Commit | Line | Data |
---|---|---|
20a884f5 | 1 | // SPDX-License-Identifier: GPL-2.0 |
df1309ce GS |
2 | /* |
3 | * Cryptographic API. | |
4 | * | |
5 | * s390 implementation of the GHASH algorithm for GCM (Galois/Counter Mode). | |
6 | * | |
7 | * Copyright IBM Corp. 2011 | |
8 | * Author(s): Gerald Schaefer <gerald.schaefer@de.ibm.com> | |
9 | */ | |
10 | ||
11 | #include <crypto/internal/hash.h> | |
12 | #include <linux/module.h> | |
d05377c1 | 13 | #include <linux/cpufeature.h> |
c7d4d259 | 14 | #include <asm/cpacf.h> |
df1309ce GS |
15 | |
16 | #define GHASH_BLOCK_SIZE 16 | |
17 | #define GHASH_DIGEST_SIZE 16 | |
18 | ||
19 | struct ghash_ctx { | |
a1cae34e | 20 | u8 key[GHASH_BLOCK_SIZE]; |
df1309ce GS |
21 | }; |
22 | ||
23 | struct ghash_desc_ctx { | |
a1cae34e HF |
24 | u8 icv[GHASH_BLOCK_SIZE]; |
25 | u8 key[GHASH_BLOCK_SIZE]; | |
df1309ce GS |
26 | u8 buffer[GHASH_BLOCK_SIZE]; |
27 | u32 bytes; | |
28 | }; | |
29 | ||
30 | static int ghash_init(struct shash_desc *desc) | |
31 | { | |
32 | struct ghash_desc_ctx *dctx = shash_desc_ctx(desc); | |
a1cae34e | 33 | struct ghash_ctx *ctx = crypto_shash_ctx(desc->tfm); |
df1309ce GS |
34 | |
35 | memset(dctx, 0, sizeof(*dctx)); | |
a1cae34e | 36 | memcpy(dctx->key, ctx->key, GHASH_BLOCK_SIZE); |
df1309ce GS |
37 | |
38 | return 0; | |
39 | } | |
40 | ||
41 | static int ghash_setkey(struct crypto_shash *tfm, | |
42 | const u8 *key, unsigned int keylen) | |
43 | { | |
44 | struct ghash_ctx *ctx = crypto_shash_ctx(tfm); | |
45 | ||
46 | if (keylen != GHASH_BLOCK_SIZE) { | |
47 | crypto_shash_set_flags(tfm, CRYPTO_TFM_RES_BAD_KEY_LEN); | |
48 | return -EINVAL; | |
49 | } | |
50 | ||
51 | memcpy(ctx->key, key, GHASH_BLOCK_SIZE); | |
df1309ce GS |
52 | |
53 | return 0; | |
54 | } | |
55 | ||
56 | static int ghash_update(struct shash_desc *desc, | |
57 | const u8 *src, unsigned int srclen) | |
58 | { | |
59 | struct ghash_desc_ctx *dctx = shash_desc_ctx(desc); | |
df1309ce GS |
60 | unsigned int n; |
61 | u8 *buf = dctx->buffer; | |
df1309ce GS |
62 | |
63 | if (dctx->bytes) { | |
64 | u8 *pos = buf + (GHASH_BLOCK_SIZE - dctx->bytes); | |
65 | ||
66 | n = min(srclen, dctx->bytes); | |
67 | dctx->bytes -= n; | |
68 | srclen -= n; | |
69 | ||
70 | memcpy(pos, src, n); | |
71 | src += n; | |
72 | ||
73 | if (!dctx->bytes) { | |
0177db01 MS |
74 | cpacf_kimd(CPACF_KIMD_GHASH, dctx, buf, |
75 | GHASH_BLOCK_SIZE); | |
df1309ce GS |
76 | } |
77 | } | |
78 | ||
79 | n = srclen & ~(GHASH_BLOCK_SIZE - 1); | |
80 | if (n) { | |
0177db01 | 81 | cpacf_kimd(CPACF_KIMD_GHASH, dctx, src, n); |
df1309ce GS |
82 | src += n; |
83 | srclen -= n; | |
84 | } | |
85 | ||
86 | if (srclen) { | |
87 | dctx->bytes = GHASH_BLOCK_SIZE - srclen; | |
88 | memcpy(buf, src, srclen); | |
89 | } | |
90 | ||
91 | return 0; | |
92 | } | |
93 | ||
a1cae34e | 94 | static int ghash_flush(struct ghash_desc_ctx *dctx) |
df1309ce GS |
95 | { |
96 | u8 *buf = dctx->buffer; | |
df1309ce GS |
97 | |
98 | if (dctx->bytes) { | |
99 | u8 *pos = buf + (GHASH_BLOCK_SIZE - dctx->bytes); | |
100 | ||
101 | memset(pos, 0, dctx->bytes); | |
0177db01 | 102 | cpacf_kimd(CPACF_KIMD_GHASH, dctx, buf, GHASH_BLOCK_SIZE); |
a1cae34e | 103 | dctx->bytes = 0; |
df1309ce GS |
104 | } |
105 | ||
36eb2caa | 106 | return 0; |
df1309ce GS |
107 | } |
108 | ||
109 | static int ghash_final(struct shash_desc *desc, u8 *dst) | |
110 | { | |
111 | struct ghash_desc_ctx *dctx = shash_desc_ctx(desc); | |
36eb2caa | 112 | int ret; |
df1309ce | 113 | |
a1cae34e | 114 | ret = ghash_flush(dctx); |
36eb2caa | 115 | if (!ret) |
a1cae34e | 116 | memcpy(dst, dctx->icv, GHASH_BLOCK_SIZE); |
36eb2caa | 117 | return ret; |
df1309ce GS |
118 | } |
119 | ||
120 | static struct shash_alg ghash_alg = { | |
121 | .digestsize = GHASH_DIGEST_SIZE, | |
122 | .init = ghash_init, | |
123 | .update = ghash_update, | |
124 | .final = ghash_final, | |
125 | .setkey = ghash_setkey, | |
126 | .descsize = sizeof(struct ghash_desc_ctx), | |
127 | .base = { | |
128 | .cra_name = "ghash", | |
129 | .cra_driver_name = "ghash-s390", | |
c7d4d259 | 130 | .cra_priority = 300, |
df1309ce GS |
131 | .cra_blocksize = GHASH_BLOCK_SIZE, |
132 | .cra_ctxsize = sizeof(struct ghash_ctx), | |
133 | .cra_module = THIS_MODULE, | |
df1309ce GS |
134 | }, |
135 | }; | |
136 | ||
137 | static int __init ghash_mod_init(void) | |
138 | { | |
69c0e360 | 139 | if (!cpacf_query_func(CPACF_KIMD, CPACF_KIMD_GHASH)) |
1c0908fc | 140 | return -ENODEV; |
df1309ce GS |
141 | |
142 | return crypto_register_shash(&ghash_alg); | |
143 | } | |
144 | ||
145 | static void __exit ghash_mod_exit(void) | |
146 | { | |
147 | crypto_unregister_shash(&ghash_alg); | |
148 | } | |
149 | ||
d05377c1 | 150 | module_cpu_feature_match(MSA, ghash_mod_init); |
df1309ce GS |
151 | module_exit(ghash_mod_exit); |
152 | ||
5d26a105 | 153 | MODULE_ALIAS_CRYPTO("ghash"); |
df1309ce GS |
154 | |
155 | MODULE_LICENSE("GPL"); | |
8dfa20fc | 156 | MODULE_DESCRIPTION("GHASH hash function, s390 implementation"); |