src/crypto/mac.bend checks
raw source on the hub · import 0xd9a2fae439ac7ff9e21e0853948f94fe/src/crypto/mac.bend as Mac
3 imports
import Base import ./sha/sha256.bend as SHA import ./subtle.bend as Subtle
Definitions
def block_len source · line 17 · raw
Nat
def fits source · line 22 · raw
@key:List<&2, U32> -> @n:Nat -> Bool
Whether a key fits in the block, looking at no more than 65 of its bytes (the length of a long key is never computed).
def block_key_if source · line 31 · raw
@+key:List<&2, U32> -> @short:Bool -> List<&2, U32>
def block_key source · line 39 · raw
@+key:List<&2, U32> -> List<&2, U32>
The key as it enters the block: itself, or its digest when too long.
def mask source · line 44 · raw
@key:List<&2, U32> -> @n:Nat -> @+pad:U32 -> List<&2, U32>
The n-byte block (key zero-padded to n bytes) XOR the pad byte, in one pass: past the end of the key a byte is 0 XOR pad = pad.
def sign source · line 55 · raw
@+key:List<&2, U32> -> @msg:List<&2, U32> -> List<&2, U32>
def verify source · line 62 · raw
@+key:List<&2, U32> -> @msg:List<&2, U32> -> @tag:List<&2, U32> -> Bool
The tag is compared in constant time (subtle.eq: no early exit on the contents; only the lengths, which are public, are compared directly).