xref: /freebsd/crypto/openssl/providers/implementations/ciphers/cipher_aes_xts_hw.c (revision b077aed33b7b6aefca7b17ddb250cf521f938613)
1*b077aed3SPierre Pronchery /*
2*b077aed3SPierre Pronchery  * Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.
3*b077aed3SPierre Pronchery  *
4*b077aed3SPierre Pronchery  * Licensed under the Apache License 2.0 (the "License").  You may not use
5*b077aed3SPierre Pronchery  * this file except in compliance with the License.  You can obtain a copy
6*b077aed3SPierre Pronchery  * in the file LICENSE in the source distribution or at
7*b077aed3SPierre Pronchery  * https://www.openssl.org/source/license.html
8*b077aed3SPierre Pronchery  */
9*b077aed3SPierre Pronchery 
10*b077aed3SPierre Pronchery /*
11*b077aed3SPierre Pronchery  * This file uses the low level AES functions (which are deprecated for
12*b077aed3SPierre Pronchery  * non-internal use) in order to implement provider AES ciphers.
13*b077aed3SPierre Pronchery  */
14*b077aed3SPierre Pronchery #include "internal/deprecated.h"
15*b077aed3SPierre Pronchery 
16*b077aed3SPierre Pronchery #include "cipher_aes_xts.h"
17*b077aed3SPierre Pronchery 
18*b077aed3SPierre Pronchery #define XTS_SET_KEY_FN(fn_set_enc_key, fn_set_dec_key,                         \
19*b077aed3SPierre Pronchery                        fn_block_enc, fn_block_dec,                             \
20*b077aed3SPierre Pronchery                        fn_stream_enc, fn_stream_dec) {                         \
21*b077aed3SPierre Pronchery     size_t bytes = keylen / 2;                                                 \
22*b077aed3SPierre Pronchery     size_t bits = bytes * 8;                                                   \
23*b077aed3SPierre Pronchery                                                                                \
24*b077aed3SPierre Pronchery     if (ctx->enc) {                                                            \
25*b077aed3SPierre Pronchery         fn_set_enc_key(key, bits, &xctx->ks1.ks);                              \
26*b077aed3SPierre Pronchery         xctx->xts.block1 = (block128_f)fn_block_enc;                           \
27*b077aed3SPierre Pronchery     } else {                                                                   \
28*b077aed3SPierre Pronchery         fn_set_dec_key(key, bits, &xctx->ks1.ks);                              \
29*b077aed3SPierre Pronchery         xctx->xts.block1 = (block128_f)fn_block_dec;                           \
30*b077aed3SPierre Pronchery     }                                                                          \
31*b077aed3SPierre Pronchery     fn_set_enc_key(key + bytes, bits, &xctx->ks2.ks);                          \
32*b077aed3SPierre Pronchery     xctx->xts.block2 = (block128_f)fn_block_enc;                               \
33*b077aed3SPierre Pronchery     xctx->xts.key1 = &xctx->ks1;                                               \
34*b077aed3SPierre Pronchery     xctx->xts.key2 = &xctx->ks2;                                               \
35*b077aed3SPierre Pronchery     xctx->stream = ctx->enc ? fn_stream_enc : fn_stream_dec;                   \
36*b077aed3SPierre Pronchery }
37*b077aed3SPierre Pronchery 
cipher_hw_aes_xts_generic_initkey(PROV_CIPHER_CTX * ctx,const unsigned char * key,size_t keylen)38*b077aed3SPierre Pronchery static int cipher_hw_aes_xts_generic_initkey(PROV_CIPHER_CTX *ctx,
39*b077aed3SPierre Pronchery                                              const unsigned char *key,
40*b077aed3SPierre Pronchery                                              size_t keylen)
41*b077aed3SPierre Pronchery {
42*b077aed3SPierre Pronchery     PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx;
43*b077aed3SPierre Pronchery     OSSL_xts_stream_fn stream_enc = NULL;
44*b077aed3SPierre Pronchery     OSSL_xts_stream_fn stream_dec = NULL;
45*b077aed3SPierre Pronchery 
46*b077aed3SPierre Pronchery #ifdef AES_XTS_ASM
47*b077aed3SPierre Pronchery     stream_enc = AES_xts_encrypt;
48*b077aed3SPierre Pronchery     stream_dec = AES_xts_decrypt;
49*b077aed3SPierre Pronchery #endif /* AES_XTS_ASM */
50*b077aed3SPierre Pronchery 
51*b077aed3SPierre Pronchery #ifdef HWAES_CAPABLE
52*b077aed3SPierre Pronchery     if (HWAES_CAPABLE) {
53*b077aed3SPierre Pronchery # ifdef HWAES_xts_encrypt
54*b077aed3SPierre Pronchery         stream_enc = HWAES_xts_encrypt;
55*b077aed3SPierre Pronchery # endif /* HWAES_xts_encrypt */
56*b077aed3SPierre Pronchery # ifdef HWAES_xts_decrypt
57*b077aed3SPierre Pronchery         stream_dec = HWAES_xts_decrypt;
58*b077aed3SPierre Pronchery # endif /* HWAES_xts_decrypt */
59*b077aed3SPierre Pronchery         XTS_SET_KEY_FN(HWAES_set_encrypt_key, HWAES_set_decrypt_key,
60*b077aed3SPierre Pronchery                        HWAES_encrypt, HWAES_decrypt,
61*b077aed3SPierre Pronchery                        stream_enc, stream_dec);
62*b077aed3SPierre Pronchery         return 1;
63*b077aed3SPierre Pronchery     } else
64*b077aed3SPierre Pronchery #endif /* HWAES_CAPABLE */
65*b077aed3SPierre Pronchery 
66*b077aed3SPierre Pronchery #ifdef BSAES_CAPABLE
67*b077aed3SPierre Pronchery     if (BSAES_CAPABLE) {
68*b077aed3SPierre Pronchery         stream_enc = ossl_bsaes_xts_encrypt;
69*b077aed3SPierre Pronchery         stream_dec = ossl_bsaes_xts_decrypt;
70*b077aed3SPierre Pronchery     } else
71*b077aed3SPierre Pronchery #endif /* BSAES_CAPABLE */
72*b077aed3SPierre Pronchery #ifdef VPAES_CAPABLE
73*b077aed3SPierre Pronchery     if (VPAES_CAPABLE) {
74*b077aed3SPierre Pronchery         XTS_SET_KEY_FN(vpaes_set_encrypt_key, vpaes_set_decrypt_key,
75*b077aed3SPierre Pronchery                        vpaes_encrypt, vpaes_decrypt, stream_enc, stream_dec);
76*b077aed3SPierre Pronchery         return 1;
77*b077aed3SPierre Pronchery     } else
78*b077aed3SPierre Pronchery #endif /* VPAES_CAPABLE */
79*b077aed3SPierre Pronchery     {
80*b077aed3SPierre Pronchery         (void)0;
81*b077aed3SPierre Pronchery     }
82*b077aed3SPierre Pronchery     {
83*b077aed3SPierre Pronchery         XTS_SET_KEY_FN(AES_set_encrypt_key, AES_set_decrypt_key,
84*b077aed3SPierre Pronchery                        AES_encrypt, AES_decrypt, stream_enc, stream_dec);
85*b077aed3SPierre Pronchery     }
86*b077aed3SPierre Pronchery     return 1;
87*b077aed3SPierre Pronchery }
88*b077aed3SPierre Pronchery 
cipher_hw_aes_xts_copyctx(PROV_CIPHER_CTX * dst,const PROV_CIPHER_CTX * src)89*b077aed3SPierre Pronchery static void cipher_hw_aes_xts_copyctx(PROV_CIPHER_CTX *dst,
90*b077aed3SPierre Pronchery                                       const PROV_CIPHER_CTX *src)
91*b077aed3SPierre Pronchery {
92*b077aed3SPierre Pronchery     PROV_AES_XTS_CTX *sctx = (PROV_AES_XTS_CTX *)src;
93*b077aed3SPierre Pronchery     PROV_AES_XTS_CTX *dctx = (PROV_AES_XTS_CTX *)dst;
94*b077aed3SPierre Pronchery 
95*b077aed3SPierre Pronchery     *dctx = *sctx;
96*b077aed3SPierre Pronchery     dctx->xts.key1 = &dctx->ks1.ks;
97*b077aed3SPierre Pronchery     dctx->xts.key2 = &dctx->ks2.ks;
98*b077aed3SPierre Pronchery }
99*b077aed3SPierre Pronchery 
100*b077aed3SPierre Pronchery #if defined(AESNI_CAPABLE)
101*b077aed3SPierre Pronchery 
cipher_hw_aesni_xts_initkey(PROV_CIPHER_CTX * ctx,const unsigned char * key,size_t keylen)102*b077aed3SPierre Pronchery static int cipher_hw_aesni_xts_initkey(PROV_CIPHER_CTX *ctx,
103*b077aed3SPierre Pronchery                                        const unsigned char *key, size_t keylen)
104*b077aed3SPierre Pronchery {
105*b077aed3SPierre Pronchery     PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx;
106*b077aed3SPierre Pronchery 
107*b077aed3SPierre Pronchery     XTS_SET_KEY_FN(aesni_set_encrypt_key, aesni_set_decrypt_key,
108*b077aed3SPierre Pronchery                    aesni_encrypt, aesni_decrypt,
109*b077aed3SPierre Pronchery                    aesni_xts_encrypt, aesni_xts_decrypt);
110*b077aed3SPierre Pronchery     return 1;
111*b077aed3SPierre Pronchery }
112*b077aed3SPierre Pronchery 
113*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_declare_xts()                                          \
114*b077aed3SPierre Pronchery static const PROV_CIPHER_HW aesni_xts = {                                      \
115*b077aed3SPierre Pronchery     cipher_hw_aesni_xts_initkey,                                               \
116*b077aed3SPierre Pronchery     NULL,                                                                      \
117*b077aed3SPierre Pronchery     cipher_hw_aes_xts_copyctx                                                  \
118*b077aed3SPierre Pronchery };
119*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_select_xts()                                           \
120*b077aed3SPierre Pronchery if (AESNI_CAPABLE)                                                             \
121*b077aed3SPierre Pronchery     return &aesni_xts;
122*b077aed3SPierre Pronchery 
123*b077aed3SPierre Pronchery # elif defined(SPARC_AES_CAPABLE)
124*b077aed3SPierre Pronchery 
cipher_hw_aes_xts_t4_initkey(PROV_CIPHER_CTX * ctx,const unsigned char * key,size_t keylen)125*b077aed3SPierre Pronchery static int cipher_hw_aes_xts_t4_initkey(PROV_CIPHER_CTX *ctx,
126*b077aed3SPierre Pronchery                                         const unsigned char *key, size_t keylen)
127*b077aed3SPierre Pronchery {
128*b077aed3SPierre Pronchery     PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx;
129*b077aed3SPierre Pronchery     OSSL_xts_stream_fn stream_enc = NULL;
130*b077aed3SPierre Pronchery     OSSL_xts_stream_fn stream_dec = NULL;
131*b077aed3SPierre Pronchery 
132*b077aed3SPierre Pronchery     /* Note: keylen is the size of 2 keys */
133*b077aed3SPierre Pronchery     switch (keylen) {
134*b077aed3SPierre Pronchery     case 32:
135*b077aed3SPierre Pronchery         stream_enc = aes128_t4_xts_encrypt;
136*b077aed3SPierre Pronchery         stream_dec = aes128_t4_xts_decrypt;
137*b077aed3SPierre Pronchery         break;
138*b077aed3SPierre Pronchery     case 64:
139*b077aed3SPierre Pronchery         stream_enc = aes256_t4_xts_encrypt;
140*b077aed3SPierre Pronchery         stream_dec = aes256_t4_xts_decrypt;
141*b077aed3SPierre Pronchery         break;
142*b077aed3SPierre Pronchery     default:
143*b077aed3SPierre Pronchery         return 0;
144*b077aed3SPierre Pronchery     }
145*b077aed3SPierre Pronchery 
146*b077aed3SPierre Pronchery     XTS_SET_KEY_FN(aes_t4_set_encrypt_key, aes_t4_set_decrypt_key,
147*b077aed3SPierre Pronchery                    aes_t4_encrypt, aes_t4_decrypt,
148*b077aed3SPierre Pronchery                    stream_enc, stream_dec);
149*b077aed3SPierre Pronchery     return 1;
150*b077aed3SPierre Pronchery }
151*b077aed3SPierre Pronchery 
152*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_declare_xts()                                          \
153*b077aed3SPierre Pronchery static const PROV_CIPHER_HW aes_xts_t4 = {                                     \
154*b077aed3SPierre Pronchery     cipher_hw_aes_xts_t4_initkey,                                              \
155*b077aed3SPierre Pronchery     NULL,                                                                      \
156*b077aed3SPierre Pronchery     cipher_hw_aes_xts_copyctx                                                  \
157*b077aed3SPierre Pronchery };
158*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_select_xts()                                           \
159*b077aed3SPierre Pronchery if (SPARC_AES_CAPABLE)                                                         \
160*b077aed3SPierre Pronchery     return &aes_xts_t4;
161*b077aed3SPierre Pronchery # else
162*b077aed3SPierre Pronchery /* The generic case */
163*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_declare_xts()
164*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_select_xts()
165*b077aed3SPierre Pronchery #endif
166*b077aed3SPierre Pronchery 
167*b077aed3SPierre Pronchery static const PROV_CIPHER_HW aes_generic_xts = {
168*b077aed3SPierre Pronchery     cipher_hw_aes_xts_generic_initkey,
169*b077aed3SPierre Pronchery     NULL,
170*b077aed3SPierre Pronchery     cipher_hw_aes_xts_copyctx
171*b077aed3SPierre Pronchery };
PROV_CIPHER_HW_declare_xts()172*b077aed3SPierre Pronchery PROV_CIPHER_HW_declare_xts()
173*b077aed3SPierre Pronchery const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts(size_t keybits)
174*b077aed3SPierre Pronchery {
175*b077aed3SPierre Pronchery     PROV_CIPHER_HW_select_xts()
176*b077aed3SPierre Pronchery     return &aes_generic_xts;
177*b077aed3SPierre Pronchery }
178