| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | =pod | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | =head1 NAME | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | EVP_MD-SHAKE, EVP_MD-KECCAK-KMAC | 
					
						
							|  |  |  | - The SHAKE / KECCAK family EVP_MD implementations | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | =head1 DESCRIPTION | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | Support for computing SHAKE or KECCAK-KMAC digests through the | 
					
						
							|  |  |  | B<EVP_MD> API. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-11-14 03:28:23 +08:00
										 |  |  | KECCAK-KMAC is an Extendable Output Function (XOF), with a definition | 
					
						
							|  |  |  | similar to SHAKE, used by the KMAC EVP_MAC implementation (see | 
					
						
							|  |  |  | L<EVP_MAC-KMAC(7)>). | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =head2 Identities | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-06-22 13:21:13 +08:00
										 |  |  | This implementation is available in the FIPS provider as well as the default | 
					
						
							|  |  |  | provider, and includes the following varieties: | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =over 4 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | =item KECCAK-KMAC-128 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-11-14 03:28:23 +08:00
										 |  |  | Known names are "KECCAK-KMAC-128" and "KECCAK-KMAC128".  This is used | 
					
						
							|  |  |  | by L<EVP_MAC-KMAC128(7)>.  Using the notation from NIST FIPS 202 | 
					
						
							| 
									
										
										
										
											2023-11-25 01:37:36 +08:00
										 |  |  | (Section 6.2), we have S<KECCAK-KMAC-128(M, d)> = S<KECCAK[256](M || 00, d)> | 
					
						
							| 
									
										
										
										
											2023-11-14 03:28:23 +08:00
										 |  |  | (see the description of KMAC128 in Appendix A of NIST SP 800-185). | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =item KECCAK-KMAC-256 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-11-14 03:28:23 +08:00
										 |  |  | Known names are "KECCAK-KMAC-256" and "KECCAK-KMAC256".  This is used | 
					
						
							|  |  |  | by L<EVP_MAC-KMAC256(7)>.  Using the notation from NIST FIPS 202 | 
					
						
							| 
									
										
										
										
											2023-11-25 01:37:36 +08:00
										 |  |  | (Section 6.2), we have S<KECCAK-KMAC-256(M, d)> = S<KECCAK[512](M || 00, d)> | 
					
						
							| 
									
										
										
										
											2023-11-14 03:28:23 +08:00
										 |  |  | (see the description of KMAC256 in Appendix A of NIST SP 800-185). | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =item SHAKE-128 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-11-14 03:28:23 +08:00
										 |  |  | Known names are "SHAKE-128" and "SHAKE128". | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =item SHAKE-256 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-11-14 03:28:23 +08:00
										 |  |  | Known names are "SHAKE-256" and "SHAKE256". | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =back | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-08-26 07:38:56 +08:00
										 |  |  | =head2 Parameters | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-08-26 07:38:56 +08:00
										 |  |  | This implementation supports the following L<OSSL_PARAM(3)> entries: | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =over 4 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | =item "xoflen" (B<OSSL_DIGEST_PARAM_XOFLEN>) <unsigned integer> | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-08-26 07:38:56 +08:00
										 |  |  | Sets or Gets the digest length for extendable output functions. | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | The length of the "xoflen" parameter should not exceed that of a B<size_t>. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-04-25 00:42:39 +08:00
										 |  |  | The SHAKE-128 and SHAKE-256 implementations do not have any default digest | 
					
						
							|  |  |  | length. | 
					
						
							| 
									
										
										
										
											2022-06-22 13:21:13 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-04-25 00:42:39 +08:00
										 |  |  | This parameter must be set before calling either EVP_DigestFinal_ex() or | 
					
						
							| 
									
										
										
										
											2023-07-21 13:05:38 +08:00
										 |  |  | EVP_DigestFinal(), since these functions were not designed to handle variable | 
					
						
							|  |  |  | length output. It is recommended to either use EVP_DigestSqueeze() or | 
					
						
							|  |  |  | EVP_DigestFinalXOF() instead. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-08-26 07:38:56 +08:00
										 |  |  | =item "size" (B<OSSL_DIGEST_PARAM_SIZE>) <unsigned integer> | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | An alias of "xoflen". | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | =back | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-08-26 07:38:56 +08:00
										 |  |  | See L<EVP_DigestInit(3)/PARAMETERS> for further information related to parameters | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-07-21 13:05:38 +08:00
										 |  |  | =head1 NOTES | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | For SHAKE-128, to ensure the maximum security strength of 128 bits, the output | 
					
						
							|  |  |  | length passed to EVP_DigestFinalXOF() should be at least 32. | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | For SHAKE-256, to ensure the maximum security strength of 256 bits, the output | 
					
						
							|  |  |  | length passed to EVP_DigestFinalXOF() should be at least 64. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | =head1 SEE ALSO | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | L<EVP_MD_CTX_set_params(3)>, L<provider-digest(7)>, L<OSSL_PROVIDER-default(7)> | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-04-25 00:42:39 +08:00
										 |  |  | =head1 HISTORY | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | Since OpenSSL 3.4 the SHAKE-128 and SHAKE-256 implementations have no default | 
					
						
							|  |  |  | digest length. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | =head1 COPYRIGHT | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-09-05 15:35:49 +08:00
										 |  |  | Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. | 
					
						
							| 
									
										
										
										
											2020-03-06 21:29:00 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | Licensed under the Apache License 2.0 (the "License").  You may not use | 
					
						
							|  |  |  | this file except in compliance with the License.  You can obtain a copy | 
					
						
							|  |  |  | in the file LICENSE in the source distribution or at | 
					
						
							|  |  |  | L<https://www.openssl.org/source/license.html>. | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | =cut |