DesCipher.cs 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Linq;
  4. using System.Text;
  5. namespace Renci.SshNet.Security.Cryptography.Ciphers
  6. {
  7. /// <summary>
  8. /// Implements DES cipher algorithm.
  9. /// </summary>
  10. public class DesCipher : BlockCipher
  11. {
  12. private int[] _encryptionKey;
  13. private int[] _decryptionKey;
  14. /// <summary>
  15. /// Gets the size of the block in bytes.
  16. /// </summary>
  17. /// <value>
  18. /// The size of the block in bytes.
  19. /// </value>
  20. public override int BlockSize
  21. {
  22. get { return 8; }
  23. }
  24. #region Static tables
  25. private static readonly short[] bytebit =
  26. {
  27. 128, 64, 32, 16, 8, 4, 2, 1
  28. };
  29. private static readonly int[] bigbyte =
  30. {
  31. 0x800000, 0x400000, 0x200000, 0x100000,
  32. 0x80000, 0x40000, 0x20000, 0x10000,
  33. 0x8000, 0x4000, 0x2000, 0x1000,
  34. 0x800, 0x400, 0x200, 0x100,
  35. 0x80, 0x40, 0x20, 0x10,
  36. 0x8, 0x4, 0x2, 0x1
  37. };
  38. /*
  39. * Use the key schedule specified in the Standard (ANSI X3.92-1981).
  40. */
  41. private static readonly byte[] pc1 =
  42. {
  43. 56, 48, 40, 32, 24, 16, 8, 0, 57, 49, 41, 33, 25, 17,
  44. 9, 1, 58, 50, 42, 34, 26, 18, 10, 2, 59, 51, 43, 35,
  45. 62, 54, 46, 38, 30, 22, 14, 6, 61, 53, 45, 37, 29, 21,
  46. 13, 5, 60, 52, 44, 36, 28, 20, 12, 4, 27, 19, 11, 3
  47. };
  48. private static readonly byte[] totrot =
  49. {
  50. 1, 2, 4, 6, 8, 10, 12, 14,
  51. 15, 17, 19, 21, 23, 25, 27, 28
  52. };
  53. private static readonly byte[] pc2 =
  54. {
  55. 13, 16, 10, 23, 0, 4, 2, 27, 14, 5, 20, 9,
  56. 22, 18, 11, 3, 25, 7, 15, 6, 26, 19, 12, 1,
  57. 40, 51, 30, 36, 46, 54, 29, 39, 50, 44, 32, 47,
  58. 43, 48, 38, 55, 33, 52, 45, 41, 49, 35, 28, 31
  59. };
  60. private static readonly uint[] SP1 =
  61. {
  62. 0x01010400, 0x00000000, 0x00010000, 0x01010404,
  63. 0x01010004, 0x00010404, 0x00000004, 0x00010000,
  64. 0x00000400, 0x01010400, 0x01010404, 0x00000400,
  65. 0x01000404, 0x01010004, 0x01000000, 0x00000004,
  66. 0x00000404, 0x01000400, 0x01000400, 0x00010400,
  67. 0x00010400, 0x01010000, 0x01010000, 0x01000404,
  68. 0x00010004, 0x01000004, 0x01000004, 0x00010004,
  69. 0x00000000, 0x00000404, 0x00010404, 0x01000000,
  70. 0x00010000, 0x01010404, 0x00000004, 0x01010000,
  71. 0x01010400, 0x01000000, 0x01000000, 0x00000400,
  72. 0x01010004, 0x00010000, 0x00010400, 0x01000004,
  73. 0x00000400, 0x00000004, 0x01000404, 0x00010404,
  74. 0x01010404, 0x00010004, 0x01010000, 0x01000404,
  75. 0x01000004, 0x00000404, 0x00010404, 0x01010400,
  76. 0x00000404, 0x01000400, 0x01000400, 0x00000000,
  77. 0x00010004, 0x00010400, 0x00000000, 0x01010004
  78. };
  79. private static readonly uint[] SP2 =
  80. {
  81. 0x80108020, 0x80008000, 0x00008000, 0x00108020,
  82. 0x00100000, 0x00000020, 0x80100020, 0x80008020,
  83. 0x80000020, 0x80108020, 0x80108000, 0x80000000,
  84. 0x80008000, 0x00100000, 0x00000020, 0x80100020,
  85. 0x00108000, 0x00100020, 0x80008020, 0x00000000,
  86. 0x80000000, 0x00008000, 0x00108020, 0x80100000,
  87. 0x00100020, 0x80000020, 0x00000000, 0x00108000,
  88. 0x00008020, 0x80108000, 0x80100000, 0x00008020,
  89. 0x00000000, 0x00108020, 0x80100020, 0x00100000,
  90. 0x80008020, 0x80100000, 0x80108000, 0x00008000,
  91. 0x80100000, 0x80008000, 0x00000020, 0x80108020,
  92. 0x00108020, 0x00000020, 0x00008000, 0x80000000,
  93. 0x00008020, 0x80108000, 0x00100000, 0x80000020,
  94. 0x00100020, 0x80008020, 0x80000020, 0x00100020,
  95. 0x00108000, 0x00000000, 0x80008000, 0x00008020,
  96. 0x80000000, 0x80100020, 0x80108020, 0x00108000
  97. };
  98. private static readonly uint[] SP3 =
  99. {
  100. 0x00000208, 0x08020200, 0x00000000, 0x08020008,
  101. 0x08000200, 0x00000000, 0x00020208, 0x08000200,
  102. 0x00020008, 0x08000008, 0x08000008, 0x00020000,
  103. 0x08020208, 0x00020008, 0x08020000, 0x00000208,
  104. 0x08000000, 0x00000008, 0x08020200, 0x00000200,
  105. 0x00020200, 0x08020000, 0x08020008, 0x00020208,
  106. 0x08000208, 0x00020200, 0x00020000, 0x08000208,
  107. 0x00000008, 0x08020208, 0x00000200, 0x08000000,
  108. 0x08020200, 0x08000000, 0x00020008, 0x00000208,
  109. 0x00020000, 0x08020200, 0x08000200, 0x00000000,
  110. 0x00000200, 0x00020008, 0x08020208, 0x08000200,
  111. 0x08000008, 0x00000200, 0x00000000, 0x08020008,
  112. 0x08000208, 0x00020000, 0x08000000, 0x08020208,
  113. 0x00000008, 0x00020208, 0x00020200, 0x08000008,
  114. 0x08020000, 0x08000208, 0x00000208, 0x08020000,
  115. 0x00020208, 0x00000008, 0x08020008, 0x00020200
  116. };
  117. private static readonly uint[] SP4 =
  118. {
  119. 0x00802001, 0x00002081, 0x00002081, 0x00000080,
  120. 0x00802080, 0x00800081, 0x00800001, 0x00002001,
  121. 0x00000000, 0x00802000, 0x00802000, 0x00802081,
  122. 0x00000081, 0x00000000, 0x00800080, 0x00800001,
  123. 0x00000001, 0x00002000, 0x00800000, 0x00802001,
  124. 0x00000080, 0x00800000, 0x00002001, 0x00002080,
  125. 0x00800081, 0x00000001, 0x00002080, 0x00800080,
  126. 0x00002000, 0x00802080, 0x00802081, 0x00000081,
  127. 0x00800080, 0x00800001, 0x00802000, 0x00802081,
  128. 0x00000081, 0x00000000, 0x00000000, 0x00802000,
  129. 0x00002080, 0x00800080, 0x00800081, 0x00000001,
  130. 0x00802001, 0x00002081, 0x00002081, 0x00000080,
  131. 0x00802081, 0x00000081, 0x00000001, 0x00002000,
  132. 0x00800001, 0x00002001, 0x00802080, 0x00800081,
  133. 0x00002001, 0x00002080, 0x00800000, 0x00802001,
  134. 0x00000080, 0x00800000, 0x00002000, 0x00802080
  135. };
  136. private static readonly uint[] SP5 =
  137. {
  138. 0x00000100, 0x02080100, 0x02080000, 0x42000100,
  139. 0x00080000, 0x00000100, 0x40000000, 0x02080000,
  140. 0x40080100, 0x00080000, 0x02000100, 0x40080100,
  141. 0x42000100, 0x42080000, 0x00080100, 0x40000000,
  142. 0x02000000, 0x40080000, 0x40080000, 0x00000000,
  143. 0x40000100, 0x42080100, 0x42080100, 0x02000100,
  144. 0x42080000, 0x40000100, 0x00000000, 0x42000000,
  145. 0x02080100, 0x02000000, 0x42000000, 0x00080100,
  146. 0x00080000, 0x42000100, 0x00000100, 0x02000000,
  147. 0x40000000, 0x02080000, 0x42000100, 0x40080100,
  148. 0x02000100, 0x40000000, 0x42080000, 0x02080100,
  149. 0x40080100, 0x00000100, 0x02000000, 0x42080000,
  150. 0x42080100, 0x00080100, 0x42000000, 0x42080100,
  151. 0x02080000, 0x00000000, 0x40080000, 0x42000000,
  152. 0x00080100, 0x02000100, 0x40000100, 0x00080000,
  153. 0x00000000, 0x40080000, 0x02080100, 0x40000100
  154. };
  155. private static readonly uint[] SP6 =
  156. {
  157. 0x20000010, 0x20400000, 0x00004000, 0x20404010,
  158. 0x20400000, 0x00000010, 0x20404010, 0x00400000,
  159. 0x20004000, 0x00404010, 0x00400000, 0x20000010,
  160. 0x00400010, 0x20004000, 0x20000000, 0x00004010,
  161. 0x00000000, 0x00400010, 0x20004010, 0x00004000,
  162. 0x00404000, 0x20004010, 0x00000010, 0x20400010,
  163. 0x20400010, 0x00000000, 0x00404010, 0x20404000,
  164. 0x00004010, 0x00404000, 0x20404000, 0x20000000,
  165. 0x20004000, 0x00000010, 0x20400010, 0x00404000,
  166. 0x20404010, 0x00400000, 0x00004010, 0x20000010,
  167. 0x00400000, 0x20004000, 0x20000000, 0x00004010,
  168. 0x20000010, 0x20404010, 0x00404000, 0x20400000,
  169. 0x00404010, 0x20404000, 0x00000000, 0x20400010,
  170. 0x00000010, 0x00004000, 0x20400000, 0x00404010,
  171. 0x00004000, 0x00400010, 0x20004010, 0x00000000,
  172. 0x20404000, 0x20000000, 0x00400010, 0x20004010
  173. };
  174. private static readonly uint[] SP7 =
  175. {
  176. 0x00200000, 0x04200002, 0x04000802, 0x00000000,
  177. 0x00000800, 0x04000802, 0x00200802, 0x04200800,
  178. 0x04200802, 0x00200000, 0x00000000, 0x04000002,
  179. 0x00000002, 0x04000000, 0x04200002, 0x00000802,
  180. 0x04000800, 0x00200802, 0x00200002, 0x04000800,
  181. 0x04000002, 0x04200000, 0x04200800, 0x00200002,
  182. 0x04200000, 0x00000800, 0x00000802, 0x04200802,
  183. 0x00200800, 0x00000002, 0x04000000, 0x00200800,
  184. 0x04000000, 0x00200800, 0x00200000, 0x04000802,
  185. 0x04000802, 0x04200002, 0x04200002, 0x00000002,
  186. 0x00200002, 0x04000000, 0x04000800, 0x00200000,
  187. 0x04200800, 0x00000802, 0x00200802, 0x04200800,
  188. 0x00000802, 0x04000002, 0x04200802, 0x04200000,
  189. 0x00200800, 0x00000000, 0x00000002, 0x04200802,
  190. 0x00000000, 0x00200802, 0x04200000, 0x00000800,
  191. 0x04000002, 0x04000800, 0x00000800, 0x00200002
  192. };
  193. private static readonly uint[] SP8 =
  194. {
  195. 0x10001040, 0x00001000, 0x00040000, 0x10041040,
  196. 0x10000000, 0x10001040, 0x00000040, 0x10000000,
  197. 0x00040040, 0x10040000, 0x10041040, 0x00041000,
  198. 0x10041000, 0x00041040, 0x00001000, 0x00000040,
  199. 0x10040000, 0x10000040, 0x10001000, 0x00001040,
  200. 0x00041000, 0x00040040, 0x10040040, 0x10041000,
  201. 0x00001040, 0x00000000, 0x00000000, 0x10040040,
  202. 0x10000040, 0x10001000, 0x00041040, 0x00040000,
  203. 0x00041040, 0x00040000, 0x10041000, 0x00001000,
  204. 0x00000040, 0x10040040, 0x00001000, 0x00041040,
  205. 0x10001000, 0x00000040, 0x10000040, 0x10040000,
  206. 0x10040040, 0x10000000, 0x00040000, 0x10001040,
  207. 0x00000000, 0x10041040, 0x00040040, 0x10000040,
  208. 0x10040000, 0x10001000, 0x10001040, 0x00000000,
  209. 0x10041040, 0x00041000, 0x00041000, 0x00001040,
  210. 0x00001040, 0x00040040, 0x10000000, 0x10041000
  211. };
  212. #endregion
  213. /// <summary>
  214. /// Initializes a new instance of the <see cref="DesCipher"/> class.
  215. /// </summary>
  216. /// <param name="key">The key.</param>
  217. /// <param name="mode">The mode.</param>
  218. /// <param name="padding">The padding.</param>
  219. public DesCipher(byte[] key, CipherMode mode, CipherPadding padding)
  220. : base(key, mode, padding)
  221. {
  222. }
  223. /// <summary>
  224. /// Encrypts the specified region of the input byte array and copies the encrypted data to the specified region of the output byte array.
  225. /// </summary>
  226. /// <param name="inputBuffer">The input data to encrypt.</param>
  227. /// <param name="inputOffset">The offset into the input byte array from which to begin using data.</param>
  228. /// <param name="inputCount">The number of bytes in the input byte array to use as data.</param>
  229. /// <param name="outputBuffer">The output to which to write encrypted data.</param>
  230. /// <param name="outputOffset">The offset into the output byte array from which to begin writing data.</param>
  231. /// <returns>
  232. /// The number of bytes encrypted.
  233. /// </returns>
  234. public override int EncryptBlock(byte[] inputBuffer, int inputOffset, int inputCount, byte[] outputBuffer, int outputOffset)
  235. {
  236. if ((inputOffset + this.BlockSize) > inputBuffer.Length)
  237. throw new IndexOutOfRangeException("input buffer too short");
  238. if ((outputOffset + this.BlockSize) > outputBuffer.Length)
  239. throw new IndexOutOfRangeException("output buffer too short");
  240. if (this._encryptionKey == null)
  241. {
  242. this._encryptionKey = GenerateWorkingKey(true, this.Key);
  243. }
  244. DesCipher.DesFunc(this._encryptionKey, inputBuffer, inputOffset, outputBuffer, outputOffset);
  245. return this.BlockSize;
  246. }
  247. /// <summary>
  248. /// Decrypts the specified region of the input byte array and copies the decrypted data to the specified region of the output byte array.
  249. /// </summary>
  250. /// <param name="inputBuffer">The input data to decrypt.</param>
  251. /// <param name="inputOffset">The offset into the input byte array from which to begin using data.</param>
  252. /// <param name="inputCount">The number of bytes in the input byte array to use as data.</param>
  253. /// <param name="outputBuffer">The output to which to write decrypted data.</param>
  254. /// <param name="outputOffset">The offset into the output byte array from which to begin writing data.</param>
  255. /// <returns>
  256. /// The number of bytes decrypted.
  257. /// </returns>
  258. public override int DecryptBlock(byte[] inputBuffer, int inputOffset, int inputCount, byte[] outputBuffer, int outputOffset)
  259. {
  260. if ((inputOffset + this.BlockSize) > inputBuffer.Length)
  261. throw new IndexOutOfRangeException("input buffer too short");
  262. if ((outputOffset + this.BlockSize) > outputBuffer.Length)
  263. throw new IndexOutOfRangeException("output buffer too short");
  264. if (this._decryptionKey == null)
  265. {
  266. this._decryptionKey = GenerateWorkingKey(false, this.Key);
  267. }
  268. DesCipher.DesFunc(this._decryptionKey, inputBuffer, inputOffset, outputBuffer, outputOffset);
  269. return this.BlockSize;
  270. }
  271. /// <summary>
  272. /// Generates the working key.
  273. /// </summary>
  274. /// <param name="encrypting">if set to <c>true</c> [encrypting].</param>
  275. /// <param name="key">The key.</param>
  276. /// <returns></returns>
  277. protected int[] GenerateWorkingKey(bool encrypting, byte[] key)
  278. {
  279. this.ValidateKey();
  280. int[] newKey = new int[32];
  281. bool[] pc1m = new bool[56];
  282. bool[] pcr = new bool[56];
  283. for (int j = 0; j < 56; j++)
  284. {
  285. int l = pc1[j];
  286. pc1m[j] = ((key[(uint)l >> 3] & bytebit[l & 07]) != 0);
  287. }
  288. for (int i = 0; i < 16; i++)
  289. {
  290. int l, m, n;
  291. if (encrypting)
  292. {
  293. m = i << 1;
  294. }
  295. else
  296. {
  297. m = (15 - i) << 1;
  298. }
  299. n = m + 1;
  300. newKey[m] = newKey[n] = 0;
  301. for (int j = 0; j < 28; j++)
  302. {
  303. l = j + totrot[i];
  304. if (l < 28)
  305. {
  306. pcr[j] = pc1m[l];
  307. }
  308. else
  309. {
  310. pcr[j] = pc1m[l - 28];
  311. }
  312. }
  313. for (int j = 28; j < 56; j++)
  314. {
  315. l = j + totrot[i];
  316. if (l < 56)
  317. {
  318. pcr[j] = pc1m[l];
  319. }
  320. else
  321. {
  322. pcr[j] = pc1m[l - 28];
  323. }
  324. }
  325. for (int j = 0; j < 24; j++)
  326. {
  327. if (pcr[pc2[j]])
  328. {
  329. newKey[m] |= bigbyte[j];
  330. }
  331. if (pcr[pc2[j + 24]])
  332. {
  333. newKey[n] |= bigbyte[j];
  334. }
  335. }
  336. }
  337. //
  338. // store the processed key
  339. //
  340. for (int i = 0; i != 32; i += 2)
  341. {
  342. int i1, i2;
  343. i1 = newKey[i];
  344. i2 = newKey[i + 1];
  345. newKey[i] = (int) ((uint)((i1 & 0x00fc0000) << 6) |
  346. (uint)((i1 & 0x00000fc0) << 10) |
  347. ((uint)(i2 & 0x00fc0000) >> 10) |
  348. ((uint)(i2 & 0x00000fc0) >> 6));
  349. newKey[i + 1] = (int)((uint)((i1 & 0x0003f000) << 12) |
  350. (uint)((i1 & 0x0000003f) << 16) |
  351. ((uint)(i2 & 0x0003f000) >> 4) |
  352. (uint)(i2 & 0x0000003f));
  353. }
  354. return newKey;
  355. }
  356. /// <summary>
  357. /// Validates the key.
  358. /// </summary>
  359. protected virtual void ValidateKey()
  360. {
  361. var keySize = this.Key.Length * 8;
  362. if (!(keySize == 64))
  363. throw new ArgumentException(string.Format("KeySize '{0}' is not valid for this algorithm.", keySize));
  364. }
  365. /// <summary>
  366. /// Performs DES function.
  367. /// </summary>
  368. /// <param name="wKey">The w key.</param>
  369. /// <param name="input">The input.</param>
  370. /// <param name="inOff">The in off.</param>
  371. /// <param name="outBytes">The out bytes.</param>
  372. /// <param name="outOff">The out off.</param>
  373. protected static void DesFunc(int[] wKey, byte[] input, int inOff, byte[] outBytes, int outOff)
  374. {
  375. uint left = BigEndianToUInt32(input, inOff);
  376. uint right = BigEndianToUInt32(input, inOff + 4);
  377. uint work;
  378. work = ((left >> 4) ^ right) & 0x0f0f0f0f;
  379. right ^= work;
  380. left ^= (work << 4);
  381. work = ((left >> 16) ^ right) & 0x0000ffff;
  382. right ^= work;
  383. left ^= (work << 16);
  384. work = ((right >> 2) ^ left) & 0x33333333;
  385. left ^= work;
  386. right ^= (work << 2);
  387. work = ((right >> 8) ^ left) & 0x00ff00ff;
  388. left ^= work;
  389. right ^= (work << 8);
  390. right = (right << 1) | (right >> 31);
  391. work = (left ^ right) & 0xaaaaaaaa;
  392. left ^= work;
  393. right ^= work;
  394. left = (left << 1) | (left >> 31);
  395. for (int round = 0; round < 8; round++)
  396. {
  397. uint fval;
  398. work = (right << 28) | (right >> 4);
  399. work ^= (uint)wKey[round * 4 + 0];
  400. fval = SP7[work & 0x3f];
  401. fval |= SP5[(work >> 8) & 0x3f];
  402. fval |= SP3[(work >> 16) & 0x3f];
  403. fval |= SP1[(work >> 24) & 0x3f];
  404. work = right ^ (uint)wKey[round * 4 + 1];
  405. fval |= SP8[work & 0x3f];
  406. fval |= SP6[(work >> 8) & 0x3f];
  407. fval |= SP4[(work >> 16) & 0x3f];
  408. fval |= SP2[(work >> 24) & 0x3f];
  409. left ^= fval;
  410. work = (left << 28) | (left >> 4);
  411. work ^= (uint)wKey[round * 4 + 2];
  412. fval = SP7[work & 0x3f];
  413. fval |= SP5[(work >> 8) & 0x3f];
  414. fval |= SP3[(work >> 16) & 0x3f];
  415. fval |= SP1[(work >> 24) & 0x3f];
  416. work = left ^ (uint)wKey[round * 4 + 3];
  417. fval |= SP8[work & 0x3f];
  418. fval |= SP6[(work >> 8) & 0x3f];
  419. fval |= SP4[(work >> 16) & 0x3f];
  420. fval |= SP2[(work >> 24) & 0x3f];
  421. right ^= fval;
  422. }
  423. right = (right << 31) | (right >> 1);
  424. work = (left ^ right) & 0xaaaaaaaa;
  425. left ^= work;
  426. right ^= work;
  427. left = (left << 31) | (left >> 1);
  428. work = ((left >> 8) ^ right) & 0x00ff00ff;
  429. right ^= work;
  430. left ^= (work << 8);
  431. work = ((left >> 2) ^ right) & 0x33333333;
  432. right ^= work;
  433. left ^= (work << 2);
  434. work = ((right >> 16) ^ left) & 0x0000ffff;
  435. left ^= work;
  436. right ^= (work << 16);
  437. work = ((right >> 4) ^ left) & 0x0f0f0f0f;
  438. left ^= work;
  439. right ^= (work << 4);
  440. UInt32ToBigEndian(right, outBytes, outOff);
  441. UInt32ToBigEndian(left, outBytes, outOff + 4);
  442. }
  443. }
  444. }