18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only
28c2ecf20Sopenharmony_ci/*
38c2ecf20Sopenharmony_ci * Scalar fixed time AES core transform
48c2ecf20Sopenharmony_ci *
58c2ecf20Sopenharmony_ci * Copyright (C) 2017 Linaro Ltd <ard.biesheuvel@linaro.org>
68c2ecf20Sopenharmony_ci */
78c2ecf20Sopenharmony_ci
88c2ecf20Sopenharmony_ci#include <crypto/aes.h>
98c2ecf20Sopenharmony_ci#include <linux/crypto.h>
108c2ecf20Sopenharmony_ci#include <linux/module.h>
118c2ecf20Sopenharmony_ci
128c2ecf20Sopenharmony_cistatic int aesti_set_key(struct crypto_tfm *tfm, const u8 *in_key,
138c2ecf20Sopenharmony_ci			 unsigned int key_len)
148c2ecf20Sopenharmony_ci{
158c2ecf20Sopenharmony_ci	struct crypto_aes_ctx *ctx = crypto_tfm_ctx(tfm);
168c2ecf20Sopenharmony_ci
178c2ecf20Sopenharmony_ci	return aes_expandkey(ctx, in_key, key_len);
188c2ecf20Sopenharmony_ci}
198c2ecf20Sopenharmony_ci
208c2ecf20Sopenharmony_cistatic void aesti_encrypt(struct crypto_tfm *tfm, u8 *out, const u8 *in)
218c2ecf20Sopenharmony_ci{
228c2ecf20Sopenharmony_ci	const struct crypto_aes_ctx *ctx = crypto_tfm_ctx(tfm);
238c2ecf20Sopenharmony_ci	unsigned long flags;
248c2ecf20Sopenharmony_ci
258c2ecf20Sopenharmony_ci	/*
268c2ecf20Sopenharmony_ci	 * Temporarily disable interrupts to avoid races where cachelines are
278c2ecf20Sopenharmony_ci	 * evicted when the CPU is interrupted to do something else.
288c2ecf20Sopenharmony_ci	 */
298c2ecf20Sopenharmony_ci	local_irq_save(flags);
308c2ecf20Sopenharmony_ci
318c2ecf20Sopenharmony_ci	aes_encrypt(ctx, out, in);
328c2ecf20Sopenharmony_ci
338c2ecf20Sopenharmony_ci	local_irq_restore(flags);
348c2ecf20Sopenharmony_ci}
358c2ecf20Sopenharmony_ci
368c2ecf20Sopenharmony_cistatic void aesti_decrypt(struct crypto_tfm *tfm, u8 *out, const u8 *in)
378c2ecf20Sopenharmony_ci{
388c2ecf20Sopenharmony_ci	const struct crypto_aes_ctx *ctx = crypto_tfm_ctx(tfm);
398c2ecf20Sopenharmony_ci	unsigned long flags;
408c2ecf20Sopenharmony_ci
418c2ecf20Sopenharmony_ci	/*
428c2ecf20Sopenharmony_ci	 * Temporarily disable interrupts to avoid races where cachelines are
438c2ecf20Sopenharmony_ci	 * evicted when the CPU is interrupted to do something else.
448c2ecf20Sopenharmony_ci	 */
458c2ecf20Sopenharmony_ci	local_irq_save(flags);
468c2ecf20Sopenharmony_ci
478c2ecf20Sopenharmony_ci	aes_decrypt(ctx, out, in);
488c2ecf20Sopenharmony_ci
498c2ecf20Sopenharmony_ci	local_irq_restore(flags);
508c2ecf20Sopenharmony_ci}
518c2ecf20Sopenharmony_ci
528c2ecf20Sopenharmony_cistatic struct crypto_alg aes_alg = {
538c2ecf20Sopenharmony_ci	.cra_name			= "aes",
548c2ecf20Sopenharmony_ci	.cra_driver_name		= "aes-fixed-time",
558c2ecf20Sopenharmony_ci	.cra_priority			= 100 + 1,
568c2ecf20Sopenharmony_ci	.cra_flags			= CRYPTO_ALG_TYPE_CIPHER,
578c2ecf20Sopenharmony_ci	.cra_blocksize			= AES_BLOCK_SIZE,
588c2ecf20Sopenharmony_ci	.cra_ctxsize			= sizeof(struct crypto_aes_ctx),
598c2ecf20Sopenharmony_ci	.cra_module			= THIS_MODULE,
608c2ecf20Sopenharmony_ci
618c2ecf20Sopenharmony_ci	.cra_cipher.cia_min_keysize	= AES_MIN_KEY_SIZE,
628c2ecf20Sopenharmony_ci	.cra_cipher.cia_max_keysize	= AES_MAX_KEY_SIZE,
638c2ecf20Sopenharmony_ci	.cra_cipher.cia_setkey		= aesti_set_key,
648c2ecf20Sopenharmony_ci	.cra_cipher.cia_encrypt		= aesti_encrypt,
658c2ecf20Sopenharmony_ci	.cra_cipher.cia_decrypt		= aesti_decrypt
668c2ecf20Sopenharmony_ci};
678c2ecf20Sopenharmony_ci
688c2ecf20Sopenharmony_cistatic int __init aes_init(void)
698c2ecf20Sopenharmony_ci{
708c2ecf20Sopenharmony_ci	return crypto_register_alg(&aes_alg);
718c2ecf20Sopenharmony_ci}
728c2ecf20Sopenharmony_ci
738c2ecf20Sopenharmony_cistatic void __exit aes_fini(void)
748c2ecf20Sopenharmony_ci{
758c2ecf20Sopenharmony_ci	crypto_unregister_alg(&aes_alg);
768c2ecf20Sopenharmony_ci}
778c2ecf20Sopenharmony_ci
788c2ecf20Sopenharmony_cimodule_init(aes_init);
798c2ecf20Sopenharmony_cimodule_exit(aes_fini);
808c2ecf20Sopenharmony_ci
818c2ecf20Sopenharmony_ciMODULE_DESCRIPTION("Generic fixed time AES");
828c2ecf20Sopenharmony_ciMODULE_AUTHOR("Ard Biesheuvel <ard.biesheuvel@linaro.org>");
838c2ecf20Sopenharmony_ciMODULE_LICENSE("GPL v2");
84