mpeg3css.c
上传用户:sun1608
上传日期:2007-02-02
资源大小:6116k
文件大小:34k
源码类别:

流媒体/Mpeg4/MP4

开发平台:

Visual C++

  1. /*
  2.  * Copyright (C) 2000 Derek Fawcus et. al.  <derek@spider.com>
  3.  * Ported to libmpeg3 by et. al.
  4.  *
  5.  * This code may be used under the terms of Version 2 of the GPL,
  6.  * read the file COPYING for details.
  7.  *
  8.  */
  9. /*
  10.  * These routines do some reordering of the supplied data before
  11.  * calling engine() to do the main work.
  12.  *
  13.  * The reordering seems similar to that done by the initial stages of
  14.  * the DES algorithm, in that it looks like it's just been done to
  15.  * try and make software decoding slower.  I'm not sure that it
  16.  * actually adds anything to the security.
  17.  *
  18.  * The nature of the shuffling is that the bits of the supplied
  19.  * parameter 'varient' are reorganised (and some inverted),  and
  20.  * the bytes of the parameter 'challenge' are reorganised.
  21.  *
  22.  * The reorganisation in each routine is different,  and the first
  23.  * (CryptKey1) does not bother of play with the 'varient' parameter.
  24.  *
  25.  * Since this code is only run once per disk change,  I've made the
  26.  * code table driven in order to improve readability.
  27.  *
  28.  * Since these routines are so similar to each other,  one could even
  29.  * abstract them all to one routine supplied a parameter determining
  30.  * the nature of the reordering it has to do.
  31.  */
  32. #if defined(HAVE_CSS) && defined(HAVE_LINUX_CDROM_H)
  33. #include "mpeg3css.h"
  34. #include "mpeg3private.h"
  35. #include <config.h>
  36. #include <unistd.h>
  37. #include <fcntl.h>
  38. #include <stdlib.h>
  39. #include <string.h>
  40. #include <sys/ioctl.h>
  41. #include <sys/types.h>
  42. #include <sys/stat.h>
  43. #include <sys/types.h>
  44. #include <linux/cdrom.h>
  45. #ifndef FIBMAP
  46. #define FIBMAP    _IO(0x00,1) /* bmap access */
  47. //#define FIBMAP 1
  48. #endif
  49. /* =================================== TABLES ================================ */
  50. static unsigned char mpeg3css_varients[] = 
  51. {
  52. 0xB7, 0x74, 0x85, 0xD0, 0xCC, 0xDB, 0xCA, 0x73,
  53. 0x03, 0xFE, 0x31, 0x03, 0x52, 0xE0, 0xB7, 0x42,
  54. 0x63, 0x16, 0xF2, 0x2A, 0x79, 0x52, 0xFF, 0x1B,
  55. 0x7A, 0x11, 0xCA, 0x1A, 0x9B, 0x40, 0xAD, 0x01
  56. };
  57. static unsigned char mpeg3css_secret[] = {0x55, 0xD6, 0xC4, 0xC5, 0x28};
  58. static unsigned char mpeg3css_table0[] = 
  59. {
  60. 0xB7, 0xF4, 0x82, 0x57, 0xDA, 0x4D, 0xDB, 0xE2,
  61. 0x2F, 0x52, 0x1A, 0xA8, 0x68, 0x5A, 0x8A, 0xFF,
  62. 0xFB, 0x0E, 0x6D, 0x35, 0xF7, 0x5C, 0x76, 0x12,
  63. 0xCE, 0x25, 0x79, 0x29, 0x39, 0x62, 0x08, 0x24,
  64. 0xA5, 0x85, 0x7B, 0x56, 0x01, 0x23, 0x68, 0xCF,
  65. 0x0A, 0xE2, 0x5A, 0xED, 0x3D, 0x59, 0xB0, 0xA9,
  66. 0xB0, 0x2C, 0xF2, 0xB8, 0xEF, 0x32, 0xA9, 0x40,
  67. 0x80, 0x71, 0xAF, 0x1E, 0xDE, 0x8F, 0x58, 0x88,
  68. 0xB8, 0x3A, 0xD0, 0xFC, 0xC4, 0x1E, 0xB5, 0xA0,
  69. 0xBB, 0x3B, 0x0F, 0x01, 0x7E, 0x1F, 0x9F, 0xD9,
  70. 0xAA, 0xB8, 0x3D, 0x9D, 0x74, 0x1E, 0x25, 0xDB,
  71. 0x37, 0x56, 0x8F, 0x16, 0xBA, 0x49, 0x2B, 0xAC,
  72. 0xD0, 0xBD, 0x95, 0x20, 0xBE, 0x7A, 0x28, 0xD0,
  73. 0x51, 0x64, 0x63, 0x1C, 0x7F, 0x66, 0x10, 0xBB,
  74. 0xC4, 0x56, 0x1A, 0x04, 0x6E, 0x0A, 0xEC, 0x9C,
  75. 0xD6, 0xE8, 0x9A, 0x7A, 0xCF, 0x8C, 0xDB, 0xB1,
  76. 0xEF, 0x71, 0xDE, 0x31, 0xFF, 0x54, 0x3E, 0x5E,
  77. 0x07, 0x69, 0x96, 0xB0, 0xCF, 0xDD, 0x9E, 0x47,
  78. 0xC7, 0x96, 0x8F, 0xE4, 0x2B, 0x59, 0xC6, 0xEE,
  79. 0xB9, 0x86, 0x9A, 0x64, 0x84, 0x72, 0xE2, 0x5B,
  80. 0xA2, 0x96, 0x58, 0x99, 0x50, 0x03, 0xF5, 0x38,
  81. 0x4D, 0x02, 0x7D, 0xE7, 0x7D, 0x75, 0xA7, 0xB8,
  82. 0x67, 0x87, 0x84, 0x3F, 0x1D, 0x11, 0xE5, 0xFC,
  83. 0x1E, 0xD3, 0x83, 0x16, 0xA5, 0x29, 0xF6, 0xC7,
  84. 0x15, 0x61, 0x29, 0x1A, 0x43, 0x4F, 0x9B, 0xAF,
  85. 0xC5, 0x87, 0x34, 0x6C, 0x0F, 0x3B, 0xA8, 0x1D,
  86. 0x45, 0x58, 0x25, 0xDC, 0xA8, 0xA3, 0x3B, 0xD1,
  87. 0x79, 0x1B, 0x48, 0xF2, 0xE9, 0x93, 0x1F, 0xFC,
  88. 0xDB, 0x2A, 0x90, 0xA9, 0x8A, 0x3D, 0x39, 0x18,
  89. 0xA3, 0x8E, 0x58, 0x6C, 0xE0, 0x12, 0xBB, 0x25,
  90. 0xCD, 0x71, 0x22, 0xA2, 0x64, 0xC6, 0xE7, 0xFB,
  91. 0xAD, 0x94, 0x77, 0x04, 0x9A, 0x39, 0xCF, 0x7C
  92. };
  93. static unsigned char mpeg3css_table1[] = 
  94. {
  95. 0x8C, 0x47, 0xB0, 0xE1, 0xEB, 0xFC, 0xEB, 0x56,
  96. 0x10, 0xE5, 0x2C, 0x1A, 0x5D, 0xEF, 0xBE, 0x4F,
  97. 0x08, 0x75, 0x97, 0x4B, 0x0E, 0x25, 0x8E, 0x6E,
  98. 0x39, 0x5A, 0x87, 0x53, 0xC4, 0x1F, 0xF4, 0x5C,
  99. 0x4E, 0xE6, 0x99, 0x30, 0xE0, 0x42, 0x88, 0xAB,
  100. 0xE5, 0x85, 0xBC, 0x8F, 0xD8, 0x3C, 0x54, 0xC9,
  101. 0x53, 0x47, 0x18, 0xD6, 0x06, 0x5B, 0x41, 0x2C,
  102. 0x67, 0x1E, 0x41, 0x74, 0x33, 0xE2, 0xB4, 0xE0,
  103. 0x23, 0x29, 0x42, 0xEA, 0x55, 0x0F, 0x25, 0xB4,
  104. 0x24, 0x2C, 0x99, 0x13, 0xEB, 0x0A, 0x0B, 0xC9,
  105. 0xF9, 0x63, 0x67, 0x43, 0x2D, 0xC7, 0x7D, 0x07,
  106. 0x60, 0x89, 0xD1, 0xCC, 0xE7, 0x94, 0x77, 0x74,
  107. 0x9B, 0x7E, 0xD7, 0xE6, 0xFF, 0xBB, 0x68, 0x14,
  108. 0x1E, 0xA3, 0x25, 0xDE, 0x3A, 0xA3, 0x54, 0x7B,
  109. 0x87, 0x9D, 0x50, 0xCA, 0x27, 0xC3, 0xA4, 0x50,
  110. 0x91, 0x27, 0xD4, 0xB0, 0x82, 0x41, 0x97, 0x79,
  111. 0x94, 0x82, 0xAC, 0xC7, 0x8E, 0xA5, 0x4E, 0xAA,
  112. 0x78, 0x9E, 0xE0, 0x42, 0xBA, 0x28, 0xEA, 0xB7,
  113. 0x74, 0xAD, 0x35, 0xDA, 0x92, 0x60, 0x7E, 0xD2,
  114. 0x0E, 0xB9, 0x24, 0x5E, 0x39, 0x4F, 0x5E, 0x63,
  115. 0x09, 0xB5, 0xFA, 0xBF, 0xF1, 0x22, 0x55, 0x1C,
  116. 0xE2, 0x25, 0xDB, 0xC5, 0xD8, 0x50, 0x03, 0x98,
  117. 0xC4, 0xAC, 0x2E, 0x11, 0xB4, 0x38, 0x4D, 0xD0,
  118. 0xB9, 0xFC, 0x2D, 0x3C, 0x08, 0x04, 0x5A, 0xEF,
  119. 0xCE, 0x32, 0xFB, 0x4C, 0x92, 0x1E, 0x4B, 0xFB,
  120. 0x1A, 0xD0, 0xE2, 0x3E, 0xDA, 0x6E, 0x7C, 0x4D,
  121. 0x56, 0xC3, 0x3F, 0x42, 0xB1, 0x3A, 0x23, 0x4D,
  122. 0x6E, 0x84, 0x56, 0x68, 0xF4, 0x0E, 0x03, 0x64,
  123. 0xD0, 0xA9, 0x92, 0x2F, 0x8B, 0xBC, 0x39, 0x9C,
  124. 0xAC, 0x09, 0x5E, 0xEE, 0xE5, 0x97, 0xBF, 0xA5,
  125. 0xCE, 0xFA, 0x28, 0x2C, 0x6D, 0x4F, 0xEF, 0x77,
  126. 0xAA, 0x1B, 0x79, 0x8E, 0x97, 0xB4, 0xC3, 0xF4
  127. };
  128. static unsigned char mpeg3css_table2[] = 
  129. {
  130. 0xB7, 0x75, 0x81, 0xD5, 0xDC, 0xCA, 0xDE, 0x66,
  131. 0x23, 0xDF, 0x15, 0x26, 0x62, 0xD1, 0x83, 0x77,
  132. 0xE3, 0x97, 0x76, 0xAF, 0xE9, 0xC3, 0x6B, 0x8E,
  133. 0xDA, 0xB0, 0x6E, 0xBF, 0x2B, 0xF1, 0x19, 0xB4,
  134. 0x95, 0x34, 0x48, 0xE4, 0x37, 0x94, 0x5D, 0x7B,
  135. 0x36, 0x5F, 0x65, 0x53, 0x07, 0xE2, 0x89, 0x11,
  136. 0x98, 0x85, 0xD9, 0x12, 0xC1, 0x9D, 0x84, 0xEC,
  137. 0xA4, 0xD4, 0x88, 0xB8, 0xFC, 0x2C, 0x79, 0x28,
  138. 0xD8, 0xDB, 0xB3, 0x1E, 0xA2, 0xF9, 0xD0, 0x44,
  139. 0xD7, 0xD6, 0x60, 0xEF, 0x14, 0xF4, 0xF6, 0x31,
  140. 0xD2, 0x41, 0x46, 0x67, 0x0A, 0xE1, 0x58, 0x27,
  141. 0x43, 0xA3, 0xF8, 0xE0, 0xC8, 0xBA, 0x5A, 0x5C,
  142. 0x80, 0x6C, 0xC6, 0xF2, 0xE8, 0xAD, 0x7D, 0x04,
  143. 0x0D, 0xB9, 0x3C, 0xC2, 0x25, 0xBD, 0x49, 0x63,
  144. 0x8C, 0x9F, 0x51, 0xCE, 0x20, 0xC5, 0xA1, 0x50,
  145. 0x92, 0x2D, 0xDD, 0xBC, 0x8D, 0x4F, 0x9A, 0x71,
  146. 0x2F, 0x30, 0x1D, 0x73, 0x39, 0x13, 0xFB, 0x1A,
  147. 0xCB, 0x24, 0x59, 0xFE, 0x05, 0x96, 0x57, 0x0F,
  148. 0x1F, 0xCF, 0x54, 0xBE, 0xF5, 0x06, 0x1B, 0xB2,
  149. 0x6D, 0xD3, 0x4D, 0x32, 0x56, 0x21, 0x33, 0x0B,
  150. 0x52, 0xE7, 0xAB, 0xEB, 0xA6, 0x74, 0x00, 0x4C,
  151. 0xB1, 0x7F, 0x82, 0x99, 0x87, 0x0E, 0x5E, 0xC0,
  152. 0x8F, 0xEE, 0x6F, 0x55, 0xF3, 0x7E, 0x08, 0x90,
  153. 0xFA, 0xB6, 0x64, 0x70, 0x47, 0x4A, 0x17, 0xA7,
  154. 0xB5, 0x40, 0x8A, 0x38, 0xE5, 0x68, 0x3E, 0x8B,
  155. 0x69, 0xAA, 0x9B, 0x42, 0xA5, 0x10, 0x01, 0x35,
  156. 0xFD, 0x61, 0x9E, 0xE6, 0x16, 0x9C, 0x86, 0xED,
  157. 0xCD, 0x2E, 0xFF, 0xC4, 0x5B, 0xA0, 0xAE, 0xCC,
  158. 0x4B, 0x3B, 0x03, 0xBB, 0x1C, 0x2A, 0xAC, 0x0C,
  159. 0x3F, 0x93, 0xC7, 0x72, 0x7A, 0x09, 0x22, 0x3D,
  160. 0x45, 0x78, 0xA9, 0xA8, 0xEA, 0xC9, 0x6A, 0xF7,
  161. 0x29, 0x91, 0xF0, 0x02, 0x18, 0x3A, 0x4E, 0x7C
  162. };
  163. static unsigned char mpeg3css_table3[] = 
  164. {
  165. 0x73, 0x51, 0x95, 0xE1, 0x12, 0xE4, 0xC0, 0x58,
  166. 0xEE, 0xF2, 0x08, 0x1B, 0xA9, 0xFA, 0x98, 0x4C,
  167. 0xA7, 0x33, 0xE2, 0x1B, 0xA7, 0x6D, 0xF5, 0x30,
  168. 0x97, 0x1D, 0xF3, 0x02, 0x60, 0x5A, 0x82, 0x0F,
  169. 0x91, 0xD0, 0x9C, 0x10, 0x39, 0x7A, 0x83, 0x85,
  170. 0x3B, 0xB2, 0xB8, 0xAE, 0x0C, 0x09, 0x52, 0xEA,
  171. 0x1C, 0xE1, 0x8D, 0x66, 0x4F, 0xF3, 0xDA, 0x92,
  172. 0x29, 0xB9, 0xD5, 0xC5, 0x77, 0x47, 0x22, 0x53,
  173. 0x14, 0xF7, 0xAF, 0x22, 0x64, 0xDF, 0xC6, 0x72,
  174. 0x12, 0xF3, 0x75, 0xDA, 0xD7, 0xD7, 0xE5, 0x02,
  175. 0x9E, 0xED, 0xDA, 0xDB, 0x4C, 0x47, 0xCE, 0x91,
  176. 0x06, 0x06, 0x6D, 0x55, 0x8B, 0x19, 0xC9, 0xEF,
  177. 0x8C, 0x80, 0x1A, 0x0E, 0xEE, 0x4B, 0xAB, 0xF2,
  178. 0x08, 0x5C, 0xE9, 0x37, 0x26, 0x5E, 0x9A, 0x90,
  179. 0x00, 0xF3, 0x0D, 0xB2, 0xA6, 0xA3, 0xF7, 0x26,
  180. 0x17, 0x48, 0x88, 0xC9, 0x0E, 0x2C, 0xC9, 0x02,
  181. 0xE7, 0x18, 0x05, 0x4B, 0xF3, 0x39, 0xE1, 0x20,
  182. 0x02, 0x0D, 0x40, 0xC7, 0xCA, 0xB9, 0x48, 0x30,
  183. 0x57, 0x67, 0xCC, 0x06, 0xBF, 0xAC, 0x81, 0x08,
  184. 0x24, 0x7A, 0xD4, 0x8B, 0x19, 0x8E, 0xAC, 0xB4,
  185. 0x5A, 0x0F, 0x73, 0x13, 0xAC, 0x9E, 0xDA, 0xB6,
  186. 0xB8, 0x96, 0x5B, 0x60, 0x88, 0xE1, 0x81, 0x3F,
  187. 0x07, 0x86, 0x37, 0x2D, 0x79, 0x14, 0x52, 0xEA,
  188. 0x73, 0xDF, 0x3D, 0x09, 0xC8, 0x25, 0x48, 0xD8,
  189. 0x75, 0x60, 0x9A, 0x08, 0x27, 0x4A, 0x2C, 0xB9,
  190. 0xA8, 0x8B, 0x8A, 0x73, 0x62, 0x37, 0x16, 0x02,
  191. 0xBD, 0xC1, 0x0E, 0x56, 0x54, 0x3E, 0x14, 0x5F,
  192. 0x8C, 0x8F, 0x6E, 0x75, 0x1C, 0x07, 0x39, 0x7B,
  193. 0x4B, 0xDB, 0xD3, 0x4B, 0x1E, 0xC8, 0x7E, 0xFE,
  194. 0x3E, 0x72, 0x16, 0x83, 0x7D, 0xEE, 0xF5, 0xCA,
  195. 0xC5, 0x18, 0xF9, 0xD8, 0x68, 0xAB, 0x38, 0x85,
  196. 0xA8, 0xF0, 0xA1, 0x73, 0x9F, 0x5D, 0x19, 0x0B,
  197. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  198. 0x33, 0x72, 0x39, 0x25, 0x67, 0x26, 0x6D, 0x71,
  199. 0x36, 0x77, 0x3C, 0x20, 0x62, 0x23, 0x68, 0x74,
  200. 0xC3, 0x82, 0xC9, 0x15, 0x57, 0x16, 0x5D, 0x81
  201. };
  202. static struct mpeg3_playkey mpeg3_pkey1a1 = {0x36b, {0x51,0x67,0x67,0xc5,0xe0}};
  203. static struct mpeg3_playkey mpeg3_pkey2a1 = {0x762, {0x2c,0xb2,0xc1,0x09,0xee}};
  204. static struct mpeg3_playkey mpeg3_pkey1b1 = {0x36b, {0x90,0xc1,0xd7,0x84,0x48}};
  205. static struct mpeg3_playkey mpeg3_pkey1a2 = {0x2f3, {0x51,0x67,0x67,0xc5,0xe0}};
  206. static struct mpeg3_playkey mpeg3_pkey2a2 = {0x730, {0x2c,0xb2,0xc1,0x09,0xee}};
  207. static struct mpeg3_playkey mpeg3_pkey1b2 = {0x2f3, {0x90,0xc1,0xd7,0x84,0x48}};
  208. static struct mpeg3_playkey mpeg3_pkey1a3 = {0x235, {0x51,0x67,0x67,0xc5,0xe0}};
  209. static struct mpeg3_playkey mpeg3_pkey1b3 = {0x235, {0x90,0xc1,0xd7,0x84,0x48}};
  210. static struct mpeg3_playkey mpeg3_pkey3a1 = {0x249, {0xb7,0x3f,0xd4,0xaa,0x14}}; /* DVD specific ? */
  211. static struct mpeg3_playkey mpeg3_pkey4a1 = {0x028, {0x53,0xd4,0xf7,0xd9,0x8f}}; /* DVD specific ? */
  212. static struct mpeg3_playkey *mpeg3_playkeys[] = 
  213. {
  214. &mpeg3_pkey1a1, &mpeg3_pkey2a1, &mpeg3_pkey1b1,
  215. &mpeg3_pkey1a2, &mpeg3_pkey2a2, &mpeg3_pkey1b2,
  216. &mpeg3_pkey1a3, &mpeg3_pkey1b3,
  217. &mpeg3_pkey3a1, &mpeg3_pkey4a1,
  218. NULL
  219. };
  220. /*
  221.  *
  222.  *  some tables used for descrambling sectors and/or decrypting title keys
  223.  *
  224.  */
  225. static unsigned char csstab1[256]=
  226. {
  227. 0x33,0x73,0x3b,0x26,0x63,0x23,0x6b,0x76,0x3e,0x7e,0x36,0x2b,0x6e,0x2e,0x66,0x7b,
  228. 0xd3,0x93,0xdb,0x06,0x43,0x03,0x4b,0x96,0xde,0x9e,0xd6,0x0b,0x4e,0x0e,0x46,0x9b,
  229. 0x57,0x17,0x5f,0x82,0xc7,0x87,0xcf,0x12,0x5a,0x1a,0x52,0x8f,0xca,0x8a,0xc2,0x1f,
  230. 0xd9,0x99,0xd1,0x00,0x49,0x09,0x41,0x90,0xd8,0x98,0xd0,0x01,0x48,0x08,0x40,0x91,
  231. 0x3d,0x7d,0x35,0x24,0x6d,0x2d,0x65,0x74,0x3c,0x7c,0x34,0x25,0x6c,0x2c,0x64,0x75,
  232. 0xdd,0x9d,0xd5,0x04,0x4d,0x0d,0x45,0x94,0xdc,0x9c,0xd4,0x05,0x4c,0x0c,0x44,0x95,
  233. 0x59,0x19,0x51,0x80,0xc9,0x89,0xc1,0x10,0x58,0x18,0x50,0x81,0xc8,0x88,0xc0,0x11,
  234. 0xd7,0x97,0xdf,0x02,0x47,0x07,0x4f,0x92,0xda,0x9a,0xd2,0x0f,0x4a,0x0a,0x42,0x9f,
  235. 0x53,0x13,0x5b,0x86,0xc3,0x83,0xcb,0x16,0x5e,0x1e,0x56,0x8b,0xce,0x8e,0xc6,0x1b,
  236. 0xb3,0xf3,0xbb,0xa6,0xe3,0xa3,0xeb,0xf6,0xbe,0xfe,0xb6,0xab,0xee,0xae,0xe6,0xfb,
  237. 0x37,0x77,0x3f,0x22,0x67,0x27,0x6f,0x72,0x3a,0x7a,0x32,0x2f,0x6a,0x2a,0x62,0x7f,
  238. 0xb9,0xf9,0xb1,0xa0,0xe9,0xa9,0xe1,0xf0,0xb8,0xf8,0xb0,0xa1,0xe8,0xa8,0xe0,0xf1,
  239. 0x5d,0x1d,0x55,0x84,0xcd,0x8d,0xc5,0x14,0x5c,0x1c,0x54,0x85,0xcc,0x8c,0xc4,0x15,
  240. 0xbd,0xfd,0xb5,0xa4,0xed,0xad,0xe5,0xf4,0xbc,0xfc,0xb4,0xa5,0xec,0xac,0xe4,0xf5,
  241. 0x39,0x79,0x31,0x20,0x69,0x29,0x61,0x70,0x38,0x78,0x30,0x21,0x68,0x28,0x60,0x71,
  242. 0xb7,0xf7,0xbf,0xa2,0xe7,0xa7,0xef,0xf2,0xba,0xfa,0xb2,0xaf,0xea,0xaa,0xe2,0xff
  243. };
  244. static unsigned char lfsr1_bits0[256]=
  245. {
  246. 0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,0x09,0x08,0x0b,0x0a,0x0d,0x0c,0x0f,0x0e,
  247. 0x12,0x13,0x10,0x11,0x16,0x17,0x14,0x15,0x1b,0x1a,0x19,0x18,0x1f,0x1e,0x1d,0x1c,
  248. 0x24,0x25,0x26,0x27,0x20,0x21,0x22,0x23,0x2d,0x2c,0x2f,0x2e,0x29,0x28,0x2b,0x2a,
  249. 0x36,0x37,0x34,0x35,0x32,0x33,0x30,0x31,0x3f,0x3e,0x3d,0x3c,0x3b,0x3a,0x39,0x38,
  250. 0x49,0x48,0x4b,0x4a,0x4d,0x4c,0x4f,0x4e,0x40,0x41,0x42,0x43,0x44,0x45,0x46,0x47,
  251. 0x5b,0x5a,0x59,0x58,0x5f,0x5e,0x5d,0x5c,0x52,0x53,0x50,0x51,0x56,0x57,0x54,0x55,
  252. 0x6d,0x6c,0x6f,0x6e,0x69,0x68,0x6b,0x6a,0x64,0x65,0x66,0x67,0x60,0x61,0x62,0x63,
  253. 0x7f,0x7e,0x7d,0x7c,0x7b,0x7a,0x79,0x78,0x76,0x77,0x74,0x75,0x72,0x73,0x70,0x71,
  254. 0x92,0x93,0x90,0x91,0x96,0x97,0x94,0x95,0x9b,0x9a,0x99,0x98,0x9f,0x9e,0x9d,0x9c,
  255. 0x80,0x81,0x82,0x83,0x84,0x85,0x86,0x87,0x89,0x88,0x8b,0x8a,0x8d,0x8c,0x8f,0x8e,
  256. 0xb6,0xb7,0xb4,0xb5,0xb2,0xb3,0xb0,0xb1,0xbf,0xbe,0xbd,0xbc,0xbb,0xba,0xb9,0xb8,
  257. 0xa4,0xa5,0xa6,0xa7,0xa0,0xa1,0xa2,0xa3,0xad,0xac,0xaf,0xae,0xa9,0xa8,0xab,0xaa,
  258. 0xdb,0xda,0xd9,0xd8,0xdf,0xde,0xdd,0xdc,0xd2,0xd3,0xd0,0xd1,0xd6,0xd7,0xd4,0xd5,
  259. 0xc9,0xc8,0xcb,0xca,0xcd,0xcc,0xcf,0xce,0xc0,0xc1,0xc2,0xc3,0xc4,0xc5,0xc6,0xc7,
  260. 0xff,0xfe,0xfd,0xfc,0xfb,0xfa,0xf9,0xf8,0xf6,0xf7,0xf4,0xf5,0xf2,0xf3,0xf0,0xf1,
  261. 0xed,0xec,0xef,0xee,0xe9,0xe8,0xeb,0xea,0xe4,0xe5,0xe6,0xe7,0xe0,0xe1,0xe2,0xe3
  262. };
  263. static unsigned char lfsr1_bits1[512]=
  264. {
  265. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  266. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  267. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  268. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  269. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  270. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  271. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  272. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  273. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  274. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  275. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  276. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  277. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  278. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  279. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  280. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  281. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  282. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  283. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  284. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  285. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  286. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  287. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  288. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  289. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  290. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  291. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  292. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  293. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  294. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  295. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,
  296. 0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff
  297. };
  298. /* Reverse the order of the bits within a byte.
  299.  */
  300. static unsigned char bit_reverse[256]=
  301. {
  302. 0x00,0x80,0x40,0xc0,0x20,0xa0,0x60,0xe0,0x10,0x90,0x50,0xd0,0x30,0xb0,0x70,0xf0,
  303. 0x08,0x88,0x48,0xc8,0x28,0xa8,0x68,0xe8,0x18,0x98,0x58,0xd8,0x38,0xb8,0x78,0xf8,
  304. 0x04,0x84,0x44,0xc4,0x24,0xa4,0x64,0xe4,0x14,0x94,0x54,0xd4,0x34,0xb4,0x74,0xf4,
  305. 0x0c,0x8c,0x4c,0xcc,0x2c,0xac,0x6c,0xec,0x1c,0x9c,0x5c,0xdc,0x3c,0xbc,0x7c,0xfc,
  306. 0x02,0x82,0x42,0xc2,0x22,0xa2,0x62,0xe2,0x12,0x92,0x52,0xd2,0x32,0xb2,0x72,0xf2,
  307. 0x0a,0x8a,0x4a,0xca,0x2a,0xaa,0x6a,0xea,0x1a,0x9a,0x5a,0xda,0x3a,0xba,0x7a,0xfa,
  308. 0x06,0x86,0x46,0xc6,0x26,0xa6,0x66,0xe6,0x16,0x96,0x56,0xd6,0x36,0xb6,0x76,0xf6,
  309. 0x0e,0x8e,0x4e,0xce,0x2e,0xae,0x6e,0xee,0x1e,0x9e,0x5e,0xde,0x3e,0xbe,0x7e,0xfe,
  310. 0x01,0x81,0x41,0xc1,0x21,0xa1,0x61,0xe1,0x11,0x91,0x51,0xd1,0x31,0xb1,0x71,0xf1,
  311. 0x09,0x89,0x49,0xc9,0x29,0xa9,0x69,0xe9,0x19,0x99,0x59,0xd9,0x39,0xb9,0x79,0xf9,
  312. 0x05,0x85,0x45,0xc5,0x25,0xa5,0x65,0xe5,0x15,0x95,0x55,0xd5,0x35,0xb5,0x75,0xf5,
  313. 0x0d,0x8d,0x4d,0xcd,0x2d,0xad,0x6d,0xed,0x1d,0x9d,0x5d,0xdd,0x3d,0xbd,0x7d,0xfd,
  314. 0x03,0x83,0x43,0xc3,0x23,0xa3,0x63,0xe3,0x13,0x93,0x53,0xd3,0x33,0xb3,0x73,0xf3,
  315. 0x0b,0x8b,0x4b,0xcb,0x2b,0xab,0x6b,0xeb,0x1b,0x9b,0x5b,0xdb,0x3b,0xbb,0x7b,0xfb,
  316. 0x07,0x87,0x47,0xc7,0x27,0xa7,0x67,0xe7,0x17,0x97,0x57,0xd7,0x37,0xb7,0x77,0xf7,
  317. 0x0f,0x8f,0x4f,0xcf,0x2f,0xaf,0x6f,0xef,0x1f,0x9f,0x5f,0xdf,0x3f,0xbf,0x7f,0xff
  318. };
  319. /* ================================= Functions ====================================== */
  320. /*
  321.  * We use two LFSR's (seeded from some of the input data bytes) to
  322.  * generate two streams of pseudo-random bits.  These two bit streams
  323.  * are then combined by simply adding with carry to generate a final
  324.  * sequence of pseudo-random bits which is stored in the buffer that
  325.  * 'output' points to the end of - len is the size of this buffer.
  326.  *
  327.  * The first LFSR is of degree 25,  and has a polynomial of:
  328.  * x^13 + x^5 + x^4 + x^1 + 1
  329.  *
  330.  * The second LSFR is of degree 17,  and has a (primitive) polynomial of:
  331.  * x^15 + x^1 + 1
  332.  *
  333.  * I don't know if these polynomials are primitive modulo 2,  and thus
  334.  * represent maximal-period LFSR's.
  335.  *
  336.  *
  337.  * Note that we take the output of each LFSR from the new shifted in
  338.  * bit,  not the old shifted out bit.  Thus for ease of use the LFSR's
  339.  * are implemented in bit reversed order.
  340.  *
  341.  */
  342. #define  BIT0(x) ((x) & 1)
  343. #define  BIT1(x) (((x) >> 1) & 1)
  344. static void generate_bits(unsigned char *output, int len, struct mpeg3_block const *s)
  345. {
  346. unsigned long lfsr0, lfsr1;
  347. unsigned char carry;
  348. /* In order to ensure that the LFSR works we need to ensure that the
  349.  * initial values are non-zero.  Thus when we initialise them from
  350.  * the seed,  we ensure that a bit is set.
  351.  */
  352. lfsr0 = (s->b[0] << 17) | (s->b[1] << 9) | ((s->b[2] & ~7) << 1) | 8 | (s->b[2] & 7);
  353. lfsr1 = (s->b[3] << 9) | 0x100 | s->b[4];
  354. ++output;
  355. carry = 0;
  356. do{
  357. int bit;
  358. unsigned char val;
  359. for (bit = 0, val = 0; bit < 8; ++bit) 
  360. {
  361. unsigned char o_lfsr0, o_lfsr1; /* Actually only 1 bit each */
  362. unsigned char combined;
  363. o_lfsr0 = ((lfsr0 >> 24) ^ (lfsr0 >> 21) ^ (lfsr0 >> 20) ^ (lfsr0 >> 12)) & 1;
  364.   lfsr0 = (lfsr0 << 1) | o_lfsr0;
  365. o_lfsr1 = ((lfsr1 >> 16) ^ (lfsr1 >> 2)) & 1;
  366.   lfsr1 = (lfsr1 << 1) | o_lfsr1;
  367. combined = !o_lfsr1 + carry + !o_lfsr0;
  368. carry = BIT1(combined);
  369. val |= BIT0(combined) << bit;
  370. }
  371. *--output = val;
  372. }while (--len > 0);
  373. }
  374. /*
  375.  * This encryption engine implements one of 32 variations
  376.  * one the same theme depending upon the choice in the
  377.  * varient parameter (0 - 31).
  378.  *
  379.  * The algorithm itself manipulates a 40 bit input into
  380.  * a 40 bit output.
  381.  * The parameter 'input' is 80 bits.  It consists of
  382.  * the 40 bit input value that is to be encrypted followed
  383.  * by a 40 bit seed value for the pseudo random number
  384.  * generators.
  385.  */
  386. static void css_engine(int varient, unsigned char const *input, struct mpeg3_block *output)
  387. {
  388. unsigned char cse, term, index;
  389. struct mpeg3_block temp1;
  390. struct mpeg3_block temp2;
  391. unsigned char bits[30];
  392. int i;
  393. /* Feed the secret into the input values such that
  394.  * we alter the seed to the LFSR's used above,  then
  395.  * generate the bits to play with.
  396.  */
  397. for(i = 5; --i >= 0; )
  398. temp1.b[i] = input[5 + i] ^ mpeg3css_secret[i] ^ mpeg3css_table2[i];
  399. generate_bits(&bits[29], sizeof bits, &temp1);
  400. /* This term is used throughout the following to
  401.  * select one of 32 different variations on the
  402.  * algorithm.
  403.  */
  404. cse = mpeg3css_varients[varient] ^ mpeg3css_table2[varient];
  405. /* Now the actual blocks doing the encryption.  Each
  406.  * of these works on 40 bits at a time and are quite
  407.  * similar.
  408.  */
  409. for(i = 5, term = 0; --i >= 0; term = input[i]) 
  410. {
  411. index = bits[25 + i] ^ input[i];
  412. index = mpeg3css_table1[index] ^ ~mpeg3css_table2[index] ^ cse;
  413. temp1.b[i] = mpeg3css_table2[index] ^ mpeg3css_table3[index] ^ term;
  414. }
  415. temp1.b[4] ^= temp1.b[0];
  416. for(i = 5, term = 0; --i >= 0; term = temp1.b[i]) 
  417. {
  418. index = bits[20 + i] ^ temp1.b[i];
  419. index = mpeg3css_table1[index] ^ ~mpeg3css_table2[index] ^ cse;
  420. temp2.b[i] = mpeg3css_table2[index] ^ mpeg3css_table3[index] ^ term;
  421. }
  422. temp2.b[4] ^= temp2.b[0];
  423. for (i = 5, term = 0; --i >= 0; term = temp2.b[i]) 
  424. {
  425. index = bits[15 + i] ^ temp2.b[i];
  426. index = mpeg3css_table1[index] ^ ~mpeg3css_table2[index] ^ cse;
  427. index = mpeg3css_table2[index] ^ mpeg3css_table3[index] ^ term;
  428. temp1.b[i] = mpeg3css_table0[index] ^ mpeg3css_table2[index];
  429. }
  430. temp1.b[4] ^= temp1.b[0];
  431. for (i = 5, term = 0; --i >= 0; term = temp1.b[i]) 
  432. {
  433. index = bits[10 + i] ^ temp1.b[i];
  434. index = mpeg3css_table1[index] ^ ~mpeg3css_table2[index] ^ cse;
  435. index = mpeg3css_table2[index] ^ mpeg3css_table3[index] ^ term;
  436. temp2.b[i] = mpeg3css_table0[index] ^ mpeg3css_table2[index];
  437. }
  438. temp2.b[4] ^= temp2.b[0];
  439. for (i = 5, term = 0; --i >= 0; term = temp2.b[i]) 
  440. {
  441. index = bits[5 + i] ^ temp2.b[i];
  442. index = mpeg3css_table1[index] ^ ~mpeg3css_table2[index] ^ cse;
  443. temp1.b[i] = mpeg3css_table2[index] ^ mpeg3css_table3[index] ^ term;
  444. }
  445. temp1.b[4] ^= temp1.b[0];
  446. for (i = 5, term = 0; --i >= 0; term = temp1.b[i]) 
  447. {
  448. index = bits[i] ^ temp1.b[i];
  449. index = mpeg3css_table1[index] ^ ~mpeg3css_table2[index] ^ cse;
  450. output->b[i] = mpeg3css_table2[index] ^ mpeg3css_table3[index] ^ term;
  451. }
  452. }
  453. static void crypt_key1(mpeg3_css_t *css, int varient, unsigned char const *challenge, struct mpeg3_block *key)
  454. {
  455. static unsigned char perm_challenge[] = {1, 3, 0, 7, 5, 2, 9, 6, 4, 8};
  456. unsigned char scratch[10];
  457. int i;
  458. for (i = 9; i >= 0; i--)
  459. scratch[i] = challenge[perm_challenge[i]];
  460. css_engine(varient, scratch, key);
  461. }
  462. /* This shuffles the bits in varient to make perm_varient such that
  463.  *                4 -> !3
  464.  *                3 ->  4
  465.  * varient bits:  2 ->  0  perm_varient bits
  466.  *                1 ->  2
  467.  *                0 -> !1
  468.  */
  469. static void crypt_key2(mpeg3_css_t *css, int varient, unsigned char const *challenge, struct mpeg3_block *key)
  470. {
  471. static unsigned char perm_challenge[] = {6, 1, 9, 3, 8, 5, 7, 4, 0, 2};
  472. static unsigned char perm_varient[] = 
  473. {
  474. 0x0a, 0x08, 0x0e, 0x0c, 0x0b, 0x09, 0x0f, 0x0d,
  475. 0x1a, 0x18, 0x1e, 0x1c, 0x1b, 0x19, 0x1f, 0x1d,
  476. 0x02, 0x00, 0x06, 0x04, 0x03, 0x01, 0x07, 0x05,
  477. 0x12, 0x10, 0x16, 0x14, 0x13, 0x11, 0x17, 0x15
  478. };
  479. unsigned char scratch[10];
  480. int i;
  481. for(i = 9; i >= 0; i--)
  482. scratch[i] = css->challenge[perm_challenge[i]];
  483. css_engine(perm_varient[varient], scratch, key);
  484. }
  485. /* This shuffles the bits in varient to make perm_varient such that
  486.  *                4 ->  0
  487.  *                3 -> !1
  488.  * varient bits:  2 -> !4  perm_varient bits
  489.  *                1 ->  2
  490.  *                0 ->  3
  491.  */
  492. static void crypt_bus_key(mpeg3_css_t *css, int varient, unsigned char const *challenge, struct mpeg3_block *key)
  493. {
  494. static unsigned char perm_challenge[] = {4,0,3,5,7, 2,8,6,1,9};
  495. static unsigned char perm_varient[] = {
  496. 0x12, 0x1a, 0x16, 0x1e, 0x02, 0x0a, 0x06, 0x0e,
  497. 0x10, 0x18, 0x14, 0x1c, 0x00, 0x08, 0x04, 0x0c,
  498. 0x13, 0x1b, 0x17, 0x1f, 0x03, 0x0b, 0x07, 0x0f,
  499. 0x11, 0x19, 0x15, 0x1d, 0x01, 0x09, 0x05, 0x0d};
  500. unsigned char scratch[10];
  501. int i;
  502. for(i = 9; i >= 0; i--)
  503. scratch[i] = css->challenge[perm_challenge[i]];
  504. css_engine(perm_varient[varient], scratch, key);
  505. }
  506. static int get_asf(mpeg3_css_t *css)
  507. {
  508. dvd_authinfo ai;
  509. ai.type = DVD_LU_SEND_ASF;
  510. ai.lsasf.agid = 0;
  511. ai.lsasf.asf = 0;
  512. if(ioctl(css->fd, DVD_AUTH, &ai))
  513. {
  514. /* Exit here for a hard drive or unencrypted CD-ROM. */
  515. return 1;
  516. }
  517. return 0;
  518. }
  519. static int authenticate_drive(mpeg3_css_t *css, const unsigned char *key)
  520. {
  521. int i;
  522. for(i = 0; i < 5; i++)
  523. css->key1.b[i] = key[4 - i];
  524. for(i = 0; i < 32; ++i)
  525. {
  526. crypt_key1(css, i, css->challenge, &(css->keycheck));
  527. if(memcmp(css->keycheck.b, css->key1.b, 5) == 0)
  528. {
  529. css->varient = i;
  530. return 0;
  531. }
  532. }
  533. if (css->varient == -1) return 1;
  534. return 0;
  535. }
  536. /* Simulation of a non-CSS compliant host (i.e. the authentication fails,
  537.  * but idea is here for a real CSS compliant authentication scheme). */
  538. static int hostauth(mpeg3_css_t *css, dvd_authinfo *ai)
  539. {
  540. int i;
  541. switch(ai->type) 
  542. {
  543. /* Host data receive (host changes state) */
  544. case DVD_LU_SEND_AGID:
  545. ai->type = DVD_HOST_SEND_CHALLENGE;
  546. break;
  547. case DVD_LU_SEND_KEY1:
  548. /* printf("Key 1: %02x %02x %02x %02x %02xn",  */
  549. /*  ai->lsk.key[4], ai->lsk.key[3], ai->lsk.key[2], ai->lsk.key[1], ai->lsk.key[0]); */
  550. if(authenticate_drive(css, ai->lsk.key)) 
  551. {
  552. ai->type = DVD_AUTH_FAILURE;
  553. return 1;
  554. }
  555. ai->type = DVD_LU_SEND_CHALLENGE;
  556. break;
  557. case DVD_LU_SEND_CHALLENGE:
  558. for(i = 0; i < 10; i++)
  559. css->challenge[i] = ai->hsc.chal[9-i];
  560. crypt_key2(css, css->varient, css->challenge, &(css->key2));
  561. ai->type = DVD_HOST_SEND_KEY2;
  562. break;
  563. /* Host data send */
  564. case DVD_HOST_SEND_CHALLENGE:
  565. for(i = 0; i < 10; i++)
  566. ai->hsc.chal[9 - i] = css->challenge[i];
  567. /* Returning data, let LU change state */
  568. break;
  569. case DVD_HOST_SEND_KEY2:
  570. for(i = 0; i < 5; i++)
  571. {
  572. ai->hsk.key[4 - i] = css->key2.b[i];
  573. }
  574. /* printf("Key 2: %02x %02x %02x %02x %02xn",  */
  575. /*  ai->hsk.key[4], ai->hsk.key[3], ai->hsk.key[2], ai->hsk.key[1], ai->hsk.key[0]); */
  576. /* Returning data, let LU change state */
  577. break;
  578. default:
  579. fprintf(stderr, "Got invalid state %dn", ai->type);
  580. return 1;
  581. }
  582. return 0;
  583. }
  584. static int get_title_key(mpeg3_css_t *css, int agid, int lba, unsigned char *key)
  585. {
  586. dvd_authinfo ai;
  587. int i;
  588. ai.type = DVD_LU_SEND_TITLE_KEY;
  589. ai.lstk.agid = agid;
  590. ai.lstk.lba = lba;
  591. if(ioctl(css->fd, DVD_AUTH, &ai))
  592. {
  593. //perror("GetTitleKey");
  594. return 1;
  595. }
  596. for (i = 0; i < 5; i++)
  597. {
  598. ai.lstk.title_key[i] ^= key[4 - (i % 5)];
  599. }
  600. /* Save the title key */
  601. for(i = 0; i < 5; i++)
  602. {
  603. css->title_key[i] = ai.lstk.title_key[i];
  604. }
  605. return 0;
  606. }
  607. static int get_disk_key(mpeg3_css_t *css, int agid, unsigned char *key)
  608. {
  609. dvd_struct s;
  610. int index, i;
  611. s.type = DVD_STRUCT_DISCKEY;
  612. s.disckey.agid = agid;
  613. memset(s.disckey.value, 0, MPEG3_DVD_PACKET_SIZE);
  614. if(ioctl(css->fd, DVD_READ_STRUCT, &s) < 0)
  615. {
  616. /*perror("get_disk_key"); */
  617. return 1;
  618. }
  619. for(index = 0; index < sizeof s.disckey.value; index ++)
  620. s.disckey.value[index] ^= key[4 - (index%5)];
  621. /* Save disk key */
  622. for(i = 0; i < MPEG3_DVD_PACKET_SIZE; i++)
  623. css->disk_key[i] = s.disckey.value[i];
  624. return 0;
  625. }
  626. static int validate(mpeg3_css_t *css, int lba, int do_title)
  627. {
  628. dvd_authinfo ai;
  629. dvd_struct dvds;
  630. int result = 0;
  631. int i, rv, tries, agid;
  632. memset(&ai, 0, sizeof (ai));
  633. memset(&dvds, 0, sizeof (dvds));
  634. if(get_asf(css)) return 1;
  635. /* Init sequence, request AGID */
  636. for(tries = 1, rv = -1; rv == -1 && tries < 4; tries++)
  637. {
  638. ai.type = DVD_LU_SEND_AGID;
  639. ai.lsa.agid = 0;
  640. rv = ioctl(css->fd, DVD_AUTH, &ai);
  641. if(rv == -1)
  642. {
  643. /* perror("validate: request AGID"); */
  644. ai.type = DVD_INVALIDATE_AGID;
  645. ai.lsa.agid = 0;
  646. ioctl(css->fd, DVD_AUTH, &ai);
  647. }
  648. }
  649. if(tries >= 4) return 1;
  650. for(i = 0; i < 10; i++) css->challenge[i] = i;
  651. /* Send AGID to host */
  652. if(hostauth(css, &ai)) return 1;
  653. /* Get challenge from host */
  654. if(hostauth(css, &ai)) return 1;
  655. agid = ai.lsa.agid;
  656. /* Send challenge to LU */
  657. if(ioctl(css->fd, DVD_AUTH, &ai) < 0) return 1;
  658. /* Get key1 from LU */
  659. if(ioctl(css->fd, DVD_AUTH, &ai) < 0) return 1;
  660. /* Send key1 to host */
  661. if(hostauth(css, &ai)) return 1;
  662. /* Get challenge from LU */
  663. if(ioctl(css->fd, DVD_AUTH, &ai) < 0) return 1;
  664. /* Send challenge to host */
  665. if(hostauth(css, &ai)) return 1;
  666. /* Get key2 from host */
  667. if(hostauth(css, &ai)) return 1;
  668. /* Send key2 to LU */
  669. if(ioctl(css->fd, DVD_AUTH, &ai) < 0) 
  670. {
  671. perror("validate: Send key2 to LU");
  672. return 1;
  673. }
  674. if(ai.type == DVD_AUTH_FAILURE)
  675. {
  676. fprintf(stderr, "validate: authorization failedn");
  677. return 1;
  678. }
  679. memcpy(css->challenge, css->key1.b, 5);
  680. memcpy(css->challenge + 5, css->key2.b, 5);
  681. crypt_bus_key(css, css->varient, css->challenge, &(css->keycheck));
  682. get_asf(css);
  683. if(do_title)
  684. return get_title_key(css, agid, lba, css->keycheck.b);
  685. else
  686. return get_disk_key(css, agid, css->keycheck.b);
  687. return 0;
  688. }
  689. static int validate_path(mpeg3_css_t *css, int do_title)
  690. {
  691. int result = 0;
  692. int lba = 0, file_fd;
  693. if(do_title)
  694. {
  695. if((file_fd = open(css->path, O_RDONLY)) == -1)
  696. {
  697. perror("validate_path: open");
  698. return 1;
  699. }
  700. if(ioctl(file_fd, FIBMAP, &lba) != 0)
  701. {
  702. perror("validate_path: FIBMAP");
  703. close(file_fd);
  704. return 1;
  705. }
  706. close(file_fd);
  707. }
  708. result = mpeg3io_device(css->path, css->device_path);
  709. //printf("validate_path 1 %dn", result);
  710. if(!result) result = (css->fd = open(css->device_path, O_RDONLY | O_NONBLOCK)) < 0;
  711. //printf("validate_path 2 %dn", result);
  712. if(!result) result = validate(css, lba, do_title);
  713. //printf("validate_path 3 %dn", result);
  714. /* Definitely encrypted if we got here. */
  715. if(!result) css->encrypted = 1;
  716. close(css->fd);
  717. return result;
  718. }
  719. /*
  720.  *
  721.  * this function is only used internally when decrypting title key
  722.  *
  723.  */
  724. static void title_key(unsigned char *key, unsigned char *im, unsigned char invert)
  725. {
  726. unsigned int lfsr1_lo, lfsr1_hi, lfsr0, combined;
  727. unsigned char o_lfsr0, o_lfsr1;
  728. unsigned char k[5];
  729. int i;
  730. lfsr1_lo = im[0] | 0x100;
  731. lfsr1_hi = im[1];
  732. lfsr0 = ((im[4] << 17) | (im[3] << 9) | (im[2] << 1)) + 8 - (im[2]&7);
  733. lfsr0 = (bit_reverse[lfsr0 & 0xff] << 24) | (bit_reverse[(lfsr0 >> 8) & 0xff] << 16)
  734.   | (bit_reverse[(lfsr0 >> 16) & 0xff] << 8) | bit_reverse[(lfsr0 >> 24) & 0xff];
  735. combined = 0;
  736. for (i = 0; i < 5; ++i) {
  737. o_lfsr1 = lfsr1_bits0[lfsr1_hi] ^ lfsr1_bits1[lfsr1_lo];
  738.   lfsr1_hi = lfsr1_lo>>1;
  739.   lfsr1_lo = ((lfsr1_lo&1)<<8) ^ o_lfsr1;
  740. o_lfsr1 = bit_reverse[o_lfsr1];
  741. /*o_lfsr0 = (lfsr0>>7)^(lfsr0>>10)^(lfsr0>>11)^(lfsr0>>19);*/
  742. o_lfsr0 = (((((((lfsr0>>8)^lfsr0)>>1)^lfsr0)>>3)^lfsr0)>>7);
  743.   lfsr0 = (lfsr0>>8)|(o_lfsr0<<24);
  744. combined += (o_lfsr0 ^ invert) + o_lfsr1;
  745. k[i] = combined & 0xff;
  746. combined >>= 8;
  747. }
  748. key[4] = k[4] ^ csstab1[key[4]] ^ key[3];
  749. key[3] = k[3] ^ csstab1[key[3]] ^ key[2];
  750. key[2] = k[2] ^ csstab1[key[2]] ^ key[1];
  751. key[1] = k[1] ^ csstab1[key[1]] ^ key[0];
  752. key[0] = k[0] ^ csstab1[key[0]] ^ key[4];
  753. key[4] = k[4] ^ csstab1[key[4]] ^ key[3];
  754. key[3] = k[3] ^ csstab1[key[3]] ^ key[2];
  755. key[2] = k[2] ^ csstab1[key[2]] ^ key[1];
  756. key[1] = k[1] ^ csstab1[key[1]] ^ key[0];
  757. key[0] = k[0] ^ csstab1[key[0]];
  758. }
  759. /*
  760.  *
  761.  * this function decrypts a title key with the specified disk key
  762.  *
  763.  * tkey: the unobfuscated title key (XORed with BusKey)
  764.  * dkey: the unobfuscated disk key (XORed with BusKey)
  765.  *       2048 bytes in length (though only 5 bytes are needed, see below)
  766.  *
  767.  * use the result returned in tkey with css_descramble
  768.  *
  769.  */
  770. static int decrypt_title_key(mpeg3_css_t *css, unsigned char *dkey, unsigned char *tkey)
  771. {
  772. unsigned char test[5], pretkey[5];
  773. int i = 0;
  774. for(i = 0; mpeg3_playkeys[i]; i++)
  775. {
  776. memcpy(pretkey, dkey + mpeg3_playkeys[i]->offset, 5);
  777. title_key(pretkey, mpeg3_playkeys[i]->key, 0);
  778. memcpy(test, dkey, 5);
  779. title_key(test, pretkey, 0);
  780. if(memcmp(test, pretkey, 5) == 0)
  781. break;
  782. }
  783. if(!mpeg3_playkeys[i])
  784. {
  785. fprintf(stderr, "mpeg3_decrypttitlekey: Shit - Need key %dn", i + 1);
  786. return 1;
  787. }
  788. title_key(css->title_key, pretkey, 0xff);
  789. return 0;
  790. }
  791. /*
  792.  *
  793.  * The descrambling core
  794.  *
  795.  * sec: encrypted sector (2048 bytes)
  796.  * key: decrypted title key obtained from css_decrypttitlekey
  797.  *
  798.  */
  799. #define SALTED(i) (key[i] ^ sec[0x54 - offset + (i)])
  800. static void descramble(unsigned char *sec, unsigned char *key, int offset)
  801. {
  802. unsigned int lfsr1_lo, lfsr1_hi, lfsr0, combined;
  803. unsigned char o_lfsr0, o_lfsr1;
  804. unsigned char *end = sec + 0x800 - offset;
  805. if(offset > 0x54)
  806. fprintf(stderr, "mpeg3css.c: descramble: offset > 0x54n");
  807. lfsr1_lo = SALTED(0) | 0x100;
  808. lfsr1_hi = SALTED(1);
  809. lfsr0 = ((SALTED(4) << 17) | (SALTED(3) << 9) | (SALTED(2) << 1)) + 8 - (SALTED(2) & 7);
  810. lfsr0 = (bit_reverse[lfsr0 & 0xff] << 24) | (bit_reverse[(lfsr0 >> 8) & 0xff] << 16)
  811.   | (bit_reverse[(lfsr0 >> 16) & 0xff] << 8) | bit_reverse[(lfsr0 >> 24) & 0xff];
  812. sec += 0x80 - offset;
  813. combined = 0;
  814. while(sec != end)
  815. {
  816. o_lfsr1 = lfsr1_bits0[lfsr1_hi] ^ lfsr1_bits1[lfsr1_lo];
  817.   lfsr1_hi = lfsr1_lo >> 1;
  818.   lfsr1_lo = ((lfsr1_lo&1) << 8) ^ o_lfsr1;
  819. o_lfsr1 = bit_reverse[o_lfsr1];
  820. /*o_lfsr0 = (lfsr0 >> 7) ^ (lfsr0 >> 10) ^ (lfsr0 >> 11) ^ (lfsr0 >> 19);*/
  821. o_lfsr0 = (((((((lfsr0 >> 8) ^ lfsr0) >> 1) ^ lfsr0) >> 3) ^ lfsr0) >> 7);
  822.   lfsr0 = (lfsr0 >> 8) | (o_lfsr0 << 24);
  823. combined += o_lfsr0 + (unsigned char)~o_lfsr1;
  824. *sec = csstab1[*sec] ^ (combined & 0xff);
  825. sec++;
  826. combined >>= 8;
  827. }
  828. //printf("descramblen");
  829. }
  830. /* =============================== Entry Points ================================= */
  831. mpeg3_css_t* mpeg3_new_css()
  832. {
  833. mpeg3_css_t *css = calloc(1, sizeof(mpeg3_css_t));
  834. css->varient = -1;
  835. return css;
  836. }
  837. int mpeg3_delete_css(mpeg3_css_t *css)
  838. {
  839. free(css);
  840. return 0;
  841. }
  842. int mpeg3_get_keys(mpeg3_css_t *css, char *path)
  843. {
  844. int result = 0;
  845. strcpy(css->path, path);
  846. /* Get disk key */
  847. result = validate_path(css, 0);
  848. /* Get title key */
  849. if(!result) result = validate_path(css, 1);
  850. /* Descramble the title key */
  851. if(!result) result = decrypt_title_key(css, css->disk_key, css->title_key);
  852. return css->encrypted ? result : 0;
  853. }
  854. /* sector is the full 2048 byte sector */
  855. int mpeg3_decrypt_packet(mpeg3_css_t *css, unsigned char *sector, int offset)
  856. {
  857. //printf("mpeg3_decrypt_packet %dn", css->encrypted);
  858. if(!css->encrypted) return 0;     /* Not encrypted */
  859. descramble(sector, css->title_key, offset);
  860. return 0;
  861. }
  862. #else // HAVE_CSS
  863. #include "mpeg3css_fake.c"
  864. #endif