1 // SPDX-License-Identifier: GPL-2.0-or-later
3 * Glue Code for x86_64/AVX/AES-NI assembler optimized version of Camellia
5 * Copyright © 2012-2013 Jussi Kivilinna <jussi.kivilinna@iki.fi>
8 #include <asm/crypto/camellia.h>
9 #include <asm/crypto/glue_helper.h>
10 #include <crypto/algapi.h>
11 #include <crypto/internal/simd.h>
12 #include <crypto/xts.h>
13 #include <linux/crypto.h>
14 #include <linux/err.h>
15 #include <linux/module.h>
16 #include <linux/types.h>
18 #define CAMELLIA_AESNI_PARALLEL_BLOCKS 16
20 /* 16-way parallel cipher functions (avx/aes-ni) */
21 asmlinkage void camellia_ecb_enc_16way(const void *ctx, u8 *dst, const u8 *src);
22 EXPORT_SYMBOL_GPL(camellia_ecb_enc_16way);
24 asmlinkage void camellia_ecb_dec_16way(const void *ctx, u8 *dst, const u8 *src);
25 EXPORT_SYMBOL_GPL(camellia_ecb_dec_16way);
27 asmlinkage void camellia_cbc_dec_16way(const void *ctx, u8 *dst, const u8 *src);
28 EXPORT_SYMBOL_GPL(camellia_cbc_dec_16way);
30 asmlinkage void camellia_ctr_16way(const void *ctx, u8 *dst, const u8 *src,
32 EXPORT_SYMBOL_GPL(camellia_ctr_16way);
34 asmlinkage void camellia_xts_enc_16way(const void *ctx, u8 *dst, const u8 *src,
36 EXPORT_SYMBOL_GPL(camellia_xts_enc_16way);
38 asmlinkage void camellia_xts_dec_16way(const void *ctx, u8 *dst, const u8 *src,
40 EXPORT_SYMBOL_GPL(camellia_xts_dec_16way);
42 void camellia_xts_enc(const void *ctx, u8 *dst, const u8 *src, le128 *iv)
44 glue_xts_crypt_128bit_one(ctx, dst, src, iv, camellia_enc_blk);
46 EXPORT_SYMBOL_GPL(camellia_xts_enc);
48 void camellia_xts_dec(const void *ctx, u8 *dst, const u8 *src, le128 *iv)
50 glue_xts_crypt_128bit_one(ctx, dst, src, iv, camellia_dec_blk);
52 EXPORT_SYMBOL_GPL(camellia_xts_dec);
54 static const struct common_glue_ctx camellia_enc = {
56 .fpu_blocks_limit = CAMELLIA_AESNI_PARALLEL_BLOCKS,
59 .num_blocks = CAMELLIA_AESNI_PARALLEL_BLOCKS,
60 .fn_u = { .ecb = camellia_ecb_enc_16way }
63 .fn_u = { .ecb = camellia_enc_blk_2way }
66 .fn_u = { .ecb = camellia_enc_blk }
70 static const struct common_glue_ctx camellia_ctr = {
72 .fpu_blocks_limit = CAMELLIA_AESNI_PARALLEL_BLOCKS,
75 .num_blocks = CAMELLIA_AESNI_PARALLEL_BLOCKS,
76 .fn_u = { .ctr = camellia_ctr_16way }
79 .fn_u = { .ctr = camellia_crypt_ctr_2way }
82 .fn_u = { .ctr = camellia_crypt_ctr }
86 static const struct common_glue_ctx camellia_enc_xts = {
88 .fpu_blocks_limit = CAMELLIA_AESNI_PARALLEL_BLOCKS,
91 .num_blocks = CAMELLIA_AESNI_PARALLEL_BLOCKS,
92 .fn_u = { .xts = camellia_xts_enc_16way }
95 .fn_u = { .xts = camellia_xts_enc }
99 static const struct common_glue_ctx camellia_dec = {
101 .fpu_blocks_limit = CAMELLIA_AESNI_PARALLEL_BLOCKS,
104 .num_blocks = CAMELLIA_AESNI_PARALLEL_BLOCKS,
105 .fn_u = { .ecb = camellia_ecb_dec_16way }
108 .fn_u = { .ecb = camellia_dec_blk_2way }
111 .fn_u = { .ecb = camellia_dec_blk }
115 static const struct common_glue_ctx camellia_dec_cbc = {
117 .fpu_blocks_limit = CAMELLIA_AESNI_PARALLEL_BLOCKS,
120 .num_blocks = CAMELLIA_AESNI_PARALLEL_BLOCKS,
121 .fn_u = { .cbc = camellia_cbc_dec_16way }
124 .fn_u = { .cbc = camellia_decrypt_cbc_2way }
127 .fn_u = { .cbc = camellia_dec_blk }
131 static const struct common_glue_ctx camellia_dec_xts = {
133 .fpu_blocks_limit = CAMELLIA_AESNI_PARALLEL_BLOCKS,
136 .num_blocks = CAMELLIA_AESNI_PARALLEL_BLOCKS,
137 .fn_u = { .xts = camellia_xts_dec_16way }
140 .fn_u = { .xts = camellia_xts_dec }
144 static int camellia_setkey(struct crypto_skcipher *tfm, const u8 *key,
147 return __camellia_setkey(crypto_skcipher_ctx(tfm), key, keylen,
148 &tfm->base.crt_flags);
151 static int ecb_encrypt(struct skcipher_request *req)
153 return glue_ecb_req_128bit(&camellia_enc, req);
156 static int ecb_decrypt(struct skcipher_request *req)
158 return glue_ecb_req_128bit(&camellia_dec, req);
161 static int cbc_encrypt(struct skcipher_request *req)
163 return glue_cbc_encrypt_req_128bit(camellia_enc_blk, req);
166 static int cbc_decrypt(struct skcipher_request *req)
168 return glue_cbc_decrypt_req_128bit(&camellia_dec_cbc, req);
171 static int ctr_crypt(struct skcipher_request *req)
173 return glue_ctr_req_128bit(&camellia_ctr, req);
176 int xts_camellia_setkey(struct crypto_skcipher *tfm, const u8 *key,
179 struct camellia_xts_ctx *ctx = crypto_skcipher_ctx(tfm);
180 u32 *flags = &tfm->base.crt_flags;
183 err = xts_verify_key(tfm, key, keylen);
187 /* first half of xts-key is for crypt */
188 err = __camellia_setkey(&ctx->crypt_ctx, key, keylen / 2, flags);
192 /* second half of xts-key is for tweak */
193 return __camellia_setkey(&ctx->tweak_ctx, key + keylen / 2, keylen / 2,
196 EXPORT_SYMBOL_GPL(xts_camellia_setkey);
198 static int xts_encrypt(struct skcipher_request *req)
200 struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
201 struct camellia_xts_ctx *ctx = crypto_skcipher_ctx(tfm);
203 return glue_xts_req_128bit(&camellia_enc_xts, req, camellia_enc_blk,
204 &ctx->tweak_ctx, &ctx->crypt_ctx, false);
207 static int xts_decrypt(struct skcipher_request *req)
209 struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
210 struct camellia_xts_ctx *ctx = crypto_skcipher_ctx(tfm);
212 return glue_xts_req_128bit(&camellia_dec_xts, req, camellia_enc_blk,
213 &ctx->tweak_ctx, &ctx->crypt_ctx, true);
216 static struct skcipher_alg camellia_algs[] = {
218 .base.cra_name = "__ecb(camellia)",
219 .base.cra_driver_name = "__ecb-camellia-aesni",
220 .base.cra_priority = 400,
221 .base.cra_flags = CRYPTO_ALG_INTERNAL,
222 .base.cra_blocksize = CAMELLIA_BLOCK_SIZE,
223 .base.cra_ctxsize = sizeof(struct camellia_ctx),
224 .base.cra_module = THIS_MODULE,
225 .min_keysize = CAMELLIA_MIN_KEY_SIZE,
226 .max_keysize = CAMELLIA_MAX_KEY_SIZE,
227 .setkey = camellia_setkey,
228 .encrypt = ecb_encrypt,
229 .decrypt = ecb_decrypt,
231 .base.cra_name = "__cbc(camellia)",
232 .base.cra_driver_name = "__cbc-camellia-aesni",
233 .base.cra_priority = 400,
234 .base.cra_flags = CRYPTO_ALG_INTERNAL,
235 .base.cra_blocksize = CAMELLIA_BLOCK_SIZE,
236 .base.cra_ctxsize = sizeof(struct camellia_ctx),
237 .base.cra_module = THIS_MODULE,
238 .min_keysize = CAMELLIA_MIN_KEY_SIZE,
239 .max_keysize = CAMELLIA_MAX_KEY_SIZE,
240 .ivsize = CAMELLIA_BLOCK_SIZE,
241 .setkey = camellia_setkey,
242 .encrypt = cbc_encrypt,
243 .decrypt = cbc_decrypt,
245 .base.cra_name = "__ctr(camellia)",
246 .base.cra_driver_name = "__ctr-camellia-aesni",
247 .base.cra_priority = 400,
248 .base.cra_flags = CRYPTO_ALG_INTERNAL,
249 .base.cra_blocksize = 1,
250 .base.cra_ctxsize = sizeof(struct camellia_ctx),
251 .base.cra_module = THIS_MODULE,
252 .min_keysize = CAMELLIA_MIN_KEY_SIZE,
253 .max_keysize = CAMELLIA_MAX_KEY_SIZE,
254 .ivsize = CAMELLIA_BLOCK_SIZE,
255 .chunksize = CAMELLIA_BLOCK_SIZE,
256 .setkey = camellia_setkey,
257 .encrypt = ctr_crypt,
258 .decrypt = ctr_crypt,
260 .base.cra_name = "__xts(camellia)",
261 .base.cra_driver_name = "__xts-camellia-aesni",
262 .base.cra_priority = 400,
263 .base.cra_flags = CRYPTO_ALG_INTERNAL,
264 .base.cra_blocksize = CAMELLIA_BLOCK_SIZE,
265 .base.cra_ctxsize = sizeof(struct camellia_xts_ctx),
266 .base.cra_module = THIS_MODULE,
267 .min_keysize = 2 * CAMELLIA_MIN_KEY_SIZE,
268 .max_keysize = 2 * CAMELLIA_MAX_KEY_SIZE,
269 .ivsize = CAMELLIA_BLOCK_SIZE,
270 .setkey = xts_camellia_setkey,
271 .encrypt = xts_encrypt,
272 .decrypt = xts_decrypt,
276 static struct simd_skcipher_alg *camellia_simd_algs[ARRAY_SIZE(camellia_algs)];
278 static int __init camellia_aesni_init(void)
280 const char *feature_name;
282 if (!boot_cpu_has(X86_FEATURE_AVX) ||
283 !boot_cpu_has(X86_FEATURE_AES) ||
284 !boot_cpu_has(X86_FEATURE_OSXSAVE)) {
285 pr_info("AVX or AES-NI instructions are not detected.\n");
289 if (!cpu_has_xfeatures(XFEATURE_MASK_SSE | XFEATURE_MASK_YMM,
291 pr_info("CPU feature '%s' is not supported.\n", feature_name);
295 return simd_register_skciphers_compat(camellia_algs,
296 ARRAY_SIZE(camellia_algs),
300 static void __exit camellia_aesni_fini(void)
302 simd_unregister_skciphers(camellia_algs, ARRAY_SIZE(camellia_algs),
306 module_init(camellia_aesni_init);
307 module_exit(camellia_aesni_fini);
309 MODULE_LICENSE("GPL");
310 MODULE_DESCRIPTION("Camellia Cipher Algorithm, AES-NI/AVX optimized");
311 MODULE_ALIAS_CRYPTO("camellia");
312 MODULE_ALIAS_CRYPTO("camellia-asm");