2013-01-19 02:20:00 +00:00
|
|
|
// sha3.cpp - modified by Wei Dai from Ronny Van Keer's public domain Keccak-simple.c
|
|
|
|
// all modifications here are placed in the public domain by Wei Dai
|
|
|
|
|
|
|
|
/*
|
|
|
|
The Keccak sponge function, designed by Guido Bertoni, Joan Daemen,
|
|
|
|
Michael Peeters and Gilles Van Assche. For more information, feedback or
|
|
|
|
questions, please refer to our website: http://keccak.noekeon.org/
|
|
|
|
|
|
|
|
Implementation by Ronny Van Keer,
|
|
|
|
hereby denoted as "the implementer".
|
|
|
|
|
|
|
|
To the extent possible under law, the implementer has waived all copyright
|
|
|
|
and related or neighboring rights to the source code in this file.
|
|
|
|
http://creativecommons.org/publicdomain/zero/1.0/
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include "pch.h"
|
|
|
|
#include "sha3.h"
|
|
|
|
|
|
|
|
NAMESPACE_BEGIN(CryptoPP)
|
|
|
|
|
2016-09-09 00:24:25 +00:00
|
|
|
static const word64 KeccakF_RoundConstants[24] =
|
2013-01-19 02:20:00 +00:00
|
|
|
{
|
|
|
|
W64LIT(0x0000000000000001), W64LIT(0x0000000000008082), W64LIT(0x800000000000808a),
|
|
|
|
W64LIT(0x8000000080008000), W64LIT(0x000000000000808b), W64LIT(0x0000000080000001),
|
|
|
|
W64LIT(0x8000000080008081), W64LIT(0x8000000000008009), W64LIT(0x000000000000008a),
|
|
|
|
W64LIT(0x0000000000000088), W64LIT(0x0000000080008009), W64LIT(0x000000008000000a),
|
|
|
|
W64LIT(0x000000008000808b), W64LIT(0x800000000000008b), W64LIT(0x8000000000008089),
|
2016-09-09 00:24:25 +00:00
|
|
|
W64LIT(0x8000000000008003), W64LIT(0x8000000000008002), W64LIT(0x8000000000000080),
|
2013-01-19 02:20:00 +00:00
|
|
|
W64LIT(0x000000000000800a), W64LIT(0x800000008000000a), W64LIT(0x8000000080008081),
|
|
|
|
W64LIT(0x8000000000008080), W64LIT(0x0000000080000001), W64LIT(0x8000000080008008)
|
|
|
|
};
|
|
|
|
|
|
|
|
static void KeccakF1600(word64 *state)
|
|
|
|
{
|
|
|
|
{
|
|
|
|
word64 Aba, Abe, Abi, Abo, Abu;
|
|
|
|
word64 Aga, Age, Agi, Ago, Agu;
|
|
|
|
word64 Aka, Ake, Aki, Ako, Aku;
|
|
|
|
word64 Ama, Ame, Ami, Amo, Amu;
|
|
|
|
word64 Asa, Ase, Asi, Aso, Asu;
|
|
|
|
word64 BCa, BCe, BCi, BCo, BCu;
|
|
|
|
word64 Da, De, Di, Do, Du;
|
|
|
|
word64 Eba, Ebe, Ebi, Ebo, Ebu;
|
|
|
|
word64 Ega, Ege, Egi, Ego, Egu;
|
|
|
|
word64 Eka, Eke, Eki, Eko, Eku;
|
|
|
|
word64 Ema, Eme, Emi, Emo, Emu;
|
|
|
|
word64 Esa, Ese, Esi, Eso, Esu;
|
|
|
|
|
|
|
|
//copyFromState(A, state)
|
2016-09-22 14:35:57 +00:00
|
|
|
typedef BlockGetAndPut<word64, LittleEndian, true, true> Block;
|
|
|
|
Block::Get(state)(Aba)(Abe)(Abi)(Abo)(Abu)(Aga)(Age)(Agi)(Ago)(Agu)(Aka)(Ake)(Aki)(Ako)(Aku)(Ama)(Ame)(Ami)(Amo)(Amu)(Asa)(Ase)(Asi)(Aso)(Asu);
|
2013-01-19 02:20:00 +00:00
|
|
|
|
|
|
|
for( unsigned int round = 0; round < 24; round += 2 )
|
|
|
|
{
|
|
|
|
// prepareTheta
|
|
|
|
BCa = Aba^Aga^Aka^Ama^Asa;
|
|
|
|
BCe = Abe^Age^Ake^Ame^Ase;
|
|
|
|
BCi = Abi^Agi^Aki^Ami^Asi;
|
|
|
|
BCo = Abo^Ago^Ako^Amo^Aso;
|
|
|
|
BCu = Abu^Agu^Aku^Amu^Asu;
|
|
|
|
|
|
|
|
//thetaRhoPiChiIotaPrepareTheta(round , A, E)
|
2017-11-25 07:52:19 +00:00
|
|
|
Da = BCu^rotlConstant<1>(BCe);
|
|
|
|
De = BCa^rotlConstant<1>(BCi);
|
|
|
|
Di = BCe^rotlConstant<1>(BCo);
|
|
|
|
Do = BCi^rotlConstant<1>(BCu);
|
|
|
|
Du = BCo^rotlConstant<1>(BCa);
|
2013-01-19 02:20:00 +00:00
|
|
|
|
|
|
|
Aba ^= Da;
|
|
|
|
BCa = Aba;
|
|
|
|
Age ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<44>(Age);
|
2013-01-19 02:20:00 +00:00
|
|
|
Aki ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<43>(Aki);
|
2013-01-19 02:20:00 +00:00
|
|
|
Amo ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<21>(Amo);
|
2013-01-19 02:20:00 +00:00
|
|
|
Asu ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<14>(Asu);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eba = BCa ^((~BCe)& BCi );
|
|
|
|
Eba ^= (word64)KeccakF_RoundConstants[round];
|
|
|
|
Ebe = BCe ^((~BCi)& BCo );
|
|
|
|
Ebi = BCi ^((~BCo)& BCu );
|
|
|
|
Ebo = BCo ^((~BCu)& BCa );
|
|
|
|
Ebu = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
Abo ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCa = rotlConstant<28>(Abo);
|
2013-01-19 02:20:00 +00:00
|
|
|
Agu ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<20>(Agu);
|
2013-01-19 02:20:00 +00:00
|
|
|
Aka ^= Da;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<3>(Aka);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ame ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<45>(Ame);
|
2013-01-19 02:20:00 +00:00
|
|
|
Asi ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<61>(Asi);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ega = BCa ^((~BCe)& BCi );
|
|
|
|
Ege = BCe ^((~BCi)& BCo );
|
|
|
|
Egi = BCi ^((~BCo)& BCu );
|
|
|
|
Ego = BCo ^((~BCu)& BCa );
|
|
|
|
Egu = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
Abe ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCa = rotlConstant<1>(Abe);
|
2013-01-19 02:20:00 +00:00
|
|
|
Agi ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<6>(Agi);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ako ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<25>(Ako);
|
2013-01-19 02:20:00 +00:00
|
|
|
Amu ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<8>(Amu);
|
2013-01-19 02:20:00 +00:00
|
|
|
Asa ^= Da;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<18>(Asa);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eka = BCa ^((~BCe)& BCi );
|
|
|
|
Eke = BCe ^((~BCi)& BCo );
|
|
|
|
Eki = BCi ^((~BCo)& BCu );
|
|
|
|
Eko = BCo ^((~BCu)& BCa );
|
|
|
|
Eku = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
Abu ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCa = rotlConstant<27>(Abu);
|
2013-01-19 02:20:00 +00:00
|
|
|
Aga ^= Da;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<36>(Aga);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ake ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<10>(Ake);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ami ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<15>(Ami);
|
2013-01-19 02:20:00 +00:00
|
|
|
Aso ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<56>(Aso);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ema = BCa ^((~BCe)& BCi );
|
|
|
|
Eme = BCe ^((~BCi)& BCo );
|
|
|
|
Emi = BCi ^((~BCo)& BCu );
|
|
|
|
Emo = BCo ^((~BCu)& BCa );
|
|
|
|
Emu = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
Abi ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCa = rotlConstant<62>(Abi);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ago ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<55>(Ago);
|
2013-01-19 02:20:00 +00:00
|
|
|
Aku ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<39>(Aku);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ama ^= Da;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<41>(Ama);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ase ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<2>(Ase);
|
2013-01-19 02:20:00 +00:00
|
|
|
Esa = BCa ^((~BCe)& BCi );
|
|
|
|
Ese = BCe ^((~BCi)& BCo );
|
|
|
|
Esi = BCi ^((~BCo)& BCu );
|
|
|
|
Eso = BCo ^((~BCu)& BCa );
|
|
|
|
Esu = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
// prepareTheta
|
|
|
|
BCa = Eba^Ega^Eka^Ema^Esa;
|
|
|
|
BCe = Ebe^Ege^Eke^Eme^Ese;
|
|
|
|
BCi = Ebi^Egi^Eki^Emi^Esi;
|
|
|
|
BCo = Ebo^Ego^Eko^Emo^Eso;
|
|
|
|
BCu = Ebu^Egu^Eku^Emu^Esu;
|
|
|
|
|
|
|
|
//thetaRhoPiChiIotaPrepareTheta(round+1, E, A)
|
2017-11-25 07:52:19 +00:00
|
|
|
Da = BCu^rotlConstant<1>(BCe);
|
|
|
|
De = BCa^rotlConstant<1>(BCi);
|
|
|
|
Di = BCe^rotlConstant<1>(BCo);
|
|
|
|
Do = BCi^rotlConstant<1>(BCu);
|
|
|
|
Du = BCo^rotlConstant<1>(BCa);
|
2013-01-19 02:20:00 +00:00
|
|
|
|
|
|
|
Eba ^= Da;
|
|
|
|
BCa = Eba;
|
|
|
|
Ege ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<44>(Ege);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eki ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<43>(Eki);
|
2013-01-19 02:20:00 +00:00
|
|
|
Emo ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<21>(Emo);
|
2013-01-19 02:20:00 +00:00
|
|
|
Esu ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<14>(Esu);
|
2013-01-19 02:20:00 +00:00
|
|
|
Aba = BCa ^((~BCe)& BCi );
|
|
|
|
Aba ^= (word64)KeccakF_RoundConstants[round+1];
|
|
|
|
Abe = BCe ^((~BCi)& BCo );
|
|
|
|
Abi = BCi ^((~BCo)& BCu );
|
|
|
|
Abo = BCo ^((~BCu)& BCa );
|
|
|
|
Abu = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
Ebo ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCa = rotlConstant<28>(Ebo);
|
2013-01-19 02:20:00 +00:00
|
|
|
Egu ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<20>(Egu);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eka ^= Da;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<3>(Eka);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eme ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<45>(Eme);
|
2013-01-19 02:20:00 +00:00
|
|
|
Esi ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<61>(Esi);
|
2013-01-19 02:20:00 +00:00
|
|
|
Aga = BCa ^((~BCe)& BCi );
|
|
|
|
Age = BCe ^((~BCi)& BCo );
|
|
|
|
Agi = BCi ^((~BCo)& BCu );
|
|
|
|
Ago = BCo ^((~BCu)& BCa );
|
|
|
|
Agu = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
Ebe ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCa = rotlConstant<1>(Ebe);
|
2013-01-19 02:20:00 +00:00
|
|
|
Egi ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<6>(Egi);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eko ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<25>(Eko);
|
2013-01-19 02:20:00 +00:00
|
|
|
Emu ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<8>(Emu);
|
2013-01-19 02:20:00 +00:00
|
|
|
Esa ^= Da;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<18>(Esa);
|
2013-01-19 02:20:00 +00:00
|
|
|
Aka = BCa ^((~BCe)& BCi );
|
|
|
|
Ake = BCe ^((~BCi)& BCo );
|
|
|
|
Aki = BCi ^((~BCo)& BCu );
|
|
|
|
Ako = BCo ^((~BCu)& BCa );
|
|
|
|
Aku = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
Ebu ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCa = rotlConstant<27>(Ebu);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ega ^= Da;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<36>(Ega);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eke ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<10>(Eke);
|
2013-01-19 02:20:00 +00:00
|
|
|
Emi ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<15>(Emi);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eso ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<56>(Eso);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ama = BCa ^((~BCe)& BCi );
|
|
|
|
Ame = BCe ^((~BCi)& BCo );
|
|
|
|
Ami = BCi ^((~BCo)& BCu );
|
|
|
|
Amo = BCo ^((~BCu)& BCa );
|
|
|
|
Amu = BCu ^((~BCa)& BCe );
|
|
|
|
|
|
|
|
Ebi ^= Di;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCa = rotlConstant<62>(Ebi);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ego ^= Do;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCe = rotlConstant<55>(Ego);
|
2013-01-19 02:20:00 +00:00
|
|
|
Eku ^= Du;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCi = rotlConstant<39>(Eku);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ema ^= Da;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCo = rotlConstant<41>(Ema);
|
2013-01-19 02:20:00 +00:00
|
|
|
Ese ^= De;
|
2017-11-25 07:52:19 +00:00
|
|
|
BCu = rotlConstant<2>(Ese);
|
2013-01-19 02:20:00 +00:00
|
|
|
Asa = BCa ^((~BCe)& BCi );
|
|
|
|
Ase = BCe ^((~BCi)& BCo );
|
|
|
|
Asi = BCi ^((~BCo)& BCu );
|
|
|
|
Aso = BCo ^((~BCu)& BCa );
|
|
|
|
Asu = BCu ^((~BCa)& BCe );
|
|
|
|
}
|
|
|
|
|
|
|
|
//copyToState(state, A)
|
2017-03-01 11:10:06 +00:00
|
|
|
Block::Put(NULLPTR, state)(Aba)(Abe)(Abi)(Abo)(Abu)(Aga)(Age)(Agi)(Ago)(Agu)(Aka)(Ake)(Aki)(Ako)(Aku)(Ama)(Ame)(Ami)(Amo)(Amu)(Asa)(Ase)(Asi)(Aso)(Asu);
|
2013-01-19 02:20:00 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void SHA3::Update(const byte *input, size_t length)
|
|
|
|
{
|
2018-05-06 02:56:15 +00:00
|
|
|
CRYPTOPP_ASSERT(!(input == NULLPTR && length != 0));
|
|
|
|
if (length == 0) { return; }
|
2015-11-18 20:32:28 +00:00
|
|
|
|
2016-09-22 14:35:57 +00:00
|
|
|
size_t spaceLeft;
|
|
|
|
while (length >= (spaceLeft = r() - m_counter))
|
|
|
|
{
|
|
|
|
if (spaceLeft)
|
|
|
|
xorbuf(m_state.BytePtr() + m_counter, input, spaceLeft);
|
|
|
|
KeccakF1600(m_state);
|
|
|
|
input += spaceLeft;
|
|
|
|
length -= spaceLeft;
|
|
|
|
m_counter = 0;
|
|
|
|
}
|
2013-01-19 02:20:00 +00:00
|
|
|
|
2016-09-22 14:35:57 +00:00
|
|
|
if (length)
|
|
|
|
xorbuf(m_state.BytePtr() + m_counter, input, length);
|
|
|
|
m_counter += (unsigned int)length;
|
2013-01-19 02:20:00 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
void SHA3::Restart()
|
|
|
|
{
|
2016-09-22 14:35:57 +00:00
|
|
|
memset(m_state, 0, m_state.SizeInBytes());
|
|
|
|
m_counter = 0;
|
2013-01-19 02:20:00 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
void SHA3::TruncatedFinal(byte *hash, size_t size)
|
|
|
|
{
|
2018-05-06 02:56:15 +00:00
|
|
|
CRYPTOPP_ASSERT(hash != NULLPTR);
|
2016-09-22 14:35:57 +00:00
|
|
|
ThrowIfInvalidTruncatedSize(size);
|
2016-04-23 22:47:23 +00:00
|
|
|
|
2016-09-22 14:35:57 +00:00
|
|
|
m_state.BytePtr()[m_counter] ^= 0x06;
|
|
|
|
m_state.BytePtr()[r()-1] ^= 0x80;
|
|
|
|
KeccakF1600(m_state);
|
|
|
|
memcpy(hash, m_state, size);
|
|
|
|
Restart();
|
2013-01-19 02:20:00 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
NAMESPACE_END
|