PageRenderTime 52ms CodeModel.GetById 16ms RepoModel.GetById 1ms app.codeStats 0ms

/vendor/phpseclib/Crypt/Hash.php

http://github.com/fuel/core
PHP | 853 lines | 499 code | 72 blank | 282 comment | 36 complexity | 208512c3764846671dd9dfb4c7a1fda2 MD5 | raw file
Possible License(s): BSD-3-Clause
  1. <?php
  2. /* vim: set expandtab tabstop=4 shiftwidth=4 softtabstop=4: */
  3. namespace PHPSecLib;
  4. /**
  5. * Pure-PHP implementations of keyed-hash message authentication codes (HMACs) and various cryptographic hashing functions.
  6. *
  7. * Uses hash() or mhash() if available and an internal implementation, otherwise. Currently supports the following:
  8. *
  9. * md2, md5, md5-96, sha1, sha1-96, sha256, sha384, and sha512
  10. *
  11. * If {@link Crypt_Hash::setKey() setKey()} is called, {@link Crypt_Hash::hash() hash()} will return the HMAC as opposed to
  12. * the hash. If no valid algorithm is provided, sha1 will be used.
  13. *
  14. * PHP versions 4 and 5
  15. *
  16. * {@internal The variable names are the same as those in
  17. * {@link http://tools.ietf.org/html/rfc2104#section-2 RFC2104}.}}
  18. *
  19. * Here's a short example of how to use this library:
  20. * <code>
  21. * <?php
  22. * include('Crypt/Hash.php');
  23. *
  24. * $hash = new Crypt_Hash('sha1');
  25. *
  26. * $hash->setKey('abcdefg');
  27. *
  28. * echo base64_encode($hash->hash('abcdefg'));
  29. * ?>
  30. * </code>
  31. *
  32. * LICENSE: This library is free software; you can redistribute it and/or
  33. * modify it under the terms of the GNU Lesser General Public
  34. * License as published by the Free Software Foundation; either
  35. * version 2.1 of the License, or (at your option) any later version.
  36. *
  37. * This library is distributed in the hope that it will be useful,
  38. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  39. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  40. * Lesser General Public License for more details.
  41. *
  42. * You should have received a copy of the GNU Lesser General Public
  43. * License along with this library; if not, write to the Free Software
  44. * Foundation, Inc., 59 Temple Place, Suite 330, Boston,
  45. * MA 02111-1307 USA
  46. *
  47. * @category Crypt
  48. * @package Crypt_Hash
  49. * @author Jim Wigginton <terrafrost@php.net>
  50. * @copyright MMVII Jim Wigginton
  51. * @license http://www.gnu.org/licenses/lgpl.txt
  52. * @version $Id: Hash.php,v 1.6 2009/11/23 23:37:07 terrafrost Exp $
  53. * @link http://phpseclib.sourceforge.net
  54. */
  55. /**#@+
  56. * @access private
  57. * @see Crypt_Hash::Crypt_Hash()
  58. */
  59. /**
  60. * Toggles the internal implementation
  61. */
  62. define('CRYPT_HASH_MODE_INTERNAL', 1);
  63. /**
  64. * Toggles the mhash() implementation, which has been deprecated on PHP 5.3.0+.
  65. */
  66. define('CRYPT_HASH_MODE_MHASH', 2);
  67. /**
  68. * Toggles the hash() implementation, which works on PHP 5.1.2+.
  69. */
  70. define('CRYPT_HASH_MODE_HASH', 3);
  71. /**#@-*/
  72. /**
  73. * Pure-PHP implementations of keyed-hash message authentication codes (HMACs) and various cryptographic hashing functions.
  74. *
  75. * @author Jim Wigginton <terrafrost@php.net>
  76. * @version 0.1.0
  77. * @access public
  78. * @package Crypt_Hash
  79. */
  80. class Crypt_Hash {
  81. /**
  82. * Byte-length of compression blocks / key (Internal HMAC)
  83. *
  84. * @see Crypt_Hash::setAlgorithm()
  85. * @var Integer
  86. * @access private
  87. */
  88. var $b;
  89. /**
  90. * Byte-length of hash output (Internal HMAC)
  91. *
  92. * @see Crypt_Hash::setHash()
  93. * @var Integer
  94. * @access private
  95. */
  96. var $l = false;
  97. /**
  98. * Hash Algorithm
  99. *
  100. * @see Crypt_Hash::setHash()
  101. * @var String
  102. * @access private
  103. */
  104. var $hash;
  105. /**
  106. * Key
  107. *
  108. * @see Crypt_Hash::setKey()
  109. * @var String
  110. * @access private
  111. */
  112. var $key = '';
  113. /**
  114. * Outer XOR (Internal HMAC)
  115. *
  116. * @see Crypt_Hash::setKey()
  117. * @var String
  118. * @access private
  119. */
  120. var $opad;
  121. /**
  122. * Inner XOR (Internal HMAC)
  123. *
  124. * @see Crypt_Hash::setKey()
  125. * @var String
  126. * @access private
  127. */
  128. var $ipad;
  129. /**
  130. * Default Constructor.
  131. *
  132. * @param optional String $hash
  133. * @return Crypt_Hash
  134. * @access public
  135. */
  136. public function __construct($hash = 'sha1')
  137. {
  138. if ( !defined('CRYPT_HASH_MODE') ) {
  139. switch (true) {
  140. case extension_loaded('hash'):
  141. define('CRYPT_HASH_MODE', CRYPT_HASH_MODE_HASH);
  142. break;
  143. case extension_loaded('mhash'):
  144. define('CRYPT_HASH_MODE', CRYPT_HASH_MODE_MHASH);
  145. break;
  146. default:
  147. define('CRYPT_HASH_MODE', CRYPT_HASH_MODE_INTERNAL);
  148. }
  149. }
  150. $this->setHash($hash);
  151. }
  152. /**
  153. * Sets the key for HMACs
  154. *
  155. * Keys can be of any length.
  156. *
  157. * @access public
  158. * @param String $key
  159. */
  160. public function setKey($key)
  161. {
  162. $this->key = $key;
  163. }
  164. /**
  165. * Sets the hash function.
  166. *
  167. * @access public
  168. * @param String $hash
  169. */
  170. public function setHash($hash)
  171. {
  172. switch ($hash) {
  173. case 'md5-96':
  174. case 'sha1-96':
  175. $this->l = 12; // 96 / 8 = 12
  176. break;
  177. case 'md2':
  178. case 'md5':
  179. $this->l = 16;
  180. break;
  181. case 'sha1':
  182. $this->l = 20;
  183. break;
  184. case 'sha256':
  185. $this->l = 32;
  186. break;
  187. case 'sha384':
  188. $this->l = 48;
  189. break;
  190. case 'sha512':
  191. $this->l = 64;
  192. }
  193. switch ($hash) {
  194. case 'md2':
  195. $mode = CRYPT_HASH_MODE_INTERNAL;
  196. break;
  197. case 'sha384':
  198. case 'sha512':
  199. $mode = CRYPT_HASH_MODE == CRYPT_HASH_MODE_MHASH ? CRYPT_HASH_MODE_INTERNAL : CRYPT_HASH_MODE;
  200. break;
  201. default:
  202. $mode = CRYPT_HASH_MODE;
  203. }
  204. switch ( $mode ) {
  205. case CRYPT_HASH_MODE_MHASH:
  206. switch ($hash) {
  207. case 'md5':
  208. case 'md5-96':
  209. $this->hash = MHASH_MD5;
  210. break;
  211. case 'sha256':
  212. $this->hash = MHASH_SHA256;
  213. break;
  214. case 'sha1':
  215. case 'sha1-96':
  216. default:
  217. $this->hash = MHASH_SHA1;
  218. }
  219. return;
  220. case CRYPT_HASH_MODE_HASH:
  221. switch ($hash) {
  222. case 'md5':
  223. case 'md5-96':
  224. $this->hash = 'md5';
  225. return;
  226. case 'sha256':
  227. case 'sha384':
  228. case 'sha512':
  229. $this->hash = $hash;
  230. return;
  231. case 'sha1':
  232. case 'sha1-96':
  233. default:
  234. $this->hash = 'sha1';
  235. }
  236. return;
  237. }
  238. switch ($hash) {
  239. case 'md2':
  240. $this->b = 16;
  241. $this->hash = array($this, '_md2');
  242. break;
  243. case 'md5':
  244. case 'md5-96':
  245. $this->b = 64;
  246. $this->hash = array($this, '_md5');
  247. break;
  248. case 'sha256':
  249. $this->b = 64;
  250. $this->hash = array($this, '_sha256');
  251. break;
  252. case 'sha384':
  253. case 'sha512':
  254. $this->b = 128;
  255. $this->hash = array($this, '_sha512');
  256. break;
  257. case 'sha1':
  258. case 'sha1-96':
  259. default:
  260. $this->b = 64;
  261. $this->hash = array($this, '_sha1');
  262. }
  263. $this->ipad = str_repeat(chr(0x36), $this->b);
  264. $this->opad = str_repeat(chr(0x5C), $this->b);
  265. }
  266. /**
  267. * Compute the HMAC.
  268. *
  269. * @access public
  270. * @param String $text
  271. * @return String
  272. */
  273. public function hash($text)
  274. {
  275. $mode = is_array($this->hash) ? CRYPT_HASH_MODE_INTERNAL : CRYPT_HASH_MODE;
  276. if (!empty($this->key)) {
  277. switch ( $mode ) {
  278. case CRYPT_HASH_MODE_MHASH:
  279. $output = mhash($this->hash, $text, $this->key);
  280. break;
  281. case CRYPT_HASH_MODE_HASH:
  282. $output = hash_hmac($this->hash, $text, $this->key, true);
  283. break;
  284. case CRYPT_HASH_MODE_INTERNAL:
  285. /* "Applications that use keys longer than B bytes will first hash the key using H and then use the
  286. resultant L byte string as the actual key to HMAC."
  287. -- http://tools.ietf.org/html/rfc2104#section-2 */
  288. $key = strlen($this->key) > $this->b ? call_user_func($this->$hash, $this->key) : $this->key;
  289. $key = str_pad($key, $this->b, chr(0)); // step 1
  290. $temp = $this->ipad ^ $key; // step 2
  291. $temp .= $text; // step 3
  292. $temp = call_user_func($this->hash, $temp); // step 4
  293. $output = $this->opad ^ $key; // step 5
  294. $output.= $temp; // step 6
  295. $output = call_user_func($this->hash, $output); // step 7
  296. }
  297. } else {
  298. switch ( $mode ) {
  299. case CRYPT_HASH_MODE_MHASH:
  300. $output = mhash($this->hash, $text);
  301. break;
  302. case CRYPT_HASH_MODE_HASH:
  303. $output = hash($this->hash, $text, true);
  304. break;
  305. case CRYPT_HASH_MODE_INTERNAL:
  306. $output = call_user_func($this->hash, $text);
  307. }
  308. }
  309. return substr($output, 0, $this->l);
  310. }
  311. /**
  312. * Returns the hash length (in bytes)
  313. *
  314. * @access private
  315. * @return Integer
  316. */
  317. public function getLength()
  318. {
  319. return $this->l;
  320. }
  321. /* PBKDF2 Implementation (described in RFC 2898)
  322. *
  323. * @param string p password
  324. * @param string s salt
  325. * @param int c iteration count (use 1000 or higher)
  326. * @param int kl derived key length
  327. * @param string a hash algorithm
  328. *
  329. * @return string derived key
  330. */
  331. public function pbkdf2( $p, $s, $c, $kl, $a = 'sha256' )
  332. {
  333. $hl = strlen(hash($a, null, true)); # Hash length
  334. $kb = ceil($kl / $hl); # Key blocks to compute
  335. $dk = ''; # Derived key
  336. # Create key
  337. for ( $block = 1; $block <= $kb; $block ++ )
  338. {
  339. # Initial hash for this block
  340. $ib = $b = hash_hmac($a, $s . pack('N', $block), $p, true);
  341. # Perform block iterations
  342. for ( $i = 1; $i < $c; $i ++ )
  343. {
  344. # XOR each iterate
  345. $ib ^= ($b = hash_hmac($a, $b, $p, true));
  346. }
  347. $dk .= $ib; # Append iterated block
  348. }
  349. # Return derived key of correct length
  350. return substr($dk, 0, $kl);
  351. }
  352. /**
  353. * Wrapper for MD5
  354. *
  355. * @access private
  356. * @param String $text
  357. */
  358. private function _md5($m)
  359. {
  360. return pack('H*', md5($m));
  361. }
  362. /**
  363. * Wrapper for SHA1
  364. *
  365. * @access private
  366. * @param String $text
  367. */
  368. private function _sha1($m)
  369. {
  370. return pack('H*', sha1($m));
  371. }
  372. /**
  373. * Pure-PHP implementation of MD2
  374. *
  375. * See {@link http://tools.ietf.org/html/rfc1319 RFC1319}.
  376. *
  377. * @access private
  378. * @param String $text
  379. */
  380. private function _md2($m)
  381. {
  382. static $s = array(
  383. 41, 46, 67, 201, 162, 216, 124, 1, 61, 54, 84, 161, 236, 240, 6,
  384. 19, 98, 167, 5, 243, 192, 199, 115, 140, 152, 147, 43, 217, 188,
  385. 76, 130, 202, 30, 155, 87, 60, 253, 212, 224, 22, 103, 66, 111, 24,
  386. 138, 23, 229, 18, 190, 78, 196, 214, 218, 158, 222, 73, 160, 251,
  387. 245, 142, 187, 47, 238, 122, 169, 104, 121, 145, 21, 178, 7, 63,
  388. 148, 194, 16, 137, 11, 34, 95, 33, 128, 127, 93, 154, 90, 144, 50,
  389. 39, 53, 62, 204, 231, 191, 247, 151, 3, 255, 25, 48, 179, 72, 165,
  390. 181, 209, 215, 94, 146, 42, 172, 86, 170, 198, 79, 184, 56, 210,
  391. 150, 164, 125, 182, 118, 252, 107, 226, 156, 116, 4, 241, 69, 157,
  392. 112, 89, 100, 113, 135, 32, 134, 91, 207, 101, 230, 45, 168, 2, 27,
  393. 96, 37, 173, 174, 176, 185, 246, 28, 70, 97, 105, 52, 64, 126, 15,
  394. 85, 71, 163, 35, 221, 81, 175, 58, 195, 92, 249, 206, 186, 197,
  395. 234, 38, 44, 83, 13, 110, 133, 40, 132, 9, 211, 223, 205, 244, 65,
  396. 129, 77, 82, 106, 220, 55, 200, 108, 193, 171, 250, 36, 225, 123,
  397. 8, 12, 189, 177, 74, 120, 136, 149, 139, 227, 99, 232, 109, 233,
  398. 203, 213, 254, 59, 0, 29, 57, 242, 239, 183, 14, 102, 88, 208, 228,
  399. 166, 119, 114, 248, 235, 117, 75, 10, 49, 68, 80, 180, 143, 237,
  400. 31, 26, 219, 153, 141, 51, 159, 17, 131, 20
  401. );
  402. // Step 1. Append Padding Bytes
  403. $pad = 16 - (strlen($m) & 0xF);
  404. $m.= str_repeat(chr($pad), $pad);
  405. $length = strlen($m);
  406. // Step 2. Append Checksum
  407. $c = str_repeat(chr(0), 16);
  408. $l = chr(0);
  409. for ($i = 0; $i < $length; $i+= 16) {
  410. for ($j = 0; $j < 16; $j++) {
  411. $c[$j] = chr($s[ord($m[$i + $j] ^ $l)]);
  412. $l = $c[$j];
  413. }
  414. }
  415. $m.= $c;
  416. $length+= 16;
  417. // Step 3. Initialize MD Buffer
  418. $x = str_repeat(chr(0), 48);
  419. // Step 4. Process Message in 16-Byte Blocks
  420. for ($i = 0; $i < $length; $i+= 16) {
  421. for ($j = 0; $j < 16; $j++) {
  422. $x[$j + 16] = $m[$i + $j];
  423. $x[$j + 32] = $x[$j + 16] ^ $x[$j];
  424. }
  425. $t = chr(0);
  426. for ($j = 0; $j < 18; $j++) {
  427. for ($k = 0; $k < 48; $k++) {
  428. $x[$k] = $t = $x[$k] ^ chr($s[ord($t)]);
  429. //$t = $x[$k] = $x[$k] ^ chr($s[ord($t)]);
  430. }
  431. $t = chr(ord($t) + $j);
  432. }
  433. }
  434. // Step 5. Output
  435. return substr($x, 0, 16);
  436. }
  437. /**
  438. * Pure-PHP implementation of SHA256
  439. *
  440. * See {@link http://en.wikipedia.org/wiki/SHA_hash_functions#SHA-256_.28a_SHA-2_variant.29_pseudocode SHA-256 (a SHA-2 variant) pseudocode - Wikipedia}.
  441. *
  442. * @access private
  443. * @param String $text
  444. */
  445. private function _sha256($m)
  446. {
  447. if (extension_loaded('suhosin')) {
  448. return pack('H*', sha256($m));
  449. }
  450. // Initialize variables
  451. $hash = array(
  452. 0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a, 0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19
  453. );
  454. // Initialize table of round constants
  455. // (first 32 bits of the fractional parts of the cube roots of the first 64 primes 2..311)
  456. static $k = array(
  457. 0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5,
  458. 0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174,
  459. 0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da,
  460. 0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967,
  461. 0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85,
  462. 0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070,
  463. 0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3,
  464. 0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2
  465. );
  466. // Pre-processing
  467. $length = strlen($m);
  468. // to round to nearest 56 mod 64, we'll add 64 - (length + (64 - 56)) % 64
  469. $m.= str_repeat(chr(0), 64 - (($length + 8) & 0x3F));
  470. $m[$length] = chr(0x80);
  471. // we don't support hashing strings 512MB long
  472. $m.= pack('N2', 0, $length << 3);
  473. // Process the message in successive 512-bit chunks
  474. $chunks = str_split($m, 64);
  475. foreach ($chunks as $chunk) {
  476. $w = array();
  477. for ($i = 0; $i < 16; $i++) {
  478. extract(unpack('Ntemp', $this->_string_shift($chunk, 4)));
  479. $w[] = $temp;
  480. }
  481. // Extend the sixteen 32-bit words into sixty-four 32-bit words
  482. for ($i = 16; $i < 64; $i++) {
  483. $s0 = $this->_rightRotate($w[$i - 15], 7) ^
  484. $this->_rightRotate($w[$i - 15], 18) ^
  485. $this->_rightShift( $w[$i - 15], 3);
  486. $s1 = $this->_rightRotate($w[$i - 2], 17) ^
  487. $this->_rightRotate($w[$i - 2], 19) ^
  488. $this->_rightShift( $w[$i - 2], 10);
  489. $w[$i] = $this->_add($w[$i - 16], $s0, $w[$i - 7], $s1);
  490. }
  491. // Initialize hash value for this chunk
  492. list($a, $b, $c, $d, $e, $f, $g, $h) = $hash;
  493. // Main loop
  494. for ($i = 0; $i < 64; $i++) {
  495. $s0 = $this->_rightRotate($a, 2) ^
  496. $this->_rightRotate($a, 13) ^
  497. $this->_rightRotate($a, 22);
  498. $maj = ($a & $b) ^
  499. ($a & $c) ^
  500. ($b & $c);
  501. $t2 = $this->_add($s0, $maj);
  502. $s1 = $this->_rightRotate($e, 6) ^
  503. $this->_rightRotate($e, 11) ^
  504. $this->_rightRotate($e, 25);
  505. $ch = ($e & $f) ^
  506. ($this->_not($e) & $g);
  507. $t1 = $this->_add($h, $s1, $ch, $k[$i], $w[$i]);
  508. $h = $g;
  509. $g = $f;
  510. $f = $e;
  511. $e = $this->_add($d, $t1);
  512. $d = $c;
  513. $c = $b;
  514. $b = $a;
  515. $a = $this->_add($t1, $t2);
  516. }
  517. // Add this chunk's hash to result so far
  518. $hash = array(
  519. $this->_add($hash[0], $a),
  520. $this->_add($hash[1], $b),
  521. $this->_add($hash[2], $c),
  522. $this->_add($hash[3], $d),
  523. $this->_add($hash[4], $e),
  524. $this->_add($hash[5], $f),
  525. $this->_add($hash[6], $g),
  526. $this->_add($hash[7], $h)
  527. );
  528. }
  529. // Produce the final hash value (big-endian)
  530. return pack('N8', $hash[0], $hash[1], $hash[2], $hash[3], $hash[4], $hash[5], $hash[6], $hash[7]);
  531. }
  532. /**
  533. * Pure-PHP implementation of SHA384 and SHA512
  534. *
  535. * @access private
  536. * @param String $text
  537. */
  538. private function _sha512($m)
  539. {
  540. if (!class_exists('Math_BigInteger')) {
  541. require_once('Math/BigInteger.php');
  542. }
  543. static $init384, $init512, $k;
  544. if (!isset($k)) {
  545. // Initialize variables
  546. $init384 = array( // initial values for SHA384
  547. 'cbbb9d5dc1059ed8', '629a292a367cd507', '9159015a3070dd17', '152fecd8f70e5939',
  548. '67332667ffc00b31', '8eb44a8768581511', 'db0c2e0d64f98fa7', '47b5481dbefa4fa4'
  549. );
  550. $init512 = array( // initial values for SHA512
  551. '6a09e667f3bcc908', 'bb67ae8584caa73b', '3c6ef372fe94f82b', 'a54ff53a5f1d36f1',
  552. '510e527fade682d1', '9b05688c2b3e6c1f', '1f83d9abfb41bd6b', '5be0cd19137e2179'
  553. );
  554. for ($i = 0; $i < 8; $i++) {
  555. $init384[$i] = new Math_BigInteger($init384[$i], 16);
  556. $init384[$i]->setPrecision(64);
  557. $init512[$i] = new Math_BigInteger($init512[$i], 16);
  558. $init512[$i]->setPrecision(64);
  559. }
  560. // Initialize table of round constants
  561. // (first 64 bits of the fractional parts of the cube roots of the first 80 primes 2..409)
  562. $k = array(
  563. '428a2f98d728ae22', '7137449123ef65cd', 'b5c0fbcfec4d3b2f', 'e9b5dba58189dbbc',
  564. '3956c25bf348b538', '59f111f1b605d019', '923f82a4af194f9b', 'ab1c5ed5da6d8118',
  565. 'd807aa98a3030242', '12835b0145706fbe', '243185be4ee4b28c', '550c7dc3d5ffb4e2',
  566. '72be5d74f27b896f', '80deb1fe3b1696b1', '9bdc06a725c71235', 'c19bf174cf692694',
  567. 'e49b69c19ef14ad2', 'efbe4786384f25e3', '0fc19dc68b8cd5b5', '240ca1cc77ac9c65',
  568. '2de92c6f592b0275', '4a7484aa6ea6e483', '5cb0a9dcbd41fbd4', '76f988da831153b5',
  569. '983e5152ee66dfab', 'a831c66d2db43210', 'b00327c898fb213f', 'bf597fc7beef0ee4',
  570. 'c6e00bf33da88fc2', 'd5a79147930aa725', '06ca6351e003826f', '142929670a0e6e70',
  571. '27b70a8546d22ffc', '2e1b21385c26c926', '4d2c6dfc5ac42aed', '53380d139d95b3df',
  572. '650a73548baf63de', '766a0abb3c77b2a8', '81c2c92e47edaee6', '92722c851482353b',
  573. 'a2bfe8a14cf10364', 'a81a664bbc423001', 'c24b8b70d0f89791', 'c76c51a30654be30',
  574. 'd192e819d6ef5218', 'd69906245565a910', 'f40e35855771202a', '106aa07032bbd1b8',
  575. '19a4c116b8d2d0c8', '1e376c085141ab53', '2748774cdf8eeb99', '34b0bcb5e19b48a8',
  576. '391c0cb3c5c95a63', '4ed8aa4ae3418acb', '5b9cca4f7763e373', '682e6ff3d6b2b8a3',
  577. '748f82ee5defb2fc', '78a5636f43172f60', '84c87814a1f0ab72', '8cc702081a6439ec',
  578. '90befffa23631e28', 'a4506cebde82bde9', 'bef9a3f7b2c67915', 'c67178f2e372532b',
  579. 'ca273eceea26619c', 'd186b8c721c0c207', 'eada7dd6cde0eb1e', 'f57d4f7fee6ed178',
  580. '06f067aa72176fba', '0a637dc5a2c898a6', '113f9804bef90dae', '1b710b35131c471b',
  581. '28db77f523047d84', '32caab7b40c72493', '3c9ebe0a15c9bebc', '431d67c49c100d4c',
  582. '4cc5d4becb3e42b6', '597f299cfc657e2a', '5fcb6fab3ad6faec', '6c44198c4a475817'
  583. );
  584. for ($i = 0; $i < 80; $i++) {
  585. $k[$i] = new Math_BigInteger($k[$i], 16);
  586. }
  587. }
  588. $hash = $this->l == 48 ? $init384 : $init512;
  589. // Pre-processing
  590. $length = strlen($m);
  591. // to round to nearest 112 mod 128, we'll add 128 - (length + (128 - 112)) % 128
  592. $m.= str_repeat(chr(0), 128 - (($length + 16) & 0x7F));
  593. $m[$length] = chr(0x80);
  594. // we don't support hashing strings 512MB long
  595. $m.= pack('N4', 0, 0, 0, $length << 3);
  596. // Process the message in successive 1024-bit chunks
  597. $chunks = str_split($m, 128);
  598. foreach ($chunks as $chunk) {
  599. $w = array();
  600. for ($i = 0; $i < 16; $i++) {
  601. $temp = new Math_BigInteger($this->_string_shift($chunk, 8), 256);
  602. $temp->setPrecision(64);
  603. $w[] = $temp;
  604. }
  605. // Extend the sixteen 32-bit words into eighty 32-bit words
  606. for ($i = 16; $i < 80; $i++) {
  607. $temp = array(
  608. $w[$i - 15]->bitwise_rightRotate(1),
  609. $w[$i - 15]->bitwise_rightRotate(8),
  610. $w[$i - 15]->bitwise_rightShift(7)
  611. );
  612. $s0 = $temp[0]->bitwise_xor($temp[1]);
  613. $s0 = $s0->bitwise_xor($temp[2]);
  614. $temp = array(
  615. $w[$i - 2]->bitwise_rightRotate(19),
  616. $w[$i - 2]->bitwise_rightRotate(61),
  617. $w[$i - 2]->bitwise_rightShift(6)
  618. );
  619. $s1 = $temp[0]->bitwise_xor($temp[1]);
  620. $s1 = $s1->bitwise_xor($temp[2]);
  621. $w[$i] = $w[$i - 16]->copy();
  622. $w[$i] = $w[$i]->add($s0);
  623. $w[$i] = $w[$i]->add($w[$i - 7]);
  624. $w[$i] = $w[$i]->add($s1);
  625. }
  626. // Initialize hash value for this chunk
  627. $a = $hash[0]->copy();
  628. $b = $hash[1]->copy();
  629. $c = $hash[2]->copy();
  630. $d = $hash[3]->copy();
  631. $e = $hash[4]->copy();
  632. $f = $hash[5]->copy();
  633. $g = $hash[6]->copy();
  634. $h = $hash[7]->copy();
  635. // Main loop
  636. for ($i = 0; $i < 80; $i++) {
  637. $temp = array(
  638. $a->bitwise_rightRotate(28),
  639. $a->bitwise_rightRotate(34),
  640. $a->bitwise_rightRotate(39)
  641. );
  642. $s0 = $temp[0]->bitwise_xor($temp[1]);
  643. $s0 = $s0->bitwise_xor($temp[2]);
  644. $temp = array(
  645. $a->bitwise_and($b),
  646. $a->bitwise_and($c),
  647. $b->bitwise_and($c)
  648. );
  649. $maj = $temp[0]->bitwise_xor($temp[1]);
  650. $maj = $maj->bitwise_xor($temp[2]);
  651. $t2 = $s0->add($maj);
  652. $temp = array(
  653. $e->bitwise_rightRotate(14),
  654. $e->bitwise_rightRotate(18),
  655. $e->bitwise_rightRotate(41)
  656. );
  657. $s1 = $temp[0]->bitwise_xor($temp[1]);
  658. $s1 = $s1->bitwise_xor($temp[2]);
  659. $temp = array(
  660. $e->bitwise_and($f),
  661. $g->bitwise_and($e->bitwise_not())
  662. );
  663. $ch = $temp[0]->bitwise_xor($temp[1]);
  664. $t1 = $h->add($s1);
  665. $t1 = $t1->add($ch);
  666. $t1 = $t1->add($k[$i]);
  667. $t1 = $t1->add($w[$i]);
  668. $h = $g->copy();
  669. $g = $f->copy();
  670. $f = $e->copy();
  671. $e = $d->add($t1);
  672. $d = $c->copy();
  673. $c = $b->copy();
  674. $b = $a->copy();
  675. $a = $t1->add($t2);
  676. }
  677. // Add this chunk's hash to result so far
  678. $hash = array(
  679. $hash[0]->add($a),
  680. $hash[1]->add($b),
  681. $hash[2]->add($c),
  682. $hash[3]->add($d),
  683. $hash[4]->add($e),
  684. $hash[5]->add($f),
  685. $hash[6]->add($g),
  686. $hash[7]->add($h)
  687. );
  688. }
  689. // Produce the final hash value (big-endian)
  690. // (Crypt_Hash::hash() trims the output for hashes but not for HMACs. as such, we trim the output here)
  691. $temp = $hash[0]->toBytes() . $hash[1]->toBytes() . $hash[2]->toBytes() . $hash[3]->toBytes() .
  692. $hash[4]->toBytes() . $hash[5]->toBytes();
  693. if ($this->l != 48) {
  694. $temp.= $hash[6]->toBytes() . $hash[7]->toBytes();
  695. }
  696. return $temp;
  697. }
  698. /**
  699. * Right Rotate
  700. *
  701. * @access private
  702. * @param Integer $int
  703. * @param Integer $amt
  704. * @see _sha256()
  705. * @return Integer
  706. */
  707. private function _rightRotate($int, $amt)
  708. {
  709. $invamt = 32 - $amt;
  710. $mask = (1 << $invamt) - 1;
  711. return (($int << $invamt) & 0xFFFFFFFF) | (($int >> $amt) & $mask);
  712. }
  713. /**
  714. * Right Shift
  715. *
  716. * @access private
  717. * @param Integer $int
  718. * @param Integer $amt
  719. * @see _sha256()
  720. * @return Integer
  721. */
  722. private function _rightShift($int, $amt)
  723. {
  724. $mask = (1 << (32 - $amt)) - 1;
  725. return ($int >> $amt) & $mask;
  726. }
  727. /**
  728. * Not
  729. *
  730. * @access private
  731. * @param Integer $int
  732. * @see _sha256()
  733. * @return Integer
  734. */
  735. private function _not($int)
  736. {
  737. return ~$int & 0xFFFFFFFF;
  738. }
  739. /**
  740. * Add
  741. *
  742. * _sha256() adds multiple unsigned 32-bit integers. Since PHP doesn't support unsigned integers and since the
  743. * possibility of overflow exists, care has to be taken. Math_BigInteger() could be used but this should be faster.
  744. *
  745. * @param String $string
  746. * @param optional Integer $index
  747. * @return String
  748. * @see _sha256()
  749. * @access private
  750. */
  751. private function _add()
  752. {
  753. static $mod;
  754. if (!isset($mod)) {
  755. $mod = pow(2, 32);
  756. }
  757. $result = 0;
  758. $arguments = func_get_args();
  759. foreach ($arguments as $argument) {
  760. $result+= $argument < 0 ? ($argument & 0x7FFFFFFF) + 0x80000000 : $argument;
  761. }
  762. return fmod($result, $mod);
  763. }
  764. /**
  765. * String Shift
  766. *
  767. * Inspired by array_shift
  768. *
  769. * @param String $string
  770. * @param optional Integer $index
  771. * @return String
  772. * @access private
  773. */
  774. private function _string_shift(&$string, $index = 1)
  775. {
  776. $substr = substr($string, 0, $index);
  777. $string = substr($string, $index);
  778. return $substr;
  779. }
  780. }