hsalsa20.go 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146
  1. // Copyright 2012 The Go Authors. All rights reserved.
  2. // Use of this source code is governed by a BSD-style
  3. // license that can be found in the LICENSE file.
  4. // Package salsa provides low-level access to functions in the Salsa family.
  5. package salsa // import "golang.org/x/crypto/salsa20/salsa"
  6. import "math/bits"
  7. // Sigma is the Salsa20 constant for 256-bit keys.
  8. var Sigma = [16]byte{'e', 'x', 'p', 'a', 'n', 'd', ' ', '3', '2', '-', 'b', 'y', 't', 'e', ' ', 'k'}
  9. // HSalsa20 applies the HSalsa20 core function to a 16-byte input in, 32-byte
  10. // key k, and 16-byte constant c, and puts the result into the 32-byte array
  11. // out.
  12. func HSalsa20(out *[32]byte, in *[16]byte, k *[32]byte, c *[16]byte) {
  13. x0 := uint32(c[0]) | uint32(c[1])<<8 | uint32(c[2])<<16 | uint32(c[3])<<24
  14. x1 := uint32(k[0]) | uint32(k[1])<<8 | uint32(k[2])<<16 | uint32(k[3])<<24
  15. x2 := uint32(k[4]) | uint32(k[5])<<8 | uint32(k[6])<<16 | uint32(k[7])<<24
  16. x3 := uint32(k[8]) | uint32(k[9])<<8 | uint32(k[10])<<16 | uint32(k[11])<<24
  17. x4 := uint32(k[12]) | uint32(k[13])<<8 | uint32(k[14])<<16 | uint32(k[15])<<24
  18. x5 := uint32(c[4]) | uint32(c[5])<<8 | uint32(c[6])<<16 | uint32(c[7])<<24
  19. x6 := uint32(in[0]) | uint32(in[1])<<8 | uint32(in[2])<<16 | uint32(in[3])<<24
  20. x7 := uint32(in[4]) | uint32(in[5])<<8 | uint32(in[6])<<16 | uint32(in[7])<<24
  21. x8 := uint32(in[8]) | uint32(in[9])<<8 | uint32(in[10])<<16 | uint32(in[11])<<24
  22. x9 := uint32(in[12]) | uint32(in[13])<<8 | uint32(in[14])<<16 | uint32(in[15])<<24
  23. x10 := uint32(c[8]) | uint32(c[9])<<8 | uint32(c[10])<<16 | uint32(c[11])<<24
  24. x11 := uint32(k[16]) | uint32(k[17])<<8 | uint32(k[18])<<16 | uint32(k[19])<<24
  25. x12 := uint32(k[20]) | uint32(k[21])<<8 | uint32(k[22])<<16 | uint32(k[23])<<24
  26. x13 := uint32(k[24]) | uint32(k[25])<<8 | uint32(k[26])<<16 | uint32(k[27])<<24
  27. x14 := uint32(k[28]) | uint32(k[29])<<8 | uint32(k[30])<<16 | uint32(k[31])<<24
  28. x15 := uint32(c[12]) | uint32(c[13])<<8 | uint32(c[14])<<16 | uint32(c[15])<<24
  29. for i := 0; i < 20; i += 2 {
  30. u := x0 + x12
  31. x4 ^= bits.RotateLeft32(u, 7)
  32. u = x4 + x0
  33. x8 ^= bits.RotateLeft32(u, 9)
  34. u = x8 + x4
  35. x12 ^= bits.RotateLeft32(u, 13)
  36. u = x12 + x8
  37. x0 ^= bits.RotateLeft32(u, 18)
  38. u = x5 + x1
  39. x9 ^= bits.RotateLeft32(u, 7)
  40. u = x9 + x5
  41. x13 ^= bits.RotateLeft32(u, 9)
  42. u = x13 + x9
  43. x1 ^= bits.RotateLeft32(u, 13)
  44. u = x1 + x13
  45. x5 ^= bits.RotateLeft32(u, 18)
  46. u = x10 + x6
  47. x14 ^= bits.RotateLeft32(u, 7)
  48. u = x14 + x10
  49. x2 ^= bits.RotateLeft32(u, 9)
  50. u = x2 + x14
  51. x6 ^= bits.RotateLeft32(u, 13)
  52. u = x6 + x2
  53. x10 ^= bits.RotateLeft32(u, 18)
  54. u = x15 + x11
  55. x3 ^= bits.RotateLeft32(u, 7)
  56. u = x3 + x15
  57. x7 ^= bits.RotateLeft32(u, 9)
  58. u = x7 + x3
  59. x11 ^= bits.RotateLeft32(u, 13)
  60. u = x11 + x7
  61. x15 ^= bits.RotateLeft32(u, 18)
  62. u = x0 + x3
  63. x1 ^= bits.RotateLeft32(u, 7)
  64. u = x1 + x0
  65. x2 ^= bits.RotateLeft32(u, 9)
  66. u = x2 + x1
  67. x3 ^= bits.RotateLeft32(u, 13)
  68. u = x3 + x2
  69. x0 ^= bits.RotateLeft32(u, 18)
  70. u = x5 + x4
  71. x6 ^= bits.RotateLeft32(u, 7)
  72. u = x6 + x5
  73. x7 ^= bits.RotateLeft32(u, 9)
  74. u = x7 + x6
  75. x4 ^= bits.RotateLeft32(u, 13)
  76. u = x4 + x7
  77. x5 ^= bits.RotateLeft32(u, 18)
  78. u = x10 + x9
  79. x11 ^= bits.RotateLeft32(u, 7)
  80. u = x11 + x10
  81. x8 ^= bits.RotateLeft32(u, 9)
  82. u = x8 + x11
  83. x9 ^= bits.RotateLeft32(u, 13)
  84. u = x9 + x8
  85. x10 ^= bits.RotateLeft32(u, 18)
  86. u = x15 + x14
  87. x12 ^= bits.RotateLeft32(u, 7)
  88. u = x12 + x15
  89. x13 ^= bits.RotateLeft32(u, 9)
  90. u = x13 + x12
  91. x14 ^= bits.RotateLeft32(u, 13)
  92. u = x14 + x13
  93. x15 ^= bits.RotateLeft32(u, 18)
  94. }
  95. out[0] = byte(x0)
  96. out[1] = byte(x0 >> 8)
  97. out[2] = byte(x0 >> 16)
  98. out[3] = byte(x0 >> 24)
  99. out[4] = byte(x5)
  100. out[5] = byte(x5 >> 8)
  101. out[6] = byte(x5 >> 16)
  102. out[7] = byte(x5 >> 24)
  103. out[8] = byte(x10)
  104. out[9] = byte(x10 >> 8)
  105. out[10] = byte(x10 >> 16)
  106. out[11] = byte(x10 >> 24)
  107. out[12] = byte(x15)
  108. out[13] = byte(x15 >> 8)
  109. out[14] = byte(x15 >> 16)
  110. out[15] = byte(x15 >> 24)
  111. out[16] = byte(x6)
  112. out[17] = byte(x6 >> 8)
  113. out[18] = byte(x6 >> 16)
  114. out[19] = byte(x6 >> 24)
  115. out[20] = byte(x7)
  116. out[21] = byte(x7 >> 8)
  117. out[22] = byte(x7 >> 16)
  118. out[23] = byte(x7 >> 24)
  119. out[24] = byte(x8)
  120. out[25] = byte(x8 >> 8)
  121. out[26] = byte(x8 >> 16)
  122. out[27] = byte(x8 >> 24)
  123. out[28] = byte(x9)
  124. out[29] = byte(x9 >> 8)
  125. out[30] = byte(x9 >> 16)
  126. out[31] = byte(x9 >> 24)
  127. }