161828Smarkm/* crypto/idea/i_skey.c */ 261828Smarkm/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) 361828Smarkm * All rights reserved. 461828Smarkm * 561828Smarkm * This package is an SSL implementation written 661828Smarkm * by Eric Young (eay@cryptsoft.com). 761828Smarkm * The implementation was written so as to conform with Netscapes SSL. 8280304Sjkim * 961828Smarkm * This library is free for commercial and non-commercial use as long as 1061828Smarkm * the following conditions are aheared to. The following conditions 1161828Smarkm * apply to all code found in this distribution, be it the RC4, RSA, 1261828Smarkm * lhash, DES, etc., code; not just the SSL code. The SSL documentation 1361828Smarkm * included with this distribution is covered by the same copyright terms 1461828Smarkm * except that the holder is Tim Hudson (tjh@cryptsoft.com). 15280304Sjkim * 1661828Smarkm * Copyright remains Eric Young's, and as such any Copyright notices in 1761828Smarkm * the code are not to be removed. 1861828Smarkm * If this package is used in a product, Eric Young should be given attribution 1961828Smarkm * as the author of the parts of the library used. 2061828Smarkm * This can be in the form of a textual message at program startup or 2161828Smarkm * in documentation (online or textual) provided with the package. 22280304Sjkim * 2361828Smarkm * Redistribution and use in source and binary forms, with or without 2461828Smarkm * modification, are permitted provided that the following conditions 2561828Smarkm * are met: 2661828Smarkm * 1. Redistributions of source code must retain the copyright 2761828Smarkm * notice, this list of conditions and the following disclaimer. 2861828Smarkm * 2. Redistributions in binary form must reproduce the above copyright 2961828Smarkm * notice, this list of conditions and the following disclaimer in the 3061828Smarkm * documentation and/or other materials provided with the distribution. 3161828Smarkm * 3. All advertising materials mentioning features or use of this software 3261828Smarkm * must display the following acknowledgement: 3361828Smarkm * "This product includes cryptographic software written by 3461828Smarkm * Eric Young (eay@cryptsoft.com)" 3561828Smarkm * The word 'cryptographic' can be left out if the rouines from the library 3661828Smarkm * being used are not cryptographic related :-). 37280304Sjkim * 4. If you include any Windows specific code (or a derivative thereof) from 3861828Smarkm * the apps directory (application code) you must include an acknowledgement: 3961828Smarkm * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" 40280304Sjkim * 4161828Smarkm * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND 4261828Smarkm * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 4361828Smarkm * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 4461828Smarkm * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 4561828Smarkm * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 4661828Smarkm * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 4761828Smarkm * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 4861828Smarkm * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 4961828Smarkm * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 5061828Smarkm * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 5161828Smarkm * SUCH DAMAGE. 52280304Sjkim * 5361828Smarkm * The licence and distribution terms for any publically available version or 5461828Smarkm * derivative of this code cannot be changed. i.e. this code cannot simply be 5561828Smarkm * copied and put under another distribution licence 5661828Smarkm * [including the GNU Public Licence.] 5761828Smarkm */ 5861828Smarkm 59238405Sjkim#include <openssl/crypto.h> 6061828Smarkm#include <openssl/idea.h> 6161828Smarkm#include "idea_lcl.h" 6261828Smarkm 6361828Smarkmstatic IDEA_INT inverse(unsigned int xin); 64238405Sjkimvoid idea_set_encrypt_key(const unsigned char *key, IDEA_KEY_SCHEDULE *ks) 65194206Ssimon#ifdef OPENSSL_FIPS 66280304Sjkim{ 67280304Sjkim fips_cipher_abort(IDEA); 68280304Sjkim private_idea_set_encrypt_key(key, ks); 69280304Sjkim} 70280304Sjkim 71280304Sjkimvoid private_idea_set_encrypt_key(const unsigned char *key, 72280304Sjkim IDEA_KEY_SCHEDULE *ks) 73194206Ssimon#endif 74280304Sjkim{ 75280304Sjkim int i; 76280304Sjkim register IDEA_INT *kt, *kf, r0, r1, r2; 7761828Smarkm 78280304Sjkim kt = &(ks->data[0][0]); 79280304Sjkim n2s(key, kt[0]); 80280304Sjkim n2s(key, kt[1]); 81280304Sjkim n2s(key, kt[2]); 82280304Sjkim n2s(key, kt[3]); 83280304Sjkim n2s(key, kt[4]); 84280304Sjkim n2s(key, kt[5]); 85280304Sjkim n2s(key, kt[6]); 86280304Sjkim n2s(key, kt[7]); 8761828Smarkm 88280304Sjkim kf = kt; 89280304Sjkim kt += 8; 90280304Sjkim for (i = 0; i < 6; i++) { 91280304Sjkim r2 = kf[1]; 92280304Sjkim r1 = kf[2]; 93280304Sjkim *(kt++) = ((r2 << 9) | (r1 >> 7)) & 0xffff; 94280304Sjkim r0 = kf[3]; 95280304Sjkim *(kt++) = ((r1 << 9) | (r0 >> 7)) & 0xffff; 96280304Sjkim r1 = kf[4]; 97280304Sjkim *(kt++) = ((r0 << 9) | (r1 >> 7)) & 0xffff; 98280304Sjkim r0 = kf[5]; 99280304Sjkim *(kt++) = ((r1 << 9) | (r0 >> 7)) & 0xffff; 100280304Sjkim r1 = kf[6]; 101280304Sjkim *(kt++) = ((r0 << 9) | (r1 >> 7)) & 0xffff; 102280304Sjkim r0 = kf[7]; 103280304Sjkim *(kt++) = ((r1 << 9) | (r0 >> 7)) & 0xffff; 104280304Sjkim r1 = kf[0]; 105280304Sjkim if (i >= 5) 106280304Sjkim break; 107280304Sjkim *(kt++) = ((r0 << 9) | (r1 >> 7)) & 0xffff; 108280304Sjkim *(kt++) = ((r1 << 9) | (r2 >> 7)) & 0xffff; 109280304Sjkim kf += 8; 110280304Sjkim } 111280304Sjkim} 11261828Smarkm 113238405Sjkimvoid idea_set_decrypt_key(IDEA_KEY_SCHEDULE *ek, IDEA_KEY_SCHEDULE *dk) 114280304Sjkim{ 115280304Sjkim int r; 116280304Sjkim register IDEA_INT *fp, *tp, t; 11761828Smarkm 118280304Sjkim tp = &(dk->data[0][0]); 119280304Sjkim fp = &(ek->data[8][0]); 120280304Sjkim for (r = 0; r < 9; r++) { 121280304Sjkim *(tp++) = inverse(fp[0]); 122280304Sjkim *(tp++) = ((int)(0x10000L - fp[2]) & 0xffff); 123280304Sjkim *(tp++) = ((int)(0x10000L - fp[1]) & 0xffff); 124280304Sjkim *(tp++) = inverse(fp[3]); 125280304Sjkim if (r == 8) 126280304Sjkim break; 127280304Sjkim fp -= 6; 128280304Sjkim *(tp++) = fp[4]; 129280304Sjkim *(tp++) = fp[5]; 130280304Sjkim } 13161828Smarkm 132280304Sjkim tp = &(dk->data[0][0]); 133280304Sjkim t = tp[1]; 134280304Sjkim tp[1] = tp[2]; 135280304Sjkim tp[2] = t; 13661828Smarkm 137280304Sjkim t = tp[49]; 138280304Sjkim tp[49] = tp[50]; 139280304Sjkim tp[50] = t; 140280304Sjkim} 14161828Smarkm 14261828Smarkm/* taken directly from the 'paper' I'll have a look at it later */ 14361828Smarkmstatic IDEA_INT inverse(unsigned int xin) 144280304Sjkim{ 145280304Sjkim long n1, n2, q, r, b1, b2, t; 14661828Smarkm 147280304Sjkim if (xin == 0) 148280304Sjkim b2 = 0; 149280304Sjkim else { 150280304Sjkim n1 = 0x10001; 151280304Sjkim n2 = xin; 152280304Sjkim b2 = 1; 153280304Sjkim b1 = 0; 15461828Smarkm 155280304Sjkim do { 156280304Sjkim r = (n1 % n2); 157280304Sjkim q = (n1 - r) / n2; 158280304Sjkim if (r == 0) { 159280304Sjkim if (b2 < 0) 160280304Sjkim b2 = 0x10001 + b2; 161280304Sjkim } else { 162280304Sjkim n1 = n2; 163280304Sjkim n2 = r; 164280304Sjkim t = b2; 165280304Sjkim b2 = b1 - q * b2; 166280304Sjkim b1 = t; 167280304Sjkim } 168280304Sjkim } while (r != 0); 169280304Sjkim } 170280304Sjkim return ((IDEA_INT) b2); 171280304Sjkim} 172