cipher-gcrypt.c.inc 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289
  1. /*
  2. * QEMU Crypto cipher libgcrypt algorithms
  3. *
  4. * Copyright (c) 2015 Red Hat, Inc.
  5. *
  6. * This library is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 2.1 of the License, or (at your option) any later version.
  10. *
  11. * This library is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public
  17. * License along with this library; if not, see <http://www.gnu.org/licenses/>.
  18. *
  19. */
  20. #include <gcrypt.h>
  21. static int qcrypto_cipher_alg_to_gcry_alg(QCryptoCipherAlgo alg)
  22. {
  23. switch (alg) {
  24. case QCRYPTO_CIPHER_ALGO_DES:
  25. return GCRY_CIPHER_DES;
  26. case QCRYPTO_CIPHER_ALGO_3DES:
  27. return GCRY_CIPHER_3DES;
  28. case QCRYPTO_CIPHER_ALGO_AES_128:
  29. return GCRY_CIPHER_AES128;
  30. case QCRYPTO_CIPHER_ALGO_AES_192:
  31. return GCRY_CIPHER_AES192;
  32. case QCRYPTO_CIPHER_ALGO_AES_256:
  33. return GCRY_CIPHER_AES256;
  34. case QCRYPTO_CIPHER_ALGO_CAST5_128:
  35. return GCRY_CIPHER_CAST5;
  36. case QCRYPTO_CIPHER_ALGO_SERPENT_128:
  37. return GCRY_CIPHER_SERPENT128;
  38. case QCRYPTO_CIPHER_ALGO_SERPENT_192:
  39. return GCRY_CIPHER_SERPENT192;
  40. case QCRYPTO_CIPHER_ALGO_SERPENT_256:
  41. return GCRY_CIPHER_SERPENT256;
  42. case QCRYPTO_CIPHER_ALGO_TWOFISH_128:
  43. return GCRY_CIPHER_TWOFISH128;
  44. case QCRYPTO_CIPHER_ALGO_TWOFISH_256:
  45. return GCRY_CIPHER_TWOFISH;
  46. #ifdef CONFIG_CRYPTO_SM4
  47. case QCRYPTO_CIPHER_ALGO_SM4:
  48. return GCRY_CIPHER_SM4;
  49. #endif
  50. default:
  51. return GCRY_CIPHER_NONE;
  52. }
  53. }
  54. static int qcrypto_cipher_mode_to_gcry_mode(QCryptoCipherMode mode)
  55. {
  56. switch (mode) {
  57. case QCRYPTO_CIPHER_MODE_ECB:
  58. return GCRY_CIPHER_MODE_ECB;
  59. case QCRYPTO_CIPHER_MODE_XTS:
  60. return GCRY_CIPHER_MODE_XTS;
  61. case QCRYPTO_CIPHER_MODE_CBC:
  62. return GCRY_CIPHER_MODE_CBC;
  63. case QCRYPTO_CIPHER_MODE_CTR:
  64. return GCRY_CIPHER_MODE_CTR;
  65. default:
  66. return GCRY_CIPHER_MODE_NONE;
  67. }
  68. }
  69. bool qcrypto_cipher_supports(QCryptoCipherAlgo alg,
  70. QCryptoCipherMode mode)
  71. {
  72. switch (alg) {
  73. case QCRYPTO_CIPHER_ALGO_DES:
  74. case QCRYPTO_CIPHER_ALGO_3DES:
  75. case QCRYPTO_CIPHER_ALGO_AES_128:
  76. case QCRYPTO_CIPHER_ALGO_AES_192:
  77. case QCRYPTO_CIPHER_ALGO_AES_256:
  78. case QCRYPTO_CIPHER_ALGO_CAST5_128:
  79. case QCRYPTO_CIPHER_ALGO_SERPENT_128:
  80. case QCRYPTO_CIPHER_ALGO_SERPENT_192:
  81. case QCRYPTO_CIPHER_ALGO_SERPENT_256:
  82. case QCRYPTO_CIPHER_ALGO_TWOFISH_128:
  83. case QCRYPTO_CIPHER_ALGO_TWOFISH_256:
  84. #ifdef CONFIG_CRYPTO_SM4
  85. case QCRYPTO_CIPHER_ALGO_SM4:
  86. #endif
  87. break;
  88. default:
  89. return false;
  90. }
  91. if (gcry_cipher_algo_info(qcrypto_cipher_alg_to_gcry_alg(alg),
  92. GCRYCTL_TEST_ALGO, NULL, NULL) != 0) {
  93. return false;
  94. }
  95. switch (mode) {
  96. case QCRYPTO_CIPHER_MODE_ECB:
  97. case QCRYPTO_CIPHER_MODE_CBC:
  98. case QCRYPTO_CIPHER_MODE_XTS:
  99. case QCRYPTO_CIPHER_MODE_CTR:
  100. return true;
  101. default:
  102. return false;
  103. }
  104. }
  105. typedef struct QCryptoCipherGcrypt {
  106. QCryptoCipher base;
  107. gcry_cipher_hd_t handle;
  108. size_t blocksize;
  109. } QCryptoCipherGcrypt;
  110. static void qcrypto_gcrypt_ctx_free(QCryptoCipher *cipher)
  111. {
  112. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  113. gcry_cipher_close(ctx->handle);
  114. g_free(ctx);
  115. }
  116. static int qcrypto_gcrypt_encrypt(QCryptoCipher *cipher, const void *in,
  117. void *out, size_t len, Error **errp)
  118. {
  119. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  120. gcry_error_t err;
  121. if (len & (ctx->blocksize - 1)) {
  122. error_setg(errp, "Length %zu must be a multiple of block size %zu",
  123. len, ctx->blocksize);
  124. return -1;
  125. }
  126. err = gcry_cipher_encrypt(ctx->handle, out, len, in, len);
  127. if (err != 0) {
  128. error_setg(errp, "Cannot encrypt data: %s", gcry_strerror(err));
  129. return -1;
  130. }
  131. return 0;
  132. }
  133. static int qcrypto_gcrypt_decrypt(QCryptoCipher *cipher, const void *in,
  134. void *out, size_t len, Error **errp)
  135. {
  136. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  137. gcry_error_t err;
  138. if (len & (ctx->blocksize - 1)) {
  139. error_setg(errp, "Length %zu must be a multiple of block size %zu",
  140. len, ctx->blocksize);
  141. return -1;
  142. }
  143. err = gcry_cipher_decrypt(ctx->handle, out, len, in, len);
  144. if (err != 0) {
  145. error_setg(errp, "Cannot decrypt data: %s",
  146. gcry_strerror(err));
  147. return -1;
  148. }
  149. return 0;
  150. }
  151. static int qcrypto_gcrypt_setiv(QCryptoCipher *cipher,
  152. const uint8_t *iv, size_t niv,
  153. Error **errp)
  154. {
  155. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  156. gcry_error_t err;
  157. if (niv != ctx->blocksize) {
  158. error_setg(errp, "Expected IV size %zu not %zu",
  159. ctx->blocksize, niv);
  160. return -1;
  161. }
  162. gcry_cipher_reset(ctx->handle);
  163. err = gcry_cipher_setiv(ctx->handle, iv, niv);
  164. if (err != 0) {
  165. error_setg(errp, "Cannot set IV: %s", gcry_strerror(err));
  166. return -1;
  167. }
  168. return 0;
  169. }
  170. static int qcrypto_gcrypt_ctr_setiv(QCryptoCipher *cipher,
  171. const uint8_t *iv, size_t niv,
  172. Error **errp)
  173. {
  174. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  175. gcry_error_t err;
  176. if (niv != ctx->blocksize) {
  177. error_setg(errp, "Expected IV size %zu not %zu",
  178. ctx->blocksize, niv);
  179. return -1;
  180. }
  181. err = gcry_cipher_setctr(ctx->handle, iv, niv);
  182. if (err != 0) {
  183. error_setg(errp, "Cannot set Counter: %s", gcry_strerror(err));
  184. return -1;
  185. }
  186. return 0;
  187. }
  188. static const struct QCryptoCipherDriver qcrypto_gcrypt_driver = {
  189. .cipher_encrypt = qcrypto_gcrypt_encrypt,
  190. .cipher_decrypt = qcrypto_gcrypt_decrypt,
  191. .cipher_setiv = qcrypto_gcrypt_setiv,
  192. .cipher_free = qcrypto_gcrypt_ctx_free,
  193. };
  194. static const struct QCryptoCipherDriver qcrypto_gcrypt_ctr_driver = {
  195. .cipher_encrypt = qcrypto_gcrypt_encrypt,
  196. .cipher_decrypt = qcrypto_gcrypt_decrypt,
  197. .cipher_setiv = qcrypto_gcrypt_ctr_setiv,
  198. .cipher_free = qcrypto_gcrypt_ctx_free,
  199. };
  200. static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgo alg,
  201. QCryptoCipherMode mode,
  202. const uint8_t *key,
  203. size_t nkey,
  204. Error **errp)
  205. {
  206. QCryptoCipherGcrypt *ctx;
  207. const QCryptoCipherDriver *drv;
  208. gcry_error_t err;
  209. int gcryalg, gcrymode;
  210. if (!qcrypto_cipher_validate_key_length(alg, mode, nkey, errp)) {
  211. return NULL;
  212. }
  213. gcryalg = qcrypto_cipher_alg_to_gcry_alg(alg);
  214. if (gcryalg == GCRY_CIPHER_NONE) {
  215. error_setg(errp, "Unsupported cipher algorithm %s",
  216. QCryptoCipherAlgo_str(alg));
  217. return NULL;
  218. }
  219. gcrymode = qcrypto_cipher_mode_to_gcry_mode(mode);
  220. if (gcrymode == GCRY_CIPHER_MODE_NONE) {
  221. error_setg(errp, "Unsupported cipher mode %s",
  222. QCryptoCipherMode_str(mode));
  223. return NULL;
  224. }
  225. if (mode == QCRYPTO_CIPHER_MODE_CTR) {
  226. drv = &qcrypto_gcrypt_ctr_driver;
  227. } else {
  228. drv = &qcrypto_gcrypt_driver;
  229. }
  230. ctx = g_new0(QCryptoCipherGcrypt, 1);
  231. ctx->base.driver = drv;
  232. err = gcry_cipher_open(&ctx->handle, gcryalg, gcrymode, 0);
  233. if (err != 0) {
  234. error_setg(errp, "Cannot initialize cipher: %s",
  235. gcry_strerror(err));
  236. goto error;
  237. }
  238. ctx->blocksize = gcry_cipher_get_algo_blklen(gcryalg);
  239. err = gcry_cipher_setkey(ctx->handle, key, nkey);
  240. if (err != 0) {
  241. error_setg(errp, "Cannot set key: %s", gcry_strerror(err));
  242. goto error;
  243. }
  244. return &ctx->base;
  245. error:
  246. gcry_cipher_close(ctx->handle);
  247. g_free(ctx);
  248. return NULL;
  249. }