162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later 262306a36Sopenharmony_ci 362306a36Sopenharmony_ci#include <crypto/curve25519.h> 462306a36Sopenharmony_ci#include <crypto/internal/kpp.h> 562306a36Sopenharmony_ci#include <crypto/kpp.h> 662306a36Sopenharmony_ci#include <linux/module.h> 762306a36Sopenharmony_ci#include <linux/scatterlist.h> 862306a36Sopenharmony_ci 962306a36Sopenharmony_cistatic int curve25519_set_secret(struct crypto_kpp *tfm, const void *buf, 1062306a36Sopenharmony_ci unsigned int len) 1162306a36Sopenharmony_ci{ 1262306a36Sopenharmony_ci u8 *secret = kpp_tfm_ctx(tfm); 1362306a36Sopenharmony_ci 1462306a36Sopenharmony_ci if (!len) 1562306a36Sopenharmony_ci curve25519_generate_secret(secret); 1662306a36Sopenharmony_ci else if (len == CURVE25519_KEY_SIZE && 1762306a36Sopenharmony_ci crypto_memneq(buf, curve25519_null_point, CURVE25519_KEY_SIZE)) 1862306a36Sopenharmony_ci memcpy(secret, buf, CURVE25519_KEY_SIZE); 1962306a36Sopenharmony_ci else 2062306a36Sopenharmony_ci return -EINVAL; 2162306a36Sopenharmony_ci return 0; 2262306a36Sopenharmony_ci} 2362306a36Sopenharmony_ci 2462306a36Sopenharmony_cistatic int curve25519_compute_value(struct kpp_request *req) 2562306a36Sopenharmony_ci{ 2662306a36Sopenharmony_ci struct crypto_kpp *tfm = crypto_kpp_reqtfm(req); 2762306a36Sopenharmony_ci const u8 *secret = kpp_tfm_ctx(tfm); 2862306a36Sopenharmony_ci u8 public_key[CURVE25519_KEY_SIZE]; 2962306a36Sopenharmony_ci u8 buf[CURVE25519_KEY_SIZE]; 3062306a36Sopenharmony_ci int copied, nbytes; 3162306a36Sopenharmony_ci u8 const *bp; 3262306a36Sopenharmony_ci 3362306a36Sopenharmony_ci if (req->src) { 3462306a36Sopenharmony_ci copied = sg_copy_to_buffer(req->src, 3562306a36Sopenharmony_ci sg_nents_for_len(req->src, 3662306a36Sopenharmony_ci CURVE25519_KEY_SIZE), 3762306a36Sopenharmony_ci public_key, CURVE25519_KEY_SIZE); 3862306a36Sopenharmony_ci if (copied != CURVE25519_KEY_SIZE) 3962306a36Sopenharmony_ci return -EINVAL; 4062306a36Sopenharmony_ci bp = public_key; 4162306a36Sopenharmony_ci } else { 4262306a36Sopenharmony_ci bp = curve25519_base_point; 4362306a36Sopenharmony_ci } 4462306a36Sopenharmony_ci 4562306a36Sopenharmony_ci curve25519_generic(buf, secret, bp); 4662306a36Sopenharmony_ci 4762306a36Sopenharmony_ci /* might want less than we've got */ 4862306a36Sopenharmony_ci nbytes = min_t(size_t, CURVE25519_KEY_SIZE, req->dst_len); 4962306a36Sopenharmony_ci copied = sg_copy_from_buffer(req->dst, sg_nents_for_len(req->dst, 5062306a36Sopenharmony_ci nbytes), 5162306a36Sopenharmony_ci buf, nbytes); 5262306a36Sopenharmony_ci if (copied != nbytes) 5362306a36Sopenharmony_ci return -EINVAL; 5462306a36Sopenharmony_ci return 0; 5562306a36Sopenharmony_ci} 5662306a36Sopenharmony_ci 5762306a36Sopenharmony_cistatic unsigned int curve25519_max_size(struct crypto_kpp *tfm) 5862306a36Sopenharmony_ci{ 5962306a36Sopenharmony_ci return CURVE25519_KEY_SIZE; 6062306a36Sopenharmony_ci} 6162306a36Sopenharmony_ci 6262306a36Sopenharmony_cistatic struct kpp_alg curve25519_alg = { 6362306a36Sopenharmony_ci .base.cra_name = "curve25519", 6462306a36Sopenharmony_ci .base.cra_driver_name = "curve25519-generic", 6562306a36Sopenharmony_ci .base.cra_priority = 100, 6662306a36Sopenharmony_ci .base.cra_module = THIS_MODULE, 6762306a36Sopenharmony_ci .base.cra_ctxsize = CURVE25519_KEY_SIZE, 6862306a36Sopenharmony_ci 6962306a36Sopenharmony_ci .set_secret = curve25519_set_secret, 7062306a36Sopenharmony_ci .generate_public_key = curve25519_compute_value, 7162306a36Sopenharmony_ci .compute_shared_secret = curve25519_compute_value, 7262306a36Sopenharmony_ci .max_size = curve25519_max_size, 7362306a36Sopenharmony_ci}; 7462306a36Sopenharmony_ci 7562306a36Sopenharmony_cistatic int __init curve25519_init(void) 7662306a36Sopenharmony_ci{ 7762306a36Sopenharmony_ci return crypto_register_kpp(&curve25519_alg); 7862306a36Sopenharmony_ci} 7962306a36Sopenharmony_ci 8062306a36Sopenharmony_cistatic void __exit curve25519_exit(void) 8162306a36Sopenharmony_ci{ 8262306a36Sopenharmony_ci crypto_unregister_kpp(&curve25519_alg); 8362306a36Sopenharmony_ci} 8462306a36Sopenharmony_ci 8562306a36Sopenharmony_cisubsys_initcall(curve25519_init); 8662306a36Sopenharmony_cimodule_exit(curve25519_exit); 8762306a36Sopenharmony_ci 8862306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("curve25519"); 8962306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("curve25519-generic"); 9062306a36Sopenharmony_ciMODULE_LICENSE("GPL"); 91