Skip to content

Commit 7951b67

Browse files
committed
Port of SM4 from Java API
1 parent c52855a commit 7951b67

14 files changed

+475
-2
lines changed

crypto/BouncyCastle.Android.csproj

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -801,6 +801,7 @@
801801
<Compile Include="src\crypto\engines\SerpentEngine.cs" />
802802
<Compile Include="src\crypto\engines\SkipjackEngine.cs" />
803803
<Compile Include="src\crypto\engines\SM2Engine.cs" />
804+
<Compile Include="src\crypto\engines\SM4Engine.cs" />
804805
<Compile Include="src\crypto\engines\TEAEngine.cs" />
805806
<Compile Include="src\crypto\engines\ThreefishEngine.cs" />
806807
<Compile Include="src\crypto\engines\TwofishEngine.cs" />

crypto/BouncyCastle.csproj

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -795,6 +795,7 @@
795795
<Compile Include="src\crypto\engines\SerpentEngine.cs" />
796796
<Compile Include="src\crypto\engines\SkipjackEngine.cs" />
797797
<Compile Include="src\crypto\engines\SM2Engine.cs" />
798+
<Compile Include="src\crypto\engines\SM4Engine.cs" />
798799
<Compile Include="src\crypto\engines\TEAEngine.cs" />
799800
<Compile Include="src\crypto\engines\ThreefishEngine.cs" />
800801
<Compile Include="src\crypto\engines\TwofishEngine.cs" />

crypto/BouncyCastle.iOS.csproj

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -796,6 +796,7 @@
796796
<Compile Include="src\crypto\engines\SerpentEngine.cs" />
797797
<Compile Include="src\crypto\engines\SkipjackEngine.cs" />
798798
<Compile Include="src\crypto\engines\SM2Engine.cs" />
799+
<Compile Include="src\crypto\engines\SM4Engine.cs" />
799800
<Compile Include="src\crypto\engines\TEAEngine.cs" />
800801
<Compile Include="src\crypto\engines\ThreefishEngine.cs" />
801802
<Compile Include="src\crypto\engines\TwofishEngine.cs" />

crypto/crypto.csproj

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3768,6 +3768,11 @@
37683768
SubType = "Code"
37693769
BuildAction = "Compile"
37703770
/>
3771+
<File
3772+
RelPath = "src\crypto\engines\SM4Engine.cs"
3773+
SubType = "Code"
3774+
BuildAction = "Compile"
3775+
/>
37713776
<File
37723777
RelPath = "src\crypto\engines\TEAEngine.cs"
37733778
SubType = "Code"
@@ -12229,6 +12234,11 @@
1222912234
SubType = "Code"
1223012235
BuildAction = "Compile"
1223112236
/>
12237+
<File
12238+
RelPath = "test\src\crypto\test\SM4Test.cs"
12239+
SubType = "Code"
12240+
BuildAction = "Compile"
12241+
/>
1223212242
<File
1223312243
RelPath = "test\src\crypto\test\SRP6Test.cs"
1223412244
SubType = "Code"
@@ -13039,6 +13049,11 @@
1303913049
SubType = "Code"
1304013050
BuildAction = "Compile"
1304113051
/>
13052+
<File
13053+
RelPath = "test\src\test\SM4Test.cs"
13054+
SubType = "Code"
13055+
BuildAction = "Compile"
13056+
/>
1304213057
<File
1304313058
RelPath = "test\src\test\TestUtilities.cs"
1304413059
SubType = "Code"
Lines changed: 189 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,189 @@
1+
using System;
2+
3+
using Org.BouncyCastle.Crypto.Parameters;
4+
using Org.BouncyCastle.Crypto.Utilities;
5+
using Org.BouncyCastle.Utilities;
6+
7+
namespace Org.BouncyCastle.Crypto.Engines
8+
{
9+
/// <summary>SM4 Block Cipher - SM4 is a 128 bit block cipher with a 128 bit key.</summary>
10+
/// <remarks>
11+
/// The implementation here is based on the document <a href="http://eprint.iacr.org/2008/329.pdf">http://eprint.iacr.org/2008/329.pdf</a>
12+
/// by Whitfield Diffie and George Ledin, which is a translation of Prof. LU Shu-wang's original standard.
13+
/// </remarks>
14+
public class SM4Engine
15+
: IBlockCipher
16+
{
17+
private const int BlockSize = 16;
18+
19+
private static readonly byte[] Sbox =
20+
{
21+
0xd6, 0x90, 0xe9, 0xfe, 0xcc, 0xe1, 0x3d, 0xb7, 0x16, 0xb6, 0x14, 0xc2, 0x28, 0xfb, 0x2c, 0x05,
22+
0x2b, 0x67, 0x9a, 0x76, 0x2a, 0xbe, 0x04, 0xc3, 0xaa, 0x44, 0x13, 0x26, 0x49, 0x86, 0x06, 0x99,
23+
0x9c, 0x42, 0x50, 0xf4, 0x91, 0xef, 0x98, 0x7a, 0x33, 0x54, 0x0b, 0x43, 0xed, 0xcf, 0xac, 0x62,
24+
0xe4, 0xb3, 0x1c, 0xa9, 0xc9, 0x08, 0xe8, 0x95, 0x80, 0xdf, 0x94, 0xfa, 0x75, 0x8f, 0x3f, 0xa6,
25+
0x47, 0x07, 0xa7, 0xfc, 0xf3, 0x73, 0x17, 0xba, 0x83, 0x59, 0x3c, 0x19, 0xe6, 0x85, 0x4f, 0xa8,
26+
0x68, 0x6b, 0x81, 0xb2, 0x71, 0x64, 0xda, 0x8b, 0xf8, 0xeb, 0x0f, 0x4b, 0x70, 0x56, 0x9d, 0x35,
27+
0x1e, 0x24, 0x0e, 0x5e, 0x63, 0x58, 0xd1, 0xa2, 0x25, 0x22, 0x7c, 0x3b, 0x01, 0x21, 0x78, 0x87,
28+
0xd4, 0x00, 0x46, 0x57, 0x9f, 0xd3, 0x27, 0x52, 0x4c, 0x36, 0x02, 0xe7, 0xa0, 0xc4, 0xc8, 0x9e,
29+
0xea, 0xbf, 0x8a, 0xd2, 0x40, 0xc7, 0x38, 0xb5, 0xa3, 0xf7, 0xf2, 0xce, 0xf9, 0x61, 0x15, 0xa1,
30+
0xe0, 0xae, 0x5d, 0xa4, 0x9b, 0x34, 0x1a, 0x55, 0xad, 0x93, 0x32, 0x30, 0xf5, 0x8c, 0xb1, 0xe3,
31+
0x1d, 0xf6, 0xe2, 0x2e, 0x82, 0x66, 0xca, 0x60, 0xc0, 0x29, 0x23, 0xab, 0x0d, 0x53, 0x4e, 0x6f,
32+
0xd5, 0xdb, 0x37, 0x45, 0xde, 0xfd, 0x8e, 0x2f, 0x03, 0xff, 0x6a, 0x72, 0x6d, 0x6c, 0x5b, 0x51,
33+
0x8d, 0x1b, 0xaf, 0x92, 0xbb, 0xdd, 0xbc, 0x7f, 0x11, 0xd9, 0x5c, 0x41, 0x1f, 0x10, 0x5a, 0xd8,
34+
0x0a, 0xc1, 0x31, 0x88, 0xa5, 0xcd, 0x7b, 0xbd, 0x2d, 0x74, 0xd0, 0x12, 0xb8, 0xe5, 0xb4, 0xb0,
35+
0x89, 0x69, 0x97, 0x4a, 0x0c, 0x96, 0x77, 0x7e, 0x65, 0xb9, 0xf1, 0x09, 0xc5, 0x6e, 0xc6, 0x84,
36+
0x18, 0xf0, 0x7d, 0xec, 0x3a, 0xdc, 0x4d, 0x20, 0x79, 0xee, 0x5f, 0x3e, 0xd7, 0xcb, 0x39, 0x48
37+
};
38+
39+
private static readonly uint[] CK =
40+
{
41+
0x00070e15, 0x1c232a31, 0x383f464d, 0x545b6269,
42+
0x70777e85, 0x8c939aa1, 0xa8afb6bd, 0xc4cbd2d9,
43+
0xe0e7eef5, 0xfc030a11, 0x181f262d, 0x343b4249,
44+
0x50575e65, 0x6c737a81, 0x888f969d, 0xa4abb2b9,
45+
0xc0c7ced5, 0xdce3eaf1, 0xf8ff060d, 0x141b2229,
46+
0x30373e45, 0x4c535a61, 0x686f767d, 0x848b9299,
47+
0xa0a7aeb5, 0xbcc3cad1, 0xd8dfe6ed, 0xf4fb0209,
48+
0x10171e25, 0x2c333a41, 0x484f565d, 0x646b7279
49+
};
50+
51+
private static readonly uint[] FK =
52+
{
53+
0xa3b1bac6, 0x56aa3350, 0x677d9197, 0xb27022dc
54+
};
55+
56+
private uint[] rk;
57+
58+
// non-linear substitution tau.
59+
private static uint tau(uint A)
60+
{
61+
uint b0 = Sbox[A >> 24];
62+
uint b1 = Sbox[(A >> 16) & 0xFF];
63+
uint b2 = Sbox[(A >> 8) & 0xFF];
64+
uint b3 = Sbox[A & 0xFF];
65+
66+
return (b0 << 24) | (b1 << 16) | (b2 << 8) | b3;
67+
}
68+
69+
private static uint L_ap(uint B)
70+
{
71+
return B ^ Integers.RotateLeft(B, 13) ^ Integers.RotateLeft(B, 23);
72+
}
73+
74+
private uint T_ap(uint Z)
75+
{
76+
return L_ap(tau(Z));
77+
}
78+
79+
// Key expansion
80+
private void ExpandKey(bool forEncryption, byte[] key)
81+
{
82+
uint K0 = Pack.BE_To_UInt32(key, 0) ^ FK[0];
83+
uint K1 = Pack.BE_To_UInt32(key, 4) ^ FK[1];
84+
uint K2 = Pack.BE_To_UInt32(key, 8) ^ FK[2];
85+
uint K3 = Pack.BE_To_UInt32(key, 12) ^ FK[3];
86+
87+
if (forEncryption)
88+
{
89+
rk[0] = K0 ^ T_ap(K1 ^ K2 ^ K3 ^ CK[0]);
90+
rk[1] = K1 ^ T_ap(K2 ^ K3 ^ rk[0] ^ CK[1]);
91+
rk[2] = K2 ^ T_ap(K3 ^ rk[0] ^ rk[1] ^ CK[2]);
92+
rk[3] = K3 ^ T_ap(rk[0] ^ rk[1] ^ rk[2] ^ CK[3]);
93+
for (int i = 4; i < 32; ++i)
94+
{
95+
rk[i] = rk[i - 4] ^ T_ap(rk[i - 3] ^ rk[i - 2] ^ rk[i - 1] ^ CK[i]);
96+
}
97+
}
98+
else
99+
{
100+
rk[31] = K0 ^ T_ap(K1 ^ K2 ^ K3 ^ CK[0]);
101+
rk[30] = K1 ^ T_ap(K2 ^ K3 ^ rk[31] ^ CK[1]);
102+
rk[29] = K2 ^ T_ap(K3 ^ rk[31] ^ rk[30] ^ CK[2]);
103+
rk[28] = K3 ^ T_ap(rk[31] ^ rk[30] ^ rk[29] ^ CK[3]);
104+
for (int i = 27; i >= 0; --i)
105+
{
106+
rk[i] = rk[i + 4] ^ T_ap(rk[i + 3] ^ rk[i + 2] ^ rk[i + 1] ^ CK[31 - i]);
107+
}
108+
}
109+
}
110+
111+
// Linear substitution L
112+
private static uint L(uint B)
113+
{
114+
return B ^ Integers.RotateLeft(B, 2) ^ Integers.RotateLeft(B, 10) ^ Integers.RotateLeft(B, 18) ^ Integers.RotateLeft(B, 24);
115+
}
116+
117+
// Mixer-substitution T
118+
private static uint T(uint Z)
119+
{
120+
return L(tau(Z));
121+
}
122+
123+
public virtual void Init(bool forEncryption, ICipherParameters parameters)
124+
{
125+
KeyParameter keyParameter = parameters as KeyParameter;
126+
if (null == keyParameter)
127+
throw new ArgumentException("invalid parameter passed to SM4 init - " + Platform.GetTypeName(parameters), "parameters");
128+
129+
byte[] key = keyParameter.GetKey();
130+
if (key.Length != 16)
131+
throw new ArgumentException("SM4 requires a 128 bit key", "parameters");
132+
133+
if (null == rk)
134+
{
135+
rk = new uint[32];
136+
}
137+
138+
ExpandKey(forEncryption, key);
139+
}
140+
141+
public virtual string AlgorithmName
142+
{
143+
get { return "SM4"; }
144+
}
145+
146+
public virtual bool IsPartialBlockOkay
147+
{
148+
get { return false; }
149+
}
150+
151+
public virtual int GetBlockSize()
152+
{
153+
return BlockSize;
154+
}
155+
156+
public virtual int ProcessBlock(byte[] input, int inOff, byte[] output, int outOff)
157+
{
158+
if (null == rk)
159+
throw new InvalidOperationException("SM4 not initialised");
160+
161+
Check.DataLength(input, inOff, BlockSize, "input buffer too short");
162+
Check.OutputLength(output, outOff, BlockSize, "output buffer too short");
163+
164+
uint X0 = Pack.BE_To_UInt32(input, inOff);
165+
uint X1 = Pack.BE_To_UInt32(input, inOff + 4);
166+
uint X2 = Pack.BE_To_UInt32(input, inOff + 8);
167+
uint X3 = Pack.BE_To_UInt32(input, inOff + 12);
168+
169+
for (int i = 0; i < 32; i += 4)
170+
{
171+
X0 ^= T(X1 ^ X2 ^ X3 ^ rk[i ]); // F0
172+
X1 ^= T(X2 ^ X3 ^ X0 ^ rk[i + 1]); // F1
173+
X2 ^= T(X3 ^ X0 ^ X1 ^ rk[i + 2]); // F2
174+
X3 ^= T(X0 ^ X1 ^ X2 ^ rk[i + 3]); // F3
175+
}
176+
177+
Pack.UInt32_To_BE(X3, output, outOff);
178+
Pack.UInt32_To_BE(X2, output, outOff + 4);
179+
Pack.UInt32_To_BE(X1, output, outOff + 8);
180+
Pack.UInt32_To_BE(X0, output, outOff + 12);
181+
182+
return BlockSize;
183+
}
184+
185+
public virtual void Reset()
186+
{
187+
}
188+
}
189+
}

crypto/src/security/CipherUtilities.cs

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,7 @@ private enum CipherAlgorithm {
5353
SEED,
5454
SERPENT,
5555
SKIPJACK,
56+
SM4,
5657
TEA,
5758
THREEFISH_256,
5859
THREEFISH_512,
@@ -433,6 +434,9 @@ public static IBufferedCipher GetCipher(
433434
case CipherAlgorithm.SKIPJACK:
434435
blockCipher = new SkipjackEngine();
435436
break;
437+
case CipherAlgorithm.SM4:
438+
blockCipher = new SM4Engine();
439+
break;
436440
case CipherAlgorithm.TEA:
437441
blockCipher = new TeaEngine();
438442
break;
@@ -740,6 +744,7 @@ private static IBlockCipher CreateBlockCipher(CipherAlgorithm cipherAlgorithm)
740744
case CipherAlgorithm.SEED: return new SeedEngine();
741745
case CipherAlgorithm.SERPENT: return new SerpentEngine();
742746
case CipherAlgorithm.SKIPJACK: return new SkipjackEngine();
747+
case CipherAlgorithm.SM4: return new SM4Engine();
743748
case CipherAlgorithm.TEA: return new TeaEngine();
744749
case CipherAlgorithm.THREEFISH_256: return new ThreefishEngine(ThreefishEngine.BLOCKSIZE_256);
745750
case CipherAlgorithm.THREEFISH_512: return new ThreefishEngine(ThreefishEngine.BLOCKSIZE_512);

crypto/src/security/GeneratorUtilities.cs

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -110,6 +110,7 @@ static GeneratorUtilities()
110110
KisaObjectIdentifiers.IdSeedCbc);
111111
AddKgAlgorithm("SERPENT");
112112
AddKgAlgorithm("SKIPJACK");
113+
AddKgAlgorithm("SM4");
113114
AddKgAlgorithm("TEA");
114115
AddKgAlgorithm("THREEFISH-256");
115116
AddKgAlgorithm("THREEFISH-512");
@@ -203,7 +204,7 @@ static GeneratorUtilities()
203204
AddDefaultKeySizeEntries(80, "SKIPJACK");
204205
AddDefaultKeySizeEntries(128, "AES128", "BLOWFISH", "CAMELLIA128", "CAST5", "DESEDE",
205206
"HC128", "HMACMD2", "HMACMD4", "HMACMD5", "HMACRIPEMD128", "IDEA", "NOEKEON",
206-
"RC2", "RC4", "RC5", "SALSA20", "SEED", "TEA", "XTEA", "VMPC", "VMPC-KSA3");
207+
"RC2", "RC4", "RC5", "SALSA20", "SEED", "SM4", "TEA", "XTEA", "VMPC", "VMPC-KSA3");
207208
AddDefaultKeySizeEntries(160, "HMACRIPEMD160", "HMACSHA1");
208209
AddDefaultKeySizeEntries(192, "AES", "AES192", "CAMELLIA192", "DESEDE3", "HMACTIGER",
209210
"RIJNDAEL", "SERPENT", "TNEPRES");

crypto/src/security/ParameterUtilities.cs

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,7 @@ static ParameterUtilities()
103103
KisaObjectIdentifiers.IdSeedCbc);
104104
AddAlgorithm("SERPENT");
105105
AddAlgorithm("SKIPJACK");
106+
AddAlgorithm("SM4");
106107
AddAlgorithm("TEA");
107108
AddAlgorithm("THREEFISH-256");
108109
AddAlgorithm("THREEFISH-512");
@@ -115,7 +116,8 @@ static ParameterUtilities()
115116

116117
AddBasicIVSizeEntries(8, "BLOWFISH", "DES", "DESEDE", "DESEDE3");
117118
AddBasicIVSizeEntries(16, "AES", "AES128", "AES192", "AES256",
118-
"CAMELLIA", "CAMELLIA128", "CAMELLIA192", "CAMELLIA256", "NOEKEON", "SEED");
119+
"CAMELLIA", "CAMELLIA128", "CAMELLIA192", "CAMELLIA256",
120+
"NOEKEON", "SEED", "SM4");
119121

120122
// TODO These algorithms support an IV
121123
// but JCE doesn't seem to provide an AlgorithmParametersGenerator for them

crypto/src/util/Integers.cs

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,21 @@ public static int RotateLeft(int i, int distance)
99
return (i << distance) ^ (int)((uint)i >> -distance);
1010
}
1111

12+
[CLSCompliantAttribute(false)]
13+
public static uint RotateLeft(uint i, int distance)
14+
{
15+
return (i << distance) ^ (i >> -distance);
16+
}
17+
1218
public static int RotateRight(int i, int distance)
1319
{
1420
return (int)((uint)i >> distance) ^ (i << -distance);
1521
}
22+
23+
[CLSCompliantAttribute(false)]
24+
public static uint RotateRight(uint i, int distance)
25+
{
26+
return (i >> distance) ^ (i << -distance);
27+
}
1628
}
1729
}

crypto/test/UnitTests.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -265,6 +265,7 @@
265265
<Compile Include="src\crypto\test\SM2KeyExchangeTest.cs" />
266266
<Compile Include="src\crypto\test\SM2SignerTest.cs" />
267267
<Compile Include="src\crypto\test\SM3DigestTest.cs" />
268+
<Compile Include="src\crypto\test\SM4Test.cs" />
268269
<Compile Include="src\crypto\test\SkeinDigestTest.cs" />
269270
<Compile Include="src\crypto\test\SkeinMacTest.cs" />
270271
<Compile Include="src\crypto\test\StreamCipherResetTest.cs" />
@@ -434,6 +435,7 @@
434435
<Compile Include="src\test\RegressionTest.cs" />
435436
<Compile Include="src\test\SEEDTest.cs" />
436437
<Compile Include="src\test\SigTest.cs" />
438+
<Compile Include="src\test\SM4Test.cs" />
437439
<Compile Include="src\test\TestUtilities.cs" />
438440
<Compile Include="src\test\WrapTest.cs" />
439441
<Compile Include="src\test\X509CertificatePairTest.cs" />

0 commit comments

Comments
 (0)