162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0 262306a36Sopenharmony_ci 362306a36Sopenharmony_ci/* 462306a36Sopenharmony_ci * OFB: Output FeedBack mode 562306a36Sopenharmony_ci * 662306a36Sopenharmony_ci * Copyright (C) 2018 ARM Limited or its affiliates. 762306a36Sopenharmony_ci * All rights reserved. 862306a36Sopenharmony_ci */ 962306a36Sopenharmony_ci 1062306a36Sopenharmony_ci#include <crypto/algapi.h> 1162306a36Sopenharmony_ci#include <crypto/internal/cipher.h> 1262306a36Sopenharmony_ci#include <crypto/internal/skcipher.h> 1362306a36Sopenharmony_ci#include <linux/err.h> 1462306a36Sopenharmony_ci#include <linux/init.h> 1562306a36Sopenharmony_ci#include <linux/kernel.h> 1662306a36Sopenharmony_ci#include <linux/module.h> 1762306a36Sopenharmony_ci 1862306a36Sopenharmony_cistatic int crypto_ofb_crypt(struct skcipher_request *req) 1962306a36Sopenharmony_ci{ 2062306a36Sopenharmony_ci struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req); 2162306a36Sopenharmony_ci struct crypto_cipher *cipher = skcipher_cipher_simple(tfm); 2262306a36Sopenharmony_ci const unsigned int bsize = crypto_cipher_blocksize(cipher); 2362306a36Sopenharmony_ci struct skcipher_walk walk; 2462306a36Sopenharmony_ci int err; 2562306a36Sopenharmony_ci 2662306a36Sopenharmony_ci err = skcipher_walk_virt(&walk, req, false); 2762306a36Sopenharmony_ci 2862306a36Sopenharmony_ci while (walk.nbytes >= bsize) { 2962306a36Sopenharmony_ci const u8 *src = walk.src.virt.addr; 3062306a36Sopenharmony_ci u8 *dst = walk.dst.virt.addr; 3162306a36Sopenharmony_ci u8 * const iv = walk.iv; 3262306a36Sopenharmony_ci unsigned int nbytes = walk.nbytes; 3362306a36Sopenharmony_ci 3462306a36Sopenharmony_ci do { 3562306a36Sopenharmony_ci crypto_cipher_encrypt_one(cipher, iv, iv); 3662306a36Sopenharmony_ci crypto_xor_cpy(dst, src, iv, bsize); 3762306a36Sopenharmony_ci dst += bsize; 3862306a36Sopenharmony_ci src += bsize; 3962306a36Sopenharmony_ci } while ((nbytes -= bsize) >= bsize); 4062306a36Sopenharmony_ci 4162306a36Sopenharmony_ci err = skcipher_walk_done(&walk, nbytes); 4262306a36Sopenharmony_ci } 4362306a36Sopenharmony_ci 4462306a36Sopenharmony_ci if (walk.nbytes) { 4562306a36Sopenharmony_ci crypto_cipher_encrypt_one(cipher, walk.iv, walk.iv); 4662306a36Sopenharmony_ci crypto_xor_cpy(walk.dst.virt.addr, walk.src.virt.addr, walk.iv, 4762306a36Sopenharmony_ci walk.nbytes); 4862306a36Sopenharmony_ci err = skcipher_walk_done(&walk, 0); 4962306a36Sopenharmony_ci } 5062306a36Sopenharmony_ci return err; 5162306a36Sopenharmony_ci} 5262306a36Sopenharmony_ci 5362306a36Sopenharmony_cistatic int crypto_ofb_create(struct crypto_template *tmpl, struct rtattr **tb) 5462306a36Sopenharmony_ci{ 5562306a36Sopenharmony_ci struct skcipher_instance *inst; 5662306a36Sopenharmony_ci struct crypto_alg *alg; 5762306a36Sopenharmony_ci int err; 5862306a36Sopenharmony_ci 5962306a36Sopenharmony_ci inst = skcipher_alloc_instance_simple(tmpl, tb); 6062306a36Sopenharmony_ci if (IS_ERR(inst)) 6162306a36Sopenharmony_ci return PTR_ERR(inst); 6262306a36Sopenharmony_ci 6362306a36Sopenharmony_ci alg = skcipher_ialg_simple(inst); 6462306a36Sopenharmony_ci 6562306a36Sopenharmony_ci /* OFB mode is a stream cipher. */ 6662306a36Sopenharmony_ci inst->alg.base.cra_blocksize = 1; 6762306a36Sopenharmony_ci 6862306a36Sopenharmony_ci /* 6962306a36Sopenharmony_ci * To simplify the implementation, configure the skcipher walk to only 7062306a36Sopenharmony_ci * give a partial block at the very end, never earlier. 7162306a36Sopenharmony_ci */ 7262306a36Sopenharmony_ci inst->alg.chunksize = alg->cra_blocksize; 7362306a36Sopenharmony_ci 7462306a36Sopenharmony_ci inst->alg.encrypt = crypto_ofb_crypt; 7562306a36Sopenharmony_ci inst->alg.decrypt = crypto_ofb_crypt; 7662306a36Sopenharmony_ci 7762306a36Sopenharmony_ci err = skcipher_register_instance(tmpl, inst); 7862306a36Sopenharmony_ci if (err) 7962306a36Sopenharmony_ci inst->free(inst); 8062306a36Sopenharmony_ci 8162306a36Sopenharmony_ci return err; 8262306a36Sopenharmony_ci} 8362306a36Sopenharmony_ci 8462306a36Sopenharmony_cistatic struct crypto_template crypto_ofb_tmpl = { 8562306a36Sopenharmony_ci .name = "ofb", 8662306a36Sopenharmony_ci .create = crypto_ofb_create, 8762306a36Sopenharmony_ci .module = THIS_MODULE, 8862306a36Sopenharmony_ci}; 8962306a36Sopenharmony_ci 9062306a36Sopenharmony_cistatic int __init crypto_ofb_module_init(void) 9162306a36Sopenharmony_ci{ 9262306a36Sopenharmony_ci return crypto_register_template(&crypto_ofb_tmpl); 9362306a36Sopenharmony_ci} 9462306a36Sopenharmony_ci 9562306a36Sopenharmony_cistatic void __exit crypto_ofb_module_exit(void) 9662306a36Sopenharmony_ci{ 9762306a36Sopenharmony_ci crypto_unregister_template(&crypto_ofb_tmpl); 9862306a36Sopenharmony_ci} 9962306a36Sopenharmony_ci 10062306a36Sopenharmony_cisubsys_initcall(crypto_ofb_module_init); 10162306a36Sopenharmony_cimodule_exit(crypto_ofb_module_exit); 10262306a36Sopenharmony_ci 10362306a36Sopenharmony_ciMODULE_LICENSE("GPL"); 10462306a36Sopenharmony_ciMODULE_DESCRIPTION("OFB block cipher mode of operation"); 10562306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ofb"); 10662306a36Sopenharmony_ciMODULE_IMPORT_NS(CRYPTO_INTERNAL); 107