+ #define ROUND_EXPAND_S() \
+ { \
+ w0_t = SHA256_EXPAND_S (we_t, w9_t, w1_t, w0_t); \
+ w1_t = SHA256_EXPAND_S (wf_t, wa_t, w2_t, w1_t); \
+ w2_t = SHA256_EXPAND_S (w0_t, wb_t, w3_t, w2_t); \
+ w3_t = SHA256_EXPAND_S (w1_t, wc_t, w4_t, w3_t); \
+ w4_t = SHA256_EXPAND_S (w2_t, wd_t, w5_t, w4_t); \
+ w5_t = SHA256_EXPAND_S (w3_t, we_t, w6_t, w5_t); \
+ w6_t = SHA256_EXPAND_S (w4_t, wf_t, w7_t, w6_t); \
+ w7_t = SHA256_EXPAND_S (w5_t, w0_t, w8_t, w7_t); \
+ w8_t = SHA256_EXPAND_S (w6_t, w1_t, w9_t, w8_t); \
+ w9_t = SHA256_EXPAND_S (w7_t, w2_t, wa_t, w9_t); \
+ wa_t = SHA256_EXPAND_S (w8_t, w3_t, wb_t, wa_t); \
+ wb_t = SHA256_EXPAND_S (w9_t, w4_t, wc_t, wb_t); \
+ wc_t = SHA256_EXPAND_S (wa_t, w5_t, wd_t, wc_t); \
+ wd_t = SHA256_EXPAND_S (wb_t, w6_t, we_t, wd_t); \
+ we_t = SHA256_EXPAND_S (wc_t, w7_t, wf_t, we_t); \
+ wf_t = SHA256_EXPAND_S (wd_t, w8_t, w0_t, wf_t); \
+ }
+
+ #define ROUND_STEP_S(i) \
+ { \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, a, b, c, d, e, f, g, h, w0_t, k_sha256[i + 0]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, h, a, b, c, d, e, f, g, w1_t, k_sha256[i + 1]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, g, h, a, b, c, d, e, f, w2_t, k_sha256[i + 2]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, f, g, h, a, b, c, d, e, w3_t, k_sha256[i + 3]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, e, f, g, h, a, b, c, d, w4_t, k_sha256[i + 4]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, d, e, f, g, h, a, b, c, w5_t, k_sha256[i + 5]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, c, d, e, f, g, h, a, b, w6_t, k_sha256[i + 6]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, b, c, d, e, f, g, h, a, w7_t, k_sha256[i + 7]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, a, b, c, d, e, f, g, h, w8_t, k_sha256[i + 8]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, h, a, b, c, d, e, f, g, w9_t, k_sha256[i + 9]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, g, h, a, b, c, d, e, f, wa_t, k_sha256[i + 10]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, f, g, h, a, b, c, d, e, wb_t, k_sha256[i + 11]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, e, f, g, h, a, b, c, d, wc_t, k_sha256[i + 12]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, d, e, f, g, h, a, b, c, wd_t, k_sha256[i + 13]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, c, d, e, f, g, h, a, b, we_t, k_sha256[i + 14]); \
+ SHA256_STEP_S (SHA256_F0o, SHA256_F1o, b, c, d, e, f, g, h, a, wf_t, k_sha256[i + 15]); \
+ }
+
+ ROUND_STEP_S (0);
+
+ #ifdef _unroll
+ #pragma unroll
+ #endif
+ for (int i = 16; i < 64; i += 16)
+ {
+ ROUND_EXPAND_S (); ROUND_STEP_S (i);
+ }
+
+ digest[0] += a;
+ digest[1] += b;
+ digest[2] += c;
+ digest[3] += d;
+ digest[4] += e;
+ digest[5] += f;
+ digest[6] += g;
+ digest[7] += h;
+}
+
+void hmac_sha256_pad_S (u32 w0[4], u32 w1[4], u32 w2[4], u32 w3[4], u32 ipad[8], u32 opad[8])
+{
+ w0[0] = w0[0] ^ 0x36363636;
+ w0[1] = w0[1] ^ 0x36363636;
+ w0[2] = w0[2] ^ 0x36363636;
+ w0[3] = w0[3] ^ 0x36363636;
+ w1[0] = w1[0] ^ 0x36363636;
+ w1[1] = w1[1] ^ 0x36363636;
+ w1[2] = w1[2] ^ 0x36363636;
+ w1[3] = w1[3] ^ 0x36363636;
+ w2[0] = w2[0] ^ 0x36363636;
+ w2[1] = w2[1] ^ 0x36363636;
+ w2[2] = w2[2] ^ 0x36363636;
+ w2[3] = w2[3] ^ 0x36363636;
+ w3[0] = w3[0] ^ 0x36363636;
+ w3[1] = w3[1] ^ 0x36363636;
+ w3[2] = w3[2] ^ 0x36363636;
+ w3[3] = w3[3] ^ 0x36363636;
+
+ ipad[0] = SHA256M_A;
+ ipad[1] = SHA256M_B;
+ ipad[2] = SHA256M_C;
+ ipad[3] = SHA256M_D;
+ ipad[4] = SHA256M_E;
+ ipad[5] = SHA256M_F;
+ ipad[6] = SHA256M_G;
+ ipad[7] = SHA256M_H;
+
+ sha256_transform_S (w0, w1, w2, w3, ipad);
+
+ w0[0] = w0[0] ^ 0x6a6a6a6a;
+ w0[1] = w0[1] ^ 0x6a6a6a6a;
+ w0[2] = w0[2] ^ 0x6a6a6a6a;
+ w0[3] = w0[3] ^ 0x6a6a6a6a;
+ w1[0] = w1[0] ^ 0x6a6a6a6a;
+ w1[1] = w1[1] ^ 0x6a6a6a6a;
+ w1[2] = w1[2] ^ 0x6a6a6a6a;
+ w1[3] = w1[3] ^ 0x6a6a6a6a;
+ w2[0] = w2[0] ^ 0x6a6a6a6a;
+ w2[1] = w2[1] ^ 0x6a6a6a6a;
+ w2[2] = w2[2] ^ 0x6a6a6a6a;
+ w2[3] = w2[3] ^ 0x6a6a6a6a;
+ w3[0] = w3[0] ^ 0x6a6a6a6a;
+ w3[1] = w3[1] ^ 0x6a6a6a6a;
+ w3[2] = w3[2] ^ 0x6a6a6a6a;
+ w3[3] = w3[3] ^ 0x6a6a6a6a;
+
+ opad[0] = SHA256M_A;
+ opad[1] = SHA256M_B;
+ opad[2] = SHA256M_C;
+ opad[3] = SHA256M_D;
+ opad[4] = SHA256M_E;
+ opad[5] = SHA256M_F;
+ opad[6] = SHA256M_G;
+ opad[7] = SHA256M_H;
+
+ sha256_transform_S (w0, w1, w2, w3, opad);
+}
+
+void hmac_sha256_run_S (u32 w0[4], u32 w1[4], u32 w2[4], u32 w3[4], u32 ipad[8], u32 opad[8], u32 digest[8])
+{
+ digest[0] = ipad[0];
+ digest[1] = ipad[1];
+ digest[2] = ipad[2];
+ digest[3] = ipad[3];
+ digest[4] = ipad[4];
+ digest[5] = ipad[5];
+ digest[6] = ipad[6];
+ digest[7] = ipad[7];
+
+ sha256_transform_S (w0, w1, w2, w3, digest);
+
+ w0[0] = digest[0];
+ w0[1] = digest[1];
+ w0[2] = digest[2];
+ w0[3] = digest[3];
+ w1[0] = digest[4];
+ w1[1] = digest[5];
+ w1[2] = digest[6];
+ w1[3] = digest[7];
+ w2[0] = 0x80000000;
+ w2[1] = 0;
+ w2[2] = 0;
+ w2[3] = 0;
+ w3[0] = 0;
+ w3[1] = 0;
+ w3[2] = 0;
+ w3[3] = (64 + 32) * 8;
+
+ digest[0] = opad[0];
+ digest[1] = opad[1];
+ digest[2] = opad[2];
+ digest[3] = opad[3];
+ digest[4] = opad[4];
+ digest[5] = opad[5];
+ digest[6] = opad[6];
+ digest[7] = opad[7];
+
+ sha256_transform_S (w0, w1, w2, w3, digest);
+}
+
+void sha256_transform_V (const u32x w0[4], const u32x w1[4], const u32x w2[4], const u32x w3[4], u32x digest[8])
+{
+ u32x a = digest[0];
+ u32x b = digest[1];
+ u32x c = digest[2];
+ u32x d = digest[3];
+ u32x e = digest[4];
+ u32x f = digest[5];
+ u32x g = digest[6];
+ u32x h = digest[7];
+
+ u32x w0_t = w0[0];
+ u32x w1_t = w0[1];
+ u32x w2_t = w0[2];
+ u32x w3_t = w0[3];
+ u32x w4_t = w1[0];
+ u32x w5_t = w1[1];
+ u32x w6_t = w1[2];
+ u32x w7_t = w1[3];
+ u32x w8_t = w2[0];
+ u32x w9_t = w2[1];
+ u32x wa_t = w2[2];
+ u32x wb_t = w2[3];
+ u32x wc_t = w3[0];
+ u32x wd_t = w3[1];
+ u32x we_t = w3[2];
+ u32x wf_t = w3[3];
+