ripemd128.c
Go to the documentation of this file.
1 /**
2  * @file ripemd128.c
3  * @brief RIPEMD-128 hash function
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2025 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.5.0
29  **/
30 
31 //Switch to the appropriate trace level
32 #define TRACE_LEVEL CRYPTO_TRACE_LEVEL
33 
34 //Dependencies
35 #include "core/crypto.h"
36 #include "hash/ripemd128.h"
37 
38 //Check crypto library configuration
39 #if (RIPEMD128_SUPPORT == ENABLED)
40 
41 //RIPEMD-128 auxiliary functions
42 #define F(x, y, z) ((x) ^ (y) ^ (z))
43 #define G(x, y, z) (((x) & (y)) | (~(x) & (z)))
44 #define H(x, y, z) (((x) | ~(y)) ^ (z))
45 #define I(x, y, z) (((x) & (z)) | ((y) & ~(z)))
46 
47 #define FF(a, b, c, d, x, s) a += F(b, c, d) + (x), a = ROL32(a, s)
48 #define GG(a, b, c, d, x, s) a += G(b, c, d) + (x) + 0x5A827999, a = ROL32(a, s)
49 #define HH(a, b, c, d, x, s) a += H(b, c, d) + (x) + 0x6ED9EBA1, a = ROL32(a, s)
50 #define II(a, b, c, d, x, s) a += I(b, c, d) + (x) + 0x8F1BBCDC, a = ROL32(a, s)
51 
52 #define FFF(a, b, c, d, x, s) a += F(b, c, d) + (x), a = ROL32(a, s)
53 #define GGG(a, b, c, d, x, s) a += G(b, c, d) + (x) + 0x6D703EF3, a = ROL32(a, s)
54 #define HHH(a, b, c, d, x, s) a += H(b, c, d) + (x) + 0x5C4DD124, a = ROL32(a, s)
55 #define III(a, b, c, d, x, s) a += I(b, c, d) + (x) + 0x50A28BE6, a = ROL32(a, s)
56 
57 //RIPEMD-128 padding
58 static const uint8_t padding[64] =
59 {
60  0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
61  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
62  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
63  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
64 };
65 
66 //RIPEMD-128 object identifier (1.3.36.3.2.2)
67 const uint8_t RIPEMD128_OID[5] = {0x2B, 0x24, 0x03, 0x02, 0x02};
68 
69 //Common interface for hash algorithms
71 {
72  "RIPEMD-128",
74  sizeof(RIPEMD128_OID),
75  sizeof(Ripemd128Context),
79  FALSE,
84  NULL
85 };
86 
87 
88 /**
89  * @brief Digest a message using RIPEMD-128
90  * @param[in] data Pointer to the message being hashed
91  * @param[in] length Length of the message
92  * @param[out] digest Pointer to the calculated digest
93  * @return Error code
94  **/
95 
96 error_t ripemd128Compute(const void *data, size_t length, uint8_t *digest)
97 {
98 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
99  Ripemd128Context *context;
100 #else
101  Ripemd128Context context[1];
102 #endif
103 
104  //Check parameters
105  if(data == NULL && length != 0)
107 
108  if(digest == NULL)
110 
111 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
112  //Allocate a memory buffer to hold the RIPEMD-128 context
113  context = cryptoAllocMem(sizeof(Ripemd128Context));
114  //Failed to allocate memory?
115  if(context == NULL)
116  return ERROR_OUT_OF_MEMORY;
117 #endif
118 
119  //Initialize the RIPEMD-128 context
120  ripemd128Init(context);
121  //Digest the message
122  ripemd128Update(context, data, length);
123  //Finalize the RIPEMD-128 message digest
124  ripemd128Final(context, digest);
125 
126 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
127  //Free previously allocated memory
128  cryptoFreeMem(context);
129 #endif
130 
131  //Successful operation
132  return NO_ERROR;
133 }
134 
135 
136 /**
137  * @brief Initialize RIPEMD-128 message digest context
138  * @param[in] context Pointer to the RIPEMD-128 context to initialize
139  **/
140 
142 {
143  //Set initial hash value
144  context->h[0] = 0x67452301;
145  context->h[1] = 0xEFCDAB89;
146  context->h[2] = 0x98BADCFE;
147  context->h[3] = 0x10325476;
148 
149  //Number of bytes in the buffer
150  context->size = 0;
151  //Total length of the message
152  context->totalSize = 0;
153 }
154 
155 
156 /**
157  * @brief Update the RIPEMD-128 context with a portion of the message being hashed
158  * @param[in] context Pointer to the RIPEMD-128 context
159  * @param[in] data Pointer to the buffer being hashed
160  * @param[in] length Length of the buffer
161  **/
162 
163 void ripemd128Update(Ripemd128Context *context, const void *data, size_t length)
164 {
165  size_t n;
166 
167  //Process the incoming data
168  while(length > 0)
169  {
170  //The buffer can hold at most 64 bytes
171  n = MIN(length, 64 - context->size);
172 
173  //Copy the data to the buffer
174  osMemcpy(context->buffer + context->size, data, n);
175 
176  //Update the RIPEMD-128 context
177  context->size += n;
178  context->totalSize += n;
179  //Advance the data pointer
180  data = (uint8_t *) data + n;
181  //Remaining bytes to process
182  length -= n;
183 
184  //Process message in 16-word blocks
185  if(context->size == 64)
186  {
187  //Transform the 16-word block
188  ripemd128ProcessBlock(context);
189  //Empty the buffer
190  context->size = 0;
191  }
192  }
193 }
194 
195 
196 /**
197  * @brief Finish the RIPEMD-128 message digest
198  * @param[in] context Pointer to the RIPEMD-128 context
199  * @param[out] digest Calculated digest
200  **/
201 
202 void ripemd128Final(Ripemd128Context *context, uint8_t *digest)
203 {
204  uint_t i;
205  size_t paddingSize;
206  uint64_t totalSize;
207 
208  //Length of the original message (before padding)
209  totalSize = context->totalSize * 8;
210 
211  //Pad the message so that its length is congruent to 56 modulo 64
212  if(context->size < 56)
213  {
214  paddingSize = 56 - context->size;
215  }
216  else
217  {
218  paddingSize = 64 + 56 - context->size;
219  }
220 
221  //Append padding
222  ripemd128Update(context, padding, paddingSize);
223 
224  //Append the length of the original message
225  for(i = 0; i < 8; i++)
226  {
227  context->buffer[56 + i] = totalSize & 0xFF;
228  totalSize >>= 8;
229  }
230 
231  //Calculate the message digest
232  ripemd128ProcessBlock(context);
233 
234  //Copy the resulting digest
235  for(i = 0; i < (RIPEMD128_DIGEST_SIZE / 4); i++)
236  {
237  STORE32LE(context->h[i], digest + i * 4);
238  }
239 }
240 
241 
242 /**
243  * @brief Process message in 16-word blocks
244  * @param[in] context Pointer to the RIPEMD-128 context
245  **/
246 
248 {
249  uint_t i;
250 
251  //Initialize the working registers
252  uint32_t aa= context->h[0];
253  uint32_t bb = context->h[1];
254  uint32_t cc = context->h[2];
255  uint32_t dd = context->h[3];
256  uint32_t aaa = context->h[0];
257  uint32_t bbb = context->h[1];
258  uint32_t ccc = context->h[2];
259  uint32_t ddd = context->h[3];
260 
261  //Process message in 16-word blocks
262  uint32_t *x = context->x;
263 
264  //Convert from little-endian byte order to host byte order
265  for(i = 0; i < 16; i++)
266  {
267  x[i] = LOAD32LE(context->buffer + i * 4);
268  }
269 
270  //Round 1
271  FF(aa, bb, cc, dd, x[0], 11);
272  FF(dd, aa, bb, cc, x[1], 14);
273  FF(cc, dd, aa, bb, x[2], 15);
274  FF(bb, cc, dd, aa, x[3], 12);
275  FF(aa, bb, cc, dd, x[4], 5);
276  FF(dd, aa, bb, cc, x[5], 8);
277  FF(cc, dd, aa, bb, x[6], 7);
278  FF(bb, cc, dd, aa, x[7], 9);
279  FF(aa, bb, cc, dd, x[8], 11);
280  FF(dd, aa, bb, cc, x[9], 13);
281  FF(cc, dd, aa, bb, x[10], 14);
282  FF(bb, cc, dd, aa, x[11], 15);
283  FF(aa, bb, cc, dd, x[12], 6);
284  FF(dd, aa, bb, cc, x[13], 7);
285  FF(cc, dd, aa, bb, x[14], 9);
286  FF(bb, cc, dd, aa, x[15], 8);
287 
288  //Round 2
289  GG(aa, bb, cc, dd, x[7], 7);
290  GG(dd, aa, bb, cc, x[4], 6);
291  GG(cc, dd, aa, bb, x[13], 8);
292  GG(bb, cc, dd, aa, x[1], 13);
293  GG(aa, bb, cc, dd, x[10], 11);
294  GG(dd, aa, bb, cc, x[6], 9);
295  GG(cc, dd, aa, bb, x[15], 7);
296  GG(bb, cc, dd, aa, x[3], 15);
297  GG(aa, bb, cc, dd, x[12], 7);
298  GG(dd, aa, bb, cc, x[0], 12);
299  GG(cc, dd, aa, bb, x[9], 15);
300  GG(bb, cc, dd, aa, x[5], 9);
301  GG(aa, bb, cc, dd, x[2], 11);
302  GG(dd, aa, bb, cc, x[14], 7);
303  GG(cc, dd, aa, bb, x[11], 13);
304  GG(bb, cc, dd, aa, x[8], 12);
305 
306  //Round 3
307  HH(aa, bb, cc, dd, x[3], 11);
308  HH(dd, aa, bb, cc, x[10], 13);
309  HH(cc, dd, aa, bb, x[14], 6);
310  HH(bb, cc, dd, aa, x[4], 7);
311  HH(aa, bb, cc, dd, x[9], 14);
312  HH(dd, aa, bb, cc, x[15], 9);
313  HH(cc, dd, aa, bb, x[8], 13);
314  HH(bb, cc, dd, aa, x[1], 15);
315  HH(aa, bb, cc, dd, x[2], 14);
316  HH(dd, aa, bb, cc, x[7], 8);
317  HH(cc, dd, aa, bb, x[0], 13);
318  HH(bb, cc, dd, aa, x[6], 6);
319  HH(aa, bb, cc, dd, x[13], 5);
320  HH(dd, aa, bb, cc, x[11], 12);
321  HH(cc, dd, aa, bb, x[5], 7);
322  HH(bb, cc, dd, aa, x[12], 5);
323 
324  //Round 4
325  II(aa, bb, cc, dd, x[1], 11);
326  II(dd, aa, bb, cc, x[9], 12);
327  II(cc, dd, aa, bb, x[11], 14);
328  II(bb, cc, dd, aa, x[10], 15);
329  II(aa, bb, cc, dd, x[0], 14);
330  II(dd, aa, bb, cc, x[8], 15);
331  II(cc, dd, aa, bb, x[12], 9);
332  II(bb, cc, dd, aa, x[4], 8);
333  II(aa, bb, cc, dd, x[13], 9);
334  II(dd, aa, bb, cc, x[3], 14);
335  II(cc, dd, aa, bb, x[7], 5);
336  II(bb, cc, dd, aa, x[15], 6);
337  II(aa, bb, cc, dd, x[14], 8);
338  II(dd, aa, bb, cc, x[5], 6);
339  II(cc, dd, aa, bb, x[6], 5);
340  II(bb, cc, dd, aa, x[2], 12);
341 
342  //Parallel round 1
343  III(aaa, bbb, ccc, ddd, x[5], 8);
344  III(ddd, aaa, bbb, ccc, x[14], 9);
345  III(ccc, ddd, aaa, bbb, x[7], 9);
346  III(bbb, ccc, ddd, aaa, x[0], 11);
347  III(aaa, bbb, ccc, ddd, x[9], 13);
348  III(ddd, aaa, bbb, ccc, x[2], 15);
349  III(ccc, ddd, aaa, bbb, x[11], 15);
350  III(bbb, ccc, ddd, aaa, x[4], 5);
351  III(aaa, bbb, ccc, ddd, x[13], 7);
352  III(ddd, aaa, bbb, ccc, x[6], 7);
353  III(ccc, ddd, aaa, bbb, x[15], 8);
354  III(bbb, ccc, ddd, aaa, x[8], 11);
355  III(aaa, bbb, ccc, ddd, x[1], 14);
356  III(ddd, aaa, bbb, ccc, x[10], 14);
357  III(ccc, ddd, aaa, bbb, x[3], 12);
358  III(bbb, ccc, ddd, aaa, x[12], 6);
359 
360  //Parallel round 2
361  HHH(aaa, bbb, ccc, ddd, x[6], 9);
362  HHH(ddd, aaa, bbb, ccc, x[11], 13);
363  HHH(ccc, ddd, aaa, bbb, x[3], 15);
364  HHH(bbb, ccc, ddd, aaa, x[7], 7);
365  HHH(aaa, bbb, ccc, ddd, x[0], 12);
366  HHH(ddd, aaa, bbb, ccc, x[13], 8);
367  HHH(ccc, ddd, aaa, bbb, x[5], 9);
368  HHH(bbb, ccc, ddd, aaa, x[10], 11);
369  HHH(aaa, bbb, ccc, ddd, x[14], 7);
370  HHH(ddd, aaa, bbb, ccc, x[15], 7);
371  HHH(ccc, ddd, aaa, bbb, x[8], 12);
372  HHH(bbb, ccc, ddd, aaa, x[12], 7);
373  HHH(aaa, bbb, ccc, ddd, x[4], 6);
374  HHH(ddd, aaa, bbb, ccc, x[9], 15);
375  HHH(ccc, ddd, aaa, bbb, x[1], 13);
376  HHH(bbb, ccc, ddd, aaa, x[2], 11);
377 
378  //Parallel round 3
379  GGG(aaa, bbb, ccc, ddd, x[15], 9);
380  GGG(ddd, aaa, bbb, ccc, x[5], 7);
381  GGG(ccc, ddd, aaa, bbb, x[1], 15);
382  GGG(bbb, ccc, ddd, aaa, x[3], 11);
383  GGG(aaa, bbb, ccc, ddd, x[7], 8);
384  GGG(ddd, aaa, bbb, ccc, x[14], 6);
385  GGG(ccc, ddd, aaa, bbb, x[6], 6);
386  GGG(bbb, ccc, ddd, aaa, x[9], 14);
387  GGG(aaa, bbb, ccc, ddd, x[11], 12);
388  GGG(ddd, aaa, bbb, ccc, x[8], 13);
389  GGG(ccc, ddd, aaa, bbb, x[12], 5);
390  GGG(bbb, ccc, ddd, aaa, x[2], 14);
391  GGG(aaa, bbb, ccc, ddd, x[10], 13);
392  GGG(ddd, aaa, bbb, ccc, x[0], 13);
393  GGG(ccc, ddd, aaa, bbb, x[4], 7);
394  GGG(bbb, ccc, ddd, aaa, x[13], 5);
395 
396  //Parallel round 4
397  FFF(aaa, bbb, ccc, ddd, x[8], 15);
398  FFF(ddd, aaa, bbb, ccc, x[6], 5);
399  FFF(ccc, ddd, aaa, bbb, x[4], 8);
400  FFF(bbb, ccc, ddd, aaa, x[1], 11);
401  FFF(aaa, bbb, ccc, ddd, x[3], 14);
402  FFF(ddd, aaa, bbb, ccc, x[11], 14);
403  FFF(ccc, ddd, aaa, bbb, x[15], 6);
404  FFF(bbb, ccc, ddd, aaa, x[0], 14);
405  FFF(aaa, bbb, ccc, ddd, x[5], 6);
406  FFF(ddd, aaa, bbb, ccc, x[12], 9);
407  FFF(ccc, ddd, aaa, bbb, x[2], 12);
408  FFF(bbb, ccc, ddd, aaa, x[13], 9);
409  FFF(aaa, bbb, ccc, ddd, x[9], 12);
410  FFF(ddd, aaa, bbb, ccc, x[7], 5);
411  FFF(ccc, ddd, aaa, bbb, x[10], 15);
412  FFF(bbb, ccc, ddd, aaa, x[14], 8);
413 
414  //Combine results
415  ddd = context->h[1] + cc + ddd;
416  context->h[1] = context->h[2] + dd + aaa;
417  context->h[2] = context->h[3] + aa + bbb;
418  context->h[3] = context->h[0] + bb + ccc;
419  context->h[0] = ddd;
420 }
421 
422 #endif
const uint8_t RIPEMD128_OID[5]
Definition: ripemd128.c:67
void(* HashAlgoInit)(void *context)
Definition: crypto.h:1027
RIPEMD-128 hash function.
uint32_t x[16]
Definition: ripemd128.h:61
uint8_t x
Definition: lldp_ext_med.h:211
#define III(a, b, c, d, x, s)
Definition: ripemd128.c:55
void ripemd128ProcessBlock(Ripemd128Context *context)
Process message in 16-word blocks.
Definition: ripemd128.c:247
uint8_t data[]
Definition: ethernet.h:222
#define STORE32LE(a, p)
Definition: cpu_endian.h:279
#define II(a, b, c, d, x, s)
Definition: ripemd128.c:50
uint8_t aa
Definition: dns_common.h:187
#define RIPEMD128_DIGEST_SIZE
Definition: ripemd128.h:40
@ ERROR_OUT_OF_MEMORY
Definition: error.h:63
#define HH(a, b, c, d, x, s)
Definition: ripemd128.c:49
void ripemd128Final(Ripemd128Context *context, uint8_t *digest)
Finish the RIPEMD-128 message digest.
Definition: ripemd128.c:202
#define HHH(a, b, c, d, x, s)
Definition: ripemd128.c:54
#define FFF(a, b, c, d, x, s)
Definition: ripemd128.c:52
void(* HashAlgoUpdate)(void *context, const void *data, size_t length)
Definition: crypto.h:1029
const HashAlgo ripemd128HashAlgo
Definition: ripemd128.c:70
#define GGG(a, b, c, d, x, s)
Definition: ripemd128.c:53
#define FALSE
Definition: os_port.h:46
@ ERROR_INVALID_PARAMETER
Invalid parameter.
Definition: error.h:47
#define osMemcpy(dest, src, length)
Definition: os_port.h:144
error_t
Error codes.
Definition: error.h:43
uint8_t buffer[64]
Definition: ripemd128.h:62
#define FF(a, b, c, d, x, s)
Definition: ripemd128.c:47
void ripemd128Init(Ripemd128Context *context)
Initialize RIPEMD-128 message digest context.
Definition: ripemd128.c:141
General definitions for cryptographic algorithms.
#define RIPEMD128_BLOCK_SIZE
Definition: ripemd128.h:38
uint8_t length
Definition: tcp.h:375
#define MIN(a, b)
Definition: os_port.h:63
void(* HashAlgoFinal)(void *context, uint8_t *digest)
Definition: crypto.h:1031
uint64_t totalSize
Definition: ripemd128.h:65
uint8_t n
#define cryptoFreeMem(p)
Definition: crypto.h:826
#define GG(a, b, c, d, x, s)
Definition: ripemd128.c:48
error_t ripemd128Compute(const void *data, size_t length, uint8_t *digest)
Digest a message using RIPEMD-128.
Definition: ripemd128.c:96
#define cryptoAllocMem(size)
Definition: crypto.h:821
uint32_t h[4]
Definition: ripemd128.h:58
RIPEMD-128 algorithm context.
Definition: ripemd128.h:57
Common interface for hash algorithms.
Definition: crypto.h:1082
#define RIPEMD128_MIN_PAD_SIZE
Definition: ripemd128.h:42
#define LOAD32LE(p)
Definition: cpu_endian.h:203
unsigned int uint_t
Definition: compiler_port.h:57
error_t(* HashAlgoCompute)(const void *data, size_t length, uint8_t *digest)
Definition: crypto.h:1024
void ripemd128Update(Ripemd128Context *context, const void *data, size_t length)
Update the RIPEMD-128 context with a portion of the message being hashed.
Definition: ripemd128.c:163
@ NO_ERROR
Success.
Definition: error.h:44