hash.h 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252
  1. /*
  2. * BLAKE2XS - Based on the BLAKE2 reference source code
  3. * Copyright 2016, JP Aumasson <jeanphilippe.aumasson@gmail.com>.
  4. * Copyright 2016, Samuel Neves <sneves@dei.uc.pt>.
  5. */
  6. #define hydro_hash_BLAKE2S_BYTES 32
  7. #define hydro_hash_BLOCKBYTES 64
  8. static const uint32_t hydro_hash_IV[8] = { 0x6A09E667UL, 0xBB67AE85UL,
  9. 0x3C6EF372UL, 0xA54FF53AUL, 0x510E527FUL, 0x9B05688CUL, 0x1F83D9ABUL,
  10. 0x5BE0CD19UL };
  11. static const uint8_t hydro_hash_SIGMA[10][8] = {
  12. { 1, 35, 69, 103, 137, 171, 205, 239 },
  13. { 234, 72, 159, 214, 28, 2, 183, 83 },
  14. { 184, 192, 82, 253, 174, 54, 113, 148 },
  15. { 121, 49, 220, 190, 38, 90, 64, 248 },
  16. { 144, 87, 36, 175, 225, 188, 104, 61 },
  17. { 44, 106, 11, 131, 77, 117, 254, 25 },
  18. { 197, 31, 237, 74, 7, 99, 146, 139 },
  19. { 219, 126, 193, 57, 80, 244, 134, 42 },
  20. { 111, 233, 179, 8, 194, 215, 20, 165 },
  21. { 162, 132, 118, 21, 251, 158, 60, 208 } };
  22. static void hydro_hash_increment_counter(
  23. hydro_hash_state *state, const uint32_t inc)
  24. {
  25. state->t[0] += inc;
  26. state->t[1] += (state->t[0] < inc);
  27. }
  28. #define hydro_hash_G(r, i, a, b, c, d) \
  29. do { \
  30. const uint8_t x = hydro_hash_SIGMA[r][i]; \
  31. a += b + m[x >> 4]; \
  32. d = ROTR32(d ^ a, 16); \
  33. c += d; \
  34. b = ROTR32(b ^ c, 12); \
  35. a += b + m[x & 0xf]; \
  36. d = ROTR32(d ^ a, 8); \
  37. c += d; \
  38. b = ROTR32(b ^ c, 7); \
  39. } while (0)
  40. #define hydro_hash_ROUND(r) \
  41. do { \
  42. hydro_hash_G(r, 0, v[0], v[4], v[8], v[12]); \
  43. hydro_hash_G(r, 1, v[1], v[5], v[9], v[13]); \
  44. hydro_hash_G(r, 2, v[2], v[6], v[10], v[14]); \
  45. hydro_hash_G(r, 3, v[3], v[7], v[11], v[15]); \
  46. hydro_hash_G(r, 4, v[0], v[5], v[10], v[15]); \
  47. hydro_hash_G(r, 5, v[1], v[6], v[11], v[12]); \
  48. hydro_hash_G(r, 6, v[2], v[7], v[8], v[13]); \
  49. hydro_hash_G(r, 7, v[3], v[4], v[9], v[14]); \
  50. } while (0)
  51. static void hydro_hash_hashblock(
  52. hydro_hash_state *state, const uint8_t mb[hydro_hash_BLOCKBYTES])
  53. {
  54. uint32_t m[16];
  55. uint32_t v[16];
  56. int i;
  57. for (i = 0; i < 16; i++) {
  58. m[i] = LOAD32_LE(mb + i * sizeof m[i]);
  59. }
  60. for (i = 0; i < 8; i++) {
  61. v[i] = state->h[i];
  62. }
  63. v[8] = hydro_hash_IV[0];
  64. v[9] = hydro_hash_IV[1];
  65. v[10] = hydro_hash_IV[2];
  66. v[11] = hydro_hash_IV[3];
  67. v[12] = state->t[0] ^ hydro_hash_IV[4];
  68. v[13] = state->t[1] ^ hydro_hash_IV[5];
  69. v[14] = state->f[0] ^ hydro_hash_IV[6];
  70. v[15] = hydro_hash_IV[7];
  71. for (i = 0; i < 10; i++) {
  72. hydro_hash_ROUND(i);
  73. }
  74. for (i = 0; i < 8; i++) {
  75. state->h[i] = state->h[i] ^ v[i] ^ v[i + 8];
  76. }
  77. }
  78. static void hydro_hash_init_params(hydro_hash_state *state)
  79. {
  80. int i;
  81. for (i = 0; i < 8; i++) {
  82. state->h[i] = hydro_hash_IV[i] ^ LOAD32_LE(&state->digest_len + i * 4);
  83. }
  84. memset(state->t, 0, sizeof state->t);
  85. memset(state->f, 0, sizeof state->f);
  86. state->buf_off = 0;
  87. }
  88. static int hydro_hash_blake2s_final(
  89. hydro_hash_state *state, uint8_t *out, size_t out_len)
  90. {
  91. uint8_t buffer[hydro_hash_BLAKE2S_BYTES];
  92. int i;
  93. memset(buffer, 0, sizeof buffer);
  94. if (state->f[0] != 0) {
  95. return -1;
  96. }
  97. state->f[0] = (uint32_t)-1;
  98. hydro_hash_increment_counter(state, state->buf_off);
  99. mem_zero(
  100. state->buf + state->buf_off, hydro_hash_BLOCKBYTES - state->buf_off);
  101. hydro_hash_hashblock(state, state->buf);
  102. for (i = 0; i < 8; i++) {
  103. STORE32_LE(buffer + sizeof(state->h[i]) * i, state->h[i]);
  104. }
  105. mem_cpy(out, buffer, out_len);
  106. return 0;
  107. }
  108. static int hydro_hash_init_with_tweak(hydro_hash_state *state,
  109. const char ctx[hydro_hash_CONTEXTBYTES], uint64_t tweak, const uint8_t *key,
  110. size_t key_len, size_t out_len)
  111. {
  112. if ((key != NULL && (key_len < hydro_hash_KEYBYTES_MIN ||
  113. key_len > hydro_hash_KEYBYTES_MAX)) ||
  114. (key == NULL && key_len > 0)) {
  115. return -1;
  116. }
  117. if (out_len < hydro_hash_BYTES_MIN || out_len > hydro_hash_BYTES_MAX) {
  118. return -1;
  119. }
  120. memset(state, 0, sizeof *state);
  121. memcpy(state->ctx, ctx, sizeof state->ctx);
  122. STORE64_LE(state->tweak, tweak);
  123. state->key_len = (uint8_t)key_len;
  124. state->fanout = 1;
  125. state->depth = 1;
  126. if (out_len > hydro_hash_BLAKE2S_BYTES) {
  127. state->digest_len = hydro_hash_BLAKE2S_BYTES;
  128. STORE16_LE(state->xof_len, (uint16_t)out_len);
  129. } else {
  130. state->digest_len = (uint8_t)out_len;
  131. }
  132. hydro_hash_init_params(state);
  133. if (key != NULL) {
  134. uint8_t block[hydro_hash_BLOCKBYTES];
  135. memset(block, 0, sizeof block);
  136. mem_cpy(block, key, key_len);
  137. hydro_hash_update(state, block, sizeof block);
  138. hydro_memzero(block, sizeof block);
  139. }
  140. return 0;
  141. }
  142. int hydro_hash_init(hydro_hash_state *state,
  143. const char ctx[hydro_hash_CONTEXTBYTES], const uint8_t *key, size_t key_len,
  144. size_t out_len)
  145. {
  146. return hydro_hash_init_with_tweak(state, ctx, 0, key, key_len, out_len);
  147. }
  148. int hydro_hash_update(hydro_hash_state *state, const void *in_, size_t in_len)
  149. {
  150. const uint8_t *in = (const uint8_t *)in_;
  151. size_t left;
  152. size_t ps;
  153. size_t i;
  154. while (in_len > 0) {
  155. left = hydro_hash_BLOCKBYTES - state->buf_off;
  156. if ((ps = in_len) > left) {
  157. ps = left;
  158. }
  159. for (i = 0; i < ps; i++) {
  160. state->buf[state->buf_off + i] = in[i];
  161. }
  162. state->buf_off += (uint8_t)ps;
  163. if (state->buf_off == hydro_hash_BLOCKBYTES) {
  164. hydro_hash_increment_counter(state, hydro_hash_BLOCKBYTES);
  165. hydro_hash_hashblock(state, state->buf);
  166. state->buf_off = 0;
  167. }
  168. in += ps;
  169. in_len -= ps;
  170. }
  171. return 0;
  172. }
  173. int hydro_hash_final(hydro_hash_state *state, uint8_t *out, size_t out_len)
  174. {
  175. uint8_t root[hydro_hash_BLOCKBYTES];
  176. uint32_t i;
  177. uint16_t xof_len;
  178. if (out_len < hydro_hash_BYTES_MIN || out_len > hydro_hash_BYTES_MAX) {
  179. return -1;
  180. }
  181. xof_len = LOAD16_LE(state->xof_len);
  182. if (xof_len == 0) {
  183. if (state->digest_len != out_len) {
  184. return -1;
  185. }
  186. return hydro_hash_blake2s_final(state, out, out_len);
  187. } else if (xof_len != out_len) {
  188. return -1;
  189. }
  190. if (hydro_hash_blake2s_final(state, root, hydro_hash_BLAKE2S_BYTES) != 0) {
  191. return -1;
  192. }
  193. state->key_len = 0;
  194. state->fanout = 0;
  195. state->depth = 0;
  196. STORE32_LE(state->leaf_len, hydro_hash_BLAKE2S_BYTES);
  197. state->inner_len = hydro_hash_BLAKE2S_BYTES;
  198. for (i = 0; out_len > 0; i++) {
  199. const size_t block_size = (out_len < hydro_hash_BLAKE2S_BYTES)
  200. ? out_len
  201. : hydro_hash_BLAKE2S_BYTES;
  202. state->digest_len = (uint8_t)block_size;
  203. STORE32_LE(state->node_offset, i);
  204. hydro_hash_init_params(state);
  205. hydro_hash_update(state, root, hydro_hash_BLAKE2S_BYTES);
  206. if (hydro_hash_blake2s_final(
  207. state, out + i * hydro_hash_BLAKE2S_BYTES, block_size) != 0) {
  208. return -1;
  209. }
  210. out_len -= block_size;
  211. }
  212. return 0;
  213. }
  214. int hydro_hash_hash(uint8_t *out, size_t out_len, const void *in_,
  215. size_t in_len, const char ctx[hydro_hash_CONTEXTBYTES], const uint8_t *key,
  216. size_t key_len)
  217. {
  218. hydro_hash_state st;
  219. const uint8_t * in = (const uint8_t *)in_;
  220. if (hydro_hash_init_with_tweak(&st, ctx, 0, key, key_len, out_len) != 0 ||
  221. hydro_hash_update(&st, in, in_len) != 0 ||
  222. hydro_hash_final(&st, out, out_len) != 0) {
  223. return -1;
  224. }
  225. return 0;
  226. }
  227. void hydro_hash_keygen(uint8_t *key, size_t key_len)
  228. {
  229. randombytes_buf(key, key_len);
  230. }