|
|
1.1 root 1: /*
2: ---------------------------------------------------------------------------
3: Copyright (c) 1998-2006, Brian Gladman, Worcester, UK. All rights reserved.
4:
5: LICENSE TERMS
6:
7: The free distribution and use of this software in both source and binary
8: form is allowed (with or without changes) provided that:
9:
10: 1. distributions of this source code include the above copyright
11: notice, this list of conditions and the following disclaimer;
12:
13: 2. distributions in binary form include the above copyright
14: notice, this list of conditions and the following disclaimer
15: in the documentation and/or other associated materials;
16:
17: 3. the copyright holder's name is not used to endorse products
18: built using this software without specific written permission.
19:
20: ALTERNATIVELY, provided that this notice is retained in full, this product
21: may be distributed under the terms of the GNU General Public License (GPL),
22: in which case the provisions of the GPL apply INSTEAD OF those given above.
23:
24: DISCLAIMER
25:
26: This software is provided 'as is' with no explicit or implied warranties
27: in respect of its properties, including, but not limited to, correctness
28: and/or fitness for purpose.
29: ---------------------------------------------------------------------------
30: Issue 09/09/2006
31:
32: This is an AES implementation that uses only 8-bit byte operations on the
33: cipher state (there are options to use 32-bit types if available).
34:
35: The combination of mix columns and byte substitution used here is based on
36: that developed by Karl Malbrain. His contribution is acknowledged.
37: */
38:
39: /* Adapted by TrueCrypt Foundation:
40: - Macro-generated tables were replaced with static data to enable compiling
41: with MSVC++ 1.5 which runs out of resources when expanding large macros.
42: */
43:
44: /* define if you have a fast memcpy function on your system */
45: #if 1
46: # define HAVE_MEMCPY
47: # include <string.h>
48: # if defined( _MSC_VER )
49: # ifndef DEBUG
50: # pragma intrinsic( memcpy )
51: # endif
52: # endif
53: #endif
54:
55: /* define if you have fast 32-bit types on your system */
56: #if 1
57: # define HAVE_UINT_32T
58: #endif
59:
60: /* alternative versions (test for performance on your system) */
61: #if 0
62: # define VERSION_1
63: #endif
64:
65: #include "AesSmall.h"
66:
67: #define WPOLY 0x011b
68: #define DPOLY 0x008d
69: #define f1(x) (x)
70: #define f2(x) ((x<<1) ^ (((x>>7) & 1) * WPOLY))
71: #define f4(x) ((x<<2) ^ (((x>>6) & 1) * WPOLY) ^ (((x>>6) & 2) * WPOLY))
72: #define f8(x) ((x<<3) ^ (((x>>5) & 1) * WPOLY) ^ (((x>>5) & 2) * WPOLY) \
73: ^ (((x>>5) & 4) * WPOLY))
74: #define d2(x) (((x) >> 1) ^ ((x) & 1 ? DPOLY : 0))
75:
76: #define f3(x) (f2(x) ^ x)
77: #define f9(x) (f8(x) ^ x)
78: #define fb(x) (f8(x) ^ f2(x) ^ x)
79: #define fd(x) (f8(x) ^ f4(x) ^ x)
80: #define fe(x) (f8(x) ^ f4(x) ^ f2(x))
81:
82: static const uint_8t s_box[256] = {
83: 0x63,0x7c,0x77,0x7b,0xf2,0x6b,0x6f,0xc5,
84: 0x30,0x01,0x67,0x2b,0xfe,0xd7,0xab,0x76,
85: 0xca,0x82,0xc9,0x7d,0xfa,0x59,0x47,0xf0,
86: 0xad,0xd4,0xa2,0xaf,0x9c,0xa4,0x72,0xc0,
87: 0xb7,0xfd,0x93,0x26,0x36,0x3f,0xf7,0xcc,
88: 0x34,0xa5,0xe5,0xf1,0x71,0xd8,0x31,0x15,
89: 0x04,0xc7,0x23,0xc3,0x18,0x96,0x05,0x9a,
90: 0x07,0x12,0x80,0xe2,0xeb,0x27,0xb2,0x75,
91: 0x09,0x83,0x2c,0x1a,0x1b,0x6e,0x5a,0xa0,
92: 0x52,0x3b,0xd6,0xb3,0x29,0xe3,0x2f,0x84,
93: 0x53,0xd1,0x00,0xed,0x20,0xfc,0xb1,0x5b,
94: 0x6a,0xcb,0xbe,0x39,0x4a,0x4c,0x58,0xcf,
95: 0xd0,0xef,0xaa,0xfb,0x43,0x4d,0x33,0x85,
96: 0x45,0xf9,0x02,0x7f,0x50,0x3c,0x9f,0xa8,
97: 0x51,0xa3,0x40,0x8f,0x92,0x9d,0x38,0xf5,
98: 0xbc,0xb6,0xda,0x21,0x10,0xff,0xf3,0xd2,
99: 0xcd,0x0c,0x13,0xec,0x5f,0x97,0x44,0x17,
100: 0xc4,0xa7,0x7e,0x3d,0x64,0x5d,0x19,0x73,
101: 0x60,0x81,0x4f,0xdc,0x22,0x2a,0x90,0x88,
102: 0x46,0xee,0xb8,0x14,0xde,0x5e,0x0b,0xdb,
103: 0xe0,0x32,0x3a,0x0a,0x49,0x06,0x24,0x5c,
104: 0xc2,0xd3,0xac,0x62,0x91,0x95,0xe4,0x79,
105: 0xe7,0xc8,0x37,0x6d,0x8d,0xd5,0x4e,0xa9,
106: 0x6c,0x56,0xf4,0xea,0x65,0x7a,0xae,0x08,
107: 0xba,0x78,0x25,0x2e,0x1c,0xa6,0xb4,0xc6,
108: 0xe8,0xdd,0x74,0x1f,0x4b,0xbd,0x8b,0x8a,
109: 0x70,0x3e,0xb5,0x66,0x48,0x03,0xf6,0x0e,
110: 0x61,0x35,0x57,0xb9,0x86,0xc1,0x1d,0x9e,
111: 0xe1,0xf8,0x98,0x11,0x69,0xd9,0x8e,0x94,
112: 0x9b,0x1e,0x87,0xe9,0xce,0x55,0x28,0xdf,
113: 0x8c,0xa1,0x89,0x0d,0xbf,0xe6,0x42,0x68,
114: 0x41,0x99,0x2d,0x0f,0xb0,0x54,0xbb,0x16
115: };
116:
117: static const uint_8t inv_s_box[256] = {
118: 0x52,0x09,0x6a,0xd5,0x30,0x36,0xa5,0x38,
119: 0xbf,0x40,0xa3,0x9e,0x81,0xf3,0xd7,0xfb,
120: 0x7c,0xe3,0x39,0x82,0x9b,0x2f,0xff,0x87,
121: 0x34,0x8e,0x43,0x44,0xc4,0xde,0xe9,0xcb,
122: 0x54,0x7b,0x94,0x32,0xa6,0xc2,0x23,0x3d,
123: 0xee,0x4c,0x95,0x0b,0x42,0xfa,0xc3,0x4e,
124: 0x08,0x2e,0xa1,0x66,0x28,0xd9,0x24,0xb2,
125: 0x76,0x5b,0xa2,0x49,0x6d,0x8b,0xd1,0x25,
126: 0x72,0xf8,0xf6,0x64,0x86,0x68,0x98,0x16,
127: 0xd4,0xa4,0x5c,0xcc,0x5d,0x65,0xb6,0x92,
128: 0x6c,0x70,0x48,0x50,0xfd,0xed,0xb9,0xda,
129: 0x5e,0x15,0x46,0x57,0xa7,0x8d,0x9d,0x84,
130: 0x90,0xd8,0xab,0x00,0x8c,0xbc,0xd3,0x0a,
131: 0xf7,0xe4,0x58,0x05,0xb8,0xb3,0x45,0x06,
132: 0xd0,0x2c,0x1e,0x8f,0xca,0x3f,0x0f,0x02,
133: 0xc1,0xaf,0xbd,0x03,0x01,0x13,0x8a,0x6b,
134: 0x3a,0x91,0x11,0x41,0x4f,0x67,0xdc,0xea,
135: 0x97,0xf2,0xcf,0xce,0xf0,0xb4,0xe6,0x73,
136: 0x96,0xac,0x74,0x22,0xe7,0xad,0x35,0x85,
137: 0xe2,0xf9,0x37,0xe8,0x1c,0x75,0xdf,0x6e,
138: 0x47,0xf1,0x1a,0x71,0x1d,0x29,0xc5,0x89,
139: 0x6f,0xb7,0x62,0x0e,0xaa,0x18,0xbe,0x1b,
140: 0xfc,0x56,0x3e,0x4b,0xc6,0xd2,0x79,0x20,
141: 0x9a,0xdb,0xc0,0xfe,0x78,0xcd,0x5a,0xf4,
142: 0x1f,0xdd,0xa8,0x33,0x88,0x07,0xc7,0x31,
143: 0xb1,0x12,0x10,0x59,0x27,0x80,0xec,0x5f,
144: 0x60,0x51,0x7f,0xa9,0x19,0xb5,0x4a,0x0d,
145: 0x2d,0xe5,0x7a,0x9f,0x93,0xc9,0x9c,0xef,
146: 0xa0,0xe0,0x3b,0x4d,0xae,0x2a,0xf5,0xb0,
147: 0xc8,0xeb,0xbb,0x3c,0x83,0x53,0x99,0x61,
148: 0x17,0x2b,0x04,0x7e,0xba,0x77,0xd6,0x26,
149: 0xe1,0x69,0x14,0x63,0x55,0x21,0x0c,0x7d
150: };
151:
152: static const uint_8t gfm2_s_box[256] = {
153: 0xc6,0xf8,0xee,0xf6,0xff,0xd6,0xde,0x91,
154: 0x60,0x02,0xce,0x56,0xe7,0xb5,0x4d,0xec,
155: 0x8f,0x1f,0x89,0xfa,0xef,0xb2,0x8e,0xfb,
156: 0x41,0xb3,0x5f,0x45,0x23,0x53,0xe4,0x9b,
157: 0x75,0xe1,0x3d,0x4c,0x6c,0x7e,0xf5,0x83,
158: 0x68,0x51,0xd1,0xf9,0xe2,0xab,0x62,0x2a,
159: 0x08,0x95,0x46,0x9d,0x30,0x37,0x0a,0x2f,
160: 0x0e,0x24,0x1b,0xdf,0xcd,0x4e,0x7f,0xea,
161: 0x12,0x1d,0x58,0x34,0x36,0xdc,0xb4,0x5b,
162: 0xa4,0x76,0xb7,0x7d,0x52,0xdd,0x5e,0x13,
163: 0xa6,0xb9,0x00,0xc1,0x40,0xe3,0x79,0xb6,
164: 0xd4,0x8d,0x67,0x72,0x94,0x98,0xb0,0x85,
165: 0xbb,0xc5,0x4f,0xed,0x86,0x9a,0x66,0x11,
166: 0x8a,0xe9,0x04,0xfe,0xa0,0x78,0x25,0x4b,
167: 0xa2,0x5d,0x80,0x05,0x3f,0x21,0x70,0xf1,
168: 0x63,0x77,0xaf,0x42,0x20,0xe5,0xfd,0xbf,
169: 0x81,0x18,0x26,0xc3,0xbe,0x35,0x88,0x2e,
170: 0x93,0x55,0xfc,0x7a,0xc8,0xba,0x32,0xe6,
171: 0xc0,0x19,0x9e,0xa3,0x44,0x54,0x3b,0x0b,
172: 0x8c,0xc7,0x6b,0x28,0xa7,0xbc,0x16,0xad,
173: 0xdb,0x64,0x74,0x14,0x92,0x0c,0x48,0xb8,
174: 0x9f,0xbd,0x43,0xc4,0x39,0x31,0xd3,0xf2,
175: 0xd5,0x8b,0x6e,0xda,0x01,0xb1,0x9c,0x49,
176: 0xd8,0xac,0xf3,0xcf,0xca,0xf4,0x47,0x10,
177: 0x6f,0xf0,0x4a,0x5c,0x38,0x57,0x73,0x97,
178: 0xcb,0xa1,0xe8,0x3e,0x96,0x61,0x0d,0x0f,
179: 0xe0,0x7c,0x71,0xcc,0x90,0x06,0xf7,0x1c,
180: 0xc2,0x6a,0xae,0x69,0x17,0x99,0x3a,0x27,
181: 0xd9,0xeb,0x2b,0x22,0xd2,0xa9,0x07,0x33,
182: 0x2d,0x3c,0x15,0xc9,0x87,0xaa,0x50,0xa5,
183: 0x03,0x59,0x09,0x1a,0x65,0xd7,0x84,0xd0,
184: 0x82,0x29,0x5a,0x1e,0x7b,0xa8,0x6d,0x2c
185: };
186:
187: static const uint_8t gfm3_s_box[256] = {
188: 0xa5,0x84,0x99,0x8d,0x0d,0xbd,0xb1,0x54,
189: 0x50,0x03,0xa9,0x7d,0x19,0x62,0xe6,0x9a,
190: 0x45,0x9d,0x40,0x87,0x15,0xeb,0xc9,0x0b,
191: 0xec,0x67,0xfd,0xea,0xbf,0xf7,0x96,0x5b,
192: 0xc2,0x1c,0xae,0x6a,0x5a,0x41,0x02,0x4f,
193: 0x5c,0xf4,0x34,0x08,0x93,0x73,0x53,0x3f,
194: 0x0c,0x52,0x65,0x5e,0x28,0xa1,0x0f,0xb5,
195: 0x09,0x36,0x9b,0x3d,0x26,0x69,0xcd,0x9f,
196: 0x1b,0x9e,0x74,0x2e,0x2d,0xb2,0xee,0xfb,
197: 0xf6,0x4d,0x61,0xce,0x7b,0x3e,0x71,0x97,
198: 0xf5,0x68,0x00,0x2c,0x60,0x1f,0xc8,0xed,
199: 0xbe,0x46,0xd9,0x4b,0xde,0xd4,0xe8,0x4a,
200: 0x6b,0x2a,0xe5,0x16,0xc5,0xd7,0x55,0x94,
201: 0xcf,0x10,0x06,0x81,0xf0,0x44,0xba,0xe3,
202: 0xf3,0xfe,0xc0,0x8a,0xad,0xbc,0x48,0x04,
203: 0xdf,0xc1,0x75,0x63,0x30,0x1a,0x0e,0x6d,
204: 0x4c,0x14,0x35,0x2f,0xe1,0xa2,0xcc,0x39,
205: 0x57,0xf2,0x82,0x47,0xac,0xe7,0x2b,0x95,
206: 0xa0,0x98,0xd1,0x7f,0x66,0x7e,0xab,0x83,
207: 0xca,0x29,0xd3,0x3c,0x79,0xe2,0x1d,0x76,
208: 0x3b,0x56,0x4e,0x1e,0xdb,0x0a,0x6c,0xe4,
209: 0x5d,0x6e,0xef,0xa6,0xa8,0xa4,0x37,0x8b,
210: 0x32,0x43,0x59,0xb7,0x8c,0x64,0xd2,0xe0,
211: 0xb4,0xfa,0x07,0x25,0xaf,0x8e,0xe9,0x18,
212: 0xd5,0x88,0x6f,0x72,0x24,0xf1,0xc7,0x51,
213: 0x23,0x7c,0x9c,0x21,0xdd,0xdc,0x86,0x85,
214: 0x90,0x42,0xc4,0xaa,0xd8,0x05,0x01,0x12,
215: 0xa3,0x5f,0xf9,0xd0,0x91,0x58,0x27,0xb9,
216: 0x38,0x13,0xb3,0x33,0xbb,0x70,0x89,0xa7,
217: 0xb6,0x22,0x92,0x20,0x49,0xff,0x78,0x7a,
218: 0x8f,0xf8,0x80,0x17,0xda,0x31,0xc6,0xb8,
219: 0xc3,0xb0,0x77,0x11,0xcb,0xfc,0xd6,0x3a
220: };
221:
222: static const uint_8t gfmul_9[256] = {
223: 0x00,0x09,0x12,0x1b,0x24,0x2d,0x36,0x3f,
224: 0x48,0x41,0x5a,0x53,0x6c,0x65,0x7e,0x77,
225: 0x90,0x99,0x82,0x8b,0xb4,0xbd,0xa6,0xaf,
226: 0xd8,0xd1,0xca,0xc3,0xfc,0xf5,0xee,0xe7,
227: 0x3b,0x32,0x29,0x20,0x1f,0x16,0x0d,0x04,
228: 0x73,0x7a,0x61,0x68,0x57,0x5e,0x45,0x4c,
229: 0xab,0xa2,0xb9,0xb0,0x8f,0x86,0x9d,0x94,
230: 0xe3,0xea,0xf1,0xf8,0xc7,0xce,0xd5,0xdc,
231: 0x76,0x7f,0x64,0x6d,0x52,0x5b,0x40,0x49,
232: 0x3e,0x37,0x2c,0x25,0x1a,0x13,0x08,0x01,
233: 0xe6,0xef,0xf4,0xfd,0xc2,0xcb,0xd0,0xd9,
234: 0xae,0xa7,0xbc,0xb5,0x8a,0x83,0x98,0x91,
235: 0x4d,0x44,0x5f,0x56,0x69,0x60,0x7b,0x72,
236: 0x05,0x0c,0x17,0x1e,0x21,0x28,0x33,0x3a,
237: 0xdd,0xd4,0xcf,0xc6,0xf9,0xf0,0xeb,0xe2,
238: 0x95,0x9c,0x87,0x8e,0xb1,0xb8,0xa3,0xaa,
239: 0xec,0xe5,0xfe,0xf7,0xc8,0xc1,0xda,0xd3,
240: 0xa4,0xad,0xb6,0xbf,0x80,0x89,0x92,0x9b,
241: 0x7c,0x75,0x6e,0x67,0x58,0x51,0x4a,0x43,
242: 0x34,0x3d,0x26,0x2f,0x10,0x19,0x02,0x0b,
243: 0xd7,0xde,0xc5,0xcc,0xf3,0xfa,0xe1,0xe8,
244: 0x9f,0x96,0x8d,0x84,0xbb,0xb2,0xa9,0xa0,
245: 0x47,0x4e,0x55,0x5c,0x63,0x6a,0x71,0x78,
246: 0x0f,0x06,0x1d,0x14,0x2b,0x22,0x39,0x30,
247: 0x9a,0x93,0x88,0x81,0xbe,0xb7,0xac,0xa5,
248: 0xd2,0xdb,0xc0,0xc9,0xf6,0xff,0xe4,0xed,
249: 0x0a,0x03,0x18,0x11,0x2e,0x27,0x3c,0x35,
250: 0x42,0x4b,0x50,0x59,0x66,0x6f,0x74,0x7d,
251: 0xa1,0xa8,0xb3,0xba,0x85,0x8c,0x97,0x9e,
252: 0xe9,0xe0,0xfb,0xf2,0xcd,0xc4,0xdf,0xd6,
253: 0x31,0x38,0x23,0x2a,0x15,0x1c,0x07,0x0e,
254: 0x79,0x70,0x6b,0x62,0x5d,0x54,0x4f,0x46
255: };
256:
257: static const uint_8t gfmul_b[256] = {
258: 0x00,0x0b,0x16,0x1d,0x2c,0x27,0x3a,0x31,
259: 0x58,0x53,0x4e,0x45,0x74,0x7f,0x62,0x69,
260: 0xb0,0xbb,0xa6,0xad,0x9c,0x97,0x8a,0x81,
261: 0xe8,0xe3,0xfe,0xf5,0xc4,0xcf,0xd2,0xd9,
262: 0x7b,0x70,0x6d,0x66,0x57,0x5c,0x41,0x4a,
263: 0x23,0x28,0x35,0x3e,0x0f,0x04,0x19,0x12,
264: 0xcb,0xc0,0xdd,0xd6,0xe7,0xec,0xf1,0xfa,
265: 0x93,0x98,0x85,0x8e,0xbf,0xb4,0xa9,0xa2,
266: 0xf6,0xfd,0xe0,0xeb,0xda,0xd1,0xcc,0xc7,
267: 0xae,0xa5,0xb8,0xb3,0x82,0x89,0x94,0x9f,
268: 0x46,0x4d,0x50,0x5b,0x6a,0x61,0x7c,0x77,
269: 0x1e,0x15,0x08,0x03,0x32,0x39,0x24,0x2f,
270: 0x8d,0x86,0x9b,0x90,0xa1,0xaa,0xb7,0xbc,
271: 0xd5,0xde,0xc3,0xc8,0xf9,0xf2,0xef,0xe4,
272: 0x3d,0x36,0x2b,0x20,0x11,0x1a,0x07,0x0c,
273: 0x65,0x6e,0x73,0x78,0x49,0x42,0x5f,0x54,
274: 0xf7,0xfc,0xe1,0xea,0xdb,0xd0,0xcd,0xc6,
275: 0xaf,0xa4,0xb9,0xb2,0x83,0x88,0x95,0x9e,
276: 0x47,0x4c,0x51,0x5a,0x6b,0x60,0x7d,0x76,
277: 0x1f,0x14,0x09,0x02,0x33,0x38,0x25,0x2e,
278: 0x8c,0x87,0x9a,0x91,0xa0,0xab,0xb6,0xbd,
279: 0xd4,0xdf,0xc2,0xc9,0xf8,0xf3,0xee,0xe5,
280: 0x3c,0x37,0x2a,0x21,0x10,0x1b,0x06,0x0d,
281: 0x64,0x6f,0x72,0x79,0x48,0x43,0x5e,0x55,
282: 0x01,0x0a,0x17,0x1c,0x2d,0x26,0x3b,0x30,
283: 0x59,0x52,0x4f,0x44,0x75,0x7e,0x63,0x68,
284: 0xb1,0xba,0xa7,0xac,0x9d,0x96,0x8b,0x80,
285: 0xe9,0xe2,0xff,0xf4,0xc5,0xce,0xd3,0xd8,
286: 0x7a,0x71,0x6c,0x67,0x56,0x5d,0x40,0x4b,
287: 0x22,0x29,0x34,0x3f,0x0e,0x05,0x18,0x13,
288: 0xca,0xc1,0xdc,0xd7,0xe6,0xed,0xf0,0xfb,
289: 0x92,0x99,0x84,0x8f,0xbe,0xb5,0xa8,0xa3
290: };
291:
292: static const uint_8t gfmul_d[256] = {
293: 0x00,0x0d,0x1a,0x17,0x34,0x39,0x2e,0x23,
294: 0x68,0x65,0x72,0x7f,0x5c,0x51,0x46,0x4b,
295: 0xd0,0xdd,0xca,0xc7,0xe4,0xe9,0xfe,0xf3,
296: 0xb8,0xb5,0xa2,0xaf,0x8c,0x81,0x96,0x9b,
297: 0xbb,0xb6,0xa1,0xac,0x8f,0x82,0x95,0x98,
298: 0xd3,0xde,0xc9,0xc4,0xe7,0xea,0xfd,0xf0,
299: 0x6b,0x66,0x71,0x7c,0x5f,0x52,0x45,0x48,
300: 0x03,0x0e,0x19,0x14,0x37,0x3a,0x2d,0x20,
301: 0x6d,0x60,0x77,0x7a,0x59,0x54,0x43,0x4e,
302: 0x05,0x08,0x1f,0x12,0x31,0x3c,0x2b,0x26,
303: 0xbd,0xb0,0xa7,0xaa,0x89,0x84,0x93,0x9e,
304: 0xd5,0xd8,0xcf,0xc2,0xe1,0xec,0xfb,0xf6,
305: 0xd6,0xdb,0xcc,0xc1,0xe2,0xef,0xf8,0xf5,
306: 0xbe,0xb3,0xa4,0xa9,0x8a,0x87,0x90,0x9d,
307: 0x06,0x0b,0x1c,0x11,0x32,0x3f,0x28,0x25,
308: 0x6e,0x63,0x74,0x79,0x5a,0x57,0x40,0x4d,
309: 0xda,0xd7,0xc0,0xcd,0xee,0xe3,0xf4,0xf9,
310: 0xb2,0xbf,0xa8,0xa5,0x86,0x8b,0x9c,0x91,
311: 0x0a,0x07,0x10,0x1d,0x3e,0x33,0x24,0x29,
312: 0x62,0x6f,0x78,0x75,0x56,0x5b,0x4c,0x41,
313: 0x61,0x6c,0x7b,0x76,0x55,0x58,0x4f,0x42,
314: 0x09,0x04,0x13,0x1e,0x3d,0x30,0x27,0x2a,
315: 0xb1,0xbc,0xab,0xa6,0x85,0x88,0x9f,0x92,
316: 0xd9,0xd4,0xc3,0xce,0xed,0xe0,0xf7,0xfa,
317: 0xb7,0xba,0xad,0xa0,0x83,0x8e,0x99,0x94,
318: 0xdf,0xd2,0xc5,0xc8,0xeb,0xe6,0xf1,0xfc,
319: 0x67,0x6a,0x7d,0x70,0x53,0x5e,0x49,0x44,
320: 0x0f,0x02,0x15,0x18,0x3b,0x36,0x21,0x2c,
321: 0x0c,0x01,0x16,0x1b,0x38,0x35,0x22,0x2f,
322: 0x64,0x69,0x7e,0x73,0x50,0x5d,0x4a,0x47,
323: 0xdc,0xd1,0xc6,0xcb,0xe8,0xe5,0xf2,0xff,
324: 0xb4,0xb9,0xae,0xa3,0x80,0x8d,0x9a,0x97
325: };
326:
327: static const uint_8t gfmul_e[256] = {
328: 0x00,0x0e,0x1c,0x12,0x38,0x36,0x24,0x2a,
329: 0x70,0x7e,0x6c,0x62,0x48,0x46,0x54,0x5a,
330: 0xe0,0xee,0xfc,0xf2,0xd8,0xd6,0xc4,0xca,
331: 0x90,0x9e,0x8c,0x82,0xa8,0xa6,0xb4,0xba,
332: 0xdb,0xd5,0xc7,0xc9,0xe3,0xed,0xff,0xf1,
333: 0xab,0xa5,0xb7,0xb9,0x93,0x9d,0x8f,0x81,
334: 0x3b,0x35,0x27,0x29,0x03,0x0d,0x1f,0x11,
335: 0x4b,0x45,0x57,0x59,0x73,0x7d,0x6f,0x61,
336: 0xad,0xa3,0xb1,0xbf,0x95,0x9b,0x89,0x87,
337: 0xdd,0xd3,0xc1,0xcf,0xe5,0xeb,0xf9,0xf7,
338: 0x4d,0x43,0x51,0x5f,0x75,0x7b,0x69,0x67,
339: 0x3d,0x33,0x21,0x2f,0x05,0x0b,0x19,0x17,
340: 0x76,0x78,0x6a,0x64,0x4e,0x40,0x52,0x5c,
341: 0x06,0x08,0x1a,0x14,0x3e,0x30,0x22,0x2c,
342: 0x96,0x98,0x8a,0x84,0xae,0xa0,0xb2,0xbc,
343: 0xe6,0xe8,0xfa,0xf4,0xde,0xd0,0xc2,0xcc,
344: 0x41,0x4f,0x5d,0x53,0x79,0x77,0x65,0x6b,
345: 0x31,0x3f,0x2d,0x23,0x09,0x07,0x15,0x1b,
346: 0xa1,0xaf,0xbd,0xb3,0x99,0x97,0x85,0x8b,
347: 0xd1,0xdf,0xcd,0xc3,0xe9,0xe7,0xf5,0xfb,
348: 0x9a,0x94,0x86,0x88,0xa2,0xac,0xbe,0xb0,
349: 0xea,0xe4,0xf6,0xf8,0xd2,0xdc,0xce,0xc0,
350: 0x7a,0x74,0x66,0x68,0x42,0x4c,0x5e,0x50,
351: 0x0a,0x04,0x16,0x18,0x32,0x3c,0x2e,0x20,
352: 0xec,0xe2,0xf0,0xfe,0xd4,0xda,0xc8,0xc6,
353: 0x9c,0x92,0x80,0x8e,0xa4,0xaa,0xb8,0xb6,
354: 0x0c,0x02,0x10,0x1e,0x34,0x3a,0x28,0x26,
355: 0x7c,0x72,0x60,0x6e,0x44,0x4a,0x58,0x56,
356: 0x37,0x39,0x2b,0x25,0x0f,0x01,0x13,0x1d,
357: 0x47,0x49,0x5b,0x55,0x7f,0x71,0x63,0x6d,
358: 0xd7,0xd9,0xcb,0xc5,0xef,0xe1,0xf3,0xfd,
359: 0xa7,0xa9,0xbb,0xb5,0x9f,0x91,0x83,0x8d
360: };
361:
362: #if defined( HAVE_UINT_32T )
363: typedef unsigned long uint_32t;
364: #endif
365:
366: #if defined( HAVE_MEMCPY )
367: # define block_copy(d, s, l) memcpy(d, s, l)
368: # define block16_copy(d, s) memcpy(d, s, N_BLOCK)
369: #else
370: # define block_copy(d, s, l) copy_block(d, s, l)
371: # define block16_copy(d, s) copy_block16(d, s)
372: #endif
373:
374: /* block size 'nn' must be a multiple of four */
375:
376: static void copy_block16( void *d, const void *s )
377: {
378: #if defined( HAVE_UINT_32T )
379: ((uint_32t*)d)[ 0] = ((uint_32t*)s)[ 0];
380: ((uint_32t*)d)[ 1] = ((uint_32t*)s)[ 1];
381: ((uint_32t*)d)[ 2] = ((uint_32t*)s)[ 2];
382: ((uint_32t*)d)[ 3] = ((uint_32t*)s)[ 3];
383: #else
384: ((uint_8t*)d)[ 0] = ((uint_8t*)s)[ 0];
385: ((uint_8t*)d)[ 1] = ((uint_8t*)s)[ 1];
386: ((uint_8t*)d)[ 2] = ((uint_8t*)s)[ 2];
387: ((uint_8t*)d)[ 3] = ((uint_8t*)s)[ 3];
388: ((uint_8t*)d)[ 4] = ((uint_8t*)s)[ 4];
389: ((uint_8t*)d)[ 5] = ((uint_8t*)s)[ 5];
390: ((uint_8t*)d)[ 6] = ((uint_8t*)s)[ 6];
391: ((uint_8t*)d)[ 7] = ((uint_8t*)s)[ 7];
392: ((uint_8t*)d)[ 8] = ((uint_8t*)s)[ 8];
393: ((uint_8t*)d)[ 9] = ((uint_8t*)s)[ 9];
394: ((uint_8t*)d)[10] = ((uint_8t*)s)[10];
395: ((uint_8t*)d)[11] = ((uint_8t*)s)[11];
396: ((uint_8t*)d)[12] = ((uint_8t*)s)[12];
397: ((uint_8t*)d)[13] = ((uint_8t*)s)[13];
398: ((uint_8t*)d)[14] = ((uint_8t*)s)[14];
399: ((uint_8t*)d)[15] = ((uint_8t*)s)[15];
400: #endif
401: }
402:
403: static void copy_block( void * d, void *s, uint_8t nn )
404: {
405: while( nn-- )
406: *((uint_8t*)d)++ = *((uint_8t*)s)++;
407: }
408:
409: static void xor_block( void *d, const void *s )
410: {
411: #if defined( HAVE_UINT_32T )
412: ((uint_32t*)d)[ 0] ^= ((uint_32t*)s)[ 0];
413: ((uint_32t*)d)[ 1] ^= ((uint_32t*)s)[ 1];
414: ((uint_32t*)d)[ 2] ^= ((uint_32t*)s)[ 2];
415: ((uint_32t*)d)[ 3] ^= ((uint_32t*)s)[ 3];
416: #else
417: ((uint_8t*)d)[ 0] ^= ((uint_8t*)s)[ 0];
418: ((uint_8t*)d)[ 1] ^= ((uint_8t*)s)[ 1];
419: ((uint_8t*)d)[ 2] ^= ((uint_8t*)s)[ 2];
420: ((uint_8t*)d)[ 3] ^= ((uint_8t*)s)[ 3];
421: ((uint_8t*)d)[ 4] ^= ((uint_8t*)s)[ 4];
422: ((uint_8t*)d)[ 5] ^= ((uint_8t*)s)[ 5];
423: ((uint_8t*)d)[ 6] ^= ((uint_8t*)s)[ 6];
424: ((uint_8t*)d)[ 7] ^= ((uint_8t*)s)[ 7];
425: ((uint_8t*)d)[ 8] ^= ((uint_8t*)s)[ 8];
426: ((uint_8t*)d)[ 9] ^= ((uint_8t*)s)[ 9];
427: ((uint_8t*)d)[10] ^= ((uint_8t*)s)[10];
428: ((uint_8t*)d)[11] ^= ((uint_8t*)s)[11];
429: ((uint_8t*)d)[12] ^= ((uint_8t*)s)[12];
430: ((uint_8t*)d)[13] ^= ((uint_8t*)s)[13];
431: ((uint_8t*)d)[14] ^= ((uint_8t*)s)[14];
432: ((uint_8t*)d)[15] ^= ((uint_8t*)s)[15];
433: #endif
434: }
435:
436: static void copy_and_key( void *d, const void *s, const void *k )
437: {
438: #if defined( HAVE_UINT_32T )
439: ((uint_32t*)d)[ 0] = ((uint_32t*)s)[ 0] ^ ((uint_32t*)k)[ 0];
440: ((uint_32t*)d)[ 1] = ((uint_32t*)s)[ 1] ^ ((uint_32t*)k)[ 1];
441: ((uint_32t*)d)[ 2] = ((uint_32t*)s)[ 2] ^ ((uint_32t*)k)[ 2];
442: ((uint_32t*)d)[ 3] = ((uint_32t*)s)[ 3] ^ ((uint_32t*)k)[ 3];
443: #elif 1
444: ((uint_8t*)d)[ 0] = ((uint_8t*)s)[ 0] ^ ((uint_8t*)k)[ 0];
445: ((uint_8t*)d)[ 1] = ((uint_8t*)s)[ 1] ^ ((uint_8t*)k)[ 1];
446: ((uint_8t*)d)[ 2] = ((uint_8t*)s)[ 2] ^ ((uint_8t*)k)[ 2];
447: ((uint_8t*)d)[ 3] = ((uint_8t*)s)[ 3] ^ ((uint_8t*)k)[ 3];
448: ((uint_8t*)d)[ 4] = ((uint_8t*)s)[ 4] ^ ((uint_8t*)k)[ 4];
449: ((uint_8t*)d)[ 5] = ((uint_8t*)s)[ 5] ^ ((uint_8t*)k)[ 5];
450: ((uint_8t*)d)[ 6] = ((uint_8t*)s)[ 6] ^ ((uint_8t*)k)[ 6];
451: ((uint_8t*)d)[ 7] = ((uint_8t*)s)[ 7] ^ ((uint_8t*)k)[ 7];
452: ((uint_8t*)d)[ 8] = ((uint_8t*)s)[ 8] ^ ((uint_8t*)k)[ 8];
453: ((uint_8t*)d)[ 9] = ((uint_8t*)s)[ 9] ^ ((uint_8t*)k)[ 9];
454: ((uint_8t*)d)[10] = ((uint_8t*)s)[10] ^ ((uint_8t*)k)[10];
455: ((uint_8t*)d)[11] = ((uint_8t*)s)[11] ^ ((uint_8t*)k)[11];
456: ((uint_8t*)d)[12] = ((uint_8t*)s)[12] ^ ((uint_8t*)k)[12];
457: ((uint_8t*)d)[13] = ((uint_8t*)s)[13] ^ ((uint_8t*)k)[13];
458: ((uint_8t*)d)[14] = ((uint_8t*)s)[14] ^ ((uint_8t*)k)[14];
459: ((uint_8t*)d)[15] = ((uint_8t*)s)[15] ^ ((uint_8t*)k)[15];
460: #else
461: block16_copy(d, s);
462: xor_block(d, k);
463: #endif
464: }
465:
466: static void add_round_key( uint_8t d[N_BLOCK], const uint_8t k[N_BLOCK] )
467: {
468: xor_block(d, k);
469: }
470:
471: static void shift_sub_rows( uint_8t st[N_BLOCK] )
472: { uint_8t tt;
473:
474: st[ 0] = s_box[st[ 0]]; st[ 4] = s_box[st[ 4]];
475: st[ 8] = s_box[st[ 8]]; st[12] = s_box[st[12]];
476:
477: tt = st[1]; st[ 1] = s_box[st[ 5]]; st[ 5] = s_box[st[ 9]];
478: st[ 9] = s_box[st[13]]; st[13] = s_box[ tt ];
479:
480: tt = st[2]; st[ 2] = s_box[st[10]]; st[10] = s_box[ tt ];
481: tt = st[6]; st[ 6] = s_box[st[14]]; st[14] = s_box[ tt ];
482:
483: tt = st[15]; st[15] = s_box[st[11]]; st[11] = s_box[st[ 7]];
484: st[ 7] = s_box[st[ 3]]; st[ 3] = s_box[ tt ];
485: }
486:
487: static void inv_shift_sub_rows( uint_8t st[N_BLOCK] )
488: { uint_8t tt;
489:
490: st[ 0] = inv_s_box[st[ 0]]; st[ 4] = inv_s_box[st[ 4]];
491: st[ 8] = inv_s_box[st[ 8]]; st[12] = inv_s_box[st[12]];
492:
493: tt = st[13]; st[13] = inv_s_box[st[9]]; st[ 9] = inv_s_box[st[5]];
494: st[ 5] = inv_s_box[st[1]]; st[ 1] = inv_s_box[ tt ];
495:
496: tt = st[2]; st[ 2] = inv_s_box[st[10]]; st[10] = inv_s_box[ tt ];
497: tt = st[6]; st[ 6] = inv_s_box[st[14]]; st[14] = inv_s_box[ tt ];
498:
499: tt = st[3]; st[ 3] = inv_s_box[st[ 7]]; st[ 7] = inv_s_box[st[11]];
500: st[11] = inv_s_box[st[15]]; st[15] = inv_s_box[ tt ];
501: }
502:
503: #if defined( VERSION_1 )
504: static void mix_sub_columns( uint_8t dt[N_BLOCK] )
505: { uint_8t st[N_BLOCK];
506: block16_copy(st, dt);
507: #else
508: static void mix_sub_columns( uint_8t dt[N_BLOCK], uint_8t st[N_BLOCK] )
509: {
510: #endif
511: dt[ 0] = gfm2_s_box[st[0]] ^ gfm3_s_box[st[5]] ^ s_box[st[10]] ^ s_box[st[15]];
512: dt[ 1] = s_box[st[0]] ^ gfm2_s_box[st[5]] ^ gfm3_s_box[st[10]] ^ s_box[st[15]];
513: dt[ 2] = s_box[st[0]] ^ s_box[st[5]] ^ gfm2_s_box[st[10]] ^ gfm3_s_box[st[15]];
514: dt[ 3] = gfm3_s_box[st[0]] ^ s_box[st[5]] ^ s_box[st[10]] ^ gfm2_s_box[st[15]];
515:
516: dt[ 4] = gfm2_s_box[st[4]] ^ gfm3_s_box[st[9]] ^ s_box[st[14]] ^ s_box[st[3]];
517: dt[ 5] = s_box[st[4]] ^ gfm2_s_box[st[9]] ^ gfm3_s_box[st[14]] ^ s_box[st[3]];
518: dt[ 6] = s_box[st[4]] ^ s_box[st[9]] ^ gfm2_s_box[st[14]] ^ gfm3_s_box[st[3]];
519: dt[ 7] = gfm3_s_box[st[4]] ^ s_box[st[9]] ^ s_box[st[14]] ^ gfm2_s_box[st[3]];
520:
521: dt[ 8] = gfm2_s_box[st[8]] ^ gfm3_s_box[st[13]] ^ s_box[st[2]] ^ s_box[st[7]];
522: dt[ 9] = s_box[st[8]] ^ gfm2_s_box[st[13]] ^ gfm3_s_box[st[2]] ^ s_box[st[7]];
523: dt[10] = s_box[st[8]] ^ s_box[st[13]] ^ gfm2_s_box[st[2]] ^ gfm3_s_box[st[7]];
524: dt[11] = gfm3_s_box[st[8]] ^ s_box[st[13]] ^ s_box[st[2]] ^ gfm2_s_box[st[7]];
525:
526: dt[12] = gfm2_s_box[st[12]] ^ gfm3_s_box[st[1]] ^ s_box[st[6]] ^ s_box[st[11]];
527: dt[13] = s_box[st[12]] ^ gfm2_s_box[st[1]] ^ gfm3_s_box[st[6]] ^ s_box[st[11]];
528: dt[14] = s_box[st[12]] ^ s_box[st[1]] ^ gfm2_s_box[st[6]] ^ gfm3_s_box[st[11]];
529: dt[15] = gfm3_s_box[st[12]] ^ s_box[st[1]] ^ s_box[st[6]] ^ gfm2_s_box[st[11]];
530: }
531:
532: #if defined( VERSION_1 )
533: static void inv_mix_sub_columns( uint_8t dt[N_BLOCK] )
534: { uint_8t st[N_BLOCK];
535: block16_copy(st, dt);
536: #else
537: static void inv_mix_sub_columns( uint_8t dt[N_BLOCK], uint_8t st[N_BLOCK] )
538: {
539: #endif
540: dt[ 0] = inv_s_box[gfmul_e[st[ 0]] ^ gfmul_b[st[ 1]] ^ gfmul_d[st[ 2]] ^ gfmul_9[st[ 3]]];
541: dt[ 5] = inv_s_box[gfmul_9[st[ 0]] ^ gfmul_e[st[ 1]] ^ gfmul_b[st[ 2]] ^ gfmul_d[st[ 3]]];
542: dt[10] = inv_s_box[gfmul_d[st[ 0]] ^ gfmul_9[st[ 1]] ^ gfmul_e[st[ 2]] ^ gfmul_b[st[ 3]]];
543: dt[15] = inv_s_box[gfmul_b[st[ 0]] ^ gfmul_d[st[ 1]] ^ gfmul_9[st[ 2]] ^ gfmul_e[st[ 3]]];
544:
545: dt[ 4] = inv_s_box[gfmul_e[st[ 4]] ^ gfmul_b[st[ 5]] ^ gfmul_d[st[ 6]] ^ gfmul_9[st[ 7]]];
546: dt[ 9] = inv_s_box[gfmul_9[st[ 4]] ^ gfmul_e[st[ 5]] ^ gfmul_b[st[ 6]] ^ gfmul_d[st[ 7]]];
547: dt[14] = inv_s_box[gfmul_d[st[ 4]] ^ gfmul_9[st[ 5]] ^ gfmul_e[st[ 6]] ^ gfmul_b[st[ 7]]];
548: dt[ 3] = inv_s_box[gfmul_b[st[ 4]] ^ gfmul_d[st[ 5]] ^ gfmul_9[st[ 6]] ^ gfmul_e[st[ 7]]];
549:
550: dt[ 8] = inv_s_box[gfmul_e[st[ 8]] ^ gfmul_b[st[ 9]] ^ gfmul_d[st[10]] ^ gfmul_9[st[11]]];
551: dt[13] = inv_s_box[gfmul_9[st[ 8]] ^ gfmul_e[st[ 9]] ^ gfmul_b[st[10]] ^ gfmul_d[st[11]]];
552: dt[ 2] = inv_s_box[gfmul_d[st[ 8]] ^ gfmul_9[st[ 9]] ^ gfmul_e[st[10]] ^ gfmul_b[st[11]]];
553: dt[ 7] = inv_s_box[gfmul_b[st[ 8]] ^ gfmul_d[st[ 9]] ^ gfmul_9[st[10]] ^ gfmul_e[st[11]]];
554:
555: dt[12] = inv_s_box[gfmul_e[st[12]] ^ gfmul_b[st[13]] ^ gfmul_d[st[14]] ^ gfmul_9[st[15]]];
556: dt[ 1] = inv_s_box[gfmul_9[st[12]] ^ gfmul_e[st[13]] ^ gfmul_b[st[14]] ^ gfmul_d[st[15]]];
557: dt[ 6] = inv_s_box[gfmul_d[st[12]] ^ gfmul_9[st[13]] ^ gfmul_e[st[14]] ^ gfmul_b[st[15]]];
558: dt[11] = inv_s_box[gfmul_b[st[12]] ^ gfmul_d[st[13]] ^ gfmul_9[st[14]] ^ gfmul_e[st[15]]];
559: }
560:
561: #if defined( AES_ENC_PREKEYED ) || defined( AES_DEC_PREKEYED )
562:
563: /* Set the cipher key for the pre-keyed version */
564:
565: return_type aes_set_key( const unsigned char key[], length_type keylen, aes_context ctx[1] )
566: {
567: uint_8t cc, rc, hi;
568:
569: switch( keylen )
570: {
571: case 16:
572: case 128:
573: keylen = 16;
574: break;
575: case 24:
576: case 192:
577: keylen = 24;
578: break;
579: case 32:
580: case 256:
581: keylen = 32;
582: break;
583: default:
584: ctx->rnd = 0;
585: return -1;
586: }
587: block_copy(ctx->ksch, key, keylen);
588: hi = (keylen + 28) << 2;
589: ctx->rnd = (hi >> 4) - 1;
590: for( cc = keylen, rc = 1; cc < hi; cc += 4 )
591: { uint_8t tt, t0, t1, t2, t3;
592:
593: t0 = ctx->ksch[cc - 4];
594: t1 = ctx->ksch[cc - 3];
595: t2 = ctx->ksch[cc - 2];
596: t3 = ctx->ksch[cc - 1];
597: if( cc % keylen == 0 )
598: {
599: tt = t0;
600: t0 = s_box[t1] ^ rc;
601: t1 = s_box[t2];
602: t2 = s_box[t3];
603: t3 = s_box[tt];
604: rc = f2(rc);
605: }
606: else if( keylen > 24 && cc % keylen == 16 )
607: {
608: t0 = s_box[t0];
609: t1 = s_box[t1];
610: t2 = s_box[t2];
611: t3 = s_box[t3];
612: }
613: tt = cc - keylen;
614: ctx->ksch[cc + 0] = ctx->ksch[tt + 0] ^ t0;
615: ctx->ksch[cc + 1] = ctx->ksch[tt + 1] ^ t1;
616: ctx->ksch[cc + 2] = ctx->ksch[tt + 2] ^ t2;
617: ctx->ksch[cc + 3] = ctx->ksch[tt + 3] ^ t3;
618: }
619: return 0;
620: }
621:
622: #endif
623:
624: #if defined( AES_ENC_PREKEYED )
625:
626: /* Encrypt a single block of 16 bytes */
627:
628: return_type aes_encrypt( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK], const aes_context ctx[1] )
629: {
630: if( ctx->rnd )
631: {
632: uint_8t s1[N_BLOCK], r;
633: copy_and_key( s1, in, ctx->ksch );
634:
635: for( r = 1 ; r < ctx->rnd ; ++r )
636: #if defined( VERSION_1 )
637: {
638: mix_sub_columns( s1 );
639: add_round_key( s1, ctx->ksch + r * N_BLOCK);
640: }
641: #else
642: { uint_8t s2[N_BLOCK];
643: mix_sub_columns( s2, s1 );
644: copy_and_key( s1, s2, ctx->ksch + r * N_BLOCK);
645: }
646: #endif
647: shift_sub_rows( s1 );
648: copy_and_key( out, s1, ctx->ksch + r * N_BLOCK );
649: }
650: else
651: return -1;
652: return 0;
653: }
654:
655: #endif
656:
657: #if defined( AES_DEC_PREKEYED )
658:
659: /* Decrypt a single block of 16 bytes */
660:
661: return_type aes_decrypt( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK], const aes_context ctx[1] )
662: {
663: if( ctx->rnd )
664: {
665: uint_8t s1[N_BLOCK], r;
666: copy_and_key( s1, in, ctx->ksch + ctx->rnd * N_BLOCK );
667: inv_shift_sub_rows( s1 );
668:
669: for( r = ctx->rnd ; --r ; )
670: #if defined( VERSION_1 )
671: {
672: add_round_key( s1, ctx->ksch + r * N_BLOCK );
673: inv_mix_sub_columns( s1 );
674: }
675: #else
676: { uint_8t s2[N_BLOCK];
677: copy_and_key( s2, s1, ctx->ksch + r * N_BLOCK );
678: inv_mix_sub_columns( s1, s2 );
679: }
680: #endif
681: copy_and_key( out, s1, ctx->ksch );
682: }
683: else
684: return -1;
685: return 0;
686: }
687:
688: #endif
689:
690: #if defined( AES_ENC_128_OTFK )
691:
692: /* The 'on the fly' encryption key update for for 128 bit keys */
693:
694: static void update_encrypt_key_128( uint_8t k[N_BLOCK], uint_8t *rc )
695: { uint_8t cc;
696:
697: k[0] ^= s_box[k[13]] ^ *rc;
698: k[1] ^= s_box[k[14]];
699: k[2] ^= s_box[k[15]];
700: k[3] ^= s_box[k[12]];
701: *rc = f2( *rc );
702:
703: for(cc = 4; cc < 16; cc += 4 )
704: {
705: k[cc + 0] ^= k[cc - 4];
706: k[cc + 1] ^= k[cc - 3];
707: k[cc + 2] ^= k[cc - 2];
708: k[cc + 3] ^= k[cc - 1];
709: }
710: }
711:
712: /* Encrypt a single block of 16 bytes with 'on the fly' 128 bit keying */
713:
714: void aes_encrypt_128( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK],
715: const unsigned char key[N_BLOCK], unsigned char o_key[N_BLOCK] )
716: { uint_8t s1[N_BLOCK], r, rc = 1;
717:
718: if(o_key != key)
719: block16_copy( o_key, key );
720: copy_and_key( s1, in, o_key );
721:
722: for( r = 1 ; r < 10 ; ++r )
723: #if defined( VERSION_1 )
724: {
725: mix_sub_columns( s1 );
726: update_encrypt_key_128( o_key, &rc );
727: add_round_key( s1, o_key );
728: }
729: #else
730: { uint_8t s2[N_BLOCK];
731: mix_sub_columns( s2, s1 );
732: update_encrypt_key_128( o_key, &rc );
733: copy_and_key( s1, s2, o_key );
734: }
735: #endif
736:
737: shift_sub_rows( s1 );
738: update_encrypt_key_128( o_key, &rc );
739: copy_and_key( out, s1, o_key );
740: }
741:
742: #endif
743:
744: #if defined( AES_DEC_128_OTFK )
745:
746: /* The 'on the fly' decryption key update for for 128 bit keys */
747:
748: static void update_decrypt_key_128( uint_8t k[N_BLOCK], uint_8t *rc )
749: { uint_8t cc;
750:
751: for( cc = 12; cc > 0; cc -= 4 )
752: {
753: k[cc + 0] ^= k[cc - 4];
754: k[cc + 1] ^= k[cc - 3];
755: k[cc + 2] ^= k[cc - 2];
756: k[cc + 3] ^= k[cc - 1];
757: }
758: *rc = d2(*rc);
759: k[0] ^= s_box[k[13]] ^ *rc;
760: k[1] ^= s_box[k[14]];
761: k[2] ^= s_box[k[15]];
762: k[3] ^= s_box[k[12]];
763: }
764:
765: /* Decrypt a single block of 16 bytes with 'on the fly' 128 bit keying */
766:
767: void aes_decrypt_128( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK],
768: const unsigned char key[N_BLOCK], unsigned char o_key[N_BLOCK] )
769: {
770: uint_8t s1[N_BLOCK], r, rc = 0x6c;
771: if(o_key != key)
772: block16_copy( o_key, key );
773:
774: copy_and_key( s1, in, o_key );
775: inv_shift_sub_rows( s1 );
776:
777: for( r = 10 ; --r ; )
778: #if defined( VERSION_1 )
779: {
780: update_decrypt_key_128( o_key, &rc );
781: add_round_key( s1, o_key );
782: inv_mix_sub_columns( s1 );
783: }
784: #else
785: { uint_8t s2[N_BLOCK];
786: update_decrypt_key_128( o_key, &rc );
787: copy_and_key( s2, s1, o_key );
788: inv_mix_sub_columns( s1, s2 );
789: }
790: #endif
791: update_decrypt_key_128( o_key, &rc );
792: copy_and_key( out, s1, o_key );
793: }
794:
795: #endif
796:
797: #if defined( AES_ENC_256_OTFK )
798:
799: /* The 'on the fly' encryption key update for for 256 bit keys */
800:
801: static void update_encrypt_key_256( uint_8t k[2 * N_BLOCK], uint_8t *rc )
802: { uint_8t cc;
803:
804: k[0] ^= s_box[k[29]] ^ *rc;
805: k[1] ^= s_box[k[30]];
806: k[2] ^= s_box[k[31]];
807: k[3] ^= s_box[k[28]];
808: *rc = f2( *rc );
809:
810: for(cc = 4; cc < 16; cc += 4)
811: {
812: k[cc + 0] ^= k[cc - 4];
813: k[cc + 1] ^= k[cc - 3];
814: k[cc + 2] ^= k[cc - 2];
815: k[cc + 3] ^= k[cc - 1];
816: }
817:
818: k[16] ^= s_box[k[12]];
819: k[17] ^= s_box[k[13]];
820: k[18] ^= s_box[k[14]];
821: k[19] ^= s_box[k[15]];
822:
823: for( cc = 20; cc < 32; cc += 4 )
824: {
825: k[cc + 0] ^= k[cc - 4];
826: k[cc + 1] ^= k[cc - 3];
827: k[cc + 2] ^= k[cc - 2];
828: k[cc + 3] ^= k[cc - 1];
829: }
830: }
831:
832: /* Encrypt a single block of 16 bytes with 'on the fly' 256 bit keying */
833:
834: void aes_encrypt_256( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK],
835: const unsigned char key[2 * N_BLOCK], unsigned char o_key[2 * N_BLOCK] )
836: {
837: uint_8t s1[N_BLOCK], r, rc = 1;
838: if(o_key != key)
839: {
840: block16_copy( o_key, key );
841: block16_copy( o_key + 16, key + 16 );
842: }
843: copy_and_key( s1, in, o_key );
844:
845: for( r = 1 ; r < 14 ; ++r )
846: #if defined( VERSION_1 )
847: {
848: mix_sub_columns(s1);
849: if( r & 1 )
850: add_round_key( s1, o_key + 16 );
851: else
852: {
853: update_encrypt_key_256( o_key, &rc );
854: add_round_key( s1, o_key );
855: }
856: }
857: #else
858: { uint_8t s2[N_BLOCK];
859: mix_sub_columns( s2, s1 );
860: if( r & 1 )
861: copy_and_key( s1, s2, o_key + 16 );
862: else
863: {
864: update_encrypt_key_256( o_key, &rc );
865: copy_and_key( s1, s2, o_key );
866: }
867: }
868: #endif
869:
870: shift_sub_rows( s1 );
871: update_encrypt_key_256( o_key, &rc );
872: copy_and_key( out, s1, o_key );
873: }
874:
875: #endif
876:
877: #if defined( AES_DEC_256_OTFK )
878:
879: /* The 'on the fly' encryption key update for for 256 bit keys */
880:
881: static void update_decrypt_key_256( uint_8t k[2 * N_BLOCK], uint_8t *rc )
882: { uint_8t cc;
883:
884: for(cc = 28; cc > 16; cc -= 4)
885: {
886: k[cc + 0] ^= k[cc - 4];
887: k[cc + 1] ^= k[cc - 3];
888: k[cc + 2] ^= k[cc - 2];
889: k[cc + 3] ^= k[cc - 1];
890: }
891:
892: k[16] ^= s_box[k[12]];
893: k[17] ^= s_box[k[13]];
894: k[18] ^= s_box[k[14]];
895: k[19] ^= s_box[k[15]];
896:
897: for(cc = 12; cc > 0; cc -= 4)
898: {
899: k[cc + 0] ^= k[cc - 4];
900: k[cc + 1] ^= k[cc - 3];
901: k[cc + 2] ^= k[cc - 2];
902: k[cc + 3] ^= k[cc - 1];
903: }
904:
905: *rc = d2(*rc);
906: k[0] ^= s_box[k[29]] ^ *rc;
907: k[1] ^= s_box[k[30]];
908: k[2] ^= s_box[k[31]];
909: k[3] ^= s_box[k[28]];
910: }
911:
912: /* Decrypt a single block of 16 bytes with 'on the fly'
913: 256 bit keying
914: */
915: void aes_decrypt_256( const unsigned char in[N_BLOCK], unsigned char out[N_BLOCK],
916: const unsigned char key[2 * N_BLOCK], unsigned char o_key[2 * N_BLOCK] )
917: {
918: uint_8t s1[N_BLOCK], r, rc = 0x80;
919:
920: if(o_key != key)
921: {
922: block16_copy( o_key, key );
923: block16_copy( o_key + 16, key + 16 );
924: }
925:
926: copy_and_key( s1, in, o_key );
927: inv_shift_sub_rows( s1 );
928:
929: for( r = 14 ; --r ; )
930: #if defined( VERSION_1 )
931: {
932: if( ( r & 1 ) )
933: {
934: update_decrypt_key_256( o_key, &rc );
935: add_round_key( s1, o_key + 16 );
936: }
937: else
938: add_round_key( s1, o_key );
939: inv_mix_sub_columns( s1 );
940: }
941: #else
942: { uint_8t s2[N_BLOCK];
943: if( ( r & 1 ) )
944: {
945: update_decrypt_key_256( o_key, &rc );
946: copy_and_key( s2, s1, o_key + 16 );
947: }
948: else
949: copy_and_key( s2, s1, o_key );
950: inv_mix_sub_columns( s1, s2 );
951: }
952: #endif
953: copy_and_key( out, s1, o_key );
954: }
955:
956: #endif
This archive runs on limited infrastructure. Preserving old code on modern bandwidth. Automated agents are requested to crawl responsibly.