18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only 28c2ecf20Sopenharmony_ci/* 38c2ecf20Sopenharmony_ci * AMD Cryptographic Coprocessor (CCP) DES3 crypto API support 48c2ecf20Sopenharmony_ci * 58c2ecf20Sopenharmony_ci * Copyright (C) 2016,2017 Advanced Micro Devices, Inc. 68c2ecf20Sopenharmony_ci * 78c2ecf20Sopenharmony_ci * Author: Gary R Hook <ghook@amd.com> 88c2ecf20Sopenharmony_ci */ 98c2ecf20Sopenharmony_ci 108c2ecf20Sopenharmony_ci#include <linux/module.h> 118c2ecf20Sopenharmony_ci#include <linux/sched.h> 128c2ecf20Sopenharmony_ci#include <linux/delay.h> 138c2ecf20Sopenharmony_ci#include <linux/scatterlist.h> 148c2ecf20Sopenharmony_ci#include <linux/crypto.h> 158c2ecf20Sopenharmony_ci#include <crypto/algapi.h> 168c2ecf20Sopenharmony_ci#include <crypto/scatterwalk.h> 178c2ecf20Sopenharmony_ci#include <crypto/internal/des.h> 188c2ecf20Sopenharmony_ci 198c2ecf20Sopenharmony_ci#include "ccp-crypto.h" 208c2ecf20Sopenharmony_ci 218c2ecf20Sopenharmony_cistatic int ccp_des3_complete(struct crypto_async_request *async_req, int ret) 228c2ecf20Sopenharmony_ci{ 238c2ecf20Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(async_req); 248c2ecf20Sopenharmony_ci struct ccp_ctx *ctx = crypto_tfm_ctx(req->base.tfm); 258c2ecf20Sopenharmony_ci struct ccp_des3_req_ctx *rctx = skcipher_request_ctx(req); 268c2ecf20Sopenharmony_ci 278c2ecf20Sopenharmony_ci if (ret) 288c2ecf20Sopenharmony_ci return ret; 298c2ecf20Sopenharmony_ci 308c2ecf20Sopenharmony_ci if (ctx->u.des3.mode != CCP_DES3_MODE_ECB) 318c2ecf20Sopenharmony_ci memcpy(req->iv, rctx->iv, DES3_EDE_BLOCK_SIZE); 328c2ecf20Sopenharmony_ci 338c2ecf20Sopenharmony_ci return 0; 348c2ecf20Sopenharmony_ci} 358c2ecf20Sopenharmony_ci 368c2ecf20Sopenharmony_cistatic int ccp_des3_setkey(struct crypto_skcipher *tfm, const u8 *key, 378c2ecf20Sopenharmony_ci unsigned int key_len) 388c2ecf20Sopenharmony_ci{ 398c2ecf20Sopenharmony_ci struct ccp_crypto_skcipher_alg *alg = ccp_crypto_skcipher_alg(tfm); 408c2ecf20Sopenharmony_ci struct ccp_ctx *ctx = crypto_skcipher_ctx(tfm); 418c2ecf20Sopenharmony_ci int err; 428c2ecf20Sopenharmony_ci 438c2ecf20Sopenharmony_ci err = verify_skcipher_des3_key(tfm, key); 448c2ecf20Sopenharmony_ci if (err) 458c2ecf20Sopenharmony_ci return err; 468c2ecf20Sopenharmony_ci 478c2ecf20Sopenharmony_ci /* It's not clear that there is any support for a keysize of 112. 488c2ecf20Sopenharmony_ci * If needed, the caller should make K1 == K3 498c2ecf20Sopenharmony_ci */ 508c2ecf20Sopenharmony_ci ctx->u.des3.type = CCP_DES3_TYPE_168; 518c2ecf20Sopenharmony_ci ctx->u.des3.mode = alg->mode; 528c2ecf20Sopenharmony_ci ctx->u.des3.key_len = key_len; 538c2ecf20Sopenharmony_ci 548c2ecf20Sopenharmony_ci memcpy(ctx->u.des3.key, key, key_len); 558c2ecf20Sopenharmony_ci sg_init_one(&ctx->u.des3.key_sg, ctx->u.des3.key, key_len); 568c2ecf20Sopenharmony_ci 578c2ecf20Sopenharmony_ci return 0; 588c2ecf20Sopenharmony_ci} 598c2ecf20Sopenharmony_ci 608c2ecf20Sopenharmony_cistatic int ccp_des3_crypt(struct skcipher_request *req, bool encrypt) 618c2ecf20Sopenharmony_ci{ 628c2ecf20Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 638c2ecf20Sopenharmony_ci struct ccp_ctx *ctx = crypto_skcipher_ctx(tfm); 648c2ecf20Sopenharmony_ci struct ccp_des3_req_ctx *rctx = skcipher_request_ctx(req); 658c2ecf20Sopenharmony_ci struct scatterlist *iv_sg = NULL; 668c2ecf20Sopenharmony_ci unsigned int iv_len = 0; 678c2ecf20Sopenharmony_ci int ret; 688c2ecf20Sopenharmony_ci 698c2ecf20Sopenharmony_ci if (!ctx->u.des3.key_len) 708c2ecf20Sopenharmony_ci return -EINVAL; 718c2ecf20Sopenharmony_ci 728c2ecf20Sopenharmony_ci if (((ctx->u.des3.mode == CCP_DES3_MODE_ECB) || 738c2ecf20Sopenharmony_ci (ctx->u.des3.mode == CCP_DES3_MODE_CBC)) && 748c2ecf20Sopenharmony_ci (req->cryptlen & (DES3_EDE_BLOCK_SIZE - 1))) 758c2ecf20Sopenharmony_ci return -EINVAL; 768c2ecf20Sopenharmony_ci 778c2ecf20Sopenharmony_ci if (ctx->u.des3.mode != CCP_DES3_MODE_ECB) { 788c2ecf20Sopenharmony_ci if (!req->iv) 798c2ecf20Sopenharmony_ci return -EINVAL; 808c2ecf20Sopenharmony_ci 818c2ecf20Sopenharmony_ci memcpy(rctx->iv, req->iv, DES3_EDE_BLOCK_SIZE); 828c2ecf20Sopenharmony_ci iv_sg = &rctx->iv_sg; 838c2ecf20Sopenharmony_ci iv_len = DES3_EDE_BLOCK_SIZE; 848c2ecf20Sopenharmony_ci sg_init_one(iv_sg, rctx->iv, iv_len); 858c2ecf20Sopenharmony_ci } 868c2ecf20Sopenharmony_ci 878c2ecf20Sopenharmony_ci memset(&rctx->cmd, 0, sizeof(rctx->cmd)); 888c2ecf20Sopenharmony_ci INIT_LIST_HEAD(&rctx->cmd.entry); 898c2ecf20Sopenharmony_ci rctx->cmd.engine = CCP_ENGINE_DES3; 908c2ecf20Sopenharmony_ci rctx->cmd.u.des3.type = ctx->u.des3.type; 918c2ecf20Sopenharmony_ci rctx->cmd.u.des3.mode = ctx->u.des3.mode; 928c2ecf20Sopenharmony_ci rctx->cmd.u.des3.action = (encrypt) 938c2ecf20Sopenharmony_ci ? CCP_DES3_ACTION_ENCRYPT 948c2ecf20Sopenharmony_ci : CCP_DES3_ACTION_DECRYPT; 958c2ecf20Sopenharmony_ci rctx->cmd.u.des3.key = &ctx->u.des3.key_sg; 968c2ecf20Sopenharmony_ci rctx->cmd.u.des3.key_len = ctx->u.des3.key_len; 978c2ecf20Sopenharmony_ci rctx->cmd.u.des3.iv = iv_sg; 988c2ecf20Sopenharmony_ci rctx->cmd.u.des3.iv_len = iv_len; 998c2ecf20Sopenharmony_ci rctx->cmd.u.des3.src = req->src; 1008c2ecf20Sopenharmony_ci rctx->cmd.u.des3.src_len = req->cryptlen; 1018c2ecf20Sopenharmony_ci rctx->cmd.u.des3.dst = req->dst; 1028c2ecf20Sopenharmony_ci 1038c2ecf20Sopenharmony_ci ret = ccp_crypto_enqueue_request(&req->base, &rctx->cmd); 1048c2ecf20Sopenharmony_ci 1058c2ecf20Sopenharmony_ci return ret; 1068c2ecf20Sopenharmony_ci} 1078c2ecf20Sopenharmony_ci 1088c2ecf20Sopenharmony_cistatic int ccp_des3_encrypt(struct skcipher_request *req) 1098c2ecf20Sopenharmony_ci{ 1108c2ecf20Sopenharmony_ci return ccp_des3_crypt(req, true); 1118c2ecf20Sopenharmony_ci} 1128c2ecf20Sopenharmony_ci 1138c2ecf20Sopenharmony_cistatic int ccp_des3_decrypt(struct skcipher_request *req) 1148c2ecf20Sopenharmony_ci{ 1158c2ecf20Sopenharmony_ci return ccp_des3_crypt(req, false); 1168c2ecf20Sopenharmony_ci} 1178c2ecf20Sopenharmony_ci 1188c2ecf20Sopenharmony_cistatic int ccp_des3_init_tfm(struct crypto_skcipher *tfm) 1198c2ecf20Sopenharmony_ci{ 1208c2ecf20Sopenharmony_ci struct ccp_ctx *ctx = crypto_skcipher_ctx(tfm); 1218c2ecf20Sopenharmony_ci 1228c2ecf20Sopenharmony_ci ctx->complete = ccp_des3_complete; 1238c2ecf20Sopenharmony_ci ctx->u.des3.key_len = 0; 1248c2ecf20Sopenharmony_ci 1258c2ecf20Sopenharmony_ci crypto_skcipher_set_reqsize(tfm, sizeof(struct ccp_des3_req_ctx)); 1268c2ecf20Sopenharmony_ci 1278c2ecf20Sopenharmony_ci return 0; 1288c2ecf20Sopenharmony_ci} 1298c2ecf20Sopenharmony_ci 1308c2ecf20Sopenharmony_cistatic const struct skcipher_alg ccp_des3_defaults = { 1318c2ecf20Sopenharmony_ci .setkey = ccp_des3_setkey, 1328c2ecf20Sopenharmony_ci .encrypt = ccp_des3_encrypt, 1338c2ecf20Sopenharmony_ci .decrypt = ccp_des3_decrypt, 1348c2ecf20Sopenharmony_ci .min_keysize = DES3_EDE_KEY_SIZE, 1358c2ecf20Sopenharmony_ci .max_keysize = DES3_EDE_KEY_SIZE, 1368c2ecf20Sopenharmony_ci .init = ccp_des3_init_tfm, 1378c2ecf20Sopenharmony_ci 1388c2ecf20Sopenharmony_ci .base.cra_flags = CRYPTO_ALG_ASYNC | 1398c2ecf20Sopenharmony_ci CRYPTO_ALG_ALLOCATES_MEMORY | 1408c2ecf20Sopenharmony_ci CRYPTO_ALG_KERN_DRIVER_ONLY | 1418c2ecf20Sopenharmony_ci CRYPTO_ALG_NEED_FALLBACK, 1428c2ecf20Sopenharmony_ci .base.cra_blocksize = DES3_EDE_BLOCK_SIZE, 1438c2ecf20Sopenharmony_ci .base.cra_ctxsize = sizeof(struct ccp_ctx), 1448c2ecf20Sopenharmony_ci .base.cra_priority = CCP_CRA_PRIORITY, 1458c2ecf20Sopenharmony_ci .base.cra_module = THIS_MODULE, 1468c2ecf20Sopenharmony_ci}; 1478c2ecf20Sopenharmony_ci 1488c2ecf20Sopenharmony_cistruct ccp_des3_def { 1498c2ecf20Sopenharmony_ci enum ccp_des3_mode mode; 1508c2ecf20Sopenharmony_ci unsigned int version; 1518c2ecf20Sopenharmony_ci const char *name; 1528c2ecf20Sopenharmony_ci const char *driver_name; 1538c2ecf20Sopenharmony_ci unsigned int blocksize; 1548c2ecf20Sopenharmony_ci unsigned int ivsize; 1558c2ecf20Sopenharmony_ci const struct skcipher_alg *alg_defaults; 1568c2ecf20Sopenharmony_ci}; 1578c2ecf20Sopenharmony_ci 1588c2ecf20Sopenharmony_cistatic const struct ccp_des3_def des3_algs[] = { 1598c2ecf20Sopenharmony_ci { 1608c2ecf20Sopenharmony_ci .mode = CCP_DES3_MODE_ECB, 1618c2ecf20Sopenharmony_ci .version = CCP_VERSION(5, 0), 1628c2ecf20Sopenharmony_ci .name = "ecb(des3_ede)", 1638c2ecf20Sopenharmony_ci .driver_name = "ecb-des3-ccp", 1648c2ecf20Sopenharmony_ci .blocksize = DES3_EDE_BLOCK_SIZE, 1658c2ecf20Sopenharmony_ci .ivsize = 0, 1668c2ecf20Sopenharmony_ci .alg_defaults = &ccp_des3_defaults, 1678c2ecf20Sopenharmony_ci }, 1688c2ecf20Sopenharmony_ci { 1698c2ecf20Sopenharmony_ci .mode = CCP_DES3_MODE_CBC, 1708c2ecf20Sopenharmony_ci .version = CCP_VERSION(5, 0), 1718c2ecf20Sopenharmony_ci .name = "cbc(des3_ede)", 1728c2ecf20Sopenharmony_ci .driver_name = "cbc-des3-ccp", 1738c2ecf20Sopenharmony_ci .blocksize = DES3_EDE_BLOCK_SIZE, 1748c2ecf20Sopenharmony_ci .ivsize = DES3_EDE_BLOCK_SIZE, 1758c2ecf20Sopenharmony_ci .alg_defaults = &ccp_des3_defaults, 1768c2ecf20Sopenharmony_ci }, 1778c2ecf20Sopenharmony_ci}; 1788c2ecf20Sopenharmony_ci 1798c2ecf20Sopenharmony_cistatic int ccp_register_des3_alg(struct list_head *head, 1808c2ecf20Sopenharmony_ci const struct ccp_des3_def *def) 1818c2ecf20Sopenharmony_ci{ 1828c2ecf20Sopenharmony_ci struct ccp_crypto_skcipher_alg *ccp_alg; 1838c2ecf20Sopenharmony_ci struct skcipher_alg *alg; 1848c2ecf20Sopenharmony_ci int ret; 1858c2ecf20Sopenharmony_ci 1868c2ecf20Sopenharmony_ci ccp_alg = kzalloc(sizeof(*ccp_alg), GFP_KERNEL); 1878c2ecf20Sopenharmony_ci if (!ccp_alg) 1888c2ecf20Sopenharmony_ci return -ENOMEM; 1898c2ecf20Sopenharmony_ci 1908c2ecf20Sopenharmony_ci INIT_LIST_HEAD(&ccp_alg->entry); 1918c2ecf20Sopenharmony_ci 1928c2ecf20Sopenharmony_ci ccp_alg->mode = def->mode; 1938c2ecf20Sopenharmony_ci 1948c2ecf20Sopenharmony_ci /* Copy the defaults and override as necessary */ 1958c2ecf20Sopenharmony_ci alg = &ccp_alg->alg; 1968c2ecf20Sopenharmony_ci *alg = *def->alg_defaults; 1978c2ecf20Sopenharmony_ci snprintf(alg->base.cra_name, CRYPTO_MAX_ALG_NAME, "%s", def->name); 1988c2ecf20Sopenharmony_ci snprintf(alg->base.cra_driver_name, CRYPTO_MAX_ALG_NAME, "%s", 1998c2ecf20Sopenharmony_ci def->driver_name); 2008c2ecf20Sopenharmony_ci alg->base.cra_blocksize = def->blocksize; 2018c2ecf20Sopenharmony_ci alg->ivsize = def->ivsize; 2028c2ecf20Sopenharmony_ci 2038c2ecf20Sopenharmony_ci ret = crypto_register_skcipher(alg); 2048c2ecf20Sopenharmony_ci if (ret) { 2058c2ecf20Sopenharmony_ci pr_err("%s skcipher algorithm registration error (%d)\n", 2068c2ecf20Sopenharmony_ci alg->base.cra_name, ret); 2078c2ecf20Sopenharmony_ci kfree(ccp_alg); 2088c2ecf20Sopenharmony_ci return ret; 2098c2ecf20Sopenharmony_ci } 2108c2ecf20Sopenharmony_ci 2118c2ecf20Sopenharmony_ci list_add(&ccp_alg->entry, head); 2128c2ecf20Sopenharmony_ci 2138c2ecf20Sopenharmony_ci return 0; 2148c2ecf20Sopenharmony_ci} 2158c2ecf20Sopenharmony_ci 2168c2ecf20Sopenharmony_ciint ccp_register_des3_algs(struct list_head *head) 2178c2ecf20Sopenharmony_ci{ 2188c2ecf20Sopenharmony_ci int i, ret; 2198c2ecf20Sopenharmony_ci unsigned int ccpversion = ccp_version(); 2208c2ecf20Sopenharmony_ci 2218c2ecf20Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(des3_algs); i++) { 2228c2ecf20Sopenharmony_ci if (des3_algs[i].version > ccpversion) 2238c2ecf20Sopenharmony_ci continue; 2248c2ecf20Sopenharmony_ci ret = ccp_register_des3_alg(head, &des3_algs[i]); 2258c2ecf20Sopenharmony_ci if (ret) 2268c2ecf20Sopenharmony_ci return ret; 2278c2ecf20Sopenharmony_ci } 2288c2ecf20Sopenharmony_ci 2298c2ecf20Sopenharmony_ci return 0; 2308c2ecf20Sopenharmony_ci} 231