cachepc-linux

Fork of AMDESE/linux with modifications for CachePC side-channel attack
git clone https://git.sinitax.com/sinitax/cachepc-linux
Log | Files | Refs | README | LICENSE | sfeed.txt

rmd160.c (12721B)


      1// SPDX-License-Identifier: GPL-2.0-or-later
      2/*
      3 * Cryptographic API.
      4 *
      5 * RIPEMD-160 - RACE Integrity Primitives Evaluation Message Digest.
      6 *
      7 * Based on the reference implementation by Antoon Bosselaers, ESAT-COSIC
      8 *
      9 * Copyright (c) 2008 Adrian-Ken Rueegsegger <ken@codelabs.ch>
     10 */
     11#include <crypto/internal/hash.h>
     12#include <linux/init.h>
     13#include <linux/module.h>
     14#include <linux/mm.h>
     15#include <linux/types.h>
     16#include <asm/byteorder.h>
     17
     18#include "ripemd.h"
     19
     20struct rmd160_ctx {
     21	u64 byte_count;
     22	u32 state[5];
     23	__le32 buffer[16];
     24};
     25
     26#define K1  RMD_K1
     27#define K2  RMD_K2
     28#define K3  RMD_K3
     29#define K4  RMD_K4
     30#define K5  RMD_K5
     31#define KK1 RMD_K6
     32#define KK2 RMD_K7
     33#define KK3 RMD_K8
     34#define KK4 RMD_K9
     35#define KK5 RMD_K1
     36
     37#define F1(x, y, z) (x ^ y ^ z)		/* XOR */
     38#define F2(x, y, z) (z ^ (x & (y ^ z)))	/* x ? y : z */
     39#define F3(x, y, z) ((x | ~y) ^ z)
     40#define F4(x, y, z) (y ^ (z & (x ^ y)))	/* z ? x : y */
     41#define F5(x, y, z) (x ^ (y | ~z))
     42
     43#define ROUND(a, b, c, d, e, f, k, x, s)  { \
     44	(a) += f((b), (c), (d)) + le32_to_cpup(&(x)) + (k); \
     45	(a) = rol32((a), (s)) + (e); \
     46	(c) = rol32((c), 10); \
     47}
     48
     49static void rmd160_transform(u32 *state, const __le32 *in)
     50{
     51	u32 aa, bb, cc, dd, ee, aaa, bbb, ccc, ddd, eee;
     52
     53	/* Initialize left lane */
     54	aa = state[0];
     55	bb = state[1];
     56	cc = state[2];
     57	dd = state[3];
     58	ee = state[4];
     59
     60	/* Initialize right lane */
     61	aaa = state[0];
     62	bbb = state[1];
     63	ccc = state[2];
     64	ddd = state[3];
     65	eee = state[4];
     66
     67	/* round 1: left lane */
     68	ROUND(aa, bb, cc, dd, ee, F1, K1, in[0],  11);
     69	ROUND(ee, aa, bb, cc, dd, F1, K1, in[1],  14);
     70	ROUND(dd, ee, aa, bb, cc, F1, K1, in[2],  15);
     71	ROUND(cc, dd, ee, aa, bb, F1, K1, in[3],  12);
     72	ROUND(bb, cc, dd, ee, aa, F1, K1, in[4],   5);
     73	ROUND(aa, bb, cc, dd, ee, F1, K1, in[5],   8);
     74	ROUND(ee, aa, bb, cc, dd, F1, K1, in[6],   7);
     75	ROUND(dd, ee, aa, bb, cc, F1, K1, in[7],   9);
     76	ROUND(cc, dd, ee, aa, bb, F1, K1, in[8],  11);
     77	ROUND(bb, cc, dd, ee, aa, F1, K1, in[9],  13);
     78	ROUND(aa, bb, cc, dd, ee, F1, K1, in[10], 14);
     79	ROUND(ee, aa, bb, cc, dd, F1, K1, in[11], 15);
     80	ROUND(dd, ee, aa, bb, cc, F1, K1, in[12],  6);
     81	ROUND(cc, dd, ee, aa, bb, F1, K1, in[13],  7);
     82	ROUND(bb, cc, dd, ee, aa, F1, K1, in[14],  9);
     83	ROUND(aa, bb, cc, dd, ee, F1, K1, in[15],  8);
     84
     85	/* round 2: left lane" */
     86	ROUND(ee, aa, bb, cc, dd, F2, K2, in[7],   7);
     87	ROUND(dd, ee, aa, bb, cc, F2, K2, in[4],   6);
     88	ROUND(cc, dd, ee, aa, bb, F2, K2, in[13],  8);
     89	ROUND(bb, cc, dd, ee, aa, F2, K2, in[1],  13);
     90	ROUND(aa, bb, cc, dd, ee, F2, K2, in[10], 11);
     91	ROUND(ee, aa, bb, cc, dd, F2, K2, in[6],   9);
     92	ROUND(dd, ee, aa, bb, cc, F2, K2, in[15],  7);
     93	ROUND(cc, dd, ee, aa, bb, F2, K2, in[3],  15);
     94	ROUND(bb, cc, dd, ee, aa, F2, K2, in[12],  7);
     95	ROUND(aa, bb, cc, dd, ee, F2, K2, in[0],  12);
     96	ROUND(ee, aa, bb, cc, dd, F2, K2, in[9],  15);
     97	ROUND(dd, ee, aa, bb, cc, F2, K2, in[5],   9);
     98	ROUND(cc, dd, ee, aa, bb, F2, K2, in[2],  11);
     99	ROUND(bb, cc, dd, ee, aa, F2, K2, in[14],  7);
    100	ROUND(aa, bb, cc, dd, ee, F2, K2, in[11], 13);
    101	ROUND(ee, aa, bb, cc, dd, F2, K2, in[8],  12);
    102
    103	/* round 3: left lane" */
    104	ROUND(dd, ee, aa, bb, cc, F3, K3, in[3],  11);
    105	ROUND(cc, dd, ee, aa, bb, F3, K3, in[10], 13);
    106	ROUND(bb, cc, dd, ee, aa, F3, K3, in[14],  6);
    107	ROUND(aa, bb, cc, dd, ee, F3, K3, in[4],   7);
    108	ROUND(ee, aa, bb, cc, dd, F3, K3, in[9],  14);
    109	ROUND(dd, ee, aa, bb, cc, F3, K3, in[15],  9);
    110	ROUND(cc, dd, ee, aa, bb, F3, K3, in[8],  13);
    111	ROUND(bb, cc, dd, ee, aa, F3, K3, in[1],  15);
    112	ROUND(aa, bb, cc, dd, ee, F3, K3, in[2],  14);
    113	ROUND(ee, aa, bb, cc, dd, F3, K3, in[7],   8);
    114	ROUND(dd, ee, aa, bb, cc, F3, K3, in[0],  13);
    115	ROUND(cc, dd, ee, aa, bb, F3, K3, in[6],   6);
    116	ROUND(bb, cc, dd, ee, aa, F3, K3, in[13],  5);
    117	ROUND(aa, bb, cc, dd, ee, F3, K3, in[11], 12);
    118	ROUND(ee, aa, bb, cc, dd, F3, K3, in[5],   7);
    119	ROUND(dd, ee, aa, bb, cc, F3, K3, in[12],  5);
    120
    121	/* round 4: left lane" */
    122	ROUND(cc, dd, ee, aa, bb, F4, K4, in[1],  11);
    123	ROUND(bb, cc, dd, ee, aa, F4, K4, in[9],  12);
    124	ROUND(aa, bb, cc, dd, ee, F4, K4, in[11], 14);
    125	ROUND(ee, aa, bb, cc, dd, F4, K4, in[10], 15);
    126	ROUND(dd, ee, aa, bb, cc, F4, K4, in[0],  14);
    127	ROUND(cc, dd, ee, aa, bb, F4, K4, in[8],  15);
    128	ROUND(bb, cc, dd, ee, aa, F4, K4, in[12],  9);
    129	ROUND(aa, bb, cc, dd, ee, F4, K4, in[4],   8);
    130	ROUND(ee, aa, bb, cc, dd, F4, K4, in[13],  9);
    131	ROUND(dd, ee, aa, bb, cc, F4, K4, in[3],  14);
    132	ROUND(cc, dd, ee, aa, bb, F4, K4, in[7],   5);
    133	ROUND(bb, cc, dd, ee, aa, F4, K4, in[15],  6);
    134	ROUND(aa, bb, cc, dd, ee, F4, K4, in[14],  8);
    135	ROUND(ee, aa, bb, cc, dd, F4, K4, in[5],   6);
    136	ROUND(dd, ee, aa, bb, cc, F4, K4, in[6],   5);
    137	ROUND(cc, dd, ee, aa, bb, F4, K4, in[2],  12);
    138
    139	/* round 5: left lane" */
    140	ROUND(bb, cc, dd, ee, aa, F5, K5, in[4],   9);
    141	ROUND(aa, bb, cc, dd, ee, F5, K5, in[0],  15);
    142	ROUND(ee, aa, bb, cc, dd, F5, K5, in[5],   5);
    143	ROUND(dd, ee, aa, bb, cc, F5, K5, in[9],  11);
    144	ROUND(cc, dd, ee, aa, bb, F5, K5, in[7],   6);
    145	ROUND(bb, cc, dd, ee, aa, F5, K5, in[12],  8);
    146	ROUND(aa, bb, cc, dd, ee, F5, K5, in[2],  13);
    147	ROUND(ee, aa, bb, cc, dd, F5, K5, in[10], 12);
    148	ROUND(dd, ee, aa, bb, cc, F5, K5, in[14],  5);
    149	ROUND(cc, dd, ee, aa, bb, F5, K5, in[1],  12);
    150	ROUND(bb, cc, dd, ee, aa, F5, K5, in[3],  13);
    151	ROUND(aa, bb, cc, dd, ee, F5, K5, in[8],  14);
    152	ROUND(ee, aa, bb, cc, dd, F5, K5, in[11], 11);
    153	ROUND(dd, ee, aa, bb, cc, F5, K5, in[6],   8);
    154	ROUND(cc, dd, ee, aa, bb, F5, K5, in[15],  5);
    155	ROUND(bb, cc, dd, ee, aa, F5, K5, in[13],  6);
    156
    157	/* round 1: right lane */
    158	ROUND(aaa, bbb, ccc, ddd, eee, F5, KK1, in[5],   8);
    159	ROUND(eee, aaa, bbb, ccc, ddd, F5, KK1, in[14],  9);
    160	ROUND(ddd, eee, aaa, bbb, ccc, F5, KK1, in[7],   9);
    161	ROUND(ccc, ddd, eee, aaa, bbb, F5, KK1, in[0],  11);
    162	ROUND(bbb, ccc, ddd, eee, aaa, F5, KK1, in[9],  13);
    163	ROUND(aaa, bbb, ccc, ddd, eee, F5, KK1, in[2],  15);
    164	ROUND(eee, aaa, bbb, ccc, ddd, F5, KK1, in[11], 15);
    165	ROUND(ddd, eee, aaa, bbb, ccc, F5, KK1, in[4],   5);
    166	ROUND(ccc, ddd, eee, aaa, bbb, F5, KK1, in[13],  7);
    167	ROUND(bbb, ccc, ddd, eee, aaa, F5, KK1, in[6],   7);
    168	ROUND(aaa, bbb, ccc, ddd, eee, F5, KK1, in[15],  8);
    169	ROUND(eee, aaa, bbb, ccc, ddd, F5, KK1, in[8],  11);
    170	ROUND(ddd, eee, aaa, bbb, ccc, F5, KK1, in[1],  14);
    171	ROUND(ccc, ddd, eee, aaa, bbb, F5, KK1, in[10], 14);
    172	ROUND(bbb, ccc, ddd, eee, aaa, F5, KK1, in[3],  12);
    173	ROUND(aaa, bbb, ccc, ddd, eee, F5, KK1, in[12],  6);
    174
    175	/* round 2: right lane */
    176	ROUND(eee, aaa, bbb, ccc, ddd, F4, KK2, in[6],   9);
    177	ROUND(ddd, eee, aaa, bbb, ccc, F4, KK2, in[11], 13);
    178	ROUND(ccc, ddd, eee, aaa, bbb, F4, KK2, in[3],  15);
    179	ROUND(bbb, ccc, ddd, eee, aaa, F4, KK2, in[7],   7);
    180	ROUND(aaa, bbb, ccc, ddd, eee, F4, KK2, in[0],  12);
    181	ROUND(eee, aaa, bbb, ccc, ddd, F4, KK2, in[13],  8);
    182	ROUND(ddd, eee, aaa, bbb, ccc, F4, KK2, in[5],   9);
    183	ROUND(ccc, ddd, eee, aaa, bbb, F4, KK2, in[10], 11);
    184	ROUND(bbb, ccc, ddd, eee, aaa, F4, KK2, in[14],  7);
    185	ROUND(aaa, bbb, ccc, ddd, eee, F4, KK2, in[15],  7);
    186	ROUND(eee, aaa, bbb, ccc, ddd, F4, KK2, in[8],  12);
    187	ROUND(ddd, eee, aaa, bbb, ccc, F4, KK2, in[12],  7);
    188	ROUND(ccc, ddd, eee, aaa, bbb, F4, KK2, in[4],   6);
    189	ROUND(bbb, ccc, ddd, eee, aaa, F4, KK2, in[9],  15);
    190	ROUND(aaa, bbb, ccc, ddd, eee, F4, KK2, in[1],  13);
    191	ROUND(eee, aaa, bbb, ccc, ddd, F4, KK2, in[2],  11);
    192
    193	/* round 3: right lane */
    194	ROUND(ddd, eee, aaa, bbb, ccc, F3, KK3, in[15],  9);
    195	ROUND(ccc, ddd, eee, aaa, bbb, F3, KK3, in[5],   7);
    196	ROUND(bbb, ccc, ddd, eee, aaa, F3, KK3, in[1],  15);
    197	ROUND(aaa, bbb, ccc, ddd, eee, F3, KK3, in[3],  11);
    198	ROUND(eee, aaa, bbb, ccc, ddd, F3, KK3, in[7],   8);
    199	ROUND(ddd, eee, aaa, bbb, ccc, F3, KK3, in[14],  6);
    200	ROUND(ccc, ddd, eee, aaa, bbb, F3, KK3, in[6],   6);
    201	ROUND(bbb, ccc, ddd, eee, aaa, F3, KK3, in[9],  14);
    202	ROUND(aaa, bbb, ccc, ddd, eee, F3, KK3, in[11], 12);
    203	ROUND(eee, aaa, bbb, ccc, ddd, F3, KK3, in[8],  13);
    204	ROUND(ddd, eee, aaa, bbb, ccc, F3, KK3, in[12],  5);
    205	ROUND(ccc, ddd, eee, aaa, bbb, F3, KK3, in[2],  14);
    206	ROUND(bbb, ccc, ddd, eee, aaa, F3, KK3, in[10], 13);
    207	ROUND(aaa, bbb, ccc, ddd, eee, F3, KK3, in[0],  13);
    208	ROUND(eee, aaa, bbb, ccc, ddd, F3, KK3, in[4],   7);
    209	ROUND(ddd, eee, aaa, bbb, ccc, F3, KK3, in[13],  5);
    210
    211	/* round 4: right lane */
    212	ROUND(ccc, ddd, eee, aaa, bbb, F2, KK4, in[8],  15);
    213	ROUND(bbb, ccc, ddd, eee, aaa, F2, KK4, in[6],   5);
    214	ROUND(aaa, bbb, ccc, ddd, eee, F2, KK4, in[4],   8);
    215	ROUND(eee, aaa, bbb, ccc, ddd, F2, KK4, in[1],  11);
    216	ROUND(ddd, eee, aaa, bbb, ccc, F2, KK4, in[3],  14);
    217	ROUND(ccc, ddd, eee, aaa, bbb, F2, KK4, in[11], 14);
    218	ROUND(bbb, ccc, ddd, eee, aaa, F2, KK4, in[15],  6);
    219	ROUND(aaa, bbb, ccc, ddd, eee, F2, KK4, in[0],  14);
    220	ROUND(eee, aaa, bbb, ccc, ddd, F2, KK4, in[5],   6);
    221	ROUND(ddd, eee, aaa, bbb, ccc, F2, KK4, in[12],  9);
    222	ROUND(ccc, ddd, eee, aaa, bbb, F2, KK4, in[2],  12);
    223	ROUND(bbb, ccc, ddd, eee, aaa, F2, KK4, in[13],  9);
    224	ROUND(aaa, bbb, ccc, ddd, eee, F2, KK4, in[9],  12);
    225	ROUND(eee, aaa, bbb, ccc, ddd, F2, KK4, in[7],   5);
    226	ROUND(ddd, eee, aaa, bbb, ccc, F2, KK4, in[10], 15);
    227	ROUND(ccc, ddd, eee, aaa, bbb, F2, KK4, in[14],  8);
    228
    229	/* round 5: right lane */
    230	ROUND(bbb, ccc, ddd, eee, aaa, F1, KK5, in[12],  8);
    231	ROUND(aaa, bbb, ccc, ddd, eee, F1, KK5, in[15],  5);
    232	ROUND(eee, aaa, bbb, ccc, ddd, F1, KK5, in[10], 12);
    233	ROUND(ddd, eee, aaa, bbb, ccc, F1, KK5, in[4],   9);
    234	ROUND(ccc, ddd, eee, aaa, bbb, F1, KK5, in[1],  12);
    235	ROUND(bbb, ccc, ddd, eee, aaa, F1, KK5, in[5],   5);
    236	ROUND(aaa, bbb, ccc, ddd, eee, F1, KK5, in[8],  14);
    237	ROUND(eee, aaa, bbb, ccc, ddd, F1, KK5, in[7],   6);
    238	ROUND(ddd, eee, aaa, bbb, ccc, F1, KK5, in[6],   8);
    239	ROUND(ccc, ddd, eee, aaa, bbb, F1, KK5, in[2],  13);
    240	ROUND(bbb, ccc, ddd, eee, aaa, F1, KK5, in[13],  6);
    241	ROUND(aaa, bbb, ccc, ddd, eee, F1, KK5, in[14],  5);
    242	ROUND(eee, aaa, bbb, ccc, ddd, F1, KK5, in[0],  15);
    243	ROUND(ddd, eee, aaa, bbb, ccc, F1, KK5, in[3],  13);
    244	ROUND(ccc, ddd, eee, aaa, bbb, F1, KK5, in[9],  11);
    245	ROUND(bbb, ccc, ddd, eee, aaa, F1, KK5, in[11], 11);
    246
    247	/* combine results */
    248	ddd += cc + state[1];		/* final result for state[0] */
    249	state[1] = state[2] + dd + eee;
    250	state[2] = state[3] + ee + aaa;
    251	state[3] = state[4] + aa + bbb;
    252	state[4] = state[0] + bb + ccc;
    253	state[0] = ddd;
    254}
    255
    256static int rmd160_init(struct shash_desc *desc)
    257{
    258	struct rmd160_ctx *rctx = shash_desc_ctx(desc);
    259
    260	rctx->byte_count = 0;
    261
    262	rctx->state[0] = RMD_H0;
    263	rctx->state[1] = RMD_H1;
    264	rctx->state[2] = RMD_H2;
    265	rctx->state[3] = RMD_H3;
    266	rctx->state[4] = RMD_H4;
    267
    268	memset(rctx->buffer, 0, sizeof(rctx->buffer));
    269
    270	return 0;
    271}
    272
    273static int rmd160_update(struct shash_desc *desc, const u8 *data,
    274			 unsigned int len)
    275{
    276	struct rmd160_ctx *rctx = shash_desc_ctx(desc);
    277	const u32 avail = sizeof(rctx->buffer) - (rctx->byte_count & 0x3f);
    278
    279	rctx->byte_count += len;
    280
    281	/* Enough space in buffer? If so copy and we're done */
    282	if (avail > len) {
    283		memcpy((char *)rctx->buffer + (sizeof(rctx->buffer) - avail),
    284		       data, len);
    285		goto out;
    286	}
    287
    288	memcpy((char *)rctx->buffer + (sizeof(rctx->buffer) - avail),
    289	       data, avail);
    290
    291	rmd160_transform(rctx->state, rctx->buffer);
    292	data += avail;
    293	len -= avail;
    294
    295	while (len >= sizeof(rctx->buffer)) {
    296		memcpy(rctx->buffer, data, sizeof(rctx->buffer));
    297		rmd160_transform(rctx->state, rctx->buffer);
    298		data += sizeof(rctx->buffer);
    299		len -= sizeof(rctx->buffer);
    300	}
    301
    302	memcpy(rctx->buffer, data, len);
    303
    304out:
    305	return 0;
    306}
    307
    308/* Add padding and return the message digest. */
    309static int rmd160_final(struct shash_desc *desc, u8 *out)
    310{
    311	struct rmd160_ctx *rctx = shash_desc_ctx(desc);
    312	u32 i, index, padlen;
    313	__le64 bits;
    314	__le32 *dst = (__le32 *)out;
    315	static const u8 padding[64] = { 0x80, };
    316
    317	bits = cpu_to_le64(rctx->byte_count << 3);
    318
    319	/* Pad out to 56 mod 64 */
    320	index = rctx->byte_count & 0x3f;
    321	padlen = (index < 56) ? (56 - index) : ((64+56) - index);
    322	rmd160_update(desc, padding, padlen);
    323
    324	/* Append length */
    325	rmd160_update(desc, (const u8 *)&bits, sizeof(bits));
    326
    327	/* Store state in digest */
    328	for (i = 0; i < 5; i++)
    329		dst[i] = cpu_to_le32p(&rctx->state[i]);
    330
    331	/* Wipe context */
    332	memset(rctx, 0, sizeof(*rctx));
    333
    334	return 0;
    335}
    336
    337static struct shash_alg alg = {
    338	.digestsize	=	RMD160_DIGEST_SIZE,
    339	.init		=	rmd160_init,
    340	.update		=	rmd160_update,
    341	.final		=	rmd160_final,
    342	.descsize	=	sizeof(struct rmd160_ctx),
    343	.base		=	{
    344		.cra_name	 =	"rmd160",
    345		.cra_driver_name =	"rmd160-generic",
    346		.cra_blocksize	 =	RMD160_BLOCK_SIZE,
    347		.cra_module	 =	THIS_MODULE,
    348	}
    349};
    350
    351static int __init rmd160_mod_init(void)
    352{
    353	return crypto_register_shash(&alg);
    354}
    355
    356static void __exit rmd160_mod_fini(void)
    357{
    358	crypto_unregister_shash(&alg);
    359}
    360
    361subsys_initcall(rmd160_mod_init);
    362module_exit(rmd160_mod_fini);
    363
    364MODULE_LICENSE("GPL");
    365MODULE_AUTHOR("Adrian-Ken Rueegsegger <ken@codelabs.ch>");
    366MODULE_DESCRIPTION("RIPEMD-160 Message Digest");
    367MODULE_ALIAS_CRYPTO("rmd160");