1 // GoGOST -- Pure Go GOST cryptographic functions library
2 // Copyright (C) 2015-2019 Sergey Matveev <stargrave@stargrave.org>
4 // This program is free software: you can redistribute it and/or modify
5 // it under the terms of the GNU General Public License as published by
6 // the Free Software Foundation, either version 3 of the License, or
7 // (at your option) any later version.
9 // This program is distributed in the hope that it will be useful,
10 // but WITHOUT ANY WARRANTY; without even the implied warranty of
11 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 // GNU General Public License for more details.
14 // You should have received a copy of the GNU General Public License
15 // along with this program. If not, see <http://www.gnu.org/licenses/>.
25 0, 1, 2, 3, 4, 5, 6, 7,
26 0, 1, 2, 3, 4, 5, 6, 7,
40 // Create MAC with given tag size and initial initialization vector.
41 // Size is in bytes and must be between 1 and 8. To be RFC conformant,
42 // iv must be the first block of the authenticated data, second and
43 // following ones are fed to Write function.
44 func (c *Cipher) NewMAC(size int, iv [BlockSize]byte) (*MAC, error) {
45 if size == 0 || size > 8 {
46 return nil, errors.New("Invalid tag size")
48 m := MAC{c: c, size: size, iv: iv[:]}
49 n2, n1 := block2nvs(iv[:])
50 m.iv = make([]byte, BlockSize)
51 nvs2block(n1, n2, m.iv)
52 m.prev = make([]byte, BlockSize)
57 func (m *MAC) Reset() {
62 func (m *MAC) BlockSize() int {
66 func (m *MAC) Size() int {
70 func (m *MAC) Write(b []byte) (int, error) {
71 m.buf = append(m.buf, b...)
72 for len(m.buf) >= BlockSize {
73 for i := 0; i < BlockSize; i++ {
76 m.n1, m.n2 = block2nvs(m.prev)
77 m.n1, m.n2 = m.c.xcrypt(SeqMAC, m.n1, m.n2)
78 nvs2block(m.n2, m.n1, m.prev)
84 func (m *MAC) Sum(b []byte) []byte {
86 return append(b, m.prev[0:m.size]...)
90 for i = 0; i < BlockSize-len(m.buf); i++ {
91 buf = append(buf, byte(0))
93 for i = 0; i < BlockSize; i++ {
96 m.n1, m.n2 = block2nvs(buf)
97 m.n1, m.n2 = m.c.xcrypt(SeqMAC, m.n1, m.n2)
98 nvs2block(m.n2, m.n1, buf)
99 return append(b, buf[0:m.size]...)