DesCipher.cs 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Linq;
  4. using System.Text;
  5. namespace Renci.SshNet.Security.Cryptography.Ciphers
  6. {
  7. /// <summary>
  8. /// Implements DES cipher algorithm.
  9. /// </summary>
  10. public class DesCipher : BlockCipher
  11. {
  12. private int[] _encryptionKey;
  13. private int[] _decryptionKey;
  14. #region Static tables
  15. private static readonly short[] bytebit =
  16. {
  17. 128, 64, 32, 16, 8, 4, 2, 1
  18. };
  19. private static readonly int[] bigbyte =
  20. {
  21. 0x800000, 0x400000, 0x200000, 0x100000,
  22. 0x80000, 0x40000, 0x20000, 0x10000,
  23. 0x8000, 0x4000, 0x2000, 0x1000,
  24. 0x800, 0x400, 0x200, 0x100,
  25. 0x80, 0x40, 0x20, 0x10,
  26. 0x8, 0x4, 0x2, 0x1
  27. };
  28. /*
  29. * Use the key schedule specified in the Standard (ANSI X3.92-1981).
  30. */
  31. private static readonly byte[] pc1 =
  32. {
  33. 56, 48, 40, 32, 24, 16, 8, 0, 57, 49, 41, 33, 25, 17,
  34. 9, 1, 58, 50, 42, 34, 26, 18, 10, 2, 59, 51, 43, 35,
  35. 62, 54, 46, 38, 30, 22, 14, 6, 61, 53, 45, 37, 29, 21,
  36. 13, 5, 60, 52, 44, 36, 28, 20, 12, 4, 27, 19, 11, 3
  37. };
  38. private static readonly byte[] totrot =
  39. {
  40. 1, 2, 4, 6, 8, 10, 12, 14,
  41. 15, 17, 19, 21, 23, 25, 27, 28
  42. };
  43. private static readonly byte[] pc2 =
  44. {
  45. 13, 16, 10, 23, 0, 4, 2, 27, 14, 5, 20, 9,
  46. 22, 18, 11, 3, 25, 7, 15, 6, 26, 19, 12, 1,
  47. 40, 51, 30, 36, 46, 54, 29, 39, 50, 44, 32, 47,
  48. 43, 48, 38, 55, 33, 52, 45, 41, 49, 35, 28, 31
  49. };
  50. private static readonly uint[] SP1 =
  51. {
  52. 0x01010400, 0x00000000, 0x00010000, 0x01010404,
  53. 0x01010004, 0x00010404, 0x00000004, 0x00010000,
  54. 0x00000400, 0x01010400, 0x01010404, 0x00000400,
  55. 0x01000404, 0x01010004, 0x01000000, 0x00000004,
  56. 0x00000404, 0x01000400, 0x01000400, 0x00010400,
  57. 0x00010400, 0x01010000, 0x01010000, 0x01000404,
  58. 0x00010004, 0x01000004, 0x01000004, 0x00010004,
  59. 0x00000000, 0x00000404, 0x00010404, 0x01000000,
  60. 0x00010000, 0x01010404, 0x00000004, 0x01010000,
  61. 0x01010400, 0x01000000, 0x01000000, 0x00000400,
  62. 0x01010004, 0x00010000, 0x00010400, 0x01000004,
  63. 0x00000400, 0x00000004, 0x01000404, 0x00010404,
  64. 0x01010404, 0x00010004, 0x01010000, 0x01000404,
  65. 0x01000004, 0x00000404, 0x00010404, 0x01010400,
  66. 0x00000404, 0x01000400, 0x01000400, 0x00000000,
  67. 0x00010004, 0x00010400, 0x00000000, 0x01010004
  68. };
  69. private static readonly uint[] SP2 =
  70. {
  71. 0x80108020, 0x80008000, 0x00008000, 0x00108020,
  72. 0x00100000, 0x00000020, 0x80100020, 0x80008020,
  73. 0x80000020, 0x80108020, 0x80108000, 0x80000000,
  74. 0x80008000, 0x00100000, 0x00000020, 0x80100020,
  75. 0x00108000, 0x00100020, 0x80008020, 0x00000000,
  76. 0x80000000, 0x00008000, 0x00108020, 0x80100000,
  77. 0x00100020, 0x80000020, 0x00000000, 0x00108000,
  78. 0x00008020, 0x80108000, 0x80100000, 0x00008020,
  79. 0x00000000, 0x00108020, 0x80100020, 0x00100000,
  80. 0x80008020, 0x80100000, 0x80108000, 0x00008000,
  81. 0x80100000, 0x80008000, 0x00000020, 0x80108020,
  82. 0x00108020, 0x00000020, 0x00008000, 0x80000000,
  83. 0x00008020, 0x80108000, 0x00100000, 0x80000020,
  84. 0x00100020, 0x80008020, 0x80000020, 0x00100020,
  85. 0x00108000, 0x00000000, 0x80008000, 0x00008020,
  86. 0x80000000, 0x80100020, 0x80108020, 0x00108000
  87. };
  88. private static readonly uint[] SP3 =
  89. {
  90. 0x00000208, 0x08020200, 0x00000000, 0x08020008,
  91. 0x08000200, 0x00000000, 0x00020208, 0x08000200,
  92. 0x00020008, 0x08000008, 0x08000008, 0x00020000,
  93. 0x08020208, 0x00020008, 0x08020000, 0x00000208,
  94. 0x08000000, 0x00000008, 0x08020200, 0x00000200,
  95. 0x00020200, 0x08020000, 0x08020008, 0x00020208,
  96. 0x08000208, 0x00020200, 0x00020000, 0x08000208,
  97. 0x00000008, 0x08020208, 0x00000200, 0x08000000,
  98. 0x08020200, 0x08000000, 0x00020008, 0x00000208,
  99. 0x00020000, 0x08020200, 0x08000200, 0x00000000,
  100. 0x00000200, 0x00020008, 0x08020208, 0x08000200,
  101. 0x08000008, 0x00000200, 0x00000000, 0x08020008,
  102. 0x08000208, 0x00020000, 0x08000000, 0x08020208,
  103. 0x00000008, 0x00020208, 0x00020200, 0x08000008,
  104. 0x08020000, 0x08000208, 0x00000208, 0x08020000,
  105. 0x00020208, 0x00000008, 0x08020008, 0x00020200
  106. };
  107. private static readonly uint[] SP4 =
  108. {
  109. 0x00802001, 0x00002081, 0x00002081, 0x00000080,
  110. 0x00802080, 0x00800081, 0x00800001, 0x00002001,
  111. 0x00000000, 0x00802000, 0x00802000, 0x00802081,
  112. 0x00000081, 0x00000000, 0x00800080, 0x00800001,
  113. 0x00000001, 0x00002000, 0x00800000, 0x00802001,
  114. 0x00000080, 0x00800000, 0x00002001, 0x00002080,
  115. 0x00800081, 0x00000001, 0x00002080, 0x00800080,
  116. 0x00002000, 0x00802080, 0x00802081, 0x00000081,
  117. 0x00800080, 0x00800001, 0x00802000, 0x00802081,
  118. 0x00000081, 0x00000000, 0x00000000, 0x00802000,
  119. 0x00002080, 0x00800080, 0x00800081, 0x00000001,
  120. 0x00802001, 0x00002081, 0x00002081, 0x00000080,
  121. 0x00802081, 0x00000081, 0x00000001, 0x00002000,
  122. 0x00800001, 0x00002001, 0x00802080, 0x00800081,
  123. 0x00002001, 0x00002080, 0x00800000, 0x00802001,
  124. 0x00000080, 0x00800000, 0x00002000, 0x00802080
  125. };
  126. private static readonly uint[] SP5 =
  127. {
  128. 0x00000100, 0x02080100, 0x02080000, 0x42000100,
  129. 0x00080000, 0x00000100, 0x40000000, 0x02080000,
  130. 0x40080100, 0x00080000, 0x02000100, 0x40080100,
  131. 0x42000100, 0x42080000, 0x00080100, 0x40000000,
  132. 0x02000000, 0x40080000, 0x40080000, 0x00000000,
  133. 0x40000100, 0x42080100, 0x42080100, 0x02000100,
  134. 0x42080000, 0x40000100, 0x00000000, 0x42000000,
  135. 0x02080100, 0x02000000, 0x42000000, 0x00080100,
  136. 0x00080000, 0x42000100, 0x00000100, 0x02000000,
  137. 0x40000000, 0x02080000, 0x42000100, 0x40080100,
  138. 0x02000100, 0x40000000, 0x42080000, 0x02080100,
  139. 0x40080100, 0x00000100, 0x02000000, 0x42080000,
  140. 0x42080100, 0x00080100, 0x42000000, 0x42080100,
  141. 0x02080000, 0x00000000, 0x40080000, 0x42000000,
  142. 0x00080100, 0x02000100, 0x40000100, 0x00080000,
  143. 0x00000000, 0x40080000, 0x02080100, 0x40000100
  144. };
  145. private static readonly uint[] SP6 =
  146. {
  147. 0x20000010, 0x20400000, 0x00004000, 0x20404010,
  148. 0x20400000, 0x00000010, 0x20404010, 0x00400000,
  149. 0x20004000, 0x00404010, 0x00400000, 0x20000010,
  150. 0x00400010, 0x20004000, 0x20000000, 0x00004010,
  151. 0x00000000, 0x00400010, 0x20004010, 0x00004000,
  152. 0x00404000, 0x20004010, 0x00000010, 0x20400010,
  153. 0x20400010, 0x00000000, 0x00404010, 0x20404000,
  154. 0x00004010, 0x00404000, 0x20404000, 0x20000000,
  155. 0x20004000, 0x00000010, 0x20400010, 0x00404000,
  156. 0x20404010, 0x00400000, 0x00004010, 0x20000010,
  157. 0x00400000, 0x20004000, 0x20000000, 0x00004010,
  158. 0x20000010, 0x20404010, 0x00404000, 0x20400000,
  159. 0x00404010, 0x20404000, 0x00000000, 0x20400010,
  160. 0x00000010, 0x00004000, 0x20400000, 0x00404010,
  161. 0x00004000, 0x00400010, 0x20004010, 0x00000000,
  162. 0x20404000, 0x20000000, 0x00400010, 0x20004010
  163. };
  164. private static readonly uint[] SP7 =
  165. {
  166. 0x00200000, 0x04200002, 0x04000802, 0x00000000,
  167. 0x00000800, 0x04000802, 0x00200802, 0x04200800,
  168. 0x04200802, 0x00200000, 0x00000000, 0x04000002,
  169. 0x00000002, 0x04000000, 0x04200002, 0x00000802,
  170. 0x04000800, 0x00200802, 0x00200002, 0x04000800,
  171. 0x04000002, 0x04200000, 0x04200800, 0x00200002,
  172. 0x04200000, 0x00000800, 0x00000802, 0x04200802,
  173. 0x00200800, 0x00000002, 0x04000000, 0x00200800,
  174. 0x04000000, 0x00200800, 0x00200000, 0x04000802,
  175. 0x04000802, 0x04200002, 0x04200002, 0x00000002,
  176. 0x00200002, 0x04000000, 0x04000800, 0x00200000,
  177. 0x04200800, 0x00000802, 0x00200802, 0x04200800,
  178. 0x00000802, 0x04000002, 0x04200802, 0x04200000,
  179. 0x00200800, 0x00000000, 0x00000002, 0x04200802,
  180. 0x00000000, 0x00200802, 0x04200000, 0x00000800,
  181. 0x04000002, 0x04000800, 0x00000800, 0x00200002
  182. };
  183. private static readonly uint[] SP8 =
  184. {
  185. 0x10001040, 0x00001000, 0x00040000, 0x10041040,
  186. 0x10000000, 0x10001040, 0x00000040, 0x10000000,
  187. 0x00040040, 0x10040000, 0x10041040, 0x00041000,
  188. 0x10041000, 0x00041040, 0x00001000, 0x00000040,
  189. 0x10040000, 0x10000040, 0x10001000, 0x00001040,
  190. 0x00041000, 0x00040040, 0x10040040, 0x10041000,
  191. 0x00001040, 0x00000000, 0x00000000, 0x10040040,
  192. 0x10000040, 0x10001000, 0x00041040, 0x00040000,
  193. 0x00041040, 0x00040000, 0x10041000, 0x00001000,
  194. 0x00000040, 0x10040040, 0x00001000, 0x00041040,
  195. 0x10001000, 0x00000040, 0x10000040, 0x10040000,
  196. 0x10040040, 0x10000000, 0x00040000, 0x10001040,
  197. 0x00000000, 0x10041040, 0x00040040, 0x10000040,
  198. 0x10040000, 0x10001000, 0x10001040, 0x00000000,
  199. 0x10041040, 0x00041000, 0x00041000, 0x00001040,
  200. 0x00001040, 0x00040040, 0x10000000, 0x10041000
  201. };
  202. #endregion
  203. /// <summary>
  204. /// Initializes a new instance of the <see cref="DesCipher"/> class.
  205. /// </summary>
  206. /// <param name="key">The key.</param>
  207. /// <param name="mode">The mode.</param>
  208. /// <param name="padding">The padding.</param>
  209. /// <exception cref="ArgumentNullException"><paramref name="key"/> is null.</exception>
  210. public DesCipher(byte[] key, CipherMode mode, CipherPadding padding)
  211. : base(key, 8, mode, padding)
  212. {
  213. }
  214. /// <summary>
  215. /// Encrypts the specified region of the input byte array and copies the encrypted data to the specified region of the output byte array.
  216. /// </summary>
  217. /// <param name="inputBuffer">The input data to encrypt.</param>
  218. /// <param name="inputOffset">The offset into the input byte array from which to begin using data.</param>
  219. /// <param name="inputCount">The number of bytes in the input byte array to use as data.</param>
  220. /// <param name="outputBuffer">The output to which to write encrypted data.</param>
  221. /// <param name="outputOffset">The offset into the output byte array from which to begin writing data.</param>
  222. /// <returns>
  223. /// The number of bytes encrypted.
  224. /// </returns>
  225. public override int EncryptBlock(byte[] inputBuffer, int inputOffset, int inputCount, byte[] outputBuffer, int outputOffset)
  226. {
  227. if ((inputOffset + this.BlockSize) > inputBuffer.Length)
  228. throw new IndexOutOfRangeException("input buffer too short");
  229. if ((outputOffset + this.BlockSize) > outputBuffer.Length)
  230. throw new IndexOutOfRangeException("output buffer too short");
  231. if (this._encryptionKey == null)
  232. {
  233. this._encryptionKey = GenerateWorkingKey(true, this.Key);
  234. }
  235. DesCipher.DesFunc(this._encryptionKey, inputBuffer, inputOffset, outputBuffer, outputOffset);
  236. return this.BlockSize;
  237. }
  238. /// <summary>
  239. /// Decrypts the specified region of the input byte array and copies the decrypted data to the specified region of the output byte array.
  240. /// </summary>
  241. /// <param name="inputBuffer">The input data to decrypt.</param>
  242. /// <param name="inputOffset">The offset into the input byte array from which to begin using data.</param>
  243. /// <param name="inputCount">The number of bytes in the input byte array to use as data.</param>
  244. /// <param name="outputBuffer">The output to which to write decrypted data.</param>
  245. /// <param name="outputOffset">The offset into the output byte array from which to begin writing data.</param>
  246. /// <returns>
  247. /// The number of bytes decrypted.
  248. /// </returns>
  249. public override int DecryptBlock(byte[] inputBuffer, int inputOffset, int inputCount, byte[] outputBuffer, int outputOffset)
  250. {
  251. if ((inputOffset + this.BlockSize) > inputBuffer.Length)
  252. throw new IndexOutOfRangeException("input buffer too short");
  253. if ((outputOffset + this.BlockSize) > outputBuffer.Length)
  254. throw new IndexOutOfRangeException("output buffer too short");
  255. if (this._decryptionKey == null)
  256. {
  257. this._decryptionKey = GenerateWorkingKey(false, this.Key);
  258. }
  259. DesCipher.DesFunc(this._decryptionKey, inputBuffer, inputOffset, outputBuffer, outputOffset);
  260. return this.BlockSize;
  261. }
  262. /// <summary>
  263. /// Generates the working key.
  264. /// </summary>
  265. /// <param name="encrypting">if set to <c>true</c> [encrypting].</param>
  266. /// <param name="key">The key.</param>
  267. /// <returns></returns>
  268. protected int[] GenerateWorkingKey(bool encrypting, byte[] key)
  269. {
  270. this.ValidateKey();
  271. int[] newKey = new int[32];
  272. bool[] pc1m = new bool[56];
  273. bool[] pcr = new bool[56];
  274. for (int j = 0; j < 56; j++)
  275. {
  276. int l = pc1[j];
  277. pc1m[j] = ((key[(uint)l >> 3] & bytebit[l & 07]) != 0);
  278. }
  279. for (int i = 0; i < 16; i++)
  280. {
  281. int l, m, n;
  282. if (encrypting)
  283. {
  284. m = i << 1;
  285. }
  286. else
  287. {
  288. m = (15 - i) << 1;
  289. }
  290. n = m + 1;
  291. newKey[m] = newKey[n] = 0;
  292. for (int j = 0; j < 28; j++)
  293. {
  294. l = j + totrot[i];
  295. if (l < 28)
  296. {
  297. pcr[j] = pc1m[l];
  298. }
  299. else
  300. {
  301. pcr[j] = pc1m[l - 28];
  302. }
  303. }
  304. for (int j = 28; j < 56; j++)
  305. {
  306. l = j + totrot[i];
  307. if (l < 56)
  308. {
  309. pcr[j] = pc1m[l];
  310. }
  311. else
  312. {
  313. pcr[j] = pc1m[l - 28];
  314. }
  315. }
  316. for (int j = 0; j < 24; j++)
  317. {
  318. if (pcr[pc2[j]])
  319. {
  320. newKey[m] |= bigbyte[j];
  321. }
  322. if (pcr[pc2[j + 24]])
  323. {
  324. newKey[n] |= bigbyte[j];
  325. }
  326. }
  327. }
  328. //
  329. // store the processed key
  330. //
  331. for (int i = 0; i != 32; i += 2)
  332. {
  333. int i1, i2;
  334. i1 = newKey[i];
  335. i2 = newKey[i + 1];
  336. newKey[i] = (int) ((uint)((i1 & 0x00fc0000) << 6) |
  337. (uint)((i1 & 0x00000fc0) << 10) |
  338. ((uint)(i2 & 0x00fc0000) >> 10) |
  339. ((uint)(i2 & 0x00000fc0) >> 6));
  340. newKey[i + 1] = (int)((uint)((i1 & 0x0003f000) << 12) |
  341. (uint)((i1 & 0x0000003f) << 16) |
  342. ((uint)(i2 & 0x0003f000) >> 4) |
  343. (uint)(i2 & 0x0000003f));
  344. }
  345. return newKey;
  346. }
  347. /// <summary>
  348. /// Validates the key.
  349. /// </summary>
  350. protected virtual void ValidateKey()
  351. {
  352. var keySize = this.Key.Length * 8;
  353. if (!(keySize == 64))
  354. throw new ArgumentException(string.Format("KeySize '{0}' is not valid for this algorithm.", keySize));
  355. }
  356. /// <summary>
  357. /// Performs DES function.
  358. /// </summary>
  359. /// <param name="wKey">The w key.</param>
  360. /// <param name="input">The input.</param>
  361. /// <param name="inOff">The in off.</param>
  362. /// <param name="outBytes">The out bytes.</param>
  363. /// <param name="outOff">The out off.</param>
  364. protected static void DesFunc(int[] wKey, byte[] input, int inOff, byte[] outBytes, int outOff)
  365. {
  366. uint left = BigEndianToUInt32(input, inOff);
  367. uint right = BigEndianToUInt32(input, inOff + 4);
  368. uint work;
  369. work = ((left >> 4) ^ right) & 0x0f0f0f0f;
  370. right ^= work;
  371. left ^= (work << 4);
  372. work = ((left >> 16) ^ right) & 0x0000ffff;
  373. right ^= work;
  374. left ^= (work << 16);
  375. work = ((right >> 2) ^ left) & 0x33333333;
  376. left ^= work;
  377. right ^= (work << 2);
  378. work = ((right >> 8) ^ left) & 0x00ff00ff;
  379. left ^= work;
  380. right ^= (work << 8);
  381. right = (right << 1) | (right >> 31);
  382. work = (left ^ right) & 0xaaaaaaaa;
  383. left ^= work;
  384. right ^= work;
  385. left = (left << 1) | (left >> 31);
  386. for (int round = 0; round < 8; round++)
  387. {
  388. uint fval;
  389. work = (right << 28) | (right >> 4);
  390. work ^= (uint)wKey[round * 4 + 0];
  391. fval = SP7[work & 0x3f];
  392. fval |= SP5[(work >> 8) & 0x3f];
  393. fval |= SP3[(work >> 16) & 0x3f];
  394. fval |= SP1[(work >> 24) & 0x3f];
  395. work = right ^ (uint)wKey[round * 4 + 1];
  396. fval |= SP8[work & 0x3f];
  397. fval |= SP6[(work >> 8) & 0x3f];
  398. fval |= SP4[(work >> 16) & 0x3f];
  399. fval |= SP2[(work >> 24) & 0x3f];
  400. left ^= fval;
  401. work = (left << 28) | (left >> 4);
  402. work ^= (uint)wKey[round * 4 + 2];
  403. fval = SP7[work & 0x3f];
  404. fval |= SP5[(work >> 8) & 0x3f];
  405. fval |= SP3[(work >> 16) & 0x3f];
  406. fval |= SP1[(work >> 24) & 0x3f];
  407. work = left ^ (uint)wKey[round * 4 + 3];
  408. fval |= SP8[work & 0x3f];
  409. fval |= SP6[(work >> 8) & 0x3f];
  410. fval |= SP4[(work >> 16) & 0x3f];
  411. fval |= SP2[(work >> 24) & 0x3f];
  412. right ^= fval;
  413. }
  414. right = (right << 31) | (right >> 1);
  415. work = (left ^ right) & 0xaaaaaaaa;
  416. left ^= work;
  417. right ^= work;
  418. left = (left << 31) | (left >> 1);
  419. work = ((left >> 8) ^ right) & 0x00ff00ff;
  420. right ^= work;
  421. left ^= (work << 8);
  422. work = ((left >> 2) ^ right) & 0x33333333;
  423. right ^= work;
  424. left ^= (work << 2);
  425. work = ((right >> 16) ^ left) & 0x0000ffff;
  426. left ^= work;
  427. right ^= (work << 16);
  428. work = ((right >> 4) ^ left) & 0x0f0f0f0f;
  429. left ^= work;
  430. right ^= (work << 4);
  431. UInt32ToBigEndian(right, outBytes, outOff);
  432. UInt32ToBigEndian(left, outBytes, outOff + 4);
  433. }
  434. }
  435. }