des-compat.c 5.43 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1 2 3 4 5 6 7
/* des-compat.h
 *
 * The des block cipher, libdes/openssl-style interface.
 */

/* nettle, low-level cryptographics library
 *
Niels Möller's avatar
Niels Möller committed
8
 * Copyright (C) 2001 Niels Möller
Niels Möller's avatar
Niels Möller committed
9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
 *  
 * The nettle library is free software; you can redistribute it and/or modify
 * it under the terms of the GNU Lesser General Public License as published by
 * the Free Software Foundation; either version 2.1 of the License, or (at your
 * option) any later version.
 * 
 * The nettle library is distributed in the hope that it will be useful, but
 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
 * or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General Public
 * License for more details.
 * 
 * You should have received a copy of the GNU Lesser General Public License
 * along with the nettle library; see the file COPYING.LIB.  If not, write to
 * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
 * MA 02111-1307, USA.
 */

26 27 28 29 30 31 32
#if HAVE_CONFIG_H
# include "config.h"
#endif

#include <string.h>
#include <assert.h>

Niels Möller's avatar
Niels Möller committed
33 34 35
#include "des-compat.h"

#include "cbc.h"
36
#include "macros.h"
Niels Möller's avatar
Niels Möller committed
37 38
#include "memxor.h"

39
struct des_compat_des3 { const struct des_ctx *keys[3]; }; 
40 41 42 43 44

static void
des_compat_des3_encrypt(struct des_compat_des3 *ctx,
			uint32_t length, uint8_t *dst, const uint8_t *src)
{
45 46 47
  nettle_des_encrypt(ctx->keys[0], length, dst, src);
  nettle_des_decrypt(ctx->keys[1], length, dst, dst);
  nettle_des_encrypt(ctx->keys[2], length, dst, dst);
48 49 50 51 52
}

static void
des_compat_des3_decrypt(struct des_compat_des3 *ctx,
			uint32_t length, uint8_t *dst, const uint8_t *src)
Niels Möller's avatar
Niels Möller committed
53
{
54 55 56
  nettle_des_decrypt(ctx->keys[2], length, dst, src);
  nettle_des_encrypt(ctx->keys[1], length, dst, dst);
  nettle_des_decrypt(ctx->keys[0], length, dst, dst);
57 58 59
}

void
60
des_ecb3_encrypt(const_des_cblock *src, des_cblock *dst,
61 62 63
		 des_key_schedule k1,
		 des_key_schedule k2,
		 des_key_schedule k3, int enc)
64
{
65 66 67 68
  struct des_compat_des3 keys;
  keys.keys[0] = k1;
  keys.keys[1] = k2;
  keys.keys[2] = k3;
69 70

  ((enc == DES_ENCRYPT) ? des_compat_des3_encrypt : des_compat_des3_decrypt)
71
    (&keys, DES_BLOCK_SIZE, *dst, *src);
Niels Möller's avatar
Niels Möller committed
72 73
}

74 75 76 77
/* If input is not a integral number of blocks, the final block is
   padded with zeros, no length field or anything like that. That's
   pretty broken, since it means that "$100" and "$100\0" always have
   the same checksum, but I think that's how it's supposed to work. */
78
uint32_t
79
des_cbc_cksum(const uint8_t *src, des_cblock *dst,
80
	      long length, des_key_schedule ctx,
81
	      const_des_cblock *iv)
Niels Möller's avatar
Niels Möller committed
82 83 84 85 86
{
  /* FIXME: I'm not entirely sure how this function is supposed to
   * work, in particular what it should return, and if iv can be
   * modified. */
  uint8_t block[DES_BLOCK_SIZE];
87 88

  memcpy(block, *iv, DES_BLOCK_SIZE);
89 90

  while (length >= DES_BLOCK_SIZE)
Niels Möller's avatar
Niels Möller committed
91
    {
92
      memxor(block, src, DES_BLOCK_SIZE);
93
      nettle_des_encrypt(ctx, DES_BLOCK_SIZE, block, block);
94 95 96 97 98 99 100 101

      src += DES_BLOCK_SIZE;
      length -= DES_BLOCK_SIZE;	  
    }
  if (length > 0)
    {
      memxor(block, src, length);
      nettle_des_encrypt(ctx, DES_BLOCK_SIZE, block, block);	  
Niels Möller's avatar
Niels Möller committed
102
    }
103
  memcpy(*dst, block, DES_BLOCK_SIZE);
104 105

  return LE_READ_UINT32(block + 4);
Niels Möller's avatar
Niels Möller committed
106 107
}

108
void
109
des_ncbc_encrypt(const_des_cblock *src, des_cblock *dst, long length,
110
                 des_key_schedule ctx, des_cblock *iv,
111 112 113 114 115
                 int enc)
{
  switch (enc)
    {
    case DES_ENCRYPT:
116
      nettle_cbc_encrypt(ctx, (nettle_crypt_func *) des_encrypt,
117 118
			 DES_BLOCK_SIZE, *iv,
			 length, *dst, *src);
119 120
      break;
    case DES_DECRYPT:
121
      nettle_cbc_decrypt(ctx,
122
			 (nettle_crypt_func *) des_decrypt,
123 124
			 DES_BLOCK_SIZE, *iv,
			 length, *dst, *src);
125 126 127 128 129
      break;
    default:
      abort();
    }
}
Niels Möller's avatar
Niels Möller committed
130 131

void
132 133
des_cbc_encrypt(const_des_cblock *src, des_cblock *dst, long length,
		des_key_schedule ctx, const_des_cblock *civ,
Niels Möller's avatar
Niels Möller committed
134 135
		int enc)
{
136
  des_cblock iv;
137 138

  memcpy(iv, civ, DES_BLOCK_SIZE);
Niels Möller's avatar
Niels Möller committed
139

140
  des_ncbc_encrypt(src, dst, length, ctx, &iv, enc);
141
}
Niels Möller's avatar
Niels Möller committed
142

143

Niels Möller's avatar
Niels Möller committed
144
void
145
des_ecb_encrypt(const_des_cblock *src, des_cblock *dst,
146
		des_key_schedule ctx,
Niels Möller's avatar
Niels Möller committed
147 148
		int enc)
{
149 150
  ((enc == DES_ENCRYPT) ? nettle_des_encrypt : nettle_des_decrypt)
    (ctx, DES_BLOCK_SIZE, *dst, *src);
Niels Möller's avatar
Niels Möller committed
151
}
152

Niels Möller's avatar
Niels Möller committed
153
void
154
des_ede3_cbc_encrypt(const_des_cblock *src, des_cblock *dst, long length,
155 156 157
		     des_key_schedule k1,
		     des_key_schedule k2,
		     des_key_schedule k3,
158
		     des_cblock *iv,
159 160
		     int enc)
{
161 162 163 164
  struct des_compat_des3 keys;
  keys.keys[0] = k1;
  keys.keys[1] = k2;
  keys.keys[2] = k3;
165

166 167 168
  switch (enc)
    {
    case DES_ENCRYPT:
169
      nettle_cbc_encrypt(&keys, (nettle_crypt_func *) des_compat_des3_encrypt,
170 171
			 DES_BLOCK_SIZE, *iv,
			 length, *dst, *src);
172 173
      break;
    case DES_DECRYPT:
174
      nettle_cbc_decrypt(&keys, (nettle_crypt_func *) des_compat_des3_decrypt,
175 176
			 DES_BLOCK_SIZE, *iv,
			 length, *dst, *src);
177 178 179 180
      break;
    default:
      abort();
    }
181
}
Niels Möller's avatar
Niels Möller committed
182 183

int
184
des_set_odd_parity(des_cblock *key)
185
{
186
  nettle_des_fix_parity(DES_KEY_SIZE, *key, *key);
Niels Möller's avatar
Niels Möller committed
187 188 189

  /* FIXME: What to return? */
  return 0;
190
}
Niels Möller's avatar
Niels Möller committed
191

192 193 194 195 196 197 198 199 200 201

/* If des_check_key is non-zero, returns
 *
 *   0 for ok, -1 for bad parity, and -2 for weak keys.
 *
 * If des_check_key is zero (the default), always returns zero.
 */

int des_check_key = 0;

Niels Möller's avatar
Niels Möller committed
202
int
203
des_key_sched(const_des_cblock *key, des_key_schedule ctx)
204
{
205 206 207
  if (des_check_key && !des_check_parity (DES_KEY_SIZE, *key))
    /* Bad parity */
    return -1;
208
  
209 210 211 212 213
  if (!nettle_des_set_key(ctx, *key) && des_check_key)
    /* Weak key */
    return -2;

  return 0;
214
}
Niels Möller's avatar
Niels Möller committed
215 216

int
217
des_is_weak_key(const_des_cblock *key)
218 219 220
{
  struct des_ctx ctx;

221
  return !nettle_des_set_key(&ctx, *key);
222
}