ripemd/
c256.rs

1use core::{convert::TryInto, mem::swap};
2
3pub const DIGEST_BUF_LEN: usize = 8;
4pub const HALF_DIGEST_BUF_LEN: usize = DIGEST_BUF_LEN / 2;
5pub const WORK_BUF_LEN: usize = 16;
6
7pub const H0: [u32; DIGEST_BUF_LEN] = [
8    0x6745_2301,
9    0xefcd_ab89,
10    0x98ba_dcfe,
11    0x1032_5476,
12    0x7654_3210,
13    0xfedc_ba98,
14    0x89ab_cdef,
15    0x0123_4567,
16];
17
18macro_rules! round(
19    ($a:expr, $b:expr, $c:expr, $d:expr,
20     $x:expr, $bits:expr, $add:expr, $round:expr) => ({
21        $a = $a.wrapping_add($round).wrapping_add($x).wrapping_add($add);
22        $a = $a.rotate_left($bits);
23    });
24);
25
26#[inline(always)]
27fn swap_idx(bb: &mut [u32; HALF_DIGEST_BUF_LEN], bbb: &mut [u32; HALF_DIGEST_BUF_LEN], idx: usize) {
28    swap(&mut bb[idx], &mut bbb[idx]);
29}
30
31macro_rules! process_block(
32    ($h:ident, $data:expr,
33    $( round1: h_ordering $f0:expr, $f1:expr, $f2:expr, $f3:expr;
34            data_index $data_index1:expr; roll_shift $bits1:expr )*;
35    $( round2: h_ordering $g0:expr, $g1:expr, $g2:expr, $g3:expr;
36            data_index $data_index2:expr; roll_shift $bits2:expr )*;
37    $( round3: h_ordering $h0:expr, $h1:expr, $h2:expr, $h3:expr;
38            data_index $data_index3:expr; roll_shift $bits3:expr )*;
39    $( round4: h_ordering $i0:expr, $i1:expr, $i2:expr, $i3:expr;
40            data_index $data_index4:expr; roll_shift $bits4:expr )*;
41    $( par_round1: h_ordering $pi0:expr, $pi1:expr, $pi2:expr, $pi3:expr;
42            data_index $pdata_index1:expr; roll_shift $pbits1:expr )*;
43    $( par_round2: h_ordering $ph0:expr, $ph1:expr, $ph2:expr, $ph3:expr;
44            data_index $pdata_index2:expr; roll_shift $pbits2:expr )*;
45    $( par_round3: h_ordering $pg0:expr, $pg1:expr, $pg2:expr, $pg3:expr;
46            data_index $pdata_index3:expr; roll_shift $pbits3:expr )*;
47    $( par_round4: h_ordering $pf0:expr, $pf1:expr, $pf2:expr, $pf3:expr;
48            data_index $pdata_index4:expr; roll_shift $pbits4:expr )*;
49    ) => ({
50        let mut bb = [0u32; HALF_DIGEST_BUF_LEN];
51        bb.copy_from_slice(&$h[..HALF_DIGEST_BUF_LEN]);
52
53        let mut bbb = [0u32; HALF_DIGEST_BUF_LEN];
54        bbb.copy_from_slice(&$h[HALF_DIGEST_BUF_LEN..]);
55
56
57        // Round 1
58        $( round!(bb[$f0], bb[$f1], bb[$f2], bb[$f3],
59            $data[$data_index1], $bits1, 0x0000_0000,
60            bb[$f1] ^ bb[$f2] ^ bb[$f3]); )*
61
62        // Parallel Round 1
63        $( round!(bbb[$pi0], bbb[$pi1], bbb[$pi2], bbb[$pi3],
64            $data[$pdata_index1], $pbits1, 0x50a2_8be6,
65            (bbb[$pi1] & bbb[$pi3]) | (bbb[$pi2] & !bbb[$pi3])); )*
66
67        swap_idx(&mut bb, &mut bbb, 0);
68
69
70        // Round 2
71        $( round!(bb[$g0], bb[$g1], bb[$g2], bb[$g3],
72            $data[$data_index2], $bits2, 0x5a82_7999,
73            (bb[$g1] & bb[$g2]) | (!bb[$g1] & bb[$g3])); )*
74
75        // Parallel Round 2
76        $( round!(bbb[$ph0], bbb[$ph1], bbb[$ph2], bbb[$ph3],
77            $data[$pdata_index2], $pbits2, 0x5c4d_d124,
78            (bbb[$ph1] | !bbb[$ph2]) ^ bbb[$ph3]); )*
79
80
81        swap_idx(&mut bb, &mut bbb, 1);
82
83
84        // Round 3
85        $( round!(bb[$h0], bb[$h1], bb[$h2], bb[$h3],
86            $data[$data_index3], $bits3, 0x6ed9_eba1,
87            (bb[$h1] | !bb[$h2]) ^ bb[$h3]); )*
88
89        // Parallel Round 3
90        $( round!(bbb[$pg0], bbb[$pg1], bbb[$pg2], bbb[$pg3],
91            $data[$pdata_index3], $pbits3, 0x6d70_3ef3,
92            (bbb[$pg1] & bbb[$pg2]) | (!bbb[$pg1] & bbb[$pg3])); )*
93
94        swap_idx(&mut bb, &mut bbb, 2);
95
96
97        // Round 4
98        $( round!(bb[$i0], bb[$i1], bb[$i2], bb[$i3],
99            $data[$data_index4], $bits4, 0x8f1b_bcdc,
100            (bb[$i1] & bb[$i3]) | (bb[$i2] & !bb[$i3])); )*
101
102
103        // Parallel Round 4
104        $( round!(bbb[$pf0], bbb[$pf1], bbb[$pf2], bbb[$pf3],
105            $data[$pdata_index4], $pbits4, 0x0000_0000,
106            bbb[$pf1] ^ bbb[$pf2] ^ bbb[$pf3]); )*
107
108        swap_idx(&mut bb,  &mut bbb, 3);
109
110        $h[0] = $h[0].wrapping_add(bb[0]);
111        $h[1] = $h[1].wrapping_add(bb[1]);
112        $h[2] = $h[2].wrapping_add(bb[2]);
113        $h[3] = $h[3].wrapping_add(bb[3]);
114        $h[4] = $h[4].wrapping_add(bbb[0]);
115        $h[5] = $h[5].wrapping_add(bbb[1]);
116        $h[6] = $h[6].wrapping_add(bbb[2]);
117        $h[7] = $h[7].wrapping_add(bbb[3]);
118    });
119);
120
121pub fn compress(h: &mut [u32; DIGEST_BUF_LEN], data: &[u8; 64]) {
122    let mut w = [0u32; WORK_BUF_LEN];
123    for (o, chunk) in w.iter_mut().zip(data.chunks_exact(4)) {
124        *o = u32::from_le_bytes(chunk.try_into().unwrap());
125    }
126
127    process_block!(h, w[..],
128
129    // Round 1
130        round1: h_ordering 0, 1, 2, 3; data_index  0; roll_shift 11
131        round1: h_ordering 3, 0, 1, 2; data_index  1; roll_shift 14
132        round1: h_ordering 2, 3, 0, 1; data_index  2; roll_shift 15
133        round1: h_ordering 1, 2, 3, 0; data_index  3; roll_shift 12
134        round1: h_ordering 0, 1, 2, 3; data_index  4; roll_shift  5
135        round1: h_ordering 3, 0, 1, 2; data_index  5; roll_shift  8
136        round1: h_ordering 2, 3, 0, 1; data_index  6; roll_shift  7
137        round1: h_ordering 1, 2, 3, 0; data_index  7; roll_shift  9
138        round1: h_ordering 0, 1, 2, 3; data_index  8; roll_shift 11
139        round1: h_ordering 3, 0, 1, 2; data_index  9; roll_shift 13
140        round1: h_ordering 2, 3, 0, 1; data_index 10; roll_shift 14
141        round1: h_ordering 1, 2, 3, 0; data_index 11; roll_shift 15
142        round1: h_ordering 0, 1, 2, 3; data_index 12; roll_shift  6
143        round1: h_ordering 3, 0, 1, 2; data_index 13; roll_shift  7
144        round1: h_ordering 2, 3, 0, 1; data_index 14; roll_shift  9
145        round1: h_ordering 1, 2, 3, 0; data_index 15; roll_shift  8;
146
147    // Round 2
148        round2: h_ordering 0, 1, 2, 3; data_index  7; roll_shift  7
149        round2: h_ordering 3, 0, 1, 2; data_index  4; roll_shift  6
150        round2: h_ordering 2, 3, 0, 1; data_index 13; roll_shift  8
151        round2: h_ordering 1, 2, 3, 0; data_index  1; roll_shift 13
152        round2: h_ordering 0, 1, 2, 3; data_index 10; roll_shift 11
153        round2: h_ordering 3, 0, 1, 2; data_index  6; roll_shift  9
154        round2: h_ordering 2, 3, 0, 1; data_index 15; roll_shift  7
155        round2: h_ordering 1, 2, 3, 0; data_index  3; roll_shift 15
156        round2: h_ordering 0, 1, 2, 3; data_index 12; roll_shift  7
157        round2: h_ordering 3, 0, 1, 2; data_index  0; roll_shift 12
158        round2: h_ordering 2, 3, 0, 1; data_index  9; roll_shift 15
159        round2: h_ordering 1, 2, 3, 0; data_index  5; roll_shift  9
160        round2: h_ordering 0, 1, 2, 3; data_index  2; roll_shift 11
161        round2: h_ordering 3, 0, 1, 2; data_index 14; roll_shift  7
162        round2: h_ordering 2, 3, 0, 1; data_index 11; roll_shift 13
163        round2: h_ordering 1, 2, 3, 0; data_index  8; roll_shift 12;
164
165    // Round 3
166        round3: h_ordering 0, 1, 2, 3; data_index  3; roll_shift 11
167        round3: h_ordering 3, 0, 1, 2; data_index 10; roll_shift 13
168        round3: h_ordering 2, 3, 0, 1; data_index 14; roll_shift  6
169        round3: h_ordering 1, 2, 3, 0; data_index  4; roll_shift  7
170        round3: h_ordering 0, 1, 2, 3; data_index  9; roll_shift 14
171        round3: h_ordering 3, 0, 1, 2; data_index 15; roll_shift  9
172        round3: h_ordering 2, 3, 0, 1; data_index  8; roll_shift 13
173        round3: h_ordering 1, 2, 3, 0; data_index  1; roll_shift 15
174        round3: h_ordering 0, 1, 2, 3; data_index  2; roll_shift 14
175        round3: h_ordering 3, 0, 1, 2; data_index  7; roll_shift  8
176        round3: h_ordering 2, 3, 0, 1; data_index  0; roll_shift 13
177        round3: h_ordering 1, 2, 3, 0; data_index  6; roll_shift  6
178        round3: h_ordering 0, 1, 2, 3; data_index 13; roll_shift  5
179        round3: h_ordering 3, 0, 1, 2; data_index 11; roll_shift 12
180        round3: h_ordering 2, 3, 0, 1; data_index  5; roll_shift  7
181        round3: h_ordering 1, 2, 3, 0; data_index 12; roll_shift  5;
182
183    // Round 4
184        round4: h_ordering 0, 1, 2, 3; data_index  1; roll_shift 11
185        round4: h_ordering 3, 0, 1, 2; data_index  9; roll_shift 12
186        round4: h_ordering 2, 3, 0, 1; data_index 11; roll_shift 14
187        round4: h_ordering 1, 2, 3, 0; data_index 10; roll_shift 15
188        round4: h_ordering 0, 1, 2, 3; data_index  0; roll_shift 14
189        round4: h_ordering 3, 0, 1, 2; data_index  8; roll_shift 15
190        round4: h_ordering 2, 3, 0, 1; data_index 12; roll_shift  9
191        round4: h_ordering 1, 2, 3, 0; data_index  4; roll_shift  8
192        round4: h_ordering 0, 1, 2, 3; data_index 13; roll_shift  9
193        round4: h_ordering 3, 0, 1, 2; data_index  3; roll_shift 14
194        round4: h_ordering 2, 3, 0, 1; data_index  7; roll_shift  5
195        round4: h_ordering 1, 2, 3, 0; data_index 15; roll_shift  6
196        round4: h_ordering 0, 1, 2, 3; data_index 14; roll_shift  8
197        round4: h_ordering 3, 0, 1, 2; data_index  5; roll_shift  6
198        round4: h_ordering 2, 3, 0, 1; data_index  6; roll_shift  5
199        round4: h_ordering 1, 2, 3, 0; data_index  2; roll_shift 12;
200
201    // Parallel Round 1
202        par_round1: h_ordering 0, 1, 2, 3; data_index  5; roll_shift  8
203        par_round1: h_ordering 3, 0, 1, 2; data_index 14; roll_shift  9
204        par_round1: h_ordering 2, 3, 0, 1; data_index  7; roll_shift  9
205        par_round1: h_ordering 1, 2, 3, 0; data_index  0; roll_shift 11
206        par_round1: h_ordering 0, 1, 2, 3; data_index  9; roll_shift 13
207        par_round1: h_ordering 3, 0, 1, 2; data_index  2; roll_shift 15
208        par_round1: h_ordering 2, 3, 0, 1; data_index 11; roll_shift 15
209        par_round1: h_ordering 1, 2, 3, 0; data_index  4; roll_shift  5
210        par_round1: h_ordering 0, 1, 2, 3; data_index 13; roll_shift  7
211        par_round1: h_ordering 3, 0, 1, 2; data_index  6; roll_shift  7
212        par_round1: h_ordering 2, 3, 0, 1; data_index 15; roll_shift  8
213        par_round1: h_ordering 1, 2, 3, 0; data_index  8; roll_shift 11
214        par_round1: h_ordering 0, 1, 2, 3; data_index  1; roll_shift 14
215        par_round1: h_ordering 3, 0, 1, 2; data_index 10; roll_shift 14
216        par_round1: h_ordering 2, 3, 0, 1; data_index  3; roll_shift 12
217        par_round1: h_ordering 1, 2, 3, 0; data_index 12; roll_shift  6;
218
219    // Parallel Round 2
220        par_round2: h_ordering 0, 1, 2, 3; data_index  6; roll_shift  9
221        par_round2: h_ordering 3, 0, 1, 2; data_index 11; roll_shift 13
222        par_round2: h_ordering 2, 3, 0, 1; data_index  3; roll_shift 15
223        par_round2: h_ordering 1, 2, 3, 0; data_index  7; roll_shift  7
224        par_round2: h_ordering 0, 1, 2, 3; data_index  0; roll_shift 12
225        par_round2: h_ordering 3, 0, 1, 2; data_index 13; roll_shift  8
226        par_round2: h_ordering 2, 3, 0, 1; data_index  5; roll_shift  9
227        par_round2: h_ordering 1, 2, 3, 0; data_index 10; roll_shift 11
228        par_round2: h_ordering 0, 1, 2, 3; data_index 14; roll_shift  7
229        par_round2: h_ordering 3, 0, 1, 2; data_index 15; roll_shift  7
230        par_round2: h_ordering 2, 3, 0, 1; data_index  8; roll_shift 12
231        par_round2: h_ordering 1, 2, 3, 0; data_index 12; roll_shift  7
232        par_round2: h_ordering 0, 1, 2, 3; data_index  4; roll_shift  6
233        par_round2: h_ordering 3, 0, 1, 2; data_index  9; roll_shift 15
234        par_round2: h_ordering 2, 3, 0, 1; data_index  1; roll_shift 13
235        par_round2: h_ordering 1, 2, 3, 0; data_index  2; roll_shift 11;
236
237    // Parallel Round 3
238        par_round3: h_ordering 0, 1, 2, 3; data_index 15; roll_shift  9
239        par_round3: h_ordering 3, 0, 1, 2; data_index  5; roll_shift  7
240        par_round3: h_ordering 2, 3, 0, 1; data_index  1; roll_shift 15
241        par_round3: h_ordering 1, 2, 3, 0; data_index  3; roll_shift 11
242        par_round3: h_ordering 0, 1, 2, 3; data_index  7; roll_shift  8
243        par_round3: h_ordering 3, 0, 1, 2; data_index 14; roll_shift  6
244        par_round3: h_ordering 2, 3, 0, 1; data_index  6; roll_shift  6
245        par_round3: h_ordering 1, 2, 3, 0; data_index  9; roll_shift 14
246        par_round3: h_ordering 0, 1, 2, 3; data_index 11; roll_shift 12
247        par_round3: h_ordering 3, 0, 1, 2; data_index  8; roll_shift 13
248        par_round3: h_ordering 2, 3, 0, 1; data_index 12; roll_shift  5
249        par_round3: h_ordering 1, 2, 3, 0; data_index  2; roll_shift 14
250        par_round3: h_ordering 0, 1, 2, 3; data_index 10; roll_shift 13
251        par_round3: h_ordering 3, 0, 1, 2; data_index  0; roll_shift 13
252        par_round3: h_ordering 2, 3, 0, 1; data_index  4; roll_shift  7
253        par_round3: h_ordering 1, 2, 3, 0; data_index 13; roll_shift  5;
254
255    // Parallel Round 4
256        par_round4: h_ordering 0, 1, 2, 3; data_index  8; roll_shift 15
257        par_round4: h_ordering 3, 0, 1, 2; data_index  6; roll_shift  5
258        par_round4: h_ordering 2, 3, 0, 1; data_index  4; roll_shift  8
259        par_round4: h_ordering 1, 2, 3, 0; data_index  1; roll_shift 11
260        par_round4: h_ordering 0, 1, 2, 3; data_index  3; roll_shift 14
261        par_round4: h_ordering 3, 0, 1, 2; data_index 11; roll_shift 14
262        par_round4: h_ordering 2, 3, 0, 1; data_index 15; roll_shift  6
263        par_round4: h_ordering 1, 2, 3, 0; data_index  0; roll_shift 14
264        par_round4: h_ordering 0, 1, 2, 3; data_index  5; roll_shift  6
265        par_round4: h_ordering 3, 0, 1, 2; data_index 12; roll_shift  9
266        par_round4: h_ordering 2, 3, 0, 1; data_index  2; roll_shift 12
267        par_round4: h_ordering 1, 2, 3, 0; data_index 13; roll_shift  9
268        par_round4: h_ordering 0, 1, 2, 3; data_index  9; roll_shift 12
269        par_round4: h_ordering 3, 0, 1, 2; data_index  7; roll_shift  5
270        par_round4: h_ordering 2, 3, 0, 1; data_index 10; roll_shift 15
271        par_round4: h_ordering 1, 2, 3, 0; data_index 14; roll_shift  8;
272    );
273}