* PBKDF2_SHA256(passwd, passwdlen, salt, saltlen, c, buf, dkLen): * Compute PBKDF2(passwd, salt, c, dkLen) using HMAC-SHA256 as the PRF, and * write the output to buf. The value dkLen must be at most 32 * (2^32 - 1). */
| 121 | * write the output to buf. The value dkLen must be at most 32 * (2^32 - 1). |
| 122 | */ |
| 123 | void |
| 124 | PBKDF2_SHA256(const uint8_t *passwd, size_t passwdlen, const uint8_t *salt, |
| 125 | size_t saltlen, uint64_t c, uint8_t *buf, size_t dkLen) |
| 126 | { |
| 127 | HMAC_SHA256_CTX PShctx, hctx; |
| 128 | size_t i; |
| 129 | uint8_t ivec[4]; |
| 130 | uint8_t U[32]; |
| 131 | uint8_t T[32]; |
| 132 | uint64_t j; |
| 133 | int k; |
| 134 | size_t clen; |
| 135 | |
| 136 | /* Compute HMAC state after processing P and S. */ |
| 137 | HMAC_SHA256_Init(&PShctx, passwd, passwdlen); |
| 138 | HMAC_SHA256_Update(&PShctx, salt, saltlen); |
| 139 | |
| 140 | /* Iterate through the blocks. */ |
| 141 | for (i = 0; i * 32 < dkLen; i++) { |
| 142 | /* Generate INT(i + 1). */ |
| 143 | be32enc(ivec, (uint32_t)(i + 1)); |
| 144 | |
| 145 | /* Compute U_1 = PRF(P, S || INT(i)). */ |
| 146 | memcpy(&hctx, &PShctx, sizeof(HMAC_SHA256_CTX)); |
| 147 | HMAC_SHA256_Update(&hctx, ivec, 4); |
| 148 | HMAC_SHA256_Final(U, &hctx); |
| 149 | |
| 150 | /* T_i = U_1 ... */ |
| 151 | memcpy(T, U, 32); |
| 152 | |
| 153 | for (j = 2; j <= c; j++) { |
| 154 | /* Compute U_j. */ |
| 155 | HMAC_SHA256_Init(&hctx, passwd, passwdlen); |
| 156 | HMAC_SHA256_Update(&hctx, U, 32); |
| 157 | HMAC_SHA256_Final(U, &hctx); |
| 158 | |
| 159 | /* ... xor U_j ... */ |
| 160 | for (k = 0; k < 32; k++) |
| 161 | T[k] ^= U[k]; |
| 162 | } |
| 163 | |
| 164 | /* Copy as many bytes as necessary into buf. */ |
| 165 | clen = dkLen - i * 32; |
| 166 | if (clen > 32) |
| 167 | clen = 32; |
| 168 | memcpy(&buf[i * 32], T, clen); |
| 169 | } |
| 170 | |
| 171 | /* Clean PShctx, since we never called _Final on it. */ |
| 172 | memset(&PShctx, 0, sizeof(HMAC_SHA256_CTX)); |
| 173 | } |
| 174 | |
| 175 | static inline uint32_t |
| 176 | le32dec_2(const void * pp) |
no test coverage detected