Blame src/lib/crypto/builtin/des/t_verify.c

Packit Service a81408
/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
Packit Service a81408
/* lib/crypto/builtin/des/t_verify.c */
Packit Service a81408
/*
Packit Service a81408
 * Copyright 1988, 1990 by the Massachusetts Institute of Technology.
Packit Service a81408
 * All Rights Reserved.
Packit Service a81408
 *
Packit Service a81408
 * Export of this software from the United States of America may
Packit Service a81408
 *   require a specific license from the United States Government.
Packit Service a81408
 *   It is the responsibility of any person or organization contemplating
Packit Service a81408
 *   export to obtain such a license before exporting.
Packit Service a81408
 *
Packit Service a81408
 * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
Packit Service a81408
 * distribute this software and its documentation for any purpose and
Packit Service a81408
 * without fee is hereby granted, provided that the above copyright
Packit Service a81408
 * notice appear in all copies and that both that copyright notice and
Packit Service a81408
 * this permission notice appear in supporting documentation, and that
Packit Service a81408
 * the name of M.I.T. not be used in advertising or publicity pertaining
Packit Service a81408
 * to distribution of the software without specific, written prior
Packit Service a81408
 * permission.  Furthermore if you modify this software you must label
Packit Service a81408
 * your software as modified software and not distribute it in such a
Packit Service a81408
 * fashion that it might be confused with the original M.I.T. software.
Packit Service a81408
 * M.I.T. makes no representations about the suitability of
Packit Service a81408
 * this software for any purpose.  It is provided "as is" without express
Packit Service a81408
 * or implied warranty.
Packit Service a81408
 */
Packit Service a81408
/*
Packit Service a81408
 * Copyright (C) 1998 by the FundsXpress, INC.
Packit Service a81408
 *
Packit Service a81408
 * All rights reserved.
Packit Service a81408
 *
Packit Service a81408
 * Export of this software from the United States of America may require
Packit Service a81408
 * a specific license from the United States Government.  It is the
Packit Service a81408
 * responsibility of any person or organization contemplating export to
Packit Service a81408
 * obtain such a license before exporting.
Packit Service a81408
 *
Packit Service a81408
 * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
Packit Service a81408
 * distribute this software and its documentation for any purpose and
Packit Service a81408
 * without fee is hereby granted, provided that the above copyright
Packit Service a81408
 * notice appear in all copies and that both that copyright notice and
Packit Service a81408
 * this permission notice appear in supporting documentation, and that
Packit Service a81408
 * the name of FundsXpress. not be used in advertising or publicity pertaining
Packit Service a81408
 * to distribution of the software without specific, written prior
Packit Service a81408
 * permission.  FundsXpress makes no representations about the suitability of
Packit Service a81408
 * this software for any purpose.  It is provided "as is" without express
Packit Service a81408
 * or implied warranty.
Packit Service a81408
 *
Packit Service a81408
 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR
Packit Service a81408
 * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
Packit Service a81408
 * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
Packit Service a81408
 */
Packit Service a81408
Packit Service a81408
/*
Packit Service a81408
 *
Packit Service a81408
 * Program to test the correctness of the DES library
Packit Service a81408
 * implementation.
Packit Service a81408
 *
Packit Service a81408
 * exit returns  0 ==> success
Packit Service a81408
 *              -1 ==> error
Packit Service a81408
 */
Packit Service a81408
Packit Service a81408
#include "k5-int.h"
Packit Service a81408
#include "des_int.h"
Packit Service a81408
#include <stdio.h>
Packit Service a81408
#include "com_err.h"
Packit Service a81408
Packit Service a81408
static void do_encrypt(unsigned char *, unsigned char *);
Packit Service a81408
static void do_decrypt(unsigned char *, unsigned char *);
Packit Service a81408
Packit Service a81408
char *progname;
Packit Service a81408
int nflag = 2;
Packit Service a81408
int vflag;
Packit Service a81408
int mflag;
Packit Service a81408
int zflag;
Packit Service a81408
int pid;
Packit Service a81408
int mit_des_debug;
Packit Service a81408
Packit Service a81408
unsigned char cipher_text[64];
Packit Service a81408
unsigned char clear_text[64] = "Now is the time for all " ;
Packit Service a81408
unsigned char clear_text2[64] = "7654321 Now is the time for ";
Packit Service a81408
unsigned char clear_text3[64] = {2,0,0,0, 1,0,0,0};
Packit Service a81408
unsigned char output[64];
Packit Service a81408
unsigned char zero_text[8] = {0x0,0,0,0,0,0,0,0};
Packit Service a81408
unsigned char msb_text[8] = {0x0,0,0,0, 0,0,0,0x40}; /* to ANSI MSB */
Packit Service a81408
unsigned char *input;
Packit Service a81408
Packit Service a81408
/* 0x0123456789abcdef */
Packit Service a81408
unsigned char default_key[8] = {
Packit Service a81408
    0x01,0x23,0x45,0x67,0x89,0xab,0xcd,0xef
Packit Service a81408
};
Packit Service a81408
unsigned char key2[8] = { 0x08,0x19,0x2a,0x3b,0x4c,0x5d,0x6e,0x7f };
Packit Service a81408
unsigned char key3[8] = { 0x80,1,1,1,1,1,1,1 };
Packit Service a81408
mit_des_cblock s_key;
Packit Service a81408
unsigned char default_ivec[8] = {
Packit Service a81408
    0x12,0x34,0x56,0x78,0x90,0xab,0xcd,0xef
Packit Service a81408
};
Packit Service a81408
unsigned char *ivec;
Packit Service a81408
unsigned char zero_key[8] = {1,1,1,1,1,1,1,1}; /* just parity bits */
Packit Service a81408
Packit Service a81408
unsigned char cipher1[8] = {
Packit Service a81408
    0x25,0xdd,0xac,0x3e,0x96,0x17,0x64,0x67
Packit Service a81408
};
Packit Service a81408
unsigned char cipher2[8] = {
Packit Service a81408
    0x3f,0xa4,0x0e,0x8a,0x98,0x4d,0x48,0x15
Packit Service a81408
};
Packit Service a81408
unsigned char cipher3[64] = {
Packit Service a81408
    0xe5,0xc7,0xcd,0xde,0x87,0x2b,0xf2,0x7c,
Packit Service a81408
    0x43,0xe9,0x34,0x00,0x8c,0x38,0x9c,0x0f,
Packit Service a81408
    0x68,0x37,0x88,0x49,0x9a,0x7c,0x05,0xf6
Packit Service a81408
};
Packit Service a81408
unsigned char checksum[8] = {
Packit Service a81408
    0x58,0xd2,0xe7,0x7e,0x86,0x06,0x27,0x33
Packit Service a81408
};
Packit Service a81408
Packit Service a81408
unsigned char zresult[8] = {
Packit Service a81408
    0x8c, 0xa6, 0x4d, 0xe9, 0xc1, 0xb1, 0x23, 0xa7
Packit Service a81408
};
Packit Service a81408
Packit Service a81408
unsigned char mresult[8] = {
Packit Service a81408
    0xa3, 0x80, 0xe0, 0x2a, 0x6b, 0xe5, 0x46, 0x96
Packit Service a81408
};
Packit Service a81408
Packit Service a81408
Packit Service a81408
/*
Packit Service a81408
 * Can also add :
Packit Service a81408
 * plaintext = 0, key = 0, cipher = 0x8ca64de9c1b123a7 (or is it a 1?)
Packit Service a81408
 */
Packit Service a81408
Packit Service a81408
mit_des_key_schedule sched;
Packit Service a81408
Packit Service a81408
int
Packit Service a81408
main(argc,argv)
Packit Service a81408
    int argc;
Packit Service a81408
    char *argv[];
Packit Service a81408
{
Packit Service a81408
    /* Local Declarations */
Packit Service a81408
    size_t  in_length;
Packit Service a81408
    int  retval;
Packit Service a81408
    int i, j;
Packit Service a81408
Packit Service a81408
#ifdef WINDOWS
Packit Service a81408
    /* Set screen window buffer to infinite size -- MS default is tiny.  */
Packit Service a81408
    _wsetscreenbuf (fileno (stdout), _WINBUFINF);
Packit Service a81408
#endif
Packit Service a81408
    progname=argv[0];           /* salt away invoking program */
Packit Service a81408
Packit Service a81408
    while (--argc > 0 && (*++argv)[0] == '-')
Packit Service a81408
        for (i=1; argv[0][i] != '\0'; i++) {
Packit Service a81408
            switch (argv[0][i]) {
Packit Service a81408
Packit Service a81408
                /* debug flag */
Packit Service a81408
            case 'd':
Packit Service a81408
                mit_des_debug=3;
Packit Service a81408
                continue;
Packit Service a81408
Packit Service a81408
            case 'z':
Packit Service a81408
                zflag = 1;
Packit Service a81408
                continue;
Packit Service a81408
Packit Service a81408
            case 'm':
Packit Service a81408
                mflag = 1;
Packit Service a81408
                continue;
Packit Service a81408
Packit Service a81408
            default:
Packit Service a81408
                printf("%s: illegal flag \"%c\" ",
Packit Service a81408
                       progname,argv[0][i]);
Packit Service a81408
                exit(1);
Packit Service a81408
            }
Packit Service a81408
        };
Packit Service a81408
Packit Service a81408
    if (argc) {
Packit Service a81408
        fprintf(stderr, "Usage: %s [-dmz]\n", progname);
Packit Service a81408
        exit(1);
Packit Service a81408
    }
Packit Service a81408
Packit Service a81408
    /* do some initialisation */
Packit Service a81408
Packit Service a81408
    /* use known input and key */
Packit Service a81408
Packit Service a81408
    /* ECB zero text zero key */
Packit Service a81408
    if (zflag) {
Packit Service a81408
        input = zero_text;
Packit Service a81408
        mit_des_key_sched(zero_key, sched);
Packit Service a81408
        printf("plaintext = key = 0, cipher = 0x8ca64de9c1b123a7\n");
Packit Service a81408
        do_encrypt(input,cipher_text);
Packit Service a81408
        printf("\tcipher  = (low to high bytes)\n\t\t");
Packit Service a81408
        for (j = 0; j<=7; j++)
Packit Service a81408
            printf("%02x ",cipher_text[j]);
Packit Service a81408
        printf("\n");
Packit Service a81408
        do_decrypt(output,cipher_text);
Packit Service a81408
        if ( memcmp((char *)cipher_text, (char *)zresult, 8) ) {
Packit Service a81408
            printf("verify: error in zero key test\n");
Packit Service a81408
            exit(-1);
Packit Service a81408
        }
Packit Service a81408
Packit Service a81408
        exit(0);
Packit Service a81408
    }
Packit Service a81408
Packit Service a81408
    if (mflag) {
Packit Service a81408
        input = msb_text;
Packit Service a81408
        mit_des_key_sched(key3, sched);
Packit Service a81408
        printf("plaintext = 0x00 00 00 00 00 00 00 40, ");
Packit Service a81408
        printf("key = 0x80 01 01 01 01 01 01 01\n");
Packit Service a81408
        printf("        cipher = 0xa380e02a6be54696\n");
Packit Service a81408
        do_encrypt(input,cipher_text);
Packit Service a81408
        printf("\tcipher  = (low to high bytes)\n\t\t");
Packit Service a81408
        for (j = 0; j<=7; j++) {
Packit Service a81408
            printf("%02x ",cipher_text[j]);
Packit Service a81408
        }
Packit Service a81408
        printf("\n");
Packit Service a81408
        do_decrypt(output,cipher_text);
Packit Service a81408
        if ( memcmp((char *)cipher_text, (char *)mresult, 8) ) {
Packit Service a81408
            printf("verify: error in msb test\n");
Packit Service a81408
            exit(-1);
Packit Service a81408
        }
Packit Service a81408
        exit(0);
Packit Service a81408
    }
Packit Service a81408
Packit Service a81408
    /* ECB mode Davies and Price */
Packit Service a81408
    {
Packit Service a81408
        input = zero_text;
Packit Service a81408
        mit_des_key_sched(key2, sched);
Packit Service a81408
        printf("Examples per FIPS publication 81, keys ivs and cipher\n");
Packit Service a81408
        printf("in hex.  These are the correct answers, see below for\n");
Packit Service a81408
        printf("the actual answers.\n\n");
Packit Service a81408
        printf("Examples per Davies and Price.\n\n");
Packit Service a81408
        printf("EXAMPLE ECB\tkey = 08192a3b4c5d6e7f\n");
Packit Service a81408
        printf("\tclear = 0\n");
Packit Service a81408
        printf("\tcipher = 25 dd ac 3e 96 17 64 67\n");
Packit Service a81408
        printf("ACTUAL ECB\n");
Packit Service a81408
        printf("\tclear \"%s\"\n", input);
Packit Service a81408
        do_encrypt(input,cipher_text);
Packit Service a81408
        printf("\tcipher  = (low to high bytes)\n\t\t");
Packit Service a81408
        for (j = 0; j<=7; j++)
Packit Service a81408
            printf("%02x ",cipher_text[j]);
Packit Service a81408
        printf("\n\n");
Packit Service a81408
        do_decrypt(output,cipher_text);
Packit Service a81408
        if ( memcmp((char *)cipher_text, (char *)cipher1, 8) ) {
Packit Service a81408
            printf("verify: error in ECB encryption\n");
Packit Service a81408
            exit(-1);
Packit Service a81408
        }
Packit Service a81408
        else
Packit Service a81408
            printf("verify: ECB encryption is correct\n\n");
Packit Service a81408
    }
Packit Service a81408
Packit Service a81408
    /* ECB mode */
Packit Service a81408
    {
Packit Service a81408
        mit_des_key_sched(default_key, sched);
Packit Service a81408
        input = clear_text;
Packit Service a81408
        ivec = default_ivec;
Packit Service a81408
        printf("EXAMPLE ECB\tkey = 0123456789abcdef\n");
Packit Service a81408
        printf("\tclear = \"Now is the time for all \"\n");
Packit Service a81408
        printf("\tcipher = 3f a4 0e 8a 98 4d 48 15 ...\n");
Packit Service a81408
        printf("ACTUAL ECB\n\tclear \"%s\"",input);
Packit Service a81408
        do_encrypt(input,cipher_text);
Packit Service a81408
        printf("\n\tcipher      = (low to high bytes)\n\t\t");
Packit Service a81408
        for (j = 0; j<=7; j++) {
Packit Service a81408
            printf("%02x ",cipher_text[j]);
Packit Service a81408
        }
Packit Service a81408
        printf("\n\n");
Packit Service a81408
        do_decrypt(output,cipher_text);
Packit Service a81408
        if ( memcmp((char *)cipher_text, (char *)cipher2, 8) ) {
Packit Service a81408
            printf("verify: error in ECB encryption\n");
Packit Service a81408
            exit(-1);
Packit Service a81408
        }
Packit Service a81408
        else
Packit Service a81408
            printf("verify: ECB encryption is correct\n\n");
Packit Service a81408
    }
Packit Service a81408
Packit Service a81408
    /* CBC mode */
Packit Service a81408
    printf("EXAMPLE CBC\tkey = 0123456789abcdef");
Packit Service a81408
    printf("\tiv = 1234567890abcdef\n");
Packit Service a81408
    printf("\tclear = \"Now is the time for all \"\n");
Packit Service a81408
    printf("\tcipher =\te5 c7 cd de 87 2b f2 7c\n");
Packit Service a81408
    printf("\t\t\t43 e9 34 00 8c 38 9c 0f\n");
Packit Service a81408
    printf("\t\t\t68 37 88 49 9a 7c 05 f6\n");
Packit Service a81408
Packit Service a81408
    printf("ACTUAL CBC\n\tclear \"%s\"\n",input);
Packit Service a81408
    in_length =  strlen((char *)input);
Packit Service a81408
    if ((retval = mit_des_cbc_encrypt((const mit_des_cblock *) input,
Packit Service a81408
                                      (mit_des_cblock *) cipher_text,
Packit Service a81408
                                      (size_t) in_length,
Packit Service a81408
                                      sched,
Packit Service a81408
                                      ivec,
Packit Service a81408
                                      MIT_DES_ENCRYPT))) {
Packit Service a81408
        com_err("des verify", retval, "can't encrypt");
Packit Service a81408
        exit(-1);
Packit Service a81408
    }
Packit Service a81408
    printf("\tciphertext = (low to high bytes)\n");
Packit Service a81408
    for (i = 0; i <= 2; i++) {
Packit Service a81408
        printf("\t\t");
Packit Service a81408
        for (j = 0; j <= 7; j++) {
Packit Service a81408
            printf("%02x ",cipher_text[i*8+j]);
Packit Service a81408
        }
Packit Service a81408
        printf("\n");
Packit Service a81408
    }
Packit Service a81408
    if ((retval = mit_des_cbc_encrypt((const mit_des_cblock *) cipher_text,
Packit Service a81408
                                      (mit_des_cblock *) clear_text,
Packit Service a81408
                                      (size_t) in_length,
Packit Service a81408
                                      sched,
Packit Service a81408
                                      ivec,
Packit Service a81408
                                      MIT_DES_DECRYPT))) {
Packit Service a81408
        com_err("des verify", retval, "can't decrypt");
Packit Service a81408
        exit(-1);
Packit Service a81408
    }
Packit Service a81408
    printf("\tdecrypted clear_text = \"%s\"\n",clear_text);
Packit Service a81408
Packit Service a81408
    if ( memcmp((char *)cipher_text, (char *)cipher3, in_length) ) {
Packit Service a81408
        printf("verify: error in CBC encryption\n");
Packit Service a81408
        exit(-1);
Packit Service a81408
    }
Packit Service a81408
    else
Packit Service a81408
        printf("verify: CBC encryption is correct\n\n");
Packit Service a81408
Packit Service a81408
    printf("EXAMPLE CBC checksum");
Packit Service a81408
    printf("\tkey =  0123456789abcdef\tiv =  1234567890abcdef\n");
Packit Service a81408
    printf("\tclear =\t\t\"7654321 Now is the time for \"\n");
Packit Service a81408
    printf("\tchecksum\t58 d2 e7 7e 86 06 27 33, ");
Packit Service a81408
    printf("or some part thereof\n");
Packit Service a81408
    input = clear_text2;
Packit Service a81408
    mit_des_cbc_cksum(input,cipher_text, strlen((char *)input),
Packit Service a81408
                      sched,ivec);
Packit Service a81408
    printf("ACTUAL CBC checksum\n");
Packit Service a81408
    printf("\t\tencrypted cksum = (low to high bytes)\n\t\t");
Packit Service a81408
    for (j = 0; j<=7; j++)
Packit Service a81408
        printf("%02x ",cipher_text[j]);
Packit Service a81408
    printf("\n\n");
Packit Service a81408
    if ( memcmp((char *)cipher_text, (char *)checksum, 8) ) {
Packit Service a81408
        printf("verify: error in CBC cheksum\n");
Packit Service a81408
        exit(-1);
Packit Service a81408
    }
Packit Service a81408
    else
Packit Service a81408
        printf("verify: CBC checksum is correct\n\n");
Packit Service a81408
Packit Service a81408
    exit(0);
Packit Service a81408
}
Packit Service a81408
Packit Service a81408
static void
Packit Service a81408
do_encrypt(in,out)
Packit Service a81408
    unsigned char *in;
Packit Service a81408
    unsigned char *out;
Packit Service a81408
{
Packit Service a81408
    int i, j;
Packit Service a81408
    for (i =1; i<=nflag; i++) {
Packit Service a81408
        mit_des_cbc_encrypt((const mit_des_cblock *)in,
Packit Service a81408
                            (mit_des_cblock *)out,
Packit Service a81408
                            8,
Packit Service a81408
                            sched,
Packit Service a81408
                            zero_text,
Packit Service a81408
                            MIT_DES_ENCRYPT);
Packit Service a81408
        if (mit_des_debug) {
Packit Service a81408
            printf("\nclear %s\n",in);
Packit Service a81408
            for (j = 0; j<=7; j++)
Packit Service a81408
                printf("%02X ",in[j] & 0xff);
Packit Service a81408
            printf("\tcipher ");
Packit Service a81408
            for (j = 0; j<=7; j++)
Packit Service a81408
                printf("%02X ",out[j] & 0xff);
Packit Service a81408
        }
Packit Service a81408
    }
Packit Service a81408
}
Packit Service a81408
Packit Service a81408
static void
Packit Service a81408
do_decrypt(in,out)
Packit Service a81408
    unsigned char *out;
Packit Service a81408
    unsigned char *in;
Packit Service a81408
    /* try to invert it */
Packit Service a81408
{
Packit Service a81408
    int i, j;
Packit Service a81408
    for (i =1; i<=nflag; i++) {
Packit Service a81408
        mit_des_cbc_encrypt((const mit_des_cblock *)out,
Packit Service a81408
                            (mit_des_cblock *)in,
Packit Service a81408
                            8,
Packit Service a81408
                            sched,
Packit Service a81408
                            zero_text,
Packit Service a81408
                            MIT_DES_DECRYPT);
Packit Service a81408
        if (mit_des_debug) {
Packit Service a81408
            printf("clear %s\n",in);
Packit Service a81408
            for (j = 0; j<=7; j++)
Packit Service a81408
                printf("%02X ",in[j] & 0xff);
Packit Service a81408
            printf("\tcipher ");
Packit Service a81408
            for (j = 0; j<=7; j++)
Packit Service a81408
                printf("%02X ",out[j] & 0xff);
Packit Service a81408
        }
Packit Service a81408
    }
Packit Service a81408
}
Packit Service a81408
Packit Service a81408
/*
Packit Service a81408
 * Fake out the DES library, for the purposes of testing.
Packit Service a81408
 */
Packit Service a81408
Packit Service a81408
int
Packit Service a81408
mit_des_is_weak_key(key)
Packit Service a81408
    mit_des_cblock key;
Packit Service a81408
{
Packit Service a81408
    return 0;                           /* fake it out for testing */
Packit Service a81408
}