Poly1305.swift 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293
  1. //
  2. // Poly1305.swift
  3. // CryptoSwift
  4. //
  5. // Created by Marcin Krzyzanowski on 30/08/14.
  6. // Copyright (c) 2014 Marcin Krzyzanowski. All rights reserved.
  7. //
  8. // http://tools.ietf.org/html/draft-agl-tls-chacha20poly1305-04#section-4
  9. //
  10. // Poly1305 takes a 32-byte, one-time key and a message and produces a 16-byte tag that authenticates the
  11. // message such that an attacker has a negligible chance of producing a valid tag for an inauthentic message.
  12. final public class Poly1305 {
  13. let blockSize = 16
  14. private var ctx:Context?
  15. private class Context {
  16. var r = Array<UInt8>(repeating: 0, count: 17)
  17. var h = Array<UInt8>(repeating: 0, count: 17)
  18. var pad = Array<UInt8>(repeating: 0, count: 17)
  19. var buffer = Array<UInt8>(repeating: 0, count: 16)
  20. var final:UInt8 = 0
  21. var leftover:Int = 0
  22. init?(_ key: Array<UInt8>) {
  23. assert(key.count == 32,"Invalid key length");
  24. if (key.count != 32) {
  25. return nil;
  26. }
  27. for i in 0..<17 {
  28. h[i] = 0
  29. }
  30. r[0] = key[0] & 0xff;
  31. r[1] = key[1] & 0xff;
  32. r[2] = key[2] & 0xff;
  33. r[3] = key[3] & 0x0f;
  34. r[4] = key[4] & 0xfc;
  35. r[5] = key[5] & 0xff;
  36. r[6] = key[6] & 0xff;
  37. r[7] = key[7] & 0x0f;
  38. r[8] = key[8] & 0xfc;
  39. r[9] = key[9] & 0xff;
  40. r[10] = key[10] & 0xff;
  41. r[11] = key[11] & 0x0f;
  42. r[12] = key[12] & 0xfc;
  43. r[13] = key[13] & 0xff;
  44. r[14] = key[14] & 0xff;
  45. r[15] = key[15] & 0x0f;
  46. r[16] = 0
  47. for i in 0..<16 {
  48. pad[i] = key[i + 16]
  49. }
  50. pad[16] = 0
  51. leftover = 0
  52. final = 0
  53. }
  54. deinit {
  55. for i in 0..<buffer.count {
  56. buffer[i] = 0
  57. }
  58. for i in 0..<r.count {
  59. r[i] = 0
  60. h[i] = 0
  61. pad[i] = 0
  62. final = 0
  63. leftover = 0
  64. }
  65. }
  66. }
  67. /**
  68. Calculate Message Authentication Code (MAC) for message.
  69. Calculation context is discarder on instance deallocation.
  70. - parameter key: 256-bit key
  71. - parameter message: Message
  72. - returns: Message Authentication Code
  73. */
  74. public func authenticate(message:Array<UInt8>) -> Array<UInt8>? {
  75. if let ctx = self.ctx {
  76. update(context: ctx, message: message)
  77. return finish(context: ctx)
  78. }
  79. return nil
  80. }
  81. public init? (key: Array<UInt8>) {
  82. ctx = Context(key)
  83. if (ctx == nil) {
  84. return nil
  85. }
  86. }
  87. // MARK: - Private
  88. /**
  89. Add message to be processed
  90. - parameter context: Context
  91. - parameter message: message
  92. - parameter bytes: length of the message fragment to be processed
  93. */
  94. private func update(context:Context, message:Array<UInt8>, bytes:Int? = nil) {
  95. var bytes = bytes ?? message.count
  96. var mPos = 0
  97. /* handle leftover */
  98. if (context.leftover > 0) {
  99. var want = blockSize - context.leftover
  100. if (want > bytes) {
  101. want = bytes
  102. }
  103. for i in 0..<want {
  104. context.buffer[context.leftover + i] = message[mPos + i]
  105. }
  106. bytes -= want
  107. mPos += want
  108. context.leftover += want
  109. if (context.leftover < blockSize) {
  110. return
  111. }
  112. blocks(context: context, m: context.buffer)
  113. context.leftover = 0
  114. }
  115. /* process full blocks */
  116. if (bytes >= blockSize) {
  117. let want = bytes & ~(blockSize - 1)
  118. blocks(context: context, m: message, startPos: mPos)
  119. mPos += want
  120. bytes -= want;
  121. }
  122. /* store leftover */
  123. if (bytes > 0) {
  124. for i in 0..<bytes {
  125. context.buffer[context.leftover + i] = message[mPos + i]
  126. }
  127. context.leftover += bytes
  128. }
  129. }
  130. private func finish(context:Context) -> Array<UInt8>? {
  131. var mac = Array<UInt8>(repeating: 0, count: 16);
  132. /* process the remaining block */
  133. if (context.leftover > 0) {
  134. context.buffer[context.leftover] = 1
  135. for i in (context.leftover + 1)..<blockSize {
  136. context.buffer[i] = 0
  137. }
  138. context.final = 1
  139. blocks(context: context, m: context.buffer)
  140. }
  141. /* fully reduce h */
  142. freeze(context: context)
  143. /* h = (h + pad) % (1 << 128) */
  144. add(context: context, c: context.pad)
  145. for i in 0..<mac.count {
  146. mac[i] = context.h[i]
  147. }
  148. return mac
  149. }
  150. // MARK: - Utils
  151. private func add(context:Context, c:Array<UInt8>) {
  152. if (context.h.count != 17 && c.count != 17) {
  153. assertionFailure()
  154. return
  155. }
  156. var u:UInt16 = 0
  157. for i in 0..<17 {
  158. u += UInt16(context.h[i]) + UInt16(c[i])
  159. context.h[i] = UInt8.withValue(v: u)
  160. u = u >> 8
  161. }
  162. return
  163. }
  164. private func squeeze(context:Context, hr:Array<UInt32>) {
  165. if (context.h.count != 17 && hr.count != 17) {
  166. assertionFailure()
  167. return
  168. }
  169. var u:UInt32 = 0
  170. for i in 0..<16 {
  171. u += hr[i];
  172. context.h[i] = UInt8.withValue(v: u) // crash! h[i] = UInt8(u) & 0xff
  173. u >>= 8;
  174. }
  175. u += hr[16]
  176. context.h[16] = UInt8.withValue(v: u) & 0x03
  177. u >>= 2
  178. u += (u << 2); /* u *= 5; */
  179. for i in 0..<16 {
  180. u += UInt32(context.h[i])
  181. context.h[i] = UInt8.withValue(v: u) // crash! h[i] = UInt8(u) & 0xff
  182. u >>= 8
  183. }
  184. context.h[16] += UInt8.withValue(v: u);
  185. }
  186. private func freeze(context:Context) {
  187. assert(context.h.count == 17,"Invalid length")
  188. if (context.h.count != 17) {
  189. return
  190. }
  191. let minusp:Array<UInt8> = [0x05,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0xfc]
  192. var horig:Array<UInt8> = Array<UInt8>(repeating: 0, count: 17)
  193. /* compute h + -p */
  194. for i in 0..<17 {
  195. horig[i] = context.h[i]
  196. }
  197. add(context: context, c: minusp)
  198. /* select h if h < p, or h + -p if h >= p */
  199. let bits:[Bit] = (context.h[16] >> 7).bits()
  200. let invertedBits = bits.map({ (bit) -> Bit in
  201. return bit.inverted()
  202. })
  203. let negative = UInt8(bits: invertedBits)
  204. for i in 0..<17 {
  205. context.h[i] ^= negative & (horig[i] ^ context.h[i]);
  206. }
  207. }
  208. private func blocks(context:Context, m:Array<UInt8>, startPos:Int = 0) {
  209. var bytes = m.count
  210. let hibit = context.final ^ 1 // 1 <<128
  211. var mPos = startPos
  212. while (bytes >= Int(blockSize)) {
  213. var hr:Array<UInt32> = Array<UInt32>(repeating: 0, count: 17)
  214. var u:UInt32 = 0
  215. var c:Array<UInt8> = Array<UInt8>(repeating: 0, count: 17)
  216. /* h += m */
  217. for i in 0..<16 {
  218. c[i] = m[mPos + i]
  219. }
  220. c[16] = hibit
  221. add(context: context, c: c)
  222. /* h *= r */
  223. for i in 0..<17 {
  224. u = 0
  225. for j in 0...i {
  226. u = u + UInt32(UInt16(context.h[j])) * UInt32(context.r[i - j]) // u += (unsigned short)st->h[j] * st->r[i - j];
  227. }
  228. for j in (i+1)..<17 {
  229. var v:UInt32 = UInt32(UInt16(context.h[j])) * UInt32(context.r[i + 17 - j]) // unsigned long v = (unsigned short)st->h[j] * st->r[i + 17 - j];
  230. v = ((v << 8) &+ (v << 6))
  231. u = u &+ v
  232. }
  233. hr[i] = u
  234. }
  235. squeeze(context: context, hr: hr)
  236. mPos += blockSize
  237. bytes -= blockSize
  238. }
  239. }
  240. }