Skip to content
  • Eric Biggers's avatar
    crypto: chacha20-generic - add XChaCha20 support · de61d7ae
    Eric Biggers authored
    Add support for the XChaCha20 stream cipher.  XChaCha20 is the
    application of the XSalsa20 construction
    (https://cr.yp.to/snuffle/xsalsa-20081128.pdf
    
    ) to ChaCha20 rather than
    to Salsa20.  XChaCha20 extends ChaCha20's nonce length from 64 bits (or
    96 bits, depending on convention) to 192 bits, while provably retaining
    ChaCha20's security.  XChaCha20 uses the ChaCha20 permutation to map the
    key and first 128 nonce bits to a 256-bit subkey.  Then, it does the
    ChaCha20 stream cipher with the subkey and remaining 64 bits of nonce.
    
    We need XChaCha support in order to add support for the Adiantum
    encryption mode.  Note that to meet our performance requirements, we
    actually plan to primarily use the variant XChaCha12.  But we believe
    it's wise to first add XChaCha20 as a baseline with a higher security
    margin, in case there are any situations where it can be used.
    Supporting both variants is straightforward.
    
    Since XChaCha20's subkey differs for each request, XChaCha20 can't be a
    template that wraps ChaCha20; that would require re-keying the
    underlying ChaCha20 for every request, which wouldn't be thread-safe.
    Instead, we make XChaCha20 its own top-level algorithm which calls the
    ChaCha20 streaming implementation internally.
    
    Similar to the existing ChaCha20 implementation, we define the IV to be
    the nonce and stream position concatenated together.  This allows users
    to seek to any position in the stream.
    
    I considered splitting the code into separate chacha20-common, chacha20,
    and xchacha20 modules, so that chacha20 and xchacha20 could be
    enabled/disabled independently.  However, since nearly all the code is
    shared anyway, I ultimately decided there would have been little benefit
    to the added complexity of separate modules.
    
    Reviewed-by: default avatarArd Biesheuvel <ard.biesheuvel@linaro.org>
    Acked-by: default avatarMartin Willi <martin@strongswan.org>
    Signed-off-by: default avatarEric Biggers <ebiggers@google.com>
    Signed-off-by: default avatarHerbert Xu <herbert@gondor.apana.org.au>
    de61d7ae