1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
use block_cipher_trait::generic_array::{GenericArray, ArrayLength};
use block_cipher_trait::generic_array::typenum::{Unsigned, U16};
use block_cipher_trait::BlockCipher;
use block_padding::Padding;
use traits::{BlockMode, BlockModeIv, BlockModeError};
use utils::xor;
use core::mem;
use core::marker::PhantomData;
pub struct Ctr128<C, P>
where C: BlockCipher<BlockSize=U16>, P: Padding,
C::ParBlocks: ArrayLength<GenericArray<u8, U16>>
{
cipher: C,
counter: [u64; 2],
_p: PhantomData<P>,
}
#[inline(always)]
fn conv_be(val: &mut [u64; 2]) {
val[0] = val[0].to_be();
val[1] = val[1].to_be();
}
impl<C, P> BlockModeIv<C, P> for Ctr128<C, P>
where C: BlockCipher<BlockSize=U16>, P: Padding,
C::ParBlocks: ArrayLength<GenericArray<u8, U16>>
{
fn new(cipher: C, nonce: &GenericArray<u8, C::BlockSize>) -> Self {
let mut counter: [u64; 2] = unsafe { mem::transmute_copy(nonce) };
conv_be(&mut counter);
Self { cipher, counter, _p: Default::default() }
}
}
impl<C, P> Ctr128<C, P>
where C: BlockCipher<BlockSize=U16>, P: Padding,
C::ParBlocks: ArrayLength<GenericArray<u8, U16>>
{
#[inline(always)]
fn inc_counter(&mut self) {
let (v, f) = self.counter[1].overflowing_add(1);
self.counter[1] = v;
if f {
self.counter[0] = self.counter[0].wrapping_add(1);
}
}
#[inline(always)]
fn next_buf(&mut self) -> GenericArray<u8, U16> {
let mut res = self.counter.clone();
conv_be(&mut res);
self.inc_counter();
unsafe { mem::transmute(res) }
}
}
impl<C, P> BlockMode<C, P> for Ctr128<C, P>
where C: BlockCipher<BlockSize=U16>, P: Padding,
C::ParBlocks: ArrayLength<GenericArray<u8, U16>>
{
fn encrypt_nopad(&mut self, buffer: &mut [u8])
-> Result<(), BlockModeError>
{
let bs = C::BlockSize::to_usize();
assert_eq!(buffer.len() % bs, 0);
for block in buffer.chunks_mut(bs) {
let mut buf = self.next_buf();
self.cipher.encrypt_block(&mut buf);
xor(block, &buf);
}
Ok(())
}
fn decrypt_nopad(&mut self, buffer: &mut [u8])
-> Result<(), BlockModeError>
{
self.encrypt_nopad(buffer)
}
}