162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * CCM: Counter with CBC-MAC 462306a36Sopenharmony_ci * 562306a36Sopenharmony_ci * (C) Copyright IBM Corp. 2007 - Joy Latten <latten@us.ibm.com> 662306a36Sopenharmony_ci */ 762306a36Sopenharmony_ci 862306a36Sopenharmony_ci#include <crypto/internal/aead.h> 962306a36Sopenharmony_ci#include <crypto/internal/cipher.h> 1062306a36Sopenharmony_ci#include <crypto/internal/hash.h> 1162306a36Sopenharmony_ci#include <crypto/internal/skcipher.h> 1262306a36Sopenharmony_ci#include <crypto/scatterwalk.h> 1362306a36Sopenharmony_ci#include <linux/err.h> 1462306a36Sopenharmony_ci#include <linux/init.h> 1562306a36Sopenharmony_ci#include <linux/kernel.h> 1662306a36Sopenharmony_ci#include <linux/module.h> 1762306a36Sopenharmony_ci#include <linux/slab.h> 1862306a36Sopenharmony_ci 1962306a36Sopenharmony_cistruct ccm_instance_ctx { 2062306a36Sopenharmony_ci struct crypto_skcipher_spawn ctr; 2162306a36Sopenharmony_ci struct crypto_ahash_spawn mac; 2262306a36Sopenharmony_ci}; 2362306a36Sopenharmony_ci 2462306a36Sopenharmony_cistruct crypto_ccm_ctx { 2562306a36Sopenharmony_ci struct crypto_ahash *mac; 2662306a36Sopenharmony_ci struct crypto_skcipher *ctr; 2762306a36Sopenharmony_ci}; 2862306a36Sopenharmony_ci 2962306a36Sopenharmony_cistruct crypto_rfc4309_ctx { 3062306a36Sopenharmony_ci struct crypto_aead *child; 3162306a36Sopenharmony_ci u8 nonce[3]; 3262306a36Sopenharmony_ci}; 3362306a36Sopenharmony_ci 3462306a36Sopenharmony_cistruct crypto_rfc4309_req_ctx { 3562306a36Sopenharmony_ci struct scatterlist src[3]; 3662306a36Sopenharmony_ci struct scatterlist dst[3]; 3762306a36Sopenharmony_ci struct aead_request subreq; 3862306a36Sopenharmony_ci}; 3962306a36Sopenharmony_ci 4062306a36Sopenharmony_cistruct crypto_ccm_req_priv_ctx { 4162306a36Sopenharmony_ci u8 odata[16]; 4262306a36Sopenharmony_ci u8 idata[16]; 4362306a36Sopenharmony_ci u8 auth_tag[16]; 4462306a36Sopenharmony_ci u32 flags; 4562306a36Sopenharmony_ci struct scatterlist src[3]; 4662306a36Sopenharmony_ci struct scatterlist dst[3]; 4762306a36Sopenharmony_ci union { 4862306a36Sopenharmony_ci struct ahash_request ahreq; 4962306a36Sopenharmony_ci struct skcipher_request skreq; 5062306a36Sopenharmony_ci }; 5162306a36Sopenharmony_ci}; 5262306a36Sopenharmony_ci 5362306a36Sopenharmony_cistruct cbcmac_tfm_ctx { 5462306a36Sopenharmony_ci struct crypto_cipher *child; 5562306a36Sopenharmony_ci}; 5662306a36Sopenharmony_ci 5762306a36Sopenharmony_cistruct cbcmac_desc_ctx { 5862306a36Sopenharmony_ci unsigned int len; 5962306a36Sopenharmony_ci}; 6062306a36Sopenharmony_ci 6162306a36Sopenharmony_cistatic inline struct crypto_ccm_req_priv_ctx *crypto_ccm_reqctx( 6262306a36Sopenharmony_ci struct aead_request *req) 6362306a36Sopenharmony_ci{ 6462306a36Sopenharmony_ci unsigned long align = crypto_aead_alignmask(crypto_aead_reqtfm(req)); 6562306a36Sopenharmony_ci 6662306a36Sopenharmony_ci return (void *)PTR_ALIGN((u8 *)aead_request_ctx(req), align + 1); 6762306a36Sopenharmony_ci} 6862306a36Sopenharmony_ci 6962306a36Sopenharmony_cistatic int set_msg_len(u8 *block, unsigned int msglen, int csize) 7062306a36Sopenharmony_ci{ 7162306a36Sopenharmony_ci __be32 data; 7262306a36Sopenharmony_ci 7362306a36Sopenharmony_ci memset(block, 0, csize); 7462306a36Sopenharmony_ci block += csize; 7562306a36Sopenharmony_ci 7662306a36Sopenharmony_ci if (csize >= 4) 7762306a36Sopenharmony_ci csize = 4; 7862306a36Sopenharmony_ci else if (msglen > (1 << (8 * csize))) 7962306a36Sopenharmony_ci return -EOVERFLOW; 8062306a36Sopenharmony_ci 8162306a36Sopenharmony_ci data = cpu_to_be32(msglen); 8262306a36Sopenharmony_ci memcpy(block - csize, (u8 *)&data + 4 - csize, csize); 8362306a36Sopenharmony_ci 8462306a36Sopenharmony_ci return 0; 8562306a36Sopenharmony_ci} 8662306a36Sopenharmony_ci 8762306a36Sopenharmony_cistatic int crypto_ccm_setkey(struct crypto_aead *aead, const u8 *key, 8862306a36Sopenharmony_ci unsigned int keylen) 8962306a36Sopenharmony_ci{ 9062306a36Sopenharmony_ci struct crypto_ccm_ctx *ctx = crypto_aead_ctx(aead); 9162306a36Sopenharmony_ci struct crypto_skcipher *ctr = ctx->ctr; 9262306a36Sopenharmony_ci struct crypto_ahash *mac = ctx->mac; 9362306a36Sopenharmony_ci int err; 9462306a36Sopenharmony_ci 9562306a36Sopenharmony_ci crypto_skcipher_clear_flags(ctr, CRYPTO_TFM_REQ_MASK); 9662306a36Sopenharmony_ci crypto_skcipher_set_flags(ctr, crypto_aead_get_flags(aead) & 9762306a36Sopenharmony_ci CRYPTO_TFM_REQ_MASK); 9862306a36Sopenharmony_ci err = crypto_skcipher_setkey(ctr, key, keylen); 9962306a36Sopenharmony_ci if (err) 10062306a36Sopenharmony_ci return err; 10162306a36Sopenharmony_ci 10262306a36Sopenharmony_ci crypto_ahash_clear_flags(mac, CRYPTO_TFM_REQ_MASK); 10362306a36Sopenharmony_ci crypto_ahash_set_flags(mac, crypto_aead_get_flags(aead) & 10462306a36Sopenharmony_ci CRYPTO_TFM_REQ_MASK); 10562306a36Sopenharmony_ci return crypto_ahash_setkey(mac, key, keylen); 10662306a36Sopenharmony_ci} 10762306a36Sopenharmony_ci 10862306a36Sopenharmony_cistatic int crypto_ccm_setauthsize(struct crypto_aead *tfm, 10962306a36Sopenharmony_ci unsigned int authsize) 11062306a36Sopenharmony_ci{ 11162306a36Sopenharmony_ci switch (authsize) { 11262306a36Sopenharmony_ci case 4: 11362306a36Sopenharmony_ci case 6: 11462306a36Sopenharmony_ci case 8: 11562306a36Sopenharmony_ci case 10: 11662306a36Sopenharmony_ci case 12: 11762306a36Sopenharmony_ci case 14: 11862306a36Sopenharmony_ci case 16: 11962306a36Sopenharmony_ci break; 12062306a36Sopenharmony_ci default: 12162306a36Sopenharmony_ci return -EINVAL; 12262306a36Sopenharmony_ci } 12362306a36Sopenharmony_ci 12462306a36Sopenharmony_ci return 0; 12562306a36Sopenharmony_ci} 12662306a36Sopenharmony_ci 12762306a36Sopenharmony_cistatic int format_input(u8 *info, struct aead_request *req, 12862306a36Sopenharmony_ci unsigned int cryptlen) 12962306a36Sopenharmony_ci{ 13062306a36Sopenharmony_ci struct crypto_aead *aead = crypto_aead_reqtfm(req); 13162306a36Sopenharmony_ci unsigned int lp = req->iv[0]; 13262306a36Sopenharmony_ci unsigned int l = lp + 1; 13362306a36Sopenharmony_ci unsigned int m; 13462306a36Sopenharmony_ci 13562306a36Sopenharmony_ci m = crypto_aead_authsize(aead); 13662306a36Sopenharmony_ci 13762306a36Sopenharmony_ci memcpy(info, req->iv, 16); 13862306a36Sopenharmony_ci 13962306a36Sopenharmony_ci /* format control info per RFC 3610 and 14062306a36Sopenharmony_ci * NIST Special Publication 800-38C 14162306a36Sopenharmony_ci */ 14262306a36Sopenharmony_ci *info |= (8 * ((m - 2) / 2)); 14362306a36Sopenharmony_ci if (req->assoclen) 14462306a36Sopenharmony_ci *info |= 64; 14562306a36Sopenharmony_ci 14662306a36Sopenharmony_ci return set_msg_len(info + 16 - l, cryptlen, l); 14762306a36Sopenharmony_ci} 14862306a36Sopenharmony_ci 14962306a36Sopenharmony_cistatic int format_adata(u8 *adata, unsigned int a) 15062306a36Sopenharmony_ci{ 15162306a36Sopenharmony_ci int len = 0; 15262306a36Sopenharmony_ci 15362306a36Sopenharmony_ci /* add control info for associated data 15462306a36Sopenharmony_ci * RFC 3610 and NIST Special Publication 800-38C 15562306a36Sopenharmony_ci */ 15662306a36Sopenharmony_ci if (a < 65280) { 15762306a36Sopenharmony_ci *(__be16 *)adata = cpu_to_be16(a); 15862306a36Sopenharmony_ci len = 2; 15962306a36Sopenharmony_ci } else { 16062306a36Sopenharmony_ci *(__be16 *)adata = cpu_to_be16(0xfffe); 16162306a36Sopenharmony_ci *(__be32 *)&adata[2] = cpu_to_be32(a); 16262306a36Sopenharmony_ci len = 6; 16362306a36Sopenharmony_ci } 16462306a36Sopenharmony_ci 16562306a36Sopenharmony_ci return len; 16662306a36Sopenharmony_ci} 16762306a36Sopenharmony_ci 16862306a36Sopenharmony_cistatic int crypto_ccm_auth(struct aead_request *req, struct scatterlist *plain, 16962306a36Sopenharmony_ci unsigned int cryptlen) 17062306a36Sopenharmony_ci{ 17162306a36Sopenharmony_ci struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req); 17262306a36Sopenharmony_ci struct crypto_aead *aead = crypto_aead_reqtfm(req); 17362306a36Sopenharmony_ci struct crypto_ccm_ctx *ctx = crypto_aead_ctx(aead); 17462306a36Sopenharmony_ci struct ahash_request *ahreq = &pctx->ahreq; 17562306a36Sopenharmony_ci unsigned int assoclen = req->assoclen; 17662306a36Sopenharmony_ci struct scatterlist sg[3]; 17762306a36Sopenharmony_ci u8 *odata = pctx->odata; 17862306a36Sopenharmony_ci u8 *idata = pctx->idata; 17962306a36Sopenharmony_ci int ilen, err; 18062306a36Sopenharmony_ci 18162306a36Sopenharmony_ci /* format control data for input */ 18262306a36Sopenharmony_ci err = format_input(odata, req, cryptlen); 18362306a36Sopenharmony_ci if (err) 18462306a36Sopenharmony_ci goto out; 18562306a36Sopenharmony_ci 18662306a36Sopenharmony_ci sg_init_table(sg, 3); 18762306a36Sopenharmony_ci sg_set_buf(&sg[0], odata, 16); 18862306a36Sopenharmony_ci 18962306a36Sopenharmony_ci /* format associated data and compute into mac */ 19062306a36Sopenharmony_ci if (assoclen) { 19162306a36Sopenharmony_ci ilen = format_adata(idata, assoclen); 19262306a36Sopenharmony_ci sg_set_buf(&sg[1], idata, ilen); 19362306a36Sopenharmony_ci sg_chain(sg, 3, req->src); 19462306a36Sopenharmony_ci } else { 19562306a36Sopenharmony_ci ilen = 0; 19662306a36Sopenharmony_ci sg_chain(sg, 2, req->src); 19762306a36Sopenharmony_ci } 19862306a36Sopenharmony_ci 19962306a36Sopenharmony_ci ahash_request_set_tfm(ahreq, ctx->mac); 20062306a36Sopenharmony_ci ahash_request_set_callback(ahreq, pctx->flags, NULL, NULL); 20162306a36Sopenharmony_ci ahash_request_set_crypt(ahreq, sg, NULL, assoclen + ilen + 16); 20262306a36Sopenharmony_ci err = crypto_ahash_init(ahreq); 20362306a36Sopenharmony_ci if (err) 20462306a36Sopenharmony_ci goto out; 20562306a36Sopenharmony_ci err = crypto_ahash_update(ahreq); 20662306a36Sopenharmony_ci if (err) 20762306a36Sopenharmony_ci goto out; 20862306a36Sopenharmony_ci 20962306a36Sopenharmony_ci /* we need to pad the MAC input to a round multiple of the block size */ 21062306a36Sopenharmony_ci ilen = 16 - (assoclen + ilen) % 16; 21162306a36Sopenharmony_ci if (ilen < 16) { 21262306a36Sopenharmony_ci memset(idata, 0, ilen); 21362306a36Sopenharmony_ci sg_init_table(sg, 2); 21462306a36Sopenharmony_ci sg_set_buf(&sg[0], idata, ilen); 21562306a36Sopenharmony_ci if (plain) 21662306a36Sopenharmony_ci sg_chain(sg, 2, plain); 21762306a36Sopenharmony_ci plain = sg; 21862306a36Sopenharmony_ci cryptlen += ilen; 21962306a36Sopenharmony_ci } 22062306a36Sopenharmony_ci 22162306a36Sopenharmony_ci ahash_request_set_crypt(ahreq, plain, odata, cryptlen); 22262306a36Sopenharmony_ci err = crypto_ahash_finup(ahreq); 22362306a36Sopenharmony_ciout: 22462306a36Sopenharmony_ci return err; 22562306a36Sopenharmony_ci} 22662306a36Sopenharmony_ci 22762306a36Sopenharmony_cistatic void crypto_ccm_encrypt_done(void *data, int err) 22862306a36Sopenharmony_ci{ 22962306a36Sopenharmony_ci struct aead_request *req = data; 23062306a36Sopenharmony_ci struct crypto_aead *aead = crypto_aead_reqtfm(req); 23162306a36Sopenharmony_ci struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req); 23262306a36Sopenharmony_ci u8 *odata = pctx->odata; 23362306a36Sopenharmony_ci 23462306a36Sopenharmony_ci if (!err) 23562306a36Sopenharmony_ci scatterwalk_map_and_copy(odata, req->dst, 23662306a36Sopenharmony_ci req->assoclen + req->cryptlen, 23762306a36Sopenharmony_ci crypto_aead_authsize(aead), 1); 23862306a36Sopenharmony_ci aead_request_complete(req, err); 23962306a36Sopenharmony_ci} 24062306a36Sopenharmony_ci 24162306a36Sopenharmony_cistatic inline int crypto_ccm_check_iv(const u8 *iv) 24262306a36Sopenharmony_ci{ 24362306a36Sopenharmony_ci /* 2 <= L <= 8, so 1 <= L' <= 7. */ 24462306a36Sopenharmony_ci if (1 > iv[0] || iv[0] > 7) 24562306a36Sopenharmony_ci return -EINVAL; 24662306a36Sopenharmony_ci 24762306a36Sopenharmony_ci return 0; 24862306a36Sopenharmony_ci} 24962306a36Sopenharmony_ci 25062306a36Sopenharmony_cistatic int crypto_ccm_init_crypt(struct aead_request *req, u8 *tag) 25162306a36Sopenharmony_ci{ 25262306a36Sopenharmony_ci struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req); 25362306a36Sopenharmony_ci struct scatterlist *sg; 25462306a36Sopenharmony_ci u8 *iv = req->iv; 25562306a36Sopenharmony_ci int err; 25662306a36Sopenharmony_ci 25762306a36Sopenharmony_ci err = crypto_ccm_check_iv(iv); 25862306a36Sopenharmony_ci if (err) 25962306a36Sopenharmony_ci return err; 26062306a36Sopenharmony_ci 26162306a36Sopenharmony_ci pctx->flags = aead_request_flags(req); 26262306a36Sopenharmony_ci 26362306a36Sopenharmony_ci /* Note: rfc 3610 and NIST 800-38C require counter of 26462306a36Sopenharmony_ci * zero to encrypt auth tag. 26562306a36Sopenharmony_ci */ 26662306a36Sopenharmony_ci memset(iv + 15 - iv[0], 0, iv[0] + 1); 26762306a36Sopenharmony_ci 26862306a36Sopenharmony_ci sg_init_table(pctx->src, 3); 26962306a36Sopenharmony_ci sg_set_buf(pctx->src, tag, 16); 27062306a36Sopenharmony_ci sg = scatterwalk_ffwd(pctx->src + 1, req->src, req->assoclen); 27162306a36Sopenharmony_ci if (sg != pctx->src + 1) 27262306a36Sopenharmony_ci sg_chain(pctx->src, 2, sg); 27362306a36Sopenharmony_ci 27462306a36Sopenharmony_ci if (req->src != req->dst) { 27562306a36Sopenharmony_ci sg_init_table(pctx->dst, 3); 27662306a36Sopenharmony_ci sg_set_buf(pctx->dst, tag, 16); 27762306a36Sopenharmony_ci sg = scatterwalk_ffwd(pctx->dst + 1, req->dst, req->assoclen); 27862306a36Sopenharmony_ci if (sg != pctx->dst + 1) 27962306a36Sopenharmony_ci sg_chain(pctx->dst, 2, sg); 28062306a36Sopenharmony_ci } 28162306a36Sopenharmony_ci 28262306a36Sopenharmony_ci return 0; 28362306a36Sopenharmony_ci} 28462306a36Sopenharmony_ci 28562306a36Sopenharmony_cistatic int crypto_ccm_encrypt(struct aead_request *req) 28662306a36Sopenharmony_ci{ 28762306a36Sopenharmony_ci struct crypto_aead *aead = crypto_aead_reqtfm(req); 28862306a36Sopenharmony_ci struct crypto_ccm_ctx *ctx = crypto_aead_ctx(aead); 28962306a36Sopenharmony_ci struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req); 29062306a36Sopenharmony_ci struct skcipher_request *skreq = &pctx->skreq; 29162306a36Sopenharmony_ci struct scatterlist *dst; 29262306a36Sopenharmony_ci unsigned int cryptlen = req->cryptlen; 29362306a36Sopenharmony_ci u8 *odata = pctx->odata; 29462306a36Sopenharmony_ci u8 *iv = req->iv; 29562306a36Sopenharmony_ci int err; 29662306a36Sopenharmony_ci 29762306a36Sopenharmony_ci err = crypto_ccm_init_crypt(req, odata); 29862306a36Sopenharmony_ci if (err) 29962306a36Sopenharmony_ci return err; 30062306a36Sopenharmony_ci 30162306a36Sopenharmony_ci err = crypto_ccm_auth(req, sg_next(pctx->src), cryptlen); 30262306a36Sopenharmony_ci if (err) 30362306a36Sopenharmony_ci return err; 30462306a36Sopenharmony_ci 30562306a36Sopenharmony_ci dst = pctx->src; 30662306a36Sopenharmony_ci if (req->src != req->dst) 30762306a36Sopenharmony_ci dst = pctx->dst; 30862306a36Sopenharmony_ci 30962306a36Sopenharmony_ci skcipher_request_set_tfm(skreq, ctx->ctr); 31062306a36Sopenharmony_ci skcipher_request_set_callback(skreq, pctx->flags, 31162306a36Sopenharmony_ci crypto_ccm_encrypt_done, req); 31262306a36Sopenharmony_ci skcipher_request_set_crypt(skreq, pctx->src, dst, cryptlen + 16, iv); 31362306a36Sopenharmony_ci err = crypto_skcipher_encrypt(skreq); 31462306a36Sopenharmony_ci if (err) 31562306a36Sopenharmony_ci return err; 31662306a36Sopenharmony_ci 31762306a36Sopenharmony_ci /* copy authtag to end of dst */ 31862306a36Sopenharmony_ci scatterwalk_map_and_copy(odata, sg_next(dst), cryptlen, 31962306a36Sopenharmony_ci crypto_aead_authsize(aead), 1); 32062306a36Sopenharmony_ci return err; 32162306a36Sopenharmony_ci} 32262306a36Sopenharmony_ci 32362306a36Sopenharmony_cistatic void crypto_ccm_decrypt_done(void *data, int err) 32462306a36Sopenharmony_ci{ 32562306a36Sopenharmony_ci struct aead_request *req = data; 32662306a36Sopenharmony_ci struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req); 32762306a36Sopenharmony_ci struct crypto_aead *aead = crypto_aead_reqtfm(req); 32862306a36Sopenharmony_ci unsigned int authsize = crypto_aead_authsize(aead); 32962306a36Sopenharmony_ci unsigned int cryptlen = req->cryptlen - authsize; 33062306a36Sopenharmony_ci struct scatterlist *dst; 33162306a36Sopenharmony_ci 33262306a36Sopenharmony_ci pctx->flags = 0; 33362306a36Sopenharmony_ci 33462306a36Sopenharmony_ci dst = sg_next(req->src == req->dst ? pctx->src : pctx->dst); 33562306a36Sopenharmony_ci 33662306a36Sopenharmony_ci if (!err) { 33762306a36Sopenharmony_ci err = crypto_ccm_auth(req, dst, cryptlen); 33862306a36Sopenharmony_ci if (!err && crypto_memneq(pctx->auth_tag, pctx->odata, authsize)) 33962306a36Sopenharmony_ci err = -EBADMSG; 34062306a36Sopenharmony_ci } 34162306a36Sopenharmony_ci aead_request_complete(req, err); 34262306a36Sopenharmony_ci} 34362306a36Sopenharmony_ci 34462306a36Sopenharmony_cistatic int crypto_ccm_decrypt(struct aead_request *req) 34562306a36Sopenharmony_ci{ 34662306a36Sopenharmony_ci struct crypto_aead *aead = crypto_aead_reqtfm(req); 34762306a36Sopenharmony_ci struct crypto_ccm_ctx *ctx = crypto_aead_ctx(aead); 34862306a36Sopenharmony_ci struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req); 34962306a36Sopenharmony_ci struct skcipher_request *skreq = &pctx->skreq; 35062306a36Sopenharmony_ci struct scatterlist *dst; 35162306a36Sopenharmony_ci unsigned int authsize = crypto_aead_authsize(aead); 35262306a36Sopenharmony_ci unsigned int cryptlen = req->cryptlen; 35362306a36Sopenharmony_ci u8 *authtag = pctx->auth_tag; 35462306a36Sopenharmony_ci u8 *odata = pctx->odata; 35562306a36Sopenharmony_ci u8 *iv = pctx->idata; 35662306a36Sopenharmony_ci int err; 35762306a36Sopenharmony_ci 35862306a36Sopenharmony_ci cryptlen -= authsize; 35962306a36Sopenharmony_ci 36062306a36Sopenharmony_ci err = crypto_ccm_init_crypt(req, authtag); 36162306a36Sopenharmony_ci if (err) 36262306a36Sopenharmony_ci return err; 36362306a36Sopenharmony_ci 36462306a36Sopenharmony_ci scatterwalk_map_and_copy(authtag, sg_next(pctx->src), cryptlen, 36562306a36Sopenharmony_ci authsize, 0); 36662306a36Sopenharmony_ci 36762306a36Sopenharmony_ci dst = pctx->src; 36862306a36Sopenharmony_ci if (req->src != req->dst) 36962306a36Sopenharmony_ci dst = pctx->dst; 37062306a36Sopenharmony_ci 37162306a36Sopenharmony_ci memcpy(iv, req->iv, 16); 37262306a36Sopenharmony_ci 37362306a36Sopenharmony_ci skcipher_request_set_tfm(skreq, ctx->ctr); 37462306a36Sopenharmony_ci skcipher_request_set_callback(skreq, pctx->flags, 37562306a36Sopenharmony_ci crypto_ccm_decrypt_done, req); 37662306a36Sopenharmony_ci skcipher_request_set_crypt(skreq, pctx->src, dst, cryptlen + 16, iv); 37762306a36Sopenharmony_ci err = crypto_skcipher_decrypt(skreq); 37862306a36Sopenharmony_ci if (err) 37962306a36Sopenharmony_ci return err; 38062306a36Sopenharmony_ci 38162306a36Sopenharmony_ci err = crypto_ccm_auth(req, sg_next(dst), cryptlen); 38262306a36Sopenharmony_ci if (err) 38362306a36Sopenharmony_ci return err; 38462306a36Sopenharmony_ci 38562306a36Sopenharmony_ci /* verify */ 38662306a36Sopenharmony_ci if (crypto_memneq(authtag, odata, authsize)) 38762306a36Sopenharmony_ci return -EBADMSG; 38862306a36Sopenharmony_ci 38962306a36Sopenharmony_ci return err; 39062306a36Sopenharmony_ci} 39162306a36Sopenharmony_ci 39262306a36Sopenharmony_cistatic int crypto_ccm_init_tfm(struct crypto_aead *tfm) 39362306a36Sopenharmony_ci{ 39462306a36Sopenharmony_ci struct aead_instance *inst = aead_alg_instance(tfm); 39562306a36Sopenharmony_ci struct ccm_instance_ctx *ictx = aead_instance_ctx(inst); 39662306a36Sopenharmony_ci struct crypto_ccm_ctx *ctx = crypto_aead_ctx(tfm); 39762306a36Sopenharmony_ci struct crypto_ahash *mac; 39862306a36Sopenharmony_ci struct crypto_skcipher *ctr; 39962306a36Sopenharmony_ci unsigned long align; 40062306a36Sopenharmony_ci int err; 40162306a36Sopenharmony_ci 40262306a36Sopenharmony_ci mac = crypto_spawn_ahash(&ictx->mac); 40362306a36Sopenharmony_ci if (IS_ERR(mac)) 40462306a36Sopenharmony_ci return PTR_ERR(mac); 40562306a36Sopenharmony_ci 40662306a36Sopenharmony_ci ctr = crypto_spawn_skcipher(&ictx->ctr); 40762306a36Sopenharmony_ci err = PTR_ERR(ctr); 40862306a36Sopenharmony_ci if (IS_ERR(ctr)) 40962306a36Sopenharmony_ci goto err_free_mac; 41062306a36Sopenharmony_ci 41162306a36Sopenharmony_ci ctx->mac = mac; 41262306a36Sopenharmony_ci ctx->ctr = ctr; 41362306a36Sopenharmony_ci 41462306a36Sopenharmony_ci align = crypto_aead_alignmask(tfm); 41562306a36Sopenharmony_ci align &= ~(crypto_tfm_ctx_alignment() - 1); 41662306a36Sopenharmony_ci crypto_aead_set_reqsize( 41762306a36Sopenharmony_ci tfm, 41862306a36Sopenharmony_ci align + sizeof(struct crypto_ccm_req_priv_ctx) + 41962306a36Sopenharmony_ci max(crypto_ahash_reqsize(mac), crypto_skcipher_reqsize(ctr))); 42062306a36Sopenharmony_ci 42162306a36Sopenharmony_ci return 0; 42262306a36Sopenharmony_ci 42362306a36Sopenharmony_cierr_free_mac: 42462306a36Sopenharmony_ci crypto_free_ahash(mac); 42562306a36Sopenharmony_ci return err; 42662306a36Sopenharmony_ci} 42762306a36Sopenharmony_ci 42862306a36Sopenharmony_cistatic void crypto_ccm_exit_tfm(struct crypto_aead *tfm) 42962306a36Sopenharmony_ci{ 43062306a36Sopenharmony_ci struct crypto_ccm_ctx *ctx = crypto_aead_ctx(tfm); 43162306a36Sopenharmony_ci 43262306a36Sopenharmony_ci crypto_free_ahash(ctx->mac); 43362306a36Sopenharmony_ci crypto_free_skcipher(ctx->ctr); 43462306a36Sopenharmony_ci} 43562306a36Sopenharmony_ci 43662306a36Sopenharmony_cistatic void crypto_ccm_free(struct aead_instance *inst) 43762306a36Sopenharmony_ci{ 43862306a36Sopenharmony_ci struct ccm_instance_ctx *ctx = aead_instance_ctx(inst); 43962306a36Sopenharmony_ci 44062306a36Sopenharmony_ci crypto_drop_ahash(&ctx->mac); 44162306a36Sopenharmony_ci crypto_drop_skcipher(&ctx->ctr); 44262306a36Sopenharmony_ci kfree(inst); 44362306a36Sopenharmony_ci} 44462306a36Sopenharmony_ci 44562306a36Sopenharmony_cistatic int crypto_ccm_create_common(struct crypto_template *tmpl, 44662306a36Sopenharmony_ci struct rtattr **tb, 44762306a36Sopenharmony_ci const char *ctr_name, 44862306a36Sopenharmony_ci const char *mac_name) 44962306a36Sopenharmony_ci{ 45062306a36Sopenharmony_ci u32 mask; 45162306a36Sopenharmony_ci struct aead_instance *inst; 45262306a36Sopenharmony_ci struct ccm_instance_ctx *ictx; 45362306a36Sopenharmony_ci struct skcipher_alg *ctr; 45462306a36Sopenharmony_ci struct hash_alg_common *mac; 45562306a36Sopenharmony_ci int err; 45662306a36Sopenharmony_ci 45762306a36Sopenharmony_ci err = crypto_check_attr_type(tb, CRYPTO_ALG_TYPE_AEAD, &mask); 45862306a36Sopenharmony_ci if (err) 45962306a36Sopenharmony_ci return err; 46062306a36Sopenharmony_ci 46162306a36Sopenharmony_ci inst = kzalloc(sizeof(*inst) + sizeof(*ictx), GFP_KERNEL); 46262306a36Sopenharmony_ci if (!inst) 46362306a36Sopenharmony_ci return -ENOMEM; 46462306a36Sopenharmony_ci ictx = aead_instance_ctx(inst); 46562306a36Sopenharmony_ci 46662306a36Sopenharmony_ci err = crypto_grab_ahash(&ictx->mac, aead_crypto_instance(inst), 46762306a36Sopenharmony_ci mac_name, 0, mask | CRYPTO_ALG_ASYNC); 46862306a36Sopenharmony_ci if (err) 46962306a36Sopenharmony_ci goto err_free_inst; 47062306a36Sopenharmony_ci mac = crypto_spawn_ahash_alg(&ictx->mac); 47162306a36Sopenharmony_ci 47262306a36Sopenharmony_ci err = -EINVAL; 47362306a36Sopenharmony_ci if (strncmp(mac->base.cra_name, "cbcmac(", 7) != 0 || 47462306a36Sopenharmony_ci mac->digestsize != 16) 47562306a36Sopenharmony_ci goto err_free_inst; 47662306a36Sopenharmony_ci 47762306a36Sopenharmony_ci err = crypto_grab_skcipher(&ictx->ctr, aead_crypto_instance(inst), 47862306a36Sopenharmony_ci ctr_name, 0, mask); 47962306a36Sopenharmony_ci if (err) 48062306a36Sopenharmony_ci goto err_free_inst; 48162306a36Sopenharmony_ci ctr = crypto_spawn_skcipher_alg(&ictx->ctr); 48262306a36Sopenharmony_ci 48362306a36Sopenharmony_ci /* The skcipher algorithm must be CTR mode, using 16-byte blocks. */ 48462306a36Sopenharmony_ci err = -EINVAL; 48562306a36Sopenharmony_ci if (strncmp(ctr->base.cra_name, "ctr(", 4) != 0 || 48662306a36Sopenharmony_ci crypto_skcipher_alg_ivsize(ctr) != 16 || 48762306a36Sopenharmony_ci ctr->base.cra_blocksize != 1) 48862306a36Sopenharmony_ci goto err_free_inst; 48962306a36Sopenharmony_ci 49062306a36Sopenharmony_ci /* ctr and cbcmac must use the same underlying block cipher. */ 49162306a36Sopenharmony_ci if (strcmp(ctr->base.cra_name + 4, mac->base.cra_name + 7) != 0) 49262306a36Sopenharmony_ci goto err_free_inst; 49362306a36Sopenharmony_ci 49462306a36Sopenharmony_ci err = -ENAMETOOLONG; 49562306a36Sopenharmony_ci if (snprintf(inst->alg.base.cra_name, CRYPTO_MAX_ALG_NAME, 49662306a36Sopenharmony_ci "ccm(%s", ctr->base.cra_name + 4) >= CRYPTO_MAX_ALG_NAME) 49762306a36Sopenharmony_ci goto err_free_inst; 49862306a36Sopenharmony_ci 49962306a36Sopenharmony_ci if (snprintf(inst->alg.base.cra_driver_name, CRYPTO_MAX_ALG_NAME, 50062306a36Sopenharmony_ci "ccm_base(%s,%s)", ctr->base.cra_driver_name, 50162306a36Sopenharmony_ci mac->base.cra_driver_name) >= CRYPTO_MAX_ALG_NAME) 50262306a36Sopenharmony_ci goto err_free_inst; 50362306a36Sopenharmony_ci 50462306a36Sopenharmony_ci inst->alg.base.cra_priority = (mac->base.cra_priority + 50562306a36Sopenharmony_ci ctr->base.cra_priority) / 2; 50662306a36Sopenharmony_ci inst->alg.base.cra_blocksize = 1; 50762306a36Sopenharmony_ci inst->alg.base.cra_alignmask = mac->base.cra_alignmask | 50862306a36Sopenharmony_ci ctr->base.cra_alignmask; 50962306a36Sopenharmony_ci inst->alg.ivsize = 16; 51062306a36Sopenharmony_ci inst->alg.chunksize = crypto_skcipher_alg_chunksize(ctr); 51162306a36Sopenharmony_ci inst->alg.maxauthsize = 16; 51262306a36Sopenharmony_ci inst->alg.base.cra_ctxsize = sizeof(struct crypto_ccm_ctx); 51362306a36Sopenharmony_ci inst->alg.init = crypto_ccm_init_tfm; 51462306a36Sopenharmony_ci inst->alg.exit = crypto_ccm_exit_tfm; 51562306a36Sopenharmony_ci inst->alg.setkey = crypto_ccm_setkey; 51662306a36Sopenharmony_ci inst->alg.setauthsize = crypto_ccm_setauthsize; 51762306a36Sopenharmony_ci inst->alg.encrypt = crypto_ccm_encrypt; 51862306a36Sopenharmony_ci inst->alg.decrypt = crypto_ccm_decrypt; 51962306a36Sopenharmony_ci 52062306a36Sopenharmony_ci inst->free = crypto_ccm_free; 52162306a36Sopenharmony_ci 52262306a36Sopenharmony_ci err = aead_register_instance(tmpl, inst); 52362306a36Sopenharmony_ci if (err) { 52462306a36Sopenharmony_cierr_free_inst: 52562306a36Sopenharmony_ci crypto_ccm_free(inst); 52662306a36Sopenharmony_ci } 52762306a36Sopenharmony_ci return err; 52862306a36Sopenharmony_ci} 52962306a36Sopenharmony_ci 53062306a36Sopenharmony_cistatic int crypto_ccm_create(struct crypto_template *tmpl, struct rtattr **tb) 53162306a36Sopenharmony_ci{ 53262306a36Sopenharmony_ci const char *cipher_name; 53362306a36Sopenharmony_ci char ctr_name[CRYPTO_MAX_ALG_NAME]; 53462306a36Sopenharmony_ci char mac_name[CRYPTO_MAX_ALG_NAME]; 53562306a36Sopenharmony_ci 53662306a36Sopenharmony_ci cipher_name = crypto_attr_alg_name(tb[1]); 53762306a36Sopenharmony_ci if (IS_ERR(cipher_name)) 53862306a36Sopenharmony_ci return PTR_ERR(cipher_name); 53962306a36Sopenharmony_ci 54062306a36Sopenharmony_ci if (snprintf(ctr_name, CRYPTO_MAX_ALG_NAME, "ctr(%s)", 54162306a36Sopenharmony_ci cipher_name) >= CRYPTO_MAX_ALG_NAME) 54262306a36Sopenharmony_ci return -ENAMETOOLONG; 54362306a36Sopenharmony_ci 54462306a36Sopenharmony_ci if (snprintf(mac_name, CRYPTO_MAX_ALG_NAME, "cbcmac(%s)", 54562306a36Sopenharmony_ci cipher_name) >= CRYPTO_MAX_ALG_NAME) 54662306a36Sopenharmony_ci return -ENAMETOOLONG; 54762306a36Sopenharmony_ci 54862306a36Sopenharmony_ci return crypto_ccm_create_common(tmpl, tb, ctr_name, mac_name); 54962306a36Sopenharmony_ci} 55062306a36Sopenharmony_ci 55162306a36Sopenharmony_cistatic int crypto_ccm_base_create(struct crypto_template *tmpl, 55262306a36Sopenharmony_ci struct rtattr **tb) 55362306a36Sopenharmony_ci{ 55462306a36Sopenharmony_ci const char *ctr_name; 55562306a36Sopenharmony_ci const char *mac_name; 55662306a36Sopenharmony_ci 55762306a36Sopenharmony_ci ctr_name = crypto_attr_alg_name(tb[1]); 55862306a36Sopenharmony_ci if (IS_ERR(ctr_name)) 55962306a36Sopenharmony_ci return PTR_ERR(ctr_name); 56062306a36Sopenharmony_ci 56162306a36Sopenharmony_ci mac_name = crypto_attr_alg_name(tb[2]); 56262306a36Sopenharmony_ci if (IS_ERR(mac_name)) 56362306a36Sopenharmony_ci return PTR_ERR(mac_name); 56462306a36Sopenharmony_ci 56562306a36Sopenharmony_ci return crypto_ccm_create_common(tmpl, tb, ctr_name, mac_name); 56662306a36Sopenharmony_ci} 56762306a36Sopenharmony_ci 56862306a36Sopenharmony_cistatic int crypto_rfc4309_setkey(struct crypto_aead *parent, const u8 *key, 56962306a36Sopenharmony_ci unsigned int keylen) 57062306a36Sopenharmony_ci{ 57162306a36Sopenharmony_ci struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(parent); 57262306a36Sopenharmony_ci struct crypto_aead *child = ctx->child; 57362306a36Sopenharmony_ci 57462306a36Sopenharmony_ci if (keylen < 3) 57562306a36Sopenharmony_ci return -EINVAL; 57662306a36Sopenharmony_ci 57762306a36Sopenharmony_ci keylen -= 3; 57862306a36Sopenharmony_ci memcpy(ctx->nonce, key + keylen, 3); 57962306a36Sopenharmony_ci 58062306a36Sopenharmony_ci crypto_aead_clear_flags(child, CRYPTO_TFM_REQ_MASK); 58162306a36Sopenharmony_ci crypto_aead_set_flags(child, crypto_aead_get_flags(parent) & 58262306a36Sopenharmony_ci CRYPTO_TFM_REQ_MASK); 58362306a36Sopenharmony_ci return crypto_aead_setkey(child, key, keylen); 58462306a36Sopenharmony_ci} 58562306a36Sopenharmony_ci 58662306a36Sopenharmony_cistatic int crypto_rfc4309_setauthsize(struct crypto_aead *parent, 58762306a36Sopenharmony_ci unsigned int authsize) 58862306a36Sopenharmony_ci{ 58962306a36Sopenharmony_ci struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(parent); 59062306a36Sopenharmony_ci 59162306a36Sopenharmony_ci switch (authsize) { 59262306a36Sopenharmony_ci case 8: 59362306a36Sopenharmony_ci case 12: 59462306a36Sopenharmony_ci case 16: 59562306a36Sopenharmony_ci break; 59662306a36Sopenharmony_ci default: 59762306a36Sopenharmony_ci return -EINVAL; 59862306a36Sopenharmony_ci } 59962306a36Sopenharmony_ci 60062306a36Sopenharmony_ci return crypto_aead_setauthsize(ctx->child, authsize); 60162306a36Sopenharmony_ci} 60262306a36Sopenharmony_ci 60362306a36Sopenharmony_cistatic struct aead_request *crypto_rfc4309_crypt(struct aead_request *req) 60462306a36Sopenharmony_ci{ 60562306a36Sopenharmony_ci struct crypto_rfc4309_req_ctx *rctx = aead_request_ctx(req); 60662306a36Sopenharmony_ci struct aead_request *subreq = &rctx->subreq; 60762306a36Sopenharmony_ci struct crypto_aead *aead = crypto_aead_reqtfm(req); 60862306a36Sopenharmony_ci struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(aead); 60962306a36Sopenharmony_ci struct crypto_aead *child = ctx->child; 61062306a36Sopenharmony_ci struct scatterlist *sg; 61162306a36Sopenharmony_ci u8 *iv = PTR_ALIGN((u8 *)(subreq + 1) + crypto_aead_reqsize(child), 61262306a36Sopenharmony_ci crypto_aead_alignmask(child) + 1); 61362306a36Sopenharmony_ci 61462306a36Sopenharmony_ci /* L' */ 61562306a36Sopenharmony_ci iv[0] = 3; 61662306a36Sopenharmony_ci 61762306a36Sopenharmony_ci memcpy(iv + 1, ctx->nonce, 3); 61862306a36Sopenharmony_ci memcpy(iv + 4, req->iv, 8); 61962306a36Sopenharmony_ci 62062306a36Sopenharmony_ci scatterwalk_map_and_copy(iv + 16, req->src, 0, req->assoclen - 8, 0); 62162306a36Sopenharmony_ci 62262306a36Sopenharmony_ci sg_init_table(rctx->src, 3); 62362306a36Sopenharmony_ci sg_set_buf(rctx->src, iv + 16, req->assoclen - 8); 62462306a36Sopenharmony_ci sg = scatterwalk_ffwd(rctx->src + 1, req->src, req->assoclen); 62562306a36Sopenharmony_ci if (sg != rctx->src + 1) 62662306a36Sopenharmony_ci sg_chain(rctx->src, 2, sg); 62762306a36Sopenharmony_ci 62862306a36Sopenharmony_ci if (req->src != req->dst) { 62962306a36Sopenharmony_ci sg_init_table(rctx->dst, 3); 63062306a36Sopenharmony_ci sg_set_buf(rctx->dst, iv + 16, req->assoclen - 8); 63162306a36Sopenharmony_ci sg = scatterwalk_ffwd(rctx->dst + 1, req->dst, req->assoclen); 63262306a36Sopenharmony_ci if (sg != rctx->dst + 1) 63362306a36Sopenharmony_ci sg_chain(rctx->dst, 2, sg); 63462306a36Sopenharmony_ci } 63562306a36Sopenharmony_ci 63662306a36Sopenharmony_ci aead_request_set_tfm(subreq, child); 63762306a36Sopenharmony_ci aead_request_set_callback(subreq, req->base.flags, req->base.complete, 63862306a36Sopenharmony_ci req->base.data); 63962306a36Sopenharmony_ci aead_request_set_crypt(subreq, rctx->src, 64062306a36Sopenharmony_ci req->src == req->dst ? rctx->src : rctx->dst, 64162306a36Sopenharmony_ci req->cryptlen, iv); 64262306a36Sopenharmony_ci aead_request_set_ad(subreq, req->assoclen - 8); 64362306a36Sopenharmony_ci 64462306a36Sopenharmony_ci return subreq; 64562306a36Sopenharmony_ci} 64662306a36Sopenharmony_ci 64762306a36Sopenharmony_cistatic int crypto_rfc4309_encrypt(struct aead_request *req) 64862306a36Sopenharmony_ci{ 64962306a36Sopenharmony_ci if (req->assoclen != 16 && req->assoclen != 20) 65062306a36Sopenharmony_ci return -EINVAL; 65162306a36Sopenharmony_ci 65262306a36Sopenharmony_ci req = crypto_rfc4309_crypt(req); 65362306a36Sopenharmony_ci 65462306a36Sopenharmony_ci return crypto_aead_encrypt(req); 65562306a36Sopenharmony_ci} 65662306a36Sopenharmony_ci 65762306a36Sopenharmony_cistatic int crypto_rfc4309_decrypt(struct aead_request *req) 65862306a36Sopenharmony_ci{ 65962306a36Sopenharmony_ci if (req->assoclen != 16 && req->assoclen != 20) 66062306a36Sopenharmony_ci return -EINVAL; 66162306a36Sopenharmony_ci 66262306a36Sopenharmony_ci req = crypto_rfc4309_crypt(req); 66362306a36Sopenharmony_ci 66462306a36Sopenharmony_ci return crypto_aead_decrypt(req); 66562306a36Sopenharmony_ci} 66662306a36Sopenharmony_ci 66762306a36Sopenharmony_cistatic int crypto_rfc4309_init_tfm(struct crypto_aead *tfm) 66862306a36Sopenharmony_ci{ 66962306a36Sopenharmony_ci struct aead_instance *inst = aead_alg_instance(tfm); 67062306a36Sopenharmony_ci struct crypto_aead_spawn *spawn = aead_instance_ctx(inst); 67162306a36Sopenharmony_ci struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(tfm); 67262306a36Sopenharmony_ci struct crypto_aead *aead; 67362306a36Sopenharmony_ci unsigned long align; 67462306a36Sopenharmony_ci 67562306a36Sopenharmony_ci aead = crypto_spawn_aead(spawn); 67662306a36Sopenharmony_ci if (IS_ERR(aead)) 67762306a36Sopenharmony_ci return PTR_ERR(aead); 67862306a36Sopenharmony_ci 67962306a36Sopenharmony_ci ctx->child = aead; 68062306a36Sopenharmony_ci 68162306a36Sopenharmony_ci align = crypto_aead_alignmask(aead); 68262306a36Sopenharmony_ci align &= ~(crypto_tfm_ctx_alignment() - 1); 68362306a36Sopenharmony_ci crypto_aead_set_reqsize( 68462306a36Sopenharmony_ci tfm, 68562306a36Sopenharmony_ci sizeof(struct crypto_rfc4309_req_ctx) + 68662306a36Sopenharmony_ci ALIGN(crypto_aead_reqsize(aead), crypto_tfm_ctx_alignment()) + 68762306a36Sopenharmony_ci align + 32); 68862306a36Sopenharmony_ci 68962306a36Sopenharmony_ci return 0; 69062306a36Sopenharmony_ci} 69162306a36Sopenharmony_ci 69262306a36Sopenharmony_cistatic void crypto_rfc4309_exit_tfm(struct crypto_aead *tfm) 69362306a36Sopenharmony_ci{ 69462306a36Sopenharmony_ci struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(tfm); 69562306a36Sopenharmony_ci 69662306a36Sopenharmony_ci crypto_free_aead(ctx->child); 69762306a36Sopenharmony_ci} 69862306a36Sopenharmony_ci 69962306a36Sopenharmony_cistatic void crypto_rfc4309_free(struct aead_instance *inst) 70062306a36Sopenharmony_ci{ 70162306a36Sopenharmony_ci crypto_drop_aead(aead_instance_ctx(inst)); 70262306a36Sopenharmony_ci kfree(inst); 70362306a36Sopenharmony_ci} 70462306a36Sopenharmony_ci 70562306a36Sopenharmony_cistatic int crypto_rfc4309_create(struct crypto_template *tmpl, 70662306a36Sopenharmony_ci struct rtattr **tb) 70762306a36Sopenharmony_ci{ 70862306a36Sopenharmony_ci u32 mask; 70962306a36Sopenharmony_ci struct aead_instance *inst; 71062306a36Sopenharmony_ci struct crypto_aead_spawn *spawn; 71162306a36Sopenharmony_ci struct aead_alg *alg; 71262306a36Sopenharmony_ci int err; 71362306a36Sopenharmony_ci 71462306a36Sopenharmony_ci err = crypto_check_attr_type(tb, CRYPTO_ALG_TYPE_AEAD, &mask); 71562306a36Sopenharmony_ci if (err) 71662306a36Sopenharmony_ci return err; 71762306a36Sopenharmony_ci 71862306a36Sopenharmony_ci inst = kzalloc(sizeof(*inst) + sizeof(*spawn), GFP_KERNEL); 71962306a36Sopenharmony_ci if (!inst) 72062306a36Sopenharmony_ci return -ENOMEM; 72162306a36Sopenharmony_ci 72262306a36Sopenharmony_ci spawn = aead_instance_ctx(inst); 72362306a36Sopenharmony_ci err = crypto_grab_aead(spawn, aead_crypto_instance(inst), 72462306a36Sopenharmony_ci crypto_attr_alg_name(tb[1]), 0, mask); 72562306a36Sopenharmony_ci if (err) 72662306a36Sopenharmony_ci goto err_free_inst; 72762306a36Sopenharmony_ci 72862306a36Sopenharmony_ci alg = crypto_spawn_aead_alg(spawn); 72962306a36Sopenharmony_ci 73062306a36Sopenharmony_ci err = -EINVAL; 73162306a36Sopenharmony_ci 73262306a36Sopenharmony_ci /* We only support 16-byte blocks. */ 73362306a36Sopenharmony_ci if (crypto_aead_alg_ivsize(alg) != 16) 73462306a36Sopenharmony_ci goto err_free_inst; 73562306a36Sopenharmony_ci 73662306a36Sopenharmony_ci /* Not a stream cipher? */ 73762306a36Sopenharmony_ci if (alg->base.cra_blocksize != 1) 73862306a36Sopenharmony_ci goto err_free_inst; 73962306a36Sopenharmony_ci 74062306a36Sopenharmony_ci err = -ENAMETOOLONG; 74162306a36Sopenharmony_ci if (snprintf(inst->alg.base.cra_name, CRYPTO_MAX_ALG_NAME, 74262306a36Sopenharmony_ci "rfc4309(%s)", alg->base.cra_name) >= 74362306a36Sopenharmony_ci CRYPTO_MAX_ALG_NAME || 74462306a36Sopenharmony_ci snprintf(inst->alg.base.cra_driver_name, CRYPTO_MAX_ALG_NAME, 74562306a36Sopenharmony_ci "rfc4309(%s)", alg->base.cra_driver_name) >= 74662306a36Sopenharmony_ci CRYPTO_MAX_ALG_NAME) 74762306a36Sopenharmony_ci goto err_free_inst; 74862306a36Sopenharmony_ci 74962306a36Sopenharmony_ci inst->alg.base.cra_priority = alg->base.cra_priority; 75062306a36Sopenharmony_ci inst->alg.base.cra_blocksize = 1; 75162306a36Sopenharmony_ci inst->alg.base.cra_alignmask = alg->base.cra_alignmask; 75262306a36Sopenharmony_ci 75362306a36Sopenharmony_ci inst->alg.ivsize = 8; 75462306a36Sopenharmony_ci inst->alg.chunksize = crypto_aead_alg_chunksize(alg); 75562306a36Sopenharmony_ci inst->alg.maxauthsize = 16; 75662306a36Sopenharmony_ci 75762306a36Sopenharmony_ci inst->alg.base.cra_ctxsize = sizeof(struct crypto_rfc4309_ctx); 75862306a36Sopenharmony_ci 75962306a36Sopenharmony_ci inst->alg.init = crypto_rfc4309_init_tfm; 76062306a36Sopenharmony_ci inst->alg.exit = crypto_rfc4309_exit_tfm; 76162306a36Sopenharmony_ci 76262306a36Sopenharmony_ci inst->alg.setkey = crypto_rfc4309_setkey; 76362306a36Sopenharmony_ci inst->alg.setauthsize = crypto_rfc4309_setauthsize; 76462306a36Sopenharmony_ci inst->alg.encrypt = crypto_rfc4309_encrypt; 76562306a36Sopenharmony_ci inst->alg.decrypt = crypto_rfc4309_decrypt; 76662306a36Sopenharmony_ci 76762306a36Sopenharmony_ci inst->free = crypto_rfc4309_free; 76862306a36Sopenharmony_ci 76962306a36Sopenharmony_ci err = aead_register_instance(tmpl, inst); 77062306a36Sopenharmony_ci if (err) { 77162306a36Sopenharmony_cierr_free_inst: 77262306a36Sopenharmony_ci crypto_rfc4309_free(inst); 77362306a36Sopenharmony_ci } 77462306a36Sopenharmony_ci return err; 77562306a36Sopenharmony_ci} 77662306a36Sopenharmony_ci 77762306a36Sopenharmony_cistatic int crypto_cbcmac_digest_setkey(struct crypto_shash *parent, 77862306a36Sopenharmony_ci const u8 *inkey, unsigned int keylen) 77962306a36Sopenharmony_ci{ 78062306a36Sopenharmony_ci struct cbcmac_tfm_ctx *ctx = crypto_shash_ctx(parent); 78162306a36Sopenharmony_ci 78262306a36Sopenharmony_ci return crypto_cipher_setkey(ctx->child, inkey, keylen); 78362306a36Sopenharmony_ci} 78462306a36Sopenharmony_ci 78562306a36Sopenharmony_cistatic int crypto_cbcmac_digest_init(struct shash_desc *pdesc) 78662306a36Sopenharmony_ci{ 78762306a36Sopenharmony_ci struct cbcmac_desc_ctx *ctx = shash_desc_ctx(pdesc); 78862306a36Sopenharmony_ci int bs = crypto_shash_digestsize(pdesc->tfm); 78962306a36Sopenharmony_ci u8 *dg = (u8 *)ctx + crypto_shash_descsize(pdesc->tfm) - bs; 79062306a36Sopenharmony_ci 79162306a36Sopenharmony_ci ctx->len = 0; 79262306a36Sopenharmony_ci memset(dg, 0, bs); 79362306a36Sopenharmony_ci 79462306a36Sopenharmony_ci return 0; 79562306a36Sopenharmony_ci} 79662306a36Sopenharmony_ci 79762306a36Sopenharmony_cistatic int crypto_cbcmac_digest_update(struct shash_desc *pdesc, const u8 *p, 79862306a36Sopenharmony_ci unsigned int len) 79962306a36Sopenharmony_ci{ 80062306a36Sopenharmony_ci struct crypto_shash *parent = pdesc->tfm; 80162306a36Sopenharmony_ci struct cbcmac_tfm_ctx *tctx = crypto_shash_ctx(parent); 80262306a36Sopenharmony_ci struct cbcmac_desc_ctx *ctx = shash_desc_ctx(pdesc); 80362306a36Sopenharmony_ci struct crypto_cipher *tfm = tctx->child; 80462306a36Sopenharmony_ci int bs = crypto_shash_digestsize(parent); 80562306a36Sopenharmony_ci u8 *dg = (u8 *)ctx + crypto_shash_descsize(parent) - bs; 80662306a36Sopenharmony_ci 80762306a36Sopenharmony_ci while (len > 0) { 80862306a36Sopenharmony_ci unsigned int l = min(len, bs - ctx->len); 80962306a36Sopenharmony_ci 81062306a36Sopenharmony_ci crypto_xor(dg + ctx->len, p, l); 81162306a36Sopenharmony_ci ctx->len +=l; 81262306a36Sopenharmony_ci len -= l; 81362306a36Sopenharmony_ci p += l; 81462306a36Sopenharmony_ci 81562306a36Sopenharmony_ci if (ctx->len == bs) { 81662306a36Sopenharmony_ci crypto_cipher_encrypt_one(tfm, dg, dg); 81762306a36Sopenharmony_ci ctx->len = 0; 81862306a36Sopenharmony_ci } 81962306a36Sopenharmony_ci } 82062306a36Sopenharmony_ci 82162306a36Sopenharmony_ci return 0; 82262306a36Sopenharmony_ci} 82362306a36Sopenharmony_ci 82462306a36Sopenharmony_cistatic int crypto_cbcmac_digest_final(struct shash_desc *pdesc, u8 *out) 82562306a36Sopenharmony_ci{ 82662306a36Sopenharmony_ci struct crypto_shash *parent = pdesc->tfm; 82762306a36Sopenharmony_ci struct cbcmac_tfm_ctx *tctx = crypto_shash_ctx(parent); 82862306a36Sopenharmony_ci struct cbcmac_desc_ctx *ctx = shash_desc_ctx(pdesc); 82962306a36Sopenharmony_ci struct crypto_cipher *tfm = tctx->child; 83062306a36Sopenharmony_ci int bs = crypto_shash_digestsize(parent); 83162306a36Sopenharmony_ci u8 *dg = (u8 *)ctx + crypto_shash_descsize(parent) - bs; 83262306a36Sopenharmony_ci 83362306a36Sopenharmony_ci if (ctx->len) 83462306a36Sopenharmony_ci crypto_cipher_encrypt_one(tfm, dg, dg); 83562306a36Sopenharmony_ci 83662306a36Sopenharmony_ci memcpy(out, dg, bs); 83762306a36Sopenharmony_ci return 0; 83862306a36Sopenharmony_ci} 83962306a36Sopenharmony_ci 84062306a36Sopenharmony_cistatic int cbcmac_init_tfm(struct crypto_tfm *tfm) 84162306a36Sopenharmony_ci{ 84262306a36Sopenharmony_ci struct crypto_cipher *cipher; 84362306a36Sopenharmony_ci struct crypto_instance *inst = (void *)tfm->__crt_alg; 84462306a36Sopenharmony_ci struct crypto_cipher_spawn *spawn = crypto_instance_ctx(inst); 84562306a36Sopenharmony_ci struct cbcmac_tfm_ctx *ctx = crypto_tfm_ctx(tfm); 84662306a36Sopenharmony_ci 84762306a36Sopenharmony_ci cipher = crypto_spawn_cipher(spawn); 84862306a36Sopenharmony_ci if (IS_ERR(cipher)) 84962306a36Sopenharmony_ci return PTR_ERR(cipher); 85062306a36Sopenharmony_ci 85162306a36Sopenharmony_ci ctx->child = cipher; 85262306a36Sopenharmony_ci 85362306a36Sopenharmony_ci return 0; 85462306a36Sopenharmony_ci}; 85562306a36Sopenharmony_ci 85662306a36Sopenharmony_cistatic void cbcmac_exit_tfm(struct crypto_tfm *tfm) 85762306a36Sopenharmony_ci{ 85862306a36Sopenharmony_ci struct cbcmac_tfm_ctx *ctx = crypto_tfm_ctx(tfm); 85962306a36Sopenharmony_ci crypto_free_cipher(ctx->child); 86062306a36Sopenharmony_ci} 86162306a36Sopenharmony_ci 86262306a36Sopenharmony_cistatic int cbcmac_create(struct crypto_template *tmpl, struct rtattr **tb) 86362306a36Sopenharmony_ci{ 86462306a36Sopenharmony_ci struct shash_instance *inst; 86562306a36Sopenharmony_ci struct crypto_cipher_spawn *spawn; 86662306a36Sopenharmony_ci struct crypto_alg *alg; 86762306a36Sopenharmony_ci u32 mask; 86862306a36Sopenharmony_ci int err; 86962306a36Sopenharmony_ci 87062306a36Sopenharmony_ci err = crypto_check_attr_type(tb, CRYPTO_ALG_TYPE_SHASH, &mask); 87162306a36Sopenharmony_ci if (err) 87262306a36Sopenharmony_ci return err; 87362306a36Sopenharmony_ci 87462306a36Sopenharmony_ci inst = kzalloc(sizeof(*inst) + sizeof(*spawn), GFP_KERNEL); 87562306a36Sopenharmony_ci if (!inst) 87662306a36Sopenharmony_ci return -ENOMEM; 87762306a36Sopenharmony_ci spawn = shash_instance_ctx(inst); 87862306a36Sopenharmony_ci 87962306a36Sopenharmony_ci err = crypto_grab_cipher(spawn, shash_crypto_instance(inst), 88062306a36Sopenharmony_ci crypto_attr_alg_name(tb[1]), 0, mask); 88162306a36Sopenharmony_ci if (err) 88262306a36Sopenharmony_ci goto err_free_inst; 88362306a36Sopenharmony_ci alg = crypto_spawn_cipher_alg(spawn); 88462306a36Sopenharmony_ci 88562306a36Sopenharmony_ci err = crypto_inst_setname(shash_crypto_instance(inst), tmpl->name, alg); 88662306a36Sopenharmony_ci if (err) 88762306a36Sopenharmony_ci goto err_free_inst; 88862306a36Sopenharmony_ci 88962306a36Sopenharmony_ci inst->alg.base.cra_priority = alg->cra_priority; 89062306a36Sopenharmony_ci inst->alg.base.cra_blocksize = 1; 89162306a36Sopenharmony_ci 89262306a36Sopenharmony_ci inst->alg.digestsize = alg->cra_blocksize; 89362306a36Sopenharmony_ci inst->alg.descsize = ALIGN(sizeof(struct cbcmac_desc_ctx), 89462306a36Sopenharmony_ci alg->cra_alignmask + 1) + 89562306a36Sopenharmony_ci alg->cra_blocksize; 89662306a36Sopenharmony_ci 89762306a36Sopenharmony_ci inst->alg.base.cra_ctxsize = sizeof(struct cbcmac_tfm_ctx); 89862306a36Sopenharmony_ci inst->alg.base.cra_init = cbcmac_init_tfm; 89962306a36Sopenharmony_ci inst->alg.base.cra_exit = cbcmac_exit_tfm; 90062306a36Sopenharmony_ci 90162306a36Sopenharmony_ci inst->alg.init = crypto_cbcmac_digest_init; 90262306a36Sopenharmony_ci inst->alg.update = crypto_cbcmac_digest_update; 90362306a36Sopenharmony_ci inst->alg.final = crypto_cbcmac_digest_final; 90462306a36Sopenharmony_ci inst->alg.setkey = crypto_cbcmac_digest_setkey; 90562306a36Sopenharmony_ci 90662306a36Sopenharmony_ci inst->free = shash_free_singlespawn_instance; 90762306a36Sopenharmony_ci 90862306a36Sopenharmony_ci err = shash_register_instance(tmpl, inst); 90962306a36Sopenharmony_ci if (err) { 91062306a36Sopenharmony_cierr_free_inst: 91162306a36Sopenharmony_ci shash_free_singlespawn_instance(inst); 91262306a36Sopenharmony_ci } 91362306a36Sopenharmony_ci return err; 91462306a36Sopenharmony_ci} 91562306a36Sopenharmony_ci 91662306a36Sopenharmony_cistatic struct crypto_template crypto_ccm_tmpls[] = { 91762306a36Sopenharmony_ci { 91862306a36Sopenharmony_ci .name = "cbcmac", 91962306a36Sopenharmony_ci .create = cbcmac_create, 92062306a36Sopenharmony_ci .module = THIS_MODULE, 92162306a36Sopenharmony_ci }, { 92262306a36Sopenharmony_ci .name = "ccm_base", 92362306a36Sopenharmony_ci .create = crypto_ccm_base_create, 92462306a36Sopenharmony_ci .module = THIS_MODULE, 92562306a36Sopenharmony_ci }, { 92662306a36Sopenharmony_ci .name = "ccm", 92762306a36Sopenharmony_ci .create = crypto_ccm_create, 92862306a36Sopenharmony_ci .module = THIS_MODULE, 92962306a36Sopenharmony_ci }, { 93062306a36Sopenharmony_ci .name = "rfc4309", 93162306a36Sopenharmony_ci .create = crypto_rfc4309_create, 93262306a36Sopenharmony_ci .module = THIS_MODULE, 93362306a36Sopenharmony_ci }, 93462306a36Sopenharmony_ci}; 93562306a36Sopenharmony_ci 93662306a36Sopenharmony_cistatic int __init crypto_ccm_module_init(void) 93762306a36Sopenharmony_ci{ 93862306a36Sopenharmony_ci return crypto_register_templates(crypto_ccm_tmpls, 93962306a36Sopenharmony_ci ARRAY_SIZE(crypto_ccm_tmpls)); 94062306a36Sopenharmony_ci} 94162306a36Sopenharmony_ci 94262306a36Sopenharmony_cistatic void __exit crypto_ccm_module_exit(void) 94362306a36Sopenharmony_ci{ 94462306a36Sopenharmony_ci crypto_unregister_templates(crypto_ccm_tmpls, 94562306a36Sopenharmony_ci ARRAY_SIZE(crypto_ccm_tmpls)); 94662306a36Sopenharmony_ci} 94762306a36Sopenharmony_ci 94862306a36Sopenharmony_cisubsys_initcall(crypto_ccm_module_init); 94962306a36Sopenharmony_cimodule_exit(crypto_ccm_module_exit); 95062306a36Sopenharmony_ci 95162306a36Sopenharmony_ciMODULE_LICENSE("GPL"); 95262306a36Sopenharmony_ciMODULE_DESCRIPTION("Counter with CBC MAC"); 95362306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ccm_base"); 95462306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("rfc4309"); 95562306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ccm"); 95662306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cbcmac"); 95762306a36Sopenharmony_ciMODULE_IMPORT_NS(CRYPTO_INTERNAL); 958