[51821] | 1 | /* $Id: alt-md2.cpp 98103 2023-01-17 14:15:46Z vboxsync $ */
|
---|
| 2 | /** @file
|
---|
| 3 | * IPRT - Message-Digest Algorithm 2, Alternative Implementation.
|
---|
| 4 | */
|
---|
| 5 |
|
---|
| 6 | /*
|
---|
[98103] | 7 | * Copyright (C) 2009-2023 Oracle and/or its affiliates.
|
---|
[51821] | 8 | *
|
---|
[96407] | 9 | * This file is part of VirtualBox base platform packages, as
|
---|
| 10 | * available from https://www.virtualbox.org.
|
---|
[51821] | 11 | *
|
---|
[96407] | 12 | * This program is free software; you can redistribute it and/or
|
---|
| 13 | * modify it under the terms of the GNU General Public License
|
---|
| 14 | * as published by the Free Software Foundation, in version 3 of the
|
---|
| 15 | * License.
|
---|
| 16 | *
|
---|
| 17 | * This program is distributed in the hope that it will be useful, but
|
---|
| 18 | * WITHOUT ANY WARRANTY; without even the implied warranty of
|
---|
| 19 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
---|
| 20 | * General Public License for more details.
|
---|
| 21 | *
|
---|
| 22 | * You should have received a copy of the GNU General Public License
|
---|
| 23 | * along with this program; if not, see <https://www.gnu.org/licenses>.
|
---|
| 24 | *
|
---|
[51821] | 25 | * The contents of this file may alternatively be used under the terms
|
---|
| 26 | * of the Common Development and Distribution License Version 1.0
|
---|
[96407] | 27 | * (CDDL), a copy of it is provided in the "COPYING.CDDL" file included
|
---|
| 28 | * in the VirtualBox distribution, in which case the provisions of the
|
---|
[51821] | 29 | * CDDL are applicable instead of those of the GPL.
|
---|
| 30 | *
|
---|
| 31 | * You may elect to license modified versions of this file under the
|
---|
| 32 | * terms and conditions of either the GPL or the CDDL or both.
|
---|
[96407] | 33 | *
|
---|
| 34 | * SPDX-License-Identifier: GPL-3.0-only OR CDDL-1.0
|
---|
[51821] | 35 | */
|
---|
| 36 |
|
---|
| 37 |
|
---|
[57358] | 38 | /*********************************************************************************************************************************
|
---|
| 39 | * Defined Constants And Macros *
|
---|
| 40 | *********************************************************************************************************************************/
|
---|
[51821] | 41 | /** The MD2 block size. */
|
---|
| 42 | #define RTMD2_BLOCK_SIZE 16
|
---|
| 43 | /** The offset of the buffer into RTMD2ALTPRIVATECTX::abStateX. */
|
---|
| 44 | #define RTMD2_BUF_OFF RTMD2_BLOCK_SIZE
|
---|
| 45 |
|
---|
| 46 |
|
---|
[57358] | 47 | /*********************************************************************************************************************************
|
---|
| 48 | * Header Files *
|
---|
| 49 | *********************************************************************************************************************************/
|
---|
[51821] | 50 | #include "internal/iprt.h"
|
---|
| 51 | #include <iprt/types.h>
|
---|
| 52 |
|
---|
| 53 |
|
---|
| 54 | /** Our private context structure. */
|
---|
| 55 | typedef struct RTMD2ALTPRIVATECTX
|
---|
| 56 | {
|
---|
| 57 | /** The state (X).
|
---|
| 58 | * The staging buffer starts byte 16. */
|
---|
| 59 | uint8_t abStateX[RTMD2_BLOCK_SIZE * 3];
|
---|
| 60 | /** The checksum. */
|
---|
| 61 | uint8_t abChecksum[RTMD2_BLOCK_SIZE];
|
---|
| 62 | /** The number of buffered bytes. */
|
---|
| 63 | uint8_t cbBuffer;
|
---|
| 64 | } RTMD2ALTPRIVATECTX;
|
---|
| 65 |
|
---|
| 66 | #define RT_MD2_PRIVATE_ALT_CONTEXT
|
---|
| 67 | #include <iprt/md2.h>
|
---|
| 68 |
|
---|
| 69 | #include <iprt/assert.h>
|
---|
| 70 | #include <iprt/string.h>
|
---|
| 71 |
|
---|
| 72 | AssertCompile(RT_SIZEOFMEMB(RTMD2CONTEXT, abPadding) >= RT_SIZEOFMEMB(RTMD2CONTEXT, AltPrivate));
|
---|
| 73 |
|
---|
| 74 |
|
---|
[57358] | 75 | /*********************************************************************************************************************************
|
---|
| 76 | * Global Variables *
|
---|
| 77 | *********************************************************************************************************************************/
|
---|
[51821] | 78 | /** PI substitation used by MD2. */
|
---|
| 79 | static uint8_t const g_PiSubst[256] =
|
---|
| 80 | {
|
---|
| 81 | 41, 46, 67, 201, 162, 216, 124, 1, 61, 54, 84, 161, 236, 240, 6, 19,
|
---|
| 82 | 98, 167, 5, 243, 192, 199, 115, 140, 152, 147, 43, 217, 188, 76, 130, 202,
|
---|
| 83 | 30, 155, 87, 60, 253, 212, 224, 22, 103, 66, 111, 24, 138, 23, 229, 18,
|
---|
| 84 | 190, 78, 196, 214, 218, 158, 222, 73, 160, 251, 245, 142, 187, 47, 238, 122,
|
---|
| 85 | 169, 104, 121, 145, 21, 178, 7, 63, 148, 194, 16, 137, 11, 34, 95, 33,
|
---|
| 86 | 128, 127, 93, 154, 90, 144, 50, 39, 53, 62, 204, 231, 191, 247, 151, 3,
|
---|
| 87 | 255, 25, 48, 179, 72, 165, 181, 209, 215, 94, 146, 42, 172, 86, 170, 198,
|
---|
| 88 | 79, 184, 56, 210, 150, 164, 125, 182, 118, 252, 107, 226, 156, 116, 4, 241,
|
---|
| 89 | 69, 157, 112, 89, 100, 113, 135, 32, 134, 91, 207, 101, 230, 45, 168, 2,
|
---|
| 90 | 27, 96, 37, 173, 174, 176, 185, 246, 28, 70, 97, 105, 52, 64, 126, 15,
|
---|
| 91 | 85, 71, 163, 35, 221, 81, 175, 58, 195, 92, 249, 206, 186, 197, 234, 38,
|
---|
| 92 | 44, 83, 13, 110, 133, 40, 132, 9, 211, 223, 205, 244, 65, 129, 77, 82,
|
---|
| 93 | 106, 220, 55, 200, 108, 193, 171, 250, 36, 225, 123, 8, 12, 189, 177, 74,
|
---|
| 94 | 120, 136, 149, 139, 227, 99, 232, 109, 233, 203, 213, 254, 59, 0, 29, 57,
|
---|
| 95 | 242, 239, 183, 14, 102, 88, 208, 228, 166, 119, 114, 248, 235, 117, 75, 10,
|
---|
| 96 | 49, 68, 80, 180, 143, 237, 31, 26, 219, 153, 141, 51, 159, 17, 131, 20,
|
---|
| 97 | };
|
---|
| 98 |
|
---|
| 99 |
|
---|
| 100 | RTDECL(void) RTMd2Init(PRTMD2CONTEXT pCtx)
|
---|
| 101 | {
|
---|
| 102 | pCtx->AltPrivate.cbBuffer = 0;
|
---|
| 103 | RT_ZERO(pCtx->AltPrivate.abStateX);
|
---|
| 104 | RT_ZERO(pCtx->AltPrivate.abChecksum);
|
---|
| 105 | }
|
---|
| 106 | RT_EXPORT_SYMBOL(RTMd2Init);
|
---|
| 107 |
|
---|
| 108 |
|
---|
| 109 |
|
---|
| 110 | /**
|
---|
| 111 | * Initializes the processing of a whole block directly from the input buffer.
|
---|
| 112 | *
|
---|
| 113 | * This will update the checksum as well as initializing abStateX.
|
---|
| 114 | *
|
---|
| 115 | * @param pCtx The MD2 context.
|
---|
| 116 | * @param pbBlock The block.
|
---|
| 117 | */
|
---|
| 118 | DECLINLINE(void) rtMd2BlockInit(PRTMD2CONTEXT pCtx, const uint8_t *pbBlock)
|
---|
| 119 | {
|
---|
| 120 | uint8_t bL = pCtx->AltPrivate.abChecksum[15];
|
---|
| 121 | for (unsigned j = 0; j < RTMD2_BLOCK_SIZE; j++)
|
---|
| 122 | {
|
---|
| 123 | uint8_t bIn = pbBlock[j];
|
---|
| 124 | pCtx->AltPrivate.abStateX[j + RTMD2_BLOCK_SIZE] = bIn;
|
---|
| 125 | pCtx->AltPrivate.abStateX[j + RTMD2_BLOCK_SIZE * 2] = bIn ^ pCtx->AltPrivate.abStateX[j];
|
---|
| 126 | bL = pCtx->AltPrivate.abChecksum[j] ^= g_PiSubst[bIn ^ bL];
|
---|
| 127 | }
|
---|
| 128 | }
|
---|
| 129 |
|
---|
| 130 |
|
---|
| 131 | /**
|
---|
| 132 | * Special version of rtMd2BlockInit that does not update the checksum.
|
---|
| 133 | *
|
---|
| 134 | * This is used in the final round when adding the checksum to the calculation.
|
---|
| 135 | *
|
---|
| 136 | * @param pCtx The MD2 context.
|
---|
| 137 | * @param pbBlock The block (i.e. the checksum).
|
---|
| 138 | */
|
---|
| 139 | DECLINLINE(void) rtMd2BlockInitNoChecksum(PRTMD2CONTEXT pCtx, const uint8_t *pbBlock)
|
---|
| 140 | {
|
---|
| 141 | for (unsigned j = 0; j < RTMD2_BLOCK_SIZE; j++)
|
---|
| 142 | {
|
---|
| 143 | uint8_t bIn = pbBlock[j];
|
---|
| 144 | pCtx->AltPrivate.abStateX[j + RTMD2_BLOCK_SIZE] = bIn;
|
---|
| 145 | pCtx->AltPrivate.abStateX[j + RTMD2_BLOCK_SIZE * 2] = bIn ^ pCtx->AltPrivate.abStateX[j];
|
---|
| 146 | }
|
---|
| 147 | }
|
---|
| 148 |
|
---|
| 149 |
|
---|
| 150 | /**
|
---|
| 151 | * Initalizes the abStateX from a full buffer and update the checksum.
|
---|
| 152 | *
|
---|
| 153 | * The buffer is part of the abStateX structure (bytes 16 thru 31), so this
|
---|
| 154 | * is a somewhat reduced version of rtMd2BlockInit.
|
---|
| 155 | *
|
---|
| 156 | * @param pCtx The MD2 context.
|
---|
| 157 | */
|
---|
| 158 | DECLINLINE(void) rtMd2BlockInitBuffered(PRTMD2CONTEXT pCtx)
|
---|
| 159 | {
|
---|
| 160 | uint8_t bL = pCtx->AltPrivate.abChecksum[15];
|
---|
| 161 | for (unsigned j = 0; j < RTMD2_BLOCK_SIZE; j++)
|
---|
| 162 | {
|
---|
| 163 | uint8_t bIn = pCtx->AltPrivate.abStateX[j + RTMD2_BLOCK_SIZE];
|
---|
| 164 | pCtx->AltPrivate.abStateX[j + RTMD2_BLOCK_SIZE * 2] = bIn ^ pCtx->AltPrivate.abStateX[j];
|
---|
| 165 | bL = pCtx->AltPrivate.abChecksum[j] ^= g_PiSubst[bIn ^ bL];
|
---|
| 166 | }
|
---|
| 167 | }
|
---|
| 168 |
|
---|
| 169 |
|
---|
| 170 | /**
|
---|
| 171 | * Process the current block.
|
---|
| 172 | *
|
---|
| 173 | * Requires one of the rtMd2BlockInit functions to be called first.
|
---|
| 174 | *
|
---|
| 175 | * @param pCtx The MD2 context.
|
---|
| 176 | */
|
---|
| 177 | DECLINLINE(void) rtMd2BlockProcess(PRTMD2CONTEXT pCtx)
|
---|
| 178 | {
|
---|
| 179 | uint8_t bT = 0;
|
---|
| 180 | for (unsigned j = 0; j < 18; j++) /* 18 rounds */
|
---|
| 181 | {
|
---|
| 182 | for (unsigned k = 0; k < RTMD2_BLOCK_SIZE * 3; k++)
|
---|
| 183 | pCtx->AltPrivate.abStateX[k] = bT = pCtx->AltPrivate.abStateX[k] ^ g_PiSubst[bT];
|
---|
| 184 | bT += (uint8_t)j;
|
---|
| 185 | }
|
---|
| 186 | }
|
---|
| 187 |
|
---|
| 188 |
|
---|
| 189 | RTDECL(void) RTMd2Update(PRTMD2CONTEXT pCtx, const void *pvBuf, size_t cbBuf)
|
---|
| 190 | {
|
---|
| 191 | Assert(pCtx->AltPrivate.cbBuffer < RTMD2_BLOCK_SIZE);
|
---|
| 192 | uint8_t const *pbBuf = (uint8_t const *)pvBuf;
|
---|
| 193 |
|
---|
| 194 | /*
|
---|
| 195 | * Deal with buffered bytes first.
|
---|
| 196 | */
|
---|
| 197 | if (pCtx->AltPrivate.cbBuffer)
|
---|
| 198 | {
|
---|
| 199 | uint8_t cbMissing = RTMD2_BLOCK_SIZE - pCtx->AltPrivate.cbBuffer;
|
---|
| 200 | if (cbBuf >= cbMissing)
|
---|
| 201 | {
|
---|
| 202 | memcpy(&pCtx->AltPrivate.abStateX[RTMD2_BUF_OFF + pCtx->AltPrivate.cbBuffer], pbBuf, cbMissing);
|
---|
| 203 | pbBuf += cbMissing;
|
---|
| 204 | cbBuf -= cbMissing;
|
---|
| 205 |
|
---|
| 206 | rtMd2BlockInitBuffered(pCtx);
|
---|
| 207 | rtMd2BlockProcess(pCtx);
|
---|
| 208 |
|
---|
| 209 | pCtx->AltPrivate.cbBuffer = 0;
|
---|
| 210 | }
|
---|
| 211 | else
|
---|
| 212 | {
|
---|
| 213 | memcpy(&pCtx->AltPrivate.abStateX[RTMD2_BUF_OFF + pCtx->AltPrivate.cbBuffer], pbBuf, cbBuf);
|
---|
| 214 | pCtx->AltPrivate.cbBuffer += (uint8_t)cbBuf;
|
---|
| 215 | return;
|
---|
| 216 | }
|
---|
| 217 | }
|
---|
| 218 |
|
---|
| 219 | /*
|
---|
| 220 | * Process full blocks directly from the input buffer.
|
---|
| 221 | */
|
---|
| 222 | while (cbBuf >= RTMD2_BLOCK_SIZE)
|
---|
| 223 | {
|
---|
| 224 | rtMd2BlockInit(pCtx, pbBuf);
|
---|
| 225 | rtMd2BlockProcess(pCtx);
|
---|
| 226 |
|
---|
| 227 | pbBuf += RTMD2_BLOCK_SIZE;
|
---|
| 228 | cbBuf -= RTMD2_BLOCK_SIZE;
|
---|
| 229 | }
|
---|
| 230 |
|
---|
| 231 | /*
|
---|
| 232 | * Stash any remaining bytes into the context buffer.
|
---|
| 233 | */
|
---|
| 234 | if (cbBuf > 0)
|
---|
| 235 | {
|
---|
| 236 | memcpy(&pCtx->AltPrivate.abStateX[RTMD2_BUF_OFF], pbBuf, cbBuf);
|
---|
| 237 | pCtx->AltPrivate.cbBuffer = (uint8_t)cbBuf;
|
---|
| 238 | }
|
---|
| 239 | }
|
---|
| 240 | RT_EXPORT_SYMBOL(RTMd2Update);
|
---|
| 241 |
|
---|
| 242 |
|
---|
| 243 | RTDECL(void) RTMd2Final(PRTMD2CONTEXT pCtx, uint8_t pabDigest[RTMD2_HASH_SIZE])
|
---|
| 244 | {
|
---|
| 245 | Assert(pCtx->AltPrivate.cbBuffer < RTMD2_BLOCK_SIZE);
|
---|
| 246 |
|
---|
| 247 | /*
|
---|
| 248 | * Pad the message to a multiple of 16 bytes. This is done even if the
|
---|
| 249 | * message already is a multiple of 16.
|
---|
| 250 | */
|
---|
| 251 | unsigned cbPad = RTMD2_BLOCK_SIZE - pCtx->AltPrivate.cbBuffer;
|
---|
| 252 | memset(&pCtx->AltPrivate.abStateX[RTMD2_BUF_OFF + pCtx->AltPrivate.cbBuffer], cbPad, cbPad);
|
---|
| 253 | rtMd2BlockInitBuffered(pCtx);
|
---|
| 254 | rtMd2BlockProcess(pCtx);
|
---|
| 255 | pCtx->AltPrivate.cbBuffer = 0;
|
---|
| 256 |
|
---|
| 257 | /*
|
---|
| 258 | * Add the checksum.
|
---|
| 259 | */
|
---|
| 260 | rtMd2BlockInitNoChecksum(pCtx, pCtx->AltPrivate.abChecksum);
|
---|
| 261 | rtMd2BlockProcess(pCtx);
|
---|
| 262 |
|
---|
| 263 | /*
|
---|
| 264 | * Done. Just copy out the digest.
|
---|
| 265 | */
|
---|
| 266 | memcpy(pabDigest, pCtx->AltPrivate.abStateX, RTMD2_HASH_SIZE);
|
---|
| 267 |
|
---|
[51861] | 268 | RT_ZERO(pCtx->AltPrivate);
|
---|
[51821] | 269 | pCtx->AltPrivate.cbBuffer = UINT8_MAX;
|
---|
| 270 | }
|
---|
| 271 | RT_EXPORT_SYMBOL(RTMd2Final);
|
---|
| 272 |
|
---|
| 273 |
|
---|
| 274 | RTDECL(void) RTMd2(const void *pvBuf, size_t cbBuf, uint8_t pabDigest[RTMD2_HASH_SIZE])
|
---|
| 275 | {
|
---|
| 276 | RTMD2CONTEXT Ctx;
|
---|
| 277 | RTMd2Init(&Ctx);
|
---|
| 278 | RTMd2Update(&Ctx, pvBuf, cbBuf);
|
---|
| 279 | RTMd2Final(&Ctx, pabDigest);
|
---|
| 280 | }
|
---|
| 281 | RT_EXPORT_SYMBOL(RTMd2);
|
---|
| 282 |
|
---|