xref: /freebsd-src/crypto/openssl/providers/implementations/ciphers/cipher_aes_hw.c (revision b077aed33b7b6aefca7b17ddb250cf521f938613)
1*b077aed3SPierre Pronchery /*
2*b077aed3SPierre Pronchery  * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved.
3*b077aed3SPierre Pronchery  *
4*b077aed3SPierre Pronchery  * Licensed under the Apache License 2.0 (the "License").  You may not use
5*b077aed3SPierre Pronchery  * this file except in compliance with the License.  You can obtain a copy
6*b077aed3SPierre Pronchery  * in the file LICENSE in the source distribution or at
7*b077aed3SPierre Pronchery  * https://www.openssl.org/source/license.html
8*b077aed3SPierre Pronchery  */
9*b077aed3SPierre Pronchery 
10*b077aed3SPierre Pronchery /*
11*b077aed3SPierre Pronchery  * This file uses the low level AES functions (which are deprecated for
12*b077aed3SPierre Pronchery  * non-internal use) in order to implement provider AES ciphers.
13*b077aed3SPierre Pronchery  */
14*b077aed3SPierre Pronchery #include "internal/deprecated.h"
15*b077aed3SPierre Pronchery 
16*b077aed3SPierre Pronchery #include <openssl/proverr.h>
17*b077aed3SPierre Pronchery #include "cipher_aes.h"
18*b077aed3SPierre Pronchery 
cipher_hw_aes_initkey(PROV_CIPHER_CTX * dat,const unsigned char * key,size_t keylen)19*b077aed3SPierre Pronchery static int cipher_hw_aes_initkey(PROV_CIPHER_CTX *dat,
20*b077aed3SPierre Pronchery                                  const unsigned char *key, size_t keylen)
21*b077aed3SPierre Pronchery {
22*b077aed3SPierre Pronchery     int ret;
23*b077aed3SPierre Pronchery     PROV_AES_CTX *adat = (PROV_AES_CTX *)dat;
24*b077aed3SPierre Pronchery     AES_KEY *ks = &adat->ks.ks;
25*b077aed3SPierre Pronchery 
26*b077aed3SPierre Pronchery     dat->ks = ks;
27*b077aed3SPierre Pronchery 
28*b077aed3SPierre Pronchery     if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE)
29*b077aed3SPierre Pronchery         && !dat->enc) {
30*b077aed3SPierre Pronchery #ifdef HWAES_CAPABLE
31*b077aed3SPierre Pronchery         if (HWAES_CAPABLE) {
32*b077aed3SPierre Pronchery             ret = HWAES_set_decrypt_key(key, keylen * 8, ks);
33*b077aed3SPierre Pronchery             dat->block = (block128_f)HWAES_decrypt;
34*b077aed3SPierre Pronchery             dat->stream.cbc = NULL;
35*b077aed3SPierre Pronchery # ifdef HWAES_cbc_encrypt
36*b077aed3SPierre Pronchery             if (dat->mode == EVP_CIPH_CBC_MODE)
37*b077aed3SPierre Pronchery                 dat->stream.cbc = (cbc128_f)HWAES_cbc_encrypt;
38*b077aed3SPierre Pronchery # endif
39*b077aed3SPierre Pronchery # ifdef HWAES_ecb_encrypt
40*b077aed3SPierre Pronchery             if (dat->mode == EVP_CIPH_ECB_MODE)
41*b077aed3SPierre Pronchery                 dat->stream.ecb = (ecb128_f)HWAES_ecb_encrypt;
42*b077aed3SPierre Pronchery # endif
43*b077aed3SPierre Pronchery         } else
44*b077aed3SPierre Pronchery #endif
45*b077aed3SPierre Pronchery #ifdef BSAES_CAPABLE
46*b077aed3SPierre Pronchery         if (BSAES_CAPABLE && dat->mode == EVP_CIPH_CBC_MODE) {
47*b077aed3SPierre Pronchery             ret = AES_set_decrypt_key(key, keylen * 8, ks);
48*b077aed3SPierre Pronchery             dat->block = (block128_f)AES_decrypt;
49*b077aed3SPierre Pronchery             dat->stream.cbc = (cbc128_f)ossl_bsaes_cbc_encrypt;
50*b077aed3SPierre Pronchery         } else
51*b077aed3SPierre Pronchery #endif
52*b077aed3SPierre Pronchery #ifdef VPAES_CAPABLE
53*b077aed3SPierre Pronchery         if (VPAES_CAPABLE) {
54*b077aed3SPierre Pronchery             ret = vpaes_set_decrypt_key(key, keylen * 8, ks);
55*b077aed3SPierre Pronchery             dat->block = (block128_f)vpaes_decrypt;
56*b077aed3SPierre Pronchery             dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE)
57*b077aed3SPierre Pronchery                               ?(cbc128_f)vpaes_cbc_encrypt : NULL;
58*b077aed3SPierre Pronchery         } else
59*b077aed3SPierre Pronchery #endif
60*b077aed3SPierre Pronchery         {
61*b077aed3SPierre Pronchery             ret = AES_set_decrypt_key(key, keylen * 8, ks);
62*b077aed3SPierre Pronchery             dat->block = (block128_f)AES_decrypt;
63*b077aed3SPierre Pronchery             dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE)
64*b077aed3SPierre Pronchery                               ? (cbc128_f)AES_cbc_encrypt : NULL;
65*b077aed3SPierre Pronchery         }
66*b077aed3SPierre Pronchery     } else
67*b077aed3SPierre Pronchery #ifdef HWAES_CAPABLE
68*b077aed3SPierre Pronchery     if (HWAES_CAPABLE) {
69*b077aed3SPierre Pronchery         ret = HWAES_set_encrypt_key(key, keylen * 8, ks);
70*b077aed3SPierre Pronchery         dat->block = (block128_f)HWAES_encrypt;
71*b077aed3SPierre Pronchery         dat->stream.cbc = NULL;
72*b077aed3SPierre Pronchery # ifdef HWAES_cbc_encrypt
73*b077aed3SPierre Pronchery         if (dat->mode == EVP_CIPH_CBC_MODE)
74*b077aed3SPierre Pronchery             dat->stream.cbc = (cbc128_f)HWAES_cbc_encrypt;
75*b077aed3SPierre Pronchery         else
76*b077aed3SPierre Pronchery # endif
77*b077aed3SPierre Pronchery # ifdef HWAES_ecb_encrypt
78*b077aed3SPierre Pronchery         if (dat->mode == EVP_CIPH_ECB_MODE)
79*b077aed3SPierre Pronchery             dat->stream.ecb = (ecb128_f)HWAES_ecb_encrypt;
80*b077aed3SPierre Pronchery         else
81*b077aed3SPierre Pronchery # endif
82*b077aed3SPierre Pronchery # ifdef HWAES_ctr32_encrypt_blocks
83*b077aed3SPierre Pronchery         if (dat->mode == EVP_CIPH_CTR_MODE)
84*b077aed3SPierre Pronchery             dat->stream.ctr = (ctr128_f)HWAES_ctr32_encrypt_blocks;
85*b077aed3SPierre Pronchery         else
86*b077aed3SPierre Pronchery # endif
87*b077aed3SPierre Pronchery             (void)0;            /* terminate potentially open 'else' */
88*b077aed3SPierre Pronchery     } else
89*b077aed3SPierre Pronchery #endif
90*b077aed3SPierre Pronchery #ifdef BSAES_CAPABLE
91*b077aed3SPierre Pronchery     if (BSAES_CAPABLE && dat->mode == EVP_CIPH_CTR_MODE) {
92*b077aed3SPierre Pronchery         ret = AES_set_encrypt_key(key, keylen * 8, ks);
93*b077aed3SPierre Pronchery         dat->block = (block128_f)AES_encrypt;
94*b077aed3SPierre Pronchery         dat->stream.ctr = (ctr128_f)ossl_bsaes_ctr32_encrypt_blocks;
95*b077aed3SPierre Pronchery     } else
96*b077aed3SPierre Pronchery #endif
97*b077aed3SPierre Pronchery #ifdef VPAES_CAPABLE
98*b077aed3SPierre Pronchery     if (VPAES_CAPABLE) {
99*b077aed3SPierre Pronchery         ret = vpaes_set_encrypt_key(key, keylen * 8, ks);
100*b077aed3SPierre Pronchery         dat->block = (block128_f)vpaes_encrypt;
101*b077aed3SPierre Pronchery         dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE)
102*b077aed3SPierre Pronchery                           ? (cbc128_f)vpaes_cbc_encrypt : NULL;
103*b077aed3SPierre Pronchery     } else
104*b077aed3SPierre Pronchery #endif
105*b077aed3SPierre Pronchery     {
106*b077aed3SPierre Pronchery         ret = AES_set_encrypt_key(key, keylen * 8, ks);
107*b077aed3SPierre Pronchery         dat->block = (block128_f)AES_encrypt;
108*b077aed3SPierre Pronchery         dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE)
109*b077aed3SPierre Pronchery                           ? (cbc128_f)AES_cbc_encrypt : NULL;
110*b077aed3SPierre Pronchery #ifdef AES_CTR_ASM
111*b077aed3SPierre Pronchery         if (dat->mode == EVP_CIPH_CTR_MODE)
112*b077aed3SPierre Pronchery             dat->stream.ctr = (ctr128_f)AES_ctr32_encrypt;
113*b077aed3SPierre Pronchery #endif
114*b077aed3SPierre Pronchery     }
115*b077aed3SPierre Pronchery 
116*b077aed3SPierre Pronchery     if (ret < 0) {
117*b077aed3SPierre Pronchery         ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED);
118*b077aed3SPierre Pronchery         return 0;
119*b077aed3SPierre Pronchery     }
120*b077aed3SPierre Pronchery 
121*b077aed3SPierre Pronchery     return 1;
122*b077aed3SPierre Pronchery }
123*b077aed3SPierre Pronchery 
124*b077aed3SPierre Pronchery IMPLEMENT_CIPHER_HW_COPYCTX(cipher_hw_aes_copyctx, PROV_AES_CTX)
125*b077aed3SPierre Pronchery 
126*b077aed3SPierre Pronchery #define PROV_CIPHER_HW_aes_mode(mode)                                          \
127*b077aed3SPierre Pronchery static const PROV_CIPHER_HW aes_##mode = {                                     \
128*b077aed3SPierre Pronchery     cipher_hw_aes_initkey,                                                     \
129*b077aed3SPierre Pronchery     ossl_cipher_hw_generic_##mode,                                             \
130*b077aed3SPierre Pronchery     cipher_hw_aes_copyctx                                                      \
131*b077aed3SPierre Pronchery };                                                                             \
132*b077aed3SPierre Pronchery PROV_CIPHER_HW_declare(mode)                                                   \
133*b077aed3SPierre Pronchery const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_##mode(size_t keybits)           \
134*b077aed3SPierre Pronchery {                                                                              \
135*b077aed3SPierre Pronchery     PROV_CIPHER_HW_select(mode)                                                \
136*b077aed3SPierre Pronchery     return &aes_##mode;                                                        \
137*b077aed3SPierre Pronchery }
138*b077aed3SPierre Pronchery 
139*b077aed3SPierre Pronchery #if defined(AESNI_CAPABLE)
140*b077aed3SPierre Pronchery # include "cipher_aes_hw_aesni.inc"
141*b077aed3SPierre Pronchery #elif defined(SPARC_AES_CAPABLE)
142*b077aed3SPierre Pronchery # include "cipher_aes_hw_t4.inc"
143*b077aed3SPierre Pronchery #elif defined(S390X_aes_128_CAPABLE)
144*b077aed3SPierre Pronchery # include "cipher_aes_hw_s390x.inc"
145*b077aed3SPierre Pronchery #else
146*b077aed3SPierre Pronchery /* The generic case */
147*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_declare(mode)
148*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_select(mode)
149*b077aed3SPierre Pronchery #endif
150*b077aed3SPierre Pronchery 
151*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(cbc)
152*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(ecb)
153*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(ofb128)
154*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(cfb128)
155*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(cfb1)
156*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(cfb8)
157*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(ctr)
158