2017-01-27 12:05:45 +00:00
|
|
|
// sha3.h - originally written and placed in the public domain by Wei Dai
|
2013-01-19 02:20:00 +00:00
|
|
|
|
2016-02-01 19:23:00 +00:00
|
|
|
//! \file sha3.h
|
2016-09-10 22:22:00 +00:00
|
|
|
//! \brief Classes for SHA3 message digests
|
|
|
|
//! \details The Crypto++ implementation conforms to the FIPS 202 version of SHA3 using F1600 with XOF d=0x06.
|
|
|
|
//! Previous behavior (XOF d=0x01) is available in Keccak classes.
|
2016-09-09 00:24:25 +00:00
|
|
|
//! \sa <a href="http://en.wikipedia.org/wiki/SHA-3">SHA-3</a>,
|
|
|
|
//! <A HREF="http://csrc.nist.gov/groups/ST/hash/sha-3/fips202_standard_2015.html">SHA-3 STANDARD (FIPS 202)</A>.
|
2016-09-09 09:19:29 +00:00
|
|
|
//! \since Crypto++ 5.6.2
|
2015-11-18 20:32:28 +00:00
|
|
|
|
2013-01-19 02:20:00 +00:00
|
|
|
#ifndef CRYPTOPP_SHA3_H
|
|
|
|
#define CRYPTOPP_SHA3_H
|
|
|
|
|
|
|
|
#include "cryptlib.h"
|
|
|
|
#include "secblock.h"
|
|
|
|
|
|
|
|
NAMESPACE_BEGIN(CryptoPP)
|
|
|
|
|
2016-02-01 19:23:00 +00:00
|
|
|
//! \class SHA3
|
|
|
|
//! \brief SHA3 message digest base class
|
2016-09-10 22:47:05 +00:00
|
|
|
//! \details The Crypto++ implementation conforms to FIPS 202 version of SHA3 using F1600 with XOF d=0x06.
|
2016-09-10 22:22:00 +00:00
|
|
|
//! Previous behavior (XOF d=0x01) is available in Keccak classes.
|
|
|
|
//! \details SHA3 is the base class for SHA3_224, SHA3_256, SHA3_384 and SHA3_512.
|
|
|
|
//! Library users should instantiate a derived class, and only use SHA3
|
|
|
|
//! as a base class reference or pointer.
|
|
|
|
//! \sa Keccak, SHA3_224, SHA3_256, SHA3_384 and SHA3_512.
|
|
|
|
//! \since Crypto++ 5.6.2
|
2013-01-19 02:20:00 +00:00
|
|
|
class SHA3 : public HashTransformation
|
|
|
|
{
|
|
|
|
public:
|
2016-02-01 19:23:00 +00:00
|
|
|
//! \brief Construct a SHA3
|
|
|
|
//! \param digestSize the digest size, in bytes
|
|
|
|
//! \details SHA3 is the base class for SHA3_224, SHA3_256, SHA3_384 and SHA3_512.
|
2016-09-09 09:04:36 +00:00
|
|
|
//! Library users should instantiate a derived class, and only use SHA3
|
2016-02-01 19:23:00 +00:00
|
|
|
//! as a base class reference or pointer.
|
2013-01-19 02:20:00 +00:00
|
|
|
SHA3(unsigned int digestSize) : m_digestSize(digestSize) {Restart();}
|
|
|
|
unsigned int DigestSize() const {return m_digestSize;}
|
2016-09-09 00:24:25 +00:00
|
|
|
std::string AlgorithmName() const {return "SHA3-" + IntToString(m_digestSize*8);}
|
2016-12-01 14:37:04 +00:00
|
|
|
CRYPTOPP_STATIC_CONSTEXPR const char* StaticAlgorithmName() { return "SHA3"; }
|
2015-11-05 06:59:46 +00:00
|
|
|
unsigned int OptimalDataAlignment() const {return GetAlignmentOf<word64>();}
|
2013-01-19 02:20:00 +00:00
|
|
|
|
|
|
|
void Update(const byte *input, size_t length);
|
|
|
|
void Restart();
|
|
|
|
void TruncatedFinal(byte *hash, size_t size);
|
|
|
|
|
2016-09-21 12:16:10 +00:00
|
|
|
// unsigned int BlockSize() const { return r(); } // that's the idea behind it
|
2013-01-19 02:20:00 +00:00
|
|
|
protected:
|
|
|
|
inline unsigned int r() const {return 200 - 2 * m_digestSize;}
|
|
|
|
|
|
|
|
FixedSizeSecBlock<word64, 25> m_state;
|
|
|
|
unsigned int m_digestSize, m_counter;
|
|
|
|
};
|
|
|
|
|
2016-09-20 23:01:38 +00:00
|
|
|
//! \class SHA3_224
|
2017-07-27 23:15:21 +00:00
|
|
|
//! \tparam T_DigestSize controls the digest size as a template parameter instead of a per-class constant
|
2016-09-21 12:16:10 +00:00
|
|
|
//! \brief SHA3-X message digest, template for more fine-grained typedefs
|
2017-02-21 17:59:20 +00:00
|
|
|
//! \since Crypto++ 6.0.0
|
2016-10-01 08:42:42 +00:00
|
|
|
template<unsigned int T_DigestSize>
|
2016-09-21 12:16:10 +00:00
|
|
|
class SHA3_Final : public SHA3
|
2013-01-19 02:20:00 +00:00
|
|
|
{
|
|
|
|
public:
|
2016-10-01 08:42:42 +00:00
|
|
|
CRYPTOPP_CONSTANT(DIGESTSIZE = T_DigestSize)
|
2016-09-21 12:16:10 +00:00
|
|
|
CRYPTOPP_CONSTANT(BLOCKSIZE = 200 - 2 * DIGESTSIZE)
|
|
|
|
|
|
|
|
//! \brief Construct a SHA3-X message digest
|
|
|
|
SHA3_Final() : SHA3(DIGESTSIZE) {}
|
|
|
|
static std::string StaticAlgorithmName() { return "SHA3-" + IntToString(DIGESTSIZE * 8); }
|
|
|
|
unsigned int BlockSize() const { return BLOCKSIZE; }
|
|
|
|
private:
|
2017-09-21 06:01:04 +00:00
|
|
|
#if !defined(__BORLANDC__)
|
2016-09-21 12:16:10 +00:00
|
|
|
CRYPTOPP_COMPILE_ASSERT(BLOCKSIZE < 200); // ensure there was no underflow in the math
|
2016-10-01 09:24:45 +00:00
|
|
|
CRYPTOPP_COMPILE_ASSERT(BLOCKSIZE > (int)T_DigestSize); // this is a general expectation by HMAC
|
2017-09-21 06:01:04 +00:00
|
|
|
#endif
|
2016-09-09 00:24:25 +00:00
|
|
|
};
|
2013-01-19 02:20:00 +00:00
|
|
|
|
2016-09-21 12:16:10 +00:00
|
|
|
//! \brief SHA3-224 message digest
|
|
|
|
//! \since Crypto++ 5.6.2
|
|
|
|
typedef SHA3_Final<28> SHA3_224;
|
2017-07-27 23:15:21 +00:00
|
|
|
|
2016-02-01 19:23:00 +00:00
|
|
|
//! \brief SHA3-256 message digest
|
2016-09-09 09:19:29 +00:00
|
|
|
//! \since Crypto++ 5.6.2
|
2016-09-21 12:16:10 +00:00
|
|
|
typedef SHA3_Final<32> SHA3_256;
|
2017-07-27 23:15:21 +00:00
|
|
|
|
2016-02-01 19:23:00 +00:00
|
|
|
//! \brief SHA3-384 message digest
|
2016-09-09 09:19:29 +00:00
|
|
|
//! \since Crypto++ 5.6.2
|
2016-09-21 12:16:10 +00:00
|
|
|
typedef SHA3_Final<48> SHA3_384;
|
2017-07-27 23:15:21 +00:00
|
|
|
|
2016-02-01 19:23:00 +00:00
|
|
|
//! \brief SHA3-512 message digest
|
2016-09-09 09:19:29 +00:00
|
|
|
//! \since Crypto++ 5.6.2
|
2016-09-21 12:16:10 +00:00
|
|
|
typedef SHA3_Final<64> SHA3_512;
|
2013-01-19 02:20:00 +00:00
|
|
|
|
|
|
|
NAMESPACE_END
|
|
|
|
|
|
|
|
#endif
|