Annotation of truecrypt/crypto/aessmall.c, revision 1.1.1.1

1.1       root        1: /*
                      2:  ---------------------------------------------------------------------------
                      3:  Copyright (c) 1998-2006, Brian Gladman, Worcester, UK. All rights reserved.
                      4: 
                      5:  LICENSE TERMS
                      6: 
                      7:  The free distribution and use of this software in both source and binary
                      8:  form is allowed (with or without changes) provided that:
                      9: 
                     10:    1. distributions of this source code include the above copyright
                     11:       notice, this list of conditions and the following disclaimer;
                     12: 
                     13:    2. distributions in binary form include the above copyright
                     14:       notice, this list of conditions and the following disclaimer
                     15:       in the documentation and/or other associated materials;
                     16: 
                     17:    3. the copyright holder's name is not used to endorse products
                     18:       built using this software without specific written permission.
                     19: 
                     20:  ALTERNATIVELY, provided that this notice is retained in full, this product
                     21:  may be distributed under the terms of the GNU General Public License (GPL),
                     22:  in which case the provisions of the GPL apply INSTEAD OF those given above.
                     23: 
                     24:  DISCLAIMER
                     25: 
                     26:  This software is provided 'as is' with no explicit or implied warranties
                     27:  in respect of its properties, including, but not limited to, correctness
                     28:  and/or fitness for purpose.
                     29:  ---------------------------------------------------------------------------
                     30:  Issue 09/09/2006
                     31: 
                     32:  This is an AES implementation that uses only 8-bit byte operations on the
                     33:  cipher state (there are options to use 32-bit types if available).
                     34: 
                     35:  The combination of mix columns and byte substitution used here is based on
                     36:  that developed by Karl Malbrain. His contribution is acknowledged.
                     37:  */
                     38: 
                     39: /* Adapted by TrueCrypt Foundation:
                     40:   - Macro-generated tables were replaced with static data to enable compiling
                     41:     with MSVC++ 1.5 which runs out of resources when expanding large macros.
                     42: */
                     43: 
                     44: /* define if you have a fast memcpy function on your system */
                     45: #if 1
                     46: #  define HAVE_MEMCPY
                     47: #  include <string.h>
                     48: #  if defined( _MSC_VER )
                     49: #    ifndef DEBUG
                     50: #      pragma intrinsic( memcpy )
                     51: #    endif
                     52: #  endif
                     53: #endif
                     54: 
                     55: /* define if you have fast 32-bit types on your system */
                     56: #if 1
                     57: #  define HAVE_UINT_32T
                     58: #endif
                     59: 
                     60: /* alternative versions (test for performance on your system) */
                     61: #if 0
                     62: #  define VERSION_1
                     63: #endif
                     64: 
                     65: #include "AesSmall.h"
                     66: 
                     67: #define WPOLY   0x011b
                     68: #define DPOLY   0x008d
                     69: #define f1(x)   (x)
                     70: #define f2(x)   ((x<<1) ^ (((x>>7) & 1) * WPOLY))
                     71: #define f4(x)   ((x<<2) ^ (((x>>6) & 1) * WPOLY) ^ (((x>>6) & 2) * WPOLY))
                     72: #define f8(x)   ((x<<3) ^ (((x>>5) & 1) * WPOLY) ^ (((x>>5) & 2) * WPOLY) \
                     73:                         ^ (((x>>5) & 4) * WPOLY))
                     74: #define d2(x)   (((x) >> 1) ^ ((x) & 1 ? DPOLY : 0))
                     75: 
                     76: #define f3(x)   (f2(x) ^ x)
                     77: #define f9(x)   (f8(x) ^ x)
                     78: #define fb(x)   (f8(x) ^ f2(x) ^ x)
                     79: #define fd(x)   (f8(x) ^ f4(x) ^ x)
                     80: #define fe(x)   (f8(x) ^ f4(x) ^ f2(x))
                     81: 
                     82: static const uint_8t s_box[256] = {
                     83:        0x63,0x7c,0x77,0x7b,0xf2,0x6b,0x6f,0xc5,
                     84:        0x30,0x01,0x67,0x2b,0xfe,0xd7,0xab,0x76,
                     85:        0xca,0x82,0xc9,0x7d,0xfa,0x59,0x47,0xf0,
                     86:        0xad,0xd4,0xa2,0xaf,0x9c,0xa4,0x72,0xc0,
                     87:        0xb7,0xfd,0x93,0x26,0x36,0x3f,0xf7,0xcc,
                     88:        0x34,0xa5,0xe5,0xf1,0x71,0xd8,0x31,0x15,
                     89:        0x04,0xc7,0x23,0xc3,0x18,0x96,0x05,0x9a,
                     90:        0x07,0x12,0x80,0xe2,0xeb,0x27,0xb2,0x75,
                     91:        0x09,0x83,0x2c,0x1a,0x1b,0x6e,0x5a,0xa0,
                     92:        0x52,0x3b,0xd6,0xb3,0x29,0xe3,0x2f,0x84,
                     93:        0x53,0xd1,0x00,0xed,0x20,0xfc,0xb1,0x5b,
                     94:        0x6a,0xcb,0xbe,0x39,0x4a,0x4c,0x58,0xcf,
                     95:        0xd0,0xef,0xaa,0xfb,0x43,0x4d,0x33,0x85,
                     96:        0x45,0xf9,0x02,0x7f,0x50,0x3c,0x9f,0xa8,
                     97:        0x51,0xa3,0x40,0x8f,0x92,0x9d,0x38,0xf5,
                     98:        0xbc,0xb6,0xda,0x21,0x10,0xff,0xf3,0xd2,
                     99:        0xcd,0x0c,0x13,0xec,0x5f,0x97,0x44,0x17,
                    100:        0xc4,0xa7,0x7e,0x3d,0x64,0x5d,0x19,0x73,
                    101:        0x60,0x81,0x4f,0xdc,0x22,0x2a,0x90,0x88,
                    102:        0x46,0xee,0xb8,0x14,0xde,0x5e,0x0b,0xdb,
                    103:        0xe0,0x32,0x3a,0x0a,0x49,0x06,0x24,0x5c,
                    104:        0xc2,0xd3,0xac,0x62,0x91,0x95,0xe4,0x79,
                    105:        0xe7,0xc8,0x37,0x6d,0x8d,0xd5,0x4e,0xa9,
                    106:        0x6c,0x56,0xf4,0xea,0x65,0x7a,0xae,0x08,
                    107:        0xba,0x78,0x25,0x2e,0x1c,0xa6,0xb4,0xc6,
                    108:        0xe8,0xdd,0x74,0x1f,0x4b,0xbd,0x8b,0x8a,
                    109:        0x70,0x3e,0xb5,0x66,0x48,0x03,0xf6,0x0e,
                    110:        0x61,0x35,0x57,0xb9,0x86,0xc1,0x1d,0x9e,
                    111:        0xe1,0xf8,0x98,0x11,0x69,0xd9,0x8e,0x94,
                    112:        0x9b,0x1e,0x87,0xe9,0xce,0x55,0x28,0xdf,
                    113:        0x8c,0xa1,0x89,0x0d,0xbf,0xe6,0x42,0x68,
                    114:        0x41,0x99,0x2d,0x0f,0xb0,0x54,0xbb,0x16
                    115: };
                    116: 
                    117: static const uint_8t inv_s_box[256] = {
                    118:        0x52,0x09,0x6a,0xd5,0x30,0x36,0xa5,0x38,
                    119:        0xbf,0x40,0xa3,0x9e,0x81,0xf3,0xd7,0xfb,
                    120:        0x7c,0xe3,0x39,0x82,0x9b,0x2f,0xff,0x87,
                    121:        0x34,0x8e,0x43,0x44,0xc4,0xde,0xe9,0xcb,
                    122:        0x54,0x7b,0x94,0x32,0xa6,0xc2,0x23,0x3d,
                    123:        0xee,0x4c,0x95,0x0b,0x42,0xfa,0xc3,0x4e,
                    124:        0x08,0x2e,0xa1,0x66,0x28,0xd9,0x24,0xb2,
                    125:        0x76,0x5b,0xa2,0x49,0x6d,0x8b,0xd1,0x25,
                    126:        0x72,0xf8,0xf6,0x64,0x86,0x68,0x98,0x16,
                    127:        0xd4,0xa4,0x5c,0xcc,0x5d,0x65,0xb6,0x92,
                    128:        0x6c,0x70,0x48,0x50,0xfd,0xed,0xb9,0xda,
                    129:        0x5e,0x15,0x46,0x57,0xa7,0x8d,0x9d,0x84,
                    130:        0x90,0xd8,0xab,0x00,0x8c,0xbc,0xd3,0x0a,
                    131:        0xf7,0xe4,0x58,0x05,0xb8,0xb3,0x45,0x06,
                    132:        0xd0,0x2c,0x1e,0x8f,0xca,0x3f,0x0f,0x02,
                    133:        0xc1,0xaf,0xbd,0x03,0x01,0x13,0x8a,0x6b,
                    134:        0x3a,0x91,0x11,0x41,0x4f,0x67,0xdc,0xea,
                    135:        0x97,0xf2,0xcf,0xce,0xf0,0xb4,0xe6,0x73,
                    136:        0x96,0xac,0x74,0x22,0xe7,0xad,0x35,0x85,
                    137:        0xe2,0xf9,0x37,0xe8,0x1c,0x75,0xdf,0x6e,
                    138:        0x47,0xf1,0x1a,0x71,0x1d,0x29,0xc5,0x89,
                    139:        0x6f,0xb7,0x62,0x0e,0xaa,0x18,0xbe,0x1b,
                    140:        0xfc,0x56,0x3e,0x4b,0xc6,0xd2,0x79,0x20,
                    141:        0x9a,0xdb,0xc0,0xfe,0x78,0xcd,0x5a,0xf4,
                    142:        0x1f,0xdd,0xa8,0x33,0x88,0x07,0xc7,0x31,
                    143:        0xb1,0x12,0x10,0x59,0x27,0x80,0xec,0x5f,
                    144:        0x60,0x51,0x7f,0xa9,0x19,0xb5,0x4a,0x0d,
                    145:        0x2d,0xe5,0x7a,0x9f,0x93,0xc9,0x9c,0xef,
                    146:        0xa0,0xe0,0x3b,0x4d,0xae,0x2a,0xf5,0xb0,
                    147:        0xc8,0xeb,0xbb,0x3c,0x83,0x53,0x99,0x61,
                    148:        0x17,0x2b,0x04,0x7e,0xba,0x77,0xd6,0x26,
                    149:        0xe1,0x69,0x14,0x63,0x55,0x21,0x0c,0x7d
                    150: };
                    151: 
                    152: static const uint_8t gfm2_s_box[256] = {
                    153:        0xc6,0xf8,0xee,0xf6,0xff,0xd6,0xde,0x91,
                    154:        0x60,0x02,0xce,0x56,0xe7,0xb5,0x4d,0xec,
                    155:        0x8f,0x1f,0x89,0xfa,0xef,0xb2,0x8e,0xfb,
                    156:        0x41,0xb3,0x5f,0x45,0x23,0x53,0xe4,0x9b,
                    157:        0x75,0xe1,0x3d,0x4c,0x6c,0x7e,0xf5,0x83,
                    158:        0x68,0x51,0xd1,0xf9,0xe2,0xab,0x62,0x2a,
                    159:        0x08,0x95,0x46,0x9d,0x30,0x37,0x0a,0x2f,
                    160:        0x0e,0x24,0x1b,0xdf,0xcd,0x4e,0x7f,0xea,
                    161:        0x12,0x1d,0x58,0x34,0x36,0xdc,0xb4,0x5b,
                    162:        0xa4,0x76,0xb7,0x7d,0x52,0xdd,0x5e,0x13,
                    163:        0xa6,0xb9,0x00,0xc1,0x40,0xe3,0x79,0xb6,
                    164:        0xd4,0x8d,0x67,0x72,0x94,0x98,0xb0,0x85,
                    165:        0xbb,0xc5,0x4f,0xed,0x86,0x9a,0x66,0x11,
                    166:        0x8a,0xe9,0x04,0xfe,0xa0,0x78,0x25,0x4b,
                    167:        0xa2,0x5d,0x80,0x05,0x3f,0x21,0x70,0xf1,
                    168:        0x63,0x77,0xaf,0x42,0x20,0xe5,0xfd,0xbf,
                    169:        0x81,0x18,0x26,0xc3,0xbe,0x35,0x88,0x2e,
                    170:        0x93,0x55,0xfc,0x7a,0xc8,0xba,0x32,0xe6,
                    171:        0xc0,0x19,0x9e,0xa3,0x44,0x54,0x3b,0x0b,
                    172:        0x8c,0xc7,0x6b,0x28,0xa7,0xbc,0x16,0xad,
                    173:        0xdb,0x64,0x74,0x14,0x92,0x0c,0x48,0xb8,
                    174:        0x9f,0xbd,0x43,0xc4,0x39,0x31,0xd3,0xf2,
                    175:        0xd5,0x8b,0x6e,0xda,0x01,0xb1,0x9c,0x49,
                    176:        0xd8,0xac,0xf3,0xcf,0xca,0xf4,0x47,0x10,
                    177:        0x6f,0xf0,0x4a,0x5c,0x38,0x57,0x73,0x97,
                    178:        0xcb,0xa1,0xe8,0x3e,0x96,0x61,0x0d,0x0f,
                    179:        0xe0,0x7c,0x71,0xcc,0x90,0x06,0xf7,0x1c,
                    180:        0xc2,0x6a,0xae,0x69,0x17,0x99,0x3a,0x27,
                    181:        0xd9,0xeb,0x2b,0x22,0xd2,0xa9,0x07,0x33,
                    182:        0x2d,0x3c,0x15,0xc9,0x87,0xaa,0x50,0xa5,
                    183:        0x03,0x59,0x09,0x1a,0x65,0xd7,0x84,0xd0,
                    184:        0x82,0x29,0x5a,0x1e,0x7b,0xa8,0x6d,0x2c
                    185: };
                    186: 
                    187: static const uint_8t gfm3_s_box[256] = {
                    188:        0xa5,0x84,0x99,0x8d,0x0d,0xbd,0xb1,0x54,
                    189:        0x50,0x03,0xa9,0x7d,0x19,0x62,0xe6,0x9a,
                    190:        0x45,0x9d,0x40,0x87,0x15,0xeb,0xc9,0x0b,
                    191:        0xec,0x67,0xfd,0xea,0xbf,0xf7,0x96,0x5b,
                    192:        0xc2,0x1c,0xae,0x6a,0x5a,0x41,0x02,0x4f,
                    193:        0x5c,0xf4,0x34,0x08,0x93,0x73,0x53,0x3f,
                    194:        0x0c,0x52,0x65,0x5e,0x28,0xa1,0x0f,0xb5,
                    195:        0x09,0x36,0x9b,0x3d,0x26,0x69,0xcd,0x9f,
                    196:        0x1b,0x9e,0x74,0x2e,0x2d,0xb2,0xee,0xfb,
                    197:        0xf6,0x4d,0x61,0xce,0x7b,0x3e,0x71,0x97,
                    198:        0xf5,0x68,0x00,0x2c,0x60,0x1f,0xc8,0xed,
                    199:        0xbe,0x46,0xd9,0x4b,0xde,0xd4,0xe8,0x4a,
                    200:        0x6b,0x2a,0xe5,0x16,0xc5,0xd7,0x55,0x94,
                    201:        0xcf,0x10,0x06,0x81,0xf0,0x44,0xba,0xe3,
                    202:        0xf3,0xfe,0xc0,0x8a,0xad,0xbc,0x48,0x04,
                    203:        0xdf,0xc1,0x75,0x63,0x30,0x1a,0x0e,0x6d,
                    204:        0x4c,0x14,0x35,0x2f,0xe1,0xa2,0xcc,0x39,
                    205:        0x57,0xf2,0x82,0x47,0xac,0xe7,0x2b,0x95,
                    206:        0xa0,0x98,0xd1,0x7f,0x66,0x7e,0xab,0x83,
                    207:        0xca,0x29,0xd3,0x3c,0x79,0xe2,0x1d,0x76,
                    208:        0x3b,0x56,0x4e,0x1e,0xdb,0x0a,0x6c,0xe4,
                    209:        0x5d,0x6e,0xef,0xa6,0xa8,0xa4,0x37,0x8b,
                    210:        0x32,0x43,0x59,0xb7,0x8c,0x64,0xd2,0xe0,
                    211:        0xb4,0xfa,0x07,0x25,0xaf,0x8e,0xe9,0x18,
                    212:        0xd5,0x88,0x6f,0x72,0x24,0xf1,0xc7,0x51,
                    213:        0x23,0x7c,0x9c,0x21,0xdd,0xdc,0x86,0x85,
                    214:        0x90,0x42,0xc4,0xaa,0xd8,0x05,0x01,0x12,
                    215:        0xa3,0x5f,0xf9,0xd0,0x91,0x58,0x27,0xb9,
                    216:        0x38,0x13,0xb3,0x33,0xbb,0x70,0x89,0xa7,
                    217:        0xb6,0x22,0x92,0x20,0x49,0xff,0x78,0x7a,
                    218:        0x8f,0xf8,0x80,0x17,0xda,0x31,0xc6,0xb8,
                    219:        0xc3,0xb0,0x77,0x11,0xcb,0xfc,0xd6,0x3a
                    220: };
                    221: 
                    222: static const uint_8t gfmul_9[256] = {
                    223:        0x00,0x09,0x12,0x1b,0x24,0x2d,0x36,0x3f,
                    224:        0x48,0x41,0x5a,0x53,0x6c,0x65,0x7e,0x77,
                    225:        0x90,0x99,0x82,0x8b,0xb4,0xbd,0xa6,0xaf,
                    226:        0xd8,0xd1,0xca,0xc3,0xfc,0xf5,0xee,0xe7,
                    227:        0x3b,0x32,0x29,0x20,0x1f,0x16,0x0d,0x04,
                    228:        0x73,0x7a,0x61,0x68,0x57,0x5e,0x45,0x4c,
                    229:        0xab,0xa2,0xb9,0xb0,0x8f,0x86,0x9d,0x94,
                    230:        0xe3,0xea,0xf1,0xf8,0xc7,0xce,0xd5,0xdc,
                    231:        0x76,0x7f,0x64,0x6d,0x52,0x5b,0x40,0x49,
                    232:        0x3e,0x37,0x2c,0x25,0x1a,0x13,0x08,0x01,
                    233:        0xe6,0xef,0xf4,0xfd,0xc2,0xcb,0xd0,0xd9,
                    234:        0xae,0xa7,0xbc,0xb5,0x8a,0x83,0x98,0x91,
                    235:        0x4d,0x44,0x5f,0x56,0x69,0x60,0x7b,0x72,
                    236:        0x05,0x0c,0x17,0x1e,0x21,0x28,0x33,0x3a,
                    237:        0xdd,0xd4,0xcf,0xc6,0xf9,0xf0,0xeb,0xe2,
                    238:        0x95,0x9c,0x87,0x8e,0xb1,0xb8,0xa3,0xaa,
                    239:        0xec,0xe5,0xfe,0xf7,0xc8,0xc1,0xda,0xd3,
                    240:        0xa4,0xad,0xb6,0xbf,0x80,0x89,0x92,0x9b,
                    241:        0x7c,0x75,0x6e,0x67,0x58,0x51,0x4a,0x43,
                    242:        0x34,0x3d,0x26,0x2f,0x10,0x19,0x02,0x0b,
                    243:        0xd7,0xde,0xc5,0xcc,0xf3,0xfa,0xe1,0xe8,
                    244:        0x9f,0x96,0x8d,0x84,0xbb,0xb2,0xa9,0xa0,
                    245:        0x47,0x4e,0x55,0x5c,0x63,0x6a,0x71,0x78,
                    246:        0x0f,0x06,0x1d,0x14,0x2b,0x22,0x39,0x30,
                    247:        0x9a,0x93,0x88,0x81,0xbe,0xb7,0xac,0xa5,
                    248:        0xd2,0xdb,0xc0,0xc9,0xf6,0xff,0xe4,0xed,
                    249:        0x0a,0x03,0x18,0x11,0x2e,0x27,0x3c,0x35,
                    250:        0x42,0x4b,0x50,0x59,0x66,0x6f,0x74,0x7d,
                    251:        0xa1,0xa8,0xb3,0xba,0x85,0x8c,0x97,0x9e,
                    252:        0xe9,0xe0,0xfb,0xf2,0xcd,0xc4,0xdf,0xd6,
                    253:        0x31,0x38,0x23,0x2a,0x15,0x1c,0x07,0x0e,
                    254:        0x79,0x70,0x6b,0x62,0x5d,0x54,0x4f,0x46
                    255: };
                    256: 
                    257: static const uint_8t gfmul_b[256] = {
                    258:        0x00,0x0b,0x16,0x1d,0x2c,0x27,0x3a,0x31,
                    259:        0x58,0x53,0x4e,0x45,0x74,0x7f,0x62,0x69,
                    260:        0xb0,0xbb,0xa6,0xad,0x9c,0x97,0x8a,0x81,
                    261:        0xe8,0xe3,0xfe,0xf5,0xc4,0xcf,0xd2,0xd9,
                    262:        0x7b,0x70,0x6d,0x66,0x57,0x5c,0x41,0x4a,
                    263:        0x23,0x28,0x35,0x3e,0x0f,0x04,0x19,0x12,
                    264:        0xcb,0xc0,0xdd,0xd6,0xe7,0xec,0xf1,0xfa,
                    265:        0x93,0x98,0x85,0x8e,0xbf,0xb4,0xa9,0xa2,
                    266:        0xf6,0xfd,0xe0,0xeb,0xda,0xd1,0xcc,0xc7,
                    267:        0xae,0xa5,0xb8,0xb3,0x82,0x89,0x94,0x9f,
                    268:        0x46,0x4d,0x50,0x5b,0x6a,0x61,0x7c,0x77,
                    269:        0x1e,0x15,0x08,0x03,0x32,0x39,0x24,0x2f,
                    270:        0x8d,0x86,0x9b,0x90,0xa1,0xaa,0xb7,0xbc,
                    271:        0xd5,0xde,0xc3,0xc8,0xf9,0xf2,0xef,0xe4,
                    272:        0x3d,0x36,0x2b,0x20,0x11,0x1a,0x07,0x0c,
                    273:        0x65,0x6e,0x73,0x78,0x49,0x42,0x5f,0x54,
                    274:        0xf7,0xfc,0xe1,0xea,0xdb,0xd0,0xcd,0xc6,
                    275:        0xaf,0xa4,0xb9,0xb2,0x83,0x88,0x95,0x9e,
                    276:        0x47,0x4c,0x51,0x5a,0x6b,0x60,0x7d,0x76,
                    277:        0x1f,0x14,0x09,0x02,0x33,0x38,0x25,0x2e,
                    278:        0x8c,0x87,0x9a,0x91,0xa0,0xab,0xb6,0xbd,
                    279:        0xd4,0xdf,0xc2,0xc9,0xf8,0xf3,0xee,0xe5,
                    280:        0x3c,0x37,0x2a,0x21,0x10,0x1b,0x06,0x0d,
                    281:        0x64,0x6f,0x72,0x79,0x48,0x43,0x5e,0x55,
                    282:        0x01,0x0a,0x17,0x1c,0x2d,0x26,0x3b,0x30,
                    283:        0x59,0x52,0x4f,0x44,0x75,0x7e,0x63,0x68,
                    284:        0xb1,0xba,0xa7,0xac,0x9d,0x96,0x8b,0x80,
                    285:        0xe9,0xe2,0xff,0xf4,0xc5,0xce,0xd3,0xd8,
                    286:        0x7a,0x71,0x6c,0x67,0x56,0x5d,0x40,0x4b,
                    287:        0x22,0x29,0x34,0x3f,0x0e,0x05,0x18,0x13,
                    288:        0xca,0xc1,0xdc,0xd7,0xe6,0xed,0xf0,0xfb,
                    289:        0x92,0x99,0x84,0x8f,0xbe,0xb5,0xa8,0xa3
                    290: };
                    291: 
                    292: static const uint_8t gfmul_d[256] = {
                    293:        0x00,0x0d,0x1a,0x17,0x34,0x39,0x2e,0x23,
                    294:        0x68,0x65,0x72,0x7f,0x5c,0x51,0x46,0x4b,
                    295:        0xd0,0xdd,0xca,0xc7,0xe4,0xe9,0xfe,0xf3,
                    296:        0xb8,0xb5,0xa2,0xaf,0x8c,0x81,0x96,0x9b,
                    297:        0xbb,0xb6,0xa1,0xac,0x8f,0x82,0x95,0x98,
                    298:        0xd3,0xde,0xc9,0xc4,0xe7,0xea,0xfd,0xf0,
                    299:        0x6b,0x66,0x71,0x7c,0x5f,0x52,0x45,0x48,
                    300:        0x03,0x0e,0x19,0x14,0x37,0x3a,0x2d,0x20,
                    301:        0x6d,0x60,0x77,0x7a,0x59,0x54,0x43,0x4e,
                    302:        0x05,0x08,0x1f,0x12,0x31,0x3c,0x2b,0x26,
                    303:        0xbd,0xb0,0xa7,0xaa,0x89,0x84,0x93,0x9e,
                    304:        0xd5,0xd8,0xcf,0xc2,0xe1,0xec,0xfb,0xf6,
                    305:        0xd6,0xdb,0xcc,0xc1,0xe2,0xef,0xf8,0xf5,
                    306:        0xbe,0xb3,0xa4,0xa9,0x8a,0x87,0x90,0x9d,
                    307:        0x06,0x0b,0x1c,0x11,0x32,0x3f,0x28,0x25,
                    308:        0x6e,0x63,0x74,0x79,0x5a,0x57,0x40,0x4d,
                    309:        0xda,0xd7,0xc0,0xcd,0xee,0xe3,0xf4,0xf9,
                    310:        0xb2,0xbf,0xa8,0xa5,0x86,0x8b,0x9c,0x91,
                    311:        0x0a,0x07,0x10,0x1d,0x3e,0x33,0x24,0x29,
                    312:        0x62,0x6f,0x78,0x75,0x56,0x5b,0x4c,0x41,
                    313:        0x61,0x6c,0x7b,0x76,0x55,0x58,0x4f,0x42,
                    314:        0x09,0x04,0x13,0x1e,0x3d,0x30,0x27,0x2a,
                    315:        0xb1,0xbc,0xab,0xa6,0x85,0x88,0x9f,0x92,
                    316:        0xd9,0xd4,0xc3,0xce,0xed,0xe0,0xf7,0xfa,
                    317:        0xb7,0xba,0xad,0xa0,0x83,0x8e,0x99,0x94,
                    318:        0xdf,0xd2,0xc5,0xc8,0xeb,0xe6,0xf1,0xfc,
                    319:        0x67,0x6a,0x7d,0x70,0x53,0x5e,0x49,0x44,
                    320:        0x0f,0x02,0x15,0x18,0x3b,0x36,0x21,0x2c,
                    321:        0x0c,0x01,0x16,0x1b,0x38,0x35,0x22,0x2f,
                    322:        0x64,0x69,0x7e,0x73,0x50,0x5d,0x4a,0x47,
                    323:        0xdc,0xd1,0xc6,0xcb,0xe8,0xe5,0xf2,0xff,
                    324:        0xb4,0xb9,0xae,0xa3,0x80,0x8d,0x9a,0x97
                    325: };
                    326: 
                    327: static const uint_8t gfmul_e[256] = {
                    328:        0x00,0x0e,0x1c,0x12,0x38,0x36,0x24,0x2a,
                    329:        0x70,0x7e,0x6c,0x62,0x48,0x46,0x54,0x5a,
                    330:        0xe0,0xee,0xfc,0xf2,0xd8,0xd6,0xc4,0xca,
                    331:        0x90,0x9e,0x8c,0x82,0xa8,0xa6,0xb4,0xba,
                    332:        0xdb,0xd5,0xc7,0xc9,0xe3,0xed,0xff,0xf1,
                    333:        0xab,0xa5,0xb7,0xb9,0x93,0x9d,0x8f,0x81,
                    334:        0x3b,0x35,0x27,0x29,0x03,0x0d,0x1f,0x11,
                    335:        0x4b,0x45,0x57,0x59,0x73,0x7d,0x6f,0x61,
                    336:        0xad,0xa3,0xb1,0xbf,0x95,0x9b,0x89,0x87,
                    337:        0xdd,0xd3,0xc1,0xcf,0xe5,0xeb,0xf9,0xf7,
                    338:        0x4d,0x43,0x51,0x5f,0x75,0x7b,0x69,0x67,
                    339:        0x3d,0x33,0x21,0x2f,0x05,0x0b,0x19,0x17,
                    340:        0x76,0x78,0x6a,0x64,0x4e,0x40,0x52,0x5c,
                    341:        0x06,0x08,0x1a,0x14,0x3e,0x30,0x22,0x2c,
                    342:        0x96,0x98,0x8a,0x84,0xae,0xa0,0xb2,0xbc,
                    343:        0xe6,0xe8,0xfa,0xf4,0xde,0xd0,0xc2,0xcc,
                    344:        0x41,0x4f,0x5d,0x53,0x79,0x77,0x65,0x6b,
                    345:        0x31,0x3f,0x2d,0x23,0x09,0x07,0x15,0x1b,
                    346:        0xa1,0xaf,0xbd,0xb3,0x99,0x97,0x85,0x8b,
                    347:        0xd1,0xdf,0xcd,0xc3,0xe9,0xe7,0xf5,0xfb,
                    348:        0x9a,0x94,0x86,0x88,0xa2,0xac,0xbe,0xb0,
                    349:        0xea,0xe4,0xf6,0xf8,0xd2,0xdc,0xce,0xc0,
                    350:        0x7a,0x74,0x66,0x68,0x42,0x4c,0x5e,0x50,
                    351:        0x0a,0x04,0x16,0x18,0x32,0x3c,0x2e,0x20,
                    352:        0xec,0xe2,0xf0,0xfe,0xd4,0xda,0xc8,0xc6,
                    353:        0x9c,0x92,0x80,0x8e,0xa4,0xaa,0xb8,0xb6,
                    354:        0x0c,0x02,0x10,0x1e,0x34,0x3a,0x28,0x26,
                    355:        0x7c,0x72,0x60,0x6e,0x44,0x4a,0x58,0x56,
                    356:        0x37,0x39,0x2b,0x25,0x0f,0x01,0x13,0x1d,
                    357:        0x47,0x49,0x5b,0x55,0x7f,0x71,0x63,0x6d,
                    358:        0xd7,0xd9,0xcb,0xc5,0xef,0xe1,0xf3,0xfd,
                    359:        0xa7,0xa9,0xbb,0xb5,0x9f,0x91,0x83,0x8d
                    360: };
                    361: 
                    362: #if defined( HAVE_UINT_32T )
                    363:   typedef unsigned long uint_32t;
                    364: #endif
                    365: 
                    366: #if defined( HAVE_MEMCPY )
                    367: #  define block_copy(d, s, l) memcpy(d, s, l)
                    368: #  define block16_copy(d, s)  memcpy(d, s, N_BLOCK)
                    369: #else
                    370: #  define block_copy(d, s, l) copy_block(d, s, l)
                    371: #  define block16_copy(d, s)  copy_block16(d, s)
                    372: #endif
                    373: 
                    374: /* block size 'nn' must be a multiple of four */
                    375: 
                    376: static void copy_block16( void *d, const void *s )
                    377: {
                    378: #if defined( HAVE_UINT_32T )
                    379:     ((uint_32t*)d)[ 0] = ((uint_32t*)s)[ 0];
                    380:     ((uint_32t*)d)[ 1] = ((uint_32t*)s)[ 1];
                    381:     ((uint_32t*)d)[ 2] = ((uint_32t*)s)[ 2];
                    382:     ((uint_32t*)d)[ 3] = ((uint_32t*)s)[ 3];
                    383: #else
                    384:     ((uint_8t*)d)[ 0] = ((uint_8t*)s)[ 0];
                    385:     ((uint_8t*)d)[ 1] = ((uint_8t*)s)[ 1];
                    386:     ((uint_8t*)d)[ 2] = ((uint_8t*)s)[ 2];
                    387:     ((uint_8t*)d)[ 3] = ((uint_8t*)s)[ 3];
                    388:     ((uint_8t*)d)[ 4] = ((uint_8t*)s)[ 4];
                    389:     ((uint_8t*)d)[ 5] = ((uint_8t*)s)[ 5];
                    390:     ((uint_8t*)d)[ 6] = ((uint_8t*)s)[ 6];
                    391:     ((uint_8t*)d)[ 7] = ((uint_8t*)s)[ 7];
                    392:     ((uint_8t*)d)[ 8] = ((uint_8t*)s)[ 8];
                    393:     ((uint_8t*)d)[ 9] = ((uint_8t*)s)[ 9];
                    394:     ((uint_8t*)d)[10] = ((uint_8t*)s)[10];
                    395:     ((uint_8t*)d)[11] = ((uint_8t*)s)[11];
                    396:     ((uint_8t*)d)[12] = ((uint_8t*)s)[12];
                    397:     ((uint_8t*)d)[13] = ((uint_8t*)s)[13];
                    398:     ((uint_8t*)d)[14] = ((uint_8t*)s)[14];
                    399:     ((uint_8t*)d)[15] = ((uint_8t*)s)[15];
                    400: #endif
                    401: }
                    402: 
                    403: static void copy_block( void * d, void *s, uint_8t nn )
                    404: {
                    405:     while( nn-- )
                    406:         *((uint_8t*)d)++ = *((uint_8t*)s)++;
                    407: }
                    408: 
                    409: static void xor_block( void *d, const void *s )
                    410: {
                    411: #if defined( HAVE_UINT_32T )
                    412:     ((uint_32t*)d)[ 0] ^= ((uint_32t*)s)[ 0];
                    413:     ((uint_32t*)d)[ 1] ^= ((uint_32t*)s)[ 1];
                    414:     ((uint_32t*)d)[ 2] ^= ((uint_32t*)s)[ 2];
                    415:     ((uint_32t*)d)[ 3] ^= ((uint_32t*)s)[ 3];
                    416: #else
                    417:     ((uint_8t*)d)[ 0] ^= ((uint_8t*)s)[ 0];
                    418:     ((uint_8t*)d)[ 1] ^= ((uint_8t*)s)[ 1];
                    419:     ((uint_8t*)d)[ 2] ^= ((uint_8t*)s)[ 2];
                    420:     ((uint_8t*)d)[ 3] ^= ((uint_8t*)s)[ 3];
                    421:     ((uint_8t*)d)[ 4] ^= ((uint_8t*)s)[ 4];
                    422:     ((uint_8t*)d)[ 5] ^= ((uint_8t*)s)[ 5];
                    423:     ((uint_8t*)d)[ 6] ^= ((uint_8t*)s)[ 6];
                    424:     ((uint_8t*)d)[ 7] ^= ((uint_8t*)s)[ 7];
                    425:     ((uint_8t*)d)[ 8] ^= ((uint_8t*)s)[ 8];
                    426:     ((uint_8t*)d)[ 9] ^= ((uint_8t*)s)[ 9];
                    427:     ((uint_8t*)d)[10] ^= ((uint_8t*)s)[10];
                    428:     ((uint_8t*)d)[11] ^= ((uint_8t*)s)[11];
                    429:     ((uint_8t*)d)[12] ^= ((uint_8t*)s)[12];
                    430:     ((uint_8t*)d)[13] ^= ((uint_8t*)s)[13];
                    431:     ((uint_8t*)d)[14] ^= ((uint_8t*)s)[14];
                    432:     ((uint_8t*)d)[15] ^= ((uint_8t*)s)[15];
                    433: #endif
                    434: }
                    435: 
                    436: static void copy_and_key( void *d, const void *s, const void *k )
                    437: {
                    438: #if defined( HAVE_UINT_32T )
                    439:     ((uint_32t*)d)[ 0] = ((uint_32t*)s)[ 0] ^ ((uint_32t*)k)[ 0];
                    440:     ((uint_32t*)d)[ 1] = ((uint_32t*)s)[ 1] ^ ((uint_32t*)k)[ 1];
                    441:     ((uint_32t*)d)[ 2] = ((uint_32t*)s)[ 2] ^ ((uint_32t*)k)[ 2];
                    442:     ((uint_32t*)d)[ 3] = ((uint_32t*)s)[ 3] ^ ((uint_32t*)k)[ 3];
                    443: #elif 1
                    444:     ((uint_8t*)d)[ 0] = ((uint_8t*)s)[ 0] ^ ((uint_8t*)k)[ 0];
                    445:     ((uint_8t*)d)[ 1] = ((uint_8t*)s)[ 1] ^ ((uint_8t*)k)[ 1];
                    446:     ((uint_8t*)d)[ 2] = ((uint_8t*)s)[ 2] ^ ((uint_8t*)k)[ 2];
                    447:     ((uint_8t*)d)[ 3] = ((uint_8t*)s)[ 3] ^ ((uint_8t*)k)[ 3];
                    448:     ((uint_8t*)d)[ 4] = ((uint_8t*)s)[ 4] ^ ((uint_8t*)k)[ 4];
                    449:     ((uint_8t*)d)[ 5] = ((uint_8t*)s)[ 5] ^ ((uint_8t*)k)[ 5];
                    450:     ((uint_8t*)d)[ 6] = ((uint_8t*)s)[ 6] ^ ((uint_8t*)k)[ 6];
                    451:     ((uint_8t*)d)[ 7] = ((uint_8t*)s)[ 7] ^ ((uint_8t*)k)[ 7];
                    452:     ((uint_8t*)d)[ 8] = ((uint_8t*)s)[ 8] ^ ((uint_8t*)k)[ 8];
                    453:     ((uint_8t*)d)[ 9] = ((uint_8t*)s)[ 9] ^ ((uint_8t*)k)[ 9];
                    454:     ((uint_8t*)d)[10] = ((uint_8t*)s)[10] ^ ((uint_8t*)k)[10];
                    455:     ((uint_8t*)d)[11] = ((uint_8t*)s)[11] ^ ((uint_8t*)k)[11];
                    456:     ((uint_8t*)d)[12] = ((uint_8t*)s)[12] ^ ((uint_8t*)k)[12];
                    457:     ((uint_8t*)d)[13] = ((uint_8t*)s)[13] ^ ((uint_8t*)k)[13];
                    458:     ((uint_8t*)d)[14] = ((uint_8t*)s)[14] ^ ((uint_8t*)k)[14];
                    459:     ((uint_8t*)d)[15] = ((uint_8t*)s)[15] ^ ((uint_8t*)k)[15];
                    460: #else
                    461:     block16_copy(d, s);
                    462:     xor_block(d, k);
                    463: #endif
                    464: }
                    465: 
                    466: static void add_round_key( uint_8t d[N_BLOCK], const uint_8t k[N_BLOCK] )
                    467: {
                    468:     xor_block(d, k);
                    469: }
                    470: 
                    471: static void shift_sub_rows( uint_8t st[N_BLOCK] )
                    472: {   uint_8t tt;
                    473: 
                    474:     st[ 0] = s_box[st[ 0]]; st[ 4] = s_box[st[ 4]];
                    475:     st[ 8] = s_box[st[ 8]]; st[12] = s_box[st[12]];
                    476: 
                    477:     tt = st[1]; st[ 1] = s_box[st[ 5]]; st[ 5] = s_box[st[ 9]];
                    478:     st[ 9] = s_box[st[13]]; st[13] = s_box[ tt ];
                    479: 
                    480:     tt = st[2]; st[ 2] = s_box[st[10]]; st[10] = s_box[ tt ];
                    481:     tt = st[6]; st[ 6] = s_box[st[14]]; st[14] = s_box[ tt ];
                    482: 
                    483:     tt = st[15]; st[15] = s_box[st[11]]; st[11] = s_box[st[ 7]];
                    484:     st[ 7] = s_box[st[ 3]]; st[ 3] = s_box[ tt ];
                    485: }
                    486: 
                    487: static void inv_shift_sub_rows( uint_8t st[N_BLOCK] )
                    488: {   uint_8t tt;
                    489: 
                    490:     st[ 0] = inv_s_box[st[ 0]]; st[ 4] = inv_s_box[st[ 4]];
                    491:     st[ 8] = inv_s_box[st[ 8]]; st[12] = inv_s_box[st[12]];
                    492: 
                    493:     tt = st[13]; st[13] = inv_s_box[st[9]]; st[ 9] = inv_s_box[st[5]];
                    494:     st[ 5] = inv_s_box[st[1]]; st[ 1] = inv_s_box[ tt ];
                    495: 
                    496:     tt = st[2]; st[ 2] = inv_s_box[st[10]]; st[10] = inv_s_box[ tt ];
                    497:     tt = st[6]; st[ 6] = inv_s_box[st[14]]; st[14] = inv_s_box[ tt ];
                    498: 
                    499:     tt = st[3]; st[ 3] = inv_s_box[st[ 7]]; st[ 7] = inv_s_box[st[11]];
                    500:     st[11] = inv_s_box[st[15]]; st[15] = inv_s_box[ tt ];
                    501: }
                    502: 
                    503: #if defined( VERSION_1 )
                    504:   static void mix_sub_columns( uint_8t dt[N_BLOCK] )
                    505:   { uint_8t st[N_BLOCK];
                    506:     block16_copy(st, dt);
                    507: #else
                    508:   static void mix_sub_columns( uint_8t dt[N_BLOCK], uint_8t st[N_BLOCK] )
                    509:   {
                    510: #endif
                    511:     dt[ 0] = gfm2_s_box[st[0]] ^ gfm3_s_box[st[5]] ^ s_box[st[10]] ^ s_box[st[15]];
                    512:     dt[ 1] = s_box[st[0]] ^ gfm2_s_box[st[5]] ^ gfm3_s_box[st[10]] ^ s_box[st[15]];
                    513:     dt[ 2] = s_box[st[0]] ^ s_box[st[5]] ^ gfm2_s_box[st[10]] ^ gfm3_s_box[st[15]];
                    514:     dt[ 3] = gfm3_s_box[st[0]] ^ s_box[st[5]] ^ s_box[st[10]] ^ gfm2_s_box[st[15]];
                    515: 
                    516:     dt[ 4] = gfm2_s_box[st[4]] ^ gfm3_s_box[st[9]] ^ s_box[st[14]] ^ s_box[st[3]];
                    517:     dt[ 5] = s_box[st[4]] ^ gfm2_s_box[st[9]] ^ gfm3_s_box[st[14]] ^ s_box[st[3]];
                    518:     dt[ 6] = s_box[st[4]] ^ s_box[st[9]] ^ gfm2_s_box[st[14]] ^ gfm3_s_box[st[3]];
                    519:     dt[ 7] = gfm3_s_box[st[4]] ^ s_box[st[9]] ^ s_box[st[14]] ^ gfm2_s_box[st[3]];
                    520: 
                    521:     dt[ 8] = gfm2_s_box[st[8]] ^ gfm3_s_box[st[13]] ^ s_box[st[2]] ^ s_box[st[7]];
                    522:     dt[ 9] = s_box[st[8]] ^ gfm2_s_box[st[13]] ^ gfm3_s_box[st[2]] ^ s_box[st[7]];
                    523:     dt[10] = s_box[st[8]] ^ s_box[st[13]] ^ gfm2_s_box[st[2]] ^ gfm3_s_box[st[7]];
                    524:     dt[11] = gfm3_s_box[st[8]] ^ s_box[st[13]] ^ s_box[st[2]] ^ gfm2_s_box[st[7]];
                    525: 
                    526:     dt[12] = gfm2_s_box[st[12]] ^ gfm3_s_box[st[1]] ^ s_box[st[6]] ^ s_box[st[11]];
                    527:     dt[13] = s_box[st[12]] ^ gfm2_s_box[st[1]] ^ gfm3_s_box[st[6]] ^ s_box[st[11]];
                    528:     dt[14] = s_box[st[12]] ^ s_box[st[1]] ^ gfm2_s_box[st[6]] ^ gfm3_s_box[st[11]];
                    529:     dt[15] = gfm3_s_box[st[12]] ^ s_box[st[1]] ^ s_box[st[6]] ^ gfm2_s_box[st[11]];
                    530:   }
                    531: 
                    532: #if defined( VERSION_1 )
                    533:   static void inv_mix_sub_columns( uint_8t dt[N_BLOCK] )
                    534:   { uint_8t st[N_BLOCK];
                    535:     block16_copy(st, dt);
                    536: #else
                    537:   static void inv_mix_sub_columns( uint_8t dt[N_BLOCK], uint_8t st[N_BLOCK] )
                    538:   {
                    539: #endif
                    540:     dt[ 0] = inv_s_box[gfmul_e[st[ 0]] ^ gfmul_b[st[ 1]] ^ gfmul_d[st[ 2]] ^ gfmul_9[st[ 3]]];
                    541:     dt[ 5] = inv_s_box[gfmul_9[st[ 0]] ^ gfmul_e[st[ 1]] ^ gfmul_b[st[ 2]] ^ gfmul_d[st[ 3]]];
                    542:     dt[10] = inv_s_box[gfmul_d[st[ 0]] ^ gfmul_9[st[ 1]] ^ gfmul_e[st[ 2]] ^ gfmul_b[st[ 3]]];
                    543:     dt[15] = inv_s_box[gfmul_b[st[ 0]] ^ gfmul_d[st[ 1]] ^ gfmul_9[st[ 2]] ^ gfmul_e[st[ 3]]];
                    544: 
                    545:     dt[ 4] = inv_s_box[gfmul_e[st[ 4]] ^ gfmul_b[st[ 5]] ^ gfmul_d[st[ 6]] ^ gfmul_9[st[ 7]]];
                    546:     dt[ 9] = inv_s_box[gfmul_9[st[ 4]] ^ gfmul_e[st[ 5]] ^ gfmul_b[st[ 6]] ^ gfmul_d[st[ 7]]];
                    547:     dt[14] = inv_s_box[gfmul_d[st[ 4]] ^ gfmul_9[st[ 5]] ^ gfmul_e[st[ 6]] ^ gfmul_b[st[ 7]]];
                    548:     dt[ 3] = inv_s_box[gfmul_b[st[ 4]] ^ gfmul_d[st[ 5]] ^ gfmul_9[st[ 6]] ^ gfmul_e[st[ 7]]];
                    549: 
                    550:     dt[ 8] = inv_s_box[gfmul_e[st[ 8]] ^ gfmul_b[st[ 9]] ^ gfmul_d[st[10]] ^ gfmul_9[st[11]]];
                    551:     dt[13] = inv_s_box[gfmul_9[st[ 8]] ^ gfmul_e[st[ 9]] ^ gfmul_b[st[10]] ^ gfmul_d[st[11]]];
                    552:     dt[ 2] = inv_s_box[gfmul_d[st[ 8]] ^ gfmul_9[st[ 9]] ^ gfmul_e[st[10]] ^ gfmul_b[st[11]]];
                    553:     dt[ 7] = inv_s_box[gfmul_b[st[ 8]] ^ gfmul_d[st[ 9]] ^ gfmul_9[st[10]] ^ gfmul_e[st[11]]];
                    554: 
                    555:     dt[12] = inv_s_box[gfmul_e[st[12]] ^ gfmul_b[st[13]] ^ gfmul_d[st[14]] ^ gfmul_9[st[15]]];
                    556:     dt[ 1] = inv_s_box[gfmul_9[st[12]] ^ gfmul_e[st[13]] ^ gfmul_b[st[14]] ^ gfmul_d[st[15]]];
                    557:     dt[ 6] = inv_s_box[gfmul_d[st[12]] ^ gfmul_9[st[13]] ^ gfmul_e[st[14]] ^ gfmul_b[st[15]]];
                    558:     dt[11] = inv_s_box[gfmul_b[st[12]] ^ gfmul_d[st[13]] ^ gfmul_9[st[14]] ^ gfmul_e[st[15]]];
                    559:   }
                    560: 
                    561: #if defined( AES_ENC_PREKEYED ) || defined( AES_DEC_PREKEYED )
                    562: 
                    563: /*  Set the cipher key for the pre-keyed version */
                    564: 
                    565: return_type aes_set_key( const unsigned char key[], length_type keylen, aes_context ctx[1] )
                    566: {
                    567:     uint_8t cc, rc, hi;
                    568: 
                    569:     switch( keylen )
                    570:     {
                    571:     case 16:
                    572:     case 128:
                    573:         keylen = 16;
                    574:         break;
                    575:     case 24:
                    576:     case 192:
                    577:         keylen = 24;
                    578:         break;
                    579:     case 32:
                    580:     case 256:
                    581:         keylen = 32;
                    582:         break;
                    583:     default:
                    584:         ctx->rnd = 0;
                    585:         return -1;
                    586:     }
                    587:     block_copy(ctx->ksch, key, keylen);
                    588:     hi = (keylen + 28) << 2;
                    589:     ctx->rnd = (hi >> 4) - 1;
                    590:     for( cc = keylen, rc = 1; cc < hi; cc += 4 )
                    591:     {   uint_8t tt, t0, t1, t2, t3;
                    592: 
                    593:         t0 = ctx->ksch[cc - 4];
                    594:         t1 = ctx->ksch[cc - 3];
                    595:         t2 = ctx->ksch[cc - 2];
                    596:         t3 = ctx->ksch[cc - 1];
                    597:         if( cc % keylen == 0 )
                    598:         {
                    599:             tt = t0;
                    600:             t0 = s_box[t1] ^ rc;
                    601:             t1 = s_box[t2];
                    602:             t2 = s_box[t3];
                    603:             t3 = s_box[tt];
                    604:             rc = f2(rc);
                    605:         }
                    606:         else if( keylen > 24 && cc % keylen == 16 )
                    607:         {
                    608:             t0 = s_box[t0];
                    609:             t1 = s_box[t1];
                    610:             t2 = s_box[t2];
                    611:             t3 = s_box[t3];
                    612:         }
                    613:         tt = cc - keylen;
                    614:         ctx->ksch[cc + 0] = ctx->ksch[tt + 0] ^ t0;
                    615:         ctx->ksch[cc + 1] = ctx->ksch[tt + 1] ^ t1;
                    616:         ctx->ksch[cc + 2] = ctx->ksch[tt + 2] ^ t2;
                    617:         ctx->ksch[cc + 3] = ctx->ksch[tt + 3] ^ t3;
                    618:     }
                    619:     return 0;
                    620: }
                    621: 
                    622: #endif
                    623: 
                    624: #if defined( AES_ENC_PREKEYED )
                    625: 
                    626: /*  Encrypt a single block of 16 bytes */
                    627: 
                    628: return_type aes_encrypt( const unsigned char in[N_BLOCK], unsigned char  out[N_BLOCK], const aes_context ctx[1] )
                    629: {
                    630:     if( ctx->rnd )
                    631:     {
                    632:         uint_8t s1[N_BLOCK], r;
                    633:         copy_and_key( s1, in, ctx->ksch );
                    634: 
                    635:         for( r = 1 ; r < ctx->rnd ; ++r )
                    636: #if defined( VERSION_1 )
                    637:         {
                    638:             mix_sub_columns( s1 );
                    639:             add_round_key( s1, ctx->ksch + r * N_BLOCK);
                    640:         }
                    641: #else
                    642:         {   uint_8t s2[N_BLOCK];
                    643:             mix_sub_columns( s2, s1 );
                    644:             copy_and_key( s1, s2, ctx->ksch + r * N_BLOCK);
                    645:         }
                    646: #endif
                    647:         shift_sub_rows( s1 );
                    648:         copy_and_key( out, s1, ctx->ksch + r * N_BLOCK );
                    649:     }
                    650:     else
                    651:         return -1;
                    652:     return 0;
                    653: }
                    654: 
                    655: #endif
                    656: 
                    657: #if defined( AES_DEC_PREKEYED )
                    658: 
                    659: /*  Decrypt a single block of 16 bytes */
                    660: 
                    661: return_type aes_decrypt( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK], const aes_context ctx[1] )
                    662: {
                    663:     if( ctx->rnd )
                    664:     {
                    665:         uint_8t s1[N_BLOCK], r;
                    666:         copy_and_key( s1, in, ctx->ksch + ctx->rnd * N_BLOCK );
                    667:         inv_shift_sub_rows( s1 );
                    668: 
                    669:         for( r = ctx->rnd ; --r ; )
                    670: #if defined( VERSION_1 )
                    671:         {
                    672:             add_round_key( s1, ctx->ksch + r * N_BLOCK );
                    673:             inv_mix_sub_columns( s1 );
                    674:         }
                    675: #else
                    676:         {   uint_8t s2[N_BLOCK];
                    677:             copy_and_key( s2, s1, ctx->ksch + r * N_BLOCK );
                    678:             inv_mix_sub_columns( s1, s2 );
                    679:         }
                    680: #endif
                    681:         copy_and_key( out, s1, ctx->ksch );
                    682:     }
                    683:     else
                    684:         return -1;
                    685:     return 0;
                    686: }
                    687: 
                    688: #endif
                    689: 
                    690: #if defined( AES_ENC_128_OTFK )
                    691: 
                    692: /*  The 'on the fly' encryption key update for for 128 bit keys */
                    693: 
                    694: static void update_encrypt_key_128( uint_8t k[N_BLOCK], uint_8t *rc )
                    695: {   uint_8t cc;
                    696: 
                    697:     k[0] ^= s_box[k[13]] ^ *rc;
                    698:     k[1] ^= s_box[k[14]];
                    699:     k[2] ^= s_box[k[15]];
                    700:     k[3] ^= s_box[k[12]];
                    701:     *rc = f2( *rc );
                    702: 
                    703:     for(cc = 4; cc < 16; cc += 4 )
                    704:     {
                    705:         k[cc + 0] ^= k[cc - 4];
                    706:         k[cc + 1] ^= k[cc - 3];
                    707:         k[cc + 2] ^= k[cc - 2];
                    708:         k[cc + 3] ^= k[cc - 1];
                    709:     }
                    710: }
                    711: 
                    712: /*  Encrypt a single block of 16 bytes with 'on the fly' 128 bit keying */
                    713: 
                    714: void aes_encrypt_128( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK],
                    715:                      const unsigned char key[N_BLOCK], unsigned char o_key[N_BLOCK] )
                    716: {   uint_8t s1[N_BLOCK], r, rc = 1;
                    717: 
                    718:     if(o_key != key)
                    719:         block16_copy( o_key, key );
                    720:     copy_and_key( s1, in, o_key );
                    721: 
                    722:     for( r = 1 ; r < 10 ; ++r )
                    723: #if defined( VERSION_1 )
                    724:     {
                    725:         mix_sub_columns( s1 );
                    726:         update_encrypt_key_128( o_key, &rc );
                    727:         add_round_key( s1, o_key );
                    728:     }
                    729: #else
                    730:     {   uint_8t s2[N_BLOCK];
                    731:         mix_sub_columns( s2, s1 );
                    732:         update_encrypt_key_128( o_key, &rc );
                    733:         copy_and_key( s1, s2, o_key );
                    734:     }
                    735: #endif
                    736: 
                    737:     shift_sub_rows( s1 );
                    738:     update_encrypt_key_128( o_key, &rc );
                    739:     copy_and_key( out, s1, o_key );
                    740: }
                    741: 
                    742: #endif
                    743: 
                    744: #if defined( AES_DEC_128_OTFK )
                    745: 
                    746: /*  The 'on the fly' decryption key update for for 128 bit keys */
                    747: 
                    748: static void update_decrypt_key_128( uint_8t k[N_BLOCK], uint_8t *rc )
                    749: {   uint_8t cc;
                    750: 
                    751:     for( cc = 12; cc > 0; cc -= 4 )
                    752:     {
                    753:         k[cc + 0] ^= k[cc - 4];
                    754:         k[cc + 1] ^= k[cc - 3];
                    755:         k[cc + 2] ^= k[cc - 2];
                    756:         k[cc + 3] ^= k[cc - 1];
                    757:     }
                    758:     *rc = d2(*rc);
                    759:     k[0] ^= s_box[k[13]] ^ *rc;
                    760:     k[1] ^= s_box[k[14]];
                    761:     k[2] ^= s_box[k[15]];
                    762:     k[3] ^= s_box[k[12]];
                    763: }
                    764: 
                    765: /*  Decrypt a single block of 16 bytes with 'on the fly' 128 bit keying */
                    766: 
                    767: void aes_decrypt_128( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK],
                    768:                       const unsigned char key[N_BLOCK], unsigned char o_key[N_BLOCK] )
                    769: {
                    770:     uint_8t s1[N_BLOCK], r, rc = 0x6c;
                    771:     if(o_key != key)
                    772:         block16_copy( o_key, key );
                    773: 
                    774:     copy_and_key( s1, in, o_key );
                    775:     inv_shift_sub_rows( s1 );
                    776: 
                    777:     for( r = 10 ; --r ; )
                    778: #if defined( VERSION_1 )
                    779:     {
                    780:         update_decrypt_key_128( o_key, &rc );
                    781:         add_round_key( s1, o_key );
                    782:         inv_mix_sub_columns( s1 );
                    783:     }
                    784: #else
                    785:     {   uint_8t s2[N_BLOCK];
                    786:         update_decrypt_key_128( o_key, &rc );
                    787:         copy_and_key( s2, s1, o_key );
                    788:         inv_mix_sub_columns( s1, s2 );
                    789:     }
                    790: #endif
                    791:     update_decrypt_key_128( o_key, &rc );
                    792:     copy_and_key( out, s1, o_key );
                    793: }
                    794: 
                    795: #endif
                    796: 
                    797: #if defined( AES_ENC_256_OTFK )
                    798: 
                    799: /*  The 'on the fly' encryption key update for for 256 bit keys */
                    800: 
                    801: static void update_encrypt_key_256( uint_8t k[2 * N_BLOCK], uint_8t *rc )
                    802: {   uint_8t cc;
                    803: 
                    804:     k[0] ^= s_box[k[29]] ^ *rc;
                    805:     k[1] ^= s_box[k[30]];
                    806:     k[2] ^= s_box[k[31]];
                    807:     k[3] ^= s_box[k[28]];
                    808:     *rc = f2( *rc );
                    809: 
                    810:     for(cc = 4; cc < 16; cc += 4)
                    811:     {
                    812:         k[cc + 0] ^= k[cc - 4];
                    813:         k[cc + 1] ^= k[cc - 3];
                    814:         k[cc + 2] ^= k[cc - 2];
                    815:         k[cc + 3] ^= k[cc - 1];
                    816:     }
                    817: 
                    818:     k[16] ^= s_box[k[12]];
                    819:     k[17] ^= s_box[k[13]];
                    820:     k[18] ^= s_box[k[14]];
                    821:     k[19] ^= s_box[k[15]];
                    822: 
                    823:     for( cc = 20; cc < 32; cc += 4 )
                    824:     {
                    825:         k[cc + 0] ^= k[cc - 4];
                    826:         k[cc + 1] ^= k[cc - 3];
                    827:         k[cc + 2] ^= k[cc - 2];
                    828:         k[cc + 3] ^= k[cc - 1];
                    829:     }
                    830: }
                    831: 
                    832: /*  Encrypt a single block of 16 bytes with 'on the fly' 256 bit keying */
                    833: 
                    834: void aes_encrypt_256( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK],
                    835:                       const unsigned char key[2 * N_BLOCK], unsigned char o_key[2 * N_BLOCK] )
                    836: {
                    837:     uint_8t s1[N_BLOCK], r, rc = 1;
                    838:     if(o_key != key)
                    839:     {
                    840:         block16_copy( o_key, key );
                    841:         block16_copy( o_key + 16, key + 16 );
                    842:     }
                    843:     copy_and_key( s1, in, o_key );
                    844: 
                    845:     for( r = 1 ; r < 14 ; ++r )
                    846: #if defined( VERSION_1 )
                    847:     {
                    848:         mix_sub_columns(s1);
                    849:         if( r & 1 )
                    850:             add_round_key( s1, o_key + 16 );
                    851:         else
                    852:         {
                    853:             update_encrypt_key_256( o_key, &rc );
                    854:             add_round_key( s1, o_key );
                    855:         }
                    856:     }
                    857: #else
                    858:     {   uint_8t s2[N_BLOCK];
                    859:         mix_sub_columns( s2, s1 );
                    860:         if( r & 1 )
                    861:             copy_and_key( s1, s2, o_key + 16 );
                    862:         else
                    863:         {
                    864:             update_encrypt_key_256( o_key, &rc );
                    865:             copy_and_key( s1, s2, o_key );
                    866:         }
                    867:     }
                    868: #endif
                    869: 
                    870:     shift_sub_rows( s1 );
                    871:     update_encrypt_key_256( o_key, &rc );
                    872:     copy_and_key( out, s1, o_key );
                    873: }
                    874: 
                    875: #endif
                    876: 
                    877: #if defined( AES_DEC_256_OTFK )
                    878: 
                    879: /*  The 'on the fly' encryption key update for for 256 bit keys */
                    880: 
                    881: static void update_decrypt_key_256( uint_8t k[2 * N_BLOCK], uint_8t *rc )
                    882: {   uint_8t cc;
                    883: 
                    884:     for(cc = 28; cc > 16; cc -= 4)
                    885:     {
                    886:         k[cc + 0] ^= k[cc - 4];
                    887:         k[cc + 1] ^= k[cc - 3];
                    888:         k[cc + 2] ^= k[cc - 2];
                    889:         k[cc + 3] ^= k[cc - 1];
                    890:     }
                    891: 
                    892:     k[16] ^= s_box[k[12]];
                    893:     k[17] ^= s_box[k[13]];
                    894:     k[18] ^= s_box[k[14]];
                    895:     k[19] ^= s_box[k[15]];
                    896: 
                    897:     for(cc = 12; cc > 0; cc -= 4)
                    898:     {
                    899:         k[cc + 0] ^= k[cc - 4];
                    900:         k[cc + 1] ^= k[cc - 3];
                    901:         k[cc + 2] ^= k[cc - 2];
                    902:         k[cc + 3] ^= k[cc - 1];
                    903:     }
                    904: 
                    905:     *rc = d2(*rc);
                    906:     k[0] ^= s_box[k[29]] ^ *rc;
                    907:     k[1] ^= s_box[k[30]];
                    908:     k[2] ^= s_box[k[31]];
                    909:     k[3] ^= s_box[k[28]];
                    910: }
                    911: 
                    912: /*  Decrypt a single block of 16 bytes with 'on the fly'
                    913:     256 bit keying
                    914: */
                    915: void aes_decrypt_256( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK],
                    916:                       const unsigned char key[2 * N_BLOCK], unsigned char o_key[2 * N_BLOCK] )
                    917: {
                    918:     uint_8t s1[N_BLOCK], r, rc = 0x80;
                    919: 
                    920:     if(o_key != key)
                    921:     {
                    922:         block16_copy( o_key, key );
                    923:         block16_copy( o_key + 16, key + 16 );
                    924:     }
                    925: 
                    926:     copy_and_key( s1, in, o_key );
                    927:     inv_shift_sub_rows( s1 );
                    928: 
                    929:     for( r = 14 ; --r ; )
                    930: #if defined( VERSION_1 )
                    931:     {
                    932:         if( ( r & 1 ) )
                    933:         {
                    934:             update_decrypt_key_256( o_key, &rc );
                    935:             add_round_key( s1, o_key + 16 );
                    936:         }
                    937:         else
                    938:             add_round_key( s1, o_key );
                    939:         inv_mix_sub_columns( s1 );
                    940:     }
                    941: #else
                    942:     {   uint_8t s2[N_BLOCK];
                    943:         if( ( r & 1 ) )
                    944:         {
                    945:             update_decrypt_key_256( o_key, &rc );
                    946:             copy_and_key( s2, s1, o_key + 16 );
                    947:         }
                    948:         else
                    949:             copy_and_key( s2, s1, o_key );
                    950:         inv_mix_sub_columns( s1, s2 );
                    951:     }
                    952: #endif
                    953:     copy_and_key( out, s1, o_key );
                    954: }
                    955: 
                    956: #endif

unix.superglobalmegacorp.com

This archive runs on limited infrastructure. Preserving old code on modern bandwidth. Automated agents are requested to crawl responsibly.