dryoc/classic/
crypto_auth_hmacsha512256.rs1use crate::classic::crypto_auth_hmac_impl::hmac_keygen;
45use crate::classic::crypto_auth_hmacsha512::{
46 HmacSha512State, crypto_auth_hmacsha512_final, crypto_auth_hmacsha512_init,
47 crypto_auth_hmacsha512_update,
48};
49use crate::constants::{
50 CRYPTO_AUTH_HMACSHA512_BYTES, CRYPTO_AUTH_HMACSHA512256_BYTES,
51 CRYPTO_AUTH_HMACSHA512256_KEYBYTES,
52};
53use crate::error::Error;
54use crate::utils::{verify_ct, zeroize_bytes};
55
56pub type Key = [u8; CRYPTO_AUTH_HMACSHA512256_KEYBYTES];
58pub type Mac = [u8; CRYPTO_AUTH_HMACSHA512256_BYTES];
60pub type HmacSha512256State = HmacSha512State;
62
63pub fn crypto_auth_hmacsha512256(mac: &mut Mac, message: &[u8], key: &Key) {
65 let mut state = crypto_auth_hmacsha512256_init(key);
66 crypto_auth_hmacsha512256_update(&mut state, message);
67 crypto_auth_hmacsha512256_final(state, mac);
68}
69
70pub fn crypto_auth_hmacsha512256_verify(mac: &Mac, input: &[u8], key: &Key) -> Result<(), Error> {
76 let mut computed_mac = Mac::default();
77 crypto_auth_hmacsha512256(&mut computed_mac, input, key);
78 let result = verify_ct(mac, &computed_mac);
79 zeroize_bytes(&mut computed_mac);
80 result
81}
82
83#[must_use]
85pub fn crypto_auth_hmacsha512256_keygen() -> Key {
86 hmac_keygen()
87}
88
89#[must_use]
91pub fn crypto_auth_hmacsha512256_init(key: &[u8]) -> HmacSha512256State {
92 crypto_auth_hmacsha512_init(key)
93}
94
95pub fn crypto_auth_hmacsha512256_update(state: &mut HmacSha512256State, input: &[u8]) {
97 crypto_auth_hmacsha512_update(state, input);
98}
99
100pub fn crypto_auth_hmacsha512256_final(state: HmacSha512256State, output: &mut Mac) {
102 let mut full_output = [0u8; CRYPTO_AUTH_HMACSHA512_BYTES];
103 crypto_auth_hmacsha512_final(state, &mut full_output);
104 output.copy_from_slice(&full_output[..CRYPTO_AUTH_HMACSHA512256_BYTES]);
105 zeroize_bytes(&mut full_output);
106}
107
108#[cfg(test)]
109mod tests {
110 use super::*;
111 use crate::classic::crypto_auth_hmac_impl::test_util::hmac_classic_tests;
112
113 hmac_classic_tests! {
114 hash: sha2::Sha512,
115 block: 128,
116 bytes: CRYPTO_AUTH_HMACSHA512256_BYTES,
117 keybytes: CRYPTO_AUTH_HMACSHA512256_KEYBYTES,
118 tag: sha512256,
119 chunk: 31,
120 one_shot: crypto_auth_hmacsha512256,
121 verify: crypto_auth_hmacsha512256_verify,
122 keygen: crypto_auth_hmacsha512256_keygen,
123 init: crypto_auth_hmacsha512256_init,
124 update: crypto_auth_hmacsha512256_update,
125 finalize: crypto_auth_hmacsha512256_final,
126 sodium_one_shot: auth_hmacsha512256,
127 sodium_state: AuthHmacSha512256State,
128 keybytes_test: test_one_shot_matches_incremental_for_keybytes_key(b"message"),
129 rfc4231: {
130 test_rfc4231_case_1_truncated => RFC4231_CASE_1,
131 test_rfc4231_short_key_case_2_truncated => RFC4231_CASE_2,
132 test_rfc4231_long_key_case_6_truncated => RFC4231_CASE_6,
133 test_rfc4231_long_key_and_message_case_7_truncated => RFC4231_CASE_7,
134 },
135 }
136}