Path: blob/master/crypto/c_blake256.c
1298 views
/*1* The blake256_* and blake224_* functions are largely copied from2* blake256_light.c and blake224_light.c from the BLAKE website:3*4* http://131002.net/blake/5*6* The hmac_* functions implement HMAC-BLAKE-256 and HMAC-BLAKE-224.7* HMAC is specified by RFC 2104.8*/910#include <string.h>11#include <stdio.h>12#include <stdint.h>13#include "c_blake256.h"1415#define U8TO32(p) \16(((uint32_t)((p)[0]) << 24) | ((uint32_t)((p)[1]) << 16) | \17((uint32_t)((p)[2]) << 8) | ((uint32_t)((p)[3]) ))18#define U32TO8(p, v) \19(p)[0] = (uint8_t)((v) >> 24); (p)[1] = (uint8_t)((v) >> 16); \20(p)[2] = (uint8_t)((v) >> 8); (p)[3] = (uint8_t)((v) );2122const uint8_t sigma[][16] = {23{ 0, 1, 2, 3, 4, 5, 6, 7, 8, 9,10,11,12,13,14,15},24{14,10, 4, 8, 9,15,13, 6, 1,12, 0, 2,11, 7, 5, 3},25{11, 8,12, 0, 5, 2,15,13,10,14, 3, 6, 7, 1, 9, 4},26{ 7, 9, 3, 1,13,12,11,14, 2, 6, 5,10, 4, 0,15, 8},27{ 9, 0, 5, 7, 2, 4,10,15,14, 1,11,12, 6, 8, 3,13},28{ 2,12, 6,10, 0,11, 8, 3, 4,13, 7, 5,15,14, 1, 9},29{12, 5, 1,15,14,13, 4,10, 0, 7, 6, 3, 9, 2, 8,11},30{13,11, 7,14,12, 1, 3, 9, 5, 0,15, 4, 8, 6, 2,10},31{ 6,15,14, 9,11, 3, 0, 8,12, 2,13, 7, 1, 4,10, 5},32{10, 2, 8, 4, 7, 6, 1, 5,15,11, 9,14, 3,12,13, 0},33{ 0, 1, 2, 3, 4, 5, 6, 7, 8, 9,10,11,12,13,14,15},34{14,10, 4, 8, 9,15,13, 6, 1,12, 0, 2,11, 7, 5, 3},35{11, 8,12, 0, 5, 2,15,13,10,14, 3, 6, 7, 1, 9, 4},36{ 7, 9, 3, 1,13,12,11,14, 2, 6, 5,10, 4, 0,15, 8}37};3839const uint32_t cst[16] = {400x243F6A88, 0x85A308D3, 0x13198A2E, 0x03707344,410xA4093822, 0x299F31D0, 0x082EFA98, 0xEC4E6C89,420x452821E6, 0x38D01377, 0xBE5466CF, 0x34E90C6C,430xC0AC29B7, 0xC97C50DD, 0x3F84D5B5, 0xB547091744};4546static const uint8_t padding[] = {470x80,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,480,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,049};505152void blake256_compress(state *S, const uint8_t *block) {53uint32_t v[16], m[16], i;5455#define ROT(x,n) (((x)<<(32-n))|((x)>>(n)))56#define G(a,b,c,d,e) \57v[a] += (m[sigma[i][e]] ^ cst[sigma[i][e+1]]) + v[b]; \58v[d] = ROT(v[d] ^ v[a],16); \59v[c] += v[d]; \60v[b] = ROT(v[b] ^ v[c],12); \61v[a] += (m[sigma[i][e+1]] ^ cst[sigma[i][e]])+v[b]; \62v[d] = ROT(v[d] ^ v[a], 8); \63v[c] += v[d]; \64v[b] = ROT(v[b] ^ v[c], 7);6566for (i = 0; i < 16; ++i) m[i] = U8TO32(block + i * 4);67for (i = 0; i < 8; ++i) v[i] = S->h[i];68v[ 8] = S->s[0] ^ 0x243F6A88;69v[ 9] = S->s[1] ^ 0x85A308D3;70v[10] = S->s[2] ^ 0x13198A2E;71v[11] = S->s[3] ^ 0x03707344;72v[12] = 0xA4093822;73v[13] = 0x299F31D0;74v[14] = 0x082EFA98;75v[15] = 0xEC4E6C89;7677if (S->nullt == 0) {78v[12] ^= S->t[0];79v[13] ^= S->t[0];80v[14] ^= S->t[1];81v[15] ^= S->t[1];82}8384for (i = 0; i < 14; ++i) {85G(0, 4, 8, 12, 0);86G(1, 5, 9, 13, 2);87G(2, 6, 10, 14, 4);88G(3, 7, 11, 15, 6);89G(3, 4, 9, 14, 14);90G(2, 7, 8, 13, 12);91G(0, 5, 10, 15, 8);92G(1, 6, 11, 12, 10);93}9495for (i = 0; i < 16; ++i) S->h[i % 8] ^= v[i];96for (i = 0; i < 8; ++i) S->h[i] ^= S->s[i % 4];97}9899void blake256_init(state *S) {100S->h[0] = 0x6A09E667;101S->h[1] = 0xBB67AE85;102S->h[2] = 0x3C6EF372;103S->h[3] = 0xA54FF53A;104S->h[4] = 0x510E527F;105S->h[5] = 0x9B05688C;106S->h[6] = 0x1F83D9AB;107S->h[7] = 0x5BE0CD19;108S->t[0] = S->t[1] = S->buflen = S->nullt = 0;109S->s[0] = S->s[1] = S->s[2] = S->s[3] = 0;110}111112void blake224_init(state *S) {113S->h[0] = 0xC1059ED8;114S->h[1] = 0x367CD507;115S->h[2] = 0x3070DD17;116S->h[3] = 0xF70E5939;117S->h[4] = 0xFFC00B31;118S->h[5] = 0x68581511;119S->h[6] = 0x64F98FA7;120S->h[7] = 0xBEFA4FA4;121S->t[0] = S->t[1] = S->buflen = S->nullt = 0;122S->s[0] = S->s[1] = S->s[2] = S->s[3] = 0;123}124125// datalen = number of bits126void blake256_update(state *S, const uint8_t *data, uint64_t datalen) {127int left = S->buflen >> 3;128int fill = 64 - left;129130if (left && (((datalen >> 3) & 0x3F) >= (unsigned) fill)) {131memcpy((void *) (S->buf + left), (void *) data, fill);132S->t[0] += 512;133if (S->t[0] == 0) S->t[1]++;134blake256_compress(S, S->buf);135data += fill;136datalen -= (fill << 3);137left = 0;138}139140while (datalen >= 512) {141S->t[0] += 512;142if (S->t[0] == 0) S->t[1]++;143blake256_compress(S, data);144data += 64;145datalen -= 512;146}147148if (datalen > 0) {149memcpy((void *) (S->buf + left), (void *) data, (size_t) (datalen >> 3));150S->buflen = (left << 3) + (int) datalen;151} else {152S->buflen = 0;153}154}155156// datalen = number of bits157void blake224_update(state *S, const uint8_t *data, uint64_t datalen) {158blake256_update(S, data, datalen);159}160161void blake256_final_h(state *S, uint8_t *digest, uint8_t pa, uint8_t pb) {162uint8_t msglen[8];163uint32_t lo = S->t[0] + S->buflen, hi = S->t[1];164if (lo < (unsigned) S->buflen) hi++;165U32TO8(msglen + 0, hi);166U32TO8(msglen + 4, lo);167168if (S->buflen == 440) { /* one padding byte */169S->t[0] -= 8;170blake256_update(S, &pa, 8);171} else {172if (S->buflen < 440) { /* enough space to fill the block */173if (S->buflen == 0) S->nullt = 1;174S->t[0] -= 440 - S->buflen;175blake256_update(S, padding, 440 - S->buflen);176} else { /* need 2 compressions */177S->t[0] -= 512 - S->buflen;178blake256_update(S, padding, 512 - S->buflen);179S->t[0] -= 440;180blake256_update(S, padding + 1, 440);181S->nullt = 1;182}183blake256_update(S, &pb, 8);184S->t[0] -= 8;185}186S->t[0] -= 64;187blake256_update(S, msglen, 64);188189U32TO8(digest + 0, S->h[0]);190U32TO8(digest + 4, S->h[1]);191U32TO8(digest + 8, S->h[2]);192U32TO8(digest + 12, S->h[3]);193U32TO8(digest + 16, S->h[4]);194U32TO8(digest + 20, S->h[5]);195U32TO8(digest + 24, S->h[6]);196U32TO8(digest + 28, S->h[7]);197}198199void blake256_final(state *S, uint8_t *digest) {200blake256_final_h(S, digest, 0x81, 0x01);201}202203void blake224_final(state *S, uint8_t *digest) {204blake256_final_h(S, digest, 0x80, 0x00);205}206207// inlen = number of bytes208void blake256_hash(uint8_t *out, const uint8_t *in, uint64_t inlen) {209state S;210blake256_init(&S);211blake256_update(&S, in, inlen * 8);212blake256_final(&S, out);213}214215// inlen = number of bytes216void blake224_hash(uint8_t *out, const uint8_t *in, uint64_t inlen) {217state S;218blake224_init(&S);219blake224_update(&S, in, inlen * 8);220blake224_final(&S, out);221}222223// keylen = number of bytes224void hmac_blake256_init(hmac_state *S, const uint8_t *_key, uint64_t keylen) {225const uint8_t *key = _key;226uint8_t keyhash[32];227uint8_t pad[64];228uint64_t i;229230if (keylen > 64) {231blake256_hash(keyhash, key, keylen);232key = keyhash;233keylen = 32;234}235236blake256_init(&S->inner);237memset(pad, 0x36, 64);238for (i = 0; i < keylen; ++i) {239pad[i] ^= key[i];240}241blake256_update(&S->inner, pad, 512);242243blake256_init(&S->outer);244memset(pad, 0x5c, 64);245for (i = 0; i < keylen; ++i) {246pad[i] ^= key[i];247}248blake256_update(&S->outer, pad, 512);249250memset(keyhash, 0, 32);251}252253// keylen = number of bytes254void hmac_blake224_init(hmac_state *S, const uint8_t *_key, uint64_t keylen) {255const uint8_t *key = _key;256uint8_t keyhash[32];257uint8_t pad[64];258uint64_t i;259260if (keylen > 64) {261blake256_hash(keyhash, key, keylen);262key = keyhash;263keylen = 28;264}265266blake224_init(&S->inner);267memset(pad, 0x36, 64);268for (i = 0; i < keylen; ++i) {269pad[i] ^= key[i];270}271blake224_update(&S->inner, pad, 512);272273blake224_init(&S->outer);274memset(pad, 0x5c, 64);275for (i = 0; i < keylen; ++i) {276pad[i] ^= key[i];277}278blake224_update(&S->outer, pad, 512);279280memset(keyhash, 0, 32);281}282283// datalen = number of bits284void hmac_blake256_update(hmac_state *S, const uint8_t *data, uint64_t datalen) {285// update the inner state286blake256_update(&S->inner, data, datalen);287}288289// datalen = number of bits290void hmac_blake224_update(hmac_state *S, const uint8_t *data, uint64_t datalen) {291// update the inner state292blake224_update(&S->inner, data, datalen);293}294295void hmac_blake256_final(hmac_state *S, uint8_t *digest) {296uint8_t ihash[32];297blake256_final(&S->inner, ihash);298blake256_update(&S->outer, ihash, 256);299blake256_final(&S->outer, digest);300memset(ihash, 0, 32);301}302303void hmac_blake224_final(hmac_state *S, uint8_t *digest) {304uint8_t ihash[32];305blake224_final(&S->inner, ihash);306blake224_update(&S->outer, ihash, 224);307blake224_final(&S->outer, digest);308memset(ihash, 0, 32);309}310311// keylen = number of bytes; inlen = number of bytes312void hmac_blake256_hash(uint8_t *out, const uint8_t *key, uint64_t keylen, const uint8_t *in, uint64_t inlen) {313hmac_state S;314hmac_blake256_init(&S, key, keylen);315hmac_blake256_update(&S, in, inlen * 8);316hmac_blake256_final(&S, out);317}318319// keylen = number of bytes; inlen = number of bytes320void hmac_blake224_hash(uint8_t *out, const uint8_t *key, uint64_t keylen, const uint8_t *in, uint64_t inlen) {321hmac_state S;322hmac_blake224_init(&S, key, keylen);323hmac_blake224_update(&S, in, inlen * 8);324hmac_blake224_final(&S, out);325}326327328