1 // Copyright 2015 The Go Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style
3 // license that can be found in the LICENSE file.
5 // Package tea implements the TEA algorithm, as defined in Needham and
6 // Wheeler's 1994 technical report, “TEA, a Tiny Encryption Algorithm”. See
7 // http://www.cix.co.uk/~klockstone/tea.pdf for details.
18 // BlockSize is the size of a TEA block, in bytes.
21 // KeySize is the size of a TEA key, in bytes.
24 // delta is the TEA key schedule constant.
27 // numRounds is the standard number of rounds in TEA.
31 // tea is an instance of the TEA cipher with a particular key.
37 // NewCipher returns an instance of the TEA cipher with the standard number of
38 // rounds. The key argument must be 16 bytes long.
39 func NewCipher(key []byte) (cipher.Block, error) {
40 return NewCipherWithRounds(key, numRounds)
43 // NewCipherWithRounds returns an instance of the TEA cipher with a given
44 // number of rounds, which must be even. The key argument must be 16 bytes
46 func NewCipherWithRounds(key []byte, rounds int) (cipher.Block, error) {
48 return nil, errors.New("tea: incorrect key size")
52 return nil, errors.New("tea: odd number of rounds specified")
63 // BlockSize returns the TEA block size, which is eight bytes. It is necessary
64 // to satisfy the Block interface in the package "crypto/cipher".
65 func (*tea) BlockSize() int {
69 // Encrypt encrypts the 8 byte buffer src using the key in t and stores the
70 // result in dst. Note that for amounts of data larger than a block, it is not
71 // safe to just call Encrypt on successive blocks; instead, use an encryption
72 // mode like CBC (see crypto/cipher/cbc.go).
73 func (t *tea) Encrypt(dst, src []byte) {
75 v0, v1 := e.Uint32(src), e.Uint32(src[4:])
76 k0, k1, k2, k3 := e.Uint32(t.key[0:]), e.Uint32(t.key[4:]), e.Uint32(t.key[8:]), e.Uint32(t.key[12:])
79 delta := uint32(delta)
81 for i := 0; i < t.rounds/2; i++ {
83 v0 += ((v1 << 4) + k0) ^ (v1 + sum) ^ ((v1 >> 5) + k1)
84 v1 += ((v0 << 4) + k2) ^ (v0 + sum) ^ ((v0 >> 5) + k3)
88 e.PutUint32(dst[4:], v1)
91 // Decrypt decrypts the 8 byte buffer src using the key in t and stores the
93 func (t *tea) Decrypt(dst, src []byte) {
95 v0, v1 := e.Uint32(src), e.Uint32(src[4:])
96 k0, k1, k2, k3 := e.Uint32(t.key[0:]), e.Uint32(t.key[4:]), e.Uint32(t.key[8:]), e.Uint32(t.key[12:])
98 delta := uint32(delta)
99 sum := delta * uint32(t.rounds/2) // in general, sum = delta * n
101 for i := 0; i < t.rounds/2; i++ {
102 v1 -= ((v0 << 4) + k2) ^ (v0 + sum) ^ ((v0 >> 5) + k3)
103 v0 -= ((v1 << 4) + k0) ^ (v1 + sum) ^ ((v1 >> 5) + k1)
108 e.PutUint32(dst[4:], v1)