CFB DES sync-up with FIPS branch.
[openssl.git] / crypto / des / cfb64ede.c
1 /* crypto/des/cfb64ede.c */
2 /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
3  * All rights reserved.
4  *
5  * This package is an SSL implementation written
6  * by Eric Young (eay@cryptsoft.com).
7  * The implementation was written so as to conform with Netscapes SSL.
8  * 
9  * This library is free for commercial and non-commercial use as long as
10  * the following conditions are aheared to.  The following conditions
11  * apply to all code found in this distribution, be it the RC4, RSA,
12  * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
13  * included with this distribution is covered by the same copyright terms
14  * except that the holder is Tim Hudson (tjh@cryptsoft.com).
15  * 
16  * Copyright remains Eric Young's, and as such any Copyright notices in
17  * the code are not to be removed.
18  * If this package is used in a product, Eric Young should be given attribution
19  * as the author of the parts of the library used.
20  * This can be in the form of a textual message at program startup or
21  * in documentation (online or textual) provided with the package.
22  * 
23  * Redistribution and use in source and binary forms, with or without
24  * modification, are permitted provided that the following conditions
25  * are met:
26  * 1. Redistributions of source code must retain the copyright
27  *    notice, this list of conditions and the following disclaimer.
28  * 2. Redistributions in binary form must reproduce the above copyright
29  *    notice, this list of conditions and the following disclaimer in the
30  *    documentation and/or other materials provided with the distribution.
31  * 3. All advertising materials mentioning features or use of this software
32  *    must display the following acknowledgement:
33  *    "This product includes cryptographic software written by
34  *     Eric Young (eay@cryptsoft.com)"
35  *    The word 'cryptographic' can be left out if the rouines from the library
36  *    being used are not cryptographic related :-).
37  * 4. If you include any Windows specific code (or a derivative thereof) from 
38  *    the apps directory (application code) you must include an acknowledgement:
39  *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
40  * 
41  * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
42  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
43  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
44  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
45  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
46  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
47  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
48  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
49  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
50  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
51  * SUCH DAMAGE.
52  * 
53  * The licence and distribution terms for any publically available version or
54  * derivative of this code cannot be changed.  i.e. this code cannot simply be
55  * copied and put under another distribution licence
56  * [including the GNU Public Licence.]
57  */
58
59 #include "des_locl.h"
60
61 /* The input and output encrypted as though 64bit cfb mode is being
62  * used.  The extra state information to record how much of the
63  * 64bit block we have used is contained in *num;
64  */
65
66 void DES_ede3_cfb64_encrypt(const unsigned char *in, unsigned char *out,
67                             long length, DES_key_schedule *ks1,
68                             DES_key_schedule *ks2, DES_key_schedule *ks3,
69                             DES_cblock *ivec, int *num, int enc)
70         {
71         register DES_LONG v0,v1;
72         register long l=length;
73         register int n= *num;
74         DES_LONG ti[2];
75         unsigned char *iv,c,cc;
76
77         iv=&(*ivec)[0];
78         if (enc)
79                 {
80                 while (l--)
81                         {
82                         if (n == 0)
83                                 {
84                                 c2l(iv,v0);
85                                 c2l(iv,v1);
86
87                                 ti[0]=v0;
88                                 ti[1]=v1;
89                                 DES_encrypt3(ti,ks1,ks2,ks3);
90                                 v0=ti[0];
91                                 v1=ti[1];
92
93                                 iv = &(*ivec)[0];
94                                 l2c(v0,iv);
95                                 l2c(v1,iv);
96                                 iv = &(*ivec)[0];
97                                 }
98                         c= *(in++)^iv[n];
99                         *(out++)=c;
100                         iv[n]=c;
101                         n=(n+1)&0x07;
102                         }
103                 }
104         else
105                 {
106                 while (l--)
107                         {
108                         if (n == 0)
109                                 {
110                                 c2l(iv,v0);
111                                 c2l(iv,v1);
112
113                                 ti[0]=v0;
114                                 ti[1]=v1;
115                                 DES_encrypt3(ti,ks1,ks2,ks3);
116                                 v0=ti[0];
117                                 v1=ti[1];
118
119                                 iv = &(*ivec)[0];
120                                 l2c(v0,iv);
121                                 l2c(v1,iv);
122                                 iv = &(*ivec)[0];
123                                 }
124                         cc= *(in++);
125                         c=iv[n];
126                         iv[n]=cc;
127                         *(out++)=c^cc;
128                         n=(n+1)&0x07;
129                         }
130                 }
131         v0=v1=ti[0]=ti[1]=c=cc=0;
132         *num=n;
133         }
134
135 #ifdef undef /* MACRO */
136 void DES_ede2_cfb64_encrypt(unsigned char *in, unsigned char *out, long length,
137              DES_key_schedule ks1, DES_key_schedule ks2, DES_cblock (*ivec),
138              int *num, int enc)
139         {
140         DES_ede3_cfb64_encrypt(in,out,length,ks1,ks2,ks1,ivec,num,enc);
141         }
142 #endif
143
144 /* This is compatible with the single key CFB-r for DES, even thought that's
145  * not what EVP needs.
146  */
147
148 void DES_ede3_cfb_encrypt(const unsigned char *in,unsigned char *out,
149                           int numbits,long length,DES_key_schedule *ks1,
150                           DES_key_schedule *ks2,DES_key_schedule *ks3,
151                           DES_cblock *ivec,int enc)
152         {
153         register DES_LONG d0,d1,v0,v1;
154         register unsigned long l=length;
155         register int num=numbits,n=(numbits+7)/8,i;
156         DES_LONG ti[2];
157         unsigned char *iv;
158         unsigned char ovec[16];
159
160         if (num > 64) return;
161         iv = &(*ivec)[0];
162         c2l(iv,v0);
163         c2l(iv,v1);
164         if (enc)
165                 {
166                 while (l >= n)
167                         {
168                         l-=n;
169                         ti[0]=v0;
170                         ti[1]=v1;
171                         DES_encrypt3(ti,ks1,ks2,ks3);
172                         c2ln(in,d0,d1,n);
173                         in+=n;
174                         d0^=ti[0];
175                         d1^=ti[1];
176                         l2cn(d0,d1,out,n);
177                         out+=n;
178                         /* 30-08-94 - eay - changed because l>>32 and
179                          * l<<32 are bad under gcc :-( */
180                         if (num == 32)
181                                 { v0=v1; v1=d0; }
182                         else if (num == 64)
183                                 { v0=d0; v1=d1; }
184                         else
185                                 {
186                                 iv=&ovec[0];
187                                 l2c(v0,iv);
188                                 l2c(v1,iv);
189                                 l2c(d0,iv);
190                                 l2c(d1,iv);
191                                 /* shift ovec left most of the bits... */
192                                 memmove(ovec,ovec+num/8,8+(num%8 ? 1 : 0));
193                                 /* now the remaining bits */
194                                 if(num%8 != 0)
195                                         for(i=0 ; i < 8 ; ++i)
196                                                 {
197                                                 ovec[i]<<=num%8;
198                                                 ovec[i]|=ovec[i+1]>>(8-num%8);
199                                                 }
200                                 iv=&ovec[0];
201                                 c2l(iv,v0);
202                                 c2l(iv,v1);
203                                 }
204                         }
205                 }
206         else
207                 {
208                 while (l >= n)
209                         {
210                         l-=n;
211                         ti[0]=v0;
212                         ti[1]=v1;
213                         DES_encrypt3(ti,ks1,ks2,ks3);
214                         c2ln(in,d0,d1,n);
215                         in+=n;
216                         /* 30-08-94 - eay - changed because l>>32 and
217                          * l<<32 are bad under gcc :-( */
218                         if (num == 32)
219                                 { v0=v1; v1=d0; }
220                         else if (num == 64)
221                                 { v0=d0; v1=d1; }
222                         else
223                                 {
224                                 iv=&ovec[0];
225                                 l2c(v0,iv);
226                                 l2c(v1,iv);
227                                 l2c(d0,iv);
228                                 l2c(d1,iv);
229                                 /* shift ovec left most of the bits... */
230                                 memmove(ovec,ovec+num/8,8+(num%8 ? 1 : 0));
231                                 /* now the remaining bits */
232                                 if(num%8 != 0)
233                                         for(i=0 ; i < 8 ; ++i)
234                                                 {
235                                                 ovec[i]<<=num%8;
236                                                 ovec[i]|=ovec[i+1]>>(8-num%8);
237                                                 }
238                                 iv=&ovec[0];
239                                 c2l(iv,v0);
240                                 c2l(iv,v1);
241                                 }
242                         d0^=ti[0];
243                         d1^=ti[1];
244                         l2cn(d0,d1,out,n);
245                         out+=n;
246                         }
247                 }
248         iv = &(*ivec)[0];
249         l2c(v0,iv);
250         l2c(v1,iv);
251         v0=v1=d0=d1=ti[0]=ti[1]=0;
252         }
253