blake2_pas.inc 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357
  1. {
  2. Implementations of BLAKE2b, BLAKE2s, aimed at portability and simplicity
  3. Copyright (C) 2018 Alexander Koblov ([email protected])
  4. Based on blake2*.pas, (C) Copyright 2017 Wolfgang Ehrhardt
  5. This software is provided 'as-is', without any express or implied warranty.
  6. In no event will the authors be held liable for any damages arising from
  7. the use of this software.
  8. Permission is granted to anyone to use this software for any purpose,
  9. including commercial applications, and to alter it and redistribute it
  10. freely, subject to the following restrictions:
  11. 1. The origin of this software must not be misrepresented; you must not
  12. claim that you wrote the original software. If you use this software in
  13. a product, an acknowledgment in the product documentation would be
  14. appreciated but is not required.
  15. 2. Altered source versions must be plainly marked as such, and must not be
  16. misrepresented as being the original software.
  17. 3. This notice may not be removed or altered from any source distribution.
  18. }
  19. const blake2s_sigma: array[0..9] of array[0..15] of cuint8 =
  20. (
  21. ( 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15 ) ,
  22. ( 14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3 ) ,
  23. ( 11, 8, 12, 0, 5, 2, 15, 13, 10, 14, 3, 6, 7, 1, 9, 4 ) ,
  24. ( 7, 9, 3, 1, 13, 12, 11, 14, 2, 6, 5, 10, 4, 0, 15, 8 ) ,
  25. ( 9, 0, 5, 7, 2, 4, 10, 15, 14, 1, 11, 12, 6, 8, 3, 13 ) ,
  26. ( 2, 12, 6, 10, 0, 11, 8, 3, 4, 13, 7, 5, 15, 14, 1, 9 ) ,
  27. ( 12, 5, 1, 15, 14, 13, 4, 10, 0, 7, 6, 3, 9, 2, 8, 11 ) ,
  28. ( 13, 11, 7, 14, 12, 1, 3, 9, 5, 0, 15, 4, 8, 6, 2, 10 ) ,
  29. ( 6, 15, 14, 9, 11, 3, 0, 8, 12, 2, 13, 7, 1, 4, 10, 5 ) ,
  30. ( 10, 2, 8, 4, 7, 6, 1, 5, 15, 11, 9, 14, 3, 12, 13 , 0 )
  31. );
  32. const blake2b_sigma: array[0..11] of array[0..15] of cuint8 =
  33. (
  34. ( 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15 ) ,
  35. ( 14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3 ) ,
  36. ( 11, 8, 12, 0, 5, 2, 15, 13, 10, 14, 3, 6, 7, 1, 9, 4 ) ,
  37. ( 7, 9, 3, 1, 13, 12, 11, 14, 2, 6, 5, 10, 4, 0, 15, 8 ) ,
  38. ( 9, 0, 5, 7, 2, 4, 10, 15, 14, 1, 11, 12, 6, 8, 3, 13 ) ,
  39. ( 2, 12, 6, 10, 0, 11, 8, 3, 4, 13, 7, 5, 15, 14, 1, 9 ) ,
  40. ( 12, 5, 1, 15, 14, 13, 4, 10, 0, 7, 6, 3, 9, 2, 8, 11 ) ,
  41. ( 13, 11, 7, 14, 12, 1, 3, 9, 5, 0, 15, 4, 8, 6, 2, 10 ) ,
  42. ( 6, 15, 14, 9, 11, 3, 0, 8, 12, 2, 13, 7, 1, 4, 10, 5 ) ,
  43. ( 10, 2, 8, 4, 7, 6, 1, 5, 15, 11, 9, 14, 3, 12, 13 , 0 ) ,
  44. ( 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15 ) ,
  45. ( 14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3 )
  46. );
  47. function blake2s_compress_pas( S: Pblake2s_state; const block: pcuint8 ): cint;
  48. var
  49. i: csize_t;
  50. tem, round: cint32;
  51. m: array[0..15] of cuint32;
  52. v: array[0..15] of cuint32;
  53. begin
  54. for i := 0 to 15 do
  55. m[i] := load32( @block[i * sizeof( m[i] )] );
  56. for i := 0 to 7 do
  57. v[i] := S^.h[i];
  58. v[ 8] := blake2s_IV[0];
  59. v[ 9] := blake2s_IV[1];
  60. v[10] := blake2s_IV[2];
  61. v[11] := blake2s_IV[3];
  62. v[12] := S^.t[0] xor blake2s_IV[4];
  63. v[13] := S^.t[1] xor blake2s_IV[5];
  64. v[14] := S^.f[0] xor blake2s_IV[6];
  65. v[15] := S^.f[1] xor blake2s_IV[7];
  66. {Code contributed by EddyHawk}
  67. for round:=0 to 9 do begin
  68. {separates BLAKE2s round into quarter-rounds}
  69. {replaces the rotr with direct code}
  70. {uses tem var for xor-ed words}
  71. {moves message-additions to the front}
  72. {regroups the rest}
  73. v[ 0] := (v[ 0] + v[ 4]) + m[blake2s_sigma[round][ 0]];
  74. v[ 1] := (v[ 1] + v[ 5]) + m[blake2s_sigma[round][ 2]];
  75. v[ 2] := (v[ 2] + v[ 6]) + m[blake2s_sigma[round][ 4]];
  76. v[ 3] := (v[ 3] + v[ 7]) + m[blake2s_sigma[round][ 6]];
  77. tem := v[12] xor v[ 0];
  78. v[12] := (tem shr 16) or (tem shl (32-16));
  79. tem := v[13] xor v[ 1];
  80. v[13] := (tem shr 16) or (tem shl (32-16));
  81. tem := v[14] xor v[ 2];
  82. v[14] := (tem shr 16) or (tem shl (32-16));
  83. tem := v[15] xor v[ 3];
  84. v[15] := (tem shr 16) or (tem shl (32-16));
  85. v[ 8] := v[ 8] + v[12];
  86. v[ 9] := v[ 9] + v[13];
  87. v[10] := v[10] + v[14];
  88. v[11] := v[11] + v[15];
  89. tem := v[ 4] xor v[ 8];
  90. v[ 4] := (tem shr 12) or (tem shl (32-12));
  91. tem := v[ 5] xor v[ 9];
  92. v[ 5] := (tem shr 12) or (tem shl (32-12));
  93. tem := v[ 6] xor v[10];
  94. v[ 6] := (tem shr 12) or (tem shl (32-12));
  95. tem := v[ 7] xor v[11];
  96. v[ 7] := (tem shr 12) or (tem shl (32-12));
  97. {2nd quarter-round}
  98. v[ 0] := (v[ 0] + v[ 4]) + m[blake2s_sigma[round][ 1]];
  99. v[ 1] := (v[ 1] + v[ 5]) + m[blake2s_sigma[round][ 3]];
  100. v[ 2] := (v[ 2] + v[ 6]) + m[blake2s_sigma[round][ 5]];
  101. v[ 3] := (v[ 3] + v[ 7]) + m[blake2s_sigma[round][ 7]];
  102. tem := v[12] xor v[ 0];
  103. v[12] := (tem shr 8) or (tem shl (32- 8));
  104. tem := v[13] xor v[ 1];
  105. v[13] := (tem shr 8) or (tem shl (32- 8));
  106. tem := v[14] xor v[ 2];
  107. v[14] := (tem shr 8) or (tem shl (32- 8));
  108. tem := v[15] xor v[ 3];
  109. v[15] := (tem shr 8) or (tem shl (32- 8));
  110. v[ 8] := v[ 8] + v[12];
  111. v[ 9] := v[ 9] + v[13];
  112. v[10] := v[10] + v[14];
  113. v[11] := v[11] + v[15];
  114. tem := v[ 4] xor v[ 8];
  115. v[ 4] := (tem shr 7) or (tem shl (32- 7));
  116. tem := v[ 5] xor v[ 9];
  117. v[ 5] := (tem shr 7) or (tem shl (32- 7));
  118. tem := v[ 6] xor v[10];
  119. v[ 6] := (tem shr 7) or (tem shl (32- 7));
  120. tem := v[ 7] xor v[11];
  121. v[ 7] := (tem shr 7) or (tem shl (32- 7));
  122. {3rd quarter-round}
  123. v[ 0] := (v[ 0] + v[ 5]) + m[blake2s_sigma[round][ 8]];
  124. v[ 1] := (v[ 1] + v[ 6]) + m[blake2s_sigma[round][10]];
  125. v[ 2] := (v[ 2] + v[ 7]) + m[blake2s_sigma[round][12]];
  126. v[ 3] := (v[ 3] + v[ 4]) + m[blake2s_sigma[round][14]];
  127. tem := v[15] xor v[ 0];
  128. v[15] := (tem shr 16) or (tem shl (32-16));
  129. tem := v[12] xor v[ 1];
  130. v[12] := (tem shr 16) or (tem shl (32-16));
  131. tem := v[13] xor v[ 2];
  132. v[13] := (tem shr 16) or (tem shl (32-16));
  133. tem := v[14] xor v[ 3];
  134. v[14] := (tem shr 16) or (tem shl (32-16));
  135. v[10] := v[10] + v[15];
  136. v[11] := v[11] + v[12];
  137. v[ 8] := v[ 8] + v[13];
  138. v[ 9] := v[ 9] + v[14];
  139. tem := v[ 5] xor v[10];
  140. v[ 5] := (tem shr 12) or (tem shl (32-12));
  141. tem := v[ 6] xor v[11];
  142. v[ 6] := (tem shr 12) or (tem shl (32-12));
  143. tem := v[ 7] xor v[ 8];
  144. v[ 7] := (tem shr 12) or (tem shl (32-12));
  145. tem := v[ 4] xor v[ 9];
  146. v[ 4] := (tem shr 12) or (tem shl (32-12));
  147. {4th quarter-round}
  148. v[ 0] := (v[ 0] + v[ 5]) + m[blake2s_sigma[round][ 9]];
  149. v[ 1] := (v[ 1] + v[ 6]) + m[blake2s_sigma[round][11]];
  150. v[ 2] := (v[ 2] + v[ 7]) + m[blake2s_sigma[round][13]];
  151. v[ 3] := (v[ 3] + v[ 4]) + m[blake2s_sigma[round][15]];
  152. tem := v[15] xor v[ 0];
  153. v[15] := (tem shr 8) or (tem shl (32- 8));
  154. tem := v[12] xor v[ 1];
  155. v[12] := (tem shr 8) or (tem shl (32- 8));
  156. tem := v[13] xor v[ 2];
  157. v[13] := (tem shr 8) or (tem shl (32- 8));
  158. tem := v[14] xor v[ 3];
  159. v[14] := (tem shr 8) or (tem shl (32- 8));
  160. v[10] := v[10] + v[15];
  161. v[11] := v[11] + v[12];
  162. v[ 8] := v[ 8] + v[13];
  163. v[ 9] := v[ 9] + v[14];
  164. tem := v[ 5] xor v[10];
  165. v[ 5] := (tem shr 7) or (tem shl (32- 7));
  166. tem := v[ 6] xor v[11];
  167. v[ 6] := (tem shr 7) or (tem shl (32- 7));
  168. tem := v[ 7] xor v[ 8];
  169. v[ 7] := (tem shr 7) or (tem shl (32- 7));
  170. tem := v[ 4] xor v[ 9];
  171. v[ 4] := (tem shr 7) or (tem shl (32- 7));
  172. end;
  173. for i := 0 to 7 do
  174. S^.h[i] := S^.h[i] xor v[i] xor v[i + 8];
  175. Result := 0;
  176. end;
  177. procedure blake2b_compress_pas( S: Pblake2b_state; const block: pcuint8 );
  178. var
  179. tem: cint64;
  180. i, round: csize_t;
  181. m: array[0..15] of cuint64;
  182. v: array[0..15] of cuint64;
  183. begin
  184. for i := 0 to 15 do
  185. m[i] := load64( block + i * sizeof( m[i] ) );
  186. for i := 0 to 7 do
  187. v[i] := S^.h[i];
  188. v[ 8] := cuint64(blake2b_IV[0]);
  189. v[ 9] := cuint64(blake2b_IV[1]);
  190. v[10] := cuint64(blake2b_IV[2]);
  191. v[11] := cuint64(blake2b_IV[3]);
  192. v[12] := cuint64(blake2b_IV[4] xor S^.t[0]);
  193. v[13] := cuint64(blake2b_IV[5] xor S^.t[1]);
  194. v[14] := cuint64(blake2b_IV[6] xor S^.f[0]);
  195. v[15] := cuint64(blake2b_IV[7] xor S^.f[1]);
  196. {do 12 rounds}
  197. for round:=0 to 11 do begin
  198. {** EddyHawk speed-ups **}
  199. {use same rearrangements as blake2s' 32/64 bit code}
  200. v[ 0] := (v[ 0] + v[ 4]) + m[blake2b_sigma[round][ 0]];
  201. v[ 1] := (v[ 1] + v[ 5]) + m[blake2b_sigma[round][ 2]];
  202. v[ 2] := (v[ 2] + v[ 6]) + m[blake2b_sigma[round][ 4]];
  203. v[ 3] := (v[ 3] + v[ 7]) + m[blake2b_sigma[round][ 6]];
  204. tem := v[12] xor v[ 0];
  205. v[12] := (tem shr 32) or (tem shl (64-32));
  206. tem := v[13] xor v[ 1];
  207. v[13] := (tem shr 32) or (tem shl (64-32));
  208. tem := v[14] xor v[ 2];
  209. v[14] := (tem shr 32) or (tem shl (64-32));
  210. tem := v[15] xor v[ 3];
  211. v[15] := (tem shr 32) or (tem shl (64-32));
  212. v[ 8] := v[ 8] + v[12];
  213. v[ 9] := v[ 9] + v[13];
  214. v[10] := v[10] + v[14];
  215. v[11] := v[11] + v[15];
  216. tem := v[ 4] xor v[ 8];
  217. v[ 4] := (tem shr 24) or (tem shl (64-24));
  218. tem := v[ 5] xor v[ 9];
  219. v[ 5] := (tem shr 24) or (tem shl (64-24));
  220. tem := v[ 6] xor v[10];
  221. v[ 6] := (tem shr 24) or (tem shl (64-24));
  222. tem := v[ 7] xor v[11];
  223. v[ 7] := (tem shr 24) or (tem shl (64-24));
  224. {---}
  225. v[ 0] := (v[ 0] + v[ 4]) + m[blake2b_sigma[round][ 1]];
  226. v[ 1] := (v[ 1] + v[ 5]) + m[blake2b_sigma[round][ 3]];
  227. v[ 2] := (v[ 2] + v[ 6]) + m[blake2b_sigma[round][ 5]];
  228. v[ 3] := (v[ 3] + v[ 7]) + m[blake2b_sigma[round][ 7]];
  229. tem := v[12] xor v[ 0];
  230. v[12] := (tem shr 16) or (tem shl (64-16));
  231. tem := v[13] xor v[ 1];
  232. v[13] := (tem shr 16) or (tem shl (64-16));
  233. tem := v[14] xor v[ 2];
  234. v[14] := (tem shr 16) or (tem shl (64-16));
  235. tem := v[15] xor v[ 3];
  236. v[15] := (tem shr 16) or (tem shl (64-16));
  237. v[ 8] := v[ 8] + v[12];
  238. v[ 9] := v[ 9] + v[13];
  239. v[10] := v[10] + v[14];
  240. v[11] := v[11] + v[15];
  241. tem := v[ 4] xor v[ 8];
  242. v[ 4] := (tem shr 63) or (tem shl (64-63));
  243. tem := v[ 5] xor v[ 9];
  244. v[ 5] := (tem shr 63) or (tem shl (64-63));
  245. tem := v[ 6] xor v[10];
  246. v[ 6] := (tem shr 63) or (tem shl (64-63));
  247. tem := v[ 7] xor v[11];
  248. v[ 7] := (tem shr 63) or (tem shl (64-63));
  249. {---}
  250. v[ 0] := (v[ 0] + v[ 5]) + m[blake2b_sigma[round][ 8]];
  251. v[ 1] := (v[ 1] + v[ 6]) + m[blake2b_sigma[round][10]];
  252. v[ 2] := (v[ 2] + v[ 7]) + m[blake2b_sigma[round][12]];
  253. v[ 3] := (v[ 3] + v[ 4]) + m[blake2b_sigma[round][14]];
  254. tem := v[15] xor v[ 0];
  255. v[15] := (tem shr 32) or (tem shl (64-32));
  256. tem := v[12] xor v[ 1];
  257. v[12] := (tem shr 32) or (tem shl (64-32));
  258. tem := v[13] xor v[ 2];
  259. v[13] := (tem shr 32) or (tem shl (64-32));
  260. tem := v[14] xor v[ 3];
  261. v[14] := (tem shr 32) or (tem shl (64-32));
  262. v[10] := v[10] + v[15];
  263. v[11] := v[11] + v[12];
  264. v[ 8] := v[ 8] + v[13];
  265. v[ 9] := v[ 9] + v[14];
  266. tem := v[ 5] xor v[10];
  267. v[ 5] := (tem shr 24) or (tem shl (64-24));
  268. tem := v[ 6] xor v[11];
  269. v[ 6] := (tem shr 24) or (tem shl (64-24));
  270. tem := v[ 7] xor v[ 8];
  271. v[ 7] := (tem shr 24) or (tem shl (64-24));
  272. tem := v[ 4] xor v[ 9];
  273. v[ 4] := (tem shr 24) or (tem shl (64-24));
  274. {---}
  275. v[ 0] := (v[ 0] + v[ 5]) + m[blake2b_sigma[round][ 9]];
  276. v[ 1] := (v[ 1] + v[ 6]) + m[blake2b_sigma[round][11]];
  277. v[ 2] := (v[ 2] + v[ 7]) + m[blake2b_sigma[round][13]];
  278. v[ 3] := (v[ 3] + v[ 4]) + m[blake2b_sigma[round][15]];
  279. tem := v[15] xor v[ 0];
  280. v[15] := (tem shr 16) or (tem shl (64-16));
  281. tem := v[12] xor v[ 1];
  282. v[12] := (tem shr 16) or (tem shl (64-16));
  283. tem := v[13] xor v[ 2];
  284. v[13] := (tem shr 16) or (tem shl (64-16));
  285. tem := v[14] xor v[ 3];
  286. v[14] := (tem shr 16) or (tem shl (64-16));
  287. v[10] := v[10] + v[15];
  288. v[11] := v[11] + v[12];
  289. v[ 8] := v[ 8] + v[13];
  290. v[ 9] := v[ 9] + v[14];
  291. tem := v[ 5] xor v[10];
  292. v[ 5] := (tem shr 63) or (tem shl (64-63));
  293. tem := v[ 6] xor v[11];
  294. v[ 6] := (tem shr 63) or (tem shl (64-63));
  295. tem := v[ 7] xor v[ 8];
  296. v[ 7] := (tem shr 63) or (tem shl (64-63));
  297. tem := v[ 4] xor v[ 9];
  298. v[ 4] := (tem shr 63) or (tem shl (64-63));
  299. end;
  300. for i := 0 to 7 do
  301. S^.h[i] := S^.h[i] xor v[i] xor v[i + 8];
  302. end;