155714Skris/* crypto/des/cfb_enc.c */
255714Skris/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
355714Skris * All rights reserved.
455714Skris *
555714Skris * This package is an SSL implementation written
655714Skris * by Eric Young (eay@cryptsoft.com).
755714Skris * The implementation was written so as to conform with Netscapes SSL.
8280304Sjkim *
955714Skris * This library is free for commercial and non-commercial use as long as
1055714Skris * the following conditions are aheared to.  The following conditions
1155714Skris * apply to all code found in this distribution, be it the RC4, RSA,
1255714Skris * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
1355714Skris * included with this distribution is covered by the same copyright terms
1455714Skris * except that the holder is Tim Hudson (tjh@cryptsoft.com).
15280304Sjkim *
1655714Skris * Copyright remains Eric Young's, and as such any Copyright notices in
1755714Skris * the code are not to be removed.
1855714Skris * If this package is used in a product, Eric Young should be given attribution
1955714Skris * as the author of the parts of the library used.
2055714Skris * This can be in the form of a textual message at program startup or
2155714Skris * in documentation (online or textual) provided with the package.
22280304Sjkim *
2355714Skris * Redistribution and use in source and binary forms, with or without
2455714Skris * modification, are permitted provided that the following conditions
2555714Skris * are met:
2655714Skris * 1. Redistributions of source code must retain the copyright
2755714Skris *    notice, this list of conditions and the following disclaimer.
2855714Skris * 2. Redistributions in binary form must reproduce the above copyright
2955714Skris *    notice, this list of conditions and the following disclaimer in the
3055714Skris *    documentation and/or other materials provided with the distribution.
3155714Skris * 3. All advertising materials mentioning features or use of this software
3255714Skris *    must display the following acknowledgement:
3355714Skris *    "This product includes cryptographic software written by
3455714Skris *     Eric Young (eay@cryptsoft.com)"
3555714Skris *    The word 'cryptographic' can be left out if the rouines from the library
3655714Skris *    being used are not cryptographic related :-).
37280304Sjkim * 4. If you include any Windows specific code (or a derivative thereof) from
3855714Skris *    the apps directory (application code) you must include an acknowledgement:
3955714Skris *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
40280304Sjkim *
4155714Skris * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
4255714Skris * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
4355714Skris * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
4455714Skris * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
4555714Skris * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
4655714Skris * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
4755714Skris * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
4855714Skris * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
4955714Skris * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
5055714Skris * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
5155714Skris * SUCH DAMAGE.
52280304Sjkim *
5355714Skris * The licence and distribution terms for any publically available version or
5455714Skris * derivative of this code cannot be changed.  i.e. this code cannot simply be
5555714Skris * copied and put under another distribution licence
5655714Skris * [including the GNU Public Licence.]
5755714Skris */
5855714Skris
59127128Snectar#include "e_os.h"
6055714Skris#include "des_locl.h"
61160814Ssimon#include <assert.h>
6255714Skris
63280304Sjkim/*
64280304Sjkim * The input and output are loaded in multiples of 8 bits. What this means is
65280304Sjkim * that if you hame numbits=12 and length=2 the first 12 bits will be
66280304Sjkim * retrieved from the first byte and half the second.  The second 12 bits
67280304Sjkim * will come from the 3rd and half the 4th byte.
6855714Skris */
69280304Sjkim/*
70280304Sjkim * Until Aug 1 2003 this function did not correctly implement CFB-r, so it
71280304Sjkim * will not be compatible with any encryption prior to that date. Ben.
72280304Sjkim */
73109998Smarkmvoid DES_cfb_encrypt(const unsigned char *in, unsigned char *out, int numbits,
74280304Sjkim                     long length, DES_key_schedule *schedule,
75280304Sjkim                     DES_cblock *ivec, int enc)
76280304Sjkim{
77280304Sjkim    register DES_LONG d0, d1, v0, v1;
78280304Sjkim    register unsigned long l = length;
79280304Sjkim    register int num = numbits / 8, n = (numbits + 7) / 8, i, rem =
80280304Sjkim        numbits % 8;
81280304Sjkim    DES_LONG ti[2];
82280304Sjkim    unsigned char *iv;
83160814Ssimon#ifndef L_ENDIAN
84280304Sjkim    unsigned char ovec[16];
85160814Ssimon#else
86280304Sjkim    unsigned int sh[4];
87280304Sjkim    unsigned char *ovec = (unsigned char *)sh;
8855714Skris
89280304Sjkim    /* I kind of count that compiler optimizes away this assertioni, */
90280304Sjkim    assert(sizeof(sh[0]) == 4); /* as this holds true for all, */
91280304Sjkim    /* but 16-bit platforms...      */
92280304Sjkim
93160814Ssimon#endif
94160814Ssimon
95280304Sjkim    if (numbits <= 0 || numbits > 64)
96280304Sjkim        return;
97280304Sjkim    iv = &(*ivec)[0];
98280304Sjkim    c2l(iv, v0);
99280304Sjkim    c2l(iv, v1);
100280304Sjkim    if (enc) {
101280304Sjkim        while (l >= (unsigned long)n) {
102280304Sjkim            l -= n;
103280304Sjkim            ti[0] = v0;
104280304Sjkim            ti[1] = v1;
105280304Sjkim            DES_encrypt1((DES_LONG *)ti, schedule, DES_ENCRYPT);
106280304Sjkim            c2ln(in, d0, d1, n);
107280304Sjkim            in += n;
108280304Sjkim            d0 ^= ti[0];
109280304Sjkim            d1 ^= ti[1];
110280304Sjkim            l2cn(d0, d1, out, n);
111280304Sjkim            out += n;
112280304Sjkim            /*
113280304Sjkim             * 30-08-94 - eay - changed because l>>32 and l<<32 are bad under
114280304Sjkim             * gcc :-(
115280304Sjkim             */
116280304Sjkim            if (numbits == 32) {
117280304Sjkim                v0 = v1;
118280304Sjkim                v1 = d0;
119280304Sjkim            } else if (numbits == 64) {
120280304Sjkim                v0 = d0;
121280304Sjkim                v1 = d1;
122280304Sjkim            } else {
123160814Ssimon#ifndef L_ENDIAN
124280304Sjkim                iv = &ovec[0];
125280304Sjkim                l2c(v0, iv);
126280304Sjkim                l2c(v1, iv);
127280304Sjkim                l2c(d0, iv);
128280304Sjkim                l2c(d1, iv);
129160814Ssimon#else
130280304Sjkim                sh[0] = v0, sh[1] = v1, sh[2] = d0, sh[3] = d1;
131160814Ssimon#endif
132280304Sjkim                if (rem == 0)
133280304Sjkim                    memmove(ovec, ovec + num, 8);
134280304Sjkim                else
135280304Sjkim                    for (i = 0; i < 8; ++i)
136280304Sjkim                        ovec[i] = ovec[i + num] << rem |
137280304Sjkim                            ovec[i + num + 1] >> (8 - rem);
138160814Ssimon#ifdef L_ENDIAN
139280304Sjkim                v0 = sh[0], v1 = sh[1];
140160814Ssimon#else
141280304Sjkim                iv = &ovec[0];
142280304Sjkim                c2l(iv, v0);
143280304Sjkim                c2l(iv, v1);
144160814Ssimon#endif
145280304Sjkim            }
146280304Sjkim        }
147280304Sjkim    } else {
148280304Sjkim        while (l >= (unsigned long)n) {
149280304Sjkim            l -= n;
150280304Sjkim            ti[0] = v0;
151280304Sjkim            ti[1] = v1;
152280304Sjkim            DES_encrypt1((DES_LONG *)ti, schedule, DES_ENCRYPT);
153280304Sjkim            c2ln(in, d0, d1, n);
154280304Sjkim            in += n;
155280304Sjkim            /*
156280304Sjkim             * 30-08-94 - eay - changed because l>>32 and l<<32 are bad under
157280304Sjkim             * gcc :-(
158280304Sjkim             */
159280304Sjkim            if (numbits == 32) {
160280304Sjkim                v0 = v1;
161280304Sjkim                v1 = d0;
162280304Sjkim            } else if (numbits == 64) {
163280304Sjkim                v0 = d0;
164280304Sjkim                v1 = d1;
165280304Sjkim            } else {
166160814Ssimon#ifndef L_ENDIAN
167280304Sjkim                iv = &ovec[0];
168280304Sjkim                l2c(v0, iv);
169280304Sjkim                l2c(v1, iv);
170280304Sjkim                l2c(d0, iv);
171280304Sjkim                l2c(d1, iv);
172160814Ssimon#else
173280304Sjkim                sh[0] = v0, sh[1] = v1, sh[2] = d0, sh[3] = d1;
174160814Ssimon#endif
175280304Sjkim                if (rem == 0)
176280304Sjkim                    memmove(ovec, ovec + num, 8);
177280304Sjkim                else
178280304Sjkim                    for (i = 0; i < 8; ++i)
179280304Sjkim                        ovec[i] = ovec[i + num] << rem |
180280304Sjkim                            ovec[i + num + 1] >> (8 - rem);
181160814Ssimon#ifdef L_ENDIAN
182280304Sjkim                v0 = sh[0], v1 = sh[1];
183160814Ssimon#else
184280304Sjkim                iv = &ovec[0];
185280304Sjkim                c2l(iv, v0);
186280304Sjkim                c2l(iv, v1);
187160814Ssimon#endif
188280304Sjkim            }
189280304Sjkim            d0 ^= ti[0];
190280304Sjkim            d1 ^= ti[1];
191280304Sjkim            l2cn(d0, d1, out, n);
192280304Sjkim            out += n;
193280304Sjkim        }
194280304Sjkim    }
195280304Sjkim    iv = &(*ivec)[0];
196280304Sjkim    l2c(v0, iv);
197280304Sjkim    l2c(v1, iv);
198280304Sjkim    v0 = v1 = d0 = d1 = ti[0] = ti[1] = 0;
199280304Sjkim}
200