SSL/TLS Library
CyaSSL is SSL/TLS library for embedded systems.
ctaocrypt/src/sha.c@0:9d17e4342598, 2014-04-20 (annotated)
- Committer:
- wolfSSL
- Date:
- Sun Apr 20 12:40:57 2014 +0000
- Revision:
- 0:9d17e4342598
CyaSSL SSL/TLS Library 2.9.4;
Who changed what in which revision?
User | Revision | Line number | New contents of line |
---|---|---|---|
wolfSSL | 0:9d17e4342598 | 1 | /* sha.c |
wolfSSL | 0:9d17e4342598 | 2 | * |
wolfSSL | 0:9d17e4342598 | 3 | * Copyright (C) 2006-2013 wolfSSL Inc. |
wolfSSL | 0:9d17e4342598 | 4 | * |
wolfSSL | 0:9d17e4342598 | 5 | * This file is part of CyaSSL. |
wolfSSL | 0:9d17e4342598 | 6 | * |
wolfSSL | 0:9d17e4342598 | 7 | * CyaSSL is free software; you can redistribute it and/or modify |
wolfSSL | 0:9d17e4342598 | 8 | * it under the terms of the GNU General Public License as published by |
wolfSSL | 0:9d17e4342598 | 9 | * the Free Software Foundation; either version 2 of the License, or |
wolfSSL | 0:9d17e4342598 | 10 | * (at your option) any later version. |
wolfSSL | 0:9d17e4342598 | 11 | * |
wolfSSL | 0:9d17e4342598 | 12 | * CyaSSL is distributed in the hope that it will be useful, |
wolfSSL | 0:9d17e4342598 | 13 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
wolfSSL | 0:9d17e4342598 | 14 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
wolfSSL | 0:9d17e4342598 | 15 | * GNU General Public License for more details. |
wolfSSL | 0:9d17e4342598 | 16 | * |
wolfSSL | 0:9d17e4342598 | 17 | * You should have received a copy of the GNU General Public License |
wolfSSL | 0:9d17e4342598 | 18 | * along with this program; if not, write to the Free Software |
wolfSSL | 0:9d17e4342598 | 19 | * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA |
wolfSSL | 0:9d17e4342598 | 20 | */ |
wolfSSL | 0:9d17e4342598 | 21 | |
wolfSSL | 0:9d17e4342598 | 22 | |
wolfSSL | 0:9d17e4342598 | 23 | #ifdef HAVE_CONFIG_H |
wolfSSL | 0:9d17e4342598 | 24 | #include <config.h> |
wolfSSL | 0:9d17e4342598 | 25 | #endif |
wolfSSL | 0:9d17e4342598 | 26 | |
wolfSSL | 0:9d17e4342598 | 27 | #include <cyassl/ctaocrypt/settings.h> |
wolfSSL | 0:9d17e4342598 | 28 | |
wolfSSL | 0:9d17e4342598 | 29 | #if !defined(NO_SHA) |
wolfSSL | 0:9d17e4342598 | 30 | |
wolfSSL | 0:9d17e4342598 | 31 | #ifdef CYASSL_PIC32MZ_HASH |
wolfSSL | 0:9d17e4342598 | 32 | #define InitSha InitSha_sw |
wolfSSL | 0:9d17e4342598 | 33 | #define ShaUpdate ShaUpdate_sw |
wolfSSL | 0:9d17e4342598 | 34 | #define ShaFinal ShaFinal_sw |
wolfSSL | 0:9d17e4342598 | 35 | #endif |
wolfSSL | 0:9d17e4342598 | 36 | |
wolfSSL | 0:9d17e4342598 | 37 | #ifdef HAVE_FIPS |
wolfSSL | 0:9d17e4342598 | 38 | /* set NO_WRAPPERS before headers, use direct internal f()s not wrappers */ |
wolfSSL | 0:9d17e4342598 | 39 | #define FIPS_NO_WRAPPERS |
wolfSSL | 0:9d17e4342598 | 40 | #endif |
wolfSSL | 0:9d17e4342598 | 41 | |
wolfSSL | 0:9d17e4342598 | 42 | #include <cyassl/ctaocrypt/sha.h> |
wolfSSL | 0:9d17e4342598 | 43 | #ifdef NO_INLINE |
wolfSSL | 0:9d17e4342598 | 44 | #include <cyassl/ctaocrypt/misc.h> |
wolfSSL | 0:9d17e4342598 | 45 | #else |
wolfSSL | 0:9d17e4342598 | 46 | #include <ctaocrypt/src/misc.c> |
wolfSSL | 0:9d17e4342598 | 47 | #endif |
wolfSSL | 0:9d17e4342598 | 48 | |
wolfSSL | 0:9d17e4342598 | 49 | #ifdef FREESCALE_MMCAU |
wolfSSL | 0:9d17e4342598 | 50 | #include "cau_api.h" |
wolfSSL | 0:9d17e4342598 | 51 | #define XTRANSFORM(S,B) cau_sha1_hash_n((B), 1, ((S))->digest) |
wolfSSL | 0:9d17e4342598 | 52 | #else |
wolfSSL | 0:9d17e4342598 | 53 | #define XTRANSFORM(S,B) Transform((S)) |
wolfSSL | 0:9d17e4342598 | 54 | #endif |
wolfSSL | 0:9d17e4342598 | 55 | |
wolfSSL | 0:9d17e4342598 | 56 | |
wolfSSL | 0:9d17e4342598 | 57 | #ifdef STM32F2_HASH |
wolfSSL | 0:9d17e4342598 | 58 | /* |
wolfSSL | 0:9d17e4342598 | 59 | * STM32F2 hardware SHA1 support through the STM32F2 standard peripheral |
wolfSSL | 0:9d17e4342598 | 60 | * library. Documentation located in STM32F2xx Standard Peripheral Library |
wolfSSL | 0:9d17e4342598 | 61 | * document (See note in README). |
wolfSSL | 0:9d17e4342598 | 62 | */ |
wolfSSL | 0:9d17e4342598 | 63 | #include "stm32f2xx.h" |
wolfSSL | 0:9d17e4342598 | 64 | #include "stm32f2xx_hash.h" |
wolfSSL | 0:9d17e4342598 | 65 | |
wolfSSL | 0:9d17e4342598 | 66 | int InitSha(Sha* sha) |
wolfSSL | 0:9d17e4342598 | 67 | { |
wolfSSL | 0:9d17e4342598 | 68 | /* STM32F2 struct notes: |
wolfSSL | 0:9d17e4342598 | 69 | * sha->buffer = first 4 bytes used to hold partial block if needed |
wolfSSL | 0:9d17e4342598 | 70 | * sha->buffLen = num bytes currently stored in sha->buffer |
wolfSSL | 0:9d17e4342598 | 71 | * sha->loLen = num bytes that have been written to STM32 FIFO |
wolfSSL | 0:9d17e4342598 | 72 | */ |
wolfSSL | 0:9d17e4342598 | 73 | XMEMSET(sha->buffer, 0, SHA_REG_SIZE); |
wolfSSL | 0:9d17e4342598 | 74 | sha->buffLen = 0; |
wolfSSL | 0:9d17e4342598 | 75 | sha->loLen = 0; |
wolfSSL | 0:9d17e4342598 | 76 | |
wolfSSL | 0:9d17e4342598 | 77 | /* initialize HASH peripheral */ |
wolfSSL | 0:9d17e4342598 | 78 | HASH_DeInit(); |
wolfSSL | 0:9d17e4342598 | 79 | |
wolfSSL | 0:9d17e4342598 | 80 | /* configure algo used, algo mode, datatype */ |
wolfSSL | 0:9d17e4342598 | 81 | HASH->CR &= ~ (HASH_CR_ALGO | HASH_CR_DATATYPE | HASH_CR_MODE); |
wolfSSL | 0:9d17e4342598 | 82 | HASH->CR |= (HASH_AlgoSelection_SHA1 | HASH_AlgoMode_HASH |
wolfSSL | 0:9d17e4342598 | 83 | | HASH_DataType_8b); |
wolfSSL | 0:9d17e4342598 | 84 | |
wolfSSL | 0:9d17e4342598 | 85 | /* reset HASH processor */ |
wolfSSL | 0:9d17e4342598 | 86 | HASH->CR |= HASH_CR_INIT; |
wolfSSL | 0:9d17e4342598 | 87 | |
wolfSSL | 0:9d17e4342598 | 88 | return 0; |
wolfSSL | 0:9d17e4342598 | 89 | } |
wolfSSL | 0:9d17e4342598 | 90 | |
wolfSSL | 0:9d17e4342598 | 91 | int ShaUpdate(Sha* sha, const byte* data, word32 len) |
wolfSSL | 0:9d17e4342598 | 92 | { |
wolfSSL | 0:9d17e4342598 | 93 | word32 i = 0; |
wolfSSL | 0:9d17e4342598 | 94 | word32 fill = 0; |
wolfSSL | 0:9d17e4342598 | 95 | word32 diff = 0; |
wolfSSL | 0:9d17e4342598 | 96 | |
wolfSSL | 0:9d17e4342598 | 97 | /* if saved partial block is available */ |
wolfSSL | 0:9d17e4342598 | 98 | if (sha->buffLen) { |
wolfSSL | 0:9d17e4342598 | 99 | fill = 4 - sha->buffLen; |
wolfSSL | 0:9d17e4342598 | 100 | |
wolfSSL | 0:9d17e4342598 | 101 | /* if enough data to fill, fill and push to FIFO */ |
wolfSSL | 0:9d17e4342598 | 102 | if (fill <= len) { |
wolfSSL | 0:9d17e4342598 | 103 | XMEMCPY((byte*)sha->buffer + sha->buffLen, data, fill); |
wolfSSL | 0:9d17e4342598 | 104 | HASH_DataIn(*(uint32_t*)sha->buffer); |
wolfSSL | 0:9d17e4342598 | 105 | |
wolfSSL | 0:9d17e4342598 | 106 | data += fill; |
wolfSSL | 0:9d17e4342598 | 107 | len -= fill; |
wolfSSL | 0:9d17e4342598 | 108 | sha->loLen += 4; |
wolfSSL | 0:9d17e4342598 | 109 | sha->buffLen = 0; |
wolfSSL | 0:9d17e4342598 | 110 | } else { |
wolfSSL | 0:9d17e4342598 | 111 | /* append partial to existing stored block */ |
wolfSSL | 0:9d17e4342598 | 112 | XMEMCPY((byte*)sha->buffer + sha->buffLen, data, len); |
wolfSSL | 0:9d17e4342598 | 113 | sha->buffLen += len; |
wolfSSL | 0:9d17e4342598 | 114 | return; |
wolfSSL | 0:9d17e4342598 | 115 | } |
wolfSSL | 0:9d17e4342598 | 116 | } |
wolfSSL | 0:9d17e4342598 | 117 | |
wolfSSL | 0:9d17e4342598 | 118 | /* write input block in the IN FIFO */ |
wolfSSL | 0:9d17e4342598 | 119 | for(i = 0; i < len; i += 4) |
wolfSSL | 0:9d17e4342598 | 120 | { |
wolfSSL | 0:9d17e4342598 | 121 | diff = len - i; |
wolfSSL | 0:9d17e4342598 | 122 | if ( diff < 4) { |
wolfSSL | 0:9d17e4342598 | 123 | /* store incomplete last block, not yet in FIFO */ |
wolfSSL | 0:9d17e4342598 | 124 | XMEMSET(sha->buffer, 0, SHA_REG_SIZE); |
wolfSSL | 0:9d17e4342598 | 125 | XMEMCPY((byte*)sha->buffer, data, diff); |
wolfSSL | 0:9d17e4342598 | 126 | sha->buffLen = diff; |
wolfSSL | 0:9d17e4342598 | 127 | } else { |
wolfSSL | 0:9d17e4342598 | 128 | HASH_DataIn(*(uint32_t*)data); |
wolfSSL | 0:9d17e4342598 | 129 | data+=4; |
wolfSSL | 0:9d17e4342598 | 130 | } |
wolfSSL | 0:9d17e4342598 | 131 | } |
wolfSSL | 0:9d17e4342598 | 132 | |
wolfSSL | 0:9d17e4342598 | 133 | /* keep track of total data length thus far */ |
wolfSSL | 0:9d17e4342598 | 134 | sha->loLen += (len - sha->buffLen); |
wolfSSL | 0:9d17e4342598 | 135 | |
wolfSSL | 0:9d17e4342598 | 136 | return 0; |
wolfSSL | 0:9d17e4342598 | 137 | } |
wolfSSL | 0:9d17e4342598 | 138 | |
wolfSSL | 0:9d17e4342598 | 139 | int ShaFinal(Sha* sha, byte* hash) |
wolfSSL | 0:9d17e4342598 | 140 | { |
wolfSSL | 0:9d17e4342598 | 141 | __IO uint16_t nbvalidbitsdata = 0; |
wolfSSL | 0:9d17e4342598 | 142 | |
wolfSSL | 0:9d17e4342598 | 143 | /* finish reading any trailing bytes into FIFO */ |
wolfSSL | 0:9d17e4342598 | 144 | if (sha->buffLen) { |
wolfSSL | 0:9d17e4342598 | 145 | HASH_DataIn(*(uint32_t*)sha->buffer); |
wolfSSL | 0:9d17e4342598 | 146 | sha->loLen += sha->buffLen; |
wolfSSL | 0:9d17e4342598 | 147 | } |
wolfSSL | 0:9d17e4342598 | 148 | |
wolfSSL | 0:9d17e4342598 | 149 | /* calculate number of valid bits in last word of input data */ |
wolfSSL | 0:9d17e4342598 | 150 | nbvalidbitsdata = 8 * (sha->loLen % SHA_REG_SIZE); |
wolfSSL | 0:9d17e4342598 | 151 | |
wolfSSL | 0:9d17e4342598 | 152 | /* configure number of valid bits in last word of the data */ |
wolfSSL | 0:9d17e4342598 | 153 | HASH_SetLastWordValidBitsNbr(nbvalidbitsdata); |
wolfSSL | 0:9d17e4342598 | 154 | |
wolfSSL | 0:9d17e4342598 | 155 | /* start HASH processor */ |
wolfSSL | 0:9d17e4342598 | 156 | HASH_StartDigest(); |
wolfSSL | 0:9d17e4342598 | 157 | |
wolfSSL | 0:9d17e4342598 | 158 | /* wait until Busy flag == RESET */ |
wolfSSL | 0:9d17e4342598 | 159 | while (HASH_GetFlagStatus(HASH_FLAG_BUSY) != RESET) {} |
wolfSSL | 0:9d17e4342598 | 160 | |
wolfSSL | 0:9d17e4342598 | 161 | /* read message digest */ |
wolfSSL | 0:9d17e4342598 | 162 | sha->digest[0] = HASH->HR[0]; |
wolfSSL | 0:9d17e4342598 | 163 | sha->digest[1] = HASH->HR[1]; |
wolfSSL | 0:9d17e4342598 | 164 | sha->digest[2] = HASH->HR[2]; |
wolfSSL | 0:9d17e4342598 | 165 | sha->digest[3] = HASH->HR[3]; |
wolfSSL | 0:9d17e4342598 | 166 | sha->digest[4] = HASH->HR[4]; |
wolfSSL | 0:9d17e4342598 | 167 | |
wolfSSL | 0:9d17e4342598 | 168 | ByteReverseWords(sha->digest, sha->digest, SHA_DIGEST_SIZE); |
wolfSSL | 0:9d17e4342598 | 169 | |
wolfSSL | 0:9d17e4342598 | 170 | XMEMCPY(hash, sha->digest, SHA_DIGEST_SIZE); |
wolfSSL | 0:9d17e4342598 | 171 | |
wolfSSL | 0:9d17e4342598 | 172 | return InitSha(sha); /* reset state */ |
wolfSSL | 0:9d17e4342598 | 173 | } |
wolfSSL | 0:9d17e4342598 | 174 | |
wolfSSL | 0:9d17e4342598 | 175 | #else /* CTaoCrypt software implementation */ |
wolfSSL | 0:9d17e4342598 | 176 | |
wolfSSL | 0:9d17e4342598 | 177 | #ifndef min |
wolfSSL | 0:9d17e4342598 | 178 | |
wolfSSL | 0:9d17e4342598 | 179 | static INLINE word32 min(word32 a, word32 b) |
wolfSSL | 0:9d17e4342598 | 180 | { |
wolfSSL | 0:9d17e4342598 | 181 | return a > b ? b : a; |
wolfSSL | 0:9d17e4342598 | 182 | } |
wolfSSL | 0:9d17e4342598 | 183 | |
wolfSSL | 0:9d17e4342598 | 184 | #endif /* min */ |
wolfSSL | 0:9d17e4342598 | 185 | |
wolfSSL | 0:9d17e4342598 | 186 | |
wolfSSL | 0:9d17e4342598 | 187 | int InitSha(Sha* sha) |
wolfSSL | 0:9d17e4342598 | 188 | { |
wolfSSL | 0:9d17e4342598 | 189 | #ifdef FREESCALE_MMCAU |
wolfSSL | 0:9d17e4342598 | 190 | cau_sha1_initialize_output(sha->digest); |
wolfSSL | 0:9d17e4342598 | 191 | #else |
wolfSSL | 0:9d17e4342598 | 192 | sha->digest[0] = 0x67452301L; |
wolfSSL | 0:9d17e4342598 | 193 | sha->digest[1] = 0xEFCDAB89L; |
wolfSSL | 0:9d17e4342598 | 194 | sha->digest[2] = 0x98BADCFEL; |
wolfSSL | 0:9d17e4342598 | 195 | sha->digest[3] = 0x10325476L; |
wolfSSL | 0:9d17e4342598 | 196 | sha->digest[4] = 0xC3D2E1F0L; |
wolfSSL | 0:9d17e4342598 | 197 | #endif |
wolfSSL | 0:9d17e4342598 | 198 | |
wolfSSL | 0:9d17e4342598 | 199 | sha->buffLen = 0; |
wolfSSL | 0:9d17e4342598 | 200 | sha->loLen = 0; |
wolfSSL | 0:9d17e4342598 | 201 | sha->hiLen = 0; |
wolfSSL | 0:9d17e4342598 | 202 | |
wolfSSL | 0:9d17e4342598 | 203 | return 0; |
wolfSSL | 0:9d17e4342598 | 204 | } |
wolfSSL | 0:9d17e4342598 | 205 | |
wolfSSL | 0:9d17e4342598 | 206 | #ifndef FREESCALE_MMCAU |
wolfSSL | 0:9d17e4342598 | 207 | |
wolfSSL | 0:9d17e4342598 | 208 | #define blk0(i) (W[i] = sha->buffer[i]) |
wolfSSL | 0:9d17e4342598 | 209 | #define blk1(i) (W[i&15] = \ |
wolfSSL | 0:9d17e4342598 | 210 | rotlFixed(W[(i+13)&15]^W[(i+8)&15]^W[(i+2)&15]^W[i&15],1)) |
wolfSSL | 0:9d17e4342598 | 211 | |
wolfSSL | 0:9d17e4342598 | 212 | #define f1(x,y,z) (z^(x &(y^z))) |
wolfSSL | 0:9d17e4342598 | 213 | #define f2(x,y,z) (x^y^z) |
wolfSSL | 0:9d17e4342598 | 214 | #define f3(x,y,z) ((x&y)|(z&(x|y))) |
wolfSSL | 0:9d17e4342598 | 215 | #define f4(x,y,z) (x^y^z) |
wolfSSL | 0:9d17e4342598 | 216 | |
wolfSSL | 0:9d17e4342598 | 217 | /* (R0+R1), R2, R3, R4 are the different operations used in SHA1 */ |
wolfSSL | 0:9d17e4342598 | 218 | #define R0(v,w,x,y,z,i) z+= f1(w,x,y) + blk0(i) + 0x5A827999+ \ |
wolfSSL | 0:9d17e4342598 | 219 | rotlFixed(v,5); w = rotlFixed(w,30); |
wolfSSL | 0:9d17e4342598 | 220 | #define R1(v,w,x,y,z,i) z+= f1(w,x,y) + blk1(i) + 0x5A827999+ \ |
wolfSSL | 0:9d17e4342598 | 221 | rotlFixed(v,5); w = rotlFixed(w,30); |
wolfSSL | 0:9d17e4342598 | 222 | #define R2(v,w,x,y,z,i) z+= f2(w,x,y) + blk1(i) + 0x6ED9EBA1+ \ |
wolfSSL | 0:9d17e4342598 | 223 | rotlFixed(v,5); w = rotlFixed(w,30); |
wolfSSL | 0:9d17e4342598 | 224 | #define R3(v,w,x,y,z,i) z+= f3(w,x,y) + blk1(i) + 0x8F1BBCDC+ \ |
wolfSSL | 0:9d17e4342598 | 225 | rotlFixed(v,5); w = rotlFixed(w,30); |
wolfSSL | 0:9d17e4342598 | 226 | #define R4(v,w,x,y,z,i) z+= f4(w,x,y) + blk1(i) + 0xCA62C1D6+ \ |
wolfSSL | 0:9d17e4342598 | 227 | rotlFixed(v,5); w = rotlFixed(w,30); |
wolfSSL | 0:9d17e4342598 | 228 | |
wolfSSL | 0:9d17e4342598 | 229 | |
wolfSSL | 0:9d17e4342598 | 230 | static void Transform(Sha* sha) |
wolfSSL | 0:9d17e4342598 | 231 | { |
wolfSSL | 0:9d17e4342598 | 232 | word32 W[SHA_BLOCK_SIZE / sizeof(word32)]; |
wolfSSL | 0:9d17e4342598 | 233 | |
wolfSSL | 0:9d17e4342598 | 234 | /* Copy context->state[] to working vars */ |
wolfSSL | 0:9d17e4342598 | 235 | word32 a = sha->digest[0]; |
wolfSSL | 0:9d17e4342598 | 236 | word32 b = sha->digest[1]; |
wolfSSL | 0:9d17e4342598 | 237 | word32 c = sha->digest[2]; |
wolfSSL | 0:9d17e4342598 | 238 | word32 d = sha->digest[3]; |
wolfSSL | 0:9d17e4342598 | 239 | word32 e = sha->digest[4]; |
wolfSSL | 0:9d17e4342598 | 240 | |
wolfSSL | 0:9d17e4342598 | 241 | #ifdef USE_SLOW_SHA |
wolfSSL | 0:9d17e4342598 | 242 | word32 t, i; |
wolfSSL | 0:9d17e4342598 | 243 | |
wolfSSL | 0:9d17e4342598 | 244 | for (i = 0; i < 16; i++) { |
wolfSSL | 0:9d17e4342598 | 245 | R0(a, b, c, d, e, i); |
wolfSSL | 0:9d17e4342598 | 246 | t = e; e = d; d = c; c = b; b = a; a = t; |
wolfSSL | 0:9d17e4342598 | 247 | } |
wolfSSL | 0:9d17e4342598 | 248 | |
wolfSSL | 0:9d17e4342598 | 249 | for (; i < 20; i++) { |
wolfSSL | 0:9d17e4342598 | 250 | R1(a, b, c, d, e, i); |
wolfSSL | 0:9d17e4342598 | 251 | t = e; e = d; d = c; c = b; b = a; a = t; |
wolfSSL | 0:9d17e4342598 | 252 | } |
wolfSSL | 0:9d17e4342598 | 253 | |
wolfSSL | 0:9d17e4342598 | 254 | for (; i < 40; i++) { |
wolfSSL | 0:9d17e4342598 | 255 | R2(a, b, c, d, e, i); |
wolfSSL | 0:9d17e4342598 | 256 | t = e; e = d; d = c; c = b; b = a; a = t; |
wolfSSL | 0:9d17e4342598 | 257 | } |
wolfSSL | 0:9d17e4342598 | 258 | |
wolfSSL | 0:9d17e4342598 | 259 | for (; i < 60; i++) { |
wolfSSL | 0:9d17e4342598 | 260 | R3(a, b, c, d, e, i); |
wolfSSL | 0:9d17e4342598 | 261 | t = e; e = d; d = c; c = b; b = a; a = t; |
wolfSSL | 0:9d17e4342598 | 262 | } |
wolfSSL | 0:9d17e4342598 | 263 | |
wolfSSL | 0:9d17e4342598 | 264 | for (; i < 80; i++) { |
wolfSSL | 0:9d17e4342598 | 265 | R4(a, b, c, d, e, i); |
wolfSSL | 0:9d17e4342598 | 266 | t = e; e = d; d = c; c = b; b = a; a = t; |
wolfSSL | 0:9d17e4342598 | 267 | } |
wolfSSL | 0:9d17e4342598 | 268 | #else |
wolfSSL | 0:9d17e4342598 | 269 | /* nearly 1 K bigger in code size but 25% faster */ |
wolfSSL | 0:9d17e4342598 | 270 | /* 4 rounds of 20 operations each. Loop unrolled. */ |
wolfSSL | 0:9d17e4342598 | 271 | R0(a,b,c,d,e, 0); R0(e,a,b,c,d, 1); R0(d,e,a,b,c, 2); R0(c,d,e,a,b, 3); |
wolfSSL | 0:9d17e4342598 | 272 | R0(b,c,d,e,a, 4); R0(a,b,c,d,e, 5); R0(e,a,b,c,d, 6); R0(d,e,a,b,c, 7); |
wolfSSL | 0:9d17e4342598 | 273 | R0(c,d,e,a,b, 8); R0(b,c,d,e,a, 9); R0(a,b,c,d,e,10); R0(e,a,b,c,d,11); |
wolfSSL | 0:9d17e4342598 | 274 | R0(d,e,a,b,c,12); R0(c,d,e,a,b,13); R0(b,c,d,e,a,14); R0(a,b,c,d,e,15); |
wolfSSL | 0:9d17e4342598 | 275 | |
wolfSSL | 0:9d17e4342598 | 276 | R1(e,a,b,c,d,16); R1(d,e,a,b,c,17); R1(c,d,e,a,b,18); R1(b,c,d,e,a,19); |
wolfSSL | 0:9d17e4342598 | 277 | |
wolfSSL | 0:9d17e4342598 | 278 | R2(a,b,c,d,e,20); R2(e,a,b,c,d,21); R2(d,e,a,b,c,22); R2(c,d,e,a,b,23); |
wolfSSL | 0:9d17e4342598 | 279 | R2(b,c,d,e,a,24); R2(a,b,c,d,e,25); R2(e,a,b,c,d,26); R2(d,e,a,b,c,27); |
wolfSSL | 0:9d17e4342598 | 280 | R2(c,d,e,a,b,28); R2(b,c,d,e,a,29); R2(a,b,c,d,e,30); R2(e,a,b,c,d,31); |
wolfSSL | 0:9d17e4342598 | 281 | R2(d,e,a,b,c,32); R2(c,d,e,a,b,33); R2(b,c,d,e,a,34); R2(a,b,c,d,e,35); |
wolfSSL | 0:9d17e4342598 | 282 | R2(e,a,b,c,d,36); R2(d,e,a,b,c,37); R2(c,d,e,a,b,38); R2(b,c,d,e,a,39); |
wolfSSL | 0:9d17e4342598 | 283 | |
wolfSSL | 0:9d17e4342598 | 284 | R3(a,b,c,d,e,40); R3(e,a,b,c,d,41); R3(d,e,a,b,c,42); R3(c,d,e,a,b,43); |
wolfSSL | 0:9d17e4342598 | 285 | R3(b,c,d,e,a,44); R3(a,b,c,d,e,45); R3(e,a,b,c,d,46); R3(d,e,a,b,c,47); |
wolfSSL | 0:9d17e4342598 | 286 | R3(c,d,e,a,b,48); R3(b,c,d,e,a,49); R3(a,b,c,d,e,50); R3(e,a,b,c,d,51); |
wolfSSL | 0:9d17e4342598 | 287 | R3(d,e,a,b,c,52); R3(c,d,e,a,b,53); R3(b,c,d,e,a,54); R3(a,b,c,d,e,55); |
wolfSSL | 0:9d17e4342598 | 288 | R3(e,a,b,c,d,56); R3(d,e,a,b,c,57); R3(c,d,e,a,b,58); R3(b,c,d,e,a,59); |
wolfSSL | 0:9d17e4342598 | 289 | |
wolfSSL | 0:9d17e4342598 | 290 | R4(a,b,c,d,e,60); R4(e,a,b,c,d,61); R4(d,e,a,b,c,62); R4(c,d,e,a,b,63); |
wolfSSL | 0:9d17e4342598 | 291 | R4(b,c,d,e,a,64); R4(a,b,c,d,e,65); R4(e,a,b,c,d,66); R4(d,e,a,b,c,67); |
wolfSSL | 0:9d17e4342598 | 292 | R4(c,d,e,a,b,68); R4(b,c,d,e,a,69); R4(a,b,c,d,e,70); R4(e,a,b,c,d,71); |
wolfSSL | 0:9d17e4342598 | 293 | R4(d,e,a,b,c,72); R4(c,d,e,a,b,73); R4(b,c,d,e,a,74); R4(a,b,c,d,e,75); |
wolfSSL | 0:9d17e4342598 | 294 | R4(e,a,b,c,d,76); R4(d,e,a,b,c,77); R4(c,d,e,a,b,78); R4(b,c,d,e,a,79); |
wolfSSL | 0:9d17e4342598 | 295 | #endif |
wolfSSL | 0:9d17e4342598 | 296 | |
wolfSSL | 0:9d17e4342598 | 297 | /* Add the working vars back into digest state[] */ |
wolfSSL | 0:9d17e4342598 | 298 | sha->digest[0] += a; |
wolfSSL | 0:9d17e4342598 | 299 | sha->digest[1] += b; |
wolfSSL | 0:9d17e4342598 | 300 | sha->digest[2] += c; |
wolfSSL | 0:9d17e4342598 | 301 | sha->digest[3] += d; |
wolfSSL | 0:9d17e4342598 | 302 | sha->digest[4] += e; |
wolfSSL | 0:9d17e4342598 | 303 | } |
wolfSSL | 0:9d17e4342598 | 304 | |
wolfSSL | 0:9d17e4342598 | 305 | #endif /* FREESCALE_MMCAU */ |
wolfSSL | 0:9d17e4342598 | 306 | |
wolfSSL | 0:9d17e4342598 | 307 | |
wolfSSL | 0:9d17e4342598 | 308 | static INLINE void AddLength(Sha* sha, word32 len) |
wolfSSL | 0:9d17e4342598 | 309 | { |
wolfSSL | 0:9d17e4342598 | 310 | word32 tmp = sha->loLen; |
wolfSSL | 0:9d17e4342598 | 311 | if ( (sha->loLen += len) < tmp) |
wolfSSL | 0:9d17e4342598 | 312 | sha->hiLen++; /* carry low to high */ |
wolfSSL | 0:9d17e4342598 | 313 | } |
wolfSSL | 0:9d17e4342598 | 314 | |
wolfSSL | 0:9d17e4342598 | 315 | |
wolfSSL | 0:9d17e4342598 | 316 | int ShaUpdate(Sha* sha, const byte* data, word32 len) |
wolfSSL | 0:9d17e4342598 | 317 | { |
wolfSSL | 0:9d17e4342598 | 318 | /* do block size increments */ |
wolfSSL | 0:9d17e4342598 | 319 | byte* local = (byte*)sha->buffer; |
wolfSSL | 0:9d17e4342598 | 320 | |
wolfSSL | 0:9d17e4342598 | 321 | while (len) { |
wolfSSL | 0:9d17e4342598 | 322 | word32 add = min(len, SHA_BLOCK_SIZE - sha->buffLen); |
wolfSSL | 0:9d17e4342598 | 323 | XMEMCPY(&local[sha->buffLen], data, add); |
wolfSSL | 0:9d17e4342598 | 324 | |
wolfSSL | 0:9d17e4342598 | 325 | sha->buffLen += add; |
wolfSSL | 0:9d17e4342598 | 326 | data += add; |
wolfSSL | 0:9d17e4342598 | 327 | len -= add; |
wolfSSL | 0:9d17e4342598 | 328 | |
wolfSSL | 0:9d17e4342598 | 329 | if (sha->buffLen == SHA_BLOCK_SIZE) { |
wolfSSL | 0:9d17e4342598 | 330 | #if defined(LITTLE_ENDIAN_ORDER) && !defined(FREESCALE_MMCAU) |
wolfSSL | 0:9d17e4342598 | 331 | ByteReverseWords(sha->buffer, sha->buffer, SHA_BLOCK_SIZE); |
wolfSSL | 0:9d17e4342598 | 332 | #endif |
wolfSSL | 0:9d17e4342598 | 333 | XTRANSFORM(sha, local); |
wolfSSL | 0:9d17e4342598 | 334 | AddLength(sha, SHA_BLOCK_SIZE); |
wolfSSL | 0:9d17e4342598 | 335 | sha->buffLen = 0; |
wolfSSL | 0:9d17e4342598 | 336 | } |
wolfSSL | 0:9d17e4342598 | 337 | } |
wolfSSL | 0:9d17e4342598 | 338 | |
wolfSSL | 0:9d17e4342598 | 339 | return 0; |
wolfSSL | 0:9d17e4342598 | 340 | } |
wolfSSL | 0:9d17e4342598 | 341 | |
wolfSSL | 0:9d17e4342598 | 342 | |
wolfSSL | 0:9d17e4342598 | 343 | int ShaFinal(Sha* sha, byte* hash) |
wolfSSL | 0:9d17e4342598 | 344 | { |
wolfSSL | 0:9d17e4342598 | 345 | byte* local = (byte*)sha->buffer; |
wolfSSL | 0:9d17e4342598 | 346 | |
wolfSSL | 0:9d17e4342598 | 347 | AddLength(sha, sha->buffLen); /* before adding pads */ |
wolfSSL | 0:9d17e4342598 | 348 | |
wolfSSL | 0:9d17e4342598 | 349 | local[sha->buffLen++] = 0x80; /* add 1 */ |
wolfSSL | 0:9d17e4342598 | 350 | |
wolfSSL | 0:9d17e4342598 | 351 | /* pad with zeros */ |
wolfSSL | 0:9d17e4342598 | 352 | if (sha->buffLen > SHA_PAD_SIZE) { |
wolfSSL | 0:9d17e4342598 | 353 | XMEMSET(&local[sha->buffLen], 0, SHA_BLOCK_SIZE - sha->buffLen); |
wolfSSL | 0:9d17e4342598 | 354 | sha->buffLen += SHA_BLOCK_SIZE - sha->buffLen; |
wolfSSL | 0:9d17e4342598 | 355 | |
wolfSSL | 0:9d17e4342598 | 356 | #if defined(LITTLE_ENDIAN_ORDER) && !defined(FREESCALE_MMCAU) |
wolfSSL | 0:9d17e4342598 | 357 | ByteReverseWords(sha->buffer, sha->buffer, SHA_BLOCK_SIZE); |
wolfSSL | 0:9d17e4342598 | 358 | #endif |
wolfSSL | 0:9d17e4342598 | 359 | XTRANSFORM(sha, local); |
wolfSSL | 0:9d17e4342598 | 360 | sha->buffLen = 0; |
wolfSSL | 0:9d17e4342598 | 361 | } |
wolfSSL | 0:9d17e4342598 | 362 | XMEMSET(&local[sha->buffLen], 0, SHA_PAD_SIZE - sha->buffLen); |
wolfSSL | 0:9d17e4342598 | 363 | |
wolfSSL | 0:9d17e4342598 | 364 | /* put lengths in bits */ |
wolfSSL | 0:9d17e4342598 | 365 | sha->hiLen = (sha->loLen >> (8*sizeof(sha->loLen) - 3)) + |
wolfSSL | 0:9d17e4342598 | 366 | (sha->hiLen << 3); |
wolfSSL | 0:9d17e4342598 | 367 | sha->loLen = sha->loLen << 3; |
wolfSSL | 0:9d17e4342598 | 368 | |
wolfSSL | 0:9d17e4342598 | 369 | /* store lengths */ |
wolfSSL | 0:9d17e4342598 | 370 | #if defined(LITTLE_ENDIAN_ORDER) && !defined(FREESCALE_MMCAU) |
wolfSSL | 0:9d17e4342598 | 371 | ByteReverseWords(sha->buffer, sha->buffer, SHA_BLOCK_SIZE); |
wolfSSL | 0:9d17e4342598 | 372 | #endif |
wolfSSL | 0:9d17e4342598 | 373 | /* ! length ordering dependent on digest endian type ! */ |
wolfSSL | 0:9d17e4342598 | 374 | XMEMCPY(&local[SHA_PAD_SIZE], &sha->hiLen, sizeof(word32)); |
wolfSSL | 0:9d17e4342598 | 375 | XMEMCPY(&local[SHA_PAD_SIZE + sizeof(word32)], &sha->loLen, sizeof(word32)); |
wolfSSL | 0:9d17e4342598 | 376 | |
wolfSSL | 0:9d17e4342598 | 377 | #ifdef FREESCALE_MMCAU |
wolfSSL | 0:9d17e4342598 | 378 | /* Kinetis requires only these bytes reversed */ |
wolfSSL | 0:9d17e4342598 | 379 | ByteReverseWords(&sha->buffer[SHA_PAD_SIZE/sizeof(word32)], |
wolfSSL | 0:9d17e4342598 | 380 | &sha->buffer[SHA_PAD_SIZE/sizeof(word32)], |
wolfSSL | 0:9d17e4342598 | 381 | 2 * sizeof(word32)); |
wolfSSL | 0:9d17e4342598 | 382 | #endif |
wolfSSL | 0:9d17e4342598 | 383 | |
wolfSSL | 0:9d17e4342598 | 384 | XTRANSFORM(sha, local); |
wolfSSL | 0:9d17e4342598 | 385 | #ifdef LITTLE_ENDIAN_ORDER |
wolfSSL | 0:9d17e4342598 | 386 | ByteReverseWords(sha->digest, sha->digest, SHA_DIGEST_SIZE); |
wolfSSL | 0:9d17e4342598 | 387 | #endif |
wolfSSL | 0:9d17e4342598 | 388 | XMEMCPY(hash, sha->digest, SHA_DIGEST_SIZE); |
wolfSSL | 0:9d17e4342598 | 389 | |
wolfSSL | 0:9d17e4342598 | 390 | return InitSha(sha); /* reset state */ |
wolfSSL | 0:9d17e4342598 | 391 | } |
wolfSSL | 0:9d17e4342598 | 392 | |
wolfSSL | 0:9d17e4342598 | 393 | #endif /* STM32F2_HASH */ |
wolfSSL | 0:9d17e4342598 | 394 | |
wolfSSL | 0:9d17e4342598 | 395 | #endif /* NO_SHA */ |