diff options
Diffstat (limited to 'src/lib/hash/shake')
-rw-r--r-- | src/lib/hash/shake/info.txt | 5 | ||||
-rw-r--r-- | src/lib/hash/shake/shake.cpp | 101 | ||||
-rw-r--r-- | src/lib/hash/shake/shake.h | 81 |
3 files changed, 187 insertions, 0 deletions
diff --git a/src/lib/hash/shake/info.txt b/src/lib/hash/shake/info.txt new file mode 100644 index 000000000..f579383eb --- /dev/null +++ b/src/lib/hash/shake/info.txt @@ -0,0 +1,5 @@ +define SHAKE 20161009 + +<requires> +sha3 +</requires> diff --git a/src/lib/hash/shake/shake.cpp b/src/lib/hash/shake/shake.cpp new file mode 100644 index 000000000..1ff6f1fd3 --- /dev/null +++ b/src/lib/hash/shake/shake.cpp @@ -0,0 +1,101 @@ +/* +* SHAKE-128/256 as a hash +* (C) 2016 Jack Lloyd +* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#include <botan/shake.h> +#include <botan/sha3.h> +#include <botan/parsing.h> +#include <botan/exceptn.h> + +namespace Botan { + +SHAKE_128::SHAKE_128(size_t output_bits) : + m_output_bits(output_bits), m_S(25), m_S_pos(0) + { + if(output_bits % 8 != 0) + throw Invalid_Argument("SHAKE_128: Invalid output length " + + std::to_string(output_bits)); + } + +std::string SHAKE_128::name() const + { + return "SHAKE-128(" + std::to_string(m_output_bits) + ")"; + } + +HashFunction* SHAKE_128::clone() const + { + return new SHAKE_128(m_output_bits); + } + +void SHAKE_128::clear() + { + zeroise(m_S); + m_S_pos = 0; + } + +void SHAKE_128::add_data(const byte input[], size_t length) + { + m_S_pos = SHA_3::absorb(SHAKE_128_BITRATE, m_S, m_S_pos, input, length); + } + +void SHAKE_128::final_result(byte output[]) + { + std::vector<byte> padding(SHAKE_128_BITRATE / 8 - m_S_pos); + + padding[0] = 0x1F; + padding[padding.size()-1] |= 0x80; + + add_data(padding.data(), padding.size()); + + SHA_3::expand(SHAKE_128_BITRATE, m_S, output, output_length()); + + clear(); + } + +SHAKE_256::SHAKE_256(size_t output_bits) : + m_output_bits(output_bits), m_S(25), m_S_pos(0) + { + if(output_bits % 8 != 0) + throw Invalid_Argument("SHAKE_256: Invalid output length " + + std::to_string(output_bits)); + } + +std::string SHAKE_256::name() const + { + return "SHAKE-256(" + std::to_string(m_output_bits) + ")"; + } + +HashFunction* SHAKE_256::clone() const + { + return new SHAKE_256(m_output_bits); + } + +void SHAKE_256::clear() + { + zeroise(m_S); + m_S_pos = 0; + } + +void SHAKE_256::add_data(const byte input[], size_t length) + { + m_S_pos = SHA_3::absorb(SHAKE_256_BITRATE, m_S, m_S_pos, input, length); + } + +void SHAKE_256::final_result(byte output[]) + { + std::vector<byte> padding(SHAKE_256_BITRATE / 8 - m_S_pos); + + padding[0] = 0x1F; + padding[padding.size()-1] |= 0x80; + + add_data(padding.data(), padding.size()); + + SHA_3::expand(SHAKE_256_BITRATE, m_S, output, output_length()); + + clear(); + } + +} diff --git a/src/lib/hash/shake/shake.h b/src/lib/hash/shake/shake.h new file mode 100644 index 000000000..96c171323 --- /dev/null +++ b/src/lib/hash/shake/shake.h @@ -0,0 +1,81 @@ +/* +* SHAKE hash functions +* (C) 2010,2016 Jack Lloyd +* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#ifndef BOTAN_SHAKE_HASH_H__ +#define BOTAN_SHAKE_HASH_H__ + +#include <botan/hash.h> +#include <botan/secmem.h> +#include <string> + +namespace Botan { + +/** +* SHAKE-128 +*/ +class BOTAN_DLL SHAKE_128 : public HashFunction + { + public: + + /** + * @param output_bits the desired output size in bits + * must be a multiple of 8 + */ + SHAKE_128(size_t output_bits); + + size_t hash_block_size() const override { return SHAKE_128_BITRATE / 8; } + size_t output_length() const override { return m_output_bits / 8; } + + HashFunction* clone() const override; + std::string name() const override; + void clear() override; + + private: + void add_data(const byte input[], size_t length) override; + void final_result(byte out[]) override; + + static const size_t SHAKE_128_BITRATE = 1600 - 256; + + size_t m_output_bits; + secure_vector<u64bit> m_S; + size_t m_S_pos; + }; + +/** +* SHAKE-256 +*/ +class BOTAN_DLL SHAKE_256 : public HashFunction + { + public: + + /** + * @param output_bits the desired output size in bits + * must be a multiple of 8 + */ + SHAKE_256(size_t output_bits); + + size_t hash_block_size() const override { return SHAKE_256_BITRATE / 8; } + size_t output_length() const override { return m_output_bits / 8; } + + HashFunction* clone() const override; + std::string name() const override; + void clear() override; + + private: + void add_data(const byte input[], size_t length) override; + void final_result(byte out[]) override; + + static const size_t SHAKE_256_BITRATE = 1600 - 512; + + size_t m_output_bits; + secure_vector<u64bit> m_S; + size_t m_S_pos; + }; + +} + +#endif |