Add an internal-representation no-op function.
[u/mdw/catacomb] / serpent.c
1 /* -*-c-*-
2 *
3 * $Id: serpent.c,v 1.1 2000/06/17 12:08:43 mdw Exp $
4 *
5 * The Serpent block cipher
6 *
7 * (c) 2000 Straylight/Edgeware
8 */
9
10 /*----- Licensing notice --------------------------------------------------*
11 *
12 * This file is part of Catacomb.
13 *
14 * Catacomb is free software; you can redistribute it and/or modify
15 * it under the terms of the GNU Library General Public License as
16 * published by the Free Software Foundation; either version 2 of the
17 * License, or (at your option) any later version.
18 *
19 * Catacomb is distributed in the hope that it will be useful,
20 * but WITHOUT ANY WARRANTY; without even the implied warranty of
21 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
22 * GNU Library General Public License for more details.
23 *
24 * You should have received a copy of the GNU Library General Public
25 * License along with Catacomb; if not, write to the Free
26 * Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
27 * MA 02111-1307, USA.
28 */
29
30 /*----- Revision history --------------------------------------------------*
31 *
32 * $Log: serpent.c,v $
33 * Revision 1.1 2000/06/17 12:08:43 mdw
34 * New cipher.
35 *
36 */
37
38 /*----- Header files ------------------------------------------------------*/
39
40 #include <assert.h>
41 #include <stdio.h>
42
43 #include <mLib/bits.h>
44
45 #include "blkc.h"
46 #include "gcipher.h"
47 #include "serpent.h"
48 #include "serpent-sbox.h"
49
50 /*----- Global variables --------------------------------------------------*/
51
52 const octet serpent_keysz[] = { KSZ_RANGE, SERPENT_KEYSZ, 0, 32, 1 };
53
54 /*----- Main code ---------------------------------------------------------*/
55
56 /* --- @serpent_init@ --- *
57 *
58 * Arguments: @serpent_ctx *k@ = pointer to context block to initialize
59 * @const void *buf@ = pointer to input buffer
60 * @size_t sz@ = size of input buffer
61 *
62 * Returns: ---
63 *
64 * Use: Initializes a Serpent context. The key may be any length of
65 * up to 32 bytes (256 bits).
66 */
67
68 void serpent_init(serpent_ctx *k, const void *buf, size_t sz)
69 {
70 uint32 a;
71 unsigned b;
72 const octet *p, *q;
73 size_t i;
74 uint32 pk[8 + 132];
75
76 KSZ_ASSERT(serpent, sz);
77
78 /* --- Read the key into the buffer --- */
79
80 if (sz > 32)
81 sz = 32;
82 i = 0; p = buf; q = p + sz;
83 a = 0; b = 0;
84 while (p < q) {
85 a |= (uint32)*p++ << b;
86 b += 8;
87 if (b == 32) {
88 pk[i++] = a;
89 a = 0; b = 0;
90 }
91 }
92
93 /* --- Pad short keys --- */
94
95 if (i < 8) {
96 a |= 0x01 << b;
97 b += 8;
98 pk[i++] = a;
99 for (; i < 8; i++)
100 pk[i] = 0;
101 }
102
103 /* --- Expand the prekeys to fill the buffer --- */
104
105 for (i = 8; i < 8 + 132; i++) {
106 uint32 x = (pk[i - 8] ^ pk[i - 5] ^ pk[i - 3] ^ pk[i - 1] ^
107 (i - 8) ^ 0x9e3779b9);
108 k->k[i - 8] = pk[i] = ROL32(x, 11);
109 }
110
111 /* --- Now substitute everything --- */
112
113 i = 0;
114 goto midway;
115 while (i < 132) {
116 #define KSUB(r) do { \
117 uint32 a, b, c, d; \
118 a = k->k[i]; b = k->k[i + 1]; c = k->k[i + 2]; d = k->k[i + 3]; \
119 S##r(a, b, c, d); \
120 k->k[i] = a; k->k[i + 1] = b; k->k[i + 2] = c; k->k[i + 3] = d; \
121 i += 4; \
122 } while (0)
123 KSUB(2); KSUB(1); KSUB(0); KSUB(7);
124 KSUB(6); KSUB(5); KSUB(4);
125 midway:
126 KSUB(3);
127 #undef KSUB
128 }
129 }
130
131 /* --- @serpent_eblk@, @serpent_dblk@ --- *
132 *
133 * Arguments: @const serpent_ctx *k@ = pointer to key context
134 * @const uint32 s[4]@ = pointer to source block
135 * @uint32 d[4]@ = pointer to destination block
136 *
137 * Returns: ---
138 *
139 * Use: Low-level block encryption.
140 */
141
142 #define EROUND(a, b, c, d, r, k) do { \
143 a ^= *k++; b ^= *k++; c ^= *k++; d ^= *k++; \
144 S##r(a, b, c, d); \
145 a = ROL32(a, 13); c = ROL32(c, 3); b ^= a ^ c; d ^= c ^ (a << 3); \
146 b = ROL32(b, 1); d = ROL32(d, 7); a ^= b ^ d; c ^= d ^ (b << 7); \
147 a = ROL32(a, 5); c = ROL32(c, 22); \
148 } while (0)
149
150 #define DROUND(a, b, c, d, r, k) do { \
151 IS##r(a, b, c, d); \
152 d ^= *--k; c ^= *--k; b ^= *--k; a ^= *--k; \
153 a = ROR32(a, 5); c = ROR32(c, 22); a ^= b ^ d; c ^= d ^ (b << 7); \
154 b = ROR32(b, 1); d = ROR32(d, 7); b ^= a ^ c; d ^= c ^ (a << 3); \
155 a = ROR32(a, 13); c = ROR32(c, 3); \
156 } while (0)
157
158 void serpent_eblk(const serpent_ctx *k, const uint32 *s, uint32 *d)
159 {
160 uint32 aa = s[0], bb = s[1], cc = s[2], dd = s[3];
161 const uint32 *kk = k->k;
162
163 EROUND(aa, bb, cc, dd, 0, kk); EROUND(aa, bb, cc, dd, 1, kk);
164 EROUND(aa, bb, cc, dd, 2, kk); EROUND(aa, bb, cc, dd, 3, kk);
165 EROUND(aa, bb, cc, dd, 4, kk); EROUND(aa, bb, cc, dd, 5, kk);
166 EROUND(aa, bb, cc, dd, 6, kk); EROUND(aa, bb, cc, dd, 7, kk);
167
168 EROUND(aa, bb, cc, dd, 0, kk); EROUND(aa, bb, cc, dd, 1, kk);
169 EROUND(aa, bb, cc, dd, 2, kk); EROUND(aa, bb, cc, dd, 3, kk);
170 EROUND(aa, bb, cc, dd, 4, kk); EROUND(aa, bb, cc, dd, 5, kk);
171 EROUND(aa, bb, cc, dd, 6, kk); EROUND(aa, bb, cc, dd, 7, kk);
172
173 EROUND(aa, bb, cc, dd, 0, kk); EROUND(aa, bb, cc, dd, 1, kk);
174 EROUND(aa, bb, cc, dd, 2, kk); EROUND(aa, bb, cc, dd, 3, kk);
175 EROUND(aa, bb, cc, dd, 4, kk); EROUND(aa, bb, cc, dd, 5, kk);
176 EROUND(aa, bb, cc, dd, 6, kk); EROUND(aa, bb, cc, dd, 7, kk);
177
178 EROUND(aa, bb, cc, dd, 0, kk); EROUND(aa, bb, cc, dd, 1, kk);
179 EROUND(aa, bb, cc, dd, 2, kk); EROUND(aa, bb, cc, dd, 3, kk);
180 EROUND(aa, bb, cc, dd, 4, kk); EROUND(aa, bb, cc, dd, 5, kk);
181 EROUND(aa, bb, cc, dd, 6, kk);
182
183 aa ^= *kk++; bb ^= *kk++; cc ^= *kk++; dd ^= *kk++;
184 S7(aa, bb, cc, dd);
185 aa ^= *kk++; bb ^= *kk++; cc ^= *kk++; dd ^= *kk++;
186 d[0] = aa; d[1] = bb; d[2] = cc; d[3] = dd;
187 }
188
189 void serpent_dblk(const serpent_ctx *k, const uint32 *s, uint32 *d)
190 {
191 uint32 aa = s[0], bb = s[1], cc = s[2], dd = s[3];
192 const uint32 *kk = k->k + 132;
193
194 dd ^= *--kk; cc ^= *--kk; bb ^= *--kk; aa ^= *--kk;
195
196 DROUND(aa, bb, cc, dd, 7, kk); DROUND(aa, bb, cc, dd, 6, kk);
197 DROUND(aa, bb, cc, dd, 5, kk); DROUND(aa, bb, cc, dd, 4, kk);
198 DROUND(aa, bb, cc, dd, 3, kk); DROUND(aa, bb, cc, dd, 2, kk);
199 DROUND(aa, bb, cc, dd, 1, kk); DROUND(aa, bb, cc, dd, 0, kk);
200
201 DROUND(aa, bb, cc, dd, 7, kk); DROUND(aa, bb, cc, dd, 6, kk);
202 DROUND(aa, bb, cc, dd, 5, kk); DROUND(aa, bb, cc, dd, 4, kk);
203 DROUND(aa, bb, cc, dd, 3, kk); DROUND(aa, bb, cc, dd, 2, kk);
204 DROUND(aa, bb, cc, dd, 1, kk); DROUND(aa, bb, cc, dd, 0, kk);
205
206 DROUND(aa, bb, cc, dd, 7, kk); DROUND(aa, bb, cc, dd, 6, kk);
207 DROUND(aa, bb, cc, dd, 5, kk); DROUND(aa, bb, cc, dd, 4, kk);
208 DROUND(aa, bb, cc, dd, 3, kk); DROUND(aa, bb, cc, dd, 2, kk);
209 DROUND(aa, bb, cc, dd, 1, kk); DROUND(aa, bb, cc, dd, 0, kk);
210
211 DROUND(aa, bb, cc, dd, 7, kk); DROUND(aa, bb, cc, dd, 6, kk);
212 DROUND(aa, bb, cc, dd, 5, kk); DROUND(aa, bb, cc, dd, 4, kk);
213 DROUND(aa, bb, cc, dd, 3, kk); DROUND(aa, bb, cc, dd, 2, kk);
214 DROUND(aa, bb, cc, dd, 1, kk);
215
216 IS0(aa, bb, cc, dd);
217 dd ^= *--kk; cc ^= *--kk; bb ^= *--kk; aa ^= *--kk;
218 d[0] = aa; d[1] = bb; d[2] = cc; d[3] = dd;
219 }
220
221 BLKC_TEST(SERPENT, serpent)
222
223 /*----- That's all, folks -------------------------------------------------*/