WEBVTT

1
00:00:00.000 --> 00:00:07.423
The input is just abc, yet SHA two fifty six
produces a two hundred fifty six bit digest.

2
00:00:07.423 --> 00:00:14.144
It prepares five hundred twelve bit blocks and
operates on thirty two bit words.

3
00:00:14.144 --> 00:00:21.397
A digest cannot be decrypted back into the
message, and identity needs a trusted comparison

4
00:00:21.397 --> 00:00:23.177
or signature protocol.

5
00:00:23.177 --> 00:00:30.297
SHA two twenty four and SHA five twelve slash two
fifty six have distinct initialization rules.

6
00:00:30.297 --> 00:00:35.468
Simply cutting off part of a digest is not a
general substitute.

7
00:00:35.468 --> 00:00:42.839
This selected core is a teaching architecture,
without a claim of RTL or silicon validation.

8
00:00:43.125 --> 00:00:45.875
Abc first reaches a message wrapper.

9
00:00:45.875 --> 00:00:51.879
The wrapper counts the original bits, pads the
message, and supplies complete blocks.

10
00:00:51.879 --> 00:00:57.801
The core drawn here accepts those prepared
blocks; it does not count an arbitrary byte

11
00:00:57.801 --> 00:00:58.377
stream.

12
00:00:58.377 --> 00:01:02.416
Software or a testbench must perform that
preparation.

13
00:01:02.416 --> 00:01:08.302
Keeping the boundary visible lets a failed test
distinguish an input-padding error from a

14
00:01:08.302 --> 00:01:10.356
compression-core error.

15
00:01:10.625 --> 00:01:15.655
Let the original length L be below two to the
sixty fourth power.

16
00:01:15.655 --> 00:01:23.036
Append one bit and zeros until the length is four
hundred forty eight modulo five hundred twelve.

17
00:01:23.036 --> 00:01:28.321
The remaining sixty four bits hold the original L
in big endian order.

18
00:01:28.321 --> 00:01:33.900
For byte-aligned data, padding begins with
hexadecimal eighty.

19
00:01:33.900 --> 00:01:38.515
Fifty five bytes still fit in one block; fifty
six need two.

20
00:01:38.515 --> 00:01:44.542
Empty input needs one block, while sixty three
and sixty four bytes need two.

21
00:01:44.542 --> 00:01:50.317
Even a completely filled data block still
requires padding.

22
00:01:50.583 --> 00:01:56.497
The bytes of abc are hexadecimal sixty one, sixty
two, and sixty three.

23
00:01:56.497 --> 00:02:03.857
Padding places eighty next, forming W zero as six
one six two six three eight zero in the most

24
00:02:03.857 --> 00:02:05.406
significant word.

25
00:02:05.406 --> 00:02:11.475
The original length is twenty four bits, so W
fifteen holds hexadecimal eighteen.

26
00:02:11.475 --> 00:02:14.514
Fix the packed-vector positions on screen.

27
00:02:14.514 --> 00:02:20.122
A processor's usual endianness does not determine
this core's byte wiring.

28
00:02:20.375 --> 00:02:27.304
At the start of a block, copy H zero through H
seven into working words a through h.

29
00:02:27.304 --> 00:02:32.426
For the first block, H contains the standard
initial values.

30
00:02:32.426 --> 00:02:38.050
The sixty four rounds update the working words
while preserving H.

31
00:02:38.050 --> 00:02:43.039
The final result must be added to this saved
starting state.

32
00:02:43.039 --> 00:02:48.529
Overwriting H each round loses the value needed
for that addition.

33
00:02:48.792 --> 00:02:52.162
Use an eight-bit word to see the movement.

34
00:02:52.162 --> 00:02:58.956
Right rotation reconnects outgoing bits on the
left; logical right shift inserts zeros.

35
00:02:58.956 --> 00:03:05.025
Actual SHA words are thirty two bits, and fixed
rotations can usually be wiring.

36
00:03:05.025 --> 00:03:12.100
Arithmetic addition is a separate operation,
modulo two to the thirty second power within each

37
00:03:12.100 --> 00:03:12.517
word.

38
00:03:12.517 --> 00:03:14.270
Discard its final carry.

39
00:03:14.270 --> 00:03:18.792
Exclusive or has no carry and cannot replace that
addition.

40
00:03:19.042 --> 00:03:25.024
At each bit, Choose uses x to select y when x is
one and z when x is zero.

41
00:03:25.024 --> 00:03:29.774
Majority returns the value held by at least two
inputs.

42
00:03:29.774 --> 00:03:37.003
Check a one-bit truth table, then apply the same
logic across thirty two positions.

43
00:03:37.003 --> 00:03:40.177
There is no carry between positions.

44
00:03:40.177 --> 00:03:47.425
These small combinational checks give a concrete
starting point when an integrated trace first

45
00:03:47.425 --> 00:03:48.580
diverges.

46
00:03:48.833 --> 00:03:54.908
The uppercase sigma functions feed the rounds,
combining rotations with exclusive or.

47
00:03:54.908 --> 00:04:00.386
The lowercase functions feed the schedule and
each include a logical right shift.

48
00:04:00.386 --> 00:04:02.688
All four sets of amounts are shown.

49
00:04:02.688 --> 00:04:06.888
Similar names do not make the functions
interchangeable.

50
00:04:06.888 --> 00:04:12.860
Check each definition, particularly that the
shift term discards outgoing bits instead of

51
00:04:12.860 --> 00:04:14.218
wrapping them.

52
00:04:14.500 --> 00:04:18.971
Compute T one and T two from the old working
state.

53
00:04:18.971 --> 00:04:26.368
T one combines h, uppercase sigma one, Choose,
public constant K, and this round's W.

54
00:04:26.368 --> 00:04:30.744
T two combines uppercase sigma zero and Majority.

55
00:04:30.744 --> 00:04:32.098
K is not secret.

56
00:04:32.098 --> 00:04:36.467
New a is T one plus T two; new e is old d plus T
one.

57
00:04:36.467 --> 00:04:39.496
The other words follow the arrows.

58
00:04:39.496 --> 00:04:42.421
Capture all new values together.

59
00:04:42.421 --> 00:04:50.500
Nonblocking assignments do not reuse a newly
overwritten value within this same round.

60
00:04:50.750 --> 00:04:54.867
The first sixteen W words come directly from the
block.

61
00:04:54.867 --> 00:05:01.509
Later words combine the positions two, seven,
fifteen, and sixteen words earlier, using the

62
00:05:01.509 --> 00:05:03.212
displayed recurrence.

63
00:05:03.212 --> 00:05:05.085
Each round needs its own W.

64
00:05:05.085 --> 00:05:10.942
Expand all sixty four words in a software
reference, then compare the smaller hardware

65
00:05:10.942 --> 00:05:12.138
window against it.

66
00:05:12.138 --> 00:05:18.193
Distinct representations help reveal indexing
mistakes that two similarly written schedules

67
00:05:18.193 --> 00:05:19.365
could share.

68
00:05:19.625 --> 00:05:22.990
The window contains sixteen q slots.

69
00:05:22.990 --> 00:05:26.053
Feed old q zero to the current round.

70
00:05:26.053 --> 00:05:34.323
Calculate the new tail from old q fourteen, nine,
one, and zero; it belongs sixteen rounds later.

71
00:05:34.323 --> 00:05:39.837
At the edge, shift the old entries forward and
store the new tail.

72
00:05:39.837 --> 00:05:43.542
Every tap reads the window before movement.

73
00:05:43.542 --> 00:05:49.163
If you shift first, the same slot numbers now
refer to different words.

74
00:05:49.417 --> 00:05:55.770
Rounds zero through forty seven generate W
sixteen through W sixty three.

75
00:05:55.770 --> 00:06:02.122
At round forty eight, all sixteen remaining words
are already in the window.

76
00:06:02.122 --> 00:06:08.739
Continue taking q zero each round, with zero
allowed at the tail because W sixty four and

77
00:06:08.739 --> 00:06:10.102
beyond are unused.

78
00:06:10.102 --> 00:06:16.234
Follow the counter beside the window to
distinguish words waiting to be consumed from

79
00:06:16.234 --> 00:06:18.032
those already used.

80
00:06:18.292 --> 00:06:23.718
After sixty four rounds, add each final working
word to its saved H word.

81
00:06:23.718 --> 00:06:30.599
These are eight separate thirty two bit modular
additions; carry cannot cross between words.

82
00:06:30.599 --> 00:06:35.216
This feed-forward step produces the completed H
for the block.

83
00:06:35.216 --> 00:06:41.959
If every round matches but the digest fails,
inspect the saved starting H, the addition

84
00:06:41.959 --> 00:06:45.438
itself, and the boundaries between words.

85
00:06:45.708 --> 00:06:51.272
For a two-block message, the completed H from the
first block starts the second.

86
00:06:51.272 --> 00:06:56.236
Load the standard initial values only for the
first block of a new message.

87
00:06:56.236 --> 00:07:01.440
Hashing each block independently and
concatenating the answers changes the

88
00:07:01.440 --> 00:07:02.400
computation.

89
00:07:02.400 --> 00:07:10.170
This dependency explains why the controller must
distinguish the first block from a continuation.

90
00:07:10.458 --> 00:07:15.154
Accept a block at a rising edge with valid and
ready both high.

91
00:07:15.154 --> 00:07:18.416
Capture its data, first, and last together.

92
00:07:18.416 --> 00:07:25.205
The source presents valid and holds everything
until acceptance; it must not wait for ready

93
00:07:25.205 --> 00:07:27.144
before presenting valid.

94
00:07:27.144 --> 00:07:29.780
First begins a new message.

95
00:07:29.780 --> 00:07:37.228
Last marks the final padded block, rather than
simply the last group of original bytes.

96
00:07:37.542 --> 00:07:40.594
WAIT FIRST accepts first asserted.

97
00:07:40.594 --> 00:07:45.538
ROUND performs sixty four rounds, then ACCUM adds
the result.

98
00:07:45.538 --> 00:07:51.719
A nonfinal block leads to WAIT NEXT, accepting a
continuation with first low.

99
00:07:51.719 --> 00:07:54.476
A final block leads to OUTPUT HOLD.

100
00:07:54.476 --> 00:08:00.765
Busy may be low while waiting for another block
even though the message is unfinished.

101
00:08:00.765 --> 00:08:05.696
The phase and last flag supply information that
busy alone cannot.

102
00:08:05.958 --> 00:08:09.438
E zero loads and initializes the block.

103
00:08:09.438 --> 00:08:15.104
Round zero occurs at E one, and the sixty fourth
round at E sixty four.

104
00:08:15.104 --> 00:08:19.776
E sixty five accumulates and makes a final digest
valid.

105
00:08:19.776 --> 00:08:25.839
Earliest transfer is E sixty six; a new message
can begin at E sixty seven.

106
00:08:25.839 --> 00:08:32.445
That gives sixty five cycles to valid, sixty six
between continuation blocks, and at least sixty

107
00:08:32.445 --> 00:08:34.973
seven between single-block messages.

108
00:08:34.973 --> 00:08:38.957
Shared adders or extra pipeline stages change
this schedule.

109
00:08:38.957 --> 00:08:44.196
Frequency still requires implementation and
timing analysis.

110
00:08:44.458 --> 00:08:48.437
The digest is valid while the receiver is not
ready.

111
00:08:48.437 --> 00:08:54.940
Preserve H, the digest data, and valid; do not
accept a block that overwrites the answer.

112
00:08:54.940 --> 00:09:02.058
Transfer completes at an edge with both signals
high, then the controller returns to WAIT FIRST.

113
00:09:02.058 --> 00:09:09.029
Recording calculation and delivery separately
lets the testbench check stability during stalls

114
00:09:09.029 --> 00:09:12.151
and detect missing or duplicate outputs.

115
00:09:12.458 --> 00:09:17.632
An active-low synchronous reset clears the
registers at a rising edge.

116
00:09:17.632 --> 00:09:23.850
H, working state, window, and control return to
their starting condition, canceling the

117
00:09:23.850 --> 00:09:25.342
unfinished message.

118
00:09:25.342 --> 00:09:30.815
After release, restart with a first block; do not
resume its old continuation.

119
00:09:30.815 --> 00:09:36.965
Remove the canceled digest expectation from the
scoreboard too, or the test will misreport the

120
00:09:36.965 --> 00:09:40.082
canceled transaction as a missing output.

121
00:09:40.333 --> 00:09:41.981
Return to abc.

122
00:09:41.981 --> 00:09:50.670
NIST's t equals zero checkpoint is after the
first round, corresponding to E one here.

123
00:09:50.670 --> 00:09:54.291
It is not the initial state at E zero.

124
00:09:54.291 --> 00:10:03.100
The displayed first-round values are a, five D
six A E B C D, and e, F A two A four six two two.

125
00:10:03.100 --> 00:10:05.723
The full digest appears below.

126
00:10:05.723 --> 00:10:11.718
Start with the earliest divergence instead of
guessing from the final string.

127
00:10:12.000 --> 00:10:15.877
If W zero is wrong, inspect padding and byte
order.

128
00:10:15.877 --> 00:10:21.655
If W sixteen first diverges, inspect lowercase
sigma, taps, and update order.

129
00:10:21.655 --> 00:10:26.033
Matching rounds with a wrong digest point to
feed-forward.

130
00:10:26.033 --> 00:10:30.395
Long-message failures point to chaining and first
or last flags.

131
00:10:30.395 --> 00:10:35.510
Correct values with incorrect counts point to
backpressure and handshake records.

132
00:10:35.510 --> 00:10:40.615
Follow each value's dependencies to narrow the
circuit under investigation.

133
00:10:40.875 --> 00:10:46.427
A software reference can check the full schedule
and digest without validating the RTL.

134
00:10:46.427 --> 00:10:51.996
The hardware testbench also needs multiple
blocks, input gaps, randomized backpressure,

135
00:10:51.996 --> 00:10:55.250
invalid first flags, and resets in different
phases.

136
00:10:55.250 --> 00:11:00.596
Record transactions at handshake edges and
compare values, counts, and order.

137
00:11:00.596 --> 00:11:04.435
A timeout distinguishes a deadlock from
legitimate waiting.

138
00:11:04.435 --> 00:11:09.952
These are further verification tasks, not results
established by this animation.

139
00:11:10.208 --> 00:11:15.847
Build a combinational round, schedule, and
constants before integrating registers and

140
00:11:15.847 --> 00:11:16.427
control.

141
00:11:16.427 --> 00:11:22.010
H, working state, and the sixteen-word window
hold one thousand twenty four data bits, with

142
00:11:22.010 --> 00:11:23.823
control counted separately.

143
00:11:23.823 --> 00:11:25.346
Add the message wrapper.

144
00:11:25.346 --> 00:11:32.702
Trusted boot or HMAC also needs protocol and key
handling; functional vectors do not establish

145
00:11:32.702 --> 00:11:35.311
fault or side-channel protection.

146
00:11:35.311 --> 00:11:37.224
Try a fifty six byte input.

147
00:11:37.224 --> 00:11:43.902
The wrapper sends an extra block: check that the
controller preserves the completed H for that

148
00:11:43.902 --> 00:11:45.285
continuation.
