2017-01-27 12:05:45 +00:00
|
|
|
// keccak.h - originally written and placed in the public domain by Wei Dai
|
2016-09-09 00:24:25 +00:00
|
|
|
|
2017-11-29 15:54:33 +00:00
|
|
|
/// \file keccak.h
|
|
|
|
/// \brief Classes for Keccak message digests
|
|
|
|
/// \details The Crypto++ Keccak implementation uses F1600 with XOF d=0x01.
|
|
|
|
/// FIPS 202 conformance (XOF d=0x06) is available in SHA3 classes.
|
|
|
|
/// \details Keccak will likely change in the future to accommodate extensibility of the
|
|
|
|
/// round function and the XOF functions.
|
|
|
|
/// \sa <a href="http://en.wikipedia.org/wiki/Keccak">Keccak</a>
|
|
|
|
/// \since Crypto++ 5.6.4
|
2016-09-09 00:24:25 +00:00
|
|
|
|
|
|
|
#ifndef CRYPTOPP_KECCAK_H
|
|
|
|
#define CRYPTOPP_KECCAK_H
|
|
|
|
|
|
|
|
#include "cryptlib.h"
|
|
|
|
#include "secblock.h"
|
|
|
|
|
|
|
|
NAMESPACE_BEGIN(CryptoPP)
|
|
|
|
|
2017-11-29 15:54:33 +00:00
|
|
|
/// \brief Keccak message digest base class
|
|
|
|
/// \details The Crypto++ Keccak implementation uses F1600 with XOF d=0x01.
|
|
|
|
/// FIPS 202 conformance (XOF d=0x06) is available in SHA3 classes.
|
|
|
|
/// \details Keccak is the base class for Keccak_224, Keccak_256, Keccak_384 and Keccak_512.
|
|
|
|
/// Library users should instantiate a derived class, and only use Keccak
|
|
|
|
/// as a base class reference or pointer.
|
|
|
|
/// \details Keccak will likely change in the future to accommodate extensibility of the
|
|
|
|
/// round function and the XOF functions.
|
|
|
|
/// \details Perform the following to specify a different digest size. The class will use F1600,
|
|
|
|
/// XOF d=0x01, and a new vaue for <tt>r()</tt> (which will be <tt>200-2*24 = 152</tt>).
|
|
|
|
/// <pre> Keccack_192 : public Keccack
|
|
|
|
/// {
|
|
|
|
/// public:
|
2019-10-14 16:30:10 +00:00
|
|
|
/// CRYPTOPP_CONSTANT(DIGESTSIZE = 24);
|
2017-11-29 15:54:33 +00:00
|
|
|
/// Keccack_192() : Keccack(DIGESTSIZE) {}
|
|
|
|
/// };
|
|
|
|
/// </pre>
|
|
|
|
///
|
|
|
|
/// \sa SHA3, Keccak_224, Keccak_256, Keccak_384 and Keccak_512.
|
|
|
|
/// \since Crypto++ 5.6.4
|
2016-09-09 00:24:25 +00:00
|
|
|
class Keccak : public HashTransformation
|
|
|
|
{
|
2019-02-13 04:52:19 +00:00
|
|
|
protected:
|
2019-02-13 00:51:37 +00:00
|
|
|
/// \brief Construct a Keccak
|
|
|
|
/// \param digestSize the digest size, in bytes
|
|
|
|
/// \details Keccak is the base class for Keccak_224, Keccak_256, Keccak_384 and Keccak_512.
|
|
|
|
/// Library users should instantiate a derived class, and only use Keccak
|
|
|
|
/// as a base class reference or pointer.
|
2019-02-13 05:01:58 +00:00
|
|
|
/// \details This constructor was moved to protected at Crypto++ 8.1
|
|
|
|
/// because users were attempting to create Keccak objects with it.
|
2019-02-13 00:51:37 +00:00
|
|
|
/// \since Crypto++ 5.6.4
|
|
|
|
Keccak(unsigned int digestSize) : m_digestSize(digestSize) {Restart();}
|
2019-02-13 04:52:19 +00:00
|
|
|
|
|
|
|
public:
|
2019-02-13 00:51:37 +00:00
|
|
|
unsigned int DigestSize() const {return m_digestSize;}
|
|
|
|
unsigned int OptimalDataAlignment() const {return GetAlignmentOf<word64>();}
|
|
|
|
|
|
|
|
void Update(const byte *input, size_t length);
|
|
|
|
void Restart();
|
|
|
|
void TruncatedFinal(byte *hash, size_t size);
|
2016-09-21 12:16:10 +00:00
|
|
|
|
2016-09-09 00:24:25 +00:00
|
|
|
protected:
|
2019-02-13 00:51:37 +00:00
|
|
|
inline unsigned int r() const {return BlockSize();}
|
2016-09-09 00:24:25 +00:00
|
|
|
|
2019-02-13 00:51:37 +00:00
|
|
|
FixedSizeSecBlock<word64, 25> m_state;
|
|
|
|
unsigned int m_digestSize, m_counter;
|
2016-09-09 00:24:25 +00:00
|
|
|
};
|
|
|
|
|
2017-12-25 02:07:18 +00:00
|
|
|
/// \brief Keccak message digest template
|
|
|
|
/// \tparam T_DigestSize the size of the digest, in bytes
|
|
|
|
/// \since Crypto++ 6.0
|
2016-10-01 08:42:42 +00:00
|
|
|
template<unsigned int T_DigestSize>
|
2016-09-21 12:16:10 +00:00
|
|
|
class Keccak_Final : public Keccak
|
2016-09-09 00:24:25 +00:00
|
|
|
{
|
|
|
|
public:
|
2019-10-14 16:30:10 +00:00
|
|
|
CRYPTOPP_CONSTANT(DIGESTSIZE = T_DigestSize);
|
|
|
|
CRYPTOPP_CONSTANT(BLOCKSIZE = 200 - 2 * DIGESTSIZE);
|
2019-02-13 04:38:38 +00:00
|
|
|
static std::string StaticAlgorithmName()
|
|
|
|
{ return "Keccak-" + IntToString(DIGESTSIZE * 8); }
|
2019-02-13 00:51:37 +00:00
|
|
|
|
|
|
|
/// \brief Construct a Keccak-X message digest
|
|
|
|
Keccak_Final() : Keccak(DIGESTSIZE) {}
|
2019-02-13 04:38:38 +00:00
|
|
|
|
|
|
|
/// \brief Provides the block size of the compression function
|
|
|
|
/// \return block size of the compression function, in bytes
|
|
|
|
/// \details BlockSize() will return 0 if the hash is not block based
|
|
|
|
/// or does not have an equivalent block size. For example, Keccak
|
|
|
|
/// and SHA-3 do not have a block size, but they do have an equivalent
|
|
|
|
/// block size called rate expressed as <tt>r</tt>.
|
2019-02-13 00:51:37 +00:00
|
|
|
unsigned int BlockSize() const { return BLOCKSIZE; }
|
2016-09-21 12:16:10 +00:00
|
|
|
|
2019-02-13 19:22:43 +00:00
|
|
|
std::string AlgorithmName() const { return StaticAlgorithmName(); }
|
|
|
|
|
2016-09-21 12:16:10 +00:00
|
|
|
private:
|
2019-02-13 04:38:38 +00:00
|
|
|
#if !defined(__BORLANDC__)
|
|
|
|
// ensure there was no underflow in the math
|
|
|
|
CRYPTOPP_COMPILE_ASSERT(BLOCKSIZE < 200);
|
|
|
|
#endif
|
2016-09-09 00:24:25 +00:00
|
|
|
};
|
|
|
|
|
2017-11-29 15:54:33 +00:00
|
|
|
/// \brief Keccak-224 message digest
|
|
|
|
/// \since Crypto++ 5.6.4
|
2020-03-31 04:23:53 +00:00
|
|
|
DOCUMENTED_TYPEDEF(Keccak_Final<28>, Keccak_224);
|
2017-07-27 23:15:21 +00:00
|
|
|
|
2017-11-29 15:54:33 +00:00
|
|
|
/// \brief Keccak-256 message digest
|
|
|
|
/// \since Crypto++ 5.6.4
|
2020-03-31 04:23:53 +00:00
|
|
|
DOCUMENTED_TYPEDEF(Keccak_Final<32>, Keccak_256);
|
2017-07-27 23:15:21 +00:00
|
|
|
|
2017-11-29 15:54:33 +00:00
|
|
|
/// \brief Keccak-384 message digest
|
|
|
|
/// \since Crypto++ 5.6.4
|
2020-03-31 04:23:53 +00:00
|
|
|
DOCUMENTED_TYPEDEF(Keccak_Final<48>, Keccak_384);
|
2017-07-27 23:15:21 +00:00
|
|
|
|
2017-11-29 15:54:33 +00:00
|
|
|
/// \brief Keccak-512 message digest
|
|
|
|
/// \since Crypto++ 5.6.4
|
2020-03-31 04:23:53 +00:00
|
|
|
DOCUMENTED_TYPEDEF(Keccak_Final<64>, Keccak_512);
|
2016-09-09 00:24:25 +00:00
|
|
|
|
|
|
|
NAMESPACE_END
|
|
|
|
|
|
|
|
#endif
|