Crypt-PQClean-Sign
view release on metacpan or search on metacpan
pqclean/crypto_sign/ml-dsa-65/avx2/sign.c view on Meta::CPAN
return -1;
}
for (j = pos; j < hint[OMEGA + i]; ++j) {
/* Coefficients are ordered for strong unforgeability */
if (j > pos && hint[j] <= hint[j - 1]) {
return -1;
}
h.coeffs[hint[j]] = 1;
}
pos = hint[OMEGA + i];
PQCLEAN_MLDSA65_AVX2_poly_caddq(&w1);
PQCLEAN_MLDSA65_AVX2_poly_use_hint(&w1, &w1, &h);
PQCLEAN_MLDSA65_AVX2_polyw1_pack(buf.coeffs + i * POLYW1_PACKEDBYTES, &w1);
}
/* Extra indices are zero for strong unforgeability */
for (j = pos; j < OMEGA; ++j) {
if (hint[j]) {
return -1;
}
}
/* Call random oracle and verify challenge */
shake256_inc_init(&state);
shake256_inc_absorb(&state, mu, CRHBYTES);
shake256_inc_absorb(&state, buf.coeffs, K * POLYW1_PACKEDBYTES);
shake256_inc_finalize(&state);
shake256_inc_squeeze(buf.coeffs, CTILDEBYTES, &state);
shake256_inc_ctx_release(&state);
for (i = 0; i < CTILDEBYTES; ++i) {
if (buf.coeffs[i] != sig[i]) {
return -1;
}
}
return 0;
}
/*************************************************
* Name: crypto_sign_open
*
* Description: Verify signed message.
*
* Arguments: - uint8_t *m: pointer to output message (allocated
* array with smlen bytes), can be equal to sm
* - size_t *mlen: pointer to output length of message
* - const uint8_t *sm: pointer to signed message
* - size_t smlen: length of signed message
* - const uint8_t *ctx: pointer to context string
* - size_t ctxlen: length of context string
* - const uint8_t *pk: pointer to bit-packed public key
*
* Returns 0 if signed message could be verified correctly and -1 otherwise
**************************************************/
int PQCLEAN_MLDSA65_AVX2_crypto_sign_open_ctx(uint8_t *m, size_t *mlen, const uint8_t *sm, size_t smlen,
const uint8_t *ctx, size_t ctxlen, const uint8_t *pk) {
size_t i;
if (smlen < PQCLEAN_MLDSA65_AVX2_CRYPTO_BYTES) {
goto badsig;
}
*mlen = smlen - PQCLEAN_MLDSA65_AVX2_CRYPTO_BYTES;
if (PQCLEAN_MLDSA65_AVX2_crypto_sign_verify_ctx(sm, PQCLEAN_MLDSA65_AVX2_CRYPTO_BYTES, sm + PQCLEAN_MLDSA65_AVX2_CRYPTO_BYTES, *mlen, ctx, ctxlen, pk)) {
goto badsig;
} else {
/* All good, copy msg, return 0 */
for (i = 0; i < *mlen; ++i) {
m[i] = sm[PQCLEAN_MLDSA65_AVX2_CRYPTO_BYTES + i];
}
return 0;
}
badsig:
/* Signature verification failed */
*mlen = 0;
for (i = 0; i < smlen; ++i) {
m[i] = 0;
}
return -1;
}
( run in 0.893 second using v1.01-cache-2.11-cpan-5c0b1e786e0 )