1*b077aed3SPierre Pronchery /*
2*b077aed3SPierre Pronchery * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved.
3*b077aed3SPierre Pronchery *
4*b077aed3SPierre Pronchery * Licensed under the Apache License 2.0 (the "License"). You may not use
5*b077aed3SPierre Pronchery * this file except in compliance with the License. You can obtain a copy
6*b077aed3SPierre Pronchery * in the file LICENSE in the source distribution or at
7*b077aed3SPierre Pronchery * https://www.openssl.org/source/license.html
8*b077aed3SPierre Pronchery */
9*b077aed3SPierre Pronchery
10*b077aed3SPierre Pronchery /*
11*b077aed3SPierre Pronchery * This file uses the low level AES functions (which are deprecated for
12*b077aed3SPierre Pronchery * non-internal use) in order to implement provider AES ciphers.
13*b077aed3SPierre Pronchery */
14*b077aed3SPierre Pronchery #include "internal/deprecated.h"
15*b077aed3SPierre Pronchery
16*b077aed3SPierre Pronchery #include <openssl/proverr.h>
17*b077aed3SPierre Pronchery #include "cipher_aes.h"
18*b077aed3SPierre Pronchery
cipher_hw_aes_initkey(PROV_CIPHER_CTX * dat,const unsigned char * key,size_t keylen)19*b077aed3SPierre Pronchery static int cipher_hw_aes_initkey(PROV_CIPHER_CTX *dat,
20*b077aed3SPierre Pronchery const unsigned char *key, size_t keylen)
21*b077aed3SPierre Pronchery {
22*b077aed3SPierre Pronchery int ret;
23*b077aed3SPierre Pronchery PROV_AES_CTX *adat = (PROV_AES_CTX *)dat;
24*b077aed3SPierre Pronchery AES_KEY *ks = &adat->ks.ks;
25*b077aed3SPierre Pronchery
26*b077aed3SPierre Pronchery dat->ks = ks;
27*b077aed3SPierre Pronchery
28*b077aed3SPierre Pronchery if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE)
29*b077aed3SPierre Pronchery && !dat->enc) {
30*b077aed3SPierre Pronchery #ifdef HWAES_CAPABLE
31*b077aed3SPierre Pronchery if (HWAES_CAPABLE) {
32*b077aed3SPierre Pronchery ret = HWAES_set_decrypt_key(key, keylen * 8, ks);
33*b077aed3SPierre Pronchery dat->block = (block128_f)HWAES_decrypt;
34*b077aed3SPierre Pronchery dat->stream.cbc = NULL;
35*b077aed3SPierre Pronchery # ifdef HWAES_cbc_encrypt
36*b077aed3SPierre Pronchery if (dat->mode == EVP_CIPH_CBC_MODE)
37*b077aed3SPierre Pronchery dat->stream.cbc = (cbc128_f)HWAES_cbc_encrypt;
38*b077aed3SPierre Pronchery # endif
39*b077aed3SPierre Pronchery # ifdef HWAES_ecb_encrypt
40*b077aed3SPierre Pronchery if (dat->mode == EVP_CIPH_ECB_MODE)
41*b077aed3SPierre Pronchery dat->stream.ecb = (ecb128_f)HWAES_ecb_encrypt;
42*b077aed3SPierre Pronchery # endif
43*b077aed3SPierre Pronchery } else
44*b077aed3SPierre Pronchery #endif
45*b077aed3SPierre Pronchery #ifdef BSAES_CAPABLE
46*b077aed3SPierre Pronchery if (BSAES_CAPABLE && dat->mode == EVP_CIPH_CBC_MODE) {
47*b077aed3SPierre Pronchery ret = AES_set_decrypt_key(key, keylen * 8, ks);
48*b077aed3SPierre Pronchery dat->block = (block128_f)AES_decrypt;
49*b077aed3SPierre Pronchery dat->stream.cbc = (cbc128_f)ossl_bsaes_cbc_encrypt;
50*b077aed3SPierre Pronchery } else
51*b077aed3SPierre Pronchery #endif
52*b077aed3SPierre Pronchery #ifdef VPAES_CAPABLE
53*b077aed3SPierre Pronchery if (VPAES_CAPABLE) {
54*b077aed3SPierre Pronchery ret = vpaes_set_decrypt_key(key, keylen * 8, ks);
55*b077aed3SPierre Pronchery dat->block = (block128_f)vpaes_decrypt;
56*b077aed3SPierre Pronchery dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE)
57*b077aed3SPierre Pronchery ?(cbc128_f)vpaes_cbc_encrypt : NULL;
58*b077aed3SPierre Pronchery } else
59*b077aed3SPierre Pronchery #endif
60*b077aed3SPierre Pronchery {
61*b077aed3SPierre Pronchery ret = AES_set_decrypt_key(key, keylen * 8, ks);
62*b077aed3SPierre Pronchery dat->block = (block128_f)AES_decrypt;
63*b077aed3SPierre Pronchery dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE)
64*b077aed3SPierre Pronchery ? (cbc128_f)AES_cbc_encrypt : NULL;
65*b077aed3SPierre Pronchery }
66*b077aed3SPierre Pronchery } else
67*b077aed3SPierre Pronchery #ifdef HWAES_CAPABLE
68*b077aed3SPierre Pronchery if (HWAES_CAPABLE) {
69*b077aed3SPierre Pronchery ret = HWAES_set_encrypt_key(key, keylen * 8, ks);
70*b077aed3SPierre Pronchery dat->block = (block128_f)HWAES_encrypt;
71*b077aed3SPierre Pronchery dat->stream.cbc = NULL;
72*b077aed3SPierre Pronchery # ifdef HWAES_cbc_encrypt
73*b077aed3SPierre Pronchery if (dat->mode == EVP_CIPH_CBC_MODE)
74*b077aed3SPierre Pronchery dat->stream.cbc = (cbc128_f)HWAES_cbc_encrypt;
75*b077aed3SPierre Pronchery else
76*b077aed3SPierre Pronchery # endif
77*b077aed3SPierre Pronchery # ifdef HWAES_ecb_encrypt
78*b077aed3SPierre Pronchery if (dat->mode == EVP_CIPH_ECB_MODE)
79*b077aed3SPierre Pronchery dat->stream.ecb = (ecb128_f)HWAES_ecb_encrypt;
80*b077aed3SPierre Pronchery else
81*b077aed3SPierre Pronchery # endif
82*b077aed3SPierre Pronchery # ifdef HWAES_ctr32_encrypt_blocks
83*b077aed3SPierre Pronchery if (dat->mode == EVP_CIPH_CTR_MODE)
84*b077aed3SPierre Pronchery dat->stream.ctr = (ctr128_f)HWAES_ctr32_encrypt_blocks;
85*b077aed3SPierre Pronchery else
86*b077aed3SPierre Pronchery # endif
87*b077aed3SPierre Pronchery (void)0; /* terminate potentially open 'else' */
88*b077aed3SPierre Pronchery } else
89*b077aed3SPierre Pronchery #endif
90*b077aed3SPierre Pronchery #ifdef BSAES_CAPABLE
91*b077aed3SPierre Pronchery if (BSAES_CAPABLE && dat->mode == EVP_CIPH_CTR_MODE) {
92*b077aed3SPierre Pronchery ret = AES_set_encrypt_key(key, keylen * 8, ks);
93*b077aed3SPierre Pronchery dat->block = (block128_f)AES_encrypt;
94*b077aed3SPierre Pronchery dat->stream.ctr = (ctr128_f)ossl_bsaes_ctr32_encrypt_blocks;
95*b077aed3SPierre Pronchery } else
96*b077aed3SPierre Pronchery #endif
97*b077aed3SPierre Pronchery #ifdef VPAES_CAPABLE
98*b077aed3SPierre Pronchery if (VPAES_CAPABLE) {
99*b077aed3SPierre Pronchery ret = vpaes_set_encrypt_key(key, keylen * 8, ks);
100*b077aed3SPierre Pronchery dat->block = (block128_f)vpaes_encrypt;
101*b077aed3SPierre Pronchery dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE)
102*b077aed3SPierre Pronchery ? (cbc128_f)vpaes_cbc_encrypt : NULL;
103*b077aed3SPierre Pronchery } else
104*b077aed3SPierre Pronchery #endif
105*b077aed3SPierre Pronchery {
106*b077aed3SPierre Pronchery ret = AES_set_encrypt_key(key, keylen * 8, ks);
107*b077aed3SPierre Pronchery dat->block = (block128_f)AES_encrypt;
108*b077aed3SPierre Pronchery dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE)
109*b077aed3SPierre Pronchery ? (cbc128_f)AES_cbc_encrypt : NULL;
110*b077aed3SPierre Pronchery #ifdef AES_CTR_ASM
111*b077aed3SPierre Pronchery if (dat->mode == EVP_CIPH_CTR_MODE)
112*b077aed3SPierre Pronchery dat->stream.ctr = (ctr128_f)AES_ctr32_encrypt;
113*b077aed3SPierre Pronchery #endif
114*b077aed3SPierre Pronchery }
115*b077aed3SPierre Pronchery
116*b077aed3SPierre Pronchery if (ret < 0) {
117*b077aed3SPierre Pronchery ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED);
118*b077aed3SPierre Pronchery return 0;
119*b077aed3SPierre Pronchery }
120*b077aed3SPierre Pronchery
121*b077aed3SPierre Pronchery return 1;
122*b077aed3SPierre Pronchery }
123*b077aed3SPierre Pronchery
124*b077aed3SPierre Pronchery IMPLEMENT_CIPHER_HW_COPYCTX(cipher_hw_aes_copyctx, PROV_AES_CTX)
125*b077aed3SPierre Pronchery
126*b077aed3SPierre Pronchery #define PROV_CIPHER_HW_aes_mode(mode) \
127*b077aed3SPierre Pronchery static const PROV_CIPHER_HW aes_##mode = { \
128*b077aed3SPierre Pronchery cipher_hw_aes_initkey, \
129*b077aed3SPierre Pronchery ossl_cipher_hw_generic_##mode, \
130*b077aed3SPierre Pronchery cipher_hw_aes_copyctx \
131*b077aed3SPierre Pronchery }; \
132*b077aed3SPierre Pronchery PROV_CIPHER_HW_declare(mode) \
133*b077aed3SPierre Pronchery const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_##mode(size_t keybits) \
134*b077aed3SPierre Pronchery { \
135*b077aed3SPierre Pronchery PROV_CIPHER_HW_select(mode) \
136*b077aed3SPierre Pronchery return &aes_##mode; \
137*b077aed3SPierre Pronchery }
138*b077aed3SPierre Pronchery
139*b077aed3SPierre Pronchery #if defined(AESNI_CAPABLE)
140*b077aed3SPierre Pronchery # include "cipher_aes_hw_aesni.inc"
141*b077aed3SPierre Pronchery #elif defined(SPARC_AES_CAPABLE)
142*b077aed3SPierre Pronchery # include "cipher_aes_hw_t4.inc"
143*b077aed3SPierre Pronchery #elif defined(S390X_aes_128_CAPABLE)
144*b077aed3SPierre Pronchery # include "cipher_aes_hw_s390x.inc"
145*b077aed3SPierre Pronchery #else
146*b077aed3SPierre Pronchery /* The generic case */
147*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_declare(mode)
148*b077aed3SPierre Pronchery # define PROV_CIPHER_HW_select(mode)
149*b077aed3SPierre Pronchery #endif
150*b077aed3SPierre Pronchery
151*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(cbc)
152*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(ecb)
153*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(ofb128)
154*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(cfb128)
155*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(cfb1)
156*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(cfb8)
157*b077aed3SPierre Pronchery PROV_CIPHER_HW_aes_mode(ctr)
158