src/java.base/share/classes/sun/security/provider/SHA3.java
author ascarpino
Fri, 20 Jul 2018 09:55:15 -0700
changeset 51216 e429a304c97d
parent 47216 71c04702a3d5
permissions -rw-r--r--
8204196: integer cleanup Reviewed-by: xuelei
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     1
/*
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     2
 * Copyright (c) 2016, Oracle and/or its affiliates. All rights reserved.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     3
 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     4
 *
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     5
 * This code is free software; you can redistribute it and/or modify it
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     6
 * under the terms of the GNU General Public License version 2 only, as
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     7
 * published by the Free Software Foundation.  Oracle designates this
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     8
 * particular file as subject to the "Classpath" exception as provided
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
     9
 * by Oracle in the LICENSE file that accompanied this code.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    10
 *
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    11
 * This code is distributed in the hope that it will be useful, but WITHOUT
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    12
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    13
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    14
 * version 2 for more details (a copy is included in the LICENSE file that
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    15
 * accompanied this code).
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    16
 *
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    17
 * You should have received a copy of the GNU General Public License version
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    18
 * 2 along with this work; if not, write to the Free Software Foundation,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    19
 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    20
 *
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    21
 * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    22
 * or visit www.oracle.com if you need additional information or have any
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    23
 * questions.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    24
 */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    25
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    26
package sun.security.provider;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    27
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    28
import static sun.security.provider.ByteArrayAccess.*;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    29
import java.nio.*;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    30
import java.util.*;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    31
import java.security.*;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    32
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    33
/**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    34
 * This class implements the Secure Hash Algorithm SHA-3 developed by
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    35
 * the National Institute of Standards and Technology along with the
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    36
 * National Security Agency as defined in FIPS PUB 202.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    37
 *
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    38
 * <p>It implements java.security.MessageDigestSpi, and can be used
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    39
 * through Java Cryptography Architecture (JCA), as a pluggable
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    40
 * MessageDigest implementation.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    41
 *
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    42
 * @since       9
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    43
 * @author      Valerie Peng
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    44
 */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    45
abstract class SHA3 extends DigestBase {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    46
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    47
    private static final int WIDTH = 200; // in bytes, e.g. 1600 bits
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    48
    private static final int DM = 5; // dimension of lanes
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    49
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    50
    private static final int NR = 24; // number of rounds
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    51
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    52
    // precomputed round constants needed by the step mapping Iota
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    53
    private static final long[] RC_CONSTANTS = {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    54
        0x01L, 0x8082L, 0x800000000000808aL,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    55
        0x8000000080008000L, 0x808bL, 0x80000001L,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    56
        0x8000000080008081L, 0x8000000000008009L, 0x8aL,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    57
        0x88L, 0x80008009L, 0x8000000aL,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    58
        0x8000808bL, 0x800000000000008bL, 0x8000000000008089L,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    59
        0x8000000000008003L, 0x8000000000008002L, 0x8000000000000080L,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    60
        0x800aL, 0x800000008000000aL, 0x8000000080008081L,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    61
        0x8000000000008080L, 0x80000001L, 0x8000000080008008L,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    62
    };
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    63
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
    64
    private byte[] state = new byte[WIDTH];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
    65
    private final long[] lanes = new long[DM*DM];
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    66
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    67
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    68
     * Creates a new SHA-3 object.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    69
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    70
    SHA3(String name, int digestLength) {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    71
        super(name, digestLength, (WIDTH - (2 * digestLength)));
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    72
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    73
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    74
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    75
     * Core compression function. Processes blockSize bytes at a time
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    76
     * and updates the state of this object.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    77
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    78
    void implCompress(byte[] b, int ofs) {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    79
        for (int i = 0; i < buffer.length; i++) {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    80
            state[i] ^= b[ofs++];
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    81
        }
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
    82
        keccak();
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    83
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    84
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    85
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    86
     * Return the digest. Subclasses do not need to reset() themselves,
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    87
     * DigestBase calls implReset() when necessary.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    88
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    89
    void implDigest(byte[] out, int ofs) {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    90
        int numOfPadding =
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    91
            setPaddingBytes(buffer, (int)(bytesProcessed % buffer.length));
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    92
        if (numOfPadding < 1) {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    93
            throw new ProviderException("Incorrect pad size: " + numOfPadding);
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    94
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    95
        for (int i = 0; i < buffer.length; i++) {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    96
            state[i] ^= buffer[i];
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    97
        }
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
    98
        keccak();
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
    99
        System.arraycopy(state, 0, out, ofs, engineGetDigestLength());
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   100
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   101
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   102
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   103
     * Resets the internal state to start a new hash.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   104
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   105
    void implReset() {
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   106
        Arrays.fill(state, (byte)0);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   107
        Arrays.fill(lanes, 0L);
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   108
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   109
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   110
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   111
     * Utility function for padding the specified data based on the
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   112
     * pad10*1 algorithm (section 5.1) and the 2-bit suffix "01" required
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   113
     * for SHA-3 hash (section 6.1).
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   114
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   115
    private static int setPaddingBytes(byte[] in, int len) {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   116
        if (len != in.length) {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   117
            // erase leftover values
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   118
            Arrays.fill(in, len, in.length, (byte)0);
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   119
            // directly store the padding bytes into the input
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   120
            // as the specified buffer is allocated w/ size = rateR
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   121
            in[len] |= (byte) 0x06;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   122
            in[in.length - 1] |= (byte) 0x80;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   123
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   124
        return (in.length - len);
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   125
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   126
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   127
    /**
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   128
     * Utility function for transforming the specified byte array 's'
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   129
     * into array of lanes 'm' as defined in section 3.1.2.
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   130
     */
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   131
    private static void bytes2Lanes(byte[] s, long[] m) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   132
        int sOfs = 0;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   133
        // Conversion traverses along x-axis before y-axis
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   134
        for (int y = 0; y < DM; y++, sOfs += 40) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   135
            b2lLittle(s, sOfs, m, DM*y, 40);
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   136
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   137
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   138
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   139
    /**
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   140
     * Utility function for transforming the specified array of
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   141
     * lanes 'm' into a byte array 's' as defined in section 3.1.3.
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   142
     */
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   143
    private static void lanes2Bytes(long[] m, byte[] s) {
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   144
        int sOfs = 0;
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   145
        // Conversion traverses along x-axis before y-axis
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   146
        for (int y = 0; y < DM; y++, sOfs += 40) {
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   147
            l2bLittle(m, DM*y, s, sOfs, 40);
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   148
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   149
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   150
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   151
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   152
     * Step mapping Theta as defined in section 3.2.1 .
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   153
     */
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   154
    private static long[] smTheta(long[] a) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   155
        long c0 = a[0]^a[5]^a[10]^a[15]^a[20];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   156
        long c1 = a[1]^a[6]^a[11]^a[16]^a[21];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   157
        long c2 = a[2]^a[7]^a[12]^a[17]^a[22];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   158
        long c3 = a[3]^a[8]^a[13]^a[18]^a[23];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   159
        long c4 = a[4]^a[9]^a[14]^a[19]^a[24];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   160
        long d0 = c4 ^ Long.rotateLeft(c1, 1);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   161
        long d1 = c0 ^ Long.rotateLeft(c2, 1);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   162
        long d2 = c1 ^ Long.rotateLeft(c3, 1);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   163
        long d3 = c2 ^ Long.rotateLeft(c4, 1);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   164
        long d4 = c3 ^ Long.rotateLeft(c0, 1);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   165
        for (int y = 0; y < a.length; y += DM) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   166
            a[y] ^= d0;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   167
            a[y+1] ^= d1;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   168
            a[y+2] ^= d2;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   169
            a[y+3] ^= d3;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   170
            a[y+4] ^= d4;
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   171
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   172
        return a;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   173
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   174
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   175
    /**
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   176
     * Merged Step mapping Rho (section 3.2.2) and Pi (section 3.2.3).
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   177
     * for performance. Optimization is achieved by precalculating
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   178
     * shift constants for the following loop
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   179
     *   int xNext, yNext;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   180
     *   for (int t = 0, x = 1, y = 0; t <= 23; t++, x = xNext, y = yNext) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   181
     *        int numberOfShift = ((t + 1)*(t + 2)/2) % 64;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   182
     *        a[y][x] = Long.rotateLeft(a[y][x], numberOfShift);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   183
     *        xNext = y;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   184
     *        yNext = (2 * x + 3 * y) % DM;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   185
     *   }
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   186
     * and with inplace permutation.
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   187
     */
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   188
    private static long[] smPiRho(long[] a) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   189
        long tmp = Long.rotateLeft(a[10], 3);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   190
        a[10] = Long.rotateLeft(a[1], 1);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   191
        a[1] = Long.rotateLeft(a[6], 44);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   192
        a[6] = Long.rotateLeft(a[9], 20);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   193
        a[9] = Long.rotateLeft(a[22], 61);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   194
        a[22] = Long.rotateLeft(a[14], 39);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   195
        a[14] = Long.rotateLeft(a[20], 18);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   196
        a[20] = Long.rotateLeft(a[2], 62);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   197
        a[2] = Long.rotateLeft(a[12], 43);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   198
        a[12] = Long.rotateLeft(a[13], 25);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   199
        a[13] = Long.rotateLeft(a[19], 8);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   200
        a[19] = Long.rotateLeft(a[23], 56);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   201
        a[23] = Long.rotateLeft(a[15], 41);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   202
        a[15] = Long.rotateLeft(a[4], 27);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   203
        a[4] = Long.rotateLeft(a[24], 14);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   204
        a[24] = Long.rotateLeft(a[21], 2);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   205
        a[21] = Long.rotateLeft(a[8], 55);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   206
        a[8] = Long.rotateLeft(a[16], 45);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   207
        a[16] = Long.rotateLeft(a[5], 36);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   208
        a[5] = Long.rotateLeft(a[3], 28);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   209
        a[3] = Long.rotateLeft(a[18], 21);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   210
        a[18] = Long.rotateLeft(a[17], 15);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   211
        a[17] = Long.rotateLeft(a[11], 10);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   212
        a[11] = Long.rotateLeft(a[7], 6);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   213
        a[7] = tmp;
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   214
        return a;
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   215
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   216
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   217
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   218
     * Step mapping Chi as defined in section 3.2.4.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   219
     */
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   220
    private static long[] smChi(long[] a) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   221
        for (int y = 0; y < a.length; y+=DM) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   222
            long ay0 = a[y];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   223
            long ay1 = a[y+1];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   224
            long ay2 = a[y+2];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   225
            long ay3 = a[y+3];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   226
            long ay4 = a[y+4];
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   227
            a[y] = ay0 ^ ((~ay1) & ay2);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   228
            a[y+1] = ay1 ^ ((~ay2) & ay3);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   229
            a[y+2] = ay2 ^ ((~ay3) & ay4);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   230
            a[y+3] = ay3 ^ ((~ay4) & ay0);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   231
            a[y+4] = ay4 ^ ((~ay0) & ay1);
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   232
        }
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   233
        return a;
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   234
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   235
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   236
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   237
     * Step mapping Iota as defined in section 3.2.5.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   238
     */
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   239
    private static long[] smIota(long[] a, int rndIndex) {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   240
        a[0] ^= RC_CONSTANTS[rndIndex];
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   241
        return a;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   242
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   243
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   244
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   245
     * The function Keccak as defined in section 5.2 with
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   246
     * rate r = 1600 and capacity c = (digest length x 2).
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   247
     */
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   248
    private void keccak() {
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   249
        // convert the 200-byte state into 25 lanes
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   250
        bytes2Lanes(state, lanes);
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   251
        // process the lanes through step mappings
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   252
        for (int ir = 0; ir < NR; ir++) {
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   253
            smIota(smChi(smPiRho(smTheta(lanes))), ir);
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   254
        }
38877
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   255
        // convert the resulting 25 lanes back into 200-byte state
2c4dd22f0629 8157495: SHA-3 Hash algorithm performance improvements (~12x speedup)
valeriep
parents: 37909
diff changeset
   256
        lanes2Bytes(lanes, state);
37909
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   257
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   258
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   259
    public Object clone() throws CloneNotSupportedException {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   260
        SHA3 copy = (SHA3) super.clone();
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   261
        copy.state = copy.state.clone();
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   262
        return copy;
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   263
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   264
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   265
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   266
     * SHA3-224 implementation class.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   267
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   268
    public static final class SHA224 extends SHA3 {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   269
        public SHA224() {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   270
            super("SHA3-224", 28);
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   271
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   272
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   273
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   274
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   275
     * SHA3-256 implementation class.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   276
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   277
    public static final class SHA256 extends SHA3 {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   278
        public SHA256() {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   279
            super("SHA3-256", 32);
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   280
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   281
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   282
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   283
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   284
     * SHAs-384 implementation class.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   285
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   286
    public static final class SHA384 extends SHA3 {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   287
        public SHA384() {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   288
            super("SHA3-384", 48);
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   289
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   290
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   291
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   292
    /**
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   293
     * SHA3-512 implementation class.
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   294
     */
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   295
    public static final class SHA512 extends SHA3 {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   296
        public SHA512() {
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   297
            super("SHA3-512", 64);
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   298
        }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   299
    }
38b1efe33344 8000415: Add support for SHA-3
valeriep
parents:
diff changeset
   300
}