Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
freebsd
GitHub Repository: freebsd/freebsd-src
Path: blob/main/sys/crypto/skein/skein.h
39478 views
1
#ifndef _SKEIN_H_
2
#define _SKEIN_H_ 1
3
/**************************************************************************
4
**
5
** Interface declarations and internal definitions for Skein hashing.
6
**
7
** Source code author: Doug Whiting, 2008.
8
**
9
** This algorithm and source code is released to the public domain.
10
**
11
***************************************************************************
12
**
13
** The following compile-time switches may be defined to control some
14
** tradeoffs between speed, code size, error checking, and security.
15
**
16
** The "default" note explains what happens when the switch is not defined.
17
**
18
** SKEIN_DEBUG -- make callouts from inside Skein code
19
** to examine/display intermediate values.
20
** [default: no callouts (no overhead)]
21
**
22
** SKEIN_ERR_CHECK -- how error checking is handled inside Skein
23
** code. If not defined, most error checking
24
** is disabled (for performance). Otherwise,
25
** the switch value is interpreted as:
26
** 0: use assert() to flag errors
27
** 1: return SKEIN_FAIL to flag errors
28
**
29
***************************************************************************/
30
#ifdef __cplusplus
31
extern "C"
32
{
33
#endif
34
35
#ifndef _KERNEL
36
#include <stddef.h> /* get size_t definition */
37
#endif
38
#include "skein_port.h" /* get platform-specific definitions */
39
40
enum
41
{
42
SKEIN_SUCCESS = 0, /* return codes from Skein calls */
43
SKEIN_FAIL = 1,
44
SKEIN_BAD_HASHLEN = 2
45
};
46
47
#define SKEIN_MODIFIER_WORDS ( 2) /* number of modifier (tweak) words */
48
49
#define SKEIN_256_STATE_WORDS ( 4)
50
#define SKEIN_512_STATE_WORDS ( 8)
51
#define SKEIN1024_STATE_WORDS (16)
52
#define SKEIN_MAX_STATE_WORDS (16)
53
54
#define SKEIN_256_STATE_BYTES ( 8*SKEIN_256_STATE_WORDS)
55
#define SKEIN_512_STATE_BYTES ( 8*SKEIN_512_STATE_WORDS)
56
#define SKEIN1024_STATE_BYTES ( 8*SKEIN1024_STATE_WORDS)
57
58
#define SKEIN_256_STATE_BITS (64*SKEIN_256_STATE_WORDS)
59
#define SKEIN_512_STATE_BITS (64*SKEIN_512_STATE_WORDS)
60
#define SKEIN1024_STATE_BITS (64*SKEIN1024_STATE_WORDS)
61
62
#define SKEIN_256_BLOCK_BYTES ( 8*SKEIN_256_STATE_WORDS)
63
#define SKEIN_512_BLOCK_BYTES ( 8*SKEIN_512_STATE_WORDS)
64
#define SKEIN1024_BLOCK_BYTES ( 8*SKEIN1024_STATE_WORDS)
65
66
typedef struct
67
{
68
size_t hashBitLen; /* size of hash result, in bits */
69
size_t bCnt; /* current byte count in buffer b[] */
70
u64b_t T[SKEIN_MODIFIER_WORDS]; /* tweak words: T[0]=byte cnt, T[1]=flags */
71
} Skein_Ctxt_Hdr_t;
72
73
typedef struct /* 256-bit Skein hash context structure */
74
{
75
Skein_Ctxt_Hdr_t h; /* common header context variables */
76
u64b_t X[SKEIN_256_STATE_WORDS]; /* chaining variables */
77
u08b_t b[SKEIN_256_BLOCK_BYTES]; /* partial block buffer (8-byte aligned) */
78
} Skein_256_Ctxt_t;
79
80
typedef struct /* 512-bit Skein hash context structure */
81
{
82
Skein_Ctxt_Hdr_t h; /* common header context variables */
83
u64b_t X[SKEIN_512_STATE_WORDS]; /* chaining variables */
84
u08b_t b[SKEIN_512_BLOCK_BYTES]; /* partial block buffer (8-byte aligned) */
85
} Skein_512_Ctxt_t;
86
87
typedef struct /* 1024-bit Skein hash context structure */
88
{
89
Skein_Ctxt_Hdr_t h; /* common header context variables */
90
u64b_t X[SKEIN1024_STATE_WORDS]; /* chaining variables */
91
u08b_t b[SKEIN1024_BLOCK_BYTES]; /* partial block buffer (8-byte aligned) */
92
} Skein1024_Ctxt_t;
93
94
/* Skein APIs for (incremental) "straight hashing" */
95
int Skein_256_Init (Skein_256_Ctxt_t *ctx, size_t hashBitLen);
96
int Skein_512_Init (Skein_512_Ctxt_t *ctx, size_t hashBitLen);
97
int Skein1024_Init (Skein1024_Ctxt_t *ctx, size_t hashBitLen);
98
99
int Skein_256_Update(Skein_256_Ctxt_t *ctx, const u08b_t *msg, size_t msgByteCnt);
100
int Skein_512_Update(Skein_512_Ctxt_t *ctx, const u08b_t *msg, size_t msgByteCnt);
101
int Skein1024_Update(Skein1024_Ctxt_t *ctx, const u08b_t *msg, size_t msgByteCnt);
102
103
int Skein_256_Final (Skein_256_Ctxt_t *ctx, u08b_t * hashVal);
104
int Skein_512_Final (Skein_512_Ctxt_t *ctx, u08b_t * hashVal);
105
int Skein1024_Final (Skein1024_Ctxt_t *ctx, u08b_t * hashVal);
106
107
/*
108
** Skein APIs for "extended" initialization: MAC keys, tree hashing.
109
** After an InitExt() call, just use Update/Final calls as with Init().
110
**
111
** Notes: Same parameters as _Init() calls, plus treeInfo/key/keyBytes.
112
** When keyBytes == 0 and treeInfo == SKEIN_SEQUENTIAL,
113
** the results of InitExt() are identical to calling Init().
114
** The function Init() may be called once to "precompute" the IV for
115
** a given hashBitLen value, then by saving a copy of the context
116
** the IV computation may be avoided in later calls.
117
** Similarly, the function InitExt() may be called once per MAC key
118
** to precompute the MAC IV, then a copy of the context saved and
119
** reused for each new MAC computation.
120
**/
121
int Skein_256_InitExt(Skein_256_Ctxt_t *ctx, size_t hashBitLen, u64b_t treeInfo, const u08b_t *key, size_t keyBytes);
122
int Skein_512_InitExt(Skein_512_Ctxt_t *ctx, size_t hashBitLen, u64b_t treeInfo, const u08b_t *key, size_t keyBytes);
123
int Skein1024_InitExt(Skein1024_Ctxt_t *ctx, size_t hashBitLen, u64b_t treeInfo, const u08b_t *key, size_t keyBytes);
124
125
/*
126
** Skein APIs for MAC and tree hash:
127
** Final_Pad: pad, do final block, but no OUTPUT type
128
** Output: do just the output stage
129
*/
130
int Skein_256_Final_Pad(Skein_256_Ctxt_t *ctx, u08b_t * hashVal);
131
int Skein_512_Final_Pad(Skein_512_Ctxt_t *ctx, u08b_t * hashVal);
132
int Skein1024_Final_Pad(Skein1024_Ctxt_t *ctx, u08b_t * hashVal);
133
134
#ifndef SKEIN_TREE_HASH
135
#define SKEIN_TREE_HASH (1)
136
#endif
137
#if SKEIN_TREE_HASH
138
int Skein_256_Output (Skein_256_Ctxt_t *ctx, u08b_t * hashVal);
139
int Skein_512_Output (Skein_512_Ctxt_t *ctx, u08b_t * hashVal);
140
int Skein1024_Output (Skein1024_Ctxt_t *ctx, u08b_t * hashVal);
141
#endif
142
143
/*****************************************************************
144
** "Internal" Skein definitions
145
** -- not needed for sequential hashing API, but will be
146
** helpful for other uses of Skein (e.g., tree hash mode).
147
** -- included here so that they can be shared between
148
** reference and optimized code.
149
******************************************************************/
150
151
/* tweak word T[1]: bit field starting positions */
152
#define SKEIN_T1_BIT(BIT) ((BIT) - 64) /* offset 64 because it's the second word */
153
154
#define SKEIN_T1_POS_TREE_LVL SKEIN_T1_BIT(112) /* bits 112..118: level in hash tree */
155
#define SKEIN_T1_POS_BIT_PAD SKEIN_T1_BIT(119) /* bit 119 : partial final input byte */
156
#define SKEIN_T1_POS_BLK_TYPE SKEIN_T1_BIT(120) /* bits 120..125: type field */
157
#define SKEIN_T1_POS_FIRST SKEIN_T1_BIT(126) /* bits 126 : first block flag */
158
#define SKEIN_T1_POS_FINAL SKEIN_T1_BIT(127) /* bit 127 : final block flag */
159
160
/* tweak word T[1]: flag bit definition(s) */
161
#define SKEIN_T1_FLAG_FIRST (((u64b_t) 1 ) << SKEIN_T1_POS_FIRST)
162
#define SKEIN_T1_FLAG_FINAL (((u64b_t) 1 ) << SKEIN_T1_POS_FINAL)
163
#define SKEIN_T1_FLAG_BIT_PAD (((u64b_t) 1 ) << SKEIN_T1_POS_BIT_PAD)
164
165
/* tweak word T[1]: tree level bit field mask */
166
#define SKEIN_T1_TREE_LVL_MASK (((u64b_t)0x7F) << SKEIN_T1_POS_TREE_LVL)
167
#define SKEIN_T1_TREE_LEVEL(n) (((u64b_t) (n)) << SKEIN_T1_POS_TREE_LVL)
168
169
/* tweak word T[1]: block type field */
170
#define SKEIN_BLK_TYPE_KEY ( 0) /* key, for MAC and KDF */
171
#define SKEIN_BLK_TYPE_CFG ( 4) /* configuration block */
172
#define SKEIN_BLK_TYPE_PERS ( 8) /* personalization string */
173
#define SKEIN_BLK_TYPE_PK (12) /* public key (for digital signature hashing) */
174
#define SKEIN_BLK_TYPE_KDF (16) /* key identifier for KDF */
175
#define SKEIN_BLK_TYPE_NONCE (20) /* nonce for PRNG */
176
#define SKEIN_BLK_TYPE_MSG (48) /* message processing */
177
#define SKEIN_BLK_TYPE_OUT (63) /* output stage */
178
#define SKEIN_BLK_TYPE_MASK (63) /* bit field mask */
179
180
#define SKEIN_T1_BLK_TYPE(T) (((u64b_t) (SKEIN_BLK_TYPE_##T)) << SKEIN_T1_POS_BLK_TYPE)
181
#define SKEIN_T1_BLK_TYPE_KEY SKEIN_T1_BLK_TYPE(KEY) /* key, for MAC and KDF */
182
#define SKEIN_T1_BLK_TYPE_CFG SKEIN_T1_BLK_TYPE(CFG) /* configuration block */
183
#define SKEIN_T1_BLK_TYPE_PERS SKEIN_T1_BLK_TYPE(PERS) /* personalization string */
184
#define SKEIN_T1_BLK_TYPE_PK SKEIN_T1_BLK_TYPE(PK) /* public key (for digital signature hashing) */
185
#define SKEIN_T1_BLK_TYPE_KDF SKEIN_T1_BLK_TYPE(KDF) /* key identifier for KDF */
186
#define SKEIN_T1_BLK_TYPE_NONCE SKEIN_T1_BLK_TYPE(NONCE)/* nonce for PRNG */
187
#define SKEIN_T1_BLK_TYPE_MSG SKEIN_T1_BLK_TYPE(MSG) /* message processing */
188
#define SKEIN_T1_BLK_TYPE_OUT SKEIN_T1_BLK_TYPE(OUT) /* output stage */
189
#define SKEIN_T1_BLK_TYPE_MASK SKEIN_T1_BLK_TYPE(MASK) /* field bit mask */
190
191
#define SKEIN_T1_BLK_TYPE_CFG_FINAL (SKEIN_T1_BLK_TYPE_CFG | SKEIN_T1_FLAG_FINAL)
192
#define SKEIN_T1_BLK_TYPE_OUT_FINAL (SKEIN_T1_BLK_TYPE_OUT | SKEIN_T1_FLAG_FINAL)
193
194
#define SKEIN_VERSION (1)
195
196
#ifndef SKEIN_ID_STRING_LE /* allow compile-time personalization */
197
#define SKEIN_ID_STRING_LE (0x33414853) /* "SHA3" (little-endian)*/
198
#endif
199
200
#define SKEIN_MK_64(hi32,lo32) ((lo32) + (((u64b_t) (hi32)) << 32))
201
#define SKEIN_SCHEMA_VER SKEIN_MK_64(SKEIN_VERSION,SKEIN_ID_STRING_LE)
202
#define SKEIN_KS_PARITY SKEIN_MK_64(0x1BD11BDA,0xA9FC1A22)
203
204
#define SKEIN_CFG_STR_LEN (4*8)
205
206
/* bit field definitions in config block treeInfo word */
207
#define SKEIN_CFG_TREE_LEAF_SIZE_POS ( 0)
208
#define SKEIN_CFG_TREE_NODE_SIZE_POS ( 8)
209
#define SKEIN_CFG_TREE_MAX_LEVEL_POS (16)
210
211
#define SKEIN_CFG_TREE_LEAF_SIZE_MSK (((u64b_t) 0xFF) << SKEIN_CFG_TREE_LEAF_SIZE_POS)
212
#define SKEIN_CFG_TREE_NODE_SIZE_MSK (((u64b_t) 0xFF) << SKEIN_CFG_TREE_NODE_SIZE_POS)
213
#define SKEIN_CFG_TREE_MAX_LEVEL_MSK (((u64b_t) 0xFF) << SKEIN_CFG_TREE_MAX_LEVEL_POS)
214
215
#define SKEIN_CFG_TREE_INFO(leaf,node,maxLvl) \
216
( (((u64b_t)(leaf )) << SKEIN_CFG_TREE_LEAF_SIZE_POS) | \
217
(((u64b_t)(node )) << SKEIN_CFG_TREE_NODE_SIZE_POS) | \
218
(((u64b_t)(maxLvl)) << SKEIN_CFG_TREE_MAX_LEVEL_POS) )
219
220
#define SKEIN_CFG_TREE_INFO_SEQUENTIAL SKEIN_CFG_TREE_INFO(0,0,0) /* use as treeInfo in InitExt() call for sequential processing */
221
222
/*
223
** Skein macros for getting/setting tweak words, etc.
224
** These are useful for partial input bytes, hash tree init/update, etc.
225
**/
226
#define Skein_Get_Tweak(ctxPtr,TWK_NUM) ((ctxPtr)->h.T[TWK_NUM])
227
#define Skein_Set_Tweak(ctxPtr,TWK_NUM,tVal) {(ctxPtr)->h.T[TWK_NUM] = (tVal);}
228
229
#define Skein_Get_T0(ctxPtr) Skein_Get_Tweak(ctxPtr,0)
230
#define Skein_Get_T1(ctxPtr) Skein_Get_Tweak(ctxPtr,1)
231
#define Skein_Set_T0(ctxPtr,T0) Skein_Set_Tweak(ctxPtr,0,T0)
232
#define Skein_Set_T1(ctxPtr,T1) Skein_Set_Tweak(ctxPtr,1,T1)
233
234
/* set both tweak words at once */
235
#define Skein_Set_T0_T1(ctxPtr,T0,T1) \
236
{ \
237
Skein_Set_T0(ctxPtr,(T0)); \
238
Skein_Set_T1(ctxPtr,(T1)); \
239
}
240
241
#define Skein_Set_Type(ctxPtr,BLK_TYPE) \
242
Skein_Set_T1(ctxPtr,SKEIN_T1_BLK_TYPE_##BLK_TYPE)
243
244
/* set up for starting with a new type: h.T[0]=0; h.T[1] = NEW_TYPE; h.bCnt=0; */
245
#define Skein_Start_New_Type(ctxPtr,BLK_TYPE) \
246
{ Skein_Set_T0_T1(ctxPtr,0,SKEIN_T1_FLAG_FIRST | SKEIN_T1_BLK_TYPE_##BLK_TYPE); (ctxPtr)->h.bCnt=0; }
247
248
#define Skein_Clear_First_Flag(hdr) { (hdr).T[1] &= ~SKEIN_T1_FLAG_FIRST; }
249
#define Skein_Set_Bit_Pad_Flag(hdr) { (hdr).T[1] |= SKEIN_T1_FLAG_BIT_PAD; }
250
251
#define Skein_Set_Tree_Level(hdr,height) { (hdr).T[1] |= SKEIN_T1_TREE_LEVEL(height);}
252
253
/*****************************************************************
254
** "Internal" Skein definitions for debugging and error checking
255
******************************************************************/
256
#ifdef SKEIN_DEBUG /* examine/display intermediate values? */
257
#include "skein_debug.h"
258
#else /* default is no callouts */
259
#define Skein_Show_Block(bits,ctx,X,blkPtr,wPtr,ksEvenPtr,ksOddPtr)
260
#define Skein_Show_Round(bits,ctx,r,X)
261
#define Skein_Show_R_Ptr(bits,ctx,r,X_ptr)
262
#define Skein_Show_Final(bits,ctx,cnt,outPtr)
263
#define Skein_Show_Key(bits,ctx,key,keyBytes)
264
#endif
265
266
#ifndef SKEIN_ERR_CHECK /* run-time checks (e.g., bad params, uninitialized context)? */
267
#define Skein_Assert(x,retCode)/* default: ignore all Asserts, for performance */
268
#define Skein_assert(x)
269
#elif defined(SKEIN_ASSERT)
270
#include <assert.h>
271
#define Skein_Assert(x,retCode) assert(x)
272
#define Skein_assert(x) assert(x)
273
#else
274
#include <assert.h>
275
#define Skein_Assert(x,retCode) { if (!(x)) return retCode; } /* caller error */
276
#define Skein_assert(x) assert(x) /* internal error */
277
#endif
278
279
/*****************************************************************
280
** Skein block function constants (shared across Ref and Opt code)
281
******************************************************************/
282
enum
283
{
284
/* Skein_256 round rotation constants */
285
R_256_0_0=14, R_256_0_1=16,
286
R_256_1_0=52, R_256_1_1=57,
287
R_256_2_0=23, R_256_2_1=40,
288
R_256_3_0= 5, R_256_3_1=37,
289
R_256_4_0=25, R_256_4_1=33,
290
R_256_5_0=46, R_256_5_1=12,
291
R_256_6_0=58, R_256_6_1=22,
292
R_256_7_0=32, R_256_7_1=32,
293
294
/* Skein_512 round rotation constants */
295
R_512_0_0=46, R_512_0_1=36, R_512_0_2=19, R_512_0_3=37,
296
R_512_1_0=33, R_512_1_1=27, R_512_1_2=14, R_512_1_3=42,
297
R_512_2_0=17, R_512_2_1=49, R_512_2_2=36, R_512_2_3=39,
298
R_512_3_0=44, R_512_3_1= 9, R_512_3_2=54, R_512_3_3=56,
299
R_512_4_0=39, R_512_4_1=30, R_512_4_2=34, R_512_4_3=24,
300
R_512_5_0=13, R_512_5_1=50, R_512_5_2=10, R_512_5_3=17,
301
R_512_6_0=25, R_512_6_1=29, R_512_6_2=39, R_512_6_3=43,
302
R_512_7_0= 8, R_512_7_1=35, R_512_7_2=56, R_512_7_3=22,
303
304
/* Skein1024 round rotation constants */
305
R1024_0_0=24, R1024_0_1=13, R1024_0_2= 8, R1024_0_3=47, R1024_0_4= 8, R1024_0_5=17, R1024_0_6=22, R1024_0_7=37,
306
R1024_1_0=38, R1024_1_1=19, R1024_1_2=10, R1024_1_3=55, R1024_1_4=49, R1024_1_5=18, R1024_1_6=23, R1024_1_7=52,
307
R1024_2_0=33, R1024_2_1= 4, R1024_2_2=51, R1024_2_3=13, R1024_2_4=34, R1024_2_5=41, R1024_2_6=59, R1024_2_7=17,
308
R1024_3_0= 5, R1024_3_1=20, R1024_3_2=48, R1024_3_3=41, R1024_3_4=47, R1024_3_5=28, R1024_3_6=16, R1024_3_7=25,
309
R1024_4_0=41, R1024_4_1= 9, R1024_4_2=37, R1024_4_3=31, R1024_4_4=12, R1024_4_5=47, R1024_4_6=44, R1024_4_7=30,
310
R1024_5_0=16, R1024_5_1=34, R1024_5_2=56, R1024_5_3=51, R1024_5_4= 4, R1024_5_5=53, R1024_5_6=42, R1024_5_7=41,
311
R1024_6_0=31, R1024_6_1=44, R1024_6_2=47, R1024_6_3=46, R1024_6_4=19, R1024_6_5=42, R1024_6_6=44, R1024_6_7=25,
312
R1024_7_0= 9, R1024_7_1=48, R1024_7_2=35, R1024_7_3=52, R1024_7_4=23, R1024_7_5=31, R1024_7_6=37, R1024_7_7=20
313
};
314
315
#ifndef SKEIN_ROUNDS
316
#define SKEIN_256_ROUNDS_TOTAL (72) /* number of rounds for the different block sizes */
317
#define SKEIN_512_ROUNDS_TOTAL (72)
318
#define SKEIN1024_ROUNDS_TOTAL (80)
319
#else /* allow command-line define in range 8*(5..14) */
320
#define SKEIN_256_ROUNDS_TOTAL (8*((((SKEIN_ROUNDS/100) + 5) % 10) + 5))
321
#define SKEIN_512_ROUNDS_TOTAL (8*((((SKEIN_ROUNDS/ 10) + 5) % 10) + 5))
322
#define SKEIN1024_ROUNDS_TOTAL (8*((((SKEIN_ROUNDS ) + 5) % 10) + 5))
323
#endif
324
325
#ifdef __cplusplus
326
}
327
#endif
328
329
/* Pull in FreeBSD specific shims */
330
#include "skein_freebsd.h"
331
332
#endif /* ifndef _SKEIN_H_ */
333
334