poly1305-jni.c 5.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210
  1. /* _____ _
  2. * |_ _| |_ _ _ ___ ___ _ __ __ _
  3. * | | | ' \| '_/ -_) -_) ' \/ _` |_
  4. * |_| |_||_|_| \___\___|_|_|_\__,_(_)
  5. *
  6. * Threema Java Client
  7. * Copyright (c) 2015-2020 Threema GmbH
  8. *
  9. * This program is free software: you can redistribute it and/or modify
  10. * it under the terms of the GNU Affero General Public License, version 3,
  11. * as published by the Free Software Foundation.
  12. *
  13. * This program is distributed in the hope that it will be useful,
  14. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. * GNU Affero General Public License for more details.
  17. *
  18. * You should have received a copy of the GNU Affero General Public License
  19. * along with this program. If not, see <https://www.gnu.org/licenses/>.
  20. */
  21. #include <string.h>
  22. #include <jni.h>
  23. int crypto_onetimeauth(unsigned char *out,const unsigned char *in,unsigned long long inlen,const unsigned char *k);
  24. int crypto_onetimeauth_verify(const unsigned char *h,const unsigned char *in,unsigned long long inlen,const unsigned char *k);
  25. JNIEXPORT jint JNICALL Java_com_neilalexander_jnacl_crypto_poly1305_crypto_1onetimeauth_1native(JNIEnv* env, jclass cls,
  26. jbyteArray outvarr, jint outvoffset, jbyteArray invarr, jint invoffset, jlong inlen, jbyteArray karr)
  27. {
  28. jbyte outv[16];
  29. jbyte *inv;
  30. jbyte k[32];
  31. int res;
  32. if ((*env)->GetArrayLength(env, invarr) < (inlen + invoffset)) {
  33. /* bad length */
  34. return 1;
  35. }
  36. (*env)->GetByteArrayRegion(env, karr, 0, 32, k);
  37. inv = (*env)->GetPrimitiveArrayCritical(env, invarr, NULL);
  38. if (inv == NULL)
  39. return 4;
  40. res = crypto_onetimeauth((unsigned char *)outv, (unsigned char *)(inv + invoffset), inlen, (unsigned char *)k);
  41. (*env)->ReleasePrimitiveArrayCritical(env, invarr, inv, JNI_ABORT);
  42. (*env)->SetByteArrayRegion(env, outvarr, outvoffset, 16, outv);
  43. return res;
  44. }
  45. JNIEXPORT jint JNICALL Java_com_neilalexander_jnacl_crypto_poly1305_crypto_1onetimeauth_1verify_1native(JNIEnv* env, jclass cls,
  46. jbyteArray harr, jint hoffset, jbyteArray invarr, jint invoffset, jlong inlen, jbyteArray karr)
  47. {
  48. jbyte h[16];
  49. jbyte *inv;
  50. jbyte k[32];
  51. int res;
  52. if ((*env)->GetArrayLength(env, invarr) < (inlen + invoffset)) {
  53. /* bad length */
  54. return 1;
  55. }
  56. (*env)->GetByteArrayRegion(env, karr, 0, 32, k);
  57. (*env)->GetByteArrayRegion(env, harr, hoffset, 16, h);
  58. inv = (*env)->GetPrimitiveArrayCritical(env, invarr, NULL);
  59. if (inv == NULL)
  60. return 4;
  61. res = crypto_onetimeauth_verify((unsigned char *)h, (unsigned char *)(inv + invoffset), inlen, (unsigned char *)k);
  62. (*env)->ReleasePrimitiveArrayCritical(env, invarr, inv, JNI_ABORT);
  63. return res;
  64. }
  65. /* Public Domain code copied verbatim from NaCl below */
  66. static void add(unsigned int h[17],const unsigned int c[17])
  67. {
  68. unsigned int j;
  69. unsigned int u;
  70. u = 0;
  71. for (j = 0;j < 17;++j) { u += h[j] + c[j]; h[j] = u & 255; u >>= 8; }
  72. }
  73. static void squeeze(unsigned int h[17])
  74. {
  75. unsigned int j;
  76. unsigned int u;
  77. u = 0;
  78. for (j = 0;j < 16;++j) { u += h[j]; h[j] = u & 255; u >>= 8; }
  79. u += h[16]; h[16] = u & 3;
  80. u = 5 * (u >> 2);
  81. for (j = 0;j < 16;++j) { u += h[j]; h[j] = u & 255; u >>= 8; }
  82. u += h[16]; h[16] = u;
  83. }
  84. static const unsigned int minusp[17] = {
  85. 5, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 252
  86. } ;
  87. static void freeze(unsigned int h[17])
  88. {
  89. unsigned int horig[17];
  90. unsigned int j;
  91. unsigned int negative;
  92. for (j = 0;j < 17;++j) horig[j] = h[j];
  93. add(h,minusp);
  94. negative = -(h[16] >> 7);
  95. for (j = 0;j < 17;++j) h[j] ^= negative & (horig[j] ^ h[j]);
  96. }
  97. static void mulmod(unsigned int h[17],const unsigned int r[17])
  98. {
  99. unsigned int hr[17];
  100. unsigned int i;
  101. unsigned int j;
  102. unsigned int u;
  103. for (i = 0;i < 17;++i) {
  104. u = 0;
  105. for (j = 0;j <= i;++j) u += h[j] * r[i - j];
  106. for (j = i + 1;j < 17;++j) u += 320 * h[j] * r[i + 17 - j];
  107. hr[i] = u;
  108. }
  109. for (i = 0;i < 17;++i) h[i] = hr[i];
  110. squeeze(h);
  111. }
  112. int crypto_verify_16(const unsigned char *x,const unsigned char *y)
  113. {
  114. unsigned int differentbits = 0;
  115. #define F(i) differentbits |= x[i] ^ y[i];
  116. F(0)
  117. F(1)
  118. F(2)
  119. F(3)
  120. F(4)
  121. F(5)
  122. F(6)
  123. F(7)
  124. F(8)
  125. F(9)
  126. F(10)
  127. F(11)
  128. F(12)
  129. F(13)
  130. F(14)
  131. F(15)
  132. return (1 & ((differentbits - 1) >> 8)) - 1;
  133. }
  134. int crypto_onetimeauth(unsigned char *out,const unsigned char *in,unsigned long long inlen,const unsigned char *k)
  135. {
  136. unsigned int j;
  137. unsigned int r[17];
  138. unsigned int h[17];
  139. unsigned int c[17];
  140. r[0] = k[0];
  141. r[1] = k[1];
  142. r[2] = k[2];
  143. r[3] = k[3] & 15;
  144. r[4] = k[4] & 252;
  145. r[5] = k[5];
  146. r[6] = k[6];
  147. r[7] = k[7] & 15;
  148. r[8] = k[8] & 252;
  149. r[9] = k[9];
  150. r[10] = k[10];
  151. r[11] = k[11] & 15;
  152. r[12] = k[12] & 252;
  153. r[13] = k[13];
  154. r[14] = k[14];
  155. r[15] = k[15] & 15;
  156. r[16] = 0;
  157. for (j = 0;j < 17;++j) h[j] = 0;
  158. while (inlen > 0) {
  159. for (j = 0;j < 17;++j) c[j] = 0;
  160. for (j = 0;(j < 16) && (j < inlen);++j) c[j] = in[j];
  161. c[j] = 1;
  162. in += j; inlen -= j;
  163. add(h,c);
  164. mulmod(h,r);
  165. }
  166. freeze(h);
  167. for (j = 0;j < 16;++j) c[j] = k[j + 16];
  168. c[16] = 0;
  169. add(h,c);
  170. for (j = 0;j < 16;++j) out[j] = h[j];
  171. return 0;
  172. }
  173. int crypto_onetimeauth_verify(const unsigned char *h,const unsigned char *in,unsigned long long inlen,const unsigned char *k)
  174. {
  175. unsigned char correct[16];
  176. crypto_onetimeauth(correct,in,inlen,k);
  177. return crypto_verify_16(h,correct);
  178. }