ReactOS 0.4.17-dev-1005-g171e1de
aes-key.c File Reference
#include "precomp.h"
Include dependency graph for aes-key.c:

Go to the source code of this file.

Functions

SYMCRYPT_NOINLINE SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKeyInternal (_Out_ PSYMCRYPT_AES_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey, BOOLEAN fCreateDecryptionKeys)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKey (_Out_ PSYMCRYPT_AES_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKeyEncryptOnly (_Out_ PSYMCRYPT_AES_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
 
VOID SYMCRYPT_CALL SymCryptAesKeyCopy (_In_ PCSYMCRYPT_AES_EXPANDED_KEY pSrc, _Out_ PSYMCRYPT_AES_EXPANDED_KEY pDst)
 

Variables

static BYTE g_SymCryptAesRoundConstant [11]
 
const BYTE SymCryptAesNistTestVector128Ciphertext [16]
 

Function Documentation

◆ SymCryptAesExpandKey()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKey ( _Out_ PSYMCRYPT_AES_EXPANDED_KEY  pExpandedKey,
_In_reads_(cbKey) PCBYTE  pbKey,
SIZE_T  cbKey 
)

Definition at line 219 of file aes-key.c.

224{
226}
SYMCRYPT_NOINLINE SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKeyInternal(_Out_ PSYMCRYPT_AES_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey, BOOLEAN fCreateDecryptionKeys)
Definition: aes-key.c:35
#define TRUE
Definition: types.h:120
PCBYTE pbKey
PCBYTE SIZE_T cbKey
PCVOID pExpandedKey

Referenced by setup_key_impl(), SymCryptAesCmacExpandKey(), SymCryptCcmSelftest(), and SymCryptXtsAesExpandKey().

◆ SymCryptAesExpandKeyEncryptOnly()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKeyEncryptOnly ( _Out_ PSYMCRYPT_AES_EXPANDED_KEY  pExpandedKey,
_In_reads_(cbKey) PCBYTE  pbKey,
SIZE_T  cbKey 
)

◆ SymCryptAesExpandKeyInternal()

SYMCRYPT_NOINLINE SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKeyInternal ( _Out_ PSYMCRYPT_AES_EXPANDED_KEY  pExpandedKey,
_In_reads_(cbKey) PCBYTE  pbKey,
SIZE_T  cbKey,
BOOLEAN  fCreateDecryptionKeys 
)

Definition at line 35 of file aes-key.c.

40{
41 UINT32 nRounds;
42 BYTE * p;
43 BYTE * q;
44 UINT32 i;
45 UINT32 t;
46
47 BOOL UseSimd = FALSE;
48 SYMCRYPT_ERROR status = SYMCRYPT_NO_ERROR;
49
50#if SYMCRYPT_CPU_X86
51 SYMCRYPT_EXTENDED_SAVE_DATA SaveData;
52
54 {
55 if( SymCryptSaveXmm( &SaveData ) == SYMCRYPT_NO_ERROR )
56 {
57 UseSimd = TRUE;
58 }
59 }
60#elif SYMCRYPT_CPU_AMD64
62 {
63 UseSimd = TRUE;
64 }
65#elif SYMCRYPT_CPU_ARM64
66 if( SYMCRYPT_CPU_FEATURES_PRESENT( SYMCRYPT_CPU_FEATURE_NEON_AES ) )
67 {
68 UseSimd = TRUE;
69 }
70#endif
71
73
74 //
75 // Separate code for each key size, this is significantly faster.
76 // We have a number of applications that do frequent key expansions.
77 //
78 switch( cbKey )
79 {
80 case 16:
81 nRounds = 10;
82 pExpandedKey->lastEncRoundKey = &pExpandedKey->RoundKey[nRounds];
83 pExpandedKey->lastDecRoundKey = &pExpandedKey->RoundKey[2*nRounds];
84
85 memcpy( &pExpandedKey->RoundKey[0], pbKey, 16 );
86
87 p = (BYTE *)&pExpandedKey->RoundKey[1];
88
89 for( i=1; i<=nRounds; i++ )
90 {
91 SymCryptAes4Sbox( &p[-4], p, UseSimd );
93 SYMCRYPT_STORE_LSBFIRST32( p, t ); // this is a macro that re-evaluates its arguments
94
95 *(UINT32 *)(p+4) = *(UINT32 *) p ^ *(UINT32 *)(p - 12);
96 *(UINT32 *)(p+8) = *(UINT32 *)(p+4) ^ *(UINT32 *)(p - 8);
97 *(UINT32 *)(p+12) = *(UINT32 *)(p+8) ^ *(UINT32 *)(p - 4);
98
99 p += 16;
100 }
101
102 break;
103
104 case 24:
105 nRounds = 12;
106 pExpandedKey->lastEncRoundKey = &pExpandedKey->RoundKey[nRounds];
107 pExpandedKey->lastDecRoundKey = &pExpandedKey->RoundKey[2*nRounds];
108
109 memcpy( &pExpandedKey->RoundKey[0], pbKey, 24 );
110
111 p = (BYTE *)&pExpandedKey->RoundKey[0] + 24;
112
113 //
114 // We have 12 rounds, 13 round keys, and 13*16 = 208 bytes of encryption key to generate.
115 // We have 24 already, so we need 184 more.
116 // Each iteration produces 24 bytes, so we need to loop 8 times.
117 //
118 for( i=1; i<=8; i++ )
119 {
120 SymCryptAes4Sbox( &p[-4], p, UseSimd );
123
124 *(UINT32 *)(p+4) = *(UINT32 *) p ^ *(UINT32 *)(p - 20);
125 *(UINT32 *)(p+8) = *(UINT32 *)(p+ 4) ^ *(UINT32 *)(p - 16);
126 *(UINT32 *)(p+12) = *(UINT32 *)(p+ 8) ^ *(UINT32 *)(p - 12);
127 *(UINT32 *)(p+16) = *(UINT32 *)(p+12) ^ *(UINT32 *)(p - 8);
128 *(UINT32 *)(p+20) = *(UINT32 *)(p+16) ^ *(UINT32 *)(p - 4);
129
130 p += 24;
131 }
132
133 break;
134
135 case 32:
136 nRounds = 14;
137 pExpandedKey->lastEncRoundKey = &pExpandedKey->RoundKey[nRounds];
138 pExpandedKey->lastDecRoundKey = &pExpandedKey->RoundKey[2*nRounds];
139
140 memcpy( &pExpandedKey->RoundKey[0], pbKey, 32 );
141
142 p = (BYTE *)&pExpandedKey->RoundKey[0] + 32;
143
144 //
145 // We have 14 rounds, 15 round keys, and 15*16 = 240 bytes of encryption key to generate.
146 // We have 32 already, so we need 208 more.
147 // Each iteration produces 32 bytes, so we need to loop 6.5 times.
148 //
149 for( i=1; i<=6; i++ )
150 {
151 SymCryptAes4Sbox( &p[-4], p, UseSimd );
154
155 *(UINT32 *)(p+4) = *(UINT32 *) p ^ *(UINT32 *)(p - 28);
156 *(UINT32 *)(p+8) = *(UINT32 *)(p + 4) ^ *(UINT32 *)(p - 24);
157 *(UINT32 *)(p+12) = *(UINT32 *)(p + 8) ^ *(UINT32 *)(p - 20);
158
159 SymCryptAes4Sbox( &p[12], &p[16], UseSimd );
160 *(UINT32 *)(p+16) = *(UINT32 *)(p + 16) ^ *(UINT32 *)(p - 16);
161
162 *(UINT32 *)(p+20) = *(UINT32 *)(p + 16) ^ *(UINT32 *)(p - 12);
163 *(UINT32 *)(p+24) = *(UINT32 *)(p + 20) ^ *(UINT32 *)(p - 8);
164 *(UINT32 *)(p+28) = *(UINT32 *)(p + 24) ^ *(UINT32 *)(p - 4);
165
166 p += 32;
167 }
168
169 // We looped 6 times, so here is the half-loop
170
171 SymCryptAes4Sbox( &p[-4], p, UseSimd );
174
175 *(UINT32 *)(p+4) = *(UINT32 *) p ^ *(UINT32 *)(p - 28);
176 *(UINT32 *)(p+8) = *(UINT32 *)(p + 4) ^ *(UINT32 *)(p - 24);
177 *(UINT32 *)(p+12) = *(UINT32 *)(p + 8) ^ *(UINT32 *)(p - 20);
178
179 break;
180
181 default:
182 status = SYMCRYPT_WRONG_KEY_SIZE;
183 goto cleanup;
184 }
185
186
187 if( fCreateDecryptionKeys )
188 {
189 p = &pExpandedKey->RoundKey[0][0][0];
190 q = (PBYTE)(pExpandedKey->lastDecRoundKey);
191
192 // The first encryption round key is the last decryption round key
194 p += 16;
195 q -= 16;
196
197 while( p < (PBYTE) pExpandedKey->lastEncRoundKey )
198 {
200 q -= 16;
201 p += 16;
202 }
203 }
204
205cleanup:
206
207#if SYMCRYPT_CPU_X86
208 if( UseSimd )
209 {
210 SymCryptRestoreXmm( &SaveData );
211 }
212#endif
213
214 return status;
215}
VOID SYMCRYPT_CALL SymCryptAesCreateDecryptionRoundKey(_In_reads_(16) PCBYTE pEncryptionRoundKey, _Out_writes_(16) PBYTE pDecryptionRoundKey, BOOL UseSimd)
Definition: aes-default.c:68
VOID SYMCRYPT_CALL SymCryptAes4Sbox(_In_reads_(4) PCBYTE pIn, _Out_writes_(4) PBYTE pOut, BOOL UseSimd)
Definition: aes-default.c:44
static BYTE g_SymCryptAesRoundConstant[11]
Definition: aes-key.c:27
VOID SaveData(HWND hwndDlg)
Definition: volume.c:368
static void cleanup(void)
Definition: main.c:1335
unsigned int BOOL
Definition: ntddk_ex.h:94
GLdouble GLdouble t
Definition: gl.h:2047
GLdouble GLdouble GLdouble GLdouble q
Definition: gl.h:2063
GLfloat GLfloat p
Definition: glext.h:8902
GLsizei GLenum const GLvoid GLsizei GLenum GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLint GLint GLint GLshort GLshort GLshort GLubyte GLubyte GLubyte GLuint GLuint GLuint GLushort GLushort GLushort GLbyte GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLfloat GLint GLint GLint GLint GLshort GLshort GLshort GLshort GLubyte GLubyte GLubyte GLubyte GLuint GLuint GLuint GLuint GLushort GLushort GLushort GLushort GLboolean const GLdouble const GLfloat const GLint const GLshort const GLbyte const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLdouble const GLfloat const GLfloat const GLint const GLint const GLshort const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort GLenum GLenum GLenum GLfloat GLenum GLint GLenum GLenum GLenum GLfloat GLenum GLenum GLint GLenum GLfloat GLenum GLint GLint GLushort GLenum GLenum GLfloat GLenum GLenum GLint GLfloat const GLubyte GLenum GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLint GLint GLsizei GLsizei GLint GLenum GLenum const GLvoid GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLenum const GLdouble GLenum GLenum const GLfloat GLenum GLenum const GLint GLsizei GLuint GLfloat GLuint GLbitfield GLfloat GLint GLuint GLboolean GLenum GLfloat GLenum GLbitfield GLenum GLfloat GLfloat GLint GLint const GLfloat GLenum GLfloat GLfloat GLint GLint GLfloat GLfloat GLint GLint const GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat const GLdouble const GLfloat const GLdouble const GLfloat GLint i
Definition: glfuncs.h:248
#define memcpy(s1, s2, n)
Definition: mkisofs.h:878
BYTE * PBYTE
Definition: pedump.c:66
#define SYMCRYPT_CPU_FEATURES_FOR_AESNI_CODE
Definition: sc_lib.h:307
Definition: ps.c:97
#define SYMCRYPT_LOAD_LSBFIRST32(p)
Definition: symcrypt.h:299
#define SYMCRYPT_AES_BLOCK_SIZE
Definition: symcrypt.h:4255
#define SYMCRYPT_STORE_LSBFIRST32(p, v)
Definition: symcrypt.h:307
SYMCRYPT_ERROR
Definition: symcrypt.h:227
#define SYMCRYPT_CPU_FEATURES_PRESENT(x)
#define SYMCRYPT_SET_MAGIC(p)
uint32_t UINT32
Definition: typedefs.h:59
unsigned char BYTE
Definition: xxhash.c:193

Referenced by SymCryptAesExpandKey(), and SymCryptAesExpandKeyEncryptOnly().

◆ SymCryptAesKeyCopy()

Definition at line 240 of file aes-key.c.

242{
243 SYMCRYPT_CHECK_MAGIC( pSrc );
244
245 *pDst = *pSrc;
246 pDst->lastEncRoundKey = &pDst->RoundKey[0] + (pSrc->lastEncRoundKey - &pSrc->RoundKey[0]);
247 pDst->lastDecRoundKey = &pDst->RoundKey[0] + (pSrc->lastDecRoundKey - &pSrc->RoundKey[0]);
248
249 SYMCRYPT_SET_MAGIC( pDst );
250}
#define SYMCRYPT_CHECK_MAGIC(p)

Referenced by duplicate_key_impl(), SymCryptAesCmacKeyCopy(), and SymCryptXtsAesKeyCopy().

Variable Documentation

◆ g_SymCryptAesRoundConstant

BYTE g_SymCryptAesRoundConstant[11]
static
Initial value:
=
{
0, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36,
}

Definition at line 27 of file aes-key.c.

Referenced by SymCryptAesExpandKeyInternal().

◆ SymCryptAesNistTestVector128Ciphertext

const BYTE SymCryptAesNistTestVector128Ciphertext[16]
Initial value:
= {
0x69, 0xc4, 0xe0, 0xd8, 0x6a, 0x7b, 0x04, 0x30,
0xd8, 0xcd, 0xb7, 0x80, 0x70, 0xb4, 0xc5, 0x5a,
}

Definition at line 257 of file aes-key.c.