Skip to main content

arcana/cipher/
aes.rs

1// SPDX-License-Identifier: Apache-2.0
2// Copyright 2026 Cédric Mesnil <cslashm@pm.me>
3
4//! AES (FIPS 197) block cipher — single-block API.
5//!
6//! Supports 128-bit, 192-bit, and 256-bit keys with 10, 12, and 14
7//! rounds respectively. Modes (ECB / CBC / CTR / GCM / CCM / XTS)
8//! live in [`super::modes`], [`super::ccm`], [`super::xts`]; the
9//! streaming wrapper lives in [`super::ctx`].
10//!
11//! # ⚠ Side-channel posture (evaluation-critical gap)
12//!
13//! This module is the **single largest open SCA gap on the
14//! classical side**. Roadmap entries
15//! (`arcana/doc/sca/countermeasures/aes.rst`):
16//!
17//! | Threat                                 | Status     | Roadmap item                                                                  |
18//! |----------------------------------------|------------|-------------------------------------------------------------------------------|
19//! | SPA / SEMA on key schedule + S-box     | vulnerable | `T1-A` — port fixsliced AES (Adomnicai-Peyrin TCHES 2021/1)                   |
20//! | **Cache-timing on shared L1 / L2**     | vulnerable | Same `T1-A`. AES-NI / VAES is host-only (`T5`)                                |
21//! | DPA / CPA on round-1 SubBytes          | vulnerable | `T2-G` — first-order Boolean masking on top of fixsliced AES                  |
22//! | Template attacks (incl. ML-DPA)        | vulnerable | `T2-G`. ANSSI's protected AES was broken end-to-end by ML-DPA in 2023         |
23//! | DFA on last AES round                  | vulnerable | `T4-AES-A` — redundancy + infective countermeasure (deferred)                 |
24//!
25//! ## Cache-timing leak — concrete model
26//!
27//! The `SBOX` array below is a 256-byte LUT. The first round of
28//! AES indexes 16 bytes of `state[i] ^ K[i]`; observing which
29//! cache lines (4 lines × 64 B = 256 B) are accessed reveals the
30//! high bits of each byte of `state[i] ^ K[i]`. Combined T-table
31//! implementations (which fold ShiftRows + MixColumns into 4 KiB
32//! of pre-computed tables) leak more. References:
33//! `bernstein2005_aes_cache_timing`, `osvik2006cache_aes`.
34//!
35//! **Until `T1-A` lands, this implementation must not be used in
36//! deployments where a co-resident or near-shared-cache attacker
37//! is in scope** — shared hosting, multi-VM tenants, or any
38//! bare-metal target with shared L1 between cryptographic and
39//! untrusted code.
40
41use crate::BlockCipher;
42
43// ============================================================
44// S-box and inverse S-box (FIPS 197, Section 5.1.1)
45// ============================================================
46
47/// AES forward S-box.
48const SBOX: [u8; 256] = [
49    0x63, 0x7c, 0x77, 0x7b, 0xf2, 0x6b, 0x6f, 0xc5, 0x30, 0x01, 0x67, 0x2b, 0xfe, 0xd7, 0xab, 0x76, 0xca, 0x82, 0xc9,
50    0x7d, 0xfa, 0x59, 0x47, 0xf0, 0xad, 0xd4, 0xa2, 0xaf, 0x9c, 0xa4, 0x72, 0xc0, 0xb7, 0xfd, 0x93, 0x26, 0x36, 0x3f,
51    0xf7, 0xcc, 0x34, 0xa5, 0xe5, 0xf1, 0x71, 0xd8, 0x31, 0x15, 0x04, 0xc7, 0x23, 0xc3, 0x18, 0x96, 0x05, 0x9a, 0x07,
52    0x12, 0x80, 0xe2, 0xeb, 0x27, 0xb2, 0x75, 0x09, 0x83, 0x2c, 0x1a, 0x1b, 0x6e, 0x5a, 0xa0, 0x52, 0x3b, 0xd6, 0xb3,
53    0x29, 0xe3, 0x2f, 0x84, 0x53, 0xd1, 0x00, 0xed, 0x20, 0xfc, 0xb1, 0x5b, 0x6a, 0xcb, 0xbe, 0x39, 0x4a, 0x4c, 0x58,
54    0xcf, 0xd0, 0xef, 0xaa, 0xfb, 0x43, 0x4d, 0x33, 0x85, 0x45, 0xf9, 0x02, 0x7f, 0x50, 0x3c, 0x9f, 0xa8, 0x51, 0xa3,
55    0x40, 0x8f, 0x92, 0x9d, 0x38, 0xf5, 0xbc, 0xb6, 0xda, 0x21, 0x10, 0xff, 0xf3, 0xd2, 0xcd, 0x0c, 0x13, 0xec, 0x5f,
56    0x97, 0x44, 0x17, 0xc4, 0xa7, 0x7e, 0x3d, 0x64, 0x5d, 0x19, 0x73, 0x60, 0x81, 0x4f, 0xdc, 0x22, 0x2a, 0x90, 0x88,
57    0x46, 0xee, 0xb8, 0x14, 0xde, 0x5e, 0x0b, 0xdb, 0xe0, 0x32, 0x3a, 0x0a, 0x49, 0x06, 0x24, 0x5c, 0xc2, 0xd3, 0xac,
58    0x62, 0x91, 0x95, 0xe4, 0x79, 0xe7, 0xc8, 0x37, 0x6d, 0x8d, 0xd5, 0x4e, 0xa9, 0x6c, 0x56, 0xf4, 0xea, 0x65, 0x7a,
59    0xae, 0x08, 0xba, 0x78, 0x25, 0x2e, 0x1c, 0xa6, 0xb4, 0xc6, 0xe8, 0xdd, 0x74, 0x1f, 0x4b, 0xbd, 0x8b, 0x8a, 0x70,
60    0x3e, 0xb5, 0x66, 0x48, 0x03, 0xf6, 0x0e, 0x61, 0x35, 0x57, 0xb9, 0x86, 0xc1, 0x1d, 0x9e, 0xe1, 0xf8, 0x98, 0x11,
61    0x69, 0xd9, 0x8e, 0x94, 0x9b, 0x1e, 0x87, 0xe9, 0xce, 0x55, 0x28, 0xdf, 0x8c, 0xa1, 0x89, 0x0d, 0xbf, 0xe6, 0x42,
62    0x68, 0x41, 0x99, 0x2d, 0x0f, 0xb0, 0x54, 0xbb, 0x16,
63];
64
65/// AES inverse S-box.
66const INV_SBOX: [u8; 256] = [
67    0x52, 0x09, 0x6a, 0xd5, 0x30, 0x36, 0xa5, 0x38, 0xbf, 0x40, 0xa3, 0x9e, 0x81, 0xf3, 0xd7, 0xfb, 0x7c, 0xe3, 0x39,
68    0x82, 0x9b, 0x2f, 0xff, 0x87, 0x34, 0x8e, 0x43, 0x44, 0xc4, 0xde, 0xe9, 0xcb, 0x54, 0x7b, 0x94, 0x32, 0xa6, 0xc2,
69    0x23, 0x3d, 0xee, 0x4c, 0x95, 0x0b, 0x42, 0xfa, 0xc3, 0x4e, 0x08, 0x2e, 0xa1, 0x66, 0x28, 0xd9, 0x24, 0xb2, 0x76,
70    0x5b, 0xa2, 0x49, 0x6d, 0x8b, 0xd1, 0x25, 0x72, 0xf8, 0xf6, 0x64, 0x86, 0x68, 0x98, 0x16, 0xd4, 0xa4, 0x5c, 0xcc,
71    0x5d, 0x65, 0xb6, 0x92, 0x6c, 0x70, 0x48, 0x50, 0xfd, 0xed, 0xb9, 0xda, 0x5e, 0x15, 0x46, 0x57, 0xa7, 0x8d, 0x9d,
72    0x84, 0x90, 0xd8, 0xab, 0x00, 0x8c, 0xbc, 0xd3, 0x0a, 0xf7, 0xe4, 0x58, 0x05, 0xb8, 0xb3, 0x45, 0x06, 0xd0, 0x2c,
73    0x1e, 0x8f, 0xca, 0x3f, 0x0f, 0x02, 0xc1, 0xaf, 0xbd, 0x03, 0x01, 0x13, 0x8a, 0x6b, 0x3a, 0x91, 0x11, 0x41, 0x4f,
74    0x67, 0xdc, 0xea, 0x97, 0xf2, 0xcf, 0xce, 0xf0, 0xb4, 0xe6, 0x73, 0x96, 0xac, 0x74, 0x22, 0xe7, 0xad, 0x35, 0x85,
75    0xe2, 0xf9, 0x37, 0xe8, 0x1c, 0x75, 0xdf, 0x6e, 0x47, 0xf1, 0x1a, 0x71, 0x1d, 0x29, 0xc5, 0x89, 0x6f, 0xb7, 0x62,
76    0x0e, 0xaa, 0x18, 0xbe, 0x1b, 0xfc, 0x56, 0x3e, 0x4b, 0xc6, 0xd2, 0x79, 0x20, 0x9a, 0xdb, 0xc0, 0xfe, 0x78, 0xcd,
77    0x5a, 0xf4, 0x1f, 0xdd, 0xa8, 0x33, 0x88, 0x07, 0xc7, 0x31, 0xb1, 0x12, 0x10, 0x59, 0x27, 0x80, 0xec, 0x5f, 0x60,
78    0x51, 0x7f, 0xa9, 0x19, 0xb5, 0x4a, 0x0d, 0x2d, 0xe5, 0x7a, 0x9f, 0x93, 0xc9, 0x9c, 0xef, 0xa0, 0xe0, 0x3b, 0x4d,
79    0xae, 0x2a, 0xf5, 0xb0, 0xc8, 0xeb, 0xbb, 0x3c, 0x83, 0x53, 0x99, 0x61, 0x17, 0x2b, 0x04, 0x7e, 0xba, 0x77, 0xd6,
80    0x26, 0xe1, 0x69, 0x14, 0x63, 0x55, 0x21, 0x0c, 0x7d,
81];
82
83/// Round constants for key expansion.
84const RCON: [u8; 10] = [0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36];
85
86// ============================================================
87// GF(2^8) helpers
88// ============================================================
89
90/// Multiply by 2 in GF(2^8) with the AES irreducible polynomial x^8+x^4+x^3+x+1.
91#[inline]
92fn xtime(a: u8) -> u8 {
93    let shifted = (a as u16) << 1;
94    (shifted ^ (if a & 0x80 != 0 { 0x1b } else { 0x00 })) as u8
95}
96
97/// Multiply two elements in GF(2^8).
98#[inline]
99fn gmul(mut a: u8, mut b: u8) -> u8 {
100    let mut p: u8 = 0;
101    for _ in 0..8 {
102        if b & 1 != 0 {
103            p ^= a;
104        }
105        let hi = a & 0x80;
106        a <<= 1;
107        if hi != 0 {
108            a ^= 0x1b;
109        }
110        b >>= 1;
111    }
112    p
113}
114
115// ============================================================
116// Aes core
117// ============================================================
118
119/// Maximum number of round keys: AES-256 has 14 rounds → 15 round keys × 4 words = 60 words.
120const MAX_ROUND_KEYS: usize = 60;
121
122/// AES block cipher supporting 128, 192, and 256-bit keys.
123///
124/// See module-level documentation for cache-timing caveats.
125pub struct Aes {
126    /// Expanded round key words (Nk * (Nr+1) 32-bit words).
127    round_keys: [u32; MAX_ROUND_KEYS],
128    /// Number of rounds (10, 12, or 14).
129    nr: usize,
130}
131
132impl Aes {
133    /// Number of rounds for a given key length in bytes.
134    fn rounds_for_key(key_len: usize) -> usize {
135        match key_len {
136            16 => 10,
137            24 => 12,
138            32 => 14,
139            _ => panic!("AES: invalid key length (must be 16, 24, or 32 bytes)"),
140        }
141    }
142
143    /// Key expansion (FIPS 197, Section 5.2).
144    fn key_expansion(key: &[u8]) -> ([u32; MAX_ROUND_KEYS], usize) {
145        let nk = key.len() / 4; // number of 32-bit words in the key
146        let nr = Self::rounds_for_key(key.len());
147        let total_words = 4 * (nr + 1);
148
149        let mut w = [0u32; MAX_ROUND_KEYS];
150
151        // Copy the key into the first Nk words
152        for i in 0..nk {
153            w[i] = u32::from_be_bytes([key[4 * i], key[4 * i + 1], key[4 * i + 2], key[4 * i + 3]]);
154        }
155
156        for i in nk..total_words {
157            let mut temp = w[i - 1];
158            if i % nk == 0 {
159                // RotWord + SubWord + Rcon
160                temp = Self::sub_word(Self::rot_word(temp)) ^ ((RCON[i / nk - 1] as u32) << 24);
161            } else if nk > 6 && i % nk == 4 {
162                temp = Self::sub_word(temp);
163            }
164            w[i] = w[i - nk] ^ temp;
165        }
166
167        (w, nr)
168    }
169
170    #[inline]
171    fn sub_word(w: u32) -> u32 {
172        let b = w.to_be_bytes();
173        u32::from_be_bytes([
174            SBOX[b[0] as usize],
175            SBOX[b[1] as usize],
176            SBOX[b[2] as usize],
177            SBOX[b[3] as usize],
178        ])
179    }
180
181    #[inline]
182    fn rot_word(w: u32) -> u32 {
183        w.rotate_left(8)
184    }
185
186    // ---- Encryption transforms ----
187
188    fn sub_bytes(state: &mut [u8; 16]) {
189        for b in state.iter_mut() {
190            *b = SBOX[*b as usize];
191        }
192    }
193
194    fn shift_rows(state: &mut [u8; 16]) {
195        // Row 1: shift left by 1
196        let tmp = state[1];
197        state[1] = state[5];
198        state[5] = state[9];
199        state[9] = state[13];
200        state[13] = tmp;
201
202        // Row 2: shift left by 2
203        let tmp0 = state[2];
204        let tmp1 = state[6];
205        state[2] = state[10];
206        state[6] = state[14];
207        state[10] = tmp0;
208        state[14] = tmp1;
209
210        // Row 3: shift left by 3 (= shift right by 1)
211        let tmp = state[15];
212        state[15] = state[11];
213        state[11] = state[7];
214        state[7] = state[3];
215        state[3] = tmp;
216    }
217
218    fn mix_columns(state: &mut [u8; 16]) {
219        for c in 0..4 {
220            let i = 4 * c;
221            let s0 = state[i];
222            let s1 = state[i + 1];
223            let s2 = state[i + 2];
224            let s3 = state[i + 3];
225
226            state[i] = xtime(s0) ^ xtime(s1) ^ s1 ^ s2 ^ s3;
227            state[i + 1] = s0 ^ xtime(s1) ^ xtime(s2) ^ s2 ^ s3;
228            state[i + 2] = s0 ^ s1 ^ xtime(s2) ^ xtime(s3) ^ s3;
229            state[i + 3] = xtime(s0) ^ s0 ^ s1 ^ s2 ^ xtime(s3);
230        }
231    }
232
233    fn add_round_key(state: &mut [u8; 16], rk: &[u32]) {
234        for c in 0..4 {
235            let k = rk[c].to_be_bytes();
236            state[4 * c] ^= k[0];
237            state[4 * c + 1] ^= k[1];
238            state[4 * c + 2] ^= k[2];
239            state[4 * c + 3] ^= k[3];
240        }
241    }
242
243    // ---- Decryption transforms ----
244
245    fn inv_sub_bytes(state: &mut [u8; 16]) {
246        for b in state.iter_mut() {
247            *b = INV_SBOX[*b as usize];
248        }
249    }
250
251    fn inv_shift_rows(state: &mut [u8; 16]) {
252        // Row 1: shift right by 1
253        let tmp = state[13];
254        state[13] = state[9];
255        state[9] = state[5];
256        state[5] = state[1];
257        state[1] = tmp;
258
259        // Row 2: shift right by 2
260        let tmp0 = state[2];
261        let tmp1 = state[6];
262        state[2] = state[10];
263        state[6] = state[14];
264        state[10] = tmp0;
265        state[14] = tmp1;
266
267        // Row 3: shift right by 3 (= shift left by 1)
268        let tmp = state[3];
269        state[3] = state[7];
270        state[7] = state[11];
271        state[11] = state[15];
272        state[15] = tmp;
273    }
274
275    fn inv_mix_columns(state: &mut [u8; 16]) {
276        for c in 0..4 {
277            let i = 4 * c;
278            let s0 = state[i];
279            let s1 = state[i + 1];
280            let s2 = state[i + 2];
281            let s3 = state[i + 3];
282
283            state[i] = gmul(s0, 0x0e) ^ gmul(s1, 0x0b) ^ gmul(s2, 0x0d) ^ gmul(s3, 0x09);
284            state[i + 1] = gmul(s0, 0x09) ^ gmul(s1, 0x0e) ^ gmul(s2, 0x0b) ^ gmul(s3, 0x0d);
285            state[i + 2] = gmul(s0, 0x0d) ^ gmul(s1, 0x09) ^ gmul(s2, 0x0e) ^ gmul(s3, 0x0b);
286            state[i + 3] = gmul(s0, 0x0b) ^ gmul(s1, 0x0d) ^ gmul(s2, 0x09) ^ gmul(s3, 0x0e);
287        }
288    }
289}
290
291impl BlockCipher for Aes {
292    const BLOCK_LEN: usize = 16;
293    const KEY_LENS: &'static [usize] = &[16, 24, 32];
294
295    fn new(key: &[u8]) -> Self {
296        let (round_keys, nr) = Self::key_expansion(key);
297        Aes { round_keys, nr }
298    }
299
300    fn encrypt_block(&self, block: &mut [u8]) {
301        assert!(block.len() >= 16, "AES: block must be at least 16 bytes");
302        let mut state = [0u8; 16];
303        state.copy_from_slice(&block[..16]);
304
305        // Initial round key addition
306        Self::add_round_key(&mut state, &self.round_keys[0..4]);
307
308        // Rounds 1..Nr-1
309        for round in 1..self.nr {
310            Self::sub_bytes(&mut state);
311            Self::shift_rows(&mut state);
312            Self::mix_columns(&mut state);
313            Self::add_round_key(&mut state, &self.round_keys[round * 4..(round + 1) * 4]);
314        }
315
316        // Final round (no MixColumns)
317        Self::sub_bytes(&mut state);
318        Self::shift_rows(&mut state);
319        Self::add_round_key(&mut state, &self.round_keys[self.nr * 4..(self.nr + 1) * 4]);
320
321        block[..16].copy_from_slice(&state);
322    }
323
324    fn decrypt_block(&self, block: &mut [u8]) {
325        assert!(block.len() >= 16, "AES: block must be at least 16 bytes");
326        let mut state = [0u8; 16];
327        state.copy_from_slice(&block[..16]);
328
329        // Initial round key addition (last round key)
330        Self::add_round_key(&mut state, &self.round_keys[self.nr * 4..(self.nr + 1) * 4]);
331
332        // Rounds Nr-1..1
333        for round in (1..self.nr).rev() {
334            Self::inv_shift_rows(&mut state);
335            Self::inv_sub_bytes(&mut state);
336            Self::add_round_key(&mut state, &self.round_keys[round * 4..(round + 1) * 4]);
337            Self::inv_mix_columns(&mut state);
338        }
339
340        // Final round (no InvMixColumns)
341        Self::inv_shift_rows(&mut state);
342        Self::inv_sub_bytes(&mut state);
343        Self::add_round_key(&mut state, &self.round_keys[0..4]);
344
345        block[..16].copy_from_slice(&state);
346    }
347}
348
349// ============================================================
350// Convenience wrappers
351// ============================================================
352
353/// AES-128 (10 rounds, 128-bit key).
354pub struct Aes128 {
355    inner: Aes,
356}
357
358impl BlockCipher for Aes128 {
359    const BLOCK_LEN: usize = 16;
360    const KEY_LENS: &'static [usize] = &[16];
361
362    fn new(key: &[u8]) -> Self {
363        assert_eq!(key.len(), 16, "AES-128 requires a 16-byte key");
364        Aes128 { inner: Aes::new(key) }
365    }
366
367    fn encrypt_block(&self, block: &mut [u8]) {
368        self.inner.encrypt_block(block);
369    }
370
371    fn decrypt_block(&self, block: &mut [u8]) {
372        self.inner.decrypt_block(block);
373    }
374}
375
376/// AES-192 (12 rounds, 192-bit key).
377pub struct Aes192 {
378    inner: Aes,
379}
380
381impl BlockCipher for Aes192 {
382    const BLOCK_LEN: usize = 16;
383    const KEY_LENS: &'static [usize] = &[24];
384
385    fn new(key: &[u8]) -> Self {
386        assert_eq!(key.len(), 24, "AES-192 requires a 24-byte key");
387        Aes192 { inner: Aes::new(key) }
388    }
389
390    fn encrypt_block(&self, block: &mut [u8]) {
391        self.inner.encrypt_block(block);
392    }
393
394    fn decrypt_block(&self, block: &mut [u8]) {
395        self.inner.decrypt_block(block);
396    }
397}
398
399/// AES-256 (14 rounds, 256-bit key).
400pub struct Aes256 {
401    inner: Aes,
402}
403
404impl BlockCipher for Aes256 {
405    const BLOCK_LEN: usize = 16;
406    const KEY_LENS: &'static [usize] = &[32];
407
408    fn new(key: &[u8]) -> Self {
409        assert_eq!(key.len(), 32, "AES-256 requires a 32-byte key");
410        Aes256 { inner: Aes::new(key) }
411    }
412
413    fn encrypt_block(&self, block: &mut [u8]) {
414        self.inner.encrypt_block(block);
415    }
416
417    fn decrypt_block(&self, block: &mut [u8]) {
418        self.inner.decrypt_block(block);
419    }
420}
421
422// ============================================================
423// Tests
424// ============================================================
425
426#[cfg(test)]
427mod tests {
428    use super::*;
429
430    fn hex_to_bytes(s: &str) -> Vec<u8> {
431        (0..s.len())
432            .step_by(2)
433            .map(|i| u8::from_str_radix(&s[i..i + 2], 16).unwrap())
434            .collect()
435    }
436
437    /// FIPS 197 Appendix B test vector.
438    #[test]
439    fn aes128_fips197_appendix_b() {
440        let key = hex_to_bytes("2b7e151628aed2a6abf7158809cf4f3c");
441        let plaintext = hex_to_bytes("3243f6a8885a308d313198a2e0370734");
442        let expected_ct = hex_to_bytes("3925841d02dc09fbdc118597196a0b32");
443
444        let cipher = Aes128::new(&key);
445
446        // Encrypt
447        let mut block = plaintext.clone();
448        cipher.encrypt_block(&mut block);
449        assert_eq!(block, expected_ct, "AES-128 encrypt mismatch");
450
451        // Decrypt
452        cipher.decrypt_block(&mut block);
453        assert_eq!(block, plaintext, "AES-128 decrypt mismatch");
454    }
455
456    /// NIST FIPS 197 Appendix C.1 — AES-128
457    #[test]
458    fn aes128_nist_c1() {
459        let key = hex_to_bytes("000102030405060708090a0b0c0d0e0f");
460        let pt = hex_to_bytes("00112233445566778899aabbccddeeff");
461        let expected = hex_to_bytes("69c4e0d86a7b0430d8cdb78070b4c55a");
462
463        let cipher = Aes128::new(&key);
464        let mut block = pt.clone();
465        cipher.encrypt_block(&mut block);
466        assert_eq!(block, expected);
467
468        cipher.decrypt_block(&mut block);
469        assert_eq!(block, pt);
470    }
471
472    /// NIST FIPS 197 Appendix C.2 — AES-192
473    #[test]
474    fn aes192_nist_c2() {
475        let key = hex_to_bytes("000102030405060708090a0b0c0d0e0f1011121314151617");
476        let pt = hex_to_bytes("00112233445566778899aabbccddeeff");
477        let expected = hex_to_bytes("dda97ca4864cdfe06eaf70a0ec0d7191");
478
479        let cipher = Aes192::new(&key);
480        let mut block = pt.clone();
481        cipher.encrypt_block(&mut block);
482        assert_eq!(block, expected);
483
484        cipher.decrypt_block(&mut block);
485        assert_eq!(block, pt);
486    }
487
488    /// NIST FIPS 197 Appendix C.3 — AES-256
489    #[test]
490    fn aes256_nist_c3() {
491        let key = hex_to_bytes("000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f");
492        let pt = hex_to_bytes("00112233445566778899aabbccddeeff");
493        let expected = hex_to_bytes("8ea2b7ca516745bfeafc49904b496089");
494
495        let cipher = Aes256::new(&key);
496        let mut block = pt.clone();
497        cipher.encrypt_block(&mut block);
498        assert_eq!(block, expected);
499
500        cipher.decrypt_block(&mut block);
501        assert_eq!(block, pt);
502    }
503}