2 * Author......: Jens Steube <jens.steube@gmail.com>
10 #include "inc_hash_constants.h"
11 #include "inc_vendor.cl"
18 #include "inc_hash_functions.cl"
19 #include "inc_types.cl"
20 #include "inc_common.cl"
21 #include "inc_simd.cl"
23 __constant u64 keccakf_rndc[24] =
25 0x0000000000000001, 0x0000000000008082, 0x800000000000808a,
26 0x8000000080008000, 0x000000000000808b, 0x0000000080000001,
27 0x8000000080008081, 0x8000000000008009, 0x000000000000008a,
28 0x0000000000000088, 0x0000000080008009, 0x000000008000000a,
29 0x000000008000808b, 0x800000000000008b, 0x8000000000008089,
30 0x8000000000008003, 0x8000000000008002, 0x8000000000000080,
31 0x000000000000800a, 0x800000008000000a, 0x8000000080008081,
32 0x8000000000008080, 0x0000000080000001, 0x8000000080008008
36 #define KECCAK_ROUNDS 24
39 #define Theta1(s) (st[0 + s] ^ st[5 + s] ^ st[10 + s] ^ st[15 + s] ^ st[20 + s])
52 u32 j = keccakf_piln[s]; \
53 u32 k = keccakf_rotc[s]; \
55 st[j] = rotl64 (t, k); \
66 st[0 + s] ^= ~bc1 & bc2; \
67 st[1 + s] ^= ~bc2 & bc3; \
68 st[2 + s] ^= ~bc3 & bc4; \
69 st[3 + s] ^= ~bc4 & bc0; \
70 st[4 + s] ^= ~bc0 & bc1; \
73 __kernel void m05000_m04 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global void *esalt_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
79 const u32 lid = get_local_id (0);
85 const u32 gid = get_global_id (0);
87 if (gid >= gid_max) return;
92 pw_buf0[0] = pws[gid].i[0];
93 pw_buf0[1] = pws[gid].i[1];
94 pw_buf0[2] = pws[gid].i[2];
95 pw_buf0[3] = pws[gid].i[3];
96 pw_buf1[0] = pws[gid].i[4];
97 pw_buf1[1] = pws[gid].i[5];
98 pw_buf1[2] = pws[gid].i[6];
99 pw_buf1[3] = pws[gid].i[7];
101 const u32 pw_l_len = pws[gid].pw_len;
107 const u8 keccakf_rotc[24] =
109 1, 3, 6, 10, 15, 21, 28, 36, 45, 55, 2, 14,
110 27, 41, 56, 8, 25, 43, 62, 18, 39, 61, 20, 44
113 const u8 keccakf_piln[24] =
115 10, 7, 11, 17, 18, 3, 5, 16, 8, 21, 24, 4,
116 15, 23, 19, 13, 12, 2, 20, 14, 22, 9, 6, 1
120 * 0x80 keccak, very special
123 const u32 mdlen = salt_bufs[salt_pos].keccak_mdlen;
125 const u32 rsiz = 200 - (2 * mdlen);
127 const u32 add80w = (rsiz - 1) / 8;
133 for (u32 il_pos = 0; il_pos < il_cnt; il_pos += VECT_SIZE)
135 const u32x pw_r_len = pwlenx_create_combt (combs_buf, il_pos);
137 const u32x pw_len = pw_l_len + pw_r_len;
140 * concat password candidate
143 u32x wordl0[4] = { 0 };
144 u32x wordl1[4] = { 0 };
145 u32x wordl2[4] = { 0 };
146 u32x wordl3[4] = { 0 };
148 wordl0[0] = pw_buf0[0];
149 wordl0[1] = pw_buf0[1];
150 wordl0[2] = pw_buf0[2];
151 wordl0[3] = pw_buf0[3];
152 wordl1[0] = pw_buf1[0];
153 wordl1[1] = pw_buf1[1];
154 wordl1[2] = pw_buf1[2];
155 wordl1[3] = pw_buf1[3];
157 u32x wordr0[4] = { 0 };
158 u32x wordr1[4] = { 0 };
159 u32x wordr2[4] = { 0 };
160 u32x wordr3[4] = { 0 };
162 wordr0[0] = ix_create_combt (combs_buf, il_pos, 0);
163 wordr0[1] = ix_create_combt (combs_buf, il_pos, 1);
164 wordr0[2] = ix_create_combt (combs_buf, il_pos, 2);
165 wordr0[3] = ix_create_combt (combs_buf, il_pos, 3);
166 wordr1[0] = ix_create_combt (combs_buf, il_pos, 4);
167 wordr1[1] = ix_create_combt (combs_buf, il_pos, 5);
168 wordr1[2] = ix_create_combt (combs_buf, il_pos, 6);
169 wordr1[3] = ix_create_combt (combs_buf, il_pos, 7);
171 if (combs_mode == COMBINATOR_MODE_BASE_LEFT)
173 switch_buffer_by_offset_le_VV (wordr0, wordr1, wordr2, wordr3, pw_l_len);
177 switch_buffer_by_offset_le_VV (wordl0, wordl1, wordl2, wordl3, pw_r_len);
185 w0[0] = wordl0[0] | wordr0[0];
186 w0[1] = wordl0[1] | wordr0[1];
187 w0[2] = wordl0[2] | wordr0[2];
188 w0[3] = wordl0[3] | wordr0[3];
189 w1[0] = wordl1[0] | wordr1[0];
190 w1[1] = wordl1[1] | wordr1[1];
191 w1[2] = wordl1[2] | wordr1[2];
192 w1[3] = wordl1[3] | wordr1[3];
193 w2[0] = wordl2[0] | wordr2[0];
194 w2[1] = wordl2[1] | wordr2[1];
195 w2[2] = wordl2[2] | wordr2[2];
196 w2[3] = wordl2[3] | wordr2[3];
197 w3[0] = wordl3[0] | wordr3[0];
198 w3[1] = wordl3[1] | wordr3[1];
199 w3[2] = wordl3[2] | wordr3[2];
200 w3[3] = wordl3[3] | wordr3[3];
208 st[ 0] = hl32_to_64 (w0[1], w0[0]);
209 st[ 1] = hl32_to_64 (w0[3], w0[2]);
210 st[ 2] = hl32_to_64 (w1[1], w1[0]);
211 st[ 3] = hl32_to_64 (w1[3], w1[2]);
212 st[ 4] = hl32_to_64 (w2[1], w2[0]);
213 st[ 5] = hl32_to_64 (w2[3], w2[2]);
214 st[ 6] = hl32_to_64 (w3[1], w3[0]);
215 st[ 7] = hl32_to_64 (w3[3], w3[2]);
234 st[add80w] |= 0x8000000000000000;
238 for (round = 0; round < KECCAK_ROUNDS; round++)
242 u64x bc0 = Theta1 (0);
243 u64x bc1 = Theta1 (1);
244 u64x bc2 = Theta1 (2);
245 u64x bc3 = Theta1 (3);
246 u64x bc4 = Theta1 (4);
250 t = bc4 ^ rotl64 (bc1, 1); Theta2 (0);
251 t = bc0 ^ rotl64 (bc2, 1); Theta2 (1);
252 t = bc1 ^ rotl64 (bc3, 1); Theta2 (2);
253 t = bc2 ^ rotl64 (bc4, 1); Theta2 (3);
254 t = bc3 ^ rotl64 (bc0, 1); Theta2 (4);
295 st[0] ^= keccakf_rndc[round];
298 const u32x r0 = l32_from_64 (st[1]);
299 const u32x r1 = h32_from_64 (st[1]);
300 const u32x r2 = l32_from_64 (st[2]);
301 const u32x r3 = h32_from_64 (st[2]);
303 COMPARE_M_SIMD (r0, r1, r2, r3);
307 __kernel void m05000_m08 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global void *esalt_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
311 __kernel void m05000_m16 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global void *esalt_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
315 __kernel void m05000_s04 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global void *esalt_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
321 const u32 lid = get_local_id (0);
327 const u32 gid = get_global_id (0);
329 if (gid >= gid_max) return;
334 pw_buf0[0] = pws[gid].i[0];
335 pw_buf0[1] = pws[gid].i[1];
336 pw_buf0[2] = pws[gid].i[2];
337 pw_buf0[3] = pws[gid].i[3];
338 pw_buf1[0] = pws[gid].i[4];
339 pw_buf1[1] = pws[gid].i[5];
340 pw_buf1[2] = pws[gid].i[6];
341 pw_buf1[3] = pws[gid].i[7];
343 const u32 pw_l_len = pws[gid].pw_len;
349 const u8 keccakf_rotc[24] =
351 1, 3, 6, 10, 15, 21, 28, 36, 45, 55, 2, 14,
352 27, 41, 56, 8, 25, 43, 62, 18, 39, 61, 20, 44
355 const u8 keccakf_piln[24] =
357 10, 7, 11, 17, 18, 3, 5, 16, 8, 21, 24, 4,
358 15, 23, 19, 13, 12, 2, 20, 14, 22, 9, 6, 1
362 * 0x80 keccak, very special
365 const u32 mdlen = salt_bufs[salt_pos].keccak_mdlen;
367 const u32 rsiz = 200 - (2 * mdlen);
369 const u32 add80w = (rsiz - 1) / 8;
375 const u32 search[4] =
377 digests_buf[digests_offset].digest_buf[DGST_R0],
378 digests_buf[digests_offset].digest_buf[DGST_R1],
379 digests_buf[digests_offset].digest_buf[DGST_R2],
380 digests_buf[digests_offset].digest_buf[DGST_R3]
387 for (u32 il_pos = 0; il_pos < il_cnt; il_pos += VECT_SIZE)
389 const u32x pw_r_len = pwlenx_create_combt (combs_buf, il_pos);
391 const u32x pw_len = pw_l_len + pw_r_len;
394 * concat password candidate
397 u32x wordl0[4] = { 0 };
398 u32x wordl1[4] = { 0 };
399 u32x wordl2[4] = { 0 };
400 u32x wordl3[4] = { 0 };
402 wordl0[0] = pw_buf0[0];
403 wordl0[1] = pw_buf0[1];
404 wordl0[2] = pw_buf0[2];
405 wordl0[3] = pw_buf0[3];
406 wordl1[0] = pw_buf1[0];
407 wordl1[1] = pw_buf1[1];
408 wordl1[2] = pw_buf1[2];
409 wordl1[3] = pw_buf1[3];
411 u32x wordr0[4] = { 0 };
412 u32x wordr1[4] = { 0 };
413 u32x wordr2[4] = { 0 };
414 u32x wordr3[4] = { 0 };
416 wordr0[0] = ix_create_combt (combs_buf, il_pos, 0);
417 wordr0[1] = ix_create_combt (combs_buf, il_pos, 1);
418 wordr0[2] = ix_create_combt (combs_buf, il_pos, 2);
419 wordr0[3] = ix_create_combt (combs_buf, il_pos, 3);
420 wordr1[0] = ix_create_combt (combs_buf, il_pos, 4);
421 wordr1[1] = ix_create_combt (combs_buf, il_pos, 5);
422 wordr1[2] = ix_create_combt (combs_buf, il_pos, 6);
423 wordr1[3] = ix_create_combt (combs_buf, il_pos, 7);
425 if (combs_mode == COMBINATOR_MODE_BASE_LEFT)
427 switch_buffer_by_offset_le_VV (wordr0, wordr1, wordr2, wordr3, pw_l_len);
431 switch_buffer_by_offset_le_VV (wordl0, wordl1, wordl2, wordl3, pw_r_len);
439 w0[0] = wordl0[0] | wordr0[0];
440 w0[1] = wordl0[1] | wordr0[1];
441 w0[2] = wordl0[2] | wordr0[2];
442 w0[3] = wordl0[3] | wordr0[3];
443 w1[0] = wordl1[0] | wordr1[0];
444 w1[1] = wordl1[1] | wordr1[1];
445 w1[2] = wordl1[2] | wordr1[2];
446 w1[3] = wordl1[3] | wordr1[3];
447 w2[0] = wordl2[0] | wordr2[0];
448 w2[1] = wordl2[1] | wordr2[1];
449 w2[2] = wordl2[2] | wordr2[2];
450 w2[3] = wordl2[3] | wordr2[3];
451 w3[0] = wordl3[0] | wordr3[0];
452 w3[1] = wordl3[1] | wordr3[1];
453 w3[2] = wordl3[2] | wordr3[2];
454 w3[3] = wordl3[3] | wordr3[3];
462 st[ 0] = hl32_to_64 (w0[1], w0[0]);
463 st[ 1] = hl32_to_64 (w0[3], w0[2]);
464 st[ 2] = hl32_to_64 (w1[1], w1[0]);
465 st[ 3] = hl32_to_64 (w1[3], w1[2]);
466 st[ 4] = hl32_to_64 (w2[1], w2[0]);
467 st[ 5] = hl32_to_64 (w2[3], w2[2]);
468 st[ 6] = hl32_to_64 (w3[1], w3[0]);
469 st[ 7] = hl32_to_64 (w3[3], w3[2]);
488 st[add80w] |= 0x8000000000000000;
492 for (round = 0; round < KECCAK_ROUNDS; round++)
496 u64x bc0 = Theta1 (0);
497 u64x bc1 = Theta1 (1);
498 u64x bc2 = Theta1 (2);
499 u64x bc3 = Theta1 (3);
500 u64x bc4 = Theta1 (4);
504 t = bc4 ^ rotl64 (bc1, 1); Theta2 (0);
505 t = bc0 ^ rotl64 (bc2, 1); Theta2 (1);
506 t = bc1 ^ rotl64 (bc3, 1); Theta2 (2);
507 t = bc2 ^ rotl64 (bc4, 1); Theta2 (3);
508 t = bc3 ^ rotl64 (bc0, 1); Theta2 (4);
549 st[0] ^= keccakf_rndc[round];
552 const u32x r0 = l32_from_64 (st[1]);
553 const u32x r1 = h32_from_64 (st[1]);
554 const u32x r2 = l32_from_64 (st[2]);
555 const u32x r3 = h32_from_64 (st[2]);
557 COMPARE_S_SIMD (r0, r1, r2, r3);
561 __kernel void m05000_s08 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global void *esalt_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
565 __kernel void m05000_s16 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global void *esalt_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)