| 1 | n/a | /* |
|---|
| 2 | n/a | Implementation by the Keccak, Keyak and Ketje Teams, namely, Guido Bertoni, |
|---|
| 3 | n/a | Joan Daemen, Michaël Peeters, Gilles Van Assche and Ronny Van Keer, hereby |
|---|
| 4 | n/a | denoted as "the implementer". |
|---|
| 5 | n/a | |
|---|
| 6 | n/a | For more information, feedback or questions, please refer to our websites: |
|---|
| 7 | n/a | http://keccak.noekeon.org/ |
|---|
| 8 | n/a | http://keyak.noekeon.org/ |
|---|
| 9 | n/a | http://ketje.noekeon.org/ |
|---|
| 10 | n/a | |
|---|
| 11 | n/a | To the extent possible under law, the implementer has waived all copyright |
|---|
| 12 | n/a | and related or neighboring rights to the source code in this file. |
|---|
| 13 | n/a | http://creativecommons.org/publicdomain/zero/1.0/ |
|---|
| 14 | n/a | */ |
|---|
| 15 | n/a | |
|---|
| 16 | n/a | #include <string.h> |
|---|
| 17 | n/a | #include <stdlib.h> |
|---|
| 18 | n/a | /* #include "brg_endian.h" */ |
|---|
| 19 | n/a | #include "KeccakP-1600-opt64-config.h" |
|---|
| 20 | n/a | |
|---|
| 21 | n/a | #if NOT_PYTHON |
|---|
| 22 | n/a | typedef unsigned char UINT8; |
|---|
| 23 | n/a | /* typedef unsigned long long int UINT64; */ |
|---|
| 24 | n/a | #endif |
|---|
| 25 | n/a | |
|---|
| 26 | n/a | #if defined(KeccakP1600_useLaneComplementing) |
|---|
| 27 | n/a | #define UseBebigokimisa |
|---|
| 28 | n/a | #endif |
|---|
| 29 | n/a | |
|---|
| 30 | n/a | #if defined(_MSC_VER) |
|---|
| 31 | n/a | #define ROL64(a, offset) _rotl64(a, offset) |
|---|
| 32 | n/a | #elif defined(KeccakP1600_useSHLD) |
|---|
| 33 | n/a | #define ROL64(x,N) ({ \ |
|---|
| 34 | n/a | register UINT64 __out; \ |
|---|
| 35 | n/a | register UINT64 __in = x; \ |
|---|
| 36 | n/a | __asm__ ("shld %2,%0,%0" : "=r"(__out) : "0"(__in), "i"(N)); \ |
|---|
| 37 | n/a | __out; \ |
|---|
| 38 | n/a | }) |
|---|
| 39 | n/a | #else |
|---|
| 40 | n/a | #define ROL64(a, offset) ((((UINT64)a) << offset) ^ (((UINT64)a) >> (64-offset))) |
|---|
| 41 | n/a | #endif |
|---|
| 42 | n/a | |
|---|
| 43 | n/a | #include "KeccakP-1600-64.macros" |
|---|
| 44 | n/a | #ifdef KeccakP1600_fullUnrolling |
|---|
| 45 | n/a | #define FullUnrolling |
|---|
| 46 | n/a | #else |
|---|
| 47 | n/a | #define Unrolling KeccakP1600_unrolling |
|---|
| 48 | n/a | #endif |
|---|
| 49 | n/a | #include "KeccakP-1600-unrolling.macros" |
|---|
| 50 | n/a | #include "SnP-Relaned.h" |
|---|
| 51 | n/a | |
|---|
| 52 | n/a | static const UINT64 KeccakF1600RoundConstants[24] = { |
|---|
| 53 | n/a | 0x0000000000000001ULL, |
|---|
| 54 | n/a | 0x0000000000008082ULL, |
|---|
| 55 | n/a | 0x800000000000808aULL, |
|---|
| 56 | n/a | 0x8000000080008000ULL, |
|---|
| 57 | n/a | 0x000000000000808bULL, |
|---|
| 58 | n/a | 0x0000000080000001ULL, |
|---|
| 59 | n/a | 0x8000000080008081ULL, |
|---|
| 60 | n/a | 0x8000000000008009ULL, |
|---|
| 61 | n/a | 0x000000000000008aULL, |
|---|
| 62 | n/a | 0x0000000000000088ULL, |
|---|
| 63 | n/a | 0x0000000080008009ULL, |
|---|
| 64 | n/a | 0x000000008000000aULL, |
|---|
| 65 | n/a | 0x000000008000808bULL, |
|---|
| 66 | n/a | 0x800000000000008bULL, |
|---|
| 67 | n/a | 0x8000000000008089ULL, |
|---|
| 68 | n/a | 0x8000000000008003ULL, |
|---|
| 69 | n/a | 0x8000000000008002ULL, |
|---|
| 70 | n/a | 0x8000000000000080ULL, |
|---|
| 71 | n/a | 0x000000000000800aULL, |
|---|
| 72 | n/a | 0x800000008000000aULL, |
|---|
| 73 | n/a | 0x8000000080008081ULL, |
|---|
| 74 | n/a | 0x8000000000008080ULL, |
|---|
| 75 | n/a | 0x0000000080000001ULL, |
|---|
| 76 | n/a | 0x8000000080008008ULL }; |
|---|
| 77 | n/a | |
|---|
| 78 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 79 | n/a | |
|---|
| 80 | n/a | void KeccakP1600_Initialize(void *state) |
|---|
| 81 | n/a | { |
|---|
| 82 | n/a | memset(state, 0, 200); |
|---|
| 83 | n/a | #ifdef KeccakP1600_useLaneComplementing |
|---|
| 84 | n/a | ((UINT64*)state)[ 1] = ~(UINT64)0; |
|---|
| 85 | n/a | ((UINT64*)state)[ 2] = ~(UINT64)0; |
|---|
| 86 | n/a | ((UINT64*)state)[ 8] = ~(UINT64)0; |
|---|
| 87 | n/a | ((UINT64*)state)[12] = ~(UINT64)0; |
|---|
| 88 | n/a | ((UINT64*)state)[17] = ~(UINT64)0; |
|---|
| 89 | n/a | ((UINT64*)state)[20] = ~(UINT64)0; |
|---|
| 90 | n/a | #endif |
|---|
| 91 | n/a | } |
|---|
| 92 | n/a | |
|---|
| 93 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 94 | n/a | |
|---|
| 95 | n/a | void KeccakP1600_AddBytesInLane(void *state, unsigned int lanePosition, const unsigned char *data, unsigned int offset, unsigned int length) |
|---|
| 96 | n/a | { |
|---|
| 97 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 98 | n/a | UINT64 lane; |
|---|
| 99 | n/a | if (length == 0) |
|---|
| 100 | n/a | return; |
|---|
| 101 | n/a | if (length == 1) |
|---|
| 102 | n/a | lane = data[0]; |
|---|
| 103 | n/a | else { |
|---|
| 104 | n/a | lane = 0; |
|---|
| 105 | n/a | memcpy(&lane, data, length); |
|---|
| 106 | n/a | } |
|---|
| 107 | n/a | lane <<= offset*8; |
|---|
| 108 | n/a | #else |
|---|
| 109 | n/a | UINT64 lane = 0; |
|---|
| 110 | n/a | unsigned int i; |
|---|
| 111 | n/a | for(i=0; i<length; i++) |
|---|
| 112 | n/a | lane |= ((UINT64)data[i]) << ((i+offset)*8); |
|---|
| 113 | n/a | #endif |
|---|
| 114 | n/a | ((UINT64*)state)[lanePosition] ^= lane; |
|---|
| 115 | n/a | } |
|---|
| 116 | n/a | |
|---|
| 117 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 118 | n/a | |
|---|
| 119 | n/a | void KeccakP1600_AddLanes(void *state, const unsigned char *data, unsigned int laneCount) |
|---|
| 120 | n/a | { |
|---|
| 121 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 122 | n/a | unsigned int i = 0; |
|---|
| 123 | n/a | #ifdef NO_MISALIGNED_ACCESSES |
|---|
| 124 | n/a | /* If either pointer is misaligned, fall back to byte-wise xor. */ |
|---|
| 125 | n/a | |
|---|
| 126 | n/a | if (((((uintptr_t)state) & 7) != 0) || ((((uintptr_t)data) & 7) != 0)) { |
|---|
| 127 | n/a | for (i = 0; i < laneCount * 8; i++) { |
|---|
| 128 | n/a | ((unsigned char*)state)[i] ^= data[i]; |
|---|
| 129 | n/a | } |
|---|
| 130 | n/a | } |
|---|
| 131 | n/a | else |
|---|
| 132 | n/a | #endif |
|---|
| 133 | n/a | { |
|---|
| 134 | n/a | /* Otherwise... */ |
|---|
| 135 | n/a | |
|---|
| 136 | n/a | for( ; (i+8)<=laneCount; i+=8) { |
|---|
| 137 | n/a | ((UINT64*)state)[i+0] ^= ((UINT64*)data)[i+0]; |
|---|
| 138 | n/a | ((UINT64*)state)[i+1] ^= ((UINT64*)data)[i+1]; |
|---|
| 139 | n/a | ((UINT64*)state)[i+2] ^= ((UINT64*)data)[i+2]; |
|---|
| 140 | n/a | ((UINT64*)state)[i+3] ^= ((UINT64*)data)[i+3]; |
|---|
| 141 | n/a | ((UINT64*)state)[i+4] ^= ((UINT64*)data)[i+4]; |
|---|
| 142 | n/a | ((UINT64*)state)[i+5] ^= ((UINT64*)data)[i+5]; |
|---|
| 143 | n/a | ((UINT64*)state)[i+6] ^= ((UINT64*)data)[i+6]; |
|---|
| 144 | n/a | ((UINT64*)state)[i+7] ^= ((UINT64*)data)[i+7]; |
|---|
| 145 | n/a | } |
|---|
| 146 | n/a | for( ; (i+4)<=laneCount; i+=4) { |
|---|
| 147 | n/a | ((UINT64*)state)[i+0] ^= ((UINT64*)data)[i+0]; |
|---|
| 148 | n/a | ((UINT64*)state)[i+1] ^= ((UINT64*)data)[i+1]; |
|---|
| 149 | n/a | ((UINT64*)state)[i+2] ^= ((UINT64*)data)[i+2]; |
|---|
| 150 | n/a | ((UINT64*)state)[i+3] ^= ((UINT64*)data)[i+3]; |
|---|
| 151 | n/a | } |
|---|
| 152 | n/a | for( ; (i+2)<=laneCount; i+=2) { |
|---|
| 153 | n/a | ((UINT64*)state)[i+0] ^= ((UINT64*)data)[i+0]; |
|---|
| 154 | n/a | ((UINT64*)state)[i+1] ^= ((UINT64*)data)[i+1]; |
|---|
| 155 | n/a | } |
|---|
| 156 | n/a | if (i<laneCount) { |
|---|
| 157 | n/a | ((UINT64*)state)[i+0] ^= ((UINT64*)data)[i+0]; |
|---|
| 158 | n/a | } |
|---|
| 159 | n/a | } |
|---|
| 160 | n/a | #else |
|---|
| 161 | n/a | unsigned int i; |
|---|
| 162 | n/a | UINT8 *curData = data; |
|---|
| 163 | n/a | for(i=0; i<laneCount; i++, curData+=8) { |
|---|
| 164 | n/a | UINT64 lane = (UINT64)curData[0] |
|---|
| 165 | n/a | | ((UINT64)curData[1] << 8) |
|---|
| 166 | n/a | | ((UINT64)curData[2] << 16) |
|---|
| 167 | n/a | | ((UINT64)curData[3] << 24) |
|---|
| 168 | n/a | | ((UINT64)curData[4] <<32) |
|---|
| 169 | n/a | | ((UINT64)curData[5] << 40) |
|---|
| 170 | n/a | | ((UINT64)curData[6] << 48) |
|---|
| 171 | n/a | | ((UINT64)curData[7] << 56); |
|---|
| 172 | n/a | ((UINT64*)state)[i] ^= lane; |
|---|
| 173 | n/a | } |
|---|
| 174 | n/a | #endif |
|---|
| 175 | n/a | } |
|---|
| 176 | n/a | |
|---|
| 177 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 178 | n/a | |
|---|
| 179 | n/a | #if (PLATFORM_BYTE_ORDER != IS_LITTLE_ENDIAN) |
|---|
| 180 | n/a | void KeccakP1600_AddByte(void *state, unsigned char byte, unsigned int offset) |
|---|
| 181 | n/a | { |
|---|
| 182 | n/a | UINT64 lane = byte; |
|---|
| 183 | n/a | lane <<= (offset%8)*8; |
|---|
| 184 | n/a | ((UINT64*)state)[offset/8] ^= lane; |
|---|
| 185 | n/a | } |
|---|
| 186 | n/a | #endif |
|---|
| 187 | n/a | |
|---|
| 188 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 189 | n/a | |
|---|
| 190 | n/a | void KeccakP1600_AddBytes(void *state, const unsigned char *data, unsigned int offset, unsigned int length) |
|---|
| 191 | n/a | { |
|---|
| 192 | n/a | SnP_AddBytes(state, data, offset, length, KeccakP1600_AddLanes, KeccakP1600_AddBytesInLane, 8); |
|---|
| 193 | n/a | } |
|---|
| 194 | n/a | |
|---|
| 195 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 196 | n/a | |
|---|
| 197 | n/a | void KeccakP1600_OverwriteBytesInLane(void *state, unsigned int lanePosition, const unsigned char *data, unsigned int offset, unsigned int length) |
|---|
| 198 | n/a | { |
|---|
| 199 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 200 | n/a | #ifdef KeccakP1600_useLaneComplementing |
|---|
| 201 | n/a | if ((lanePosition == 1) || (lanePosition == 2) || (lanePosition == 8) || (lanePosition == 12) || (lanePosition == 17) || (lanePosition == 20)) { |
|---|
| 202 | n/a | unsigned int i; |
|---|
| 203 | n/a | for(i=0; i<length; i++) |
|---|
| 204 | n/a | ((unsigned char*)state)[lanePosition*8+offset+i] = ~data[i]; |
|---|
| 205 | n/a | } |
|---|
| 206 | n/a | else |
|---|
| 207 | n/a | #endif |
|---|
| 208 | n/a | { |
|---|
| 209 | n/a | memcpy((unsigned char*)state+lanePosition*8+offset, data, length); |
|---|
| 210 | n/a | } |
|---|
| 211 | n/a | #else |
|---|
| 212 | n/a | #error "Not yet implemented" |
|---|
| 213 | n/a | #endif |
|---|
| 214 | n/a | } |
|---|
| 215 | n/a | |
|---|
| 216 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 217 | n/a | |
|---|
| 218 | n/a | void KeccakP1600_OverwriteLanes(void *state, const unsigned char *data, unsigned int laneCount) |
|---|
| 219 | n/a | { |
|---|
| 220 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 221 | n/a | #ifdef KeccakP1600_useLaneComplementing |
|---|
| 222 | n/a | unsigned int lanePosition; |
|---|
| 223 | n/a | |
|---|
| 224 | n/a | for(lanePosition=0; lanePosition<laneCount; lanePosition++) |
|---|
| 225 | n/a | if ((lanePosition == 1) || (lanePosition == 2) || (lanePosition == 8) || (lanePosition == 12) || (lanePosition == 17) || (lanePosition == 20)) |
|---|
| 226 | n/a | ((UINT64*)state)[lanePosition] = ~((const UINT64*)data)[lanePosition]; |
|---|
| 227 | n/a | else |
|---|
| 228 | n/a | ((UINT64*)state)[lanePosition] = ((const UINT64*)data)[lanePosition]; |
|---|
| 229 | n/a | #else |
|---|
| 230 | n/a | memcpy(state, data, laneCount*8); |
|---|
| 231 | n/a | #endif |
|---|
| 232 | n/a | #else |
|---|
| 233 | n/a | #error "Not yet implemented" |
|---|
| 234 | n/a | #endif |
|---|
| 235 | n/a | } |
|---|
| 236 | n/a | |
|---|
| 237 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 238 | n/a | |
|---|
| 239 | n/a | void KeccakP1600_OverwriteBytes(void *state, const unsigned char *data, unsigned int offset, unsigned int length) |
|---|
| 240 | n/a | { |
|---|
| 241 | n/a | SnP_OverwriteBytes(state, data, offset, length, KeccakP1600_OverwriteLanes, KeccakP1600_OverwriteBytesInLane, 8); |
|---|
| 242 | n/a | } |
|---|
| 243 | n/a | |
|---|
| 244 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 245 | n/a | |
|---|
| 246 | n/a | void KeccakP1600_OverwriteWithZeroes(void *state, unsigned int byteCount) |
|---|
| 247 | n/a | { |
|---|
| 248 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 249 | n/a | #ifdef KeccakP1600_useLaneComplementing |
|---|
| 250 | n/a | unsigned int lanePosition; |
|---|
| 251 | n/a | |
|---|
| 252 | n/a | for(lanePosition=0; lanePosition<byteCount/8; lanePosition++) |
|---|
| 253 | n/a | if ((lanePosition == 1) || (lanePosition == 2) || (lanePosition == 8) || (lanePosition == 12) || (lanePosition == 17) || (lanePosition == 20)) |
|---|
| 254 | n/a | ((UINT64*)state)[lanePosition] = ~0; |
|---|
| 255 | n/a | else |
|---|
| 256 | n/a | ((UINT64*)state)[lanePosition] = 0; |
|---|
| 257 | n/a | if (byteCount%8 != 0) { |
|---|
| 258 | n/a | lanePosition = byteCount/8; |
|---|
| 259 | n/a | if ((lanePosition == 1) || (lanePosition == 2) || (lanePosition == 8) || (lanePosition == 12) || (lanePosition == 17) || (lanePosition == 20)) |
|---|
| 260 | n/a | memset((unsigned char*)state+lanePosition*8, 0xFF, byteCount%8); |
|---|
| 261 | n/a | else |
|---|
| 262 | n/a | memset((unsigned char*)state+lanePosition*8, 0, byteCount%8); |
|---|
| 263 | n/a | } |
|---|
| 264 | n/a | #else |
|---|
| 265 | n/a | memset(state, 0, byteCount); |
|---|
| 266 | n/a | #endif |
|---|
| 267 | n/a | #else |
|---|
| 268 | n/a | #error "Not yet implemented" |
|---|
| 269 | n/a | #endif |
|---|
| 270 | n/a | } |
|---|
| 271 | n/a | |
|---|
| 272 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 273 | n/a | |
|---|
| 274 | n/a | void KeccakP1600_Permute_24rounds(void *state) |
|---|
| 275 | n/a | { |
|---|
| 276 | n/a | declareABCDE |
|---|
| 277 | n/a | #ifndef KeccakP1600_fullUnrolling |
|---|
| 278 | n/a | unsigned int i; |
|---|
| 279 | n/a | #endif |
|---|
| 280 | n/a | UINT64 *stateAsLanes = (UINT64*)state; |
|---|
| 281 | n/a | |
|---|
| 282 | n/a | copyFromState(A, stateAsLanes) |
|---|
| 283 | n/a | rounds24 |
|---|
| 284 | n/a | copyToState(stateAsLanes, A) |
|---|
| 285 | n/a | } |
|---|
| 286 | n/a | |
|---|
| 287 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 288 | n/a | |
|---|
| 289 | n/a | void KeccakP1600_Permute_12rounds(void *state) |
|---|
| 290 | n/a | { |
|---|
| 291 | n/a | declareABCDE |
|---|
| 292 | n/a | #ifndef KeccakP1600_fullUnrolling |
|---|
| 293 | n/a | unsigned int i; |
|---|
| 294 | n/a | #endif |
|---|
| 295 | n/a | UINT64 *stateAsLanes = (UINT64*)state; |
|---|
| 296 | n/a | |
|---|
| 297 | n/a | copyFromState(A, stateAsLanes) |
|---|
| 298 | n/a | rounds12 |
|---|
| 299 | n/a | copyToState(stateAsLanes, A) |
|---|
| 300 | n/a | } |
|---|
| 301 | n/a | |
|---|
| 302 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 303 | n/a | |
|---|
| 304 | n/a | void KeccakP1600_ExtractBytesInLane(const void *state, unsigned int lanePosition, unsigned char *data, unsigned int offset, unsigned int length) |
|---|
| 305 | n/a | { |
|---|
| 306 | n/a | UINT64 lane = ((UINT64*)state)[lanePosition]; |
|---|
| 307 | n/a | #ifdef KeccakP1600_useLaneComplementing |
|---|
| 308 | n/a | if ((lanePosition == 1) || (lanePosition == 2) || (lanePosition == 8) || (lanePosition == 12) || (lanePosition == 17) || (lanePosition == 20)) |
|---|
| 309 | n/a | lane = ~lane; |
|---|
| 310 | n/a | #endif |
|---|
| 311 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 312 | n/a | { |
|---|
| 313 | n/a | UINT64 lane1[1]; |
|---|
| 314 | n/a | lane1[0] = lane; |
|---|
| 315 | n/a | memcpy(data, (UINT8*)lane1+offset, length); |
|---|
| 316 | n/a | } |
|---|
| 317 | n/a | #else |
|---|
| 318 | n/a | unsigned int i; |
|---|
| 319 | n/a | lane >>= offset*8; |
|---|
| 320 | n/a | for(i=0; i<length; i++) { |
|---|
| 321 | n/a | data[i] = lane & 0xFF; |
|---|
| 322 | n/a | lane >>= 8; |
|---|
| 323 | n/a | } |
|---|
| 324 | n/a | #endif |
|---|
| 325 | n/a | } |
|---|
| 326 | n/a | |
|---|
| 327 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 328 | n/a | |
|---|
| 329 | n/a | #if (PLATFORM_BYTE_ORDER != IS_LITTLE_ENDIAN) |
|---|
| 330 | n/a | void fromWordToBytes(UINT8 *bytes, const UINT64 word) |
|---|
| 331 | n/a | { |
|---|
| 332 | n/a | unsigned int i; |
|---|
| 333 | n/a | |
|---|
| 334 | n/a | for(i=0; i<(64/8); i++) |
|---|
| 335 | n/a | bytes[i] = (word >> (8*i)) & 0xFF; |
|---|
| 336 | n/a | } |
|---|
| 337 | n/a | #endif |
|---|
| 338 | n/a | |
|---|
| 339 | n/a | void KeccakP1600_ExtractLanes(const void *state, unsigned char *data, unsigned int laneCount) |
|---|
| 340 | n/a | { |
|---|
| 341 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 342 | n/a | memcpy(data, state, laneCount*8); |
|---|
| 343 | n/a | #else |
|---|
| 344 | n/a | unsigned int i; |
|---|
| 345 | n/a | |
|---|
| 346 | n/a | for(i=0; i<laneCount; i++) |
|---|
| 347 | n/a | fromWordToBytes(data+(i*8), ((const UINT64*)state)[i]); |
|---|
| 348 | n/a | #endif |
|---|
| 349 | n/a | #ifdef KeccakP1600_useLaneComplementing |
|---|
| 350 | n/a | if (laneCount > 1) { |
|---|
| 351 | n/a | ((UINT64*)data)[ 1] = ~((UINT64*)data)[ 1]; |
|---|
| 352 | n/a | if (laneCount > 2) { |
|---|
| 353 | n/a | ((UINT64*)data)[ 2] = ~((UINT64*)data)[ 2]; |
|---|
| 354 | n/a | if (laneCount > 8) { |
|---|
| 355 | n/a | ((UINT64*)data)[ 8] = ~((UINT64*)data)[ 8]; |
|---|
| 356 | n/a | if (laneCount > 12) { |
|---|
| 357 | n/a | ((UINT64*)data)[12] = ~((UINT64*)data)[12]; |
|---|
| 358 | n/a | if (laneCount > 17) { |
|---|
| 359 | n/a | ((UINT64*)data)[17] = ~((UINT64*)data)[17]; |
|---|
| 360 | n/a | if (laneCount > 20) { |
|---|
| 361 | n/a | ((UINT64*)data)[20] = ~((UINT64*)data)[20]; |
|---|
| 362 | n/a | } |
|---|
| 363 | n/a | } |
|---|
| 364 | n/a | } |
|---|
| 365 | n/a | } |
|---|
| 366 | n/a | } |
|---|
| 367 | n/a | } |
|---|
| 368 | n/a | #endif |
|---|
| 369 | n/a | } |
|---|
| 370 | n/a | |
|---|
| 371 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 372 | n/a | |
|---|
| 373 | n/a | void KeccakP1600_ExtractBytes(const void *state, unsigned char *data, unsigned int offset, unsigned int length) |
|---|
| 374 | n/a | { |
|---|
| 375 | n/a | SnP_ExtractBytes(state, data, offset, length, KeccakP1600_ExtractLanes, KeccakP1600_ExtractBytesInLane, 8); |
|---|
| 376 | n/a | } |
|---|
| 377 | n/a | |
|---|
| 378 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 379 | n/a | |
|---|
| 380 | n/a | void KeccakP1600_ExtractAndAddBytesInLane(const void *state, unsigned int lanePosition, const unsigned char *input, unsigned char *output, unsigned int offset, unsigned int length) |
|---|
| 381 | n/a | { |
|---|
| 382 | n/a | UINT64 lane = ((UINT64*)state)[lanePosition]; |
|---|
| 383 | n/a | #ifdef KeccakP1600_useLaneComplementing |
|---|
| 384 | n/a | if ((lanePosition == 1) || (lanePosition == 2) || (lanePosition == 8) || (lanePosition == 12) || (lanePosition == 17) || (lanePosition == 20)) |
|---|
| 385 | n/a | lane = ~lane; |
|---|
| 386 | n/a | #endif |
|---|
| 387 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 388 | n/a | { |
|---|
| 389 | n/a | unsigned int i; |
|---|
| 390 | n/a | UINT64 lane1[1]; |
|---|
| 391 | n/a | lane1[0] = lane; |
|---|
| 392 | n/a | for(i=0; i<length; i++) |
|---|
| 393 | n/a | output[i] = input[i] ^ ((UINT8*)lane1)[offset+i]; |
|---|
| 394 | n/a | } |
|---|
| 395 | n/a | #else |
|---|
| 396 | n/a | unsigned int i; |
|---|
| 397 | n/a | lane >>= offset*8; |
|---|
| 398 | n/a | for(i=0; i<length; i++) { |
|---|
| 399 | n/a | output[i] = input[i] ^ (lane & 0xFF); |
|---|
| 400 | n/a | lane >>= 8; |
|---|
| 401 | n/a | } |
|---|
| 402 | n/a | #endif |
|---|
| 403 | n/a | } |
|---|
| 404 | n/a | |
|---|
| 405 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 406 | n/a | |
|---|
| 407 | n/a | void KeccakP1600_ExtractAndAddLanes(const void *state, const unsigned char *input, unsigned char *output, unsigned int laneCount) |
|---|
| 408 | n/a | { |
|---|
| 409 | n/a | unsigned int i; |
|---|
| 410 | n/a | #if (PLATFORM_BYTE_ORDER != IS_LITTLE_ENDIAN) |
|---|
| 411 | n/a | unsigned char temp[8]; |
|---|
| 412 | n/a | unsigned int j; |
|---|
| 413 | n/a | #endif |
|---|
| 414 | n/a | |
|---|
| 415 | n/a | for(i=0; i<laneCount; i++) { |
|---|
| 416 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
|---|
| 417 | n/a | ((UINT64*)output)[i] = ((UINT64*)input)[i] ^ ((const UINT64*)state)[i]; |
|---|
| 418 | n/a | #else |
|---|
| 419 | n/a | fromWordToBytes(temp, ((const UINT64*)state)[i]); |
|---|
| 420 | n/a | for(j=0; j<8; j++) |
|---|
| 421 | n/a | output[i*8+j] = input[i*8+j] ^ temp[j]; |
|---|
| 422 | n/a | #endif |
|---|
| 423 | n/a | } |
|---|
| 424 | n/a | #ifdef KeccakP1600_useLaneComplementing |
|---|
| 425 | n/a | if (laneCount > 1) { |
|---|
| 426 | n/a | ((UINT64*)output)[ 1] = ~((UINT64*)output)[ 1]; |
|---|
| 427 | n/a | if (laneCount > 2) { |
|---|
| 428 | n/a | ((UINT64*)output)[ 2] = ~((UINT64*)output)[ 2]; |
|---|
| 429 | n/a | if (laneCount > 8) { |
|---|
| 430 | n/a | ((UINT64*)output)[ 8] = ~((UINT64*)output)[ 8]; |
|---|
| 431 | n/a | if (laneCount > 12) { |
|---|
| 432 | n/a | ((UINT64*)output)[12] = ~((UINT64*)output)[12]; |
|---|
| 433 | n/a | if (laneCount > 17) { |
|---|
| 434 | n/a | ((UINT64*)output)[17] = ~((UINT64*)output)[17]; |
|---|
| 435 | n/a | if (laneCount > 20) { |
|---|
| 436 | n/a | ((UINT64*)output)[20] = ~((UINT64*)output)[20]; |
|---|
| 437 | n/a | } |
|---|
| 438 | n/a | } |
|---|
| 439 | n/a | } |
|---|
| 440 | n/a | } |
|---|
| 441 | n/a | } |
|---|
| 442 | n/a | } |
|---|
| 443 | n/a | #endif |
|---|
| 444 | n/a | } |
|---|
| 445 | n/a | |
|---|
| 446 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 447 | n/a | |
|---|
| 448 | n/a | void KeccakP1600_ExtractAndAddBytes(const void *state, const unsigned char *input, unsigned char *output, unsigned int offset, unsigned int length) |
|---|
| 449 | n/a | { |
|---|
| 450 | n/a | SnP_ExtractAndAddBytes(state, input, output, offset, length, KeccakP1600_ExtractAndAddLanes, KeccakP1600_ExtractAndAddBytesInLane, 8); |
|---|
| 451 | n/a | } |
|---|
| 452 | n/a | |
|---|
| 453 | n/a | /* ---------------------------------------------------------------- */ |
|---|
| 454 | n/a | |
|---|
| 455 | n/a | size_t KeccakF1600_FastLoop_Absorb(void *state, unsigned int laneCount, const unsigned char *data, size_t dataByteLen) |
|---|
| 456 | n/a | { |
|---|
| 457 | n/a | size_t originalDataByteLen = dataByteLen; |
|---|
| 458 | n/a | declareABCDE |
|---|
| 459 | n/a | #ifndef KeccakP1600_fullUnrolling |
|---|
| 460 | n/a | unsigned int i; |
|---|
| 461 | n/a | #endif |
|---|
| 462 | n/a | UINT64 *stateAsLanes = (UINT64*)state; |
|---|
| 463 | n/a | UINT64 *inDataAsLanes = (UINT64*)data; |
|---|
| 464 | n/a | |
|---|
| 465 | n/a | copyFromState(A, stateAsLanes) |
|---|
| 466 | n/a | while(dataByteLen >= laneCount*8) { |
|---|
| 467 | n/a | addInput(A, inDataAsLanes, laneCount) |
|---|
| 468 | n/a | rounds24 |
|---|
| 469 | n/a | inDataAsLanes += laneCount; |
|---|
| 470 | n/a | dataByteLen -= laneCount*8; |
|---|
| 471 | n/a | } |
|---|
| 472 | n/a | copyToState(stateAsLanes, A) |
|---|
| 473 | n/a | return originalDataByteLen - dataByteLen; |
|---|
| 474 | n/a | } |
|---|