330A40E4546BD76B979E9EEB8AE22DDEF7A2B2A3F5EC9E8289466FE038C1EB224ED4CC8248BAA09827E2A8E08ED2E64B233EBAA973D459DE59ECD7A4E47A36D12CC86EEAC6D2DE57AFC79BB41177F6E7E0853F8E2D43DD9E206F242501794E73F049A046522434E35FC255BE32996A9A67188440C78F39309060FE62121D5FFC0CD8DC91F220403049390212DC9A0BF50D1D58A3D4E5ABBD1CC6D50020FBBD7AE31683E01648F71828594311B45C60EC2272144C6D8548777E74D79B5F83C4AB3E26F1C05F99A3CF59F8E63CBEE6E5BB2A10F7B9512D6BDED02314516526854DAC0349897B9DFA3FAABE9A886C6AE8281FFBA9E71FC4D35DE35B7B456C7C6B95BD4BA0DCCE93323F055890226E95F267F03B166509C3788184BAF6B3236BC674190B2D3ABF2876717D90324B6A7715CA39B77CDE920E7E39F2DBED6A4FE6AF3C5AF8BCF555B0F77FD63F9FC15E622323F8D0BEE79450F367250B5E77568C5E650B06346AD938FF4345833B98CDE075CA1D4F36EED5A0CEC89F6A2E33D22B64D0A4C39780E62A21E4106DFDC3CCA753F659F3CCB9FFA760EE79FB6D6ACE22B8FBFDEF1F1D297860E07D726C667BB13653A391A839AD24DA7FC889C194879D4AA22E3CA7F7929040F8325FFEFD805B769B02F39042B03B04B4DAFCB23C360A4811F70E7F95DC20CF5E0FE8D5567A96D95896BA67938E5458685527636DC1CC38389A25A1EF8A44D04ADB2113613323637478C6992466AA02BA69462D85F8FAD94F3228A9374B26FD050BF0BDBB18502C5507C74C40850FCC6BBD9A771FEA0772B5FDD7EA346867A444AFACBF6F2FA4C781E8C49A1FC4B3CA4068F737FBADF261C25B264C2FD8B9623E55941534EF53933BBD2E8628CC0DE5C60B472170B204867623AF8441F84486240114D164C54F316A6DB6EFC6A35BC7FC1A06A17E9E5B410E26C67E78857BFC6FBD8A4F71F9F81D8DD85958B486EF132E983BFFA0EE4E2F2D13600A51C331FE58EB164F58757A0649F0D0A0CE7665A6A099856EFE3150C3AA79299DC1DD4DFFB0E939611A74B69D821E33CECD5FA2F012F2D40E494085CC3DEFED33E101E5240F7C2116BE78D3843EA1ACB017D27888D76E17654A3F0C9CE653D4910C09F883B8D4A7A6DA7BE70B3356EE4F253C583C086A6ED94B0E87CA9BC0DEF3AD297C76FE001EF31B028DFB7A1D430B7F569EFB8EABFEEB09063F0ABCCB87A66D58230D947EC0D3F233457FA206FEA765837168525F5B70095EBE76CF3F5FD69CB65F7DF3917BEC3D843F39B65789A28ECE4ECF35FD54F9D5881CFAECEEC601589C17C227477836EB11989474CE24B64956022E16ED7275FB32833E22AEDA33E89E2810F479E886F2B42DCBB1D4F7D662BEE7AAA6C942C38AFFA6BE24EDC48E2F47131D7CBCAD87C639969B2E58E71005393294A1FB75CECE19DBB87F309D9989D3F1D98744608AA73B53887660E22BFA6087678F52A636F5A0DD00EE1A40D721ABFFAC571852F5301A71F23DA7F2D21B49B36C4D0E85D3BA7A9D15A5364B799F696EE31701A6F53F22D2111F025D4919C6B305304AA180FC6551F7A9997D9A5A242692DC8C146B282FCB864062119C89050DD8952C563D336A2D00560A5C5EA5A1DFDC8273CEE2B9546813198F011D9C7D640A7D75CF036445E58E566A2434CEB19EF8870E190E9451D537E0B5E4471446366834DB65649F58DB535152061A5BD598F9D940F299B42775290719DEEDC87CE332EE592DD40E687B5D6A19E68CB24293F3AAECA1B0059CE264562190DA057A230C98222A0664741B63D570B195A510B5DFFEE9831C7CDB05936F0EBF0A9339324D1E42BC9157216D5F61C177D08C620E2F997259C7323143F0B968EDD22EA9A003C8CB3A74C2481B3596E64B261129B96F345B4927F144C6F1D744D88FCCCE76368B915C75D09089D9542C0CFB45A770A0EE5E03F6C4AF3C49735317136E25197C589958D0155F97DA3BC054CBCDEC2730A8B4D680CA67C358B887285BFF3EBBB3EB6379EE79E2BA86C7887C8EB4983833E48C9D1BD56E1013969C7E040196E9AD08980284760CD737FD46AA537D8B1274DD8267CC7F82889B1AB9B2F6CE75FDDEEBB7315B710A1A2BC6D286832E2FA6E0AE88B6AEB5CC99E99567E5CB106FED3747D132F1AE277DF8FDAD615328E2C7F3CE2BF4B1D75B9E6E6B68758FF634158D3CA893C49070FCB5F5D0C491334537BF3D33723E09996843177A77BA37A268D63CC95B36AD8F53BD9CA859345DC7A2535E488BC4D5C2B889F1CBCF242C35181121C8997734A0E614038FF6ECC1C15F9BC6B1F4B3F40DF1D612A1633485AD2A8040401F1915405565F4716A5CA159B7B6EB09A7EBAADDE2E5DA3D936B2CE5847CC9BFF737A2978F92AF3C5B907B370E49133D6E162B89BFCFF176965497A24EE4A6C0C6FE05C544A4C00D5352F6DE408D34DA24248EA94601201E6C0EA92B2562E030B16AD3E3C391445D3EC63591470D2E9896E07C7A17FBCCF45D69B1C9BB1BA07B6311FF2B97C620CD0AA0E500222E7F17C816BF5EA50F85302F198830A7E4B47A80896290F8DDDBE63E1646947C7EF5ADA43249E35DA580A61AD34EA9DE90785B144564C936090F2C725C86246723B5750C2CD15888F03DED5904065F4CB00EC42F7106F41F11E69246E59737AD06772A0437EC5E25D80AC6815CAD5B7EF29F71AC68263246E725C21DEF39E6DD1316C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 000000010000000C061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1011 -max = 1023 - -count = 12 -seed = 495AC157AF18D1563D6A03CCFF53807D532FD46AC67A624D433DAE418CD1E0F5FB76789EEBE1FE0A50279D28E411CFFC -mlen = 429 -msg = 0FF7A2C1D92BE47802CFA7186033B611FFC9C4C385F016D1762A79ADE356C85E9D81F35F5B3095927B855C194DA184B90A54B6241B8915A5F989130248E28A92C9A7EB5A1C6FCC96432C4DB091C75923BECA9C4666320D955EA2AEC268E47DB6735CF0297B9BC6E4A033D413A3CA7B7BC6B8393268AC91DAD4DA427DBDB14A20F16CFDC9CA0E7C904EA182F060BF6458147ABBDBBAF69C631B9DF27330F8AF63122F32D0099F5CAE7FE0DC3AF91E8FBAC3591B5A8B5ABDFCCD714F6643D4D3D65C6CE7C73194A8A3193FF8DD2AA8ED8113548C0BBBBE4C68F96BEC93D799B64149B010EF776B191E6246498B19286B8D53D67CE09D5CAC398917B46D8530EE55B67BF8D4D00164A519288D9112309713B9EEDEAB11346264221FAF4BADCA7E6578B3EDDE6F37EE9CE2C2CCA03FD61383213C2252D35178918476B7A1B9E6FBEFDCDF1B3F02BA60562EDC5B68C6AC6FADFC1CAE6E9C267DEDED7ECFA507F277C18F80FE0A9E160654F1F4234E5EFCA51D9754C12CA0C5E96395835F3465E6AF793ACA81DC57EA044D43DED72BEFC8806DCFBEC917E89DD816A48CC726A39EA8EDA3917744EB45C6B4C09A08636D -smlen = 2500 -smsklen = 136 -sk = 000000010000000D061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1010 -max = 1023 - -count = 13 -seed = 21905954F5B96B48D223480BE10EED13A16F59C175072AFC3FBF0B6A69939917E07EA5D998523CBED0993F9D5C5F603D -mlen = 462 -msg = DE4F0CEFC7B6A7A83AF41268C268EBDDFD5C01366509402723283AC6BF6EBB5330CF62190E4ED61F8C232C9DD0DABE0628782029CD7BFC67765EA0167294CBC6EDD7C63829ACD5D09447AF5B13AB605FC51CA16044336DC888AEF43C7312E38BEA5E4378E7B260E01A9566FE2A8B2893429BF5B4F5A755EF901EB19BB2E6365FA83F11BC1CC5BDFE57E2A009340A034644AD8A72B467430D42AF7DEE753572E00A41886D971D4145A8D0B7540A63D26BFAA06BAFBA4C46FC5672047C56D7D5BE1E12F50AB0B3430A815B43901FA2BB1921956492692A6943E6035099D509CFA0CCA8077329786962ABD134909643BBD89D7A5F81A8F96CAA93E80BCC35BD75AB6F7CC43F1563EAC9FBCC697061C7FBC391E55AB545105B70555490F10C86D0B0ACBE5758B06132530E90D9F35B3E23C1E42F46405BB54D485B8A78264EA8E612A4332FCC46EA04938465B94298900129231E974159CF5359C6BEDBD7CC4CFCF0E79DAFD0738307105590AFC8F076AE6F026B9FCE281727D1DA9D3064BD534810EF08E05181F1496B0F014F7F895D67465781A905F3B90CD203C78442EC4F289DB7814763473FFB29B60645FDDD910C35F5D3AFAAAF516AB5060CE9AD57C616D15D90F8277ED658A6D2089535E437 -smlen = 2500 -smsklen = 136 -sk = 000000010000000E061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1009 -max = 1023 - -count = 14 -seed = 5B9F2A1DFD877CBE4E30BCB6F022FE142E1611189F83AE628D64EBB329AB0D9C66461CB73EE17E69F5B637CF4886BDD0 -mlen = 495 -msg = 971DA327D2195078632898AF79691F8F5F93189EF0807714096D27480E82B1F0B884AD43FEB3151AB6B7261A501416AB982BF9F2234B8199F89EDDCD56E160E1825E79365625A979FE157E9FA937926E7F12C4B5091EE6572CF8D4FB9FB8E1090BEABCED73AC36B35A5020EAE0134A3291CB10A05C3EF778038702843739E59ADA2C3CEBA6353B482C5F80E751E10BF13DDACFC6C0E3FDD09B21710ECE846ACFA1305074ED4328B90E65B1FBABC53ADFD964A4527CB1B8101C30A41804A5EAB9A00D135C38C52EB5149B6655B60D5A1AF50E3D0DBDF63A035924102495B46327A063292503F4D72BEAE063B577B57226175AD58DB98AB164521EA9C21A78D2BFADCC109B78082FA4AB1FF3FAA2B768BE3FDB1F929B67010944DC3AE6941877F599B478B03F0C267616AEE949197CF7D230EFE0930CD01D6D4E0A6A628068C6006B06C75F2DACF6027D5A2721B34A232A73DADA62A1721F2903983A5A04EF8ACC4C5E29114A9BED0BBE492C1972212DF08D3D2D8041E5658A42442821044AC7A8151F621BC88A56B53E84B5F342154C1109716BDF877A631EDF7BD64E5FE45A0DD40BB58C91F9DD5005736DB32DB3B57B9DAAC0ECCB66860689F5C1F6BF9D5115544601260F22A90EF77B340DE9B4C7F38250528D57140EA5FFDDCCA4C4254252CAA34A4DBB9F643B18ED950DC89A06 -smlen = 2500 -sm = 0000000EC2BDBED877538AEAC597717A7AFBEA0D0954ABE8A2E303FD5386BE09B9145B0C4F5203CC3771E11D3EBF99F8CDB84B8B59940B570676EA55FDF6996BF8A8EBC5293080B32CEFD214031A7CE6C9A239751D15738EF36195812AE0553CA5054C8DACBBCBF686C371801CC80544E9BE47B1E01090090D7BB51B52DF71D91417FB922D6235B34464CB75D6357A9FD3FB19789C78A1B5445265157A8F58C97083C9A3F77E1CB62F400722ECF9EA9607872D3C6A12925EA7F4D0FAE1359D3CAD5B84BAC51B5E18DC6F915D9D3877248331E841CA5E2A9E5E22ED89FF387200E50F52CCEABD27D6826EB2287DB82D7EE520391FD597B6E73139D84BE3C1378B822898C4A8EC07FC922FFBF9DA07B3A08A3CEA274606F312AAE564D581E8E2E7DFC83C26D7FB29C88996A6363BFDA2115931D23AFA9E1345B9D8DE542FBB8AE1A883EA2C3DD893029D9DDB7320E0B8CCD1E864D04FB2A0F88F8974FC26841D212F70F7714EA7676B20C0EDB14F3551FEDF6A6F9A81C06F5409791E02B2152E90B3647D326890361887E005819E758367695243C60DF2CA9611B9836478290A82E471494336FA2D40D2C5768047EE8B2837D82E232F8A52A5F28D79A5E0EDF59E8FB27FE189BB5B0F3E8F2112955DEA9435CD0E8DC59671930528016B04B05864D309080A6A142F0ADA36AABBF0A7565F08B7AE8F893D0E724DA5DDEE68CF6EB05DD8ED5BF327B3F681FCDB708F47894072B5A60C1FC4DA918A8BF40E01A1B85D546A9CCD65CA4C45EC66B81D15BEEC0BB1114CC87C8768EE0C1787EFAEF0B623754DF068A9530EEF7E4A19434BE78605C5230F8351AFB855920EB056BE2A3C38AA1130479E653E93869E556170CD10F9A9820E6B6A17BCAD164A16E0AFD1F57FC7C517AEE878241675E44B8F85ABD1404E4C55F17B05C4D3E3E6C7197B1B90CC1C770758BDBA381E61BBDC0E4BA9E36FCD992EC1FD2A8E598CBB9F6374A3665E10DFD38E1087998DA2875594CD5712639D28F4614C3A5238FB611ABAA56ECD0D80CA77AC229B6B7CF9F0678A4C9ACB41E232B29BE6A7C3973364801E1DF151E9B947F768CB76FF97E4C7F00902FCA4D83DCFB51359F01C68314BE71B7311F4A93AD651014F35BA773E27EE81E38018FF840FB5456120021B04B9CD5503D5829A7394EB0FAB8E211BEB08DD5063CE686B34CFCDF0101F29CA63D1A6AFCE6ED512B3D4E06DEF655C1E70C09072911F6ED8E75B35A466941CD98B91927A59F89D4E417B4457FF686CB305BE08A9FCA46AE7B3D0515374A3A15CEDCF67BC0ADFB84605471C5D17141D89B4930B8D16309FC3FE1B4BE671671C67761A2A65565ADFC7BBA5EBA03D46675DC407511A8AF49055628E47BB8148F69A0DD542AF9A8ACAE95042D2173FF559AB30689BF2DD6CE2E9BC177DCC38954F5019B7F9CC6D9B6966D6B5F3ADEDB3CE772A017DC98CFE1C3EEEC6CEA804D9A862CA7CBA4F3CE71D27647784840F22DB7DC1D24FFCFCC73CD086AC0C2F5CF6F090CF508BF802C397A53EB393B6A8E3B890615C690AC84C7111BDA73D772AAC3D3A85A23A10299C98D8CF31A96F75E69B00A1C7E73A5DF7F5E5156315D60A26D2620720EB7D2D1218328BA7CEA44C0E4F67F5390CD395DE53A2A1284B643BD496D4622739BE6D6D20967E6D295ED74753859E43762105686FE56BAE2BB7D7DFE92148123BE34FC191A3A095ABEB7D62D9276986F6A6E5E491707750CD9397315A8E0A116E730EF0DC1F872DD3CE6C7EAEEB299016940A49D6D858E1130B4BC0DBEEB28DCC45507477E149AA8F89165494D20DB95960788B7056F3C300664C51B6E57AFFB185760E7CFEA4E0950A6087327FE90B85525EAAA477EE77A3E5CDDC7BD7BCF2E0527B04BBEE19531131335F280406CF18AD9755ED995F5D7DFF50C2843719A8A65626F978D15F738019C5CF0E9C83639EED862E518F29FB0D70D80A3C36E565AAE7BBB04BA42809C591002BA8D1B7FF8579A1D50761A10A0CCC32219784A7C79DAC25CF1495B2409D5743D93CC3371BBBB66D1CC54CA6B5FDFF6F55AF6439CE48B2B54420214147E247AD6AFE0612556F092C9A3009DCD78D322374D111B8097AB516402CB129CF3CDB02EC6F86D85B67B8E3C46637A20CD853E0419DA7351803B6B716B143636C6B67E911508FBA163FD126C895E916FDA1E61652AD18B5F875CD954CB401820DD4B33D42F6AC6EEEF32FC6F002F93A02DA8B94996676D189C1EC49DC3B50883300654904C3FF42EE2204AFC09F10FD31840DFC03C6F1DB94E9B4717A81BA75EA6414E25EAF1EBB07EB10A06DC8F6E998C8BD2B4FC11B0A39132787BCF8EF204325CD749CA55C0C0F181C860506422AD1533DF054CE2C4A14336CFC2F491D8898881C7BDEA290F03B592F41803DBFA4242B36A00AD5679A4B399F6BFE5CAD3651C20864278C1E21108FC5C931DD609DF0C862DD5580D143122B31752EC50166449897AB37CBD781A38FBAA8AEC433CFE069375345000C149664AD80A49A42D63E6ABA5EF18A7D5BF3DB41A2AC6F37EEBE6EB51D6A33DCD0D8696060CCE1588E4F5FFFC9FDD71D77841C999E305A89FCC77FA47DBEF546787A18D5BD3B245069E12BFD01EB979D661194A65B9F63B2B618A924BF6EDA90F10457A10F90BD0D8EC793ABD8826A7858691A600BDCB889CABAC8D6DE95D68A2AFC1B6A7D62286302D6C639BAF3BB56CC040D33B0187220708B7B9FB9B61EDB2919585F39171A084EBA668007357DBED95E8A9F4E19B91CCFEE25DCFD85CFAFA286A77451934373B5F100621C794E375F6E69F6DFFAF61B9375EC5B5EBC8F0AECA1E2AA2437D0DA7331207270FFDFD83CD40C3EAB2A4BD452DD5567FE4794C74509A840815F12EF9CD26DBD164B677FA61C06CE7280C7A1A9D2570081161C15CE3F39183F8D7DEA87966BF87E191261E810A4E476A29E8FBAC4C51BEBB86630CE74538E9161F05E001E7AB2DEDF2C4E85957B0E9DB53E2190CAA2513CFBEAE419499E68303810DD604475B2DDE732DCC42FA8BD29FECD128393E422E35D9ACC7BC70F43787A4F755BE4A04D21DB18559FCE2F8C54EF3BFF39348DA5E63456B063063786637ADA04174AB9B37257E6024EB56767E439125B55B23CB29B00820BF6C9F81CFE63392A76BD3DC57C574540C6BD3EEDE15DF113D2E8492260FEEAA8049ADE7A99AF98CFBB7C67F06C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 000000010000000F061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1008 -max = 1023 - -count = 15 -seed = 6F41B5F7648FBC1B70F35CED64B3EA95E04EF08CA2C96D8AA264D85F1556C15B295E98699431B072AB2EB621390B6BC1 -mlen = 528 -msg = B0B98E653197404F869906E4E247A0C65C485EDB719D0F24508F55E2E6B2F10247C431B7D02E7107375D6E3DE9F289993C5C082026EC982D0B3998448E4E82610A7EAC8ADB3C2BB1FA3FDCA3ED8151CA94DEEDCDBC6022FCC2E89C2CE89D3C3DDFF2BF86C3AA47FDB7992E1DFED195E2AD2DC46D8E8D67DF6C7157B85E941DA8A703040741DEAAA88FD97642B546C40A135E5D184403A218EF425069D698D9D2B765FC7DBDE46661644F616DDEA73FF9E0ABDBACE39A00DF1802BADE7059DEF4E2FD622DA13154612DE5A74EE2B38EC29D3F4C8AD96EFB347B29B77902E0020919C32E698EDF88816F4D8E55F6EB84B273B879D51AF6DFEFDCEC72113EA9947E7448C2D15A56E748D389FA84C94F8F67DD52B5AE6393EF4B48ACE2B45F4A47007F33CF1C40F0DD043D964B403104290FDCDF56AC39DD3BD28F7AB3EE8BB455CDB0E9AC9129363E8979B53E34320C6516F6861D70AD47A605A13D00E59506A6FD48D8DDFCFBAEFA0A3FC6A1D4B8599D440EE71AECF85F3456098F361C3BCD1562C8537CDA207B1911E33C58CDA460A7A349528DDF8B2AD41E979C858FEA5BE70F2147316FC92103D6786A75D1B3D3B5B18C9DC0A702710D3E4EF0AC9BE325CD0E8F1AE09ACFB0CDE162153CA8E894AEE6B9059AF9BB37150FFA76C532122531B3DBD4D323BCC10F3D0FC7E814C6074B9C5D9328510415D7DD236D478D3F349D5338DDA8D4BB273C8D0290664D6661080B -smlen = 2500 -sm = 0000000F6380E9DD17D8D82C80034710AFF3D2405CDE036AE70A8708C52A514783B2DD9212717E6AD1CD1A850658EDA7D055CF04648DD80D6DA435DBBD4140B90DE079C064D1FD5611B0F5810264A148DECD4E62A8554FE38D50E43CE5F8E1D72723C12134BDFA3105F5D90C8D21FACC87EFF761589B23AAB9DA9154E7E252ED30AA186221D640903E2A7D2328629B8E7C2BDC9CA34886171ADA9E8533C983738A84A2982797D8E200BF43FC145B4F4897D06F3BFA36D57146777A34ED9A331BF33028A1CA92C0B24E849A3217EA488BD91743A44700928532C0953C227CB2D55589A8F340AE7ADB2C032A35B79E35C718CAE4BC28B3DE25C031116DB97C9542E3782AD56511A9D5403A93A06482A84469362E83F35EA57660602E3E0A37F0173CE0DF978678609AAE4EF9A413E09A78B1F29534CDB9087B494AF99ED2FABDADDD2341EE50B9CDB3F70C3C04225599FC5BEABE0E4F1643685E5F2D9DFCD239E40E9F26AE5BCB355845BF3803B7A4FDCAA5CE632740C32B6988B8EEDFF960F9489C4A45CB5147A69658D73B1591B6C6867BE801E95EAA2F6881370EF61D17CA8FEEAB89C3914C7095AF2F119820585193CBB91F70D5408A623C518B6EC2468937C3D9960E217B79BA016809ED28604DE75C9FCC65F77503FC95CBFE6415F4C06B6750A88387F8AF1825C982369AC1B97CDA8B96CAAB4EEA9C4A1771427A64DF8F9F8E2C1DD9A2106D16216D1411D8F3FE17C191729A75075AF3001721472A311810E26471832BA89143A762DF88E00C3F958DF6DB414602AEB08E97A4FCE7219362EF3800EC2B3BDC1E2B936D8F4B1E4F2F65F2A40B404E397765181CC40D0BE334793D827F5151A66CA637E5914ACE7B72C7DF2E20841CB2CC3DAB8D00C30E7392F146B55770D4AD23365373C4FF113255C9DB98319A2ECD5B2CA74216B623F1E3AC2351B322C2F8296677E5A1C6E499019087B2AED8B8F7634F4BF74454B65DF2CEE89C3BF4458A240F2CDE6E5D6598607303746F22A5813DD284E458C1875A23738D2D061F738C45875CF1C09895424AF5B16C444935DA630958D036FBE7E8112307027410012162EF755B11A9A717FCE491597659C1C7D613917A3EE153C0DA747BA30979A75DABC39CE1C4DAFC9B8CA4B9CAD9389759564DBF6E5C44338DA26AB20BB89884ACE11C23C80C772F338026D679BA493BA54B43EEBC894FCFCB82037CA9B87610C3CDB6B40FE2A4D0D994736E41BFCD52B1E353DCD1F6A936D46A088658F29AEF70E52CB10B7C9913161D534DEDB19F3052642B2FBE3B7F13A9DFC90ED2F31CB13E40851E63477EBCA17AE8DD57162DBD50229E53CE2F7BE182BFDAFB1CBF7411BF81A6347D36EF370A80C214BD810DCC51AF6D41339450967BB1D64C83D291F6A83A34DFE75F8EAD9BCE44A1C35D63B5052DC6D1453BEA470CC4A305353E5AC54316FAFDE70CA0DA16DE0558F99ADAE0817EF389DB33520A86E1BA5AEB53F9AECC98ADEF00D191EF7366F35A95FA5875D9E9328B8B60E7F55B49BF8D813CCDD1ABD4D06F44B09819A2E8EFC61EE12DC83A5D46A2B673A8B985F763CD7D1A396F7E0ECEC0BFC0D4916946B68C6CAFE5F2B45F345ADD145ED25BA9BBDAF5DDB7EA6BE3B8E89D7A9837BB55851AC5DE3F0ADE35A3C5E1E39561FB850D238ACA632997059755FC1F5C9B7A58479CCED5251F39811885AB916CBAAE4698E8F6CC67D14071317FA79DABF2F3C9098438BFCE22F64EDCD49EBF75FCB7CF0D5804821B1892F7F417FF77B2C61020A1DBF66561B351503E8DED31427B50CA896A2BA37627477F33FC50CB0E51107ADD6391C5290C9CEB0AEFB837EE3BAE99FAE78C2215CFD10E008BD0F26490DD5A1ACC9727405EEFCE6CCACFC4F291D9CCFD726957477487E3B64200EC4FABB79A38BF7E1F4B00FEDE43C28D1E7A0EEF3B8E1639436DE69B53A13EF5267837A28B1E0788E736F08C5DE95BCF030F9B24DA8616218B983D22C20C6A5C4436EF236C6DBD6AED69D86F5BEEF250FE21FE4F75630C2D77D39FF35C205363A40A7461B12E2A52BF0BDF70FB8C6879D2A00B8CC6B44DB4F7FB8806DC5D80CE9AA2F72268BFC256848618F25C46260D013D3F0B0D2139B63829F1D616CF4D47749CFEA5E5336539214FA73F1048C0E012CB702B4D1C0407DEE769A4AD046480EC020E90622A2BF1BB6480E52E8CD6EA4AAB9F861FB3B9F2C8853F3FBB397BF7F58ED6EC2033FE0579ECD921C24B03A446ED3BC2F7C8B93D59E52EBC8CA571A6DA8AD8C4B2DA83C0A3EB19B5439235097CF87710D9378FAAA12EC6BF5AE6E36D3DDF2A4809CCAAE552E41F404006785C9BF30A7EAB3AA5CC9C9FBF7F8DFE93A356993D3752FE88C77E9FA9B40A2B5272855B8C7307119946E5577037E2382EC700F57B8B962DECDCD2AC7D6C4EE1887EB9EAD542753548A60BFE6FF83F8F9D8950B82C4642FAFB58C152D69F5E993F762A86CB9A13290F07AE77CF788361E5013B3D1EAF5174D4184AE7BF8711EA50B04163CB4CC7EF645A2822BD5ADFA0DEB85D6E1CFF105B1BC96F2C0644DD375E5078B8E3F7A0962C54BD89121DE087243ECF73588938F487F163CF333E5B5212EE3E71264D21A3965785F09CD97737CF0FD3206347A33DC95A7A31BBB2FDB52C0988A35AA3EF74EE257C3096FB0AC40CF11DCB91C09E1A19B86F57E20FC6C1B868D10B990BEFB03C975A0E010D131344557C8CB49BD1351E166B712B351771D7935E5A26BA1DCBC7832D467F6B8D2BDC69078E1AA40D236700EFEC54E7E7D26C67B2167DBE76C9F529F28CB8C2078EBFDB364886686DD3D251C6F060C1971504984D33AAFA4503043339A494FA48165B42CF153DF2DFB6B5ABC2716DFA6FFCCDC60C49C82D27773B0D7E6194BD5840ECCCDD59C776501F7C2793F726FBB79C7E174689BDD5D47E50DEE6B1FC2DBFD7A968A57DFFB2D646192DFF2B4AB63A284A9FC4583FBCD0128BF3831F579BE0F2000E31C7C98C43104304CBC168F60AFF77E65DE4BFB716B9F3619688945BEB34ED112E619B017A744A9AE1624A3DFF9E935E639D9DBF5700D99575A8681F83BF86EE67ED1D9E75F03622149FBAE8E916A1DAF2255304CC3676687257E6024EB56767E439125B55B23CB29B00820BF6C9F81CFE63392A76BD3DC57C574540C6BD3EEDE15DF113D2E8492260FEEAA8049ADE7A99AF98CFBB7C67F06C6ED9028BCCB791AAF3D679BFA20D6CF6DF982D4A166AB137796D648D6388CB31D08FB964E185527B3D7C13580E52A30F40A0B9764BD9CE61BBA6263CFF9DB0199DA11AC26B56F08913B30427020DEFE45B5056D2EE1A5DD1CC4866BD30016F748C3DCD2899B4A8AD108B686AC2985260CD274286B6BED29F2A76F058FD406471C5783FCA881501FCB5736BFB1155A501CD674620F158AE7D857F4F440F126C3FE6FD472885A0B99AE949CED819F6B3E91D5EFB5A62B47F3C08BB57F3A66482146F7AD3EE350C510732349F62CB0D57100A63E4DB00D053A58ACA49ABA4AD11 -sklen = 136 -sk = 0000000100000010061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A57A2329C502273655AA85737E957C7FA379A71BEFE44012B5249386CE2FD0BF64E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FD -remain = 1007 -max = 1023 - +max = 1023 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp new file mode 100644 index 0000000000..c56266bf30 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp @@ -0,0 +1,14 @@ +# XMSS-SHA2_10_512 + +pk = 00000004E219A0AAB2C8F4054939A56A419E39D2B91371C6A2A485B21D749DC399E0E58275A69ED6A400A7C1EA5A7B4EEFF0DB2A7E742C062A847DDBA24680388DDDBFC14D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9092 +smremain = 1022 +max = 1023 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp new file mode 100644 index 0000000000..299c00ae9b --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp @@ -0,0 +1,14 @@ +# XMSS-SHA2_16_256 + +pk = 000000025E84310CC01CAAD0B2B1E010C15F6691FF24977EF626465F5CAC2B015342A52404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 2692 +sm = 00000000404DFF9B9F3931FE6158FFF355A8EE715C9BC6A87FE6627928F3CA1055FA70104A82ECC99EF0F9172F36D2B461A6515DC13666B7F1D917746E7086F99C8F1A63E1C7E5A339AC394788015AB12B3532C7ED27D1BCE2B1F25ADC96165F6104861C3DCC2B150E1DD088C95AED7DBA928946BCC8351DAF6136F7335FA45EE8F4651CB9A6E98D556765100FECE8CCAE704D7AE90AEABE735C2FF46DC9FB302D2A1F4C33F371ACC4FA552FE83C254761E140E990474A10D5D2119D90AC9C2736BA2992026D11473619FC9D1857C50BD2ECB693FE0DD9C15EEAA100015D58F2D8F936E154B5C932078BABD1E9A3E3D7B876174311282D3C02D8463E268FB1542D967EEDD01DA7D0ECA0E3257F84C2813FD01B211B495B9191A48E3CFC34E056844855BD1EF463F5D1F9E9A8C7FBACBD29E2726EC1AFA11522536678005155E1CCC5562A8C0D1AE450EA842EE72F236381AEF42F2445DD5B9CB2A791B1D95240D10FE14A3343E73C5FE2CC524A7FD21FA547675C86F6C8D4EADEB1AE29060EF687EF65344A45A5F1033DA0B50A5529AC43435DC3A8BBBC986F1ACC1AD60CC13F9BB26A1F99DF207BA4E2C7B1A4A0BD8B5B9529F705C1C323AD93B7F67D735958A454CC7D6927CB165E25F6C4811F8D486A34DAC2C8A920D506682D747BD6496258BB4011164FB8F12A3E984085401E73A96C5A0B7A661F6D9288910CCF1C1101E0BBB68646191DCEFF06EAE14F3762FA5C231D3D57770F230802C2188D108FE326778A10980AFDFCCD50CB32C844771C1B5DF2054A7F9D19FA28F461E81EDE49B2D780FB3FCF424A28FB9B2E88CD08E4D4BCC31E1BD06481E817980FA8A40E74D0CECA78B87452100271944681A77667368E04F077001DD9B1454DA4614F631A83335A8C5B1F83087C603CA6D731A4AE32346FFBF5BBBE7FFCD206304CA468789748789EA6620D7C8AAA5D10EA029C3EAF78675E35C29A598CB5624FF0ABCE0548CD6C9DAE3CE9BFE4665EE57358DBEC0D157880889597F245FA042D00FFB56066AC873718FB1BD12E0428923AEF51F55928C8DA0D632382E3325E4CC5C6A3EBC4776C9F6520EF2C6960F0129A707F90315AC1AB035A7BA0D293A6400C30D363DF000F53D309FCB4CD455AF4290FE44F8FB76B6C32ABF15BAEEF44136CCD739D96CC95B0DC0EC8186125075F21570A6440A5967CFB83836BBE0FA463C0B6692A9C6D673038D17D343EF79BA50ACE3835F6216C3943470012081600FD81FE5B31B604E946A2328C40E977558DBDECCB8D643E07A573A9CB5DB4518877320FBB4998BFDC59FEDF2EFBDAEA4058725054A1317CA755D3BDD4780AF57F3B76649B3675DD9DD95A16F5CBDFCE00CADC229C2DD7B4E32D6EF82B346C5900BD03164C1896A4640F8B79FD7241614D2FED6D1E2E5795827F146C2158BE0A39E9556BCE1B08B774531FBFED5012C3F1DDB0C27A8503A43AD652AEBCF8E6F904EB09F30AAFF35952227395C3151F2927727015BE31E6A03C994E8011B555AA21C792E806511407B653D1CFBBD97D1D4CC87BEC5E436487DD454363E2E87AF3C2AD4590B98E9597885A533623BDDDA308151FD4902D8BE5EA43CEC046E62DE367D9C21F581AC2EF46EAF0F0E10438D4895C49FDD3049A23E32561BCEAF00F0C192BB9B2426CBDE0CC3E6186C3228990D0C0703BCB923061D0256CA76F9A75429F35CF416D6A93FE80E8C771DE016EB671CCD86B9B221CAF0C521F58D8BDDD226514234C6D44554A5943C782FFE265FEB6309F643277F09495ADB42B4C362E1EBD6790AEEB0C5329F797809B1A99E617BF85395C38D7B367F2C2AB5E26A156437E7248DF2E9F2F6170493DDD3FD0A0CFEFE8577D87D69AA8E668F66279BE02DEC2D05BBA330A504C68A7E81709454395DB2C55345262308C2443E6D245675277291C8E6718B222332047A841B2EF96801D464F6EA1053BF96F6E69F495D45535AC3FD4411C27FF7DEE1A7BE429B3D9A386E40B99329DE24163911705BC3137F0C728AB5848532999315D7DD980036E8107AC3A68691D840FD37C6950FED7E43C79CED8DB06685476979EB357AEFCBB1CE969D9C37505FF2EE6B27F8FCED566180664EAA36D867E2C702C6716A8EC826FAAD00204EE915AC2241D72BD22B8C46387703E5005F5A2FBACA6F84D5B6250F4B5BC0A2A6A31DAF9C60EB13C20CC649A18E27A6C98B82F08E21775133C937E715F8EB13518C059EDF4585E7446408D2AED56F1AF125187E172DA47D9A150ABAFCBBB6BD37E68B51E1E3B76A88186784096804E0CA23134BDB161B70F2AF126A3DABA5C918B224DE444B8733E6FA601B3D349307E94583D0EC97649EDFF2BD44402B649537B4A3AB06D71227E40BE5A484B47D7364A839A4730A09D12310A297840646C5828AAC63A9C3D416A375BFD3CE0D4A35C24762B458CD70B23AD28725612F5FB98FF740AFB457915740084644120ADD17B445078AAF541C08E140C4F0E8E005322F8AB6BAB5DF2FEF6DC1EEF9555B3FDA2C9354130A171A704637AD2E628163EE49D33FFA1530ED03F0A3E771B74CCF546BEF58EF21DD1522538D7ABA7F4A83155F8567A89BB7E052994F9E491025A37F3229BA80485F66F0BFEB7D77B5227DB43AC1360C86DFEDA86872B28FA47CE1C78A4DA2508F2144D5F353F6EAB57CC363587735255342964CCE7ABFB619A8072054867C554D4474EC48C059D2384AE7E36865F8DDF0CDF3C1B34C9783169B23CEAD96903024CE5D0B798AF6C9717BBC5DEE4C9150E8B271E12B53D2DC24D62BB1B522696BA13C595EED0091E7B3E7B5E50DB3DAD2516992EF120B950C8A22C5D1DC1959D8A6DE0E31E568B1B105DF9711B589CCEE0BF0A8A4597AFB9D07663D1FA4FE307488CDC692382EFB7882F60DC53AAAFDF2014CA7D27F8FA93C187A8371B41796557AE738D2AE42D887D10EDBCABE6AAF951E0A070D881879332064C99F8527A5EFF252439DDC6270CBF5906FC144DE1CBB74B260E8615FDB2903BBACC7A30DA76937CC982BBF293AF6DE61315DE00A8D15148487FFC0BA96489AB359231EF31202AF53CC22F2E9109F9BB35426BDDB4A69EB8F45CD5B226F92E8026F1E62DE1DE435A4FC0CAEDA91C38A88F0037BDB296CD7B07FF040B1E08F02711E946B307A5A38487F53070985B8E28BE6CCE809F34100F0CA780996CD38E91BA7773BB632D0BE7978F3AF3A92B961BD3A8759590726D6C1811F9E0BCA87377334E7C1F12FE37401CA0200823938C816ED98981521470F7F2CCDD69D85E7530EBF39E3A592B1C09BC6C352C3FDB108FB26E7ACD3D5A4FC0442962E2C09651AC0D026E370F1EE1A8219C4833D70793D6E581FD25B0E95FAB1EDA67232C2FA12C4E379A6627E75AD408C1D2526005F2567CED8608E88CF53064FCDC58007198ADFA860F9FED1DF80EFACC768A0A063E1AFEE6DF1BE3483105B1C45EB50BF7863B4278422CEBA9001EA00299AC0415BF28A9C49CC2E92FC15565B547538A027886C6EB0D83B71138CE1ABCC7BF5184638350478FE05829DCD0C5190BF84804D293190C08140A600415D691DBB652DE950481258ABD45E76B9668FEEB94EB6605DF5900501BDACB58F4CE0F6B0120CAB51933633EF98DE5471774EA6BA1642AFB0DF6C7041A8C05555A5F1D0212EC753E23A7CF68CE52417C9D7CA5F9C180D04C6B64F70CB860D2903E843B956807A682500805ED38DE3DB09B05C5E31C4E78C72F83F1446F69441E4D9D9168B4F97EE394586A683D38B9FC72FBD5D92D976C70A407E0B1E25F3046B583 +remain = 65534 +max = 65535 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp new file mode 100644 index 0000000000..ab807bc996 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp @@ -0,0 +1,14 @@ +# XMSS-SHA2_16_512 + +pk = 000000058AA2D66ED8FC46C0EC0504C56F35B897EEE56E6E022C0020BA1B38E675296297D99CA20060E4954AD137D640B279CD2903DE768E1FBF6A412EA45B5A33EC55D54D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9476 +smremain = 65534 +max = 65535 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp new file mode 100644 index 0000000000..5fb1e18f1c --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp @@ -0,0 +1,14 @@ +# XMSS-SHA2_20_256 + +pk = 00000003A7FBDCA19FC30ADB13F35C92F71086094413263CD71A0570C9C2F250CBC2842704562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 2820 +sm = 00000000404DFF9B9F3931FE6158FFF355A8EE715C9BC6A87FE6627928F3CA1055FA7010C534B0D4C6FFDF4DBFE00E72405EFE83BBCF19AA2030A8CB163808482B6376FFD2CB50DDA1EDFD708F002ABF07D0001C3357A70F6511884C4185790EECECCC578715C21A26FC1E7A951C54A30ABCDB7EC71AAD92F2662BC900F9E9A93054CF39B9A6E98D556765100FECE8CCAE704D7AE90AEABE735C2FF46DC9FB302D2A1F4C3C0901B0B16F96846F8196BA6E2E8BA4375B3F5FE010A02661EE3374C1B28A76A4A8879EF91C329714FFDF118CF5669BF7BD65CBDB738CF6A8636F20F399855E5BA4B0955661EA3FC882D9D64954405502E2BEF7D3063D36F993460D2557C7977DACE2D6D7D9A77DEB151610372F7DA0C73F7B2A737064A6C62DD0CF4B69F1CE4D9BAE3589B525734E92F3F8D4D2AD9091B6C82F7C0189D3780AD854BCF3CD62ECA5F998274C2E153FFF3CEB473D81B551AB5F85CA351B4BC225D7942733BC8DA6EEF78B8184B2E355CC338055DD2A26DD02B1A0740CD15F6CBA4EF429254DBCE0CC4F4B00DBFFBA622360B091DD6AA817423484ADF53F5D8A30E3D4164F539899DF207BA4E2C7B1A4A0BD8B5B9529F705C1C323AD93B7F67D735958A454CC7D4290DEE03A74DB1B3A62D2EC10EA3C3EF2DB3375893598133F36B5B8F2AD5929164FB8F12A3E984085401E73A96C5A0B7A661F6D9288910CCF1C1101E0BBB686FC03DC302429EA2768093BA3B43C542F272E93D15A190426830A92526E5251912FE8153DDA93C92A1195701DAB2D2A22C9F380DD4984645384692FF8721D549A4CC74ADF8A5C2BD5DE48F6A923D8FD37E36377639AD73D1C7AE721D0152DE0E73844FC867FC8C029E657271B738EFCC1A39C2A64EC5DCA96D89BAD4C407D4F0CB226B913ACD451E7C65BAFC90021E665C24A2EA208A16D92E9C27BC18B9D59B7FAA8FD4A12AD43A403062FC7003ECC756E3E26F8B1BA47801DAA46173063E37823CFA4B1481DF4C88093941CB014F54D73B5058ADD52B6A0638C8F3341DC13235F18FFADE0EA5601EE831BD587A8EDB72F96744AF8B08AFF190BA55D0B25D47F33F84F17D6C15B50AF1684C8F4044CA7BA2CC196C7F3CC9AC2603194A9A536347F33972E57BD89F4E3AB7977CD3220C0D5E54911F17007973BAEB9C8B3DBB95D1483FB4C281E8137940969814A5B6FE7D1057E1DCFB7AB61415E94AA4338F0635813AC5FC9767CAB6C9B71F63D372BA40AF511C7259875386539636DD45512165EB3E72F1046CBFF94254043D879CA0B64F7BD7AEC79F5F87C11DE3DE80756E9FA3DFCF5C9CEC2D80AD509A65AEF0E3E663B7F31BCA437311BA799D4C2ACC13818BDA90266F7A362B61CFDDE0523BEB8866B829512E9B625A90898DCA3DBA0BAD32BB3F2B1687014B418E277BEF2F73A6CFC6016578227EA1A56E5F7655C68B27E3B486B3D2D5EDAD5390DA570BEC6613D901E5D75A913978DF9002D8AF64A9B4E6BDB7388057A17624FC600F3031D016E61D17E3E6A9B2771E2CC466B2A17C425E4F21F65131B4005AF392C685BEAB2FF1E5E4E886E1454DB240AFA0319449B4F3DACFC2FAFF74844BF8128A3B77237211ED11362BA8A6F87C6D103A23A7D6628B57D137C5264CC2E627F24A3BAD50EA4F75C7BD8998709C01ED5ACFFF08919C609F8F74BF5303C281E4D8D1488EFB7FCBCF8AEC5C4B26330A6CF6E4D798C1FA4FC6DDFE7FBFCD3C4CCC352F28FFFB9301C08B0731F472F6CFDED99EFFBDCFF23AD4839258197D6706C3551375B3F7359C6A8403C9BA07CDAA348C82E896416D74BEB3BDC53DC8CBD2A281340B78F7635419636A3C38E9D5515CF8A035A439D322FAC7F9853AD29B44EAFA7AA9A4ED2471B0BC91B4E1FDB7E6A80056C0F264CD1E0837F2ECDB1EC864CF6565D6F9ECA34C9B961B278867E8ED627C1CA3F0E05A841B2EF96801D464F6EA1053BF96F6E69F495D45535AC3FD4411C27FF7DEE1A7BE429B3D9A386E40B99329DE24163911705BC3137F0C728AB5848532999315D616AE1EE474D3F1C1DD7BC7F282E6DA92731914758830B8AF74345719259AC8366C65C61697E08F06B61AAFB4C247C6FC8412F815114AC9C3D9172C1B5CF22867D870CE2534C0C2A163DD971EFB7226AF5B9BE4351DE6AAA45F27F9B2CB0831FB8C51B0C6412F36BA064FEA5ED935CD8FC498C92D651E2C9BB0A294D35E87BE8B94C03E5893DFAD17EB8A15E5B131E62A0924331F3888CD95D68D0541171EFE3389CBEC636344A6AB01468843A94F56FA7FC1806448C09DA99219B5B3FF5EEEC1397B66DA61A963FEAFD805408782D911B79206BE9A53D04EB1ADDF69988D97437FAFA9FE1D707144A2290523A7D25AC1BB6206AB824556519D2B909E4D04DE8D8D35A0398398CFD1A6A4D5B8B9BAC3A42A27B05E91DC07C8AE10BB4636D08A9D08F444A61A465254F464EBBA190A6B09EF04567EA727CF57713F381DDD9FA8D431BD19121BCE533E07068AB0500B15488F2F60DC3C2BFE4CBDBD849C873D2036743E7CBED5BFC1F8511489AED9E0CCC0FAD5D9F1805544D2A20F56AAD3E0058522538D7ABA7F4A83155F8567A89BB7E052994F9E491025A37F3229BA80485F6823B9A3781C1CC42488414DD491B2F80FD91E049E56AFB0D3823E66A6A3FCB1660641E4368990B3D05CFA937C51BE7692B36F007281321B5F317242030B2007DEFBA495E0499587494A9B6E4974C37F5C006A34FF102A23985FA9F660326DA39E41C65227E6F51D5EC56D93D19E1D3279F668A13A2B3599139B265111473D5F8F0B23E656D7E2729177C18213323818435F2951FAF7288F66F9B7B6ABBFC9617B0191CC9DA4EDE34F511E0849E7C27115FA6EB6C43172DC2FD4CB1AF4C27A4A6874419356CEE67CFA51989ECB77328F87F18629E63A6732C5BEBAB4DB4BEA3E19912E5991C713532E81FA57F9BA562E1D3026D2D2D7373D99871BC62768AD70D982818E4AA66E926983B45F64AA0172AEB48B28DD4994F24311F28B2577791EF712689DF5DE30ED5313C773311EC605B8E44C297ED4AAC95D3B1DAA8631F7786C22F2E9109F9BB35426BDDB4A69EB8F45CD5B226F92E8026F1E62DE1DE435A4FC0CAEDA91C38A88F0037BDB296CD7B07FF040B1E08F02711E946B307A5A38487F53070985B8E28BE6CCE809F34100F0CA780996CD38E91BA7773BB632D0BE7978F3AF3A92B961BD3A8759590726D6C1811F9E0BCA87377334E7C1F12FE37401CA0200823938C816ED98981521470F7F2CCDD69D85E7530EBF39E3A592B1C09BC6C352C3FDB108FB26E7ACD3D5A4FC0442962E2C09651AC0D026E370F1EE1A8219C4833D70793D6E581FD25B0E95FAB1EDA67232C2FA12C4E379A6627E75AD408C1D2526005F2567CED8608E88CF53064FCDC58007198ADFA860F9FED1DF80EFACC768A0A063E1AFEE6DF1BE3483105B1C45EB50BF7863B4278422CEBA9001EA00299AC0415BF28A9C49CC2E92FC15565B547538A027886C6EB0D83B71138CE1ABCC7BF5184638350478FE05829DCD0C5190BF84804D293190C08140A600415D691DBB652DE950481258ABD45E76B9668FEEB94EB6605DF5900501BDACB58F4CE0F6B0120CAB51933633EF98DE5471774EA6BA1642AFB0DF6C7041A8C05555A5F1D0212EC753E23A7CF68CE52417C9D7CA5F9C180D04C6B64F70CB860D2903E843B956807A682500805ED38DE3DB09B05C5E31C4E78C72F83F1446F69441E4D9D9168B4F97EE394586A683D38B9FC72FBD5D92D976C70A407E0B1E25F3046B5832CE029A1A95FFCBD5C8B157282F7364E680C60B252C49483FCA03529693B074E0D2B1F6DFD6463B974DE6829A616F20C839B0D2B8BE5405623B5B722EF22F7A3BB78E91315F715D9DCDB0C8639CB8A90685BEE7969671789047083CACF24FBC4B601B1B23B2E79E42176B2438CB405BDF46369F4DE5F411B2ACD32BEE3065DF9 +remain = 1048574 +max = 1048575 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp new file mode 100644 index 0000000000..92b345dd0e --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp @@ -0,0 +1,14 @@ +# XMSS-SHA2_20_512 + +pk = 000000065711A97061C93B4FF7199D48104CC42415C4634EBA3647D8E51BB1ECB7D4C455418BDE977F20460E48826E531A7A59E7DA8746D7AD5D80CD059D8007C2E890304D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9732 +smremain = 1048574 +max = 1048575 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp new file mode 100644 index 0000000000..c684aa186f --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp @@ -0,0 +1,14 @@ +# XMSS-SHAKE_10_256 + +pk = 000000077B563C8B187847A60569B3A0CD3049A5DF6CA3EA3B446D75F99F8D37B940AA9604562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 2500 +sm = 000000003017CF6CDBA4AF7D6CA495B9872967AFAB62AB87100AA92CFBD66591BEE188E651324F8D245291EFF735334671EFFD85F3A823D972D2D49DF408A2AE09590B24CB219D4BA4FD030544953AE56AB3CC426D1E89F8567A33D4ED495164A01434E617E01CF73FA1022A8E19ECD580802F2A359A6BE287236C711249E8CFD26E81E0D962E4E6007A684AF87B096B9034966949F56D02660E2B7279214CEB93E62073BCA7A334E8928210CE101C948DE9105A5FE3B87AB9741B4B4185D7EE42AFA3055430682E22AC918051D97466B12D2FC559413DEFAAFC677C8351565ACC58D481259F0F41EE4C3DA4365AE4ED4094E4B7406AB6963FA3883037750A6ACBD864F56826811C4DD77FD89B17FB35E2EA7C907A056063335AE03884B54E791EFC5B68DCFFA47AB17563DEFAC3A51C0C7E96367FD2A5BDB6420DB2F8E1FA8A1E04E02B5033836AC23BCDF359C659C13E9237867828AF0F173B3F932629847BAA0FF1658833035CF78699FC249FF331272A068D55590E7451D2F1C118B8DFE554FEC7D2B2E0B494B145F9033007E7EFF53151299DA3E5C48DD1F35C37DE0D832D55AED0433B04149A965F5EF8A804F0E6EA4239ABF28A694648719C1A4A315A4EE054B04CAE408D5436A081A948E75B7EF5914E0DD9A9D01018918CBF37A224824D0B936F9E659D7C7663EB4B63FABA90515F2700301544682570E6B3EF16C59082F949173C93ADEC1E111F387845B826C3523FC184B5F1D1D830191C88D1F9F3C3A81337495F73F2B992EDD1E9D930F098492BDF4DE0C16A604D71CA275176A5C2148B151E1961C11F7D8CCCE4F08E9BADDA88E17BF2DB02A6D1E1D2827021DB46592168223ED5CE3170858485437C132229DB3823CF7D727E8DDC6B6BF00983947D02DA1D6A0C82EF62F0B0A9F1FBC427D200F636E66DE934401583B67DB03BB8492A21BE921E1C2CC0ECBA29139E304A0BDF7123670D3FF614F1F0E22C7C8E161E91E90EBDABC3BDA8347463B052E4E97DBA22481C772462763AA738E424431E22FC0B8441A43735869308C228166FE2041FE782E25EC9ED80EC9994EA098FDB0782856925994C9E8FDF09EC353677934D465C348E01FEC000C30ADC8B85F0C19844A4E6B4D0E8F6B2040D9CCF85DA7C9522BD571EFF09D5B1561225886FFCD6B788E6A6267ACECD693E42C90E4730F2EBCF73204F7DBE114540F4AD0C2CAAC6D0565C6DCE9F7F1C5542DD0F7016BD1C976AC68FC2C45E702D9D428999F9041C8CD89B70FA2A90286D7A5F6EB267C45893AB7A9C0E9F75889E64F9A24ACF8963268ACA48B903DA92B5D86FA1C5E8DA5C12CD2C030F11A8F670E028AC1E3925B5D70E7EF6E258B5B1C7F64D767098FA20C976F74949B4BD4792A13DE3CDBAB345B43C1900F6F63F45D02F6A576D8E6234AF7631821A82C758CB0FE7A920EB689186D83BC6D34D4FA579D07F899DE605C6B6C53BB3EB5DBDDA07747CD49164C54A9BF8A9F6A9548A58E119830C4A1C28BDAFB0F94E7539D5F73E2043018B8FCEB218AD24D0B5AF139DE4BF0968A70B206EDA0FF3324096BDCB13A3DA1C550639C0606527E494572744D779FACB63A81CBFD2C18FDDF4883B35F19FAF86B48D5CD2DD9177065D7380AFB479A59205262C98995C8EC3B26E648E01252E75EE3278581B71C84A6F9F49B0EDFFDCE1DBC2AE84F1FD849E3E1D049EDA6A5EEFC0E5EFB68199B40274DBE381ABC0C1BB6336975F1CB08EA7A875241CB911B9853025F7CF48F75D4FA0ECC39C94887E71903538BE9408E8DD1AF757ABC63097ED308C7F0EDF784DBDCE94CF1B52C96E524E7179C8ACBBCFCAB586CE6CDAC4FD71787904D4D19A3C95963CC8A0B0F4073965CD5FEBC875F971ECD647F269A6365491CFB0E6F0908347A384EFBE009EE5ACD512C88DC34BB54340BC9B1C0CCA389E8BDE6AF14B3DC4672459266931B482AAAC2ACBB4542B22D3D25E2E279700167CD7AF03866E60B41CDBCDFFF1216F45CE0741C53B57059C2F55F8D2529C6B0E760FA3BB04A38153913A2A372B5CEC76D57348A81842EC2A2BA6D8D23C976F3CB9F3D349A8448C04962D6B064AB2B8D48AD48F1B221B7BBD9612FBD83C101B7047D793FBD30262FDB21DA3610060FCCE410A86D46779A61C7122F5BA45A814E46224EB6D5969EB9FEE6EDCEEED25B698E4E83CA574A8AC2896FBE20E91DE3BC759FB39137FE7C26A9201D40914CB387223C9F8937FE6F5503D7C207C9330CEF1A170F355484FB1A3BEEE3253FB58D7B532C7885549593BF2984B3D6FCC2E70105FC34A1CD9A85B5D7EEB3A3EB4F07F2E7E0E649042A947B4F9D9A5149F0D57913A7EFE5265E853091C4EB95FCB9EEC69656DBF47ACD54F0045644E95BC75168F17C797F9E54C42DA5ED4E72F3CBDC54D20135C64F39492E2F2F577EB888047FF44CC2528BDCF0F387DC53F045523D40423CD4BA0626CF907312F5314FD59BF41A47F18186B517A59C7B9BD07FFF6433631AC5C062DDFE499E0C22DC5E3A10AB8D8D0C5D9A098331052A74A72C2599419F61A78459B45C7976E43E96BDC2EBA3AE45FFFC8766D70CAB36512C02951240FD5ACE420AB2C8CA931E1113F541C8439AADB13BBD01D08553C645E1E8AD6AC0BDFC48F9179909E135B6055FA9CBA44BA072D2A538BE604D931A5E3273F4F5BEC1CAB03D56A297B5EB5AF99C83F60C70873CB17A1ABB1665B6D7DAB0DB36359457BE473FBD9078313419BD89B3B947A46C2FED48F0CBF057F179016B6DA9B9ABFCC164E97B4E56278799D669385C5F0EE1BC47C9DF611F3C69CD4BA07AECE7C31D5EFA0A3D8FFC137CAE208E806DCABE99584F7EE28086E4A338CE9B8073DAE5D30A9571B807D43788E72A7A499DA5589B7C5BF91173A9A93A386048112071548CF0A71C9991DBB3A11D93483E3716D9A8BAAF62BC5BB58B991456CDDF24C6BFC89FB8A8757F940DF8DE473602610F33F655872E11109EA6E323ED6E8A520C761F371CF760445A3E865E4B2524DEC48F47386A1E6CE5561FCD200F736E4CCC848CF9D69404EE753B6CA35671A40AA2B667270FF670DCE5AF0E70EDE870D540FE22DCF51857EC30BD19ADB90CC68E6E51F3AB68DE8785CF510E7F3A5A039709DF63B801DC3323251351376715F8095ACF170629954B96795175B24E1C258AAB6CC89CED08AD7F756DEEE47A8D0D840E9B431461563DB4EED9560FC38258423E965E31E14D6074C9346404A6ADEF162D1C91432E5F83F97BE838879301613ED7190B2364158338F84A912C522F3D9E643BB90D65727628D26C8694BB2E1F35A45A4C4DC4F6974F9B8371DEDB8D4567370FB91A3AB7744D87321D2A37E808A0AF39B13AEC4593BC12BDB3FFFB32E69644B7CAB6860EA783BCDCFF142775F8C724B9F3E28C6686F9EE8422B03DBE8FE038717EE84BA5A8636DBC22FC29FBF6D07DF598B4641D4EEEE179160AC230A6A201F4127333E15975099212DA36524881CE7A2BFDEB0A69944804A6406D160D57942E851CD23F2445BCD +remain = 1022 +max = 1023 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp new file mode 100644 index 0000000000..8cb2fae6cf --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp @@ -0,0 +1,14 @@ +# XMSS-SHAKE_10_512 + +pk = 0000000A28C42CBBFDE2F32EC67C1630DF460F62D15643A6B5FD3A53D78B5A0011F6621D645A874D43300F9F334AB1D6DB08EEE382C34931E9EBEDF37ADAA8A57A37AA404D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9092 +smremain = 1022 +max = 1023 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp new file mode 100644 index 0000000000..0726254105 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp @@ -0,0 +1,14 @@ +# XMSS-SHAKE_16_256 + +pk = 000000088B4832442313757CA73F5832B981BBB6B72FFD8A75EADB03605950D69CDC5FBA04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 2692 +sm = 000000003017CF6CDBA4AF7D6CA495B9872967AFAB62AB87100AA92CFBD66591BEE188E6FE5428C1B38A2155B8EF1FB9DE8440D993A1F197229DF83843A1615CACF924D481D1478868BB902124AF51010672C7478B1AA93977097EE47375B6A5BD3ADCDB13077F648B8C7435CE755907418C55379857F06E2F7A61A232B67C86AC1352B9854E31EDDBFAFFD3992A2FF8D8B758452896E7B2D56A89B09055C2684A6FBCD2868149F65E73EF30210B36E03DCD6257185F671F78904B3F11EC67EAF994D1B9810B03806BA5E0F9C9F764CF3EFC1772C1624A7C8D63A6295339488C2FDD9CBC4D52F94BD09075E359134DCC1745B0B9A12095AC493DBCA32FAB2980588C131B31246F16CC261A56C9F1903B0B4498B849B4598E5F8C73A6A1521F7D75628427F95374C29BB0585B22A7421D7A01B07092AF4E6C0D03F0445A64110B93F814194F4EE29447A8424917FD3EBBE24F5128280697659EBE4569087D96AD8F0AC7B67D272DEFC429B7BE6E9F76ED4A60B42FF5F0CF9EC09791851E1E7D263EF374CFBBA724670050F31569813630709AB6A4E35D66684AB154CF647FD64DA3B2E5530B4ECA5ABD9666549F8079173D267642D94F9660C76FF6D5378E015B792B13BB773CEEF4C7B3AD10BC12FDEA7DCC1891BCBDC9CD83ABD7DE6012ED3F07F1CE676F9E659D7C7663EB4B63FABA90515F2700301544682570E6B3EF16C59082F949F388D9FDC43455CABDCD4AD51E010674F23D753CB00A62685205FAD8CB4BE5D5174BC2039A9D72F3887749FF061BAB898B75511280A6E9134C3379B1609BADF260A2F78C4C9863965A97BF5DA405B992E011375D9834FD1AA73799E97F4F701E1453388E6A2E01080743D9A836F20FC93663C7E4591849A616ACE98011E52BFD3C156F233100992998ABCDFE26F36A0A4191998EBFE07E2B4D7D9787DFB44F858B43CCAA440867C0C6B6C74E32368C7884B8860E5AD1B518F322EE72CEC31F5253891BCA1195D4B5CD305ACB28479FB1BE4550E16F85D9285EF98B1F325D755F2D43E285EFDDA4F0842A1727C2EAA123789C359DF0C696349055E452E7F27CC668814754D5F91CBC9BB551E5663948A692D12D054D90840580C1D66423931FC5A4E6B4D0E8F6B2040D9CCF85DA7C9522BD571EFF09D5B1561225886FFCD6B788B60A2740339A04956DC654E108016C69006BDE4C2BEBB3A3DE40FA45F5DD19D0E3F2D9487FC2287870964D9F328563E36677622B3E074A980DAB585FF96FD09B95A6065CB8246841079ABE344B55A1F2D367FB3CF72F1391462C45BCAA89EF4D623FDA3904F18B7739B10C9EAC71DCDBA418DF1E5DA13E1BA5A122000BD71E0C2060ECF72407AFDEF3BA54EC75F425B4AB32F564854AD5C39A2A1D9D06FBD74DA44B83F449072FE1E7F6A82B308A253FA60B722B0B949204E5931BCED17F2B1C5EF51D9A6F477F108EFC9DCC7F139617993D5362ED390A73955749EF1FF0825D95C689192BB35FCFF90B87519113376A44AE4BA207EE9AF82719AA72ABF543ED04221A9176561983CE0FEAE6C491381F6E112192272AD8C82CE4037BD968C1F4E7B693C41F717FEC260DC06486D04822DCD3BA1CEB89F12DFFE3534B51B107E73383B4DF8B367F2E123BC873626A8EF6142C485C932E27BFE6024722F5825CA4C84A6F9F49B0EDFFDCE1DBC2AE84F1FD849E3E1D049EDA6A5EEFC0E5EFB68199A9913158FD2FD0A1EB0C039623FA42CFCF6A0AE68C6B65B60D79C9987EBDDB191E271CD9632AA1EEDD35A437D3405B89CEED11D4871C6C1F9A9C33B15AC647845C27F1B5233F2C78E908DC396F097744D841C8BF1BD732255BC62E601A9E50DABEE504FAFD020889BD3E0335DF683D946334C147F31FEC61975DC21582CCD00E77AE099812A621537438D6AF2F1A64E98F801173C97B9EF4923BE9B179A94D20D64CDB799F04FA406789F34D5A04CE3FEA635DE803FA73EBE3439BA0238086F39970601DEBD0E7DEFA07933EAD357C796B76DB6E6F557222BBC9AE2F4840F608E59075A190F8A156CA92CC81F4F69369EF086D61EE895B7F12C300DA076E09BD43CBCAD6F5857BAAE18071F291C3D742C9FF3FC54A51D1CB8061D5A0ED4358E8AB70079EFEAEB3947276F612A4376555002FA7AC9B7EC9778FC3B4A6EE1025D4C73A8CABF27E1CC7B33448B947CD339BDFFC9F377952D6249911F099F535E6FFD1BECF740CC96822076C1C173E32EB8A2A1D282D8BFEB277B9BAD5906F6C8ECDFF4C980A4F708C8D83847A125F12D726A803911B7669FB587EDDAA13FAA92D1745DAE5494E4DBE639AA2B03412ED97FE1C1EFC391CBE070881822B2626AA473C605E9D16D8A4A44644D551C332240FC9CE25D8A9484A9F0A65B6DF11CE50A984285D2B583BC4ABD4A26907E5613CDD84BBC4B8A6FE153F5D50CDC700FA96C40B8F33F4F73F6260DAAB08BF5A02A2F664E62BC3BFAA6A4800EEE8423D93ADB908B28E1F1DAD9CCF410A1A717F2FAFAAD47C60AA96B100947EB6EDEBAA92FBE4C0AD2407EB3D645DB8FA4EEC242E907FFA8E6D5771F18739E44FF6E70221FA212F5755BD9574163E60412DC2DCC34F449167D76C769FC5D9D4AEA104824F0872C46D1E4C35F337D007F2EB9B832EFD426982739F74A14BEE901570011D4FB7F43B5069C64556087A248D8C09CFA5E34600B3BD6194649DCB093B3DF86DEEB4FB42EF65CB5CC3C3FDC89852BD57F34D20B9EB617AF516E372BBC4154AA94744BF2835AD2E71334279B019756795B96FBE4D57FFFBBD3D6E4E5786234FDC6E5768AF9329225E1BCB7F680B66729BEAAB9C5AC5A2120C8D427E349F364F595BC1D72874466844FCD43252D480576898E9037633A8424577B3DCFFA3AECFE14317B60F84E450247EEFBD497F4F79FBFD48BD99EA0CAB725A1A4F1CB10B461FA0AE6F5FB991456CDDF24C6BFC89FB8A8757F940DF8DE473602610F33F655872E11109EA6B7E3BC14749E7C7FA2F28480EFC0784B9C5FEEE217946EF2D55F5FD2902B6E080431350D4BB60DFB6DC98FF57CE274ECF76AB7C2E9A87D99EF54D9B8A5B4481F0E70EDE870D540FE22DCF51857EC30BD19ADB90CC68E6E51F3AB68DE8785CF510E7F3A5A039709DF63B801DC3323251351376715F8095ACF170629954B96795175B24E1C258AAB6CC89CED08AD7F756DEEE47A8D0D840E9B431461563DB4EED9560FC38258423E965E31E14D6074C9346404A6ADEF162D1C91432E5F83F97BE838879301613ED7190B2364158338F84A912C522F3D9E643BB90D65727628D26C8694BB2E1F35A45A4C4DC4F6974F9B8371DEDB8D4567370FB91A3AB7744D87321D2A37E808A0AF39B13AEC4593BC12BDB3FFFB32E69644B7CAB6860EA783BCDCFF142775F8C724B9F3E28C6686F9EE8422B03DBE8FE038717EE84BA5A8636DBC22FC29FBF6D07DF598B4641D4EEEE179160AC230A6A201F4127333E15975099212DA36524881CE7A2BFDEB0A69944804A6406D160D57942E851CD23F2445BCD38CE6D0281ABBF9C140B2614526F684254F54E121E3B0291C3926AFDD98DFD10D8959C450F726A8334D3B3C5FF6D5AEE8D27458A4D78040B7F5555AB46E6662EB1D0908805D2B7EAA686FCB7069283CDD505069A7AD1B5BE804548C41A4E273F58EE1E8BA7E951B2F766E1F11C03881B4CDB9A520BC04EDF8E8A9BCE919575914CA22623741D57FF97B036BC9B09C7D5162D983DD5B4D519A869CFFF53F37FD8F550B1F006A3856ECA2DA3804EBC5AB1CD68D64FD4D11747C17C6D3206CCA24C +remain = 65534 +max = 65535 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp new file mode 100644 index 0000000000..b3718c5f09 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp @@ -0,0 +1,14 @@ +# XMSS-SHAKE_16_512 + +pk = 0000000BE63E1958AFF9CEC5CC26706D9B33FE461CF17B8FCF54E1B7394AA3E0B51BDCC89B4D854731B25D63C27019AF9AD43E63969A575E7C181079BC1207320A6658BC4D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9476 +smremain = 65534 +max = 65535 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp new file mode 100644 index 0000000000..a6484c2776 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp @@ -0,0 +1,14 @@ +# XMSS-SHAKE_20_256 + +pk = 000000091EA51EAA13ABDB2B1A37732B47125C74B4F2D624F9145E295C560DF4FFD6AEB404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 2820 +sm = 000000003017CF6CDBA4AF7D6CA495B9872967AFAB62AB87100AA92CFBD66591BEE188E6429AAFF05B285E06B6EDBBA11503F92E15E17C582FDE9CCF8FB0E5BDB90FCABDB107005759C1AD991FBACA5F12BE25CCF5A487CDCB35D2FA0415A48AED18AECFE49E32AF457F664D605D54CF42246B21C1B822727BF0869E79C2479B3CF7EF92B2D92D18C1A9520CC21A0A17908D121E1EA426738CFE364AB99172E83544AD0FEC48EF86066353B471BDF03374C02568B2ACA5D9787A3547B32EAD02723B86085852D62225D7554249CC1FE71B8CA3B01240808B769DC4154DB886DB5C1EF5B5CD1E9A5781AF0B8028EC1D1E1E82D6AD6AA45A6D07B244962F9CC5A5A14674087C37F5C128471A780F7E20C5F04EE713489718EA13D2DD776EC37B91AEC089A1CB652A4CA27DF77D2B59BDD5DB0D4657882E1C3D50D022B673C7E4C1DC6AA9D0961BA4254B0FBC7E8A37B1D610C74A511E52A8A50F4943217493F7EA4C92CF25FC55C8986FBEA375F95A3E2EEA5595322FC1079823D49731A6713DD270B3AD1DFA54D60EC4408C15DA7FC4B5BEC5120F1966279A400F0AF374CF6ACD439AB0307168092C3A8F03F4024169DBE782051501D6CFD53F3344F583668D2F25276D0F93B0896752FCAE3699AF03C2E8C8725BE6073251317D1EEFB497336A32C511CA3D91BA9C3CF4528D139148FFFBE43536D085EF62CA9EDD4A56A4127C96366A690A32F4705C98818ACAC9A62F3421985687FC5107199B035FFCFFF5103D7B169AAFA3F7873198C245BEA6FB442A5EA0710814787B60EF727174C29BA2DE46E283BDECDC6DB095544CECE9268232729556E6339B9B8A2F22FEEA16F32E6FBA5577B4CA665BE58EE459BDEA5C1765D63045C230ACB40DEE76D8FFD25275D33730D608B41AD8FCF6149DC8C5602305056A1E00EFD26E79C204239C69DEC416E8AAA98B43CCAA440867C0C6B6C74E32368C7884B8860E5AD1B518F322EE72CEC31F52CB0B5D16C7813F05F9578CECC287D621864B54E54836F3315642DAF8E0F3A61C68EFB4FCE7D560363BC9F3A5A0086D87169AAB81B9736674E598CB301F84E7F03D94EC6741B481B978440F93D3B0A5426121B516C7A4D5DDF078995BD22D0970A4E6B4D0E8F6B2040D9CCF85DA7C9522BD571EFF09D5B1561225886FFCD6B7884FFEACF7644B9DF10F6FF9F1408EB28E5F212BFB503C2F8FC7981663C50B7739E3F2D9487FC2287870964D9F328563E36677622B3E074A980DAB585FF96FD09B7A843E4B2BA51E42D964AF28BDFA113E2853EE1051EF044C34EE020DBC7172C1A1C5F71AF0F2B8A6A8F9C2E4C8BBEA834A94F34114CEE3ED19E514449946DAEF69516854BC502BB54F46086F5FA4EDAD92893384F67C4D1C11E826B5F1E910DDA7ADFB66C00FA7BEC717F2419E026C3492CE4DE1B568A4DBC25C6C592641852AD2D562A9CEF92CDA1EE295DAD0074EA1C01DC90A6831D3499FA6DC8D6B5D737C95C689192BB35FCFF90B87519113376A44AE4BA207EE9AF82719AA72ABF543ED8EC30C89BEF5ADF1723437F91863B0B6CBD2373F9638D74D6EF309D1B787311CA839339BB9AB60CB5B1F922D6C430FDF84A3A8A81B7FC0282C404FAD61A9AEC0E974476860D49A2BA734DC223B46D2C25797CC55E16A37D56B5021A9413F7F65DE41A840258A1A492267B8EA54C51DCCC1A4572023546321CE81E7F51B4DB3836B1E2CC30E6E7DC45BFDA37C100EB88E44069492CECC82E9E4EC8C7C2C9F85B0BB6B57713F156B0F0B1F2D50589DEF2CDB05E5790D34CECE7C22212AE889BAD4A39F127D0F88709DF1FA2D58AB09D249014EAD040C0934787438A1A5C7C9520F36D18AFC8DAB6866EA201DB358B45AA0CDCA0959B4F0BF7ADDCDB0CF61ECC7FBCEDD43D7F85EB9C9B771CB8EEA797E79F369BCE45087374A20BDC6FEB45871AF744BD1C6D91F72509602FDCA13C0F43D8C9C0EC8141AC267D940537B86335E609D558CB2D1DA9EE891F338DFF31CD3748B61CDE572EC77997A2BCD420E58ECBDAAFD9BDBA4BD815108B240DEA39524C501079A2815C04018C444AAC8AEC51B9207412600285537487F1C65E5E53B472D0836698B80E10F1F06EA466C78F7065088E07801C44DC68A93ECA841BFA02881FA3003878D8EC6E3CA1CC6590607558CE59C93E72BCDE6D87961B3185CA3ECD7D6A913D9F86EDB5017F5A1F28FBFF054D1BECF740CC96822076C1C173E32EB8A2A1D282D8BFEB277B9BAD5906F6C8ECDA3BEEE3253FB58D7B532C7885549593BF2984B3D6FCC2E70105FC34A1CD9A85B9B2A48FA806BB1FE35675ECD1BA10FD998068C0797A6874B02F3759F9DCD3B771041F74F76D99E4FF70A47B904C80118090DA4220AC717C36C588FD89EFC473084AB49FC4849D497AAEC8FA2A8C8DB244001F4348AE47425932E61A64C79846C4214ED25F04D7E07E38C51FF1B1B3BCF0D8D38B31CD3B8A69210C1C3E5A92FB8CD5BB3A57E03D5D9672A86589501558211537988D9B6FD2B248B4C6B39CAD3A41052A74A72C2599419F61A78459B45C7976E43E96BDC2EBA3AE45FFFC8766D70EF340F6C1BE587DFAED8EA010542245C17684A9944E53BB33C776507D940D6990B152898366FC0906F835ED4B9FE9A776EC249F3B7A73C8ADD42D2B17B5893634E68CEE35D6BFFC32B9C588DE07ADEC32475AE5AF1F29EDC5E4EBB848C5DF4EEFB01A405403F4ADDD2097729FDE708EB369DB19FAFC35528A11EFF706445E69FC3F47DDF27092C44B520438B711428B717CF2D19F31D996047E852CC36403C86BD4C2485B886668646E164CD67132C6D187490F3B18BD3A339FD5FB07DFA9F1F74466844FCD43252D480576898E9037633A8424577B3DCFFA3AECFE14317B60F573A7CB1C938876CA58C9DEE64B7EDCB6BACA85C9E20AFAD6B68054B862DDFCEB991456CDDF24C6BFC89FB8A8757F940DF8DE473602610F33F655872E11109EA6E323ED6E8A520C761F371CF760445A3E865E4B2524DEC48F47386A1E6CE55611B40AFF393D6177502756D15DB5232BCD58ABDB633EFEA7390FF8BEA443BFB32F0E70EDE870D540FE22DCF51857EC30BD19ADB90CC68E6E51F3AB68DE8785CF510E7F3A5A039709DF63B801DC3323251351376715F8095ACF170629954B96795175B24E1C258AAB6CC89CED08AD7F756DEEE47A8D0D840E9B431461563DB4EED9560FC38258423E965E31E14D6074C9346404A6ADEF162D1C91432E5F83F97BE838879301613ED7190B2364158338F84A912C522F3D9E643BB90D65727628D26C8694BB2E1F35A45A4C4DC4F6974F9B8371DEDB8D4567370FB91A3AB7744D87321D2A37E808A0AF39B13AEC4593BC12BDB3FFFB32E69644B7CAB6860EA783BCDCFF142775F8C724B9F3E28C6686F9EE8422B03DBE8FE038717EE84BA5A8636DBC22FC29FBF6D07DF598B4641D4EEEE179160AC230A6A201F4127333E15975099212DA36524881CE7A2BFDEB0A69944804A6406D160D57942E851CD23F2445BCD38CE6D0281ABBF9C140B2614526F684254F54E121E3B0291C3926AFDD98DFD10D8959C450F726A8334D3B3C5FF6D5AEE8D27458A4D78040B7F5555AB46E6662EB1D0908805D2B7EAA686FCB7069283CDD505069A7AD1B5BE804548C41A4E273F58EE1E8BA7E951B2F766E1F11C03881B4CDB9A520BC04EDF8E8A9BCE919575914CA22623741D57FF97B036BC9B09C7D5162D983DD5B4D519A869CFFF53F37FD8F550B1F006A3856ECA2DA3804EBC5AB1CD68D64FD4D11747C17C6D3206CCA24C7D176B37A7DC26214FBBF555DDEF8D970B6AA840AFCEE7B674EE05845118A6FB277ABEB1A792B61CA4D24646DBBFD623564F93B74C1277C1AE4CB326411850F0371D6A848ED0BBFB8B0BC3254398F513E630D075CDD277E0AE10D8D13EBDD0CC60AB0FFC61631C5D17989AD9DDF25BADAF0BB87FD0E32975EB673434812D58CC +remain = 1048574 +max = 1048575 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp new file mode 100644 index 0000000000..d573423186 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp @@ -0,0 +1,14 @@ +# XMSS-SHAKE_20_512 + +pk = 0000000C2A857867C4C12EC4296D971A38A242B9DAB9C173678C2BC776A662A1619B1B0149358B252995E4B17AD6593C1ABE2AEFE1D2A0E4FA52E24E73AFB0A4B61A3D544D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9732 +smremain = 1048574 +max = 1048575 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp new file mode 100644 index 0000000000..4a3ba78be4 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHA2_20/2_256 + +pk = 00000001049D5FE86EA348F4C6D28583AA3F9F86C36156FD23AAE68BD09B104163E2E2EB04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 4963 +sm =  +remain = 1048574 +max = 1048575 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp new file mode 100644 index 0000000000..a5a2cd2a31 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHA2_20/4_256 + +pk = 00000002CFA7F813F78C9797C0F6AD44C84059350BE2D1EE249919C6E1F305D3C0E7024404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9251 +sm =  +remain = 1048574 +max = 1048575 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp new file mode 100644 index 0000000000..8fba48c4f8 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHA2_40/2_256 + +pk = 000000030D4B3BE22EE30889C2EA6A12AD6FCC92452E1B92832A599FB4CE52C86E8C429504562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 5605 +smremain = 1099511627774 +max = 1099511627775 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp new file mode 100644 index 0000000000..ced74682a5 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHA2_40/4_256 + +pk = 0000000463FD804E9E56657035D9C1FC5A291B8586E41D1E5E5560AA76B30C26198181A604562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9893 +smremain = 1099511627774 +max = 1099511627775 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp new file mode 100644 index 0000000000..395864aeff --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHA2_40/8_256 + +pk = 00000005AF6E11950B411D09B02C47AA513FC66675E96AA47C3B284279F9543FA23A226804562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 18469 +smremain = 1099511627774 +max = 1099511627775 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp new file mode 100644 index 0000000000..b5b876c43b --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHA2_60/12_256 + +pk = 000000089C3469640CD3578A98E9F9471F596649E45D969754FFE37395B79731156A1E2204562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 27688 +smremain = 1152921504606846974 +max = 1152921504606846975 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp new file mode 100644 index 0000000000..7410c6ae5d --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHA2_60/3_256 + +pk = 000000065FC7351ADB3E5E78B0A1EA06ED988995BFD8960B36F604AC8F03600F0F15E05004562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 8392 +sm =  +remain = 1152921504606846974 +max = 1152921504606846975 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp new file mode 100644 index 0000000000..98d33b6b08 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHA2_60/6_256 + +pk = 000000076948691BBB3D39575B96EB00BBE25665738D3B70378EC25AB76CD8D200F9BFDB04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 14824 +smremain = 1152921504606846974 +max = 1152921504606846975 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp new file mode 100644 index 0000000000..bbf9b3b078 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHAKE_20/2_256 + +pk = 00000011CC3CD3FEFBB5188AE538CEAFC0E64816F394C351FE22AA134A3EC20A6A25FB5004562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 4963 +sm =  +remain = 1048574 +max = 1048575 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp new file mode 100644 index 0000000000..7a37a6015f --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHAKE_20/4_256 + +pk = 0000001253040139BB0C869F0B49F12B2ACB6B6E78731BF48B976D5668CF38EA836868E404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9251 +sm =  +remain = 1048574 +max = 1048575 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp new file mode 100644 index 0000000000..c9042e164a --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHAKE_40/2_256 + +pk = 000000139671F9E99FB4EC6B22DCD31B932FA6A76204CF58477B1B054F10C47913D088D804562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 5605 +sm =  +remain = 1099511627774 +max = 1099511627775 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp new file mode 100644 index 0000000000..7f15d5b83b --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHAKE_40/4_256 + +pk = 00000014A855A0EF256ED6B3F83CB4938E1BCAB172AA13D2FF813E233B4C2E3DB18D27D804562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 9893 +smremain = 1099511627774 +max = 1099511627775 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp new file mode 100644 index 0000000000..791dde71df --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHAKE_40/8_256 + +pk = 000000150C866CCF8B4C8031FC149A5B5C6C504B1DE97B1C9B8F84B9CE8BCF536E3BC15404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 18469 +smremain = 1099511627774 +max = 1099511627775 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp new file mode 100644 index 0000000000..7a3f549c8b --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHAKE_60/12_256 + +pk = 000000187C9DBD8C9B8EA4E9F5B0D99E80ACDC712F597F327BFE800419A478530242532C04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 27688 +smremain = 1152921504606846974 +max = 1152921504606846975 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp new file mode 100644 index 0000000000..ab3935d58d --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHAKE_60/3_256 + +pk = 00000016BBA15DFC230A90773653F36EDD994F661301535E235D0034A34B25B25C58531B04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 8392 +smremain = 1152921504606846974 +max = 1152921504606846975 \ No newline at end of file diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp new file mode 100644 index 0000000000..bf11e7de76 --- /dev/null +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp @@ -0,0 +1,14 @@ +# XMSSMT-SHAKE_60/6_256 + +pk = 000000171657949C495B0A1FD294C1E4123901C1A43FE62FEBC70C30CB6088378ADDBAAA04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 +skcount = 0 +seed = 1840C60AD9F35C900372EF38D08671A74353C965C3C5DE0668C9C3E5CF3926304322530FD9681CF3A9C71FD633D60C66 +mlen = 33 +msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE +smlen = 14824 +smremain = 1152921504606846974 +max = 1152921504606846975 \ No newline at end of file diff --git a/tests/helpers.py b/tests/helpers.py index f050f83366..781df5e45a 100644 --- a/tests/helpers.py +++ b/tests/helpers.py @@ -204,7 +204,9 @@ def get_katfile(t: str, sig_stfl_name: str) -> str: algo_dir = 'xmss' if not algo_dir: return '' - kat_filename = f"{sig_stfl_name}.rsp" + # Replace the "/" to "-" in XMSSMT parameters + clean_sig_stfl_name = sig_stfl_name.replace("/", "-", 1) + kat_filename = f"{clean_sig_stfl_name}.rsp" katfile = os.path.join('tests', 'KATs', t, algo_dir, kat_filename) return katfile diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 9685265902..8e56bac5b8 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -2,7 +2,6 @@ // This KAT test only generates a subset of the NIST KAT files. // To extract the subset from a submission file, use the command: -// cat PQCsignKAT_XMSS-SHA2_10_256.rsp | head -n 16 | tail -n 14 #include #include @@ -19,42 +18,41 @@ #include "system_info.c" -#define MAX_MARKER_LEN 50 +#define MAX_MARKER_LEN 50 // // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // -int -FindMarker(FILE *infile, const char *marker) { - char line[MAX_MARKER_LEN]; - int i, len; +int FindMarker(FILE *infile, const char *marker) { + char line[MAX_MARKER_LEN]; + unsigned long i, len; int curr_line; - len = (int)strlen(marker); - if ( len > MAX_MARKER_LEN - 1 ) { + len = strlen(marker); + if (len > MAX_MARKER_LEN - 1) { len = MAX_MARKER_LEN - 1; } - for ( i = 0; i < len; i++ ) { + for (i = 0; i < len; i++) { curr_line = fgetc(infile); - line[i] = curr_line; - if (curr_line == EOF ) { + line[i] = (char)curr_line; + if (curr_line == EOF) { return 0; } } line[len] = '\0'; - while ( 1 ) { - if ( !strncmp(line, marker, len) ) { + while (1) { + if (!strncmp(line, marker, len)) { return 1; } - for ( i = 0; i < len - 1; i++ ) { + for (i = 0; i < len - 1; i++) { line[i] = line[i + 1]; } curr_line = fgetc(infile); - line[len - 1] = curr_line; - if (curr_line == EOF ) { + line[len - 1] = (char)curr_line; + if (curr_line == EOF) { return 0; } line[len] = '\0'; @@ -67,22 +65,21 @@ FindMarker(FILE *infile, const char *marker) { // // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // -int -ReadHex(FILE *infile, unsigned char *a, int Length, char *str) { - int i, ch, started; - unsigned char ich; +int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { + int i, ch, started; + unsigned char ich; - if ( Length == 0 ) { + if (Length == 0) { a[0] = 0x00; return 1; } memset(a, 0x00, Length); started = 0; - if ( FindMarker(infile, str) ) - while ( (ch = fgetc(infile)) != EOF ) { - if ( !isxdigit(ch) ) { - if ( !started ) { - if ( ch == '\n' ) { + if (FindMarker(infile, str)) + while ((ch = fgetc(infile)) != EOF) { + if (!isxdigit(ch)) { + if (!started) { + if (ch == '\n') { break; } else { continue; @@ -92,20 +89,21 @@ ReadHex(FILE *infile, unsigned char *a, int Length, char *str) { } } started = 1; - if ( (ch >= '0') && (ch <= '9') ) { - ich = ch - '0'; - } else if ( (ch >= 'A') && (ch <= 'F') ) { - ich = ch - 'A' + 10; - } else if ( (ch >= 'a') && (ch <= 'f') ) { - ich = ch - 'a' + 10; - } else { // shouldn't ever get here + if ((ch >= '0') && (ch <= '9')) { + ich = (unsigned char)ch - '0'; + } else if ((ch >= 'A') && (ch <= 'F')) { + ich = (unsigned char)ch - 'A' + 10; + } else if ((ch >= 'a') && (ch <= 'f')) { + ich = (unsigned char)ch - 'a' + 10; + } else { + // shouldn't ever get here ich = 0; } - for ( i = 0; i < Length - 1; i++ ) { - a[i] = (a[i] << 4) | (a[i + 1] >> 4); + for (i = 0; i < Length - 1; i++) { + a[i] = (unsigned char) (a[i] << 4) | (unsigned char) (a[i + 1] >> 4); } - a[Length - 1] = (a[Length - 1] << 4) | ich; + a[Length - 1] = (unsigned char) (a[Length - 1] << 4) | (unsigned char) ich; } else { return 0; } @@ -130,16 +128,16 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { FILE *fh = NULL; FILE *fp_rsp = NULL; OQS_SIG_STFL *sig = NULL; - uint8_t *msg = NULL; + uint8_t *msg = NULL, *msg_rand = NULL; size_t msg_len = 0; uint8_t *public_key = NULL; uint8_t *secret_key = NULL; - uint8_t *signature = NULL; + uint8_t *signature = NULL, *signature_kat = NULL; uint8_t *signed_msg = NULL; size_t signature_len = 0; size_t signed_msg_len = 0; - size_t sigs_remain = 0; - size_t sigs_maximum = 0; + unsigned long long sigs_remain = 0; + unsigned long long sigs_maximum = 0; OQS_STATUS rc, ret = OQS_ERROR; OQS_KAT_PRNG *prng = NULL; @@ -150,19 +148,20 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { sig = OQS_SIG_STFL_new(method_name); if (sig == NULL) { - printf("[sig_stfl_kat] %s was not enabled at compile-time.\n", method_name); + fprintf(stderr, "[sig_stfl_kat] %s was not enabled at compile-time.\n", method_name); goto algo_not_enabled; } - if ( (fp_rsp = fopen(katfile, "r")) == NULL ) { - printf("Couldn't open <%s> for read\n", katfile); + if ((fp_rsp = fopen(katfile, "r")) == NULL) { + fprintf(stderr, "Couldn't open <%s> for read\n", katfile); return OQS_ERROR; } // Grab the pk and sk from KAT file public_key = malloc(sig->length_public_key); secret_key = calloc(sig->length_secret_key, sizeof(uint8_t)); - signature = malloc(sig->length_signature); + signature = calloc(sig->length_signature, sizeof(uint8_t)); + signature_kat = calloc(sig->length_signature, sizeof(uint8_t)); if ((public_key == NULL) || (secret_key == NULL) || (signature == NULL)) { fprintf(stderr, "[kat_stfl_sig] %s ERROR: malloc failed!\n", method_name); @@ -170,12 +169,12 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { } if (!ReadHex(fp_rsp, public_key, sig->length_public_key, "pk = ")) { - printf("ERROR: unable to read 'pk' from <%s>\n", katfile); + fprintf(stderr, "ERROR: unable to read 'pk' from <%s>\n", katfile); goto err; } if (!ReadHex(fp_rsp, secret_key, sig->length_secret_key, "sk = ")) { - printf("ERROR: unable to read 'sk' from <%s>\n", katfile); + fprintf(stderr, "ERROR: unable to read 'sk' from <%s>\n", katfile); goto err; } @@ -187,8 +186,8 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { fprintf(fh, "\n\n"); fprintf(fh, "count = 0\n"); - if ( !ReadHex(fp_rsp, seed, 48, "seed = ") ) { - printf("ERROR: unable to read 'seed' from <%s>\n", katfile); + if (!ReadHex(fp_rsp, seed, 48, "seed = ")) { + fprintf(stderr, "ERROR: unable to read 'seed' from <%s>\n", katfile); goto err; } @@ -197,9 +196,23 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { msg_len = 33 * (0 + 1); fprintf(fh, "mlen = %zu\n", msg_len); - msg = malloc(msg_len); - OQS_randombytes(msg, msg_len); + msg_rand = malloc(msg_len); + + if (!ReadHex(fp_rsp, msg, msg_len, "msg = ")) { + fprintf(stderr, "ERROR: unable to read 'msg' from <%s>\n", katfile); + goto err; + } + + OQS_randombytes(msg_rand, msg_len); + + if (memcmp(msg_rand, msg, msg_len)) { + fprintf(stderr, "randombytes data unaligned\n"); + OQS_fprintBstr(fh, "m = ", msg, msg_len); + OQS_fprintBstr(fh, "m_rand = ", msg_rand, msg_len); + goto err; + } + OQS_fprintBstr(fh, "msg = ", msg, msg_len); rc = OQS_SIG_STFL_sign(sig, signature, &signature_len, msg, msg_len, secret_key); @@ -207,33 +220,44 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sign failed!\n", method_name); goto err; } - fprintf(fh, "smlen = %zu\n", signature_len); OQS_fprintBstr(fh, "sm = ", signature, signature_len); + if (signature_len != sig->length_signature) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sign incorrect length of signature!\n", method_name); + goto err; + } + + if (!ReadHex(fp_rsp, signature_kat, signature_len, "sm = ")) { + fprintf(stderr, "ERROR: unable to read 'msg' from <%s>\n", katfile); + goto err; + } + + if (memcmp(signature, signature_kat, signature_len)) { + OQS_fprintBstr(fh, "sm_kat = ", signature_kat, signature_len); + fprintf(stderr, "Incorrect signature output\n"); + goto err; + } + rc = OQS_SIG_STFL_verify(sig, msg, msg_len, signature, signature_len, public_key); if (rc != OQS_SUCCESS) { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_verify failed!\n", method_name); goto err; } - // print sklen and sk to check the updated secret key - fprintf(fh, "sklen = %zu\n", sig->length_secret_key); - OQS_fprintBstr(fh, "sk = ", secret_key, sig->length_secret_key); - rc = OQS_SIG_STFL_sigs_remaining(sig, &sigs_remain, secret_key); if (rc != OQS_SUCCESS) { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_remaining failed!\n", method_name); goto err; } - fprintf(fh, "remain = %zu\n", sigs_remain); + fprintf(fh, "remain = %llu\n", sigs_remain); rc = OQS_SIG_STFL_sigs_total(sig, &sigs_maximum, secret_key); if (rc != OQS_SUCCESS) { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_total failed!\n", method_name); goto err; } - fprintf(fh, "max = %zu\n", sigs_maximum); + fprintf(fh, "max = %llu", sigs_maximum); ret = OQS_SUCCESS; goto cleanup; @@ -252,9 +276,12 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { } OQS_MEM_insecure_free(public_key); OQS_MEM_insecure_free(signature); + OQS_MEM_insecure_free(signature_kat); OQS_MEM_insecure_free(msg); + OQS_MEM_insecure_free(msg_rand); OQS_SIG_STFL_free(sig); OQS_KAT_PRNG_free(prng); + fclose(fp_rsp); return ret; } diff --git a/tests/test_cmdline.py b/tests/test_cmdline.py index 66962cd98c..ca24bf92f9 100644 --- a/tests/test_cmdline.py +++ b/tests/test_cmdline.py @@ -32,9 +32,17 @@ def test_sig(sig_name): @pytest.mark.parametrize('sig_stfl_name', helpers.available_sig_stfls_by_name()) def test_sig_stfl(sig_stfl_name): if not(helpers.is_sig_stfl_enabled_by_name(sig_stfl_name)): pytest.skip('Not enabled') - helpers.run_subprocess( - [helpers.path_to_executable('test_sig_stfl'), sig_stfl_name], - ) + # Test with KATs apply for XMSS + if sig_stfl_name.startswith("XMSS"): + katfile = helpers.get_katfile("sig_stfl", sig_stfl_name) + if not katfile: pytest.skip("KATs file is missing") + helpers.run_subprocess( + [helpers.path_to_executable('test_sig_stfl'), sig_stfl_name, katfile], + ) + else: + helpers.run_subprocess( + [helpers.path_to_executable('test_sig_stfl'), sig_stfl_name], + ) if __name__ == "__main__": import sys diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 45f700608b..26385ab063 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -4,6 +4,7 @@ #pragma warning(disable : 4244 4293) #endif +#include #include #include #include @@ -25,11 +26,230 @@ #include "system_info.c" +/* + * For stateful signature, we skip key generation because it can takes hours to complete. + * So the ReadHex and and FindMarker serve the purpose of reading pre-generate keypair from KATs. + */ +#define MAX_MARKER_LEN 50 + +// +// ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) +// +int FindMarker(FILE *infile, const char *marker) { + char line[MAX_MARKER_LEN]; + unsigned long i, len; + int curr_line; + + len = strlen(marker); + if (len > MAX_MARKER_LEN - 1) { + len = MAX_MARKER_LEN - 1; + } + + for (i = 0; i < len; i++) { + curr_line = fgetc(infile); + line[i] = (char)curr_line; + if (curr_line == EOF) { + return 0; + } + } + line[len] = '\0'; + + while (1) { + if (!strncmp(line, marker, len)) { + return 1; + } + + for (i = 0; i < len - 1; i++) { + line[i] = line[i + 1]; + } + curr_line = fgetc(infile); + line[len - 1] = (char)curr_line; + if (curr_line == EOF) { + return 0; + } + line[len] = '\0'; + } + + // shouldn't get here + return 0; +} + +// +// ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) +// +int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { + int i, ch, started; + unsigned char ich; + + if (Length == 0) { + a[0] = 0x00; + return 1; + } + memset(a, 0x00, Length); + started = 0; + if (FindMarker(infile, str)) + while ((ch = fgetc(infile)) != EOF) { + if (!isxdigit(ch)) { + if (!started) { + if (ch == '\n') { + break; + } else { + continue; + } + } else { + break; + } + } + started = 1; + if ((ch >= '0') && (ch <= '9')) { + ich = (unsigned char)ch - '0'; + } else if ((ch >= 'A') && (ch <= 'F')) { + ich = (unsigned char)ch - 'A' + 10; + } else if ((ch >= 'a') && (ch <= 'f')) { + ich = (unsigned char)ch - 'a' + 10; + } else { + // shouldn't ever get here + ich = 0; + } + + for (i = 0; i < Length - 1; i++) { + a[i] = (unsigned char) (a[i] << 4) | (unsigned char) (a[i + 1] >> 4); + } + a[Length - 1] = (unsigned char) (a[Length - 1] << 4) | (unsigned char) ich; + } else { + return 0; + } + + return 1; +} + +OQS_STATUS sig_stfl_keypair_from_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, uint8_t *secret_key) { + OQS_STATUS rc; + rc = OQS_SIG_STFL_keypair(sig, public_key, secret_key); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_STATUS sig_stfl_keypair_from_KATs(OQS_SIG_STFL *sig, uint8_t *public_key, uint8_t *secret_key, const char *katfile) { + OQS_STATUS ret = OQS_ERROR; + FILE *fp_rsp = NULL; + + if ((fp_rsp = fopen(katfile, "r")) == NULL) { + fprintf(stderr, "Couldn't open <%s> for read\n", katfile); + goto err; + } + + // Grab the pk and sk from KAT file + if (!ReadHex(fp_rsp, public_key, sig->length_public_key, "pk = ")) { + fprintf(stderr, "ERROR: unable to read 'pk' from <%s>\n", katfile); + goto err; + } + + if (!ReadHex(fp_rsp, secret_key, sig->length_secret_key, "sk = ")) { + fprintf(stderr, "ERROR: unable to read 'sk' from <%s>\n", katfile); + goto err; + } + + // We are done reading, clean up and exit + ret = OQS_SUCCESS; + goto cleanup; + +err: + ret = OQS_ERROR; + +cleanup: + fclose(fp_rsp); + return ret; +} + +/* + * We read from KATs these parameters: + * XMSS-SHA2_16_256 + * XMSS-SHA2_20_256 + * XMSS-SHAKE_16_256 + * XMSS-SHAKE_20_256 + * XMSSMT-SHA2_40/2_256 + * XMSSMT-SHA2_60/3_256 + * XMSSMT-SHAKE_40/2_256 + * XMSSMT-SHAKE_60/3_256 + */ +OQS_STATUS sig_stfl_KATs_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, uint8_t *secret_key, const char *katfile) { + + printf("%s", sig->method_name); + if (0) { + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { + goto from_kats; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { + goto from_kats; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { + goto from_kats; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { + goto from_kats; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { + goto from_kats; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { + goto from_kats; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { + goto from_kats; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { + goto from_kats; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { + goto from_kats; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { + goto from_kats; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { + goto from_kats; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + } else if (0 == strcasecmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { + goto from_kats; +#endif + } else { + goto from_keygen; + } + +from_kats: + return sig_stfl_keypair_from_KATs(sig, public_key, secret_key, katfile); + +from_keygen: + return sig_stfl_keypair_from_keygen(sig, public_key, secret_key); +} + typedef struct magic_s { uint8_t val[31]; } magic_t; -static OQS_STATUS sig_stfl_test_correctness(const char *method_name) { +static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char *katfile) { OQS_SIG_STFL *sig = NULL; uint8_t *public_key = NULL; @@ -85,7 +305,10 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name) { OQS_randombytes(message, message_len); OQS_TEST_CT_DECLASSIFY(message, message_len); - rc = OQS_SIG_STFL_keypair(sig, public_key, secret_key); + /* + * Some keypair generation is fast, so we only read keypair from KATs for slow XMSS parameters + */ + rc = sig_stfl_KATs_keygen(sig, public_key, secret_key, katfile); OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); if (rc != OQS_SUCCESS) { fprintf(stderr, "ERROR: OQS_SIG_STFL_keypair failed\n"); @@ -205,14 +428,15 @@ static void TEST_SIG_STFL_randombytes(uint8_t *random_array, size_t bytes_to_rea #if OQS_USE_PTHREADS_IN_TESTS struct thread_data { - char *alg_name; + const char *alg_name; + const char *katfile; OQS_STATUS rc; OQS_STATUS rc1; }; void *test_wrapper(void *arg) { struct thread_data *td = arg; - td->rc = sig_stfl_test_correctness(td->alg_name); + td->rc = sig_stfl_test_correctness(td->alg_name, td->katfile); td->rc1 = sig_stfl_test_secret_key(td->alg_name); return NULL; } @@ -223,8 +447,8 @@ int main(int argc, char **argv) { printf("Testing stateful signature algorithms using liboqs version %s\n", OQS_version()); - if (argc != 2) { - fprintf(stderr, "Usage: test_sig_stfl algname\n"); + if (argc < 2) { + fprintf(stderr, "Usage: test_sig_stfl algname katfile\n"); fprintf(stderr, " algname: "); for (size_t i = 0; i < OQS_SIG_STFL_algs_length; i++) { if (i > 0) { @@ -239,7 +463,8 @@ int main(int argc, char **argv) { print_system_info(); - char *alg_name = argv[1]; + const char *alg_name = argv[1]; + const char *katfile = argv[2]; if (!OQS_SIG_STFL_alg_is_enabled(alg_name)) { printf("Stateful signature algorithm %s not enabled!\n", alg_name); OQS_destroy(); @@ -258,6 +483,7 @@ int main(int argc, char **argv) { pthread_t thread; struct thread_data td; td.alg_name = alg_name; + td.katfile = katfile; int trc = pthread_create(&thread, NULL, test_wrapper, &td); if (trc) { fprintf(stderr, "ERROR: Creating pthread\n"); @@ -268,7 +494,7 @@ int main(int argc, char **argv) { rc = td.rc; rc1 = td.rc1; #else - rc = sig_stfl_test_correctness(alg_name); + rc = sig_stfl_test_correctness(alg_name, katfile); rc1 = sig_stfl_test_secret_key(alg_name); #endif if ((rc != OQS_SUCCESS) || (rc1 != OQS_SUCCESS)) { From 55094c37f167ec4323411853ffc63da923741662 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Mon, 31 Jul 2023 12:53:22 -0400 Subject: [PATCH 09/68] LMS H5_W1 (#1513) * Support LMS H5_W1 * Fix style check * Rename CmakeLists.txt CMakeLists.txt * Add namespace * Address issues from scan results * Address SA issue * Fix formatting * Fix formatting * Commit Duc's SA fixes * Fix mem leak, and compiler warning. --- .CMake/alg_support.cmake | 2 + CMakeLists.txt | 3 + src/CMakeLists.txt | 5 + src/oqsconfig.h.cmake | 4 +- src/sig_stfl/lms/CMakeLists.txt | 45 +++ src/sig_stfl/lms/external/endian.h | 1 + src/sig_stfl/lms/external/hash.h | 1 + src/sig_stfl/lms/external/hss.h | 1 + src/sig_stfl/lms/external/hss_aux.h | 1 + src/sig_stfl/lms/external/hss_common.h | 1 + src/sig_stfl/lms/external/hss_derive.h | 1 + src/sig_stfl/lms/external/hss_internal.h | 1 + src/sig_stfl/lms/external/hss_keygen.c | 3 + src/sig_stfl/lms/external/hss_reserve.h | 1 + src/sig_stfl/lms/external/hss_sign_inc.h | 1 + src/sig_stfl/lms/external/hss_thread.h | 1 + src/sig_stfl/lms/external/hss_verify.h | 1 + src/sig_stfl/lms/external/hss_verify_inc.h | 1 + src/sig_stfl/lms/external/hss_zeroize.h | 1 + src/sig_stfl/lms/external/lm_common.h | 1 + src/sig_stfl/lms/external/lm_ots.h | 1 + src/sig_stfl/lms/external/lm_ots_common.h | 1 + src/sig_stfl/lms/external/lm_ots_verify.h | 1 + src/sig_stfl/lms/external/lm_verify.h | 1 + src/sig_stfl/lms/external/lms_namespace.h | 96 +++++++ src/sig_stfl/lms/external/sha256.h | 1 + src/sig_stfl/lms/sig_stfl_lms.c | 93 ++++++ src/sig_stfl/lms/sig_stfl_lms.h | 41 +++ src/sig_stfl/lms/sig_stfl_lms_functions.c | 266 ++++++++++++++++++ src/sig_stfl/lms/sig_stfl_lms_wrap.h | 62 ++++ src/sig_stfl/sig_stfl.c | 23 +- src/sig_stfl/sig_stfl.h | 21 +- src/sig_stfl/xmss/sig_stfl_xmss.h | 112 ++++---- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 17 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 12 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 12 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 12 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 12 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 12 +- .../xmss/sig_stfl_xmss_shake128_h10.c | 12 +- .../xmss/sig_stfl_xmss_shake128_h16.c | 12 +- .../xmss/sig_stfl_xmss_shake128_h20.c | 12 +- .../xmss/sig_stfl_xmss_shake256_h10.c | 12 +- .../xmss/sig_stfl_xmss_shake256_h16.c | 12 +- .../xmss/sig_stfl_xmss_shake256_h20.c | 12 +- .../xmss/sig_stfl_xmssmt_sha256_h20_2.c | 12 +- .../xmss/sig_stfl_xmssmt_sha256_h20_4.c | 12 +- .../xmss/sig_stfl_xmssmt_sha256_h40_2.c | 12 +- .../xmss/sig_stfl_xmssmt_sha256_h40_4.c | 12 +- .../xmss/sig_stfl_xmssmt_sha256_h40_8.c | 12 +- .../xmss/sig_stfl_xmssmt_sha256_h60_12.c | 12 +- .../xmss/sig_stfl_xmssmt_sha256_h60_3.c | 12 +- .../xmss/sig_stfl_xmssmt_sha256_h60_6.c | 12 +- .../xmss/sig_stfl_xmssmt_shake128_h20_2.c | 12 +- .../xmss/sig_stfl_xmssmt_shake128_h20_4.c | 12 +- .../xmss/sig_stfl_xmssmt_shake128_h40_2.c | 12 +- .../xmss/sig_stfl_xmssmt_shake128_h40_4.c | 12 +- .../xmss/sig_stfl_xmssmt_shake128_h40_8.c | 12 +- .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 12 +- .../xmss/sig_stfl_xmssmt_shake128_h60_3.c | 12 +- .../xmss/sig_stfl_xmssmt_shake128_h60_6.c | 12 +- tests/test_sig_stfl.c | 2 +- 62 files changed, 846 insertions(+), 292 deletions(-) create mode 100644 src/sig_stfl/lms/CMakeLists.txt create mode 100644 src/sig_stfl/lms/external/lms_namespace.h create mode 100644 src/sig_stfl/lms/sig_stfl_lms.c create mode 100644 src/sig_stfl/lms/sig_stfl_lms.h create mode 100644 src/sig_stfl/lms/sig_stfl_lms_functions.c create mode 100644 src/sig_stfl/lms/sig_stfl_lms_wrap.h diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index aaf8ea6fef..da79308dfd 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -528,6 +528,8 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 "" ON "OQS_ENAB cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) +option(OQS_ENABLE_SIG_STFL_LMS "Enable LMS algorithm family" ON) + if((OQS_MINIMAL_BUILD STREQUAL "ON")) message(FATAL_ERROR "OQS_MINIMAL_BUILD option ${OQS_MINIMAL_BUILD} no longer supported") endif() diff --git a/CMakeLists.txt b/CMakeLists.txt index f95809e9df..16b09a6400 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -199,6 +199,9 @@ endif() if(OQS_ENABLE_SIG_STFL_XMSS) set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig_stfl/xmss/sig_stfl_xmss.h) endif() +if(OQS_ENABLE_SIG_STFL_LMS) + set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig_stfl/lms/sig_stfl_lms.h) +endif() ##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_INCLUDE_HEADERS_END execute_process(COMMAND ${CMAKE_COMMAND} -E make_directory ${PROJECT_BINARY_DIR}/include/oqs) execute_process(COMMAND ${CMAKE_COMMAND} -E copy ${PUBLIC_HEADERS} ${PROJECT_BINARY_DIR}/include/oqs) diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt index e6e6ce6f07..a5b64fd294 100644 --- a/src/CMakeLists.txt +++ b/src/CMakeLists.txt @@ -62,6 +62,11 @@ if(OQS_ENABLE_SIG_STFL_XMSS) set(SIG_STFL_OBJS ${SIG_STFL_OBJS} ${XMSS_OBJS}) endif() +if(OQS_ENABLE_SIG_STFL_LMS) + add_subdirectory(sig_stfl/lms) + set(SIG_STFL_OBJS ${SIG_STFL_OBJS} ${LMS_OBJS}) +endif() + add_library(oqs kem/kem.c ${KEM_OBJS} sig/sig.c diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index aef6c427aa..9626119e71 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -219,4 +219,6 @@ #cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8 1 #cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 1 #cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 1 -#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 1 \ No newline at end of file +#cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 1 + +#cmakedefine OQS_ENABLE_SIG_STFL_LMS 1 diff --git a/src/sig_stfl/lms/CMakeLists.txt b/src/sig_stfl/lms/CMakeLists.txt new file mode 100644 index 0000000000..93fa290084 --- /dev/null +++ b/src/sig_stfl/lms/CMakeLists.txt @@ -0,0 +1,45 @@ +# SPDX-License-Identifier: MIT + +set(_LMS_OBJS "") + +set(SRCS + external/endian.c + external/hash.c + external/hss.c + external/hss_alloc.c + external/hss_aux.c + external/hss_common.c + external/hss_compute.c + external/hss_derive.c + external/hss_generate.c + external/hss_keygen.c + external/hss_param.c + external/hss_reserve.c + external/hss_sign.c + external/hss_sign_inc.c + external/hss_thread_single.c + external/hss_verify.c + external/hss_verify_inc.c + external/hss_zeroize.c + external/lm_common.c + external/lm_ots_common.c + external/lm_ots_sign.c + external/lm_ots_verify.c + external/lm_verify.c + external/sha256.c + sig_stfl_lms.c + sig_stfl_lms_functions.c + ) + +#if (OQS_ENABLE_SIG_STFL_lms) +# add_compile_definitions(OQS_ENABLE_SIG_STFL_lms) +# set (SRCS ${SRCS} sig_stfl_lms.c sig_stfl_lms_functions.c) +#endif() + + +add_library(lms OBJECT ${SRCS}) +set(_LMS_OBJS ${_LMS_OBJS} $) +set(LMS_OBJS ${_LMS_OBJS} PARENT_SCOPE) + + + diff --git a/src/sig_stfl/lms/external/endian.h b/src/sig_stfl/lms/external/endian.h index 9f8099d808..a94177ddeb 100644 --- a/src/sig_stfl/lms/external/endian.h +++ b/src/sig_stfl/lms/external/endian.h @@ -2,6 +2,7 @@ #define ENDIAN_H_ #include +#include "lms_namespace.h" void put_bigendian( void *target, unsigned long long value, size_t bytes ); unsigned long long get_bigendian( const void *target, size_t bytes ); diff --git a/src/sig_stfl/lms/external/hash.h b/src/sig_stfl/lms/external/hash.h index a61f9f5039..5e8fb3134d 100644 --- a/src/sig_stfl/lms/external/hash.h +++ b/src/sig_stfl/lms/external/hash.h @@ -3,6 +3,7 @@ #include "sha256.h" #include #include +#include "lms_namespace.h" /* * This defines the hash interface used within HSS. diff --git a/src/sig_stfl/lms/external/hss.h b/src/sig_stfl/lms/external/hss.h index b4e5e1698d..5ff8fc5c52 100644 --- a/src/sig_stfl/lms/external/hss.h +++ b/src/sig_stfl/lms/external/hss.h @@ -4,6 +4,7 @@ #include #include #include "common_defs.h" +#include "lms_namespace.h" /* * This is intended to be a usable (nontoy) implementation of the LMS diff --git a/src/sig_stfl/lms/external/hss_aux.h b/src/sig_stfl/lms/external/hss_aux.h index 634df88684..02e6677a38 100644 --- a/src/sig_stfl/lms/external/hss_aux.h +++ b/src/sig_stfl/lms/external/hss_aux.h @@ -9,6 +9,7 @@ #include "common_defs.h" #include #include +#include "lms_namespace.h" struct hss_working_key; diff --git a/src/sig_stfl/lms/external/hss_common.h b/src/sig_stfl/lms/external/hss_common.h index c455b9af5e..a5640d669e 100644 --- a/src/sig_stfl/lms/external/hss_common.h +++ b/src/sig_stfl/lms/external/hss_common.h @@ -3,6 +3,7 @@ #include #include "common_defs.h" +#include "lms_namespace.h" /* * This returns the length of the public key for the given parameter set diff --git a/src/sig_stfl/lms/external/hss_derive.h b/src/sig_stfl/lms/external/hss_derive.h index ee47eb6cfc..57ba4a1bc8 100644 --- a/src/sig_stfl/lms/external/hss_derive.h +++ b/src/sig_stfl/lms/external/hss_derive.h @@ -4,6 +4,7 @@ #include "common_defs.h" #include "config.h" +#include "lms_namespace.h" #if SECRET_MAX > 31 #error The code is not designed for a SECRET_MAX that high diff --git a/src/sig_stfl/lms/external/hss_internal.h b/src/sig_stfl/lms/external/hss_internal.h index c1541375fe..4e7c53675d 100644 --- a/src/sig_stfl/lms/external/hss_internal.h +++ b/src/sig_stfl/lms/external/hss_internal.h @@ -5,6 +5,7 @@ #include "common_defs.h" #include "hss.h" #include "config.h" +#include "lms_namespace.h" /* * This is the central internal include file for the functions that make up diff --git a/src/sig_stfl/lms/external/hss_keygen.c b/src/sig_stfl/lms/external/hss_keygen.c index ac471a952a..743604f170 100644 --- a/src/sig_stfl/lms/external/hss_keygen.c +++ b/src/sig_stfl/lms/external/hss_keygen.c @@ -345,6 +345,9 @@ bool hss_generate_private_key( public_key += I_LEN; len_public_key -= I_LEN; memcpy( public_key, root_hash, size_hash ); public_key += size_hash; len_public_key -= size_hash; + /* Address static analysis issue*/ + LMS_UNUSED(public_key); + LMS_UNUSED(len_public_key); /* Hey, what do you know -- it all worked! */ hss_zeroize( private_key, sizeof private_key ); /* Zeroize local copy of */ diff --git a/src/sig_stfl/lms/external/hss_reserve.h b/src/sig_stfl/lms/external/hss_reserve.h index 3b101c1130..14f4da3096 100644 --- a/src/sig_stfl/lms/external/hss_reserve.h +++ b/src/sig_stfl/lms/external/hss_reserve.h @@ -7,6 +7,7 @@ */ #include "common_defs.h" +#include "lms_namespace.h" struct hss_working_key; diff --git a/src/sig_stfl/lms/external/hss_sign_inc.h b/src/sig_stfl/lms/external/hss_sign_inc.h index 426d271abd..cf4f25aec6 100644 --- a/src/sig_stfl/lms/external/hss_sign_inc.h +++ b/src/sig_stfl/lms/external/hss_sign_inc.h @@ -4,6 +4,7 @@ #include #include "hash.h" #include "common_defs.h" +#include "lms_namespace.h" /* * These are the functions to sign a message incrementally. diff --git a/src/sig_stfl/lms/external/hss_thread.h b/src/sig_stfl/lms/external/hss_thread.h index fbf572ad4b..0fa48e958c 100644 --- a/src/sig_stfl/lms/external/hss_thread.h +++ b/src/sig_stfl/lms/external/hss_thread.h @@ -29,6 +29,7 @@ * by the time hss_thread_done returns */ #include +#include "lms_namespace.h" /* This is our abstract object that stands for a set of threads */ struct thread_collection; diff --git a/src/sig_stfl/lms/external/hss_verify.h b/src/sig_stfl/lms/external/hss_verify.h index 7a29deb275..6561ee2a3c 100644 --- a/src/sig_stfl/lms/external/hss_verify.h +++ b/src/sig_stfl/lms/external/hss_verify.h @@ -2,6 +2,7 @@ #define HSS_VERIFY_H_ #include +#include "lms_namespace.h" struct hss_extra_info; /* diff --git a/src/sig_stfl/lms/external/hss_verify_inc.h b/src/sig_stfl/lms/external/hss_verify_inc.h index 147308b23c..6c3ec74da1 100644 --- a/src/sig_stfl/lms/external/hss_verify_inc.h +++ b/src/sig_stfl/lms/external/hss_verify_inc.h @@ -5,6 +5,7 @@ #include "hash.h" #include "common_defs.h" #include "hss.h" +#include "lms_namespace.h" /* * These are the functions to validate a signature incrementally. diff --git a/src/sig_stfl/lms/external/hss_zeroize.h b/src/sig_stfl/lms/external/hss_zeroize.h index 702d91137b..bfe84db155 100644 --- a/src/sig_stfl/lms/external/hss_zeroize.h +++ b/src/sig_stfl/lms/external/hss_zeroize.h @@ -2,6 +2,7 @@ #define HSS_ZEROIZE_H_ #include +#include "lms_namespace.h" /* Zeroize an area, that is, scrub it from holding any potentially secret */ /* information */ diff --git a/src/sig_stfl/lms/external/lm_common.h b/src/sig_stfl/lms/external/lm_common.h index 027eda2214..b577c22462 100644 --- a/src/sig_stfl/lms/external/lm_common.h +++ b/src/sig_stfl/lms/external/lm_common.h @@ -3,6 +3,7 @@ #include #include "common_defs.h" +#include "lms_namespace.h" size_t lm_get_public_key_len(param_set_t lm_type); size_t lm_get_signature_len(param_set_t lm_type, diff --git a/src/sig_stfl/lms/external/lm_ots.h b/src/sig_stfl/lms/external/lm_ots.h index 4fcf690342..4e33d9e9fd 100644 --- a/src/sig_stfl/lms/external/lm_ots.h +++ b/src/sig_stfl/lms/external/lm_ots.h @@ -3,6 +3,7 @@ #include "common_defs.h" #include +#include "lms_namespace.h" /* * These are routines that implement the OTS signature scheme. These routines diff --git a/src/sig_stfl/lms/external/lm_ots_common.h b/src/sig_stfl/lms/external/lm_ots_common.h index 12530dd6dd..fe6faebe98 100644 --- a/src/sig_stfl/lms/external/lm_ots_common.h +++ b/src/sig_stfl/lms/external/lm_ots_common.h @@ -3,6 +3,7 @@ #include #include "common_defs.h" +#include "lms_namespace.h" bool lm_ots_look_up_parameter_set(param_set_t parameter_set, unsigned *h, unsigned *n, unsigned *w, unsigned *p, unsigned *ls); diff --git a/src/sig_stfl/lms/external/lm_ots_verify.h b/src/sig_stfl/lms/external/lm_ots_verify.h index 439f0f94a6..dcf6551b0f 100644 --- a/src/sig_stfl/lms/external/lm_ots_verify.h +++ b/src/sig_stfl/lms/external/lm_ots_verify.h @@ -3,6 +3,7 @@ #include #include "common_defs.h" +#include "lms_namespace.h" /* * This validates an OTS signature, but instead of producing a SUCCESS/FAILURE diff --git a/src/sig_stfl/lms/external/lm_verify.h b/src/sig_stfl/lms/external/lm_verify.h index 7f48767fcb..b7b6b0736d 100644 --- a/src/sig_stfl/lms/external/lm_verify.h +++ b/src/sig_stfl/lms/external/lm_verify.h @@ -3,6 +3,7 @@ #include #include +#include "lms_namespace.h" bool lm_validate_signature( const unsigned char *public_key, diff --git a/src/sig_stfl/lms/external/lms_namespace.h b/src/sig_stfl/lms/external/lms_namespace.h new file mode 100644 index 0000000000..56898589ee --- /dev/null +++ b/src/sig_stfl/lms/external/lms_namespace.h @@ -0,0 +1,96 @@ +#ifndef _LMS_NAMESPACE_H +#define _LMS_NAMESPACE_H + +#define LMS_NAMESPACE(s) OQS_LMS_NAMESPACE_##s + +#define get_bigendian LMS_NAMESPACE(get_bigendian) +#define put_bigendian LMS_NAMESPACE(put_bigendian) +#define hss_finalize_hash_context LMS_NAMESPACE(hss_finalize_hash_context) +#define hss_hash LMS_NAMESPACE(hss_hash) +#define hss_hash_blocksize LMS_NAMESPACE(hss_hash_blocksize) +#define hss_hash_ctx LMS_NAMESPACE(hss_hash_ctx) +#define hss_hash_length LMS_NAMESPACE(hss_hash_length) +#define hss_init_hash_context LMS_NAMESPACE(hss_init_hash_context) +#define hss_update_hash_context LMS_NAMESPACE(hss_update_hash_context) +#define hss_extra_info_set_threads LMS_NAMESPACE(hss_extra_info_set_threads) +#define hss_extra_info_test_error_code LMS_NAMESPACE(hss_extra_info_test_error_code) +#define hss_extra_info_test_last_signature LMS_NAMESPACE(hss_extra_info_test_last_signature) +#define hss_generate_child_seed_I_value LMS_NAMESPACE(hss_generate_child_seed_I_value) +#define hss_generate_root_seed_I_value LMS_NAMESPACE(hss_generate_root_seed_I_value) +#define hss_init_extra_info LMS_NAMESPACE(hss_init_extra_info) +#define hss_load_private_key LMS_NAMESPACE(hss_load_private_key) + +#define allocate_working_key LMS_NAMESPACE(allocate_working_key) + +#define hss_free_working_key LMS_NAMESPACE(hss_free_working_key) +#define hss_smallest_subtree_size LMS_NAMESPACE(hss_smallest_subtree_size) +#define hss_expand_aux_data LMS_NAMESPACE(hss_expand_aux_data) +#define hss_extract_aux_data LMS_NAMESPACE(hss_extract_aux_data) +#define hss_finalize_aux_data LMS_NAMESPACE(hss_finalize_aux_data) +#define hss_get_aux_data_len LMS_NAMESPACE(hss_get_aux_data_len) +#define hss_optimal_aux_level LMS_NAMESPACE(hss_optimal_aux_level) +#define hss_save_aux_data LMS_NAMESPACE(hss_save_aux_data) +#define hss_store_aux_marker LMS_NAMESPACE(hss_store_aux_marker) + +#define hss_get_public_key_len LMS_NAMESPACE(hss_get_public_key_len) +#define hss_get_signature_len LMS_NAMESPACE(hss_get_signature_len) +#define hss_combine_internal_nodes LMS_NAMESPACE(hss_combine_internal_nodes) +#define hss_gen_intermediate_tree LMS_NAMESPACE(hss_gen_intermediate_tree) +#define hss_seed_derive LMS_NAMESPACE(hss_seed_derive) +#define hss_seed_derive_done LMS_NAMESPACE(hss_seed_derive_done) +#define hss_seed_derive_init LMS_NAMESPACE(hss_seed_derive_init) +#define hss_seed_derive_set_j LMS_NAMESPACE(hss_seed_derive_set_j) +#define hss_seed_derive_set_q LMS_NAMESPACE(hss_seed_derive_set_q) +#define hss_generate_working_key LMS_NAMESPACE(hss_generate_working_key) + +#define hss_generate_private_key LMS_NAMESPACE(hss_generate_private_key) +#define hss_get_private_key_len LMS_NAMESPACE(hss_get_private_key_len) +#define hss_compress_param_set LMS_NAMESPACE(hss_compress_param_set) +#define hss_get_parameter_set LMS_NAMESPACE(hss_get_parameter_set) +#define hss_advance_count LMS_NAMESPACE(hss_advance_count) +#define hss_reserve_signature LMS_NAMESPACE(hss_reserve_signature) +#define hss_set_autoreserve LMS_NAMESPACE(hss_set_autoreserve) +#define hss_set_reserve_count LMS_NAMESPACE(hss_set_reserve_count) +#define hss_create_signed_public_key LMS_NAMESPACE(hss_create_signed_public_key) +#define hss_generate_signature LMS_NAMESPACE(hss_generate_signature) +#define hss_get_signature_len_from_working_key LMS_NAMESPACE(hss_get_signature_len_from_working_key) +#define hss_sign_finalize LMS_NAMESPACE(hss_sign_finalize) +#define hss_sign_init LMS_NAMESPACE(hss_sign_init) +#define hss_sign_update LMS_NAMESPACE(hss_sign_update) +#define hss_thread_after_write LMS_NAMESPACE(hss_thread_after_write) +#define hss_thread_before_write LMS_NAMESPACE(hss_thread_before_write) +#define hss_thread_done LMS_NAMESPACE(hss_thread_done) +#define hss_thread_init LMS_NAMESPACE(hss_thread_init) +#define hss_thread_issue_work LMS_NAMESPACE(hss_thread_issue_work) +#define hss_thread_num_tracks LMS_NAMESPACE(hss_thread_num_tracks) +#define hss_validate_signature LMS_NAMESPACE(hss_validate_signature) + +#define validate_internal_sig LMS_NAMESPACE(validate_internal_sig) + +#define hss_validate_signature_finalize LMS_NAMESPACE(hss_validate_signature_finalize) +#define hss_validate_signature_init LMS_NAMESPACE(hss_validate_signature_init) +#define hss_validate_signature_update LMS_NAMESPACE(hss_validate_signature_update) +#define hss_zeroize LMS_NAMESPACE(hss_zeroize) + +#define lm_get_public_key_len LMS_NAMESPACE(lm_get_public_key_len) +#define lm_get_signature_len LMS_NAMESPACE(lm_get_signature_len) +#define lm_look_up_parameter_set LMS_NAMESPACE(lm_look_up_parameter_set) + +#define lm_ots_coef LMS_NAMESPACE(lm_ots_coef) +#define lm_ots_compute_checksum LMS_NAMESPACE(lm_ots_compute_checksum) +#define lm_ots_get_public_key_len LMS_NAMESPACE(lm_ots_get_public_key_len) +#define lm_ots_get_signature_len LMS_NAMESPACE(lm_ots_get_signature_len) +#define lm_ots_hashes_per_public_key LMS_NAMESPACE(lm_ots_hashes_per_public_key) +#define lm_ots_look_up_parameter_set LMS_NAMESPACE(lm_ots_look_up_parameter_set) +#define lm_ots_generate_public_key LMS_NAMESPACE(lm_ots_generate_public_key) +#define lm_ots_generate_randomizer LMS_NAMESPACE(lm_ots_generate_randomizer) +#define lm_ots_generate_signature LMS_NAMESPACE(lm_ots_generate_signature) +#define lm_ots_validate_signature_compute LMS_NAMESPACE(lm_ots_validate_signature_compute) +#define lm_validate_signature LMS_NAMESPACE(lm_validate_signature) + +#define SHA256_Final LMS_NAMESPACE(SHA256_Final) +#define SHA256_Init LMS_NAMESPACE(SHA256_Init) +#define SHA256_Update LMS_NAMESPACE(SHA256_Update) +#define LMS_randombytes LMS_NAMESPACE(LMS_randombytes) + +#endif //_LMS_NAMESPACE_H diff --git a/src/sig_stfl/lms/external/sha256.h b/src/sig_stfl/lms/external/sha256.h index a5de21c014..f7f78ad18c 100644 --- a/src/sig_stfl/lms/external/sha256.h +++ b/src/sig_stfl/lms/external/sha256.h @@ -14,6 +14,7 @@ #include #else +#include "lms_namespace.h" /* SHA256 context. */ typedef struct { diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c new file mode 100644 index 0000000000..dde8dc586f --- /dev/null +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -0,0 +1,93 @@ +// SPDX-License-Identifier: MIT + +#include +#include +#include +#include "./external/config.h" +#include "sig_stfl_lms_wrap.h" +#include "sig_stfl_lms.h" + + +// ======================== LMS-SHA256 H5/W1 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, uint8_t *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)0x00000001) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = 0x00000001; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk; + + if (sk->length_secret_key) { + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + if (sk->secret_key_data) { + memset(sk->secret_key_data, 0, sk->length_secret_key); + } else { + OQS_SECRET_KEY_LMS_free(sk); + OQS_MEM_insecure_free(sk); + sk = NULL; + return NULL; + } + } + + sk->free_key = OQS_SECRET_KEY_LMS_free; + + return sk; +} + +void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return; + } + + //TODO: cleanup lock_key + + if (sk->sig) { + OQS_MEM_insecure_free(sk->sig); + sk->sig = NULL; + } + OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); + sk->secret_key_data = NULL; +} diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h new file mode 100644 index 0000000000..97104b47f8 --- /dev/null +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -0,0 +1,41 @@ +// SPDX-License-Identifier: MIT + +#ifndef OQS_SIG_STFL_LMS_H +#define OQS_SIG_STFL_LMS_H + +#include + +//H5 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_signature 8688 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk 64 + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, uint8_t *secret_key); + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(uint64_t *totaln, const uint8_t *secret_key); + +void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); + +// ----------------------------------- WRAPPER FUNCTIONS ------------------------------------------------ +int oqs_sig_stfl_lms_keypair(uint8_t *pk, uint8_t *sk, const uint32_t oid); + +int oqs_sig_stfl_lms_sign(uint8_t *sk, uint8_t *sm, size_t *smlen, + const uint8_t *m, size_t mlen); + +int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, const uint8_t *sm, size_t smlen, + const uint8_t *pk); + +// ---------------------------- FUNCTIONS INDEPENDENT OF VARIANT ----------------------------------------- + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signature_length, const uint8_t *message, size_t message_len, uint8_t *secret_key); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); + + +// -------------------------------------------------------------------------------------------------------- + +#endif /* OQS_SIG_STFL_LMS_H */ diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c new file mode 100644 index 0000000000..8c17ddddd0 --- /dev/null +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -0,0 +1,266 @@ +// SPDX-License-Identifier: MIT + +#include +#include "sig_stfl_lms.h" +#include "external/config.h" +#include "external/hss_verify_inc.h" +#include "external/hss_sign_inc.h" +#include "external/hss.h" +#include "sig_stfl_lms_wrap.h" +#include + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signature_length, const uint8_t *message, + size_t message_len, uint8_t *secret_key) { + + if (secret_key == NULL || message == NULL || signature == NULL) { + return OQS_ERROR; + } + + /* TODO: Make sure we have a way to update the private key */ + + if (oqs_sig_stfl_lms_sign(secret_key, signature, + signature_length, + message, message_len) != 0) { + return OQS_ERROR; + } + + /* TODO: Update private key */ + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t message_len, + const uint8_t *signature, size_t signature_len, + const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_verify(message, message_len, + signature, signature_len, + public_key) != 0 ) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const uint8_t *secret_key) { + + if (remain == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + remain = 0; + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(uint64_t *total, const uint8_t *secret_key) { + + if (total == NULL || secret_key == NULL) { + return OQS_ERROR; + } + + total = 0; + return OQS_SUCCESS; +} + +/* LMS wrapper functions use internal OIDs to + * identify the parameter set to be used + */ + +bool LMS_randombytes(void *buffer, size_t length) { + + OQS_randombytes((uint8_t *)buffer, length); + return true; +} + +int oqs_sig_stfl_lms_keypair(uint8_t *pk, uint8_t *sk, const uint32_t oid) { + + int ret = -1; + bool b_ret; + int parse_err = 0; + unsigned levels = 1; + + unsigned char public_key[60]; + size_t len_public_key = 60; + unsigned char *aux_data = NULL; + size_t max_aux_data = 10916; + int aux_len = 0; + oqs_lms_key_data *oqs_data = NULL; + + param_set_t lm_type[1]; + param_set_t lm_ots_type[1]; + + if (!pk || !sk || !oid) { + return -1; + } + + /* Set lms param set */ + switch (oid) { + case 0x1: + lm_type[0] = LMS_SHA256_N32_H5; + lm_ots_type[0] = LMOTS_SHA256_N32_W1; + break; + default: + lm_type[0] = 0; + lm_ots_type[0] = 0; + parse_err = 1; + break; + } + + if (parse_err) { + return -1; + } + + /* + * This creates a private key (and the correspond public key, and optionally + * the aux data for that key) + * Parameters: + * generate_random - the function to be called to generate randomness. This + * is assumed to be a pointer to a cryptographically secure rng, + * otherwise all security is lost. This function is expected to fill + * output with 'length' uniformly distributed bits, and return 1 on + * success, 0 if something went wrong + * levels - the number of levels for the key pair (2-8) + * lm_type - an array of the LM registry entries for the various levels; + * entry 0 is the topmost + * lm_ots_type - an array of the LM-OTS registry entries for the various + * levels; again, entry 0 is the topmost + * update_private_key, context - the function that is called when the + * private key is generated; it is expected to store it to secure NVRAM + * If this is NULL, then the context pointer is reinterpretted to mean + * where in RAM the private key is expected to be placed + * public_key - where to store the public key + * len_public_key - length of the above buffer; see hss_get_public_key_len + * if you need a hint. + * aux_data - where to store the optional aux data. This is not required, but + * if provided, can be used to speed up the hss_generate_working_key + * process; + * len_aux_data - the length of the above buffer. This is not fixed length; + * the function will run different time/memory trade-offs based on the + * length provided + * + * This returns true on success, false on failure + */ + b_ret = hss_generate_private_key( + LMS_randombytes, + levels, + lm_type, + lm_ots_type, + NULL, //File handler function? + (void *)sk, + public_key, len_public_key, + aux_data, aux_len, + NULL); + if (b_ret) { + memcpy(pk, public_key, len_public_key); + } + + /* TODO: store key pair, file handler */ + + ret = 0; + return ret; +} + +int oqs_sig_stfl_lms_sign(uint8_t *sk, + uint8_t *sm, size_t *smlen, + const uint8_t *m, size_t mlen) { + + size_t sig_len; + bool status; + unsigned char *sig = NULL; + struct hss_working_key *w = NULL; + struct hss_sign_inc ctx; + w = hss_load_private_key(NULL, sk, + 0, + NULL, + 0, + 0); + if (!w) { + printf( "Error loading private key\n" ); + hss_free_working_key(w); + return 0; + } + + /* Now, go through the file list, and generate the signatures for each */ + + /* Look up the signature length */ + + sig_len = hss_get_signature_len_from_working_key(w); + if (sig_len == 0) { + printf( "Error getting signature len\n" ); + hss_free_working_key(w); + return 0; + } + + sig = malloc(sig_len); + if (!sig) { + printf( "Error during malloc\n" ); + hss_free_working_key(w); + return -1; + } + + (void)hss_sign_init( + &ctx, /* Incremental signing context */ + w, /* Working key */ + NULL, /* Routine to update the */ + sk, /* private key */ + sig, sig_len, /* Where to place the signature */ + 0); + + (void)hss_sign_update( + &ctx, /* Incremental signing context */ + m, /* Next piece of the message */ + mlen); /* Length of this piece */ + + status = hss_sign_finalize( + &ctx, /* Incremental signing context */ + w, /* Working key */ + sig, /* Signature */ + 0); + + if (!status) { + hss_free_working_key(w); + OQS_MEM_insecure_free(sig); + return -1; + } + + *smlen = sig_len; + memcpy(sm, sig, sig_len); + OQS_MEM_insecure_free(sig); + + return 0; +} + +int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, + const uint8_t *sm, size_t smlen, + const uint8_t *pk) { + + struct hss_validate_inc ctx; + (void)hss_validate_signature_init( + &ctx, /* Incremental validate context */ + (const unsigned char *)pk, /* Public key */ + (const unsigned char *)sm, + (size_t)smlen, /* Signature */ + 0); /* Use the defaults for extra info */ + + (void)hss_validate_signature_update( + &ctx, /* Incremental validate context */ + (const void *) m, /* Next piece of the message */ + (size_t)mlen); /* Length of this piece */ + + bool status = hss_validate_signature_finalize( + &ctx, /* Incremental validate context */ + (const unsigned char *)sm, /* Signature */ + 0); /* Use the defaults for extra info */ + + if (status) { + /* Signature verified */ + return 0; + } else { + /* signature NOT verified */ + return -1; + } +} + diff --git a/src/sig_stfl/lms/sig_stfl_lms_wrap.h b/src/sig_stfl/lms/sig_stfl_lms_wrap.h new file mode 100644 index 0000000000..043de2c461 --- /dev/null +++ b/src/sig_stfl/lms/sig_stfl_lms_wrap.h @@ -0,0 +1,62 @@ +// SPDX-License-Identifier: MIT + +#ifndef OQS_SIG_STFL_LMS_WRAP_H +#define OQS_SIG_STFL_LMS_WRAP_H + +//#include +#include "external/hss.h" +#include "external/hss_sign_inc.h" + + +/** + * @brief OQS_LMS_KEY object for HSS key pair + */ +typedef struct OQS_LMS_KEY_DATA oqs_lms_key_data; + +typedef struct OQS_LMS_KEY_DATA { + + /* Tree levels. */ + unsigned levels; + + /* Array, 8 levels max, of LMS types */ + param_set_t lm_type[8]; + + /* Array, 8 levels max, of LM OTS types */ + param_set_t lm_ots_type[8]; + + /* LMS public key */ + unsigned char public_key[60]; + + /* internal nodes info of the Merkle tree */ + unsigned char *aux_data; + + /* Length of aux data */ + size_t len_aux_data; + + /* User defined data that may be used for the SAFETY functions */ + void *data; + +} oqs_lms_key_data; + + +typedef struct OQS_LMS_SIG_DATA oqs_lms_sig_data; + +typedef struct OQS_LMS_SIG_DATA { + + + /* message buffer */ + unsigned char *message; + + /* Length of msg buffer */ + size_t len_msg_buf; + + /* signature buffer */ + unsigned char *signature; + + /* Length of sig buffer */ + size_t len_sig_buf; + +} oqs_lms_sig_data; + +#endif //OQS_SIG_STFL_LMS_H + diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 20bf641b95..dd3b1ed5cc 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -42,6 +42,7 @@ OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { OQS_SIG_STFL_alg_xmssmt_shake128_h60_3, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12, + OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1, }; if (i >= OQS_SIG_STFL_algs_length) { @@ -229,6 +230,12 @@ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name) { return 1; #else return 0; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_LMS + return 1; +#else + return 0; #endif } else { return 0; @@ -409,6 +416,12 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { #else return NULL; #endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_LMS + return OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(); +#else + return NULL; +#endif //OQS_ENABLE_SIG_STFL_LMS } else { return NULL; } @@ -439,7 +452,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m } } -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const uint8_t *secret_key) { if (sig == NULL || sig->sigs_remaining == NULL || sig->sigs_remaining(remain, secret_key) != 0) { return OQS_ERROR; } else { @@ -447,7 +460,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, uint64_t } } -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, uint64_t *max, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const uint8_t *secret_key) { if (sig == NULL || sig->sigs_total == NULL || sig->sigs_total(max, secret_key) != 0) { return OQS_ERROR; } else { @@ -636,6 +649,12 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_ return OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(); #else return NULL; +#endif + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_LMS + return OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(); +#else + return NULL; #endif } else { return NULL; diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index b2955d78ba..892054a78c 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -50,7 +50,14 @@ extern "C" { #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6 "XMSSMT-SHAKE_60/6_256" #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12 "XMSSMT-SHAKE_60/12_256" -#define OQS_SIG_STFL_algs_length 28 +/* Defined LMS parameter identifiers */ +#define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1 "LMS_SHA256_H5_W1" //"5/1" + +#define OQS_SIG_STFL_algs_length 29 + +/* Defined LM parameter identifiers */ +/* Algorithm identifier for LMS-SHA256_N32_H5 */ +#define OQS_SIG_STFL_alg_lms_sha256_n32_h5 "LMS-SHA256_N32_H5" //0x00000005 /** * Returns identifiers for available signature schemes in liboqs. Used with OQS_SIG_STFL_new. @@ -159,7 +166,7 @@ typedef struct OQS_SIG_STFL { * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*sigs_remaining)(uint64_t *remain, const uint8_t *secret_key); + OQS_STATUS (*sigs_remaining)(unsigned long long *remain, const uint8_t *secret_key); /** * Total number of signatures @@ -168,7 +175,7 @@ typedef struct OQS_SIG_STFL { * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*sigs_total)(uint64_t *total, const uint8_t *secret_key); + OQS_STATUS (*sigs_total)(unsigned long long *total, const uint8_t *secret_key); } OQS_SIG_STFL; @@ -311,7 +318,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, uint64_t *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const uint8_t *secret_key); /** * * Total number of signatures @@ -321,7 +328,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, uint64_t * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, uint64_t *max, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const uint8_t *secret_key); /** * Frees an OQS_SIG_STFL object that was constructed by OQS_SIG_STFL_new. @@ -365,4 +372,8 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk); #include #endif // OQS_ENABLE_SIG_STFL_XMSS +#ifdef OQS_ENABLE_SIG_STFL_LMS +#include +#endif // OQS_ENABLE_SIG_STFL_LMS + #endif /* OQS_SIG_STATEFUL_H */ diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index 1fbc305b29..aa326dfff5 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -57,8 +57,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -73,8 +73,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -89,8 +89,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -105,8 +105,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -121,8 +121,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -137,8 +137,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -153,8 +153,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -169,8 +169,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -185,8 +185,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -201,8 +201,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -217,8 +217,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -233,8 +233,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -249,8 +249,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -265,8 +265,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -281,8 +281,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -297,8 +297,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -313,8 +313,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -329,8 +329,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -345,8 +345,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -361,8 +361,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -377,8 +377,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -393,8 +393,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -409,8 +409,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -425,8 +425,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -441,8 +441,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -457,8 +457,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -473,8 +473,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif @@ -489,8 +489,8 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void) OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(uint8_t *public_key, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(uint64_t *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(uint64_t *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned long long *total, const uint8_t *secret_key); #endif diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index aa812bd22c..9a30f7c4f0 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -89,7 +89,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, siz if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; + *signature_len = (size_t)sig_length; return OQS_SUCCESS; } @@ -100,38 +100,33 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const return OQS_ERROR; } - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { + if (xmss_sign_open(message, (unsigned long long)message_len, signature, (unsigned long long)signature_len, public_key)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } - diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index d613a4f9c0..289732ecdb 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index 5d40092b9c..936fbdd32a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index 81a1b85c5f..488713d95a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index b99b429fbd..6993faf83a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index 8c618b8bd7..2ebfc9dd57 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index efc4c6ed5d..3e961c076b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index 948e29b597..a8ed4fa37e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index 9e9d330da7..e39f3912c2 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index e96c5da22a..26bd706c9c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index b90fe2cc79..c5c44d6655 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index 53a88db04b..439f4b3f99 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmss_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmss_total_signatures(&total_signatures, secret_key)) { + if (xmss_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index b5c1df16af..4cbd91beb5 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index 2bad4a33a2..9e830571cd 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index c1a0243e96..42181f75f6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index 9835724a5c..69df1302f8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index ed223acdd7..6d4e161d53 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index de9253552d..377518a0da 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index 7e54ff760c..a455e43814 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index 49d870dec0..e57d298615 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 5a66fc4e96..331949be1f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 163689fc33..0acc511e7a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index 9e59b72d19..cc379336b2 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index 4dbd11f836..11030a2494 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index 91223579b6..cec3c1cd73 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index e480d2d5e7..3cb5f20300 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(XMSS_UNUSED_AT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index 3904bd43b5..bc8f7a96bb 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index b6cf53cfe0..8bcb4dc0dd 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -107,30 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(uint64_t *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t remaining_signatures = 0; - if (xmssmt_remaining_signatures(&remaining_signatures, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key)) { return OQS_ERROR; } - *remain = (uint64_t) remaining_signatures; return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned long long *total, const uint8_t *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - uint64_t total_signatures = 0; - if (xmssmt_total_signatures(&total_signatures, secret_key)) { + if (xmssmt_total_signatures(total, secret_key)) { return OQS_ERROR; } - *total = (uint64_t) total_signatures; return OQS_SUCCESS; } \ No newline at end of file diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 26385ab063..a393dc6cf4 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -393,7 +393,7 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { } printf("================================================================================\n"); - printf("Create for statefull Secret Key %s\n", method_name); + printf("Create stateful Secret Key %s\n", method_name); printf("================================================================================\n"); if (!sk->secret_key_data) { From 4d773d785e1640889e8c3d84dfb3139c9804587b Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Sat, 12 Aug 2023 12:00:59 -0400 Subject: [PATCH 10/68] Convert to use OQS_SIG_STFL_SECRET_KEY struct (#1525) * Convert API to use OQS_SIG_STFL_SECRET_KEY * Update formatting --- src/sig_stfl/sig_stfl.c | 10 ++++++---- src/sig_stfl/sig_stfl.h | 19 ++++++++++--------- 2 files changed, 16 insertions(+), 13 deletions(-) diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index dd3b1ed5cc..c440e9e95d 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -428,15 +428,17 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { } -OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { if (sig == NULL || sig->keypair == NULL || sig->keypair(public_key, secret_key) != 0) { return OQS_ERROR; } else { return OQS_SUCCESS; } + return OQS_ERROR; } -OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, + size_t message_len, const OQS_SIG_STFL_SECRET_KEY *secret_key) { if (sig == NULL || sig->sign == NULL || sig->sign(signature, signature_len, message, message_len, secret_key) != 0) { return OQS_ERROR; } else { @@ -452,7 +454,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m } } -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { if (sig == NULL || sig->sigs_remaining == NULL || sig->sigs_remaining(remain, secret_key) != 0) { return OQS_ERROR; } else { @@ -460,7 +462,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned } } -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const OQS_SIG_STFL_SECRET_KEY *secret_key) { if (sig == NULL || sig->sigs_total == NULL || sig->sigs_total(max, secret_key) != 0) { return OQS_ERROR; } else { diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 892054a78c..5ef5317376 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -59,6 +59,8 @@ extern "C" { /* Algorithm identifier for LMS-SHA256_N32_H5 */ #define OQS_SIG_STFL_alg_lms_sha256_n32_h5 "LMS-SHA256_N32_H5" //0x00000005 +typedef struct OQS_SIG_STFL_SECRET_KEY OQS_SIG_STFL_SECRET_KEY; + /** * Returns identifiers for available signature schemes in liboqs. Used with OQS_SIG_STFL_new. * @@ -129,7 +131,7 @@ typedef struct OQS_SIG_STFL { * @param[out] secret_key The secret key represented as a byt string * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*keypair)(uint8_t *public_key, uint8_t *secret_key); + OQS_STATUS (*keypair)(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Signature generation algorithm. @@ -145,7 +147,7 @@ typedef struct OQS_SIG_STFL { * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*sign)(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); + OQS_STATUS (*sign)(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, const OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Signature verification algorithm. @@ -166,7 +168,7 @@ typedef struct OQS_SIG_STFL { * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*sigs_remaining)(unsigned long long *remain, const uint8_t *secret_key); + OQS_STATUS (*sigs_remaining)(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Total number of signatures @@ -175,14 +177,13 @@ typedef struct OQS_SIG_STFL { * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*sigs_total)(unsigned long long *total, const uint8_t *secret_key); + OQS_STATUS (*sigs_total)(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); } OQS_SIG_STFL; /** * @brief OQS_SIG_STFL_SECRET_KEY object for stateful signature schemes */ -typedef struct OQS_SIG_STFL_SECRET_KEY OQS_SIG_STFL_SECRET_KEY; typedef struct OQS_SIG_STFL_SECRET_KEY { @@ -278,7 +279,7 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name); * @param[out] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *pk, uint8_t *sk); +OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk); /** * Signature generation algorithm. @@ -295,7 +296,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *pk, ui * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, const OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Signature verification algorithm. @@ -318,7 +319,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); /** * * Total number of signatures @@ -328,7 +329,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Frees an OQS_SIG_STFL object that was constructed by OQS_SIG_STFL_new. From 4694fc3b6e03720b25a8bb1ab292111dccb5bb28 Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Fri, 18 Aug 2023 14:12:14 -0400 Subject: [PATCH 11/68] Add secret key object to XMSS (#1530) * Initial addition of sig_stfl API and dummy XMSS variant * add secret key object * allocate and free using wrapper function instead of malloc/free * cleaner function signature * Fix comment * Delete old file * Missing newline * Missing newlines --- src/CMakeLists.txt | 2 + src/sig_stfl/sig_stfl.c | 2 +- src/sig_stfl/sig_stfl.h | 6 +- src/sig_stfl/xmss/external/core_hash.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss.h | 224 +++++++++--------- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 24 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 26 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 26 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 26 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 26 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 26 +- .../xmss/sig_stfl_xmss_shake128_h10.c | 26 +- .../xmss/sig_stfl_xmss_shake128_h16.c | 26 +- .../xmss/sig_stfl_xmss_shake128_h20.c | 26 +- .../xmss/sig_stfl_xmss_shake256_h10.c | 26 +- .../xmss/sig_stfl_xmss_shake256_h16.c | 26 +- .../xmss/sig_stfl_xmss_shake256_h20.c | 26 +- .../xmss/sig_stfl_xmssmt_sha256_h20_2.c | 26 +- .../xmss/sig_stfl_xmssmt_sha256_h20_4.c | 26 +- .../xmss/sig_stfl_xmssmt_sha256_h40_2.c | 26 +- .../xmss/sig_stfl_xmssmt_sha256_h40_4.c | 26 +- .../xmss/sig_stfl_xmssmt_sha256_h40_8.c | 26 +- .../xmss/sig_stfl_xmssmt_sha256_h60_12.c | 26 +- .../xmss/sig_stfl_xmssmt_sha256_h60_3.c | 26 +- .../xmss/sig_stfl_xmssmt_sha256_h60_6.c | 26 +- .../xmss/sig_stfl_xmssmt_shake128_h20_2.c | 26 +- .../xmss/sig_stfl_xmssmt_shake128_h20_4.c | 26 +- .../xmss/sig_stfl_xmssmt_shake128_h40_2.c | 26 +- .../xmss/sig_stfl_xmssmt_shake128_h40_4.c | 26 +- .../xmss/sig_stfl_xmssmt_shake128_h40_8.c | 26 +- .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 26 +- .../xmss/sig_stfl_xmssmt_shake128_h60_3.c | 26 +- .../xmss/sig_stfl_xmssmt_shake128_h60_6.c | 26 +- tests/kat_sig_stfl.c | 10 +- tests/test_sig_stfl.c | 21 +- 35 files changed, 493 insertions(+), 500 deletions(-) diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt index a5b64fd294..b6772ee9ff 100644 --- a/src/CMakeLists.txt +++ b/src/CMakeLists.txt @@ -73,6 +73,8 @@ add_library(oqs kem/kem.c ${SIG_OBJS} sig_stfl/sig_stfl.c ${SIG_STFL_OBJS} + sig_stfl/sig_stfl.c + ${SIG_STFL_OBJS} ${COMMON_OBJS}) # Internal library to be used only by test programs diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index c440e9e95d..c77139e20a 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -438,7 +438,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public } OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, - size_t message_len, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { if (sig == NULL || sig->sign == NULL || sig->sign(signature, signature_len, message, message_len, secret_key) != 0) { return OQS_ERROR; } else { diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 5ef5317376..b795853c5c 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -147,7 +147,7 @@ typedef struct OQS_SIG_STFL { * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*sign)(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, const OQS_SIG_STFL_SECRET_KEY *secret_key); + OQS_STATUS (*sign)(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Signature verification algorithm. @@ -296,7 +296,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *pk, OQ * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Signature verification algorithm. @@ -315,7 +315,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m * Query number of remaining signatures * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. - * @param[out] remain The number of remaining signatures * @param[in] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ @@ -334,7 +333,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned lon /** * Frees an OQS_SIG_STFL object that was constructed by OQS_SIG_STFL_new. * - * @param[in] sig The OQS_SIG_STFL object to free. */ OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig); diff --git a/src/sig_stfl/xmss/external/core_hash.c b/src/sig_stfl/xmss/external/core_hash.c index 565e571e36..b27ad2ca9b 100644 --- a/src/sig_stfl/xmss/external/core_hash.c +++ b/src/sig_stfl/xmss/external/core_hash.c @@ -35,4 +35,4 @@ int core_hash(const xmss_params *params, #endif return 0; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index aa326dfff5..1cf29900f3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -54,11 +54,11 @@ void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -70,11 +70,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long lon OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h16_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -86,11 +86,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long lon OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h20_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -102,11 +102,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long lon OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h10_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -118,11 +118,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long l OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h16_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -134,11 +134,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long l OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h20_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -150,11 +150,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long l OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h10_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -166,11 +166,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long lon OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h16_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -182,11 +182,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long lon OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h20_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -198,11 +198,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long lon OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h10_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -214,11 +214,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long l OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h16_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -230,11 +230,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long l OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h20_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -246,11 +246,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long l OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -262,11 +262,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -278,11 +278,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -294,11 +294,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -310,11 +310,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -326,11 +326,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -342,11 +342,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -358,11 +358,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -374,11 +374,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned lon OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -390,11 +390,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned lo OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -406,11 +406,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned lo OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -422,11 +422,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned lo OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -438,11 +438,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned lo OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -454,11 +454,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned lo OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -470,11 +470,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned lo OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif @@ -486,11 +486,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned lo OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(uint8_t *public_key, uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned long long *total, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); #endif diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index 9a30f7c4f0..4ff8f24e7d 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_sha256_h10_oid = 0x01; - if (xmss_keypair(public_key, secret_key, xmss_sha256_h10_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha256_h10_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t)sig_length; @@ -107,24 +107,24 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index 289732ecdb..f467b67595 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_sha256_h16_oid = 0x02; - if (xmss_keypair(public_key, secret_key, xmss_sha256_h16_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha256_h16_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index 936fbdd32a..ab7a74410f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_sha256_h20_oid = 0x03; - if (xmss_keypair(public_key, secret_key, xmss_sha256_h20_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha256_h20_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index 488713d95a..b38207c86b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_sha512_h10_oid = 0x04; - if (xmss_keypair(public_key, secret_key, xmss_sha512_h10_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha512_h10_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index 6993faf83a..050026311a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_sha512_h16_oid = 0x05; - if (xmss_keypair(public_key, secret_key, xmss_sha512_h16_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha512_h16_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index 2ebfc9dd57..b5084201fd 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_sha512_h20_oid = 0x06; - if (xmss_keypair(public_key, secret_key, xmss_sha512_h20_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha512_h20_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(XMSS_UNUSED_ATT const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index 3e961c076b..ac43b57b3c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_shake128_h10_oid = 0x07; - if (xmss_keypair(public_key, secret_key, xmss_shake128_h10_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake128_h10_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index a8ed4fa37e..596939f155 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_shake128_h16_oid = 0x08; - if (xmss_keypair(public_key, secret_key, xmss_shake128_h16_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake128_h16_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index e39f3912c2..37da02a13b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_shake128_h20_oid = 0x09; - if (xmss_keypair(public_key, secret_key, xmss_shake128_h20_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake128_h20_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index 26bd706c9c..f0d27e2033 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_shake256_h10_oid = 0x0a; - if (xmss_keypair(public_key, secret_key, xmss_shake256_h10_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake256_h10_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index c5c44d6655..38cd5603a9 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_shake256_h16_oid = 0x0b; - if (xmss_keypair(public_key, secret_key, xmss_shake256_h16_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake256_h16_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index 439f4b3f99..ed1989876e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmss_shake256_h20_oid = 0x0c; - if (xmss_keypair(public_key, secret_key, xmss_shake256_h20_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake256_h20_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmss_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(XMSS_UNUSED_ATT con return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_remaining_signatures(remain, secret_key)) { + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmss_total_signatures(total, secret_key)) { + if (xmss_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index 4cbd91beb5..792d7a3559 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_sha256_h20_2_oid = 0x01; - if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h20_2_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h20_2_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index 9e830571cd..4a1d1cad52 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_sha256_h20_4_oid = 0x02; - if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h20_4_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h20_4_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index 42181f75f6..9bb9c61445 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_sha256_h40_2_oid = 0x03; - if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h40_2_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h40_2_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index 69df1302f8..64a2da1331 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_sha256_h40_4_oid = 0x04; - if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h40_4_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h40_4_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index 6d4e161d53..13843351ee 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_sha256_h40_8_oid = 0x05; - if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h40_8_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h40_8_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index 377518a0da..06873a58db 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_sha256_h60_12_oid = 0x08; - if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h60_12_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h60_12_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index a455e43814..67183fee79 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_sha256_h60_3_oid = 0x06; - if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h60_3_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h60_3_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index e57d298615..8ab9134684 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_sha256_h60_6_oid = 0x07; - if (xmssmt_keypair(public_key, secret_key, xmssmt_sha256_h60_6_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h60_6_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(XMSS_UNUSED_ATT c return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 331949be1f..279146a010 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_shake128_h20_2_oid = 0x11; - if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h20_2_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h20_2_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 0acc511e7a..961fd8c0a7 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_shake128_h20_4_oid = 0x12; - if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h20_4_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h20_4_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index cc379336b2..a72d9b7e67 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_shake128_h40_2_oid = 0x13; - if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h40_2_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h40_2_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index 11030a2494..64c2f8cea3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_shake128_h40_4_oid = 0x14; - if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h40_4_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h40_4_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index cec3c1cd73..7b1c137e8a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_shake128_h40_8_oid = 0x15; - if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h40_8_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h40_8_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index 3cb5f20300..41c4317ad9 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_shake128_h60_12_oid = 0x18; - if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h60_12_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h60_12_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(XMSS_UNUSED_AT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index bc8f7a96bb..5a38219f83 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_shake128_h60_3_oid = 0x16; - if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h60_3_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h60_3_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index 8bcb4dc0dd..9c860051d7 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -65,28 +65,28 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void) { return sk; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (public_key == NULL || secret_key == NULL) { + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } const uint32_t xmssmt_shake128_h60_6_oid = 0x17; - if (xmssmt_keypair(public_key, secret_key, xmssmt_shake128_h60_6_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h60_6_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL) { + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key, signature, &sig_length, message, message_len)) { + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { return OQS_ERROR; } *signature_len = (size_t) sig_length; @@ -107,26 +107,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(XMSS_UNUSED_ATT return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(unsigned long long *remain, const uint8_t *secret_key) { - if (remain == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_remaining_signatures(remain, secret_key)) { + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned long long *total, const uint8_t *secret_key) { - if (total == NULL || secret_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - if (xmssmt_total_signatures(total, secret_key)) { + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { return OQS_ERROR; } return OQS_SUCCESS; -} \ No newline at end of file +} diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 8e56bac5b8..9a5cdd7a6d 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -131,7 +131,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { uint8_t *msg = NULL, *msg_rand = NULL; size_t msg_len = 0; uint8_t *public_key = NULL; - uint8_t *secret_key = NULL; + OQS_SIG_STFL_SECRET_KEY *secret_key = NULL; uint8_t *signature = NULL, *signature_kat = NULL; uint8_t *signed_msg = NULL; size_t signature_len = 0; @@ -159,7 +159,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { // Grab the pk and sk from KAT file public_key = malloc(sig->length_public_key); - secret_key = calloc(sig->length_secret_key, sizeof(uint8_t)); + secret_key = OQS_SIG_STFL_SECRET_KEY_new(sig->method_name); signature = calloc(sig->length_signature, sizeof(uint8_t)); signature_kat = calloc(sig->length_signature, sizeof(uint8_t)); @@ -173,7 +173,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { goto err; } - if (!ReadHex(fp_rsp, secret_key, sig->length_secret_key, "sk = ")) { + if (!ReadHex(fp_rsp, secret_key->secret_key_data, sig->length_secret_key, "sk = ")) { fprintf(stderr, "ERROR: unable to read 'sk' from <%s>\n", katfile); goto err; } @@ -182,7 +182,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { fprintf(fh, "# %s\n\n", sig->method_name); OQS_fprintBstr(fh, "pk = ", public_key, sig->length_public_key); - OQS_fprintBstr(fh, "sk = ", secret_key, sig->length_secret_key); + OQS_fprintBstr(fh, "sk = ", secret_key->secret_key_data, sig->length_secret_key); fprintf(fh, "\n\n"); fprintf(fh, "count = 0\n"); @@ -271,10 +271,10 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { cleanup: if (sig != NULL) { - OQS_MEM_secure_free(secret_key, sig->length_secret_key); OQS_MEM_secure_free(signed_msg, signed_msg_len); } OQS_MEM_insecure_free(public_key); + OQS_SIG_STFL_SECRET_KEY_free(secret_key); OQS_MEM_insecure_free(signature); OQS_MEM_insecure_free(signature_kat); OQS_MEM_insecure_free(msg); diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index a393dc6cf4..770eb58f82 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -123,7 +123,7 @@ int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { return 1; } -OQS_STATUS sig_stfl_keypair_from_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, uint8_t *secret_key) { +OQS_STATUS sig_stfl_keypair_from_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { OQS_STATUS rc; rc = OQS_SIG_STFL_keypair(sig, public_key, secret_key); OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); @@ -133,7 +133,7 @@ OQS_STATUS sig_stfl_keypair_from_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, return OQS_SUCCESS; } -OQS_STATUS sig_stfl_keypair_from_KATs(OQS_SIG_STFL *sig, uint8_t *public_key, uint8_t *secret_key, const char *katfile) { +OQS_STATUS sig_stfl_keypair_from_KATs(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key, const char *katfile) { OQS_STATUS ret = OQS_ERROR; FILE *fp_rsp = NULL; @@ -148,7 +148,7 @@ OQS_STATUS sig_stfl_keypair_from_KATs(OQS_SIG_STFL *sig, uint8_t *public_key, ui goto err; } - if (!ReadHex(fp_rsp, secret_key, sig->length_secret_key, "sk = ")) { + if (!ReadHex(fp_rsp, secret_key->secret_key_data, sig->length_secret_key, "sk = ")) { fprintf(stderr, "ERROR: unable to read 'sk' from <%s>\n", katfile); goto err; } @@ -176,7 +176,7 @@ OQS_STATUS sig_stfl_keypair_from_KATs(OQS_SIG_STFL *sig, uint8_t *public_key, ui * XMSSMT-SHAKE_40/2_256 * XMSSMT-SHAKE_60/3_256 */ -OQS_STATUS sig_stfl_KATs_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, uint8_t *secret_key, const char *katfile) { +OQS_STATUS sig_stfl_KATs_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key, const char *katfile) { printf("%s", sig->method_name); if (0) { @@ -253,7 +253,7 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char OQS_SIG_STFL *sig = NULL; uint8_t *public_key = NULL; - uint8_t *secret_key = NULL; + OQS_SIG_STFL_SECRET_KEY *secret_key = NULL; uint8_t *message = NULL; size_t message_len = 100; uint8_t *signature = NULL; @@ -275,8 +275,8 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char printf("Sample computation for stateful signature %s\n", sig->method_name); printf("================================================================================\n"); + secret_key = OQS_SIG_STFL_SECRET_KEY_new(sig->method_name); public_key = malloc(sig->length_public_key + 2 * sizeof(magic_t)); - secret_key = malloc(sig->length_secret_key + 2 * sizeof(magic_t)); message = malloc(message_len + 2 * sizeof(magic_t)); signature = malloc(sig->length_signature + 2 * sizeof(magic_t)); @@ -287,18 +287,15 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char //Set the magic numbers before memcpy(public_key, magic.val, sizeof(magic_t)); - memcpy(secret_key, magic.val, sizeof(magic_t)); memcpy(message, magic.val, sizeof(magic_t)); memcpy(signature, magic.val, sizeof(magic_t)); public_key += sizeof(magic_t); - secret_key += sizeof(magic_t); message += sizeof(magic_t); signature += sizeof(magic_t); // and after memcpy(public_key + sig->length_public_key, magic.val, sizeof(magic_t)); - memcpy(secret_key + sig->length_secret_key, magic.val, sizeof(magic_t)); memcpy(message + message_len, magic.val, sizeof(magic_t)); memcpy(signature + sig->length_signature, magic.val, sizeof(magic_t)); @@ -344,11 +341,9 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char #ifndef OQS_ENABLE_TEST_CONSTANT_TIME /* check magic values */ int rv = memcmp(public_key + sig->length_public_key, magic.val, sizeof(magic_t)); - rv |= memcmp(secret_key + sig->length_secret_key, magic.val, sizeof(magic_t)); rv |= memcmp(message + message_len, magic.val, sizeof(magic_t)); rv |= memcmp(signature + sig->length_signature, magic.val, sizeof(magic_t)); rv |= memcmp(public_key - sizeof(magic_t), magic.val, sizeof(magic_t)); - rv |= memcmp(secret_key - sizeof(magic_t), magic.val, sizeof(magic_t)); rv |= memcmp(message - sizeof(magic_t), magic.val, sizeof(magic_t)); rv |= memcmp(signature - sizeof(magic_t), magic.val, sizeof(magic_t)); if (rv) { @@ -365,9 +360,7 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char ret = OQS_ERROR; cleanup: - if (secret_key) { - OQS_MEM_secure_free(secret_key - sizeof(magic_t), sig->length_secret_key + 2 * sizeof(magic_t)); - } + OQS_SIG_STFL_SECRET_KEY_free(secret_key); if (public_key) { OQS_MEM_insecure_free(public_key - sizeof(magic_t)); } From 245aede9970934f45801aa12ed9189b42c94993a Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Tue, 29 Aug 2023 15:48:49 -0400 Subject: [PATCH 12/68] LMS updated to use new SK API (#1533) * Use secret key struct in LMS. Update de/serialize sk API * Updates per comments * Update per comments * Fix mem leak * Address scan bild issue * Removed unused variable * Remove unused struc member * Address macOS-noopenssl build failures --- src/sig_stfl/lms/sig_stfl_lms.c | 65 +++-- src/sig_stfl/lms/sig_stfl_lms.h | 25 +- src/sig_stfl/lms/sig_stfl_lms_functions.c | 277 +++++++++++++++++++--- src/sig_stfl/lms/sig_stfl_lms_wrap.h | 26 -- src/sig_stfl/sig_stfl.h | 20 +- tests/kat_sig_stfl.c | 14 +- tests/test_sig_stfl.c | 102 +++++++- 7 files changed, 421 insertions(+), 108 deletions(-) diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index dde8dc586f..1a0831f39d 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -10,7 +10,7 @@ // ======================== LMS-SHA256 H5/W1 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { if (secret_key == NULL || public_key == NULL) { return OQS_ERROR; } @@ -60,34 +60,55 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void) { // Initialize the key with length_secret_key amount of bytes. sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk; - if (sk->length_secret_key) { - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - if (sk->secret_key_data) { - memset(sk->secret_key_data, 0, sk->length_secret_key); - } else { - OQS_SECRET_KEY_LMS_free(sk); - OQS_MEM_insecure_free(sk); - sk = NULL; - return NULL; - } - } + /* Function that returns the total number of signatures for the secret key */ + sk->sigs_total = NULL; + + /* set Function to returns the number of signatures left for the secret key */ + sk->sigs_left = NULL; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + /* + * Set Secret Key Saving Function + */ + sk->save_secret_key = NULL; + + /* + * Set Secret Key free function + */ sk->free_key = OQS_SECRET_KEY_LMS_free; return sk; } void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk) { - if (sk == NULL) { - return; - } + oqs_secret_lms_key_free(sk); +} - //TODO: cleanup lock_key +/* Convert LMS secret key object to byte string */ +size_t OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_buf) { + return oqs_serialize_lms_key(sk, sk_buf); +} - if (sk->sig) { - OQS_MEM_insecure_free(sk->sig); - sk->sig = NULL; - } - OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); - sk->secret_key_data = NULL; +/* Insert lms byte string in an LMS secret key object */ +OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf) { + return oqs_deserialize_lms_key(sk, key_len, sk_buf); } diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index 97104b47f8..ab32848ac8 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -10,32 +10,43 @@ #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk 64 -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); + +/* Convert LMS secret key object to byte string */ +size_t OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_buf); + +/* Insert lms byte string in an LMS secret key object */ +OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf); + OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const uint8_t *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(uint64_t *totaln, const uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(uint64_t *totaln, const OQS_SIG_STFL_SECRET_KEY *secret_key); void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); // ----------------------------------- WRAPPER FUNCTIONS ------------------------------------------------ -int oqs_sig_stfl_lms_keypair(uint8_t *pk, uint8_t *sk, const uint32_t oid); +int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uint32_t oid); -int oqs_sig_stfl_lms_sign(uint8_t *sk, uint8_t *sm, size_t *smlen, +int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, uint8_t *sm, size_t *smlen, const uint8_t *m, size_t mlen); int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, const uint8_t *sm, size_t smlen, const uint8_t *pk); +void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk); + +size_t oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_key); +int oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf); + // ---------------------------- FUNCTIONS INDEPENDENT OF VARIANT ----------------------------------------- -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signature_length, const uint8_t *message, size_t message_len, uint8_t *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signature_length, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); - // -------------------------------------------------------------------------------------------------------- #endif /* OQS_SIG_STFL_LMS_H */ diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index 8c17ddddd0..da7f865c07 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -9,8 +9,40 @@ #include "sig_stfl_lms_wrap.h" #include +#define DEFAULT_AUX_DATA 10916 /* Use 10+k of aux data (which works well */ +/* with the above default parameter set) */ +/** + * @brief OQS_LMS_KEY object for HSS key pair + */ + +typedef struct OQS_LMS_KEY_DATA { + + /* Tree levels. */ + uint32_t levels; + + /* Array, 8 levels max, of LMS types */ + param_set_t lm_type[8]; + + /* Array, 8 levels max, of LM OTS types */ + param_set_t lm_ots_type[8]; + + /* LMS public key */ + uint8_t public_key[60]; + + /* Length of aux data */ + size_t len_aux_data; + /* internal nodes info of the Merkle tree */ + uint8_t *aux_data; + + /* Length of sec_key */ + size_t len_sec_key; + + /* secret key data */ + uint8_t *sec_key; +} oqs_lms_key_data; + OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signature_length, const uint8_t *message, - size_t message_len, uint8_t *secret_key) { + size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { if (secret_key == NULL || message == NULL || signature == NULL) { return OQS_ERROR; @@ -45,7 +77,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t me return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { if (remain == NULL || secret_key == NULL) { return OQS_ERROR; @@ -55,7 +87,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(uint64_t *total, const uint8_t *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(uint64_t *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; @@ -75,41 +107,78 @@ bool LMS_randombytes(void *buffer, size_t length) { return true; } -int oqs_sig_stfl_lms_keypair(uint8_t *pk, uint8_t *sk, const uint32_t oid) { +int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uint32_t oid) { int ret = -1; bool b_ret; int parse_err = 0; - unsigned levels = 1; - unsigned char public_key[60]; size_t len_public_key = 60; - unsigned char *aux_data = NULL; - size_t max_aux_data = 10916; - int aux_len = 0; - oqs_lms_key_data *oqs_data = NULL; - - param_set_t lm_type[1]; - param_set_t lm_ots_type[1]; + oqs_lms_key_data *oqs_key_data = NULL; if (!pk || !sk || !oid) { return -1; } + if (sk->secret_key_data) { + //this means a key pair has already been recreated + //TODO log error. + return -1; + } + + oqs_key_data = malloc(sizeof(oqs_lms_key_data)); + if (oqs_key_data) { + oqs_key_data->levels = 1; + if (sk->length_secret_key) { + oqs_key_data->len_sec_key = sk->length_secret_key; + oqs_key_data->sec_key = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + if (oqs_key_data->sec_key) { + memset(oqs_key_data->sec_key, 0, sk->length_secret_key); + } else { + OQS_MEM_insecure_free(oqs_key_data); + oqs_key_data = NULL; + return -1; + } + } else { + OQS_MEM_insecure_free(oqs_key_data); + oqs_key_data = NULL; + return -1; + } + + //Aux Data + size_t len_aux_data = DEFAULT_AUX_DATA; + uint8_t *aux_data = malloc(sizeof(uint8_t) * len_aux_data); + if (aux_data) { + oqs_key_data->aux_data = aux_data; + oqs_key_data->len_aux_data = len_aux_data; + } else { + OQS_MEM_insecure_free( oqs_key_data->sec_key); + OQS_MEM_insecure_free(oqs_key_data); + return -1; + } + } else { + //TODO log error + return -1; + } + /* Set lms param set */ switch (oid) { case 0x1: - lm_type[0] = LMS_SHA256_N32_H5; - lm_ots_type[0] = LMOTS_SHA256_N32_W1; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; break; default: - lm_type[0] = 0; - lm_ots_type[0] = 0; + oqs_key_data->lm_type[0] = 0; + oqs_key_data->lm_ots_type[0] = 0; parse_err = 1; break; } if (parse_err) { + OQS_MEM_insecure_free(oqs_key_data->sec_key); + OQS_MEM_insecure_free(oqs_key_data->aux_data); + OQS_MEM_insecure_free(oqs_key_data); + oqs_key_data = NULL; return -1; } @@ -145,16 +214,23 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, uint8_t *sk, const uint32_t oid) { */ b_ret = hss_generate_private_key( LMS_randombytes, - levels, - lm_type, - lm_ots_type, + oqs_key_data->levels, + oqs_key_data->lm_type, + oqs_key_data->lm_ots_type, NULL, //File handler function? - (void *)sk, - public_key, len_public_key, - aux_data, aux_len, + oqs_key_data->sec_key, + oqs_key_data->public_key, len_public_key, + oqs_key_data->aux_data, oqs_key_data->len_aux_data, NULL); if (b_ret) { - memcpy(pk, public_key, len_public_key); + memcpy(pk, oqs_key_data->public_key, len_public_key); + sk->secret_key_data = oqs_key_data; + } else { + OQS_MEM_insecure_free(oqs_key_data->sec_key); + OQS_MEM_insecure_free(oqs_key_data->aux_data); + OQS_MEM_insecure_free(oqs_key_data); + oqs_key_data = NULL; + return -1; } /* TODO: store key pair, file handler */ @@ -163,16 +239,24 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, uint8_t *sk, const uint32_t oid) { return ret; } -int oqs_sig_stfl_lms_sign(uint8_t *sk, +int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, uint8_t *sm, size_t *smlen, const uint8_t *m, size_t mlen) { size_t sig_len; bool status; - unsigned char *sig = NULL; + uint8_t *sig = NULL; + uint8_t *priv_key = NULL; + oqs_lms_key_data *oqs_key_data = NULL; struct hss_working_key *w = NULL; struct hss_sign_inc ctx; - w = hss_load_private_key(NULL, sk, + if (sk) { + oqs_key_data = sk->secret_key_data; + priv_key = oqs_key_data->sec_key; + } else { + return -1; + } + w = hss_load_private_key(NULL, priv_key, 0, NULL, 0, @@ -205,7 +289,7 @@ int oqs_sig_stfl_lms_sign(uint8_t *sk, &ctx, /* Incremental signing context */ w, /* Working key */ NULL, /* Routine to update the */ - sk, /* private key */ + priv_key, /* private key */ sig, sig_len, /* Where to place the signature */ 0); @@ -264,3 +348,140 @@ int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, } } +void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return; + } + + //TODO: cleanup lock_key + + if (sk->sig) { + OQS_MEM_insecure_free(sk->sig); + sk->sig = NULL; + } + + if (sk->secret_key_data) { + oqs_lms_key_data *key_data = (oqs_lms_key_data *)sk->secret_key_data; + if (key_data) { + OQS_MEM_secure_free(key_data->sec_key, key_data->len_sec_key); + key_data->sec_key = NULL; + + OQS_MEM_secure_free(key_data->aux_data, key_data->len_aux_data); + } + + OQS_MEM_insecure_free(key_data); + sk->secret_key_data = NULL; + } +} + +/* + * Convert LMS secret key object to byte string + * Writes secret key + aux data if present + */ +size_t oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_key) { + + oqs_lms_key_data *lms_key_data = NULL; + size_t key_len = 0; + if (sk) { + uint8_t *sk_key_buf = NULL; + lms_key_data = sk->secret_key_data; + if (lms_key_data && lms_key_data->sec_key) { + size_t buf_size_needed = lms_key_data->len_aux_data + lms_key_data->len_sec_key; + key_len = buf_size_needed; + /* pass back serialized data */ + if (sk_key) { + if (buf_size_needed) { + sk_key_buf = malloc(buf_size_needed * sizeof(uint8_t)); + if (sk_key_buf) { + + /* + * Serialized data is sec_key followed by aux data + * So aux data begins after buffer top + sec_key length + */ + if (lms_key_data->len_sec_key) { + memcpy(sk_key_buf, lms_key_data->sec_key, lms_key_data->len_sec_key); + } + + if (lms_key_data->len_aux_data) { + memcpy(sk_key_buf + lms_key_data->len_sec_key, lms_key_data->aux_data, lms_key_data->len_aux_data); + } + + *sk_key = sk_key_buf; + key_len = sk->length_secret_key + lms_key_data->len_aux_data; + } + } + } //sk_key + } + } //sk + return key_len; +} + +/* + * Convert LMS byte string to secret key object + * Writes secret key + aux data if present + * key_len is priv key length + aux length + */ +int oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf) { + int oqs_status = -1; + oqs_lms_key_data *lms_key_data = NULL; + uint8_t priv_ky_len = hss_get_private_key_len((unsigned )(1), NULL, NULL); + + if ((!sk) || (key_len == 0) || (key_len < priv_ky_len) || (!sk_buf)) { + return oqs_status; + } + + if (sk->secret_key_data) { + //Key data already present + //We dont want to trample over data + return oqs_status; + } + + uint8_t *lms_sk = NULL; + uint8_t *lms_aux = NULL; + + unsigned levels = 0; + + int key_buf_left = key_len - priv_ky_len; + + param_set_t lm_type[ MAX_HSS_LEVELS ]; + param_set_t lm_ots_type[ MAX_HSS_LEVELS ]; + + // validate sk_buf for lms params + if (hss_get_parameter_set(&levels, + lm_type, + lm_ots_type, + NULL, + (void *)sk_buf)) { + return oqs_status; + } + + lms_key_data = malloc(sizeof(oqs_lms_key_data)); + if (lms_key_data) { + lms_sk = malloc(priv_ky_len * sizeof(uint8_t)); + if (lms_sk) { + memcpy(lms_sk, sk_buf, priv_ky_len); + lms_key_data->sec_key = lms_sk; + lms_key_data->len_sec_key = priv_ky_len; + } else { + OQS_MEM_insecure_free(lms_key_data); + return oqs_status; + } + + if (key_buf_left) { + lms_aux = malloc(key_buf_left * sizeof(uint8_t)); + if (lms_aux) { + memcpy(lms_aux, (sk_buf + priv_ky_len), key_buf_left); + lms_key_data->aux_data = lms_aux; + lms_key_data->len_aux_data = key_buf_left; + } else { + OQS_MEM_insecure_free(lms_key_data); + OQS_MEM_insecure_free(lms_sk); + return oqs_status; + } + } + + sk->secret_key_data = lms_key_data; + oqs_status = 0; + } + return oqs_status; +} diff --git a/src/sig_stfl/lms/sig_stfl_lms_wrap.h b/src/sig_stfl/lms/sig_stfl_lms_wrap.h index 043de2c461..1d5486d21a 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_wrap.h +++ b/src/sig_stfl/lms/sig_stfl_lms_wrap.h @@ -13,32 +13,6 @@ */ typedef struct OQS_LMS_KEY_DATA oqs_lms_key_data; -typedef struct OQS_LMS_KEY_DATA { - - /* Tree levels. */ - unsigned levels; - - /* Array, 8 levels max, of LMS types */ - param_set_t lm_type[8]; - - /* Array, 8 levels max, of LM OTS types */ - param_set_t lm_ots_type[8]; - - /* LMS public key */ - unsigned char public_key[60]; - - /* internal nodes info of the Merkle tree */ - unsigned char *aux_data; - - /* Length of aux data */ - size_t len_aux_data; - - /* User defined data that may be used for the SAFETY functions */ - void *data; - -} oqs_lms_key_data; - - typedef struct OQS_LMS_SIG_DATA oqs_lms_sig_data; typedef struct OQS_LMS_SIG_DATA { diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index b795853c5c..a3423a667b 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -206,21 +206,23 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * Secret Key retrieval Function * * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object - * @param[out] key_len length of the returned byte string - * @returns newly created pointer to ley byte string if none-zero length. Caller - * deletes the buffer. + * @param[out] sk_buf private key data as a byte stream + * @returns length of key material data available + * Caller deletes the buffer if memory was allocated. */ - uint8_t *(*serialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len); + size_t (*serialize_key)(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_buf); /** * set Secret Key to internal structure Function * - * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object - * @param[out] key_len length of the returned byte string - * @returns newly created pointer to ley byte string if none-zero length. Caller - * deletes the buffer. + * @param[in] sk OQS_SIG_STFL_SECRET_KEY object + * @param[in] key_len length of the returned byte string + * @param[in] sk_key The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @param[in] key_len length of the returned byte string + * @returns status of the operation populated with key material none-zero length. Caller + * deletes the buffer. if sk_buf is NULL the function returns the length */ - uint8_t *(*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, uint8_t *sk_key); + OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf); /** * Secret Key Locking Function diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 9a5cdd7a6d..d5de696580 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -66,7 +66,8 @@ int FindMarker(FILE *infile, const char *marker) { // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { - int i, ch, started; + int ch, started; + unsigned long i; unsigned char ich; if (Length == 0) { @@ -111,19 +112,8 @@ int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { return 1; } -static inline uint16_t UINT16_TO_BE(const uint16_t x) { - union { - uint16_t val; - uint8_t bytes[2]; - } y; - y.bytes[0] = (x >> 8) & 0xFF; - y.bytes[1] = x & 0xFF; - return y.val; -} - OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { - uint8_t entropy_input[48]; uint8_t seed[48]; FILE *fh = NULL; FILE *fp_rsp = NULL; diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 770eb58f82..b496457b99 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -78,7 +78,8 @@ int FindMarker(FILE *infile, const char *marker) { // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { - int i, ch, started; + int ch, started; + unsigned long i; unsigned char ich; if (Length == 0) { @@ -178,7 +179,7 @@ OQS_STATUS sig_stfl_keypair_from_KATs(OQS_SIG_STFL *sig, uint8_t *public_key, OQ */ OQS_STATUS sig_stfl_KATs_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key, const char *katfile) { - printf("%s", sig->method_name); + printf("%s ", sig->method_name); if (0) { #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 @@ -379,6 +380,93 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { OQS_STATUS rc = OQS_SUCCESS; OQS_SIG_STFL_SECRET_KEY *sk = NULL; + OQS_SIG_STFL *sig_obj = NULL; + uint8_t *public_key = NULL; + + /* + * Temporarily skip algs with long key generation times. + */ + + if (0) { + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { + goto skip_test; +#endif + } else { + goto keep_going; + } +skip_test: + printf("Skip slow test %s.\n", method_name); + return rc; + +keep_going: + + printf("================================================================================\n"); + printf("Create stateful Signature %s\n", method_name); + printf("================================================================================\n"); + + sig_obj = OQS_SIG_STFL_new(method_name); + if (sig_obj == NULL) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_new failed\n"); + goto err; + } + + public_key = malloc(sig_obj->length_public_key * sizeof(uint8_t)); + + printf("================================================================================\n"); + printf("Create stateful Secret Key %s\n", method_name); + printf("================================================================================\n"); + sk = OQS_SIG_STFL_SECRET_KEY_new(method_name); if (sk == NULL) { fprintf(stderr, "ERROR: OQS_SECRET_KEY_new failed\n"); @@ -386,21 +474,27 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { } printf("================================================================================\n"); - printf("Create stateful Secret Key %s\n", method_name); + printf("Generate keypair %s\n", method_name); printf("================================================================================\n"); + rc = OQS_SIG_STFL_keypair(sig_obj, public_key, sk); + if (!sk->secret_key_data) { fprintf(stderr, "ERROR: OQS_SECRET_KEY_new incomplete.\n"); + OQS_MEM_insecure_free(public_key); goto err; } - OQS_SIG_STFL_SECRET_KEY_free(sk); printf("Secret Key created as expected.\n"); goto end_it; err: rc = OQS_ERROR; end_it: + + OQS_SIG_STFL_SECRET_KEY_free(sk); + OQS_MEM_insecure_free(public_key); + OQS_SIG_STFL_free(sig_obj); return rc; } From 99067be855c99de792d4e25a3beb736ef9ecf80b Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Sat, 9 Sep 2023 17:24:32 -0400 Subject: [PATCH 13/68] Add XMSS Serialize/Deserialize (#1542) * Add serialize and deserialize to XMSS --------- Co-authored-by: Norman Ashley --- src/sig_stfl/lms/sig_stfl_lms.c | 9 +- src/sig_stfl/lms/sig_stfl_lms.h | 10 +- src/sig_stfl/lms/sig_stfl_lms_functions.c | 157 +++++++++--------- src/sig_stfl/sig_stfl.h | 14 +- src/sig_stfl/xmss/CMakeLists.txt | 3 + src/sig_stfl/xmss/external/sign_params.h | 142 ---------------- src/sig_stfl/xmss/sig_stfl_xmss.h | 9 + .../xmss/sig_stfl_xmss_secret_key_functions.c | 48 ++++++ src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 10 ++ src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 9 + src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 9 + src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 9 + src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 9 + src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 9 + .../xmss/sig_stfl_xmss_shake128_h10.c | 9 + .../xmss/sig_stfl_xmss_shake128_h16.c | 9 + .../xmss/sig_stfl_xmss_shake128_h20.c | 9 + .../xmss/sig_stfl_xmss_shake256_h10.c | 9 + .../xmss/sig_stfl_xmss_shake256_h16.c | 9 + .../xmss/sig_stfl_xmss_shake256_h20.c | 9 + .../xmss/sig_stfl_xmssmt_sha256_h20_2.c | 9 + .../xmss/sig_stfl_xmssmt_sha256_h20_4.c | 9 + .../xmss/sig_stfl_xmssmt_sha256_h40_2.c | 9 + .../xmss/sig_stfl_xmssmt_sha256_h40_4.c | 9 + .../xmss/sig_stfl_xmssmt_sha256_h40_8.c | 9 + .../xmss/sig_stfl_xmssmt_sha256_h60_12.c | 9 + .../xmss/sig_stfl_xmssmt_sha256_h60_3.c | 9 + .../xmss/sig_stfl_xmssmt_sha256_h60_6.c | 9 + .../xmss/sig_stfl_xmssmt_shake128_h20_2.c | 9 + .../xmss/sig_stfl_xmssmt_shake128_h20_4.c | 9 + .../xmss/sig_stfl_xmssmt_shake128_h40_2.c | 9 + .../xmss/sig_stfl_xmssmt_shake128_h40_4.c | 9 + .../xmss/sig_stfl_xmssmt_shake128_h40_8.c | 9 + .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 9 + .../xmss/sig_stfl_xmssmt_shake128_h60_3.c | 9 + .../xmss/sig_stfl_xmssmt_shake128_h60_6.c | 9 + 36 files changed, 412 insertions(+), 233 deletions(-) delete mode 100644 src/sig_stfl/xmss/external/sign_params.h create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index 1a0831f39d..6ae6d1dde6 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -7,7 +7,6 @@ #include "sig_stfl_lms_wrap.h" #include "sig_stfl_lms.h" - // ======================== LMS-SHA256 H5/W1 ======================== // OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -104,11 +103,11 @@ void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk) { } /* Convert LMS secret key object to byte string */ -size_t OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_buf) { - return oqs_serialize_lms_key(sk, sk_buf); +OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr) { + return oqs_serialize_lms_key(sk, sk_len, sk_buf_ptr); } /* Insert lms byte string in an LMS secret key object */ -OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf) { - return oqs_deserialize_lms_key(sk, key_len, sk_buf); +OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf) { + return oqs_deserialize_lms_key(sk, sk_len, sk_buf); } diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index ab32848ac8..76de39a6e3 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -15,15 +15,15 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); /* Convert LMS secret key object to byte string */ -size_t OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_buf); +OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); /* Insert lms byte string in an LMS secret key object */ -OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf); +OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t key_len, const uint8_t *sk_buf); OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(uint64_t *totaln, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *totaln, const OQS_SIG_STFL_SECRET_KEY *secret_key); void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); @@ -38,8 +38,8 @@ int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, const uint8_t *sm, si void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk); -size_t oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_key); -int oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf); +OQS_STATUS oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_key); +OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf); // ---------------------------- FUNCTIONS INDEPENDENT OF VARIANT ----------------------------------------- diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index da7f865c07..ea4f42d8af 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -1,6 +1,7 @@ // SPDX-License-Identifier: MIT #include +#include #include "sig_stfl_lms.h" #include "external/config.h" #include "external/hss_verify_inc.h" @@ -87,7 +88,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(uint64_t *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { if (total == NULL || secret_key == NULL) { return OQS_ERROR; @@ -378,42 +379,46 @@ void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk) { * Convert LMS secret key object to byte string * Writes secret key + aux data if present */ -size_t oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_key) { +OQS_STATUS oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_key) { - oqs_lms_key_data *lms_key_data = NULL; - size_t key_len = 0; - if (sk) { - uint8_t *sk_key_buf = NULL; - lms_key_data = sk->secret_key_data; - if (lms_key_data && lms_key_data->sec_key) { - size_t buf_size_needed = lms_key_data->len_aux_data + lms_key_data->len_sec_key; - key_len = buf_size_needed; - /* pass back serialized data */ - if (sk_key) { - if (buf_size_needed) { - sk_key_buf = malloc(buf_size_needed * sizeof(uint8_t)); - if (sk_key_buf) { - - /* - * Serialized data is sec_key followed by aux data - * So aux data begins after buffer top + sec_key length - */ - if (lms_key_data->len_sec_key) { - memcpy(sk_key_buf, lms_key_data->sec_key, lms_key_data->len_sec_key); - } - - if (lms_key_data->len_aux_data) { - memcpy(sk_key_buf + lms_key_data->len_sec_key, lms_key_data->aux_data, lms_key_data->len_aux_data); - } - - *sk_key = sk_key_buf; - key_len = sk->length_secret_key + lms_key_data->len_aux_data; - } - } - } //sk_key - } - } //sk - return key_len; + if (sk == NULL || sk_len == NULL || sk_key == NULL) { + return OQS_ERROR; + } + + oqs_lms_key_data *lms_key_data = sk->secret_key_data; + + if (lms_key_data == NULL || lms_key_data->sec_key == NULL) { + return OQS_ERROR; + } + + size_t key_len = lms_key_data->len_aux_data + lms_key_data->len_sec_key; + + if (key_len == 0) { + return OQS_ERROR; + } + + uint8_t *sk_key_buf = malloc(key_len * sizeof(uint8_t)); + + if (sk_key_buf == NULL) { + return OQS_ERROR; + } + /* pass back serialized data */ + /* + * Serialized data is sec_key followed by aux data + * So aux data begins after buffer top + sec_key length + */ + if (lms_key_data->len_sec_key != 0) { + memcpy(sk_key_buf, lms_key_data->sec_key, lms_key_data->len_sec_key); + } + + if (lms_key_data->len_aux_data != 0) { + memcpy(sk_key_buf + lms_key_data->len_sec_key, lms_key_data->aux_data, lms_key_data->len_aux_data); + } + + *sk_key = sk_key_buf; + *sk_len = sk->length_secret_key + lms_key_data->len_aux_data; + + return OQS_SUCCESS; } /* @@ -421,28 +426,27 @@ size_t oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_ke * Writes secret key + aux data if present * key_len is priv key length + aux length */ -int oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf) { - int oqs_status = -1; +OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf) { + oqs_lms_key_data *lms_key_data = NULL; - uint8_t priv_ky_len = hss_get_private_key_len((unsigned )(1), NULL, NULL); + uint8_t *lms_sk = NULL; + uint8_t *lms_aux = NULL; + int aux_buf_len = 0; + uint8_t lms_sk_len = hss_get_private_key_len((unsigned )(1), NULL, NULL); - if ((!sk) || (key_len == 0) || (key_len < priv_ky_len) || (!sk_buf)) { - return oqs_status; + if (sk == NULL || sk_buf == NULL || (sk_len == 0) || (sk_len < lms_sk_len )) { + return OQS_ERROR; } + aux_buf_len = sk_len - lms_sk_len; if (sk->secret_key_data) { - //Key data already present - //We dont want to trample over data - return oqs_status; + // Key data already present + // We dont want to trample over data + return OQS_ERROR; } - uint8_t *lms_sk = NULL; - uint8_t *lms_aux = NULL; - unsigned levels = 0; - int key_buf_left = key_len - priv_ky_len; - param_set_t lm_type[ MAX_HSS_LEVELS ]; param_set_t lm_ots_type[ MAX_HSS_LEVELS ]; @@ -452,36 +456,41 @@ int oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const u lm_ots_type, NULL, (void *)sk_buf)) { - return oqs_status; + return OQS_ERROR; } lms_key_data = malloc(sizeof(oqs_lms_key_data)); - if (lms_key_data) { - lms_sk = malloc(priv_ky_len * sizeof(uint8_t)); - if (lms_sk) { - memcpy(lms_sk, sk_buf, priv_ky_len); - lms_key_data->sec_key = lms_sk; - lms_key_data->len_sec_key = priv_ky_len; - } else { - OQS_MEM_insecure_free(lms_key_data); - return oqs_status; - } + lms_sk = malloc(lms_sk_len * sizeof(uint8_t)); - if (key_buf_left) { - lms_aux = malloc(key_buf_left * sizeof(uint8_t)); - if (lms_aux) { - memcpy(lms_aux, (sk_buf + priv_ky_len), key_buf_left); - lms_key_data->aux_data = lms_aux; - lms_key_data->len_aux_data = key_buf_left; - } else { - OQS_MEM_insecure_free(lms_key_data); - OQS_MEM_insecure_free(lms_sk); - return oqs_status; - } + if (lms_key_data == NULL || lms_sk == NULL) { + goto err; + } + + memcpy(lms_sk, sk_buf, lms_sk_len); + lms_key_data->sec_key = lms_sk; + lms_key_data->len_sec_key = lms_sk_len; + + if (aux_buf_len) { + lms_aux = malloc(aux_buf_len * sizeof(uint8_t)); + + if (lms_aux == NULL) { + goto err; } - sk->secret_key_data = lms_key_data; - oqs_status = 0; + memcpy(lms_aux, sk_buf + lms_sk_len, aux_buf_len); + lms_key_data->aux_data = lms_aux; + lms_key_data->len_aux_data = aux_buf_len; } - return oqs_status; + + sk->secret_key_data = lms_key_data; + goto success; + +err: + OQS_MEM_secure_free(lms_key_data, sizeof(oqs_lms_key_data)); + OQS_MEM_secure_free(lms_sk, lms_sk_len); + OQS_MEM_secure_free(lms_aux, aux_buf_len); + return OQS_ERROR; + +success: + return OQS_SUCCESS; } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index a3423a667b..eb1b4088d5 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -206,23 +206,23 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * Secret Key retrieval Function * * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object - * @param[out] sk_buf private key data as a byte stream + * @param[out] sk_len length of private key as a byte stream + * @param[out] sk_buf_ptr pointer to private key data as a byte stream * @returns length of key material data available * Caller deletes the buffer if memory was allocated. */ - size_t (*serialize_key)(const OQS_SIG_STFL_SECRET_KEY *sk, uint8_t **sk_buf); + OQS_STATUS (*serialize_key)(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); /** * set Secret Key to internal structure Function * - * @param[in] sk OQS_SIG_STFL_SECRET_KEY object - * @param[in] key_len length of the returned byte string - * @param[in] sk_key The secret key represented as OQS_SIG_STFL_SECRET_KEY object - * @param[in] key_len length of the returned byte string + * @param[out] sk OQS_SIG_STFL_SECRET_KEY object + * @param[in] sk_len length of the returned byte string + * @param[in] sk_buf The secret key represented as OQS_SIG_STFL_SECRET_KEY object * @returns status of the operation populated with key material none-zero length. Caller * deletes the buffer. if sk_buf is NULL the function returns the length */ - OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf); + OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf); /** * Secret Key Locking Function diff --git a/src/sig_stfl/xmss/CMakeLists.txt b/src/sig_stfl/xmss/CMakeLists.txt index b4b3038c69..1b55b20866 100644 --- a/src/sig_stfl/xmss/CMakeLists.txt +++ b/src/sig_stfl/xmss/CMakeLists.txt @@ -13,6 +13,9 @@ set(SRCS external/core_hash.c external/xmss_core_fast.c ) +add_library(sig_stfl_xmss_secret_key_functions OBJECT sig_stfl_xmss_secret_key_functions.c) +set(_XMSS_OBJS ${_XMSS_OBJS} $) + if (OQS_ENABLE_SIG_STFL_xmss_sha256_h10) add_library(xmss_sha256_h10 OBJECT sig_stfl_xmss_sha256_h10.c ${SRCS}) target_compile_options(xmss_sha256_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha256_h10 -DHASH=3) diff --git a/src/sig_stfl/xmss/external/sign_params.h b/src/sig_stfl/xmss/external/sign_params.h deleted file mode 100644 index d9dce53e42..0000000000 --- a/src/sig_stfl/xmss/external/sign_params.h +++ /dev/null @@ -1,142 +0,0 @@ -#ifndef NIST_PARAM_H -#define NIST_PARAM_H - -#include "params.h" -#include "xmss.h" - -#ifndef TREE_LEVEL -#define TREE_LEVEL 0 -#endif - -#ifndef XMSSMT -#define XMSSMT 0 -#endif - -#if XMSSMT == 0 - /* - * Maximum signatures: 2^h - 1 = 2^10 - 1 - */ - #if TREE_LEVEL == 0 - - #define XMSS_OID "XMSS-SHA2_10_256" - - #define XMSS_PUBLICKEYBYTES 64 - #define XMSS_SECRETKEYBYTES_SMALL 132 - #define XMSS_SECRETKEYBYTES 1373 - - #define XMSS_SIGNBYTES 2500 - - /* - * Maximum signatures: 2^h - 1 = 2^16 - 1 - */ - #elif TREE_LEVEL == 1 - - #define XMSS_OID "XMSS-SHA2_16_256" - - #define XMSS_PUBLICKEYBYTES 64 - #define XMSS_SECRETKEYBYTES_SMALL 132 - #define XMSS_SECRETKEYBYTES 2093 - - #define XMSS_SIGNBYTES 2692 - - /* - * Maximum signatures: 2^h - 1 = 2^20 - 1 - */ - #elif TREE_LEVEL == 2 - - #define XMSS_OID "XMSS-SHA2_20_256" - - #define XMSS_PUBLICKEYBYTES 64 - #define XMSS_SECRETKEYBYTES_SMALL 132 - #define XMSS_SECRETKEYBYTES 2573 - - #define XMSS_SIGNBYTES 2820 - - - #else - - #error "Unspecified TREE_LEVEL {0,1,2}" - - #endif -#else - /* - * Maximum signatures: 2^h - 1 = 2^20 - 1 - * XMSS^MT has bigger signature and secret key (secret is not transfer), but better speed - */ - #if TREE_LEVEL == 0 - - #define XMSS_OID "XMSSMT-SHA2_20/2_256" - - #define XMSS_PUBLICKEYBYTES 64 - #define XMSS_SECRETKEYBYTES_SMALL 131 - #define XMSS_SECRETKEYBYTES 5998 - - #define XMSS_SIGNBYTES 4963 - - /* - * Maximum signatures: 2^h - 1 = 2^40 - 1 - * XMSS^MT has bigger signature and secret key (secret is not transfer), but better speed - */ - #elif TREE_LEVEL == 1 - - #define XMSS_OID "XMSSMT-SHA2_40/2_256" - - #define XMSS_PUBLICKEYBYTES 64 - #define XMSS_SECRETKEYBYTES_SMALL 133 - #define XMSS_SECRETKEYBYTES 9600 - - #define XMSS_SIGNBYTES 5605 - - /* - * Maximum signatures: 2^h - 1 = 2^60 - 1 - * XMSS^MT has bigger signature and secret key (secret is not transfer), but better speed - */ - #elif TREE_LEVEL == 2 - - #define XMSS_OID "XMSSMT-SHA2_60/3_256" - - #define XMSS_PUBLICKEYBYTES 64 - #define XMSS_SECRETKEYBYTES_SMALL 136 - #define XMSS_SECRETKEYBYTES 16629 - - #define XMSS_SIGNBYTES 8392 - - - #else - - #error "Unspecified TREE_LEVEL {0,1,2}" - - #endif - -#endif - -#if XMSSMT == 1 - #define XMSS_PARSE_OID xmssmt_parse_oid - #define XMSS_STR_TO_OID xmssmt_str_to_oid - #define XMSS_KEYPAIR xmssmt_keypair - #define XMSS_SIGN xmssmt_sign - #define XMSS_SIGN_OPEN xmssmt_sign_open - #define XMSS_REMAINING_SIG xmssmt_remaining_signatures - #define XMSS_TOTAL_SIG xmssmt_total_signatures -#else - #define XMSS_PARSE_OID xmss_parse_oid - #define XMSS_STR_TO_OID xmss_str_to_oid - #define XMSS_KEYPAIR xmss_keypair - #define XMSS_SIGN xmss_sign - #define XMSS_SIGN_OPEN xmss_sign_open - #define XMSS_REMAINING_SIG xmss_remaining_signatures - #define XMSS_TOTAL_SIG xmss_total_signatures -#endif - -#if XMSS_SECRETKEYBYTES_SMALL_ENABLE -#define CRYPTO_SECRETKEYBYTES (XMSS_SECRETKEYBYTES_SMALL + XMSS_OID_LEN) -#define CRYPTO_ALGNAME XMSS_OID -#else -#define CRYPTO_SECRETKEYBYTES (XMSS_SECRETKEYBYTES + XMSS_OID_LEN) -#define CRYPTO_ALGNAME (XMSS_OID "_fast") -#endif - -#define CRYPTO_PUBLICKEYBYTES (XMSS_PUBLICKEYBYTES + XMSS_OID_LEN) -#define CRYPTO_BYTES XMSS_SIGNBYTES - -#endif diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index 1cf29900f3..d0f6ae6300 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -494,4 +494,13 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned l #endif +/* + * Secret key functions + */ +/* Serialize XMSS secret key data into a byte string */ +OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); + +/* Deserialize XMSS byte string into an XMSS secret key data */ +OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf); + #endif /* OQS_SIG_STFL_XMSS_H */ diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c new file mode 100644 index 0000000000..9f50754ed2 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -0,0 +1,48 @@ +// SPDX-License-Identifier: MIT + +#include +#include +#include "sig_stfl_xmss.h" + +/* Serialize XMSS secret key data into a byte string */ +OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr) { + if (sk == NULL || sk_len == NULL || sk_buf_ptr == NULL) { + return OQS_ERROR; + } + + uint8_t *sk_buf = malloc(sk->length_secret_key * sizeof(uint8_t)); + if (sk_buf == NULL) { + return OQS_ERROR; + } + + // Simply copy byte string of secret_key_data + memcpy(sk_buf, sk->secret_key_data, sk->length_secret_key); + + *sk_buf_ptr = sk_buf; + *sk_len = sk->length_secret_key; + + return OQS_SUCCESS; +} + +/* Deserialize XMSS byte string into an XMSS secret key data */ +OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf) { + if (sk == NULL || sk_buf == NULL || (sk_len != sk->length_secret_key)) { + return OQS_ERROR; + } + + if (sk->secret_key_data != NULL) { + // Key data already present + // We dont want to trample over data + return OQS_ERROR; + } + + // Assume key data is not present + sk->secret_key_data = malloc(sk_len); + if (sk->secret_key_data == NULL) { + return OQS_ERROR; + } + + memcpy(sk->secret_key_data, sk_buf, sk_len); + + return OQS_SUCCESS; +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index 4ff8f24e7d..83d3c4b275 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -56,8 +56,18 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } + memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index f467b67595..b3f72ef038 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index ab7a74410f..660f8c797c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index b38207c86b..735cd012f2 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index 050026311a..de64237cb1 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index b5084201fd..0917020588 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index ac43b57b3c..708981b3ac 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index 596939f155..e6381f0209 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index 37da02a13b..4b80a0c938 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index f0d27e2033..bdb3243bfc 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index 38cd5603a9..7b6b352720 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index ed1989876e..fa6c7cc060 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index 792d7a3559..60cb3dd8ad 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index 4a1d1cad52..cd698b3d44 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index 9bb9c61445..4b6d0a9021 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index 64a2da1331..c42a6db25f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index 13843351ee..c29b43d2d1 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index 06873a58db..7e53563c2d 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index 67183fee79..c1ed78f606 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index 8ab9134684..bc644a4223 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 279146a010..807eae702d 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 961fd8c0a7..1082dcd999 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index a72d9b7e67..01d70f3a37 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index 64c2f8cea3..d5935a5752 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index 7b1c137e8a..743ff4cb96 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index 41c4317ad9..c571bbe7ea 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index 5a38219f83..83ed6b0b63 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index 9c860051d7..a8c3ed07af 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -56,8 +56,17 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void) { sk->sigs_left = NULL; sk->sigs_total = NULL; + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + // Initialize the key with length_secret_key amount of bytes. sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } memset(sk->secret_key_data, 0, sk->length_secret_key); sk->free_key = OQS_SECRET_KEY_XMSS_free; From a85a9aa172647fa42fbc3cf63a477a691ecb68c5 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Fri, 22 Sep 2023 12:00:43 -0400 Subject: [PATCH 14/68] Stateful sigs secret key storage callback (#1553) * Callback implemention updating secret key. * Block XMSS from secret key tests until after support code has been added. * Remove / from test file names * Format * Address SA issues * Fix mem leak * Fix mem leak * Address various comments * Fix SA issue --- src/sig_stfl/lms/sig_stfl_lms.c | 24 +- src/sig_stfl/lms/sig_stfl_lms.h | 9 +- src/sig_stfl/lms/sig_stfl_lms_functions.c | 79 ++++- src/sig_stfl/sig_stfl.c | 33 ++ src/sig_stfl/sig_stfl.h | 58 +++- src/sig_stfl/xmss/sig_stfl_xmss.h | 2 +- .../xmss/sig_stfl_xmss_secret_key_functions.c | 8 +- tests/test_sig_stfl.c | 281 ++++++++++++++---- 8 files changed, 404 insertions(+), 90 deletions(-) diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index 6ae6d1dde6..582b50b3e4 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -7,6 +7,14 @@ #include "sig_stfl_lms_wrap.h" #include "sig_stfl_lms.h" +/* Convert LMS secret key object to byte string */ +static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); + +/* Insert lms byte string in an LMS secret key object */ +static OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); + +static void OQS_SECRET_KEY_LMS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); + // ======================== LMS-SHA256 H5/W1 ======================== // OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -88,13 +96,15 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void) { /* * Set Secret Key Saving Function */ - sk->save_secret_key = NULL; + sk->secure_store_scrt_key = NULL; /* * Set Secret Key free function */ sk->free_key = OQS_SECRET_KEY_LMS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + return sk; } @@ -103,11 +113,17 @@ void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk) { } /* Convert LMS secret key object to byte string */ -OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr) { +static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr) { return oqs_serialize_lms_key(sk, sk_len, sk_buf_ptr); } /* Insert lms byte string in an LMS secret key object */ -OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf) { - return oqs_deserialize_lms_key(sk, sk_len, sk_buf); +static OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context) { + return oqs_deserialize_lms_key(sk, sk_len, sk_buf, context); +} + +static void OQS_SECRET_KEY_LMS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { + if (sk && store_cb && context) { + oqs_lms_key_set_store_cb(sk, store_cb, context); + } } diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index 76de39a6e3..75ce739238 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -14,12 +14,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); -/* Convert LMS secret key object to byte string */ -OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); - -/* Insert lms byte string in an LMS secret key object */ -OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t key_len, const uint8_t *sk_buf); - OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -39,7 +33,8 @@ int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, const uint8_t *sm, si void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk); OQS_STATUS oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_key); -OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf); +OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); +void oqs_lms_key_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); // ---------------------------- FUNCTIONS INDEPENDENT OF VARIANT ----------------------------------------- diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index ea4f42d8af..d918cbdac4 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -40,25 +40,70 @@ typedef struct OQS_LMS_KEY_DATA { /* secret key data */ uint8_t *sec_key; + + /* app specific */ + void *context; } oqs_lms_key_data; OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signature_length, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || message == NULL || signature == NULL) { + OQS_STATUS rc_keyupdate = OQS_ERROR; + oqs_lms_key_data *lms_key_data = NULL; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf = NULL; + size_t sk_key_buf_len = 0; + void *context; + + if (secret_key == NULL || message == NULL || signature == NULL || signature_length == NULL) { return OQS_ERROR; } - /* TODO: Make sure we have a way to update the private key */ + /* + * Don't even attempt signing without a way to safe the updated private key + */ + if (secret_key->secure_store_scrt_key == NULL) { + goto err; + } + + lms_key_data = (oqs_lms_key_data *)secret_key->secret_key_data; + if (lms_key_data == NULL) { + goto err; + } if (oqs_sig_stfl_lms_sign(secret_key, signature, signature_length, message, message_len) != 0) { - return OQS_ERROR; + goto err; + } + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = oqs_serialize_lms_key(sk, &sk_key_buf_len, &sk_key_buf); + if (rc_keyupdate != OQS_SUCCESS) { + goto err; + } + + context = lms_key_data->context; + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf, sk_key_buf_len, context); + if (rc_keyupdate != OQS_SUCCESS) { + goto err; } - /* TODO: Update private key */ + OQS_MEM_secure_free(sk_key_buf, sk_key_buf_len); return OQS_SUCCESS; + +err: + OQS_MEM_secure_free(sk_key_buf, sk_key_buf_len); + if (*signature_length) { + memset(signature, 0, *signature_length); + } + *signature_length = 0; + return OQS_ERROR; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t message_len, @@ -356,11 +401,6 @@ void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk) { //TODO: cleanup lock_key - if (sk->sig) { - OQS_MEM_insecure_free(sk->sig); - sk->sig = NULL; - } - if (sk->secret_key_data) { oqs_lms_key_data *key_data = (oqs_lms_key_data *)sk->secret_key_data; if (key_data) { @@ -426,7 +466,7 @@ OQS_STATUS oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_l * Writes secret key + aux data if present * key_len is priv key length + aux length */ -OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf) { +OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context) { oqs_lms_key_data *lms_key_data = NULL; uint8_t *lms_sk = NULL; @@ -451,11 +491,11 @@ OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_ param_set_t lm_ots_type[ MAX_HSS_LEVELS ]; // validate sk_buf for lms params - if (hss_get_parameter_set(&levels, - lm_type, - lm_ots_type, - NULL, - (void *)sk_buf)) { + if (!hss_get_parameter_set(&levels, + lm_type, + lm_ots_type, + NULL, + (void *)sk_buf)) { return OQS_ERROR; } @@ -469,6 +509,7 @@ OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_ memcpy(lms_sk, sk_buf, lms_sk_len); lms_key_data->sec_key = lms_sk; lms_key_data->len_sec_key = lms_sk_len; + lms_key_data->context = context; if (aux_buf_len) { lms_aux = malloc(aux_buf_len * sizeof(uint8_t)); @@ -494,3 +535,11 @@ OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_ success: return OQS_SUCCESS; } + +void oqs_lms_key_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { + oqs_lms_key_data *lms_key_data = (oqs_lms_key_data *)sk->secret_key_data; + if (lms_key_data) { + lms_key_data->context = context; + sk->secure_store_scrt_key = store_cb; + } +} diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index c77139e20a..5480af5dd2 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -683,3 +683,36 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk) { } OQS_MEM_secure_free(sk, sizeof(sk)); } + +OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { + if (sk) { + if (sk->set_scrt_key_store_cb) { + sk->set_scrt_key_store_cb(sk, store_cb, context); + } + } +} + +/* Convert secret key object to byte string */ +OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf) { + if ((sk == NULL) || (sk_len == NULL) || (sk_buf == NULL)) { + return 0; + } + if (sk->serialize_key) { + return sk->serialize_key(sk, sk_len, sk_buf); + } else { + return 0; + } +} + +/* Insert secret key byte string in an Stateful secret key object */ +OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t key_len, const uint8_t *sk_buf, void *context) { + if ((sk == NULL) || (sk_buf == NULL)) { + return OQS_ERROR; + } + + if (sk->deserialize_key == NULL) { + return OQS_ERROR; + } + + return sk->deserialize_key(sk, key_len, sk_buf, context); +} diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index eb1b4088d5..1320ff02d3 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -61,6 +61,15 @@ extern "C" { typedef struct OQS_SIG_STFL_SECRET_KEY OQS_SIG_STFL_SECRET_KEY; +/** + * Application provided function to securely store data + * @param[in] sk_buf pointer to the data to be saved + * @param[in] buf_len length of the the data to be store + * @param[out] context pointer to application relevant data. + * @retrun OQS_SUCCESS if successful, otherwise OQS_ERROR + */ +typedef OQS_STATUS (*secure_store_sk)(/*const*/ uint8_t *sk_buf, size_t buf_len, void *context); + /** * Returns identifiers for available signature schemes in liboqs. Used with OQS_SIG_STFL_new. * @@ -216,13 +225,14 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /** * set Secret Key to internal structure Function * - * @param[out] sk OQS_SIG_STFL_SECRET_KEY object - * @param[in] sk_len length of the returned byte string - * @param[in] sk_buf The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @param[in] sk OQS_SIG_STFL_SECRET_KEY object + * @param[in] key_len length of the returned byte string + * @param[in] sk_buf The secret key data to populate key obj + * @param[in] context application specific data * @returns status of the operation populated with key material none-zero length. Caller * deletes the buffer. if sk_buf is NULL the function returns the length */ - OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf); + OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); /** * Secret Key Locking Function @@ -241,12 +251,16 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { OQS_STATUS (*unlock_key)(OQS_SIG_STFL_SECRET_KEY *sk); /** - * Secret Key Saving Function + * Store Secret Key Function + * Callback function used to securely store key data + * @param[in] sk_buf The serialized secret key data to secure store + * @param[in] buf_len length of data to secure + * @param[in] context aides the secure writing of data * - * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object * @return OQS_SUCCESS or OQS_ERROR + * Idealy written to secure device */ - OQS_STATUS (*save_secret_key)(const OQS_SIG_STFL_SECRET_KEY *sk); + OQS_STATUS (*secure_store_scrt_key)(/*const*/ uint8_t *sk_buf, size_t buf_len, void *context); /** * Secret Key free internal variant specific data @@ -255,6 +269,15 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * @return none */ void (*free_key)(OQS_SIG_STFL_SECRET_KEY *sk); + + /** + * Set Secret Key store callback Function + * + * @param[in] sk secret key pointer to be updated + * @param[in] store_cb callback pointer + * @param[in] context secret key specific data/identifier + */ + void (*set_scrt_key_store_cb)(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); } OQS_SIG_STFL_SECRET_KEY; /** @@ -281,7 +304,7 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name); * @param[out] secret_key The secret key represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ -OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk); +OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); /** * Signature generation algorithm. @@ -365,6 +388,25 @@ void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); */ OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk); + +/** + * OQS_SIG_STFL_SECRET_KEY_SET_store_cb . + * + * Can be called after creating a new stateful secret key has been generated. + * Allows the lib to securely store and update secret key after a sign operation. + * + * @param[in] sk secret key pointer to be updated + * @param[in] store_cb callback pointer + * @param[in] context secret key specific data/identifier + * + */ +void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); + +OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf); + +/* Insert lms byte string in an LMS secret key object */ +OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf, void *context); + #if defined(__cplusplus) } // extern "C" #endif diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index d0f6ae6300..54006043e1 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -501,6 +501,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned l OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); /* Deserialize XMSS byte string into an XMSS secret key data */ -OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf); +OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); #endif /* OQS_SIG_STFL_XMSS_H */ diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index 9f50754ed2..4a47c938c3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -4,6 +4,12 @@ #include #include "sig_stfl_xmss.h" +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + /* Serialize XMSS secret key data into a byte string */ OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr) { if (sk == NULL || sk_len == NULL || sk_buf_ptr == NULL) { @@ -25,7 +31,7 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, } /* Deserialize XMSS byte string into an XMSS secret key data */ -OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf) { +OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, XMSS_UNUSED_ATT void *context) { if (sk == NULL || sk_buf == NULL || (sk_len != sk->length_secret_key)) { return OQS_ERROR; } diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index b496457b99..0a0f08cd4b 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -10,6 +10,7 @@ #include #include +#include "tmp_store.c" #if OQS_USE_PTHREADS_IN_TESTS #include @@ -32,6 +33,25 @@ */ #define MAX_MARKER_LEN 50 +/* + * Write stateful secret keys to disk. + */ +static OQS_STATUS test_save_secret_key(uint8_t *key_buf, size_t buf_len, void *context) { + uint8_t *kb = key_buf; + + if (key_buf && context && buf_len != 0) { + if (oqs_fstore("sk", (const char *)context, kb, buf_len) == OQS_SUCCESS) { + printf("\n================================================================================\n"); + printf("Updated STFL SK <%s>.\n", (const char *)context); + printf("================================================================================\n"); + return OQS_SUCCESS; + } else { + return OQS_ERROR; + } + } + return OQS_ERROR; +} + // // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // @@ -126,6 +146,11 @@ int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { OQS_STATUS sig_stfl_keypair_from_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { OQS_STATUS rc; + + if ((sig == NULL) || (public_key == NULL) || (secret_key == NULL)) { + return OQS_ERROR; + } + rc = OQS_SIG_STFL_keypair(sig, public_key, secret_key); OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); if (rc != OQS_SUCCESS) { @@ -255,10 +280,20 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char OQS_SIG_STFL *sig = NULL; uint8_t *public_key = NULL; OQS_SIG_STFL_SECRET_KEY *secret_key = NULL; + const OQS_SIG_STFL_SECRET_KEY *sk = NULL; + OQS_SIG_STFL_SECRET_KEY *secret_key_rd = NULL; uint8_t *message = NULL; size_t message_len = 100; uint8_t *signature = NULL; size_t signature_len; + + uint8_t *sk_buf = NULL; + uint8_t *read_pk_buf = NULL; + char *context = NULL; + const char *file_store = NULL; + size_t sk_buf_len = 0; + size_t read_pk_len = 0; + OQS_STATUS rc, ret = OQS_ERROR; //The magic numbers are random values. @@ -277,6 +312,7 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char printf("================================================================================\n"); secret_key = OQS_SIG_STFL_SECRET_KEY_new(sig->method_name); + secret_key_rd = OQS_SIG_STFL_SECRET_KEY_new(sig->method_name); public_key = malloc(sig->length_public_key + 2 * sizeof(magic_t)); message = malloc(message_len + 2 * sizeof(magic_t)); signature = malloc(sig->length_signature + 2 * sizeof(magic_t)); @@ -307,12 +343,67 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char * Some keypair generation is fast, so we only read keypair from KATs for slow XMSS parameters */ rc = sig_stfl_KATs_keygen(sig, public_key, secret_key, katfile); + sk = secret_key; OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); if (rc != OQS_SUCCESS) { fprintf(stderr, "ERROR: OQS_SIG_STFL_keypair failed\n"); goto err; } + rc = OQS_SECRET_KEY_STFL_serialize_key(sk, &sk_buf_len, &sk_buf); + if (rc != OQS_SUCCESS) { + goto err; + } + + if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2) == 0) { + file_store = "XMSSMT-SHA2_20-2_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4) == 0) { + file_store = "XMSSMT-SHA2_20-4_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2) == 0) { + file_store = "XMSSMT-SHA2_40-2_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_4) == 0) { + file_store = "XMSSMT-SHA2_40-4_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_8) == 0) { + file_store = "XMSSMT-SHA2_40-8_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3) == 0) { + file_store = "XMSSMT-SHA2_60-3_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_6) == 0) { + file_store = "XMSSMT-SHA2_60-6_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_12) == 0) { + file_store = "XMSSMT-SHA2_60-12_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_2) == 0) { + file_store = "XMSSMT-SHAKE_20-2_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_4) == 0) { + file_store = "XMSSMT-SHAKE_20-4_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2) == 0) { + file_store = "XMSSMT-SHAKE_40-2_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_4) == 0) { + file_store = "XMSSMT-SHAKE_40-4_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_8) == 0) { + file_store = "XMSSMT-SHAKE_40-8_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3) == 0) { + file_store = "XMSSMT-SHAKE_60-3_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6) == 0) { + file_store = "XMSSMT-SHAKE_60-6_256"; + } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12) == 0) { + file_store = "XMSSMT-SHAKE_60-12_256"; + } else { + file_store = sig->method_name; + } + + /* write key pair to disk */ + if (oqs_fstore("sk", file_store, sk_buf, sk_buf_len) != OQS_SUCCESS) { + goto err; + } + + if (oqs_fstore("pk", file_store, public_key, sig->length_public_key) != OQS_SUCCESS) { + goto err; + } + + /* set context and secure store callback */ + context = strdup(((file_store))); + OQS_SIG_STFL_SECRET_KEY_SET_store_cb(secret_key, test_save_secret_key, (void *)context); + rc = OQS_SIG_STFL_sign(sig, signature, &signature_len, message, message_len, secret_key); OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); if (rc != OQS_SUCCESS) { @@ -329,6 +420,17 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char goto err; } + /* Read public key and re-test verify.*/ + read_pk_buf = malloc(sig->length_public_key); + if (oqs_fload("pk", file_store, read_pk_buf, sig->length_public_key, &read_pk_len) != OQS_SUCCESS) { + goto err; + } + rc = OQS_SIG_STFL_verify(sig, message, message_len, signature, signature_len, read_pk_buf); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: 2nd Verify with restored public key OQS_SIG_STFL_verify failed\n"); + } + /* modify the signature to invalidate it */ OQS_randombytes(signature, signature_len); OQS_TEST_CT_DECLASSIFY(signature, signature_len); @@ -362,6 +464,7 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char cleanup: OQS_SIG_STFL_SECRET_KEY_free(secret_key); + OQS_SIG_STFL_SECRET_KEY_free(secret_key_rd); if (public_key) { OQS_MEM_insecure_free(public_key - sizeof(magic_t)); } @@ -371,80 +474,97 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char if (signature) { OQS_MEM_insecure_free(signature - sizeof(magic_t)); } + OQS_MEM_secure_free(sk_buf, sk_buf_len); OQS_SIG_STFL_free(sig); + OQS_MEM_insecure_free(read_pk_buf); + OQS_MEM_insecure_free(context); return ret; } static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { OQS_STATUS rc = OQS_SUCCESS; OQS_SIG_STFL_SECRET_KEY *sk = NULL; + OQS_SIG_STFL_SECRET_KEY *sk_frm_file = NULL; OQS_SIG_STFL *sig_obj = NULL; uint8_t *public_key = NULL; + uint8_t *frm_file_sk_buf = NULL; + uint8_t *to_file_sk_buf = NULL; + size_t frm_file_sk_len = 0; + size_t to_file_sk_len = 0; + char *context = NULL; + char *context_2 = NULL; /* * Temporarily skip algs with long key generation times. */ - if (0) { - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { + if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) != 0) { goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { - goto skip_test; -#endif } else { goto keep_going; } + +// if (0) { +// +//#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 +// } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { +// goto skip_test; +//#endif +//#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 +// } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { +// goto skip_test; +//#endif +// +//#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { +// goto skip_test; +//#endif +//#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { +// goto skip_test; +//#endif +// +//#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { +// goto skip_test; +//#endif +//#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { +// goto skip_test; +//#endif +// +//#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { +// goto skip_test; +//#endif +//#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { +// goto skip_test; +//#endif +// +//#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { +// goto skip_test; +//#endif +//#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { +// goto skip_test; +//#endif +// +//#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { +// goto skip_test; +//#endif +//#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 +// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { +// goto skip_test; +//#endif +// } else { +// goto keep_going; +// } + skip_test: printf("Skip slow test %s.\n", method_name); return rc; @@ -479,12 +599,58 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { rc = OQS_SIG_STFL_keypair(sig_obj, public_key, sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key gen failed.\n"); + goto err; + } + + /* write sk key to disk */ + rc = OQS_SECRET_KEY_STFL_serialize_key(sk, &to_file_sk_len, &to_file_sk_buf); + if (rc != OQS_SUCCESS) { + goto err; + } + + if (oqs_fstore("sk", sig_obj->method_name, to_file_sk_buf, to_file_sk_len) != OQS_SUCCESS) { + goto err; + } + if (!sk->secret_key_data) { fprintf(stderr, "ERROR: OQS_SECRET_KEY_new incomplete.\n"); OQS_MEM_insecure_free(public_key); goto err; } + /* set context and secure store callback */ + if (sk->set_scrt_key_store_cb) { + context = strdup(((method_name))); + sk->set_scrt_key_store_cb(sk, test_save_secret_key, (void *)context); + } + + + /* read secret key from disk */ + frm_file_sk_buf = malloc(to_file_sk_len); + if (oqs_fload("sk", method_name, frm_file_sk_buf, to_file_sk_len, &frm_file_sk_len) != OQS_SUCCESS) { + goto err; + } + if (to_file_sk_len != frm_file_sk_len) { + fprintf(stderr, "ERROR: OQS_SECRET_KEY_new stored length not equal read length\n"); + goto err; + } + + sk_frm_file = OQS_SIG_STFL_SECRET_KEY_new(method_name); + if (sk_frm_file == NULL) { + fprintf(stderr, "ERROR: 2nd OQS_SECRET_KEY_new failed\n"); + goto err; + } + + context_2 = strdup(((method_name))); + rc = OQS_SECRET_KEY_STFL_deserialize_key(sk_frm_file, frm_file_sk_len, frm_file_sk_buf, (void *)context_2); + + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS restore %s from file failed.\n", method_name); + goto err; + } + printf("Secret Key created as expected.\n"); goto end_it; @@ -493,8 +659,14 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { end_it: OQS_SIG_STFL_SECRET_KEY_free(sk); + OQS_SIG_STFL_SECRET_KEY_free(sk_frm_file); + OQS_MEM_insecure_free(public_key); + OQS_MEM_secure_free(to_file_sk_buf, to_file_sk_len); + OQS_MEM_secure_free(frm_file_sk_buf, frm_file_sk_len); OQS_SIG_STFL_free(sig_obj); + OQS_MEM_insecure_free(context); + OQS_MEM_insecure_free(context_2); return rc; } @@ -531,6 +703,7 @@ void *test_wrapper(void *arg) { int main(int argc, char **argv) { OQS_init(); + oqs_fstore_init(); printf("Testing stateful signature algorithms using liboqs version %s\n", OQS_version()); From 3934949d260909e22cdf347cfc32e3231ea30214 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Thu, 28 Sep 2023 13:30:50 -0400 Subject: [PATCH 15/68] Na statful sig lock (#1559) * Add mutex protection around access to stateful secret key * Formatting. * Clean up warnings * Exclude XMSS from some tests temporarily * Remove commented code. * Document use of callback functions for secret key thread safe protection and storage. --- src/sig_stfl/lms/sig_stfl_lms.c | 12 +- src/sig_stfl/lms/sig_stfl_lms_functions.c | 31 +- src/sig_stfl/sig_stfl.c | 49 +++ src/sig_stfl/sig_stfl.h | 110 +++++- tests/test_sig_stfl.c | 386 +++++++++++++++++++++- 5 files changed, 572 insertions(+), 16 deletions(-) diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index 582b50b3e4..e6c30e66d5 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -114,7 +114,17 @@ void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk) { /* Convert LMS secret key object to byte string */ static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr) { - return oqs_serialize_lms_key(sk, sk_len, sk_buf_ptr); + OQS_STATUS status; + if (sk->lock_key && sk->mutex) { + sk->lock_key(sk->mutex); + } + + status = oqs_serialize_lms_key(sk, sk_len, sk_buf_ptr); + + if (sk->unlock_key && sk->mutex) { + sk->unlock_key(sk->mutex); + } + return status; } /* Insert lms byte string in an LMS secret key object */ diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index d918cbdac4..59265f3110 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -47,7 +47,7 @@ typedef struct OQS_LMS_KEY_DATA { OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signature_length, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - + OQS_STATUS status = OQS_ERROR; OQS_STATUS rc_keyupdate = OQS_ERROR; oqs_lms_key_data *lms_key_data = NULL; const OQS_SIG_STFL_SECRET_KEY *sk; @@ -59,6 +59,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu return OQS_ERROR; } + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + /* * Don't even attempt signing without a way to safe the updated private key */ @@ -94,16 +99,23 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu goto err; } - OQS_MEM_secure_free(sk_key_buf, sk_key_buf_len); - return OQS_SUCCESS; + status = OQS_SUCCESS; + goto passed; err: - OQS_MEM_secure_free(sk_key_buf, sk_key_buf_len); if (*signature_length) { memset(signature, 0, *signature_length); } *signature_length = 0; - return OQS_ERROR; + +passed: + OQS_MEM_secure_free(sk_key_buf, sk_key_buf_len); + + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t message_len, @@ -128,8 +140,17 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } + /* Lock secret key to ensure data integrity use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } remain = 0; + + /* Unlock secret key */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } return OQS_SUCCESS; } diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 5480af5dd2..023d4e1df3 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -716,3 +716,52 @@ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY * return sk->deserialize_key(sk, key_len, sk_buf, context); } + + + +/* OQS_SIG_STFL_SECRET_KEY_SET_lock callback function*/ +OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_lock(OQS_SIG_STFL_SECRET_KEY *sk, lock_key lock) { + if (sk == NULL) { + return; + } + sk->lock_key = lock; +} + +/* OQS_SIG_STFL_SECRET_KEY_SET_unlock callback function */ +OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_unlock(OQS_SIG_STFL_SECRET_KEY *sk, unlock_key unlock) { + if (sk == NULL) { + return; + } + sk->unlock_key = unlock; +} + +/* OQS_SIG_STFL_SECRET_KEY_SET_mutex */ +OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_mutex(OQS_SIG_STFL_SECRET_KEY *sk, void *mutex) { + if (sk == NULL) { + return; + } + sk->mutex = mutex; +} + +/* OQS_SIG_STFL_SECRET_KEY_lock */ +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return OQS_ERROR; + } + if (sk->lock_key == NULL) { + return OQS_SUCCESS; + } + + return (sk->lock_key(sk->mutex)); +} + +/* OQS_SIG_STFL_SECRET_KEY_unlock */ +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return OQS_ERROR; + } + if (sk->unlock_key == NULL) { + return OQS_SUCCESS; + } + return (sk->unlock_key(sk->mutex)); +} diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 1320ff02d3..a9bffdfdd8 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -16,6 +16,29 @@ #include +/* + * Developer's Notes: + * Stateful signatures are based on one-time use of a secret key. A pool of secret keys are created for this purpose. + * The state of these keys are tracked to ensure that they are used only once to generate a signature. + * + * As such, product specific environments do play a role in ensuring the safety of the keys. + * Secret keys must be store securely. + * The key index/counter must be updated after each signature generation. + * Secret key must be protected in a thread-save manner. + * + * Application therefore are required to provide environment specific callback functions to + * - store private key + * - lock/unlock private key + * + * See below for details + * OQS_SIG_STFL_SECRET_KEY_SET_lock + * OQS_SIG_STFL_SECRET_KEY_SET_unlock + * OQS_SIG_STFL_SECRET_KEY_SET_mutex + * OQS_SIG_STFL_SECRET_KEY_SET_store_cb + * + */ + + #if defined(__cplusplus) extern "C" { #endif @@ -66,9 +89,25 @@ typedef struct OQS_SIG_STFL_SECRET_KEY OQS_SIG_STFL_SECRET_KEY; * @param[in] sk_buf pointer to the data to be saved * @param[in] buf_len length of the the data to be store * @param[out] context pointer to application relevant data. - * @retrun OQS_SUCCESS if successful, otherwise OQS_ERROR + * return OQS_SUCCESS if successful, otherwise OQS_ERROR + */ +typedef OQS_STATUS (*secure_store_sk)(uint8_t *sk_buf, size_t buf_len, void *context); + +/** + * Application provided function to lock secret key object serialize access + * @param[in] sk pointer to secret key object to lock + * @param[in] mutex pointer to mutex struct + * return OQS_SUCCESS if successful, otherwise OQS_ERROR + */ +typedef OQS_STATUS (*lock_key)(void *mutex); + +/** + * Application provided function to unlock secret key object + * @param[in] sk pointer to secret key object to unlock + * @param[in] mutex pointer to mutex struct + * return OQS_SUCCESS if successful, otherwise OQS_ERROR */ -typedef OQS_STATUS (*secure_store_sk)(/*const*/ uint8_t *sk_buf, size_t buf_len, void *context); +typedef OQS_STATUS (*unlock_key)(void *mutex); /** * Returns identifiers for available signature schemes in liboqs. Used with OQS_SIG_STFL_new. @@ -205,6 +244,9 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /* The variant specific secret key data */ void *secret_key_data; + /* mutual exclusion struct */ + void *mutex; + /* Function that returns the total number of signatures for the secret key */ uint64_t (*sigs_total)(const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -237,18 +279,18 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /** * Secret Key Locking Function * - * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @param[in] mutex application defined mutex * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*lock_key)(OQS_SIG_STFL_SECRET_KEY *sk); + OQS_STATUS (*lock_key)(void *mutex); /** * Secret Key Unlocking / Releasing Function * - * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object + * @param[in] mutex application defined mutex * @return OQS_SUCCESS or OQS_ERROR */ - OQS_STATUS (*unlock_key)(OQS_SIG_STFL_SECRET_KEY *sk); + OQS_STATUS (*unlock_key)(void *mutex); /** * Store Secret Key Function @@ -260,7 +302,7 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * @return OQS_SUCCESS or OQS_ERROR * Idealy written to secure device */ - OQS_STATUS (*secure_store_scrt_key)(/*const*/ uint8_t *sk_buf, size_t buf_len, void *context); + OQS_STATUS (*secure_store_scrt_key)(uint8_t *sk_buf, size_t buf_len, void *context); /** * Secret Key free internal variant specific data @@ -388,6 +430,60 @@ void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); */ OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk); +/** + * OQS_SIG_STFL_SECRET_KEY_SET_lock . + * + * Sets function to prevent multiple processes from using the sk at the same time. + * + * @param[in] sk secret key pointer to be updated + * @param[in] lock function pointer + * + */ +void OQS_SIG_STFL_SECRET_KEY_SET_lock(OQS_SIG_STFL_SECRET_KEY *sk, lock_key lock); + +/** + * OQS_SIG_STFL_SECRET_KEY_SET_unlock . + * + * Sets function to prevent multiple processes from using the sk at the same time. + * + * @param[in] sk secret key pointer to be updated + * @param[in] unlock function pointer + * + */ +void OQS_SIG_STFL_SECRET_KEY_SET_unlock(OQS_SIG_STFL_SECRET_KEY *sk, unlock_key unlock); + +/** + * OQS_SIG_STFL_SECRET_KEY_SET_mutex . + * + * Sets function to prevent multiple processes from using the sk at the same time. + * + * @param[in] sk secret key pointer to be updated + * @param[in] mutex function pointer + * + */ +void OQS_SIG_STFL_SECRET_KEY_SET_mutex(OQS_SIG_STFL_SECRET_KEY *sk, void *mutex); + +/** + * OQS_SIG_STFL_SECRET_KEY_lock . + * + * Locks sk so only one application that holds the lock can access it. + * + * @param[in] sk secret key pointer to be locked + * @return OQS_SUCCESS if successful, or OQS_ERROR if the object fails to apply the lock + * + */ +OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk); + +/** + * OQS_SIG_STFL_SECRET_KEY_unlock . + * + * Unlocks the resouces so that th enext process can access it. + * + * @param[in] sk secret key pointer + * @return OQS_SUCCESS if successful, or OQS_ERROR if the object fails to release the lock + * + */ +OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); /** * OQS_SIG_STFL_SECRET_KEY_SET_store_cb . diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 0a0f08cd4b..8a3cb2252d 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -9,6 +9,9 @@ #include #include +#include +#include + #include #include "tmp_store.c" @@ -33,6 +36,18 @@ */ #define MAX_MARKER_LEN 50 +static OQS_SIG_STFL_SECRET_KEY *lock_test_sk = NULL; +static OQS_SIG_STFL *lock_test_sig_obj = NULL; +static uint8_t *lock_test_public_key = NULL; +static char *lock_test_context = NULL; +static uint8_t *signature_1 = NULL; +static uint8_t *signature_2 = NULL; +static size_t signature_len_1; +static size_t signature_len_2; +static uint8_t message_1[] = "The quick brown fox ..."; +static uint8_t message_2[] = "The quick brown fox jumped from the tree."; +static pthread_mutex_t *test_sk_lock = NULL; + /* * Write stateful secret keys to disk. */ @@ -52,6 +67,38 @@ static OQS_STATUS test_save_secret_key(uint8_t *key_buf, size_t buf_len, void *c return OQS_ERROR; } +#if OQS_USE_PTHREADS_IN_TESTS +static OQS_STATUS lock_sk_key(void *mutex) { + if (mutex == NULL) { + return OQS_ERROR; + } + + if (!(pthread_mutex_lock((pthread_mutex_t *)mutex))) { + return OQS_SUCCESS; + } + return OQS_ERROR; +} + +static OQS_STATUS unlock_sk_key(void *mutex) { + if (mutex == NULL) { + return OQS_ERROR; + } + + if (!(pthread_mutex_unlock((pthread_mutex_t *)mutex))) { + return OQS_SUCCESS; + } + return OQS_ERROR; +} +#else +static OQS_STATUS lock_sk_key(void *mutex) { + return sk != NULL ? OQS_SUCCESS : OQS_ERROR; +} + +static OQS_STATUS unlock_sk_key(void *mutex) { + return sk != NULL ? OQS_SUCCESS : OQS_ERROR; +} +#endif + // // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // @@ -294,6 +341,10 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char size_t sk_buf_len = 0; size_t read_pk_len = 0; +#if OQS_USE_PTHREADS_IN_TESTS + pthread_mutex_t *sk_lock = NULL; +#endif + OQS_STATUS rc, ret = OQS_ERROR; //The magic numbers are random values. @@ -313,6 +364,21 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char secret_key = OQS_SIG_STFL_SECRET_KEY_new(sig->method_name); secret_key_rd = OQS_SIG_STFL_SECRET_KEY_new(sig->method_name); + + OQS_SIG_STFL_SECRET_KEY_SET_lock(secret_key, lock_sk_key); + OQS_SIG_STFL_SECRET_KEY_SET_unlock(secret_key, unlock_sk_key); + +#if OQS_USE_PTHREADS_IN_TESTS + sk_lock = (pthread_mutex_t *)malloc(sizeof(pthread_mutex_t)); + if (sk_lock == NULL) { + goto err; + } + + if (0 != pthread_mutex_init(sk_lock, 0)) { + goto err; + } + OQS_SIG_STFL_SECRET_KEY_SET_mutex(secret_key, sk_lock); +#endif public_key = malloc(sig->length_public_key + 2 * sizeof(magic_t)); message = malloc(message_len + 2 * sizeof(magic_t)); signature = malloc(sig->length_signature + 2 * sizeof(magic_t)); @@ -479,6 +545,13 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char OQS_MEM_insecure_free(read_pk_buf); OQS_MEM_insecure_free(context); + +#if OQS_USE_PTHREADS_IN_TESTS + if (sk_lock) { + pthread_mutex_destroy(sk_lock); + OQS_MEM_insecure_free(sk_lock); + } +#endif return ret; } @@ -616,7 +689,6 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { if (!sk->secret_key_data) { fprintf(stderr, "ERROR: OQS_SECRET_KEY_new incomplete.\n"); - OQS_MEM_insecure_free(public_key); goto err; } @@ -670,10 +742,240 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { return rc; } +static OQS_STATUS sig_stfl_test_query_key(const char *method_name) { + OQS_STATUS rc = OQS_SUCCESS; + + size_t message_len_1 = sizeof(message_1); + size_t message_len_2 = sizeof(message_2); + + /* + * Temporarily skip algs with long key generation times. + */ + + if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) != 0) { + goto skip_test; + } else { + goto keep_going; + } + +skip_test: + printf("Skip slow alg %s.\n", method_name); + return rc; + +keep_going: + + printf("================================================================================\n"); + printf("Testing stateful Signature Verification %s\n", method_name); + printf("================================================================================\n"); + + if ( lock_test_sk == NULL || lock_test_sig_obj == NULL || signature_1 == NULL + || signature_2 == NULL || lock_test_public_key == NULL) { + return OQS_ERROR; + } + + + printf("================================================================================\n"); + printf("Sig Verify 1 %s\n", method_name); + printf("================================================================================\n"); + + rc = OQS_SIG_STFL_verify(lock_test_sig_obj, message_1, message_len_1, signature_1, signature_len_1, lock_test_public_key); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: lock thread test OQS_SIG_STFL_verify failed\n"); + goto err; + } + + printf("================================================================================\n"); + printf("Sig Verify 2 %s\n", method_name); + printf("================================================================================\n"); + + rc = OQS_SIG_STFL_verify(lock_test_sig_obj, message_2, message_len_2, signature_2, signature_len_2, lock_test_public_key); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: lock thread test OQS_SIG_STFL_verify failed\n"); + goto err; + } + rc = OQS_SUCCESS; + printf("================================================================================\n"); + printf("Stateful Signature Verification %s Passed.\n", method_name); + printf("================================================================================\n"); + goto end_it; +err: + rc = OQS_ERROR; +end_it: + + return rc; +} + +static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { + OQS_STATUS rc = OQS_SUCCESS; + size_t message_len_1 = sizeof(message_1); + size_t message_len_2 = sizeof(message_2); + + /* + * Temporarily skip algs with long key generation times. + */ + + if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) != 0) { + goto skip_test; + } else { + goto keep_going; + } + +skip_test: + printf("Skip slow alg %s.\n", method_name); + return rc; + +keep_going: + + printf("================================================================================\n"); + printf("Testing stateful Signature Generation %s\n", method_name); + printf("================================================================================\n"); + + if ( lock_test_sk == NULL || lock_test_sig_obj == NULL) { + return OQS_ERROR; + } + + + printf("================================================================================\n"); + printf("Sig Gen 1 %s\n", method_name); + printf("================================================================================\n"); + + signature_1 = malloc(lock_test_sig_obj->length_signature); + + rc = OQS_SIG_STFL_sign(lock_test_sig_obj, signature_1, &signature_len_1, message_1, message_len_1, lock_test_sk); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: lock thread test OQS_SIG_STFL_sign failed\n"); + goto err; + } + + sleep(3); + + printf("================================================================================\n"); + printf("Sig Gen 2 %s\n", method_name); + printf("================================================================================\n"); + + signature_2 = malloc(lock_test_sig_obj->length_signature); + + rc = OQS_SIG_STFL_sign(lock_test_sig_obj, signature_2, &signature_len_2, message_2, message_len_2, lock_test_sk); + OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: lock thread test OQS_SIG_STFL_sign failed\n"); + goto err; + } + rc = OQS_SUCCESS; + printf("================================================================================\n"); + printf("Stateful Key Gen %s Passed.\n", method_name); + printf("================================================================================\n"); + goto end_it; +err: + rc = OQS_ERROR; +end_it: + + return rc; +} + + +static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { + OQS_STATUS rc = OQS_SUCCESS; + + /* + * Temporarily skip algs with long key generation times. + */ + + if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) != 0) { + goto skip_test; + } else { + goto keep_going; + } + +skip_test: + printf("Skip slow test %s.\n", method_name); + return rc; + +keep_going: + + printf("================================================================================\n"); + printf("Testing stateful Signature locks %s\n", method_name); + printf("================================================================================\n"); + + printf("================================================================================\n"); + printf("Create stateful Signature %s\n", method_name); + printf("================================================================================\n"); + + lock_test_sig_obj = OQS_SIG_STFL_new(method_name); + if (lock_test_sig_obj == NULL) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_new failed\n"); + goto err; + } + + lock_test_public_key = malloc(lock_test_sig_obj->length_public_key * sizeof(uint8_t)); + + printf("================================================================================\n"); + printf("Create stateful Secret Key %s\n", method_name); + printf("================================================================================\n"); + + lock_test_sk = OQS_SIG_STFL_SECRET_KEY_new(method_name); + if (lock_test_sk == NULL) { + fprintf(stderr, "ERROR: OQS_SECRET_KEY_new failed\n"); + goto err; + } + + OQS_SIG_STFL_SECRET_KEY_SET_lock(lock_test_sk, lock_sk_key); + OQS_SIG_STFL_SECRET_KEY_SET_unlock(lock_test_sk, unlock_sk_key); + +#if OQS_USE_PTHREADS_IN_TESTS + + test_sk_lock = (pthread_mutex_t *)malloc(sizeof(pthread_mutex_t)); + if (test_sk_lock == NULL) { + goto err; + } + + if (0 != pthread_mutex_init(test_sk_lock, 0)) { + goto err; + } + OQS_SIG_STFL_SECRET_KEY_SET_mutex(lock_test_sk, test_sk_lock); +#endif + + printf("================================================================================\n"); + printf("Generate keypair %s\n", method_name); + printf("================================================================================\n"); + + rc = OQS_SIG_STFL_keypair(lock_test_sig_obj, lock_test_public_key, lock_test_sk); + + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key gen failed.\n"); + goto err; + } + + + + if (!lock_test_sk->secret_key_data) { + fprintf(stderr, "ERROR: OQS_SECRET_KEY_new incomplete.\n"); + goto err; + } + + /* set context and secure store callback */ + if (lock_test_sk->set_scrt_key_store_cb) { + lock_test_context = strdup(((method_name))); + lock_test_sk->set_scrt_key_store_cb(lock_test_sk, test_save_secret_key, (void *)lock_test_context); + } + + printf("Test Secret Key Creator Thread created Stateful Signature and Secret Key objects.\n"); + goto end_it; + +err: + rc = OQS_ERROR; +end_it: + return rc; +} + #ifdef OQS_ENABLE_TEST_CONSTANT_TIME static void TEST_SIG_STFL_randombytes(uint8_t *random_array, size_t bytes_to_read) { // We can't make direct calls to the system randombytes on some platforms, // so we have to swap out the OQS_randombytes provider. + OQS_randombytes_switch_algorithm("system"); OQS_randombytes(random_array, bytes_to_read); OQS_randombytes_custom_algorithm(&TEST_SIG_STFL_randombytes); @@ -693,6 +995,35 @@ struct thread_data { OQS_STATUS rc1; }; +struct lock_test_data { + const char *alg_name; + OQS_STATUS rc; +}; + +void *test_query_key(void *arg) { + struct lock_test_data *td = arg; + printf("\n%s: Start Query Stateful Key info\n", __FUNCTION__); + td->rc = sig_stfl_test_query_key(td->alg_name); + printf("%s: End Query Stateful Key info\n\n", __FUNCTION__); + return NULL; +} + +void *test_sig_gen(void *arg) { + struct lock_test_data *td = arg; + printf("\n%s: Start Generate Stateful Signature\n", __FUNCTION__); + td->rc = sig_stfl_test_sig_gen(td->alg_name); + printf("%s: End Generate Stateful Signature\n\n", __FUNCTION__); + return NULL; +} + +void *test_create_keys(void *arg) { + struct lock_test_data *td = arg; + printf("\n%s: Start Generate Keys\n", __FUNCTION__); + td->rc = sig_stfl_test_secret_key_lock(td->alg_name); + printf("%s: End Generate Stateful Keys\n\n", __FUNCTION__); + return NULL; +} + void *test_wrapper(void *arg) { struct thread_data *td = arg; td->rc = sig_stfl_test_correctness(td->alg_name, td->katfile); @@ -737,13 +1068,26 @@ int main(int argc, char **argv) { OQS_randombytes_switch_algorithm("system"); #endif - OQS_STATUS rc, rc1; + OQS_STATUS rc, rc1, rc_lck, rc_sig, rc_qry; #if OQS_USE_PTHREADS_IN_TESTS #define MAX_LEN_SIG_NAME_ 64 + pthread_t thread; + pthread_t create_key_thread; + pthread_t sign_key_thread; + pthread_t query_key_thread; struct thread_data td; td.alg_name = alg_name; td.katfile = katfile; + + struct lock_test_data td_create; + struct lock_test_data td_sign; + struct lock_test_data td_query; + td_create.alg_name = alg_name; + td_sign.alg_name = alg_name; + td_query.alg_name = alg_name; + + int trc = pthread_create(&thread, NULL, test_wrapper, &td); if (trc) { fprintf(stderr, "ERROR: Creating pthread\n"); @@ -753,11 +1097,47 @@ int main(int argc, char **argv) { pthread_join(thread, NULL); rc = td.rc; rc1 = td.rc1; + + int trc_2 = pthread_create(&create_key_thread, NULL, test_create_keys, &td_create); + if (trc_2) { + fprintf(stderr, "ERROR: Creating pthread for stateful key gen test\n"); + OQS_destroy(); + return EXIT_FAILURE; + } + pthread_join(create_key_thread, NULL); + rc_lck = td_create.rc; + + int trc_3 = pthread_create(&sign_key_thread, NULL, test_sig_gen, &td_sign); + if (trc_3) { + fprintf(stderr, "ERROR: Creating pthread for sig gen test\n"); + OQS_destroy(); + return EXIT_FAILURE; + } + pthread_join(sign_key_thread, NULL); + rc_sig = td_sign.rc; + + int trc_4 = pthread_create(&query_key_thread, NULL, test_query_key, &td_query); + if (trc_4) { + fprintf(stderr, "ERROR: Creating pthread for query key test.\n"); + OQS_destroy(); + return EXIT_FAILURE; + } + pthread_join(query_key_thread, NULL); + rc_qry = td_query.rc; #else rc = sig_stfl_test_correctness(alg_name, katfile); rc1 = sig_stfl_test_secret_key(alg_name); #endif - if ((rc != OQS_SUCCESS) || (rc1 != OQS_SUCCESS)) { + + OQS_SIG_STFL_SECRET_KEY_free(lock_test_sk); + OQS_MEM_insecure_free(lock_test_public_key); + OQS_SIG_STFL_free(lock_test_sig_obj); + OQS_MEM_insecure_free(lock_test_context); + OQS_MEM_insecure_free(signature_1); + OQS_MEM_insecure_free(signature_2); + + if ((rc != OQS_SUCCESS) || (rc1 != OQS_SUCCESS) || (rc_lck != OQS_SUCCESS) || (rc_sig != OQS_SUCCESS) + || (rc_qry != OQS_SUCCESS)) { OQS_destroy(); return EXIT_FAILURE; } From 3db6b44f775fdb57440678c42153c57660ad50c1 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Thu, 5 Oct 2023 14:19:13 -0400 Subject: [PATCH 16/68] Secret Key Query (#1572) * Added functions to query the total, as well as, the remaining numbers of signing operation for a given secret key. * Cleanup unused variable * Fix code style --- src/sig_stfl/lms/sig_stfl_lms_functions.c | 61 +++++++++++++++--- tests/test_sig_stfl.c | 77 ++++++++++++++++++++++- 2 files changed, 128 insertions(+), 10 deletions(-) diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index 59265f3110..018b04b21e 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -7,8 +7,9 @@ #include "external/hss_verify_inc.h" #include "external/hss_sign_inc.h" #include "external/hss.h" +#include "external/endian.h" +#include "external/hss_internal.h" #include "sig_stfl_lms_wrap.h" -#include #define DEFAULT_AUX_DATA 10916 /* Use 10+k of aux data (which works well */ /* with the above default parameter set) */ @@ -136,17 +137,39 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t me } OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS status; + uint8_t *priv_key = NULL; + unsigned long long total_sigs = 0; + sequence_t current_count = 0; + oqs_lms_key_data *oqs_key_data = NULL; if (remain == NULL || secret_key == NULL) { return OQS_ERROR; } + + status = OQS_SIG_STFL_lms_sigs_total(&total_sigs, secret_key); + if (status != OQS_SUCCESS) { + return OQS_ERROR; + } + /* Lock secret key to ensure data integrity use */ if ((secret_key->lock_key) && (secret_key->mutex)) { secret_key->lock_key(secret_key->mutex); } - remain = 0; + oqs_key_data = secret_key->secret_key_data; + if (oqs_key_data == NULL) { + goto err; + } + priv_key = oqs_key_data->sec_key; + if (priv_key == NULL) { + goto err; + } + + current_count = get_bigendian(priv_key + PRIVATE_KEY_INDEX, PRIVATE_KEY_INDEX_LEN /*0, 8 */); + *remain = (total_sigs - (unsigned long long)current_count); +err: /* Unlock secret key */ if ((secret_key->unlock_key) && (secret_key->mutex)) { secret_key->unlock_key(secret_key->mutex); @@ -156,11 +179,38 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + uint8_t *priv_key = NULL; + oqs_lms_key_data *oqs_key_data = NULL; + struct hss_working_key *working_key = NULL; + + if (total == NULL || secret_key == NULL) { return OQS_ERROR; } - total = 0; + oqs_key_data = secret_key->secret_key_data; + if (!oqs_key_data) { + return OQS_ERROR; + } + + priv_key = oqs_key_data->sec_key; + if (!priv_key) { + return OQS_ERROR; + } + + working_key = hss_load_private_key(NULL, priv_key, + 0, + NULL, + 0, + 0); + if (!working_key) { + return OQS_ERROR; + } + + + + *total = (unsigned long long)working_key->max_count; + OQS_MEM_secure_free(working_key, sizeof(struct hss_working_key)); return OQS_SUCCESS; } @@ -293,7 +343,7 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uin memcpy(pk, oqs_key_data->public_key, len_public_key); sk->secret_key_data = oqs_key_data; } else { - OQS_MEM_insecure_free(oqs_key_data->sec_key); + OQS_MEM_secure_free(oqs_key_data->sec_key, sk->length_secret_key * sizeof(uint8_t)); OQS_MEM_insecure_free(oqs_key_data->aux_data); OQS_MEM_insecure_free(oqs_key_data); oqs_key_data = NULL; @@ -329,7 +379,6 @@ int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, 0, 0); if (!w) { - printf( "Error loading private key\n" ); hss_free_working_key(w); return 0; } @@ -340,14 +389,12 @@ int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, sig_len = hss_get_signature_len_from_working_key(w); if (sig_len == 0) { - printf( "Error getting signature len\n" ); hss_free_working_key(w); return 0; } sig = malloc(sig_len); if (!sig) { - printf( "Error during malloc\n" ); hss_free_working_key(w); return -1; } diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 8a3cb2252d..2f2b176016 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -559,7 +559,7 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { OQS_STATUS rc = OQS_SUCCESS; OQS_SIG_STFL_SECRET_KEY *sk = NULL; OQS_SIG_STFL_SECRET_KEY *sk_frm_file = NULL; - + unsigned long long num_sig_left = 0, max_num_sigs = 0; OQS_SIG_STFL *sig_obj = NULL; uint8_t *public_key = NULL; uint8_t *frm_file_sk_buf = NULL; @@ -677,6 +677,23 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { goto err; } + /* + * Get max num signature and the amount remaining + */ + rc = OQS_SIG_STFL_sigs_total((const OQS_SIG_STFL *)sig_obj, &max_num_sigs, (const OQS_SIG_STFL_SECRET_KEY *)sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key: Failed to get max number of sig from %s.\n", method_name); + goto err; + } + printf("%s Maximum num of sign operations = %llu\n", method_name, max_num_sigs); + + rc = OQS_SIG_STFL_sigs_remaining((const OQS_SIG_STFL *)sig_obj, &num_sig_left, (const OQS_SIG_STFL_SECRET_KEY *)sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key: Failed to get the remaining number of sig from %s.\n", method_name); + goto err; + } + printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); + /* write sk key to disk */ rc = OQS_SECRET_KEY_STFL_serialize_key(sk, &to_file_sk_len, &to_file_sk_buf); if (rc != OQS_SUCCESS) { @@ -837,6 +854,25 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { } + /* + * Get max num signature and the amount remaining + */ + unsigned long long num_sig_left = 0, max_num_sigs = 0; + rc = OQS_SIG_STFL_sigs_total((const OQS_SIG_STFL *)lock_test_sig_obj, &max_num_sigs, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key: Failed to get max number of sig from %s.\n", method_name); + goto err; + } + printf("%s Maximum num of sign operations = %llu\n", method_name, max_num_sigs); + + rc = OQS_SIG_STFL_sigs_remaining((const OQS_SIG_STFL *)lock_test_sig_obj, &num_sig_left, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key: Failed to get the remaining number of sig from %s.\n", method_name); + goto err; + } + printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); + + printf("================================================================================\n"); printf("Sig Gen 1 %s\n", method_name); printf("================================================================================\n"); @@ -850,7 +886,23 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { goto err; } - sleep(3); + /* + * Get max num signature and the amount remaining + */ + num_sig_left = 0, max_num_sigs = 0; + rc = OQS_SIG_STFL_sigs_total((const OQS_SIG_STFL *)lock_test_sig_obj, &max_num_sigs, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key: Failed to get max number of sig from %s.\n", method_name); + goto err; + } + printf("%s Maximum num of sign operations = %llu\n", method_name, max_num_sigs); + + rc = OQS_SIG_STFL_sigs_remaining((const OQS_SIG_STFL *)lock_test_sig_obj, &num_sig_left, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key: Failed to get the remaining number of sig from %s.\n", method_name); + goto err; + } + printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); printf("================================================================================\n"); printf("Sig Gen 2 %s\n", method_name); @@ -864,10 +916,29 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { fprintf(stderr, "ERROR: lock thread test OQS_SIG_STFL_sign failed\n"); goto err; } - rc = OQS_SUCCESS; + printf("================================================================================\n"); printf("Stateful Key Gen %s Passed.\n", method_name); printf("================================================================================\n"); + + /* + * Get max num signature and the amount remaining + */ + num_sig_left = 0, max_num_sigs = 0; + rc = OQS_SIG_STFL_sigs_total((const OQS_SIG_STFL *)lock_test_sig_obj, &max_num_sigs, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key: Failed to get max number of sig from %s.\n", method_name); + goto err; + } + printf("%s Maximum num of sign operations = %llu\n", method_name, max_num_sigs); + + rc = OQS_SIG_STFL_sigs_remaining((const OQS_SIG_STFL *)lock_test_sig_obj, &num_sig_left, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "OQS STFL key: Failed to get the remaining number of sig from %s.\n", method_name); + goto err; + } + printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); + goto end_it; err: rc = OQS_ERROR; From 2446c64b3fd067452f6d07d283a660ac9af7b2cd Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Tue, 10 Oct 2023 12:21:19 -0400 Subject: [PATCH 17/68] Na stateful sigs lms var (#1574) * Added new LMS varients. Removed unneeded vector functions from secret key data struc. * Add LMS variants * Fix formatting --- src/sig_stfl/lms/sig_stfl_lms.c | 1659 ++++++++++++++++- src/sig_stfl/lms/sig_stfl_lms.h | 183 +- src/sig_stfl/lms/sig_stfl_lms_functions.c | 87 +- src/sig_stfl/sig_stfl.c | 180 +- src/sig_stfl/sig_stfl.h | 33 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 4 - src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 4 - src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 4 - src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 4 - src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 4 - src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 4 - .../xmss/sig_stfl_xmss_shake128_h10.c | 4 - .../xmss/sig_stfl_xmss_shake128_h16.c | 4 - .../xmss/sig_stfl_xmss_shake128_h20.c | 4 - .../xmss/sig_stfl_xmss_shake256_h10.c | 4 - .../xmss/sig_stfl_xmss_shake256_h16.c | 4 - .../xmss/sig_stfl_xmss_shake256_h20.c | 4 - .../xmss/sig_stfl_xmssmt_sha256_h20_2.c | 4 - .../xmss/sig_stfl_xmssmt_sha256_h20_4.c | 4 - .../xmss/sig_stfl_xmssmt_sha256_h40_2.c | 4 - .../xmss/sig_stfl_xmssmt_sha256_h40_4.c | 4 - .../xmss/sig_stfl_xmssmt_sha256_h40_8.c | 4 - .../xmss/sig_stfl_xmssmt_sha256_h60_12.c | 4 - .../xmss/sig_stfl_xmssmt_sha256_h60_3.c | 4 - .../xmss/sig_stfl_xmssmt_sha256_h60_6.c | 4 - .../xmss/sig_stfl_xmssmt_shake128_h20_2.c | 4 - .../xmss/sig_stfl_xmssmt_shake128_h20_4.c | 4 - .../xmss/sig_stfl_xmssmt_shake128_h40_2.c | 4 - .../xmss/sig_stfl_xmssmt_shake128_h40_4.c | 4 - .../xmss/sig_stfl_xmssmt_shake128_h40_8.c | 4 - .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 4 - .../xmss/sig_stfl_xmssmt_shake128_h60_3.c | 4 - .../xmss/sig_stfl_xmssmt_shake128_h60_6.c | 4 - tests/test_sig_stfl.c | 56 +- 34 files changed, 2132 insertions(+), 178 deletions(-) diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index e6c30e66d5..3503c7447b 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -22,7 +22,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)0x00000001) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h5_w1) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -36,7 +36,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = 0x00000001; + sig->oid = OQS_LMS_ID_sha256_n32_h5_w1; sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -67,11 +67,1658 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void) { // Initialize the key with length_secret_key amount of bytes. sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk; - /* Function that returns the total number of signatures for the secret key */ - sk->sigs_total = NULL; + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H5/W2 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h5_w2) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h5_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H5/W4 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h5_w4) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h5_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H5/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h5_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h5_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W1 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h10_w1) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h10_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w1_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W1_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W2 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h10_w2) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h10_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w2_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W4 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h10_w4) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h10_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w4_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h10_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h10_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H15/W1 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h15_w1) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h15_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w1_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W1_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H15/W2 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h15_w2) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h15_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w2_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H15/W4 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h15_w4) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h15_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w4_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H15/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h15_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h15_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H20/W1 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h20_w1) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h20_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w1_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W1_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H20/W2 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h20_w2) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h20_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w2_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H20/W4 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h20_w4) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h20_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w4_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H20/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h20_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h20_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H25/W1 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h25_w1) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h25_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h25_w1_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W1_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H25/W2 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h25_w2) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h25_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h25_w2_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H25/W4 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h25_w4) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h25_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h25_w4_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_sk; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - /* set Function to returns the number of signatures left for the secret key */ - sk->sigs_left = NULL; + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H25/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h25_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_n32_h25_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_pk; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_sk; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h25_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_sk; /* * Secret Key retrieval Function diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index 75ce739238..e42450fd15 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -5,16 +5,193 @@ #include +//OQS LMS parameter identifiers +/* Defined LM parameter sets */ +#define OQS_LMS_ID_sha256_n32_h5_w1 0x1 //"5/1" +#define OQS_LMS_ID_sha256_n32_h5_w2 0x2 //"5/2" +#define OQS_LMS_ID_sha256_n32_h5_w4 0x3 //"5/4" +#define OQS_LMS_ID_sha256_n32_h5_w8 0x4 //"5/8" + +#define OQS_LMS_ID_sha256_n32_h10_w1 0x5 //"10/1" +#define OQS_LMS_ID_sha256_n32_h10_w2 0x7 //"10/2" +#define OQS_LMS_ID_sha256_n32_h10_w4 0x8 //"10/4" +#define OQS_LMS_ID_sha256_n32_h10_w8 0x9 //"10/8" + +#define OQS_LMS_ID_sha256_n32_h15_w1 0xa //"15/1" +#define OQS_LMS_ID_sha256_n32_h15_w2 0xb //"15/2" +#define OQS_LMS_ID_sha256_n32_h15_w4 0xc//"15/4" +#define OQS_LMS_ID_sha256_n32_h15_w8 0xd //"15/8" + +#define OQS_LMS_ID_sha256_n32_h20_w1 0xe //"20/1" +#define OQS_LMS_ID_sha256_n32_h20_w2 0xf //"20/2" +#define OQS_LMS_ID_sha256_n32_h20_w4 0x10 //"20/4" +#define OQS_LMS_ID_sha256_n32_h20_w8 0x11 //"20/8" + +#define OQS_LMS_ID_sha256_n32_h25_w1 0x12 //"25/1" +#define OQS_LMS_ID_sha256_n32_h25_w2 0x13 //"25/2" +#define OQS_LMS_ID_sha256_n32_h25_w4 0x14 //"25/4" +#define OQS_LMS_ID_sha256_n32_h25_w8 0x15 //"25/8" + //H5 #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_signature 8688 #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk 64 - +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); +#define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_signature 4464 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_sk 64 +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + +#define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_signature 2352 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_sk 64 +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(void); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + +#define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_signature 1296 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_sk 64 +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(void); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(void); +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + +//H10 +// H10 W1 60 8848 64 +// H10 W2 60 4624 64 +// H10 W4 60 2512 64 +// H10 W8 60 1456 64 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_signature 8848 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W1_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_signature 4624 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_signature 2512 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_signature 1456 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(void); + +//H15 +// H15 W1 60 9008 64 +// H15 W2 60 4784 64 +// H15 W4 60 2672 64 +// H15 W8 60 1616 64 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_signature 9008 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W1_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_signature 4784 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W2_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_signature 2672 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W4_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_signature 1616 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(void); + +//H20 +// H20 W1 60 9168 64 +// H20 W2 60 4944 64 +// H20 W4 60 2832 64 +// H20 W8 60 1776 64 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_signature 9168 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W1_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_signature 4944 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W2_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_signature 2832 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W4_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_signature 1776 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(void); + +//H25 +// H25 W1 60 9328 64 +// H25 W2 60 5104 64 +// H25 W4 60 2992 64 +// H25 W8 60 1936 64 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_signature 9328 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_sk 64 -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W1_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_signature 5104 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W2_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_signature 2992 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W4_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(void); + +#define OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_signature 1936 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_pk 60 +#define OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_sk 64 + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *totaln, const OQS_SIG_STFL_SECRET_KEY *secret_key); diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index 018b04b21e..f18d8c445b 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -183,7 +183,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *total, const oqs_lms_key_data *oqs_key_data = NULL; struct hss_working_key *working_key = NULL; - if (total == NULL || secret_key == NULL) { return OQS_ERROR; } @@ -207,8 +206,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *total, const return OQS_ERROR; } - - *total = (unsigned long long)working_key->max_count; OQS_MEM_secure_free(working_key, sizeof(struct hss_working_key)); return OQS_SUCCESS; @@ -280,11 +277,91 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uin /* Set lms param set */ switch (oid) { - case 0x1: + case OQS_LMS_ID_sha256_n32_h5_w1: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; break; - default: + case OQS_LMS_ID_sha256_n32_h5_w2: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; + break; + case OQS_LMS_ID_sha256_n32_h5_w4: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; + break; + case OQS_LMS_ID_sha256_n32_h5_w8: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + break; + + case OQS_LMS_ID_sha256_n32_h10_w1: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; + break; + case OQS_LMS_ID_sha256_n32_h10_w2: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; + break; + case OQS_LMS_ID_sha256_n32_h10_w4: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; + break; + case OQS_LMS_ID_sha256_n32_h10_w8: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + break; + + case OQS_LMS_ID_sha256_n32_h15_w1: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; + break; + case OQS_LMS_ID_sha256_n32_h15_w2: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; + break; + case OQS_LMS_ID_sha256_n32_h15_w4: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; + break; + case OQS_LMS_ID_sha256_n32_h15_w8: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + break; + + case OQS_LMS_ID_sha256_n32_h20_w1: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; + break; + case OQS_LMS_ID_sha256_n32_h20_w2: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; + break; + case OQS_LMS_ID_sha256_n32_h20_w4: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; + break; + case OQS_LMS_ID_sha256_n32_h20_w8: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + break; + + case OQS_LMS_ID_sha256_n32_h25_w1: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H25; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; + break; + case OQS_LMS_ID_sha256_n32_h25_w2: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H25; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; + break; + case OQS_LMS_ID_sha256_n32_h25_w4: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H25; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; + break; + case OQS_LMS_ID_sha256_n32_h25_w8: + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H25; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + break; + oqs_key_data->lm_type[0] = 0; oqs_key_data->lm_ots_type[0] = 0; parse_err = 1; diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 023d4e1df3..b434f54715 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -43,6 +43,29 @@ OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { OQS_SIG_STFL_alg_xmssmt_shake128_h60_6, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1, + OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2, + OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4, + OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8, + + OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1, + OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2, + OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4, + OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8, + + OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1, + OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2, + OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4, + OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8, + + OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1, + OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2, + OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4, + OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8, + + OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1, + OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2, + OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4, + OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8, }; if (i >= OQS_SIG_STFL_algs_length) { @@ -52,12 +75,10 @@ OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { } } - OQS_API int OQS_SIG_STFL_alg_count(void) { return OQS_SIG_STFL_algs_length; } - OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name) { assert(method_name != NULL); @@ -231,18 +252,61 @@ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name) { #else return 0; #endif - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { + } #ifdef OQS_ENABLE_SIG_STFL_LMS + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { return 1; -#else - return 0; -#endif - } else { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8)) { + return 1; + } + + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8)) { + return 1; + } + + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8)) { + return 1; + } + + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8)) { + return 1; + } +#endif //OQS_ENABLE_SIG_STFL_LMS + else { return 0; } } - OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { assert(method_name != NULL); @@ -416,18 +480,55 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { #else return NULL; #endif - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { + } #ifdef OQS_ENABLE_SIG_STFL_LMS + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { return OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(); -#else - return NULL; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2)) { + return OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4)) { + return OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1)) { + return OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2)) { + return OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4)) { + return OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1)) { + return OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2)) { + return OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4)) { + return OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1)) { + return OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2)) { + return OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4)) { + return OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(); + } #endif //OQS_ENABLE_SIG_STFL_LMS - } else { + else { return NULL; } } - OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { if (sig == NULL || sig->keypair == NULL || sig->keypair(public_key, secret_key) != 0) { return OQS_ERROR; @@ -474,11 +575,8 @@ OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig) { OQS_MEM_insecure_free(sig); } - - // ================================= OQS_SIG_STFL_SECRET_KEY FUNCTION =============================================== - OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_name) { assert(method_name != NULL); @@ -652,13 +750,51 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_ #else return NULL; #endif - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { + } #ifdef OQS_ENABLE_SIG_STFL_LMS + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { return OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(); -#else - return NULL; -#endif - } else { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2)) { + return OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4)) { + return OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W1_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1)) { + return OQS_SECRET_KEY_LMS_SHA256_H15_W1_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2)) { + return OQS_SECRET_KEY_LMS_SHA256_H15_W2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4)) { + return OQS_SECRET_KEY_LMS_SHA256_H15_W4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H15_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1)) { + return OQS_SECRET_KEY_LMS_SHA256_H20_W1_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2)) { + return OQS_SECRET_KEY_LMS_SHA256_H20_W2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4)) { + return OQS_SECRET_KEY_LMS_SHA256_H20_W4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H20_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1)) { + return OQS_SECRET_KEY_LMS_SHA256_H25_W1_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2)) { + return OQS_SECRET_KEY_LMS_SHA256_H25_W2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4)) { + return OQS_SECRET_KEY_LMS_SHA256_H25_W4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(); + } +#endif //OQS_ENABLE_SIG_STFL_LMS + else { return NULL; } } @@ -717,8 +853,6 @@ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY * return sk->deserialize_key(sk, key_len, sk_buf, context); } - - /* OQS_SIG_STFL_SECRET_KEY_SET_lock callback function*/ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_lock(OQS_SIG_STFL_SECRET_KEY *sk, lock_key lock) { if (sk == NULL) { diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index a9bffdfdd8..33177e829e 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -38,7 +38,6 @@ * */ - #if defined(__cplusplus) extern "C" { #endif @@ -75,8 +74,31 @@ extern "C" { /* Defined LMS parameter identifiers */ #define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1 "LMS_SHA256_H5_W1" //"5/1" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2 "LMS_SHA256_H5_W2" //"5/2" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4 "LMS_SHA256_H5_W4" //"5/4" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8 "LMS_SHA256_H5_W8" //"5/8" + +#define OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1 "LMS_SHA256_H10_W1" //"10/1" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2 "LMS_SHA256_H10_W2" //"10/2" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4 "LMS_SHA256_H10_W4" //"10/4" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8 "LMS_SHA256_H10_W8" //"10/8" + +#define OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1 "LMS_SHA256_H15_W1" //"15/1" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2 "LMS_SHA256_H15_W2" //"15/2" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4 "LMS_SHA256_H15_W4" //"15/4" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8 "LMS_SHA256_H15_W8" //"15/8" + +#define OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1 "LMS_SHA256_H20_W1" //"20/1" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2 "LMS_SHA256_H20_W2" //"20/2" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4 "LMS_SHA256_H20_W4" //"20/4" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8 "LMS_SHA256_H20_W8" //"20/8" -#define OQS_SIG_STFL_algs_length 29 +#define OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1 "LMS_SHA256_H25_W1" //"25/1" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2 "LMS_SHA256_H25_W2" //"25/2" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4 "LMS_SHA256_H25_W4" //"25/4" +#define OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8 "LMS_SHA256_H25_W8" //"25/8" + +#define OQS_SIG_STFL_algs_length 48 /* Defined LM parameter identifiers */ /* Algorithm identifier for LMS-SHA256_N32_H5 */ @@ -167,7 +189,6 @@ typedef struct OQS_SIG_STFL { /** The (maximum) length, in bytes, of signatures for this signature scheme. */ size_t length_signature; - /** * Keypair generation algorithm. * @@ -247,12 +268,6 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /* mutual exclusion struct */ void *mutex; - /* Function that returns the total number of signatures for the secret key */ - uint64_t (*sigs_total)(const OQS_SIG_STFL_SECRET_KEY *secret_key); - - /* Function that returns the number of signatures left for the secret key */ - uint64_t (*sigs_left)(const OQS_SIG_STFL_SECRET_KEY *secret_key); - /** * Secret Key retrieval Function * diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index 83d3c4b275..20a8f87af0 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index b3f72ef038..d32ad7df05 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index 660f8c797c..9675fb1151 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index 735cd012f2..c4589175c6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index de64237cb1..bab2bda1f2 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index 0917020588..5c931a35c4 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index 708981b3ac..fde4331e66 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index e6381f0209..d1587260f3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index 4b80a0c938..c618ce8260 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index bdb3243bfc..84e5772280 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index 7b6b352720..788eb8f1e7 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index fa6c7cc060..7029f669f8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index 60cb3dd8ad..c4862f728e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index cd698b3d44..efa097b262 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index 4b6d0a9021..04c8fd52fb 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index c42a6db25f..dfa69325e8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index c29b43d2d1..7b4640ed40 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index 7e53563c2d..84f0f589d3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index c1ed78f606..c9616932eb 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index bc644a4223..7ab46f56ad 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 807eae702d..19421bb2ae 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 1082dcd999..1b51a87c76 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index 01d70f3a37..8e3617fbd0 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index d5935a5752..9a5f66ccef 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index 743ff4cb96..9b6fc160ed 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index c571bbe7ea..dfad288f23 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index 83ed6b0b63..acd7b70165 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index a8c3ed07af..889e831775 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -52,10 +52,6 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void) { sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk; - // Assign the sigs_left and sigs_max functions - sk->sigs_left = NULL; - sk->sigs_total = NULL; - // Secret serialize/deserialize function sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 2f2b176016..9abd8dbe73 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -573,10 +573,16 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) != 0) { - goto skip_test; - } else { + if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8) == 0 + + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1) == 0) { goto keep_going; + } else { + goto skip_test; } // if (0) { @@ -715,7 +721,6 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { sk->set_scrt_key_store_cb(sk, test_save_secret_key, (void *)context); } - /* read secret key from disk */ frm_file_sk_buf = malloc(to_file_sk_len); if (oqs_fload("sk", method_name, frm_file_sk_buf, to_file_sk_len, &frm_file_sk_len) != OQS_SUCCESS) { @@ -769,10 +774,16 @@ static OQS_STATUS sig_stfl_test_query_key(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) != 0) { - goto skip_test; - } else { + if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8) == 0 + + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1) == 0) { goto keep_going; + } else { + goto skip_test; } skip_test: @@ -790,7 +801,6 @@ static OQS_STATUS sig_stfl_test_query_key(const char *method_name) { return OQS_ERROR; } - printf("================================================================================\n"); printf("Sig Verify 1 %s\n", method_name); printf("================================================================================\n"); @@ -833,10 +843,16 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) != 0) { - goto skip_test; + if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8) == 0 + + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1) == 0) { + goto keep_going; } else { - goto keep_going; + goto skip_test; } skip_test: @@ -853,7 +869,6 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { return OQS_ERROR; } - /* * Get max num signature and the amount remaining */ @@ -872,7 +887,6 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { } printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); - printf("================================================================================\n"); printf("Sig Gen 1 %s\n", method_name); printf("================================================================================\n"); @@ -947,7 +961,6 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { return rc; } - static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { OQS_STATUS rc = OQS_SUCCESS; @@ -955,10 +968,16 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) != 0) { - goto skip_test; - } else { + if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8) == 0 + + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1) == 0 + || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1) == 0) { goto keep_going; + } else { + goto skip_test; } skip_test: @@ -1020,8 +1039,6 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { goto err; } - - if (!lock_test_sk->secret_key_data) { fprintf(stderr, "ERROR: OQS_SECRET_KEY_new incomplete.\n"); goto err; @@ -1158,7 +1175,6 @@ int main(int argc, char **argv) { td_sign.alg_name = alg_name; td_query.alg_name = alg_name; - int trc = pthread_create(&thread, NULL, test_wrapper, &td); if (trc) { fprintf(stderr, "ERROR: Creating pthread\n"); From 8df253944127c4da39d8a7068b98244c1619baea Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Fri, 20 Oct 2023 14:58:20 -0400 Subject: [PATCH 18/68] Stateful sigs XMSS updates (#1590) * Update XMSS to use callbacks. Update test cases. * Fix format * Fix SA issues * Fix format * Fix SA issue * set secure function callback for KAT tests. Block slow tests * set secure function callback for KAT tests. Block slow tests. --- src/sig_stfl/lms/sig_stfl_lms_functions.c | 74 +-- src/sig_stfl/sig_stfl.h | 3 + src/sig_stfl/xmss/sig_stfl_xmss.h | 3 + .../xmss/sig_stfl_xmss_secret_key_functions.c | 15 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 47 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 49 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 49 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 49 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 49 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 49 +- .../xmss/sig_stfl_xmss_shake128_h10.c | 49 +- .../xmss/sig_stfl_xmss_shake128_h16.c | 49 +- .../xmss/sig_stfl_xmss_shake128_h20.c | 49 +- .../xmss/sig_stfl_xmss_shake256_h10.c | 49 +- .../xmss/sig_stfl_xmss_shake256_h16.c | 49 +- .../xmss/sig_stfl_xmss_shake256_h20.c | 49 +- .../xmss/sig_stfl_xmssmt_sha256_h20_2.c | 49 +- .../xmss/sig_stfl_xmssmt_sha256_h20_4.c | 49 +- .../xmss/sig_stfl_xmssmt_sha256_h40_2.c | 50 +- .../xmss/sig_stfl_xmssmt_sha256_h40_4.c | 49 +- .../xmss/sig_stfl_xmssmt_sha256_h40_8.c | 49 +- .../xmss/sig_stfl_xmssmt_sha256_h60_12.c | 50 +- .../xmss/sig_stfl_xmssmt_sha256_h60_3.c | 49 +- .../xmss/sig_stfl_xmssmt_sha256_h60_6.c | 49 +- .../xmss/sig_stfl_xmssmt_shake128_h20_2.c | 49 +- .../xmss/sig_stfl_xmssmt_shake128_h20_4.c | 49 +- .../xmss/sig_stfl_xmssmt_shake128_h40_2.c | 49 +- .../xmss/sig_stfl_xmssmt_shake128_h40_4.c | 49 +- .../xmss/sig_stfl_xmssmt_shake128_h40_8.c | 49 +- .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 49 +- .../xmss/sig_stfl_xmssmt_shake128_h60_3.c | 49 +- .../xmss/sig_stfl_xmssmt_shake128_h60_6.c | 2 + tests/kat_sig_stfl.c | 8 + tests/test_sig_stfl.c | 515 +++++++++++++----- 34 files changed, 1653 insertions(+), 290 deletions(-) diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index f18d8c445b..63db4c49f1 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -69,6 +69,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu * Don't even attempt signing without a way to safe the updated private key */ if (secret_key->secure_store_scrt_key == NULL) { + fprintf(stderr, "No Secure-store set for secret key.\n."); goto err; } @@ -94,7 +95,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu goto err; } - context = lms_key_data->context; + context = secret_key->context; rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf, sk_key_buf_len, context); if (rc_keyupdate != OQS_SUCCESS) { goto err; @@ -241,40 +242,41 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uin } oqs_key_data = malloc(sizeof(oqs_lms_key_data)); - if (oqs_key_data) { - oqs_key_data->levels = 1; - if (sk->length_secret_key) { - oqs_key_data->len_sec_key = sk->length_secret_key; - oqs_key_data->sec_key = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - if (oqs_key_data->sec_key) { - memset(oqs_key_data->sec_key, 0, sk->length_secret_key); - } else { - OQS_MEM_insecure_free(oqs_key_data); - oqs_key_data = NULL; - return -1; - } - } else { - OQS_MEM_insecure_free(oqs_key_data); - oqs_key_data = NULL; - return -1; - } + if (oqs_key_data == NULL) { + return -1; + } - //Aux Data - size_t len_aux_data = DEFAULT_AUX_DATA; - uint8_t *aux_data = malloc(sizeof(uint8_t) * len_aux_data); - if (aux_data) { - oqs_key_data->aux_data = aux_data; - oqs_key_data->len_aux_data = len_aux_data; - } else { - OQS_MEM_insecure_free( oqs_key_data->sec_key); - OQS_MEM_insecure_free(oqs_key_data); - return -1; - } - } else { - //TODO log error + memset(oqs_key_data, 0, sizeof(oqs_lms_key_data)); + if (sk->length_secret_key == 0) { + OQS_MEM_insecure_free(oqs_key_data); + oqs_key_data = NULL; + return -1; + } + + oqs_key_data->levels = 1; + oqs_key_data->len_sec_key = sk->length_secret_key; + oqs_key_data->sec_key = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + if (oqs_key_data->sec_key == NULL) { + OQS_MEM_insecure_free(oqs_key_data); + oqs_key_data = NULL; return -1; } + memset(oqs_key_data->sec_key, 0, sk->length_secret_key); + + //Aux Data + size_t len_aux_data = DEFAULT_AUX_DATA; + uint8_t *aux_data = malloc(sizeof(uint8_t) * len_aux_data); + if (aux_data == NULL) { + OQS_MEM_insecure_free( oqs_key_data->sec_key); + OQS_MEM_insecure_free(oqs_key_data); + return -1; + } + + oqs_key_data->aux_data = aux_data; + oqs_key_data->len_aux_data = len_aux_data; + oqs_key_data->context = sk->context; + /* Set lms param set */ switch (oid) { case OQS_LMS_ID_sha256_n32_h5_w1: @@ -668,6 +670,7 @@ OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_ lms_key_data->len_aux_data = aux_buf_len; } + sk->context = context; sk->secret_key_data = lms_key_data; goto success; @@ -682,9 +685,10 @@ OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_ } void oqs_lms_key_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { - oqs_lms_key_data *lms_key_data = (oqs_lms_key_data *)sk->secret_key_data; - if (lms_key_data) { - lms_key_data->context = context; - sk->secure_store_scrt_key = store_cb; + + if (sk == NULL) { + return; } + sk->secure_store_scrt_key = store_cb; + sk->context = context; } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 33177e829e..e4b7d42c9c 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -268,6 +268,9 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /* mutual exclusion struct */ void *mutex; + /* file storage handle */ + void *context; + /** * Secret Key retrieval Function * diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index 54006043e1..8b9536daed 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -503,4 +503,7 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, /* Deserialize XMSS byte string into an XMSS secret key data */ OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); +/* Set XMSS byte string into an XMSS secret key data */ +void OQS_SECRET_KEY_XMSS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); + #endif /* OQS_SIG_STFL_XMSS_H */ diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index 4a47c938c3..a9ea864cdb 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -37,9 +37,8 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, cons } if (sk->secret_key_data != NULL) { - // Key data already present - // We dont want to trample over data - return OQS_ERROR; + OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); + sk->secret_key_data = NULL; } // Assume key data is not present @@ -48,7 +47,17 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, cons return OQS_ERROR; } + sk->context = context; memcpy(sk->secret_key_data, sk_buf, sk_len); return OQS_SUCCESS; } + +void OQS_SECRET_KEY_XMSS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { + if (!sk || !store_cb || !context) { + return; + } + + sk->context = context; + sk->secure_store_scrt_key = store_cb; +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index 20a8f87af0..2affc67195 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -68,6 +68,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -87,17 +89,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } + + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } *signature_len = (size_t)sig_length; - return OQS_SUCCESS; + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index d32ad7df05..cfaa958dd7 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(XMSS_UNUSED_ATT uint OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index 9675fb1151..1145d17e2b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(XMSS_UNUSED_ATT uint OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index c4589175c6..c7ca88eee7 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(XMSS_UNUSED_ATT uint OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index bab2bda1f2..70123ccb16 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(XMSS_UNUSED_ATT uint OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index 5c931a35c4..ebb03643a6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(XMSS_UNUSED_ATT uint OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index fde4331e66..4d15d86461 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(XMSS_UNUSED_ATT ui OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index d1587260f3..499ba294ad 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(XMSS_UNUSED_ATT ui OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index c618ce8260..8f47a4f825 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(XMSS_UNUSED_ATT ui OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = oqs_serialize_lms_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index 84e5772280..944a34d9de 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(XMSS_UNUSED_ATT ui OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index 788eb8f1e7..93e8791bf8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(XMSS_UNUSED_ATT ui OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index 7029f669f8..e701614e79 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(XMSS_UNUSED_ATT ui OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index c4862f728e..f333b08a0e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(XMSS_UNUSED_ATT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index efa097b262..76febd3103 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(XMSS_UNUSED_ATT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index 04c8fd52fb..b2b39b51ec 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,57 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(XMSS_UNUSED_ATT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { + fprintf(stderr, "No secret key secure-store set.\n"); return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index dfa69325e8..4781f49cfe 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(XMSS_UNUSED_ATT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index 7b4640ed40..2acbc1046e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(XMSS_UNUSED_ATT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index 84f0f589d3..d9b98a749f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,57 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(XMSS_UNUSED_ATT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index c9616932eb..c45fef5959 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(XMSS_UNUSED_ATT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index 7ab46f56ad..f43f87c6b4 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(XMSS_UNUSED_ATT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 19421bb2ae..16d7270593 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(XMSS_UNUSED_AT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 1b51a87c76..941a2ecb3c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(XMSS_UNUSED_AT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index 8e3617fbd0..adc47b4d11 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(XMSS_UNUSED_AT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index 9a5f66ccef..3312f25477 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(XMSS_UNUSED_AT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index 9b6fc160ed..43afdfeeff 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(XMSS_UNUSED_AT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index dfad288f23..bf7c0c56d2 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(XMSS_UNUSED_A OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index acd7b70165..f8b6ab6ec5 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } @@ -86,17 +88,56 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(XMSS_UNUSED_AT OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; + const OQS_SIG_STFL_SECRET_KEY *sk; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { return OQS_ERROR; } - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + /* check for secret key update function */ + if (secret_key->secure_store_scrt_key == NULL) { return OQS_ERROR; } - *signature_len = (size_t) sig_length; - return OQS_SUCCESS; + /* Lock secret to ensure OTS use */ + if ((secret_key->lock_key) && (secret_key->mutex)) { + secret_key->lock_key(secret_key->mutex); + } + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + + /* + * serialize and securely store the updated private key + * but, delete signature and the serialized key other wise + */ + + sk = secret_key; + rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + goto err; + } + + rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + if (rc_keyupdate != OQS_SUCCESS) { + status = OQS_ERROR; + } + + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); +err: + /* Unlock secret to ensure OTS use */ + if ((secret_key->unlock_key) && (secret_key->mutex)) { + secret_key->unlock_key(secret_key->mutex); + } + return status; } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index 889e831775..1821340645 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -67,6 +67,8 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void) { sk->free_key = OQS_SECRET_KEY_XMSS_free; + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + return sk; } diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index d5de696580..33dce7e897 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -20,6 +20,12 @@ #define MAX_MARKER_LEN 50 +static OQS_STATUS do_nothing_save(uint8_t *key_buf, size_t buf_len, void *context) { + (void)(context); + (void)(buf_len); + return key_buf != NULL ? OQS_SUCCESS : OQS_ERROR; +} + // // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // @@ -150,6 +156,8 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { // Grab the pk and sk from KAT file public_key = malloc(sig->length_public_key); secret_key = OQS_SIG_STFL_SECRET_KEY_new(sig->method_name); + OQS_SIG_STFL_SECRET_KEY_SET_store_cb(secret_key, do_nothing_save, NULL); + signature = calloc(sig->length_signature, sizeof(uint8_t)); signature_kat = calloc(sig->length_signature, sizeof(uint8_t)); diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 9abd8dbe73..305001a462 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -322,6 +322,52 @@ typedef struct magic_s { uint8_t val[31]; } magic_t; +static char *convert_method_name_to_file_name(const char *method_name) { + + const char *file_store = NULL; + char *name = NULL; + if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2) == 0) { + file_store = "XMSSMT-SHA2_20-2_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4) == 0) { + file_store = "XMSSMT-SHA2_20-4_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2) == 0) { + file_store = "XMSSMT-SHA2_40-2_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_4) == 0) { + file_store = "XMSSMT-SHA2_40-4_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_8) == 0) { + file_store = "XMSSMT-SHA2_40-8_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3) == 0) { + file_store = "XMSSMT-SHA2_60-3_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_6) == 0) { + file_store = "XMSSMT-SHA2_60-6_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_12) == 0) { + file_store = "XMSSMT-SHA2_60-12_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_2) == 0) { + file_store = "XMSSMT-SHAKE_20-2_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_4) == 0) { + file_store = "XMSSMT-SHAKE_20-4_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2) == 0) { + file_store = "XMSSMT-SHAKE_40-2_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_4) == 0) { + file_store = "XMSSMT-SHAKE_40-4_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_8) == 0) { + file_store = "XMSSMT-SHAKE_40-8_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3) == 0) { + file_store = "XMSSMT-SHAKE_60-3_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6) == 0) { + file_store = "XMSSMT-SHAKE_60-6_256"; + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12) == 0) { + file_store = "XMSSMT-SHAKE_60-12_256"; + } else { + file_store = method_name; + } + + if (file_store) { + name = strdup(file_store); + } + return name; +} + static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char *katfile) { OQS_SIG_STFL *sig = NULL; @@ -337,19 +383,86 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char uint8_t *sk_buf = NULL; uint8_t *read_pk_buf = NULL; char *context = NULL; - const char *file_store = NULL; + char *file_store = NULL; size_t sk_buf_len = 0; size_t read_pk_len = 0; + magic_t magic; + #if OQS_USE_PTHREADS_IN_TESTS pthread_mutex_t *sk_lock = NULL; #endif OQS_STATUS rc, ret = OQS_ERROR; + if (0) { + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { + goto skip_test; +#endif + } else { + goto test_on; + } +skip_test: + printf("skipping slow test %s\n", method_name); + return OQS_SUCCESS; + +test_on: + //The magic numbers are random values. //The length of the magic number was chosen to be 31 to break alignment - magic_t magic; + + OQS_randombytes(magic.val, sizeof(magic_t)); sig = OQS_SIG_STFL_new(method_name); @@ -368,6 +481,16 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char OQS_SIG_STFL_SECRET_KEY_SET_lock(secret_key, lock_sk_key); OQS_SIG_STFL_SECRET_KEY_SET_unlock(secret_key, unlock_sk_key); + file_store = convert_method_name_to_file_name(sig->method_name); + if (file_store == NULL) { + fprintf(stderr, "%s: file_store is null\n", __FUNCTION__); + goto err; + } + + /* set context and secure store callback */ + context = strdup(((file_store))); + OQS_SIG_STFL_SECRET_KEY_SET_store_cb(secret_key, test_save_secret_key, (void *)context); + #if OQS_USE_PTHREADS_IN_TESTS sk_lock = (pthread_mutex_t *)malloc(sizeof(pthread_mutex_t)); if (sk_lock == NULL) { @@ -421,42 +544,6 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char goto err; } - if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2) == 0) { - file_store = "XMSSMT-SHA2_20-2_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4) == 0) { - file_store = "XMSSMT-SHA2_20-4_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2) == 0) { - file_store = "XMSSMT-SHA2_40-2_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_4) == 0) { - file_store = "XMSSMT-SHA2_40-4_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_8) == 0) { - file_store = "XMSSMT-SHA2_40-8_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3) == 0) { - file_store = "XMSSMT-SHA2_60-3_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_6) == 0) { - file_store = "XMSSMT-SHA2_60-6_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_12) == 0) { - file_store = "XMSSMT-SHA2_60-12_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_2) == 0) { - file_store = "XMSSMT-SHAKE_20-2_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h20_4) == 0) { - file_store = "XMSSMT-SHAKE_20-4_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2) == 0) { - file_store = "XMSSMT-SHAKE_40-2_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_4) == 0) { - file_store = "XMSSMT-SHAKE_40-4_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_8) == 0) { - file_store = "XMSSMT-SHAKE_40-8_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3) == 0) { - file_store = "XMSSMT-SHAKE_60-3_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6) == 0) { - file_store = "XMSSMT-SHAKE_60-6_256"; - } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12) == 0) { - file_store = "XMSSMT-SHAKE_60-12_256"; - } else { - file_store = sig->method_name; - } - /* write key pair to disk */ if (oqs_fstore("sk", file_store, sk_buf, sk_buf_len) != OQS_SUCCESS) { goto err; @@ -466,10 +553,6 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char goto err; } - /* set context and secure store callback */ - context = strdup(((file_store))); - OQS_SIG_STFL_SECRET_KEY_SET_store_cb(secret_key, test_save_secret_key, (void *)context); - rc = OQS_SIG_STFL_sign(sig, signature, &signature_len, message, message_len, secret_key); OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); if (rc != OQS_SUCCESS) { @@ -545,6 +628,7 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char OQS_MEM_insecure_free(read_pk_buf); OQS_MEM_insecure_free(context); + OQS_MEM_insecure_free(file_store); #if OQS_USE_PTHREADS_IN_TESTS if (sk_lock) { @@ -568,81 +652,70 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { size_t to_file_sk_len = 0; char *context = NULL; char *context_2 = NULL; + char *file_store_name = NULL; /* * Temporarily skip algs with long key generation times. */ - if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8) == 0 + if (0) { - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1) == 0) { - goto keep_going; - } else { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { goto skip_test; - } +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { + goto skip_test; +#endif -// if (0) { -// -//#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 -// } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { -// goto skip_test; -//#endif -//#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 -// } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { -// goto skip_test; -//#endif -// -//#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { -// goto skip_test; -//#endif -//#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { -// goto skip_test; -//#endif -// -//#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { -// goto skip_test; -//#endif -//#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { -// goto skip_test; -//#endif -// -//#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { -// goto skip_test; -//#endif -//#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { -// goto skip_test; -//#endif -// -//#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { -// goto skip_test; -//#endif -//#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { -// goto skip_test; -//#endif -// -//#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { -// goto skip_test; -//#endif -//#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 -// } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { -// goto skip_test; -//#endif -// } else { -// goto keep_going; -// } +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { + goto skip_test; +#endif + } else { + goto keep_going; + } skip_test: printf("Skip slow test %s.\n", method_name); @@ -706,7 +779,8 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { goto err; } - if (oqs_fstore("sk", sig_obj->method_name, to_file_sk_buf, to_file_sk_len) != OQS_SUCCESS) { + file_store_name = convert_method_name_to_file_name(sig_obj->method_name); + if (oqs_fstore("sk", file_store_name, to_file_sk_buf, to_file_sk_len) != OQS_SUCCESS) { goto err; } @@ -717,13 +791,13 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { /* set context and secure store callback */ if (sk->set_scrt_key_store_cb) { - context = strdup(((method_name))); + context = strdup(file_store_name); sk->set_scrt_key_store_cb(sk, test_save_secret_key, (void *)context); } /* read secret key from disk */ frm_file_sk_buf = malloc(to_file_sk_len); - if (oqs_fload("sk", method_name, frm_file_sk_buf, to_file_sk_len, &frm_file_sk_len) != OQS_SUCCESS) { + if (oqs_fload("sk", file_store_name, frm_file_sk_buf, to_file_sk_len, &frm_file_sk_len) != OQS_SUCCESS) { goto err; } if (to_file_sk_len != frm_file_sk_len) { @@ -737,7 +811,7 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { goto err; } - context_2 = strdup(((method_name))); + context_2 = strdup(file_store_name); rc = OQS_SECRET_KEY_STFL_deserialize_key(sk_frm_file, frm_file_sk_len, frm_file_sk_buf, (void *)context_2); if (rc != OQS_SUCCESS) { @@ -761,12 +835,12 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { OQS_SIG_STFL_free(sig_obj); OQS_MEM_insecure_free(context); OQS_MEM_insecure_free(context_2); + OQS_MEM_insecure_free(file_store_name); return rc; } static OQS_STATUS sig_stfl_test_query_key(const char *method_name) { OQS_STATUS rc = OQS_SUCCESS; - size_t message_len_1 = sizeof(message_1); size_t message_len_2 = sizeof(message_2); @@ -774,20 +848,67 @@ static OQS_STATUS sig_stfl_test_query_key(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8) == 0 + if (0) { - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1) == 0) { - goto keep_going; - } else { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { + goto skip_test; +#endif + } else { + goto keep_going; } skip_test: - printf("Skip slow alg %s.\n", method_name); + printf("Skip slow test %s.\n", method_name); return rc; keep_going: @@ -839,24 +960,74 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { size_t message_len_1 = sizeof(message_1); size_t message_len_2 = sizeof(message_2); + char *context = NULL; + char *key_store_name = NULL; + /* * Temporarily skip algs with long key generation times. */ - if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8) == 0 + if (0) { - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1) == 0) { - goto keep_going; - } else { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { + goto skip_test; +#endif + } else { + goto keep_going; } skip_test: - printf("Skip slow alg %s.\n", method_name); + printf("Skip slow test %s.\n", method_name); return rc; keep_going: @@ -869,6 +1040,11 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { return OQS_ERROR; } + key_store_name = convert_method_name_to_file_name(method_name); + /* set context and secure store callback */ + context = strdup(((key_store_name))); + OQS_SIG_STFL_SECRET_KEY_SET_store_cb(lock_test_sk, test_save_secret_key, (void *)context); + /* * Get max num signature and the amount remaining */ @@ -957,6 +1133,8 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { err: rc = OQS_ERROR; end_it: + OQS_MEM_insecure_free(context); + OQS_MEM_insecure_free(key_store_name); return rc; } @@ -964,20 +1142,71 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { OQS_STATUS rc = OQS_SUCCESS; + printf("================================================================================\n"); + printf("Testing stateful Signature locks %s\n", method_name); + printf("================================================================================\n"); + /* * Temporarily skip algs with long key generation times. */ - if (strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8) == 0 + if (0) { - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1) == 0 - || strcmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1) == 0) { - goto keep_going; - } else { +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 + } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { + goto skip_test; +#endif + +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { + goto skip_test; +#endif +#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { + goto skip_test; +#endif + } else { + goto keep_going; } skip_test: @@ -986,10 +1215,6 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { keep_going: - printf("================================================================================\n"); - printf("Testing stateful Signature locks %s\n", method_name); - printf("================================================================================\n"); - printf("================================================================================\n"); printf("Create stateful Signature %s\n", method_name); printf("================================================================================\n"); @@ -1046,7 +1271,7 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { /* set context and secure store callback */ if (lock_test_sk->set_scrt_key_store_cb) { - lock_test_context = strdup(((method_name))); + lock_test_context = convert_method_name_to_file_name(method_name); lock_test_sk->set_scrt_key_store_cb(lock_test_sk, test_save_secret_key, (void *)lock_test_context); } From 2dbfc400734501386fd51d50c2739b3f09d25b3d Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Wed, 1 Nov 2023 13:34:21 -0400 Subject: [PATCH 19/68] Update XMSS secret key object APIs, sync with LMS (#1588) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * Init * convert all variable length array to malloc/free fix astyle fixed all memory errors * refactor XMSS and XMSS^MT, shorten LOC * clean up unused function * TODO: restore core_hash.c later * Add activate_lock and activate_unlock functions * Add `bool is_locked` to retain lock information, and adjust function signatures * cleanup test_sig_stfl.c * remove const in LMS_serialize_key and add `is_locked` to OQS_SIG_STFL_SECRET_KEY initialization * fix astyle error * fix astyle. I have to update local astyle to 3.4.10 * remove incorrect comments * remove unsued variables * fix if guard * fix const warnings * fix namespace error. revert core_hash.c to original namespace separation * move XMSS_free to internal of XMSS * Fix memory leaks * fix astyle format * fix typo * improve readablity * Update OID comment. * Trim the space * Remove mutex status bool * Remove use of mutex status bool. Use recursive mutex” src/sig_stfl/lms/sig_stfl_lms.c src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c tests/test_sig_stfl.c * rename lock function * simplify the check with 0 * Fix grammar * add `const` back to serialize. Reorder parameters to follow liboqs convention * use inner_serialize to avoid recursive lock * add return code in case pthread API has errors * fix scan_build NULL error --------- Co-authored-by: Norman Ashley --- src/sig_stfl/lms/sig_stfl_lms.c | 6 +- src/sig_stfl/lms/sig_stfl_lms.h | 2 +- src/sig_stfl/lms/sig_stfl_lms_functions.c | 9 +- src/sig_stfl/lms/sig_stfl_lms_wrap.h | 3 - src/sig_stfl/sig_stfl.c | 46 +- src/sig_stfl/sig_stfl.h | 110 ++- src/sig_stfl/xmss/CMakeLists.txt | 56 +- src/sig_stfl/xmss/external/hash.c | 41 +- src/sig_stfl/xmss/external/sign.c | 139 ---- src/sig_stfl/xmss/external/sign.h | 90 --- src/sig_stfl/xmss/external/utils.h | 2 +- src/sig_stfl/xmss/external/wots.c | 25 +- src/sig_stfl/xmss/external/xmss_commons.c | 28 +- src/sig_stfl/xmss/external/xmss_core_fast.c | 110 ++- src/sig_stfl/xmss/sig_stfl_xmss.h | 149 +++- src/sig_stfl/xmss/sig_stfl_xmss_functions.c | 99 +++ .../xmss/sig_stfl_xmss_secret_key_functions.c | 129 +++- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 121 +-- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 120 +-- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 120 +-- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 120 +-- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 120 +-- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 120 +-- .../xmss/sig_stfl_xmss_shake128_h10.c | 120 +-- .../xmss/sig_stfl_xmss_shake128_h16.c | 121 +-- .../xmss/sig_stfl_xmss_shake128_h20.c | 120 +-- .../xmss/sig_stfl_xmss_shake256_h10.c | 120 +-- .../xmss/sig_stfl_xmss_shake256_h16.c | 121 +-- .../xmss/sig_stfl_xmss_shake256_h20.c | 120 +-- src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c | 99 +++ .../xmss/sig_stfl_xmssmt_sha256_h20_2.c | 120 +-- .../xmss/sig_stfl_xmssmt_sha256_h20_4.c | 120 +-- .../xmss/sig_stfl_xmssmt_sha256_h40_2.c | 121 +-- .../xmss/sig_stfl_xmssmt_sha256_h40_4.c | 120 +-- .../xmss/sig_stfl_xmssmt_sha256_h40_8.c | 120 +-- .../xmss/sig_stfl_xmssmt_sha256_h60_12.c | 121 +-- .../xmss/sig_stfl_xmssmt_sha256_h60_3.c | 120 +-- .../xmss/sig_stfl_xmssmt_sha256_h60_6.c | 120 +-- .../xmss/sig_stfl_xmssmt_shake128_h20_2.c | 120 +-- .../xmss/sig_stfl_xmssmt_shake128_h20_4.c | 120 +-- .../xmss/sig_stfl_xmssmt_shake128_h40_2.c | 120 +-- .../xmss/sig_stfl_xmssmt_shake128_h40_4.c | 120 +-- .../xmss/sig_stfl_xmssmt_shake128_h40_8.c | 120 +-- .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 121 +-- .../xmss/sig_stfl_xmssmt_shake128_h60_3.c | 120 +-- .../xmss/sig_stfl_xmssmt_shake128_h60_6.c | 81 +- tests/kat_sig_stfl.c | 2 +- tests/test_sig_stfl.c | 702 +++++------------- 48 files changed, 1097 insertions(+), 4077 deletions(-) delete mode 100644 src/sig_stfl/xmss/external/sign.c delete mode 100644 src/sig_stfl/xmss/external/sign.h create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_functions.c create mode 100644 src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index 3503c7447b..b6d57902ee 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -8,7 +8,7 @@ #include "sig_stfl_lms.h" /* Convert LMS secret key object to byte string */ -static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); +static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); /* Insert lms byte string in an LMS secret key object */ static OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); @@ -1760,13 +1760,13 @@ void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk) { } /* Convert LMS secret key object to byte string */ -static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr) { +static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk) { OQS_STATUS status; if (sk->lock_key && sk->mutex) { sk->lock_key(sk->mutex); } - status = oqs_serialize_lms_key(sk, sk_len, sk_buf_ptr); + status = oqs_serialize_lms_key(sk_buf_ptr, sk_len, sk); if (sk->unlock_key && sk->mutex) { sk->unlock_key(sk->mutex); diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index e42450fd15..b75446d2e3 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -209,7 +209,7 @@ int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, const uint8_t *sm, si void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk); -OQS_STATUS oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_key); +OQS_STATUS oqs_serialize_lms_key(uint8_t **sk_key, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); void oqs_lms_key_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index 63db4c49f1..1e3154b009 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -51,7 +51,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu OQS_STATUS status = OQS_ERROR; OQS_STATUS rc_keyupdate = OQS_ERROR; oqs_lms_key_data *lms_key_data = NULL; - const OQS_SIG_STFL_SECRET_KEY *sk; uint8_t *sk_key_buf = NULL; size_t sk_key_buf_len = 0; void *context; @@ -89,8 +88,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu * but, delete signature and the serialized key other wise */ - sk = secret_key; - rc_keyupdate = oqs_serialize_lms_key(sk, &sk_key_buf_len, &sk_key_buf); + rc_keyupdate = oqs_serialize_lms_key(&sk_key_buf, &sk_key_buf_len, secret_key); if (rc_keyupdate != OQS_SUCCESS) { goto err; } @@ -121,8 +119,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu } OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t message_len, - const uint8_t *signature, size_t signature_len, - const uint8_t *public_key) { + const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { if (message == NULL || signature == NULL || public_key == NULL) { return OQS_ERROR; @@ -566,7 +563,7 @@ void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk) { * Convert LMS secret key object to byte string * Writes secret key + aux data if present */ -OQS_STATUS oqs_serialize_lms_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_key) { +OQS_STATUS oqs_serialize_lms_key(uint8_t **sk_key, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk) { if (sk == NULL || sk_len == NULL || sk_key == NULL) { return OQS_ERROR; diff --git a/src/sig_stfl/lms/sig_stfl_lms_wrap.h b/src/sig_stfl/lms/sig_stfl_lms_wrap.h index 1d5486d21a..e113a16ed6 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_wrap.h +++ b/src/sig_stfl/lms/sig_stfl_lms_wrap.h @@ -7,7 +7,6 @@ #include "external/hss.h" #include "external/hss_sign_inc.h" - /** * @brief OQS_LMS_KEY object for HSS key pair */ @@ -17,7 +16,6 @@ typedef struct OQS_LMS_SIG_DATA oqs_lms_sig_data; typedef struct OQS_LMS_SIG_DATA { - /* message buffer */ unsigned char *message; @@ -33,4 +31,3 @@ typedef struct OQS_LMS_SIG_DATA { } oqs_lms_sig_data; #endif //OQS_SIG_STFL_LMS_H - diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index b434f54715..9bdee77780 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -14,6 +14,7 @@ OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { const char *a[OQS_SIG_STFL_algs_length] = { + // XMSS OQS_SIG_STFL_alg_xmss_sha256_h10, OQS_SIG_STFL_alg_xmss_sha256_h16, OQS_SIG_STFL_alg_xmss_sha256_h20, @@ -42,6 +43,7 @@ OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { OQS_SIG_STFL_alg_xmssmt_shake128_h60_3, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12, + // LMS OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4, @@ -799,54 +801,38 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_ } } -void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk) { - if (sk == NULL) { - return; - } - - OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); - sk->secret_key_data = NULL; -} - OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk) { - if (sk == NULL) { + if (sk == NULL || sk->free_key == NULL) { return; } /* Call object specific free */ - if (sk->free_key) { - sk->free_key(sk); - } + sk->free_key(sk); + + /* Free sk object */ OQS_MEM_secure_free(sk, sizeof(sk)); + sk = NULL; } OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { - if (sk) { - if (sk->set_scrt_key_store_cb) { - sk->set_scrt_key_store_cb(sk, store_cb, context); - } + if (sk == NULL || sk->set_scrt_key_store_cb == NULL) { + return; } + sk->set_scrt_key_store_cb(sk, store_cb, context); } /* Convert secret key object to byte string */ -OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf) { - if ((sk == NULL) || (sk_len == NULL) || (sk_buf == NULL)) { - return 0; - } - if (sk->serialize_key) { - return sk->serialize_key(sk, sk_len, sk_buf); - } else { - return 0; +OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL || sk_len == NULL || sk_buf_ptr == NULL || sk->serialize_key == NULL) { + return OQS_ERROR; } + + return sk->serialize_key(sk_buf_ptr, sk_len, sk); } /* Insert secret key byte string in an Stateful secret key object */ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t key_len, const uint8_t *sk_buf, void *context) { - if ((sk == NULL) || (sk_buf == NULL)) { - return OQS_ERROR; - } - - if (sk->deserialize_key == NULL) { + if (sk == NULL || sk_buf == NULL || sk->deserialize_key == NULL) { return OQS_ERROR; } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index e4b7d42c9c..ad55b11d1a 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -18,15 +18,15 @@ /* * Developer's Notes: - * Stateful signatures are based on one-time use of a secret key. A pool of secret keys are created for this purpose. - * The state of these keys are tracked to ensure that they are used only once to generate a signature. + * Stateful signatures are based on the one-time use of a secret key. A pool of secret keys is created for this purpose. + * The state of these keys is tracked to ensure that they are used only once to generate a signature. * - * As such, product specific environments do play a role in ensuring the safety of the keys. - * Secret keys must be store securely. + * As such, product-specific environments do play a role in ensuring the safety of the keys. + * Secret keys must be stored securely. * The key index/counter must be updated after each signature generation. - * Secret key must be protected in a thread-save manner. + * The secret key must be protected in a thread-safe manner. * - * Application therefore are required to provide environment specific callback functions to + * Applications therefore are required to provide environment-specific callback functions to * - store private key * - lock/unlock private key * @@ -109,7 +109,7 @@ typedef struct OQS_SIG_STFL_SECRET_KEY OQS_SIG_STFL_SECRET_KEY; /** * Application provided function to securely store data * @param[in] sk_buf pointer to the data to be saved - * @param[in] buf_len length of the the data to be store + * @param[in] buf_len length of the data to be stored * @param[out] context pointer to application relevant data. * return OQS_SUCCESS if successful, otherwise OQS_ERROR */ @@ -117,7 +117,7 @@ typedef OQS_STATUS (*secure_store_sk)(uint8_t *sk_buf, size_t buf_len, void *con /** * Application provided function to lock secret key object serialize access - * @param[in] sk pointer to secret key object to lock + * @param[in] sk pointer to the secret key object to lock * @param[in] mutex pointer to mutex struct * return OQS_SUCCESS if successful, otherwise OQS_ERROR */ @@ -125,7 +125,7 @@ typedef OQS_STATUS (*lock_key)(void *mutex); /** * Application provided function to unlock secret key object - * @param[in] sk pointer to secret key object to unlock + * @param[in] sk pointer to the secret key object to unlock * @param[in] mutex pointer to mutex struct * return OQS_SUCCESS if successful, otherwise OQS_ERROR */ @@ -165,7 +165,10 @@ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name); */ typedef struct OQS_SIG_STFL { - /** A local ordinal representing the LMS parameter of the signature scheme. */ + /** + * A local ordinal representing the LMS/XMSS OID parameter of the signature scheme. + * This OID is unrelated to ASN.1 OID or anything, it's only for LMS/XMSS internal usage. + */ uint32_t oid; /** Printable string representing the name of the signature scheme. */ @@ -196,8 +199,8 @@ typedef struct OQS_SIG_STFL { * based on the `length_*` members in this object or the per-scheme * compile-time macros `OQS_SIG_STFL_*_length_*`. * - * @param[out] public_key The public key represented as a byte string. - * @param[out] secret_key The secret key represented as a byt string + * @param[out] public_key The public key is represented as a byte string. + * @param[out] secret_key The secret key is represented as a byte string * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*keypair)(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -209,11 +212,11 @@ typedef struct OQS_SIG_STFL { * based on the `length_*` members in this object or the per-scheme * compile-time macros `OQS_SIG_STFL_*_length_*`. * - * @param[out] signature The signature on the message represented as a byte string. + * @param[out] signature The signature on the message is represented as a byte string. * @param[out] signature_len The length of the signature. - * @param[in] message The message to sign represented as a byte string. + * @param[in] message The message to sign is represented as a byte string. * @param[in] message_len The length of the message to sign. - * @param[in] secret_key The secret key represented as a byte string. + * @param[in] secret_key The secret key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*sign)(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -221,11 +224,11 @@ typedef struct OQS_SIG_STFL { /** * Signature verification algorithm. * - * @param[in] message The message represented as a byte string. + * @param[in] message The message is represented as a byte string. * @param[in] message_len The length of the message. - * @param[in] signature The signature on the message represented as a byte string. + * @param[in] signature The signature on the message is represented as a byte string. * @param[in] signature_len The length of the signature. - * @param[in] public_key The public key represented as a byte string. + * @param[in] public_key The public key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*verify)(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); @@ -234,7 +237,7 @@ typedef struct OQS_SIG_STFL { * Query number of remaining signatures * * @param[out] remain The number of remaining signatures - * @param[in] secret_key The secret key represented as a byte string. + * @param[in] secret_key The secret key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*sigs_remaining)(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -243,7 +246,7 @@ typedef struct OQS_SIG_STFL { * Total number of signatures * * @param[out] total The total number of signatures - * @param[in] secret_key The secret key represented as a byte string. + * @param[in] secret_key The secret key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*sigs_total)(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -262,7 +265,7 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /* The (maximum) length, in bytes, of secret keys for this signature scheme. */ size_t length_secret_key; - /* The variant specific secret key data */ + /* The variant-specific secret key data, must be allocated at the initialization. */ void *secret_key_data; /* mutual exclusion struct */ @@ -275,22 +278,22 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * Secret Key retrieval Function * * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object - * @param[out] sk_len length of private key as a byte stream + * @param[out] sk_len length of the private key as a byte stream * @param[out] sk_buf_ptr pointer to private key data as a byte stream * @returns length of key material data available - * Caller deletes the buffer if memory was allocated. + * Caller is responsible for **deallocating** the pointer to buffer `sk_buf_ptr`. */ - OQS_STATUS (*serialize_key)(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); + OQS_STATUS (*serialize_key)(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); /** - * set Secret Key to internal structure Function + * Secret Key to internal structure Function * * @param[in] sk OQS_SIG_STFL_SECRET_KEY object * @param[in] key_len length of the returned byte string - * @param[in] sk_buf The secret key data to populate key obj - * @param[in] context application specific data - * @returns status of the operation populated with key material none-zero length. Caller - * deletes the buffer. if sk_buf is NULL the function returns the length + * @param[in] sk_buf The secret key data to populate the key object + * @param[in] context application-specific data + * @returns status of the operation populated with key material none zero length. + * Caller is responsible to **unallocate** the buffer `sk_buf`. */ OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); @@ -315,15 +318,15 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * Callback function used to securely store key data * @param[in] sk_buf The serialized secret key data to secure store * @param[in] buf_len length of data to secure - * @param[in] context aides the secure writing of data + * @param[in] context aids the secure writing of data * * @return OQS_SUCCESS or OQS_ERROR - * Idealy written to secure device + * Ideally written to secure device */ OQS_STATUS (*secure_store_scrt_key)(uint8_t *sk_buf, size_t buf_len, void *context); /** - * Secret Key free internal variant specific data + * Free internal variant-specific data * * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object * @return none @@ -356,12 +359,12 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name); * * Caller is responsible for allocating sufficient memory for `public_key` based * on the `length_*` members in this object or the per-scheme compile-time macros - * `OQS_SIG_STFL_*_length_*`. Caller is also responsible for initializing + * `OQS_SIG_STFL_*_length_*`. The caller is also responsible for initializing * `secret_key` using the OQS_SIG_STFL_SECRET_KEY(*) function * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. - * @param[out] public_key The public key represented as a byte string. - * @param[out] secret_key The secret key represented as a byte string. + * @param[out] public_key The public key is represented as a byte string. + * @param[out] secret_key The secret key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -374,11 +377,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public * compile-time macros `OQS_SIG_STFL_*_length_*`. * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. - * @param[out] signature The signature on the message represented as a byte string. + * @param[out] signature The signature on the message is represented as a byte string. * @param[out] signature_len The length of the signature. - * @param[in] message The message to sign represented as a byte string. + * @param[in] message The message to sign is represented as a byte string. * @param[in] message_len The length of the message to sign. - * @param[in] secret_key The secret key represented as a byte string. + * @param[in] secret_key The secret key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -387,11 +390,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature * Signature verification algorithm. * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. - * @param[in] message The message represented as a byte string. + * @param[in] message The message is represented as a byte string. * @param[in] message_len The length of the message. - * @param[in] signature The signature on the message represented as a byte string. + * @param[in] signature The signature on the message is represented as a byte string. * @param[in] signature_len The length of the signature. - * @param[in] public_key The public key represented as a byte string. + * @param[in] public_key The public key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); @@ -400,7 +403,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m * Query number of remaining signatures * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. - * @param[in] secret_key The secret key represented as a byte string. + * @param[in] secret_key The secret key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -410,7 +413,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. * @param[out] max The number of remaining signatures - * @param[in] secret_key The secret key represented as a byte string. + * @param[in] secret_key The secret key is represented as a byte string. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -432,19 +435,11 @@ OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig); */ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_name); -/** - * Frees an OQS_SIG_STFL_SECRET_KEY **inner** data that was constructed by OQS_SECRET_KEY_new. - * - * @param[in] sig The OQS_SIG_STFL_SECRET_KEY object to free. - * @return OQS_SUCCESS if successful, or OQS_ERROR if the object could not be freed. - */ -void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); - /** * Frees an OQS_SIG_STFL_SECRET_KEY object that was constructed by OQS_SECRET_KEY_new. * * @param[in] sig The OQS_SIG_STFL_SECRET_KEY object to free. - * @return OQS_SUCCESS if successful, or OQS_ERROR if the object could not be freed. + * @return OQS_SUCCESS if successful, or OQS_ERROR if the object cannot be freed. */ OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk); @@ -484,7 +479,7 @@ void OQS_SIG_STFL_SECRET_KEY_SET_mutex(OQS_SIG_STFL_SECRET_KEY *sk, void *mutex) /** * OQS_SIG_STFL_SECRET_KEY_lock . * - * Locks sk so only one application that holds the lock can access it. + * Locks the secret key so only one application that holds the lock can access it. * * @param[in] sk secret key pointer to be locked * @return OQS_SUCCESS if successful, or OQS_ERROR if the object fails to apply the lock @@ -495,7 +490,7 @@ OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk); /** * OQS_SIG_STFL_SECRET_KEY_unlock . * - * Unlocks the resouces so that th enext process can access it. + * Unlocks the secret key so that the next process can access it. * * @param[in] sk secret key pointer * @return OQS_SUCCESS if successful, or OQS_ERROR if the object fails to release the lock @@ -507,7 +502,7 @@ OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); * OQS_SIG_STFL_SECRET_KEY_SET_store_cb . * * Can be called after creating a new stateful secret key has been generated. - * Allows the lib to securely store and update secret key after a sign operation. + * Allows the lib to securely store and update the secret key after a sign operation. * * @param[in] sk secret key pointer to be updated * @param[in] store_cb callback pointer @@ -516,9 +511,10 @@ OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); */ void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); -OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf); +/* Serialize stateful secret key data into a byte string, and return an allocated buffer. Users are responsible for deallocating the buffer `sk_buf`. */ +OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); -/* Insert lms byte string in an LMS secret key object */ +/* Insert stateful byte string into a secret key object. Users are responsible for deallocating buffer `sk_buf`. */ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf, void *context); #if defined(__cplusplus) diff --git a/src/sig_stfl/xmss/CMakeLists.txt b/src/sig_stfl/xmss/CMakeLists.txt index 1b55b20866..e1d287472f 100644 --- a/src/sig_stfl/xmss/CMakeLists.txt +++ b/src/sig_stfl/xmss/CMakeLists.txt @@ -17,169 +17,169 @@ add_library(sig_stfl_xmss_secret_key_functions OBJECT sig_stfl_xmss_secret_key_f set(_XMSS_OBJS ${_XMSS_OBJS} $) if (OQS_ENABLE_SIG_STFL_xmss_sha256_h10) - add_library(xmss_sha256_h10 OBJECT sig_stfl_xmss_sha256_h10.c ${SRCS}) + add_library(xmss_sha256_h10 OBJECT sig_stfl_xmss_sha256_h10.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_sha256_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha256_h10 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_sha256_h16) - add_library(xmss_sha256_h16 OBJECT sig_stfl_xmss_sha256_h16.c ${SRCS}) + add_library(xmss_sha256_h16 OBJECT sig_stfl_xmss_sha256_h16.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_sha256_h16 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha256_h16 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_sha256_h20) - add_library(xmss_sha256_h20 OBJECT sig_stfl_xmss_sha256_h20.c ${SRCS}) + add_library(xmss_sha256_h20 OBJECT sig_stfl_xmss_sha256_h20.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_sha256_h20 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha256_h20 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_shake128_h10) - add_library(xmss_shake128_h10 OBJECT sig_stfl_xmss_shake128_h10.c ${SRCS}) + add_library(xmss_shake128_h10 OBJECT sig_stfl_xmss_shake128_h10.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_shake128_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake128_h10 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_shake128_h16) - add_library(xmss_shake128_h16 OBJECT sig_stfl_xmss_shake128_h16.c ${SRCS}) + add_library(xmss_shake128_h16 OBJECT sig_stfl_xmss_shake128_h16.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_shake128_h16 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake128_h16 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_shake128_h20) - add_library(xmss_shake128_h20 OBJECT sig_stfl_xmss_shake128_h20.c ${SRCS}) + add_library(xmss_shake128_h20 OBJECT sig_stfl_xmss_shake128_h20.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_shake128_h20 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake128_h20 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_sha512_h10) - add_library(xmss_sha512_h10 OBJECT sig_stfl_xmss_sha512_h10.c ${SRCS}) + add_library(xmss_sha512_h10 OBJECT sig_stfl_xmss_sha512_h10.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_sha512_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha512_h10 -DHASH=6) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_sha512_h16) - add_library(xmss_sha512_h16 OBJECT sig_stfl_xmss_sha512_h16.c ${SRCS}) + add_library(xmss_sha512_h16 OBJECT sig_stfl_xmss_sha512_h16.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_sha512_h16 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha512_h16 -DHASH=6) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_sha512_h20) - add_library(xmss_sha512_h20 OBJECT sig_stfl_xmss_sha512_h20.c ${SRCS}) + add_library(xmss_sha512_h20 OBJECT sig_stfl_xmss_sha512_h20.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_sha512_h20 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_sha512_h20 -DHASH=6) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_shake256_h10) - add_library(xmss_shake256_h10 OBJECT sig_stfl_xmss_shake256_h10.c ${SRCS}) + add_library(xmss_shake256_h10 OBJECT sig_stfl_xmss_shake256_h10.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_shake256_h10 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake256_h10 -DHASH=7) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_shake256_h16) - add_library(xmss_shake256_h16 OBJECT sig_stfl_xmss_shake256_h16.c ${SRCS}) + add_library(xmss_shake256_h16 OBJECT sig_stfl_xmss_shake256_h16.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_shake256_h16 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake256_h16 -DHASH=7) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmss_shake256_h20) - add_library(xmss_shake256_h20 OBJECT sig_stfl_xmss_shake256_h20.c ${SRCS}) + add_library(xmss_shake256_h20 OBJECT sig_stfl_xmss_shake256_h20.c sig_stfl_xmss_functions.c ${SRCS}) target_compile_options(xmss_shake256_h20 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmss_shake256_h20 -DHASH=7) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2) - add_library(xmssmt_sha256_h20_2 OBJECT sig_stfl_xmssmt_sha256_h20_2.c ${SRCS}) + add_library(xmssmt_sha256_h20_2 OBJECT sig_stfl_xmssmt_sha256_h20_2.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_sha256_h20_2 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h20_2 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4) - add_library(xmssmt_sha256_h20_4 OBJECT sig_stfl_xmssmt_sha256_h20_4.c ${SRCS}) + add_library(xmssmt_sha256_h20_4 OBJECT sig_stfl_xmssmt_sha256_h20_4.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_sha256_h20_4 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h20_4 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2) - add_library(xmssmt_sha256_h40_2 OBJECT sig_stfl_xmssmt_sha256_h40_2.c ${SRCS}) + add_library(xmssmt_sha256_h40_2 OBJECT sig_stfl_xmssmt_sha256_h40_2.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_sha256_h40_2 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h40_2 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4) - add_library(xmssmt_sha256_h40_4 OBJECT sig_stfl_xmssmt_sha256_h40_4.c ${SRCS}) + add_library(xmssmt_sha256_h40_4 OBJECT sig_stfl_xmssmt_sha256_h40_4.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_sha256_h40_4 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h40_4 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8) - add_library(xmssmt_sha256_h40_8 OBJECT sig_stfl_xmssmt_sha256_h40_8.c ${SRCS}) + add_library(xmssmt_sha256_h40_8 OBJECT sig_stfl_xmssmt_sha256_h40_8.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_sha256_h40_8 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h40_8 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3) - add_library(xmssmt_sha256_h60_3 OBJECT sig_stfl_xmssmt_sha256_h60_3.c ${SRCS}) + add_library(xmssmt_sha256_h60_3 OBJECT sig_stfl_xmssmt_sha256_h60_3.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_sha256_h60_3 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h60_3 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6) - add_library(xmssmt_sha256_h60_6 OBJECT sig_stfl_xmssmt_sha256_h60_6.c ${SRCS}) + add_library(xmssmt_sha256_h60_6 OBJECT sig_stfl_xmssmt_sha256_h60_6.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_sha256_h60_6 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h60_6 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12) - add_library(xmssmt_sha256_h60_12 OBJECT sig_stfl_xmssmt_sha256_h60_12.c ${SRCS}) + add_library(xmssmt_sha256_h60_12 OBJECT sig_stfl_xmssmt_sha256_h60_12.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_sha256_h60_12 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_sha256_h60_12 -DHASH=3) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2) - add_library(xmssmt_shake128_h20_2 OBJECT sig_stfl_xmssmt_shake128_h20_2.c ${SRCS}) + add_library(xmssmt_shake128_h20_2 OBJECT sig_stfl_xmssmt_shake128_h20_2.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_shake128_h20_2 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h20_2 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4) - add_library(xmssmt_shake128_h20_4 OBJECT sig_stfl_xmssmt_shake128_h20_4.c ${SRCS}) + add_library(xmssmt_shake128_h20_4 OBJECT sig_stfl_xmssmt_shake128_h20_4.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_shake128_h20_4 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h20_4 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2) - add_library(xmssmt_shake128_h40_2 OBJECT sig_stfl_xmssmt_shake128_h40_2.c ${SRCS}) + add_library(xmssmt_shake128_h40_2 OBJECT sig_stfl_xmssmt_shake128_h40_2.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_shake128_h40_2 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h40_2 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4) - add_library(xmssmt_shake128_h40_4 OBJECT sig_stfl_xmssmt_shake128_h40_4.c ${SRCS}) + add_library(xmssmt_shake128_h40_4 OBJECT sig_stfl_xmssmt_shake128_h40_4.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_shake128_h40_4 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h40_4 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8) - add_library(xmssmt_shake128_h40_8 OBJECT sig_stfl_xmssmt_shake128_h40_8.c ${SRCS}) + add_library(xmssmt_shake128_h40_8 OBJECT sig_stfl_xmssmt_shake128_h40_8.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_shake128_h40_8 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h40_8 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3) - add_library(xmssmt_shake128_h60_3 OBJECT sig_stfl_xmssmt_shake128_h60_3.c ${SRCS}) + add_library(xmssmt_shake128_h60_3 OBJECT sig_stfl_xmssmt_shake128_h60_3.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_shake128_h60_3 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h60_3 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6) - add_library(xmssmt_shake128_h60_6 OBJECT sig_stfl_xmssmt_shake128_h60_6.c ${SRCS}) + add_library(xmssmt_shake128_h60_6 OBJECT sig_stfl_xmssmt_shake128_h60_6.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_shake128_h60_6 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h60_6 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() if (OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12) - add_library(xmssmt_shake128_h60_12 OBJECT sig_stfl_xmssmt_shake128_h60_12.c ${SRCS}) + add_library(xmssmt_shake128_h60_12 OBJECT sig_stfl_xmssmt_shake128_h60_12.c sig_stfl_xmssmt_functions.c ${SRCS}) target_compile_options(xmssmt_shake128_h60_12 PRIVATE -DXMSS_PARAMS_NAMESPACE=xmssmt_shake128_h60_12 -DHASH=4) set(_XMSS_OBJS ${_XMSS_OBJS} $) endif() diff --git a/src/sig_stfl/xmss/external/hash.c b/src/sig_stfl/xmss/external/hash.c index c335d7d680..a6bac00724 100644 --- a/src/sig_stfl/xmss/external/hash.c +++ b/src/sig_stfl/xmss/external/hash.c @@ -30,13 +30,17 @@ int prf(const xmss_params *params, unsigned char *out, const unsigned char in[32], const unsigned char *key) { - unsigned char buf[params->padding_len + params->n + 32]; + unsigned char* buf = malloc(params->padding_len + params->n + 32); ull_to_bytes(buf, params->padding_len, XMSS_HASH_PADDING_PRF); memcpy(buf + params->padding_len, key, params->n); memcpy(buf + params->padding_len + params->n, in, 32); - return core_hash(params, out, buf, params->padding_len + params->n + 32); + int ret = core_hash(params, out, buf, params->padding_len + params->n + 32); + + OQS_MEM_insecure_free(buf); + + return ret; } /* @@ -47,13 +51,17 @@ int prf_keygen(const xmss_params *params, unsigned char *out, const unsigned char *in, const unsigned char *key) { - unsigned char buf[params->padding_len + 2*params->n + 32]; + unsigned char *buf = malloc(params->padding_len + 2*params->n + 32); ull_to_bytes(buf, params->padding_len, XMSS_HASH_PADDING_PRF_KEYGEN); memcpy(buf + params->padding_len, key, params->n); memcpy(buf + params->padding_len + params->n, in, params->n + 32); - return core_hash(params, out, buf, params->padding_len + 2*params->n + 32); + int ret = core_hash(params, out, buf, params->padding_len + 2*params->n + 32); + + OQS_MEM_insecure_free(buf); + + return ret; } /* @@ -85,8 +93,11 @@ int thash_h(const xmss_params *params, unsigned char *out, const unsigned char *in, const unsigned char *pub_seed, uint32_t addr[8]) { - unsigned char buf[params->padding_len + 3 * params->n]; - unsigned char bitmask[2 * params->n]; + unsigned char *tmp = malloc(params->padding_len + 3 * params->n + 2 * params->n); + + unsigned char *buf = tmp; + unsigned char *bitmask = tmp + (params->padding_len + 3 * params->n); + unsigned char addr_as_bytes[32]; unsigned int i; @@ -110,15 +121,21 @@ int thash_h(const xmss_params *params, for (i = 0; i < 2 * params->n; i++) { buf[params->padding_len + params->n + i] = in[i] ^ bitmask[i]; } - return core_hash(params, out, buf, params->padding_len + 3 * params->n); + int ret = core_hash(params, out, buf, params->padding_len + 3 * params->n); + + OQS_MEM_insecure_free(tmp); + + return ret; } int thash_f(const xmss_params *params, unsigned char *out, const unsigned char *in, const unsigned char *pub_seed, uint32_t addr[8]) { - unsigned char buf[params->padding_len + 2 * params->n]; - unsigned char bitmask[params->n]; + unsigned char *tmp = malloc(params->padding_len + 2 * params->n + params->n); + unsigned char *buf = tmp; + unsigned char *bitmask = tmp + (params->padding_len + 2 * params->n); + unsigned char addr_as_bytes[32]; unsigned int i; @@ -138,5 +155,9 @@ int thash_f(const xmss_params *params, for (i = 0; i < params->n; i++) { buf[params->padding_len + params->n + i] = in[i] ^ bitmask[i]; } - return core_hash(params, out, buf, params->padding_len + 2 * params->n); + int ret = core_hash(params, out, buf, params->padding_len + 2 * params->n); + + OQS_MEM_insecure_free(tmp); + + return ret; } diff --git a/src/sig_stfl/xmss/external/sign.c b/src/sig_stfl/xmss/external/sign.c deleted file mode 100644 index 8bffc7f516..0000000000 --- a/src/sig_stfl/xmss/external/sign.c +++ /dev/null @@ -1,139 +0,0 @@ -/*============================================================================= - * Copyright (c) 2022 by SandboxAQ Inc - * Author: Duc Tri Nguyen (ductri.nguyen@sandboxaq.com) - * SPDX-License-Identifier: MIT -=============================================================================*/ -#include -#include - -#include "sign.h" -#include "sign_params.h" - -/************************************************* - * Name: XMSS_crypto_sign_keypair - * - * Description: Generates public and private key. - * - * Arguments: - uint8_t *pk: pointer to output public key (allocated - * array of CRYPTO_PUBLICKEYBYTES bytes) - * - uint8_t *sk: pointer to output private key (allocated - * array of CRYPTO_SECRETKEYBYTES bytes) - * - * Returns 0 (success), -1 otherwise - **************************************************/ -int crypto_sign_keypair(unsigned char *pk, unsigned char *sk) -{ - xmss_params params; - uint32_t oid; - int ret = 0; - - ret |= XMSS_STR_TO_OID(&oid, XMSS_OID); - if (ret) - { - return OQS_ERROR; - } - - ret |= XMSS_PARSE_OID(¶ms, oid); - if (ret) - { - return OQS_ERROR; - } - - // TODO: set OID directly here - ret |= XMSS_KEYPAIR(pk, sk, oid); - if (ret) - { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -/************************************************* - * Name: XMSS_crypto_sign - * - * Description: Computes signature. - * - * Arguments: - uint8_t *sm: pointer to output signature (of length CRYPTO_BYTES) - * - uint64_t *smlen: pointer to output length of signature - * - uint8_t *m: pointer to message to be signed - * - uint64_t mlen: length of message - * - uint8_t *sk: pointer to bit-packed secret key - * - * Returns 0 (success), -1 otherwise - **************************************************/ -int crypto_sign(unsigned char *sm, unsigned long long *smlen, - const unsigned char *m, unsigned long long mlen, unsigned char *sk) -{ - int ret = XMSS_SIGN(sk, sm, smlen, m, mlen); - if (ret) - { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -/************************************************* - * Name: XMSS_crypto_sign_open - * - * Description: Verify signed message. - * - * Arguments: - * - uint8_t *m: pointer to output message (allocated - * array with smlen bytes), can be equal to sm - * - uint64_t *mlen: pointer to output length of message - * - uint8_t *sm: pointer to signed message - * - uint64_t smlen: length of signed message - * - uint8_t *pk: pointer to bit-packed public key - * - * Returns 0 if signed message could be verified correctly and -1 otherwise - **************************************************/ -int crypto_sign_open(const unsigned char *m, unsigned long long mlen, - const unsigned char *sm, unsigned long long smlen, const unsigned char *pk) -{ - if (XMSS_SIGN_OPEN(m, mlen, sm, smlen, pk)) - { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -/************************************************* - * Name: XMSS_crypto_remaining_signatures - * - * Description: Return number of remaining signatures - * - * Arguments: - uint64_t *remain: remaining signatures - * - uint8_t *sk: pointer to bit-packed private key - * - * Returns 0 (sucess), -1 otherwise - **************************************************/ -int crypto_remaining_signatures(unsigned long long *remain, const unsigned char *sk) -{ - if (XMSS_REMAINING_SIG(remain, sk)) - { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -/************************************************* - * Name: XMSS_crypto_total_signatures - * - * Description: Return number of total signatures - * - * Arguments: - uint64_t *max: maximum number of signatures - * - uint8_t *sk: pointer to bit-packed private key - * - * Returns 0 (sucess), -1 otherwise - **************************************************/ -int crypto_total_signatures(unsigned long long *max, const unsigned char *sk) -{ - if (XMSS_TOTAL_SIG(max, sk)) - { - return OQS_ERROR; - } - return OQS_SUCCESS; -} diff --git a/src/sig_stfl/xmss/external/sign.h b/src/sig_stfl/xmss/external/sign.h deleted file mode 100644 index df2c2fb7ca..0000000000 --- a/src/sig_stfl/xmss/external/sign.h +++ /dev/null @@ -1,90 +0,0 @@ -/*============================================================================= - * Copyright (c) 2022 by SandboxAQ Inc - * Author: Duc Tri Nguyen (ductri.nguyen@sandboxaq.com) - * SPDX-License-Identifier: MIT -=============================================================================*/ -#ifndef API_H -#define API_H - -#include -#include "namespace.h" -/************************************************* - * Name: XMSS_crypto_sign_keypair - * - * Description: Generates public and private key. - * - * Arguments: - uint8_t *pk: pointer to output public key (allocated - * array of CRYPTO_PUBLICKEYBYTES bytes) - * - uint8_t *sk: pointer to output private key (allocated - * array of CRYPTO_SECRETKEYBYTES bytes) - * - * Returns 0 (success), -1 otherwise - **************************************************/ -#define crypto_sign_keypair XMSS_NAMESPACE(crypto_sign_keypair) -int crypto_sign_keypair(unsigned char *pk, unsigned char *sk); - -/************************************************* - * Name: XMSS_crypto_sign - * - * Description: Computes signature. - * - * Arguments: - uint8_t *sm: pointer to output signature (of length CRYPTO_BYTES) - * - uint64_t *smlen: pointer to output length of signature - * - uint8_t *m: pointer to message to be signed - * - uint64_t mlen: length of message - * - uint8_t *sk: pointer to bit-packed secret key - * - * Returns 0 (success), -1 otherwise - **************************************************/ -#define crypto_sign XMSS_NAMESPACE(crypto_sign) -int crypto_sign(unsigned char *sm, unsigned long long *smlen, - const unsigned char *m, unsigned long long mlen, unsigned char *sk); - -/************************************************* - * Name: XMSS_crypto_sign_open - * - * Description: Verify signed message. - * - * Arguments: - * - uint8_t *m: pointer to output message (allocated - * array with smlen bytes), can be equal to sm - * - uint64_t *mlen: pointer to output length of message - * - uint8_t *sm: pointer to signed message - * - uint64_t smlen: length of signed message - * - uint8_t *pk: pointer to bit-packed public key - * - * Returns 0 if signed message could be verified correctly and -1 otherwise - **************************************************/ -#define crypto_sign_open XMSS_NAMESPACE(crypto_sign_open) -int crypto_sign_open(const unsigned char *m, unsigned long long mlen, - const unsigned char *sm, unsigned long long smlen, const unsigned char *pk); - -/************************************************* - * Name: XMSS_crypto_remaining_signatures - * - * Description: Return number of signatures left - * - * Arguments: - uint64_t *remain: remaining signatures - * - uint8_t *sk: pointer to bit-packed private key - * - * Returns 0 (sucess), -1 otherwise - **************************************************/ -#define crypto_remaining_signatures XMSS_NAMESPACE(crypto_remaining_signatures) -int crypto_remaining_signatures(unsigned long long *remain, const unsigned char *sk); - - -/************************************************* - * Name: XMSS_crypto_total_signatures - * - * Description: Return number of total signatures - * - * Arguments: - uint64_t *max: maximum number of signatures - * - uint8_t *sk: pointer to bit-packed private key - * - * Returns 0 (sucess), -1 otherwise - **************************************************/ -#define crypto_total_signatures XMSS_NAMESPACE(crypto_total_signatures) -int crypto_total_signatures(unsigned long long *max, const unsigned char *sk); - -#endif - diff --git a/src/sig_stfl/xmss/external/utils.h b/src/sig_stfl/xmss/external/utils.h index 0cdf79475a..fc5df634a6 100644 --- a/src/sig_stfl/xmss/external/utils.h +++ b/src/sig_stfl/xmss/external/utils.h @@ -2,7 +2,7 @@ #define XMSS_UTILS_H #include "namespace.h" - +#include /** * Converts the value of 'in' to 'outlen' bytes in big-endian byte order. */ diff --git a/src/sig_stfl/xmss/external/wots.c b/src/sig_stfl/xmss/external/wots.c index 90a6bd74d0..09db90e55c 100644 --- a/src/sig_stfl/xmss/external/wots.c +++ b/src/sig_stfl/xmss/external/wots.c @@ -12,11 +12,11 @@ * Expands an n-byte array into a len*n byte array using the `prf_keygen` function. */ static void expand_seed(const xmss_params *params, - unsigned char *outseeds, const unsigned char *inseed, + unsigned char *outseeds, const unsigned char *inseed, const unsigned char *pub_seed, uint32_t addr[8]) { unsigned int i; - unsigned char buf[params->n + 32]; + unsigned char *buf = malloc(params->n + 32); set_hash_addr(addr, 0); set_key_and_mask(addr, 0); @@ -26,6 +26,8 @@ static void expand_seed(const xmss_params *params, addr_to_bytes(buf + params->n, addr); prf_keygen(params, outseeds + i*params->n, buf, inseed); } + + OQS_MEM_insecure_free(buf); } /** @@ -83,7 +85,8 @@ static void wots_checksum(const xmss_params *params, unsigned int *csum_base_w, const unsigned int *msg_base_w) { int csum = 0; - unsigned char csum_bytes[(params->wots_len2 * params->wots_log_w + 7) / 8]; + unsigned int csum_bytes_length = (params->wots_len2 * params->wots_log_w + 7) / 8; + unsigned char *csum_bytes = malloc(csum_bytes_length); unsigned int i; /* Compute checksum. */ @@ -94,8 +97,10 @@ static void wots_checksum(const xmss_params *params, /* Convert checksum to base_w. */ /* Make sure expected empty zero bits are the least significant bits. */ csum = csum << (8 - ((params->wots_len2 * params->wots_log_w) % 8)); - ull_to_bytes(csum_bytes, sizeof(csum_bytes), csum); + ull_to_bytes(csum_bytes, csum_bytes_length, csum); base_w(params, csum_base_w, params->wots_len2, csum_bytes); + + OQS_MEM_insecure_free(csum_bytes); } /* Takes a message and derives the matching chain lengths. */ @@ -139,11 +144,9 @@ void wots_sign(const xmss_params *params, const unsigned char *seed, const unsigned char *pub_seed, uint32_t addr[8]) { - unsigned int lengths[params->wots_len]; + unsigned int *lengths = calloc(params->wots_len, sizeof(unsigned int)); unsigned int i; - memset(lengths, 0, sizeof(unsigned int)*params->wots_len); - chain_lengths(params, lengths, msg); /* The WOTS+ private key is derived from the seed. */ @@ -154,6 +157,8 @@ void wots_sign(const xmss_params *params, gen_chain(params, sig + i*params->n, sig + i*params->n, 0, lengths[i], pub_seed, addr); } + + OQS_MEM_insecure_free(lengths); } /** @@ -165,11 +170,9 @@ void wots_pk_from_sig(const xmss_params *params, unsigned char *pk, const unsigned char *sig, const unsigned char *msg, const unsigned char *pub_seed, uint32_t addr[8]) { - unsigned int lengths[params->wots_len]; + unsigned int *lengths = calloc(params->wots_len, sizeof(unsigned int )); unsigned int i; - memset(lengths, 0, sizeof(unsigned int)*params->wots_len); - chain_lengths(params, lengths, msg); for (i = 0; i < params->wots_len; i++) { @@ -177,4 +180,6 @@ void wots_pk_from_sig(const xmss_params *params, unsigned char *pk, gen_chain(params, pk + i*params->n, sig + i*params->n, lengths[i], params->wots_w - 1 - lengths[i], pub_seed, addr); } + + OQS_MEM_insecure_free(lengths); } diff --git a/src/sig_stfl/xmss/external/xmss_commons.c b/src/sig_stfl/xmss/external/xmss_commons.c index 882a3e39d6..9838f755b0 100644 --- a/src/sig_stfl/xmss/external/xmss_commons.c +++ b/src/sig_stfl/xmss/external/xmss_commons.c @@ -57,7 +57,7 @@ static void compute_root(const xmss_params *params, unsigned char *root, const unsigned char *pub_seed, uint32_t addr[8]) { uint32_t i; - unsigned char buffer[2*params->n]; + unsigned char *buffer = malloc(2*params->n); /* If leafidx is odd (last bit = 1), current path element is a right child and auth_path has to go left. Otherwise it is the other way around. */ @@ -93,6 +93,8 @@ static void compute_root(const xmss_params *params, unsigned char *root, leafidx >>= 1; set_tree_index(addr, leafidx); thash_h(params, root, buffer, pub_seed, addr); + + OQS_MEM_insecure_free(buffer); } @@ -105,11 +107,13 @@ void gen_leaf_wots(const xmss_params *params, unsigned char *leaf, const unsigned char *sk_seed, const unsigned char *pub_seed, uint32_t ltree_addr[8], uint32_t ots_addr[8]) { - unsigned char pk[params->wots_sig_bytes]; + unsigned char *pk = malloc(params->wots_sig_bytes); wots_pkgen(params, pk, sk_seed, pub_seed, ots_addr); l_tree(params, leaf, pk, pub_seed, ltree_addr); + + OQS_MEM_insecure_free(pk); } @@ -140,16 +144,18 @@ int xmssmt_core_sign_open(const xmss_params *params, { const unsigned char *pub_root = pk; const unsigned char *pub_seed = pk + params->n; - unsigned char wots_pk[params->wots_sig_bytes]; - unsigned char leaf[params->n]; - unsigned char root[params->n]; + + unsigned char *tmp = malloc(params->wots_sig_bytes + params->n + params->n); + unsigned char *wots_pk = tmp; + unsigned char *leaf = tmp + params->wots_sig_bytes; + unsigned char *root = leaf + params->n; unsigned long long prefix_length = params->padding_len + 3*params->n; unsigned char m_with_prefix[mlen + prefix_length]; - + unsigned char *mhash = root; unsigned long long idx = 0; - unsigned int i; + unsigned int i, ret; uint32_t idx_leaf; uint32_t ots_addr[8] = {0}; @@ -209,8 +215,12 @@ int xmssmt_core_sign_open(const xmss_params *params, /* Check if the root node equals the root node in the public key. */ if (memcmp(root, pub_root, params->n)) { /* If not, return fail */ - return -1; + ret = -1; + goto fail; } + ret = 0; +fail: + OQS_MEM_insecure_free(tmp); + return ret; - return 0; } diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c index b3de5f17f0..4dd4c9b41d 100644 --- a/src/sig_stfl/xmss/external/xmss_core_fast.c +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -170,11 +170,11 @@ static void deep_state_swap(const xmss_params *params, } // TODO this is extremely ugly and should be refactored // TODO right now, this ensures that both 'stack' and 'retain' fit - unsigned char t[ + unsigned char *t = malloc( ((params->tree_height + 1) > ((1 << params->bds_k) - params->bds_k - 1) ? (params->tree_height + 1) : ((1 << params->bds_k) - params->bds_k - 1)) - * params->n]; + * params->n); unsigned int i; memswap(a->stack, b->stack, t, (params->tree_height + 1) * params->n); @@ -193,6 +193,8 @@ static void deep_state_swap(const xmss_params *params, memswap(a->retain, b->retain, t, ((1 << params->bds_k) - params->bds_k - 1) * params->n); memswap(&a->next_leaf, &b->next_leaf, t, sizeof(a->next_leaf)); + + OQS_MEM_insecure_free(t); } static int treehash_minheight_on_stack(const xmss_params *params, @@ -235,7 +237,7 @@ static void treehash_init(const xmss_params *params, uint32_t lastnode, i; unsigned char *stack = calloc((height+1)*params->n, sizeof(unsigned char)); - unsigned int stacklevels[height+1]; + unsigned int *stacklevels = malloc((height + 1)*sizeof(unsigned int)); unsigned int stackoffset=0; unsigned int nodeh; @@ -283,6 +285,7 @@ static void treehash_init(const xmss_params *params, node[i] = stack[i]; } + OQS_MEM_insecure_free(stacklevels); OQS_MEM_insecure_free(stack); } @@ -307,7 +310,7 @@ static void treehash_update(const xmss_params *params, set_ltree_addr(ltree_addr, treehash->next_idx); set_ots_addr(ots_addr, treehash->next_idx); - unsigned char nodebuffer[2 * params->n]; + unsigned char *nodebuffer = malloc(2 * params->n); unsigned int nodeheight = 0; gen_leaf_wots(params, nodebuffer, sk_seed, pub_seed, ltree_addr, ots_addr); while (treehash->stackusage > 0 && state->stacklevels[state->stackoffset-1] == nodeheight) { @@ -331,6 +334,8 @@ static void treehash_update(const xmss_params *params, state->stackoffset++; treehash->next_idx++; } + + OQS_MEM_insecure_free(nodebuffer); } /** @@ -454,7 +459,7 @@ static void bds_round(const xmss_params *params, unsigned int tau = params->tree_height; unsigned int startidx; unsigned int offset, rowidx; - unsigned char buf[2 * params->n]; + unsigned char *buf = malloc(2 * params->n); uint32_t ots_addr[8] = {0}; uint32_t ltree_addr[8] = {0}; @@ -514,6 +519,8 @@ static void bds_round(const xmss_params *params, } } } + + OQS_MEM_insecure_free(buf); } /** @@ -551,7 +558,7 @@ int xmss_core_keypair(const xmss_params *params, // TODO refactor BDS state not to need separate treehash instances bds_state state; - treehash_inst treehash[params->tree_height - params->bds_k]; + treehash_inst *treehash = calloc(params->tree_height - params->bds_k, sizeof(treehash_inst)); state.treehash = treehash; xmss_deserialize_state(params, &state, sk); @@ -580,6 +587,8 @@ int xmss_core_keypair(const xmss_params *params, /* Write the BDS state into sk. */ xmss_serialize_state(params, sk, &state); + OQS_MEM_insecure_free(treehash); + return 0; } @@ -601,12 +610,13 @@ int xmss_core_sign(const xmss_params *params, } const unsigned char *pub_root = sk + params->index_bytes + 2*params->n; + int ret; uint16_t i = 0; // TODO refactor BDS state not to need separate treehash instances bds_state state; - treehash_inst treehash[params->tree_height - params->bds_k]; + treehash_inst *treehash = calloc(params->tree_height - params->bds_k, sizeof(treehash_inst)); state.treehash = treehash; /* Load the BDS state from sk. */ @@ -617,29 +627,33 @@ int xmss_core_sign(const xmss_params *params, /* Check if we can still sign with this sk. * If not, return -2 - * - * If this is the last possible signature (because the max index value - * is reached), production implementations should delete the secret key + * + * If this is the last possible signature (because the max index value + * is reached), production implementations should delete the secret key * to prevent accidental further use. - * - * For the case of total tree height of 64 we do not use the last signature - * to be on the safe side (there is no index value left to indicate that the + * + * For the case of total tree height of 64 we do not use the last signature + * to be on the safe side (there is no index value left to indicate that the * key is finished, hence external handling would be necessary) - */ + */ if (idx >= ((1ULL << params->full_height) - 1)) { // Delete secret key here. We only do this in memory, production code // has to make sure that this happens on disk. memset(sk, 0xFF, params->index_bytes); memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); - if (idx > ((1ULL << params->full_height) - 1)) - return -2; // We already used all one-time keys + if (idx > ((1ULL << params->full_height) - 1)) { + ret = -2; // We already used all one-time keys + goto cleanup; + } } - - unsigned char sk_seed[params->n]; + unsigned char *tmp = malloc(5 * params->n); + + unsigned char *sk_seed = tmp; + unsigned char *sk_prf = sk_seed + params->n; + unsigned char *pub_seed = sk_prf + params->n; + memcpy(sk_seed, sk + params->index_bytes, params->n); - unsigned char sk_prf[params->n]; memcpy(sk_prf, sk + params->index_bytes + params->n, params->n); - unsigned char pub_seed[params->n]; memcpy(pub_seed, sk + params->index_bytes + 3*params->n, params->n); // index as 32 bytes string @@ -656,8 +670,8 @@ int xmss_core_sign(const xmss_params *params, // and write the updated secret key at this point! // Init working params - unsigned char R[params->n]; - unsigned char msg_h[params->n]; + unsigned char *R = pub_seed + params->n; + unsigned char *msg_h = R + params->n; uint32_t ots_addr[8] = {0}; // --------------------------------- @@ -671,7 +685,7 @@ int xmss_core_sign(const xmss_params *params, /* Already put the message in the right place, to make it easier to prepend * things when computing the hash over the message. */ unsigned long long prefix_length = params->padding_len + 3*params->n; - unsigned char m_with_prefix[mlen + prefix_length]; + unsigned char *m_with_prefix = malloc(mlen + prefix_length); memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); memcpy(m_with_prefix + prefix_length, m, mlen); @@ -727,7 +741,15 @@ int xmss_core_sign(const xmss_params *params, /* Write the updated BDS state back into sk. */ xmss_serialize_state(params, sk, &state); - return 0; + ret = 0; + + OQS_MEM_insecure_free(m_with_prefix); + OQS_MEM_insecure_free(tmp); + +cleanup: + OQS_MEM_insecure_free(treehash); + + return ret; } /* @@ -743,8 +765,8 @@ int xmssmt_core_keypair(const xmss_params *params, unsigned char *wots_sigs; // TODO refactor BDS state not to need separate treehash instances - bds_state states[2*params->d - 1]; - treehash_inst treehash[(2*params->d - 1) * (params->tree_height - params->bds_k)]; + bds_state *states = calloc(2*params->d - 1, sizeof(bds_state)); + treehash_inst *treehash = calloc((2*params->d - 1) * (params->tree_height - params->bds_k), sizeof(treehash_inst)); for (i = 0; i < 2*params->d - 1; i++) { states[i].treehash = treehash + i * (params->tree_height - params->bds_k); } @@ -783,6 +805,9 @@ int xmssmt_core_keypair(const xmss_params *params, xmssmt_serialize_state(params, sk, states); + OQS_MEM_insecure_free(treehash); + OQS_MEM_insecure_free(states); + return 0; } @@ -811,12 +836,14 @@ int xmssmt_core_sign(const xmss_params *params, int needswap_upto = -1; unsigned int updates; - unsigned char sk_seed[params->n]; - unsigned char sk_prf[params->n]; - unsigned char pub_seed[params->n]; + unsigned char *tmp = malloc(5 * params->n); + + unsigned char *sk_seed = tmp; + unsigned char *sk_prf = sk_seed + params->n; + unsigned char *pub_seed = sk_prf + params->n; // Init working params - unsigned char R[params->n]; - unsigned char msg_h[params->n]; + unsigned char *R = pub_seed + params->n; + unsigned char *msg_h = R + params->n; uint32_t addr[8] = {0}; uint32_t ots_addr[8] = {0}; unsigned char idx_bytes_32[32]; @@ -828,7 +855,7 @@ int xmssmt_core_sign(const xmss_params *params, // TODO refactor BDS state not to need separate treehash instances bds_state *states = calloc(2*params->d - 1, sizeof(bds_state)); - treehash_inst treehash[(2*params->d - 1) * (params->tree_height - params->bds_k)]; + treehash_inst *treehash = calloc((2*params->d - 1) * (params->tree_height - params->bds_k), sizeof(treehash_inst)); for (i = 0; i < 2*params->d - 1; i++) { states[i].stack = NULL; states[i].stackoffset = 0; @@ -850,15 +877,15 @@ int xmssmt_core_sign(const xmss_params *params, /* Check if we can still sign with this sk. * If not, return -2 - * - * If this is the last possible signature (because the max index value - * is reached), production implementations should delete the secret key + * + * If this is the last possible signature (because the max index value + * is reached), production implementations should delete the secret key * to prevent accidental further use. - * - * For the case of total tree height of 64 we do not use the last signature - * to be on the safe side (there is no index value left to indicate that the + * + * For the case of total tree height of 64 we do not use the last signature + * to be on the safe side (there is no index value left to indicate that the * key is finished, hence external handling would be necessary) - */ + */ if (idx >= ((1ULL << params->full_height) - 1)) { // Delete secret key here. We only do this in memory, production code // has to make sure that this happens on disk. @@ -870,7 +897,7 @@ int xmssmt_core_sign(const xmss_params *params, goto cleanup; } } - + memcpy(sk_seed, sk+params->index_bytes, params->n); memcpy(sk_prf, sk+params->index_bytes+params->n, params->n); memcpy(pub_seed, sk+params->index_bytes+3*params->n, params->n); @@ -1012,10 +1039,11 @@ int xmssmt_core_sign(const xmss_params *params, } xmssmt_serialize_state(params, sk, states); - goto cleanup; cleanup: + OQS_MEM_insecure_free(treehash); OQS_MEM_insecure_free(states); + OQS_MEM_insecure_free(tmp); return ret; } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index 8b9536daed..d1663f1720 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -4,50 +4,55 @@ #define OQS_SIG_STFL_XMSS_H #include +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif #define XMSS_OID_LEN 4 -void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); /* - * | Algorithms | oid | sk | pk | sig | n | - * |-------------------------------|------|--------|-----|------|----| - * | XMSS-SHA2_10_256 | 0x01 | 1373 | 64 | 2500 | 32 | - * | XMSS-SHA2_16_256 | 0x02 | 2093 | 64 | 2692 | 32 | - * | XMSS-SHA2_20_256 | 0x03 | 2573 | 64 | 2820 | 32 | + * | Algorithms | oid | sk (b) | pk (b) | sig (b) | n | + * |-------------------------------|------|--------|--------|---------|----| + * | XMSS-SHA2_10_256 | 0x01 | 1373 | 64 | 2500 | 32 | + * | XMSS-SHA2_16_256 | 0x02 | 2093 | 64 | 2692 | 32 | + * | XMSS-SHA2_20_256 | 0x03 | 2573 | 64 | 2820 | 32 | * - * | XMSS-SHAKE_10_256 | 0x07 | 1373 | 64 | 2500 | 32 | - * | XMSS-SHAKE_16_256 | 0x08 | 2093 | 64 | 2692 | 32 | - * | XMSS-SHAKE_20_256 | 0x09 | 2573 | 64 | 2820 | 32 | + * | XMSS-SHAKE_10_256 | 0x07 | 1373 | 64 | 2500 | 32 | + * | XMSS-SHAKE_16_256 | 0x08 | 2093 | 64 | 2692 | 32 | + * | XMSS-SHAKE_20_256 | 0x09 | 2573 | 64 | 2820 | 32 | * - * | XMSS-SHA2_10_512 | 0x04 | 2653 | 128 | 9092 | 64 | - * | XMSS-SHA2_16_512 | 0x05 | 4045 | 128 | 9476 | 64 | - * | XMSS-SHA2_20_512 | 0x06 | 4973 | 128 | 9732 | 64 | + * | XMSS-SHA2_10_512 | 0x04 | 2653 | 128 | 9092 | 64 | + * | XMSS-SHA2_16_512 | 0x05 | 4045 | 128 | 9476 | 64 | + * | XMSS-SHA2_20_512 | 0x06 | 4973 | 128 | 9732 | 64 | * - * | XMSS-SHAKE_10_512 | 0x0a | 2653 | 128 | 9092 | 64 | - * | XMSS-SHAKE_16_512 | 0x0b | 4045 | 128 | 9476 | 64 | - * | XMSS-SHAKE_20_512 | 0x0c | 4973 | 128 | 9732 | 64 | + * | XMSS-SHAKE_10_512 | 0x0a | 2653 | 128 | 9092 | 64 | + * | XMSS-SHAKE_16_512 | 0x0b | 4045 | 128 | 9476 | 64 | + * | XMSS-SHAKE_20_512 | 0x0c | 4973 | 128 | 9732 | 64 | * - * | XMSSMT-SHA2_20/2_256 | 0x01 | 5998 | 64 | 4963 | 32 | - * | XMSSMT-SHA2_20/4_256 | 0x02 | 10938 | 64 | 9251 | 32 | - * | XMSSMT-SHA2_40/2_256 | 0x03 | 9600 | 64 | 5605 | 32 | - * | XMSSMT-SHA2_40/4_256 | 0x04 | 15252 | 64 | 9893 | 32 | - * | XMSSMT-SHA2_40/8_256 | 0x05 | 24516 | 64 | 18469 | 32 | - * | XMSSMT-SHA2_60/3_256 | 0x06 | 16629 | 64 | 8392 | 32 | - * | XMSSMT-SHA2_60/6_256 | 0x07 | 24507 | 64 | 14824 | 32 | - * | XMSSMT-SHA2_60/12_256 | 0x08 | 38095 | 64 | 27688 | 32 | + * | XMSSMT-SHA2_20/2_256 | 0x01 | 5998 | 64 | 4963 | 32 | + * | XMSSMT-SHA2_20/4_256 | 0x02 | 10938 | 64 | 9251 | 32 | + * | XMSSMT-SHA2_40/2_256 | 0x03 | 9600 | 64 | 5605 | 32 | + * | XMSSMT-SHA2_40/4_256 | 0x04 | 15252 | 64 | 9893 | 32 | + * | XMSSMT-SHA2_40/8_256 | 0x05 | 24516 | 64 | 18469 | 32 | + * | XMSSMT-SHA2_60/3_256 | 0x06 | 16629 | 64 | 8392 | 32 | + * | XMSSMT-SHA2_60/6_256 | 0x07 | 24507 | 64 | 14824 | 32 | + * | XMSSMT-SHA2_60/12_256 | 0x08 | 38095 | 64 | 27688 | 32 | * - * | XMSSMT-SHAKE_20/2_256 | 0x11 | 5998 | 64 | 4963 | 32 | - * | XMSSMT-SHAKE_20/4_256 | 0x12 | 10938 | 64 | 9251 | 32 | - * | XMSSMT-SHAKE_40/2_256 | 0x13 | 9600 | 64 | 5605 | 32 | - * | XMSSMT-SHAKE_40/4_256 | 0x14 | 15252 | 64 | 9893 | 32 | - * | XMSSMT-SHAKE_40/8_256 | 0x15 | 24516 | 64 | 18469 | 32 | - * | XMSSMT-SHAKE_60/3_256 | 0x16 | 16629 | 64 | 8392 | 32 | - * | XMSSMT-SHAKE_60/6_256 | 0x17 | 24507 | 64 | 14824 | 32 | - * | XMSSMT-SHAKE_60/12_256 | 0x18 | 38095 | 64 | 27688 | 32 | + * | XMSSMT-SHAKE_20/2_256 | 0x11 | 5998 | 64 | 4963 | 32 | + * | XMSSMT-SHAKE_20/4_256 | 0x12 | 10938 | 64 | 9251 | 32 | + * | XMSSMT-SHAKE_40/2_256 | 0x13 | 9600 | 64 | 5605 | 32 | + * | XMSSMT-SHAKE_40/4_256 | 0x14 | 15252 | 64 | 9893 | 32 | + * | XMSSMT-SHAKE_40/8_256 | 0x15 | 24516 | 64 | 18469 | 32 | + * | XMSSMT-SHAKE_60/3_256 | 0x16 | 16629 | 64 | 8392 | 32 | + * | XMSSMT-SHAKE_60/6_256 | 0x17 | 24507 | 64 | 14824 | 32 | + * | XMSSMT-SHAKE_60/12_256 | 0x18 | 38095 | 64 | 27688 | 32 | */ #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h10 +#define OQS_SIG_STFL_alg_xmss_sha256_h10_oid 0x01 #define OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk (1373 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature 2500 @@ -64,6 +69,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long lon #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 +#define OQS_SIG_STFL_alg_xmss_sha256_h16_oid 0x02 #define OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk (2093 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha256_h16_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha256_h16_length_signature 2692 @@ -80,6 +86,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long lon #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 +#define OQS_SIG_STFL_alg_xmss_sha256_h20_oid 0x03 #define OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk (2573 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha256_h20_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha256_h20_length_signature 2820 @@ -96,6 +103,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long lon #ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h10 +#define OQS_SIG_STFL_alg_xmss_shake128_h10_oid 0x07 #define OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk (1373 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake128_h10_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake128_h10_length_signature 2500 @@ -112,6 +120,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long l #ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 +#define OQS_SIG_STFL_alg_xmss_shake128_h16_oid 0x08 #define OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk (2093 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake128_h16_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake128_h16_length_signature 2692 @@ -128,6 +137,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long l #ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 +#define OQS_SIG_STFL_alg_xmss_shake128_h20_oid 0x09 #define OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk (2573 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake128_h20_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake128_h20_length_signature 2820 @@ -144,6 +154,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long l #ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h10 +#define OQS_SIG_STFL_alg_xmss_sha512_h10_oid 0x04 #define OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk (2653 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha512_h10_length_pk (128 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha512_h10_length_signature 9092 @@ -160,6 +171,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long lon #ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 +#define OQS_SIG_STFL_alg_xmss_sha512_h16_oid 0x05 #define OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk (4045 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha512_h16_length_pk (128 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha512_h16_length_signature 9476 @@ -176,6 +188,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long lon #ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 +#define OQS_SIG_STFL_alg_xmss_sha512_h20_oid 0x06 #define OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk (4973 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha512_h20_length_pk (128 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_sha512_h20_length_signature 9732 @@ -192,6 +205,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long lon #ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h10 +#define OQS_SIG_STFL_alg_xmss_shake256_h10_oid 0x0a #define OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk (2653 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake256_h10_length_pk (128 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake256_h10_length_signature 9092 @@ -208,6 +222,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long l #ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 +#define OQS_SIG_STFL_alg_xmss_shake256_h16_oid 0x0b #define OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk (4045 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake256_h16_length_pk (128 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake256_h16_length_signature 9476 @@ -224,6 +239,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long l #ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 +#define OQS_SIG_STFL_alg_xmss_shake256_h20_oid 0x0c #define OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk (4973 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake256_h20_length_pk (128 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmss_shake256_h20_length_signature 9732 @@ -240,6 +256,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long l #ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_2 +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_oid 0x01 #define OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk (5998 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_signature 4963 @@ -256,6 +273,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long #ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h20_4 +#define OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_oid 0x02 #define OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk (10938 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_signature 9251 @@ -272,6 +290,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long #ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_oid 0x03 #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk (9600 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_signature 5605 @@ -288,6 +307,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long #ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_4 +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_oid 0x04 #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk (15252 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_signature 9893 @@ -304,6 +324,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long #ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_8 +#define OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_oid 0x05 #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk (24516 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_signature 18469 @@ -320,6 +341,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long #ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_oid 0x06 #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk (16629 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_signature 8392 @@ -336,6 +358,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long #ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_6 +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_oid 0x07 #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk (24507 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_signature 14824 @@ -352,6 +375,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long #ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_12 +#define OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_oid 0x08 #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk (38095 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_signature 27688 @@ -368,6 +392,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned lon #ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_2 +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_oid 0x11 #define OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk (5998 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_signature 4963 @@ -384,6 +409,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned lo #ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h20_4 +#define OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_oid 0x12 #define OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk (10938 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_signature 9251 @@ -400,6 +426,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned lo #ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_oid 0x13 #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk (9600 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_signature 5605 @@ -416,6 +443,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned lo #ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_4 +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_oid 0x14 #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk (15252 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_signature 9893 @@ -432,6 +460,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned lo #ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_8 +#define OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_oid 0x15 #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk (24516 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_signature 18469 @@ -448,6 +477,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned lo #ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_oid 0x16 #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk (16629 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_signature 8392 @@ -464,6 +494,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned lo #ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_oid 0x17 #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk (24507 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_signature 14824 @@ -480,6 +511,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned lo #ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 +#define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_oid 0x18 #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk (38095 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_pk (64 + XMSS_OID_LEN) #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_signature 27688 @@ -494,16 +526,65 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned l #endif +#define __alg_xmss_XMSS(funcname, postfix) funcname##_##postfix +#define _alg_xmss_XMSS(funcname, postfix) __alg_xmss_XMSS(funcname, postfix) +#define OQS_SIG_STFL_alg_xmss_NAMESPACE(funcname) _alg_xmss_XMSS(funcname, XMSS_PARAMS_NAMESPACE) + +/* + * Generic XMSS APIs + */ +#define OQS_SIG_STFL_alg_xmss_sign OQS_SIG_STFL_alg_xmss_NAMESPACE(OQS_SIG_STFL_alg_xmss_sign) +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key); + +#define OQS_SIG_STFL_alg_xmss_verify OQS_SIG_STFL_alg_xmss_NAMESPACE(OQS_SIG_STFL_alg_xmss_verify) +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key); + +#define OQS_SIG_STFL_alg_xmss_sigs_remaining OQS_SIG_STFL_alg_xmss_NAMESPACE(OQS_SIG_STFL_alg_xmss_sigs_remaining) +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); + +#define OQS_SIG_STFL_alg_xmss_sigs_total OQS_SIG_STFL_alg_xmss_NAMESPACE(OQS_SIG_STFL_alg_xmss_sigs_total) +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); + +/* + * Generic XMSS^MT APIs + */ +#define OQS_SIG_STFL_alg_xmssmt_sign OQS_SIG_STFL_alg_xmss_NAMESPACE(OQS_SIG_STFL_alg_xmssmt_sign) +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key); + +#define OQS_SIG_STFL_alg_xmssmt_verify OQS_SIG_STFL_alg_xmss_NAMESPACE(OQS_SIG_STFL_alg_xmssmt_verify) +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key); + +#define OQS_SIG_STFL_alg_xmssmt_sigs_remaining OQS_SIG_STFL_alg_xmss_NAMESPACE(OQS_SIG_STFL_alg_xmssmt_sigs_remaining) +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); + +#define OQS_SIG_STFL_alg_xmssmt_sigs_total OQS_SIG_STFL_alg_xmss_NAMESPACE(OQS_SIG_STFL_alg_xmssmt_sigs_total) +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); + /* * Secret key functions */ -/* Serialize XMSS secret key data into a byte string */ -OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr); +/* Generic XMSS SECRET_KEY object initialization */ +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_new(size_t length_secret_key); + +/* Serialize XMSS secret key data into a byte string, and return an allocated buffer. Users must deallocate the buffer. */ +OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); + +/* Only for internal use. Similar to OQS_SECRET_KEY_XMSS_serialize_key, this function does not acquire and release a lock. */ +OQS_STATUS OQS_SECRET_KEY_XMSS_inner_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); /* Deserialize XMSS byte string into an XMSS secret key data */ OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); -/* Set XMSS byte string into an XMSS secret key data */ +/* Store Secret Key Function, ideally written to secure device */ void OQS_SECRET_KEY_XMSS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); +/* Free Secret key object */ +void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); + +/* Lock the key if possible */ +void OQS_SECRET_KEY_XMSS_acquire_lock(const OQS_SIG_STFL_SECRET_KEY *sk); + +/* Unlock the key if possible */ +void OQS_SECRET_KEY_XMSS_release_lock(const OQS_SIG_STFL_SECRET_KEY *sk); + #endif /* OQS_SIG_STFL_XMSS_H */ diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c new file mode 100644 index 0000000000..bfdf3e023b --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c @@ -0,0 +1,99 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +/* -------------- XMSS -------------- */ + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + + OQS_STATUS status = OQS_SUCCESS; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { + return OQS_ERROR; + } + + /* Don't even attempt signing without a way to safe the updated private key */ + if (secret_key->secure_store_scrt_key == NULL) { + return OQS_ERROR; + } + + /* Lock secret to ensure OTS use */ + OQS_SECRET_KEY_XMSS_acquire_lock(secret_key); + + if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + /* + * serialize and securely store the updated private key + * regardless, delete signature and the serialized key other wise + */ + + status = OQS_SECRET_KEY_XMSS_inner_serialize_key(&sk_key_buf_ptr, &sk_key_buf_len, secret_key); + if (status != OQS_SUCCESS) { + goto err; + } + + // Store updated private key securely + status = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); + +err: + /* Unlock secret to ensure OTS use */ + OQS_SECRET_KEY_XMSS_release_lock(secret_key); + + return status; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmss_sign_open(message, (unsigned long long)message_len, signature, (unsigned long long)signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { + return OQS_ERROR; + } + + if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { + return OQS_ERROR; + } + + if (xmss_total_signatures(total, secret_key->secret_key_data)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index a9ea864cdb..cfeab4548e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -2,6 +2,7 @@ #include #include +#include #include "sig_stfl_xmss.h" #if defined(__GNUC__) || defined(__clang__) @@ -10,12 +11,68 @@ #define XMSS_UNUSED_ATT #endif -/* Serialize XMSS secret key data into a byte string */ -OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, size_t *sk_len, uint8_t **sk_buf_ptr) { +extern inline +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_new(size_t length_secret_key) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + sk->length_secret_key = length_secret_key; + + // Secret serialize/deserialize function + sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; + sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; + + // Initialize the key with length_secret_key amount of bytes. + sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); + + if (sk->secret_key_data == NULL) { + OQS_MEM_insecure_free(sk); + return NULL; + } + + memset(sk->secret_key_data, 0, sk->length_secret_key); + + // Set application specific context + sk->context = NULL; + + // Point to associated OQS_SIG_STFL object + sk->sig = NULL; + + // Mutual exclusion struct + sk->mutex = NULL; + + // Set Secret Key locking function + sk->lock_key = NULL; + + // Set Secret Key unlocking / releasing function + sk->unlock_key = NULL; + + // Set Secret Key saving function + sk->secure_store_scrt_key = NULL; + + // Set Secret Key store callback function + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; + + // Set Secret Key free function + sk->free_key = OQS_SECRET_KEY_XMSS_free; + + return sk; +} + +/* Serialize XMSS secret key data into a byte string, return an allocated buffer. Users have to unallocated the buffer. */ +OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk) { if (sk == NULL || sk_len == NULL || sk_buf_ptr == NULL) { return OQS_ERROR; } + /* Lock the key if possible */ + OQS_SECRET_KEY_XMSS_acquire_lock(sk); + uint8_t *sk_buf = malloc(sk->length_secret_key * sizeof(uint8_t)); if (sk_buf == NULL) { return OQS_ERROR; @@ -27,37 +84,79 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(const OQS_SIG_STFL_SECRET_KEY *sk, *sk_buf_ptr = sk_buf; *sk_len = sk->length_secret_key; + /* Unlock the key if possible */ + OQS_SECRET_KEY_XMSS_release_lock(sk); + return OQS_SUCCESS; } -/* Deserialize XMSS byte string into an XMSS secret key data */ -OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, XMSS_UNUSED_ATT void *context) { - if (sk == NULL || sk_buf == NULL || (sk_len != sk->length_secret_key)) { +/* Only for internal use. Similar to OQS_SECRET_KEY_XMSS_serialize_key, but this function does not aquire and release lock. */ +OQS_STATUS OQS_SECRET_KEY_XMSS_inner_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL || sk_len == NULL || sk_buf_ptr == NULL) { return OQS_ERROR; } - if (sk->secret_key_data != NULL) { - OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); - sk->secret_key_data = NULL; + uint8_t *sk_buf = malloc(sk->length_secret_key * sizeof(uint8_t)); + if (sk_buf == NULL) { + return OQS_ERROR; } - // Assume key data is not present - sk->secret_key_data = malloc(sk_len); - if (sk->secret_key_data == NULL) { + // Simply copy byte string of secret_key_data + memcpy(sk_buf, sk->secret_key_data, sk->length_secret_key); + + *sk_buf_ptr = sk_buf; + *sk_len = sk->length_secret_key; + + return OQS_SUCCESS; +} + +/* Deserialize XMSS byte string into an XMSS secret key data. */ +OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, XMSS_UNUSED_ATT void *context) { + if (sk == NULL || sk_buf == NULL || (sk_len != sk->length_secret_key)) { return OQS_ERROR; } + memcpy(sk->secret_key_data, sk_buf, sk->length_secret_key); sk->context = context; - memcpy(sk->secret_key_data, sk_buf, sk_len); return OQS_SUCCESS; } void OQS_SECRET_KEY_XMSS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { - if (!sk || !store_cb || !context) { + if (sk == NULL || store_cb == NULL) { return; } - - sk->context = context; sk->secure_store_scrt_key = store_cb; + sk->context = context; +} + +void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return; + } + + OQS_MEM_secure_free(sk->secret_key_data, sk->length_secret_key); + sk->secret_key_data = NULL; +} + +void OQS_SECRET_KEY_XMSS_acquire_lock(const OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return; + } + + /* Lock the key if possible */ + if ((sk->lock_key != NULL) && (sk->mutex != NULL)) { + sk->lock_key(sk->mutex); + } +} + +void OQS_SECRET_KEY_XMSS_release_lock(const OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL) { + return; + } + + /* Unlock the key if possible */ + if ((sk->unlock_key != NULL) && (sk->mutex != NULL)) { + sk->unlock_key(sk->mutex); + } } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index 2affc67195..849839ef0d 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_sha256_h10_oid; sig->method_name = "XMSS-SHA2_10_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,35 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -79,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint return OQS_ERROR; } - const uint32_t xmss_sha256_h10_oid = 0x01; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha256_h10_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha256_h10_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long)message_len, signature, (unsigned long long)signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index cfaa958dd7..53fd443a44 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h16_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_sha256_h16_oid; sig->method_name = "XMSS-SHA2_16_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h16_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(XMSS_UNUSED_ATT uint return OQS_ERROR; } - const uint32_t xmss_sha256_h16_oid = 0x02; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha256_h16_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha256_h16_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index 1145d17e2b..a95007730b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h20_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_sha256_h20_oid; sig->method_name = "XMSS-SHA2_20_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h20_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(XMSS_UNUSED_ATT uint return OQS_ERROR; } - const uint32_t xmss_sha256_h20_oid = 0x03; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha256_h20_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha256_h20_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index c7ca88eee7..6c382dcabb 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h10_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_sha512_h10_oid; sig->method_name = "XMSS-SHA2_10_512"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h10_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(XMSS_UNUSED_ATT uint return OQS_ERROR; } - const uint32_t xmss_sha512_h10_oid = 0x04; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha512_h10_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha512_h10_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index 70123ccb16..c9b2a3e51e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h16_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_sha512_h16_oid; sig->method_name = "XMSS-SHA2_16_512"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h16_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(XMSS_UNUSED_ATT uint return OQS_ERROR; } - const uint32_t xmss_sha512_h16_oid = 0x05; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha512_h16_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha512_h16_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index ebb03643a6..817004658b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h20_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_sha512_h20_oid; sig->method_name = "XMSS-SHA2_20_512"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h20_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(XMSS_UNUSED_ATT uint return OQS_ERROR; } - const uint32_t xmss_sha512_h20_oid = 0x06; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_sha512_h20_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha512_h20_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index 4d15d86461..971b3de4ed 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h10_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_shake128_h10_oid; sig->method_name = "XMSS-SHAKE_10_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h10_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(XMSS_UNUSED_ATT ui return OQS_ERROR; } - const uint32_t xmss_shake128_h10_oid = 0x07; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake128_h10_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake128_h10_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index 499ba294ad..93abb5d6e2 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h16_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_shake128_h16_oid; sig->method_name = "XMSS-SHAKE_16_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h16_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(XMSS_UNUSED_ATT ui return OQS_ERROR; } - const uint32_t xmss_shake128_h16_oid = 0x08; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake128_h16_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake128_h16_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } + diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index 8f47a4f825..1e320ed7ba 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h20_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_shake128_h20_oid; sig->method_name = "XMSS-SHAKE_20_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h20_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(XMSS_UNUSED_ATT ui return OQS_ERROR; } - const uint32_t xmss_shake128_h20_oid = 0x09; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake128_h20_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake128_h20_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = oqs_serialize_lms_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index 944a34d9de..d67c17015b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h10_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_shake256_h10_oid; sig->method_name = "XMSS-SHAKE_10_512"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h10_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(XMSS_UNUSED_ATT ui return OQS_ERROR; } - const uint32_t xmss_shake256_h10_oid = 0x0a; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake256_h10_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake256_h10_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index 93e8791bf8..e938187119 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h16_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_shake256_h16_oid; sig->method_name = "XMSS-SHAKE_16_512"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h16_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(XMSS_UNUSED_ATT ui return OQS_ERROR; } - const uint32_t xmss_shake256_h16_oid = 0x0b; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake256_h16_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake256_h16_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } + diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index e701614e79..15f591466e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h20_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmss_shake256_h20_oid; sig->method_name = "XMSS-SHAKE_20_512"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h20_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(XMSS_UNUSED_ATT ui return OQS_ERROR; } - const uint32_t xmss_shake256_h20_oid = 0x0c; - if (xmss_keypair(public_key, secret_key->secret_key_data, xmss_shake256_h20_oid)) { + if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake256_h20_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmss_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c new file mode 100644 index 0000000000..d1aa9e923d --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c @@ -0,0 +1,99 @@ +// SPDX-License-Identifier: MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + +/* -------------- XMSSMT -------------- */ + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + + OQS_STATUS status = OQS_SUCCESS; + uint8_t *sk_key_buf_ptr = NULL; + unsigned long long sig_length = 0; + size_t sk_key_buf_len = 0; + + if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { + return OQS_ERROR; + } + + /* Don't even attempt signing without a way to safe the updated private key */ + if (secret_key->secure_store_scrt_key == NULL) { + return OQS_ERROR; + } + + /* Lock secret to ensure OTS use */ + OQS_SECRET_KEY_XMSS_acquire_lock(secret_key); + + if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { + status = OQS_ERROR; + goto err; + } + *signature_len = (size_t)sig_length; + /* + * serialize and securely store the updated private key + * regardless, delete signature and the serialized key other wise + */ + + status = OQS_SECRET_KEY_XMSS_inner_serialize_key(&sk_key_buf_ptr, &sk_key_buf_len, secret_key); + if (status != OQS_SUCCESS) { + goto err; + } + + // Store updated private key securely + status = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); + OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); + +err: + /* Unlock secret to ensure OTS use */ + OQS_SECRET_KEY_XMSS_release_lock(secret_key); + + return status; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { + + if (message == NULL || signature == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (xmssmt_sign_open(message, (unsigned long long)message_len, signature, (unsigned long long)signature_len, public_key)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { + return OQS_ERROR; + } + + if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { + return OQS_ERROR; + } + + if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { + return OQS_ERROR; + } + + return OQS_SUCCESS; +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index f333b08a0e..ab3c2d6765 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_oid; sig->method_name = "XMSSMT-SHA2_20/2_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(XMSS_UNUSED_ATT return OQS_ERROR; } - const uint32_t xmssmt_sha256_h20_2_oid = 0x01; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h20_2_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index 76febd3103..62df91e621 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_oid; sig->method_name = "XMSSMT-SHA2_20/4_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(XMSS_UNUSED_ATT return OQS_ERROR; } - const uint32_t xmssmt_sha256_h20_4_oid = 0x02; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h20_4_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index b2b39b51ec..0ff6054cc6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_oid; sig->method_name = "XMSSMT-SHA2_40/2_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,102 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(XMSS_UNUSED_ATT return OQS_ERROR; } - const uint32_t xmssmt_sha256_h40_2_oid = 0x03; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h40_2_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - fprintf(stderr, "No secret key secure-store set.\n"); - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index 4781f49cfe..721eba5f9f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_oid; sig->method_name = "XMSSMT-SHA2_40/4_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(XMSS_UNUSED_ATT return OQS_ERROR; } - const uint32_t xmssmt_sha256_h40_4_oid = 0x04; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h40_4_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index 2acbc1046e..9433c61944 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_oid; sig->method_name = "XMSSMT-SHA2_40/8_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(XMSS_UNUSED_ATT return OQS_ERROR; } - const uint32_t xmssmt_sha256_h40_8_oid = 0x05; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h40_8_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index d9b98a749f..edfc7239d6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_oid; sig->method_name = "XMSSMT-SHA2_60/12_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,102 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(XMSS_UNUSED_ATT return OQS_ERROR; } - const uint32_t xmssmt_sha256_h60_12_oid = 0x08; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h60_12_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index c45fef5959..1d66ba99cc 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_oid; sig->method_name = "XMSSMT-SHA2_60/3_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(XMSS_UNUSED_ATT return OQS_ERROR; } - const uint32_t xmssmt_sha256_h60_3_oid = 0x06; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h60_3_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index f43f87c6b4..e445cb05f8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_oid; sig->method_name = "XMSSMT-SHA2_60/6_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(XMSS_UNUSED_ATT return OQS_ERROR; } - const uint32_t xmssmt_sha256_h60_6_oid = 0x07; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_sha256_h60_6_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 16d7270593..13e9ae5d8e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_oid; sig->method_name = "XMSSMT-SHAKE_20/2_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(XMSS_UNUSED_AT return OQS_ERROR; } - const uint32_t xmssmt_shake128_h20_2_oid = 0x11; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h20_2_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 941a2ecb3c..1e1ac0915d 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_oid; sig->method_name = "XMSSMT-SHAKE_20/4_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(XMSS_UNUSED_AT return OQS_ERROR; } - const uint32_t xmssmt_shake128_h20_4_oid = 0x12; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h20_4_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index adc47b4d11..3bc608f484 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_oid; sig->method_name = "XMSSMT-SHAKE_40/2_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(XMSS_UNUSED_AT return OQS_ERROR; } - const uint32_t xmssmt_shake128_h40_2_oid = 0x13; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h40_2_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index 3312f25477..0bee9336da 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_oid; sig->method_name = "XMSSMT-SHAKE_40/4_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(XMSS_UNUSED_AT return OQS_ERROR; } - const uint32_t xmssmt_shake128_h40_4_oid = 0x14; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h40_4_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index 43afdfeeff..994393935f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_oid; sig->method_name = "XMSSMT-SHAKE_40/8_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(XMSS_UNUSED_AT return OQS_ERROR; } - const uint32_t xmssmt_shake128_h40_8_oid = 0x15; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h40_8_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index bf7c0c56d2..c60eecd101 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_oid; sig->method_name = "XMSSMT-SHAKE_60/12_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,26 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(XMSS_UNUSED_A return OQS_ERROR; } - const uint32_t xmssmt_shake128_h60_12_oid = 0x18; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h60_12_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } + diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index f8b6ab6ec5..5c3242a8e1 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_oid; sig->method_name = "XMSSMT-SHAKE_60/3_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,101 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(XMSS_UNUSED_AT return OQS_ERROR; } - const uint32_t xmssmt_shake128_h60_3_oid = 0x16; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h60_3_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - OQS_STATUS rc_keyupdate, status = OQS_SUCCESS; - const OQS_SIG_STFL_SECRET_KEY *sk; - uint8_t *sk_key_buf_ptr = NULL; - unsigned long long sig_length = 0; - size_t sk_key_buf_len = 0; - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - /* check for secret key update function */ - if (secret_key->secure_store_scrt_key == NULL) { - return OQS_ERROR; - } - - /* Lock secret to ensure OTS use */ - if ((secret_key->lock_key) && (secret_key->mutex)) { - secret_key->lock_key(secret_key->mutex); - } - - if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - status = OQS_ERROR; - goto err; - } - *signature_len = (size_t)sig_length; - - /* - * serialize and securely store the updated private key - * but, delete signature and the serialized key other wise - */ - - sk = secret_key; - rc_keyupdate = OQS_SECRET_KEY_XMSS_serialize_key(sk, &sk_key_buf_len, &sk_key_buf_ptr); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - goto err; - } - - rc_keyupdate = secret_key->secure_store_scrt_key(sk_key_buf_ptr, sk_key_buf_len, secret_key->context); - if (rc_keyupdate != OQS_SUCCESS) { - status = OQS_ERROR; - } - - OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); -err: - /* Unlock secret to ensure OTS use */ - if ((secret_key->unlock_key) && (secret_key->mutex)) { - secret_key->unlock_key(secret_key->mutex); - } - return status; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index 1821340645..3874589c2f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -24,6 +24,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); + sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_oid; sig->method_name = "XMSSMT-SHAKE_60/6_256"; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; sig->euf_cma = true; @@ -42,34 +43,7 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_new(void) { } OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - sk->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk; - - // Secret serialize/deserialize function - sk->serialize_key = OQS_SECRET_KEY_XMSS_serialize_key; - sk->deserialize_key = OQS_SECRET_KEY_XMSS_deserialize_key; - - // Initialize the key with length_secret_key amount of bytes. - sk->secret_key_data = (uint8_t *)malloc(sk->length_secret_key * sizeof(uint8_t)); - - if (sk->secret_key_data == NULL) { - OQS_MEM_insecure_free(sk); - return NULL; - } - memset(sk->secret_key_data, 0, sk->length_secret_key); - - sk->free_key = OQS_SECRET_KEY_XMSS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_XMSS_set_store_cb; - - return sk; + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { @@ -78,62 +52,25 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(XMSS_UNUSED_AT return OQS_ERROR; } - const uint32_t xmssmt_shake128_h60_6_oid = 0x17; - if (xmssmt_keypair(public_key, secret_key->secret_key_data, xmssmt_shake128_h60_6_oid)) { + if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_oid)) { return OQS_ERROR; } return OQS_SUCCESS; } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (signature == NULL || signature_len == NULL || message == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - unsigned long long sig_length = 0; - if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { - return OQS_ERROR; - } - *signature_len = (size_t) sig_length; - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); } -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { - - if (message == NULL || signature == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (xmssmt_sign_open(message, (unsigned long long) message_len, signature, (unsigned long long) signature_len, public_key)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { + return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (remain == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_remaining_signatures(remain, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); } OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (total == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_total_signatures(total, secret_key->secret_key_data)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; + return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); } diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 33dce7e897..4607977065 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -71,7 +71,7 @@ int FindMarker(FILE *infile, const char *marker) { // // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // -int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { +int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, const char *str) { int ch, started; unsigned long i; unsigned char ich; diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 305001a462..dd75b8a916 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -14,9 +14,13 @@ #include #include "tmp_store.c" +#include "system_info.c" #if OQS_USE_PTHREADS_IN_TESTS #include + +static pthread_mutex_t *test_sk_lock = NULL; +static pthread_mutex_t *sk_lock = NULL; #endif #ifdef OQS_ENABLE_TEST_CONSTANT_TIME @@ -28,77 +32,12 @@ #define OQS_TEST_CT_DECLASSIFY(addr, len) #endif -#include "system_info.c" - /* * For stateful signature, we skip key generation because it can takes hours to complete. * So the ReadHex and and FindMarker serve the purpose of reading pre-generate keypair from KATs. */ #define MAX_MARKER_LEN 50 -static OQS_SIG_STFL_SECRET_KEY *lock_test_sk = NULL; -static OQS_SIG_STFL *lock_test_sig_obj = NULL; -static uint8_t *lock_test_public_key = NULL; -static char *lock_test_context = NULL; -static uint8_t *signature_1 = NULL; -static uint8_t *signature_2 = NULL; -static size_t signature_len_1; -static size_t signature_len_2; -static uint8_t message_1[] = "The quick brown fox ..."; -static uint8_t message_2[] = "The quick brown fox jumped from the tree."; -static pthread_mutex_t *test_sk_lock = NULL; - -/* - * Write stateful secret keys to disk. - */ -static OQS_STATUS test_save_secret_key(uint8_t *key_buf, size_t buf_len, void *context) { - uint8_t *kb = key_buf; - - if (key_buf && context && buf_len != 0) { - if (oqs_fstore("sk", (const char *)context, kb, buf_len) == OQS_SUCCESS) { - printf("\n================================================================================\n"); - printf("Updated STFL SK <%s>.\n", (const char *)context); - printf("================================================================================\n"); - return OQS_SUCCESS; - } else { - return OQS_ERROR; - } - } - return OQS_ERROR; -} - -#if OQS_USE_PTHREADS_IN_TESTS -static OQS_STATUS lock_sk_key(void *mutex) { - if (mutex == NULL) { - return OQS_ERROR; - } - - if (!(pthread_mutex_lock((pthread_mutex_t *)mutex))) { - return OQS_SUCCESS; - } - return OQS_ERROR; -} - -static OQS_STATUS unlock_sk_key(void *mutex) { - if (mutex == NULL) { - return OQS_ERROR; - } - - if (!(pthread_mutex_unlock((pthread_mutex_t *)mutex))) { - return OQS_SUCCESS; - } - return OQS_ERROR; -} -#else -static OQS_STATUS lock_sk_key(void *mutex) { - return sk != NULL ? OQS_SUCCESS : OQS_ERROR; -} - -static OQS_STATUS unlock_sk_key(void *mutex) { - return sk != NULL ? OQS_SUCCESS : OQS_ERROR; -} -#endif - // // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // @@ -191,12 +130,70 @@ int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { return 1; } -OQS_STATUS sig_stfl_keypair_from_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - OQS_STATUS rc; +static OQS_SIG_STFL_SECRET_KEY *lock_test_sk = NULL; +static OQS_SIG_STFL *lock_test_sig_obj = NULL; +static uint8_t *lock_test_public_key = NULL; +static char *lock_test_context = NULL; +static uint8_t *signature_1 = NULL; +static uint8_t *signature_2 = NULL; +static size_t signature_len_1; +static size_t signature_len_2; +static uint8_t message_1[] = "The quick brown fox ..."; +static uint8_t message_2[] = "The quick brown fox jumped from the tree."; + +/* + * Write stateful secret keys to disk. + */ +static OQS_STATUS save_secret_key(uint8_t *key_buf, size_t buf_len, void *context) { + if (key_buf == NULL || buf_len == 0 || context == NULL) { + return OQS_ERROR; + } + const char *context_char = context; - if ((sig == NULL) || (public_key == NULL) || (secret_key == NULL)) { + if (oqs_fstore("sk", context_char, key_buf, buf_len) == OQS_SUCCESS) { + printf("\n================================================================================\n"); + printf("Updated STFL SK <%s>.\n", context_char); + printf("================================================================================\n"); + return OQS_SUCCESS; + } + + return OQS_ERROR; +} + +#if OQS_USE_PTHREADS_IN_TESTS +static OQS_STATUS lock_sk_key(void *mutex) { + if (mutex == NULL) { + return OQS_ERROR; + } + + if (pthread_mutex_lock((pthread_mutex_t *)mutex)) { return OQS_ERROR; } + return OQS_SUCCESS; +} + +static OQS_STATUS unlock_sk_key(void *mutex) { + if (mutex == NULL) { + return OQS_ERROR; + } + + if (pthread_mutex_unlock((pthread_mutex_t *)mutex)) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} +#else +static OQS_STATUS lock_sk_key(void *mutex) { + return OQS_SUCCESS; +} + +static OQS_STATUS unlock_sk_key(void *mutex) { + return OQS_SUCCESS; +} +#endif + +OQS_STATUS sig_stfl_keypair_from_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + OQS_STATUS rc; rc = OQS_SIG_STFL_keypair(sig, public_key, secret_key); OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); @@ -250,8 +247,10 @@ OQS_STATUS sig_stfl_keypair_from_KATs(OQS_SIG_STFL *sig, uint8_t *public_key, OQ * XMSSMT-SHAKE_60/3_256 */ OQS_STATUS sig_stfl_KATs_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key, const char *katfile) { + if (sig == NULL || public_key == NULL || secret_key == NULL ) { + return OQS_ERROR; + } - printf("%s ", sig->method_name); if (0) { #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 @@ -323,9 +322,11 @@ typedef struct magic_s { } magic_t; static char *convert_method_name_to_file_name(const char *method_name) { + if (method_name == NULL) { + return NULL; + } const char *file_store = NULL; - char *name = NULL; if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2) == 0) { file_store = "XMSSMT-SHA2_20-2_256"; } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4) == 0) { @@ -362,10 +363,7 @@ static char *convert_method_name_to_file_name(const char *method_name) { file_store = method_name; } - if (file_store) { - name = strdup(file_store); - } - return name; + return strdup(file_store); } static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char *katfile) { @@ -373,7 +371,6 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char OQS_SIG_STFL *sig = NULL; uint8_t *public_key = NULL; OQS_SIG_STFL_SECRET_KEY *secret_key = NULL; - const OQS_SIG_STFL_SECRET_KEY *sk = NULL; OQS_SIG_STFL_SECRET_KEY *secret_key_rd = NULL; uint8_t *message = NULL; size_t message_len = 100; @@ -389,80 +386,10 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char magic_t magic; -#if OQS_USE_PTHREADS_IN_TESTS - pthread_mutex_t *sk_lock = NULL; -#endif - OQS_STATUS rc, ret = OQS_ERROR; - if (0) { - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { - goto skip_test; -#endif - } else { - goto test_on; - } -skip_test: - printf("skipping slow test %s\n", method_name); - return OQS_SUCCESS; - -test_on: - //The magic numbers are random values. //The length of the magic number was chosen to be 31 to break alignment - - OQS_randombytes(magic.val, sizeof(magic_t)); sig = OQS_SIG_STFL_new(method_name); @@ -489,17 +416,9 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char /* set context and secure store callback */ context = strdup(((file_store))); - OQS_SIG_STFL_SECRET_KEY_SET_store_cb(secret_key, test_save_secret_key, (void *)context); + OQS_SIG_STFL_SECRET_KEY_SET_store_cb(secret_key, save_secret_key, (void *)context); #if OQS_USE_PTHREADS_IN_TESTS - sk_lock = (pthread_mutex_t *)malloc(sizeof(pthread_mutex_t)); - if (sk_lock == NULL) { - goto err; - } - - if (0 != pthread_mutex_init(sk_lock, 0)) { - goto err; - } OQS_SIG_STFL_SECRET_KEY_SET_mutex(secret_key, sk_lock); #endif public_key = malloc(sig->length_public_key + 2 * sizeof(magic_t)); @@ -532,14 +451,13 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char * Some keypair generation is fast, so we only read keypair from KATs for slow XMSS parameters */ rc = sig_stfl_KATs_keygen(sig, public_key, secret_key, katfile); - sk = secret_key; OQS_TEST_CT_DECLASSIFY(&rc, sizeof rc); if (rc != OQS_SUCCESS) { fprintf(stderr, "ERROR: OQS_SIG_STFL_keypair failed\n"); goto err; } - rc = OQS_SECRET_KEY_STFL_serialize_key(sk, &sk_buf_len, &sk_buf); + rc = OQS_SECRET_KEY_STFL_serialize_key(&sk_buf, &sk_buf_len, secret_key); if (rc != OQS_SUCCESS) { goto err; } @@ -604,7 +522,6 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char } #endif - printf("verification passes as expected\n"); ret = OQS_SUCCESS; goto cleanup; @@ -630,25 +547,19 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char OQS_MEM_insecure_free(context); OQS_MEM_insecure_free(file_store); -#if OQS_USE_PTHREADS_IN_TESTS - if (sk_lock) { - pthread_mutex_destroy(sk_lock); - OQS_MEM_insecure_free(sk_lock); - } -#endif return ret; } -static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { +static OQS_STATUS sig_stfl_test_secret_key(const char *method_name, const char *katfile) { OQS_STATUS rc = OQS_SUCCESS; OQS_SIG_STFL_SECRET_KEY *sk = NULL; - OQS_SIG_STFL_SECRET_KEY *sk_frm_file = NULL; + OQS_SIG_STFL_SECRET_KEY *sk_from_file = NULL; unsigned long long num_sig_left = 0, max_num_sigs = 0; OQS_SIG_STFL *sig_obj = NULL; uint8_t *public_key = NULL; - uint8_t *frm_file_sk_buf = NULL; + uint8_t *from_file_sk_buf = NULL; uint8_t *to_file_sk_buf = NULL; - size_t frm_file_sk_len = 0; + size_t from_file_sk_len = 0; size_t to_file_sk_len = 0; char *context = NULL; char *context_2 = NULL; @@ -658,71 +569,6 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (0) { - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { - goto skip_test; -#endif - } else { - goto keep_going; - } - -skip_test: - printf("Skip slow test %s.\n", method_name); - return rc; - -keep_going: - printf("================================================================================\n"); printf("Create stateful Signature %s\n", method_name); printf("================================================================================\n"); @@ -749,7 +595,7 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { printf("Generate keypair %s\n", method_name); printf("================================================================================\n"); - rc = OQS_SIG_STFL_keypair(sig_obj, public_key, sk); + rc = sig_stfl_KATs_keygen(sig_obj, public_key, sk, katfile); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS STFL key gen failed.\n"); @@ -764,17 +610,15 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { fprintf(stderr, "OQS STFL key: Failed to get max number of sig from %s.\n", method_name); goto err; } - printf("%s Maximum num of sign operations = %llu\n", method_name, max_num_sigs); rc = OQS_SIG_STFL_sigs_remaining((const OQS_SIG_STFL *)sig_obj, &num_sig_left, (const OQS_SIG_STFL_SECRET_KEY *)sk); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS STFL key: Failed to get the remaining number of sig from %s.\n", method_name); goto err; } - printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); /* write sk key to disk */ - rc = OQS_SECRET_KEY_STFL_serialize_key(sk, &to_file_sk_len, &to_file_sk_buf); + rc = OQS_SECRET_KEY_STFL_serialize_key(&to_file_sk_buf, &to_file_sk_len, sk); if (rc != OQS_SUCCESS) { goto err; } @@ -784,54 +628,54 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name) { goto err; } - if (!sk->secret_key_data) { + if (sk->secret_key_data == NULL) { fprintf(stderr, "ERROR: OQS_SECRET_KEY_new incomplete.\n"); goto err; } /* set context and secure store callback */ - if (sk->set_scrt_key_store_cb) { + if (sk->set_scrt_key_store_cb != NULL) { context = strdup(file_store_name); - sk->set_scrt_key_store_cb(sk, test_save_secret_key, (void *)context); + sk->set_scrt_key_store_cb(sk, save_secret_key, (void *)context); } /* read secret key from disk */ - frm_file_sk_buf = malloc(to_file_sk_len); - if (oqs_fload("sk", file_store_name, frm_file_sk_buf, to_file_sk_len, &frm_file_sk_len) != OQS_SUCCESS) { + from_file_sk_buf = malloc(to_file_sk_len); + if (oqs_fload("sk", file_store_name, from_file_sk_buf, to_file_sk_len, &from_file_sk_len) != OQS_SUCCESS) { goto err; } - if (to_file_sk_len != frm_file_sk_len) { + if (to_file_sk_len != from_file_sk_len) { fprintf(stderr, "ERROR: OQS_SECRET_KEY_new stored length not equal read length\n"); goto err; } - sk_frm_file = OQS_SIG_STFL_SECRET_KEY_new(method_name); - if (sk_frm_file == NULL) { + sk_from_file = OQS_SIG_STFL_SECRET_KEY_new(method_name); + if (sk_from_file == NULL) { fprintf(stderr, "ERROR: 2nd OQS_SECRET_KEY_new failed\n"); goto err; } context_2 = strdup(file_store_name); - rc = OQS_SECRET_KEY_STFL_deserialize_key(sk_frm_file, frm_file_sk_len, frm_file_sk_buf, (void *)context_2); + rc = OQS_SECRET_KEY_STFL_deserialize_key(sk_from_file, from_file_sk_len, from_file_sk_buf, (void *)context_2); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS restore %s from file failed.\n", method_name); goto err; } - printf("Secret Key created as expected.\n"); - goto end_it; + rc = OQS_SUCCESS; + goto cleanup; err: rc = OQS_ERROR; -end_it: +cleanup: OQS_SIG_STFL_SECRET_KEY_free(sk); - OQS_SIG_STFL_SECRET_KEY_free(sk_frm_file); + OQS_SIG_STFL_SECRET_KEY_free(sk_from_file); OQS_MEM_insecure_free(public_key); OQS_MEM_secure_free(to_file_sk_buf, to_file_sk_len); - OQS_MEM_secure_free(frm_file_sk_buf, frm_file_sk_len); + OQS_MEM_secure_free(from_file_sk_buf, from_file_sk_len); OQS_SIG_STFL_free(sig_obj); OQS_MEM_insecure_free(context); OQS_MEM_insecure_free(context_2); @@ -848,77 +692,13 @@ static OQS_STATUS sig_stfl_test_query_key(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (0) { - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { - goto skip_test; -#endif - } else { - goto keep_going; - } - -skip_test: - printf("Skip slow test %s.\n", method_name); - return rc; - -keep_going: - printf("================================================================================\n"); printf("Testing stateful Signature Verification %s\n", method_name); printf("================================================================================\n"); - if ( lock_test_sk == NULL || lock_test_sig_obj == NULL || signature_1 == NULL - || signature_2 == NULL || lock_test_public_key == NULL) { + if ( lock_test_sk == NULL || lock_test_sig_obj == NULL || + signature_1 == NULL || signature_2 == NULL || + lock_test_public_key == NULL) { return OQS_ERROR; } @@ -943,16 +723,14 @@ static OQS_STATUS sig_stfl_test_query_key(const char *method_name) { fprintf(stderr, "ERROR: lock thread test OQS_SIG_STFL_verify failed\n"); goto err; } - rc = OQS_SUCCESS; printf("================================================================================\n"); printf("Stateful Signature Verification %s Passed.\n", method_name); printf("================================================================================\n"); - goto end_it; -err: - rc = OQS_ERROR; -end_it: - return rc; + return OQS_SUCCESS; + +err: + return OQS_ERROR; } static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { @@ -967,71 +745,6 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (0) { - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { - goto skip_test; -#endif - } else { - goto keep_going; - } - -skip_test: - printf("Skip slow test %s.\n", method_name); - return rc; - -keep_going: - printf("================================================================================\n"); printf("Testing stateful Signature Generation %s\n", method_name); printf("================================================================================\n"); @@ -1043,7 +756,7 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { key_store_name = convert_method_name_to_file_name(method_name); /* set context and secure store callback */ context = strdup(((key_store_name))); - OQS_SIG_STFL_SECRET_KEY_SET_store_cb(lock_test_sk, test_save_secret_key, (void *)context); + OQS_SIG_STFL_SECRET_KEY_SET_store_cb(lock_test_sk, save_secret_key, (void *)context); /* * Get max num signature and the amount remaining @@ -1054,14 +767,12 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { fprintf(stderr, "OQS STFL key: Failed to get max number of sig from %s.\n", method_name); goto err; } - printf("%s Maximum num of sign operations = %llu\n", method_name, max_num_sigs); rc = OQS_SIG_STFL_sigs_remaining((const OQS_SIG_STFL *)lock_test_sig_obj, &num_sig_left, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS STFL key: Failed to get the remaining number of sig from %s.\n", method_name); goto err; } - printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); printf("================================================================================\n"); printf("Sig Gen 1 %s\n", method_name); @@ -1085,14 +796,12 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { fprintf(stderr, "OQS STFL key: Failed to get max number of sig from %s.\n", method_name); goto err; } - printf("%s Maximum num of sign operations = %llu\n", method_name, max_num_sigs); rc = OQS_SIG_STFL_sigs_remaining((const OQS_SIG_STFL *)lock_test_sig_obj, &num_sig_left, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS STFL key: Failed to get the remaining number of sig from %s.\n", method_name); goto err; } - printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); printf("================================================================================\n"); printf("Sig Gen 2 %s\n", method_name); @@ -1120,26 +829,25 @@ static OQS_STATUS sig_stfl_test_sig_gen(const char *method_name) { fprintf(stderr, "OQS STFL key: Failed to get max number of sig from %s.\n", method_name); goto err; } - printf("%s Maximum num of sign operations = %llu\n", method_name, max_num_sigs); rc = OQS_SIG_STFL_sigs_remaining((const OQS_SIG_STFL *)lock_test_sig_obj, &num_sig_left, (const OQS_SIG_STFL_SECRET_KEY *)lock_test_sk); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS STFL key: Failed to get the remaining number of sig from %s.\n", method_name); goto err; } - printf("%s Remaining number of sign operations = %llu\n", method_name, num_sig_left); - goto end_it; + rc = OQS_SUCCESS; + goto cleanup; err: rc = OQS_ERROR; -end_it: +cleanup: OQS_MEM_insecure_free(context); OQS_MEM_insecure_free(key_store_name); return rc; } -static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { +static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name, const char *katfile) { OQS_STATUS rc = OQS_SUCCESS; printf("================================================================================\n"); @@ -1150,71 +858,6 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { * Temporarily skip algs with long key generation times. */ - if (0) { - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h20 - } else if (strcmp(method_name, OQS_SIG_STFL_alg_xmss_sha256_h20) == 0) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake128_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake128_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_sha512_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_sha512_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h16 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h16)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmss_shake256_h20 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmss_shake256_h20)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_sha256_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3)) { - goto skip_test; -#endif - -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h40_2 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2)) { - goto skip_test; -#endif -#ifdef OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_3 - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3)) { - goto skip_test; -#endif - } else { - goto keep_going; - } - -skip_test: - printf("Skip slow test %s.\n", method_name); - return rc; - -keep_going: - printf("================================================================================\n"); printf("Create stateful Signature %s\n", method_name); printf("================================================================================\n"); @@ -1241,15 +884,6 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { OQS_SIG_STFL_SECRET_KEY_SET_unlock(lock_test_sk, unlock_sk_key); #if OQS_USE_PTHREADS_IN_TESTS - - test_sk_lock = (pthread_mutex_t *)malloc(sizeof(pthread_mutex_t)); - if (test_sk_lock == NULL) { - goto err; - } - - if (0 != pthread_mutex_init(test_sk_lock, 0)) { - goto err; - } OQS_SIG_STFL_SECRET_KEY_SET_mutex(lock_test_sk, test_sk_lock); #endif @@ -1257,14 +891,14 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { printf("Generate keypair %s\n", method_name); printf("================================================================================\n"); - rc = OQS_SIG_STFL_keypair(lock_test_sig_obj, lock_test_public_key, lock_test_sk); + rc = sig_stfl_KATs_keygen(lock_test_sig_obj, lock_test_public_key, lock_test_sk, katfile); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS STFL key gen failed.\n"); goto err; } - if (!lock_test_sk->secret_key_data) { + if (lock_test_sk->secret_key_data == NULL) { fprintf(stderr, "ERROR: OQS_SECRET_KEY_new incomplete.\n"); goto err; } @@ -1272,16 +906,13 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name) { /* set context and secure store callback */ if (lock_test_sk->set_scrt_key_store_cb) { lock_test_context = convert_method_name_to_file_name(method_name); - lock_test_sk->set_scrt_key_store_cb(lock_test_sk, test_save_secret_key, (void *)lock_test_context); + lock_test_sk->set_scrt_key_store_cb(lock_test_sk, save_secret_key, (void *)lock_test_context); } - printf("Test Secret Key Creator Thread created Stateful Signature and Secret Key objects.\n"); - goto end_it; + return OQS_SUCCESS; err: - rc = OQS_ERROR; -end_it: - return rc; + return OQS_ERROR; } #ifdef OQS_ENABLE_TEST_CONSTANT_TIME @@ -1301,17 +932,18 @@ static void TEST_SIG_STFL_randombytes(uint8_t *random_array, size_t bytes_to_rea #endif #if OQS_USE_PTHREADS_IN_TESTS -struct thread_data { +typedef struct thread_data { const char *alg_name; const char *katfile; OQS_STATUS rc; OQS_STATUS rc1; -}; +} thread_data_t; -struct lock_test_data { +typedef struct lock_test_data { const char *alg_name; + const char *katfile; OQS_STATUS rc; -}; +} lock_test_data_t; void *test_query_key(void *arg) { struct lock_test_data *td = arg; @@ -1332,7 +964,7 @@ void *test_sig_gen(void *arg) { void *test_create_keys(void *arg) { struct lock_test_data *td = arg; printf("\n%s: Start Generate Keys\n", __FUNCTION__); - td->rc = sig_stfl_test_secret_key_lock(td->alg_name); + td->rc = sig_stfl_test_secret_key_lock(td->alg_name, td->katfile); printf("%s: End Generate Stateful Keys\n\n", __FUNCTION__); return NULL; } @@ -1340,7 +972,7 @@ void *test_create_keys(void *arg) { void *test_wrapper(void *arg) { struct thread_data *td = arg; td->rc = sig_stfl_test_correctness(td->alg_name, td->katfile); - td->rc1 = sig_stfl_test_secret_key(td->alg_name); + td->rc1 = sig_stfl_test_secret_key(td->alg_name, td->katfile); return NULL; } #endif @@ -1381,64 +1013,81 @@ int main(int argc, char **argv) { OQS_randombytes_switch_algorithm("system"); #endif - OQS_STATUS rc, rc1, rc_lck, rc_sig, rc_qry; + OQS_STATUS rc = OQS_ERROR, rc1 = OQS_ERROR; + int exit_status = EXIT_SUCCESS; + #if OQS_USE_PTHREADS_IN_TESTS #define MAX_LEN_SIG_NAME_ 64 + OQS_STATUS rc_create = OQS_ERROR, rc_sign = OQS_ERROR, rc_query = OQS_ERROR; pthread_t thread; pthread_t create_key_thread; pthread_t sign_key_thread; pthread_t query_key_thread; - struct thread_data td; - td.alg_name = alg_name; - td.katfile = katfile; - - struct lock_test_data td_create; - struct lock_test_data td_sign; - struct lock_test_data td_query; - td_create.alg_name = alg_name; - td_sign.alg_name = alg_name; - td_query.alg_name = alg_name; - - int trc = pthread_create(&thread, NULL, test_wrapper, &td); - if (trc) { - fprintf(stderr, "ERROR: Creating pthread\n"); - OQS_destroy(); - return EXIT_FAILURE; + + thread_data_t td = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR, .rc1 = OQS_ERROR}; + lock_test_data_t td_create = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR}; + lock_test_data_t td_sign = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR}; + lock_test_data_t td_query = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR}; + + test_sk_lock = (pthread_mutex_t *)malloc(sizeof(pthread_mutex_t)); + if (test_sk_lock == NULL) { + goto err; + } + sk_lock = (pthread_mutex_t *)malloc(sizeof(pthread_mutex_t)); + if (sk_lock == NULL) { + goto err; + } + + if (pthread_mutex_init(test_sk_lock, NULL) || pthread_mutex_init(sk_lock, NULL)) { + fprintf(stderr, "ERROR: Initializing mutex\n"); + exit_status = EXIT_FAILURE; + goto err; + } + + if (pthread_create(&thread, NULL, test_wrapper, &td)) { + fprintf(stderr, "ERROR: Creating pthread for test_wrapper\n"); + exit_status = EXIT_FAILURE; + goto err; } pthread_join(thread, NULL); rc = td.rc; rc1 = td.rc1; - int trc_2 = pthread_create(&create_key_thread, NULL, test_create_keys, &td_create); - if (trc_2) { - fprintf(stderr, "ERROR: Creating pthread for stateful key gen test\n"); - OQS_destroy(); - return EXIT_FAILURE; + if (pthread_create(&create_key_thread, NULL, test_create_keys, &td_create)) { + fprintf(stderr, "ERROR: Creating pthread for test_create_keys\n"); + exit_status = EXIT_FAILURE; + goto err; } pthread_join(create_key_thread, NULL); - rc_lck = td_create.rc; + rc_create = td_create.rc; - int trc_3 = pthread_create(&sign_key_thread, NULL, test_sig_gen, &td_sign); - if (trc_3) { - fprintf(stderr, "ERROR: Creating pthread for sig gen test\n"); - OQS_destroy(); - return EXIT_FAILURE; + if (pthread_create(&sign_key_thread, NULL, test_sig_gen, &td_sign)) { + fprintf(stderr, "ERROR: Creating pthread for test_sig_gen\n"); + exit_status = EXIT_FAILURE; + goto err; } pthread_join(sign_key_thread, NULL); - rc_sig = td_sign.rc; + rc_sign = td_sign.rc; - int trc_4 = pthread_create(&query_key_thread, NULL, test_query_key, &td_query); - if (trc_4) { - fprintf(stderr, "ERROR: Creating pthread for query key test.\n"); - OQS_destroy(); - return EXIT_FAILURE; + if (pthread_create(&query_key_thread, NULL, test_query_key, &td_query)) { + fprintf(stderr, "ERROR: Creating pthread for test_query_key\n"); + exit_status = EXIT_FAILURE; + goto err; } pthread_join(query_key_thread, NULL); - rc_qry = td_query.rc; + rc_query = td_query.rc; + +err: + if (test_sk_lock) { + pthread_mutex_destroy(test_sk_lock); + } + if (sk_lock) { + pthread_mutex_destroy(sk_lock); + } #else rc = sig_stfl_test_correctness(alg_name, katfile); - rc1 = sig_stfl_test_secret_key(alg_name); + rc1 = sig_stfl_test_secret_key(alg_name, katfile); #endif OQS_SIG_STFL_SECRET_KEY_free(lock_test_sk); @@ -1448,11 +1097,10 @@ int main(int argc, char **argv) { OQS_MEM_insecure_free(signature_1); OQS_MEM_insecure_free(signature_2); - if ((rc != OQS_SUCCESS) || (rc1 != OQS_SUCCESS) || (rc_lck != OQS_SUCCESS) || (rc_sig != OQS_SUCCESS) - || (rc_qry != OQS_SUCCESS)) { - OQS_destroy(); + OQS_destroy(); + if (rc != OQS_SUCCESS || rc1 != OQS_SUCCESS || + rc_create != OQS_SUCCESS || rc_sign != OQS_SUCCESS || rc_query != OQS_SUCCESS) { return EXIT_FAILURE; } - OQS_destroy(); - return EXIT_SUCCESS; + return exit_status; } From 47740ad98cc5361c9916abca1944f1e6a24c0158 Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Wed, 15 Nov 2023 14:41:47 -0500 Subject: [PATCH 20/68] Enforce idx from unsigned int to uint32_t. (#1611) --- src/sig_stfl/xmss/external/xmss_core_fast.c | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c index 4dd4c9b41d..deaedefa8a 100644 --- a/src/sig_stfl/xmss/external/xmss_core_fast.c +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -221,7 +221,6 @@ static void treehash_init(const xmss_params *params, bds_state *state, const unsigned char *sk_seed, const unsigned char *pub_seed, const uint32_t addr[8]) { - unsigned int idx = index; // use three different addresses because at this point we use all three formats in parallel uint32_t ots_addr[8] = {0}; uint32_t ltree_addr[8] = {0}; @@ -235,14 +234,14 @@ static void treehash_init(const xmss_params *params, copy_subtree_addr(node_addr, addr); set_type(node_addr, 2); - uint32_t lastnode, i; + /* The subtree has at most 2^20 leafs, so uint32_t suffices. */ + uint32_t idx = index; + uint32_t lastnode = index +(1<n, sizeof(unsigned char)); unsigned int *stacklevels = malloc((height + 1)*sizeof(unsigned int)); unsigned int stackoffset=0; unsigned int nodeh; - lastnode = idx+(1<tree_height-params->bds_k; i++) { state->treehash[i].h = i; state->treehash[i].completed = 1; @@ -281,9 +280,7 @@ static void treehash_init(const xmss_params *params, i++; } - for (i = 0; i < params->n; i++) { - node[i] = stack[i]; - } + memcpy(node, stack, params->n); OQS_MEM_insecure_free(stacklevels); OQS_MEM_insecure_free(stack); From a7b29874fd7aec76165626c2e6ea8a66de91e0b9 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Mon, 27 Nov 2023 17:26:08 -0500 Subject: [PATCH 21/68] SHA2 Increment with arbitrary length (non-block sizes) (#1614) * Enhanced with new SHA2 API that allows arbitary length updates * Fix style * Fix format * Document struct members * Fix comparison sign * Use OQS SHA2 API * Add nl at end * Use OQS_MEM_secure_free instead of free * Updated per review... mem check after malloc, use memcpy * Fix style --- src/common/sha2/sha2.c | 4 + src/common/sha2/sha2.h | 38 +++++ src/common/sha2/sha2_armv8.c | 99 ++++++++++-- src/common/sha2/sha2_c.c | 114 ++++++++++++-- src/common/sha2/sha2_impl.c | 8 + src/common/sha2/sha2_local.h | 10 ++ src/common/sha2/sha2_ossl.c | 5 + src/sig_stfl/lms/CMakeLists.txt | 1 - src/sig_stfl/lms/external/hash.c | 13 +- src/sig_stfl/lms/external/hash.h | 5 +- src/sig_stfl/lms/external/lms_namespace.h | 2 - src/sig_stfl/lms/external/sha256.c | 183 ---------------------- src/sig_stfl/lms/external/sha256.h | 44 ------ tests/test_hash.c | 54 ++++++- 14 files changed, 317 insertions(+), 263 deletions(-) delete mode 100644 src/sig_stfl/lms/external/sha256.c delete mode 100644 src/sig_stfl/lms/external/sha256.h diff --git a/src/common/sha2/sha2.c b/src/common/sha2/sha2.c index 9cc732d1d3..e0d3902e3b 100644 --- a/src/common/sha2/sha2.c +++ b/src/common/sha2/sha2.c @@ -22,6 +22,10 @@ void OQS_SHA2_sha256_inc_blocks(OQS_SHA2_sha256_ctx *state, const uint8_t *in, s callbacks->SHA2_sha256_inc_blocks(state, in, inblocks); } +void OQS_SHA2_sha256_inc(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t len) { + callbacks->SHA2_sha256_inc(state, in, len); +} + void OQS_SHA2_sha256_inc_finalize(uint8_t *out, OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t inlen) { callbacks->SHA2_sha256_inc_finalize(out, state, in, inlen); } diff --git a/src/common/sha2/sha2.h b/src/common/sha2/sha2.h index 41562f8f5e..cd993e69c8 100644 --- a/src/common/sha2/sha2.h +++ b/src/common/sha2/sha2.h @@ -24,6 +24,16 @@ extern "C" { #endif +/** Data structure for the state of the SHA-224 incremental hashing API. */ +typedef struct { + /** Internal state */ + void *ctx; + /** current number of bytes in data */ + size_t data_len; + /** unprocessed data buffer */ + uint8_t data[128]; +} OQS_SHA2_sha224_ctx; + /** * \brief Process a message with SHA-256 and return the hash code in the output byte array. * @@ -39,6 +49,10 @@ void OQS_SHA2_sha256(uint8_t *output, const uint8_t *input, size_t inplen); typedef struct { /** Internal state */ void *ctx; + /** current number of bytes in data */ + size_t data_len; + /** unprocessed data buffer */ + uint8_t data[128]; } OQS_SHA2_sha256_ctx; /** @@ -74,6 +88,17 @@ void OQS_SHA2_sha256_inc_ctx_clone(OQS_SHA2_sha256_ctx *dest, const OQS_SHA2_sha */ void OQS_SHA2_sha256_inc_blocks(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t inblocks); +/** + * \brief Process message bytes with SHA-256 and update the state. + * + * \warning The state must be initialized by OQS_SHA2_sha256_inc_init or OQS_SHA2_sha256_inc_ctx_clone. + * + * \param state The state to update + * \param in Message input byte array + * \param len The number of bytes of message to process + */ +void OQS_SHA2_sha256_inc(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t len); + /** * \brief Process more message bytes with SHA-256 and return the hash code in the output byte array. * @@ -113,6 +138,10 @@ void OQS_SHA2_sha384(uint8_t *output, const uint8_t *input, size_t inplen); typedef struct { /** Internal state. */ void *ctx; + /** current number of bytes in data */ + size_t data_len; + /** unprocessed data buffer */ + uint8_t data[128]; } OQS_SHA2_sha384_ctx; /** @@ -187,6 +216,10 @@ void OQS_SHA2_sha512(uint8_t *output, const uint8_t *input, size_t inplen); typedef struct { /** Internal state. */ void *ctx; + /** current number of bytes in data */ + size_t data_len; + /** unprocessed data buffer */ + uint8_t data[128]; } OQS_SHA2_sha512_ctx; /** @@ -264,6 +297,11 @@ struct OQS_SHA2_callbacks { */ void (*SHA2_sha256_inc_ctx_clone)(OQS_SHA2_sha256_ctx *dest, const OQS_SHA2_sha256_ctx *src); + /** + * Implementation of function OQS_SHA2_sha256_inc. + */ + void (*SHA2_sha256_inc)(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t len); + /** * Implementation of function OQS_SHA2_sha256_inc_blocks. */ diff --git a/src/common/sha2/sha2_armv8.c b/src/common/sha2/sha2_armv8.c index 49a63448aa..f3bbf573a1 100644 --- a/src/common/sha2/sha2_armv8.c +++ b/src/common/sha2/sha2_armv8.c @@ -3,7 +3,7 @@ #include #include "sha2_local.h" - +#include #include // ARM includes #ifndef WIN32 @@ -169,23 +169,43 @@ static size_t crypto_hashblocks_sha256_armv8(uint8_t *statebytes, return length; } + void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const uint8_t *in, size_t inlen) { uint8_t padded[128]; - uint64_t bytes = load_bigendian_64(state->ctx + 32) + inlen; - crypto_hashblocks_sha256_armv8(state->ctx, in, inlen); - in += inlen; - inlen &= 63; - in -= inlen; + size_t new_inlen = state->data_len + inlen; + size_t tmp_len = new_inlen; + const uint8_t *new_in; + uint8_t *tmp_in = NULL; + + if (new_inlen == inlen) { + new_in = in; + } else { //Combine incremental data with final input + tmp_in = malloc(tmp_len); + if (tmp_in == NULL) { + exit(111); + } + + memcpy(tmp_in, state->data, state->data_len); + memcpy(tmp_in + state->data_len, in, inlen); + new_in = tmp_in; + } + + uint64_t bytes = load_bigendian_64(state->ctx + 32) + new_inlen; + + crypto_hashblocks_sha256_armv8(state->ctx, new_in, new_inlen); + new_in += new_inlen; + new_inlen &= 63; + new_in -= new_inlen; - for (size_t i = 0; i < inlen; ++i) { - padded[i] = in[i]; + for (size_t i = 0; i < new_inlen; ++i) { + padded[i] = new_in[i]; } - padded[inlen] = 0x80; + padded[new_inlen] = 0x80; - if (inlen < 56) { - for (size_t i = inlen + 1; i < 56; ++i) { + if (new_inlen < 56) { + for (size_t i = new_inlen + 1; i < 56; ++i) { padded[i] = 0; } padded[56] = (uint8_t) (bytes >> 53); @@ -198,7 +218,7 @@ void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const ui padded[63] = (uint8_t) (bytes << 3); crypto_hashblocks_sha256_armv8(state->ctx, padded, 64); } else { - for (size_t i = inlen + 1; i < 120; ++i) { + for (size_t i = new_inlen + 1; i < 120; ++i) { padded[i] = 0; } padded[120] = (uint8_t) (bytes >> 53); @@ -216,6 +236,7 @@ void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const ui out[i] = state->ctx[i]; } oqs_sha2_sha256_inc_ctx_release_c(state); + OQS_MEM_secure_free(tmp_in, tmp_len); } void oqs_sha2_sha224_inc_finalize_armv8(uint8_t *out, sha224ctx *state, const uint8_t *in, size_t inlen) { @@ -229,11 +250,63 @@ void oqs_sha2_sha224_inc_finalize_armv8(uint8_t *out, sha224ctx *state, const ui void oqs_sha2_sha256_inc_blocks_armv8(sha256ctx *state, const uint8_t *in, size_t inblocks) { uint64_t bytes = load_bigendian_64(state->ctx + 32); + const uint8_t *new_in; + size_t buf_len = 64 * inblocks; + uint8_t *tmp_in = NULL; + + /* Process any existing incremental data first */ + if (state->data_len) { + tmp_in = malloc(buf_len); + if (tmp_in == NULL) { + exit(111); + } + + memcpy(tmp_in, state->data, state->data_len); + memcpy(tmp_in + state->data_len, in, buf_len - state->data_len); + + /* store the reminder input as incremental data */ + memcpy(state->data, in + (buf_len - state->data_len), state->data_len); + new_in = tmp_in; + } else { + new_in = in; + } - crypto_hashblocks_sha256_armv8(state->ctx, in, 64 * inblocks); + crypto_hashblocks_sha256_armv8(state->ctx, new_in, 64 * inblocks); bytes += 64 * inblocks; store_bigendian_64(state->ctx + 32, bytes); + OQS_MEM_secure_free(tmp_in, buf_len); +} + +void oqs_sha2_sha256_inc_armv8(sha256ctx *state, const uint8_t *in, size_t len) { + uint64_t bytes = 0; + while (len) { + size_t incr = 64 - state->data_len; + if (incr > len) { + incr = len; + } + + for (size_t i = 0; i < incr; ++i, state->data_len++) { + state->data[state->data_len] = in[i]; + } + + if (state->data_len < 64) { + break; + } + + /* + * Process a complete block now + */ + bytes = load_bigendian_64(state->ctx + 32) + 64; + crypto_hashblocks_sha256_armv8(state->ctx, state->data, 64); + store_bigendian_64(state->ctx + 32, bytes); + + /* + * update the remaining input + */ + len -= incr; + state->data_len = 0; + } } void oqs_sha2_sha224_inc_blocks_armv8(sha224ctx *state, const uint8_t *in, size_t inblocks) { diff --git a/src/common/sha2/sha2_c.c b/src/common/sha2/sha2_c.c index 1de100c306..33863f8040 100644 --- a/src/common/sha2/sha2_c.c +++ b/src/common/sha2/sha2_c.c @@ -512,9 +512,12 @@ void oqs_sha2_sha224_inc_init_c(sha224ctx *state) { for (size_t i = 32; i < 40; ++i) { state->ctx[i] = 0; } + state->data_len = 0; + memset(state->data, 0, 128); } void oqs_sha2_sha256_inc_init_c(sha256ctx *state) { + state->data_len = 0; state->ctx = malloc(PQC_SHA256CTX_BYTES); if (state->ctx == NULL) { exit(111); @@ -525,6 +528,8 @@ void oqs_sha2_sha256_inc_init_c(sha256ctx *state) { for (size_t i = 32; i < 40; ++i) { state->ctx[i] = 0; } + state->data_len = 0; + memset(state->data, 0, 128); } void oqs_sha2_sha384_inc_init_c(sha384ctx *state) { @@ -538,6 +543,8 @@ void oqs_sha2_sha384_inc_init_c(sha384ctx *state) { for (size_t i = 64; i < 72; ++i) { state->ctx[i] = 0; } + state->data_len = 0; + memset(state->data, 0, 128); } void oqs_sha2_sha512_inc_init_c(sha512ctx *state) { @@ -551,6 +558,8 @@ void oqs_sha2_sha512_inc_init_c(sha512ctx *state) { for (size_t i = 64; i < 72; ++i) { state->ctx[i] = 0; } + state->data_len = 0; + memset(state->data, 0, 128); } void oqs_sha2_sha224_inc_ctx_clone_c(sha224ctx *stateout, const sha224ctx *statein) { @@ -558,6 +567,8 @@ void oqs_sha2_sha224_inc_ctx_clone_c(sha224ctx *stateout, const sha224ctx *state if (stateout->ctx == NULL) { exit(111); } + stateout->data_len = statein->data_len; + memcpy(stateout->data, statein->data, 128); memcpy(stateout->ctx, statein->ctx, PQC_SHA256CTX_BYTES); } @@ -566,6 +577,8 @@ void oqs_sha2_sha256_inc_ctx_clone_c(sha256ctx *stateout, const sha256ctx *state if (stateout->ctx == NULL) { exit(111); } + stateout->data_len = statein->data_len; + memcpy(stateout->data, statein->data, 128); memcpy(stateout->ctx, statein->ctx, PQC_SHA256CTX_BYTES); } @@ -574,6 +587,8 @@ void oqs_sha2_sha384_inc_ctx_clone_c(sha384ctx *stateout, const sha384ctx *state if (stateout->ctx == NULL) { exit(111); } + stateout->data_len = statein->data_len; + memcpy(stateout->data, statein->data, 128); memcpy(stateout->ctx, statein->ctx, PQC_SHA512CTX_BYTES); } @@ -582,6 +597,8 @@ void oqs_sha2_sha512_inc_ctx_clone_c(sha512ctx *stateout, const sha512ctx *state if (stateout->ctx == NULL) { exit(111); } + stateout->data_len = statein->data_len; + memcpy(stateout->data, statein->data, 128); memcpy(stateout->ctx, statein->ctx, PQC_SHA512CTX_BYTES); } @@ -607,11 +624,64 @@ void oqs_sha2_sha512_inc_ctx_release_c(sha512ctx *state) { void oqs_sha2_sha256_inc_blocks_c(sha256ctx *state, const uint8_t *in, size_t inblocks) { uint64_t bytes = load_bigendian_64(state->ctx + 32); + size_t tmp_buflen = 64 * inblocks; + const uint8_t *new_in; + uint8_t *tmp_in = NULL; + + /* Process any existing incremental data first */ + if (state->data_len) { + tmp_in = malloc(tmp_buflen); + if (tmp_in == NULL) { + exit(111); + } + + memcpy(tmp_in, state->data, state->data_len); + memcpy(tmp_in + state->data_len, in, tmp_buflen - state->data_len); + + /* store the reminder input as incremental data */ + memcpy(state->data, in + (tmp_buflen - state->data_len), state->data_len); + new_in = tmp_in; + } else { + new_in = in; + } - crypto_hashblocks_sha256_c(state->ctx, in, 64 * inblocks); + crypto_hashblocks_sha256_c(state->ctx, new_in, 64 * inblocks); bytes += 64 * inblocks; store_bigendian_64(state->ctx + 32, bytes); + OQS_MEM_secure_free(tmp_in, tmp_buflen); +} + +void oqs_sha2_sha256_inc_c(sha256ctx *state, const uint8_t *in, size_t len) { + uint64_t bytes = 0; + while (len) { + size_t incr = 64 - state->data_len; + if (incr > len) { + incr = len; + } + + for (size_t i = 0; i < incr; ++i, state->data_len++) { + state->data[state->data_len] = in[i]; + } + + if (state->data_len < 64) { + break; + } + + /* + * Process a complete block now + */ + bytes = load_bigendian_64(state->ctx + 32); + crypto_hashblocks_sha256_c(state->ctx, state->data, 64); + bytes += 64; + store_bigendian_64(state->ctx + 32, bytes); + + /* + * update the remaining input + */ + len -= incr; + state->data_len = 0; + } } void oqs_sha2_sha224_inc_blocks_c(sha224ctx *state, const uint8_t *in, size_t inblocks) { @@ -633,20 +703,39 @@ void oqs_sha2_sha384_inc_blocks_c(sha384ctx *state, const uint8_t *in, size_t in void oqs_sha2_sha256_inc_finalize_c(uint8_t *out, sha256ctx *state, const uint8_t *in, size_t inlen) { uint8_t padded[128]; - uint64_t bytes = load_bigendian_64(state->ctx + 32) + inlen; - crypto_hashblocks_sha256_c(state->ctx, in, inlen); - in += inlen; - inlen &= 63; - in -= inlen; + size_t new_inlen = state->data_len + inlen; + size_t tmp_len = new_inlen; + const uint8_t *new_in; + uint8_t *tmp_in = NULL; + + if (new_inlen == inlen) { + new_in = in; + } else { //Combine incremental data with final input + tmp_in = malloc(tmp_len); + if (tmp_in == NULL) { + exit(111); + } - for (size_t i = 0; i < inlen; ++i) { - padded[i] = in[i]; + memcpy(tmp_in, state->data, state->data_len); + memcpy(tmp_in + state->data_len, in, inlen); + new_in = tmp_in; } - padded[inlen] = 0x80; - if (inlen < 56) { - for (size_t i = inlen + 1; i < 56; ++i) { + uint64_t bytes = load_bigendian_64(state->ctx + 32) + new_inlen; + + crypto_hashblocks_sha256_c(state->ctx, new_in, new_inlen); + new_in += new_inlen; + new_inlen &= 63; + new_in -= new_inlen; + + for (size_t i = 0; i < new_inlen; ++i) { + padded[i] = new_in[i]; + } + padded[new_inlen] = 0x80; + + if (new_inlen < 56) { + for (size_t i = new_inlen + 1; i < 56; ++i) { padded[i] = 0; } padded[56] = (uint8_t) (bytes >> 53); @@ -659,7 +748,7 @@ void oqs_sha2_sha256_inc_finalize_c(uint8_t *out, sha256ctx *state, const uint8_ padded[63] = (uint8_t) (bytes << 3); crypto_hashblocks_sha256_c(state->ctx, padded, 64); } else { - for (size_t i = inlen + 1; i < 120; ++i) { + for (size_t i = new_inlen + 1; i < 120; ++i) { padded[i] = 0; } padded[120] = (uint8_t) (bytes >> 53); @@ -677,6 +766,7 @@ void oqs_sha2_sha256_inc_finalize_c(uint8_t *out, sha256ctx *state, const uint8_ out[i] = state->ctx[i]; } oqs_sha2_sha256_inc_ctx_release_c(state); + OQS_MEM_secure_free(tmp_in, tmp_len); } void oqs_sha2_sha224_inc_finalize_c(uint8_t *out, sha224ctx *state, const uint8_t *in, size_t inlen) { diff --git a/src/common/sha2/sha2_impl.c b/src/common/sha2/sha2_impl.c index f7f01b24f5..1d6d4fb323 100644 --- a/src/common/sha2/sha2_impl.c +++ b/src/common/sha2/sha2_impl.c @@ -31,6 +31,13 @@ static void SHA2_sha256_inc_ctx_clone(OQS_SHA2_sha256_ctx *dest, const OQS_SHA2_ oqs_sha2_sha256_inc_ctx_clone_c((sha256ctx *) dest, (const sha256ctx *) src); } +static void SHA2_sha256_inc(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t len) { + C_OR_ARM( + oqs_sha2_sha256_inc_c((sha256ctx *) state, in, len), + oqs_sha2_sha256_inc_armv8((sha256ctx *) state, in, len) + ); +} + static void SHA2_sha256_inc_blocks(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t inblocks) { C_OR_ARM( oqs_sha2_sha256_inc_blocks_c((sha256ctx *) state, in, inblocks), @@ -105,6 +112,7 @@ struct OQS_SHA2_callbacks sha2_default_callbacks = { SHA2_sha256, SHA2_sha256_inc_init, SHA2_sha256_inc_ctx_clone, + SHA2_sha256_inc, SHA2_sha256_inc_blocks, SHA2_sha256_inc_finalize, SHA2_sha256_inc_ctx_release, diff --git a/src/common/sha2/sha2_local.h b/src/common/sha2/sha2_local.h index dcb1392841..969e791d20 100644 --- a/src/common/sha2/sha2_local.h +++ b/src/common/sha2/sha2_local.h @@ -23,18 +23,26 @@ extern "C" { typedef struct { uint8_t *ctx; + size_t data_len; /* current number of bytes in data */ + uint8_t data[128]; /* msg buffer */ } sha224ctx; typedef struct { uint8_t *ctx; + size_t data_len; /* current number of bytes in data */ + uint8_t data[128]; /* msg buffer */ } sha256ctx; typedef struct { uint8_t *ctx; + size_t data_len; /* current number of bytes in data */ + uint8_t data[128]; /* msg buffer */ } sha384ctx; typedef struct { uint8_t *ctx; + size_t data_len; /* current number of bytes in data */ + uint8_t data[128]; /* msg buffer */ } sha512ctx; void oqs_sha2_sha224_inc_init_c(sha224ctx *state); @@ -46,6 +54,7 @@ void oqs_sha2_sha224_inc_ctx_release_c(sha224ctx *state); void oqs_sha2_sha256_inc_init_c(sha256ctx *state); void oqs_sha2_sha256_inc_ctx_clone_c(sha256ctx *dest, const sha256ctx *src); void oqs_sha2_sha256_inc_blocks_c(sha256ctx *state, const uint8_t *in, size_t inblocks); +void oqs_sha2_sha256_inc_c(sha256ctx *state, const uint8_t *in, size_t len); void oqs_sha2_sha256_inc_finalize_c(uint8_t *out, sha256ctx *state, const uint8_t *in, size_t inlen); void oqs_sha2_sha256_inc_ctx_release_c(sha256ctx *state); @@ -66,6 +75,7 @@ void oqs_sha2_sha512_inc_ctx_release_c(sha512ctx *state); void oqs_sha2_sha224_inc_blocks_armv8(sha224ctx *state, const uint8_t *in, size_t inblocks); void oqs_sha2_sha224_armv8(uint8_t *out, const uint8_t *in, size_t inlen); void oqs_sha2_sha256_inc_blocks_armv8(sha256ctx *state, const uint8_t *in, size_t inblocks); +void oqs_sha2_sha256_inc_armv8(sha256ctx *state, const uint8_t *in, size_t len); void oqs_sha2_sha256_armv8(uint8_t *out, const uint8_t *in, size_t inlen); void oqs_sha2_sha384_inc_init_armv8(sha384ctx *state); diff --git a/src/common/sha2/sha2_ossl.c b/src/common/sha2/sha2_ossl.c index 0953feb194..064fb61ad8 100644 --- a/src/common/sha2/sha2_ossl.c +++ b/src/common/sha2/sha2_ossl.c @@ -58,6 +58,10 @@ static void SHA2_sha256_inc_init(OQS_SHA2_sha256_ctx *state) { state->ctx = mdctx; } +static void SHA2_sha256_inc(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t len) { + OQS_OPENSSL_GUARD(EVP_DigestUpdate((EVP_MD_CTX *) state->ctx, in, len)); +} + static void SHA2_sha256_inc_blocks(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t inblocks) { OQS_OPENSSL_GUARD(OSSL_FUNC(EVP_DigestUpdate)((EVP_MD_CTX *) state->ctx, in, inblocks * SHA2_BLOCK_SIZE)); } @@ -153,6 +157,7 @@ struct OQS_SHA2_callbacks sha2_default_callbacks = { SHA2_sha256, SHA2_sha256_inc_init, SHA2_sha256_inc_ctx_clone, + SHA2_sha256_inc, SHA2_sha256_inc_blocks, SHA2_sha256_inc_finalize, SHA2_sha256_inc_ctx_release, diff --git a/src/sig_stfl/lms/CMakeLists.txt b/src/sig_stfl/lms/CMakeLists.txt index 93fa290084..e47452eb50 100644 --- a/src/sig_stfl/lms/CMakeLists.txt +++ b/src/sig_stfl/lms/CMakeLists.txt @@ -26,7 +26,6 @@ set(SRCS external/lm_ots_sign.c external/lm_ots_verify.c external/lm_verify.c - external/sha256.c sig_stfl_lms.c sig_stfl_lms_functions.c ) diff --git a/src/sig_stfl/lms/external/hash.c b/src/sig_stfl/lms/external/hash.c index dffcdaf6a6..0fe23ecc62 100644 --- a/src/sig_stfl/lms/external/hash.c +++ b/src/sig_stfl/lms/external/hash.c @@ -1,6 +1,5 @@ #include #include "hash.h" -#include "sha256.h" #include "hss_zeroize.h" #define ALLOW_VERBOSE 0 /* 1 -> we allow the dumping of intermediate */ @@ -39,8 +38,8 @@ void hss_hash_ctx(void *result, int hash_type, union hash_context *ctx, switch (hash_type) { case HASH_SHA256: { - SHA256_Init(&ctx->sha256); - SHA256_Update(&ctx->sha256, message, message_len); + OQS_SHA2_sha256_inc_init(&ctx->sha256); + OQS_SHA2_sha256_inc(&ctx->sha256, message, message_len); SHA256_Final(result, &ctx->sha256); #if ALLOW_VERBOSE if (hss_verbose) { @@ -69,7 +68,7 @@ void hss_hash(void *result, int hash_type, void hss_init_hash_context(int h, union hash_context *ctx) { switch (h) { case HASH_SHA256: - SHA256_Init( &ctx->sha256 ); + OQS_SHA2_sha256_inc_init( &ctx->sha256 ); break; } } @@ -83,7 +82,7 @@ void hss_update_hash_context(int h, union hash_context *ctx, #endif switch (h) { case HASH_SHA256: - SHA256_Update(&ctx->sha256, msg, len_msg); + OQS_SHA2_sha256_inc(&ctx->sha256, msg, len_msg); break; } } @@ -117,3 +116,7 @@ unsigned hss_hash_blocksize(int hash_type) { } return 0; } + +void SHA256_Final(unsigned char *output, OQS_SHA2_sha256_ctx *ctx) { + OQS_SHA2_sha256_inc_finalize(output, ctx, NULL, 0); +} diff --git a/src/sig_stfl/lms/external/hash.h b/src/sig_stfl/lms/external/hash.h index 5e8fb3134d..8b1891f108 100644 --- a/src/sig_stfl/lms/external/hash.h +++ b/src/sig_stfl/lms/external/hash.h @@ -1,6 +1,6 @@ #if !defined( HASH_H__ ) #define HASH_H__ -#include "sha256.h" +#include #include #include #include "lms_namespace.h" @@ -19,7 +19,7 @@ enum { }; union hash_context { - SHA256_CTX sha256; + OQS_SHA2_sha256_ctx sha256; /* Any other hash contexts would go here */ }; @@ -54,5 +54,6 @@ void hss_update_hash_context( int h, union hash_context *ctx, const void *msg, size_t len_msg ); void hss_finalize_hash_context( int h, union hash_context *ctx, void *buffer); +void SHA256_Final(unsigned char *output, OQS_SHA2_sha256_ctx *ctx); #endif /* HASH_H__ */ diff --git a/src/sig_stfl/lms/external/lms_namespace.h b/src/sig_stfl/lms/external/lms_namespace.h index 56898589ee..c1b8f142ae 100644 --- a/src/sig_stfl/lms/external/lms_namespace.h +++ b/src/sig_stfl/lms/external/lms_namespace.h @@ -89,8 +89,6 @@ #define lm_validate_signature LMS_NAMESPACE(lm_validate_signature) #define SHA256_Final LMS_NAMESPACE(SHA256_Final) -#define SHA256_Init LMS_NAMESPACE(SHA256_Init) -#define SHA256_Update LMS_NAMESPACE(SHA256_Update) #define LMS_randombytes LMS_NAMESPACE(LMS_randombytes) #endif //_LMS_NAMESPACE_H diff --git a/src/sig_stfl/lms/external/sha256.c b/src/sig_stfl/lms/external/sha256.c deleted file mode 100644 index fb18892a31..0000000000 --- a/src/sig_stfl/lms/external/sha256.c +++ /dev/null @@ -1,183 +0,0 @@ -/* - * SHA-256 - * Implementation derived from LibTomCrypt (Tom St Denis) - * - * LibTomCrypt is a library that provides various cryptographic - * algorithms in a highly modular and flexible manner. - * - * The library is free for all purposes without any express - * guarantee it works. - * - * Tom St Denis, tomstdenis@gmail.com, http://libtomcrypt.org - */ - -#include -#include "sha256.h" -#include "endian.h" - -#if !USE_OPENSSL && !defined(EXT_SHA256_H) - -/* If we don't have OpenSSL, here's a SHA256 implementation */ -#define SHA256_FINALCOUNT_SIZE 8 -#define SHA256_K_SIZE 64 -static const unsigned long K[SHA256_K_SIZE] = { - 0x428a2f98UL, 0x71374491UL, 0xb5c0fbcfUL, 0xe9b5dba5UL, 0x3956c25bUL, - 0x59f111f1UL, 0x923f82a4UL, 0xab1c5ed5UL, 0xd807aa98UL, 0x12835b01UL, - 0x243185beUL, 0x550c7dc3UL, 0x72be5d74UL, 0x80deb1feUL, 0x9bdc06a7UL, - 0xc19bf174UL, 0xe49b69c1UL, 0xefbe4786UL, 0x0fc19dc6UL, 0x240ca1ccUL, - 0x2de92c6fUL, 0x4a7484aaUL, 0x5cb0a9dcUL, 0x76f988daUL, 0x983e5152UL, - 0xa831c66dUL, 0xb00327c8UL, 0xbf597fc7UL, 0xc6e00bf3UL, 0xd5a79147UL, - 0x06ca6351UL, 0x14292967UL, 0x27b70a85UL, 0x2e1b2138UL, 0x4d2c6dfcUL, - 0x53380d13UL, 0x650a7354UL, 0x766a0abbUL, 0x81c2c92eUL, 0x92722c85UL, - 0xa2bfe8a1UL, 0xa81a664bUL, 0xc24b8b70UL, 0xc76c51a3UL, 0xd192e819UL, - 0xd6990624UL, 0xf40e3585UL, 0x106aa070UL, 0x19a4c116UL, 0x1e376c08UL, - 0x2748774cUL, 0x34b0bcb5UL, 0x391c0cb3UL, 0x4ed8aa4aUL, 0x5b9cca4fUL, - 0x682e6ff3UL, 0x748f82eeUL, 0x78a5636fUL, 0x84c87814UL, 0x8cc70208UL, - 0x90befffaUL, 0xa4506cebUL, 0xbef9a3f7UL, 0xc67178f2UL -}; - -/* Various logical functions */ - -/* Rotate x right by rot bits */ -static unsigned long RORc(unsigned long x, int rot) { - rot &= 31; if (rot == 0) return x; - unsigned long right = ((x&0xFFFFFFFFUL)>>rot ); - unsigned long left = ((x&0xFFFFFFFFUL)<<(32-rot) ); - return (right|left) & 0xFFFFFFFFUL; -} -#define Ch(x,y,z) (z ^ (x & (y ^ z))) -#define Maj(x,y,z) (((x | y) & z) | (x & y)) -#define S(x, n) RORc((x),(n)) -#define R(x, n) (((x)&0xFFFFFFFFUL)>>(n)) -#define Sigma0(x) (S(x, 2) ^ S(x, 13) ^ S(x, 22)) -#define Sigma1(x) (S(x, 6) ^ S(x, 11) ^ S(x, 25)) -#define Gamma0(x) (S(x, 7) ^ S(x, 18) ^ R(x, 3)) -#define Gamma1(x) (S(x, 17) ^ S(x, 19) ^ R(x, 10)) - -static void sha256_compress (SHA256_CTX * ctx, const void *buf) -{ - unsigned long S0, S1, S2, S3, S4, S5, S6, S7, W[SHA256_K_SIZE], t0, t1, t; - int i; - const unsigned char *p; - - /* copy state into S */ - S0 = ctx->h[0]; - S1 = ctx->h[1]; - S2 = ctx->h[2]; - S3 = ctx->h[3]; - S4 = ctx->h[4]; - S5 = ctx->h[5]; - S6 = ctx->h[6]; - S7 = ctx->h[7]; - - /* - * We've been asked to perform the hash computation on this 512-bit string. - * SHA256 interprets that as an array of 16 bigendian 32 bit numbers; copy - * it, and convert it into 16 unsigned long's of the CPU's native format - */ - p = buf; - for (i=0; i<16; i++) { - W[i] = get_bigendian( p, 4 ); - p += 4; - } - - /* fill W[16..63] */ - for (i = 16; i < SHA256_K_SIZE; i++) { - W[i] = Gamma1(W[i - 2]) + W[i - 7] + Gamma0(W[i - 15]) + W[i - 16]; - } - - /* Compress */ -#define RND(a,b,c,d,e,f,g,h,i) \ - t0 = h + Sigma1(e) + Ch(e, f, g) + K[i] + W[i]; \ - t1 = Sigma0(a) + Maj(a, b, c); \ - d += t0; \ - h = t0 + t1; - - for (i = 0; i < SHA256_K_SIZE; ++i) { - RND(S0,S1,S2,S3,S4,S5,S6,S7,i); - t = S7; S7 = S6; S6 = S5; S5 = S4; - S4 = S3; S3 = S2; S2 = S1; S1 = S0; S0 = t; - } -#undef RND - - /* feedback */ - ctx->h[0] += S0; - ctx->h[1] += S1; - ctx->h[2] += S2; - ctx->h[3] += S3; - ctx->h[4] += S4; - ctx->h[5] += S5; - ctx->h[6] += S6; - ctx->h[7] += S7; -} - -void SHA256_Init (SHA256_CTX *ctx) -{ - ctx->Nl = 0; - ctx->Nh = 0; - ctx->num = 0; - ctx->h[0] = 0x6A09E667UL; - ctx->h[1] = 0xBB67AE85UL; - ctx->h[2] = 0x3C6EF372UL; - ctx->h[3] = 0xA54FF53AUL; - ctx->h[4] = 0x510E527FUL; - ctx->h[5] = 0x9B05688CUL; - ctx->h[6] = 0x1F83D9ABUL; - ctx->h[7] = 0x5BE0CD19UL; -} - -void SHA256_Update (SHA256_CTX *ctx, const void *src, unsigned int count) -{ - unsigned new_count = (ctx->Nl + (count << 3)) & 0xffffffff; - if (new_count < ctx->Nl) { - ctx->Nh += 1; - } - ctx->Nl = new_count; - - while (count) { - unsigned int this_step = 64 - ctx->num; - if (this_step > count) this_step = count; - memcpy( ctx->data + ctx->num, src, this_step); - - if (this_step + ctx->num < 64) { - ctx->num += this_step; - break; - } - - src = (const unsigned char *)src + this_step; - count -= this_step; - ctx->num = 0; - - sha256_compress( ctx, ctx->data ); - } -} - -/* - * Add padding and return the message digest. - */ -void SHA256_Final (unsigned char *digest, SHA256_CTX *ctx) -{ - unsigned int i; - unsigned char finalcount[SHA256_FINALCOUNT_SIZE]; - - put_bigendian( &finalcount[0], ctx->Nh, 4 ); - put_bigendian( &finalcount[4], ctx->Nl, 4 ); - - SHA256_Update(ctx, "\200", 1); - - if (ctx->num > 56) { - SHA256_Update(ctx, "\0\0\0\0\0\0\0\0", 8); - } - memset( ctx->data + ctx->num, 0, 56 - ctx->num ); - ctx->num = 56; - SHA256_Update(ctx, finalcount, SHA256_FINALCOUNT_SIZE); /* Should cause a sha256_compress() */ - - /* - * The final state is an array of unsigned long's; place them as a series - * of bigendian 4-byte words onto the output - */ - for (i=0; i<8; i++) { - put_bigendian( digest + 4*i, ctx->h[i], 4 ); - } -} -#endif diff --git a/src/sig_stfl/lms/external/sha256.h b/src/sig_stfl/lms/external/sha256.h deleted file mode 100644 index f7f78ad18c..0000000000 --- a/src/sig_stfl/lms/external/sha256.h +++ /dev/null @@ -1,44 +0,0 @@ -#if !defined(SHA256_H_) -#define SHA256_H_ - -#if defined( EXT_SHA256_H ) -#include EXT_SHA256_H -#else - -#define USE_OPENSSL 0 /* We use the OpenSSL implementation for SHA-256 */ - /* (which is quite a bit faster than our portable */ - /* C version) */ - -#if USE_OPENSSL - -#include - -#else -#include "lms_namespace.h" - -/* SHA256 context. */ -typedef struct { - unsigned long int h[8]; /* state; this is in the CPU native format */ - unsigned long Nl, Nh; /* number of bits processed so far */ - unsigned num; /* number of bytes within the below */ - /* buffer */ - unsigned char data[64]; /* input buffer. This is in byte vector format */ -} SHA256_CTX; - -void SHA256_Init(SHA256_CTX *); /* context */ - -void SHA256_Update(SHA256_CTX *, /* context */ - const void *, /* input block */ - unsigned int);/* length of input block */ - -void SHA256_Final(unsigned char *, - SHA256_CTX *); -#endif - -#endif /* EXT_SHA256_H */ - -#if !defined( SHA256_LEN ) -#define SHA256_LEN 32 /* The length of a SHA256 hash output */ -#endif - -#endif /* ifdef(SHA256_H_) */ diff --git a/tests/test_hash.c b/tests/test_hash.c index 022fb61a7b..3fea2f00ad 100644 --- a/tests/test_hash.c +++ b/tests/test_hash.c @@ -50,16 +50,24 @@ static int do_sha256(void) { fprintf(stderr, "ERROR reading from stdin\n"); return -1; } + // run main SHA-256 API uint8_t output[32]; OQS_SHA2_sha256(output, msg, msg_len); + // run incremental SHA-256 API uint8_t output_inc[32]; + uint8_t output_inc_2[32]; OQS_SHA2_sha256_ctx state; OQS_SHA2_sha256_inc_init(&state); + // clone state - OQS_SHA2_sha256_ctx state2; + OQS_SHA2_sha256_ctx state2, state3, state4, state5; OQS_SHA2_sha256_inc_ctx_clone(&state2, &state); + OQS_SHA2_sha256_inc_ctx_clone(&state3, &state); + OQS_SHA2_sha256_inc_ctx_clone(&state4, &state); + OQS_SHA2_sha256_inc_ctx_clone(&state5, &state); + // hash with first state if (msg_len > 64) { OQS_SHA2_sha256_inc_blocks(&state, msg, 1); @@ -67,6 +75,7 @@ static int do_sha256(void) { } else { OQS_SHA2_sha256_inc_finalize(output_inc, &state, msg, msg_len); } + if (memcmp(output, output_inc, 32) != 0) { fprintf(stderr, "ERROR: Incremental API does not match main API\n"); free(msg); @@ -84,6 +93,49 @@ static int do_sha256(void) { free(msg); return -3; } + + // hash with increment API less than block size + size_t i = 0; + for (i = 0; i < msg_len; i++) { + OQS_SHA2_sha256_inc(&state3, &msg[i], 1); + } + OQS_SHA2_sha256_inc_finalize(output_inc_2, &state3, &msg[i], 0); + if (memcmp(output, output_inc_2, 32) != 0) { + fprintf(stderr, "ERROR: Non-block Incremental API with cloned state does not match main API\n"); + free(msg); + return -4; + } + + // hash with combination of block-size increments and non block-size increments [64 bytes] + [n < 64 bytes] + if (msg_len > 64) { + OQS_SHA2_sha256_inc_blocks(&state4, msg, 1); + for (i = 0; i < (msg_len - 64); i++) { + OQS_SHA2_sha256_inc(&state4, &msg[64 + i], 1); + } + OQS_SHA2_sha256_inc_finalize(output_inc_2, &state4, &msg[msg_len - 1], 0); + } else { + OQS_SHA2_sha256_inc_finalize(output_inc_2, &state4, msg, msg_len); + } + if (memcmp(output, output_inc_2, 32) != 0) { + fprintf(stderr, "ERROR: Combined block increments with non-block size failed to match main API\n"); + free(msg); + return -5; + } + + // hash with combination of non block-size and block-size [n < 64 bytes] + [64 bytes] + if (msg_len > 64) { + OQS_SHA2_sha256_inc(&state5, msg, 1); + OQS_SHA2_sha256_inc_blocks(&state5, &msg[1], 1); + OQS_SHA2_sha256_inc_finalize(output_inc_2, &state5, &msg[65], msg_len - 65); + } else { + OQS_SHA2_sha256_inc_finalize(output_inc_2, &state5, msg, msg_len); + } + if (memcmp(output, output_inc_2, 32) != 0) { + fprintf(stderr, "ERROR: Combined non-block size and block increments failed to match main API\n"); + free(msg); + return -5; + } + //Test inc API print_hex(output, 32); free(msg); return 0; From 2dd9e07e07802c9afaf4cd3461d9473bccf44844 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Wed, 13 Dec 2023 18:48:20 -0500 Subject: [PATCH 22/68] Na lms kat multi level (#1620) * 2-level LMS Support * Add LMS KAT from RFC 8554 * Fix format * Add multi level LMS variants supported by other libraried * Added 2-Level LMS Variants. Updated test vector format per code review comments. Updated tests accordingly. * Removed unused variable * Update per comments * Added stateful example application and review comments * Fixed use of uninit var * Update some comments * rename LMS KAT files * rename LMS KAT files * Added LMS KAT * rename KAT file * add individual options * add missing N32 in algorithm name * Use strip to remove new line, instead of [1:-2]. Add algo_dir = lms * Rename KATs.json for LMS * Shorten LMS names * Supported KAT files for LMS * Remove unsupported KAT files * Fix format * Fix mem leak * Add testcase for hash corner. Fix hash increment problem. * Fix formatting --------- Co-authored-by: Duc Nguyen --- .CMake/alg_support.cmake | 2 + README.md | 4 + src/common/sha2/sha2_armv8.c | 38 +- src/common/sha2/sha2_c.c | 10 +- src/oqsconfig.h.cmake | 2 + src/sig_stfl/lms/sig_stfl_lms.c | 1235 ++++++++++++++++- src/sig_stfl/lms/sig_stfl_lms.h | 181 ++- src/sig_stfl/lms/sig_stfl_lms_functions.c | 136 +- src/sig_stfl/sig_stfl.c | 270 ++-- src/sig_stfl/sig_stfl.h | 144 +- tests/CMakeLists.txt | 4 + tests/KATs/sig_stfl/kats.json | 4 +- .../sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp | 8 + .../sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp | 8 + tests/example_sig_stfl.c | 133 ++ tests/helpers.py | 14 +- tests/kat_sig_stfl.c | 143 +- tests/test_hash.c | 14 +- tests/test_sig_stfl.c | 1 + 19 files changed, 2085 insertions(+), 266 deletions(-) create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp create mode 100644 tests/example_sig_stfl.c diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index da79308dfd..27ce29c1da 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -529,6 +529,8 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 "" ON "OQS_ENA option(OQS_ENABLE_SIG_STFL_LMS "Enable LMS algorithm family" ON) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) if((OQS_MINIMAL_BUILD STREQUAL "ON")) message(FATAL_ERROR "OQS_MINIMAL_BUILD option ${OQS_MINIMAL_BUILD} no longer supported") diff --git a/README.md b/README.md index 53ef332e24..f91e39dea0 100644 --- a/README.md +++ b/README.md @@ -68,6 +68,8 @@ All names other than `ML-KEM` and `ML-DSA` are subject to change. `liboqs` makes - **ML-DSA**: ML-DSA-44-ipd (alias: ML-DSA-44), ML-DSA-65-ipd (alias: ML-DSA-65), ML-DSA-87-ipd (alias: ML-DSA-87) - **SPHINCS+-SHA2**: SPHINCS+-SHA2-128f-simple, SPHINCS+-SHA2-128s-simple, SPHINCS+-SHA2-192f-simple, SPHINCS+-SHA2-192s-simple, SPHINCS+-SHA2-256f-simple, SPHINCS+-SHA2-256s-simple - **SPHINCS+-SHAKE**: SPHINCS+-SHAKE-128f-simple, SPHINCS+-SHAKE-128s-simple, SPHINCS+-SHAKE-192f-simple, SPHINCS+-SHAKE-192s-simple, SPHINCS+-SHAKE-256f-simple, SPHINCS+-SHAKE-256s-simple +- **XMSS**: XMSS-SHA2_10_256, XMSS-SHA2_16_256, XMSS-SHA2_20_256, XMSS-SHAKE_10_256, XMSS-SHAKE_16_256, XMSS-SHAKE_20_256, XMSS-SHA2_10_512, XMSS-SHA2_16_512, XMSS-SHA2_20_512, XMSS-SHAKE_10_512, XMSS-SHAKE_16_512, XMSS-SHAKE_20_512, XMSSMT-SHA2_20/2_256, XMSSMT-SHA2_20/4_256, XMSSMT-SHA2_40/2_256, XMSSMT-SHA2_40/4_256, XMSSMT-SHA2_40/8_256, XMSSMT-SHA2_60/3_256, XMSSMT-SHA2_60/6_256, XMSSMT-SHA2_60/12_256, XMSSMT-SHAKE_20/2_256, XMSSMT-SHAKE_20/4_256, XMSSMT-SHAKE_40/2_256, XMSSMT-SHAKE_40/4_256, XMSSMT-SHAKE_40/8_256, XMSSMT-SHAKE_60/3_256, XMSSMT-SHAKE_60/6_256, XMSSMT-SHAKE_60/12_256 +- **LMS**: LMS_SHA256_H5_W1, LMS_SHA256_H5_W2, LMS_SHA256_H5_W4, LMS_SHA256_H5_W8, LMS_SHA256_H10_W1, LMS_SHA256_H10_W2, LMS_SHA256_H10_W4, LMS_SHA256_H10_W8, LMS_SHA256_H15_W1, LMS_SHA256_H15_W2, LMS_SHA256_H15_W4, LMS_SHA256_H15_W8, LMS_SHA256_H20_W1, LMS_SHA256_H20_W2, LMS_SHA256_H20_W4, LMS_SHA256_H20_W8, LMS_SHA256_H25_W1, LMS_SHA256_H25_W2, LMS_SHA256_H25_W4, LMS_SHA256_H25_W8, LMS_SHA256_H5_W8_H5_W8, LMS_SHA256_H10_W4_H5_W8, LMS_SHA256_H10_W8_H5_W8, LMS_SHA256_H10_W2_H10_W2, LMS_SHA256_H10_W4_H10_W4, LMS_SHA256_H10_W8_H10_W8, LMS_SHA256_H15_W8_H5_W8, LMS_SHA256_H15_W8_H10_W8, LMS_SHA256_H15_W8_H15_W8, LMS_SHA256_H20_W8_H5_W8, LMS_SHA256_H20_W8_H10_W8, LMS_SHA256_H20_W8_H15_W8, LMS_SHA256_H20_W8_H20_W8 Note that for algorithms marked with a dagger (†), liboqs contains at least one implementation that uses a large amount of stack space; this may cause failures when run in threads or in constrained environments. For more information, consult the algorithm information sheets in the [docs/algorithms](https://github.com/open-quantum-safe/liboqs/tree/main/docs/algorithms) folder. @@ -124,10 +126,12 @@ The following instructions assume we are in `build`. - `test_kem`: Simple test harness for key encapsulation mechanisms - `test_sig`: Simple test harness for key signature schemes + - `test_sig_stfl`: Simple test harness for stateful key signature schemes - `test_kem_mem`: Simple test harness for checking memory consumption of key encapsulation mechanisms - `test_sig_mem`: Simple test harness for checking memory consumption of key signature schemes - `kat_kem`: Program that generates known answer test (KAT) values for key encapsulation mechanisms using the same procedure as the NIST submission requirements, for checking against submitted KAT values using `tests/test_kat.py` - `kat_sig`: Program that generates known answer test (KAT) values for signature schemes using the same procedure as the NIST submission requirements, for checking against submitted KAT values using `tests/test_kat.py` + - `kat_stfl_sig`: Program for checking results against submitted KAT values using `tests/test_kat.py` - `speed_kem`: Benchmarking program for key encapsulation mechanisms; see `./speed_kem --help` for usage instructions - `speed_sig`: Benchmarking program for signature mechanisms; see `./speed_sig --help` for usage instructions - `example_kem`: Minimal runnable example showing the usage of the KEM API diff --git a/src/common/sha2/sha2_armv8.c b/src/common/sha2/sha2_armv8.c index f3bbf573a1..71d2cebb59 100644 --- a/src/common/sha2/sha2_armv8.c +++ b/src/common/sha2/sha2_armv8.c @@ -187,8 +187,11 @@ void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const ui } memcpy(tmp_in, state->data, state->data_len); - memcpy(tmp_in + state->data_len, in, inlen); + if (in && inlen) { + memcpy(tmp_in + state->data_len, in, inlen); + } new_in = tmp_in; + state->data_len = 0; } uint64_t bytes = load_bigendian_64(state->ctx + 32) + new_inlen; @@ -280,33 +283,34 @@ void oqs_sha2_sha256_inc_blocks_armv8(sha256ctx *state, const uint8_t *in, size_ void oqs_sha2_sha256_inc_armv8(sha256ctx *state, const uint8_t *in, size_t len) { uint64_t bytes = 0; + size_t in_index = 0; while (len) { size_t incr = 64 - state->data_len; if (incr > len) { incr = len; } - for (size_t i = 0; i < incr; ++i, state->data_len++) { - state->data[state->data_len] = in[i]; + for (size_t i = 0; i < incr; ++i, state->data_len++, in_index++)) { + state->data[state->data_len] = in[in_index++)]; } if (state->data_len < 64) { - break; - } + break; + } - /* - * Process a complete block now - */ - bytes = load_bigendian_64(state->ctx + 32) + 64; - crypto_hashblocks_sha256_armv8(state->ctx, state->data, 64); - store_bigendian_64(state->ctx + 32, bytes); + /* + * Process a complete block now + */ + bytes = load_bigendian_64(state->ctx + 32) + 64; + crypto_hashblocks_sha256_armv8(state->ctx, state->data, 64); + store_bigendian_64(state->ctx + 32, bytes); - /* - * update the remaining input - */ - len -= incr; - state->data_len = 0; - } + /* + * update the remaining input + */ + len -= incr; + state->data_len = 0; +} } void oqs_sha2_sha224_inc_blocks_armv8(sha224ctx *state, const uint8_t *in, size_t inblocks) { diff --git a/src/common/sha2/sha2_c.c b/src/common/sha2/sha2_c.c index 33863f8040..b0f628136a 100644 --- a/src/common/sha2/sha2_c.c +++ b/src/common/sha2/sha2_c.c @@ -654,14 +654,15 @@ void oqs_sha2_sha256_inc_blocks_c(sha256ctx *state, const uint8_t *in, size_t in void oqs_sha2_sha256_inc_c(sha256ctx *state, const uint8_t *in, size_t len) { uint64_t bytes = 0; + size_t in_index = 0; while (len) { size_t incr = 64 - state->data_len; if (incr > len) { incr = len; } - for (size_t i = 0; i < incr; ++i, state->data_len++) { - state->data[state->data_len] = in[i]; + for (size_t i = 0; i < incr; ++i, state->data_len++, in_index++) { + state->data[state->data_len] = in[in_index]; } if (state->data_len < 64) { @@ -718,8 +719,11 @@ void oqs_sha2_sha256_inc_finalize_c(uint8_t *out, sha256ctx *state, const uint8_ } memcpy(tmp_in, state->data, state->data_len); - memcpy(tmp_in + state->data_len, in, inlen); + if (in && inlen) { + memcpy(tmp_in + state->data_len, in, inlen); + } new_in = tmp_in; + state->data_len = 0; } uint64_t bytes = load_bigendian_64(state->ctx + 32) + new_inlen; diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index 9626119e71..c2de65c545 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -222,3 +222,5 @@ #cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 1 #cmakedefine OQS_ENABLE_SIG_STFL_LMS 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 1 diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index b6d57902ee..9e65a5e442 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -22,7 +22,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h5_w1) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w1) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -36,8 +36,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h5_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1; + sig->oid = OQS_LMS_ID_sha256_h5_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w1; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -109,7 +109,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair(uint8_t *public_key return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h5_w2) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w2) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -123,8 +123,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h5_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2; + sig->oid = OQS_LMS_ID_sha256_h5_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w2; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -196,7 +196,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair(uint8_t *public_key return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h5_w4) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w4) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -210,8 +210,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h5_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4; + sig->oid = OQS_LMS_ID_sha256_h5_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w4; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -283,7 +283,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h5_w8) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w8) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -297,8 +297,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h5_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8; + sig->oid = OQS_LMS_ID_sha256_h5_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w8; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -370,7 +370,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w1_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h10_w1) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w1) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -384,8 +384,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h10_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1; + sig->oid = OQS_LMS_ID_sha256_h10_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w1; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -457,7 +457,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h10_w2) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w2) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -471,8 +471,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h10_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2; + sig->oid = OQS_LMS_ID_sha256_h10_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w2; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -544,7 +544,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h10_w4) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w4) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -558,8 +558,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h10_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4; + sig->oid = OQS_LMS_ID_sha256_h10_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w4; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -631,7 +631,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h10_w8) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w8) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -645,8 +645,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h10_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8; + sig->oid = OQS_LMS_ID_sha256_h10_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w8; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -718,7 +718,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w1_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h15_w1) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w1) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -732,8 +732,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h15_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1; + sig->oid = OQS_LMS_ID_sha256_h15_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w1; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -805,7 +805,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w2_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h15_w2) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w2) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -819,8 +819,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h15_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2; + sig->oid = OQS_LMS_ID_sha256_h15_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w2; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -892,7 +892,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w4_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h15_w4) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w4) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -906,8 +906,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h15_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4; + sig->oid = OQS_LMS_ID_sha256_h15_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w4; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -979,7 +979,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h15_w8) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w8) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -993,8 +993,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h15_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8; + sig->oid = OQS_LMS_ID_sha256_h15_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w8; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1066,7 +1066,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w1_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h20_w1) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w1) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -1080,8 +1080,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h20_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1; + sig->oid = OQS_LMS_ID_sha256_h20_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w1; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1153,7 +1153,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w2_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h20_w2) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w2) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -1167,8 +1167,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h20_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2; + sig->oid = OQS_LMS_ID_sha256_h20_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w2; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1240,7 +1240,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w4_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h20_w4) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w4) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -1254,8 +1254,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h20_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4; + sig->oid = OQS_LMS_ID_sha256_h20_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w4; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1327,7 +1327,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h20_w8) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -1341,8 +1341,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h20_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8; + sig->oid = OQS_LMS_ID_sha256_h20_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1414,7 +1414,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w1_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h25_w1) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h25_w1) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -1428,8 +1428,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h25_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1; + sig->oid = OQS_LMS_ID_sha256_h25_w1; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h25_w1; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1501,7 +1501,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w2_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h25_w2) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h25_w2) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -1515,8 +1515,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h25_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2; + sig->oid = OQS_LMS_ID_sha256_h25_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h25_w2; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1588,7 +1588,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w4_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h25_w4) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h25_w4) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -1602,8 +1602,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h25_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4; + sig->oid = OQS_LMS_ID_sha256_h25_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h25_w4; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1675,7 +1675,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w8_keypair(uint8_t *public_ke return OQS_ERROR; } - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_n32_h25_w8) != 0) { + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h25_w8) != 0) { return OQS_ERROR; } return OQS_SUCCESS; @@ -1689,8 +1689,8 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(void) { } memset(sig, 0, sizeof(OQS_SIG_STFL)); - sig->oid = OQS_LMS_ID_sha256_n32_h25_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8; + sig->oid = OQS_LMS_ID_sha256_h25_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h25_w8; sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; sig->euf_cma = true; @@ -1755,6 +1755,1121 @@ OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(void) { return sk; } +// +//2-Level LMS +// ======================== LMS-SHA256 H5/W8, H5/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w8_h5_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h5_w8_h5_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_H5_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W2, H10/W2 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w2_h10_w2) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h10_w2_h10_w2; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_H10_W2_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W4, H5/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w4_h5_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h10_w4_h5_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H5_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W4, H10/W4 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w4_h10_w4) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h10_w4_h10_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H10_W4_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W8, H5/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w8_h5_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h10_w8_h5_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H5_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H10/W8, H10/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w8_h10_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h15_w4; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H10_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H15/W8, H5/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w8_h5_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h15_w8_h5_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H5_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H15/W8, H10/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w8_h10_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h15_w8_h10_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H10_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H15/W8, H15/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w8_h15_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h15_w8_h15_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H15_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H20/W8, H5/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8_h5_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h20_w8_h5_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H5_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H20/W8, H10/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8_h10_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h20_w8_h10_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H10_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H20/W8, H15/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8_h15_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h20_w8_h15_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H15_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} + +// ======================== LMS-SHA256 H20/W8, H20/W8 ======================== // + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { + if (secret_key == NULL || public_key == NULL) { + return OQS_ERROR; + } + + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8_h20_w8) != 0) { + return OQS_ERROR; + } + return OQS_SUCCESS; +} + +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_new(void) { + + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); + if (sig == NULL) { + return NULL; + } + memset(sig, 0, sizeof(OQS_SIG_STFL)); + + sig->oid = OQS_LMS_ID_sha256_h20_w8_h20_w8; + sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8; + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; + sig->euf_cma = true; + + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; + sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_length_signature; + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair; + sig->sign = OQS_SIG_STFL_alg_lms_sign; + sig->verify = OQS_SIG_STFL_alg_lms_verify; + + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; + + return sig; +} + +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H20_W8_new(void) { + + // Initialize the secret key in the heap with adequate memory + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); + if (sk == NULL) { + return NULL; + } + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); + + // Initialize the key with length_secret_key amount of bytes. + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; + + /* + * Secret Key retrieval Function + */ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; + + /* + * set Secret Key to internal structure Function + */ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; + + /* + * Set Secret Key Locking Function + */ + sk->lock_key = NULL; + + /* + * Set Secret Key Unlocking / Releasing Function + */ + sk->unlock_key = NULL; + + /* + * Set Secret Key Saving Function + */ + sk->secure_store_scrt_key = NULL; + + /* + * Set Secret Key free function + */ + sk->free_key = OQS_SECRET_KEY_LMS_free; + + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; + + return sk; +} +//2-Level LMS + + void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk) { oqs_secret_lms_key_free(sk); } diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index b75446d2e3..8380656eb0 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -7,30 +7,88 @@ //OQS LMS parameter identifiers /* Defined LM parameter sets */ -#define OQS_LMS_ID_sha256_n32_h5_w1 0x1 //"5/1" -#define OQS_LMS_ID_sha256_n32_h5_w2 0x2 //"5/2" -#define OQS_LMS_ID_sha256_n32_h5_w4 0x3 //"5/4" -#define OQS_LMS_ID_sha256_n32_h5_w8 0x4 //"5/8" - -#define OQS_LMS_ID_sha256_n32_h10_w1 0x5 //"10/1" -#define OQS_LMS_ID_sha256_n32_h10_w2 0x7 //"10/2" -#define OQS_LMS_ID_sha256_n32_h10_w4 0x8 //"10/4" -#define OQS_LMS_ID_sha256_n32_h10_w8 0x9 //"10/8" - -#define OQS_LMS_ID_sha256_n32_h15_w1 0xa //"15/1" -#define OQS_LMS_ID_sha256_n32_h15_w2 0xb //"15/2" -#define OQS_LMS_ID_sha256_n32_h15_w4 0xc//"15/4" -#define OQS_LMS_ID_sha256_n32_h15_w8 0xd //"15/8" - -#define OQS_LMS_ID_sha256_n32_h20_w1 0xe //"20/1" -#define OQS_LMS_ID_sha256_n32_h20_w2 0xf //"20/2" -#define OQS_LMS_ID_sha256_n32_h20_w4 0x10 //"20/4" -#define OQS_LMS_ID_sha256_n32_h20_w8 0x11 //"20/8" - -#define OQS_LMS_ID_sha256_n32_h25_w1 0x12 //"25/1" -#define OQS_LMS_ID_sha256_n32_h25_w2 0x13 //"25/2" -#define OQS_LMS_ID_sha256_n32_h25_w4 0x14 //"25/4" -#define OQS_LMS_ID_sha256_n32_h25_w8 0x15 //"25/8" +/* + * Convention + * Where ... + * L = number of Levels + * H = LMS H ID + * LMS_SHA256_M32_H5 0x05 + * LMS_SHA256_M32_H10 0x06 + * LMS_SHA256_M32_H15 0x07 + * LMS_SHA256_M32_H20 0x08 + * LMS_SHA256_M32_H25 0x09 + * + * W = Winternitz value + * LMOTS_SHA256_N32_W1 0x01 + * LMOTS_SHA256_N32_W2 0x02 + * LMOTS_SHA256_N32_W4 0x03 + * LMOTS_SHA256_N32_W8 0x04 + * + * e.g. + * OQS_LMS_ID_sha256_h5_w1 -- "5/1" ----- 0x0151 + * "5/1,5/2" ----- 0x025152 + * Number of levels L {1, 2, 3, ..., 8} + * 0x0LH(l1))W(l1)H(l2)W(l2) + * e.g + * For OQS_LMS_ID_sha256_h5_w1 the oid is 0x0151 + * Number of levels is.....0x01 + * H5 ID is.........5 + * W1 ID is..........1 + * +* For OQS_LMS_ID_sha256_h10_w4_h5_w8 the is 0x026354 + * Number of levels is.......0x02 + * Level 1 H10 ID is...........6 + * Level 1 W4 ID is............3 + * Level 2 H5 ID is.............5 + * Level 2 W8 ID is..............4 + */ +#define OQS_LMS_ID_sha256_h5_w1 0x0151 //"5/1" +#define OQS_LMS_ID_sha256_h5_w2 0x0152 //"5/2" +#define OQS_LMS_ID_sha256_h5_w4 0x0153 //"5/4" +#define OQS_LMS_ID_sha256_h5_w8 0x0154 //"5/8" + +#define OQS_LMS_ID_sha256_h10_w1 0x0161 //"10/1" +#define OQS_LMS_ID_sha256_h10_w2 0x0162 //"10/2" +#define OQS_LMS_ID_sha256_h10_w4 0x0163 //"10/4" +#define OQS_LMS_ID_sha256_h10_w8 0x0164 //"10/8" + +#define OQS_LMS_ID_sha256_h15_w1 0x0171 //"15/1" +#define OQS_LMS_ID_sha256_h15_w2 0x0172 //"15/2" +#define OQS_LMS_ID_sha256_h15_w4 0x0173 //"15/4" +#define OQS_LMS_ID_sha256_h15_w8 0x0174 //"15/8" + +#define OQS_LMS_ID_sha256_h20_w1 0x0181 //"20/1" +#define OQS_LMS_ID_sha256_h20_w2 0x0182 //"20/2" +#define OQS_LMS_ID_sha256_h20_w4 0x0183 //"20/4" +#define OQS_LMS_ID_sha256_h20_w8 0x0184 //"20/8" + +#define OQS_LMS_ID_sha256_h25_w1 0x0191 //"25/1" +#define OQS_LMS_ID_sha256_h25_w2 0x0192 //"25/2" +#define OQS_LMS_ID_sha256_h25_w4 0x0193 //"25/4" +#define OQS_LMS_ID_sha256_h25_w8 0x0194 //"25/8" + +//2-Level LMS + +//RFC 8554 example +#define OQS_LMS_ID_sha256_h5_w8_h5_w8 0x025454 //"5/8,5/8" + +//RFC 8554 example +#define OQS_LMS_ID_sha256_h10_w4_h5_w8 0x026354 //"10/4,5/8" + +//Wolf +#define OQS_LMS_ID_sha256_h10_w2_h10_w2 0x026262 //"10/2,10/2" +#define OQS_LMS_ID_sha256_h10_w4_h10_w4 0x026363 //"10/4,10/4" + +#define OQS_LMS_ID_sha256_h10_w8_h5_w8 0x026454 //"10/8,5/8" +//Wolf +#define OQS_LMS_ID_sha256_h10_w8_h10_w8 0x026464 //"10/8,10/8" +#define OQS_LMS_ID_sha256_h15_w8_h5_w8 0x027454 //"15/8,5/8" +#define OQS_LMS_ID_sha256_h15_w8_h10_w8 0x027464 //"15/8,10/8" +#define OQS_LMS_ID_sha256_h15_w8_h15_w8 0x027474 //"15/8,15/8" +#define OQS_LMS_ID_sha256_h20_w8_h5_w8 0x028454 //"20/8,5/8" +#define OQS_LMS_ID_sha256_h20_w8_h10_w8 0x028464 //"20/8,10/8" +#define OQS_LMS_ID_sha256_h20_w8_h15_w8 0x028474 //"20/8,15/8" +#define OQS_LMS_ID_sha256_h20_w8_h20_w8 0x028484 //"20/8,20/8" //H5 #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_signature 8688 @@ -198,6 +256,81 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *totaln, const void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); + +//2-Level LMS +#define OQS_SIG_STFL_alg_lms_length_private_key 64 +#define OQS_SIG_STFL_alg_lms_length_public_key 60 +#define OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_length_signature 2644 + +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_length_signature 2804 + +#define OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_length_signature 3860 + +#define OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_length_signature 9300 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_length_signature 5076 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_length_signature 2964 + +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_length_signature 2964 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_length_signature 3124 +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_length_signature 3284 + +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_length_signature 3124 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_length_signature 3284 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_length_signature 3444 +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_length_signature 3604 + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_H5_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H5_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H5_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_H10_W2_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H10_W4_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H10_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H5_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H10_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H15_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H5_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H10_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H15_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_new(void); + +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H20_W8_new(void); +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_new(void); + // ----------------------------------- WRAPPER FUNCTIONS ------------------------------------------------ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uint32_t oid); diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index 1e3154b009..b05910d089 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -205,7 +205,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *total, const } *total = (unsigned long long)working_key->max_count; - OQS_MEM_secure_free(working_key, sizeof(struct hss_working_key)); + hss_free_working_key(working_key); return OQS_SUCCESS; } @@ -276,91 +276,182 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uin /* Set lms param set */ switch (oid) { - case OQS_LMS_ID_sha256_n32_h5_w1: + case OQS_LMS_ID_sha256_h5_w1: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; break; - case OQS_LMS_ID_sha256_n32_h5_w2: + case OQS_LMS_ID_sha256_h5_w2: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; break; - case OQS_LMS_ID_sha256_n32_h5_w4: + case OQS_LMS_ID_sha256_h5_w4: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; break; - case OQS_LMS_ID_sha256_n32_h5_w8: + case OQS_LMS_ID_sha256_h5_w8: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; break; - case OQS_LMS_ID_sha256_n32_h10_w1: + case OQS_LMS_ID_sha256_h10_w1: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; break; - case OQS_LMS_ID_sha256_n32_h10_w2: + case OQS_LMS_ID_sha256_h10_w2: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; break; - case OQS_LMS_ID_sha256_n32_h10_w4: + case OQS_LMS_ID_sha256_h10_w4: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; break; - case OQS_LMS_ID_sha256_n32_h10_w8: + case OQS_LMS_ID_sha256_h10_w8: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; break; - case OQS_LMS_ID_sha256_n32_h15_w1: + case OQS_LMS_ID_sha256_h15_w1: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; break; - case OQS_LMS_ID_sha256_n32_h15_w2: + case OQS_LMS_ID_sha256_h15_w2: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; break; - case OQS_LMS_ID_sha256_n32_h15_w4: + case OQS_LMS_ID_sha256_h15_w4: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; break; - case OQS_LMS_ID_sha256_n32_h15_w8: + case OQS_LMS_ID_sha256_h15_w8: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; break; - case OQS_LMS_ID_sha256_n32_h20_w1: + case OQS_LMS_ID_sha256_h20_w1: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; break; - case OQS_LMS_ID_sha256_n32_h20_w2: + case OQS_LMS_ID_sha256_h20_w2: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; break; - case OQS_LMS_ID_sha256_n32_h20_w4: + case OQS_LMS_ID_sha256_h20_w4: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; break; - case OQS_LMS_ID_sha256_n32_h20_w8: + case OQS_LMS_ID_sha256_h20_w8: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; break; - case OQS_LMS_ID_sha256_n32_h25_w1: + case OQS_LMS_ID_sha256_h25_w1: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H25; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W1; break; - case OQS_LMS_ID_sha256_n32_h25_w2: + case OQS_LMS_ID_sha256_h25_w2: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H25; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; break; - case OQS_LMS_ID_sha256_n32_h25_w4: + case OQS_LMS_ID_sha256_h25_w4: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H25; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; break; - case OQS_LMS_ID_sha256_n32_h25_w8: + case OQS_LMS_ID_sha256_h25_w8: oqs_key_data->lm_type[0] = LMS_SHA256_N32_H25; oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; break; - + case OQS_LMS_ID_sha256_h5_w8_h5_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h10_w8_h5_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h10_w2_h10_w2: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W2; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W2; + break; + case OQS_LMS_ID_sha256_h10_w4_h5_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h10_w4_h10_w4: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W4; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W4; + break; + case OQS_LMS_ID_sha256_h10_w8_h10_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h15_w8_h5_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h15_w8_h10_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h15_w8_h15_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h20_w8_h5_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H5; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h20_w8_h10_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H10; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h20_w8_h15_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H15; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + case OQS_LMS_ID_sha256_h20_w8_h20_w8: + oqs_key_data->levels = 2; + oqs_key_data->lm_type[0] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[0] = LMOTS_SHA256_N32_W8; + oqs_key_data->lm_type[1] = LMS_SHA256_N32_H20; + oqs_key_data->lm_ots_type[1] = LMOTS_SHA256_N32_W8; + break; + default: oqs_key_data->lm_type[0] = 0; oqs_key_data->lm_ots_type[0] = 0; parse_err = 1; @@ -503,6 +594,7 @@ int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, *smlen = sig_len; memcpy(sm, sig, sig_len); OQS_MEM_insecure_free(sig); + hss_free_working_key(w); return 0; } diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 9bdee77780..dafbcd8aa5 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -44,30 +44,48 @@ OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { OQS_SIG_STFL_alg_xmssmt_shake128_h60_6, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12, // LMS - OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1, - OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2, - OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4, - OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8, - - OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1, - OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2, - OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4, - OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8, - - OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1, - OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2, - OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4, - OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8, - - OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1, - OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2, - OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4, - OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8, - - OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1, - OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2, - OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4, - OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8, + OQS_SIG_STFL_alg_lms_sha256_h5_w1, + OQS_SIG_STFL_alg_lms_sha256_h5_w2, + OQS_SIG_STFL_alg_lms_sha256_h5_w4, + OQS_SIG_STFL_alg_lms_sha256_h5_w8, + + OQS_SIG_STFL_alg_lms_sha256_h10_w1, + OQS_SIG_STFL_alg_lms_sha256_h10_w2, + OQS_SIG_STFL_alg_lms_sha256_h10_w4, + OQS_SIG_STFL_alg_lms_sha256_h10_w8, + + OQS_SIG_STFL_alg_lms_sha256_h15_w1, + OQS_SIG_STFL_alg_lms_sha256_h15_w2, + OQS_SIG_STFL_alg_lms_sha256_h15_w4, + OQS_SIG_STFL_alg_lms_sha256_h15_w8, + + OQS_SIG_STFL_alg_lms_sha256_h20_w1, + OQS_SIG_STFL_alg_lms_sha256_h20_w2, + OQS_SIG_STFL_alg_lms_sha256_h20_w4, + OQS_SIG_STFL_alg_lms_sha256_h20_w8, + + OQS_SIG_STFL_alg_lms_sha256_h25_w1, + OQS_SIG_STFL_alg_lms_sha256_h25_w2, + OQS_SIG_STFL_alg_lms_sha256_h25_w4, + OQS_SIG_STFL_alg_lms_sha256_h25_w8, + + //2-Level LMS + OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8, + OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8, + + OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8, + OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2, + OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4, + OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8, + + OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8, + OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8, + OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8, + + OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8, + OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8, + OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8, + OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8, }; if (i >= OQS_SIG_STFL_algs_length) { @@ -256,51 +274,79 @@ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name) { #endif } #ifdef OQS_ENABLE_SIG_STFL_LMS - else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w1)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w2)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w4)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w1)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8)) { return 1; } - else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1)) { + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w1)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w2)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w4)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8)) { return 1; } - else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1)) { + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w1)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w2)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w4)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8)) { return 1; } - else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1)) { + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w1)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w2)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w4)) { return 1; - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w8)) { + return 1; + } + //2-Level LMS + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8)) { + return 1; + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8)) { return 1; } #endif //OQS_ENABLE_SIG_STFL_LMS @@ -484,47 +530,75 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { #endif } #ifdef OQS_ENABLE_SIG_STFL_LMS - else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w1)) { return OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w2)) { return OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w4)) { return OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8)) { return OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w1)) { return OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2)) { return OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4)) { return OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8)) { return OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w1)) { return OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w2)) { return OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w4)) { return OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8)) { return OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w1)) { return OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w2)) { return OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w4)) { return OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8)) { return OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w1)) { return OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w2)) { return OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w4)) { return OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w8)) { return OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(); } +//2-Level LMS + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8)) { + return OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_new(); + } #endif //OQS_ENABLE_SIG_STFL_LMS else { return NULL; @@ -754,47 +828,75 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_ #endif } #ifdef OQS_ENABLE_SIG_STFL_LMS - else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1)) { + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w1)) { return OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w2)) { return OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w4)) { return OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8)) { return OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w1)) { return OQS_SECRET_KEY_LMS_SHA256_H10_W1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2)) { return OQS_SECRET_KEY_LMS_SHA256_H10_W2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4)) { return OQS_SECRET_KEY_LMS_SHA256_H10_W4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8)) { return OQS_SECRET_KEY_LMS_SHA256_H10_W8_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w1)) { return OQS_SECRET_KEY_LMS_SHA256_H15_W1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w2)) { return OQS_SECRET_KEY_LMS_SHA256_H15_W2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w4)) { return OQS_SECRET_KEY_LMS_SHA256_H15_W4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8)) { return OQS_SECRET_KEY_LMS_SHA256_H15_W8_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w1)) { return OQS_SECRET_KEY_LMS_SHA256_H20_W1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w2)) { return OQS_SECRET_KEY_LMS_SHA256_H20_W2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w4)) { return OQS_SECRET_KEY_LMS_SHA256_H20_W4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8)) { return OQS_SECRET_KEY_LMS_SHA256_H20_W8_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w1)) { return OQS_SECRET_KEY_LMS_SHA256_H25_W1_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w2)) { return OQS_SECRET_KEY_LMS_SHA256_H25_W2_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w4)) { return OQS_SECRET_KEY_LMS_SHA256_H25_W4_new(); - } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8)) { + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w8)) { return OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(); } +//2-Level LMS + else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H5_W8_H5_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W8_H5_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W2_H10_W2_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W4_H10_W4_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W4_H5_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H10_W8_H10_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H15_W8_H5_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H15_W8_H10_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H15_W8_H15_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H20_W8_H5_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H20_W8_H10_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H20_W8_H15_W8_new(); + } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8)) { + return OQS_SECRET_KEY_LMS_SHA256_H20_W8_H20_W8_new(); + } #endif //OQS_ENABLE_SIG_STFL_LMS else { return NULL; diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index ad55b11d1a..aa83e4c486 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -73,36 +73,55 @@ extern "C" { #define OQS_SIG_STFL_alg_xmssmt_shake128_h60_12 "XMSSMT-SHAKE_60/12_256" /* Defined LMS parameter identifiers */ -#define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w1 "LMS_SHA256_H5_W1" //"5/1" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w2 "LMS_SHA256_H5_W2" //"5/2" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w4 "LMS_SHA256_H5_W4" //"5/4" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h5_w8 "LMS_SHA256_H5_W8" //"5/8" +#define OQS_SIG_STFL_alg_lms_sha256_h5_w1 "LMS_SHA256_H5_W1" //"5/1" +#define OQS_SIG_STFL_alg_lms_sha256_h5_w2 "LMS_SHA256_H5_W2" //"5/2" +#define OQS_SIG_STFL_alg_lms_sha256_h5_w4 "LMS_SHA256_H5_W4" //"5/4" +#define OQS_SIG_STFL_alg_lms_sha256_h5_w8 "LMS_SHA256_H5_W8" //"5/8" + +#define OQS_SIG_STFL_alg_lms_sha256_h10_w1 "LMS_SHA256_H10_W1" //"10/1" +#define OQS_SIG_STFL_alg_lms_sha256_h10_w2 "LMS_SHA256_H10_W2" //"10/2" +#define OQS_SIG_STFL_alg_lms_sha256_h10_w4 "LMS_SHA256_H10_W4" //"10/4" +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8 "LMS_SHA256_H10_W8" //"10/8" + +#define OQS_SIG_STFL_alg_lms_sha256_h15_w1 "LMS_SHA256_H15_W1" //"15/1" +#define OQS_SIG_STFL_alg_lms_sha256_h15_w2 "LMS_SHA256_H15_W2" //"15/2" +#define OQS_SIG_STFL_alg_lms_sha256_h15_w4 "LMS_SHA256_H15_W4" //"15/4" +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8 "LMS_SHA256_H15_W8" //"15/8" + +#define OQS_SIG_STFL_alg_lms_sha256_h20_w1 "LMS_SHA256_H20_W1" //"20/1" +#define OQS_SIG_STFL_alg_lms_sha256_h20_w2 "LMS_SHA256_H20_W2" //"20/2" +#define OQS_SIG_STFL_alg_lms_sha256_h20_w4 "LMS_SHA256_H20_W4" //"20/4" +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8 "LMS_SHA256_H20_W8" //"20/8" + +#define OQS_SIG_STFL_alg_lms_sha256_h25_w1 "LMS_SHA256_H25_W1" //"25/1" +#define OQS_SIG_STFL_alg_lms_sha256_h25_w2 "LMS_SHA256_H25_W2" //"25/2" +#define OQS_SIG_STFL_alg_lms_sha256_h25_w4 "LMS_SHA256_H25_W4" //"25/4" +#define OQS_SIG_STFL_alg_lms_sha256_h25_w8 "LMS_SHA256_H25_W8" //"25/8" + +//2-Level LMS +#define OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8 "LMS_SHA256_H5_W8_H5_W8" //"5/8, 5/8" + +//RFC 6554 +#define OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8 "LMS_SHA256_H10_W4_H5_W8" //"10/4, 5/8" + +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8 "LMS_SHA256_H10_W8_H5_W8" //"10/8, 5/8" +#define OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2 "LMS_SHA256_H10_W2_H10_W2" //"10/2, 10/2" +#define OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4 "LMS_SHA256_H10_W4_H10_W4" //"10/4, 10/4" +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8 "LMS_SHA256_H10_W8_H10_W8" //"10/8, 10/8" + +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8 "LMS_SHA256_H15_W8_H5_W8" //"15/8, 5/8" +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8 "LMS_SHA256_H15_W8_H10_W8" //"15/8, 10/8" +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8 "LMS_SHA256_H15_W8_H15_W8" //"15/8, 15/8" + +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8 "LMS_SHA256_H20_W8_H5_W8" //"20/8, 5/8" +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8 "LMS_SHA256_H20_W8_H10_W8" //"20/8, 10/8" +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8 "LMS_SHA256_H20_W8_H15_W8" //"20/8, 15/8" +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8 "LMS_SHA256_H20_W8_H20_W8" //"20/8, 20/8" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h10_w1 "LMS_SHA256_H10_W1" //"10/1" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h10_w2 "LMS_SHA256_H10_W2" //"10/2" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h10_w4 "LMS_SHA256_H10_W4" //"10/4" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h10_w8 "LMS_SHA256_H10_W8" //"10/8" - -#define OQS_SIG_STFL_alg_lms_sha256_n32_h15_w1 "LMS_SHA256_H15_W1" //"15/1" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h15_w2 "LMS_SHA256_H15_W2" //"15/2" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h15_w4 "LMS_SHA256_H15_W4" //"15/4" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h15_w8 "LMS_SHA256_H15_W8" //"15/8" - -#define OQS_SIG_STFL_alg_lms_sha256_n32_h20_w1 "LMS_SHA256_H20_W1" //"20/1" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h20_w2 "LMS_SHA256_H20_W2" //"20/2" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h20_w4 "LMS_SHA256_H20_W4" //"20/4" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h20_w8 "LMS_SHA256_H20_W8" //"20/8" - -#define OQS_SIG_STFL_alg_lms_sha256_n32_h25_w1 "LMS_SHA256_H25_W1" //"25/1" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h25_w2 "LMS_SHA256_H25_W2" //"25/2" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h25_w4 "LMS_SHA256_H25_W4" //"25/4" -#define OQS_SIG_STFL_alg_lms_sha256_n32_h25_w8 "LMS_SHA256_H25_W8" //"25/8" - -#define OQS_SIG_STFL_algs_length 48 - -/* Defined LM parameter identifiers */ -/* Algorithm identifier for LMS-SHA256_N32_H5 */ -#define OQS_SIG_STFL_alg_lms_sha256_n32_h5 "LMS-SHA256_N32_H5" //0x00000005 +/* + * Total number of stateful variants defined above, used to create the tracking array + */ +#define OQS_SIG_STFL_algs_length 61 typedef struct OQS_SIG_STFL_SECRET_KEY OQS_SIG_STFL_SECRET_KEY; @@ -110,7 +129,7 @@ typedef struct OQS_SIG_STFL_SECRET_KEY OQS_SIG_STFL_SECRET_KEY; * Application provided function to securely store data * @param[in] sk_buf pointer to the data to be saved * @param[in] buf_len length of the data to be stored - * @param[out] context pointer to application relevant data. + * @param[out] context pass back application data related to secret key data storage. * return OQS_SUCCESS if successful, otherwise OQS_ERROR */ typedef OQS_STATUS (*secure_store_sk)(uint8_t *sk_buf, size_t buf_len, void *context); @@ -200,7 +219,7 @@ typedef struct OQS_SIG_STFL { * compile-time macros `OQS_SIG_STFL_*_length_*`. * * @param[out] public_key The public key is represented as a byte string. - * @param[out] secret_key The secret key is represented as a byte string + * @param[out] secret_key The secret key object * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*keypair)(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -216,7 +235,7 @@ typedef struct OQS_SIG_STFL { * @param[out] signature_len The length of the signature. * @param[in] message The message to sign is represented as a byte string. * @param[in] message_len The length of the message to sign. - * @param[in] secret_key The secret key is represented as a byte string. + * @param[in] secret_key The secret key object pointer. * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*sign)(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -237,7 +256,7 @@ typedef struct OQS_SIG_STFL { * Query number of remaining signatures * * @param[out] remain The number of remaining signatures - * @param[in] secret_key The secret key is represented as a byte string. + * @param[in] secret_key The secret key object pointer. * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*sigs_remaining)(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -246,7 +265,7 @@ typedef struct OQS_SIG_STFL { * Total number of signatures * * @param[out] total The total number of signatures - * @param[in] secret_key The secret key is represented as a byte string. + * @param[in] secret_key The secret key key object pointer. * @return OQS_SUCCESS or OQS_ERROR */ OQS_STATUS (*sigs_total)(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -271,7 +290,7 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /* mutual exclusion struct */ void *mutex; - /* file storage handle */ + /* Application managed data related to secure storage of secret key data */ void *context; /** @@ -292,6 +311,8 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * @param[in] key_len length of the returned byte string * @param[in] sk_buf The secret key data to populate the key object * @param[in] context application-specific data + * used to keep track of this secret key stored in a secure manner. + * The application manages this memory. * @returns status of the operation populated with key material none zero length. * Caller is responsible to **unallocate** the buffer `sk_buf`. */ @@ -315,10 +336,12 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /** * Store Secret Key Function - * Callback function used to securely store key data + * Callback function used to securely store key data after a signature generation. + * When populated, this pointer points to the application supplied secure storage function. * @param[in] sk_buf The serialized secret key data to secure store * @param[in] buf_len length of data to secure - * @param[in] context aids the secure writing of data + * @param[in] context application supplied data used to locate where this secret key + * is stored (passed in at the time the function pointer was set). * * @return OQS_SUCCESS or OQS_ERROR * Ideally written to secure device @@ -333,12 +356,22 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { */ void (*free_key)(OQS_SIG_STFL_SECRET_KEY *sk); + /* + * Secure storage for private keys used in stateful signature schemes is outside the scope of the OQS library. + * This is the responsibility of any adopting application. The application must supply + * a function to for this purpose. A callback function and context data must be set in-order + * to perform stateful signature generation. + * The context var may contain, for example an HSM context, a filename or other such data that + * is used to store the private key. This var is passed into the OQS lib when the application sets + * the callback function use to save/update the private key. + */ /** * Set Secret Key store callback Function * * @param[in] sk secret key pointer to be updated * @param[in] store_cb callback pointer - * @param[in] context secret key specific data/identifier + * @param[in] context application data related to secret key data/identifier storage. + * Provided when OQS_SIG_STFL_SECRET_KEY_SET_store_cb() is called. */ void (*set_scrt_key_store_cb)(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); } OQS_SIG_STFL_SECRET_KEY; @@ -364,7 +397,7 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name); * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. * @param[out] public_key The public key is represented as a byte string. - * @param[out] secret_key The secret key is represented as a byte string. + * @param[out] secret_key The secret key object pointer. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -381,7 +414,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public * @param[out] signature_len The length of the signature. * @param[in] message The message to sign is represented as a byte string. * @param[in] message_len The length of the message to sign. - * @param[in] secret_key The secret key is represented as a byte string. + * @param[in] secret_key The secret key object pointer. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -403,7 +436,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m * Query number of remaining signatures * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. - * @param[in] secret_key The secret key is represented as a byte string. + * @param[in] secret_key The secret key object. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -413,7 +446,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. * @param[out] max The number of remaining signatures - * @param[in] secret_key The secret key is represented as a byte string. + * @param[in] secret_key The secret key object. * @return OQS_SUCCESS or OQS_ERROR */ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -506,15 +539,36 @@ OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); * * @param[in] sk secret key pointer to be updated * @param[in] store_cb callback pointer - * @param[in] context secret key specific data/identifier + * @param[in] context application data related to where/how secret key data storage. + * Applications allocates, tracks, deallocates this. Signature generation fails without this set. * */ void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); -/* Serialize stateful secret key data into a byte string, and return an allocated buffer. Users are responsible for deallocating the buffer `sk_buf`. */ +/** + * OQS_SECRET_KEY_STFL_serialize_key . + * + * Serialize stateful secret key data into a byte string, and + * return an allocated buffer. Users are responsible for deallocating + * the buffer `sk_buf_ptr`. + * + * @param[out] sk_buf_ptr secret key buffer returned. Caller deletes. + * @param[out] sk_len size of the buffer returned + * @param[in] sk secret key pointer to be serialize + */ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); -/* Insert stateful byte string into a secret key object. Users are responsible for deallocating buffer `sk_buf`. */ +/** + * OQS_SECRET_KEY_STFL_deserialize_key . + * + * Insert stateful byte string into a secret key object. + * Users are responsible for deallocating buffer `sk_buf`. + * + * @param[in] sk secret key pointer to be populated + * @param[in] sk_len size of the supplied buffer + * @param[in] sk_buf secret key buffer. Caller deletes. + * @param[in] context application managed data related to where/how secret key data is stored. + */ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf, void *context); #if defined(__cplusplus) diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt index 22c26a053a..c59657f646 100644 --- a/tests/CMakeLists.txt +++ b/tests/CMakeLists.txt @@ -88,6 +88,10 @@ set(KEM_TESTS example_kem kat_kem test_kem test_kem_mem speed_kem vectors_kem) add_executable(example_sig example_sig.c) target_link_libraries(example_sig PRIVATE ${TEST_DEPS}) +# Stateful SIG API tests +add_executable(example_sig_stfl example_sig_stfl.c) +target_link_libraries(example_sig_stfl PRIVATE ${TEST_DEPS}) + add_executable(kat_sig kat_sig.c test_helpers.c) target_link_libraries(kat_sig PRIVATE ${TEST_DEPS}) if(CMAKE_SYSTEM_NAME STREQUAL "Windows" AND BUILD_SHARED_LIBS) diff --git a/tests/KATs/sig_stfl/kats.json b/tests/KATs/sig_stfl/kats.json index 7ed8350ad1..592008ce84 100644 --- a/tests/KATs/sig_stfl/kats.json +++ b/tests/KATs/sig_stfl/kats.json @@ -26,5 +26,7 @@ "XMSSMT-SHAKE_40/8_256" : "cf301b7d978d5c0afcdf3300ba97d829e2e5f737cb449968b19b45f05b987591", "XMSSMT-SHAKE_60/3_256" : "09d26df5e911e98e71ef73a1ab6f224964d4a7beacd8071b4c7f7d1930a537bd", "XMSSMT-SHAKE_60/6_256" : "0692a32e318d5c3ac8631120910b783edfed4cb7ed69e3ffa29f83aaa34e27d5", - "XMSSMT-SHAKE_60/12_256" : "1a05ff4a4fea850a5fe5c9e976006577335eab0494e1759fe217c2f33f5a84e6" + "XMSSMT-SHAKE_60/12_256" : "1a05ff4a4fea850a5fe5c9e976006577335eab0494e1759fe217c2f33f5a84e6", + "LMS_SHA256_H5_W8_H5_W8": "fa6f9a0948626c1e078ad442ea2fccdf456b529413eba441c175cbb681f9bc32", + "LMS_SHA256_H10_W4_H5_W8": "2485c56164bbfa4bdc8604195bf397bfe8f54e2ebe925423e4e70fce173c0fff" } \ No newline at end of file diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp new file mode 100644 index 0000000000..d5b66c3f7d --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H10_W4_H5_W8 + +msg = 54686520656e756d65726174696f6e20696e2074686520436f6e737469747574696f6e2c206f66206365727461696e207269676874732c207368616c6c206e6f7420626520636f6e73747275656420746f2064656e79206f7220646973706172616765206f74686572732072657461696e6564206279207468652070656f706c652e0a + +sm = 0000000100000003000000033d46bee8660f8f215d3f96408a7a64cf1c4da02b63a55f62c666ef5707a914ce0674e8cb7a55f0c48d484f31f3aa4af9719a74f22cf823b94431d01c926e2a76bb71226d279700ec81c9e95fb11a0d10d065279a5796e265ae17737c44eb8c594508e126a9a7870bf4360820bdeb9a01d9693779e416828e75bddd7d8c70d50a0ac8ba39810909d445f44cb5bb58de737e60cb4345302786ef2c6b14af212ca19edeaa3bfcfe8baa6621ce88480df2371dd37add732c9de4ea2ce0dffa53c92649a18d39a50788f4652987f226a1d48168205df6ae7c58e049a25d4907edc1aa90da8aa5e5f7671773e941d8055360215c6b60dd35463cf2240a9c06d694e9cb54e7b1e1bf494d0d1a28c0d31acc75161f4f485dfd3cb9578e836ec2dc722f37ed30872e07f2b8bd0374eb57d22c614e09150f6c0d8774a39a6e168211035dc52988ab46eaca9ec597fb18b4936e66ef2f0df26e8d1e34da28cbb3af752313720c7b345434f72d65314328bbb030d0f0f6d5e47b28ea91008fb11b05017705a8be3b2adb83c60a54f9d1d1b2f476f9e393eb5695203d2ba6ad815e6a111ea293dcc21033f9453d49c8e5a6387f588b1ea4f706217c151e05f55a6eb7997be09d56a326a32f9cba1fbe1c07bb49fa04cecf9df1a1b815483c75d7a27cc88ad1b1238e5ea986b53e087045723ce16187eda22e33b2c70709e53251025abde8939645fc8c0693e97763928f00b2e3c75af3942d8ddaee81b59a6f1f67efda0ef81d11873b59137f67800b35e81b01563d187c4a1575a1acb92d087b517a8833383f05d357ef4678de0c57ff9f1b2da61dfde5d88318bcdde4d9061cc75c2de3cd4740dd7739ca3ef66f1930026f47d9ebaa713b07176f76f953e1c2e7f8f271a6ca375dbfb83d719b1635a7d8a13891957944b1c29bb101913e166e11bd5f34186fa6c0a555c9026b256a6860f4866bd6d0b5bf90627086c6149133f8282ce6c9b3622442443d5eca959d6c14ca8389d12c4068b503e4e3c39b635bea245d9d05a2558f249c9661c0427d2e489ca5b5dde220a90333f4862aec793223c781997da98266c12c50ea28b2c438e7a379eb106eca0c7fd6006e9bf612f3ea0a454ba3bdb76e8027992e60de01e9094fddeb3349883914fb17a9621ab929d970d101e45f8278c14b032bcab02bd15692d21b6c5c204abbf077d465553bd6eda645e6c3065d33b10d518a61e15ed0f092c32226281a29c8a0f50cde0a8c66236e29c2f310a375cebda1dc6bb9a1a01dae6c7aba8ebedc6371a7d52aacb955f83bd6e4f84d2949dcc198fb77c7e5cdf6040b0f84faf82808bf985577f0a2acf2ec7ed7c0b0ae8a270e951743ff23e0b2dd12e9c3c828fb5598a22461af94d568f29240ba2820c4591f71c088f96e095dd98beae456579ebbba36f6d9ca2613d1c26eee4d8c73217ac5962b5f3147b492e8831597fd89b64aa7fde82e1974d2f6779504dc21435eb3109350756b9fdabe1c6f368081bd40b27ebcb9819a75d7df8bb07bb05db1bab705a4b7e37125186339464ad8faaa4f052cc1272919fde3e025bb64aa8e0eb1fcbfcc25acb5f718ce4f7c2182fb393a1814b0e942490e52d3bca817b2b26e90d4c9b0cc38608a6cef5eb153af0858acc867c9922aed43bb67d7b33acc519313d28d41a5c6fe6cf3595dd5ee63f0a4c4065a083590b275788bee7ad875a7f88dd73720708c6c6c0ecf1f43bbaadae6f208557fdc07bd4ed91f88ce4c0de842761c70c186bfdafafc444834bd3418be4253a71eaf41d718753ad07754ca3effd5960b0336981795721426803599ed5b2b7516920efcbe32ada4bcf6c73bd29e3fa152d9adeca36020fdeeee1b739521d3ea8c0da497003df1513897b0f54794a873670b8d93bcca2ae47e64424b7423e1f078d9554bb5232cc6de8aae9b83fa5b9510beb39ccf4b4e1d9c0f19d5e17f58e5b8705d9a6837a7d9bf99cd13387af256a8491671f1f2f22af253bcff54b673199bdb7d05d81064ef05f80f0153d0be7919684b23da8d42ff3effdb7ca0985033f389181f47659138003d712b5ec0a614d31cc7487f52de8664916af79c98456b2c94a8038083db55391e3475862250274a1de2584fec975fb09536792cfbfcf6192856cc76eb5b13dc4709e2f7301ddff26ec1b23de2d188c999166c74e1e14bbc15f457cf4e471ae13dcbdd9c50f4d646fc6278e8fe7eb6cb5c94100fa870187380b777ed19d7868fd8ca7ceb7fa7d5cc861c5bdac98e7495eb0a2ceec1924ae979f44c5390ebedddc65d6ec11287d978b8df064219bc5679f7d7b264a76ff272b2ac9f2f7cfc9fdcfb6a51428240027afd9d52a79b647c90c2709e060ed70f87299dd798d68f4fadd3da6c51d839f851f98f67840b964ebe73f8cec41572538ec6bc131034ca2894eb736b3bda93d9f5f6fa6f6c0f03ce43362b8414940355fb54d3dfdd03633ae108f3de3ebc85a3ff51efeea3bc2cf27e1658f1789ee612c83d0f5fd56f7cd071930e2946beeecaa04dccea9f97786001475e0294bc2852f62eb5d39bb9fbeef75916efe44a662ecae37ede27e9d6eadfdeb8f8b2b2dbccbf96fa6dbaf7321fb0e701f4d429c2f4dcd153a2742574126e5eaccc77686acf6e3ee48f423766e0fc466810a905ff5453ec99897b56bc55dd49b991142f65043f2d744eeb935ba7f4ef23cf80cc5a8a335d3619d781e7454826df720eec82e06034c44699b5f0c44a8787752e057fa3419b5bb0e25d30981e41cb1361322dba8f69931cf42fad3f3bce6ded5b8bfc3d20a2148861b2afc14562ddd27f12897abf0685288dcc5c4982f826026846a24bf77e383c7aacab1ab692b29ed8c018a65f3dc2b87ff619a633c41b4fadb1c78725c1f8f922f6009787b1964247df0136b1bc614ab575c59a16d089917bd4a8b6f04d95c581279a139be09fcf6e98a470a0bceca191fce476f9370021cbc05518a7efd35d89d8577c990a5e19961ba16203c959c91829ba7497cffcbb4b294546454fa5388a23a22e805a5ca35f956598848bda678615fec28afd5da61a00000006b326493313053ced3876db9d237148181b7173bc7d042cefb4dbe94d2e58cd21a769db4657a103279ba8ef3a629ca84ee836172a9c50e51f45581741cf8083150b491cb4ecbbabec128e7c81a46e62a67b57640a0a78be1cbf7dd9d419a10cd8686d16621a80816bfdb5bdc56211d72ca70b81f1117d129529a7570cf79cf52a7028a48538ecdd3b38d3d5d62d26246595c4fb73a525a5ed2c30524ebb1d8cc82e0c19bc4977c6898ff95fd3d310b0bae71696cef93c6a552456bf96e9d075e383bb7543c675842bafbfc7cdb88483b3276c29d4f0a341c2d406e40d4653b7e4d045851acf6a0a0ea9c710b805cced4635ee8c107362f0fc8d80c14d0ac49c516703d26d14752f34c1c0d2c4247581c18c2cf4de48e9ce949be7c888e9caebe4a415e291fd107d21dc1f084b1158208249f28f4f7c7e931ba7b3bd0d824a45700000000500000004215f83b7ccb9acbcd08db97b0d04dc2ba1cd035833e0e90059603f26e07ad2aad152338e7a5e5984bcd5f7bb4eba40b700000004000000040eb1ed54a2460d512388cad533138d240534e97b1e82d33bd927d201dfc24ebb11b3649023696f85150b189e50c00e98850ac343a77b3638319c347d7310269d3b7714fa406b8c35b021d54d4fdada7b9ce5d4ba5b06719e72aaf58c5aae7aca057aa0e2e74e7dcfd17a0823429db62965b7d563c57b4cec942cc865e29c1dad83cac8b4d61aacc457f336e6a10b66323f5887bf3523dfcadee158503bfaa89dc6bf59daa82afd2b5ebb2a9ca6572a6067cee7c327e9039b3b6ea6a1edc7fdc3df927aade10c1c9f2d5ff446450d2a3998d0f9f6202b5e07c3f97d2458c69d3c8190643978d7a7f4d64e97e3f1c4a08a7c5bc03fd55682c017e2907eab07e5bb2f190143475a6043d5e6d5263471f4eecf6e2575fbc6ff37edfa249d6cda1a09f797fd5a3cd53a066700f45863f04b6c8a58cfd341241e002d0d2c0217472bf18b636ae547c1771368d9f317835c9b0ef430b3df4034f6af00d0da44f4af7800bc7a5cf8a5abdb12dc718b559b74cab9090e33cc58a955300981c420c4da8ffd67df540890a062fe40dba8b2c1c548ced22473219c534911d48ccaabfb71bc71862f4a24ebd376d288fd4e6fb06ed8705787c5fedc813cd2697e5b1aac1ced45767b14ce88409eaebb601a93559aae893e143d1c395bc326da821d79a9ed41dcfbe549147f71c092f4f3ac522b5cc57290706650487bae9bb5671ecc9ccc2ce51ead87ac01985268521222fb9057df7ed41810b5ef0d4f7cc67368c90f573b1ac2ce956c365ed38e893ce7b2fae15d3685a3df2fa3d4cc098fa57dd60d2c9754a8ade980ad0f93f6787075c3f680a2ba1936a8c61d1af52ab7e21f416be09d2a8d64c3d3d8582968c2839902229f85aee297e717c094c8df4a23bb5db658dd377bf0f4ff3ffd8fba5e383a48574802ed545bbe7a6b4753533353d73706067640135a7ce517279cd683039747d218647c86e097b0daa2872d54b8f3e5085987629547b830d8118161b65079fe7bc59a99e9c3c7380e3e70b7138fe5d9be2551502b698d09ae193972f27d40f38dea264a0126e637d74ae4c92a6249fa103436d3eb0d4029ac712bfc7a5eacbdd7518d6d4fe903a5ae65527cd65bb0d4e9925ca24fd7214dc617c150544e423f450c99ce51ac8005d33acd74f1bed3b17b7266a4a3bb86da7eba80b101e15cb79de9a207852cf91249ef480619ff2af8cabca83125d1faa94cbb0a03a906f683b3f47a97c871fd513e510a7a25f283b196075778496152a91c2bf9da76ebe089f4654877f2d586ae7149c406e663eadeb2b5c7e82429b9e8cb4834c83464f079995332e4b3c8f5a72bb4b8c6f74b0d45dc6c1f79952c0b7420df525e37c15377b5f0984319c3993921e5ccd97e097592064530d33de3afad5733cbe7703c5296263f77342efbf5a04755b0b3c997c4328463e84caa2de3ffdcd297baaaacd7ae646e44b5c0f16044df38fabd296a47b3a838a913982fb2e370c078edb042c84db34ce36b46ccb76460a690cc86c302457dd1cde197ec8075e82b393d542075134e2a17ee70a5e187075d03ae3c853cff60729ba4000000054de1f6965bdabc676c5a4dc7c35f97f82cb0e31c68d04f1dad96314ff09e6b3de96aeee300d1f68bf1bca9fc58e4032336cd819aaf578744e50d1357a0e4286704d341aa0a337b19fe4bc43c2e79964d4f351089f2e0e41c7c43ae0d49e7f404b0f75be80ea3af098c9752420a8ac0ea2bbb1f4eeba05238aef0d8ce63f0c6e5e4041d95398a6f7f3e0ee97cc1591849d4ed236338b147abde9f51ef9fd4e1c1 + +pk = 000000020000000600000003d08fabd4a2091ff0a8cb4ed834e7453432a58885cd9ba0431235466bff9651c6c92124404d45fa53cf161c28f1ad5a8e + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp new file mode 100644 index 0000000000..7e8dc7bd21 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H5_W8_H5_W8 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e0a + +sm = 000000010000000500000004d32b56671d7eb98833c49b433c272586bc4a1c8a8970528ffa04b966f9426eb9965a25bfd37f196b9073f3d4a232feb69128ec45146f86292f9dff9610a7bf95a64c7f60f6261a62043f86c70324b7707f5b4a8a6e19c114c7be866d488778a0e05fd5c6509a6e61d559cf1a77a970de927d60c70d3de31a7fa0100994e162a2582e8ff1b10cd99d4e8e413ef469559f7d7ed12c838342f9b9c96b83a4943d1681d84b15357ff48ca579f19f5e71f18466f2bbef4bf660c2518eb20de2f66e3b14784269d7d876f5d35d3fbfc7039a462c716bb9f6891a7f41ad133e9e1f6d9560b960e7777c52f060492f2d7c660e1471e07e72655562035abc9a701b473ecbc3943c6b9c4f2405a3cb8bf8a691ca51d3f6ad2f428bab6f3a30f55dd9625563f0a75ee390e385e3ae0b906961ecf41ae073a0590c2eb6204f44831c26dd768c35b167b28ce8dc988a3748255230cef99ebf14e730632f27414489808afab1d1e783ed04516de012498682212b07810579b250365941bcc98142da13609e9768aaf65de7620dabec29eb82a17fde35af15ad238c73f81bdb8dec2fc0e7f932701099762b37f43c4a3c20010a3d72e2f606be108d310e639f09ce7286800d9ef8a1a40281cc5a7ea98d2adc7c7400c2fe5a101552df4e3cccfd0cbf2ddf5dc6779cbbc68fee0c3efe4ec22b83a2caa3e48e0809a0a750b73ccdcf3c79e6580c154f8a58f7f24335eec5c5eb5e0cf01dcf4439424095fceb077f66ded5bec73b27c5b9f64a2a9af2f07c05e99e5cf80f00252e39db32f6c19674f190c9fbc506d826857713afd2ca6bb85cd8c107347552f30575a5417816ab4db3f603f2df56fbc413e7d0acd8bdd81352b2471fc1bc4f1ef296fea1220403466b1afe78b94f7ecf7cc62fb92be14f18c2192384ebceaf8801afdf947f698ce9c6ceb696ed70e9e87b0144417e8d7baf25eb5f70f09f016fc925b4db048ab8d8cb2a661ce3b57ada67571f5dd546fc22cb1f97e0ebd1a65926b1234fd04f171cf469c76b884cf3115cce6f792cc84e36da58960c5f1d760f32c12faef477e94c92eb75625b6a371efc72d60ca5e908b3a7dd69fef0249150e3eebdfed39cbdc3ce9704882a2072c75e13527b7a581a556168783dc1e97545e31865ddc46b3c957835da252bb7328d3ee2062445dfb85ef8c35f8e1f3371af34023cef626e0af1e0bc017351aae2ab8f5c612ead0b729a1d059d02bfe18efa971b7300e882360a93b025ff97e9e0eec0f3f3f13039a17f88b0cf808f488431606cb13f9241f40f44e537d302c64a4f1f4ab949b9feefadcb71ab50ef27d6d6ca8510f150c85fb525bf25703df7209b6066f09c37280d59128d2f0f637c7d7d7fad4ed1c1ea04e628d221e3d8db77b7c878c9411cafc5071a34a00f4cf07738912753dfce48f07576f0d4f94f42c6d76f7ce973e9367095ba7e9a3649b7f461d9f9ac1332a4d1044c96aefee67676401b64457c54d65fef6500c59cdfb69af7b6dddfcb0f086278dd8ad0686078dfb0f3f79cd893d314168648499898fbc0ced5f95b74e8ff14d735cdea968bee7400000005d8b8112f9200a5e50c4a262165bd342cd800b8496810bc716277435ac376728d129ac6eda839a6f357b5a04387c5ce97382a78f2a4372917eefcbf93f63bb59112f5dbe400bd49e4501e859f885bf0736e90a509b30a26bfac8c17b5991c157eb5971115aa39efd8d564a6b90282c3168af2d30ef89d51bf14654510a12b8a144cca1848cf7da59cc2b3d9d0692dd2a20ba3863480e25b1b85ee860c62bf51360000000500000004d2f14ff6346af964569f7d6cb880a1b66c5004917da6eafe4d9ef6c6407b3db0e5485b122d9ebe15cda93cfec582d7ab0000000a000000040703c491e7558b35011ece3592eaa5da4d918786771233e8353bc4f62323185c95cae05b899e35dffd717054706209988ebfdf6e37960bb5c38d7657e8bffeef9bc042da4b4525650485c66d0ce19b317587c6ba4bffcc428e25d08931e72dfb6a120c5612344258b85efdb7db1db9e1865a73caf96557eb39ed3e3f426933ac9eeddb03a1d2374af7bf77185577456237f9de2d60113c23f846df26fa942008a698994c0827d90e86d43e0df7f4bfcdb09b86a373b98288b7094ad81a0185ac100e4f2c5fc38c003c1ab6fea479eb2f5ebe48f584d7159b8ada03586e65ad9c969f6aecbfe44cf356888a7b15a3ff074f771760b26f9c04884ee1faa329fbf4e61af23aee7fa5d4d9a5dfcf43c4c26ce8aea2ce8a2990d7ba7b57108b47dabfbeadb2b25b3cacc1ac0cef346cbb90fb044beee4fac2603a442bdf7e507243b7319c9944b1586e899d431c7f91bcccc8690dbf59b28386b2315f3d36ef2eaa3cf30b2b51f48b71b003dfb08249484201043f65f5a3ef6bbd61ddfee81aca9ce60081262a00000480dcbc9a3da6fbef5c1c0a55e48a0e729f9184fcb1407c31529db268f6fe50032a363c9801306837fafabdf957fd97eafc80dbd165e435d0e2dfd836a28b354023924b6fb7e48bc0b3ed95eea64c2d402f4d734c8dc26f3ac591825daef01eae3c38e3328d00a77dc657034f287ccb0f0e1c9a7cbdc828f627205e4737b84b58376551d44c12c3c215c812a0970789c83de51d6ad787271963327f0a5fbb6b5907dec02c9a90934af5a1c63b72c82653605d1dcce51596b3c2b45696689f2eb382007497557692caac4d57b5de9f5569bc2ad0137fd47fb47e664fcb6db4971f5b3e07aceda9ac130e9f38182de994cff192ec0e82fd6d4cb7f3fe00812589b7a7ce515440456433016b84a59bec6619a1c6c0b37dd1450ed4f2d8b584410ceda8025f5d2d8dd0d2176fc1cf2cc06fa8c82bed4d944e71339ece780fd025bd41ec34ebff9d4270a3224e019fcb444474d482fd2dbe75efb20389cc10cd600abb54c47ede93e08c114edb04117d714dc1d525e11bed8756192f929d15462b939ff3f52f2252da2ed64d8fae88818b1efa2c7b08c8794fb1b214aa233db3162833141ea4383f1a6f120be1db82ce3630b3429114463157a64e91234d475e2f79cbf05e4db6a9407d72c6bff7d1198b5c4d6aad2831db61274993715a0182c7dc8089e32c8531deed4f7431c07c02195eba2ef91efb5613c37af7ae0c066babc69369700e1dd26eddc0d216c781d56e4ce47e3303fa73007ff7b949ef23be2aa4dbf25206fe45c20dd888395b2526391a724996a44156beac808212858792bf8e74cba49dee5e8812e019da87454bff9e847ed83db07af313743082f880a278f682c2bd0ad6887cb59f652e155987d61bbf6a88d36ee93b6072e6656d9ccbaae3d655852e38deb3a2dcf8058dc9fb6f2ab3d3b3539eb77b248a661091d05eb6e2f297774fe6053598457cc61908318de4b826f0fc86d4bb117d33e865aa805009cc2918d9c2f840c4da43a703ad9f5b5806163d7161696b5a0adc00000005d5c0d1bebb06048ed6fe2ef2c6cef305b3ed633941ebc8b3bec9738754cddd60e1920ada52f43d055b5031cee6192520d6a5115514851ce7fd448d4a39fae2ab2335b525f484e9b40d6a4a969394843bdcf6d14c48e8015e08ab92662c05c6e9f90b65a7a6201689999f32bfd368e5e3ec9cb70ac7b8399003f175c40885081a09ab3034911fe125631051df0408b3946b0bde790911e8978ba07dd56c73e7ee + +pk = 00000002000000050000000461a5d57d37f5e46bfb7520806b07a1b850650e3b31fe4a773ea29a07f09cf2ea30e579f0df58ef8e298da0434cb2b878 + diff --git a/tests/example_sig_stfl.c b/tests/example_sig_stfl.c new file mode 100644 index 0000000000..b332d8479b --- /dev/null +++ b/tests/example_sig_stfl.c @@ -0,0 +1,133 @@ +/* + * example_sig_stfl.c + * + * Minimal example of using a post-quantum stateful signature implemented in liboqs. + * + * SPDX-License-Identifier: MIT + */ + +#include +#include +#include +#include + +#include + +#define MESSAGE_LEN 50 + +static OQS_STATUS do_nothing_save(uint8_t *key_buf, size_t buf_len, void *context) { + (void)(context); + (void)(buf_len); + return key_buf != NULL ? OQS_SUCCESS : OQS_ERROR; +} + +/* This function gives an example of the signing operations, + * allocating variables dynamically on the heap and calling the + * OQS_SIG_STFL and OQS_SIG_STFL_SECRET_KEY objects. + * + * This does not require the use of compile-time macros to check if the + * algorithm in question was enabled at compile-time; instead, the caller + * must check that the OQS_SIG object returned is not NULL. + */ +static OQS_STATUS stfl_example(char *method_name) { + + OQS_SIG_STFL *sig = NULL; + uint8_t *public_key = NULL; + OQS_SIG_STFL_SECRET_KEY *secret_key = NULL; + uint8_t *message = NULL; + uint8_t *signature = NULL; + size_t message_len = MESSAGE_LEN; + size_t signature_len; + char *sk_fname = NULL; + OQS_STATUS rc = OQS_ERROR; + + /* + * Steps + * 1. create stateful signature object + * 2. create secret key object + * 3. set key storage callback function + * set mutex if necessary + * 4. Generate key-pair + * 5. Signature generation + * 6. verify signature + */ + sig = OQS_SIG_STFL_new(method_name); + if (sig == NULL) { + printf("[Stateful sig] %s new failed.\n", method_name); + return OQS_ERROR; + } + + secret_key = OQS_SIG_STFL_SECRET_KEY_new(method_name); + if (secret_key == NULL) { + printf("[Stateful secret key] %s new failed.\n", method_name); + goto err; + } + + /* + * Allocate storage for public key, secret key filename, message and signature + */ + public_key = malloc(sig->length_public_key); + sk_fname = malloc(strlen(method_name) + strlen(".sk")); + message = malloc(message_len); + signature = malloc(sig->length_signature); + if ((public_key == NULL) || (message == NULL) || (signature == NULL) || (sk_fname == NULL)) { + fprintf(stderr, "ERROR: malloc failed!\n"); + goto err; + } + + strcpy(sk_fname, method_name); + strcat(sk_fname, ".sk"); + /* + * set callback to securely store the secret key + * secret keys are one time use only. So after a signature gen + * the secret key most be advanced to the next + */ + OQS_SIG_STFL_SECRET_KEY_SET_store_cb(secret_key, do_nothing_save, (void *)sk_fname); + + /* + * Generate key pair + */ + rc = OQS_SIG_STFL_keypair(sig, public_key, secret_key); + if (rc != OQS_SUCCESS) { + printf("[Stateful key pair generation] %s new failed.\n", method_name); + goto err; + } + + // let's create a random test message to sign + OQS_randombytes(message, message_len); + + rc = OQS_SIG_STFL_sign(sig, signature, &signature_len, message, message_len, secret_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_sign failed %s!\n", method_name); + goto err; + } + rc = OQS_SIG_STFL_verify(sig, message, message_len, signature, signature_len, public_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: OQS_SIG_STFL_verify failed %s!\n", method_name); + goto err; + } + + printf("[Stateful signature] %s operations completed.\n", method_name); +err: +//cleanup + OQS_MEM_insecure_free(public_key); + OQS_MEM_insecure_free(sk_fname); + OQS_MEM_insecure_free(message); + OQS_MEM_insecure_free(signature); + OQS_SIG_STFL_free(sig); + OQS_SIG_STFL_SECRET_KEY_free(secret_key); + + return rc; +} + +int main(void) { + OQS_init(); + if (stfl_example("XMSS-SHA2_10_256") == OQS_SUCCESS && stfl_example("LMS_SHA256_H10_W4") == OQS_SUCCESS) { + OQS_destroy(); + return EXIT_SUCCESS; + } else { + OQS_destroy(); + return EXIT_FAILURE; + } +} + diff --git a/tests/helpers.py b/tests/helpers.py index 781df5e45a..b911f5d9bd 100644 --- a/tests/helpers.py +++ b/tests/helpers.py @@ -114,8 +114,8 @@ def available_sig_stfls_by_name(): with open(os.path.join('src', 'sig_stfl', 'sig_stfl.h')) as fh: for line in fh: if line.startswith("#define OQS_SIG_STFL_alg_"): - sig_stfl_name = line.split(' ')[2] - sig_stfl_name = sig_stfl_name[1:-2] + sig_stfl_name = line.split(' ')[2].strip() + sig_stfl_name = sig_stfl_name[1:-1] available_names.append(sig_stfl_name) return available_names @@ -126,8 +126,8 @@ def is_sig_stfl_enabled_by_name(name): if line.startswith("#define OQS_SIG_STFL_alg_"): sig_stfl_symbol = line.split(' ')[1] sig_stfl_symbol = sig_stfl_symbol[len("OQS_SIG_STFL_alg_"):] - sig_stfl_name = line.split(' ')[2] - sig_stfl_name = sig_stfl_name[1:-2] + sig_stfl_name = line.split(' ')[2].strip() + sig_stfl_name = sig_stfl_name[1:-1] if sig_stfl_name == name: symbol = sig_stfl_symbol break @@ -202,8 +202,10 @@ def get_katfile(t: str, sig_stfl_name: str) -> str: algo_dir = '' if "XMSS" in sig_stfl_name: algo_dir = 'xmss' - if not algo_dir: - return '' + if "LMS" in sig_stfl_name: + algo_dir = 'lms' + if algo_dir == '': + return '' # Replace the "/" to "-" in XMSSMT parameters clean_sig_stfl_name = sig_stfl_name.replace("/", "-", 1) kat_filename = f"{clean_sig_stfl_name}.rsp" diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 4607977065..457a5c3778 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -71,11 +71,29 @@ int FindMarker(FILE *infile, const char *marker) { // // ALLOW TO READ HEXADECIMAL ENTRY (KEYS, DATA, TEXT, etc.) // -int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, const char *str) { +size_t ReadHex(FILE *infile, unsigned char *a, unsigned long Length, const char *str) { int ch, started; unsigned long i; unsigned char ich; + /* + * Caller is just trying to get the length target data + */ + if ((Length == 0) && (a == NULL)) { + i = 0; + if (FindMarker(infile, str)) { + while ((ch = fgetc(infile)) != EOF) { + if (!isxdigit(ch)) { + if (ch == '\n') { + break; + } + } + i += 1; + } + } + return (i / 2); + } + if (Length == 0) { a[0] = 0x00; return 1; @@ -118,6 +136,18 @@ int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, const char *st return 1; } +void fprint_l_str(FILE *fp, const char *S, const uint8_t *A, size_t L) { + size_t i; + fprintf(fp, "%s", S); + for (i = 0; i < L; i++) { + fprintf(fp, "%02x", A[i]); + } + if (L == 0) { + fprintf(fp, "00"); + } + fprintf(fp, "\n"); +} + OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { uint8_t seed[48]; @@ -283,7 +313,112 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { return ret; } +/* + * LMS Test Vector + */ +static OQS_STATUS test_lms_kat(const char *method_name, const char *katfile) { + OQS_STATUS rc = OQS_ERROR; + OQS_SIG_STFL *sig = NULL; + uint8_t *public_key = NULL; + uint8_t *msg = NULL; + size_t msg_len = 0; + uint8_t *sm = NULL; + FILE *fp_rsp = NULL; + FILE *fh = NULL; + + if ((fp_rsp = fopen(katfile, "r")) == NULL) { + fprintf(stderr, "Couldn't open <%s> for read\n", katfile); + goto err; + } + + //Allocate a OQS stateful signature struct + sig = OQS_SIG_STFL_new(method_name); + if (sig == NULL) { + fprintf(stderr, "ERROR: Failed to create signature object for %s\n", method_name); + goto err; + } + + /* + * Get the message length + * Zero length means no KAT is currently available, so skip this method + * and return success + */ + msg_len = ReadHex(fp_rsp, 0, 0, "msg = "); + if (!(msg_len > 0)) { + fprintf(stderr, "No msg present\n"); + goto err; + } + + fclose(fp_rsp); + if ((fp_rsp = fopen(katfile, "r")) == NULL) { + fprintf(stderr, "Couldn't open <%s> for read\n", katfile); + goto err; + } + + public_key = malloc(sig->length_public_key); + sm = malloc(sig->length_signature); + msg = malloc((unsigned long)msg_len); + + if ((!msg || !sm || !public_key)) { + fprintf(stderr, "ERROR: unable to allocate memory.\n"); + goto err; + } + + /* + * Read signature and public key, msg and signature data from KAT file + */ + if (!ReadHex(fp_rsp, public_key, sig->length_public_key, "pk = ")) { + fprintf(stderr, "ERROR: unable to read 'pk' from <%s>\n", katfile); + goto err; + } + fclose(fp_rsp); + if ((fp_rsp = fopen(katfile, "r")) == NULL) { + fprintf(stderr, "Couldn't open <%s> for read\n", katfile); + goto err; + } + + if (!ReadHex(fp_rsp, msg, msg_len, "msg = ")) { + fprintf(stderr, "ERROR: unable to read 'msg' from <%s>\n", katfile); + goto err; + } + fclose(fp_rsp); + if ((fp_rsp = fopen(katfile, "r")) == NULL) { + fprintf(stderr, "Couldn't open <%s> for read\n", katfile); + goto err; + } + + if (!ReadHex(fp_rsp, sm, sig->length_signature, "sm = ")) { + fprintf(stderr, "ERROR: unable to read 'sm' from <%s>\n", katfile); + goto err; + } + + //Verify KAT + rc = OQS_SIG_STFL_verify(sig, msg, msg_len, sm, sig->length_signature, public_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "ERROR: Verify test vector failed: %s\n", method_name); + } else { + fh = stdout; + fprintf(fh, "# %s\n\n", sig->method_name); + fprint_l_str(fh, "msg = ", msg, msg_len); + fprintf(fh, "\n"); + fprint_l_str(fh, "sm = ", sm, sig->length_signature); + fprintf(fh, "\n"); + fprint_l_str(fh, "pk = ", public_key, sig->length_public_key); + fprintf(fh, "\n"); + } +err: + OQS_SIG_STFL_free(sig); + OQS_MEM_insecure_free(sm); + OQS_MEM_insecure_free(public_key); + OQS_MEM_insecure_free(msg); + if (fp_rsp) { + fclose(fp_rsp); + } + return rc; +} + int main(int argc, char **argv) { + OQS_STATUS rc; OQS_init(); if (argc != 3) { @@ -304,7 +439,11 @@ int main(int argc, char **argv) { char *alg_name = argv[1]; char *katfile = argv[2]; - OQS_STATUS rc = sig_stfl_kat(alg_name, katfile); + if (strncmp(alg_name, "LMS", 3) != 0) { + rc = sig_stfl_kat(alg_name, katfile); + } else { + rc = test_lms_kat(alg_name, katfile); + } if (rc != OQS_SUCCESS) { OQS_destroy(); return EXIT_FAILURE; diff --git a/tests/test_hash.c b/tests/test_hash.c index 3fea2f00ad..788f41ffb2 100644 --- a/tests/test_hash.c +++ b/tests/test_hash.c @@ -62,11 +62,12 @@ static int do_sha256(void) { OQS_SHA2_sha256_inc_init(&state); // clone state - OQS_SHA2_sha256_ctx state2, state3, state4, state5; + OQS_SHA2_sha256_ctx state2, state3, state4, state5, state6; OQS_SHA2_sha256_inc_ctx_clone(&state2, &state); OQS_SHA2_sha256_inc_ctx_clone(&state3, &state); OQS_SHA2_sha256_inc_ctx_clone(&state4, &state); OQS_SHA2_sha256_inc_ctx_clone(&state5, &state); + OQS_SHA2_sha256_inc_ctx_clone(&state6, &state); // hash with first state if (msg_len > 64) { @@ -94,7 +95,7 @@ static int do_sha256(void) { return -3; } - // hash with increment API less than block size + // hash with increment 1 byte at a time size_t i = 0; for (i = 0; i < msg_len; i++) { OQS_SHA2_sha256_inc(&state3, &msg[i], 1); @@ -106,6 +107,15 @@ static int do_sha256(void) { return -4; } + // hash increment with the entire msg len + OQS_SHA2_sha256_inc(&state6, msg, msg_len); + OQS_SHA2_sha256_inc_finalize(output_inc, &state6, NULL, 0); + if (memcmp(output, output_inc, 32) != 0) { + fprintf(stderr, "ERROR: Incremental API with the entire msg.\n"); + free(msg); + return -3; + } + // hash with combination of block-size increments and non block-size increments [64 bytes] + [n < 64 bytes] if (msg_len > 64) { OQS_SHA2_sha256_inc_blocks(&state4, msg, 1); diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index dd75b8a916..55ba104d56 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -1001,6 +1001,7 @@ int main(int argc, char **argv) { const char *alg_name = argv[1]; const char *katfile = argv[2]; + if (!OQS_SIG_STFL_alg_is_enabled(alg_name)) { printf("Stateful signature algorithm %s not enabled!\n", alg_name); OQS_destroy(); From 982b44061b575ad573f81bb668325ef4dedb8014 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Tue, 19 Dec 2023 10:46:19 -0500 Subject: [PATCH 23/68] Fix Build Errors (#1635) * Fix build err when built with no thread * Enable KAT * Add Generated test * Fix typo * update formatting * Fix typo * Fix build issues * Fix undefined error * Fixed SA issue * Fixed warnings * Skip variant that exceeds timeout * Fix style format * Fix various build issues --- .CMake/alg_support.cmake | 20 +++ src/common/sha2/sha2_armv8.c | 32 ++--- src/oqsconfig.h.cmake | 13 ++ src/sig_stfl/lms/external/endian.c | 2 +- src/sig_stfl/lms/external/hss_alloc.c | 10 +- src/sig_stfl/lms/external/hss_aux.c | 2 +- src/sig_stfl/lms/external/hss_compute.c | 2 +- src/sig_stfl/lms/external/hss_generate.c | 2 +- src/sig_stfl/lms/external/hss_keygen.c | 2 +- src/sig_stfl/lms/external/hss_sign.c | 6 +- src/sig_stfl/lms/external/hss_sign_inc.c | 2 +- src/sig_stfl/lms/external/hss_verify.c | 16 +-- src/sig_stfl/lms/external/hss_verify_inc.c | 16 +-- src/sig_stfl/lms/external/lm_common.c | 2 +- src/sig_stfl/lms/external/lm_ots_verify.c | 2 +- src/sig_stfl/lms/external/lm_verify.c | 8 +- src/sig_stfl/lms/sig_stfl_lms.h | 136 +++++++++--------- tests/KATs/sig_stfl/kats.json | 16 +++ tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp | 8 ++ tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp | 8 ++ tests/example_sig_stfl.c | 2 +- tests/test_sig_stfl.c | 121 ++++++++++------ 36 files changed, 374 insertions(+), 166 deletions(-) create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp create mode 100644 tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index 27ce29c1da..119ee52f3f 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -529,6 +529,26 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 "" ON "OQS_ENA option(OQS_ENABLE_SIG_STFL_LMS "Enable LMS algorithm family" ON) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w2 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w4 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w1 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h15_w1 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h15_w2 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h15_w4 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w1 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w2 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w4 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h25_w1 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h25_w2 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h25_w4 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h25_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) diff --git a/src/common/sha2/sha2_armv8.c b/src/common/sha2/sha2_armv8.c index 71d2cebb59..9f5a96bd97 100644 --- a/src/common/sha2/sha2_armv8.c +++ b/src/common/sha2/sha2_armv8.c @@ -290,27 +290,27 @@ void oqs_sha2_sha256_inc_armv8(sha256ctx *state, const uint8_t *in, size_t len) incr = len; } - for (size_t i = 0; i < incr; ++i, state->data_len++, in_index++)) { - state->data[state->data_len] = in[in_index++)]; + for (size_t i = 0; i < incr; ++i, state->data_len++, in_index++) { + state->data[state->data_len] = in[in_index++]; } if (state->data_len < 64) { - break; - } + break; + } - /* - * Process a complete block now - */ - bytes = load_bigendian_64(state->ctx + 32) + 64; - crypto_hashblocks_sha256_armv8(state->ctx, state->data, 64); - store_bigendian_64(state->ctx + 32, bytes); + /* + * Process a complete block now + */ + bytes = load_bigendian_64(state->ctx + 32) + 64; + crypto_hashblocks_sha256_armv8(state->ctx, state->data, 64); + store_bigendian_64(state->ctx + 32, bytes); - /* - * update the remaining input - */ - len -= incr; - state->data_len = 0; -} + /* + * update the remaining input + */ + len -= incr; + state->data_len = 0; + } } void oqs_sha2_sha224_inc_blocks_armv8(sha224ctx *state, const uint8_t *in, size_t inblocks) { diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index c2de65c545..9fce48b769 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -222,5 +222,18 @@ #cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 1 #cmakedefine OQS_ENABLE_SIG_STFL_LMS 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w2 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w4 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w1 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w1 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w2 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w4 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8 1 +#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h20_w1 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 1 diff --git a/src/sig_stfl/lms/external/endian.c b/src/sig_stfl/lms/external/endian.c index 709dc7bf98..0c3c55b0fe 100644 --- a/src/sig_stfl/lms/external/endian.c +++ b/src/sig_stfl/lms/external/endian.c @@ -4,7 +4,7 @@ void put_bigendian( void *target, unsigned long long value, size_t bytes ) { unsigned char *b = target; int i; - for (i = bytes-1; i >= 0; i--) { + for (i = (int)(bytes-1); i >= 0; i--) { b[i] = value & 0xff; value >>= 8; } diff --git a/src/sig_stfl/lms/external/hss_alloc.c b/src/sig_stfl/lms/external/hss_alloc.c index 8f7cf6054b..3907d8764b 100644 --- a/src/sig_stfl/lms/external/hss_alloc.c +++ b/src/sig_stfl/lms/external/hss_alloc.c @@ -167,7 +167,7 @@ struct hss_working_key *allocate_working_key( if (memory_target > LONG_MAX) { mem_target = LONG_MAX; } else { - mem_target = memory_target; + mem_target = (unsigned long)memory_target; } #if 0 signed long initial_mem_target = mem_target; /* DEBUG HACK */ @@ -178,7 +178,7 @@ signed long initial_mem_target = mem_target; /* DEBUG HACK */ info->error_code = hss_error_out_of_memory; return NULL; } - mem_target -= sizeof(*w) + MALLOC_OVERHEAD; + mem_target -= (unsigned long)sizeof(*w) + MALLOC_OVERHEAD; unsigned i; w->levels = levels; w->status = hss_error_key_uninitialized; /* Not usable until we see a */ @@ -220,13 +220,13 @@ signed long initial_mem_target = mem_target; /* DEBUG HACK */ info->error_code = hss_error_out_of_memory; return 0; } - mem_target -= w->signed_pk_len[i] + MALLOC_OVERHEAD; + mem_target -= (unsigned long)w->signed_pk_len[i] + MALLOC_OVERHEAD; } w->signature_len = signature_len; /* Also account for the overhead for the stack allocation (the memory */ /* used by the stack will be accounted as a part of the tree level size */ - mem_target -= MALLOC_OVERHEAD; + mem_target -= (unsigned long)MALLOC_OVERHEAD; /* * Plot out how many subtree sizes we have at each level. We start by @@ -305,7 +305,7 @@ signed long initial_mem_target = mem_target; /* DEBUG HACK */ level_height[i], hash_size[i], &subtree_levels[i], &stack_used ); - mem_target -= mem; + mem_target -= (unsigned long)mem; stack_usage += stack_used; } diff --git a/src/sig_stfl/lms/external/hss_aux.c b/src/sig_stfl/lms/external/hss_aux.c index 5817b76c81..0d8777386f 100644 --- a/src/sig_stfl/lms/external/hss_aux.c +++ b/src/sig_stfl/lms/external/hss_aux.c @@ -133,7 +133,7 @@ struct expanded_aux_data *hss_expand_aux_data( const unsigned char *aux_data, if (!aux_data || aux_data[AUX_DATA_MARKER] == NO_AUX_DATA) return 0; const unsigned char *orig_aux_data = aux_data; - unsigned long aux_level = get_bigendian( aux_data, 4 ); + unsigned long aux_level = (unsigned long)get_bigendian( aux_data, 4 ); aux_data += 4; aux_level &= 0x7ffffffffL; /* Turn off the 'used' marker */ diff --git a/src/sig_stfl/lms/external/hss_compute.c b/src/sig_stfl/lms/external/hss_compute.c index 353ec939fb..752a7e2868 100644 --- a/src/sig_stfl/lms/external/hss_compute.c +++ b/src/sig_stfl/lms/external/hss_compute.c @@ -51,7 +51,7 @@ static enum hss_error_code hss_compute_internal_node( unsigned char *dest, merkle_index_t q = r - tree_size; merkle_index_t i; - unsigned ots_len = lm_ots_get_public_key_len(lm_ots_type); + unsigned ots_len = (unsigned)lm_ots_get_public_key_len(lm_ots_type); unsigned char pub_key[ LEAF_MAX_LEN ]; memcpy( pub_key + LEAF_I, I, I_LEN ); SET_D( pub_key + LEAF_D, D_LEAF ); diff --git a/src/sig_stfl/lms/external/hss_generate.c b/src/sig_stfl/lms/external/hss_generate.c index b604ab3593..5d6880c267 100644 --- a/src/sig_stfl/lms/external/hss_generate.c +++ b/src/sig_stfl/lms/external/hss_generate.c @@ -695,7 +695,7 @@ bool hss_generate_working_key( if (ratio > 1000) { core_target = 1; } else { - core_target = core_target / ratio; + core_target = (unsigned)(core_target / ratio); if (core_target == 0) core_target = 1; } prev_cost = p_order->cost; diff --git a/src/sig_stfl/lms/external/hss_keygen.c b/src/sig_stfl/lms/external/hss_keygen.c index 743604f170..7a364b3f04 100644 --- a/src/sig_stfl/lms/external/hss_keygen.c +++ b/src/sig_stfl/lms/external/hss_keygen.c @@ -101,7 +101,7 @@ bool hss_generate_private_key( return false; } - unsigned len_ots_pub = lm_ots_get_public_key_len(lm_ots_type[0]); + unsigned len_ots_pub = (unsigned)lm_ots_get_public_key_len(lm_ots_type[0]); if (len_ots_pub == 0) { info->error_code = hss_error_bad_param_set; return false; diff --git a/src/sig_stfl/lms/external/hss_sign.c b/src/sig_stfl/lms/external/hss_sign.c index 359e59df7b..3ce7159fbf 100644 --- a/src/sig_stfl/lms/external/hss_sign.c +++ b/src/sig_stfl/lms/external/hss_sign.c @@ -41,7 +41,7 @@ static enum subtree_build_status subtree_add_next_node( /* Compute the leaf node */ merkle_index_t i; - unsigned ots_len = lm_ots_get_public_key_len(tree->lm_ots_type); + unsigned ots_len = (unsigned int)lm_ots_get_public_key_len(tree->lm_ots_type); unsigned char pub_key[ LEAF_MAX_LEN ]; const unsigned char *I = (next_tree ? tree->I_next : tree->I); memcpy( pub_key + LEAF_I, I, I_LEN ); @@ -253,7 +253,7 @@ bool hss_create_signed_public_key(unsigned char *signed_key, unsigned len_public_key = 8 + I_LEN + hash_size; /* Now, generate the signature */ - if (!generate_merkle_signature( signed_key, len_signature, + if (!(unsigned int)generate_merkle_signature( signed_key, len_signature, parent, w, public_key, len_public_key)) { return false; } @@ -303,7 +303,7 @@ static void do_gen_sig( const void *detail, struct thread_collection *col) { const unsigned char *message = d->message; size_t message_len = d->message_len; - if (!generate_merkle_signature(signature, signature_len, + if (!(unsigned int)generate_merkle_signature(signature, signature_len, w->tree[ levels-1 ], w, message, message_len)) { goto failed; } diff --git a/src/sig_stfl/lms/external/hss_sign_inc.c b/src/sig_stfl/lms/external/hss_sign_inc.c index e455b5cd2b..6890a4a621 100644 --- a/src/sig_stfl/lms/external/hss_sign_inc.c +++ b/src/sig_stfl/lms/external/hss_sign_inc.c @@ -159,7 +159,7 @@ bool hss_sign_finalize( int i; for (i=0; i working_key->tree[i]->max_index) { hss_zeroize( seed_buff, sizeof seed_buff ); return 0; diff --git a/src/sig_stfl/lms/external/hss_verify.c b/src/sig_stfl/lms/external/hss_verify.c index 089bdbd1ef..b7f0f8b489 100644 --- a/src/sig_stfl/lms/external/hss_verify.c +++ b/src/sig_stfl/lms/external/hss_verify.c @@ -68,17 +68,17 @@ bool hss_validate_signature( info->error_code = hss_error_bad_signature; return false; } - uint_fast32_t levels = get_bigendian( signature, 4 ) + 1; + uint_fast32_t levels = (uint_fast32_t)get_bigendian( signature, 4 ) + 1; /* +1 because what's in the signature is levels-1 */ signature += 4; signature_len -= 4; if (levels < MIN_HSS_LEVELS || levels > MAX_HSS_LEVELS || - levels != get_bigendian( public_key, 4 )) { + levels != (uint_fast32_t)get_bigendian( public_key, 4 )) { info->error_code = hss_error_bad_signature; return false; } /* Compare that to what the public key says */ - uint_fast32_t pub_levels = get_bigendian( public_key, 4 ); + uint_fast32_t pub_levels = (uint_fast32_t)get_bigendian( public_key, 4 ); if (levels != pub_levels) { /* Signature and public key don't agree */ info->error_code = hss_error_bad_signature; @@ -109,9 +109,9 @@ bool hss_validate_signature( */ /* Get the length of Signature A */ - param_set_t lm_type = get_bigendian( public_key, 4 ); - param_set_t lm_ots_type = get_bigendian( public_key+4, 4 ); - unsigned l_siglen = lm_get_signature_len(lm_type, lm_ots_type); + param_set_t lm_type = (param_set_t)get_bigendian( public_key, 4 ); + param_set_t lm_ots_type = (param_set_t)get_bigendian( public_key+4, 4 ); + unsigned l_siglen = (unsigned)lm_get_signature_len(lm_type, lm_ots_type); if (l_siglen == 0 || l_siglen > signature_len) { info->error_code = hss_error_bad_signature; goto failed; @@ -134,8 +134,8 @@ bool hss_validate_signature( * someone other than the valid signer modified it), then * Signature A will not validate, and so we'll catch that */ - lm_type = get_bigendian( signature, 4 ); - unsigned l_pubkeylen = lm_get_public_key_len(lm_type); + lm_type = (param_set_t)get_bigendian( signature, 4 ); + unsigned l_pubkeylen = (unsigned)lm_get_public_key_len(lm_type); if (l_pubkeylen == 0 || l_pubkeylen > signature_len) { info->error_code = hss_error_bad_signature; goto failed; diff --git a/src/sig_stfl/lms/external/hss_verify_inc.c b/src/sig_stfl/lms/external/hss_verify_inc.c index 451082f8de..bb8da66db1 100644 --- a/src/sig_stfl/lms/external/hss_verify_inc.c +++ b/src/sig_stfl/lms/external/hss_verify_inc.c @@ -44,15 +44,15 @@ bool hss_validate_signature_init( ctx->status = info->error_code = hss_error_bad_signature; return false; } - uint_fast32_t levels = get_bigendian( signature, 4 ) + 1; + uint_fast32_t levels = (uint_fast32_t)get_bigendian( signature, 4 ) + 1; /* +1 because what's in the signature is levels-1 */ signature += 4; signature_len -= 4; if (levels < MIN_HSS_LEVELS || levels > MAX_HSS_LEVELS || - levels != get_bigendian( public_key, 4 )) { + levels != (uint_fast32_t)get_bigendian( public_key, 4 )) { ctx->status = info->error_code = hss_error_bad_signature; return false; } - uint_fast32_t pub_levels = get_bigendian( public_key, 4 ); + uint_fast32_t pub_levels = (uint_fast32_t)get_bigendian( public_key, 4 ); if (levels != pub_levels) { /* Signature and public key don't agree */ ctx->status = info->error_code = hss_error_bad_signature; @@ -72,9 +72,9 @@ bool hss_validate_signature_init( /* as we go. Note that we don't validate the bottom level yet */ for (i=0; i signature_len) goto failed; const unsigned char *l_sig = signature; signature += l_siglen; signature_len -= l_siglen; @@ -82,7 +82,7 @@ bool hss_validate_signature_init( /* The next thing is the next level public key (which we need */ /* to validate) */ if (signature_len < 4) goto failed; - lm_type = get_bigendian( signature, 4 ); + lm_type = (param_set_t)get_bigendian( signature, 4 ); unsigned l_pubkeylen = lm_get_public_key_len(lm_type); if (l_pubkeylen == 0 || l_pubkeylen > signature_len) goto failed; const unsigned char *l_pubkey = signature; @@ -122,7 +122,7 @@ bool hss_validate_signature_init( memcpy( ctx->final_public_key, public_key, 8 + I_LEN + MAX_HASH ); /* Now, initialize the context */ - param_set_t ots_type = get_bigendian( public_key+4, 4 ); + param_set_t ots_type = (param_set_t)get_bigendian( public_key+4, 4 ); unsigned h, n; if (!lm_ots_look_up_parameter_set(ots_type, &h, &n, NULL, NULL, NULL)) { diff --git a/src/sig_stfl/lms/external/lm_common.c b/src/sig_stfl/lms/external/lm_common.c index e3eb56f0f0..5976f4b589 100644 --- a/src/sig_stfl/lms/external/lm_common.c +++ b/src/sig_stfl/lms/external/lm_common.c @@ -66,7 +66,7 @@ size_t lm_get_signature_len(param_set_t lm_type, if (!lm_look_up_parameter_set( lm_type, 0, &n, &height )) return 0; - int ots_sig_len = lm_ots_get_signature_len(lm_ots_type); + int ots_sig_len = (int)lm_ots_get_signature_len(lm_ots_type); if (ots_sig_len == 0) return 0; diff --git a/src/sig_stfl/lms/external/lm_ots_verify.c b/src/sig_stfl/lms/external/lm_ots_verify.c index 91576474b5..478f5ffe8d 100644 --- a/src/sig_stfl/lms/external/lm_ots_verify.c +++ b/src/sig_stfl/lms/external/lm_ots_verify.c @@ -38,7 +38,7 @@ bool lm_ots_validate_signature_compute( if (signature_len < 4) return false; /* Ha, ha, very funny... */ /* We don't trust the parameter set that's in the signature; verify it */ - param_set_t parameter_set = get_bigendian( signature, 4 ); + param_set_t parameter_set = (param_set_t)get_bigendian( signature, 4 ); if (parameter_set != expected_parameter_set) { return false; } diff --git a/src/sig_stfl/lms/external/lm_verify.c b/src/sig_stfl/lms/external/lm_verify.c index 46b3627885..3ec4cb6599 100644 --- a/src/sig_stfl/lms/external/lm_verify.c +++ b/src/sig_stfl/lms/external/lm_verify.c @@ -36,8 +36,8 @@ bool lm_validate_signature( const unsigned char *signature, size_t signature_len) { union hash_context ctx; - param_set_t lm_type = get_bigendian( public_key + LM_PUB_PARM_SET, 4 ); - param_set_t ots_type = get_bigendian( public_key + LM_PUB_OTS_PARM_SET, 4 ); + param_set_t lm_type = (param_set_t)get_bigendian( public_key + LM_PUB_PARM_SET, 4 ); + param_set_t ots_type = (param_set_t)get_bigendian( public_key + LM_PUB_OTS_PARM_SET, 4 ); unsigned h, n, height; if (!lm_look_up_parameter_set(lm_type, &h, &n, &height)) return false; @@ -47,7 +47,7 @@ bool lm_validate_signature( const unsigned char *I = public_key + LM_PUB_I; if (signature_len < 8) return false; - merkle_index_t count = get_bigendian( signature, 4 ); + merkle_index_t count = (param_set_t)get_bigendian( signature, 4 ); signature += 4; signature_len -= 4; /* 4 bytes, rather then 8 */ /* the OTS type is expected to be a part of the OTS signature, */ /* which lm_ots_validate_signature_compute will expect */ @@ -67,7 +67,7 @@ bool lm_validate_signature( /* Get the parameter set declared in the sigature; make sure it matches */ /* what we expect */ if (signature_len < 4) return false; - param_set_t parameter_set = get_bigendian( signature, 4 ); + param_set_t parameter_set = (param_set_t)get_bigendian( signature, 4 ); if (parameter_set != lm_type) return false; signature += 4; signature_len -= 4; diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index 8380656eb0..b583782e64 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -94,29 +94,29 @@ #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_signature 8688 #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk 64 -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); #define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_signature 4464 #define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_sk 64 -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); #define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_signature 2352 #define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_sk 64 -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(void); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); #define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_signature 1296 #define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_sk 64 -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(void); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); //H10 @@ -128,29 +128,29 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key #define OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W1_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W1_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_signature 4624 #define OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_signature 2512 #define OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_signature 1456 #define OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(void); //H15 // H15 W1 60 9008 64 @@ -161,29 +161,29 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W1_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W1_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_signature 4784 #define OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W2_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W2_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_signature 2672 #define OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W4_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W4_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_signature 1616 #define OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(void); //H20 // H20 W1 60 9168 64 @@ -194,29 +194,29 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W1_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W1_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_signature 4944 #define OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W2_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W2_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_signature 2832 #define OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W4_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W4_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_signature 1776 #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(void); //H25 // H25 W1 60 9328 64 @@ -227,32 +227,32 @@ OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W1_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W1_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_signature 5104 #define OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W2_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W2_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_signature 2992 #define OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W4_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W4_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(void); #define OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_signature 1936 #define OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_sk 64 -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *totaln, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *totaln, const OQS_SIG_STFL_SECRET_KEY *secret_key); void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); @@ -280,56 +280,56 @@ void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_length_signature 3604 OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_H5_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_H5_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H5_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H5_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H5_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H5_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_H10_W2_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_H10_W2_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H10_W4_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H10_W4_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H10_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H10_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H5_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H5_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H10_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H10_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H15_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H15_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H5_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H5_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H10_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H10_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H15_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H15_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_new(void); OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H20_W8_new(void); -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_new(void); +OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H20_W8_new(void); +OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_new(void); // ----------------------------------- WRAPPER FUNCTIONS ------------------------------------------------ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uint32_t oid); diff --git a/tests/KATs/sig_stfl/kats.json b/tests/KATs/sig_stfl/kats.json index 592008ce84..59bda4d7e2 100644 --- a/tests/KATs/sig_stfl/kats.json +++ b/tests/KATs/sig_stfl/kats.json @@ -27,6 +27,22 @@ "XMSSMT-SHAKE_60/3_256" : "09d26df5e911e98e71ef73a1ab6f224964d4a7beacd8071b4c7f7d1930a537bd", "XMSSMT-SHAKE_60/6_256" : "0692a32e318d5c3ac8631120910b783edfed4cb7ed69e3ffa29f83aaa34e27d5", "XMSSMT-SHAKE_60/12_256" : "1a05ff4a4fea850a5fe5c9e976006577335eab0494e1759fe217c2f33f5a84e6", + "LMS_SHA256_H5_W1" : "6b5ffc953ee90b32ee4f1972de5bbb8f055073e831009fc3004e1ead32ecf64e", + "LMS_SHA256_H5_W2" : "68f4412a902595e6debe7da1af714ba3179e2ea21053d8fa25acc1bddad7232c", + "LMS_SHA256_H5_W4" : "01c828a559c5b91b3347c4a1ff5040a50371b7056b4248cba6b8d35080240e37", + "LMS_SHA256_H5_W8" : "f8bc9145732676a2017a3cd065cca68d224cef1671487e3cbd921bd9c772c745", + "LMS_SHA256_H10_W1" : "276a037406ce9f1df6a8ff87f6b892d45bd42af5724a2ebd3fdb1d64b3d94d5f", + "LMS_SHA256_H10_W2" : "c59da910cf06a8de9f0c5fd4b55895ce1996a55983f4c8d9be328c5d83831041", + "LMS_SHA256_H10_W4" : "2ae301108ed8c9eb363e423a483925dcfc089720cd5b9cf8eee62bd1869c8182", + "LMS_SHA256_H10_W8" : "3eac8278b3f9eaea6361ced30149d2d3136c153c6e45d59899af4322e5df7941", + "LMS_SHA256_H15_W1" : "a68af38d6c955fda6c6deabb6925a686ad768ffaa0f6a93d8649e5985dbc6be1", + "LMS_SHA256_H15_W2" : "3ce54ed403203c996c50bf50c69492acb7cadbb41521c2b7d49baed65fe2bda4", + "LMS_SHA256_H15_W4" : "38cce574c163e6a7167ae328dc6bdd44c60d4e9be08408eaa6c239d8625d5a07", + "LMS_SHA256_H15_W8" : "a2e16430224b3caeebd63397e9780be087efcf672421ffc5008f852af2597692", + "LMS_SHA256_H20_W1" : "b31f8b45eee9ec551178cb260cc431256ed7ddd233e69de1587579f0b8ff0128", + "LMS_SHA256_H20_W2" : "0d9ced22271ab0bf90968ec4934a4a44211ef25df11e562bc32767a42cd3a9b2", + "LMS_SHA256_H20_W4" : "7f52315a8fe04caee69874e87bc0f7f4ce38a250f95a0ed39baecc0cb55cad54", + "LMS_SHA256_H20_W8" : "1f5d5a149830ad72a9709659d5968997ffe4a43e034a5c72550032ce6dbb53c2", "LMS_SHA256_H5_W8_H5_W8": "fa6f9a0948626c1e078ad442ea2fccdf456b529413eba441c175cbb681f9bc32", "LMS_SHA256_H10_W4_H5_W8": "2485c56164bbfa4bdc8604195bf397bfe8f54e2ebe925423e4e70fce173c0fff" } \ No newline at end of file diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp new file mode 100644 index 0000000000..206c2dd284 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H10_W1 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm =  + +pk = 00000001000000060000000116dc020cfd4abfd4d0423565aba4d66f585c5f38861af8c7c2626cc33b043c12db72c2210f1578c00a1e6d087eb37c8e + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp new file mode 100644 index 0000000000..4a8296a3b8 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H10_W2 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm =  + +pk = 000000010000000600000002f669d58a91971ac07f6a5944eb3559d47589156c855b69b744ce85da0ff511a6a353f52748de5549c1c7c6cd4236564d + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp new file mode 100644 index 0000000000..ed69d34822 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H10_W4 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm = 000000000000000100000003584a33ceb2d50a9af04409357774dbaf8b8ea517370e62c4dc06882c1407baca174157ebbde27d8e255d5c522c78617f3cfa03b811e32593ca965f771f8d88fb3059a272c3b9af8e445b37650f3616b9a06d2a79e74e847dceddcb6f854fbae8e6790d241e5e496a66244ae738bca8482630b5369e2c45e27c7ed919fa298c1d5ca5efdde0a12b258a584c9f44799b5c40f3889b1e8f3c274a355e24c088bcdb5288a47bf40a4677062662f4feef135493ea4498640c8efca349dbedbf5525af5425a8aabbfb671de5f71072eb07867e15c383a06f39ca2a09ae0d53c4db18370011d4ab6842a35c3bab93e642bee89310ac457e68869f4289f9e93ba553e39892b2969578ca5a02ae8a0272f1b2d6c8a022dac6a397d84bd2ea56136ea45aaccc1122aca34bd4ba6a7a06b2cfede81ce193ff878368f9f2181b8116185558cee1cac048f61109ae5c7b3973241919d9974f8b44dde66f1a8b2830abebf3ba1a115f4563453fe20f7ac023f6a02544d24b38e661a25a68ccb44c287f28d3fb0769048eee6d8f41046423d77e56344f7d5771f8ebacda4a4b5069f0c4746a74e77aa8b5615257b2dbac9863937e6d9c905217341a825c0460dce7a13845db6449d1e1f86d42731df8eb6f4381d71dff4defc11fa5d6bc9a0309a47e298dcf55e559c750f3c5d0fc1a1fedc8c8c0248a7babf6390fbcf70ad7b51259b336a2a39e1306968abb7f39a94a36374910ffa96a436a225436f7753eb7a28198750c3b5deffa1092eeec7857244b4a4d13d1eec3adf0efcce3ea75507f376a6c7effcd9e904ef2bd7b3c8c092066d46955c7ca38ed79ca8a7ffb1617d1619026c8fcb3cdc23c7403cc3f90e3c3d88123b20d40e8763c0aeccaadf79c41a69667cdbdfb73b33642f1d1e3b021cf2400e6252526d3fe62edc9d022e88ef111b6b5b668d2b20e23baccd9746668fb63f3916630506d0b696d850dcc60eec42504398f4d25e2eb6f36a417bd71c20c780f1a5075f86e953302ef0b7a6a9b909857d0ee6fd4c1ade224cf667067d9df328433b19e136bed536e364f82ac05705439967560c8606cd1c26b7146b82e825a233dca703ce03ab7df5c5345b5285be16d542a47a1fb4af74e786cbfd01c0456b8f86fd0e685137617224ff627b5f3dfbb75c9258484d9347ad6282e170c2657f5721e24d5643a4705d6f9aa335294278421da783d44ac38cfc7676740a399f9002ecac9a78b41c70c3188298dca26452b72a8d582d167c3c965d5f5c8c8f57022f417b0941f7828721951978d568a3d2ee0b7a843e5c697b0c7fc0975f0f09fd18856a16fc63db04e0f3ce3a357e4d3208546460814c270629d7810e452454927f29666a919fc8fb104f3c9c1fd38c19c6574d4dddb5c18683a8973cd061faf5f5c18b66734bf8c08766612897d0d9025e380c6317d88791d0861484e51f205c14e0bd83d2d61c394df3645eb0d66c80ded707429fe5e1fa77f3c3389ac59b353ca657e6aa88dcf6498479e76bbba01e75e9d992e6d3181eccd53e122c0c3ed428d809eef91934ee657364151bf711f0c922b6490fa2a9ea9ef02a9fad3a655cd305a2ccff01f60b9ca0b3e8381cd83960c08c066a30a9f46585e7ba143da7700216cb5234406301beb66a0cecd7d8122429992f8eab74cebaa1e7c8ce4d54587056bdad8636c46326e484c63b5aef8b6560e289acc20b953e8bac254da2f22751d83845be6132c6595cbf91b0d2ff7402fd789c92249af031afc1076bc99b9e9cd6e42a1a2dcf8baa42a0c34dc343508e70bb0760e5f9d8ec6390995bbca810dff3a0474c59cf9fafd9d09bf190bbafe003c7576960a6dcfa0226f874a084b4a50d6a680f88f1f3f352c71eb26df521e5ac9c2c6cc410c51ecbfcd090d7c09541810c80cafa5710c849ed324ee734a8ec0610a1a0ccda429f86b28ca0d0cfdc7d29ec03ea1b97021dbb00a7837d5ec8f6e6ae198ae31c9b4365aec42e83e92e879fb641915ca129324176444171873a75b3df1322cc74796b5e6cac0f950d92c322a8a3c6c0a824f8f92ae30aa110c8a415687ce6dae5135b4121b67fe4e5bff65fda4e0cde3372a0937488d22211c92192eebb9c0b38770356fc65533a86efb75a759fcb02c62aff2f61d3af079ce09d6b01ec9d6fd3fa6f5e2f60273f4b9c3de7bed546311557c197dd2c5398853a5b768db5d45b64d2860137c1c1e9bf3bbaf8f44cda1ba1c88798bf91c962195a11d1d43b937801243ad3483d951ce3c250de463aa136273c9fb9404ea92a204ad15a161852182d271e6dccce0c1385eb8a192d063b0a018cfa36d8357d89f1257aef5be8be3f26051dcd238e4977324204029f2d70a4dd2a9e9cdef1831c7163276bcfff2f2530f29dff5dac9a7026f3ebf9ee0449465a61db572b18434dcbd30fb0843ed81560473f8529191b25abb086d5ee06022b10a64b3a1ff18aeeccf277c4b33c9ecf4097bd5097e6bd0a30ad4d52cf5db089d15f4627a44e0689781a6c6a8ce08d744123f6364b1e7428aea701b20985f2ef76cdb3023297c894c7f14892a3e891f396a3edc2507892034a142556e78deba31ee286f0e2752eea28a0322789fecdeec35306d87105ca2c19f977597bdce1de1f8cc1f00c45ab2ecc7dd6f2d8e8e7f625be39a2348e77688819ed541d2c12ed74688d201fa307d958ebc4b8ce08a6b0e9a3116b89a038807e587bceb9cc98cb91d69f884c67e88e30c7c8d72b208dca96f6af60a73c4444d5e7f5b472fd2ca3b36cfa2b4bcb767acea4d8085b080e57f76ccc0dce2c2943b6c806ce20c88300bed34a383e5bbcdfad496910b9198bd43364da92d1fec89b90b53ba54ac634d5ac1f7faf0385358b6b0b5f5d06e31df6d3b17eb9181cfa131897dacbde42ae3c66010b978ea391944db2b52e52e47ff7312b1600e569b46859bfb6af8c4402ccaa3632eb293ced20d61552c75f0068b5a0a7d71f276367f0061f01e7fe71985ecd70fea79d406217f42260791f554b1a1b943e5312ee65251ac228d78c90f517949f6460dd3664f09b092f483d6ef2c00000006ecf1ce60192137cb466675f2310292d462477d811c672cb1890ffff4979ded0aa791c87c602307be68e7e3ed69e59b7c22458d9d49f353679f1f89cba91cd886900b1eb3666e5f0e78dec37a110c5cf09c1571f66e5862d48f6f4dc01812fb600ab2b3ddb1c5585cb2127e4a5e5faf00636beeeafb3b18f2481de5a4dbb9182e93a5cad39c43bab87f66eefd1428d0a426e0ee8c41fab4baf40bb982b9b5f1ce9eb65ad914744b45a4f00c11dc8fb012844cde05816d91fd387be9a2087c3758634e4ae3658a035e9b9e2d50a98ecb21489779c538aac7fde32b293e4f809494a800bb16c5ad2e8d4f22d61fadd2cf82bcc9ac210bada1a203f90f67b115cca1f9c109cc955776335779e6d9153a9880c91c9af9eac9e88b7a5e5bceb3bba9ec9432fe015b672ce4c04cc49ec42b865038b7166de32c1f745c27ee919bc25d0a + +pk = 0000000100000006000000031fc1a45b518c620d9ecff3b054dc2104f35f80dffa2515819e569eaf3594081dd7029a581ae1e818b181368d1cabd76e + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp new file mode 100644 index 0000000000..500754baef --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H10_W8 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm = 000000000000000000000004e8005f5e66764d13c1a66c4b0919b51b818e23767f813cd64ce8f961e189ad2287a30c45cb69478d54db906e55516483dc65862e24ef059bafa11845aba072ee4302a1e4c22243cd893f12b053529942bf1d3c97de2c317a317c9d2fe5dd7e3cdab428bcb8935db5f3efbd2757261b50431c9ef1cf49256a37355bbc2931ff7478acce22a47dcf7c0662d7b21a8727b0d1ae54473d2c761cdfddefcf10f050821345b78d6a1fb6399a0233d8cb0062792bd3e944951a9d1bc85922fd5bad206242800aa6070d1968d1738f2837039f1d8023543302c075ae3b7e490b4e49b1c2f52f7604f94d455d49c08695f4536d027374838fb11e1c32de758434c1b95aff54b3a949c2249eade7486bbd5a600060d1d925da6cf66ec882558813bc3c35c7b461b013f847c3fcde510affdbb548f0cb16d4151341ecbf521090d6d94062d4c06316a0c932a260cc3a93fe75a6e56e642238902fe1d064b43390e71c95ab901dffaa506aa89fb5e4620fd9b71718a8e4516b791c0ca899addd197172f26fecfb6905ef031679b85fc32b98bebf54c172d294d749e041d4b8e11dcca56c70a181c55d1fac4acc936efa857eca994ef6b4bdbea24881ca38607babb2bfa9635d824119d87c78aa919b9ed71d4708f044222f5c80590638981ed8b46a099c5162982665ed2c1bbe1a6f1a91ebb2c07dd5d577713bac16964eb5bbc763b7600c08a13e02bfa253caac622d038961fac0d45f3e3ffa998d13f80f78f454ec7593bcf47214584f4f32dd02350a0175f646c7a80685f2d5d2bfa3ec8f09bf45869d077a6fd43b777c95bf8f848445709acaac75e82fb479a578a16ae5724084b3bab6d8bb5006d246545dabe8a27bc7419f2cbb71beaf7d30d2213d053e3d75d3e785d7d76347b45f0ae31e1d4138da2836b401424213e08863e87760d3cee7caee7e5c9d576ddd3cd0a827960c2697751b855fdfbb1ae63a87317fcabcbe251a305340172bbf0d907ca57d4d01fc10abdd4d7191fcd9400cac13ab3c949f2ff0b1559cf6336f2cac59b97c45faa702b1212b341490bb0905b0598b8d76d95cec3ee6fc37d4096b625c84c2ce3a4bfd1e541661eb57bd4ca0a5d1a55578d0018bf0183cc2684fe61d8376ed35fc6c9715e03d20c3c103f29f8eb4d19bfbfe71a81cd587ec0a2302789bdc9b6741fa811e0b7dd4e66abf7287fa282d039f9c98cba1e46594ba3d2fd2b994794c7afc627f3dbb29900f42aeb0d7aad125634fc281e9c37047a1c7aa7cf9d78c3100e3d1395df86e785970f3e107bf12ffcf7ee3fa8c1169192c61dd9f3bebdc08d4290e36e8b135d6596b70c91c281b766b0ff8ecc82d2355f33d1077d7f0a5bfd05e19210b78408175b1e7c9330a8f4ab4ceeee202b3667694277169bd0403db497b57d9974a3c1ee438a0339908736e1f97ccb1ea3f324682f0786e218c59751f8231ab20d9bf2648e06e32018f3822d66a2d180fe5203484401e5471b925cf05aa64f287571b0645d05c438f61c14660c316dce2d8aaf22a64430f69d7c3bb14721ce16569863b7e65dbb6192b581751a903fa2de500000006979941fe2a0034185d9aeb8f6eb51ef6767f2e0218f9f1a20c604fb41592503e1efd6c941c7e3056ad0b47b3afc6954a6354791967c9274a43f835fc370099fe0d26a4850bd75228166c06d23d16cb07326be16f454269d1648fa58b6ce4738a8fb926d2a61b5aa66c4a3d4417b0ab7ba7fec2f7bcc1d1d179b7d7a90bc316975c81d903b29345a3ccb9309534aeeb6647dc5662a5a64e9b2c622bd394339b9963ac9e6c3479a5d6180400620115b6b09af77ad82c7a39e278ced784702d1ca621705827bce972d17fe501ad892d4de6f94e748cc7ebaf600ef73037d41a4719cb7a96ef86d89b0eb0e7da8668c85e52407b2b14c232ae6df56bed6d1ab6d7e5bd2448f15e0acdb7792f62cdc3e7ff1db99db034524e0e2b77749ef0b624dc6e2937e289954069c33fe4d0328672caceb377112bbdaa844bdef5bfdedc1950aa + +pk = 000000010000000600000004d1436ef5c39f769b4c9b61659c603f4a29be7b4a06700654e65fcce588dab0b2478e6b0bfb4e74880afac2a1a2d2fb66 + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp new file mode 100644 index 0000000000..138da7ff33 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H15_W1 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm =  + +pk = 000000010000000700000001ae5630e18184f7991499298f672208ddbc2277f012b38faec33bcdd80ef1b5f3577e649214e41db2724dfd194e3258d2 + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp new file mode 100644 index 0000000000..e478aa9d33 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H15_W2 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm =  + +pk = 000000010000000700000002e8de95cb58a8b0aa8ad47f68af1c98524fd0f190b5205f40ed55507653ae7fda835c910eea1f29d7716330c27dc4f835 + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp new file mode 100644 index 0000000000..b63cadafb9 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H15_W4 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm = 000000000000000000000003b15d44eb5dec79430945738b499d2beebb5302eafc1318028103aab6469c2cc9f7701919bad01498c915de8d56a9e221413bc8191bbb0a6e538298c49f46213ec9b6f27b26d85c13541b2dca4fde3fcb5c6cd830ba044c8e6478011c13a10e79d5ab11157d952166ca5e5cf7f36c675af016a4476d97b79bed46cc06d261e82ee8eceae9031cdf85e0afabb71aee45054e90534ea22e32987f6bdad1d82e5753c3d49b70a2da50e715598dc45e37ce67404f50d6f068ea9f053f89a25f3167b778f670834a4247dbf2f3463772f1af1fe98def960bad75531503874a8ba1679b0eaacfa0532017d7f12587180a0cadd20abd54e206f9482ff3d24be9efb41e6fe749facd7312927a81857f0810d14610528c4ea6b3fe3e8efb75f3c100ace31d91b273790534851f0ba37977178b38df4319405c8ad6c9a657c536836c6362f41fe67884198d8ec5366bc788c43b8f7c1689c47d4f3d1c33727937fcab453fccb7dfd4f1932caad1ad5ac45d51e4c4fec014ea796b3b9e70781a541e9bebdb309ebde3a30918b63d6d076c4ca22387e0b7a17a42e300ec1f9b750511d989c443edf89d9f24bcfe96767aca712ee08583a70fc80b6d7b7f3d7883c02491bcc02e37e267d9f14ac003fe002a669a8ff5ffb37e55a8c002bc1ed3743745119eb0ec227ff38eec5956f1a36390fa086f98ab4d9200e7c17a48ecd8f8b5bf38341ecbf8a5a0f5f3fe4b2a0f813df19df6277b014126d1c0d42e093d1bbc4e2cbae00422a78c1e70b2203ea18591b22d2015f8d4d000fa484e879d44ceb86e7ef89e11f3ea786f3b6d204e4ba13466bad37b1cfb4cdbe0f7bf26623d787681441e6a64d3d783bdeae7fceb6fad18c8b011c2f14b3660951a8cf87b75d292489dc87cfdfed0610cbc7b727b780400b8ddf7a1c5d5fc265a7f0d2356a7e39862dca4ceb0b07efbea59bfa5c8d27ca1c04857b5c033322dfa8bb5f0aad504c246f17d97e306c55cf17f0724d5201ef283f8e0191ddb9b5ffb5f2e86586a1ec2243dfe17b61e6c5b48204717a3de944a26082b396d016a3f689fec52354321d08722f2141e53063305f988a720a91cd326bd7ec72071ea45e314ad505c66a85ac4478fa2fbb7abfe83e890779f607de7bef9b852e1b72ca511cb49b5495884f04a6c6252dae87ad6154f0934c44ffd9f9b7e78ff32163f414fb1ae01d703b53afd5400178ebdfefaaff149de556b474d507cc4f83a2b6bc8d8aba86d55f32dd6c59f90376480d195ccb157201150438b93432b26cb6a437be4bc84b5239b89bc477ce4ad981c7c6ff38cee53091aa3489a095e72b582ccfcfe783554b3dedb32af18f136cbe0c83ace70cc09164debd2b67fc5aa9a9320024dec45a74be1793e3850062849860596cdc36b9ea154cada6ea752049b391082ba0107e4658e6efd741fc5899fb5ddb7549cae174fb9e08d0b42d75f15b1743d06f107045ec931f8ffcc67fe70779cfb6c3e3f58fa230c951cc6278571796cd0f83249ec93f7ba62868782e431c177a691fdf617e9af2221feab9ee09684365d0a8a5e1948de7a01b6e390d18651f26655d994c1363efb93e6dc196b64e65b8ce1150b7d020b280760e0354d561d08228611e2fe9f483ab574f93cbd709fb3b4b07af72d27f3960f6c6579ecc02ceaae745a3939112e883e9dca7856d5803dd5b21f889c145d3c54b2a5fc117c341e2109b935cde6c7959ef33e3c2a9aaf32cbe003c14aff7f36cabdf25f37467e7fcc58155eb0a354313057f30898370ecdc5b75eb2a74388197adfb36439ecf97a7f9302a2f4d7be079abb824db22f7e962136df36dad41cd5816f4e8deb434b59b4f308818a12963dcc0168f20a15017f941f129dbced6e41fadd87f91655655b7001170188fe9545fa93424f939464c7af32a5f282d999e5f93523ac2090041cb087f6be7e8cf2aeb95e05afba361e973c4a69eca8bf7c1f22bd98e94dd71e604561ccd316f6579a82c75b58f731282f658ed2de278ec4c627bd7e89b4f7c4a8ea68a48cf8744be232981218ca4ed83db5dce7719b3237236632e9679516271015ec8db512d517f03e038910cdac47ab895d8a8a17dc43fdb7c27273cb830372edc94e9188fc8eb0b95bbd6f10ea1d593a7aaccf302b6ceea1f6f3b71d7d4bff16abefdc5c065922e1eb3527af393186b963b15b3a5c0c7626e68b69de1df88dd9d5430d8919548b1dd21fc65f4e602b6a0e1fed96e931ad8953b30f84eaf86b630a104d5f296afd9196c865134e9f93ccafd17abcb2b2fad3d7c379cd4b7f2382b30af940474665eef0e0817e322cbaed4ff5607e7970a8b5292313a9594e5ad6878cfb8cd74e9c498dcc63510e7c28d931ff70253c602ab5cd2d600580ff642f68aabf7a3643f1c7af8a41e65310311ea43c75e95f8370ba5a6ac3cb0065d599d79e4d44f0591135a87245eaa7866f49046e764facfaddff76c5759fb7e58c215dd446f8a81ff4b8e48154e6840c38cd961b9b9dfcd55fd605880bdb8816d877fe1a53237b7a3e056f60476ef3ae607725eab95cf03290fda825d9db7ae0262ecfda3370e5799ea77dce227ed43316cbaca2bf61217151d703ad6801add7891d374353de6bedbf63c69bf33eff12c937df5300f52bfe07f7dc12f197e7aa071a76e0d2e3eba64f99737a8fc0f413b143c8a068e64fd7c0767094b46945ccb76ca3591c0f7cf02caf00254eec04585a8b9e38d3125283c3932fa6ea02999cde821a534272b267df5be0aa822a18edbd174bba9262d0f43a6870b2a5e95e8e673a00b7de8a0acaa0f38d78523564b7dd045c151e5c072f6e8d4b179eb36d7775d3f55523331527c1af2b623b4c894da1847a3bf9ace1eff733eb1dd0a04c09d8b378e9abbd00ffdb9d9bc8d73fd4977b8271240d1ddcda20bf41e2402e2f3085dd9ccd4ac881455a22d46cf9637ab93fcb3e4bdea1facb4f10fcbcd96fa21ec295837c56148dcad04c34a15db5aa2a9b0b4098493682e9d536acce9150cdbcfa62015c43473d58e5fb1f30adb8905b90a4426c81abdb345696f21da4bd210000000775500fe3a11d75bbd8a575414493dd05e9089d78918012e60f09610f1d957fc6724bc66eb0f0ecaaf9d040e31cd61531b5b950991637d97ec4aebbdd68efef4fa42b984809bf91e21b1b767d8550f0ed2d957fc61db16b5bcb2965436e5e15b76bc299f66f30d459eca6642eba5b5068cbdb38aa87def567852f1adce0d08175390ad6b1e9db4eaf8a07c11fdc7e68bbeb66afa3916aca2b7e9366cea55c60d643ddae869ef53e95a5e24866168c106f6ed019c0b120417c64b479bd973077c1543ca6242a05abc1d48e778eaaa3b3bd5e45bc9d569f372189309aa91a927ab31f67daf8b45a5947db1149a9ff29a4972ea03b0b238bde23599b4068f4075f02bce308631ad3b4a00babb5fef7a03a6a335a543e10e360824272d7d17b9f169f1a9d39e941c61da753842870f3d058192ba9b808376e08a5879c077ee8fca7228f96cbb6d694d6bc10be0cf5b718389378115e38943a57716e5d98041c4a6b93f40e2a781728d98d9965784f7404dc2fc7b63e3c8af12992afe5322284fed577a9e9c866a590332436b08fb783891cf1cc7c7b4753d24e23feb7046f90aa3bb9ec1e30ed1dfcc1f22e78ee63e648ed3bf949bc04e47f410a3441d614b912a8e7aa21ffbb15fa2f3261cddac3758c6f5a54fecf3153d7e168c0aeed75c91cbef8 + +pk = 000000010000000700000003a61d708a980acafcb08bf59ee41d84fbac8fb29c8713a2d9ca6f42c2df089c931619b265671140e35027c6428e2cc18a + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp new file mode 100644 index 0000000000..cc7ddaa6d2 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H15_W8 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm = 0000000000000000000000047af430445b89d9b8c82509c6d6e14559a7e26488764d076cb6428ec25a95afb01d0fa6b245bcd544909ca29bf1787ea02eb45ad125a5aff76f43fcf8d58c8c92559e4a1f99339a26f66a75296eaef6d9c087606dd3df5987808521b95905e0a6c7119faa2e57df8e1ec02be9d1ce346f32d465eb404e928080dbbbc6f9994bdf9ef72a44948a0f69794401fedab887ba9a8dcf117650c5cb45b239d08b9247dcde09b238a5cfa5fc26aa00f2060e7eda5bd7d5ce5b6037475185b0b2561d8851626b2beebe8f12b1efb24bdb9a86b657893ccbadbee0d04efb421fa494aa1dc926a3666a959313d08358dce4d7ce16b23e36cad0c26e56e2d5b32afa744ed53310fceea855092a45fcd7058568cbe4508d511b8bab52cd30a75d3c97cd1a42e7cc2f16a6242e8e10fb498606556d6e65e2f7d55294560856f706cddaaea7f3d495d4d0c6b655cba91b211b7d79dd9e4cb4e8c44f187ee7de6312c39a99c34590a8f50141c31be1efd6083a8aaf36f5da7eca4f66fdff1d984e764b720bdc830ee4f6c7406c2b0cf0889a00ed51d435f0b31c7b9a10eb8484c64d3d24cac953d38b11c02047d919da39782db070571a9a10658eac751c19eca9df0b0a0f68916ae4830f56d28eec5f18341542bbf2c8652b44ac354326a9b2a854f6326ae920f4f201f5f71a1c698ce69e9964fe7aca73f9080c420fffc8fa3838194ce479c87e6ed5619eab0bd317b84485755a2390ab4b8220d74b73d14087ea334c14f61bb06da084eaa77aa99f13b62758e6a83f9665999b0f86f92c854a1e44b45e5cb5209193025d78bc7e5fd8300c91740b444ae3cd3880bf22927f777d2833eae0d4792b917fae8dda163cf4be2928e8c881d0fbab323a4925657335a5964f2cf295de1d4c1817be9a78e89712accb11e4b02bb02ef55e42832f94b293c732e1164e1254c6597053620fd88b78d884106d98c88f87756656ab1fab40175542c4f716340d485441e9af121860e971eb8c2b26d8f5d262d09376e04c8cbfd79f5c45261cfb6c290563b4ea0b62c6464d40d1ef036a2cbc3e8e9e227c91798fc2018c393ad54a6709a8b13caa03e2c0c8cace8253baef126a4e2900ec69bd79e2a99faf088795b894b09f002e8c33ac189346003372543b186e145f322630883a283b9c31d8f0679b9fddf0b3a551c451bce5f9d6e47cd113894d723accf6ff6a28e37452884244456f55cc89514dc24585b458725595890c809a6e034e69135ce605bba18d813a3f68f0a91595b3c301e955a283620e88425d3ce747e68d081dcaca159d269adfdd8901920916ac8dc652fd2b019d86342d1b92e3e8dacae938fc14bc775021a8faac81f5722446c8e9715e23ce5c68a114ad1611a6e146dc80488d4f359537de3b44bd3f1b7ea74d045f6846931bfcf1747e089c75a5ffd2b7cc7adf693a282966d414ce7715fae6064938f7db7006bbd98c70b661f2b82bfe5dc4d30a9d7763e4be9bfefbc63bb7c5d4c8da6c9adf6a9e1f20025bef2564fa87886feed6789d555ebee11bc812660b5e5b4b54c196eea96f693324ff20646e1e4dba9400000007f656672dea662ec5bcc26a23487368222eade00324f8f5f72c9111c474af6995e54f45a1ea3ede6d95a73d863b1491982f23f2ecada075a63512600c7661590ea4097241a052c5bcad87ba7858e9d5458a9a7627c06ffb3a7351aa34e7654ea893deced8e5736374ad7a3efae2331d3f4ccfa90ba46871258a920ad200f575b755e977555f8480b3b59e1e5aca7300654b78a56befe6cbc8f7194ef7b451e09644d4220ddb8c52ddb9029d220bc3794a26581e2e1dab769184b502f32141242b0f73f608ecea7f3915e7e4730a99dca80a672cd4ee902b64e15ab4292e265431012040373192b3579d916b8cb20f746c512c065eed493dc15d7af1a7836caa481a3a0369373debf8061bc276f8fe6cdf6062c607457bb08653baad184ce8dc6262114e566eb3e6917a12977028a252d27b4d20f88a0157dd5bcda24fb14d9b55a4663782d6ba567f424acfcdaa1ef74e3b4467f42f78cb1a75e5df72d2f3f1f8b027252d2598fa3cfe6cb30db132eee876479f7de10a3988bf5f9f828bb34cd497307f92d16d14ea5041dcb7223099850a79f6411dd01eae4d04a5a029c6c32f728f778728492ff47cd2867a830a0c68db065021b163470ec315ac84d0f1086b841651ed5101170aa822dc63cd76d198a44d50ca755cc39d0cc421b9923ff4e2 + +pk = 000000010000000700000004ee75d92a6e0f472dfff23ae76e330d6175dc24edee5b25641c195c2c60ddbfd9382942405a37f4bb4b3bac9806603507 + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp new file mode 100644 index 0000000000..b9d272dd0d --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H20_W1 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm =  + +pk = 000000010000000800000001f8142f2273c3495dc1e4bced0300a27839572bc36123d71f3bc6b847841ba4c377bd240deb05ec3ed15ee30f7fca56d3 + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp new file mode 100644 index 0000000000..46b9405c33 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H20_W2 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm =  + +pk = 0000000100000008000000027298009a2dad468224314c20395b436b6cd9955b10abbc17538e96f1cd6d55ee948288bf22a0602760b00231a8d71ba0 + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp new file mode 100644 index 0000000000..0d461a43e6 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H20_W4 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm = 0000000000000000000000037c43ee18a5df8fbfd9e917f1c48edfdf3bba8def38735c8467489c1392881b827fa292e35aa39f67ca2a2ceb9301d7a592458d8bb115f78241ae487783e50926c43c04ae72ef85993a9a2d8db2139ae7cc95eb1d1cc04840713e0e867f0aa3644179e4411498d0f50c3e149c8849e03979ab92e726ffc2e3be442cbd4d1c9eb8605678e51e613417f33479ea18e3ac3e864c8219554629568da7f5b8ba9d4f3dfdd7f63b4fcaf606467d1f5b326e20c36e45c9f251c08b0116bcb01e3e5cbaa1d5e154ac2ce0e11ec42e81e105244a020773ed094262ee3d609d668b2948a0682e96ec77532d85e899d5f7e07e48b99b7416f27f05408e8704d36251bb5df5568c53df8c3aa7a0b14a7e311f0cb63752610127d73ac0b80733144c93d6de013fdfda6ff4693fbd19e6c7ecead046f1e2c937875f74f1428e3f1f54996b3b47fde49a07b34298b678d0753b9e363ac9e8a777148cf816ecffb458d829a440d983ab9b0d435bf8d98ae71a81a37b7d10f5e001fd0c6a3ff033530f0eb1f155fe96e21637dfc82c9e802070b1c4e008998206e9c04cf3a38f89108b275b5afed4d58b9c34cf4b7d94df20ae5a516e7da4557d53750ead4f760ba82a8e7e217c048acd6ba2ba877825522cdb72e152b31993cfc0fc1df21934cdb80fa088011c62e127b3799a498860108e5f4f8cd6e9fbaeab60b7ea46e84942e354e4065391a6c7039125eaab29dc08cc5bb695ee950bf37cd1d3d83030ba994f280b00d22d48269f05c56ffc54e43c45311bc6dbfb4b53a1df6ee4920a370c894c17fe90e521175bb5ed8bf39987d343e59fafe785e9389daef38de6e863035a3fb630cc2755b58f0d4952cdaa83040c84775faf0314a7d84008ff79239b7f77e3627afd2e868aaf5a73cb3d92f697eb4b880557cfa589fdde3feac0336c7814cd0bb962d96ab5a9a3737cc465e605ccdaf5162c21de0feebd23b6cf9cb0fccce7a1645a66341b7314df7cbf24ac1256ae53d5ac9952de184c1b026b9b2f227591694939f95d1480243488e5a26ed84a628dce33aa884460c0cc3535b73be0dbf4b01608866ac032c19fc1ddf288ee7e2b955c1fc80c1761cd6ce0ed9d6fa3a66723c1f4bfc67b5c2b36269035661a8f10d20dbee8712322d93f6d70c329b5ca914ccc91373f2b809686a5a68ed5bce241112ff1274350219cd10208c51f1b1ba415b61a1bab437e6a75d422f635584a83633ccac0040215df734c6d5e654874f8059a26893183a3d1357e01f2f5522351f945957a0d14c263d5da7602b2168c786c66bc419eb941c1b029ac4ae53b89fecfadfb58ee1aaea9e71287152c180952de7f553599aed4adaf6a6741fd358f2ae0968c027a1f5f175acd951303059cea84a98b70b7ca986709bc2ea405159ac9d50665f25eaba56e0ce2fbc5439df6e5cd08d10d4167030fdbade6eafac433d37eebffc185c9333411d3abe34f5254f1451191c7541352f7daafca626b26716663fb25726e77aee9c1c6ea2de33c1f28c2b6d15cb7addca5bc422d6b06c0e4db832b9ab0f08da4530218d082116a1a0ff9f4563992302b2ba889d04c1375bc15fda2510aa034963121af0cb9be12a68c99d76390c126f6fd7df89f8a38982e7edff991e8d9318a9429dfdab46a54aa9a04018b634079d23a511350e4b0162e628605ad852f0e589730d0f8e09222716bdae6151aed4a62dc3d50e417e9a8817fac017ddb0da99ce08723bf420b6a70d25abcb2914c3997361b5be31e485b4c621ae493729c7f9efb00e5e445f4828629d61d532459f08654531b4bd5da5867745b58a9e608a753e568c931afa3909da2a5dbede3ac7cd52cbf954e9fa26f510476cdaca57fb014b4d9f46cbf4d2450e2c5ad020d189e5d32eb49aec0782de2556403f51ed8ce5f519c2cbd451233f1adb9702918dfad4031ff5604376384a200fd64bc0bd80371cfb896dc56f379b8f3c964d2e57998bf67fc2fe12c88d23ed3bbb267e0b54d1603f833a5588a0458a04521b86d90a56c7e9ed3a8beff5f13a49517a79f270d245fb24fc3dafb1ce0f01f6f15b8e230291d5f6d6f394572a49f9f85d1847b990cb2060b09dcdbff555eaf9961fd5acfbacc64556b77139c177438b8e7a86112c60293eb1c583afbc17de5261eca46b76de8160d5068764c194fcb6a9243396ac5a7a6db9602b3421f8f4f425495d91d5da88eb9aa3036b5749a670d0fc8b40af82515f296057210751d49269d6e86e7cede47534b7b307b39c6ab21fecc37048f4c911112f38ae2cb01a5fe9a2379d37bdb4986a0e40c2db67f529cd3903d41a9157224224661414a9092f906e6fc7b6d60a68d311159107d22d2a15d757f0b4aee8d1a453676f26ba90ba8862b9ae5ea403e6ebee935407d468bd84107c8913592539adc3c65609f859f57770f72d202a903a63ee0778a321e402e036fdcfe4b62d78a67e3330b71efadf9bf2678fb024c75d9ec9591f2c58c08e6543b5fb5427177cda74ac3c0c641308c0562938e30455799bc555f9c0cbbbf12b9b1b7ad907ddf838c86634d3ae4f3b9f9d5d4dea929c75c5af465d17fa96fe88233fa8996cdff1e1cbe21cd5ee75fb3ffbee0f0f15817923588737a6b1647324b9cad29c33414b5f87c7db0b0280bc27dab78b4c8cf137752169d65fa5b9d374fceece83acbfca612847a147a66642d2b25bc19c4e7e86118efef57ef08eba9fd9bd36854f96ae47ec1b7ba8d4e53f97553386d1a117fd6d11eead3d10e58cda7258ab8d530c47d33321247690dddaa770c9dd6b5295e164e2a0b9b815dedbb9654517be6691b3dfc739c9d470cfee8ea2117ab7a2c2876a21e3513911486e00649f98aaf9ef1a32b63000dea1ecfecb9d433b51333781262053f1096c884fbcbb3187b09489fe1da7ef9d3eb14ec1cd91fa1e09bdc2a6f05ba95bbcc583a86fc73daeb18ffaa7802e671e0641331813bded68bfc6f284cf44ed3cf810caa5e6103208bd4c56ea670269e04f96a5627ce77b364b50b21b38eeebbaabed9b311bdf49f46310be5d19aba8b76b5ff276f90a784850000000863db9401ef22c5a1bc3ef9a0894c875e66109f097575f50f8feb4e2c18ef1b3804d41ae1c38fb1dc4d3306ab4cdc3a0912ea0d70983212a10c7fd15f9eabe503251cd8e12103dbb3d5520a22bb4f758ace010741d5eca7d2fb972e70abc782243b7639d486656e9c0bef7a89c6e64ecc0bdfee8af27e24349e9cbf37ea13c9533fac0b57d5ad9ed89b7af20991dd140b9c23a01f53eb3f1e649d8b2d6d941948ae30c64cdec7cf05e17ef2b74d24445ff0c108a240168aa5694336f1ebc3f9577ecf4aba3fe7494eed663a8fc01b85498206a6e87a435e30a3bfa64558126e79e440369683bba29269d86d8c08150286a1ff69fc0a4eec0067e88542a2dc03fbef3d11681fa55c18d9ce1ed722755012df301ad7082256925a5fd0b50d675913a929f7cb289ef8abfc5514815a88397a1be657ac0f5a3a343e18d56a8264d0d52596c561a22a72d18a7d6551b001af0ffc60576f54829d36515e4b9a5c4069306d2c3511f176d2d74c092c7e261d9fe4b8ef9b1d2f1dea9663795afbc7058c147f1fcb977f80f98fda75a7c8821fa226af50fe8d02b9f8b9a9ab58d6f498544e4c8414938f106891bbf87d215e42a3b3dd82462c9ee5007edbe45379f89bde29d86b485af81942fc8a71123b51971ecbb49ebce70a85298ef1eef2226ded1b68a16f525be1f074364084b9aa50a2f215e9824727ecdfb536c3e2f8254b2e37aa81bdd106ed7669e5085774e49ebeb7683554c867c6aa891d6f02ba298fb5bd75e2af2163e211cf09873ce061f20badfd14743a9088c2fcf756c37ebb41d3a437857a85abafd33d57765e8619429abeef65b6a532f5b2a8ed9892316f3ed951eb32a10f51edd95d7a5a0e5eda591a481d081e124831d297cbc44c233522ea9f26 + +pk = 000000010000000800000003bf90b647b42dad7ba89ff319a8b70dc30f41f24161c1b6d1935257ae4b0bfa5ce168fddedee56ad0931604f868f9d5b2 + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp new file mode 100644 index 0000000000..dae33fafca --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H20_W8 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm = 000000000000000000000004c77901fbdf3723a0e739e33dad60d6438b3a33adfc72c33f3e1a3e13791a362aa3a1cf96aefb864bcab9cf5714de25794d8d59428eb4585ba22ccb719b12dd7301bb456156130d9c8d34e1624025b402dca6c4d2d5462ef59c5842a9aa242c72cdf29daa26527f5f529c01af89066ed129477f2796f7a2bbf91233f4bd3a9f658e995fcf6221a40547c442f3f5dad46aecff3a4b061bd72c2bd725af87940805954d9b9cef4395fe8e914c736cff67cb8f481c5e9842ddfb95a4c7f9f1310c3bdf951acc06337ca482b677992f207e11fc3520c923d69fcf8b863bf113531e0266246adbd818300bce8ab72b081d453f109bb298e72bd499614f9e609a12bd1e7171187b65e70e9f175b7f03eec038f2faeea0a6c13058264f3b21ef4cfd27c3502eccaf94c68060a468353f1e3c111226bf3baae1af78d783c91c32a344ea5b1e3875f1571cf381e4a142f154c749a572ee587395b1bc49df8c979623dd8b4b09bf1622d7bd1846bf5f65d7be5f28f69a40eb9cb0f25cb30b1090205f85b067870d2abebc20f7bb67a35afe9eb9e1c8f9d90d32b18728b313e055c22671682ae85de2277aebfa94380bbc7ca11c090430cc519695f3af0c5667a3595bf565e7b1114e069d9343132d36adc42043cf0ff1d075f82147d4f8baa9e38e68ba8aa9170c855f3c6e3be4840dc92f65cb5f2e1e24730bbf6d4f73349c3d85e4507b8c4f39bc8b07eeee8f2fff240b07858d391a9e24d34d7f219bad1688546106ecdc177589ea3cda62c02b3c862d7ec1e995e6555beb0d2fecb6d6d86c232dc76f063fb90b1bb4f20116bafdd7436825a53fcd26d1544e71a1feeb0b154ea298948c3ba9ba0adeacdd46860c6d28da3630b36acc8913ecfbc1288417513b8988d977613b93fe7c5c883a4df6096ca35875f24b4e2f7c6c5cf715aa9428069b365e1a121323556113a0ed9a2b8c1cbb944eba56e4917ae1dd6dca34dbb4098a52651af8a8b32a0416b85a9ec8c3e305268c518f713edb977fd6b17cac7fe85d574003bc5133b590d117e5b471a0abe73f96a069b0162bafd492a01900cb3c9bf6ffa6c30f11e9d1ce0eb5385187990f54387a1f66be91b8e9cc09acc5cf0545da67470ffbe95b856f90335573b14cb487787a1440166a4b5249c8108b7d7e07f340f2a30f986cbc2b1e3055cf425dde138deb3fb12a9bb2cfae7020b2503ff50840ad2f026282bb9725e82e310cb2c32a1fc1e7291817f7539055d8b61335643d2a6754033df4326da389ed5f83a6a1c88125975548fb213a2fd7287d98e8d815f42524e10ad9117cdbf88464a8354a96e6c1127167f7cf00088440501d660e670bf98e174cbb5bef986899bd2ed23f0051d1d776e6f4eaf6a8b4c973f12fc85b218c17d346dc8e8f820f71716219165fecc90ac1101a58d0325a586e9a2fed1a2ca2a96b86c94892551712aa032e2a474315ef6e0aeabb2d92356a65e55ccdd371f79a5e6f59e902667731512f1faf7bbbc3ed307927323b1a51f52268d696be32066cdb859662fdb69f8e2a718462537a612987377552f3e34919ff9e044ebfef0f000000088688c398c528e063a27c2654d8ef6fcf86cccf6111384367569f78e0c5544ac0c32f502398b9fb43c94ce6b0c2fdff387ca058d8b3d70edf444567347c32180e5f579935bee605d8d59580c7092b374ce27758f3fabbdc1210c52e7cdea694281ba308427afff30f71588a9280f7ebc56fe9b80c84ea65867cbe443ce760d0dfa3c7889846873ca76dcf464c7ac41ce082605d115f02ac350289557bf7afa58157cbed69a0dee6991af022ce6cd54867c1a05e71949fef85c941fca240e0cb67ea053725b7fa8de0ef248b9203f3de202fad5415112aa621ffaa5504fe4d20929b4f761d9b8621a63726e079b36c2e04bff0782374e2cb103c54842768c164ee77668753efebca2f6f075f47002f7dfb3689e27f1096236cd904645108e7ee25a0f6f3a24ca2db67b53a13a5e9c39601d526b5bf1658c9e9ce2b80f0a6eda7ddeb8811c6458dcea902dad8c1e0da485459d01a9349bebc7e03c7da4366fd53ed29b30c7bb9d28d758c5574f7347cc02e1becabc07964ef20bb27950f4352c92382eba52126a33d4fbe947a1a70dcc622115e4a1e61d283cb7e21a26d43f5ef2317acba85a2aafd6fcdc6fd902bf7821de2b21f252d73efb0f632e46097ed8b9d7c859175c8b4c54d7509ed221131702fef73ca28d9f25f7e1e915be840ff3e56b8d09323f93da0a6a041b5fe66a1910707f5a06c805efe8cbbbcef36a20680cfbbc4d793bf7ba9be868e290e4fe99c1f44eff6f1444775ce1f2c2bf2479b38db8029024f7cca496cc0c1d4013f96a1791e73b72d4220d649d7333761aad155a45e23e00b83bf3c80848c4c3bef451b33102338b11e4fa27c0e63800f1fb10c72029c3034e04d606bed563c0a001f5ad8c718d4056acce6076a1a652b28699928 + +pk = 0000000100000008000000042fd1d7b686c84cbe1eaaf415f6095268787d809d3b8d9cd021a0967b3972c847cfdc0935346b1ce9f3f6e21a2fcde0cd + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp new file mode 100644 index 0000000000..a3527abf11 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H5_W1 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm =  + +pk = 000000010000000500000001b36459ada3fda491d658ab3eb3746402365eff2d5dc9a06584f35229d860137b855cf7759157d382db8a687384089567 + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp new file mode 100644 index 0000000000..488997fed8 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H5_W2 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm =  + +pk = 000000010000000500000002ad412ccdb2962114e64225d1add892b4adf8f6b43057169755d96b6ebc59eaa37904fb719e358e6759f598593ea69f7f + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp new file mode 100644 index 0000000000..7e4ae977d5 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H5_W4 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm = 000000000000000000000003aeb14a03f55d830d64ab4981809d932f48f8371887e4b52188d67e9e77d296b7699c4267b07320535a32b9fda668fe4d64e126e1190851de8400a1eb29b6251778dbf3fb6e6c2d4ed9cd306501ff53e4b3e2e6338d8107537ba3bfd14ce795cf8f939e9ea6add97df60ae591800014cac041bb38857d29a479ece3289240b926b02e7079af6ce0bd239fd9c9c55880c7c68d527abc9210cba38903c561130e1cf88e75ac230a1ba6591edf39142739e8cd16d5c744d49c6dc9318927b3f6a2f44139131b5a29635a80e5e4ebde27570727e9fcd9aa18c7e45293f67c0a179a7a159574908c1a43de083e69aead0dfe6ae356367da1de7bc4007b45483f3863b045a047ccad8a88c16ebf45aa2e76a40a5806225bfefcfce1687602b204efd87385308a2a4d4e0378714ce5bd12341b1a71e8d155b2cb2e08616d5280c418d355987cffad11b65e2032371a211269943baa66907285e4968fb4bfb271230809365dbcb8fece0e66a6c23ae94a4a91ad6cebea8c2ed848ac76fd43935db8382731ad2188f556519b87efad901b656f8c5b533a772cdb1f59b2afadf46ea3cacb9eff1eff51ef73cb414da18f188880a67d6a2dc70c4aafda7d2d65ccb3e870033c3ccd2e16116b4f685ee45194cb8ff4415768a22ae5189ebd2f5d2a0bb796890b85a01979536d5ca3ea77994cfd530bf95a039a7ce635a6db922baa997a6c26ef45e12018b58cd2cbc7b3b3d0d2938b28ae7d0779369e0f8889c36ad3a20e6cac70268428eb43fc660d6a2a293762aef9df55e5873304141ec87a96ce4d6a7e20fe69d66a70e872c4f037f32b5317f51a602196c8e443ed0cf80bc2b7104b2b5211cffd650cba2de1777268b1e015556e55f3e4400e61abcff383541594947f4ca2394ad26c43d3301264d05cae9a38d4c70b7b6edf50368f2e30842bd619387961c258abf34181b0e662af0db9ddd8e444116e28d1959c4e56f5e32322d51b772f6f994e971c49869ced203936f76731787fa6e8d13dfc533103ca0c3cea5d8c27d8b3b05f9ac81b30b9ec947cf39299972214b6e058f3fcf58ed982efb02bd1cdb6199264183c82853ae04cac67f6d2baa37f725dc77f08534273e8cf070e9383d8f4ebdc44bb2f4a48a8aa9ad9b8c6ccd1a718fd9ad8716aece437630a5294ae83898d44392444bd7d26fa0705fc37f384b9b09b94ef0ffab639b9d01758d286a8ae14c933e746459c64dc31d609716e928469e38b36e563ef68e3644a7200a262b1688fd8e4363b57d42a64d0866e19501ec91d83707067fd37e1a3b42453e75afa9739e73030180ad38b687230b6bc8ba02ec2bc300a87828a1de3a8cab63fb26d30099f960dd82b7cc65923b0dc380d3513cf0c74e671e50ba668b8b0497919e260cd8c2755de8ae3455ab3dc3c378a789b8c84dd6ee8641a4feb06ac3d8dd80093e744ca7f44e1a3bd0e1d05870841e13a6744530cf89b887085cf8031c1c713d9167d9e1ad5d5e7c5d6ecce0830863f846d423dd76a91be60aff65a72f16e71173609a46f3bbd33f46d8d1928fe620a646bba75325dda0e8dbf1f95ca9bc02e891889e6b3009cbc944b9aab65fa30cce224ec1856abf23556ac570f43396c61cab7f458d5ff1fe7f83c0764e78fa0f9f9d75fa9e0c518379a3ca746205fe03751231ba269e19b579b90b1da30d8b6315ed7a4e54ae88fbcdb15a8fbf24fee6d9f7b95dceb99d330b449f05a53974118989ca9ac1bcdddad5a43b882db01cd27d72236c0d060b2b6120ecd7053820a5cfa84dc672fc2c310067cffd3f5a8c3bca13077fc1d44e99c111d4f95cd68d74bf827849277ccd7245166950beb19f33297a00838ca21b896073878f2b509bedc6d6ae8295dbe1a059cf3ebcf40e7790e0530dcb66159a8c0e0fdde36f1b6374e42eb331b92bfa9061c6f480bb64e73c539eda7ef879730904d5843ea1c5616798adbe21d6c5fc4efebb60c45ccb30b7b1fbe673e754717ac71f5ca272dfffd2aca2eb8cb885c8a8395800f70c90271aba676239abb86c0708301bbf643028e55b9dfcbd338f2e22f5cee5c4d0fa163488a06fab8f15337dc219292f53325f98a4ce0f3f931b2961483d165a97e19d9d1408a156c7d35eab47fa5edf71dcf862e68a37787a1203c35383047398b3f305e1d4fe19d8dddbeb07990c507e8d80b6992c5c996c14b7cd31f65006585dd6bdc7fe43a893e96e06daecbcde583759f8138b3461341ec115ff29f1ed2eb72ff45d29e674dbc27165c9c2ba212455264936a9b8615ec5fd6cc26390dc45e1bfdb9815c8026ab9744af6eedfef8d2b2e73adcc50c52593ae3750dbc880c19dd627f215a49b044f87f866098c14e2716a055819ed0314ce687193cddc15773a220c1204b81dbf11087019ef723f0e14131f638cce5224bc1c73626a2811fec0becf91b6e39674c16c31407289222bb02eeca5ccb6a195c8c594d5ec984ac7fa1cc266f40dc4c6ca0724a94da0e1c8ac89ae52ab5c35ab2dfab88d9899336b19b099a71d0564f31ecfce6c582446a37e4acd62c62902afe83d01b977d61b31e4d03efeef17e381891c5e96a1043da0421eafacb98358ec2e98986762add3036aa1a1dd9f3235dd9a6f991e935d44337a265755aec34e819175e140b51079662ab5905073e588c785647444c4a3484c7f5643056b49e4fd0927cbfdab1b4c3101484c20a673b5322fafba8525d8c76f05e2cf522f1bd9955b86ebff690c02bbe96f73247396f50829f12ab26d21f082af26fb68cf7c4edd47602955a72eb29fe18a22131a8ec9b33936e816da6ecbc78b83e7656796dd756eb408a462df7830a67371d088b4e3aa15d4f56412cc1147338ca3fbd759ec61c2069d58ef9e84fd436eadaf2f8a955bf86c1d336830e9e8e8ae5374827cd801f0fd92dfe10043e8e1776c6ecd0cb7b9e0bfb6e326e8eb0224203575ec16007008dd284836dc7b4425fd39048d3cd2df1ef4fe18d6499abcd55d38d44c70852557ce09c3e3f45234cfa94f417600886b9b8a946a24ddeb19726c8b0a0b1a41be57b203c310f558daa000000050233c68da9d372a5a75790fd99589f6cb07f2c9cf97325a28c59bac5ec87e8eac10877a29091357b9b12611d2ad4b6ebb92f2a92cd0efd4a80eba5fec0eb6f95d1d9ddfe0b6e9eadb2420921ab517eba102bb8fa0402cf463d7b7d3122e161a5b18959390a8a38d08706f1ee4c2a7cdbbf95a642133e504791cb5516e1ccf2915cdc752a2a6cc023632112bf44115a1d97fce39359885b203307721151e4574c + +pk = 0000000100000005000000034cadc1a52afbdd1adb775d499fa9defb5f95bfa52fa746594f3311b8fb9c837b15412323da079146956b63e0a30c423c + diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp new file mode 100644 index 0000000000..57369ce635 --- /dev/null +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp @@ -0,0 +1,8 @@ +# LMS_SHA256_H5_W8 + +msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a + +sm = 000000000000000000000004c15445cdb0955e650d038fe369128bb41dec49c85cd58208337d27a63c4c4c613fa669e360606b31f1bcbcef9540a8babe0fb27755ca9e444cc7e3b2de51f4f63b9fad23b7a334003a45ce9919f223efa24d1e24ccd6b7d46f645834ae72cdd32484d1db569f8ed1b784ee2aaca9645e3fb7b0c68c1c8d22812b6903176e4475f307e0fad497f2134462d94f51c63e1e29defaad7bdaf03e49da1ea7086c064b3e536c01c4cc435d5be073cea199da5e6d1c3fd3a9f6d5b32f5ae2d974f07dfef21994f9e33999dfc0d3074aa8bf41c73d1b2f106ec5624badbb6521a3d21bb59fa5c28e8f02788975290248ad126ccec0639da4b0eb2e1a09be522dbadac2fdf2643c4cf2f905a55e7181542ce391f9ec6e3023fb3f015a52358be92385d6fb2c5ea84ed630622c872fcfcfab61e90b94b0307b31fab6df36c43c3d8907ff7842573d998b4e66f629d37681700c8f8d0c4da8ff8ab6e20348e817ba9e818de076ebd99d0b8ce672c12459b5955dd714b40a93210050bf54c8bbaf22840c2d007cd1f40a000cc55c745cfd3316205731818b93cfb51045369a4ee88cbce94b77544e64861d62dd10e711795d6fe3d4ad1517ead72967403c1a6a308bf834d224da53c2f89528c480bf294ca41e9018f129c0ba6316ea18fdd6e9d80e0593333c668432cf8a9505659fb63fe309b5ef348bef9e19fbecc33af91790b1c4531a85cad51af236ce5efdcbd77212fc0b642dcb91f7719e49a38ddd5afad688ed9ce5fb48d98f5e2c08f06d743d92b005e4d013e4474703f8c8f5b085f4f479896191f8fc9e9d6fd8b9c529ce2a7e8d1fcf614078366943deb263455843a31d16be42aa8551185315c705e90afaf25a06e93a7c7ea6696cf6f3cb496c674e3366e1fd6c1280a83900d5e62de9757e3383feb324728b32a496b97f6356f30ab160611ea04abc38b21cc7553901599ea4c590f9a4082e6341a9c323ea5dbf0f93180ef5bec182694c44e3360cc4ba3be21aed6958da7a6d8a75bbd84e24b40d88a2cd477e319933ad193b3072a987915edd7404e67d67759b31bfca09c6863e3230ff1e8731d1d8611bcdf31d5c5e272f674eff68b25933555feb2356b7639b7147961e3d8405e42f01bd6710bf64e896658d3532a78f67dd99d047060e107e084141ab06ba38124224861d6ff5e356bb43f90ca37b7b119ee2a06665b1c9f5d913853cc27f20b539727957ff17c07de0b9754d49f3ea1ea6da022112015e82a477e719aebb35e4c7e680dce407e3919832143ae3898ee14cf91ceb150341ebf5f767d2e1581c41751b8ddee365491e69d4c3c9ac548d60b8105b6b6afef80be691f1a766c59ad94ddee2ac824e26a3341b4409050486fbc94a1d95488446fd58595465204a0b7baeb3654c85ad124a6a42d6bb134e2bb9231a9f073afdfdb9fc6f114a99d08a685587475567cc68df54376fd13acab6b83b06628715e5ebc69938154c9e7c14c7cae80f78ccd41a8d07f2a65c09f5be027cd8fae674059b48d9d720250fc35160dfbcf520f89cce57af12415ea14996e85c6eaecef30319642839d4ce000000052c26f6dbb703f8711854e896635d51cec418c2c01df5fa5067c3a3ec08b30d042f4a08bb5dd156f17039c6eb9cbea8cdfbf46e64c6e345edc8aff2dcc7ad2ad911f2fca9853978b696cab99a0d633873e5f36f7e3faae37e24f8a27451604e9aca4a6d3549035e7a4e4527fead4920e658bd66d06509eda1841f843720016117ef0a66c52e26a12b719480cdb6055127a1601bb7110772341f1202e54ac90824 + +pk = 00000001000000050000000467bf07c0d0e24981d1b189ccad1efab150d6409b74d36699f982f537969d785c7bc406d1803ccca5905e8e9c0aca1113 + diff --git a/tests/example_sig_stfl.c b/tests/example_sig_stfl.c index b332d8479b..cbabee8b14 100644 --- a/tests/example_sig_stfl.c +++ b/tests/example_sig_stfl.c @@ -122,7 +122,7 @@ static OQS_STATUS stfl_example(char *method_name) { int main(void) { OQS_init(); - if (stfl_example("XMSS-SHA2_10_256") == OQS_SUCCESS && stfl_example("LMS_SHA256_H10_W4") == OQS_SUCCESS) { + if (stfl_example((char *)"XMSS-SHA2_10_256") == OQS_SUCCESS && stfl_example((char *)"LMS_SHA256_H10_W4") == OQS_SUCCESS) { OQS_destroy(); return EXIT_SUCCESS; } else { diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 55ba104d56..973a16692a 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -32,6 +32,12 @@ static pthread_mutex_t *sk_lock = NULL; #define OQS_TEST_CT_DECLASSIFY(addr, len) #endif +#ifdef __GNUC__ +#define UNUSED __attribute__((unused)) +#else +#define UNUSED +#endif + /* * For stateful signature, we skip key generation because it can takes hours to complete. * So the ReadHex and and FindMarker serve the purpose of reading pre-generate keypair from KATs. @@ -46,6 +52,7 @@ int FindMarker(FILE *infile, const char *marker) { unsigned long i, len; int curr_line; + memset(line, 0, MAX_MARKER_LEN); len = strlen(marker); if (len > MAX_MARKER_LEN - 1) { len = MAX_MARKER_LEN - 1; @@ -130,16 +137,16 @@ int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { return 1; } -static OQS_SIG_STFL_SECRET_KEY *lock_test_sk = NULL; -static OQS_SIG_STFL *lock_test_sig_obj = NULL; -static uint8_t *lock_test_public_key = NULL; -static char *lock_test_context = NULL; -static uint8_t *signature_1 = NULL; -static uint8_t *signature_2 = NULL; -static size_t signature_len_1; -static size_t signature_len_2; -static uint8_t message_1[] = "The quick brown fox ..."; -static uint8_t message_2[] = "The quick brown fox jumped from the tree."; +// static OQS_SIG_STFL_SECRET_KEY *lock_test_sk = NULL; +// static OQS_SIG_STFL *lock_test_sig_obj = NULL; +// static uint8_t *lock_test_public_key = NULL; +// static char *lock_test_context = NULL; +// static uint8_t *signature_1 = NULL; +// static uint8_t *signature_2 = NULL; +// static size_t signature_len_1; +// static size_t signature_len_2; +// static uint8_t message_1[] = "The quick brown fox ..."; +// static uint8_t message_2[] = "The quick brown fox jumped from the tree."; /* * Write stateful secret keys to disk. @@ -161,6 +168,18 @@ static OQS_STATUS save_secret_key(uint8_t *key_buf, size_t buf_len, void *contex } #if OQS_USE_PTHREADS_IN_TESTS + +static OQS_SIG_STFL_SECRET_KEY *lock_test_sk = NULL; +static OQS_SIG_STFL *lock_test_sig_obj = NULL; +static uint8_t *lock_test_public_key = NULL; +static char *lock_test_context = NULL; +static uint8_t *signature_1 = NULL; +static uint8_t *signature_2 = NULL; +static size_t signature_len_1; +static size_t signature_len_2; +static uint8_t message_1[] = "The quick brown fox ..."; +static uint8_t message_2[] = "The quick brown fox jumped from the tree."; + static OQS_STATUS lock_sk_key(void *mutex) { if (mutex == NULL) { return OQS_ERROR; @@ -183,11 +202,13 @@ static OQS_STATUS unlock_sk_key(void *mutex) { return OQS_SUCCESS; } #else -static OQS_STATUS lock_sk_key(void *mutex) { +static OQS_STATUS lock_sk_key(UNUSED void *mutex) { + // void(*mutex); return OQS_SUCCESS; } -static OQS_STATUS unlock_sk_key(void *mutex) { +static OQS_STATUS unlock_sk_key(UNUSED void *mutex) { + // void(mutex); return OQS_SUCCESS; } #endif @@ -213,12 +234,12 @@ OQS_STATUS sig_stfl_keypair_from_KATs(OQS_SIG_STFL *sig, uint8_t *public_key, OQ } // Grab the pk and sk from KAT file - if (!ReadHex(fp_rsp, public_key, sig->length_public_key, "pk = ")) { + if (!ReadHex(fp_rsp, public_key, sig->length_public_key, (char *)"pk = ")) { fprintf(stderr, "ERROR: unable to read 'pk' from <%s>\n", katfile); goto err; } - if (!ReadHex(fp_rsp, secret_key->secret_key_data, sig->length_secret_key, "sk = ")) { + if (!ReadHex(fp_rsp, secret_key->secret_key_data, sig->length_secret_key, (char *)"sk = ")) { fprintf(stderr, "ERROR: unable to read 'sk' from <%s>\n", katfile); goto err; } @@ -410,7 +431,7 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char file_store = convert_method_name_to_file_name(sig->method_name); if (file_store == NULL) { - fprintf(stderr, "%s: file_store is null\n", __FUNCTION__); + fprintf(stderr, "%s: file_store is null\n", __func__); goto err; } @@ -683,6 +704,23 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name, const char * return rc; } +#ifdef OQS_ENABLE_TEST_CONSTANT_TIME +static void TEST_SIG_STFL_randombytes(uint8_t *random_array, size_t bytes_to_read) { + // We can't make direct calls to the system randombytes on some platforms, + // so we have to swap out the OQS_randombytes provider. + + OQS_randombytes_switch_algorithm("system"); + OQS_randombytes(random_array, bytes_to_read); + OQS_randombytes_custom_algorithm(&TEST_SIG_STFL_randombytes); + + // OQS_TEST_CT_CLASSIFY tells Valgrind's memcheck tool to issue a warning if + // the program branches on any byte that depends on random_array. This helps us + // identify timing side-channels, as these bytes often contain secret data. + OQS_TEST_CT_CLASSIFY(random_array, bytes_to_read); +} +#endif + +#if OQS_USE_PTHREADS_IN_TESTS static OQS_STATUS sig_stfl_test_query_key(const char *method_name) { OQS_STATUS rc = OQS_SUCCESS; size_t message_len_1 = sizeof(message_1); @@ -883,9 +921,9 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name, const c OQS_SIG_STFL_SECRET_KEY_SET_lock(lock_test_sk, lock_sk_key); OQS_SIG_STFL_SECRET_KEY_SET_unlock(lock_test_sk, unlock_sk_key); -#if OQS_USE_PTHREADS_IN_TESTS +//#if OQS_USE_PTHREADS_IN_TESTS OQS_SIG_STFL_SECRET_KEY_SET_mutex(lock_test_sk, test_sk_lock); -#endif +//#endif printf("================================================================================\n"); printf("Generate keypair %s\n", method_name); @@ -915,23 +953,7 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name, const c return OQS_ERROR; } -#ifdef OQS_ENABLE_TEST_CONSTANT_TIME -static void TEST_SIG_STFL_randombytes(uint8_t *random_array, size_t bytes_to_read) { - // We can't make direct calls to the system randombytes on some platforms, - // so we have to swap out the OQS_randombytes provider. - - OQS_randombytes_switch_algorithm("system"); - OQS_randombytes(random_array, bytes_to_read); - OQS_randombytes_custom_algorithm(&TEST_SIG_STFL_randombytes); - // OQS_TEST_CT_CLASSIFY tells Valgrind's memcheck tool to issue a warning if - // the program branches on any byte that depends on random_array. This helps us - // identify timing side-channels, as these bytes often contain secret data. - OQS_TEST_CT_CLASSIFY(random_array, bytes_to_read); -} -#endif - -#if OQS_USE_PTHREADS_IN_TESTS typedef struct thread_data { const char *alg_name; const char *katfile; @@ -947,25 +969,25 @@ typedef struct lock_test_data { void *test_query_key(void *arg) { struct lock_test_data *td = arg; - printf("\n%s: Start Query Stateful Key info\n", __FUNCTION__); + printf("\n%s: Start Query Stateful Key info\n", __func__); td->rc = sig_stfl_test_query_key(td->alg_name); - printf("%s: End Query Stateful Key info\n\n", __FUNCTION__); + printf("%s: End Query Stateful Key info\n\n", __func__); return NULL; } void *test_sig_gen(void *arg) { struct lock_test_data *td = arg; - printf("\n%s: Start Generate Stateful Signature\n", __FUNCTION__); + printf("\n%s: Start Generate Stateful Signature\n", __func__); td->rc = sig_stfl_test_sig_gen(td->alg_name); - printf("%s: End Generate Stateful Signature\n\n", __FUNCTION__); + printf("%s: End Generate Stateful Signature\n\n", __func__); return NULL; } void *test_create_keys(void *arg) { struct lock_test_data *td = arg; - printf("\n%s: Start Generate Keys\n", __FUNCTION__); + printf("\n%s: Start Generate Keys\n", __func__); td->rc = sig_stfl_test_secret_key_lock(td->alg_name, td->katfile); - printf("%s: End Generate Stateful Keys\n\n", __FUNCTION__); + printf("%s: End Generate Stateful Keys\n\n", __func__); return NULL; } @@ -1086,10 +1108,6 @@ int main(int argc, char **argv) { if (sk_lock) { pthread_mutex_destroy(sk_lock); } -#else - rc = sig_stfl_test_correctness(alg_name, katfile); - rc1 = sig_stfl_test_secret_key(alg_name, katfile); -#endif OQS_SIG_STFL_SECRET_KEY_free(lock_test_sk); OQS_MEM_insecure_free(lock_test_public_key); @@ -1097,11 +1115,24 @@ int main(int argc, char **argv) { OQS_MEM_insecure_free(lock_test_context); OQS_MEM_insecure_free(signature_1); OQS_MEM_insecure_free(signature_2); - - OQS_destroy(); if (rc != OQS_SUCCESS || rc1 != OQS_SUCCESS || rc_create != OQS_SUCCESS || rc_sign != OQS_SUCCESS || rc_query != OQS_SUCCESS) { return EXIT_FAILURE; } return exit_status; +#else + rc = sig_stfl_test_correctness(alg_name, katfile); + rc1 = sig_stfl_test_secret_key(alg_name, katfile); +// OQS_MEM_insecure_free(signature_1); +// signature_1 = NULL; +// OQS_MEM_insecure_free(signature_2); +// signature_2 = NULL; + + OQS_destroy(); + + if (rc != OQS_SUCCESS || rc1 != OQS_SUCCESS) { + return EXIT_FAILURE; + } + return exit_status; +#endif } From ddae6444b424343e7623b010d3dc304adc101ce6 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Wed, 20 Dec 2023 01:22:18 -0500 Subject: [PATCH 24/68] Various fixes --- .CMake/alg_support.cmake | 12 + src/common/sha2/sha2_armv8.c | 2 +- src/oqsconfig.h.cmake | 2 - src/sig_stfl/lms/external/hss_alloc.c | 2 +- src/sig_stfl/lms/external/hss_sign.c | 6 +- src/sig_stfl/lms/external/hss_verify_inc.c | 2 +- src/sig_stfl/lms/sig_stfl_lms_functions.c | 4 +- src/sig_stfl/sig_stfl.c | 416 ++++++++++++++++++++- src/sig_stfl/sig_stfl.h | 8 - tests/test_sig_stfl.c | 19 - 10 files changed, 430 insertions(+), 43 deletions(-) diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index 119ee52f3f..d1f9e8daae 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -551,6 +551,18 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h25_w4 "" ON "OQS_ENABLE_S cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h25_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2_h10_w2 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h10_w4 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h10_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h10_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h15_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h5_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h10_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h15_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h20_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) + if((OQS_MINIMAL_BUILD STREQUAL "ON")) message(FATAL_ERROR "OQS_MINIMAL_BUILD option ${OQS_MINIMAL_BUILD} no longer supported") diff --git a/src/common/sha2/sha2_armv8.c b/src/common/sha2/sha2_armv8.c index 9f5a96bd97..b8f6b16cb3 100644 --- a/src/common/sha2/sha2_armv8.c +++ b/src/common/sha2/sha2_armv8.c @@ -291,7 +291,7 @@ void oqs_sha2_sha256_inc_armv8(sha256ctx *state, const uint8_t *in, size_t len) } for (size_t i = 0; i < incr; ++i, state->data_len++, in_index++) { - state->data[state->data_len] = in[in_index++]; + state->data[state->data_len] = in[in_index]; } if (state->data_len < 64) { diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index 9fce48b769..7fdfd7bdb9 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -233,7 +233,5 @@ #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w1 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w2 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w4 1 -#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8 1 -#cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h20_w1 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 1 diff --git a/src/sig_stfl/lms/external/hss_alloc.c b/src/sig_stfl/lms/external/hss_alloc.c index 3907d8764b..9e6e7694c1 100644 --- a/src/sig_stfl/lms/external/hss_alloc.c +++ b/src/sig_stfl/lms/external/hss_alloc.c @@ -361,7 +361,7 @@ signed long initial_mem_target = mem_target; /* DEBUG HACK */ /* This is a signed type so that the comparison works as */ /* expected if mem_target is negative */ size_t stack_used; - unsigned long mem = compute_level_memory_usage(i, j, + unsigned long mem = (unsigned long)compute_level_memory_usage(i, j, level_height[i], hash_size[i], &subtree_levels[i], &stack_used ); /* # of sublevels this would have */ diff --git a/src/sig_stfl/lms/external/hss_sign.c b/src/sig_stfl/lms/external/hss_sign.c index 3ce7159fbf..9b452e7a83 100644 --- a/src/sig_stfl/lms/external/hss_sign.c +++ b/src/sig_stfl/lms/external/hss_sign.c @@ -197,7 +197,7 @@ static int generate_merkle_signature( hss_seed_derive_done(&derive); if (!success) return 0; } - signature += ots_sig_size; signature_len -= ots_sig_size; + signature += ots_sig_size; signature_len -= (unsigned)ots_sig_size; /* Write the LM parameter set */ if (signature_len < 4) return 0; @@ -253,7 +253,7 @@ bool hss_create_signed_public_key(unsigned char *signed_key, unsigned len_public_key = 8 + I_LEN + hash_size; /* Now, generate the signature */ - if (!(unsigned int)generate_merkle_signature( signed_key, len_signature, + if ((int)0 == generate_merkle_signature( signed_key, len_signature, parent, w, public_key, len_public_key)) { return false; } @@ -303,7 +303,7 @@ static void do_gen_sig( const void *detail, struct thread_collection *col) { const unsigned char *message = d->message; size_t message_len = d->message_len; - if (!(unsigned int)generate_merkle_signature(signature, signature_len, + if ((int)0 == generate_merkle_signature(signature, signature_len, w->tree[ levels-1 ], w, message, message_len)) { goto failed; } diff --git a/src/sig_stfl/lms/external/hss_verify_inc.c b/src/sig_stfl/lms/external/hss_verify_inc.c index bb8da66db1..4b5cf7e7a1 100644 --- a/src/sig_stfl/lms/external/hss_verify_inc.c +++ b/src/sig_stfl/lms/external/hss_verify_inc.c @@ -83,7 +83,7 @@ bool hss_validate_signature_init( /* to validate) */ if (signature_len < 4) goto failed; lm_type = (param_set_t)get_bigendian( signature, 4 ); - unsigned l_pubkeylen = lm_get_public_key_len(lm_type); + unsigned l_pubkeylen = (unsigned)lm_get_public_key_len(lm_type); if (l_pubkeylen == 0 || l_pubkeylen > signature_len) goto failed; const unsigned char *l_pubkey = signature; signature += l_pubkeylen; signature_len -= l_pubkeylen; diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index b05910d089..be709fc71c 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -707,8 +707,8 @@ OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_ oqs_lms_key_data *lms_key_data = NULL; uint8_t *lms_sk = NULL; uint8_t *lms_aux = NULL; - int aux_buf_len = 0; - uint8_t lms_sk_len = hss_get_private_key_len((unsigned )(1), NULL, NULL); + size_t aux_buf_len = 0; + size_t lms_sk_len = hss_get_private_key_len((unsigned )(1), NULL, NULL); if (sk == NULL || sk_buf == NULL || (sk_len == 0) || (sk_len < lms_sk_len )) { return OQS_ERROR; diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index dafbcd8aa5..6b63f8a73e 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -11,6 +11,14 @@ #include +#ifdef OQS_ENABLE_SIG_STFL_XMSS +#include +#endif // OQS_ENABLE_SIG_STFL_XMSS + +#ifdef OQS_ENABLE_SIG_STFL_LMS +#include +#endif // OQS_ENABLE_SIG_STFL_LMS + OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i) { const char *a[OQS_SIG_STFL_algs_length] = { @@ -273,83 +281,215 @@ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name) { return 0; #endif } -#ifdef OQS_ENABLE_SIG_STFL_LMS +//#ifdef OQS_ENABLE_SIG_STFL_LMS else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w2 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w4 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w1 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w1 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w2 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w4 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w1 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w2 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w4 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w1 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w2 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w4 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w8 return 1; +#else + return 0; +#endif } //2-Level LMS else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h5_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2_h10_w2 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h10_w4 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h10_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h5_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h10_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h15_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h5_w8 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 return 1; +#else + return 0; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 return 1; +#else + return 0; +#endif } -#endif //OQS_ENABLE_SIG_STFL_LMS +//#endif //OQS_ENABLE_SIG_STFL_LMS else { return 0; } @@ -529,77 +669,209 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { return NULL; #endif } -#ifdef OQS_ENABLE_SIG_STFL_LMS +//#ifdef OQS_ENABLE_SIG_STFL_LMS else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 return OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w2 return OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w4 return OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8 return OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w1 return OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2 return OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4 return OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8 return OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w1 return OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w2 return OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w4 return OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8 return OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w1 return OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w2 return OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w4 return OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8 return OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h28_w1 return OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h28_w2 return OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w4 return OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w8 return OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(); +#else + return NULL; +#endif } //2-Level LMS else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 return OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 return OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h5_w8 return OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2_h10_w2 return OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h10_w4 return OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h10_w8 return OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h5_w8 return OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h10_w8 return OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h15_w8 return OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h5_w8 return OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h10_w8 return OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h15_w8 return OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h20_w8 return OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_new(); +#else + return NULL; +#endif } -#endif //OQS_ENABLE_SIG_STFL_LMS +//#endif //OQS_ENABLE_SIG_STFL_LMS else { return NULL; } @@ -827,77 +1099,209 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_ return NULL; #endif } -#ifdef OQS_ENABLE_SIG_STFL_LMS +//#ifdef OQS_ENABLE_SIG_STFL_LMS else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 return OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w2 return OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w4 return OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8 return OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w1 return OQS_SECRET_KEY_LMS_SHA256_H10_W1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2 return OQS_SECRET_KEY_LMS_SHA256_H10_W2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4 return OQS_SECRET_KEY_LMS_SHA256_H10_W4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8 return OQS_SECRET_KEY_LMS_SHA256_H10_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w1 return OQS_SECRET_KEY_LMS_SHA256_H15_W1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w2 return OQS_SECRET_KEY_LMS_SHA256_H15_W2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w4 return OQS_SECRET_KEY_LMS_SHA256_H15_W4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8 return OQS_SECRET_KEY_LMS_SHA256_H15_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w1 return OQS_SECRET_KEY_LMS_SHA256_H20_W1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w2 return OQS_SECRET_KEY_LMS_SHA256_H20_W2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w4 return OQS_SECRET_KEY_LMS_SHA256_H20_W4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8 return OQS_SECRET_KEY_LMS_SHA256_H20_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w1)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w1 return OQS_SECRET_KEY_LMS_SHA256_H25_W1_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w2 return OQS_SECRET_KEY_LMS_SHA256_H25_W2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w4 return OQS_SECRET_KEY_LMS_SHA256_H25_W4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h25_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h25_w4 return OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(); +#else + return NULL; +#endif } //2-Level LMS else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 return OQS_SECRET_KEY_LMS_SHA256_H5_W8_H5_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h5_w8 return OQS_SECRET_KEY_LMS_SHA256_H10_W8_H5_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w2_h10_w2 return OQS_SECRET_KEY_LMS_SHA256_H10_W2_H10_W2_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h10_w4 return OQS_SECRET_KEY_LMS_SHA256_H10_W4_H10_W4_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 return OQS_SECRET_KEY_LMS_SHA256_H10_W4_H5_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h10_w8 return OQS_SECRET_KEY_LMS_SHA256_H10_W8_H10_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h5_w8 return OQS_SECRET_KEY_LMS_SHA256_H15_W8_H5_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h10_w8_h10_w8 return OQS_SECRET_KEY_LMS_SHA256_H15_W8_H10_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h15_w8_h15_w8 return OQS_SECRET_KEY_LMS_SHA256_H15_W8_H15_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h5_w8 return OQS_SECRET_KEY_LMS_SHA256_H20_W8_H5_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h10_w8 return OQS_SECRET_KEY_LMS_SHA256_H20_W8_H10_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h15_w8 return OQS_SECRET_KEY_LMS_SHA256_H20_W8_H15_W8_new(); +#else + return NULL; +#endif } else if (0 == strcasecmp(method_name, OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8)) { +#ifdef OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h20_w8 return OQS_SECRET_KEY_LMS_SHA256_H20_W8_H20_W8_new(); +#else + return NULL; +#endif } -#endif //OQS_ENABLE_SIG_STFL_LMS +//#endif //OQS_ENABLE_SIG_STFL_LMS else { return NULL; } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index aa83e4c486..70797ee80a 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -575,12 +575,4 @@ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY * } // extern "C" #endif -#ifdef OQS_ENABLE_SIG_STFL_XMSS -#include -#endif // OQS_ENABLE_SIG_STFL_XMSS - -#ifdef OQS_ENABLE_SIG_STFL_LMS -#include -#endif // OQS_ENABLE_SIG_STFL_LMS - #endif /* OQS_SIG_STATEFUL_H */ diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 973a16692a..a3d4bfd3f5 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -137,17 +137,6 @@ int ReadHex(FILE *infile, unsigned char *a, unsigned long Length, char *str) { return 1; } -// static OQS_SIG_STFL_SECRET_KEY *lock_test_sk = NULL; -// static OQS_SIG_STFL *lock_test_sig_obj = NULL; -// static uint8_t *lock_test_public_key = NULL; -// static char *lock_test_context = NULL; -// static uint8_t *signature_1 = NULL; -// static uint8_t *signature_2 = NULL; -// static size_t signature_len_1; -// static size_t signature_len_2; -// static uint8_t message_1[] = "The quick brown fox ..."; -// static uint8_t message_2[] = "The quick brown fox jumped from the tree."; - /* * Write stateful secret keys to disk. */ @@ -203,12 +192,10 @@ static OQS_STATUS unlock_sk_key(void *mutex) { } #else static OQS_STATUS lock_sk_key(UNUSED void *mutex) { - // void(*mutex); return OQS_SUCCESS; } static OQS_STATUS unlock_sk_key(UNUSED void *mutex) { - // void(mutex); return OQS_SUCCESS; } #endif @@ -921,9 +908,7 @@ static OQS_STATUS sig_stfl_test_secret_key_lock(const char *method_name, const c OQS_SIG_STFL_SECRET_KEY_SET_lock(lock_test_sk, lock_sk_key); OQS_SIG_STFL_SECRET_KEY_SET_unlock(lock_test_sk, unlock_sk_key); -//#if OQS_USE_PTHREADS_IN_TESTS OQS_SIG_STFL_SECRET_KEY_SET_mutex(lock_test_sk, test_sk_lock); -//#endif printf("================================================================================\n"); printf("Generate keypair %s\n", method_name); @@ -1123,10 +1108,6 @@ int main(int argc, char **argv) { #else rc = sig_stfl_test_correctness(alg_name, katfile); rc1 = sig_stfl_test_secret_key(alg_name, katfile); -// OQS_MEM_insecure_free(signature_1); -// signature_1 = NULL; -// OQS_MEM_insecure_free(signature_2); -// signature_2 = NULL; OQS_destroy(); From cc50ef00d14eef43e51c1b83ef32637a1f42f7af Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Thu, 21 Dec 2023 00:28:13 -0500 Subject: [PATCH 25/68] Fix warning --- src/sig_stfl/lms/external/hss_sign.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/sig_stfl/lms/external/hss_sign.c b/src/sig_stfl/lms/external/hss_sign.c index 9b452e7a83..cbcbdf845b 100644 --- a/src/sig_stfl/lms/external/hss_sign.c +++ b/src/sig_stfl/lms/external/hss_sign.c @@ -253,7 +253,7 @@ bool hss_create_signed_public_key(unsigned char *signed_key, unsigned len_public_key = 8 + I_LEN + hash_size; /* Now, generate the signature */ - if ((int)0 == generate_merkle_signature( signed_key, len_signature, + if (!generate_merkle_signature( signed_key, (unsigned)len_signature, parent, w, public_key, len_public_key)) { return false; } @@ -303,7 +303,7 @@ static void do_gen_sig( const void *detail, struct thread_collection *col) { const unsigned char *message = d->message; size_t message_len = d->message_len; - if ((int)0 == generate_merkle_signature(signature, signature_len, + if (!generate_merkle_signature(signature, (unsigned)signature_len, w->tree[ levels-1 ], w, message, message_len)) { goto failed; } From 9610576db49c8ebb1c21a8a4bcde942d0ade53f9 Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Tue, 2 Jan 2024 16:17:08 -0500 Subject: [PATCH 26/68] Fix windows-x86 and arm compiling error. (#1634) * Fix windows-x86 and arm compiling error. --------- Co-authored-by: Norman Ashley --- CMakeLists.txt | 2 +- README.md | 2 +- .../copy_from_upstream/copy_from_upstream.py | 2 +- src/common/sha2/sha2_armv8.c | 110 +++++++++--------- src/oqsconfig.h.cmake | 2 + src/sig_stfl/lms/sig_stfl_lms.h | 4 +- src/sig_stfl/sig_stfl.h | 14 +-- src/sig_stfl/xmss/external/xmss_commons.c | 14 ++- src/sig_stfl/xmss/external/xmss_core_fast.c | 69 ++++++----- tests/helpers.py | 3 +- tests/test_sig_stfl.c | 17 ++- 11 files changed, 132 insertions(+), 107 deletions(-) diff --git a/CMakeLists.txt b/CMakeLists.txt index 16b09a6400..5881ea3f73 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -196,13 +196,13 @@ endif() if(OQS_ENABLE_SIG_SPHINCS) set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/sphincs/sig_sphincs.h) endif() +##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_INCLUDE_HEADERS_END if(OQS_ENABLE_SIG_STFL_XMSS) set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig_stfl/xmss/sig_stfl_xmss.h) endif() if(OQS_ENABLE_SIG_STFL_LMS) set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig_stfl/lms/sig_stfl_lms.h) endif() -##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_INCLUDE_HEADERS_END execute_process(COMMAND ${CMAKE_COMMAND} -E make_directory ${PROJECT_BINARY_DIR}/include/oqs) execute_process(COMMAND ${CMAKE_COMMAND} -E copy ${PUBLIC_HEADERS} ${PROJECT_BINARY_DIR}/include/oqs) execute_process(COMMAND ${CMAKE_COMMAND} -E copy ${INTERNAL_HEADERS} ${PROJECT_BINARY_DIR}/include/oqs) diff --git a/README.md b/README.md index f91e39dea0..926a8ce28a 100644 --- a/README.md +++ b/README.md @@ -68,9 +68,9 @@ All names other than `ML-KEM` and `ML-DSA` are subject to change. `liboqs` makes - **ML-DSA**: ML-DSA-44-ipd (alias: ML-DSA-44), ML-DSA-65-ipd (alias: ML-DSA-65), ML-DSA-87-ipd (alias: ML-DSA-87) - **SPHINCS+-SHA2**: SPHINCS+-SHA2-128f-simple, SPHINCS+-SHA2-128s-simple, SPHINCS+-SHA2-192f-simple, SPHINCS+-SHA2-192s-simple, SPHINCS+-SHA2-256f-simple, SPHINCS+-SHA2-256s-simple - **SPHINCS+-SHAKE**: SPHINCS+-SHAKE-128f-simple, SPHINCS+-SHAKE-128s-simple, SPHINCS+-SHAKE-192f-simple, SPHINCS+-SHAKE-192s-simple, SPHINCS+-SHAKE-256f-simple, SPHINCS+-SHAKE-256s-simple + - **XMSS**: XMSS-SHA2_10_256, XMSS-SHA2_16_256, XMSS-SHA2_20_256, XMSS-SHAKE_10_256, XMSS-SHAKE_16_256, XMSS-SHAKE_20_256, XMSS-SHA2_10_512, XMSS-SHA2_16_512, XMSS-SHA2_20_512, XMSS-SHAKE_10_512, XMSS-SHAKE_16_512, XMSS-SHAKE_20_512, XMSSMT-SHA2_20/2_256, XMSSMT-SHA2_20/4_256, XMSSMT-SHA2_40/2_256, XMSSMT-SHA2_40/4_256, XMSSMT-SHA2_40/8_256, XMSSMT-SHA2_60/3_256, XMSSMT-SHA2_60/6_256, XMSSMT-SHA2_60/12_256, XMSSMT-SHAKE_20/2_256, XMSSMT-SHAKE_20/4_256, XMSSMT-SHAKE_40/2_256, XMSSMT-SHAKE_40/4_256, XMSSMT-SHAKE_40/8_256, XMSSMT-SHAKE_60/3_256, XMSSMT-SHAKE_60/6_256, XMSSMT-SHAKE_60/12_256 - **LMS**: LMS_SHA256_H5_W1, LMS_SHA256_H5_W2, LMS_SHA256_H5_W4, LMS_SHA256_H5_W8, LMS_SHA256_H10_W1, LMS_SHA256_H10_W2, LMS_SHA256_H10_W4, LMS_SHA256_H10_W8, LMS_SHA256_H15_W1, LMS_SHA256_H15_W2, LMS_SHA256_H15_W4, LMS_SHA256_H15_W8, LMS_SHA256_H20_W1, LMS_SHA256_H20_W2, LMS_SHA256_H20_W4, LMS_SHA256_H20_W8, LMS_SHA256_H25_W1, LMS_SHA256_H25_W2, LMS_SHA256_H25_W4, LMS_SHA256_H25_W8, LMS_SHA256_H5_W8_H5_W8, LMS_SHA256_H10_W4_H5_W8, LMS_SHA256_H10_W8_H5_W8, LMS_SHA256_H10_W2_H10_W2, LMS_SHA256_H10_W4_H10_W4, LMS_SHA256_H10_W8_H10_W8, LMS_SHA256_H15_W8_H5_W8, LMS_SHA256_H15_W8_H10_W8, LMS_SHA256_H15_W8_H15_W8, LMS_SHA256_H20_W8_H5_W8, LMS_SHA256_H20_W8_H10_W8, LMS_SHA256_H20_W8_H15_W8, LMS_SHA256_H20_W8_H20_W8 - Note that for algorithms marked with a dagger (†), liboqs contains at least one implementation that uses a large amount of stack space; this may cause failures when run in threads or in constrained environments. For more information, consult the algorithm information sheets in the [docs/algorithms](https://github.com/open-quantum-safe/liboqs/tree/main/docs/algorithms) folder. diff --git a/scripts/copy_from_upstream/copy_from_upstream.py b/scripts/copy_from_upstream/copy_from_upstream.py index 0db38f54bf..9c4f8f2232 100755 --- a/scripts/copy_from_upstream/copy_from_upstream.py +++ b/scripts/copy_from_upstream/copy_from_upstream.py @@ -642,7 +642,7 @@ def verify_from_upstream(): '{}_{}_{}'.format(impl['upstream']['name'], scheme['pqclean_scheme'], impl)) verifydir = os.path.join(basedir, 'src', family['type'], family['name'], '{}_{}_{}'.format(impl['upstream']['name'], scheme['pqclean_scheme'], impl)) - if not os.path.isdir(oqsdir) and os.path.isdir(erifydir): + if not os.path.isdir(oqsdir) and os.path.isdir(verifydir): print('Available implementation in upstream that isn\'t integrated into LIBOQS: {}_{}_{}'.format(impl['upstream']['name'], scheme['pqclean_scheme'], impl)) else: diff --git a/src/common/sha2/sha2_armv8.c b/src/common/sha2/sha2_armv8.c index b8f6b16cb3..dc8661485b 100644 --- a/src/common/sha2/sha2_armv8.c +++ b/src/common/sha2/sha2_armv8.c @@ -15,7 +15,6 @@ * from http://bench.cr.yp.to/supercop.html * by D. J. Bernstein */ - static uint64_t load_bigendian_64(const uint8_t *x) { return (uint64_t)(x[7]) | (((uint64_t)(x[6])) << 8) | (((uint64_t)(x[5])) << 16) | (((uint64_t)(x[4])) << 24) | @@ -24,21 +23,21 @@ static uint64_t load_bigendian_64(const uint8_t *x) { } static void store_bigendian_64(uint8_t *x, uint64_t u) { - x[7] = (uint8_t) u; + x[7] = (uint8_t)u; u >>= 8; - x[6] = (uint8_t) u; + x[6] = (uint8_t)u; u >>= 8; - x[5] = (uint8_t) u; + x[5] = (uint8_t)u; u >>= 8; - x[4] = (uint8_t) u; + x[4] = (uint8_t)u; u >>= 8; - x[3] = (uint8_t) u; + x[3] = (uint8_t)u; u >>= 8; - x[2] = (uint8_t) u; + x[2] = (uint8_t)u; u >>= 8; - x[1] = (uint8_t) u; + x[1] = (uint8_t)u; u >>= 8; - x[0] = (uint8_t) u; + x[0] = (uint8_t)u; } static size_t crypto_hashblocks_sha256_armv8(uint8_t *statebytes, @@ -63,9 +62,9 @@ static size_t crypto_hashblocks_sha256_armv8(uint8_t *statebytes, }; unsigned long long pos = 0; /* load constants */ - uint32x4_t c0 = vld1q_u32(s256cst + 0); - uint32x4_t c1 = vld1q_u32(s256cst + 4); - uint32x4_t c2 = vld1q_u32(s256cst + 8); + uint32x4_t c0 = vld1q_u32(s256cst + 0); + uint32x4_t c1 = vld1q_u32(s256cst + 4); + uint32x4_t c2 = vld1q_u32(s256cst + 8); uint32x4_t c3 = vld1q_u32(s256cst + 12); uint32x4_t c4 = vld1q_u32(s256cst + 16); uint32x4_t c5 = vld1q_u32(s256cst + 20); @@ -80,13 +79,13 @@ static size_t crypto_hashblocks_sha256_armv8(uint8_t *statebytes, uint32x4_t ce = vld1q_u32(s256cst + 56); uint32x4_t cf = vld1q_u32(s256cst + 60); /* load state */ - uint32x4_t d0 = vld1q_u32((uint32_t *)(statebytes + 0)); + uint32x4_t d0 = vld1q_u32((uint32_t *)(statebytes + 0)); uint32x4_t d1 = vld1q_u32((uint32_t *)(statebytes + 16)); uint32x4_t s0, s1, h0, h1; /* make state big-endian */ d0 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(d0))); d1 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(d1))); - while (length >= 64) { + while (length >= 64) { /* load one block */ uint32x4_t i0 = vld1q_u32((const uint32_t *)(data + pos + 0)); uint32x4_t i1 = vld1q_u32((const uint32_t *)(data + pos + 16)); @@ -110,33 +109,33 @@ static size_t crypto_hashblocks_sha256_armv8(uint8_t *statebytes, * using 16 constants in c0..c3 * we need h0,h1,x0,x1 as scratch */ -#define DO16ROUNDS(i0, i1, i2, i3, c0, c1, c2, c3) \ - h0 = vaddq_u32(i0, c0); \ - x0 = vsha256hq_u32(s0, s1, h0); \ - x1 = vsha256h2q_u32(s1, s0, h0); \ - h1 = vaddq_u32(i1, c1); \ - s0 = vsha256hq_u32(x0, x1, h1); \ - s1 = vsha256h2q_u32(x1, x0, h1); \ - h0 = vaddq_u32(i2, c2); \ - x0 = vsha256hq_u32(s0, s1, h0); \ - x1 = vsha256h2q_u32(s1, s0, h0); \ - h1 = vaddq_u32(i3, c3); \ - s0 = vsha256hq_u32(x0, x1, h1); \ - s1 = vsha256h2q_u32(x1, x0, h1) +#define DO16ROUNDS(i0, i1, i2, i3, c0, c1, c2, c3) \ + h0 = vaddq_u32(i0, c0); \ + x0 = vsha256hq_u32(s0, s1, h0); \ + x1 = vsha256h2q_u32(s1, s0, h0); \ + h1 = vaddq_u32(i1, c1); \ + s0 = vsha256hq_u32(x0, x1, h1); \ + s1 = vsha256h2q_u32(x1, x0, h1); \ + h0 = vaddq_u32(i2, c2); \ + x0 = vsha256hq_u32(s0, s1, h0); \ + x1 = vsha256h2q_u32(s1, s0, h0); \ + h1 = vaddq_u32(i3, c3); \ + s0 = vsha256hq_u32(x0, x1, h1); \ + s1 = vsha256h2q_u32(x1, x0, h1) /* * this expands the block (or previously * expanded) in i0..i3 to j0..j3 */ #define DO16EXPANDS(i0, i1, i2, i3, j0, j1, j2, j3) \ - j0 = vsha256su0q_u32(i0, i1); \ - j0 = vsha256su1q_u32(j0, i2, i3); \ - j1 = vsha256su0q_u32(i1, i2); \ - j1 = vsha256su1q_u32(j1, i3, j0); \ - j2 = vsha256su0q_u32(i2, i3); \ - j2 = vsha256su1q_u32(j2, j0, j1); \ - j3 = vsha256su0q_u32(i3, j0); \ - j3 = vsha256su1q_u32(j3, j1, j2) + j0 = vsha256su0q_u32(i0, i1); \ + j0 = vsha256su1q_u32(j0, i2, i3); \ + j1 = vsha256su0q_u32(i1, i2); \ + j1 = vsha256su1q_u32(j1, i3, j0); \ + j2 = vsha256su0q_u32(i2, i3); \ + j2 = vsha256su1q_u32(j2, j0, j1); \ + j3 = vsha256su0q_u32(i3, j0); \ + j3 = vsha256su1q_u32(j3, j1, j2) DO16ROUNDS(i0, i1, i2, i3, c0, c1, c2, c3); @@ -163,11 +162,10 @@ static size_t crypto_hashblocks_sha256_armv8(uint8_t *statebytes, /* store back to little-endian */ d0 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(d0))); d1 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(d1))); - vst1q_u32((uint32_t *)(statebytes + 0), d0); + vst1q_u32((uint32_t *)(statebytes + 0), d0); vst1q_u32((uint32_t *)(statebytes + 16), d1); return length; - } void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const uint8_t *in, size_t inlen) { @@ -180,7 +178,8 @@ void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const ui if (new_inlen == inlen) { new_in = in; - } else { //Combine incremental data with final input + } else { + // Combine incremental data with final input tmp_in = malloc(tmp_len); if (tmp_in == NULL) { exit(111); @@ -201,7 +200,6 @@ void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const ui new_inlen &= 63; new_in -= new_inlen; - for (size_t i = 0; i < new_inlen; ++i) { padded[i] = new_in[i]; } @@ -211,27 +209,27 @@ void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const ui for (size_t i = new_inlen + 1; i < 56; ++i) { padded[i] = 0; } - padded[56] = (uint8_t) (bytes >> 53); - padded[57] = (uint8_t) (bytes >> 45); - padded[58] = (uint8_t) (bytes >> 37); - padded[59] = (uint8_t) (bytes >> 29); - padded[60] = (uint8_t) (bytes >> 21); - padded[61] = (uint8_t) (bytes >> 13); - padded[62] = (uint8_t) (bytes >> 5); - padded[63] = (uint8_t) (bytes << 3); + padded[56] = (uint8_t)(bytes >> 53); + padded[57] = (uint8_t)(bytes >> 45); + padded[58] = (uint8_t)(bytes >> 37); + padded[59] = (uint8_t)(bytes >> 29); + padded[60] = (uint8_t)(bytes >> 21); + padded[61] = (uint8_t)(bytes >> 13); + padded[62] = (uint8_t)(bytes >> 5); + padded[63] = (uint8_t)(bytes << 3); crypto_hashblocks_sha256_armv8(state->ctx, padded, 64); } else { for (size_t i = new_inlen + 1; i < 120; ++i) { padded[i] = 0; } - padded[120] = (uint8_t) (bytes >> 53); - padded[121] = (uint8_t) (bytes >> 45); - padded[122] = (uint8_t) (bytes >> 37); - padded[123] = (uint8_t) (bytes >> 29); - padded[124] = (uint8_t) (bytes >> 21); - padded[125] = (uint8_t) (bytes >> 13); - padded[126] = (uint8_t) (bytes >> 5); - padded[127] = (uint8_t) (bytes << 3); + padded[120] = (uint8_t)(bytes >> 53); + padded[121] = (uint8_t)(bytes >> 45); + padded[122] = (uint8_t)(bytes >> 37); + padded[123] = (uint8_t)(bytes >> 29); + padded[124] = (uint8_t)(bytes >> 21); + padded[125] = (uint8_t)(bytes >> 13); + padded[126] = (uint8_t)(bytes >> 5); + padded[127] = (uint8_t)(bytes << 3); crypto_hashblocks_sha256_armv8(state->ctx, padded, 128); } @@ -314,7 +312,7 @@ void oqs_sha2_sha256_inc_armv8(sha256ctx *state, const uint8_t *in, size_t len) } void oqs_sha2_sha224_inc_blocks_armv8(sha224ctx *state, const uint8_t *in, size_t inblocks) { - oqs_sha2_sha256_inc_blocks_armv8((sha256ctx *) state, in, inblocks); + oqs_sha2_sha256_inc_blocks_armv8((sha256ctx *)state, in, inblocks); } void oqs_sha2_sha256_armv8(uint8_t *out, const uint8_t *in, size_t inlen) { diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index 7fdfd7bdb9..9d533a8b27 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -221,6 +221,7 @@ #cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 1 #cmakedefine OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 1 + #cmakedefine OQS_ENABLE_SIG_STFL_LMS 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w2 1 @@ -235,3 +236,4 @@ #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h15_w4 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 1 + diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index b583782e64..4405e60c1c 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -251,8 +251,8 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(void); -OQS_API OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); -OQS_API OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *totaln, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_left(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *totaln, const OQS_SIG_STFL_SECRET_KEY *secret_key); void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 70797ee80a..a0691a9d59 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -485,7 +485,7 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk); * @param[in] lock function pointer * */ -void OQS_SIG_STFL_SECRET_KEY_SET_lock(OQS_SIG_STFL_SECRET_KEY *sk, lock_key lock); +OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_lock(OQS_SIG_STFL_SECRET_KEY *sk, lock_key lock); /** * OQS_SIG_STFL_SECRET_KEY_SET_unlock . @@ -496,7 +496,7 @@ void OQS_SIG_STFL_SECRET_KEY_SET_lock(OQS_SIG_STFL_SECRET_KEY *sk, lock_key lock * @param[in] unlock function pointer * */ -void OQS_SIG_STFL_SECRET_KEY_SET_unlock(OQS_SIG_STFL_SECRET_KEY *sk, unlock_key unlock); +OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_unlock(OQS_SIG_STFL_SECRET_KEY *sk, unlock_key unlock); /** * OQS_SIG_STFL_SECRET_KEY_SET_mutex . @@ -507,7 +507,7 @@ void OQS_SIG_STFL_SECRET_KEY_SET_unlock(OQS_SIG_STFL_SECRET_KEY *sk, unlock_key * @param[in] mutex function pointer * */ -void OQS_SIG_STFL_SECRET_KEY_SET_mutex(OQS_SIG_STFL_SECRET_KEY *sk, void *mutex); +OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_mutex(OQS_SIG_STFL_SECRET_KEY *sk, void *mutex); /** * OQS_SIG_STFL_SECRET_KEY_lock . @@ -518,7 +518,7 @@ void OQS_SIG_STFL_SECRET_KEY_SET_mutex(OQS_SIG_STFL_SECRET_KEY *sk, void *mutex) * @return OQS_SUCCESS if successful, or OQS_ERROR if the object fails to apply the lock * */ -OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk); +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk); /** * OQS_SIG_STFL_SECRET_KEY_unlock . @@ -529,7 +529,7 @@ OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk); * @return OQS_SUCCESS if successful, or OQS_ERROR if the object fails to release the lock * */ -OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); /** * OQS_SIG_STFL_SECRET_KEY_SET_store_cb . @@ -543,7 +543,7 @@ OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); * Applications allocates, tracks, deallocates this. Signature generation fails without this set. * */ -void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); +OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); /** * OQS_SECRET_KEY_STFL_serialize_key . @@ -572,7 +572,7 @@ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf, void *context); #if defined(__cplusplus) -} // extern "C" +// extern "C" #endif #endif /* OQS_SIG_STATEFUL_H */ diff --git a/src/sig_stfl/xmss/external/xmss_commons.c b/src/sig_stfl/xmss/external/xmss_commons.c index 9838f755b0..5f3818d184 100644 --- a/src/sig_stfl/xmss/external/xmss_commons.c +++ b/src/sig_stfl/xmss/external/xmss_commons.c @@ -151,8 +151,8 @@ int xmssmt_core_sign_open(const xmss_params *params, unsigned char *root = leaf + params->n; unsigned long long prefix_length = params->padding_len + 3*params->n; - unsigned char m_with_prefix[mlen + prefix_length]; - + unsigned long long m_with_prefix_len = mlen + prefix_length; + unsigned char *m_with_prefix = NULL; unsigned char *mhash = root; unsigned long long idx = 0; unsigned int i, ret; @@ -169,13 +169,18 @@ int xmssmt_core_sign_open(const xmss_params *params, // Unused since smlen is a constant (void) smlen; + if ((m_with_prefix_len == 0) || (m_with_prefix = malloc(m_with_prefix_len)) == NULL){ + ret = -1; + goto fail; + } + /* Convert the index bytes from the signature to an integer. */ idx = bytes_to_ull(sm, params->index_bytes); /* Put the message at the m_with_prefix buffer, so that we can * prepend the required other inputs for the hash function. */ - memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); - memcpy(m_with_prefix + prefix_length, m, mlen); + memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, (size_t)prefix_length); + memcpy(m_with_prefix + prefix_length, m, (size_t)mlen); /* Compute the message hash. */ hash_message(params, mhash, sm + params->index_bytes, pk, idx, @@ -221,6 +226,7 @@ int xmssmt_core_sign_open(const xmss_params *params, ret = 0; fail: OQS_MEM_insecure_free(tmp); + OQS_MEM_insecure_free(m_with_prefix); return ret; } diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c index deaedefa8a..70b4b9774e 100644 --- a/src/sig_stfl/xmss/external/xmss_core_fast.c +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -13,7 +13,7 @@ typedef struct{ unsigned char h; - unsigned long next_idx; + unsigned long long next_idx; unsigned char stackusage; unsigned char completed; unsigned char *node; @@ -27,7 +27,7 @@ typedef struct { unsigned char *keep; treehash_inst *treehash; unsigned char *retain; - unsigned int next_leaf; + unsigned long long next_leaf; } bds_state; /* These serialization functions provide a transition between the current @@ -94,7 +94,7 @@ static void xmssmt_deserialize_state(const xmss_params *params, states[i].stack = sk; sk += (params->tree_height + 1) * params->n; - states[i].stackoffset = bytes_to_ull(sk, 4); + states[i].stackoffset = (unsigned int)bytes_to_ull(sk, 4); sk += 4; states[i].stacklevels = sk; @@ -107,16 +107,16 @@ static void xmssmt_deserialize_state(const xmss_params *params, sk += (params->tree_height >> 1) * params->n; for (j = 0; j < params->tree_height - params->bds_k; j++) { - states[i].treehash[j].h = bytes_to_ull(sk, 1); + states[i].treehash[j].h = (unsigned char)bytes_to_ull(sk, 1); sk += 1; - states[i].treehash[j].next_idx = bytes_to_ull(sk, 4); + states[i].treehash[j].next_idx = (unsigned long long)bytes_to_ull(sk, 4); sk += 4; - states[i].treehash[j].stackusage = bytes_to_ull(sk, 1); + states[i].treehash[j].stackusage = (unsigned char)bytes_to_ull(sk, 1); sk += 1; - states[i].treehash[j].completed = bytes_to_ull(sk, 1); + states[i].treehash[j].completed = (unsigned char)bytes_to_ull(sk, 1); sk += 1; states[i].treehash[j].node = sk; @@ -126,7 +126,7 @@ static void xmssmt_deserialize_state(const xmss_params *params, states[i].retain = sk; sk += ((1 << params->bds_k) - params->bds_k - 1) * params->n; - states[i].next_leaf = bytes_to_ull(sk, 4); + states[i].next_leaf = (unsigned long long)bytes_to_ull(sk, 4); sk += 4; } @@ -149,9 +149,9 @@ static void xmss_deserialize_state(const xmss_params *params, static void memswap(void *a, void *b, void *t, unsigned long long len) { - memcpy(t, a, len); - memcpy(a, b, len); - memcpy(b, t, len); + memcpy(t, a, (size_t)len); + memcpy(a, b, (size_t)len); + memcpy(b, t, (size_t)len); } /** @@ -637,7 +637,7 @@ int xmss_core_sign(const xmss_params *params, // Delete secret key here. We only do this in memory, production code // has to make sure that this happens on disk. memset(sk, 0xFF, params->index_bytes); - memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); + memset(sk + params->index_bytes, 0, (size_t)(params->sk_bytes - params->index_bytes)); if (idx > ((1ULL << params->full_height) - 1)) { ret = -2; // We already used all one-time keys goto cleanup; @@ -682,9 +682,9 @@ int xmss_core_sign(const xmss_params *params, /* Already put the message in the right place, to make it easier to prepend * things when computing the hash over the message. */ unsigned long long prefix_length = params->padding_len + 3*params->n; - unsigned char *m_with_prefix = malloc(mlen + prefix_length); - memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); - memcpy(m_with_prefix + prefix_length, m, mlen); + unsigned char *m_with_prefix = malloc((size_t)(mlen + prefix_length)); + memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, (size_t)prefix_length); + memcpy(m_with_prefix + prefix_length, m, (size_t)mlen); /* Compute the message hash. */ hash_message(params, msg_h, R, pub_root, idx, @@ -717,7 +717,7 @@ int xmss_core_sign(const xmss_params *params, // Prepare Address set_type(ots_addr, 0); - set_ots_addr(ots_addr, idx); + set_ots_addr(ots_addr, (uint32_t) idx); // Compute WOTS signature wots_sign(params, sm, msg_h, sk_seed, pub_seed, ots_addr); @@ -728,8 +728,8 @@ int xmss_core_sign(const xmss_params *params, // the auth path was already computed during the previous round memcpy(sm, state.auth, params->tree_height*params->n); - if (idx < (1U << params->tree_height) - 1) { - bds_round(params, &state, idx, sk_seed, pub_seed, ots_addr); + if (idx < (1ULL << params->tree_height) - 1) { + bds_round(params, &state, (const unsigned long)idx, sk_seed, pub_seed, ots_addr); bds_treehash_update(params, &state, (params->tree_height - params->bds_k) >> 1, sk_seed, pub_seed, ots_addr); } @@ -829,7 +829,7 @@ int xmssmt_core_sign(const xmss_params *params, uint64_t idx_tree; uint32_t idx_leaf; - uint64_t i, j; + unsigned int i, j; int needswap_upto = -1; unsigned int updates; @@ -847,7 +847,8 @@ int xmssmt_core_sign(const xmss_params *params, unsigned char *wots_sigs = NULL; unsigned long long prefix_length = params->padding_len + 3*params->n; - unsigned char m_with_prefix[mlen + prefix_length]; + unsigned long long m_with_prefix_len = mlen + prefix_length; + unsigned char *m_with_prefix = NULL; int ret = 0; // TODO refactor BDS state not to need separate treehash instances @@ -864,6 +865,11 @@ int xmssmt_core_sign(const xmss_params *params, states[i].next_leaf = 0; } + if ((m_with_prefix_len == 0) || (m_with_prefix = malloc(m_with_prefix_len)) == NULL) { + ret = -1; + goto cleanup; + } + xmssmt_deserialize_state(params, states, &wots_sigs, sk); // Extract SK @@ -887,7 +893,7 @@ int xmssmt_core_sign(const xmss_params *params, // Delete secret key here. We only do this in memory, production code // has to make sure that this happens on disk. memset(sk, 0xFF, params->index_bytes); - memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); + memset(sk + params->index_bytes, 0, (size_t)(params->sk_bytes - params->index_bytes)); if (idx > ((1ULL << params->full_height) - 1)) { // We already used all one-time keys ret = -2; @@ -895,9 +901,9 @@ int xmssmt_core_sign(const xmss_params *params, } } - memcpy(sk_seed, sk+params->index_bytes, params->n); - memcpy(sk_prf, sk+params->index_bytes+params->n, params->n); - memcpy(pub_seed, sk+params->index_bytes+3*params->n, params->n); + memcpy(sk_seed, sk+params->index_bytes, (size_t)params->n); + memcpy(sk_prf, sk+params->index_bytes+params->n, (size_t)params->n); + memcpy(pub_seed, sk+params->index_bytes+3*params->n, (size_t)params->n); // Update SK for (i = 0; i < params->index_bytes; i++) { @@ -991,24 +997,24 @@ int xmssmt_core_sign(const xmss_params *params, set_tree_addr(addr, (idx_tree + 1)); // mandatory update for NEXT_0 (does not count towards h-k/2) if NEXT_0 exists - if ((1 + idx_tree) * (1 << params->tree_height) + idx_leaf < (1ULL << params->full_height)) { + if ((1 + idx_tree) * (1ULL << params->tree_height) + idx_leaf < (1ULL << (unsigned long long) params->full_height)) { bds_state_update(params, &states[params->d], sk_seed, pub_seed, addr); } for (i = 0; i < params->d; i++) { // check if we're not at the end of a tree if (! (((idx + 1) & ((1ULL << ((i+1)*params->tree_height)) - 1)) == 0)) { - idx_leaf = (idx >> (params->tree_height * i)) & ((1 << params->tree_height)-1); + idx_leaf = (uint32_t)((idx >> (params->tree_height * i)) & ((1 << params->tree_height)-1)); idx_tree = (idx >> (params->tree_height * (i+1))); set_layer_addr(addr, i); - set_tree_addr(addr, idx_tree); + set_tree_addr(addr, (uint32_t)idx_tree); if (i == (unsigned int) (needswap_upto + 1)) { bds_round(params, &states[i], idx_leaf, sk_seed, pub_seed, addr); } updates = bds_treehash_update(params, &states[i], updates, sk_seed, pub_seed, addr); set_tree_addr(addr, (idx_tree + 1)); // if a NEXT-tree exists for this level; - if ((1 + idx_tree) * (1 << params->tree_height) + idx_leaf < (1ULL << (params->full_height - params->tree_height * i))) { + if ((1 + idx_tree) * (1ULL << params->tree_height) + idx_leaf < (1ULL << (params->full_height - params->tree_height * i))) { if (i > 0 && updates > 0 && states[params->d + i].next_leaf < (1ULL << params->full_height)) { bds_state_update(params, &states[params->d + i], sk_seed, pub_seed, addr); updates--; @@ -1018,9 +1024,9 @@ int xmssmt_core_sign(const xmss_params *params, else if (idx < (1ULL << params->full_height) - 1) { deep_state_swap(params, &states[params->d + i], &states[i]); - set_layer_addr(ots_addr, (i+1)); + set_layer_addr(ots_addr, (uint32_t)(i+1)); set_tree_addr(ots_addr, ((idx + 1) >> ((i+2) * params->tree_height))); - set_ots_addr(ots_addr, (((idx >> ((i+1) * params->tree_height)) + 1) & ((1 << params->tree_height)-1))); + set_ots_addr(ots_addr, (((idx >> ((i+1) * params->tree_height)) + 1) & ((1ULL << params->tree_height)-1))); wots_sign(params, wots_sigs + i*params->wots_sig_bytes, states[i].stack, sk_seed, pub_seed, ots_addr); @@ -1028,7 +1034,7 @@ int xmssmt_core_sign(const xmss_params *params, states[params->d + i].next_leaf = 0; updates--; // WOTS-signing counts as one update - needswap_upto = i; + needswap_upto = (int)i; for (j = 0; j < params->tree_height-params->bds_k; j++) { states[i].treehash[j].completed = 1; } @@ -1041,6 +1047,7 @@ int xmssmt_core_sign(const xmss_params *params, OQS_MEM_insecure_free(treehash); OQS_MEM_insecure_free(states); OQS_MEM_insecure_free(tmp); + OQS_MEM_insecure_free(m_with_prefix); return ret; } diff --git a/tests/helpers.py b/tests/helpers.py index b911f5d9bd..077b4d428f 100644 --- a/tests/helpers.py +++ b/tests/helpers.py @@ -175,7 +175,8 @@ def path_to_executable(program_name): for executable in [ os.path.join(path, program_name), os.path.join(path, program_name + ".EXE"), - os.path.join(path, program_name + ".exe")]: + os.path.join(path, program_name + ".exe"), + os.path.join(path, "Debug", program_name + ".exe"),]: if os.path.isfile(executable): return executable assert False, "Unable to find executable file {}".format(program_name) diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index a3d4bfd3f5..a8b3e7962d 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -7,10 +7,14 @@ #include #include #include +#if defined(_WIN32) #include +#define strcasecmp _stricmp +#else +#include +#endif #include -#include #include #include "tmp_store.c" @@ -1100,10 +1104,17 @@ int main(int argc, char **argv) { OQS_MEM_insecure_free(lock_test_context); OQS_MEM_insecure_free(signature_1); OQS_MEM_insecure_free(signature_2); - if (rc != OQS_SUCCESS || rc1 != OQS_SUCCESS || - rc_create != OQS_SUCCESS || rc_sign != OQS_SUCCESS || rc_query != OQS_SUCCESS) { + + OQS_destroy(); + if (rc != OQS_SUCCESS || rc1 != OQS_SUCCESS) { return EXIT_FAILURE; } + +#if OQS_USE_PTHREADS_IN_TESTS + if (rc_create != OQS_SUCCESS || rc_sign != OQS_SUCCESS || rc_query != OQS_SUCCESS) { + return EXIT_FAILURE; + } +#endif return exit_status; #else rc = sig_stfl_test_correctness(alg_name, katfile); From bb658b79261e3f7187bd03c8ee19223555b2a96a Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Thu, 11 Jan 2024 12:52:08 -0500 Subject: [PATCH 27/68] Address stateful-sigs comments in #1650 (#1656) * Add sig_stfl to configure.md * Add OQS_MEM_checked_malloc and OQS_MEM_checked_aligned_alloc * Use memcpy and checked_malloc --- CONFIGURE.md | 28 +++++++------- src/common/common.c | 20 ++++++++++ src/common/common.h | 55 +++++++++++++++++++++++++++ src/common/sha2/sha2_armv8.c | 20 +++------- src/common/sha2/sha2_c.c | 70 +++++++++++------------------------ src/common/sha3/ossl_sha3.c | 12 +----- src/common/sha3/ossl_sha3x4.c | 12 +----- src/common/sha3/xkcp_sha3.c | 25 +++---------- src/common/sha3/xkcp_sha3x4.c | 10 +---- 9 files changed, 129 insertions(+), 123 deletions(-) diff --git a/CONFIGURE.md b/CONFIGURE.md index 6605c7f3c5..ffc40273e2 100644 --- a/CONFIGURE.md +++ b/CONFIGURE.md @@ -8,7 +8,7 @@ The following options can be passed to CMake before the build file generation pr - [CMAKE_INSTALL_PREFIX](#CMAKE_INSTALL_PREFIX) - [OQS_ALGS_ENABLED](#OQS_ALGS_ENABLED) - [OQS_BUILD_ONLY_LIB](#OQS_BUILD_ONLY_LIB) -- [OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG](#OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG) +- [OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG](#OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG) - [OQS_MINIMAL_BUILD](#OQS_MINIMAL_BUILD) - [OQS_DIST_BUILD](#OQS_DIST_BUILD) - [OQS_USE_CPUFEATURE_INSTRUCTIONS](OQS_USE_CPUFEATURE_INSTRUCTIONS) @@ -42,21 +42,23 @@ Can be set to the following values: See the [CMake documentation](https://cmake.org/cmake/help/latest/variable/CMAKE_INSTALL_PREFIX.html). -## OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG +## OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG -Note: `ALG` in `OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG` should be replaced with the specific algorithm name as demonstrated below. +Note: `ALG` in `OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG` should be replaced with the specific algorithm name as demonstrated below. This can be set to `ON` or `OFF`, and is `ON` by default. When `OFF`, `ALG` and its code are excluded from the build process. When `ON`, made available are additional options whereby individual variants of `ALG` can be excluded from the build process. For example: if `OQS_ENABLE_KEM_BIKE` is set to `ON`, the options `OQS_ENABLE_KEM_bike_l1`, `OQS_ENABLE_KEM_bike_l3`, and `OQS_ENABLE_KEM_bike_l5` are made available (and are set to be `ON` by default). +To enable `XMSS` stateful signature, set `OQS_ENABLE_SIG_STFL_XMSS` to `ON`, the options `OQS_ENABLE_SIG_STFL_xmss_sha256_h10` and its variants are also set to be `ON` by default. Similarly, `LMS` stateful signature family can also be enabled by setting `OQS_ENABLE_SIG_STFL_LMS` to `ON`. + For a full list of such options and their default values, consult [.CMake/alg_support.cmake](https://github.com/open-quantum-safe/liboqs/blob/master/.CMake/alg_support.cmake). **Default**: Unset. ## OQS_ALGS_ENABLED -Selects algorithm set enabled. Possible values are "STD" selecting all algorithms standardized by NIST; "NIST_R4" selecting all algorithms evaluated in round 4 of the NIST PQC competition; "All" (or any other value) selecting all algorithms integrated into liboqs. Parameter setting "STD" minimizes library size but may require re-running code generator scripts in projects integrating `liboqs`; e.g., [oqs-provider](https://github.com/open-quantum-safe/oqs-provider) and [oqs-boringssl](https://github.com/open-quantum-safe/boringssl). +A selected algorithm set is enabled. Possible values are "STD" selecting all algorithms standardized by NIST; "NIST_R4" selecting all algorithms evaluated in round 4 of the NIST PQC competition; "All" (or any other value) selecting all algorithms integrated into liboqs. Parameter setting "STD" minimizes library size but may require re-running code generator scripts in projects integrating `liboqs`; e.g., [oqs-provider](https://github.com/open-quantum-safe/oqs-provider) and [oqs-boringssl](https://github.com/open-quantum-safe/boringssl). **Attention**: If you use any predefined value (`STD` or `NIST_R4` as of now) for this variable, the values added via [OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG](#OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG) variables will be ignored. @@ -70,9 +72,9 @@ Can be `ON` or `OFF`. When `ON`, only liboqs is built, and all the targets: `run ## OQS_MINIMAL_BUILD -If set, this defines a semicolon deliminated list of algorithms to be contained in a minimal build of `liboqs`: Only algorithms explicitly set here are included in a build: For example running `cmake -DOQS_MINIMAL_BUILD="KEM_kyber_768;SIG_dilithium_3" ..` will build a minimum-size `liboqs` library only containing support for Kyber768 and Dilithium3. +If set, this defines a semicolon-delimited list of algorithms to be contained in a minimal build of `liboqs`: Only algorithms explicitly set here are included in a build: For example running `cmake -DOQS_MINIMAL_BUILD="KEM_kyber_768;SIG_dilithium_3" ..` will build a minimum-size `liboqs` library only containing support for Kyber768 and Dilithium3. -The full list of identifiers that can set are listed [here for KEM algorithms](https://github.com/open-quantum-safe/liboqs/blob/main/src/kem/kem.h#L34) and [here for Signature algorithms](https://github.com/open-quantum-safe/liboqs/blob/f3caccff9e6225e7c50ca27f5ee6e58b7bc74188/src/sig/sig.h#L34). Default setting is empty, thus including all [supported algorithms](https://github.com/open-quantum-safe/liboqs#supported-algorithms) in the build. +The full list of identifiers that can be set is listed [here for KEM algorithms](https://github.com/open-quantum-safe/liboqs/blob/main/src/kem/kem.h#L34) and [here for Signature algorithms](https://github.com/open-quantum-safe/liboqs/blob/f3caccff9e6225e7c50ca27f5ee6e58b7bc74188/src/sig/sig.h#L34). The default setting is empty, thus including all [supported algorithms](https://github.com/open-quantum-safe/liboqs#supported-algorithms) in the build. **Default**: Unset. @@ -92,13 +94,13 @@ When built for use on a single machine, the library will only include the best a Note: `CPUFEATURE` in `OQS_USE_CPUFEATURE_INSTRUCTIONS` should be replaced with the specific CPU feature as noted below. -These can be set to `ON` or `OFF` and take an effect if liboqs is built for use on a single machine. By default, the CPU features are automatically determined and set to `ON` or `OFF` based on the CPU features available on the build system. The default values can be overridden by providing CMake build options. The available options on x86-64 are: `OQS_USE_ADX_INSTRUCTIONS`, `OQS_USE_AES_INSTRUCTIONS`, `OQS_USE_AVX_INSTRUCTIONS`, `OQS_USE_AVX2_INSTRUCTIONS`, `OQS_USE_AVX512_INSTRUCTIONS`, `OQS_USE_BMI1_INSTRUCTIONS`, `OQS_USE_BMI2_INSTRUCTIONS`, `OQS_USE_PCLMULQDQ_INSTRUCTIONS`, `OQS_USE_VPCLMULQDQ_INSTRUCTIONS`, `OQS_USE_POPCNT_INSTRUCTIONS`, `OQS_USE_SSE_INSTRUCTIONS`, `OQS_USE_SSE2_INSTRUCTIONS` and `OQS_USE_SSE3_INSTRUCTIONS`. The available options on ARM64v8 are `OQS_USE_ARM_AES_INSTRUCTIONS`, `OQS_USE_ARM_SHA2_INSTRUCTIONS`, `OQS_USE_ARM_SHA3_INSTRUCTIONS` and `OQS_USE_ARM_NEON_INSTRUCTIONS`. +These can be set to `ON` or `OFF` and take effect if liboqs is built for use on a single machine. By default, the CPU features are automatically determined and set to `ON` or `OFF` based on the CPU features available on the build system. The default values can be overridden by providing CMake build options. The available options on x86-64 are: `OQS_USE_ADX_INSTRUCTIONS`, `OQS_USE_AES_INSTRUCTIONS`, `OQS_USE_AVX_INSTRUCTIONS`, `OQS_USE_AVX2_INSTRUCTIONS`, `OQS_USE_AVX512_INSTRUCTIONS`, `OQS_USE_BMI1_INSTRUCTIONS`, `OQS_USE_BMI2_INSTRUCTIONS`, `OQS_USE_PCLMULQDQ_INSTRUCTIONS`, `OQS_USE_VPCLMULQDQ_INSTRUCTIONS`, `OQS_USE_POPCNT_INSTRUCTIONS`, `OQS_USE_SSE_INSTRUCTIONS`, `OQS_USE_SSE2_INSTRUCTIONS` and `OQS_USE_SSE3_INSTRUCTIONS`. The available options on ARM64v8 are `OQS_USE_ARM_AES_INSTRUCTIONS`, `OQS_USE_ARM_SHA2_INSTRUCTIONS`, `OQS_USE_ARM_SHA3_INSTRUCTIONS` and `OQS_USE_ARM_NEON_INSTRUCTIONS`. **Default**: Options valid on the build machine. ## OQS_USE_OPENSSL -In order to save size and limit the amount of different cryptographic code bases, it is possible to use OpenSSL as a crypto code provider by setting this configuration option. +To save size and limit the amount of different cryptographic code bases, it is possible to use OpenSSL as a crypto code provider by setting this configuration option. This can be set to `ON` or `OFF`. When `ON`, the additional options `OQS_USE_AES_OPENSSL`, `OQS_USE_SHA2_OPENSSL`, and `OQS_USE_SHA3_OPENSSL` are made available to control whether liboqs uses OpenSSL's AES, SHA-2, and SHA-3 implementations. @@ -107,7 +109,7 @@ By default, - `OQS_USE_SHA2_OPENSSL` is `ON` - `OQS_USE_SHA3_OPENSSL` is `OFF`. -These default choices have been made in order to optimize the default performance of all algorithms. Changing them implies performance penalties. +These default choices have been made to optimize the default performance of all algorithms. Changing them implies performance penalties. When `OQS_USE_OPENSSL` is `ON`, CMake also scans the filesystem to find the minimum version of OpenSSL required by liboqs (which happens to be 1.1.1). The [OPENSSL_ROOT_DIR](https://cmake.org/cmake/help/latest/module/FindOpenSSL.html) option can be set to aid CMake in its search. @@ -133,7 +135,7 @@ An optimization target. Only has an effect if the compiler is GCC or Clang and ` Can be `ON` or `OFF`. When `ON`, the benchmarking script will try to use the ARMv8 Performance Monitoring Unit (PMU). This will make cycle counts on ARMv8 platforms significantly more accurate. -In order to use this option, user mode access to the PMU must be enabled via a kernel module. If user mode access is not enabled via kernel module, benchmarking will throw an `Illegal Instruction` error. A kernel module that has been found to work on several platforms can be found [here for linux](https://github.com/mupq/pqax#enable-access-to-performance-counters). Follow the instructions there (i.e., clone the repository, `cd enable_ccr` and `make install`) to load the kernel module, after which benchmarking should work. Superuser permissions are required. Linux header files must also be installed on your platform, which may not be present by default. +In order to use this option, user mode access to the PMU must be enabled via a kernel module. If user mode access is not enabled via the kernel module, benchmarking will throw an `Illegal Instruction` error. A kernel module that has been found to work on several platforms can be found [here for Linux](https://github.com/mupq/pqax#enable-access-to-performance-counters). Follow the instructions there (i.e., clone the repository, `cd enable_ccr` and `make install`) to load the kernel module, after which benchmarking should work. Superuser permissions are required. Linux header files must also be installed on your platform, which may not be present by default. Note that this option is not known to work on Apple M1 chips. @@ -141,7 +143,7 @@ Note that this option is not known to work on Apple M1 chips. ## USE_SANITIZER -This has effect when the compiler is Clang and when [CMAKE_BUILD_TYPE](#CMAKE_BUILD_TYPE) is `Debug`. Then, it can be set to: +This has an effect when the compiler is Clang and when [CMAKE_BUILD_TYPE](#CMAKE_BUILD_TYPE) is `Debug`. Then, it can be set to: - `Address`: This enables Clang's `AddressSanitizer` - `Memory`: This enables Clang's `MemorySanitizer` @@ -156,13 +158,13 @@ This has effect when the compiler is Clang and when [CMAKE_BUILD_TYPE](#CMAKE_BU This is used in conjunction with `tests/test_constant_time.py` to use Valgrind to look for instances of secret-dependent control flow. liboqs must also be compiled with [CMAKE_BUILD_TYPE](#CMAKE_BUILD_TYPE) set to `Debug`. -See the documentation in [`tests/test_constant_time.py`](https://github.com/open-quantum-safe/liboqs/blob/main/tests/test_constant_time.py) for more information on usage. +See the documentation in [`tests/test_constant_time.py`](https://github.com/open-quantum-safe/liboqs/blob/main/tests/test_constant_time.py) for more usage information. **Default**: `OFF`. ## OQS_STRICT_WARNINGS -Can be `ON` or `OFF`. When `ON`, all compiler warnings are enabled and treated as errors. This setting is recommended to be enabled prior to submission of a Pull Request as CI runs with this setting active. When `OFF`, significantly fewer compiler warnings are enabled such as to avoid undue build errors triggered by (future) compiler warning features/unknown at development time of this library. +Can be `ON` or `OFF`. When `ON`, all compiler warnings are enabled and treated as errors. This setting is recommended to be enabled prior to submission of a Pull Request as CI runs with this setting active. When `OFF`, significantly fewer compiler warnings are enabled such as to avoid undue build errors triggered by (future) compiler warning features/unknown at the development time of this library. **Default**: `OFF`. diff --git a/src/common/common.c b/src/common/common.c index 7de1e65815..1146f5c45b 100644 --- a/src/common/common.c +++ b/src/common/common.c @@ -271,6 +271,26 @@ OQS_API void OQS_MEM_cleanse(void *ptr, size_t len) { #endif } +void *OQS_MEM_checked_malloc(size_t len) { + void *ptr = malloc(len); + if (ptr == NULL) { + fprintf(stderr, "Memory allocation failed\n"); + exit(EXIT_FAILURE); + } + + return ptr; +} + +void *OQS_MEM_checked_aligned_alloc(size_t alignment, size_t size) { + void *ptr = OQS_MEM_aligned_alloc(alignment, size); + if (ptr == NULL) { + fprintf(stderr, "Memory allocation failed\n"); + exit(EXIT_FAILURE); + } + + return ptr; +} + OQS_API void OQS_MEM_secure_free(void *ptr, size_t len) { if (ptr != NULL) { OQS_MEM_cleanse(ptr, len); diff --git a/src/common/common.h b/src/common/common.h index 8ddeef6f8f..b092baa036 100644 --- a/src/common/common.h +++ b/src/common/common.h @@ -180,6 +180,59 @@ OQS_API int OQS_MEM_secure_bcmp(const void *a, const void *b, size_t len); */ OQS_API void OQS_MEM_cleanse(void *ptr, size_t len); +/** + * Allocates memory of a specified size and checks for successful allocation. + * + * This function attempts to allocate a block of memory of the specified size. + * If the allocation is successful, it returns a pointer to the beginning of the + * memory block. If the allocation fails, it prints an error message to stderr + * and terminates the program. + * + * @param[in] len The size of the memory block to allocate, in bytes. + * + * @return A pointer to the allocated memory block if the allocation is successful. + * + * @note This function is intended to be used when the allocation must succeed, + * and failure to allocate memory is considered a fatal error. As such, + * it does not return if the allocation fails, but instead terminates the + * program with an exit status indicating failure. + * + * @note The memory block returned by this function is not initialized. The caller + * is responsible for initializing the memory if required. + * + * @note The allocated memory should be freed using the standard `free` function + * when it is no longer needed. + */ +void *OQS_MEM_checked_malloc(size_t len); + +/** + * Allocates memory of a specified size and alignment and checks for successful allocation. + * + * This function attempts to allocate a block of memory with the specified size + * and alignment. If the allocation is successful, it returns a pointer to the + * memory block. If the allocation fails, it prints an error message to stderr + * and terminates the program. + * + * Alignment must be a power of two and a multiple of sizeof(void *). + * + * @param[in] alignment The alignment of the memory block to allocate. + * @param[in] size The size of the memory block to allocate, in bytes. + * + * @return A pointer to the allocated memory block if the allocation is successful. + * + * @note This function is intended to be used when the allocation must succeed, + * and failure to allocate memory is considered a fatal error. As such, + * it does not return if the allocation fails, but instead terminates the + * program with an exit status indicating failure. + * + * @note The memory block returned by this function is not initialized. The caller + * is responsible for initializing the memory if required. + * + * @note The allocated memory should be freed with `OQS_MEM_aligned_free` when it + * is no longer needed. + */ +void *OQS_MEM_checked_aligned_alloc(size_t alignment, size_t size); + /** * Zeros out `len` bytes of memory starting at `ptr`, then frees `ptr`. * @@ -211,6 +264,8 @@ OQS_API void OQS_MEM_insecure_free(void *ptr); * Allocates size bytes of uninitialized memory with a base pointer that is * a multiple of alignment. Alignment must be a power of two and a multiple * of sizeof(void *). Size must be a multiple of alignment. + * @note The allocated memory should be freed with `OQS_MEM_aligned_free` when it + * is no longer needed. */ void *OQS_MEM_aligned_alloc(size_t alignment, size_t size); diff --git a/src/common/sha2/sha2_armv8.c b/src/common/sha2/sha2_armv8.c index dc8661485b..65ea6750c3 100644 --- a/src/common/sha2/sha2_armv8.c +++ b/src/common/sha2/sha2_armv8.c @@ -180,10 +180,7 @@ void oqs_sha2_sha256_inc_finalize_armv8(uint8_t *out, sha256ctx *state, const ui new_in = in; } else { // Combine incremental data with final input - tmp_in = malloc(tmp_len); - if (tmp_in == NULL) { - exit(111); - } + tmp_in = OQS_MEM_checked_malloc(tmp_len); memcpy(tmp_in, state->data, state->data_len); if (in && inlen) { @@ -257,10 +254,7 @@ void oqs_sha2_sha256_inc_blocks_armv8(sha256ctx *state, const uint8_t *in, size_ /* Process any existing incremental data first */ if (state->data_len) { - tmp_in = malloc(buf_len); - if (tmp_in == NULL) { - exit(111); - } + tmp_in = OQS_MEM_checked_malloc(buf_len); memcpy(tmp_in, state->data, state->data_len); memcpy(tmp_in + state->data_len, in, buf_len - state->data_len); @@ -280,17 +274,15 @@ void oqs_sha2_sha256_inc_blocks_armv8(sha256ctx *state, const uint8_t *in, size_ } void oqs_sha2_sha256_inc_armv8(sha256ctx *state, const uint8_t *in, size_t len) { - uint64_t bytes = 0; - size_t in_index = 0; while (len) { size_t incr = 64 - state->data_len; if (incr > len) { incr = len; } - for (size_t i = 0; i < incr; ++i, state->data_len++, in_index++) { - state->data[state->data_len] = in[in_index]; - } + memcpy(state->data + state->data_len, in, incr); + state->data_len += incr; + in += incr; if (state->data_len < 64) { break; @@ -299,7 +291,7 @@ void oqs_sha2_sha256_inc_armv8(sha256ctx *state, const uint8_t *in, size_t len) /* * Process a complete block now */ - bytes = load_bigendian_64(state->ctx + 32) + 64; + uint64_t bytes = load_bigendian_64(state->ctx + 32) + 64; crypto_hashblocks_sha256_armv8(state->ctx, state->data, 64); store_bigendian_64(state->ctx + 32, bytes); diff --git a/src/common/sha2/sha2_c.c b/src/common/sha2/sha2_c.c index b0f628136a..e5bd350889 100644 --- a/src/common/sha2/sha2_c.c +++ b/src/common/sha2/sha2_c.c @@ -502,10 +502,8 @@ static const uint8_t iv_512[64] = { }; void oqs_sha2_sha224_inc_init_c(sha224ctx *state) { - state->ctx = malloc(PQC_SHA256CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_malloc(PQC_SHA256CTX_BYTES); + for (size_t i = 0; i < 32; ++i) { state->ctx[i] = iv_224[i]; } @@ -518,10 +516,8 @@ void oqs_sha2_sha224_inc_init_c(sha224ctx *state) { void oqs_sha2_sha256_inc_init_c(sha256ctx *state) { state->data_len = 0; - state->ctx = malloc(PQC_SHA256CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_malloc(PQC_SHA256CTX_BYTES); + for (size_t i = 0; i < 32; ++i) { state->ctx[i] = iv_256[i]; } @@ -533,10 +529,8 @@ void oqs_sha2_sha256_inc_init_c(sha256ctx *state) { } void oqs_sha2_sha384_inc_init_c(sha384ctx *state) { - state->ctx = malloc(PQC_SHA512CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_malloc(PQC_SHA512CTX_BYTES); + for (size_t i = 0; i < 64; ++i) { state->ctx[i] = iv_384[i]; } @@ -548,10 +542,8 @@ void oqs_sha2_sha384_inc_init_c(sha384ctx *state) { } void oqs_sha2_sha512_inc_init_c(sha512ctx *state) { - state->ctx = malloc(PQC_SHA512CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_malloc(PQC_SHA512CTX_BYTES); + for (size_t i = 0; i < 64; ++i) { state->ctx[i] = iv_512[i]; } @@ -563,40 +555,32 @@ void oqs_sha2_sha512_inc_init_c(sha512ctx *state) { } void oqs_sha2_sha224_inc_ctx_clone_c(sha224ctx *stateout, const sha224ctx *statein) { - stateout->ctx = malloc(PQC_SHA256CTX_BYTES); - if (stateout->ctx == NULL) { - exit(111); - } + stateout->ctx = OQS_MEM_checked_malloc(PQC_SHA256CTX_BYTES); + stateout->data_len = statein->data_len; memcpy(stateout->data, statein->data, 128); memcpy(stateout->ctx, statein->ctx, PQC_SHA256CTX_BYTES); } void oqs_sha2_sha256_inc_ctx_clone_c(sha256ctx *stateout, const sha256ctx *statein) { - stateout->ctx = malloc(PQC_SHA256CTX_BYTES); - if (stateout->ctx == NULL) { - exit(111); - } + stateout->ctx = OQS_MEM_checked_malloc(PQC_SHA256CTX_BYTES); + stateout->data_len = statein->data_len; memcpy(stateout->data, statein->data, 128); memcpy(stateout->ctx, statein->ctx, PQC_SHA256CTX_BYTES); } void oqs_sha2_sha384_inc_ctx_clone_c(sha384ctx *stateout, const sha384ctx *statein) { - stateout->ctx = malloc(PQC_SHA512CTX_BYTES); - if (stateout->ctx == NULL) { - exit(111); - } + stateout->ctx = OQS_MEM_checked_malloc(PQC_SHA512CTX_BYTES); + stateout->data_len = statein->data_len; memcpy(stateout->data, statein->data, 128); memcpy(stateout->ctx, statein->ctx, PQC_SHA512CTX_BYTES); } void oqs_sha2_sha512_inc_ctx_clone_c(sha512ctx *stateout, const sha512ctx *statein) { - stateout->ctx = malloc(PQC_SHA512CTX_BYTES); - if (stateout->ctx == NULL) { - exit(111); - } + stateout->ctx = OQS_MEM_checked_malloc(PQC_SHA512CTX_BYTES); + stateout->data_len = statein->data_len; memcpy(stateout->data, statein->data, 128); memcpy(stateout->ctx, statein->ctx, PQC_SHA512CTX_BYTES); @@ -630,10 +614,7 @@ void oqs_sha2_sha256_inc_blocks_c(sha256ctx *state, const uint8_t *in, size_t in /* Process any existing incremental data first */ if (state->data_len) { - tmp_in = malloc(tmp_buflen); - if (tmp_in == NULL) { - exit(111); - } + tmp_in = OQS_MEM_checked_malloc(tmp_buflen); memcpy(tmp_in, state->data, state->data_len); memcpy(tmp_in + state->data_len, in, tmp_buflen - state->data_len); @@ -653,17 +634,15 @@ void oqs_sha2_sha256_inc_blocks_c(sha256ctx *state, const uint8_t *in, size_t in } void oqs_sha2_sha256_inc_c(sha256ctx *state, const uint8_t *in, size_t len) { - uint64_t bytes = 0; - size_t in_index = 0; while (len) { size_t incr = 64 - state->data_len; if (incr > len) { incr = len; } - for (size_t i = 0; i < incr; ++i, state->data_len++, in_index++) { - state->data[state->data_len] = in[in_index]; - } + memcpy(state->data + state->data_len, in, incr); + state->data_len += incr; + in += incr; if (state->data_len < 64) { break; @@ -672,9 +651,8 @@ void oqs_sha2_sha256_inc_c(sha256ctx *state, const uint8_t *in, size_t len) { /* * Process a complete block now */ - bytes = load_bigendian_64(state->ctx + 32); + uint64_t bytes = load_bigendian_64(state->ctx + 32) + 64; crypto_hashblocks_sha256_c(state->ctx, state->data, 64); - bytes += 64; store_bigendian_64(state->ctx + 32, bytes); /* @@ -713,10 +691,7 @@ void oqs_sha2_sha256_inc_finalize_c(uint8_t *out, sha256ctx *state, const uint8_ if (new_inlen == inlen) { new_in = in; } else { //Combine incremental data with final input - tmp_in = malloc(tmp_len); - if (tmp_in == NULL) { - exit(111); - } + tmp_in = OQS_MEM_checked_malloc(tmp_len); memcpy(tmp_in, state->data, state->data_len); if (in && inlen) { @@ -868,4 +843,3 @@ void oqs_sha2_sha512_c(uint8_t *out, const uint8_t *in, size_t inlen) { oqs_sha2_sha512_inc_init_c(&state); oqs_sha2_sha512_inc_finalize_c(out, &state, in, inlen); } - diff --git a/src/common/sha3/ossl_sha3.c b/src/common/sha3/ossl_sha3.c index 1b65b37662..5d36f2280c 100644 --- a/src/common/sha3/ossl_sha3.c +++ b/src/common/sha3/ossl_sha3.c @@ -198,11 +198,7 @@ static void SHA3_shake128_inc_squeeze(uint8_t *output, size_t outlen, OQS_SHA3_s if (s->n_out == 0) { OSSL_FUNC(EVP_DigestFinalXOF)(clone, output, outlen); } else { - uint8_t *tmp; - tmp = malloc(s->n_out + outlen); - if (tmp == NULL) { - exit(111); - } + uint8_t *tmp = OQS_MEM_checked_malloc(s->n_out + outlen); OSSL_FUNC(EVP_DigestFinalXOF)(clone, tmp, s->n_out + outlen); memcpy(output, tmp + s->n_out, outlen); free(tmp); // IGNORE free-check @@ -276,11 +272,7 @@ static void SHA3_shake256_inc_squeeze(uint8_t *output, size_t outlen, OQS_SHA3_s if (s->n_out == 0) { OSSL_FUNC(EVP_DigestFinalXOF)(clone, output, outlen); } else { - uint8_t *tmp; - tmp = malloc(s->n_out + outlen); - if (tmp == NULL) { - exit(111); - } + uint8_t *tmp = OQS_MEM_checked_malloc(s->n_out + outlen); OSSL_FUNC(EVP_DigestFinalXOF)(clone, tmp, s->n_out + outlen); memcpy(output, tmp + s->n_out, outlen); free(tmp); // IGNORE free-check diff --git a/src/common/sha3/ossl_sha3x4.c b/src/common/sha3/ossl_sha3x4.c index 971a26c4e8..1f6a03c615 100644 --- a/src/common/sha3/ossl_sha3x4.c +++ b/src/common/sha3/ossl_sha3x4.c @@ -81,11 +81,7 @@ static void SHA3_shake128_x4_inc_squeeze(uint8_t *out0, uint8_t *out1, uint8_t * OSSL_FUNC(EVP_MD_CTX_copy_ex)(clone, s->mdctx3); OSSL_FUNC(EVP_DigestFinalXOF)(clone, out3, outlen); } else { - uint8_t *tmp; - tmp = malloc(s->n_out + outlen); - if (tmp == NULL) { - exit(111); - } + uint8_t *tmp = OQS_MEM_checked_malloc(s->n_out + outlen); OSSL_FUNC(EVP_MD_CTX_copy_ex)(clone, s->mdctx0); OSSL_FUNC(EVP_DigestFinalXOF)(clone, tmp, s->n_out + outlen); memcpy(out0, tmp + s->n_out, outlen); @@ -206,11 +202,7 @@ static void SHA3_shake256_x4_inc_squeeze(uint8_t *out0, uint8_t *out1, uint8_t * OSSL_FUNC(EVP_MD_CTX_copy_ex)(clone, s->mdctx3); OSSL_FUNC(EVP_DigestFinalXOF)(clone, out3, outlen); } else { - uint8_t *tmp; - tmp = malloc(s->n_out + outlen); - if (tmp == NULL) { - exit(111); - } + uint8_t *tmp = OQS_MEM_checked_malloc(s->n_out + outlen); OSSL_FUNC(EVP_MD_CTX_copy_ex)(clone, s->mdctx0); OSSL_FUNC(EVP_DigestFinalXOF)(clone, tmp, s->n_out + outlen); memcpy(out0, tmp + s->n_out, outlen); diff --git a/src/common/sha3/xkcp_sha3.c b/src/common/sha3/xkcp_sha3.c index 2fce9d9fe0..196652d85d 100644 --- a/src/common/sha3/xkcp_sha3.c +++ b/src/common/sha3/xkcp_sha3.c @@ -199,10 +199,7 @@ static void SHA3_sha3_256(uint8_t *output, const uint8_t *input, size_t inlen) { } static void SHA3_sha3_256_inc_init(OQS_SHA3_sha3_256_inc_ctx *state) { - state->ctx = OQS_MEM_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); keccak_inc_reset((uint64_t *)state->ctx); } @@ -238,10 +235,7 @@ static void SHA3_sha3_384(uint8_t *output, const uint8_t *input, size_t inlen) { } static void SHA3_sha3_384_inc_init(OQS_SHA3_sha3_384_inc_ctx *state) { - state->ctx = OQS_MEM_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); keccak_inc_reset((uint64_t *)state->ctx); } @@ -277,10 +271,7 @@ static void SHA3_sha3_512(uint8_t *output, const uint8_t *input, size_t inlen) { } static void SHA3_sha3_512_inc_init(OQS_SHA3_sha3_512_inc_ctx *state) { - state->ctx = OQS_MEM_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); keccak_inc_reset((uint64_t *)state->ctx); } @@ -319,10 +310,7 @@ static void SHA3_shake128(uint8_t *output, size_t outlen, const uint8_t *input, /* SHAKE128 incremental */ static void SHA3_shake128_inc_init(OQS_SHA3_shake128_inc_ctx *state) { - state->ctx = OQS_MEM_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); keccak_inc_reset((uint64_t *)state->ctx); } @@ -364,10 +352,7 @@ static void SHA3_shake256(uint8_t *output, size_t outlen, const uint8_t *input, /* SHAKE256 incremental */ static void SHA3_shake256_inc_init(OQS_SHA3_shake256_inc_ctx *state) { - state->ctx = OQS_MEM_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_aligned_alloc(KECCAK_CTX_ALIGNMENT, KECCAK_CTX_BYTES); keccak_inc_reset((uint64_t *)state->ctx); } diff --git a/src/common/sha3/xkcp_sha3x4.c b/src/common/sha3/xkcp_sha3x4.c index 8ed5da878b..bd441a01ff 100644 --- a/src/common/sha3/xkcp_sha3x4.c +++ b/src/common/sha3/xkcp_sha3x4.c @@ -167,10 +167,7 @@ static void SHA3_shake128_x4(uint8_t *out0, uint8_t *out1, uint8_t *out2, uint8_ /* SHAKE128 incremental */ static void SHA3_shake128_x4_inc_init(OQS_SHA3_shake128_x4_inc_ctx *state) { - state->ctx = OQS_MEM_aligned_alloc(KECCAK_X4_CTX_ALIGNMENT, KECCAK_X4_CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_aligned_alloc(KECCAK_X4_CTX_ALIGNMENT, KECCAK_X4_CTX_BYTES); keccak_x4_inc_reset((uint64_t *)state->ctx); } @@ -212,10 +209,7 @@ static void SHA3_shake256_x4(uint8_t *out0, uint8_t *out1, uint8_t *out2, uint8_ /* SHAKE256 incremental */ static void SHA3_shake256_x4_inc_init(OQS_SHA3_shake256_x4_inc_ctx *state) { - state->ctx = OQS_MEM_aligned_alloc(KECCAK_X4_CTX_ALIGNMENT, KECCAK_X4_CTX_BYTES); - if (state->ctx == NULL) { - exit(111); - } + state->ctx = OQS_MEM_checked_aligned_alloc(KECCAK_X4_CTX_ALIGNMENT, KECCAK_X4_CTX_BYTES); keccak_x4_inc_reset((uint64_t *)state->ctx); } From 7db8ddfe24a189e84e0d72dc127a8c09c8c89f24 Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Thu, 11 Jan 2024 14:39:43 -0500 Subject: [PATCH 28/68] Update `sig_stfl.h` document for #1650 (#1655) * update the stateful siganture header documentation * catch the case when mutex is not set * stress that only the Signing operation need to be locked/unlocked. * make lock and unlock function to internal APIs. --- src/sig_stfl/sig_stfl.c | 15 ++- src/sig_stfl/sig_stfl.h | 284 +++++++++++++++++++++++++--------------- 2 files changed, 195 insertions(+), 104 deletions(-) diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 6b63f8a73e..e3a9d0f71c 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -1370,7 +1370,7 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_mutex(OQS_SIG_STFL_SECRET_KEY *sk, void } /* OQS_SIG_STFL_SECRET_KEY_lock */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk) { +OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk) { if (sk == NULL) { return OQS_ERROR; } @@ -1378,16 +1378,27 @@ OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk) { return OQS_SUCCESS; } + // Try to lock the private key but the mutex is unset. + if (sk->mutex == NULL) { + return OQS_ERROR; + } + return (sk->lock_key(sk->mutex)); } /* OQS_SIG_STFL_SECRET_KEY_unlock */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk) { +OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk) { if (sk == NULL) { return OQS_ERROR; } if (sk->unlock_key == NULL) { return OQS_SUCCESS; } + + // Try to unlock the private key but the mutex is unset. + if (sk->mutex == NULL) { + return OQS_ERROR; + } + return (sk->unlock_key(sk->mutex)); } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index a0691a9d59..ac95842400 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -39,7 +39,8 @@ */ #if defined(__cplusplus) -extern "C" { +extern "C" +{ #endif /* Algorithm identifier for XMSS-SHA2_10_256 */ @@ -98,22 +99,22 @@ extern "C" { #define OQS_SIG_STFL_alg_lms_sha256_h25_w4 "LMS_SHA256_H25_W4" //"25/4" #define OQS_SIG_STFL_alg_lms_sha256_h25_w8 "LMS_SHA256_H25_W8" //"25/8" -//2-Level LMS +// 2-Level LMS #define OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8 "LMS_SHA256_H5_W8_H5_W8" //"5/8, 5/8" -//RFC 6554 +// RFC 6554 #define OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8 "LMS_SHA256_H10_W4_H5_W8" //"10/4, 5/8" -#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8 "LMS_SHA256_H10_W8_H5_W8" //"10/8, 5/8" +#define OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8 "LMS_SHA256_H10_W8_H5_W8" //"10/8, 5/8" #define OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2 "LMS_SHA256_H10_W2_H10_W2" //"10/2, 10/2" #define OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4 "LMS_SHA256_H10_W4_H10_W4" //"10/4, 10/4" #define OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8 "LMS_SHA256_H10_W8_H10_W8" //"10/8, 10/8" -#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8 "LMS_SHA256_H15_W8_H5_W8" //"15/8, 5/8" +#define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8 "LMS_SHA256_H15_W8_H5_W8" //"15/8, 5/8" #define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8 "LMS_SHA256_H15_W8_H10_W8" //"15/8, 10/8" #define OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8 "LMS_SHA256_H15_W8_H15_W8" //"15/8, 15/8" -#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8 "LMS_SHA256_H20_W8_H5_W8" //"20/8, 5/8" +#define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8 "LMS_SHA256_H20_W8_H5_W8" //"20/8, 5/8" #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8 "LMS_SHA256_H20_W8_H10_W8" //"20/8, 10/8" #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8 "LMS_SHA256_H20_W8_H15_W8" //"20/8, 15/8" #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8 "LMS_SHA256_H20_W8_H20_W8" //"20/8, 20/8" @@ -136,7 +137,6 @@ typedef OQS_STATUS (*secure_store_sk)(uint8_t *sk_buf, size_t buf_len, void *con /** * Application provided function to lock secret key object serialize access - * @param[in] sk pointer to the secret key object to lock * @param[in] mutex pointer to mutex struct * return OQS_SUCCESS if successful, otherwise OQS_ERROR */ @@ -144,14 +144,13 @@ typedef OQS_STATUS (*lock_key)(void *mutex); /** * Application provided function to unlock secret key object - * @param[in] sk pointer to the secret key object to unlock * @param[in] mutex pointer to mutex struct * return OQS_SUCCESS if successful, otherwise OQS_ERROR */ typedef OQS_STATUS (*unlock_key)(void *mutex); /** - * Returns identifiers for available signature schemes in liboqs. Used with OQS_SIG_STFL_new. + * Returns identifiers for available signature schemes in liboqs. Used with `OQS_SIG_STFL_new`. * * Note that algorithm identifiers are present in this list even when the algorithm is disabled * at compile time. @@ -162,12 +161,12 @@ typedef OQS_STATUS (*unlock_key)(void *mutex); OQS_API const char *OQS_SIG_STFL_alg_identifier(size_t i); /** - * Returns the number of signature mechanisms in liboqs. They can be enumerated with + * Returns the number of stateful signature mechanisms in liboqs. They can be enumerated with * OQS_SIG_STFL_alg_identifier. * * Note that some mechanisms may be disabled at compile time. * - * @return The number of signature mechanisms. + * @return The number of stateful signature mechanisms. */ OQS_API int OQS_SIG_STFL_alg_count(void); @@ -186,7 +185,7 @@ typedef struct OQS_SIG_STFL { /** * A local ordinal representing the LMS/XMSS OID parameter of the signature scheme. - * This OID is unrelated to ASN.1 OID or anything, it's only for LMS/XMSS internal usage. + * This OID is unrelated to ASN.1 OID, it's only for LMS/XMSS internal usage. */ uint32_t oid; @@ -227,6 +226,10 @@ typedef struct OQS_SIG_STFL { /** * Signature generation algorithm. * + * For stateful signatures, there is always a limited number of signatures that can be used, + * The private key signature counter is increased by one once a signature is successfully generated, + * When the signature counter reaches the maximum number of available signatures, the signature generation always fails. + * * Caller is responsible for allocating sufficient memory for `signature`, * based on the `length_*` members in this object or the per-scheme * compile-time macros `OQS_SIG_STFL_*_length_*`. @@ -237,6 +240,9 @@ typedef struct OQS_SIG_STFL { * @param[in] message_len The length of the message to sign. * @param[in] secret_key The secret key object pointer. * @return OQS_SUCCESS or OQS_ERROR + * + * @note Internally, if `lock/unlock` functions and `mutex` are set, it will attempt to lock the private key and unlock + * the private key after the Signing operation is completed. */ OQS_STATUS (*sign)(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -253,7 +259,9 @@ typedef struct OQS_SIG_STFL { OQS_STATUS (*verify)(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); /** - * Query number of remaining signatures + * Query the number of remaining signatures. + * + * The remaining signatures are the number of signatures available before the private key runs out of its total signature and expires. * * @param[out] remain The number of remaining signatures * @param[in] secret_key The secret key object pointer. @@ -262,7 +270,9 @@ typedef struct OQS_SIG_STFL { OQS_STATUS (*sigs_remaining)(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); /** - * Total number of signatures + * Query the total number of signatures. + * + * The total number of signatures is the constant number present in how many signatures can be generated from a private key. * * @param[out] total The total number of signatures * @param[in] secret_key The secret key key object pointer. @@ -284,37 +294,46 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /* The (maximum) length, in bytes, of secret keys for this signature scheme. */ size_t length_secret_key; - /* The variant-specific secret key data, must be allocated at the initialization. */ + /* The variant-specific secret key data must be allocated at the initialization. */ void *secret_key_data; - /* mutual exclusion struct */ + /* The mutual exclusion struct */ void *mutex; - /* Application managed data related to secure storage of secret key data */ + /* Application-managed data related to secure storage of secret key data */ void *context; /** - * Secret Key retrieval Function + * Serialize the stateful secret key. * - * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object - * @param[out] sk_len length of the private key as a byte stream - * @param[out] sk_buf_ptr pointer to private key data as a byte stream - * @returns length of key material data available - * Caller is responsible for **deallocating** the pointer to buffer `sk_buf_ptr`. + * This function encodes the stateful secret key represented by `sk` into a byte stream + * for storage or transfer. The `sk_buf_ptr` will point to the allocated memory containing + * the byte stream. Users must free the `sk_buf_ptr` using `OQS_MEM_secure_free` after use. + * The `sk_len` will contain the length of the byte stream. + * + * @param[out] sk_buf_ptr Pointer to the byte stream representing the serialized secret key. + * @param[out] sk_len Pointer to the length of the serialized byte stream. + * @param[in] sk Pointer to the `OQS_SIG_STFL_SECRET_KEY` object to serialize. + * @return The number of bytes in the serialized byte stream upon success, or an OQS error code on failure. + * + * @attention The caller is responsible for ensuring that `sk` is a valid object before calling this function. */ OQS_STATUS (*serialize_key)(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); /** - * Secret Key to internal structure Function + * Deserialize a byte stream into the internal representation of a stateful secret key. + * + * This function takes a series of bytes representing a stateful secret key and initializes + * the internal `OQS_SIG_STFL_SECRET_KEY` object with the key material. This is particularly + * useful for reconstructing key objects from persisted or transmitted state. + * + * @param[out] sk Pointer to an uninitialized `OQS_SIG_STFL_SECRET_KEY` object to hold the secret key. + * @param[in] sk_len The length of the secret key byte stream. + * @param[in] sk_buf Pointer to the byte stream containing the serialized secret key data. + * @param[in] context Pointer to application-specific data, handled externally, associated with the key. + * @returns OQS_SUCCESS if the deserialization succeeds, with the `sk` object populated with the key material. * - * @param[in] sk OQS_SIG_STFL_SECRET_KEY object - * @param[in] key_len length of the returned byte string - * @param[in] sk_buf The secret key data to populate the key object - * @param[in] context application-specific data - * used to keep track of this secret key stored in a secure manner. - * The application manages this memory. - * @returns status of the operation populated with key material none zero length. - * Caller is responsible to **unallocate** the buffer `sk_buf`. + * @attention The caller is responsible for ensuring that `sk_buf` is securely deallocated when it's no longer needed. */ OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); @@ -336,42 +355,48 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { /** * Store Secret Key Function + * * Callback function used to securely store key data after a signature generation. - * When populated, this pointer points to the application supplied secure storage function. + * When populated, this pointer points to the application-supplied secure storage function. * @param[in] sk_buf The serialized secret key data to secure store * @param[in] buf_len length of data to secure * @param[in] context application supplied data used to locate where this secret key * is stored (passed in at the time the function pointer was set). * * @return OQS_SUCCESS or OQS_ERROR - * Ideally written to secure device + * Ideally written to a secure device. */ OQS_STATUS (*secure_store_scrt_key)(uint8_t *sk_buf, size_t buf_len, void *context); /** * Free internal variant-specific data * - * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object - * @return none + * @param[in] sk The secret key represented as OQS_SIG_STFL_SECRET_KEY object. + * @return None. */ void (*free_key)(OQS_SIG_STFL_SECRET_KEY *sk); - /* - * Secure storage for private keys used in stateful signature schemes is outside the scope of the OQS library. - * This is the responsibility of any adopting application. The application must supply - * a function to for this purpose. A callback function and context data must be set in-order - * to perform stateful signature generation. - * The context var may contain, for example an HSM context, a filename or other such data that - * is used to store the private key. This var is passed into the OQS lib when the application sets - * the callback function use to save/update the private key. - */ /** - * Set Secret Key store callback Function + * Set Secret Key Store Callback Function + * + * This function is used to establish a callback mechanism for secure storage + * of private keys involved in stateful signature Signing operation. The secure storage + * and the management of private keys is the responsibility of the adopting application. + * Therefore, before invoking stateful signature generation, a callback function and + * associated context data must be provided by the application to manage the storage. * - * @param[in] sk secret key pointer to be updated - * @param[in] store_cb callback pointer - * @param[in] context application data related to secret key data/identifier storage. - * Provided when OQS_SIG_STFL_SECRET_KEY_SET_store_cb() is called. + * The `context` argument is designed to hold information requisite for private key storage, + * such as a hardware security module (HSM) context, a file path, or other relevant data. + * This context is passed to the libOQS when the callback function is registered. + * + * @param[in] sk A pointer to the secret key object that requires secure storage management + * after signature Signing operations. + * @param[in] store_cb A pointer to the callback function provided by the application + * for storing and updating the private key securely. + * @param[in] context Application-specific context information for the private key storage, + * furnished when setting the callback function via + * OQS_SIG_STFL_SECRET_KEY_set_store_cb(). + * @return None. */ void (*set_scrt_key_store_cb)(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); } OQS_SIG_STFL_SECRET_KEY; @@ -393,7 +418,7 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name); * Caller is responsible for allocating sufficient memory for `public_key` based * on the `length_*` members in this object or the per-scheme compile-time macros * `OQS_SIG_STFL_*_length_*`. The caller is also responsible for initializing - * `secret_key` using the OQS_SIG_STFL_SECRET_KEY(*) function + * `secret_key` using the OQS_SIG_STFL_SECRET_KEY(*) function. * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. * @param[out] public_key The public key is represented as a byte string. @@ -405,6 +430,10 @@ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public /** * Signature generation algorithm. * + * For stateful signatures, there is always a limited number of signatures that can be used, + * The private key signature counter is increased by one once a signature is successfully generated, + * When the signature counter reaches the maximum number of available signatures, the signature generation always fails. + * * Caller is responsible for allocating sufficient memory for `signature`, * based on the `length_*` members in this object or the per-scheme * compile-time macros `OQS_SIG_STFL_*_length_*`. @@ -416,6 +445,9 @@ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public * @param[in] message_len The length of the message to sign. * @param[in] secret_key The secret key object pointer. * @return OQS_SUCCESS or OQS_ERROR + * + * @note Internally, if `lock/unlock` functions and `mutex` are set, it will attempt to lock the private key and unlock + * the private key after the Signing operation is completed. */ OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -433,7 +465,9 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key); /** - * Query number of remaining signatures + * Query the number of remaining signatures. + * + * The remaining signatures are the number of signatures available before the private key runs out of its total signature and expires. * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. * @param[in] secret_key The secret key object. @@ -442,7 +476,9 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key); /** - * * Total number of signatures + * Query the total number of signatures. + * + * The total number of signatures is the constant number present in how many signatures can be generated from a private key. * * @param[in] sig The OQS_SIG_STFL object representing the signature scheme. * @param[out] max The number of remaining signatures @@ -452,13 +488,13 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const OQS_SIG_STFL_SECRET_KEY *secret_key); /** - * Frees an OQS_SIG_STFL object that was constructed by OQS_SIG_STFL_new. + * Free an OQS_SIG_STFL object that was constructed by OQS_SIG_STFL_new. * */ OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig); /** - * Constructs an OQS_SIG_STFL_SECRET_KEY object for a particular algorithm. + * Construct an OQS_SIG_STFL_SECRET_KEY object for a particular algorithm. * * Callers should always check whether the return value is `NULL`, which indicates either than an * invalid algorithm name was provided, or that the requested algorithm was disabled at compile-time. @@ -469,7 +505,7 @@ OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_name); /** - * Frees an OQS_SIG_STFL_SECRET_KEY object that was constructed by OQS_SECRET_KEY_new. + * Free an OQS_SIG_STFL_SECRET_KEY object that was constructed by OQS_SECRET_KEY_new. * * @param[in] sig The OQS_SIG_STFL_SECRET_KEY object to free. * @return OQS_SUCCESS if successful, or OQS_ERROR if the object cannot be freed. @@ -477,97 +513,141 @@ OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SIG_STFL_SECRET_KEY_new(const char *method_ OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk); /** - * OQS_SIG_STFL_SECRET_KEY_SET_lock . + * Attach a locking mechanism to a secret key object. * - * Sets function to prevent multiple processes from using the sk at the same time. + * This allows for proper synchronization in a multi-threaded or multi-process environment, + * by ensuring that a secret key is not used concurrently by multiple entities, which could otherwise lead to security issues. * - * @param[in] sk secret key pointer to be updated - * @param[in] lock function pointer + * @param[in] sk Pointer to the secret key object whose lock function is to be set. + * @param[in] lock Function pointer to the locking routine provided by the application. + * @return None. * + * @note It's not required to set the lock and unlock functions in a single-threaded environment. + * + * @note Once the `lock` function is set, users must also set the `mutex` and `unlock` functions. + * + * @note By default, the internal value of `sk->lock` is NULL, which does nothing to lock the private key. */ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_lock(OQS_SIG_STFL_SECRET_KEY *sk, lock_key lock); /** - * OQS_SIG_STFL_SECRET_KEY_SET_unlock . + * Attach an unlock mechanism to a secret key object. + * + * This allows for proper synchronization in a multi-threaded or multi-process environment, + * by ensuring that a secret key is not used concurrently by multiple entities, which could otherwise lead to security issues. + * + * @param[in] sk Pointer to the secret key object whose unlock function is to be set. + * @param[in] unlock Function pointer to the unlock routine provided by the application. + * @return None. * - * Sets function to prevent multiple processes from using the sk at the same time. + * @note It's not required to set the lock and unlock functions in a single-threaded environment. * - * @param[in] sk secret key pointer to be updated - * @param[in] unlock function pointer + * @note Once the `unlock` function is set, users must also set the `mutex` and `lock` functions. * + * @note By default, the internal value of `sk->unlock` is NULL, which does nothing to unlock the private key. */ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_unlock(OQS_SIG_STFL_SECRET_KEY *sk, unlock_key unlock); /** - * OQS_SIG_STFL_SECRET_KEY_SET_mutex . + * Assign a mutex function to handle concurrency control over the secret key. * - * Sets function to prevent multiple processes from using the sk at the same time. + * This is to ensure that only one process can access or modify the key at any given time. * - * @param[in] sk secret key pointer to be updated - * @param[in] mutex function pointer + * @param[in] sk A pointer to the secret key that the mutex functionality will protect. + * @param[in] mutex A function pointer to the desired concurrency control mechanism. + * @return None. * + * @note It's not required to set the lock and unlock functions in a single-threaded environment. + * + * @note By default, the internal value of `sk->mutex` is NULL, it must be set to be used in `lock` or `unlock` the private key. */ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_mutex(OQS_SIG_STFL_SECRET_KEY *sk, void *mutex); /** - * OQS_SIG_STFL_SECRET_KEY_lock . + * Lock the secret key to ensure exclusive access in a concurrent environment. + * + * If the `mutex` is not set, this lock operation will fail. + * This lock operation is essential in multi-threaded or multi-process contexts + * to prevent simultaneous Signing operations that could compromise the stateful signature security. + * + * @warning If the `lock` function is set and `mutex` is not set, this lock operation will fail. * - * Locks the secret key so only one application that holds the lock can access it. + * @param[in] sk Pointer to the secret key to be locked. + * @return OQS_SUCCESS if the lock is successfully applied; OQS_ERROR otherwise. * - * @param[in] sk secret key pointer to be locked - * @return OQS_SUCCESS if successful, or OQS_ERROR if the object fails to apply the lock + * @note It's not necessary to use this function in either Keygen or Verifying operations. + * In a concurrent environment, the user is responsible for locking and unlocking the private key, + * to make sure that only one thread can access the private key during a Signing operation. * + * @note If the `lock` function and `mutex` are both set, proceed to lock the private key. */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk); +OQS_STATUS OQS_SIG_STFL_SECRET_KEY_lock(OQS_SIG_STFL_SECRET_KEY *sk); /** - * OQS_SIG_STFL_SECRET_KEY_unlock . + * Unlock the secret key, making it accessible to other processes. * - * Unlocks the secret key so that the next process can access it. + * This function is crucial in environments where multiple processes need to coordinate access to + * the secret key, as it allows a process to signal that it has finished using the key, so + * others can safely use it. * - * @param[in] sk secret key pointer - * @return OQS_SUCCESS if successful, or OQS_ERROR if the object fails to release the lock + * @warning If the `unlock` function is set and `mutex` is not set, this unlock operation will fail. * + * @param[in] sk Pointer to the secret key whose lock should be released. + * @return OQS_SUCCESS if the lock was successfully released; otherwise, OQS_ERROR. + * + * @note It's not necessary to use this function in either Keygen or Verifying operations. + * In a concurrent environment, the user is responsible for locking and unlocking the private key, + * to make sure that only one thread can access the private key during a Signing operation. + * + * @note If the `unlock` function and `mutex` are both set, proceed to unlock the private key. */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); +OQS_STATUS OQS_SIG_STFL_SECRET_KEY_unlock(OQS_SIG_STFL_SECRET_KEY *sk); /** - * OQS_SIG_STFL_SECRET_KEY_SET_store_cb . - * - * Can be called after creating a new stateful secret key has been generated. - * Allows the lib to securely store and update the secret key after a sign operation. - * - * @param[in] sk secret key pointer to be updated - * @param[in] store_cb callback pointer - * @param[in] context application data related to where/how secret key data storage. - * Applications allocates, tracks, deallocates this. Signature generation fails without this set. - * + * Set the callback and context for securely storing a stateful secret key. + * + * This function is designed to be called after a new stateful secret key + * has been generated. It enables the library to securely store secret key + * and update it every time a Signing operation occurs. + * Without properly setting this callback and context, signature generation + * will not succeed as the updated state of the secret key cannot be preserved. + * + * @param[in] sk Pointer to the stateful secret key to be managed. + * @param[in] store_cb Callback function that handles the secure storage of the key. + * @param[in] context Application-specific context that assists in the storage of secret key data. + * This context is managed by the application, which allocates it, keeps track of it, + * and deallocates it as necessary. + * @return None. */ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); /** - * OQS_SECRET_KEY_STFL_serialize_key . + * Serialize the stateful secret key data into a byte array. + * + * Converts an OQS_SIG_STFL_SECRET_KEY object into a byte array for storage or transmission. * - * Serialize stateful secret key data into a byte string, and - * return an allocated buffer. Users are responsible for deallocating - * the buffer `sk_buf_ptr`. + * @param[out] sk_buf_ptr Pointer to the allocated byte array containing the serialized key. + * @param[out] sk_len Length of the serialized key byte array. + * @param[in] sk Pointer to the OQS_SIG_STFL_SECRET_KEY object to be serialized. + * @return OQS_SUCCESS on success, or an OQS error code on failure. * - * @param[out] sk_buf_ptr secret key buffer returned. Caller deletes. - * @param[out] sk_len size of the buffer returned - * @param[in] sk secret key pointer to be serialize + * @note The function allocates memory for the byte array, and it is the caller's responsibility to free this memory after use. */ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); /** - * OQS_SECRET_KEY_STFL_deserialize_key . + * Deserialize a byte array into an OQS_SIG_STFL_SECRET_KEY object. + * + * Transforms a binary representation of a secret key into an OQS_SIG_STFL_SECRET_KEY structure. + * After deserialization, the secret key object can be used for subsequent cryptographic operations. * - * Insert stateful byte string into a secret key object. - * Users are responsible for deallocating buffer `sk_buf`. + * @param[out] sk A pointer to the secret key object that will be populated from the binary data. + * @param[in] key_len The length of the binary secret key data in bytes. + * @param[in] sk_buf The buffer containing the serialized secret key data. + * @param[in] context Application-specific data used to maintain context about the secret key. + * @return OQS_SUCCESS if deserialization was successful; otherwise, OQS_ERROR. * - * @param[in] sk secret key pointer to be populated - * @param[in] sk_len size of the supplied buffer - * @param[in] sk_buf secret key buffer. Caller deletes. - * @param[in] context application managed data related to where/how secret key data is stored. + * @attention The caller is responsible for freeing the `sk_buf` memory when it is no longer needed. */ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf, void *context); From cf03392510f426da2f1283b4c709d39fb92bcaf8 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Sat, 13 Jan 2024 00:27:58 -0500 Subject: [PATCH 29/68] Update README.md Co-authored-by: Spencer Wilson --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 926a8ce28a..1f549a3b14 100644 --- a/README.md +++ b/README.md @@ -126,7 +126,7 @@ The following instructions assume we are in `build`. - `test_kem`: Simple test harness for key encapsulation mechanisms - `test_sig`: Simple test harness for key signature schemes - - `test_sig_stfl`: Simple test harness for stateful key signature schemes + - `test_sig_stfl`: Simple test harness for stateful signature schemes - `test_kem_mem`: Simple test harness for checking memory consumption of key encapsulation mechanisms - `test_sig_mem`: Simple test harness for checking memory consumption of key signature schemes - `kat_kem`: Program that generates known answer test (KAT) values for key encapsulation mechanisms using the same procedure as the NIST submission requirements, for checking against submitted KAT values using `tests/test_kat.py` From 93257132a7b4687674803fd903ab986a32fd1143 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Sat, 13 Jan 2024 00:28:28 -0500 Subject: [PATCH 30/68] Update README.md Co-authored-by: Spencer Wilson --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 1f549a3b14..7baf922749 100644 --- a/README.md +++ b/README.md @@ -125,7 +125,7 @@ The following instructions assume we are in `build`. 3. By default the main build result is `lib/liboqs.a`, a static library. If you want to build a shared/dynamic library, append [`-DBUILD_SHARED_LIBS=ON`](CONFIGURE.md#build_shared_libs) to the `cmake -GNinja ..` command above and the result will be `lib/liboqs.so|dylib|dll`. The public headers are located in the `include` directory. There are also a variety of programs built under the `tests` directory: - `test_kem`: Simple test harness for key encapsulation mechanisms - - `test_sig`: Simple test harness for key signature schemes + - `test_sig`: Simple test harness for signature schemes - `test_sig_stfl`: Simple test harness for stateful signature schemes - `test_kem_mem`: Simple test harness for checking memory consumption of key encapsulation mechanisms - `test_sig_mem`: Simple test harness for checking memory consumption of key signature schemes From a52b2176eceed0ccff2df31302907b50c8d2dc22 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Sat, 13 Jan 2024 00:28:45 -0500 Subject: [PATCH 31/68] Update README.md Co-authored-by: Spencer Wilson --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 7baf922749..c589d7c18b 100644 --- a/README.md +++ b/README.md @@ -128,7 +128,7 @@ The following instructions assume we are in `build`. - `test_sig`: Simple test harness for signature schemes - `test_sig_stfl`: Simple test harness for stateful signature schemes - `test_kem_mem`: Simple test harness for checking memory consumption of key encapsulation mechanisms - - `test_sig_mem`: Simple test harness for checking memory consumption of key signature schemes + - `test_sig_mem`: Simple test harness for checking memory consumption of signature schemes - `kat_kem`: Program that generates known answer test (KAT) values for key encapsulation mechanisms using the same procedure as the NIST submission requirements, for checking against submitted KAT values using `tests/test_kat.py` - `kat_sig`: Program that generates known answer test (KAT) values for signature schemes using the same procedure as the NIST submission requirements, for checking against submitted KAT values using `tests/test_kat.py` - `kat_stfl_sig`: Program for checking results against submitted KAT values using `tests/test_kat.py` From d442ac9ba861f9171b45a34de148f935a5de600d Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Sat, 13 Jan 2024 00:29:05 -0500 Subject: [PATCH 32/68] Update README.md Co-authored-by: Spencer Wilson --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index c589d7c18b..0752ad5163 100644 --- a/README.md +++ b/README.md @@ -131,7 +131,7 @@ The following instructions assume we are in `build`. - `test_sig_mem`: Simple test harness for checking memory consumption of signature schemes - `kat_kem`: Program that generates known answer test (KAT) values for key encapsulation mechanisms using the same procedure as the NIST submission requirements, for checking against submitted KAT values using `tests/test_kat.py` - `kat_sig`: Program that generates known answer test (KAT) values for signature schemes using the same procedure as the NIST submission requirements, for checking against submitted KAT values using `tests/test_kat.py` - - `kat_stfl_sig`: Program for checking results against submitted KAT values using `tests/test_kat.py` + - `kat_sig_stfl`: Program for checking results against submitted KAT values using `tests/test_kat.py` - `speed_kem`: Benchmarking program for key encapsulation mechanisms; see `./speed_kem --help` for usage instructions - `speed_sig`: Benchmarking program for signature mechanisms; see `./speed_sig --help` for usage instructions - `example_kem`: Minimal runnable example showing the usage of the KEM API From 72ab47826cac51e47ea00cfccdeac2bc4c9c0485 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Sat, 13 Jan 2024 00:32:50 -0500 Subject: [PATCH 33/68] Update README.md --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 0752ad5163..b47b82d660 100644 --- a/README.md +++ b/README.md @@ -136,6 +136,7 @@ The following instructions assume we are in `build`. - `speed_sig`: Benchmarking program for signature mechanisms; see `./speed_sig --help` for usage instructions - `example_kem`: Minimal runnable example showing the usage of the KEM API - `example_sig`: Minimal runnable example showing the usage of the signature API + - `example_sig_stfl`: Minimal runnable example showing the usage of the stateful signature API - `test_aes`, `test_sha3`: Simple test harnesses for crypto sub-components - `test_portability`: Simple test harnesses for checking cross-CPU code portability; requires presence of `qemu`; proper operation validated only on Ubuntu From 5967f12281ac99b206407c44e340026fdb2ef7c7 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Sat, 13 Jan 2024 00:33:57 -0500 Subject: [PATCH 34/68] Update src/CMakeLists.txt Co-authored-by: Spencer Wilson --- src/CMakeLists.txt | 2 -- 1 file changed, 2 deletions(-) diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt index b6772ee9ff..a5b64fd294 100644 --- a/src/CMakeLists.txt +++ b/src/CMakeLists.txt @@ -73,8 +73,6 @@ add_library(oqs kem/kem.c ${SIG_OBJS} sig_stfl/sig_stfl.c ${SIG_STFL_OBJS} - sig_stfl/sig_stfl.c - ${SIG_STFL_OBJS} ${COMMON_OBJS}) # Internal library to be used only by test programs From fc6d512ac18d08727a73b4232f1f5030eced7fe0 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Fri, 19 Jan 2024 14:22:27 -0500 Subject: [PATCH 35/68] Update documentation and license text. (#1663) * Update documentation and license text. * Fix missing CR in calls to printf * Updates per review comments --- docs/algorithms/sig_stfl/lms.md | 50 ++++ docs/algorithms/sig_stfl/lms.yml | 216 ++++++++++++++++++ docs/algorithms/sig_stfl/sig_stfl.md | 29 +++ docs/algorithms/sig_stfl/xmss.md | 44 ++++ docs/algorithms/sig_stfl/xmss.yml | 187 +++++++++++++++ scripts/update_docs_from_yaml.py | 61 +++++ src/sig_stfl/lms/external/common_defs.h | 1 + src/sig_stfl/lms/external/config.h | 1 + src/sig_stfl/lms/external/endian.c | 1 + src/sig_stfl/lms/external/endian.h | 1 + src/sig_stfl/lms/external/hash.c | 1 + src/sig_stfl/lms/external/hash.h | 1 + src/sig_stfl/lms/external/hss.c | 1 + src/sig_stfl/lms/external/hss.h | 1 + src/sig_stfl/lms/external/hss_alloc.c | 1 + src/sig_stfl/lms/external/hss_aux.c | 1 + src/sig_stfl/lms/external/hss_aux.h | 1 + src/sig_stfl/lms/external/hss_common.c | 1 + src/sig_stfl/lms/external/hss_common.h | 1 + src/sig_stfl/lms/external/hss_compute.c | 1 + src/sig_stfl/lms/external/hss_derive.c | 1 + src/sig_stfl/lms/external/hss_derive.h | 1 + src/sig_stfl/lms/external/hss_generate.c | 1 + src/sig_stfl/lms/external/hss_internal.h | 1 + src/sig_stfl/lms/external/hss_keygen.c | 1 + src/sig_stfl/lms/external/hss_param.c | 1 + src/sig_stfl/lms/external/hss_reserve.c | 1 + src/sig_stfl/lms/external/hss_reserve.h | 1 + src/sig_stfl/lms/external/hss_sign.c | 1 + src/sig_stfl/lms/external/hss_sign_inc.c | 1 + src/sig_stfl/lms/external/hss_sign_inc.h | 1 + src/sig_stfl/lms/external/hss_thread.h | 1 + .../lms/external/hss_thread_pthread.c | 1 + src/sig_stfl/lms/external/hss_thread_single.c | 1 + src/sig_stfl/lms/external/hss_verify.c | 1 + src/sig_stfl/lms/external/hss_verify.h | 1 + src/sig_stfl/lms/external/hss_verify_inc.c | 1 + src/sig_stfl/lms/external/hss_verify_inc.h | 1 + src/sig_stfl/lms/external/hss_zeroize.c | 1 + src/sig_stfl/lms/external/hss_zeroize.h | 1 + src/sig_stfl/lms/external/license.txt | 29 +++ src/sig_stfl/lms/external/lm_common.c | 1 + src/sig_stfl/lms/external/lm_common.h | 1 + src/sig_stfl/lms/external/lm_ots.h | 1 + src/sig_stfl/lms/external/lm_ots_common.c | 1 + src/sig_stfl/lms/external/lm_ots_common.h | 1 + src/sig_stfl/lms/external/lm_ots_sign.c | 1 + src/sig_stfl/lms/external/lm_ots_verify.c | 1 + src/sig_stfl/lms/external/lm_ots_verify.h | 1 + src/sig_stfl/lms/external/lm_verify.c | 1 + src/sig_stfl/lms/external/lm_verify.h | 1 + src/sig_stfl/lms/external/lms_namespace.h | 1 + 52 files changed, 661 insertions(+) create mode 100644 docs/algorithms/sig_stfl/lms.md create mode 100644 docs/algorithms/sig_stfl/lms.yml create mode 100644 docs/algorithms/sig_stfl/sig_stfl.md create mode 100644 docs/algorithms/sig_stfl/xmss.md create mode 100644 docs/algorithms/sig_stfl/xmss.yml create mode 100644 src/sig_stfl/lms/external/license.txt diff --git a/docs/algorithms/sig_stfl/lms.md b/docs/algorithms/sig_stfl/lms.md new file mode 100644 index 0000000000..8357d0a8f6 --- /dev/null +++ b/docs/algorithms/sig_stfl/lms.md @@ -0,0 +1,50 @@ +# LMS + +- **Algorithm type**: Digital signature scheme. +- **Main cryptographic assumption**: hash function second-preimage resistance. +- **Principal submitters**: Scott Fluhrer. +- **Auxiliary submitters**: C Martin, Maurice Hieronymus. +- **Authors' website**: https://www.rfc-editor.org/info/rfc8554 +- **Specification version**: None. +- **Primary Source**: + - **Source**: https://github.com/cisco/hash-sigs + - **Implementation license (SPDX-Identifier)**: MIT + + +## Parameter set summary + +| Parameter set | Security model | Claimed NIST Level | Public key size (bytes) | Secret key size (bytes) | Signature size (bytes) | +|:------------------------:|:-----------------|:---------------------|--------------------------:|--------------------------:|-------------------------:| +| LMS_SHA256_H5_W1 | | | 60 | 64 | 8688 | +| LMS_SHA256_H5_W2 | | | 60 | 64 | 4464 | +| LMS_SHA256_H5_W4 | | | 60 | 64 | 2352 | +| LMS_SHA256_H5_W8 | | | 60 | 64 | 1296 | +| LMS_SHA256_H10_W1 | | | 60 | 64 | 8848 | +| LMS_SHA256_H10_W2 | | | 60 | 64 | 4624 | +| LMS_SHA256_H10_W4 | | | 60 | 64 | 2512 | +| LMS_SHA256_H10_W8 | | | 60 | 64 | 1456 | +| LMS_SHA256_H15_W1 | | | 60 | 64 | 9008 | +| LMS_SHA256_H15_W2 | | | 60 | 64 | 4784 | +| LMS_SHA256_H15_W4 | | | 60 | 64 | 2672 | +| LMS_SHA256_H15_W8 | | | 60 | 64 | 1616 | +| LMS_SHA256_H20_W1 | | | 60 | 64 | 9168 | +| LMS_SHA256_H20_W2 | | | 60 | 64 | 4944 | +| LMS_SHA256_H20_W4 | | | 60 | 64 | 2832 | +| LMS_SHA256_H20_W8 | | | 60 | 64 | 1776 | +| LMS_SHA256_H25_W1 | | | 60 | 64 | 9328 | +| LMS_SHA256_H25_W2 | | | 60 | 64 | 5104 | +| LMS_SHA256_H25_W4 | | | 60 | 64 | 2992 | +| LMS_SHA256_H25_W8 | | | 60 | 64 | 1936 | +| LMS_SHA256_H5_W8_H5_W8 | | | 60 | 64 | 2644 | +| LMS_SHA256_H10_W4_H5_W8 | | | 60 | 64 | 2804 | +| LMS_SHA256_H10_W8_H5_W8 | | | 60 | 64 | 3860 | +| LMS_SHA256_H10_W2_H10_W2 | | | 60 | 64 | 9300 | +| LMS_SHA256_H10_W4_H10_W4 | | | 60 | 64 | 5076 | +| LMS_SHA256_H10_W8_H10_W8 | | | 60 | 64 | 2964 | +| LMS_SHA256_H15_W8_H5_W8 | | | 60 | 64 | 2964 | +| LMS_SHA256_H15_W8_H10_W8 | | | 60 | 64 | 3124 | +| LMS_SHA256_H15_W8_H15_W8 | | | 60 | 64 | 3284 | +| LMS_SHA256_H20_W8_H5_W8 | | | 60 | 64 | 3124 | +| LMS_SHA256_H20_W8_H10_W8 | | | 60 | 64 | 3284 | +| LMS_SHA256_H20_W8_H15_W8 | | | 60 | 64 | 3444 | +| LMS_SHA256_H20_W8_H20_W8 | | | 60 | 64 | 3604 | diff --git a/docs/algorithms/sig_stfl/lms.yml b/docs/algorithms/sig_stfl/lms.yml new file mode 100644 index 0000000000..2741a3afea --- /dev/null +++ b/docs/algorithms/sig_stfl/lms.yml @@ -0,0 +1,216 @@ +name: LMS +type: stateful signature +principal-submitters: +- Scott Fluhrer +auxiliary-submitters: +- C Martin +- Maurice Hieronymus + +crypto-assumption: hash function second-preimage resistance +website: https://www.rfc-editor.org/info/rfc8554 +nist-round: +spec-version: +spdx-license-identifier: +primary-upstream: + source: https://github.com/cisco/hash-sigs + spdx-license-identifier: MIT + upstream-ancestors: +parameter-sets: +- name: LMS_SHA256_H5_W1 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 8688 +- name: LMS_SHA256_H5_W2 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 4464 +- name: LMS_SHA256_H5_W4 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2352 +- name: LMS_SHA256_H5_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 1296 +- name: LMS_SHA256_H10_W1 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 8848 +- name: LMS_SHA256_H10_W2 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 4624 +- name: LMS_SHA256_H10_W4 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2512 +- name: LMS_SHA256_H10_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 1456 +- name: LMS_SHA256_H15_W1 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 9008 +- name: LMS_SHA256_H15_W2 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 4784 +- name: LMS_SHA256_H15_W4 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2672 +- name: LMS_SHA256_H15_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 1616 +- name: LMS_SHA256_H20_W1 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 9168 +- name: LMS_SHA256_H20_W2 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 4944 +- name: LMS_SHA256_H20_W4 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2832 +- name: LMS_SHA256_H20_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 1776 +- name: LMS_SHA256_H25_W1 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 9328 +- name: LMS_SHA256_H25_W2 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 5104 +- name: LMS_SHA256_H25_W4 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2992 +- name: LMS_SHA256_H25_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 1936 +- name: LMS_SHA256_H5_W8_H5_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2644 +- name: LMS_SHA256_H10_W4_H5_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2804 +- name: LMS_SHA256_H10_W8_H5_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 3860 +- name: LMS_SHA256_H10_W2_H10_W2 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 9300 +- name: LMS_SHA256_H10_W4_H10_W4 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 5076 +- name: LMS_SHA256_H10_W8_H10_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2964 +- name: LMS_SHA256_H15_W8_H5_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 2964 +- name: LMS_SHA256_H15_W8_H10_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 3124 +- name: LMS_SHA256_H15_W8_H15_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 3284 +- name: LMS_SHA256_H20_W8_H5_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 3124 +- name: LMS_SHA256_H20_W8_H10_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 3284 +- name: LMS_SHA256_H20_W8_H15_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 3444 +- name: LMS_SHA256_H20_W8_H20_W8 + claimed-nist-level: + claimed-security: + length-public-key: 60 + length-secret-key: 64 + length-signature: 3604 diff --git a/docs/algorithms/sig_stfl/sig_stfl.md b/docs/algorithms/sig_stfl/sig_stfl.md new file mode 100644 index 0000000000..dfd0403066 --- /dev/null +++ b/docs/algorithms/sig_stfl/sig_stfl.md @@ -0,0 +1,29 @@ + +# **Stateful Hash Based Signatures** + +The security of hash based signatures (HBS) is based on the underlying hash functions on which they are built. +NIST recommendation is that they are suitable for near term use to mitigate against attacks mounted by quantum computers. +While not a general purpose solution, they are useful means to authenticate boot or firmware images. + +**General** + +This package provides full support for a variety of variants for XMSS and LMS. +Key generation, signature generation, and signature verification. +Security of HBS also depends on the management of the state of the secret key. Secret keys can only used once to generate a signature. +Multiple signing with same key can reveal that key to an attacker. +Because of this, NIST recommends that key and signature generation be done in hardware security modules. +Having said that, this library is fully functional for research purposes. Secret keys are incremented after each sign operation. +However, secure storage and lifecycle management of the secret keys are left to applications using this feature. +Secret key storage is easily done by supplying a callback function to the library. This callback is invoked to store the secret key. + + +**Key State Management** + +Application writers have to supply callback functions to store and update secret keys. +After a sign operation the secret key index is advanced and stored. This ensures one-time use of the key. +Signing operations will fail without this callback set because the private key cannot be advanced (to prevent reuse). + +Stateful keys can generate a finite number of signatures. A counter tracks the limit when the key is created and is decremented after each signature is generated. +When the counter is down to 0, signature generation fails. Applications can query the remaining count via an API. + + diff --git a/docs/algorithms/sig_stfl/xmss.md b/docs/algorithms/sig_stfl/xmss.md new file mode 100644 index 0000000000..b78dce983b --- /dev/null +++ b/docs/algorithms/sig_stfl/xmss.md @@ -0,0 +1,44 @@ +# XMSS + +- **Algorithm type**: Digital signature scheme. +- **Main cryptographic assumption**: hash function second-preimage resistance. +- **Principal submitters**: Joost Rijneveld, A. Huelsing, David Cooper, Bas Westerbaan. +- **Authors' website**: https://www.rfc-editor.org/info/rfc8391 +- **Specification version**: None. +- **Primary Source**: + - **Source**: https://github.com/XMSS/xmss-reference + - **Implementation license (SPDX-Identifier)**: Apache-2.0 AND MIT + + +## Parameter set summary + +| Parameter set | Security model | Claimed NIST Level | Public key size (bytes) | Secret key size (bytes) | Signature size (bytes) | +|:----------------------:|:-----------------|:---------------------|--------------------------:|--------------------------:|-------------------------:| +| XMSS-SHA2_10_256 | | | 64 | 1373 | 2500 | +| XMSS-SHA2_16_256 | | | 64 | 2093 | 2692 | +| XMSS-SHA2_20_256 | | | 64 | 2573 | 2820 | +| XMSS-SHAKE_10_256 | | | 64 | 1373 | 2500 | +| XMSS-SHAKE_16_256 | | | 64 | 2093 | 2692 | +| XMSS-SHAKE_20_256 | | | 64 | 2573 | 2820 | +| XMSS-SHA2_10_512 | | | 128 | 2653 | 9092 | +| XMSS-SHA2_16_512 | | | 128 | 4045 | 9476 | +| XMSS-SHA2_20_512 | | | 128 | 2653 | 9732 | +| XMSS-SHAKE_10_512 | | | 128 | 2653 | 9092 | +| XMSS-SHAKE_16_512 | | | 128 | 4045 | 9476 | +| XMSS-SHAKE_20_512 | | | 128 | 4973 | 9732 | +| XMSSMT-SHA2_20/2_256 | | | 64 | 5998 | 4963 | +| XMSSMT-SHA2_20/4_256 | | | 64 | 10938 | 9251 | +| XMSSMT-SHA2_40/2_256 | | | 64 | 9600 | 5605 | +| XMSSMT-SHA2_40/4_256 | | | 64 | 15252 | 9893 | +| XMSSMT-SHA2_40/8_256 | | | 64 | 24516 | 18469 | +| XMSSMT-SHA2_60/3_256 | | | 64 | 16629 | 8392 | +| XMSSMT-SHA2_60/6_256 | | | 64 | 24507 | 14824 | +| XMSSMT-SHA2_60/12_256 | | | 64 | 38095 | 27688 | +| XMSSMT-SHAKE_20/2_256 | | | 64 | 5998 | 4963 | +| XMSSMT-SHAKE_20/4_256 | | | 64 | 10938 | 9251 | +| XMSSMT-SHAKE_40/2_256 | | | 64 | 9600 | 5605 | +| XMSSMT-SHAKE_40/4_256 | | | 64 | 15252 | 9893 | +| XMSSMT-SHAKE_40/8_256 | | | 64 | 24516 | 18469 | +| XMSSMT-SHAKE_60/3_256 | | | 64 | 24516 | 8392 | +| XMSSMT-SHAKE_60/6_256 | | | 64 | 24507 | 14824 | +| XMSSMT-SHAKE_60/12_256 | | | 64 | 38095 | 27688 | diff --git a/docs/algorithms/sig_stfl/xmss.yml b/docs/algorithms/sig_stfl/xmss.yml new file mode 100644 index 0000000000..bf57a7eeb8 --- /dev/null +++ b/docs/algorithms/sig_stfl/xmss.yml @@ -0,0 +1,187 @@ +name: XMSS +type: stateful signature +principal-submitters: +- Joost Rijneveld +- A. Huelsing +- David Cooper +- Bas Westerbaan +auxiliary-submitters: + +crypto-assumption: hash function second-preimage resistance +website: https://www.rfc-editor.org/info/rfc8391 +nist-round: +spec-version: +spdx-license-identifier: Apache-2.0 AND MIT +primary-upstream: + source: https://github.com/XMSS/xmss-reference + spdx-license-identifier: Apache-2.0 AND MIT + upstream-ancestors: +parameter-sets: +- name: XMSS-SHA2_10_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 1373 + length-signature: 2500 +- name: XMSS-SHA2_16_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 2093 + length-signature: 2692 +- name: XMSS-SHA2_20_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 2573 + length-signature: 2820 +- name: XMSS-SHAKE_10_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 1373 + length-signature: 2500 +- name: XMSS-SHAKE_16_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 2093 + length-signature: 2692 +- name: XMSS-SHAKE_20_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 2573 + length-signature: 2820 +- name: XMSS-SHA2_10_512 + claimed-nist-level: + claimed-security: + length-public-key: 128 + length-secret-key: 2653 + length-signature: 9092 +- name: XMSS-SHA2_16_512 + claimed-nist-level: + claimed-security: + length-public-key: 128 + length-secret-key: 4045 + length-signature: 9476 +- name: XMSS-SHA2_20_512 + claimed-nist-level: + claimed-security: + length-public-key: 128 + length-secret-key: 2653 + length-signature: 9732 +- name: XMSS-SHAKE_10_512 + claimed-nist-level: + claimed-security: + length-public-key: 128 + length-secret-key: 2653 + length-signature: 9092 +- name: XMSS-SHAKE_16_512 + claimed-nist-level: + claimed-security: + length-public-key: 128 + length-secret-key: 4045 + length-signature: 9476 +- name: XMSS-SHAKE_20_512 + claimed-nist-level: + claimed-security: + length-public-key: 128 + length-secret-key: 4973 + length-signature: 9732 +- name: XMSSMT-SHA2_20/2_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 5998 + length-signature: 4963 +- name: XMSSMT-SHA2_20/4_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 10938 + length-signature: 9251 +- name: XMSSMT-SHA2_40/2_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 9600 + length-signature: 5605 +- name: XMSSMT-SHA2_40/4_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 15252 + length-signature: 9893 +- name: XMSSMT-SHA2_40/8_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 24516 + length-signature: 18469 +- name: XMSSMT-SHA2_60/3_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 16629 + length-signature: 8392 +- name: XMSSMT-SHA2_60/6_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 24507 + length-signature: 14824 +- name: XMSSMT-SHA2_60/12_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 38095 + length-signature: 27688 +- name: XMSSMT-SHAKE_20/2_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 5998 + length-signature: 4963 +- name: XMSSMT-SHAKE_20/4_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 10938 + length-signature: 9251 +- name: XMSSMT-SHAKE_40/2_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 9600 + length-signature: 5605 +- name: XMSSMT-SHAKE_40/4_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 15252 + length-signature: 9893 +- name: XMSSMT-SHAKE_40/8_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 24516 + length-signature: 18469 +- name: XMSSMT-SHAKE_60/3_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 24516 + length-signature: 8392 +- name: XMSSMT-SHAKE_60/6_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 24507 + length-signature: 14824 +- name: XMSSMT-SHAKE_60/12_256 + claimed-nist-level: + claimed-security: + length-public-key: 64 + length-secret-key: 38095 + length-signature: 27688 \ No newline at end of file diff --git a/scripts/update_docs_from_yaml.py b/scripts/update_docs_from_yaml.py index ef152d376a..a07a81c2d0 100644 --- a/scripts/update_docs_from_yaml.py +++ b/scripts/update_docs_from_yaml.py @@ -17,6 +17,7 @@ def file_get_contents(filename, encoding=None): kem_yamls = [] sig_yamls = [] +sig_stfl_yamls = [] ######################################## # Update the KEM markdown documentation. @@ -269,6 +270,66 @@ def do_it(liboqs_root): out_md.write('- **Large Stack Usage**: Implementations identified as having such may cause failures when running in threads or in constrained environments.') + ############################################## + # Update the stateful signature markdown documentation. + ############################################## + for sig_stfl_yaml_path in sorted(glob.glob(os.path.join(liboqs_root, 'docs', 'algorithms', 'sig_stfl', '*.yml'))): + sig_stfl_yaml = load_yaml(sig_stfl_yaml_path) + sig_stfl_yamls.append(sig_stfl_yaml) + sig_stfl_name = os.path.splitext(os.path.basename(sig_stfl_yaml_path))[0] + print('Updating {}/{}.md'.format(os.path.dirname(sig_stfl_yaml_path), sig_stfl_name)) + + with open(os.path.join(liboqs_root, 'docs', 'algorithms', 'sig_stfl', '{}.md'.format(sig_stfl_name)), mode='w', encoding='utf-8') as out_md: + out_md.write('# {}\n\n'.format(sig_stfl_yaml['name'])) + out_md.write('- **Algorithm type**: Digital signature scheme.\n') + out_md.write('- **Main cryptographic assumption**: {}.\n'.format(sig_stfl_yaml['crypto-assumption'])) + out_md.write('- **Principal submitters**: {}.\n'.format(', '.join(sig_stfl_yaml['principal-submitters']))) + if 'auxiliary-submitters' in sig_stfl_yaml and sig_stfl_yaml['auxiliary-submitters']: + out_md.write('- **Auxiliary submitters**: {}.\n'.format(', '.join(sig_stfl_yaml['auxiliary-submitters']))) + out_md.write('- **Authors\' website**: {}\n'.format(sig_stfl_yaml['website'])) + out_md.write('- **Specification version**: {}.\n'.format(sig_stfl_yaml['spec-version'])) + + out_md.write('- **Primary Source**:\n') + out_md.write(' - **Source**: {}\n'.format(sig_stfl_yaml['primary-upstream']['source'])) + out_md.write(' - **Implementation license (SPDX-Identifier)**: {}\n'.format(sig_stfl_yaml['primary-upstream']['spdx-license-identifier'])) + if 'optimized-upstreams' in sig_stfl_yaml: + out_md.write('- **Optimized Implementation sources**: {}\n'.format(sig_stfl_yaml['primary-upstream']['source'])) + for opt_upstream in sig_stfl_yaml['optimized-upstreams']: + out_md.write(' - **{}**:\n'.format(opt_upstream, opt_upstream)) + out_md.write(' - **Source**: {}\n'.format(sig_stfl_yaml['optimized-upstreams'][opt_upstream]['source'])) + out_md.write(' - **Implementation license (SPDX-Identifier)**: {}\n'.format(sig_stfl_yaml['optimized-upstreams'][opt_upstream]['spdx-license-identifier'])) + + if 'upstream-ancestors' in sig_stfl_yaml: + out_md.write(', which takes it from:\n') + for url in sig_stfl_yaml['upstream-ancestors'][:-1]: + out_md.write(' - {}, which takes it from:\n'.format(url)) + out_md.write(' - {}\n'.format(sig_stfl_yaml['upstream-ancestors'][-1])) + else: + out_md.write('\n') + + if 'advisories' in sig_stfl_yaml: + out_md.write('\n## Advisories\n\n') + for advisory in sig_stfl_yaml['advisories']: + out_md.write('- {}\n'.format(advisory)) + + out_md.write('\n## Parameter set summary\n\n') + table = [['Parameter set', + 'Security model', + 'Claimed NIST Level', + 'Public key size (bytes)', + 'Secret key size (bytes)', + 'Signature size (bytes)']] + for parameter_set in sig_stfl_yaml['parameter-sets']: + table.append([parameter_set['name'], + parameter_set['claimed-security'], + parameter_set['claimed-nist-level'], + parameter_set['length-public-key'], + parameter_set['length-secret-key'], + parameter_set['length-signature']]) + out_md.write(tabulate.tabulate(table, tablefmt="pipe", headers="firstrow", colalign=("center",))) + out_md.write('\n') + + #################### # Update the README. diff --git a/src/sig_stfl/lms/external/common_defs.h b/src/sig_stfl/lms/external/common_defs.h index 83739949ee..1c7c85d382 100644 --- a/src/sig_stfl/lms/external/common_defs.h +++ b/src/sig_stfl/lms/external/common_defs.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( COMMON_DEFS_H_ ) #define COMMON_DEFS_H_ diff --git a/src/sig_stfl/lms/external/config.h b/src/sig_stfl/lms/external/config.h index e23d19fa9a..f9549858a9 100644 --- a/src/sig_stfl/lms/external/config.h +++ b/src/sig_stfl/lms/external/config.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( CONFIG_H_ ) #define CONFIG_H_ diff --git a/src/sig_stfl/lms/external/endian.c b/src/sig_stfl/lms/external/endian.c index 0c3c55b0fe..52f8439baf 100644 --- a/src/sig_stfl/lms/external/endian.c +++ b/src/sig_stfl/lms/external/endian.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #include "endian.h" void put_bigendian( void *target, unsigned long long value, size_t bytes ) { diff --git a/src/sig_stfl/lms/external/endian.h b/src/sig_stfl/lms/external/endian.h index a94177ddeb..09b9a609da 100644 --- a/src/sig_stfl/lms/external/endian.h +++ b/src/sig_stfl/lms/external/endian.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( ENDIAN_H_ ) #define ENDIAN_H_ diff --git a/src/sig_stfl/lms/external/hash.c b/src/sig_stfl/lms/external/hash.c index 0fe23ecc62..090dafd66c 100644 --- a/src/sig_stfl/lms/external/hash.c +++ b/src/sig_stfl/lms/external/hash.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #include #include "hash.h" #include "hss_zeroize.h" diff --git a/src/sig_stfl/lms/external/hash.h b/src/sig_stfl/lms/external/hash.h index 8b1891f108..bd42d3f0e9 100644 --- a/src/sig_stfl/lms/external/hash.h +++ b/src/sig_stfl/lms/external/hash.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HASH_H__ ) #define HASH_H__ #include diff --git a/src/sig_stfl/lms/external/hss.c b/src/sig_stfl/lms/external/hss.c index c38455daed..fd5342a982 100644 --- a/src/sig_stfl/lms/external/hss.c +++ b/src/sig_stfl/lms/external/hss.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is an implementation of the HSS signature scheme from LMS * This is designed to be full-featured diff --git a/src/sig_stfl/lms/external/hss.h b/src/sig_stfl/lms/external/hss.h index 5ff8fc5c52..675089ddf0 100644 --- a/src/sig_stfl/lms/external/hss.h +++ b/src/sig_stfl/lms/external/hss.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined(HSS_H_) #define HSS_H_ diff --git a/src/sig_stfl/lms/external/hss_alloc.c b/src/sig_stfl/lms/external/hss_alloc.c index 9e6e7694c1..53eaa762e2 100644 --- a/src/sig_stfl/lms/external/hss_alloc.c +++ b/src/sig_stfl/lms/external/hss_alloc.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code which allocates a working key (and initializes the fields * that are independent of the key) diff --git a/src/sig_stfl/lms/external/hss_aux.c b/src/sig_stfl/lms/external/hss_aux.c index 0d8777386f..a53b73a42b 100644 --- a/src/sig_stfl/lms/external/hss_aux.c +++ b/src/sig_stfl/lms/external/hss_aux.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the implementation of the aux data within the HSS tree */ diff --git a/src/sig_stfl/lms/external/hss_aux.h b/src/sig_stfl/lms/external/hss_aux.h index 02e6677a38..8e5386b5b3 100644 --- a/src/sig_stfl/lms/external/hss_aux.h +++ b/src/sig_stfl/lms/external/hss_aux.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_AUX_H_ ) #define HSS_AUX_H_ diff --git a/src/sig_stfl/lms/external/hss_common.c b/src/sig_stfl/lms/external/hss_common.c index d07261dd26..4c764d6650 100644 --- a/src/sig_stfl/lms/external/hss_common.c +++ b/src/sig_stfl/lms/external/hss_common.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that is common between an HSS verifier, and a full HSS * implementation that both signs and verifies diff --git a/src/sig_stfl/lms/external/hss_common.h b/src/sig_stfl/lms/external/hss_common.h index a5640d669e..17729a6a97 100644 --- a/src/sig_stfl/lms/external/hss_common.h +++ b/src/sig_stfl/lms/external/hss_common.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_COMMON_H_ ) #define HSS_COMMON_H_ diff --git a/src/sig_stfl/lms/external/hss_compute.c b/src/sig_stfl/lms/external/hss_compute.c index 752a7e2868..f4b1f3c1cd 100644 --- a/src/sig_stfl/lms/external/hss_compute.c +++ b/src/sig_stfl/lms/external/hss_compute.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This includes some computation methods that are shared between different * subsystems of the HSS signature package diff --git a/src/sig_stfl/lms/external/hss_derive.c b/src/sig_stfl/lms/external/hss_derive.c index fc8833594a..d978fc5a66 100644 --- a/src/sig_stfl/lms/external/hss_derive.c +++ b/src/sig_stfl/lms/external/hss_derive.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the file that contains the routines that generate various 'random' * values from the master seed. diff --git a/src/sig_stfl/lms/external/hss_derive.h b/src/sig_stfl/lms/external/hss_derive.h index 57ba4a1bc8..4886ab3f6a 100644 --- a/src/sig_stfl/lms/external/hss_derive.h +++ b/src/sig_stfl/lms/external/hss_derive.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_DERIVE_H_ ) #define HSS_DERIVE_H_ diff --git a/src/sig_stfl/lms/external/hss_generate.c b/src/sig_stfl/lms/external/hss_generate.c index 5d6880c267..28fcc9eaee 100644 --- a/src/sig_stfl/lms/external/hss_generate.c +++ b/src/sig_stfl/lms/external/hss_generate.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the routine that generates the ephemeral ("working") key from the * short private value. It builds all the various current, building and diff --git a/src/sig_stfl/lms/external/hss_internal.h b/src/sig_stfl/lms/external/hss_internal.h index 4e7c53675d..3458e9ef85 100644 --- a/src/sig_stfl/lms/external/hss_internal.h +++ b/src/sig_stfl/lms/external/hss_internal.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_INTERNAL_H_ ) #define HSS_INTERNAL_H_ diff --git a/src/sig_stfl/lms/external/hss_keygen.c b/src/sig_stfl/lms/external/hss_keygen.c index 7a364b3f04..71da413325 100644 --- a/src/sig_stfl/lms/external/hss_keygen.c +++ b/src/sig_stfl/lms/external/hss_keygen.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #include #include #include "common_defs.h" diff --git a/src/sig_stfl/lms/external/hss_param.c b/src/sig_stfl/lms/external/hss_param.c index a1c20ab14c..838f7a8381 100644 --- a/src/sig_stfl/lms/external/hss_param.c +++ b/src/sig_stfl/lms/external/hss_param.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #include #include "hss.h" #include "hss_internal.h" diff --git a/src/sig_stfl/lms/external/hss_reserve.c b/src/sig_stfl/lms/external/hss_reserve.c index 7ef8585560..662df26628 100644 --- a/src/sig_stfl/lms/external/hss_reserve.c +++ b/src/sig_stfl/lms/external/hss_reserve.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #include #include "common_defs.h" #include "hss_internal.h" diff --git a/src/sig_stfl/lms/external/hss_reserve.h b/src/sig_stfl/lms/external/hss_reserve.h index 14f4da3096..d5c8284cf9 100644 --- a/src/sig_stfl/lms/external/hss_reserve.h +++ b/src/sig_stfl/lms/external/hss_reserve.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_RESERVE_H_ ) #define HSS_RESERVE_H_ diff --git a/src/sig_stfl/lms/external/hss_sign.c b/src/sig_stfl/lms/external/hss_sign.c index cbcbdf845b..44e850424e 100644 --- a/src/sig_stfl/lms/external/hss_sign.c +++ b/src/sig_stfl/lms/external/hss_sign.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is an implementation of the HSS signature scheme from LMS * This is the part that actually generates the signature diff --git a/src/sig_stfl/lms/external/hss_sign_inc.c b/src/sig_stfl/lms/external/hss_sign_inc.c index 6890a4a621..72a8a22c91 100644 --- a/src/sig_stfl/lms/external/hss_sign_inc.c +++ b/src/sig_stfl/lms/external/hss_sign_inc.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that implements the hierarchical part of the LMS hash * based signatures; in this case, incremental signing diff --git a/src/sig_stfl/lms/external/hss_sign_inc.h b/src/sig_stfl/lms/external/hss_sign_inc.h index cf4f25aec6..ddca5ea63e 100644 --- a/src/sig_stfl/lms/external/hss_sign_inc.h +++ b/src/sig_stfl/lms/external/hss_sign_inc.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_SIGN_INC_H_ ) #define HSS_SIGN_INC_H_ #include diff --git a/src/sig_stfl/lms/external/hss_thread.h b/src/sig_stfl/lms/external/hss_thread.h index 0fa48e958c..d2dcd8a3ea 100644 --- a/src/sig_stfl/lms/external/hss_thread.h +++ b/src/sig_stfl/lms/external/hss_thread.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_THREAD_H_ ) #define HSS_THREAD_H_ /* diff --git a/src/sig_stfl/lms/external/hss_thread_pthread.c b/src/sig_stfl/lms/external/hss_thread_pthread.c index b5f64d3764..1ea90cc161 100644 --- a/src/sig_stfl/lms/external/hss_thread_pthread.c +++ b/src/sig_stfl/lms/external/hss_thread_pthread.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #include "hss_thread.h" #include diff --git a/src/sig_stfl/lms/external/hss_thread_single.c b/src/sig_stfl/lms/external/hss_thread_single.c index d844385293..698e2dba6a 100644 --- a/src/sig_stfl/lms/external/hss_thread_single.c +++ b/src/sig_stfl/lms/external/hss_thread_single.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #include "hss_thread.h" #include "config.h" diff --git a/src/sig_stfl/lms/external/hss_verify.c b/src/sig_stfl/lms/external/hss_verify.c index b7f0f8b489..1b993aa9b4 100644 --- a/src/sig_stfl/lms/external/hss_verify.c +++ b/src/sig_stfl/lms/external/hss_verify.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that implements the hierarchical part of the LMS hash * based signatures diff --git a/src/sig_stfl/lms/external/hss_verify.h b/src/sig_stfl/lms/external/hss_verify.h index 6561ee2a3c..d806900fe4 100644 --- a/src/sig_stfl/lms/external/hss_verify.h +++ b/src/sig_stfl/lms/external/hss_verify.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_VERIFY_H_ ) #define HSS_VERIFY_H_ diff --git a/src/sig_stfl/lms/external/hss_verify_inc.c b/src/sig_stfl/lms/external/hss_verify_inc.c index 4b5cf7e7a1..e12cf5c021 100644 --- a/src/sig_stfl/lms/external/hss_verify_inc.c +++ b/src/sig_stfl/lms/external/hss_verify_inc.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that implements the hierarchical part of the LMS hash * based signatures; in this case, incremental verification diff --git a/src/sig_stfl/lms/external/hss_verify_inc.h b/src/sig_stfl/lms/external/hss_verify_inc.h index 6c3ec74da1..c09d006e4a 100644 --- a/src/sig_stfl/lms/external/hss_verify_inc.h +++ b/src/sig_stfl/lms/external/hss_verify_inc.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_VERIFY_INC_H_ ) #define HSS_VERIFY_INC_H_ #include diff --git a/src/sig_stfl/lms/external/hss_zeroize.c b/src/sig_stfl/lms/external/hss_zeroize.c index f2bd334903..9c31168069 100644 --- a/src/sig_stfl/lms/external/hss_zeroize.c +++ b/src/sig_stfl/lms/external/hss_zeroize.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #include "hss_zeroize.h" #include diff --git a/src/sig_stfl/lms/external/hss_zeroize.h b/src/sig_stfl/lms/external/hss_zeroize.h index bfe84db155..6571c4233d 100644 --- a/src/sig_stfl/lms/external/hss_zeroize.h +++ b/src/sig_stfl/lms/external/hss_zeroize.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( HSS_ZEROIZE_H_ ) #define HSS_ZEROIZE_H_ diff --git a/src/sig_stfl/lms/external/license.txt b/src/sig_stfl/lms/external/license.txt new file mode 100644 index 0000000000..4e5a9b9b1e --- /dev/null +++ b/src/sig_stfl/lms/external/license.txt @@ -0,0 +1,29 @@ +****************************************************************************** +Copyright (c) 2017 Cisco Systems, Inc. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +Redistributions in binary form must reproduce the above + copyright notice, this list of conditions and the following + disclaimer in the documentation and/or other materials provided + with the distribution. +Neither the name of the Cisco Systems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS +FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE +COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, +INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES +(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR +SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, +STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED +OF THE POSSIBILITY OF SUCH DAMAGE. +****************************************************************************** diff --git a/src/sig_stfl/lms/external/lm_common.c b/src/sig_stfl/lms/external/lm_common.c index 5976f4b589..6f37af627e 100644 --- a/src/sig_stfl/lms/external/lm_common.c +++ b/src/sig_stfl/lms/external/lm_common.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that implements the tree part of the LMS hash * based signatures diff --git a/src/sig_stfl/lms/external/lm_common.h b/src/sig_stfl/lms/external/lm_common.h index b577c22462..c7197fd5a0 100644 --- a/src/sig_stfl/lms/external/lm_common.h +++ b/src/sig_stfl/lms/external/lm_common.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined(LM_COMMON_H_) #define LM_COMMON_H_ diff --git a/src/sig_stfl/lms/external/lm_ots.h b/src/sig_stfl/lms/external/lm_ots.h index 4e33d9e9fd..f0cc42d11f 100644 --- a/src/sig_stfl/lms/external/lm_ots.h +++ b/src/sig_stfl/lms/external/lm_ots.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( LM_OTS_H_ ) #define LM_OTS_H_ diff --git a/src/sig_stfl/lms/external/lm_ots_common.c b/src/sig_stfl/lms/external/lm_ots_common.c index 45672e18b2..100eff606a 100644 --- a/src/sig_stfl/lms/external/lm_ots_common.c +++ b/src/sig_stfl/lms/external/lm_ots_common.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that implements the one-time-signature part of the LMS hash * based signatures diff --git a/src/sig_stfl/lms/external/lm_ots_common.h b/src/sig_stfl/lms/external/lm_ots_common.h index fe6faebe98..db25d20999 100644 --- a/src/sig_stfl/lms/external/lm_ots_common.h +++ b/src/sig_stfl/lms/external/lm_ots_common.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( LM_OTS_COMMON_H_ ) #define LM_OTS_COMMON_H_ diff --git a/src/sig_stfl/lms/external/lm_ots_sign.c b/src/sig_stfl/lms/external/lm_ots_sign.c index ee8f56b0a2..7e0950c564 100644 --- a/src/sig_stfl/lms/external/lm_ots_sign.c +++ b/src/sig_stfl/lms/external/lm_ots_sign.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that implements the one-time-signature part of the LMS hash * based signatures diff --git a/src/sig_stfl/lms/external/lm_ots_verify.c b/src/sig_stfl/lms/external/lm_ots_verify.c index 478f5ffe8d..b6e3980ab7 100644 --- a/src/sig_stfl/lms/external/lm_ots_verify.c +++ b/src/sig_stfl/lms/external/lm_ots_verify.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that implements the one-time-signature part of the LMS hash * based signatures diff --git a/src/sig_stfl/lms/external/lm_ots_verify.h b/src/sig_stfl/lms/external/lm_ots_verify.h index dcf6551b0f..006ffe23bd 100644 --- a/src/sig_stfl/lms/external/lm_ots_verify.h +++ b/src/sig_stfl/lms/external/lm_ots_verify.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined( LM_OTS_VERIFY_H_ ) #define LM_OTS_VERIFY_H_ diff --git a/src/sig_stfl/lms/external/lm_verify.c b/src/sig_stfl/lms/external/lm_verify.c index 3ec4cb6599..50fa54f475 100644 --- a/src/sig_stfl/lms/external/lm_verify.c +++ b/src/sig_stfl/lms/external/lm_verify.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT /* * This is the code that implements the tree part of the LMS hash * based signatures diff --git a/src/sig_stfl/lms/external/lm_verify.h b/src/sig_stfl/lms/external/lm_verify.h index b7b6b0736d..ff67f51ac8 100644 --- a/src/sig_stfl/lms/external/lm_verify.h +++ b/src/sig_stfl/lms/external/lm_verify.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #if !defined(LM_VERIFY_H_) #define LM_VERIFY_H_ diff --git a/src/sig_stfl/lms/external/lms_namespace.h b/src/sig_stfl/lms/external/lms_namespace.h index c1b8f142ae..099a37c19b 100644 --- a/src/sig_stfl/lms/external/lms_namespace.h +++ b/src/sig_stfl/lms/external/lms_namespace.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: MIT #ifndef _LMS_NAMESPACE_H #define _LMS_NAMESPACE_H From c3e57507e57cd406c420e35ec13cdd7214402be1 Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Fri, 19 Jan 2024 14:37:07 -0500 Subject: [PATCH 36/68] Add Apache 2.0 and MIT License to XMSS (#1662) * Add Apache 2.0 and MIT License to XMSS --- CONTRIBUTORS | 1 + src/sig_stfl/xmss/CMakeLists.txt | 2 +- src/sig_stfl/xmss/LICENSE | 12 ++++++++++++ src/sig_stfl/xmss/LICENSE-MIT | 9 +++++++++ src/sig_stfl/xmss/external/core_hash.c | 1 + src/sig_stfl/xmss/external/core_hash.h | 1 + src/sig_stfl/xmss/external/hash.c | 1 + src/sig_stfl/xmss/external/hash.h | 1 + src/sig_stfl/xmss/external/hash_address.c | 1 + src/sig_stfl/xmss/external/hash_address.h | 1 + src/sig_stfl/xmss/external/namespace.h | 1 + src/sig_stfl/xmss/external/params.c | 1 + src/sig_stfl/xmss/external/params.h | 1 + src/sig_stfl/xmss/external/utils.c | 1 + src/sig_stfl/xmss/external/utils.h | 1 + src/sig_stfl/xmss/external/wots.c | 1 + src/sig_stfl/xmss/external/wots.h | 1 + src/sig_stfl/xmss/external/xmss.c | 1 + src/sig_stfl/xmss/external/xmss.h | 1 + src/sig_stfl/xmss/external/xmss_commons.c | 1 + src/sig_stfl/xmss/external/xmss_commons.h | 1 + src/sig_stfl/xmss/external/xmss_core.c | 1 + src/sig_stfl/xmss/external/xmss_core.h | 1 + src/sig_stfl/xmss/external/xmss_core_fast.c | 1 + src/sig_stfl/xmss/sig_stfl_xmss.h | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_functions.c | 3 +-- .../xmss/sig_stfl_xmss_secret_key_functions.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c | 2 +- 56 files changed, 75 insertions(+), 34 deletions(-) create mode 100644 src/sig_stfl/xmss/LICENSE create mode 100644 src/sig_stfl/xmss/LICENSE-MIT diff --git a/CONTRIBUTORS b/CONTRIBUTORS index 918394b8c4..83d9337ca5 100644 --- a/CONTRIBUTORS +++ b/CONTRIBUTORS @@ -34,5 +34,6 @@ Karolin Varner Sebastian Verschoor (University of Waterloo) Thom Wiggers (Radboud University) Dindyal Jeevesh Rishi (University of Mauritius / cyberstorm.mu) +Duc Tri Nguyen See additional contributors at https://github.com/open-quantum-safe/liboqs/graphs/contributors diff --git a/src/sig_stfl/xmss/CMakeLists.txt b/src/sig_stfl/xmss/CMakeLists.txt index e1d287472f..dc57732e16 100644 --- a/src/sig_stfl/xmss/CMakeLists.txt +++ b/src/sig_stfl/xmss/CMakeLists.txt @@ -1,4 +1,4 @@ -# SPDX-License-Identifier: MIT +# SPDX-License-Identifier: Apache-2.0 AND MIT set(_XMSS_OBJS "") diff --git a/src/sig_stfl/xmss/LICENSE b/src/sig_stfl/xmss/LICENSE new file mode 100644 index 0000000000..90a1bebcfa --- /dev/null +++ b/src/sig_stfl/xmss/LICENSE @@ -0,0 +1,12 @@ +## License + +This XMSS reference implementation is Copyright (c) 2024 SandboxAQ and licensed under both the [Apache License, Version 2.0](https://www.apache.org/licenses/LICENSE-2.0.txt) and [MIT License](LICENSE-MIT). + +Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions. + +This XMSS reference implementation is based on the [XMSS reference implementation written by Andreas Hülsing and Joost Rijneveld](https://github.com/XMSS/xmss-reference#license) provided under the CC0 1.0 Universal Public Domain Dedication. + + +## Disclaimer + +The software and documentation are provided "as is" and SandboxAQ hereby disclaims all warranties, whether express, implied, statutory, or otherwise. SandboxAQ specifically disclaims, without limitation, all implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement, and all warranties arising from course of dealing, usage, or trade practice. SandboxAQ makes no warranty of any kind that the software and documentation, or any products or results of the use thereof, will meet any person's requirements, operate without interruption, achieve any intended result, be compatible or work with any software, system or other services, or be secure, accurate, complete, free of harmful code, or error-free. \ No newline at end of file diff --git a/src/sig_stfl/xmss/LICENSE-MIT b/src/sig_stfl/xmss/LICENSE-MIT new file mode 100644 index 0000000000..7b1af979f6 --- /dev/null +++ b/src/sig_stfl/xmss/LICENSE-MIT @@ -0,0 +1,9 @@ +The MIT License (MIT) + +Copyright © 2024 SandboxAQ + +Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/src/sig_stfl/xmss/external/core_hash.c b/src/sig_stfl/xmss/external/core_hash.c index b27ad2ca9b..72fe4e9d5c 100644 --- a/src/sig_stfl/xmss/external/core_hash.c +++ b/src/sig_stfl/xmss/external/core_hash.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include #include "core_hash.h" diff --git a/src/sig_stfl/xmss/external/core_hash.h b/src/sig_stfl/xmss/external/core_hash.h index f350857d14..e292e4c06d 100644 --- a/src/sig_stfl/xmss/external/core_hash.h +++ b/src/sig_stfl/xmss/external/core_hash.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef CORE_HASH #define CORE_HASH diff --git a/src/sig_stfl/xmss/external/hash.c b/src/sig_stfl/xmss/external/hash.c index a6bac00724..557c8de7db 100644 --- a/src/sig_stfl/xmss/external/hash.c +++ b/src/sig_stfl/xmss/external/hash.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/external/hash.h b/src/sig_stfl/xmss/external/hash.h index 076b3b56ec..bd1e1c1202 100644 --- a/src/sig_stfl/xmss/external/hash.h +++ b/src/sig_stfl/xmss/external/hash.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_HASH_H #define XMSS_HASH_H diff --git a/src/sig_stfl/xmss/external/hash_address.c b/src/sig_stfl/xmss/external/hash_address.c index 7aacee5a58..a9fec506b5 100644 --- a/src/sig_stfl/xmss/external/hash_address.c +++ b/src/sig_stfl/xmss/external/hash_address.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include "hash_address.h" diff --git a/src/sig_stfl/xmss/external/hash_address.h b/src/sig_stfl/xmss/external/hash_address.h index 50ad17885e..06f5c502bd 100644 --- a/src/sig_stfl/xmss/external/hash_address.h +++ b/src/sig_stfl/xmss/external/hash_address.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_HASH_ADDRESS_H #define XMSS_HASH_ADDRESS_H diff --git a/src/sig_stfl/xmss/external/namespace.h b/src/sig_stfl/xmss/external/namespace.h index 468388aa3b..7bb7d05349 100644 --- a/src/sig_stfl/xmss/external/namespace.h +++ b/src/sig_stfl/xmss/external/namespace.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_NAMESPACE_H #define XMSS_NAMESPACE_H diff --git a/src/sig_stfl/xmss/external/params.c b/src/sig_stfl/xmss/external/params.c index fdb9c76f2c..f9ba544e47 100644 --- a/src/sig_stfl/xmss/external/params.c +++ b/src/sig_stfl/xmss/external/params.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/external/params.h b/src/sig_stfl/xmss/external/params.h index 59b86d3da6..f75e3c97c5 100644 --- a/src/sig_stfl/xmss/external/params.h +++ b/src/sig_stfl/xmss/external/params.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_PARAMS_H #define XMSS_PARAMS_H diff --git a/src/sig_stfl/xmss/external/utils.c b/src/sig_stfl/xmss/external/utils.c index 855f63654d..c2d76aba15 100644 --- a/src/sig_stfl/xmss/external/utils.c +++ b/src/sig_stfl/xmss/external/utils.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include "utils.h" /** diff --git a/src/sig_stfl/xmss/external/utils.h b/src/sig_stfl/xmss/external/utils.h index fc5df634a6..14d8588ddc 100644 --- a/src/sig_stfl/xmss/external/utils.h +++ b/src/sig_stfl/xmss/external/utils.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_UTILS_H #define XMSS_UTILS_H diff --git a/src/sig_stfl/xmss/external/wots.c b/src/sig_stfl/xmss/external/wots.c index 09db90e55c..a4bfae956d 100644 --- a/src/sig_stfl/xmss/external/wots.c +++ b/src/sig_stfl/xmss/external/wots.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/external/wots.h b/src/sig_stfl/xmss/external/wots.h index 0ee55b5b10..e0e3f1d0a9 100644 --- a/src/sig_stfl/xmss/external/wots.h +++ b/src/sig_stfl/xmss/external/wots.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_WOTS_H #define XMSS_WOTS_H diff --git a/src/sig_stfl/xmss/external/xmss.c b/src/sig_stfl/xmss/external/xmss.c index 53ea10c24a..17b40f5627 100644 --- a/src/sig_stfl/xmss/external/xmss.c +++ b/src/sig_stfl/xmss/external/xmss.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include "params.h" diff --git a/src/sig_stfl/xmss/external/xmss.h b/src/sig_stfl/xmss/external/xmss.h index b21db845d3..53d21e2dbd 100644 --- a/src/sig_stfl/xmss/external/xmss.h +++ b/src/sig_stfl/xmss/external/xmss.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_H #define XMSS_H diff --git a/src/sig_stfl/xmss/external/xmss_commons.c b/src/sig_stfl/xmss/external/xmss_commons.c index 5f3818d184..168e6ffed5 100644 --- a/src/sig_stfl/xmss/external/xmss_commons.c +++ b/src/sig_stfl/xmss/external/xmss_commons.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include #include diff --git a/src/sig_stfl/xmss/external/xmss_commons.h b/src/sig_stfl/xmss/external/xmss_commons.h index dbe841c6bf..26eb537ee3 100644 --- a/src/sig_stfl/xmss/external/xmss_commons.h +++ b/src/sig_stfl/xmss/external/xmss_commons.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_COMMONS_H #define XMSS_COMMONS_H diff --git a/src/sig_stfl/xmss/external/xmss_core.c b/src/sig_stfl/xmss/external/xmss_core.c index daaf6aa6e4..4d7e8de096 100644 --- a/src/sig_stfl/xmss/external/xmss_core.c +++ b/src/sig_stfl/xmss/external/xmss_core.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include #include diff --git a/src/sig_stfl/xmss/external/xmss_core.h b/src/sig_stfl/xmss/external/xmss_core.h index bed99862c5..007c42172a 100644 --- a/src/sig_stfl/xmss/external/xmss_core.h +++ b/src/sig_stfl/xmss/external/xmss_core.h @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef XMSS_CORE_H #define XMSS_CORE_H diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c index 70b4b9774e..71b0f471ca 100644 --- a/src/sig_stfl/xmss/external/xmss_core_fast.c +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -1,3 +1,4 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index d1663f1720..4166cafcb7 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #ifndef OQS_SIG_STFL_XMSS_H #define OQS_SIG_STFL_XMSS_H diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c index bfdf3e023b..a19cdc7527 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c @@ -1,5 +1,4 @@ -// SPDX-License-Identifier: MIT - +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index cfeab4548e..40ad786c4e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index 849839ef0d..ebcf4f7608 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index 53fd443a44..d401b2aa75 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index a95007730b..5cc2804754 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index 6c382dcabb..b77a8c8436 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index c9b2a3e51e..695d5de288 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index 817004658b..f4b579deec 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index 971b3de4ed..d216a02a15 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index 93abb5d6e2..bb0bd4684b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index 1e320ed7ba..b601e09a4e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index d67c17015b..33b685c20b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index e938187119..02781a8600 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index 15f591466e..f4d856c34a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c index d1aa9e923d..a3a2257b1c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index ab3c2d6765..3d90674459 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index 62df91e621..0305764855 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index 0ff6054cc6..19db158709 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index 721eba5f9f..0f17088d4b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index 9433c61944..b985951514 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index edfc7239d6..60e3cae071 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index 1d66ba99cc..fc5cf35c23 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index e445cb05f8..6f055e949b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 13e9ae5d8e..98a085ce22 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 1e1ac0915d..37ee00a20b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index 3bc608f484..a4175423a7 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index 0bee9336da..bbadceea0f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index 994393935f..14b3b50ffb 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index c60eecd101..74c378ac7e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index 5c3242a8e1..f7bae2956c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index 3874589c2f..33f714d702 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: MIT +// SPDX-License-Identifier: Apache-2.0 AND MIT #include #include From e7a83c7167032084a9fe8ab2ae86f4b2e19c4bf5 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Tue, 30 Jan 2024 11:45:30 -0500 Subject: [PATCH 37/68] Disable Stateful Signatures in the build by default (#1676) * Disable stateful signature as default. When enabled, key and signature generation is disabled by default. Only signature verification is allowed. Key and signature generation can be enabled by defining OQS_ENABLE_SIG_STFL_KEY_SIG_GEN * Fixed format * Address unused variables * Update .CMake/alg_support.cmake Co-authored-by: Spencer Wilson * Update CONFIGURE.md Co-authored-by: Spencer Wilson * Update example_sig_stfl.c Fixed compile error, unused function. Added a negative test when stateful signature is disabled. * Fix build error. Allow some key generation tests to run as negative tests when key and sig gen is off * Fix format * Fix build error * Fix build error --------- Co-authored-by: Spencer Wilson --- .CMake/alg_support.cmake | 22 ++++- CONFIGURE.md | 18 ++++ src/oqsconfig.h.cmake | 4 + src/sig_stfl/lms/external/hss_keygen.c | 3 + src/sig_stfl/lms/external/hss_sign_inc.c | 3 + src/sig_stfl/lms/sig_stfl_lms_functions.c | 30 +++++++ src/sig_stfl/sig_stfl.c | 17 ++++ src/sig_stfl/xmss/external/xmss.c | 22 +++++ src/sig_stfl/xmss/sig_stfl_xmss_functions.c | 8 +- .../xmss/sig_stfl_xmss_secret_key_functions.c | 4 + src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c | 8 +- tests/example_sig_stfl.c | 33 ++++++- tests/kat_sig_stfl.c | 38 ++++++++ tests/test_sig_stfl.c | 88 +++++++++++++++++-- 14 files changed, 285 insertions(+), 13 deletions(-) diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index d1f9e8daae..bcf6150e7e 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -497,7 +497,7 @@ endif() ##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ENABLE_BY_ALG_END -option(OQS_ENABLE_SIG_STFL_XMSS "Enable XMSS algorithm family" ON) +option(OQS_ENABLE_SIG_STFL_XMSS "Enable XMSS algorithm family" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha256_h10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha256_h16 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha256_h20 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) @@ -528,7 +528,7 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_6 "" ON "OQS_ENAB cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmssmt_shake128_h60_12 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) -option(OQS_ENABLE_SIG_STFL_LMS "Enable LMS algorithm family" ON) +option(OQS_ENABLE_SIG_STFL_LMS "Enable LMS algorithm family" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w1 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w2 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h5_w4 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) @@ -563,6 +563,24 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h10_w8 "" ON "OQS_E cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h15_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h20_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) +option(OQS_ENABLE_SIG_STFL_KEY_SIG_GEN "Enable stateful key and signature generation for research and experimentation" OFF) +cmake_dependent_option(OQS_ALLOW_SFTL_KEY_AND_SIG_GEN "" ON "OQS_ENABLE_SIG_STFL_KEY_SIG_GEN" OFF) + +if (${OQS_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_XMSS}) + set(OQS_ALLOW_XMSS_KEY_AND_SIG_GEN ON) +else() + set(OQS_ALLOW_XMSS_KEY_AND_SIG_GEN OFF) +endif() + +if (${OQS_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_LMS}) + set(OQS_ALLOW_LMS_KEY_AND_SIG_GEN ON) +else() + set(OQS_ALLOW_LMS_KEY_AND_SIG_GEN OFF) +endif() + +if(OQS_ALLOW_SFTL_KEY_AND_SIG_GEN STREQUAL "ON") + message(STATUS "Experimental stateful key and signature generation is enabled. Ensure secret keys are securely stored to prevent multiple simultaneous sign operations.") +endif() if((OQS_MINIMAL_BUILD STREQUAL "ON")) message(FATAL_ERROR "OQS_MINIMAL_BUILD option ${OQS_MINIMAL_BUILD} no longer supported") diff --git a/CONFIGURE.md b/CONFIGURE.md index ffc40273e2..89bd01e042 100644 --- a/CONFIGURE.md +++ b/CONFIGURE.md @@ -121,6 +121,24 @@ Dynamically load OpenSSL through `dlopen`. When using liboqs from other cryptogr Only has an effect if the system supports `dlopen` and ELF binary format, such as Linux or BSD family. +## Stateful Hash Based Signatures + +XMSS and LMS are the two supported Hash-Based Signatures schemes. +`OQS_ENABLE_SIG_STFL_XMSS` and `OQS_ENABLE_SIG_STFL_LMS` control these algorithms, which are disabled by default. +A thrid variable, `OQS_ENABLE_SIG_STFL_KEY_SIG_GEN`, also controls the ability to generate keys and signatures. This is also disabled by default. +Each of these variables can be set to `ON` or `OFF`. +When all three are `ON`, stateful signatures are fully functional and can generate key pairs, sign data, and verify signatures. +If `OQS_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF` signature verification is the only functional operation. + +Standards bodies, such as NIST, recommend that key and signature generation only by done in hardware in order to best enforce the one-time use of secret keys. +Keys stored in a file system are extremely susceptible to simultaneous use. +When enabled in this library a warning message will be generated by the config process. + +By default, +- `OQS_ENABLE_SIG_STFL_XMSS` is `OFF` +- `OQS_ENABLE_SIG_STFL_LMS` is `OFF` +- `OQS_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF`. + **Default**: `OFF`. ## OQS_OPT_TARGET diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index 9d533a8b27..ac13bf093c 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -237,3 +237,7 @@ #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 1 +#cmakedefine OQS_ENABLE_SIG_STFL_KEY_SIG_GEN 1 +#cmakedefine OQS_ALLOW_SFTL_KEY_AND_SIG_GEN 1 +#cmakedefine OQS_ALLOW_XMSS_KEY_AND_SIG_GEN 1 +#cmakedefine OQS_ALLOW_LMS_KEY_AND_SIG_GEN 1 \ No newline at end of file diff --git a/src/sig_stfl/lms/external/hss_keygen.c b/src/sig_stfl/lms/external/hss_keygen.c index 71da413325..d85d9626c7 100644 --- a/src/sig_stfl/lms/external/hss_keygen.c +++ b/src/sig_stfl/lms/external/hss_keygen.c @@ -10,6 +10,7 @@ #include "hss_thread.h" #include "lm_common.h" #include "lm_ots_common.h" +#include /* Count the number of 1 bits at the end (lsbits) of the integer */ /* Do it in the obvious way; straightline code may be faster (no */ @@ -51,6 +52,7 @@ static int trailing_1_bits(merkle_index_t n) { * * This returns true on success, false on failure */ +#ifdef OQS_ALLOW_LMS_KEY_AND_SIG_GEN bool hss_generate_private_key( bool (*generate_random)(void *output, size_t length), unsigned levels, @@ -356,6 +358,7 @@ bool hss_generate_private_key( free(temp_buffer); // IGNORE free-check return true; } +#endif /* * The length of the private key diff --git a/src/sig_stfl/lms/external/hss_sign_inc.c b/src/sig_stfl/lms/external/hss_sign_inc.c index 72a8a22c91..ab3112ee03 100644 --- a/src/sig_stfl/lms/external/hss_sign_inc.c +++ b/src/sig_stfl/lms/external/hss_sign_inc.c @@ -16,6 +16,7 @@ #include "hss_internal.h" #include "hss_sign_inc.h" #include "hss_derive.h" +#include /* * Start the process of creating an HSS signature incrementally. Parameters: @@ -28,6 +29,7 @@ * this_is_the_last_signature - if non-NULL, this will be set if this * signature is the last for this private key */ +#ifdef OQS_ALLOW_LMS_KEY_AND_SIG_GEN bool hss_sign_init( struct hss_sign_inc *ctx, struct hss_working_key *w, @@ -217,3 +219,4 @@ bool hss_sign_finalize( hss_zeroize( seed_buff, sizeof seed_buff ); return success; } +#endif diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index be709fc71c..d0b1559e2d 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -11,6 +11,12 @@ #include "external/hss_internal.h" #include "sig_stfl_lms_wrap.h" +#ifdef __GNUC__ +#define UNUSED __attribute__((unused)) +#else +#define UNUSED +#endif + #define DEFAULT_AUX_DATA 10916 /* Use 10+k of aux data (which works well */ /* with the above default parameter set) */ /** @@ -46,6 +52,12 @@ typedef struct OQS_LMS_KEY_DATA { void *context; } oqs_lms_key_data; +#ifndef OQS_ALLOW_LMS_KEY_AND_SIG_GEN +OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(UNUSED uint8_t *signature, UNUSED size_t *signature_length, UNUSED const uint8_t *message, + UNUSED size_t message_len, UNUSED OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_ERROR; +} +#else OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signature_length, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { OQS_STATUS status = OQS_ERROR; @@ -117,6 +129,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu } return status; } +#endif OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { @@ -219,6 +232,11 @@ bool LMS_randombytes(void *buffer, size_t length) { return true; } +#ifndef OQS_ALLOW_LMS_KEY_AND_SIG_GEN +int oqs_sig_stfl_lms_keypair(UNUSED uint8_t *pk, UNUSED OQS_SIG_STFL_SECRET_KEY *sk, UNUSED const uint32_t oid) { + return -1; +} +#else int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uint32_t oid) { int ret = -1; @@ -522,7 +540,14 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uin ret = 0; return ret; } +#endif +#ifndef OQS_ALLOW_LMS_KEY_AND_SIG_GEN +int oqs_sig_stfl_lms_sign(UNUSED OQS_SIG_STFL_SECRET_KEY *sk, UNUSED uint8_t *sm, UNUSED size_t *smlen, + UNUSED const uint8_t *m, UNUSED size_t mlen) { + return -1; +} +#else int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, uint8_t *sm, size_t *smlen, const uint8_t *m, size_t mlen) { @@ -598,6 +623,7 @@ int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, return 0; } +#endif int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, const uint8_t *sm, size_t smlen, @@ -714,6 +740,10 @@ OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_ return OQS_ERROR; } +#ifndef OQS_ALLOW_LMS_KEY_AND_SIG_GEN + return OQS_ERROR; +#endif + aux_buf_len = sk_len - lms_sk_len; if (sk->secret_key_data) { // Key data already present diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index e3a9d0f71c..0f6ebff7af 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -878,21 +878,38 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { } OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { +#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN + (void)sig; + (void)public_key; + (void)secret_key; + return OQS_ERROR; +#else if (sig == NULL || sig->keypair == NULL || sig->keypair(public_key, secret_key) != 0) { return OQS_ERROR; } else { return OQS_SUCCESS; } return OQS_ERROR; +#endif } OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { +#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN + (void)sig; + (void)signature; + (void)signature_len; + (void)message; + (void)message_len; + (void)secret_key; + return OQS_ERROR; +#else if (sig == NULL || sig->sign == NULL || sig->sign(signature, signature_len, message, message_len, secret_key) != 0) { return OQS_ERROR; } else { return OQS_SUCCESS; } +#endif } OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/external/xmss.c b/src/sig_stfl/xmss/external/xmss.c index 17b40f5627..71d3f0a463 100644 --- a/src/sig_stfl/xmss/external/xmss.c +++ b/src/sig_stfl/xmss/external/xmss.c @@ -6,6 +6,13 @@ #include "utils.h" #include "xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + /* This file provides wrapper functions that take keys that include OIDs to identify the parameter set to be used. After setting the parameters accordingly it falls back to the regular XMSS core functions. */ @@ -25,6 +32,12 @@ it falls back to the regular XMSS core functions. */ * @return an integer value. If the function executes successfully, it will return 0. If there is an * error, it will return -1. */ +#ifndef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN +int xmss_keypair(XMSS_UNUSED_ATT unsigned char *pk, XMSS_UNUSED_ATT unsigned char *sk, XMSS_UNUSED_ATT const uint32_t oid) +{ + return -1; +} +#else int xmss_keypair(unsigned char *pk, unsigned char *sk, const uint32_t oid) { xmss_params params; @@ -42,6 +55,7 @@ int xmss_keypair(unsigned char *pk, unsigned char *sk, const uint32_t oid) } return xmss_core_keypair(¶ms, pk + XMSS_OID_LEN, sk + XMSS_OID_LEN); } +#endif /** * This function parses the XMSS OID from a secret key, uses it to determine the XMSS parameters, and @@ -57,6 +71,13 @@ int xmss_keypair(unsigned char *pk, unsigned char *sk, const uint32_t oid) * @return an integer value. If the function executes successfully, it will return 0. If there is an * error, it will return -1. */ +#ifndef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN +int xmss_sign(XMSS_UNUSED_ATT unsigned char *sk, XMSS_UNUSED_ATT unsigned char *sm, XMSS_UNUSED_ATT unsigned long long *smlen, + XMSS_UNUSED_ATT const unsigned char *m, XMSS_UNUSED_ATT unsigned long long mlen) +{ + return -1; +} +#else int xmss_sign(unsigned char *sk, unsigned char *sm, unsigned long long *smlen, const unsigned char *m, unsigned long long mlen) @@ -73,6 +94,7 @@ int xmss_sign(unsigned char *sk, } return xmss_core_sign(¶ms, sk + XMSS_OID_LEN, sm, smlen, m, mlen); } +#endif /** * The function xmss_sign_open verifies a signature and retrieves the original message using the XMSS diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c index a19cdc7527..ce2df38238 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c @@ -14,7 +14,12 @@ #endif /* -------------- XMSS -------------- */ - +#ifndef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sign(XMSS_UNUSED_ATT uint8_t *signature, XMSS_UNUSED_ATT size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, + XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_ERROR; +} +#else OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { OQS_STATUS status = OQS_SUCCESS; @@ -59,6 +64,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sign(uint8_t *signature, size_t *signat return status; } +#endif OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index 40ad786c4e..4f6413a98b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -112,6 +112,10 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_inner_serialize_key(uint8_t **sk_buf_ptr, size_t /* Deserialize XMSS byte string into an XMSS secret key data. */ OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, XMSS_UNUSED_ATT void *context) { +#ifndef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN + return OQS_ERROR; +#endif + if (sk == NULL || sk_buf == NULL || (sk_len != sk->length_secret_key)) { return OQS_ERROR; } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c index a3a2257b1c..f5d99705d3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c @@ -15,7 +15,12 @@ #endif /* -------------- XMSSMT -------------- */ - +#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sign(XMSS_UNUSED_ATT uint8_t *signature, XMSS_UNUSED_ATT size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, + XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { + return OQS_ERROR; +} +#else OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sign(uint8_t *signature, size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { OQS_STATUS status = OQS_SUCCESS; @@ -60,6 +65,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sign(uint8_t *signature, size_t *sign return status; } +#endif OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_verify(XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, const uint8_t *signature, size_t signature_len, XMSS_UNUSED_ATT const uint8_t *public_key) { diff --git a/tests/example_sig_stfl.c b/tests/example_sig_stfl.c index cbabee8b14..cdcd9f6472 100644 --- a/tests/example_sig_stfl.c +++ b/tests/example_sig_stfl.c @@ -121,13 +121,44 @@ static OQS_STATUS stfl_example(char *method_name) { } int main(void) { +#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN OQS_init(); - if (stfl_example((char *)"XMSS-SHA2_10_256") == OQS_SUCCESS && stfl_example((char *)"LMS_SHA256_H10_W4") == OQS_SUCCESS) { + printf("Stateful signature algorithms key and signature generation is not enabled.\n"); + if (stfl_example((char *)"XMSS-SHA2_10_256") == OQS_ERROR && stfl_example((char *)"LMS_SHA256_H10_W4") == OQS_ERROR) { OQS_destroy(); return EXIT_SUCCESS; } else { OQS_destroy(); return EXIT_FAILURE; } +#else + OQS_STATUS lms_status; + OQS_STATUS xmss_status; + OQS_init(); + xmss_status = stfl_example((char *)"XMSS-SHA2_10_256"); + lms_status = stfl_example((char *)"LMS_SHA256_H10_W4"); + OQS_destroy(); + +#ifndef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN + if (xmss_status == OQS_ERROR) { + xmss_status = OQS_SUCCESS; + } else { + xmss_status = OQS_ERROR; + } +#endif +#ifndef OQS_ALLOW_LMS_KEY_AND_SIG_GEN + if (lms_status == OQS_ERROR) { + lms_status = OQS_SUCCESS; + } else { + lms_status = OQS_ERROR; + } +#endif + if ((xmss_status == OQS_SUCCESS) && (lms_status == OQS_SUCCESS)) { + return EXIT_SUCCESS; + } else { + return EXIT_FAILURE; + } +#endif } + diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 457a5c3778..23ec293e4b 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -243,6 +243,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { OQS_fprintBstr(fh, "msg = ", msg, msg_len); +#ifdef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN rc = OQS_SIG_STFL_sign(sig, signature, &signature_len, msg, msg_len, secret_key); if (rc != OQS_SUCCESS) { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sign failed!\n", method_name); @@ -289,7 +290,44 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { ret = OQS_SUCCESS; goto cleanup; +#else + /* + * Signature generation is disabled so only signature verification can be tested. + */ + signature_len = sig->length_signature; + if (!ReadHex(fp_rsp, signature_kat, signature_len, "sm = ")) { + fprintf(stderr, "ERROR: unable to read 'msg' from <%s>\n", katfile); + goto err; + } + + //Echo back the signature read to keep the test tool happy. + fprintf(fh, "smlen = %zu\n", sig->length_signature); + fprintBstr(fh, "sm = ", signature_kat, sig->length_signature); + rc = OQS_SIG_STFL_verify(sig, msg, msg_len, signature_kat, signature_len, public_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_verify failed!\n", method_name); + goto err; + } + + rc = OQS_SIG_STFL_sigs_remaining(sig, &sigs_remain, secret_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_remaining failed!\n", method_name); + goto err; + } + //Update value to keep the test tool happy + fprintf(fh, "remain = %llu\n", sigs_remain - 1); + + rc = OQS_SIG_STFL_sigs_total(sig, &sigs_maximum, secret_key); + if (rc != OQS_SUCCESS) { + fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_total failed!\n", method_name); + goto err; + } + fprintf(fh, "max = %llu", sigs_maximum); + + ret = OQS_SUCCESS; + goto cleanup; +#endif err: ret = OQS_ERROR; goto cleanup; diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index a8b3e7962d..f0a51aac74 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -321,11 +321,13 @@ OQS_STATUS sig_stfl_KATs_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_ } else { goto from_keygen; } - +#ifdef OQS_ENABLE_SIG_STFL_XMSS from_kats: return sig_stfl_keypair_from_KATs(sig, public_key, secret_key, katfile); +#endif from_keygen: + (void)(katfile); return sig_stfl_keypair_from_keygen(sig, public_key, secret_key); } @@ -947,7 +949,7 @@ typedef struct thread_data { const char *alg_name; const char *katfile; OQS_STATUS rc; - OQS_STATUS rc1; + // OQS_STATUS rc1; } thread_data_t; typedef struct lock_test_data { @@ -980,13 +982,46 @@ void *test_create_keys(void *arg) { return NULL; } -void *test_wrapper(void *arg) { +void *test_correctness_wrapper(void *arg) { struct thread_data *td = arg; td->rc = sig_stfl_test_correctness(td->alg_name, td->katfile); - td->rc1 = sig_stfl_test_secret_key(td->alg_name, td->katfile); return NULL; } + +void *test_secret_key_wrapper(void *arg) { + struct thread_data *td = arg; + td->rc = sig_stfl_test_secret_key(td->alg_name, td->katfile); + return NULL; +} +#endif + +/* + * When key and signature generation is off + * these operations should fail. So flip the results. + */ +static OQS_STATUS update_test_result( OQS_STATUS rc, int xmss_or_lms) { + OQS_STATUS rc_update = rc; + if (xmss_or_lms) { + ; +#ifndef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN + if (rc_update == OQS_ERROR) { + rc_update = OQS_SUCCESS; + } else { + rc_update = OQS_ERROR; + } #endif + } else { + ; +#ifndef OQS_ALLOW_LMS_KEY_AND_SIG_GEN + if (rc_update == OQS_ERROR) { + rc_update = OQS_SUCCESS; + } else { + rc_update = OQS_ERROR; + } +#endif + } + return rc_update; +} int main(int argc, char **argv) { OQS_init(); @@ -1012,11 +1047,31 @@ int main(int argc, char **argv) { const char *alg_name = argv[1]; const char *katfile = argv[2]; + int is_xmss = 0; + if (strstr(alg_name, "XMSS") != NULL) { + is_xmss = 1; + } + /* + * Tests executed by CI/DI only run algoritms that have been emabled. + * + */ if (!OQS_SIG_STFL_alg_is_enabled(alg_name)) { printf("Stateful signature algorithm %s not enabled!\n", alg_name); OQS_destroy(); - return EXIT_FAILURE; + if (is_xmss) { +#ifndef OQS_ENABLE_SIG_STFL_XMSS + return EXIT_SUCCESS; +#else + return EXIT_FAILURE; +#endif + } else { +#ifndef OQS_ENABLE_SIG_STFL_LMS + return EXIT_SUCCESS; +#else + return EXIT_FAILURE; +#endif + } } #ifdef OQS_ENABLE_TEST_CONSTANT_TIME @@ -1037,7 +1092,9 @@ int main(int argc, char **argv) { pthread_t sign_key_thread; pthread_t query_key_thread; - thread_data_t td = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR, .rc1 = OQS_ERROR}; + thread_data_t td = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR}; + thread_data_t td_2 = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR}; + lock_test_data_t td_create = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR}; lock_test_data_t td_sign = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR}; lock_test_data_t td_query = {.alg_name = alg_name, .katfile = katfile, .rc = OQS_ERROR}; @@ -1057,14 +1114,23 @@ int main(int argc, char **argv) { goto err; } - if (pthread_create(&thread, NULL, test_wrapper, &td)) { + if (pthread_create(&thread, NULL, test_correctness_wrapper, &td)) { fprintf(stderr, "ERROR: Creating pthread for test_wrapper\n"); exit_status = EXIT_FAILURE; goto err; } pthread_join(thread, NULL); rc = td.rc; - rc1 = td.rc1; + rc = update_test_result(rc, is_xmss); + + if (pthread_create(&thread, NULL, test_secret_key_wrapper, &td_2)) { + fprintf(stderr, "ERROR: Creating pthread for test_wrapper_2\n"); + exit_status = EXIT_FAILURE; + goto err; + } + pthread_join(thread, NULL); + rc1 = td_2.rc; + rc1 = update_test_result(rc1, is_xmss); if (pthread_create(&create_key_thread, NULL, test_create_keys, &td_create)) { fprintf(stderr, "ERROR: Creating pthread for test_create_keys\n"); @@ -1073,6 +1139,7 @@ int main(int argc, char **argv) { } pthread_join(create_key_thread, NULL); rc_create = td_create.rc; + rc_create = update_test_result(rc_create, is_xmss); if (pthread_create(&sign_key_thread, NULL, test_sig_gen, &td_sign)) { fprintf(stderr, "ERROR: Creating pthread for test_sig_gen\n"); @@ -1081,6 +1148,7 @@ int main(int argc, char **argv) { } pthread_join(sign_key_thread, NULL); rc_sign = td_sign.rc; + rc_sign = update_test_result(rc_sign, is_xmss); if (pthread_create(&query_key_thread, NULL, test_query_key, &td_query)) { fprintf(stderr, "ERROR: Creating pthread for test_query_key\n"); @@ -1089,6 +1157,7 @@ int main(int argc, char **argv) { } pthread_join(query_key_thread, NULL); rc_query = td_query.rc; + rc_query = update_test_result(rc_query, is_xmss); err: if (test_sk_lock) { @@ -1121,6 +1190,9 @@ int main(int argc, char **argv) { rc1 = sig_stfl_test_secret_key(alg_name, katfile); OQS_destroy(); + rc = update_test_result(rc, is_xmss); + rc1 = update_test_result(rc1, is_xmss); + if (rc != OQS_SUCCESS || rc1 != OQS_SUCCESS) { return EXIT_FAILURE; From 6c81bae0099c069c5e9b08fb0ea87d40302c07b9 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Thu, 8 Feb 2024 14:09:28 -0500 Subject: [PATCH 38/68] Na stateful macro (#1687) * Use OQS_SIG data struct for verify only capability. Refactor code via macro * Fix format issues * Fix build error * Fix build error * Remove comments --- src/sig_stfl/lms/sig_stfl_lms.c | 2954 +---------------- src/sig_stfl/lms/sig_stfl_lms.h | 17 - src/sig_stfl/sig_stfl.c | 17 + src/sig_stfl/sig_stfl.h | 4 + src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 73 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 73 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 73 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 74 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 73 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 73 +- .../xmss/sig_stfl_xmss_shake128_h10.c | 74 +- .../xmss/sig_stfl_xmss_shake128_h16.c | 75 +- .../xmss/sig_stfl_xmss_shake128_h20.c | 74 +- .../xmss/sig_stfl_xmss_shake256_h10.c | 74 +- .../xmss/sig_stfl_xmss_shake256_h16.c | 75 +- .../xmss/sig_stfl_xmss_shake256_h20.c | 74 +- src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c | 85 + .../xmss/sig_stfl_xmssmt_sha256_h20_2.c | 74 +- .../xmss/sig_stfl_xmssmt_sha256_h20_4.c | 74 +- .../xmss/sig_stfl_xmssmt_sha256_h40_2.c | 74 +- .../xmss/sig_stfl_xmssmt_sha256_h40_4.c | 74 +- .../xmss/sig_stfl_xmssmt_sha256_h40_8.c | 73 +- .../xmss/sig_stfl_xmssmt_sha256_h60_12.c | 72 +- .../xmss/sig_stfl_xmssmt_sha256_h60_3.c | 74 +- .../xmss/sig_stfl_xmssmt_sha256_h60_6.c | 73 +- .../xmss/sig_stfl_xmssmt_shake128_h20_2.c | 73 +- .../xmss/sig_stfl_xmssmt_shake128_h20_4.c | 73 +- .../xmss/sig_stfl_xmssmt_shake128_h40_2.c | 73 +- .../xmss/sig_stfl_xmssmt_shake128_h40_4.c | 73 +- .../xmss/sig_stfl_xmssmt_shake128_h40_8.c | 73 +- .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 74 +- .../xmss/sig_stfl_xmssmt_shake128_h60_3.c | 73 +- .../xmss/sig_stfl_xmssmt_shake128_h60_6.c | 73 +- tests/test_sig_stfl.c | 5 +- 34 files changed, 340 insertions(+), 4800 deletions(-) create mode 100644 src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index 9e65a5e442..7e5e99ea45 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -7,6 +7,50 @@ #include "sig_stfl_lms_wrap.h" #include "sig_stfl_lms.h" +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + + +// OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); +// OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +// OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void); +// OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(void); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); +OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); + /* Convert LMS secret key object to byte string */ static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); @@ -15,2858 +59,212 @@ static OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk static void OQS_SECRET_KEY_LMS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); -// ======================== LMS-SHA256 H5/W1 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w1) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h5_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w1; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; +// ======================== LMS Maccros ======================== // +// macro to en/disable OQS_SIG_STFL-only structs used only in sig&gen case: +#ifdef OQS_ALLOW_LMS_KEY_AND_SIG_GEN +#define LMS_SIGGEN(lms_variant, LMS_VARIANT) \ + sig->oid = OQS_LMS_ID_##lms_variant; \ + sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; \ + sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; \ + sig->keypair = OQS_SIG_STFL_alg_lms_##lms_variant##_keypair; \ + sig->sign = OQS_SIG_STFL_alg_lms_sign; +#else +#define LMS_SIGGEN(lms_variant, LMS_VARIANT) +#endif +// generator for all alg-specific functions: +#define LMS_ALG(lms_variant, LMS_VARIANT) \ +OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_##lms_variant##_new(void) { \ +\ + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); \ + if (sig == NULL) { \ + return NULL; \ + } \ + memset(sig, 0, sizeof(OQS_SIG_STFL)); \ +\ + LMS_SIGGEN(lms_variant, ) \ + sig->method_name = OQS_SIG_STFL_alg_lms_##lms_variant; \ + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; \ + sig->euf_cma = true; \ +\ + sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; \ + sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; \ + sig->length_signature = OQS_SIG_STFL_alg_lms_##lms_variant##_length_signature; \ +\ + sig->verify = OQS_SIG_STFL_alg_lms_verify; \ +\ + return sig;\ +} \ +\ +OQS_STATUS OQS_SIG_STFL_alg_lms_##lms_variant##_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) {\ + if (secret_key == NULL || public_key == NULL) {\ + return OQS_ERROR;\ + }\ +\ + if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_##lms_variant) != 0) {\ + return OQS_ERROR;\ + }\ + return OQS_SUCCESS;\ +}\ +\ +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_##LMS_VARIANT##_new(void) {\ +\ + OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY));\ + if (sk == NULL) {\ + return NULL;\ + }\ + memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY));\ +\ + sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key;\ +\ + sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key;\ +\ + sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key;\ +\ + sk->lock_key = NULL;\ +\ + sk->unlock_key = NULL;\ +\ + sk->secure_store_scrt_key = NULL;\ +\ + sk->free_key = OQS_SECRET_KEY_LMS_free;\ +\ + sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb;\ +\ + return sk;\ } -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +// ======================== LMS-SHA256 H5/W1 ======================== // +LMS_ALG(sha256_h5_w1, SHA256_H5_W1) // ======================== LMS-SHA256 H5/W2 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w2) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h5_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w2; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +LMS_ALG(sha256_h5_w2, SHA256_H5_W2) // ======================== LMS-SHA256 H5/W4 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w4) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h5_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w4; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +LMS_ALG(sha256_h5_w4, SHA256_H5_W4) // ======================== LMS-SHA256 H5/W8 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h5_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +LMS_ALG(sha256_h5_w8, SHA256_H5_W8) // ======================== LMS-SHA256 H10/W1 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w1) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w1_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h10_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w1; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w1_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W1_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w1_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +LMS_ALG(sha256_h10_w1, SHA256_H10_W1) // ======================== LMS-SHA256 H10/W2 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w2) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h10_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w2; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w2_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w2_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +LMS_ALG(sha256_h10_w2, SHA256_H10_W2) // ======================== LMS-SHA256 H10/W4 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w4) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h10_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w4; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w4_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w4_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +LMS_ALG(sha256_h10_w4, SHA256_H10_W4) // ======================== LMS-SHA256 H10/W8 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h10_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h10_w8_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +LMS_ALG(sha256_h10_w8, SHA256_H10_W8) // ======================== LMS-SHA256 H15/W1 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w1) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} +LMS_ALG(sha256_h15_w1, SHA256_H15_W1) -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w1_new(void) { +// ======================== LMS-SHA256 H15/W2 ======================== // - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); +LMS_ALG(sha256_h15_w2, SHA256_H15_W2) - sig->oid = OQS_LMS_ID_sha256_h15_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w1; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; +// ======================== LMS-SHA256 H15/W4 ======================== // - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_sk; +LMS_ALG(sha256_h15_w4, SHA256_H15_W4) - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w1_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; +// ======================== LMS-SHA256 H15/W8 ======================== // - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; +LMS_ALG(sha256_h15_w8, SHA256_H15_W8) - return sig; -} +// ======================== LMS-SHA256 H20/W1 ======================== // -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W1_new(void) { +LMS_ALG(sha256_h20_w1, SHA256_H20_W1) - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); +// // ======================== LMS-SHA256 H20/W2 ======================== // - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w1_length_sk; +LMS_ALG(sha256_h20_w2, SHA256_H20_W2) - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; +// ======================== LMS-SHA256 H20/W4 ======================== // - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; +LMS_ALG(sha256_h20_w4, SHA256_H20_W4) - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; +// ======================== LMS-SHA256 H20/W8 ======================== // - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; +LMS_ALG(sha256_h20_w8, SHA256_H20_W8) - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; +// ======================== LMS-SHA256 H25/W1 ======================== // - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; +LMS_ALG(sha256_h25_w1, SHA256_H25_W1) - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; +// ======================== LMS-SHA256 H25/W2 ======================== // - return sk; -} +LMS_ALG(sha256_h25_w2, SHA256_H25_W2) -// ======================== LMS-SHA256 H15/W2 ======================== // +// ======================== LMS-SHA256 H25/W4 ======================== // -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } +LMS_ALG(sha256_h25_w4, SHA256_H25_W4) - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w2) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} +// ======================== LMS-SHA256 H25/W8 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w2_new(void) { +LMS_ALG(sha256_h25_w8, SHA256_H25_W8) - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); +// +//2-Level LMS +// ======================== LMS-SHA256 H5/W8, H5/W8 ======================== // - sig->oid = OQS_LMS_ID_sha256_h15_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w2; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; +LMS_ALG(sha256_h5_w8_h5_w8, SHA256_H5_W8_H5_W8) - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_sk; +// ======================== LMS-SHA256 H10/W2, H10/W2 ======================== // - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w2_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; +LMS_ALG(sha256_h10_w2_h10_w2, SHA256_H10_W2_H10_W2) - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; +// ======================== LMS-SHA256 H10/W4, H5/W8 ======================== // - return sig; -} +LMS_ALG(sha256_h10_w4_h5_w8, SHA256_H10_W4_H5_W8) -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W2_new(void) { +// ======================== LMS-SHA256 H10/W4, H10/W4 ======================== // - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); +LMS_ALG(sha256_h10_w4_h10_w4, SHA256_H10_W4_H10_W4) - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w2_length_sk; +// ======================== LMS-SHA256 H10/W8, H5/W8 ======================== // - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; +LMS_ALG(sha256_h10_w8_h5_w8, SHA256_H10_W8_H5_W8) - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; +// ======================== LMS-SHA256 H10/W8, H10/W8 ======================== // - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; +LMS_ALG(sha256_h10_w8_h10_w8, SHA256_H10_W8_H10_W8) - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; +// ======================== LMS-SHA256 H15/W8, H5/W8 ======================== // - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; +LMS_ALG(sha256_h15_w8_h5_w8, SHA256_H15_W8_H5_W8) - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; +// ======================== LMS-SHA256 H15/W8, H10/W8 ======================== // - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; +LMS_ALG(sha256_h15_w8_h10_w8, SHA256_H15_W8_H10_W8) - return sk; -} +// ======================== LMS-SHA256 H15/W8, H15/W8 ======================== // -// ======================== LMS-SHA256 H15/W4 ======================== // +LMS_ALG(sha256_h15_w8_h15_w8, SHA256_H15_W8_H15_W8) -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } +// ======================== LMS-SHA256 H20/W8, H5/W8 ======================== // - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w4) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} +LMS_ALG(sha256_h20_w8_h5_w8, SHA256_H20_W8_H5_W8) -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w4_new(void) { +// ======================== LMS-SHA256 H20/W8, H10/W8 ======================== // - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); +LMS_ALG(sha256_h20_w8_h10_w8, SHA256_H20_W8_H10_W8) - sig->oid = OQS_LMS_ID_sha256_h15_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w4; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; +// ======================== LMS-SHA256 H20/W8, H15/W8 ======================== // - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_sk; +LMS_ALG(sha256_h20_w8_h15_w8, SHA256_H20_W8_H15_W8) - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w4_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; +// ======================== LMS-SHA256 H20/W8, H20/W8 ======================== // - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w4_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H15/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h15_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h15_w8_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H20/W1 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w1) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w1_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h20_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w1; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w1_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W1_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w1_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H20/W2 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w2) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h20_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w2; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w2_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w2_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H20/W4 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w4) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h20_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w4; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w4_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w4_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H20/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h20_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h20_w8_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H25/W1 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h25_w1) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w1_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h25_w1; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h25_w1; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h25_w1_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W1_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w1_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H25/W2 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h25_w2) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h25_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h25_w2; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h25_w2_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w2_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H25/W4 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h25_w4) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h25_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h25_w4; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h25_w4_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w4_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H25/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h25_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h25_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h25_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h25_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_pk; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_sk; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h25_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H25_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_sha256_h25_w8_length_sk; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// -//2-Level LMS -// ======================== LMS-SHA256 H5/W8, H5/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h5_w8_h5_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h5_w8_h5_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_H5_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H10/W2, H10/W2 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w2_h10_w2) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h10_w2_h10_w2; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_H10_W2_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H10/W4, H5/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w4_h5_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h10_w4_h5_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H5_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H10/W4, H10/W4 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w4_h10_w4) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h10_w4_h10_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H10_W4_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H10/W8, H5/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w8_h5_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h10_w8_h5_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H5_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H10/W8, H10/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h10_w8_h10_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h15_w4; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H10_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H15/W8, H5/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w8_h5_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h15_w8_h5_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H5_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H15/W8, H10/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w8_h10_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h15_w8_h10_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H10_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H15/W8, H15/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h15_w8_h15_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h15_w8_h15_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H15_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H20/W8, H5/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8_h5_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h20_w8_h5_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H5_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H20/W8, H10/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8_h10_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h20_w8_h10_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H10_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H20/W8, H15/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8_h15_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h20_w8_h15_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H15_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} - -// ======================== LMS-SHA256 H20/W8, H20/W8 ======================== // - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { - if (secret_key == NULL || public_key == NULL) { - return OQS_ERROR; - } - - if (oqs_sig_stfl_lms_keypair(public_key, secret_key, (const uint32_t)OQS_LMS_ID_sha256_h20_w8_h20_w8) != 0) { - return OQS_ERROR; - } - return OQS_SUCCESS; -} - -OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_LMS_ID_sha256_h20_w8_h20_w8; - sig->method_name = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8554"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_lms_length_public_key; - sig->length_signature = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_length_signature; - sig->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - sig->keypair = OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair; - sig->sign = OQS_SIG_STFL_alg_lms_sign; - sig->verify = OQS_SIG_STFL_alg_lms_verify; - - sig->sigs_remaining = OQS_SIG_STFL_lms_sigs_left; - sig->sigs_total = OQS_SIG_STFL_lms_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H20_W8_new(void) { - - // Initialize the secret key in the heap with adequate memory - OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); - if (sk == NULL) { - return NULL; - } - memset(sk, 0, sizeof(OQS_SIG_STFL_SECRET_KEY)); - - // Initialize the key with length_secret_key amount of bytes. - sk->length_secret_key = OQS_SIG_STFL_alg_lms_length_private_key; - - /* - * Secret Key retrieval Function - */ - sk->serialize_key = OQS_SECRET_KEY_LMS_serialize_key; - - /* - * set Secret Key to internal structure Function - */ - sk->deserialize_key = OQS_SECRET_KEY_LMS_deserialize_key; - - /* - * Set Secret Key Locking Function - */ - sk->lock_key = NULL; - - /* - * Set Secret Key Unlocking / Releasing Function - */ - sk->unlock_key = NULL; - - /* - * Set Secret Key Saving Function - */ - sk->secure_store_scrt_key = NULL; - - /* - * Set Secret Key free function - */ - sk->free_key = OQS_SECRET_KEY_LMS_free; - - sk->set_scrt_key_store_cb = OQS_SECRET_KEY_LMS_set_store_cb; - - return sk; -} +LMS_ALG(sha256_h20_w8_h20_w8, SHA256_H20_W8_H20_W8) //2-Level LMS diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index 4405e60c1c..c5deed2f40 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -96,28 +96,24 @@ #define OQS_SIG_STFL_alg_lms_sha256_h5_w1_length_sk 64 OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); #define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_signature 4464 #define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w2_length_sk 64 OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); #define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_signature 2352 #define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w4_length_sk 64 OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w4_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W4_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); #define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_signature 1296 #define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_pk 60 #define OQS_SIG_STFL_alg_lms_sha256_h5_w8_length_sk 64 OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_new(void); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); //H10 // H10 W1 60 8848 64 @@ -279,55 +275,42 @@ void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_length_signature 3444 #define OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_length_signature 3604 -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W8_H5_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w8_h5_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H5_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h5_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H5_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h5_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W2_H10_W2_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w2_h10_w2_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W4_H10_W4_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w4_h10_w4_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H10_W8_H10_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h10_w8_h10_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H5_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h5_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H10_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h10_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H15_W8_H15_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h15_w8_h15_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H5_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h5_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H10_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h10_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H15_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h15_w8_new(void); -OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_API OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H20_W8_H20_W8_new(void); OQS_API OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_new(void); diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 0f6ebff7af..69fdbc352c 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -912,6 +912,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature #endif } + OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { if (sig == NULL || sig->verify == NULL || sig->verify(message, message_len, signature, signature_len, public_key) != 0) { return OQS_ERROR; @@ -920,20 +921,36 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m } } + OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { +#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN + (void)sig; + (void)remain; + (void)secret_key; + return OQS_ERROR; +#else if (sig == NULL || sig->sigs_remaining == NULL || sig->sigs_remaining(remain, secret_key) != 0) { return OQS_ERROR; } else { return OQS_SUCCESS; } +#endif //OQS_ALLOW_SFTL_KEY_AND_SIG_GEN } + OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const OQS_SIG_STFL_SECRET_KEY *secret_key) { +#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN + (void)sig; + (void)max; + (void)secret_key; + return OQS_ERROR; +#else if (sig == NULL || sig->sigs_total == NULL || sig->sigs_total(max, secret_key) != 0) { return OQS_ERROR; } else { return OQS_SUCCESS; } +#endif //OQS_ALLOW_SFTL_KEY_AND_SIG_GEN } OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig) { diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index ac95842400..b0cb69b843 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -178,6 +178,9 @@ OQS_API int OQS_SIG_STFL_alg_count(void); */ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name); +#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#define OQS_SIG_STFL OQS_SIG +#else /** * Stateful signature scheme object */ @@ -281,6 +284,7 @@ typedef struct OQS_SIG_STFL { OQS_STATUS (*sigs_total)(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); } OQS_SIG_STFL; +#endif //OQS_ALLOW_SFTL_KEY_AND_SIG_GEN /** * @brief OQS_SIG_STFL_SECRET_KEY object for stateful signature schemes diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index ebcf4f7608..7b9bcff39b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHA2_10_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h10_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_sha256_h10_oid; - sig->method_name = "XMSS-SHA2_10_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h10_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h10_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_sha256_h10_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_sha256_h10_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H10_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha256_h10_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha256_h10_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _sha256_h10, _SHA256_H10) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index d401b2aa75..c883e21e0e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHA2_16_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h16_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_sha256_h16_oid; - sig->method_name = "XMSS-SHA2_16_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h16_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h16_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h16_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_sha256_h16_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_sha256_h16_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H16_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha256_h16_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha256_h16_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _sha256_h16, _SHA256_H16) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index 5cc2804754..a190255f2c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHA2_16_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha256_h20_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_sha256_h20_oid; - sig->method_name = "XMSS-SHA2_20_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha256_h20_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_sha256_h20_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_sha256_h20_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_sha256_h20_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_sha256_h20_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA256_H20_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha256_h20_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha256_h20_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha256_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _sha256_h20, _SHA256_H20) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index b77a8c8436..1ff4cd891a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHA2_10_512 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h10_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_sha512_h10_oid; - sig->method_name = "XMSS-SHA2_10_512"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha512_h10_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_sha512_h10_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_sha512_h10_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_sha512_h10_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_sha512_h10_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H10_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha512_h10_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha512_h10_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _sha512_h10, _SHA512_H10) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index 695d5de288..c1b5ed9150 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHA2_16_512 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h16_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_sha512_h16_oid; - sig->method_name = "XMSS-SHA2_16_512"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha512_h16_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_sha512_h16_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_sha512_h16_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_sha512_h16_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_sha512_h16_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H16_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha512_h16_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha512_h16_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _sha512_h16, _SHA512_H16) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index f4b579deec..bf0a5b8d12 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHA2_20_512 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_sha512_h20_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_sha512_h20_oid; - sig->method_name = "XMSS-SHA2_20_512"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_sha512_h20_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_sha512_h20_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_sha512_h20_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_sha512_h20_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_sha512_h20_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHA512_H20_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_sha512_h20_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_sha512_h20_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sha512_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _sha512_h20, _SHA512_H20) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index d216a02a15..8c01394663 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_10_256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h10_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_shake128_h10_oid; - sig->method_name = "XMSS-SHAKE_10_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake128_h10_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_shake128_h10_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_shake128_h10_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_shake128_h10_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_shake128_h10_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H10_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake128_h10_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake128_h10_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _shake128_h10, _SHAKE128_H10) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index bb0bd4684b..ff45fc0f5f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -1,77 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_10_256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h16_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_shake128_h16_oid; - sig->method_name = "XMSS-SHAKE_16_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake128_h16_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_shake128_h16_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_shake128_h16_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_shake128_h16_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_shake128_h16_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H16_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake128_h16_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake128_h16_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} - +XMSS_ALG(, _shake128_h16, _SHAKE128_H16) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index b601e09a4e..d566069a82 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_10_256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake128_h20_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_shake128_h20_oid; - sig->method_name = "XMSS-SHAKE_20_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake128_h20_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_shake128_h20_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_shake128_h20_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_shake128_h20_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_shake128_h20_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE128_H20_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake128_h20_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake128_h20_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake128_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _shake128_h20, _SHAKE128_H20) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index 33b685c20b..aea7ef0204 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_10_512 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h10_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_shake256_h10_oid; - sig->method_name = "XMSS-SHAKE_10_512"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake256_h10_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_shake256_h10_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_shake256_h10_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_shake256_h10_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_shake256_h10_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H10_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake256_h10_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake256_h10_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h10_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _shake256_h10, _SHAKE256_H10) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index 02781a8600..d96e7644b3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -1,77 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_16_512 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h16_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_shake256_h16_oid; - sig->method_name = "XMSS-SHAKE_16_512"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake256_h16_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_shake256_h16_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_shake256_h16_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_shake256_h16_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_shake256_h16_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H16_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake256_h16_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake256_h16_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h16_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} - +XMSS_ALG(, _shake256_h16, _SHAKE256_H16) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index f4d856c34a..5bf41b07f9 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_20_512 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss_shake256_h20_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmss_shake256_h20_oid; - sig->method_name = "XMSS-SHAKE_20_512"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmss_shake256_h20_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmss_shake256_h20_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmss_shake256_h20_keypair; - sig->sign = OQS_SIG_STFL_alg_xmss_shake256_h20_sign; - sig->verify = OQS_SIG_STFL_alg_xmss_shake256_h20_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_SHAKE256_H20_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss_shake256_h20_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmss_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss_shake256_h20_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmss_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_shake256_h20_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmss_sigs_total(total, secret_key); -} +XMSS_ALG(, _shake256_h20, _SHAKE256_H20) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c b/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c new file mode 100644 index 0000000000..1b81bec309 --- /dev/null +++ b/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c @@ -0,0 +1,85 @@ +// SPDX-License-Identifier: Apache-2.0 AND MIT + +#include +#include + +#include +#include "sig_stfl_xmss.h" + +#include "external/xmss.h" + +#if defined(__GNUC__) || defined(__clang__) +#define XMSS_UNUSED_ATT __attribute__((unused)) +#else +#define XMSS_UNUSED_ATT +#endif + + +// macro to en/disable OQS_SIG_STFL-only structs used only in sig&gen case: +#ifdef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN +#define XMSS_SIGGEN(xmss_v, XMSS_V) \ + sig->oid = OQS_SIG_STFL_alg_xmss##xmss_v##_oid; \ + sig->sigs_remaining = OQS_SIG_STFL_alg_xmss##xmss_v##_sigs_remaining;\ + sig->sigs_total = OQS_SIG_STFL_alg_xmss##xmss_v##_sigs_total;\ + sig->keypair = OQS_SIG_STFL_alg_xmss##xmss_v##_keypair;\ + sig->sign = OQS_SIG_STFL_alg_xmss##xmss_v##_sign; +#else +#define XMSS_SIGGEN(xmss_v, XMSS_V) +#endif + +// generator for all alg-specific functions: +#define XMSS_ALG(mt, xmss_v, XMSS_V) \ +OQS_SIG_STFL *OQS_SIG_STFL_alg_xmss##xmss_v##_new(void) { \ +\ + OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); \ + if (sig == NULL) { \ + return NULL; \ + } \ + memset(sig, 0, sizeof(OQS_SIG_STFL)); \ +\ + XMSS_SIGGEN(xmss_v, XMSS_V) \ + sig->method_name = OQS_SIG_STFL_alg_xmss##xmss_v; \ + sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; \ + sig->euf_cma = true; \ +\ + sig->length_public_key = OQS_SIG_STFL_alg_xmss##xmss_v##_length_pk; \ + sig->length_secret_key = OQS_SIG_STFL_alg_xmss##xmss_v##_length_sk; \ + sig->length_signature = OQS_SIG_STFL_alg_xmss##xmss_v##_length_signature; \ +\ + sig->verify = OQS_SIG_STFL_alg_xmss##xmss_v##_verify;\ +\ + return sig;\ +} \ +\ +OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS##XMSS_V##_new(void) {\ + return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmss##xmss_v##_length_sk);\ +}\ +\ +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss##xmss_v##_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) {\ +\ + if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) {\ + return OQS_ERROR;\ + }\ +\ + if (xmss##mt##_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmss##xmss_v##_oid)) {\ + return OQS_ERROR;\ + }\ +\ + return OQS_SUCCESS;\ +}\ +\ +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss##xmss_v##_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) {\ + return OQS_SIG_STFL_alg_xmss##mt##_sign(signature, signature_len, message, message_len, secret_key);\ +}\ +\ +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss##xmss_v##_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) {\ + return OQS_SIG_STFL_alg_xmss##mt##_verify(message, message_len, signature, signature_len, public_key);\ +}\ +\ +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss##xmss_v##_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) {\ + return OQS_SIG_STFL_alg_xmss##mt##_sigs_remaining(remain, secret_key);\ +}\ +\ +OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss##xmss_v##_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) {\ + return OQS_SIG_STFL_alg_xmss##mt##_sigs_total(total, secret_key);\ +} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index 3d90674459..0c6057eef9 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_20/2_256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_oid; - sig->method_name = "XMSSMT-SHA2_20/2_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_2_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_sha256_h20_2, MT_SHA256_H20_2) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index 0305764855..867e0928b1 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_20/4_256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_oid; - sig->method_name = "XMSSMT-SHA2_20/4_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H20_4_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h20_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_sha256_h20_4, MT_SHA256_H20_4) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index 19db158709..e972df04ee 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_40/2_256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_oid; - sig->method_name = "XMSSMT-SHA2_40/2_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_2_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_sha256_h40_2, MT_SHA256_H40_2) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index 0f17088d4b..63c9af0bc8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_40/4_256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_oid; - sig->method_name = "XMSSMT-SHA2_40/4_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_4_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_sha256_h40_4, MT_SHA256_H40_4) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index b985951514..156c2e3fd6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_40/8_256 ======================== // +XMSS_ALG(mt, mt_sha256_h40_8, MT_SHA256_H40_8) -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_oid; - sig->method_name = "XMSSMT-SHA2_40/8_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H40_8_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h40_8_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index 60e3cae071..64f6576f82 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -1,76 +1,8 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include +#include "sig_stfl_xmss_xmssmt.c" -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif // ======================== XMSSMT-SHA2_60/12_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_oid; - sig->method_name = "XMSSMT-SHA2_60/12_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_12_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_12_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_sha256_h60_12, MT_SHA256_H60_12) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index fc5cf35c23..d37e1244ae 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -1,76 +1,6 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_60/3_256 ======================== // - -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_oid; - sig->method_name = "XMSSMT-SHA2_60/3_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_3_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_3_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_sha256_h60_3, MT_SHA256_H60_3) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index 6f055e949b..d5992617c0 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_60/6_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_oid; - sig->method_name = "XMSSMT-SHA2_60/6_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHA256_H60_6_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sha256_h60_6_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_sha256_h60_6, MT_SHA256_H60_6) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 98a085ce22..76c8523a80 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHAKE_20/2_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_oid; - sig->method_name = "XMSSMT-SHAKE_20/2_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_2_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_shake128_h20_2, MT_SHAKE128_H20_2) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 37ee00a20b..0dec4743e6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHAKE_20/4_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_oid; - sig->method_name = "XMSSMT-SHAKE_20/4_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H20_4_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h20_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_shake128_h20_4, MT_SHAKE128_H20_4) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index a4175423a7..765694287d 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHAKE_40/2_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_oid; - sig->method_name = "XMSSMT-SHAKE_40/2_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_2_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_2_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_shake128_h40_2, MT_SHAKE128_H40_2) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index bbadceea0f..7ce156c659 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHAKE_40/4_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_oid; - sig->method_name = "XMSSMT-SHAKE_40/4_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_4_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_4_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_shake128_h40_4, MT_SHAKE128_H40_4) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index 14b3b50ffb..1c3f9671c0 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHAKE_40/8_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_oid; - sig->method_name = "XMSSMT-SHAKE_40/8_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H40_8_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h40_8_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_shake128_h40_8, MT_SHAKE128_H40_8) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index 74c378ac7e..793393eaf3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -1,77 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHAKE_60/12_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_oid; - sig->method_name = "XMSSMT-SHAKE_60/12_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_12_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_12_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} - +XMSS_ALG(mt, mt_shake128_h60_12, MT_SHAKE128_H60_12) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index f7bae2956c..09edd7ebd7 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHAKE_60/3_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_oid; - sig->method_name = "XMSSMT-SHAKE_60/3_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_3_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_3_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_shake128_h60_3, MT_SHAKE128_H60_3) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index 33f714d702..aae4ca20a6 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -1,76 +1,7 @@ // SPDX-License-Identifier: Apache-2.0 AND MIT -#include -#include - -#include -#include "sig_stfl_xmss.h" - -#include "external/xmss.h" - -#if defined(__GNUC__) || defined(__clang__) -#define XMSS_UNUSED_ATT __attribute__((unused)) -#else -#define XMSS_UNUSED_ATT -#endif +#include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHAKE_60/6_256 ======================== // -OQS_SIG_STFL *OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_new(void) { - - OQS_SIG_STFL *sig = (OQS_SIG_STFL *)malloc(sizeof(OQS_SIG_STFL)); - if (sig == NULL) { - return NULL; - } - memset(sig, 0, sizeof(OQS_SIG_STFL)); - - sig->oid = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_oid; - sig->method_name = "XMSSMT-SHAKE_60/6_256"; - sig->alg_version = "https://datatracker.ietf.org/doc/html/rfc8391"; - sig->euf_cma = true; - - sig->length_public_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_pk; - sig->length_secret_key = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk; - sig->length_signature = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_signature; - - sig->keypair = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair; - sig->sign = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign; - sig->verify = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify; - sig->sigs_remaining = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining; - sig->sigs_total = OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total; - - return sig; -} - -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSSMT_SHAKE128_H60_6_new(void) { - return OQS_SECRET_KEY_XMSS_new(OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_length_sk); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_keypair(XMSS_UNUSED_ATT uint8_t *public_key, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { - - if (public_key == NULL || secret_key == NULL || secret_key->secret_key_data == NULL) { - return OQS_ERROR; - } - - if (xmssmt_keypair(public_key, secret_key->secret_key_data, OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_oid)) { - return OQS_ERROR; - } - - return OQS_SUCCESS; -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sign(uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sign(signature, signature_len, message, message_len, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_verify(const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { - return OQS_SIG_STFL_alg_xmssmt_verify(message, message_len, signature, signature_len, public_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_remaining(unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_remaining(remain, secret_key); -} - -OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_shake128_h60_6_sigs_total(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key) { - return OQS_SIG_STFL_alg_xmssmt_sigs_total(total, secret_key); -} +XMSS_ALG(mt, mt_shake128_h60_6, MT_SHAKE128_H60_6) diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index f0a51aac74..5626eee5b3 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -263,8 +263,8 @@ OQS_STATUS sig_stfl_KATs_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_ return OQS_ERROR; } +#ifdef OQS_ENABLE_SIG_STFL_XMSS if (0) { - #ifdef OQS_ENABLE_SIG_STFL_xmss_sha256_h16 } else if (strcmp(sig->method_name, OQS_SIG_STFL_alg_xmss_sha256_h16) == 0) { goto from_kats; @@ -321,12 +321,11 @@ OQS_STATUS sig_stfl_KATs_keygen(OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_ } else { goto from_keygen; } -#ifdef OQS_ENABLE_SIG_STFL_XMSS from_kats: return sig_stfl_keypair_from_KATs(sig, public_key, secret_key, katfile); -#endif from_keygen: +#endif //OQS_ENABLE_SIG_STFL_XMSS (void)(katfile); return sig_stfl_keypair_from_keygen(sig, public_key, secret_key); } From 001e96a03a853d07518f8215634a98f439d5eab3 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Tue, 13 Feb 2024 11:07:06 -0500 Subject: [PATCH 39/68] Update GitHub Actions workflows for stateful signatures (#1692) Co-authored-by: Duc Nguyen --- .github/workflows/android.yml | 4 +++- .github/workflows/apple.yml | 5 ++++- .github/workflows/unix.yml | 22 +++++++++++++++++----- .github/workflows/windows.yml | 8 ++++++-- scripts/build-android.sh | 9 ++++++--- tests/kat_sig_stfl.c | 33 +++++++++++++++++++-------------- 6 files changed, 55 insertions(+), 26 deletions(-) diff --git a/.github/workflows/android.yml b/.github/workflows/android.yml index 895ed7b171..26b4d13186 100644 --- a/.github/workflows/android.yml +++ b/.github/workflows/android.yml @@ -10,8 +10,10 @@ jobs: fail-fast: false matrix: abi: [armeabi-v7a, arm64-v8a, x86, x86_64] + stfl_opt: [ON, OFF] + steps: - name: Checkout code uses: actions/checkout@v3 - name: Build project - run: ./scripts/build-android.sh $ANDROID_NDK_HOME -a ${{ matrix.abi }} + run: ./scripts/build-android.sh $ANDROID_NDK_HOME -a ${{ matrix.abi }} -f "-DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }}" diff --git a/.github/workflows/apple.yml b/.github/workflows/apple.yml index 1ced2dea76..bb9a2f47b6 100644 --- a/.github/workflows/apple.yml +++ b/.github/workflows/apple.yml @@ -10,10 +10,13 @@ jobs: fail-fast: false matrix: platform: [OS64, TVOS] + stfl_opt: [OFF, ON] steps: - name: Checkout code uses: actions/checkout@v3 - name: Generate project - run: cmake -B build --toolchain .CMake/apple.cmake -DOQS_USE_OPENSSL=OFF -DPLATFORM=${{ matrix.platform }} . + run: | + cmake -B build --toolchain .CMake/apple.cmake -DOQS_USE_OPENSSL=OFF -DPLATFORM=${{ matrix.platform }} \ + -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build project run: cmake --build build diff --git a/.github/workflows/unix.yml b/.github/workflows/unix.yml index ab0213ef34..3e534319c7 100644 --- a/.github/workflows/unix.yml +++ b/.github/workflows/unix.yml @@ -74,15 +74,19 @@ jobs: include: - name: alpine container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py + - name: alpine-no-stfl-key-sig-gen + container: openquantumsafe/ci-alpine-amd64:latest + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: alpine-openssl-all container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: alpine-noopenssl container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=OFF + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=OFF -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: focal-nistr4-openssl container: openquantumsafe/ci-ubuntu-focal-x86_64:latest @@ -98,7 +102,11 @@ jobs: PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py - name: address-sanitizer container: openquantumsafe/ci-ubuntu-focal-x86_64:latest - CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address + CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --numprocesses=auto --maxprocesses=10 + - name: address-sanitizer-no-stfl-key-sig-gen + container: openquantumsafe/ci-ubuntu-focal-x86_64:latest + CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --numprocesses=auto --maxprocesses=10 container: image: ${{ matrix.container }} @@ -137,7 +145,11 @@ jobs: include: - name: armhf ARCH: armhf - CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic + CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py + - name: armhf-no-stfl-key-sig-gen + ARCH: armhf + CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py # no longer supporting armel # - name: armel diff --git a/.github/workflows/windows.yml b/.github/workflows/windows.yml index 8b5716554f..de0d5e82db 100644 --- a/.github/workflows/windows.yml +++ b/.github/workflows/windows.yml @@ -6,10 +6,13 @@ jobs: windows-arm64: runs-on: windows-2022 + strategy: + matrix: + stfl_opt: [ON, OFF] steps: - uses: actions/checkout@v3 - name: Generate Project - run: cmake -B build --toolchain .CMake/toolchain_windows_arm64.cmake . + run: cmake -B build --toolchain .CMake/toolchain_windows_arm64.cmake -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build Project run: cmake --build build @@ -19,10 +22,11 @@ jobs: fail-fast: false matrix: toolchain: [.CMake/toolchain_windows_x86.cmake, .CMake/toolchain_windows_amd64.cmake] + stfl_opt: [ON, OFF] steps: - uses: actions/checkout@v3 - name: Generate Project - run: cmake -B build --toolchain ${{ matrix.toolchain }} . + run: cmake -B build --toolchain ${{ matrix.toolchain }} -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build Project run: cmake --build build - name: Test dependencies diff --git a/scripts/build-android.sh b/scripts/build-android.sh index 574c8d8ea4..54a03d21b3 100755 --- a/scripts/build-android.sh +++ b/scripts/build-android.sh @@ -6,12 +6,13 @@ set -e show_help() { echo "" - echo " Usage: ./build-android -a [abi] -b [build-directory] -s [sdk-version]" + echo " Usage: ./build-android -a [abi] -b [build-directory] -s [sdk-version] -f [extra-cmake-flags]" echo " ndk-dir: the directory of the Android NDK (required)" echo " abi: the Android ABI to target for the build" echo " build-directory: the directory in which to build the project" echo " sdk-version: the minimum Android SDK version to target" + echo " extra-cmake-flags: extra flags to use for CMake configuration" echo "" exit 0 } @@ -52,12 +53,13 @@ MINSDKVERSION=21 BUILDDIR="build" OPTIND=2 -while getopts "a:s:b:" flag +while getopts "a:s:b:f:" flag do case $flag in a) ABI=$OPTARG;; s) MINSDKVERSION=$OPTARG;; b) BUILDDIR=$OPTARG;; + f) EXTRAFLAGS="$OPTARG";; *) exit 1 esac done @@ -107,7 +109,8 @@ cmake .. -DOQS_USE_OPENSSL=OFF \ -DBUILD_SHARED_LIBS=ON \ -DCMAKE_TOOLCHAIN_FILE="$NDK"/build/cmake/android.toolchain.cmake \ -DANDROID_ABI="$ABI" \ - -DANDROID_NATIVE_API_LEVEL="$MINSDKVERSION" + -DANDROID_NATIVE_API_LEVEL="$MINSDKVERSION" \ + $EXTRAFLAGS cmake --build ./ # Provide rudimentary information following build diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 23ec293e4b..52245f3dac 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -300,9 +300,9 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { goto err; } - //Echo back the signature read to keep the test tool happy. + // Echo back the signature read to keep the test tool happy. fprintf(fh, "smlen = %zu\n", sig->length_signature); - fprintBstr(fh, "sm = ", signature_kat, sig->length_signature); + OQS_fprintBstr(fh, "sm = ", signature_kat, sig->length_signature); rc = OQS_SIG_STFL_verify(sig, msg, msg_len, signature_kat, signature_len, public_key); if (rc != OQS_SUCCESS) { @@ -310,20 +310,23 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { goto err; } - rc = OQS_SIG_STFL_sigs_remaining(sig, &sigs_remain, secret_key); - if (rc != OQS_SUCCESS) { + // Echo back remain + if (FindMarker(fp_rsp, "remain = ")) { + fscanf(fp_rsp, "%lld", &sigs_remain); + fprintf(fh, "remain = %llu\n", sigs_remain); + } else { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_remaining failed!\n", method_name); goto err; } - //Update value to keep the test tool happy - fprintf(fh, "remain = %llu\n", sigs_remain - 1); - rc = OQS_SIG_STFL_sigs_total(sig, &sigs_maximum, secret_key); - if (rc != OQS_SUCCESS) { + // Echo back max + if (FindMarker(fp_rsp, "max = ")) { + fscanf(fp_rsp, "%lld", &sigs_maximum); + fprintf(fh, "max = %llu", sigs_maximum); + } else { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_total failed!\n", method_name); goto err; } - fprintf(fh, "max = %llu", sigs_maximum); ret = OQS_SUCCESS; goto cleanup; @@ -347,7 +350,9 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { OQS_MEM_insecure_free(msg_rand); OQS_SIG_STFL_free(sig); OQS_KAT_PRNG_free(prng); - fclose(fp_rsp); + if (fp_rsp != NULL) { + fclose(fp_rsp); + } return ret; } @@ -430,7 +435,7 @@ static OQS_STATUS test_lms_kat(const char *method_name, const char *katfile) { goto err; } - //Verify KAT + // Verify KAT rc = OQS_SIG_STFL_verify(sig, msg, msg_len, sm, sig->length_signature, public_key); if (rc != OQS_SUCCESS) { fprintf(stderr, "ERROR: Verify test vector failed: %s\n", method_name); @@ -477,10 +482,10 @@ int main(int argc, char **argv) { char *alg_name = argv[1]; char *katfile = argv[2]; - if (strncmp(alg_name, "LMS", 3) != 0) { - rc = sig_stfl_kat(alg_name, katfile); - } else { + if (strncmp(alg_name, "LMS", 3) == 0) { rc = test_lms_kat(alg_name, katfile); + } else { + rc = sig_stfl_kat(alg_name, katfile); } if (rc != OQS_SUCCESS) { OQS_destroy(); From e1f02b2d6dca61523094640868116a8d997eb14e Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Tue, 13 Feb 2024 12:45:42 -0500 Subject: [PATCH 40/68] Change XMSS License from `(Apache 2.0 AND MIT)` to `(Apache 2.0 OR MIT) AND CC0-1.0` (#1697) * include CC0 and convert to Apache 2.0 OR MIT * update license * Add missing CC0-1.0 --- docs/algorithms/sig_stfl/xmss.md | 2 +- docs/algorithms/sig_stfl/xmss.yml | 4 ++-- src/sig_stfl/xmss/CMakeLists.txt | 2 +- src/sig_stfl/xmss/LICENSE | 14 ++++++++++++-- src/sig_stfl/xmss/LICENSE-MIT | 9 --------- src/sig_stfl/xmss/external/core_hash.c | 2 +- src/sig_stfl/xmss/external/core_hash.h | 2 +- src/sig_stfl/xmss/external/hash.c | 2 +- src/sig_stfl/xmss/external/hash.h | 2 +- src/sig_stfl/xmss/external/hash_address.c | 2 +- src/sig_stfl/xmss/external/hash_address.h | 2 +- src/sig_stfl/xmss/external/namespace.h | 2 +- src/sig_stfl/xmss/external/params.c | 2 +- src/sig_stfl/xmss/external/params.h | 2 +- src/sig_stfl/xmss/external/utils.c | 2 +- src/sig_stfl/xmss/external/utils.h | 2 +- src/sig_stfl/xmss/external/wots.c | 2 +- src/sig_stfl/xmss/external/wots.h | 2 +- src/sig_stfl/xmss/external/xmss.c | 2 +- src/sig_stfl/xmss/external/xmss.h | 2 +- src/sig_stfl/xmss/external/xmss_commons.c | 2 +- src/sig_stfl/xmss/external/xmss_commons.h | 2 +- src/sig_stfl/xmss/external/xmss_core.c | 2 +- src/sig_stfl/xmss/external/xmss_core.h | 2 +- src/sig_stfl/xmss/external/xmss_core_fast.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss.h | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_functions.c | 2 +- .../xmss/sig_stfl_xmss_secret_key_functions.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c | 4 ++-- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c | 3 +-- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c | 3 ++- src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c | 2 +- .../xmss/sig_stfl_xmssmt_shake128_h60_12.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c | 2 +- src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c | 2 +- 58 files changed, 82 insertions(+), 70 deletions(-) delete mode 100644 src/sig_stfl/xmss/LICENSE-MIT diff --git a/docs/algorithms/sig_stfl/xmss.md b/docs/algorithms/sig_stfl/xmss.md index b78dce983b..b68bfc3020 100644 --- a/docs/algorithms/sig_stfl/xmss.md +++ b/docs/algorithms/sig_stfl/xmss.md @@ -7,7 +7,7 @@ - **Specification version**: None. - **Primary Source**: - **Source**: https://github.com/XMSS/xmss-reference - - **Implementation license (SPDX-Identifier)**: Apache-2.0 AND MIT + - **Implementation license (SPDX-Identifier)**: (Apache-2.0 OR MIT) AND CC0-1.0 ## Parameter set summary diff --git a/docs/algorithms/sig_stfl/xmss.yml b/docs/algorithms/sig_stfl/xmss.yml index bf57a7eeb8..ccc92c26ea 100644 --- a/docs/algorithms/sig_stfl/xmss.yml +++ b/docs/algorithms/sig_stfl/xmss.yml @@ -11,10 +11,10 @@ crypto-assumption: hash function second-preimage resistance website: https://www.rfc-editor.org/info/rfc8391 nist-round: spec-version: -spdx-license-identifier: Apache-2.0 AND MIT +spdx-license-identifier: (Apache-2.0 OR MIT) AND CC0-1.0 primary-upstream: source: https://github.com/XMSS/xmss-reference - spdx-license-identifier: Apache-2.0 AND MIT + spdx-license-identifier: (Apache-2.0 OR MIT) AND CC0-1.0 upstream-ancestors: parameter-sets: - name: XMSS-SHA2_10_256 diff --git a/src/sig_stfl/xmss/CMakeLists.txt b/src/sig_stfl/xmss/CMakeLists.txt index dc57732e16..f9fc4fc08d 100644 --- a/src/sig_stfl/xmss/CMakeLists.txt +++ b/src/sig_stfl/xmss/CMakeLists.txt @@ -1,4 +1,4 @@ -# SPDX-License-Identifier: Apache-2.0 AND MIT +# SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 set(_XMSS_OBJS "") diff --git a/src/sig_stfl/xmss/LICENSE b/src/sig_stfl/xmss/LICENSE index 90a1bebcfa..6fc799ea78 100644 --- a/src/sig_stfl/xmss/LICENSE +++ b/src/sig_stfl/xmss/LICENSE @@ -1,8 +1,18 @@ ## License -This XMSS reference implementation is Copyright (c) 2024 SandboxAQ and licensed under both the [Apache License, Version 2.0](https://www.apache.org/licenses/LICENSE-2.0.txt) and [MIT License](LICENSE-MIT). +This XMSS reference implementation is Copyright (c) 2024 SandboxAQ and licensed under the CC0-1.0 AND ([Apache License, Version 2.0](https://www.apache.org/licenses/LICENSE-2.0.txt) OR MIT License) at your option. -Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions. +--------------------------------- +The MIT License (MIT) + +Copyright © 2024 SandboxAQ + +Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. +--------------------------------- This XMSS reference implementation is based on the [XMSS reference implementation written by Andreas Hülsing and Joost Rijneveld](https://github.com/XMSS/xmss-reference#license) provided under the CC0 1.0 Universal Public Domain Dedication. diff --git a/src/sig_stfl/xmss/LICENSE-MIT b/src/sig_stfl/xmss/LICENSE-MIT deleted file mode 100644 index 7b1af979f6..0000000000 --- a/src/sig_stfl/xmss/LICENSE-MIT +++ /dev/null @@ -1,9 +0,0 @@ -The MIT License (MIT) - -Copyright © 2024 SandboxAQ - -Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: - -The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. - -THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/src/sig_stfl/xmss/external/core_hash.c b/src/sig_stfl/xmss/external/core_hash.c index 72fe4e9d5c..7c80f3f860 100644 --- a/src/sig_stfl/xmss/external/core_hash.c +++ b/src/sig_stfl/xmss/external/core_hash.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include #include "core_hash.h" diff --git a/src/sig_stfl/xmss/external/core_hash.h b/src/sig_stfl/xmss/external/core_hash.h index e292e4c06d..dbbeecca83 100644 --- a/src/sig_stfl/xmss/external/core_hash.h +++ b/src/sig_stfl/xmss/external/core_hash.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef CORE_HASH #define CORE_HASH diff --git a/src/sig_stfl/xmss/external/hash.c b/src/sig_stfl/xmss/external/hash.c index 557c8de7db..f9272f01c3 100644 --- a/src/sig_stfl/xmss/external/hash.c +++ b/src/sig_stfl/xmss/external/hash.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include diff --git a/src/sig_stfl/xmss/external/hash.h b/src/sig_stfl/xmss/external/hash.h index bd1e1c1202..708dd6932a 100644 --- a/src/sig_stfl/xmss/external/hash.h +++ b/src/sig_stfl/xmss/external/hash.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_HASH_H #define XMSS_HASH_H diff --git a/src/sig_stfl/xmss/external/hash_address.c b/src/sig_stfl/xmss/external/hash_address.c index a9fec506b5..eaa5ff6fc9 100644 --- a/src/sig_stfl/xmss/external/hash_address.c +++ b/src/sig_stfl/xmss/external/hash_address.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include "hash_address.h" diff --git a/src/sig_stfl/xmss/external/hash_address.h b/src/sig_stfl/xmss/external/hash_address.h index 06f5c502bd..3929558546 100644 --- a/src/sig_stfl/xmss/external/hash_address.h +++ b/src/sig_stfl/xmss/external/hash_address.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_HASH_ADDRESS_H #define XMSS_HASH_ADDRESS_H diff --git a/src/sig_stfl/xmss/external/namespace.h b/src/sig_stfl/xmss/external/namespace.h index 7bb7d05349..3fe67527d2 100644 --- a/src/sig_stfl/xmss/external/namespace.h +++ b/src/sig_stfl/xmss/external/namespace.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_NAMESPACE_H #define XMSS_NAMESPACE_H diff --git a/src/sig_stfl/xmss/external/params.c b/src/sig_stfl/xmss/external/params.c index f9ba544e47..a1d49d1340 100644 --- a/src/sig_stfl/xmss/external/params.c +++ b/src/sig_stfl/xmss/external/params.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include diff --git a/src/sig_stfl/xmss/external/params.h b/src/sig_stfl/xmss/external/params.h index f75e3c97c5..e9a5faaa2b 100644 --- a/src/sig_stfl/xmss/external/params.h +++ b/src/sig_stfl/xmss/external/params.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_PARAMS_H #define XMSS_PARAMS_H diff --git a/src/sig_stfl/xmss/external/utils.c b/src/sig_stfl/xmss/external/utils.c index c2d76aba15..f03ef93d40 100644 --- a/src/sig_stfl/xmss/external/utils.c +++ b/src/sig_stfl/xmss/external/utils.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "utils.h" /** diff --git a/src/sig_stfl/xmss/external/utils.h b/src/sig_stfl/xmss/external/utils.h index 14d8588ddc..e3c1d2853d 100644 --- a/src/sig_stfl/xmss/external/utils.h +++ b/src/sig_stfl/xmss/external/utils.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_UTILS_H #define XMSS_UTILS_H diff --git a/src/sig_stfl/xmss/external/wots.c b/src/sig_stfl/xmss/external/wots.c index a4bfae956d..8ef4f026cd 100644 --- a/src/sig_stfl/xmss/external/wots.c +++ b/src/sig_stfl/xmss/external/wots.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include diff --git a/src/sig_stfl/xmss/external/wots.h b/src/sig_stfl/xmss/external/wots.h index e0e3f1d0a9..8f8756ede3 100644 --- a/src/sig_stfl/xmss/external/wots.h +++ b/src/sig_stfl/xmss/external/wots.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_WOTS_H #define XMSS_WOTS_H diff --git a/src/sig_stfl/xmss/external/xmss.c b/src/sig_stfl/xmss/external/xmss.c index 71d3f0a463..6a224a8d3e 100644 --- a/src/sig_stfl/xmss/external/xmss.c +++ b/src/sig_stfl/xmss/external/xmss.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include "params.h" diff --git a/src/sig_stfl/xmss/external/xmss.h b/src/sig_stfl/xmss/external/xmss.h index 53d21e2dbd..566b809b9e 100644 --- a/src/sig_stfl/xmss/external/xmss.h +++ b/src/sig_stfl/xmss/external/xmss.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_H #define XMSS_H diff --git a/src/sig_stfl/xmss/external/xmss_commons.c b/src/sig_stfl/xmss/external/xmss_commons.c index 168e6ffed5..645faf0112 100644 --- a/src/sig_stfl/xmss/external/xmss_commons.c +++ b/src/sig_stfl/xmss/external/xmss_commons.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include #include diff --git a/src/sig_stfl/xmss/external/xmss_commons.h b/src/sig_stfl/xmss/external/xmss_commons.h index 26eb537ee3..958fd3ffa3 100644 --- a/src/sig_stfl/xmss/external/xmss_commons.h +++ b/src/sig_stfl/xmss/external/xmss_commons.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_COMMONS_H #define XMSS_COMMONS_H diff --git a/src/sig_stfl/xmss/external/xmss_core.c b/src/sig_stfl/xmss/external/xmss_core.c index 4d7e8de096..1052d4d7e5 100644 --- a/src/sig_stfl/xmss/external/xmss_core.c +++ b/src/sig_stfl/xmss/external/xmss_core.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include #include diff --git a/src/sig_stfl/xmss/external/xmss_core.h b/src/sig_stfl/xmss/external/xmss_core.h index 007c42172a..54cccc25e4 100644 --- a/src/sig_stfl/xmss/external/xmss_core.h +++ b/src/sig_stfl/xmss/external/xmss_core.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef XMSS_CORE_H #define XMSS_CORE_H diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c index 71b0f471ca..d539c1f6c2 100644 --- a/src/sig_stfl/xmss/external/xmss_core_fast.c +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index 4166cafcb7..a926c5ddd3 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #ifndef OQS_SIG_STFL_XMSS_H #define OQS_SIG_STFL_XMSS_H diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c index ce2df38238..64d714e600 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index 4f6413a98b..59321ffcfa 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c index 7b9bcff39b..7e4a5e50c2 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h10.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c index c883e21e0e..bcd4cd56de 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h16.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c index a190255f2c..80392100cd 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha256_h20.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c index 1ff4cd891a..1a4fe53c41 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h10.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHA2_10_512 ======================== // + XMSS_ALG(, _sha512_h10, _SHA512_H10) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c index c1b5ed9150..2e8f87c026 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h16.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c index bf0a5b8d12..bc3827e3de 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_sha512_h20.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c index 8c01394663..85fde8add4 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h10.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_10_256 ======================== // + XMSS_ALG(, _shake128_h10, _SHAKE128_H10) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c index ff45fc0f5f..8b48276f45 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h16.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_10_256 ======================== // + XMSS_ALG(, _shake128_h16, _SHAKE128_H16) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c index d566069a82..30d34b9633 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake128_h20.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_10_256 ======================== // + XMSS_ALG(, _shake128_h20, _SHAKE128_H20) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c index aea7ef0204..dde4f1d400 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h10.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_10_512 ======================== // + XMSS_ALG(, _shake256_h10, _SHAKE256_H10) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c index d96e7644b3..1a41d0f172 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h16.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_16_512 ======================== // + XMSS_ALG(, _shake256_h16, _SHAKE256_H16) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c index 5bf41b07f9..321876fb97 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_shake256_h20.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSS-SHAKE_20_512 ======================== // + XMSS_ALG(, _shake256_h20, _SHAKE256_H20) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c b/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c index 1b81bec309..7868d68c94 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c index f5d99705d3..ec1143f1b8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include #include diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c index 0c6057eef9..1ce98d95ff 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_2.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_20/2_256 ======================== // + XMSS_ALG(mt, mt_sha256_h20_2, MT_SHA256_H20_2) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c index 867e0928b1..c914958bb1 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h20_4.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_20/4_256 ======================== // + XMSS_ALG(mt, mt_sha256_h20_4, MT_SHA256_H20_4) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c index e972df04ee..187292a29e 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_2.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_40/2_256 ======================== // + XMSS_ALG(mt, mt_sha256_h40_2, MT_SHA256_H40_2) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c index 63c9af0bc8..db6ac22a05 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_4.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_40/4_256 ======================== // + XMSS_ALG(mt, mt_sha256_h40_4, MT_SHA256_H40_4) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c index 156c2e3fd6..293810cc19 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h40_8.c @@ -1,7 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_40/8_256 ======================== // -XMSS_ALG(mt, mt_sha256_h40_8, MT_SHA256_H40_8) +XMSS_ALG(mt, mt_sha256_h40_8, MT_SHA256_H40_8) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c index 64f6576f82..eb80bd0f91 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_12.c @@ -1,8 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" - // ======================== XMSSMT-SHA2_60/12_256 ======================== // XMSS_ALG(mt, mt_sha256_h60_12, MT_SHA256_H60_12) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c index d37e1244ae..05a4cef584 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_3.c @@ -1,6 +1,7 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" // ======================== XMSSMT-SHA2_60/3_256 ======================== // + XMSS_ALG(mt, mt_sha256_h60_3, MT_SHA256_H60_3) diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c index d5992617c0..b0a552ca26 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_sha256_h60_6.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c index 76c8523a80..682859a90c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_2.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c index 0dec4743e6..9325b6b81d 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h20_4.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c index 765694287d..9ef0fccb47 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_2.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c index 7ce156c659..2568826e85 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_4.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c index 1c3f9671c0..9605ef940c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h40_8.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c index 793393eaf3..db71c1ca4f 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_12.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c index 09edd7ebd7..60dfeaf572 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_3.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c index aae4ca20a6..e658846d57 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_shake128_h60_6.c @@ -1,4 +1,4 @@ -// SPDX-License-Identifier: Apache-2.0 AND MIT +// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 #include "sig_stfl_xmss_xmssmt.c" From 17c12c3c7f0e1b0c92085f5001559e0f892f9d18 Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Fri, 1 Mar 2024 10:30:12 -0500 Subject: [PATCH 41/68] Add return status for XMSS lock/unlock functions. (#1712) * Add return status for XMSS lock/unlock functions. * it should say return ERROR instead of SUCCESS. --- src/sig_stfl/xmss/sig_stfl_xmss.h | 4 +- .../xmss/sig_stfl_xmss_secret_key_functions.c | 39 ++++++++++++------- 2 files changed, 27 insertions(+), 16 deletions(-) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index a926c5ddd3..6ee03f3b12 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -582,9 +582,9 @@ void OQS_SECRET_KEY_XMSS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_ void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk); /* Lock the key if possible */ -void OQS_SECRET_KEY_XMSS_acquire_lock(const OQS_SIG_STFL_SECRET_KEY *sk); +OQS_STATUS OQS_SECRET_KEY_XMSS_acquire_lock(const OQS_SIG_STFL_SECRET_KEY *sk); /* Unlock the key if possible */ -void OQS_SECRET_KEY_XMSS_release_lock(const OQS_SIG_STFL_SECRET_KEY *sk); +OQS_STATUS OQS_SECRET_KEY_XMSS_release_lock(const OQS_SIG_STFL_SECRET_KEY *sk); #endif /* OQS_SIG_STFL_XMSS_H */ diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index 59321ffcfa..1ccc8e8c09 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -11,8 +11,7 @@ #define XMSS_UNUSED_ATT #endif -extern inline -OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_new(size_t length_secret_key) { +extern inline OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_new(size_t length_secret_key) { // Initialize the secret key in the heap with adequate memory OQS_SIG_STFL_SECRET_KEY *sk = malloc(sizeof(OQS_SIG_STFL_SECRET_KEY)); @@ -71,7 +70,9 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_le } /* Lock the key if possible */ - OQS_SECRET_KEY_XMSS_acquire_lock(sk); + if (OQS_SECRET_KEY_XMSS_acquire_lock(sk) != OQS_SUCCESS) { + return OQS_ERROR; + } uint8_t *sk_buf = malloc(sk->length_secret_key * sizeof(uint8_t)); if (sk_buf == NULL) { @@ -85,7 +86,9 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_le *sk_len = sk->length_secret_key; /* Unlock the key if possible */ - OQS_SECRET_KEY_XMSS_release_lock(sk); + if (OQS_SECRET_KEY_XMSS_release_lock(sk) != OQS_SUCCESS) { + return OQS_ERROR; + } return OQS_SUCCESS; } @@ -143,24 +146,32 @@ void OQS_SECRET_KEY_XMSS_free(OQS_SIG_STFL_SECRET_KEY *sk) { sk->secret_key_data = NULL; } -void OQS_SECRET_KEY_XMSS_acquire_lock(const OQS_SIG_STFL_SECRET_KEY *sk) { +OQS_STATUS OQS_SECRET_KEY_XMSS_acquire_lock(const OQS_SIG_STFL_SECRET_KEY *sk) { if (sk == NULL) { - return; + return OQS_ERROR; } - /* Lock the key if possible */ - if ((sk->lock_key != NULL) && (sk->mutex != NULL)) { - sk->lock_key(sk->mutex); + /* Lock the key if possible, otherwise return OQS_ERROR because the lock_key, unlock_key and mutex are not defined.*/ + if ((sk->lock_key != NULL) && (sk->mutex != NULL) && (sk->unlock_key != NULL)) { + if (sk->lock_key(sk->mutex) != OQS_SUCCESS) { + return OQS_ERROR; + } } + + return OQS_SUCCESS; } -void OQS_SECRET_KEY_XMSS_release_lock(const OQS_SIG_STFL_SECRET_KEY *sk) { +OQS_STATUS OQS_SECRET_KEY_XMSS_release_lock(const OQS_SIG_STFL_SECRET_KEY *sk) { if (sk == NULL) { - return; + return OQS_ERROR; } - /* Unlock the key if possible */ - if ((sk->unlock_key != NULL) && (sk->mutex != NULL)) { - sk->unlock_key(sk->mutex); + /* Unlock the key if possible, otherwise return OQS_ERROR because the lock_key, unlock_key and mutex are not defined. */ + if ((sk->unlock_key != NULL) && (sk->mutex != NULL) && (sk->lock_key != NULL)) { + if (sk->unlock_key(sk->mutex) != OQS_SUCCESS) { + return OQS_ERROR; + } } + + return OQS_SUCCESS; } From 32949b7dfbc72458d18e06c3e8b4be4cb688dd1e Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Mon, 11 Mar 2024 14:33:41 -0400 Subject: [PATCH 42/68] Reformat LMS / XMSS KAT files (#1722) Signed-off-by: Spencer Wilson --- tests/KATs/sig_stfl/kats.json | 94 +++++++++---------- tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp | 2 - .../sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp | 2 - tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp | 2 - .../sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp | 2 - tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp | 4 +- tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp | 4 +- tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp | 4 +- tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp | 4 +- tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp | 4 +- tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp | 4 +- .../KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp | 4 +- .../KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp | 4 +- .../KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp | 4 +- .../KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp | 4 +- .../KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp | 4 +- .../KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp | 4 +- .../sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp | 4 +- tests/kat_sig_stfl.c | 6 +- 48 files changed, 77 insertions(+), 171 deletions(-) diff --git a/tests/KATs/sig_stfl/kats.json b/tests/KATs/sig_stfl/kats.json index 59bda4d7e2..21d0c11252 100644 --- a/tests/KATs/sig_stfl/kats.json +++ b/tests/KATs/sig_stfl/kats.json @@ -1,48 +1,48 @@ { - "XMSS-SHA2_10_256": "4ff9ea00bec98f790a5b5e96ddb8441d58e646d679a47f02db21085c35a006f4", - "XMSS-SHA2_16_256": "398ef810276efaeabc84780816950a9243be0b37122f33db556010a5ec606a8d", - "XMSS-SHA2_20_256": "d695061163e3a5124222a6d3202f1e397cde65733b84d700196a9c55b7d721a2", - "XMSS-SHAKE_10_256": "b5ec13a0eceb7cc1bd14f2288557b7dcb431c3c930ed8eb2d09be32eca52f722", - "XMSS-SHAKE_16_256": "2875eafcdad20e964c6abf4d90bdb73e1ab47fd2e636ed949502fff9f77ea94f", - "XMSS-SHAKE_20_256": "7e78a5792165d0ba1484f4cca60985373be475fbf1047e58997798b2048f5048", - "XMSS-SHA2_10_512": "791840f9f015bad6df9138d2ced1690daea746f65d54826ce85a6ba38211d16c", - "XMSS-SHA2_16_512": "c060814c9e029d9272c8942bb3f9a5ca46cf361e59c16bf70065476243095196", - "XMSS-SHA2_20_512": "c5684bba5d53983cf3c52b45ca0b443a38102573cae4aeab5e4a911b02b0fe47", - "XMSS-SHAKE_10_512": "edd6ff8923afdefa3ad7b5158f2adc90eb58c377b847c5c35508546a7ea2ca3c", - "XMSS-SHAKE_16_512": "537540146232f6647c215e32ae057fc9cf3e83932a6447953c7f9ac5d38eccf0", - "XMSS-SHAKE_20_512": "e803f3af92cea3f8004a94484f8f666b306fa353c3b09e9e0763b63f7f9b20d6", - "XMSSMT-SHA2_20/2_256": "da52ae24ebd6fb3ef85a80d83357835164a292fd8c0e83a32c21d386969d5c0b", - "XMSSMT-SHA2_20/4_256": "eb5a0afd967f660714b1b9bb6a214f348cfeb06e474048c94d6e08de183b78fe", - "XMSSMT-SHA2_40/2_256": "0cb74272d179eaefc180303cfaaaed13093268ead2b6e3d066228b64077609ee", - "XMSSMT-SHA2_40/4_256": "16a7047724db2ff45999a4e95048bae3bac5d645986d6670014c53478412b4f1", - "XMSSMT-SHA2_40/8_256": "fff5c6a02f8995342199155052ac5115af6340ff9e729a1609c815c891797111", - "XMSSMT-SHA2_60/12_256": "2e5869150c17da8c13094b66a94a94342d62d035fa63bd972757f3eda2c9c248", - "XMSSMT-SHA2_60/3_256": "04b10f0320cd77b8094b1116d67085b38a0d68f02aa9b0ec5938a511ece1ef6f", - "XMSSMT-SHA2_60/6_256": "0ea5be22f851a84e1bbbc21a84dfb5c5a5d2f5d636dbae49e1e092e6ec5833f9", - "XMSSMT-SHAKE_20/2_256": "5893c3acc4ab1448510888ca6c6f483d1ed247028900752d11d2ec9dea77356d", - "XMSSMT-SHAKE_20/4_256": "eece12452652dc37d1600b39e4bf589ac12bee6d5e5025845bc06c7e5321669e", - "XMSSMT-SHAKE_40/2_256" : "c5a539dc3cd7af4710362c3e9962137e33e4061099bb2dd0a03eff862c9cd01d", - "XMSSMT-SHAKE_40/4_256" : "b25c826e97d442ade70dff6e7008e95c099d7cde6f533fb9059299d9e1ff200c", - "XMSSMT-SHAKE_40/8_256" : "cf301b7d978d5c0afcdf3300ba97d829e2e5f737cb449968b19b45f05b987591", - "XMSSMT-SHAKE_60/3_256" : "09d26df5e911e98e71ef73a1ab6f224964d4a7beacd8071b4c7f7d1930a537bd", - "XMSSMT-SHAKE_60/6_256" : "0692a32e318d5c3ac8631120910b783edfed4cb7ed69e3ffa29f83aaa34e27d5", - "XMSSMT-SHAKE_60/12_256" : "1a05ff4a4fea850a5fe5c9e976006577335eab0494e1759fe217c2f33f5a84e6", - "LMS_SHA256_H5_W1" : "6b5ffc953ee90b32ee4f1972de5bbb8f055073e831009fc3004e1ead32ecf64e", - "LMS_SHA256_H5_W2" : "68f4412a902595e6debe7da1af714ba3179e2ea21053d8fa25acc1bddad7232c", - "LMS_SHA256_H5_W4" : "01c828a559c5b91b3347c4a1ff5040a50371b7056b4248cba6b8d35080240e37", - "LMS_SHA256_H5_W8" : "f8bc9145732676a2017a3cd065cca68d224cef1671487e3cbd921bd9c772c745", - "LMS_SHA256_H10_W1" : "276a037406ce9f1df6a8ff87f6b892d45bd42af5724a2ebd3fdb1d64b3d94d5f", - "LMS_SHA256_H10_W2" : "c59da910cf06a8de9f0c5fd4b55895ce1996a55983f4c8d9be328c5d83831041", - "LMS_SHA256_H10_W4" : "2ae301108ed8c9eb363e423a483925dcfc089720cd5b9cf8eee62bd1869c8182", - "LMS_SHA256_H10_W8" : "3eac8278b3f9eaea6361ced30149d2d3136c153c6e45d59899af4322e5df7941", - "LMS_SHA256_H15_W1" : "a68af38d6c955fda6c6deabb6925a686ad768ffaa0f6a93d8649e5985dbc6be1", - "LMS_SHA256_H15_W2" : "3ce54ed403203c996c50bf50c69492acb7cadbb41521c2b7d49baed65fe2bda4", - "LMS_SHA256_H15_W4" : "38cce574c163e6a7167ae328dc6bdd44c60d4e9be08408eaa6c239d8625d5a07", - "LMS_SHA256_H15_W8" : "a2e16430224b3caeebd63397e9780be087efcf672421ffc5008f852af2597692", - "LMS_SHA256_H20_W1" : "b31f8b45eee9ec551178cb260cc431256ed7ddd233e69de1587579f0b8ff0128", - "LMS_SHA256_H20_W2" : "0d9ced22271ab0bf90968ec4934a4a44211ef25df11e562bc32767a42cd3a9b2", - "LMS_SHA256_H20_W4" : "7f52315a8fe04caee69874e87bc0f7f4ce38a250f95a0ed39baecc0cb55cad54", - "LMS_SHA256_H20_W8" : "1f5d5a149830ad72a9709659d5968997ffe4a43e034a5c72550032ce6dbb53c2", - "LMS_SHA256_H5_W8_H5_W8": "fa6f9a0948626c1e078ad442ea2fccdf456b529413eba441c175cbb681f9bc32", - "LMS_SHA256_H10_W4_H5_W8": "2485c56164bbfa4bdc8604195bf397bfe8f54e2ebe925423e4e70fce173c0fff" -} \ No newline at end of file + "XMSS-SHA2_10_256": "7acc06cc456a087456f937d07c7acae2ffeee517cf71b1693adc916f638df388", + "XMSS-SHA2_16_256": "b20ee19984d6a47529c8e2c127e43e619090a7dff0f2dfdc750d96b6d2453275", + "XMSS-SHA2_20_256": "0632c1e3049918a208676d9d39a97b81f3296665205ad342ed0f0042c7ad848c", + "XMSS-SHAKE_10_256": "f5175c88db4f0ffca54998e0e46cc15d02b5f193063cc349926e493fbe8c39f4", + "XMSS-SHAKE_16_256": "519f61b7c839cf29b4a67b8fa9bfa64a37b360cb98232363a7768a5004ac8a37", + "XMSS-SHAKE_20_256": "0b1e25ce1c89709624a3a668a4ac75ae053f1306b5f461b9424ca3ae6a153057", + "XMSS-SHA2_10_512": "854cb9aede50a359703934010d08db846a3a8c4b9b984471cba74ef07d620bc5", + "XMSS-SHA2_16_512": "772613c5d30da675b87a4f3f932ac71c7dc3ebf8803a9bc12936e6683c3f60d1", + "XMSS-SHA2_20_512": "7ae409257aaf6756ac9a804aec3df8ab98916e026f6ffa2a78da3bbc97dd48b7", + "XMSS-SHAKE_10_512": "8142c58d407dab3f39f1142e253fff535c572d5adcb4fd21b51a62eef33453d8", + "XMSS-SHAKE_16_512": "29150754aad6d8150e86f58224f72521d76d5bfba43d5f54791c1d5def27a205", + "XMSS-SHAKE_20_512": "fbe74ab00eb150f63b9da9ddd325b667e55a65bb994434ccf2c7b670e7e22406", + "XMSSMT-SHA2_20/2_256": "9f117294999c886ac6b69d6f32c3fc152599343add210f4464aee5d1ca0ec34d", + "XMSSMT-SHA2_20/4_256": "0c990e8ff8189140e8539b11ae3f85040544fc7d549f8db17d83392569647de9", + "XMSSMT-SHA2_40/2_256": "91605c4b67afb4e17d57ed076e10d3c4287264deea4a46092e374199c041d489", + "XMSSMT-SHA2_40/4_256": "78e16d2935701cda17ecf493f5ed292827c20f0bf34c1c63c25c94f028ee62c9", + "XMSSMT-SHA2_40/8_256": "f0feef94797276e832634a3b55020a8791dbe14d400e3c076d4f8ecd53892dac", + "XMSSMT-SHA2_60/12_256": "7bdbc5498d33dffcb32675df8578d8ef590f0f06cbac6685342a131cc34bc720", + "XMSSMT-SHA2_60/3_256": "62ee9b8b9a46ed95a2e4fb3d18552fe2e87f91e530b0fb82c5edb1242c0e0258", + "XMSSMT-SHA2_60/6_256": "5ab099ea120729e8b4fbbd074bc7b60396c009a69725eeefefa9d89274b2ba83", + "XMSSMT-SHAKE_20/2_256": "75d79d1a8a0cc714a97acc956f12040808c9382b37e3fb2d389e5ad29a1f3b53", + "XMSSMT-SHAKE_20/4_256": "391f4d0b64d1a24f53fcc642bd679f4b6f9230abd1c4641f30e6c7d7dee451f9", + "XMSSMT-SHAKE_40/2_256": "f2601cb4acc1422852ff3dd933ed84f3ce4dcb0218db6f43793bb146e6b75a10", + "XMSSMT-SHAKE_40/4_256": "eb578e8b7d7dad45e99a177abe482fbd087c9281767b1a3bdd660c2d5e04712d", + "XMSSMT-SHAKE_40/8_256": "1597d62ea8aebbebaf364141d1443a804fe3f6d0705165a55794096a4a3b1c71", + "XMSSMT-SHAKE_60/3_256": "7ca90f7c64b21d844975ef39c48405dc61922f6fd0be8cbb88b2a18a54bc754d", + "XMSSMT-SHAKE_60/6_256": "c11ca5be510f88c9c8188cb98da65e7d4b2be1cd7efc5a9769348c4fa2b33b24", + "XMSSMT-SHAKE_60/12_256": "79b6690809f1317fbc2466590e4fccc8a7f706b05abcb277ad1018565096ad88", + "LMS_SHA256_H5_W1": "26273b16351d40b7a7bf73db200c4494cba890624235d214bca9368e60cd1c02", + "LMS_SHA256_H5_W2": "a4877dbf9f06a08469afaee13cf25ef98e20064d2be0009888c68698995aca7d", + "LMS_SHA256_H5_W4": "e13ceda1f66c90cad1a15087f26bb025378f7fbb69ecfc138ac365a9bf3fb6a5", + "LMS_SHA256_H5_W8": "175f2b5b8a6e8a5faa82bdeb2779a88cc977ad7cca46d815b0d02c6dd672396d", + "LMS_SHA256_H10_W1": "b52bb3ff8fab21d69eb0933f5eeffac1380f87c1c8154983cfe4f3f27fcfb1e9", + "LMS_SHA256_H10_W2": "a1a2709362ac8aeb956d0d88cd4a42ce2fc8df9a69979270299b9471f61c3dbd", + "LMS_SHA256_H10_W4": "707e4ff1adb835f6e79453caca0c787c156a2ee270b1657a42ebbe6eb7424494", + "LMS_SHA256_H10_W8": "799e7bdf00fc0839519e6847b7df40763b89949e1d1b99bd5b9f669387bf0fbc", + "LMS_SHA256_H15_W1": "af9d334c2d306bb1f5409f45c4669799c952593cb23e1ecd5acce37900bf598b", + "LMS_SHA256_H15_W2": "0c6455312cd68eb9023ed4e74474c000210d67d042038a62dbe322a3f4c43c2b", + "LMS_SHA256_H15_W4": "9e2a4d4b52212ecfbb0a1df877aaef0406e373bcec54597df81bd1d300c2eaba", + "LMS_SHA256_H15_W8": "ea0f3dcdcf73a2b990b86707c480fc698f9325537672928064c9b40348ce1cca", + "LMS_SHA256_H20_W1": "5670ee0668ccb704e15c9f6e42f4a017f4b8cf8aa34c311ca905b1b538a2352f", + "LMS_SHA256_H20_W2": "53e844066e5dda43713261704c6d07b785373dccc37293b2cbe2ba1b7b961382", + "LMS_SHA256_H20_W4": "55a9c196d69acdff73b2e95f9d0bb97b9edd260bd93f53b5ce4f50c26d6575a4", + "LMS_SHA256_H20_W8": "2594c05e1ae86a029ff42a74d2b3ab4d0adf01729f4fbfe81269037ac029c184", + "LMS_SHA256_H5_W8_H5_W8": "a20ce5f27d9962865463223a138a7507f30690ec7268e802eb6ba2f04c6bd99e", + "LMS_SHA256_H10_W4_H5_W8": "f51cd27e5a35f63586796a39f00d6729f5148fb6d454e61737fbdeebbde3aed8" +} diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp index 206c2dd284..13e87a9215 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W1.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H10_W1 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm =  diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp index 4a8296a3b8..8bfba122e1 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W2.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H10_W2 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm =  diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp index ed69d34822..a11e9ec00d 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H10_W4 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm = 000000000000000100000003584a33ceb2d50a9af04409357774dbaf8b8ea517370e62c4dc06882c1407baca174157ebbde27d8e255d5c522c78617f3cfa03b811e32593ca965f771f8d88fb3059a272c3b9af8e445b37650f3616b9a06d2a79e74e847dceddcb6f854fbae8e6790d241e5e496a66244ae738bca8482630b5369e2c45e27c7ed919fa298c1d5ca5efdde0a12b258a584c9f44799b5c40f3889b1e8f3c274a355e24c088bcdb5288a47bf40a4677062662f4feef135493ea4498640c8efca349dbedbf5525af5425a8aabbfb671de5f71072eb07867e15c383a06f39ca2a09ae0d53c4db18370011d4ab6842a35c3bab93e642bee89310ac457e68869f4289f9e93ba553e39892b2969578ca5a02ae8a0272f1b2d6c8a022dac6a397d84bd2ea56136ea45aaccc1122aca34bd4ba6a7a06b2cfede81ce193ff878368f9f2181b8116185558cee1cac048f61109ae5c7b3973241919d9974f8b44dde66f1a8b2830abebf3ba1a115f4563453fe20f7ac023f6a02544d24b38e661a25a68ccb44c287f28d3fb0769048eee6d8f41046423d77e56344f7d5771f8ebacda4a4b5069f0c4746a74e77aa8b5615257b2dbac9863937e6d9c905217341a825c0460dce7a13845db6449d1e1f86d42731df8eb6f4381d71dff4defc11fa5d6bc9a0309a47e298dcf55e559c750f3c5d0fc1a1fedc8c8c0248a7babf6390fbcf70ad7b51259b336a2a39e1306968abb7f39a94a36374910ffa96a436a225436f7753eb7a28198750c3b5deffa1092eeec7857244b4a4d13d1eec3adf0efcce3ea75507f376a6c7effcd9e904ef2bd7b3c8c092066d46955c7ca38ed79ca8a7ffb1617d1619026c8fcb3cdc23c7403cc3f90e3c3d88123b20d40e8763c0aeccaadf79c41a69667cdbdfb73b33642f1d1e3b021cf2400e6252526d3fe62edc9d022e88ef111b6b5b668d2b20e23baccd9746668fb63f3916630506d0b696d850dcc60eec42504398f4d25e2eb6f36a417bd71c20c780f1a5075f86e953302ef0b7a6a9b909857d0ee6fd4c1ade224cf667067d9df328433b19e136bed536e364f82ac05705439967560c8606cd1c26b7146b82e825a233dca703ce03ab7df5c5345b5285be16d542a47a1fb4af74e786cbfd01c0456b8f86fd0e685137617224ff627b5f3dfbb75c9258484d9347ad6282e170c2657f5721e24d5643a4705d6f9aa335294278421da783d44ac38cfc7676740a399f9002ecac9a78b41c70c3188298dca26452b72a8d582d167c3c965d5f5c8c8f57022f417b0941f7828721951978d568a3d2ee0b7a843e5c697b0c7fc0975f0f09fd18856a16fc63db04e0f3ce3a357e4d3208546460814c270629d7810e452454927f29666a919fc8fb104f3c9c1fd38c19c6574d4dddb5c18683a8973cd061faf5f5c18b66734bf8c08766612897d0d9025e380c6317d88791d0861484e51f205c14e0bd83d2d61c394df3645eb0d66c80ded707429fe5e1fa77f3c3389ac59b353ca657e6aa88dcf6498479e76bbba01e75e9d992e6d3181eccd53e122c0c3ed428d809eef91934ee657364151bf711f0c922b6490fa2a9ea9ef02a9fad3a655cd305a2ccff01f60b9ca0b3e8381cd83960c08c066a30a9f46585e7ba143da7700216cb5234406301beb66a0cecd7d8122429992f8eab74cebaa1e7c8ce4d54587056bdad8636c46326e484c63b5aef8b6560e289acc20b953e8bac254da2f22751d83845be6132c6595cbf91b0d2ff7402fd789c92249af031afc1076bc99b9e9cd6e42a1a2dcf8baa42a0c34dc343508e70bb0760e5f9d8ec6390995bbca810dff3a0474c59cf9fafd9d09bf190bbafe003c7576960a6dcfa0226f874a084b4a50d6a680f88f1f3f352c71eb26df521e5ac9c2c6cc410c51ecbfcd090d7c09541810c80cafa5710c849ed324ee734a8ec0610a1a0ccda429f86b28ca0d0cfdc7d29ec03ea1b97021dbb00a7837d5ec8f6e6ae198ae31c9b4365aec42e83e92e879fb641915ca129324176444171873a75b3df1322cc74796b5e6cac0f950d92c322a8a3c6c0a824f8f92ae30aa110c8a415687ce6dae5135b4121b67fe4e5bff65fda4e0cde3372a0937488d22211c92192eebb9c0b38770356fc65533a86efb75a759fcb02c62aff2f61d3af079ce09d6b01ec9d6fd3fa6f5e2f60273f4b9c3de7bed546311557c197dd2c5398853a5b768db5d45b64d2860137c1c1e9bf3bbaf8f44cda1ba1c88798bf91c962195a11d1d43b937801243ad3483d951ce3c250de463aa136273c9fb9404ea92a204ad15a161852182d271e6dccce0c1385eb8a192d063b0a018cfa36d8357d89f1257aef5be8be3f26051dcd238e4977324204029f2d70a4dd2a9e9cdef1831c7163276bcfff2f2530f29dff5dac9a7026f3ebf9ee0449465a61db572b18434dcbd30fb0843ed81560473f8529191b25abb086d5ee06022b10a64b3a1ff18aeeccf277c4b33c9ecf4097bd5097e6bd0a30ad4d52cf5db089d15f4627a44e0689781a6c6a8ce08d744123f6364b1e7428aea701b20985f2ef76cdb3023297c894c7f14892a3e891f396a3edc2507892034a142556e78deba31ee286f0e2752eea28a0322789fecdeec35306d87105ca2c19f977597bdce1de1f8cc1f00c45ab2ecc7dd6f2d8e8e7f625be39a2348e77688819ed541d2c12ed74688d201fa307d958ebc4b8ce08a6b0e9a3116b89a038807e587bceb9cc98cb91d69f884c67e88e30c7c8d72b208dca96f6af60a73c4444d5e7f5b472fd2ca3b36cfa2b4bcb767acea4d8085b080e57f76ccc0dce2c2943b6c806ce20c88300bed34a383e5bbcdfad496910b9198bd43364da92d1fec89b90b53ba54ac634d5ac1f7faf0385358b6b0b5f5d06e31df6d3b17eb9181cfa131897dacbde42ae3c66010b978ea391944db2b52e52e47ff7312b1600e569b46859bfb6af8c4402ccaa3632eb293ced20d61552c75f0068b5a0a7d71f276367f0061f01e7fe71985ecd70fea79d406217f42260791f554b1a1b943e5312ee65251ac228d78c90f517949f6460dd3664f09b092f483d6ef2c00000006ecf1ce60192137cb466675f2310292d462477d811c672cb1890ffff4979ded0aa791c87c602307be68e7e3ed69e59b7c22458d9d49f353679f1f89cba91cd886900b1eb3666e5f0e78dec37a110c5cf09c1571f66e5862d48f6f4dc01812fb600ab2b3ddb1c5585cb2127e4a5e5faf00636beeeafb3b18f2481de5a4dbb9182e93a5cad39c43bab87f66eefd1428d0a426e0ee8c41fab4baf40bb982b9b5f1ce9eb65ad914744b45a4f00c11dc8fb012844cde05816d91fd387be9a2087c3758634e4ae3658a035e9b9e2d50a98ecb21489779c538aac7fde32b293e4f809494a800bb16c5ad2e8d4f22d61fadd2cf82bcc9ac210bada1a203f90f67b115cca1f9c109cc955776335779e6d9153a9880c91c9af9eac9e88b7a5e5bceb3bba9ec9432fe015b672ce4c04cc49ec42b865038b7166de32c1f745c27ee919bc25d0a diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp index d5b66c3f7d..638351718d 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W4_H5_W8.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H10_W4_H5_W8 - msg = 54686520656e756d65726174696f6e20696e2074686520436f6e737469747574696f6e2c206f66206365727461696e207269676874732c207368616c6c206e6f7420626520636f6e73747275656420746f2064656e79206f7220646973706172616765206f74686572732072657461696e6564206279207468652070656f706c652e0a sm = 0000000100000003000000033d46bee8660f8f215d3f96408a7a64cf1c4da02b63a55f62c666ef5707a914ce0674e8cb7a55f0c48d484f31f3aa4af9719a74f22cf823b94431d01c926e2a76bb71226d279700ec81c9e95fb11a0d10d065279a5796e265ae17737c44eb8c594508e126a9a7870bf4360820bdeb9a01d9693779e416828e75bddd7d8c70d50a0ac8ba39810909d445f44cb5bb58de737e60cb4345302786ef2c6b14af212ca19edeaa3bfcfe8baa6621ce88480df2371dd37add732c9de4ea2ce0dffa53c92649a18d39a50788f4652987f226a1d48168205df6ae7c58e049a25d4907edc1aa90da8aa5e5f7671773e941d8055360215c6b60dd35463cf2240a9c06d694e9cb54e7b1e1bf494d0d1a28c0d31acc75161f4f485dfd3cb9578e836ec2dc722f37ed30872e07f2b8bd0374eb57d22c614e09150f6c0d8774a39a6e168211035dc52988ab46eaca9ec597fb18b4936e66ef2f0df26e8d1e34da28cbb3af752313720c7b345434f72d65314328bbb030d0f0f6d5e47b28ea91008fb11b05017705a8be3b2adb83c60a54f9d1d1b2f476f9e393eb5695203d2ba6ad815e6a111ea293dcc21033f9453d49c8e5a6387f588b1ea4f706217c151e05f55a6eb7997be09d56a326a32f9cba1fbe1c07bb49fa04cecf9df1a1b815483c75d7a27cc88ad1b1238e5ea986b53e087045723ce16187eda22e33b2c70709e53251025abde8939645fc8c0693e97763928f00b2e3c75af3942d8ddaee81b59a6f1f67efda0ef81d11873b59137f67800b35e81b01563d187c4a1575a1acb92d087b517a8833383f05d357ef4678de0c57ff9f1b2da61dfde5d88318bcdde4d9061cc75c2de3cd4740dd7739ca3ef66f1930026f47d9ebaa713b07176f76f953e1c2e7f8f271a6ca375dbfb83d719b1635a7d8a13891957944b1c29bb101913e166e11bd5f34186fa6c0a555c9026b256a6860f4866bd6d0b5bf90627086c6149133f8282ce6c9b3622442443d5eca959d6c14ca8389d12c4068b503e4e3c39b635bea245d9d05a2558f249c9661c0427d2e489ca5b5dde220a90333f4862aec793223c781997da98266c12c50ea28b2c438e7a379eb106eca0c7fd6006e9bf612f3ea0a454ba3bdb76e8027992e60de01e9094fddeb3349883914fb17a9621ab929d970d101e45f8278c14b032bcab02bd15692d21b6c5c204abbf077d465553bd6eda645e6c3065d33b10d518a61e15ed0f092c32226281a29c8a0f50cde0a8c66236e29c2f310a375cebda1dc6bb9a1a01dae6c7aba8ebedc6371a7d52aacb955f83bd6e4f84d2949dcc198fb77c7e5cdf6040b0f84faf82808bf985577f0a2acf2ec7ed7c0b0ae8a270e951743ff23e0b2dd12e9c3c828fb5598a22461af94d568f29240ba2820c4591f71c088f96e095dd98beae456579ebbba36f6d9ca2613d1c26eee4d8c73217ac5962b5f3147b492e8831597fd89b64aa7fde82e1974d2f6779504dc21435eb3109350756b9fdabe1c6f368081bd40b27ebcb9819a75d7df8bb07bb05db1bab705a4b7e37125186339464ad8faaa4f052cc1272919fde3e025bb64aa8e0eb1fcbfcc25acb5f718ce4f7c2182fb393a1814b0e942490e52d3bca817b2b26e90d4c9b0cc38608a6cef5eb153af0858acc867c9922aed43bb67d7b33acc519313d28d41a5c6fe6cf3595dd5ee63f0a4c4065a083590b275788bee7ad875a7f88dd73720708c6c6c0ecf1f43bbaadae6f208557fdc07bd4ed91f88ce4c0de842761c70c186bfdafafc444834bd3418be4253a71eaf41d718753ad07754ca3effd5960b0336981795721426803599ed5b2b7516920efcbe32ada4bcf6c73bd29e3fa152d9adeca36020fdeeee1b739521d3ea8c0da497003df1513897b0f54794a873670b8d93bcca2ae47e64424b7423e1f078d9554bb5232cc6de8aae9b83fa5b9510beb39ccf4b4e1d9c0f19d5e17f58e5b8705d9a6837a7d9bf99cd13387af256a8491671f1f2f22af253bcff54b673199bdb7d05d81064ef05f80f0153d0be7919684b23da8d42ff3effdb7ca0985033f389181f47659138003d712b5ec0a614d31cc7487f52de8664916af79c98456b2c94a8038083db55391e3475862250274a1de2584fec975fb09536792cfbfcf6192856cc76eb5b13dc4709e2f7301ddff26ec1b23de2d188c999166c74e1e14bbc15f457cf4e471ae13dcbdd9c50f4d646fc6278e8fe7eb6cb5c94100fa870187380b777ed19d7868fd8ca7ceb7fa7d5cc861c5bdac98e7495eb0a2ceec1924ae979f44c5390ebedddc65d6ec11287d978b8df064219bc5679f7d7b264a76ff272b2ac9f2f7cfc9fdcfb6a51428240027afd9d52a79b647c90c2709e060ed70f87299dd798d68f4fadd3da6c51d839f851f98f67840b964ebe73f8cec41572538ec6bc131034ca2894eb736b3bda93d9f5f6fa6f6c0f03ce43362b8414940355fb54d3dfdd03633ae108f3de3ebc85a3ff51efeea3bc2cf27e1658f1789ee612c83d0f5fd56f7cd071930e2946beeecaa04dccea9f97786001475e0294bc2852f62eb5d39bb9fbeef75916efe44a662ecae37ede27e9d6eadfdeb8f8b2b2dbccbf96fa6dbaf7321fb0e701f4d429c2f4dcd153a2742574126e5eaccc77686acf6e3ee48f423766e0fc466810a905ff5453ec99897b56bc55dd49b991142f65043f2d744eeb935ba7f4ef23cf80cc5a8a335d3619d781e7454826df720eec82e06034c44699b5f0c44a8787752e057fa3419b5bb0e25d30981e41cb1361322dba8f69931cf42fad3f3bce6ded5b8bfc3d20a2148861b2afc14562ddd27f12897abf0685288dcc5c4982f826026846a24bf77e383c7aacab1ab692b29ed8c018a65f3dc2b87ff619a633c41b4fadb1c78725c1f8f922f6009787b1964247df0136b1bc614ab575c59a16d089917bd4a8b6f04d95c581279a139be09fcf6e98a470a0bceca191fce476f9370021cbc05518a7efd35d89d8577c990a5e19961ba16203c959c91829ba7497cffcbb4b294546454fa5388a23a22e805a5ca35f956598848bda678615fec28afd5da61a00000006b326493313053ced3876db9d237148181b7173bc7d042cefb4dbe94d2e58cd21a769db4657a103279ba8ef3a629ca84ee836172a9c50e51f45581741cf8083150b491cb4ecbbabec128e7c81a46e62a67b57640a0a78be1cbf7dd9d419a10cd8686d16621a80816bfdb5bdc56211d72ca70b81f1117d129529a7570cf79cf52a7028a48538ecdd3b38d3d5d62d26246595c4fb73a525a5ed2c30524ebb1d8cc82e0c19bc4977c6898ff95fd3d310b0bae71696cef93c6a552456bf96e9d075e383bb7543c675842bafbfc7cdb88483b3276c29d4f0a341c2d406e40d4653b7e4d045851acf6a0a0ea9c710b805cced4635ee8c107362f0fc8d80c14d0ac49c516703d26d14752f34c1c0d2c4247581c18c2cf4de48e9ce949be7c888e9caebe4a415e291fd107d21dc1f084b1158208249f28f4f7c7e931ba7b3bd0d824a45700000000500000004215f83b7ccb9acbcd08db97b0d04dc2ba1cd035833e0e90059603f26e07ad2aad152338e7a5e5984bcd5f7bb4eba40b700000004000000040eb1ed54a2460d512388cad533138d240534e97b1e82d33bd927d201dfc24ebb11b3649023696f85150b189e50c00e98850ac343a77b3638319c347d7310269d3b7714fa406b8c35b021d54d4fdada7b9ce5d4ba5b06719e72aaf58c5aae7aca057aa0e2e74e7dcfd17a0823429db62965b7d563c57b4cec942cc865e29c1dad83cac8b4d61aacc457f336e6a10b66323f5887bf3523dfcadee158503bfaa89dc6bf59daa82afd2b5ebb2a9ca6572a6067cee7c327e9039b3b6ea6a1edc7fdc3df927aade10c1c9f2d5ff446450d2a3998d0f9f6202b5e07c3f97d2458c69d3c8190643978d7a7f4d64e97e3f1c4a08a7c5bc03fd55682c017e2907eab07e5bb2f190143475a6043d5e6d5263471f4eecf6e2575fbc6ff37edfa249d6cda1a09f797fd5a3cd53a066700f45863f04b6c8a58cfd341241e002d0d2c0217472bf18b636ae547c1771368d9f317835c9b0ef430b3df4034f6af00d0da44f4af7800bc7a5cf8a5abdb12dc718b559b74cab9090e33cc58a955300981c420c4da8ffd67df540890a062fe40dba8b2c1c548ced22473219c534911d48ccaabfb71bc71862f4a24ebd376d288fd4e6fb06ed8705787c5fedc813cd2697e5b1aac1ced45767b14ce88409eaebb601a93559aae893e143d1c395bc326da821d79a9ed41dcfbe549147f71c092f4f3ac522b5cc57290706650487bae9bb5671ecc9ccc2ce51ead87ac01985268521222fb9057df7ed41810b5ef0d4f7cc67368c90f573b1ac2ce956c365ed38e893ce7b2fae15d3685a3df2fa3d4cc098fa57dd60d2c9754a8ade980ad0f93f6787075c3f680a2ba1936a8c61d1af52ab7e21f416be09d2a8d64c3d3d8582968c2839902229f85aee297e717c094c8df4a23bb5db658dd377bf0f4ff3ffd8fba5e383a48574802ed545bbe7a6b4753533353d73706067640135a7ce517279cd683039747d218647c86e097b0daa2872d54b8f3e5085987629547b830d8118161b65079fe7bc59a99e9c3c7380e3e70b7138fe5d9be2551502b698d09ae193972f27d40f38dea264a0126e637d74ae4c92a6249fa103436d3eb0d4029ac712bfc7a5eacbdd7518d6d4fe903a5ae65527cd65bb0d4e9925ca24fd7214dc617c150544e423f450c99ce51ac8005d33acd74f1bed3b17b7266a4a3bb86da7eba80b101e15cb79de9a207852cf91249ef480619ff2af8cabca83125d1faa94cbb0a03a906f683b3f47a97c871fd513e510a7a25f283b196075778496152a91c2bf9da76ebe089f4654877f2d586ae7149c406e663eadeb2b5c7e82429b9e8cb4834c83464f079995332e4b3c8f5a72bb4b8c6f74b0d45dc6c1f79952c0b7420df525e37c15377b5f0984319c3993921e5ccd97e097592064530d33de3afad5733cbe7703c5296263f77342efbf5a04755b0b3c997c4328463e84caa2de3ffdcd297baaaacd7ae646e44b5c0f16044df38fabd296a47b3a838a913982fb2e370c078edb042c84db34ce36b46ccb76460a690cc86c302457dd1cde197ec8075e82b393d542075134e2a17ee70a5e187075d03ae3c853cff60729ba4000000054de1f6965bdabc676c5a4dc7c35f97f82cb0e31c68d04f1dad96314ff09e6b3de96aeee300d1f68bf1bca9fc58e4032336cd819aaf578744e50d1357a0e4286704d341aa0a337b19fe4bc43c2e79964d4f351089f2e0e41c7c43ae0d49e7f404b0f75be80ea3af098c9752420a8ac0ea2bbb1f4eeba05238aef0d8ce63f0c6e5e4041d95398a6f7f3e0ee97cc1591849d4ed236338b147abde9f51ef9fd4e1c1 diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp index 500754baef..912d84328d 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H10_W8.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H10_W8 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm = 000000000000000000000004e8005f5e66764d13c1a66c4b0919b51b818e23767f813cd64ce8f961e189ad2287a30c45cb69478d54db906e55516483dc65862e24ef059bafa11845aba072ee4302a1e4c22243cd893f12b053529942bf1d3c97de2c317a317c9d2fe5dd7e3cdab428bcb8935db5f3efbd2757261b50431c9ef1cf49256a37355bbc2931ff7478acce22a47dcf7c0662d7b21a8727b0d1ae54473d2c761cdfddefcf10f050821345b78d6a1fb6399a0233d8cb0062792bd3e944951a9d1bc85922fd5bad206242800aa6070d1968d1738f2837039f1d8023543302c075ae3b7e490b4e49b1c2f52f7604f94d455d49c08695f4536d027374838fb11e1c32de758434c1b95aff54b3a949c2249eade7486bbd5a600060d1d925da6cf66ec882558813bc3c35c7b461b013f847c3fcde510affdbb548f0cb16d4151341ecbf521090d6d94062d4c06316a0c932a260cc3a93fe75a6e56e642238902fe1d064b43390e71c95ab901dffaa506aa89fb5e4620fd9b71718a8e4516b791c0ca899addd197172f26fecfb6905ef031679b85fc32b98bebf54c172d294d749e041d4b8e11dcca56c70a181c55d1fac4acc936efa857eca994ef6b4bdbea24881ca38607babb2bfa9635d824119d87c78aa919b9ed71d4708f044222f5c80590638981ed8b46a099c5162982665ed2c1bbe1a6f1a91ebb2c07dd5d577713bac16964eb5bbc763b7600c08a13e02bfa253caac622d038961fac0d45f3e3ffa998d13f80f78f454ec7593bcf47214584f4f32dd02350a0175f646c7a80685f2d5d2bfa3ec8f09bf45869d077a6fd43b777c95bf8f848445709acaac75e82fb479a578a16ae5724084b3bab6d8bb5006d246545dabe8a27bc7419f2cbb71beaf7d30d2213d053e3d75d3e785d7d76347b45f0ae31e1d4138da2836b401424213e08863e87760d3cee7caee7e5c9d576ddd3cd0a827960c2697751b855fdfbb1ae63a87317fcabcbe251a305340172bbf0d907ca57d4d01fc10abdd4d7191fcd9400cac13ab3c949f2ff0b1559cf6336f2cac59b97c45faa702b1212b341490bb0905b0598b8d76d95cec3ee6fc37d4096b625c84c2ce3a4bfd1e541661eb57bd4ca0a5d1a55578d0018bf0183cc2684fe61d8376ed35fc6c9715e03d20c3c103f29f8eb4d19bfbfe71a81cd587ec0a2302789bdc9b6741fa811e0b7dd4e66abf7287fa282d039f9c98cba1e46594ba3d2fd2b994794c7afc627f3dbb29900f42aeb0d7aad125634fc281e9c37047a1c7aa7cf9d78c3100e3d1395df86e785970f3e107bf12ffcf7ee3fa8c1169192c61dd9f3bebdc08d4290e36e8b135d6596b70c91c281b766b0ff8ecc82d2355f33d1077d7f0a5bfd05e19210b78408175b1e7c9330a8f4ab4ceeee202b3667694277169bd0403db497b57d9974a3c1ee438a0339908736e1f97ccb1ea3f324682f0786e218c59751f8231ab20d9bf2648e06e32018f3822d66a2d180fe5203484401e5471b925cf05aa64f287571b0645d05c438f61c14660c316dce2d8aaf22a64430f69d7c3bb14721ce16569863b7e65dbb6192b581751a903fa2de500000006979941fe2a0034185d9aeb8f6eb51ef6767f2e0218f9f1a20c604fb41592503e1efd6c941c7e3056ad0b47b3afc6954a6354791967c9274a43f835fc370099fe0d26a4850bd75228166c06d23d16cb07326be16f454269d1648fa58b6ce4738a8fb926d2a61b5aa66c4a3d4417b0ab7ba7fec2f7bcc1d1d179b7d7a90bc316975c81d903b29345a3ccb9309534aeeb6647dc5662a5a64e9b2c622bd394339b9963ac9e6c3479a5d6180400620115b6b09af77ad82c7a39e278ced784702d1ca621705827bce972d17fe501ad892d4de6f94e748cc7ebaf600ef73037d41a4719cb7a96ef86d89b0eb0e7da8668c85e52407b2b14c232ae6df56bed6d1ab6d7e5bd2448f15e0acdb7792f62cdc3e7ff1db99db034524e0e2b77749ef0b624dc6e2937e289954069c33fe4d0328672caceb377112bbdaa844bdef5bfdedc1950aa diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp index 138da7ff33..3d78978c41 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W1.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H15_W1 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm =  diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp index e478aa9d33..5ec6a5b991 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W2.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H15_W2 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm =  diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp index b63cadafb9..a3ba862944 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W4.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H15_W4 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm = 000000000000000000000003b15d44eb5dec79430945738b499d2beebb5302eafc1318028103aab6469c2cc9f7701919bad01498c915de8d56a9e221413bc8191bbb0a6e538298c49f46213ec9b6f27b26d85c13541b2dca4fde3fcb5c6cd830ba044c8e6478011c13a10e79d5ab11157d952166ca5e5cf7f36c675af016a4476d97b79bed46cc06d261e82ee8eceae9031cdf85e0afabb71aee45054e90534ea22e32987f6bdad1d82e5753c3d49b70a2da50e715598dc45e37ce67404f50d6f068ea9f053f89a25f3167b778f670834a4247dbf2f3463772f1af1fe98def960bad75531503874a8ba1679b0eaacfa0532017d7f12587180a0cadd20abd54e206f9482ff3d24be9efb41e6fe749facd7312927a81857f0810d14610528c4ea6b3fe3e8efb75f3c100ace31d91b273790534851f0ba37977178b38df4319405c8ad6c9a657c536836c6362f41fe67884198d8ec5366bc788c43b8f7c1689c47d4f3d1c33727937fcab453fccb7dfd4f1932caad1ad5ac45d51e4c4fec014ea796b3b9e70781a541e9bebdb309ebde3a30918b63d6d076c4ca22387e0b7a17a42e300ec1f9b750511d989c443edf89d9f24bcfe96767aca712ee08583a70fc80b6d7b7f3d7883c02491bcc02e37e267d9f14ac003fe002a669a8ff5ffb37e55a8c002bc1ed3743745119eb0ec227ff38eec5956f1a36390fa086f98ab4d9200e7c17a48ecd8f8b5bf38341ecbf8a5a0f5f3fe4b2a0f813df19df6277b014126d1c0d42e093d1bbc4e2cbae00422a78c1e70b2203ea18591b22d2015f8d4d000fa484e879d44ceb86e7ef89e11f3ea786f3b6d204e4ba13466bad37b1cfb4cdbe0f7bf26623d787681441e6a64d3d783bdeae7fceb6fad18c8b011c2f14b3660951a8cf87b75d292489dc87cfdfed0610cbc7b727b780400b8ddf7a1c5d5fc265a7f0d2356a7e39862dca4ceb0b07efbea59bfa5c8d27ca1c04857b5c033322dfa8bb5f0aad504c246f17d97e306c55cf17f0724d5201ef283f8e0191ddb9b5ffb5f2e86586a1ec2243dfe17b61e6c5b48204717a3de944a26082b396d016a3f689fec52354321d08722f2141e53063305f988a720a91cd326bd7ec72071ea45e314ad505c66a85ac4478fa2fbb7abfe83e890779f607de7bef9b852e1b72ca511cb49b5495884f04a6c6252dae87ad6154f0934c44ffd9f9b7e78ff32163f414fb1ae01d703b53afd5400178ebdfefaaff149de556b474d507cc4f83a2b6bc8d8aba86d55f32dd6c59f90376480d195ccb157201150438b93432b26cb6a437be4bc84b5239b89bc477ce4ad981c7c6ff38cee53091aa3489a095e72b582ccfcfe783554b3dedb32af18f136cbe0c83ace70cc09164debd2b67fc5aa9a9320024dec45a74be1793e3850062849860596cdc36b9ea154cada6ea752049b391082ba0107e4658e6efd741fc5899fb5ddb7549cae174fb9e08d0b42d75f15b1743d06f107045ec931f8ffcc67fe70779cfb6c3e3f58fa230c951cc6278571796cd0f83249ec93f7ba62868782e431c177a691fdf617e9af2221feab9ee09684365d0a8a5e1948de7a01b6e390d18651f26655d994c1363efb93e6dc196b64e65b8ce1150b7d020b280760e0354d561d08228611e2fe9f483ab574f93cbd709fb3b4b07af72d27f3960f6c6579ecc02ceaae745a3939112e883e9dca7856d5803dd5b21f889c145d3c54b2a5fc117c341e2109b935cde6c7959ef33e3c2a9aaf32cbe003c14aff7f36cabdf25f37467e7fcc58155eb0a354313057f30898370ecdc5b75eb2a74388197adfb36439ecf97a7f9302a2f4d7be079abb824db22f7e962136df36dad41cd5816f4e8deb434b59b4f308818a12963dcc0168f20a15017f941f129dbced6e41fadd87f91655655b7001170188fe9545fa93424f939464c7af32a5f282d999e5f93523ac2090041cb087f6be7e8cf2aeb95e05afba361e973c4a69eca8bf7c1f22bd98e94dd71e604561ccd316f6579a82c75b58f731282f658ed2de278ec4c627bd7e89b4f7c4a8ea68a48cf8744be232981218ca4ed83db5dce7719b3237236632e9679516271015ec8db512d517f03e038910cdac47ab895d8a8a17dc43fdb7c27273cb830372edc94e9188fc8eb0b95bbd6f10ea1d593a7aaccf302b6ceea1f6f3b71d7d4bff16abefdc5c065922e1eb3527af393186b963b15b3a5c0c7626e68b69de1df88dd9d5430d8919548b1dd21fc65f4e602b6a0e1fed96e931ad8953b30f84eaf86b630a104d5f296afd9196c865134e9f93ccafd17abcb2b2fad3d7c379cd4b7f2382b30af940474665eef0e0817e322cbaed4ff5607e7970a8b5292313a9594e5ad6878cfb8cd74e9c498dcc63510e7c28d931ff70253c602ab5cd2d600580ff642f68aabf7a3643f1c7af8a41e65310311ea43c75e95f8370ba5a6ac3cb0065d599d79e4d44f0591135a87245eaa7866f49046e764facfaddff76c5759fb7e58c215dd446f8a81ff4b8e48154e6840c38cd961b9b9dfcd55fd605880bdb8816d877fe1a53237b7a3e056f60476ef3ae607725eab95cf03290fda825d9db7ae0262ecfda3370e5799ea77dce227ed43316cbaca2bf61217151d703ad6801add7891d374353de6bedbf63c69bf33eff12c937df5300f52bfe07f7dc12f197e7aa071a76e0d2e3eba64f99737a8fc0f413b143c8a068e64fd7c0767094b46945ccb76ca3591c0f7cf02caf00254eec04585a8b9e38d3125283c3932fa6ea02999cde821a534272b267df5be0aa822a18edbd174bba9262d0f43a6870b2a5e95e8e673a00b7de8a0acaa0f38d78523564b7dd045c151e5c072f6e8d4b179eb36d7775d3f55523331527c1af2b623b4c894da1847a3bf9ace1eff733eb1dd0a04c09d8b378e9abbd00ffdb9d9bc8d73fd4977b8271240d1ddcda20bf41e2402e2f3085dd9ccd4ac881455a22d46cf9637ab93fcb3e4bdea1facb4f10fcbcd96fa21ec295837c56148dcad04c34a15db5aa2a9b0b4098493682e9d536acce9150cdbcfa62015c43473d58e5fb1f30adb8905b90a4426c81abdb345696f21da4bd210000000775500fe3a11d75bbd8a575414493dd05e9089d78918012e60f09610f1d957fc6724bc66eb0f0ecaaf9d040e31cd61531b5b950991637d97ec4aebbdd68efef4fa42b984809bf91e21b1b767d8550f0ed2d957fc61db16b5bcb2965436e5e15b76bc299f66f30d459eca6642eba5b5068cbdb38aa87def567852f1adce0d08175390ad6b1e9db4eaf8a07c11fdc7e68bbeb66afa3916aca2b7e9366cea55c60d643ddae869ef53e95a5e24866168c106f6ed019c0b120417c64b479bd973077c1543ca6242a05abc1d48e778eaaa3b3bd5e45bc9d569f372189309aa91a927ab31f67daf8b45a5947db1149a9ff29a4972ea03b0b238bde23599b4068f4075f02bce308631ad3b4a00babb5fef7a03a6a335a543e10e360824272d7d17b9f169f1a9d39e941c61da753842870f3d058192ba9b808376e08a5879c077ee8fca7228f96cbb6d694d6bc10be0cf5b718389378115e38943a57716e5d98041c4a6b93f40e2a781728d98d9965784f7404dc2fc7b63e3c8af12992afe5322284fed577a9e9c866a590332436b08fb783891cf1cc7c7b4753d24e23feb7046f90aa3bb9ec1e30ed1dfcc1f22e78ee63e648ed3bf949bc04e47f410a3441d614b912a8e7aa21ffbb15fa2f3261cddac3758c6f5a54fecf3153d7e168c0aeed75c91cbef8 diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp index cc7ddaa6d2..06c629fe73 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H15_W8.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H15_W8 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm = 0000000000000000000000047af430445b89d9b8c82509c6d6e14559a7e26488764d076cb6428ec25a95afb01d0fa6b245bcd544909ca29bf1787ea02eb45ad125a5aff76f43fcf8d58c8c92559e4a1f99339a26f66a75296eaef6d9c087606dd3df5987808521b95905e0a6c7119faa2e57df8e1ec02be9d1ce346f32d465eb404e928080dbbbc6f9994bdf9ef72a44948a0f69794401fedab887ba9a8dcf117650c5cb45b239d08b9247dcde09b238a5cfa5fc26aa00f2060e7eda5bd7d5ce5b6037475185b0b2561d8851626b2beebe8f12b1efb24bdb9a86b657893ccbadbee0d04efb421fa494aa1dc926a3666a959313d08358dce4d7ce16b23e36cad0c26e56e2d5b32afa744ed53310fceea855092a45fcd7058568cbe4508d511b8bab52cd30a75d3c97cd1a42e7cc2f16a6242e8e10fb498606556d6e65e2f7d55294560856f706cddaaea7f3d495d4d0c6b655cba91b211b7d79dd9e4cb4e8c44f187ee7de6312c39a99c34590a8f50141c31be1efd6083a8aaf36f5da7eca4f66fdff1d984e764b720bdc830ee4f6c7406c2b0cf0889a00ed51d435f0b31c7b9a10eb8484c64d3d24cac953d38b11c02047d919da39782db070571a9a10658eac751c19eca9df0b0a0f68916ae4830f56d28eec5f18341542bbf2c8652b44ac354326a9b2a854f6326ae920f4f201f5f71a1c698ce69e9964fe7aca73f9080c420fffc8fa3838194ce479c87e6ed5619eab0bd317b84485755a2390ab4b8220d74b73d14087ea334c14f61bb06da084eaa77aa99f13b62758e6a83f9665999b0f86f92c854a1e44b45e5cb5209193025d78bc7e5fd8300c91740b444ae3cd3880bf22927f777d2833eae0d4792b917fae8dda163cf4be2928e8c881d0fbab323a4925657335a5964f2cf295de1d4c1817be9a78e89712accb11e4b02bb02ef55e42832f94b293c732e1164e1254c6597053620fd88b78d884106d98c88f87756656ab1fab40175542c4f716340d485441e9af121860e971eb8c2b26d8f5d262d09376e04c8cbfd79f5c45261cfb6c290563b4ea0b62c6464d40d1ef036a2cbc3e8e9e227c91798fc2018c393ad54a6709a8b13caa03e2c0c8cace8253baef126a4e2900ec69bd79e2a99faf088795b894b09f002e8c33ac189346003372543b186e145f322630883a283b9c31d8f0679b9fddf0b3a551c451bce5f9d6e47cd113894d723accf6ff6a28e37452884244456f55cc89514dc24585b458725595890c809a6e034e69135ce605bba18d813a3f68f0a91595b3c301e955a283620e88425d3ce747e68d081dcaca159d269adfdd8901920916ac8dc652fd2b019d86342d1b92e3e8dacae938fc14bc775021a8faac81f5722446c8e9715e23ce5c68a114ad1611a6e146dc80488d4f359537de3b44bd3f1b7ea74d045f6846931bfcf1747e089c75a5ffd2b7cc7adf693a282966d414ce7715fae6064938f7db7006bbd98c70b661f2b82bfe5dc4d30a9d7763e4be9bfefbc63bb7c5d4c8da6c9adf6a9e1f20025bef2564fa87886feed6789d555ebee11bc812660b5e5b4b54c196eea96f693324ff20646e1e4dba9400000007f656672dea662ec5bcc26a23487368222eade00324f8f5f72c9111c474af6995e54f45a1ea3ede6d95a73d863b1491982f23f2ecada075a63512600c7661590ea4097241a052c5bcad87ba7858e9d5458a9a7627c06ffb3a7351aa34e7654ea893deced8e5736374ad7a3efae2331d3f4ccfa90ba46871258a920ad200f575b755e977555f8480b3b59e1e5aca7300654b78a56befe6cbc8f7194ef7b451e09644d4220ddb8c52ddb9029d220bc3794a26581e2e1dab769184b502f32141242b0f73f608ecea7f3915e7e4730a99dca80a672cd4ee902b64e15ab4292e265431012040373192b3579d916b8cb20f746c512c065eed493dc15d7af1a7836caa481a3a0369373debf8061bc276f8fe6cdf6062c607457bb08653baad184ce8dc6262114e566eb3e6917a12977028a252d27b4d20f88a0157dd5bcda24fb14d9b55a4663782d6ba567f424acfcdaa1ef74e3b4467f42f78cb1a75e5df72d2f3f1f8b027252d2598fa3cfe6cb30db132eee876479f7de10a3988bf5f9f828bb34cd497307f92d16d14ea5041dcb7223099850a79f6411dd01eae4d04a5a029c6c32f728f778728492ff47cd2867a830a0c68db065021b163470ec315ac84d0f1086b841651ed5101170aa822dc63cd76d198a44d50ca755cc39d0cc421b9923ff4e2 diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp index b9d272dd0d..94f25d3247 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W1.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H20_W1 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm =  diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp index 46b9405c33..1ddbe2f50d 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W2.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H20_W2 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm =  diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp index 0d461a43e6..50424b9e17 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W4.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H20_W4 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm = 0000000000000000000000037c43ee18a5df8fbfd9e917f1c48edfdf3bba8def38735c8467489c1392881b827fa292e35aa39f67ca2a2ceb9301d7a592458d8bb115f78241ae487783e50926c43c04ae72ef85993a9a2d8db2139ae7cc95eb1d1cc04840713e0e867f0aa3644179e4411498d0f50c3e149c8849e03979ab92e726ffc2e3be442cbd4d1c9eb8605678e51e613417f33479ea18e3ac3e864c8219554629568da7f5b8ba9d4f3dfdd7f63b4fcaf606467d1f5b326e20c36e45c9f251c08b0116bcb01e3e5cbaa1d5e154ac2ce0e11ec42e81e105244a020773ed094262ee3d609d668b2948a0682e96ec77532d85e899d5f7e07e48b99b7416f27f05408e8704d36251bb5df5568c53df8c3aa7a0b14a7e311f0cb63752610127d73ac0b80733144c93d6de013fdfda6ff4693fbd19e6c7ecead046f1e2c937875f74f1428e3f1f54996b3b47fde49a07b34298b678d0753b9e363ac9e8a777148cf816ecffb458d829a440d983ab9b0d435bf8d98ae71a81a37b7d10f5e001fd0c6a3ff033530f0eb1f155fe96e21637dfc82c9e802070b1c4e008998206e9c04cf3a38f89108b275b5afed4d58b9c34cf4b7d94df20ae5a516e7da4557d53750ead4f760ba82a8e7e217c048acd6ba2ba877825522cdb72e152b31993cfc0fc1df21934cdb80fa088011c62e127b3799a498860108e5f4f8cd6e9fbaeab60b7ea46e84942e354e4065391a6c7039125eaab29dc08cc5bb695ee950bf37cd1d3d83030ba994f280b00d22d48269f05c56ffc54e43c45311bc6dbfb4b53a1df6ee4920a370c894c17fe90e521175bb5ed8bf39987d343e59fafe785e9389daef38de6e863035a3fb630cc2755b58f0d4952cdaa83040c84775faf0314a7d84008ff79239b7f77e3627afd2e868aaf5a73cb3d92f697eb4b880557cfa589fdde3feac0336c7814cd0bb962d96ab5a9a3737cc465e605ccdaf5162c21de0feebd23b6cf9cb0fccce7a1645a66341b7314df7cbf24ac1256ae53d5ac9952de184c1b026b9b2f227591694939f95d1480243488e5a26ed84a628dce33aa884460c0cc3535b73be0dbf4b01608866ac032c19fc1ddf288ee7e2b955c1fc80c1761cd6ce0ed9d6fa3a66723c1f4bfc67b5c2b36269035661a8f10d20dbee8712322d93f6d70c329b5ca914ccc91373f2b809686a5a68ed5bce241112ff1274350219cd10208c51f1b1ba415b61a1bab437e6a75d422f635584a83633ccac0040215df734c6d5e654874f8059a26893183a3d1357e01f2f5522351f945957a0d14c263d5da7602b2168c786c66bc419eb941c1b029ac4ae53b89fecfadfb58ee1aaea9e71287152c180952de7f553599aed4adaf6a6741fd358f2ae0968c027a1f5f175acd951303059cea84a98b70b7ca986709bc2ea405159ac9d50665f25eaba56e0ce2fbc5439df6e5cd08d10d4167030fdbade6eafac433d37eebffc185c9333411d3abe34f5254f1451191c7541352f7daafca626b26716663fb25726e77aee9c1c6ea2de33c1f28c2b6d15cb7addca5bc422d6b06c0e4db832b9ab0f08da4530218d082116a1a0ff9f4563992302b2ba889d04c1375bc15fda2510aa034963121af0cb9be12a68c99d76390c126f6fd7df89f8a38982e7edff991e8d9318a9429dfdab46a54aa9a04018b634079d23a511350e4b0162e628605ad852f0e589730d0f8e09222716bdae6151aed4a62dc3d50e417e9a8817fac017ddb0da99ce08723bf420b6a70d25abcb2914c3997361b5be31e485b4c621ae493729c7f9efb00e5e445f4828629d61d532459f08654531b4bd5da5867745b58a9e608a753e568c931afa3909da2a5dbede3ac7cd52cbf954e9fa26f510476cdaca57fb014b4d9f46cbf4d2450e2c5ad020d189e5d32eb49aec0782de2556403f51ed8ce5f519c2cbd451233f1adb9702918dfad4031ff5604376384a200fd64bc0bd80371cfb896dc56f379b8f3c964d2e57998bf67fc2fe12c88d23ed3bbb267e0b54d1603f833a5588a0458a04521b86d90a56c7e9ed3a8beff5f13a49517a79f270d245fb24fc3dafb1ce0f01f6f15b8e230291d5f6d6f394572a49f9f85d1847b990cb2060b09dcdbff555eaf9961fd5acfbacc64556b77139c177438b8e7a86112c60293eb1c583afbc17de5261eca46b76de8160d5068764c194fcb6a9243396ac5a7a6db9602b3421f8f4f425495d91d5da88eb9aa3036b5749a670d0fc8b40af82515f296057210751d49269d6e86e7cede47534b7b307b39c6ab21fecc37048f4c911112f38ae2cb01a5fe9a2379d37bdb4986a0e40c2db67f529cd3903d41a9157224224661414a9092f906e6fc7b6d60a68d311159107d22d2a15d757f0b4aee8d1a453676f26ba90ba8862b9ae5ea403e6ebee935407d468bd84107c8913592539adc3c65609f859f57770f72d202a903a63ee0778a321e402e036fdcfe4b62d78a67e3330b71efadf9bf2678fb024c75d9ec9591f2c58c08e6543b5fb5427177cda74ac3c0c641308c0562938e30455799bc555f9c0cbbbf12b9b1b7ad907ddf838c86634d3ae4f3b9f9d5d4dea929c75c5af465d17fa96fe88233fa8996cdff1e1cbe21cd5ee75fb3ffbee0f0f15817923588737a6b1647324b9cad29c33414b5f87c7db0b0280bc27dab78b4c8cf137752169d65fa5b9d374fceece83acbfca612847a147a66642d2b25bc19c4e7e86118efef57ef08eba9fd9bd36854f96ae47ec1b7ba8d4e53f97553386d1a117fd6d11eead3d10e58cda7258ab8d530c47d33321247690dddaa770c9dd6b5295e164e2a0b9b815dedbb9654517be6691b3dfc739c9d470cfee8ea2117ab7a2c2876a21e3513911486e00649f98aaf9ef1a32b63000dea1ecfecb9d433b51333781262053f1096c884fbcbb3187b09489fe1da7ef9d3eb14ec1cd91fa1e09bdc2a6f05ba95bbcc583a86fc73daeb18ffaa7802e671e0641331813bded68bfc6f284cf44ed3cf810caa5e6103208bd4c56ea670269e04f96a5627ce77b364b50b21b38eeebbaabed9b311bdf49f46310be5d19aba8b76b5ff276f90a784850000000863db9401ef22c5a1bc3ef9a0894c875e66109f097575f50f8feb4e2c18ef1b3804d41ae1c38fb1dc4d3306ab4cdc3a0912ea0d70983212a10c7fd15f9eabe503251cd8e12103dbb3d5520a22bb4f758ace010741d5eca7d2fb972e70abc782243b7639d486656e9c0bef7a89c6e64ecc0bdfee8af27e24349e9cbf37ea13c9533fac0b57d5ad9ed89b7af20991dd140b9c23a01f53eb3f1e649d8b2d6d941948ae30c64cdec7cf05e17ef2b74d24445ff0c108a240168aa5694336f1ebc3f9577ecf4aba3fe7494eed663a8fc01b85498206a6e87a435e30a3bfa64558126e79e440369683bba29269d86d8c08150286a1ff69fc0a4eec0067e88542a2dc03fbef3d11681fa55c18d9ce1ed722755012df301ad7082256925a5fd0b50d675913a929f7cb289ef8abfc5514815a88397a1be657ac0f5a3a343e18d56a8264d0d52596c561a22a72d18a7d6551b001af0ffc60576f54829d36515e4b9a5c4069306d2c3511f176d2d74c092c7e261d9fe4b8ef9b1d2f1dea9663795afbc7058c147f1fcb977f80f98fda75a7c8821fa226af50fe8d02b9f8b9a9ab58d6f498544e4c8414938f106891bbf87d215e42a3b3dd82462c9ee5007edbe45379f89bde29d86b485af81942fc8a71123b51971ecbb49ebce70a85298ef1eef2226ded1b68a16f525be1f074364084b9aa50a2f215e9824727ecdfb536c3e2f8254b2e37aa81bdd106ed7669e5085774e49ebeb7683554c867c6aa891d6f02ba298fb5bd75e2af2163e211cf09873ce061f20badfd14743a9088c2fcf756c37ebb41d3a437857a85abafd33d57765e8619429abeef65b6a532f5b2a8ed9892316f3ed951eb32a10f51edd95d7a5a0e5eda591a481d081e124831d297cbc44c233522ea9f26 diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp index dae33fafca..de889b92b8 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H20_W8.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H20_W8 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm = 000000000000000000000004c77901fbdf3723a0e739e33dad60d6438b3a33adfc72c33f3e1a3e13791a362aa3a1cf96aefb864bcab9cf5714de25794d8d59428eb4585ba22ccb719b12dd7301bb456156130d9c8d34e1624025b402dca6c4d2d5462ef59c5842a9aa242c72cdf29daa26527f5f529c01af89066ed129477f2796f7a2bbf91233f4bd3a9f658e995fcf6221a40547c442f3f5dad46aecff3a4b061bd72c2bd725af87940805954d9b9cef4395fe8e914c736cff67cb8f481c5e9842ddfb95a4c7f9f1310c3bdf951acc06337ca482b677992f207e11fc3520c923d69fcf8b863bf113531e0266246adbd818300bce8ab72b081d453f109bb298e72bd499614f9e609a12bd1e7171187b65e70e9f175b7f03eec038f2faeea0a6c13058264f3b21ef4cfd27c3502eccaf94c68060a468353f1e3c111226bf3baae1af78d783c91c32a344ea5b1e3875f1571cf381e4a142f154c749a572ee587395b1bc49df8c979623dd8b4b09bf1622d7bd1846bf5f65d7be5f28f69a40eb9cb0f25cb30b1090205f85b067870d2abebc20f7bb67a35afe9eb9e1c8f9d90d32b18728b313e055c22671682ae85de2277aebfa94380bbc7ca11c090430cc519695f3af0c5667a3595bf565e7b1114e069d9343132d36adc42043cf0ff1d075f82147d4f8baa9e38e68ba8aa9170c855f3c6e3be4840dc92f65cb5f2e1e24730bbf6d4f73349c3d85e4507b8c4f39bc8b07eeee8f2fff240b07858d391a9e24d34d7f219bad1688546106ecdc177589ea3cda62c02b3c862d7ec1e995e6555beb0d2fecb6d6d86c232dc76f063fb90b1bb4f20116bafdd7436825a53fcd26d1544e71a1feeb0b154ea298948c3ba9ba0adeacdd46860c6d28da3630b36acc8913ecfbc1288417513b8988d977613b93fe7c5c883a4df6096ca35875f24b4e2f7c6c5cf715aa9428069b365e1a121323556113a0ed9a2b8c1cbb944eba56e4917ae1dd6dca34dbb4098a52651af8a8b32a0416b85a9ec8c3e305268c518f713edb977fd6b17cac7fe85d574003bc5133b590d117e5b471a0abe73f96a069b0162bafd492a01900cb3c9bf6ffa6c30f11e9d1ce0eb5385187990f54387a1f66be91b8e9cc09acc5cf0545da67470ffbe95b856f90335573b14cb487787a1440166a4b5249c8108b7d7e07f340f2a30f986cbc2b1e3055cf425dde138deb3fb12a9bb2cfae7020b2503ff50840ad2f026282bb9725e82e310cb2c32a1fc1e7291817f7539055d8b61335643d2a6754033df4326da389ed5f83a6a1c88125975548fb213a2fd7287d98e8d815f42524e10ad9117cdbf88464a8354a96e6c1127167f7cf00088440501d660e670bf98e174cbb5bef986899bd2ed23f0051d1d776e6f4eaf6a8b4c973f12fc85b218c17d346dc8e8f820f71716219165fecc90ac1101a58d0325a586e9a2fed1a2ca2a96b86c94892551712aa032e2a474315ef6e0aeabb2d92356a65e55ccdd371f79a5e6f59e902667731512f1faf7bbbc3ed307927323b1a51f52268d696be32066cdb859662fdb69f8e2a718462537a612987377552f3e34919ff9e044ebfef0f000000088688c398c528e063a27c2654d8ef6fcf86cccf6111384367569f78e0c5544ac0c32f502398b9fb43c94ce6b0c2fdff387ca058d8b3d70edf444567347c32180e5f579935bee605d8d59580c7092b374ce27758f3fabbdc1210c52e7cdea694281ba308427afff30f71588a9280f7ebc56fe9b80c84ea65867cbe443ce760d0dfa3c7889846873ca76dcf464c7ac41ce082605d115f02ac350289557bf7afa58157cbed69a0dee6991af022ce6cd54867c1a05e71949fef85c941fca240e0cb67ea053725b7fa8de0ef248b9203f3de202fad5415112aa621ffaa5504fe4d20929b4f761d9b8621a63726e079b36c2e04bff0782374e2cb103c54842768c164ee77668753efebca2f6f075f47002f7dfb3689e27f1096236cd904645108e7ee25a0f6f3a24ca2db67b53a13a5e9c39601d526b5bf1658c9e9ce2b80f0a6eda7ddeb8811c6458dcea902dad8c1e0da485459d01a9349bebc7e03c7da4366fd53ed29b30c7bb9d28d758c5574f7347cc02e1becabc07964ef20bb27950f4352c92382eba52126a33d4fbe947a1a70dcc622115e4a1e61d283cb7e21a26d43f5ef2317acba85a2aafd6fcdc6fd902bf7821de2b21f252d73efb0f632e46097ed8b9d7c859175c8b4c54d7509ed221131702fef73ca28d9f25f7e1e915be840ff3e56b8d09323f93da0a6a041b5fe66a1910707f5a06c805efe8cbbbcef36a20680cfbbc4d793bf7ba9be868e290e4fe99c1f44eff6f1444775ce1f2c2bf2479b38db8029024f7cca496cc0c1d4013f96a1791e73b72d4220d649d7333761aad155a45e23e00b83bf3c80848c4c3bef451b33102338b11e4fa27c0e63800f1fb10c72029c3034e04d606bed563c0a001f5ad8c718d4056acce6076a1a652b28699928 diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp index a3527abf11..340436bf29 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W1.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H5_W1 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm =  diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp index 488997fed8..436baba31e 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W2.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H5_W2 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm =  diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp index 7e4ae977d5..222fdfcdab 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W4.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H5_W4 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm = 000000000000000000000003aeb14a03f55d830d64ab4981809d932f48f8371887e4b52188d67e9e77d296b7699c4267b07320535a32b9fda668fe4d64e126e1190851de8400a1eb29b6251778dbf3fb6e6c2d4ed9cd306501ff53e4b3e2e6338d8107537ba3bfd14ce795cf8f939e9ea6add97df60ae591800014cac041bb38857d29a479ece3289240b926b02e7079af6ce0bd239fd9c9c55880c7c68d527abc9210cba38903c561130e1cf88e75ac230a1ba6591edf39142739e8cd16d5c744d49c6dc9318927b3f6a2f44139131b5a29635a80e5e4ebde27570727e9fcd9aa18c7e45293f67c0a179a7a159574908c1a43de083e69aead0dfe6ae356367da1de7bc4007b45483f3863b045a047ccad8a88c16ebf45aa2e76a40a5806225bfefcfce1687602b204efd87385308a2a4d4e0378714ce5bd12341b1a71e8d155b2cb2e08616d5280c418d355987cffad11b65e2032371a211269943baa66907285e4968fb4bfb271230809365dbcb8fece0e66a6c23ae94a4a91ad6cebea8c2ed848ac76fd43935db8382731ad2188f556519b87efad901b656f8c5b533a772cdb1f59b2afadf46ea3cacb9eff1eff51ef73cb414da18f188880a67d6a2dc70c4aafda7d2d65ccb3e870033c3ccd2e16116b4f685ee45194cb8ff4415768a22ae5189ebd2f5d2a0bb796890b85a01979536d5ca3ea77994cfd530bf95a039a7ce635a6db922baa997a6c26ef45e12018b58cd2cbc7b3b3d0d2938b28ae7d0779369e0f8889c36ad3a20e6cac70268428eb43fc660d6a2a293762aef9df55e5873304141ec87a96ce4d6a7e20fe69d66a70e872c4f037f32b5317f51a602196c8e443ed0cf80bc2b7104b2b5211cffd650cba2de1777268b1e015556e55f3e4400e61abcff383541594947f4ca2394ad26c43d3301264d05cae9a38d4c70b7b6edf50368f2e30842bd619387961c258abf34181b0e662af0db9ddd8e444116e28d1959c4e56f5e32322d51b772f6f994e971c49869ced203936f76731787fa6e8d13dfc533103ca0c3cea5d8c27d8b3b05f9ac81b30b9ec947cf39299972214b6e058f3fcf58ed982efb02bd1cdb6199264183c82853ae04cac67f6d2baa37f725dc77f08534273e8cf070e9383d8f4ebdc44bb2f4a48a8aa9ad9b8c6ccd1a718fd9ad8716aece437630a5294ae83898d44392444bd7d26fa0705fc37f384b9b09b94ef0ffab639b9d01758d286a8ae14c933e746459c64dc31d609716e928469e38b36e563ef68e3644a7200a262b1688fd8e4363b57d42a64d0866e19501ec91d83707067fd37e1a3b42453e75afa9739e73030180ad38b687230b6bc8ba02ec2bc300a87828a1de3a8cab63fb26d30099f960dd82b7cc65923b0dc380d3513cf0c74e671e50ba668b8b0497919e260cd8c2755de8ae3455ab3dc3c378a789b8c84dd6ee8641a4feb06ac3d8dd80093e744ca7f44e1a3bd0e1d05870841e13a6744530cf89b887085cf8031c1c713d9167d9e1ad5d5e7c5d6ecce0830863f846d423dd76a91be60aff65a72f16e71173609a46f3bbd33f46d8d1928fe620a646bba75325dda0e8dbf1f95ca9bc02e891889e6b3009cbc944b9aab65fa30cce224ec1856abf23556ac570f43396c61cab7f458d5ff1fe7f83c0764e78fa0f9f9d75fa9e0c518379a3ca746205fe03751231ba269e19b579b90b1da30d8b6315ed7a4e54ae88fbcdb15a8fbf24fee6d9f7b95dceb99d330b449f05a53974118989ca9ac1bcdddad5a43b882db01cd27d72236c0d060b2b6120ecd7053820a5cfa84dc672fc2c310067cffd3f5a8c3bca13077fc1d44e99c111d4f95cd68d74bf827849277ccd7245166950beb19f33297a00838ca21b896073878f2b509bedc6d6ae8295dbe1a059cf3ebcf40e7790e0530dcb66159a8c0e0fdde36f1b6374e42eb331b92bfa9061c6f480bb64e73c539eda7ef879730904d5843ea1c5616798adbe21d6c5fc4efebb60c45ccb30b7b1fbe673e754717ac71f5ca272dfffd2aca2eb8cb885c8a8395800f70c90271aba676239abb86c0708301bbf643028e55b9dfcbd338f2e22f5cee5c4d0fa163488a06fab8f15337dc219292f53325f98a4ce0f3f931b2961483d165a97e19d9d1408a156c7d35eab47fa5edf71dcf862e68a37787a1203c35383047398b3f305e1d4fe19d8dddbeb07990c507e8d80b6992c5c996c14b7cd31f65006585dd6bdc7fe43a893e96e06daecbcde583759f8138b3461341ec115ff29f1ed2eb72ff45d29e674dbc27165c9c2ba212455264936a9b8615ec5fd6cc26390dc45e1bfdb9815c8026ab9744af6eedfef8d2b2e73adcc50c52593ae3750dbc880c19dd627f215a49b044f87f866098c14e2716a055819ed0314ce687193cddc15773a220c1204b81dbf11087019ef723f0e14131f638cce5224bc1c73626a2811fec0becf91b6e39674c16c31407289222bb02eeca5ccb6a195c8c594d5ec984ac7fa1cc266f40dc4c6ca0724a94da0e1c8ac89ae52ab5c35ab2dfab88d9899336b19b099a71d0564f31ecfce6c582446a37e4acd62c62902afe83d01b977d61b31e4d03efeef17e381891c5e96a1043da0421eafacb98358ec2e98986762add3036aa1a1dd9f3235dd9a6f991e935d44337a265755aec34e819175e140b51079662ab5905073e588c785647444c4a3484c7f5643056b49e4fd0927cbfdab1b4c3101484c20a673b5322fafba8525d8c76f05e2cf522f1bd9955b86ebff690c02bbe96f73247396f50829f12ab26d21f082af26fb68cf7c4edd47602955a72eb29fe18a22131a8ec9b33936e816da6ecbc78b83e7656796dd756eb408a462df7830a67371d088b4e3aa15d4f56412cc1147338ca3fbd759ec61c2069d58ef9e84fd436eadaf2f8a955bf86c1d336830e9e8e8ae5374827cd801f0fd92dfe10043e8e1776c6ecd0cb7b9e0bfb6e326e8eb0224203575ec16007008dd284836dc7b4425fd39048d3cd2df1ef4fe18d6499abcd55d38d44c70852557ce09c3e3f45234cfa94f417600886b9b8a946a24ddeb19726c8b0a0b1a41be57b203c310f558daa000000050233c68da9d372a5a75790fd99589f6cb07f2c9cf97325a28c59bac5ec87e8eac10877a29091357b9b12611d2ad4b6ebb92f2a92cd0efd4a80eba5fec0eb6f95d1d9ddfe0b6e9eadb2420921ab517eba102bb8fa0402cf463d7b7d3122e161a5b18959390a8a38d08706f1ee4c2a7cdbbf95a642133e504791cb5516e1ccf2915cdc752a2a6cc023632112bf44115a1d97fce39359885b203307721151e4574c diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp index 57369ce635..709a37263d 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H5_W8 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e2e0a0a sm = 000000000000000000000004c15445cdb0955e650d038fe369128bb41dec49c85cd58208337d27a63c4c4c613fa669e360606b31f1bcbcef9540a8babe0fb27755ca9e444cc7e3b2de51f4f63b9fad23b7a334003a45ce9919f223efa24d1e24ccd6b7d46f645834ae72cdd32484d1db569f8ed1b784ee2aaca9645e3fb7b0c68c1c8d22812b6903176e4475f307e0fad497f2134462d94f51c63e1e29defaad7bdaf03e49da1ea7086c064b3e536c01c4cc435d5be073cea199da5e6d1c3fd3a9f6d5b32f5ae2d974f07dfef21994f9e33999dfc0d3074aa8bf41c73d1b2f106ec5624badbb6521a3d21bb59fa5c28e8f02788975290248ad126ccec0639da4b0eb2e1a09be522dbadac2fdf2643c4cf2f905a55e7181542ce391f9ec6e3023fb3f015a52358be92385d6fb2c5ea84ed630622c872fcfcfab61e90b94b0307b31fab6df36c43c3d8907ff7842573d998b4e66f629d37681700c8f8d0c4da8ff8ab6e20348e817ba9e818de076ebd99d0b8ce672c12459b5955dd714b40a93210050bf54c8bbaf22840c2d007cd1f40a000cc55c745cfd3316205731818b93cfb51045369a4ee88cbce94b77544e64861d62dd10e711795d6fe3d4ad1517ead72967403c1a6a308bf834d224da53c2f89528c480bf294ca41e9018f129c0ba6316ea18fdd6e9d80e0593333c668432cf8a9505659fb63fe309b5ef348bef9e19fbecc33af91790b1c4531a85cad51af236ce5efdcbd77212fc0b642dcb91f7719e49a38ddd5afad688ed9ce5fb48d98f5e2c08f06d743d92b005e4d013e4474703f8c8f5b085f4f479896191f8fc9e9d6fd8b9c529ce2a7e8d1fcf614078366943deb263455843a31d16be42aa8551185315c705e90afaf25a06e93a7c7ea6696cf6f3cb496c674e3366e1fd6c1280a83900d5e62de9757e3383feb324728b32a496b97f6356f30ab160611ea04abc38b21cc7553901599ea4c590f9a4082e6341a9c323ea5dbf0f93180ef5bec182694c44e3360cc4ba3be21aed6958da7a6d8a75bbd84e24b40d88a2cd477e319933ad193b3072a987915edd7404e67d67759b31bfca09c6863e3230ff1e8731d1d8611bcdf31d5c5e272f674eff68b25933555feb2356b7639b7147961e3d8405e42f01bd6710bf64e896658d3532a78f67dd99d047060e107e084141ab06ba38124224861d6ff5e356bb43f90ca37b7b119ee2a06665b1c9f5d913853cc27f20b539727957ff17c07de0b9754d49f3ea1ea6da022112015e82a477e719aebb35e4c7e680dce407e3919832143ae3898ee14cf91ceb150341ebf5f767d2e1581c41751b8ddee365491e69d4c3c9ac548d60b8105b6b6afef80be691f1a766c59ad94ddee2ac824e26a3341b4409050486fbc94a1d95488446fd58595465204a0b7baeb3654c85ad124a6a42d6bb134e2bb9231a9f073afdfdb9fc6f114a99d08a685587475567cc68df54376fd13acab6b83b06628715e5ebc69938154c9e7c14c7cae80f78ccd41a8d07f2a65c09f5be027cd8fae674059b48d9d720250fc35160dfbcf520f89cce57af12415ea14996e85c6eaecef30319642839d4ce000000052c26f6dbb703f8711854e896635d51cec418c2c01df5fa5067c3a3ec08b30d042f4a08bb5dd156f17039c6eb9cbea8cdfbf46e64c6e345edc8aff2dcc7ad2ad911f2fca9853978b696cab99a0d633873e5f36f7e3faae37e24f8a27451604e9aca4a6d3549035e7a4e4527fead4920e658bd66d06509eda1841f843720016117ef0a66c52e26a12b719480cdb6055127a1601bb7110772341f1202e54ac90824 diff --git a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp index 7e8dc7bd21..57f2155e3e 100644 --- a/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp +++ b/tests/KATs/sig_stfl/lms/LMS_SHA256_H5_W8_H5_W8.rsp @@ -1,5 +1,3 @@ -# LMS_SHA256_H5_W8_H5_W8 - msg = 54686520706f77657273206e6f742064656c65676174656420746f2074686520556e69746564205374617465732062792074686520436f6e737469747574696f6e2c206e6f722070726f6869626974656420627920697420746f20746865205374617465732c2061726520726573657276656420746f207468652053746174657320726573706563746976656c792c206f7220746f207468652070656f706c652e0a sm = 000000010000000500000004d32b56671d7eb98833c49b433c272586bc4a1c8a8970528ffa04b966f9426eb9965a25bfd37f196b9073f3d4a232feb69128ec45146f86292f9dff9610a7bf95a64c7f60f6261a62043f86c70324b7707f5b4a8a6e19c114c7be866d488778a0e05fd5c6509a6e61d559cf1a77a970de927d60c70d3de31a7fa0100994e162a2582e8ff1b10cd99d4e8e413ef469559f7d7ed12c838342f9b9c96b83a4943d1681d84b15357ff48ca579f19f5e71f18466f2bbef4bf660c2518eb20de2f66e3b14784269d7d876f5d35d3fbfc7039a462c716bb9f6891a7f41ad133e9e1f6d9560b960e7777c52f060492f2d7c660e1471e07e72655562035abc9a701b473ecbc3943c6b9c4f2405a3cb8bf8a691ca51d3f6ad2f428bab6f3a30f55dd9625563f0a75ee390e385e3ae0b906961ecf41ae073a0590c2eb6204f44831c26dd768c35b167b28ce8dc988a3748255230cef99ebf14e730632f27414489808afab1d1e783ed04516de012498682212b07810579b250365941bcc98142da13609e9768aaf65de7620dabec29eb82a17fde35af15ad238c73f81bdb8dec2fc0e7f932701099762b37f43c4a3c20010a3d72e2f606be108d310e639f09ce7286800d9ef8a1a40281cc5a7ea98d2adc7c7400c2fe5a101552df4e3cccfd0cbf2ddf5dc6779cbbc68fee0c3efe4ec22b83a2caa3e48e0809a0a750b73ccdcf3c79e6580c154f8a58f7f24335eec5c5eb5e0cf01dcf4439424095fceb077f66ded5bec73b27c5b9f64a2a9af2f07c05e99e5cf80f00252e39db32f6c19674f190c9fbc506d826857713afd2ca6bb85cd8c107347552f30575a5417816ab4db3f603f2df56fbc413e7d0acd8bdd81352b2471fc1bc4f1ef296fea1220403466b1afe78b94f7ecf7cc62fb92be14f18c2192384ebceaf8801afdf947f698ce9c6ceb696ed70e9e87b0144417e8d7baf25eb5f70f09f016fc925b4db048ab8d8cb2a661ce3b57ada67571f5dd546fc22cb1f97e0ebd1a65926b1234fd04f171cf469c76b884cf3115cce6f792cc84e36da58960c5f1d760f32c12faef477e94c92eb75625b6a371efc72d60ca5e908b3a7dd69fef0249150e3eebdfed39cbdc3ce9704882a2072c75e13527b7a581a556168783dc1e97545e31865ddc46b3c957835da252bb7328d3ee2062445dfb85ef8c35f8e1f3371af34023cef626e0af1e0bc017351aae2ab8f5c612ead0b729a1d059d02bfe18efa971b7300e882360a93b025ff97e9e0eec0f3f3f13039a17f88b0cf808f488431606cb13f9241f40f44e537d302c64a4f1f4ab949b9feefadcb71ab50ef27d6d6ca8510f150c85fb525bf25703df7209b6066f09c37280d59128d2f0f637c7d7d7fad4ed1c1ea04e628d221e3d8db77b7c878c9411cafc5071a34a00f4cf07738912753dfce48f07576f0d4f94f42c6d76f7ce973e9367095ba7e9a3649b7f461d9f9ac1332a4d1044c96aefee67676401b64457c54d65fef6500c59cdfb69af7b6dddfcb0f086278dd8ad0686078dfb0f3f79cd893d314168648499898fbc0ced5f95b74e8ff14d735cdea968bee7400000005d8b8112f9200a5e50c4a262165bd342cd800b8496810bc716277435ac376728d129ac6eda839a6f357b5a04387c5ce97382a78f2a4372917eefcbf93f63bb59112f5dbe400bd49e4501e859f885bf0736e90a509b30a26bfac8c17b5991c157eb5971115aa39efd8d564a6b90282c3168af2d30ef89d51bf14654510a12b8a144cca1848cf7da59cc2b3d9d0692dd2a20ba3863480e25b1b85ee860c62bf51360000000500000004d2f14ff6346af964569f7d6cb880a1b66c5004917da6eafe4d9ef6c6407b3db0e5485b122d9ebe15cda93cfec582d7ab0000000a000000040703c491e7558b35011ece3592eaa5da4d918786771233e8353bc4f62323185c95cae05b899e35dffd717054706209988ebfdf6e37960bb5c38d7657e8bffeef9bc042da4b4525650485c66d0ce19b317587c6ba4bffcc428e25d08931e72dfb6a120c5612344258b85efdb7db1db9e1865a73caf96557eb39ed3e3f426933ac9eeddb03a1d2374af7bf77185577456237f9de2d60113c23f846df26fa942008a698994c0827d90e86d43e0df7f4bfcdb09b86a373b98288b7094ad81a0185ac100e4f2c5fc38c003c1ab6fea479eb2f5ebe48f584d7159b8ada03586e65ad9c969f6aecbfe44cf356888a7b15a3ff074f771760b26f9c04884ee1faa329fbf4e61af23aee7fa5d4d9a5dfcf43c4c26ce8aea2ce8a2990d7ba7b57108b47dabfbeadb2b25b3cacc1ac0cef346cbb90fb044beee4fac2603a442bdf7e507243b7319c9944b1586e899d431c7f91bcccc8690dbf59b28386b2315f3d36ef2eaa3cf30b2b51f48b71b003dfb08249484201043f65f5a3ef6bbd61ddfee81aca9ce60081262a00000480dcbc9a3da6fbef5c1c0a55e48a0e729f9184fcb1407c31529db268f6fe50032a363c9801306837fafabdf957fd97eafc80dbd165e435d0e2dfd836a28b354023924b6fb7e48bc0b3ed95eea64c2d402f4d734c8dc26f3ac591825daef01eae3c38e3328d00a77dc657034f287ccb0f0e1c9a7cbdc828f627205e4737b84b58376551d44c12c3c215c812a0970789c83de51d6ad787271963327f0a5fbb6b5907dec02c9a90934af5a1c63b72c82653605d1dcce51596b3c2b45696689f2eb382007497557692caac4d57b5de9f5569bc2ad0137fd47fb47e664fcb6db4971f5b3e07aceda9ac130e9f38182de994cff192ec0e82fd6d4cb7f3fe00812589b7a7ce515440456433016b84a59bec6619a1c6c0b37dd1450ed4f2d8b584410ceda8025f5d2d8dd0d2176fc1cf2cc06fa8c82bed4d944e71339ece780fd025bd41ec34ebff9d4270a3224e019fcb444474d482fd2dbe75efb20389cc10cd600abb54c47ede93e08c114edb04117d714dc1d525e11bed8756192f929d15462b939ff3f52f2252da2ed64d8fae88818b1efa2c7b08c8794fb1b214aa233db3162833141ea4383f1a6f120be1db82ce3630b3429114463157a64e91234d475e2f79cbf05e4db6a9407d72c6bff7d1198b5c4d6aad2831db61274993715a0182c7dc8089e32c8531deed4f7431c07c02195eba2ef91efb5613c37af7ae0c066babc69369700e1dd26eddc0d216c781d56e4ce47e3303fa73007ff7b949ef23be2aa4dbf25206fe45c20dd888395b2526391a724996a44156beac808212858792bf8e74cba49dee5e8812e019da87454bff9e847ed83db07af313743082f880a278f682c2bd0ad6887cb59f652e155987d61bbf6a88d36ee93b6072e6656d9ccbaae3d655852e38deb3a2dcf8058dc9fb6f2ab3d3b3539eb77b248a661091d05eb6e2f297774fe6053598457cc61908318de4b826f0fc86d4bb117d33e865aa805009cc2918d9c2f840c4da43a703ad9f5b5806163d7161696b5a0adc00000005d5c0d1bebb06048ed6fe2ef2c6cef305b3ed633941ebc8b3bec9738754cddd60e1920ada52f43d055b5031cee6192520d6a5115514851ce7fd448d4a39fae2ab2335b525f484e9b40d6a4a969394843bdcf6d14c48e8015e08ab92662c05c6e9f90b65a7a6201689999f32bfd368e5e3ec9cb70ac7b8399003f175c40885081a09ab3034911fe125631051df0408b3946b0bde790911e8978ba07dd56c73e7ee diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp index ea0bef3312..e48c4fed28 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_256.rsp @@ -1,5 +1,3 @@ -# XMSS-SHA2_10_256 - pk = 00000001B901B8D9332FE458EB6DE87AF74655D0B5AD936A66FDB6AC9D1B8CF25BB6DB8404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 2500 sm = 00000000404DFF9B9F3931FE6158FFF355A8EE715C9BC6A87FE6627928F3CA1055FA7010C534B0D4C6FFDF4DBFE00E72405EFE83BBCF19AA2030A8CB163808482B6376FF8CE01FB8090F4842896A1EA5E9282F35CACD245A4B9DE9FE84E9315851D68A72B3ECB9F440937C8BA4AC3F0429246CBC2777E8B92D84F4BA49FAB89465FCB0FC8017E582746F531B4697925154A22E2D6A0F1B81913438000C295153D7ADCA8F852C50D360F65F887479E9631A2CA30FE3AD92E7BF648643835F4F8CC081A6C951B83B77608A08C021821DA61962CFCC8E97D75441921D39C5AD537543EFBAF0345DC70826E6E950929570C72E51619600C58D932A72657B19AF163E0B8F7AAF2949A5EB26C517909E0E663E36753491182975206009107509DFFC898D308B903E84A8B29718BF7125397AFF5467D53CF8F36EB945B6B98D48E81C0174A0E03541D24369CF8EDDA4288FFA615D16FBC7355CFC0966BA9256E5B8A44DA95760DFB61301B10FD3E82436E267DB089773E43B984297D1E0D395DCC77FCFECCEFEBD4B80B3F241872EA251DA466CA6C5324346F4B5E6886654A86592641A8C32AC554261B2D9130462C976B039E593F873AD1712820FF3E723FE57F137751AB3CA8B5B20D28D1B9384DF1D710AC39FAF699989418B7856C2034C695A693ECC336EB472DE5049C743089529695B028F2F72BE0893E59169E9A2376C64BC5CCAC5482E5A6E9C88D710A3FF8F23C206B09D314BF50568228B1BACF1CE330D529BD3793D7C7CD9EC770C111D9681D6F1B97D908CBBD436444853FEB47F234D31F5E92B9E0465D67AC0FE48859126BEFA7F7D121A67C2C2970B37B8081B4E73C5A21A41F60160A61FAFBD48649A3D2032C1679A67F348E3E25275FCD9AF650937FEB0A30F25878CEED7D6CA693518B5A2F5418135EA9316EFFDECDB1DFFC9EE3A62EFF0E66F3D05BD9D5F8679B536BB6D39792B28DF2481A6EECB9BEE40B11A10D39A90EA1AAC47BF956FBFE9B0427B599B9BC024F326515E71615419423FEC3F19F621D49B6EED59F129A6B1411B7B1AFCF073095D57B03F25A16F946ED716BF705F567A151BE85B8E8195CC2F070BFD482702182B8A4A43ED942F6BD3CBF9DE7E8AEB17C41E1C009C94FF4A2050E3731088B75474B38DC52BADF53C7DCD3FB98D023649FC4799CE060ADDACEC7CD4E656074E631C1CB8AEF88EFEE0817C2E3D79E287F4510E48DFB7E23CB49D6FCA39A1E0F471F16A8BB65AF02150D059036D00386DD287BEA4D52FB263B57AE5ADD901CADE838B1D7347D9E47EAF6456148C6C4E44B0FA3DFCF5C9CEC2D80AD509A65AEF0E3E663B7F31BCA437311BA799D4C2ACC138F85D73CB40792FF03F8F20427D951444990CA3976A71368A7DC1455E880722F06F02163BC712E852A914F22E5675EB9B1C6C8B7FD20A8880AD2EEF97982C065C937BD3639357E4C7450CBDA0B51CCA8E3E078DC760FD99EBF646B82369576539B2BD5B2C866ED5AE94423A5CE18C685352398D01C983F080D7BEB8A9243AAA9AC1DDCC1B058B92BEAD301E8F3B8F5EF71EEE7966302B44D2E26D2A02393713E5D4D3FEF42196FAA368274C78C2932D22840ECA6018CE7D16B19A0727CB1966EB28B57D137C5264CC2E627F24A3BAD50EA4F75C7BD8998709C01ED5ACFFF0891934E94DA2CACCA212FB48BE3F9EAA310547E73C388D881F36AE21EFEDD23744F6B07C5D6D2776C191ED41E607316F61BBEF7A20E1A03150AE833D18952AE35188FBFDFA55C12A388836717BB2BDD97E89121C56C3B53E8198242315C9E438512E0C8354A3E599CB7217AE688647A72985606BBD0720F6FA5C5B6F70E88234EE54C6DB0A41106C866564650829FE4B232635B06B18240C9F86369C75B2F7D237211A380C43F95D362E0680D9EA2CA47E1DC8C49703E22650B765F847AD86BE25A3B7630D640A0097632DF13F600E8A025DD9A1FC67B0EB09C1CA9FA3923896927DEE1E3CC0C81F4B82E43B89CACC69C9B8ADCA1670F7D4E50DB7BCD94C2115E75F2BFD2336DA5A304D0F3455927360BF5040E95D1454106F2A8A7CD27D5510E7B5BE7B5B9EDEFDC3D4249D655C51F4C1DBA0F359BE4769AB66EDBC802824E9AB866E8EEAA2FEB1CC855F0A745AAC84A610DF0238112C6519F8E7346C45331A6036F84D5B6250F4B5BC0A2A6A31DAF9C60EB13C20CC649A18E27A6C98B82F08E21706A8BDF338CC69C1679D25ECFF733A721211C1F6DD28091AAA9C93B047EFCD2C8A55F2DA65E616F07DCC0F44081D4E359C1688A00F062EC925D24432862B547BB70F2AF126A3DABA5C918B224DE444B8733E6FA601B3D349307E94583D0EC976AEDA2B90972324B3ACE8C7B79A67723AEA037E12DA9EFA9CA9668A4F5FDADFB9EEE13398921F5023E354A6894825431DBA7317E6A6F69F0E77294BCD02D7616E75AC31EC528FC070B8C34027C4E9CD0672903412FCA6B723650D56AF562069312FC7EF1891A77E1A3F29D810C205EE212E75863F3B8B1ED216DF888ADD07AFF45F1B5C01196329311414797CD5F67FFC54AAD04C803FF7E83C2E8BA224CE83695BB7916AC42B1861F5CB527FDBCD82DBFA31C5ACF981D8414203837504263C96A0015841FBCC721F96D50A86D6E096AB54AF9980F06CEE6341C78D6583F6BAE8081B3C44B0F10FB7300874B5011FF0F97C52F975A31355884C2F12B6FFEE20E8371D38183C9D04977BFA037C9BD4DD7F7CE203FD7FAD3852B3C2AE9D078ADEC70DB1A7140EF1114EBB03E8DE03237E0A27FF510015AC76FCEFE4EBD4C3A1B6C67DB2A82FE2B1BF18723DB0F29FE4AD47B2EEF22AC3C6661CFA7DA7476D23B470FA2E0441B6473EBD291791F09B4ADA70A5286EB05167BD59BFD8C46427413D60692382EFB7882F60DC53AAAFDF2014CA7D27F8FA93C187A8371B41796557AE739912E5991C713532E81FA57F9BA562E1D3026D2D2D7373D99871BC62768AD70D3DB184EABED83E30C11C9BC62F3340923A0082B987EC45CC7BD1DB4B2B15E8AD3EAD74E96D8C20D85617BBEDC0BDAF8ED48B7EE8D7C42990028EC0669AFC0861C22F2E9109F9BB35426BDDB4A69EB8F45CD5B226F92E8026F1E62DE1DE435A4FC0CAEDA91C38A88F0037BDB296CD7B07FF040B1E08F02711E946B307A5A38487F53070985B8E28BE6CCE809F34100F0CA780996CD38E91BA7773BB632D0BE7978F3AF3A92B961BD3A8759590726D6C1811F9E0BCA87377334E7C1F12FE37401CA0200823938C816ED98981521470F7F2CCDD69D85E7530EBF39E3A592B1C09BC6C352C3FDB108FB26E7ACD3D5A4FC0442962E2C09651AC0D026E370F1EE1A8219C4833D70793D6E581FD25B0E95FAB1EDA67232C2FA12C4E379A6627E75AD408C1D2526005F2567CED8608E88CF53064FCDC58007198ADFA860F9FED1DF80EFACC768A0A063E1AFEE6DF1BE3483105B1C45EB50BF7863B4278422CEBA9001EA00299AC0415BF28A9C49CC2E92FC15565B547538A027886C6EB0D83B71138CE1A remain = 1022 -max = 1023 \ No newline at end of file +max = 1023 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp index c56266bf30..4c5d3081f7 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_10_512.rsp @@ -1,5 +1,3 @@ -# XMSS-SHA2_10_512 - pk = 00000004E219A0AAB2C8F4054939A56A419E39D2B91371C6A2A485B21D749DC399E0E58275A69ED6A400A7C1EA5A7B4EEFF0DB2A7E742C062A847DDBA24680388DDDBFC14D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9092 smremain = 1022 -max = 1023 \ No newline at end of file +max = 1023 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp index 299c00ae9b..8cd3c93b7c 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_256.rsp @@ -1,5 +1,3 @@ -# XMSS-SHA2_16_256 - pk = 000000025E84310CC01CAAD0B2B1E010C15F6691FF24977EF626465F5CAC2B015342A52404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 2692 sm = 00000000404DFF9B9F3931FE6158FFF355A8EE715C9BC6A87FE6627928F3CA1055FA70104A82ECC99EF0F9172F36D2B461A6515DC13666B7F1D917746E7086F99C8F1A63E1C7E5A339AC394788015AB12B3532C7ED27D1BCE2B1F25ADC96165F6104861C3DCC2B150E1DD088C95AED7DBA928946BCC8351DAF6136F7335FA45EE8F4651CB9A6E98D556765100FECE8CCAE704D7AE90AEABE735C2FF46DC9FB302D2A1F4C33F371ACC4FA552FE83C254761E140E990474A10D5D2119D90AC9C2736BA2992026D11473619FC9D1857C50BD2ECB693FE0DD9C15EEAA100015D58F2D8F936E154B5C932078BABD1E9A3E3D7B876174311282D3C02D8463E268FB1542D967EEDD01DA7D0ECA0E3257F84C2813FD01B211B495B9191A48E3CFC34E056844855BD1EF463F5D1F9E9A8C7FBACBD29E2726EC1AFA11522536678005155E1CCC5562A8C0D1AE450EA842EE72F236381AEF42F2445DD5B9CB2A791B1D95240D10FE14A3343E73C5FE2CC524A7FD21FA547675C86F6C8D4EADEB1AE29060EF687EF65344A45A5F1033DA0B50A5529AC43435DC3A8BBBC986F1ACC1AD60CC13F9BB26A1F99DF207BA4E2C7B1A4A0BD8B5B9529F705C1C323AD93B7F67D735958A454CC7D6927CB165E25F6C4811F8D486A34DAC2C8A920D506682D747BD6496258BB4011164FB8F12A3E984085401E73A96C5A0B7A661F6D9288910CCF1C1101E0BBB68646191DCEFF06EAE14F3762FA5C231D3D57770F230802C2188D108FE326778A10980AFDFCCD50CB32C844771C1B5DF2054A7F9D19FA28F461E81EDE49B2D780FB3FCF424A28FB9B2E88CD08E4D4BCC31E1BD06481E817980FA8A40E74D0CECA78B87452100271944681A77667368E04F077001DD9B1454DA4614F631A83335A8C5B1F83087C603CA6D731A4AE32346FFBF5BBBE7FFCD206304CA468789748789EA6620D7C8AAA5D10EA029C3EAF78675E35C29A598CB5624FF0ABCE0548CD6C9DAE3CE9BFE4665EE57358DBEC0D157880889597F245FA042D00FFB56066AC873718FB1BD12E0428923AEF51F55928C8DA0D632382E3325E4CC5C6A3EBC4776C9F6520EF2C6960F0129A707F90315AC1AB035A7BA0D293A6400C30D363DF000F53D309FCB4CD455AF4290FE44F8FB76B6C32ABF15BAEEF44136CCD739D96CC95B0DC0EC8186125075F21570A6440A5967CFB83836BBE0FA463C0B6692A9C6D673038D17D343EF79BA50ACE3835F6216C3943470012081600FD81FE5B31B604E946A2328C40E977558DBDECCB8D643E07A573A9CB5DB4518877320FBB4998BFDC59FEDF2EFBDAEA4058725054A1317CA755D3BDD4780AF57F3B76649B3675DD9DD95A16F5CBDFCE00CADC229C2DD7B4E32D6EF82B346C5900BD03164C1896A4640F8B79FD7241614D2FED6D1E2E5795827F146C2158BE0A39E9556BCE1B08B774531FBFED5012C3F1DDB0C27A8503A43AD652AEBCF8E6F904EB09F30AAFF35952227395C3151F2927727015BE31E6A03C994E8011B555AA21C792E806511407B653D1CFBBD97D1D4CC87BEC5E436487DD454363E2E87AF3C2AD4590B98E9597885A533623BDDDA308151FD4902D8BE5EA43CEC046E62DE367D9C21F581AC2EF46EAF0F0E10438D4895C49FDD3049A23E32561BCEAF00F0C192BB9B2426CBDE0CC3E6186C3228990D0C0703BCB923061D0256CA76F9A75429F35CF416D6A93FE80E8C771DE016EB671CCD86B9B221CAF0C521F58D8BDDD226514234C6D44554A5943C782FFE265FEB6309F643277F09495ADB42B4C362E1EBD6790AEEB0C5329F797809B1A99E617BF85395C38D7B367F2C2AB5E26A156437E7248DF2E9F2F6170493DDD3FD0A0CFEFE8577D87D69AA8E668F66279BE02DEC2D05BBA330A504C68A7E81709454395DB2C55345262308C2443E6D245675277291C8E6718B222332047A841B2EF96801D464F6EA1053BF96F6E69F495D45535AC3FD4411C27FF7DEE1A7BE429B3D9A386E40B99329DE24163911705BC3137F0C728AB5848532999315D7DD980036E8107AC3A68691D840FD37C6950FED7E43C79CED8DB06685476979EB357AEFCBB1CE969D9C37505FF2EE6B27F8FCED566180664EAA36D867E2C702C6716A8EC826FAAD00204EE915AC2241D72BD22B8C46387703E5005F5A2FBACA6F84D5B6250F4B5BC0A2A6A31DAF9C60EB13C20CC649A18E27A6C98B82F08E21775133C937E715F8EB13518C059EDF4585E7446408D2AED56F1AF125187E172DA47D9A150ABAFCBBB6BD37E68B51E1E3B76A88186784096804E0CA23134BDB161B70F2AF126A3DABA5C918B224DE444B8733E6FA601B3D349307E94583D0EC97649EDFF2BD44402B649537B4A3AB06D71227E40BE5A484B47D7364A839A4730A09D12310A297840646C5828AAC63A9C3D416A375BFD3CE0D4A35C24762B458CD70B23AD28725612F5FB98FF740AFB457915740084644120ADD17B445078AAF541C08E140C4F0E8E005322F8AB6BAB5DF2FEF6DC1EEF9555B3FDA2C9354130A171A704637AD2E628163EE49D33FFA1530ED03F0A3E771B74CCF546BEF58EF21DD1522538D7ABA7F4A83155F8567A89BB7E052994F9E491025A37F3229BA80485F66F0BFEB7D77B5227DB43AC1360C86DFEDA86872B28FA47CE1C78A4DA2508F2144D5F353F6EAB57CC363587735255342964CCE7ABFB619A8072054867C554D4474EC48C059D2384AE7E36865F8DDF0CDF3C1B34C9783169B23CEAD96903024CE5D0B798AF6C9717BBC5DEE4C9150E8B271E12B53D2DC24D62BB1B522696BA13C595EED0091E7B3E7B5E50DB3DAD2516992EF120B950C8A22C5D1DC1959D8A6DE0E31E568B1B105DF9711B589CCEE0BF0A8A4597AFB9D07663D1FA4FE307488CDC692382EFB7882F60DC53AAAFDF2014CA7D27F8FA93C187A8371B41796557AE738D2AE42D887D10EDBCABE6AAF951E0A070D881879332064C99F8527A5EFF252439DDC6270CBF5906FC144DE1CBB74B260E8615FDB2903BBACC7A30DA76937CC982BBF293AF6DE61315DE00A8D15148487FFC0BA96489AB359231EF31202AF53CC22F2E9109F9BB35426BDDB4A69EB8F45CD5B226F92E8026F1E62DE1DE435A4FC0CAEDA91C38A88F0037BDB296CD7B07FF040B1E08F02711E946B307A5A38487F53070985B8E28BE6CCE809F34100F0CA780996CD38E91BA7773BB632D0BE7978F3AF3A92B961BD3A8759590726D6C1811F9E0BCA87377334E7C1F12FE37401CA0200823938C816ED98981521470F7F2CCDD69D85E7530EBF39E3A592B1C09BC6C352C3FDB108FB26E7ACD3D5A4FC0442962E2C09651AC0D026E370F1EE1A8219C4833D70793D6E581FD25B0E95FAB1EDA67232C2FA12C4E379A6627E75AD408C1D2526005F2567CED8608E88CF53064FCDC58007198ADFA860F9FED1DF80EFACC768A0A063E1AFEE6DF1BE3483105B1C45EB50BF7863B4278422CEBA9001EA00299AC0415BF28A9C49CC2E92FC15565B547538A027886C6EB0D83B71138CE1ABCC7BF5184638350478FE05829DCD0C5190BF84804D293190C08140A600415D691DBB652DE950481258ABD45E76B9668FEEB94EB6605DF5900501BDACB58F4CE0F6B0120CAB51933633EF98DE5471774EA6BA1642AFB0DF6C7041A8C05555A5F1D0212EC753E23A7CF68CE52417C9D7CA5F9C180D04C6B64F70CB860D2903E843B956807A682500805ED38DE3DB09B05C5E31C4E78C72F83F1446F69441E4D9D9168B4F97EE394586A683D38B9FC72FBD5D92D976C70A407E0B1E25F3046B583 remain = 65534 -max = 65535 \ No newline at end of file +max = 65535 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp index ab807bc996..062a0f68cb 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_16_512.rsp @@ -1,5 +1,3 @@ -# XMSS-SHA2_16_512 - pk = 000000058AA2D66ED8FC46C0EC0504C56F35B897EEE56E6E022C0020BA1B38E675296297D99CA20060E4954AD137D640B279CD2903DE768E1FBF6A412EA45B5A33EC55D54D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9476 smremain = 65534 -max = 65535 \ No newline at end of file +max = 65535 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp index 5fb1e18f1c..778c2c0169 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_256.rsp @@ -1,5 +1,3 @@ -# XMSS-SHA2_20_256 - pk = 00000003A7FBDCA19FC30ADB13F35C92F71086094413263CD71A0570C9C2F250CBC2842704562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 2820 sm = 00000000404DFF9B9F3931FE6158FFF355A8EE715C9BC6A87FE6627928F3CA1055FA7010C534B0D4C6FFDF4DBFE00E72405EFE83BBCF19AA2030A8CB163808482B6376FFD2CB50DDA1EDFD708F002ABF07D0001C3357A70F6511884C4185790EECECCC578715C21A26FC1E7A951C54A30ABCDB7EC71AAD92F2662BC900F9E9A93054CF39B9A6E98D556765100FECE8CCAE704D7AE90AEABE735C2FF46DC9FB302D2A1F4C3C0901B0B16F96846F8196BA6E2E8BA4375B3F5FE010A02661EE3374C1B28A76A4A8879EF91C329714FFDF118CF5669BF7BD65CBDB738CF6A8636F20F399855E5BA4B0955661EA3FC882D9D64954405502E2BEF7D3063D36F993460D2557C7977DACE2D6D7D9A77DEB151610372F7DA0C73F7B2A737064A6C62DD0CF4B69F1CE4D9BAE3589B525734E92F3F8D4D2AD9091B6C82F7C0189D3780AD854BCF3CD62ECA5F998274C2E153FFF3CEB473D81B551AB5F85CA351B4BC225D7942733BC8DA6EEF78B8184B2E355CC338055DD2A26DD02B1A0740CD15F6CBA4EF429254DBCE0CC4F4B00DBFFBA622360B091DD6AA817423484ADF53F5D8A30E3D4164F539899DF207BA4E2C7B1A4A0BD8B5B9529F705C1C323AD93B7F67D735958A454CC7D4290DEE03A74DB1B3A62D2EC10EA3C3EF2DB3375893598133F36B5B8F2AD5929164FB8F12A3E984085401E73A96C5A0B7A661F6D9288910CCF1C1101E0BBB686FC03DC302429EA2768093BA3B43C542F272E93D15A190426830A92526E5251912FE8153DDA93C92A1195701DAB2D2A22C9F380DD4984645384692FF8721D549A4CC74ADF8A5C2BD5DE48F6A923D8FD37E36377639AD73D1C7AE721D0152DE0E73844FC867FC8C029E657271B738EFCC1A39C2A64EC5DCA96D89BAD4C407D4F0CB226B913ACD451E7C65BAFC90021E665C24A2EA208A16D92E9C27BC18B9D59B7FAA8FD4A12AD43A403062FC7003ECC756E3E26F8B1BA47801DAA46173063E37823CFA4B1481DF4C88093941CB014F54D73B5058ADD52B6A0638C8F3341DC13235F18FFADE0EA5601EE831BD587A8EDB72F96744AF8B08AFF190BA55D0B25D47F33F84F17D6C15B50AF1684C8F4044CA7BA2CC196C7F3CC9AC2603194A9A536347F33972E57BD89F4E3AB7977CD3220C0D5E54911F17007973BAEB9C8B3DBB95D1483FB4C281E8137940969814A5B6FE7D1057E1DCFB7AB61415E94AA4338F0635813AC5FC9767CAB6C9B71F63D372BA40AF511C7259875386539636DD45512165EB3E72F1046CBFF94254043D879CA0B64F7BD7AEC79F5F87C11DE3DE80756E9FA3DFCF5C9CEC2D80AD509A65AEF0E3E663B7F31BCA437311BA799D4C2ACC13818BDA90266F7A362B61CFDDE0523BEB8866B829512E9B625A90898DCA3DBA0BAD32BB3F2B1687014B418E277BEF2F73A6CFC6016578227EA1A56E5F7655C68B27E3B486B3D2D5EDAD5390DA570BEC6613D901E5D75A913978DF9002D8AF64A9B4E6BDB7388057A17624FC600F3031D016E61D17E3E6A9B2771E2CC466B2A17C425E4F21F65131B4005AF392C685BEAB2FF1E5E4E886E1454DB240AFA0319449B4F3DACFC2FAFF74844BF8128A3B77237211ED11362BA8A6F87C6D103A23A7D6628B57D137C5264CC2E627F24A3BAD50EA4F75C7BD8998709C01ED5ACFFF08919C609F8F74BF5303C281E4D8D1488EFB7FCBCF8AEC5C4B26330A6CF6E4D798C1FA4FC6DDFE7FBFCD3C4CCC352F28FFFB9301C08B0731F472F6CFDED99EFFBDCFF23AD4839258197D6706C3551375B3F7359C6A8403C9BA07CDAA348C82E896416D74BEB3BDC53DC8CBD2A281340B78F7635419636A3C38E9D5515CF8A035A439D322FAC7F9853AD29B44EAFA7AA9A4ED2471B0BC91B4E1FDB7E6A80056C0F264CD1E0837F2ECDB1EC864CF6565D6F9ECA34C9B961B278867E8ED627C1CA3F0E05A841B2EF96801D464F6EA1053BF96F6E69F495D45535AC3FD4411C27FF7DEE1A7BE429B3D9A386E40B99329DE24163911705BC3137F0C728AB5848532999315D616AE1EE474D3F1C1DD7BC7F282E6DA92731914758830B8AF74345719259AC8366C65C61697E08F06B61AAFB4C247C6FC8412F815114AC9C3D9172C1B5CF22867D870CE2534C0C2A163DD971EFB7226AF5B9BE4351DE6AAA45F27F9B2CB0831FB8C51B0C6412F36BA064FEA5ED935CD8FC498C92D651E2C9BB0A294D35E87BE8B94C03E5893DFAD17EB8A15E5B131E62A0924331F3888CD95D68D0541171EFE3389CBEC636344A6AB01468843A94F56FA7FC1806448C09DA99219B5B3FF5EEEC1397B66DA61A963FEAFD805408782D911B79206BE9A53D04EB1ADDF69988D97437FAFA9FE1D707144A2290523A7D25AC1BB6206AB824556519D2B909E4D04DE8D8D35A0398398CFD1A6A4D5B8B9BAC3A42A27B05E91DC07C8AE10BB4636D08A9D08F444A61A465254F464EBBA190A6B09EF04567EA727CF57713F381DDD9FA8D431BD19121BCE533E07068AB0500B15488F2F60DC3C2BFE4CBDBD849C873D2036743E7CBED5BFC1F8511489AED9E0CCC0FAD5D9F1805544D2A20F56AAD3E0058522538D7ABA7F4A83155F8567A89BB7E052994F9E491025A37F3229BA80485F6823B9A3781C1CC42488414DD491B2F80FD91E049E56AFB0D3823E66A6A3FCB1660641E4368990B3D05CFA937C51BE7692B36F007281321B5F317242030B2007DEFBA495E0499587494A9B6E4974C37F5C006A34FF102A23985FA9F660326DA39E41C65227E6F51D5EC56D93D19E1D3279F668A13A2B3599139B265111473D5F8F0B23E656D7E2729177C18213323818435F2951FAF7288F66F9B7B6ABBFC9617B0191CC9DA4EDE34F511E0849E7C27115FA6EB6C43172DC2FD4CB1AF4C27A4A6874419356CEE67CFA51989ECB77328F87F18629E63A6732C5BEBAB4DB4BEA3E19912E5991C713532E81FA57F9BA562E1D3026D2D2D7373D99871BC62768AD70D982818E4AA66E926983B45F64AA0172AEB48B28DD4994F24311F28B2577791EF712689DF5DE30ED5313C773311EC605B8E44C297ED4AAC95D3B1DAA8631F7786C22F2E9109F9BB35426BDDB4A69EB8F45CD5B226F92E8026F1E62DE1DE435A4FC0CAEDA91C38A88F0037BDB296CD7B07FF040B1E08F02711E946B307A5A38487F53070985B8E28BE6CCE809F34100F0CA780996CD38E91BA7773BB632D0BE7978F3AF3A92B961BD3A8759590726D6C1811F9E0BCA87377334E7C1F12FE37401CA0200823938C816ED98981521470F7F2CCDD69D85E7530EBF39E3A592B1C09BC6C352C3FDB108FB26E7ACD3D5A4FC0442962E2C09651AC0D026E370F1EE1A8219C4833D70793D6E581FD25B0E95FAB1EDA67232C2FA12C4E379A6627E75AD408C1D2526005F2567CED8608E88CF53064FCDC58007198ADFA860F9FED1DF80EFACC768A0A063E1AFEE6DF1BE3483105B1C45EB50BF7863B4278422CEBA9001EA00299AC0415BF28A9C49CC2E92FC15565B547538A027886C6EB0D83B71138CE1ABCC7BF5184638350478FE05829DCD0C5190BF84804D293190C08140A600415D691DBB652DE950481258ABD45E76B9668FEEB94EB6605DF5900501BDACB58F4CE0F6B0120CAB51933633EF98DE5471774EA6BA1642AFB0DF6C7041A8C05555A5F1D0212EC753E23A7CF68CE52417C9D7CA5F9C180D04C6B64F70CB860D2903E843B956807A682500805ED38DE3DB09B05C5E31C4E78C72F83F1446F69441E4D9D9168B4F97EE394586A683D38B9FC72FBD5D92D976C70A407E0B1E25F3046B5832CE029A1A95FFCBD5C8B157282F7364E680C60B252C49483FCA03529693B074E0D2B1F6DFD6463B974DE6829A616F20C839B0D2B8BE5405623B5B722EF22F7A3BB78E91315F715D9DCDB0C8639CB8A90685BEE7969671789047083CACF24FBC4B601B1B23B2E79E42176B2438CB405BDF46369F4DE5F411B2ACD32BEE3065DF9 remain = 1048574 -max = 1048575 \ No newline at end of file +max = 1048575 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp index 92b345dd0e..ffa415e6a1 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHA2_20_512.rsp @@ -1,5 +1,3 @@ -# XMSS-SHA2_20_512 - pk = 000000065711A97061C93B4FF7199D48104CC42415C4634EBA3647D8E51BB1ECB7D4C455418BDE977F20460E48826E531A7A59E7DA8746D7AD5D80CD059D8007C2E890304D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9732 smremain = 1048574 -max = 1048575 \ No newline at end of file +max = 1048575 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp index c684aa186f..1c1436e12d 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_256.rsp @@ -1,5 +1,3 @@ -# XMSS-SHAKE_10_256 - pk = 000000077B563C8B187847A60569B3A0CD3049A5DF6CA3EA3B446D75F99F8D37B940AA9604562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 2500 sm = 000000003017CF6CDBA4AF7D6CA495B9872967AFAB62AB87100AA92CFBD66591BEE188E651324F8D245291EFF735334671EFFD85F3A823D972D2D49DF408A2AE09590B24CB219D4BA4FD030544953AE56AB3CC426D1E89F8567A33D4ED495164A01434E617E01CF73FA1022A8E19ECD580802F2A359A6BE287236C711249E8CFD26E81E0D962E4E6007A684AF87B096B9034966949F56D02660E2B7279214CEB93E62073BCA7A334E8928210CE101C948DE9105A5FE3B87AB9741B4B4185D7EE42AFA3055430682E22AC918051D97466B12D2FC559413DEFAAFC677C8351565ACC58D481259F0F41EE4C3DA4365AE4ED4094E4B7406AB6963FA3883037750A6ACBD864F56826811C4DD77FD89B17FB35E2EA7C907A056063335AE03884B54E791EFC5B68DCFFA47AB17563DEFAC3A51C0C7E96367FD2A5BDB6420DB2F8E1FA8A1E04E02B5033836AC23BCDF359C659C13E9237867828AF0F173B3F932629847BAA0FF1658833035CF78699FC249FF331272A068D55590E7451D2F1C118B8DFE554FEC7D2B2E0B494B145F9033007E7EFF53151299DA3E5C48DD1F35C37DE0D832D55AED0433B04149A965F5EF8A804F0E6EA4239ABF28A694648719C1A4A315A4EE054B04CAE408D5436A081A948E75B7EF5914E0DD9A9D01018918CBF37A224824D0B936F9E659D7C7663EB4B63FABA90515F2700301544682570E6B3EF16C59082F949173C93ADEC1E111F387845B826C3523FC184B5F1D1D830191C88D1F9F3C3A81337495F73F2B992EDD1E9D930F098492BDF4DE0C16A604D71CA275176A5C2148B151E1961C11F7D8CCCE4F08E9BADDA88E17BF2DB02A6D1E1D2827021DB46592168223ED5CE3170858485437C132229DB3823CF7D727E8DDC6B6BF00983947D02DA1D6A0C82EF62F0B0A9F1FBC427D200F636E66DE934401583B67DB03BB8492A21BE921E1C2CC0ECBA29139E304A0BDF7123670D3FF614F1F0E22C7C8E161E91E90EBDABC3BDA8347463B052E4E97DBA22481C772462763AA738E424431E22FC0B8441A43735869308C228166FE2041FE782E25EC9ED80EC9994EA098FDB0782856925994C9E8FDF09EC353677934D465C348E01FEC000C30ADC8B85F0C19844A4E6B4D0E8F6B2040D9CCF85DA7C9522BD571EFF09D5B1561225886FFCD6B788E6A6267ACECD693E42C90E4730F2EBCF73204F7DBE114540F4AD0C2CAAC6D0565C6DCE9F7F1C5542DD0F7016BD1C976AC68FC2C45E702D9D428999F9041C8CD89B70FA2A90286D7A5F6EB267C45893AB7A9C0E9F75889E64F9A24ACF8963268ACA48B903DA92B5D86FA1C5E8DA5C12CD2C030F11A8F670E028AC1E3925B5D70E7EF6E258B5B1C7F64D767098FA20C976F74949B4BD4792A13DE3CDBAB345B43C1900F6F63F45D02F6A576D8E6234AF7631821A82C758CB0FE7A920EB689186D83BC6D34D4FA579D07F899DE605C6B6C53BB3EB5DBDDA07747CD49164C54A9BF8A9F6A9548A58E119830C4A1C28BDAFB0F94E7539D5F73E2043018B8FCEB218AD24D0B5AF139DE4BF0968A70B206EDA0FF3324096BDCB13A3DA1C550639C0606527E494572744D779FACB63A81CBFD2C18FDDF4883B35F19FAF86B48D5CD2DD9177065D7380AFB479A59205262C98995C8EC3B26E648E01252E75EE3278581B71C84A6F9F49B0EDFFDCE1DBC2AE84F1FD849E3E1D049EDA6A5EEFC0E5EFB68199B40274DBE381ABC0C1BB6336975F1CB08EA7A875241CB911B9853025F7CF48F75D4FA0ECC39C94887E71903538BE9408E8DD1AF757ABC63097ED308C7F0EDF784DBDCE94CF1B52C96E524E7179C8ACBBCFCAB586CE6CDAC4FD71787904D4D19A3C95963CC8A0B0F4073965CD5FEBC875F971ECD647F269A6365491CFB0E6F0908347A384EFBE009EE5ACD512C88DC34BB54340BC9B1C0CCA389E8BDE6AF14B3DC4672459266931B482AAAC2ACBB4542B22D3D25E2E279700167CD7AF03866E60B41CDBCDFFF1216F45CE0741C53B57059C2F55F8D2529C6B0E760FA3BB04A38153913A2A372B5CEC76D57348A81842EC2A2BA6D8D23C976F3CB9F3D349A8448C04962D6B064AB2B8D48AD48F1B221B7BBD9612FBD83C101B7047D793FBD30262FDB21DA3610060FCCE410A86D46779A61C7122F5BA45A814E46224EB6D5969EB9FEE6EDCEEED25B698E4E83CA574A8AC2896FBE20E91DE3BC759FB39137FE7C26A9201D40914CB387223C9F8937FE6F5503D7C207C9330CEF1A170F355484FB1A3BEEE3253FB58D7B532C7885549593BF2984B3D6FCC2E70105FC34A1CD9A85B5D7EEB3A3EB4F07F2E7E0E649042A947B4F9D9A5149F0D57913A7EFE5265E853091C4EB95FCB9EEC69656DBF47ACD54F0045644E95BC75168F17C797F9E54C42DA5ED4E72F3CBDC54D20135C64F39492E2F2F577EB888047FF44CC2528BDCF0F387DC53F045523D40423CD4BA0626CF907312F5314FD59BF41A47F18186B517A59C7B9BD07FFF6433631AC5C062DDFE499E0C22DC5E3A10AB8D8D0C5D9A098331052A74A72C2599419F61A78459B45C7976E43E96BDC2EBA3AE45FFFC8766D70CAB36512C02951240FD5ACE420AB2C8CA931E1113F541C8439AADB13BBD01D08553C645E1E8AD6AC0BDFC48F9179909E135B6055FA9CBA44BA072D2A538BE604D931A5E3273F4F5BEC1CAB03D56A297B5EB5AF99C83F60C70873CB17A1ABB1665B6D7DAB0DB36359457BE473FBD9078313419BD89B3B947A46C2FED48F0CBF057F179016B6DA9B9ABFCC164E97B4E56278799D669385C5F0EE1BC47C9DF611F3C69CD4BA07AECE7C31D5EFA0A3D8FFC137CAE208E806DCABE99584F7EE28086E4A338CE9B8073DAE5D30A9571B807D43788E72A7A499DA5589B7C5BF91173A9A93A386048112071548CF0A71C9991DBB3A11D93483E3716D9A8BAAF62BC5BB58B991456CDDF24C6BFC89FB8A8757F940DF8DE473602610F33F655872E11109EA6E323ED6E8A520C761F371CF760445A3E865E4B2524DEC48F47386A1E6CE5561FCD200F736E4CCC848CF9D69404EE753B6CA35671A40AA2B667270FF670DCE5AF0E70EDE870D540FE22DCF51857EC30BD19ADB90CC68E6E51F3AB68DE8785CF510E7F3A5A039709DF63B801DC3323251351376715F8095ACF170629954B96795175B24E1C258AAB6CC89CED08AD7F756DEEE47A8D0D840E9B431461563DB4EED9560FC38258423E965E31E14D6074C9346404A6ADEF162D1C91432E5F83F97BE838879301613ED7190B2364158338F84A912C522F3D9E643BB90D65727628D26C8694BB2E1F35A45A4C4DC4F6974F9B8371DEDB8D4567370FB91A3AB7744D87321D2A37E808A0AF39B13AEC4593BC12BDB3FFFB32E69644B7CAB6860EA783BCDCFF142775F8C724B9F3E28C6686F9EE8422B03DBE8FE038717EE84BA5A8636DBC22FC29FBF6D07DF598B4641D4EEEE179160AC230A6A201F4127333E15975099212DA36524881CE7A2BFDEB0A69944804A6406D160D57942E851CD23F2445BCD remain = 1022 -max = 1023 \ No newline at end of file +max = 1023 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp index 8cb2fae6cf..2dbce6b683 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_10_512.rsp @@ -1,5 +1,3 @@ -# XMSS-SHAKE_10_512 - pk = 0000000A28C42CBBFDE2F32EC67C1630DF460F62D15643A6B5FD3A53D78B5A0011F6621D645A874D43300F9F334AB1D6DB08EEE382C34931E9EBEDF37ADAA8A57A37AA404D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE sk = 0000000A00000000061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94A4E3B7DCC104A05BB089D338BF55C72CAB375389A94BB920BD5D6DC9E7F2EC6FDE028B6F5724BB039F3652AD98DF8CE6C97013210B84BBE81388C3D141D61957C28C42CBBFDE2F32EC67C1630DF460F62D15643A6B5FD3A53D78B5A0011F6621D645A874D43300F9F334AB1D6DB08EEE382C34931E9EBEDF37ADAA8A57A37AA404D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002AFCF3BD5578FC5A469B5EE30687A6686B9CF04E9AA88815B89EE6F2D170BF84B0BF845A75B2C303B3968643511D4AB568552F4FF6C0243725F291341AAF654E72DD805C798FCD5214B14616E7AC9F3A4EA6C211B319FC9009536A1772156E62E666788121874F472FA5CAB32BA174FD0B2218F50A3BE7BDF448263F84CE6184306BDB40D6AC6EEEB7A009144D47CFE5121C5F44044D10B0776B575F883AA5CD63B5A577409851707816E4CBFBB13B047D3902D0C7916E4C9598BDADB732E82166F10149695106C8A9F3C0D2CF4349B59CC5A66177FC51A7B1098F6D30FFD8A5D016AD38097C062E0DA6BA3EB4C8FF851503B97E7A276E026DC8D92C68F979D53F9157695FC63A97A9F58D8F92140217D196A9778CD52A9074348743BCCD068B5DF2D5B76943651822D37F217E71EA6763CED121444AA3570A5880DCF44CE21FF035E8EA8107430E6116C10485E4DC7792D04A9B9717932D621B572F42221F1BAC60D3B65D93007913BB100E8658968B0CA77C533F20B9396BE2A7DB9B233028465E54648E3329BA2820ACF6CF00D46BA0CFD045C20C6BA992AEE34F57E9C84ACA1E95C45E9EC6D0BF500A7F7E6626D5777DC6AEDB370A4B1EB82BF4CD0F63DED9A4CCA567FCACDA440EC29CC67A926059152AD7BDB3F3EB06813BFDD8314C365E490C41C6FD4A6173A13F4C4A4E517037315D0EF14428275919CC61AD393BE23333F7D8A93C59DF7FBD4DFA8235AFE88803BDD881CB8E591A721E917CE44103EE38CD499655B666AC3536A1DE850F3FCA9C393454D9BD6F0C75B11822FF23EB22DBA69B08D3F4E92B8ECFE9BE9432A8B445A5BEE8757C7C53DD96FB2058A5370EFC4368FD6B5FC124FA0B9366074719377A0C533415161E29C71D5AA85356B90000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000016A30B3920D43D47945F47566B618719C38844032986568606F2DCFBD7104EEAC5436CCD86E9677E05985FA63C1B6D3E642D0F145B3FF637B96F2AFBEADED75F30100000000000197C186BD25DEEE5DC2CE5B760508549B1EFB2F3E0A34047232BDCCA39B144EAE820DB1F2D3C3159D012D7CAD7AAB1C44E15F53F4B1166E23DB8AA23ADA9E23AE02000000000001C5A2B2230C54CCBDFB5F42AD8805628B6B3D4723AB84E514035694195F2FB7E716F21EE8845170F30D1BEF79ED4468F2A45A72853F2D8F601973595098010E1D03000000000001C9E730A265A6F2DDC4B0F420CEC9C7AC976ADE4FDD5CEA3B6D5445AA2562772F76635C514BC81DA00E36681EDFEAFEBF29B1C3078AFEBAE3956D74AAF351E35904000000000001B661B82380E38D5CC77679867BB8FC1C94E77006AD05DE9576A7BD210641D25D011A056637775E72395B7643018E0BA023747219D875DBA848A58E0F9D7FD2DA050000000000019F3A31924919E8711F88BC45477356D330ACF65BDA612F6AC681F64C24FD70A6AF08B3FBB6136E4AF05B38A9205ACA4A2773D100FF79057CE6EF6C3F82AA9DEA06000000000001EDF9A31569FF07104E7B2FDF78D2CFC2FB28903D720F4D2ED95AB35DEB5EE579384ABCDC10CCE008B5BF753154B78207E452D4AF2B5646C42B89EBDDFA02570107000000000001BA911C4438781B45414444B18E3EEB1F0E57D33FB8F1BFB5DF1DC85D88A29371496D214B1042FADF9F17DFAC6215231DECB7D4ED1ADE6272BA7933403D3BADA608000000000001D85DF2FBED8348BA8E34D08202B5F944A00F91F1CC1F50C50D2460DFF1CFF490D84B84A1FDCA7A5E1760FF2E3A392D3F4ABB78116DDA6CAD29E694F9A4691E3B090000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 @@ -11,4 +9,4 @@ msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9092 smremain = 1022 -max = 1023 \ No newline at end of file +max = 1023 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp index 0726254105..c63503507e 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_256.rsp @@ -1,5 +1,3 @@ -# XMSS-SHAKE_16_256 - pk = 000000088B4832442313757CA73F5832B981BBB6B72FFD8A75EADB03605950D69CDC5FBA04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 2692 sm = 000000003017CF6CDBA4AF7D6CA495B9872967AFAB62AB87100AA92CFBD66591BEE188E6FE5428C1B38A2155B8EF1FB9DE8440D993A1F197229DF83843A1615CACF924D481D1478868BB902124AF51010672C7478B1AA93977097EE47375B6A5BD3ADCDB13077F648B8C7435CE755907418C55379857F06E2F7A61A232B67C86AC1352B9854E31EDDBFAFFD3992A2FF8D8B758452896E7B2D56A89B09055C2684A6FBCD2868149F65E73EF30210B36E03DCD6257185F671F78904B3F11EC67EAF994D1B9810B03806BA5E0F9C9F764CF3EFC1772C1624A7C8D63A6295339488C2FDD9CBC4D52F94BD09075E359134DCC1745B0B9A12095AC493DBCA32FAB2980588C131B31246F16CC261A56C9F1903B0B4498B849B4598E5F8C73A6A1521F7D75628427F95374C29BB0585B22A7421D7A01B07092AF4E6C0D03F0445A64110B93F814194F4EE29447A8424917FD3EBBE24F5128280697659EBE4569087D96AD8F0AC7B67D272DEFC429B7BE6E9F76ED4A60B42FF5F0CF9EC09791851E1E7D263EF374CFBBA724670050F31569813630709AB6A4E35D66684AB154CF647FD64DA3B2E5530B4ECA5ABD9666549F8079173D267642D94F9660C76FF6D5378E015B792B13BB773CEEF4C7B3AD10BC12FDEA7DCC1891BCBDC9CD83ABD7DE6012ED3F07F1CE676F9E659D7C7663EB4B63FABA90515F2700301544682570E6B3EF16C59082F949F388D9FDC43455CABDCD4AD51E010674F23D753CB00A62685205FAD8CB4BE5D5174BC2039A9D72F3887749FF061BAB898B75511280A6E9134C3379B1609BADF260A2F78C4C9863965A97BF5DA405B992E011375D9834FD1AA73799E97F4F701E1453388E6A2E01080743D9A836F20FC93663C7E4591849A616ACE98011E52BFD3C156F233100992998ABCDFE26F36A0A4191998EBFE07E2B4D7D9787DFB44F858B43CCAA440867C0C6B6C74E32368C7884B8860E5AD1B518F322EE72CEC31F5253891BCA1195D4B5CD305ACB28479FB1BE4550E16F85D9285EF98B1F325D755F2D43E285EFDDA4F0842A1727C2EAA123789C359DF0C696349055E452E7F27CC668814754D5F91CBC9BB551E5663948A692D12D054D90840580C1D66423931FC5A4E6B4D0E8F6B2040D9CCF85DA7C9522BD571EFF09D5B1561225886FFCD6B788B60A2740339A04956DC654E108016C69006BDE4C2BEBB3A3DE40FA45F5DD19D0E3F2D9487FC2287870964D9F328563E36677622B3E074A980DAB585FF96FD09B95A6065CB8246841079ABE344B55A1F2D367FB3CF72F1391462C45BCAA89EF4D623FDA3904F18B7739B10C9EAC71DCDBA418DF1E5DA13E1BA5A122000BD71E0C2060ECF72407AFDEF3BA54EC75F425B4AB32F564854AD5C39A2A1D9D06FBD74DA44B83F449072FE1E7F6A82B308A253FA60B722B0B949204E5931BCED17F2B1C5EF51D9A6F477F108EFC9DCC7F139617993D5362ED390A73955749EF1FF0825D95C689192BB35FCFF90B87519113376A44AE4BA207EE9AF82719AA72ABF543ED04221A9176561983CE0FEAE6C491381F6E112192272AD8C82CE4037BD968C1F4E7B693C41F717FEC260DC06486D04822DCD3BA1CEB89F12DFFE3534B51B107E73383B4DF8B367F2E123BC873626A8EF6142C485C932E27BFE6024722F5825CA4C84A6F9F49B0EDFFDCE1DBC2AE84F1FD849E3E1D049EDA6A5EEFC0E5EFB68199A9913158FD2FD0A1EB0C039623FA42CFCF6A0AE68C6B65B60D79C9987EBDDB191E271CD9632AA1EEDD35A437D3405B89CEED11D4871C6C1F9A9C33B15AC647845C27F1B5233F2C78E908DC396F097744D841C8BF1BD732255BC62E601A9E50DABEE504FAFD020889BD3E0335DF683D946334C147F31FEC61975DC21582CCD00E77AE099812A621537438D6AF2F1A64E98F801173C97B9EF4923BE9B179A94D20D64CDB799F04FA406789F34D5A04CE3FEA635DE803FA73EBE3439BA0238086F39970601DEBD0E7DEFA07933EAD357C796B76DB6E6F557222BBC9AE2F4840F608E59075A190F8A156CA92CC81F4F69369EF086D61EE895B7F12C300DA076E09BD43CBCAD6F5857BAAE18071F291C3D742C9FF3FC54A51D1CB8061D5A0ED4358E8AB70079EFEAEB3947276F612A4376555002FA7AC9B7EC9778FC3B4A6EE1025D4C73A8CABF27E1CC7B33448B947CD339BDFFC9F377952D6249911F099F535E6FFD1BECF740CC96822076C1C173E32EB8A2A1D282D8BFEB277B9BAD5906F6C8ECDFF4C980A4F708C8D83847A125F12D726A803911B7669FB587EDDAA13FAA92D1745DAE5494E4DBE639AA2B03412ED97FE1C1EFC391CBE070881822B2626AA473C605E9D16D8A4A44644D551C332240FC9CE25D8A9484A9F0A65B6DF11CE50A984285D2B583BC4ABD4A26907E5613CDD84BBC4B8A6FE153F5D50CDC700FA96C40B8F33F4F73F6260DAAB08BF5A02A2F664E62BC3BFAA6A4800EEE8423D93ADB908B28E1F1DAD9CCF410A1A717F2FAFAAD47C60AA96B100947EB6EDEBAA92FBE4C0AD2407EB3D645DB8FA4EEC242E907FFA8E6D5771F18739E44FF6E70221FA212F5755BD9574163E60412DC2DCC34F449167D76C769FC5D9D4AEA104824F0872C46D1E4C35F337D007F2EB9B832EFD426982739F74A14BEE901570011D4FB7F43B5069C64556087A248D8C09CFA5E34600B3BD6194649DCB093B3DF86DEEB4FB42EF65CB5CC3C3FDC89852BD57F34D20B9EB617AF516E372BBC4154AA94744BF2835AD2E71334279B019756795B96FBE4D57FFFBBD3D6E4E5786234FDC6E5768AF9329225E1BCB7F680B66729BEAAB9C5AC5A2120C8D427E349F364F595BC1D72874466844FCD43252D480576898E9037633A8424577B3DCFFA3AECFE14317B60F84E450247EEFBD497F4F79FBFD48BD99EA0CAB725A1A4F1CB10B461FA0AE6F5FB991456CDDF24C6BFC89FB8A8757F940DF8DE473602610F33F655872E11109EA6B7E3BC14749E7C7FA2F28480EFC0784B9C5FEEE217946EF2D55F5FD2902B6E080431350D4BB60DFB6DC98FF57CE274ECF76AB7C2E9A87D99EF54D9B8A5B4481F0E70EDE870D540FE22DCF51857EC30BD19ADB90CC68E6E51F3AB68DE8785CF510E7F3A5A039709DF63B801DC3323251351376715F8095ACF170629954B96795175B24E1C258AAB6CC89CED08AD7F756DEEE47A8D0D840E9B431461563DB4EED9560FC38258423E965E31E14D6074C9346404A6ADEF162D1C91432E5F83F97BE838879301613ED7190B2364158338F84A912C522F3D9E643BB90D65727628D26C8694BB2E1F35A45A4C4DC4F6974F9B8371DEDB8D4567370FB91A3AB7744D87321D2A37E808A0AF39B13AEC4593BC12BDB3FFFB32E69644B7CAB6860EA783BCDCFF142775F8C724B9F3E28C6686F9EE8422B03DBE8FE038717EE84BA5A8636DBC22FC29FBF6D07DF598B4641D4EEEE179160AC230A6A201F4127333E15975099212DA36524881CE7A2BFDEB0A69944804A6406D160D57942E851CD23F2445BCD38CE6D0281ABBF9C140B2614526F684254F54E121E3B0291C3926AFDD98DFD10D8959C450F726A8334D3B3C5FF6D5AEE8D27458A4D78040B7F5555AB46E6662EB1D0908805D2B7EAA686FCB7069283CDD505069A7AD1B5BE804548C41A4E273F58EE1E8BA7E951B2F766E1F11C03881B4CDB9A520BC04EDF8E8A9BCE919575914CA22623741D57FF97B036BC9B09C7D5162D983DD5B4D519A869CFFF53F37FD8F550B1F006A3856ECA2DA3804EBC5AB1CD68D64FD4D11747C17C6D3206CCA24C remain = 65534 -max = 65535 \ No newline at end of file +max = 65535 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp index b3718c5f09..4385540527 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_16_512.rsp @@ -1,5 +1,3 @@ -# XMSS-SHAKE_16_512 - pk = 0000000BE63E1958AFF9CEC5CC26706D9B33FE461CF17B8FCF54E1B7394AA3E0B51BDCC89B4D854731B25D63C27019AF9AD43E63969A575E7C181079BC1207320A6658BC4D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE sk =  @@ -11,4 +9,4 @@ msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9476 smremain = 65534 -max = 65535 \ No newline at end of file +max = 65535 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp index a6484c2776..ff52ff9d9a 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_256.rsp @@ -1,5 +1,3 @@ -# XMSS-SHAKE_20_256 - pk = 000000091EA51EAA13ABDB2B1A37732B47125C74B4F2D624F9145E295C560DF4FFD6AEB404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 2820 sm = 000000003017CF6CDBA4AF7D6CA495B9872967AFAB62AB87100AA92CFBD66591BEE188E6429AAFF05B285E06B6EDBBA11503F92E15E17C582FDE9CCF8FB0E5BDB90FCABDB107005759C1AD991FBACA5F12BE25CCF5A487CDCB35D2FA0415A48AED18AECFE49E32AF457F664D605D54CF42246B21C1B822727BF0869E79C2479B3CF7EF92B2D92D18C1A9520CC21A0A17908D121E1EA426738CFE364AB99172E83544AD0FEC48EF86066353B471BDF03374C02568B2ACA5D9787A3547B32EAD02723B86085852D62225D7554249CC1FE71B8CA3B01240808B769DC4154DB886DB5C1EF5B5CD1E9A5781AF0B8028EC1D1E1E82D6AD6AA45A6D07B244962F9CC5A5A14674087C37F5C128471A780F7E20C5F04EE713489718EA13D2DD776EC37B91AEC089A1CB652A4CA27DF77D2B59BDD5DB0D4657882E1C3D50D022B673C7E4C1DC6AA9D0961BA4254B0FBC7E8A37B1D610C74A511E52A8A50F4943217493F7EA4C92CF25FC55C8986FBEA375F95A3E2EEA5595322FC1079823D49731A6713DD270B3AD1DFA54D60EC4408C15DA7FC4B5BEC5120F1966279A400F0AF374CF6ACD439AB0307168092C3A8F03F4024169DBE782051501D6CFD53F3344F583668D2F25276D0F93B0896752FCAE3699AF03C2E8C8725BE6073251317D1EEFB497336A32C511CA3D91BA9C3CF4528D139148FFFBE43536D085EF62CA9EDD4A56A4127C96366A690A32F4705C98818ACAC9A62F3421985687FC5107199B035FFCFFF5103D7B169AAFA3F7873198C245BEA6FB442A5EA0710814787B60EF727174C29BA2DE46E283BDECDC6DB095544CECE9268232729556E6339B9B8A2F22FEEA16F32E6FBA5577B4CA665BE58EE459BDEA5C1765D63045C230ACB40DEE76D8FFD25275D33730D608B41AD8FCF6149DC8C5602305056A1E00EFD26E79C204239C69DEC416E8AAA98B43CCAA440867C0C6B6C74E32368C7884B8860E5AD1B518F322EE72CEC31F52CB0B5D16C7813F05F9578CECC287D621864B54E54836F3315642DAF8E0F3A61C68EFB4FCE7D560363BC9F3A5A0086D87169AAB81B9736674E598CB301F84E7F03D94EC6741B481B978440F93D3B0A5426121B516C7A4D5DDF078995BD22D0970A4E6B4D0E8F6B2040D9CCF85DA7C9522BD571EFF09D5B1561225886FFCD6B7884FFEACF7644B9DF10F6FF9F1408EB28E5F212BFB503C2F8FC7981663C50B7739E3F2D9487FC2287870964D9F328563E36677622B3E074A980DAB585FF96FD09B7A843E4B2BA51E42D964AF28BDFA113E2853EE1051EF044C34EE020DBC7172C1A1C5F71AF0F2B8A6A8F9C2E4C8BBEA834A94F34114CEE3ED19E514449946DAEF69516854BC502BB54F46086F5FA4EDAD92893384F67C4D1C11E826B5F1E910DDA7ADFB66C00FA7BEC717F2419E026C3492CE4DE1B568A4DBC25C6C592641852AD2D562A9CEF92CDA1EE295DAD0074EA1C01DC90A6831D3499FA6DC8D6B5D737C95C689192BB35FCFF90B87519113376A44AE4BA207EE9AF82719AA72ABF543ED8EC30C89BEF5ADF1723437F91863B0B6CBD2373F9638D74D6EF309D1B787311CA839339BB9AB60CB5B1F922D6C430FDF84A3A8A81B7FC0282C404FAD61A9AEC0E974476860D49A2BA734DC223B46D2C25797CC55E16A37D56B5021A9413F7F65DE41A840258A1A492267B8EA54C51DCCC1A4572023546321CE81E7F51B4DB3836B1E2CC30E6E7DC45BFDA37C100EB88E44069492CECC82E9E4EC8C7C2C9F85B0BB6B57713F156B0F0B1F2D50589DEF2CDB05E5790D34CECE7C22212AE889BAD4A39F127D0F88709DF1FA2D58AB09D249014EAD040C0934787438A1A5C7C9520F36D18AFC8DAB6866EA201DB358B45AA0CDCA0959B4F0BF7ADDCDB0CF61ECC7FBCEDD43D7F85EB9C9B771CB8EEA797E79F369BCE45087374A20BDC6FEB45871AF744BD1C6D91F72509602FDCA13C0F43D8C9C0EC8141AC267D940537B86335E609D558CB2D1DA9EE891F338DFF31CD3748B61CDE572EC77997A2BCD420E58ECBDAAFD9BDBA4BD815108B240DEA39524C501079A2815C04018C444AAC8AEC51B9207412600285537487F1C65E5E53B472D0836698B80E10F1F06EA466C78F7065088E07801C44DC68A93ECA841BFA02881FA3003878D8EC6E3CA1CC6590607558CE59C93E72BCDE6D87961B3185CA3ECD7D6A913D9F86EDB5017F5A1F28FBFF054D1BECF740CC96822076C1C173E32EB8A2A1D282D8BFEB277B9BAD5906F6C8ECDA3BEEE3253FB58D7B532C7885549593BF2984B3D6FCC2E70105FC34A1CD9A85B9B2A48FA806BB1FE35675ECD1BA10FD998068C0797A6874B02F3759F9DCD3B771041F74F76D99E4FF70A47B904C80118090DA4220AC717C36C588FD89EFC473084AB49FC4849D497AAEC8FA2A8C8DB244001F4348AE47425932E61A64C79846C4214ED25F04D7E07E38C51FF1B1B3BCF0D8D38B31CD3B8A69210C1C3E5A92FB8CD5BB3A57E03D5D9672A86589501558211537988D9B6FD2B248B4C6B39CAD3A41052A74A72C2599419F61A78459B45C7976E43E96BDC2EBA3AE45FFFC8766D70EF340F6C1BE587DFAED8EA010542245C17684A9944E53BB33C776507D940D6990B152898366FC0906F835ED4B9FE9A776EC249F3B7A73C8ADD42D2B17B5893634E68CEE35D6BFFC32B9C588DE07ADEC32475AE5AF1F29EDC5E4EBB848C5DF4EEFB01A405403F4ADDD2097729FDE708EB369DB19FAFC35528A11EFF706445E69FC3F47DDF27092C44B520438B711428B717CF2D19F31D996047E852CC36403C86BD4C2485B886668646E164CD67132C6D187490F3B18BD3A339FD5FB07DFA9F1F74466844FCD43252D480576898E9037633A8424577B3DCFFA3AECFE14317B60F573A7CB1C938876CA58C9DEE64B7EDCB6BACA85C9E20AFAD6B68054B862DDFCEB991456CDDF24C6BFC89FB8A8757F940DF8DE473602610F33F655872E11109EA6E323ED6E8A520C761F371CF760445A3E865E4B2524DEC48F47386A1E6CE55611B40AFF393D6177502756D15DB5232BCD58ABDB633EFEA7390FF8BEA443BFB32F0E70EDE870D540FE22DCF51857EC30BD19ADB90CC68E6E51F3AB68DE8785CF510E7F3A5A039709DF63B801DC3323251351376715F8095ACF170629954B96795175B24E1C258AAB6CC89CED08AD7F756DEEE47A8D0D840E9B431461563DB4EED9560FC38258423E965E31E14D6074C9346404A6ADEF162D1C91432E5F83F97BE838879301613ED7190B2364158338F84A912C522F3D9E643BB90D65727628D26C8694BB2E1F35A45A4C4DC4F6974F9B8371DEDB8D4567370FB91A3AB7744D87321D2A37E808A0AF39B13AEC4593BC12BDB3FFFB32E69644B7CAB6860EA783BCDCFF142775F8C724B9F3E28C6686F9EE8422B03DBE8FE038717EE84BA5A8636DBC22FC29FBF6D07DF598B4641D4EEEE179160AC230A6A201F4127333E15975099212DA36524881CE7A2BFDEB0A69944804A6406D160D57942E851CD23F2445BCD38CE6D0281ABBF9C140B2614526F684254F54E121E3B0291C3926AFDD98DFD10D8959C450F726A8334D3B3C5FF6D5AEE8D27458A4D78040B7F5555AB46E6662EB1D0908805D2B7EAA686FCB7069283CDD505069A7AD1B5BE804548C41A4E273F58EE1E8BA7E951B2F766E1F11C03881B4CDB9A520BC04EDF8E8A9BCE919575914CA22623741D57FF97B036BC9B09C7D5162D983DD5B4D519A869CFFF53F37FD8F550B1F006A3856ECA2DA3804EBC5AB1CD68D64FD4D11747C17C6D3206CCA24C7D176B37A7DC26214FBBF555DDEF8D970B6AA840AFCEE7B674EE05845118A6FB277ABEB1A792B61CA4D24646DBBFD623564F93B74C1277C1AE4CB326411850F0371D6A848ED0BBFB8B0BC3254398F513E630D075CDD277E0AE10D8D13EBDD0CC60AB0FFC61631C5D17989AD9DDF25BADAF0BB87FD0E32975EB673434812D58CC remain = 1048574 -max = 1048575 \ No newline at end of file +max = 1048575 diff --git a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp index d573423186..35c2aeb6a0 100644 --- a/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSS-SHAKE_20_512.rsp @@ -1,5 +1,3 @@ -# XMSS-SHAKE_20_512 - pk = 0000000C2A857867C4C12EC4296D971A38A242B9DAB9C173678C2BC776A662A1619B1B0149358B252995E4B17AD6593C1ABE2AEFE1D2A0E4FA52E24E73AFB0A4B61A3D544D3FB22591039B76774FDAF41CDB22A8B5C5A20F3BE5F9058E466D2A013C60E39DBA2EEB33B69D3A87F593F3D02EF134760D5BE6BD693833524E2A5B4AEA21BE skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9732 sm =  remain = 1048574 -max = 1048575 \ No newline at end of file +max = 1048575 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp index 4a3ba78be4..a07767dc99 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-2_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHA2_20/2_256 - pk = 00000001049D5FE86EA348F4C6D28583AA3F9F86C36156FD23AAE68BD09B104163E2E2EB04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 4963 sm =  remain = 1048574 -max = 1048575 \ No newline at end of file +max = 1048575 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp index a5a2cd2a31..4bbff39fe9 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_20-4_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHA2_20/4_256 - pk = 00000002CFA7F813F78C9797C0F6AD44C84059350BE2D1EE249919C6E1F305D3C0E7024404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9251 smremain = 1048574 -max = 1048575 \ No newline at end of file +max = 1048575 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp index 8fba48c4f8..9b66f0f23c 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-2_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHA2_40/2_256 - pk = 000000030D4B3BE22EE30889C2EA6A12AD6FCC92452E1B92832A599FB4CE52C86E8C429504562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 5605 smremain = 1099511627774 -max = 1099511627775 \ No newline at end of file +max = 1099511627775 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp index ced74682a5..d17a127d5f 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-4_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHA2_40/4_256 - pk = 0000000463FD804E9E56657035D9C1FC5A291B8586E41D1E5E5560AA76B30C26198181A604562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9893 sm =  remain = 1099511627774 -max = 1099511627775 \ No newline at end of file +max = 1099511627775 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp index 395864aeff..fac5a0f156 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_40-8_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHA2_40/8_256 - pk = 00000005AF6E11950B411D09B02C47AA513FC66675E96AA47C3B284279F9543FA23A226804562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 sk = 000000050000000000061550234D158C5EC95595FE04EF7A25767F2E24CC2BC479D09D86DC9ABCFDE7056A8C266F9EF97ED08541DBD2E1FFA19810F5392D076276EF41277C3AB6E94AAF6E11950B411D09B02C47AA513FC66675E96AA47C3B284279F9543FA23A226804562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F9400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000C22F2E9109F9BB35426BDDB4A69EB8F45CD5B226F92E8026F1E62DE1DE435A4FC0CAEDA91C38A88F0037BDB296CD7B07FF040B1E08F02711E946B307A5A38487F53070985B8E28BE6CCE809F34100F0CA780996CD38E91BA7773BB632D0BE7978F3AF3A92B961BD3A8759590726D6C1811F9E0BCA87377334E7C1F12FE37401CA0200823938C816ED98981521470F7F2CCDD69D85E7530EBF39E3A592B1C09BC0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001BABEE5DDEAD48C384DD12B603E7DC662BECD05787E659B7A4F42C219604631E9010000000000014FAF3A985C827CC08F0D3F4B0931AAA529DEA84CAF9C6EE9906E2A940BA1E327020000000000010F8E4B4F87A6782C5EEC46137A8A8C6E86E11F46C241FCFD839218BB0305105203000000000001D49255A7D48890564ACBEE0BD3619157B47C374DEEC424D7430636AD855D145C0400000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000794155E7245F6CAE1088C20619158F78F7B9554B43C2872DC68AAB415F3065688612EC88D83577278C8A7B64334993F80BE7EDCBF5CEF5B00A2FC5B0CA04564DB35EE027BFB28DA1A7EEE4E72E366A22F6B50780F70355DA825FC2101BF7A057E5D26BF4216269A4C807F6B2055367D88910FBC65533CD0EDE915232B023D039AE21A53217DCF8398A5B70C3F2F1820F5CE459DFBFE7C3C9387F93D488D000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001679E9E3F9DCC784BF6B061A699870789E78B2AEE2C1D9F082DD7FD241A53647F010000000000013A62723E901C4C50A6D05799DAE9C4F804BD9F01AA226EDC129C77E962D909B502000000000001F1F2182334ED10684EF22D59127FD103A216EF4CB169A4615C1013B2D00D143A03000000000001916D09F583779651E6B192ADEB350B07714F00E125E51013C6A4F41EAB50C2E704000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002F0EF9A0EB57779C157657D9A1BCCF0DE21B60DCA9EA29FB5D6D36C7973FE0D8FB8CFFB812B2C3080BF0F0DDCD99BF9832A3161F14FEB8863777E8EE65B8F88B2262991CEA2227E360DE1F384A9E4C722302C42F9ED9CE1ECB1225BC3180B4CA27552F940E6D3AC102CB0EDF13951506103BF790CA9923937C7AD9661B13617CADDD3F1D81944A87AEC9AC06202EC18EF736DC325C55E21D33A313DACEF54961000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000113CD47F2466A56323209409FD7FCF7485A71CD8CE96D61298A20473D9ACBF99C010000000000019AB3950B30D3E7877159B364A25B214B41B8AA32E293E2DDD44AEB7DFC560A82020000000000019C359D104347B69607EB28A02E6924C24BD2A26DE4CFFF3FF98E48688E291E58030000000000011EC9B78F3B1189A5482238BCF700922D642E45D07E7EA10833E31A4CBC3CA08F0400000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000C96C6E10238113B17AE11147C1BF46D1D0E16BF333B1A12BA3D2C34F69CE34186FADFEEB02418D227AB09DD8F5B50664B97BC1ECB70C28C79FDC3B16FCE85D63D1A59107BB62594C2FD67438D6448FDC8005FB3BD2BE1E7CBBB35FC5F1E6B1284641E1B520AFC98F158BFEE2D20A6B03541AB11A19B0D02D9F628C4A00C25A03457C2A17D3B1E11A8AAFB4BC26ECFB423BEAE0F68EE89AB2C7FEDEA2FCAC00A300000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000019C1A7BFD8300283215BA57DB5CDD95EDCBD04E1C41419317BC2069C2AAAE22130100000000000143ED646E32FC21554D8DAD350C5732270CC220F7E264ECB5B7A8E8A4586D0CD002000000000001762D040EECA13E137753604D099809D946063368BFE1C7CF0E6549FCA746F7C6030000000000015FB7406F1B25A2B4A6A1666269772EB08D6FE78D8A8395C56AD80FE6924DF082040000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000044E3C9C3413B4497ABA623AFE3257572D979FD7234C04292B8EC507187752446AD11D10DE925035D368AF83D202AF6979123C7F3B7FCB8D83812728A890B5C09B482529FFC0737FB59C35B552AD7C5820E27332D2E44F2A31ED972E2E5C834FCC652204BB401557D6FEC656BD9F63B9226056E2D025988ED1312A2A767D418F1342BE489B463AA4BE823D471648D9893364758DACBAA63BED8B3D8D4DE1E4A7600000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000017F7DF0085A4DAADCB03AB4E8241B0E6DC05E727E817C3B6FA27F05AE1FA2DE1601000000000001BCF2F650C31EFD6F2F09775A3B4F87BBB33AD0D51537DAF37E0D1C1AE8BE8DC00200000000000174F4FE7914F390776AF328164E738CA8EB0751EF9E535BB1B0E80B05762E683C03000000000001241535B940156367A4ABD922871FB10B37235B67CA38CD8B2B02AA8064C5CAC60400000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D4FF586D6CC300F09F878FF5FDD7E7BFD0AC3AA2AEC0C223DE23D190C6F67AFF7C00001F7DE39C907235BF8D5EC16A34AD2D2E6DDC419F5B24EACE1A17BEF5CC52AAA05F04D5AA8BB018210354282E98DABB918100165E7D962A6F396F22753B1FB928AE3576A91CE62216E9E6214ABFF91FCA2E6E77611AD13F70CC87E67A1E6D886120CD2C2404E0312A57635D1C2524C97EC0BDD9DE011D158F8FCA7AD1A2000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000186A69EB284CFC56C72C2C83351D5CCDBEC831992175BC2D2D91B3F9378E0DE9E010000000000010A318F954C197DF2DF39A85C4B322E7EB1B16B0B4EB8C8A492F4F3B904C47E7602000000000001A9204F8E84112663772797AF87ED34C559ED4D6D37E634EFACE6A18C700CD53A03000000000001D2E20083FA11E157A2E5B72C9A986D3F47348E54C1935F48A86F7A9D78B2BE600400000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000A6442DC6DD49889C3DA3AAF0FB310C3AD990480EF12059DD23AE881D5A72603F50C7C61626AB2E0BF9C8C198CB0F637EF72954E04DF5956355147B5073EEF3848CE65EBA73E67955A1CFF187CCA758372FB67823E230B05EAA9982488E8D22F6DA1415A731BD0A2B036F858FE16FB4349149B507D9DF770B9F3D3B45ED752EE888F40FEE65C4F3EC6897906303A19863DD968C666AC1980F26D8B574D5A16C95000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100132C90901F97161C5614019A534B035942B26ADCEF40AB97BE258B03C87585010000000000012BB35E6F2C4AE0A3430CE207629C011B30E4C6F5D6BDFF2AB750EA0C69BE95C1020000000000019CAFA71D2E43D02FBB0C55294A6CD0AF3AF0816F6E6D1F4022AEFD413DBE8C1E03000000000001943191FF197E71722D961AF04F9570BBEC438A6D22058F1018F6C61F3CED67E50400000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000290F4FE6675D4A1FBE8A93A91C6B09B1456828554CD0CDA039569E2C08430C3481E2970BA760DA29C31944AF18085694530E8A952B54516062CD9528A95D0772323B4B8E02C7DCBD71FFD2236E772268E25F6D4C622F07F5D437275B2FEBECE7605967771BFA2007FECA33154FB46A3B788E9E7702F38BCDF175EFE4611B61147D89195BE90840FB1E365A76840BD9B40C21949F2D41205A491C019B7F49139C00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000012A13FF51186CBFE9467BCAB51417E5129671EFD5D0D686D09E2C5BB683FD45450100000000000184D0629348E528473585F873A1929F01BB41F19090B770D155E497E4AFF30A990200000000000163EB4A114558605E9DDBDA75D10B78F28322197D1DF7FB4214438DA12328F8F203000000000001B86361D142F7F14ADAF4EC3E307CA82B6106FBDE3777E656781187D3558E3E1F04000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000009D550F851D023315BE35A69C83D099341F6BA69B6A40E224DC554A3489D33729C9EC8196BD665514030C26AAEF80CD6E1BB9EC739BAA2B8E4A63EE691AD2BFBABDDEE2B13CFFEEAB7C25273CAD45409B5270678CB1535AB800679906CE77189DCFE05BBF92FB5E31F184CECF3C427437958F695917E343ACF46DA2B9D988CFE316313FA9FAAD49EDB72B007A7F3D6FC55A88E6BA784FEBE9737803AF05B4801CE0C723C0D15CD8E7CA8E237D4A1C0BB1413D369FC3F21F69205D428069EABE626B971A2B5698ED05BAE54218300BE8C4BC9A52EE5FB296BAF2A9AA42F3C865DCC1DDA69969F085C91D3CC5934567476EB70461B942059AC0F83BA10DFE783F5FB405F159563419B3F5699179D6F33AD05E840EC9227C592E361A49E31D99445437D77E70EF7E12A80A3DC73CE284F2BAAE3816C351BAF037F5FBDF29A970BB3844833CA9CC7907865878A01BCAE7DB72BA4F7701F20523E0E98B27AF08AA747B57DB1DAAA1B616DE469C7FC83CAA1DA1D6BA6F0C2B0F7F2CB7A4F58FBF7FFEC292AAA7FC3B87E797DCA067ED7672BA9B4CBC27FE9AAEEA63C8569A567129990E1E12A8D23039A877F7FA3EA9B9359A842A19E33CDBF284AF95FAE2A2DDEB80030A8245A7E51131D27EAE94B6C38A8C4818CA7EAE0A1C0841E7AACDDF68A4C4491EF97D5F3F6AD8CC47D2489DF1FF96B7DD444D31DD2FFFDC69C9ED7F750526B3CD81EDEEE2CBBFC0BCEBE875DBB644B3828795D2B81DFE37E0E4E68F9A798E09588F62EA602BA30FA9ECF3462711612B3E1AC0CDC4C11C85ABB04AE596674368D1D405B742EE812FB88947D9F5DE52083777E54C2F0A1F605027BCA5A12BDBF9CDF900B1632F65393977D69F5FD1FDEF8E6A2101281D4997C7E4F821A421318ECCE515F732608A96D4E557ACCA60F144A212276CD52FAC0F12C39F7F45565346B6EE409558FF37D5C50280099C9D75B688C7D873EA7D07EC6C9305AB367ABC2FEAFF9200CAD14D71DE9E1F1DFFC4F15FD0908C6687F585D9721AA773BDECA4C7DBDA2D8275C59A2E90EE07ED6734A09566174D695356166041C646F18180DFC5ACCBA61F1672213C3CA6933A5ED65898AEB4BAF534751900D2CF25A7A94C273533B8694EEFB366F4B3E6D4DBE7FF5FC70EF5341217906FCEC863502598936A4A0D7DD4267B1C0C6E8175CFB3B9B6BA86CF3094D4677BD57712235CA8395A6914063B4E2849AFA406B7EC6E3AE39B343EE39348D2D29A0C2319BB34655A53E1A816CD5FBAD3A3796FEF2C7B67BE4507438E5AEB603B1A0796293A274A3F3D63C7C1F14297987085EC271F06E8DC986CE41DDA37ADBB39613E6790644A669594AF10B5D7C2DCDA7190B03F77E69D79A143E9B7D8B42E18E56D1D191DE05D58DC29F438BF7F77A856295E0D55A3AF7F55BEF0D7643D85B8892A69304AB1FECE1EA4C86ADE353F4AA57DE2220D13EAC9BC8FE02D625EBE3BF2761493F180F968DE438B34833D55E1761FBEDC88E644D7CA5F8D33E86EE25C65C2A6DA4F57D2B580FE8D6603D01C8308F95620A16B4B993AEC83DC9E71A16C2D22B89E7CF8290DB07425116F11D430A927D45FBAC134C59EA8E5907C35A59E0CF2FA548F9AA27A3530AEEC1D3E5B7DF7AA1564E1D8294F454E439B7F102074AA586FF5931827B7F7FBE6FFF1A2A91E8DD23131A7840BF7CDEA3E18E706A324AB688A5866B82EC18082D89DB83F78DB30D5CE6EF134BBCE7628AC017E6D6974B1D82E4227235AEC9862899B7A4E0E8B10A8AD0B19A54DE7ECA861D6AFA1D91C9CAC7B8D6AE536C458E176AE68697912D7EC853D514AD4EDE982FA89400CE895D3241E5610D0AFB17AEFE51FBB41E2DE044A00D84BE759242476BC0099DFE159F0CAF2187BB311DF2342A59C003778A56907F086C8DC9309D8E41703779C8E1141070708E02B9F987ACF3214A8E442B76121374DD243643D64283D01279A49154760E3567E46ACE89898BCD67842223D5B8CAB03DC13930BE7210FAB7FB2318BDCD92B642F6BF178BC30B4F959F5D8BE15F67C5AC4A4C81F1E3E707AADF0B4CD02982ED4E4E52A81EA2FCB60ACB5817849D53C2FFFBF7906E290BF76E505071913AE0361FDFCA4B279897C9DECF546FB0366D65C9F81A9B51402F3694F0B5DC600B7E4F084383B643AABC755E11DC4E5E06CA263A2E6D229726B08A66962C1AAFE0B85A896D3A21AB0E6C007F614D3C0A2E45486C2E457C2E6636BC1AFB76B2A7FA351FD88399098C64E379F99B64A3340473DD46C11564937DB9A28C4DE3745308433153B2BC6D5E0D515C7816B7C5CC8035F4FDDB37C9A09712BA1A8E1FB4E0D8B37F0BEABA9D1ACFF0116375D404211C3D3302D17DDD0390712E06CA05FB4BB2AF749D3439A5B30D3E9FF4731822AE6607BD96108BD229A4BDA5ACF50F7185BD1C0F56CC56D69C008077082C0869F237A6F19D73ADCF9844686E3C5583E7D8FFDA636E70E989B1742ACA4DCE98101BBAEDA8E852555033A46F8DF4E3DCA1B9A09E9F938E0C1E468C52F7DC695389C21D0F425B4DB554FD5BE1FDC2765B997FAB1F94D864DE1B4C8FB1323A8D90DC0CD7FA7363AB70728FDBF33C2325FF97C59ADC84C104E730C85CFBF72E5CE393330FF905F02DA9C591FAC66CBAF1FF1DABB3B199AC4A764EB5272D144DEFA2E32DCBE8CF7843CBDB9A67EAD7892ABCE9B25A6B91AF0B893846ADDDB6C26354D4D8B77B14FC2FA2D8D589237C4BAF80344C306439619E5A4DDD4630B558BC9B3581AB842BC8B630F232BD18D4BB10FFA1DD3805B18635F6A9A22CE0D470FAA2AB813662EF63C784628138499A1A3648CC877300401E61DA9A379FDB3FC6DD985CA26EE8093A24879BEF107C4D6A38017BE3AA5CCE124259C42519C6FEA1DA8EC1D45CE65C4DFD09532FDAF74F99152DDBF0AAA53806F2C4EB3A156771072191C21BC3190193111CD3BD0604EC5427C6D70B1BF21DB6E59ED636342BC417CD9F69B804EDB6359C9F8E347AD253370E065D500CAC64BFABE3E420E39C27D20CB93DA243BB3270F1EF2DE68AFB80842E8BE7C1FD48BF0F5622530CE84C1D30BC69EE1164CC602F2522FA39158D4D0D30ABE4FDE43213ABD6E4D65E62FBEC9AA1D485599FB7ADF5C2C97B90C82A1DCCD2C44ED66CCE79EFCEDCAD0CA1366FA51DD03DAC9BFC60B79719033B32247DDA9195233329F5AA36627FCEC5E42F078A9E3A5823FD097F6860AF7B8E224D3C5222A049D22E7B73CE6D9300530DF657C03A3914FD3BF1E82EF96AD7EA46373B0A4DD0F5655F22F754DCD35ADA89358DDAF6AFF78EEEF21010DBC6556C2C3A018E4DA1D612CC3EF237BC2B1E9E600D923E2CE04FA27CE8EE63B969F6079FF8551B8C06018E99D84669C059AE08081E3A1C7ABC19272D7FA3F2704CCF6E491AF93C7CBD4660410389D86BBA47BD5A0E996F788FB9CE600AD76485D265628019B57FC69631D5266E8E46913ED9142FEFAD87E26DE53ECDF43B352EAC14BF6DA899058228C9414E7323430F9357D6244E7165F5CA2FF2DC9899AA6D8C2B8DDE8E2C5FB7C6E02BF74F578823CFA2355F2FCA1F776C6A87943344A5E53BFA39559EF98C397423C75EB318EA9B5F375C17E7B46A8D592651E7D50E70233224592389C1EBD1EB66678AC42C2862A2C660BACD03BA4064EA38D34A7D44B32DB9E75ABC6B5025B504DEC60512A80F78876C54D36324C7143FEA85ECB9E66800E8F4004061EA7607EAB964DE3F9A273D2C7A4CECC1B4270ECFF87A254A139DEA1E0F0B0F6366C02A0A790D46EAC94866A82DD8349F7B23EC43C839B4B963BC694E34AD8F363615405D3297F051BA1B16CB53D4DEA67846512E96901F78E601EE427F8B1A7986FB8832D091D575C277CB202E87602D670CE131CC6023A9E83AF41486A04D62616C1E912D4EAECD5DC815BAC1C0DBDB347F6B5DF06B0F58441FAB98B9511AC0423ACFA43E0422A62AE32A48E935C6288BD0D2314C6A739A7779BFE24DD7E2D66E9C4A4111E22481688EA39F256224531ED241A9D35D395F340421F2D8F5C05B873052D2128CEDF4ABE49E609176674363E31FB88FC21F83DD7C34DF85ADECFFF23FD036F17F0AA81FCF008CA4D02AB14858954A117C6B6F2CDF4823BEEF1904FFB4D841B30537D57C577968CDF18EC8631C536AF09B54D5887FC0EB11A70E86B72EF315FD722FB680EF03A3487434215A0EEA412C0D78DB2EFE20061576237453927710860F0A49DE0ED0C42FDE2A5903D635B19D4F2001EE353D7B5210E1C01F50251ED6E753635A972EC8C1914E36522B1B41BA51E9F3F1CE83BB5F526FBEC31C21983736E42EB7880B9B27EF6CAE0618E57F881193714D3E8B38C9E9056378DD79E78422BD7C4CD57D230EF44B38F6A107ABC77B8D5A953D3A3969FBB7DAB145C4F4615FAF8F2172AA2BDEB35C4A0494100CB9CE188DA4318EA5B617EBACE910A32F0A280C82AF82121720569232D71AD065E45268B36F92DDA13673529F24E6B83A865F3E266635D9655C8000C06478530294DE092640DFB324E09DB3B87497C94502BD46092D72DAEDFA93A0353661988C85A63C489C30724588FE31CBDB00FDC94A011F2D2A269B872CB51691B3F0ACA92B02FE916D2AEB98BD9E23313F49A0F44394883A432523EB5B34B690EF9C16B4D60572EF2D791F2BF403255A28D9BC3352B02687AD9200D34C05259FE0C93B75455218E031D59A65D4F571CD7F8B130A0CA1363BAF2D9895A8E8925ED20ADBE8FE96C34A6A13B9318AC8A23A7EA320B83B7175FB54868DAFA9E233B0F4B18CF6FC7D85F7A2B28CEEC561222C5051572B092F2FB269ABF1CC7826675F09949FC443EF723AB476E9E5D670C5F05E46DAE93837AA0F65A4E83AE2C71DD02CAB1038086531F93E163AD65BD962ACB9497C0F268876B5AD3CBBFC4C24EB2A98243675E5887CE67C324C1894250CEE560A971E8C32D69205DB2D932E9ADB0A78B6C1C4ACB8B4C97EA8C4CC3F3778CBF761AA653D9531216588A46701366E0186ABE46D179477CD209BDB5EE46DF3D36DBA69F5453C9AEB1E1DF4FAC4050CBFA6FEF6B9FE785A59511CCCE21EC5AE3F429A07B4626A4F0C555A15B42C26A5F353E7A479A700595689D5734C39D61177AAB2943775ADAC879B4ED7B8ED826CB43881D2C1B5734F64A5490A4F77ED4DCB9775B258C18182B42C560E6CEE89A329EF62E543C4E18C1587F6203711CFA12253211CE4521AE01F2273FBA71CFB041A19053D3003420EC262BF0F45F1C7CF6E55BA9001E4BE097329CA460D335BA899503CAE0D617BB7FFF0AD37076C91B1659BD448C05C49D9360462B4BC601536844FF2C635BB654EC5749FBCEF3288E41B8A7835B645E0BB501FF805EA4B39785C203BE03F0B105D17E513D50B7738E78EC18AFAB3FE134FD551E754CAA189DC4FA2308B6EED1B8CE87EBCE212E15E72C9516B778C1F62819131E2EFA7AF63BCF0EA404D9BDD7F4AC2E61DCB5286BC8B66483D5459E273EAAEE8E77A5EC02A0A2979199F43F2F59FB2C62E8AF2EABAFE9B89B71E75AF029BEC77A6A56F86EF6A4A7212A7458986D2DAC9E00CF68EDB81CA05A297B522D3CB2E0AC3146E4638995B683EC201C67C911C83E6BA3567D31565DF914783F41077E2C31B06640446A6D403F9D46BB9D00B3C436FE1FFDA80AD0AC466AF0417D18D5E7DFEDD7D68987BA55F545F3B89A38908BCCA1DACE0B89FFB49FBA3A67EE7384DEE68FD05721483030ED53913A6CFA059DDB451C780877E919BB86DDCA9E18814123CCC822A8F30D0AB4602815D2279398ADEDE00B23AF4EE605A771AC616CAFFCD3AB12991023A6BE6BCEAFB1672ADA631C6CC29827088627EF9380FFF46FC479E2B586432B58F95A824C0D5F08704C2B596A7BD0A36A52BFD8C14D999F92E676C83EA62DE54C3ED7ABF290BF17C48DD69F949668E11D957299DB6920D740252A9AFB65179FDD62B69D2A1A339CEF805FD258D83FD2F406841565AEF5E42ED7687D9D466E6A4E513E072A9EF6181016DAD988F7C2305A77740F196465CE30A35BF3D098781DBA7285753A9438517AA7159A9C806A19CE8B8BA5F9C99250358404671F36214E8A7B5A04767FF8C094A3CD74751835BD896FAEFD1747DDFBBE79F48148D56BF585CB0CBBF34300CBFAB9DB32469814F107EF7822151D158CAD68F01418F88B181B092970DACAE4D5DEA7AE39965D1929CBAB7685E758206D309CADC07687274657F6EEF56A657D3FED4D34C7FF6C9CC5F344F0EF4F0E752F83E06B8A23DA0D65A2C10C2D675CB3A214F5D363C35E6E10A1323579803E4268F7D868F4716BF849B3C3D8EDA94476BE7322891C36D6DF146075F11AD02434D2216351CC26600662BE0D38E1DFEF9A832B9F066718FCB2134115F33717B57936CCD2DFA3A95C1D4C4C98BD09D64EC04912C06C7C6A2FFDCA2801628D873EE6D0D43EB67FF0AC93A7666C9ACBB9400593C00316E05F0F5706ABD923D85DE72A0D1CA9F0774F5180B65AA578B95BD20C1FCC322A5B23995ACC9DC97CE3043B1A723AA2815314637B7667DE02ED0FA0924C0791CA09FA028633CCC594429D6E7429930C7F01EB6A134952E89B8CCEC743A23C63CDD9E161B5A2D1F1E0D005F16727A3B0E8B90C20656B850A4F8B5D400B65E91E45AA25A880B76BE09F226DDD4F0E0AEA00259E19634EBAD387CCAB556997A153D1C1B87AA62E5B613A5E02C65E7EE7DDE2E19D965D27B42AF8542066549A6FEFF3E10A93B349EACB843759F5E4EECA76CF82277BD55C57FAD09BE938ABB47720E49CED626AC860446B290C7FE9BC83DB0C7FDCBD5CA2B8FF6C52B2CF2556040B3792BA99DD43EDF1FD4CBE38970D235E8BEE40DDCD2708E432008992D3F9DCD73AD594171092909019E9BBE7A5D4A21EADF82C5C22D877F422EBC64734717C93A027E9EA7EDADFFBB8A04B465E2F1BDDA54BA30963A41978562C27EE91E8ADD7A95B97A1F9F5C0494C3E44AC5422759F971200B1927F5C37B003499B213C1CEF1823847ED4A308D7D98FD5E42115D49B1FD42C7405B55437E1C8C0226884DD801CD89163AEE8D74105F621EF2CE222B13ABBD14078943CE054E3D68F7E8D763948CA83876F0AB7CA5123ABA8C5F68679FCD116D03391F2A53F637D26EC486FF6363F0C297E1A672EB717107ED9540C2AAD46038F8D4C2B5D1D918AF6BFBA7DE46E6628B2C217672257EB98F585A4E4CDD87729BA5ED16719F869FA1495302E8BD043F92ECF8799DAB7B9C501DC956EE3E55FF30E6D565E228CDA2CED81BA796890764881DCF4C9907BF8477F939F43C8AA173CD3044023E10A68B5275694C30FA7BE9BE2392EE6B18651980A01348A97C4BF091DE3501B30B528092599313ADC93C8407FB07E740F784E80461A23A1DCCD78BE8A72EE2AD69CC6E63F385963275DF49AF300E5D468285CA4457F090504D42056F571A8D453903B85D7E63F893431A5A1C8A66A8E4C999F0592D75717940E296C8275952C4A8DC6E97B3D5602408DF3644E8A1338C856296C37B1BA8445883CAFB408EFB9A545AB53CD632C40659DC607F4937A4F364F7E3B47A907BD30D8558C76A8EA9EB357177B8B2639477433604EB74F9C2E3528215459533C1A989FEF107944FC8A402E29495F72F2C210135FD836028B9E21E76C6F13096DBD2BE9721DD2C35504D648C474907FFB896B014CB022942F308C3263CFF227D4444763A483658E728EE6B7954C48E3FCAB1246CED1B1E2EA9CC4D5475BD4FA43FFEF56AB2A2D779E9D206E3E657A2244108BCF55C7F4F97666457CF5F796105ABC773C541173B9E338B4273A8BC3E031CA33BC4DE4FE367B0BBE3530C88C0DDD7F55A358F9338191406A4C257E6B7C058565272FB78A54A46007F5550234FE9B7952A82581C08AA6A1EA68E497D663F82C5D20E9D1134816EEA319EEAC8E431A0D82B6D62F7B93D121D8382F0EB3DDBB9FCD43901C8AF1AA019A7160B76B72D4E8CA1228E5E9DFD49E24F3154F4A914987FD0264ADA4C8D6FF9EBB91C59C03CBD484E9EE72F1A98C3F97B9F2479FFB79DFAFBC33C8ED249286369F003C471C8B64A9B1546B1F31BFDD0ACA06AAB3EFB61E49CDF5506AF8A4693A7591498D9D7F8B28A72A10EC60F806A9955D7EB41D2654EE5B37C284F41CFF3F591C227E3FD0CD524379DCB384ACF486CE7B1E658CC743293DCF546BE85382FC40CFDFDFA407A9EA33AC46468E060524BF06C9CC109A726CEAF0811D0F857C08A3D4AEA67CCC0B17B2C38C53DA9F860C99E3AA769EE27CB7C9229207ACAEFE6C62D3ECFCA201DDFAAEEE1EC7BFD40086AA922961198B53C94BCFA97EEC1DC0FB8FF1D9448B6770DE4F5703CAE179FB51CEAF935F666F398B74BDE9FC87B01AFB6EE8B47490453198F9B38AA2259D2194E9EBC42E1C57994921413D6327018B91538CCB0B90E965564171D133CCD9E7F65E851971FB71F2C47B4592C2A52A4101D2EE7A69DCAB3852A56C4DBC9295D2EEC5BAD1B8A13B7EDE84768C0AF5FF0B0253B44038C236412ADCEC91508A76BD8D16E6D6BD5CBB3179B34DB8902863056CC65A4DD40B6A1929F28DFAE1CEC64A74DB5A8DE17226344C0D3769F1DF6B6B9C494783121EB3F42B8686D7FEF027D7E8104E8D9DB129F0AEFF48177BE4EB60236851F6D0DF3EAF508CA7F97E4D5814F71ACBCF00471EF263D3B5CD58ADEEF11E3465C704D90101A5FCC1C8CAC25387B7D6B83C7CBEF04E05BBA1766C5C5D804642609AF84AF3FA7E4572393761664021A632DA048F2A10C2A349E2E1C260C1C3CA6184BEF6045F43D9C767E2328B9AF5E48EFE8298DF69599C49CFE153BF59010741DEE011FFFBFB4EFC5AA4B5DE409B2AD90DA73CF2B0FFF812ED813AFE0934EFADC2CB387678B5A2D6C0E640388F83369497B16CBA6B3104624902242C468F89E89322D299123ECDD8ECC98FD5C53D99FDFBBADB056D1034CA39CBBFF29300769BFF634A38678FE7BF929676A43CD0FC3161391877F0623D9B59DF30E28F5B47C0445F83B36F0AA67F6A2DB8C0C3D3F45738A4DE393D8675E286F4530AC810D244C621963923BEB20810EE32909D5F79B7F944D0041C0130B7F59B0ADCCAD97670C92355CCC8F0FE34612A088BFAAB33542EBE8F3283AD67A79EECC3E7B7C5D4CCC29B6083AEDF7AABBFAC8281B7D7711DED8D4CA70C383C5042272379356BB80EC0A9BB8E4F1C73F2D2DE1676BF5AF43AF87AA2B2C4A6826DCDE46E599B2F31E9EA87A816EC5D8163952A7384603C8FEC20F58E1AAC52188E42774382077A35700EA5EA2FBD04135593A7E40ABA137FE400EB63BAC7F417252EF6AF6EA8FA9CB3BABE7718FAC4A756702AD64BF1F912E6ED44DC6D424CD15D3E45BC9F86ABF7CB2924D7B4E8AAF67D69401F5609B17D251140842D7A94FE5D911BF2FD37418208B716D2DC66320743B79E64CDAC6F2257AD34D112E22F977AE6034068C0E0F089FECA11DE03396BFBD365B1A788B2C550ACBED3643C1E4F13618F904B40031CA9E73F9B13293DC92102B33FBC16C9CDA02E511D49394D5DEFB95770E5CC750801623042B7113D385E8BE8FEDA1D7F9105D545B18AE98870B1326494F9BC31B33EC24CCA7CB8E53F9AF1A7E099B0D9A40CCF40B085C0D406B5F1DD7DCA794345FF98F272F7D9A11C30CC5448D2D311502B7F0F81437B52EB11CC5FF11C1FD62B9A34E2E102C5C59D14A3326702F6B6862383B5BA1041A59B2F4E009161857FEAAE3F0C4006926444BE77169E9963DF262BBACFC643F032414200B26840295326BA1983CF450DDABD0DEAF05B3AEE35CC029B1E67729517B6555FDC996782FE0CB275645E739BA0BC75A08869998C082BF6680E2DED0D643F06EED3947CB24E4D240CDAB6B07EB71762DB159BD8E8FEBFF190763906FAEE1D307115E7D6697AF3DB2192D37468806FD49ABAFFD157647B652B339A8912CAA3730EDB23593BE64CE9A50A1622D43538926E5B05D878029C5AE57DB40072EBB7889423A948257F9E8684E5B4F10C09A22AC506B5105246ADE89409D3AA78C4A88181FD562EB714E9402F8C4AB2129E73FD77BB64F3F6752E5AEEBC4DACC209D01A274E39A84857736671BD0604C153703CEC940CB0D79CC433D157EC5004ABA2F359B80DA9FC04267584B2897B594C494883185E613283B939DEBE0F324B3CB9F45A6FBF11AB1CF2704C5F83BE3B8CE1C38663757828909CA4AC49ACC134F533F5DAF470EC30D2E8FBC66C9B6C58CBD2ACBFBFA2842E78DEA2DCB820CCCBFB17454EFDB2B1D706B93B0254B3209CFFECDA9F52CFDC1CF312EAE3035C1A3D75D8764F693350C2301864EE1A3797F6574AE38F66B40F82904FFE6CBB34655B99959759EDB652F6A3BDC1D0F24E8EBE1761B43E876A6A7AA29E8B1158F1D150E25A742B5FBC7161234A85B35803FABBC0AEA40821E9990D48BA7EF7E1A50178ABB3CDBEE228B40C8B02C98C5E8B70CFF650E570988E64E6F4FB69DD11814016F8AFC30F853DCF0B793E150C3B796CDE2B1B43B3E346E257302026A4B5934CC6A417A99706CF783722DC2663F469896FF8EB4CC741D531F3C32B41F0BC6DCD4A32786747BE120B33718A94639FB4D754E0508B0315990F31555D6C1DE281244E229377BB4FDB9CBB38AE483A3569F735AC438C492DFE94149EB3F4A4F9779A1AEFE60FA343AC04323795C9D33DE8AF95219B8711B1168A107EF83062F033203511E5663EFA0C45ACF54432C9D4EFB5678332B5E164092612E42C61560D9EEC768594F4E0E6AF10AC7B3DCD22D229AFA8C022EB00AFA626C63E8E96B72DF979586867B42B8FEDE446A0F6807F1F1C775595FB5DEAA3BE2A45570235BF1169F163501B400DB5A48D7FF08851543CA92A0E8448F98BE619F41FACBF13EE45A1F97C20748CDC3B4068D993D944D5A165FB858FDF4FBF88632FB826103B1276C7791C64195106635996700A71E299889131E533F7F060C7F96E7C54F02D2A32835106FEBE6D40CD4D56B57ED26A7431731B04A78CB5A4884F0CACDF007DA6E1C4195B2B59A53F31C48EF9FC33CC7F6BD147032A1B6313C7EEC43B1E46164BEBFEF16FADDB1A176FBFBE34DDA7C88AC9C1EEFD4F33B7960D847872B8B433AD5D1293EA480E6FA097BB9AE29A7C0270A062EF9BADDD796FD8EBB1502606E9262357EFCBCC9B7343ACBD03CFAE6907BE46BCD32C4C4C4722C8D3A9EBC76EE4CDCE71B049D688C42104B94A1F7FE6F945BDD02E3DCE0C345C047AB31E7E8051ADDD3DBCBD33699AD660C1CE3E25D203C4EA56368B19C77D498E67CFE083ECD3D36BDCDF29A148224623E0D70D060EC964B329186162C1567F7E7B5B6921CAC8894E88BD8BD6FBA1E8EC4081D35931ECA2BE1E72E32D7C986956EE9CFB07CE0B5091605780D9770A00252C92C4DEDD4D8B942E14C90DFC5BD612D85CE24C5CEFDB3EA964FFF256B20A4DC2C0EFD50DA4BAB56BC846B09DE27F341EE42E63C0C23B6C61D15F2C9FFEE5663E3CC74F7400D0645219751B70C916C03C0C67159F71BC0B3BFA0956F026B91F8C2419D671D3E00D7F633DBD2DBE88126DEEFC7733C2C926D1D8B0C8BFB1077A700BBF3892F0C4F3E30DF78BCE0A340A8F98EBA5BD384684D1E0081C1237440B3A6F117178C0DE4F19D05D4241240924D9EAF9CA45E3D4231AC903C8EE5298A3445F01961D6D3786E36D24875E6DF3EB1D6C1BE5EEA0E060D3E0EED1DB2D4E795D35A0DABE4A745764F05A858291993541AE149CECC5147FEF0F3A96B42F38963B9B29466FD66AD46CADA8F10E2D53BFC3B823CFED410147B5FD315FAA62ED06429D6D3FE6E5778A64B5C9BB06A8CF5561EB7A8B15838AA226DDFCFD4C31805D53A6EB7D2DB861451027CF84218C39078756B2911021C3EAFC2E82ABF792C5012CFCA3AAFB0A277A9C9E1E515CBC4439D95B2A54510318F5D6EBF97C8DE2AE0D4FF669493AA354C25460D3C15B1A57AC53D7E6C07CA407AB1EEC4A366A637AD4081F0343433C555DE72B71ABCD8ED3C043532A61125CC3CA06CAA634E5F75B750BF262756A57E3FD235FA9EF00CDD9553D37968DD680EBD5935FBDFE43A82E9DD39F96FD483AAB7F2D0517F23727E8F4DACBF1442D207EFD647078CA9CDF7800804012D4EC23BA14C99666610A22DA87523E4E5E41A6698E5235743A9B9E1C4795F38AE20CBE5C3A2111ABA307C3BA6E03F092E96AC6EF297548A3F144ECF7F643EF19024B2E98B51173450ED06ED68EFFA06EFD60721E73C9C6993F14C00E3E4BE441791C648110F699AB5089D7CD092AAD82AE007C0C3C8659506D5F2817E75EAE8B803734822A2526861036E35C3689EDCBA348A7A2E4BE2F1E291F63473988AFFE650C1BC49CDEA3875DF4E6B541727B5AA6F04C9C1E4D06BC5CC744D1B955958E2578C6176AFD7E3262CCBC0F6FA21596BDC36349BF9329BCBA08FFF934E31DC1FEDB7D7F6B459BB1A0165043B902D600C447792A618B77C1671E5793473DED54FB3322180F198873E306E1F8BD17BE04FCD3CF4D6A9201B9B804BBC772B742097663C42F0FEE3766B3B205F14A39D6ABA56963D03DCDF538ECFB8A7AE64DA3C116BFC09506BACF5E8B5754B220F7CF70C5AA4492AB72D20CF8F4966A114833B057662EC63B9570D9B2DCEAC86590569934F91A61A03E18835E31ADBC2EED3BE0BC148FF004675C9555C901B280BFB56FF8A1C079E1F290C67FD1B7E53A6C27A5C649ECA9EEF836621F9E708EB84B6F5C529ED2F07BF0A6160154F41F323DFF8A498177FD09D22DB15A273F787529852D898A6DF0FDBEBEFBA3F3B602B1E67352224860125216AD6D68CA891606E179FB415DE4B95484CA6907319438F69337316203F06AB1488A471924545C81A470D78E2EA29AAF89E94920AC4B0E7F2FE01092BC8CF3839480A02C0E8DAC1E864C9BFF5CBF46C0FC7B6A01FF0DBBCF96E3585496C392C6496D06C44765878B26B6DFF2C2FEC20F26A9A2706838A2048E579C65F3BDDEFC58C89D8830FB8C75FAF96788998DD200D48189C3B59B41501BD310420DB96F7CC5B61A2EAF88B498ACD890F7DF623A35479472694CDDA58C000D9BC04FD903E4AB88A2E757700FF3F460F075F9876DB3F76F17003E01DC96A92543DCDFCD7EFC86A5C0DF387A50ABB69953D6DC19A699CD225941F82438A8EB7889B212F65ECA7399F89CA0D9B9915E827D2E520B6D481C27D4CD833EE7D985B20FA5BF7A21E4DFCAD092628EC0A6E2DC876E4C5BF248F94C2ADB3D6C9F23C3E70D1F611A2041C7759317B8EC1696B2632CA10CEFA498D7571D016E102DAC10051DAD086BEC58AD5DDFD7988C5F433DE87C314E3930FFF937A6E0C81787F04B77F893287AB63125CAB8B7460F119D03BF3076A98FF029EA5022201DD54C854711B8BE718EE678544B51AB13B7ED0262C8180C2F36CBAB64D862D38AD7D8172AD8BA3380706D52048826CAC611B07468967CA4A4DB52628A2FD56DD3A323382E5DB171811EA861E2D46537D0A4E545C65F238380083A064421DC7CE13EC2F715580924D9B6EFBDBB0D45AD8952F602BDED6455C0BC2734CB135B79966464546A261D0A551DEB43E5AE111CD02D0F2F2E996454DE17B471C6103D851CCE2E1FEDBB828C7F4EE66053A57831C708C377FDC6FDF037F400A09E9A610350BE6C013239D7F1C42758CA84B428EB06C6A6A3E05F10FED769CEE2D8EDC3EEA29204605005468B0366B2E957A7A55FBCC7842598F55021E58DBEEF44C5313226E6E56A2D3837F2A098C94BEC791737F355E6CE5643C954C4719C6C1C939B7716A29191CF0530BC2E78CD028D526EC286FCF02B18A077C86BC54F078A19A529F6EAF69D5562D4B31E4CE3B953A24655429BDBAEB5378C13E5B404A138B2B5473A415EA236245B0541B6D92F384D4CE63680ED5A6C035FFFC663C893C8F51C5DEC6F90D33573A05CBAED63B69079EE77DBDD21AD7A778B37EA5E0543BBDCD47497F355B1B2D8AD93DF4BB96A5E85A2344192B782D54C4C8DF251BD5F72EC415621FCE91148DB266EE1BDA0885827E96E8A9AD9C50F43D947DFA8260661FC9326B9E76214D36B22172C026EC12E04ADE3C62D4E957AAAAE686D350793BC6E9C862D968C0E56B3160B5C70520E9AC7767AD2BD8D1D6DC951A23BE9FAF9DBFF407E7766C84CCC3F281C6383079DC3188FBE8F9675D0A26831EC44071AC6184AACBFA0A2326D7EF097650C1D4D1E58134408C11E839A0DBA17CAC9DE3B437E697663AC136380D0690DA4A52070A2DC552275BA09C01B601D55E97AD7DE83A32B962D0A9053C1533600FEFD1171C638A50922B9962C195551F81FE80BE28342A13ED0B25FF8986E0E9C39F3C2F29B9F40AADF8CF61E879A7FC863B32F02C5B5BE16F0E2CF00F30E312820E84D09BDF073E0B16B1F32C73F0E6031DCB3221DDC48670D0F2DF9A8065BD027C30DCF9F12782C812753F109615828997768C75660D469691278A111D50A72CEE9600124E3850507C0B963E9121C8B28262B6C82510AC69F4785752AE1F619E3D334170A4ADB4DAF3138AE90AAF8D82573E7AD25A16243E16650219C47F4CEBE6915B433B0ED0354EE62FABFD3E118AC777A63316637DA755A99AF97DFE9857B2F58A83ED70041EDBC49997EC93C03A7D55524CCFFF8018EE1A587AAB9FB5D3E33FE7BAF2642CF9421540C134F9BDE458A65E6B9BB209359F7FA47B95EBB79C83F329ECF88C7541446868CEF363218841F55D346A2B714DD48C711555BB25B1CCEFA6199A0E7646646B667634E486116C0AAD7E977C091A5EA356778C299EFFB7DBD3232C4B73B54C796BD1E33284CC8E4354C772DF1CCF762F615715FAA903D1551A67965FED6C7E1ED7BABB9325AC30F92305FC284724C59079B11D1A0E32F4665AD8390B34968D1885C9EB8BC5DDF63D7858E042CF7C66FF5E36365F1C7156C79CCDF596EFA551E203456E5BB22C2D9B742F490824B1D5EE482F335393E34E69C7820A639858C6EFFC2E8377876E461788FD2736A2D1BAAA432B008850BBB44FA193DC54757D8C75760638A12DFB614580A882EBD945716D7A3D3D29396D4A0D267B07B035EC001CF29C87E23D8446E21D604BCAB110869FFA98C32E35A9B6C878360FD7BF8D564B09384D5C52E0C9BE0F45E814C954FBA214F3D3089AC4D01ACBCDB25B9331558FE1D29E67628E13BFC928F7A9A88D13E0759B77674C3F2795CDFE0C6617022F9C6A87B60C4B5A69E8D1706749FB0B4E086C94B5BFC16CC3B34FF3B7EC227A5CC646E9A003E5D897871067191AD1F8A8C33A0E567F4DF2D91D00FEA00B152183D202BD72DC0694F16ADFDD6E44A248D80FC6609E601CB91EE691C4535CD80BECFF9F23F32BAB5F106234A8867CAC0B5269CA2BC588E48AF922B5917BB6813E9D1005F35CCBFDFD419404B59A84497BCAD743384461F24267C497A932411B690BF405A7ADCA63858F439B123201F41AAAAA4D0A478101EDC6AD214E025B5DB6D24021464C53FB376503B6CAF4E4D4974E072F8C88A7C61957239581B589ED8D1753844ED928642CF96E5ACCA32E69B52CFA3AF54B9FF793E7553CBE16C4F9DD6114D1357E539C238AAA4434C5E540AB31FA584B82AFBF419DC51D6B08FEBE34B7991EBF2A82FF8E94990BFD02764F7D1DC049A635A08B7BFDB46A521170B6B8BD940883CD4505224D9DF930E33C5827E303083CAC4F846D9CB9A6E3FF57E755C7CCA541DF51819C5A52BDFDF005217000967A2776F51217813B2FFC509EE35F8AED6481BBFF5D5E61732BA17C90FBBCE1FC29E8DE849C146642845F982A2F766DFC0A703B5BB612E4C2B8CC426BB56196D714FC6F1BCAA0F19F32CBC06C3DD1406B591D2B0CD0E834D003CE56313B66C224594354866598118C87C1A86F7D247593846100395EE6303E54D130F91FDF81D0DFD021C274AA9567B9F9A500F35507519BCC25535407E419B52FA4D9ECD3D53F467B6295505DE979CBF6C7BC909812265ED65B30269FA1500264347FBCF1CB34AC5A405F208E73DD503D0D0E15FA474802F273C76C3D3DF98070BF3151D5D338DB368DA0D2280BD821880265763EAB2076766540EB9A51EAE647B96CA4326C82626DBCFCA1B3FF6DBA63DD64AEEA6741FA49E358E97D8F60C7F1A56248E8CE18933CD6F850E667134F69176DFBE2A4FC259994ADE12676F63D483FE16F7658F1003C1561B8D46FEA0888D2C82A4254AEB9E4104B9FBC973CF836BCAB5E263240ED9D87E9C434DC66E8F4A7B73EAEB30BB745F4094A4B82EC96CF99219F557ADEFA605DDE957CAD9D5343558A9A0904575A7A954948DC927E71786394DF40E9328C9B4382CF4FD8423B97088BB07CB4B257E5AC7B817088C3A6912441992153D374D477EA4EFD21C9F706D3619634AF7DB364F5FE73D12FF9623B665980B98E83991215E188462A57C4B3F653E11B4B1E16522CD421105A1FE67AD0F58F3D4AD34A8BDDEC13454EFD5FAC6146012476391769D4AAD22B1A0BD1CE9599600EEDD95DD265C4640CB064F92C22B0C45C64FC411375852E596F268EB415B03DA88ABF9A089EDCC5F06ABBD96E1BA461D4DFB3772938CCBE093AF922F5CE290295EBA2289660868ED4B6AE38B28B1ABAA06B66BB97A5396218691B13D099ACB89D6754517372564CAB054763190677139C9E2F0BA2FB19D0471E49BF6A0DFF2F951A414ED5D0F17C729891F4EF658F19FEB6D31F0BD8EC15DC9F9CC1FD73BBD7A6CA326AB06F55078D4F2F90CF185849567E8C78F2773938A916FDA23279FC3A9D62CE3C3AAD309264EA076635487EDE98CE79ED297D1BA99D96C84EB712CCE028298C8BAF5B5CB3EFB2EB8996EFFF6F7682D6EAFE498B886FFDC157AE3995D8493BC6B51541BE6862B41B5A35AC420D4D120957AC00B6E488AFA394C5C3F99DEDB4BC4AD4127082E44F22194654D3FEF9CFF3AFA66A764864D8344939255F4BD77942D6B2063FA9C0F82DD3B8D9ABF5C633B6CACB152AC09B9DF3BD12770444F99843FD913E2C815368910DECDB46DC4E13EF2E89AC3FC7D13749B88197F633BB6044E1EA0FF4CE060C7F426D01D0CE94833304CDEE3C857FC7258DB654F49E7C949C4D4B2DDD689DEA7E0C526E694B5EF77F8DBCC199F73D833C54C6C389C9C63A9E203FDF4389D83A4DF4AD86D7B36D3847C8DA829E04E31BD81791E403D6098AE9DA476D75B357A74FBE2F0C42FADDA27AC72B653FD87A8D1D72E72E2BAF5D852D1FD6DE10D5A6A600C795F65A4A59A00E2C503DA0BAD2344CD62FFFAF6761831AB2CA4055C18294DB1CCAF2BC6A13DB522CA1BFBA9DFCB930E4D6C32EC24DB5A8D5C15398CF2202878D240BEE11756559F26355C059A81765FD0D993FA64887D5CB6EDE1B379B2B8B5D5430F3D7A6ECB8259220DA7C9106CACBA69CF6444192275A2C6EDC588234E8D24985A0770607FE1C4AE8CC7559B3687522EBF7D3CEF0E19B229509D2A247E8650C3676B3B272340EB71C69064FD3CE931406569E7AC1603E49A13BEA93B2892704378ACB4796CEA77687C98E8AAEC3501143271E504408CA5D7ED271C45A1A7637CFABEA8EDFCB11DFF3F8324C8C2C7D9C73A26B8B1C05B6F18013E03928FFFBBB5068FCF4B29FBC21A5819EF85B91B19A5098883EF40D91B7E287749A578E7743680786FCA565BC4D19AAC06BF70C283E7649992BD6BC0305A0A093B75DCFAECD7E049E16F274AA9B017CAF3F5068FECB55C6FA6ED97F64E17CF1CDDDAEDB45036C6B2227A0AD5181AD7389B72C8967B8176E18CAA3506BECFCDFFF15B598C47D10E11E65D9AE8AF9AFC8B189562D98BBB02EE55D0A5C41EEFFD3D6E8EE69878B3A003DE7A52A98978892E51219387C24BAA7A773944F530816FB27BCDCA933370CB340781A70DB5724C597F72F7A34DC05B732FEB79A18171281AB7A94DFCDFC2C96DD00784F2E67D7E56D0F146F1585EAA1448BE1CCAFC6F334CAB07A27E524BEB95E19D426689B900176A70B21E32278F27EA3BAEE623F92B14696CFB1EABA0D90EDC414FAAB03AC0572B4B8836F071A375849BCF46E83A05979A4111167CE5C43F6FF48F386E3E8F92FCA1655E3ADF4C2123DA2C5551E252E9BFD93276B5B2BDADBC8F23C0406875614ABDE72C520002AFE6F55BF1D19ADB7F26D4F71842FC66335FF670C60583CE65DF747AA6DB218471551478BF36140DCC5C6B9AECD22944CD2B781A240C914D2BC4B37877709794CA33ABA878615050637B0A0B3F04DE2FCF37A2442A242E6C97398CF483260BE8A092F998EEA5FB5519EB25BB10B9350AC7F6948CE13DC282ADFD3A251C07E32A25A8A93276A563755B3164C0A9510260425ACDC093CBDBC6C8C5D0FEC94A6DDB415C80D45BF9A6D8DCDA606E3204EEF6AA291AAC9AF7122810A77E0E1160A461AED63687B3C137EC40897B972493F33636B2CFF07747A394747C0887C0402CC4F50E78F70785E5DA4C6084BFD7AE379F0AADBA0CBADF8C70C34FA7A6B0C14F32D52FE8AC726F750DDDA95C741131C7F692CAF7A3A80173479690A3CC0A93D1823BA1AFD5634A9D14E17E7858221497CE6934D7630E73D615127209FA239A190EB60B4D49770A1122DE7ED76708CB660EC4E52900D130C9A4638448CBFB16B1943D7C007D521F945D00D42CD0AE51FA89D5BBB9DC68360C2551D3A0E08CB0025B061057FEA0855305C0F6496903EC94DDF067E722AE07D06AD5AC67A1B5A9D1D036F4D157220087AB098F2C6A911F710332AC3AF782A6747B8E079F12A768B9372BAA222EF43084F65A46EFBDC5D8BE794084FEDD23BB2BE82A7FD1C5FCCCA0E10FFF7CD47FE805A43F82E73773670C4F43571767DB9F9A59A16B1C6DFF3AEB739FDFDCEE27D8699BC080B9D5973F30BD546DAC6DE594F91E5C2F0DF432099D949C5FD0E9ED66BA4FD37F77CBBA8D511A0D712DD62859D6E3C0177A264EDC37393FA86D8BB241B13A2023CECC4A8A57242DA1C7BB796DB4B50197F8E7DE6FD645C6B9099D6F76701B0A36CF2DBC1C9E2F56AC8CB222D37682E19D33A1728916687BE117E14BC7D137CE28948A0997FD9B25545316DC91AF2780D34EB5D9A262B327FE0E57AF30D9299C1CDD7FF92E3CF8C70A9CBA640A71425B164DE8D2D0D78A19853125F684FB1E94D7D02473BF12C6537595311354BAB832C69593F4195132C6552176CD781A04D4293BB9E329B78AE8929A249AAC01C5C81DC46DF707C914E08A642BF4B0277302BBFE3950EAB036CEABBDDED57D2AB2DAC00B61474150F0F641A571573A79C7CEFE5B1E08C2A0D7C144D69764BBAAA9DA45E8C1CE02AD4BDA14E86E6F4509823913D553117C25BA7727244D0A5F4106962D2441C4D3813A780757E169AB7DA6FAE572D7CB919DF7BA028ADD524236473F8CEC4509FA954310D970F13B8F57505F248413F93CCEB0D2A8B81A3B6B812422E630863D5F37142EC8B03444B7509B92C2C46E8B7DB79679EE93FFC1DF1B807E29773C0B9A280334CD97CFFA2AEAACDA2A662F8767A323DA9D48CBCD419ACB2EF27A01A26F7F2968B572B679155717F7AE7CF17987EEBF9B088B153D06F88F683CD8A53B1D69CA429BC5D17DFF465377F6895611C319A8C8BC23438BED492817703D83BDBB93CD491EA8C39122ACD809BA158D5951E0B78FA5409E63E7CC69B5B6BC9BC56349CAFB05B71BD8C8ACC90F929F58037617118351CC1E0E0B3CC4040BCAB505CA4AA36C06277B4D550922DC424A005854FEA6EBE6C833980D3F7D49F38F595E3B156B89809B65E62B57E0C79947B2EC463027DE21FECA9FBEE0CD5B8EC64BB776FC95D93232C53A5A5D8F5954AD65E6BA6A3677C62497C3F4DD408AB08F2B05E00F865CAC6983159D2E4EB54EC0B89384F890E6033F71C5C888A9EF25C2E5563F4B79CF7F80E221C59FCC0CBA7A56ACA182D6A22A77AFBDD2209D5BBE8400605B918912E1F8268EEA13534E86FE8B6588ACF64A1322DFBA8990E280AD5A2E185DC29AE3AB7AEDEBDFF8932A21ECB57071D2C6207740AB48DA0286EBABE44AB1566D845A6B231073076634B6493FF5F4669CE06BB0BEB477C3BF2F9173ED7A36C22EB347036E7358BB62192E4E7BF5B9515C6A433D21E47F56C886AF92422741D1CA07EEB3A67A027283E78A27B64C89AC0EDF6D3CA5AAB03AB2437B7813BC5E349434386F00F0C0D592256BB28E68D0ADD1F23F001F2F0DC867BE42CFB316FCC3AB7F2ADE8F262E2F2A817435D72D2B9F181E285F7D58C2E9D0ADCA7E67933CEE6F908BBF182523A0367EC978CAC6373140022E3B851EBAE9D7086C4191C0BB856FBA1C5785F57A555985D0060A4BD79FC0FBD7798CE46C543B3D26C62BF07B7FFC0C5CB00729D2F9DC75A8A308AD312EFDB71DCF069034FB4F970969B749BD6F487F5E77627FFA00F64DBCF819A4F8EC0681AC3816282EC1717DA96444B3EC00B32B8C07E806988EEE0B8CEAF0CEED4F400F27F1D79267AA4BA333E61B84E6F10222FDEAF05D3561F5796CD819C879A07E780BAE63E780C05F024F2880EBCAEA6C1C8258D94B753BEED298829CF221BEEFF249643A4915D5C0E8AEAD2C85ED170790074EEC22327260470E99DD940227A671D56A9204224861E56624244241513ED4AC7117ABD09523C29C4F23E0C41900011215540597EC1BF8516CD28C228D03F8C7A65E4FFE575C6F5FB1F833B04F3DD1FE2DA3F983FC8A6BEE8CD7FDCFBB4436D8E8F09D466CA0129B4080F5C4D2A078B1CA2BAB5B306B26B4F75F49335E128D5E27B6FE1D96B9B863268E813A092C5176087562125530D23E8F6D61D99ABF133B032021530A5FBD7CAA65063B17304B76498D90B0F3E6541534667952F6B31A74394000AA731CD42D2CAB1EF3AD7AADBAEC7541D04E60B843FD337D7D08B9991452889376EB57FFC5D2D454B35DE0BE42E0B04E5C21D950E809C5D499AC04DE0E4FF912237DD83AF0FFC5CB8E520493400C91235F9D49BB30724098295713F70ACB57194F53B656D4B3E5879E2E28734370A052FE51C8139021ADD0DFC6D3D8491AE9C7C8E3AEF6A5C1E119D65923212BFDC35792BB5E3109BC36003C17100DF5302C7FE73ADA012B36AFA5452CFE356C38E63C59E80C1F3FAA1735150F1F3CE87E7008281D125FE7627B3D6C8DB3A2101DD6D650656EE5B8E0E8F0CA1DBEE12303499B6CECE8AC80111C504804F9ABF9C616D22DF34FBDAF27 @@ -11,4 +9,4 @@ msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 18469 smremain = 1099511627774 -max = 1099511627775 \ No newline at end of file +max = 1099511627775 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp index b5b876c43b..a99617b857 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-12_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHA2_60/12_256 - pk = 000000089C3469640CD3578A98E9F9471F596649E45D969754FFE37395B79731156A1E2204562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 27688 smremain = 1152921504606846974 -max = 1152921504606846975 \ No newline at end of file +max = 1152921504606846975 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp index 7410c6ae5d..86915f5431 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-3_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHA2_60/3_256 - pk = 000000065FC7351ADB3E5E78B0A1EA06ED988995BFD8960B36F604AC8F03600F0F15E05004562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 8392 smremain = 1152921504606846974 -max = 1152921504606846975 \ No newline at end of file +max = 1152921504606846975 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp index 98d33b6b08..f775441ed4 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHA2_60-6_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHA2_60/6_256 - pk = 000000076948691BBB3D39575B96EB00BBE25665738D3B70378EC25AB76CD8D200F9BFDB04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 14824 smremain = 1152921504606846974 -max = 1152921504606846975 \ No newline at end of file +max = 1152921504606846975 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp index bbf9b3b078..8693856dba 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-2_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHAKE_20/2_256 - pk = 00000011CC3CD3FEFBB5188AE538CEAFC0E64816F394C351FE22AA134A3EC20A6A25FB5004562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 4963 sm =  remain = 1048574 -max = 1048575 \ No newline at end of file +max = 1048575 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp index 7a37a6015f..07fb5d5c3f 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_20-4_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHAKE_20/4_256 - pk = 0000001253040139BB0C869F0B49F12B2ACB6B6E78731BF48B976D5668CF38EA836868E404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9251 smremain = 1048574 -max = 1048575 \ No newline at end of file +max = 1048575 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp index c9042e164a..5fba789ede 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-2_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHAKE_40/2_256 - pk = 000000139671F9E99FB4EC6B22DCD31B932FA6A76204CF58477B1B054F10C47913D088D804562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 5605 sm =  remain = 1099511627774 -max = 1099511627775 \ No newline at end of file +max = 1099511627775 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp index 7f15d5b83b..38e4a7a962 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-4_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHAKE_40/4_256 - pk = 00000014A855A0EF256ED6B3F83CB4938E1BCAB172AA13D2FF813E233B4C2E3DB18D27D804562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 sk =  @@ -11,4 +9,4 @@ msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 9893 smremain = 1099511627774 -max = 1099511627775 \ No newline at end of file +max = 1099511627775 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp index 791dde71df..405000a405 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_40-8_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHAKE_40/8_256 - pk = 000000150C866CCF8B4C8031FC149A5B5C6C504B1DE97B1C9B8F84B9CE8BCF536E3BC15404562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 sk =  @@ -11,4 +9,4 @@ msg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 18469 smremain = 1099511627774 -max = 1099511627775 \ No newline at end of file +max = 1099511627775 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp index 7a3f549c8b..678fdccf6a 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-12_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHAKE_60/12_256 - pk = 000000187C9DBD8C9B8EA4E9F5B0D99E80ACDC712F597F327BFE800419A478530242532C04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 27688 smremain = 1152921504606846974 -max = 1152921504606846975 \ No newline at end of file +max = 1152921504606846975 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp index ab3935d58d..e407b94de5 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-3_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHAKE_60/3_256 - pk = 00000016BBA15DFC230A90773653F36EDD994F661301535E235D0034A34B25B25C58531B04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 8392 smremain = 1152921504606846974 -max = 1152921504606846975 \ No newline at end of file +max = 1152921504606846975 diff --git a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp index bf11e7de76..9c54ac3b00 100644 --- a/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp +++ b/tests/KATs/sig_stfl/xmss/XMSSMT-SHAKE_60-6_256.rsp @@ -1,5 +1,3 @@ -# XMSSMT-SHAKE_60/6_256 - pk = 000000171657949C495B0A1FD294C1E4123901C1A43FE62FEBC70C30CB6088378ADDBAAA04562AD35E8ECAFAAFDA16981CDAA147606BEEA62801342AF13C8B5535F72F94 skmsg = B338DD755D5618C464AB331F14DE3DD4A358BBA00D28FB35236741E902F7B248CE smlen = 14824 smremain = 1152921504606846974 -max = 1152921504606846975 \ No newline at end of file +max = 1152921504606846975 diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 52245f3dac..76a7307037 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -207,7 +207,6 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { } fh = stdout; - fprintf(fh, "# %s\n\n", sig->method_name); OQS_fprintBstr(fh, "pk = ", public_key, sig->length_public_key); OQS_fprintBstr(fh, "sk = ", secret_key->secret_key_data, sig->length_secret_key); @@ -286,7 +285,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_total failed!\n", method_name); goto err; } - fprintf(fh, "max = %llu", sigs_maximum); + fprintf(fh, "max = %llu\n", sigs_maximum); ret = OQS_SUCCESS; goto cleanup; @@ -322,7 +321,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { // Echo back max if (FindMarker(fp_rsp, "max = ")) { fscanf(fp_rsp, "%lld", &sigs_maximum); - fprintf(fh, "max = %llu", sigs_maximum); + fprintf(fh, "max = %llu\n", sigs_maximum); } else { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_total failed!\n", method_name); goto err; @@ -441,7 +440,6 @@ static OQS_STATUS test_lms_kat(const char *method_name, const char *katfile) { fprintf(stderr, "ERROR: Verify test vector failed: %s\n", method_name); } else { fh = stdout; - fprintf(fh, "# %s\n\n", sig->method_name); fprint_l_str(fh, "msg = ", msg, msg_len); fprintf(fh, "\n"); fprint_l_str(fh, "sm = ", sm, sig->length_signature); From 194163611c1353b417ac47f4568f74fdd9325cff Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Mon, 11 Mar 2024 15:45:18 -0400 Subject: [PATCH 43/68] Add return check for lock/unlock function (#1727) --- src/sig_stfl/xmss/sig_stfl_xmss_functions.c | 10 +++++++--- src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c | 10 +++++++--- 2 files changed, 14 insertions(+), 6 deletions(-) diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c index 64d714e600..3b205e8f90 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_functions.c @@ -37,7 +37,9 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sign(uint8_t *signature, size_t *signat } /* Lock secret to ensure OTS use */ - OQS_SECRET_KEY_XMSS_acquire_lock(secret_key); + if (OQS_SECRET_KEY_XMSS_acquire_lock(secret_key) != OQS_SUCCESS) { + return OQS_ERROR; + } if (xmss_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { status = OQS_ERROR; @@ -59,8 +61,10 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmss_sign(uint8_t *signature, size_t *signat OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); err: - /* Unlock secret to ensure OTS use */ - OQS_SECRET_KEY_XMSS_release_lock(secret_key); + /* Unlock the key if possible */ + if (OQS_SECRET_KEY_XMSS_release_lock(secret_key) != OQS_SUCCESS) { + return OQS_ERROR; + } return status; } diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c index ec1143f1b8..3f280e024c 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c @@ -38,7 +38,9 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sign(uint8_t *signature, size_t *sign } /* Lock secret to ensure OTS use */ - OQS_SECRET_KEY_XMSS_acquire_lock(secret_key); + if (OQS_SECRET_KEY_XMSS_acquire_lock(secret_key) != OQS_SUCCESS) { + return OQS_ERROR; + } if (xmssmt_sign(secret_key->secret_key_data, signature, &sig_length, message, message_len)) { status = OQS_ERROR; @@ -60,8 +62,10 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sign(uint8_t *signature, size_t *sign OQS_MEM_secure_free(sk_key_buf_ptr, sk_key_buf_len); err: - /* Unlock secret to ensure OTS use */ - OQS_SECRET_KEY_XMSS_release_lock(secret_key); + /* Unlock the key if possible */ + if (OQS_SECRET_KEY_XMSS_release_lock(secret_key) != OQS_SUCCESS) { + return OQS_ERROR; + } return status; } From b45415c5ff2b4087c4e3091a6ef7dc3f25eb3940 Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Tue, 12 Mar 2024 12:49:19 -0400 Subject: [PATCH 44/68] Use `abort()` instead of exit to get the trace log. (#1728) --- src/common/common.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/common/common.c b/src/common/common.c index 1146f5c45b..904b91519c 100644 --- a/src/common/common.c +++ b/src/common/common.c @@ -275,7 +275,7 @@ void *OQS_MEM_checked_malloc(size_t len) { void *ptr = malloc(len); if (ptr == NULL) { fprintf(stderr, "Memory allocation failed\n"); - exit(EXIT_FAILURE); + abort(); } return ptr; @@ -285,7 +285,7 @@ void *OQS_MEM_checked_aligned_alloc(size_t alignment, size_t size) { void *ptr = OQS_MEM_aligned_alloc(alignment, size); if (ptr == NULL) { fprintf(stderr, "Memory allocation failed\n"); - exit(EXIT_FAILURE); + abort(); } return ptr; From ba63672527eabfe43139adaf9bc37e15e8a3657a Mon Sep 17 00:00:00 2001 From: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> Date: Sat, 30 Mar 2024 12:53:22 -0400 Subject: [PATCH 45/68] Reduce number of `malloc/free` call in `XMSS/external` (#1724) * remove unused file * move malloc from prf and prf_keygen to external, reduce number of malloc/free calls * push malloc/free to top level function * continue to move malloc/free to upper level * clean up * modify TODO to TODO(from upstream) * make astyle happy * clean up * use malloc and NULL check --- src/sig_stfl/sig_stfl.c | 3 - src/sig_stfl/xmss/external/hash.c | 44 ++-- src/sig_stfl/xmss/external/hash.h | 12 +- src/sig_stfl/xmss/external/params.c | 4 +- src/sig_stfl/xmss/external/wots.c | 46 +++- src/sig_stfl/xmss/external/xmss_commons.c | 39 ++- src/sig_stfl/xmss/external/xmss_core.c | 278 -------------------- src/sig_stfl/xmss/external/xmss_core_fast.c | 87 ++++-- src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c | 1 - 9 files changed, 151 insertions(+), 363 deletions(-) delete mode 100644 src/sig_stfl/xmss/external/xmss_core.c diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 69fdbc352c..9299975348 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -912,7 +912,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature #endif } - OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *message, size_t message_len, const uint8_t *signature, size_t signature_len, const uint8_t *public_key) { if (sig == NULL || sig->verify == NULL || sig->verify(message, message_len, signature, signature_len, public_key) != 0) { return OQS_ERROR; @@ -921,7 +920,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m } } - OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { #ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN (void)sig; @@ -937,7 +935,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned #endif //OQS_ALLOW_SFTL_KEY_AND_SIG_GEN } - OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const OQS_SIG_STFL_SECRET_KEY *secret_key) { #ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN (void)sig; diff --git a/src/sig_stfl/xmss/external/hash.c b/src/sig_stfl/xmss/external/hash.c index f9272f01c3..6330c5871a 100644 --- a/src/sig_stfl/xmss/external/hash.c +++ b/src/sig_stfl/xmss/external/hash.c @@ -29,17 +29,15 @@ void addr_to_bytes(unsigned char *bytes, const uint32_t addr[8]) */ int prf(const xmss_params *params, unsigned char *out, const unsigned char in[32], - const unsigned char *key) + const unsigned char *key, + unsigned char *buf) { - unsigned char* buf = malloc(params->padding_len + params->n + 32); - ull_to_bytes(buf, params->padding_len, XMSS_HASH_PADDING_PRF); memcpy(buf + params->padding_len, key, params->n); memcpy(buf + params->padding_len + params->n, in, 32); int ret = core_hash(params, out, buf, params->padding_len + params->n + 32); - OQS_MEM_insecure_free(buf); return ret; } @@ -50,18 +48,15 @@ int prf(const xmss_params *params, */ int prf_keygen(const xmss_params *params, unsigned char *out, const unsigned char *in, - const unsigned char *key) + const unsigned char *key, + unsigned char *buf) { - unsigned char *buf = malloc(params->padding_len + 2*params->n + 32); - ull_to_bytes(buf, params->padding_len, XMSS_HASH_PADDING_PRF_KEYGEN); memcpy(buf + params->padding_len, key, params->n); memcpy(buf + params->padding_len + params->n, in, params->n + 32); int ret = core_hash(params, out, buf, params->padding_len + 2*params->n + 32); - OQS_MEM_insecure_free(buf); - return ret; } @@ -92,12 +87,11 @@ int hash_message(const xmss_params *params, unsigned char *out, */ int thash_h(const xmss_params *params, unsigned char *out, const unsigned char *in, - const unsigned char *pub_seed, uint32_t addr[8]) + const unsigned char *pub_seed, uint32_t addr[8], + unsigned char *buf) { - unsigned char *tmp = malloc(params->padding_len + 3 * params->n + 2 * params->n); - - unsigned char *buf = tmp; - unsigned char *bitmask = tmp + (params->padding_len + 3 * params->n); + unsigned char *bitmask = buf + (params->padding_len + 3 * params->n); + unsigned char *prf_buf = bitmask + 2*params->n; unsigned char addr_as_bytes[32]; unsigned int i; @@ -108,34 +102,32 @@ int thash_h(const xmss_params *params, /* Generate the n-byte key. */ set_key_and_mask(addr, 0); addr_to_bytes(addr_as_bytes, addr); - prf(params, buf + params->padding_len, addr_as_bytes, pub_seed); + prf(params, buf + params->padding_len, addr_as_bytes, pub_seed, prf_buf); /* Generate the 2n-byte mask. */ set_key_and_mask(addr, 1); addr_to_bytes(addr_as_bytes, addr); - prf(params, bitmask, addr_as_bytes, pub_seed); + prf(params, bitmask, addr_as_bytes, pub_seed, prf_buf); set_key_and_mask(addr, 2); addr_to_bytes(addr_as_bytes, addr); - prf(params, bitmask + params->n, addr_as_bytes, pub_seed); + prf(params, bitmask + params->n, addr_as_bytes, pub_seed, prf_buf); for (i = 0; i < 2 * params->n; i++) { buf[params->padding_len + params->n + i] = in[i] ^ bitmask[i]; } int ret = core_hash(params, out, buf, params->padding_len + 3 * params->n); - OQS_MEM_insecure_free(tmp); - return ret; } int thash_f(const xmss_params *params, unsigned char *out, const unsigned char *in, - const unsigned char *pub_seed, uint32_t addr[8]) + const unsigned char *pub_seed, uint32_t addr[8], + unsigned char *buf) { - unsigned char *tmp = malloc(params->padding_len + 2 * params->n + params->n); - unsigned char *buf = tmp; - unsigned char *bitmask = tmp + (params->padding_len + 2 * params->n); + unsigned char *bitmask = buf + (params->padding_len + 2 * params->n); + unsigned char *prf_buf = bitmask + params->n; unsigned char addr_as_bytes[32]; unsigned int i; @@ -146,19 +138,17 @@ int thash_f(const xmss_params *params, /* Generate the n-byte key. */ set_key_and_mask(addr, 0); addr_to_bytes(addr_as_bytes, addr); - prf(params, buf + params->padding_len, addr_as_bytes, pub_seed); + prf(params, buf + params->padding_len, addr_as_bytes, pub_seed, prf_buf); /* Generate the n-byte mask. */ set_key_and_mask(addr, 1); addr_to_bytes(addr_as_bytes, addr); - prf(params, bitmask, addr_as_bytes, pub_seed); + prf(params, bitmask, addr_as_bytes, pub_seed, prf_buf); for (i = 0; i < params->n; i++) { buf[params->padding_len + params->n + i] = in[i] ^ bitmask[i]; } int ret = core_hash(params, out, buf, params->padding_len + 2 * params->n); - OQS_MEM_insecure_free(tmp); - return ret; } diff --git a/src/sig_stfl/xmss/external/hash.h b/src/sig_stfl/xmss/external/hash.h index 708dd6932a..e0b06eba98 100644 --- a/src/sig_stfl/xmss/external/hash.h +++ b/src/sig_stfl/xmss/external/hash.h @@ -12,12 +12,14 @@ void addr_to_bytes(unsigned char *bytes, const uint32_t addr[8]); #define prf XMSS_INNER_NAMESPACE(prf) int prf(const xmss_params *params, unsigned char *out, const unsigned char in[32], - const unsigned char *key); + const unsigned char *key, + unsigned char *buf); #define prf_keygen XMSS_INNER_NAMESPACE(prf_keygen) int prf_keygen(const xmss_params *params, unsigned char *out, const unsigned char *in, - const unsigned char *key); + const unsigned char *key, + unsigned char *buf); #define h_msg XMSS_INNER_NAMESPACE(h_msg) int h_msg(const xmss_params *params, @@ -28,12 +30,14 @@ int h_msg(const xmss_params *params, #define thash_h XMSS_INNER_NAMESPACE(thash_h) int thash_h(const xmss_params *params, unsigned char *out, const unsigned char *in, - const unsigned char *pub_seed, uint32_t addr[8]); + const unsigned char *pub_seed, uint32_t addr[8], + unsigned char *buf); #define thash_f XMSS_INNER_NAMESPACE(thash_f) int thash_f(const xmss_params *params, unsigned char *out, const unsigned char *in, - const unsigned char *pub_seed, uint32_t addr[8]); + const unsigned char *pub_seed, uint32_t addr[8], + unsigned char *buf); #define hash_message XMSS_INNER_NAMESPACE(hash_message) int hash_message(const xmss_params *params, unsigned char *out, diff --git a/src/sig_stfl/xmss/external/params.c b/src/sig_stfl/xmss/external/params.c index a1d49d1340..2a91a964df 100644 --- a/src/sig_stfl/xmss/external/params.c +++ b/src/sig_stfl/xmss/external/params.c @@ -369,7 +369,7 @@ int xmss_parse_oid(xmss_params *params, const uint32_t oid) params->d = 1; params->wots_w = 16; - // TODO figure out sensible and legal values for this based on the above + // TODO (from upstream) figure out sensible and legal values for this based on the above params->bds_k = 0; return xmss_xmssmt_initialize_params(params); @@ -692,7 +692,7 @@ int xmssmt_parse_oid(xmss_params *params, const uint32_t oid) params->wots_w = 16; - // TODO figure out sensible and legal values for this based on the above + // TODO (from upstream) figure out sensible and legal values for this based on the above params->bds_k = 0; return xmss_xmssmt_initialize_params(params); diff --git a/src/sig_stfl/xmss/external/wots.c b/src/sig_stfl/xmss/external/wots.c index 8ef4f026cd..067d48e6e4 100644 --- a/src/sig_stfl/xmss/external/wots.c +++ b/src/sig_stfl/xmss/external/wots.c @@ -14,10 +14,11 @@ */ static void expand_seed(const xmss_params *params, unsigned char *outseeds, const unsigned char *inseed, - const unsigned char *pub_seed, uint32_t addr[8]) + const unsigned char *pub_seed, uint32_t addr[8], + unsigned char *buf) { unsigned int i; - unsigned char *buf = malloc(params->n + 32); + unsigned char *prf_buf = buf + params->n + 32; set_hash_addr(addr, 0); set_key_and_mask(addr, 0); @@ -25,10 +26,8 @@ static void expand_seed(const xmss_params *params, for (i = 0; i < params->wots_len; i++) { set_chain_addr(addr, i); addr_to_bytes(buf + params->n, addr); - prf_keygen(params, outseeds + i*params->n, buf, inseed); + prf_keygen(params, outseeds + i*params->n, buf, inseed, prf_buf); } - - OQS_MEM_insecure_free(buf); } /** @@ -41,7 +40,8 @@ static void expand_seed(const xmss_params *params, static void gen_chain(const xmss_params *params, unsigned char *out, const unsigned char *in, unsigned int start, unsigned int steps, - const unsigned char *pub_seed, uint32_t addr[8]) + const unsigned char *pub_seed, uint32_t addr[8], + unsigned char *thash_buf) { unsigned int i; @@ -51,7 +51,7 @@ static void gen_chain(const xmss_params *params, /* Iterate 'steps' calls to the hash function. */ for (i = start; i < (start+steps) && i < params->wots_w; i++) { set_hash_addr(addr, i); - thash_f(params, out, out, pub_seed, addr); + thash_f(params, out, out, pub_seed, addr, thash_buf); } } @@ -88,6 +88,9 @@ static void wots_checksum(const xmss_params *params, int csum = 0; unsigned int csum_bytes_length = (params->wots_len2 * params->wots_log_w + 7) / 8; unsigned char *csum_bytes = malloc(csum_bytes_length); + if (csum_bytes == NULL) { + return; + } unsigned int i; /* Compute checksum. */ @@ -125,15 +128,21 @@ void wots_pkgen(const xmss_params *params, const unsigned char *pub_seed, uint32_t addr[8]) { unsigned int i; - + unsigned char *buf = malloc(2 * params->padding_len + 4 * params->n + 64); + if (buf == NULL) { + return; + } + /* The WOTS+ private key is derived from the seed. */ - expand_seed(params, pk, seed, pub_seed, addr); + expand_seed(params, pk, seed, pub_seed, addr, buf); for (i = 0; i < params->wots_len; i++) { set_chain_addr(addr, i); gen_chain(params, pk + i*params->n, pk + i*params->n, - 0, params->wots_w - 1, pub_seed, addr); + 0, params->wots_w - 1, pub_seed, addr, buf); } + + OQS_MEM_insecure_free(buf); } /** @@ -146,20 +155,25 @@ void wots_sign(const xmss_params *params, uint32_t addr[8]) { unsigned int *lengths = calloc(params->wots_len, sizeof(unsigned int)); + unsigned char *buf = malloc(2 * params->padding_len + 4 * params->n + 64); unsigned int i; + if (lengths == NULL || buf == NULL) { + return; + } chain_lengths(params, lengths, msg); /* The WOTS+ private key is derived from the seed. */ - expand_seed(params, sig, seed, pub_seed, addr); + expand_seed(params, sig, seed, pub_seed, addr, buf); for (i = 0; i < params->wots_len; i++) { set_chain_addr(addr, i); gen_chain(params, sig + i*params->n, sig + i*params->n, - 0, lengths[i], pub_seed, addr); + 0, lengths[i], pub_seed, addr, buf); } OQS_MEM_insecure_free(lengths); + OQS_MEM_insecure_free(buf); } /** @@ -172,15 +186,21 @@ void wots_pk_from_sig(const xmss_params *params, unsigned char *pk, const unsigned char *pub_seed, uint32_t addr[8]) { unsigned int *lengths = calloc(params->wots_len, sizeof(unsigned int )); + const size_t thash_buf_len = 2 * params->padding_len + 4 * params->n + 32; + unsigned char *thash_buf = malloc(thash_buf_len); unsigned int i; + if (lengths == NULL || thash_buf == NULL) { + return; + } chain_lengths(params, lengths, msg); for (i = 0; i < params->wots_len; i++) { set_chain_addr(addr, i); gen_chain(params, pk + i*params->n, sig + i*params->n, - lengths[i], params->wots_w - 1 - lengths[i], pub_seed, addr); + lengths[i], params->wots_w - 1 - lengths[i], pub_seed, addr, thash_buf); } OQS_MEM_insecure_free(lengths); + OQS_MEM_insecure_free(thash_buf); } diff --git a/src/sig_stfl/xmss/external/xmss_commons.c b/src/sig_stfl/xmss/external/xmss_commons.c index 645faf0112..3d7e469a4d 100644 --- a/src/sig_stfl/xmss/external/xmss_commons.c +++ b/src/sig_stfl/xmss/external/xmss_commons.c @@ -16,7 +16,8 @@ */ static void l_tree(const xmss_params *params, unsigned char *leaf, unsigned char *wots_pk, - const unsigned char *pub_seed, uint32_t addr[8]) + const unsigned char *pub_seed, uint32_t addr[8], + unsigned char *thash_buf) { unsigned int l = params->wots_len; unsigned int parent_nodes; @@ -31,7 +32,7 @@ static void l_tree(const xmss_params *params, set_tree_index(addr, i); /* Hashes the nodes at (i*2)*params->n and (i*2)*params->n + 1 */ thash_h(params, wots_pk + i*params->n, - wots_pk + (i*2)*params->n, pub_seed, addr); + wots_pk + (i*2)*params->n, pub_seed, addr, thash_buf); } /* If the row contained an odd number of nodes, the last node was not hashed. Instead, we pull it up to the next layer. */ @@ -55,10 +56,11 @@ static void l_tree(const xmss_params *params, static void compute_root(const xmss_params *params, unsigned char *root, const unsigned char *leaf, unsigned long leafidx, const unsigned char *auth_path, - const unsigned char *pub_seed, uint32_t addr[8]) + const unsigned char *pub_seed, uint32_t addr[8], + unsigned char *buffer, + unsigned char *thash_buf) { - uint32_t i; - unsigned char *buffer = malloc(2*params->n); + uint32_t i; /* If leafidx is odd (last bit = 1), current path element is a right child and auth_path has to go left. Otherwise it is the other way around. */ @@ -79,11 +81,11 @@ static void compute_root(const xmss_params *params, unsigned char *root, /* Pick the right or left neighbor, depending on parity of the node. */ if (leafidx & 1) { - thash_h(params, buffer + params->n, buffer, pub_seed, addr); + thash_h(params, buffer + params->n, buffer, pub_seed, addr, thash_buf); memcpy(buffer, auth_path, params->n); } else { - thash_h(params, buffer, buffer, pub_seed, addr); + thash_h(params, buffer, buffer, pub_seed, addr, thash_buf); memcpy(buffer + params->n, auth_path, params->n); } auth_path += params->n; @@ -93,9 +95,8 @@ static void compute_root(const xmss_params *params, unsigned char *root, set_tree_height(addr, params->tree_height - 1); leafidx >>= 1; set_tree_index(addr, leafidx); - thash_h(params, root, buffer, pub_seed, addr); + thash_h(params, root, buffer, pub_seed, addr, thash_buf); - OQS_MEM_insecure_free(buffer); } @@ -108,11 +109,15 @@ void gen_leaf_wots(const xmss_params *params, unsigned char *leaf, const unsigned char *sk_seed, const unsigned char *pub_seed, uint32_t ltree_addr[8], uint32_t ots_addr[8]) { - unsigned char *pk = malloc(params->wots_sig_bytes); + unsigned char *pk = malloc(params->wots_sig_bytes + 2 * params->padding_len + 6 * params->n + 32); + if (pk == NULL) { + return; + } + unsigned char *thash_buf = pk + params->wots_sig_bytes; wots_pkgen(params, pk, sk_seed, pub_seed, ots_addr); - l_tree(params, leaf, pk, pub_seed, ltree_addr); + l_tree(params, leaf, pk, pub_seed, ltree_addr, thash_buf); OQS_MEM_insecure_free(pk); } @@ -146,10 +151,16 @@ int xmssmt_core_sign_open(const xmss_params *params, const unsigned char *pub_root = pk; const unsigned char *pub_seed = pk + params->n; - unsigned char *tmp = malloc(params->wots_sig_bytes + params->n + params->n); + unsigned char *tmp = malloc(params->wots_sig_bytes + params->n + params->n + + + 2 *params->n + 2 * params->padding_len + 6 * params->n + 32); + if (tmp == NULL) { + return -1; + } unsigned char *wots_pk = tmp; unsigned char *leaf = tmp + params->wots_sig_bytes; unsigned char *root = leaf + params->n; + unsigned char *compute_root_buf = root + params->n; + unsigned char *thash_buf = compute_root_buf + 2*params->n; unsigned long long prefix_length = params->padding_len + 3*params->n; unsigned long long m_with_prefix_len = mlen + prefix_length; @@ -211,10 +222,10 @@ int xmssmt_core_sign_open(const xmss_params *params, /* Compute the leaf node using the WOTS public key. */ set_ltree_addr(ltree_addr, idx_leaf); - l_tree(params, leaf, wots_pk, pub_seed, ltree_addr); + l_tree(params, leaf, wots_pk, pub_seed, ltree_addr, thash_buf); /* Compute the root node of this subtree. */ - compute_root(params, root, leaf, idx_leaf, sm, pub_seed, node_addr); + compute_root(params, root, leaf, idx_leaf, sm, pub_seed, node_addr, compute_root_buf, thash_buf); sm += params->tree_height*params->n; } diff --git a/src/sig_stfl/xmss/external/xmss_core.c b/src/sig_stfl/xmss/external/xmss_core.c deleted file mode 100644 index 1052d4d7e5..0000000000 --- a/src/sig_stfl/xmss/external/xmss_core.c +++ /dev/null @@ -1,278 +0,0 @@ -// SPDX-License-Identifier: (Apache-2.0 OR MIT) AND CC0-1.0 -#include -#include -#include -#include - -#include "hash.h" -#include "hash_address.h" -#include "params.h" -#include "wots.h" -#include "utils.h" -#include "xmss_commons.h" -#include "xmss_core.h" - -/** - * For a given leaf index, computes the authentication path and the resulting - * root node using Merkle's TreeHash algorithm. - * Expects the layer and tree parts of subtree_addr to be set. - */ -static void treehash(const xmss_params *params, - unsigned char *root, unsigned char *auth_path, - const unsigned char *sk_seed, - const unsigned char *pub_seed, - uint32_t leaf_idx, const uint32_t subtree_addr[8]) -{ - unsigned char stack[(params->tree_height+1)*params->n]; - unsigned int heights[params->tree_height+1]; - unsigned int offset = 0; - - /* The subtree has at most 2^20 leafs, so uint32_t suffices. */ - uint32_t idx; - uint32_t tree_idx; - - /* We need all three types of addresses in parallel. */ - uint32_t ots_addr[8] = {0}; - uint32_t ltree_addr[8] = {0}; - uint32_t node_addr[8] = {0}; - - /* Select the required subtree. */ - copy_subtree_addr(ots_addr, subtree_addr); - copy_subtree_addr(ltree_addr, subtree_addr); - copy_subtree_addr(node_addr, subtree_addr); - - set_type(ots_addr, XMSS_ADDR_TYPE_OTS); - set_type(ltree_addr, XMSS_ADDR_TYPE_LTREE); - set_type(node_addr, XMSS_ADDR_TYPE_HASHTREE); - - for (idx = 0; idx < (uint32_t)(1 << params->tree_height); idx++) { - /* Add the next leaf node to the stack. */ - set_ltree_addr(ltree_addr, idx); - set_ots_addr(ots_addr, idx); - gen_leaf_wots(params, stack + offset*params->n, - sk_seed, pub_seed, ltree_addr, ots_addr); - offset++; - heights[offset - 1] = 0; - - /* If this is a node we need for the auth path.. */ - if ((leaf_idx ^ 0x1) == idx) { - memcpy(auth_path, stack + (offset - 1)*params->n, params->n); - } - - /* While the top-most nodes are of equal height.. */ - while (offset >= 2 && heights[offset - 1] == heights[offset - 2]) { - /* Compute index of the new node, in the next layer. */ - tree_idx = (idx >> (heights[offset - 1] + 1)); - - /* Hash the top-most nodes from the stack together. */ - /* Note that tree height is the 'lower' layer, even though we use - the index of the new node on the 'higher' layer. This follows - from the fact that we address the hash function calls. */ - set_tree_height(node_addr, heights[offset - 1]); - set_tree_index(node_addr, tree_idx); - thash_h(params, stack + (offset-2)*params->n, - stack + (offset-2)*params->n, pub_seed, node_addr); - offset--; - /* Note that the top-most node is now one layer higher. */ - heights[offset - 1]++; - - /* If this is a node we need for the auth path.. */ - if (((leaf_idx >> heights[offset - 1]) ^ 0x1) == tree_idx) { - memcpy(auth_path + heights[offset - 1]*params->n, - stack + (offset - 1)*params->n, params->n); - } - } - } - memcpy(root, stack, params->n); -} - -/** - * Given a set of parameters, this function returns the size of the secret key. - * This is implementation specific, as varying choices in tree traversal will - * result in varying requirements for state storage. - */ -unsigned long long xmss_xmssmt_core_sk_bytes(const xmss_params *params) -{ - return params->index_bytes + 4 * params->n; -} - -/* - * Generates a XMSS key pair for a given parameter set. - * Format sk: [(32bit) index || SK_SEED || SK_PRF || root || PUB_SEED] - * Format pk: [root || PUB_SEED], omitting algorithm OID. - */ -int xmss_core_keypair(const xmss_params *params, - unsigned char *pk, unsigned char *sk) -{ - /* The key generation procedure of XMSS and XMSSMT is exactly the same. - The only important detail is that the right subtree must be selected; - this requires us to correctly set the d=1 parameter for XMSS. */ - return xmssmt_core_keypair(params, pk, sk); -} - -/** - * Signs a message. Returns an array containing the signature followed by the - * message and an updated secret key. - */ -int xmss_core_sign(const xmss_params *params, - unsigned char *sk, - unsigned char *sm, unsigned long long *smlen, - const unsigned char *m, unsigned long long mlen) -{ - /* XMSS signatures are fundamentally an instance of XMSSMT signatures. - For d=1, as is the case with XMSS, some of the calls in the XMSSMT - routine become vacuous (i.e. the loop only iterates once, and address - management can be simplified a bit).*/ - return xmssmt_core_sign(params, sk, sm, smlen, m, mlen); -} - -/* - * Derives a XMSSMT key pair for a given parameter set. - * Seed must be 3*n long. - * Format sk: [(ceil(h/8) bit) index || SK_SEED || SK_PRF || root || PUB_SEED] - * Format pk: [root || PUB_SEED] omitting algorithm OID. - */ -int xmssmt_core_seed_keypair(const xmss_params *params, - unsigned char *pk, unsigned char *sk, - unsigned char *seed) -{ - /* We do not need the auth path in key generation, but it simplifies the - code to have just one treehash routine that computes both root and path - in one function. */ - unsigned char auth_path[params->tree_height * params->n]; - uint32_t top_tree_addr[8] = {0}; - set_layer_addr(top_tree_addr, params->d - 1); - - /* Initialize index to 0. */ - memset(sk, 0, params->index_bytes); - sk += params->index_bytes; - - /* Initialize SK_SEED and SK_PRF. */ - memcpy(sk, seed, 2 * params->n); - - /* Initialize PUB_SEED. */ - memcpy(sk + 3 * params->n, seed + 2 * params->n, params->n); - memcpy(pk + params->n, sk + 3*params->n, params->n); - - /* Compute root node of the top-most subtree. */ - treehash(params, pk, auth_path, sk, pk + params->n, 0, top_tree_addr); - memcpy(sk + 2*params->n, pk, params->n); - - return 0; -} - -/* - * Generates a XMSSMT key pair for a given parameter set. - * Format sk: [(ceil(h/8) bit) index || SK_SEED || SK_PRF || root || PUB_SEED] - * Format pk: [root || PUB_SEED] omitting algorithm OID. - */ -int xmssmt_core_keypair(const xmss_params *params, - unsigned char *pk, unsigned char *sk) -{ - unsigned char seed[3 * params->n]; - - OQS_randombytes(seed, 3 * params->n); - xmssmt_core_seed_keypair(params, pk, sk, seed); - - return 0; -} - -/** - * Signs a message. Returns an array containing the signature followed by the - * message and an updated secret key. - */ -int xmssmt_core_sign(const xmss_params *params, - unsigned char *sk, - unsigned char *sm, unsigned long long *smlen, - const unsigned char *m, unsigned long long mlen) -{ - const unsigned char *sk_seed = sk + params->index_bytes; - const unsigned char *sk_prf = sk + params->index_bytes + params->n; - const unsigned char *pub_root = sk + params->index_bytes + 2*params->n; - const unsigned char *pub_seed = sk + params->index_bytes + 3*params->n; - - unsigned long long prefix_length = params->padding_len + 3*params->n; - unsigned char m_with_prefix[mlen + prefix_length]; - - unsigned char root[params->n]; - unsigned char *mhash = root; - unsigned long long idx; - unsigned char idx_bytes_32[32]; - unsigned int i; - uint32_t idx_leaf; - - uint32_t ots_addr[8] = {0}; - set_type(ots_addr, XMSS_ADDR_TYPE_OTS); - - /* Already put the message in the right place, to make it easier to prepend - * things when computing the hash over the message. */ - memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, prefix_length); - memcpy(m_with_prefix + prefix_length, m, mlen); - *smlen = params->sig_bytes; - - /* Read and use the current index from the secret key. */ - idx = (unsigned long)bytes_to_ull(sk, params->index_bytes); - - /* Check if we can still sign with this sk. - * If not, return -2 - * - * If this is the last possible signature (because the max index value - * is reached), production implementations should delete the secret key - * to prevent accidental further use. - * - * For the case of total tree height of 64 we do not use the last signature - * to be on the safe side (there is no index value left to indicate that the - * key is finished, hence external handling would be necessary) - */ - if (idx >= ((1ULL << params->full_height) - 1)) { - // Delete secret key here. We only do this in memory, production code - // has to make sure that this happens on disk. - memset(sk, 0xFF, params->index_bytes); - memset(sk + params->index_bytes, 0, (params->sk_bytes - params->index_bytes)); - if (idx > ((1ULL << params->full_height) - 1)) - return -2; // We already used all one-time keys - if ((params->full_height == 64) && (idx == UINT64_MAX)) - return -2; // We already used all one-time keys - } - - memcpy(sm, sk, params->index_bytes); - - /************************************************************************* - * THIS IS WHERE PRODUCTION IMPLEMENTATIONS WOULD UPDATE THE SECRET KEY. * - *************************************************************************/ - /* Increment the index in the secret key. */ - ull_to_bytes(sk, params->index_bytes, idx + 1); - - /* Compute the digest randomization value. */ - ull_to_bytes(idx_bytes_32, 32, idx); - prf(params, sm + params->index_bytes, idx_bytes_32, sk_prf); - - /* Compute the message hash. */ - hash_message(params, mhash, sm + params->index_bytes, pub_root, idx, - m_with_prefix, - mlen); - sm += params->index_bytes + params->n; - - set_type(ots_addr, XMSS_ADDR_TYPE_OTS); - - for (i = 0; i < params->d; i++) { - idx_leaf = (idx & ((1 << params->tree_height)-1)); - idx = idx >> params->tree_height; - - set_layer_addr(ots_addr, i); - set_tree_addr(ots_addr, idx); - set_ots_addr(ots_addr, idx_leaf); - - /* Compute a WOTS signature. */ - /* Initially, root = mhash, but on subsequent iterations it is the root - of the subtree below the currently processed subtree. */ - wots_sign(params, sm, root, sk_seed, pub_seed, ots_addr); - sm += params->wots_sig_bytes; - - /* Compute the authentication path for the used WOTS leaf. */ - treehash(params, root, sm, sk_seed, pub_seed, idx_leaf, ots_addr); - sm += params->tree_height*params->n; - } - - return 0; -} diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c index d539c1f6c2..ed8886501f 100644 --- a/src/sig_stfl/xmss/external/xmss_core_fast.c +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -88,8 +88,8 @@ static void xmssmt_deserialize_state(const xmss_params *params, /* Skip past the 'regular' sk */ sk += params->index_bytes + 4*params->n; - // TODO These data sizes follow from the (former) test xmss_core_fast.c - // TODO They should be reconsidered / motivated more explicitly + // TODO (from upstream) These data sizes follow from the (former) test xmss_core_fast.c + // TODO (from upstream) They should be reconsidered / motivated more explicitly for (i = 0; i < 2*params->d - 1; i++) { states[i].stack = sk; @@ -162,20 +162,23 @@ static void memswap(void *a, void *b, void *t, unsigned long long len) * it is now necessary to make swaps 'real swaps'. This could be done in the * serialization function as well, but that causes more overhead */ -// TODO this should not be necessary if we keep better track of the states +// TODO (from upstream) this should not be necessary if we keep better track of the states static void deep_state_swap(const xmss_params *params, bds_state *a, bds_state *b) { if (a->stack == NULL || b->stack == NULL) { return; } - // TODO this is extremely ugly and should be refactored - // TODO right now, this ensures that both 'stack' and 'retain' fit + // TODO (from upstream) this is extremely ugly and should be refactored + // TODO (from upstream) right now, this ensures that both 'stack' and 'retain' fit unsigned char *t = malloc( ((params->tree_height + 1) > ((1 << params->bds_k) - params->bds_k - 1) ? (params->tree_height + 1) : ((1 << params->bds_k) - params->bds_k - 1)) * params->n); + if (t == NULL) { + return; + } unsigned int i; memswap(a->stack, b->stack, t, (params->tree_height + 1) * params->n); @@ -240,6 +243,12 @@ static void treehash_init(const xmss_params *params, uint32_t lastnode = index +(1<n, sizeof(unsigned char)); unsigned int *stacklevels = malloc((height + 1)*sizeof(unsigned int)); + unsigned char *thash_buf = malloc(2 * params->padding_len + 6 * params->n + 32); + + if (stack == NULL || stacklevels == NULL || thash_buf == NULL) { + return; + } + unsigned int stackoffset=0; unsigned int nodeh; @@ -274,7 +283,7 @@ static void treehash_init(const xmss_params *params, } set_tree_height(node_addr, stacklevels[stackoffset-1]); set_tree_index(node_addr, (idx >> (stacklevels[stackoffset-1]+1))); - thash_h(params, stack+(stackoffset-2)*params->n, stack+(stackoffset-2)*params->n, pub_seed, node_addr); + thash_h(params, stack+(stackoffset-2)*params->n, stack+(stackoffset-2)*params->n, pub_seed, node_addr, thash_buf); stacklevels[stackoffset-2]++; stackoffset--; } @@ -285,6 +294,7 @@ static void treehash_init(const xmss_params *params, OQS_MEM_insecure_free(stacklevels); OQS_MEM_insecure_free(stack); + OQS_MEM_insecure_free(thash_buf); } static void treehash_update(const xmss_params *params, @@ -309,6 +319,11 @@ static void treehash_update(const xmss_params *params, set_ots_addr(ots_addr, treehash->next_idx); unsigned char *nodebuffer = malloc(2 * params->n); + unsigned char *thash_buf = malloc(2 * params->padding_len + 6 * params->n + 32); + if (nodebuffer == NULL || thash_buf == NULL) { + return; + } + unsigned int nodeheight = 0; gen_leaf_wots(params, nodebuffer, sk_seed, pub_seed, ltree_addr, ots_addr); while (treehash->stackusage > 0 && state->stacklevels[state->stackoffset-1] == nodeheight) { @@ -316,7 +331,7 @@ static void treehash_update(const xmss_params *params, memcpy(nodebuffer, state->stack + (state->stackoffset-1)*params->n, params->n); set_tree_height(node_addr, nodeheight); set_tree_index(node_addr, (treehash->next_idx >> (nodeheight+1))); - thash_h(params, nodebuffer, nodebuffer, pub_seed, node_addr); + thash_h(params, nodebuffer, nodebuffer, pub_seed, node_addr, thash_buf); nodeheight++; treehash->stackusage--; state->stackoffset--; @@ -334,6 +349,7 @@ static void treehash_update(const xmss_params *params, } OQS_MEM_insecure_free(nodebuffer); + OQS_MEM_insecure_free(thash_buf); } /** @@ -393,6 +409,11 @@ static char bds_state_update(const xmss_params *params, uint32_t ltree_addr[8] = {0}; uint32_t node_addr[8] = {0}; uint32_t ots_addr[8] = {0}; + unsigned char *thash_buf = malloc(2 * params->padding_len + 6 * params->n + 32); + if (thash_buf == NULL) + { + return -1; + } unsigned int nodeh; int idx = state->next_leaf; @@ -434,12 +455,14 @@ static char bds_state_update(const xmss_params *params, } set_tree_height(node_addr, state->stacklevels[state->stackoffset-1]); set_tree_index(node_addr, (idx >> (state->stacklevels[state->stackoffset-1]+1))); - thash_h(params, state->stack+(state->stackoffset-2)*params->n, state->stack+(state->stackoffset-2)*params->n, pub_seed, node_addr); + thash_h(params, state->stack+(state->stackoffset-2)*params->n, state->stack+(state->stackoffset-2)*params->n, pub_seed, node_addr, thash_buf); state->stacklevels[state->stackoffset-2]++; state->stackoffset--; } state->next_leaf++; + + OQS_MEM_insecure_free(thash_buf); return 0; } @@ -458,6 +481,10 @@ static void bds_round(const xmss_params *params, unsigned int startidx; unsigned int offset, rowidx; unsigned char *buf = malloc(2 * params->n); + unsigned char *thash_buf = malloc(2 * params->padding_len + 6 * params->n + 32); + if (buf == NULL || thash_buf == NULL) { + return; + } uint32_t ots_addr[8] = {0}; uint32_t ltree_addr[8] = {0}; @@ -495,7 +522,7 @@ static void bds_round(const xmss_params *params, else { set_tree_height(node_addr, (tau-1)); set_tree_index(node_addr, leaf_idx >> tau); - thash_h(params, state->auth + tau * params->n, buf, pub_seed, node_addr); + thash_h(params, state->auth + tau * params->n, buf, pub_seed, node_addr, thash_buf); for (i = 0; i < tau; i++) { if (i < params->tree_height - params->bds_k) { memcpy(state->auth + i * params->n, state->treehash[i].node, params->n); @@ -519,6 +546,7 @@ static void bds_round(const xmss_params *params, } OQS_MEM_insecure_free(buf); + OQS_MEM_insecure_free(thash_buf); } /** @@ -554,9 +582,12 @@ int xmss_core_keypair(const xmss_params *params, { uint32_t addr[8] = {0}; - // TODO refactor BDS state not to need separate treehash instances + // TODO (from upstream) refactor BDS state not to need separate treehash instances bds_state state; treehash_inst *treehash = calloc(params->tree_height - params->bds_k, sizeof(treehash_inst)); + if (treehash == NULL) { + return -1; + } state.treehash = treehash; xmss_deserialize_state(params, &state, sk); @@ -612,11 +643,15 @@ int xmss_core_sign(const xmss_params *params, uint16_t i = 0; - // TODO refactor BDS state not to need separate treehash instances + // TODO (from upstream) refactor BDS state not to need separate treehash instances bds_state state; treehash_inst *treehash = calloc(params->tree_height - params->bds_k, sizeof(treehash_inst)); - state.treehash = treehash; + unsigned char *tmp = malloc(5 * params->n + params->padding_len + params->n + 32); + if (treehash == NULL || tmp == NULL) { + return -1; + } + state.treehash = treehash; /* Load the BDS state from sk. */ xmss_deserialize_state(params, &state, sk); @@ -644,7 +679,6 @@ int xmss_core_sign(const xmss_params *params, goto cleanup; } } - unsigned char *tmp = malloc(5 * params->n); unsigned char *sk_seed = tmp; unsigned char *sk_prf = sk_seed + params->n; @@ -670,6 +704,7 @@ int xmss_core_sign(const xmss_params *params, // Init working params unsigned char *R = pub_seed + params->n; unsigned char *msg_h = R + params->n; + unsigned char *prf_buf = msg_h + params->n; uint32_t ots_addr[8] = {0}; // --------------------------------- @@ -678,12 +713,15 @@ int xmss_core_sign(const xmss_params *params, // Message Hash: // First compute pseudorandom value - prf(params, R, idx_bytes_32, sk_prf); + prf(params, R, idx_bytes_32, sk_prf, prf_buf); /* Already put the message in the right place, to make it easier to prepend * things when computing the hash over the message. */ unsigned long long prefix_length = params->padding_len + 3*params->n; unsigned char *m_with_prefix = malloc((size_t)(mlen + prefix_length)); + if (m_with_prefix == NULL) { + return -1; + } memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, (size_t)prefix_length); memcpy(m_with_prefix + prefix_length, m, (size_t)mlen); @@ -762,9 +800,12 @@ int xmssmt_core_keypair(const xmss_params *params, unsigned int i; unsigned char *wots_sigs; - // TODO refactor BDS state not to need separate treehash instances + // TODO (from upstream) refactor BDS state not to need separate treehash instances bds_state *states = calloc(2*params->d - 1, sizeof(bds_state)); treehash_inst *treehash = calloc((2*params->d - 1) * (params->tree_height - params->bds_k), sizeof(treehash_inst)); + if (states == NULL || treehash == NULL) { + return -1; + } for (i = 0; i < 2*params->d - 1; i++) { states[i].treehash = treehash + i * (params->tree_height - params->bds_k); } @@ -834,14 +875,21 @@ int xmssmt_core_sign(const xmss_params *params, int needswap_upto = -1; unsigned int updates; - unsigned char *tmp = malloc(5 * params->n); - + // TODO (from upstream) refactor BDS state not to need separate treehash instances + bds_state *states = calloc(2*params->d - 1, sizeof(bds_state)); + treehash_inst *treehash = calloc((2*params->d - 1) * (params->tree_height - params->bds_k), sizeof(treehash_inst)); + unsigned char *tmp = malloc(5 * params->n + + params->padding_len + params->n + 32); + if (states == NULL || treehash == NULL || tmp == NULL) { + return -1; + } unsigned char *sk_seed = tmp; unsigned char *sk_prf = sk_seed + params->n; unsigned char *pub_seed = sk_prf + params->n; // Init working params unsigned char *R = pub_seed + params->n; unsigned char *msg_h = R + params->n; + unsigned char *prf_buf = msg_h + params->n; uint32_t addr[8] = {0}; uint32_t ots_addr[8] = {0}; unsigned char idx_bytes_32[32]; @@ -852,9 +900,6 @@ int xmssmt_core_sign(const xmss_params *params, unsigned char *m_with_prefix = NULL; int ret = 0; - // TODO refactor BDS state not to need separate treehash instances - bds_state *states = calloc(2*params->d - 1, sizeof(bds_state)); - treehash_inst *treehash = calloc((2*params->d - 1) * (params->tree_height - params->bds_k), sizeof(treehash_inst)); for (i = 0; i < 2*params->d - 1; i++) { states[i].stack = NULL; states[i].stackoffset = 0; @@ -921,7 +966,7 @@ int xmssmt_core_sign(const xmss_params *params, // Message Hash: // First compute pseudorandom value ull_to_bytes(idx_bytes_32, 32, idx); - prf(params, R, idx_bytes_32, sk_prf); + prf(params, R, idx_bytes_32, sk_prf, prf_buf); /* Already put the message in the right place, to make it easier to prepend * things when computing the hash over the message. */ diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c b/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c index 7868d68c94..ed25233be1 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_xmssmt.c @@ -14,7 +14,6 @@ #define XMSS_UNUSED_ATT #endif - // macro to en/disable OQS_SIG_STFL-only structs used only in sig&gen case: #ifdef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN #define XMSS_SIGGEN(xmss_v, XMSS_V) \ From 8524a16c4e3a4daa6e067af1f4a1dbb3858093d6 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Fri, 12 Apr 2024 11:55:57 -0400 Subject: [PATCH 46/68] Post-rebase cleanup --- .CMake/alg_support.cmake | 24 ++---------------------- 1 file changed, 2 insertions(+), 22 deletions(-) diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index bcf6150e7e..75bee17e6a 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -495,7 +495,7 @@ if(OQS_DIST_X86_64_BUILD OR (OQS_USE_AVX2_INSTRUCTIONS)) endif() endif() -##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ENABLE_BY_ALG_END +##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_ADD_ENABLE_BY_ALG_CONDITIONAL_END option(OQS_ENABLE_SIG_STFL_XMSS "Enable XMSS algorithm family" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_xmss_sha256_h10 "" ON "OQS_ENABLE_SIG_STFL_XMSS" OFF) @@ -582,26 +582,6 @@ if(OQS_ALLOW_SFTL_KEY_AND_SIG_GEN STREQUAL "ON") message(STATUS "Experimental stateful key and signature generation is enabled. Ensure secret keys are securely stored to prevent multiple simultaneous sign operations.") endif() -if((OQS_MINIMAL_BUILD STREQUAL "ON")) - message(FATAL_ERROR "OQS_MINIMAL_BUILD option ${OQS_MINIMAL_BUILD} no longer supported") -endif() - -if(NOT DEFINED OQS_ALGS_ENABLED OR OQS_ALGS_ENABLED STREQUAL "") - set(OQS_ALGS_ENABLED "All") -endif() - -if(NOT ((OQS_MINIMAL_BUILD STREQUAL "") OR (OQS_MINIMAL_BUILD STREQUAL "OFF"))) - filter_algs("${OQS_MINIMAL_BUILD}") -elseif (${OQS_ALGS_ENABLED} STREQUAL "STD") -##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_LIST_STANDARDIZED_ALGS_START - filter_algs("KEM_kyber_512;KEM_kyber_768;KEM_kyber_1024;SIG_dilithium_2;SIG_dilithium_3;SIG_dilithium_5;SIG_falcon_512;SIG_falcon_1024;SIG_sphincs_sha2_128f_simple;SIG_sphincs_sha2_128s_simple;SIG_sphincs_sha2_192f_simple;SIG_sphincs_sha2_192s_simple;SIG_sphincs_sha2_256f_simple;SIG_sphincs_sha2_256s_simple;SIG_sphincs_shake_128f_simple;SIG_sphincs_shake_128s_simple;SIG_sphincs_shake_192f_simple;SIG_sphincs_shake_192s_simple;SIG_sphincs_shake_256f_simple;SIG_sphincs_shake_256s_simple") -##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_LIST_STANDARDIZED_ALGS_END -elseif(${OQS_ALGS_ENABLED} STREQUAL "NIST_R4") - filter_algs("KEM_classic_mceliece_348864;KEM_classic_mceliece_348864f;KEM_classic_mceliece_460896;KEM_classic_mceliece_460896f;KEM_classic_mceliece_6688128;KEM_classic_mceliece_6688128f;KEM_classic_mceliece_6960119;KEM_classic_mceliece_6960119f;KEM_classic_mceliece_8192128;KEM_classic_mceliece_8192128f;KEM_hqc_128;KEM_hqc_192;KEM_hqc_256;KEM_bike_l1;KEM_bike_l3") -else() - message(STATUS "Alg enablement unchanged") -endif() - # Set XKCP (Keccak) required for Sphincs AVX2 code even if OpenSSL3 SHA3 is used: if (${OQS_ENABLE_SIG_SPHINCS} OR NOT ${OQS_USE_SHA3_OPENSSL}) set(OQS_ENABLE_SHA3_xkcp_low ON) @@ -614,4 +594,4 @@ if(CMAKE_SYSTEM_NAME MATCHES "Linux|Darwin") else() set(OQS_ENABLE_SHA3_xkcp_low_avx2 OFF) endif() -endif() \ No newline at end of file +endif() From 5da49e33c6dd35780dc65dd5b1a4200191436405 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Fri, 12 Apr 2024 12:05:51 -0400 Subject: [PATCH 47/68] Satisfy astyle --- src/common/sha2/sha2.c | 2 +- src/common/sha2/sha2_impl.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/common/sha2/sha2.c b/src/common/sha2/sha2.c index e0d3902e3b..b34e61273e 100644 --- a/src/common/sha2/sha2.c +++ b/src/common/sha2/sha2.c @@ -23,7 +23,7 @@ void OQS_SHA2_sha256_inc_blocks(OQS_SHA2_sha256_ctx *state, const uint8_t *in, s } void OQS_SHA2_sha256_inc(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t len) { - callbacks->SHA2_sha256_inc(state, in, len); + callbacks->SHA2_sha256_inc(state, in, len); } void OQS_SHA2_sha256_inc_finalize(uint8_t *out, OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t inlen) { diff --git a/src/common/sha2/sha2_impl.c b/src/common/sha2/sha2_impl.c index 1d6d4fb323..33805989e8 100644 --- a/src/common/sha2/sha2_impl.c +++ b/src/common/sha2/sha2_impl.c @@ -112,7 +112,7 @@ struct OQS_SHA2_callbacks sha2_default_callbacks = { SHA2_sha256, SHA2_sha256_inc_init, SHA2_sha256_inc_ctx_clone, - SHA2_sha256_inc, + SHA2_sha256_inc, SHA2_sha256_inc_blocks, SHA2_sha256_inc_finalize, SHA2_sha256_inc_ctx_release, From a535114d514dc5871a8f4d7ce9515954b9befc3a Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Mon, 15 Apr 2024 09:28:23 -0400 Subject: [PATCH 48/68] Fix macOS build error: lld -> llu --- tests/kat_sig_stfl.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 76a7307037..158c953fa5 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -311,7 +311,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { // Echo back remain if (FindMarker(fp_rsp, "remain = ")) { - fscanf(fp_rsp, "%lld", &sigs_remain); + fscanf(fp_rsp, "%llu", &sigs_remain); fprintf(fh, "remain = %llu\n", sigs_remain); } else { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_remaining failed!\n", method_name); @@ -320,7 +320,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { // Echo back max if (FindMarker(fp_rsp, "max = ")) { - fscanf(fp_rsp, "%lld", &sigs_maximum); + fscanf(fp_rsp, "%llu", &sigs_maximum); fprintf(fh, "max = %llu\n", sigs_maximum); } else { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sigs_total failed!\n", method_name); From 71ee535eca8398f170a489ad45556464816782de Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Mon, 15 Apr 2024 09:37:34 -0400 Subject: [PATCH 49/68] Bring EVP_DigestUpdate calls in line with main --- src/common/sha2/sha2_ossl.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/common/sha2/sha2_ossl.c b/src/common/sha2/sha2_ossl.c index 064fb61ad8..3aff58fab6 100644 --- a/src/common/sha2/sha2_ossl.c +++ b/src/common/sha2/sha2_ossl.c @@ -59,7 +59,7 @@ static void SHA2_sha256_inc_init(OQS_SHA2_sha256_ctx *state) { } static void SHA2_sha256_inc(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t len) { - OQS_OPENSSL_GUARD(EVP_DigestUpdate((EVP_MD_CTX *) state->ctx, in, len)); + OQS_OPENSSL_GUARD(OSSL_FUNC(EVP_DigestUpdate)((EVP_MD_CTX *) state->ctx, in, len)); } static void SHA2_sha256_inc_blocks(OQS_SHA2_sha256_ctx *state, const uint8_t *in, size_t inblocks) { From 154d8e4b1c07c5fa4f0c12303a9c2a38aa3a36b3 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Mon, 15 Apr 2024 09:38:32 -0400 Subject: [PATCH 50/68] Fix test program linkage for cross-compiling --- tests/CMakeLists.txt | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt index c59657f646..eb297a8047 100644 --- a/tests/CMakeLists.txt +++ b/tests/CMakeLists.txt @@ -105,6 +105,14 @@ endif() add_executable(kat_sig_stfl kat_sig_stfl.c test_helpers.c) target_link_libraries(kat_sig_stfl PRIVATE ${TEST_DEPS}) +if(CMAKE_SYSTEM_NAME STREQUAL "Windows" AND BUILD_SHARED_LIBS) + # workaround for Windows .dll + if(CMAKE_CROSSCOMPILING) + target_link_options(kat_sig_stfl PRIVATE -Wl,--allow-multiple-definition) + else() + target_link_options(kat_sig_stfl PRIVATE "/FORCE:MULTIPLE") + endif() +endif() add_executable(test_sig test_sig.c) target_link_libraries(test_sig PRIVATE ${TEST_DEPS}) From b2cdab6b79acaa60080328be1db02a0c55c52811 Mon Sep 17 00:00:00 2001 From: Duc Tri Nguyen Date: Tue, 16 Apr 2024 14:58:10 -0400 Subject: [PATCH 51/68] Fix typo from STFL to SFTL Signed-off-by: Duc Tri Nguyen --- .CMake/alg_support.cmake | 4 ++-- src/oqsconfig.h.cmake | 2 +- src/sig_stfl/sig_stfl.c | 12 ++++++------ src/sig_stfl/sig_stfl.h | 4 ++-- src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c | 2 +- tests/example_sig_stfl.c | 2 +- tests/kat_sig_stfl.c | 2 +- 7 files changed, 14 insertions(+), 14 deletions(-) diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index 75bee17e6a..c2c74230cc 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -564,7 +564,7 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h15_w8 "" ON "OQS_E cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h20_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) option(OQS_ENABLE_SIG_STFL_KEY_SIG_GEN "Enable stateful key and signature generation for research and experimentation" OFF) -cmake_dependent_option(OQS_ALLOW_SFTL_KEY_AND_SIG_GEN "" ON "OQS_ENABLE_SIG_STFL_KEY_SIG_GEN" OFF) +cmake_dependent_option(OQS_ALLOW_STFL_KEY_AND_SIG_GEN "" ON "OQS_ENABLE_SIG_STFL_KEY_SIG_GEN" OFF) if (${OQS_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_XMSS}) set(OQS_ALLOW_XMSS_KEY_AND_SIG_GEN ON) @@ -578,7 +578,7 @@ else() set(OQS_ALLOW_LMS_KEY_AND_SIG_GEN OFF) endif() -if(OQS_ALLOW_SFTL_KEY_AND_SIG_GEN STREQUAL "ON") +if(OQS_ALLOW_STFL_KEY_AND_SIG_GEN STREQUAL "ON") message(STATUS "Experimental stateful key and signature generation is enabled. Ensure secret keys are securely stored to prevent multiple simultaneous sign operations.") endif() diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index ac13bf093c..f2dd085519 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -238,6 +238,6 @@ #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 1 #cmakedefine OQS_ENABLE_SIG_STFL_KEY_SIG_GEN 1 -#cmakedefine OQS_ALLOW_SFTL_KEY_AND_SIG_GEN 1 +#cmakedefine OQS_ALLOW_STFL_KEY_AND_SIG_GEN 1 #cmakedefine OQS_ALLOW_XMSS_KEY_AND_SIG_GEN 1 #cmakedefine OQS_ALLOW_LMS_KEY_AND_SIG_GEN 1 \ No newline at end of file diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 9299975348..d0047108c8 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -878,7 +878,7 @@ OQS_API OQS_SIG_STFL *OQS_SIG_STFL_new(const char *method_name) { } OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key) { -#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#ifndef OQS_ALLOW_STFL_KEY_AND_SIG_GEN (void)sig; (void)public_key; (void)secret_key; @@ -895,7 +895,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_keypair(const OQS_SIG_STFL *sig, uint8_t *public OQS_API OQS_STATUS OQS_SIG_STFL_sign(const OQS_SIG_STFL *sig, uint8_t *signature, size_t *signature_len, const uint8_t *message, size_t message_len, OQS_SIG_STFL_SECRET_KEY *secret_key) { -#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#ifndef OQS_ALLOW_STFL_KEY_AND_SIG_GEN (void)sig; (void)signature; (void)signature_len; @@ -921,7 +921,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_verify(const OQS_SIG_STFL *sig, const uint8_t *m } OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned long long *remain, const OQS_SIG_STFL_SECRET_KEY *secret_key) { -#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#ifndef OQS_ALLOW_STFL_KEY_AND_SIG_GEN (void)sig; (void)remain; (void)secret_key; @@ -932,11 +932,11 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_remaining(const OQS_SIG_STFL *sig, unsigned } else { return OQS_SUCCESS; } -#endif //OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#endif //OQS_ALLOW_STFL_KEY_AND_SIG_GEN } OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned long long *max, const OQS_SIG_STFL_SECRET_KEY *secret_key) { -#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#ifndef OQS_ALLOW_STFL_KEY_AND_SIG_GEN (void)sig; (void)max; (void)secret_key; @@ -947,7 +947,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_sigs_total(const OQS_SIG_STFL *sig, unsigned lon } else { return OQS_SUCCESS; } -#endif //OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#endif //OQS_ALLOW_STFL_KEY_AND_SIG_GEN } OQS_API void OQS_SIG_STFL_free(OQS_SIG_STFL *sig) { diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index b0cb69b843..615c18738f 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -178,7 +178,7 @@ OQS_API int OQS_SIG_STFL_alg_count(void); */ OQS_API int OQS_SIG_STFL_alg_is_enabled(const char *method_name); -#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#ifndef OQS_ALLOW_STFL_KEY_AND_SIG_GEN #define OQS_SIG_STFL OQS_SIG #else /** @@ -284,7 +284,7 @@ typedef struct OQS_SIG_STFL { OQS_STATUS (*sigs_total)(unsigned long long *total, const OQS_SIG_STFL_SECRET_KEY *secret_key); } OQS_SIG_STFL; -#endif //OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#endif //OQS_ALLOW_STFL_KEY_AND_SIG_GEN /** * @brief OQS_SIG_STFL_SECRET_KEY object for stateful signature schemes diff --git a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c index 3f280e024c..0a0664291a 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmssmt_functions.c @@ -15,7 +15,7 @@ #endif /* -------------- XMSSMT -------------- */ -#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#ifndef OQS_ALLOW_STFL_KEY_AND_SIG_GEN OQS_API OQS_STATUS OQS_SIG_STFL_alg_xmssmt_sign(XMSS_UNUSED_ATT uint8_t *signature, XMSS_UNUSED_ATT size_t *signature_len, XMSS_UNUSED_ATT const uint8_t *message, XMSS_UNUSED_ATT size_t message_len, XMSS_UNUSED_ATT OQS_SIG_STFL_SECRET_KEY *secret_key) { return OQS_ERROR; diff --git a/tests/example_sig_stfl.c b/tests/example_sig_stfl.c index cdcd9f6472..a2b3ba21c1 100644 --- a/tests/example_sig_stfl.c +++ b/tests/example_sig_stfl.c @@ -121,7 +121,7 @@ static OQS_STATUS stfl_example(char *method_name) { } int main(void) { -#ifndef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#ifndef OQS_ALLOW_STFL_KEY_AND_SIG_GEN OQS_init(); printf("Stateful signature algorithms key and signature generation is not enabled.\n"); if (stfl_example((char *)"XMSS-SHA2_10_256") == OQS_ERROR && stfl_example((char *)"LMS_SHA256_H10_W4") == OQS_ERROR) { diff --git a/tests/kat_sig_stfl.c b/tests/kat_sig_stfl.c index 158c953fa5..5c99f5d5bd 100644 --- a/tests/kat_sig_stfl.c +++ b/tests/kat_sig_stfl.c @@ -242,7 +242,7 @@ OQS_STATUS sig_stfl_kat(const char *method_name, const char *katfile) { OQS_fprintBstr(fh, "msg = ", msg, msg_len); -#ifdef OQS_ALLOW_SFTL_KEY_AND_SIG_GEN +#ifdef OQS_ALLOW_STFL_KEY_AND_SIG_GEN rc = OQS_SIG_STFL_sign(sig, signature, &signature_len, msg, msg_len, secret_key); if (rc != OQS_SUCCESS) { fprintf(stderr, "[kat_stfl_sig] %s ERROR: OQS_SIG_STFL_sign failed!\n", method_name); From e92aab307f41b492c684438c4fdd8caae7b7a820 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Thu, 18 Apr 2024 13:02:13 -0400 Subject: [PATCH 52/68] Stateful sigs: Rename keygen / sign option, add more tests, fix memory errors (#1755) * Add "EXPERIMENTAL" to keygen / sign enable switch * Add CI tests for macos * Zero-initialize aux_data * Fix test program arg parsing * Fix typo * Valgrind testing for stateful sigs * Satisfy astyle * Use calloc instead of malloc / memset --- .CMake/alg_support.cmake | 8 ++++---- .github/workflows/android.yml | 2 +- .github/workflows/apple.yml | 2 +- .github/workflows/unix.yml | 19 ++++++++++--------- .github/workflows/windows.yml | 4 ++-- CONFIGURE.md | 6 +++--- src/oqsconfig.h.cmake | 4 ++-- src/sig_stfl/lms/sig_stfl_lms_functions.c | 2 +- tests/test_leaks.py | 16 ++++++++++++++++ tests/test_sig_stfl.c | 7 ++++++- 10 files changed, 46 insertions(+), 24 deletions(-) diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index c2c74230cc..3810585a9c 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -563,16 +563,16 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h10_w8 "" ON "OQS_E cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h15_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h20_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) -option(OQS_ENABLE_SIG_STFL_KEY_SIG_GEN "Enable stateful key and signature generation for research and experimentation" OFF) -cmake_dependent_option(OQS_ALLOW_STFL_KEY_AND_SIG_GEN "" ON "OQS_ENABLE_SIG_STFL_KEY_SIG_GEN" OFF) +option(OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN "Enable stateful key and signature generation for research and experimentation" OFF) +cmake_dependent_option(OQS_ALLOW_STFL_KEY_AND_SIG_GEN "" ON "OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN" OFF) -if (${OQS_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_XMSS}) +if (${OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_XMSS}) set(OQS_ALLOW_XMSS_KEY_AND_SIG_GEN ON) else() set(OQS_ALLOW_XMSS_KEY_AND_SIG_GEN OFF) endif() -if (${OQS_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_LMS}) +if (${OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_LMS}) set(OQS_ALLOW_LMS_KEY_AND_SIG_GEN ON) else() set(OQS_ALLOW_LMS_KEY_AND_SIG_GEN OFF) diff --git a/.github/workflows/android.yml b/.github/workflows/android.yml index 26b4d13186..d54b6ebcde 100644 --- a/.github/workflows/android.yml +++ b/.github/workflows/android.yml @@ -16,4 +16,4 @@ jobs: - name: Checkout code uses: actions/checkout@v3 - name: Build project - run: ./scripts/build-android.sh $ANDROID_NDK_HOME -a ${{ matrix.abi }} -f "-DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }}" + run: ./scripts/build-android.sh $ANDROID_NDK_HOME -a ${{ matrix.abi }} -f "-DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }}" diff --git a/.github/workflows/apple.yml b/.github/workflows/apple.yml index bb9a2f47b6..69021d60a9 100644 --- a/.github/workflows/apple.yml +++ b/.github/workflows/apple.yml @@ -17,6 +17,6 @@ jobs: - name: Generate project run: | cmake -B build --toolchain .CMake/apple.cmake -DOQS_USE_OPENSSL=OFF -DPLATFORM=${{ matrix.platform }} \ - -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . + -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build project run: cmake --build build diff --git a/.github/workflows/unix.yml b/.github/workflows/unix.yml index 3e534319c7..fa459f9aed 100644 --- a/.github/workflows/unix.yml +++ b/.github/workflows/unix.yml @@ -74,19 +74,19 @@ jobs: include: - name: alpine container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: alpine-no-stfl-key-sig-gen container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: alpine-openssl-all container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: alpine-noopenssl container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=OFF -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=OFF -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: focal-nistr4-openssl container: openquantumsafe/ci-ubuntu-focal-x86_64:latest @@ -102,11 +102,11 @@ jobs: PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py - name: address-sanitizer container: openquantumsafe/ci-ubuntu-focal-x86_64:latest - CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --numprocesses=auto --maxprocesses=10 - name: address-sanitizer-no-stfl-key-sig-gen container: openquantumsafe/ci-ubuntu-focal-x86_64:latest - CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --numprocesses=auto --maxprocesses=10 container: image: ${{ matrix.container }} @@ -145,11 +145,11 @@ jobs: include: - name: armhf ARCH: armhf - CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: armhf-no-stfl-key-sig-gen ARCH: armhf - CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py # no longer supporting armel # - name: armel @@ -215,6 +215,7 @@ jobs: - macos-13 - macos-14 CMAKE_ARGS: + - -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON - -DCMAKE_C_COMPILER=gcc-13 - -DOQS_USE_OPENSSL=OFF - -DBUILD_SHARED_LIBS=ON -DOQS_DIST_BUILD=OFF @@ -280,4 +281,4 @@ jobs: working-directory: build - name: Run tests timeout-minutes: 60 - run: mkdir -p tmp && python3 -m pytest --verbose --ignore=tests/test_code_conventions.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py \ No newline at end of file + run: mkdir -p tmp && python3 -m pytest --verbose --ignore=tests/test_code_conventions.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py diff --git a/.github/workflows/windows.yml b/.github/workflows/windows.yml index de0d5e82db..3c3e483337 100644 --- a/.github/workflows/windows.yml +++ b/.github/workflows/windows.yml @@ -12,7 +12,7 @@ jobs: steps: - uses: actions/checkout@v3 - name: Generate Project - run: cmake -B build --toolchain .CMake/toolchain_windows_arm64.cmake -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . + run: cmake -B build --toolchain .CMake/toolchain_windows_arm64.cmake -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build Project run: cmake --build build @@ -26,7 +26,7 @@ jobs: steps: - uses: actions/checkout@v3 - name: Generate Project - run: cmake -B build --toolchain ${{ matrix.toolchain }} -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . + run: cmake -B build --toolchain ${{ matrix.toolchain }} -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build Project run: cmake --build build - name: Test dependencies diff --git a/CONFIGURE.md b/CONFIGURE.md index 89bd01e042..a537f94be5 100644 --- a/CONFIGURE.md +++ b/CONFIGURE.md @@ -125,10 +125,10 @@ Only has an effect if the system supports `dlopen` and ELF binary format, such a XMSS and LMS are the two supported Hash-Based Signatures schemes. `OQS_ENABLE_SIG_STFL_XMSS` and `OQS_ENABLE_SIG_STFL_LMS` control these algorithms, which are disabled by default. -A thrid variable, `OQS_ENABLE_SIG_STFL_KEY_SIG_GEN`, also controls the ability to generate keys and signatures. This is also disabled by default. +A third variable, `OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN`, also controls the ability to generate keys and signatures. This is also disabled by default. Each of these variables can be set to `ON` or `OFF`. When all three are `ON`, stateful signatures are fully functional and can generate key pairs, sign data, and verify signatures. -If `OQS_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF` signature verification is the only functional operation. +If `OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF` signature verification is the only functional operation. Standards bodies, such as NIST, recommend that key and signature generation only by done in hardware in order to best enforce the one-time use of secret keys. Keys stored in a file system are extremely susceptible to simultaneous use. @@ -137,7 +137,7 @@ When enabled in this library a warning message will be generated by the config p By default, - `OQS_ENABLE_SIG_STFL_XMSS` is `OFF` - `OQS_ENABLE_SIG_STFL_LMS` is `OFF` -- `OQS_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF`. +- `OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF`. **Default**: `OFF`. diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index f2dd085519..414b759cfa 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -237,7 +237,7 @@ #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 1 -#cmakedefine OQS_ENABLE_SIG_STFL_KEY_SIG_GEN 1 +#cmakedefine OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN 1 #cmakedefine OQS_ALLOW_STFL_KEY_AND_SIG_GEN 1 #cmakedefine OQS_ALLOW_XMSS_KEY_AND_SIG_GEN 1 -#cmakedefine OQS_ALLOW_LMS_KEY_AND_SIG_GEN 1 \ No newline at end of file +#cmakedefine OQS_ALLOW_LMS_KEY_AND_SIG_GEN 1 diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index d0b1559e2d..498324d3da 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -281,7 +281,7 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uin //Aux Data size_t len_aux_data = DEFAULT_AUX_DATA; - uint8_t *aux_data = malloc(sizeof(uint8_t) * len_aux_data); + uint8_t *aux_data = calloc(len_aux_data, sizeof(uint8_t)); if (aux_data == NULL) { OQS_MEM_insecure_free( oqs_key_data->sec_key); OQS_MEM_insecure_free(oqs_key_data); diff --git a/tests/test_leaks.py b/tests/test_leaks.py index e0e8f395d3..f75fece11a 100644 --- a/tests/test_leaks.py +++ b/tests/test_leaks.py @@ -24,6 +24,22 @@ def test_sig_leak(sig_name): ["valgrind", "-s", "--error-exitcode=1", "--leak-check=full", "--show-leak-kinds=all", helpers.path_to_executable('test_sig'), sig_name], ) +@helpers.filtered_test +@pytest.mark.parametrize('sig_stfl_name', helpers.available_sig_stfls_by_name()) +def test_sig_stfl_leak(sig_stfl_name): + if not(helpers.is_sig_stfl_enabled_by_name(sig_stfl_name)): pytest.skip('Not enabled') + if sys.platform != "linux" or os.system("grep ubuntu /etc/os-release") != 0 or os.system("uname -a | grep x86_64") != 0: pytest.skip('Leak testing not supported on this platform') + if sig_stfl_name.startswith("XMSS"): + katfile = helpers.get_katfile("sig_stfl", sig_stfl_name) + if not katfile: pytest.skip("KATs file is missing") + helpers.run_subprocess( + ["valgrind", "-s", "--error-exitcode=1", "--leak-check=full", "--show-leak-kinds=all", helpers.path_to_executable('test_sig_stfl'), sig_stfl_name, katfile], + ) + else: + helpers.run_subprocess( + ["valgrind", "-s", "--error-exitcode=1", "--leak-check=full", "--show-leak-kinds=all", helpers.path_to_executable('test_sig_stfl'), sig_stfl_name], + ) + if __name__ == "__main__": import sys pytest.main(sys.argv) diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 5626eee5b3..30894ee19f 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -1029,7 +1029,7 @@ int main(int argc, char **argv) { printf("Testing stateful signature algorithms using liboqs version %s\n", OQS_version()); if (argc < 2) { - fprintf(stderr, "Usage: test_sig_stfl algname katfile\n"); + fprintf(stderr, "Usage: test_sig_stfl algname [katfile]\n"); fprintf(stderr, " algname: "); for (size_t i = 0; i < OQS_SIG_STFL_algs_length; i++) { if (i > 0) { @@ -1049,6 +1049,11 @@ int main(int argc, char **argv) { int is_xmss = 0; if (strstr(alg_name, "XMSS") != NULL) { is_xmss = 1; + if (argc < 3) { + fprintf(stderr, "KAT file must be provided for XMSS.\n"); + OQS_destroy(); + return EXIT_FAILURE; + } } /* From b0758784cc5f4171ff264964a9f79e62e9503e30 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Mon, 22 Apr 2024 13:57:24 -0400 Subject: [PATCH 53/68] Clean up OQS_SIG_STFL_SECRET_KEY_free --- src/sig_stfl/sig_stfl.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index d0047108c8..4015297572 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -1347,8 +1347,7 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_free(OQS_SIG_STFL_SECRET_KEY *sk) { sk->free_key(sk); /* Free sk object */ - OQS_MEM_secure_free(sk, sizeof(sk)); - sk = NULL; + OQS_MEM_secure_free(sk, sizeof(*sk)); } OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { From db000c263a87d6830b125e045059664fc6b95cb5 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Thu, 25 Apr 2024 20:39:42 -0400 Subject: [PATCH 54/68] Remove unused sig member --- src/sig_stfl/sig_stfl.h | 3 --- src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c | 3 --- 2 files changed, 6 deletions(-) diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 615c18738f..976e19e51b 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -292,9 +292,6 @@ typedef struct OQS_SIG_STFL { typedef struct OQS_SIG_STFL_SECRET_KEY { - /** Associated signature object */ - OQS_SIG_STFL *sig; - /* The (maximum) length, in bytes, of secret keys for this signature scheme. */ size_t length_secret_key; diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index 1ccc8e8c09..ba526bc7e8 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -39,9 +39,6 @@ extern inline OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_XMSS_new(size_t length_sec // Set application specific context sk->context = NULL; - // Point to associated OQS_SIG_STFL object - sk->sig = NULL; - // Mutual exclusion struct sk->mutex = NULL; From 9b60f60b42a5570b86a511439925dcca48554c00 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Fri, 26 Apr 2024 09:42:21 -0400 Subject: [PATCH 55/68] Naming convention for serialize / deserialize functions --- src/sig_stfl/sig_stfl.c | 4 ++-- src/sig_stfl/sig_stfl.h | 4 ++-- tests/test_sig_stfl.c | 6 +++--- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 4015297572..415a607295 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -1358,7 +1358,7 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, s } /* Convert secret key object to byte string */ -OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk) { +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk) { if (sk == NULL || sk_len == NULL || sk_buf_ptr == NULL || sk->serialize_key == NULL) { return OQS_ERROR; } @@ -1367,7 +1367,7 @@ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_ } /* Insert secret key byte string in an Stateful secret key object */ -OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t key_len, const uint8_t *sk_buf, void *context) { +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, const size_t key_len, const uint8_t *sk_buf, void *context) { if (sk == NULL || sk_buf == NULL || sk->deserialize_key == NULL) { return OQS_ERROR; } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 976e19e51b..b6eded5d76 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -634,7 +634,7 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, s * * @note The function allocates memory for the byte array, and it is the caller's responsibility to free this memory after use. */ -OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); /** * Deserialize a byte array into an OQS_SIG_STFL_SECRET_KEY object. @@ -650,7 +650,7 @@ OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_serialize_key(uint8_t **sk_buf_ptr, size_ * * @attention The caller is responsible for freeing the `sk_buf` memory when it is no longer needed. */ -OQS_API OQS_STATUS OQS_SECRET_KEY_STFL_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf, void *context); +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf, void *context); #if defined(__cplusplus) // extern "C" diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index 30894ee19f..a916a4fd96 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -470,7 +470,7 @@ static OQS_STATUS sig_stfl_test_correctness(const char *method_name, const char goto err; } - rc = OQS_SECRET_KEY_STFL_serialize_key(&sk_buf, &sk_buf_len, secret_key); + rc = OQS_SIG_STFL_SECRET_KEY_serialize(&sk_buf, &sk_buf_len, secret_key); if (rc != OQS_SUCCESS) { goto err; } @@ -631,7 +631,7 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name, const char * } /* write sk key to disk */ - rc = OQS_SECRET_KEY_STFL_serialize_key(&to_file_sk_buf, &to_file_sk_len, sk); + rc = OQS_SIG_STFL_SECRET_KEY_serialize(&to_file_sk_buf, &to_file_sk_len, sk); if (rc != OQS_SUCCESS) { goto err; } @@ -669,7 +669,7 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name, const char * } context_2 = strdup(file_store_name); - rc = OQS_SECRET_KEY_STFL_deserialize_key(sk_from_file, from_file_sk_len, from_file_sk_buf, (void *)context_2); + rc = OQS_SIG_STFL_SECRET_KEY_deserialize(sk_from_file, from_file_sk_len, from_file_sk_buf, (void *)context_2); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS restore %s from file failed.\n", method_name); From f9a4f03109d5495d2b35f0dc8248f087c14e5377 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Fri, 26 Apr 2024 10:27:52 -0400 Subject: [PATCH 56/68] Switch order of params for deserialize Signed-off-by: Spencer Wilson --- src/sig_stfl/sig_stfl.c | 2 +- src/sig_stfl/sig_stfl.h | 2 +- tests/test_sig_stfl.c | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 415a607295..00d02436bc 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -1367,7 +1367,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_ } /* Insert secret key byte string in an Stateful secret key object */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, const size_t key_len, const uint8_t *sk_buf, void *context) { +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t key_len, void *context) { if (sk == NULL || sk_buf == NULL || sk->deserialize_key == NULL) { return OQS_ERROR; } diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index b6eded5d76..dfdc8145d4 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -650,7 +650,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_ * * @attention The caller is responsible for freeing the `sk_buf` memory when it is no longer needed. */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, size_t key_len, const uint8_t *sk_buf, void *context); +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, size_t key_len, void *context); #if defined(__cplusplus) // extern "C" diff --git a/tests/test_sig_stfl.c b/tests/test_sig_stfl.c index a916a4fd96..a21119138a 100644 --- a/tests/test_sig_stfl.c +++ b/tests/test_sig_stfl.c @@ -669,7 +669,7 @@ static OQS_STATUS sig_stfl_test_secret_key(const char *method_name, const char * } context_2 = strdup(file_store_name); - rc = OQS_SIG_STFL_SECRET_KEY_deserialize(sk_from_file, from_file_sk_len, from_file_sk_buf, (void *)context_2); + rc = OQS_SIG_STFL_SECRET_KEY_deserialize(sk_from_file, from_file_sk_buf, from_file_sk_len, (void *)context_2); if (rc != OQS_SUCCESS) { fprintf(stderr, "OQS restore %s from file failed.\n", method_name); From 8c1529d4a8abe06b3d7996b8e20559ad1c71301d Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Fri, 26 Apr 2024 11:24:12 -0400 Subject: [PATCH 57/68] Swap param order down the stack; rename length param; update documentation Signed-off-by: Spencer Wilson --- src/sig_stfl/lms/sig_stfl_lms.c | 6 +++--- src/sig_stfl/lms/sig_stfl_lms.h | 2 +- src/sig_stfl/lms/sig_stfl_lms_functions.c | 2 +- src/sig_stfl/sig_stfl.c | 10 +++++----- src/sig_stfl/sig_stfl.h | 20 +++++++++---------- src/sig_stfl/xmss/sig_stfl_xmss.h | 2 +- .../xmss/sig_stfl_xmss_secret_key_functions.c | 2 +- 7 files changed, 22 insertions(+), 22 deletions(-) diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index 7e5e99ea45..33d18b6c3c 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -55,7 +55,7 @@ OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h20_w8_h20_w8_keypair(uint8_t *public_key static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); /* Insert lms byte string in an LMS secret key object */ -static OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); +static OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t sk_len, void *context); static void OQS_SECRET_KEY_LMS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); @@ -288,8 +288,8 @@ static OQS_STATUS OQS_SECRET_KEY_LMS_serialize_key(uint8_t **sk_buf_ptr, size_t } /* Insert lms byte string in an LMS secret key object */ -static OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context) { - return oqs_deserialize_lms_key(sk, sk_len, sk_buf, context); +static OQS_STATUS OQS_SECRET_KEY_LMS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t sk_len, void *context) { + return oqs_deserialize_lms_key(sk, sk_buf, sk_len, context); } static void OQS_SECRET_KEY_LMS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context) { diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index c5deed2f40..941f17a0ff 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -326,7 +326,7 @@ int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, const uint8_t *sm, si void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk); OQS_STATUS oqs_serialize_lms_key(uint8_t **sk_key, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); -OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); +OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t sk_len, void *context); void oqs_lms_key_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); // ---------------------------- FUNCTIONS INDEPENDENT OF VARIANT ----------------------------------------- diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index 498324d3da..f3660e40d8 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -728,7 +728,7 @@ OQS_STATUS oqs_serialize_lms_key(uint8_t **sk_key, size_t *sk_len, const OQS_SIG * Writes secret key + aux data if present * key_len is priv key length + aux length */ -OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context) { +OQS_STATUS oqs_deserialize_lms_key(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t sk_len, void *context) { oqs_lms_key_data *lms_key_data = NULL; uint8_t *lms_sk = NULL; diff --git a/src/sig_stfl/sig_stfl.c b/src/sig_stfl/sig_stfl.c index 00d02436bc..51d7865373 100644 --- a/src/sig_stfl/sig_stfl.c +++ b/src/sig_stfl/sig_stfl.c @@ -1358,21 +1358,21 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, s } /* Convert secret key object to byte string */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk) { - if (sk == NULL || sk_len == NULL || sk_buf_ptr == NULL || sk->serialize_key == NULL) { +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_t *sk_buf_len, const OQS_SIG_STFL_SECRET_KEY *sk) { + if (sk == NULL || sk_buf_len == NULL || sk_buf_ptr == NULL || sk->serialize_key == NULL) { return OQS_ERROR; } - return sk->serialize_key(sk_buf_ptr, sk_len, sk); + return sk->serialize_key(sk_buf_ptr, sk_buf_len, sk); } /* Insert secret key byte string in an Stateful secret key object */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t key_len, void *context) { +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t sk_buf_len, void *context) { if (sk == NULL || sk_buf == NULL || sk->deserialize_key == NULL) { return OQS_ERROR; } - return sk->deserialize_key(sk, key_len, sk_buf, context); + return sk->deserialize_key(sk, sk_buf, sk_buf_len, context); } /* OQS_SIG_STFL_SECRET_KEY_SET_lock callback function*/ diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index dfdc8145d4..91df350add 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -313,13 +313,13 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * The `sk_len` will contain the length of the byte stream. * * @param[out] sk_buf_ptr Pointer to the byte stream representing the serialized secret key. - * @param[out] sk_len Pointer to the length of the serialized byte stream. + * @param[out] sk_buf_len Pointer to the length of the serialized byte stream. * @param[in] sk Pointer to the `OQS_SIG_STFL_SECRET_KEY` object to serialize. * @return The number of bytes in the serialized byte stream upon success, or an OQS error code on failure. * * @attention The caller is responsible for ensuring that `sk` is a valid object before calling this function. */ - OQS_STATUS (*serialize_key)(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); + OQS_STATUS (*serialize_key)(uint8_t **sk_buf_ptr, size_t *sk_buf_len, const OQS_SIG_STFL_SECRET_KEY *sk); /** * Deserialize a byte stream into the internal representation of a stateful secret key. @@ -329,14 +329,14 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * useful for reconstructing key objects from persisted or transmitted state. * * @param[out] sk Pointer to an uninitialized `OQS_SIG_STFL_SECRET_KEY` object to hold the secret key. - * @param[in] sk_len The length of the secret key byte stream. * @param[in] sk_buf Pointer to the byte stream containing the serialized secret key data. + * @param[in] sk_buf_len The length of the secret key byte stream. * @param[in] context Pointer to application-specific data, handled externally, associated with the key. * @returns OQS_SUCCESS if the deserialization succeeds, with the `sk` object populated with the key material. * * @attention The caller is responsible for ensuring that `sk_buf` is securely deallocated when it's no longer needed. */ - OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); + OQS_STATUS (*deserialize_key)(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t sk_buf_len, void *context); /** * Secret Key Locking Function @@ -360,14 +360,14 @@ typedef struct OQS_SIG_STFL_SECRET_KEY { * Callback function used to securely store key data after a signature generation. * When populated, this pointer points to the application-supplied secure storage function. * @param[in] sk_buf The serialized secret key data to secure store - * @param[in] buf_len length of data to secure + * @param[in] sk_buf_len length of data to secure * @param[in] context application supplied data used to locate where this secret key * is stored (passed in at the time the function pointer was set). * * @return OQS_SUCCESS or OQS_ERROR * Ideally written to a secure device. */ - OQS_STATUS (*secure_store_scrt_key)(uint8_t *sk_buf, size_t buf_len, void *context); + OQS_STATUS (*secure_store_scrt_key)(uint8_t *sk_buf, size_t sk_buf_len, void *context); /** * Free internal variant-specific data @@ -628,13 +628,13 @@ OQS_API void OQS_SIG_STFL_SECRET_KEY_SET_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, s * Converts an OQS_SIG_STFL_SECRET_KEY object into a byte array for storage or transmission. * * @param[out] sk_buf_ptr Pointer to the allocated byte array containing the serialized key. - * @param[out] sk_len Length of the serialized key byte array. + * @param[out] sk_buf_len Length of the serialized key byte array. * @param[in] sk Pointer to the OQS_SIG_STFL_SECRET_KEY object to be serialized. * @return OQS_SUCCESS on success, or an OQS error code on failure. * * @note The function allocates memory for the byte array, and it is the caller's responsibility to free this memory after use. */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_t *sk_buf_len, const OQS_SIG_STFL_SECRET_KEY *sk); /** * Deserialize a byte array into an OQS_SIG_STFL_SECRET_KEY object. @@ -643,14 +643,14 @@ OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_serialize(uint8_t **sk_buf_ptr, size_ * After deserialization, the secret key object can be used for subsequent cryptographic operations. * * @param[out] sk A pointer to the secret key object that will be populated from the binary data. - * @param[in] key_len The length of the binary secret key data in bytes. * @param[in] sk_buf The buffer containing the serialized secret key data. + * @param[in] sk_buf_len The length of the binary secret key data in bytes. * @param[in] context Application-specific data used to maintain context about the secret key. * @return OQS_SUCCESS if deserialization was successful; otherwise, OQS_ERROR. * * @attention The caller is responsible for freeing the `sk_buf` memory when it is no longer needed. */ -OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, size_t key_len, void *context); +OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, size_t sk_buf_len, void *context); #if defined(__cplusplus) // extern "C" diff --git a/src/sig_stfl/xmss/sig_stfl_xmss.h b/src/sig_stfl/xmss/sig_stfl_xmss.h index 6ee03f3b12..a6d0aad55b 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss.h +++ b/src/sig_stfl/xmss/sig_stfl_xmss.h @@ -573,7 +573,7 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_le OQS_STATUS OQS_SECRET_KEY_XMSS_inner_serialize_key(uint8_t **sk_buf_ptr, size_t *sk_len, const OQS_SIG_STFL_SECRET_KEY *sk); /* Deserialize XMSS byte string into an XMSS secret key data */ -OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, void *context); +OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t sk_len, void *context); /* Store Secret Key Function, ideally written to secure device */ void OQS_SECRET_KEY_XMSS_set_store_cb(OQS_SIG_STFL_SECRET_KEY *sk, secure_store_sk store_cb, void *context); diff --git a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c index ba526bc7e8..6903135cb0 100644 --- a/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c +++ b/src/sig_stfl/xmss/sig_stfl_xmss_secret_key_functions.c @@ -111,7 +111,7 @@ OQS_STATUS OQS_SECRET_KEY_XMSS_inner_serialize_key(uint8_t **sk_buf_ptr, size_t } /* Deserialize XMSS byte string into an XMSS secret key data. */ -OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const size_t sk_len, const uint8_t *sk_buf, XMSS_UNUSED_ATT void *context) { +OQS_STATUS OQS_SECRET_KEY_XMSS_deserialize_key(OQS_SIG_STFL_SECRET_KEY *sk, const uint8_t *sk_buf, const size_t sk_len, XMSS_UNUSED_ATT void *context) { #ifndef OQS_ALLOW_XMSS_KEY_AND_SIG_GEN return OQS_ERROR; #endif From c408cee90727c3a69e7fa5f256f467842ef23220 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Fri, 26 Apr 2024 13:34:51 -0400 Subject: [PATCH 58/68] Update src/sig_stfl/sig_stfl.h Co-authored-by: Jason Goertzen <133878263+jgoertzen-sb@users.noreply.github.com> Signed-off-by: Spencer Wilson --- src/sig_stfl/sig_stfl.h | 1 + 1 file changed, 1 insertion(+) diff --git a/src/sig_stfl/sig_stfl.h b/src/sig_stfl/sig_stfl.h index 91df350add..6154f47a64 100644 --- a/src/sig_stfl/sig_stfl.h +++ b/src/sig_stfl/sig_stfl.h @@ -654,6 +654,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_SECRET_KEY_deserialize(OQS_SIG_STFL_SECRET_KEY * #if defined(__cplusplus) // extern "C" +} #endif #endif /* OQS_SIG_STATEFUL_H */ From 7dd4ea0a9ecadce45050bdffe07e2d9fb4b338cc Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Mon, 29 Apr 2024 11:06:23 -0400 Subject: [PATCH 59/68] Test stateful sigs on arm64, s390x, and powerpc (#1772) --- .circleci/config.yml | 1 + .travis.yml | 4 ++-- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.circleci/config.yml b/.circleci/config.yml index 5c15e2dc37..6dda717b1d 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -344,6 +344,7 @@ workflows: <<: *require_buildcheck name: arm64 PYTEST_ARGS: --numprocesses=auto --maxprocesses=10 --ignore=tests/test_kat_all.py + CMAKE_ARGS: -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON commit-to-main: when: diff --git a/.travis.yml b/.travis.yml index fd13edc301..882b92b755 100644 --- a/.travis.yml +++ b/.travis.yml @@ -9,7 +9,7 @@ jobs: compiler: gcc if: NOT branch =~ /^ghactionsonly-/ script: - - mkdir build && cd build && cmake -GNinja .. && cmake -LA .. && ninja + - mkdir build && cd build && cmake -GNinja -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_STFL_SIG_KEY_SIG_GEN=ON .. && cmake -LA .. && ninja - cd build & ninja run_tests - arch: s390x os: linux @@ -17,5 +17,5 @@ jobs: compiler: gcc if: NOT branch =~ /^ghactionsonly-/ script: - - mkdir build && cd build && cmake -GNinja .. && cmake -LA .. && ninja + - mkdir build && cd build && cmake -GNinja -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_STFL_SIG_KEY_SIG_GEN=ON .. && cmake -LA .. && ninja - cd build & ninja run_tests From 4ebd1b94ebd71181a43653e441700226d537026f Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Sat, 11 May 2024 22:57:04 -0400 Subject: [PATCH 60/68] Update tests/example_sig_stfl.c Co-authored-by: Douglas Stebila Signed-off-by: Norman Ashley --- tests/example_sig_stfl.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/example_sig_stfl.c b/tests/example_sig_stfl.c index a2b3ba21c1..f653ccba4c 100644 --- a/tests/example_sig_stfl.c +++ b/tests/example_sig_stfl.c @@ -112,7 +112,7 @@ static OQS_STATUS stfl_example(char *method_name) { //cleanup OQS_MEM_insecure_free(public_key); OQS_MEM_insecure_free(sk_fname); - OQS_MEM_insecure_free(message); + OQS_MEM_secure_free(message, message_len); OQS_MEM_insecure_free(signature); OQS_SIG_STFL_free(sig); OQS_SIG_STFL_SECRET_KEY_free(secret_key); From 0c3d39c26ccf37333092f404bc149be7218174d4 Mon Sep 17 00:00:00 2001 From: Duc Tri Nguyen Date: Tue, 14 May 2024 15:14:00 -0400 Subject: [PATCH 61/68] Zeroing internal state memory on heap (#1790) * Address stateful-sigs comments in #1650 (#1656) * Add sig_stfl to configure.md * Add OQS_MEM_checked_malloc and OQS_MEM_checked_aligned_alloc * Use memcpy and checked_malloc * Zeroing internal state memory on heap Signed-off-by: Duc Tri Nguyen * make astyle happy Signed-off-by: Duc Tri Nguyen * secure free for wots key,sig tree stack Signed-off-by: Duc Tri Nguyen * revert * fix markdown link invalid Signed-off-by: Duc Tri Nguyen * fix markdown link, work with doxygen 1.10 Signed-off-by: Duc Tri Nguyen --------- Signed-off-by: Duc Tri Nguyen Co-authored-by: Duc Nguyen <106774416+ducnguyen-sb@users.noreply.github.com> --- CONFIGURE.md | 4 +- src/sig_stfl/lms/sig_stfl_lms.c | 2 - src/sig_stfl/lms/sig_stfl_lms.h | 1 - src/sig_stfl/xmss/external/wots.c | 10 ++- src/sig_stfl/xmss/external/xmss_core_fast.c | 86 ++++++++++++--------- 5 files changed, 58 insertions(+), 45 deletions(-) diff --git a/CONFIGURE.md b/CONFIGURE.md index a537f94be5..7ffcebae25 100644 --- a/CONFIGURE.md +++ b/CONFIGURE.md @@ -11,7 +11,7 @@ The following options can be passed to CMake before the build file generation pr - [OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG](#OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG) - [OQS_MINIMAL_BUILD](#OQS_MINIMAL_BUILD) - [OQS_DIST_BUILD](#OQS_DIST_BUILD) -- [OQS_USE_CPUFEATURE_INSTRUCTIONS](OQS_USE_CPUFEATURE_INSTRUCTIONS) +- [OQS_USE_CPUFEATURE_INSTRUCTIONS](#OQS_USE_CPUFEATURE_INSTRUCTIONS) - [OQS_USE_OPENSSL](#OQS_USE_OPENSSL) - [OQS_OPT_TARGET](#OQS_OPT_TARGET) - [OQS_SPEED_USE_ARM_PMU](#OQS_SPEED_USE_ARM_PMU) @@ -60,7 +60,7 @@ For a full list of such options and their default values, consult [.CMake/alg_su A selected algorithm set is enabled. Possible values are "STD" selecting all algorithms standardized by NIST; "NIST_R4" selecting all algorithms evaluated in round 4 of the NIST PQC competition; "All" (or any other value) selecting all algorithms integrated into liboqs. Parameter setting "STD" minimizes library size but may require re-running code generator scripts in projects integrating `liboqs`; e.g., [oqs-provider](https://github.com/open-quantum-safe/oqs-provider) and [oqs-boringssl](https://github.com/open-quantum-safe/boringssl). -**Attention**: If you use any predefined value (`STD` or `NIST_R4` as of now) for this variable, the values added via [OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG](#OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG) variables will be ignored. +**Attention**: If you use any predefined value (`STD` or `NIST_R4` as of now) for this variable, the values added via [OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG](#OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG) variables will be ignored. **Default**: `All`. diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index 33d18b6c3c..88dc5938fc 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -27,7 +27,6 @@ OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w2_keypair(uint8_t *public_key, OQS_S OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); - // OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); // OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); @@ -267,7 +266,6 @@ LMS_ALG(sha256_h20_w8_h15_w8, SHA256_H20_W8_H15_W8) LMS_ALG(sha256_h20_w8_h20_w8, SHA256_H20_W8_H20_W8) //2-Level LMS - void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk) { oqs_secret_lms_key_free(sk); } diff --git a/src/sig_stfl/lms/sig_stfl_lms.h b/src/sig_stfl/lms/sig_stfl_lms.h index 941f17a0ff..13ef40f704 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.h +++ b/src/sig_stfl/lms/sig_stfl_lms.h @@ -252,7 +252,6 @@ OQS_API OQS_STATUS OQS_SIG_STFL_lms_sigs_total(unsigned long long *totaln, const void OQS_SECRET_KEY_LMS_free(OQS_SIG_STFL_SECRET_KEY *sk); - //2-Level LMS #define OQS_SIG_STFL_alg_lms_length_private_key 64 #define OQS_SIG_STFL_alg_lms_length_public_key 60 diff --git a/src/sig_stfl/xmss/external/wots.c b/src/sig_stfl/xmss/external/wots.c index 067d48e6e4..0d5b57fd57 100644 --- a/src/sig_stfl/xmss/external/wots.c +++ b/src/sig_stfl/xmss/external/wots.c @@ -128,7 +128,8 @@ void wots_pkgen(const xmss_params *params, const unsigned char *pub_seed, uint32_t addr[8]) { unsigned int i; - unsigned char *buf = malloc(2 * params->padding_len + 4 * params->n + 64); + const size_t buf_size = 2 * params->padding_len + 4 * params->n + 64; + unsigned char *buf = malloc(buf_size); if (buf == NULL) { return; } @@ -142,7 +143,7 @@ void wots_pkgen(const xmss_params *params, 0, params->wots_w - 1, pub_seed, addr, buf); } - OQS_MEM_insecure_free(buf); + OQS_MEM_secure_free(buf, buf_size); } /** @@ -154,8 +155,9 @@ void wots_sign(const xmss_params *params, const unsigned char *seed, const unsigned char *pub_seed, uint32_t addr[8]) { + const size_t buf_size = 2 * params->padding_len + 4 * params->n + 64; unsigned int *lengths = calloc(params->wots_len, sizeof(unsigned int)); - unsigned char *buf = malloc(2 * params->padding_len + 4 * params->n + 64); + unsigned char *buf = malloc(buf_size); unsigned int i; if (lengths == NULL || buf == NULL) { return; @@ -173,7 +175,7 @@ void wots_sign(const xmss_params *params, } OQS_MEM_insecure_free(lengths); - OQS_MEM_insecure_free(buf); + OQS_MEM_secure_free(buf, buf_size); } /** diff --git a/src/sig_stfl/xmss/external/xmss_core_fast.c b/src/sig_stfl/xmss/external/xmss_core_fast.c index ed8886501f..9ad19e3908 100644 --- a/src/sig_stfl/xmss/external/xmss_core_fast.c +++ b/src/sig_stfl/xmss/external/xmss_core_fast.c @@ -171,11 +171,11 @@ static void deep_state_swap(const xmss_params *params, } // TODO (from upstream) this is extremely ugly and should be refactored // TODO (from upstream) right now, this ensures that both 'stack' and 'retain' fit - unsigned char *t = malloc( - ((params->tree_height + 1) > ((1 << params->bds_k) - params->bds_k - 1) + const size_t t_size = ((params->tree_height + 1) > ((1 << params->bds_k) - params->bds_k - 1) ? (params->tree_height + 1) : ((1 << params->bds_k) - params->bds_k - 1)) - * params->n); + * params->n; + unsigned char *t = malloc(t_size); if (t == NULL) { return; } @@ -198,7 +198,7 @@ static void deep_state_swap(const xmss_params *params, memswap(a->retain, b->retain, t, ((1 << params->bds_k) - params->bds_k - 1) * params->n); memswap(&a->next_leaf, &b->next_leaf, t, sizeof(a->next_leaf)); - OQS_MEM_insecure_free(t); + OQS_MEM_secure_free(t, t_size); } static int treehash_minheight_on_stack(const xmss_params *params, @@ -241,9 +241,11 @@ static void treehash_init(const xmss_params *params, /* The subtree has at most 2^20 leafs, so uint32_t suffices. */ uint32_t idx = index; uint32_t lastnode = index +(1<padding_len + 6 * params->n + 32; + const size_t stack_size = ((height+1)*params->n)* sizeof(unsigned char); unsigned char *stack = calloc((height+1)*params->n, sizeof(unsigned char)); unsigned int *stacklevels = malloc((height + 1)*sizeof(unsigned int)); - unsigned char *thash_buf = malloc(2 * params->padding_len + 6 * params->n + 32); + unsigned char *thash_buf = malloc(thash_buf_size); if (stack == NULL || stacklevels == NULL || thash_buf == NULL) { return; @@ -293,8 +295,8 @@ static void treehash_init(const xmss_params *params, memcpy(node, stack, params->n); OQS_MEM_insecure_free(stacklevels); - OQS_MEM_insecure_free(stack); - OQS_MEM_insecure_free(thash_buf); + OQS_MEM_secure_free(stack, stack_size); + OQS_MEM_secure_free(thash_buf, thash_buf_size); } static void treehash_update(const xmss_params *params, @@ -318,11 +320,13 @@ static void treehash_update(const xmss_params *params, set_ltree_addr(ltree_addr, treehash->next_idx); set_ots_addr(ots_addr, treehash->next_idx); - unsigned char *nodebuffer = malloc(2 * params->n); - unsigned char *thash_buf = malloc(2 * params->padding_len + 6 * params->n + 32); - if (nodebuffer == NULL || thash_buf == NULL) { + const size_t buf_size = 2 * params->n + 2 * params->padding_len + 6 * params->n + 32; + unsigned char *buf = malloc(buf_size); + if (buf == NULL) { return; } + unsigned char *nodebuffer = buf; + unsigned char *thash_buf = buf + 2 * params->n; unsigned int nodeheight = 0; gen_leaf_wots(params, nodebuffer, sk_seed, pub_seed, ltree_addr, ots_addr); @@ -348,8 +352,7 @@ static void treehash_update(const xmss_params *params, treehash->next_idx++; } - OQS_MEM_insecure_free(nodebuffer); - OQS_MEM_insecure_free(thash_buf); + OQS_MEM_secure_free(buf, buf_size); } /** @@ -406,21 +409,22 @@ static char bds_state_update(const xmss_params *params, return -1; } + unsigned int nodeh; + int idx = state->next_leaf; + if (idx == 1 << params->tree_height) { + return -1; + } + uint32_t ltree_addr[8] = {0}; uint32_t node_addr[8] = {0}; uint32_t ots_addr[8] = {0}; - unsigned char *thash_buf = malloc(2 * params->padding_len + 6 * params->n + 32); + const size_t thash_buf_size = 2 * params->padding_len + 6 * params->n + 32; + unsigned char *thash_buf = malloc(thash_buf_size); if (thash_buf == NULL) { return -1; } - unsigned int nodeh; - int idx = state->next_leaf; - if (idx == 1 << params->tree_height) { - return -1; - } - // only copy layer and tree address parts copy_subtree_addr(ots_addr, addr); // type = ots @@ -462,7 +466,7 @@ static char bds_state_update(const xmss_params *params, } state->next_leaf++; - OQS_MEM_insecure_free(thash_buf); + OQS_MEM_secure_free(thash_buf, thash_buf_size); return 0; } @@ -480,11 +484,12 @@ static void bds_round(const xmss_params *params, unsigned int tau = params->tree_height; unsigned int startidx; unsigned int offset, rowidx; - unsigned char *buf = malloc(2 * params->n); - unsigned char *thash_buf = malloc(2 * params->padding_len + 6 * params->n + 32); - if (buf == NULL || thash_buf == NULL) { + const size_t buf_size = 2 * params->n + 2 * params->padding_len + 6 * params->n + 32; + unsigned char *buf = malloc(buf_size); + if (buf == NULL) { return; } + unsigned char *thash_buf = buf + 2 * params->n; uint32_t ots_addr[8] = {0}; uint32_t ltree_addr[8] = {0}; @@ -545,8 +550,7 @@ static void bds_round(const xmss_params *params, } } - OQS_MEM_insecure_free(buf); - OQS_MEM_insecure_free(thash_buf); + OQS_MEM_secure_free(buf, buf_size); } /** @@ -584,6 +588,7 @@ int xmss_core_keypair(const xmss_params *params, // TODO (from upstream) refactor BDS state not to need separate treehash instances bds_state state; + const size_t treehash_size = (params->tree_height - params->bds_k)*sizeof(treehash_inst); treehash_inst *treehash = calloc(params->tree_height - params->bds_k, sizeof(treehash_inst)); if (treehash == NULL) { return -1; @@ -616,7 +621,7 @@ int xmss_core_keypair(const xmss_params *params, /* Write the BDS state into sk. */ xmss_serialize_state(params, sk, &state); - OQS_MEM_insecure_free(treehash); + OQS_MEM_secure_free(treehash, treehash_size); return 0; } @@ -645,8 +650,10 @@ int xmss_core_sign(const xmss_params *params, // TODO (from upstream) refactor BDS state not to need separate treehash instances bds_state state; + const size_t treehash_size = (params->tree_height - params->bds_k) * sizeof(treehash_inst); + const size_t tmp_size = 5 * params->n + params->padding_len + params->n + 32; treehash_inst *treehash = calloc(params->tree_height - params->bds_k, sizeof(treehash_inst)); - unsigned char *tmp = malloc(5 * params->n + params->padding_len + params->n + 32); + unsigned char *tmp = malloc(tmp_size); if (treehash == NULL || tmp == NULL) { return -1; } @@ -720,7 +727,8 @@ int xmss_core_sign(const xmss_params *params, unsigned long long prefix_length = params->padding_len + 3*params->n; unsigned char *m_with_prefix = malloc((size_t)(mlen + prefix_length)); if (m_with_prefix == NULL) { - return -1; + ret = -1; + goto cleanup; } memcpy(m_with_prefix, sm + params->sig_bytes - prefix_length, (size_t)prefix_length); memcpy(m_with_prefix + prefix_length, m, (size_t)mlen); @@ -780,10 +788,10 @@ int xmss_core_sign(const xmss_params *params, ret = 0; OQS_MEM_insecure_free(m_with_prefix); - OQS_MEM_insecure_free(tmp); cleanup: - OQS_MEM_insecure_free(treehash); + OQS_MEM_secure_free(tmp, tmp_size); + OQS_MEM_secure_free(treehash, treehash_size); return ret; } @@ -801,6 +809,8 @@ int xmssmt_core_keypair(const xmss_params *params, unsigned char *wots_sigs; // TODO (from upstream) refactor BDS state not to need separate treehash instances + const size_t states_size = (2*params->d - 1)* sizeof(bds_state); + const size_t treehash_size = ((2*params->d - 1) * (params->tree_height - params->bds_k))* sizeof(treehash_inst); bds_state *states = calloc(2*params->d - 1, sizeof(bds_state)); treehash_inst *treehash = calloc((2*params->d - 1) * (params->tree_height - params->bds_k), sizeof(treehash_inst)); if (states == NULL || treehash == NULL) { @@ -844,8 +854,8 @@ int xmssmt_core_keypair(const xmss_params *params, xmssmt_serialize_state(params, sk, states); - OQS_MEM_insecure_free(treehash); - OQS_MEM_insecure_free(states); + OQS_MEM_secure_free(treehash, treehash_size); + OQS_MEM_secure_free(states, states_size); return 0; } @@ -876,9 +886,13 @@ int xmssmt_core_sign(const xmss_params *params, unsigned int updates; // TODO (from upstream) refactor BDS state not to need separate treehash instances + const size_t states_size = (2*params->d - 1)* sizeof(bds_state); + const size_t treehash_size = (2*params->d - 1) * (params->tree_height - params->bds_k) * sizeof(treehash_inst); + const size_t tmp_size = 5 * params->n + + params->padding_len + params->n + 32; bds_state *states = calloc(2*params->d - 1, sizeof(bds_state)); treehash_inst *treehash = calloc((2*params->d - 1) * (params->tree_height - params->bds_k), sizeof(treehash_inst)); - unsigned char *tmp = malloc(5 * params->n + + unsigned char *tmp = malloc(5 * params->n + params->padding_len + params->n + 32); if (states == NULL || treehash == NULL || tmp == NULL) { return -1; @@ -1090,9 +1104,9 @@ int xmssmt_core_sign(const xmss_params *params, xmssmt_serialize_state(params, sk, states); cleanup: - OQS_MEM_insecure_free(treehash); - OQS_MEM_insecure_free(states); - OQS_MEM_insecure_free(tmp); + OQS_MEM_secure_free(treehash, treehash_size); + OQS_MEM_secure_free(states, states_size); + OQS_MEM_secure_free(tmp, tmp_size); OQS_MEM_insecure_free(m_with_prefix); return ret; From 31bdf13d4b8717b143f9ed584dfb8faceb80ebd9 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Tue, 14 May 2024 16:58:36 -0400 Subject: [PATCH 62/68] Clean up unresolved comments on stateful-sigs PR (#1793) * Simplify security assumption in docs * Get rid of commented functions * Rename sm variable; use OQS_MEM_cleanse * Clean up TODOs * Update markdown files --- docs/algorithms/sig_stfl/lms.md | 2 +- docs/algorithms/sig_stfl/lms.yml | 2 +- docs/algorithms/sig_stfl/xmss.md | 2 +- docs/algorithms/sig_stfl/xmss.yml | 4 ++-- src/sig_stfl/lms/sig_stfl_lms.c | 4 ---- src/sig_stfl/lms/sig_stfl_lms_functions.c | 23 +++++++++-------------- 6 files changed, 14 insertions(+), 23 deletions(-) diff --git a/docs/algorithms/sig_stfl/lms.md b/docs/algorithms/sig_stfl/lms.md index 8357d0a8f6..d436b6b616 100644 --- a/docs/algorithms/sig_stfl/lms.md +++ b/docs/algorithms/sig_stfl/lms.md @@ -1,7 +1,7 @@ # LMS - **Algorithm type**: Digital signature scheme. -- **Main cryptographic assumption**: hash function second-preimage resistance. +- **Main cryptographic assumption**: hash-based signatures. - **Principal submitters**: Scott Fluhrer. - **Auxiliary submitters**: C Martin, Maurice Hieronymus. - **Authors' website**: https://www.rfc-editor.org/info/rfc8554 diff --git a/docs/algorithms/sig_stfl/lms.yml b/docs/algorithms/sig_stfl/lms.yml index 2741a3afea..9293ff70c3 100644 --- a/docs/algorithms/sig_stfl/lms.yml +++ b/docs/algorithms/sig_stfl/lms.yml @@ -6,7 +6,7 @@ auxiliary-submitters: - C Martin - Maurice Hieronymus -crypto-assumption: hash function second-preimage resistance +crypto-assumption: hash-based signatures website: https://www.rfc-editor.org/info/rfc8554 nist-round: spec-version: diff --git a/docs/algorithms/sig_stfl/xmss.md b/docs/algorithms/sig_stfl/xmss.md index b68bfc3020..446adcd8e1 100644 --- a/docs/algorithms/sig_stfl/xmss.md +++ b/docs/algorithms/sig_stfl/xmss.md @@ -1,7 +1,7 @@ # XMSS - **Algorithm type**: Digital signature scheme. -- **Main cryptographic assumption**: hash function second-preimage resistance. +- **Main cryptographic assumption**: hash-based signatures. - **Principal submitters**: Joost Rijneveld, A. Huelsing, David Cooper, Bas Westerbaan. - **Authors' website**: https://www.rfc-editor.org/info/rfc8391 - **Specification version**: None. diff --git a/docs/algorithms/sig_stfl/xmss.yml b/docs/algorithms/sig_stfl/xmss.yml index ccc92c26ea..dccefa12f9 100644 --- a/docs/algorithms/sig_stfl/xmss.yml +++ b/docs/algorithms/sig_stfl/xmss.yml @@ -7,7 +7,7 @@ principal-submitters: - Bas Westerbaan auxiliary-submitters: -crypto-assumption: hash function second-preimage resistance +crypto-assumption: hash-based signatures website: https://www.rfc-editor.org/info/rfc8391 nist-round: spec-version: @@ -184,4 +184,4 @@ parameter-sets: claimed-security: length-public-key: 64 length-secret-key: 38095 - length-signature: 27688 \ No newline at end of file + length-signature: 27688 diff --git a/src/sig_stfl/lms/sig_stfl_lms.c b/src/sig_stfl/lms/sig_stfl_lms.c index 88dc5938fc..acc218a6ba 100644 --- a/src/sig_stfl/lms/sig_stfl_lms.c +++ b/src/sig_stfl/lms/sig_stfl_lms.c @@ -27,11 +27,7 @@ OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w2_keypair(uint8_t *public_key, OQS_S OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h25_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -// OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w1_new(void); -// OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W1_new(void); OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w1_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); -// OQS_SIG_STFL *OQS_SIG_STFL_alg_lms_sha256_h5_w2_new(void); -// OQS_SIG_STFL_SECRET_KEY *OQS_SECRET_KEY_LMS_SHA256_H5_W2_new(void); OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w2_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w4_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); OQS_STATUS OQS_SIG_STFL_alg_lms_sha256_h5_w8_keypair(uint8_t *public_key, OQS_SIG_STFL_SECRET_KEY *secret_key); diff --git a/src/sig_stfl/lms/sig_stfl_lms_functions.c b/src/sig_stfl/lms/sig_stfl_lms_functions.c index f3660e40d8..60d1d0c60b 100644 --- a/src/sig_stfl/lms/sig_stfl_lms_functions.c +++ b/src/sig_stfl/lms/sig_stfl_lms_functions.c @@ -116,7 +116,7 @@ OQS_API OQS_STATUS OQS_SIG_STFL_alg_lms_sign(uint8_t *signature, size_t *signatu err: if (*signature_length) { - memset(signature, 0, *signature_length); + OQS_MEM_cleanse(signature, *signature_length); } *signature_length = 0; @@ -252,7 +252,6 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uin if (sk->secret_key_data) { //this means a key pair has already been recreated - //TODO log error. return -1; } @@ -535,21 +534,19 @@ int oqs_sig_stfl_lms_keypair(uint8_t *pk, OQS_SIG_STFL_SECRET_KEY *sk, const uin return -1; } - /* TODO: store key pair, file handler */ - ret = 0; return ret; } #endif #ifndef OQS_ALLOW_LMS_KEY_AND_SIG_GEN -int oqs_sig_stfl_lms_sign(UNUSED OQS_SIG_STFL_SECRET_KEY *sk, UNUSED uint8_t *sm, UNUSED size_t *smlen, +int oqs_sig_stfl_lms_sign(UNUSED OQS_SIG_STFL_SECRET_KEY *sk, UNUSED uint8_t *signature, UNUSED size_t *signature_len, UNUSED const uint8_t *m, UNUSED size_t mlen) { return -1; } #else int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, - uint8_t *sm, size_t *smlen, + uint8_t *signature, size_t *signature_len, const uint8_t *m, size_t mlen) { size_t sig_len; @@ -616,8 +613,8 @@ int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, return -1; } - *smlen = sig_len; - memcpy(sm, sig, sig_len); + *signature_len = sig_len; + memcpy(signature, sig, sig_len); OQS_MEM_insecure_free(sig); hss_free_working_key(w); @@ -626,15 +623,15 @@ int oqs_sig_stfl_lms_sign(OQS_SIG_STFL_SECRET_KEY *sk, #endif int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, - const uint8_t *sm, size_t smlen, + const uint8_t *signature, size_t signature_len, const uint8_t *pk) { struct hss_validate_inc ctx; (void)hss_validate_signature_init( &ctx, /* Incremental validate context */ (const unsigned char *)pk, /* Public key */ - (const unsigned char *)sm, - (size_t)smlen, /* Signature */ + (const unsigned char *)signature, + (size_t)signature_len, /* Signature */ 0); /* Use the defaults for extra info */ (void)hss_validate_signature_update( @@ -644,7 +641,7 @@ int oqs_sig_stfl_lms_verify(const uint8_t *m, size_t mlen, bool status = hss_validate_signature_finalize( &ctx, /* Incremental validate context */ - (const unsigned char *)sm, /* Signature */ + (const unsigned char *)signature, /* Signature */ 0); /* Use the defaults for extra info */ if (status) { @@ -661,8 +658,6 @@ void oqs_secret_lms_key_free(OQS_SIG_STFL_SECRET_KEY *sk) { return; } - //TODO: cleanup lock_key - if (sk->secret_key_data) { oqs_lms_key_data *key_data = (oqs_lms_key_data *)sk->secret_key_data; if (key_data) { From 8e75f98929042052a97a18f70ec7193abe8798de Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Thu, 23 May 2024 11:43:06 -0400 Subject: [PATCH 63/68] Update config variable name --- .CMake/alg_support.cmake | 8 ++++---- .circleci/config.yml | 2 +- .github/workflows/android.yml | 2 +- .github/workflows/apple.yml | 2 +- .github/workflows/unix.yml | 18 +++++++++--------- .github/workflows/windows.yml | 4 ++-- .travis.yml | 4 ++-- CONFIGURE.md | 6 +++--- src/oqsconfig.h.cmake | 2 +- 9 files changed, 24 insertions(+), 24 deletions(-) diff --git a/.CMake/alg_support.cmake b/.CMake/alg_support.cmake index 3810585a9c..2b0eec0c18 100644 --- a/.CMake/alg_support.cmake +++ b/.CMake/alg_support.cmake @@ -563,16 +563,16 @@ cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h10_w8 "" ON "OQS_E cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h15_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) cmake_dependent_option(OQS_ENABLE_SIG_STFL_lms_sha256_h20_w8_h20_w8 "" ON "OQS_ENABLE_SIG_STFL_LMS" OFF) -option(OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN "Enable stateful key and signature generation for research and experimentation" OFF) -cmake_dependent_option(OQS_ALLOW_STFL_KEY_AND_SIG_GEN "" ON "OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN" OFF) +option(OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN "Enable stateful key and signature generation for research and experimentation" OFF) +cmake_dependent_option(OQS_ALLOW_STFL_KEY_AND_SIG_GEN "" ON "OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN" OFF) -if (${OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_XMSS}) +if (${OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_XMSS}) set(OQS_ALLOW_XMSS_KEY_AND_SIG_GEN ON) else() set(OQS_ALLOW_XMSS_KEY_AND_SIG_GEN OFF) endif() -if (${OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_LMS}) +if (${OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN} AND ${OQS_ENABLE_SIG_STFL_LMS}) set(OQS_ALLOW_LMS_KEY_AND_SIG_GEN ON) else() set(OQS_ALLOW_LMS_KEY_AND_SIG_GEN OFF) diff --git a/.circleci/config.yml b/.circleci/config.yml index 6dda717b1d..a5a31cd1c0 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -344,7 +344,7 @@ workflows: <<: *require_buildcheck name: arm64 PYTEST_ARGS: --numprocesses=auto --maxprocesses=10 --ignore=tests/test_kat_all.py - CMAKE_ARGS: -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON + CMAKE_ARGS: -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON commit-to-main: when: diff --git a/.github/workflows/android.yml b/.github/workflows/android.yml index d54b6ebcde..930aec691f 100644 --- a/.github/workflows/android.yml +++ b/.github/workflows/android.yml @@ -16,4 +16,4 @@ jobs: - name: Checkout code uses: actions/checkout@v3 - name: Build project - run: ./scripts/build-android.sh $ANDROID_NDK_HOME -a ${{ matrix.abi }} -f "-DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }}" + run: ./scripts/build-android.sh $ANDROID_NDK_HOME -a ${{ matrix.abi }} -f "-DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }}" diff --git a/.github/workflows/apple.yml b/.github/workflows/apple.yml index 69021d60a9..34dae893f5 100644 --- a/.github/workflows/apple.yml +++ b/.github/workflows/apple.yml @@ -17,6 +17,6 @@ jobs: - name: Generate project run: | cmake -B build --toolchain .CMake/apple.cmake -DOQS_USE_OPENSSL=OFF -DPLATFORM=${{ matrix.platform }} \ - -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . + -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build project run: cmake --build build diff --git a/.github/workflows/unix.yml b/.github/workflows/unix.yml index fa459f9aed..0645616dce 100644 --- a/.github/workflows/unix.yml +++ b/.github/workflows/unix.yml @@ -74,19 +74,19 @@ jobs: include: - name: alpine container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: alpine-no-stfl-key-sig-gen container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: alpine-openssl-all container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: alpine-noopenssl container: openquantumsafe/ci-alpine-amd64:latest - CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=OFF -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: focal-nistr4-openssl container: openquantumsafe/ci-ubuntu-focal-x86_64:latest @@ -102,11 +102,11 @@ jobs: PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py - name: address-sanitizer container: openquantumsafe/ci-ubuntu-focal-x86_64:latest - CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --numprocesses=auto --maxprocesses=10 - name: address-sanitizer-no-stfl-key-sig-gen container: openquantumsafe/ci-ubuntu-focal-x86_64:latest - CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DCMAKE_C_COMPILER=clang-9 -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --numprocesses=auto --maxprocesses=10 container: image: ${{ matrix.container }} @@ -145,11 +145,11 @@ jobs: include: - name: armhf ARCH: armhf - CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py - name: armhf-no-stfl-key-sig-gen ARCH: armhf - CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + CMAKE_ARGS: -DOQS_ENABLE_SIG_SPHINCS=OFF -DOQS_USE_OPENSSL=OFF -DOQS_OPT_TARGET=generic -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py # no longer supporting armel # - name: armel @@ -215,7 +215,7 @@ jobs: - macos-13 - macos-14 CMAKE_ARGS: - - -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON + - -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON - -DCMAKE_C_COMPILER=gcc-13 - -DOQS_USE_OPENSSL=OFF - -DBUILD_SHARED_LIBS=ON -DOQS_DIST_BUILD=OFF diff --git a/.github/workflows/windows.yml b/.github/workflows/windows.yml index 3c3e483337..d2552fae4c 100644 --- a/.github/workflows/windows.yml +++ b/.github/workflows/windows.yml @@ -12,7 +12,7 @@ jobs: steps: - uses: actions/checkout@v3 - name: Generate Project - run: cmake -B build --toolchain .CMake/toolchain_windows_arm64.cmake -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . + run: cmake -B build --toolchain .CMake/toolchain_windows_arm64.cmake -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build Project run: cmake --build build @@ -26,7 +26,7 @@ jobs: steps: - uses: actions/checkout@v3 - name: Generate Project - run: cmake -B build --toolchain ${{ matrix.toolchain }} -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . + run: cmake -B build --toolchain ${{ matrix.toolchain }} -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} . - name: Build Project run: cmake --build build - name: Test dependencies diff --git a/.travis.yml b/.travis.yml index 882b92b755..1ebffdf879 100644 --- a/.travis.yml +++ b/.travis.yml @@ -9,7 +9,7 @@ jobs: compiler: gcc if: NOT branch =~ /^ghactionsonly-/ script: - - mkdir build && cd build && cmake -GNinja -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_STFL_SIG_KEY_SIG_GEN=ON .. && cmake -LA .. && ninja + - mkdir build && cd build && cmake -GNinja -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_STFL_SIG_KEY_SIG_GEN=ON .. && cmake -LA .. && ninja - cd build & ninja run_tests - arch: s390x os: linux @@ -17,5 +17,5 @@ jobs: compiler: gcc if: NOT branch =~ /^ghactionsonly-/ script: - - mkdir build && cd build && cmake -GNinja -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_EXPERIMENTAL_ENABLE_STFL_SIG_KEY_SIG_GEN=ON .. && cmake -LA .. && ninja + - mkdir build && cd build && cmake -GNinja -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_STFL_SIG_KEY_SIG_GEN=ON .. && cmake -LA .. && ninja - cd build & ninja run_tests diff --git a/CONFIGURE.md b/CONFIGURE.md index 7ffcebae25..00d60cdfa7 100644 --- a/CONFIGURE.md +++ b/CONFIGURE.md @@ -125,10 +125,10 @@ Only has an effect if the system supports `dlopen` and ELF binary format, such a XMSS and LMS are the two supported Hash-Based Signatures schemes. `OQS_ENABLE_SIG_STFL_XMSS` and `OQS_ENABLE_SIG_STFL_LMS` control these algorithms, which are disabled by default. -A third variable, `OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN`, also controls the ability to generate keys and signatures. This is also disabled by default. +A third variable, `OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN`, also controls the ability to generate keys and signatures. This is also disabled by default. Each of these variables can be set to `ON` or `OFF`. When all three are `ON`, stateful signatures are fully functional and can generate key pairs, sign data, and verify signatures. -If `OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF` signature verification is the only functional operation. +If `OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF` signature verification is the only functional operation. Standards bodies, such as NIST, recommend that key and signature generation only by done in hardware in order to best enforce the one-time use of secret keys. Keys stored in a file system are extremely susceptible to simultaneous use. @@ -137,7 +137,7 @@ When enabled in this library a warning message will be generated by the config p By default, - `OQS_ENABLE_SIG_STFL_XMSS` is `OFF` - `OQS_ENABLE_SIG_STFL_LMS` is `OFF` -- `OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF`. +- `OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF`. **Default**: `OFF`. diff --git a/src/oqsconfig.h.cmake b/src/oqsconfig.h.cmake index 414b759cfa..0617d30661 100644 --- a/src/oqsconfig.h.cmake +++ b/src/oqsconfig.h.cmake @@ -237,7 +237,7 @@ #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h5_w8_h5_w8 1 #cmakedefine OQS_ENABLE_SIG_STFL_lms_sha256_h10_w4_h5_w8 1 -#cmakedefine OQS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN 1 +#cmakedefine OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN 1 #cmakedefine OQS_ALLOW_STFL_KEY_AND_SIG_GEN 1 #cmakedefine OQS_ALLOW_XMSS_KEY_AND_SIG_GEN 1 #cmakedefine OQS_ALLOW_LMS_KEY_AND_SIG_GEN 1 From ca2792266d06409b9fb05ee2280cf3c8cc767e2b Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Thu, 23 May 2024 11:45:49 -0400 Subject: [PATCH 64/68] Strengthen warning in CONFIGURE.md --- CONFIGURE.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/CONFIGURE.md b/CONFIGURE.md index 00d60cdfa7..9bae9f5af2 100644 --- a/CONFIGURE.md +++ b/CONFIGURE.md @@ -133,6 +133,9 @@ If `OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF` signature v Standards bodies, such as NIST, recommend that key and signature generation only by done in hardware in order to best enforce the one-time use of secret keys. Keys stored in a file system are extremely susceptible to simultaneous use. When enabled in this library a warning message will be generated by the config process. +The name of the configuration variable has been chosen to make every user of this feature aware of its security risks. +The OQS team explicitly discourages enabling this variable and reserves the right to remove this feature in future releases if its use causes actual harm. +It remains present as long as it is responsibly used as per the stated warnings. By default, - `OQS_ENABLE_SIG_STFL_XMSS` is `OFF` From 6f35f43ad06aef313bc84f4be78808522dd3f94b Mon Sep 17 00:00:00 2001 From: Douglas Stebila Date: Thu, 30 May 2024 13:55:38 -0400 Subject: [PATCH 65/68] DCO sign-off [skip ci] I, Douglas Stebila, retroactively sign off on these commits: commit b0c06fa966360bad2c128b5b37255ced1266d9e3 Fix API and build issues commit 7b591542e3455b9407be44a54e0a67ffb455eb97 Add SIG_STFL to tests/dump_alg_info commit 8e1dd5ce0f6efbf221f3eb1ead8c295f72ab460e Update sig_stfl dummy scheme and add basic test program commit c9c3835c577e52d5da0fdf3c83334d59594fcfa8 Re-add OQS_SECRET_KEY (#1493) Signed-off-by: Douglas Stebila From 20d39aa6d8fa0c7a1d5c7d41a32a130f3e9e0e3e Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Thu, 30 May 2024 15:27:49 -0400 Subject: [PATCH 66/68] I, Spencer Wilson, retroactively sign off on these commits: commit 001e96a03a853d07518f8215634a98f439d5eab3 Update GitHub Actions workflows for stateful signatures (#1692) commit 8524a16c4e3a4daa6e067af1f4a1dbb3858093d6 Post-rebase cleanup commit 5da49e33c6dd35780dc65dd5b1a4200191436405 Satisfy astyle commit a535114d514dc5871a8f4d7ce9515954b9befc3a Fix macOS build error: lld -> llu commit 71ee535eca8398f170a489ad45556464816782de Bring EVP_DigestUpdate calls in line with main commit 154d8e4b1c07c5fa4f0c12303a9c2a38aa3a36b3 Fix test program linkage for cross-compiling commit e92aab307f41b492c684438c4fdd8caae7b7a820 Stateful sigs: Rename keygen / sign option, add more tests, fix memory errors (#1755) commit b0758784cc5f4171ff264964a9f79e62e9503e30 Clean up OQS_SIG_STFL_SECRET_KEY_free commit db000c263a87d6830b125e045059664fc6b95cb5 Remove unused sig member commit 9b60f60b42a5570b86a511439925dcca48554c00 Naming convention for serialize / deserialize functions commit 7dd4ea0a9ecadce45050bdffe07e2d9fb4b338cc Test stateful sigs on arm64, s390x, and powerpc (#1772) commit 31bdf13d4b8717b143f9ed584dfb8faceb80ebd9 Clean up unresolved comments on stateful-sigs PR (#1793) commit 8e75f98929042052a97a18f70ec7193abe8798de Update config variable name commit ca2792266d06409b9fb05ee2280cf3c8cc767e2b Strengthen warning in CONFIGURE.md Signed-off-by: Spencer Wilson From d37f20dea787fc26398d8d09116e80493806a326 Mon Sep 17 00:00:00 2001 From: Duc Tri Nguyen Date: Thu, 30 May 2024 17:02:08 -0400 Subject: [PATCH 67/68] I, Duc Nguyen, retroactively sign off on these commits: commit 244288f8acdab63813fbb9514f85b5bf6f8d372c Add XMSS parameter xmss_sha256_h10 (#1482) commit a7e26d95451a5386b7726a614337a2db7045f24e Add 12 XMSS and 16 XMSSMT parameters. (#1489) commit 4694fc3b6e03720b25a8bb1ab292111dccb5bb28 Add secret key object to XMSS (#1530) commit 99067be855c99de792d4e25a3beb736ef9ecf80b Add XMSS Serialize/Deserialize (#1542) commit 2dbfc400734501386fd51d50c2739b3f09d25b3d Update XMSS secret key object APIs, sync with LMS (#1588) commit 47740ad98cc5361c9916abca1944f1e6a24c0158 Enforce idx from unsigned int to uint32_t. (#1611) commit 9610576db49c8ebb1c21a8a4bcde942d0ade53f9 Fix windows-x86 and arm compiling error. (#1634) commit bb658b79261e3f7187bd03c8ee19223555b2a96a Address stateful-sigs comments in #1650 (#1656) commit 7db8ddfe24a189e84e0d72dc127a8c09c8c89f24 Update `sig_stfl.h` document for #1650 (#1655) commit c3e57507e57cd406c420e35ec13cdd7214402be1 Add Apache 2.0 and MIT License to XMSS (#1662) commit e1f02b2d6dca61523094640868116a8d997eb14e Change XMSS License from `(Apache 2.0 AND MIT)` to `(Apache 2.0 OR MIT) AND CC0-1.0` (#1697) commit 17c12c3c7f0e1b0c92085f5001559e0f892f9d18 Add return status for XMSS lock/unlock functions. (#1712) commit 194163611c1353b417ac47f4568f74fdd9325cff Add return check for lock/unlock function (#1727) commit b45415c5ff2b4087c4e3091a6ef7dc3f25eb3940 Use `abort()` instead of exit to get the trace log. (#1728) commit ba63672527eabfe43139adaf9bc37e15e8a3657a Reduce number of `malloc/free` call in `XMSS/external` (#1724) Signed-off-by: Duc Tri Nguyen From 3621a6bfdd0f821de51223047df9628f4dd6d5f2 Mon Sep 17 00:00:00 2001 From: Norman Ashley Date: Tue, 4 Jun 2024 13:26:45 -0400 Subject: [PATCH 68/68] I, Norman Ashley, retroactively sign off on these commits: commit e356ebf33167f7514466ce4c44c90a46e6f213bd Na lms (#1486) commit 55094c37f167ec4323411853ffc63da923741662 LMS H5_W1 (#1513) commit 4d773d785e1640889e8c3d84dfb3139c9804587b Convert to use OQS_SIG_STFL_SECRET_KEY struct (#1525) commit 245aede9970934f45801aa12ed9189b42c94993a LMS updated to use new SK API (#1533) commit a85a9aa172647fa42fbc3cf63a477a691ecb68c5 Stateful sigs secret key storage callback (#1553) commit 3934949d260909e22cdf347cfc32e3231ea30214 Na statful sig lock (#1559) commit 3db6b44f775fdb57440678c42153c57660ad50c1 Secret Key Query (#1572) commit 2446c64b3fd067452f6d07d283a660ac9af7b2cd Na stateful sigs lms var (#1574) commit 8df253944127c4da39d8a7068b98244c1619baea Stateful sigs XMSS updates (#1590) commit a7b29874fd7aec76165626c2e6ea8a66de91e0b9 SHA2 Increment with arbitrary length (non-block sizes) (#1614) commit 2dd9e07e07802c9afaf4cd3461d9473bccf44844 Na lms kat multi level (#1620) commit 982b44061b575ad573f81bb668325ef4dedb8014 Fix Build Errors (#1635) commit ddae6444b424343e7623b010d3dc304adc101ce6 Various fixes commit cc50ef00d14eef43e51c1b83ef32637a1f42f7af Fix warning commit cf03392510f426da2f1283b4c709d39fb92bcaf8 Update README.md commit 93257132a7b4687674803fd903ab986a32fd1143 Update README.md commit a52b2176eceed0ccff2df31302907b50c8d2dc22 Update README.md commit d442ac9ba861f9171b45a34de148f935a5de600d Update README.md commit 72ab47826cac51e47ea00cfccdeac2bc4c9c0485 Update README.md commit 5967f12281ac99b206407c44e340026fdb2ef7c7 Update src/CMakeLists.txt commit fc6d512ac18d08727a73b4232f1f5030eced7fe0 Update documentation and license text. (#1663) commit e7a83c7167032084a9fe8ab2ae86f4b2e19c4bf5 Disable Stateful Signatures in the build by default (#1676) commit 6c81bae0099c069c5e9b08fb0ea87d40302c07b9 Na stateful macro (#1687) Signed-off-by: Norman Ashley