1 /* threefish256_enc.c */
3 This file is part of the ARM-Crypto-Lib.
4 Copyright (C) 2006-2010 Daniel Otte (daniel.otte@rub.de)
6 This program is free software: you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation, either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 * \email daniel.otte@rub.de
23 * \license GPLv3 or later
31 #include "threefish.h"
33 #define X(a) (((uint64_t*)data)[(a)])
35 void permute_4(void* data){
42 //#define THREEFISH_KEY_CONST 0x5555555555555555LL /* 2**64/3 */
43 #define THREEFISH_KEY_CONST 0x1BD11BDAA9FC1A22LL
45 #define K(s) (((uint64_t*)key)[(s)])
46 #define T(s) (((uint64_t*)tweak)[(s)])
48 void threefish256_init(const void* key, const void* tweak, threefish256_ctx_t* ctx){
49 memcpy(ctx->k, key, 4*8);
51 memcpy(ctx->t, tweak, 2*8);
52 ctx->t[2] = T(0) ^ T(1);
54 memset(ctx->t, 0, 3*8);
57 ctx->k[4] = THREEFISH_KEY_CONST;
64 void add_key_4(void* data, const threefish256_ctx_t* ctx, uint8_t s){
65 X(0) += ctx->k[(s+0)%5];
66 X(1) += ctx->k[(s+1)%5] + ctx->t[s%3];
67 X(2) += ctx->k[(s+2)%5] + ctx->t[(s+1)%3];
68 X(3) += ctx->k[(s+3)%5] + s;
71 void threefish256_enc(void* data, const threefish256_ctx_t* ctx){
73 /* old constans, changed at round 2 of the SHA-3 contest
74 uint8_t r0[8] = { 5, 36, 13, 58, 26, 53, 11, 59};
75 uint8_t r1[8] = {56, 28, 46, 44, 20, 35, 42, 50};
77 uint8_t r0[8] = {14, 52, 23, 5, 25, 46, 58, 32};
78 uint8_t r1[8] = {16, 57, 40, 37, 33, 12, 22, 32};
81 add_key_4(data, ctx, s);
84 threefish_mix(data, r0[i%8]);
85 threefish_mix((uint8_t*)data + 16, r1[i%8]);
89 add_key_4(data, ctx, s);