You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

330 lines
8.1 KiB

4 years ago
  1. 'use strict';
  2. var utils = require('../utils');
  3. var common = require('../common');
  4. var assert = require('minimalistic-assert');
  5. var rotr64_hi = utils.rotr64_hi;
  6. var rotr64_lo = utils.rotr64_lo;
  7. var shr64_hi = utils.shr64_hi;
  8. var shr64_lo = utils.shr64_lo;
  9. var sum64 = utils.sum64;
  10. var sum64_hi = utils.sum64_hi;
  11. var sum64_lo = utils.sum64_lo;
  12. var sum64_4_hi = utils.sum64_4_hi;
  13. var sum64_4_lo = utils.sum64_4_lo;
  14. var sum64_5_hi = utils.sum64_5_hi;
  15. var sum64_5_lo = utils.sum64_5_lo;
  16. var BlockHash = common.BlockHash;
  17. var sha512_K = [
  18. 0x428a2f98, 0xd728ae22, 0x71374491, 0x23ef65cd,
  19. 0xb5c0fbcf, 0xec4d3b2f, 0xe9b5dba5, 0x8189dbbc,
  20. 0x3956c25b, 0xf348b538, 0x59f111f1, 0xb605d019,
  21. 0x923f82a4, 0xaf194f9b, 0xab1c5ed5, 0xda6d8118,
  22. 0xd807aa98, 0xa3030242, 0x12835b01, 0x45706fbe,
  23. 0x243185be, 0x4ee4b28c, 0x550c7dc3, 0xd5ffb4e2,
  24. 0x72be5d74, 0xf27b896f, 0x80deb1fe, 0x3b1696b1,
  25. 0x9bdc06a7, 0x25c71235, 0xc19bf174, 0xcf692694,
  26. 0xe49b69c1, 0x9ef14ad2, 0xefbe4786, 0x384f25e3,
  27. 0x0fc19dc6, 0x8b8cd5b5, 0x240ca1cc, 0x77ac9c65,
  28. 0x2de92c6f, 0x592b0275, 0x4a7484aa, 0x6ea6e483,
  29. 0x5cb0a9dc, 0xbd41fbd4, 0x76f988da, 0x831153b5,
  30. 0x983e5152, 0xee66dfab, 0xa831c66d, 0x2db43210,
  31. 0xb00327c8, 0x98fb213f, 0xbf597fc7, 0xbeef0ee4,
  32. 0xc6e00bf3, 0x3da88fc2, 0xd5a79147, 0x930aa725,
  33. 0x06ca6351, 0xe003826f, 0x14292967, 0x0a0e6e70,
  34. 0x27b70a85, 0x46d22ffc, 0x2e1b2138, 0x5c26c926,
  35. 0x4d2c6dfc, 0x5ac42aed, 0x53380d13, 0x9d95b3df,
  36. 0x650a7354, 0x8baf63de, 0x766a0abb, 0x3c77b2a8,
  37. 0x81c2c92e, 0x47edaee6, 0x92722c85, 0x1482353b,
  38. 0xa2bfe8a1, 0x4cf10364, 0xa81a664b, 0xbc423001,
  39. 0xc24b8b70, 0xd0f89791, 0xc76c51a3, 0x0654be30,
  40. 0xd192e819, 0xd6ef5218, 0xd6990624, 0x5565a910,
  41. 0xf40e3585, 0x5771202a, 0x106aa070, 0x32bbd1b8,
  42. 0x19a4c116, 0xb8d2d0c8, 0x1e376c08, 0x5141ab53,
  43. 0x2748774c, 0xdf8eeb99, 0x34b0bcb5, 0xe19b48a8,
  44. 0x391c0cb3, 0xc5c95a63, 0x4ed8aa4a, 0xe3418acb,
  45. 0x5b9cca4f, 0x7763e373, 0x682e6ff3, 0xd6b2b8a3,
  46. 0x748f82ee, 0x5defb2fc, 0x78a5636f, 0x43172f60,
  47. 0x84c87814, 0xa1f0ab72, 0x8cc70208, 0x1a6439ec,
  48. 0x90befffa, 0x23631e28, 0xa4506ceb, 0xde82bde9,
  49. 0xbef9a3f7, 0xb2c67915, 0xc67178f2, 0xe372532b,
  50. 0xca273ece, 0xea26619c, 0xd186b8c7, 0x21c0c207,
  51. 0xeada7dd6, 0xcde0eb1e, 0xf57d4f7f, 0xee6ed178,
  52. 0x06f067aa, 0x72176fba, 0x0a637dc5, 0xa2c898a6,
  53. 0x113f9804, 0xbef90dae, 0x1b710b35, 0x131c471b,
  54. 0x28db77f5, 0x23047d84, 0x32caab7b, 0x40c72493,
  55. 0x3c9ebe0a, 0x15c9bebc, 0x431d67c4, 0x9c100d4c,
  56. 0x4cc5d4be, 0xcb3e42b6, 0x597f299c, 0xfc657e2a,
  57. 0x5fcb6fab, 0x3ad6faec, 0x6c44198c, 0x4a475817
  58. ];
  59. function SHA512() {
  60. if (!(this instanceof SHA512))
  61. return new SHA512();
  62. BlockHash.call(this);
  63. this.h = [
  64. 0x6a09e667, 0xf3bcc908,
  65. 0xbb67ae85, 0x84caa73b,
  66. 0x3c6ef372, 0xfe94f82b,
  67. 0xa54ff53a, 0x5f1d36f1,
  68. 0x510e527f, 0xade682d1,
  69. 0x9b05688c, 0x2b3e6c1f,
  70. 0x1f83d9ab, 0xfb41bd6b,
  71. 0x5be0cd19, 0x137e2179 ];
  72. this.k = sha512_K;
  73. this.W = new Array(160);
  74. }
  75. utils.inherits(SHA512, BlockHash);
  76. module.exports = SHA512;
  77. SHA512.blockSize = 1024;
  78. SHA512.outSize = 512;
  79. SHA512.hmacStrength = 192;
  80. SHA512.padLength = 128;
  81. SHA512.prototype._prepareBlock = function _prepareBlock(msg, start) {
  82. var W = this.W;
  83. // 32 x 32bit words
  84. for (var i = 0; i < 32; i++)
  85. W[i] = msg[start + i];
  86. for (; i < W.length; i += 2) {
  87. var c0_hi = g1_512_hi(W[i - 4], W[i - 3]); // i - 2
  88. var c0_lo = g1_512_lo(W[i - 4], W[i - 3]);
  89. var c1_hi = W[i - 14]; // i - 7
  90. var c1_lo = W[i - 13];
  91. var c2_hi = g0_512_hi(W[i - 30], W[i - 29]); // i - 15
  92. var c2_lo = g0_512_lo(W[i - 30], W[i - 29]);
  93. var c3_hi = W[i - 32]; // i - 16
  94. var c3_lo = W[i - 31];
  95. W[i] = sum64_4_hi(
  96. c0_hi, c0_lo,
  97. c1_hi, c1_lo,
  98. c2_hi, c2_lo,
  99. c3_hi, c3_lo);
  100. W[i + 1] = sum64_4_lo(
  101. c0_hi, c0_lo,
  102. c1_hi, c1_lo,
  103. c2_hi, c2_lo,
  104. c3_hi, c3_lo);
  105. }
  106. };
  107. SHA512.prototype._update = function _update(msg, start) {
  108. this._prepareBlock(msg, start);
  109. var W = this.W;
  110. var ah = this.h[0];
  111. var al = this.h[1];
  112. var bh = this.h[2];
  113. var bl = this.h[3];
  114. var ch = this.h[4];
  115. var cl = this.h[5];
  116. var dh = this.h[6];
  117. var dl = this.h[7];
  118. var eh = this.h[8];
  119. var el = this.h[9];
  120. var fh = this.h[10];
  121. var fl = this.h[11];
  122. var gh = this.h[12];
  123. var gl = this.h[13];
  124. var hh = this.h[14];
  125. var hl = this.h[15];
  126. assert(this.k.length === W.length);
  127. for (var i = 0; i < W.length; i += 2) {
  128. var c0_hi = hh;
  129. var c0_lo = hl;
  130. var c1_hi = s1_512_hi(eh, el);
  131. var c1_lo = s1_512_lo(eh, el);
  132. var c2_hi = ch64_hi(eh, el, fh, fl, gh, gl);
  133. var c2_lo = ch64_lo(eh, el, fh, fl, gh, gl);
  134. var c3_hi = this.k[i];
  135. var c3_lo = this.k[i + 1];
  136. var c4_hi = W[i];
  137. var c4_lo = W[i + 1];
  138. var T1_hi = sum64_5_hi(
  139. c0_hi, c0_lo,
  140. c1_hi, c1_lo,
  141. c2_hi, c2_lo,
  142. c3_hi, c3_lo,
  143. c4_hi, c4_lo);
  144. var T1_lo = sum64_5_lo(
  145. c0_hi, c0_lo,
  146. c1_hi, c1_lo,
  147. c2_hi, c2_lo,
  148. c3_hi, c3_lo,
  149. c4_hi, c4_lo);
  150. c0_hi = s0_512_hi(ah, al);
  151. c0_lo = s0_512_lo(ah, al);
  152. c1_hi = maj64_hi(ah, al, bh, bl, ch, cl);
  153. c1_lo = maj64_lo(ah, al, bh, bl, ch, cl);
  154. var T2_hi = sum64_hi(c0_hi, c0_lo, c1_hi, c1_lo);
  155. var T2_lo = sum64_lo(c0_hi, c0_lo, c1_hi, c1_lo);
  156. hh = gh;
  157. hl = gl;
  158. gh = fh;
  159. gl = fl;
  160. fh = eh;
  161. fl = el;
  162. eh = sum64_hi(dh, dl, T1_hi, T1_lo);
  163. el = sum64_lo(dl, dl, T1_hi, T1_lo);
  164. dh = ch;
  165. dl = cl;
  166. ch = bh;
  167. cl = bl;
  168. bh = ah;
  169. bl = al;
  170. ah = sum64_hi(T1_hi, T1_lo, T2_hi, T2_lo);
  171. al = sum64_lo(T1_hi, T1_lo, T2_hi, T2_lo);
  172. }
  173. sum64(this.h, 0, ah, al);
  174. sum64(this.h, 2, bh, bl);
  175. sum64(this.h, 4, ch, cl);
  176. sum64(this.h, 6, dh, dl);
  177. sum64(this.h, 8, eh, el);
  178. sum64(this.h, 10, fh, fl);
  179. sum64(this.h, 12, gh, gl);
  180. sum64(this.h, 14, hh, hl);
  181. };
  182. SHA512.prototype._digest = function digest(enc) {
  183. if (enc === 'hex')
  184. return utils.toHex32(this.h, 'big');
  185. else
  186. return utils.split32(this.h, 'big');
  187. };
  188. function ch64_hi(xh, xl, yh, yl, zh) {
  189. var r = (xh & yh) ^ ((~xh) & zh);
  190. if (r < 0)
  191. r += 0x100000000;
  192. return r;
  193. }
  194. function ch64_lo(xh, xl, yh, yl, zh, zl) {
  195. var r = (xl & yl) ^ ((~xl) & zl);
  196. if (r < 0)
  197. r += 0x100000000;
  198. return r;
  199. }
  200. function maj64_hi(xh, xl, yh, yl, zh) {
  201. var r = (xh & yh) ^ (xh & zh) ^ (yh & zh);
  202. if (r < 0)
  203. r += 0x100000000;
  204. return r;
  205. }
  206. function maj64_lo(xh, xl, yh, yl, zh, zl) {
  207. var r = (xl & yl) ^ (xl & zl) ^ (yl & zl);
  208. if (r < 0)
  209. r += 0x100000000;
  210. return r;
  211. }
  212. function s0_512_hi(xh, xl) {
  213. var c0_hi = rotr64_hi(xh, xl, 28);
  214. var c1_hi = rotr64_hi(xl, xh, 2); // 34
  215. var c2_hi = rotr64_hi(xl, xh, 7); // 39
  216. var r = c0_hi ^ c1_hi ^ c2_hi;
  217. if (r < 0)
  218. r += 0x100000000;
  219. return r;
  220. }
  221. function s0_512_lo(xh, xl) {
  222. var c0_lo = rotr64_lo(xh, xl, 28);
  223. var c1_lo = rotr64_lo(xl, xh, 2); // 34
  224. var c2_lo = rotr64_lo(xl, xh, 7); // 39
  225. var r = c0_lo ^ c1_lo ^ c2_lo;
  226. if (r < 0)
  227. r += 0x100000000;
  228. return r;
  229. }
  230. function s1_512_hi(xh, xl) {
  231. var c0_hi = rotr64_hi(xh, xl, 14);
  232. var c1_hi = rotr64_hi(xh, xl, 18);
  233. var c2_hi = rotr64_hi(xl, xh, 9); // 41
  234. var r = c0_hi ^ c1_hi ^ c2_hi;
  235. if (r < 0)
  236. r += 0x100000000;
  237. return r;
  238. }
  239. function s1_512_lo(xh, xl) {
  240. var c0_lo = rotr64_lo(xh, xl, 14);
  241. var c1_lo = rotr64_lo(xh, xl, 18);
  242. var c2_lo = rotr64_lo(xl, xh, 9); // 41
  243. var r = c0_lo ^ c1_lo ^ c2_lo;
  244. if (r < 0)
  245. r += 0x100000000;
  246. return r;
  247. }
  248. function g0_512_hi(xh, xl) {
  249. var c0_hi = rotr64_hi(xh, xl, 1);
  250. var c1_hi = rotr64_hi(xh, xl, 8);
  251. var c2_hi = shr64_hi(xh, xl, 7);
  252. var r = c0_hi ^ c1_hi ^ c2_hi;
  253. if (r < 0)
  254. r += 0x100000000;
  255. return r;
  256. }
  257. function g0_512_lo(xh, xl) {
  258. var c0_lo = rotr64_lo(xh, xl, 1);
  259. var c1_lo = rotr64_lo(xh, xl, 8);
  260. var c2_lo = shr64_lo(xh, xl, 7);
  261. var r = c0_lo ^ c1_lo ^ c2_lo;
  262. if (r < 0)
  263. r += 0x100000000;
  264. return r;
  265. }
  266. function g1_512_hi(xh, xl) {
  267. var c0_hi = rotr64_hi(xh, xl, 19);
  268. var c1_hi = rotr64_hi(xl, xh, 29); // 61
  269. var c2_hi = shr64_hi(xh, xl, 6);
  270. var r = c0_hi ^ c1_hi ^ c2_hi;
  271. if (r < 0)
  272. r += 0x100000000;
  273. return r;
  274. }
  275. function g1_512_lo(xh, xl) {
  276. var c0_lo = rotr64_lo(xh, xl, 19);
  277. var c1_lo = rotr64_lo(xl, xh, 29); // 61
  278. var c2_lo = shr64_lo(xh, xl, 6);
  279. var r = c0_lo ^ c1_lo ^ c2_lo;
  280. if (r < 0)
  281. r += 0x100000000;
  282. return r;
  283. }