ReactOS 0.4.17-dev-1005-g171e1de
sc_lib_mldsa.h
Go to the documentation of this file.
1//
2// sc_lib_mldsa.h
3//
4// Copyright (c) Microsoft Corporation. Licensed under the MIT license.
5//
6// Internal ML-DSA definitions for the symcrypt library.
7// Always intended to be included as part of sc_lib.h
8//
9
10//
11// Modulus for ML-DSA
12//
13#define SYMCRYPT_MLDSA_Q (8380417)
14
15//
16// Montgomery multiplier for ML-DSA, log 2 (i.e. R = 2^32)
17//
18#define SYMCRYPT_MLDSA_R_LOG2 (32)
19
20//
21// Size of the root seed xi used in key generation
22//
23#define SYMCRYPT_MLDSA_ROOT_SEED_SIZE (32)
24
25//
26// Size of the public seed rho
27//
28#define SYMCRYPT_MLDSA_PUBLIC_SEED_SIZE (32)
29
30//
31// Size of public key hash (tr) = SHAKE256 result size = 64 bytes
32//
33#define SYMCRYPT_MLDSA_PUBLIC_KEY_HASH_SIZE SYMCRYPT_SHAKE256_RESULT_SIZE
34
35//
36// Size of private signing seed K
37//
38#define SYMCRYPT_MLDSA_PRIVATE_SIGNING_SEED_SIZE (32)
39
40//
41// Size of the private vector seed rho prime
42//
43#define SYMCRYPT_MLDSA_PRIVATE_VECTOR_SEED_SIZE (64)
44
45//
46// Size of random value used in signing (rnd in FIPS 204)
47//
48#define SYMCRYPT_MLDSA_SIGNING_RANDOM_SIZE (32)
49
50//
51// Length of hash algorithm OIDs in bytes. Currently all supported hash algorithms have 11-byte
52// OIDs, but this is not guaranteed to be the case as more algorithms are added in the future.
53// If the OID length becomes variable, functions which use this value will need to be changed.
54//
55#define SYMCRYPT_MLDSA_SUPPORTED_HASH_OID_SIZE (11)
56
57//
58// Flag for Sign and Verify with External Mu
59//
60#define SYMCRYPT_FLAG_MLDSA_EXTERNALMU (0x1)
61
63 // PolyElements just store the coefficients without any header.
67
68// Maximum number of rows and columns in A matrix for ML-DSA
69#define SYMCRYPT_MLDSA_VECTOR_MAX_LENGTH (8)
70#define SYMCRYPT_MLDSA_MATRIX_MAX_NROWS (8)
71#define SYMCRYPT_MLDSA_MATRIX_MAX_NCOLS (7)
72
73typedef _Struct_size_bytes_( cbTotalSize ) struct _SYMCRYPT_MLDSA_VECTOR {
75 UINT8 nElems; // Number of PolyElements in the vector
76 UINT32 cbTotalSize; // Total size of the Vector
77
78 // Followed by:
79 // nElems PolyElements
82
83typedef _Struct_size_bytes_( cbTotalSize ) struct _SYMCRYPT_MLDSA_MATRIX {
85 UINT8 nRows; // k in FIPS-204
87 UINT8 nCols; // l in FIPS-204
88 UINT32 cbTotalSize; // Total size of the Matrix
89
90 // Followed by:
91 // nRows*nCols PolyElements in row-major order
94
96 UINT32 params; // parameter set of ML-DSA being used - takes a value from SYMCRYPT_MLDSA_PARAMS
97
98 UINT32 cbPolyElement; // size in bytes of one polynomial ring element
99 UINT32 cbRowVector; // size in bytes of one row vector (k elements)
100 UINT32 cbColVector; // size in bytes of one column vector (l elements)
101 UINT32 cbMatrix; // size in bytes of one matrix
102
103 UINT8 nRows; // Number of rows in the A matrix (k in FIPS-204)
104 UINT8 nCols; // Number of columns in the A matrix (l in FIPS-204)
105
106 UINT8 privateKeyRange; // Coefficient range of s1, s2 private key vectors (eta in FIPS-204)
107 UINT8 encodedCoefficientBitLength; // Bit length of encoded private key coefficients
108
109 UINT8 nChallengeNonZeroCoeffs; // Number of non-zero coefficients in the challenge polynomial (tau in FIPS-204)
110 UINT8 nHintNonZeroCoeffs; // Max number of non-zero coefficients in the hint polynomial (omega in FIPS-204)
111 UINT8 maskCoefficientRangeLog2; // Coefficient range of mask polynomial y (log_2(gamma_1) in FIPS-204)
112 UINT8 commitmentModulus; // Modulus for commitment values in UseHint and MakeHint (q-1)/(2*gamma_2)
113 UINT32 decomposeR1Factor; // Multiplication factor for R1 in SymCryptMlDsaDecompose - see function comments
114 UINT32 commitmentRoundingRange; // Rounding range for commitment value (gamma_2 in FIPS-204)
115 UINT32 w1EncodeCoefficientBitLength; // Bit length of coefficients for w1 encoding (q - 1) / ((2 * gamma_2) - 1))
116
117 UINT32 cbCommitmentHash; // Size of the commitment hash (lambda / 4 in FIPS 204)
118 UINT32 cbEncodedPrivateKey; // Size of the encoded private key
119 UINT32 cbEncodedPublicKey; // Size of the encoded public key
120 UINT32 cbEncodedSignature; // Size of the encoded signature
123
124typedef _Struct_size_bytes_( cbTotalSize ) struct _SYMCRYPT_MLDSAKEY {
125 UINT32 fAlgorithmInfo; // Tracks which algorithms the key can be used in (not currently used)
126 // Also tracks which per-key selftests have been performed on this key
127 // A bitwise OR of SYMCRYPT_FLAG_KEY_*, SYMCRYPT_FLAG_MLDSAKEY_*, and
128 // SYMCRYPT_SELFTEST_KEY_* values
129
131
132 UINT32 cbTotalSize; // Total in-memory size of the ML-DSA key (this header and the following structs)
133
134 BOOLEAN hasRootSeed; // True if the key has the seed used in key generation (xi)
135 BOOLEAN hasPrivateKey; // True if the key has private vectors s1, s2, t0
136
137 // Seeds
140 BYTE rootSeed[SYMCRYPT_MLDSA_ROOT_SEED_SIZE]; // Root seed used in key generation (xi) - only available for keys generated by SymCrypt, or imported from a seed
141
144 BYTE privateSigningSeed[SYMCRYPT_MLDSA_PRIVATE_SIGNING_SEED_SIZE]; // Private seed used in signing (K)
145
146 BYTE publicSeed[SYMCRYPT_MLDSA_PUBLIC_SEED_SIZE]; // Public seed from which A can be derived (rho)
147 BYTE publicKeyHash[SYMCRYPT_MLDSA_PUBLIC_KEY_HASH_SIZE]; // SHAKE-256 hash of the public key
148
149 //
150 // ML-DSA matrix/vector components: A * s1 + s2 = t
151 //
152 // t is separated into two components, t0 and t1, using Power2Round. t0 is private and is used
153 // during signing; t1 is public and is used during verification. All components are stored in
154 // NTT form so that we do not need to convert them during signing or verification.
155 //
156
157 // Public components - always valid
158 PSYMCRYPT_MLDSA_MATRIX pmA; // Public matrix A - size nRows x nCols
159 PSYMCRYPT_MLDSA_VECTOR pvt1; // Public component of t vector from Power2Round (row vector)
160
161 // Private components - only valid when hasPrivateKey is TRUE
162 PSYMCRYPT_MLDSA_VECTOR pvs1; // Private vector s1 (column vector)
163 PSYMCRYPT_MLDSA_VECTOR pvs2; // Private vector s2 (row vector)
164 PSYMCRYPT_MLDSA_VECTOR pvt0; // Private component of t vector from Power2Round (row vector)
165
167 // Followed by:
168 // A
169 // t1
170 // s1
171 // s2
172 // t0
175
176typedef _Struct_size_bytes_(cbTotalSize) struct _SYMCRYPT_MLDSA_INTERNAL_COMPUTATION_TEMPORARIES
177{
178 UINT32 cbTotalSize; // Total in-memory size of this structure
179 UINT32 nRowVectors; // Number of row vectors
180 UINT32 nColVectors; // Number of column vectors
181 UINT32 nPolyElements; // Number of PolyElements
182 UINT32 cbScratch; // Size of scratch buffer
183
184
186
188 PSYMCRYPT_MLDSA_VECTOR* pvRowVectors; // Array of pointers to row vectors
190 PSYMCRYPT_MLDSA_VECTOR* pvColVectors; // Array of pointers to column vectors
192 PSYMCRYPT_MLDSA_POLYELEMENT* pePolyElements; // Array of pointers to PolyElements
193
195 PBYTE pbScratch;
196
198 // Followed by:
199 // pvRowVectors[0..nRowVectors-1]
200 // pvColVectors[0..nColVectors-1]
201 // pePolyElements[0..nPolyElements-1]
202 // nRowVectors * SYMCRYPT_INTERNAL_MLDSA_SIZEOF_VECTOR( nRows ) buffer for row vectors
203 // nColVectors * SYMCRYPT_INTERNAL_MLDSA_SIZEOF_VECTOR( nCols ) buffer for column vectors
204 // nPoly * SYMCRYPT_INTERNAL_MLDSA_SIZEOF_POLYELEMENT buffer for PolyElements
205 // cbScratch bytes of scratch space
207
208#define SYMCRYPT_INTERNAL_MLDSA_SIZEOF_POLYELEMENT ( sizeof( SYMCRYPT_MLDSA_POLYELEMENT ) )
209#define SYMCRYPT_INTERNAL_MLDSA_SIZEOF_VECTOR( _nElems ) ( sizeof( SYMCRYPT_MLDSA_VECTOR ) + ( _nElems * sizeof( SYMCRYPT_MLDSA_POLYELEMENT ) ) )
210#define SYMCRYPT_INTERNAL_MLDSA_SIZEOF_MATRIX( _nRows, _nCols ) ( sizeof( SYMCRYPT_MLDSA_MATRIX ) + ( _nRows * _nCols * sizeof( SYMCRYPT_MLDSA_POLYELEMENT ) ) )
211#define SYMCRYPT_INTERNAL_MLDSA_SIZEOF_KEY( _nRows, _nCols ) ( sizeof( SYMCRYPT_MLDSAKEY) + \
212 SYMCRYPT_INTERNAL_MLDSA_SIZEOF_MATRIX( _nRows, _nCols ) + \
213 SYMCRYPT_INTERNAL_MLDSA_SIZEOF_VECTOR( _nCols ) + \
214 (SYMCRYPT_INTERNAL_MLDSA_SIZEOF_VECTOR( _nRows ) * 3u) )
215
216#define SYMCRYPT_INTERNAL_MLDSA_VECTOR_ELEMENT_OFFSET( _row ) ( sizeof( SYMCRYPT_MLDSA_VECTOR ) + (_row * SYMCRYPT_INTERNAL_MLDSA_SIZEOF_POLYELEMENT) )
217#define SYMCRYPT_INTERNAL_MLDSA_VECTOR_ELEMENT( _row, _pVector ) ((PSYMCRYPT_MLDSA_POLYELEMENT) ( ((PBYTE) (_pVector)) + SYMCRYPT_INTERNAL_MLDSA_VECTOR_ELEMENT_OFFSET( _row ) ))
218#define SYMCRYPT_INTERNAL_MLDSA_MATRIX_ELEMENT_OFFSET( _row, _col, _pMatrix ) ( sizeof( SYMCRYPT_MLDSA_MATRIX ) + ((_row * (_pMatrix)->nCols + _col) * SYMCRYPT_INTERNAL_MLDSA_SIZEOF_POLYELEMENT) )
219#define SYMCRYPT_INTERNAL_MLDSA_MATRIX_ELEMENT( _row, _col, _pMatrix) ((PSYMCRYPT_MLDSA_POLYELEMENT) ( ((PBYTE) (_pMatrix)) + SYMCRYPT_INTERNAL_MLDSA_MATRIX_ELEMENT_OFFSET( _row, _col, _pMatrix ) ))
220
221#define SYMCRYPT_INTERNAL_MLDSA_SIZEOF_ENCODED_VECTOR( _pVector, _nBitsPerCoeff ) ( ((_pVector)->nElems * SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS * (_nBitsPerCoeff) ) / 8u )
222
223// For packing signed coefficients into the minimum possible number of bits for encoding, ML-DSA
224// converts them to (signed upper bound - x) for each coefficient x. For example, when encoding
225// s1 and s2 which have coefficients in the range [-eta, eta] with ML-DSA-65 (eta = 4), 1 is encoded
226// as (4 - 1) = 3, 0 is encoded as (4 - 0) = 4, -1 is encoded as (4 - (-1)) = 5, etc. Conveniently,
227// this also works in reverse to decode the coefficients.
228#define SYMCRYPT_INTERNAL_MLDSA_SHORT_COEFFICIENT_ENCODE_DECODE( _val, _bound) ( _bound - _val )
229
231// Internal implementations of public APIs
233
237 _Inout_ PSYMCRYPT_MLDSAKEY pkMlDsakey,
238 _In_reads_( cbRootSeed ) PCBYTE pbRootSeed,
239 SIZE_T cbRootSeed,
240 UINT32 flags );
241//
242// Implements SymCryptMlDsakeyGenerate. Takes a seed from the caller so that keys can be generated
243// deterministically for testing.
244//
245// Parameters:
246// - (pbRootSeed, cbRootSeed): The seed used to generate the key (xi in FIPS 204)
247//
248// See SymCryptMlDsakeyGenerate for additional documentation.
249//
250
254 _In_ PCSYMCRYPT_MLDSAKEY pkMlDsakey,
255 _In_reads_( cbInput ) PCBYTE pbInput,
256 SIZE_T cbInput,
257 _In_reads_opt_( cbContext ) PCBYTE pbContext,
259 _In_reads_opt_( cbHashOid ) PCBYTE pbHashOid,
260 SIZE_T cbHashOid,
261 _In_reads_( cbRandom ) PCBYTE pbRandom,
262 SIZE_T cbRandom,
264 _Out_writes_( cbSignature ) PBYTE pbSignature,
265 SIZE_T cbSignature );
266//
267// Implements SymCryptMlDsaSign, SymCryptExternalMuMlDsaSign, and SymCryptHashMlDsaSign.
268// Takes the random value from the caller so that signing can be done deterministically for testing.
269//
270// Parameters:
271// - (pbInput, cbInput): The message to be signed. For SymCryptMlDsaSign, this is the full message.
272// For SymCryptHashMlDsaSign, this is the hash of the message.
273// - (pbContext, cbContext): An optional context string which will be prepended to the message.
274// - (pbHashOid, cbHashOid): The DER-encoded OID of the hash algorithm used to hash the message,
275// when using SymCryptHashMlDsaSign. Must be NULL for SymCryptMlDsaSign.
276// - (pbRandom, cbRandom): The random value used in the signing process (rnd in FIPS 204).
277// - flags: 0 or SYMCRYPT_FLAG_MLDSA_EXTERNALMU.
278//
279
283 _In_ PCSYMCRYPT_MLDSAKEY pkMlDsakey,
284 _In_reads_( cbInput ) PCBYTE pbInput,
285 SIZE_T cbInput,
286 _In_reads_opt_( cbContext ) PCBYTE pbContext,
288 _In_reads_opt_( cbHashOid ) PCBYTE pbHashOid,
289 SIZE_T cbHashOid,
290 _In_reads_( cbSignature ) PCBYTE pbSignature,
291 SIZE_T cbSignature,
292 UINT32 flags );
293//
294// Implements SymCryptMlDsaVerify, SymCryptExternalMuMlDsaVerify, and SymCryptHashMlDsaVerify.
295//
296// Parameters:
297// - (pbInput, cbInput): The message to be verified. For SymCryptMlDsaVerify, this is the full
298// message. For SymCryptHashMlDsaVerify, this is the hash of the message.
299// - (pbContext, cbContext): An optional context string which will be prepended to the message.
300// - (pbHashOid, cbHashOid): The DER-encoded OID of the hash algorithm used to hash the message,
301// when using SymCryptHashMlDsaVerify. Must be NULL for SymCryptMlDsaVerify.
302// - (pbSignature, cbSignature): The signature to be verified.
303// - flags: 0 or SYMCRYPT_FLAG_MLDSA_EXTERNALMU.
304//
305
313//
314// Initializes a SYMCRYPT_MLDSAKEY structure in the given buffer. The buffer size (cbKey) must
315// be exactly equal to the size of the key structure, which can be calculated using
316// SYMCRYPT_INTERNAL_MLDSA_SIZEOF_KEY.
317//
318// Parameters:
319// - pInternalParams: Parameter set to use for the key.
320// - (pbKey, cbKey): Buffer for the key structure.
321//
322
323VOID
333//
334// Helper function for computing the t vector in ML-DSA: A * s1 + s2 = t. Used by key generation
335// and private key import. All inputs must be in NTT form. The outputs t0 and t1 are NOT returned
336// in NTT form; it is the caller's responsibility to convert them when appropriate.
337//
338// Parameters:
339// - pmA: Public matrix A
340// - pvs1: Private vector s1.
341// - pvs2: Private vector s2.
342// - pvt0: Private component of t vector from Power2Round.
343// - pvt1: Public component of t vector from Power2Round.
344// - pvTmp: Temporary vector for intermediate computations.
345// - peTmp: Temporary PolyElement for intermediate computations.
346//
347
349// Montgomery reduction and multiplication
351
352UINT32
355//
356// Montgomery reduction
357// res = a * R^-1 mod Q.
358//
359// Note that this divides out a factor of R.
360//
361
362UINT32
365//
366// Montgomery multiplication
367// res = (a * b) / R mod Q
368//
369// Equivalent to SymCryptMlDsaMontReduce( (UINT64) a * b )
370// As above, this divides out a factor of R, which can be compensated for in either input,
371// or taken into account in the output.
372//
373
375// 32-bit modular arithmetic
377
378UINT32
381//
382// res := a + b mod Q
383//
384// Requirements: a < Q, b < Q
385//
386
387UINT32
390//
391// res := a - b mod Q
392//
393// Requirements: a < Q, b < Q
394//
395
397// Polynomial operations
399
404 _Inout_updates_( cbBuffer ) PBYTE pbBuffer,
406//
407// Initializes a SYMCRYPT_MLDSA_POLYELEMENT in the given buffer.
408// cbBuffer must be equal to SYMCRYPT_INTERNAL_MLDSA_SIZEOF_POLYELEMENT.
409//
410
411VOID
415//
416// Sets all coefficients to zero
417//
418
419VOID
423//
424// ML-DSA Polynomial Ring Element NTT:
425// peSrc = NTT(peSrc) per FIPS 204
426//
427
428VOID
432//
433// ML-DSA Polynomial Ring Element inverse NTT:
434// peSrc = InverseNTT(peSrc) per FIPS 204
435//
436
437VOID
441//
442// ML-DSA Polynomial multiplication by the Montgomery multiplier R:
443// peSrc = (peSrc * R) mod Q
444//
445
446VOID
452//
453// ML-DSA Polynomial Montgomery multiplication:
454// peDst = (peSrc1 * peSrc2) ./ R
455// where:
456// * is polynomial multiplication given sources in NTT form
457// ./ is coefficient-wise division and R is the Montgomery multiplier
458//
459// Requirements:
460// - peSrc1 and peSrc2 must be PolyElements in ML-DSA NTT form
461//
462
463VOID
469//
470// ML-DSA Polynomial Ring Element addition
471// peDst = peSrc1 + peSrc2
472//
473
474VOID
480//
481// ML-DSA Polynomial Ring Element subtraction
482// peDst = peSrc1 - peSrc2
483//
484
486// Vector operations
488
493 _Out_writes_( cbBuffer ) PBYTE pbBuffer,
496//
497// Initializes a vector of nElems PolyElements in the given buffer.
498// cbBuffer must be equal to SYMCRYPT_INTERNAL_MLDSA_SIZEOF_VECTOR( nElems ).
499//
500
501VOID
506//
507// pvDst = pvSrc. Vectors must be the same size.
508//
509
510VOID
514//
515// Sets all elements of the vector to zero.
516//
517
518VOID
524//
525// pvDst = pvSrc1 + pvSrc2
526//
527// Requirements: pvSrc1, pvSrc2, and pvDst must all have the same number of elements.
528//
529
530VOID
536//
537// pvDst = pvSrc1 - pvSrc2
538//
539// Requirements: pvSrc1, pvSrc2, and pvDst must all have the same number of elements.
540//
541
542VOID
548//
549// ML-DSA Vector-PolyElement Montgomery Multiplication:
550// pvDst[i] = (pvSrc1[i] * peSrc2) ./ R
551//
552// where:
553// * is polynomial multiplication given sources in NTT form
554// ./ is coefficient-wise division and R is Montgomery multiplier
555//
556// Requirements:
557// - peSrc2, and all elements of pvSrc1 must be in ML-DSA NTT form
558//
559
560VOID
564//
565// ML-DSA Vector NTT:
566// pvSrc[i] = NTT(pvSrc[i]) for each element in pvSrc
567//
568
569VOID
573//
574// ML-DSA Vector inverse NTT:
575// pvSrc[i] = INTT(pvSrc[i]) for each element in pvSrc
576//
577
578
580// Matrix operations
582
586 _Out_writes_( cbBuffer ) PBYTE pbBuffer,
588 UINT8 nRows,
589 UINT8 nCols );
590//
591// Initializes a matrix of nRows * nCols PolyElements in the given buffer.
592// cbBuffer must be equal to SYMCRYPT_INTERNAL_MLDSA_SIZEOF_MATRIX( nRows, nCols ).
593//
594
595VOID
602//
603// ML-DSA Matrix-Vector Montgomery Multiplication:
604// pvDst = (pmSrc1 * pvSrc2) ./ R
605//
606// where:
607// * is matrix-vector multiplication of polynomials in NTT form
608// ./ is coefficient-wise division and R is Montgomery multiplier
609//
610
611
613// Sampling and rejection
615
616VOID
619 _In_reads_( cbRejNttPolySeed ) PCBYTE pbRejNttPolySeed,
620 SIZE_T cbRejNttPolySeed,
622//
623// RejNTTPoly from FIPS 204
624// Used by SymCryptMlDsaExpandA to generate a polynomials in the public matrix A from the expanded
625// public seed. The output polynomial is in NTT form with coefficients modulo Q.
626//
627
628VOID
631 _In_reads_( cbPublicSeed ) PCBYTE pbPublicSeed,
632 SIZE_T cbPublicSeed,
634//
635// ExpandA from FIPS 204
636// Expands the public seed into the public matrix A.
637// \hat{A}[i, j] = RejNttPoly(seed || j || i) for each index (i, j) in A
638//
639
641INT8
645 _In_range_( 0, 15 ) UINT8 halfByte );
646//
647// CoeffFromHalfByte from FIPS 204
648// Converts a nibble (range [0, 15]) to a coefficient in the range [-eta, eta]
649// If the nibble is outside of the valid private key range ([0, 14] for eta = 2, [0, 8] for eta = 4),
650// returns INT8_MIN.
651//
652
653VOID
657 _In_reads_( cbRejBoundedPolySeed ) PCBYTE pbRejBoundedPolySeed,
658 SIZE_T cbRejBoundedPolySeed,
660//
661// RejBoundedPoly from FIPS 204
662// Used by SymCryptMlDsaExpandS to generate polynomials in the private vectors s1 and s2 from the
663// expanded private vector seed. Coefficients in the output polynomial are modulo Q.
664//
665
666VOID
670 _In_reads_( cbPrivateVectorSeed ) PCBYTE pbPrivateVectorSeed,
671 SIZE_T cbPrivateVectorSeed,
674//
675// ExpandS from FIPS 204
676// s1 = RejBoundedPoly(seed || i) for each index i in s1 (column vector)
677// s2 = RejBoundedPoly(seed || i) for each index i in s2 (row vector)
678//
679
680VOID
684 _In_reads_( cbCommitmentHash ) PCBYTE pbCommitmentHash,
685 SIZE_T cbCommitmentHash,
687//
688// SampleInBall from FIPS 204
689// Samples a polynomial c in R_q with coefficients in {-1, 0, 1} and Hamming weight tau.
690// As with all polynomials, coefficients are represented as unsigned integers modulo Q.
691//
692
693VOID
698 _In_reads_( cbPrivateRandom ) PCBYTE pbPrivateRandom,
699 SIZE_T cbPrivateRandom,
702//
703// ExpandMask from FIPS 204
704// Samples a polynomial vector y in R^l such that each polynomial y[r] has coefficients between
705// (-gamma_1 + 1, gamma_1) modulo Q, where gamma_1 == 2^(maskCoefficientRangeLog2) . The output
706// vector is returned in NTT form.
707//
708
709VOID
714 _Inout_ PSYMCRYPT_MLDSA_VECTOR pvWMinusCs2PlusCt0,
716 _Out_ UINT32* nBitsSet );
717//
718// MakeHint from FIPS 204
719// Computes the hint vector. Each coefficient of the polynomials in the vector is a single bit
720// indicating whether adding ct0 to (w - cs2) alters the high bits of the corresponding coefficient.
721// We define our inputs differently from FIPS 204 to reduce computations:
722//
723// In FIPS 204, MakeHint is defined as:
724// [[r1 != v1]] where r1 = HighBits(r), v1 = HighBits(r + z)
725//
726// ML-DSA.Sign_internal calls MakeHint with inputs:
727// z = -ct0, r = w - cs2 + ct0
728//
729// We can simplify this to:
730// r1 = HighBits(w - cs2 + ct0), v1 = HighBits(w - cs2)
731//
732// Note that this function modifies the inputs in place for efficiency.
733//
734
735VOID
740 _Inout_ PSYMCRYPT_MLDSA_VECTOR pvCommitment );
741//
742// UseHint from FIPS 204
743// Uses the hint vector to recalculate the original commitment vector from the approximated
744// commitment vector by setting the high bits of the coefficients that were dropped in the
745// approximation. On input, pvCommitment is the approximated commitment vector. On output, it is
746// the recalculated original commitment vector.
747//
748// TODO osgvsowi/55435592 Consider decoding the hint just-in-time to avoid allocating an
749// entire vector for it
750//
751
753// Encoding/decoding
755
756VOID
760 UINT32 nBitsPerCoefficient,
761 UINT32 signedCoefficientBound,
762 _Out_writes_( nBitsPerCoefficient * (SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS / 8) )
763 PBYTE pbDst );
764//
765// Encode a polynomial with coefficients in the range [0, 2^nBitsPerCoefficient] into a tightly
766// packed byte array.
767//
768// Signed coefficients are encoded as described in the comment for
769// SYMCRYPT_INTERNAL_MLDSA_SHORT_COEFFICIENT_ENCODE_DECODE. For these coefficients, the
770// signedCoefficientBound parameter indicates the upper bound of the coefficients when they are
771// positive, and is used to convert them from their internal representation modulo Q to the
772// encoded representation.
773//
774// For polynomials whose coefficients are always positive and do not need any special encoding
775// (e.g. t1), signedCoefficientBound must be 0.
776//
777
781 _In_reads_bytes_( nBitsPerCoefficient * (SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS / 8) )
783 UINT32 nBitsPerCoefficient,
784 UINT32 signedCoefficientBound,
786//
787// From a byte array that was previously encoded as described in SymCryptMlDsaPolyElementEncode,
788// decode a polynomial with coefficients in the range [0, 2^nBitsPerCoefficient].
789//
790// See comments on SymCryptMlDsaPolyElementEncode for information about how coefficients are
791// encoded and decoded.
792//
793
794VOID
798 UINT32 nBitsPerCoefficient,
799 UINT32 signedCoefficientBound,
800 _Out_writes_( pvSrc->nElems * nBitsPerCoefficient * (SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS / 8) )
801 PBYTE pbDst );
802//
803// Encodes a vector of polynomials into a tightly packed byte array.
804// pbDst := SymCryptMlDsaPolyElementEncode(i) for each polynomial i in pvSrc
805//
806
810 _In_reads_bytes_( pvDst->nElems * nBitsPerCoefficient * (SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS / 8) )
812 UINT32 nBitsPerCoefficient,
813 UINT32 signedCoefficientBound,
815//
816// Decodes a vector of encoded polynomials from a byte array.
817// pvDst[i] := SymCryptMlDsaPolyElementDecode(i) for each encoded polynomial i in pbSrc
818//
819
823 _In_ PCSYMCRYPT_MLDSAKEY pkMlDsakey,
824 _Out_writes_( cbDst ) PBYTE pbDst,
825 SIZE_T cbDst );
826//
827// pkEncode(key) = rho || SimpleBitPack(t1)
828//
829
833 _In_reads_( cbSrc ) PCBYTE pbSrc,
834 SIZE_T cbSrc,
836 _Inout_ PSYMCRYPT_MLDSAKEY pkMlDsakey );
837//
838// Decodes a public key from a byte array. The encoded public key only contains rho and t1.
839// We recalculate the A matrix from rho.
840//
841
846 _Out_writes_( cbDst ) PBYTE pbDst,
847 SIZE_T cbDst );
848//
849// skEncode(key) = rho || K || H(pkEncode(key)) || BitPack(s1) || BitPack(s2) || BitPack(t0)
850//
851
855 _In_reads_( cbSrc ) PCBYTE pbSrc,
856 SIZE_T cbSrc,
859//
860// Decodes a private key from a byte array. The encoded private key contains rho, K, s1, s2 and t0.
861// We recalculate the A matrix from rho, t1 by recalculating A * s1 + s2 = t. This function also
862// validates that the recalculated public key hash and t0 match the encoded values. If they do
863// not, it returns SYMCRYPT_INVALID_BLOB.
864//
865
866VOID
870 _In_reads_( cbCommitmentHash ) PBYTE pbCommitmentHash,
871 SIZE_T cbCommitmentHash,
872 _In_ PCSYMCRYPT_MLDSA_VECTOR pvResponse,
874 _Out_writes_( cbDst ) PBYTE pbDst,
875 SIZE_T cbDst );
876//
877// SigEncode from FIPS 204
878// Encodes a signature into a tightly packed byte array.
879//
880
885 _In_reads_( cbSig ) PCBYTE pbSig,
886 SIZE_T cbSig,
887 _Out_writes_( cbCommitmentHash) PBYTE pbCommitmentHash,
888 SIZE_T cbCommitmentHash,
891//
892// SigDecode from FIPS 204
893// Decodes a signature from a tightly packed byte array, producing the commitment hash, response
894// vector, and hint vector.
895//
896
897VOID
902 _Out_writes_bytes_( pParams->nHintNonZeroCoeffs + pvSrc->nElems )
903 PBYTE pbDst );
904//
905// HintBitPack from FIPS 204
906// Packs the hint vector into a byte array. The first nHintNonZeroCoeffs bytes are the indices
907// of non-zero coefficients in the vector, and the last nElems bytes contain the number of
908// non-zero coefficients in polynomials 0..i of the vector.
909//
910
915 _In_reads_bytes_( pParams->nHintNonZeroCoeffs + pvDst->nElems )
918//
919// HintBitUnpack from FIPS 204
920// Unpacks the hint vector from a byte array where each byte indicates the index of a non-zero
921// coefficient in the corresponding polynomial. See comment on SymCryptMlDsaHintBitPack for more
922// details about encoding.
923//
924
926// Auxiliary functions
928
933 _Out_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS* pInternalParams );
934//
935// Get the internal parameter structure corresponding to the given parameter set enum.
936//
937
943 SIZE_T cbHash,
944 _Out_ PCSYMCRYPT_OID* ppOid );
945//
946// Validates that the given hash algorithm meets the required collision strength for the ML-DSA
947// parameter set, as defined in FIPS 204. Also validates that cbHash matches the expected length
948// for the hash algorithm, or for XOFs, is >= the required collision strength.
949// See comments on the definition of SymCryptHashMlDsaSign
950//
951
953INT32
956//
957// Helper function which implements the mod+- operation from FIPS 204.
958// In FIPS 204, r0 := r mod+- 2^d where mod+- returns the unique element in (-(2^d/2), 2^d/2]
959// which is congruent to r modulo 2^d. Importantly, this means that r0 may be negative.
960// To use consistent data structures throughout the our implementation and simplify modular
961// arithmetic, we do not use negative numbers. Instead, we always represent negative values as
962// UINT32s modulo Q.
963//
964// Requirements: r < modulus
965//
966
968UINT32
971//
972// Returns the infinity norm of the given polynomial element as defined in FIPS 204.
973// The infinity norm is the maximum absolute value of w mod+- Q for each coefficient w in the
974// polynomial.
975//
976
977UINT32
980//
981// Returns the infinity norm of the given vector as defined in FIPS 204.
982// = max(InfinityNorm(pvSrc[i])) for each polynomial in pvSrc
983//
984
986VOID
991 _Out_opt_ UINT32 *puR1,
992 _Out_opt_ UINT32 *puR0 );
993//
994// Decompose from FIPS 204
995// Decomposes r into (r1, r0) such that r1*2*gamma_2 + r0 is congruent to r modulo q
996// See note above in SymCryptMlDsaModPlusMinus for important information about the
997// representation of r0.
998//
999
1000VOID
1006//
1007// HighBits from FIPS 204
1008// For each coefficent r of each polynomial in pvSrc, the corresponding coefficient in pvDst is
1009// set to *puR1 from Decompose(r).
1010//
1011
1012VOID
1018//
1019// LowBits from FIPS 204
1020// For each coefficent r of each polynomial in pvSrc, the corresponding coefficient in pvDst is
1021// set to *puR0 from Decompose(r).
1022//
1023
1024VOID
1028 _Out_ UINT32 *puR1,
1029 _Out_ UINT32 *puR0 );
1030//
1031// Power2Round from FIPS 204
1032// Decomposes r into (r1, r0) such that r1*2^d + r0 is congruent to r modulo q
1033// See note above in SymCryptMlDsaModPlusMinus for important information about the
1034// representation of r0.
1035//
1036
1037VOID
1043//
1044// (peDst1[i], peDst0[i]) = Power2Round(peSrc[i]) for each coefficient in peSrc
1045//
1046
1047VOID
1053//
1054// (pvDst1[i], pvDst0[i]) = Power2Round(pvSrc[i]) for each polynomial in pvSrc
1055//
1056
1058UINT32
1061//
1062// Maps a signed short coefficient to a residue modulo Q.
1063//
1064
1065_Success_( return != NULL )
1074//
1075// Allocates and initializes a SYMCRYPT_MLDSA_INTERNAL_COMPUTATION_TEMPORARIES structure and
1076// returns a pointer to the caller. Returns NULL if allocation fails.
1077//
1078
1079VOID
1083//
1084// Wipes and frees a SYMCRYPT_MLDSA_INTERNAL_COMPUTATION_TEMPORARIES structure previously allocated
1085// by SymCryptMlDsaTemporariesAllocateAndInitialize.
1086//
unsigned short UINT16
Definition: actypes.h:129
unsigned char BOOLEAN
Definition: actypes.h:127
unsigned char UINT8
Definition: actypes.h:128
COMPILER_DEPENDENT_UINT64 UINT64
Definition: actypes.h:131
int nCols
Definition: appswitch.c:55
signed char INT8
Definition: basetsd.h:183
BYTE coefficient[512/16]
Definition: bcrypt.c:2463
#define NULL
Definition: types.h:112
#define TRUE
Definition: types.h:120
GLdouble GLdouble GLdouble r
Definition: gl.h:2055
GLenum GLenum const GLfloat * coeffs
Definition: glext.h:11733
GLbitfield flags
Definition: glext.h:7161
GLboolean GLboolean GLboolean b
Definition: glext.h:6204
GLboolean GLboolean GLboolean GLboolean a
Definition: glext.h:6204
GLenum const GLfloat * params
Definition: glext.h:5645
_Use_decl_annotations_ PSYMCRYPT_MLDSA_INTERNAL_COMPUTATION_TEMPORARIES SYMCRYPT_CALL SymCryptMlDsaTemporariesAllocateAndInitialize(PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, UINT32 nRowVectors, UINT32 nColVectors, UINT32 nPolyElements, UINT32 cbScratch)
_Use_decl_annotations_ PSYMCRYPT_MLDSA_POLYELEMENT SYMCRYPT_CALL SymCryptMlDsaPolyElementCreate(PBYTE pbBuffer, SIZE_T cbBuffer)
_Use_decl_annotations_ PSYMCRYPT_MLDSAKEY SYMCRYPT_CALL SymCryptMlDsakeyInitialize(PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pInternalParams, PBYTE pbKey, UINT32 cbKey)
_Use_decl_annotations_ PSYMCRYPT_MLDSA_VECTOR SYMCRYPT_CALL SymCryptMlDsaVectorCreate(PBYTE pbBuffer, UINT32 cbBuffer, UINT8 nElems)
#define _In_reads_bytes_(s)
Definition: no_sal2.h:170
#define _In_reads_(s)
Definition: no_sal2.h:168
#define _Out_opt_
Definition: no_sal2.h:214
#define _Struct_size_bytes_(s)
Definition: no_sal2.h:386
#define _Inout_updates_(s)
Definition: no_sal2.h:182
#define _Inout_
Definition: no_sal2.h:162
#define _Success_(c)
Definition: no_sal2.h:84
#define _Field_size_(s)
Definition: no_sal2.h:332
#define _Field_size_bytes_(s)
Definition: no_sal2.h:336
#define _Post_invalid_
Definition: no_sal2.h:524
#define _Out_writes_(s)
Definition: no_sal2.h:176
#define _Out_
Definition: no_sal2.h:160
#define _In_reads_opt_(s)
Definition: no_sal2.h:222
#define _In_
Definition: no_sal2.h:158
#define _Field_range_(l, h)
Definition: no_sal2.h:380
#define _In_range_(l, h)
Definition: no_sal2.h:368
#define _Out_writes_bytes_(s)
Definition: no_sal2.h:178
#define _Field_size_bytes_part_(s, c)
Definition: no_sal2.h:344
#define _When_(c, a)
Definition: no_sal2.h:38
BYTE * PBYTE
Definition: pedump.c:66
#define SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS
Definition: sc_lib.h:4347
const SYMCRYPT_MLDSA_INTERNAL_PARAMS * PCSYMCRYPT_MLDSA_INTERNAL_PARAMS
Definition: sc_lib_mldsa.h:122
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaSkDecode(_In_reads_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, UINT32 flags, _Inout_ PSYMCRYPT_MLDSAKEY pKey)
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementPower2Round(_In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc, _Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peDst1, _Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peDst0)
UINT32 SYMCRYPT_CALL SymCryptMlDsaModSub(UINT32 a, UINT32 b)
VOID SYMCRYPT_CALL SymCryptMlDsaVectorSetZero(_Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
VOID SYMCRYPT_CALL SymCryptMlDsaVectorPower2Round(_In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst1, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst0)
VOID SYMCRYPT_CALL SymCryptMlDsaExpandA(_In_reads_(cbPublicSeed) PCBYTE pbPublicSeed, SIZE_T cbPublicSeed, _Inout_ PSYMCRYPT_MLDSA_MATRIX pmA)
#define SYMCRYPT_MLDSA_Q
Definition: sc_lib_mldsa.h:13
UINT32 nRowVectors
VOID SYMCRYPT_CALL SymCryptMlDsaMakeHint(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvWMinusCs2, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvWMinusCs2PlusCt0, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst, _Out_ UINT32 *nBitsSet)
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementINTT(_Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peSrc)
SYMCRYPT_MLDSA_VECTOR
Definition: sc_lib_mldsa.h:80
#define SYMCRYPT_MLDSA_PUBLIC_KEY_HASH_SIZE
Definition: sc_lib_mldsa.h:33
#define SYMCRYPT_MLDSA_PUBLIC_SEED_SIZE
Definition: sc_lib_mldsa.h:28
VOID SYMCRYPT_CALL SymCryptMlDsaVectorSub(_In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc1, _In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc2, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementNTT(_Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peSrc)
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementMulR(_Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peSrc)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaSignEx(_In_ PCSYMCRYPT_MLDSAKEY pkMlDsakey, _In_reads_(cbInput) PCBYTE pbInput, SIZE_T cbInput, _In_reads_opt_(cbContext) PCBYTE pbContext, _In_range_(0, SYMCRYPT_MLDSA_CONTEXT_MAX_LENGTH) SIZE_T cbContext, _In_reads_opt_(cbHashOid) PCBYTE pbHashOid, SIZE_T cbHashOid, _In_reads_(cbRandom) PCBYTE pbRandom, SIZE_T cbRandom, UINT32 flags, _Out_writes_(cbSignature) PBYTE pbSignature, SIZE_T cbSignature)
SYMCRYPT_MLDSA_INTERNAL_COMPUTATION_TEMPORARIES
Definition: sc_lib_mldsa.h:206
const SYMCRYPT_MLDSAKEY * PCSYMCRYPT_MLDSAKEY
Definition: sc_lib_mldsa.h:174
VOID SYMCRYPT_CALL SymCryptMlDsaVectorLowBits(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
FORCEINLINE UINT32 SYMCRYPT_CALL SymCryptMlDsaSignedCoefficientModQ(INT32 coefficient)
#define SYMCRYPT_MLDSA_MATRIX_MAX_NCOLS
Definition: sc_lib_mldsa.h:71
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaVerifyEx(_In_ PCSYMCRYPT_MLDSAKEY pkMlDsakey, _In_reads_(cbInput) PCBYTE pbInput, SIZE_T cbInput, _In_reads_opt_(cbContext) PCBYTE pbContext, _In_range_(0, SYMCRYPT_MLDSA_CONTEXT_MAX_LENGTH) SIZE_T cbContext, _In_reads_opt_(cbHashOid) PCBYTE pbHashOid, SIZE_T cbHashOid, _In_reads_(cbSignature) PCBYTE pbSignature, SIZE_T cbSignature, UINT32 flags)
PSYMCRYPT_MLDSA_MATRIX SYMCRYPT_CALL SymCryptMlDsaMatrixCreate(_Out_writes_(cbBuffer) PBYTE pbBuffer, UINT32 cbBuffer, UINT8 nRows, UINT8 nCols)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaVectorDecode(_In_reads_bytes_(pvDst->nElems *nBitsPerCoefficient *(SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS/8)) PCBYTE pbSrc, UINT32 nBitsPerCoefficient, UINT32 signedCoefficientBound, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
const SYMCRYPT_MLDSA_MATRIX * PCSYMCRYPT_MLDSA_MATRIX
Definition: sc_lib_mldsa.h:93
UINT32 UINT32 UINT32 nPolyElements
VOID SYMCRYPT_CALL SymCryptMlDsaExpandS(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_reads_(cbPrivateVectorSeed) PCBYTE pbPrivateVectorSeed, SIZE_T cbPrivateVectorSeed, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvs1, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvs2)
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementSub(_In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc1, _In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc2, _Out_ PSYMCRYPT_MLDSA_POLYELEMENT peDst)
VOID SYMCRYPT_CALL SymCryptMlDsakeyComputeT(_In_ PCSYMCRYPT_MLDSA_MATRIX pmA, _In_ PCSYMCRYPT_MLDSA_VECTOR pvs1, _In_ PCSYMCRYPT_MLDSA_VECTOR pvs2, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvt0, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvt1, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvTmp, _Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peTmp)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaGetInternalParamsFromParams(SYMCRYPT_MLDSA_PARAMS params, _Out_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS *pInternalParams)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaKeyGenerateEx(_Inout_ PSYMCRYPT_MLDSAKEY pkMlDsakey, _In_reads_(cbRootSeed) PCBYTE pbRootSeed, SIZE_T cbRootSeed, UINT32 flags)
SYMCRYPT_MLDSA_MATRIX
Definition: sc_lib_mldsa.h:92
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaSkEncode(_In_ PCSYMCRYPT_MLDSAKEY pKey, _Out_writes_(cbDst) PBYTE pbDst, SIZE_T cbDst)
struct _SYMCRYPT_MLDSA_POLYELEMENT * PSYMCRYPT_MLDSA_POLYELEMENT
UINT32 SYMCRYPT_CALL SymCryptMlDsaModAdd(UINT32 a, UINT32 b)
VOID SYMCRYPT_CALL SymCryptMlDsaRejNttPoly(_In_reads_(cbRejNttPolySeed) PCBYTE pbRejNttPolySeed, SIZE_T cbRejNttPolySeed, _Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peDst)
UINT32 SYMCRYPT_CALL SymCryptMlDsaMontMul(UINT32 a, UINT32 b)
VOID SYMCRYPT_CALL SymCryptMlDsaSampleInBall(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_reads_(cbCommitmentHash) PCBYTE pbCommitmentHash, SIZE_T cbCommitmentHash, _Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peChallenge)
VOID SYMCRYPT_CALL SymCryptMlDsaExpandMask(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _Inout_ PSYMCRYPT_SHAKE256_STATE pShakeState, _In_reads_(cbPrivateRandom) PCBYTE pbPrivateRandom, SIZE_T cbPrivateRandom, _In_ UINT16 counter, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvMask)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptHashMlDsaValidateHashAlgAndGetOid(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, SYMCRYPT_PQDSA_HASH_ID hashAlg, SIZE_T cbHash, _Out_ PCSYMCRYPT_OID *ppOid)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaPolyElementDecode(_In_reads_bytes_(nBitsPerCoefficient *(SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS/8)) PCBYTE pbSrc, UINT32 nBitsPerCoefficient, UINT32 signedCoefficientBound, _Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peDst)
const SYMCRYPT_MLDSA_VECTOR * PCSYMCRYPT_MLDSA_VECTOR
Definition: sc_lib_mldsa.h:81
VOID SYMCRYPT_CALL SymCryptMlDsaHintBitPack(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc, _Out_writes_bytes_(pParams->nHintNonZeroCoeffs+pvSrc->nElems) PBYTE pbDst)
VOID SYMCRYPT_CALL SymCryptMlDsaVectorAdd(_In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc1, _In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc2, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
struct _SYMCRYPT_MLDSA_INTERNAL_PARAMS * PSYMCRYPT_MLDSA_INTERNAL_PARAMS
VOID SYMCRYPT_CALL SymCryptMlDsaSigEncode(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_reads_(cbCommitmentHash) PBYTE pbCommitmentHash, SIZE_T cbCommitmentHash, _In_ PCSYMCRYPT_MLDSA_VECTOR pvResponse, _In_ PCSYMCRYPT_MLDSA_VECTOR pvHint, _Out_writes_(cbDst) PBYTE pbDst, SIZE_T cbDst)
struct _SYMCRYPT_MLDSA_INTERNAL_PARAMS SYMCRYPT_MLDSA_INTERNAL_PARAMS
VOID SYMCRYPT_CALL SymCryptMlDsaVectorHighBits(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
FORCEINLINE INT8 SYMCRYPT_CALL SymCryptMlDsaCoeffFromHalfByte(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_range_(0, 15) UINT8 halfByte)
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementAdd(_In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc1, _In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc2, _Out_ PSYMCRYPT_MLDSA_POLYELEMENT peDst)
* PSYMCRYPT_MLDSAKEY
Definition: sc_lib_mldsa.h:173
SYMCRYPT_MLDSAKEY
Definition: sc_lib_mldsa.h:173
#define SYMCRYPT_MLDSA_ROOT_SEED_SIZE
Definition: sc_lib_mldsa.h:23
struct _SYMCRYPT_MLDSA_POLYELEMENT SYMCRYPT_MLDSA_POLYELEMENT
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaPkDecode(_In_reads_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, UINT32 flags, _Inout_ PSYMCRYPT_MLDSAKEY pkMlDsakey)
UINT32 UINT32 nColVectors
#define SYMCRYPT_MLDSA_VECTOR_MAX_LENGTH
Definition: sc_lib_mldsa.h:69
UINT32 UINT32 UINT32 UINT32 cbScratch
SIZE_T cbBuffer
Definition: sc_lib_mldsa.h:405
FORCEINLINE INT32 SYMCRYPT_CALL SymCryptMlDsaModPlusMinus(UINT32 r, UINT32 modulus)
VOID SYMCRYPT_CALL SymCryptMlDsaPower2Round(_In_range_(0, SYMCRYPT_MLDSA_Q - 1) UINT32 r, _Out_ UINT32 *puR1, _Out_ UINT32 *puR0)
VOID SYMCRYPT_CALL SymCryptMlDsaVectorPolyElementMontMul(_In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc1, _In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc2, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementMontMul(_In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc1, _In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc2, _Out_ PSYMCRYPT_MLDSA_POLYELEMENT peDst)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaSigDecode(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_reads_(cbSig) PCBYTE pbSig, SIZE_T cbSig, _Out_writes_(cbCommitmentHash) PBYTE pbCommitmentHash, SIZE_T cbCommitmentHash, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvResponse, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvHint)
VOID SYMCRYPT_CALL SymCryptMlDsaRejBoundedPoly(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_reads_(cbRejBoundedPolySeed) PCBYTE pbRejBoundedPolySeed, SIZE_T cbRejBoundedPolySeed, _Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peDst)
VOID SYMCRYPT_CALL SymCryptMlDsaUseHint(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_ PCSYMCRYPT_MLDSA_VECTOR pvHint, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvCommitment)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaHintBitUnpack(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_reads_bytes_(pParams->nHintNonZeroCoeffs+pvDst->nElems) PCBYTE pbSrc, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
UINT32 UINT8 nElems
Definition: sc_lib_mldsa.h:495
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementSetZero(_Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peDst)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlDsaPkEncode(_In_ PCSYMCRYPT_MLDSAKEY pkMlDsakey, _Out_writes_(cbDst) PBYTE pbDst, SIZE_T cbDst)
* PSYMCRYPT_MLDSA_VECTOR
Definition: sc_lib_mldsa.h:80
VOID SYMCRYPT_CALL SymCryptMlDsaTemporariesFree(_In_ _Post_invalid_ PSYMCRYPT_MLDSA_INTERNAL_COMPUTATION_TEMPORARIES pTemporaries)
VOID SYMCRYPT_CALL SymCryptMlDsaVectorNTT(_Inout_ PSYMCRYPT_MLDSA_VECTOR pvSrc)
* PSYMCRYPT_MLDSA_INTERNAL_COMPUTATION_TEMPORARIES
Definition: sc_lib_mldsa.h:206
VOID SYMCRYPT_CALL SymCryptMlDsaVectorINTT(_Inout_ PSYMCRYPT_MLDSA_VECTOR pvSrc)
VOID SYMCRYPT_CALL SymCryptMlDsaVectorCopy(_In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst)
VOID SYMCRYPT_CALL SymCryptMlDsaMatrixVectorMontMul(_In_ PCSYMCRYPT_MLDSA_MATRIX pmSrc1, _In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc2, _Inout_ PSYMCRYPT_MLDSA_VECTOR pvDst, _Inout_ PSYMCRYPT_MLDSA_POLYELEMENT peTmp)
#define SYMCRYPT_MLDSA_PRIVATE_SIGNING_SEED_SIZE
Definition: sc_lib_mldsa.h:38
UINT32 SYMCRYPT_CALL SymCryptMlDsaVectorInfinityNorm(_In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc)
const SYMCRYPT_MLDSA_POLYELEMENT * PCSYMCRYPT_MLDSA_POLYELEMENT
Definition: sc_lib_mldsa.h:66
* PSYMCRYPT_MLDSA_MATRIX
Definition: sc_lib_mldsa.h:92
VOID SYMCRYPT_CALL SymCryptMlDsaVectorEncode(_In_ PCSYMCRYPT_MLDSA_VECTOR pvSrc, UINT32 nBitsPerCoefficient, UINT32 signedCoefficientBound, _Out_writes_(pvSrc->nElems *nBitsPerCoefficient *(SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS/8)) PBYTE pbDst)
FORCEINLINE VOID SYMCRYPT_CALL SymCryptMlDsaDecompose(_In_ PCSYMCRYPT_MLDSA_INTERNAL_PARAMS pParams, _In_range_(0, SYMCRYPT_MLDSA_Q - 1) UINT32 r, _Out_opt_ UINT32 *puR1, _Out_opt_ UINT32 *puR0)
#define SYMCRYPT_MLDSA_MATRIX_MAX_NROWS
Definition: sc_lib_mldsa.h:70
UINT32 SYMCRYPT_CALL SymCryptMlDsaMontReduce(UINT64 a)
FORCEINLINE UINT32 SYMCRYPT_CALL SymCryptMlDsaPolyElementInfinityNorm(_In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc)
VOID SYMCRYPT_CALL SymCryptMlDsaPolyElementEncode(_In_ PCSYMCRYPT_MLDSA_POLYELEMENT peSrc, UINT32 nBitsPerCoefficient, UINT32 signedCoefficientBound, _Out_writes_(nBitsPerCoefficient *(SYMCRYPT_MLWE_POLYNOMIAL_COEFFICIENTS/8)) PBYTE pbDst)
UINT8 nRows
Definition: sc_lib_mlkem.h:69
SYMCRYPT_SHAKE256_STATE shake256State
Definition: sc_lib_mlkem.h:143
BYTE publicSeed[32]
Definition: sc_lib_mlkem.h:99
#define SYMCRYPT_MLDSA_CONTEXT_MAX_LENGTH
Definition: symcrypt.h:10395
enum _SYMCRYPT_PQDSA_HASH_ID SYMCRYPT_PQDSA_HASH_ID
enum _SYMCRYPT_MLDSA_PARAMS SYMCRYPT_MLDSA_PARAMS
SYMCRYPT_ERROR
Definition: symcrypt.h:227
PCBYTE pbSrc
UINT32 cbTotalSize
#define SYMCRYPT_CALL
const SYMCRYPT_MLDSAKEY * PCSYMCRYPT_MLDSAKEY
PCBYTE pbKey
SYMCRYPT_MAGIC_FIELD SYMCRYPT_SHAKE256_STATE
struct _SYMCRYPT_MLDSAKEY SYMCRYPT_MLDSAKEY
PCBYTE SIZE_T cbKey
PCBYTE PBYTE pbDst
PCSYMCRYPT_HMAC_MD5_EXPANDED_KEY pKey
#define SYMCRYPT_MAGIC_FIELD
const BYTE * PCBYTE
SYMCRYPT_MLDSAKEY * PSYMCRYPT_MLDSAKEY
BOOLEAN hasPrivateKey
SYMCRYPT_MAGIC_FIELD * PSYMCRYPT_SHAKE256_STATE
int32_t INT32
Definition: typedefs.h:58
ULONG_PTR SIZE_T
Definition: typedefs.h:80
uint32_t UINT32
Definition: typedefs.h:59
#define FORCEINLINE
Definition: wdftypes.h:67
unsigned char BYTE
Definition: xxhash.c:193