Skip to main content

Module blake2s

Module blake2s 

Source
Expand description

BLAKE2s hash function circuit.

BLAKE2s is a cryptographic hash function optimized for 32-bit platforms.

It produces digests from 1 to 32 bytes.

This implementation follows RFC 7693.

It supports fixed-length messages with unkeyed hashing.

§RFC 7693 compliance

This implementation is fully compliant with RFC 7693 for the core BLAKE2s-256 hash function.

The compression function, the G mixing function, and the message scheduling all match the specification.

§Excluded features

This circuit intentionally excludes the following optional features from RFC 7693:

  • Keyed hashing, also called MAC mode: only unkeyed hash verification is supported.
  • The 8-byte salt field.
  • The 8-byte personalization field.
  • Tree hashing mode: only sequential mode is supported.
  • Runtime-variable message length: the length is fixed at circuit construction time instead.
  • Variable output length: the digest is fixed at 256 bits.
  • Messages of 4 GiB or more.

The high half of the byte counter is always the zero constant, which caps the supported message length at just under 4 GiB.

These exclusions suit a circuit whose job is hash verification, rather than general-purpose hashing.

§Algorithm overview

BLAKE2s processes a message in 64-byte blocks.

Each block goes through a compression function built from a modified ChaCha cipher core.

A compression runs ten mixing rounds, and each round mixes the internal state with the message block through eight calls to the G mixing function.

§Circuit design

This circuit verifies that a message of a fixed, compile-time-known length produces a specific BLAKE2s digest.

Blocks chain sequentially: each one’s input state is the previous one’s output.

So consecutive blocks are compressed two at a time, packing both compressions into the two 32-bit lanes of one parallel core.

A trailing block with no partner runs through the same paired core with its second lane left dead, except when the whole message is a single block, which stays fully single-lane.

Structs§

Blake2s
BLAKE2s hash function circuit for a fixed-length message.
Blake2sCompress2x
The two-lane compression above, in a form a circuit can register as a chip.

Functions§

blake2s_compress
BLAKE2s compression function.
blake2s_compress_2x
BLAKE2s compression function running two independent compressions in parallel.
blake2s_compress_2x_seq
Two sequential BLAKE2s block compressions, evaluated in one parallel core.
ref_compress
Pure-Rust BLAKE2s compression of a single 64-byte block.