sha3.h 4.21 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1
/* sha3.h
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

   The sha3 hash function (aka Keccak).

   Copyright (C) 2012 Niels Möller

   This file is part of GNU Nettle.

   GNU Nettle is free software: you can redistribute it and/or
   modify it under the terms of either:

     * the GNU Lesser General Public License as published by the Free
       Software Foundation; either version 3 of the License, or (at your
       option) any later version.

   or

     * the GNU General Public License as published by the Free
       Software Foundation; either version 2 of the License, or (at your
       option) any later version.

   or both in parallel, as here.

   GNU Nettle is distributed in the hope that it will be useful,
   but WITHOUT ANY WARRANTY; without even the implied warranty of
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
   General Public License for more details.

   You should have received copies of the GNU General Public License and
   the GNU Lesser General Public License along with this program.  If
   not, see http://www.gnu.org/licenses/.
*/
Niels Möller's avatar
Niels Möller committed
33 34 35 36 37 38 39 40 41 42 43 44 45
 
#ifndef NETTLE_SHA3_H_INCLUDED
#define NETTLE_SHA3_H_INCLUDED

#include "nettle-types.h"

#ifdef __cplusplus
extern "C" {
#endif

#define sha3_permute nettle_sha3_permute
#define _sha3_update _nettle_sha3_update
#define _sha3_pad _nettle_sha3_pad
46 47 48
#define sha3_224_init nettle_sha3_224_init
#define sha3_224_update nettle_sha3_224_update
#define sha3_224_digest nettle_sha3_224_digest
Niels Möller's avatar
Niels Möller committed
49 50 51
#define sha3_256_init nettle_sha3_256_init
#define sha3_256_update nettle_sha3_256_update
#define sha3_256_digest nettle_sha3_256_digest
52 53 54 55 56 57
#define sha3_384_init nettle_sha3_384_init
#define sha3_384_update nettle_sha3_384_update
#define sha3_384_digest nettle_sha3_384_digest
#define sha3_512_init nettle_sha3_512_init
#define sha3_512_update nettle_sha3_512_update
#define sha3_512_digest nettle_sha3_512_digest
Niels Möller's avatar
Niels Möller committed
58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77

/* The sha3 state is a 5x5 matrix of 64-bit words. In the notation of
   Keccak description, S[x,y] is element x + 5*y, so if x is
   interpreted as the row index and y the column index, it is stored
   in column-major order. */
#define SHA3_STATE_LENGTH 25

/* The "width" is 1600 bits or 200 octets */
struct sha3_state
{
  uint64_t a[SHA3_STATE_LENGTH];
};

void
sha3_permute (struct sha3_state *state);

unsigned
_sha3_update (struct sha3_state *state,
	      unsigned block_size, uint8_t *block,
	      unsigned pos,
78
	      size_t length, const uint8_t *data);
Niels Möller's avatar
Niels Möller committed
79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106
void
_sha3_pad (struct sha3_state *state,
	   unsigned block_size, uint8_t *block, unsigned pos);

/* The "capacity" is set to 2*(digest size), 512 bits or 64 octets.
   The "rate" is the width - capacity, or width - 2 * (digest
   size). */

#define SHA3_224_DIGEST_SIZE 28
#define SHA3_224_DATA_SIZE 144

#define SHA3_256_DIGEST_SIZE 32
#define SHA3_256_DATA_SIZE 136

#define SHA3_384_DIGEST_SIZE 48
#define SHA3_384_DATA_SIZE 104

#define SHA3_512_DIGEST_SIZE 64
#define SHA3_512_DATA_SIZE 72


struct sha3_224_ctx
{
  struct sha3_state state;
  unsigned index;
  uint8_t block[SHA3_224_DATA_SIZE];
};

107 108 109 110 111
void
sha3_224_init (struct sha3_224_ctx *ctx);

void
sha3_224_update (struct sha3_224_ctx *ctx,
112
		 size_t length,
113 114 115 116
		 const uint8_t *data);

void
sha3_224_digest(struct sha3_224_ctx *ctx,
117
		size_t length,
118 119
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
120 121 122 123 124 125 126 127 128 129 130 131
struct sha3_256_ctx
{
  struct sha3_state state;
  unsigned index;
  uint8_t block[SHA3_256_DATA_SIZE];
};

void
sha3_256_init (struct sha3_256_ctx *ctx);

void
sha3_256_update (struct sha3_256_ctx *ctx,
132
		 size_t length,
Niels Möller's avatar
Niels Möller committed
133 134 135 136
		 const uint8_t *data);

void
sha3_256_digest(struct sha3_256_ctx *ctx,
137
		size_t length,
Niels Möller's avatar
Niels Möller committed
138 139 140 141 142 143 144 145 146
		uint8_t *digest);

struct sha3_384_ctx
{
  struct sha3_state state;
  unsigned index;
  uint8_t block[SHA3_384_DATA_SIZE];
};

147 148 149 150 151
void
sha3_384_init (struct sha3_384_ctx *ctx);

void
sha3_384_update (struct sha3_384_ctx *ctx,
152
		 size_t length,
153 154 155 156
		 const uint8_t *data);

void
sha3_384_digest(struct sha3_384_ctx *ctx,
157
		size_t length,
158 159
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
160 161 162 163 164 165 166
struct sha3_512_ctx
{
  struct sha3_state state;
  unsigned index;
  uint8_t block[SHA3_512_DATA_SIZE];
};

167 168 169 170 171
void
sha3_512_init (struct sha3_512_ctx *ctx);

void
sha3_512_update (struct sha3_512_ctx *ctx,
172
		 size_t length,
173 174 175 176
		 const uint8_t *data);

void
sha3_512_digest(struct sha3_512_ctx *ctx,
177
		size_t length,
178 179
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
180 181 182 183 184
#ifdef __cplusplus
}
#endif

#endif /* NETTLE_SHA3_H_INCLUDED */