155714Skris/* crypto/des/cfb_enc.c */
255714Skris/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
355714Skris * All rights reserved.
455714Skris *
555714Skris * This package is an SSL implementation written
655714Skris * by Eric Young (eay@cryptsoft.com).
755714Skris * The implementation was written so as to conform with Netscapes SSL.
8296341Sdelphij *
955714Skris * This library is free for commercial and non-commercial use as long as
1055714Skris * the following conditions are aheared to.  The following conditions
1155714Skris * apply to all code found in this distribution, be it the RC4, RSA,
1255714Skris * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
1355714Skris * included with this distribution is covered by the same copyright terms
1455714Skris * except that the holder is Tim Hudson (tjh@cryptsoft.com).
15296341Sdelphij *
1655714Skris * Copyright remains Eric Young's, and as such any Copyright notices in
1755714Skris * the code are not to be removed.
1855714Skris * If this package is used in a product, Eric Young should be given attribution
1955714Skris * as the author of the parts of the library used.
2055714Skris * This can be in the form of a textual message at program startup or
2155714Skris * in documentation (online or textual) provided with the package.
22296341Sdelphij *
2355714Skris * Redistribution and use in source and binary forms, with or without
2455714Skris * modification, are permitted provided that the following conditions
2555714Skris * are met:
2655714Skris * 1. Redistributions of source code must retain the copyright
2755714Skris *    notice, this list of conditions and the following disclaimer.
2855714Skris * 2. Redistributions in binary form must reproduce the above copyright
2955714Skris *    notice, this list of conditions and the following disclaimer in the
3055714Skris *    documentation and/or other materials provided with the distribution.
3155714Skris * 3. All advertising materials mentioning features or use of this software
3255714Skris *    must display the following acknowledgement:
3355714Skris *    "This product includes cryptographic software written by
3455714Skris *     Eric Young (eay@cryptsoft.com)"
3555714Skris *    The word 'cryptographic' can be left out if the rouines from the library
3655714Skris *    being used are not cryptographic related :-).
37296341Sdelphij * 4. If you include any Windows specific code (or a derivative thereof) from
3855714Skris *    the apps directory (application code) you must include an acknowledgement:
3955714Skris *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
40296341Sdelphij *
4155714Skris * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
4255714Skris * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
4355714Skris * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
4455714Skris * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
4555714Skris * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
4655714Skris * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
4755714Skris * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
4855714Skris * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
4955714Skris * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
5055714Skris * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
5155714Skris * SUCH DAMAGE.
52296341Sdelphij *
5355714Skris * The licence and distribution terms for any publically available version or
5455714Skris * derivative of this code cannot be changed.  i.e. this code cannot simply be
5555714Skris * copied and put under another distribution licence
5655714Skris * [including the GNU Public Licence.]
5755714Skris */
5855714Skris
59127128Snectar#include "e_os.h"
6055714Skris#include "des_locl.h"
61160814Ssimon#include <assert.h>
6255714Skris
63296341Sdelphij/*
64296341Sdelphij * The input and output are loaded in multiples of 8 bits. What this means is
65296341Sdelphij * that if you hame numbits=12 and length=2 the first 12 bits will be
66296341Sdelphij * retrieved from the first byte and half the second.  The second 12 bits
67296341Sdelphij * will come from the 3rd and half the 4th byte.
6855714Skris */
69296341Sdelphij/*
70296341Sdelphij * Until Aug 1 2003 this function did not correctly implement CFB-r, so it
71296341Sdelphij * will not be compatible with any encryption prior to that date. Ben.
72296341Sdelphij */
73109998Smarkmvoid DES_cfb_encrypt(const unsigned char *in, unsigned char *out, int numbits,
74296341Sdelphij                     long length, DES_key_schedule *schedule,
75296341Sdelphij                     DES_cblock *ivec, int enc)
76296341Sdelphij{
77296341Sdelphij    register DES_LONG d0, d1, v0, v1;
78296341Sdelphij    register unsigned long l = length;
79296341Sdelphij    register int num = numbits / 8, n = (numbits + 7) / 8, i, rem =
80296341Sdelphij        numbits % 8;
81296341Sdelphij    DES_LONG ti[2];
82296341Sdelphij    unsigned char *iv;
83160814Ssimon#ifndef L_ENDIAN
84296341Sdelphij    unsigned char ovec[16];
85160814Ssimon#else
86296341Sdelphij    unsigned int sh[4];
87296341Sdelphij    unsigned char *ovec = (unsigned char *)sh;
8855714Skris
89296341Sdelphij    /* I kind of count that compiler optimizes away this assertioni, */
90296341Sdelphij    assert(sizeof(sh[0]) == 4); /* as this holds true for all, */
91296341Sdelphij    /* but 16-bit platforms...      */
92296341Sdelphij
93160814Ssimon#endif
94160814Ssimon
95296341Sdelphij    if (numbits <= 0 || numbits > 64)
96296341Sdelphij        return;
97296341Sdelphij    iv = &(*ivec)[0];
98296341Sdelphij    c2l(iv, v0);
99296341Sdelphij    c2l(iv, v1);
100296341Sdelphij    if (enc) {
101296341Sdelphij        while (l >= (unsigned long)n) {
102296341Sdelphij            l -= n;
103296341Sdelphij            ti[0] = v0;
104296341Sdelphij            ti[1] = v1;
105296341Sdelphij            DES_encrypt1((DES_LONG *)ti, schedule, DES_ENCRYPT);
106296341Sdelphij            c2ln(in, d0, d1, n);
107296341Sdelphij            in += n;
108296341Sdelphij            d0 ^= ti[0];
109296341Sdelphij            d1 ^= ti[1];
110296341Sdelphij            l2cn(d0, d1, out, n);
111296341Sdelphij            out += n;
112296341Sdelphij            /*
113296341Sdelphij             * 30-08-94 - eay - changed because l>>32 and l<<32 are bad under
114296341Sdelphij             * gcc :-(
115296341Sdelphij             */
116296341Sdelphij            if (numbits == 32) {
117296341Sdelphij                v0 = v1;
118296341Sdelphij                v1 = d0;
119296341Sdelphij            } else if (numbits == 64) {
120296341Sdelphij                v0 = d0;
121296341Sdelphij                v1 = d1;
122296341Sdelphij            } else {
123160814Ssimon#ifndef L_ENDIAN
124296341Sdelphij                iv = &ovec[0];
125296341Sdelphij                l2c(v0, iv);
126296341Sdelphij                l2c(v1, iv);
127296341Sdelphij                l2c(d0, iv);
128296341Sdelphij                l2c(d1, iv);
129160814Ssimon#else
130296341Sdelphij                sh[0] = v0, sh[1] = v1, sh[2] = d0, sh[3] = d1;
131160814Ssimon#endif
132296341Sdelphij                if (rem == 0)
133296341Sdelphij                    memmove(ovec, ovec + num, 8);
134296341Sdelphij                else
135296341Sdelphij                    for (i = 0; i < 8; ++i)
136296341Sdelphij                        ovec[i] = ovec[i + num] << rem |
137296341Sdelphij                            ovec[i + num + 1] >> (8 - rem);
138160814Ssimon#ifdef L_ENDIAN
139296341Sdelphij                v0 = sh[0], v1 = sh[1];
140160814Ssimon#else
141296341Sdelphij                iv = &ovec[0];
142296341Sdelphij                c2l(iv, v0);
143296341Sdelphij                c2l(iv, v1);
144160814Ssimon#endif
145296341Sdelphij            }
146296341Sdelphij        }
147296341Sdelphij    } else {
148296341Sdelphij        while (l >= (unsigned long)n) {
149296341Sdelphij            l -= n;
150296341Sdelphij            ti[0] = v0;
151296341Sdelphij            ti[1] = v1;
152296341Sdelphij            DES_encrypt1((DES_LONG *)ti, schedule, DES_ENCRYPT);
153296341Sdelphij            c2ln(in, d0, d1, n);
154296341Sdelphij            in += n;
155296341Sdelphij            /*
156296341Sdelphij             * 30-08-94 - eay - changed because l>>32 and l<<32 are bad under
157296341Sdelphij             * gcc :-(
158296341Sdelphij             */
159296341Sdelphij            if (numbits == 32) {
160296341Sdelphij                v0 = v1;
161296341Sdelphij                v1 = d0;
162296341Sdelphij            } else if (numbits == 64) {
163296341Sdelphij                v0 = d0;
164296341Sdelphij                v1 = d1;
165296341Sdelphij            } else {
166160814Ssimon#ifndef L_ENDIAN
167296341Sdelphij                iv = &ovec[0];
168296341Sdelphij                l2c(v0, iv);
169296341Sdelphij                l2c(v1, iv);
170296341Sdelphij                l2c(d0, iv);
171296341Sdelphij                l2c(d1, iv);
172160814Ssimon#else
173296341Sdelphij                sh[0] = v0, sh[1] = v1, sh[2] = d0, sh[3] = d1;
174160814Ssimon#endif
175296341Sdelphij                if (rem == 0)
176296341Sdelphij                    memmove(ovec, ovec + num, 8);
177296341Sdelphij                else
178296341Sdelphij                    for (i = 0; i < 8; ++i)
179296341Sdelphij                        ovec[i] = ovec[i + num] << rem |
180296341Sdelphij                            ovec[i + num + 1] >> (8 - rem);
181160814Ssimon#ifdef L_ENDIAN
182296341Sdelphij                v0 = sh[0], v1 = sh[1];
183160814Ssimon#else
184296341Sdelphij                iv = &ovec[0];
185296341Sdelphij                c2l(iv, v0);
186296341Sdelphij                c2l(iv, v1);
187160814Ssimon#endif
188296341Sdelphij            }
189296341Sdelphij            d0 ^= ti[0];
190296341Sdelphij            d1 ^= ti[1];
191296341Sdelphij            l2cn(d0, d1, out, n);
192296341Sdelphij            out += n;
193296341Sdelphij        }
194296341Sdelphij    }
195296341Sdelphij    iv = &(*ivec)[0];
196296341Sdelphij    l2c(v0, iv);
197296341Sdelphij    l2c(v1, iv);
198296341Sdelphij    v0 = v1 = d0 = d1 = ti[0] = ti[1] = 0;
199296341Sdelphij}
200