1 | n/a | /* |
---|
2 | n/a | The Keccak sponge function, designed by Guido Bertoni, Joan Daemen, |
---|
3 | n/a | Michaël Peeters and Gilles Van Assche. For more information, feedback or |
---|
4 | n/a | questions, please refer to our website: http://keccak.noekeon.org/ |
---|
5 | n/a | |
---|
6 | n/a | Implementation by the designers, |
---|
7 | n/a | hereby denoted as "the implementer". |
---|
8 | n/a | |
---|
9 | n/a | To the extent possible under law, the implementer has waived all copyright |
---|
10 | n/a | and related or neighboring rights to the source code in this file. |
---|
11 | n/a | http://creativecommons.org/publicdomain/zero/1.0/ |
---|
12 | n/a | */ |
---|
13 | n/a | |
---|
14 | n/a | #include <string.h> |
---|
15 | n/a | /* #include "brg_endian.h" */ |
---|
16 | n/a | #include "KeccakF-1600-opt32-settings.h" |
---|
17 | n/a | #include "KeccakF-1600-interface.h" |
---|
18 | n/a | |
---|
19 | n/a | typedef unsigned char UINT8; |
---|
20 | n/a | typedef unsigned short UINT16; |
---|
21 | n/a | typedef unsigned int UINT32; |
---|
22 | n/a | /* typedef unsigned long long int UINT64; */ |
---|
23 | n/a | |
---|
24 | n/a | #ifdef UseInterleaveTables |
---|
25 | n/a | static int interleaveTablesBuilt = 0; |
---|
26 | n/a | static UINT16 interleaveTable[65536]; |
---|
27 | n/a | static UINT16 deinterleaveTable[65536]; |
---|
28 | n/a | |
---|
29 | n/a | static void buildInterleaveTables() |
---|
30 | n/a | { |
---|
31 | n/a | UINT32 i, j; |
---|
32 | n/a | UINT16 x; |
---|
33 | n/a | |
---|
34 | n/a | if (!interleaveTablesBuilt) { |
---|
35 | n/a | for(i=0; i<65536; i++) { |
---|
36 | n/a | x = 0; |
---|
37 | n/a | for(j=0; j<16; j++) { |
---|
38 | n/a | if (i & (1 << j)) |
---|
39 | n/a | x |= (1 << (j/2 + 8*(j%2))); |
---|
40 | n/a | } |
---|
41 | n/a | interleaveTable[i] = x; |
---|
42 | n/a | deinterleaveTable[x] = (UINT16)i; |
---|
43 | n/a | } |
---|
44 | n/a | interleaveTablesBuilt = 1; |
---|
45 | n/a | } |
---|
46 | n/a | } |
---|
47 | n/a | |
---|
48 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
---|
49 | n/a | |
---|
50 | n/a | #define xor2bytesIntoInterleavedWords(even, odd, source, j) \ |
---|
51 | n/a | i##j = interleaveTable[((const UINT16*)source)[j]]; \ |
---|
52 | n/a | ((UINT8*)even)[j] ^= i##j & 0xFF; \ |
---|
53 | n/a | ((UINT8*)odd)[j] ^= i##j >> 8; |
---|
54 | n/a | |
---|
55 | n/a | #define setInterleavedWordsInto2bytes(dest, even, odd, j) \ |
---|
56 | n/a | d##j = deinterleaveTable[((even >> (j*8)) & 0xFF) ^ (((odd >> (j*8)) & 0xFF) << 8)]; \ |
---|
57 | n/a | ((UINT16*)dest)[j] = d##j; |
---|
58 | n/a | |
---|
59 | n/a | #else /* (PLATFORM_BYTE_ORDER == IS_BIG_ENDIAN) */ |
---|
60 | n/a | |
---|
61 | n/a | #define xor2bytesIntoInterleavedWords(even, odd, source, j) \ |
---|
62 | n/a | i##j = interleaveTable[source[2*j] ^ ((UINT16)source[2*j+1] << 8)]; \ |
---|
63 | n/a | *even ^= (i##j & 0xFF) << (j*8); \ |
---|
64 | n/a | *odd ^= ((i##j >> 8) & 0xFF) << (j*8); |
---|
65 | n/a | |
---|
66 | n/a | #define setInterleavedWordsInto2bytes(dest, even, odd, j) \ |
---|
67 | n/a | d##j = deinterleaveTable[((even >> (j*8)) & 0xFF) ^ (((odd >> (j*8)) & 0xFF) << 8)]; \ |
---|
68 | n/a | dest[2*j] = d##j & 0xFF; \ |
---|
69 | n/a | dest[2*j+1] = d##j >> 8; |
---|
70 | n/a | |
---|
71 | n/a | #endif /* Endianness */ |
---|
72 | n/a | |
---|
73 | n/a | static void xor8bytesIntoInterleavedWords(UINT32 *even, UINT32 *odd, const UINT8* source) |
---|
74 | n/a | { |
---|
75 | n/a | UINT16 i0, i1, i2, i3; |
---|
76 | n/a | |
---|
77 | n/a | xor2bytesIntoInterleavedWords(even, odd, source, 0) |
---|
78 | n/a | xor2bytesIntoInterleavedWords(even, odd, source, 1) |
---|
79 | n/a | xor2bytesIntoInterleavedWords(even, odd, source, 2) |
---|
80 | n/a | xor2bytesIntoInterleavedWords(even, odd, source, 3) |
---|
81 | n/a | } |
---|
82 | n/a | |
---|
83 | n/a | #define xorLanesIntoState(laneCount, state, input) \ |
---|
84 | n/a | { \ |
---|
85 | n/a | int i; \ |
---|
86 | n/a | for(i=0; i<(laneCount); i++) \ |
---|
87 | n/a | xor8bytesIntoInterleavedWords(state+i*2, state+i*2+1, input+i*8); \ |
---|
88 | n/a | } |
---|
89 | n/a | |
---|
90 | n/a | static void setInterleavedWordsInto8bytes(UINT8* dest, UINT32 even, UINT32 odd) |
---|
91 | n/a | { |
---|
92 | n/a | UINT16 d0, d1, d2, d3; |
---|
93 | n/a | |
---|
94 | n/a | setInterleavedWordsInto2bytes(dest, even, odd, 0) |
---|
95 | n/a | setInterleavedWordsInto2bytes(dest, even, odd, 1) |
---|
96 | n/a | setInterleavedWordsInto2bytes(dest, even, odd, 2) |
---|
97 | n/a | setInterleavedWordsInto2bytes(dest, even, odd, 3) |
---|
98 | n/a | } |
---|
99 | n/a | |
---|
100 | n/a | #define extractLanes(laneCount, state, data) \ |
---|
101 | n/a | { \ |
---|
102 | n/a | int i; \ |
---|
103 | n/a | for(i=0; i<(laneCount); i++) \ |
---|
104 | n/a | setInterleavedWordsInto8bytes(data+i*8, ((UINT32*)state)[i*2], ((UINT32*)state)[i*2+1]); \ |
---|
105 | n/a | } |
---|
106 | n/a | |
---|
107 | n/a | #else /* No interleaving tables */ |
---|
108 | n/a | |
---|
109 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
---|
110 | n/a | |
---|
111 | n/a | /* Credit: Henry S. Warren, Hacker's Delight, Addison-Wesley, 2002 */ |
---|
112 | n/a | #define xorInterleavedLE(rateInLanes, state, input) \ |
---|
113 | n/a | { \ |
---|
114 | n/a | const UINT32 * pI = (const UINT32 *)input; \ |
---|
115 | n/a | UINT32 * pS = state; \ |
---|
116 | n/a | UINT32 t, x0, x1; \ |
---|
117 | n/a | int i; \ |
---|
118 | n/a | for (i = (rateInLanes)-1; i >= 0; --i) \ |
---|
119 | n/a | { \ |
---|
120 | n/a | x0 = *(pI++); \ |
---|
121 | n/a | t = (x0 ^ (x0 >> 1)) & 0x22222222UL; x0 = x0 ^ t ^ (t << 1); \ |
---|
122 | n/a | t = (x0 ^ (x0 >> 2)) & 0x0C0C0C0CUL; x0 = x0 ^ t ^ (t << 2); \ |
---|
123 | n/a | t = (x0 ^ (x0 >> 4)) & 0x00F000F0UL; x0 = x0 ^ t ^ (t << 4); \ |
---|
124 | n/a | t = (x0 ^ (x0 >> 8)) & 0x0000FF00UL; x0 = x0 ^ t ^ (t << 8); \ |
---|
125 | n/a | x1 = *(pI++); \ |
---|
126 | n/a | t = (x1 ^ (x1 >> 1)) & 0x22222222UL; x1 = x1 ^ t ^ (t << 1); \ |
---|
127 | n/a | t = (x1 ^ (x1 >> 2)) & 0x0C0C0C0CUL; x1 = x1 ^ t ^ (t << 2); \ |
---|
128 | n/a | t = (x1 ^ (x1 >> 4)) & 0x00F000F0UL; x1 = x1 ^ t ^ (t << 4); \ |
---|
129 | n/a | t = (x1 ^ (x1 >> 8)) & 0x0000FF00UL; x1 = x1 ^ t ^ (t << 8); \ |
---|
130 | n/a | *(pS++) ^= (UINT16)x0 | (x1 << 16); \ |
---|
131 | n/a | *(pS++) ^= (x0 >> 16) | (x1 & 0xFFFF0000); \ |
---|
132 | n/a | } \ |
---|
133 | n/a | } |
---|
134 | n/a | |
---|
135 | n/a | #define xorLanesIntoState(laneCount, state, input) \ |
---|
136 | n/a | xorInterleavedLE(laneCount, state, input) |
---|
137 | n/a | |
---|
138 | n/a | #else /* (PLATFORM_BYTE_ORDER == IS_BIG_ENDIAN) */ |
---|
139 | n/a | |
---|
140 | n/a | /* Credit: Henry S. Warren, Hacker's Delight, Addison-Wesley, 2002 */ |
---|
141 | n/a | UINT64 toInterleaving(UINT64 x) |
---|
142 | n/a | { |
---|
143 | n/a | UINT64 t; |
---|
144 | n/a | |
---|
145 | n/a | t = (x ^ (x >> 1)) & 0x2222222222222222ULL; x = x ^ t ^ (t << 1); |
---|
146 | n/a | t = (x ^ (x >> 2)) & 0x0C0C0C0C0C0C0C0CULL; x = x ^ t ^ (t << 2); |
---|
147 | n/a | t = (x ^ (x >> 4)) & 0x00F000F000F000F0ULL; x = x ^ t ^ (t << 4); |
---|
148 | n/a | t = (x ^ (x >> 8)) & 0x0000FF000000FF00ULL; x = x ^ t ^ (t << 8); |
---|
149 | n/a | t = (x ^ (x >> 16)) & 0x00000000FFFF0000ULL; x = x ^ t ^ (t << 16); |
---|
150 | n/a | |
---|
151 | n/a | return x; |
---|
152 | n/a | } |
---|
153 | n/a | |
---|
154 | n/a | static void xor8bytesIntoInterleavedWords(UINT32* evenAndOdd, const UINT8* source) |
---|
155 | n/a | { |
---|
156 | n/a | /* This can be optimized */ |
---|
157 | n/a | UINT64 sourceWord = |
---|
158 | n/a | (UINT64)source[0] |
---|
159 | n/a | ^ (((UINT64)source[1]) << 8) |
---|
160 | n/a | ^ (((UINT64)source[2]) << 16) |
---|
161 | n/a | ^ (((UINT64)source[3]) << 24) |
---|
162 | n/a | ^ (((UINT64)source[4]) << 32) |
---|
163 | n/a | ^ (((UINT64)source[5]) << 40) |
---|
164 | n/a | ^ (((UINT64)source[6]) << 48) |
---|
165 | n/a | ^ (((UINT64)source[7]) << 56); |
---|
166 | n/a | UINT64 evenAndOddWord = toInterleaving(sourceWord); |
---|
167 | n/a | evenAndOdd[0] ^= (UINT32)evenAndOddWord; |
---|
168 | n/a | evenAndOdd[1] ^= (UINT32)(evenAndOddWord >> 32); |
---|
169 | n/a | } |
---|
170 | n/a | |
---|
171 | n/a | #define xorLanesIntoState(laneCount, state, input) \ |
---|
172 | n/a | { \ |
---|
173 | n/a | int i; \ |
---|
174 | n/a | for(i=0; i<(laneCount); i++) \ |
---|
175 | n/a | xor8bytesIntoInterleavedWords(state+i*2, input+i*8); \ |
---|
176 | n/a | } |
---|
177 | n/a | |
---|
178 | n/a | #endif /* Endianness */ |
---|
179 | n/a | |
---|
180 | n/a | /* Credit: Henry S. Warren, Hacker's Delight, Addison-Wesley, 2002 */ |
---|
181 | n/a | UINT64 fromInterleaving(UINT64 x) |
---|
182 | n/a | { |
---|
183 | n/a | UINT64 t; |
---|
184 | n/a | |
---|
185 | n/a | t = (x ^ (x >> 16)) & 0x00000000FFFF0000ULL; x = x ^ t ^ (t << 16); |
---|
186 | n/a | t = (x ^ (x >> 8)) & 0x0000FF000000FF00ULL; x = x ^ t ^ (t << 8); |
---|
187 | n/a | t = (x ^ (x >> 4)) & 0x00F000F000F000F0ULL; x = x ^ t ^ (t << 4); |
---|
188 | n/a | t = (x ^ (x >> 2)) & 0x0C0C0C0C0C0C0C0CULL; x = x ^ t ^ (t << 2); |
---|
189 | n/a | t = (x ^ (x >> 1)) & 0x2222222222222222ULL; x = x ^ t ^ (t << 1); |
---|
190 | n/a | |
---|
191 | n/a | return x; |
---|
192 | n/a | } |
---|
193 | n/a | |
---|
194 | n/a | static void setInterleavedWordsInto8bytes(UINT8* dest, UINT32* evenAndOdd) |
---|
195 | n/a | { |
---|
196 | n/a | #if (PLATFORM_BYTE_ORDER == IS_LITTLE_ENDIAN) |
---|
197 | n/a | ((UINT64*)dest)[0] = fromInterleaving(*(UINT64*)evenAndOdd); |
---|
198 | n/a | #else /* (PLATFORM_BYTE_ORDER == IS_BIG_ENDIAN) */ |
---|
199 | n/a | /* This can be optimized */ |
---|
200 | n/a | UINT64 evenAndOddWord = (UINT64)evenAndOdd[0] ^ ((UINT64)evenAndOdd[1] << 32); |
---|
201 | n/a | UINT64 destWord = fromInterleaving(evenAndOddWord); |
---|
202 | n/a | dest[0] = destWord & 0xFF; |
---|
203 | n/a | dest[1] = (destWord >> 8) & 0xFF; |
---|
204 | n/a | dest[2] = (destWord >> 16) & 0xFF; |
---|
205 | n/a | dest[3] = (destWord >> 24) & 0xFF; |
---|
206 | n/a | dest[4] = (destWord >> 32) & 0xFF; |
---|
207 | n/a | dest[5] = (destWord >> 40) & 0xFF; |
---|
208 | n/a | dest[6] = (destWord >> 48) & 0xFF; |
---|
209 | n/a | dest[7] = (destWord >> 56) & 0xFF; |
---|
210 | n/a | #endif /* Endianness */ |
---|
211 | n/a | } |
---|
212 | n/a | |
---|
213 | n/a | #define extractLanes(laneCount, state, data) \ |
---|
214 | n/a | { \ |
---|
215 | n/a | int i; \ |
---|
216 | n/a | for(i=0; i<(laneCount); i++) \ |
---|
217 | n/a | setInterleavedWordsInto8bytes(data+i*8, (UINT32*)state+i*2); \ |
---|
218 | n/a | } |
---|
219 | n/a | |
---|
220 | n/a | #endif /* With or without interleaving tables */ |
---|
221 | n/a | |
---|
222 | n/a | #if defined(_MSC_VER) |
---|
223 | n/a | #define ROL32(a, offset) _rotl(a, offset) |
---|
224 | n/a | #elif (defined (__arm__) && defined(__ARMCC_VERSION)) |
---|
225 | n/a | #define ROL32(a, offset) __ror(a, 32-(offset)) |
---|
226 | n/a | #else |
---|
227 | n/a | #define ROL32(a, offset) ((((UINT32)a) << (offset)) ^ (((UINT32)a) >> (32-(offset)))) |
---|
228 | n/a | #endif |
---|
229 | n/a | |
---|
230 | n/a | #include "KeccakF-1600-unrolling.macros" |
---|
231 | n/a | #include "KeccakF-1600-32.macros" |
---|
232 | n/a | |
---|
233 | n/a | #if (UseSchedule == 3) |
---|
234 | n/a | |
---|
235 | n/a | #ifdef UseBebigokimisa |
---|
236 | n/a | #error "No lane complementing with schedule 3." |
---|
237 | n/a | #endif |
---|
238 | n/a | |
---|
239 | n/a | #if (Unrolling != 2) |
---|
240 | n/a | #error "Only unrolling 2 is supported by schedule 3." |
---|
241 | n/a | #endif |
---|
242 | n/a | |
---|
243 | n/a | static void KeccakPermutationOnWords(UINT32 *state) |
---|
244 | n/a | { |
---|
245 | n/a | rounds |
---|
246 | n/a | } |
---|
247 | n/a | |
---|
248 | n/a | static void KeccakPermutationOnWordsAfterXoring(UINT32 *state, const UINT8 *input, unsigned int laneCount) |
---|
249 | n/a | { |
---|
250 | n/a | xorLanesIntoState(laneCount, state, input) |
---|
251 | n/a | rounds |
---|
252 | n/a | } |
---|
253 | n/a | |
---|
254 | n/a | #ifdef ProvideFast576 |
---|
255 | n/a | static void KeccakPermutationOnWordsAfterXoring576bits(UINT32 *state, const UINT8 *input) |
---|
256 | n/a | { |
---|
257 | n/a | xorLanesIntoState(9, state, input) |
---|
258 | n/a | rounds |
---|
259 | n/a | } |
---|
260 | n/a | #endif |
---|
261 | n/a | |
---|
262 | n/a | #ifdef ProvideFast832 |
---|
263 | n/a | static void KeccakPermutationOnWordsAfterXoring832bits(UINT32 *state, const UINT8 *input) |
---|
264 | n/a | { |
---|
265 | n/a | xorLanesIntoState(13, state, input) |
---|
266 | n/a | rounds |
---|
267 | n/a | } |
---|
268 | n/a | #endif |
---|
269 | n/a | |
---|
270 | n/a | #ifdef ProvideFast1024 |
---|
271 | n/a | static void KeccakPermutationOnWordsAfterXoring1024bits(UINT32 *state, const UINT8 *input) |
---|
272 | n/a | { |
---|
273 | n/a | xorLanesIntoState(16, state, input) |
---|
274 | n/a | rounds |
---|
275 | n/a | } |
---|
276 | n/a | #endif |
---|
277 | n/a | |
---|
278 | n/a | #ifdef ProvideFast1088 |
---|
279 | n/a | static void KeccakPermutationOnWordsAfterXoring1088bits(UINT32 *state, const UINT8 *input) |
---|
280 | n/a | { |
---|
281 | n/a | xorLanesIntoState(17, state, input) |
---|
282 | n/a | rounds |
---|
283 | n/a | } |
---|
284 | n/a | #endif |
---|
285 | n/a | |
---|
286 | n/a | #ifdef ProvideFast1152 |
---|
287 | n/a | static void KeccakPermutationOnWordsAfterXoring1152bits(UINT32 *state, const UINT8 *input) |
---|
288 | n/a | { |
---|
289 | n/a | xorLanesIntoState(18, state, input) |
---|
290 | n/a | rounds |
---|
291 | n/a | } |
---|
292 | n/a | #endif |
---|
293 | n/a | |
---|
294 | n/a | #ifdef ProvideFast1344 |
---|
295 | n/a | static void KeccakPermutationOnWordsAfterXoring1344bits(UINT32 *state, const UINT8 *input) |
---|
296 | n/a | { |
---|
297 | n/a | xorLanesIntoState(21, state, input) |
---|
298 | n/a | rounds |
---|
299 | n/a | } |
---|
300 | n/a | #endif |
---|
301 | n/a | |
---|
302 | n/a | #else /* (Schedule != 3) */ |
---|
303 | n/a | |
---|
304 | n/a | static void KeccakPermutationOnWords(UINT32 *state) |
---|
305 | n/a | { |
---|
306 | n/a | declareABCDE |
---|
307 | n/a | #if (Unrolling != 24) |
---|
308 | n/a | unsigned int i; |
---|
309 | n/a | #endif |
---|
310 | n/a | |
---|
311 | n/a | copyFromState(A, state) |
---|
312 | n/a | rounds |
---|
313 | n/a | } |
---|
314 | n/a | |
---|
315 | n/a | static void KeccakPermutationOnWordsAfterXoring(UINT32 *state, const UINT8 *input, unsigned int laneCount) |
---|
316 | n/a | { |
---|
317 | n/a | declareABCDE |
---|
318 | n/a | unsigned int i; |
---|
319 | n/a | |
---|
320 | n/a | xorLanesIntoState(laneCount, state, input) |
---|
321 | n/a | copyFromState(A, state) |
---|
322 | n/a | rounds |
---|
323 | n/a | } |
---|
324 | n/a | |
---|
325 | n/a | #ifdef ProvideFast576 |
---|
326 | n/a | static void KeccakPermutationOnWordsAfterXoring576bits(UINT32 *state, const UINT8 *input) |
---|
327 | n/a | { |
---|
328 | n/a | declareABCDE |
---|
329 | n/a | unsigned int i; |
---|
330 | n/a | |
---|
331 | n/a | xorLanesIntoState(9, state, input) |
---|
332 | n/a | copyFromState(A, state) |
---|
333 | n/a | rounds |
---|
334 | n/a | } |
---|
335 | n/a | #endif |
---|
336 | n/a | |
---|
337 | n/a | #ifdef ProvideFast832 |
---|
338 | n/a | static void KeccakPermutationOnWordsAfterXoring832bits(UINT32 *state, const UINT8 *input) |
---|
339 | n/a | { |
---|
340 | n/a | declareABCDE |
---|
341 | n/a | unsigned int i; |
---|
342 | n/a | |
---|
343 | n/a | xorLanesIntoState(13, state, input) |
---|
344 | n/a | copyFromState(A, state) |
---|
345 | n/a | rounds |
---|
346 | n/a | } |
---|
347 | n/a | #endif |
---|
348 | n/a | |
---|
349 | n/a | #ifdef ProvideFast1024 |
---|
350 | n/a | static void KeccakPermutationOnWordsAfterXoring1024bits(UINT32 *state, const UINT8 *input) |
---|
351 | n/a | { |
---|
352 | n/a | declareABCDE |
---|
353 | n/a | unsigned int i; |
---|
354 | n/a | |
---|
355 | n/a | xorLanesIntoState(16, state, input) |
---|
356 | n/a | copyFromState(A, state) |
---|
357 | n/a | rounds |
---|
358 | n/a | } |
---|
359 | n/a | #endif |
---|
360 | n/a | |
---|
361 | n/a | #ifdef ProvideFast1088 |
---|
362 | n/a | static void KeccakPermutationOnWordsAfterXoring1088bits(UINT32 *state, const UINT8 *input) |
---|
363 | n/a | { |
---|
364 | n/a | declareABCDE |
---|
365 | n/a | unsigned int i; |
---|
366 | n/a | |
---|
367 | n/a | xorLanesIntoState(17, state, input) |
---|
368 | n/a | copyFromState(A, state) |
---|
369 | n/a | rounds |
---|
370 | n/a | } |
---|
371 | n/a | #endif |
---|
372 | n/a | |
---|
373 | n/a | #ifdef ProvideFast1152 |
---|
374 | n/a | static void KeccakPermutationOnWordsAfterXoring1152bits(UINT32 *state, const UINT8 *input) |
---|
375 | n/a | { |
---|
376 | n/a | declareABCDE |
---|
377 | n/a | unsigned int i; |
---|
378 | n/a | |
---|
379 | n/a | xorLanesIntoState(18, state, input) |
---|
380 | n/a | copyFromState(A, state) |
---|
381 | n/a | rounds |
---|
382 | n/a | } |
---|
383 | n/a | #endif |
---|
384 | n/a | |
---|
385 | n/a | #ifdef ProvideFast1344 |
---|
386 | n/a | static void KeccakPermutationOnWordsAfterXoring1344bits(UINT32 *state, const UINT8 *input) |
---|
387 | n/a | { |
---|
388 | n/a | declareABCDE |
---|
389 | n/a | unsigned int i; |
---|
390 | n/a | |
---|
391 | n/a | xorLanesIntoState(21, state, input) |
---|
392 | n/a | copyFromState(A, state) |
---|
393 | n/a | rounds |
---|
394 | n/a | } |
---|
395 | n/a | #endif |
---|
396 | n/a | |
---|
397 | n/a | #endif |
---|
398 | n/a | |
---|
399 | n/a | static void KeccakInitialize() |
---|
400 | n/a | { |
---|
401 | n/a | #ifdef UseInterleaveTables |
---|
402 | n/a | buildInterleaveTables(); |
---|
403 | n/a | #endif |
---|
404 | n/a | } |
---|
405 | n/a | |
---|
406 | n/a | static void KeccakInitializeState(unsigned char *state) |
---|
407 | n/a | { |
---|
408 | n/a | memset(state, 0, 200); |
---|
409 | n/a | #ifdef UseBebigokimisa |
---|
410 | n/a | ((UINT32*)state)[ 2] = ~(UINT32)0; |
---|
411 | n/a | ((UINT32*)state)[ 3] = ~(UINT32)0; |
---|
412 | n/a | ((UINT32*)state)[ 4] = ~(UINT32)0; |
---|
413 | n/a | ((UINT32*)state)[ 5] = ~(UINT32)0; |
---|
414 | n/a | ((UINT32*)state)[16] = ~(UINT32)0; |
---|
415 | n/a | ((UINT32*)state)[17] = ~(UINT32)0; |
---|
416 | n/a | ((UINT32*)state)[24] = ~(UINT32)0; |
---|
417 | n/a | ((UINT32*)state)[25] = ~(UINT32)0; |
---|
418 | n/a | ((UINT32*)state)[34] = ~(UINT32)0; |
---|
419 | n/a | ((UINT32*)state)[35] = ~(UINT32)0; |
---|
420 | n/a | ((UINT32*)state)[40] = ~(UINT32)0; |
---|
421 | n/a | ((UINT32*)state)[41] = ~(UINT32)0; |
---|
422 | n/a | #endif |
---|
423 | n/a | } |
---|
424 | n/a | |
---|
425 | n/a | static void KeccakPermutation(unsigned char *state) |
---|
426 | n/a | { |
---|
427 | n/a | /* We assume the state is always stored as interleaved 32-bit words */ |
---|
428 | n/a | KeccakPermutationOnWords((UINT32*)state); |
---|
429 | n/a | } |
---|
430 | n/a | |
---|
431 | n/a | #ifdef ProvideFast576 |
---|
432 | n/a | static void KeccakAbsorb576bits(unsigned char *state, const unsigned char *data) |
---|
433 | n/a | { |
---|
434 | n/a | KeccakPermutationOnWordsAfterXoring576bits((UINT32*)state, data); |
---|
435 | n/a | } |
---|
436 | n/a | #endif |
---|
437 | n/a | |
---|
438 | n/a | #ifdef ProvideFast832 |
---|
439 | n/a | static void KeccakAbsorb832bits(unsigned char *state, const unsigned char *data) |
---|
440 | n/a | { |
---|
441 | n/a | KeccakPermutationOnWordsAfterXoring832bits((UINT32*)state, data); |
---|
442 | n/a | } |
---|
443 | n/a | #endif |
---|
444 | n/a | |
---|
445 | n/a | #ifdef ProvideFast1024 |
---|
446 | n/a | static void KeccakAbsorb1024bits(unsigned char *state, const unsigned char *data) |
---|
447 | n/a | { |
---|
448 | n/a | KeccakPermutationOnWordsAfterXoring1024bits((UINT32*)state, data); |
---|
449 | n/a | } |
---|
450 | n/a | #endif |
---|
451 | n/a | |
---|
452 | n/a | #ifdef ProvideFast1088 |
---|
453 | n/a | static void KeccakAbsorb1088bits(unsigned char *state, const unsigned char *data) |
---|
454 | n/a | { |
---|
455 | n/a | KeccakPermutationOnWordsAfterXoring1088bits((UINT32*)state, data); |
---|
456 | n/a | } |
---|
457 | n/a | #endif |
---|
458 | n/a | |
---|
459 | n/a | #ifdef ProvideFast1152 |
---|
460 | n/a | static void KeccakAbsorb1152bits(unsigned char *state, const unsigned char *data) |
---|
461 | n/a | { |
---|
462 | n/a | KeccakPermutationOnWordsAfterXoring1152bits((UINT32*)state, data); |
---|
463 | n/a | } |
---|
464 | n/a | #endif |
---|
465 | n/a | |
---|
466 | n/a | #ifdef ProvideFast1344 |
---|
467 | n/a | static void KeccakAbsorb1344bits(unsigned char *state, const unsigned char *data) |
---|
468 | n/a | { |
---|
469 | n/a | KeccakPermutationOnWordsAfterXoring1344bits((UINT32*)state, data); |
---|
470 | n/a | } |
---|
471 | n/a | #endif |
---|
472 | n/a | |
---|
473 | n/a | static void KeccakAbsorb(unsigned char *state, const unsigned char *data, unsigned int laneCount) |
---|
474 | n/a | { |
---|
475 | n/a | KeccakPermutationOnWordsAfterXoring((UINT32*)state, data, laneCount); |
---|
476 | n/a | } |
---|
477 | n/a | |
---|
478 | n/a | #ifdef ProvideFast1024 |
---|
479 | n/a | static void KeccakExtract1024bits(const unsigned char *state, unsigned char *data) |
---|
480 | n/a | { |
---|
481 | n/a | extractLanes(16, state, data) |
---|
482 | n/a | #ifdef UseBebigokimisa |
---|
483 | n/a | ((UINT32*)data)[ 2] = ~((UINT32*)data)[ 2]; |
---|
484 | n/a | ((UINT32*)data)[ 3] = ~((UINT32*)data)[ 3]; |
---|
485 | n/a | ((UINT32*)data)[ 4] = ~((UINT32*)data)[ 4]; |
---|
486 | n/a | ((UINT32*)data)[ 5] = ~((UINT32*)data)[ 5]; |
---|
487 | n/a | ((UINT32*)data)[16] = ~((UINT32*)data)[16]; |
---|
488 | n/a | ((UINT32*)data)[17] = ~((UINT32*)data)[17]; |
---|
489 | n/a | ((UINT32*)data)[24] = ~((UINT32*)data)[24]; |
---|
490 | n/a | ((UINT32*)data)[25] = ~((UINT32*)data)[25]; |
---|
491 | n/a | #endif |
---|
492 | n/a | } |
---|
493 | n/a | #endif |
---|
494 | n/a | |
---|
495 | n/a | static void KeccakExtract(const unsigned char *state, unsigned char *data, unsigned int laneCount) |
---|
496 | n/a | { |
---|
497 | n/a | extractLanes(laneCount, state, data) |
---|
498 | n/a | #ifdef UseBebigokimisa |
---|
499 | n/a | if (laneCount > 1) { |
---|
500 | n/a | ((UINT32*)data)[ 2] = ~((UINT32*)data)[ 2]; |
---|
501 | n/a | ((UINT32*)data)[ 3] = ~((UINT32*)data)[ 3]; |
---|
502 | n/a | if (laneCount > 2) { |
---|
503 | n/a | ((UINT32*)data)[ 4] = ~((UINT32*)data)[ 4]; |
---|
504 | n/a | ((UINT32*)data)[ 5] = ~((UINT32*)data)[ 5]; |
---|
505 | n/a | if (laneCount > 8) { |
---|
506 | n/a | ((UINT32*)data)[16] = ~((UINT32*)data)[16]; |
---|
507 | n/a | ((UINT32*)data)[17] = ~((UINT32*)data)[17]; |
---|
508 | n/a | if (laneCount > 12) { |
---|
509 | n/a | ((UINT32*)data)[24] = ~((UINT32*)data)[24]; |
---|
510 | n/a | ((UINT32*)data)[25] = ~((UINT32*)data)[25]; |
---|
511 | n/a | if (laneCount > 17) { |
---|
512 | n/a | ((UINT32*)data)[34] = ~((UINT32*)data)[34]; |
---|
513 | n/a | ((UINT32*)data)[35] = ~((UINT32*)data)[35]; |
---|
514 | n/a | if (laneCount > 20) { |
---|
515 | n/a | ((UINT32*)data)[40] = ~((UINT32*)data)[40]; |
---|
516 | n/a | ((UINT32*)data)[41] = ~((UINT32*)data)[41]; |
---|
517 | n/a | } |
---|
518 | n/a | } |
---|
519 | n/a | } |
---|
520 | n/a | } |
---|
521 | n/a | } |
---|
522 | n/a | } |
---|
523 | n/a | #endif |
---|
524 | n/a | } |
---|