src/crypto/chacha/core.bend checks
raw source on the hub · import 0xd9a2fae439ac7ff9e21e0853948f94fe/src/crypto/chacha/core.bend as Core
Generated by tools/generators/chacha_gen.py; do not edit. The ChaCha core (RFC 8439 sections 2.1-2.3): the sixteen-word state as a record, one double round (four column and four diagonal quarter rounds) fully unrolled with constant rotations, and the block function with the number of double rounds as a parameter (ChaCha20: 10; ChaCha8: 4; ChaCha12: 6). No operation depends on secret data for its control flow or memory access: the round count is public and every step is an add, xor or constant rotation.
1 import
import Base
Types
type State source · line 11 · raw
Data
S@x0:U32 -> @x1:U32 -> @x2:U32 -> @x3:U32 -> @x4:U32 -> @x5:U32 -> @x6:U32 -> @x7:U32 -> @x8:U32 -> @x9:U32 -> @x10:U32 -> @x11:U32 -> @x12:U32 -> @x13:U32 -> @x14:U32 -> @x15:U32 -> State
Definitions
def double_round source · line 16 · raw
@s:State -> State
One double round: QUARTERROUND on the columns (0,4,8,12) .. (3,7,11,15), then on the diagonals (0,5,10,15) (1,6,11,12) (2,7,8,13) (3,4,9,14).
def rounds source · line 117 · raw
@n:Nat -> @s:State -> State
n double rounds (2n rounds).
def add source · line 123 · raw
@a:State -> @b:State -> State
Word-wise sum of two states (the feed-forward).
def block source · line 129 · raw
@+n:Nat -> @+s:State -> State
The block function with n double rounds: the rounds, then the input added.
def init source · line 133 · raw
@k0:U32 -> @k1:U32 -> @k2:U32 -> @k3:U32 -> @k4:U32 -> @k5:U32 -> @k6:U32 -> @k7:U32 -> @counter:U32 -> @n0:U32 -> @n1:U32 -> @n2:U32 -> State
The ChaCha20 input state: constants, key, block counter, nonce.
def hinit source · line 137 · raw
@k0:U32 -> @k1:U32 -> @k2:U32 -> @k3:U32 -> @k4:U32 -> @k5:U32 -> @k6:U32 -> @k7:U32 -> @n0:U32 -> @n1:U32 -> @n2:U32 -> @n3:U32 -> State
The HChaCha20 input state: constants, key, the four words of the 16-byte nonce.
def bytes source · line 141 · raw
@s:State -> List<&2, U32>
The 64 little-endian bytes of a state.
def hbytes source · line 147 · raw
@s:State -> List<&2, U32>
HChaCha20's output: the little-endian bytes of words 0..3 and 12..15.