Go to the source code of this file.
A Twofish_UInt32 must be an unsigned integer of at least 32 bits.
This type is used only internally in the implementation, so ideally it would not appear in the header file, but it is used inside the Twofish_key structure which means it has to be included here.
Decrypt a single block of data.
This function decrypts a single block of 16 bytes of data. If you want to decrypt a larger or variable-length message, you will have to use a cipher mode, such as CBC or CTR. These are outside the scope of this implementation.
The xkey structure is not modified by this routine, and can be used for further encryption and decryption operations.
Encrypt a single block of data.
This function encrypts a single block of 16 bytes of data. If you want to encrypt a larger or variable-length message, you will have to use a cipher mode, such as CBC or CTR. These are outside the scope of this implementation.
The xkey structure is not modified by this routine, and can be used for further encryption and decryption operations.
Initialise and test the Twofish implementation.
This function MUST be called before any other function in the Twofish implementation is called. It only needs to be called once.
Apart from initialising the implementation it performs a self test. If the Twofish_fatal function is not called, the code passed the test. (See the twofish.c file for details on the Twofish_fatal function.)
Convert a cipher key to the internal form used for encryption and decryption.
The cipher key is an array of bytes; the Twofish_Byte type is defined above to a type suitable on your platform.
Any key must be converted to an internal form in the Twofisk_key structure before it can be used. The encryption and decryption functions only work with the internal form. The conversion to internal form need only be done once for each key value.
Be sure to wipe all key storage, including the Twofish_key structure, once you are done with the key data. A simple memset( TwofishKey, 0, sizeof( TwofishKey ) ) will do just fine.
Unlike most implementations, this one allows any key size from 0 bytes to 32 bytes. According to the Twofish specifications, irregular key sizes are handled by padding the key with zeroes at the end until the key size is 16, 24, or 32 bytes, whichever comes first. Note that each key of irregular size is equivalent to exactly one key of 16, 24, or 32 bytes.
WARNING: Short keys have low entropy, and result in low security. Anything less than 8 bytes is utterly insecure. For good security use at least 16 bytes. I prefer to use 32-byte keys to prevent any collision attacks on the key.
The key length argument key_len must be in the proper range. If key_len is not in the range 0,...,32 this routine attempts to generate a fatal error (depending on the code environment), and at best (or worst) returns without having done anything.