C语言实现AES加解密

  • AES算法
  • 具体代码


AES算法

(AES)RIJNDAEL算法是一个数据块长度盒密钥长度都可变的分组加密算法,其数据块长度和密钥长度都可独立地选定为大于等于128位且小于等于256位的32位任意倍数。在本次实验中采用的是128位数据和密钥长度。

RIJNDAEL算法结构如图:

aes算法python语言实现 aes算法编程_c语言

轮函数
RIJNDAEL的轮函数由以下三层组成:
①非线性层:进行非线性S盒变换subByte,由16个S盒并置而成,起混淆的作用。
②线性混合层:进行行移位变换shiftRow和列混合变换mixColumn以确保多轮之上的高度扩散。
③密钥加层:进行轮密钥加变换addRoundKey,将轮密钥简单地异或到中间状态上,实现密钥地加密控制作用。
轮函数用伪c语言表述为(state为明文加密状态):

Round(state,RoundKey){
		subByte(state);
		shiftRow(state);
		mixColumn(state);
		addRoundKey(state, RoundKey);
	}
**加密算法中最后一轮的轮函数域上面的标准函数略有不同(没有mixColumn(state))**

(1)其中,S盒变换subByte是按照字节进行的代替变换。
假设i是state中某字节,则经过替换后:i=SBOX[i];

S盒如下:
		int SBOX[256] =   {
			0x63, 0x7c, 0x77, 0x7b, 0xf2, 0x6b, 0x6f, 0xc5, 0x30, 0x01, 0x67, 0x2b, 0xfe, 0xd7, 0xab, 0x76,
			0xca, 0x82, 0xc9, 0x7d, 0xfa, 0x59, 0x47, 0xf0, 0xad, 0xd4, 0xa2, 0xaf, 0x9c, 0xa4, 0x72, 0xc0,
			0xb7, 0xfd, 0x93, 0x26, 0x36, 0x3f, 0xf7, 0xcc, 0x34, 0xa5, 0xe5, 0xf1, 0x71, 0xd8, 0x31, 0x15,
			0x04, 0xc7, 0x23, 0xc3, 0x18, 0x96, 0x05, 0x9a, 0x07, 0x12, 0x80, 0xe2, 0xeb, 0x27, 0xb2, 0x75,
			0x09, 0x83, 0x2c, 0x1a, 0x1b, 0x6e, 0x5a, 0xa0, 0x52, 0x3b, 0xd6, 0xb3, 0x29, 0xe3, 0x2f, 0x84,
			0x53, 0xd1, 0x00, 0xed, 0x20, 0xfc, 0xb1, 0x5b, 0x6a, 0xcb, 0xbe, 0x39, 0x4a, 0x4c, 0x58, 0xcf,
			0xd0, 0xef, 0xaa, 0xfb, 0x43, 0x4d, 0x33, 0x85, 0x45, 0xf9, 0x02, 0x7f, 0x50, 0x3c, 0x9f, 0xa8,
			0x51, 0xa3, 0x40, 0x8f, 0x92, 0x9d, 0x38, 0xf5, 0xbc, 0xb6, 0xda, 0x21, 0x10, 0xff, 0xf3, 0xd2,
			0xcd, 0x0c, 0x13, 0xec, 0x5f, 0x97, 0x44, 0x17, 0xc4, 0xa7, 0x7e, 0x3d, 0x64, 0x5d, 0x19, 0x73,
			0x60, 0x81, 0x4f, 0xdc, 0x22, 0x2a, 0x90, 0x88, 0x46, 0xee, 0xb8, 0x14, 0xde, 0x5e, 0x0b, 0xdb,
			0xe0, 0x32, 0x3a, 0x0a, 0x49, 0x06, 0x24, 0x5c, 0xc2, 0xd3, 0xac, 0x62, 0x91, 0x95, 0xe4, 0x79,
			0xe7, 0xc8, 0x37, 0x6d, 0x8d, 0xd5, 0x4e, 0xa9, 0x6c, 0x56, 0xf4, 0xea, 0x65, 0x7a, 0xae, 0x08,
			0xba, 0x78, 0x25, 0x2e, 0x1c, 0xa6, 0xb4, 0xc6, 0xe8, 0xdd, 0x74, 0x1f, 0x4b, 0xbd, 0x8b, 0x8a,
			0x70, 0x3e, 0xb5, 0x66, 0x48, 0x03, 0xf6, 0x0e, 0x61, 0x35, 0x57, 0xb9, 0x86, 0xc1, 0x1d, 0x9e,
			0xe1, 0xf8, 0x98, 0x11, 0x69, 0xd9, 0x8e, 0x94, 0x9b, 0x1e, 0x87, 0xe9, 0xce, 0x55, 0x28, 0xdf,
			0x8c, 0xa1, 0x89, 0x0d, 0xbf, 0xe6, 0x42, 0x68, 0x41, 0x99, 0x2d, 0x0f, 0xb0, 0x54, 0xbb, 0x16 
};

(2)行移位和Nb的关系(数字代表上移次数):

aes算法python语言实现 aes算法编程_c语言_02

本实验中Nb=4;

一次行移位变换示例(此实验为了方便结果阅读,行和列与一般定义不同),从左到右:
state[4][4]={									state[4][4]={
	1,    2,    3,     4,							1,   6,   11,   16,   //第一行
	5,    6,    7,     8, 							5,   10,  15,    4,  //第二行                     
	9,   10,   11,    12,						 	9,   14,   3,    8,  //第三行
   13,   14,   15,    16						   13,   2,   7,    12  …… 	
}											}

(3)列混淆变换mixColumn是对状态列的混淆变换。在mixColumn中,把状态中每一列看作伽罗华域GF(2^8) 上的多项式与一固定多项式相乘然后模多项式 x^4-1。该多项式为:

(4)轮密钥加变换addRoundKey是利用轮密钥对状态进行模2相加的变换。

密钥扩展
用一个四字节元素的一维数组(一个元素为一行)RoundKey[Nb*(Nr+1)]表示扩展密钥。
本实验中的密钥扩展策略(伪c代码表示):

keyExpansion(key,RoundKey){
		for(i=0;i<Nk;i++)Roundkey[i]=key[i]; //第一轮密钥即原密钥
		while(i<(Nb*(Nr+1))){
			temp=RoundKey[i];
			if(i%4==0){
				rotWord(temp);
				subWord(temp);
				temp[0]^=Rocn[i/Nk];
			}
			RoundKey[i]=RoundKey[i-Nk]^temp;
			i++;
		}
	}

Rcon表如下,实际上只需要Rocn[1-10]:

int Rcon[255] = {
			0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36, 0x6c, 0xd8, 0xab, 0x4d, 0x9a,
			0x2f, 0x5e, 0xbc, 0x63, 0xc6, 0x97, 0x35, 0x6a, 0xd4, 0xb3, 0x7d, 0xfa, 0xef, 0xc5, 0x91, 0x39,
			0x72, 0xe4, 0xd3, 0xbd, 0x61, 0xc2, 0x9f, 0x25, 0x4a, 0x94, 0x33, 0x66, 0xcc, 0x83, 0x1d, 0x3a,
			0x74, 0xe8, 0xcb, 0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36, 0x6c, 0xd8,
			0xab, 0x4d, 0x9a, 0x2f, 0x5e, 0xbc, 0x63, 0xc6, 0x97, 0x35, 0x6a, 0xd4, 0xb3, 0x7d, 0xfa, 0xef,
			0xc5, 0x91, 0x39, 0x72, 0xe4, 0xd3, 0xbd, 0x61, 0xc2, 0x9f, 0x25, 0x4a, 0x94, 0x33, 0x66, 0xcc,
			0x83, 0x1d, 0x3a, 0x74, 0xe8, 0xcb, 0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b,
			0x36, 0x6c, 0xd8, 0xab, 0x4d, 0x9a, 0x2f, 0x5e, 0xbc, 0x63, 0xc6, 0x97, 0x35, 0x6a, 0xd4, 0xb3,
			0x7d, 0xfa, 0xef, 0xc5, 0x91, 0x39, 0x72, 0xe4, 0xd3, 0xbd, 0x61, 0xc2, 0x9f, 0x25, 0x4a, 0x94,
			0x33, 0x66, 0xcc, 0x83, 0x1d, 0x3a, 0x74, 0xe8, 0xcb, 0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20,
			0x40, 0x80, 0x1b, 0x36, 0x6c, 0xd8, 0xab, 0x4d, 0x9a, 0x2f, 0x5e, 0xbc, 0x63, 0xc6, 0x97, 0x35,
			0x6a, 0xd4, 0xb3, 0x7d, 0xfa, 0xef, 0xc5, 0x91, 0x39, 0x72, 0xe4, 0xd3, 0xbd, 0x61, 0xc2, 0x9f,
			0x25, 0x4a, 0x94, 0x33, 0x66, 0xcc, 0x83, 0x1d, 0x3a, 0x74, 0xe8, 0xcb, 0x8d, 0x01, 0x02, 0x04,
			0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36, 0x6c, 0xd8, 0xab, 0x4d, 0x9a, 0x2f, 0x5e, 0xbc, 0x63,
			0xc6, 0x97, 0x35, 0x6a, 0xd4, 0xb3, 0x7d, 0xfa, 0xef, 0xc5, 0x91, 0x39, 0x72, 0xe4, 0xd3, 0xbd,
			0x61, 0xc2, 0x9f, 0x25, 0x4a, 0x94, 0x33, 0x66, 0xcc, 0x83, 0x1d, 0x3a, 0x74, 0xe8, 0xcb
};

逆变换
(1)subByte的逆是RIJNDAEL的R_SBOX作用到状态的每个字节上,R_SBOX如下:

int R_SBOX[256] ={ 
			0x52, 0x09, 0x6a, 0xd5, 0x30, 0x36, 0xa5, 0x38, 0xbf, 0x40, 0xa3, 0x9e, 0x81, 0xf3, 0xd7, 0xfb, 
			0x7c, 0xe3, 0x39, 0x82, 0x9b, 0x2f, 0xff, 0x87, 0x34, 0x8e, 0x43, 0x44, 0xc4, 0xde, 0xe9, 0xcb, 
			0x54, 0x7b, 0x94, 0x32, 0xa6, 0xc2, 0x23, 0x3d, 0xee, 0x4c, 0x95, 0x0b, 0x42, 0xfa, 0xc3, 0x4e, 
			0x08, 0x2e,0xa1, 0x66, 0x28, 0xd9, 0x24, 0xb2, 0x76, 0x5b, 0xa2, 0x49, 0x6d, 0x8b, 0xd1, 0x25, 
			0x72, 0xf8, 0xf6, 0x64, 0x86, 0x68, 0x98, 0x16, 0xd4, 0xa4, 0x5c, 0xcc, 0x5d, 0x65, 0xb6, 0x92, 
			0x6c, 0x70, 0x48, 0x50, 0xfd, 0xed, 0xb9, 0xda, 0x5e, 0x15, 0x46, 0x57, 0xa7, 0x8d, 0x9d, 0x84, 
			0x90, 0xd8, 0xab, 0x00, 0x8c, 0xbc, 0xd3, 0x0a, 0xf7, 0xe4, 0x58, 0x05, 0xb8, 0xb3, 0x45, 0x06, 
			0xd0, 0x2c, 0x1e, 0x8f, 0xca, 0x3f, 0x0f, 0x02, 0xc1, 0xaf, 0xbd, 0x03, 0x01, 0x13, 0x8a, 0x6b, 
			0x3a, 0x91, 0x11, 0x41, 0x4f, 0x67, 0xdc, 0xea, 0x97, 0xf2, 0xcf, 0xce, 0xf0, 0xb4, 0xe6, 0x73, 
			0x96, 0xac, 0x74, 0x22, 0xe7, 0xad, 0x35, 0x85, 0xe2, 0xf9, 0x37, 0xe8, 0x1c, 0x75, 0xdf, 0x6e, 
			0x47, 0xf1, 0x1a, 0x71, 0x1d, 0x29, 0xc5, 0x89, 0x6f, 0xb7, 0x62, 0x0e, 0xaa, 0x18, 0xbe, 0x1b, 
			0xfc, 0x56, 0x3e, 0x4b, 0xc6, 0xd2, 0x79, 0x20, 0x9a, 0xdb, 0xc0, 0xfe, 0x78, 0xcd, 0x5a, 0xf4, 
			0x1f, 0xdd, 0xa8, 0x33, 0x88, 0x07, 0xc7, 0x31, 0xb1, 0x12, 0x10, 0x59, 0x27, 0x80, 0xec, 0x5f, 
			0x60, 0x51, 0x7f, 0xa9, 0x19, 0xb5, 0x4a, 0x0d, 0x2d, 0xe5, 0x7a, 0x9f, 0x93, 0xc9, 0x9c, 0xef, 
			0xa0, 0xe0, 0x3b, 0x4d, 0xae, 0x2a, 0xf5, 0xb0, 0xc8, 0xeb, 0xbb, 0x3c, 0x83, 0x53, 0x99, 0x61, 
			0x17, 0x2b, 0x04, 0x7e, 0xba, 0x77, 0xd6, 0x26, 0xe1, 0x69, 0x14, 0x63, 0x55, 0x21, 0x0c, 0x7d
};

(2)shiftRow的逆是后三行分别下移1,2,3行。
(3)mixColumn的逆类似于mixColumn,状态的每列都乘以一个固定多项式:
(4)addRoundKey的逆即它本身。

RIJNDAEL加密过程

keyExpansion();	
			addRoundKey(0);     //addRoundKey中的数字表示轮密钥的编号(0-10)
			for(round=1;round<Nr;round++){
				subBytes();
				shiftRows();
				mixColumns();
				addRoundKey(round);
			}
			subBytes();      //此处即FinalRound()
			shiftRows();
			addRoundKey(Nr);

RIJNDAEL解密过程

keyExpansion();
			addRoundKey(Nr);
			for(round=Nr-1;round>0;round--){
				invSubBytes();
				invShiftRows();
				addRoundKey(round);
				invMixColumns();
			}
			invSubBytes();	
			invShiftRows();
			addRoundKey(0);

具体代码

#include<stdio.h>
#include<string.h> 
#include<time.h>
#include<windows.h> 

#define Nb 4   //数据块行数 
#define Nk 4   //密码块行数 
#define Nr 10  //轮加密次数 


unsigned char RoundKey[4*Nb*(Nr+1)]; //轮密钥 
unsigned char Key[17];     //密钥 
unsigned char state[4][4];  //明文加密状态 


//实际上只需要用Rocn[1-10] 
int Rcon[255] = {
	0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36, 0x6c, 0xd8, 0xab, 0x4d, 0x9a,
	0x2f, 0x5e, 0xbc, 0x63, 0xc6, 0x97, 0x35, 0x6a, 0xd4, 0xb3, 0x7d, 0xfa, 0xef, 0xc5, 0x91, 0x39,
	0x72, 0xe4, 0xd3, 0xbd, 0x61, 0xc2, 0x9f, 0x25, 0x4a, 0x94, 0x33, 0x66, 0xcc, 0x83, 0x1d, 0x3a,
	0x74, 0xe8, 0xcb, 0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36, 0x6c, 0xd8,
	0xab, 0x4d, 0x9a, 0x2f, 0x5e, 0xbc, 0x63, 0xc6, 0x97, 0x35, 0x6a, 0xd4, 0xb3, 0x7d, 0xfa, 0xef,
	0xc5, 0x91, 0x39, 0x72, 0xe4, 0xd3, 0xbd, 0x61, 0xc2, 0x9f, 0x25, 0x4a, 0x94, 0x33, 0x66, 0xcc,
	0x83, 0x1d, 0x3a, 0x74, 0xe8, 0xcb, 0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b,
	0x36, 0x6c, 0xd8, 0xab, 0x4d, 0x9a, 0x2f, 0x5e, 0xbc, 0x63, 0xc6, 0x97, 0x35, 0x6a, 0xd4, 0xb3,
	0x7d, 0xfa, 0xef, 0xc5, 0x91, 0x39, 0x72, 0xe4, 0xd3, 0xbd, 0x61, 0xc2, 0x9f, 0x25, 0x4a, 0x94,
	0x33, 0x66, 0xcc, 0x83, 0x1d, 0x3a, 0x74, 0xe8, 0xcb, 0x8d, 0x01, 0x02, 0x04, 0x08, 0x10, 0x20,
	0x40, 0x80, 0x1b, 0x36, 0x6c, 0xd8, 0xab, 0x4d, 0x9a, 0x2f, 0x5e, 0xbc, 0x63, 0xc6, 0x97, 0x35,
	0x6a, 0xd4, 0xb3, 0x7d, 0xfa, 0xef, 0xc5, 0x91, 0x39, 0x72, 0xe4, 0xd3, 0xbd, 0x61, 0xc2, 0x9f,
	0x25, 0x4a, 0x94, 0x33, 0x66, 0xcc, 0x83, 0x1d, 0x3a, 0x74, 0xe8, 0xcb, 0x8d, 0x01, 0x02, 0x04,
	0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36, 0x6c, 0xd8, 0xab, 0x4d, 0x9a, 0x2f, 0x5e, 0xbc, 0x63,
	0xc6, 0x97, 0x35, 0x6a, 0xd4, 0xb3, 0x7d, 0xfa, 0xef, 0xc5, 0x91, 0x39, 0x72, 0xe4, 0xd3, 0xbd,
	0x61, 0xc2, 0x9f, 0x25, 0x4a, 0x94, 0x33, 0x66, 0xcc, 0x83, 0x1d, 0x3a, 0x74, 0xe8, 0xcb
};


//s盒 
int SBOX[256] =   {
	//0     1    2      3     4    5     6     7      8    9     A      B    C     D     E     F
	0x63, 0x7c, 0x77, 0x7b, 0xf2, 0x6b, 0x6f, 0xc5, 0x30, 0x01, 0x67, 0x2b, 0xfe, 0xd7, 0xab, 0x76,
	0xca, 0x82, 0xc9, 0x7d, 0xfa, 0x59, 0x47, 0xf0, 0xad, 0xd4, 0xa2, 0xaf, 0x9c, 0xa4, 0x72, 0xc0,
	0xb7, 0xfd, 0x93, 0x26, 0x36, 0x3f, 0xf7, 0xcc, 0x34, 0xa5, 0xe5, 0xf1, 0x71, 0xd8, 0x31, 0x15,
	0x04, 0xc7, 0x23, 0xc3, 0x18, 0x96, 0x05, 0x9a, 0x07, 0x12, 0x80, 0xe2, 0xeb, 0x27, 0xb2, 0x75,
	0x09, 0x83, 0x2c, 0x1a, 0x1b, 0x6e, 0x5a, 0xa0, 0x52, 0x3b, 0xd6, 0xb3, 0x29, 0xe3, 0x2f, 0x84,
	0x53, 0xd1, 0x00, 0xed, 0x20, 0xfc, 0xb1, 0x5b, 0x6a, 0xcb, 0xbe, 0x39, 0x4a, 0x4c, 0x58, 0xcf,
	0xd0, 0xef, 0xaa, 0xfb, 0x43, 0x4d, 0x33, 0x85, 0x45, 0xf9, 0x02, 0x7f, 0x50, 0x3c, 0x9f, 0xa8,
	0x51, 0xa3, 0x40, 0x8f, 0x92, 0x9d, 0x38, 0xf5, 0xbc, 0xb6, 0xda, 0x21, 0x10, 0xff, 0xf3, 0xd2,
	0xcd, 0x0c, 0x13, 0xec, 0x5f, 0x97, 0x44, 0x17, 0xc4, 0xa7, 0x7e, 0x3d, 0x64, 0x5d, 0x19, 0x73,
	0x60, 0x81, 0x4f, 0xdc, 0x22, 0x2a, 0x90, 0x88, 0x46, 0xee, 0xb8, 0x14, 0xde, 0x5e, 0x0b, 0xdb,
	0xe0, 0x32, 0x3a, 0x0a, 0x49, 0x06, 0x24, 0x5c, 0xc2, 0xd3, 0xac, 0x62, 0x91, 0x95, 0xe4, 0x79,
	0xe7, 0xc8, 0x37, 0x6d, 0x8d, 0xd5, 0x4e, 0xa9, 0x6c, 0x56, 0xf4, 0xea, 0x65, 0x7a, 0xae, 0x08,
	0xba, 0x78, 0x25, 0x2e, 0x1c, 0xa6, 0xb4, 0xc6, 0xe8, 0xdd, 0x74, 0x1f, 0x4b, 0xbd, 0x8b, 0x8a,
	0x70, 0x3e, 0xb5, 0x66, 0x48, 0x03, 0xf6, 0x0e, 0x61, 0x35, 0x57, 0xb9, 0x86, 0xc1, 0x1d, 0x9e,
	0xe1, 0xf8, 0x98, 0x11, 0x69, 0xd9, 0x8e, 0x94, 0x9b, 0x1e, 0x87, 0xe9, 0xce, 0x55, 0x28, 0xdf,
	0x8c, 0xa1, 0x89, 0x0d, 0xbf, 0xe6, 0x42, 0x68, 0x41, 0x99, 0x2d, 0x0f, 0xb0, 0x54, 0xbb, 0x16 
};

//逆s盒 
int R_SBOX[256] ={ 
	0x52, 0x09, 0x6a, 0xd5, 0x30, 0x36, 0xa5, 0x38, 0xbf, 0x40, 0xa3, 0x9e, 0x81, 0xf3, 0xd7, 0xfb, 
	0x7c, 0xe3, 0x39, 0x82, 0x9b, 0x2f, 0xff, 0x87, 0x34, 0x8e, 0x43, 0x44, 0xc4, 0xde, 0xe9, 0xcb, 
	0x54, 0x7b, 0x94, 0x32, 0xa6, 0xc2, 0x23, 0x3d, 0xee, 0x4c, 0x95, 0x0b, 0x42, 0xfa, 0xc3, 0x4e, 
	0x08, 0x2e, 0xa1, 0x66, 0x28, 0xd9, 0x24, 0xb2, 0x76, 0x5b, 0xa2, 0x49, 0x6d, 0x8b, 0xd1, 0x25, 
	0x72, 0xf8, 0xf6, 0x64, 0x86, 0x68, 0x98, 0x16, 0xd4, 0xa4, 0x5c, 0xcc, 0x5d, 0x65, 0xb6, 0x92, 
	0x6c, 0x70, 0x48, 0x50, 0xfd, 0xed, 0xb9, 0xda, 0x5e, 0x15, 0x46, 0x57, 0xa7, 0x8d, 0x9d, 0x84, 
	0x90, 0xd8, 0xab, 0x00, 0x8c, 0xbc, 0xd3, 0x0a, 0xf7, 0xe4, 0x58, 0x05, 0xb8, 0xb3, 0x45, 0x06, 
	0xd0, 0x2c, 0x1e, 0x8f, 0xca, 0x3f, 0x0f, 0x02, 0xc1, 0xaf, 0xbd, 0x03, 0x01, 0x13, 0x8a, 0x6b, 
	0x3a, 0x91, 0x11, 0x41, 0x4f, 0x67, 0xdc, 0xea, 0x97, 0xf2, 0xcf, 0xce, 0xf0, 0xb4, 0xe6, 0x73, 
	0x96, 0xac, 0x74, 0x22, 0xe7, 0xad, 0x35, 0x85, 0xe2, 0xf9, 0x37, 0xe8, 0x1c, 0x75, 0xdf, 0x6e, 
	0x47, 0xf1, 0x1a, 0x71, 0x1d, 0x29, 0xc5, 0x89, 0x6f, 0xb7, 0x62, 0x0e, 0xaa, 0x18, 0xbe, 0x1b, 
	0xfc, 0x56, 0x3e, 0x4b, 0xc6, 0xd2, 0x79, 0x20, 0x9a, 0xdb, 0xc0, 0xfe, 0x78, 0xcd, 0x5a, 0xf4, 
	0x1f, 0xdd, 0xa8, 0x33, 0x88, 0x07, 0xc7, 0x31, 0xb1, 0x12, 0x10, 0x59, 0x27, 0x80, 0xec, 0x5f, 
	0x60, 0x51, 0x7f, 0xa9, 0x19, 0xb5, 0x4a, 0x0d, 0x2d, 0xe5, 0x7a, 0x9f, 0x93, 0xc9, 0x9c, 0xef, 
	0xa0, 0xe0, 0x3b, 0x4d, 0xae, 0x2a, 0xf5, 0xb0, 0xc8, 0xeb, 0xbb, 0x3c, 0x83, 0x53, 0x99, 0x61, 
	0x17, 0x2b, 0x04, 0x7e, 0xba, 0x77, 0xd6, 0x26, 0xe1, 0x69, 0x14, 0x63, 0x55, 0x21, 0x0c, 0x7d
};

//在一行上进位移 
void rotWord(unsigned char temp[]) {
	int i,k=temp[0];
	for(i=1;i<4;i++)
		temp[i-1]=temp[i];
	temp[3]=k;
}

//在一行上进行s盒替换 
void subWord(unsigned char temp[]) {
	int i;
	for(i=0;i<4;i++)
		temp[i]=SBOX[temp[i]];
}

//密钥扩展,最终得到Nr+1个轮密钥,用于轮次加密 
void keyExpansion(){
	int i,j;
	unsigned char temp[5];
	memset(RoundKey,0,sizeof(RoundKey));

	for(i=0;i<Nk;i++){
		for(j=0;j<4;j++){
			RoundKey[i*4+j]=Key[i*4+j];
		}
	}
	
	while(i<(Nb*(Nr+1))){
		for(j=0;j<4;j++){
			temp[j]=RoundKey[(i-1)*4+j];
		}
		if(i%Nk==0){
			rotWord(temp);
			subWord(temp);
			temp[0]^=Rcon[i/Nk];
		}
		
		for(j=0;j<4;j++)
			RoundKey[i*4+j]=RoundKey[(i-Nk)*4+j]^temp[j];
		i++;
	}
}

//轮密钥加函数,将明文加密状态与轮密钥简单异或 
void addRoundKey(int round){
	int i,j;
	for(i=0;i<4;i++){
		for(j=0;j<4;j++){
			state[i][j]^=RoundKey[round*Nb*4+i*Nb+j];
		}
	}
}

//s盒替换函数 
void subBytes(){
	int i,j;
	for(i=0;i<4;i++){
		for(j=0;j<4;j++){
			state[i][j]=SBOX[state[i][j]];
		}
	}
}

//逆s盒替换函数 
void invSubBytes(){
	int i,j;
	for(i=0;i<4;i++){
		for(j=0;j<4;j++){
			state[i][j]=R_SBOX[state[i][j]];
		}
	}
}

//行位移函数 
void shiftRows(){
	int i,j,k;
	int shiftnum=1;
	unsigned char tmp;
	for(j=1;j<4;j++){
		for(i=0;i<shiftnum;i++){
			tmp=state[0][j];
			for(k=0;k<3;k++)
				state[k][j]=state[k+1][j];
			state[3][j]=tmp;
		}
		shiftnum++;
	}
}

//逆行位移函数 
void invShiftRows(){
	int i,j,k;
	int shiftnum=1;
	unsigned char tmp;
	for(j=1;j<4;j++){
		for(i=0;i<shiftnum;i++){
			tmp=state[3][j];
			for(k=3;k>0;k--)
				state[k][j]=state[k-1][j];
			state[0][j]=tmp;
		}
		shiftnum++;
	}
}

//列混淆函数 
#define xtime(x)   ((x<<1) ^ (((x>>7) & 1) * 0x1b))
void mixColumns(){
	int i,j;
	unsigned char tmp,t,p;
	for(i=0;i<4;i++){
		p=state[i][0];
		tmp=state[i][0]^state[i][1]^state[i][2]^state[i][3];
		for(j=0;j<3;j++){
			t=state[i][j]^state[i][j+1];
			t=xtime(t);
			state[i][j]^=t^tmp;
		}
		t=state[i][3]^p;t=xtime(t);state[i][3]^=t^tmp;
	}
}

//逆列混淆函数 
#define Multiply(x,y) (((y & 1) * x) ^ ((y>>1 & 1) * xtime(x)) ^ ((y>>2 & 1) * xtime(xtime(x))) ^ ((y>>3 & 1) * xtime(xtime(xtime(x)))) ^ ((y>>4 & 1) * xtime(xtime(xtime(xtime(x))))))
void invMixColumns(){
	int i;
	unsigned char a,b,c,d;
	for( i=0; i<4; i++)
	{   
		a = state[i][0];
		b = state[i][1];
		c = state[i][2];
		d = state[i][3];

		state[i][0] = Multiply(a, 0x0e) ^ Multiply(b, 0x0b) ^ Multiply(c, 0x0d) ^ Multiply(d, 0x09);
		state[i][1] = Multiply(a, 0x09) ^ Multiply(b, 0x0e) ^ Multiply(c, 0x0b) ^ Multiply(d, 0x0d);
		state[i][2] = Multiply(a, 0x0d) ^ Multiply(b, 0x09) ^ Multiply(c, 0x0e) ^ Multiply(d, 0x0b);
		state[i][3] = Multiply(a, 0x0b) ^ Multiply(b, 0x0d) ^ Multiply(c, 0x09) ^ Multiply(d, 0x0e);
	}
}

//aes加密函数,key为密钥,input为需要加密的128位明文,output为输出128位密文 
void aes_enc(unsigned char*key,unsigned char *input,unsigned char*output){
	int i,j,round=0;
	memset(Key,0,sizeof(Key));
	for(i=0;i<Nk*4;i++){
		Key[i]=key[i];
	}

	keyExpansion();

	memset(state,0,sizeof(state));
	for(i=0;i<4;i++){
		for(j=0;j<4;j++)
			state[i][j]=input[i*4+j];
	}
	addRoundKey(0);
	for(round=1;round<Nr;round++){
		subBytes();
		shiftRows();
		mixColumns();
		addRoundKey(round);
	}
	
	subBytes();
	shiftRows();
	addRoundKey(Nr);
	
	for(i=0;i<4;i++){
		for(j=0;j<4;j++)
			output[i*4+j]=state[i][j];
	}
}

//aes解密函数,key为密钥,input为需要解密的128位密文,output为输出128位明文
void aes_dec(unsigned char*key,unsigned char*input,unsigned char*output){
	int i,j,round=0;
	memset(Key,0,sizeof(Key));
	for(i=0;i<Nk*4;i++){
		Key[i]=key[i];
	}
	
	keyExpansion();
	
	memset(state,0,sizeof(state));
	for(i=0;i<4;i++){
		for(j=0;j<4;j++)
			state[i][j]=input[i*4+j];
	}
	addRoundKey(Nr);
	for(round=Nr-1;round>0;round--){
		invSubBytes();
		invShiftRows();
		addRoundKey(round);
		invMixColumns();
	}
	
	invSubBytes();	
	invShiftRows();
	addRoundKey(0);
	
	for(i=0;i<4;i++){
		for(j=0;j<4;j++)
			output[i*4+j]=state[i][j];
	}
}

void gets_t(unsigned char*str){
	char fin_input;
	scanf("%66s",str);
	do
		fin_input=getchar();
	while(fin_input!='\n');
}


int main(){
	unsigned char key[17]={0};
	unsigned char input[17]={0};
	unsigned char enc[17]={0};
	unsigned char dec[17]={0};
	
	printf("input key: ");
	gets_t(key);
	printf("input state: ");
	gets_t(input);
	aes_enc(key,input,enc);
	printf("enc:%s\n",enc);
	aes_dec(key,enc,dec);
	printf("dec:%s\n",dec);
	return 0;
}

代码效果:

aes算法python语言实现 aes算法编程_5e_03