U
    ´cic  ã                   @   s^   d dl Z d dlmZ d dlmZ ddlmZmZ G dd„ deƒZ	eee
ef e	dœd	d
„ZdS )é    N)Ú
ModuleType)ÚUnioné   )ÚWÚ	W_inversec                   @   sX   e Zd ZdZeeeef dœdd„Zeeef edœdd„Z	eeef edœd	d
„Z
dS )ÚKWPModea  Key Wrap with Padding (KWP) mode.

    This is a deterministic Authenticated Encryption (AE) mode
    for protecting cryptographic keys. See `NIST SP800-38F`_.

    It provides both confidentiality and authenticity, and it designed
    so that any bit of the ciphertext depends on all bits of the plaintext.

    This mode is only available for ciphers that operate on 128 bits blocks
    (e.g., AES).

    .. _`NIST SP800-38F`: http://csrc.nist.gov/publications/nistpubs/800-38F/SP-800-38F.pdf

    :undocumented: __init__
    )ÚfactoryÚkeyc                 C   s:   |j | _ | j dkrtdƒ‚|| _| ||j¡| _d| _d S )Né   zXKey Wrap with Padding mode is only available for ciphers that operate on 128 bits blocksF)Ú
block_sizeÚ
ValueErrorÚ_factoryÚnewZMODE_ECBÚ_cipherÚ_done)Úselfr   r	   © r   ú?/tmp/pip-unpacked-wheel-juw9_yux/Cryptodome/Cipher/_mode_kwp.pyÚ__init__   s    
zKWPMode.__init__)Ú	plaintextÚreturnc                 C   s˜   | j rtdƒ‚t|ƒdkr"tdƒ‚t|ƒdkr6tdƒ‚dt|ƒ d }|d|  }dt d	t|ƒ¡ }t|ƒdkr„| j || ¡}nt| j|| ƒ}|S )
z»Encrypt and authenticate (wrap) a cryptographic key.

        Args:
          plaintext:
            The cryptographic key to wrap.

        Returns:
            The wrapped key.
        ú(The cipher cannot be used more than oncer   z%The plaintext must be at least 1 bytel        zThe plaintext is too longé   ó    ó   ¦YY¦ú>I)r   r   ÚlenÚstructÚpackr   Zencryptr   )r   r   ÚpadlenZpaddedZAIVÚresr   r   r   Úseal'   s    zKWPMode.seal)Ú
ciphertextr   c                 C   sì   | j rtdƒ‚t|ƒd r"tdƒ‚t|ƒdk r6tdƒ‚t|ƒdkrP| j |¡}nt| j|ƒ}|dd… dkrttd	ƒ‚t d
|dd… ¡d }t|ƒd | }|dk s¬|dkr´td	ƒ‚|t|ƒ| d… d| krØtd	ƒ‚|dt|ƒ| … S )aw  Decrypt and authenticate (unwrap) a cryptographic key.

        Args:
          ciphertext:
            The cryptographic key to unwrap.
            It must be at least 16 bytes long, and its length
            must be a multiple of 8.

        Returns:
            The original key.

        Raises: ValueError
           If the ciphertext or the key are not valid.
        r   r   z3The ciphertext must have length multiple of 8 bytesr
   z-The ciphertext must be at least 24 bytes longNé   r   zIncorrect decryptionr   r   é   r   )r   r   r   r   Zdecryptr   r   Úunpack)r   r"   ÚSZPlenr   r   r   r   ÚunsealG   s$    zKWPMode.unsealN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   ÚbytesÚ	bytearrayr   r!   r'   r   r   r   r   r   	   s   
þ r   )r   Úkwargsr   c              
   K   sJ   z|d }W n2 t k
r> } ztdt|ƒ ƒ‚W 5 d}~X Y nX t| |ƒS )a%  Create a new block cipher in Key Wrap with Padding mode.

    Args:
      factory:
        A block cipher module, taken from `Cryptodome.Cipher`.
        The cipher must have block length of 16 bytes, such as AES.

    Keywords:
      key:
        The secret key to use to seal or unseal.
    r	   zMissing parameter:N)ÚKeyErrorÚ	TypeErrorÚstrr   )r   r.   r	   Úer   r   r   Ú_create_kwp_ciphert   s
    "r3   )r   Útypesr   Útypingr   Z_mode_kwr   r   Úobjectr   r,   r-   r3   r   r   r   r   Ú<module>   s   k
 ÿ