xref: /freebsd-src/crypto/openssl/providers/implementations/ciphers/cipher_rc4_hmac_md5_hw.c (revision b077aed33b7b6aefca7b17ddb250cf521f938613)
1*b077aed3SPierre Pronchery /*
2*b077aed3SPierre Pronchery  * Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.
3*b077aed3SPierre Pronchery  *
4*b077aed3SPierre Pronchery  * Licensed under the Apache License 2.0 (the "License").  You may not use
5*b077aed3SPierre Pronchery  * this file except in compliance with the License.  You can obtain a copy
6*b077aed3SPierre Pronchery  * in the file LICENSE in the source distribution or at
7*b077aed3SPierre Pronchery  * https://www.openssl.org/source/license.html
8*b077aed3SPierre Pronchery  */
9*b077aed3SPierre Pronchery 
10*b077aed3SPierre Pronchery /* RC4_HMAC_MD5 cipher implementation */
11*b077aed3SPierre Pronchery 
12*b077aed3SPierre Pronchery /*
13*b077aed3SPierre Pronchery  * MD5 and RC4 low level APIs are deprecated for public use, but still ok for
14*b077aed3SPierre Pronchery  * internal use.
15*b077aed3SPierre Pronchery  */
16*b077aed3SPierre Pronchery #include "internal/deprecated.h"
17*b077aed3SPierre Pronchery 
18*b077aed3SPierre Pronchery #include "cipher_rc4_hmac_md5.h"
19*b077aed3SPierre Pronchery 
20*b077aed3SPierre Pronchery #define NO_PAYLOAD_LENGTH ((size_t)-1)
21*b077aed3SPierre Pronchery 
22*b077aed3SPierre Pronchery #if defined(RC4_ASM)                                                           \
23*b077aed3SPierre Pronchery     && defined(MD5_ASM)                                                        \
24*b077aed3SPierre Pronchery     && (defined(__x86_64)                                                      \
25*b077aed3SPierre Pronchery         || defined(__x86_64__)                                                 \
26*b077aed3SPierre Pronchery         || defined(_M_AMD64)                                                   \
27*b077aed3SPierre Pronchery         || defined(_M_X64))
28*b077aed3SPierre Pronchery # define STITCHED_CALL
29*b077aed3SPierre Pronchery # define MOD 32 /* 32 is $MOD from rc4_md5-x86_64.pl */
30*b077aed3SPierre Pronchery #else
31*b077aed3SPierre Pronchery # define rc4_off 0
32*b077aed3SPierre Pronchery # define md5_off 0
33*b077aed3SPierre Pronchery #endif
34*b077aed3SPierre Pronchery 
cipher_hw_rc4_hmac_md5_initkey(PROV_CIPHER_CTX * bctx,const uint8_t * key,size_t keylen)35*b077aed3SPierre Pronchery static int cipher_hw_rc4_hmac_md5_initkey(PROV_CIPHER_CTX *bctx,
36*b077aed3SPierre Pronchery                                           const uint8_t *key, size_t keylen)
37*b077aed3SPierre Pronchery {
38*b077aed3SPierre Pronchery     PROV_RC4_HMAC_MD5_CTX *ctx = (PROV_RC4_HMAC_MD5_CTX *)bctx;
39*b077aed3SPierre Pronchery 
40*b077aed3SPierre Pronchery     RC4_set_key(&ctx->ks.ks, keylen, key);
41*b077aed3SPierre Pronchery     MD5_Init(&ctx->head);       /* handy when benchmarking */
42*b077aed3SPierre Pronchery     ctx->tail = ctx->head;
43*b077aed3SPierre Pronchery     ctx->md = ctx->head;
44*b077aed3SPierre Pronchery     ctx->payload_length = NO_PAYLOAD_LENGTH;
45*b077aed3SPierre Pronchery     bctx->removetlsfixed = MD5_DIGEST_LENGTH;
46*b077aed3SPierre Pronchery     return 1;
47*b077aed3SPierre Pronchery }
48*b077aed3SPierre Pronchery 
cipher_hw_rc4_hmac_md5_cipher(PROV_CIPHER_CTX * bctx,unsigned char * out,const unsigned char * in,size_t len)49*b077aed3SPierre Pronchery static int cipher_hw_rc4_hmac_md5_cipher(PROV_CIPHER_CTX *bctx,
50*b077aed3SPierre Pronchery                                          unsigned char *out,
51*b077aed3SPierre Pronchery                                          const unsigned char *in, size_t len)
52*b077aed3SPierre Pronchery {
53*b077aed3SPierre Pronchery     PROV_RC4_HMAC_MD5_CTX *ctx = (PROV_RC4_HMAC_MD5_CTX *)bctx;
54*b077aed3SPierre Pronchery     RC4_KEY *ks = &ctx->ks.ks;
55*b077aed3SPierre Pronchery 
56*b077aed3SPierre Pronchery #if defined(STITCHED_CALL)
57*b077aed3SPierre Pronchery     size_t rc4_off = MOD - 1 - (ks->x & (MOD - 1));
58*b077aed3SPierre Pronchery     size_t md5_off = MD5_CBLOCK - ctx->md.num, blocks;
59*b077aed3SPierre Pronchery     unsigned int l;
60*b077aed3SPierre Pronchery #endif
61*b077aed3SPierre Pronchery     size_t plen = ctx->payload_length;
62*b077aed3SPierre Pronchery 
63*b077aed3SPierre Pronchery     if (plen != NO_PAYLOAD_LENGTH && len != (plen + MD5_DIGEST_LENGTH))
64*b077aed3SPierre Pronchery         return 0;
65*b077aed3SPierre Pronchery 
66*b077aed3SPierre Pronchery     if (ctx->base.enc) {
67*b077aed3SPierre Pronchery         if (plen == NO_PAYLOAD_LENGTH)
68*b077aed3SPierre Pronchery             plen = len;
69*b077aed3SPierre Pronchery #if defined(STITCHED_CALL)
70*b077aed3SPierre Pronchery         /* cipher has to "fall behind" */
71*b077aed3SPierre Pronchery         if (rc4_off > md5_off)
72*b077aed3SPierre Pronchery             md5_off += MD5_CBLOCK;
73*b077aed3SPierre Pronchery 
74*b077aed3SPierre Pronchery         if (plen > md5_off
75*b077aed3SPierre Pronchery                 && (blocks = (plen - md5_off) / MD5_CBLOCK)
76*b077aed3SPierre Pronchery                 && (OPENSSL_ia32cap_P[0] & (1 << 20)) == 0) {
77*b077aed3SPierre Pronchery             MD5_Update(&ctx->md, in, md5_off);
78*b077aed3SPierre Pronchery             RC4(ks, rc4_off, in, out);
79*b077aed3SPierre Pronchery 
80*b077aed3SPierre Pronchery             rc4_md5_enc(ks, in + rc4_off, out + rc4_off,
81*b077aed3SPierre Pronchery                         &ctx->md, in + md5_off, blocks);
82*b077aed3SPierre Pronchery             blocks *= MD5_CBLOCK;
83*b077aed3SPierre Pronchery             rc4_off += blocks;
84*b077aed3SPierre Pronchery             md5_off += blocks;
85*b077aed3SPierre Pronchery             ctx->md.Nh += blocks >> 29;
86*b077aed3SPierre Pronchery             ctx->md.Nl += blocks <<= 3;
87*b077aed3SPierre Pronchery             if (ctx->md.Nl < (unsigned int)blocks)
88*b077aed3SPierre Pronchery                 ctx->md.Nh++;
89*b077aed3SPierre Pronchery         } else {
90*b077aed3SPierre Pronchery             rc4_off = 0;
91*b077aed3SPierre Pronchery             md5_off = 0;
92*b077aed3SPierre Pronchery         }
93*b077aed3SPierre Pronchery #endif
94*b077aed3SPierre Pronchery         MD5_Update(&ctx->md, in + md5_off, plen - md5_off);
95*b077aed3SPierre Pronchery 
96*b077aed3SPierre Pronchery         if (plen != len) {      /* "TLS" mode of operation */
97*b077aed3SPierre Pronchery             if (in != out)
98*b077aed3SPierre Pronchery                 memcpy(out + rc4_off, in + rc4_off, plen - rc4_off);
99*b077aed3SPierre Pronchery 
100*b077aed3SPierre Pronchery             /* calculate HMAC and append it to payload */
101*b077aed3SPierre Pronchery             MD5_Final(out + plen, &ctx->md);
102*b077aed3SPierre Pronchery             ctx->md = ctx->tail;
103*b077aed3SPierre Pronchery             MD5_Update(&ctx->md, out + plen, MD5_DIGEST_LENGTH);
104*b077aed3SPierre Pronchery             MD5_Final(out + plen, &ctx->md);
105*b077aed3SPierre Pronchery             /* encrypt HMAC at once */
106*b077aed3SPierre Pronchery             RC4(ks, len - rc4_off, out + rc4_off, out + rc4_off);
107*b077aed3SPierre Pronchery         } else {
108*b077aed3SPierre Pronchery             RC4(ks, len - rc4_off, in + rc4_off, out + rc4_off);
109*b077aed3SPierre Pronchery         }
110*b077aed3SPierre Pronchery     } else {
111*b077aed3SPierre Pronchery         unsigned char mac[MD5_DIGEST_LENGTH];
112*b077aed3SPierre Pronchery 
113*b077aed3SPierre Pronchery #if defined(STITCHED_CALL)
114*b077aed3SPierre Pronchery         /* digest has to "fall behind" */
115*b077aed3SPierre Pronchery         if (md5_off > rc4_off)
116*b077aed3SPierre Pronchery             rc4_off += 2 * MD5_CBLOCK;
117*b077aed3SPierre Pronchery         else
118*b077aed3SPierre Pronchery             rc4_off += MD5_CBLOCK;
119*b077aed3SPierre Pronchery 
120*b077aed3SPierre Pronchery         if (len > rc4_off
121*b077aed3SPierre Pronchery                 && (blocks = (len - rc4_off) / MD5_CBLOCK)
122*b077aed3SPierre Pronchery                 && (OPENSSL_ia32cap_P[0] & (1 << 20)) == 0) {
123*b077aed3SPierre Pronchery             RC4(ks, rc4_off, in, out);
124*b077aed3SPierre Pronchery             MD5_Update(&ctx->md, out, md5_off);
125*b077aed3SPierre Pronchery 
126*b077aed3SPierre Pronchery             rc4_md5_enc(ks, in + rc4_off, out + rc4_off,
127*b077aed3SPierre Pronchery                         &ctx->md, out + md5_off, blocks);
128*b077aed3SPierre Pronchery             blocks *= MD5_CBLOCK;
129*b077aed3SPierre Pronchery             rc4_off += blocks;
130*b077aed3SPierre Pronchery             md5_off += blocks;
131*b077aed3SPierre Pronchery             l = (ctx->md.Nl + (blocks << 3)) & 0xffffffffU;
132*b077aed3SPierre Pronchery             if (l < ctx->md.Nl)
133*b077aed3SPierre Pronchery                 ctx->md.Nh++;
134*b077aed3SPierre Pronchery             ctx->md.Nl = l;
135*b077aed3SPierre Pronchery             ctx->md.Nh += blocks >> 29;
136*b077aed3SPierre Pronchery         } else {
137*b077aed3SPierre Pronchery             md5_off = 0;
138*b077aed3SPierre Pronchery             rc4_off = 0;
139*b077aed3SPierre Pronchery         }
140*b077aed3SPierre Pronchery #endif
141*b077aed3SPierre Pronchery         /* decrypt HMAC at once */
142*b077aed3SPierre Pronchery         RC4(ks, len - rc4_off, in + rc4_off, out + rc4_off);
143*b077aed3SPierre Pronchery         if (plen != NO_PAYLOAD_LENGTH) {
144*b077aed3SPierre Pronchery             /* "TLS" mode of operation */
145*b077aed3SPierre Pronchery             MD5_Update(&ctx->md, out + md5_off, plen - md5_off);
146*b077aed3SPierre Pronchery 
147*b077aed3SPierre Pronchery             /* calculate HMAC and verify it */
148*b077aed3SPierre Pronchery             MD5_Final(mac, &ctx->md);
149*b077aed3SPierre Pronchery             ctx->md = ctx->tail;
150*b077aed3SPierre Pronchery             MD5_Update(&ctx->md, mac, MD5_DIGEST_LENGTH);
151*b077aed3SPierre Pronchery             MD5_Final(mac, &ctx->md);
152*b077aed3SPierre Pronchery 
153*b077aed3SPierre Pronchery             if (CRYPTO_memcmp(out + plen, mac, MD5_DIGEST_LENGTH))
154*b077aed3SPierre Pronchery                 return 0;
155*b077aed3SPierre Pronchery         } else {
156*b077aed3SPierre Pronchery             MD5_Update(&ctx->md, out + md5_off, len - md5_off);
157*b077aed3SPierre Pronchery         }
158*b077aed3SPierre Pronchery     }
159*b077aed3SPierre Pronchery 
160*b077aed3SPierre Pronchery     ctx->payload_length = NO_PAYLOAD_LENGTH;
161*b077aed3SPierre Pronchery 
162*b077aed3SPierre Pronchery     return 1;
163*b077aed3SPierre Pronchery }
164*b077aed3SPierre Pronchery 
cipher_hw_rc4_hmac_md5_tls_init(PROV_CIPHER_CTX * bctx,unsigned char * aad,size_t aad_len)165*b077aed3SPierre Pronchery static int cipher_hw_rc4_hmac_md5_tls_init(PROV_CIPHER_CTX *bctx,
166*b077aed3SPierre Pronchery                                            unsigned char *aad, size_t aad_len)
167*b077aed3SPierre Pronchery {
168*b077aed3SPierre Pronchery     PROV_RC4_HMAC_MD5_CTX *ctx = (PROV_RC4_HMAC_MD5_CTX *)bctx;
169*b077aed3SPierre Pronchery     unsigned int len;
170*b077aed3SPierre Pronchery 
171*b077aed3SPierre Pronchery     if (aad_len != EVP_AEAD_TLS1_AAD_LEN)
172*b077aed3SPierre Pronchery         return 0;
173*b077aed3SPierre Pronchery 
174*b077aed3SPierre Pronchery     len = aad[aad_len - 2] << 8 | aad[aad_len - 1];
175*b077aed3SPierre Pronchery 
176*b077aed3SPierre Pronchery     if (!bctx->enc) {
177*b077aed3SPierre Pronchery         if (len < MD5_DIGEST_LENGTH)
178*b077aed3SPierre Pronchery             return 0;
179*b077aed3SPierre Pronchery         len -= MD5_DIGEST_LENGTH;
180*b077aed3SPierre Pronchery         aad[aad_len - 2] = len >> 8;
181*b077aed3SPierre Pronchery         aad[aad_len - 1] = len;
182*b077aed3SPierre Pronchery     }
183*b077aed3SPierre Pronchery     ctx->payload_length = len;
184*b077aed3SPierre Pronchery     ctx->md = ctx->head;
185*b077aed3SPierre Pronchery     MD5_Update(&ctx->md, aad, aad_len);
186*b077aed3SPierre Pronchery 
187*b077aed3SPierre Pronchery     return MD5_DIGEST_LENGTH;
188*b077aed3SPierre Pronchery }
189*b077aed3SPierre Pronchery 
cipher_hw_rc4_hmac_md5_init_mackey(PROV_CIPHER_CTX * bctx,const unsigned char * key,size_t len)190*b077aed3SPierre Pronchery static void cipher_hw_rc4_hmac_md5_init_mackey(PROV_CIPHER_CTX *bctx,
191*b077aed3SPierre Pronchery                                                const unsigned char *key,
192*b077aed3SPierre Pronchery                                                size_t len)
193*b077aed3SPierre Pronchery {
194*b077aed3SPierre Pronchery     PROV_RC4_HMAC_MD5_CTX *ctx = (PROV_RC4_HMAC_MD5_CTX *)bctx;
195*b077aed3SPierre Pronchery     unsigned int i;
196*b077aed3SPierre Pronchery     unsigned char hmac_key[64];
197*b077aed3SPierre Pronchery 
198*b077aed3SPierre Pronchery     memset(hmac_key, 0, sizeof(hmac_key));
199*b077aed3SPierre Pronchery 
200*b077aed3SPierre Pronchery     if (len > (int)sizeof(hmac_key)) {
201*b077aed3SPierre Pronchery         MD5_Init(&ctx->head);
202*b077aed3SPierre Pronchery         MD5_Update(&ctx->head, key, len);
203*b077aed3SPierre Pronchery         MD5_Final(hmac_key, &ctx->head);
204*b077aed3SPierre Pronchery     } else {
205*b077aed3SPierre Pronchery         memcpy(hmac_key, key, len);
206*b077aed3SPierre Pronchery     }
207*b077aed3SPierre Pronchery 
208*b077aed3SPierre Pronchery     for (i = 0; i < sizeof(hmac_key); i++)
209*b077aed3SPierre Pronchery         hmac_key[i] ^= 0x36; /* ipad */
210*b077aed3SPierre Pronchery     MD5_Init(&ctx->head);
211*b077aed3SPierre Pronchery     MD5_Update(&ctx->head, hmac_key, sizeof(hmac_key));
212*b077aed3SPierre Pronchery 
213*b077aed3SPierre Pronchery     for (i = 0; i < sizeof(hmac_key); i++)
214*b077aed3SPierre Pronchery         hmac_key[i] ^= 0x36 ^ 0x5c; /* opad */
215*b077aed3SPierre Pronchery     MD5_Init(&ctx->tail);
216*b077aed3SPierre Pronchery     MD5_Update(&ctx->tail, hmac_key, sizeof(hmac_key));
217*b077aed3SPierre Pronchery 
218*b077aed3SPierre Pronchery     OPENSSL_cleanse(hmac_key, sizeof(hmac_key));
219*b077aed3SPierre Pronchery }
220*b077aed3SPierre Pronchery 
221*b077aed3SPierre Pronchery static const PROV_CIPHER_HW_RC4_HMAC_MD5 rc4_hmac_md5_hw = {
222*b077aed3SPierre Pronchery     {
223*b077aed3SPierre Pronchery       cipher_hw_rc4_hmac_md5_initkey,
224*b077aed3SPierre Pronchery       cipher_hw_rc4_hmac_md5_cipher
225*b077aed3SPierre Pronchery     },
226*b077aed3SPierre Pronchery     cipher_hw_rc4_hmac_md5_tls_init,
227*b077aed3SPierre Pronchery     cipher_hw_rc4_hmac_md5_init_mackey
228*b077aed3SPierre Pronchery };
229*b077aed3SPierre Pronchery 
ossl_prov_cipher_hw_rc4_hmac_md5(size_t keybits)230*b077aed3SPierre Pronchery const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc4_hmac_md5(size_t keybits)
231*b077aed3SPierre Pronchery {
232*b077aed3SPierre Pronchery     return (PROV_CIPHER_HW *)&rc4_hmac_md5_hw;
233*b077aed3SPierre Pronchery }
234