sha3.h 4.44 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1
/* sha3.h
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

   The sha3 hash function (aka Keccak).

   Copyright (C) 2012 Niels Möller

   This file is part of GNU Nettle.

   GNU Nettle is free software: you can redistribute it and/or
   modify it under the terms of either:

     * the GNU Lesser General Public License as published by the Free
       Software Foundation; either version 3 of the License, or (at your
       option) any later version.

   or

     * the GNU General Public License as published by the Free
       Software Foundation; either version 2 of the License, or (at your
       option) any later version.

   or both in parallel, as here.

   GNU Nettle is distributed in the hope that it will be useful,
   but WITHOUT ANY WARRANTY; without even the implied warranty of
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
   General Public License for more details.

   You should have received copies of the GNU General Public License and
   the GNU Lesser General Public License along with this program.  If
   not, see http://www.gnu.org/licenses/.
*/
Niels Möller's avatar
Niels Möller committed
33 34 35 36 37 38 39 40 41 42 43 44 45
 
#ifndef NETTLE_SHA3_H_INCLUDED
#define NETTLE_SHA3_H_INCLUDED

#include "nettle-types.h"

#ifdef __cplusplus
extern "C" {
#endif

#define sha3_permute nettle_sha3_permute
#define _sha3_update _nettle_sha3_update
#define _sha3_pad _nettle_sha3_pad
46 47 48
#define sha3_224_init nettle_sha3_224_init
#define sha3_224_update nettle_sha3_224_update
#define sha3_224_digest nettle_sha3_224_digest
Niels Möller's avatar
Niels Möller committed
49 50 51
#define sha3_256_init nettle_sha3_256_init
#define sha3_256_update nettle_sha3_256_update
#define sha3_256_digest nettle_sha3_256_digest
52 53 54 55 56 57
#define sha3_384_init nettle_sha3_384_init
#define sha3_384_update nettle_sha3_384_update
#define sha3_384_digest nettle_sha3_384_digest
#define sha3_512_init nettle_sha3_512_init
#define sha3_512_update nettle_sha3_512_update
#define sha3_512_digest nettle_sha3_512_digest
Niels Möller's avatar
Niels Möller committed
58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77

/* The sha3 state is a 5x5 matrix of 64-bit words. In the notation of
   Keccak description, S[x,y] is element x + 5*y, so if x is
   interpreted as the row index and y the column index, it is stored
   in column-major order. */
#define SHA3_STATE_LENGTH 25

/* The "width" is 1600 bits or 200 octets */
struct sha3_state
{
  uint64_t a[SHA3_STATE_LENGTH];
};

void
sha3_permute (struct sha3_state *state);

unsigned
_sha3_update (struct sha3_state *state,
	      unsigned block_size, uint8_t *block,
	      unsigned pos,
78
	      size_t length, const uint8_t *data);
Niels Möller's avatar
Niels Möller committed
79 80 81 82 83 84 85 86 87
void
_sha3_pad (struct sha3_state *state,
	   unsigned block_size, uint8_t *block, unsigned pos);

/* The "capacity" is set to 2*(digest size), 512 bits or 64 octets.
   The "rate" is the width - capacity, or width - 2 * (digest
   size). */

#define SHA3_224_DIGEST_SIZE 28
88
#define SHA3_224_BLOCK_SIZE 144
Niels Möller's avatar
Niels Möller committed
89 90

#define SHA3_256_DIGEST_SIZE 32
91
#define SHA3_256_BLOCK_SIZE 136
Niels Möller's avatar
Niels Möller committed
92 93

#define SHA3_384_DIGEST_SIZE 48
94
#define SHA3_384_BLOCK_SIZE 104
Niels Möller's avatar
Niels Möller committed
95 96

#define SHA3_512_DIGEST_SIZE 64
97
#define SHA3_512_BLOCK_SIZE 72
Niels Möller's avatar
Niels Möller committed
98

99 100 101 102 103
/* For backwards compatibility */
#define SHA3_224_DATA_SIZE SHA3_224_BLOCK_SIZE
#define SHA3_256_DATA_SIZE SHA3_256_BLOCK_SIZE
#define SHA3_384_DATA_SIZE SHA3_384_BLOCK_SIZE
#define SHA3_512_DATA_SIZE SHA3_512_BLOCK_SIZE
Niels Möller's avatar
Niels Möller committed
104 105 106 107 108

struct sha3_224_ctx
{
  struct sha3_state state;
  unsigned index;
109
  uint8_t block[SHA3_224_BLOCK_SIZE];
Niels Möller's avatar
Niels Möller committed
110 111
};

112 113 114 115 116
void
sha3_224_init (struct sha3_224_ctx *ctx);

void
sha3_224_update (struct sha3_224_ctx *ctx,
117
		 size_t length,
118 119 120 121
		 const uint8_t *data);

void
sha3_224_digest(struct sha3_224_ctx *ctx,
122
		size_t length,
123 124
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
125 126 127 128
struct sha3_256_ctx
{
  struct sha3_state state;
  unsigned index;
129
  uint8_t block[SHA3_256_BLOCK_SIZE];
Niels Möller's avatar
Niels Möller committed
130 131 132 133 134 135 136
};

void
sha3_256_init (struct sha3_256_ctx *ctx);

void
sha3_256_update (struct sha3_256_ctx *ctx,
137
		 size_t length,
Niels Möller's avatar
Niels Möller committed
138 139 140 141
		 const uint8_t *data);

void
sha3_256_digest(struct sha3_256_ctx *ctx,
142
		size_t length,
Niels Möller's avatar
Niels Möller committed
143 144 145 146 147 148
		uint8_t *digest);

struct sha3_384_ctx
{
  struct sha3_state state;
  unsigned index;
149
  uint8_t block[SHA3_384_BLOCK_SIZE];
Niels Möller's avatar
Niels Möller committed
150 151
};

152 153 154 155 156
void
sha3_384_init (struct sha3_384_ctx *ctx);

void
sha3_384_update (struct sha3_384_ctx *ctx,
157
		 size_t length,
158 159 160 161
		 const uint8_t *data);

void
sha3_384_digest(struct sha3_384_ctx *ctx,
162
		size_t length,
163 164
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
165 166 167 168
struct sha3_512_ctx
{
  struct sha3_state state;
  unsigned index;
169
  uint8_t block[SHA3_512_BLOCK_SIZE];
Niels Möller's avatar
Niels Möller committed
170 171
};

172 173 174 175 176
void
sha3_512_init (struct sha3_512_ctx *ctx);

void
sha3_512_update (struct sha3_512_ctx *ctx,
177
		 size_t length,
178 179 180 181
		 const uint8_t *data);

void
sha3_512_digest(struct sha3_512_ctx *ctx,
182
		size_t length,
183 184
		uint8_t *digest);

Niels Möller's avatar
Niels Möller committed
185 186 187 188 189
#ifdef __cplusplus
}
#endif

#endif /* NETTLE_SHA3_H_INCLUDED */