des-compat.c 5.59 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
/* des-compat.h
 *
 * The des block cipher, libdes/openssl-style interface.
 */

/* nettle, low-level cryptographics library
 *
 * Copyright (C) 2001 Niels Möller
 *  
 * The nettle library is free software; you can redistribute it and/or modify
 * it under the terms of the GNU Lesser General Public License as published by
 * the Free Software Foundation; either version 2.1 of the License, or (at your
 * option) any later version.
 * 
 * The nettle library is distributed in the hope that it will be useful, but
 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
 * or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General Public
 * License for more details.
 * 
 * You should have received a copy of the GNU Lesser General Public License
 * along with the nettle library; see the file COPYING.LIB.  If not, write to
 * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
 * MA 02111-1307, USA.
 */

26 27 28 29 30 31 32
#if HAVE_CONFIG_H
# include "config.h"
#endif

#include <string.h>
#include <assert.h>

Niels Möller's avatar
Niels Möller committed
33 34 35
#include "des-compat.h"

#include "cbc.h"
36
#include "macros.h"
Niels Möller's avatar
Niels Möller committed
37 38
#include "memxor.h"

39
struct des_compat_des3 { const struct des_ctx *keys[3]; }; 
40

41
typedef void (*cbc_crypt_func)(const void *, uint32_t, uint8_t *, const uint8_t *);
42 43 44 45 46

static void
des_compat_des3_encrypt(struct des_compat_des3 *ctx,
			uint32_t length, uint8_t *dst, const uint8_t *src)
{
47 48 49
  nettle_des_encrypt(ctx->keys[0], length, dst, src);
  nettle_des_decrypt(ctx->keys[1], length, dst, dst);
  nettle_des_encrypt(ctx->keys[2], length, dst, dst);
50 51 52 53 54
}

static void
des_compat_des3_decrypt(struct des_compat_des3 *ctx,
			uint32_t length, uint8_t *dst, const uint8_t *src)
Niels Möller's avatar
Niels Möller committed
55
{
56 57 58
  nettle_des_decrypt(ctx->keys[2], length, dst, src);
  nettle_des_encrypt(ctx->keys[1], length, dst, dst);
  nettle_des_decrypt(ctx->keys[0], length, dst, dst);
59 60 61
}

void
62 63 64
des_ecb3_encrypt(const des_cblock *src, des_cblock *dst,
		 const des_key_schedule k1, const des_key_schedule k2,
		 const des_key_schedule k3, int enc)
65
{
66 67 68 69
  struct des_compat_des3 keys;
  keys.keys[0] = k1;
  keys.keys[1] = k2;
  keys.keys[2] = k3;
70 71

  ((enc == DES_ENCRYPT) ? des_compat_des3_encrypt : des_compat_des3_decrypt)
72
    (&keys, DES_BLOCK_SIZE, *dst, *src);
Niels Möller's avatar
Niels Möller committed
73 74
}

75
uint32_t
76 77 78
des_cbc_cksum(const des_cblock *src, des_cblock *dst,
	      long length, const des_key_schedule ctx,
	      const des_cblock *iv)
Niels Möller's avatar
Niels Möller committed
79 80 81 82 83
{
  /* FIXME: I'm not entirely sure how this function is supposed to
   * work, in particular what it should return, and if iv can be
   * modified. */
  uint8_t block[DES_BLOCK_SIZE];
84
  const uint8_t *p;
85 86

  memcpy(block, *iv, DES_BLOCK_SIZE);
87
  
Niels Möller's avatar
Niels Möller committed
88 89
  assert(!(length % DES_BLOCK_SIZE));
  
90
  for (p = *src; length; length -= DES_BLOCK_SIZE, p += DES_BLOCK_SIZE)
Niels Möller's avatar
Niels Möller committed
91
    {
92
      memxor(block, p, DES_BLOCK_SIZE);
93
      nettle_des_encrypt(ctx, DES_BLOCK_SIZE, block, block);
Niels Möller's avatar
Niels Möller committed
94
    }
95
  memcpy(*dst, block, DES_BLOCK_SIZE);
96 97

  return LE_READ_UINT32(block + 4);
Niels Möller's avatar
Niels Möller committed
98 99
}

100
void
101 102
des_ncbc_encrypt(const des_cblock *src, des_cblock *dst, long length,
                 const des_key_schedule ctx, des_cblock *iv,
103 104 105 106 107
                 int enc)
{
  switch (enc)
    {
    case DES_ENCRYPT:
108 109 110
      nettle_cbc_encrypt(ctx, (cbc_crypt_func) des_encrypt,
			 DES_BLOCK_SIZE, *iv,
			 length, *dst, *src);
111 112
      break;
    case DES_DECRYPT:
113 114 115 116
      nettle_cbc_decrypt(ctx,
			 (cbc_crypt_func) des_decrypt,
			 DES_BLOCK_SIZE, *iv,
			 length, *dst, *src);
117 118 119 120 121
      break;
    default:
      abort();
    }
}
Niels Möller's avatar
Niels Möller committed
122 123

void
124 125
des_cbc_encrypt(const des_cblock *src, des_cblock *dst, long length,
		const des_key_schedule ctx, const des_cblock *civ,
Niels Möller's avatar
Niels Möller committed
126 127
		int enc)
{
128
  des_cblock iv;
129 130

  memcpy(iv, civ, DES_BLOCK_SIZE);
Niels Möller's avatar
Niels Möller committed
131

132
  des_ncbc_encrypt(src, dst, length, ctx, &iv, enc);
133
}
Niels Möller's avatar
Niels Möller committed
134

135

Niels Möller's avatar
Niels Möller committed
136
void
137 138
des_ecb_encrypt(const des_cblock *src, des_cblock *dst,
		const des_key_schedule ctx,
Niels Möller's avatar
Niels Möller committed
139 140
		int enc)
{
141 142
  ((enc == DES_ENCRYPT) ? nettle_des_encrypt : nettle_des_decrypt)
    (ctx, DES_BLOCK_SIZE, *dst, *src);
Niels Möller's avatar
Niels Möller committed
143
}
144

Niels Möller's avatar
Niels Möller committed
145
void
146 147 148 149
des_ede3_cbc_encrypt(const des_cblock *src, des_cblock *dst, long length,
		     const des_key_schedule k1,
		     const des_key_schedule k2,
		     const des_key_schedule k3,
150
		     des_cblock *iv,
151 152
		     int enc)
{
153 154 155 156
  struct des_compat_des3 keys;
  keys.keys[0] = k1;
  keys.keys[1] = k2;
  keys.keys[2] = k3;
157

158 159 160
  switch (enc)
    {
    case DES_ENCRYPT:
161 162 163
      nettle_cbc_encrypt(&keys, (cbc_crypt_func) des_compat_des3_encrypt,
			 DES_BLOCK_SIZE, *iv,
			 length, *dst, *src);
164 165
      break;
    case DES_DECRYPT:
166 167 168
      nettle_cbc_decrypt(&keys, (cbc_crypt_func) des_compat_des3_decrypt,
			 DES_BLOCK_SIZE, *iv,
			 length, *dst, *src);
169 170 171 172
      break;
    default:
      abort();
    }
173
}
Niels Möller's avatar
Niels Möller committed
174 175

int
176
des_set_odd_parity(des_cblock *key)
177
{
178
  nettle_des_fix_parity(DES_KEY_SIZE, *key, *key);
Niels Möller's avatar
Niels Möller committed
179 180 181

  /* FIXME: What to return? */
  return 0;
182
}
Niels Möller's avatar
Niels Möller committed
183

184 185 186 187 188 189 190 191 192 193

/* If des_check_key is non-zero, returns
 *
 *   0 for ok, -1 for bad parity, and -2 for weak keys.
 *
 * If des_check_key is zero (the default), always returns zero.
 */

int des_check_key = 0;

Niels Möller's avatar
Niels Möller committed
194
int
195
des_key_sched(const des_cblock *key, des_key_schedule ctx)
196
{
197 198
  des_cblock nkey;
  const uint8_t *pkey;
199
  
200 201 202 203 204 205 206 207 208 209
  if (des_check_key)
    pkey = *key;
  else
    {
      /* Fix the parity */
      nettle_des_fix_parity(DES_KEY_SIZE, nkey, *key);
      pkey = nkey;
    }
  
  if (nettle_des_set_key(ctx, pkey))
Niels Möller's avatar
Niels Möller committed
210 211 212 213
    return 0;
  else switch(ctx->status)
    {
    case DES_BAD_PARITY:
214 215 216 217 218
      if (des_check_key)
        return -1;
      else
        /* We fixed the parity above */
        abort();
Niels Möller's avatar
Niels Möller committed
219
    case DES_WEAK_KEY:
220 221 222 223 224 225 226
      if (des_check_key)
        return -2;

      /* Pretend the key was good */
      ctx->status = DES_OK;
      return 0;
      
Niels Möller's avatar
Niels Möller committed
227 228 229
    default:
      abort();
    }
230
}
Niels Möller's avatar
Niels Möller committed
231 232

int
233
des_is_weak_key(const des_cblock *key)
234 235 236
{
  struct des_ctx ctx;

237
  return !nettle_des_set_key(&ctx, *key);
238
}