8#include <botan/internal/idea.h>
10#include <botan/internal/ct_utils.h>
11#include <botan/internal/loadstor.h>
13#if defined(BOTAN_HAS_CPUID)
14 #include <botan/internal/cpuid.h>
24inline uint16_t mul(uint16_t x, uint16_t y) {
25 uint32_t P =
static_cast<uint32_t
>(x) * y;
26 const uint16_t P_is_zero =
static_cast<uint16_t
>(
ct_is_zero(P));
28 P = (P & 0xFFFF) - (P >> 16);
29 const uint16_t
R1 =
static_cast<uint16_t
>(P - (P >> 16));
30 const uint16_t R0 = 1 - x - y;
46uint16_t mul_inv(uint16_t x) {
49 for(
size_t i = 0; i != 15; ++i) {
60void idea_op(
const uint8_t in[], uint8_t out[],
size_t blocks,
const uint16_t K[52]) {
61 const size_t BLOCK_SIZE = 8;
67 for(
size_t i = 0; i < blocks; ++i) {
72 load_be(in + BLOCK_SIZE * i, X1, X2, X3, X4);
74 for(
size_t j = 0; j != 8; ++j) {
75 X1 = mul(X1, K[6 * j + 0]);
78 X4 = mul(X4, K[6 * j + 3]);
80 const uint16_t T0 = X3;
81 X3 = mul(X3 ^ X1, K[6 * j + 4]);
83 const uint16_t T1 = X2;
84 X2 = mul((X2 ^ X4) + X3, K[6 * j + 5]);
98 store_be(out + BLOCK_SIZE * i, X1, X3, X2, X4);
109#if defined(BOTAN_HAS_IDEA_AVX2)
115#if defined(BOTAN_HAS_IDEA_SSE2)
125#if defined(BOTAN_HAS_IDEA_AVX2)
131#if defined(BOTAN_HAS_IDEA_SSE2)
146#if defined(BOTAN_HAS_IDEA_AVX2)
148 while(blocks >= 16) {
149 avx2_idea_op_16(in, out, m_EK.data());
157#if defined(BOTAN_HAS_IDEA_SSE2)
160 sse2_idea_op_8(in, out, m_EK.data());
168 idea_op(in, out, blocks, m_EK.data());
177#if defined(BOTAN_HAS_IDEA_AVX2)
179 while(blocks >= 16) {
180 avx2_idea_op_16(in, out, m_DK.data());
188#if defined(BOTAN_HAS_IDEA_SSE2)
191 sse2_idea_op_8(in, out, m_DK.data());
199 idea_op(in, out, blocks, m_DK.data());
203 return !m_EK.empty();
209void IDEA::key_schedule(std::span<const uint8_t> key) {
222 for(
size_t off = 0; off != 48; off += 8) {
223 for(
size_t i = 0; i != 8; ++i) {
224 m_EK[off + i] =
static_cast<uint16_t
>(K[i / 4] >> (48 - 16 * (i % 4)));
227 const uint64_t Kx = (K[0] >> 39);
228 const uint64_t Ky = (K[1] >> 39);
230 K[0] = (K[0] << 25) | Ky;
231 K[1] = (K[1] << 25) | Kx;
234 for(
size_t i = 0; i != 4; ++i) {
235 m_EK[48 + i] =
static_cast<uint16_t
>(K[i / 4] >> (48 - 16 * (i % 4)));
238 m_DK[0] = mul_inv(m_EK[48]);
241 m_DK[3] = mul_inv(m_EK[51]);
243 for(
size_t i = 0; i != 8 * 6; i += 6) {
244 m_DK[i + 4] = m_EK[46 - i];
245 m_DK[i + 5] = m_EK[47 - i];
246 m_DK[i + 6] = mul_inv(m_EK[42 - i]);
247 m_DK[i + 7] = -m_EK[44 - i];
248 m_DK[i + 8] = -m_EK[43 - i];
249 m_DK[i + 9] = mul_inv(m_EK[45 - i]);
252 std::swap(m_DK[49], m_DK[50]);
static std::optional< std::string > check(CPUID::Feature feat)
static bool has(CPUID::Feature feat)
void decrypt_n(const uint8_t in[], uint8_t out[], size_t blocks) const override
std::string provider() const override
bool has_keying_material() const override
void encrypt_n(const uint8_t in[], uint8_t out[], size_t blocks) const override
size_t parallelism() const override
void assert_key_material_set() const
constexpr void unpoison(const T *p, size_t n)
constexpr void poison(const T *p, size_t n)
void zap(std::vector< T, Alloc > &vec)
void R1(uint32_t A, uint32_t &B, uint32_t C, uint32_t &D, uint32_t E, uint32_t &F, uint32_t G, uint32_t &H, uint32_t TJ, uint32_t Wi, uint32_t Wj)
BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b)
std::vector< T, secure_allocator< T > > secure_vector
constexpr auto store_be(ParamTs &&... params)
constexpr auto load_be(ParamTs &&... params)
BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x)