sha1.c 3.11 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1
/* sha1.c
Niels Möller's avatar
Niels Möller committed
2 3
 *
 * The sha1 hash function.
4
 * Defined by http://www.itl.nist.gov/fipspubs/fip180-1.htm.
Niels Möller's avatar
Niels Möller committed
5 6 7 8
 */

/* nettle, low-level cryptographics library
 *
Niels Möller's avatar
Niels Möller committed
9
 * Copyright (C) 2001 Peter Gutmann, Andrew Kuchling, Niels Möller
Niels Möller's avatar
Niels Möller committed
10 11 12 13 14 15
 *  
 * The nettle library is free software; you can redistribute it and/or modify
 * it under the terms of the GNU Lesser General Public License as published by
 * the Free Software Foundation; either version 2.1 of the License, or (at your
 * option) any later version.
 * 
Niels Möller's avatar
Niels Möller committed
16
 * The nettle library is distributed in the hope that it will be useful, but
Niels Möller's avatar
Niels Möller committed
17 18 19 20 21
 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
 * or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General Public
 * License for more details.
 * 
 * You should have received a copy of the GNU Lesser General Public License
Niels Möller's avatar
Niels Möller committed
22
 * along with the nettle library; see the file COPYING.LIB.  If not, write to
23 24
 * the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,
 * MA 02111-1301, USA.
Niels Möller's avatar
Niels Möller committed
25 26 27 28 29 30 31 32 33 34 35 36 37 38
 */

/* Here's the first paragraph of Peter Gutmann's posting,
 * <30ajo5$oe8@ccu2.auckland.ac.nz>: 
 *
 * The following is my SHA (FIPS 180) code updated to allow use of the "fixed"
 * SHA, thanks to Jim Gillogly and an anonymous contributor for the information on
 * what's changed in the new version.  The fix is a simple change which involves
 * adding a single rotate in the initial expansion function.  It is unknown
 * whether this is an optimal solution to the problem which was discovered in the
 * SHA or whether it's simply a bandaid which fixes the problem with a minimum of
 * effort (for example the reengineering of a great many Capstone chips).
 */

39 40 41
#if HAVE_CONFIG_H
# include "config.h"
#endif
Niels Möller's avatar
Niels Möller committed
42 43

#include <assert.h>
Niels Möller's avatar
Niels Möller committed
44
#include <stdlib.h>
Niels Möller's avatar
Niels Möller committed
45 46
#include <string.h>

47
#include "sha1.h"
48 49

#include "macros.h"
50
#include "nettle-write.h"
51

Niels Möller's avatar
Niels Möller committed
52 53 54 55
/* Initialize the SHA values */
void
sha1_init(struct sha1_ctx *ctx)
{
56 57 58 59 60 61 62 63 64 65 66 67 68
  /* FIXME: Put the buffer last in the struct, and arrange so that we
     can initialize with a single memcpy. */
  static const uint32_t iv[_SHA1_DIGEST_LENGTH] = 
    {
      /* SHA initial values */
      0x67452301L,
      0xEFCDAB89L,
      0x98BADCFEL,
      0x10325476L,
      0xC3D2E1F0L,
    };

  memcpy(ctx->state, iv, sizeof(ctx->state));
Niels Möller's avatar
Niels Möller committed
69 70 71 72 73 74
  ctx->count_low = ctx->count_high = 0;
  
  /* Initialize buffer */
  ctx->index = 0;
}

75 76
#define COMPRESS(ctx, data) (_nettle_sha1_compress((ctx)->state, data))

Niels Möller's avatar
Niels Möller committed
77 78
void
sha1_update(struct sha1_ctx *ctx,
79
	    unsigned length, const uint8_t *data)
Niels Möller's avatar
Niels Möller committed
80
{
81
  MD_UPDATE (ctx, length, data, COMPRESS, MD_INCR(ctx));
Niels Möller's avatar
Niels Möller committed
82 83 84
}
	  
void
85
sha1_digest(struct sha1_ctx *ctx,
Niels Möller's avatar
Niels Möller committed
86 87 88
	    unsigned length,
	    uint8_t *digest)
{
89 90
  uint32_t high, low;

Niels Möller's avatar
Niels Möller committed
91 92
  assert(length <= SHA1_DIGEST_SIZE);

93 94
  MD_PAD(ctx, 8, COMPRESS);

95
  /* There are 512 = 2^9 bits in one block */  
96 97 98 99 100 101 102 103
  high = (ctx->count_high << 9) | (ctx->count_low >> 23);
  low = (ctx->count_low << 9) | (ctx->index << 3);

  /* append the 64 bit count */
  WRITE_UINT32(ctx->block + (SHA1_DATA_SIZE - 8), high);
  WRITE_UINT32(ctx->block + (SHA1_DATA_SIZE - 4), low);
  _nettle_sha1_compress(ctx->state, ctx->block);

104
  _nettle_write_be32(length, digest, ctx->state);
105
  sha1_init(ctx);
Niels Möller's avatar
Niels Möller committed
106
}