xref: /linux/crypto/Kconfig (revision e2ee95b8c69e542d6afef3f6f38ea598cc146ba7)
11da177e4SLinus Torvalds#
2685784aaSDan Williams# Generic algorithms support
3685784aaSDan Williams#
4685784aaSDan Williamsconfig XOR_BLOCKS
5685784aaSDan Williams	tristate
6685784aaSDan Williams
7685784aaSDan Williams#
89bc89cd8SDan Williams# async_tx api: hardware offloaded memory transfer/transform support
99bc89cd8SDan Williams#
109bc89cd8SDan Williamssource "crypto/async_tx/Kconfig"
119bc89cd8SDan Williams
129bc89cd8SDan Williams#
131da177e4SLinus Torvalds# Cryptographic API Configuration
141da177e4SLinus Torvalds#
152e290f43SJan Engelhardtmenuconfig CRYPTO
161da177e4SLinus Torvalds	bool "Cryptographic API"
171da177e4SLinus Torvalds	help
181da177e4SLinus Torvalds	  This option provides the core Cryptographic API.
191da177e4SLinus Torvalds
20cce9e06dSHerbert Xuif CRYPTO
21cce9e06dSHerbert Xu
22cce9e06dSHerbert Xuconfig CRYPTO_ALGAPI
23cce9e06dSHerbert Xu	tristate
24cce9e06dSHerbert Xu	help
25cce9e06dSHerbert Xu	  This option provides the API for cryptographic algorithms.
26cce9e06dSHerbert Xu
27b5b7f088SHerbert Xuconfig CRYPTO_ABLKCIPHER
28b5b7f088SHerbert Xu	tristate
29b5b7f088SHerbert Xu	select CRYPTO_BLKCIPHER
30b5b7f088SHerbert Xu
315cde0af2SHerbert Xuconfig CRYPTO_BLKCIPHER
325cde0af2SHerbert Xu	tristate
335cde0af2SHerbert Xu	select CRYPTO_ALGAPI
345cde0af2SHerbert Xu
35055bcee3SHerbert Xuconfig CRYPTO_HASH
36055bcee3SHerbert Xu	tristate
37055bcee3SHerbert Xu	select CRYPTO_ALGAPI
38055bcee3SHerbert Xu
392b8c19dbSHerbert Xuconfig CRYPTO_MANAGER
402b8c19dbSHerbert Xu	tristate "Cryptographic algorithm manager"
412b8c19dbSHerbert Xu	select CRYPTO_ALGAPI
422b8c19dbSHerbert Xu	help
432b8c19dbSHerbert Xu	  Create default cryptographic template instantiations such as
442b8c19dbSHerbert Xu	  cbc(aes).
452b8c19dbSHerbert Xu
461da177e4SLinus Torvaldsconfig CRYPTO_HMAC
478425165dSHerbert Xu	tristate "HMAC support"
480796ae06SHerbert Xu	select CRYPTO_HASH
4943518407SHerbert Xu	select CRYPTO_MANAGER
501da177e4SLinus Torvalds	help
511da177e4SLinus Torvalds	  HMAC: Keyed-Hashing for Message Authentication (RFC2104).
521da177e4SLinus Torvalds	  This is required for IPSec.
531da177e4SLinus Torvalds
54333b0d7eSKazunori MIYAZAWAconfig CRYPTO_XCBC
55333b0d7eSKazunori MIYAZAWA	tristate "XCBC support"
56333b0d7eSKazunori MIYAZAWA	depends on EXPERIMENTAL
57333b0d7eSKazunori MIYAZAWA	select CRYPTO_HASH
58333b0d7eSKazunori MIYAZAWA	select CRYPTO_MANAGER
59333b0d7eSKazunori MIYAZAWA	help
60333b0d7eSKazunori MIYAZAWA	  XCBC: Keyed-Hashing with encryption algorithm
61333b0d7eSKazunori MIYAZAWA		http://www.ietf.org/rfc/rfc3566.txt
62333b0d7eSKazunori MIYAZAWA		http://csrc.nist.gov/encryption/modes/proposedmodes/
63333b0d7eSKazunori MIYAZAWA		 xcbc-mac/xcbc-mac-spec.pdf
64333b0d7eSKazunori MIYAZAWA
651da177e4SLinus Torvaldsconfig CRYPTO_NULL
661da177e4SLinus Torvalds	tristate "Null algorithms"
67cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
681da177e4SLinus Torvalds	help
691da177e4SLinus Torvalds	  These are 'Null' algorithms, used by IPsec, which do nothing.
701da177e4SLinus Torvalds
711da177e4SLinus Torvaldsconfig CRYPTO_MD4
721da177e4SLinus Torvalds	tristate "MD4 digest algorithm"
73cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
741da177e4SLinus Torvalds	help
751da177e4SLinus Torvalds	  MD4 message digest algorithm (RFC1320).
761da177e4SLinus Torvalds
771da177e4SLinus Torvaldsconfig CRYPTO_MD5
781da177e4SLinus Torvalds	tristate "MD5 digest algorithm"
79cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
801da177e4SLinus Torvalds	help
811da177e4SLinus Torvalds	  MD5 message digest algorithm (RFC1321).
821da177e4SLinus Torvalds
831da177e4SLinus Torvaldsconfig CRYPTO_SHA1
841da177e4SLinus Torvalds	tristate "SHA1 digest algorithm"
85cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
861da177e4SLinus Torvalds	help
871da177e4SLinus Torvalds	  SHA-1 secure hash standard (FIPS 180-1/DFIPS 180-2).
881da177e4SLinus Torvalds
891da177e4SLinus Torvaldsconfig CRYPTO_SHA256
901da177e4SLinus Torvalds	tristate "SHA256 digest algorithm"
91cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
921da177e4SLinus Torvalds	help
931da177e4SLinus Torvalds	  SHA256 secure hash standard (DFIPS 180-2).
941da177e4SLinus Torvalds
951da177e4SLinus Torvalds	  This version of SHA implements a 256 bit hash with 128 bits of
961da177e4SLinus Torvalds	  security against collision attacks.
971da177e4SLinus Torvalds
981da177e4SLinus Torvaldsconfig CRYPTO_SHA512
991da177e4SLinus Torvalds	tristate "SHA384 and SHA512 digest algorithms"
100cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
1011da177e4SLinus Torvalds	help
1021da177e4SLinus Torvalds	  SHA512 secure hash standard (DFIPS 180-2).
1031da177e4SLinus Torvalds
1041da177e4SLinus Torvalds	  This version of SHA implements a 512 bit hash with 256 bits of
1051da177e4SLinus Torvalds	  security against collision attacks.
1061da177e4SLinus Torvalds
1071da177e4SLinus Torvalds	  This code also includes SHA-384, a 384 bit hash with 192 bits
1081da177e4SLinus Torvalds	  of security against collision attacks.
1091da177e4SLinus Torvalds
1101da177e4SLinus Torvaldsconfig CRYPTO_WP512
1111da177e4SLinus Torvalds	tristate "Whirlpool digest algorithms"
112cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
1131da177e4SLinus Torvalds	help
1141da177e4SLinus Torvalds	  Whirlpool hash algorithm 512, 384 and 256-bit hashes
1151da177e4SLinus Torvalds
1161da177e4SLinus Torvalds	  Whirlpool-512 is part of the NESSIE cryptographic primitives.
1171da177e4SLinus Torvalds	  Whirlpool will be part of the ISO/IEC 10118-3:2003(E) standard
1181da177e4SLinus Torvalds
1191da177e4SLinus Torvalds	  See also:
1201da177e4SLinus Torvalds	  <http://planeta.terra.com.br/informatica/paulobarreto/WhirlpoolPage.html>
1211da177e4SLinus Torvalds
1221da177e4SLinus Torvaldsconfig CRYPTO_TGR192
1231da177e4SLinus Torvalds	tristate "Tiger digest algorithms"
124cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
1251da177e4SLinus Torvalds	help
1261da177e4SLinus Torvalds	  Tiger hash algorithm 192, 160 and 128-bit hashes
1271da177e4SLinus Torvalds
1281da177e4SLinus Torvalds	  Tiger is a hash function optimized for 64-bit processors while
1291da177e4SLinus Torvalds	  still having decent performance on 32-bit processors.
1301da177e4SLinus Torvalds	  Tiger was developed by Ross Anderson and Eli Biham.
1311da177e4SLinus Torvalds
1321da177e4SLinus Torvalds	  See also:
1331da177e4SLinus Torvalds	  <http://www.cs.technion.ac.il/~biham/Reports/Tiger/>.
1341da177e4SLinus Torvalds
135c494e070SRik Snelconfig CRYPTO_GF128MUL
136c494e070SRik Snel	tristate "GF(2^128) multiplication functions (EXPERIMENTAL)"
137c494e070SRik Snel	depends on EXPERIMENTAL
138c494e070SRik Snel	help
139c494e070SRik Snel	  Efficient table driven implementation of multiplications in the
140c494e070SRik Snel	  field GF(2^128).  This is needed by some cypher modes. This
141c494e070SRik Snel	  option will be selected automatically if you select such a
142c494e070SRik Snel	  cipher mode.  Only select this option by hand if you expect to load
143c494e070SRik Snel	  an external module that requires these functions.
144c494e070SRik Snel
145db131ef9SHerbert Xuconfig CRYPTO_ECB
146db131ef9SHerbert Xu	tristate "ECB support"
147db131ef9SHerbert Xu	select CRYPTO_BLKCIPHER
14843518407SHerbert Xu	select CRYPTO_MANAGER
149db131ef9SHerbert Xu	help
150db131ef9SHerbert Xu	  ECB: Electronic CodeBook mode
151db131ef9SHerbert Xu	  This is the simplest block cipher algorithm.  It simply encrypts
152db131ef9SHerbert Xu	  the input block by block.
153db131ef9SHerbert Xu
154db131ef9SHerbert Xuconfig CRYPTO_CBC
155db131ef9SHerbert Xu	tristate "CBC support"
156db131ef9SHerbert Xu	select CRYPTO_BLKCIPHER
15743518407SHerbert Xu	select CRYPTO_MANAGER
158db131ef9SHerbert Xu	help
159db131ef9SHerbert Xu	  CBC: Cipher Block Chaining mode
160db131ef9SHerbert Xu	  This block cipher algorithm is required for IPSec.
161db131ef9SHerbert Xu
16291652be5SDavid Howellsconfig CRYPTO_PCBC
16391652be5SDavid Howells	tristate "PCBC support"
16491652be5SDavid Howells	select CRYPTO_BLKCIPHER
16591652be5SDavid Howells	select CRYPTO_MANAGER
16691652be5SDavid Howells	help
16791652be5SDavid Howells	  PCBC: Propagating Cipher Block Chaining mode
16891652be5SDavid Howells	  This block cipher algorithm is required for RxRPC.
16991652be5SDavid Howells
17064470f1bSRik Snelconfig CRYPTO_LRW
17164470f1bSRik Snel	tristate "LRW support (EXPERIMENTAL)"
17264470f1bSRik Snel	depends on EXPERIMENTAL
17364470f1bSRik Snel	select CRYPTO_BLKCIPHER
17464470f1bSRik Snel	select CRYPTO_MANAGER
17564470f1bSRik Snel	select CRYPTO_GF128MUL
17664470f1bSRik Snel	help
17764470f1bSRik Snel	  LRW: Liskov Rivest Wagner, a tweakable, non malleable, non movable
17864470f1bSRik Snel	  narrow block cipher mode for dm-crypt.  Use it with cipher
17964470f1bSRik Snel	  specification string aes-lrw-benbi, the key must be 256, 320 or 384.
18064470f1bSRik Snel	  The first 128, 192 or 256 bits in the key are used for AES and the
18164470f1bSRik Snel	  rest is used to tie each cipher block to its logical position.
18264470f1bSRik Snel
183124b53d0SHerbert Xuconfig CRYPTO_CRYPTD
184124b53d0SHerbert Xu	tristate "Software async crypto daemon"
185124b53d0SHerbert Xu	select CRYPTO_ABLKCIPHER
186124b53d0SHerbert Xu	select CRYPTO_MANAGER
187124b53d0SHerbert Xu	help
188124b53d0SHerbert Xu	  This is a generic software asynchronous crypto daemon that
189124b53d0SHerbert Xu	  converts an arbitrary synchronous software crypto algorithm
190124b53d0SHerbert Xu	  into an asynchronous algorithm that executes in a kernel thread.
191124b53d0SHerbert Xu
1921da177e4SLinus Torvaldsconfig CRYPTO_DES
1931da177e4SLinus Torvalds	tristate "DES and Triple DES EDE cipher algorithms"
194cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
1951da177e4SLinus Torvalds	help
1961da177e4SLinus Torvalds	  DES cipher algorithm (FIPS 46-2), and Triple DES EDE (FIPS 46-3).
1971da177e4SLinus Torvalds
19890831639SDavid Howellsconfig CRYPTO_FCRYPT
19990831639SDavid Howells	tristate "FCrypt cipher algorithm"
20090831639SDavid Howells	select CRYPTO_ALGAPI
20190831639SDavid Howells	select CRYPTO_BLKCIPHER
20290831639SDavid Howells	help
20390831639SDavid Howells	  FCrypt algorithm used by RxRPC.
20490831639SDavid Howells
2051da177e4SLinus Torvaldsconfig CRYPTO_BLOWFISH
2061da177e4SLinus Torvalds	tristate "Blowfish cipher algorithm"
207cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
2081da177e4SLinus Torvalds	help
2091da177e4SLinus Torvalds	  Blowfish cipher algorithm, by Bruce Schneier.
2101da177e4SLinus Torvalds
2111da177e4SLinus Torvalds	  This is a variable key length cipher which can use keys from 32
2121da177e4SLinus Torvalds	  bits to 448 bits in length.  It's fast, simple and specifically
2131da177e4SLinus Torvalds	  designed for use on "large microprocessors".
2141da177e4SLinus Torvalds
2151da177e4SLinus Torvalds	  See also:
2161da177e4SLinus Torvalds	  <http://www.schneier.com/blowfish.html>
2171da177e4SLinus Torvalds
2181da177e4SLinus Torvaldsconfig CRYPTO_TWOFISH
2191da177e4SLinus Torvalds	tristate "Twofish cipher algorithm"
220cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
2212729bb42SJoachim Fritschi	select CRYPTO_TWOFISH_COMMON
2221da177e4SLinus Torvalds	help
2231da177e4SLinus Torvalds	  Twofish cipher algorithm.
2241da177e4SLinus Torvalds
2251da177e4SLinus Torvalds	  Twofish was submitted as an AES (Advanced Encryption Standard)
2261da177e4SLinus Torvalds	  candidate cipher by researchers at CounterPane Systems.  It is a
2271da177e4SLinus Torvalds	  16 round block cipher supporting key sizes of 128, 192, and 256
2281da177e4SLinus Torvalds	  bits.
2291da177e4SLinus Torvalds
2301da177e4SLinus Torvalds	  See also:
2311da177e4SLinus Torvalds	  <http://www.schneier.com/twofish.html>
2321da177e4SLinus Torvalds
2332729bb42SJoachim Fritschiconfig CRYPTO_TWOFISH_COMMON
2342729bb42SJoachim Fritschi	tristate
2352729bb42SJoachim Fritschi	help
2362729bb42SJoachim Fritschi	  Common parts of the Twofish cipher algorithm shared by the
2372729bb42SJoachim Fritschi	  generic c and the assembler implementations.
2382729bb42SJoachim Fritschi
239b9f535ffSJoachim Fritschiconfig CRYPTO_TWOFISH_586
240b9f535ffSJoachim Fritschi	tristate "Twofish cipher algorithms (i586)"
241cce9e06dSHerbert Xu	depends on (X86 || UML_X86) && !64BIT
242cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
243b9f535ffSJoachim Fritschi	select CRYPTO_TWOFISH_COMMON
244b9f535ffSJoachim Fritschi	help
245b9f535ffSJoachim Fritschi	  Twofish cipher algorithm.
246b9f535ffSJoachim Fritschi
247b9f535ffSJoachim Fritschi	  Twofish was submitted as an AES (Advanced Encryption Standard)
248b9f535ffSJoachim Fritschi	  candidate cipher by researchers at CounterPane Systems.  It is a
249b9f535ffSJoachim Fritschi	  16 round block cipher supporting key sizes of 128, 192, and 256
250b9f535ffSJoachim Fritschi	  bits.
251b9f535ffSJoachim Fritschi
252b9f535ffSJoachim Fritschi	  See also:
253b9f535ffSJoachim Fritschi	  <http://www.schneier.com/twofish.html>
254b9f535ffSJoachim Fritschi
255eaf44088SJoachim Fritschiconfig CRYPTO_TWOFISH_X86_64
256eaf44088SJoachim Fritschi	tristate "Twofish cipher algorithm (x86_64)"
257cce9e06dSHerbert Xu	depends on (X86 || UML_X86) && 64BIT
258cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
259eaf44088SJoachim Fritschi	select CRYPTO_TWOFISH_COMMON
260eaf44088SJoachim Fritschi	help
261eaf44088SJoachim Fritschi	  Twofish cipher algorithm (x86_64).
262eaf44088SJoachim Fritschi
263eaf44088SJoachim Fritschi	  Twofish was submitted as an AES (Advanced Encryption Standard)
264eaf44088SJoachim Fritschi	  candidate cipher by researchers at CounterPane Systems.  It is a
265eaf44088SJoachim Fritschi	  16 round block cipher supporting key sizes of 128, 192, and 256
266eaf44088SJoachim Fritschi	  bits.
267eaf44088SJoachim Fritschi
268eaf44088SJoachim Fritschi	  See also:
269eaf44088SJoachim Fritschi	  <http://www.schneier.com/twofish.html>
270eaf44088SJoachim Fritschi
2711da177e4SLinus Torvaldsconfig CRYPTO_SERPENT
2721da177e4SLinus Torvalds	tristate "Serpent cipher algorithm"
273cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
2741da177e4SLinus Torvalds	help
2751da177e4SLinus Torvalds	  Serpent cipher algorithm, by Anderson, Biham & Knudsen.
2761da177e4SLinus Torvalds
2771da177e4SLinus Torvalds	  Keys are allowed to be from 0 to 256 bits in length, in steps
2781da177e4SLinus Torvalds	  of 8 bits.  Also includes the 'Tnepres' algorithm, a reversed
2793dde6ad8SDavid Sterba	  variant of Serpent for compatibility with old kerneli.org code.
2801da177e4SLinus Torvalds
2811da177e4SLinus Torvalds	  See also:
2821da177e4SLinus Torvalds	  <http://www.cl.cam.ac.uk/~rja14/serpent.html>
2831da177e4SLinus Torvalds
2841da177e4SLinus Torvaldsconfig CRYPTO_AES
2851da177e4SLinus Torvalds	tristate "AES cipher algorithms"
286cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
2871da177e4SLinus Torvalds	help
2881da177e4SLinus Torvalds	  AES cipher algorithms (FIPS-197). AES uses the Rijndael
2891da177e4SLinus Torvalds	  algorithm.
2901da177e4SLinus Torvalds
2911da177e4SLinus Torvalds	  Rijndael appears to be consistently a very good performer in
2921da177e4SLinus Torvalds	  both hardware and software across a wide range of computing
2931da177e4SLinus Torvalds	  environments regardless of its use in feedback or non-feedback
2941da177e4SLinus Torvalds	  modes. Its key setup time is excellent, and its key agility is
2951da177e4SLinus Torvalds	  good. Rijndael's very low memory requirements make it very well
2961da177e4SLinus Torvalds	  suited for restricted-space environments, in which it also
2971da177e4SLinus Torvalds	  demonstrates excellent performance. Rijndael's operations are
2981da177e4SLinus Torvalds	  among the easiest to defend against power and timing attacks.
2991da177e4SLinus Torvalds
3001da177e4SLinus Torvalds	  The AES specifies three key sizes: 128, 192 and 256 bits
3011da177e4SLinus Torvalds
3021da177e4SLinus Torvalds	  See <http://csrc.nist.gov/CryptoToolkit/aes/> for more information.
3031da177e4SLinus Torvalds
3041da177e4SLinus Torvaldsconfig CRYPTO_AES_586
3051da177e4SLinus Torvalds	tristate "AES cipher algorithms (i586)"
306cce9e06dSHerbert Xu	depends on (X86 || UML_X86) && !64BIT
307cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
3081da177e4SLinus Torvalds	help
3091da177e4SLinus Torvalds	  AES cipher algorithms (FIPS-197). AES uses the Rijndael
3101da177e4SLinus Torvalds	  algorithm.
3111da177e4SLinus Torvalds
3121da177e4SLinus Torvalds	  Rijndael appears to be consistently a very good performer in
3131da177e4SLinus Torvalds	  both hardware and software across a wide range of computing
3141da177e4SLinus Torvalds	  environments regardless of its use in feedback or non-feedback
3151da177e4SLinus Torvalds	  modes. Its key setup time is excellent, and its key agility is
3161da177e4SLinus Torvalds	  good. Rijndael's very low memory requirements make it very well
3171da177e4SLinus Torvalds	  suited for restricted-space environments, in which it also
3181da177e4SLinus Torvalds	  demonstrates excellent performance. Rijndael's operations are
3191da177e4SLinus Torvalds	  among the easiest to defend against power and timing attacks.
3201da177e4SLinus Torvalds
3211da177e4SLinus Torvalds	  The AES specifies three key sizes: 128, 192 and 256 bits
3221da177e4SLinus Torvalds
3231da177e4SLinus Torvalds	  See <http://csrc.nist.gov/encryption/aes/> for more information.
3241da177e4SLinus Torvalds
325a2a892a2SAndreas Steinmetzconfig CRYPTO_AES_X86_64
326a2a892a2SAndreas Steinmetz	tristate "AES cipher algorithms (x86_64)"
327cce9e06dSHerbert Xu	depends on (X86 || UML_X86) && 64BIT
328cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
329a2a892a2SAndreas Steinmetz	help
330a2a892a2SAndreas Steinmetz	  AES cipher algorithms (FIPS-197). AES uses the Rijndael
331a2a892a2SAndreas Steinmetz	  algorithm.
332a2a892a2SAndreas Steinmetz
333a2a892a2SAndreas Steinmetz	  Rijndael appears to be consistently a very good performer in
334a2a892a2SAndreas Steinmetz	  both hardware and software across a wide range of computing
335a2a892a2SAndreas Steinmetz	  environments regardless of its use in feedback or non-feedback
336a2a892a2SAndreas Steinmetz	  modes. Its key setup time is excellent, and its key agility is
337a2a892a2SAndreas Steinmetz	  good. Rijndael's very low memory requirements make it very well
338a2a892a2SAndreas Steinmetz	  suited for restricted-space environments, in which it also
339a2a892a2SAndreas Steinmetz	  demonstrates excellent performance. Rijndael's operations are
340a2a892a2SAndreas Steinmetz	  among the easiest to defend against power and timing attacks.
341a2a892a2SAndreas Steinmetz
342a2a892a2SAndreas Steinmetz	  The AES specifies three key sizes: 128, 192 and 256 bits
343a2a892a2SAndreas Steinmetz
344a2a892a2SAndreas Steinmetz	  See <http://csrc.nist.gov/encryption/aes/> for more information.
345a2a892a2SAndreas Steinmetz
3461da177e4SLinus Torvaldsconfig CRYPTO_CAST5
3471da177e4SLinus Torvalds	tristate "CAST5 (CAST-128) cipher algorithm"
348cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
3491da177e4SLinus Torvalds	help
3501da177e4SLinus Torvalds	  The CAST5 encryption algorithm (synonymous with CAST-128) is
3511da177e4SLinus Torvalds	  described in RFC2144.
3521da177e4SLinus Torvalds
3531da177e4SLinus Torvaldsconfig CRYPTO_CAST6
3541da177e4SLinus Torvalds	tristate "CAST6 (CAST-256) cipher algorithm"
355cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
3561da177e4SLinus Torvalds	help
3571da177e4SLinus Torvalds	  The CAST6 encryption algorithm (synonymous with CAST-256) is
3581da177e4SLinus Torvalds	  described in RFC2612.
3591da177e4SLinus Torvalds
3601da177e4SLinus Torvaldsconfig CRYPTO_TEA
361fb4f10edSAaron Grothe	tristate "TEA, XTEA and XETA cipher algorithms"
362cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
3631da177e4SLinus Torvalds	help
3641da177e4SLinus Torvalds	  TEA cipher algorithm.
3651da177e4SLinus Torvalds
3661da177e4SLinus Torvalds	  Tiny Encryption Algorithm is a simple cipher that uses
3671da177e4SLinus Torvalds	  many rounds for security.  It is very fast and uses
3681da177e4SLinus Torvalds	  little memory.
3691da177e4SLinus Torvalds
3701da177e4SLinus Torvalds	  Xtendend Tiny Encryption Algorithm is a modification to
3711da177e4SLinus Torvalds	  the TEA algorithm to address a potential key weakness
3721da177e4SLinus Torvalds	  in the TEA algorithm.
3731da177e4SLinus Torvalds
374fb4f10edSAaron Grothe	  Xtendend Encryption Tiny Algorithm is a mis-implementation
375fb4f10edSAaron Grothe	  of the XTEA algorithm for compatibility purposes.
376fb4f10edSAaron Grothe
3771da177e4SLinus Torvaldsconfig CRYPTO_ARC4
3781da177e4SLinus Torvalds	tristate "ARC4 cipher algorithm"
379cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
3801da177e4SLinus Torvalds	help
3811da177e4SLinus Torvalds	  ARC4 cipher algorithm.
3821da177e4SLinus Torvalds
3831da177e4SLinus Torvalds	  ARC4 is a stream cipher using keys ranging from 8 bits to 2048
3841da177e4SLinus Torvalds	  bits in length.  This algorithm is required for driver-based
3851da177e4SLinus Torvalds	  WEP, but it should not be for other purposes because of the
3861da177e4SLinus Torvalds	  weakness of the algorithm.
3871da177e4SLinus Torvalds
3881da177e4SLinus Torvaldsconfig CRYPTO_KHAZAD
3891da177e4SLinus Torvalds	tristate "Khazad cipher algorithm"
390cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
3911da177e4SLinus Torvalds	help
3921da177e4SLinus Torvalds	  Khazad cipher algorithm.
3931da177e4SLinus Torvalds
3941da177e4SLinus Torvalds	  Khazad was a finalist in the initial NESSIE competition.  It is
3951da177e4SLinus Torvalds	  an algorithm optimized for 64-bit processors with good performance
3961da177e4SLinus Torvalds	  on 32-bit processors.  Khazad uses an 128 bit key size.
3971da177e4SLinus Torvalds
3981da177e4SLinus Torvalds	  See also:
3991da177e4SLinus Torvalds	  <http://planeta.terra.com.br/informatica/paulobarreto/KhazadPage.html>
4001da177e4SLinus Torvalds
4011da177e4SLinus Torvaldsconfig CRYPTO_ANUBIS
4021da177e4SLinus Torvalds	tristate "Anubis cipher algorithm"
403cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
4041da177e4SLinus Torvalds	help
4051da177e4SLinus Torvalds	  Anubis cipher algorithm.
4061da177e4SLinus Torvalds
4071da177e4SLinus Torvalds	  Anubis is a variable key length cipher which can use keys from
4081da177e4SLinus Torvalds	  128 bits to 320 bits in length.  It was evaluated as a entrant
4091da177e4SLinus Torvalds	  in the NESSIE competition.
4101da177e4SLinus Torvalds
4111da177e4SLinus Torvalds	  See also:
4121da177e4SLinus Torvalds	  <https://www.cosic.esat.kuleuven.ac.be/nessie/reports/>
4131da177e4SLinus Torvalds	  <http://planeta.terra.com.br/informatica/paulobarreto/AnubisPage.html>
4141da177e4SLinus Torvalds
415*e2ee95b8SHye-Shik Changconfig CRYPTO_SEED
416*e2ee95b8SHye-Shik Chang	tristate "SEED cipher algorithm"
417*e2ee95b8SHye-Shik Chang	select CRYPTO_ALGAPI
418*e2ee95b8SHye-Shik Chang	help
419*e2ee95b8SHye-Shik Chang	  SEED cipher algorithm (RFC4269).
420*e2ee95b8SHye-Shik Chang
421*e2ee95b8SHye-Shik Chang	  SEED is a 128-bit symmetric key block cipher that has been
422*e2ee95b8SHye-Shik Chang	  developed by KISA (Korea Information Security Agency) as a
423*e2ee95b8SHye-Shik Chang	  national standard encryption algorithm of the Republic of Korea.
424*e2ee95b8SHye-Shik Chang	  It is a 16 round block cipher with the key size of 128 bit.
425*e2ee95b8SHye-Shik Chang
426*e2ee95b8SHye-Shik Chang	  See also:
427*e2ee95b8SHye-Shik Chang	  <http://www.kisa.or.kr/kisa/seed/jsp/seed_eng.jsp>
428*e2ee95b8SHye-Shik Chang
4291da177e4SLinus Torvalds
4301da177e4SLinus Torvaldsconfig CRYPTO_DEFLATE
4311da177e4SLinus Torvalds	tristate "Deflate compression algorithm"
432cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
4331da177e4SLinus Torvalds	select ZLIB_INFLATE
4341da177e4SLinus Torvalds	select ZLIB_DEFLATE
4351da177e4SLinus Torvalds	help
4361da177e4SLinus Torvalds	  This is the Deflate algorithm (RFC1951), specified for use in
4371da177e4SLinus Torvalds	  IPSec with the IPCOMP protocol (RFC3173, RFC2394).
4381da177e4SLinus Torvalds
4391da177e4SLinus Torvalds	  You will most probably want this if using IPSec.
4401da177e4SLinus Torvalds
4411da177e4SLinus Torvaldsconfig CRYPTO_MICHAEL_MIC
4421da177e4SLinus Torvalds	tristate "Michael MIC keyed digest algorithm"
443cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
4441da177e4SLinus Torvalds	help
4451da177e4SLinus Torvalds	  Michael MIC is used for message integrity protection in TKIP
4461da177e4SLinus Torvalds	  (IEEE 802.11i). This algorithm is required for TKIP, but it
4471da177e4SLinus Torvalds	  should not be used for other purposes because of the weakness
4481da177e4SLinus Torvalds	  of the algorithm.
4491da177e4SLinus Torvalds
4501da177e4SLinus Torvaldsconfig CRYPTO_CRC32C
4511da177e4SLinus Torvalds	tristate "CRC32c CRC algorithm"
452cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
4531da177e4SLinus Torvalds	select LIBCRC32C
4541da177e4SLinus Torvalds	help
4551da177e4SLinus Torvalds	  Castagnoli, et al Cyclic Redundancy-Check Algorithm.  Used
4561da177e4SLinus Torvalds	  by iSCSI for header and data digests and by others.
4571da177e4SLinus Torvalds	  See Castagnoli93.  This implementation uses lib/libcrc32c.
4581da177e4SLinus Torvalds          Module will be crc32c.
4591da177e4SLinus Torvalds
46004ac7db3SNoriaki TAKAMIYAconfig CRYPTO_CAMELLIA
46104ac7db3SNoriaki TAKAMIYA	tristate "Camellia cipher algorithms"
46204ac7db3SNoriaki TAKAMIYA	depends on CRYPTO
46304ac7db3SNoriaki TAKAMIYA	select CRYPTO_ALGAPI
46404ac7db3SNoriaki TAKAMIYA	help
46504ac7db3SNoriaki TAKAMIYA	  Camellia cipher algorithms module.
46604ac7db3SNoriaki TAKAMIYA
46704ac7db3SNoriaki TAKAMIYA	  Camellia is a symmetric key block cipher developed jointly
46804ac7db3SNoriaki TAKAMIYA	  at NTT and Mitsubishi Electric Corporation.
46904ac7db3SNoriaki TAKAMIYA
47004ac7db3SNoriaki TAKAMIYA	  The Camellia specifies three key sizes: 128, 192 and 256 bits.
47104ac7db3SNoriaki TAKAMIYA
47204ac7db3SNoriaki TAKAMIYA	  See also:
47304ac7db3SNoriaki TAKAMIYA	  <https://info.isl.ntt.co.jp/crypt/eng/camellia/index_s.html>
47404ac7db3SNoriaki TAKAMIYA
4751da177e4SLinus Torvaldsconfig CRYPTO_TEST
4761da177e4SLinus Torvalds	tristate "Testing module"
477cce9e06dSHerbert Xu	depends on m
478cce9e06dSHerbert Xu	select CRYPTO_ALGAPI
4791da177e4SLinus Torvalds	help
4801da177e4SLinus Torvalds	  Quick & dirty crypto test module.
4811da177e4SLinus Torvalds
4821da177e4SLinus Torvaldssource "drivers/crypto/Kconfig"
4831da177e4SLinus Torvalds
484cce9e06dSHerbert Xuendif	# if CRYPTO
485