md5.c 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271
  1. /*
  2. * Cryptographic API.
  3. *
  4. * MD5 Message Digest Algorithm (RFC1321).
  5. *
  6. * Derived from cryptoapi implementation, originally based on the
  7. * public domain implementation written by Colin Plumb in 1993.
  8. *
  9. * Copyright (c) Cryptoapi developers.
  10. * Copyright (c) 2002 James Morris <jmorris@intercode.com.au>
  11. *
  12. * This program is free software; you can redistribute it and/or modify it
  13. * under the terms of the GNU General Public License as published by the Free
  14. * Software Foundation; either version 2 of the License, or (at your option)
  15. * any later version.
  16. *
  17. */
  18. #include <crypto/internal/hash.h>
  19. #include <crypto/md5.h>
  20. #include <linux/init.h>
  21. #include <linux/module.h>
  22. #include <linux/string.h>
  23. #include <linux/types.h>
  24. #include <asm/byteorder.h>
  25. #define MD5_DIGEST_WORDS 4
  26. #define MD5_MESSAGE_BYTES 64
  27. const u8 md5_zero_message_hash[MD5_DIGEST_SIZE] = {
  28. 0xd4, 0x1d, 0x8c, 0xd9, 0x8f, 0x00, 0xb2, 0x04,
  29. 0xe9, 0x80, 0x09, 0x98, 0xec, 0xf8, 0x42, 0x7e,
  30. };
  31. EXPORT_SYMBOL_GPL(md5_zero_message_hash);
  32. /* XXX: this stuff can be optimized */
  33. static inline void le32_to_cpu_array(u32 *buf, unsigned int words)
  34. {
  35. while (words--) {
  36. __le32_to_cpus(buf);
  37. buf++;
  38. }
  39. }
  40. static inline void cpu_to_le32_array(u32 *buf, unsigned int words)
  41. {
  42. while (words--) {
  43. __cpu_to_le32s(buf);
  44. buf++;
  45. }
  46. }
  47. #define F1(x, y, z) (z ^ (x & (y ^ z)))
  48. #define F2(x, y, z) F1(z, x, y)
  49. #define F3(x, y, z) (x ^ y ^ z)
  50. #define F4(x, y, z) (y ^ (x | ~z))
  51. #define MD5STEP(f, w, x, y, z, in, s) \
  52. (w += f(x, y, z) + in, w = (w<<s | w>>(32-s)) + x)
  53. static void md5_transform(__u32 *hash, __u32 const *in)
  54. {
  55. u32 a, b, c, d;
  56. a = hash[0];
  57. b = hash[1];
  58. c = hash[2];
  59. d = hash[3];
  60. MD5STEP(F1, a, b, c, d, in[0] + 0xd76aa478, 7);
  61. MD5STEP(F1, d, a, b, c, in[1] + 0xe8c7b756, 12);
  62. MD5STEP(F1, c, d, a, b, in[2] + 0x242070db, 17);
  63. MD5STEP(F1, b, c, d, a, in[3] + 0xc1bdceee, 22);
  64. MD5STEP(F1, a, b, c, d, in[4] + 0xf57c0faf, 7);
  65. MD5STEP(F1, d, a, b, c, in[5] + 0x4787c62a, 12);
  66. MD5STEP(F1, c, d, a, b, in[6] + 0xa8304613, 17);
  67. MD5STEP(F1, b, c, d, a, in[7] + 0xfd469501, 22);
  68. MD5STEP(F1, a, b, c, d, in[8] + 0x698098d8, 7);
  69. MD5STEP(F1, d, a, b, c, in[9] + 0x8b44f7af, 12);
  70. MD5STEP(F1, c, d, a, b, in[10] + 0xffff5bb1, 17);
  71. MD5STEP(F1, b, c, d, a, in[11] + 0x895cd7be, 22);
  72. MD5STEP(F1, a, b, c, d, in[12] + 0x6b901122, 7);
  73. MD5STEP(F1, d, a, b, c, in[13] + 0xfd987193, 12);
  74. MD5STEP(F1, c, d, a, b, in[14] + 0xa679438e, 17);
  75. MD5STEP(F1, b, c, d, a, in[15] + 0x49b40821, 22);
  76. MD5STEP(F2, a, b, c, d, in[1] + 0xf61e2562, 5);
  77. MD5STEP(F2, d, a, b, c, in[6] + 0xc040b340, 9);
  78. MD5STEP(F2, c, d, a, b, in[11] + 0x265e5a51, 14);
  79. MD5STEP(F2, b, c, d, a, in[0] + 0xe9b6c7aa, 20);
  80. MD5STEP(F2, a, b, c, d, in[5] + 0xd62f105d, 5);
  81. MD5STEP(F2, d, a, b, c, in[10] + 0x02441453, 9);
  82. MD5STEP(F2, c, d, a, b, in[15] + 0xd8a1e681, 14);
  83. MD5STEP(F2, b, c, d, a, in[4] + 0xe7d3fbc8, 20);
  84. MD5STEP(F2, a, b, c, d, in[9] + 0x21e1cde6, 5);
  85. MD5STEP(F2, d, a, b, c, in[14] + 0xc33707d6, 9);
  86. MD5STEP(F2, c, d, a, b, in[3] + 0xf4d50d87, 14);
  87. MD5STEP(F2, b, c, d, a, in[8] + 0x455a14ed, 20);
  88. MD5STEP(F2, a, b, c, d, in[13] + 0xa9e3e905, 5);
  89. MD5STEP(F2, d, a, b, c, in[2] + 0xfcefa3f8, 9);
  90. MD5STEP(F2, c, d, a, b, in[7] + 0x676f02d9, 14);
  91. MD5STEP(F2, b, c, d, a, in[12] + 0x8d2a4c8a, 20);
  92. MD5STEP(F3, a, b, c, d, in[5] + 0xfffa3942, 4);
  93. MD5STEP(F3, d, a, b, c, in[8] + 0x8771f681, 11);
  94. MD5STEP(F3, c, d, a, b, in[11] + 0x6d9d6122, 16);
  95. MD5STEP(F3, b, c, d, a, in[14] + 0xfde5380c, 23);
  96. MD5STEP(F3, a, b, c, d, in[1] + 0xa4beea44, 4);
  97. MD5STEP(F3, d, a, b, c, in[4] + 0x4bdecfa9, 11);
  98. MD5STEP(F3, c, d, a, b, in[7] + 0xf6bb4b60, 16);
  99. MD5STEP(F3, b, c, d, a, in[10] + 0xbebfbc70, 23);
  100. MD5STEP(F3, a, b, c, d, in[13] + 0x289b7ec6, 4);
  101. MD5STEP(F3, d, a, b, c, in[0] + 0xeaa127fa, 11);
  102. MD5STEP(F3, c, d, a, b, in[3] + 0xd4ef3085, 16);
  103. MD5STEP(F3, b, c, d, a, in[6] + 0x04881d05, 23);
  104. MD5STEP(F3, a, b, c, d, in[9] + 0xd9d4d039, 4);
  105. MD5STEP(F3, d, a, b, c, in[12] + 0xe6db99e5, 11);
  106. MD5STEP(F3, c, d, a, b, in[15] + 0x1fa27cf8, 16);
  107. MD5STEP(F3, b, c, d, a, in[2] + 0xc4ac5665, 23);
  108. MD5STEP(F4, a, b, c, d, in[0] + 0xf4292244, 6);
  109. MD5STEP(F4, d, a, b, c, in[7] + 0x432aff97, 10);
  110. MD5STEP(F4, c, d, a, b, in[14] + 0xab9423a7, 15);
  111. MD5STEP(F4, b, c, d, a, in[5] + 0xfc93a039, 21);
  112. MD5STEP(F4, a, b, c, d, in[12] + 0x655b59c3, 6);
  113. MD5STEP(F4, d, a, b, c, in[3] + 0x8f0ccc92, 10);
  114. MD5STEP(F4, c, d, a, b, in[10] + 0xffeff47d, 15);
  115. MD5STEP(F4, b, c, d, a, in[1] + 0x85845dd1, 21);
  116. MD5STEP(F4, a, b, c, d, in[8] + 0x6fa87e4f, 6);
  117. MD5STEP(F4, d, a, b, c, in[15] + 0xfe2ce6e0, 10);
  118. MD5STEP(F4, c, d, a, b, in[6] + 0xa3014314, 15);
  119. MD5STEP(F4, b, c, d, a, in[13] + 0x4e0811a1, 21);
  120. MD5STEP(F4, a, b, c, d, in[4] + 0xf7537e82, 6);
  121. MD5STEP(F4, d, a, b, c, in[11] + 0xbd3af235, 10);
  122. MD5STEP(F4, c, d, a, b, in[2] + 0x2ad7d2bb, 15);
  123. MD5STEP(F4, b, c, d, a, in[9] + 0xeb86d391, 21);
  124. hash[0] += a;
  125. hash[1] += b;
  126. hash[2] += c;
  127. hash[3] += d;
  128. }
  129. static inline void md5_transform_helper(struct md5_state *ctx)
  130. {
  131. le32_to_cpu_array(ctx->block, sizeof(ctx->block) / sizeof(u32));
  132. md5_transform(ctx->hash, ctx->block);
  133. }
  134. static int md5_init(struct shash_desc *desc)
  135. {
  136. struct md5_state *mctx = shash_desc_ctx(desc);
  137. mctx->hash[0] = MD5_H0;
  138. mctx->hash[1] = MD5_H1;
  139. mctx->hash[2] = MD5_H2;
  140. mctx->hash[3] = MD5_H3;
  141. mctx->byte_count = 0;
  142. return 0;
  143. }
  144. static int md5_update(struct shash_desc *desc, const u8 *data, unsigned int len)
  145. {
  146. struct md5_state *mctx = shash_desc_ctx(desc);
  147. const u32 avail = sizeof(mctx->block) - (mctx->byte_count & 0x3f);
  148. mctx->byte_count += len;
  149. if (avail > len) {
  150. memcpy((char *)mctx->block + (sizeof(mctx->block) - avail),
  151. data, len);
  152. return 0;
  153. }
  154. memcpy((char *)mctx->block + (sizeof(mctx->block) - avail),
  155. data, avail);
  156. md5_transform_helper(mctx);
  157. data += avail;
  158. len -= avail;
  159. while (len >= sizeof(mctx->block)) {
  160. memcpy(mctx->block, data, sizeof(mctx->block));
  161. md5_transform_helper(mctx);
  162. data += sizeof(mctx->block);
  163. len -= sizeof(mctx->block);
  164. }
  165. memcpy(mctx->block, data, len);
  166. return 0;
  167. }
  168. static int md5_final(struct shash_desc *desc, u8 *out)
  169. {
  170. struct md5_state *mctx = shash_desc_ctx(desc);
  171. const unsigned int offset = mctx->byte_count & 0x3f;
  172. char *p = (char *)mctx->block + offset;
  173. int padding = 56 - (offset + 1);
  174. *p++ = 0x80;
  175. if (padding < 0) {
  176. memset(p, 0x00, padding + sizeof (u64));
  177. md5_transform_helper(mctx);
  178. p = (char *)mctx->block;
  179. padding = 56;
  180. }
  181. memset(p, 0, padding);
  182. mctx->block[14] = mctx->byte_count << 3;
  183. mctx->block[15] = mctx->byte_count >> 29;
  184. le32_to_cpu_array(mctx->block, (sizeof(mctx->block) -
  185. sizeof(u64)) / sizeof(u32));
  186. md5_transform(mctx->hash, mctx->block);
  187. cpu_to_le32_array(mctx->hash, sizeof(mctx->hash) / sizeof(u32));
  188. memcpy(out, mctx->hash, sizeof(mctx->hash));
  189. memset(mctx, 0, sizeof(*mctx));
  190. return 0;
  191. }
  192. static int md5_export(struct shash_desc *desc, void *out)
  193. {
  194. struct md5_state *ctx = shash_desc_ctx(desc);
  195. memcpy(out, ctx, sizeof(*ctx));
  196. return 0;
  197. }
  198. static int md5_import(struct shash_desc *desc, const void *in)
  199. {
  200. struct md5_state *ctx = shash_desc_ctx(desc);
  201. memcpy(ctx, in, sizeof(*ctx));
  202. return 0;
  203. }
  204. static struct shash_alg alg = {
  205. .digestsize = MD5_DIGEST_SIZE,
  206. .init = md5_init,
  207. .update = md5_update,
  208. .final = md5_final,
  209. .export = md5_export,
  210. .import = md5_import,
  211. .descsize = sizeof(struct md5_state),
  212. .statesize = sizeof(struct md5_state),
  213. .base = {
  214. .cra_name = "md5",
  215. .cra_flags = CRYPTO_ALG_TYPE_SHASH,
  216. .cra_blocksize = MD5_HMAC_BLOCK_SIZE,
  217. .cra_module = THIS_MODULE,
  218. }
  219. };
  220. static int __init md5_mod_init(void)
  221. {
  222. return crypto_register_shash(&alg);
  223. }
  224. static void __exit md5_mod_fini(void)
  225. {
  226. crypto_unregister_shash(&alg);
  227. }
  228. module_init(md5_mod_init);
  229. module_exit(md5_mod_fini);
  230. MODULE_LICENSE("GPL");
  231. MODULE_DESCRIPTION("MD5 Message Digest Algorithm");
  232. MODULE_ALIAS_CRYPTO("md5");