mgf1: Refactored MGF1 as an XOF
This commit is contained in:
@@ -1,180 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2013-2014 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "mgf1.h"
|
||||
|
||||
#include "crypto/hashers/hasher.h"
|
||||
#include "utils/debug.h"
|
||||
#include "utils/test.h"
|
||||
|
||||
typedef struct private_mgf1_t private_mgf1_t;
|
||||
|
||||
/**
|
||||
* Private data of an mgf1_t object.
|
||||
*/
|
||||
struct private_mgf1_t {
|
||||
|
||||
/**
|
||||
* Public mgf1_t interface.
|
||||
*/
|
||||
mgf1_t public;
|
||||
|
||||
/**
|
||||
* Hasher the MGF1 Mask Generation Function is based on
|
||||
*/
|
||||
hasher_t *hasher;
|
||||
|
||||
/**
|
||||
* Counter
|
||||
*/
|
||||
uint32_t counter;
|
||||
|
||||
/**
|
||||
* Set if counter has reached 2^32
|
||||
*/
|
||||
bool overflow;
|
||||
|
||||
/**
|
||||
* Current state to be hashed
|
||||
*/
|
||||
chunk_t state;
|
||||
|
||||
/**
|
||||
* Position of the 4 octet counter string
|
||||
*/
|
||||
u_char *ctr_str;
|
||||
|
||||
};
|
||||
|
||||
METHOD(mgf1_t, get_hash_size, size_t,
|
||||
private_mgf1_t *this)
|
||||
{
|
||||
return this->hasher->get_hash_size(this->hasher);
|
||||
}
|
||||
|
||||
METHOD(mgf1_t, get_mask, bool,
|
||||
private_mgf1_t *this, size_t mask_len, u_char *mask)
|
||||
{
|
||||
u_char buf[HASH_SIZE_SHA512];
|
||||
size_t hash_len;
|
||||
|
||||
hash_len = this->hasher->get_hash_size(this->hasher);
|
||||
|
||||
while (mask_len > 0)
|
||||
{
|
||||
/* detect overflow, set counter string and increment counter */
|
||||
if (this->overflow)
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
htoun32(this->ctr_str, this->counter++);
|
||||
if (this->counter == 0)
|
||||
{
|
||||
this->overflow = TRUE;
|
||||
}
|
||||
|
||||
/* get the next or final mask block from the hash function */
|
||||
if (!this->hasher->get_hash(this->hasher, this->state,
|
||||
(mask_len < hash_len) ? buf : mask))
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
if (mask_len < hash_len)
|
||||
{
|
||||
memcpy(mask, buf, mask_len);
|
||||
return TRUE;
|
||||
}
|
||||
mask_len -= hash_len;
|
||||
mask += hash_len;
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(mgf1_t, allocate_mask, bool,
|
||||
private_mgf1_t *this, size_t mask_len, chunk_t *mask)
|
||||
{
|
||||
if (mask_len == 0)
|
||||
{
|
||||
*mask = chunk_empty;
|
||||
return TRUE;
|
||||
}
|
||||
*mask = chunk_alloc(mask_len);
|
||||
|
||||
return get_mask(this, mask_len, mask->ptr);
|
||||
}
|
||||
|
||||
METHOD(mgf1_t, destroy, void,
|
||||
private_mgf1_t *this)
|
||||
{
|
||||
this->hasher->destroy(this->hasher);
|
||||
chunk_clear(&this->state);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* Described in header.
|
||||
*/
|
||||
mgf1_t *mgf1_create(hash_algorithm_t alg, chunk_t seed,
|
||||
bool hash_seed)
|
||||
{
|
||||
private_mgf1_t *this;
|
||||
hasher_t *hasher;
|
||||
size_t state_len;
|
||||
|
||||
if (seed.len == 0)
|
||||
{
|
||||
DBG1(DBG_LIB, "empty seed for MGF1");
|
||||
return NULL;
|
||||
}
|
||||
|
||||
hasher = lib->crypto->create_hasher(lib->crypto, alg);
|
||||
if (!hasher)
|
||||
{
|
||||
DBG1(DBG_LIB, "failed to create %N hasher for MGF1",
|
||||
hash_algorithm_names, alg);
|
||||
return NULL;
|
||||
}
|
||||
state_len = (hash_seed ? hasher->get_hash_size(hasher) : seed.len) + 4;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.get_hash_size = _get_hash_size,
|
||||
.allocate_mask = _allocate_mask,
|
||||
.get_mask = _get_mask,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.hasher = hasher,
|
||||
.state = chunk_alloc(state_len),
|
||||
);
|
||||
|
||||
/* determine position of the 4 octet counter string */
|
||||
this->ctr_str = this->state.ptr + state_len - 4;
|
||||
|
||||
if (hash_seed)
|
||||
{
|
||||
if (!hasher->get_hash(hasher, seed, this->state.ptr))
|
||||
{
|
||||
DBG1(DBG_LIB, "failed to hash seed for MGF1");
|
||||
destroy(this);
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
memcpy(this->state.ptr, seed.ptr, seed.len);
|
||||
}
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
@@ -1,77 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2013-2014 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup mgf1 mgf1
|
||||
* @{ @ingroup crypto
|
||||
*/
|
||||
|
||||
#ifndef MGF1_H_
|
||||
#define MGF1_H_
|
||||
|
||||
typedef struct mgf1_t mgf1_t;
|
||||
|
||||
#include <library.h>
|
||||
|
||||
/**
|
||||
* Implements the PKCS#1 MGF1 Mask Generation Function based on a hash function
|
||||
* defined in section 10.2.1 of RFC 2437
|
||||
*/
|
||||
struct mgf1_t {
|
||||
|
||||
/**
|
||||
* Get the hash size of the underlying hash function
|
||||
*
|
||||
* @return hash size in bytes
|
||||
*/
|
||||
size_t (*get_hash_size)(mgf1_t *this);
|
||||
|
||||
/**
|
||||
* Generate a mask pattern and copy it to an output buffer
|
||||
* If the maximum number of requests has been reached, reseeding occurs
|
||||
*
|
||||
* @param mask_len number of mask bytes to generate
|
||||
* @param mask output buffer of minimum size mask_len
|
||||
* @return TRUE if successful
|
||||
*/
|
||||
bool (*get_mask)(mgf1_t *this, size_t mask_len, u_char *mask);
|
||||
|
||||
/**
|
||||
* Generate a mask pattern and return it in an allocated chunk
|
||||
*
|
||||
* @param mask_len number of mask bytes to generate
|
||||
* @param mask chunk containing generated mask
|
||||
* @return TRUE if successful
|
||||
*/
|
||||
bool (*allocate_mask)(mgf1_t *this, size_t mask_len, chunk_t *mask);
|
||||
|
||||
/**
|
||||
* Destroy the MGF1 object
|
||||
*/
|
||||
void (*destroy)(mgf1_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create an MGF1 object
|
||||
*
|
||||
* @param alg hash algorithm to be used by MGF1
|
||||
* @param seed seed used by MGF1 to generate mask from
|
||||
* @param hash_seed hash seed before using it as a seed for MGF1
|
||||
*/
|
||||
mgf1_t *mgf1_create(hash_algorithm_t alg, chunk_t seed,
|
||||
bool hash_seed);
|
||||
|
||||
#endif /** MGF1_H_ @}*/
|
||||
|
||||
@@ -1,208 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2014 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "mgf1_bitspender.h"
|
||||
|
||||
#include <crypto/mgf1/mgf1.h>
|
||||
|
||||
typedef struct private_mgf1_bitspender_t private_mgf1_bitspender_t;
|
||||
|
||||
/**
|
||||
* Private data structure for mgf1_bitspender_t object
|
||||
*/
|
||||
struct private_mgf1_bitspender_t {
|
||||
/**
|
||||
* Public interface.
|
||||
*/
|
||||
mgf1_bitspender_t public;
|
||||
|
||||
/**
|
||||
* MGF1 bit mask generator
|
||||
*/
|
||||
mgf1_t *mgf1;
|
||||
|
||||
/**
|
||||
* Octet storage (accommodates up to 64 octets)
|
||||
*/
|
||||
uint8_t octets[HASH_SIZE_SHA512];
|
||||
|
||||
/**
|
||||
* Length of the returned hash value in octets
|
||||
*/
|
||||
int hash_len;
|
||||
|
||||
/**
|
||||
* Number of generated octets
|
||||
*/
|
||||
int octets_count;
|
||||
|
||||
/**
|
||||
* Number of available octets
|
||||
*/
|
||||
int octets_left;
|
||||
|
||||
/**
|
||||
* Bit storage (accommodates up to 32 bits)
|
||||
*/
|
||||
uint32_t bits;
|
||||
|
||||
/**
|
||||
* Number of available bits
|
||||
*/
|
||||
int bits_left;
|
||||
|
||||
/**
|
||||
* Byte storage (accommodates up to 4 bytes)
|
||||
*/
|
||||
uint8_t bytes[4];
|
||||
|
||||
/**
|
||||
* Number of available bytes
|
||||
*/
|
||||
int bytes_left;
|
||||
|
||||
};
|
||||
|
||||
METHOD(mgf1_bitspender_t, get_bits, bool,
|
||||
private_mgf1_bitspender_t *this, int bits_needed, uint32_t *bits)
|
||||
{
|
||||
int bits_now;
|
||||
|
||||
*bits = 0x00000000;
|
||||
|
||||
if (bits_needed == 0)
|
||||
{
|
||||
/* trivial */
|
||||
return TRUE;
|
||||
}
|
||||
if (bits_needed > 32)
|
||||
{
|
||||
/* too many bits requested */
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
while (bits_needed)
|
||||
{
|
||||
if (this->bits_left == 0)
|
||||
{
|
||||
if (this->octets_left == 0)
|
||||
{
|
||||
/* get another block from MGF1 */
|
||||
if (!this->mgf1->get_mask(this->mgf1, this->hash_len,
|
||||
this->octets))
|
||||
{
|
||||
/* no block available */
|
||||
return FALSE;
|
||||
}
|
||||
this->octets_left = this->hash_len;
|
||||
this->octets_count += this->hash_len;
|
||||
}
|
||||
this->bits = untoh32(this->octets + this->hash_len -
|
||||
this->octets_left);
|
||||
this->bits_left = 32;
|
||||
this->octets_left -= 4;
|
||||
}
|
||||
if (bits_needed > this->bits_left)
|
||||
{
|
||||
bits_now = this->bits_left;
|
||||
this->bits_left = 0;
|
||||
bits_needed -= bits_now;
|
||||
}
|
||||
else
|
||||
{
|
||||
bits_now = bits_needed;
|
||||
this->bits_left -= bits_needed;
|
||||
bits_needed = 0;
|
||||
}
|
||||
if (bits_now == 32)
|
||||
{
|
||||
*bits = this->bits;
|
||||
}
|
||||
else
|
||||
{
|
||||
*bits <<= bits_now;
|
||||
*bits |= this->bits >> this->bits_left;
|
||||
if (this->bits_left)
|
||||
{
|
||||
this->bits &= 0xffffffff >> (32 - this->bits_left);
|
||||
}
|
||||
}
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(mgf1_bitspender_t, get_byte, bool,
|
||||
private_mgf1_bitspender_t *this, uint8_t *byte)
|
||||
{
|
||||
if (this->bytes_left == 0)
|
||||
{
|
||||
if (this->octets_left == 0)
|
||||
{
|
||||
/* get another block from MGF1 */
|
||||
if (!this->mgf1->get_mask(this->mgf1, this->hash_len, this->octets))
|
||||
{
|
||||
/* no block available */
|
||||
return FALSE;
|
||||
}
|
||||
this->octets_left = this->hash_len;
|
||||
this->octets_count += this->hash_len;
|
||||
}
|
||||
memcpy(this->bytes, this->octets + this->hash_len - this->octets_left, 4);
|
||||
this->bytes_left = 4;
|
||||
this->octets_left -= 4;
|
||||
}
|
||||
*byte = this->bytes[4 - this->bytes_left--];
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(mgf1_bitspender_t, destroy, void,
|
||||
private_mgf1_bitspender_t *this)
|
||||
{
|
||||
DBG2(DBG_LIB, "mgf1 generated %u octets", this->octets_count);
|
||||
memwipe(this->octets, sizeof(this->octets));
|
||||
this->mgf1->destroy(this->mgf1);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* See header.
|
||||
*/
|
||||
mgf1_bitspender_t *mgf1_bitspender_create(hash_algorithm_t alg, chunk_t seed,
|
||||
bool hash_seed)
|
||||
{
|
||||
private_mgf1_bitspender_t *this;
|
||||
mgf1_t *mgf1;
|
||||
|
||||
mgf1 = mgf1_create(alg, seed, hash_seed);
|
||||
if (!mgf1)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
DBG2(DBG_LIB, "mgf1 based on %N is seeded with %u octets",
|
||||
hash_algorithm_short_names, alg, seed.len);
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.get_bits = _get_bits,
|
||||
.get_byte = _get_byte,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.mgf1 = mgf1,
|
||||
.hash_len = mgf1->get_hash_size(mgf1),
|
||||
);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
/*
|
||||
* Copyright (C) 2016 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup mgf1 mgf1
|
||||
* @{ @ingroup crypto
|
||||
*/
|
||||
|
||||
#ifndef MGF1_H_
|
||||
#define MGF1_H_
|
||||
|
||||
typedef struct mgf1_t mgf1_t;
|
||||
|
||||
#include "xof.h"
|
||||
|
||||
/**
|
||||
* Implements the PKCS#1 MGF1 Mask Generation Function based on a hash function
|
||||
* defined in section 10.2.1 of RFC 2437
|
||||
*/
|
||||
struct mgf1_t {
|
||||
|
||||
/**
|
||||
* Generic xof_t interface for this Extended Output Function (XOF).
|
||||
*/
|
||||
xof_t xof_interface;
|
||||
|
||||
/**
|
||||
* Hash the seed before using it as a seed for MGF1
|
||||
*
|
||||
* @param yes TRUE if seed has to be hashed first
|
||||
*/
|
||||
void (*set_hash_seed)(mgf1_t *this, bool yes);
|
||||
};
|
||||
|
||||
#endif /** MGF1_H_ @}*/
|
||||
@@ -17,11 +17,11 @@
|
||||
|
||||
ENUM(ext_out_function_names, XOF_UNDEFINED, XOF_CHACHA20,
|
||||
"XOF_UNDEFINED",
|
||||
"XOF_SHAKE128",
|
||||
"XOF_SHAKE256",
|
||||
"XOF_MGF1_SHA1",
|
||||
"XOF_MGF1_SHA256",
|
||||
"XOF_MGF1_SHA512",
|
||||
"XOF_SHAKE128",
|
||||
"XOF_SHAKE256",
|
||||
"XOF_CHACHA20"
|
||||
);
|
||||
|
||||
|
||||
@@ -31,16 +31,16 @@ typedef struct xof_t xof_t;
|
||||
*/
|
||||
enum ext_out_function_t {
|
||||
XOF_UNDEFINED,
|
||||
/** FIPS 202 */
|
||||
XOF_SHAKE_128,
|
||||
/** FIPS 202 */
|
||||
XOF_SHAKE_256,
|
||||
/** RFC 2437 PKCS#1 */
|
||||
XOF_MGF1_SHA1,
|
||||
/** RFC 2437 PKCS#1 */
|
||||
XOF_MGF1_SHA256,
|
||||
/** RFC 2437 PKCS#1 */
|
||||
XOF_MGF1_SHA512,
|
||||
/** FIPS 202 */
|
||||
XOF_SHAKE_128,
|
||||
/** FIPS 202 */
|
||||
XOF_SHAKE_256,
|
||||
/** RFC 7539 ChaCha20 */
|
||||
XOF_CHACHA20,
|
||||
};
|
||||
@@ -51,10 +51,17 @@ enum ext_out_function_t {
|
||||
extern enum_name_t *ext_out_function_names;
|
||||
|
||||
/**
|
||||
* Generic interface for pseudo-random-functions.
|
||||
* Generic interface for Extended Output Function (XOF)
|
||||
*/
|
||||
struct xof_t {
|
||||
|
||||
/**
|
||||
* Return the type of the Extended Output Function
|
||||
*
|
||||
* @return XOF type
|
||||
*/
|
||||
ext_out_function_t (*get_type)(xof_t *this);
|
||||
|
||||
/**
|
||||
* Generates pseudo random bytes and writes them in the buffer.
|
||||
*
|
||||
|
||||
@@ -0,0 +1,213 @@
|
||||
/*
|
||||
* Copyright (C) 2014-2016 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "xof_bitspender.h"
|
||||
#include "mgf1.h"
|
||||
|
||||
typedef struct private_xof_bitspender_t private_xof_bitspender_t;
|
||||
|
||||
/**
|
||||
* Private data structure for xof_bitspender_t object
|
||||
*/
|
||||
struct private_xof_bitspender_t {
|
||||
/**
|
||||
* Public interface.
|
||||
*/
|
||||
xof_bitspender_t public;
|
||||
|
||||
/**
|
||||
* Extended Output Function (XOF)
|
||||
*/
|
||||
xof_t *xof;
|
||||
|
||||
/**
|
||||
* Length of the returned hash value in octets
|
||||
*/
|
||||
int hash_len;
|
||||
|
||||
/**
|
||||
* Bit storage (accommodates up to 32 bits)
|
||||
*/
|
||||
uint32_t bits;
|
||||
|
||||
/**
|
||||
* Number of available bits
|
||||
*/
|
||||
int bits_left;
|
||||
|
||||
/**
|
||||
* Byte storage (accommodates up to 4 bytes)
|
||||
*/
|
||||
uint8_t bytes[4];
|
||||
|
||||
/**
|
||||
* Number of available bytes
|
||||
*/
|
||||
int bytes_left;
|
||||
|
||||
/**
|
||||
* Number of octets spent
|
||||
*/
|
||||
int octet_count;
|
||||
|
||||
};
|
||||
|
||||
static bool get_next_block(private_xof_bitspender_t *this, uint8_t *buffer)
|
||||
{
|
||||
if (!this->xof->get_bytes(this->xof, 4, buffer))
|
||||
{
|
||||
/* no block available */
|
||||
return FALSE;
|
||||
}
|
||||
this->octet_count += 4;
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(xof_bitspender_t, get_bits, bool,
|
||||
private_xof_bitspender_t *this, int bits_needed, uint32_t *bits)
|
||||
{
|
||||
int bits_now;
|
||||
|
||||
*bits = 0x00000000;
|
||||
|
||||
if (bits_needed == 0)
|
||||
{
|
||||
/* trivial */
|
||||
return TRUE;
|
||||
}
|
||||
if (bits_needed > 32)
|
||||
{
|
||||
/* too many bits requested */
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
while (bits_needed)
|
||||
{
|
||||
if (this->bits_left == 0)
|
||||
{
|
||||
uint8_t buf[4];
|
||||
|
||||
if (!get_next_block(this, buf))
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
this->bits = untoh32(buf);
|
||||
this->bits_left = 32;
|
||||
}
|
||||
if (bits_needed > this->bits_left)
|
||||
{
|
||||
bits_now = this->bits_left;
|
||||
this->bits_left = 0;
|
||||
bits_needed -= bits_now;
|
||||
}
|
||||
else
|
||||
{
|
||||
bits_now = bits_needed;
|
||||
this->bits_left -= bits_needed;
|
||||
bits_needed = 0;
|
||||
}
|
||||
if (bits_now == 32)
|
||||
{
|
||||
*bits = this->bits;
|
||||
}
|
||||
else
|
||||
{
|
||||
*bits <<= bits_now;
|
||||
*bits |= this->bits >> this->bits_left;
|
||||
if (this->bits_left)
|
||||
{
|
||||
this->bits &= 0xffffffff >> (32 - this->bits_left);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(xof_bitspender_t, get_byte, bool,
|
||||
private_xof_bitspender_t *this, uint8_t *byte)
|
||||
{
|
||||
if (this->bytes_left == 0)
|
||||
{
|
||||
if (!get_next_block(this, this->bytes))
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
this->bytes_left = 4;
|
||||
}
|
||||
*byte = this->bytes[4 - this->bytes_left--];
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(xof_bitspender_t, destroy, void,
|
||||
private_xof_bitspender_t *this)
|
||||
{
|
||||
DBG2(DBG_LIB, "%N generated %u octets", ext_out_function_names,
|
||||
this->xof->get_type(this->xof), this->octet_count);
|
||||
memwipe(this->bytes, 4);
|
||||
this->xof->destroy(this->xof);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* See header.
|
||||
*/
|
||||
xof_bitspender_t *xof_bitspender_create(ext_out_function_t alg, chunk_t seed,
|
||||
bool hash_seed)
|
||||
{
|
||||
private_xof_bitspender_t *this;
|
||||
xof_t *xof;
|
||||
|
||||
xof = lib->crypto->create_xof(lib->crypto, alg);
|
||||
if (!xof)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
switch (alg)
|
||||
{
|
||||
case XOF_MGF1_SHA1:
|
||||
case XOF_MGF1_SHA256:
|
||||
case XOF_MGF1_SHA512:
|
||||
{
|
||||
mgf1_t *mgf1 = (mgf1_t*)xof;
|
||||
|
||||
mgf1->set_hash_seed(mgf1, hash_seed);
|
||||
break;
|
||||
}
|
||||
default:
|
||||
break;
|
||||
}
|
||||
if (!xof->set_seed(xof, seed))
|
||||
{
|
||||
xof->destroy(xof);
|
||||
return NULL;
|
||||
}
|
||||
DBG2(DBG_LIB, "%N is seeded with %u octets", ext_out_function_names,
|
||||
alg, seed.len);
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.get_bits = _get_bits,
|
||||
.get_byte = _get_byte,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.xof = xof,
|
||||
);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
+20
-18
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2014 Andreas Steffen
|
||||
* Copyright (C) 2014-2016 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -14,22 +14,24 @@
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup mgf1_bitspender mgf1_bitspender
|
||||
* @defgroup xof_bitspender xof_bitspender
|
||||
* @{ @ingroup mgf1
|
||||
*/
|
||||
|
||||
#ifndef MGF1_BITSPENDER_H_
|
||||
#define MGF1_BITSPENDER_H_
|
||||
#ifndef XOF_BITSPENDER_H_
|
||||
#define XOF_BITSPENDER_H_
|
||||
|
||||
#include "xof.h"
|
||||
|
||||
#include <library.h>
|
||||
#include <crypto/hashers/hasher.h>
|
||||
|
||||
typedef struct mgf1_bitspender_t mgf1_bitspender_t;
|
||||
typedef struct xof_bitspender_t xof_bitspender_t;
|
||||
|
||||
/**
|
||||
* Generates a given number of pseudo-random bits at a time using MGF1
|
||||
* Generates a given number of pseudo-random bits at a time using an
|
||||
* Extended Output Function (XOF)
|
||||
*/
|
||||
struct mgf1_bitspender_t {
|
||||
struct xof_bitspender_t {
|
||||
|
||||
/**
|
||||
* Get pseudo-random bits
|
||||
@@ -38,7 +40,7 @@ struct mgf1_bitspender_t {
|
||||
* @param bits Pseudo-random bits
|
||||
* @result FALSE if internal MGF1 error occurred
|
||||
*/
|
||||
bool (*get_bits)(mgf1_bitspender_t *this, int bits_needed, uint32_t *bits);
|
||||
bool (*get_bits)(xof_bitspender_t *this, int bits_needed, uint32_t *bits);
|
||||
|
||||
/**
|
||||
* Get a pseudo-random byte
|
||||
@@ -46,22 +48,22 @@ struct mgf1_bitspender_t {
|
||||
* @param byte Pseudo-random byte
|
||||
* @result FALSE if internal MGF1 error occurred
|
||||
*/
|
||||
bool (*get_byte)(mgf1_bitspender_t *this, uint8_t *byte);
|
||||
bool (*get_byte)(xof_bitspender_t *this, uint8_t *byte);
|
||||
|
||||
/**
|
||||
* Destroy mgf1_bitspender_t object
|
||||
* Destroy xof_bitspender_t object
|
||||
*/
|
||||
void (*destroy)(mgf1_bitspender_t *this);
|
||||
void (*destroy)(xof_bitspender_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a mgf1_bitspender_t object
|
||||
* Create a xof_bitspender_t object
|
||||
*
|
||||
* @param alg Hash algorithm to be used with MGF1
|
||||
* @param seed Seed used to initialize MGF1
|
||||
* @param alg XOF to be used
|
||||
* @param seed Seed used to initialize XOF
|
||||
* @param hash_seed Hash seed before using it as a seed for MFG1
|
||||
*/
|
||||
mgf1_bitspender_t *mgf1_bitspender_create(hash_algorithm_t alg, chunk_t seed,
|
||||
bool hash_seed);
|
||||
xof_bitspender_t *xof_bitspender_create(ext_out_function_t alg, chunk_t seed,
|
||||
bool hash_seed);
|
||||
|
||||
#endif /** MGF1_BITSPENDER_H_ @}*/
|
||||
#endif /** XOF_BITSPENDER_H_ @}*/
|
||||
Reference in New Issue
Block a user