DesEngine.cs 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. #pragma warning disable
  3. using System;
  4. using BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto.Parameters;
  5. using BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto.Utilities;
  6. using BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities;
  7. namespace BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto.Engines
  8. {
  9. /// <remarks>A class that provides a basic DES engine.</remarks>
  10. public class DesEngine
  11. : IBlockCipher
  12. {
  13. internal const int BLOCK_SIZE = 8;
  14. private int[] workingKey;
  15. public virtual int[] GetWorkingKey()
  16. {
  17. return workingKey;
  18. }
  19. /**
  20. * initialise a DES cipher.
  21. *
  22. * @param forEncryption whether or not we are for encryption.
  23. * @param parameters the parameters required to set up the cipher.
  24. * @exception ArgumentException if the parameters argument is
  25. * inappropriate.
  26. */
  27. public virtual void Init(
  28. bool forEncryption,
  29. ICipherParameters parameters)
  30. {
  31. if (!(parameters is KeyParameter))
  32. throw new ArgumentException("invalid parameter passed to DES init - " + BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.GetTypeName(parameters));
  33. workingKey = GenerateWorkingKey(forEncryption, ((KeyParameter)parameters).GetKey());
  34. }
  35. public virtual string AlgorithmName
  36. {
  37. get { return "DES"; }
  38. }
  39. public virtual bool IsPartialBlockOkay
  40. {
  41. get { return false; }
  42. }
  43. public virtual int GetBlockSize()
  44. {
  45. return BLOCK_SIZE;
  46. }
  47. public virtual int ProcessBlock(
  48. byte[] input,
  49. int inOff,
  50. byte[] output,
  51. int outOff)
  52. {
  53. if (workingKey == null)
  54. throw new InvalidOperationException("DES engine not initialised");
  55. Check.DataLength(input, inOff, BLOCK_SIZE, "input buffer too short");
  56. Check.OutputLength(output, outOff, BLOCK_SIZE, "output buffer too short");
  57. DesFunc(workingKey, input, inOff, output, outOff);
  58. return BLOCK_SIZE;
  59. }
  60. public virtual void Reset()
  61. {
  62. }
  63. /**
  64. * what follows is mainly taken from "Applied Cryptography", by
  65. * Bruce Schneier, however it also bears great resemblance to Richard
  66. * Outerbridge's D3DES...
  67. */
  68. // private static readonly short[] Df_Key =
  69. // {
  70. // 0x01,0x23,0x45,0x67,0x89,0xab,0xcd,0xef,
  71. // 0xfe,0xdc,0xba,0x98,0x76,0x54,0x32,0x10,
  72. // 0x89,0xab,0xcd,0xef,0x01,0x23,0x45,0x67
  73. // };
  74. private static readonly short[] bytebit =
  75. {
  76. 128, 64, 32, 16, 8, 4, 2, 1
  77. };
  78. private static readonly int[] bigbyte =
  79. {
  80. 0x800000, 0x400000, 0x200000, 0x100000,
  81. 0x80000, 0x40000, 0x20000, 0x10000,
  82. 0x8000, 0x4000, 0x2000, 0x1000,
  83. 0x800, 0x400, 0x200, 0x100,
  84. 0x80, 0x40, 0x20, 0x10,
  85. 0x8, 0x4, 0x2, 0x1
  86. };
  87. /*
  88. * Use the key schedule specified in the Standard (ANSI X3.92-1981).
  89. */
  90. private static readonly byte[] pc1 =
  91. {
  92. 56, 48, 40, 32, 24, 16, 8, 0, 57, 49, 41, 33, 25, 17,
  93. 9, 1, 58, 50, 42, 34, 26, 18, 10, 2, 59, 51, 43, 35,
  94. 62, 54, 46, 38, 30, 22, 14, 6, 61, 53, 45, 37, 29, 21,
  95. 13, 5, 60, 52, 44, 36, 28, 20, 12, 4, 27, 19, 11, 3
  96. };
  97. private static readonly byte[] totrot =
  98. {
  99. 1, 2, 4, 6, 8, 10, 12, 14,
  100. 15, 17, 19, 21, 23, 25, 27, 28
  101. };
  102. private static readonly byte[] pc2 =
  103. {
  104. 13, 16, 10, 23, 0, 4, 2, 27, 14, 5, 20, 9,
  105. 22, 18, 11, 3, 25, 7, 15, 6, 26, 19, 12, 1,
  106. 40, 51, 30, 36, 46, 54, 29, 39, 50, 44, 32, 47,
  107. 43, 48, 38, 55, 33, 52, 45, 41, 49, 35, 28, 31
  108. };
  109. private static readonly uint[] SP1 =
  110. {
  111. 0x01010400, 0x00000000, 0x00010000, 0x01010404,
  112. 0x01010004, 0x00010404, 0x00000004, 0x00010000,
  113. 0x00000400, 0x01010400, 0x01010404, 0x00000400,
  114. 0x01000404, 0x01010004, 0x01000000, 0x00000004,
  115. 0x00000404, 0x01000400, 0x01000400, 0x00010400,
  116. 0x00010400, 0x01010000, 0x01010000, 0x01000404,
  117. 0x00010004, 0x01000004, 0x01000004, 0x00010004,
  118. 0x00000000, 0x00000404, 0x00010404, 0x01000000,
  119. 0x00010000, 0x01010404, 0x00000004, 0x01010000,
  120. 0x01010400, 0x01000000, 0x01000000, 0x00000400,
  121. 0x01010004, 0x00010000, 0x00010400, 0x01000004,
  122. 0x00000400, 0x00000004, 0x01000404, 0x00010404,
  123. 0x01010404, 0x00010004, 0x01010000, 0x01000404,
  124. 0x01000004, 0x00000404, 0x00010404, 0x01010400,
  125. 0x00000404, 0x01000400, 0x01000400, 0x00000000,
  126. 0x00010004, 0x00010400, 0x00000000, 0x01010004
  127. };
  128. private static readonly uint[] SP2 =
  129. {
  130. 0x80108020, 0x80008000, 0x00008000, 0x00108020,
  131. 0x00100000, 0x00000020, 0x80100020, 0x80008020,
  132. 0x80000020, 0x80108020, 0x80108000, 0x80000000,
  133. 0x80008000, 0x00100000, 0x00000020, 0x80100020,
  134. 0x00108000, 0x00100020, 0x80008020, 0x00000000,
  135. 0x80000000, 0x00008000, 0x00108020, 0x80100000,
  136. 0x00100020, 0x80000020, 0x00000000, 0x00108000,
  137. 0x00008020, 0x80108000, 0x80100000, 0x00008020,
  138. 0x00000000, 0x00108020, 0x80100020, 0x00100000,
  139. 0x80008020, 0x80100000, 0x80108000, 0x00008000,
  140. 0x80100000, 0x80008000, 0x00000020, 0x80108020,
  141. 0x00108020, 0x00000020, 0x00008000, 0x80000000,
  142. 0x00008020, 0x80108000, 0x00100000, 0x80000020,
  143. 0x00100020, 0x80008020, 0x80000020, 0x00100020,
  144. 0x00108000, 0x00000000, 0x80008000, 0x00008020,
  145. 0x80000000, 0x80100020, 0x80108020, 0x00108000
  146. };
  147. private static readonly uint[] SP3 =
  148. {
  149. 0x00000208, 0x08020200, 0x00000000, 0x08020008,
  150. 0x08000200, 0x00000000, 0x00020208, 0x08000200,
  151. 0x00020008, 0x08000008, 0x08000008, 0x00020000,
  152. 0x08020208, 0x00020008, 0x08020000, 0x00000208,
  153. 0x08000000, 0x00000008, 0x08020200, 0x00000200,
  154. 0x00020200, 0x08020000, 0x08020008, 0x00020208,
  155. 0x08000208, 0x00020200, 0x00020000, 0x08000208,
  156. 0x00000008, 0x08020208, 0x00000200, 0x08000000,
  157. 0x08020200, 0x08000000, 0x00020008, 0x00000208,
  158. 0x00020000, 0x08020200, 0x08000200, 0x00000000,
  159. 0x00000200, 0x00020008, 0x08020208, 0x08000200,
  160. 0x08000008, 0x00000200, 0x00000000, 0x08020008,
  161. 0x08000208, 0x00020000, 0x08000000, 0x08020208,
  162. 0x00000008, 0x00020208, 0x00020200, 0x08000008,
  163. 0x08020000, 0x08000208, 0x00000208, 0x08020000,
  164. 0x00020208, 0x00000008, 0x08020008, 0x00020200
  165. };
  166. private static readonly uint[] SP4 =
  167. {
  168. 0x00802001, 0x00002081, 0x00002081, 0x00000080,
  169. 0x00802080, 0x00800081, 0x00800001, 0x00002001,
  170. 0x00000000, 0x00802000, 0x00802000, 0x00802081,
  171. 0x00000081, 0x00000000, 0x00800080, 0x00800001,
  172. 0x00000001, 0x00002000, 0x00800000, 0x00802001,
  173. 0x00000080, 0x00800000, 0x00002001, 0x00002080,
  174. 0x00800081, 0x00000001, 0x00002080, 0x00800080,
  175. 0x00002000, 0x00802080, 0x00802081, 0x00000081,
  176. 0x00800080, 0x00800001, 0x00802000, 0x00802081,
  177. 0x00000081, 0x00000000, 0x00000000, 0x00802000,
  178. 0x00002080, 0x00800080, 0x00800081, 0x00000001,
  179. 0x00802001, 0x00002081, 0x00002081, 0x00000080,
  180. 0x00802081, 0x00000081, 0x00000001, 0x00002000,
  181. 0x00800001, 0x00002001, 0x00802080, 0x00800081,
  182. 0x00002001, 0x00002080, 0x00800000, 0x00802001,
  183. 0x00000080, 0x00800000, 0x00002000, 0x00802080
  184. };
  185. private static readonly uint[] SP5 =
  186. {
  187. 0x00000100, 0x02080100, 0x02080000, 0x42000100,
  188. 0x00080000, 0x00000100, 0x40000000, 0x02080000,
  189. 0x40080100, 0x00080000, 0x02000100, 0x40080100,
  190. 0x42000100, 0x42080000, 0x00080100, 0x40000000,
  191. 0x02000000, 0x40080000, 0x40080000, 0x00000000,
  192. 0x40000100, 0x42080100, 0x42080100, 0x02000100,
  193. 0x42080000, 0x40000100, 0x00000000, 0x42000000,
  194. 0x02080100, 0x02000000, 0x42000000, 0x00080100,
  195. 0x00080000, 0x42000100, 0x00000100, 0x02000000,
  196. 0x40000000, 0x02080000, 0x42000100, 0x40080100,
  197. 0x02000100, 0x40000000, 0x42080000, 0x02080100,
  198. 0x40080100, 0x00000100, 0x02000000, 0x42080000,
  199. 0x42080100, 0x00080100, 0x42000000, 0x42080100,
  200. 0x02080000, 0x00000000, 0x40080000, 0x42000000,
  201. 0x00080100, 0x02000100, 0x40000100, 0x00080000,
  202. 0x00000000, 0x40080000, 0x02080100, 0x40000100
  203. };
  204. private static readonly uint[] SP6 =
  205. {
  206. 0x20000010, 0x20400000, 0x00004000, 0x20404010,
  207. 0x20400000, 0x00000010, 0x20404010, 0x00400000,
  208. 0x20004000, 0x00404010, 0x00400000, 0x20000010,
  209. 0x00400010, 0x20004000, 0x20000000, 0x00004010,
  210. 0x00000000, 0x00400010, 0x20004010, 0x00004000,
  211. 0x00404000, 0x20004010, 0x00000010, 0x20400010,
  212. 0x20400010, 0x00000000, 0x00404010, 0x20404000,
  213. 0x00004010, 0x00404000, 0x20404000, 0x20000000,
  214. 0x20004000, 0x00000010, 0x20400010, 0x00404000,
  215. 0x20404010, 0x00400000, 0x00004010, 0x20000010,
  216. 0x00400000, 0x20004000, 0x20000000, 0x00004010,
  217. 0x20000010, 0x20404010, 0x00404000, 0x20400000,
  218. 0x00404010, 0x20404000, 0x00000000, 0x20400010,
  219. 0x00000010, 0x00004000, 0x20400000, 0x00404010,
  220. 0x00004000, 0x00400010, 0x20004010, 0x00000000,
  221. 0x20404000, 0x20000000, 0x00400010, 0x20004010
  222. };
  223. private static readonly uint[] SP7 =
  224. {
  225. 0x00200000, 0x04200002, 0x04000802, 0x00000000,
  226. 0x00000800, 0x04000802, 0x00200802, 0x04200800,
  227. 0x04200802, 0x00200000, 0x00000000, 0x04000002,
  228. 0x00000002, 0x04000000, 0x04200002, 0x00000802,
  229. 0x04000800, 0x00200802, 0x00200002, 0x04000800,
  230. 0x04000002, 0x04200000, 0x04200800, 0x00200002,
  231. 0x04200000, 0x00000800, 0x00000802, 0x04200802,
  232. 0x00200800, 0x00000002, 0x04000000, 0x00200800,
  233. 0x04000000, 0x00200800, 0x00200000, 0x04000802,
  234. 0x04000802, 0x04200002, 0x04200002, 0x00000002,
  235. 0x00200002, 0x04000000, 0x04000800, 0x00200000,
  236. 0x04200800, 0x00000802, 0x00200802, 0x04200800,
  237. 0x00000802, 0x04000002, 0x04200802, 0x04200000,
  238. 0x00200800, 0x00000000, 0x00000002, 0x04200802,
  239. 0x00000000, 0x00200802, 0x04200000, 0x00000800,
  240. 0x04000002, 0x04000800, 0x00000800, 0x00200002
  241. };
  242. private static readonly uint[] SP8 =
  243. {
  244. 0x10001040, 0x00001000, 0x00040000, 0x10041040,
  245. 0x10000000, 0x10001040, 0x00000040, 0x10000000,
  246. 0x00040040, 0x10040000, 0x10041040, 0x00041000,
  247. 0x10041000, 0x00041040, 0x00001000, 0x00000040,
  248. 0x10040000, 0x10000040, 0x10001000, 0x00001040,
  249. 0x00041000, 0x00040040, 0x10040040, 0x10041000,
  250. 0x00001040, 0x00000000, 0x00000000, 0x10040040,
  251. 0x10000040, 0x10001000, 0x00041040, 0x00040000,
  252. 0x00041040, 0x00040000, 0x10041000, 0x00001000,
  253. 0x00000040, 0x10040040, 0x00001000, 0x00041040,
  254. 0x10001000, 0x00000040, 0x10000040, 0x10040000,
  255. 0x10040040, 0x10000000, 0x00040000, 0x10001040,
  256. 0x00000000, 0x10041040, 0x00040040, 0x10000040,
  257. 0x10040000, 0x10001000, 0x10001040, 0x00000000,
  258. 0x10041040, 0x00041000, 0x00041000, 0x00001040,
  259. 0x00001040, 0x00040040, 0x10000000, 0x10041000
  260. };
  261. /**
  262. * Generate an integer based working key based on our secret key
  263. * and what we processing we are planning to do.
  264. *
  265. * Acknowledgements for this routine go to James Gillogly and Phil Karn.
  266. * (whoever, and wherever they are!).
  267. */
  268. protected static int[] GenerateWorkingKey(
  269. bool encrypting,
  270. byte[] key)
  271. {
  272. int[] newKey = new int[32];
  273. bool[] pc1m = new bool[56];
  274. bool[] pcr = new bool[56];
  275. for (int j = 0; j < 56; j++ )
  276. {
  277. int l = pc1[j];
  278. pc1m[j] = ((key[(uint) l >> 3] & bytebit[l & 07]) != 0);
  279. }
  280. for (int i = 0; i < 16; i++)
  281. {
  282. int l, m, n;
  283. if (encrypting)
  284. {
  285. m = i << 1;
  286. }
  287. else
  288. {
  289. m = (15 - i) << 1;
  290. }
  291. n = m + 1;
  292. newKey[m] = newKey[n] = 0;
  293. for (int j = 0; j < 28; j++)
  294. {
  295. l = j + totrot[i];
  296. if ( l < 28 )
  297. {
  298. pcr[j] = pc1m[l];
  299. }
  300. else
  301. {
  302. pcr[j] = pc1m[l - 28];
  303. }
  304. }
  305. for (int j = 28; j < 56; j++)
  306. {
  307. l = j + totrot[i];
  308. if (l < 56 )
  309. {
  310. pcr[j] = pc1m[l];
  311. }
  312. else
  313. {
  314. pcr[j] = pc1m[l - 28];
  315. }
  316. }
  317. for (int j = 0; j < 24; j++)
  318. {
  319. if (pcr[pc2[j]])
  320. {
  321. newKey[m] |= bigbyte[j];
  322. }
  323. if (pcr[pc2[j + 24]])
  324. {
  325. newKey[n] |= bigbyte[j];
  326. }
  327. }
  328. }
  329. //
  330. // store the processed key
  331. //
  332. for (int i = 0; i != 32; i += 2)
  333. {
  334. int i1, i2;
  335. i1 = newKey[i];
  336. i2 = newKey[i + 1];
  337. newKey[i] = (int) ( (uint) ((i1 & 0x00fc0000) << 6) |
  338. (uint) ((i1 & 0x00000fc0) << 10) |
  339. ((uint) (i2 & 0x00fc0000) >> 10) |
  340. ((uint) (i2 & 0x00000fc0) >> 6));
  341. newKey[i + 1] = (int) ( (uint) ((i1 & 0x0003f000) << 12) |
  342. (uint) ((i1 & 0x0000003f) << 16) |
  343. ((uint) (i2 & 0x0003f000) >> 4) |
  344. (uint) (i2 & 0x0000003f));
  345. }
  346. return newKey;
  347. }
  348. /**
  349. * the DES engine.
  350. */
  351. internal static void DesFunc(
  352. int[] wKey,
  353. byte[] input,
  354. int inOff,
  355. byte[] outBytes,
  356. int outOff)
  357. {
  358. uint left = Pack.BE_To_UInt32(input, inOff);
  359. uint right = Pack.BE_To_UInt32(input, inOff + 4);
  360. uint work;
  361. work = ((left >> 4) ^ right) & 0x0f0f0f0f;
  362. right ^= work;
  363. left ^= (work << 4);
  364. work = ((left >> 16) ^ right) & 0x0000ffff;
  365. right ^= work;
  366. left ^= (work << 16);
  367. work = ((right >> 2) ^ left) & 0x33333333;
  368. left ^= work;
  369. right ^= (work << 2);
  370. work = ((right >> 8) ^ left) & 0x00ff00ff;
  371. left ^= work;
  372. right ^= (work << 8);
  373. right = (right << 1) | (right >> 31);
  374. work = (left ^ right) & 0xaaaaaaaa;
  375. left ^= work;
  376. right ^= work;
  377. left = (left << 1) | (left >> 31);
  378. for (int round = 0; round < 8; round++)
  379. {
  380. uint fval;
  381. work = (right << 28) | (right >> 4);
  382. work ^= (uint)wKey[round * 4 + 0];
  383. fval = SP7[work & 0x3f];
  384. fval |= SP5[(work >> 8) & 0x3f];
  385. fval |= SP3[(work >> 16) & 0x3f];
  386. fval |= SP1[(work >> 24) & 0x3f];
  387. work = right ^ (uint)wKey[round * 4 + 1];
  388. fval |= SP8[ work & 0x3f];
  389. fval |= SP6[(work >> 8) & 0x3f];
  390. fval |= SP4[(work >> 16) & 0x3f];
  391. fval |= SP2[(work >> 24) & 0x3f];
  392. left ^= fval;
  393. work = (left << 28) | (left >> 4);
  394. work ^= (uint)wKey[round * 4 + 2];
  395. fval = SP7[ work & 0x3f];
  396. fval |= SP5[(work >> 8) & 0x3f];
  397. fval |= SP3[(work >> 16) & 0x3f];
  398. fval |= SP1[(work >> 24) & 0x3f];
  399. work = left ^ (uint)wKey[round * 4 + 3];
  400. fval |= SP8[ work & 0x3f];
  401. fval |= SP6[(work >> 8) & 0x3f];
  402. fval |= SP4[(work >> 16) & 0x3f];
  403. fval |= SP2[(work >> 24) & 0x3f];
  404. right ^= fval;
  405. }
  406. right = (right << 31) | (right >> 1);
  407. work = (left ^ right) & 0xaaaaaaaa;
  408. left ^= work;
  409. right ^= work;
  410. left = (left << 31) | (left >> 1);
  411. work = ((left >> 8) ^ right) & 0x00ff00ff;
  412. right ^= work;
  413. left ^= (work << 8);
  414. work = ((left >> 2) ^ right) & 0x33333333;
  415. right ^= work;
  416. left ^= (work << 2);
  417. work = ((right >> 16) ^ left) & 0x0000ffff;
  418. left ^= work;
  419. right ^= (work << 16);
  420. work = ((right >> 4) ^ left) & 0x0f0f0f0f;
  421. left ^= work;
  422. right ^= (work << 4);
  423. Pack.UInt32_To_BE(right, outBytes, outOff);
  424. Pack.UInt32_To_BE(left, outBytes, outOff + 4);
  425. }
  426. }
  427. }
  428. #pragma warning restore
  429. #endif