1 /*
2 * Keccak
3 * (C) 2010,2016 Jack Lloyd
4 *
5 * Botan is released under the Simplified BSD License (see license.txt)
6 */
7 
8 #include <botan/keccak.h>
9 #include <botan/sha3.h>
10 #include <botan/exceptn.h>
11 #include <botan/loadstor.h>
12 
13 namespace Botan {
14 
copy_state() const15 std::unique_ptr<HashFunction> Keccak_1600::copy_state() const
16    {
17    return std::unique_ptr<HashFunction>(new Keccak_1600(*this));
18    }
19 
Keccak_1600(size_t output_bits)20 Keccak_1600::Keccak_1600(size_t output_bits) :
21    m_output_bits(output_bits),
22    m_bitrate(1600 - 2*output_bits),
23    m_S(25),
24    m_S_pos(0)
25    {
26    // We only support the parameters for the SHA-3 proposal
27 
28    if(output_bits != 224 && output_bits != 256 &&
29       output_bits != 384 && output_bits != 512)
30       throw Invalid_Argument("Keccak_1600: Invalid output length " +
31                              std::to_string(output_bits));
32    }
33 
name() const34 std::string Keccak_1600::name() const
35    {
36    return "Keccak-1600(" + std::to_string(m_output_bits) + ")";
37    }
38 
clone() const39 HashFunction* Keccak_1600::clone() const
40    {
41    return new Keccak_1600(m_output_bits);
42    }
43 
clear()44 void Keccak_1600::clear()
45    {
46    zeroise(m_S);
47    m_S_pos = 0;
48    }
49 
add_data(const uint8_t input[],size_t length)50 void Keccak_1600::add_data(const uint8_t input[], size_t length)
51    {
52    m_S_pos = SHA_3::absorb(m_bitrate, m_S, m_S_pos, input, length);
53    }
54 
final_result(uint8_t output[])55 void Keccak_1600::final_result(uint8_t output[])
56    {
57    SHA_3::finish(m_bitrate, m_S, m_S_pos, 0x01, 0x80);
58 
59    /*
60    * We never have to run the permutation again because we only support
61    * limited output lengths
62    */
63    copy_out_vec_le(output, m_output_bits/8, m_S);
64 
65    clear();
66    }
67 
68 }
69