cipher-gcrypt.c.inc 7.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272
  1. /*
  2. * QEMU Crypto cipher libgcrypt algorithms
  3. *
  4. * Copyright (c) 2015 Red Hat, Inc.
  5. *
  6. * This library is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 2.1 of the License, or (at your option) any later version.
  10. *
  11. * This library is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public
  17. * License along with this library; if not, see <http://www.gnu.org/licenses/>.
  18. *
  19. */
  20. #include <gcrypt.h>
  21. bool qcrypto_cipher_supports(QCryptoCipherAlgorithm alg,
  22. QCryptoCipherMode mode)
  23. {
  24. switch (alg) {
  25. case QCRYPTO_CIPHER_ALG_DES:
  26. case QCRYPTO_CIPHER_ALG_3DES:
  27. case QCRYPTO_CIPHER_ALG_AES_128:
  28. case QCRYPTO_CIPHER_ALG_AES_192:
  29. case QCRYPTO_CIPHER_ALG_AES_256:
  30. case QCRYPTO_CIPHER_ALG_CAST5_128:
  31. case QCRYPTO_CIPHER_ALG_SERPENT_128:
  32. case QCRYPTO_CIPHER_ALG_SERPENT_192:
  33. case QCRYPTO_CIPHER_ALG_SERPENT_256:
  34. case QCRYPTO_CIPHER_ALG_TWOFISH_128:
  35. case QCRYPTO_CIPHER_ALG_TWOFISH_256:
  36. break;
  37. default:
  38. return false;
  39. }
  40. switch (mode) {
  41. case QCRYPTO_CIPHER_MODE_ECB:
  42. case QCRYPTO_CIPHER_MODE_CBC:
  43. case QCRYPTO_CIPHER_MODE_XTS:
  44. case QCRYPTO_CIPHER_MODE_CTR:
  45. return true;
  46. default:
  47. return false;
  48. }
  49. }
  50. typedef struct QCryptoCipherGcrypt {
  51. QCryptoCipher base;
  52. gcry_cipher_hd_t handle;
  53. size_t blocksize;
  54. } QCryptoCipherGcrypt;
  55. static void qcrypto_gcrypt_ctx_free(QCryptoCipher *cipher)
  56. {
  57. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  58. gcry_cipher_close(ctx->handle);
  59. g_free(ctx);
  60. }
  61. static int qcrypto_gcrypt_encrypt(QCryptoCipher *cipher, const void *in,
  62. void *out, size_t len, Error **errp)
  63. {
  64. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  65. gcry_error_t err;
  66. if (len & (ctx->blocksize - 1)) {
  67. error_setg(errp, "Length %zu must be a multiple of block size %zu",
  68. len, ctx->blocksize);
  69. return -1;
  70. }
  71. err = gcry_cipher_encrypt(ctx->handle, out, len, in, len);
  72. if (err != 0) {
  73. error_setg(errp, "Cannot encrypt data: %s", gcry_strerror(err));
  74. return -1;
  75. }
  76. return 0;
  77. }
  78. static int qcrypto_gcrypt_decrypt(QCryptoCipher *cipher, const void *in,
  79. void *out, size_t len, Error **errp)
  80. {
  81. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  82. gcry_error_t err;
  83. if (len & (ctx->blocksize - 1)) {
  84. error_setg(errp, "Length %zu must be a multiple of block size %zu",
  85. len, ctx->blocksize);
  86. return -1;
  87. }
  88. err = gcry_cipher_decrypt(ctx->handle, out, len, in, len);
  89. if (err != 0) {
  90. error_setg(errp, "Cannot decrypt data: %s",
  91. gcry_strerror(err));
  92. return -1;
  93. }
  94. return 0;
  95. }
  96. static int qcrypto_gcrypt_setiv(QCryptoCipher *cipher,
  97. const uint8_t *iv, size_t niv,
  98. Error **errp)
  99. {
  100. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  101. gcry_error_t err;
  102. if (niv != ctx->blocksize) {
  103. error_setg(errp, "Expected IV size %zu not %zu",
  104. ctx->blocksize, niv);
  105. return -1;
  106. }
  107. gcry_cipher_reset(ctx->handle);
  108. err = gcry_cipher_setiv(ctx->handle, iv, niv);
  109. if (err != 0) {
  110. error_setg(errp, "Cannot set IV: %s", gcry_strerror(err));
  111. return -1;
  112. }
  113. return 0;
  114. }
  115. static int qcrypto_gcrypt_ctr_setiv(QCryptoCipher *cipher,
  116. const uint8_t *iv, size_t niv,
  117. Error **errp)
  118. {
  119. QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
  120. gcry_error_t err;
  121. if (niv != ctx->blocksize) {
  122. error_setg(errp, "Expected IV size %zu not %zu",
  123. ctx->blocksize, niv);
  124. return -1;
  125. }
  126. err = gcry_cipher_setctr(ctx->handle, iv, niv);
  127. if (err != 0) {
  128. error_setg(errp, "Cannot set Counter: %s", gcry_strerror(err));
  129. return -1;
  130. }
  131. return 0;
  132. }
  133. static const struct QCryptoCipherDriver qcrypto_gcrypt_driver = {
  134. .cipher_encrypt = qcrypto_gcrypt_encrypt,
  135. .cipher_decrypt = qcrypto_gcrypt_decrypt,
  136. .cipher_setiv = qcrypto_gcrypt_setiv,
  137. .cipher_free = qcrypto_gcrypt_ctx_free,
  138. };
  139. static const struct QCryptoCipherDriver qcrypto_gcrypt_ctr_driver = {
  140. .cipher_encrypt = qcrypto_gcrypt_encrypt,
  141. .cipher_decrypt = qcrypto_gcrypt_decrypt,
  142. .cipher_setiv = qcrypto_gcrypt_ctr_setiv,
  143. .cipher_free = qcrypto_gcrypt_ctx_free,
  144. };
  145. static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgorithm alg,
  146. QCryptoCipherMode mode,
  147. const uint8_t *key,
  148. size_t nkey,
  149. Error **errp)
  150. {
  151. QCryptoCipherGcrypt *ctx;
  152. const QCryptoCipherDriver *drv;
  153. gcry_error_t err;
  154. int gcryalg, gcrymode;
  155. if (!qcrypto_cipher_validate_key_length(alg, mode, nkey, errp)) {
  156. return NULL;
  157. }
  158. switch (alg) {
  159. case QCRYPTO_CIPHER_ALG_DES:
  160. gcryalg = GCRY_CIPHER_DES;
  161. break;
  162. case QCRYPTO_CIPHER_ALG_3DES:
  163. gcryalg = GCRY_CIPHER_3DES;
  164. break;
  165. case QCRYPTO_CIPHER_ALG_AES_128:
  166. gcryalg = GCRY_CIPHER_AES128;
  167. break;
  168. case QCRYPTO_CIPHER_ALG_AES_192:
  169. gcryalg = GCRY_CIPHER_AES192;
  170. break;
  171. case QCRYPTO_CIPHER_ALG_AES_256:
  172. gcryalg = GCRY_CIPHER_AES256;
  173. break;
  174. case QCRYPTO_CIPHER_ALG_CAST5_128:
  175. gcryalg = GCRY_CIPHER_CAST5;
  176. break;
  177. case QCRYPTO_CIPHER_ALG_SERPENT_128:
  178. gcryalg = GCRY_CIPHER_SERPENT128;
  179. break;
  180. case QCRYPTO_CIPHER_ALG_SERPENT_192:
  181. gcryalg = GCRY_CIPHER_SERPENT192;
  182. break;
  183. case QCRYPTO_CIPHER_ALG_SERPENT_256:
  184. gcryalg = GCRY_CIPHER_SERPENT256;
  185. break;
  186. case QCRYPTO_CIPHER_ALG_TWOFISH_128:
  187. gcryalg = GCRY_CIPHER_TWOFISH128;
  188. break;
  189. case QCRYPTO_CIPHER_ALG_TWOFISH_256:
  190. gcryalg = GCRY_CIPHER_TWOFISH;
  191. break;
  192. default:
  193. error_setg(errp, "Unsupported cipher algorithm %s",
  194. QCryptoCipherAlgorithm_str(alg));
  195. return NULL;
  196. }
  197. drv = &qcrypto_gcrypt_driver;
  198. switch (mode) {
  199. case QCRYPTO_CIPHER_MODE_ECB:
  200. gcrymode = GCRY_CIPHER_MODE_ECB;
  201. break;
  202. case QCRYPTO_CIPHER_MODE_XTS:
  203. gcrymode = GCRY_CIPHER_MODE_XTS;
  204. break;
  205. case QCRYPTO_CIPHER_MODE_CBC:
  206. gcrymode = GCRY_CIPHER_MODE_CBC;
  207. break;
  208. case QCRYPTO_CIPHER_MODE_CTR:
  209. drv = &qcrypto_gcrypt_ctr_driver;
  210. gcrymode = GCRY_CIPHER_MODE_CTR;
  211. break;
  212. default:
  213. error_setg(errp, "Unsupported cipher mode %s",
  214. QCryptoCipherMode_str(mode));
  215. return NULL;
  216. }
  217. ctx = g_new0(QCryptoCipherGcrypt, 1);
  218. ctx->base.driver = drv;
  219. err = gcry_cipher_open(&ctx->handle, gcryalg, gcrymode, 0);
  220. if (err != 0) {
  221. error_setg(errp, "Cannot initialize cipher: %s",
  222. gcry_strerror(err));
  223. goto error;
  224. }
  225. ctx->blocksize = gcry_cipher_get_algo_blklen(gcryalg);
  226. err = gcry_cipher_setkey(ctx->handle, key, nkey);
  227. if (err != 0) {
  228. error_setg(errp, "Cannot set key: %s", gcry_strerror(err));
  229. goto error;
  230. }
  231. return &ctx->base;
  232. error:
  233. gcry_cipher_close(ctx->handle);
  234. g_free(ctx);
  235. return NULL;
  236. }