Transcription of Data Encryption Routines for PIC24 and dsPIC Device
1 AN1044. data Encryption Routines for PIC24 and dsPIC Devices Authors: David Flowers and Triple DES (TDES) is a variant of DES, and is described in FIPS 46-2 and 46-3. TDES uses three Howard Henry Schlunder cycles of DES to extend the key from 56 bits to 112 or Microchip Technology Inc. 168 bits, depending on the mode of operation. Because of known weaknesses in the DES algorithm, the actual INTRODUCTION security is believed to be on the order of 80 and 112 bits, respectively, for the two different methods. Currently, there are three data Encryption standards The use of TDES was suggested by the American gov- approved for use in the Federal Information Processing ernment in 1999 for use in all systems, except in legacy Standards (FIPS).
2 This application note discusses the systems, where only DES was available. implementation of two of these for PIC24 and There are several different modes of TDES. The most dsPIC30/33 devices: Triple data Encryption Standard common involves using two different keys. The data is (TDES) and Advanced Encryption Standard (AES). encrypted with the first key. That result is then decrypted with the second key. The data is then finally TDES Encryption encrypted once again with the first key. Other modes of operation include using three different keys, one for Background each of the stages, and encrypting in all rounds instead of decrypting during the second round.
3 For most new The original data Encryption Standard (DES), a 64-bit applications, TDES has been replaced with Advanced block cipher, was invented in the early 1970s by IBM . Encryption Standard (AES). AES provides a slightly DES uses a 64-bit Encryption key: 56 bits for encoding higher security level than TDES and is much faster and and decoding, the remainder for parity. It was adopted smaller in implementation than TDES. by the United States government in 1977 as standard The original DES algorithm is outlined in Figure 1. The for encrypting sensitive data . By the mid 1990s, several cycle is run 32 times before the ciphertext is valid. public organizations had demonstrated that they were able to crack a DES code within days.
4 FIGURE 1: ORIGINAL DES ALGORITHM. Plaintext Key IP Permutation Left Half Right Half E Permutation Subkey Generator IP-1 Permutation S1 S2 S3 S4 S5 S6 S7 S8. Ciphertext Old Left P Permutation 2006 Microchip Technology Inc. DS01044A-page 1. AN1044. In the original DES, the plaintext is permuted by the FIGURE 4: PERMUTATION BOX. initial permutation matrix, IP (Figure 2). It is then split MATRIX (P). into a left portion and a right portion. The right portion 16 7 20 21 29 12 28 17. is permuted by E (Figure 3), XORed with the round 1 15 23 26 5 18 31 10. subkey, substituted with an S-Box value (Figure 6), 2 8 24 14 32 27 3 9. permuted by P (Figure 4) and XORed with the left half 19 13 30 6 22 11 4 25.
5 Of the data from the last round. The left data is replaced with the right data from the last round and the right data is replaced with this new calculated value. The cycle is FIGURE 5: INVERSE PERMUTATION. repeated for 32 iterations, with the result permuted by (IP-1) MATRIX. the inverse permutation matrix, IP-1 (Figure 5), to get 40 8 48 16 56 24 64 32. the final cipher text. 39 7 47 15 55 23 63 31. 38 6 46 14 54 22 62 30. FIGURE 2: INITIAL PERMUTATION 37 5 45 13 53 21 61 29. MATRIX (IP) 36 4 44 14 52 20 60 28. 58 50 42 34 26 18 10 2 35 3 43 13 51 19 59 27. 60 52 44 36 28 20 12 4 34 2 42 12 50 18 58 26. 62 54 46 38 30 22 14 6 33 1 41 11 49 17 57 25.
6 64 56 48 40 32 24 16 8. 57 49 41 33 25 17 9 1 An optional implementation, shown in Figure 7, can be 59 51 43 35 27 19 11 3 used to reduce the execution time required for each 61 53 45 37 29 21 13 5 Encryption . Because the S-Box substitution and P. 63 55 47 39 31 23 15 7 permutation are both linear operations, they can be combined into one operation, instead of two separate operations, thus resulting in a PS table. Unrolling the FIGURE 3: EXPANSION PERMUTATION DES loop once removes the need for some temporary MATRIX (E) variables and reduces the overhead of shuffling data . It 32 1 2 3 4 5 4 5 does, however, increase the code size. 6 7 8 9 8 9 10 11 For a more detailed description of how the permuta- 12 13 12 13 14 15 16 17 tions and substitutions work, please refer to Microchip 16 17 18 19 20 21 20 21 application note AN583, Implementation of the data 22 23 24 25 24 25 26 27 Encryption Standard Using PIC17C42 (DS00583).
7 28 29 28 29 30 31 32 1. FIGURE 6: S-BOX MATRICES (Sn). 14 4 13 1 2 15 11 8 3 10 6 12 5 9 0 7 2 12 4 1 7 10 11 6 8 5 3 15 13 0 14 9. S1 = 0 15 7 4 14 2 13 1 10 6 12 11 9 5 3 8 S4 = 14 11 2 12 4 7 13 1 5 0 15 10 3 9 8 6. 4 1 14 8 13 6 2 11 15 12 9 7 3 10 5 0 10 6 9 0 12 11 7 13 15 1 3 14 5 2 8 4. 15 12 8 2 4 9 1 7 5 11 3 14 10 0 6 3 3 15 0 6 10 1 13 8 9 4 5 11 12 7 2 14. 15 1 8 14 6 11 3 4 9 7 2 13 12 0 5 10 12 1 10 15 9 2 6 8 0 13 3 4 14 7 5 11. S2 = 3 13 4 7 15 2 8 14 12 0 1 10 6 9 11 5 S 6 = 10 15 4 2 7 12 9 5 6 1 13 14 0 11 3 8. 0 14 7 11 10 4 13 1 5 8 12 6 9 3 2 15 9 14 15 5 2 8 12 3 7 0 4 10 1 13 11 6. 13 8 10 1 3 15 4 2 11 6 7 12 0 5 14 9 4 3 2 12 9 5 15 10 11 14 1 7 6 0 8 13.
8 10 0 9 14 6 3 15 5 1 13 12 7 11 4 2 8 4 11 2 14 15 0 8 13 3 12 9 7 5 10 6 1. 13 0 11 7 4 9 1 10 14 3 5 12 2 15 8 6. S 3 = 13 7 0 9 3 4 6 10 2 8 5 14 12 11 15 1 S7 =. 13 6 4 9 8 15 3 0 11 1 2 12 5 10 14 7 1 4 11 13 12 3 7 14 10 15 6 8 0 5 9 2. 1 10 13 0 6 9 8 7 4 15 14 3 11 5 2 12 6 11 13 8 1 4 10 7 9 5 0 15 14 2 3 12. 7 13 14 3 0 6 9 10 1 2 8 5 11 12 4 15 13 2 8 4 6 15 11 1 10 9 3 14 5 0 12 7. S4 = 13 8 11 5 6 15 0 3 4 7 2 12 1 10 14 9 S8 = 1 15 13 8 10 3 7 4 12 5 6 11 0 14 9 2. 10 6 9 0 12 11 7 13 15 1 3 14 5 2 8 4 7 11 4 1 9 12 14 2 0 6 10 13 15 3 5 8. 3 15 0 6 10 1 13 8 9 4 5 11 12 7 2 14 2 1 14 7 4 10 8 13 15 12 9 0 3 5 6 11. DS01044A-page 2 2006 Microchip Technology Inc.
9 AN1044. FIGURE 7: SPEED-OPTIMIZED DES ALGORITHM. Plaintext Key IP Permutation Left Half Right Half E Permutation Subkey Generator IP-1 Permutation Ciphertext PS1 PS2 PS3 PS4 PS5 PS6 PS7 PS8. E Permutation PS1 PS2 PS3 PS4 PS5 PS6 PS7 PS8. 2006 Microchip Technology Inc. DS01044A-page 3. AN1044. Using the TDES Algorithm This implementation of TDES is accessed through three function calls: initTDES, TDES_encrypt and TDES_decrypt. Their usage is discussed below. initTDES. This function precalculates the subkey groups needed for TDES. By precalculating the subkeys, the Encryption and decryption Routines can be significantly enhanced for speed. Syntax void initTDES(unsigned int *KeyLocation).
10 Parameters KeyLocation: word-aligned starting address in RAM where the calculated subkeys will be stored. This requires a 384-byte (192-word) block of memory. Return Values None Pre-Conditions KeyLocation is either reserved or allocated memory of 384 bytes (192 words). unsigned int Key[12] is loaded with the Encryption /Decryption Keys, where Key[0-3] is the first DES key, Key[4-7] is the second key and Key[8-11] is the third key. The same keys used to encrypt a block must also be used to decrypt it. Side Effects Values at reserved addresses are changed. Example .. unsigned int *KeyPointer;. KeyPointer = (unsigned int*)malloc(384);. if(KeyPointer != NULL).