You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

112 lines
2.7 KiB

  1. // signal input hin[256];
  2. // signal input inp[512];
  3. // signal output out[256];
  4. pragma circom 2.0.0;
  5. function rrot(x, n) {
  6. return ((x >> n) | (x << (32-n))) & 0xFFFFFFFF;
  7. }
  8. function bsigma0(x) {
  9. return rrot(x,2) ^ rrot(x,13) ^ rrot(x,22);
  10. }
  11. function bsigma1(x) {
  12. return rrot(x,6) ^ rrot(x,11) ^ rrot(x,25);
  13. }
  14. function ssigma0(x) {
  15. return rrot(x,7) ^ rrot(x,18) ^ (x >> 3);
  16. }
  17. function ssigma1(x) {
  18. return rrot(x,17) ^ rrot(x,19) ^ (x >> 10);
  19. }
  20. function Maj(x, y, z) {
  21. return (x&y) ^ (x&z) ^ (y&z);
  22. }
  23. function Ch(x, y, z) {
  24. return (x & y) ^ ((0xFFFFFFFF ^x) & z);
  25. }
  26. function sha256K(i) {
  27. var k[64] = [
  28. 0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5,
  29. 0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174,
  30. 0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da,
  31. 0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967,
  32. 0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85,
  33. 0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070,
  34. 0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3,
  35. 0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2
  36. ];
  37. return k[i];
  38. }
  39. function sha256compression(hin, inp) {
  40. var H[8];
  41. var a;
  42. var b;
  43. var c;
  44. var d;
  45. var e;
  46. var f;
  47. var g;
  48. var h;
  49. var out[256];
  50. for (var i=0; i<8; i++) {
  51. H[i] = 0;
  52. for (var j=0; j<32; j++) {
  53. H[i] += hin[i*32+j] << j;
  54. }
  55. }
  56. a=H[0];
  57. b=H[1];
  58. c=H[2];
  59. d=H[3];
  60. e=H[4];
  61. f=H[5];
  62. g=H[6];
  63. h=H[7];
  64. var w[64];
  65. var T1;
  66. var T2;
  67. for (var i=0; i<64; i++) {
  68. if (i<16) {
  69. w[i]=0;
  70. for (var j=0; j<32; j++) {
  71. w[i] += inp[i*32+31-j]<<j;
  72. }
  73. } else {
  74. w[i] = (ssigma1(w[i-2]) + w[i-7] + ssigma0(w[i-15]) + w[i-16]) & 0xFFFFFFFF;
  75. }
  76. T1 = (h + bsigma1(e) + Ch(e,f,g) + sha256K(i) + w[i]) & 0xFFFFFFFF;
  77. T2 = (bsigma0(a) + Maj(a,b,c)) & 0xFFFFFFFF;
  78. h=g;
  79. g=f;
  80. f=e;
  81. e=(d+T1) & 0xFFFFFFFF;
  82. d=c;
  83. c=b;
  84. b=a;
  85. a=(T1+T2) & 0xFFFFFFFF;
  86. }
  87. H[0] = H[0] + a;
  88. H[1] = H[1] + b;
  89. H[2] = H[2] + c;
  90. H[3] = H[3] + d;
  91. H[4] = H[4] + e;
  92. H[5] = H[5] + f;
  93. H[6] = H[6] + g;
  94. H[7] = H[7] + h;
  95. for (var i=0; i<8; i++) {
  96. for (var j=0; j<32; j++) {
  97. out[i*32+31-j] = (H[i] >> j) & 1;
  98. }
  99. }
  100. return out;
  101. }