diff options
| author | Stefan Majewsky <majewsky@gmx.net> | 2017-05-04 22:36:53 +0200 |
|---|---|---|
| committer | Stefan Majewsky <majewsky@gmx.net> | 2017-05-04 22:36:53 +0200 |
| commit | ec4270c43f1ddd37d1eb19da5db78129b93f72b7 (patch) | |
| tree | 67ab3eab1e71ef1b5479f3f5a00e040b622d7191 /vendor/golang.org/x/crypto/poly1305/poly1305.go | |
| parent | c69e9f604c47469429a6a8a27ba7ef873134e0a1 (diff) | |
| download | gofu-ec4270c43f1ddd37d1eb19da5db78129b93f72b7.tar.gz | |
add "cli" package with a Query method
Diffstat (limited to 'vendor/golang.org/x/crypto/poly1305/poly1305.go')
| -rw-r--r-- | vendor/golang.org/x/crypto/poly1305/poly1305.go | 32 |
1 files changed, 32 insertions, 0 deletions
diff --git a/vendor/golang.org/x/crypto/poly1305/poly1305.go b/vendor/golang.org/x/crypto/poly1305/poly1305.go new file mode 100644 index 0000000..4a5f826 --- /dev/null +++ b/vendor/golang.org/x/crypto/poly1305/poly1305.go @@ -0,0 +1,32 @@ +// Copyright 2012 The Go Authors. All rights reserved. +// Use of this source code is governed by a BSD-style +// license that can be found in the LICENSE file. + +/* +Package poly1305 implements Poly1305 one-time message authentication code as specified in http://cr.yp.to/mac/poly1305-20050329.pdf. + +Poly1305 is a fast, one-time authentication function. It is infeasible for an +attacker to generate an authenticator for a message without the key. However, a +key must only be used for a single message. Authenticating two different +messages with the same key allows an attacker to forge authenticators for other +messages with the same key. + +Poly1305 was originally coupled with AES in order to make Poly1305-AES. AES was +used with a fixed key in order to generate one-time keys from an nonce. +However, in this package AES isn't used and the one-time key is specified +directly. +*/ +package poly1305 // import "golang.org/x/crypto/poly1305" + +import "crypto/subtle" + +// TagSize is the size, in bytes, of a poly1305 authenticator. +const TagSize = 16 + +// Verify returns true if mac is a valid authenticator for m with the given +// key. +func Verify(mac *[16]byte, m []byte, key *[32]byte) bool { + var tmp [16]byte + Sum(&tmp, m, key) + return subtle.ConstantTimeCompare(tmp[:], mac[:]) == 1 +} |
