1*ebfedea0SLionel Sambuc /* $NetBSD: aes.c,v 1.1.1.1 2011/04/13 18:14:49 elric Exp $ */
2*ebfedea0SLionel Sambuc
3*ebfedea0SLionel Sambuc /*
4*ebfedea0SLionel Sambuc * Copyright (c) 2003 Kungliga Tekniska Högskolan
5*ebfedea0SLionel Sambuc * (Royal Institute of Technology, Stockholm, Sweden).
6*ebfedea0SLionel Sambuc * All rights reserved.
7*ebfedea0SLionel Sambuc *
8*ebfedea0SLionel Sambuc * Redistribution and use in source and binary forms, with or without
9*ebfedea0SLionel Sambuc * modification, are permitted provided that the following conditions
10*ebfedea0SLionel Sambuc * are met:
11*ebfedea0SLionel Sambuc *
12*ebfedea0SLionel Sambuc * 1. Redistributions of source code must retain the above copyright
13*ebfedea0SLionel Sambuc * notice, this list of conditions and the following disclaimer.
14*ebfedea0SLionel Sambuc *
15*ebfedea0SLionel Sambuc * 2. Redistributions in binary form must reproduce the above copyright
16*ebfedea0SLionel Sambuc * notice, this list of conditions and the following disclaimer in the
17*ebfedea0SLionel Sambuc * documentation and/or other materials provided with the distribution.
18*ebfedea0SLionel Sambuc *
19*ebfedea0SLionel Sambuc * 3. Neither the name of the Institute nor the names of its contributors
20*ebfedea0SLionel Sambuc * may be used to endorse or promote products derived from this software
21*ebfedea0SLionel Sambuc * without specific prior written permission.
22*ebfedea0SLionel Sambuc *
23*ebfedea0SLionel Sambuc * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
24*ebfedea0SLionel Sambuc * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25*ebfedea0SLionel Sambuc * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26*ebfedea0SLionel Sambuc * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
27*ebfedea0SLionel Sambuc * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28*ebfedea0SLionel Sambuc * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29*ebfedea0SLionel Sambuc * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30*ebfedea0SLionel Sambuc * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31*ebfedea0SLionel Sambuc * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32*ebfedea0SLionel Sambuc * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33*ebfedea0SLionel Sambuc * SUCH DAMAGE.
34*ebfedea0SLionel Sambuc */
35*ebfedea0SLionel Sambuc
36*ebfedea0SLionel Sambuc #include "config.h"
37*ebfedea0SLionel Sambuc
38*ebfedea0SLionel Sambuc
39*ebfedea0SLionel Sambuc #ifdef KRB5
40*ebfedea0SLionel Sambuc #include <krb5/krb5-types.h>
41*ebfedea0SLionel Sambuc #endif
42*ebfedea0SLionel Sambuc
43*ebfedea0SLionel Sambuc #include <string.h>
44*ebfedea0SLionel Sambuc
45*ebfedea0SLionel Sambuc #include "rijndael-alg-fst.h"
46*ebfedea0SLionel Sambuc #include "aes.h"
47*ebfedea0SLionel Sambuc
48*ebfedea0SLionel Sambuc int
AES_set_encrypt_key(const unsigned char * userkey,const int bits,AES_KEY * key)49*ebfedea0SLionel Sambuc AES_set_encrypt_key(const unsigned char *userkey, const int bits, AES_KEY *key)
50*ebfedea0SLionel Sambuc {
51*ebfedea0SLionel Sambuc key->rounds = rijndaelKeySetupEnc(key->key, userkey, bits);
52*ebfedea0SLionel Sambuc if (key->rounds == 0)
53*ebfedea0SLionel Sambuc return -1;
54*ebfedea0SLionel Sambuc return 0;
55*ebfedea0SLionel Sambuc }
56*ebfedea0SLionel Sambuc
57*ebfedea0SLionel Sambuc int
AES_set_decrypt_key(const unsigned char * userkey,const int bits,AES_KEY * key)58*ebfedea0SLionel Sambuc AES_set_decrypt_key(const unsigned char *userkey, const int bits, AES_KEY *key)
59*ebfedea0SLionel Sambuc {
60*ebfedea0SLionel Sambuc key->rounds = rijndaelKeySetupDec(key->key, userkey, bits);
61*ebfedea0SLionel Sambuc if (key->rounds == 0)
62*ebfedea0SLionel Sambuc return -1;
63*ebfedea0SLionel Sambuc return 0;
64*ebfedea0SLionel Sambuc }
65*ebfedea0SLionel Sambuc
66*ebfedea0SLionel Sambuc void
AES_encrypt(const unsigned char * in,unsigned char * out,const AES_KEY * key)67*ebfedea0SLionel Sambuc AES_encrypt(const unsigned char *in, unsigned char *out, const AES_KEY *key)
68*ebfedea0SLionel Sambuc {
69*ebfedea0SLionel Sambuc rijndaelEncrypt(key->key, key->rounds, in, out);
70*ebfedea0SLionel Sambuc }
71*ebfedea0SLionel Sambuc
72*ebfedea0SLionel Sambuc void
AES_decrypt(const unsigned char * in,unsigned char * out,const AES_KEY * key)73*ebfedea0SLionel Sambuc AES_decrypt(const unsigned char *in, unsigned char *out, const AES_KEY *key)
74*ebfedea0SLionel Sambuc {
75*ebfedea0SLionel Sambuc rijndaelDecrypt(key->key, key->rounds, in, out);
76*ebfedea0SLionel Sambuc }
77*ebfedea0SLionel Sambuc
78*ebfedea0SLionel Sambuc void
AES_cbc_encrypt(const unsigned char * in,unsigned char * out,unsigned long size,const AES_KEY * key,unsigned char * iv,int forward_encrypt)79*ebfedea0SLionel Sambuc AES_cbc_encrypt(const unsigned char *in, unsigned char *out,
80*ebfedea0SLionel Sambuc unsigned long size, const AES_KEY *key,
81*ebfedea0SLionel Sambuc unsigned char *iv, int forward_encrypt)
82*ebfedea0SLionel Sambuc {
83*ebfedea0SLionel Sambuc unsigned char tmp[AES_BLOCK_SIZE];
84*ebfedea0SLionel Sambuc int i;
85*ebfedea0SLionel Sambuc
86*ebfedea0SLionel Sambuc if (forward_encrypt) {
87*ebfedea0SLionel Sambuc while (size >= AES_BLOCK_SIZE) {
88*ebfedea0SLionel Sambuc for (i = 0; i < AES_BLOCK_SIZE; i++)
89*ebfedea0SLionel Sambuc tmp[i] = in[i] ^ iv[i];
90*ebfedea0SLionel Sambuc AES_encrypt(tmp, out, key);
91*ebfedea0SLionel Sambuc memcpy(iv, out, AES_BLOCK_SIZE);
92*ebfedea0SLionel Sambuc size -= AES_BLOCK_SIZE;
93*ebfedea0SLionel Sambuc in += AES_BLOCK_SIZE;
94*ebfedea0SLionel Sambuc out += AES_BLOCK_SIZE;
95*ebfedea0SLionel Sambuc }
96*ebfedea0SLionel Sambuc if (size) {
97*ebfedea0SLionel Sambuc for (i = 0; i < size; i++)
98*ebfedea0SLionel Sambuc tmp[i] = in[i] ^ iv[i];
99*ebfedea0SLionel Sambuc for (i = size; i < AES_BLOCK_SIZE; i++)
100*ebfedea0SLionel Sambuc tmp[i] = iv[i];
101*ebfedea0SLionel Sambuc AES_encrypt(tmp, out, key);
102*ebfedea0SLionel Sambuc memcpy(iv, out, AES_BLOCK_SIZE);
103*ebfedea0SLionel Sambuc }
104*ebfedea0SLionel Sambuc } else {
105*ebfedea0SLionel Sambuc while (size >= AES_BLOCK_SIZE) {
106*ebfedea0SLionel Sambuc memcpy(tmp, in, AES_BLOCK_SIZE);
107*ebfedea0SLionel Sambuc AES_decrypt(tmp, out, key);
108*ebfedea0SLionel Sambuc for (i = 0; i < AES_BLOCK_SIZE; i++)
109*ebfedea0SLionel Sambuc out[i] ^= iv[i];
110*ebfedea0SLionel Sambuc memcpy(iv, tmp, AES_BLOCK_SIZE);
111*ebfedea0SLionel Sambuc size -= AES_BLOCK_SIZE;
112*ebfedea0SLionel Sambuc in += AES_BLOCK_SIZE;
113*ebfedea0SLionel Sambuc out += AES_BLOCK_SIZE;
114*ebfedea0SLionel Sambuc }
115*ebfedea0SLionel Sambuc if (size) {
116*ebfedea0SLionel Sambuc memcpy(tmp, in, AES_BLOCK_SIZE);
117*ebfedea0SLionel Sambuc AES_decrypt(tmp, out, key);
118*ebfedea0SLionel Sambuc for (i = 0; i < size; i++)
119*ebfedea0SLionel Sambuc out[i] ^= iv[i];
120*ebfedea0SLionel Sambuc memcpy(iv, tmp, AES_BLOCK_SIZE);
121*ebfedea0SLionel Sambuc }
122*ebfedea0SLionel Sambuc }
123*ebfedea0SLionel Sambuc }
124*ebfedea0SLionel Sambuc
125*ebfedea0SLionel Sambuc void
AES_cfb8_encrypt(const unsigned char * in,unsigned char * out,unsigned long size,const AES_KEY * key,unsigned char * iv,int forward_encrypt)126*ebfedea0SLionel Sambuc AES_cfb8_encrypt(const unsigned char *in, unsigned char *out,
127*ebfedea0SLionel Sambuc unsigned long size, const AES_KEY *key,
128*ebfedea0SLionel Sambuc unsigned char *iv, int forward_encrypt)
129*ebfedea0SLionel Sambuc {
130*ebfedea0SLionel Sambuc int i;
131*ebfedea0SLionel Sambuc
132*ebfedea0SLionel Sambuc for (i = 0; i < size; i++) {
133*ebfedea0SLionel Sambuc unsigned char tmp[AES_BLOCK_SIZE + 1];
134*ebfedea0SLionel Sambuc
135*ebfedea0SLionel Sambuc memcpy(tmp, iv, AES_BLOCK_SIZE);
136*ebfedea0SLionel Sambuc AES_encrypt(iv, iv, key);
137*ebfedea0SLionel Sambuc if (!forward_encrypt) {
138*ebfedea0SLionel Sambuc tmp[AES_BLOCK_SIZE] = in[i];
139*ebfedea0SLionel Sambuc }
140*ebfedea0SLionel Sambuc out[i] = in[i] ^ iv[0];
141*ebfedea0SLionel Sambuc if (forward_encrypt) {
142*ebfedea0SLionel Sambuc tmp[AES_BLOCK_SIZE] = out[i];
143*ebfedea0SLionel Sambuc }
144*ebfedea0SLionel Sambuc memcpy(iv, &tmp[1], AES_BLOCK_SIZE);
145*ebfedea0SLionel Sambuc }
146*ebfedea0SLionel Sambuc }
147