1e1051a39Sopenharmony_ci/* 2e1051a39Sopenharmony_ci * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved. 3e1051a39Sopenharmony_ci * 4e1051a39Sopenharmony_ci * Licensed under the Apache License 2.0 (the "License"). You may not use 5e1051a39Sopenharmony_ci * this file except in compliance with the License. You can obtain a copy 6e1051a39Sopenharmony_ci * in the file LICENSE in the source distribution or at 7e1051a39Sopenharmony_ci * https://www.openssl.org/source/license.html 8e1051a39Sopenharmony_ci */ 9e1051a39Sopenharmony_ci 10e1051a39Sopenharmony_ci/* 11e1051a39Sopenharmony_ci * CAST low level APIs are deprecated for public use, but still ok for 12e1051a39Sopenharmony_ci * internal use. 13e1051a39Sopenharmony_ci */ 14e1051a39Sopenharmony_ci#include "internal/deprecated.h" 15e1051a39Sopenharmony_ci 16e1051a39Sopenharmony_ci#include <openssl/cast.h> 17e1051a39Sopenharmony_ci#include "cast_local.h" 18e1051a39Sopenharmony_ci 19e1051a39Sopenharmony_civoid CAST_encrypt(CAST_LONG *data, const CAST_KEY *key) 20e1051a39Sopenharmony_ci{ 21e1051a39Sopenharmony_ci CAST_LONG l, r, t; 22e1051a39Sopenharmony_ci const CAST_LONG *k; 23e1051a39Sopenharmony_ci 24e1051a39Sopenharmony_ci k = &(key->data[0]); 25e1051a39Sopenharmony_ci l = data[0]; 26e1051a39Sopenharmony_ci r = data[1]; 27e1051a39Sopenharmony_ci 28e1051a39Sopenharmony_ci E_CAST(0, k, l, r, +, ^, -); 29e1051a39Sopenharmony_ci E_CAST(1, k, r, l, ^, -, +); 30e1051a39Sopenharmony_ci E_CAST(2, k, l, r, -, +, ^); 31e1051a39Sopenharmony_ci E_CAST(3, k, r, l, +, ^, -); 32e1051a39Sopenharmony_ci E_CAST(4, k, l, r, ^, -, +); 33e1051a39Sopenharmony_ci E_CAST(5, k, r, l, -, +, ^); 34e1051a39Sopenharmony_ci E_CAST(6, k, l, r, +, ^, -); 35e1051a39Sopenharmony_ci E_CAST(7, k, r, l, ^, -, +); 36e1051a39Sopenharmony_ci E_CAST(8, k, l, r, -, +, ^); 37e1051a39Sopenharmony_ci E_CAST(9, k, r, l, +, ^, -); 38e1051a39Sopenharmony_ci E_CAST(10, k, l, r, ^, -, +); 39e1051a39Sopenharmony_ci E_CAST(11, k, r, l, -, +, ^); 40e1051a39Sopenharmony_ci if (!key->short_key) { 41e1051a39Sopenharmony_ci E_CAST(12, k, l, r, +, ^, -); 42e1051a39Sopenharmony_ci E_CAST(13, k, r, l, ^, -, +); 43e1051a39Sopenharmony_ci E_CAST(14, k, l, r, -, +, ^); 44e1051a39Sopenharmony_ci E_CAST(15, k, r, l, +, ^, -); 45e1051a39Sopenharmony_ci } 46e1051a39Sopenharmony_ci 47e1051a39Sopenharmony_ci data[1] = l & 0xffffffffL; 48e1051a39Sopenharmony_ci data[0] = r & 0xffffffffL; 49e1051a39Sopenharmony_ci} 50e1051a39Sopenharmony_ci 51e1051a39Sopenharmony_civoid CAST_decrypt(CAST_LONG *data, const CAST_KEY *key) 52e1051a39Sopenharmony_ci{ 53e1051a39Sopenharmony_ci CAST_LONG l, r, t; 54e1051a39Sopenharmony_ci const CAST_LONG *k; 55e1051a39Sopenharmony_ci 56e1051a39Sopenharmony_ci k = &(key->data[0]); 57e1051a39Sopenharmony_ci l = data[0]; 58e1051a39Sopenharmony_ci r = data[1]; 59e1051a39Sopenharmony_ci 60e1051a39Sopenharmony_ci if (!key->short_key) { 61e1051a39Sopenharmony_ci E_CAST(15, k, l, r, +, ^, -); 62e1051a39Sopenharmony_ci E_CAST(14, k, r, l, -, +, ^); 63e1051a39Sopenharmony_ci E_CAST(13, k, l, r, ^, -, +); 64e1051a39Sopenharmony_ci E_CAST(12, k, r, l, +, ^, -); 65e1051a39Sopenharmony_ci } 66e1051a39Sopenharmony_ci E_CAST(11, k, l, r, -, +, ^); 67e1051a39Sopenharmony_ci E_CAST(10, k, r, l, ^, -, +); 68e1051a39Sopenharmony_ci E_CAST(9, k, l, r, +, ^, -); 69e1051a39Sopenharmony_ci E_CAST(8, k, r, l, -, +, ^); 70e1051a39Sopenharmony_ci E_CAST(7, k, l, r, ^, -, +); 71e1051a39Sopenharmony_ci E_CAST(6, k, r, l, +, ^, -); 72e1051a39Sopenharmony_ci E_CAST(5, k, l, r, -, +, ^); 73e1051a39Sopenharmony_ci E_CAST(4, k, r, l, ^, -, +); 74e1051a39Sopenharmony_ci E_CAST(3, k, l, r, +, ^, -); 75e1051a39Sopenharmony_ci E_CAST(2, k, r, l, -, +, ^); 76e1051a39Sopenharmony_ci E_CAST(1, k, l, r, ^, -, +); 77e1051a39Sopenharmony_ci E_CAST(0, k, r, l, +, ^, -); 78e1051a39Sopenharmony_ci 79e1051a39Sopenharmony_ci data[1] = l & 0xffffffffL; 80e1051a39Sopenharmony_ci data[0] = r & 0xffffffffL; 81e1051a39Sopenharmony_ci} 82e1051a39Sopenharmony_ci 83e1051a39Sopenharmony_civoid CAST_cbc_encrypt(const unsigned char *in, unsigned char *out, 84e1051a39Sopenharmony_ci long length, const CAST_KEY *ks, unsigned char *iv, 85e1051a39Sopenharmony_ci int enc) 86e1051a39Sopenharmony_ci{ 87e1051a39Sopenharmony_ci register CAST_LONG tin0, tin1; 88e1051a39Sopenharmony_ci register CAST_LONG tout0, tout1, xor0, xor1; 89e1051a39Sopenharmony_ci register long l = length; 90e1051a39Sopenharmony_ci CAST_LONG tin[2]; 91e1051a39Sopenharmony_ci 92e1051a39Sopenharmony_ci if (enc) { 93e1051a39Sopenharmony_ci n2l(iv, tout0); 94e1051a39Sopenharmony_ci n2l(iv, tout1); 95e1051a39Sopenharmony_ci iv -= 8; 96e1051a39Sopenharmony_ci for (l -= 8; l >= 0; l -= 8) { 97e1051a39Sopenharmony_ci n2l(in, tin0); 98e1051a39Sopenharmony_ci n2l(in, tin1); 99e1051a39Sopenharmony_ci tin0 ^= tout0; 100e1051a39Sopenharmony_ci tin1 ^= tout1; 101e1051a39Sopenharmony_ci tin[0] = tin0; 102e1051a39Sopenharmony_ci tin[1] = tin1; 103e1051a39Sopenharmony_ci CAST_encrypt(tin, ks); 104e1051a39Sopenharmony_ci tout0 = tin[0]; 105e1051a39Sopenharmony_ci tout1 = tin[1]; 106e1051a39Sopenharmony_ci l2n(tout0, out); 107e1051a39Sopenharmony_ci l2n(tout1, out); 108e1051a39Sopenharmony_ci } 109e1051a39Sopenharmony_ci if (l != -8) { 110e1051a39Sopenharmony_ci n2ln(in, tin0, tin1, l + 8); 111e1051a39Sopenharmony_ci tin0 ^= tout0; 112e1051a39Sopenharmony_ci tin1 ^= tout1; 113e1051a39Sopenharmony_ci tin[0] = tin0; 114e1051a39Sopenharmony_ci tin[1] = tin1; 115e1051a39Sopenharmony_ci CAST_encrypt(tin, ks); 116e1051a39Sopenharmony_ci tout0 = tin[0]; 117e1051a39Sopenharmony_ci tout1 = tin[1]; 118e1051a39Sopenharmony_ci l2n(tout0, out); 119e1051a39Sopenharmony_ci l2n(tout1, out); 120e1051a39Sopenharmony_ci } 121e1051a39Sopenharmony_ci l2n(tout0, iv); 122e1051a39Sopenharmony_ci l2n(tout1, iv); 123e1051a39Sopenharmony_ci } else { 124e1051a39Sopenharmony_ci n2l(iv, xor0); 125e1051a39Sopenharmony_ci n2l(iv, xor1); 126e1051a39Sopenharmony_ci iv -= 8; 127e1051a39Sopenharmony_ci for (l -= 8; l >= 0; l -= 8) { 128e1051a39Sopenharmony_ci n2l(in, tin0); 129e1051a39Sopenharmony_ci n2l(in, tin1); 130e1051a39Sopenharmony_ci tin[0] = tin0; 131e1051a39Sopenharmony_ci tin[1] = tin1; 132e1051a39Sopenharmony_ci CAST_decrypt(tin, ks); 133e1051a39Sopenharmony_ci tout0 = tin[0] ^ xor0; 134e1051a39Sopenharmony_ci tout1 = tin[1] ^ xor1; 135e1051a39Sopenharmony_ci l2n(tout0, out); 136e1051a39Sopenharmony_ci l2n(tout1, out); 137e1051a39Sopenharmony_ci xor0 = tin0; 138e1051a39Sopenharmony_ci xor1 = tin1; 139e1051a39Sopenharmony_ci } 140e1051a39Sopenharmony_ci if (l != -8) { 141e1051a39Sopenharmony_ci n2l(in, tin0); 142e1051a39Sopenharmony_ci n2l(in, tin1); 143e1051a39Sopenharmony_ci tin[0] = tin0; 144e1051a39Sopenharmony_ci tin[1] = tin1; 145e1051a39Sopenharmony_ci CAST_decrypt(tin, ks); 146e1051a39Sopenharmony_ci tout0 = tin[0] ^ xor0; 147e1051a39Sopenharmony_ci tout1 = tin[1] ^ xor1; 148e1051a39Sopenharmony_ci l2nn(tout0, tout1, out, l + 8); 149e1051a39Sopenharmony_ci xor0 = tin0; 150e1051a39Sopenharmony_ci xor1 = tin1; 151e1051a39Sopenharmony_ci } 152e1051a39Sopenharmony_ci l2n(xor0, iv); 153e1051a39Sopenharmony_ci l2n(xor1, iv); 154e1051a39Sopenharmony_ci } 155e1051a39Sopenharmony_ci tin0 = tin1 = tout0 = tout1 = xor0 = xor1 = 0; 156e1051a39Sopenharmony_ci tin[0] = tin[1] = 0; 157e1051a39Sopenharmony_ci} 158