Poly1305 message authentication code


Poly1305 is a message authentication code (MAC) designed by Daniel J. Bernstein and specified in RFC 8439. It provides strong authentication guarantees when used with a unique, unpredictable 32-byte key per message.

Poly1305 is typically paired with ChaCha20, as in the ChaCha20-Poly1305 AEAD construction defined in RFC 8439. The pairing is used in TLS 1.3, WireGuard, and SSH.

This implementation follows RFC 8439. It evaluates the message as a polynomial modulo the prime 2^130-5 over 16-byte blocks and produces a 128-bit (16-byte) authentication tag.

Security notes
• The 32-byte key MUST be unique and unpredictable for each message. Two messages authenticated with the same key are enough for an attacker to recover the key and forge tags.
• Poly1305 authenticates but does not encrypt. For authenticated encryption, use an AEAD construction like ChaCha20-Poly1305.
• Tag verification compares tags in constant time. The tag computation uses bignum arithmetic, which is not constant-time, so it can leak timing information about the key (see RFC 8439 Sections 3 and 4).


Computing MACs
poly1305-mac ( message key -- tag )


Verifying MACs
poly1305-verify ( message key expected-tag -- ? )


Further reading
https://cr.yp.to/mac.html

https://www.rfc-editor.org/rfc/rfc8439.html