mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 05:49:47 -04:00
crypto: aes - Add CTR and XCTR support using library
Implement the "ctr(aes)" and "xctr(aes)" crypto_skcipher algorithms using the corresponding library functions. Among other benefits, this allows the architecture-optimized AES-CTR and AES-XCTR code to be migrated into the library while still leaving it accessible via crypto_skcipher, eliminating lots of boilerplate code. For now the cra_priority is set to just 110, since the architecture-optimized implementations of these algorithms haven't yet been migrated into the library. It will be boosted once that happens. Link: https://patch.msgid.link/20260715221153.246410-11-ebiggers@kernel.org Signed-off-by: Eric Biggers <ebiggers@kernel.org>
This commit is contained in:
@@ -360,6 +360,7 @@ config CRYPTO_AES
|
||||
select CRYPTO_LIB_AES
|
||||
select CRYPTO_LIB_AES_CBC if CRYPTO_CBC != n || CRYPTO_CTS != n
|
||||
select CRYPTO_LIB_AES_CBC_MACS if CRYPTO_CMAC != n || CRYPTO_XCBC != n || CRYPTO_CCM != n
|
||||
select CRYPTO_LIB_AES_CTR if CRYPTO_CTR != n || CRYPTO_XCTR != n
|
||||
select CRYPTO_LIB_AES_ECB if CRYPTO_ECB != n
|
||||
select CRYPTO_HASH if CRYPTO_CMAC != n || CRYPTO_XCBC != n || CRYPTO_CCM != n
|
||||
# CRYPTO_SKCIPHER should be selected only if a mode that needs it is
|
||||
|
||||
68
crypto/aes.c
68
crypto/aes.c
@@ -7,6 +7,7 @@
|
||||
|
||||
#include <crypto/aes-cbc-macs.h>
|
||||
#include <crypto/aes-cbc.h>
|
||||
#include <crypto/aes-ctr.h>
|
||||
#include <crypto/aes-ecb.h>
|
||||
#include <crypto/aes.h>
|
||||
#include <crypto/algapi.h>
|
||||
@@ -456,6 +457,31 @@ crypto_aes_cbc_cts_decrypt(struct skcipher_request *req)
|
||||
return crypto_aes_cbc_cts_crypt_nonlinear(req, /* enc= */ false);
|
||||
}
|
||||
|
||||
/* AES-CTR */
|
||||
|
||||
static __maybe_unused int crypto_aes_ctr_crypt(struct skcipher_request *req)
|
||||
{
|
||||
const struct aes_enckey *key =
|
||||
crypto_skcipher_ctx(crypto_skcipher_reqtfm(req));
|
||||
|
||||
AES_CRYPT_SG(aes_ctr, req->dst, req->src, req->cryptlen, 0, req->iv,
|
||||
key);
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* AES-XCTR */
|
||||
|
||||
static __maybe_unused int crypto_aes_xctr_crypt(struct skcipher_request *req)
|
||||
{
|
||||
const struct aes_enckey *key =
|
||||
crypto_skcipher_ctx(crypto_skcipher_reqtfm(req));
|
||||
u64 ctr = 1;
|
||||
|
||||
AES_CRYPT_SG(aes_xctr, req->dst, req->src, req->cryptlen, 0, &ctr,
|
||||
req->iv, key);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static struct skcipher_alg skcipher_algs[] = {
|
||||
#if IS_ENABLED(CONFIG_CRYPTO_ECB)
|
||||
{
|
||||
@@ -504,6 +530,40 @@ static struct skcipher_alg skcipher_algs[] = {
|
||||
.decrypt = crypto_aes_cbc_cts_decrypt,
|
||||
},
|
||||
#endif
|
||||
#if IS_ENABLED(CONFIG_CRYPTO_CTR)
|
||||
{
|
||||
.base.cra_name = "ctr(aes)",
|
||||
.base.cra_driver_name = "ctr-aes-lib",
|
||||
.base.cra_priority = 110,
|
||||
.base.cra_blocksize = 1,
|
||||
.base.cra_ctxsize = sizeof(struct aes_enckey),
|
||||
.base.cra_module = THIS_MODULE,
|
||||
.min_keysize = AES_MIN_KEY_SIZE,
|
||||
.max_keysize = AES_MAX_KEY_SIZE,
|
||||
.ivsize = AES_BLOCK_SIZE,
|
||||
.chunksize = AES_BLOCK_SIZE,
|
||||
.setkey = crypto_aes_skcipher_setenckey,
|
||||
.encrypt = crypto_aes_ctr_crypt,
|
||||
.decrypt = crypto_aes_ctr_crypt,
|
||||
},
|
||||
#endif
|
||||
#if IS_ENABLED(CONFIG_CRYPTO_XCTR)
|
||||
{
|
||||
.base.cra_name = "xctr(aes)",
|
||||
.base.cra_driver_name = "xctr-aes-lib",
|
||||
.base.cra_priority = 110,
|
||||
.base.cra_blocksize = 1,
|
||||
.base.cra_ctxsize = sizeof(struct aes_enckey),
|
||||
.base.cra_module = THIS_MODULE,
|
||||
.min_keysize = AES_MIN_KEY_SIZE,
|
||||
.max_keysize = AES_MAX_KEY_SIZE,
|
||||
.ivsize = AES_BLOCK_SIZE,
|
||||
.chunksize = AES_BLOCK_SIZE,
|
||||
.setkey = crypto_aes_skcipher_setenckey,
|
||||
.encrypt = crypto_aes_xctr_crypt,
|
||||
.decrypt = crypto_aes_xctr_crypt,
|
||||
},
|
||||
#endif
|
||||
};
|
||||
|
||||
static int __init crypto_aes_mod_init(void)
|
||||
@@ -576,3 +636,11 @@ MODULE_ALIAS_CRYPTO("cbc-aes-lib");
|
||||
MODULE_ALIAS_CRYPTO("cts(cbc(aes))");
|
||||
MODULE_ALIAS_CRYPTO("cts-cbc-aes-lib");
|
||||
#endif
|
||||
#if IS_ENABLED(CONFIG_CRYPTO_CTR)
|
||||
MODULE_ALIAS_CRYPTO("ctr(aes)");
|
||||
MODULE_ALIAS_CRYPTO("ctr-aes-lib");
|
||||
#endif
|
||||
#if IS_ENABLED(CONFIG_CRYPTO_XCTR)
|
||||
MODULE_ALIAS_CRYPTO("xctr(aes)");
|
||||
MODULE_ALIAS_CRYPTO("xctr-aes-lib");
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user