Botan 3.6.1
Crypto and TLS for C&
sha2_64.cpp
Go to the documentation of this file.
1/*
2* SHA-{384,512}
3* (C) 1999-2011,2015 Jack Lloyd
4*
5* Botan is released under the Simplified BSD License (see license.txt)
6*/
7
8#include <botan/internal/sha2_64.h>
9
10#include <botan/internal/bit_ops.h>
11#include <botan/internal/cpuid.h>
12#include <botan/internal/loadstor.h>
13#include <botan/internal/rotate.h>
14#include <botan/internal/sha2_64_f.h>
15#include <botan/internal/stl_util.h>
16
17namespace Botan {
18
19namespace {
20
21std::string sha512_provider() {
22#if defined(BOTAN_HAS_SHA2_64_BMI2)
23 if(CPUID::has_bmi2()) {
24 return "bmi2";
25 }
26#endif
27
28#if defined(BOTAN_HAS_SHA2_64_ARMV8)
29 if(CPUID::has_arm_sha2_512()) {
30 return "armv8";
31 }
32#endif
33
34 return "base";
35}
36
37} // namespace
38
39/*
40* SHA-{384,512} Compression Function
41*/
42//static
43void SHA_512::compress_digest(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
44#if defined(BOTAN_HAS_SHA2_64_BMI2)
45 if(CPUID::has_bmi2()) {
46 return compress_digest_bmi2(digest, input, blocks);
47 }
48#endif
49
50#if defined(BOTAN_HAS_SHA2_64_ARMV8)
51 if(CPUID::has_arm_sha2_512()) {
52 return compress_digest_armv8(digest, input, blocks);
53 }
54#endif
55
56 uint64_t A = digest[0], B = digest[1], C = digest[2], D = digest[3], E = digest[4], F = digest[5], G = digest[6],
57 H = digest[7];
58
59 std::array<uint64_t, 16> W;
60
61 BufferSlicer in(input);
62
63 for(size_t i = 0; i != blocks; ++i) {
64 load_be(W, in.take<block_bytes>());
65
66 // clang-format off
67
68 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x428A2F98D728AE22);
69 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x7137449123EF65CD);
70 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0xB5C0FBCFEC4D3B2F);
71 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0xE9B5DBA58189DBBC);
72 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x3956C25BF348B538);
73 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x59F111F1B605D019);
74 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x923F82A4AF194F9B);
75 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0xAB1C5ED5DA6D8118);
76 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0xD807AA98A3030242);
77 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0x12835B0145706FBE);
78 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0x243185BE4EE4B28C);
79 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0x550C7DC3D5FFB4E2);
80 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0x72BE5D74F27B896F);
81 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0x80DEB1FE3B1696B1);
82 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0x9BDC06A725C71235);
83 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0xC19BF174CF692694);
84 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0xE49B69C19EF14AD2);
85 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0xEFBE4786384F25E3);
86 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x0FC19DC68B8CD5B5);
87 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x240CA1CC77AC9C65);
88 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x2DE92C6F592B0275);
89 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x4A7484AA6EA6E483);
90 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x5CB0A9DCBD41FBD4);
91 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x76F988DA831153B5);
92 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0x983E5152EE66DFAB);
93 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0xA831C66D2DB43210);
94 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0xB00327C898FB213F);
95 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0xBF597FC7BEEF0EE4);
96 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0xC6E00BF33DA88FC2);
97 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xD5A79147930AA725);
98 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0x06CA6351E003826F);
99 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0x142929670A0E6E70);
100 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x27B70A8546D22FFC);
101 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x2E1B21385C26C926);
102 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x4D2C6DFC5AC42AED);
103 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x53380D139D95B3DF);
104 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x650A73548BAF63DE);
105 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x766A0ABB3C77B2A8);
106 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x81C2C92E47EDAEE6);
107 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x92722C851482353B);
108 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0xA2BFE8A14CF10364);
109 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0xA81A664BBC423001);
110 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0xC24B8B70D0F89791);
111 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0xC76C51A30654BE30);
112 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0xD192E819D6EF5218);
113 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xD69906245565A910);
114 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0xF40E35855771202A);
115 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0x106AA07032BBD1B8);
116 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x19A4C116B8D2D0C8);
117 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x1E376C085141AB53);
118 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x2748774CDF8EEB99);
119 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x34B0BCB5E19B48A8);
120 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x391C0CB3C5C95A63);
121 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x4ED8AA4AE3418ACB);
122 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x5B9CCA4F7763E373);
123 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x682E6FF3D6B2B8A3);
124 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0x748F82EE5DEFB2FC);
125 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0x78A5636F43172F60);
126 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0x84C87814A1F0AB72);
127 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0x8CC702081A6439EC);
128 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0x90BEFFFA23631E28);
129 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xA4506CEBDE82BDE9);
130 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0xBEF9A3F7B2C67915);
131 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0xC67178F2E372532B);
132 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0xCA273ECEEA26619C);
133 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0xD186B8C721C0C207);
134 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0xEADA7DD6CDE0EB1E);
135 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0xF57D4F7FEE6ED178);
136 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x06F067AA72176FBA);
137 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x0A637DC5A2C898A6);
138 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x113F9804BEF90DAE);
139 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x1B710B35131C471B);
140 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0x28DB77F523047D84);
141 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0x32CAAB7B40C72493);
142 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0x3C9EBE0A15C9BEBC);
143 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0x431D67C49C100D4C);
144 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0x4CC5D4BECB3E42B6);
145 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0x597F299CFC657E2A);
146 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0x5FCB6FAB3AD6FAEC);
147 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0x6C44198C4A475817);
148
149 // clang-format on
150
151 A = (digest[0] += A);
152 B = (digest[1] += B);
153 C = (digest[2] += C);
154 D = (digest[3] += D);
155 E = (digest[4] += E);
156 F = (digest[5] += F);
157 G = (digest[6] += G);
158 H = (digest[7] += H);
159 }
160}
161
162std::string SHA_512_256::provider() const {
163 return sha512_provider();
164}
165
166std::string SHA_384::provider() const {
167 return sha512_provider();
168}
169
170std::string SHA_512::provider() const {
171 return sha512_provider();
172}
173
174void SHA_512_256::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
175 SHA_512::compress_digest(digest, input, blocks);
176}
177
178void SHA_384::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
179 SHA_512::compress_digest(digest, input, blocks);
180}
181
182void SHA_512::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
183 SHA_512::compress_digest(digest, input, blocks);
184}
185
187 digest.assign({0x22312194FC2BF72C,
188 0x9F555FA3C84C64C2,
189 0x2393B86B6F53B151,
190 0x963877195940EABD,
191 0x96283EE2A88EFFE3,
192 0xBE5E1E2553863992,
193 0x2B0199FC2C85B8AA,
194 0x0EB72DDC81C52CA2});
195}
196
198 digest.assign({0xCBBB9D5DC1059ED8,
199 0x629A292A367CD507,
200 0x9159015A3070DD17,
201 0x152FECD8F70E5939,
202 0x67332667FFC00B31,
203 0x8EB44A8768581511,
204 0xDB0C2E0D64F98FA7,
205 0x47B5481DBEFA4FA4});
206}
207
209 digest.assign({0x6A09E667F3BCC908,
210 0xBB67AE8584CAA73B,
211 0x3C6EF372FE94F82B,
212 0xA54FF53A5F1D36F1,
213 0x510E527FADE682D1,
214 0x9B05688C2B3E6C1F,
215 0x1F83D9ABFB41BD6B,
216 0x5BE0CD19137E2179});
217}
218
219std::unique_ptr<HashFunction> SHA_384::new_object() const {
220 return std::make_unique<SHA_384>();
221}
222
223std::unique_ptr<HashFunction> SHA_512::new_object() const {
224 return std::make_unique<SHA_512>();
225}
226
227std::unique_ptr<HashFunction> SHA_512_256::new_object() const {
228 return std::make_unique<SHA_512_256>();
229}
230
231std::unique_ptr<HashFunction> SHA_384::copy_state() const {
232 return std::make_unique<SHA_384>(*this);
233}
234
235std::unique_ptr<HashFunction> SHA_512::copy_state() const {
236 return std::make_unique<SHA_512>(*this);
237}
238
239std::unique_ptr<HashFunction> SHA_512_256::copy_state() const {
240 return std::make_unique<SHA_512_256>(*this);
241}
242
243void SHA_384::add_data(std::span<const uint8_t> input) {
244 m_md.update(input);
245}
246
247void SHA_512::add_data(std::span<const uint8_t> input) {
248 m_md.update(input);
249}
250
251void SHA_512_256::add_data(std::span<const uint8_t> input) {
252 m_md.update(input);
253}
254
255void SHA_384::final_result(std::span<uint8_t> output) {
256 m_md.final(output);
257}
258
259void SHA_512::final_result(std::span<uint8_t> output) {
260 m_md.final(output);
261}
262
263void SHA_512_256::final_result(std::span<uint8_t> output) {
264 m_md.final(output);
265}
266
267} // namespace Botan
std::span< const uint8_t > take(const size_t count)
Definition stl_util.h:98
std::unique_ptr< HashFunction > new_object() const override
Definition sha2_64.cpp:219
std::unique_ptr< HashFunction > copy_state() const override
Definition sha2_64.cpp:231
secure_vector< uint64_t > digest_type
Definition sha2_64.h:20
std::string provider() const override
Definition sha2_64.cpp:166
static void init(digest_type &digest)
Definition sha2_64.cpp:197
static void compress_n(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
Definition sha2_64.cpp:178
secure_vector< uint64_t > digest_type
Definition sha2_64.h:111
std::string provider() const override
Definition sha2_64.cpp:162
std::unique_ptr< HashFunction > copy_state() const override
Definition sha2_64.cpp:239
std::unique_ptr< HashFunction > new_object() const override
Definition sha2_64.cpp:227
static void init(digest_type &digest)
Definition sha2_64.cpp:186
static void compress_n(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
Definition sha2_64.cpp:174
static void compress_n(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
Definition sha2_64.cpp:182
std::unique_ptr< HashFunction > new_object() const override
Definition sha2_64.cpp:223
static constexpr size_t block_bytes
Definition sha2_64.h:64
std::string provider() const override
Definition sha2_64.cpp:170
static void compress_digest_bmi2(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
static void init(digest_type &digest)
Definition sha2_64.cpp:208
secure_vector< uint64_t > digest_type
Definition sha2_64.h:60
std::unique_ptr< HashFunction > copy_state() const override
Definition sha2_64.cpp:235
static void compress_digest(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
Definition sha2_64.cpp:43
BOTAN_FORCE_INLINE void SHA2_64_F(uint64_t A, uint64_t B, uint64_t C, uint64_t &D, uint64_t E, uint64_t F, uint64_t G, uint64_t &H, uint64_t &M1, uint64_t M2, uint64_t M3, uint64_t M4, uint64_t magic)
Definition sha2_64_f.h:19
constexpr auto load_be(ParamTs &&... params)
Definition loadstor.h:530