162306a36Sopenharmony_ci/* SPDX-License-Identifier: GPL-2.0-only */ 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * AMD Cryptographic Coprocessor (CCP) crypto API support 462306a36Sopenharmony_ci * 562306a36Sopenharmony_ci * Copyright (C) 2013,2017 Advanced Micro Devices, Inc. 662306a36Sopenharmony_ci * 762306a36Sopenharmony_ci * Author: Tom Lendacky <thomas.lendacky@amd.com> 862306a36Sopenharmony_ci */ 962306a36Sopenharmony_ci 1062306a36Sopenharmony_ci#ifndef __CCP_CRYPTO_H__ 1162306a36Sopenharmony_ci#define __CCP_CRYPTO_H__ 1262306a36Sopenharmony_ci 1362306a36Sopenharmony_ci#include <linux/list.h> 1462306a36Sopenharmony_ci#include <linux/wait.h> 1562306a36Sopenharmony_ci#include <linux/ccp.h> 1662306a36Sopenharmony_ci#include <crypto/algapi.h> 1762306a36Sopenharmony_ci#include <crypto/aes.h> 1862306a36Sopenharmony_ci#include <crypto/internal/aead.h> 1962306a36Sopenharmony_ci#include <crypto/aead.h> 2062306a36Sopenharmony_ci#include <crypto/ctr.h> 2162306a36Sopenharmony_ci#include <crypto/hash.h> 2262306a36Sopenharmony_ci#include <crypto/sha1.h> 2362306a36Sopenharmony_ci#include <crypto/sha2.h> 2462306a36Sopenharmony_ci#include <crypto/akcipher.h> 2562306a36Sopenharmony_ci#include <crypto/skcipher.h> 2662306a36Sopenharmony_ci#include <crypto/internal/rsa.h> 2762306a36Sopenharmony_ci 2862306a36Sopenharmony_ci/* We want the module name in front of our messages */ 2962306a36Sopenharmony_ci#undef pr_fmt 3062306a36Sopenharmony_ci#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt 3162306a36Sopenharmony_ci 3262306a36Sopenharmony_ci#define CCP_LOG_LEVEL KERN_INFO 3362306a36Sopenharmony_ci 3462306a36Sopenharmony_ci#define CCP_CRA_PRIORITY 300 3562306a36Sopenharmony_ci 3662306a36Sopenharmony_cistruct ccp_crypto_skcipher_alg { 3762306a36Sopenharmony_ci struct list_head entry; 3862306a36Sopenharmony_ci 3962306a36Sopenharmony_ci u32 mode; 4062306a36Sopenharmony_ci 4162306a36Sopenharmony_ci struct skcipher_alg alg; 4262306a36Sopenharmony_ci}; 4362306a36Sopenharmony_ci 4462306a36Sopenharmony_cistruct ccp_crypto_aead { 4562306a36Sopenharmony_ci struct list_head entry; 4662306a36Sopenharmony_ci 4762306a36Sopenharmony_ci u32 mode; 4862306a36Sopenharmony_ci 4962306a36Sopenharmony_ci struct aead_alg alg; 5062306a36Sopenharmony_ci}; 5162306a36Sopenharmony_ci 5262306a36Sopenharmony_cistruct ccp_crypto_ahash_alg { 5362306a36Sopenharmony_ci struct list_head entry; 5462306a36Sopenharmony_ci 5562306a36Sopenharmony_ci const __be32 *init; 5662306a36Sopenharmony_ci u32 type; 5762306a36Sopenharmony_ci u32 mode; 5862306a36Sopenharmony_ci 5962306a36Sopenharmony_ci /* Child algorithm used for HMAC, CMAC, etc */ 6062306a36Sopenharmony_ci char child_alg[CRYPTO_MAX_ALG_NAME]; 6162306a36Sopenharmony_ci 6262306a36Sopenharmony_ci struct ahash_alg alg; 6362306a36Sopenharmony_ci}; 6462306a36Sopenharmony_ci 6562306a36Sopenharmony_cistruct ccp_crypto_akcipher_alg { 6662306a36Sopenharmony_ci struct list_head entry; 6762306a36Sopenharmony_ci 6862306a36Sopenharmony_ci struct akcipher_alg alg; 6962306a36Sopenharmony_ci}; 7062306a36Sopenharmony_ci 7162306a36Sopenharmony_cistatic inline struct ccp_crypto_skcipher_alg * 7262306a36Sopenharmony_ci ccp_crypto_skcipher_alg(struct crypto_skcipher *tfm) 7362306a36Sopenharmony_ci{ 7462306a36Sopenharmony_ci struct skcipher_alg *alg = crypto_skcipher_alg(tfm); 7562306a36Sopenharmony_ci 7662306a36Sopenharmony_ci return container_of(alg, struct ccp_crypto_skcipher_alg, alg); 7762306a36Sopenharmony_ci} 7862306a36Sopenharmony_ci 7962306a36Sopenharmony_cistatic inline struct ccp_crypto_ahash_alg * 8062306a36Sopenharmony_ci ccp_crypto_ahash_alg(struct crypto_tfm *tfm) 8162306a36Sopenharmony_ci{ 8262306a36Sopenharmony_ci struct crypto_alg *alg = tfm->__crt_alg; 8362306a36Sopenharmony_ci struct ahash_alg *ahash_alg; 8462306a36Sopenharmony_ci 8562306a36Sopenharmony_ci ahash_alg = container_of(alg, struct ahash_alg, halg.base); 8662306a36Sopenharmony_ci 8762306a36Sopenharmony_ci return container_of(ahash_alg, struct ccp_crypto_ahash_alg, alg); 8862306a36Sopenharmony_ci} 8962306a36Sopenharmony_ci 9062306a36Sopenharmony_ci/***** AES related defines *****/ 9162306a36Sopenharmony_cistruct ccp_aes_ctx { 9262306a36Sopenharmony_ci /* Fallback cipher for XTS with unsupported unit sizes */ 9362306a36Sopenharmony_ci struct crypto_skcipher *tfm_skcipher; 9462306a36Sopenharmony_ci 9562306a36Sopenharmony_ci enum ccp_engine engine; 9662306a36Sopenharmony_ci enum ccp_aes_type type; 9762306a36Sopenharmony_ci enum ccp_aes_mode mode; 9862306a36Sopenharmony_ci 9962306a36Sopenharmony_ci struct scatterlist key_sg; 10062306a36Sopenharmony_ci unsigned int key_len; 10162306a36Sopenharmony_ci u8 key[AES_MAX_KEY_SIZE * 2]; 10262306a36Sopenharmony_ci 10362306a36Sopenharmony_ci u8 nonce[CTR_RFC3686_NONCE_SIZE]; 10462306a36Sopenharmony_ci 10562306a36Sopenharmony_ci /* CMAC key structures */ 10662306a36Sopenharmony_ci struct scatterlist k1_sg; 10762306a36Sopenharmony_ci struct scatterlist k2_sg; 10862306a36Sopenharmony_ci unsigned int kn_len; 10962306a36Sopenharmony_ci u8 k1[AES_BLOCK_SIZE]; 11062306a36Sopenharmony_ci u8 k2[AES_BLOCK_SIZE]; 11162306a36Sopenharmony_ci}; 11262306a36Sopenharmony_ci 11362306a36Sopenharmony_cistruct ccp_aes_req_ctx { 11462306a36Sopenharmony_ci struct scatterlist iv_sg; 11562306a36Sopenharmony_ci u8 iv[AES_BLOCK_SIZE]; 11662306a36Sopenharmony_ci 11762306a36Sopenharmony_ci struct scatterlist tag_sg; 11862306a36Sopenharmony_ci u8 tag[AES_BLOCK_SIZE]; 11962306a36Sopenharmony_ci 12062306a36Sopenharmony_ci /* Fields used for RFC3686 requests */ 12162306a36Sopenharmony_ci u8 *rfc3686_info; 12262306a36Sopenharmony_ci u8 rfc3686_iv[AES_BLOCK_SIZE]; 12362306a36Sopenharmony_ci 12462306a36Sopenharmony_ci struct ccp_cmd cmd; 12562306a36Sopenharmony_ci 12662306a36Sopenharmony_ci struct skcipher_request fallback_req; // keep at the end 12762306a36Sopenharmony_ci}; 12862306a36Sopenharmony_ci 12962306a36Sopenharmony_cistruct ccp_aes_cmac_req_ctx { 13062306a36Sopenharmony_ci unsigned int null_msg; 13162306a36Sopenharmony_ci unsigned int final; 13262306a36Sopenharmony_ci 13362306a36Sopenharmony_ci struct scatterlist *src; 13462306a36Sopenharmony_ci unsigned int nbytes; 13562306a36Sopenharmony_ci 13662306a36Sopenharmony_ci u64 hash_cnt; 13762306a36Sopenharmony_ci unsigned int hash_rem; 13862306a36Sopenharmony_ci 13962306a36Sopenharmony_ci struct sg_table data_sg; 14062306a36Sopenharmony_ci 14162306a36Sopenharmony_ci struct scatterlist iv_sg; 14262306a36Sopenharmony_ci u8 iv[AES_BLOCK_SIZE]; 14362306a36Sopenharmony_ci 14462306a36Sopenharmony_ci struct scatterlist buf_sg; 14562306a36Sopenharmony_ci unsigned int buf_count; 14662306a36Sopenharmony_ci u8 buf[AES_BLOCK_SIZE]; 14762306a36Sopenharmony_ci 14862306a36Sopenharmony_ci struct scatterlist pad_sg; 14962306a36Sopenharmony_ci unsigned int pad_count; 15062306a36Sopenharmony_ci u8 pad[AES_BLOCK_SIZE]; 15162306a36Sopenharmony_ci 15262306a36Sopenharmony_ci struct ccp_cmd cmd; 15362306a36Sopenharmony_ci}; 15462306a36Sopenharmony_ci 15562306a36Sopenharmony_cistruct ccp_aes_cmac_exp_ctx { 15662306a36Sopenharmony_ci unsigned int null_msg; 15762306a36Sopenharmony_ci 15862306a36Sopenharmony_ci u8 iv[AES_BLOCK_SIZE]; 15962306a36Sopenharmony_ci 16062306a36Sopenharmony_ci unsigned int buf_count; 16162306a36Sopenharmony_ci u8 buf[AES_BLOCK_SIZE]; 16262306a36Sopenharmony_ci}; 16362306a36Sopenharmony_ci 16462306a36Sopenharmony_ci/***** 3DES related defines *****/ 16562306a36Sopenharmony_cistruct ccp_des3_ctx { 16662306a36Sopenharmony_ci enum ccp_engine engine; 16762306a36Sopenharmony_ci enum ccp_des3_type type; 16862306a36Sopenharmony_ci enum ccp_des3_mode mode; 16962306a36Sopenharmony_ci 17062306a36Sopenharmony_ci struct scatterlist key_sg; 17162306a36Sopenharmony_ci unsigned int key_len; 17262306a36Sopenharmony_ci u8 key[AES_MAX_KEY_SIZE]; 17362306a36Sopenharmony_ci}; 17462306a36Sopenharmony_ci 17562306a36Sopenharmony_cistruct ccp_des3_req_ctx { 17662306a36Sopenharmony_ci struct scatterlist iv_sg; 17762306a36Sopenharmony_ci u8 iv[AES_BLOCK_SIZE]; 17862306a36Sopenharmony_ci 17962306a36Sopenharmony_ci struct ccp_cmd cmd; 18062306a36Sopenharmony_ci}; 18162306a36Sopenharmony_ci 18262306a36Sopenharmony_ci/* SHA-related defines 18362306a36Sopenharmony_ci * These values must be large enough to accommodate any variant 18462306a36Sopenharmony_ci */ 18562306a36Sopenharmony_ci#define MAX_SHA_CONTEXT_SIZE SHA512_DIGEST_SIZE 18662306a36Sopenharmony_ci#define MAX_SHA_BLOCK_SIZE SHA512_BLOCK_SIZE 18762306a36Sopenharmony_ci 18862306a36Sopenharmony_cistruct ccp_sha_ctx { 18962306a36Sopenharmony_ci struct scatterlist opad_sg; 19062306a36Sopenharmony_ci unsigned int opad_count; 19162306a36Sopenharmony_ci 19262306a36Sopenharmony_ci unsigned int key_len; 19362306a36Sopenharmony_ci u8 key[MAX_SHA_BLOCK_SIZE]; 19462306a36Sopenharmony_ci u8 ipad[MAX_SHA_BLOCK_SIZE]; 19562306a36Sopenharmony_ci u8 opad[MAX_SHA_BLOCK_SIZE]; 19662306a36Sopenharmony_ci struct crypto_shash *hmac_tfm; 19762306a36Sopenharmony_ci}; 19862306a36Sopenharmony_ci 19962306a36Sopenharmony_cistruct ccp_sha_req_ctx { 20062306a36Sopenharmony_ci enum ccp_sha_type type; 20162306a36Sopenharmony_ci 20262306a36Sopenharmony_ci u64 msg_bits; 20362306a36Sopenharmony_ci 20462306a36Sopenharmony_ci unsigned int first; 20562306a36Sopenharmony_ci unsigned int final; 20662306a36Sopenharmony_ci 20762306a36Sopenharmony_ci struct scatterlist *src; 20862306a36Sopenharmony_ci unsigned int nbytes; 20962306a36Sopenharmony_ci 21062306a36Sopenharmony_ci u64 hash_cnt; 21162306a36Sopenharmony_ci unsigned int hash_rem; 21262306a36Sopenharmony_ci 21362306a36Sopenharmony_ci struct sg_table data_sg; 21462306a36Sopenharmony_ci 21562306a36Sopenharmony_ci struct scatterlist ctx_sg; 21662306a36Sopenharmony_ci u8 ctx[MAX_SHA_CONTEXT_SIZE]; 21762306a36Sopenharmony_ci 21862306a36Sopenharmony_ci struct scatterlist buf_sg; 21962306a36Sopenharmony_ci unsigned int buf_count; 22062306a36Sopenharmony_ci u8 buf[MAX_SHA_BLOCK_SIZE]; 22162306a36Sopenharmony_ci 22262306a36Sopenharmony_ci /* CCP driver command */ 22362306a36Sopenharmony_ci struct ccp_cmd cmd; 22462306a36Sopenharmony_ci}; 22562306a36Sopenharmony_ci 22662306a36Sopenharmony_cistruct ccp_sha_exp_ctx { 22762306a36Sopenharmony_ci enum ccp_sha_type type; 22862306a36Sopenharmony_ci 22962306a36Sopenharmony_ci u64 msg_bits; 23062306a36Sopenharmony_ci 23162306a36Sopenharmony_ci unsigned int first; 23262306a36Sopenharmony_ci 23362306a36Sopenharmony_ci u8 ctx[MAX_SHA_CONTEXT_SIZE]; 23462306a36Sopenharmony_ci 23562306a36Sopenharmony_ci unsigned int buf_count; 23662306a36Sopenharmony_ci u8 buf[MAX_SHA_BLOCK_SIZE]; 23762306a36Sopenharmony_ci}; 23862306a36Sopenharmony_ci 23962306a36Sopenharmony_ci/***** RSA related defines *****/ 24062306a36Sopenharmony_ci 24162306a36Sopenharmony_cistruct ccp_rsa_ctx { 24262306a36Sopenharmony_ci unsigned int key_len; /* in bits */ 24362306a36Sopenharmony_ci struct scatterlist e_sg; 24462306a36Sopenharmony_ci u8 *e_buf; 24562306a36Sopenharmony_ci unsigned int e_len; 24662306a36Sopenharmony_ci struct scatterlist n_sg; 24762306a36Sopenharmony_ci u8 *n_buf; 24862306a36Sopenharmony_ci unsigned int n_len; 24962306a36Sopenharmony_ci struct scatterlist d_sg; 25062306a36Sopenharmony_ci u8 *d_buf; 25162306a36Sopenharmony_ci unsigned int d_len; 25262306a36Sopenharmony_ci}; 25362306a36Sopenharmony_ci 25462306a36Sopenharmony_cistruct ccp_rsa_req_ctx { 25562306a36Sopenharmony_ci struct ccp_cmd cmd; 25662306a36Sopenharmony_ci}; 25762306a36Sopenharmony_ci 25862306a36Sopenharmony_ci#define CCP_RSA_MAXMOD (4 * 1024 / 8) 25962306a36Sopenharmony_ci#define CCP5_RSA_MAXMOD (16 * 1024 / 8) 26062306a36Sopenharmony_ci 26162306a36Sopenharmony_ci/***** Common Context Structure *****/ 26262306a36Sopenharmony_cistruct ccp_ctx { 26362306a36Sopenharmony_ci int (*complete)(struct crypto_async_request *req, int ret); 26462306a36Sopenharmony_ci 26562306a36Sopenharmony_ci union { 26662306a36Sopenharmony_ci struct ccp_aes_ctx aes; 26762306a36Sopenharmony_ci struct ccp_rsa_ctx rsa; 26862306a36Sopenharmony_ci struct ccp_sha_ctx sha; 26962306a36Sopenharmony_ci struct ccp_des3_ctx des3; 27062306a36Sopenharmony_ci } u; 27162306a36Sopenharmony_ci}; 27262306a36Sopenharmony_ci 27362306a36Sopenharmony_ciint ccp_crypto_enqueue_request(struct crypto_async_request *req, 27462306a36Sopenharmony_ci struct ccp_cmd *cmd); 27562306a36Sopenharmony_cistruct scatterlist *ccp_crypto_sg_table_add(struct sg_table *table, 27662306a36Sopenharmony_ci struct scatterlist *sg_add); 27762306a36Sopenharmony_ci 27862306a36Sopenharmony_ciint ccp_register_aes_algs(struct list_head *head); 27962306a36Sopenharmony_ciint ccp_register_aes_cmac_algs(struct list_head *head); 28062306a36Sopenharmony_ciint ccp_register_aes_xts_algs(struct list_head *head); 28162306a36Sopenharmony_ciint ccp_register_aes_aeads(struct list_head *head); 28262306a36Sopenharmony_ciint ccp_register_sha_algs(struct list_head *head); 28362306a36Sopenharmony_ciint ccp_register_des3_algs(struct list_head *head); 28462306a36Sopenharmony_ciint ccp_register_rsa_algs(struct list_head *head); 28562306a36Sopenharmony_ci 28662306a36Sopenharmony_ci#endif 287