Twofish CBC-Mode IV-KAT Tables

John Bryan

Table of Contents
Key Schedule
Unexpanded key, M, Me,  Mo,  M64, S vectors
K0,  K1 K2,  K3 K4,  K5 K6,  K7 K8,  K9 K10,  K11 K12,  K13 K14,  K15 K16,  K17 K18,  K19
K20,  K21 K22,  K23 K24,  K25 K26,  K27 K28,  K29 K30,  K31 K32,  K33 K34,  K35 K36,  K37 K38,  K39
Summary listing of the 40 expanded key words
Encryption of plaintext block 1
Encryption start
Encryption CBC xor
Encryption input whiten
r=0 r=1 r=2 r=3 r=4 r=5 r=6 r=7 r=8 r=9 r=10 r=11 r=12 r=13 r=14 r=15
Encryption output whiten Ciphertext result
Encryption of plaintext block 2
Encryption start
Encryption CBC xor
Encryption input whiten
r=0 r=1 r=2 r=3 r=4 r=5 r=6 r=7 r=8 r=9 r=10 r=11 r=12 r=13 r=14 r=15
Encryption output whiten Ciphertext result
Encryption of plaintext block 3
Encryption start
Encryption CBC xor
Encryption input whiten
r=0 r=1 r=2 r=3 r=4 r=5 r=6 r=7 r=8 r=9 r=10 r=11 r=12 r=13 r=14 r=15
Encryption output whiten Ciphertext result
Encryption of plaintext block 4
Encryption start
Encryption CBC xor
Encryption input whiten
r=0 r=1 r=2 r=3 r=4 r=5 r=6 r=7 r=8 r=9 r=10 r=11 r=12 r=13 r=14 r=15
Encryption output whiten Ciphertext result
Decryption of ciphertext block 1
Decryption start
Decryption input unwhiten
r=15 r=14 r=13 r=12 r=11 r=10 r=9 r=8 r=7 r=6 r=5 r=4 r=3 r=2 r=1 r=0
Decryption output unwhiten Decryption CBC xor Plaintext result
Decryption of ciphertext block 2
Decryption start
Decryption input unwhiten
r=15 r=14 r=13 r=12 r=11 r=10 r=9 r=8 r=7 r=6 r=5 r=4 r=3 r=2 r=1 r=0
Decryption output unwhiten Decryption CBC xor Plaintext result
Decryption of ciphertext block 3
Decryption start
Decryption input unwhiten
r=15 r=14 r=13 r=12 r=11 r=10 r=9 r=8 r=7 r=6 r=5 r=4 r=3 r=2 r=1 r=0
Decryption output unwhiten Decryption CBC xor Plaintext result
Decryption of ciphertext block 4
Decryption start
Decryption input unwhiten
r=15 r=14 r=13 r=12 r=11 r=10 r=9 r=8 r=7 r=6 r=5 r=4 r=3 r=2 r=1 r=0
Decryption output unwhiten Decryption CBC xor Plaintext result


Unexpanded Key, M, Me,  Mo,  M64,  S word vectors
key = m0m1m2m3m4m5m6m7m8m9m10m11m12m13m14m15 = 9f589f5cf6122c32b6bfec2f2ae8c35a
m0=9f m1=58 m2=9f m3=5c m4=f6 m5=12 m6=2c m7=32 m8=b6 m9=bf m10=ec m11=2f m12=2a m13=e8 m14=c3 m15=5a
Me0 = M0 = m0m1m2m3 = 9f589f5c Me1 = M2 = m8m9m10m11 = b6bfec2f
Mo0 = M1 = m4m5m6m7 = f6122c32 Mo1 = M3 = m12m13m14m15 = 2ae8c35a
le0,0 = m0 = 9f le0,1 = m1 = 58 le0,2 = m2 = 9f le0,3 = m3 = 5c le1,0 = m8 = b6 le1,1 = m9 = bf le1,2 = m10 = ec le1,3 = m11 = 2f
lo0,0 = m4 = f6 lo0,1 = m5 = 12 lo0,2 = m6 = 2c lo0,3 = m7 = 32 lo1,0 = m12 = 2a lo1,1 = m13 = e8 lo1,2 = m14 = c3 lo1,3 = m15 = 5a
M640 = M0M1 = m0m1m2m3m4m5m6m7 = 9f589f5cf6122c32 M641 = M2M3 = m8m9m10m11m12m13m14m15 = b6bfec2f2ae8c35a
Pre S list reversal: s0,0 = 18 s0,1 = 8a s0,2 = 9c s0,3 = 14 s1,0 = 81 s1,1 = 8b s1,2 = 53 s1,3 = dc
S0 = s0,0s0,1s0,2s0,3 = 188a9c14 S1 = s1,0s1,1s1,2s1,3 = 818b53dc
Post S list reversal: s0,0 = 81 s0,1 = 8b s0,2 = 53 s0,3 = dc s1,0 = 18 s1,1 = 8a s1,2 = 9c s1,3 = 14
S0 = s0,0s0,1s0,2s0,3 = 818b53dc S1 = s1,0s1,1s1,2s1,3 = 188a9c14


Key Schedule: K0 and K1
i = 0 i = 0
h input = X = x0x1x2x3 = 2ip = 00000000 h input = X = x0x1x2x3 = (2i+1)p = 01010101
x0 = 00 x1 = 00 x2 = 00 x3 = 00 x0 = 01 x1 = 01 x2 = 01 x3 = 01
y2,0 = 00 y2,1 = 00 y2,2 = 00 y2,3 = 00 y2,0 = 01 y2,1 = 01 y2,2 = 01 y2,3 = 01
q0.in=00
a0=0 b0=0
a1=0 b1=0
a2=8 b2=e
a3=6 b3=f
a4=9 b4=a
q0.out=a9
l1,3=2f
q0.in=1f
a0=1 b0=f
a1=e b1=6
a2=a b2=3
a3=9 b3=3
a4=8 b4=4
q0.out=48
l0,3=5c
q1.in=d7
a0=d b0=7
a1=a b1=e
a2=9 b2=0
a3=9 b3=1
a4=e b4=9
q1.out=9e
q1.in=00
a0=0 b0=0
a1=0 b1=0
a2=2 b2=1
a3=3 b3=a
a4=5 b4=7
q1.out=75
l1,2=ec
q0.in=ca
a0=c b0=a
a1=6 b1=9
a2=3 b2=4
a3=7 b3=9
a4=0 b4=b
q0.out=b0
l0,2=9f
q0.in=e8
a0=e b0=8
a1=6 b1=a
a2=3 b2=a
a3=9 b3=e
a4=8 b4=c
q0.out=c8
q0.in=00
a0=0 b0=0
a1=0 b1=0
a2=8 b2=e
a3=6 b3=f
a4=9 b4=a
q0.out=a9
l1,1=bf
q1.in=45
a0=4 b0=5
a1=1 b1=e
a2=8 b2=0
a3=8 b3=8
a4=0 b4=6
q1.out=60
l0,1=58
q1.in=ff
a0=f b0=f
a1=0 b1=8
a2=2 b2=6
a3=4 b3=1
a4=1 b4=9
q1.out=91
q1.in=00
a0=0 b0=0
a1=0 b1=0
a2=2 b2=1
a3=3 b3=a
a4=5 b4=7
q1.out=75
l1,0=b6
q1.in=5a
a0=5 b0=a
a1=f b1=8
a2=5 b2=6
a3=3 b3=e
a4=5 b4=8
q1.out=85
l0,0=9f
q0.in=d9
a0=d b0=9
a1=4 b1=9
a2=6 b2=4
a3=2 b3=4
a4=5 b4=1
q0.out=15
q0.in=01
a0=0 b0=1
a1=1 b1=8
a2=1 b2=f
a3=e b3=6
a4=7 b4=6
q0.out=67
l1,3=5a
q0.in=4d
a0=4 b0=d
a1=9 b1=a
a2=b b2=a
a3=1 b3=6
a4=a b4=6
q0.out=6a
l0,3=32
q1.in=9c
a0=9 b0=c
a1=5 b1=7
a2=7 b2=7
a3=0 b3=4
a4=4 b4=c
q1.out=c4
q1.in=01
a0=0 b0=1
a1=1 b1=8
a2=8 b2=6
a3=e b3=b
a4=3 b4=f
q1.out=f3
l1,2=c3
q0.in=1b
a0=1 b0=b
a1=a b1=4
a2=5 b2=1
a3=4 b3=5
a4=6 b4=2
q0.out=26
l0,2=2c
q0.in=34
a0=3 b0=4
a1=7 b1=9
a2=2 b2=4
a3=6 b3=0
a4=9 b4=d
q0.out=d9
q0.in=01
a0=0 b0=1
a1=1 b1=8
a2=1 b2=f
a3=e b3=6
a4=7 b4=6
q0.out=67
l1,1=e8
q1.in=a4
a0=a b0=4
a1=e b1=8
a2=c b2=6
a3=a b3=f
a4=d b4=a
q1.out=ad
l0,1=12
q1.in=81
a0=8 b0=1
a1=9 b1=0
a2=1 b2=1
a3=0 b3=1
a4=4 b4=9
q1.out=94
q1.in=01
a0=0 b0=1
a1=1 b1=8
a2=8 b2=6
a3=e b3=b
a4=3 b4=f
q1.out=f3
l1,0=2a
q1.in=a9
a0=a b0=9
a1=3 b1=6
a2=d b2=3
a3=e b3=c
a4=3 b4=2
q1.out=23
l0,0=f6
q0.in=11
a0=1 b0=1
a1=0 b1=1
a2=8 b2=c
a3=4 b3=e
a4=6 b4=c
q0.out=c6
y0 = 9e y1 = c8 y2 = 91 y3 = 15 y0 = c4 y1 = d9 y2 = 94 y3 = c6
MDS input = Y = y0y1y2y3 = 9ec89115 MDS input = Y = y0y1y2y3 = c4d994c6
MDS output = Z = z0z1z2z3 = a595ddd3 MDS output = Z = z0z1z2z3 = 5ba596f6
z0 = a5 z1 = 95 z2 = dd z3 = d3 z0 = 5b z1 = a5 z2 = 96 z3 = f6
A0 = h(2pi, Me) = a595ddd3
B0 = ROL[h({2i+1}p, Mo),  8]
= ROL[5ba596f6,8]
= ROL[f696a55b(big endian),  8]
= 96a55bf6(big endian)
= f65ba596.
K0 = (A0 + B0) mod 232 = (a595ddd3 + f65ba596) mod 232
= (d3dd95a5(big endian) + 96a55bf6(big endian)) mod 232
= 6a82f19b(big endian) = 9bf1826a.
K1 = ROL([A0 + 2B0] mod 232,  9) = ROL([a595ddd3 + 2(f65ba596) mod32,  9)
= ROL([d3dd95a5(big endian) + 2(96a55bf6(big endian))] mod32,  9)
= ROL([d3dd95a5(big endian) + 2d4ab7ec(big endian)] mod32,  9)
= ROL(01284d91(big endian),  9) = 509b2202(big endian) = 02229b50.


Key Schedule: K2 and K3
i = 1 i = 1
h input = X = x0x1x2x3 = 2ip = 02020202 h input = X = x0x1x2x3 = (2i+1)p = 03030303
x0 = 02 x1 = 02 x2 = 02 x3 = 02 x0 = 03 x1 = 03 x2 = 03 x3 = 03
y2,0 = 02 y2,1 = 02 y2,2 = 02 y2,3 = 02 y2,0 = 03 y2,1 = 03 y2,2 = 03 y2,3 = 03
q0.in=02
a0=0 b0=2
a1=2 b1=1
a2=7 b2=c
a3=b b3=9
a4=3 b4=b
q0.out=b3
l1,3=2f
q0.in=05
a0=0 b0=5
a1=5 b1=a
a2=f b2=a
a3=5 b3=2
a4=d b4=f
q0.out=fd
l0,3=5c
q1.in=62
a0=6 b0=2
a1=4 b1=7
a2=f b2=7
a3=8 b3=c
a4=0 b4=2
q1.out=20
q1.in=02
a0=0 b0=2
a1=2 b1=1
a2=b b2=e
a3=5 b3=4
a4=6 b4=c
q1.out=c6
l1,2=ec
q0.in=79
a0=7 b0=9
a1=e b1=3
a2=a b2=8
a3=2 b3=e
a4=5 b4=c
q0.out=c5
l0,2=9f
q0.in=9d
a0=9 b0=d
a1=4 b1=f
a2=6 b2=d
a3=b b3=8
a4=3 b4=9
q0.out=93
q0.in=02
a0=0 b0=2
a1=2 b1=1
a2=7 b2=c
a3=b b3=9
a4=3 b4=b
q0.out=b3
l1,1=bf
q1.in=5f
a0=5 b0=f
a1=a b1=2
a2=9 b2=2
a3=b b3=0
a4=8 b4=b
q1.out=b8
l0,1=58
q1.in=27
a0=2 b0=7
a1=5 b1=9
a2=7 b2=d
a3=a b3=1
a4=d b4=9
q1.out=9d
q1.in=02
a0=0 b0=2
a1=2 b1=1
a2=b b2=e
a3=5 b3=4
a4=6 b4=c
q1.out=c6
l1,0=b6
q1.in=e9
a0=e b0=9
a1=7 b1=2
a2=e b2=2
a3=c b3=f
a4=2 b4=a
q1.out=a2
l0,0=9f
q0.in=fe
a0=f b0=e
a1=1 b1=0
a2=1 b2=e
a3=f b3=e
a4=1 b4=c
q0.out=c1
q0.in=03
a0=0 b0=3
a1=3 b1=9
a2=d b2=4
a3=9 b3=7
a4=8 b4=e
q0.out=e8
l1,3=5a
q0.in=c2
a0=c b0=2
a1=e b1=d
a2=a b2=0
a3=a b3=a
a4=f b4=3
q0.out=3f
l0,3=32
q1.in=c9
a0=c b0=9
a1=5 b1=0
a2=7 b2=1
a3=6 b3=7
a4=9 b4=e
q1.out=e9
q1.in=03
a0=0 b0=3
a1=3 b1=9
a2=d b2=d
a3=0 b3=b
a4=4 b4=f
q1.out=f4
l1,2=c3
q0.in=1c
a0=1 b0=c
a1=d b1=f
a2=c b2=d
a3=1 b3=2
a4=a b4=f
q0.out=fa
l0,2=2c
q0.in=e8
a0=e b0=8
a1=6 b1=a
a2=3 b2=a
a3=9 b3=e
a4=8 b4=c
q0.out=c8
q0.in=03
a0=0 b0=3
a1=3 b1=9
a2=d b2=4
a3=9 b3=7
a4=8 b4=e
q0.out=e8
l1,1=e8
q1.in=2b
a0=2 b0=b
a1=9 b1=f
a2=1 b2=8
a3=9 b3=d
a4=e b4=0
q1.out=0e
l0,1=12
q1.in=22
a0=2 b0=2
a1=0 b1=3
a2=2 b2=b
a3=9 b3=f
a4=e b4=a
q1.out=ae
q1.in=03
a0=0 b0=3
a1=3 b1=9
a2=d b2=d
a3=0 b3=b
a4=4 b4=f
q1.out=f4
l1,0=2a
q1.in=ae
a0=a b0=e
a1=4 b1=d
a2=f b2=9
a3=6 b3=b
a4=9 b4=f
q1.out=f9
l0,0=f6
q0.in=cb
a0=c b0=b
a1=7 b1=1
a2=2 b2=c
a3=e b3=4
a4=7 b4=1
q0.out=17
y0 = 20 y1 = 93 y2 = 9d y3 = c1 y0 = e9 y1 = c8 y2 = ae y3 = 17
MDS input = Y = y0y1y2y3 = 20939dc1 MDS input = Y = y0y1y2y3 = e9c8ae17
MDS output = Z = z0z1z2z3 = cf57831a MDS output = Z = z0z1z2z3 = ba665e1b
z0 = cf z1 = 57 z2 = 83 z3 = 1a z0 = ba z1 = 66 z2 = 5e z3 = 1b
A1 = h(2pi, Me) = cf57831a
B1 = ROL[h({2i+1}p, Mo),  8]
= ROL[ba665e1b,8]
= ROL[1b5e66ba(big endian),  8]
= 5e66ba1b(big endian)
= 1bba665e.
K2 = (A1 + B1) mod 232 = (cf57831a + 1bba665e) mod 232
= (1a8357cf(big endian) + 5e66ba1b(big endian)) mod 232
= 78ea11ea(big endian) = ea11ea78.
K3 = ROL([A1 + 2B1] mod 232,  9) = ROL([cf57831a + 2(1bba665e) mod32,  9)
= ROL([1a8357cf(big endian) + 2(5e66ba1b(big endian))] mod32,  9)
= ROL([1a8357cf(big endian) + bccd7436(big endian)] mod32,  9)
= ROL(d750cc05(big endian),  9) = a1980bae(big endian) = ae0b98a1.


Key Schedule: K4 and K5
i = 2 i = 2
h input = X = x0x1x2x3 = 2ip = 04040404 h input = X = x0x1x2x3 = (2i+1)p = 05050505
x0 = 04 x1 = 04 x2 = 04 x3 = 04 x0 = 05 x1 = 05 x2 = 05 x3 = 05
y2,0 = 04 y2,1 = 04 y2,2 = 04 y2,3 = 04 y2,0 = 05 y2,1 = 05 y2,2 = 05 y2,3 = 05
q0.in=04
a0=0 b0=4
a1=4 b1=2
a2=6 b2=b
a3=d b3=b
a4=4 b4=0
q0.out=04
l1,3=2f
q0.in=b2
a0=b b0=2
a1=9 b1=2
a2=b b2=b
a3=0 b3=e
a4=b b4=c
q0.out=cb
l0,3=5c
q1.in=54
a0=5 b0=4
a1=1 b1=f
a2=8 b2=8
a3=0 b3=c
a4=4 b4=2
q1.out=24
q1.in=04
a0=0 b0=4
a1=4 b1=2
a2=f b2=2
a3=d b3=6
a4=b b4=d
q1.out=db
l1,2=ec
q0.in=64
a0=6 b0=4
a1=2 b1=4
a2=7 b2=1
a3=6 b3=7
a4=9 b4=e
q0.out=e9
l0,2=9f
q0.in=b1
a0=b b0=1
a1=a b1=b
a2=5 b2=6
a3=3 b3=e
a4=e b4=c
q0.out=ce
q0.in=04
a0=0 b0=4
a1=4 b1=2
a2=6 b2=b
a3=d b3=b
a4=4 b4=0
q0.out=04
l1,1=bf
q1.in=e8
a0=e b0=8
a1=6 b1=a
a2=6 b2=a
a3=c b3=3
a4=2 b4=1
q1.out=12
l0,1=58
q1.in=8d
a0=8 b0=d
a1=5 b1=6
a2=7 b2=3
a3=4 b3=6
a4=1 b4=d
q1.out=d1
q1.in=04
a0=0 b0=4
a1=4 b1=2
a2=f b2=2
a3=d b3=6
a4=b b4=d
q1.out=db
l1,0=b6
q1.in=f4
a0=f b0=4
a1=b b1=5
a2=4 b2=c
a3=8 b3=2
a4=0 b4=5
q1.out=50
l0,0=9f
q0.in=0c
a0=0 b0=c
a1=c b1=6
a2=e b2=3
a3=d b3=7
a4=4 b4=e
q0.out=e4
q0.in=05
a0=0 b0=5
a1=5 b1=a
a2=f b2=a
a3=5 b3=2
a4=d b4=f
q0.out=fd
l1,3=5a
q0.in=d7
a0=d b0=7
a1=a b1=e
a2=5 b2=9
a3=c b3=1
a4=2 b4=7
q0.out=72
l0,3=32
q1.in=84
a0=8 b0=4
a1=c b1=a
a2=0 b2=a
a3=a b3=5
a4=d b4=3
q1.out=3d
q1.in=05
a0=0 b0=5
a1=5 b1=a
a2=7 b2=a
a3=d b3=a
a4=b b4=7
q1.out=7b
l1,2=c3
q0.in=93
a0=9 b0=3
a1=a b1=8
a2=5 b2=f
a3=a b3=2
a4=f b4=f
q0.out=ff
l0,2=2c
q0.in=ed
a0=e b0=d
a1=3 b1=0
a2=d b2=e
a3=3 b3=2
a4=e b4=f
q0.out=fe
q0.in=05
a0=0 b0=5
a1=5 b1=a
a2=f b2=a
a3=5 b3=2
a4=d b4=f
q0.out=fd
l1,1=e8
q1.in=3e
a0=3 b0=e
a1=d b1=c
a2=a b2=f
a3=5 b3=5
a4=6 b4=3
q1.out=36
l0,1=12
q1.in=1a
a0=1 b0=a
a1=b b1=c
a2=4 b2=f
a3=b b3=b
a4=8 b4=f
q1.out=f8
q1.in=05
a0=0 b0=5
a1=5 b1=a
a2=7 b2=a
a3=d b3=a
a4=b b4=7
q1.out=7b
l1,0=2a
q1.in=21
a0=2 b0=1
a1=3 b1=a
a2=d b2=a
a3=7 b3=0
a4=a b4=b
q1.out=ba
l0,0=f6
q0.in=88
a0=8 b0=8
a1=0 b1=c
a2=8 b2=7
a3=f b3=3
a4=1 b4=4
q0.out=41
y0 = 24 y1 = ce y2 = d1 y3 = e4 y0 = 3d y1 = fe y2 = f8 y3 = 41
MDS input = Y = y0y1y2y3 = 24ced1e4 MDS input = Y = y0y1y2y3 = 3dfef841
MDS output = Z = z0z1z2z3 = 6884084f MDS output = Z = z0z1z2z3 = fa99d08d
z0 = 68 z1 = 84 z2 = 08 z3 = 4f z0 = fa z1 = 99 z2 = d0 z3 = 8d
A2 = h(2pi, Me) = 6884084f
B2 = ROL[h({2i+1}p, Mo),  8]
= ROL[fa99d08d,8]
= ROL[8dd099fa(big endian),  8]
= d099fa8d(big endian)
= 8dfa99d0.
K4 = (A2 + B2) mod 232 = (6884084f + 8dfa99d0) mod 232
= (4f088468(big endian) + d099fa8d(big endian)) mod 232
= 1fa27ef5(big endian) = f57ea21f.
K5 = ROL([A2 + 2B2] mod 232,  9) = ROL([6884084f + 2(8dfa99d0) mod32,  9)
= ROL([4f088468(big endian) + 2(d099fa8d(big endian))] mod32,  9)
= ROL([4f088468(big endian) + a133f51a(big endian)] mod32,  9)
= ROL(f03c7982(big endian),  9) = 78f305e0(big endian) = e005f378.


Key Schedule: K6 and K7
i = 3 i = 3
h input = X = x0x1x2x3 = 2ip = 06060606 h input = X = x0x1x2x3 = (2i+1)p = 07070707
x0 = 06 x1 = 06 x2 = 06 x3 = 06 x0 = 07 x1 = 07 x2 = 07 x3 = 07
y2,0 = 06 y2,1 = 06 y2,2 = 06 y2,3 = 06 y2,0 = 07 y2,1 = 07 y2,2 = 07 y2,3 = 07
q0.in=06
a0=0 b0=6
a1=6 b1=3
a2=3 b2=8
a3=b b3=f
a4=3 b4=a
q0.out=a3
l1,3=2f
q0.in=15
a0=1 b0=5
a1=4 b1=3
a2=6 b2=8
a3=e b3=2
a4=7 b4=f
q0.out=f7
l0,3=5c
q1.in=68
a0=6 b0=8
a1=e b1=2
a2=c b2=2
a3=e b3=d
a4=3 b4=0
q1.out=03
q1.in=06
a0=0 b0=6
a1=6 b1=3
a2=6 b2=b
a3=d b3=b
a4=b b4=f
q1.out=fb
l1,2=ec
q0.in=44
a0=4 b0=4
a1=0 b1=6
a2=8 b2=3
a3=b b3=1
a4=3 b4=7
q0.out=73
l0,2=9f
q0.in=2b
a0=2 b0=b
a1=9 b1=f
a2=b b2=d
a3=6 b3=d
a4=9 b4=5
q0.out=59
q0.in=06
a0=0 b0=6
a1=6 b1=3
a2=3 b2=8
a3=b b3=f
a4=3 b4=a
q0.out=a3
l1,1=bf
q1.in=4f
a0=4 b0=f
a1=b b1=b
a2=4 b2=5
a3=1 b3=e
a4=c b4=8
q1.out=8c
l0,1=58
q1.in=13
a0=1 b0=3
a1=2 b1=0
a2=b b2=1
a3=a b3=b
a4=d b4=f
q1.out=fd
q1.in=06
a0=0 b0=6
a1=6 b1=3
a2=6 b2=b
a3=d b3=b
a4=b b4=f
q1.out=fb
l1,0=b6
q1.in=d4
a0=d b0=4
a1=9 b1=7
a2=1 b2=7
a3=6 b3=2
a4=9 b4=5
q1.out=59
l0,0=9f
q0.in=05
a0=0 b0=5
a1=5 b1=a
a2=f b2=a
a3=5 b3=2
a4=d b4=f
q0.out=fd
q0.in=07
a0=0 b0=7
a1=7 b1=b
a2=2 b2=6
a3=4 b3=1
a4=6 b4=7
q0.out=76
l1,3=5a
q0.in=5c
a0=5 b0=c
a1=9 b1=b
a2=b b2=6
a3=d b3=0
a4=4 b4=d
q0.out=d4
l0,3=32
q1.in=22
a0=2 b0=2
a1=0 b1=3
a2=2 b2=b
a3=9 b3=f
a4=e b4=a
q1.out=ae
q1.in=07
a0=0 b0=7
a1=7 b1=b
a2=e b2=5
a3=b b3=4
a4=8 b4=c
q1.out=c8
l1,2=c3
q0.in=20
a0=2 b0=0
a1=2 b1=2
a2=7 b2=b
a3=c b3=2
a4=2 b4=f
q0.out=f2
l0,2=2c
q0.in=e0
a0=e b0=0
a1=e b1=e
a2=a b2=9
a3=3 b3=6
a4=e b4=6
q0.out=6e
q0.in=07
a0=0 b0=7
a1=7 b1=b
a2=2 b2=6
a3=4 b3=1
a4=6 b4=7
q0.out=76
l1,1=e8
q1.in=b5
a0=b b0=5
a1=e b1=9
a2=c b2=d
a3=1 b3=2
a4=c b4=5
q1.out=5c
l0,1=12
q1.in=70
a0=7 b0=0
a1=7 b1=f
a2=e b2=8
a3=6 b3=a
a4=9 b4=7
q1.out=79
q1.in=07
a0=0 b0=7
a1=7 b1=b
a2=e b2=5
a3=b b3=4
a4=8 b4=c
q1.out=c8
l1,0=2a
q1.in=92
a0=9 b0=2
a1=b b1=0
a2=4 b2=1
a3=5 b3=c
a4=6 b4=2
q1.out=26
l0,0=f6
q0.in=14
a0=1 b0=4
a1=5 b1=b
a2=f b2=6
a3=9 b3=4
a4=8 b4=1
q0.out=18
y0 = 03 y1 = 59 y2 = fd y3 = fd y0 = ae y1 = 6e y2 = 79 y3 = 18
MDS input = Y = y0y1y2y3 = 0359fdfd MDS input = Y = y0y1y2y3 = ae6e7918
MDS output = Z = z0z1z2z3 = 8ecfe2cb MDS output = Z = z0z1z2z3 = 7b6acca3
z0 = 8e z1 = cf z2 = e2 z3 = cb z0 = 7b z1 = 6a z2 = cc z3 = a3
A3 = h(2pi, Me) = 8ecfe2cb
B3 = ROL[h({2i+1}p, Mo),  8]
= ROL[7b6acca3,8]
= ROL[a3cc6a7b(big endian),  8]
= cc6a7ba3(big endian)
= a37b6acc.
K6 = (A3 + B3) mod 232 = (8ecfe2cb + a37b6acc) mod 232
= (cbe2cf8e(big endian) + cc6a7ba3(big endian)) mod 232
= 984d4b31(big endian) = 314b4d98.
K7 = ROL([A3 + 2B3] mod 232,  9) = ROL([8ecfe2cb + 2(a37b6acc) mod32,  9)
= ROL([cbe2cf8e(big endian) + 2(cc6a7ba3(big endian))] mod32,  9)
= ROL([cbe2cf8e(big endian) + 98d4f746(big endian)] mod32,  9)
= ROL(64b7c6d4(big endian),  9) = 6f8da8c9(big endian) = c9a88d6f.


Key Schedule: K8 and K9
i = 4 i = 4
h input = X = x0x1x2x3 = 2ip = 08080808 h input = X = x0x1x2x3 = (2i+1)p = 09090909
x0 = 08 x1 = 08 x2 = 08 x3 = 08 x0 = 09 x1 = 09 x2 = 09 x3 = 09
y2,0 = 08 y2,1 = 08 y2,2 = 08 y2,3 = 08 y2,0 = 09 y2,1 = 09 y2,2 = 09 y2,3 = 09
q0.in=08
a0=0 b0=8
a1=8 b1=4
a2=0 b2=1
a3=1 b3=8
a4=a b4=9
q0.out=9a
l1,3=2f
q0.in=2c
a0=2 b0=c
a1=e b1=4
a2=a b2=1
a3=b b3=2
a4=3 b4=f
q0.out=f3
l0,3=5c
q1.in=6c
a0=6 b0=c
a1=a b1=0
a2=9 b2=1
a3=8 b3=9
a4=0 b4=4
q1.out=40
q1.in=08
a0=0 b0=8
a1=8 b1=4
a2=3 b2=4
a3=7 b3=9
a4=a b4=4
q1.out=4a
l1,2=ec
q0.in=f5
a0=f b0=5
a1=a b1=d
a2=5 b2=0
a3=5 b3=d
a4=d b4=5
q0.out=5d
l0,2=9f
q0.in=05
a0=0 b0=5
a1=5 b1=a
a2=f b2=a
a3=5 b3=2
a4=d b4=f
q0.out=fd
q0.in=08
a0=0 b0=8
a1=8 b1=4
a2=0 b2=1
a3=1 b3=8
a4=a b4=9
q0.out=9a
l1,1=bf
q1.in=76
a0=7 b0=6
a1=1 b1=c
a2=8 b2=f
a3=7 b3=7
a4=a b4=e
q1.out=ea
l0,1=58
q1.in=75
a0=7 b0=5
a1=2 b1=5
a2=b b2=c
a3=7 b3=5
a4=a b4=3
q1.out=3a
q1.in=08
a0=0 b0=8
a1=8 b1=4
a2=3 b2=4
a3=7 b3=9
a4=a b4=4
q1.out=4a
l1,0=b6
q1.in=65
a0=6 b0=5
a1=3 b1=c
a2=d b2=f
a3=2 b3=a
a4=7 b4=7
q1.out=77
l0,0=9f
q0.in=2b
a0=2 b0=b
a1=9 b1=f
a2=b b2=d
a3=6 b3=d
a4=9 b4=5
q0.out=59
q0.in=09
a0=0 b0=9
a1=9 b1=c
a2=b b2=7
a3=c b3=8
a4=2 b4=9
q0.out=92
l1,3=5a
q0.in=b8
a0=b b0=8
a1=3 b1=7
a2=d b2=5
a3=8 b3=f
a4=c b4=a
q0.out=ac
l0,3=32
q1.in=5a
a0=5 b0=a
a1=f b1=8
a2=5 b2=6
a3=3 b3=e
a4=5 b4=8
q1.out=85
q1.in=09
a0=0 b0=9
a1=9 b1=c
a2=1 b2=f
a3=e b3=6
a4=3 b4=d
q1.out=d3
l1,2=c3
q0.in=3b
a0=3 b0=b
a1=8 b1=6
a2=0 b2=3
a3=3 b3=9
a4=e b4=b
q0.out=be
l0,2=2c
q0.in=ac
a0=a b0=c
a1=6 b1=c
a2=3 b2=7
a3=4 b3=0
a4=6 b4=d
q0.out=d6
q0.in=09
a0=0 b0=9
a1=9 b1=c
a2=b b2=7
a3=c b3=8
a4=2 b4=9
q0.out=92
l1,1=e8
q1.in=51
a0=5 b0=1
a1=4 b1=5
a2=f b2=c
a3=3 b3=1
a4=5 b4=9
q1.out=95
l0,1=12
q1.in=b9
a0=b b0=9
a1=2 b1=f
a2=b b2=8
a3=3 b3=7
a4=5 b4=e
q1.out=e5
q1.in=09
a0=0 b0=9
a1=9 b1=c
a2=1 b2=f
a3=e b3=6
a4=3 b4=d
q1.out=d3
l1,0=2a
q1.in=89
a0=8 b0=9
a1=1 b1=4
a2=8 b2=4
a3=c b3=a
a4=2 b4=7
q1.out=72
l0,0=f6
q0.in=40
a0=4 b0=0
a1=4 b1=4
a2=6 b2=1
a3=7 b3=e
a4=0 b4=c
q0.out=c0
y0 = 40 y1 = fd y2 = 3a y3 = 59 y0 = 85 y1 = d6 y2 = e5 y3 = c0
MDS input = Y = y0y1y2y3 = 40fd3a59 MDS input = Y = y0y1y2y3 = 85d6e5c0
MDS output = Z = z0z1z2z3 = 87c65f05 MDS output = Z = z0z1z2z3 = cf422a6e
z0 = 87 z1 = c6 z2 = 5f z3 = 05 z0 = cf z1 = 42 z2 = 2a z3 = 6e
A4 = h(2pi, Me) = 87c65f05
B4 = ROL[h({2i+1}p, Mo),  8]
= ROL[cf422a6e,8]
= ROL[6e2a42cf(big endian),  8]
= 2a42cf6e(big endian)
= 6ecf422a.
K8 = (A4 + B4) mod 232 = (87c65f05 + 6ecf422a) mod 232
= (055fc687(big endian) + 2a42cf6e(big endian)) mod 232
= 2fa295f5(big endian) = f595a22f.
K9 = ROL([A4 + 2B4] mod 232,  9) = ROL([87c65f05 + 2(6ecf422a) mod32,  9)
= ROL([055fc687(big endian) + 2(2a42cf6e(big endian))] mod32,  9)
= ROL([055fc687(big endian) + 54859edc(big endian)] mod32,  9)
= ROL(59e56563(big endian),  9) = cacac6b3(big endian) = b3c6caca.


Key Schedule: K10 and K11
i = 5 i = 5
h input = X = x0x1x2x3 = 2ip = 0a0a0a0a h input = X = x0x1x2x3 = (2i+1)p = 0b0b0b0b
x0 = 0a x1 = 0a x2 = 0a x3 = 0a x0 = 0b x1 = 0b x2 = 0b x3 = 0b
y2,0 = 0a y2,1 = 0a y2,2 = 0a y2,3 = 0a y2,0 = 0b y2,1 = 0b y2,2 = 0b y2,3 = 0b
q0.in=0a
a0=0 b0=a
a1=a b1=5
a2=5 b2=2
a3=7 b3=c
a4=0 b4=8
q0.out=80
l1,3=2f
q0.in=36
a0=3 b0=6
a1=5 b1=8
a2=f b2=f
a3=0 b3=8
a4=b b4=9
q0.out=9b
l0,3=5c
q1.in=04
a0=0 b0=4
a1=4 b1=2
a2=f b2=2
a3=d b3=6
a4=b b4=d
q1.out=db
q1.in=0a
a0=0 b0=a
a1=a b1=5
a2=9 b2=c
a3=5 b3=7
a4=6 b4=e
q1.out=e6
l1,2=ec
q0.in=59
a0=5 b0=9
a1=c b1=1
a2=e b2=c
a3=2 b3=8
a4=5 b4=9
q0.out=95
l0,2=9f
q0.in=cd
a0=c b0=d
a1=1 b1=2
a2=1 b2=b
a3=a b3=4
a4=f b4=1
q0.out=1f
q0.in=0a
a0=0 b0=a
a1=a b1=5
a2=5 b2=2
a3=7 b3=c
a4=0 b4=8
q0.out=80
l1,1=bf
q1.in=6c
a0=6 b0=c
a1=a b1=0
a2=9 b2=1
a3=8 b3=9
a4=0 b4=4
q1.out=40
l0,1=58
q1.in=df
a0=d b0=f
a1=2 b1=a
a2=b b2=a
a3=1 b3=6
a4=c b4=d
q1.out=dc
q1.in=0a
a0=0 b0=a
a1=a b1=5
a2=9 b2=c
a3=5 b3=7
a4=6 b4=e
q1.out=e6
l1,0=b6
q1.in=c9
a0=c b0=9
a1=5 b1=0
a2=7 b2=1
a3=6 b3=7
a4=9 b4=e
q1.out=e9
l0,0=9f
q0.in=b5
a0=b b0=5
a1=e b1=9
a2=a b2=4
a3=e b3=8
a4=7 b4=9
q0.out=97
q0.in=0b
a0=0 b0=b
a1=b b1=d
a2=9 b2=0
a3=9 b3=1
a4=8 b4=7
q0.out=78
l1,3=5a
q0.in=52
a0=5 b0=2
a1=7 b1=c
a2=2 b2=7
a3=5 b3=9
a4=d b4=b
q0.out=bd
l0,3=32
q1.in=4b
a0=4 b0=b
a1=f b1=9
a2=5 b2=d
a3=8 b3=3
a4=0 b4=1
q1.out=10
q1.in=0b
a0=0 b0=b
a1=b b1=d
a2=4 b2=9
a3=d b3=8
a4=b b4=6
q1.out=6b
l1,2=c3
q0.in=83
a0=8 b0=3
a1=b b1=1
a2=9 b2=c
a3=5 b3=7
a4=d b4=e
q0.out=ed
l0,2=2c
q0.in=ff
a0=f b0=f
a1=0 b1=8
a2=8 b2=f
a3=7 b3=7
a4=0 b4=e
q0.out=e0
q0.in=0b
a0=0 b0=b
a1=b b1=d
a2=9 b2=0
a3=9 b3=1
a4=8 b4=7
q0.out=78
l1,1=e8
q1.in=bb
a0=b b0=b
a1=0 b1=e
a2=2 b2=0
a3=2 b3=2
a4=7 b4=5
q1.out=57
l0,1=12
q1.in=7b
a0=7 b0=b
a1=c b1=2
a2=0 b2=2
a3=2 b3=1
a4=7 b4=9
q1.out=97
q1.in=0b
a0=0 b0=b
a1=b b1=d
a2=4 b2=9
a3=d b3=8
a4=b b4=6
q1.out=6b
l1,0=2a
q1.in=31
a0=3 b0=1
a1=2 b1=3
a2=b b2=b
a3=0 b3=e
a4=4 b4=8
q1.out=84
l0,0=f6
q0.in=b6
a0=b b0=6
a1=d b1=0
a2=c b2=e
a3=2 b3=b
a4=5 b4=0
q0.out=05
y0 = db y1 = 1f y2 = dc y3 = 97 y0 = 10 y1 = e0 y2 = 97 y3 = 05
MDS input = Y = y0y1y2y3 = db1fdc97 MDS input = Y = y0y1y2y3 = 10e09705
MDS output = Z = z0z1z2z3 = 215c531c MDS output = Z = z0z1z2z3 = ba1abb01
z0 = 21 z1 = 5c z2 = 53 z3 = 1c z0 = ba z1 = 1a z2 = bb z3 = 01
A5 = h(2pi, Me) = 215c531c
B5 = ROL[h({2i+1}p, Mo),  8]
= ROL[ba1abb01,8]
= ROL[01bb1aba(big endian),  8]
= bb1aba01(big endian)
= 01ba1abb.
K10 = (A5 + B5) mod 232 = (215c531c + 01ba1abb) mod 232
= (1c535c21(big endian) + bb1aba01(big endian)) mod 232
= d76e1622(big endian) = 22166ed7.
K11 = ROL([A5 + 2B5] mod 232,  9) = ROL([215c531c + 2(01ba1abb) mod32,  9)
= ROL([1c535c21(big endian) + 2(bb1aba01(big endian))] mod32,  9)
= ROL([1c535c21(big endian) + 76357402(big endian)] mod32,  9)
= ROL(9288d023(big endian),  9) = 11a04725(big endian) = 2547a011.


Key Schedule: K12 and K13
i = 6 i = 6
h input = X = x0x1x2x3 = 2ip = 0c0c0c0c h input = X = x0x1x2x3 = (2i+1)p = 0d0d0d0d
x0 = 0c x1 = 0c x2 = 0c x3 = 0c x0 = 0d x1 = 0d x2 = 0d x3 = 0d
y2,0 = 0c y2,1 = 0c y2,2 = 0c y2,3 = 0c y2,0 = 0d y2,1 = 0d y2,2 = 0d y2,3 = 0d
q0.in=0c
a0=0 b0=c
a1=c b1=6
a2=e b2=3
a3=d b3=7
a4=4 b4=e
q0.out=e4
l1,3=2f
q0.in=52
a0=5 b0=2
a1=7 b1=c
a2=2 b2=7
a3=5 b3=9
a4=d b4=b
q0.out=bd
l0,3=5c
q1.in=22
a0=2 b0=2
a1=0 b1=3
a2=2 b2=b
a3=9 b3=f
a4=e b4=a
q1.out=ae
q1.in=0c
a0=0 b0=c
a1=c b1=6
a2=0 b2=3
a3=3 b3=9
a4=5 b4=4
q1.out=45
l1,2=ec
q0.in=fa
a0=f b0=a
a1=5 b1=2
a2=f b2=b
a3=4 b3=a
a4=6 b4=3
q0.out=36
l0,2=9f
q0.in=6e
a0=6 b0=e
a1=8 b1=1
a2=0 b2=c
a3=c b3=6
a4=2 b4=6
q0.out=62
q0.in=0c
a0=0 b0=c
a1=c b1=6
a2=e b2=3
a3=d b3=7
a4=4 b4=e
q0.out=e4
l1,1=bf
q1.in=08
a0=0 b0=8
a1=8 b1=4
a2=3 b2=4
a3=7 b3=9
a4=a b4=4
q1.out=4a
l0,1=58
q1.in=d5
a0=d b0=5
a1=8 b1=f
a2=3 b2=8
a3=b b3=f
a4=8 b4=a
q1.out=a8
q1.in=0c
a0=0 b0=c
a1=c b1=6
a2=0 b2=3
a3=3 b3=9
a4=5 b4=4
q1.out=45
l1,0=b6
q1.in=6a
a0=6 b0=a
a1=c b1=3
a2=0 b2=b
a3=b b3=d
a4=8 b4=0
q1.out=08
l0,0=9f
q0.in=54
a0=5 b0=4
a1=1 b1=f
a2=1 b2=d
a3=c b3=7
a4=2 b4=e
q0.out=e2
q0.in=0d
a0=0 b0=d
a1=d b1=e
a2=c b2=9
a3=5 b3=0
a4=d b4=d
q0.out=dd
l1,3=5a
q0.in=f7
a0=f b0=7
a1=8 b1=c
a2=0 b2=7
a3=7 b3=b
a4=0 b4=0
q0.out=00
l0,3=32
q1.in=f6
a0=f b0=6
a1=9 b1=4
a2=1 b2=4
a3=5 b3=b
a4=6 b4=f
q1.out=f6
q1.in=0d
a0=0 b0=d
a1=d b1=e
a2=a b2=0
a3=a b3=a
a4=d b4=7
q1.out=7d
l1,2=c3
q0.in=95
a0=9 b0=5
a1=c b1=b
a2=e b2=6
a3=8 b3=d
a4=c b4=5
q0.out=5c
l0,2=2c
q0.in=4e
a0=4 b0=e
a1=a b1=3
a2=5 b2=8
a3=d b3=9
a4=4 b4=b
q0.out=b4
q0.in=0d
a0=0 b0=d
a1=d b1=e
a2=c b2=9
a3=5 b3=0
a4=d b4=d
q0.out=dd
l1,1=e8
q1.in=1e
a0=1 b0=e
a1=f b1=e
a2=5 b2=0
a3=5 b3=d
a4=6 b4=0
q1.out=06
l0,1=12
q1.in=2a
a0=2 b0=a
a1=8 b1=7
a2=3 b2=7
a3=4 b3=0
a4=1 b4=b
q1.out=b1
q1.in=0d
a0=0 b0=d
a1=d b1=e
a2=a b2=0
a3=a b3=a
a4=d b4=7
q1.out=7d
l1,0=2a
q1.in=27
a0=2 b0=7
a1=5 b1=9
a2=7 b2=d
a3=a b3=1
a4=d b4=9
q1.out=9d
l0,0=f6
q0.in=af
a0=a b0=f
a1=5 b1=5
a2=f b2=2
a3=d b3=6
a4=4 b4=6
q0.out=64
y0 = ae y1 = 62 y2 = a8 y3 = e2 y0 = f6 y1 = b4 y2 = b1 y3 = 64
MDS input = Y = y0y1y2y3 = ae62a8e2 MDS input = Y = y0y1y2y3 = f6b4b164
MDS output = Z = z0z1z2z3 = bdfa1fbc MDS output = Z = z0z1z2z3 = 8ff363e6
z0 = bd z1 = fa z2 = 1f z3 = bc z0 = 8f z1 = f3 z2 = 63 z3 = e6
A6 = h(2pi, Me) = bdfa1fbc
B6 = ROL[h({2i+1}p, Mo),  8]
= ROL[8ff363e6,8]
= ROL[e663f38f(big endian),  8]
= 63f38fe6(big endian)
= e68ff363.
K12 = (A6 + B6) mod 232 = (bdfa1fbc + e68ff363) mod 232
= (bc1ffabd(big endian) + 63f38fe6(big endian)) mod 232
= 20138aa3(big endian) = a38a1320.
K13 = ROL([A6 + 2B6] mod 232,  9) = ROL([bdfa1fbc + 2(e68ff363) mod32,  9)
= ROL([bc1ffabd(big endian) + 2(63f38fe6(big endian))] mod32,  9)
= ROL([bc1ffabd(big endian) + c7e71fcc(big endian)] mod32,  9)
= ROL(84071a89(big endian),  9) = 0e351308(big endian) = 0813350e.


Key Schedule: K14 and K15
i = 7 i = 7
h input = X = x0x1x2x3 = 2ip = 0e0e0e0e h input = X = x0x1x2x3 = (2i+1)p = 0f0f0f0f
x0 = 0e x1 = 0e x2 = 0e x3 = 0e x0 = 0f x1 = 0f x2 = 0f x3 = 0f
y2,0 = 0e y2,1 = 0e y2,2 = 0e y2,3 = 0e y2,0 = 0f y2,1 = 0f y2,2 = 0f y2,3 = 0f
q0.in=0e
a0=0 b0=e
a1=e b1=7
a2=a b2=5
a3=f b3=0
a4=1 b4=d
q0.out=d1
l1,3=2f
q0.in=67
a0=6 b0=7
a1=1 b1=d
a2=1 b2=0
a3=1 b3=9
a4=a b4=b
q0.out=ba
l0,3=5c
q1.in=25
a0=2 b0=5
a1=7 b1=8
a2=e b2=6
a3=8 b3=d
a4=0 b4=0
q1.out=00
q1.in=0e
a0=0 b0=e
a1=e b1=7
a2=c b2=7
a3=b b3=7
a4=8 b4=e
q1.out=e8
l1,2=ec
q0.in=57
a0=5 b0=7
a1=2 b1=6
a2=7 b2=3
a3=4 b3=6
a4=6 b4=6
q0.out=66
l0,2=9f
q0.in=3e
a0=3 b0=e
a1=d b1=c
a2=c b2=7
a3=b b3=7
a4=3 b4=e
q0.out=e3
q0.in=0e
a0=0 b0=e
a1=e b1=7
a2=a b2=5
a3=f b3=0
a4=1 b4=d
q0.out=d1
l1,1=bf
q1.in=3d
a0=3 b0=d
a1=e b1=5
a2=c b2=c
a3=0 b3=a
a4=4 b4=7
q1.out=74
l0,1=58
q1.in=eb
a0=e b0=b
a1=5 b1=3
a2=7 b2=b
a3=c b3=2
a4=2 b4=5
q1.out=52
q1.in=0e
a0=0 b0=e
a1=e b1=7
a2=c b2=7
a3=b b3=7
a4=8 b4=e
q1.out=e8
l1,0=b6
q1.in=c7
a0=c b0=7
a1=b b1=7
a2=4 b2=7
a3=3 b3=f
a4=5 b4=a
q1.out=a5
l0,0=9f
q0.in=f9
a0=f b0=9
a1=6 b1=b
a2=3 b2=6
a3=5 b3=8
a4=d b4=9
q0.out=9d
q0.in=0f
a0=0 b0=f
a1=f b1=f
a2=4 b2=d
a3=9 b3=a
a4=8 b4=3
q0.out=38
l1,3=5a
q0.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=f
a3=2 b3=a
a4=5 b4=3
q0.out=35
l0,3=32
q1.in=c3
a0=c b0=3
a1=f b1=5
a2=5 b2=c
a3=9 b3=b
a4=e b4=f
q1.out=fe
q1.in=0f
a0=0 b0=f
a1=f b1=f
a2=5 b2=8
a3=d b3=9
a4=b b4=4
q1.out=4b
l1,2=c3
q0.in=a3
a0=a b0=3
a1=9 b1=3
a2=b b2=8
a3=3 b3=7
a4=e b4=e
q0.out=ee
l0,2=2c
q0.in=fc
a0=f b0=c
a1=3 b1=1
a2=d b2=c
a3=1 b3=3
a4=a b4=4
q0.out=4a
q0.in=0f
a0=0 b0=f
a1=f b1=f
a2=4 b2=d
a3=9 b3=a
a4=8 b4=3
q0.out=38
l1,1=e8
q1.in=fb
a0=f b0=b
a1=4 b1=a
a2=f b2=a
a3=5 b3=2
a4=6 b4=5
q1.out=56
l0,1=12
q1.in=7a
a0=7 b0=a
a1=d b1=a
a2=a b2=a
a3=0 b3=f
a4=4 b4=a
q1.out=a4
q1.in=0f
a0=0 b0=f
a1=f b1=f
a2=5 b2=8
a3=d b3=9
a4=b b4=4
q1.out=4b
l1,0=2a
q1.in=11
a0=1 b0=1
a1=0 b1=1
a2=2 b2=e
a3=c b3=5
a4=2 b4=3
q1.out=32
l0,0=f6
q0.in=00
a0=0 b0=0
a1=0 b1=0
a2=8 b2=e
a3=6 b3=f
a4=9 b4=a
q0.out=a9
y0 = 00 y1 = e3 y2 = 52 y3 = 9d y0 = fe y1 = 4a y2 = a4 y3 = a9
MDS input = Y = y0y1y2y3 = 00e3529d MDS input = Y = y0y1y2y3 = fe4aa4a9
MDS output = Z = z0z1z2z3 = e2b67dd8 MDS output = Z = z0z1z2z3 = 63ca7b46
z0 = e2 z1 = b6 z2 = 7d z3 = d8 z0 = 63 z1 = ca z2 = 7b z3 = 46
A7 = h(2pi, Me) = e2b67dd8
B7 = ROL[h({2i+1}p, Mo),  8]
= ROL[63ca7b46,8]
= ROL[467bca63(big endian),  8]
= 7bca6346(big endian)
= 4663ca7b.
K14 = (A7 + B7) mod 232 = (e2b67dd8 + 4663ca7b) mod 232
= (d87db6e2(big endian) + 7bca6346(big endian)) mod 232
= 54481a28(big endian) = 281a4854.
K15 = ROL([A7 + 2B7] mod 232,  9) = ROL([e2b67dd8 + 2(4663ca7b) mod32,  9)
= ROL([d87db6e2(big endian) + 2(7bca6346(big endian))] mod32,  9)
= ROL([d87db6e2(big endian) + f794c68c(big endian)] mod32,  9)
= ROL(d0127d6e(big endian),  9) = 24fadda0(big endian) = a0ddfa24.


Key Schedule: K16 and K17
i = 8 i = 8
h input = X = x0x1x2x3 = 2ip = 10101010 h input = X = x0x1x2x3 = (2i+1)p = 11111111
x0 = 10 x1 = 10 x2 = 10 x3 = 10 x0 = 11 x1 = 11 x2 = 11 x3 = 11
y2,0 = 10 y2,1 = 10 y2,2 = 10 y2,3 = 10 y2,0 = 11 y2,1 = 11 y2,2 = 11 y2,3 = 11
q0.in=10
a0=1 b0=0
a1=1 b1=9
a2=1 b2=4
a3=5 b3=b
a4=d b4=0
q0.out=0d
l1,3=2f
q0.in=bb
a0=b b0=b
a1=0 b1=e
a2=8 b2=9
a3=1 b3=4
a4=a b4=1
q0.out=1a
l0,3=5c
q1.in=85
a0=8 b0=5
a1=d b1=2
a2=a b2=2
a3=8 b3=b
a4=0 b4=f
q1.out=f0
q1.in=10
a0=1 b0=0
a1=1 b1=9
a2=8 b2=d
a3=5 b3=6
a4=6 b4=d
q1.out=d6
l1,2=ec
q0.in=69
a0=6 b0=9
a1=f b1=a
a2=4 b2=a
a3=e b3=1
a4=7 b4=7
q0.out=77
l0,2=9f
q0.in=2f
a0=2 b0=f
a1=d b1=d
a2=c b2=0
a3=c b3=c
a4=2 b4=8
q0.out=82
q0.in=10
a0=1 b0=0
a1=1 b1=9
a2=1 b2=4
a3=5 b3=b
a4=d b4=0
q0.out=0d
l1,1=bf
q1.in=e1
a0=e b0=1
a1=f b1=6
a2=5 b2=3
a3=6 b3=4
a4=9 b4=c
q1.out=c9
l0,1=58
q1.in=56
a0=5 b0=6
a1=3 b1=e
a2=d b2=0
a3=d b3=5
a4=b b4=3
q1.out=3b
q1.in=10
a0=1 b0=0
a1=1 b1=9
a2=8 b2=d
a3=5 b3=6
a4=6 b4=d
q1.out=d6
l1,0=b6
q1.in=f9
a0=f b0=9
a1=6 b1=b
a2=6 b2=5
a3=3 b3=c
a4=5 b4=2
q1.out=25
l0,0=9f
q0.in=79
a0=7 b0=9
a1=e b1=3
a2=a b2=8
a3=2 b3=e
a4=5 b4=c
q0.out=c5
q0.in=11
a0=1 b0=1
a1=0 b1=1
a2=8 b2=c
a3=4 b3=e
a4=6 b4=c
q0.out=c6
l1,3=5a
q0.in=ec
a0=e b0=c
a1=2 b1=8
a2=7 b2=f
a3=8 b3=0
a4=c b4=d
q0.out=dc
l0,3=32
q1.in=2a
a0=2 b0=a
a1=8 b1=7
a2=3 b2=7
a3=4 b3=0
a4=1 b4=b
q1.out=b1
q1.in=11
a0=1 b0=1
a1=0 b1=1
a2=2 b2=e
a3=c b3=5
a4=2 b4=3
q1.out=32
l1,2=c3
q0.in=da
a0=d b0=a
a1=7 b1=0
a2=2 b2=e
a3=c b3=5
a4=2 b4=2
q0.out=22
l0,2=2c
q0.in=30
a0=3 b0=0
a1=3 b1=b
a2=d b2=6
a3=b b3=6
a4=3 b4=6
q0.out=63
q0.in=11
a0=1 b0=1
a1=0 b1=1
a2=8 b2=c
a3=4 b3=e
a4=6 b4=c
q0.out=c6
l1,1=e8
q1.in=05
a0=0 b0=5
a1=5 b1=a
a2=7 b2=a
a3=d b3=a
a4=b b4=7
q1.out=7b
l0,1=12
q1.in=57
a0=5 b0=7
a1=2 b1=6
a2=b b2=3
a3=8 b3=a
a4=0 b4=7
q1.out=70
q1.in=11
a0=1 b0=1
a1=0 b1=1
a2=2 b2=e
a3=c b3=5
a4=2 b4=3
q1.out=32
l1,0=2a
q1.in=68
a0=6 b0=8
a1=e b1=2
a2=c b2=2
a3=e b3=d
a4=3 b4=0
q1.out=03
l0,0=f6
q0.in=31
a0=3 b0=1
a1=2 b1=3
a2=7 b2=8
a3=f b3=b
a4=1 b4=0
q0.out=01
y0 = f0 y1 = 82 y2 = 3b y3 = c5 y0 = b1 y1 = 63 y2 = 70 y3 = 01
MDS input = Y = y0y1y2y3 = f0823bc5 MDS input = Y = y0y1y2y3 = b1637001
MDS output = Z = z0z1z2z3 = d22ce1ea MDS output = Z = z0z1z2z3 = 96822147
z0 = d2 z1 = 2c z2 = e1 z3 = ea z0 = 96 z1 = 82 z2 = 21 z3 = 47
A8 = h(2pi, Me) = d22ce1ea
B8 = ROL[h({2i+1}p, Mo),  8]
= ROL[96822147,8]
= ROL[47218296(big endian),  8]
= 21829647(big endian)
= 47968221.
K16 = (A8 + B8) mod 232 = (d22ce1ea + 47968221) mod 232
= (eae12cd2(big endian) + 21829647(big endian)) mod 232
= 0c63c319(big endian) = 19c3630c.
K17 = ROL([A8 + 2B8] mod 232,  9) = ROL([d22ce1ea + 2(47968221) mod32,  9)
= ROL([eae12cd2(big endian) + 2(21829647(big endian))] mod32,  9)
= ROL([eae12cd2(big endian) + 43052c8e(big endian)] mod32,  9)
= ROL(2de65960(big endian),  9) = ccb2c05b(big endian) = 5bc0b2cc.


Key Schedule: K18 and K19
i = 9 i = 9
h input = X = x0x1x2x3 = 2ip = 12121212 h input = X = x0x1x2x3 = (2i+1)p = 13131313
x0 = 12 x1 = 12 x2 = 12 x3 = 12 x0 = 13 x1 = 13 x2 = 13 x3 = 13
y2,0 = 12 y2,1 = 12 y2,2 = 12 y2,3 = 12 y2,0 = 13 y2,1 = 13 y2,2 = 13 y2,3 = 13
q0.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=f
a3=2 b3=a
a4=5 b4=3
q0.out=35
l1,3=2f
q0.in=83
a0=8 b0=3
a1=b b1=1
a2=9 b2=c
a3=5 b3=7
a4=d b4=e
q0.out=ed
l0,3=5c
q1.in=72
a0=7 b0=2
a1=5 b1=e
a2=7 b2=0
a3=7 b3=f
a4=a b4=a
q1.out=aa
q1.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=6
a3=b b3=6
a4=8 b4=d
q1.out=d8
l1,2=ec
q0.in=67
a0=6 b0=7
a1=1 b1=d
a2=1 b2=0
a3=1 b3=9
a4=a b4=b
q0.out=ba
l0,2=9f
q0.in=e2
a0=e b0=2
a1=c b1=f
a2=e b2=d
a3=3 b3=0
a4=e b4=d
q0.out=de
q0.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=f
a3=2 b3=a
a4=5 b4=3
q0.out=35
l1,1=bf
q1.in=d9
a0=d b0=9
a1=4 b1=9
a2=f b2=d
a3=2 b3=9
a4=7 b4=4
q1.out=47
l0,1=58
q1.in=d8
a0=d b0=8
a1=5 b1=1
a2=7 b2=e
a3=9 b3=8
a4=e b4=6
q1.out=6e
q1.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=6
a3=b b3=6
a4=8 b4=d
q1.out=d8
l1,0=b6
q1.in=f7
a0=f b0=7
a1=8 b1=c
a2=3 b2=f
a3=c b3=4
a4=2 b4=c
q1.out=c2
l0,0=9f
q0.in=9e
a0=9 b0=e
a1=7 b1=6
a2=2 b2=3
a3=1 b3=b
a4=a b4=0
q0.out=0a
q0.in=13
a0=1 b0=3
a1=2 b1=0
a2=7 b2=e
a3=9 b3=8
a4=8 b4=9
q0.out=98
l1,3=5a
q0.in=b2
a0=b b0=2
a1=9 b1=2
a2=b b2=b
a3=0 b3=e
a4=b b4=c
q0.out=cb
l0,3=32
q1.in=3d
a0=3 b0=d
a1=e b1=5
a2=c b2=c
a3=0 b3=a
a4=4 b4=7
q1.out=74
q1.in=13
a0=1 b0=3
a1=2 b1=0
a2=b b2=1
a3=a b3=b
a4=d b4=f
q1.out=fd
l1,2=c3
q0.in=15
a0=1 b0=5
a1=4 b1=3
a2=6 b2=8
a3=e b3=2
a4=7 b4=f
q0.out=f7
l0,2=2c
q0.in=e5
a0=e b0=5
a1=b b1=4
a2=9 b2=1
a3=8 b3=9
a4=c b4=b
q0.out=bc
q0.in=13
a0=1 b0=3
a1=2 b1=0
a2=7 b2=e
a3=9 b3=8
a4=8 b4=9
q0.out=98
l1,1=e8
q1.in=5b
a0=5 b0=b
a1=e b1=0
a2=c b2=1
a3=d b3=4
a4=b b4=c
q1.out=cb
l0,1=12
q1.in=e7
a0=e b0=7
a1=9 b1=5
a2=1 b2=c
a3=d b3=f
a4=b b4=a
q1.out=ab
q1.in=13
a0=1 b0=3
a1=2 b1=0
a2=b b2=1
a3=a b3=b
a4=d b4=f
q1.out=fd
l1,0=2a
q1.in=a7
a0=a b0=7
a1=d b1=1
a2=a b2=e
a3=4 b3=d
a4=1 b4=0
q1.out=01
l0,0=f6
q0.in=33
a0=3 b0=3
a1=0 b1=2
a2=8 b2=b
a3=3 b3=5
a4=e b4=2
q0.out=2e
y0 = aa y1 = de y2 = 6e y3 = 0a y0 = 74 y1 = bc y2 = ab y3 = 2e
MDS input = Y = y0y1y2y3 = aade6e0a MDS input = Y = y0y1y2y3 = 74bcab2e
MDS output = Z = z0z1z2z3 = e5faebf5 MDS output = Z = z0z1z2z3 = 4704edf0
z0 = e5 z1 = fa z2 = eb z3 = f5 z0 = 47 z1 = 04 z2 = ed z3 = f0
A9 = h(2pi, Me) = e5faebf5
B9 = ROL[h({2i+1}p, Mo),  8]
= ROL[4704edf0,8]
= ROL[f0ed0447(big endian),  8]
= ed0447f0(big endian)
= f04704ed.
K18 = (A9 + B9) mod 232 = (e5faebf5 + f04704ed) mod 232
= (f5ebfae5(big endian) + ed0447f0(big endian)) mod 232
= e2f042d5(big endian) = d542f0e2.
K19 = ROL([A9 + 2B9] mod 232,  9) = ROL([e5faebf5 + 2(f04704ed) mod32,  9)
= ROL([f5ebfae5(big endian) + 2(ed0447f0(big endian))] mod32,  9)
= ROL([f5ebfae5(big endian) + da088fe0(big endian)] mod32,  9)
= ROL(cff48ac5(big endian),  9) = e9158b9f(big endian) = 9f8b15e9.


Key Schedule: K20 and K21
i = a i = a
h input = X = x0x1x2x3 = 2ip = 14141414 h input = X = x0x1x2x3 = (2i+1)p = 15151515
x0 = 14 x1 = 14 x2 = 14 x3 = 14 x0 = 15 x1 = 15 x2 = 15 x3 = 15
y2,0 = 14 y2,1 = 14 y2,2 = 14 y2,3 = 14 y2,0 = 15 y2,1 = 15 y2,2 = 15 y2,3 = 15
q0.in=14
a0=1 b0=4
a1=5 b1=b
a2=f b2=6
a3=9 b3=4
a4=8 b4=1
q0.out=18
l1,3=2f
q0.in=ae
a0=a b0=e
a1=4 b1=d
a2=6 b2=0
a3=6 b3=6
a4=9 b4=6
q0.out=69
l0,3=5c
q1.in=f6
a0=f b0=6
a1=9 b1=4
a2=1 b2=4
a3=5 b3=b
a4=6 b4=f
q1.out=f6
q1.in=14
a0=1 b0=4
a1=5 b1=b
a2=7 b2=5
a3=2 b3=5
a4=7 b4=3
q1.out=37
l1,2=ec
q0.in=88
a0=8 b0=8
a1=0 b1=c
a2=8 b2=7
a3=f b3=3
a4=1 b4=4
q0.out=41
l0,2=9f
q0.in=19
a0=1 b0=9
a1=8 b1=5
a2=0 b2=2
a3=2 b3=1
a4=5 b4=7
q0.out=75
q0.in=14
a0=1 b0=4
a1=5 b1=b
a2=f b2=6
a3=9 b3=4
a4=8 b4=1
q0.out=18
l1,1=bf
q1.in=f4
a0=f b0=4
a1=b b1=5
a2=4 b2=c
a3=8 b3=2
a4=0 b4=5
q1.out=50
l0,1=58
q1.in=cf
a0=c b0=f
a1=3 b1=3
a2=d b2=b
a3=6 b3=8
a4=9 b4=6
q1.out=69
q1.in=14
a0=1 b0=4
a1=5 b1=b
a2=7 b2=5
a3=2 b3=5
a4=7 b4=3
q1.out=37
l1,0=b6
q1.in=18
a0=1 b0=8
a1=9 b1=d
a2=1 b2=9
a3=8 b3=5
a4=0 b4=3
q1.out=30
l0,0=9f
q0.in=6c
a0=6 b0=c
a1=a b1=0
a2=5 b2=e
a3=b b3=a
a4=3 b4=3
q0.out=33
q0.in=15
a0=1 b0=5
a1=4 b1=3
a2=6 b2=8
a3=e b3=2
a4=7 b4=f
q0.out=f7
l1,3=5a
q0.in=dd
a0=d b0=d
a1=0 b1=b
a2=8 b2=6
a3=e b3=b
a4=7 b4=0
q0.out=07
l0,3=32
q1.in=f1
a0=f b0=1
a1=e b1=f
a2=c b2=8
a3=4 b3=8
a4=1 b4=6
q1.out=61
q1.in=15
a0=1 b0=5
a1=4 b1=3
a2=f b2=b
a3=4 b3=a
a4=1 b4=7
q1.out=71
l1,2=c3
q0.in=99
a0=9 b0=9
a1=0 b1=d
a2=8 b2=0
a3=8 b3=8
a4=c b4=9
q0.out=9c
l0,2=2c
q0.in=8e
a0=8 b0=e
a1=6 b1=f
a2=3 b2=d
a3=e b3=5
a4=7 b4=2
q0.out=27
q0.in=15
a0=1 b0=5
a1=4 b1=3
a2=6 b2=8
a3=e b3=2
a4=7 b4=f
q0.out=f7
l1,1=e8
q1.in=34
a0=3 b0=4
a1=7 b1=9
a2=e b2=d
a3=3 b3=0
a4=5 b4=b
q1.out=b5
l0,1=12
q1.in=99
a0=9 b0=9
a1=0 b1=d
a2=2 b2=9
a3=b b3=e
a4=8 b4=8
q1.out=88
q1.in=15
a0=1 b0=5
a1=4 b1=3
a2=f b2=b
a3=4 b3=a
a4=1 b4=7
q1.out=71
l1,0=2a
q1.in=2b
a0=2 b0=b
a1=9 b1=f
a2=1 b2=8
a3=9 b3=d
a4=e b4=0
q1.out=0e
l0,0=f6
q0.in=3c
a0=3 b0=c
a1=f b1=d
a2=4 b2=0
a3=4 b3=4
a4=6 b4=1
q0.out=16
y0 = f6 y1 = 75 y2 = 69 y3 = 33 y0 = 61 y1 = 27 y2 = 88 y3 = 16
MDS input = Y = y0y1y2y3 = f6756933 MDS input = Y = y0y1y2y3 = 61278816
MDS output = Z = z0z1z2z3 = b2592309 MDS output = Z = z0z1z2z3 = 0bbc43c9
z0 = b2 z1 = 59 z2 = 23 z3 = 09 z0 = 0b z1 = bc z2 = 43 z3 = c9
A10 = h(2pi, Me) = b2592309
B10 = ROL[h({2i+1}p, Mo),  8]
= ROL[0bbc43c9,8]
= ROL[c943bc0b(big endian),  8]
= 43bc0bc9(big endian)
= c90bbc43.
K20 = (A10 + B10) mod 232 = (b2592309 + c90bbc43) mod 232
= (092359b2(big endian) + 43bc0bc9(big endian)) mod 232
= 4cdf657b(big endian) = 7b65df4c.
K21 = ROL([A10 + 2B10] mod 232,  9) = ROL([b2592309 + 2(c90bbc43) mod32,  9)
= ROL([092359b2(big endian) + 2(43bc0bc9(big endian))] mod32,  9)
= ROL([092359b2(big endian) + 87781792(big endian)] mod32,  9)
= ROL(909b7144(big endian),  9) = 36e28921(big endian) = 2189e236.


Key Schedule: K22 and K23
i = b i = b
h input = X = x0x1x2x3 = 2ip = 16161616 h input = X = x0x1x2x3 = (2i+1)p = 17171717
x0 = 16 x1 = 16 x2 = 16 x3 = 16 x0 = 17 x1 = 17 x2 = 17 x3 = 17
y2,0 = 16 y2,1 = 16 y2,2 = 16 y2,3 = 16 y2,0 = 17 y2,1 = 17 y2,2 = 17 y2,3 = 17
q0.in=16
a0=1 b0=6
a1=7 b1=a
a2=2 b2=a
a3=8 b3=7
a4=c b4=e
q0.out=ec
l1,3=2f
q0.in=5a
a0=5 b0=a
a1=f b1=8
a2=4 b2=f
a3=b b3=b
a4=3 b4=0
q0.out=03
l0,3=5c
q1.in=9c
a0=9 b0=c
a1=5 b1=7
a2=7 b2=7
a3=0 b3=4
a4=4 b4=c
q1.out=c4
q1.in=16
a0=1 b0=6
a1=7 b1=a
a2=e b2=a
a3=4 b3=b
a4=1 b4=f
q1.out=f1
l1,2=ec
q0.in=4e
a0=4 b0=e
a1=a b1=3
a2=5 b2=8
a3=d b3=9
a4=4 b4=b
q0.out=b4
l0,2=9f
q0.in=ec
a0=e b0=c
a1=2 b1=8
a2=7 b2=f
a3=8 b3=0
a4=c b4=d
q0.out=dc
q0.in=16
a0=1 b0=6
a1=7 b1=a
a2=2 b2=a
a3=8 b3=7
a4=c b4=e
q0.out=ec
l1,1=bf
q1.in=00
a0=0 b0=0
a1=0 b1=0
a2=2 b2=1
a3=3 b3=a
a4=5 b4=7
q1.out=75
l0,1=58
q1.in=ea
a0=e b0=a
a1=4 b1=b
a2=f b2=5
a3=a b3=d
a4=d b4=0
q1.out=0d
q1.in=16
a0=1 b0=6
a1=7 b1=a
a2=e b2=a
a3=4 b3=b
a4=1 b4=f
q1.out=f1
l1,0=b6
q1.in=de
a0=d b0=e
a1=3 b1=2
a2=d b2=2
a3=f b3=4
a4=f b4=c
q1.out=cf
l0,0=9f
q0.in=93
a0=9 b0=3
a1=a b1=8
a2=5 b2=f
a3=a b3=2
a4=f b4=f
q0.out=ff
q0.in=17
a0=1 b0=7
a1=6 b1=2
a2=3 b2=b
a3=8 b3=6
a4=c b4=6
q0.out=6c
l1,3=5a
q0.in=46
a0=4 b0=6
a1=2 b1=7
a2=7 b2=5
a3=2 b3=5
a4=5 b4=2
q0.out=25
l0,3=32
q1.in=d3
a0=d b0=3
a1=e b1=c
a2=c b2=f
a3=3 b3=3
a4=5 b4=1
q1.out=15
q1.in=17
a0=1 b0=7
a1=6 b1=2
a2=6 b2=2
a3=4 b3=7
a4=1 b4=e
q1.out=e1
l1,2=c3
q0.in=09
a0=0 b0=9
a1=9 b1=c
a2=b b2=7
a3=c b3=8
a4=2 b4=9
q0.out=92
l0,2=2c
q0.in=80
a0=8 b0=0
a1=8 b1=8
a2=0 b2=f
a3=f b3=f
a4=1 b4=a
q0.out=a1
q0.in=17
a0=1 b0=7
a1=6 b1=2
a2=3 b2=b
a3=8 b3=6
a4=c b4=6
q0.out=6c
l1,1=e8
q1.in=af
a0=a b0=f
a1=5 b1=5
a2=7 b2=c
a3=b b3=9
a4=8 b4=4
q1.out=48
l0,1=12
q1.in=64
a0=6 b0=4
a1=2 b1=4
a2=b b2=4
a3=f b3=1
a4=f b4=9
q1.out=9f
q1.in=17
a0=1 b0=7
a1=6 b1=2
a2=6 b2=2
a3=4 b3=7
a4=1 b4=e
q1.out=e1
l1,0=2a
q1.in=bb
a0=b b0=b
a1=0 b1=e
a2=2 b2=0
a3=2 b3=2
a4=7 b4=5
q1.out=57
l0,0=f6
q0.in=65
a0=6 b0=5
a1=3 b1=c
a2=d b2=7
a3=a b3=e
a4=f b4=c
q0.out=cf
y0 = c4 y1 = dc y2 = 0d y3 = ff y0 = 15 y1 = a1 y2 = 9f y3 = cf
MDS input = Y = y0y1y2y3 = c4dc0dff MDS input = Y = y0y1y2y3 = 15a19fcf
MDS output = Z = z0z1z2z3 = 3b699483 MDS output = Z = z0z1z2z3 = 661f79ea
z0 = 3b z1 = 69 z2 = 94 z3 = 83 z0 = 66 z1 = 1f z2 = 79 z3 = ea
A11 = h(2pi, Me) = 3b699483
B11 = ROL[h({2i+1}p, Mo),  8]
= ROL[661f79ea,8]
= ROL[ea791f66(big endian),  8]
= 791f66ea(big endian)
= ea661f79.
K22 = (A11 + B11) mod 232 = (3b699483 + ea661f79) mod 232
= (8394693b(big endian) + 791f66ea(big endian)) mod 232
= fcb3d025(big endian) = 25d0b3fc.
K23 = ROL([A11 + 2B11] mod 232,  9) = ROL([3b699483 + 2(ea661f79) mod32,  9)
= ROL([8394693b(big endian) + 2(791f66ea(big endian))] mod32,  9)
= ROL([8394693b(big endian) + f23ecdd4(big endian)] mod32,  9)
= ROL(75d3370f(big endian),  9) = a66e1eeb(big endian) = eb1e6ea6.


Key Schedule: K24 and K25
i = c i = c
h input = X = x0x1x2x3 = 2ip = 18181818 h input = X = x0x1x2x3 = (2i+1)p = 19191919
x0 = 18 x1 = 18 x2 = 18 x3 = 18 x0 = 19 x1 = 19 x2 = 19 x3 = 19
y2,0 = 18 y2,1 = 18 y2,2 = 18 y2,3 = 18 y2,0 = 19 y2,1 = 19 y2,2 = 19 y2,3 = 19
q0.in=18
a0=1 b0=8
a1=9 b1=d
a2=b b2=0
a3=b b3=3
a4=3 b4=4
q0.out=43
l1,3=2f
q0.in=f5
a0=f b0=5
a1=a b1=d
a2=5 b2=0
a3=5 b3=d
a4=d b4=5
q0.out=5d
l0,3=5c
q1.in=c2
a0=c b0=2
a1=e b1=d
a2=c b2=9
a3=5 b3=0
a4=6 b4=b
q1.out=b6
q1.in=18
a0=1 b0=8
a1=9 b1=d
a2=1 b2=9
a3=8 b3=5
a4=0 b4=3
q1.out=30
l1,2=ec
q0.in=8f
a0=8 b0=f
a1=7 b1=7
a2=2 b2=5
a3=7 b3=8
a4=0 b4=9
q0.out=90
l0,2=9f
q0.in=c8
a0=c b0=8
a1=4 b1=8
a2=6 b2=f
a3=9 b3=9
a4=8 b4=b
q0.out=b8
q0.in=18
a0=1 b0=8
a1=9 b1=d
a2=b b2=0
a3=b b3=3
a4=3 b4=4
q0.out=43
l1,1=bf
q1.in=af
a0=a b0=f
a1=5 b1=5
a2=7 b2=c
a3=b b3=9
a4=8 b4=4
q1.out=48
l0,1=58
q1.in=d7
a0=d b0=7
a1=a b1=e
a2=9 b2=0
a3=9 b3=1
a4=e b4=9
q1.out=9e
q1.in=18
a0=1 b0=8
a1=9 b1=d
a2=1 b2=9
a3=8 b3=5
a4=0 b4=3
q1.out=30
l1,0=b6
q1.in=1f
a0=1 b0=f
a1=e b1=6
a2=c b2=3
a3=f b3=5
a4=f b4=3
q1.out=3f
l0,0=9f
q0.in=63
a0=6 b0=3
a1=5 b1=f
a2=f b2=d
a3=2 b3=9
a4=5 b4=b
q0.out=b5
q0.in=19
a0=1 b0=9
a1=8 b1=5
a2=0 b2=2
a3=2 b3=1
a4=5 b4=7
q0.out=75
l1,3=5a
q0.in=5f
a0=5 b0=f
a1=a b1=2
a2=5 b2=b
a3=e b3=0
a4=7 b4=d
q0.out=d7
l0,3=32
q1.in=21
a0=2 b0=1
a1=3 b1=a
a2=d b2=a
a3=7 b3=0
a4=a b4=b
q1.out=ba
q1.in=19
a0=1 b0=9
a1=8 b1=5
a2=3 b2=c
a3=f b3=d
a4=f b4=0
q1.out=0f
l1,2=c3
q0.in=e7
a0=e b0=7
a1=9 b1=5
a2=b b2=2
a3=9 b3=2
a4=8 b4=f
q0.out=f8
l0,2=2c
q0.in=ea
a0=e b0=a
a1=4 b1=b
a2=6 b2=6
a3=0 b3=5
a4=b b4=2
q0.out=2b
q0.in=19
a0=1 b0=9
a1=8 b1=5
a2=0 b2=2
a3=2 b3=1
a4=5 b4=7
q0.out=75
l1,1=e8
q1.in=b6
a0=b b0=6
a1=d b1=0
a2=a b2=1
a3=b b3=2
a4=8 b4=5
q1.out=58
l0,1=12
q1.in=74
a0=7 b0=4
a1=3 b1=d
a2=d b2=9
a3=4 b3=9
a4=1 b4=4
q1.out=41
q1.in=19
a0=1 b0=9
a1=8 b1=5
a2=3 b2=c
a3=f b3=d
a4=f b4=0
q1.out=0f
l1,0=2a
q1.in=55
a0=5 b0=5
a1=0 b1=7
a2=2 b2=7
a3=5 b3=9
a4=6 b4=4
q1.out=46
l0,0=f6
q0.in=74
a0=7 b0=4
a1=3 b1=d
a2=d b2=0
a3=d b3=5
a4=4 b4=2
q0.out=24
y0 = b6 y1 = b8 y2 = 9e y3 = b5 y0 = ba y1 = 2b y2 = 41 y3 = 24
MDS input = Y = y0y1y2y3 = b6b89eb5 MDS input = Y = y0y1y2y3 = ba2b4124
MDS output = Z = z0z1z2z3 = b312504c MDS output = Z = z0z1z2z3 = f2f5cce4
z0 = b3 z1 = 12 z2 = 50 z3 = 4c z0 = f2 z1 = f5 z2 = cc z3 = e4
A12 = h(2pi, Me) = b312504c
B12 = ROL[h({2i+1}p, Mo),  8]
= ROL[f2f5cce4,8]
= ROL[e4ccf5f2(big endian),  8]
= ccf5f2e4(big endian)
= e4f2f5cc.
K24 = (A12 + B12) mod 232 = (b312504c + e4f2f5cc) mod 232
= (4c5012b3(big endian) + ccf5f2e4(big endian)) mod 232
= 19460597(big endian) = 97054619.
K25 = ROL([A12 + 2B12] mod 232,  9) = ROL([b312504c + 2(e4f2f5cc) mod32,  9)
= ROL([4c5012b3(big endian) + 2(ccf5f2e4(big endian))] mod32,  9)
= ROL([4c5012b3(big endian) + 99ebe5c8(big endian)] mod32,  9)
= ROL(e63bf87b(big endian),  9) = 77f0f7cc(big endian) = ccf7f077.


Key Schedule: K26 and K27
i = d i = d
h input = X = x0x1x2x3 = 2ip = 1a1a1a1a h input = X = x0x1x2x3 = (2i+1)p = 1b1b1b1b
x0 = 1a x1 = 1a x2 = 1a x3 = 1a x0 = 1b x1 = 1b x2 = 1b x3 = 1b
y2,0 = 1a y2,1 = 1a y2,2 = 1a y2,3 = 1a y2,0 = 1b y2,1 = 1b y2,2 = 1b y2,3 = 1b
q0.in=1a
a0=1 b0=a
a1=b b1=c
a2=9 b2=7
a3=e b3=a
a4=7 b4=3
q0.out=37
l1,3=2f
q0.in=81
a0=8 b0=1
a1=9 b1=0
a2=b b2=e
a3=5 b3=4
a4=d b4=1
q0.out=1d
l0,3=5c
q1.in=82
a0=8 b0=2
a1=a b1=9
a2=9 b2=d
a3=4 b3=f
a4=1 b4=a
q1.out=a1
q1.in=1a
a0=1 b0=a
a1=b b1=c
a2=4 b2=f
a3=b b3=b
a4=8 b4=f
q1.out=f8
l1,2=ec
q0.in=47
a0=4 b0=7
a1=3 b1=f
a2=d b2=d
a3=0 b3=b
a4=b b4=0
q0.out=0b
l0,2=9f
q0.in=53
a0=5 b0=3
a1=6 b1=4
a2=3 b2=1
a3=2 b3=3
a4=5 b4=4
q0.out=45
q0.in=1a
a0=1 b0=a
a1=b b1=c
a2=9 b2=7
a3=e b3=a
a4=7 b4=3
q0.out=37
l1,1=bf
q1.in=db
a0=d b0=b
a1=6 b1=8
a2=6 b2=6
a3=0 b3=5
a4=4 b4=3
q1.out=34
l0,1=58
q1.in=ab
a0=a b0=b
a1=1 b1=7
a2=8 b2=7
a3=f b3=3
a4=f b4=1
q1.out=1f
q1.in=1a
a0=1 b0=a
a1=b b1=c
a2=4 b2=f
a3=b b3=b
a4=8 b4=f
q1.out=f8
l1,0=b6
q1.in=d7
a0=d b0=7
a1=a b1=e
a2=9 b2=0
a3=9 b3=1
a4=e b4=9
q1.out=9e
l0,0=9f
q0.in=c2
a0=c b0=2
a1=e b1=d
a2=a b2=0
a3=a b3=a
a4=f b4=3
q0.out=3f
q0.in=1b
a0=1 b0=b
a1=a b1=4
a2=5 b2=1
a3=4 b3=5
a4=6 b4=2
q0.out=26
l1,3=5a
q0.in=0c
a0=0 b0=c
a1=c b1=6
a2=e b2=3
a3=d b3=7
a4=4 b4=e
q0.out=e4
l0,3=32
q1.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=6
a3=b b3=6
a4=8 b4=d
q1.out=d8
q1.in=1b
a0=1 b0=b
a1=a b1=4
a2=9 b2=4
a3=d b3=3
a4=b b4=1
q1.out=1b
l1,2=c3
q0.in=f3
a0=f b0=3
a1=c b1=e
a2=e b2=9
a3=7 b3=2
a4=0 b4=f
q0.out=f0
l0,2=2c
q0.in=e2
a0=e b0=2
a1=c b1=f
a2=e b2=d
a3=3 b3=0
a4=e b4=d
q0.out=de
q0.in=1b
a0=1 b0=b
a1=a b1=4
a2=5 b2=1
a3=4 b3=5
a4=6 b4=2
q0.out=26
l1,1=e8
q1.in=e5
a0=e b0=5
a1=b b1=4
a2=4 b2=4
a3=0 b3=6
a4=4 b4=d
q1.out=d4
l0,1=12
q1.in=f8
a0=f b0=8
a1=7 b1=3
a2=e b2=b
a3=5 b3=3
a4=6 b4=1
q1.out=16
q1.in=1b
a0=1 b0=b
a1=a b1=4
a2=9 b2=4
a3=d b3=3
a4=b b4=1
q1.out=1b
l1,0=2a
q1.in=41
a0=4 b0=1
a1=5 b1=c
a2=7 b2=f
a3=8 b3=0
a4=0 b4=b
q1.out=b0
l0,0=f6
q0.in=82
a0=8 b0=2
a1=a b1=9
a2=5 b2=4
a3=1 b3=f
a4=a b4=a
q0.out=aa
y0 = a1 y1 = 45 y2 = 1f y3 = 3f y0 = d8 y1 = de y2 = 16 y3 = aa
MDS input = Y = y0y1y2y3 = a1451f3f MDS input = Y = y0y1y2y3 = d8de16aa
MDS output = Z = z0z1z2z3 = 113953e1 MDS output = Z = z0z1z2z3 = 79daa8c4
z0 = 11 z1 = 39 z2 = 53 z3 = e1 z0 = 79 z1 = da z2 = a8 z3 = c4
A13 = h(2pi, Me) = 113953e1
B13 = ROL[h({2i+1}p, Mo),  8]
= ROL[79daa8c4,8]
= ROL[c4a8da79(big endian),  8]
= a8da79c4(big endian)
= c479daa8.
K26 = (A13 + B13) mod 232 = (113953e1 + c479daa8) mod 232
= (e1533911(big endian) + a8da79c4(big endian)) mod 232
= 8a2db2d5(big endian) = d5b22d8a.
K27 = ROL([A13 + 2B13] mod 232,  9) = ROL([113953e1 + 2(c479daa8) mod32,  9)
= ROL([e1533911(big endian) + 2(a8da79c4(big endian))] mod32,  9)
= ROL([e1533911(big endian) + 51b4f388(big endian)] mod32,  9)
= ROL(33082c99(big endian),  9) = 10593266(big endian) = 66325910.


Key Schedule: K28 and K29
i = e i = e
h input = X = x0x1x2x3 = 2ip = 1c1c1c1c h input = X = x0x1x2x3 = (2i+1)p = 1d1d1d1d
x0 = 1c x1 = 1c x2 = 1c x3 = 1c x0 = 1d x1 = 1d x2 = 1d x3 = 1d
y2,0 = 1c y2,1 = 1c y2,2 = 1c y2,3 = 1c y2,0 = 1d y2,1 = 1d y2,2 = 1d y2,3 = 1d
q0.in=1c
a0=1 b0=c
a1=d b1=f
a2=c b2=d
a3=1 b3=2
a4=a b4=f
q0.out=fa
l1,3=2f
q0.in=4c
a0=4 b0=c
a1=8 b1=2
a2=0 b2=b
a3=b b3=d
a4=3 b4=5
q0.out=53
l0,3=5c
q1.in=cc
a0=c b0=c
a1=0 b1=a
a2=2 b2=a
a3=8 b3=7
a4=0 b4=e
q1.out=e0
q1.in=1c
a0=1 b0=c
a1=d b1=f
a2=a b2=8
a3=2 b3=e
a4=7 b4=8
q1.out=87
l1,2=ec
q0.in=38
a0=3 b0=8
a1=b b1=f
a2=9 b2=d
a3=4 b3=f
a4=6 b4=a
q0.out=a6
l0,2=9f
q0.in=fe
a0=f b0=e
a1=1 b1=0
a2=1 b2=e
a3=f b3=e
a4=1 b4=c
q0.out=c1
q0.in=1c
a0=1 b0=c
a1=d b1=f
a2=c b2=d
a3=1 b3=2
a4=a b4=f
q0.out=fa
l1,1=bf
q1.in=16
a0=1 b0=6
a1=7 b1=a
a2=e b2=a
a3=4 b3=b
a4=1 b4=f
q1.out=f1
l0,1=58
q1.in=6e
a0=6 b0=e
a1=8 b1=1
a2=3 b2=e
a3=d b3=c
a4=b b4=2
q1.out=2b
q1.in=1c
a0=1 b0=c
a1=d b1=f
a2=a b2=8
a3=2 b3=e
a4=7 b4=8
q1.out=87
l1,0=b6
q1.in=a8
a0=a b0=8
a1=2 b1=e
a2=b b2=0
a3=b b3=3
a4=8 b4=1
q1.out=18
l0,0=9f
q0.in=44
a0=4 b0=4
a1=0 b1=6
a2=8 b2=3
a3=b b3=1
a4=3 b4=7
q0.out=73
q0.in=1d
a0=1 b0=d
a1=c b1=7
a2=e b2=5
a3=b b3=4
a4=3 b4=1
q0.out=13
l1,3=5a
q0.in=39
a0=3 b0=9
a1=a b1=7
a2=5 b2=5
a3=0 b3=7
a4=b b4=e
q0.out=eb
l0,3=32
q1.in=1d
a0=1 b0=d
a1=c b1=7
a2=0 b2=7
a3=7 b3=b
a4=a b4=f
q1.out=fa
q1.in=1d
a0=1 b0=d
a1=c b1=7
a2=0 b2=7
a3=7 b3=b
a4=a b4=f
q1.out=fa
l1,2=c3
q0.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=f
a3=2 b3=a
a4=5 b4=3
q0.out=35
l0,2=2c
q0.in=27
a0=2 b0=7
a1=5 b1=9
a2=f b2=4
a3=b b3=5
a4=3 b4=2
q0.out=23
q0.in=1d
a0=1 b0=d
a1=c b1=7
a2=e b2=5
a3=b b3=4
a4=3 b4=1
q0.out=13
l1,1=e8
q1.in=d0
a0=d b0=0
a1=d b1=5
a2=a b2=c
a3=6 b3=c
a4=9 b4=2
q1.out=29
l0,1=12
q1.in=05
a0=0 b0=5
a1=5 b1=a
a2=7 b2=a
a3=d b3=a
a4=b b4=7
q1.out=7b
q1.in=1d
a0=1 b0=d
a1=c b1=7
a2=0 b2=7
a3=7 b3=b
a4=a b4=f
q1.out=fa
l1,0=2a
q1.in=a0
a0=a b0=0
a1=a b1=a
a2=9 b2=a
a3=3 b3=4
a4=5 b4=c
q1.out=c5
l0,0=f6
q0.in=f7
a0=f b0=7
a1=8 b1=c
a2=0 b2=7
a3=7 b3=b
a4=0 b4=0
q0.out=00
y0 = e0 y1 = c1 y2 = 2b y3 = 73 y0 = fa y1 = 23 y2 = 7b y3 = 00
MDS input = Y = y0y1y2y3 = e0c12b73 MDS input = Y = y0y1y2y3 = fa237b00
MDS output = Z = z0z1z2z3 = d1ba2486 MDS output = Z = z0z1z2z3 = 1112b32c
z0 = d1 z1 = ba z2 = 24 z3 = 86 z0 = 11 z1 = 12 z2 = b3 z3 = 2c
A14 = h(2pi, Me) = d1ba2486
B14 = ROL[h({2i+1}p, Mo),  8]
= ROL[1112b32c,8]
= ROL[2cb31211(big endian),  8]
= b312112c(big endian)
= 2c1112b3.
K28 = (A14 + B14) mod 232 = (d1ba2486 + 2c1112b3) mod 232
= (8624bad1(big endian) + b312112c(big endian)) mod 232
= 3936cbfd(big endian) = fdcb3639.
K29 = ROL([A14 + 2B14] mod 232,  9) = ROL([d1ba2486 + 2(2c1112b3) mod32,  9)
= ROL([8624bad1(big endian) + 2(b312112c(big endian))] mod32,  9)
= ROL([8624bad1(big endian) + 66242258(big endian)] mod32,  9)
= ROL(ec48dd29(big endian),  9) = 91ba53d8(big endian) = d853ba91.


Key Schedule: K30 and K31
i = f i = f
h input = X = x0x1x2x3 = 2ip = 1e1e1e1e h input = X = x0x1x2x3 = (2i+1)p = 1f1f1f1f
x0 = 1e x1 = 1e x2 = 1e x3 = 1e x0 = 1f x1 = 1f x2 = 1f x3 = 1f
y2,0 = 1e y2,1 = 1e y2,2 = 1e y2,3 = 1e y2,0 = 1f y2,1 = 1f y2,2 = 1f y2,3 = 1f
q0.in=1e
a0=1 b0=e
a1=f b1=e
a2=4 b2=9
a3=d b3=8
a4=4 b4=9
q0.out=94
l1,3=2f
q0.in=22
a0=2 b0=2
a1=0 b1=3
a2=8 b2=8
a3=0 b3=c
a4=b b4=8
q0.out=8b
l0,3=5c
q1.in=14
a0=1 b0=4
a1=5 b1=b
a2=7 b2=5
a3=2 b3=5
a4=7 b4=3
q1.out=37
q1.in=1e
a0=1 b0=e
a1=f b1=e
a2=5 b2=0
a3=5 b3=d
a4=6 b4=0
q1.out=06
l1,2=ec
q0.in=b9
a0=b b0=9
a1=2 b1=f
a2=7 b2=d
a3=a b3=1
a4=f b4=7
q0.out=7f
l0,2=9f
q0.in=27
a0=2 b0=7
a1=5 b1=9
a2=f b2=4
a3=b b3=5
a4=3 b4=2
q0.out=23
q0.in=1e
a0=1 b0=e
a1=f b1=e
a2=4 b2=9
a3=d b3=8
a4=4 b4=9
q0.out=94
l1,1=bf
q1.in=78
a0=7 b0=8
a1=f b1=b
a2=5 b2=5
a3=0 b3=7
a4=4 b4=e
q1.out=e4
l0,1=58
q1.in=7b
a0=7 b0=b
a1=c b1=2
a2=0 b2=2
a3=2 b3=1
a4=7 b4=9
q1.out=97
q1.in=1e
a0=1 b0=e
a1=f b1=e
a2=5 b2=0
a3=5 b3=d
a4=6 b4=0
q1.out=06
l1,0=b6
q1.in=29
a0=2 b0=9
a1=b b1=e
a2=4 b2=0
a3=4 b3=4
a4=1 b4=c
q1.out=c1
l0,0=9f
q0.in=9d
a0=9 b0=d
a1=4 b1=f
a2=6 b2=d
a3=b b3=8
a4=3 b4=9
q0.out=93
q0.in=1f
a0=1 b0=f
a1=e b1=6
a2=a b2=3
a3=9 b3=3
a4=8 b4=4
q0.out=48
l1,3=5a
q0.in=62
a0=6 b0=2
a1=4 b1=7
a2=6 b2=5
a3=3 b3=c
a4=e b4=8
q0.out=8e
l0,3=32
q1.in=78
a0=7 b0=8
a1=f b1=b
a2=5 b2=5
a3=0 b3=7
a4=4 b4=e
q1.out=e4
q1.in=1f
a0=1 b0=f
a1=e b1=6
a2=c b2=3
a3=f b3=5
a4=f b4=3
q1.out=3f
l1,2=c3
q0.in=d7
a0=d b0=7
a1=a b1=e
a2=5 b2=9
a3=c b3=1
a4=2 b4=7
q0.out=72
l0,2=2c
q0.in=60
a0=6 b0=0
a1=6 b1=6
a2=3 b2=3
a3=0 b3=2
a4=b b4=f
q0.out=fb
q0.in=1f
a0=1 b0=f
a1=e b1=6
a2=a b2=3
a3=9 b3=3
a4=8 b4=4
q0.out=48
l1,1=e8
q1.in=8b
a0=8 b0=b
a1=3 b1=5
a2=d b2=c
a3=1 b3=3
a4=c b4=1
q1.out=1c
l0,1=12
q1.in=30
a0=3 b0=0
a1=3 b1=b
a2=d b2=5
a3=8 b3=f
a4=0 b4=a
q1.out=a0
q1.in=1f
a0=1 b0=f
a1=e b1=6
a2=c b2=3
a3=f b3=5
a4=f b4=3
q1.out=3f
l1,0=2a
q1.in=65
a0=6 b0=5
a1=3 b1=c
a2=d b2=f
a3=2 b3=a
a4=7 b4=7
q1.out=77
l0,0=f6
q0.in=45
a0=4 b0=5
a1=1 b1=e
a2=1 b2=9
a3=8 b3=5
a4=c b4=2
q0.out=2c
y0 = 37 y1 = 23 y2 = 97 y3 = 93 y0 = e4 y1 = fb y2 = a0 y3 = 2c
MDS input = Y = y0y1y2y3 = 37239793 MDS input = Y = y0y1y2y3 = e4fba02c
MDS output = Z = z0z1z2z3 = 52848da2 MDS output = Z = z0z1z2z3 = a9cb15ab
z0 = 52 z1 = 84 z2 = 8d z3 = a2 z0 = a9 z1 = cb z2 = 15 z3 = ab
A15 = h(2pi, Me) = 52848da2
B15 = ROL[h({2i+1}p, Mo),  8]
= ROL[a9cb15ab,8]
= ROL[ab15cba9(big endian),  8]
= 15cba9ab(big endian)
= aba9cb15.
K30 = (A15 + B15) mod 232 = (52848da2 + aba9cb15) mod 232
= (a28d8452(big endian) + 15cba9ab(big endian)) mod 232
= b8592dfd(big endian) = fd2d59b8.
K31 = ROL([A15 + 2B15] mod 232,  9) = ROL([52848da2 + 2(aba9cb15) mod32,  9)
= ROL([a28d8452(big endian) + 2(15cba9ab(big endian))] mod32,  9)
= ROL([a28d8452(big endian) + 2b975356(big endian)] mod32,  9)
= ROL(ce24d7a8(big endian),  9) = 49af519c(big endian) = 9c51af49.


Key Schedule: K32 and K33
i = 10 i = 10
h input = X = x0x1x2x3 = 2ip = 20202020 h input = X = x0x1x2x3 = (2i+1)p = 21212121
x0 = 20 x1 = 20 x2 = 20 x3 = 20 x0 = 21 x1 = 21 x2 = 21 x3 = 21
y2,0 = 20 y2,1 = 20 y2,2 = 20 y2,3 = 20 y2,0 = 21 y2,1 = 21 y2,2 = 21 y2,3 = 21
q0.in=20
a0=2 b0=0
a1=2 b1=2
a2=7 b2=b
a3=c b3=2
a4=2 b4=f
q0.out=f2
l1,3=2f
q0.in=44
a0=4 b0=4
a1=0 b1=6
a2=8 b2=3
a3=b b3=1
a4=3 b4=7
q0.out=73
l0,3=5c
q1.in=ec
a0=e b0=c
a1=2 b1=8
a2=b b2=6
a3=d b3=0
a4=b b4=b
q1.out=bb
q1.in=20
a0=2 b0=0
a1=2 b1=2
a2=b b2=2
a3=9 b3=2
a4=e b4=5
q1.out=5e
l1,2=ec
q0.in=e1
a0=e b0=1
a1=f b1=6
a2=4 b2=3
a3=7 b3=d
a4=0 b4=5
q0.out=50
l0,2=9f
q0.in=08
a0=0 b0=8
a1=8 b1=4
a2=0 b2=1
a3=1 b3=8
a4=a b4=9
q0.out=9a
q0.in=20
a0=2 b0=0
a1=2 b1=2
a2=7 b2=b
a3=c b3=2
a4=2 b4=f
q0.out=f2
l1,1=bf
q1.in=1e
a0=1 b0=e
a1=f b1=e
a2=5 b2=0
a3=5 b3=d
a4=6 b4=0
q1.out=06
l0,1=58
q1.in=99
a0=9 b0=9
a1=0 b1=d
a2=2 b2=9
a3=b b3=e
a4=8 b4=8
q1.out=88
q1.in=20
a0=2 b0=0
a1=2 b1=2
a2=b b2=2
a3=9 b3=2
a4=e b4=5
q1.out=5e
l1,0=b6
q1.in=71
a0=7 b0=1
a1=6 b1=7
a2=6 b2=7
a3=1 b3=d
a4=c b4=0
q1.out=0c
l0,0=9f
q0.in=50
a0=5 b0=0
a1=5 b1=d
a2=f b2=0
a3=f b3=7
a4=1 b4=e
q0.out=e1
q0.in=21
a0=2 b0=1
a1=3 b1=a
a2=d b2=a
a3=7 b3=0
a4=0 b4=d
q0.out=d0
l1,3=5a
q0.in=fa
a0=f b0=a
a1=5 b1=2
a2=f b2=b
a3=4 b3=a
a4=6 b4=3
q0.out=36
l0,3=32
q1.in=c0
a0=c b0=0
a1=c b1=c
a2=0 b2=f
a3=f b3=f
a4=f b4=a
q1.out=af
q1.in=21
a0=2 b0=1
a1=3 b1=a
a2=d b2=a
a3=7 b3=0
a4=a b4=b
q1.out=ba
l1,2=c3
q0.in=52
a0=5 b0=2
a1=7 b1=c
a2=2 b2=7
a3=5 b3=9
a4=d b4=b
q0.out=bd
l0,2=2c
q0.in=af
a0=a b0=f
a1=5 b1=5
a2=f b2=2
a3=d b3=6
a4=4 b4=6
q0.out=64
q0.in=21
a0=2 b0=1
a1=3 b1=a
a2=d b2=a
a3=7 b3=0
a4=0 b4=d
q0.out=d0
l1,1=e8
q1.in=13
a0=1 b0=3
a1=2 b1=0
a2=b b2=1
a3=a b3=b
a4=d b4=f
q1.out=fd
l0,1=12
q1.in=d1
a0=d b0=1
a1=c b1=d
a2=0 b2=9
a3=9 b3=c
a4=e b4=2
q1.out=2e
q1.in=21
a0=2 b0=1
a1=3 b1=a
a2=d b2=a
a3=7 b3=0
a4=a b4=b
q1.out=ba
l1,0=2a
q1.in=e0
a0=e b0=0
a1=e b1=e
a2=c b2=0
a3=c b3=c
a4=2 b4=2
q1.out=22
l0,0=f6
q0.in=10
a0=1 b0=0
a1=1 b1=9
a2=1 b2=4
a3=5 b3=b
a4=d b4=0
q0.out=0d
y0 = bb y1 = 9a y2 = 88 y3 = e1 y0 = af y1 = 64 y2 = 2e y3 = 0d
MDS input = Y = y0y1y2y3 = bb9a88e1 MDS input = Y = y0y1y2y3 = af642e0d
MDS output = Z = z0z1z2z3 = d7315565 MDS output = Z = z0z1z2z3 = 25ae3c3f
z0 = d7 z1 = 31 z2 = 55 z3 = 65 z0 = 25 z1 = ae z2 = 3c z3 = 3f
A16 = h(2pi, Me) = d7315565
B16 = ROL[h({2i+1}p, Mo),  8]
= ROL[25ae3c3f,8]
= ROL[3f3cae25(big endian),  8]
= 3cae253f(big endian)
= 3f25ae3c.
K32 = (A16 + B16) mod 232 = (d7315565 + 3f25ae3c) mod 232
= (655531d7(big endian) + 3cae253f(big endian)) mod 232
= a2035716(big endian) = 165703a2.
K33 = ROL([A16 + 2B16] mod 232,  9) = ROL([d7315565 + 2(3f25ae3c) mod32,  9)
= ROL([655531d7(big endian) + 2(3cae253f(big endian))] mod32,  9)
= ROL([655531d7(big endian) + 795c4a7e(big endian)] mod32,  9)
= ROL(deb17c55(big endian),  9) = 62f8abbd(big endian) = bdabf862.


Key Schedule: K34 and K35
i = 11 i = 11
h input = X = x0x1x2x3 = 2ip = 22222222 h input = X = x0x1x2x3 = (2i+1)p = 23232323
x0 = 22 x1 = 22 x2 = 22 x3 = 22 x0 = 23 x1 = 23 x2 = 23 x3 = 23
y2,0 = 22 y2,1 = 22 y2,2 = 22 y2,3 = 22 y2,0 = 23 y2,1 = 23 y2,2 = 23 y2,3 = 23
q0.in=22
a0=2 b0=2
a1=0 b1=3
a2=8 b2=8
a3=0 b3=c
a4=b b4=8
q0.out=8b
l1,3=2f
q0.in=3d
a0=3 b0=d
a1=e b1=5
a2=a b2=2
a3=8 b3=b
a4=c b4=0
q0.out=0c
l0,3=5c
q1.in=93
a0=9 b0=3
a1=a b1=8
a2=9 b2=6
a3=f b3=2
a4=f b4=5
q1.out=5f
q1.in=22
a0=2 b0=2
a1=0 b1=3
a2=2 b2=b
a3=9 b3=f
a4=e b4=a
q1.out=ae
l1,2=ec
q0.in=11
a0=1 b0=1
a1=0 b1=1
a2=8 b2=c
a3=4 b3=e
a4=6 b4=c
q0.out=c6
l0,2=9f
q0.in=9e
a0=9 b0=e
a1=7 b1=6
a2=2 b2=3
a3=1 b3=b
a4=a b4=0
q0.out=0a
q0.in=22
a0=2 b0=2
a1=0 b1=3
a2=8 b2=8
a3=0 b3=c
a4=b b4=8
q0.out=8b
l1,1=bf
q1.in=67
a0=6 b0=7
a1=1 b1=d
a2=8 b2=9
a3=1 b3=4
a4=c b4=c
q1.out=cc
l0,1=58
q1.in=53
a0=5 b0=3
a1=6 b1=4
a2=6 b2=4
a3=2 b3=4
a4=7 b4=c
q1.out=c7
q1.in=22
a0=2 b0=2
a1=0 b1=3
a2=2 b2=b
a3=9 b3=f
a4=e b4=a
q1.out=ae
l1,0=b6
q1.in=81
a0=8 b0=1
a1=9 b1=0
a2=1 b2=1
a3=0 b3=1
a4=4 b4=9
q1.out=94
l0,0=9f
q0.in=c8
a0=c b0=8
a1=4 b1=8
a2=6 b2=f
a3=9 b3=9
a4=8 b4=b
q0.out=b8
q0.in=23
a0=2 b0=3
a1=1 b1=b
a2=1 b2=6
a3=7 b3=a
a4=0 b4=3
q0.out=30
l1,3=5a
q0.in=1a
a0=1 b0=a
a1=b b1=c
a2=9 b2=7
a3=e b3=a
a4=7 b4=3
q0.out=37
l0,3=32
q1.in=c1
a0=c b0=1
a1=d b1=4
a2=a b2=4
a3=e b3=8
a4=3 b4=6
q1.out=63
q1.in=23
a0=2 b0=3
a1=1 b1=b
a2=8 b2=5
a3=d b3=2
a4=b b4=5
q1.out=5b
l1,2=c3
q0.in=b3
a0=b b0=3
a1=8 b1=a
a2=0 b2=a
a3=a b3=5
a4=f b4=2
q0.out=2f
l0,2=2c
q0.in=3d
a0=3 b0=d
a1=e b1=5
a2=a b2=2
a3=8 b3=b
a4=c b4=0
q0.out=0c
q0.in=23
a0=2 b0=3
a1=1 b1=b
a2=1 b2=6
a3=7 b3=a
a4=0 b4=3
q0.out=30
l1,1=e8
q1.in=f3
a0=f b0=3
a1=c b1=e
a2=0 b2=0
a3=0 b3=0
a4=4 b4=b
q1.out=b4
l0,1=12
q1.in=98
a0=9 b0=8
a1=1 b1=5
a2=8 b2=c
a3=4 b3=e
a4=1 b4=8
q1.out=81
q1.in=23
a0=2 b0=3
a1=1 b1=b
a2=8 b2=5
a3=d b3=2
a4=b b4=5
q1.out=5b
l1,0=2a
q1.in=01
a0=0 b0=1
a1=1 b1=8
a2=8 b2=6
a3=e b3=b
a4=3 b4=f
q1.out=f3
l0,0=f6
q0.in=c1
a0=c b0=1
a1=d b1=4
a2=c b2=1
a3=d b3=4
a4=4 b4=1
q0.out=14
y0 = 5f y1 = 0a y2 = c7 y3 = b8 y0 = 63 y1 = 0c y2 = 81 y3 = 14
MDS input = Y = y0y1y2y3 = 5f0ac7b8 MDS input = Y = y0y1y2y3 = 630c8114
MDS output = Z = z0z1z2z3 = 68688c6e MDS output = Z = z0z1z2z3 = 80878502
z0 = 68 z1 = 68 z2 = 8c z3 = 6e z0 = 80 z1 = 87 z2 = 85 z3 = 02
A17 = h(2pi, Me) = 68688c6e
B17 = ROL[h({2i+1}p, Mo),  8]
= ROL[80878502,8]
= ROL[02858780(big endian),  8]
= 85878002(big endian)
= 02808785.
K34 = (A17 + B17) mod 232 = (68688c6e + 02808785) mod 232
= (6e8c6868(big endian) + 85878002(big endian)) mod 232
= f413e86a(big endian) = 6ae813f4.
K35 = ROL([A17 + 2B17] mod 232,  9) = ROL([68688c6e + 2(02808785) mod32,  9)
= ROL([6e8c6868(big endian) + 2(85878002(big endian))] mod32,  9)
= ROL([6e8c6868(big endian) + 0b0f0004(big endian)] mod32,  9)
= ROL(799b686c(big endian),  9) = 36d0d8f3(big endian) = f3d8d036.


Key Schedule: K36 and K37
i = 12 i = 12
h input = X = x0x1x2x3 = 2ip = 24242424 h input = X = x0x1x2x3 = (2i+1)p = 25252525
x0 = 24 x1 = 24 x2 = 24 x3 = 24 x0 = 25 x1 = 25 x2 = 25 x3 = 25
y2,0 = 24 y2,1 = 24 y2,2 = 24 y2,3 = 24 y2,0 = 25 y2,1 = 25 y2,2 = 25 y2,3 = 25
q0.in=24
a0=2 b0=4
a1=6 b1=0
a2=3 b2=e
a3=d b3=c
a4=4 b4=8
q0.out=84
l1,3=2f
q0.in=32
a0=3 b0=2
a1=1 b1=a
a2=1 b2=a
a3=b b3=c
a4=3 b4=8
q0.out=83
l0,3=5c
q1.in=1c
a0=1 b0=c
a1=d b1=f
a2=a b2=8
a3=2 b3=e
a4=7 b4=8
q1.out=87
q1.in=24
a0=2 b0=4
a1=6 b1=0
a2=6 b2=1
a3=7 b3=e
a4=a b4=8
q1.out=8a
l1,2=ec
q0.in=35
a0=3 b0=5
a1=6 b1=1
a2=3 b2=c
a3=f b3=d
a4=1 b4=5
q0.out=51
l0,2=9f
q0.in=09
a0=0 b0=9
a1=9 b1=c
a2=b b2=7
a3=c b3=8
a4=2 b4=9
q0.out=92
q0.in=24
a0=2 b0=4
a1=6 b1=0
a2=3 b2=e
a3=d b3=c
a4=4 b4=8
q0.out=84
l1,1=bf
q1.in=68
a0=6 b0=8
a1=e b1=2
a2=c b2=2
a3=e b3=d
a4=3 b4=0
q1.out=03
l0,1=58
q1.in=9c
a0=9 b0=c
a1=5 b1=7
a2=7 b2=7
a3=0 b3=4
a4=4 b4=c
q1.out=c4
q1.in=24
a0=2 b0=4
a1=6 b1=0
a2=6 b2=1
a3=7 b3=e
a4=a b4=8
q1.out=8a
l1,0=b6
q1.in=a5
a0=a b0=5
a1=f b1=0
a2=5 b2=1
a3=4 b3=5
a4=1 b4=3
q1.out=31
l0,0=9f
q0.in=6d
a0=6 b0=d
a1=b b1=8
a2=9 b2=f
a3=6 b3=e
a4=9 b4=c
q0.out=c9
q0.in=25
a0=2 b0=5
a1=7 b1=8
a2=2 b2=f
a3=d b3=d
a4=4 b4=5
q0.out=54
l1,3=5a
q0.in=7e
a0=7 b0=e
a1=9 b1=8
a2=b b2=f
a3=4 b3=c
a4=6 b4=8
q0.out=86
l0,3=32
q1.in=70
a0=7 b0=0
a1=7 b1=f
a2=e b2=8
a3=6 b3=a
a4=9 b4=7
q1.out=79
q1.in=25
a0=2 b0=5
a1=7 b1=8
a2=e b2=6
a3=8 b3=d
a4=0 b4=0
q1.out=00
l1,2=c3
q0.in=e8
a0=e b0=8
a1=6 b1=a
a2=3 b2=a
a3=9 b3=e
a4=8 b4=c
q0.out=c8
l0,2=2c
q0.in=da
a0=d b0=a
a1=7 b1=0
a2=2 b2=e
a3=c b3=5
a4=2 b4=2
q0.out=22
q0.in=25
a0=2 b0=5
a1=7 b1=8
a2=2 b2=f
a3=d b3=d
a4=4 b4=5
q0.out=54
l1,1=e8
q1.in=97
a0=9 b0=7
a1=e b1=a
a2=c b2=a
a3=6 b3=9
a4=9 b4=4
q1.out=49
l0,1=12
q1.in=65
a0=6 b0=5
a1=3 b1=c
a2=d b2=f
a3=2 b3=a
a4=7 b4=7
q1.out=77
q1.in=25
a0=2 b0=5
a1=7 b1=8
a2=e b2=6
a3=8 b3=d
a4=0 b4=0
q1.out=00
l1,0=2a
q1.in=5a
a0=5 b0=a
a1=f b1=8
a2=5 b2=6
a3=3 b3=e
a4=5 b4=8
q1.out=85
l0,0=f6
q0.in=b7
a0=b b0=7
a1=c b1=8
a2=e b2=f
a3=1 b3=1
a4=a b4=7
q0.out=7a
y0 = 87 y1 = 92 y2 = c4 y3 = c9 y0 = 79 y1 = 22 y2 = 77 y3 = 7a
MDS input = Y = y0y1y2y3 = 8792c4c9 MDS input = Y = y0y1y2y3 = 7922777a
MDS output = Z = z0z1z2z3 = 985d081b MDS output = Z = z0z1z2z3 = a2c3b14c
z0 = 98 z1 = 5d z2 = 08 z3 = 1b z0 = a2 z1 = c3 z2 = b1 z3 = 4c
A18 = h(2pi, Me) = 985d081b
B18 = ROL[h({2i+1}p, Mo),  8]
= ROL[a2c3b14c,8]
= ROL[4cb1c3a2(big endian),  8]
= b1c3a24c(big endian)
= 4ca2c3b1.
K36 = (A18 + B18) mod 232 = (985d081b + 4ca2c3b1) mod 232
= (1b085d98(big endian) + b1c3a24c(big endian)) mod 232
= cccbffe4(big endian) = e4ffcbcc.
K37 = ROL([A18 + 2B18] mod 232,  9) = ROL([985d081b + 2(4ca2c3b1) mod32,  9)
= ROL([1b085d98(big endian) + 2(b1c3a24c(big endian))] mod32,  9)
= ROL([1b085d98(big endian) + 63874498(big endian)] mod32,  9)
= ROL(7e8fa230(big endian),  9) = 1f4460fd(big endian) = fd60441f.


Key Schedule: K38 and K39
i = 13 i = 13
h input = X = x0x1x2x3 = 2ip = 26262626 h input = X = x0x1x2x3 = (2i+1)p = 27272727
x0 = 26 x1 = 26 x2 = 26 x3 = 26 x0 = 27 x1 = 27 x2 = 27 x3 = 27
y2,0 = 26 y2,1 = 26 y2,2 = 26 y2,3 = 26 y2,0 = 27 y2,1 = 27 y2,2 = 27 y2,3 = 27
q0.in=26
a0=2 b0=6
a1=4 b1=1
a2=6 b2=c
a3=a b3=0
a4=f b4=d
q0.out=df
l1,3=2f
q0.in=69
a0=6 b0=9
a1=f b1=a
a2=4 b2=a
a3=e b3=1
a4=7 b4=7
q0.out=77
l0,3=5c
q1.in=e8
a0=e b0=8
a1=6 b1=a
a2=6 b2=a
a3=c b3=3
a4=2 b4=1
q1.out=12
q1.in=26
a0=2 b0=6
a1=4 b1=1
a2=f b2=e
a3=1 b3=0
a4=c b4=b
q1.out=bc
l1,2=ec
q0.in=03
a0=0 b0=3
a1=3 b1=9
a2=d b2=4
a3=9 b3=7
a4=8 b4=e
q0.out=e8
l0,2=9f
q0.in=b0
a0=b b0=0
a1=b b1=3
a2=9 b2=8
a3=1 b3=5
a4=a b4=2
q0.out=2a
q0.in=26
a0=2 b0=6
a1=4 b1=1
a2=6 b2=c
a3=a b3=0
a4=f b4=d
q0.out=df
l1,1=bf
q1.in=33
a0=3 b0=3
a1=0 b1=2
a2=2 b2=2
a3=0 b3=3
a4=4 b4=1
q1.out=14
l0,1=58
q1.in=8b
a0=8 b0=b
a1=3 b1=5
a2=d b2=c
a3=1 b3=3
a4=c b4=1
q1.out=1c
q1.in=26
a0=2 b0=6
a1=4 b1=1
a2=f b2=e
a3=1 b3=0
a4=c b4=b
q1.out=bc
l1,0=b6
q1.in=93
a0=9 b0=3
a1=a b1=8
a2=9 b2=6
a3=f b3=2
a4=f b4=5
q1.out=5f
l0,0=9f
q0.in=03
a0=0 b0=3
a1=3 b1=9
a2=d b2=4
a3=9 b3=7
a4=8 b4=e
q0.out=e8
q0.in=27
a0=2 b0=7
a1=5 b1=9
a2=f b2=4
a3=b b3=5
a4=3 b4=2
q0.out=23
l1,3=5a
q0.in=09
a0=0 b0=9
a1=9 b1=c
a2=b b2=7
a3=c b3=8
a4=2 b4=9
q0.out=92
l0,3=32
q1.in=64
a0=6 b0=4
a1=2 b1=4
a2=b b2=4
a3=f b3=1
a4=f b4=9
q1.out=9f
q1.in=27
a0=2 b0=7
a1=5 b1=9
a2=7 b2=d
a3=a b3=1
a4=d b4=9
q1.out=9d
l1,2=c3
q0.in=75
a0=7 b0=5
a1=2 b1=5
a2=7 b2=2
a3=5 b3=e
a4=d b4=c
q0.out=cd
l0,2=2c
q0.in=df
a0=d b0=f
a1=2 b1=a
a2=7 b2=a
a3=d b3=a
a4=4 b4=3
q0.out=34
q0.in=27
a0=2 b0=7
a1=5 b1=9
a2=f b2=4
a3=b b3=5
a4=3 b4=2
q0.out=23
l1,1=e8
q1.in=e0
a0=e b0=0
a1=e b1=e
a2=c b2=0
a3=c b3=c
a4=2 b4=2
q1.out=22
l0,1=12
q1.in=0e
a0=0 b0=e
a1=e b1=7
a2=c b2=7
a3=b b3=7
a4=8 b4=e
q1.out=e8
q1.in=27
a0=2 b0=7
a1=5 b1=9
a2=7 b2=d
a3=a b3=1
a4=d b4=9
q1.out=9d
l1,0=2a
q1.in=c7
a0=c b0=7
a1=b b1=7
a2=4 b2=7
a3=3 b3=f
a4=5 b4=a
q1.out=a5
l0,0=f6
q0.in=97
a0=9 b0=7
a1=e b1=a
a2=a b2=a
a3=0 b3=f
a4=b b4=a
q0.out=ab
y0 = 12 y1 = 2a y2 = 1c y3 = e8 y0 = 9f y1 = 34 y2 = e8 y3 = ab
MDS input = Y = y0y1y2y3 = 122a1ce8 MDS input = Y = y0y1y2y3 = 9f34e8ab
MDS output = Z = z0z1z2z3 = 5ade8546 MDS output = Z = z0z1z2z3 = 0178f250
z0 = 5a z1 = de z2 = 85 z3 = 46 z0 = 01 z1 = 78 z2 = f2 z3 = 50
A19 = h(2pi, Me) = 5ade8546
B19 = ROL[h({2i+1}p, Mo),  8]
= ROL[0178f250,8]
= ROL[50f27801(big endian),  8]
= f2780150(big endian)
= 500178f2.
K38 = (A19 + B19) mod 232 = (5ade8546 + 500178f2) mod 232
= (4685de5a(big endian) + f2780150(big endian)) mod 232
= 38fddfaa(big endian) = aadffd38.
K39 = ROL([A19 + 2B19] mod 232,  9) = ROL([5ade8546 + 2(500178f2) mod32,  9)
= ROL([4685de5a(big endian) + 2(f2780150(big endian))] mod32,  9)
= ROL([4685de5a(big endian) + e4f002a0(big endian)] mod32,  9)
= ROL(2b75e0fa(big endian),  9) = ebc1f456(big endian) = 56f4c1eb.

 

Summary listing of the 40 expanded key words
K0 = 9bf1826a K1 = 02229b50 K2 = ea11ea78 K3 = ae0b98a1
K4 = f57ea21f K5 = e005f378 K6 = 314b4d98 K7 = c9a88d6f
K8 = f595a22f K9 = b3c6caca K10 = 22166ed7 K11 = 2547a011
K12 = a38a1320 K13 = 0813350e K14 = 281a4854 K15 = a0ddfa24
K16 = 19c3630c K17 = 5bc0b2cc K18 = d542f0e2 K19 = 9f8b15e9
K20 = 7b65df4c K21 = 2189e236 K22 = 25d0b3fc K23 = eb1e6ea6
K24 = 97054619 K25 = ccf7f077 K26 = d5b22d8a K27 = 66325910
K28 = fdcb3639 K29 = d853ba91 K30 = fd2d59b8 K31 = 9c51af49
K32 = 165703a2 K33 = bdabf862 K34 = 6ae813f4 K35 = f3d8d036
K36 = e4ffcbcc K37 = fd60441f K38 = aadffd38 K39 = 56f4c1eb

 

Encryption start: block 1
128-bit plaintext block = p0p1p2p3p4p5p6p7p8p9p10p11p12p13p14p15 = d4919116e7b1b19e86cbcb6b789f9f19
P0 = p0p1p2p3 = d491db16 P1 = p4p5p6p7 = e7b1c39e
P2 = p8p9p10p11 = 86cb086b P3 = p12p13p14p15 = 789f5419

 

Encryption of block 1 : Encryption CBC step: Xor of plaintext block with ciphertext result of previous block
P '0 = P0 C0(previous round) = d491db16 00000000 = d491db16
P '1 = P1 C1(previous round) = e7b1c39e 00000000 = e7b1c39e
P '2 = P2 C2(previous round) = 86cb086b 00000000 = 86cb086b
P '3 = P3 C3(previous round) = 789f5419 00000000 = 789f5419

 

Encryption Input Whiten : Block 1
R0,0 = P '0 K0 = d491db16 9bf1826a = 4f60597c
R0,1 = P '1 K1 = e7b1c39e 02229b50 = e59358ce
R0,2 = P '2 K2 = 86cb086b ea11ea78 = 6cdae213
R0,3 = P '3 K3 = 789f5419 ae0b98a1 = d694ccb8

 

Encryption of block 1, round r=0
g input = X = x0x1x2x3 = R0,0 = 4f60597c
g input = X = x0x1x2x3
= ROL(R0,1,  8) = ROL(e59358ce ,  8)
= ROL(ce5893e5(big endian),  8)
= 5893e5ce(big endian) = cee59358.
x0 = 4f x1 = 60 x2 = 59 x3 = 7c x0 = ce x1 = e5 x2 = 93 x3 = 58
y2,0 = 4f y2,1 = 60 y2,2 = 59 y2,3 = 7c y2,0 = ce y2,1 = e5 y2,2 = 93 y2,3 = 58
q0.in=4f
a0=4 b0=f
a1=b b1=b
a2=9 b2=6
a3=f b3=2
a4=1 b4=f
q0.out=f1
l1,3=14
q0.in=e9
a0=e b0=9
a1=7 b1=2
a2=2 b2=b
a3=9 b3=f
a4=8 b4=a
q0.out=a8
l0,3=dc
q1.in=29
a0=2 b0=9
a1=b b1=e
a2=4 b2=0
a3=4 b3=4
a4=1 b4=c
q1.out=c1
q1.in=60
a0=6 b0=0
a1=6 b1=6
a2=6 b2=3
a3=5 b3=f
a4=6 b4=a
q1.out=a6
l1,2=9c
q0.in=2c
a0=2 b0=c
a1=e b1=4
a2=a b2=1
a3=b b3=2
a4=3 b4=f
q0.out=f3
l0,2=53
q0.in=78
a0=7 b0=8
a1=f b1=b
a2=4 b2=6
a3=2 b3=7
a4=5 b4=e
q0.out=e5
q0.in=59
a0=5 b0=9
a1=c b1=1
a2=e b2=c
a3=2 b3=8
a4=5 b4=9
q0.out=95
l1,1=8a
q1.in=09
a0=0 b0=9
a1=9 b1=c
a2=1 b2=f
a3=e b3=6
a4=3 b4=d
q1.out=d3
l0,1=8b
q1.in=80
a0=8 b0=0
a1=8 b1=8
a2=3 b2=6
a3=5 b3=8
a4=6 b4=6
q1.out=66
q1.in=7c
a0=7 b0=c
a1=b b1=9
a2=4 b2=d
a3=9 b3=a
a4=e b4=7
q1.out=7e
l1,0=18
q1.in=6a
a0=6 b0=a
a1=c b1=3
a2=0 b2=b
a3=b b3=d
a4=8 b4=0
q1.out=08
l0,0=81
q0.in=d4
a0=d b0=4
a1=9 b1=7
a2=b b2=5
a3=e b3=9
a4=7 b4=b
q0.out=b7
q0.in=ce
a0=c b0=e
a1=2 b1=b
a2=7 b2=6
a3=1 b3=c
a4=a b4=8
q0.out=8a
l1,3=14
q0.in=92
a0=9 b0=2
a1=b b1=0
a2=9 b2=e
a3=7 b3=6
a4=0 b4=6
q0.out=60
l0,3=dc
q1.in=e1
a0=e b0=1
a1=f b1=6
a2=5 b2=3
a3=6 b3=4
a4=9 b4=c
q1.out=c9
q1.in=e5
a0=e b0=5
a1=b b1=4
a2=4 b2=4
a3=0 b3=6
a4=4 b4=d
q1.out=d4
l1,2=9c
q0.in=5e
a0=5 b0=e
a1=b b1=a
a2=9 b2=a
a3=3 b3=4
a4=e b4=1
q0.out=1e
l0,2=53
q0.in=95
a0=9 b0=5
a1=c b1=b
a2=e b2=6
a3=8 b3=d
a4=c b4=5
q0.out=5c
q0.in=93
a0=9 b0=3
a1=a b1=8
a2=5 b2=f
a3=a b3=2
a4=f b4=f
q0.out=ff
l1,1=8a
q1.in=63
a0=6 b0=3
a1=5 b1=f
a2=7 b2=8
a3=f b3=b
a4=f b4=f
q1.out=ff
l0,1=8b
q1.in=ac
a0=a b0=c
a1=6 b1=c
a2=6 b2=f
a3=9 b3=9
a4=e b4=4
q1.out=4e
q1.in=58
a0=5 b0=8
a1=d b1=9
a2=a b2=d
a3=7 b3=4
a4=a b4=c
q1.out=ca
l1,0=18
q1.in=de
a0=d b0=e
a1=3 b1=2
a2=d b2=2
a3=f b3=4
a4=f b4=c
q1.out=cf
l0,0=81
q0.in=13
a0=1 b0=3
a1=2 b1=0
a2=7 b2=e
a3=9 b3=8
a4=8 b4=9
q0.out=98
y0 = c1 y1 = e5 y2 = 66 y3 = b7 y0 = c9 y1 = 5c y2 = 4e y3 = 98
MDS input = Y = y0y1y2y3 = c1e566b7 MDS input = Y = y0y1y2y3 = c95c4e98
MDS output = Z = z0z1z2z3 = 3ea40416 MDS output = Z = z0z1z2z3 = fb92865d
z0 = 3e z1 = a4 z2 = 04 z3 = 16 z0 = fb z1 = 92 z2 = 86 z3 = 5d
T0 = g(R0) = 3ea40416 T1 = g(ROL(R1, 8)) = fb92865d
F0,0 = (T0 + T1 + K8) mod 232 = (3ea40416 + fb92865d + f595a22f) mod 232
= (1604a43e(big endian) + 5d8692fb(big endian) + 2fa295f5(big endian)) mod 232
= a32dcd2e(big endian) = 2ecd2da3.
F0,1 = (T0 + 2T1 + K9) mod 232 = (3ea40416 + 2[fb92865d] + b3c6caca) mod 232
= (1604a43e(big endian) + 2[5d8692fb(big endian)] + cacac6b3(big endian)) mod 232
= (1604a43e(big endian) + bb0d25f6(big endian) + cacac6b3(big endian)) mod 232
= 9bdc90e7(big endian) = e790dc9b.
R1,0  =  ROR(R0, 2    F0,0,1) =  ROR(6cdae213    2ecd2da3, 1)
=  ROR(4217cfb0, 1) =  ROR(b0cf1742(big endian), 1)
=  58678ba1(big endian) =  a18b6758
R1,1  =  ROL(R0, 3,  1)    F0,1) =  ROL(d694ccb8,  1)    e790dc9b
=  ROL(b8cc94d6(big endian),  1)    e790dc9b
=  719929ad(big endian)    e790dc9b
=  ad299971   e790dc9b =  4ab945ea.
R1,2 = R0,0 = 4f60597c R1,3 = R0,1 = e59358ce

 

Encryption of block 1, round r=1
g input = X = x0x1x2x3 = R1,0 = a18b6758
g input = X = x0x1x2x3
= ROL(R1,1,  8) = ROL(4ab945ea ,  8)
= ROL(ea45b94a(big endian),  8)
= 45b94aea(big endian) = ea4ab945.
x0 = a1 x1 = 8b x2 = 67 x3 = 58 x0 = ea x1 = 4a x2 = b9 x3 = 45
y2,0 = a1 y2,1 = 8b y2,2 = 67 y2,3 = 58 y2,0 = ea y2,1 = 4a y2,2 = b9 y2,3 = 45
q0.in=a1
a0=a b0=1
a1=b b1=2
a2=9 b2=b
a3=2 b3=c
a4=5 b4=8
q0.out=85
l1,3=14
q0.in=9d
a0=9 b0=d
a1=4 b1=f
a2=6 b2=d
a3=b b3=8
a4=3 b4=9
q0.out=93
l0,3=dc
q1.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=6
a3=b b3=6
a4=8 b4=d
q1.out=d8
q1.in=8b
a0=8 b0=b
a1=3 b1=5
a2=d b2=c
a3=1 b3=3
a4=c b4=1
q1.out=1c
l1,2=9c
q0.in=96
a0=9 b0=6
a1=f b1=2
a2=4 b2=b
a3=f b3=9
a4=1 b4=b
q0.out=b1
l0,2=53
q0.in=3a
a0=3 b0=a
a1=9 b1=e
a2=b b2=9
a3=2 b3=f
a4=5 b4=a
q0.out=a5
q0.in=67
a0=6 b0=7
a1=1 b1=d
a2=1 b2=0
a3=1 b3=9
a4=a b4=b
q0.out=ba
l1,1=8a
q1.in=26
a0=2 b0=6
a1=4 b1=1
a2=f b2=e
a3=1 b3=0
a4=c b4=b
q1.out=bc
l0,1=8b
q1.in=ef
a0=e b0=f
a1=1 b1=1
a2=8 b2=e
a3=6 b3=f
a4=9 b4=a
q1.out=a9
q1.in=58
a0=5 b0=8
a1=d b1=9
a2=a b2=d
a3=7 b3=4
a4=a b4=c
q1.out=ca
l1,0=18
q1.in=de
a0=d b0=e
a1=3 b1=2
a2=d b2=2
a3=f b3=4
a4=f b4=c
q1.out=cf
l0,0=81
q0.in=13
a0=1 b0=3
a1=2 b1=0
a2=7 b2=e
a3=9 b3=8
a4=8 b4=9
q0.out=98
q0.in=ea
a0=e b0=a
a1=4 b1=b
a2=6 b2=6
a3=0 b3=5
a4=b b4=2
q0.out=2b
l1,3=14
q0.in=33
a0=3 b0=3
a1=0 b1=2
a2=8 b2=b
a3=3 b3=5
a4=e b4=2
q0.out=2e
l0,3=dc
q1.in=af
a0=a b0=f
a1=5 b1=5
a2=7 b2=c
a3=b b3=9
a4=8 b4=4
q1.out=48
q1.in=4a
a0=4 b0=a
a1=e b1=1
a2=c b2=e
a3=2 b3=b
a4=7 b4=f
q1.out=f7
l1,2=9c
q0.in=7d
a0=7 b0=d
a1=a b1=1
a2=5 b2=c
a3=9 b3=b
a4=8 b4=0
q0.out=08
l0,2=53
q0.in=83
a0=8 b0=3
a1=b b1=1
a2=9 b2=c
a3=5 b3=7
a4=d b4=e
q0.out=ed
q0.in=b9
a0=b b0=9
a1=2 b1=f
a2=7 b2=d
a3=a b3=1
a4=f b4=7
q0.out=7f
l1,1=8a
q1.in=e3
a0=e b0=3
a1=d b1=7
a2=a b2=7
a3=d b3=1
a4=b b4=9
q1.out=9b
l0,1=8b
q1.in=c8
a0=c b0=8
a1=4 b1=8
a2=f b2=6
a3=9 b3=4
a4=e b4=c
q1.out=ce
q1.in=45
a0=4 b0=5
a1=1 b1=e
a2=8 b2=0
a3=8 b3=8
a4=0 b4=6
q1.out=60
l1,0=18
q1.in=74
a0=7 b0=4
a1=3 b1=d
a2=d b2=9
a3=4 b3=9
a4=1 b4=4
q1.out=41
l0,0=81
q0.in=9d
a0=9 b0=d
a1=4 b1=f
a2=6 b2=d
a3=b b3=8
a4=3 b4=9
q0.out=93
y0 = d8 y1 = a5 y2 = a9 y3 = 98 y0 = 48 y1 = ed y2 = ce y3 = 93
MDS input = Y = y0y1y2y3 = d8a5a998 MDS input = Y = y0y1y2y3 = 48edce93
MDS output = Z = z0z1z2z3 = 8f7f0fa0 MDS output = Z = z0z1z2z3 = 16a998e4
z0 = 8f z1 = 7f z2 = 0f z3 = a0 z0 = 16 z1 = a9 z2 = 98 z3 = e4
T0 = g(R0) = 8f7f0fa0 T1 = g(ROL(R1, 8)) = 16a998e4
F1,0 = (T0 + T1 + K10) mod 232 = (8f7f0fa0 + 16a998e4 + 22166ed7) mod 232
= (a00f7f8f(big endian) + e498a916(big endian) + d76e1622(big endian)) mod 232
= 5c163ec7(big endian) = c73e165c.
F1,1 = (T0 + 2T1 + K11) mod 232 = (8f7f0fa0 + 2[16a998e4] + 2547a011) mod 232
= (a00f7f8f(big endian) + 2[e498a916(big endian)] + 11a04725(big endian)) mod 232
= (a00f7f8f(big endian) + c931522c(big endian) + 11a04725(big endian)) mod 232
= 7ae118e0(big endian) = e018e17a.
R2,0  =  ROR(R1, 2    F1,0,1) =  ROR(4f60597c    c73e165c, 1)
=  ROR(885e4f20, 1) =  ROR(204f5e88(big endian), 1)
=  1027af44(big endian) =  44af2710
R2,1  =  ROL(R1, 3,  1)    F1,1) =  ROL(e59358ce,  1)    e018e17a
=  ROL(ce5893e5(big endian),  1)    e018e17a
=  9cb127cb(big endian)    e018e17a
=  cb27b19c   e018e17a =  2b3f50e6.
R2,2 = R1,0 = a18b6758 R2,3 = R1,1 = 4ab945ea

 

Encryption of block 1, round r=2
g input = X = x0x1x2x3 = R2,0 = 44af2710
g input = X = x0x1x2x3
= ROL(R2,1,  8) = ROL(2b3f50e6 ,  8)
= ROL(e6503f2b(big endian),  8)
= 503f2be6(big endian) = e62b3f50.
x0 = 44 x1 = af x2 = 27 x3 = 10 x0 = e6 x1 = 2b x2 = 3f x3 = 50
y2,0 = 44 y2,1 = af y2,2 = 27 y2,3 = 10 y2,0 = e6 y2,1 = 2b y2,2 = 3f y2,3 = 50
q0.in=44
a0=4 b0=4
a1=0 b1=6
a2=8 b2=3
a3=b b3=1
a4=3 b4=7
q0.out=73
l1,3=14
q0.in=6b
a0=6 b0=b
a1=d b1=b
a2=c b2=6
a3=a b3=f
a4=f b4=a
q0.out=af
l0,3=dc
q1.in=2e
a0=2 b0=e
a1=c b1=5
a2=0 b2=c
a3=c b3=6
a4=2 b4=d
q1.out=d2
q1.in=af
a0=a b0=f
a1=5 b1=5
a2=7 b2=c
a3=b b3=9
a4=8 b4=4
q1.out=48
l1,2=9c
q0.in=c2
a0=c b0=2
a1=e b1=d
a2=a b2=0
a3=a b3=a
a4=f b4=3
q0.out=3f
l0,2=53
q0.in=b4
a0=b b0=4
a1=f b1=1
a2=4 b2=c
a3=8 b3=2
a4=c b4=f
q0.out=fc
q0.in=27
a0=2 b0=7
a1=5 b1=9
a2=f b2=4
a3=b b3=5
a4=3 b4=2
q0.out=23
l1,1=8a
q1.in=bf
a0=b b0=f
a1=4 b1=c
a2=f b2=f
a3=0 b3=8
a4=4 b4=6
q1.out=64
l0,1=8b
q1.in=37
a0=3 b0=7
a1=4 b1=0
a2=f b2=1
a3=e b3=f
a4=3 b4=a
q1.out=a3
q1.in=10
a0=1 b0=0
a1=1 b1=9
a2=8 b2=d
a3=5 b3=6
a4=6 b4=d
q1.out=d6
l1,0=18
q1.in=c2
a0=c b0=2
a1=e b1=d
a2=c b2=9
a3=5 b3=0
a4=6 b4=b
q1.out=b6
l0,0=81
q0.in=6a
a0=6 b0=a
a1=c b1=3
a2=e b2=8
a3=6 b3=a
a4=9 b4=3
q0.out=39
q0.in=e6
a0=e b0=6
a1=8 b1=d
a2=0 b2=0
a3=0 b3=0
a4=b b4=d
q0.out=db
l1,3=14
q0.in=c3
a0=c b0=3
a1=f b1=5
a2=4 b2=2
a3=6 b3=5
a4=9 b4=2
q0.out=29
l0,3=dc
q1.in=a8
a0=a b0=8
a1=2 b1=e
a2=b b2=0
a3=b b3=3
a4=8 b4=1
q1.out=18
q1.in=2b
a0=2 b0=b
a1=9 b1=f
a2=1 b2=8
a3=9 b3=d
a4=e b4=0
q1.out=0e
l1,2=9c
q0.in=84
a0=8 b0=4
a1=c b1=a
a2=e b2=a
a3=4 b3=b
a4=6 b4=0
q0.out=06
l0,2=53
q0.in=8d
a0=8 b0=d
a1=5 b1=6
a2=f b2=3
a3=c b3=e
a4=2 b4=c
q0.out=c2
q0.in=3f
a0=3 b0=f
a1=c b1=4
a2=e b2=1
a3=f b3=6
a4=1 b4=6
q0.out=61
l1,1=8a
q1.in=fd
a0=f b0=d
a1=2 b1=9
a2=b b2=d
a3=6 b3=d
a4=9 b4=0
q1.out=09
l0,1=8b
q1.in=5a
a0=5 b0=a
a1=f b1=8
a2=5 b2=6
a3=3 b3=e
a4=5 b4=8
q1.out=85
q1.in=50
a0=5 b0=0
a1=5 b1=d
a2=7 b2=9
a3=e b3=3
a4=3 b4=1
q1.out=13
l1,0=18
q1.in=07
a0=0 b0=7
a1=7 b1=b
a2=e b2=5
a3=b b3=4
a4=8 b4=c
q1.out=c8
l0,0=81
q0.in=14
a0=1 b0=4
a1=5 b1=b
a2=f b2=6
a3=9 b3=4
a4=8 b4=1
q0.out=18
y0 = d2 y1 = fc y2 = a3 y3 = 39 y0 = 18 y1 = c2 y2 = 85 y3 = 18
MDS input = Y = y0y1y2y3 = d2fca339 MDS input = Y = y0y1y2y3 = 18c28518
MDS output = Z = z0z1z2z3 = 67569e2a MDS output = Z = z0z1z2z3 = df29c3c6
z0 = 67 z1 = 56 z2 = 9e z3 = 2a z0 = df z1 = 29 z2 = c3 z3 = c6
T0 = g(R0) = 67569e2a T1 = g(ROL(R1, 8)) = df29c3c6
F2,0 = (T0 + T1 + K12) mod 232 = (67569e2a + df29c3c6 + a38a1320) mod 232
= (2a9e5667(big endian) + c6c329df(big endian) + 20138aa3(big endian)) mod 232
= 11750ae9(big endian) = e90a7511.
F2,1 = (T0 + 2T1 + K13) mod 232 = (67569e2a + 2[df29c3c6] + 0813350e) mod 232
= (2a9e5667(big endian) + 2[c6c329df(big endian)] + 0e351308(big endian)) mod 232
= (2a9e5667(big endian) + 8d8653be(big endian) + 0e351308(big endian)) mod 232
= c659bd2d(big endian) = 2dbd59c6.
R3,0  =  ROR(R2, 2    F2,0,1) =  ROR(a18b6758    e90a7511, 1)
=  ROR(48811249, 1) =  ROR(49128148(big endian), 1)
=  248940a4(big endian) =  a4408924
R3,1  =  ROL(R2, 3,  1)    F2,1) =  ROL(4ab945ea,  1)    2dbd59c6
=  ROL(ea45b94a(big endian),  1)    2dbd59c6
=  d48b7295(big endian)    2dbd59c6
=  95728bd4   2dbd59c6 =  b8cfd212.
R3,2 = R2,0 = 44af2710 R3,3 = R2,1 = 2b3f50e6

 

Encryption of block 1, round r=3
g input = X = x0x1x2x3 = R3,0 = a4408924
g input = X = x0x1x2x3
= ROL(R3,1,  8) = ROL(b8cfd212 ,  8)
= ROL(12d2cfb8(big endian),  8)
= d2cfb812(big endian) = 12b8cfd2.
x0 = a4 x1 = 40 x2 = 89 x3 = 24 x0 = 12 x1 = b8 x2 = cf x3 = d2
y2,0 = a4 y2,1 = 40 y2,2 = 89 y2,3 = 24 y2,0 = 12 y2,1 = b8 y2,2 = cf y2,3 = d2
q0.in=a4
a0=a b0=4
a1=e b1=8
a2=a b2=f
a3=5 b3=5
a4=d b4=2
q0.out=2d
l1,3=14
q0.in=35
a0=3 b0=5
a1=6 b1=1
a2=3 b2=c
a3=f b3=d
a4=1 b4=5
q0.out=51
l0,3=dc
q1.in=d0
a0=d b0=0
a1=d b1=5
a2=a b2=c
a3=6 b3=c
a4=9 b4=2
q1.out=29
q1.in=40
a0=4 b0=0
a1=4 b1=4
a2=f b2=4
a3=b b3=5
a4=8 b4=3
q1.out=38
l1,2=9c
q0.in=b2
a0=b b0=2
a1=9 b1=2
a2=b b2=b
a3=0 b3=e
a4=b b4=c
q0.out=cb
l0,2=53
q0.in=40
a0=4 b0=0
a1=4 b1=4
a2=6 b2=1
a3=7 b3=e
a4=0 b4=c
q0.out=c0
q0.in=89
a0=8 b0=9
a1=1 b1=4
a2=1 b2=1
a3=0 b3=1
a4=b b4=7
q0.out=7b
l1,1=8a
q1.in=e7
a0=e b0=7
a1=9 b1=5
a2=1 b2=c
a3=d b3=f
a4=b b4=a
q1.out=ab
l0,1=8b
q1.in=f8
a0=f b0=8
a1=7 b1=3
a2=e b2=b
a3=5 b3=3
a4=6 b4=1
q1.out=16
q1.in=24
a0=2 b0=4
a1=6 b1=0
a2=6 b2=1
a3=7 b3=e
a4=a b4=8
q1.out=8a
l1,0=18
q1.in=9e
a0=9 b0=e
a1=7 b1=6
a2=e b2=3
a3=d b3=7
a4=b b4=e
q1.out=eb
l0,0=81
q0.in=37
a0=3 b0=7
a1=4 b1=0
a2=6 b2=e
a3=8 b3=1
a4=c b4=7
q0.out=7c
q0.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=f
a3=2 b3=a
a4=5 b4=3
q0.out=35
l1,3=14
q0.in=2d
a0=2 b0=d
a1=f b1=c
a2=4 b2=7
a3=3 b3=f
a4=e b4=a
q0.out=ae
l0,3=dc
q1.in=2f
a0=2 b0=f
a1=d b1=d
a2=a b2=9
a3=3 b3=6
a4=5 b4=d
q1.out=d5
q1.in=b8
a0=b b0=8
a1=3 b1=7
a2=d b2=7
a3=a b3=e
a4=d b4=8
q1.out=8d
l1,2=9c
q0.in=07
a0=0 b0=7
a1=7 b1=b
a2=2 b2=6
a3=4 b3=1
a4=6 b4=7
q0.out=76
l0,2=53
q0.in=fd
a0=f b0=d
a1=2 b1=9
a2=7 b2=4
a3=3 b3=d
a4=e b4=5
q0.out=5e
q0.in=cf
a0=c b0=f
a1=3 b1=3
a2=d b2=8
a3=5 b3=1
a4=d b4=7
q0.out=7d
l1,1=8a
q1.in=e1
a0=e b0=1
a1=f b1=6
a2=5 b2=3
a3=6 b3=4
a4=9 b4=c
q1.out=c9
l0,1=8b
q1.in=9a
a0=9 b0=a
a1=3 b1=4
a2=d b2=4
a3=9 b3=7
a4=e b4=e
q1.out=ee
q1.in=d2
a0=d b0=2
a1=f b1=4
a2=5 b2=4
a3=1 b3=f
a4=c b4=a
q1.out=ac
l1,0=18
q1.in=b8
a0=b b0=8
a1=3 b1=7
a2=d b2=7
a3=a b3=e
a4=d b4=8
q1.out=8d
l0,0=81
q0.in=51
a0=5 b0=1
a1=4 b1=5
a2=6 b2=2
a3=4 b3=7
a4=6 b4=e
q0.out=e6
y0 = 29 y1 = c0 y2 = 16 y3 = 7c y0 = d5 y1 = 5e y2 = ee y3 = e6
MDS input = Y = y0y1y2y3 = 29c0167c MDS input = Y = y0y1y2y3 = d55eeee6
MDS output = Z = z0z1z2z3 = 7d3962d6 MDS output = Z = z0z1z2z3 = 0d986f47
z0 = 7d z1 = 39 z2 = 62 z3 = d6 z0 = 0d z1 = 98 z2 = 6f z3 = 47
T0 = g(R0) = 7d3962d6 T1 = g(ROL(R1, 8)) = 0d986f47
F3,0 = (T0 + T1 + K14) mod 232 = (7d3962d6 + 0d986f47 + 281a4854) mod 232
= (d662397d(big endian) + 476f980d(big endian) + 54481a28(big endian)) mod 232
= 7219ebb2(big endian) = b2eb1972.
F3,1 = (T0 + 2T1 + K15) mod 232 = (7d3962d6 + 2[0d986f47] + a0ddfa24) mod 232
= (d662397d(big endian) + 2[476f980d(big endian)] + 24fadda0(big endian)) mod 232
= (d662397d(big endian) + 8edf301a(big endian) + 24fadda0(big endian)) mod 232
= 8a3c4737(big endian) = 37473c8a.
R4,0  =  ROR(R3, 2    F3,0,1) =  ROR(44af2710    b2eb1972, 1)
=  ROR(f6443e62, 1) =  ROR(623e44f6(big endian), 1)
=  311f227b(big endian) =  7b221f31
R4,1  =  ROL(R3, 3,  1)    F3,1) =  ROL(2b3f50e6,  1)    37473c8a
=  ROL(e6503f2b(big endian),  1)    37473c8a
=  cca07e57(big endian)    37473c8a
=  577ea0cc   37473c8a =  60399c46.
R4,2 = R3,0 = a4408924 R4,3 = R3,1 = b8cfd212

 

Encryption of block 1, round r=4
g input = X = x0x1x2x3 = R4,0 = 7b221f31
g input = X = x0x1x2x3
= ROL(R4,1,  8) = ROL(60399c46 ,  8)
= ROL(469c3960(big endian),  8)
= 9c396046(big endian) = 4660399c.
x0 = 7b x1 = 22 x2 = 1f x3 = 31 x0 = 46 x1 = 60 x2 = 39 x3 = 9c
y2,0 = 7b y2,1 = 22 y2,2 = 1f y2,3 = 31 y2,0 = 46 y2,1 = 60 y2,2 = 39 y2,3 = 9c
q0.in=7b
a0=7 b0=b
a1=c b1=2
a2=e b2=b
a3=5 b3=3
a4=d b4=4
q0.out=4d
l1,3=14
q0.in=55
a0=5 b0=5
a1=0 b1=7
a2=8 b2=5
a3=d b3=2
a4=4 b4=f
q0.out=f4
l0,3=dc
q1.in=75
a0=7 b0=5
a1=2 b1=5
a2=b b2=c
a3=7 b3=5
a4=a b4=3
q1.out=3a
q1.in=22
a0=2 b0=2
a1=0 b1=3
a2=2 b2=b
a3=9 b3=f
a4=e b4=a
q1.out=ae
l1,2=9c
q0.in=24
a0=2 b0=4
a1=6 b1=0
a2=3 b2=e
a3=d b3=c
a4=4 b4=8
q0.out=84
l0,2=53
q0.in=0f
a0=0 b0=f
a1=f b1=f
a2=4 b2=d
a3=9 b3=a
a4=8 b4=3
q0.out=38
q0.in=1f
a0=1 b0=f
a1=e b1=6
a2=a b2=3
a3=9 b3=3
a4=8 b4=4
q0.out=48
l1,1=8a
q1.in=d4
a0=d b0=4
a1=9 b1=7
a2=1 b2=7
a3=6 b3=2
a4=9 b4=5
q1.out=59
l0,1=8b
q1.in=0a
a0=0 b0=a
a1=a b1=5
a2=9 b2=c
a3=5 b3=7
a4=6 b4=e
q1.out=e6
q1.in=31
a0=3 b0=1
a1=2 b1=3
a2=b b2=b
a3=0 b3=e
a4=4 b4=8
q1.out=84
l1,0=18
q1.in=90
a0=9 b0=0
a1=9 b1=1
a2=1 b2=e
a3=f b3=e
a4=f b4=8
q1.out=8f
l0,0=81
q0.in=53
a0=5 b0=3
a1=6 b1=4
a2=3 b2=1
a3=2 b3=3
a4=5 b4=4
q0.out=45
q0.in=46
a0=4 b0=6
a1=2 b1=7
a2=7 b2=5
a3=2 b3=5
a4=5 b4=2
q0.out=25
l1,3=14
q0.in=3d
a0=3 b0=d
a1=e b1=5
a2=a b2=2
a3=8 b3=b
a4=c b4=0
q0.out=0c
l0,3=dc
q1.in=8d
a0=8 b0=d
a1=5 b1=6
a2=7 b2=3
a3=4 b3=6
a4=1 b4=d
q1.out=d1
q1.in=60
a0=6 b0=0
a1=6 b1=6
a2=6 b2=3
a3=5 b3=f
a4=6 b4=a
q1.out=a6
l1,2=9c
q0.in=2c
a0=2 b0=c
a1=e b1=4
a2=a b2=1
a3=b b3=2
a4=3 b4=f
q0.out=f3
l0,2=53
q0.in=78
a0=7 b0=8
a1=f b1=b
a2=4 b2=6
a3=2 b3=7
a4=5 b4=e
q0.out=e5
q0.in=39
a0=3 b0=9
a1=a b1=7
a2=5 b2=5
a3=0 b3=7
a4=b b4=e
q0.out=eb
l1,1=8a
q1.in=77
a0=7 b0=7
a1=0 b1=4
a2=2 b2=4
a3=6 b3=0
a4=9 b4=b
q1.out=b9
l0,1=8b
q1.in=ea
a0=e b0=a
a1=4 b1=b
a2=f b2=5
a3=a b3=d
a4=d b4=0
q1.out=0d
q1.in=9c
a0=9 b0=c
a1=5 b1=7
a2=7 b2=7
a3=0 b3=4
a4=4 b4=c
q1.out=c4
l1,0=18
q1.in=d0
a0=d b0=0
a1=d b1=5
a2=a b2=c
a3=6 b3=c
a4=9 b4=2
q1.out=29
l0,0=81
q0.in=f5
a0=f b0=5
a1=a b1=d
a2=5 b2=0
a3=5 b3=d
a4=d b4=5
q0.out=5d
y0 = 3a y1 = 38 y2 = e6 y3 = 45 y0 = d1 y1 = e5 y2 = 0d y3 = 5d
MDS input = Y = y0y1y2y3 = 3a38e645 MDS input = Y = y0y1y2y3 = d1e50d5d
MDS output = Z = z0z1z2z3 = 75f7d5b3 MDS output = Z = z0z1z2z3 = d5446270
z0 = 75 z1 = f7 z2 = d5 z3 = b3 z0 = d5 z1 = 44 z2 = 62 z3 = 70
T0 = g(R0) = 75f7d5b3 T1 = g(ROL(R1, 8)) = d5446270
F4,0 = (T0 + T1 + K16) mod 232 = (75f7d5b3 + d5446270 + 19c3630c) mod 232
= (b3d5f775(big endian) + 706244d5(big endian) + 0c63c319(big endian)) mod 232
= 309bff63(big endian) = 63ff9b30.
F4,1 = (T0 + 2T1 + K17) mod 232 = (75f7d5b3 + 2[d5446270] + 5bc0b2cc) mod 232
= (b3d5f775(big endian) + 2[706244d5(big endian)] + ccb2c05b(big endian)) mod 232
= (b3d5f775(big endian) + e0c489aa(big endian) + ccb2c05b(big endian)) mod 232
= 614d417a(big endian) = 7a414d61.
R5,0  =  ROR(R4, 2    F4,0,1) =  ROR(a4408924    63ff9b30, 1)
=  ROR(c7bf1214, 1) =  ROR(1412bfc7(big endian), 1)
=  8a095fe3(big endian) =  e35f098a
R5,1  =  ROL(R4, 3,  1)    F4,1) =  ROL(b8cfd212,  1)    7a414d61
=  ROL(12d2cfb8(big endian),  1)    7a414d61
=  25a59f70(big endian)    7a414d61
=  709fa525   7a414d61 =  0adee844.
R5,2 = R4,0 = 7b221f31 R5,3 = R4,1 = 60399c46

 

Encryption of block 1, round r=5
g input = X = x0x1x2x3 = R5,0 = e35f098a
g input = X = x0x1x2x3
= ROL(R5,1,  8) = ROL(0adee844 ,  8)
= ROL(44e8de0a(big endian),  8)
= e8de0a44(big endian) = 440adee8.
x0 = e3 x1 = 5f x2 = 09 x3 = 8a x0 = 44 x1 = 0a x2 = de x3 = e8
y2,0 = e3 y2,1 = 5f y2,2 = 09 y2,3 = 8a y2,0 = 44 y2,1 = 0a y2,2 = de y2,3 = e8
q0.in=e3
a0=e b0=3
a1=d b1=7
a2=c b2=5
a3=9 b3=6
a4=8 b4=6
q0.out=68
l1,3=14
q0.in=70
a0=7 b0=0
a1=7 b1=f
a2=2 b2=d
a3=f b3=c
a4=1 b4=8
q0.out=81
l0,3=dc
q1.in=00
a0=0 b0=0
a1=0 b1=0
a2=2 b2=1
a3=3 b3=a
a4=5 b4=7
q1.out=75
q1.in=5f
a0=5 b0=f
a1=a b1=2
a2=9 b2=2
a3=b b3=0
a4=8 b4=b
q1.out=b8
l1,2=9c
q0.in=32
a0=3 b0=2
a1=1 b1=a
a2=1 b2=a
a3=b b3=c
a4=3 b4=8
q0.out=83
l0,2=53
q0.in=08
a0=0 b0=8
a1=8 b1=4
a2=0 b2=1
a3=1 b3=8
a4=a b4=9
q0.out=9a
q0.in=09
a0=0 b0=9
a1=9 b1=c
a2=b b2=7
a3=c b3=8
a4=2 b4=9
q0.out=92
l1,1=8a
q1.in=0e
a0=0 b0=e
a1=e b1=7
a2=c b2=7
a3=b b3=7
a4=8 b4=e
q1.out=e8
l0,1=8b
q1.in=bb
a0=b b0=b
a1=0 b1=e
a2=2 b2=0
a3=2 b3=2
a4=7 b4=5
q1.out=57
q1.in=8a
a0=8 b0=a
a1=2 b1=d
a2=b b2=9
a3=2 b3=f
a4=7 b4=a
q1.out=a7
l1,0=18
q1.in=b3
a0=b b0=3
a1=8 b1=a
a2=3 b2=a
a3=9 b3=e
a4=e b4=8
q1.out=8e
l0,0=81
q0.in=52
a0=5 b0=2
a1=7 b1=c
a2=2 b2=7
a3=5 b3=9
a4=d b4=b
q0.out=bd
q0.in=44
a0=4 b0=4
a1=0 b1=6
a2=8 b2=3
a3=b b3=1
a4=3 b4=7
q0.out=73
l1,3=14
q0.in=6b
a0=6 b0=b
a1=d b1=b
a2=c b2=6
a3=a b3=f
a4=f b4=a
q0.out=af
l0,3=dc
q1.in=2e
a0=2 b0=e
a1=c b1=5
a2=0 b2=c
a3=c b3=6
a4=2 b4=d
q1.out=d2
q1.in=0a
a0=0 b0=a
a1=a b1=5
a2=9 b2=c
a3=5 b3=7
a4=6 b4=e
q1.out=e6
l1,2=9c
q0.in=6c
a0=6 b0=c
a1=a b1=0
a2=5 b2=e
a3=b b3=a
a4=3 b4=3
q0.out=33
l0,2=53
q0.in=b8
a0=b b0=8
a1=3 b1=7
a2=d b2=5
a3=8 b3=f
a4=c b4=a
q0.out=ac
q0.in=de
a0=d b0=e
a1=3 b1=2
a2=d b2=b
a3=6 b3=8
a4=9 b4=9
q0.out=99
l1,1=8a
q1.in=05
a0=0 b0=5
a1=5 b1=a
a2=7 b2=a
a3=d b3=a
a4=b b4=7
q1.out=7b
l0,1=8b
q1.in=28
a0=2 b0=8
a1=a b1=6
a2=9 b2=3
a3=a b3=8
a4=d b4=6
q1.out=6d
q1.in=e8
a0=e b0=8
a1=6 b1=a
a2=6 b2=a
a3=c b3=3
a4=2 b4=1
q1.out=12
l1,0=18
q1.in=06
a0=0 b0=6
a1=6 b1=3
a2=6 b2=b
a3=d b3=b
a4=b b4=f
q1.out=fb
l0,0=81
q0.in=27
a0=2 b0=7
a1=5 b1=9
a2=f b2=4
a3=b b3=5
a4=3 b4=2
q0.out=23
y0 = 75 y1 = 9a y2 = 57 y3 = bd y0 = d2 y1 = ac y2 = 6d y3 = 23
MDS input = Y = y0y1y2y3 = 759a57bd MDS input = Y = y0y1y2y3 = d2ac6d23
MDS output = Z = z0z1z2z3 = 54f9c1dd MDS output = Z = z0z1z2z3 = ea0eb1fc
z0 = 54 z1 = f9 z2 = c1 z3 = dd z0 = ea z1 = 0e z2 = b1 z3 = fc
T0 = g(R0) = 54f9c1dd T1 = g(ROL(R1, 8)) = ea0eb1fc
F5,0 = (T0 + T1 + K18) mod 232 = (54f9c1dd + ea0eb1fc + d542f0e2) mod 232
= (ddc1f954(big endian) + fcb10eea(big endian) + e2f042d5(big endian)) mod 232
= bd634b13(big endian) = 134b63bd.
F5,1 = (T0 + 2T1 + K19) mod 232 = (54f9c1dd + 2[ea0eb1fc] + 9f8b15e9) mod 232
= (ddc1f954(big endian) + 2[fcb10eea(big endian)] + e9158b9f(big endian)) mod 232
= (ddc1f954(big endian) + f9621dd4(big endian) + e9158b9f(big endian)) mod 232
= c039a2c7(big endian) = c7a239c0.
R6,0  =  ROR(R5, 2    F5,0,1) =  ROR(7b221f31    134b63bd, 1)
=  ROR(68697c8c, 1) =  ROR(8c7c6968(big endian), 1)
=  463e34b4(big endian) =  b4343e46
R6,1  =  ROL(R5, 3,  1)    F5,1) =  ROL(60399c46,  1)    c7a239c0
=  ROL(469c3960(big endian),  1)    c7a239c0
=  8d3872c0(big endian)    c7a239c0
=  c072388d   c7a239c0 =  07d0014d.
R6,2 = R5,0 = e35f098a R6,3 = R5,1 = 0adee844

 

Encryption of block 1, round r=6
g input = X = x0x1x2x3 = R6,0 = b4343e46
g input = X = x0x1x2x3
= ROL(R6,1,  8) = ROL(07d0014d ,  8)
= ROL(4d01d007(big endian),  8)
= 01d0074d(big endian) = 4d07d001.
x0 = b4 x1 = 34 x2 = 3e x3 = 46 x0 = 4d x1 = 07 x2 = d0 x3 = 01
y2,0 = b4 y2,1 = 34 y2,2 = 3e y2,3 = 46 y2,0 = 4d y2,1 = 07 y2,2 = d0 y2,3 = 01
q0.in=b4
a0=b b0=4
a1=f b1=1
a2=4 b2=c
a3=8 b3=2
a4=c b4=f
q0.out=fc
l1,3=14
q0.in=e4
a0=e b0=4
a1=a b1=c
a2=5 b2=7
a3=2 b3=6
a4=5 b4=6
q0.out=65
l0,3=dc
q1.in=e4
a0=e b0=4
a1=a b1=c
a2=9 b2=f
a3=6 b3=e
a4=9 b4=8
q1.out=89
q1.in=34
a0=3 b0=4
a1=7 b1=9
a2=e b2=d
a3=3 b3=0
a4=5 b4=b
q1.out=b5
l1,2=9c
q0.in=3f
a0=3 b0=f
a1=c b1=4
a2=e b2=1
a3=f b3=6
a4=1 b4=6
q0.out=61
l0,2=53
q0.in=ea
a0=e b0=a
a1=4 b1=b
a2=6 b2=6
a3=0 b3=5
a4=b b4=2
q0.out=2b
q0.in=3e
a0=3 b0=e
a1=d b1=c
a2=c b2=7
a3=b b3=7
a4=3 b4=e
q0.out=e3
l1,1=8a
q1.in=7f
a0=7 b0=f
a1=8 b1=0
a2=3 b2=1
a3=2 b3=3
a4=7 b4=1
q1.out=17
l0,1=8b
q1.in=44
a0=4 b0=4
a1=0 b1=6
a2=2 b2=3
a3=1 b3=b
a4=c b4=f
q1.out=fc
q1.in=46
a0=4 b0=6
a1=2 b1=7
a2=b b2=7
a3=c b3=8
a4=2 b4=6
q1.out=62
l1,0=18
q1.in=76
a0=7 b0=6
a1=1 b1=c
a2=8 b2=f
a3=7 b3=7
a4=a b4=e
q1.out=ea
l0,0=81
q0.in=36
a0=3 b0=6
a1=5 b1=8
a2=f b2=f
a3=0 b3=8
a4=b b4=9
q0.out=9b
q0.in=4d
a0=4 b0=d
a1=9 b1=a
a2=b b2=a
a3=1 b3=6
a4=a b4=6
q0.out=6a
l1,3=14
q0.in=72
a0=7 b0=2
a1=5 b1=e
a2=f b2=9
a3=6 b3=b
a4=9 b4=0
q0.out=09
l0,3=dc
q1.in=88
a0=8 b0=8
a1=0 b1=c
a2=2 b2=f
a3=d b3=d
a4=b b4=0
q1.out=0b
q1.in=07
a0=0 b0=7
a1=7 b1=b
a2=e b2=5
a3=b b3=4
a4=8 b4=c
q1.out=c8
l1,2=9c
q0.in=42
a0=4 b0=2
a1=6 b1=5
a2=3 b2=2
a3=1 b3=a
a4=a b4=3
q0.out=3a
l0,2=53
q0.in=b1
a0=b b0=1
a1=a b1=b
a2=5 b2=6
a3=3 b3=e
a4=e b4=c
q0.out=ce
q0.in=d0
a0=d b0=0
a1=d b1=5
a2=c b2=2
a3=e b3=d
a4=7 b4=5
q0.out=57
l1,1=8a
q1.in=cb
a0=c b0=b
a1=7 b1=1
a2=e b2=e
a3=0 b3=9
a4=4 b4=4
q1.out=44
l0,1=8b
q1.in=17
a0=1 b0=7
a1=6 b1=2
a2=6 b2=2
a3=4 b3=7
a4=1 b4=e
q1.out=e1
q1.in=01
a0=0 b0=1
a1=1 b1=8
a2=8 b2=6
a3=e b3=b
a4=3 b4=f
q1.out=f3
l1,0=18
q1.in=e7
a0=e b0=7
a1=9 b1=5
a2=1 b2=c
a3=d b3=f
a4=b b4=a
q1.out=ab
l0,0=81
q0.in=77
a0=7 b0=7
a1=0 b1=4
a2=8 b2=1
a3=9 b3=0
a4=8 b4=d
q0.out=d8
y0 = 89 y1 = 2b y2 = fc y3 = 9b y0 = 0b y1 = ce y2 = e1 y3 = d8
MDS input = Y = y0y1y2y3 = 892bfc9b MDS input = Y = y0y1y2y3 = 0bcee1d8
MDS output = Z = z0z1z2z3 = 77b998c4 MDS output = Z = z0z1z2z3 = 48567c31
z0 = 77 z1 = b9 z2 = 98 z3 = c4 z0 = 48 z1 = 56 z2 = 7c z3 = 31
T0 = g(R0) = 77b998c4 T1 = g(ROL(R1, 8)) = 48567c31
F6,0 = (T0 + T1 + K20) mod 232 = (77b998c4 + 48567c31 + 7b65df4c) mod 232
= (c498b977(big endian) + 317c5648(big endian) + 4cdf657b(big endian)) mod 232
= 42f4753a(big endian) = 3a75f442.
F6,1 = (T0 + 2T1 + K21) mod 232 = (77b998c4 + 2[48567c31] + 2189e236) mod 232
= (c498b977(big endian) + 2[317c5648(big endian)] + 36e28921(big endian)) mod 232
= (c498b977(big endian) + 62f8ac90(big endian) + 36e28921(big endian)) mod 232
= 5e73ef28(big endian) = 28ef735e.
R7,0  =  ROR(R6, 2    F6,0,1) =  ROR(e35f098a    3a75f442, 1)
=  ROR(d92afdc8, 1) =  ROR(c8fd2ad9(big endian), 1)
=  e47e956c(big endian) =  6c957ee4
R7,1  =  ROL(R6, 3,  1)    F6,1) =  ROL(0adee844,  1)    28ef735e
=  ROL(44e8de0a(big endian),  1)    28ef735e
=  89d1bc14(big endian)    28ef735e
=  14bcd189   28ef735e =  3c53a2d7.
R7,2 = R6,0 = b4343e46 R7,3 = R6,1 = 07d0014d

 

Encryption of block 1, round r=7
g input = X = x0x1x2x3 = R7,0 = 6c957ee4
g input = X = x0x1x2x3
= ROL(R7,1,  8) = ROL(3c53a2d7 ,  8)
= ROL(d7a2533c(big endian),  8)
= a2533cd7(big endian) = d73c53a2.
x0 = 6c x1 = 95 x2 = 7e x3 = e4 x0 = d7 x1 = 3c x2 = 53 x3 = a2
y2,0 = 6c y2,1 = 95 y2,2 = 7e y2,3 = e4 y2,0 = d7 y2,1 = 3c y2,2 = 53 y2,3 = a2
q0.in=6c
a0=6 b0=c
a1=a b1=0
a2=5 b2=e
a3=b b3=a
a4=3 b4=3
q0.out=33
l1,3=14
q0.in=2b
a0=2 b0=b
a1=9 b1=f
a2=b b2=d
a3=6 b3=d
a4=9 b4=5
q0.out=59
l0,3=dc
q1.in=d8
a0=d b0=8
a1=5 b1=1
a2=7 b2=e
a3=9 b3=8
a4=e b4=6
q1.out=6e
q1.in=95
a0=9 b0=5
a1=c b1=b
a2=0 b2=5
a3=5 b3=a
a4=6 b4=7
q1.out=76
l1,2=9c
q0.in=fc
a0=f b0=c
a1=3 b1=1
a2=d b2=c
a3=1 b3=3
a4=a b4=4
q0.out=4a
l0,2=53
q0.in=c1
a0=c b0=1
a1=d b1=4
a2=c b2=1
a3=d b3=4
a4=4 b4=1
q0.out=14
q0.in=7e
a0=7 b0=e
a1=9 b1=8
a2=b b2=f
a3=4 b3=c
a4=6 b4=8
q0.out=86
l1,1=8a
q1.in=1a
a0=1 b0=a
a1=b b1=c
a2=4 b2=f
a3=b b3=b
a4=8 b4=f
q1.out=f8
l0,1=8b
q1.in=ab
a0=a b0=b
a1=1 b1=7
a2=8 b2=7
a3=f b3=3
a4=f b4=1
q1.out=1f
q1.in=e4
a0=e b0=4
a1=a b1=c
a2=9 b2=f
a3=6 b3=e
a4=9 b4=8
q1.out=89
l1,0=18
q1.in=9d
a0=9 b0=d
a1=4 b1=f
a2=f b2=8
a3=7 b3=3
a4=a b4=1
q1.out=1a
l0,0=81
q0.in=c6
a0=c b0=6
a1=a b1=f
a2=5 b2=d
a3=8 b3=3
a4=c b4=4
q0.out=4c
q0.in=d7
a0=d b0=7
a1=a b1=e
a2=5 b2=9
a3=c b3=1
a4=2 b4=7
q0.out=72
l1,3=14
q0.in=6a
a0=6 b0=a
a1=c b1=3
a2=e b2=8
a3=6 b3=a
a4=9 b4=3
q0.out=39
l0,3=dc
q1.in=b8
a0=b b0=8
a1=3 b1=7
a2=d b2=7
a3=a b3=e
a4=d b4=8
q1.out=8d
q1.in=3c
a0=3 b0=c
a1=f b1=d
a2=5 b2=9
a3=c b3=1
a4=2 b4=9
q1.out=92
l1,2=9c
q0.in=18
a0=1 b0=8
a1=9 b1=d
a2=b b2=0
a3=b b3=3
a4=3 b4=4
q0.out=43
l0,2=53
q0.in=c8
a0=c b0=8
a1=4 b1=8
a2=6 b2=f
a3=9 b3=9
a4=8 b4=b
q0.out=b8
q0.in=53
a0=5 b0=3
a1=6 b1=4
a2=3 b2=1
a3=2 b3=3
a4=5 b4=4
q0.out=45
l1,1=8a
q1.in=d9
a0=d b0=9
a1=4 b1=9
a2=f b2=d
a3=2 b3=9
a4=7 b4=4
q1.out=47
l0,1=8b
q1.in=14
a0=1 b0=4
a1=5 b1=b
a2=7 b2=5
a3=2 b3=5
a4=7 b4=3
q1.out=37
q1.in=a2
a0=a b0=2
a1=8 b1=b
a2=3 b2=5
a3=6 b3=1
a4=9 b4=9
q1.out=99
l1,0=18
q1.in=8d
a0=8 b0=d
a1=5 b1=6
a2=7 b2=3
a3=4 b3=6
a4=1 b4=d
q1.out=d1
l0,0=81
q0.in=0d
a0=0 b0=d
a1=d b1=e
a2=c b2=9
a3=5 b3=0
a4=d b4=d
q0.out=dd
y0 = 6e y1 = 14 y2 = 1f y3 = 4c y0 = 8d y1 = b8 y2 = 37 y3 = dd
MDS input = Y = y0y1y2y3 = 6e141f4c MDS input = Y = y0y1y2y3 = 8db837dd
MDS output = Z = z0z1z2z3 = dcdb81f0 MDS output = Z = z0z1z2z3 = 2398cd75
z0 = dc z1 = db z2 = 81 z3 = f0 z0 = 23 z1 = 98 z2 = cd z3 = 75
T0 = g(R0) = dcdb81f0 T1 = g(ROL(R1, 8)) = 2398cd75
F7,0 = (T0 + T1 + K22) mod 232 = (dcdb81f0 + 2398cd75 + 25d0b3fc) mod 232
= (f081dbdc(big endian) + 75cd9823(big endian) + fcb3d025(big endian)) mod 232
= 63034424(big endian) = 24440363.
F7,1 = (T0 + 2T1 + K23) mod 232 = (dcdb81f0 + 2[2398cd75] + eb1e6ea6) mod 232
= (f081dbdc(big endian) + 2[75cd9823(big endian)] + a66e1eeb(big endian)) mod 232
= (f081dbdc(big endian) + eb9b3046(big endian) + a66e1eeb(big endian)) mod 232
= 828b2b0d(big endian) = 0d2b8b82.
R8,0  =  ROR(R7, 2    F7,0,1) =  ROR(b4343e46    24440363, 1)
=  ROR(90703d25, 1) =  ROR(253d7090(big endian), 1)
=  129eb848(big endian) =  48b89e12
R8,1  =  ROL(R7, 3,  1)    F7,1) =  ROL(07d0014d,  1)    0d2b8b82
=  ROL(4d01d007(big endian),  1)    0d2b8b82
=  9a03a00e(big endian)    0d2b8b82
=  0ea0039a   0d2b8b82 =  038b8818.
R8,2 = R7,0 = 6c957ee4 R8,3 = R7,1 = 3c53a2d7

 

Encryption of block 1, round r=8
g input = X = x0x1x2x3 = R8,0 = 48b89e12
g input = X = x0x1x2x3
= ROL(R8,1,  8) = ROL(038b8818 ,  8)
= ROL(18888b03(big endian),  8)
= 888b0318(big endian) = 18038b88.
x0 = 48 x1 = b8 x2 = 9e x3 = 12 x0 = 18 x1 = 03 x2 = 8b x3 = 88
y2,0 = 48 y2,1 = b8 y2,2 = 9e y2,3 = 12 y2,0 = 18 y2,1 = 03 y2,2 = 8b y2,3 = 88
q0.in=48
a0=4 b0=8
a1=c b1=0
a2=e b2=e
a3=0 b3=9
a4=b b4=b
q0.out=bb
l1,3=14
q0.in=a3
a0=a b0=3
a1=9 b1=3
a2=b b2=8
a3=3 b3=7
a4=e b4=e
q0.out=ee
l0,3=dc
q1.in=6f
a0=6 b0=f
a1=9 b1=9
a2=1 b2=d
a3=c b3=7
a4=2 b4=e
q1.out=e2
q1.in=b8
a0=b b0=8
a1=3 b1=7
a2=d b2=7
a3=a b3=e
a4=d b4=8
q1.out=8d
l1,2=9c
q0.in=07
a0=0 b0=7
a1=7 b1=b
a2=2 b2=6
a3=4 b3=1
a4=6 b4=7
q0.out=76
l0,2=53
q0.in=fd
a0=f b0=d
a1=2 b1=9
a2=7 b2=4
a3=3 b3=d
a4=e b4=5
q0.out=5e
q0.in=9e
a0=9 b0=e
a1=7 b1=6
a2=2 b2=3
a3=1 b3=b
a4=a b4=0
q0.out=0a
l1,1=8a
q1.in=96
a0=9 b0=6
a1=f b1=2
a2=5 b2=2
a3=7 b3=c
a4=a b4=2
q1.out=2a
l0,1=8b
q1.in=79
a0=7 b0=9
a1=e b1=3
a2=c b2=b
a3=7 b3=1
a4=a b4=9
q1.out=9a
q1.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=6
a3=b b3=6
a4=8 b4=d
q1.out=d8
l1,0=18
q1.in=cc
a0=c b0=c
a1=0 b1=a
a2=2 b2=a
a3=8 b3=7
a4=0 b4=e
q1.out=e0
l0,0=81
q0.in=3c
a0=3 b0=c
a1=f b1=d
a2=4 b2=0
a3=4 b3=4
a4=6 b4=1
q0.out=16
q0.in=18
a0=1 b0=8
a1=9 b1=d
a2=b b2=0
a3=b b3=3
a4=3 b4=4
q0.out=43
l1,3=14
q0.in=5b
a0=5 b0=b
a1=e b1=0
a2=a b2=e
a3=4 b3=d
a4=6 b4=5
q0.out=56
l0,3=dc
q1.in=d7
a0=d b0=7
a1=a b1=e
a2=9 b2=0
a3=9 b3=1
a4=e b4=9
q1.out=9e
q1.in=03
a0=0 b0=3
a1=3 b1=9
a2=d b2=d
a3=0 b3=b
a4=4 b4=f
q1.out=f4
l1,2=9c
q0.in=7e
a0=7 b0=e
a1=9 b1=8
a2=b b2=f
a3=4 b3=c
a4=6 b4=8
q0.out=86
l0,2=53
q0.in=0d
a0=0 b0=d
a1=d b1=e
a2=c b2=9
a3=5 b3=0
a4=d b4=d
q0.out=dd
q0.in=8b
a0=8 b0=b
a1=3 b1=5
a2=d b2=2
a3=f b3=4
a4=1 b4=1
q0.out=11
l1,1=8a
q1.in=8d
a0=8 b0=d
a1=5 b1=6
a2=7 b2=3
a3=4 b3=6
a4=1 b4=d
q1.out=d1
l0,1=8b
q1.in=82
a0=8 b0=2
a1=a b1=9
a2=9 b2=d
a3=4 b3=f
a4=1 b4=a
q1.out=a1
q1.in=88
a0=8 b0=8
a1=0 b1=c
a2=2 b2=f
a3=d b3=d
a4=b b4=0
q1.out=0b
l1,0=18
q1.in=1f
a0=1 b0=f
a1=e b1=6
a2=c b2=3
a3=f b3=5
a4=f b4=3
q1.out=3f
l0,0=81
q0.in=e3
a0=e b0=3
a1=d b1=7
a2=c b2=5
a3=9 b3=6
a4=8 b4=6
q0.out=68
y0 = e2 y1 = 5e y2 = 9a y3 = 16 y0 = 9e y1 = dd y2 = a1 y3 = 68
MDS input = Y = y0y1y2y3 = e25e9a16 MDS input = Y = y0y1y2y3 = 9edda168
MDS output = Z = z0z1z2z3 = 9fefd4a3 MDS output = Z = z0z1z2z3 = 553815da
z0 = 9f z1 = ef z2 = d4 z3 = a3 z0 = 55 z1 = 38 z2 = 15 z3 = da
T0 = g(R0) = 9fefd4a3 T1 = g(ROL(R1, 8)) = 553815da
F8,0 = (T0 + T1 + K24) mod 232 = (9fefd4a3 + 553815da + 97054619) mod 232
= (a3d4ef9f(big endian) + da153855(big endian) + 19460597(big endian)) mod 232
= 97302d8b(big endian) = 8b2d3097.
F8,1 = (T0 + 2T1 + K25) mod 232 = (9fefd4a3 + 2[553815da] + ccf7f077) mod 232
= (a3d4ef9f(big endian) + 2[da153855(big endian)] + 77f0f7cc(big endian)) mod 232
= (a3d4ef9f(big endian) + b42a70aa(big endian) + 77f0f7cc(big endian)) mod 232
= cff05815(big endian) = 1558f0cf.
R9,0  =  ROR(R8, 2    F8,0,1) =  ROR(6c957ee4    8b2d3097, 1)
=  ROR(e7b84e73, 1) =  ROR(734eb8e7(big endian), 1)
=  b9a75c73(big endian) =  735ca7b9
R9,1  =  ROL(R8, 3,  1)    F8,1) =  ROL(3c53a2d7,  1)    1558f0cf
=  ROL(d7a2533c(big endian),  1)    1558f0cf
=  af44a679(big endian)    1558f0cf
=  79a644af   1558f0cf =  6cfeb460.
R9,2 = R8,0 = 48b89e12 R9,3 = R8,1 = 038b8818

 

Encryption of block 1, round r=9
g input = X = x0x1x2x3 = R9,0 = 735ca7b9
g input = X = x0x1x2x3
= ROL(R9,1,  8) = ROL(6cfeb460 ,  8)
= ROL(60b4fe6c(big endian),  8)
= b4fe6c60(big endian) = 606cfeb4.
x0 = 73 x1 = 5c x2 = a7 x3 = b9 x0 = 60 x1 = 6c x2 = fe x3 = b4
y2,0 = 73 y2,1 = 5c y2,2 = a7 y2,3 = b9 y2,0 = 60 y2,1 = 6c y2,2 = fe y2,3 = b4
q0.in=73
a0=7 b0=3
a1=4 b1=6
a2=6 b2=3
a3=5 b3=f
a4=d b4=a
q0.out=ad
l1,3=14
q0.in=b5
a0=b b0=5
a1=e b1=9
a2=a b2=4
a3=e b3=8
a4=7 b4=9
q0.out=97
l0,3=dc
q1.in=16
a0=1 b0=6
a1=7 b1=a
a2=e b2=a
a3=4 b3=b
a4=1 b4=f
q1.out=f1
q1.in=5c
a0=5 b0=c
a1=9 b1=b
a2=1 b2=5
a3=4 b3=3
a4=1 b4=1
q1.out=11
l1,2=9c
q0.in=9b
a0=9 b0=b
a1=2 b1=c
a2=7 b2=7
a3=0 b3=4
a4=b b4=1
q0.out=1b
l0,2=53
q0.in=90
a0=9 b0=0
a1=9 b1=1
a2=b b2=c
a3=7 b3=5
a4=0 b4=2
q0.out=20
q0.in=a7
a0=a b0=7
a1=d b1=1
a2=c b2=c
a3=0 b3=a
a4=b b4=3
q0.out=3b
l1,1=8a
q1.in=a7
a0=a b0=7
a1=d b1=1
a2=a b2=e
a3=4 b3=d
a4=1 b4=0
q1.out=01
l0,1=8b
q1.in=52
a0=5 b0=2
a1=7 b1=c
a2=e b2=f
a3=1 b3=1
a4=c b4=9
q1.out=9c
q1.in=b9
a0=b b0=9
a1=2 b1=f
a2=b b2=8
a3=3 b3=7
a4=5 b4=e
q1.out=e5
l1,0=18
q1.in=f1
a0=f b0=1
a1=e b1=f
a2=c b2=8
a3=4 b3=8
a4=1 b4=6
q1.out=61
l0,0=81
q0.in=bd
a0=b b0=d
a1=6 b1=d
a2=3 b2=0
a3=3 b3=b
a4=e b4=0
q0.out=0e
q0.in=60
a0=6 b0=0
a1=6 b1=6
a2=3 b2=3
a3=0 b3=2
a4=b b4=f
q0.out=fb
l1,3=14
q0.in=e3
a0=e b0=3
a1=d b1=7
a2=c b2=5
a3=9 b3=6
a4=8 b4=6
q0.out=68
l0,3=dc
q1.in=e9
a0=e b0=9
a1=7 b1=2
a2=e b2=2
a3=c b3=f
a4=2 b4=a
q1.out=a2
q1.in=6c
a0=6 b0=c
a1=a b1=0
a2=9 b2=1
a3=8 b3=9
a4=0 b4=4
q1.out=40
l1,2=9c
q0.in=ca
a0=c b0=a
a1=6 b1=9
a2=3 b2=4
a3=7 b3=9
a4=0 b4=b
q0.out=b0
l0,2=53
q0.in=3b
a0=3 b0=b
a1=8 b1=6
a2=0 b2=3
a3=3 b3=9
a4=e b4=b
q0.out=be
q0.in=fe
a0=f b0=e
a1=1 b1=0
a2=1 b2=e
a3=f b3=e
a4=1 b4=c
q0.out=c1
l1,1=8a
q1.in=5d
a0=5 b0=d
a1=8 b1=3
a2=3 b2=b
a3=8 b3=6
a4=0 b4=d
q1.out=d0
l0,1=8b
q1.in=83
a0=8 b0=3
a1=b b1=1
a2=4 b2=e
a3=a b3=3
a4=d b4=1
q1.out=1d
q1.in=b4
a0=b b0=4
a1=f b1=1
a2=5 b2=e
a3=b b3=a
a4=8 b4=7
q1.out=78
l1,0=18
q1.in=6c
a0=6 b0=c
a1=a b1=0
a2=9 b2=1
a3=8 b3=9
a4=0 b4=4
q1.out=40
l0,0=81
q0.in=9c
a0=9 b0=c
a1=5 b1=7
a2=f b2=5
a3=a b3=d
a4=f b4=5
q0.out=5f
y0 = f1 y1 = 20 y2 = 9c y3 = 0e y0 = a2 y1 = be y2 = 1d y3 = 5f
MDS input = Y = y0y1y2y3 = f1209c0e MDS input = Y = y0y1y2y3 = a2be1d5f
MDS output = Z = z0z1z2z3 = cb545137 MDS output = Z = z0z1z2z3 = 3ee16a8d
z0 = cb z1 = 54 z2 = 51 z3 = 37 z0 = 3e z1 = e1 z2 = 6a z3 = 8d
T0 = g(R0) = cb545137 T1 = g(ROL(R1, 8)) = 3ee16a8d
F9,0 = (T0 + T1 + K26) mod 232 = (cb545137 + 3ee16a8d + d5b22d8a) mod 232
= (375154cb(big endian) + 8d6ae13e(big endian) + 8a2db2d5(big endian)) mod 232
= 4ee9e8de(big endian) = dee8e94e.
F9,1 = (T0 + 2T1 + K27) mod 232 = (cb545137 + 2[3ee16a8d] + 66325910) mod 232
= (375154cb(big endian) + 2[8d6ae13e(big endian)] + 10593266(big endian)) mod 232
= (375154cb(big endian) + 1ad5c27c(big endian) + 10593266(big endian)) mod 232
= 628049ad(big endian) = ad498062.
R10,0  =  ROR(R9, 2    F9,0,1) =  ROR(48b89e12    dee8e94e, 1)
=  ROR(9650775c, 1) =  ROR(5c775096(big endian), 1)
=  2e3ba84b(big endian) =  4ba83b2e
R10,1  =  ROL(R9, 3,  1)    F9,1) =  ROL(038b8818,  1)    ad498062
=  ROL(18888b03(big endian),  1)    ad498062
=  31111606(big endian)    ad498062
=  06161131   ad498062 =  ab5f9153.
R10,2 = R9,0 = 735ca7b9 R10,3 = R9,1 = 6cfeb460

 

Encryption of block 1, round r=10
g input = X = x0x1x2x3 = R10,0 = 4ba83b2e
g input = X = x0x1x2x3
= ROL(R10,1,  8) = ROL(ab5f9153 ,  8)
= ROL(53915fab(big endian),  8)
= 915fab53(big endian) = 53ab5f91.
x0 = 4b x1 = a8 x2 = 3b x3 = 2e x0 = 53 x1 = ab x2 = 5f x3 = 91
y2,0 = 4b y2,1 = a8 y2,2 = 3b y2,3 = 2e y2,0 = 53 y2,1 = ab y2,2 = 5f y2,3 = 91
q0.in=4b
a0=4 b0=b
a1=f b1=9
a2=4 b2=4
a3=0 b3=6
a4=b b4=6
q0.out=6b
l1,3=14
q0.in=73
a0=7 b0=3
a1=4 b1=6
a2=6 b2=3
a3=5 b3=f
a4=d b4=a
q0.out=ad
l0,3=dc
q1.in=2c
a0=2 b0=c
a1=e b1=4
a2=c b2=4
a3=8 b3=e
a4=0 b4=8
q1.out=80
q1.in=a8
a0=a b0=8
a1=2 b1=e
a2=b b2=0
a3=b b3=3
a4=8 b4=1
q1.out=18
l1,2=9c
q0.in=92
a0=9 b0=2
a1=b b1=0
a2=9 b2=e
a3=7 b3=6
a4=0 b4=6
q0.out=60
l0,2=53
q0.in=eb
a0=e b0=b
a1=5 b1=3
a2=f b2=8
a3=7 b3=3
a4=0 b4=4
q0.out=40
q0.in=3b
a0=3 b0=b
a1=8 b1=6
a2=0 b2=3
a3=3 b3=9
a4=e b4=b
q0.out=be
l1,1=8a
q1.in=22
a0=2 b0=2
a1=0 b1=3
a2=2 b2=b
a3=9 b3=f
a4=e b4=a
q1.out=ae
l0,1=8b
q1.in=fd
a0=f b0=d
a1=2 b1=9
a2=b b2=d
a3=6 b3=d
a4=9 b4=0
q1.out=09
q1.in=2e
a0=2 b0=e
a1=c b1=5
a2=0 b2=c
a3=c b3=6
a4=2 b4=d
q1.out=d2
l1,0=18
q1.in=c6
a0=c b0=6
a1=a b1=f
a2=9 b2=8
a3=1 b3=5
a4=c b4=3
q1.out=3c
l0,0=81
q0.in=e0
a0=e b0=0
a1=e b1=e
a2=a b2=9
a3=3 b3=6
a4=e b4=6
q0.out=6e
q0.in=53
a0=5 b0=3
a1=6 b1=4
a2=3 b2=1
a3=2 b3=3
a4=5 b4=4
q0.out=45
l1,3=14
q0.in=5d
a0=5 b0=d
a1=8 b1=3
a2=0 b2=8
a3=8 b3=4
a4=c b4=1
q0.out=1c
l0,3=dc
q1.in=9d
a0=9 b0=d
a1=4 b1=f
a2=f b2=8
a3=7 b3=3
a4=a b4=1
q1.out=1a
q1.in=ab
a0=a b0=b
a1=1 b1=7
a2=8 b2=7
a3=f b3=3
a4=f b4=1
q1.out=1f
l1,2=9c
q0.in=95
a0=9 b0=5
a1=c b1=b
a2=e b2=6
a3=8 b3=d
a4=c b4=5
q0.out=5c
l0,2=53
q0.in=d7
a0=d b0=7
a1=a b1=e
a2=5 b2=9
a3=c b3=1
a4=2 b4=7
q0.out=72
q0.in=5f
a0=5 b0=f
a1=a b1=2
a2=5 b2=b
a3=e b3=0
a4=7 b4=d
q0.out=d7
l1,1=8a
q1.in=4b
a0=4 b0=b
a1=f b1=9
a2=5 b2=d
a3=8 b3=3
a4=0 b4=1
q1.out=10
l0,1=8b
q1.in=43
a0=4 b0=3
a1=7 b1=d
a2=e b2=9
a3=7 b3=2
a4=a b4=5
q1.out=5a
q1.in=91
a0=9 b0=1
a1=8 b1=9
a2=3 b2=d
a3=e b3=5
a4=3 b4=3
q1.out=33
l1,0=18
q1.in=27
a0=2 b0=7
a1=5 b1=9
a2=7 b2=d
a3=a b3=1
a4=d b4=9
q1.out=9d
l0,0=81
q0.in=41
a0=4 b0=1
a1=5 b1=c
a2=f b2=7
a3=8 b3=c
a4=c b4=8
q0.out=8c
y0 = 80 y1 = 40 y2 = 09 y3 = 6e y0 = 1a y1 = 72 y2 = 5a y3 = 8c
MDS input = Y = y0y1y2y3 = 8040096e MDS input = Y = y0y1y2y3 = 1a725a8c
MDS output = Z = z0z1z2z3 = 605f4f80 MDS output = Z = z0z1z2z3 = ae12ccad
z0 = 60 z1 = 5f z2 = 4f z3 = 80 z0 = ae z1 = 12 z2 = cc z3 = ad
T0 = g(R0) = 605f4f80 T1 = g(ROL(R1, 8)) = ae12ccad
F10,0 = (T0 + T1 + K28) mod 232 = (605f4f80 + ae12ccad + fdcb3639) mod 232
= (804f5f60(big endian) + adcc12ae(big endian) + 3936cbfd(big endian)) mod 232
= 67523e0b(big endian) = 0b3e5267.
F10,1 = (T0 + 2T1 + K29) mod 232 = (605f4f80 + 2[ae12ccad] + d853ba91) mod 232
= (804f5f60(big endian) + 2[adcc12ae(big endian)] + 91ba53d8(big endian)) mod 232
= (804f5f60(big endian) + 5b98255c(big endian) + 91ba53d8(big endian)) mod 232
= 6da1d894(big endian) = 94d8a16d.
R11,0  =  ROR(R10, 2    F10,0,1) =  ROR(735ca7b9    0b3e5267, 1)
=  ROR(7862f5de, 1) =  ROR(def56278(big endian), 1)
=  6f7ab13c(big endian) =  3cb17a6f
R11,1  =  ROL(R10, 3,  1)    F10,1) =  ROL(6cfeb460,  1)    94d8a16d
=  ROL(60b4fe6c(big endian),  1)    94d8a16d
=  c169fcd8(big endian)    94d8a16d
=  d8fc69c1   94d8a16d =  4c24c8ac.
R11,2 = R10,0 = 4ba83b2e R11,3 = R10,1 = ab5f9153

 

Encryption of block 1, round r=11
g input = X = x0x1x2x3 = R11,0 = 3cb17a6f
g input = X = x0x1x2x3
= ROL(R11,1,  8) = ROL(4c24c8ac ,  8)
= ROL(acc8244c(big endian),  8)
= c8244cac(big endian) = ac4c24c8.
x0 = 3c x1 = b1 x2 = 7a x3 = 6f x0 = ac x1 = 4c x2 = 24 x3 = c8
y2,0 = 3c y2,1 = b1 y2,2 = 7a y2,3 = 6f y2,0 = ac y2,1 = 4c y2,2 = 24 y2,3 = c8
q0.in=3c
a0=3 b0=c
a1=f b1=d
a2=4 b2=0
a3=4 b3=4
a4=6 b4=1
q0.out=16
l1,3=14
q0.in=0e
a0=0 b0=e
a1=e b1=7
a2=a b2=5
a3=f b3=0
a4=1 b4=d
q0.out=d1
l0,3=dc
q1.in=50
a0=5 b0=0
a1=5 b1=d
a2=7 b2=9
a3=e b3=3
a4=3 b4=1
q1.out=13
q1.in=b1
a0=b b0=1
a1=a b1=b
a2=9 b2=5
a3=c b3=b
a4=2 b4=f
q1.out=f2
l1,2=9c
q0.in=78
a0=7 b0=8
a1=f b1=b
a2=4 b2=6
a3=2 b3=7
a4=5 b4=e
q0.out=e5
l0,2=53
q0.in=6e
a0=6 b0=e
a1=8 b1=1
a2=0 b2=c
a3=c b3=6
a4=2 b4=6
q0.out=62
q0.in=7a
a0=7 b0=a
a1=d b1=a
a2=c b2=a
a3=6 b3=9
a4=9 b4=b
q0.out=b9
l1,1=8a
q1.in=25
a0=2 b0=5
a1=7 b1=8
a2=e b2=6
a3=8 b3=d
a4=0 b4=0
q1.out=00
l0,1=8b
q1.in=53
a0=5 b0=3
a1=6 b1=4
a2=6 b2=4
a3=2 b3=4
a4=7 b4=c
q1.out=c7
q1.in=6f
a0=6 b0=f
a1=9 b1=9
a2=1 b2=d
a3=c b3=7
a4=2 b4=e
q1.out=e2
l1,0=18
q1.in=f6
a0=f b0=6
a1=9 b1=4
a2=1 b2=4
a3=5 b3=b
a4=6 b4=f
q1.out=f6
l0,0=81
q0.in=2a
a0=2 b0=a
a1=8 b1=7
a2=0 b2=5
a3=5 b3=a
a4=d b4=3
q0.out=3d
q0.in=ac
a0=a b0=c
a1=6 b1=c
a2=3 b2=7
a3=4 b3=0
a4=6 b4=d
q0.out=d6
l1,3=14
q0.in=ce
a0=c b0=e
a1=2 b1=b
a2=7 b2=6
a3=1 b3=c
a4=a b4=8
q0.out=8a
l0,3=dc
q1.in=0b
a0=0 b0=b
a1=b b1=d
a2=4 b2=9
a3=d b3=8
a4=b b4=6
q1.out=6b
q1.in=4c
a0=4 b0=c
a1=8 b1=2
a2=3 b2=2
a3=1 b3=a
a4=c b4=7
q1.out=7c
l1,2=9c
q0.in=f6
a0=f b0=6
a1=9 b1=4
a2=b b2=1
a3=a b3=b
a4=f b4=0
q0.out=0f
l0,2=53
q0.in=84
a0=8 b0=4
a1=c b1=a
a2=e b2=a
a3=4 b3=b
a4=6 b4=0
q0.out=06
q0.in=24
a0=2 b0=4
a1=6 b1=0
a2=3 b2=e
a3=d b3=c
a4=4 b4=8
q0.out=84
l1,1=8a
q1.in=18
a0=1 b0=8
a1=9 b1=d
a2=1 b2=9
a3=8 b3=5
a4=0 b4=3
q1.out=30
l0,1=8b
q1.in=63
a0=6 b0=3
a1=5 b1=f
a2=7 b2=8
a3=f b3=b
a4=f b4=f
q1.out=ff
q1.in=c8
a0=c b0=8
a1=4 b1=8
a2=f b2=6
a3=9 b3=4
a4=e b4=c
q1.out=ce
l1,0=18
q1.in=da
a0=d b0=a
a1=7 b1=0
a2=e b2=1
a3=f b3=6
a4=f b4=d
q1.out=df
l0,0=81
q0.in=03
a0=0 b0=3
a1=3 b1=9
a2=d b2=4
a3=9 b3=7
a4=8 b4=e
q0.out=e8
y0 = 13 y1 = 62 y2 = c7 y3 = 3d y0 = 6b y1 = 06 y2 = ff y3 = e8
MDS input = Y = y0y1y2y3 = 1362c73d MDS input = Y = y0y1y2y3 = 6b06ffe8
MDS output = Z = z0z1z2z3 = 9cf48f81 MDS output = Z = z0z1z2z3 = 2722f42f
z0 = 9c z1 = f4 z2 = 8f z3 = 81 z0 = 27 z1 = 22 z2 = f4 z3 = 2f
T0 = g(R0) = 9cf48f81 T1 = g(ROL(R1, 8)) = 2722f42f
F11,0 = (T0 + T1 + K30) mod 232 = (9cf48f81 + 2722f42f + fd2d59b8) mod 232
= (818ff49c(big endian) + 2ff42227(big endian) + b8592dfd(big endian)) mod 232
= 69dd44c0(big endian) = c044dd69.
F11,1 = (T0 + 2T1 + K31) mod 232 = (9cf48f81 + 2[2722f42f] + 9c51af49) mod 232
= (818ff49c(big endian) + 2[2ff42227(big endian)] + 49af519c(big endian)) mod 232
= (818ff49c(big endian) + 5fe8444e(big endian) + 49af519c(big endian)) mod 232
= 2b278a86(big endian) = 868a272b.
R12,0  =  ROR(R11, 2    F11,0,1) =  ROR(4ba83b2e    c044dd69, 1)
=  ROR(8bece647, 1) =  ROR(47e6ec8b(big endian), 1)
=  a3f37645(big endian) =  4576f3a3
R12,1  =  ROL(R11, 3,  1)    F11,1) =  ROL(ab5f9153,  1)    868a272b
=  ROL(53915fab(big endian),  1)    868a272b
=  a722bf56(big endian)    868a272b
=  56bf22a7   868a272b =  d035058c.
R12,2 = R11,0 = 3cb17a6f R12,3 = R11,1 = 4c24c8ac

 

Encryption of block 1, round r=12
g input = X = x0x1x2x3 = R12,0 = 4576f3a3
g input = X = x0x1x2x3
= ROL(R12,1,  8) = ROL(d035058c ,  8)
= ROL(8c0535d0(big endian),  8)
= 0535d08c(big endian) = 8cd03505.
x0 = 45 x1 = 76 x2 = f3 x3 = a3 x0 = 8c x1 = d0 x2 = 35 x3 = 05
y2,0 = 45 y2,1 = 76 y2,2 = f3 y2,3 = a3 y2,0 = 8c y2,1 = d0 y2,2 = 35 y2,3 = 05
q0.in=45
a0=4 b0=5
a1=1 b1=e
a2=1 b2=9
a3=8 b3=5
a4=c b4=2
q0.out=2c
l1,3=14
q0.in=34
a0=3 b0=4
a1=7 b1=9
a2=2 b2=4
a3=6 b3=0
a4=9 b4=d
q0.out=d9
l0,3=dc
q1.in=58
a0=5 b0=8
a1=d b1=9
a2=a b2=d
a3=7 b3=4
a4=a b4=c
q1.out=ca
q1.in=76
a0=7 b0=6
a1=1 b1=c
a2=8 b2=f
a3=7 b3=7
a4=a b4=e
q1.out=ea
l1,2=9c
q0.in=60
a0=6 b0=0
a1=6 b1=6
a2=3 b2=3
a3=0 b3=2
a4=b b4=f
q0.out=fb
l0,2=53
q0.in=70
a0=7 b0=0
a1=7 b1=f
a2=2 b2=d
a3=f b3=c
a4=1 b4=8
q0.out=81
q0.in=f3
a0=f b0=3
a1=c b1=e
a2=e b2=9
a3=7 b3=2
a4=0 b4=f
q0.out=f0
l1,1=8a
q1.in=6c
a0=6 b0=c
a1=a b1=0
a2=9 b2=1
a3=8 b3=9
a4=0 b4=4
q1.out=40
l0,1=8b
q1.in=13
a0=1 b0=3
a1=2 b1=0
a2=b b2=1
a3=a b3=b
a4=d b4=f
q1.out=fd
q1.in=a3
a0=a b0=3
a1=9 b1=3
a2=1 b2=b
a3=a b3=4
a4=d b4=c
q1.out=cd
l1,0=18
q1.in=d9
a0=d b0=9
a1=4 b1=9
a2=f b2=d
a3=2 b3=9
a4=7 b4=4
q1.out=47
l0,0=81
q0.in=9b
a0=9 b0=b
a1=2 b1=c
a2=7 b2=7
a3=0 b3=4
a4=b b4=1
q0.out=1b
q0.in=8c
a0=8 b0=c
a1=4 b1=e
a2=6 b2=9
a3=f b3=a
a4=1 b4=3
q0.out=31
l1,3=14
q0.in=29
a0=2 b0=9
a1=b b1=e
a2=9 b2=9
a3=0 b3=d
a4=b b4=5
q0.out=5b
l0,3=dc
q1.in=da
a0=d b0=a
a1=7 b1=0
a2=e b2=1
a3=f b3=6
a4=f b4=d
q1.out=df
q1.in=d0
a0=d b0=0
a1=d b1=5
a2=a b2=c
a3=6 b3=c
a4=9 b4=2
q1.out=29
l1,2=9c
q0.in=a3
a0=a b0=3
a1=9 b1=3
a2=b b2=8
a3=3 b3=7
a4=e b4=e
q0.out=ee
l0,2=53
q0.in=65
a0=6 b0=5
a1=3 b1=c
a2=d b2=7
a3=a b3=e
a4=f b4=c
q0.out=cf
q0.in=35
a0=3 b0=5
a1=6 b1=1
a2=3 b2=c
a3=f b3=d
a4=1 b4=5
q0.out=51
l1,1=8a
q1.in=cd
a0=c b0=d
a1=1 b1=2
a2=8 b2=2
a3=a b3=9
a4=d b4=4
q1.out=4d
l0,1=8b
q1.in=1e
a0=1 b0=e
a1=f b1=e
a2=5 b2=0
a3=5 b3=d
a4=6 b4=0
q1.out=06
q1.in=05
a0=0 b0=5
a1=5 b1=a
a2=7 b2=a
a3=d b3=a
a4=b b4=7
q1.out=7b
l1,0=18
q1.in=6f
a0=6 b0=f
a1=9 b1=9
a2=1 b2=d
a3=c b3=7
a4=2 b4=e
q1.out=e2
l0,0=81
q0.in=3e
a0=3 b0=e
a1=d b1=c
a2=c b2=7
a3=b b3=7
a4=3 b4=e
q0.out=e3
y0 = ca y1 = 81 y2 = fd y3 = 1b y0 = df y1 = cf y2 = 06 y3 = e3
MDS input = Y = y0y1y2y3 = ca81fd1b MDS input = Y = y0y1y2y3 = dfcf06e3
MDS output = Z = z0z1z2z3 = ae0a6509 MDS output = Z = z0z1z2z3 = 98943997
z0 = ae z1 = 0a z2 = 65 z3 = 09 z0 = 98 z1 = 94 z2 = 39 z3 = 97
T0 = g(R0) = ae0a6509 T1 = g(ROL(R1, 8)) = 98943997
F12,0 = (T0 + T1 + K32) mod 232 = (ae0a6509 + 98943997 + 165703a2) mod 232
= (09650aae(big endian) + 97399498(big endian) + a2035716(big endian)) mod 232
= 42a1f65c(big endian) = 5cf6a142.
F12,1 = (T0 + 2T1 + K33) mod 232 = (ae0a6509 + 2[98943997] + bdabf862) mod 232
= (09650aae(big endian) + 2[97399498(big endian)] + 62f8abbd(big endian)) mod 232
= (09650aae(big endian) + 2e732930(big endian) + 62f8abbd(big endian)) mod 232
= 9ad0df9b(big endian) = 9bdfd09a.
R13,0  =  ROR(R12, 2    F12,0,1) =  ROR(3cb17a6f    5cf6a142, 1)
=  ROR(6047db2d, 1) =  ROR(2ddb4760(big endian), 1)
=  16eda3b0(big endian) =  b0a3ed16
R13,1  =  ROL(R12, 3,  1)    F12,1) =  ROL(4c24c8ac,  1)    9bdfd09a
=  ROL(acc8244c(big endian),  1)    9bdfd09a
=  59904899(big endian)    9bdfd09a
=  99489059   9bdfd09a =  029740c3.
R13,2 = R12,0 = 4576f3a3 R13,3 = R12,1 = d035058c

 

Encryption of block 1, round r=13
g input = X = x0x1x2x3 = R13,0 = b0a3ed16
g input = X = x0x1x2x3
= ROL(R13,1,  8) = ROL(029740c3 ,  8)
= ROL(c3409702(big endian),  8)
= 409702c3(big endian) = c3029740.
x0 = b0 x1 = a3 x2 = ed x3 = 16 x0 = c3 x1 = 02 x2 = 97 x3 = 40
y2,0 = b0 y2,1 = a3 y2,2 = ed y2,3 = 16 y2,0 = c3 y2,1 = 02 y2,2 = 97 y2,3 = 40
q0.in=b0
a0=b b0=0
a1=b b1=3
a2=9 b2=8
a3=1 b3=5
a4=a b4=2
q0.out=2a
l1,3=14
q0.in=32
a0=3 b0=2
a1=1 b1=a
a2=1 b2=a
a3=b b3=c
a4=3 b4=8
q0.out=83
l0,3=dc
q1.in=02
a0=0 b0=2
a1=2 b1=1
a2=b b2=e
a3=5 b3=4
a4=6 b4=c
q1.out=c6
q1.in=a3
a0=a b0=3
a1=9 b1=3
a2=1 b2=b
a3=a b3=4
a4=d b4=c
q1.out=cd
l1,2=9c
q0.in=47
a0=4 b0=7
a1=3 b1=f
a2=d b2=d
a3=0 b3=b
a4=b b4=0
q0.out=0b
l0,2=53
q0.in=80
a0=8 b0=0
a1=8 b1=8
a2=0 b2=f
a3=f b3=f
a4=1 b4=a
q0.out=a1
q0.in=ed
a0=e b0=d
a1=3 b1=0
a2=d b2=e
a3=3 b3=2
a4=e b4=f
q0.out=fe
l1,1=8a
q1.in=62
a0=6 b0=2
a1=4 b1=7
a2=f b2=7
a3=8 b3=c
a4=0 b4=2
q1.out=20
l0,1=8b
q1.in=73
a0=7 b0=3
a1=4 b1=6
a2=f b2=3
a3=c b3=e
a4=2 b4=8
q1.out=82
q1.in=16
a0=1 b0=6
a1=7 b1=a
a2=e b2=a
a3=4 b3=b
a4=1 b4=f
q1.out=f1
l1,0=18
q1.in=e5
a0=e b0=5
a1=b b1=4
a2=4 b2=4
a3=0 b3=6
a4=4 b4=d
q1.out=d4
l0,0=81
q0.in=08
a0=0 b0=8
a1=8 b1=4
a2=0 b2=1
a3=1 b3=8
a4=a b4=9
q0.out=9a
q0.in=c3
a0=c b0=3
a1=f b1=5
a2=4 b2=2
a3=6 b3=5
a4=9 b4=2
q0.out=29
l1,3=14
q0.in=31
a0=3 b0=1
a1=2 b1=3
a2=7 b2=8
a3=f b3=b
a4=1 b4=0
q0.out=01
l0,3=dc
q1.in=80
a0=8 b0=0
a1=8 b1=8
a2=3 b2=6
a3=5 b3=8
a4=6 b4=6
q1.out=66
q1.in=02
a0=0 b0=2
a1=2 b1=1
a2=b b2=e
a3=5 b3=4
a4=6 b4=c
q1.out=c6
l1,2=9c
q0.in=4c
a0=4 b0=c
a1=8 b1=2
a2=0 b2=b
a3=b b3=d
a4=3 b4=5
q0.out=53
l0,2=53
q0.in=d8
a0=d b0=8
a1=5 b1=1
a2=f b2=c
a3=3 b3=1
a4=e b4=7
q0.out=7e
q0.in=97
a0=9 b0=7
a1=e b1=a
a2=a b2=a
a3=0 b3=f
a4=b b4=a
q0.out=ab
l1,1=8a
q1.in=37
a0=3 b0=7
a1=4 b1=0
a2=f b2=1
a3=e b3=f
a4=3 b4=a
q1.out=a3
l0,1=8b
q1.in=f0
a0=f b0=0
a1=f b1=7
a2=5 b2=7
a3=2 b3=6
a4=7 b4=d
q1.out=d7
q1.in=40
a0=4 b0=0
a1=4 b1=4
a2=f b2=4
a3=b b3=5
a4=8 b4=3
q1.out=38
l1,0=18
q1.in=2c
a0=2 b0=c
a1=e b1=4
a2=c b2=4
a3=8 b3=e
a4=0 b4=8
q1.out=80
l0,0=81
q0.in=5c
a0=5 b0=c
a1=9 b1=b
a2=b b2=6
a3=d b3=0
a4=4 b4=d
q0.out=d4
y0 = c6 y1 = a1 y2 = 82 y3 = 9a y0 = 66 y1 = 7e y2 = d7 y3 = d4
MDS input = Y = y0y1y2y3 = c6a1829a MDS input = Y = y0y1y2y3 = 667ed7d4
MDS output = Z = z0z1z2z3 = efb934de MDS output = Z = z0z1z2z3 = 612671b4
z0 = ef z1 = b9 z2 = 34 z3 = de z0 = 61 z1 = 26 z2 = 71 z3 = b4
T0 = g(R0) = efb934de T1 = g(ROL(R1, 8)) = 612671b4
F13,0 = (T0 + T1 + K34) mod 232 = (efb934de + 612671b4 + 6ae813f4) mod 232
= (de34b9ef(big endian) + b4712661(big endian) + f413e86a(big endian)) mod 232
= 86b9c8ba(big endian) = bac8b986.
F13,1 = (T0 + 2T1 + K35) mod 232 = (efb934de + 2[612671b4] + f3d8d036) mod 232
= (de34b9ef(big endian) + 2[b4712661(big endian)] + 36d0d8f3(big endian)) mod 232
= (de34b9ef(big endian) + 68e24cc2(big endian) + 36d0d8f3(big endian)) mod 232
= 7de7dfa4(big endian) = a4dfe77d.
R14,0  =  ROR(R13, 2    F13,0,1) =  ROR(4576f3a3    bac8b986, 1)
=  ROR(ffbe4a25, 1) =  ROR(254abeff(big endian), 1)
=  92a55f7f(big endian) =  7f5fa592
R14,1  =  ROL(R13, 3,  1)    F13,1) =  ROL(d035058c,  1)    a4dfe77d
=  ROL(8c0535d0(big endian),  1)    a4dfe77d
=  180a6ba1(big endian)    a4dfe77d
=  a16b0a18   a4dfe77d =  05b4ed65.
R14,2 = R13,0 = b0a3ed16 R14,3 = R13,1 = 029740c3

 

Encryption of block 1, round r=14
g input = X = x0x1x2x3 = R14,0 = 7f5fa592
g input = X = x0x1x2x3
= ROL(R14,1,  8) = ROL(05b4ed65 ,  8)
= ROL(65edb405(big endian),  8)
= edb40565(big endian) = 6505b4ed.
x0 = 7f x1 = 5f x2 = a5 x3 = 92 x0 = 65 x1 = 05 x2 = b4 x3 = ed
y2,0 = 7f y2,1 = 5f y2,2 = a5 y2,3 = 92 y2,0 = 65 y2,1 = 05 y2,2 = b4 y2,3 = ed
q0.in=7f
a0=7 b0=f
a1=8 b1=0
a2=0 b2=e
a3=e b3=7
a4=7 b4=e
q0.out=e7
l1,3=14
q0.in=ff
a0=f b0=f
a1=0 b1=8
a2=8 b2=f
a3=7 b3=7
a4=0 b4=e
q0.out=e0
l0,3=dc
q1.in=61
a0=6 b0=1
a1=7 b1=e
a2=e b2=0
a3=e b3=e
a4=3 b4=8
q1.out=83
q1.in=5f
a0=5 b0=f
a1=a b1=2
a2=9 b2=2
a3=b b3=0
a4=8 b4=b
q1.out=b8
l1,2=9c
q0.in=32
a0=3 b0=2
a1=1 b1=a
a2=1 b2=a
a3=b b3=c
a4=3 b4=8
q0.out=83
l0,2=53
q0.in=08
a0=0 b0=8
a1=8 b1=4
a2=0 b2=1
a3=1 b3=8
a4=a b4=9
q0.out=9a
q0.in=a5
a0=a b0=5
a1=f b1=0
a2=4 b2=e
a3=a b3=3
a4=f b4=4
q0.out=4f
l1,1=8a
q1.in=d3
a0=d b0=3
a1=e b1=c
a2=c b2=f
a3=3 b3=3
a4=5 b4=1
q1.out=15
l0,1=8b
q1.in=46
a0=4 b0=6
a1=2 b1=7
a2=b b2=7
a3=c b3=8
a4=2 b4=6
q1.out=62
q1.in=92
a0=9 b0=2
a1=b b1=0
a2=4 b2=1
a3=5 b3=c
a4=6 b4=2
q1.out=26
l1,0=18
q1.in=32
a0=3 b0=2
a1=1 b1=a
a2=8 b2=a
a3=2 b3=d
a4=7 b4=0
q1.out=07
l0,0=81
q0.in=db
a0=d b0=b
a1=6 b1=8
a2=3 b2=f
a3=c b3=4
a4=2 b4=1
q0.out=12
q0.in=65
a0=6 b0=5
a1=3 b1=c
a2=d b2=7
a3=a b3=e
a4=f b4=c
q0.out=cf
l1,3=14
q0.in=d7
a0=d b0=7
a1=a b1=e
a2=5 b2=9
a3=c b3=1
a4=2 b4=7
q0.out=72
l0,3=dc
q1.in=f3
a0=f b0=3
a1=c b1=e
a2=0 b2=0
a3=0 b3=0
a4=4 b4=b
q1.out=b4
q1.in=05
a0=0 b0=5
a1=5 b1=a
a2=7 b2=a
a3=d b3=a
a4=b b4=7
q1.out=7b
l1,2=9c
q0.in=f1
a0=f b0=1
a1=e b1=f
a2=a b2=d
a3=7 b3=4
a4=0 b4=1
q0.out=10
l0,2=53
q0.in=9b
a0=9 b0=b
a1=2 b1=c
a2=7 b2=7
a3=0 b3=4
a4=b b4=1
q0.out=1b
q0.in=b4
a0=b b0=4
a1=f b1=1
a2=4 b2=c
a3=8 b3=2
a4=c b4=f
q0.out=fc
l1,1=8a
q1.in=60
a0=6 b0=0
a1=6 b1=6
a2=6 b2=3
a3=5 b3=f
a4=6 b4=a
q1.out=a6
l0,1=8b
q1.in=f5
a0=f b0=5
a1=a b1=d
a2=9 b2=9
a3=0 b3=d
a4=4 b4=0
q1.out=04
q1.in=ed
a0=e b0=d
a1=3 b1=0
a2=d b2=1
a3=c b3=d
a4=2 b4=0
q1.out=02
l1,0=18
q1.in=16
a0=1 b0=6
a1=7 b1=a
a2=e b2=a
a3=4 b3=b
a4=1 b4=f
q1.out=f1
l0,0=81
q0.in=2d
a0=2 b0=d
a1=f b1=c
a2=4 b2=7
a3=3 b3=f
a4=e b4=a
q0.out=ae
y0 = 83 y1 = 9a y2 = 62 y3 = 12 y0 = b4 y1 = 1b y2 = 04 y3 = ae
MDS input = Y = y0y1y2y3 = 839a6212 MDS input = Y = y0y1y2y3 = b41b04ae
MDS output = Z = z0z1z2z3 = aae5797f MDS output = Z = z0z1z2z3 = ca7a52ee
z0 = aa z1 = e5 z2 = 79 z3 = 7f z0 = ca z1 = 7a z2 = 52 z3 = ee
T0 = g(R0) = aae5797f T1 = g(ROL(R1, 8)) = ca7a52ee
F14,0 = (T0 + T1 + K36) mod 232 = (aae5797f + ca7a52ee + e4ffcbcc) mod 232
= (7f79e5aa(big endian) + ee527aca(big endian) + cccbffe4(big endian)) mod 232
= 3a986058(big endian) = 5860983a.
F14,1 = (T0 + 2T1 + K37) mod 232 = (aae5797f + 2[ca7a52ee] + fd60441f) mod 232
= (7f79e5aa(big endian) + 2[ee527aca(big endian)] + 1f4460fd(big endian)) mod 232
= (7f79e5aa(big endian) + dca4f594(big endian) + 1f4460fd(big endian)) mod 232
= 7b633c3b(big endian) = 3b3c637b.
R15,0  =  ROR(R14, 2    F14,0,1) =  ROR(b0a3ed16    5860983a, 1)
=  ROR(e8c3752c, 1) =  ROR(2c75c3e8(big endian), 1)
=  163ae1f4(big endian) =  f4e13a16
R15,1  =  ROL(R14, 3,  1)    F14,1) =  ROL(029740c3,  1)    3b3c637b
=  ROL(c3409702(big endian),  1)    3b3c637b
=  86812e05(big endian)    3b3c637b
=  052e8186   3b3c637b =  3e12e2fd.
R15,2 = R14,0 = 7f5fa592 R15,3 = R14,1 = 05b4ed65

 

Encryption of block 1, round r=15
g input = X = x0x1x2x3 = R15,0 = f4e13a16
g input = X = x0x1x2x3
= ROL(R15,1,  8) = ROL(3e12e2fd ,  8)
= ROL(fde2123e(big endian),  8)
= e2123efd(big endian) = fd3e12e2.
x0 = f4 x1 = e1 x2 = 3a x3 = 16 x0 = fd x1 = 3e x2 = 12 x3 = e2
y2,0 = f4 y2,1 = e1 y2,2 = 3a y2,3 = 16 y2,0 = fd y2,1 = 3e y2,2 = 12 y2,3 = e2
q0.in=f4
a0=f b0=4
a1=b b1=5
a2=9 b2=2
a3=b b3=0
a4=3 b4=d
q0.out=d3
l1,3=14
q0.in=cb
a0=c b0=b
a1=7 b1=1
a2=2 b2=c
a3=e b3=4
a4=7 b4=1
q0.out=17
l0,3=dc
q1.in=96
a0=9 b0=6
a1=f b1=2
a2=5 b2=2
a3=7 b3=c
a4=a b4=2
q1.out=2a
q1.in=e1
a0=e b0=1
a1=f b1=6
a2=5 b2=3
a3=6 b3=4
a4=9 b4=c
q1.out=c9
l1,2=9c
q0.in=43
a0=4 b0=3
a1=7 b1=d
a2=2 b2=0
a3=2 b3=2
a4=5 b4=f
q0.out=f5
l0,2=53
q0.in=7e
a0=7 b0=e
a1=9 b1=8
a2=b b2=f
a3=4 b3=c
a4=6 b4=8
q0.out=86
q0.in=3a
a0=3 b0=a
a1=9 b1=e
a2=b b2=9
a3=2 b3=f
a4=5 b4=a
q0.out=a5
l1,1=8a
q1.in=39
a0=3 b0=9
a1=a b1=7
a2=9 b2=7
a3=e b3=a
a4=3 b4=7
q1.out=73
l0,1=8b
q1.in=20
a0=2 b0=0
a1=2 b1=2
a2=b b2=2
a3=9 b3=2
a4=e b4=5
q1.out=5e
q1.in=16
a0=1 b0=6
a1=7 b1=a
a2=e b2=a
a3=4 b3=b
a4=1 b4=f
q1.out=f1
l1,0=18
q1.in=e5
a0=e b0=5
a1=b b1=4
a2=4 b2=4
a3=0 b3=6
a4=4 b4=d
q1.out=d4
l0,0=81
q0.in=08
a0=0 b0=8
a1=8 b1=4
a2=0 b2=1
a3=1 b3=8
a4=a b4=9
q0.out=9a
q0.in=fd
a0=f b0=d
a1=2 b1=9
a2=7 b2=4
a3=3 b3=d
a4=e b4=5
q0.out=5e
l1,3=14
q0.in=46
a0=4 b0=6
a1=2 b1=7
a2=7 b2=5
a3=2 b3=5
a4=5 b4=2
q0.out=25
l0,3=dc
q1.in=a4
a0=a b0=4
a1=e b1=8
a2=c b2=6
a3=a b3=f
a4=d b4=a
q1.out=ad
q1.in=3e
a0=3 b0=e
a1=d b1=c
a2=a b2=f
a3=5 b3=5
a4=6 b4=3
q1.out=36
l1,2=9c
q0.in=bc
a0=b b0=c
a1=7 b1=5
a2=2 b2=2
a3=0 b3=3
a4=b b4=4
q0.out=4b
l0,2=53
q0.in=c0
a0=c b0=0
a1=c b1=c
a2=e b2=7
a3=9 b3=5
a4=8 b4=2
q0.out=28
q0.in=12
a0=1 b0=2
a1=3 b1=8
a2=d b2=f
a3=2 b3=a
a4=5 b4=3
q0.out=35
l1,1=8a
q1.in=a9
a0=a b0=9
a1=3 b1=6
a2=d b2=3
a3=e b3=c
a4=3 b4=2
q1.out=23
l0,1=8b
q1.in=70
a0=7 b0=0
a1=7 b1=f
a2=e b2=8
a3=6 b3=a
a4=9 b4=7
q1.out=79
q1.in=e2
a0=e b0=2
a1=c b1=f
a2=0 b2=8
a3=8 b3=4
a4=0 b4=c
q1.out=c0
l1,0=18
q1.in=d4
a0=d b0=4
a1=9 b1=7
a2=1 b2=7
a3=6 b3=2
a4=9 b4=5
q1.out=59
l0,0=81
q0.in=85
a0=8 b0=5
a1=d b1=2
a2=c b2=b
a3=7 b3=1
a4=0 b4=7
q0.out=70
y0 = 2a y1 = 86 y2 = 5e y3 = 9a y0 = ad y1 = 28 y2 = 79 y3 = 70
MDS input = Y = y0y1y2y3 = 2a865e9a MDS input = Y = y0y1y2y3 = ad287970
MDS output = Z = z0z1z2z3 = 8f8c89dd MDS output = Z = z0z1z2z3 = ca2f31cf
z0 = 8f z1 = 8c z2 = 89 z3 = dd z0 = ca z1 = 2f z2 = 31 z3 = cf
T0 = g(R0) = 8f8c89dd T1 = g(ROL(R1, 8)) = ca2f31cf
F15,0 = (T0 + T1 + K38) mod 232 = (8f8c89dd + ca2f31cf + aadffd38) mod 232
= (dd898c8f(big endian) + cf312fca(big endian) + 38fddfaa(big endian)) mod 232
= e5b89c03(big endian) = 039cb8e5.
F15,1 = (T0 + 2T1 + K39) mod 232 = (8f8c89dd + 2[ca2f31cf] + 56f4c1eb) mod 232
= (dd898c8f(big endian) + 2[cf312fca(big endian)] + ebc1f456(big endian)) mod 232
= (dd898c8f(big endian) + 9e625f94(big endian) + ebc1f456(big endian)) mod 232
= 67ade079(big endian) = 79e0ad67.
R16,0  =  ROR(R15, 2    F15,0,1) =  ROR(7f5fa592    039cb8e5, 1)
=  ROR(7cc31d77, 1) =  ROR(771dc37c(big endian), 1)
=  3b8ee1be(big endian) =  bee18e3b
R16,1  =  ROL(R15, 3,  1)    F15,1) =  ROL(05b4ed65,  1)    79e0ad67
=  ROL(65edb405(big endian),  1)    79e0ad67
=  cbdb680a(big endian)    79e0ad67
=  0a68dbcb   79e0ad67 =  738876ac.
R16,2 = R15,0 = f4e13a16 R16,3 = R15,1 = 3e12e2fd

 

Encryption of block 1 : Output Whiten
C0 = R16,2 mod 4    K0+4 = R16,2    K4 = f4e13a16    f57ea21f  =  019f9809
C1 = R16,3 mod 4    K1+4 = R16,3    K5 = 3e12e2fd    e005f378  =  de171185
C2 = R16,4 mod 4    K2+4 = R16,0    K6 = bee18e3b    314b4d98  =  8faac3a3
C3 = R16,5 mod 4    K3+4 = R16,1    K7 = 738876ac    c9a88d6f  =  ba20fbc3

 

Encryption of block 1: Ciphertext result
c0 = [C0 2[8(0 mod 4)]] mod 28 = [019f9809 20] mod 28 = [09989f01(big endian) 20] mod 28 = 01
c1 = [C0 2[8(1 mod 4)]] mod 28 = [019f9809 28] mod 28 = [09989f01(big endian) 28] mod 28 = 9f
c2 = [C0 2[8(2 mod 4)]] mod 28 = [019f9809 216] mod 28 = [09989f01(big endian) 216] mod 28 = 98
c3 = [C0 2[8(3 mod 4)]] mod 28 = [019f9809 224] mod 28 = [09989f01(big endian) 224] mod 28 = 09
c4 = [C1 2[8(4 mod 4)]] mod 28 = [de171185 20] mod 28 = [851117de(big endian) 20] mod 28 = de
c5 = [C1 2[8(5 mod 4)]] mod 28 = [de171185 28] mod 28 = [851117de(big endian) 28] mod 28 = 17
c6 = [C1 2[8(6 mod 4)]] mod 28 = [de171185 216] mod 28 = [851117de(big endian) 216] mod 28 = 11
c7 = [C1 2[8(7 mod 4)]] mod 28 = [de171185 224] mod 28 = [851117de(big endian) 224] mod 28 = 85
c8 = [C2 2[8(8 mod 4)]] mod 28 = [8faac3a3 20] mod 28 = [a3c3aa8f(big endian) 20] mod 28 = 8f
c9 = [C2 2[8(9 mod 4)]] mod 28 = [8faac3a3 28] mod 28 = [a3c3aa8f(big endian) 28] mod 28 = aa
c10 = [C2 2[8(10 mod 4)]] mod 28 = [8faac3a3 216] mod 28 = [a3c3aa8f(big endian) 216] mod 28 = c3
c11 = [C2 2[8(11 mod 4)]] mod 28 = [8faac3a3 224] mod 28 = [a3c3aa8f(big endian) 224] mod 28 = a3
c12 = [C3 2[8(12 mod 4)]] mod 28 = [ba20fbc3 20] mod 28 = [c3fb20ba(big endian) 20] mod 28 = ba
c13 = [C3 2[8(13 mod 4)]] mod 28 = [ba20fbc3 28] mod 28 = [c3fb20ba(big endian) 28] mod 28 = 20
c14 = [C3 2[8(14 mod 4)]] mod 28 = [ba20fbc3 216] mod 28 = [c3fb20ba(big endian) 216] mod 28 = fb
c15 = [C3 2[8(15 mod 4)]] mod 28 = [ba20fbc3 224] mod 28 = [c3fb20ba(big endian) 224] mod 28 = c3
Ciphertext block output = c0c1c2c3c4c5c6c7c8c9c10c11c12c13c14c15 = 019f9809de1711858faac3a3ba20fbc3

 

Encryption start: block 2
128-bit plaintext block = p0p1p2p3p4p5p6p7p8p9p10p11p12p13p14p15 = 182b2bd814979745f9dadadc29191965
P0 = p0p1p2p3 = 182b02d8 P1 = p4p5p6p7 = 1497ea45
P2 = p8p9p10p11 = f9daacdc P3 = p12p13p14p15 = 29193a65

 

Encryption of block 2 : Encryption CBC step: Xor of plaintext block with ciphertext result of previous block
P '0 = P0 C0(previous round) = 182b02d8 019f9809 = 19b49ad1
P '1 = P1 C1(previous round) = 1497ea45 de171185 = ca80fbc0
P '2 = P2 C2(previous round) = f9daacdc 8faac3a3 = 76706f7f
P '3 = P3 C3(previous round) = 29193a65 ba20fbc3 = 9339c1a6

 

Encryption Input Whiten : Block 2
R0,0 = P '0 K0 = 19b49ad1 9bf1826a = 824518bb
R0,1 = P '1 K1 = ca80fbc0 02229b50 = c8a26090
R0,2 = P '2 K2 = 76706f7f ea11ea78 = 9c618507
R0,3 = P '3 K3 = 9339c1a6 ae0b98a1 = 3d325907

 

Encryption of block 2, round r=0
g input = X = x0x1x2x3 = R0,0 = 824518bb
g input = X = x0x1x2x3
= ROL(R0,1,  8) = ROL(c8a26090 ,  8)
= ROL(9060a2c8(big endian),  8)
= 60a2c890(big endian) = 90c8a260.
x0 = 82 x1 = 45 x2 = 18 x3 = bb x0 = 90 x1 = c8 x2 = a2 x3 = 60
y2,0 = 82 y2,1 = 45 y2,2 = 18 y2,3 = bb y2,0 = 90 y2,1 = c8 y2,2 = a2 y2,3 = 60
q0.in=82
a0=8 b0=2
a1=a b1=9
a2=5 b2=4
a3=1 b3=f
a4=a b4=a
q0.out=aa
l1,3=14
q0.in=b2
a0=b b0=2
a1=9 b1=2
a2=b b2=b
a3=0 b3=e
a4=b b4=c
q0.out=cb
l0,3=dc
q1.in=4a
a0=4 b0=a
a1=e b1=1
a2=c b2=e
a3=2 b3=b
a4=7 b4=f
q1.out=f7
q1.in=45
a0=4 b0=5
a1=1 b1=e
a2=8 b2=0
a3=8 b3=8
a4=0 b4=6
q1.out=60
l1,2=9c
q0.in=ea
a0=e b0=a
a1=4 b1=b
a2=6 b2=6
a3=0 b3=5
a4=b b4=2
q0.out=2b
l0,2=53
q0.in=a0
a0=a b0=0
a1=a b1=a
a2=5 b2=a
a3=f b3=8
a4=1 b4=9
q0.out=91
q0.in=18
a0=1 b0=8
a1=9 b1=d
a2=b b2=0
a3=b b3=3
a4=3 b4=4
q0.out=43
l1,1=8a
q1.in=df
a0=d b0=f
a1=2 b1=a
a2=b b2=a
a3=1 b3=6
a4=c b4=d
q1.out=dc
l0,1=8b
q1.in=8f
a0=8 b0=f
a1=7 b1=7
a2=e b2=7
a3=9 b3=5
a4=e b4=3
q1.out=3e
q1.in=bb
a0=b b0=b
a1=0 b1=e
a2=2 b2=0
a3=2 b3=2
a4=7 b4=5
q1.out=57
l1,0=18
q1.in=43
a0=4 b0=3
a1=7 b1=d
a2=e b2=9
a3=7 b3=2
a4=a b4=5
q1.out=5a
l0,0=81
q0.in=86
a0=8 b0=6
a1=e b1=b
a2=a b2=6
a3=c b3=9
a4=2 b4=b
q0.out=b2
q0.in=90
a0=9 b0=0
a1=9 b1=1
a2=b b2=c
a3=7 b3=5
a4=0 b4=2
q0.out=20
l1,3=14
q0.in=38
a0=3 b0=8
a1=b b1=f
a2=9 b2=d
a3=4 b3=f
a4=6 b4=a
q0.out=a6
l0,3=dc
q1.in=27
a0=2 b0=7
a1=5 b1=9
a2=7 b2=d
a3=a b3=1
a4=d b4=9
q1.out=9d
q1.in=c8
a0=c b0=8
a1=4 b1=8
a2=f b2=6
a3=9 b3=4
a4=e b4=c
q1.out=ce
l1,2=9c
q0.in=44
a0=4 b0=4
a1=0 b1=6
a2=8 b2=3
a3=b b3=1
a4=3 b4=7
q0.out=73
l0,2=53
q0.in=f8
a0=f b0=8
a1=7 b1=3
a2=2 b2=8
a3=a b3=6
a4=f b4=6
q0.out=6f
q0.in=a2
a0=a b0=2
a1=8 b1=b
a2=0 b2=6
a3=6 b3=3
a4=9 b4=4
q0.out=49
l1,1=8a
q1.in=d5
a0=d b0=5
a1=8 b1=f
a2=3 b2=8
a3=b b3=f
a4=8 b4=a
q1.out=a8
l0,1=8b
q1.in=fb
a0=f b0=b
a1=4 b1=a
a2=f b2=a
a3=5 b3=2
a4=6 b4=5
q1.out=56
q1.in=60
a0=6 b0=0
a1=6 b1=6
a2=6 b2=3
a3=5 b3=f
a4=6 b4=a
q1.out=a6
l1,0=18
q1.in=b2
a0=b b0=2
a1=9 b1=2
a2=1 b2=2
a3=3 b3=8
a4=5 b4=6
q1.out=65
l0,0=81
q0.in=b9
a0=b b0=9
a1=2 b1=f
a2=7 b2=d
a3=a b3=1
a4=f b4=7
q0.out=7f
y0 = f7 y1 = 91 y2 = 3e y3 = b2 y0 = 9d y1 = 6f y2 = 56 y3 = 7f
MDS input = Y = y0y1y2y3 = f7913eb2 MDS input = Y = y0y1y2y3 = 9d6f567f
MDS output = Z = z0z1z2z3 = 4b1f49ca MDS output = Z = z0z1z2z3 = fd5ad327
z0 = 4b z1 = 1f z2 = 49 z3 = ca z0 = fd z1 = 5a z2 = d3 z3 = 27
T0 = g(R0) = 4b1f49ca T1 = g(ROL(R1, 8)) = fd5ad327
F0,0 = (T0 + T1 + K8) mod 232 = (4b1f49ca + fd5ad327 + f595a22f) mod 232
= (ca491f4b(big endian) + 27d35afd(big endian) + 2fa295f5(big endian)) mod 232
= 21bf103d(big endian) = 3d10bf21.
F0,1 = (T0 + 2T1 + K9) mod 232 = (4b1f49ca + 2[fd5ad327] + b3c6caca) mod 232
= (ca491f4b(big endian) + 2[27d35afd(big endian)] + cacac6b3(big endian)) mod 232
= (ca491f4b(big endian) + 4fa6b5fa(big endian) + cacac6b3(big endian)) mod 232
= e4ba9bf8(big endian) = f89bbae4.
R1,0  =  ROR(R0, 2    F0,0,1) =  ROR(9c618507    3d10bf21, 1)
=  ROR(a1713a26, 1) =  ROR(263a71a1(big endian), 1)
=  931d38d0(big endian) =  d0381d93
R1,1  =  ROL(R0, 3,  1)    F0,1) =  ROL(3d325907,  1)