Expand description
BLAKE2s hash function circuit.
BLAKE2s is a cryptographic hash function optimized for 32-bit platforms.
It produces digests from 1 to 32 bytes.
This implementation follows RFC 7693.
It supports fixed-length messages with unkeyed hashing.
§RFC 7693 compliance
This implementation is fully compliant with RFC 7693 for the core BLAKE2s-256 hash function.
The compression function, the G mixing function, and the message scheduling all match the specification.
§Excluded features
This circuit intentionally excludes the following optional features from RFC 7693:
- Keyed hashing, also called MAC mode: only unkeyed hash verification is supported.
- The 8-byte salt field.
- The 8-byte personalization field.
- Tree hashing mode: only sequential mode is supported.
- Runtime-variable message length: the length is fixed at circuit construction time instead.
- Variable output length: the digest is fixed at 256 bits.
- Messages of 4 GiB or more.
The high half of the byte counter is always the zero constant, which caps the supported message length at just under 4 GiB.
These exclusions suit a circuit whose job is hash verification, rather than general-purpose hashing.
§Algorithm overview
BLAKE2s processes a message in 64-byte blocks.
Each block goes through a compression function built from a modified ChaCha cipher core.
A compression runs ten mixing rounds, and each round mixes the internal state with the message block through eight calls to the G mixing function.
§Circuit design
This circuit verifies that a message of a fixed, compile-time-known length produces a specific BLAKE2s digest.
Blocks chain sequentially: each one’s input state is the previous one’s output.
So consecutive blocks are compressed two at a time, packing both compressions into the two 32-bit lanes of one parallel core.
A trailing block with no partner runs through the same paired core with its second lane left dead, except when the whole message is a single block, which stays fully single-lane.
Structs§
- Blake2s
- BLAKE2s hash function circuit for a fixed-length message.
- Blake2s
Compress2x - The two-lane compression above, in a form a circuit can register as a chip.
Functions§
- blake2s_
compress - BLAKE2s compression function.
- blake2s_
compress_ 2x - BLAKE2s compression function running two independent compressions in parallel.
- blake2s_
compress_ 2x_ seq - Two sequential BLAKE2s block compressions, evaluated in one parallel core.
- ref_
compress - Pure-Rust BLAKE2s compression of a single 64-byte block.