Home | History | Annotate | Line # | Download | only in opencrypto
cryptosoft_xform.c revision 1.21
      1  1.21  drochner /*	$NetBSD: cryptosoft_xform.c,v 1.21 2011/05/24 18:59:22 drochner Exp $ */
      2   1.1   thorpej /*	$FreeBSD: src/sys/opencrypto/xform.c,v 1.1.2.1 2002/11/21 23:34:23 sam Exp $	*/
      3   1.1   thorpej /*	$OpenBSD: xform.c,v 1.19 2002/08/16 22:47:25 dhartmei Exp $	*/
      4   1.1   thorpej 
      5   1.1   thorpej /*
      6   1.1   thorpej  * The authors of this code are John Ioannidis (ji (at) tla.org),
      7   1.1   thorpej  * Angelos D. Keromytis (kermit (at) csd.uch.gr) and
      8   1.1   thorpej  * Niels Provos (provos (at) physnet.uni-hamburg.de).
      9   1.1   thorpej  *
     10   1.1   thorpej  * This code was written by John Ioannidis for BSD/OS in Athens, Greece,
     11   1.1   thorpej  * in November 1995.
     12   1.1   thorpej  *
     13   1.1   thorpej  * Ported to OpenBSD and NetBSD, with additional transforms, in December 1996,
     14   1.1   thorpej  * by Angelos D. Keromytis.
     15   1.1   thorpej  *
     16   1.1   thorpej  * Additional transforms and features in 1997 and 1998 by Angelos D. Keromytis
     17   1.1   thorpej  * and Niels Provos.
     18   1.1   thorpej  *
     19   1.1   thorpej  * Additional features in 1999 by Angelos D. Keromytis.
     20   1.1   thorpej  *
     21   1.1   thorpej  * Copyright (C) 1995, 1996, 1997, 1998, 1999 by John Ioannidis,
     22   1.1   thorpej  * Angelos D. Keromytis and Niels Provos.
     23   1.1   thorpej  *
     24   1.1   thorpej  * Copyright (C) 2001, Angelos D. Keromytis.
     25   1.1   thorpej  *
     26   1.1   thorpej  * Permission to use, copy, and modify this software with or without fee
     27   1.1   thorpej  * is hereby granted, provided that this entire notice is included in
     28   1.1   thorpej  * all copies of any software which is or includes a copy or
     29   1.1   thorpej  * modification of this software.
     30   1.1   thorpej  * You may use this code under the GNU public license if you so wish. Please
     31   1.1   thorpej  * contribute changes back to the authors under this freer than GPL license
     32   1.1   thorpej  * so that we may further the use of strong encryption without limitations to
     33   1.1   thorpej  * all.
     34   1.1   thorpej  *
     35   1.1   thorpej  * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR
     36   1.1   thorpej  * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY
     37   1.1   thorpej  * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE
     38   1.1   thorpej  * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR
     39   1.1   thorpej  * PURPOSE.
     40   1.1   thorpej  */
     41   1.1   thorpej 
     42   1.1   thorpej #include <sys/cdefs.h>
     43  1.21  drochner __KERNEL_RCSID(1, "$NetBSD: cryptosoft_xform.c,v 1.21 2011/05/24 18:59:22 drochner Exp $");
     44   1.1   thorpej 
     45   1.1   thorpej #include <crypto/blowfish/blowfish.h>
     46   1.1   thorpej #include <crypto/cast128/cast128.h>
     47   1.1   thorpej #include <crypto/des/des.h>
     48   1.1   thorpej #include <crypto/rijndael/rijndael.h>
     49   1.1   thorpej #include <crypto/skipjack/skipjack.h>
     50  1.15  drochner #include <crypto/camellia/camellia.h>
     51   1.1   thorpej 
     52   1.1   thorpej #include <opencrypto/deflate.h>
     53   1.1   thorpej 
     54   1.1   thorpej #include <sys/md5.h>
     55   1.3  christos #include <sys/rmd160.h>
     56   1.1   thorpej #include <sys/sha1.h>
     57  1.21  drochner #include <sys/sha2.h>
     58   1.1   thorpej 
     59   1.1   thorpej struct swcr_auth_hash {
     60  1.13  drochner 	const struct auth_hash *auth_hash;
     61  1.21  drochner 	int ctxsize;
     62   1.1   thorpej 	void (*Init)(void *);
     63   1.1   thorpej 	int  (*Update)(void *, const uint8_t *, uint16_t);
     64   1.1   thorpej 	void (*Final)(uint8_t *, void *);
     65   1.1   thorpej };
     66   1.1   thorpej 
     67   1.1   thorpej struct swcr_enc_xform {
     68  1.13  drochner 	const struct enc_xform *enc_xform;
     69   1.5  christos 	void (*encrypt)(void *, uint8_t *);
     70   1.5  christos 	void (*decrypt)(void *, uint8_t *);
     71  1.16  drochner 	int  (*setkey)(uint8_t **, const uint8_t *, int);
     72   1.1   thorpej 	void (*zerokey)(uint8_t **);
     73  1.20  drochner 	void (*reinit)(void *, const uint8_t *, uint8_t *);
     74   1.1   thorpej };
     75   1.1   thorpej 
     76   1.1   thorpej struct swcr_comp_algo {
     77  1.14  drochner 	const struct comp_algo *unused_comp_algo;
     78   1.1   thorpej 	uint32_t (*compress)(uint8_t *, uint32_t, uint8_t **);
     79  1.14  drochner 	uint32_t (*decompress)(uint8_t *, uint32_t, uint8_t **, int);
     80   1.1   thorpej };
     81   1.1   thorpej 
     82   1.5  christos static void null_encrypt(void *, u_int8_t *);
     83   1.5  christos static void null_decrypt(void *, u_int8_t *);
     84   1.1   thorpej static int null_setkey(u_int8_t **, const u_int8_t *, int);
     85   1.1   thorpej static void null_zerokey(u_int8_t **);
     86   1.1   thorpej 
     87   1.1   thorpej static	int des1_setkey(u_int8_t **, const u_int8_t *, int);
     88   1.1   thorpej static	int des3_setkey(u_int8_t **, const u_int8_t *, int);
     89   1.1   thorpej static	int blf_setkey(u_int8_t **, const u_int8_t *, int);
     90   1.1   thorpej static	int cast5_setkey(u_int8_t **, const u_int8_t *, int);
     91   1.1   thorpej static  int skipjack_setkey(u_int8_t **, const u_int8_t *, int);
     92   1.1   thorpej static  int rijndael128_setkey(u_int8_t **, const u_int8_t *, int);
     93  1.15  drochner static  int cml_setkey(u_int8_t **, const u_int8_t *, int);
     94  1.18  drochner static  int aes_ctr_setkey(u_int8_t **, const u_int8_t *, int);
     95   1.5  christos static	void des1_encrypt(void *, u_int8_t *);
     96   1.5  christos static	void des3_encrypt(void *, u_int8_t *);
     97   1.5  christos static	void blf_encrypt(void *, u_int8_t *);
     98   1.5  christos static	void cast5_encrypt(void *, u_int8_t *);
     99   1.5  christos static	void skipjack_encrypt(void *, u_int8_t *);
    100   1.5  christos static	void rijndael128_encrypt(void *, u_int8_t *);
    101  1.15  drochner static  void cml_encrypt(void *, u_int8_t *);
    102   1.5  christos static	void des1_decrypt(void *, u_int8_t *);
    103   1.5  christos static	void des3_decrypt(void *, u_int8_t *);
    104   1.5  christos static	void blf_decrypt(void *, u_int8_t *);
    105   1.5  christos static	void cast5_decrypt(void *, u_int8_t *);
    106   1.5  christos static	void skipjack_decrypt(void *, u_int8_t *);
    107   1.5  christos static	void rijndael128_decrypt(void *, u_int8_t *);
    108  1.15  drochner static  void cml_decrypt(void *, u_int8_t *);
    109  1.18  drochner static  void aes_ctr_crypt(void *, u_int8_t *);
    110   1.1   thorpej static	void des1_zerokey(u_int8_t **);
    111   1.1   thorpej static	void des3_zerokey(u_int8_t **);
    112   1.1   thorpej static	void blf_zerokey(u_int8_t **);
    113   1.1   thorpej static	void cast5_zerokey(u_int8_t **);
    114   1.1   thorpej static	void skipjack_zerokey(u_int8_t **);
    115   1.1   thorpej static	void rijndael128_zerokey(u_int8_t **);
    116  1.15  drochner static  void cml_zerokey(u_int8_t **);
    117  1.18  drochner static  void aes_ctr_zerokey(u_int8_t **);
    118  1.20  drochner static  void aes_ctr_reinit(void *, const u_int8_t *, u_int8_t *);
    119   1.1   thorpej 
    120   1.1   thorpej static	void null_init(void *);
    121   1.1   thorpej static	int null_update(void *, const u_int8_t *, u_int16_t);
    122   1.1   thorpej static	void null_final(u_int8_t *, void *);
    123   1.1   thorpej 
    124   1.1   thorpej static int	MD5Update_int(void *, const u_int8_t *, u_int16_t);
    125   1.1   thorpej static void	SHA1Init_int(void *);
    126   1.1   thorpej static	int SHA1Update_int(void *, const u_int8_t *, u_int16_t);
    127   1.1   thorpej static	void SHA1Final_int(u_int8_t *, void *);
    128   1.1   thorpej 
    129   1.1   thorpej 
    130   1.1   thorpej static int RMD160Update_int(void *, const u_int8_t *, u_int16_t);
    131   1.1   thorpej static	int SHA1Update_int(void *, const u_int8_t *, u_int16_t);
    132   1.1   thorpej static	void SHA1Final_int(u_int8_t *, void *);
    133   1.1   thorpej static	int RMD160Update_int(void *, const u_int8_t *, u_int16_t);
    134   1.1   thorpej static	int SHA256Update_int(void *, const u_int8_t *, u_int16_t);
    135   1.1   thorpej static	int SHA384Update_int(void *, const u_int8_t *, u_int16_t);
    136   1.1   thorpej static	int SHA512Update_int(void *, const u_int8_t *, u_int16_t);
    137   1.1   thorpej 
    138   1.1   thorpej static u_int32_t deflate_compress(u_int8_t *, u_int32_t, u_int8_t **);
    139  1.14  drochner static u_int32_t deflate_decompress(u_int8_t *, u_int32_t, u_int8_t **, int);
    140  1.12    darran static u_int32_t gzip_compress(u_int8_t *, u_int32_t, u_int8_t **);
    141  1.14  drochner static u_int32_t gzip_decompress(u_int8_t *, u_int32_t, u_int8_t **, int);
    142   1.1   thorpej 
    143   1.1   thorpej /* Encryption instances */
    144   1.1   thorpej static const struct swcr_enc_xform swcr_enc_xform_null = {
    145   1.1   thorpej 	&enc_xform_null,
    146   1.1   thorpej 	null_encrypt,
    147   1.1   thorpej 	null_decrypt,
    148   1.1   thorpej 	null_setkey,
    149   1.1   thorpej 	null_zerokey,
    150  1.17  drochner 	NULL
    151   1.1   thorpej };
    152   1.1   thorpej 
    153   1.1   thorpej static const struct swcr_enc_xform swcr_enc_xform_des = {
    154   1.1   thorpej 	&enc_xform_des,
    155   1.1   thorpej 	des1_encrypt,
    156   1.1   thorpej 	des1_decrypt,
    157   1.1   thorpej 	des1_setkey,
    158   1.1   thorpej 	des1_zerokey,
    159  1.17  drochner 	NULL
    160   1.1   thorpej };
    161   1.1   thorpej 
    162   1.1   thorpej static const struct swcr_enc_xform swcr_enc_xform_3des = {
    163   1.1   thorpej 	&enc_xform_3des,
    164   1.1   thorpej 	des3_encrypt,
    165   1.1   thorpej 	des3_decrypt,
    166   1.1   thorpej 	des3_setkey,
    167  1.17  drochner 	des3_zerokey,
    168  1.17  drochner 	NULL
    169   1.1   thorpej };
    170   1.1   thorpej 
    171   1.1   thorpej static const struct swcr_enc_xform swcr_enc_xform_blf = {
    172   1.1   thorpej 	&enc_xform_blf,
    173   1.1   thorpej 	blf_encrypt,
    174   1.1   thorpej 	blf_decrypt,
    175   1.1   thorpej 	blf_setkey,
    176  1.17  drochner 	blf_zerokey,
    177  1.17  drochner 	NULL
    178   1.1   thorpej };
    179   1.1   thorpej 
    180   1.1   thorpej static const struct swcr_enc_xform swcr_enc_xform_cast5 = {
    181   1.1   thorpej 	&enc_xform_cast5,
    182   1.1   thorpej 	cast5_encrypt,
    183   1.1   thorpej 	cast5_decrypt,
    184   1.1   thorpej 	cast5_setkey,
    185  1.17  drochner 	cast5_zerokey,
    186  1.17  drochner 	NULL
    187   1.1   thorpej };
    188   1.1   thorpej 
    189   1.1   thorpej static const struct swcr_enc_xform swcr_enc_xform_skipjack = {
    190   1.1   thorpej 	&enc_xform_skipjack,
    191   1.1   thorpej 	skipjack_encrypt,
    192   1.1   thorpej 	skipjack_decrypt,
    193   1.1   thorpej 	skipjack_setkey,
    194  1.17  drochner 	skipjack_zerokey,
    195  1.17  drochner 	NULL
    196   1.1   thorpej };
    197   1.1   thorpej 
    198   1.1   thorpej static const struct swcr_enc_xform swcr_enc_xform_rijndael128 = {
    199   1.1   thorpej 	&enc_xform_rijndael128,
    200   1.1   thorpej 	rijndael128_encrypt,
    201   1.1   thorpej 	rijndael128_decrypt,
    202   1.1   thorpej 	rijndael128_setkey,
    203   1.1   thorpej 	rijndael128_zerokey,
    204  1.17  drochner 	NULL
    205   1.1   thorpej };
    206   1.1   thorpej 
    207  1.18  drochner static const struct swcr_enc_xform swcr_enc_xform_aes_ctr = {
    208  1.18  drochner 	&enc_xform_aes_ctr,
    209  1.18  drochner 	aes_ctr_crypt,
    210  1.18  drochner 	aes_ctr_crypt,
    211  1.18  drochner 	aes_ctr_setkey,
    212  1.18  drochner 	aes_ctr_zerokey,
    213  1.18  drochner 	aes_ctr_reinit
    214  1.18  drochner };
    215  1.18  drochner 
    216  1.15  drochner static const struct swcr_enc_xform swcr_enc_xform_camellia = {
    217  1.15  drochner 	&enc_xform_camellia,
    218  1.15  drochner 	cml_encrypt,
    219  1.15  drochner 	cml_decrypt,
    220  1.15  drochner 	cml_setkey,
    221  1.17  drochner 	cml_zerokey,
    222  1.17  drochner 	NULL
    223  1.15  drochner };
    224  1.15  drochner 
    225   1.1   thorpej /* Authentication instances */
    226   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_null = {
    227  1.21  drochner 	&auth_hash_null, sizeof(int), /* NB: context isn't used */
    228   1.1   thorpej 	null_init, null_update, null_final
    229   1.1   thorpej };
    230   1.1   thorpej 
    231   1.7       tls static const struct swcr_auth_hash swcr_auth_hash_hmac_md5 = {
    232  1.21  drochner 	&auth_hash_hmac_md5, sizeof(MD5_CTX),
    233   1.7       tls 	(void (*) (void *)) MD5Init, MD5Update_int,
    234   1.7       tls 	(void (*) (u_int8_t *, void *)) MD5Final
    235   1.7       tls };
    236   1.7       tls 
    237   1.7       tls static const struct swcr_auth_hash swcr_auth_hash_hmac_sha1 = {
    238  1.21  drochner 	&auth_hash_hmac_sha1, sizeof(SHA1_CTX),
    239   1.7       tls 	SHA1Init_int, SHA1Update_int, SHA1Final_int
    240   1.7       tls };
    241   1.7       tls 
    242   1.7       tls static const struct swcr_auth_hash swcr_auth_hash_hmac_ripemd_160 = {
    243  1.21  drochner 	&auth_hash_hmac_ripemd_160, sizeof(RMD160_CTX),
    244   1.7       tls 	(void (*)(void *)) RMD160Init, RMD160Update_int,
    245   1.7       tls 	(void (*)(u_int8_t *, void *)) RMD160Final
    246   1.7       tls };
    247   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_hmac_md5_96 = {
    248  1.21  drochner 	&auth_hash_hmac_md5_96, sizeof(MD5_CTX),
    249   1.1   thorpej 	(void (*) (void *)) MD5Init, MD5Update_int,
    250   1.1   thorpej 	(void (*) (u_int8_t *, void *)) MD5Final
    251   1.1   thorpej };
    252   1.1   thorpej 
    253   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_hmac_sha1_96 = {
    254  1.21  drochner 	&auth_hash_hmac_sha1_96, sizeof(SHA1_CTX),
    255   1.1   thorpej 	SHA1Init_int, SHA1Update_int, SHA1Final_int
    256   1.1   thorpej };
    257   1.1   thorpej 
    258   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_hmac_ripemd_160_96 = {
    259  1.21  drochner 	&auth_hash_hmac_ripemd_160_96, sizeof(RMD160_CTX),
    260   1.1   thorpej 	(void (*)(void *)) RMD160Init, RMD160Update_int,
    261   1.1   thorpej 	(void (*)(u_int8_t *, void *)) RMD160Final
    262   1.1   thorpej };
    263   1.1   thorpej 
    264   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_key_md5 = {
    265  1.21  drochner 	&auth_hash_key_md5, sizeof(MD5_CTX),
    266   1.1   thorpej 	(void (*)(void *)) MD5Init, MD5Update_int,
    267   1.1   thorpej 	(void (*)(u_int8_t *, void *)) MD5Final
    268   1.1   thorpej };
    269   1.1   thorpej 
    270   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_key_sha1 = {
    271  1.21  drochner 	&auth_hash_key_sha1, sizeof(SHA1_CTX),
    272   1.1   thorpej 	SHA1Init_int, SHA1Update_int, SHA1Final_int
    273   1.1   thorpej };
    274   1.1   thorpej 
    275   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_md5 = {
    276  1.21  drochner 	&auth_hash_md5, sizeof(MD5_CTX),
    277   1.1   thorpej 	(void (*) (void *)) MD5Init, MD5Update_int,
    278   1.1   thorpej 	(void (*) (u_int8_t *, void *)) MD5Final
    279   1.1   thorpej };
    280   1.1   thorpej 
    281   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_sha1 = {
    282  1.21  drochner 	&auth_hash_sha1, sizeof(SHA1_CTX),
    283   1.1   thorpej 	(void (*)(void *)) SHA1Init, SHA1Update_int,
    284   1.1   thorpej 	(void (*)(u_int8_t *, void *)) SHA1Final
    285   1.1   thorpej };
    286   1.1   thorpej 
    287   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_hmac_sha2_256 = {
    288  1.21  drochner 	&auth_hash_hmac_sha2_256, sizeof(SHA256_CTX),
    289   1.1   thorpej 	(void (*)(void *)) SHA256_Init, SHA256Update_int,
    290   1.1   thorpej 	(void (*)(u_int8_t *, void *)) SHA256_Final
    291   1.1   thorpej };
    292   1.1   thorpej 
    293   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_hmac_sha2_384 = {
    294  1.21  drochner 	&auth_hash_hmac_sha2_384, sizeof(SHA384_CTX),
    295   1.1   thorpej 	(void (*)(void *)) SHA384_Init, SHA384Update_int,
    296   1.1   thorpej 	(void (*)(u_int8_t *, void *)) SHA384_Final
    297   1.1   thorpej };
    298   1.1   thorpej 
    299   1.1   thorpej static const struct swcr_auth_hash swcr_auth_hash_hmac_sha2_512 = {
    300  1.21  drochner 	&auth_hash_hmac_sha2_512, sizeof(SHA512_CTX),
    301   1.1   thorpej 	(void (*)(void *)) SHA512_Init, SHA512Update_int,
    302   1.1   thorpej 	(void (*)(u_int8_t *, void *)) SHA512_Final
    303   1.1   thorpej };
    304   1.1   thorpej 
    305   1.1   thorpej /* Compression instance */
    306   1.1   thorpej static const struct swcr_comp_algo swcr_comp_algo_deflate = {
    307   1.1   thorpej 	&comp_algo_deflate,
    308   1.1   thorpej 	deflate_compress,
    309   1.1   thorpej 	deflate_decompress
    310   1.1   thorpej };
    311   1.1   thorpej 
    312  1.14  drochner static const struct swcr_comp_algo swcr_comp_algo_deflate_nogrow = {
    313  1.14  drochner 	&comp_algo_deflate_nogrow,
    314  1.14  drochner 	deflate_compress,
    315  1.14  drochner 	deflate_decompress
    316  1.14  drochner };
    317  1.14  drochner 
    318  1.12    darran static const struct swcr_comp_algo swcr_comp_algo_gzip = {
    319  1.12    darran 	&comp_algo_deflate,
    320  1.12    darran 	gzip_compress,
    321  1.12    darran 	gzip_decompress
    322  1.12    darran };
    323  1.12    darran 
    324   1.1   thorpej /*
    325   1.1   thorpej  * Encryption wrapper routines.
    326   1.1   thorpej  */
    327   1.1   thorpej static void
    328   1.5  christos null_encrypt(void *key, u_int8_t *blk)
    329   1.1   thorpej {
    330   1.1   thorpej }
    331   1.1   thorpej static void
    332   1.5  christos null_decrypt(void *key, u_int8_t *blk)
    333   1.1   thorpej {
    334   1.1   thorpej }
    335   1.1   thorpej static int
    336   1.4  christos null_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    337   1.1   thorpej {
    338   1.1   thorpej 	*sched = NULL;
    339   1.1   thorpej 	return 0;
    340   1.1   thorpej }
    341   1.1   thorpej static void
    342   1.1   thorpej null_zerokey(u_int8_t **sched)
    343   1.1   thorpej {
    344   1.1   thorpej 	*sched = NULL;
    345   1.1   thorpej }
    346   1.1   thorpej 
    347   1.1   thorpej static void
    348   1.5  christos des1_encrypt(void *key, u_int8_t *blk)
    349   1.1   thorpej {
    350   1.1   thorpej 	des_cblock *cb = (des_cblock *) blk;
    351   1.1   thorpej 	des_key_schedule *p = (des_key_schedule *) key;
    352   1.1   thorpej 
    353   1.1   thorpej 	des_ecb_encrypt(cb, cb, p[0], DES_ENCRYPT);
    354   1.1   thorpej }
    355   1.1   thorpej 
    356   1.1   thorpej static void
    357   1.5  christos des1_decrypt(void *key, u_int8_t *blk)
    358   1.1   thorpej {
    359   1.1   thorpej 	des_cblock *cb = (des_cblock *) blk;
    360   1.1   thorpej 	des_key_schedule *p = (des_key_schedule *) key;
    361   1.1   thorpej 
    362   1.1   thorpej 	des_ecb_encrypt(cb, cb, p[0], DES_DECRYPT);
    363   1.1   thorpej }
    364   1.1   thorpej 
    365   1.1   thorpej static int
    366   1.4  christos des1_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    367   1.1   thorpej {
    368   1.1   thorpej 	des_key_schedule *p;
    369   1.1   thorpej 	int err;
    370   1.1   thorpej 
    371   1.9    cegger 	p = malloc(sizeof (des_key_schedule),
    372   1.8       tls 		M_CRYPTO_DATA, M_NOWAIT|M_ZERO);
    373   1.1   thorpej 	if (p != NULL) {
    374   1.1   thorpej 		des_set_key((des_cblock *)__UNCONST(key), p[0]);
    375   1.1   thorpej 		err = 0;
    376   1.1   thorpej 	} else
    377   1.1   thorpej 		err = ENOMEM;
    378   1.1   thorpej 	*sched = (u_int8_t *) p;
    379   1.1   thorpej 	return err;
    380   1.1   thorpej }
    381   1.1   thorpej 
    382   1.1   thorpej static void
    383   1.1   thorpej des1_zerokey(u_int8_t **sched)
    384   1.1   thorpej {
    385  1.11    cegger 	memset(*sched, 0, sizeof (des_key_schedule));
    386   1.9    cegger 	free(*sched, M_CRYPTO_DATA);
    387   1.1   thorpej 	*sched = NULL;
    388   1.1   thorpej }
    389   1.1   thorpej 
    390   1.1   thorpej static void
    391   1.5  christos des3_encrypt(void *key, u_int8_t *blk)
    392   1.1   thorpej {
    393   1.1   thorpej 	des_cblock *cb = (des_cblock *) blk;
    394   1.1   thorpej 	des_key_schedule *p = (des_key_schedule *) key;
    395   1.1   thorpej 
    396   1.1   thorpej 	des_ecb3_encrypt(cb, cb, p[0], p[1], p[2], DES_ENCRYPT);
    397   1.1   thorpej }
    398   1.1   thorpej 
    399   1.1   thorpej static void
    400   1.5  christos des3_decrypt(void *key, u_int8_t *blk)
    401   1.1   thorpej {
    402   1.1   thorpej 	des_cblock *cb = (des_cblock *) blk;
    403   1.1   thorpej 	des_key_schedule *p = (des_key_schedule *) key;
    404   1.1   thorpej 
    405   1.1   thorpej 	des_ecb3_encrypt(cb, cb, p[0], p[1], p[2], DES_DECRYPT);
    406   1.1   thorpej }
    407   1.1   thorpej 
    408   1.1   thorpej static int
    409   1.4  christos des3_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    410   1.1   thorpej {
    411   1.1   thorpej 	des_key_schedule *p;
    412   1.1   thorpej 	int err;
    413   1.1   thorpej 
    414   1.9    cegger 	p = malloc(3*sizeof (des_key_schedule),
    415   1.8       tls 		M_CRYPTO_DATA, M_NOWAIT|M_ZERO);
    416   1.1   thorpej 	if (p != NULL) {
    417   1.1   thorpej 		des_set_key((des_cblock *)__UNCONST(key +  0), p[0]);
    418   1.1   thorpej 		des_set_key((des_cblock *)__UNCONST(key +  8), p[1]);
    419   1.1   thorpej 		des_set_key((des_cblock *)__UNCONST(key + 16), p[2]);
    420   1.1   thorpej 		err = 0;
    421   1.1   thorpej 	} else
    422   1.1   thorpej 		err = ENOMEM;
    423   1.1   thorpej 	*sched = (u_int8_t *) p;
    424   1.1   thorpej 	return err;
    425   1.1   thorpej }
    426   1.1   thorpej 
    427   1.1   thorpej static void
    428   1.1   thorpej des3_zerokey(u_int8_t **sched)
    429   1.1   thorpej {
    430  1.11    cegger 	memset(*sched, 0, 3*sizeof (des_key_schedule));
    431   1.9    cegger 	free(*sched, M_CRYPTO_DATA);
    432   1.1   thorpej 	*sched = NULL;
    433   1.1   thorpej }
    434   1.1   thorpej 
    435   1.1   thorpej static void
    436   1.5  christos blf_encrypt(void *key, u_int8_t *blk)
    437   1.1   thorpej {
    438   1.1   thorpej 
    439   1.1   thorpej 	BF_ecb_encrypt(blk, blk, (BF_KEY *)key, 1);
    440   1.1   thorpej }
    441   1.1   thorpej 
    442   1.1   thorpej static void
    443   1.5  christos blf_decrypt(void *key, u_int8_t *blk)
    444   1.1   thorpej {
    445   1.1   thorpej 
    446   1.1   thorpej 	BF_ecb_encrypt(blk, blk, (BF_KEY *)key, 0);
    447   1.1   thorpej }
    448   1.1   thorpej 
    449   1.1   thorpej static int
    450   1.1   thorpej blf_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    451   1.1   thorpej {
    452   1.1   thorpej 	int err;
    453   1.1   thorpej 
    454   1.9    cegger 	*sched = malloc(sizeof(BF_KEY),
    455   1.8       tls 		M_CRYPTO_DATA, M_NOWAIT|M_ZERO);
    456   1.1   thorpej 	if (*sched != NULL) {
    457   1.1   thorpej 		BF_set_key((BF_KEY *) *sched, len, key);
    458   1.1   thorpej 		err = 0;
    459   1.1   thorpej 	} else
    460   1.1   thorpej 		err = ENOMEM;
    461   1.1   thorpej 	return err;
    462   1.1   thorpej }
    463   1.1   thorpej 
    464   1.1   thorpej static void
    465   1.1   thorpej blf_zerokey(u_int8_t **sched)
    466   1.1   thorpej {
    467  1.11    cegger 	memset(*sched, 0, sizeof(BF_KEY));
    468   1.9    cegger 	free(*sched, M_CRYPTO_DATA);
    469   1.1   thorpej 	*sched = NULL;
    470   1.1   thorpej }
    471   1.1   thorpej 
    472   1.1   thorpej static void
    473   1.5  christos cast5_encrypt(void *key, u_int8_t *blk)
    474   1.1   thorpej {
    475   1.1   thorpej 	cast128_encrypt((cast128_key *) key, blk, blk);
    476   1.1   thorpej }
    477   1.1   thorpej 
    478   1.1   thorpej static void
    479   1.5  christos cast5_decrypt(void *key, u_int8_t *blk)
    480   1.1   thorpej {
    481   1.1   thorpej 	cast128_decrypt((cast128_key *) key, blk, blk);
    482   1.1   thorpej }
    483   1.1   thorpej 
    484   1.1   thorpej static int
    485   1.1   thorpej cast5_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    486   1.1   thorpej {
    487   1.1   thorpej 	int err;
    488   1.1   thorpej 
    489   1.9    cegger 	*sched = malloc(sizeof(cast128_key), M_CRYPTO_DATA,
    490   1.8       tls 	       M_NOWAIT|M_ZERO);
    491   1.1   thorpej 	if (*sched != NULL) {
    492   1.1   thorpej 		cast128_setkey((cast128_key *)*sched, key, len);
    493   1.1   thorpej 		err = 0;
    494   1.1   thorpej 	} else
    495   1.1   thorpej 		err = ENOMEM;
    496   1.1   thorpej 	return err;
    497   1.1   thorpej }
    498   1.1   thorpej 
    499   1.1   thorpej static void
    500   1.1   thorpej cast5_zerokey(u_int8_t **sched)
    501   1.1   thorpej {
    502  1.11    cegger 	memset(*sched, 0, sizeof(cast128_key));
    503   1.9    cegger 	free(*sched, M_CRYPTO_DATA);
    504   1.1   thorpej 	*sched = NULL;
    505   1.1   thorpej }
    506   1.1   thorpej 
    507   1.1   thorpej static void
    508   1.5  christos skipjack_encrypt(void *key, u_int8_t *blk)
    509   1.1   thorpej {
    510   1.1   thorpej 	skipjack_forwards(blk, blk, (u_int8_t **) key);
    511   1.1   thorpej }
    512   1.1   thorpej 
    513   1.1   thorpej static void
    514   1.5  christos skipjack_decrypt(void *key, u_int8_t *blk)
    515   1.1   thorpej {
    516   1.1   thorpej 	skipjack_backwards(blk, blk, (u_int8_t **) key);
    517   1.1   thorpej }
    518   1.1   thorpej 
    519   1.1   thorpej static int
    520   1.4  christos skipjack_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    521   1.1   thorpej {
    522   1.1   thorpej 	int err;
    523   1.1   thorpej 
    524   1.1   thorpej 	/* NB: allocate all the memory that's needed at once */
    525   1.1   thorpej 	/* XXX assumes bytes are aligned on sizeof(u_char) == 1 boundaries.
    526   1.1   thorpej 	 * Will this break a pdp-10, Cray-1, or GE-645 port?
    527   1.1   thorpej 	 */
    528   1.9    cegger 	*sched = malloc(10 * (sizeof(u_int8_t *) + 0x100),
    529   1.8       tls 		M_CRYPTO_DATA, M_NOWAIT|M_ZERO);
    530   1.1   thorpej 
    531   1.1   thorpej 	if (*sched != NULL) {
    532   1.1   thorpej 
    533   1.1   thorpej 		u_int8_t** key_tables = (u_int8_t**) *sched;
    534   1.1   thorpej 		u_int8_t* table = (u_int8_t*) &key_tables[10];
    535   1.1   thorpej 		int k;
    536   1.1   thorpej 
    537   1.1   thorpej 		for (k = 0; k < 10; k++) {
    538   1.1   thorpej 			key_tables[k] = table;
    539   1.1   thorpej 			table += 0x100;
    540   1.1   thorpej 		}
    541   1.1   thorpej 		subkey_table_gen(key, (u_int8_t **) *sched);
    542   1.1   thorpej 		err = 0;
    543   1.1   thorpej 	} else
    544   1.1   thorpej 		err = ENOMEM;
    545   1.1   thorpej 	return err;
    546   1.1   thorpej }
    547   1.1   thorpej 
    548   1.1   thorpej static void
    549   1.1   thorpej skipjack_zerokey(u_int8_t **sched)
    550   1.1   thorpej {
    551  1.11    cegger 	memset(*sched, 0, 10 * (sizeof(u_int8_t *) + 0x100));
    552   1.9    cegger 	free(*sched, M_CRYPTO_DATA);
    553   1.1   thorpej 	*sched = NULL;
    554   1.1   thorpej }
    555   1.1   thorpej 
    556   1.1   thorpej static void
    557   1.5  christos rijndael128_encrypt(void *key, u_int8_t *blk)
    558   1.1   thorpej {
    559   1.1   thorpej 	rijndael_encrypt((rijndael_ctx *) key, (u_char *) blk, (u_char *) blk);
    560   1.1   thorpej }
    561   1.1   thorpej 
    562   1.1   thorpej static void
    563   1.5  christos rijndael128_decrypt(void *key, u_int8_t *blk)
    564   1.1   thorpej {
    565   1.1   thorpej 	rijndael_decrypt((rijndael_ctx *) key, (u_char *) blk,
    566   1.1   thorpej 	    (u_char *) blk);
    567   1.1   thorpej }
    568   1.1   thorpej 
    569   1.1   thorpej static int
    570   1.1   thorpej rijndael128_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    571   1.1   thorpej {
    572   1.1   thorpej 	int err;
    573   1.1   thorpej 
    574  1.16  drochner 	if (len != 16 && len != 24 && len != 32)
    575  1.16  drochner 		return EINVAL;
    576   1.9    cegger 	*sched = malloc(sizeof(rijndael_ctx), M_CRYPTO_DATA,
    577   1.8       tls 	    M_NOWAIT|M_ZERO);
    578   1.1   thorpej 	if (*sched != NULL) {
    579   1.1   thorpej 		rijndael_set_key((rijndael_ctx *) *sched, key, len * 8);
    580   1.1   thorpej 		err = 0;
    581   1.1   thorpej 	} else
    582   1.1   thorpej 		err = ENOMEM;
    583   1.1   thorpej 	return err;
    584   1.1   thorpej }
    585   1.1   thorpej 
    586   1.1   thorpej static void
    587   1.1   thorpej rijndael128_zerokey(u_int8_t **sched)
    588   1.1   thorpej {
    589  1.11    cegger 	memset(*sched, 0, sizeof(rijndael_ctx));
    590   1.9    cegger 	free(*sched, M_CRYPTO_DATA);
    591   1.1   thorpej 	*sched = NULL;
    592   1.1   thorpej }
    593   1.1   thorpej 
    594  1.15  drochner static void
    595  1.15  drochner cml_encrypt(void *key, u_int8_t *blk)
    596  1.15  drochner {
    597  1.15  drochner 
    598  1.15  drochner 	camellia_encrypt(key, blk, blk);
    599  1.15  drochner }
    600  1.15  drochner 
    601  1.15  drochner static void
    602  1.15  drochner cml_decrypt(void *key, u_int8_t *blk)
    603  1.15  drochner {
    604  1.15  drochner 
    605  1.15  drochner 	camellia_decrypt(key, blk, blk);
    606  1.15  drochner }
    607  1.15  drochner 
    608  1.15  drochner static int
    609  1.15  drochner cml_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    610  1.15  drochner {
    611  1.15  drochner 	int err;
    612  1.15  drochner 
    613  1.15  drochner 	if (len != 16 && len != 24 && len != 32)
    614  1.15  drochner 		return (EINVAL);
    615  1.15  drochner 	*sched = malloc(sizeof(camellia_ctx), M_CRYPTO_DATA,
    616  1.15  drochner 			M_NOWAIT|M_ZERO);
    617  1.15  drochner 	if (*sched != NULL) {
    618  1.15  drochner 		camellia_set_key((camellia_ctx *) *sched, key, len * 8);
    619  1.15  drochner 		err = 0;
    620  1.15  drochner 	} else
    621  1.15  drochner 		err = ENOMEM;
    622  1.15  drochner 	return err;
    623  1.15  drochner }
    624  1.15  drochner 
    625  1.15  drochner static void
    626  1.15  drochner cml_zerokey(u_int8_t **sched)
    627  1.15  drochner {
    628  1.15  drochner 
    629  1.15  drochner 	memset(*sched, 0, sizeof(camellia_ctx));
    630  1.15  drochner 	free(*sched, M_CRYPTO_DATA);
    631  1.15  drochner 	*sched = NULL;
    632  1.15  drochner }
    633  1.15  drochner 
    634  1.18  drochner #define AESCTR_NONCESIZE	4
    635  1.18  drochner #define AESCTR_IVSIZE		8
    636  1.18  drochner #define AESCTR_BLOCKSIZE	16
    637  1.18  drochner 
    638  1.18  drochner struct aes_ctr_ctx {
    639  1.18  drochner 	/* need only encryption half */
    640  1.18  drochner 	u_int32_t ac_ek[4*(RIJNDAEL_MAXNR + 1)];
    641  1.18  drochner 	u_int8_t ac_block[AESCTR_BLOCKSIZE];
    642  1.18  drochner 	int ac_nr;
    643  1.20  drochner 	struct {
    644  1.20  drochner 		u_int64_t lastiv;
    645  1.20  drochner 	} ivgenctx;
    646  1.18  drochner };
    647  1.18  drochner 
    648  1.18  drochner static void
    649  1.18  drochner aes_ctr_crypt(void *key, u_int8_t *blk)
    650  1.18  drochner {
    651  1.18  drochner 	struct aes_ctr_ctx *ctx;
    652  1.18  drochner 	u_int8_t keystream[AESCTR_BLOCKSIZE];
    653  1.18  drochner 	int i;
    654  1.18  drochner 
    655  1.18  drochner 	ctx = key;
    656  1.18  drochner 	/* increment counter */
    657  1.18  drochner 	for (i = AESCTR_BLOCKSIZE - 1;
    658  1.18  drochner 	     i >= AESCTR_NONCESIZE + AESCTR_IVSIZE; i--)
    659  1.18  drochner 		if (++ctx->ac_block[i]) /* continue on overflow */
    660  1.18  drochner 			break;
    661  1.18  drochner 	rijndaelEncrypt(ctx->ac_ek, ctx->ac_nr, ctx->ac_block, keystream);
    662  1.18  drochner 	for (i = 0; i < AESCTR_BLOCKSIZE; i++)
    663  1.18  drochner 		blk[i] ^= keystream[i];
    664  1.18  drochner 	memset(keystream, 0, sizeof(keystream));
    665  1.18  drochner }
    666  1.18  drochner 
    667  1.18  drochner int
    668  1.18  drochner aes_ctr_setkey(u_int8_t **sched, const u_int8_t *key, int len)
    669  1.18  drochner {
    670  1.18  drochner 	struct aes_ctr_ctx *ctx;
    671  1.18  drochner 
    672  1.18  drochner 	if (len < AESCTR_NONCESIZE)
    673  1.18  drochner 		return EINVAL;
    674  1.18  drochner 
    675  1.18  drochner 	ctx = malloc(sizeof(struct aes_ctr_ctx), M_CRYPTO_DATA,
    676  1.18  drochner 		     M_NOWAIT|M_ZERO);
    677  1.18  drochner 	if (!ctx)
    678  1.18  drochner 		return ENOMEM;
    679  1.18  drochner 	ctx->ac_nr = rijndaelKeySetupEnc(ctx->ac_ek, (const u_char *)key,
    680  1.18  drochner 			(len - AESCTR_NONCESIZE) * 8);
    681  1.18  drochner 	if (!ctx->ac_nr) { /* wrong key len */
    682  1.18  drochner 		aes_ctr_zerokey((u_int8_t **)&ctx);
    683  1.18  drochner 		return EINVAL;
    684  1.18  drochner 	}
    685  1.18  drochner 	memcpy(ctx->ac_block, key + len - AESCTR_NONCESIZE, AESCTR_NONCESIZE);
    686  1.20  drochner 	/* random start value for simple counter */
    687  1.20  drochner 	arc4randbytes(&ctx->ivgenctx.lastiv, sizeof(ctx->ivgenctx.lastiv));
    688  1.18  drochner 	*sched = (void *)ctx;
    689  1.18  drochner 	return 0;
    690  1.18  drochner }
    691  1.18  drochner 
    692  1.18  drochner void
    693  1.18  drochner aes_ctr_zerokey(u_int8_t **sched)
    694  1.18  drochner {
    695  1.18  drochner 
    696  1.18  drochner 	memset(*sched, 0, sizeof(struct aes_ctr_ctx));
    697  1.18  drochner 	free(*sched, M_CRYPTO_DATA);
    698  1.18  drochner 	*sched = NULL;
    699  1.18  drochner }
    700  1.18  drochner 
    701  1.18  drochner void
    702  1.20  drochner aes_ctr_reinit(void *key, const u_int8_t *iv, u_int8_t *ivout)
    703  1.18  drochner {
    704  1.18  drochner 	struct aes_ctr_ctx *ctx = key;
    705  1.18  drochner 
    706  1.20  drochner 	if (!iv) {
    707  1.20  drochner 		ctx->ivgenctx.lastiv++;
    708  1.20  drochner 		iv = (const u_int8_t *)&ctx->ivgenctx.lastiv;
    709  1.20  drochner 	}
    710  1.20  drochner 	if (ivout)
    711  1.20  drochner 		memcpy(ivout, iv, AESCTR_IVSIZE);
    712  1.18  drochner 	memcpy(ctx->ac_block + AESCTR_NONCESIZE, iv, AESCTR_IVSIZE);
    713  1.18  drochner 	/* reset counter */
    714  1.18  drochner 	memset(ctx->ac_block + AESCTR_NONCESIZE + AESCTR_IVSIZE, 0, 4);
    715  1.18  drochner }
    716  1.18  drochner 
    717   1.1   thorpej /*
    718   1.1   thorpej  * And now for auth.
    719   1.1   thorpej  */
    720   1.1   thorpej 
    721   1.1   thorpej static void
    722   1.4  christos null_init(void *ctx)
    723   1.1   thorpej {
    724   1.1   thorpej }
    725   1.1   thorpej 
    726   1.1   thorpej static int
    727   1.4  christos null_update(void *ctx, const u_int8_t *buf,
    728   1.4  christos     u_int16_t len)
    729   1.1   thorpej {
    730   1.1   thorpej 	return 0;
    731   1.1   thorpej }
    732   1.1   thorpej 
    733   1.1   thorpej static void
    734   1.4  christos null_final(u_int8_t *buf, void *ctx)
    735   1.1   thorpej {
    736   1.1   thorpej 	if (buf != (u_int8_t *) 0)
    737  1.11    cegger 		memset(buf, 0, 12);
    738   1.1   thorpej }
    739   1.1   thorpej 
    740   1.1   thorpej static int
    741   1.1   thorpej RMD160Update_int(void *ctx, const u_int8_t *buf, u_int16_t len)
    742   1.1   thorpej {
    743   1.1   thorpej 	RMD160Update(ctx, buf, len);
    744   1.1   thorpej 	return 0;
    745   1.1   thorpej }
    746   1.1   thorpej 
    747   1.1   thorpej static int
    748   1.1   thorpej MD5Update_int(void *ctx, const u_int8_t *buf, u_int16_t len)
    749   1.1   thorpej {
    750   1.1   thorpej 	MD5Update(ctx, buf, len);
    751   1.1   thorpej 	return 0;
    752   1.1   thorpej }
    753   1.1   thorpej 
    754   1.1   thorpej static void
    755   1.1   thorpej SHA1Init_int(void *ctx)
    756   1.1   thorpej {
    757   1.1   thorpej 	SHA1Init(ctx);
    758   1.1   thorpej }
    759   1.1   thorpej 
    760   1.1   thorpej static int
    761   1.1   thorpej SHA1Update_int(void *ctx, const u_int8_t *buf, u_int16_t len)
    762   1.1   thorpej {
    763   1.1   thorpej 	SHA1Update(ctx, buf, len);
    764   1.1   thorpej 	return 0;
    765   1.1   thorpej }
    766   1.1   thorpej 
    767   1.1   thorpej static void
    768   1.1   thorpej SHA1Final_int(u_int8_t *blk, void *ctx)
    769   1.1   thorpej {
    770   1.1   thorpej 	SHA1Final(blk, ctx);
    771   1.1   thorpej }
    772   1.1   thorpej 
    773   1.1   thorpej static int
    774   1.1   thorpej SHA256Update_int(void *ctx, const u_int8_t *buf, u_int16_t len)
    775   1.1   thorpej {
    776   1.1   thorpej 	SHA256_Update(ctx, buf, len);
    777   1.1   thorpej 	return 0;
    778   1.1   thorpej }
    779   1.1   thorpej 
    780   1.1   thorpej static int
    781   1.1   thorpej SHA384Update_int(void *ctx, const u_int8_t *buf, u_int16_t len)
    782   1.1   thorpej {
    783   1.1   thorpej 	SHA384_Update(ctx, buf, len);
    784   1.1   thorpej 	return 0;
    785   1.1   thorpej }
    786   1.1   thorpej 
    787   1.1   thorpej static int
    788   1.1   thorpej SHA512Update_int(void *ctx, const u_int8_t *buf, u_int16_t len)
    789   1.1   thorpej {
    790   1.1   thorpej 	SHA512_Update(ctx, buf, len);
    791   1.1   thorpej 	return 0;
    792   1.1   thorpej }
    793   1.1   thorpej 
    794   1.1   thorpej /*
    795   1.1   thorpej  * And compression
    796   1.1   thorpej  */
    797   1.1   thorpej 
    798   1.1   thorpej static u_int32_t
    799  1.10       dsl deflate_compress(u_int8_t *data, u_int32_t size, u_int8_t **out)
    800   1.1   thorpej {
    801  1.14  drochner 	return deflate_global(data, size, 0, out, 0);
    802   1.1   thorpej }
    803   1.1   thorpej 
    804   1.1   thorpej static u_int32_t
    805  1.14  drochner deflate_decompress(u_int8_t *data, u_int32_t size, u_int8_t **out,
    806  1.14  drochner 		   int size_hint)
    807   1.1   thorpej {
    808  1.14  drochner 	return deflate_global(data, size, 1, out, size_hint);
    809   1.1   thorpej }
    810  1.12    darran 
    811  1.12    darran static u_int32_t
    812  1.12    darran gzip_compress(u_int8_t *data, u_int32_t size, u_int8_t **out)
    813  1.12    darran {
    814  1.14  drochner 	return gzip_global(data, size, 0, out, 0);
    815  1.12    darran }
    816  1.12    darran 
    817  1.12    darran static u_int32_t
    818  1.14  drochner gzip_decompress(u_int8_t *data, u_int32_t size, u_int8_t **out,
    819  1.14  drochner 		int size_hint)
    820  1.12    darran {
    821  1.14  drochner 	return gzip_global(data, size, 1, out, size_hint);
    822  1.12    darran }
    823