ripemd.c 15 KB


  1. /* ripemd.c
  2. *
  3. * Copyright (C) 2006-2015 wolfSSL Inc.
  4. *
  5. * This file is part of wolfSSL. (formerly known as CyaSSL)
  6. *
  7. * wolfSSL is free software; you can redistribute it and/or modify
  8. * it under the terms of the GNU General Public License as published by
  9. * the Free Software Foundation; either version 2 of the License, or
  10. * (at your option) any later version.
  11. *
  12. * wolfSSL is distributed in the hope that it will be useful,
  13. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  15. * GNU General Public License for more details.
  16. *
  17. * You should have received a copy of the GNU General Public License
  18. * along with this program; if not, write to the Free Software
  19. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA
  20. */
  21. #ifdef HAVE_CONFIG_H
  22. #include <config.h>
  23. #endif
  24. #include <wolfssl/wolfcrypt/settings.h>
  25. #ifdef WOLFSSL_RIPEMD
  26. #include <wolfssl/wolfcrypt/ripemd.h>
  27. #ifdef NO_INLINE
  28. #include <wolfssl/wolfcrypt/misc.h>
  29. #else
  30. #include <wolfcrypt/src/misc.c>
  31. #endif
  32. #ifndef WOLFSSL_HAVE_MIN
  33. #define WOLFSSL_HAVE_MIN
  34. static INLINE word32 min(word32 a, word32 b)
  35. {
  36. return a > b ? b : a;
  37. }
  38. #endif /* WOLFSSL_HAVE_MIN */
  39. void wc_InitRipeMd(RipeMd* ripemd)
  40. {
  41. ripemd->digest[0] = 0x67452301L;
  42. ripemd->digest[1] = 0xEFCDAB89L;
  43. ripemd->digest[2] = 0x98BADCFEL;
  44. ripemd->digest[3] = 0x10325476L;
  45. ripemd->digest[4] = 0xC3D2E1F0L;
  46. ripemd->buffLen = 0;
  47. ripemd->loLen = 0;
  48. ripemd->hiLen = 0;
  49. }
  50. /* for all */
  51. #define F(x, y, z) (x ^ y ^ z)
  52. #define G(x, y, z) (z ^ (x & (y^z)))
  53. #define H(x, y, z) (z ^ (x | ~y))
  54. #define I(x, y, z) (y ^ (z & (x^y)))
  55. #define J(x, y, z) (x ^ (y | ~z))
  56. #define k0 0
  57. #define k1 0x5a827999
  58. #define k2 0x6ed9eba1
  59. #define k3 0x8f1bbcdc
  60. #define k4 0xa953fd4e
  61. #define k5 0x50a28be6
  62. #define k6 0x5c4dd124
  63. #define k7 0x6d703ef3
  64. #define k8 0x7a6d76e9
  65. #define k9 0
  66. /* for 160 and 320 */
  67. #define Subround(f, a, b, c, d, e, x, s, k) \
  68. a += f(b, c, d) + x + k;\
  69. a = rotlFixed((word32)a, s) + e;\
  70. c = rotlFixed((word32)c, 10U)
  71. static void Transform(RipeMd* ripemd)
  72. {
  73. word32 a1, b1, c1, d1, e1, a2, b2, c2, d2, e2;
  74. a1 = a2 = ripemd->digest[0];
  75. b1 = b2 = ripemd->digest[1];
  76. c1 = c2 = ripemd->digest[2];
  77. d1 = d2 = ripemd->digest[3];
  78. e1 = e2 = ripemd->digest[4];
  79. Subround(F, a1, b1, c1, d1, e1, ripemd->buffer[ 0], 11, k0);
  80. Subround(F, e1, a1, b1, c1, d1, ripemd->buffer[ 1], 14, k0);
  81. Subround(F, d1, e1, a1, b1, c1, ripemd->buffer[ 2], 15, k0);
  82. Subround(F, c1, d1, e1, a1, b1, ripemd->buffer[ 3], 12, k0);
  83. Subround(F, b1, c1, d1, e1, a1, ripemd->buffer[ 4], 5, k0);
  84. Subround(F, a1, b1, c1, d1, e1, ripemd->buffer[ 5], 8, k0);
  85. Subround(F, e1, a1, b1, c1, d1, ripemd->buffer[ 6], 7, k0);
  86. Subround(F, d1, e1, a1, b1, c1, ripemd->buffer[ 7], 9, k0);
  87. Subround(F, c1, d1, e1, a1, b1, ripemd->buffer[ 8], 11, k0);
  88. Subround(F, b1, c1, d1, e1, a1, ripemd->buffer[ 9], 13, k0);
  89. Subround(F, a1, b1, c1, d1, e1, ripemd->buffer[10], 14, k0);
  90. Subround(F, e1, a1, b1, c1, d1, ripemd->buffer[11], 15, k0);
  91. Subround(F, d1, e1, a1, b1, c1, ripemd->buffer[12], 6, k0);
  92. Subround(F, c1, d1, e1, a1, b1, ripemd->buffer[13], 7, k0);
  93. Subround(F, b1, c1, d1, e1, a1, ripemd->buffer[14], 9, k0);
  94. Subround(F, a1, b1, c1, d1, e1, ripemd->buffer[15], 8, k0);
  95. Subround(G, e1, a1, b1, c1, d1, ripemd->buffer[ 7], 7, k1);
  96. Subround(G, d1, e1, a1, b1, c1, ripemd->buffer[ 4], 6, k1);
  97. Subround(G, c1, d1, e1, a1, b1, ripemd->buffer[13], 8, k1);
  98. Subround(G, b1, c1, d1, e1, a1, ripemd->buffer[ 1], 13, k1);
  99. Subround(G, a1, b1, c1, d1, e1, ripemd->buffer[10], 11, k1);
  100. Subround(G, e1, a1, b1, c1, d1, ripemd->buffer[ 6], 9, k1);
  101. Subround(G, d1, e1, a1, b1, c1, ripemd->buffer[15], 7, k1);
  102. Subround(G, c1, d1, e1, a1, b1, ripemd->buffer[ 3], 15, k1);
  103. Subround(G, b1, c1, d1, e1, a1, ripemd->buffer[12], 7, k1);
  104. Subround(G, a1, b1, c1, d1, e1, ripemd->buffer[ 0], 12, k1);
  105. Subround(G, e1, a1, b1, c1, d1, ripemd->buffer[ 9], 15, k1);
  106. Subround(G, d1, e1, a1, b1, c1, ripemd->buffer[ 5], 9, k1);
  107. Subround(G, c1, d1, e1, a1, b1, ripemd->buffer[ 2], 11, k1);
  108. Subround(G, b1, c1, d1, e1, a1, ripemd->buffer[14], 7, k1);
  109. Subround(G, a1, b1, c1, d1, e1, ripemd->buffer[11], 13, k1);
  110. Subround(G, e1, a1, b1, c1, d1, ripemd->buffer[ 8], 12, k1);
  111. Subround(H, d1, e1, a1, b1, c1, ripemd->buffer[ 3], 11, k2);
  112. Subround(H, c1, d1, e1, a1, b1, ripemd->buffer[10], 13, k2);
  113. Subround(H, b1, c1, d1, e1, a1, ripemd->buffer[14], 6, k2);
  114. Subround(H, a1, b1, c1, d1, e1, ripemd->buffer[ 4], 7, k2);
  115. Subround(H, e1, a1, b1, c1, d1, ripemd->buffer[ 9], 14, k2);
  116. Subround(H, d1, e1, a1, b1, c1, ripemd->buffer[15], 9, k2);
  117. Subround(H, c1, d1, e1, a1, b1, ripemd->buffer[ 8], 13, k2);
  118. Subround(H, b1, c1, d1, e1, a1, ripemd->buffer[ 1], 15, k2);
  119. Subround(H, a1, b1, c1, d1, e1, ripemd->buffer[ 2], 14, k2);
  120. Subround(H, e1, a1, b1, c1, d1, ripemd->buffer[ 7], 8, k2);
  121. Subround(H, d1, e1, a1, b1, c1, ripemd->buffer[ 0], 13, k2);
  122. Subround(H, c1, d1, e1, a1, b1, ripemd->buffer[ 6], 6, k2);
  123. Subround(H, b1, c1, d1, e1, a1, ripemd->buffer[13], 5, k2);
  124. Subround(H, a1, b1, c1, d1, e1, ripemd->buffer[11], 12, k2);
  125. Subround(H, e1, a1, b1, c1, d1, ripemd->buffer[ 5], 7, k2);
  126. Subround(H, d1, e1, a1, b1, c1, ripemd->buffer[12], 5, k2);
  127. Subround(I, c1, d1, e1, a1, b1, ripemd->buffer[ 1], 11, k3);
  128. Subround(I, b1, c1, d1, e1, a1, ripemd->buffer[ 9], 12, k3);
  129. Subround(I, a1, b1, c1, d1, e1, ripemd->buffer[11], 14, k3);
  130. Subround(I, e1, a1, b1, c1, d1, ripemd->buffer[10], 15, k3);
  131. Subround(I, d1, e1, a1, b1, c1, ripemd->buffer[ 0], 14, k3);
  132. Subround(I, c1, d1, e1, a1, b1, ripemd->buffer[ 8], 15, k3);
  133. Subround(I, b1, c1, d1, e1, a1, ripemd->buffer[12], 9, k3);
  134. Subround(I, a1, b1, c1, d1, e1, ripemd->buffer[ 4], 8, k3);
  135. Subround(I, e1, a1, b1, c1, d1, ripemd->buffer[13], 9, k3);
  136. Subround(I, d1, e1, a1, b1, c1, ripemd->buffer[ 3], 14, k3);
  137. Subround(I, c1, d1, e1, a1, b1, ripemd->buffer[ 7], 5, k3);
  138. Subround(I, b1, c1, d1, e1, a1, ripemd->buffer[15], 6, k3);
  139. Subround(I, a1, b1, c1, d1, e1, ripemd->buffer[14], 8, k3);
  140. Subround(I, e1, a1, b1, c1, d1, ripemd->buffer[ 5], 6, k3);
  141. Subround(I, d1, e1, a1, b1, c1, ripemd->buffer[ 6], 5, k3);
  142. Subround(I, c1, d1, e1, a1, b1, ripemd->buffer[ 2], 12, k3);
  143. Subround(J, b1, c1, d1, e1, a1, ripemd->buffer[ 4], 9, k4);
  144. Subround(J, a1, b1, c1, d1, e1, ripemd->buffer[ 0], 15, k4);
  145. Subround(J, e1, a1, b1, c1, d1, ripemd->buffer[ 5], 5, k4);
  146. Subround(J, d1, e1, a1, b1, c1, ripemd->buffer[ 9], 11, k4);
  147. Subround(J, c1, d1, e1, a1, b1, ripemd->buffer[ 7], 6, k4);
  148. Subround(J, b1, c1, d1, e1, a1, ripemd->buffer[12], 8, k4);
  149. Subround(J, a1, b1, c1, d1, e1, ripemd->buffer[ 2], 13, k4);
  150. Subround(J, e1, a1, b1, c1, d1, ripemd->buffer[10], 12, k4);
  151. Subround(J, d1, e1, a1, b1, c1, ripemd->buffer[14], 5, k4);
  152. Subround(J, c1, d1, e1, a1, b1, ripemd->buffer[ 1], 12, k4);
  153. Subround(J, b1, c1, d1, e1, a1, ripemd->buffer[ 3], 13, k4);
  154. Subround(J, a1, b1, c1, d1, e1, ripemd->buffer[ 8], 14, k4);
  155. Subround(J, e1, a1, b1, c1, d1, ripemd->buffer[11], 11, k4);
  156. Subround(J, d1, e1, a1, b1, c1, ripemd->buffer[ 6], 8, k4);
  157. Subround(J, c1, d1, e1, a1, b1, ripemd->buffer[15], 5, k4);
  158. Subround(J, b1, c1, d1, e1, a1, ripemd->buffer[13], 6, k4);
  159. Subround(J, a2, b2, c2, d2, e2, ripemd->buffer[ 5], 8, k5);
  160. Subround(J, e2, a2, b2, c2, d2, ripemd->buffer[14], 9, k5);
  161. Subround(J, d2, e2, a2, b2, c2, ripemd->buffer[ 7], 9, k5);
  162. Subround(J, c2, d2, e2, a2, b2, ripemd->buffer[ 0], 11, k5);
  163. Subround(J, b2, c2, d2, e2, a2, ripemd->buffer[ 9], 13, k5);
  164. Subround(J, a2, b2, c2, d2, e2, ripemd->buffer[ 2], 15, k5);
  165. Subround(J, e2, a2, b2, c2, d2, ripemd->buffer[11], 15, k5);
  166. Subround(J, d2, e2, a2, b2, c2, ripemd->buffer[ 4], 5, k5);
  167. Subround(J, c2, d2, e2, a2, b2, ripemd->buffer[13], 7, k5);
  168. Subround(J, b2, c2, d2, e2, a2, ripemd->buffer[ 6], 7, k5);
  169. Subround(J, a2, b2, c2, d2, e2, ripemd->buffer[15], 8, k5);
  170. Subround(J, e2, a2, b2, c2, d2, ripemd->buffer[ 8], 11, k5);
  171. Subround(J, d2, e2, a2, b2, c2, ripemd->buffer[ 1], 14, k5);
  172. Subround(J, c2, d2, e2, a2, b2, ripemd->buffer[10], 14, k5);
  173. Subround(J, b2, c2, d2, e2, a2, ripemd->buffer[ 3], 12, k5);
  174. Subround(J, a2, b2, c2, d2, e2, ripemd->buffer[12], 6, k5);
  175. Subround(I, e2, a2, b2, c2, d2, ripemd->buffer[ 6], 9, k6);
  176. Subround(I, d2, e2, a2, b2, c2, ripemd->buffer[11], 13, k6);
  177. Subround(I, c2, d2, e2, a2, b2, ripemd->buffer[ 3], 15, k6);
  178. Subround(I, b2, c2, d2, e2, a2, ripemd->buffer[ 7], 7, k6);
  179. Subround(I, a2, b2, c2, d2, e2, ripemd->buffer[ 0], 12, k6);
  180. Subround(I, e2, a2, b2, c2, d2, ripemd->buffer[13], 8, k6);
  181. Subround(I, d2, e2, a2, b2, c2, ripemd->buffer[ 5], 9, k6);
  182. Subround(I, c2, d2, e2, a2, b2, ripemd->buffer[10], 11, k6);
  183. Subround(I, b2, c2, d2, e2, a2, ripemd->buffer[14], 7, k6);
  184. Subround(I, a2, b2, c2, d2, e2, ripemd->buffer[15], 7, k6);
  185. Subround(I, e2, a2, b2, c2, d2, ripemd->buffer[ 8], 12, k6);
  186. Subround(I, d2, e2, a2, b2, c2, ripemd->buffer[12], 7, k6);
  187. Subround(I, c2, d2, e2, a2, b2, ripemd->buffer[ 4], 6, k6);
  188. Subround(I, b2, c2, d2, e2, a2, ripemd->buffer[ 9], 15, k6);
  189. Subround(I, a2, b2, c2, d2, e2, ripemd->buffer[ 1], 13, k6);
  190. Subround(I, e2, a2, b2, c2, d2, ripemd->buffer[ 2], 11, k6);
  191. Subround(H, d2, e2, a2, b2, c2, ripemd->buffer[15], 9, k7);
  192. Subround(H, c2, d2, e2, a2, b2, ripemd->buffer[ 5], 7, k7);
  193. Subround(H, b2, c2, d2, e2, a2, ripemd->buffer[ 1], 15, k7);
  194. Subround(H, a2, b2, c2, d2, e2, ripemd->buffer[ 3], 11, k7);
  195. Subround(H, e2, a2, b2, c2, d2, ripemd->buffer[ 7], 8, k7);
  196. Subround(H, d2, e2, a2, b2, c2, ripemd->buffer[14], 6, k7);
  197. Subround(H, c2, d2, e2, a2, b2, ripemd->buffer[ 6], 6, k7);
  198. Subround(H, b2, c2, d2, e2, a2, ripemd->buffer[ 9], 14, k7);
  199. Subround(H, a2, b2, c2, d2, e2, ripemd->buffer[11], 12, k7);
  200. Subround(H, e2, a2, b2, c2, d2, ripemd->buffer[ 8], 13, k7);
  201. Subround(H, d2, e2, a2, b2, c2, ripemd->buffer[12], 5, k7);
  202. Subround(H, c2, d2, e2, a2, b2, ripemd->buffer[ 2], 14, k7);
  203. Subround(H, b2, c2, d2, e2, a2, ripemd->buffer[10], 13, k7);
  204. Subround(H, a2, b2, c2, d2, e2, ripemd->buffer[ 0], 13, k7);
  205. Subround(H, e2, a2, b2, c2, d2, ripemd->buffer[ 4], 7, k7);
  206. Subround(H, d2, e2, a2, b2, c2, ripemd->buffer[13], 5, k7);
  207. Subround(G, c2, d2, e2, a2, b2, ripemd->buffer[ 8], 15, k8);
  208. Subround(G, b2, c2, d2, e2, a2, ripemd->buffer[ 6], 5, k8);
  209. Subround(G, a2, b2, c2, d2, e2, ripemd->buffer[ 4], 8, k8);
  210. Subround(G, e2, a2, b2, c2, d2, ripemd->buffer[ 1], 11, k8);
  211. Subround(G, d2, e2, a2, b2, c2, ripemd->buffer[ 3], 14, k8);
  212. Subround(G, c2, d2, e2, a2, b2, ripemd->buffer[11], 14, k8);
  213. Subround(G, b2, c2, d2, e2, a2, ripemd->buffer[15], 6, k8);
  214. Subround(G, a2, b2, c2, d2, e2, ripemd->buffer[ 0], 14, k8);
  215. Subround(G, e2, a2, b2, c2, d2, ripemd->buffer[ 5], 6, k8);
  216. Subround(G, d2, e2, a2, b2, c2, ripemd->buffer[12], 9, k8);
  217. Subround(G, c2, d2, e2, a2, b2, ripemd->buffer[ 2], 12, k8);
  218. Subround(G, b2, c2, d2, e2, a2, ripemd->buffer[13], 9, k8);
  219. Subround(G, a2, b2, c2, d2, e2, ripemd->buffer[ 9], 12, k8);
  220. Subround(G, e2, a2, b2, c2, d2, ripemd->buffer[ 7], 5, k8);
  221. Subround(G, d2, e2, a2, b2, c2, ripemd->buffer[10], 15, k8);
  222. Subround(G, c2, d2, e2, a2, b2, ripemd->buffer[14], 8, k8);
  223. Subround(F, b2, c2, d2, e2, a2, ripemd->buffer[12], 8, k9);
  224. Subround(F, a2, b2, c2, d2, e2, ripemd->buffer[15], 5, k9);
  225. Subround(F, e2, a2, b2, c2, d2, ripemd->buffer[10], 12, k9);
  226. Subround(F, d2, e2, a2, b2, c2, ripemd->buffer[ 4], 9, k9);
  227. Subround(F, c2, d2, e2, a2, b2, ripemd->buffer[ 1], 12, k9);
  228. Subround(F, b2, c2, d2, e2, a2, ripemd->buffer[ 5], 5, k9);
  229. Subround(F, a2, b2, c2, d2, e2, ripemd->buffer[ 8], 14, k9);
  230. Subround(F, e2, a2, b2, c2, d2, ripemd->buffer[ 7], 6, k9);
  231. Subround(F, d2, e2, a2, b2, c2, ripemd->buffer[ 6], 8, k9);
  232. Subround(F, c2, d2, e2, a2, b2, ripemd->buffer[ 2], 13, k9);
  233. Subround(F, b2, c2, d2, e2, a2, ripemd->buffer[13], 6, k9);
  234. Subround(F, a2, b2, c2, d2, e2, ripemd->buffer[14], 5, k9);
  235. Subround(F, e2, a2, b2, c2, d2, ripemd->buffer[ 0], 15, k9);
  236. Subround(F, d2, e2, a2, b2, c2, ripemd->buffer[ 3], 13, k9);
  237. Subround(F, c2, d2, e2, a2, b2, ripemd->buffer[ 9], 11, k9);
  238. Subround(F, b2, c2, d2, e2, a2, ripemd->buffer[11], 11, k9);
  239. c1 = ripemd->digest[1] + c1 + d2;
  240. ripemd->digest[1] = ripemd->digest[2] + d1 + e2;
  241. ripemd->digest[2] = ripemd->digest[3] + e1 + a2;
  242. ripemd->digest[3] = ripemd->digest[4] + a1 + b2;
  243. ripemd->digest[4] = ripemd->digest[0] + b1 + c2;
  244. ripemd->digest[0] = c1;
  245. }
  246. static INLINE void AddLength(RipeMd* ripemd, word32 len)
  247. {
  248. word32 tmp = ripemd->loLen;
  249. if ( (ripemd->loLen += len) < tmp)
  250. ripemd->hiLen++; /* carry low to high */
  251. }
  252. void wc_RipeMdUpdate(RipeMd* ripemd, const byte* data, word32 len)
  253. {
  254. /* do block size increments */
  255. byte* local = (byte*)ripemd->buffer;
  256. while (len) {
  257. word32 add = min(len, RIPEMD_BLOCK_SIZE - ripemd->buffLen);
  258. XMEMCPY(&local[ripemd->buffLen], data, add);
  259. ripemd->buffLen += add;
  260. data += add;
  261. len -= add;
  262. if (ripemd->buffLen == RIPEMD_BLOCK_SIZE) {
  263. #ifdef BIG_ENDIAN_ORDER
  264. ByteReverseWords(ripemd->buffer, ripemd->buffer,
  265. RIPEMD_BLOCK_SIZE);
  266. #endif
  267. Transform(ripemd);
  268. AddLength(ripemd, RIPEMD_BLOCK_SIZE);
  269. ripemd->buffLen = 0;
  270. }
  271. }
  272. }
  273. void wc_RipeMdFinal(RipeMd* ripemd, byte* hash)
  274. {
  275. byte* local = (byte*)ripemd->buffer;
  276. AddLength(ripemd, ripemd->buffLen); /* before adding pads */
  277. local[ripemd->buffLen++] = 0x80; /* add 1 */
  278. /* pad with zeros */
  279. if (ripemd->buffLen > RIPEMD_PAD_SIZE) {
  280. XMEMSET(&local[ripemd->buffLen], 0, RIPEMD_BLOCK_SIZE - ripemd->buffLen);
  281. ripemd->buffLen += RIPEMD_BLOCK_SIZE - ripemd->buffLen;
  282. #ifdef BIG_ENDIAN_ORDER
  283. ByteReverseWords(ripemd->buffer, ripemd->buffer, RIPEMD_BLOCK_SIZE);
  284. #endif
  285. Transform(ripemd);
  286. ripemd->buffLen = 0;
  287. }
  288. XMEMSET(&local[ripemd->buffLen], 0, RIPEMD_PAD_SIZE - ripemd->buffLen);
  289. /* put lengths in bits */
  290. ripemd->loLen = ripemd->loLen << 3;
  291. ripemd->hiLen = (ripemd->loLen >> (8*sizeof(ripemd->loLen) - 3)) +
  292. (ripemd->hiLen << 3);
  293. /* store lengths */
  294. #ifdef BIG_ENDIAN_ORDER
  295. ByteReverseWords(ripemd->buffer, ripemd->buffer, RIPEMD_BLOCK_SIZE);
  296. #endif
  297. /* ! length ordering dependent on digest endian type ! */
  298. XMEMCPY(&local[RIPEMD_PAD_SIZE], &ripemd->loLen, sizeof(word32));
  299. XMEMCPY(&local[RIPEMD_PAD_SIZE + sizeof(word32)], &ripemd->hiLen,
  300. sizeof(word32));
  301. Transform(ripemd);
  302. #ifdef BIG_ENDIAN_ORDER
  303. ByteReverseWords(ripemd->digest, ripemd->digest, RIPEMD_DIGEST_SIZE);
  304. #endif
  305. XMEMCPY(hash, ripemd->digest, RIPEMD_DIGEST_SIZE);
  306. wc_InitRipeMd(ripemd); /* reset state */
  307. }
  308. #endif /* WOLFSSL_RIPEMD */