Skip to content
Snippets Groups Projects
Select Git revision
  • 0dce9932b6006dd601d07659921574830258ceea
  • master default protected
  • hpke
  • ppc-chacha-4core
  • delete-internal-name-mangling
  • master-updates
  • ppc-gcm
  • ppc-chacha-2core
  • refactor-ecc-mod
  • ppc-chacha-core
  • use-mpn_cnd-functions
  • optimize-ecc-invert
  • default-m4-quote-char
  • power-asm-wip
  • test-fat
  • chacha-3core-neon
  • x86_64-salsa20-2core
  • salsa20-2core-neon
  • bcrypt
  • arm-salsa20-chacha-vsra
  • test-shlib-dir
  • nettle_3.6_release_20200429
  • nettle_3.6rc3
  • nettle_3.6rc2
  • nettle_3.6rc1
  • nettle_3.5.1_release_20190627
  • nettle_3.5_release_20190626
  • nettle_3.5rc1
  • nettle_3.4.1_release_20181204
  • nettle_3.4.1rc1
  • nettle_3.4_release_20171119
  • nettle_3.4rc2
  • nettle_3.4rc1
  • nettle_3.3_release_20161001
  • nettle_3.2_release_20160128
  • nettle_3.1.1_release_20150424
  • nettle_3.1_release_20150407
  • nettle_3.1rc3
  • nettle_3.1rc2
  • nettle_3.1rc1
  • nettle_3.0_release_20140607
41 results

knuth-lfib.c

Blame
  • Forked from Nettle / nettle
    Source project has a limited visibility.
    • Niels Möller's avatar
      a0b3dc84
      Use "config.h", not <config.h>. · a0b3dc84
      Niels Möller authored
      Rev: src/nettle/cbc.c:1.7
      Rev: src/nettle/hmac.c:1.5
      Rev: src/nettle/knuth-lfib.c:1.3
      Rev: src/nettle/md5-compat.c:1.4
      Rev: src/nettle/md5-meta.c:1.3
      Rev: src/nettle/md5.c:1.7
      Rev: src/nettle/memxor.c:1.3
      Rev: src/nettle/nettle-internal.c:1.4
      a0b3dc84
      History
      Use "config.h", not <config.h>.
      Niels Möller authored
      Rev: src/nettle/cbc.c:1.7
      Rev: src/nettle/hmac.c:1.5
      Rev: src/nettle/knuth-lfib.c:1.3
      Rev: src/nettle/md5-compat.c:1.4
      Rev: src/nettle/md5-meta.c:1.3
      Rev: src/nettle/md5.c:1.7
      Rev: src/nettle/memxor.c:1.3
      Rev: src/nettle/nettle-internal.c:1.4
    knuth-lfib.c 3.65 KiB
    /* knuth-lfib.c
     *
     * A "lagged fibonacci" pseudorandomness generator.
     *
     * Described in Knuth, TAOCP, 3.6
     */
    
    /* nettle, low-level cryptographics library
     *
     * Copyright (C) 2002 Niels Mller
     *
     * Includes code copied verbatim from Knuth's TAOCP.
     *  
     * The nettle library is free software; you can redistribute it and/or modify
     * it under the terms of the GNU Lesser General Public License as published by
     * the Free Software Foundation; either version 2.1 of the License, or (at your
     * option) any later version.
     * 
     * The nettle library is distributed in the hope that it will be useful, but
     * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
     * or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General Public
     * License for more details.
     * 
     * You should have received a copy of the GNU Lesser General Public License
     * along with the nettle library; see the file COPYING.LIB.  If not, write to
     * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
     * MA 02111-1307, USA.
     */
    
    /* NOTE: This generator is totally inappropriate for cryptographic
     * applications. It is useful for generating deterministic but
     * random-looking test data, and is used by the Nettle testsuite. */
    
    #if HAVE_CONFIG_H
    # include "config.h"
    #endif
    
    #include <assert.h>
    #include <stdlib.h>
    
    #include "knuth-lfib.h"
    
    #include "macros.h"
    
    #define KK _KNUTH_LFIB_KK
    #define LL 37
    #define MM (1UL << 30)
    #define TT 70
    
    void
    knuth_lfib_init(struct knuth_lfib_ctx *ctx, uint32_t seed)
    {
      uint32_t t,j;
      uint32_t x[2*KK - 1];
      uint32_t ss = (seed + 2) & (MM-2);
    
      for (j = 0; j<KK; j++)
        {
          x[j] = ss;
          ss <<= 1;  if (ss >= MM) ss -= (MM-2);
        }
      for (;j< 2*KK-1; j++)
        x[j] = 0;
    
      x[1]++;
    
      ss = seed & (MM-1);
      for (t = TT-1; t; )
        {
          for (j = KK-1; j>0; j--)
            x[j+j] = x[j];
          for (j = 2*KK-2; j > KK-LL; j-= 2)
            x[2*KK-1-j] = x[j] & ~1;
          for (j = 2*KK-2; j>=KK; j--)
            if (x[j] & 1)
              {
                x[j-(KK-LL)] = (x[j - (KK-LL)] - x[j]) & (MM-1);
                x[j-KK] = (x[j-KK] - x[j]) & (MM-1);
              }
          if (ss & 1)
            {
              for (j=KK; j>0; j--)
                x[j] = x[j-1];
              x[0] = x[KK];
              if (x[KK] & 1)
                x[LL] = (x[LL] - x[KK]) & (MM-1);
            }
          if (ss)
            ss >>= 1;
          else
            t--;
        }
      for (j=0; j<LL; j++)
        ctx->x[j+KK-LL] = x[j];
      for (; j<KK; j++)
        ctx->x[j-LL] = x[j];
    
      ctx->index = 0;
    }     
    
    /* Get's a single number in the range 0 ... 2^30-1 */
    uint32_t
    knuth_lfib_get(struct knuth_lfib_ctx *ctx)
    {
      uint32_t value;
      assert(ctx->index < KK);
      
      value = ctx->x[ctx->index];
      ctx->x[ctx->index] -= ctx->x[(ctx->index + KK - LL) % KK];
      ctx->x[ctx->index] &= (MM-1);
      
      ctx->index = (ctx->index + 1) % KK;
    
      return value;
    } 
    
    /* NOTE: Not at all optimized. */
    void
    knuth_lfib_get_array(struct knuth_lfib_ctx *ctx,
    		     unsigned n, uint32_t *a)
    {
      unsigned i;
      
      for (i = 0; i<n; i++)
        a[i] = knuth_lfib_get(ctx);
    }
    
    /* NOTE: Not at all optimized. */
    void
    knuth_lfib_random(struct knuth_lfib_ctx *ctx,
    		  unsigned n, uint8_t *dst)
    {
      /* Use 24 bits from each number, xoring together some of the
         bits. */
      
      for (; n >= 3; n-=3, dst += 3)
        {
          uint32_t value = knuth_lfib_get(ctx);
    
          /* Xor the most significant octet (containing 6 significant bits)
           * into the lower octet. */
          value ^= (value >> 24);
    
          WRITE_UINT24(dst, value);
        }
      if (n)
        {
          /* We need one or two octets more */
          uint32_t value = knuth_lfib_get(ctx);
          switch (n)
    	{
    	case 1:
    	  *dst++ = value & 0xff;
    	  break;
    	case 2:
    	  WRITE_UINT16(dst, value);
    	  break;
    	default:
    	  abort();
    	}
        }
    }