xref: /minix3/crypto/external/bsd/heimdal/dist/lib/hcrypto/aes.c (revision ebfedea0ce5bbe81e252ddf32d732e40fb633fae)
1*ebfedea0SLionel Sambuc /*	$NetBSD: aes.c,v 1.1.1.1 2011/04/13 18:14:49 elric Exp $	*/
2*ebfedea0SLionel Sambuc 
3*ebfedea0SLionel Sambuc /*
4*ebfedea0SLionel Sambuc  * Copyright (c) 2003 Kungliga Tekniska Högskolan
5*ebfedea0SLionel Sambuc  * (Royal Institute of Technology, Stockholm, Sweden).
6*ebfedea0SLionel Sambuc  * All rights reserved.
7*ebfedea0SLionel Sambuc  *
8*ebfedea0SLionel Sambuc  * Redistribution and use in source and binary forms, with or without
9*ebfedea0SLionel Sambuc  * modification, are permitted provided that the following conditions
10*ebfedea0SLionel Sambuc  * are met:
11*ebfedea0SLionel Sambuc  *
12*ebfedea0SLionel Sambuc  * 1. Redistributions of source code must retain the above copyright
13*ebfedea0SLionel Sambuc  *    notice, this list of conditions and the following disclaimer.
14*ebfedea0SLionel Sambuc  *
15*ebfedea0SLionel Sambuc  * 2. Redistributions in binary form must reproduce the above copyright
16*ebfedea0SLionel Sambuc  *    notice, this list of conditions and the following disclaimer in the
17*ebfedea0SLionel Sambuc  *    documentation and/or other materials provided with the distribution.
18*ebfedea0SLionel Sambuc  *
19*ebfedea0SLionel Sambuc  * 3. Neither the name of the Institute nor the names of its contributors
20*ebfedea0SLionel Sambuc  *    may be used to endorse or promote products derived from this software
21*ebfedea0SLionel Sambuc  *    without specific prior written permission.
22*ebfedea0SLionel Sambuc  *
23*ebfedea0SLionel Sambuc  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
24*ebfedea0SLionel Sambuc  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25*ebfedea0SLionel Sambuc  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26*ebfedea0SLionel Sambuc  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
27*ebfedea0SLionel Sambuc  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28*ebfedea0SLionel Sambuc  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29*ebfedea0SLionel Sambuc  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30*ebfedea0SLionel Sambuc  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31*ebfedea0SLionel Sambuc  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32*ebfedea0SLionel Sambuc  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33*ebfedea0SLionel Sambuc  * SUCH DAMAGE.
34*ebfedea0SLionel Sambuc  */
35*ebfedea0SLionel Sambuc 
36*ebfedea0SLionel Sambuc #include "config.h"
37*ebfedea0SLionel Sambuc 
38*ebfedea0SLionel Sambuc 
39*ebfedea0SLionel Sambuc #ifdef KRB5
40*ebfedea0SLionel Sambuc #include <krb5/krb5-types.h>
41*ebfedea0SLionel Sambuc #endif
42*ebfedea0SLionel Sambuc 
43*ebfedea0SLionel Sambuc #include <string.h>
44*ebfedea0SLionel Sambuc 
45*ebfedea0SLionel Sambuc #include "rijndael-alg-fst.h"
46*ebfedea0SLionel Sambuc #include "aes.h"
47*ebfedea0SLionel Sambuc 
48*ebfedea0SLionel Sambuc int
AES_set_encrypt_key(const unsigned char * userkey,const int bits,AES_KEY * key)49*ebfedea0SLionel Sambuc AES_set_encrypt_key(const unsigned char *userkey, const int bits, AES_KEY *key)
50*ebfedea0SLionel Sambuc {
51*ebfedea0SLionel Sambuc     key->rounds = rijndaelKeySetupEnc(key->key, userkey, bits);
52*ebfedea0SLionel Sambuc     if (key->rounds == 0)
53*ebfedea0SLionel Sambuc 	return -1;
54*ebfedea0SLionel Sambuc     return 0;
55*ebfedea0SLionel Sambuc }
56*ebfedea0SLionel Sambuc 
57*ebfedea0SLionel Sambuc int
AES_set_decrypt_key(const unsigned char * userkey,const int bits,AES_KEY * key)58*ebfedea0SLionel Sambuc AES_set_decrypt_key(const unsigned char *userkey, const int bits, AES_KEY *key)
59*ebfedea0SLionel Sambuc {
60*ebfedea0SLionel Sambuc     key->rounds = rijndaelKeySetupDec(key->key, userkey, bits);
61*ebfedea0SLionel Sambuc     if (key->rounds == 0)
62*ebfedea0SLionel Sambuc 	return -1;
63*ebfedea0SLionel Sambuc     return 0;
64*ebfedea0SLionel Sambuc }
65*ebfedea0SLionel Sambuc 
66*ebfedea0SLionel Sambuc void
AES_encrypt(const unsigned char * in,unsigned char * out,const AES_KEY * key)67*ebfedea0SLionel Sambuc AES_encrypt(const unsigned char *in, unsigned char *out, const AES_KEY *key)
68*ebfedea0SLionel Sambuc {
69*ebfedea0SLionel Sambuc     rijndaelEncrypt(key->key, key->rounds, in, out);
70*ebfedea0SLionel Sambuc }
71*ebfedea0SLionel Sambuc 
72*ebfedea0SLionel Sambuc void
AES_decrypt(const unsigned char * in,unsigned char * out,const AES_KEY * key)73*ebfedea0SLionel Sambuc AES_decrypt(const unsigned char *in, unsigned char *out, const AES_KEY *key)
74*ebfedea0SLionel Sambuc {
75*ebfedea0SLionel Sambuc     rijndaelDecrypt(key->key, key->rounds, in, out);
76*ebfedea0SLionel Sambuc }
77*ebfedea0SLionel Sambuc 
78*ebfedea0SLionel Sambuc void
AES_cbc_encrypt(const unsigned char * in,unsigned char * out,unsigned long size,const AES_KEY * key,unsigned char * iv,int forward_encrypt)79*ebfedea0SLionel Sambuc AES_cbc_encrypt(const unsigned char *in, unsigned char *out,
80*ebfedea0SLionel Sambuc 		unsigned long size, const AES_KEY *key,
81*ebfedea0SLionel Sambuc 		unsigned char *iv, int forward_encrypt)
82*ebfedea0SLionel Sambuc {
83*ebfedea0SLionel Sambuc     unsigned char tmp[AES_BLOCK_SIZE];
84*ebfedea0SLionel Sambuc     int i;
85*ebfedea0SLionel Sambuc 
86*ebfedea0SLionel Sambuc     if (forward_encrypt) {
87*ebfedea0SLionel Sambuc 	while (size >= AES_BLOCK_SIZE) {
88*ebfedea0SLionel Sambuc 	    for (i = 0; i < AES_BLOCK_SIZE; i++)
89*ebfedea0SLionel Sambuc 		tmp[i] = in[i] ^ iv[i];
90*ebfedea0SLionel Sambuc 	    AES_encrypt(tmp, out, key);
91*ebfedea0SLionel Sambuc 	    memcpy(iv, out, AES_BLOCK_SIZE);
92*ebfedea0SLionel Sambuc 	    size -= AES_BLOCK_SIZE;
93*ebfedea0SLionel Sambuc 	    in += AES_BLOCK_SIZE;
94*ebfedea0SLionel Sambuc 	    out += AES_BLOCK_SIZE;
95*ebfedea0SLionel Sambuc 	}
96*ebfedea0SLionel Sambuc 	if (size) {
97*ebfedea0SLionel Sambuc 	    for (i = 0; i < size; i++)
98*ebfedea0SLionel Sambuc 		tmp[i] = in[i] ^ iv[i];
99*ebfedea0SLionel Sambuc 	    for (i = size; i < AES_BLOCK_SIZE; i++)
100*ebfedea0SLionel Sambuc 		tmp[i] = iv[i];
101*ebfedea0SLionel Sambuc 	    AES_encrypt(tmp, out, key);
102*ebfedea0SLionel Sambuc 	    memcpy(iv, out, AES_BLOCK_SIZE);
103*ebfedea0SLionel Sambuc 	}
104*ebfedea0SLionel Sambuc     } else {
105*ebfedea0SLionel Sambuc 	while (size >= AES_BLOCK_SIZE) {
106*ebfedea0SLionel Sambuc 	    memcpy(tmp, in, AES_BLOCK_SIZE);
107*ebfedea0SLionel Sambuc 	    AES_decrypt(tmp, out, key);
108*ebfedea0SLionel Sambuc 	    for (i = 0; i < AES_BLOCK_SIZE; i++)
109*ebfedea0SLionel Sambuc 		out[i] ^= iv[i];
110*ebfedea0SLionel Sambuc 	    memcpy(iv, tmp, AES_BLOCK_SIZE);
111*ebfedea0SLionel Sambuc 	    size -= AES_BLOCK_SIZE;
112*ebfedea0SLionel Sambuc 	    in += AES_BLOCK_SIZE;
113*ebfedea0SLionel Sambuc 	    out += AES_BLOCK_SIZE;
114*ebfedea0SLionel Sambuc 	}
115*ebfedea0SLionel Sambuc 	if (size) {
116*ebfedea0SLionel Sambuc 	    memcpy(tmp, in, AES_BLOCK_SIZE);
117*ebfedea0SLionel Sambuc 	    AES_decrypt(tmp, out, key);
118*ebfedea0SLionel Sambuc 	    for (i = 0; i < size; i++)
119*ebfedea0SLionel Sambuc 		out[i] ^= iv[i];
120*ebfedea0SLionel Sambuc 	    memcpy(iv, tmp, AES_BLOCK_SIZE);
121*ebfedea0SLionel Sambuc 	}
122*ebfedea0SLionel Sambuc     }
123*ebfedea0SLionel Sambuc }
124*ebfedea0SLionel Sambuc 
125*ebfedea0SLionel Sambuc void
AES_cfb8_encrypt(const unsigned char * in,unsigned char * out,unsigned long size,const AES_KEY * key,unsigned char * iv,int forward_encrypt)126*ebfedea0SLionel Sambuc AES_cfb8_encrypt(const unsigned char *in, unsigned char *out,
127*ebfedea0SLionel Sambuc                  unsigned long size, const AES_KEY *key,
128*ebfedea0SLionel Sambuc                  unsigned char *iv, int forward_encrypt)
129*ebfedea0SLionel Sambuc {
130*ebfedea0SLionel Sambuc     int i;
131*ebfedea0SLionel Sambuc 
132*ebfedea0SLionel Sambuc     for (i = 0; i < size; i++) {
133*ebfedea0SLionel Sambuc         unsigned char tmp[AES_BLOCK_SIZE + 1];
134*ebfedea0SLionel Sambuc 
135*ebfedea0SLionel Sambuc         memcpy(tmp, iv, AES_BLOCK_SIZE);
136*ebfedea0SLionel Sambuc         AES_encrypt(iv, iv, key);
137*ebfedea0SLionel Sambuc         if (!forward_encrypt) {
138*ebfedea0SLionel Sambuc             tmp[AES_BLOCK_SIZE] = in[i];
139*ebfedea0SLionel Sambuc         }
140*ebfedea0SLionel Sambuc         out[i] = in[i] ^ iv[0];
141*ebfedea0SLionel Sambuc         if (forward_encrypt) {
142*ebfedea0SLionel Sambuc             tmp[AES_BLOCK_SIZE] = out[i];
143*ebfedea0SLionel Sambuc         }
144*ebfedea0SLionel Sambuc         memcpy(iv, &tmp[1], AES_BLOCK_SIZE);
145*ebfedea0SLionel Sambuc     }
146*ebfedea0SLionel Sambuc }
147