UNPKG

2.51 kBJavaScriptView Raw
1var md5 = require('create-hash/md5')
2var RIPEMD160 = require('ripemd160')
3var sha = require('sha.js')
4var Buffer = require('safe-buffer').Buffer
5
6var checkParameters = require('./precondition')
7var defaultEncoding = require('./default-encoding')
8var toBuffer = require('./to-buffer')
9
10var ZEROS = Buffer.alloc(128)
11var sizes = {
12 md5: 16,
13 sha1: 20,
14 sha224: 28,
15 sha256: 32,
16 sha384: 48,
17 sha512: 64,
18 rmd160: 20,
19 ripemd160: 20
20}
21
22function Hmac (alg, key, saltLen) {
23 var hash = getDigest(alg)
24 var blocksize = (alg === 'sha512' || alg === 'sha384') ? 128 : 64
25
26 if (key.length > blocksize) {
27 key = hash(key)
28 } else if (key.length < blocksize) {
29 key = Buffer.concat([key, ZEROS], blocksize)
30 }
31
32 var ipad = Buffer.allocUnsafe(blocksize + sizes[alg])
33 var opad = Buffer.allocUnsafe(blocksize + sizes[alg])
34 for (var i = 0; i < blocksize; i++) {
35 ipad[i] = key[i] ^ 0x36
36 opad[i] = key[i] ^ 0x5C
37 }
38
39 var ipad1 = Buffer.allocUnsafe(blocksize + saltLen + 4)
40 ipad.copy(ipad1, 0, 0, blocksize)
41 this.ipad1 = ipad1
42 this.ipad2 = ipad
43 this.opad = opad
44 this.alg = alg
45 this.blocksize = blocksize
46 this.hash = hash
47 this.size = sizes[alg]
48}
49
50Hmac.prototype.run = function (data, ipad) {
51 data.copy(ipad, this.blocksize)
52 var h = this.hash(ipad)
53 h.copy(this.opad, this.blocksize)
54 return this.hash(this.opad)
55}
56
57function getDigest (alg) {
58 function shaFunc (data) {
59 return sha(alg).update(data).digest()
60 }
61 function rmd160Func (data) {
62 return new RIPEMD160().update(data).digest()
63 }
64
65 if (alg === 'rmd160' || alg === 'ripemd160') return rmd160Func
66 if (alg === 'md5') return md5
67 return shaFunc
68}
69
70function pbkdf2 (password, salt, iterations, keylen, digest) {
71 checkParameters(iterations, keylen)
72 password = toBuffer(password, defaultEncoding, 'Password')
73 salt = toBuffer(salt, defaultEncoding, 'Salt')
74
75 digest = digest || 'sha1'
76
77 var hmac = new Hmac(digest, password, salt.length)
78
79 var DK = Buffer.allocUnsafe(keylen)
80 var block1 = Buffer.allocUnsafe(salt.length + 4)
81 salt.copy(block1, 0, 0, salt.length)
82
83 var destPos = 0
84 var hLen = sizes[digest]
85 var l = Math.ceil(keylen / hLen)
86
87 for (var i = 1; i <= l; i++) {
88 block1.writeUInt32BE(i, salt.length)
89
90 var T = hmac.run(block1, hmac.ipad1)
91 var U = T
92
93 for (var j = 1; j < iterations; j++) {
94 U = hmac.run(U, hmac.ipad2)
95 for (var k = 0; k < hLen; k++) T[k] ^= U[k]
96 }
97
98 T.copy(DK, destPos)
99 destPos += hLen
100 }
101
102 return DK
103}
104
105module.exports = pbkdf2