You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

cbc.c 6.5 KiB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217
  1. /* ====================================================================
  2. * Copyright (c) 2008 The OpenSSL Project. All rights reserved.
  3. *
  4. * Redistribution and use in source and binary forms, with or without
  5. * modification, are permitted provided that the following conditions
  6. * are met:
  7. *
  8. * 1. Redistributions of source code must retain the above copyright
  9. * notice, this list of conditions and the following disclaimer.
  10. *
  11. * 2. Redistributions in binary form must reproduce the above copyright
  12. * notice, this list of conditions and the following disclaimer in
  13. * the documentation and/or other materials provided with the
  14. * distribution.
  15. *
  16. * 3. All advertising materials mentioning features or use of this
  17. * software must display the following acknowledgment:
  18. * "This product includes software developed by the OpenSSL Project
  19. * for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
  20. *
  21. * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
  22. * endorse or promote products derived from this software without
  23. * prior written permission. For written permission, please contact
  24. * openssl-core@openssl.org.
  25. *
  26. * 5. Products derived from this software may not be called "OpenSSL"
  27. * nor may "OpenSSL" appear in their names without prior written
  28. * permission of the OpenSSL Project.
  29. *
  30. * 6. Redistributions of any form whatsoever must retain the following
  31. * acknowledgment:
  32. * "This product includes software developed by the OpenSSL Project
  33. * for use in the OpenSSL Toolkit (http://www.openssl.org/)"
  34. *
  35. * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
  36. * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  37. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
  38. * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
  39. * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  40. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  41. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  42. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
  43. * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  44. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  45. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
  46. * OF THE POSSIBILITY OF SUCH DAMAGE.
  47. * ==================================================================== */
  48. #include <openssl/modes.h>
  49. #include <assert.h>
  50. #include <string.h>
  51. #include "internal.h"
  52. #ifndef STRICT_ALIGNMENT
  53. # define STRICT_ALIGNMENT 0
  54. #endif
  55. void CRYPTO_cbc128_encrypt(const uint8_t *in, uint8_t *out, size_t len,
  56. const void *key, uint8_t ivec[16],
  57. block128_f block) {
  58. size_t n;
  59. const uint8_t *iv = ivec;
  60. assert(key != NULL && ivec != NULL);
  61. assert(len == 0 || (in != NULL && out != NULL));
  62. if (STRICT_ALIGNMENT &&
  63. ((size_t)in | (size_t)out | (size_t)ivec) % sizeof(size_t) != 0) {
  64. while (len >= 16) {
  65. for (n = 0; n < 16; ++n) {
  66. out[n] = in[n] ^ iv[n];
  67. }
  68. (*block)(out, out, key);
  69. iv = out;
  70. len -= 16;
  71. in += 16;
  72. out += 16;
  73. }
  74. } else {
  75. while (len >= 16) {
  76. for (n = 0; n < 16; n += sizeof(size_t)) {
  77. *(size_t *)(out + n) = *(size_t *)(in + n) ^ *(size_t *)(iv + n);
  78. }
  79. (*block)(out, out, key);
  80. iv = out;
  81. len -= 16;
  82. in += 16;
  83. out += 16;
  84. }
  85. }
  86. while (len) {
  87. for (n = 0; n < 16 && n < len; ++n) {
  88. out[n] = in[n] ^ iv[n];
  89. }
  90. for (; n < 16; ++n) {
  91. out[n] = iv[n];
  92. }
  93. (*block)(out, out, key);
  94. iv = out;
  95. if (len <= 16) {
  96. break;
  97. }
  98. len -= 16;
  99. in += 16;
  100. out += 16;
  101. }
  102. memcpy(ivec, iv, 16);
  103. }
  104. void CRYPTO_cbc128_decrypt(const uint8_t *in, uint8_t *out, size_t len,
  105. const void *key, uint8_t ivec[16],
  106. block128_f block) {
  107. size_t n;
  108. union {
  109. size_t t[16 / sizeof(size_t)];
  110. uint8_t c[16];
  111. } tmp;
  112. assert(key != NULL && ivec != NULL);
  113. assert(len == 0 || (in != NULL && out != NULL));
  114. const uintptr_t inptr = (uintptr_t) in;
  115. const uintptr_t outptr = (uintptr_t) out;
  116. /* If |in| and |out| alias, |in| must be ahead. */
  117. assert(inptr >= outptr || inptr + len <= outptr);
  118. if ((inptr >= 32 && outptr <= inptr - 32) || inptr < outptr) {
  119. /* If |out| is at least two blocks behind |in| or completely disjoint, there
  120. * is no need to decrypt to a temporary block. */
  121. const uint8_t *iv = ivec;
  122. if (STRICT_ALIGNMENT &&
  123. ((size_t)in | (size_t)out | (size_t)ivec) % sizeof(size_t) != 0) {
  124. while (len >= 16) {
  125. (*block)(in, out, key);
  126. for (n = 0; n < 16; ++n) {
  127. out[n] ^= iv[n];
  128. }
  129. iv = in;
  130. len -= 16;
  131. in += 16;
  132. out += 16;
  133. }
  134. } else if (16 % sizeof(size_t) == 0) { /* always true */
  135. while (len >= 16) {
  136. size_t *out_t = (size_t *)out, *iv_t = (size_t *)iv;
  137. (*block)(in, out, key);
  138. for (n = 0; n < 16 / sizeof(size_t); n++) {
  139. out_t[n] ^= iv_t[n];
  140. }
  141. iv = in;
  142. len -= 16;
  143. in += 16;
  144. out += 16;
  145. }
  146. }
  147. memcpy(ivec, iv, 16);
  148. } else {
  149. /* |out| is less than two blocks behind |in|. Decrypting an input block
  150. * directly to |out| would overwrite a ciphertext block before it is used as
  151. * the next block's IV. Decrypt to a temporary block instead. */
  152. if (STRICT_ALIGNMENT &&
  153. ((size_t)in | (size_t)out | (size_t)ivec) % sizeof(size_t) != 0) {
  154. uint8_t c;
  155. while (len >= 16) {
  156. (*block)(in, tmp.c, key);
  157. for (n = 0; n < 16; ++n) {
  158. c = in[n];
  159. out[n] = tmp.c[n] ^ ivec[n];
  160. ivec[n] = c;
  161. }
  162. len -= 16;
  163. in += 16;
  164. out += 16;
  165. }
  166. } else if (16 % sizeof(size_t) == 0) { /* always true */
  167. while (len >= 16) {
  168. size_t c, *out_t = (size_t *)out, *ivec_t = (size_t *)ivec;
  169. const size_t *in_t = (const size_t *)in;
  170. (*block)(in, tmp.c, key);
  171. for (n = 0; n < 16 / sizeof(size_t); n++) {
  172. c = in_t[n];
  173. out_t[n] = tmp.t[n] ^ ivec_t[n];
  174. ivec_t[n] = c;
  175. }
  176. len -= 16;
  177. in += 16;
  178. out += 16;
  179. }
  180. }
  181. }
  182. while (len) {
  183. uint8_t c;
  184. (*block)(in, tmp.c, key);
  185. for (n = 0; n < 16 && n < len; ++n) {
  186. c = in[n];
  187. out[n] = tmp.c[n] ^ ivec[n];
  188. ivec[n] = c;
  189. }
  190. if (len <= 16) {
  191. for (; n < 16; ++n) {
  192. ivec[n] = in[n];
  193. }
  194. break;
  195. }
  196. len -= 16;
  197. in += 16;
  198. out += 16;
  199. }
  200. }