rabbit.js 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186
  1. /*
  2. CryptoJS v3.0.2
  3. code.google.com/p/crypto-js
  4. (c) 2009-2012 by Jeff Mott. All rights reserved.
  5. code.google.com/p/crypto-js/wiki/License
  6. */
  7. (function () {
  8. // Shortcuts
  9. var C = CryptoJS;
  10. var C_lib = C.lib;
  11. var StreamCipher = C_lib.StreamCipher;
  12. var C_algo = C.algo;
  13. // Reusable objects
  14. var S = [];
  15. var G = [];
  16. /**
  17. * Rabbit stream cipher algorithm
  18. */
  19. var Rabbit = C_algo.Rabbit = StreamCipher.extend({
  20. _doReset: function () {
  21. // Shortcuts
  22. var K = this._key.words;
  23. var K0 = K[0];
  24. var K1 = K[1];
  25. var K2 = K[2];
  26. var K3 = K[3];
  27. // Generate initial state values
  28. var X = this._X = [
  29. K0, (K3 << 16) | (K2 >>> 16),
  30. K1, (K0 << 16) | (K3 >>> 16),
  31. K2, (K1 << 16) | (K0 >>> 16),
  32. K3, (K2 << 16) | (K1 >>> 16)
  33. ];
  34. // Generate initial counter values
  35. var C = this._C = [
  36. (K2 << 16) | (K2 >>> 16), (K0 & 0xffff0000) | (K1 & 0x0000ffff),
  37. (K3 << 16) | (K3 >>> 16), (K1 & 0xffff0000) | (K2 & 0x0000ffff),
  38. (K0 << 16) | (K0 >>> 16), (K2 & 0xffff0000) | (K3 & 0x0000ffff),
  39. (K1 << 16) | (K1 >>> 16), (K3 & 0xffff0000) | (K0 & 0x0000ffff)
  40. ];
  41. // Carry bit
  42. this._b = 0;
  43. // Iterate the system four times
  44. for (var i = 0; i < 4; i++) {
  45. nextState.call(this);
  46. }
  47. // Modify the counters
  48. for (var i = 0; i < 8; i++) {
  49. C[i] ^= X[(i + 4) & 7];
  50. }
  51. // Shortcut
  52. var iv = this.cfg.iv;
  53. // IV setup
  54. if (iv) {
  55. // Shortcuts
  56. var IV = iv.words;
  57. var IV0 = IV[0];
  58. var IV1 = IV[1];
  59. // Generate four subvectors
  60. var i0 = (((IV0 << 8) | (IV0 >>> 24)) & 0x00ff00ff) | (((IV0 << 24) | (IV0 >>> 8)) & 0xff00ff00);
  61. var i2 = (((IV1 << 8) | (IV1 >>> 24)) & 0x00ff00ff) | (((IV1 << 24) | (IV1 >>> 8)) & 0xff00ff00);
  62. var i1 = (i0 >>> 16) | (i2 & 0xffff0000);
  63. var i3 = (i2 << 16) | (i0 & 0x0000ffff);
  64. // Modify counter values
  65. C[0] ^= i0;
  66. C[1] ^= i1;
  67. C[2] ^= i2;
  68. C[3] ^= i3;
  69. C[4] ^= i0;
  70. C[5] ^= i1;
  71. C[6] ^= i2;
  72. C[7] ^= i3;
  73. // Iterate the system four times
  74. for (var i = 0; i < 4; i++) {
  75. nextState.call(this);
  76. }
  77. }
  78. },
  79. _doProcessBlock: function (M, offset) {
  80. // Shortcut
  81. var X = this._X;
  82. // Iterate the system
  83. nextState.call(this);
  84. // Generate four keystream words
  85. S[0] = X[0] ^ (X[5] >>> 16) ^ (X[3] << 16);
  86. S[1] = X[2] ^ (X[7] >>> 16) ^ (X[5] << 16);
  87. S[2] = X[4] ^ (X[1] >>> 16) ^ (X[7] << 16);
  88. S[3] = X[6] ^ (X[3] >>> 16) ^ (X[1] << 16);
  89. for (var i = 0; i < 4; i++) {
  90. // Shortcut
  91. var Si = S[i];
  92. // Swap endian
  93. Si = (((Si << 8) | (Si >>> 24)) & 0x00ff00ff) |
  94. (((Si << 24) | (Si >>> 8)) & 0xff00ff00);
  95. // Encrypt
  96. M[offset + i] ^= Si;
  97. }
  98. },
  99. blockSize: 128/32,
  100. ivSize: 64/32
  101. });
  102. function nextState() {
  103. // Shortcuts
  104. var X = this._X;
  105. var C = this._C;
  106. // Calculate new counter values
  107. C[0] = (C[0] + 0x4d34d34d + this._b) | 0;
  108. C[1] = (C[1] + 0xd34d34d3 + ((C[0] >>> 0) < 0x4d34d34d ? 1 : 0)) | 0;
  109. C[2] = (C[2] + 0x34d34d34 + ((C[1] >>> 0) < 0xd34d34d3 ? 1 : 0)) | 0;
  110. C[3] = (C[3] + 0x4d34d34d + ((C[2] >>> 0) < 0x34d34d34 ? 1 : 0)) | 0;
  111. C[4] = (C[4] + 0xd34d34d3 + ((C[3] >>> 0) < 0x4d34d34d ? 1 : 0)) | 0;
  112. C[5] = (C[5] + 0x34d34d34 + ((C[4] >>> 0) < 0xd34d34d3 ? 1 : 0)) | 0;
  113. C[6] = (C[6] + 0x4d34d34d + ((C[5] >>> 0) < 0x34d34d34 ? 1 : 0)) | 0;
  114. C[7] = (C[7] + 0xd34d34d3 + ((C[6] >>> 0) < 0x4d34d34d ? 1 : 0)) | 0;
  115. this._b = (C[7] >>> 0) < 0xd34d34d3 ? 1 : 0;
  116. // Calculate the g-values
  117. for (var i = 0; i < 8; i++) {
  118. var gx = X[i] + C[i];
  119. // Construct high and low argument for squaring
  120. var ga = gx & 0xffff;
  121. var gb = gx >>> 16;
  122. // Calculate high and low result of squaring
  123. var gh = ((((ga * ga) >>> 17) + ga * gb) >>> 15) + gb * gb;
  124. var gl = (((gx & 0xffff0000) * gx) | 0) + (((gx & 0x0000ffff) * gx) | 0);
  125. // High XOR low
  126. G[i] = gh ^ gl;
  127. }
  128. // Shortcuts
  129. var G0 = G[0];
  130. var G1 = G[1];
  131. var G2 = G[2];
  132. var G3 = G[3];
  133. var G4 = G[4];
  134. var G5 = G[5];
  135. var G6 = G[6];
  136. var G7 = G[7];
  137. // Calculate new state values
  138. X[0] = (G0 + ((G7 << 16) | (G7 >>> 16)) + ((G6 << 16) | (G6 >>> 16))) | 0;
  139. X[1] = (G1 + ((G0 << 8) | (G0 >>> 24)) + G7) | 0;
  140. X[2] = (G2 + ((G1 << 16) | (G1 >>> 16)) + ((G0 << 16) | (G0 >>> 16))) | 0;
  141. X[3] = (G3 + ((G2 << 8) | (G2 >>> 24)) + G1) | 0;
  142. X[4] = (G4 + ((G3 << 16) | (G3 >>> 16)) + ((G2 << 16) | (G2 >>> 16))) | 0;
  143. X[5] = (G5 + ((G4 << 8) | (G4 >>> 24)) + G3) | 0;
  144. X[6] = (G6 + ((G5 << 16) | (G5 >>> 16)) + ((G4 << 16) | (G4 >>> 16))) | 0;
  145. X[7] = (G7 + ((G6 << 8) | (G6 >>> 24)) + G5) | 0;
  146. }
  147. /**
  148. * Shortcut functions to the cipher's object interface.
  149. *
  150. * @example
  151. *
  152. * var ciphertext = CryptoJS.Rabbit.encrypt(message, key, cfg);
  153. * var plaintext = CryptoJS.Rabbit.decrypt(ciphertext, key, cfg);
  154. */
  155. C.Rabbit = StreamCipher._createHelper(Rabbit);
  156. }());