162306a36Sopenharmony_ci/* SPDX-License-Identifier: GPL-2.0-or-later */ 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * SM4 Cipher Algorithm, using ARMv8 Crypto Extensions 462306a36Sopenharmony_ci * as specified in 562306a36Sopenharmony_ci * https://tools.ietf.org/id/draft-ribose-cfrg-sm4-10.html 662306a36Sopenharmony_ci * 762306a36Sopenharmony_ci * Copyright (C) 2022, Alibaba Group. 862306a36Sopenharmony_ci * Copyright (C) 2022 Tianjia Zhang <tianjia.zhang@linux.alibaba.com> 962306a36Sopenharmony_ci */ 1062306a36Sopenharmony_ci 1162306a36Sopenharmony_ci#include <linux/module.h> 1262306a36Sopenharmony_ci#include <linux/crypto.h> 1362306a36Sopenharmony_ci#include <linux/kernel.h> 1462306a36Sopenharmony_ci#include <linux/cpufeature.h> 1562306a36Sopenharmony_ci#include <asm/neon.h> 1662306a36Sopenharmony_ci#include <asm/simd.h> 1762306a36Sopenharmony_ci#include <crypto/b128ops.h> 1862306a36Sopenharmony_ci#include <crypto/internal/simd.h> 1962306a36Sopenharmony_ci#include <crypto/internal/skcipher.h> 2062306a36Sopenharmony_ci#include <crypto/internal/hash.h> 2162306a36Sopenharmony_ci#include <crypto/scatterwalk.h> 2262306a36Sopenharmony_ci#include <crypto/xts.h> 2362306a36Sopenharmony_ci#include <crypto/sm4.h> 2462306a36Sopenharmony_ci 2562306a36Sopenharmony_ci#define BYTES2BLKS(nbytes) ((nbytes) >> 4) 2662306a36Sopenharmony_ci 2762306a36Sopenharmony_ciasmlinkage void sm4_ce_expand_key(const u8 *key, u32 *rkey_enc, u32 *rkey_dec, 2862306a36Sopenharmony_ci const u32 *fk, const u32 *ck); 2962306a36Sopenharmony_ciasmlinkage void sm4_ce_crypt_block(const u32 *rkey, u8 *dst, const u8 *src); 3062306a36Sopenharmony_ciasmlinkage void sm4_ce_crypt(const u32 *rkey, u8 *dst, const u8 *src, 3162306a36Sopenharmony_ci unsigned int nblks); 3262306a36Sopenharmony_ciasmlinkage void sm4_ce_cbc_enc(const u32 *rkey, u8 *dst, const u8 *src, 3362306a36Sopenharmony_ci u8 *iv, unsigned int nblocks); 3462306a36Sopenharmony_ciasmlinkage void sm4_ce_cbc_dec(const u32 *rkey, u8 *dst, const u8 *src, 3562306a36Sopenharmony_ci u8 *iv, unsigned int nblocks); 3662306a36Sopenharmony_ciasmlinkage void sm4_ce_cbc_cts_enc(const u32 *rkey, u8 *dst, const u8 *src, 3762306a36Sopenharmony_ci u8 *iv, unsigned int nbytes); 3862306a36Sopenharmony_ciasmlinkage void sm4_ce_cbc_cts_dec(const u32 *rkey, u8 *dst, const u8 *src, 3962306a36Sopenharmony_ci u8 *iv, unsigned int nbytes); 4062306a36Sopenharmony_ciasmlinkage void sm4_ce_cfb_enc(const u32 *rkey, u8 *dst, const u8 *src, 4162306a36Sopenharmony_ci u8 *iv, unsigned int nblks); 4262306a36Sopenharmony_ciasmlinkage void sm4_ce_cfb_dec(const u32 *rkey, u8 *dst, const u8 *src, 4362306a36Sopenharmony_ci u8 *iv, unsigned int nblks); 4462306a36Sopenharmony_ciasmlinkage void sm4_ce_ctr_enc(const u32 *rkey, u8 *dst, const u8 *src, 4562306a36Sopenharmony_ci u8 *iv, unsigned int nblks); 4662306a36Sopenharmony_ciasmlinkage void sm4_ce_xts_enc(const u32 *rkey1, u8 *dst, const u8 *src, 4762306a36Sopenharmony_ci u8 *tweak, unsigned int nbytes, 4862306a36Sopenharmony_ci const u32 *rkey2_enc); 4962306a36Sopenharmony_ciasmlinkage void sm4_ce_xts_dec(const u32 *rkey1, u8 *dst, const u8 *src, 5062306a36Sopenharmony_ci u8 *tweak, unsigned int nbytes, 5162306a36Sopenharmony_ci const u32 *rkey2_enc); 5262306a36Sopenharmony_ciasmlinkage void sm4_ce_mac_update(const u32 *rkey_enc, u8 *digest, 5362306a36Sopenharmony_ci const u8 *src, unsigned int nblocks, 5462306a36Sopenharmony_ci bool enc_before, bool enc_after); 5562306a36Sopenharmony_ci 5662306a36Sopenharmony_ciEXPORT_SYMBOL(sm4_ce_expand_key); 5762306a36Sopenharmony_ciEXPORT_SYMBOL(sm4_ce_crypt_block); 5862306a36Sopenharmony_ciEXPORT_SYMBOL(sm4_ce_cbc_enc); 5962306a36Sopenharmony_ciEXPORT_SYMBOL(sm4_ce_cfb_enc); 6062306a36Sopenharmony_ci 6162306a36Sopenharmony_cistruct sm4_xts_ctx { 6262306a36Sopenharmony_ci struct sm4_ctx key1; 6362306a36Sopenharmony_ci struct sm4_ctx key2; 6462306a36Sopenharmony_ci}; 6562306a36Sopenharmony_ci 6662306a36Sopenharmony_cistruct sm4_mac_tfm_ctx { 6762306a36Sopenharmony_ci struct sm4_ctx key; 6862306a36Sopenharmony_ci u8 __aligned(8) consts[]; 6962306a36Sopenharmony_ci}; 7062306a36Sopenharmony_ci 7162306a36Sopenharmony_cistruct sm4_mac_desc_ctx { 7262306a36Sopenharmony_ci unsigned int len; 7362306a36Sopenharmony_ci u8 digest[SM4_BLOCK_SIZE]; 7462306a36Sopenharmony_ci}; 7562306a36Sopenharmony_ci 7662306a36Sopenharmony_cistatic int sm4_setkey(struct crypto_skcipher *tfm, const u8 *key, 7762306a36Sopenharmony_ci unsigned int key_len) 7862306a36Sopenharmony_ci{ 7962306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 8062306a36Sopenharmony_ci 8162306a36Sopenharmony_ci if (key_len != SM4_KEY_SIZE) 8262306a36Sopenharmony_ci return -EINVAL; 8362306a36Sopenharmony_ci 8462306a36Sopenharmony_ci kernel_neon_begin(); 8562306a36Sopenharmony_ci sm4_ce_expand_key(key, ctx->rkey_enc, ctx->rkey_dec, 8662306a36Sopenharmony_ci crypto_sm4_fk, crypto_sm4_ck); 8762306a36Sopenharmony_ci kernel_neon_end(); 8862306a36Sopenharmony_ci return 0; 8962306a36Sopenharmony_ci} 9062306a36Sopenharmony_ci 9162306a36Sopenharmony_cistatic int sm4_xts_setkey(struct crypto_skcipher *tfm, const u8 *key, 9262306a36Sopenharmony_ci unsigned int key_len) 9362306a36Sopenharmony_ci{ 9462306a36Sopenharmony_ci struct sm4_xts_ctx *ctx = crypto_skcipher_ctx(tfm); 9562306a36Sopenharmony_ci int ret; 9662306a36Sopenharmony_ci 9762306a36Sopenharmony_ci if (key_len != SM4_KEY_SIZE * 2) 9862306a36Sopenharmony_ci return -EINVAL; 9962306a36Sopenharmony_ci 10062306a36Sopenharmony_ci ret = xts_verify_key(tfm, key, key_len); 10162306a36Sopenharmony_ci if (ret) 10262306a36Sopenharmony_ci return ret; 10362306a36Sopenharmony_ci 10462306a36Sopenharmony_ci kernel_neon_begin(); 10562306a36Sopenharmony_ci sm4_ce_expand_key(key, ctx->key1.rkey_enc, 10662306a36Sopenharmony_ci ctx->key1.rkey_dec, crypto_sm4_fk, crypto_sm4_ck); 10762306a36Sopenharmony_ci sm4_ce_expand_key(&key[SM4_KEY_SIZE], ctx->key2.rkey_enc, 10862306a36Sopenharmony_ci ctx->key2.rkey_dec, crypto_sm4_fk, crypto_sm4_ck); 10962306a36Sopenharmony_ci kernel_neon_end(); 11062306a36Sopenharmony_ci 11162306a36Sopenharmony_ci return 0; 11262306a36Sopenharmony_ci} 11362306a36Sopenharmony_ci 11462306a36Sopenharmony_cistatic int sm4_ecb_do_crypt(struct skcipher_request *req, const u32 *rkey) 11562306a36Sopenharmony_ci{ 11662306a36Sopenharmony_ci struct skcipher_walk walk; 11762306a36Sopenharmony_ci unsigned int nbytes; 11862306a36Sopenharmony_ci int err; 11962306a36Sopenharmony_ci 12062306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, req, false); 12162306a36Sopenharmony_ci 12262306a36Sopenharmony_ci while ((nbytes = walk.nbytes) > 0) { 12362306a36Sopenharmony_ci const u8 *src = walk.src.virt.addr; 12462306a36Sopenharmony_ci u8 *dst = walk.dst.virt.addr; 12562306a36Sopenharmony_ci unsigned int nblks; 12662306a36Sopenharmony_ci 12762306a36Sopenharmony_ci kernel_neon_begin(); 12862306a36Sopenharmony_ci 12962306a36Sopenharmony_ci nblks = BYTES2BLKS(nbytes); 13062306a36Sopenharmony_ci if (nblks) { 13162306a36Sopenharmony_ci sm4_ce_crypt(rkey, dst, src, nblks); 13262306a36Sopenharmony_ci nbytes -= nblks * SM4_BLOCK_SIZE; 13362306a36Sopenharmony_ci } 13462306a36Sopenharmony_ci 13562306a36Sopenharmony_ci kernel_neon_end(); 13662306a36Sopenharmony_ci 13762306a36Sopenharmony_ci err = skcipher_walk_done(&walk, nbytes); 13862306a36Sopenharmony_ci } 13962306a36Sopenharmony_ci 14062306a36Sopenharmony_ci return err; 14162306a36Sopenharmony_ci} 14262306a36Sopenharmony_ci 14362306a36Sopenharmony_cistatic int sm4_ecb_encrypt(struct skcipher_request *req) 14462306a36Sopenharmony_ci{ 14562306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 14662306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 14762306a36Sopenharmony_ci 14862306a36Sopenharmony_ci return sm4_ecb_do_crypt(req, ctx->rkey_enc); 14962306a36Sopenharmony_ci} 15062306a36Sopenharmony_ci 15162306a36Sopenharmony_cistatic int sm4_ecb_decrypt(struct skcipher_request *req) 15262306a36Sopenharmony_ci{ 15362306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 15462306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 15562306a36Sopenharmony_ci 15662306a36Sopenharmony_ci return sm4_ecb_do_crypt(req, ctx->rkey_dec); 15762306a36Sopenharmony_ci} 15862306a36Sopenharmony_ci 15962306a36Sopenharmony_cistatic int sm4_cbc_crypt(struct skcipher_request *req, 16062306a36Sopenharmony_ci struct sm4_ctx *ctx, bool encrypt) 16162306a36Sopenharmony_ci{ 16262306a36Sopenharmony_ci struct skcipher_walk walk; 16362306a36Sopenharmony_ci unsigned int nbytes; 16462306a36Sopenharmony_ci int err; 16562306a36Sopenharmony_ci 16662306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, req, false); 16762306a36Sopenharmony_ci if (err) 16862306a36Sopenharmony_ci return err; 16962306a36Sopenharmony_ci 17062306a36Sopenharmony_ci while ((nbytes = walk.nbytes) > 0) { 17162306a36Sopenharmony_ci const u8 *src = walk.src.virt.addr; 17262306a36Sopenharmony_ci u8 *dst = walk.dst.virt.addr; 17362306a36Sopenharmony_ci unsigned int nblocks; 17462306a36Sopenharmony_ci 17562306a36Sopenharmony_ci nblocks = nbytes / SM4_BLOCK_SIZE; 17662306a36Sopenharmony_ci if (nblocks) { 17762306a36Sopenharmony_ci kernel_neon_begin(); 17862306a36Sopenharmony_ci 17962306a36Sopenharmony_ci if (encrypt) 18062306a36Sopenharmony_ci sm4_ce_cbc_enc(ctx->rkey_enc, dst, src, 18162306a36Sopenharmony_ci walk.iv, nblocks); 18262306a36Sopenharmony_ci else 18362306a36Sopenharmony_ci sm4_ce_cbc_dec(ctx->rkey_dec, dst, src, 18462306a36Sopenharmony_ci walk.iv, nblocks); 18562306a36Sopenharmony_ci 18662306a36Sopenharmony_ci kernel_neon_end(); 18762306a36Sopenharmony_ci } 18862306a36Sopenharmony_ci 18962306a36Sopenharmony_ci err = skcipher_walk_done(&walk, nbytes % SM4_BLOCK_SIZE); 19062306a36Sopenharmony_ci } 19162306a36Sopenharmony_ci 19262306a36Sopenharmony_ci return err; 19362306a36Sopenharmony_ci} 19462306a36Sopenharmony_ci 19562306a36Sopenharmony_cistatic int sm4_cbc_encrypt(struct skcipher_request *req) 19662306a36Sopenharmony_ci{ 19762306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 19862306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 19962306a36Sopenharmony_ci 20062306a36Sopenharmony_ci return sm4_cbc_crypt(req, ctx, true); 20162306a36Sopenharmony_ci} 20262306a36Sopenharmony_ci 20362306a36Sopenharmony_cistatic int sm4_cbc_decrypt(struct skcipher_request *req) 20462306a36Sopenharmony_ci{ 20562306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 20662306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 20762306a36Sopenharmony_ci 20862306a36Sopenharmony_ci return sm4_cbc_crypt(req, ctx, false); 20962306a36Sopenharmony_ci} 21062306a36Sopenharmony_ci 21162306a36Sopenharmony_cistatic int sm4_cbc_cts_crypt(struct skcipher_request *req, bool encrypt) 21262306a36Sopenharmony_ci{ 21362306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 21462306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 21562306a36Sopenharmony_ci struct scatterlist *src = req->src; 21662306a36Sopenharmony_ci struct scatterlist *dst = req->dst; 21762306a36Sopenharmony_ci struct scatterlist sg_src[2], sg_dst[2]; 21862306a36Sopenharmony_ci struct skcipher_request subreq; 21962306a36Sopenharmony_ci struct skcipher_walk walk; 22062306a36Sopenharmony_ci int cbc_blocks; 22162306a36Sopenharmony_ci int err; 22262306a36Sopenharmony_ci 22362306a36Sopenharmony_ci if (req->cryptlen < SM4_BLOCK_SIZE) 22462306a36Sopenharmony_ci return -EINVAL; 22562306a36Sopenharmony_ci 22662306a36Sopenharmony_ci if (req->cryptlen == SM4_BLOCK_SIZE) 22762306a36Sopenharmony_ci return sm4_cbc_crypt(req, ctx, encrypt); 22862306a36Sopenharmony_ci 22962306a36Sopenharmony_ci skcipher_request_set_tfm(&subreq, tfm); 23062306a36Sopenharmony_ci skcipher_request_set_callback(&subreq, skcipher_request_flags(req), 23162306a36Sopenharmony_ci NULL, NULL); 23262306a36Sopenharmony_ci 23362306a36Sopenharmony_ci /* handle the CBC cryption part */ 23462306a36Sopenharmony_ci cbc_blocks = DIV_ROUND_UP(req->cryptlen, SM4_BLOCK_SIZE) - 2; 23562306a36Sopenharmony_ci if (cbc_blocks) { 23662306a36Sopenharmony_ci skcipher_request_set_crypt(&subreq, src, dst, 23762306a36Sopenharmony_ci cbc_blocks * SM4_BLOCK_SIZE, 23862306a36Sopenharmony_ci req->iv); 23962306a36Sopenharmony_ci 24062306a36Sopenharmony_ci err = sm4_cbc_crypt(&subreq, ctx, encrypt); 24162306a36Sopenharmony_ci if (err) 24262306a36Sopenharmony_ci return err; 24362306a36Sopenharmony_ci 24462306a36Sopenharmony_ci dst = src = scatterwalk_ffwd(sg_src, src, subreq.cryptlen); 24562306a36Sopenharmony_ci if (req->dst != req->src) 24662306a36Sopenharmony_ci dst = scatterwalk_ffwd(sg_dst, req->dst, 24762306a36Sopenharmony_ci subreq.cryptlen); 24862306a36Sopenharmony_ci } 24962306a36Sopenharmony_ci 25062306a36Sopenharmony_ci /* handle ciphertext stealing */ 25162306a36Sopenharmony_ci skcipher_request_set_crypt(&subreq, src, dst, 25262306a36Sopenharmony_ci req->cryptlen - cbc_blocks * SM4_BLOCK_SIZE, 25362306a36Sopenharmony_ci req->iv); 25462306a36Sopenharmony_ci 25562306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, &subreq, false); 25662306a36Sopenharmony_ci if (err) 25762306a36Sopenharmony_ci return err; 25862306a36Sopenharmony_ci 25962306a36Sopenharmony_ci kernel_neon_begin(); 26062306a36Sopenharmony_ci 26162306a36Sopenharmony_ci if (encrypt) 26262306a36Sopenharmony_ci sm4_ce_cbc_cts_enc(ctx->rkey_enc, walk.dst.virt.addr, 26362306a36Sopenharmony_ci walk.src.virt.addr, walk.iv, walk.nbytes); 26462306a36Sopenharmony_ci else 26562306a36Sopenharmony_ci sm4_ce_cbc_cts_dec(ctx->rkey_dec, walk.dst.virt.addr, 26662306a36Sopenharmony_ci walk.src.virt.addr, walk.iv, walk.nbytes); 26762306a36Sopenharmony_ci 26862306a36Sopenharmony_ci kernel_neon_end(); 26962306a36Sopenharmony_ci 27062306a36Sopenharmony_ci return skcipher_walk_done(&walk, 0); 27162306a36Sopenharmony_ci} 27262306a36Sopenharmony_ci 27362306a36Sopenharmony_cistatic int sm4_cbc_cts_encrypt(struct skcipher_request *req) 27462306a36Sopenharmony_ci{ 27562306a36Sopenharmony_ci return sm4_cbc_cts_crypt(req, true); 27662306a36Sopenharmony_ci} 27762306a36Sopenharmony_ci 27862306a36Sopenharmony_cistatic int sm4_cbc_cts_decrypt(struct skcipher_request *req) 27962306a36Sopenharmony_ci{ 28062306a36Sopenharmony_ci return sm4_cbc_cts_crypt(req, false); 28162306a36Sopenharmony_ci} 28262306a36Sopenharmony_ci 28362306a36Sopenharmony_cistatic int sm4_cfb_encrypt(struct skcipher_request *req) 28462306a36Sopenharmony_ci{ 28562306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 28662306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 28762306a36Sopenharmony_ci struct skcipher_walk walk; 28862306a36Sopenharmony_ci unsigned int nbytes; 28962306a36Sopenharmony_ci int err; 29062306a36Sopenharmony_ci 29162306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, req, false); 29262306a36Sopenharmony_ci 29362306a36Sopenharmony_ci while ((nbytes = walk.nbytes) > 0) { 29462306a36Sopenharmony_ci const u8 *src = walk.src.virt.addr; 29562306a36Sopenharmony_ci u8 *dst = walk.dst.virt.addr; 29662306a36Sopenharmony_ci unsigned int nblks; 29762306a36Sopenharmony_ci 29862306a36Sopenharmony_ci kernel_neon_begin(); 29962306a36Sopenharmony_ci 30062306a36Sopenharmony_ci nblks = BYTES2BLKS(nbytes); 30162306a36Sopenharmony_ci if (nblks) { 30262306a36Sopenharmony_ci sm4_ce_cfb_enc(ctx->rkey_enc, dst, src, walk.iv, nblks); 30362306a36Sopenharmony_ci dst += nblks * SM4_BLOCK_SIZE; 30462306a36Sopenharmony_ci src += nblks * SM4_BLOCK_SIZE; 30562306a36Sopenharmony_ci nbytes -= nblks * SM4_BLOCK_SIZE; 30662306a36Sopenharmony_ci } 30762306a36Sopenharmony_ci 30862306a36Sopenharmony_ci /* tail */ 30962306a36Sopenharmony_ci if (walk.nbytes == walk.total && nbytes > 0) { 31062306a36Sopenharmony_ci u8 keystream[SM4_BLOCK_SIZE]; 31162306a36Sopenharmony_ci 31262306a36Sopenharmony_ci sm4_ce_crypt_block(ctx->rkey_enc, keystream, walk.iv); 31362306a36Sopenharmony_ci crypto_xor_cpy(dst, src, keystream, nbytes); 31462306a36Sopenharmony_ci nbytes = 0; 31562306a36Sopenharmony_ci } 31662306a36Sopenharmony_ci 31762306a36Sopenharmony_ci kernel_neon_end(); 31862306a36Sopenharmony_ci 31962306a36Sopenharmony_ci err = skcipher_walk_done(&walk, nbytes); 32062306a36Sopenharmony_ci } 32162306a36Sopenharmony_ci 32262306a36Sopenharmony_ci return err; 32362306a36Sopenharmony_ci} 32462306a36Sopenharmony_ci 32562306a36Sopenharmony_cistatic int sm4_cfb_decrypt(struct skcipher_request *req) 32662306a36Sopenharmony_ci{ 32762306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 32862306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 32962306a36Sopenharmony_ci struct skcipher_walk walk; 33062306a36Sopenharmony_ci unsigned int nbytes; 33162306a36Sopenharmony_ci int err; 33262306a36Sopenharmony_ci 33362306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, req, false); 33462306a36Sopenharmony_ci 33562306a36Sopenharmony_ci while ((nbytes = walk.nbytes) > 0) { 33662306a36Sopenharmony_ci const u8 *src = walk.src.virt.addr; 33762306a36Sopenharmony_ci u8 *dst = walk.dst.virt.addr; 33862306a36Sopenharmony_ci unsigned int nblks; 33962306a36Sopenharmony_ci 34062306a36Sopenharmony_ci kernel_neon_begin(); 34162306a36Sopenharmony_ci 34262306a36Sopenharmony_ci nblks = BYTES2BLKS(nbytes); 34362306a36Sopenharmony_ci if (nblks) { 34462306a36Sopenharmony_ci sm4_ce_cfb_dec(ctx->rkey_enc, dst, src, walk.iv, nblks); 34562306a36Sopenharmony_ci dst += nblks * SM4_BLOCK_SIZE; 34662306a36Sopenharmony_ci src += nblks * SM4_BLOCK_SIZE; 34762306a36Sopenharmony_ci nbytes -= nblks * SM4_BLOCK_SIZE; 34862306a36Sopenharmony_ci } 34962306a36Sopenharmony_ci 35062306a36Sopenharmony_ci /* tail */ 35162306a36Sopenharmony_ci if (walk.nbytes == walk.total && nbytes > 0) { 35262306a36Sopenharmony_ci u8 keystream[SM4_BLOCK_SIZE]; 35362306a36Sopenharmony_ci 35462306a36Sopenharmony_ci sm4_ce_crypt_block(ctx->rkey_enc, keystream, walk.iv); 35562306a36Sopenharmony_ci crypto_xor_cpy(dst, src, keystream, nbytes); 35662306a36Sopenharmony_ci nbytes = 0; 35762306a36Sopenharmony_ci } 35862306a36Sopenharmony_ci 35962306a36Sopenharmony_ci kernel_neon_end(); 36062306a36Sopenharmony_ci 36162306a36Sopenharmony_ci err = skcipher_walk_done(&walk, nbytes); 36262306a36Sopenharmony_ci } 36362306a36Sopenharmony_ci 36462306a36Sopenharmony_ci return err; 36562306a36Sopenharmony_ci} 36662306a36Sopenharmony_ci 36762306a36Sopenharmony_cistatic int sm4_ctr_crypt(struct skcipher_request *req) 36862306a36Sopenharmony_ci{ 36962306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 37062306a36Sopenharmony_ci struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm); 37162306a36Sopenharmony_ci struct skcipher_walk walk; 37262306a36Sopenharmony_ci unsigned int nbytes; 37362306a36Sopenharmony_ci int err; 37462306a36Sopenharmony_ci 37562306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, req, false); 37662306a36Sopenharmony_ci 37762306a36Sopenharmony_ci while ((nbytes = walk.nbytes) > 0) { 37862306a36Sopenharmony_ci const u8 *src = walk.src.virt.addr; 37962306a36Sopenharmony_ci u8 *dst = walk.dst.virt.addr; 38062306a36Sopenharmony_ci unsigned int nblks; 38162306a36Sopenharmony_ci 38262306a36Sopenharmony_ci kernel_neon_begin(); 38362306a36Sopenharmony_ci 38462306a36Sopenharmony_ci nblks = BYTES2BLKS(nbytes); 38562306a36Sopenharmony_ci if (nblks) { 38662306a36Sopenharmony_ci sm4_ce_ctr_enc(ctx->rkey_enc, dst, src, walk.iv, nblks); 38762306a36Sopenharmony_ci dst += nblks * SM4_BLOCK_SIZE; 38862306a36Sopenharmony_ci src += nblks * SM4_BLOCK_SIZE; 38962306a36Sopenharmony_ci nbytes -= nblks * SM4_BLOCK_SIZE; 39062306a36Sopenharmony_ci } 39162306a36Sopenharmony_ci 39262306a36Sopenharmony_ci /* tail */ 39362306a36Sopenharmony_ci if (walk.nbytes == walk.total && nbytes > 0) { 39462306a36Sopenharmony_ci u8 keystream[SM4_BLOCK_SIZE]; 39562306a36Sopenharmony_ci 39662306a36Sopenharmony_ci sm4_ce_crypt_block(ctx->rkey_enc, keystream, walk.iv); 39762306a36Sopenharmony_ci crypto_inc(walk.iv, SM4_BLOCK_SIZE); 39862306a36Sopenharmony_ci crypto_xor_cpy(dst, src, keystream, nbytes); 39962306a36Sopenharmony_ci nbytes = 0; 40062306a36Sopenharmony_ci } 40162306a36Sopenharmony_ci 40262306a36Sopenharmony_ci kernel_neon_end(); 40362306a36Sopenharmony_ci 40462306a36Sopenharmony_ci err = skcipher_walk_done(&walk, nbytes); 40562306a36Sopenharmony_ci } 40662306a36Sopenharmony_ci 40762306a36Sopenharmony_ci return err; 40862306a36Sopenharmony_ci} 40962306a36Sopenharmony_ci 41062306a36Sopenharmony_cistatic int sm4_xts_crypt(struct skcipher_request *req, bool encrypt) 41162306a36Sopenharmony_ci{ 41262306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 41362306a36Sopenharmony_ci struct sm4_xts_ctx *ctx = crypto_skcipher_ctx(tfm); 41462306a36Sopenharmony_ci int tail = req->cryptlen % SM4_BLOCK_SIZE; 41562306a36Sopenharmony_ci const u32 *rkey2_enc = ctx->key2.rkey_enc; 41662306a36Sopenharmony_ci struct scatterlist sg_src[2], sg_dst[2]; 41762306a36Sopenharmony_ci struct skcipher_request subreq; 41862306a36Sopenharmony_ci struct scatterlist *src, *dst; 41962306a36Sopenharmony_ci struct skcipher_walk walk; 42062306a36Sopenharmony_ci unsigned int nbytes; 42162306a36Sopenharmony_ci int err; 42262306a36Sopenharmony_ci 42362306a36Sopenharmony_ci if (req->cryptlen < SM4_BLOCK_SIZE) 42462306a36Sopenharmony_ci return -EINVAL; 42562306a36Sopenharmony_ci 42662306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, req, false); 42762306a36Sopenharmony_ci if (err) 42862306a36Sopenharmony_ci return err; 42962306a36Sopenharmony_ci 43062306a36Sopenharmony_ci if (unlikely(tail > 0 && walk.nbytes < walk.total)) { 43162306a36Sopenharmony_ci int nblocks = DIV_ROUND_UP(req->cryptlen, SM4_BLOCK_SIZE) - 2; 43262306a36Sopenharmony_ci 43362306a36Sopenharmony_ci skcipher_walk_abort(&walk); 43462306a36Sopenharmony_ci 43562306a36Sopenharmony_ci skcipher_request_set_tfm(&subreq, tfm); 43662306a36Sopenharmony_ci skcipher_request_set_callback(&subreq, 43762306a36Sopenharmony_ci skcipher_request_flags(req), 43862306a36Sopenharmony_ci NULL, NULL); 43962306a36Sopenharmony_ci skcipher_request_set_crypt(&subreq, req->src, req->dst, 44062306a36Sopenharmony_ci nblocks * SM4_BLOCK_SIZE, req->iv); 44162306a36Sopenharmony_ci 44262306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, &subreq, false); 44362306a36Sopenharmony_ci if (err) 44462306a36Sopenharmony_ci return err; 44562306a36Sopenharmony_ci } else { 44662306a36Sopenharmony_ci tail = 0; 44762306a36Sopenharmony_ci } 44862306a36Sopenharmony_ci 44962306a36Sopenharmony_ci while ((nbytes = walk.nbytes) >= SM4_BLOCK_SIZE) { 45062306a36Sopenharmony_ci if (nbytes < walk.total) 45162306a36Sopenharmony_ci nbytes &= ~(SM4_BLOCK_SIZE - 1); 45262306a36Sopenharmony_ci 45362306a36Sopenharmony_ci kernel_neon_begin(); 45462306a36Sopenharmony_ci 45562306a36Sopenharmony_ci if (encrypt) 45662306a36Sopenharmony_ci sm4_ce_xts_enc(ctx->key1.rkey_enc, walk.dst.virt.addr, 45762306a36Sopenharmony_ci walk.src.virt.addr, walk.iv, nbytes, 45862306a36Sopenharmony_ci rkey2_enc); 45962306a36Sopenharmony_ci else 46062306a36Sopenharmony_ci sm4_ce_xts_dec(ctx->key1.rkey_dec, walk.dst.virt.addr, 46162306a36Sopenharmony_ci walk.src.virt.addr, walk.iv, nbytes, 46262306a36Sopenharmony_ci rkey2_enc); 46362306a36Sopenharmony_ci 46462306a36Sopenharmony_ci kernel_neon_end(); 46562306a36Sopenharmony_ci 46662306a36Sopenharmony_ci rkey2_enc = NULL; 46762306a36Sopenharmony_ci 46862306a36Sopenharmony_ci err = skcipher_walk_done(&walk, walk.nbytes - nbytes); 46962306a36Sopenharmony_ci if (err) 47062306a36Sopenharmony_ci return err; 47162306a36Sopenharmony_ci } 47262306a36Sopenharmony_ci 47362306a36Sopenharmony_ci if (likely(tail == 0)) 47462306a36Sopenharmony_ci return 0; 47562306a36Sopenharmony_ci 47662306a36Sopenharmony_ci /* handle ciphertext stealing */ 47762306a36Sopenharmony_ci 47862306a36Sopenharmony_ci dst = src = scatterwalk_ffwd(sg_src, req->src, subreq.cryptlen); 47962306a36Sopenharmony_ci if (req->dst != req->src) 48062306a36Sopenharmony_ci dst = scatterwalk_ffwd(sg_dst, req->dst, subreq.cryptlen); 48162306a36Sopenharmony_ci 48262306a36Sopenharmony_ci skcipher_request_set_crypt(&subreq, src, dst, SM4_BLOCK_SIZE + tail, 48362306a36Sopenharmony_ci req->iv); 48462306a36Sopenharmony_ci 48562306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, &subreq, false); 48662306a36Sopenharmony_ci if (err) 48762306a36Sopenharmony_ci return err; 48862306a36Sopenharmony_ci 48962306a36Sopenharmony_ci kernel_neon_begin(); 49062306a36Sopenharmony_ci 49162306a36Sopenharmony_ci if (encrypt) 49262306a36Sopenharmony_ci sm4_ce_xts_enc(ctx->key1.rkey_enc, walk.dst.virt.addr, 49362306a36Sopenharmony_ci walk.src.virt.addr, walk.iv, walk.nbytes, 49462306a36Sopenharmony_ci rkey2_enc); 49562306a36Sopenharmony_ci else 49662306a36Sopenharmony_ci sm4_ce_xts_dec(ctx->key1.rkey_dec, walk.dst.virt.addr, 49762306a36Sopenharmony_ci walk.src.virt.addr, walk.iv, walk.nbytes, 49862306a36Sopenharmony_ci rkey2_enc); 49962306a36Sopenharmony_ci 50062306a36Sopenharmony_ci kernel_neon_end(); 50162306a36Sopenharmony_ci 50262306a36Sopenharmony_ci return skcipher_walk_done(&walk, 0); 50362306a36Sopenharmony_ci} 50462306a36Sopenharmony_ci 50562306a36Sopenharmony_cistatic int sm4_xts_encrypt(struct skcipher_request *req) 50662306a36Sopenharmony_ci{ 50762306a36Sopenharmony_ci return sm4_xts_crypt(req, true); 50862306a36Sopenharmony_ci} 50962306a36Sopenharmony_ci 51062306a36Sopenharmony_cistatic int sm4_xts_decrypt(struct skcipher_request *req) 51162306a36Sopenharmony_ci{ 51262306a36Sopenharmony_ci return sm4_xts_crypt(req, false); 51362306a36Sopenharmony_ci} 51462306a36Sopenharmony_ci 51562306a36Sopenharmony_cistatic struct skcipher_alg sm4_algs[] = { 51662306a36Sopenharmony_ci { 51762306a36Sopenharmony_ci .base = { 51862306a36Sopenharmony_ci .cra_name = "ecb(sm4)", 51962306a36Sopenharmony_ci .cra_driver_name = "ecb-sm4-ce", 52062306a36Sopenharmony_ci .cra_priority = 400, 52162306a36Sopenharmony_ci .cra_blocksize = SM4_BLOCK_SIZE, 52262306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_ctx), 52362306a36Sopenharmony_ci .cra_module = THIS_MODULE, 52462306a36Sopenharmony_ci }, 52562306a36Sopenharmony_ci .min_keysize = SM4_KEY_SIZE, 52662306a36Sopenharmony_ci .max_keysize = SM4_KEY_SIZE, 52762306a36Sopenharmony_ci .setkey = sm4_setkey, 52862306a36Sopenharmony_ci .encrypt = sm4_ecb_encrypt, 52962306a36Sopenharmony_ci .decrypt = sm4_ecb_decrypt, 53062306a36Sopenharmony_ci }, { 53162306a36Sopenharmony_ci .base = { 53262306a36Sopenharmony_ci .cra_name = "cbc(sm4)", 53362306a36Sopenharmony_ci .cra_driver_name = "cbc-sm4-ce", 53462306a36Sopenharmony_ci .cra_priority = 400, 53562306a36Sopenharmony_ci .cra_blocksize = SM4_BLOCK_SIZE, 53662306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_ctx), 53762306a36Sopenharmony_ci .cra_module = THIS_MODULE, 53862306a36Sopenharmony_ci }, 53962306a36Sopenharmony_ci .min_keysize = SM4_KEY_SIZE, 54062306a36Sopenharmony_ci .max_keysize = SM4_KEY_SIZE, 54162306a36Sopenharmony_ci .ivsize = SM4_BLOCK_SIZE, 54262306a36Sopenharmony_ci .setkey = sm4_setkey, 54362306a36Sopenharmony_ci .encrypt = sm4_cbc_encrypt, 54462306a36Sopenharmony_ci .decrypt = sm4_cbc_decrypt, 54562306a36Sopenharmony_ci }, { 54662306a36Sopenharmony_ci .base = { 54762306a36Sopenharmony_ci .cra_name = "cfb(sm4)", 54862306a36Sopenharmony_ci .cra_driver_name = "cfb-sm4-ce", 54962306a36Sopenharmony_ci .cra_priority = 400, 55062306a36Sopenharmony_ci .cra_blocksize = 1, 55162306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_ctx), 55262306a36Sopenharmony_ci .cra_module = THIS_MODULE, 55362306a36Sopenharmony_ci }, 55462306a36Sopenharmony_ci .min_keysize = SM4_KEY_SIZE, 55562306a36Sopenharmony_ci .max_keysize = SM4_KEY_SIZE, 55662306a36Sopenharmony_ci .ivsize = SM4_BLOCK_SIZE, 55762306a36Sopenharmony_ci .chunksize = SM4_BLOCK_SIZE, 55862306a36Sopenharmony_ci .setkey = sm4_setkey, 55962306a36Sopenharmony_ci .encrypt = sm4_cfb_encrypt, 56062306a36Sopenharmony_ci .decrypt = sm4_cfb_decrypt, 56162306a36Sopenharmony_ci }, { 56262306a36Sopenharmony_ci .base = { 56362306a36Sopenharmony_ci .cra_name = "ctr(sm4)", 56462306a36Sopenharmony_ci .cra_driver_name = "ctr-sm4-ce", 56562306a36Sopenharmony_ci .cra_priority = 400, 56662306a36Sopenharmony_ci .cra_blocksize = 1, 56762306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_ctx), 56862306a36Sopenharmony_ci .cra_module = THIS_MODULE, 56962306a36Sopenharmony_ci }, 57062306a36Sopenharmony_ci .min_keysize = SM4_KEY_SIZE, 57162306a36Sopenharmony_ci .max_keysize = SM4_KEY_SIZE, 57262306a36Sopenharmony_ci .ivsize = SM4_BLOCK_SIZE, 57362306a36Sopenharmony_ci .chunksize = SM4_BLOCK_SIZE, 57462306a36Sopenharmony_ci .setkey = sm4_setkey, 57562306a36Sopenharmony_ci .encrypt = sm4_ctr_crypt, 57662306a36Sopenharmony_ci .decrypt = sm4_ctr_crypt, 57762306a36Sopenharmony_ci }, { 57862306a36Sopenharmony_ci .base = { 57962306a36Sopenharmony_ci .cra_name = "cts(cbc(sm4))", 58062306a36Sopenharmony_ci .cra_driver_name = "cts-cbc-sm4-ce", 58162306a36Sopenharmony_ci .cra_priority = 400, 58262306a36Sopenharmony_ci .cra_blocksize = SM4_BLOCK_SIZE, 58362306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_ctx), 58462306a36Sopenharmony_ci .cra_module = THIS_MODULE, 58562306a36Sopenharmony_ci }, 58662306a36Sopenharmony_ci .min_keysize = SM4_KEY_SIZE, 58762306a36Sopenharmony_ci .max_keysize = SM4_KEY_SIZE, 58862306a36Sopenharmony_ci .ivsize = SM4_BLOCK_SIZE, 58962306a36Sopenharmony_ci .walksize = SM4_BLOCK_SIZE * 2, 59062306a36Sopenharmony_ci .setkey = sm4_setkey, 59162306a36Sopenharmony_ci .encrypt = sm4_cbc_cts_encrypt, 59262306a36Sopenharmony_ci .decrypt = sm4_cbc_cts_decrypt, 59362306a36Sopenharmony_ci }, { 59462306a36Sopenharmony_ci .base = { 59562306a36Sopenharmony_ci .cra_name = "xts(sm4)", 59662306a36Sopenharmony_ci .cra_driver_name = "xts-sm4-ce", 59762306a36Sopenharmony_ci .cra_priority = 400, 59862306a36Sopenharmony_ci .cra_blocksize = SM4_BLOCK_SIZE, 59962306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_xts_ctx), 60062306a36Sopenharmony_ci .cra_module = THIS_MODULE, 60162306a36Sopenharmony_ci }, 60262306a36Sopenharmony_ci .min_keysize = SM4_KEY_SIZE * 2, 60362306a36Sopenharmony_ci .max_keysize = SM4_KEY_SIZE * 2, 60462306a36Sopenharmony_ci .ivsize = SM4_BLOCK_SIZE, 60562306a36Sopenharmony_ci .walksize = SM4_BLOCK_SIZE * 2, 60662306a36Sopenharmony_ci .setkey = sm4_xts_setkey, 60762306a36Sopenharmony_ci .encrypt = sm4_xts_encrypt, 60862306a36Sopenharmony_ci .decrypt = sm4_xts_decrypt, 60962306a36Sopenharmony_ci } 61062306a36Sopenharmony_ci}; 61162306a36Sopenharmony_ci 61262306a36Sopenharmony_cistatic int sm4_cbcmac_setkey(struct crypto_shash *tfm, const u8 *key, 61362306a36Sopenharmony_ci unsigned int key_len) 61462306a36Sopenharmony_ci{ 61562306a36Sopenharmony_ci struct sm4_mac_tfm_ctx *ctx = crypto_shash_ctx(tfm); 61662306a36Sopenharmony_ci 61762306a36Sopenharmony_ci if (key_len != SM4_KEY_SIZE) 61862306a36Sopenharmony_ci return -EINVAL; 61962306a36Sopenharmony_ci 62062306a36Sopenharmony_ci kernel_neon_begin(); 62162306a36Sopenharmony_ci sm4_ce_expand_key(key, ctx->key.rkey_enc, ctx->key.rkey_dec, 62262306a36Sopenharmony_ci crypto_sm4_fk, crypto_sm4_ck); 62362306a36Sopenharmony_ci kernel_neon_end(); 62462306a36Sopenharmony_ci 62562306a36Sopenharmony_ci return 0; 62662306a36Sopenharmony_ci} 62762306a36Sopenharmony_ci 62862306a36Sopenharmony_cistatic int sm4_cmac_setkey(struct crypto_shash *tfm, const u8 *key, 62962306a36Sopenharmony_ci unsigned int key_len) 63062306a36Sopenharmony_ci{ 63162306a36Sopenharmony_ci struct sm4_mac_tfm_ctx *ctx = crypto_shash_ctx(tfm); 63262306a36Sopenharmony_ci be128 *consts = (be128 *)ctx->consts; 63362306a36Sopenharmony_ci u64 a, b; 63462306a36Sopenharmony_ci 63562306a36Sopenharmony_ci if (key_len != SM4_KEY_SIZE) 63662306a36Sopenharmony_ci return -EINVAL; 63762306a36Sopenharmony_ci 63862306a36Sopenharmony_ci memset(consts, 0, SM4_BLOCK_SIZE); 63962306a36Sopenharmony_ci 64062306a36Sopenharmony_ci kernel_neon_begin(); 64162306a36Sopenharmony_ci 64262306a36Sopenharmony_ci sm4_ce_expand_key(key, ctx->key.rkey_enc, ctx->key.rkey_dec, 64362306a36Sopenharmony_ci crypto_sm4_fk, crypto_sm4_ck); 64462306a36Sopenharmony_ci 64562306a36Sopenharmony_ci /* encrypt the zero block */ 64662306a36Sopenharmony_ci sm4_ce_crypt_block(ctx->key.rkey_enc, (u8 *)consts, (const u8 *)consts); 64762306a36Sopenharmony_ci 64862306a36Sopenharmony_ci kernel_neon_end(); 64962306a36Sopenharmony_ci 65062306a36Sopenharmony_ci /* gf(2^128) multiply zero-ciphertext with u and u^2 */ 65162306a36Sopenharmony_ci a = be64_to_cpu(consts[0].a); 65262306a36Sopenharmony_ci b = be64_to_cpu(consts[0].b); 65362306a36Sopenharmony_ci consts[0].a = cpu_to_be64((a << 1) | (b >> 63)); 65462306a36Sopenharmony_ci consts[0].b = cpu_to_be64((b << 1) ^ ((a >> 63) ? 0x87 : 0)); 65562306a36Sopenharmony_ci 65662306a36Sopenharmony_ci a = be64_to_cpu(consts[0].a); 65762306a36Sopenharmony_ci b = be64_to_cpu(consts[0].b); 65862306a36Sopenharmony_ci consts[1].a = cpu_to_be64((a << 1) | (b >> 63)); 65962306a36Sopenharmony_ci consts[1].b = cpu_to_be64((b << 1) ^ ((a >> 63) ? 0x87 : 0)); 66062306a36Sopenharmony_ci 66162306a36Sopenharmony_ci return 0; 66262306a36Sopenharmony_ci} 66362306a36Sopenharmony_ci 66462306a36Sopenharmony_cistatic int sm4_xcbc_setkey(struct crypto_shash *tfm, const u8 *key, 66562306a36Sopenharmony_ci unsigned int key_len) 66662306a36Sopenharmony_ci{ 66762306a36Sopenharmony_ci struct sm4_mac_tfm_ctx *ctx = crypto_shash_ctx(tfm); 66862306a36Sopenharmony_ci u8 __aligned(8) key2[SM4_BLOCK_SIZE]; 66962306a36Sopenharmony_ci static u8 const ks[3][SM4_BLOCK_SIZE] = { 67062306a36Sopenharmony_ci { [0 ... SM4_BLOCK_SIZE - 1] = 0x1}, 67162306a36Sopenharmony_ci { [0 ... SM4_BLOCK_SIZE - 1] = 0x2}, 67262306a36Sopenharmony_ci { [0 ... SM4_BLOCK_SIZE - 1] = 0x3}, 67362306a36Sopenharmony_ci }; 67462306a36Sopenharmony_ci 67562306a36Sopenharmony_ci if (key_len != SM4_KEY_SIZE) 67662306a36Sopenharmony_ci return -EINVAL; 67762306a36Sopenharmony_ci 67862306a36Sopenharmony_ci kernel_neon_begin(); 67962306a36Sopenharmony_ci 68062306a36Sopenharmony_ci sm4_ce_expand_key(key, ctx->key.rkey_enc, ctx->key.rkey_dec, 68162306a36Sopenharmony_ci crypto_sm4_fk, crypto_sm4_ck); 68262306a36Sopenharmony_ci 68362306a36Sopenharmony_ci sm4_ce_crypt_block(ctx->key.rkey_enc, key2, ks[0]); 68462306a36Sopenharmony_ci sm4_ce_crypt(ctx->key.rkey_enc, ctx->consts, ks[1], 2); 68562306a36Sopenharmony_ci 68662306a36Sopenharmony_ci sm4_ce_expand_key(key2, ctx->key.rkey_enc, ctx->key.rkey_dec, 68762306a36Sopenharmony_ci crypto_sm4_fk, crypto_sm4_ck); 68862306a36Sopenharmony_ci 68962306a36Sopenharmony_ci kernel_neon_end(); 69062306a36Sopenharmony_ci 69162306a36Sopenharmony_ci return 0; 69262306a36Sopenharmony_ci} 69362306a36Sopenharmony_ci 69462306a36Sopenharmony_cistatic int sm4_mac_init(struct shash_desc *desc) 69562306a36Sopenharmony_ci{ 69662306a36Sopenharmony_ci struct sm4_mac_desc_ctx *ctx = shash_desc_ctx(desc); 69762306a36Sopenharmony_ci 69862306a36Sopenharmony_ci memset(ctx->digest, 0, SM4_BLOCK_SIZE); 69962306a36Sopenharmony_ci ctx->len = 0; 70062306a36Sopenharmony_ci 70162306a36Sopenharmony_ci return 0; 70262306a36Sopenharmony_ci} 70362306a36Sopenharmony_ci 70462306a36Sopenharmony_cistatic int sm4_mac_update(struct shash_desc *desc, const u8 *p, 70562306a36Sopenharmony_ci unsigned int len) 70662306a36Sopenharmony_ci{ 70762306a36Sopenharmony_ci struct sm4_mac_tfm_ctx *tctx = crypto_shash_ctx(desc->tfm); 70862306a36Sopenharmony_ci struct sm4_mac_desc_ctx *ctx = shash_desc_ctx(desc); 70962306a36Sopenharmony_ci unsigned int l, nblocks; 71062306a36Sopenharmony_ci 71162306a36Sopenharmony_ci if (len == 0) 71262306a36Sopenharmony_ci return 0; 71362306a36Sopenharmony_ci 71462306a36Sopenharmony_ci if (ctx->len || ctx->len + len < SM4_BLOCK_SIZE) { 71562306a36Sopenharmony_ci l = min(len, SM4_BLOCK_SIZE - ctx->len); 71662306a36Sopenharmony_ci 71762306a36Sopenharmony_ci crypto_xor(ctx->digest + ctx->len, p, l); 71862306a36Sopenharmony_ci ctx->len += l; 71962306a36Sopenharmony_ci len -= l; 72062306a36Sopenharmony_ci p += l; 72162306a36Sopenharmony_ci } 72262306a36Sopenharmony_ci 72362306a36Sopenharmony_ci if (len && (ctx->len % SM4_BLOCK_SIZE) == 0) { 72462306a36Sopenharmony_ci kernel_neon_begin(); 72562306a36Sopenharmony_ci 72662306a36Sopenharmony_ci if (len < SM4_BLOCK_SIZE && ctx->len == SM4_BLOCK_SIZE) { 72762306a36Sopenharmony_ci sm4_ce_crypt_block(tctx->key.rkey_enc, 72862306a36Sopenharmony_ci ctx->digest, ctx->digest); 72962306a36Sopenharmony_ci ctx->len = 0; 73062306a36Sopenharmony_ci } else { 73162306a36Sopenharmony_ci nblocks = len / SM4_BLOCK_SIZE; 73262306a36Sopenharmony_ci len %= SM4_BLOCK_SIZE; 73362306a36Sopenharmony_ci 73462306a36Sopenharmony_ci sm4_ce_mac_update(tctx->key.rkey_enc, ctx->digest, p, 73562306a36Sopenharmony_ci nblocks, (ctx->len == SM4_BLOCK_SIZE), 73662306a36Sopenharmony_ci (len != 0)); 73762306a36Sopenharmony_ci 73862306a36Sopenharmony_ci p += nblocks * SM4_BLOCK_SIZE; 73962306a36Sopenharmony_ci 74062306a36Sopenharmony_ci if (len == 0) 74162306a36Sopenharmony_ci ctx->len = SM4_BLOCK_SIZE; 74262306a36Sopenharmony_ci } 74362306a36Sopenharmony_ci 74462306a36Sopenharmony_ci kernel_neon_end(); 74562306a36Sopenharmony_ci 74662306a36Sopenharmony_ci if (len) { 74762306a36Sopenharmony_ci crypto_xor(ctx->digest, p, len); 74862306a36Sopenharmony_ci ctx->len = len; 74962306a36Sopenharmony_ci } 75062306a36Sopenharmony_ci } 75162306a36Sopenharmony_ci 75262306a36Sopenharmony_ci return 0; 75362306a36Sopenharmony_ci} 75462306a36Sopenharmony_ci 75562306a36Sopenharmony_cistatic int sm4_cmac_final(struct shash_desc *desc, u8 *out) 75662306a36Sopenharmony_ci{ 75762306a36Sopenharmony_ci struct sm4_mac_tfm_ctx *tctx = crypto_shash_ctx(desc->tfm); 75862306a36Sopenharmony_ci struct sm4_mac_desc_ctx *ctx = shash_desc_ctx(desc); 75962306a36Sopenharmony_ci const u8 *consts = tctx->consts; 76062306a36Sopenharmony_ci 76162306a36Sopenharmony_ci if (ctx->len != SM4_BLOCK_SIZE) { 76262306a36Sopenharmony_ci ctx->digest[ctx->len] ^= 0x80; 76362306a36Sopenharmony_ci consts += SM4_BLOCK_SIZE; 76462306a36Sopenharmony_ci } 76562306a36Sopenharmony_ci 76662306a36Sopenharmony_ci kernel_neon_begin(); 76762306a36Sopenharmony_ci sm4_ce_mac_update(tctx->key.rkey_enc, ctx->digest, consts, 1, 76862306a36Sopenharmony_ci false, true); 76962306a36Sopenharmony_ci kernel_neon_end(); 77062306a36Sopenharmony_ci 77162306a36Sopenharmony_ci memcpy(out, ctx->digest, SM4_BLOCK_SIZE); 77262306a36Sopenharmony_ci 77362306a36Sopenharmony_ci return 0; 77462306a36Sopenharmony_ci} 77562306a36Sopenharmony_ci 77662306a36Sopenharmony_cistatic int sm4_cbcmac_final(struct shash_desc *desc, u8 *out) 77762306a36Sopenharmony_ci{ 77862306a36Sopenharmony_ci struct sm4_mac_tfm_ctx *tctx = crypto_shash_ctx(desc->tfm); 77962306a36Sopenharmony_ci struct sm4_mac_desc_ctx *ctx = shash_desc_ctx(desc); 78062306a36Sopenharmony_ci 78162306a36Sopenharmony_ci if (ctx->len) { 78262306a36Sopenharmony_ci kernel_neon_begin(); 78362306a36Sopenharmony_ci sm4_ce_crypt_block(tctx->key.rkey_enc, ctx->digest, 78462306a36Sopenharmony_ci ctx->digest); 78562306a36Sopenharmony_ci kernel_neon_end(); 78662306a36Sopenharmony_ci } 78762306a36Sopenharmony_ci 78862306a36Sopenharmony_ci memcpy(out, ctx->digest, SM4_BLOCK_SIZE); 78962306a36Sopenharmony_ci 79062306a36Sopenharmony_ci return 0; 79162306a36Sopenharmony_ci} 79262306a36Sopenharmony_ci 79362306a36Sopenharmony_cistatic struct shash_alg sm4_mac_algs[] = { 79462306a36Sopenharmony_ci { 79562306a36Sopenharmony_ci .base = { 79662306a36Sopenharmony_ci .cra_name = "cmac(sm4)", 79762306a36Sopenharmony_ci .cra_driver_name = "cmac-sm4-ce", 79862306a36Sopenharmony_ci .cra_priority = 400, 79962306a36Sopenharmony_ci .cra_blocksize = SM4_BLOCK_SIZE, 80062306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_mac_tfm_ctx) 80162306a36Sopenharmony_ci + SM4_BLOCK_SIZE * 2, 80262306a36Sopenharmony_ci .cra_module = THIS_MODULE, 80362306a36Sopenharmony_ci }, 80462306a36Sopenharmony_ci .digestsize = SM4_BLOCK_SIZE, 80562306a36Sopenharmony_ci .init = sm4_mac_init, 80662306a36Sopenharmony_ci .update = sm4_mac_update, 80762306a36Sopenharmony_ci .final = sm4_cmac_final, 80862306a36Sopenharmony_ci .setkey = sm4_cmac_setkey, 80962306a36Sopenharmony_ci .descsize = sizeof(struct sm4_mac_desc_ctx), 81062306a36Sopenharmony_ci }, { 81162306a36Sopenharmony_ci .base = { 81262306a36Sopenharmony_ci .cra_name = "xcbc(sm4)", 81362306a36Sopenharmony_ci .cra_driver_name = "xcbc-sm4-ce", 81462306a36Sopenharmony_ci .cra_priority = 400, 81562306a36Sopenharmony_ci .cra_blocksize = SM4_BLOCK_SIZE, 81662306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_mac_tfm_ctx) 81762306a36Sopenharmony_ci + SM4_BLOCK_SIZE * 2, 81862306a36Sopenharmony_ci .cra_module = THIS_MODULE, 81962306a36Sopenharmony_ci }, 82062306a36Sopenharmony_ci .digestsize = SM4_BLOCK_SIZE, 82162306a36Sopenharmony_ci .init = sm4_mac_init, 82262306a36Sopenharmony_ci .update = sm4_mac_update, 82362306a36Sopenharmony_ci .final = sm4_cmac_final, 82462306a36Sopenharmony_ci .setkey = sm4_xcbc_setkey, 82562306a36Sopenharmony_ci .descsize = sizeof(struct sm4_mac_desc_ctx), 82662306a36Sopenharmony_ci }, { 82762306a36Sopenharmony_ci .base = { 82862306a36Sopenharmony_ci .cra_name = "cbcmac(sm4)", 82962306a36Sopenharmony_ci .cra_driver_name = "cbcmac-sm4-ce", 83062306a36Sopenharmony_ci .cra_priority = 400, 83162306a36Sopenharmony_ci .cra_blocksize = 1, 83262306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct sm4_mac_tfm_ctx), 83362306a36Sopenharmony_ci .cra_module = THIS_MODULE, 83462306a36Sopenharmony_ci }, 83562306a36Sopenharmony_ci .digestsize = SM4_BLOCK_SIZE, 83662306a36Sopenharmony_ci .init = sm4_mac_init, 83762306a36Sopenharmony_ci .update = sm4_mac_update, 83862306a36Sopenharmony_ci .final = sm4_cbcmac_final, 83962306a36Sopenharmony_ci .setkey = sm4_cbcmac_setkey, 84062306a36Sopenharmony_ci .descsize = sizeof(struct sm4_mac_desc_ctx), 84162306a36Sopenharmony_ci } 84262306a36Sopenharmony_ci}; 84362306a36Sopenharmony_ci 84462306a36Sopenharmony_cistatic int __init sm4_init(void) 84562306a36Sopenharmony_ci{ 84662306a36Sopenharmony_ci int err; 84762306a36Sopenharmony_ci 84862306a36Sopenharmony_ci err = crypto_register_skciphers(sm4_algs, ARRAY_SIZE(sm4_algs)); 84962306a36Sopenharmony_ci if (err) 85062306a36Sopenharmony_ci return err; 85162306a36Sopenharmony_ci 85262306a36Sopenharmony_ci err = crypto_register_shashes(sm4_mac_algs, ARRAY_SIZE(sm4_mac_algs)); 85362306a36Sopenharmony_ci if (err) 85462306a36Sopenharmony_ci goto out_err; 85562306a36Sopenharmony_ci 85662306a36Sopenharmony_ci return 0; 85762306a36Sopenharmony_ci 85862306a36Sopenharmony_ciout_err: 85962306a36Sopenharmony_ci crypto_unregister_skciphers(sm4_algs, ARRAY_SIZE(sm4_algs)); 86062306a36Sopenharmony_ci return err; 86162306a36Sopenharmony_ci} 86262306a36Sopenharmony_ci 86362306a36Sopenharmony_cistatic void __exit sm4_exit(void) 86462306a36Sopenharmony_ci{ 86562306a36Sopenharmony_ci crypto_unregister_shashes(sm4_mac_algs, ARRAY_SIZE(sm4_mac_algs)); 86662306a36Sopenharmony_ci crypto_unregister_skciphers(sm4_algs, ARRAY_SIZE(sm4_algs)); 86762306a36Sopenharmony_ci} 86862306a36Sopenharmony_ci 86962306a36Sopenharmony_cimodule_cpu_feature_match(SM4, sm4_init); 87062306a36Sopenharmony_cimodule_exit(sm4_exit); 87162306a36Sopenharmony_ci 87262306a36Sopenharmony_ciMODULE_DESCRIPTION("SM4 ECB/CBC/CFB/CTR/XTS using ARMv8 Crypto Extensions"); 87362306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("sm4-ce"); 87462306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("sm4"); 87562306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ecb(sm4)"); 87662306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cbc(sm4)"); 87762306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cfb(sm4)"); 87862306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ctr(sm4)"); 87962306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cts(cbc(sm4))"); 88062306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("xts(sm4)"); 88162306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cmac(sm4)"); 88262306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("xcbc(sm4)"); 88362306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cbcmac(sm4)"); 88462306a36Sopenharmony_ciMODULE_AUTHOR("Tianjia Zhang <tianjia.zhang@linux.alibaba.com>"); 88562306a36Sopenharmony_ciMODULE_LICENSE("GPL v2"); 886