sha3.h 4.22 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1
/* sha3.h
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

   The sha3 hash function (aka Keccak).

   Copyright (C) 2012 Niels Möller

   This file is part of GNU Nettle.

   GNU Nettle is free software: you can redistribute it and/or
   modify it under the terms of either:

     * the GNU Lesser General Public License as published by the Free
       Software Foundation; either version 3 of the License, or (at your
       option) any later version.

   or

     * the GNU General Public License as published by the Free
       Software Foundation; either version 2 of the License, or (at your
       option) any later version.

   or both in parallel, as here.

   GNU Nettle is distributed in the hope that it will be useful,
   but WITHOUT ANY WARRANTY; without even the implied warranty of
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
   General Public License for more details.

   You should have received copies of the GNU General Public License and
   the GNU Lesser General Public License along with this program.  If
   not, see http://www.gnu.org/licenses/.
*/
Niels Möller's avatar
Niels Möller committed
33 34 35 36 37 38 39 40 41 42
 
#ifndef NETTLE_SHA3_H_INCLUDED
#define NETTLE_SHA3_H_INCLUDED

#include "nettle-types.h"

#ifdef __cplusplus
extern "C" {
#endif

43
/* Name mangling */
Niels Möller's avatar
Niels Möller committed
44
#define sha3_permute nettle_sha3_permute
45 46 47
#define sha3_224_init nettle_sha3_224_init
#define sha3_224_update nettle_sha3_224_update
#define sha3_224_digest nettle_sha3_224_digest
Niels Möller's avatar
Niels Möller committed
48 49 50
#define sha3_256_init nettle_sha3_256_init
#define sha3_256_update nettle_sha3_256_update
#define sha3_256_digest nettle_sha3_256_digest
51 52 53 54 55 56
#define sha3_384_init nettle_sha3_384_init
#define sha3_384_update nettle_sha3_384_update
#define sha3_384_digest nettle_sha3_384_digest
#define sha3_512_init nettle_sha3_512_init
#define sha3_512_update nettle_sha3_512_update
#define sha3_512_digest nettle_sha3_512_digest
Niels Möller's avatar
Niels Möller committed
57

58 59 60
/* Indicates that SHA3 is the NIST FIPS 202 version. */
#define NETTLE_SHA3_FIPS202 1

Niels Möller's avatar
Niels Möller committed
61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80
/* The sha3 state is a 5x5 matrix of 64-bit words. In the notation of
   Keccak description, S[x,y] is element x + 5*y, so if x is
   interpreted as the row index and y the column index, it is stored
   in column-major order. */
#define SHA3_STATE_LENGTH 25

/* The "width" is 1600 bits or 200 octets */
struct sha3_state
{
  uint64_t a[SHA3_STATE_LENGTH];
};

void
sha3_permute (struct sha3_state *state);

/* The "capacity" is set to 2*(digest size), 512 bits or 64 octets.
   The "rate" is the width - capacity, or width - 2 * (digest
   size). */

#define SHA3_224_DIGEST_SIZE 28
81
#define SHA3_224_BLOCK_SIZE 144
Niels Möller's avatar
Niels Möller committed
82 83

#define SHA3_256_DIGEST_SIZE 32
84
#define SHA3_256_BLOCK_SIZE 136
Niels Möller's avatar
Niels Möller committed
85 86

#define SHA3_384_DIGEST_SIZE 48
87
#define SHA3_384_BLOCK_SIZE 104
Niels Möller's avatar
Niels Möller committed
88 89

#define SHA3_512_DIGEST_SIZE 64
90
#define SHA3_512_BLOCK_SIZE 72
Niels Möller's avatar
Niels Möller committed
91

92 93 94 95 96
/* For backwards compatibility */
#define SHA3_224_DATA_SIZE SHA3_224_BLOCK_SIZE
#define SHA3_256_DATA_SIZE SHA3_256_BLOCK_SIZE
#define SHA3_384_DATA_SIZE SHA3_384_BLOCK_SIZE
#define SHA3_512_DATA_SIZE SHA3_512_BLOCK_SIZE
Niels Möller's avatar
Niels Möller committed
97 98 99 100 101

struct sha3_224_ctx
{
  struct sha3_state state;
  unsigned index;
102
  uint8_t block[SHA3_224_BLOCK_SIZE];
Niels Möller's avatar
Niels Möller committed
103 104
};

105 106 107 108 109
void
sha3_224_init (struct sha3_224_ctx *ctx);

void
sha3_224_update (struct sha3_224_ctx *ctx,
110
		 size_t length,
111 112 113 114
		 const uint8_t *data);

void
sha3_224_digest(struct sha3_224_ctx *ctx,
115
		size_t length,
116 117
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
118 119 120 121
struct sha3_256_ctx
{
  struct sha3_state state;
  unsigned index;
122
  uint8_t block[SHA3_256_BLOCK_SIZE];
Niels Möller's avatar
Niels Möller committed
123 124 125 126 127 128 129
};

void
sha3_256_init (struct sha3_256_ctx *ctx);

void
sha3_256_update (struct sha3_256_ctx *ctx,
130
		 size_t length,
Niels Möller's avatar
Niels Möller committed
131 132 133 134
		 const uint8_t *data);

void
sha3_256_digest(struct sha3_256_ctx *ctx,
135
		size_t length,
Niels Möller's avatar
Niels Möller committed
136 137 138 139 140 141
		uint8_t *digest);

struct sha3_384_ctx
{
  struct sha3_state state;
  unsigned index;
142
  uint8_t block[SHA3_384_BLOCK_SIZE];
Niels Möller's avatar
Niels Möller committed
143 144
};

145 146 147 148 149
void
sha3_384_init (struct sha3_384_ctx *ctx);

void
sha3_384_update (struct sha3_384_ctx *ctx,
150
		 size_t length,
151 152 153 154
		 const uint8_t *data);

void
sha3_384_digest(struct sha3_384_ctx *ctx,
155
		size_t length,
156 157
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
158 159 160 161
struct sha3_512_ctx
{
  struct sha3_state state;
  unsigned index;
162
  uint8_t block[SHA3_512_BLOCK_SIZE];
Niels Möller's avatar
Niels Möller committed
163 164
};

165 166 167 168 169
void
sha3_512_init (struct sha3_512_ctx *ctx);

void
sha3_512_update (struct sha3_512_ctx *ctx,
170
		 size_t length,
171 172 173 174
		 const uint8_t *data);

void
sha3_512_digest(struct sha3_512_ctx *ctx,
175
		size_t length,
176 177
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
178 179 180 181 182
#ifdef __cplusplus
}
#endif

#endif /* NETTLE_SHA3_H_INCLUDED */