162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * The AEGIS-128 Authenticated-Encryption Algorithm 462306a36Sopenharmony_ci * Glue for AES-NI + SSE2 implementation 562306a36Sopenharmony_ci * 662306a36Sopenharmony_ci * Copyright (c) 2017-2018 Ondrej Mosnacek <omosnacek@gmail.com> 762306a36Sopenharmony_ci * Copyright (C) 2017-2018 Red Hat, Inc. All rights reserved. 862306a36Sopenharmony_ci */ 962306a36Sopenharmony_ci 1062306a36Sopenharmony_ci#include <crypto/internal/aead.h> 1162306a36Sopenharmony_ci#include <crypto/internal/simd.h> 1262306a36Sopenharmony_ci#include <crypto/internal/skcipher.h> 1362306a36Sopenharmony_ci#include <crypto/scatterwalk.h> 1462306a36Sopenharmony_ci#include <linux/module.h> 1562306a36Sopenharmony_ci#include <asm/fpu/api.h> 1662306a36Sopenharmony_ci#include <asm/cpu_device_id.h> 1762306a36Sopenharmony_ci 1862306a36Sopenharmony_ci#define AEGIS128_BLOCK_ALIGN 16 1962306a36Sopenharmony_ci#define AEGIS128_BLOCK_SIZE 16 2062306a36Sopenharmony_ci#define AEGIS128_NONCE_SIZE 16 2162306a36Sopenharmony_ci#define AEGIS128_STATE_BLOCKS 5 2262306a36Sopenharmony_ci#define AEGIS128_KEY_SIZE 16 2362306a36Sopenharmony_ci#define AEGIS128_MIN_AUTH_SIZE 8 2462306a36Sopenharmony_ci#define AEGIS128_MAX_AUTH_SIZE 16 2562306a36Sopenharmony_ci 2662306a36Sopenharmony_ciasmlinkage void crypto_aegis128_aesni_init(void *state, void *key, void *iv); 2762306a36Sopenharmony_ci 2862306a36Sopenharmony_ciasmlinkage void crypto_aegis128_aesni_ad( 2962306a36Sopenharmony_ci void *state, unsigned int length, const void *data); 3062306a36Sopenharmony_ci 3162306a36Sopenharmony_ciasmlinkage void crypto_aegis128_aesni_enc( 3262306a36Sopenharmony_ci void *state, unsigned int length, const void *src, void *dst); 3362306a36Sopenharmony_ci 3462306a36Sopenharmony_ciasmlinkage void crypto_aegis128_aesni_dec( 3562306a36Sopenharmony_ci void *state, unsigned int length, const void *src, void *dst); 3662306a36Sopenharmony_ci 3762306a36Sopenharmony_ciasmlinkage void crypto_aegis128_aesni_enc_tail( 3862306a36Sopenharmony_ci void *state, unsigned int length, const void *src, void *dst); 3962306a36Sopenharmony_ci 4062306a36Sopenharmony_ciasmlinkage void crypto_aegis128_aesni_dec_tail( 4162306a36Sopenharmony_ci void *state, unsigned int length, const void *src, void *dst); 4262306a36Sopenharmony_ci 4362306a36Sopenharmony_ciasmlinkage void crypto_aegis128_aesni_final( 4462306a36Sopenharmony_ci void *state, void *tag_xor, unsigned int cryptlen, 4562306a36Sopenharmony_ci unsigned int assoclen); 4662306a36Sopenharmony_ci 4762306a36Sopenharmony_cistruct aegis_block { 4862306a36Sopenharmony_ci u8 bytes[AEGIS128_BLOCK_SIZE] __aligned(AEGIS128_BLOCK_ALIGN); 4962306a36Sopenharmony_ci}; 5062306a36Sopenharmony_ci 5162306a36Sopenharmony_cistruct aegis_state { 5262306a36Sopenharmony_ci struct aegis_block blocks[AEGIS128_STATE_BLOCKS]; 5362306a36Sopenharmony_ci}; 5462306a36Sopenharmony_ci 5562306a36Sopenharmony_cistruct aegis_ctx { 5662306a36Sopenharmony_ci struct aegis_block key; 5762306a36Sopenharmony_ci}; 5862306a36Sopenharmony_ci 5962306a36Sopenharmony_cistruct aegis_crypt_ops { 6062306a36Sopenharmony_ci int (*skcipher_walk_init)(struct skcipher_walk *walk, 6162306a36Sopenharmony_ci struct aead_request *req, bool atomic); 6262306a36Sopenharmony_ci 6362306a36Sopenharmony_ci void (*crypt_blocks)(void *state, unsigned int length, const void *src, 6462306a36Sopenharmony_ci void *dst); 6562306a36Sopenharmony_ci void (*crypt_tail)(void *state, unsigned int length, const void *src, 6662306a36Sopenharmony_ci void *dst); 6762306a36Sopenharmony_ci}; 6862306a36Sopenharmony_ci 6962306a36Sopenharmony_cistatic void crypto_aegis128_aesni_process_ad( 7062306a36Sopenharmony_ci struct aegis_state *state, struct scatterlist *sg_src, 7162306a36Sopenharmony_ci unsigned int assoclen) 7262306a36Sopenharmony_ci{ 7362306a36Sopenharmony_ci struct scatter_walk walk; 7462306a36Sopenharmony_ci struct aegis_block buf; 7562306a36Sopenharmony_ci unsigned int pos = 0; 7662306a36Sopenharmony_ci 7762306a36Sopenharmony_ci scatterwalk_start(&walk, sg_src); 7862306a36Sopenharmony_ci while (assoclen != 0) { 7962306a36Sopenharmony_ci unsigned int size = scatterwalk_clamp(&walk, assoclen); 8062306a36Sopenharmony_ci unsigned int left = size; 8162306a36Sopenharmony_ci void *mapped = scatterwalk_map(&walk); 8262306a36Sopenharmony_ci const u8 *src = (const u8 *)mapped; 8362306a36Sopenharmony_ci 8462306a36Sopenharmony_ci if (pos + size >= AEGIS128_BLOCK_SIZE) { 8562306a36Sopenharmony_ci if (pos > 0) { 8662306a36Sopenharmony_ci unsigned int fill = AEGIS128_BLOCK_SIZE - pos; 8762306a36Sopenharmony_ci memcpy(buf.bytes + pos, src, fill); 8862306a36Sopenharmony_ci crypto_aegis128_aesni_ad(state, 8962306a36Sopenharmony_ci AEGIS128_BLOCK_SIZE, 9062306a36Sopenharmony_ci buf.bytes); 9162306a36Sopenharmony_ci pos = 0; 9262306a36Sopenharmony_ci left -= fill; 9362306a36Sopenharmony_ci src += fill; 9462306a36Sopenharmony_ci } 9562306a36Sopenharmony_ci 9662306a36Sopenharmony_ci crypto_aegis128_aesni_ad(state, left, src); 9762306a36Sopenharmony_ci 9862306a36Sopenharmony_ci src += left & ~(AEGIS128_BLOCK_SIZE - 1); 9962306a36Sopenharmony_ci left &= AEGIS128_BLOCK_SIZE - 1; 10062306a36Sopenharmony_ci } 10162306a36Sopenharmony_ci 10262306a36Sopenharmony_ci memcpy(buf.bytes + pos, src, left); 10362306a36Sopenharmony_ci pos += left; 10462306a36Sopenharmony_ci assoclen -= size; 10562306a36Sopenharmony_ci 10662306a36Sopenharmony_ci scatterwalk_unmap(mapped); 10762306a36Sopenharmony_ci scatterwalk_advance(&walk, size); 10862306a36Sopenharmony_ci scatterwalk_done(&walk, 0, assoclen); 10962306a36Sopenharmony_ci } 11062306a36Sopenharmony_ci 11162306a36Sopenharmony_ci if (pos > 0) { 11262306a36Sopenharmony_ci memset(buf.bytes + pos, 0, AEGIS128_BLOCK_SIZE - pos); 11362306a36Sopenharmony_ci crypto_aegis128_aesni_ad(state, AEGIS128_BLOCK_SIZE, buf.bytes); 11462306a36Sopenharmony_ci } 11562306a36Sopenharmony_ci} 11662306a36Sopenharmony_ci 11762306a36Sopenharmony_cistatic void crypto_aegis128_aesni_process_crypt( 11862306a36Sopenharmony_ci struct aegis_state *state, struct skcipher_walk *walk, 11962306a36Sopenharmony_ci const struct aegis_crypt_ops *ops) 12062306a36Sopenharmony_ci{ 12162306a36Sopenharmony_ci while (walk->nbytes >= AEGIS128_BLOCK_SIZE) { 12262306a36Sopenharmony_ci ops->crypt_blocks(state, 12362306a36Sopenharmony_ci round_down(walk->nbytes, AEGIS128_BLOCK_SIZE), 12462306a36Sopenharmony_ci walk->src.virt.addr, walk->dst.virt.addr); 12562306a36Sopenharmony_ci skcipher_walk_done(walk, walk->nbytes % AEGIS128_BLOCK_SIZE); 12662306a36Sopenharmony_ci } 12762306a36Sopenharmony_ci 12862306a36Sopenharmony_ci if (walk->nbytes) { 12962306a36Sopenharmony_ci ops->crypt_tail(state, walk->nbytes, walk->src.virt.addr, 13062306a36Sopenharmony_ci walk->dst.virt.addr); 13162306a36Sopenharmony_ci skcipher_walk_done(walk, 0); 13262306a36Sopenharmony_ci } 13362306a36Sopenharmony_ci} 13462306a36Sopenharmony_ci 13562306a36Sopenharmony_cistatic struct aegis_ctx *crypto_aegis128_aesni_ctx(struct crypto_aead *aead) 13662306a36Sopenharmony_ci{ 13762306a36Sopenharmony_ci u8 *ctx = crypto_aead_ctx(aead); 13862306a36Sopenharmony_ci ctx = PTR_ALIGN(ctx, __alignof__(struct aegis_ctx)); 13962306a36Sopenharmony_ci return (void *)ctx; 14062306a36Sopenharmony_ci} 14162306a36Sopenharmony_ci 14262306a36Sopenharmony_cistatic int crypto_aegis128_aesni_setkey(struct crypto_aead *aead, const u8 *key, 14362306a36Sopenharmony_ci unsigned int keylen) 14462306a36Sopenharmony_ci{ 14562306a36Sopenharmony_ci struct aegis_ctx *ctx = crypto_aegis128_aesni_ctx(aead); 14662306a36Sopenharmony_ci 14762306a36Sopenharmony_ci if (keylen != AEGIS128_KEY_SIZE) 14862306a36Sopenharmony_ci return -EINVAL; 14962306a36Sopenharmony_ci 15062306a36Sopenharmony_ci memcpy(ctx->key.bytes, key, AEGIS128_KEY_SIZE); 15162306a36Sopenharmony_ci 15262306a36Sopenharmony_ci return 0; 15362306a36Sopenharmony_ci} 15462306a36Sopenharmony_ci 15562306a36Sopenharmony_cistatic int crypto_aegis128_aesni_setauthsize(struct crypto_aead *tfm, 15662306a36Sopenharmony_ci unsigned int authsize) 15762306a36Sopenharmony_ci{ 15862306a36Sopenharmony_ci if (authsize > AEGIS128_MAX_AUTH_SIZE) 15962306a36Sopenharmony_ci return -EINVAL; 16062306a36Sopenharmony_ci if (authsize < AEGIS128_MIN_AUTH_SIZE) 16162306a36Sopenharmony_ci return -EINVAL; 16262306a36Sopenharmony_ci return 0; 16362306a36Sopenharmony_ci} 16462306a36Sopenharmony_ci 16562306a36Sopenharmony_cistatic void crypto_aegis128_aesni_crypt(struct aead_request *req, 16662306a36Sopenharmony_ci struct aegis_block *tag_xor, 16762306a36Sopenharmony_ci unsigned int cryptlen, 16862306a36Sopenharmony_ci const struct aegis_crypt_ops *ops) 16962306a36Sopenharmony_ci{ 17062306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 17162306a36Sopenharmony_ci struct aegis_ctx *ctx = crypto_aegis128_aesni_ctx(tfm); 17262306a36Sopenharmony_ci struct skcipher_walk walk; 17362306a36Sopenharmony_ci struct aegis_state state; 17462306a36Sopenharmony_ci 17562306a36Sopenharmony_ci ops->skcipher_walk_init(&walk, req, true); 17662306a36Sopenharmony_ci 17762306a36Sopenharmony_ci kernel_fpu_begin(); 17862306a36Sopenharmony_ci 17962306a36Sopenharmony_ci crypto_aegis128_aesni_init(&state, ctx->key.bytes, req->iv); 18062306a36Sopenharmony_ci crypto_aegis128_aesni_process_ad(&state, req->src, req->assoclen); 18162306a36Sopenharmony_ci crypto_aegis128_aesni_process_crypt(&state, &walk, ops); 18262306a36Sopenharmony_ci crypto_aegis128_aesni_final(&state, tag_xor, req->assoclen, cryptlen); 18362306a36Sopenharmony_ci 18462306a36Sopenharmony_ci kernel_fpu_end(); 18562306a36Sopenharmony_ci} 18662306a36Sopenharmony_ci 18762306a36Sopenharmony_cistatic int crypto_aegis128_aesni_encrypt(struct aead_request *req) 18862306a36Sopenharmony_ci{ 18962306a36Sopenharmony_ci static const struct aegis_crypt_ops OPS = { 19062306a36Sopenharmony_ci .skcipher_walk_init = skcipher_walk_aead_encrypt, 19162306a36Sopenharmony_ci .crypt_blocks = crypto_aegis128_aesni_enc, 19262306a36Sopenharmony_ci .crypt_tail = crypto_aegis128_aesni_enc_tail, 19362306a36Sopenharmony_ci }; 19462306a36Sopenharmony_ci 19562306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 19662306a36Sopenharmony_ci struct aegis_block tag = {}; 19762306a36Sopenharmony_ci unsigned int authsize = crypto_aead_authsize(tfm); 19862306a36Sopenharmony_ci unsigned int cryptlen = req->cryptlen; 19962306a36Sopenharmony_ci 20062306a36Sopenharmony_ci crypto_aegis128_aesni_crypt(req, &tag, cryptlen, &OPS); 20162306a36Sopenharmony_ci 20262306a36Sopenharmony_ci scatterwalk_map_and_copy(tag.bytes, req->dst, 20362306a36Sopenharmony_ci req->assoclen + cryptlen, authsize, 1); 20462306a36Sopenharmony_ci return 0; 20562306a36Sopenharmony_ci} 20662306a36Sopenharmony_ci 20762306a36Sopenharmony_cistatic int crypto_aegis128_aesni_decrypt(struct aead_request *req) 20862306a36Sopenharmony_ci{ 20962306a36Sopenharmony_ci static const struct aegis_block zeros = {}; 21062306a36Sopenharmony_ci 21162306a36Sopenharmony_ci static const struct aegis_crypt_ops OPS = { 21262306a36Sopenharmony_ci .skcipher_walk_init = skcipher_walk_aead_decrypt, 21362306a36Sopenharmony_ci .crypt_blocks = crypto_aegis128_aesni_dec, 21462306a36Sopenharmony_ci .crypt_tail = crypto_aegis128_aesni_dec_tail, 21562306a36Sopenharmony_ci }; 21662306a36Sopenharmony_ci 21762306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 21862306a36Sopenharmony_ci struct aegis_block tag; 21962306a36Sopenharmony_ci unsigned int authsize = crypto_aead_authsize(tfm); 22062306a36Sopenharmony_ci unsigned int cryptlen = req->cryptlen - authsize; 22162306a36Sopenharmony_ci 22262306a36Sopenharmony_ci scatterwalk_map_and_copy(tag.bytes, req->src, 22362306a36Sopenharmony_ci req->assoclen + cryptlen, authsize, 0); 22462306a36Sopenharmony_ci 22562306a36Sopenharmony_ci crypto_aegis128_aesni_crypt(req, &tag, cryptlen, &OPS); 22662306a36Sopenharmony_ci 22762306a36Sopenharmony_ci return crypto_memneq(tag.bytes, zeros.bytes, authsize) ? -EBADMSG : 0; 22862306a36Sopenharmony_ci} 22962306a36Sopenharmony_ci 23062306a36Sopenharmony_cistatic int crypto_aegis128_aesni_init_tfm(struct crypto_aead *aead) 23162306a36Sopenharmony_ci{ 23262306a36Sopenharmony_ci return 0; 23362306a36Sopenharmony_ci} 23462306a36Sopenharmony_ci 23562306a36Sopenharmony_cistatic void crypto_aegis128_aesni_exit_tfm(struct crypto_aead *aead) 23662306a36Sopenharmony_ci{ 23762306a36Sopenharmony_ci} 23862306a36Sopenharmony_ci 23962306a36Sopenharmony_cistatic struct aead_alg crypto_aegis128_aesni_alg = { 24062306a36Sopenharmony_ci .setkey = crypto_aegis128_aesni_setkey, 24162306a36Sopenharmony_ci .setauthsize = crypto_aegis128_aesni_setauthsize, 24262306a36Sopenharmony_ci .encrypt = crypto_aegis128_aesni_encrypt, 24362306a36Sopenharmony_ci .decrypt = crypto_aegis128_aesni_decrypt, 24462306a36Sopenharmony_ci .init = crypto_aegis128_aesni_init_tfm, 24562306a36Sopenharmony_ci .exit = crypto_aegis128_aesni_exit_tfm, 24662306a36Sopenharmony_ci 24762306a36Sopenharmony_ci .ivsize = AEGIS128_NONCE_SIZE, 24862306a36Sopenharmony_ci .maxauthsize = AEGIS128_MAX_AUTH_SIZE, 24962306a36Sopenharmony_ci .chunksize = AEGIS128_BLOCK_SIZE, 25062306a36Sopenharmony_ci 25162306a36Sopenharmony_ci .base = { 25262306a36Sopenharmony_ci .cra_flags = CRYPTO_ALG_INTERNAL, 25362306a36Sopenharmony_ci .cra_blocksize = 1, 25462306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct aegis_ctx) + 25562306a36Sopenharmony_ci __alignof__(struct aegis_ctx), 25662306a36Sopenharmony_ci .cra_alignmask = 0, 25762306a36Sopenharmony_ci .cra_priority = 400, 25862306a36Sopenharmony_ci 25962306a36Sopenharmony_ci .cra_name = "__aegis128", 26062306a36Sopenharmony_ci .cra_driver_name = "__aegis128-aesni", 26162306a36Sopenharmony_ci 26262306a36Sopenharmony_ci .cra_module = THIS_MODULE, 26362306a36Sopenharmony_ci } 26462306a36Sopenharmony_ci}; 26562306a36Sopenharmony_ci 26662306a36Sopenharmony_cistatic struct simd_aead_alg *simd_alg; 26762306a36Sopenharmony_ci 26862306a36Sopenharmony_cistatic int __init crypto_aegis128_aesni_module_init(void) 26962306a36Sopenharmony_ci{ 27062306a36Sopenharmony_ci if (!boot_cpu_has(X86_FEATURE_XMM2) || 27162306a36Sopenharmony_ci !boot_cpu_has(X86_FEATURE_AES) || 27262306a36Sopenharmony_ci !cpu_has_xfeatures(XFEATURE_MASK_SSE, NULL)) 27362306a36Sopenharmony_ci return -ENODEV; 27462306a36Sopenharmony_ci 27562306a36Sopenharmony_ci return simd_register_aeads_compat(&crypto_aegis128_aesni_alg, 1, 27662306a36Sopenharmony_ci &simd_alg); 27762306a36Sopenharmony_ci} 27862306a36Sopenharmony_ci 27962306a36Sopenharmony_cistatic void __exit crypto_aegis128_aesni_module_exit(void) 28062306a36Sopenharmony_ci{ 28162306a36Sopenharmony_ci simd_unregister_aeads(&crypto_aegis128_aesni_alg, 1, &simd_alg); 28262306a36Sopenharmony_ci} 28362306a36Sopenharmony_ci 28462306a36Sopenharmony_cimodule_init(crypto_aegis128_aesni_module_init); 28562306a36Sopenharmony_cimodule_exit(crypto_aegis128_aesni_module_exit); 28662306a36Sopenharmony_ci 28762306a36Sopenharmony_ciMODULE_LICENSE("GPL"); 28862306a36Sopenharmony_ciMODULE_AUTHOR("Ondrej Mosnacek <omosnacek@gmail.com>"); 28962306a36Sopenharmony_ciMODULE_DESCRIPTION("AEGIS-128 AEAD algorithm -- AESNI+SSE2 implementation"); 29062306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("aegis128"); 29162306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("aegis128-aesni"); 292