sha512.js 7.1 KB


  1. 'use strict';
  2. var inherits = require('inherits');
  3. var Hash = require('./hash');
  4. var Buffer = require('safe-buffer').Buffer;
  5. var K = [
  6. 0x428a2f98,
  7. 0xd728ae22,
  8. 0x71374491,
  9. 0x23ef65cd,
  10. 0xb5c0fbcf,
  11. 0xec4d3b2f,
  12. 0xe9b5dba5,
  13. 0x8189dbbc,
  14. 0x3956c25b,
  15. 0xf348b538,
  16. 0x59f111f1,
  17. 0xb605d019,
  18. 0x923f82a4,
  19. 0xaf194f9b,
  20. 0xab1c5ed5,
  21. 0xda6d8118,
  22. 0xd807aa98,
  23. 0xa3030242,
  24. 0x12835b01,
  25. 0x45706fbe,
  26. 0x243185be,
  27. 0x4ee4b28c,
  28. 0x550c7dc3,
  29. 0xd5ffb4e2,
  30. 0x72be5d74,
  31. 0xf27b896f,
  32. 0x80deb1fe,
  33. 0x3b1696b1,
  34. 0x9bdc06a7,
  35. 0x25c71235,
  36. 0xc19bf174,
  37. 0xcf692694,
  38. 0xe49b69c1,
  39. 0x9ef14ad2,
  40. 0xefbe4786,
  41. 0x384f25e3,
  42. 0x0fc19dc6,
  43. 0x8b8cd5b5,
  44. 0x240ca1cc,
  45. 0x77ac9c65,
  46. 0x2de92c6f,
  47. 0x592b0275,
  48. 0x4a7484aa,
  49. 0x6ea6e483,
  50. 0x5cb0a9dc,
  51. 0xbd41fbd4,
  52. 0x76f988da,
  53. 0x831153b5,
  54. 0x983e5152,
  55. 0xee66dfab,
  56. 0xa831c66d,
  57. 0x2db43210,
  58. 0xb00327c8,
  59. 0x98fb213f,
  60. 0xbf597fc7,
  61. 0xbeef0ee4,
  62. 0xc6e00bf3,
  63. 0x3da88fc2,
  64. 0xd5a79147,
  65. 0x930aa725,
  66. 0x06ca6351,
  67. 0xe003826f,
  68. 0x14292967,
  69. 0x0a0e6e70,
  70. 0x27b70a85,
  71. 0x46d22ffc,
  72. 0x2e1b2138,
  73. 0x5c26c926,
  74. 0x4d2c6dfc,
  75. 0x5ac42aed,
  76. 0x53380d13,
  77. 0x9d95b3df,
  78. 0x650a7354,
  79. 0x8baf63de,
  80. 0x766a0abb,
  81. 0x3c77b2a8,
  82. 0x81c2c92e,
  83. 0x47edaee6,
  84. 0x92722c85,
  85. 0x1482353b,
  86. 0xa2bfe8a1,
  87. 0x4cf10364,
  88. 0xa81a664b,
  89. 0xbc423001,
  90. 0xc24b8b70,
  91. 0xd0f89791,
  92. 0xc76c51a3,
  93. 0x0654be30,
  94. 0xd192e819,
  95. 0xd6ef5218,
  96. 0xd6990624,
  97. 0x5565a910,
  98. 0xf40e3585,
  99. 0x5771202a,
  100. 0x106aa070,
  101. 0x32bbd1b8,
  102. 0x19a4c116,
  103. 0xb8d2d0c8,
  104. 0x1e376c08,
  105. 0x5141ab53,
  106. 0x2748774c,
  107. 0xdf8eeb99,
  108. 0x34b0bcb5,
  109. 0xe19b48a8,
  110. 0x391c0cb3,
  111. 0xc5c95a63,
  112. 0x4ed8aa4a,
  113. 0xe3418acb,
  114. 0x5b9cca4f,
  115. 0x7763e373,
  116. 0x682e6ff3,
  117. 0xd6b2b8a3,
  118. 0x748f82ee,
  119. 0x5defb2fc,
  120. 0x78a5636f,
  121. 0x43172f60,
  122. 0x84c87814,
  123. 0xa1f0ab72,
  124. 0x8cc70208,
  125. 0x1a6439ec,
  126. 0x90befffa,
  127. 0x23631e28,
  128. 0xa4506ceb,
  129. 0xde82bde9,
  130. 0xbef9a3f7,
  131. 0xb2c67915,
  132. 0xc67178f2,
  133. 0xe372532b,
  134. 0xca273ece,
  135. 0xea26619c,
  136. 0xd186b8c7,
  137. 0x21c0c207,
  138. 0xeada7dd6,
  139. 0xcde0eb1e,
  140. 0xf57d4f7f,
  141. 0xee6ed178,
  142. 0x06f067aa,
  143. 0x72176fba,
  144. 0x0a637dc5,
  145. 0xa2c898a6,
  146. 0x113f9804,
  147. 0xbef90dae,
  148. 0x1b710b35,
  149. 0x131c471b,
  150. 0x28db77f5,
  151. 0x23047d84,
  152. 0x32caab7b,
  153. 0x40c72493,
  154. 0x3c9ebe0a,
  155. 0x15c9bebc,
  156. 0x431d67c4,
  157. 0x9c100d4c,
  158. 0x4cc5d4be,
  159. 0xcb3e42b6,
  160. 0x597f299c,
  161. 0xfc657e2a,
  162. 0x5fcb6fab,
  163. 0x3ad6faec,
  164. 0x6c44198c,
  165. 0x4a475817
  166. ];
  167. var W = new Array(160);
  168. function Sha512() {
  169. this.init();
  170. this._w = W;
  171. Hash.call(this, 128, 112);
  172. }
  173. inherits(Sha512, Hash);
  174. Sha512.prototype.init = function () {
  175. this._ah = 0x6a09e667;
  176. this._bh = 0xbb67ae85;
  177. this._ch = 0x3c6ef372;
  178. this._dh = 0xa54ff53a;
  179. this._eh = 0x510e527f;
  180. this._fh = 0x9b05688c;
  181. this._gh = 0x1f83d9ab;
  182. this._hh = 0x5be0cd19;
  183. this._al = 0xf3bcc908;
  184. this._bl = 0x84caa73b;
  185. this._cl = 0xfe94f82b;
  186. this._dl = 0x5f1d36f1;
  187. this._el = 0xade682d1;
  188. this._fl = 0x2b3e6c1f;
  189. this._gl = 0xfb41bd6b;
  190. this._hl = 0x137e2179;
  191. return this;
  192. };
  193. function Ch(x, y, z) {
  194. return z ^ (x & (y ^ z));
  195. }
  196. function maj(x, y, z) {
  197. return (x & y) | (z & (x | y));
  198. }
  199. function sigma0(x, xl) {
  200. return ((x >>> 28) | (xl << 4)) ^ ((xl >>> 2) | (x << 30)) ^ ((xl >>> 7) | (x << 25));
  201. }
  202. function sigma1(x, xl) {
  203. return ((x >>> 14) | (xl << 18)) ^ ((x >>> 18) | (xl << 14)) ^ ((xl >>> 9) | (x << 23));
  204. }
  205. function Gamma0(x, xl) {
  206. return ((x >>> 1) | (xl << 31)) ^ ((x >>> 8) | (xl << 24)) ^ (x >>> 7);
  207. }
  208. function Gamma0l(x, xl) {
  209. return ((x >>> 1) | (xl << 31)) ^ ((x >>> 8) | (xl << 24)) ^ ((x >>> 7) | (xl << 25));
  210. }
  211. function Gamma1(x, xl) {
  212. return ((x >>> 19) | (xl << 13)) ^ ((xl >>> 29) | (x << 3)) ^ (x >>> 6);
  213. }
  214. function Gamma1l(x, xl) {
  215. return ((x >>> 19) | (xl << 13)) ^ ((xl >>> 29) | (x << 3)) ^ ((x >>> 6) | (xl << 26));
  216. }
  217. function getCarry(a, b) {
  218. return (a >>> 0) < (b >>> 0) ? 1 : 0;
  219. }
  220. Sha512.prototype._update = function (M) {
  221. var w = this._w;
  222. var ah = this._ah | 0;
  223. var bh = this._bh | 0;
  224. var ch = this._ch | 0;
  225. var dh = this._dh | 0;
  226. var eh = this._eh | 0;
  227. var fh = this._fh | 0;
  228. var gh = this._gh | 0;
  229. var hh = this._hh | 0;
  230. var al = this._al | 0;
  231. var bl = this._bl | 0;
  232. var cl = this._cl | 0;
  233. var dl = this._dl | 0;
  234. var el = this._el | 0;
  235. var fl = this._fl | 0;
  236. var gl = this._gl | 0;
  237. var hl = this._hl | 0;
  238. for (var i = 0; i < 32; i += 2) {
  239. w[i] = M.readInt32BE(i * 4);
  240. w[i + 1] = M.readInt32BE((i * 4) + 4);
  241. }
  242. for (; i < 160; i += 2) {
  243. var xh = w[i - (15 * 2)];
  244. var xl = w[i - (15 * 2) + 1];
  245. var gamma0 = Gamma0(xh, xl);
  246. var gamma0l = Gamma0l(xl, xh);
  247. xh = w[i - (2 * 2)];
  248. xl = w[i - (2 * 2) + 1];
  249. var gamma1 = Gamma1(xh, xl);
  250. var gamma1l = Gamma1l(xl, xh);
  251. // w[i] = gamma0 + w[i - 7] + gamma1 + w[i - 16]
  252. var Wi7h = w[i - (7 * 2)];
  253. var Wi7l = w[i - (7 * 2) + 1];
  254. var Wi16h = w[i - (16 * 2)];
  255. var Wi16l = w[i - (16 * 2) + 1];
  256. var Wil = (gamma0l + Wi7l) | 0;
  257. var Wih = (gamma0 + Wi7h + getCarry(Wil, gamma0l)) | 0;
  258. Wil = (Wil + gamma1l) | 0;
  259. Wih = (Wih + gamma1 + getCarry(Wil, gamma1l)) | 0;
  260. Wil = (Wil + Wi16l) | 0;
  261. Wih = (Wih + Wi16h + getCarry(Wil, Wi16l)) | 0;
  262. w[i] = Wih;
  263. w[i + 1] = Wil;
  264. }
  265. for (var j = 0; j < 160; j += 2) {
  266. Wih = w[j];
  267. Wil = w[j + 1];
  268. var majh = maj(ah, bh, ch);
  269. var majl = maj(al, bl, cl);
  270. var sigma0h = sigma0(ah, al);
  271. var sigma0l = sigma0(al, ah);
  272. var sigma1h = sigma1(eh, el);
  273. var sigma1l = sigma1(el, eh);
  274. // t1 = h + sigma1 + ch + K[j] + w[j]
  275. var Kih = K[j];
  276. var Kil = K[j + 1];
  277. var chh = Ch(eh, fh, gh);
  278. var chl = Ch(el, fl, gl);
  279. var t1l = (hl + sigma1l) | 0;
  280. var t1h = (hh + sigma1h + getCarry(t1l, hl)) | 0;
  281. t1l = (t1l + chl) | 0;
  282. t1h = (t1h + chh + getCarry(t1l, chl)) | 0;
  283. t1l = (t1l + Kil) | 0;
  284. t1h = (t1h + Kih + getCarry(t1l, Kil)) | 0;
  285. t1l = (t1l + Wil) | 0;
  286. t1h = (t1h + Wih + getCarry(t1l, Wil)) | 0;
  287. // t2 = sigma0 + maj
  288. var t2l = (sigma0l + majl) | 0;
  289. var t2h = (sigma0h + majh + getCarry(t2l, sigma0l)) | 0;
  290. hh = gh;
  291. hl = gl;
  292. gh = fh;
  293. gl = fl;
  294. fh = eh;
  295. fl = el;
  296. el = (dl + t1l) | 0;
  297. eh = (dh + t1h + getCarry(el, dl)) | 0;
  298. dh = ch;
  299. dl = cl;
  300. ch = bh;
  301. cl = bl;
  302. bh = ah;
  303. bl = al;
  304. al = (t1l + t2l) | 0;
  305. ah = (t1h + t2h + getCarry(al, t1l)) | 0;
  306. }
  307. this._al = (this._al + al) | 0;
  308. this._bl = (this._bl + bl) | 0;
  309. this._cl = (this._cl + cl) | 0;
  310. this._dl = (this._dl + dl) | 0;
  311. this._el = (this._el + el) | 0;
  312. this._fl = (this._fl + fl) | 0;
  313. this._gl = (this._gl + gl) | 0;
  314. this._hl = (this._hl + hl) | 0;
  315. this._ah = (this._ah + ah + getCarry(this._al, al)) | 0;
  316. this._bh = (this._bh + bh + getCarry(this._bl, bl)) | 0;
  317. this._ch = (this._ch + ch + getCarry(this._cl, cl)) | 0;
  318. this._dh = (this._dh + dh + getCarry(this._dl, dl)) | 0;
  319. this._eh = (this._eh + eh + getCarry(this._el, el)) | 0;
  320. this._fh = (this._fh + fh + getCarry(this._fl, fl)) | 0;
  321. this._gh = (this._gh + gh + getCarry(this._gl, gl)) | 0;
  322. this._hh = (this._hh + hh + getCarry(this._hl, hl)) | 0;
  323. };
  324. Sha512.prototype._hash = function () {
  325. var H = Buffer.allocUnsafe(64);
  326. function writeInt64BE(h, l, offset) {
  327. H.writeInt32BE(h, offset);
  328. H.writeInt32BE(l, offset + 4);
  329. }
  330. writeInt64BE(this._ah, this._al, 0);
  331. writeInt64BE(this._bh, this._bl, 8);
  332. writeInt64BE(this._ch, this._cl, 16);
  333. writeInt64BE(this._dh, this._dl, 24);
  334. writeInt64BE(this._eh, this._el, 32);
  335. writeInt64BE(this._fh, this._fl, 40);
  336. writeInt64BE(this._gh, this._gl, 48);
  337. writeInt64BE(this._hh, this._hl, 56);
  338. return H;
  339. };
  340. module.exports = Sha512;