css-descramble.c
上传用户:aoeyumen
上传日期:2007-01-06
资源大小:3329k
文件大小:5k
源码类别:

DVD

开发平台:

Unix_Linux

  1. /* 
  2.  *  css_descramble.c
  3.  *
  4.  *  Released under the version 2 of the GPL.
  5.  *
  6.  *  Copyright 1999 Derek Fawcus / M Roberts
  7.  *
  8.  *  This file contains functions to descramble CSS encrypted DVD content
  9.  *
  10.  */
  11. #include <stdio.h>
  12. #include <string.h>
  13. #include "css.h"
  14. #include "css-descramble.h"
  15. #define CSS_DEBUG 0x00
  16. /*
  17.  *
  18.  *  some tables used for descrambling sectors and/or decrypting title keys
  19.  *
  20.  */
  21. static byte csstab1[256]=
  22. {
  23. 0x33,0x73,0x3b,0x26,0x63,0x23,0x6b,0x76,0x3e,0x7e,0x36,0x2b,0x6e,0x2e,0x66,0x7b,
  24. 0xd3,0x93,0xdb,0x06,0x43,0x03,0x4b,0x96,0xde,0x9e,0xd6,0x0b,0x4e,0x0e,0x46,0x9b,
  25. 0x57,0x17,0x5f,0x82,0xc7,0x87,0xcf,0x12,0x5a,0x1a,0x52,0x8f,0xca,0x8a,0xc2,0x1f,
  26. 0xd9,0x99,0xd1,0x00,0x49,0x09,0x41,0x90,0xd8,0x98,0xd0,0x01,0x48,0x08,0x40,0x91,
  27. 0x3d,0x7d,0x35,0x24,0x6d,0x2d,0x65,0x74,0x3c,0x7c,0x34,0x25,0x6c,0x2c,0x64,0x75,
  28. 0xdd,0x9d,0xd5,0x04,0x4d,0x0d,0x45,0x94,0xdc,0x9c,0xd4,0x05,0x4c,0x0c,0x44,0x95,
  29. 0x59,0x19,0x51,0x80,0xc9,0x89,0xc1,0x10,0x58,0x18,0x50,0x81,0xc8,0x88,0xc0,0x11,
  30. 0xd7,0x97,0xdf,0x02,0x47,0x07,0x4f,0x92,0xda,0x9a,0xd2,0x0f,0x4a,0x0a,0x42,0x9f,
  31. 0x53,0x13,0x5b,0x86,0xc3,0x83,0xcb,0x16,0x5e,0x1e,0x56,0x8b,0xce,0x8e,0xc6,0x1b,
  32. 0xb3,0xf3,0xbb,0xa6,0xe3,0xa3,0xeb,0xf6,0xbe,0xfe,0xb6,0xab,0xee,0xae,0xe6,0xfb,
  33. 0x37,0x77,0x3f,0x22,0x67,0x27,0x6f,0x72,0x3a,0x7a,0x32,0x2f,0x6a,0x2a,0x62,0x7f,
  34. 0xb9,0xf9,0xb1,0xa0,0xe9,0xa9,0xe1,0xf0,0xb8,0xf8,0xb0,0xa1,0xe8,0xa8,0xe0,0xf1,
  35. 0x5d,0x1d,0x55,0x84,0xcd,0x8d,0xc5,0x14,0x5c,0x1c,0x54,0x85,0xcc,0x8c,0xc4,0x15,
  36. 0xbd,0xfd,0xb5,0xa4,0xed,0xad,0xe5,0xf4,0xbc,0xfc,0xb4,0xa5,0xec,0xac,0xe4,0xf5,
  37. 0x39,0x79,0x31,0x20,0x69,0x29,0x61,0x70,0x38,0x78,0x30,0x21,0x68,0x28,0x60,0x71,
  38. 0xb7,0xf7,0xbf,0xa2,0xe7,0xa7,0xef,0xf2,0xba,0xfa,0xb2,0xaf,0xea,0xaa,0xe2,0xff
  39. };
  40. /*
  41.  *
  42.  * this function is only used internally when decrypting title key
  43.  *
  44.  */
  45. static void css_titlekey(byte *key, byte *im, byte invert)
  46. {
  47. int i;
  48. byte k[5];
  49. int val;
  50. unsigned int lfsr0, lfsr1;
  51. byte         o_lfsr0, o_lfsr1;
  52. lfsr0 = ((im[4] << 17) | (im[3] << 9) | (im[2] << 1)) + 8 - (im[2] & 7);
  53.         lfsr0 = (reverse[lfsr0&0xff]<<17) | (reverse[(lfsr0>>8)&0xff] << 9)
  54.   | (reverse[(lfsr0>>16)&0xff]<<1) |(lfsr0>>24);
  55. lfsr1 = (reverse[ im[0] ] << 9) | 0x100 | reverse[ im[1]];
  56. #if (CSS_DEBUG & 0x01)
  57. fprintf( stderr,"SEED lfsr0:0x%08x lfsr1: 0x%08xn", lfsr0, lfsr1);
  58. #endif
  59. val = 0;
  60. for (i = 0; i < 5; ++i) {
  61.     o_lfsr0 = (lfsr0 >> 12) ^ (lfsr0 >> 4) ^ (lfsr0 >> 3) ^ lfsr0;
  62. o_lfsr1 = ((lfsr1 >> 14) & 7) ^ lfsr1;
  63. o_lfsr1 ^= (o_lfsr1 << 3) ^ (o_lfsr1 << 6);
  64. lfsr1 = (lfsr1 >> 8) ^ (o_lfsr1 << 9);
  65. lfsr0 = (lfsr0 >> 8) ^ (o_lfsr0 << 17);
  66. #if (CSS_DEBUG & 0x01)
  67. fprintf( stderr,"lfsr0:0x%08x lfsr1: 0x%08x o_lfsr0:0x%02x o_lfsr1:0x%02xn",
  68. lfsr0, lfsr1, o_lfsr0, o_lfsr1);
  69. #endif
  70. val += (o_lfsr0 ^ invert) + o_lfsr1;
  71. k[i] = val & 0xff;
  72. val >>= 8;
  73. }
  74. key[4]=k[4]^csstab1[key[4]]^key[3];
  75. key[3]=k[3]^csstab1[key[3]]^key[2];
  76. key[2]=k[2]^csstab1[key[2]]^key[1];
  77. key[1]=k[1]^csstab1[key[1]]^key[0];
  78. key[0]=k[0]^csstab1[key[0]]^key[4];
  79. key[4]=k[4]^csstab1[key[4]]^key[3];
  80. key[3]=k[3]^csstab1[key[3]]^key[2];
  81. key[2]=k[2]^csstab1[key[2]]^key[1];
  82. key[1]=k[1]^csstab1[key[1]]^key[0];
  83. key[0]=k[0]^csstab1[key[0]];
  84. }
  85. /*
  86.  *
  87.  * this function decrypts a title key with the specified disk key
  88.  *
  89.  * tkey: the unobfuscated title key (XORed with BusKey)
  90.  * dkey: the unobfuscated disk key (XORed with BusKey)
  91.  *       2048 bytes in length (though only 5 bytes are needed, see below)
  92.  * pkey: array of pointers to player keys and disk key offsets
  93.  *
  94.  *
  95.  * use the result returned in tkey with css_descramble
  96.  *
  97.  */
  98. int css_decrypttitlekey(byte *tkey, byte *dkey, struct playkey **pkey)
  99. {
  100. byte test[5], pretkey[5];
  101. int i = 0;
  102. for (; *pkey; ++pkey, ++i) {
  103. memcpy(pretkey, dkey + (*pkey)->offset, 5);
  104. css_titlekey(pretkey, (*pkey)->key, 0);
  105. memcpy(test, dkey, 5);
  106. css_titlekey(test, pretkey, 0);
  107. if (memcmp(test, pretkey, 5) == 0) {
  108. fprintf(stderr, "Using Key %dn", i+1);
  109. break;
  110. }
  111. }
  112. if (!*pkey) {
  113. fprintf(stderr, "Shit - Need Key %dn", i+1);
  114. return 0;
  115. }
  116. css_titlekey(tkey, pretkey, 0xff);
  117. return 1;
  118. }
  119. /*
  120.  *
  121.  * this function does the actual descrambling
  122.  *
  123.  * sec: encrypted sector (2048 bytes)
  124.  * key: decrypted title key obtained from css_decrypttitlekey
  125.  *
  126.  */
  127. void css_descramble(byte *sec,byte *key)
  128. {
  129. #define SALTED(i) (key[i] ^ sec[0x54 + (i)])
  130. unsigned char *end = sec + 0x800;
  131. int            val;
  132. unsigned int   lfsr0, lfsr1;
  133. byte           o_lfsr0, o_lfsr1;
  134. lfsr0 = ((SALTED(4) << 17) | (SALTED(3) << 9) | (SALTED(2) << 1)) + 8 - (SALTED(2)&7);
  135.         lfsr0 = (reverse[lfsr0&0xff]<<17) | (reverse[(lfsr0>>8)&0xff] << 9)
  136.   | (reverse[(lfsr0>>16)&0xff]<<1) |(lfsr0>>24);
  137. lfsr1 = (reverse[SALTED(0)] << 9) | 0x100 | (reverse[SALTED(1)]);
  138. #if (CSS_DEBUG & 0x10)
  139. fprintf( stderr,"SEED lfsr0:0x%08x lfsr1: 0x%08xn", lfsr0, lfsr1);
  140. #endif
  141. sec+=0x80;
  142. val = 0;
  143. while (sec != end) {
  144.     o_lfsr0 = (lfsr0 >> 12) ^ (lfsr0 >> 4) ^  (lfsr0 >> 3) ^ lfsr0;
  145. o_lfsr1 = ((lfsr1 >> 14) & 7) ^ lfsr1;
  146. o_lfsr1 ^= (o_lfsr1 << 3) ^ (o_lfsr1 << 6);
  147. lfsr1 = (lfsr1 >> 8) ^ (o_lfsr1 << 9);
  148. lfsr0 = (lfsr0 >> 8) ^ (o_lfsr0 << 17);
  149.     val += o_lfsr0 + (byte)~o_lfsr1;
  150. *sec++ = csstab1[*sec] ^ (val & 0xff);
  151. val >>= 8;
  152. #if (CSS_DEBUG & 0x10)
  153. fprintf( stderr,"lfsr0:0x%08x lfsr1: 0x%08x o_lfsr0:0x%02x o_lfsr1:0x%02xn",
  154. lfsr0, lfsr1, o_lfsr0, o_lfsr1);
  155. #endif
  156. }
  157. }