10SN/A#ifdef WITH_XMSS
21472SN/A/* $OpenBSD: xmss_fast.h,v 1.2 2018/02/26 03:56:44 dtucker Exp $ */
30SN/A/*
40SN/Axmss_fast.h version 20160722
50SN/AAndreas H��lsing
60SN/AJoost Rijneveld
70SN/APublic domain.
80SN/A*/
90SN/A
100SN/A#include "xmss_wots.h"
110SN/A
120SN/A#ifndef XMSS_H
130SN/A#define XMSS_H
140SN/Atypedef struct{
150SN/A  unsigned int level;
160SN/A  unsigned long long subtree;
170SN/A  unsigned int subleaf;
180SN/A} leafaddr;
191472SN/A
201472SN/Atypedef struct{
211472SN/A  wots_params wots_par;
220SN/A  unsigned int n;
230SN/A  unsigned int h;
240SN/A  unsigned int k;
250SN/A} xmss_params;
260SN/A
270SN/Atypedef struct{
280SN/A  xmss_params xmss_par;
290SN/A  unsigned int n;
300SN/A  unsigned int h;
310SN/A  unsigned int d;
320SN/A  unsigned int index_len;
330SN/A} xmssmt_params;
340SN/A
350SN/Atypedef struct{
360SN/A  unsigned int h;
370SN/A  unsigned int next_idx;
380SN/A  unsigned int stackusage;
390SN/A  unsigned char completed;
400SN/A  unsigned char *node;
410SN/A} treehash_inst;
420SN/A
43typedef struct {
44  unsigned char *stack;
45  unsigned int stackoffset;
46  unsigned char *stacklevels;
47  unsigned char *auth;
48  unsigned char *keep;
49  treehash_inst *treehash;
50  unsigned char *retain;
51  unsigned int next_leaf;
52} bds_state;
53
54/**
55 * Initialize BDS state struct
56 * parameter names are the same as used in the description of the BDS traversal
57 */
58void xmss_set_bds_state(bds_state *state, unsigned char *stack, int stackoffset, unsigned char *stacklevels, unsigned char *auth, unsigned char *keep, treehash_inst *treehash, unsigned char *retain, int next_leaf);
59/**
60 * Initializes parameter set.
61 * Needed, for any of the other methods.
62 */
63int xmss_set_params(xmss_params *params, int n, int h, int w, int k);
64/**
65 * Initialize xmssmt_params struct
66 * parameter names are the same as in the draft
67 *
68 * Especially h is the total tree height, i.e. the XMSS trees have height h/d
69 */
70int xmssmt_set_params(xmssmt_params *params, int n, int h, int d, int w, int k);
71/**
72 * Generates a XMSS key pair for a given parameter set.
73 * Format sk: [(32bit) idx || SK_SEED || SK_PRF || PUB_SEED || root]
74 * Format pk: [root || PUB_SEED] omitting algo oid.
75 */
76int xmss_keypair(unsigned char *pk, unsigned char *sk, bds_state *state, xmss_params *params);
77/**
78 * Signs a message.
79 * Returns
80 * 1. an array containing the signature followed by the message AND
81 * 2. an updated secret key!
82 *
83 */
84int xmss_sign(unsigned char *sk, bds_state *state, unsigned char *sig_msg, unsigned long long *sig_msg_len, const unsigned char *msg,unsigned long long msglen, const xmss_params *params);
85/**
86 * Verifies a given message signature pair under a given public key.
87 *
88 * Note: msg and msglen are pure outputs which carry the message in case verification succeeds. The (input) message is assumed to be within sig_msg which has the form (sig||msg).
89 */
90int xmss_sign_open(unsigned char *msg,unsigned long long *msglen, const unsigned char *sig_msg,unsigned long long sig_msg_len, const unsigned char *pk, const xmss_params *params);
91
92/*
93 * Generates a XMSSMT key pair for a given parameter set.
94 * Format sk: [(ceil(h/8) bit) idx || SK_SEED || SK_PRF || PUB_SEED || root]
95 * Format pk: [root || PUB_SEED] omitting algo oid.
96 */
97int xmssmt_keypair(unsigned char *pk, unsigned char *sk, bds_state *states, unsigned char *wots_sigs, xmssmt_params *params);
98/**
99 * Signs a message.
100 * Returns
101 * 1. an array containing the signature followed by the message AND
102 * 2. an updated secret key!
103 *
104 */
105int xmssmt_sign(unsigned char *sk, bds_state *state, unsigned char *wots_sigs, unsigned char *sig_msg, unsigned long long *sig_msg_len, const unsigned char *msg, unsigned long long msglen, const xmssmt_params *params);
106/**
107 * Verifies a given message signature pair under a given public key.
108 */
109int xmssmt_sign_open(unsigned char *msg, unsigned long long *msglen, const unsigned char *sig_msg, unsigned long long sig_msg_len, const unsigned char *pk, const xmssmt_params *params);
110#endif
111#endif /* WITH_XMSS */
112