1e71b7053SJung-uk Kim /*
2b6c1fdcdSJung-uk Kim * Copyright 2008-2021 The OpenSSL Project Authors. All Rights Reserved.
31f13597dSJung-uk Kim *
4*b077aed3SPierre Pronchery * Licensed under the Apache License 2.0 (the "License"). You may not use
5e71b7053SJung-uk Kim * this file except in compliance with the License. You can obtain a copy
6e71b7053SJung-uk Kim * in the file LICENSE in the source distribution or at
7e71b7053SJung-uk Kim * https://www.openssl.org/source/license.html
81f13597dSJung-uk Kim */
91f13597dSJung-uk Kim
101f13597dSJung-uk Kim #include <string.h>
11*b077aed3SPierre Pronchery #include <openssl/crypto.h>
12*b077aed3SPierre Pronchery #include "crypto/modes.h"
131f13597dSJung-uk Kim
147bded2dbSJung-uk Kim #if !defined(STRICT_ALIGNMENT) && !defined(PEDANTIC)
151f13597dSJung-uk Kim # define STRICT_ALIGNMENT 0
161f13597dSJung-uk Kim #endif
171f13597dSJung-uk Kim
1858f35182SJung-uk Kim #if defined(__GNUC__) && !STRICT_ALIGNMENT
1958f35182SJung-uk Kim typedef size_t size_t_aX __attribute((__aligned__(1)));
2058f35182SJung-uk Kim #else
2158f35182SJung-uk Kim typedef size_t size_t_aX;
2258f35182SJung-uk Kim #endif
2358f35182SJung-uk Kim
CRYPTO_cbc128_encrypt(const unsigned char * in,unsigned char * out,size_t len,const void * key,unsigned char ivec[16],block128_f block)241f13597dSJung-uk Kim void CRYPTO_cbc128_encrypt(const unsigned char *in, unsigned char *out,
251f13597dSJung-uk Kim size_t len, const void *key,
261f13597dSJung-uk Kim unsigned char ivec[16], block128_f block)
271f13597dSJung-uk Kim {
281f13597dSJung-uk Kim size_t n;
291f13597dSJung-uk Kim const unsigned char *iv = ivec;
301f13597dSJung-uk Kim
31e71b7053SJung-uk Kim if (len == 0)
32e71b7053SJung-uk Kim return;
331f13597dSJung-uk Kim
341f13597dSJung-uk Kim #if !defined(OPENSSL_SMALL_FOOTPRINT)
351f13597dSJung-uk Kim if (STRICT_ALIGNMENT &&
361f13597dSJung-uk Kim ((size_t)in | (size_t)out | (size_t)ivec) % sizeof(size_t) != 0) {
371f13597dSJung-uk Kim while (len >= 16) {
381f13597dSJung-uk Kim for (n = 0; n < 16; ++n)
391f13597dSJung-uk Kim out[n] = in[n] ^ iv[n];
401f13597dSJung-uk Kim (*block) (out, out, key);
411f13597dSJung-uk Kim iv = out;
421f13597dSJung-uk Kim len -= 16;
431f13597dSJung-uk Kim in += 16;
441f13597dSJung-uk Kim out += 16;
451f13597dSJung-uk Kim }
461f13597dSJung-uk Kim } else {
471f13597dSJung-uk Kim while (len >= 16) {
481f13597dSJung-uk Kim for (n = 0; n < 16; n += sizeof(size_t))
4958f35182SJung-uk Kim *(size_t_aX *)(out + n) =
5058f35182SJung-uk Kim *(size_t_aX *)(in + n) ^ *(size_t_aX *)(iv + n);
511f13597dSJung-uk Kim (*block) (out, out, key);
521f13597dSJung-uk Kim iv = out;
531f13597dSJung-uk Kim len -= 16;
541f13597dSJung-uk Kim in += 16;
551f13597dSJung-uk Kim out += 16;
561f13597dSJung-uk Kim }
571f13597dSJung-uk Kim }
581f13597dSJung-uk Kim #endif
591f13597dSJung-uk Kim while (len) {
601f13597dSJung-uk Kim for (n = 0; n < 16 && n < len; ++n)
611f13597dSJung-uk Kim out[n] = in[n] ^ iv[n];
621f13597dSJung-uk Kim for (; n < 16; ++n)
631f13597dSJung-uk Kim out[n] = iv[n];
641f13597dSJung-uk Kim (*block) (out, out, key);
651f13597dSJung-uk Kim iv = out;
666f9291ceSJung-uk Kim if (len <= 16)
676f9291ceSJung-uk Kim break;
681f13597dSJung-uk Kim len -= 16;
691f13597dSJung-uk Kim in += 16;
701f13597dSJung-uk Kim out += 16;
711f13597dSJung-uk Kim }
72b6c1fdcdSJung-uk Kim if (ivec != iv)
731f13597dSJung-uk Kim memcpy(ivec, iv, 16);
741f13597dSJung-uk Kim }
751f13597dSJung-uk Kim
CRYPTO_cbc128_decrypt(const unsigned char * in,unsigned char * out,size_t len,const void * key,unsigned char ivec[16],block128_f block)761f13597dSJung-uk Kim void CRYPTO_cbc128_decrypt(const unsigned char *in, unsigned char *out,
771f13597dSJung-uk Kim size_t len, const void *key,
781f13597dSJung-uk Kim unsigned char ivec[16], block128_f block)
791f13597dSJung-uk Kim {
801f13597dSJung-uk Kim size_t n;
816f9291ceSJung-uk Kim union {
826f9291ceSJung-uk Kim size_t t[16 / sizeof(size_t)];
836f9291ceSJung-uk Kim unsigned char c[16];
846f9291ceSJung-uk Kim } tmp;
851f13597dSJung-uk Kim
86e71b7053SJung-uk Kim if (len == 0)
87e71b7053SJung-uk Kim return;
881f13597dSJung-uk Kim
891f13597dSJung-uk Kim #if !defined(OPENSSL_SMALL_FOOTPRINT)
901f13597dSJung-uk Kim if (in != out) {
911f13597dSJung-uk Kim const unsigned char *iv = ivec;
921f13597dSJung-uk Kim
931f13597dSJung-uk Kim if (STRICT_ALIGNMENT &&
941f13597dSJung-uk Kim ((size_t)in | (size_t)out | (size_t)ivec) % sizeof(size_t) != 0) {
951f13597dSJung-uk Kim while (len >= 16) {
961f13597dSJung-uk Kim (*block) (in, out, key);
971f13597dSJung-uk Kim for (n = 0; n < 16; ++n)
981f13597dSJung-uk Kim out[n] ^= iv[n];
991f13597dSJung-uk Kim iv = in;
1001f13597dSJung-uk Kim len -= 16;
1011f13597dSJung-uk Kim in += 16;
1021f13597dSJung-uk Kim out += 16;
1031f13597dSJung-uk Kim }
1046f9291ceSJung-uk Kim } else if (16 % sizeof(size_t) == 0) { /* always true */
1051f13597dSJung-uk Kim while (len >= 16) {
10658f35182SJung-uk Kim size_t_aX *out_t = (size_t_aX *)out;
10758f35182SJung-uk Kim size_t_aX *iv_t = (size_t_aX *)iv;
108de78d5d8SJung-uk Kim
1091f13597dSJung-uk Kim (*block) (in, out, key);
110de78d5d8SJung-uk Kim for (n = 0; n < 16 / sizeof(size_t); n++)
111de78d5d8SJung-uk Kim out_t[n] ^= iv_t[n];
1121f13597dSJung-uk Kim iv = in;
1131f13597dSJung-uk Kim len -= 16;
1141f13597dSJung-uk Kim in += 16;
1151f13597dSJung-uk Kim out += 16;
1161f13597dSJung-uk Kim }
1171f13597dSJung-uk Kim }
118b6c1fdcdSJung-uk Kim if (ivec != iv)
1191f13597dSJung-uk Kim memcpy(ivec, iv, 16);
1201f13597dSJung-uk Kim } else {
1211f13597dSJung-uk Kim if (STRICT_ALIGNMENT &&
1221f13597dSJung-uk Kim ((size_t)in | (size_t)out | (size_t)ivec) % sizeof(size_t) != 0) {
1231f13597dSJung-uk Kim unsigned char c;
1241f13597dSJung-uk Kim while (len >= 16) {
1251f13597dSJung-uk Kim (*block) (in, tmp.c, key);
1261f13597dSJung-uk Kim for (n = 0; n < 16; ++n) {
1271f13597dSJung-uk Kim c = in[n];
1281f13597dSJung-uk Kim out[n] = tmp.c[n] ^ ivec[n];
1291f13597dSJung-uk Kim ivec[n] = c;
1301f13597dSJung-uk Kim }
1311f13597dSJung-uk Kim len -= 16;
1321f13597dSJung-uk Kim in += 16;
1331f13597dSJung-uk Kim out += 16;
1341f13597dSJung-uk Kim }
1356f9291ceSJung-uk Kim } else if (16 % sizeof(size_t) == 0) { /* always true */
1361f13597dSJung-uk Kim while (len >= 16) {
13758f35182SJung-uk Kim size_t c;
13858f35182SJung-uk Kim size_t_aX *out_t = (size_t_aX *)out;
13958f35182SJung-uk Kim size_t_aX *ivec_t = (size_t_aX *)ivec;
14058f35182SJung-uk Kim const size_t_aX *in_t = (const size_t_aX *)in;
141de78d5d8SJung-uk Kim
1421f13597dSJung-uk Kim (*block) (in, tmp.c, key);
143de78d5d8SJung-uk Kim for (n = 0; n < 16 / sizeof(size_t); n++) {
144de78d5d8SJung-uk Kim c = in_t[n];
145de78d5d8SJung-uk Kim out_t[n] = tmp.t[n] ^ ivec_t[n];
146de78d5d8SJung-uk Kim ivec_t[n] = c;
1471f13597dSJung-uk Kim }
1481f13597dSJung-uk Kim len -= 16;
1491f13597dSJung-uk Kim in += 16;
1501f13597dSJung-uk Kim out += 16;
1511f13597dSJung-uk Kim }
1521f13597dSJung-uk Kim }
1531f13597dSJung-uk Kim }
1541f13597dSJung-uk Kim #endif
1551f13597dSJung-uk Kim while (len) {
1561f13597dSJung-uk Kim unsigned char c;
1571f13597dSJung-uk Kim (*block) (in, tmp.c, key);
1581f13597dSJung-uk Kim for (n = 0; n < 16 && n < len; ++n) {
1591f13597dSJung-uk Kim c = in[n];
1601f13597dSJung-uk Kim out[n] = tmp.c[n] ^ ivec[n];
1611f13597dSJung-uk Kim ivec[n] = c;
1621f13597dSJung-uk Kim }
1631f13597dSJung-uk Kim if (len <= 16) {
1641f13597dSJung-uk Kim for (; n < 16; ++n)
1651f13597dSJung-uk Kim ivec[n] = in[n];
1661f13597dSJung-uk Kim break;
1671f13597dSJung-uk Kim }
1681f13597dSJung-uk Kim len -= 16;
1691f13597dSJung-uk Kim in += 16;
1701f13597dSJung-uk Kim out += 16;
1711f13597dSJung-uk Kim }
1721f13597dSJung-uk Kim }
173