yarrow.h 3.6 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1
/* yarrow.h
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

   The yarrow pseudo-randomness generator.

   Copyright (C) 2001 Niels Möller

   This file is part of GNU Nettle.

   GNU Nettle is free software: you can redistribute it and/or
   modify it under the terms of either:

     * the GNU Lesser General Public License as published by the Free
       Software Foundation; either version 3 of the License, or (at your
       option) any later version.

   or

     * the GNU General Public License as published by the Free
       Software Foundation; either version 2 of the License, or (at your
       option) any later version.

   or both in parallel, as here.

   GNU Nettle is distributed in the hope that it will be useful,
   but WITHOUT ANY WARRANTY; without even the implied warranty of
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
   General Public License for more details.

   You should have received copies of the GNU General Public License and
   the GNU Lesser General Public License along with this program.  If
   not, see http://www.gnu.org/licenses/.
*/
Niels Möller's avatar
Niels Möller committed
33
 
Niels Möller's avatar
Niels Möller committed
34 35
#ifndef NETTLE_YARROW_H_INCLUDED
#define NETTLE_YARROW_H_INCLUDED
Niels Möller's avatar
Niels Möller committed
36

37
#include "aes.h"
38
#include "sha2.h"
Niels Möller's avatar
Niels Möller committed
39

Niels Möller's avatar
Niels Möller committed
40 41 42 43
#ifdef __cplusplus
extern "C" {
#endif

44 45 46 47 48 49 50
/* Name mangling */
#define yarrow256_init nettle_yarrow256_init
#define yarrow256_seed nettle_yarrow256_seed
#define yarrow256_update nettle_yarrow256_update
#define yarrow256_random nettle_yarrow256_random
#define yarrow256_is_seeded nettle_yarrow256_is_seeded
#define yarrow256_needed_sources nettle_yarrow256_needed_sources
51 52
#define yarrow256_fast_reseed nettle_yarrow256_fast_reseed
#define yarrow256_slow_reseed nettle_yarrow256_slow_reseed
53 54 55
#define yarrow_key_event_init nettle_yarrow_key_event_init
#define yarrow_key_event_estimate nettle_yarrow_key_event_estimate

56 57 58 59
/* Obsolete alias for backwards compatibility. Will be deleted in some
   later version. */
#define yarrow256_force_reseed yarrow256_slow_reseed
  
Niels Möller's avatar
Niels Möller committed
60 61 62 63
enum yarrow_pool_id { YARROW_FAST = 0, YARROW_SLOW = 1 };

struct yarrow_source
{
64 65
  /* Indexed by yarrow_pool_id */
  uint32_t estimate[2];
Niels Möller's avatar
Niels Möller committed
66 67 68 69 70
  
  /* The pool next sample should go to. */
  enum yarrow_pool_id next;
};

Niels Möller's avatar
Niels Möller committed
71

72
#define YARROW256_SEED_FILE_SIZE (2 * AES_BLOCK_SIZE)
Niels Möller's avatar
Niels Möller committed
73

74 75 76 77 78 79 80 81
/* Yarrow-256, based on SHA-256 and AES-256 */
struct yarrow256_ctx
{
  /* Indexed by yarrow_pool_id */
  struct sha256_ctx pools[2];

  int seeded;

82
  /* The current key and counter block */
83
  struct aes256_ctx key;
84 85 86 87 88 89 90 91 92
  uint8_t counter[AES_BLOCK_SIZE];

  /* The entropy sources */
  unsigned nsources;
  struct yarrow_source *sources;
};

void
yarrow256_init(struct yarrow256_ctx *ctx,
93
	       unsigned nsources,
94 95 96
	       struct yarrow_source *sources);

void
97
yarrow256_seed(struct yarrow256_ctx *ctx,
98
	       size_t length,
99
	       const uint8_t *seed_file);
100 101 102

/* Returns 1 on reseed */
int
103 104
yarrow256_update(struct yarrow256_ctx *ctx,
		 unsigned source, unsigned entropy,
105
		 size_t length, const uint8_t *data);
106 107

void
108
yarrow256_random(struct yarrow256_ctx *ctx, size_t length, uint8_t *dst);
109 110

int
111
yarrow256_is_seeded(struct yarrow256_ctx *ctx);
112

113 114
unsigned
yarrow256_needed_sources(struct yarrow256_ctx *ctx);
115

116
void
117 118 119 120
yarrow256_fast_reseed(struct yarrow256_ctx *ctx);

void
yarrow256_slow_reseed(struct yarrow256_ctx *ctx);
121 122


123
/* Key event estimator */
124 125
#define YARROW_KEY_EVENT_BUFFER 16

126 127 128 129
struct yarrow_key_event_ctx
{
  /* Counter for initial priming of the state */
  unsigned index;
130
  unsigned chars[YARROW_KEY_EVENT_BUFFER];
131 132
  unsigned previous;
};
Niels Möller's avatar
Niels Möller committed
133

134 135 136 137 138 139 140
void
yarrow_key_event_init(struct yarrow_key_event_ctx *ctx);

unsigned
yarrow_key_event_estimate(struct yarrow_key_event_ctx *ctx,
			  unsigned key, unsigned time);
  
Niels Möller's avatar
Niels Möller committed
141 142 143 144
#ifdef __cplusplus
}
#endif

Niels Möller's avatar
Niels Möller committed
145
#endif /* NETTLE_YARROW_H_INCLUDED */