ReactOS 0.4.17-dev-1005-g171e1de
sha1.c
Go to the documentation of this file.
1//
2// Sha1.c
3//
4// Copyright (c) Microsoft Corporation. Licensed under the MIT license.
5//
6// This revised implementation is based on the older one in RSA32LIB by
7// Scott Field and Dan Shumow. It is not based on any 3rd party code.
8//
9
10#include "precomp.h"
11
12//
13// See the symcrypt.h file for documentation on what the various functions do.
14//
15
22 sizeof( SYMCRYPT_SHA1_STATE ),
27};
28
30
31
32//
33// The round constants used by SHA-1
34//
35static const UINT32 Sha1K[4] = {
36 0x5a827999UL, 0x6ed9eba1UL, 0x8f1bbcdcUL, 0xca62c1d6UL,
37};
38
39//
40// Initial state
41//
42static const UINT32 sha1InitialState[5] = {
43 0x67452301UL,
44 0xefcdab89UL,
45 0x98badcfeUL,
46 0x10325476UL,
47 0xc3d2e1f0UL,
48};
49
50//
51// SymCryptSha1
52//
53#define ALG SHA1
54#define Alg Sha1
55#include "hash_pattern.c"
56#undef ALG
57#undef Alg
58
59
60
61
62//
63// SymCryptSha1Init
64//
65SYMCRYPT_NOINLINE
66VOID
69{
71
72 pState->dataLengthL = 0;
73 pState->dataLengthH = 0;
74 pState->bytesInBuffer = 0;
75
76 memcpy( &pState->chain.H[0], &sha1InitialState[0], sizeof( sha1InitialState ) );
77
78 //
79 // There is no need to initialize the buffer part of the state as that will be
80 // filled before it is used.
81 //
82}
83
84
85//
86// SymCryptSha1Append
87//
88SYMCRYPT_NOINLINE
89VOID
95{
97}
98
99
100//
101// SymCryptSha1Result
102//
103SYMCRYPT_NOINLINE
104VOID
109{
111 SIZE_T tmp;
112
113 //
114 // SHA-1 uses almost the MD4 padding, except that the length in the padding is stored
115 // MSBFirst, rather than LSBFirst.
116 // As SHA-256 has a dedicated (fast) padding anyway, there is no gain to create a
117 // common padding routine for SHA-1 as it wouldn't be shared by anyone right now.
118 //
120
121 bytesInBuffer = (UINT32)(pState->bytesInBuffer);
122
123 //
124 // The buffer is never completely full, so we can always put the first
125 // padding byte in.
126 //
127 pState->buffer[bytesInBuffer++] = 0x80;
128
129 if( bytesInBuffer > 64-8 ) {
130 //
131 // No room for the rest of the padding. Pad with zeroes & process block
132 // bytesInBuffer is at most 64, so we do not have an integer underflow
133 //
134 memset( &pState->buffer[bytesInBuffer], 0, 64-bytesInBuffer );
135 SymCryptSha1AppendBlocks( &pState->chain, pState->buffer, 64, &tmp );
136 bytesInBuffer = 0;
137 }
138
139 //
140 // Set rest of padding
141 // At this point bytesInBuffer <= 64-8, so we don't have an underflow
142 // We wipe to the end of the buffer as it is 16-aligned,
143 // and it is faster to wipe to an aligned point
144 //
145 memset( &pState->buffer[bytesInBuffer], 0, 64-bytesInBuffer );
146 SYMCRYPT_STORE_MSBFIRST64( &pState->buffer[64-8], pState->dataLengthL * 8 );
147
148 //
149 // Process the final block
150 //
151 SymCryptSha1AppendBlocks( &pState->chain, pState->buffer, 64, &tmp );
152
153 //
154 // Write the output in the correct byte order
155 //
156 SymCryptUint32ToMsbFirst( &pState->chain.H[0], pbResult, 5 );
157
158 //
159 // Wipe & re-initialize
160 // We have to wipe the whole state because the Init call
161 // might be optimized away by a smart compiler.
162 //
163 SymCryptWipeKnownSize( pState, sizeof( *pState ) );
165}
166
167
168//
169// For documentation on these function see FIPS 180-2
170//
171// CH, MAJ and PARITY are the functions Ch, Maj, and Parity from the standard.
172//
173//#define CH( x, y, z ) (((x) & (y)) ^ ((~(x)) & (z)))
174//#define MAJ( x, y, z ) (((x) & (y)) ^ ((x) & (z)) ^ ((y) & (z)))
175#define MAJ( x, y, z ) ((((x) | (y)) & (z) ) | ((x) & (y)))
176#define CH( x, y, z ) ((((z) ^ (y)) & (x)) ^ (z))
177
178#define PARITY( x, y, z ) ((x) ^ (y) ^ (z) )
179
180
181//
182// The values a-e are stored in an array called ae.
183// We have unrolled the code completely. This makes both the indices into
184// the ae array constant, and it makes the message addressing constant.
185//
186
187//
188// Initial round macro
189//
190// r is the round number
191// ae[(r+0)%5] = e;
192// ae[(r+1)%5] = d;
193// ae[(r+2)%5] = c;
194// ae[(r+3)%5] = b;
195// ae[(r+4)%5] = a;
196// After that incrementing the round number will automatically map a->b, b->c, etc.
197//
198
199//
200// The core round routine (excluding the message schedule)
201//
202// In more readable form this macro does the following:
203// e = ROL(a,5) + F(b,c,d) + e + K[r/20] + W[round]
204// b = ROL( b, 30 )
205//
206
207#define CROUND( a, b, c, d, e, r, F ) {\
208 W[r%16] = Wt; \
209 e += ROL32( a, 5 ) + F(b, c, d) + Sha1K[r/20] + Wt;\
210 b = ROR32( b, 2 );\
211}
212
213#define IROUND( a, b, c, d, e, r, F ) { \
214 Wt = SYMCRYPT_LOAD_MSBFIRST32( &pbData[ 4*r ] ); \
215 CROUND( a, b, c, d, e, r, F ); \
216}
217
218//
219// Subsequent rounds.
220// This is the same as the IROUND except that it adds the message schedule,
221// and takes the message word from the intermediate
222//
223#define FROUND( a, b, c, d, e, r, F ) { \
224 Wt = ROL32( W[(r+13)%16] ^ W[(r+8)%16] ^ W[(r+2)%16] ^ W[r%16], 1 );\
225 CROUND( a, b, c, d, e, r, F ); \
226}
227
228VOID
234 _Out_ SIZE_T * pcbRemaining )
235{
236
238 UINT32 A, B, C, D, E;
239 UINT32 Wt;
240
241 A = pChain->H[0];
242 B = pChain->H[1];
243 C = pChain->H[2];
244 D = pChain->H[3];
245 E = pChain->H[4];
246
247 while( cbData >= 64 )
248 {
249 //
250 // initial rounds 1 to 16
251 //
252
253 IROUND( A, B, C, D, E, 0, CH );
254 IROUND( E, A, B, C, D, 1, CH );
255 IROUND( D, E, A, B, C, 2, CH );
256 IROUND( C, D, E, A, B, 3, CH );
257 IROUND( B, C, D, E, A, 4, CH );
258 IROUND( A, B, C, D, E, 5, CH );
259 IROUND( E, A, B, C, D, 6, CH );
260 IROUND( D, E, A, B, C, 7, CH );
261 IROUND( C, D, E, A, B, 8, CH );
262 IROUND( B, C, D, E, A, 9, CH );
263 IROUND( A, B, C, D, E, 10, CH );
264 IROUND( E, A, B, C, D, 11, CH );
265 IROUND( D, E, A, B, C, 12, CH );
266 IROUND( C, D, E, A, B, 13, CH );
267 IROUND( B, C, D, E, A, 14, CH );
268 IROUND( A, B, C, D, E, 15, CH );
269
270 //
271 // Full rounds (including msg expansion) from here on
272 //
273 FROUND( E, A, B, C, D, 16, CH );
274 FROUND( D, E, A, B, C, 17, CH );
275 FROUND( C, D, E, A, B, 18, CH );
276 FROUND( B, C, D, E, A, 19, CH );
277
278
279 FROUND( A, B, C, D, E, 20, PARITY );
280 FROUND( E, A, B, C, D, 21, PARITY );
281 FROUND( D, E, A, B, C, 22, PARITY );
282 FROUND( C, D, E, A, B, 23, PARITY );
283 FROUND( B, C, D, E, A, 24, PARITY );
284 FROUND( A, B, C, D, E, 25, PARITY );
285 FROUND( E, A, B, C, D, 26, PARITY );
286 FROUND( D, E, A, B, C, 27, PARITY );
287 FROUND( C, D, E, A, B, 28, PARITY );
288 FROUND( B, C, D, E, A, 29, PARITY );
289 FROUND( A, B, C, D, E, 30, PARITY );
290 FROUND( E, A, B, C, D, 31, PARITY );
291 FROUND( D, E, A, B, C, 32, PARITY );
292 FROUND( C, D, E, A, B, 33, PARITY );
293 FROUND( B, C, D, E, A, 34, PARITY );
294 FROUND( A, B, C, D, E, 35, PARITY );
295 FROUND( E, A, B, C, D, 36, PARITY );
296 FROUND( D, E, A, B, C, 37, PARITY );
297 FROUND( C, D, E, A, B, 38, PARITY );
298 FROUND( B, C, D, E, A, 39, PARITY );
299
300
301 FROUND( A, B, C, D, E, 40, MAJ );
302 FROUND( E, A, B, C, D, 41, MAJ );
303 FROUND( D, E, A, B, C, 42, MAJ );
304 FROUND( C, D, E, A, B, 43, MAJ );
305 FROUND( B, C, D, E, A, 44, MAJ );
306 FROUND( A, B, C, D, E, 45, MAJ );
307 FROUND( E, A, B, C, D, 46, MAJ );
308 FROUND( D, E, A, B, C, 47, MAJ );
309 FROUND( C, D, E, A, B, 48, MAJ );
310 FROUND( B, C, D, E, A, 49, MAJ );
311 FROUND( A, B, C, D, E, 50, MAJ );
312 FROUND( E, A, B, C, D, 51, MAJ );
313 FROUND( D, E, A, B, C, 52, MAJ );
314 FROUND( C, D, E, A, B, 53, MAJ );
315 FROUND( B, C, D, E, A, 54, MAJ );
316 FROUND( A, B, C, D, E, 55, MAJ );
317 FROUND( E, A, B, C, D, 56, MAJ );
318 FROUND( D, E, A, B, C, 57, MAJ );
319 FROUND( C, D, E, A, B, 58, MAJ );
320 FROUND( B, C, D, E, A, 59, MAJ );
321
322 FROUND( A, B, C, D, E, 60, PARITY );
323 FROUND( E, A, B, C, D, 61, PARITY );
324 FROUND( D, E, A, B, C, 62, PARITY );
325 FROUND( C, D, E, A, B, 63, PARITY );
326 FROUND( B, C, D, E, A, 64, PARITY );
327 FROUND( A, B, C, D, E, 65, PARITY );
328 FROUND( E, A, B, C, D, 66, PARITY );
329 FROUND( D, E, A, B, C, 67, PARITY );
330 FROUND( C, D, E, A, B, 68, PARITY );
331 FROUND( B, C, D, E, A, 69, PARITY );
332 FROUND( A, B, C, D, E, 70, PARITY );
333 FROUND( E, A, B, C, D, 71, PARITY );
334 FROUND( D, E, A, B, C, 72, PARITY );
335 FROUND( C, D, E, A, B, 73, PARITY );
336 FROUND( B, C, D, E, A, 74, PARITY );
337 FROUND( A, B, C, D, E, 75, PARITY );
338 FROUND( E, A, B, C, D, 76, PARITY );
339 FROUND( D, E, A, B, C, 77, PARITY );
340 FROUND( C, D, E, A, B, 78, PARITY );
341 FROUND( B, C, D, E, A, 79, PARITY );
342
343
344 pChain->H[0] = A = A + pChain->H[0];
345 pChain->H[1] = B = B + pChain->H[1];
346 pChain->H[2] = C = C + pChain->H[2];
347 pChain->H[3] = D = D + pChain->H[3];
348 pChain->H[4] = E = E + pChain->H[4];
349
350 pbData += 64;
351 cbData -= 64;
352 }
353
354 *pcbRemaining = cbData;
355
356 //
357 // Wipe the variables;
358 //
359 SymCryptWipeKnownSize( W, sizeof( W ) );
364 SYMCRYPT_FORCE_WRITE32( &E, 0 );
365 SYMCRYPT_FORCE_WRITE32( &Wt, 0 );
366}
367
368
369VOID
374{
375 SYMCRYPT_ALIGN SYMCRYPT_SHA1_STATE_EXPORT_BLOB blob; // local copy to have proper alignment.
377
379
380 SymCryptWipeKnownSize( &blob, sizeof( blob ) ); // wipe to avoid any data leakage
381
382 blob.header.magic = SYMCRYPT_BLOB_MAGIC;
384 blob.header.type = SymCryptBlobTypeSha1State;
385
386 //
387 // Copy the relevant data. Buffer will be 0-padded.
388 //
389
390 SymCryptUint32ToMsbFirst( &pState->chain.H[0], &blob.chain[0], 5 );
391 blob.dataLength = pState->dataLengthL;
392 memcpy( &blob.buffer[0], &pState->buffer[0], blob.dataLength & 0x3f );
393
394 SYMCRYPT_ASSERT( (PCBYTE) &blob + sizeof( blob ) - sizeof( SYMCRYPT_BLOB_TRAILER ) == (PCBYTE) &blob.trailer );
395 SymCryptMarvin32( SymCryptMarvin32DefaultSeed, (PCBYTE) &blob, sizeof( blob ) - sizeof( SYMCRYPT_BLOB_TRAILER ), &blob.trailer.checksum[0] );
396
397 memcpy( pbBlob, &blob, sizeof( blob ) );
398
399//cleanup:
400 SymCryptWipeKnownSize( &blob, sizeof( blob ) );
401 return;
402}
403
409{
410 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
411 SYMCRYPT_ALIGN SYMCRYPT_SHA1_STATE_EXPORT_BLOB blob; // local copy to have proper alignment.
412 BYTE checksum[8];
413
415 memcpy( &blob, pbBlob, sizeof( blob ) );
416
417 if( blob.header.magic != SYMCRYPT_BLOB_MAGIC ||
418 blob.header.size != SYMCRYPT_SHA1_STATE_EXPORT_SIZE ||
419 blob.header.type != SymCryptBlobTypeSha1State )
420 {
421 scError = SYMCRYPT_INVALID_BLOB;
422 goto cleanup;
423 }
424
426 if( memcmp( checksum, &blob.trailer.checksum[0], 8 ) != 0 )
427 {
428 scError = SYMCRYPT_INVALID_BLOB;
429 goto cleanup;
430 }
431
432 SymCryptMsbFirstToUint32( &blob.chain[0], &pState->chain.H[0], 5 );
433 pState->dataLengthL = blob.dataLength;
434 pState->dataLengthH = 0;
435 pState->bytesInBuffer = blob.dataLength & 0x3f;
436 memcpy( &pState->buffer[0], &blob.buffer[0], pState->bytesInBuffer );
437
439
440cleanup:
441 SymCryptWipeKnownSize( &blob, sizeof(blob) );
442 return scError;
443}
444
445
446
447//
448// Simple test vector for FIPS module testing
449//
450
451static const BYTE sha1KATAnswer[ 20 ] = {
452 0xa9, 0x99, 0x3e, 0x36,
453 0x47, 0x06, 0x81, 0x6a,
454 0xba, 0x3e, 0x25, 0x71,
455 0x78, 0x50, 0xc2, 0x6c,
456 0x9c, 0xd0, 0xd8, 0x9d
457 } ;
458
459VOID
462{
464
466
467 SymCryptInjectError( result, sizeof( result ) );
468
469 if( memcmp( result, sha1KATAnswer, sizeof( result ) ) != 0 ) {
470 SymCryptFatal( 'SHA1' );
471 }
472}
#define D(d)
Definition: builtin.c:4557
#define C(c)
Definition: builtin.c:4556
Definition: ehthrow.cxx:93
Definition: ehthrow.cxx:54
Definition: terminate.cpp:24
#define A(row, col)
#define B(row, col)
static cab_ULONG checksum(const cab_UBYTE *data, cab_UWORD bytes, cab_ULONG csum)
Definition: fdi.c:353
static void cleanup(void)
Definition: main.c:1335
_ACRTIMP int __cdecl memcmp(const void *, const void *, size_t)
Definition: string.c:2807
GLuint64EXT * result
Definition: glext.h:11304
#define C_ASSERT(e)
Definition: intsafe.h:73
#define memcpy(s1, s2, n)
Definition: mkisofs.h:878
enum _CH CH
#define _In_reads_bytes_(s)
Definition: no_sal2.h:170
#define _In_reads_(s)
Definition: no_sal2.h:168
#define _Inout_
Definition: no_sal2.h:162
#define _Out_writes_(s)
Definition: no_sal2.h:176
#define _Out_
Definition: no_sal2.h:160
#define _In_
Definition: no_sal2.h:158
#define _Out_writes_bytes_(s)
Definition: no_sal2.h:178
BYTE * PBYTE
Definition: pedump.c:66
#define SYMCRYPT_BLOB_MAGIC
Definition: sc_lib.h:1077
@ SymCryptBlobTypeSha1State
Definition: sc_lib.h:1064
VOID SYMCRYPT_CALL SymCryptInjectError(PBYTE pbData, SIZE_T cbData)
FORCEINLINE VOID SYMCRYPT_CALL SymCryptUint32ToMsbFirst(_In_reads_(cuData) PCUINT32 puData, _Out_writes_(4 *cuData) PBYTE pbResult, SIZE_T cuData)
Definition: sc_lib.h:405
const BYTE SymCryptTestMsg3[3]
Definition: selftest.c:8
FORCEINLINE VOID SYMCRYPT_CALL SymCryptMsbFirstToUint32(_In_reads_(4 *cuResult) PCBYTE pbData, _Out_writes_(cuResult) PUINT32 puResult, SIZE_T cuResult)
Definition: sc_lib.h:422
VOID SYMCRYPT_CALL SymCryptHashAppendInternal(_In_ PCSYMCRYPT_HASH pHash, _Inout_ PSYMCRYPT_COMMON_HASH_STATE pState, _In_reads_bytes_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: hash.c:10
const SYMCRYPT_HASH SymCryptSha1Algorithm_default
Definition: sha1.c:16
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha1Init(_Out_ PSYMCRYPT_SHA1_STATE pState)
Definition: sha1.c:68
static const BYTE sha1KATAnswer[20]
Definition: sha1.c:451
#define IROUND(a, b, c, d, e, r, F)
Definition: sha1.c:213
static const UINT32 sha1InitialState[5]
Definition: sha1.c:42
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha1StateImport(_Out_ PSYMCRYPT_SHA1_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA1_STATE_EXPORT_SIZE) PCBYTE pbBlob)
Definition: sha1.c:406
const PCSYMCRYPT_HASH SymCryptSha1Algorithm
Definition: sha1.c:29
VOID SYMCRYPT_CALL SymCryptSha1StateExport(_In_ PCSYMCRYPT_SHA1_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA1_STATE_EXPORT_SIZE) PBYTE pbBlob)
Definition: sha1.c:371
#define FROUND(a, b, c, d, e, r, F)
Definition: sha1.c:223
VOID SYMCRYPT_CALL SymCryptSha1AppendBlocks(_Inout_ SYMCRYPT_SHA1_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
Definition: sha1.c:230
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha1Result(_Inout_ PSYMCRYPT_SHA1_STATE pState, _Out_writes_(SYMCRYPT_SHA1_RESULT_SIZE) PBYTE pbResult)
Definition: sha1.c:106
#define PARITY(x, y, z)
Definition: sha1.c:178
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha1Append(_Inout_ PSYMCRYPT_SHA1_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha1.c:91
VOID SYMCRYPT_CALL SymCryptSha1Selftest(void)
Definition: sha1.c:461
#define MAJ(x, y, z)
Definition: sha1.c:175
static const UINT32 Sha1K[4]
Definition: sha1.c:35
#define memset(x, y, z)
Definition: compat.h:39
static const BYTE pbResult[]
Definition: polytest.cpp:36
Definition: image.c:229
#define SYMCRYPT_ASSERT(_x)
Definition: symcrypt.h:10807
VOID SYMCRYPT_CALL SymCryptMarvin32(_In_ PCSYMCRYPT_MARVIN32_EXPANDED_SEED pExpandedSeed, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_MARVIN32_RESULT_SIZE) PBYTE pbResult)
Definition: marvin32.c:239
FORCEINLINE VOID SYMCRYPT_CALL SymCryptWipeKnownSize(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
#define SYMCRYPT_SHA1_RESULT_SIZE
Definition: symcrypt.h:1090
_Analysis_noreturn_ VOID SYMCRYPT_CALL SymCryptFatal(UINT32 fatalCode)
#define SYMCRYPT_SHA1_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1091
#define SYMCRYPT_FORCE_WRITE32(_p, _v)
Definition: symcrypt.h:423
PCSYMCRYPT_MARVIN32_EXPANDED_SEED const SymCryptMarvin32DefaultSeed
Definition: marvin32.c:29
VOID SYMCRYPT_CALL SymCryptSha1StateCopy(_In_ PCSYMCRYPT_SHA1_STATE pSrc, _Out_ PSYMCRYPT_SHA1_STATE pDst)
VOID SYMCRYPT_CALL SymCryptSha1(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA1_RESULT_SIZE) PBYTE pbResult)
#define SYMCRYPT_STORE_MSBFIRST64(p, v)
Definition: symcrypt.h:312
SYMCRYPT_ERROR
Definition: symcrypt.h:227
#define SYMCRYPT_ALIGN
#define SYMCRYPT_CALL
#define SYMCRYPT_SHA1_STATE_EXPORT_SIZE
* PSYMCRYPT_SHA1_STATE
struct _SYMCRYPT_HASH SYMCRYPT_HASH
#define SYMCRYPT_FIELD_SIZE(type, field)
SIZE_T bytesInBuffer
const SYMCRYPT_HASH * PCSYMCRYPT_HASH
PCBYTE PBYTE SIZE_T cbData
#define SYMCRYPT_SET_MAGIC(p)
#define SYMCRYPT_FIELD_OFFSET(type, field)
* PSYMCRYPT_COMMON_HASH_STATE
SYMCRYPT_SHA1_STATE
PSYMCRYPT_COMMON_HASH_STATE pState
const BYTE * PCBYTE
PCBYTE pbData
SYMCRYPT_SHA1_CHAINING_STATE
#define SYMCRYPT_CHECK_MAGIC(p)
const SYMCRYPT_SHA1_STATE * PCSYMCRYPT_SHA1_STATE
struct sock * chain
Definition: tcpcore.h:1
ULONG_PTR SIZE_T
Definition: typedefs.h:80
uint32_t UINT32
Definition: typedefs.h:59
unsigned char BYTE
Definition: xxhash.c:193