Created
June 13, 2013 16:54
-
-
Save bonsaiviking/5775378 to your computer and use it in GitHub Desktop.
Pure-python SHA-2 implementation, including all FIPS 180-2 specified variants (SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, and SHA-512/256)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#!/usr/bin/env python | |
import struct | |
def rightrotate(i, n, wsize): | |
return ((i << (wsize-n)) & (2**wsize-1)) | (i >> n) | |
class SHA2(object): | |
"""Abstract class for SHA-2 variants""" | |
def __init__(self): | |
raise NotImplementedError | |
def _add_chunk(self, chunk): | |
self.count += 1 | |
unpack_fmt = ">16I" | |
if self.wsize == 64: | |
unpack_fmt = ">16Q" | |
w = list( struct.unpack(unpack_fmt, chunk) + (None,) * (self.rounds-16) ) | |
for i in xrange(16, self.rounds): | |
s0 = self.__class__.sigma0(w[i-15]) | |
s1 = self.__class__.sigma1(w[i-2]) | |
w[i] = (w[i-16] + s0 + w[i-7] + s1) % 2**self.wsize | |
a,b,c,d,e,f,g,h = self.h | |
for i in xrange(self.rounds): | |
S1 = self.__class__.bigsigma1(e) | |
ch = (e & f) ^ (~e & g) | |
temp1 = (h + S1 + ch + self.__class__.k[i] + w[i]) % 2**self.wsize | |
S0 = self.__class__.bigsigma0(a) | |
maj = (a & b) ^ (a & c) ^ (b & c) | |
temp2 = (S0 + maj) % 2**self.wsize | |
h = g | |
g = f | |
f = e | |
e = (d + temp1) % 2**self.wsize | |
d = c | |
c = b | |
b = a | |
a = (temp1 + temp2) % 2**self.wsize | |
self.h[0] = (self.h[0] + a) % 2**self.wsize | |
self.h[1] = (self.h[1] + b) % 2**self.wsize | |
self.h[2] = (self.h[2] + c) % 2**self.wsize | |
self.h[3] = (self.h[3] + d) % 2**self.wsize | |
self.h[4] = (self.h[4] + e) % 2**self.wsize | |
self.h[5] = (self.h[5] + f) % 2**self.wsize | |
self.h[6] = (self.h[6] + g) % 2**self.wsize | |
self.h[7] = (self.h[7] + h) % 2**self.wsize | |
def add(self, data): | |
message = self.remainder + data | |
r = len(message) % self.bsize | |
if r != 0: | |
self.remainder = message[-r:] | |
else: | |
self.remainder = "" | |
for chunk in xrange(0, len(message)-r, self.bsize): | |
self._add_chunk( message[chunk:chunk+self.bsize] ) | |
return self | |
def pad(self, l): | |
raise NotImplementedError | |
def _finish(self): | |
l = len(self.remainder) + self.bsize * self.count | |
self.add( self.pad(l) ) | |
assert(self.remainder == "") | |
h = tuple(x for x in self.h) | |
self.__init__() | |
return h | |
class SHA2b256(SHA2): | |
"""Abstract class for SHA-2 variants with 256-bit block size""" | |
bsize = 64 | |
rounds = 64 | |
wsize = 32 | |
k = ( | |
0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5, | |
0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174, | |
0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da, | |
0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967, | |
0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85, | |
0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070, | |
0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3, | |
0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2 | |
) | |
@staticmethod | |
def sigma0(word): | |
return rightrotate(word,7,32) ^ rightrotate(word,18,32) ^ (word >> 3) | |
@staticmethod | |
def sigma1(word): | |
return rightrotate(word,17,32) ^ rightrotate(word,19,32) ^ (word >> 10) | |
@staticmethod | |
def bigsigma1(word): | |
return rightrotate(word, 6,32) ^ rightrotate(word, 11,32) ^ rightrotate(word, 25,32) | |
@staticmethod | |
def bigsigma0(word): | |
return rightrotate(word, 2,32) ^ rightrotate(word, 13,32) ^ rightrotate(word, 22,32) | |
def pad(self,l): | |
return "\x80" + "\x00" * ((55 - l) % self.bsize) + struct.pack(">Q", l*8) | |
class SHA256(SHA2b256): | |
def __init__(self, data=""): | |
self.h = [ | |
0x6a09e667, | |
0xbb67ae85, | |
0x3c6ef372, | |
0xa54ff53a, | |
0x510e527f, | |
0x9b05688c, | |
0x1f83d9ab, | |
0x5be0cd19 | |
] | |
self.remainder = data | |
self.count = 0 | |
def finish(self): | |
h = self._finish() | |
return struct.pack(">8I", *h) | |
class SHA224(SHA2b256): | |
def __init__(self, data=""): | |
self.h = [ | |
0xc1059ed8, | |
0x367cd507, | |
0x3070dd17, | |
0xf70e5939, | |
0xffc00b31, | |
0x68581511, | |
0x64f98fa7, | |
0xbefa4fa4 | |
] | |
self.remainder = data | |
self.count = 0 | |
def finish(self): | |
h = self._finish()[:7] | |
return struct.pack(">7I", *h) | |
class SHA2b512(SHA2): | |
"""Abstract class for SHA-2 variants with 512-bit block size""" | |
bsize = 128 | |
rounds = 80 | |
wsize = 64 | |
k = ( | |
0x428a2f98d728ae22, 0x7137449123ef65cd, 0xb5c0fbcfec4d3b2f, 0xe9b5dba58189dbbc, | |
0x3956c25bf348b538, 0x59f111f1b605d019, 0x923f82a4af194f9b, 0xab1c5ed5da6d8118, | |
0xd807aa98a3030242, 0x12835b0145706fbe, 0x243185be4ee4b28c, 0x550c7dc3d5ffb4e2, | |
0x72be5d74f27b896f, 0x80deb1fe3b1696b1, 0x9bdc06a725c71235, 0xc19bf174cf692694, | |
0xe49b69c19ef14ad2, 0xefbe4786384f25e3, 0x0fc19dc68b8cd5b5, 0x240ca1cc77ac9c65, | |
0x2de92c6f592b0275, 0x4a7484aa6ea6e483, 0x5cb0a9dcbd41fbd4, 0x76f988da831153b5, | |
0x983e5152ee66dfab, 0xa831c66d2db43210, 0xb00327c898fb213f, 0xbf597fc7beef0ee4, | |
0xc6e00bf33da88fc2, 0xd5a79147930aa725, 0x06ca6351e003826f, 0x142929670a0e6e70, | |
0x27b70a8546d22ffc, 0x2e1b21385c26c926, 0x4d2c6dfc5ac42aed, 0x53380d139d95b3df, | |
0x650a73548baf63de, 0x766a0abb3c77b2a8, 0x81c2c92e47edaee6, 0x92722c851482353b, | |
0xa2bfe8a14cf10364, 0xa81a664bbc423001, 0xc24b8b70d0f89791, 0xc76c51a30654be30, | |
0xd192e819d6ef5218, 0xd69906245565a910, 0xf40e35855771202a, 0x106aa07032bbd1b8, | |
0x19a4c116b8d2d0c8, 0x1e376c085141ab53, 0x2748774cdf8eeb99, 0x34b0bcb5e19b48a8, | |
0x391c0cb3c5c95a63, 0x4ed8aa4ae3418acb, 0x5b9cca4f7763e373, 0x682e6ff3d6b2b8a3, | |
0x748f82ee5defb2fc, 0x78a5636f43172f60, 0x84c87814a1f0ab72, 0x8cc702081a6439ec, | |
0x90befffa23631e28, 0xa4506cebde82bde9, 0xbef9a3f7b2c67915, 0xc67178f2e372532b, | |
0xca273eceea26619c, 0xd186b8c721c0c207, 0xeada7dd6cde0eb1e, 0xf57d4f7fee6ed178, | |
0x06f067aa72176fba, 0x0a637dc5a2c898a6, 0x113f9804bef90dae, 0x1b710b35131c471b, | |
0x28db77f523047d84, 0x32caab7b40c72493, 0x3c9ebe0a15c9bebc, 0x431d67c49c100d4c, | |
0x4cc5d4becb3e42b6, 0x597f299cfc657e2a, 0x5fcb6fab3ad6faec, 0x6c44198c4a475817, | |
) | |
@staticmethod | |
def sigma0(word): | |
return rightrotate(word,1,64) ^ rightrotate(word,8,64) ^ (word >> 7) | |
@staticmethod | |
def sigma1(word): | |
return rightrotate(word,19,64) ^ rightrotate(word,61,64) ^ (word >> 6) | |
@staticmethod | |
def bigsigma0(word): | |
return rightrotate(word,28,64) ^ rightrotate(word,34,64) ^ rightrotate(word,39,64) | |
@staticmethod | |
def bigsigma1(word): | |
return rightrotate(word, 14,64) ^ rightrotate(word,18,64) ^ rightrotate(word,41,64) | |
def pad(self,l): | |
lb = l * 8 | |
return "\x80" + "\x00" * ((111 - l) % self.bsize) + struct.pack(">QQ", lb >> 64, lb & (2**64-1)) | |
class SHA384(SHA2b512): | |
def __init__(self, data=""): | |
self.h = [ | |
0xcbbb9d5dc1059ed8, | |
0x629a292a367cd507, | |
0x9159015a3070dd17, | |
0x152fecd8f70e5939, | |
0x67332667ffc00b31, | |
0x8eb44a8768581511, | |
0xdb0c2e0d64f98fa7, | |
0x47b5481dbefa4fa4 | |
] | |
self.remainder = data | |
self.count = 0 | |
def finish(self): | |
h = self._finish()[:6] | |
return struct.pack(">6Q", *h) | |
class SHA512(SHA2b512): | |
def __init__(self, data=""): | |
self.h = [ | |
0x6a09e667f3bcc908, | |
0xbb67ae8584caa73b, | |
0x3c6ef372fe94f82b, | |
0xa54ff53a5f1d36f1, | |
0x510e527fade682d1, | |
0x9b05688c2b3e6c1f, | |
0x1f83d9abfb41bd6b, | |
0x5be0cd19137e2179 | |
] | |
self.remainder = data | |
self.count = 0 | |
def finish(self): | |
h = self._finish() | |
return struct.pack(">8Q", *h) | |
class SHA512t(SHA512): | |
"""Base class for truncated SHA512 variants""" | |
def __init__(self, t=None, data=""): | |
if t is None: | |
if not hasattr(self, "t"): | |
raise TypeError, "Missing required argument 't'" | |
elif t == 384: | |
raise ValueError, "Use SHA384 instead" | |
else: | |
self.t = t | |
super(SHA512t, self).__init__() | |
self.h = map(lambda x: x ^ 0xa5a5a5a5a5a5a5a5, self.h) | |
iv = "SHA-512/{0}".format(self.t) | |
self.add( iv + self.pad(len(iv)) ) | |
self.remainder = data | |
self.count = 0 | |
def finish(self): | |
h = super(SHA512t, self)._finish() | |
out = struct.pack(">8Q", *h) | |
return out[:self.t//8] | |
class SHA512_224(SHA512t): | |
def __init__(self, data=""): | |
super(SHA512_224, self).__init__(t=224, data=data) | |
class SHA512_256(SHA512t): | |
def __init__(self, data=""): | |
super(SHA512_256, self).__init__(t=256, data=data) | |
if __name__=="__main__": | |
tests = ( | |
(SHA224, "", "d14a028c2a3a2bc9476102bb288234c415a2b01f828ea62ac5b3e42f"), | |
(SHA256, "", "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"), | |
(SHA384, "", "38b060a751ac96384cd9327eb1b1e36a21fdb71114be07434c0cc7bf63f6e1da274edebfe76f65fbd51ad2f14898b95b"), | |
(SHA512, "", "cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e"), | |
(SHA512_224, "", "6ed0dd02806fa89e25de060c19d3ac86cabb87d6a0ddd05c333b84f4"), | |
(SHA512_256, "", "c672b8d1ef56ed28ab87c3622c5114069bdd3ad7b8f9737498d0c01ecef0967a"), | |
) | |
for klass, v, h in tests: | |
h1 = klass(v).finish().encode('hex') | |
if h1 == h: | |
print "{0!r} - pass".format(klass) | |
else: | |
print "{0!r} - fail - {1}".format(klass, h1) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment