Botan 3.9.0
Crypto and TLS for C&
sha2_64.cpp
Go to the documentation of this file.
1/*
2* SHA-{384,512}
3* (C) 1999-2011,2015 Jack Lloyd
4*
5* Botan is released under the Simplified BSD License (see license.txt)
6*/
7
8#include <botan/internal/sha2_64.h>
9
10#include <botan/internal/bit_ops.h>
11#include <botan/internal/loadstor.h>
12#include <botan/internal/rotate.h>
13#include <botan/internal/sha2_64_f.h>
14#include <botan/internal/stl_util.h>
15
16#if defined(BOTAN_HAS_CPUID)
17 #include <botan/internal/cpuid.h>
18#endif
19
20namespace Botan {
21
22namespace {
23
24std::string sha512_provider() {
25#if defined(BOTAN_HAS_SHA2_64_X86)
26 if(auto feat = CPUID::check(CPUID::Feature::SHA512)) {
27 return *feat;
28 }
29#endif
30
31#if defined(BOTAN_HAS_SHA2_64_ARMV8)
32 if(auto feat = CPUID::check(CPUID::Feature::SHA2_512)) {
33 return *feat;
34 }
35#endif
36
37#if defined(BOTAN_HAS_SHA2_64_X86_AVX512)
39 return *feat;
40 }
41#endif
42
43#if defined(BOTAN_HAS_SHA2_64_X86_AVX2)
45 return *feat;
46 }
47#endif
48
49 return "base";
50}
51
52} // namespace
53
54/*
55* SHA-{384,512} Compression Function
56*/
57//static
58void SHA_512::compress_digest(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
59#if defined(BOTAN_HAS_SHA2_64_X86)
61 return compress_digest_x86(digest, input, blocks);
62 }
63#endif
64
65#if defined(BOTAN_HAS_SHA2_64_ARMV8)
67 return compress_digest_armv8(digest, input, blocks);
68 }
69#endif
70
71#if defined(BOTAN_HAS_SHA2_64_X86_AVX512)
73 return compress_digest_x86_avx512(digest, input, blocks);
74 }
75#endif
76
77#if defined(BOTAN_HAS_SHA2_64_X86_AVX2)
79 return compress_digest_x86_avx2(digest, input, blocks);
80 }
81#endif
82
83 uint64_t A = digest[0];
84 uint64_t B = digest[1];
85 uint64_t C = digest[2];
86 uint64_t D = digest[3];
87 uint64_t E = digest[4];
88 uint64_t F = digest[5];
89 uint64_t G = digest[6];
90 uint64_t H = digest[7];
91
92 std::array<uint64_t, 16> W{};
93
94 BufferSlicer in(input);
95
96 for(size_t i = 0; i != blocks; ++i) {
97 load_be(W, in.take<block_bytes>());
98
99 // clang-format off
100
101 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x428A2F98D728AE22);
102 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x7137449123EF65CD);
103 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0xB5C0FBCFEC4D3B2F);
104 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0xE9B5DBA58189DBBC);
105 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x3956C25BF348B538);
106 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x59F111F1B605D019);
107 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x923F82A4AF194F9B);
108 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0xAB1C5ED5DA6D8118);
109 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0xD807AA98A3030242);
110 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0x12835B0145706FBE);
111 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0x243185BE4EE4B28C);
112 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0x550C7DC3D5FFB4E2);
113 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0x72BE5D74F27B896F);
114 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0x80DEB1FE3B1696B1);
115 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0x9BDC06A725C71235);
116 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0xC19BF174CF692694);
117 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0xE49B69C19EF14AD2);
118 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0xEFBE4786384F25E3);
119 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x0FC19DC68B8CD5B5);
120 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x240CA1CC77AC9C65);
121 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x2DE92C6F592B0275);
122 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x4A7484AA6EA6E483);
123 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x5CB0A9DCBD41FBD4);
124 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x76F988DA831153B5);
125 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0x983E5152EE66DFAB);
126 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0xA831C66D2DB43210);
127 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0xB00327C898FB213F);
128 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0xBF597FC7BEEF0EE4);
129 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0xC6E00BF33DA88FC2);
130 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xD5A79147930AA725);
131 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0x06CA6351E003826F);
132 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0x142929670A0E6E70);
133 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x27B70A8546D22FFC);
134 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x2E1B21385C26C926);
135 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x4D2C6DFC5AC42AED);
136 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x53380D139D95B3DF);
137 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x650A73548BAF63DE);
138 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x766A0ABB3C77B2A8);
139 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x81C2C92E47EDAEE6);
140 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x92722C851482353B);
141 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0xA2BFE8A14CF10364);
142 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0xA81A664BBC423001);
143 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0xC24B8B70D0F89791);
144 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0xC76C51A30654BE30);
145 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0xD192E819D6EF5218);
146 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xD69906245565A910);
147 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0xF40E35855771202A);
148 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0x106AA07032BBD1B8);
149 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x19A4C116B8D2D0C8);
150 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x1E376C085141AB53);
151 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x2748774CDF8EEB99);
152 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x34B0BCB5E19B48A8);
153 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x391C0CB3C5C95A63);
154 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x4ED8AA4AE3418ACB);
155 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x5B9CCA4F7763E373);
156 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x682E6FF3D6B2B8A3);
157 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0x748F82EE5DEFB2FC);
158 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0x78A5636F43172F60);
159 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0x84C87814A1F0AB72);
160 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0x8CC702081A6439EC);
161 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0x90BEFFFA23631E28);
162 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xA4506CEBDE82BDE9);
163 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0xBEF9A3F7B2C67915);
164 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0xC67178F2E372532B);
165 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0xCA273ECEEA26619C);
166 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0xD186B8C721C0C207);
167 SHA2_64_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0xEADA7DD6CDE0EB1E);
168 SHA2_64_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0xF57D4F7FEE6ED178);
169 SHA2_64_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x06F067AA72176FBA);
170 SHA2_64_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x0A637DC5A2C898A6);
171 SHA2_64_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x113F9804BEF90DAE);
172 SHA2_64_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x1B710B35131C471B);
173 SHA2_64_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0x28DB77F523047D84);
174 SHA2_64_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0x32CAAB7B40C72493);
175 SHA2_64_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0x3C9EBE0A15C9BEBC);
176 SHA2_64_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0x431D67C49C100D4C);
177 SHA2_64_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0x4CC5D4BECB3E42B6);
178 SHA2_64_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0x597F299CFC657E2A);
179 SHA2_64_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0x5FCB6FAB3AD6FAEC);
180 SHA2_64_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0x6C44198C4A475817);
181
182 // clang-format on
183
184 A = (digest[0] += A);
185 B = (digest[1] += B);
186 C = (digest[2] += C);
187 D = (digest[3] += D);
188 E = (digest[4] += E);
189 F = (digest[5] += F);
190 G = (digest[6] += G);
191 H = (digest[7] += H);
192 }
193}
194
195std::string SHA_512_256::provider() const {
196 return sha512_provider();
197}
198
199std::string SHA_384::provider() const {
200 return sha512_provider();
201}
202
203std::string SHA_512::provider() const {
204 return sha512_provider();
205}
206
207void SHA_512_256::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
208 SHA_512::compress_digest(digest, input, blocks);
209}
210
211void SHA_384::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
212 SHA_512::compress_digest(digest, input, blocks);
213}
214
215void SHA_512::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
216 SHA_512::compress_digest(digest, input, blocks);
217}
218
220 digest.assign({0x22312194FC2BF72C,
221 0x9F555FA3C84C64C2,
222 0x2393B86B6F53B151,
223 0x963877195940EABD,
224 0x96283EE2A88EFFE3,
225 0xBE5E1E2553863992,
226 0x2B0199FC2C85B8AA,
227 0x0EB72DDC81C52CA2});
228}
229
231 digest.assign({0xCBBB9D5DC1059ED8,
232 0x629A292A367CD507,
233 0x9159015A3070DD17,
234 0x152FECD8F70E5939,
235 0x67332667FFC00B31,
236 0x8EB44A8768581511,
237 0xDB0C2E0D64F98FA7,
238 0x47B5481DBEFA4FA4});
239}
240
242 digest.assign({0x6A09E667F3BCC908,
243 0xBB67AE8584CAA73B,
244 0x3C6EF372FE94F82B,
245 0xA54FF53A5F1D36F1,
246 0x510E527FADE682D1,
247 0x9B05688C2B3E6C1F,
248 0x1F83D9ABFB41BD6B,
249 0x5BE0CD19137E2179});
250}
251
252std::unique_ptr<HashFunction> SHA_384::new_object() const {
253 return std::make_unique<SHA_384>();
254}
255
256std::unique_ptr<HashFunction> SHA_512::new_object() const {
257 return std::make_unique<SHA_512>();
258}
259
260std::unique_ptr<HashFunction> SHA_512_256::new_object() const {
261 return std::make_unique<SHA_512_256>();
262}
263
264std::unique_ptr<HashFunction> SHA_384::copy_state() const {
265 return std::make_unique<SHA_384>(*this);
266}
267
268std::unique_ptr<HashFunction> SHA_512::copy_state() const {
269 return std::make_unique<SHA_512>(*this);
270}
271
272std::unique_ptr<HashFunction> SHA_512_256::copy_state() const {
273 return std::make_unique<SHA_512_256>(*this);
274}
275
276void SHA_384::add_data(std::span<const uint8_t> input) {
277 m_md.update(input);
278}
279
280void SHA_512::add_data(std::span<const uint8_t> input) {
281 m_md.update(input);
282}
283
284void SHA_512_256::add_data(std::span<const uint8_t> input) {
285 m_md.update(input);
286}
287
288void SHA_384::final_result(std::span<uint8_t> output) {
289 m_md.final(output);
290}
291
292void SHA_512::final_result(std::span<uint8_t> output) {
293 m_md.final(output);
294}
295
296void SHA_512_256::final_result(std::span<uint8_t> output) {
297 m_md.final(output);
298}
299
300} // namespace Botan
std::span< const uint8_t > take(const size_t count)
Definition stl_util.h:90
static std::optional< std::string > check(CPUID::Feature feat)
Definition cpuid.h:67
static bool has(CPUID::Feature feat)
Definition cpuid.h:94
std::unique_ptr< HashFunction > new_object() const override
Definition sha2_64.cpp:252
std::unique_ptr< HashFunction > copy_state() const override
Definition sha2_64.cpp:264
secure_vector< uint64_t > digest_type
Definition sha2_64.h:20
std::string provider() const override
Definition sha2_64.cpp:199
static void init(digest_type &digest)
Definition sha2_64.cpp:230
static void compress_n(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
Definition sha2_64.cpp:211
secure_vector< uint64_t > digest_type
Definition sha2_64.h:119
std::string provider() const override
Definition sha2_64.cpp:195
std::unique_ptr< HashFunction > copy_state() const override
Definition sha2_64.cpp:272
std::unique_ptr< HashFunction > new_object() const override
Definition sha2_64.cpp:260
static void init(digest_type &digest)
Definition sha2_64.cpp:219
static void compress_n(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
Definition sha2_64.cpp:207
static void compress_n(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
Definition sha2_64.cpp:215
std::unique_ptr< HashFunction > new_object() const override
Definition sha2_64.cpp:256
static constexpr size_t block_bytes
Definition sha2_64.h:64
std::string provider() const override
Definition sha2_64.cpp:203
static void init(digest_type &digest)
Definition sha2_64.cpp:241
secure_vector< uint64_t > digest_type
Definition sha2_64.h:60
std::unique_ptr< HashFunction > copy_state() const override
Definition sha2_64.cpp:268
static void compress_digest(digest_type &digest, std::span< const uint8_t > input, size_t blocks)
Definition sha2_64.cpp:58
BOTAN_FORCE_INLINE void SHA2_64_F(uint64_t A, uint64_t B, uint64_t C, uint64_t &D, uint64_t E, uint64_t F, uint64_t G, uint64_t &H, uint64_t &M1, uint64_t M2, uint64_t M3, uint64_t M4, uint64_t magic)
Definition sha2_64_f.h:19
constexpr auto load_be(ParamTs &&... params)
Definition loadstor.h:504