DesEngine.cs 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. using System;
  3. using Org.BouncyCastle.Crypto.Parameters;
  4. using Org.BouncyCastle.Crypto.Utilities;
  5. using Org.BouncyCastle.Utilities;
  6. namespace Org.BouncyCastle.Crypto.Engines
  7. {
  8. /// <remarks>A class that provides a basic DES engine.</remarks>
  9. public class DesEngine
  10. : IBlockCipher
  11. {
  12. internal const int BLOCK_SIZE = 8;
  13. private int[] workingKey;
  14. public virtual int[] GetWorkingKey()
  15. {
  16. return workingKey;
  17. }
  18. /**
  19. * initialise a DES cipher.
  20. *
  21. * @param forEncryption whether or not we are for encryption.
  22. * @param parameters the parameters required to set up the cipher.
  23. * @exception ArgumentException if the parameters argument is
  24. * inappropriate.
  25. */
  26. public virtual void Init(
  27. bool forEncryption,
  28. ICipherParameters parameters)
  29. {
  30. if (!(parameters is KeyParameter))
  31. throw new ArgumentException("invalid parameter passed to DES init - " + Org.BouncyCastle.Utilities.Platform.GetTypeName(parameters));
  32. workingKey = GenerateWorkingKey(forEncryption, ((KeyParameter)parameters).GetKey());
  33. }
  34. public virtual string AlgorithmName
  35. {
  36. get { return "DES"; }
  37. }
  38. public virtual bool IsPartialBlockOkay
  39. {
  40. get { return false; }
  41. }
  42. public virtual int GetBlockSize()
  43. {
  44. return BLOCK_SIZE;
  45. }
  46. public virtual int ProcessBlock(
  47. byte[] input,
  48. int inOff,
  49. byte[] output,
  50. int outOff)
  51. {
  52. if (workingKey == null)
  53. throw new InvalidOperationException("DES engine not initialised");
  54. Check.DataLength(input, inOff, BLOCK_SIZE, "input buffer too short");
  55. Check.OutputLength(output, outOff, BLOCK_SIZE, "output buffer too short");
  56. DesFunc(workingKey, input, inOff, output, outOff);
  57. return BLOCK_SIZE;
  58. }
  59. public virtual void Reset()
  60. {
  61. }
  62. /**
  63. * what follows is mainly taken from "Applied Cryptography", by
  64. * Bruce Schneier, however it also bears great resemblance to Richard
  65. * Outerbridge's D3DES...
  66. */
  67. // private static readonly short[] Df_Key =
  68. // {
  69. // 0x01,0x23,0x45,0x67,0x89,0xab,0xcd,0xef,
  70. // 0xfe,0xdc,0xba,0x98,0x76,0x54,0x32,0x10,
  71. // 0x89,0xab,0xcd,0xef,0x01,0x23,0x45,0x67
  72. // };
  73. private static readonly short[] bytebit =
  74. {
  75. 128, 64, 32, 16, 8, 4, 2, 1
  76. };
  77. private static readonly int[] bigbyte =
  78. {
  79. 0x800000, 0x400000, 0x200000, 0x100000,
  80. 0x80000, 0x40000, 0x20000, 0x10000,
  81. 0x8000, 0x4000, 0x2000, 0x1000,
  82. 0x800, 0x400, 0x200, 0x100,
  83. 0x80, 0x40, 0x20, 0x10,
  84. 0x8, 0x4, 0x2, 0x1
  85. };
  86. /*
  87. * Use the key schedule specified in the Standard (ANSI X3.92-1981).
  88. */
  89. private static readonly byte[] pc1 =
  90. {
  91. 56, 48, 40, 32, 24, 16, 8, 0, 57, 49, 41, 33, 25, 17,
  92. 9, 1, 58, 50, 42, 34, 26, 18, 10, 2, 59, 51, 43, 35,
  93. 62, 54, 46, 38, 30, 22, 14, 6, 61, 53, 45, 37, 29, 21,
  94. 13, 5, 60, 52, 44, 36, 28, 20, 12, 4, 27, 19, 11, 3
  95. };
  96. private static readonly byte[] totrot =
  97. {
  98. 1, 2, 4, 6, 8, 10, 12, 14,
  99. 15, 17, 19, 21, 23, 25, 27, 28
  100. };
  101. private static readonly byte[] pc2 =
  102. {
  103. 13, 16, 10, 23, 0, 4, 2, 27, 14, 5, 20, 9,
  104. 22, 18, 11, 3, 25, 7, 15, 6, 26, 19, 12, 1,
  105. 40, 51, 30, 36, 46, 54, 29, 39, 50, 44, 32, 47,
  106. 43, 48, 38, 55, 33, 52, 45, 41, 49, 35, 28, 31
  107. };
  108. private static readonly uint[] SP1 =
  109. {
  110. 0x01010400, 0x00000000, 0x00010000, 0x01010404,
  111. 0x01010004, 0x00010404, 0x00000004, 0x00010000,
  112. 0x00000400, 0x01010400, 0x01010404, 0x00000400,
  113. 0x01000404, 0x01010004, 0x01000000, 0x00000004,
  114. 0x00000404, 0x01000400, 0x01000400, 0x00010400,
  115. 0x00010400, 0x01010000, 0x01010000, 0x01000404,
  116. 0x00010004, 0x01000004, 0x01000004, 0x00010004,
  117. 0x00000000, 0x00000404, 0x00010404, 0x01000000,
  118. 0x00010000, 0x01010404, 0x00000004, 0x01010000,
  119. 0x01010400, 0x01000000, 0x01000000, 0x00000400,
  120. 0x01010004, 0x00010000, 0x00010400, 0x01000004,
  121. 0x00000400, 0x00000004, 0x01000404, 0x00010404,
  122. 0x01010404, 0x00010004, 0x01010000, 0x01000404,
  123. 0x01000004, 0x00000404, 0x00010404, 0x01010400,
  124. 0x00000404, 0x01000400, 0x01000400, 0x00000000,
  125. 0x00010004, 0x00010400, 0x00000000, 0x01010004
  126. };
  127. private static readonly uint[] SP2 =
  128. {
  129. 0x80108020, 0x80008000, 0x00008000, 0x00108020,
  130. 0x00100000, 0x00000020, 0x80100020, 0x80008020,
  131. 0x80000020, 0x80108020, 0x80108000, 0x80000000,
  132. 0x80008000, 0x00100000, 0x00000020, 0x80100020,
  133. 0x00108000, 0x00100020, 0x80008020, 0x00000000,
  134. 0x80000000, 0x00008000, 0x00108020, 0x80100000,
  135. 0x00100020, 0x80000020, 0x00000000, 0x00108000,
  136. 0x00008020, 0x80108000, 0x80100000, 0x00008020,
  137. 0x00000000, 0x00108020, 0x80100020, 0x00100000,
  138. 0x80008020, 0x80100000, 0x80108000, 0x00008000,
  139. 0x80100000, 0x80008000, 0x00000020, 0x80108020,
  140. 0x00108020, 0x00000020, 0x00008000, 0x80000000,
  141. 0x00008020, 0x80108000, 0x00100000, 0x80000020,
  142. 0x00100020, 0x80008020, 0x80000020, 0x00100020,
  143. 0x00108000, 0x00000000, 0x80008000, 0x00008020,
  144. 0x80000000, 0x80100020, 0x80108020, 0x00108000
  145. };
  146. private static readonly uint[] SP3 =
  147. {
  148. 0x00000208, 0x08020200, 0x00000000, 0x08020008,
  149. 0x08000200, 0x00000000, 0x00020208, 0x08000200,
  150. 0x00020008, 0x08000008, 0x08000008, 0x00020000,
  151. 0x08020208, 0x00020008, 0x08020000, 0x00000208,
  152. 0x08000000, 0x00000008, 0x08020200, 0x00000200,
  153. 0x00020200, 0x08020000, 0x08020008, 0x00020208,
  154. 0x08000208, 0x00020200, 0x00020000, 0x08000208,
  155. 0x00000008, 0x08020208, 0x00000200, 0x08000000,
  156. 0x08020200, 0x08000000, 0x00020008, 0x00000208,
  157. 0x00020000, 0x08020200, 0x08000200, 0x00000000,
  158. 0x00000200, 0x00020008, 0x08020208, 0x08000200,
  159. 0x08000008, 0x00000200, 0x00000000, 0x08020008,
  160. 0x08000208, 0x00020000, 0x08000000, 0x08020208,
  161. 0x00000008, 0x00020208, 0x00020200, 0x08000008,
  162. 0x08020000, 0x08000208, 0x00000208, 0x08020000,
  163. 0x00020208, 0x00000008, 0x08020008, 0x00020200
  164. };
  165. private static readonly uint[] SP4 =
  166. {
  167. 0x00802001, 0x00002081, 0x00002081, 0x00000080,
  168. 0x00802080, 0x00800081, 0x00800001, 0x00002001,
  169. 0x00000000, 0x00802000, 0x00802000, 0x00802081,
  170. 0x00000081, 0x00000000, 0x00800080, 0x00800001,
  171. 0x00000001, 0x00002000, 0x00800000, 0x00802001,
  172. 0x00000080, 0x00800000, 0x00002001, 0x00002080,
  173. 0x00800081, 0x00000001, 0x00002080, 0x00800080,
  174. 0x00002000, 0x00802080, 0x00802081, 0x00000081,
  175. 0x00800080, 0x00800001, 0x00802000, 0x00802081,
  176. 0x00000081, 0x00000000, 0x00000000, 0x00802000,
  177. 0x00002080, 0x00800080, 0x00800081, 0x00000001,
  178. 0x00802001, 0x00002081, 0x00002081, 0x00000080,
  179. 0x00802081, 0x00000081, 0x00000001, 0x00002000,
  180. 0x00800001, 0x00002001, 0x00802080, 0x00800081,
  181. 0x00002001, 0x00002080, 0x00800000, 0x00802001,
  182. 0x00000080, 0x00800000, 0x00002000, 0x00802080
  183. };
  184. private static readonly uint[] SP5 =
  185. {
  186. 0x00000100, 0x02080100, 0x02080000, 0x42000100,
  187. 0x00080000, 0x00000100, 0x40000000, 0x02080000,
  188. 0x40080100, 0x00080000, 0x02000100, 0x40080100,
  189. 0x42000100, 0x42080000, 0x00080100, 0x40000000,
  190. 0x02000000, 0x40080000, 0x40080000, 0x00000000,
  191. 0x40000100, 0x42080100, 0x42080100, 0x02000100,
  192. 0x42080000, 0x40000100, 0x00000000, 0x42000000,
  193. 0x02080100, 0x02000000, 0x42000000, 0x00080100,
  194. 0x00080000, 0x42000100, 0x00000100, 0x02000000,
  195. 0x40000000, 0x02080000, 0x42000100, 0x40080100,
  196. 0x02000100, 0x40000000, 0x42080000, 0x02080100,
  197. 0x40080100, 0x00000100, 0x02000000, 0x42080000,
  198. 0x42080100, 0x00080100, 0x42000000, 0x42080100,
  199. 0x02080000, 0x00000000, 0x40080000, 0x42000000,
  200. 0x00080100, 0x02000100, 0x40000100, 0x00080000,
  201. 0x00000000, 0x40080000, 0x02080100, 0x40000100
  202. };
  203. private static readonly uint[] SP6 =
  204. {
  205. 0x20000010, 0x20400000, 0x00004000, 0x20404010,
  206. 0x20400000, 0x00000010, 0x20404010, 0x00400000,
  207. 0x20004000, 0x00404010, 0x00400000, 0x20000010,
  208. 0x00400010, 0x20004000, 0x20000000, 0x00004010,
  209. 0x00000000, 0x00400010, 0x20004010, 0x00004000,
  210. 0x00404000, 0x20004010, 0x00000010, 0x20400010,
  211. 0x20400010, 0x00000000, 0x00404010, 0x20404000,
  212. 0x00004010, 0x00404000, 0x20404000, 0x20000000,
  213. 0x20004000, 0x00000010, 0x20400010, 0x00404000,
  214. 0x20404010, 0x00400000, 0x00004010, 0x20000010,
  215. 0x00400000, 0x20004000, 0x20000000, 0x00004010,
  216. 0x20000010, 0x20404010, 0x00404000, 0x20400000,
  217. 0x00404010, 0x20404000, 0x00000000, 0x20400010,
  218. 0x00000010, 0x00004000, 0x20400000, 0x00404010,
  219. 0x00004000, 0x00400010, 0x20004010, 0x00000000,
  220. 0x20404000, 0x20000000, 0x00400010, 0x20004010
  221. };
  222. private static readonly uint[] SP7 =
  223. {
  224. 0x00200000, 0x04200002, 0x04000802, 0x00000000,
  225. 0x00000800, 0x04000802, 0x00200802, 0x04200800,
  226. 0x04200802, 0x00200000, 0x00000000, 0x04000002,
  227. 0x00000002, 0x04000000, 0x04200002, 0x00000802,
  228. 0x04000800, 0x00200802, 0x00200002, 0x04000800,
  229. 0x04000002, 0x04200000, 0x04200800, 0x00200002,
  230. 0x04200000, 0x00000800, 0x00000802, 0x04200802,
  231. 0x00200800, 0x00000002, 0x04000000, 0x00200800,
  232. 0x04000000, 0x00200800, 0x00200000, 0x04000802,
  233. 0x04000802, 0x04200002, 0x04200002, 0x00000002,
  234. 0x00200002, 0x04000000, 0x04000800, 0x00200000,
  235. 0x04200800, 0x00000802, 0x00200802, 0x04200800,
  236. 0x00000802, 0x04000002, 0x04200802, 0x04200000,
  237. 0x00200800, 0x00000000, 0x00000002, 0x04200802,
  238. 0x00000000, 0x00200802, 0x04200000, 0x00000800,
  239. 0x04000002, 0x04000800, 0x00000800, 0x00200002
  240. };
  241. private static readonly uint[] SP8 =
  242. {
  243. 0x10001040, 0x00001000, 0x00040000, 0x10041040,
  244. 0x10000000, 0x10001040, 0x00000040, 0x10000000,
  245. 0x00040040, 0x10040000, 0x10041040, 0x00041000,
  246. 0x10041000, 0x00041040, 0x00001000, 0x00000040,
  247. 0x10040000, 0x10000040, 0x10001000, 0x00001040,
  248. 0x00041000, 0x00040040, 0x10040040, 0x10041000,
  249. 0x00001040, 0x00000000, 0x00000000, 0x10040040,
  250. 0x10000040, 0x10001000, 0x00041040, 0x00040000,
  251. 0x00041040, 0x00040000, 0x10041000, 0x00001000,
  252. 0x00000040, 0x10040040, 0x00001000, 0x00041040,
  253. 0x10001000, 0x00000040, 0x10000040, 0x10040000,
  254. 0x10040040, 0x10000000, 0x00040000, 0x10001040,
  255. 0x00000000, 0x10041040, 0x00040040, 0x10000040,
  256. 0x10040000, 0x10001000, 0x10001040, 0x00000000,
  257. 0x10041040, 0x00041000, 0x00041000, 0x00001040,
  258. 0x00001040, 0x00040040, 0x10000000, 0x10041000
  259. };
  260. /**
  261. * Generate an integer based working key based on our secret key
  262. * and what we processing we are planning to do.
  263. *
  264. * Acknowledgements for this routine go to James Gillogly and Phil Karn.
  265. * (whoever, and wherever they are!).
  266. */
  267. protected static int[] GenerateWorkingKey(
  268. bool encrypting,
  269. byte[] key)
  270. {
  271. int[] newKey = new int[32];
  272. bool[] pc1m = new bool[56];
  273. bool[] pcr = new bool[56];
  274. for (int j = 0; j < 56; j++ )
  275. {
  276. int l = pc1[j];
  277. pc1m[j] = ((key[(uint) l >> 3] & bytebit[l & 07]) != 0);
  278. }
  279. for (int i = 0; i < 16; i++)
  280. {
  281. int l, m, n;
  282. if (encrypting)
  283. {
  284. m = i << 1;
  285. }
  286. else
  287. {
  288. m = (15 - i) << 1;
  289. }
  290. n = m + 1;
  291. newKey[m] = newKey[n] = 0;
  292. for (int j = 0; j < 28; j++)
  293. {
  294. l = j + totrot[i];
  295. if ( l < 28 )
  296. {
  297. pcr[j] = pc1m[l];
  298. }
  299. else
  300. {
  301. pcr[j] = pc1m[l - 28];
  302. }
  303. }
  304. for (int j = 28; j < 56; j++)
  305. {
  306. l = j + totrot[i];
  307. if (l < 56 )
  308. {
  309. pcr[j] = pc1m[l];
  310. }
  311. else
  312. {
  313. pcr[j] = pc1m[l - 28];
  314. }
  315. }
  316. for (int j = 0; j < 24; j++)
  317. {
  318. if (pcr[pc2[j]])
  319. {
  320. newKey[m] |= bigbyte[j];
  321. }
  322. if (pcr[pc2[j + 24]])
  323. {
  324. newKey[n] |= bigbyte[j];
  325. }
  326. }
  327. }
  328. //
  329. // store the processed key
  330. //
  331. for (int i = 0; i != 32; i += 2)
  332. {
  333. int i1, i2;
  334. i1 = newKey[i];
  335. i2 = newKey[i + 1];
  336. newKey[i] = (int) ( (uint) ((i1 & 0x00fc0000) << 6) |
  337. (uint) ((i1 & 0x00000fc0) << 10) |
  338. ((uint) (i2 & 0x00fc0000) >> 10) |
  339. ((uint) (i2 & 0x00000fc0) >> 6));
  340. newKey[i + 1] = (int) ( (uint) ((i1 & 0x0003f000) << 12) |
  341. (uint) ((i1 & 0x0000003f) << 16) |
  342. ((uint) (i2 & 0x0003f000) >> 4) |
  343. (uint) (i2 & 0x0000003f));
  344. }
  345. return newKey;
  346. }
  347. /**
  348. * the DES engine.
  349. */
  350. internal static void DesFunc(
  351. int[] wKey,
  352. byte[] input,
  353. int inOff,
  354. byte[] outBytes,
  355. int outOff)
  356. {
  357. uint left = Pack.BE_To_UInt32(input, inOff);
  358. uint right = Pack.BE_To_UInt32(input, inOff + 4);
  359. uint work;
  360. work = ((left >> 4) ^ right) & 0x0f0f0f0f;
  361. right ^= work;
  362. left ^= (work << 4);
  363. work = ((left >> 16) ^ right) & 0x0000ffff;
  364. right ^= work;
  365. left ^= (work << 16);
  366. work = ((right >> 2) ^ left) & 0x33333333;
  367. left ^= work;
  368. right ^= (work << 2);
  369. work = ((right >> 8) ^ left) & 0x00ff00ff;
  370. left ^= work;
  371. right ^= (work << 8);
  372. right = (right << 1) | (right >> 31);
  373. work = (left ^ right) & 0xaaaaaaaa;
  374. left ^= work;
  375. right ^= work;
  376. left = (left << 1) | (left >> 31);
  377. for (int round = 0; round < 8; round++)
  378. {
  379. uint fval;
  380. work = (right << 28) | (right >> 4);
  381. work ^= (uint)wKey[round * 4 + 0];
  382. fval = SP7[work & 0x3f];
  383. fval |= SP5[(work >> 8) & 0x3f];
  384. fval |= SP3[(work >> 16) & 0x3f];
  385. fval |= SP1[(work >> 24) & 0x3f];
  386. work = right ^ (uint)wKey[round * 4 + 1];
  387. fval |= SP8[ work & 0x3f];
  388. fval |= SP6[(work >> 8) & 0x3f];
  389. fval |= SP4[(work >> 16) & 0x3f];
  390. fval |= SP2[(work >> 24) & 0x3f];
  391. left ^= fval;
  392. work = (left << 28) | (left >> 4);
  393. work ^= (uint)wKey[round * 4 + 2];
  394. fval = SP7[ work & 0x3f];
  395. fval |= SP5[(work >> 8) & 0x3f];
  396. fval |= SP3[(work >> 16) & 0x3f];
  397. fval |= SP1[(work >> 24) & 0x3f];
  398. work = left ^ (uint)wKey[round * 4 + 3];
  399. fval |= SP8[ work & 0x3f];
  400. fval |= SP6[(work >> 8) & 0x3f];
  401. fval |= SP4[(work >> 16) & 0x3f];
  402. fval |= SP2[(work >> 24) & 0x3f];
  403. right ^= fval;
  404. }
  405. right = (right << 31) | (right >> 1);
  406. work = (left ^ right) & 0xaaaaaaaa;
  407. left ^= work;
  408. right ^= work;
  409. left = (left << 31) | (left >> 1);
  410. work = ((left >> 8) ^ right) & 0x00ff00ff;
  411. right ^= work;
  412. left ^= (work << 8);
  413. work = ((left >> 2) ^ right) & 0x33333333;
  414. right ^= work;
  415. left ^= (work << 2);
  416. work = ((right >> 16) ^ left) & 0x0000ffff;
  417. left ^= work;
  418. right ^= (work << 16);
  419. work = ((right >> 4) ^ left) & 0x0f0f0f0f;
  420. left ^= work;
  421. right ^= (work << 4);
  422. Pack.UInt32_To_BE(right, outBytes, outOff);
  423. Pack.UInt32_To_BE(left, outBytes, outOff + 4);
  424. }
  425. }
  426. }
  427. #endif