Skip to content

Implement verified x86-64 Triple DES ECB - #504

Closed
reaperhulk wants to merge 17 commits into
mainfrom
codex/3des-ecb-x86-64
Closed

reaperhulk wants to merge 17 commits into
mainfrom
codex/3des-ecb-x86-64

Conversation

@reaperhulk

@reaperhulk reaperhulk commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Adds complete baseline x86-64 Triple DES ECB: verified key expansion, single-block encryption/decryption, and multi-block ECB encryption/decryption, with generated assembly and an allocation-free, in-place Rust API. Accepts 16- and 24-byte keys, ignores parity bits, and rejects buffers with incomplete blocks without padding. Uses the specification merged in #459; no Spec/ or TCB/ changes.

The scalar implementation shares IP/FP across the three DES passes and keeps Feistel halves in registers. I reviewed OpenSSL's scalar DES and AWS-LC's DES. Their secret-indexed round/key tables cannot meet this repository's constant-time contract, so this version uses Boolean S-box circuits synthesized from the merged specification and fixed key permutations. All five entry points have functional, frame, ABI and constant-time proofs against the shared contracts. Removes the standalone design prose added in #459, following review feedback.

Validation: full lake build, emitter generation and --check (standard-axiom and compiler audits); all six repository check scripts; formatting and clippy; full Rust tests with Wycheproof, both normal and VG_CPU_FEATURES=none; all 500 published NIST ECB vectors in both directions, block-aligned splits, key parity and invalid lengths.

Benchmarks cover both directions and key sizes alongside OpenSSL. Earlier measurements used the original streaming API and need to be rerun for the revised in-place API before quoting throughput here.

Review feedback addressed: TripleDesEcb::new(key) expands a reusable key; encrypt and decrypt transform complete blocks in place. No allocation, direction stored in the context, buffering, or finalization. Invalid lengths leave the buffer unchanged. All 500 NIST cases pass with default features enabled and disabled, and formatting, architecture gates and root/benchmark clippy pass.

@reaperhulk
reaperhulk force-pushed the codex/3des-ecb-x86-64 branch from c16c998 to d8e8ece Compare October 1, 2026 19:52
@reaperhulk
reaperhulk changed the base branch from main to codex/benchmark-suite-timeout October 1, 2026 19:52
@reaperhulk
reaperhulk force-pushed the codex/3des-ecb-x86-64 branch from d8e8ece to fa6b742 Compare October 1, 2026 21:40
@reaperhulk
reaperhulk changed the base branch from codex/benchmark-suite-timeout to main October 1, 2026 21:41
@reaperhulk
reaperhulk force-pushed the codex/3des-ecb-x86-64 branch from 81c539b to ff7ae5a Compare October 1, 2026 21:50
Comment thread src/triple_des_ecb.rs Outdated

impl TripleDesEcb {
/// Initializes ECB with a 16- or 24-byte key and the chosen direction.
pub fn init(key: &[u8], direction: Direction) -> Result<Self, Error> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

no, this is a terrible api, wtf

@reaperhulk
reaperhulk force-pushed the codex/3des-ecb-x86-64 branch 6 times, most recently from 2925d54 to 1f31a8c Compare October 1, 2026 22:22
@reaperhulk
reaperhulk force-pushed the codex/3des-ecb-x86-64 branch from 1f31a8c to cfc436b Compare October 2, 2026 00:52
@reaperhulk
reaperhulk added this pull request to stack #551 October 2, 2026 00:57
@reaperhulk reaperhulk closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants