3 * Definitions for HMAC and NMAC
5 * (c) 1999 Straylight/Edgeware
8 /*----- Licensing notice --------------------------------------------------*
10 * This file is part of Catacomb.
12 * Catacomb is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU Library General Public License as
14 * published by the Free Software Foundation; either version 2 of the
15 * License, or (at your option) any later version.
17 * Catacomb is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20 * GNU Library General Public License for more details.
22 * You should have received a copy of the GNU Library General Public
23 * License along with Catacomb; if not, write to the Free
24 * Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
28 #ifndef CATACOMB_HMAC_DEF_H
29 #define CATACOMB_HMAC_DEF_H
35 /*----- Header files ------------------------------------------------------*/
41 #include <mLib/bits.h>
44 #ifndef CATACOMB_ARENA_H
48 #ifndef CATACOMB_GMAC_H
52 #ifndef CATACOMB_PARANOIA_H
53 # include "paranoia.h"
56 /*----- Macros ------------------------------------------------------------*/
58 /* --- @HMAC_DEF@ --- *
60 * Arguments: @PRE@, @pre@ = prefixes for the underlying hash function
62 * Use: Creates implementations for the HMAC and NMAC functions.
65 #define HMAC_DEF(PRE, pre) HMAC_DEFX(PRE, pre, #pre, #pre)
66 #define HMAC_DEFX(PRE, pre, name, fname) \
68 /* --- Useful constants --- */ \
70 const octet pre##_hmackeysz[] = \
71 { KSZ_ANY | KSZ_16BIT, PRE##_STATESZ/256, PRE##_STATESZ%256 }; \
72 const octet pre##_sslmackeysz[] = \
73 { KSZ_ANY | KSZ_16BIT, PRE##_STATESZ/256, PRE##_STATESZ%256 }; \
74 const octet pre##_nmackeysz[] = \
75 { KSZ_SET | KSZ_16BIT, \
76 2*PRE##_STATESZ/256, 2*PRE##_STATESZ%256, 0, 0 }; \
78 /* --- @pre_nmacinit@ --- * \
80 * Arguments: @pre_macctx *key@ = pointer to a MAC key object \
81 * @const void *ok@ = pointer to outer hash init vector \
82 * @const void *ik@ = pointer to inner hash init vector \
86 * Use: Initializes a MAC key for doing NMAC hashing. \
89 void pre##_nmacinit(pre##_mackey *key, const void *ok, const void *ik) \
91 memcpy(key->ochain, ok, PRE##_STATESZ); \
92 memcpy(key->ichain, ik, PRE##_STATESZ); \
93 key->ocount = key->icount = 0; \
96 /* --- @pre_hmacinit@ --- * \
98 * Arguments: @pre_mackey *key@ = pointer to MAC key object \
99 * @const void *k@ = pointer to key to use \
100 * @size_t sz@ = size of key data \
104 * Use: Initializes a MAC key for doing HMAC hashing. Keys \
105 * longer than the hash function's output size aren't very \
106 * useful, but are accepted. Keys longer than the hash's \
107 * block size are also accepted; they are hashed before \
108 * use, as specified in RFC2104. \
111 void pre##_hmacinit(pre##_mackey *key, const void *k, size_t sz) \
114 const octet *kbuf = k; \
116 octet hbuf[PRE##_HASHSZ], buf[PRE##_BUFSZ]; \
118 if (sz > PRE##_BUFSZ) { \
120 pre##_hash(&ctx, k, sz); \
121 pre##_done(&ctx, hbuf); \
127 memset(buf, 0x5c, PRE##_BUFSZ); \
128 for (i = 0; i < sz; i++) buf[i] ^= kbuf[i]; \
129 pre##_hash(&ctx, buf, PRE##_BUFSZ); \
130 key->ocount = pre##_state(&ctx, key->ochain); \
133 memset(buf, 0x36, PRE##_BUFSZ); \
134 for (i = 0; i < sz; i++) buf[i] ^= kbuf[i]; \
135 pre##_hash(&ctx, buf, PRE##_BUFSZ); \
136 key->icount = pre##_state(&ctx, key->ichain); \
141 /* --- @pre_sslmacinit@ --- * \
143 * Arguments: @pre_mackey *key@ = pointer to MAC key object \
144 * @const void *k@ = pointer to key to use \
145 * @size_t sz@ = size of key data \
149 * Use: Initializes a MAC key for doing hasing using the SSL3 \
153 void pre##_sslmacinit(pre##_mackey *key, const void *k, size_t sz) \
155 const octet *kbuf = k; \
157 octet hbuf[PRE##_HASHSZ], buf[PRE##_BUFSZ]; \
159 if (sz > PRE##_BUFSZ) { \
161 pre##_hash(&ctx, k, sz); \
162 pre##_done(&ctx, hbuf); \
168 memcpy(buf, kbuf, sz); \
169 memset(buf + sz, 0x5c, PRE##_BUFSZ - sz); \
170 pre##_hash(&ctx, buf, PRE##_BUFSZ); \
171 key->ocount = pre##_state(&ctx, key->ochain); \
174 memcpy(buf, kbuf, sz); \
175 memset(buf + sz, 0x36, PRE##_BUFSZ - sz); \
176 pre##_hash(&ctx, buf, PRE##_BUFSZ); \
177 key->icount = pre##_state(&ctx, key->ichain); \
182 /* --- @pre_macinit@ --- * \
184 * Arguments: @pre_macctx *ctx@ = pointer to MAC context block \
185 * @const pre_mackey *key@ = pointer to MAC key block \
189 * Use: Instantiates a MAC context from a key block. \
192 void pre##_macinit(pre##_macctx *ctx, const pre##_mackey *key) \
194 memcpy(ctx->chain, key->ochain, PRE##_STATESZ); \
195 ctx->count = key->ocount; \
196 pre##_set(&ctx->ctx, key->ichain, key->icount); \
199 /* --- @pre_machash@ --- * \
201 * Arguments: @pre_macctx *ctx@ = pointer to MAC context block \
202 * @const void *buf@ = pointer to buffer \
203 * @size_t sz@ = size of the buffer \
207 * Use: Hashes a buffer. \
210 void pre##_machash(pre##_macctx *ctx, const void *buf, size_t sz) \
212 pre##_hash(&ctx->ctx, buf, sz); \
215 /* --- @pre_macdone@ --- * \
217 * Arguments: @pre_macctx *ctx@ = pointer to MAC context block \
218 * @void *mac@ = pointer to buffer to receive MAC \
222 * Use: Returns the result of a MAC computation. \
225 void pre##_macdone(pre##_macctx *ctx, void *mac) \
227 pre##_done(&ctx->ctx, mac); \
228 pre##_set(&ctx->ctx, ctx->chain, ctx->count); \
229 pre##_hash(&ctx->ctx, mac, PRE##_HASHSZ); \
230 pre##_done(&ctx->ctx, mac); \
233 /* --- Generic MAC interface --- */ \
235 static const gmac_ops gkops, gnkops, gsslkops; \
236 static const ghash_ops gops, gnops, gsslops; \
238 typedef struct gkctx { \
240 const ghash_ops *gops; \
244 typedef struct gctx { \
247 octet buf[PRE##_HASHSZ]; \
250 static ghash *gkinit(gmac *m) \
252 gkctx *gk = (gkctx *)m; \
253 gctx *g = S_CREATE(gctx); \
254 g->h.ops = gk->gops; \
255 pre##_macinit(&g->c, &gk->k); \
259 static gmac *gkey(const void *k, size_t sz) \
261 gkctx *gk = S_CREATE(gkctx); \
262 gk->m.ops = &gkops; \
264 pre##_hmacinit(&gk->k, k, sz); \
268 static gmac *gnkey(const void *k, size_t sz) \
270 gkctx *gk = S_CREATE(gkctx); \
271 const octet *kk = k; \
272 assert(keysz(sz, pre##_nmackeysz) == sz); \
273 gk->m.ops = &gnkops; \
275 pre##_nmacinit(&gk->k, kk, kk + PRE##_STATESZ); \
279 static gmac *gsslkey(const void *k, size_t sz) \
281 gkctx *gk = S_CREATE(gkctx); \
282 gk->m.ops = &gsslkops; \
283 gk->gops = &gsslops; \
284 pre##_sslmacinit(&gk->k, k, sz); \
288 static void ghhash(ghash *h, const void *p, size_t sz) \
290 gctx *g = (gctx *)h; \
291 pre##_machash(&g->c, p, sz); \
294 static octet *ghdone(ghash *h, void *buf) \
296 gctx *g = (gctx *)h; \
299 pre##_macdone(&g->c, buf); \
303 static ghash *ghcopy(ghash *h) \
305 gctx *g = (gctx *)h; \
306 gctx *gg = S_CREATE(gctx); \
307 memcpy(gg, g, sizeof(gctx)); \
311 static void ghdestroy(ghash *h) \
313 gctx *g = (gctx *)h; \
318 static void gkdestroy(gmac *m) \
320 gkctx *gk = (gkctx *)m; \
325 static ghash *ghinit(void) \
327 assert(((void)"Attempt to instantiate an unkeyed MAC", 0)); \
331 const gcmac pre##_nmac = \
332 { name "-nmac", PRE##_HASHSZ, pre##_nmackeysz, gnkey }; \
333 const gcmac pre##_hmac = \
334 { name "-hmac", PRE##_HASHSZ, pre##_hmackeysz, gkey }; \
335 const gcmac pre##_sslmac = \
336 { name "-sslmac", PRE##_HASHSZ, pre##_sslmackeysz, gsslkey }; \
337 static const gmac_ops gkops = { &pre##_hmac, gkinit, gkdestroy }; \
338 static const gmac_ops gnkops = { &pre##_nmac, gkinit, gkdestroy }; \
339 static const gmac_ops gsslkops = { &pre##_sslmac, gkinit, gkdestroy }; \
340 static const gchash gch = { name "-hmac", PRE##_HASHSZ, ghinit }; \
341 static const ghash_ops gops = \
342 { &gch, ghhash, ghdone, ghdestroy, ghcopy }; \
343 static const gchash gnch = { name "-nmac", PRE##_HASHSZ, ghinit }; \
344 static const ghash_ops gnops = \
345 { &gnch, ghhash, ghdone, ghdestroy, ghcopy }; \
346 static const gchash gsslch = { name "-sslmac", PRE##_HASHSZ, ghinit }; \
347 static const ghash_ops gsslops = \
348 { &gsslch, ghhash, ghdone, ghdestroy, ghcopy }; \
350 HMAC_TESTX(PRE, pre, name, fname)
352 #define HMAC_TEST(PRE, pre) HMAC_TESTX(PRE, pre, #pre, #pre)
354 /* --- @HMAC_TEST@ --- *
356 * Arguments: @PRE@, @pre@ = prefixes for hash-specfic definitions
358 * Use: Standard test rig for MAC functions.
365 #include <mLib/dstr.h>
366 #include <mLib/quis.h>
367 #include <mLib/testrig.h>
369 #define HMAC_TESTX(PRE, pre, name, fname) \
371 static int macverify(dstr *v) \
378 int szs[] = { 1, 7, 192, -1, 0 }, *ip; \
383 dstr_ensure(&d, PRE##_HASHSZ); \
384 d.len = PRE##_HASHSZ; \
386 pre##_hmacinit(&ckey, v[1].buf, v[1].len); \
388 for (ip = szs; *ip; ip++) { \
395 p = (octet *)v[0].buf; \
396 pre##_macinit(&cctx, &ckey); \
400 pre##_machash(&cctx, p, i); \
404 pre##_macdone(&cctx, d.buf); \
405 if (memcmp(d.buf, v[2].buf, PRE##_HASHSZ) != 0) { \
406 printf("\nfail:\n\tstep = %i\n\tinput = `%s'\n\tkey = ", \
408 type_hex.dump(&v[1], stdout); \
409 fputs("\n\texpected = ", stdout); \
410 type_hex.dump(&v[2], stdout); \
411 fputs("\n\tcomputed = ", stdout); \
412 type_hex.dump(&d, stdout); \
422 static test_chunk macdefs[] = { \
423 { name "-hmac", macverify, \
424 { &type_string, &type_hex, &type_hex, 0 } }, \
428 int main(int argc, char *argv[]) \
431 test_run(argc, argv, macdefs, SRCDIR"/t/" fname); \
436 # define HMAC_TESTX(PRE, pre, name, fname)
439 /*----- That's all, folks -------------------------------------------------*/