3 * $Id: serpent.c,v 1.1 2000/06/17 12:08:43 mdw Exp $
5 * The Serpent block cipher
7 * (c) 2000 Straylight/Edgeware
10 /*----- Licensing notice --------------------------------------------------*
12 * This file is part of Catacomb.
14 * Catacomb is free software; you can redistribute it and/or modify
15 * it under the terms of the GNU Library General Public License as
16 * published by the Free Software Foundation; either version 2 of the
17 * License, or (at your option) any later version.
19 * Catacomb is distributed in the hope that it will be useful,
20 * but WITHOUT ANY WARRANTY; without even the implied warranty of
21 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
22 * GNU Library General Public License for more details.
24 * You should have received a copy of the GNU Library General Public
25 * License along with Catacomb; if not, write to the Free
26 * Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
30 /*----- Revision history --------------------------------------------------*
33 * Revision 1.1 2000/06/17 12:08:43 mdw
38 /*----- Header files ------------------------------------------------------*/
43 #include <mLib/bits.h>
48 #include "serpent-sbox.h"
50 /*----- Global variables --------------------------------------------------*/
52 const octet serpent_keysz
[] = { KSZ_RANGE
, SERPENT_KEYSZ
, 0, 32, 1 };
54 /*----- Main code ---------------------------------------------------------*/
56 /* --- @serpent_init@ --- *
58 * Arguments: @serpent_ctx *k@ = pointer to context block to initialize
59 * @const void *buf@ = pointer to input buffer
60 * @size_t sz@ = size of input buffer
64 * Use: Initializes a Serpent context. The key may be any length of
65 * up to 32 bytes (256 bits).
68 void serpent_init(serpent_ctx
*k
, const void *buf
, size_t sz
)
76 KSZ_ASSERT(serpent
, sz
);
78 /* --- Read the key into the buffer --- */
82 i
= 0; p
= buf
; q
= p
+ sz
;
85 a
|= (uint32
)*p
++ << b
;
93 /* --- Pad short keys --- */
103 /* --- Expand the prekeys to fill the buffer --- */
105 for (i
= 8; i
< 8 + 132; i
++) {
106 uint32 x
= (pk
[i
- 8] ^ pk
[i
- 5] ^ pk
[i
- 3] ^ pk
[i
- 1] ^
107 (i
- 8) ^ 0x9e3779b9);
108 k
->k
[i
- 8] = pk
[i
] = ROL32(x
, 11);
111 /* --- Now substitute everything --- */
116 #define KSUB(r) do { \
118 a = k->k[i]; b = k->k[i + 1]; c = k->k[i + 2]; d = k->k[i + 3]; \
120 k->k[i] = a; k->k[i + 1] = b; k->k[i + 2] = c; k->k[i + 3] = d; \
123 KSUB(2); KSUB(1); KSUB(0); KSUB(7);
124 KSUB(6); KSUB(5); KSUB(4);
131 /* --- @serpent_eblk@, @serpent_dblk@ --- *
133 * Arguments: @const serpent_ctx *k@ = pointer to key context
134 * @const uint32 s[4]@ = pointer to source block
135 * @uint32 d[4]@ = pointer to destination block
139 * Use: Low-level block encryption.
142 #define EROUND(a, b, c, d, r, k) do { \
143 a ^= *k++; b ^= *k++; c ^= *k++; d ^= *k++; \
145 a = ROL32(a, 13); c = ROL32(c, 3); b ^= a ^ c; d ^= c ^ (a << 3); \
146 b = ROL32(b, 1); d = ROL32(d, 7); a ^= b ^ d; c ^= d ^ (b << 7); \
147 a = ROL32(a, 5); c = ROL32(c, 22); \
150 #define DROUND(a, b, c, d, r, k) do { \
152 d ^= *--k; c ^= *--k; b ^= *--k; a ^= *--k; \
153 a = ROR32(a, 5); c = ROR32(c, 22); a ^= b ^ d; c ^= d ^ (b << 7); \
154 b = ROR32(b, 1); d = ROR32(d, 7); b ^= a ^ c; d ^= c ^ (a << 3); \
155 a = ROR32(a, 13); c = ROR32(c, 3); \
158 void serpent_eblk(const serpent_ctx
*k
, const uint32
*s
, uint32
*d
)
160 uint32 aa
= s
[0], bb
= s
[1], cc
= s
[2], dd
= s
[3];
161 const uint32
*kk
= k
->k
;
163 EROUND(aa
, bb
, cc
, dd
, 0, kk
); EROUND(aa
, bb
, cc
, dd
, 1, kk
);
164 EROUND(aa
, bb
, cc
, dd
, 2, kk
); EROUND(aa
, bb
, cc
, dd
, 3, kk
);
165 EROUND(aa
, bb
, cc
, dd
, 4, kk
); EROUND(aa
, bb
, cc
, dd
, 5, kk
);
166 EROUND(aa
, bb
, cc
, dd
, 6, kk
); EROUND(aa
, bb
, cc
, dd
, 7, kk
);
168 EROUND(aa
, bb
, cc
, dd
, 0, kk
); EROUND(aa
, bb
, cc
, dd
, 1, kk
);
169 EROUND(aa
, bb
, cc
, dd
, 2, kk
); EROUND(aa
, bb
, cc
, dd
, 3, kk
);
170 EROUND(aa
, bb
, cc
, dd
, 4, kk
); EROUND(aa
, bb
, cc
, dd
, 5, kk
);
171 EROUND(aa
, bb
, cc
, dd
, 6, kk
); EROUND(aa
, bb
, cc
, dd
, 7, kk
);
173 EROUND(aa
, bb
, cc
, dd
, 0, kk
); EROUND(aa
, bb
, cc
, dd
, 1, kk
);
174 EROUND(aa
, bb
, cc
, dd
, 2, kk
); EROUND(aa
, bb
, cc
, dd
, 3, kk
);
175 EROUND(aa
, bb
, cc
, dd
, 4, kk
); EROUND(aa
, bb
, cc
, dd
, 5, kk
);
176 EROUND(aa
, bb
, cc
, dd
, 6, kk
); EROUND(aa
, bb
, cc
, dd
, 7, kk
);
178 EROUND(aa
, bb
, cc
, dd
, 0, kk
); EROUND(aa
, bb
, cc
, dd
, 1, kk
);
179 EROUND(aa
, bb
, cc
, dd
, 2, kk
); EROUND(aa
, bb
, cc
, dd
, 3, kk
);
180 EROUND(aa
, bb
, cc
, dd
, 4, kk
); EROUND(aa
, bb
, cc
, dd
, 5, kk
);
181 EROUND(aa
, bb
, cc
, dd
, 6, kk
);
183 aa
^= *kk
++; bb
^= *kk
++; cc
^= *kk
++; dd
^= *kk
++;
185 aa
^= *kk
++; bb
^= *kk
++; cc
^= *kk
++; dd
^= *kk
++;
186 d
[0] = aa
; d
[1] = bb
; d
[2] = cc
; d
[3] = dd
;
189 void serpent_dblk(const serpent_ctx
*k
, const uint32
*s
, uint32
*d
)
191 uint32 aa
= s
[0], bb
= s
[1], cc
= s
[2], dd
= s
[3];
192 const uint32
*kk
= k
->k
+ 132;
194 dd
^= *--kk
; cc
^= *--kk
; bb
^= *--kk
; aa
^= *--kk
;
196 DROUND(aa
, bb
, cc
, dd
, 7, kk
); DROUND(aa
, bb
, cc
, dd
, 6, kk
);
197 DROUND(aa
, bb
, cc
, dd
, 5, kk
); DROUND(aa
, bb
, cc
, dd
, 4, kk
);
198 DROUND(aa
, bb
, cc
, dd
, 3, kk
); DROUND(aa
, bb
, cc
, dd
, 2, kk
);
199 DROUND(aa
, bb
, cc
, dd
, 1, kk
); DROUND(aa
, bb
, cc
, dd
, 0, kk
);
201 DROUND(aa
, bb
, cc
, dd
, 7, kk
); DROUND(aa
, bb
, cc
, dd
, 6, kk
);
202 DROUND(aa
, bb
, cc
, dd
, 5, kk
); DROUND(aa
, bb
, cc
, dd
, 4, kk
);
203 DROUND(aa
, bb
, cc
, dd
, 3, kk
); DROUND(aa
, bb
, cc
, dd
, 2, kk
);
204 DROUND(aa
, bb
, cc
, dd
, 1, kk
); DROUND(aa
, bb
, cc
, dd
, 0, kk
);
206 DROUND(aa
, bb
, cc
, dd
, 7, kk
); DROUND(aa
, bb
, cc
, dd
, 6, kk
);
207 DROUND(aa
, bb
, cc
, dd
, 5, kk
); DROUND(aa
, bb
, cc
, dd
, 4, kk
);
208 DROUND(aa
, bb
, cc
, dd
, 3, kk
); DROUND(aa
, bb
, cc
, dd
, 2, kk
);
209 DROUND(aa
, bb
, cc
, dd
, 1, kk
); DROUND(aa
, bb
, cc
, dd
, 0, kk
);
211 DROUND(aa
, bb
, cc
, dd
, 7, kk
); DROUND(aa
, bb
, cc
, dd
, 6, kk
);
212 DROUND(aa
, bb
, cc
, dd
, 5, kk
); DROUND(aa
, bb
, cc
, dd
, 4, kk
);
213 DROUND(aa
, bb
, cc
, dd
, 3, kk
); DROUND(aa
, bb
, cc
, dd
, 2, kk
);
214 DROUND(aa
, bb
, cc
, dd
, 1, kk
);
217 dd
^= *--kk
; cc
^= *--kk
; bb
^= *--kk
; aa
^= *--kk
;
218 d
[0] = aa
; d
[1] = bb
; d
[2] = cc
; d
[3] = dd
;
221 BLKC_TEST(SERPENT
, serpent
)
223 /*----- That's all, folks -------------------------------------------------*/