|
1 /* |
|
2 * Copyright (c) 2007-2009 Nokia Corporation and/or its subsidiary(-ies). |
|
3 * All rights reserved. |
|
4 * This component and the accompanying materials are made available |
|
5 * under the terms of the License "Eclipse Public License v1.0" |
|
6 * which accompanies this distribution, and is available |
|
7 * at the URL "http://www.eclipse.org/legal/epl-v10.html". |
|
8 * |
|
9 * Initial Contributors: |
|
10 * Nokia Corporation - initial contribution. |
|
11 * |
|
12 * Contributors: |
|
13 * |
|
14 * Description: |
|
15 * Common implementation of SHA384 and SHA512 |
|
16 * RFC 4634 (US Secure Hash Algorithms (SHA and HMAC-SHA)) |
|
17 * |
|
18 */ |
|
19 |
|
20 |
|
21 |
|
22 |
|
23 /** |
|
24 @file |
|
25 */ |
|
26 |
|
27 #include "sha384and512.h" |
|
28 |
|
29 /** |
|
30 * SHA512 Constants |
|
31 * |
|
32 * SHA-512 uses a sequence of eighty constant 64-bit words. |
|
33 * These words represent the first sixty-four bits of the fractional |
|
34 * parts of the cube roots of the first eighty prime numbers. |
|
35 * |
|
36 * FIPS 180-2 Section 4.2.3 |
|
37 */ |
|
38 const TUint64 K[80] = |
|
39 { |
|
40 UI64LIT(0x428a2f98d728ae22), UI64LIT(0x7137449123ef65cd), UI64LIT(0xb5c0fbcfec4d3b2f), UI64LIT(0xe9b5dba58189dbbc), |
|
41 UI64LIT(0x3956c25bf348b538), UI64LIT(0x59f111f1b605d019), UI64LIT(0x923f82a4af194f9b), UI64LIT(0xab1c5ed5da6d8118), |
|
42 UI64LIT(0xd807aa98a3030242), UI64LIT(0x12835b0145706fbe), UI64LIT(0x243185be4ee4b28c), UI64LIT(0x550c7dc3d5ffb4e2), |
|
43 UI64LIT(0x72be5d74f27b896f), UI64LIT(0x80deb1fe3b1696b1), UI64LIT(0x9bdc06a725c71235), UI64LIT(0xc19bf174cf692694), |
|
44 UI64LIT(0xe49b69c19ef14ad2), UI64LIT(0xefbe4786384f25e3), UI64LIT(0x0fc19dc68b8cd5b5), UI64LIT(0x240ca1cc77ac9c65), |
|
45 UI64LIT(0x2de92c6f592b0275), UI64LIT(0x4a7484aa6ea6e483), UI64LIT(0x5cb0a9dcbd41fbd4), UI64LIT(0x76f988da831153b5), |
|
46 UI64LIT(0x983e5152ee66dfab), UI64LIT(0xa831c66d2db43210), UI64LIT(0xb00327c898fb213f), UI64LIT(0xbf597fc7beef0ee4), |
|
47 UI64LIT(0xc6e00bf33da88fc2), UI64LIT(0xd5a79147930aa725), UI64LIT(0x06ca6351e003826f), UI64LIT(0x142929670a0e6e70), |
|
48 UI64LIT(0x27b70a8546d22ffc), UI64LIT(0x2e1b21385c26c926), UI64LIT(0x4d2c6dfc5ac42aed), UI64LIT(0x53380d139d95b3df), |
|
49 UI64LIT(0x650a73548baf63de), UI64LIT(0x766a0abb3c77b2a8), UI64LIT(0x81c2c92e47edaee6), UI64LIT(0x92722c851482353b), |
|
50 UI64LIT(0xa2bfe8a14cf10364), UI64LIT(0xa81a664bbc423001), UI64LIT(0xc24b8b70d0f89791), UI64LIT(0xc76c51a30654be30), |
|
51 UI64LIT(0xd192e819d6ef5218), UI64LIT(0xd69906245565a910), UI64LIT(0xf40e35855771202a), UI64LIT(0x106aa07032bbd1b8), |
|
52 UI64LIT(0x19a4c116b8d2d0c8), UI64LIT(0x1e376c085141ab53), UI64LIT(0x2748774cdf8eeb99), UI64LIT(0x34b0bcb5e19b48a8), |
|
53 UI64LIT(0x391c0cb3c5c95a63), UI64LIT(0x4ed8aa4ae3418acb), UI64LIT(0x5b9cca4f7763e373), UI64LIT(0x682e6ff3d6b2b8a3), |
|
54 UI64LIT(0x748f82ee5defb2fc), UI64LIT(0x78a5636f43172f60), UI64LIT(0x84c87814a1f0ab72), UI64LIT(0x8cc702081a6439ec), |
|
55 UI64LIT(0x90befffa23631e28), UI64LIT(0xa4506cebde82bde9), UI64LIT(0xbef9a3f7b2c67915), UI64LIT(0xc67178f2e372532b), |
|
56 UI64LIT(0xca273eceea26619c), UI64LIT(0xd186b8c721c0c207), UI64LIT(0xeada7dd6cde0eb1e), UI64LIT(0xf57d4f7fee6ed178), |
|
57 UI64LIT(0x06f067aa72176fba), UI64LIT(0x0a637dc5a2c898a6), UI64LIT(0x113f9804bef90dae), UI64LIT(0x1b710b35131c471b), |
|
58 UI64LIT(0x28db77f523047d84), UI64LIT(0x32caab7b40c72493), UI64LIT(0x3c9ebe0a15c9bebc), UI64LIT(0x431d67c49c100d4c), |
|
59 UI64LIT(0x4cc5d4becb3e42b6), UI64LIT(0x597f299cfc657e2a), UI64LIT(0x5fcb6fab3ad6faec), UI64LIT(0x6c44198c4a475817) |
|
60 }; |
|
61 |
|
62 /** |
|
63 * Define the SHA SIGMA and sigma macros |
|
64 * |
|
65 * FIPS 180-2 section 4.1.3 |
|
66 */ |
|
67 // Equation 4.10 |
|
68 inline TUint64 SHA512_SIGMA0(TUint64 aWord) |
|
69 { |
|
70 return (SHA_ROTR<TUint64>(28,aWord) ^ SHA_ROTR<TUint64>(34,aWord) ^ SHA_ROTR<TUint64>(39,aWord)); |
|
71 } |
|
72 // Equation 4.11 |
|
73 inline TUint64 SHA512_SIGMA1(TUint64 aWord) |
|
74 { |
|
75 return (SHA_ROTR<TUint64>(14,aWord) ^ SHA_ROTR<TUint64>(18,aWord) ^ SHA_ROTR<TUint64>(41,aWord)); |
|
76 } |
|
77 // Equation 4.12 |
|
78 inline TUint64 SHA512_sigma0(TUint64 aWord) |
|
79 { |
|
80 return (SHA_ROTR<TUint64>(1, aWord) ^ SHA_ROTR<TUint64>(8, aWord) ^ SHA_SHR<TUint64>(7, aWord)); |
|
81 } |
|
82 // Equation 4.13 |
|
83 inline TUint64 SHA512_sigma1(TUint64 aWord) |
|
84 { |
|
85 return (SHA_ROTR<TUint64>(19,aWord) ^ SHA_ROTR<TUint64>(61,aWord) ^ SHA_SHR<TUint64>(6,aWord)); |
|
86 } |
|
87 |
|
88 // Macros |
|
89 inline TUint64 Make64BitWord(const TUint8* aData) |
|
90 { |
|
91 TUint64 result = (TUint64)aData[0] << 56 | (TUint64)aData[1] << 48 | (TUint64)aData[2] << 40 | |
|
92 (TUint64)aData[3] << 32 | (TUint64)aData[4] << 24 | (TUint64)aData[5] << 16 | |
|
93 (TUint64)aData[6] << 8 | (TUint64)aData[7]; |
|
94 return result; |
|
95 } |
|
96 |
|
97 |
|
98 CSHA384And512* CSHA384And512::NewL() |
|
99 { |
|
100 CSHA384And512* self=new (ELeave) CSHA384And512(); |
|
101 return self; |
|
102 } |
|
103 |
|
104 CSHA384And512::CSHA384And512() : iHash(KSHA512HashSize) |
|
105 { |
|
106 } |
|
107 |
|
108 CSHA384And512::CSHA384And512(const CSHA384And512& aSHAImpl) |
|
109 : iHash(aSHAImpl.iHash), |
|
110 iA(aSHAImpl.iA), |
|
111 iB(aSHAImpl.iB), |
|
112 iC(aSHAImpl.iC), |
|
113 iD(aSHAImpl.iD), |
|
114 iE(aSHAImpl.iE), |
|
115 iF(aSHAImpl.iF), |
|
116 iG(aSHAImpl.iG), |
|
117 iH(aSHAImpl.iH), |
|
118 iNl(aSHAImpl.iNl), |
|
119 iNh(aSHAImpl.iNh), |
|
120 iBlockIndex(aSHAImpl.iBlockIndex) |
|
121 { |
|
122 Mem::Copy(iData, aSHAImpl.iData, KSHA512BlockSize*sizeof(TUint64)); |
|
123 } |
|
124 |
|
125 void CSHA384And512::Reset(const TAny* aValueArr) |
|
126 { |
|
127 const TUint64* values = static_cast<const TUint64*>(aValueArr); |
|
128 |
|
129 iA = values[0]; |
|
130 iB = values[1]; |
|
131 iC = values[2]; |
|
132 iD = values[3]; |
|
133 iE = values[4]; |
|
134 iF = values[5]; |
|
135 iG = values[6]; |
|
136 iH = values[7]; |
|
137 iNh = 0; |
|
138 iNl = 0; |
|
139 iBlockIndex = 0; |
|
140 } |
|
141 |
|
142 //This function will panic if the total input length is longer than 2^128 in bits |
|
143 _LIT(KPanicString, "Message length exceeds supported length"); |
|
144 inline void CSHA384And512::AddLength(const TUint64 aLength) |
|
145 { |
|
146 TUint64 temp = iNl; |
|
147 iNl += aLength << 3; |
|
148 __ASSERT_ALWAYS(((iNh != KMaxTUint64) || (temp <= iNl)), User::Panic(KPanicString, KErrOverflow)); |
|
149 iNh += (temp > iNl); |
|
150 } |
|
151 |
|
152 // This assumes a big-endian architecture |
|
153 void CSHA384And512::Update(const TUint8* aData,TUint aLength) |
|
154 { |
|
155 while((aLength / 8) > 0 && (iBlockIndex % 8 == 0)) |
|
156 { |
|
157 iData[iBlockIndex>>3] = Make64BitWord(aData); |
|
158 iBlockIndex+=8; |
|
159 aData+=8; |
|
160 aLength-=8; |
|
161 if(iBlockIndex==KSHA512BlockSize) |
|
162 { |
|
163 Block(); |
|
164 AddLength(KSHA512BlockSize); |
|
165 } |
|
166 } |
|
167 |
|
168 while(aLength--) |
|
169 { |
|
170 if(!(iBlockIndex&0x07)) |
|
171 { |
|
172 iData[iBlockIndex >> 3] = 0; |
|
173 } |
|
174 iData[iBlockIndex >> 3] |= static_cast<TUint64>(*aData) << ((7 - iBlockIndex&0x07) << 3) ; |
|
175 ++aData; |
|
176 ++iBlockIndex; |
|
177 if(iBlockIndex==KSHA512BlockSize) |
|
178 { |
|
179 Block(); |
|
180 AddLength(KSHA512BlockSize); |
|
181 } |
|
182 } |
|
183 } |
|
184 |
|
185 static inline void CSHA512_16( const TUint64 aA, |
|
186 const TUint64 aB, |
|
187 const TUint64 aC, |
|
188 TUint64& aD, |
|
189 const TUint64 aE, |
|
190 const TUint64 aF, |
|
191 const TUint64 aG, |
|
192 TUint64& aH, |
|
193 TUint64 aTemp1, |
|
194 TUint64 aTemp2, |
|
195 const TUint64 aK, |
|
196 const TUint64 aWord) |
|
197 { |
|
198 aTemp1 = aH + SHA512_SIGMA1(aE) + SHA_Ch(aE,aF,aG) + aK + aWord; |
|
199 aTemp2 = SHA512_SIGMA0(aA) + SHA_Maj(aA,aB,aC); |
|
200 aD = aD + aTemp1; |
|
201 aH = aTemp1 + aTemp2; |
|
202 } |
|
203 |
|
204 static inline void CSHA512_64( const TUint64 aA, |
|
205 const TUint64 aB, |
|
206 const TUint64 aC, |
|
207 TUint64& aD, |
|
208 const TUint64 aE, |
|
209 const TUint64 aF, |
|
210 const TUint64 aG, |
|
211 TUint64& aH, |
|
212 TUint64 aTemp1, |
|
213 TUint64 aTemp2, |
|
214 const TUint64 aK, |
|
215 TUint64& aWord0, |
|
216 const TUint64 aWord2, |
|
217 const TUint64 aWord7, |
|
218 const TUint64 aWord15, |
|
219 const TUint64 aWord16) |
|
220 { |
|
221 aWord0 = SHA512_sigma1(aWord2) + aWord7 + SHA512_sigma0(aWord15) + aWord16; |
|
222 CSHA512_16(aA, aB, aC, aD, aE, aF, aG, aH, aTemp1, aTemp2, aK, aWord0); |
|
223 } |
|
224 |
|
225 /** |
|
226 * This function actually calculates the hash. |
|
227 * Function is defined in FIPS 180-2 section 6.3.2 |
|
228 * |
|
229 * This function is the expanded version of the following loop. |
|
230 * for(TUint i = 0; i < 80; ++i) |
|
231 * { |
|
232 * if(i >= 16) |
|
233 * { |
|
234 * iData[i] = SHA512_sigma1(iData[i-2]) + iData[i-7] + SHA512_sigma0(iData[i-15]) + iData[i-16]; |
|
235 * } |
|
236 * |
|
237 * temp1 = tempH + SHA512_SIGMA1(tempE) + SHA_Ch(tempE,tempF,tempG) + K[i] + iData[i]; |
|
238 * temp2 = SHA512_SIGMA0(tempA) + SHA_Maj(tempA,tempB,tempC); |
|
239 * tempH = tempG; |
|
240 * tempG = tempF; |
|
241 * tempF = tempE; |
|
242 * tempE = tempD + temp1; |
|
243 * tempD = tempC; |
|
244 * tempC = tempB; |
|
245 * tempB = tempA; |
|
246 * tempA = temp1 + temp2; |
|
247 * } |
|
248 */ |
|
249 void CSHA384And512::Block() |
|
250 { |
|
251 TUint64 tempA=iA; |
|
252 TUint64 tempB=iB; |
|
253 TUint64 tempC=iC; |
|
254 TUint64 tempD=iD; |
|
255 TUint64 tempE=iE; |
|
256 TUint64 tempF=iF; |
|
257 TUint64 tempG=iG; |
|
258 TUint64 tempH=iH; |
|
259 TUint64 temp1=0; |
|
260 TUint64 temp2=0; |
|
261 |
|
262 CSHA512_16(tempA,tempB,tempC,tempD,tempE,tempF,tempG,tempH,temp1,temp2,K[0],iData[0]); |
|
263 CSHA512_16(tempH,tempA,tempB,tempC,tempD,tempE,tempF,tempG,temp1,temp2,K[1],iData[1]); |
|
264 CSHA512_16(tempG,tempH,tempA,tempB,tempC,tempD,tempE,tempF,temp1,temp2,K[2],iData[2]); |
|
265 CSHA512_16(tempF,tempG,tempH,tempA,tempB,tempC,tempD,tempE,temp1,temp2,K[3],iData[3]); |
|
266 CSHA512_16(tempE,tempF,tempG,tempH,tempA,tempB,tempC,tempD,temp1,temp2,K[4],iData[4]); |
|
267 CSHA512_16(tempD,tempE,tempF,tempG,tempH,tempA,tempB,tempC,temp1,temp2,K[5],iData[5]); |
|
268 CSHA512_16(tempC,tempD,tempE,tempF,tempG,tempH,tempA,tempB,temp1,temp2,K[6],iData[6]); |
|
269 CSHA512_16(tempB,tempC,tempD,tempE,tempF,tempG,tempH,tempA,temp1,temp2,K[7],iData[7]); |
|
270 |
|
271 CSHA512_16(tempA,tempB,tempC,tempD,tempE,tempF,tempG,tempH,temp1,temp2,K[8],iData[8]); |
|
272 CSHA512_16(tempH,tempA,tempB,tempC,tempD,tempE,tempF,tempG,temp1,temp2,K[9],iData[9]); |
|
273 CSHA512_16(tempG,tempH,tempA,tempB,tempC,tempD,tempE,tempF,temp1,temp2,K[10],iData[10]); |
|
274 CSHA512_16(tempF,tempG,tempH,tempA,tempB,tempC,tempD,tempE,temp1,temp2,K[11],iData[11]); |
|
275 CSHA512_16(tempE,tempF,tempG,tempH,tempA,tempB,tempC,tempD,temp1,temp2,K[12],iData[12]); |
|
276 CSHA512_16(tempD,tempE,tempF,tempG,tempH,tempA,tempB,tempC,temp1,temp2,K[13],iData[13]); |
|
277 CSHA512_16(tempC,tempD,tempE,tempF,tempG,tempH,tempA,tempB,temp1,temp2,K[14],iData[14]); |
|
278 CSHA512_16(tempB,tempC,tempD,tempE,tempF,tempG,tempH,tempA,temp1,temp2,K[15],iData[15]); |
|
279 |
|
280 CSHA512_64( tempA, tempB, tempC, tempD, tempE, tempF, tempG, tempH, temp1, temp2, |
|
281 K[16], iData[16], iData[14], iData[9], iData[1], iData[0]); |
|
282 CSHA512_64( tempH, tempA, tempB, tempC, tempD, tempE, tempF, tempG, temp1, temp2, |
|
283 K[17], iData[17], iData[15], iData[10], iData[2], iData[1]); |
|
284 CSHA512_64( tempG, tempH, tempA, tempB, tempC, tempD, tempE, tempF, temp1, temp2, |
|
285 K[18], iData[18], iData[16], iData[11], iData[3], iData[2]); |
|
286 CSHA512_64( tempF, tempG, tempH, tempA, tempB, tempC, tempD, tempE, temp1, temp2, |
|
287 K[19], iData[19], iData[17], iData[12], iData[4], iData[3]); |
|
288 CSHA512_64( tempE, tempF, tempG, tempH, tempA, tempB, tempC, tempD, temp1, temp2, |
|
289 K[20], iData[20], iData[18], iData[13], iData[5], iData[4]); |
|
290 CSHA512_64( tempD, tempE, tempF, tempG, tempH, tempA, tempB, tempC, temp1, temp2, |
|
291 K[21], iData[21], iData[19], iData[14], iData[6], iData[5]); |
|
292 CSHA512_64( tempC, tempD, tempE, tempF, tempG, tempH, tempA, tempB, temp1, temp2, |
|
293 K[22], iData[22], iData[20], iData[15], iData[7], iData[6]); |
|
294 CSHA512_64( tempB, tempC, tempD, tempE, tempF, tempG, tempH, tempA, temp1, temp2, |
|
295 K[23], iData[23], iData[21], iData[16], iData[8], iData[7]); |
|
296 |
|
297 CSHA512_64( tempA, tempB, tempC, tempD, tempE, tempF, tempG, tempH, temp1, temp2, |
|
298 K[24], iData[24], iData[22], iData[17], iData[9], iData[8]); |
|
299 CSHA512_64( tempH, tempA, tempB, tempC, tempD, tempE, tempF, tempG, temp1, temp2, |
|
300 K[25], iData[25], iData[23], iData[18], iData[10], iData[9]); |
|
301 CSHA512_64( tempG, tempH, tempA, tempB, tempC, tempD, tempE, tempF, temp1, temp2, |
|
302 K[26], iData[26], iData[24], iData[19], iData[11], iData[10]); |
|
303 CSHA512_64( tempF, tempG, tempH, tempA, tempB, tempC, tempD, tempE, temp1, temp2, |
|
304 K[27], iData[27], iData[25], iData[20], iData[12], iData[11]); |
|
305 CSHA512_64( tempE, tempF, tempG, tempH, tempA, tempB, tempC, tempD, temp1, temp2, |
|
306 K[28], iData[28], iData[26], iData[21], iData[13], iData[12]); |
|
307 CSHA512_64( tempD, tempE, tempF, tempG, tempH, tempA, tempB, tempC, temp1, temp2, |
|
308 K[29], iData[29], iData[27], iData[22], iData[14], iData[13]); |
|
309 CSHA512_64( tempC, tempD, tempE, tempF, tempG, tempH, tempA, tempB, temp1, temp2, |
|
310 K[30], iData[30], iData[28], iData[23], iData[15], iData[14]); |
|
311 CSHA512_64( tempB, tempC, tempD, tempE, tempF, tempG, tempH, tempA, temp1, temp2, |
|
312 K[31], iData[31], iData[29], iData[24], iData[16], iData[15]); |
|
313 |
|
314 CSHA512_64( tempA, tempB, tempC, tempD, tempE, tempF, tempG, tempH, temp1, temp2, |
|
315 K[32], iData[32], iData[30], iData[25], iData[17], iData[16]); |
|
316 CSHA512_64( tempH, tempA, tempB, tempC, tempD, tempE, tempF, tempG, temp1, temp2, |
|
317 K[33], iData[33], iData[31], iData[26], iData[18], iData[17]); |
|
318 CSHA512_64( tempG, tempH, tempA, tempB, tempC, tempD, tempE, tempF, temp1, temp2, |
|
319 K[34], iData[34], iData[32], iData[27], iData[19], iData[18]); |
|
320 CSHA512_64( tempF, tempG, tempH, tempA, tempB, tempC, tempD, tempE, temp1, temp2, |
|
321 K[35], iData[35], iData[33], iData[28], iData[20], iData[19]); |
|
322 CSHA512_64( tempE, tempF, tempG, tempH, tempA, tempB, tempC, tempD, temp1, temp2, |
|
323 K[36], iData[36], iData[34], iData[29], iData[21], iData[20]); |
|
324 CSHA512_64( tempD, tempE, tempF, tempG, tempH, tempA, tempB, tempC, temp1, temp2, |
|
325 K[37], iData[37], iData[35], iData[30], iData[22], iData[21]); |
|
326 CSHA512_64( tempC, tempD, tempE, tempF, tempG, tempH, tempA, tempB, temp1, temp2, |
|
327 K[38], iData[38], iData[36], iData[31], iData[23], iData[22]); |
|
328 CSHA512_64( tempB, tempC, tempD, tempE, tempF, tempG, tempH, tempA, temp1, temp2, |
|
329 K[39], iData[39], iData[37], iData[32], iData[24], iData[23]); |
|
330 |
|
331 CSHA512_64( tempA, tempB, tempC, tempD, tempE, tempF, tempG, tempH, temp1, temp2, |
|
332 K[40], iData[40], iData[38], iData[33], iData[25], iData[24]); |
|
333 CSHA512_64( tempH, tempA, tempB, tempC, tempD, tempE, tempF, tempG, temp1, temp2, |
|
334 K[41], iData[41], iData[39], iData[34], iData[26], iData[25]); |
|
335 CSHA512_64( tempG, tempH, tempA, tempB, tempC, tempD, tempE, tempF, temp1, temp2, |
|
336 K[42], iData[42], iData[40], iData[35], iData[27], iData[26]); |
|
337 CSHA512_64( tempF, tempG, tempH, tempA, tempB, tempC, tempD, tempE, temp1, temp2, |
|
338 K[43], iData[43], iData[41], iData[36], iData[28], iData[27]); |
|
339 CSHA512_64( tempE, tempF, tempG, tempH, tempA, tempB, tempC, tempD, temp1, temp2, |
|
340 K[44], iData[44], iData[42], iData[37], iData[29], iData[28]); |
|
341 CSHA512_64( tempD, tempE, tempF, tempG, tempH, tempA, tempB, tempC, temp1, temp2, |
|
342 K[45], iData[45], iData[43], iData[38], iData[30], iData[29]); |
|
343 CSHA512_64( tempC, tempD, tempE, tempF, tempG, tempH, tempA, tempB, temp1, temp2, |
|
344 K[46], iData[46], iData[44], iData[39], iData[31], iData[30]); |
|
345 CSHA512_64( tempB, tempC, tempD, tempE, tempF, tempG, tempH, tempA, temp1, temp2, |
|
346 K[47], iData[47], iData[45], iData[40], iData[32], iData[31]); |
|
347 |
|
348 CSHA512_64( tempA, tempB, tempC, tempD, tempE, tempF, tempG, tempH, temp1, temp2, |
|
349 K[48], iData[48], iData[46], iData[41], iData[33], iData[32]); |
|
350 CSHA512_64( tempH, tempA, tempB, tempC, tempD, tempE, tempF, tempG, temp1, temp2, |
|
351 K[49], iData[49], iData[47], iData[42], iData[34], iData[33]); |
|
352 CSHA512_64( tempG, tempH, tempA, tempB, tempC, tempD, tempE, tempF, temp1, temp2, |
|
353 K[50], iData[50], iData[48], iData[43], iData[35], iData[34]); |
|
354 CSHA512_64( tempF, tempG, tempH, tempA, tempB, tempC, tempD, tempE, temp1, temp2, |
|
355 K[51], iData[51], iData[49], iData[44], iData[36], iData[35]); |
|
356 CSHA512_64( tempE, tempF, tempG, tempH, tempA, tempB, tempC, tempD, temp1, temp2, |
|
357 K[52], iData[52], iData[50], iData[45], iData[37], iData[36]); |
|
358 CSHA512_64( tempD, tempE, tempF, tempG, tempH, tempA, tempB, tempC, temp1, temp2, |
|
359 K[53], iData[53], iData[51], iData[46], iData[38], iData[37]); |
|
360 CSHA512_64( tempC, tempD, tempE, tempF, tempG, tempH, tempA, tempB, temp1, temp2, |
|
361 K[54], iData[54], iData[52], iData[47], iData[39], iData[38]); |
|
362 CSHA512_64( tempB, tempC, tempD, tempE, tempF, tempG, tempH, tempA, temp1, temp2, |
|
363 K[55], iData[55], iData[53], iData[48], iData[40], iData[39]); |
|
364 |
|
365 CSHA512_64( tempA, tempB, tempC, tempD, tempE, tempF, tempG, tempH, temp1, temp2, |
|
366 K[56], iData[56], iData[54], iData[49], iData[41], iData[40]); |
|
367 CSHA512_64( tempH, tempA, tempB, tempC, tempD, tempE, tempF, tempG, temp1, temp2, |
|
368 K[57], iData[57], iData[55], iData[50], iData[42], iData[41]); |
|
369 CSHA512_64( tempG, tempH, tempA, tempB, tempC, tempD, tempE, tempF, temp1, temp2, |
|
370 K[58], iData[58], iData[56], iData[51], iData[43], iData[42]); |
|
371 CSHA512_64( tempF, tempG, tempH, tempA, tempB, tempC, tempD, tempE, temp1, temp2, |
|
372 K[59], iData[59], iData[57], iData[52], iData[44], iData[43]); |
|
373 CSHA512_64( tempE, tempF, tempG, tempH, tempA, tempB, tempC, tempD, temp1, temp2, |
|
374 K[60], iData[60], iData[58], iData[53], iData[45], iData[44]); |
|
375 CSHA512_64( tempD, tempE, tempF, tempG, tempH, tempA, tempB, tempC, temp1, temp2, |
|
376 K[61], iData[61], iData[59], iData[54], iData[46], iData[45]); |
|
377 CSHA512_64( tempC, tempD, tempE, tempF, tempG, tempH, tempA, tempB, temp1, temp2, |
|
378 K[62], iData[62], iData[60], iData[55], iData[47], iData[46]); |
|
379 CSHA512_64( tempB, tempC, tempD, tempE, tempF, tempG, tempH, tempA, temp1, temp2, |
|
380 K[63], iData[63], iData[61], iData[56], iData[48], iData[47]); |
|
381 |
|
382 CSHA512_64( tempA, tempB, tempC, tempD, tempE, tempF, tempG, tempH, temp1, temp2, |
|
383 K[64], iData[64], iData[62], iData[57], iData[49], iData[48]); |
|
384 CSHA512_64( tempH, tempA, tempB, tempC, tempD, tempE, tempF, tempG, temp1, temp2, |
|
385 K[65], iData[65], iData[63], iData[58], iData[50], iData[49]); |
|
386 CSHA512_64( tempG, tempH, tempA, tempB, tempC, tempD, tempE, tempF, temp1, temp2, |
|
387 K[66], iData[66], iData[64], iData[59], iData[51], iData[50]); |
|
388 CSHA512_64( tempF, tempG, tempH, tempA, tempB, tempC, tempD, tempE, temp1, temp2, |
|
389 K[67], iData[67], iData[65], iData[60], iData[52], iData[51]); |
|
390 CSHA512_64( tempE, tempF, tempG, tempH, tempA, tempB, tempC, tempD, temp1, temp2, |
|
391 K[68], iData[68], iData[66], iData[61], iData[53], iData[52]); |
|
392 CSHA512_64( tempD, tempE, tempF, tempG, tempH, tempA, tempB, tempC, temp1, temp2, |
|
393 K[69], iData[69], iData[67], iData[62], iData[54], iData[53]); |
|
394 CSHA512_64( tempC, tempD, tempE, tempF, tempG, tempH, tempA, tempB, temp1, temp2, |
|
395 K[70], iData[70], iData[68], iData[63], iData[55], iData[54]); |
|
396 CSHA512_64( tempB, tempC, tempD, tempE, tempF, tempG, tempH, tempA, temp1, temp2, |
|
397 K[71], iData[71], iData[69], iData[64], iData[56], iData[55]); |
|
398 |
|
399 CSHA512_64( tempA, tempB, tempC, tempD, tempE, tempF, tempG, tempH, temp1, temp2, |
|
400 K[72], iData[72], iData[70], iData[65], iData[57], iData[56]); |
|
401 CSHA512_64( tempH, tempA, tempB, tempC, tempD, tempE, tempF, tempG, temp1, temp2, |
|
402 K[73], iData[73], iData[71], iData[66], iData[58], iData[57]); |
|
403 CSHA512_64( tempG, tempH, tempA, tempB, tempC, tempD, tempE, tempF, temp1, temp2, |
|
404 K[74], iData[74], iData[72], iData[67], iData[59], iData[58]); |
|
405 CSHA512_64( tempF, tempG, tempH, tempA, tempB, tempC, tempD, tempE, temp1, temp2, |
|
406 K[75], iData[75], iData[73], iData[68], iData[60], iData[59]); |
|
407 CSHA512_64( tempE, tempF, tempG, tempH, tempA, tempB, tempC, tempD, temp1, temp2, |
|
408 K[76], iData[76], iData[74], iData[69], iData[61], iData[60]); |
|
409 CSHA512_64( tempD, tempE, tempF, tempG, tempH, tempA, tempB, tempC, temp1, temp2, |
|
410 K[77], iData[77], iData[75], iData[70], iData[62], iData[61]); |
|
411 CSHA512_64( tempC, tempD, tempE, tempF, tempG, tempH, tempA, tempB, temp1, temp2, |
|
412 K[78], iData[78], iData[76], iData[71], iData[63], iData[62]); |
|
413 CSHA512_64( tempB, tempC, tempD, tempE, tempF, tempG, tempH, tempA, temp1, temp2, |
|
414 K[79], iData[79], iData[77], iData[72], iData[64], iData[63]); |
|
415 |
|
416 iA+=tempA; |
|
417 iB+=tempB; |
|
418 iC+=tempC; |
|
419 iD+=tempD; |
|
420 iE+=tempE; |
|
421 iF+=tempF; |
|
422 iG+=tempG; |
|
423 iH+=tempH; |
|
424 |
|
425 iBlockIndex=0; |
|
426 } |
|
427 |
|
428 /** |
|
429 * According to the standard, the message must be padded to an |
|
430 * even 512 bits. The first padding bit must be a '1'. The last |
|
431 * 64 bits represent the length of the original message. All bits |
|
432 * in between should be 0. This helper function will pad the |
|
433 * message according to those rules by filling the iData array |
|
434 * accordingly. |
|
435 */ |
|
436 void CSHA384And512::PadMessage() |
|
437 { |
|
438 const TUint64 padByte = 0x80; |
|
439 |
|
440 if(!(iBlockIndex&0x07)) |
|
441 { |
|
442 iData[iBlockIndex >> 3] = 0; |
|
443 } |
|
444 iData[iBlockIndex >> 3] |= padByte << ((7 - iBlockIndex&0x07) << 3) ; |
|
445 |
|
446 if (iBlockIndex >= (KSHA512BlockSize - 2*sizeof(TUint64))) |
|
447 { |
|
448 if (iBlockIndex < (KSHA512BlockSize - sizeof(TUint64))) |
|
449 iData[(KSHA512BlockSize>>3)-1]=0; |
|
450 Block(); |
|
451 Mem::FillZ(iData,KSHA512BlockSize); |
|
452 } |
|
453 else |
|
454 { |
|
455 const TUint offset=(iBlockIndex+8)>>3; //+8 to account for the word added in the |
|
456 //switch statement above |
|
457 Mem::FillZ(iData+offset, (KSHA512BlockSize - offset*sizeof(TUint64))); |
|
458 } |
|
459 |
|
460 iData[(KSHA512BlockSize >> 3) - 2] = iNh; |
|
461 iData[(KSHA512BlockSize >> 3) - 1] = iNl; |
|
462 } |
|
463 |
|
464 inline void CSHA384And512::CopyWordToHash(TUint64 aVal, TUint aIndex) |
|
465 { |
|
466 TUint64 value = Make64BitWord(reinterpret_cast<TUint8*>(&aVal)); |
|
467 Mem::Copy(const_cast<TUint8*>(iHash.Ptr())+ (8*aIndex), &value, sizeof(aVal)); |
|
468 } |
|
469 |
|
470 const TDesC8& CSHA384And512::Final() |
|
471 { |
|
472 AddLength(iBlockIndex); |
|
473 PadMessage(); |
|
474 Block(); |
|
475 // |
|
476 // Generate hash value into iHash |
|
477 // |
|
478 CopyWordToHash(iA, 0); |
|
479 CopyWordToHash(iB, 1); |
|
480 CopyWordToHash(iC, 2); |
|
481 CopyWordToHash(iD, 3); |
|
482 CopyWordToHash(iE, 4); |
|
483 CopyWordToHash(iF, 5); |
|
484 CopyWordToHash(iG, 6); |
|
485 CopyWordToHash(iH, 7); |
|
486 |
|
487 return iHash; |
|
488 } |
|
489 |
|
490 void CSHA384And512::RestoreState() |
|
491 { |
|
492 iA = iACopy; |
|
493 iB = iBCopy; |
|
494 iC = iCCopy; |
|
495 iD = iDCopy; |
|
496 iE = iECopy; |
|
497 iF = iFCopy; |
|
498 iG = iGCopy; |
|
499 iH = iHCopy; |
|
500 iNl = iNlCopy; |
|
501 iNh = iNhCopy; |
|
502 iBlockIndex = iBlockIndexCopy; |
|
503 Mem::Copy((TAny*)iData, (TAny*)iDataCopy, KSHA512BlockSize*sizeof(TUint64)); |
|
504 } |
|
505 |
|
506 void CSHA384And512::StoreState() |
|
507 { |
|
508 iACopy = iA; |
|
509 iBCopy = iB; |
|
510 iCCopy = iC; |
|
511 iDCopy = iD; |
|
512 iECopy = iE; |
|
513 iFCopy = iF; |
|
514 iGCopy = iG; |
|
515 iHCopy = iH; |
|
516 iNlCopy = iNl; |
|
517 iNhCopy = iNh; |
|
518 iBlockIndexCopy = iBlockIndex; |
|
519 Mem::Copy((TAny*)iDataCopy, (TAny*)iData, KSHA512BlockSize*sizeof(TUint64)); |
|
520 } |
|
521 |
|
522 // Implemented in hmacimpl.cpp or softwarehashbase.cpp |
|
523 // but required as derived from MHash. No coverage here. |
|
524 #ifdef _BullseyeCoverage |
|
525 #pragma suppress_warnings on |
|
526 #pragma BullseyeCoverage off |
|
527 #pragma suppress_warnings off |
|
528 #endif |