camellia-internal.h 4.09 KB
Newer Older
1 2
/* camellia-internal.h

3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35
   The camellia block cipher.

   Copyright (C) 2006,2007 NTT
   (Nippon Telegraph and Telephone Corporation).

   Copyright (C) 2010 Niels Möller

   This file is part of GNU Nettle.

   GNU Nettle is free software: you can redistribute it and/or
   modify it under the terms of either:

     * the GNU Lesser General Public License as published by the Free
       Software Foundation; either version 3 of the License, or (at your
       option) any later version.

   or

     * the GNU General Public License as published by the Free
       Software Foundation; either version 2 of the License, or (at your
       option) any later version.

   or both in parallel, as here.

   GNU Nettle is distributed in the hope that it will be useful,
   but WITHOUT ANY WARRANTY; without even the implied warranty of
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
   General Public License for more details.

   You should have received copies of the GNU General Public License and
   the GNU Lesser General Public License along with this program.  If
   not, see http://www.gnu.org/licenses/.
*/
36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52

/*
 * Algorithm Specification 
 *  http://info.isl.ntt.co.jp/crypt/eng/camellia/specifications.html
 */

/* Based on camellia.c ver 1.2.0, see
   http://info.isl.ntt.co.jp/crypt/eng/camellia/dl/camellia-LGPL-1.2.0.tar.gz.
 */

#ifndef NETTLE_CAMELLIA_INTERNAL_H_INCLUDED
#define NETTLE_CAMELLIA_INTERNAL_H_INCLUDED

#include "camellia.h"

/* Name mangling */
#define _camellia_crypt _nettle_camellia_crypt
Niels Möller's avatar
Niels Möller committed
53 54
#define _camellia_absorb _nettle_camellia_absorb
#define _camellia_invert_key _nettle_camellia_invert_key
55 56 57 58 59 60 61
#define _camellia_table _nettle_camellia_table

/*
 *  macros
 */

/* Destructive rotation of 128 bit values. */
62
#define ROTL128(bits, xl, xr) do {		\
63 64 65 66 67 68 69 70 71 72 73 74 75
    uint64_t __rol128_t = (xl);			     \
    (xl) = ((xl) << (bits)) | ((xr) >> (64 - (bits)));	   \
    (xr) = ((xr) << (bits)) | (__rol128_t >> (64 - (bits)));	\
  } while (0)

struct camellia_table
{
  uint32_t sp1110[256];
  uint32_t sp0222[256];
  uint32_t sp3033[256];
  uint32_t sp4404[256];
};

Niels Möller's avatar
Niels Möller committed
76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118
/* key constants */

#define SIGMA1 0xA09E667F3BCC908BULL
#define SIGMA2 0xB67AE8584CAA73B2ULL
#define SIGMA3 0xC6EF372FE94F82BEULL
#define SIGMA4 0x54FF53A5F1D36F1CULL
#define SIGMA5 0x10E527FADE682D1DULL
#define SIGMA6 0xB05688C2B3E6C1FDULL

#define CAMELLIA_SP1110(INDEX) (_nettle_camellia_table.sp1110[(int)(INDEX)])
#define CAMELLIA_SP0222(INDEX) (_nettle_camellia_table.sp0222[(int)(INDEX)])
#define CAMELLIA_SP3033(INDEX) (_nettle_camellia_table.sp3033[(int)(INDEX)])
#define CAMELLIA_SP4404(INDEX) (_nettle_camellia_table.sp4404[(int)(INDEX)])

#define CAMELLIA_F(x, k, y) do {		\
    uint32_t __yl, __yr;			\
    uint64_t __i = (x) ^ (k);			\
    __yl					\
      = CAMELLIA_SP1110( __i & 0xff)		\
      ^ CAMELLIA_SP0222((__i >> 24) & 0xff)	\
      ^ CAMELLIA_SP3033((__i >> 16) & 0xff)	\
      ^ CAMELLIA_SP4404((__i >> 8) & 0xff);	\
    __yr					\
      = CAMELLIA_SP1110( __i >> 56)		\
      ^ CAMELLIA_SP0222((__i >> 48) & 0xff)	\
      ^ CAMELLIA_SP3033((__i >> 40) & 0xff)	\
      ^ CAMELLIA_SP4404((__i >> 32) & 0xff);	\
    __yl ^= __yr;				\
    __yr = ROTL32(24, __yr);			\
    __yr ^= __yl;				\
    (y) = ((uint64_t) __yl << 32) | __yr;	\
  } while (0)

#if ! HAVE_NATIVE_64_BIT
#define CAMELLIA_F_HALF_INV(x) do {            \
    uint32_t __t, __w;                         \
    __t = (x) >> 32;                           \
    __w = __t ^(x);                            \
    __w = ROTL32(8, __w);                       \
    (x) = ((uint64_t) __w << 32) | (__t ^ __w);        \
  } while (0)
#endif

119
void
Niels Möller's avatar
Niels Möller committed
120
_camellia_crypt(unsigned nkeys, const uint64_t *keys,
121
		const struct camellia_table *T,
122
		size_t length, uint8_t *dst,
123 124
		const uint8_t *src);

Niels Möller's avatar
Niels Möller committed
125 126 127 128 129 130 131 132 133 134
/* The initial NKEYS + 2 subkeys in SUBKEY are reduced to the final
   NKEYS subkeys stored in DST. SUBKEY data is modified in the
   process. */
void
_camellia_absorb(unsigned nkeys, uint64_t *dst, uint64_t *subkey);

void
_camellia_invert_key(unsigned nkeys,
		     uint64_t *dst, const uint64_t *src);

135 136 137
extern const struct camellia_table _camellia_table;

#endif /* NETTLE_CAMELLIA_INTERNAL_H_INCLUDED */