Tables8kGcmMultiplier.cs 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. #pragma warning disable
  3. using System;
  4. using Best.HTTP.SecureProtocol.Org.BouncyCastle.Crypto.Utilities;
  5. using Best.HTTP.SecureProtocol.Org.BouncyCastle.Utilities;
  6. namespace Best.HTTP.SecureProtocol.Org.BouncyCastle.Crypto.Modes.Gcm
  7. {
  8. public sealed class Tables8kGcmMultiplier
  9. : IGcmMultiplier
  10. {
  11. private byte[] H;
  12. private GcmUtilities.FieldElement[][] T;
  13. public void Init(byte[] H)
  14. {
  15. if (T == null)
  16. {
  17. T = new GcmUtilities.FieldElement[2][];
  18. }
  19. else if (Arrays.AreEqual(this.H, H))
  20. {
  21. return;
  22. }
  23. this.H = Arrays.Clone(H);
  24. for (int i = 0; i < 2; ++i)
  25. {
  26. GcmUtilities.FieldElement[] t = T[i] = new GcmUtilities.FieldElement[256];
  27. // t[0] = 0
  28. if (i == 0)
  29. {
  30. // t[1] = H.p^7
  31. GcmUtilities.AsFieldElement(this.H, out t[1]);
  32. GcmUtilities.MultiplyP7(ref t[1]);
  33. }
  34. else
  35. {
  36. // t[1] = T[i-1][1].p^8
  37. GcmUtilities.MultiplyP8(ref T[i - 1][1], out t[1]);
  38. }
  39. for (int n = 1; n < 128; ++n)
  40. {
  41. // t[2.n] = t[n].p^-1
  42. GcmUtilities.DivideP(ref t[n], out t[n << 1]);
  43. // t[2.n + 1] = t[2.n] + t[1]
  44. GcmUtilities.Xor(ref t[n << 1], ref t[1], out t[(n << 1) + 1]);
  45. }
  46. }
  47. }
  48. uint[] z = new uint[4];
  49. public void MultiplyH(byte[] x)
  50. {
  51. GcmUtilities.FieldElement[] T0 = T[0], T1 = T[1];
  52. //GcmUtilities.FieldElement z;
  53. //GcmUtilities.Xor(ref T0[x[14]], ref T1[x[15]], out z);
  54. //for (int i = 12; i >= 0; i -= 2)
  55. //{
  56. // GcmUtilities.MultiplyP16(ref z);
  57. // GcmUtilities.Xor(ref z, ref T0[x[i]]);
  58. // GcmUtilities.Xor(ref z, ref T1[x[i + 1]]);
  59. //}
  60. //GcmUtilities.AsBytes(ref z, x);
  61. int vPos = x[15];
  62. int uPos = x[14];
  63. ulong z1 = T0[uPos].n1 ^ T1[vPos].n1;
  64. ulong z0 = T0[uPos].n0 ^ T1[vPos].n0;
  65. for (int i = 12; i >= 0; i -= 2)
  66. {
  67. vPos = x[i + 1];
  68. uPos = x[i];
  69. ulong c = z1 << 48;
  70. z1 = T0[uPos].n1 ^ T1[vPos].n1 ^ ((z1 >> 16) | (z0 << 48));
  71. z0 = T0[uPos].n0 ^ T1[vPos].n0 ^ (z0 >> 16) ^ c ^ (c >> 1) ^ (c >> 2) ^ (c >> 7);
  72. }
  73. GcmUtilities.AsBytes(z0, z1, x);
  74. }
  75. }
  76. }
  77. #pragma warning restore
  78. #endif