rabbit.js 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177
  1. import {
  2. StreamCipher,
  3. } from './cipher-core.js';
  4. // Reusable objects
  5. const S = [];
  6. const C_ = [];
  7. const G = [];
  8. function nextState() {
  9. // Shortcuts
  10. const X = this._X;
  11. const C = this._C;
  12. // Save old counter values
  13. for (let i = 0; i < 8; i += 1) {
  14. C_[i] = C[i];
  15. }
  16. // Calculate new counter values
  17. C[0] = (C[0] + 0x4d34d34d + this._b) | 0;
  18. C[1] = (C[1] + 0xd34d34d3 + ((C[0] >>> 0) < (C_[0] >>> 0) ? 1 : 0)) | 0;
  19. C[2] = (C[2] + 0x34d34d34 + ((C[1] >>> 0) < (C_[1] >>> 0) ? 1 : 0)) | 0;
  20. C[3] = (C[3] + 0x4d34d34d + ((C[2] >>> 0) < (C_[2] >>> 0) ? 1 : 0)) | 0;
  21. C[4] = (C[4] + 0xd34d34d3 + ((C[3] >>> 0) < (C_[3] >>> 0) ? 1 : 0)) | 0;
  22. C[5] = (C[5] + 0x34d34d34 + ((C[4] >>> 0) < (C_[4] >>> 0) ? 1 : 0)) | 0;
  23. C[6] = (C[6] + 0x4d34d34d + ((C[5] >>> 0) < (C_[5] >>> 0) ? 1 : 0)) | 0;
  24. C[7] = (C[7] + 0xd34d34d3 + ((C[6] >>> 0) < (C_[6] >>> 0) ? 1 : 0)) | 0;
  25. this._b = (C[7] >>> 0) < (C_[7] >>> 0) ? 1 : 0;
  26. // Calculate the g-values
  27. for (let i = 0; i < 8; i += 1) {
  28. const gx = X[i] + C[i];
  29. // Construct high and low argument for squaring
  30. const ga = gx & 0xffff;
  31. const gb = gx >>> 16;
  32. // Calculate high and low result of squaring
  33. const gh = ((((ga * ga) >>> 17) + ga * gb) >>> 15) + gb * gb;
  34. const gl = (((gx & 0xffff0000) * gx) | 0) + (((gx & 0x0000ffff) * gx) | 0);
  35. // High XOR low
  36. G[i] = gh ^ gl;
  37. }
  38. // Calculate new state values
  39. X[0] = (G[0] + ((G[7] << 16) | (G[7] >>> 16)) + ((G[6] << 16) | (G[6] >>> 16))) | 0;
  40. X[1] = (G[1] + ((G[0] << 8) | (G[0] >>> 24)) + G[7]) | 0;
  41. X[2] = (G[2] + ((G[1] << 16) | (G[1] >>> 16)) + ((G[0] << 16) | (G[0] >>> 16))) | 0;
  42. X[3] = (G[3] + ((G[2] << 8) | (G[2] >>> 24)) + G[1]) | 0;
  43. X[4] = (G[4] + ((G[3] << 16) | (G[3] >>> 16)) + ((G[2] << 16) | (G[2] >>> 16))) | 0;
  44. X[5] = (G[5] + ((G[4] << 8) | (G[4] >>> 24)) + G[3]) | 0;
  45. X[6] = (G[6] + ((G[5] << 16) | (G[5] >>> 16)) + ((G[4] << 16) | (G[4] >>> 16))) | 0;
  46. X[7] = (G[7] + ((G[6] << 8) | (G[6] >>> 24)) + G[5]) | 0;
  47. }
  48. /**
  49. * Rabbit stream cipher algorithm
  50. */
  51. export class RabbitAlgo extends StreamCipher {
  52. constructor(...args) {
  53. super(...args);
  54. this.blockSize = 128 / 32;
  55. this.ivSize = 64 / 32;
  56. }
  57. _doReset() {
  58. // Shortcuts
  59. const K = this._key.words;
  60. const { iv } = this.cfg;
  61. // Swap endian
  62. for (let i = 0; i < 4; i += 1) {
  63. K[i] = (((K[i] << 8) | (K[i] >>> 24)) & 0x00ff00ff)
  64. | (((K[i] << 24) | (K[i] >>> 8)) & 0xff00ff00);
  65. }
  66. // Generate initial state values
  67. this._X = [
  68. K[0], (K[3] << 16) | (K[2] >>> 16),
  69. K[1], (K[0] << 16) | (K[3] >>> 16),
  70. K[2], (K[1] << 16) | (K[0] >>> 16),
  71. K[3], (K[2] << 16) | (K[1] >>> 16),
  72. ];
  73. const X = this._X;
  74. // Generate initial counter values
  75. this._C = [
  76. (K[2] << 16) | (K[2] >>> 16), (K[0] & 0xffff0000) | (K[1] & 0x0000ffff),
  77. (K[3] << 16) | (K[3] >>> 16), (K[1] & 0xffff0000) | (K[2] & 0x0000ffff),
  78. (K[0] << 16) | (K[0] >>> 16), (K[2] & 0xffff0000) | (K[3] & 0x0000ffff),
  79. (K[1] << 16) | (K[1] >>> 16), (K[3] & 0xffff0000) | (K[0] & 0x0000ffff),
  80. ];
  81. const C = this._C;
  82. // Carry bit
  83. this._b = 0;
  84. // Iterate the system four times
  85. for (let i = 0; i < 4; i += 1) {
  86. nextState.call(this);
  87. }
  88. // Modify the counters
  89. for (let i = 0; i < 8; i += 1) {
  90. C[i] ^= X[(i + 4) & 7];
  91. }
  92. // IV setup
  93. if (iv) {
  94. // Shortcuts
  95. const IV = iv.words;
  96. const IV_0 = IV[0];
  97. const IV_1 = IV[1];
  98. // Generate four subvectors
  99. const i0 = (((IV_0 << 8) | (IV_0 >>> 24)) & 0x00ff00ff)
  100. | (((IV_0 << 24) | (IV_0 >>> 8)) & 0xff00ff00);
  101. const i2 = (((IV_1 << 8) | (IV_1 >>> 24)) & 0x00ff00ff)
  102. | (((IV_1 << 24) | (IV_1 >>> 8)) & 0xff00ff00);
  103. const i1 = (i0 >>> 16) | (i2 & 0xffff0000);
  104. const i3 = (i2 << 16) | (i0 & 0x0000ffff);
  105. // Modify counter values
  106. C[0] ^= i0;
  107. C[1] ^= i1;
  108. C[2] ^= i2;
  109. C[3] ^= i3;
  110. C[4] ^= i0;
  111. C[5] ^= i1;
  112. C[6] ^= i2;
  113. C[7] ^= i3;
  114. // Iterate the system four times
  115. for (let i = 0; i < 4; i += 1) {
  116. nextState.call(this);
  117. }
  118. }
  119. }
  120. _doProcessBlock(M, offset) {
  121. const _M = M;
  122. // Shortcut
  123. const X = this._X;
  124. // Iterate the system
  125. nextState.call(this);
  126. // Generate four keystream words
  127. S[0] = X[0] ^ (X[5] >>> 16) ^ (X[3] << 16);
  128. S[1] = X[2] ^ (X[7] >>> 16) ^ (X[5] << 16);
  129. S[2] = X[4] ^ (X[1] >>> 16) ^ (X[7] << 16);
  130. S[3] = X[6] ^ (X[3] >>> 16) ^ (X[1] << 16);
  131. for (let i = 0; i < 4; i += 1) {
  132. // Swap endian
  133. S[i] = (((S[i] << 8) | (S[i] >>> 24)) & 0x00ff00ff)
  134. | (((S[i] << 24) | (S[i] >>> 8)) & 0xff00ff00);
  135. // Encrypt
  136. _M[offset + i] ^= S[i];
  137. }
  138. }
  139. }
  140. /**
  141. * Shortcut functions to the cipher's object interface.
  142. *
  143. * @example
  144. *
  145. * var ciphertext = CryptoJS.Rabbit.encrypt(message, key, cfg);
  146. * var plaintext = CryptoJS.Rabbit.decrypt(ciphertext, key, cfg);
  147. */
  148. export const Rabbit = StreamCipher._createHelper(RabbitAlgo);