7 ANONYMOUS_NAMESPACE_BEGIN
9 using CryptoPP::word32;
14 word32 F(word32 x, word32 y, word32 z) {
return x ^ y ^ z; }
15 word32 G(word32 x, word32 y, word32 z) {
return z ^ (x & (y^z)); }
16 word32 H(word32 x, word32 y, word32 z) {
return z ^ (x | ~y); }
17 word32 I(word32 x, word32 y, word32 z) {
return y ^ (z & (x^y)); }
18 word32 J(word32 x, word32 y, word32 z) {
return x ^ (y | ~z); }
20 typedef word32 (*Fn)(word32, word32, word32);
21 template <Fn f,
unsigned int S>
22 void Subround(word32& a, word32 b, word32& c, word32 d, word32 e, word32 x, word32 k)
24 a += f(b, c, d) + x + k;
26 c = rotlConstant<10>(c);
29 ANONYMOUS_NAMESPACE_END
33 const unsigned int k0 = 0;
34 const unsigned int k1 = 0x5a827999;
35 const unsigned int k2 = 0x6ed9eba1;
36 const unsigned int k3 = 0x8f1bbcdc;
37 const unsigned int k4 = 0xa953fd4e;
38 const unsigned int k5 = 0x50a28be6;
39 const unsigned int k6 = 0x5c4dd124;
40 const unsigned int k7 = 0x6d703ef3;
41 const unsigned int k8 = 0x7a6d76e9;
42 const unsigned int k9 = 0;
46 AssertValidKeyLength(keylength);
54 void TTMAC_Base::Init()
56 m_digest[0] = m_digest[5] = m_key[0];
57 m_digest[1] = m_digest[6] = m_key[1];
58 m_digest[2] = m_digest[7] = m_key[2];
59 m_digest[3] = m_digest[8] = m_key[3];
60 m_digest[4] = m_digest[9] = m_key[4];
65 PadLastBlock(
BlockSize() - 2*
sizeof(HashWordType));
68 m_data[m_data.size()-2] = GetBitCountLo();
69 m_data[m_data.size()-1] = GetBitCountHi();
71 Transform(m_digest, m_data,
true);
73 word32 t2 = m_digest[2];
74 word32 t3 = m_digest[3];
75 if (size != DIGESTSIZE)
80 m_digest[3] += m_digest[1] + m_digest[4];
83 m_digest[2] += m_digest[0] + t3;
86 m_digest[0] += m_digest[1] + t3;
87 m_digest[1] += m_digest[4] + t2;
109 memcpy(hash, m_digest, size);
114 void TTMAC_Base::Transform(word32 *digest,
const word32 *X,
bool last)
116 word32 a1, b1, c1, d1, e1, a2, b2, c2, d2, e2;
117 word32 *trackA, *trackB;
140 Subround<F,11>(a1, b1, c1, d1, e1, X[ 0], k0);
141 Subround<F,14>(e1, a1, b1, c1, d1, X[ 1], k0);
142 Subround<F,15>(d1, e1, a1, b1, c1, X[ 2], k0);
143 Subround<F,12>(c1, d1, e1, a1, b1, X[ 3], k0);
144 Subround<F, 5>(b1, c1, d1, e1, a1, X[ 4], k0);
145 Subround<F, 8>(a1, b1, c1, d1, e1, X[ 5], k0);
146 Subround<F, 7>(e1, a1, b1, c1, d1, X[ 6], k0);
147 Subround<F, 9>(d1, e1, a1, b1, c1, X[ 7], k0);
148 Subround<F,11>(c1, d1, e1, a1, b1, X[ 8], k0);
149 Subround<F,13>(b1, c1, d1, e1, a1, X[ 9], k0);
150 Subround<F,14>(a1, b1, c1, d1, e1, X[10], k0);
151 Subround<F,15>(e1, a1, b1, c1, d1, X[11], k0);
152 Subround<F, 6>(d1, e1, a1, b1, c1, X[12], k0);
153 Subround<F, 7>(c1, d1, e1, a1, b1, X[13], k0);
154 Subround<F, 9>(b1, c1, d1, e1, a1, X[14], k0);
155 Subround<F, 8>(a1, b1, c1, d1, e1, X[15], k0);
157 Subround<G, 7>(e1, a1, b1, c1, d1, X[ 7], k1);
158 Subround<G, 6>(d1, e1, a1, b1, c1, X[ 4], k1);
159 Subround<G, 8>(c1, d1, e1, a1, b1, X[13], k1);
160 Subround<G,13>(b1, c1, d1, e1, a1, X[ 1], k1);
161 Subround<G,11>(a1, b1, c1, d1, e1, X[10], k1);
162 Subround<G, 9>(e1, a1, b1, c1, d1, X[ 6], k1);
163 Subround<G, 7>(d1, e1, a1, b1, c1, X[15], k1);
164 Subround<G,15>(c1, d1, e1, a1, b1, X[ 3], k1);
165 Subround<G, 7>(b1, c1, d1, e1, a1, X[12], k1);
166 Subround<G,12>(a1, b1, c1, d1, e1, X[ 0], k1);
167 Subround<G,15>(e1, a1, b1, c1, d1, X[ 9], k1);
168 Subround<G, 9>(d1, e1, a1, b1, c1, X[ 5], k1);
169 Subround<G,11>(c1, d1, e1, a1, b1, X[ 2], k1);
170 Subround<G, 7>(b1, c1, d1, e1, a1, X[14], k1);
171 Subround<G,13>(a1, b1, c1, d1, e1, X[11], k1);
172 Subround<G,12>(e1, a1, b1, c1, d1, X[ 8], k1);
174 Subround<H,11>(d1, e1, a1, b1, c1, X[ 3], k2);
175 Subround<H,13>(c1, d1, e1, a1, b1, X[10], k2);
176 Subround<H, 6>(b1, c1, d1, e1, a1, X[14], k2);
177 Subround<H, 7>(a1, b1, c1, d1, e1, X[ 4], k2);
178 Subround<H,14>(e1, a1, b1, c1, d1, X[ 9], k2);
179 Subround<H, 9>(d1, e1, a1, b1, c1, X[15], k2);
180 Subround<H,13>(c1, d1, e1, a1, b1, X[ 8], k2);
181 Subround<H,15>(b1, c1, d1, e1, a1, X[ 1], k2);
182 Subround<H,14>(a1, b1, c1, d1, e1, X[ 2], k2);
183 Subround<H, 8>(e1, a1, b1, c1, d1, X[ 7], k2);
184 Subround<H,13>(d1, e1, a1, b1, c1, X[ 0], k2);
185 Subround<H, 6>(c1, d1, e1, a1, b1, X[ 6], k2);
186 Subround<H, 5>(b1, c1, d1, e1, a1, X[13], k2);
187 Subround<H,12>(a1, b1, c1, d1, e1, X[11], k2);
188 Subround<H, 7>(e1, a1, b1, c1, d1, X[ 5], k2);
189 Subround<H, 5>(d1, e1, a1, b1, c1, X[12], k2);
191 Subround<I,11>(c1, d1, e1, a1, b1, X[ 1], k3);
192 Subround<I,12>(b1, c1, d1, e1, a1, X[ 9], k3);
193 Subround<I,14>(a1, b1, c1, d1, e1, X[11], k3);
194 Subround<I,15>(e1, a1, b1, c1, d1, X[10], k3);
195 Subround<I,14>(d1, e1, a1, b1, c1, X[ 0], k3);
196 Subround<I,15>(c1, d1, e1, a1, b1, X[ 8], k3);
197 Subround<I, 9>(b1, c1, d1, e1, a1, X[12], k3);
198 Subround<I, 8>(a1, b1, c1, d1, e1, X[ 4], k3);
199 Subround<I, 9>(e1, a1, b1, c1, d1, X[13], k3);
200 Subround<I,14>(d1, e1, a1, b1, c1, X[ 3], k3);
201 Subround<I, 5>(c1, d1, e1, a1, b1, X[ 7], k3);
202 Subround<I, 6>(b1, c1, d1, e1, a1, X[15], k3);
203 Subround<I, 8>(a1, b1, c1, d1, e1, X[14], k3);
204 Subround<I, 6>(e1, a1, b1, c1, d1, X[ 5], k3);
205 Subround<I, 5>(d1, e1, a1, b1, c1, X[ 6], k3);
206 Subround<I,12>(c1, d1, e1, a1, b1, X[ 2], k3);
208 Subround<J, 9>(b1, c1, d1, e1, a1, X[ 4], k4);
209 Subround<J,15>(a1, b1, c1, d1, e1, X[ 0], k4);
210 Subround<J, 5>(e1, a1, b1, c1, d1, X[ 5], k4);
211 Subround<J,11>(d1, e1, a1, b1, c1, X[ 9], k4);
212 Subround<J, 6>(c1, d1, e1, a1, b1, X[ 7], k4);
213 Subround<J, 8>(b1, c1, d1, e1, a1, X[12], k4);
214 Subround<J,13>(a1, b1, c1, d1, e1, X[ 2], k4);
215 Subround<J,12>(e1, a1, b1, c1, d1, X[10], k4);
216 Subround<J, 5>(d1, e1, a1, b1, c1, X[14], k4);
217 Subround<J,12>(c1, d1, e1, a1, b1, X[ 1], k4);
218 Subround<J,13>(b1, c1, d1, e1, a1, X[ 3], k4);
219 Subround<J,14>(a1, b1, c1, d1, e1, X[ 8], k4);
220 Subround<J,11>(e1, a1, b1, c1, d1, X[11], k4);
221 Subround<J, 8>(d1, e1, a1, b1, c1, X[ 6], k4);
222 Subround<J, 5>(c1, d1, e1, a1, b1, X[15], k4);
223 Subround<J, 6>(b1, c1, d1, e1, a1, X[13], k4);
225 Subround<J, 8>(a2, b2, c2, d2, e2, X[ 5], k5);
226 Subround<J, 9>(e2, a2, b2, c2, d2, X[14], k5);
227 Subround<J, 9>(d2, e2, a2, b2, c2, X[ 7], k5);
228 Subround<J,11>(c2, d2, e2, a2, b2, X[ 0], k5);
229 Subround<J,13>(b2, c2, d2, e2, a2, X[ 9], k5);
230 Subround<J,15>(a2, b2, c2, d2, e2, X[ 2], k5);
231 Subround<J,15>(e2, a2, b2, c2, d2, X[11], k5);
232 Subround<J, 5>(d2, e2, a2, b2, c2, X[ 4], k5);
233 Subround<J, 7>(c2, d2, e2, a2, b2, X[13], k5);
234 Subround<J, 7>(b2, c2, d2, e2, a2, X[ 6], k5);
235 Subround<J, 8>(a2, b2, c2, d2, e2, X[15], k5);
236 Subround<J,11>(e2, a2, b2, c2, d2, X[ 8], k5);
237 Subround<J,14>(d2, e2, a2, b2, c2, X[ 1], k5);
238 Subround<J,14>(c2, d2, e2, a2, b2, X[10], k5);
239 Subround<J,12>(b2, c2, d2, e2, a2, X[ 3], k5);
240 Subround<J, 6>(a2, b2, c2, d2, e2, X[12], k5);
242 Subround<I, 9>(e2, a2, b2, c2, d2, X[ 6], k6);
243 Subround<I,13>(d2, e2, a2, b2, c2, X[11], k6);
244 Subround<I,15>(c2, d2, e2, a2, b2, X[ 3], k6);
245 Subround<I, 7>(b2, c2, d2, e2, a2, X[ 7], k6);
246 Subround<I,12>(a2, b2, c2, d2, e2, X[ 0], k6);
247 Subround<I, 8>(e2, a2, b2, c2, d2, X[13], k6);
248 Subround<I, 9>(d2, e2, a2, b2, c2, X[ 5], k6);
249 Subround<I,11>(c2, d2, e2, a2, b2, X[10], k6);
250 Subround<I, 7>(b2, c2, d2, e2, a2, X[14], k6);
251 Subround<I, 7>(a2, b2, c2, d2, e2, X[15], k6);
252 Subround<I,12>(e2, a2, b2, c2, d2, X[ 8], k6);
253 Subround<I, 7>(d2, e2, a2, b2, c2, X[12], k6);
254 Subround<I, 6>(c2, d2, e2, a2, b2, X[ 4], k6);
255 Subround<I,15>(b2, c2, d2, e2, a2, X[ 9], k6);
256 Subround<I,13>(a2, b2, c2, d2, e2, X[ 1], k6);
257 Subround<I,11>(e2, a2, b2, c2, d2, X[ 2], k6);
259 Subround<H, 9>(d2, e2, a2, b2, c2, X[15], k7);
260 Subround<H, 7>(c2, d2, e2, a2, b2, X[ 5], k7);
261 Subround<H,15>(b2, c2, d2, e2, a2, X[ 1], k7);
262 Subround<H,11>(a2, b2, c2, d2, e2, X[ 3], k7);
263 Subround<H, 8>(e2, a2, b2, c2, d2, X[ 7], k7);
264 Subround<H, 6>(d2, e2, a2, b2, c2, X[14], k7);
265 Subround<H, 6>(c2, d2, e2, a2, b2, X[ 6], k7);
266 Subround<H,14>(b2, c2, d2, e2, a2, X[ 9], k7);
267 Subround<H,12>(a2, b2, c2, d2, e2, X[11], k7);
268 Subround<H,13>(e2, a2, b2, c2, d2, X[ 8], k7);
269 Subround<H, 5>(d2, e2, a2, b2, c2, X[12], k7);
270 Subround<H,14>(c2, d2, e2, a2, b2, X[ 2], k7);
271 Subround<H,13>(b2, c2, d2, e2, a2, X[10], k7);
272 Subround<H,13>(a2, b2, c2, d2, e2, X[ 0], k7);
273 Subround<H, 7>(e2, a2, b2, c2, d2, X[ 4], k7);
274 Subround<H, 5>(d2, e2, a2, b2, c2, X[13], k7);
276 Subround<G,15>(c2, d2, e2, a2, b2, X[ 8], k8);
277 Subround<G, 5>(b2, c2, d2, e2, a2, X[ 6], k8);
278 Subround<G, 8>(a2, b2, c2, d2, e2, X[ 4], k8);
279 Subround<G,11>(e2, a2, b2, c2, d2, X[ 1], k8);
280 Subround<G,14>(d2, e2, a2, b2, c2, X[ 3], k8);
281 Subround<G,14>(c2, d2, e2, a2, b2, X[11], k8);
282 Subround<G, 6>(b2, c2, d2, e2, a2, X[15], k8);
283 Subround<G,14>(a2, b2, c2, d2, e2, X[ 0], k8);
284 Subround<G, 6>(e2, a2, b2, c2, d2, X[ 5], k8);
285 Subround<G, 9>(d2, e2, a2, b2, c2, X[12], k8);
286 Subround<G,12>(c2, d2, e2, a2, b2, X[ 2], k8);
287 Subround<G, 9>(b2, c2, d2, e2, a2, X[13], k8);
288 Subround<G,12>(a2, b2, c2, d2, e2, X[ 9], k8);
289 Subround<G, 5>(e2, a2, b2, c2, d2, X[ 7], k8);
290 Subround<G,15>(d2, e2, a2, b2, c2, X[10], k8);
291 Subround<G, 8>(c2, d2, e2, a2, b2, X[14], k8);
293 Subround<F, 8>(b2, c2, d2, e2, a2, X[12], k9);
294 Subround<F, 5>(a2, b2, c2, d2, e2, X[15], k9);
295 Subround<F,12>(e2, a2, b2, c2, d2, X[10], k9);
296 Subround<F, 9>(d2, e2, a2, b2, c2, X[ 4], k9);
297 Subround<F,12>(c2, d2, e2, a2, b2, X[ 1], k9);
298 Subround<F, 5>(b2, c2, d2, e2, a2, X[ 5], k9);
299 Subround<F,14>(a2, b2, c2, d2, e2, X[ 8], k9);
300 Subround<F, 6>(e2, a2, b2, c2, d2, X[ 7], k9);
301 Subround<F, 8>(d2, e2, a2, b2, c2, X[ 6], k9);
302 Subround<F,13>(c2, d2, e2, a2, b2, X[ 2], k9);
303 Subround<F, 6>(b2, c2, d2, e2, a2, X[13], k9);
304 Subround<F, 5>(a2, b2, c2, d2, e2, X[14], k9);
305 Subround<F,15>(e2, a2, b2, c2, d2, X[ 0], k9);
306 Subround<F,13>(d2, e2, a2, b2, c2, X[ 3], k9);
307 Subround<F,11>(c2, d2, e2, a2, b2, X[ 9], k9);
308 Subround<F,11>(b2, c2, d2, e2, a2, X[11], k9);
323 trackA[0] = (b1 + e1) - d2;
329 trackB[1] = (e1 + c1) - a2;
An invalid argument was detected.
Utility functions for the Crypto++ library.
static const int KEYLENGTH
The default key length used by the algorithm provided as a constant.
T rotlVariable(T x, unsigned int y)
Performs a left rotate.
unsigned int BlockSize() const
Provides the block size of the hash.
T rotlConstant(T x)
Performs a left rotate.
void CorrectEndianess(HashWordType *out, const HashWordType *in, size_t byteCount)
Adjusts the byte ordering of the hash.
void TruncatedFinal(byte *mac, size_t size)
Computes the hash of the current message.
void Restart()
Restart the hash.
std::string IntToString(T value, unsigned int base=10)
Converts a value to a string.
void UncheckedSetKey(const byte *userKey, unsigned int keylength, const NameValuePairs ¶ms)
Sets the key for this object without performing parameter validation.
Crypto++ library namespace.
Classes for the TTMAC message authentication code.
Interface for retrieving values given their names.