symm/sha512.[ch], etc.: Support SHA512/224 and SHA512/256.
[catacomb] / symm / sha512.c
1 /* -*-c-*-
2 *
3 * Implementation of the SHA-512 hash function
4 *
5 * (c) 2000 Straylight/Edgeware
6 */
7
8 /*----- Licensing notice --------------------------------------------------*
9 *
10 * This file is part of Catacomb.
11 *
12 * Catacomb is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU Library General Public License as
14 * published by the Free Software Foundation; either version 2 of the
15 * License, or (at your option) any later version.
16 *
17 * Catacomb is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20 * GNU Library General Public License for more details.
21 *
22 * You should have received a copy of the GNU Library General Public
23 * License along with Catacomb; if not, write to the Free
24 * Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
25 * MA 02111-1307, USA.
26 */
27
28 /*----- Header files ------------------------------------------------------*/
29
30 #include <mLib/bits.h>
31
32 #include "ghash.h"
33 #include "ghash-def.h"
34 #include "hash.h"
35 #include "sha512.h"
36
37 /*----- Main code ---------------------------------------------------------*/
38
39 /* --- @sha512_compress@, etc. --- *
40 *
41 * Arguments: @sha512_ctx *ctx@ = pointer to context block
42 * @const void *sbuf@ = pointer to buffer of appropriate size
43 *
44 * Returns: ---
45 *
46 * Use: SHA-512 compression function.
47 */
48
49 void sha512_compress(sha512_ctx *ctx, const void *sbuf)
50 {
51 kludge64 a, b, c, d, e, f, g, h;
52 kludge64 buf[80];
53 int i;
54
55 static const kludge64 K[80] = {
56 X64(428a2f98, d728ae22), X64(71374491, 23ef65cd),
57 X64(b5c0fbcf, ec4d3b2f), X64(e9b5dba5, 8189dbbc),
58 X64(3956c25b, f348b538), X64(59f111f1, b605d019),
59 X64(923f82a4, af194f9b), X64(ab1c5ed5, da6d8118),
60 X64(d807aa98, a3030242), X64(12835b01, 45706fbe),
61 X64(243185be, 4ee4b28c), X64(550c7dc3, d5ffb4e2),
62 X64(72be5d74, f27b896f), X64(80deb1fe, 3b1696b1),
63 X64(9bdc06a7, 25c71235), X64(c19bf174, cf692694),
64 X64(e49b69c1, 9ef14ad2), X64(efbe4786, 384f25e3),
65 X64(0fc19dc6, 8b8cd5b5), X64(240ca1cc, 77ac9c65),
66 X64(2de92c6f, 592b0275), X64(4a7484aa, 6ea6e483),
67 X64(5cb0a9dc, bd41fbd4), X64(76f988da, 831153b5),
68 X64(983e5152, ee66dfab), X64(a831c66d, 2db43210),
69 X64(b00327c8, 98fb213f), X64(bf597fc7, beef0ee4),
70 X64(c6e00bf3, 3da88fc2), X64(d5a79147, 930aa725),
71 X64(06ca6351, e003826f), X64(14292967, 0a0e6e70),
72 X64(27b70a85, 46d22ffc), X64(2e1b2138, 5c26c926),
73 X64(4d2c6dfc, 5ac42aed), X64(53380d13, 9d95b3df),
74 X64(650a7354, 8baf63de), X64(766a0abb, 3c77b2a8),
75 X64(81c2c92e, 47edaee6), X64(92722c85, 1482353b),
76 X64(a2bfe8a1, 4cf10364), X64(a81a664b, bc423001),
77 X64(c24b8b70, d0f89791), X64(c76c51a3, 0654be30),
78 X64(d192e819, d6ef5218), X64(d6990624, 5565a910),
79 X64(f40e3585, 5771202a), X64(106aa070, 32bbd1b8),
80 X64(19a4c116, b8d2d0c8), X64(1e376c08, 5141ab53),
81 X64(2748774c, df8eeb99), X64(34b0bcb5, e19b48a8),
82 X64(391c0cb3, c5c95a63), X64(4ed8aa4a, e3418acb),
83 X64(5b9cca4f, 7763e373), X64(682e6ff3, d6b2b8a3),
84 X64(748f82ee, 5defb2fc), X64(78a5636f, 43172f60),
85 X64(84c87814, a1f0ab72), X64(8cc70208, 1a6439ec),
86 X64(90befffa, 23631e28), X64(a4506ceb, de82bde9),
87 X64(bef9a3f7, b2c67915), X64(c67178f2, e372532b),
88 X64(ca273ece, ea26619c), X64(d186b8c7, 21c0c207),
89 X64(eada7dd6, cde0eb1e), X64(f57d4f7f, ee6ed178),
90 X64(06f067aa, 72176fba), X64(0a637dc5, a2c898a6),
91 X64(113f9804, bef90dae), X64(1b710b35, 131c471b),
92 X64(28db77f5, 23047d84), X64(32caab7b, 40c72493),
93 X64(3c9ebe0a, 15c9bebc), X64(431d67c4, 9c100d4c),
94 X64(4cc5d4be, cb3e42b6), X64(597f299c, fc657e2a),
95 X64(5fcb6fab, 3ad6faec), X64(6c44198c, 4a475817)
96 };
97
98 /* --- Fetch the chaining variables --- */
99
100 a = ctx->a;
101 b = ctx->b;
102 c = ctx->c;
103 d = ctx->d;
104 e = ctx->e;
105 f = ctx->f;
106 g = ctx->g;
107 h = ctx->h;
108
109 /* --- Definitions for round functions --- */
110
111 #define CH(d, x, y, z) do { \
112 kludge64 _x; AND64((d), (x), (y)); CPL64(_x, (x)); \
113 AND64(_x, _x, (z)); OR64((d), (d), _x); \
114 } while (0)
115
116 #define MAJ(d, x, y, z) do { \
117 kludge64 _x; AND64((d), (x), (y)); AND64(_x, (x), (z)); \
118 OR64((d), (d), _x); AND64(_x, (y), (z)); OR64((d), (d), _x); \
119 } while (0)
120
121 #define SIGMA(d, x, i, j, k, last, what) do { \
122 kludge64 _x; ROR64_((d), (x), (i)); ROR64_(_x, (x), (j)); \
123 XOR64((d), (d), _x); last##64_(_x, (x), (k)); XOR64((d), (d), _x); \
124 } while (0)
125
126 #define S0(d, x) SIGMA(d, x, 28, 34, 39, ROR, S0);
127 #define S1(d, x) SIGMA(d, x, 14, 18, 41, ROR, S1);
128 #define s0(d, x) SIGMA(d, x, 1, 8, 7, LSR, s0);
129 #define s1(d, x) SIGMA(d, x, 19, 61, 6, LSR, s1);
130
131 #define T(a, b, c, d, e, f, g, h, i) do { \
132 kludge64 t1, t2, x; \
133 ADD64(t1, buf[i], K[i]); ADD64(t1, t1, h); \
134 S1(x, e); ADD64(t1, t1, x); CH(x, e, f, g); ADD64(t1, t1, x); \
135 S0(t2, a); MAJ(x, a, b, c); ADD64(t2, t2, x); \
136 ADD64(d, d, t1); ADD64(h, t1, t2); \
137 } while (0)
138
139 /* --- Fetch and expand the buffer contents --- */
140
141 {
142 const octet *p;
143
144 for (i = 0, p = sbuf; i < 16; i++, p += 8)
145 LOAD64_(buf[i], p);
146 for (i = 16; i < 80; i++) {
147 kludge64 x;
148 buf[i] = buf[i - 7]; s1(x, buf[i - 2]); ADD64(buf[i], buf[i], x);
149 s0(x, buf[i - 15]); ADD64(buf[i], buf[i], x);
150 ADD64(buf[i], buf[i], buf[i - 16]);
151 }
152 }
153
154 /* --- The main compression function --- */
155
156 for (i = 0; i < 80; i += 8) {
157 T(a, b, c, d, e, f, g, h, i + 0);
158 T(h, a, b, c, d, e, f, g, i + 1);
159 T(g, h, a, b, c, d, e, f, i + 2);
160 T(f, g, h, a, b, c, d, e, i + 3);
161 T(e, f, g, h, a, b, c, d, i + 4);
162 T(d, e, f, g, h, a, b, c, i + 5);
163 T(c, d, e, f, g, h, a, b, i + 6);
164 T(b, c, d, e, f, g, h, a, i + 7);
165 }
166
167 /* --- Update the chaining variables --- */
168
169 ADD64(ctx->a, ctx->a, a);
170 ADD64(ctx->b, ctx->b, b);
171 ADD64(ctx->c, ctx->c, c);
172 ADD64(ctx->d, ctx->d, d);
173 ADD64(ctx->e, ctx->e, e);
174 ADD64(ctx->f, ctx->f, f);
175 ADD64(ctx->g, ctx->g, g);
176 ADD64(ctx->h, ctx->h, h);
177 }
178
179 /* --- @sha512_init@, etc. --- *
180 *
181 * Arguments: @sha512_ctx *ctx@ = pointer to context block to initialize
182 *
183 * Returns: ---
184 *
185 * Use: Initializes a context block ready for hashing.
186 */
187
188 void sha512_init(sha512_ctx *ctx)
189 {
190 SET64(ctx->a, 0x6a09e667, 0xf3bcc908);
191 SET64(ctx->b, 0xbb67ae85, 0x84caa73b);
192 SET64(ctx->c, 0x3c6ef372, 0xfe94f82b);
193 SET64(ctx->d, 0xa54ff53a, 0x5f1d36f1);
194 SET64(ctx->e, 0x510e527f, 0xade682d1);
195 SET64(ctx->f, 0x9b05688c, 0x2b3e6c1f);
196 SET64(ctx->g, 0x1f83d9ab, 0xfb41bd6b);
197 SET64(ctx->h, 0x5be0cd19, 0x137e2179);
198 ctx->off = 0;
199 ctx->nh = ctx->nl = 0;
200 }
201
202 void sha384_init(sha512_ctx *ctx)
203 {
204 SET64(ctx->a, 0xcbbb9d5d, 0xc1059ed8);
205 SET64(ctx->b, 0x629a292a, 0x367cd507);
206 SET64(ctx->c, 0x9159015a, 0x3070dd17);
207 SET64(ctx->d, 0x152fecd8, 0xf70e5939);
208 SET64(ctx->e, 0x67332667, 0xffc00b31);
209 SET64(ctx->f, 0x8eb44a87, 0x68581511);
210 SET64(ctx->g, 0xdb0c2e0d, 0x64f98fa7);
211 SET64(ctx->h, 0x47b5481d, 0xbefa4fa4);
212 ctx->off = 0;
213 ctx->nh = ctx->nl = 0;
214 }
215
216 void sha512_256_init(sha512_ctx *ctx)
217 {
218 SET64(ctx->a, 0x22312194, 0xfc2bf72c);
219 SET64(ctx->b, 0x9f555fa3, 0xc84c64c2);
220 SET64(ctx->c, 0x2393b86b, 0x6f53b151);
221 SET64(ctx->d, 0x96387719, 0x5940eabd);
222 SET64(ctx->e, 0x96283ee2, 0xa88effe3);
223 SET64(ctx->f, 0xbe5e1e25, 0x53863992);
224 SET64(ctx->g, 0x2b0199fc, 0x2c85b8aa);
225 SET64(ctx->h, 0x0eb72ddc, 0x81c52ca2);
226 ctx->off = 0;
227 ctx->nh = ctx->nl = 0;
228 }
229
230 void sha512_224_init(sha512_ctx *ctx)
231 {
232 SET64(ctx->a, 0x8c3d37c8, 0x19544da2);
233 SET64(ctx->b, 0x73e19966, 0x89dcd4d6);
234 SET64(ctx->c, 0x1dfab7ae, 0x32ff9c82);
235 SET64(ctx->d, 0x679dd514, 0x582f9fcf);
236 SET64(ctx->e, 0x0f6d2b69, 0x7bd44da8);
237 SET64(ctx->f, 0x77e36f73, 0x04c48942);
238 SET64(ctx->g, 0x3f9d85a8, 0x6a1d36c8);
239 SET64(ctx->h, 0x1112e6ad, 0x91d692a1);
240 ctx->off = 0;
241 ctx->nh = ctx->nl = 0;
242 }
243
244 /* --- @sha512_set@, etc. --- *
245 *
246 * Arguments: @sha512_ctx *ctx@ = pointer to context block
247 * @const void *buf@ = pointer to state buffer
248 * @unsigned long count@ = current count of bytes processed
249 *
250 * Returns: ---
251 *
252 * Use: Initializes a context block from a given state. This is
253 * useful in cases where the initial hash state is meant to be
254 * secret, e.g., for NMAC and HMAC support.
255 */
256
257 void sha512_set(sha512_ctx *ctx, const void *buf, unsigned long count)
258 {
259 const octet *p = buf;
260 LOAD64_(ctx->a, p + 0);
261 LOAD64_(ctx->b, p + 8);
262 LOAD64_(ctx->c, p + 16);
263 LOAD64_(ctx->d, p + 24);
264 LOAD64_(ctx->e, p + 32);
265 LOAD64_(ctx->f, p + 40);
266 LOAD64_(ctx->g, p + 48);
267 LOAD64_(ctx->h, p + 56);
268 ctx->off = 0;
269 ctx->nl = U32(count);
270 ctx->nh = U32(((count & ~MASK32) >> 16) >> 16);
271 }
272
273 /* --- @sha512_hash@, @sha384_hash@ --- *
274 *
275 * Arguments: @sha512_ctx *ctx@ = pointer to context block
276 * @const void *buf@ = buffer of data to hash
277 * @size_t sz@ = size of buffer to hash
278 *
279 * Returns: ---
280 *
281 * Use: Hashes a buffer of data. The buffer may be of any size and
282 * alignment.
283 */
284
285 void sha512_hash(sha512_ctx *ctx, const void *buf, size_t sz)
286 {
287 HASH_BUFFER(SHA512, sha512, ctx, buf, sz);
288 }
289
290 /* --- @sha512_done@, etc. --- *
291 *
292 * Arguments: @sha512_ctx *ctx@ = pointer to context block
293 * @void *hash@ = pointer to output buffer
294 *
295 * Returns: ---
296 *
297 * Use: Returns the hash of the data read so far.
298 */
299
300 static void final(sha512_ctx *ctx)
301 {
302 HASH_PAD(SHA512, sha512, ctx, 0x80, 0, 16);
303 memset(ctx->buf + SHA512_BUFSZ - 16, 0, 8);
304 STORE32(ctx->buf + SHA512_BUFSZ - 8, (ctx->nl >> 29) | (ctx->nh << 3));
305 STORE32(ctx->buf + SHA512_BUFSZ - 4, ctx->nl << 3);
306 sha512_compress(ctx, ctx->buf);
307 }
308
309 void sha512_done(sha512_ctx *ctx, void *hash)
310 {
311 octet *p = hash;
312 final(ctx);
313 STORE64_(p + 0, ctx->a);
314 STORE64_(p + 8, ctx->b);
315 STORE64_(p + 16, ctx->c);
316 STORE64_(p + 24, ctx->d);
317 STORE64_(p + 32, ctx->e);
318 STORE64_(p + 40, ctx->f);
319 STORE64_(p + 48, ctx->g);
320 STORE64_(p + 56, ctx->h);
321 }
322
323 void sha384_done(sha512_ctx *ctx, void *hash)
324 {
325 octet *p = hash;
326 final(ctx);
327 STORE64_(p + 0, ctx->a);
328 STORE64_(p + 8, ctx->b);
329 STORE64_(p + 16, ctx->c);
330 STORE64_(p + 24, ctx->d);
331 STORE64_(p + 32, ctx->e);
332 STORE64_(p + 40, ctx->f);
333 }
334
335 void sha512_256_done(sha384_ctx *ctx, void *hash)
336 {
337 octet *p = hash;
338 final(ctx);
339 STORE64_(p + 0, ctx->a);
340 STORE64_(p + 8, ctx->b);
341 STORE64_(p + 16, ctx->c);
342 STORE64_(p + 24, ctx->d);
343 }
344
345 void sha512_224_done(sha384_ctx *ctx, void *hash)
346 {
347 octet *p = hash;
348 final(ctx);
349 STORE64_(p + 0, ctx->a);
350 STORE64_(p + 8, ctx->b);
351 STORE64_(p + 16, ctx->c);
352 STORE32 (p + 24, HI64(ctx->d));
353 }
354
355 /* --- @sha512_state@, etc. --- *
356 *
357 * Arguments: @sha512_ctx *ctx@ = pointer to context
358 * @void *state@ = pointer to buffer for current state
359 *
360 * Returns: Number of bytes written to the hash function so far.
361 *
362 * Use: Returns the current state of the hash function such that
363 * it can be passed to @sha512_set@.
364 */
365
366 unsigned long sha512_state(sha512_ctx *ctx, void *state)
367 {
368 octet *p = state;
369 STORE64_(p + 0, ctx->a);
370 STORE64_(p + 8, ctx->b);
371 STORE64_(p + 16, ctx->c);
372 STORE64_(p + 24, ctx->d);
373 STORE64_(p + 32, ctx->e);
374 STORE64_(p + 40, ctx->f);
375 STORE64_(p + 48, ctx->g);
376 STORE64_(p + 56, ctx->h);
377 return (ctx->nl | ((ctx->nh << 16) << 16));
378 }
379
380 /* --- Generic interface --- */
381
382 #define HASHES(_) \
383 _(SHA512_224, sha512_224, "sha512/224") \
384 _(SHA512_256, sha512_256, "sha512/256") \
385 _(SHA384, sha384, "sha384") \
386 _(SHA512, sha512, "sha512")
387
388 HASHES(GHASH_DEFX)
389
390 /*----- Test rig ----------------------------------------------------------*/
391
392 #ifdef TEST_RIG
393
394 #include <mLib/testrig.h>
395
396 HASHES(HASH_VERIFYX)
397
398 static const test_chunk defs[] = {
399 HASHES(HASH_TESTDEFSX)
400 { 0, 0, { 0 } }
401 };
402
403 int main(int argc, char *argv[])
404 {
405 test_run(argc, argv, defs, SRCDIR "/t/sha512");
406 return (0);
407 }
408
409 #endif
410
411 /*----- That's all, folks -------------------------------------------------*/