2 // HMAC.cs: Generic HMAC inplementation
5 // Sebastien Pouliot <sebastien@xamarin.com>
7 // (C) 2003 Motus Technologies Inc. (http://www.motus.com)
8 // Copyright (C) 2004-2005, 2007 Novell, Inc (http://www.novell.com)
9 // Copyright 2013 Xamarin Inc. (http://www.xamarin.com)
11 // Permission is hereby granted, free of charge, to any person obtaining
12 // a copy of this software and associated documentation files (the
13 // "Software"), to deal in the Software without restriction, including
14 // without limitation the rights to use, copy, modify, merge, publish,
15 // distribute, sublicense, and/or sell copies of the Software, and to
16 // permit persons to whom the Software is furnished to do so, subject to
17 // the following conditions:
19 // The above copyright notice and this permission notice shall be
20 // included in all copies or substantial portions of the Software.
22 // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
23 // EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
24 // MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
25 // NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
26 // LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
27 // OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
28 // WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
32 using System.Runtime.InteropServices;
33 using Mono.Security.Cryptography;
35 namespace System.Security.Cryptography {
37 // Mostly copied from (internal) Mono.Security.Cryptography.HMACAlgorithm
40 // a. FIPS PUB 198: The Keyed-Hash Message Authentication Code (HMAC), 2002 March.
41 // http://csrc.nist.gov/publications/fips/fips198/fips-198a.pdf
42 // b. Internet RFC 2104, HMAC, Keyed-Hashing for Message Authentication
43 // (include C source for HMAC-MD5)
44 // http://www.ietf.org/rfc/rfc2104.txt
45 // c. IETF RFC2202: Test Cases for HMAC-MD5 and HMAC-SHA-1
46 // (include C source for HMAC-MD5 and HAMAC-SHA1)
47 // http://www.ietf.org/rfc/rfc2202.txt
48 // d. ANSI X9.71, Keyed Hash Message Authentication Code.
50 // http://webstore.ansi.org/ansidocstore/product.asp?sku=ANSI+X9%2E71%2D2000
53 public abstract class HMAC : KeyedHashAlgorithm {
55 private bool _disposed;
56 private string _hashName;
57 private HashAlgorithm _algo;
58 private BlockProcessor _block;
59 private int _blockSizeValue;
71 protected int BlockSizeValue {
72 get { return _blockSizeValue; }
73 set { _blockSizeValue = value; }
76 public string HashName {
77 get { return _hashName; }
80 _algo = HashAlgorithm.Create (_hashName);
84 public override byte[] Key {
85 get { return (byte[]) base.Key.Clone (); }
87 if ((value != null) && (value.Length > BlockSizeValue))
88 base.Key = _algo.ComputeHash (value);
90 base.Key = (byte[]) value.Clone();
94 internal BlockProcessor Block {
97 _block = new BlockProcessor (_algo, (BlockSizeValue >> 3));
104 private byte[] KeySetup (byte[] key, byte padding)
106 byte[] buf = new byte [BlockSizeValue];
108 for (int i = 0; i < key.Length; ++i)
109 buf [i] = (byte) ((byte) key [i] ^ padding);
111 for (int i = key.Length; i < BlockSizeValue; ++i)
117 protected override void Dispose (bool disposing)
121 base.Dispose (disposing);
125 protected override void HashCore (byte[] rgb, int ib, int cb)
128 throw new ObjectDisposedException ("HMACSHA1");
134 Block.Core (rgb, ib, cb);
137 protected override byte[] HashFinal ()
140 throw new ObjectDisposedException ("HMAC");
144 byte[] intermediate = _algo.Hash;
146 byte[] buf = KeySetup (Key, 0x5C);
148 _algo.TransformBlock (buf, 0, buf.Length, buf, 0);
149 _algo.TransformFinalBlock (intermediate, 0, intermediate.Length);
150 byte[] hash = _algo.Hash;
152 // zeroize sensitive data
153 Array.Clear (buf, 0, buf.Length);
154 Array.Clear (intermediate, 0, intermediate.Length);
158 public override void Initialize ()
161 throw new ObjectDisposedException ("HMAC");
165 byte[] buf = KeySetup (Key, 0x36);
169 Array.Clear (buf, 0, buf.Length);
173 // Allow using HMAC without bringing (most of) the whole crypto stack (using CryptoConfig)
174 // or even without bringing all the hash algorithms (using a common switch)
175 internal void SetHash (string name, HashAlgorithm instance)
183 public static new HMAC Create ()
186 return new System.Security.Cryptography.HMACSHA1 ();
188 return Create ("System.Security.Cryptography.HMAC");
192 public static new HMAC Create (string algorithmName)
194 return (HMAC) CryptoConfig.CreateFromName (algorithmName);