Source file Chacha20_poly1305.ml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
let pad16 (s : string) : string = String.make ((16 - (String.length s mod 16)) mod 16) '\000'
let le64 (n : int) : string = String.init 8 (fun i -> Char.chr ((n lsr (8 * i)) land 0xff))
let tag ~key ~nonce ~aad (ct : string) : string =
let otk = String.sub (Chacha20.block ~key ~nonce 0) 0 32 in
Poly1305.mac ~key:otk (aad ^ pad16 aad ^ ct ^ pad16 ct ^ le64 (String.length aad) ^ le64 (String.length ct))
let seal ~key ~nonce ~aad (plaintext : string) : string =
let ct = Chacha20.encrypt ~key ~nonce ~counter:1 plaintext in
ct ^ tag ~key ~nonce ~aad ct
let same (a : string) (b : string) : bool =
String.length a = String.length b
&&
let d = ref 0 in
String.iteri (fun i c -> d := !d lor (Char.code c lxor Char.code b.[i])) a;
!d = 0
let open_ ~key ~nonce ~aad (data : string) : string option =
let n = String.length data in
if n < 16 then None
else
let ct = String.sub data 0 (n - 16) and t = String.sub data (n - 16) 16 in
if same t (tag ~key ~nonce ~aad ct) then Some (Chacha20.encrypt ~key ~nonce ~counter:1 ct) else None