diff options
author | Michael Brown | 2009-02-19 02:48:52 +0100 |
---|---|---|
committer | Michael Brown | 2009-02-19 02:53:25 +0100 |
commit | 9937bf13c961bb452e3e41a8fb28694af2b73c46 (patch) | |
tree | a1a168d7dd04f749a35b28e5a2851c82d12c1d47 /src/crypto | |
parent | [crypto] Add our own general-purpose cipher-block chaining routines (diff) | |
download | ipxe-9937bf13c961bb452e3e41a8fb28694af2b73c46.tar.gz ipxe-9937bf13c961bb452e3e41a8fb28694af2b73c46.tar.xz ipxe-9937bf13c961bb452e3e41a8fb28694af2b73c46.zip |
[crypto] Allow creation of arbitrary CBC cipher algorithms using CBC_CIPHER()
Given any block cipher, a corresponding CBC mode of behaviour for the
cipher can be created using the CBC_CIPHER() macro.
Diffstat (limited to 'src/crypto')
-rw-r--r-- | src/crypto/axtls_aes.c | 92 | ||||
-rw-r--r-- | src/crypto/cbc.c | 16 |
2 files changed, 10 insertions, 98 deletions
diff --git a/src/crypto/axtls_aes.c b/src/crypto/axtls_aes.c index 04d274d3..51e1924e 100644 --- a/src/crypto/axtls_aes.c +++ b/src/crypto/axtls_aes.c @@ -33,13 +33,6 @@ /** Basic AES blocksize */ #define AES_BLOCKSIZE 16 -/**************************************************************************** - * - * Basic AES algorithm (independent of mode of operation) - * - **************************************************************************** - */ - /** AES context */ struct aes_context { /** AES context for AXTLS */ @@ -169,87 +162,6 @@ static struct cipher_algorithm aes_algorithm = { .decrypt = aes_decrypt, }; -/**************************************************************************** - * - * AES with cipher-block chaining (CBC) - * - **************************************************************************** - */ - -/** AES with CBC context */ -struct aes_cbc_context { - /** AES context */ - struct aes_context aes_ctx; - /** CBC context */ - uint8_t cbc_ctx[AES_BLOCKSIZE]; -}; - -/** - * Set key - * - * @v ctx Context - * @v key Key - * @v keylen Key length - * @ret rc Return status code - */ -static int aes_cbc_setkey ( void *ctx, const void *key, size_t keylen ) { - struct aes_cbc_context *aes_cbc_ctx = ctx; - - return cbc_setkey ( ctx, key, keylen, &aes_algorithm, - &aes_cbc_ctx->cbc_ctx ); -} - -/** - * Set initialisation vector - * - * @v ctx Context - * @v iv Initialisation vector - */ -static void aes_cbc_setiv ( void *ctx, const void *iv ) { - struct aes_cbc_context *aes_cbc_ctx = ctx; - - cbc_setiv ( ctx, iv, &aes_algorithm, &aes_cbc_ctx->cbc_ctx ); -} - -/** - * Encrypt data - * - * @v ctx Context - * @v src Data to encrypt - * @v dst Buffer for encrypted data - * @v len Length of data - */ -static void aes_cbc_encrypt ( void *ctx, const void *src, void *dst, - size_t len ) { - struct aes_cbc_context *aes_cbc_ctx = ctx; - - cbc_encrypt ( &aes_cbc_ctx->aes_ctx, src, dst, len, - &aes_algorithm, &aes_cbc_ctx->cbc_ctx ); -} - -/** - * Decrypt data - * - * @v ctx Context - * @v src Data to decrypt - * @v dst Buffer for decrypted data - * @v len Length of data - */ -static void aes_cbc_decrypt ( void *ctx, const void *src, void *dst, - size_t len ) { - struct aes_cbc_context *aes_cbc_ctx = ctx; - - cbc_decrypt ( &aes_cbc_ctx->aes_ctx, src, dst, len, - &aes_algorithm, &aes_cbc_ctx->cbc_ctx ); -} - /* AES with cipher-block chaining */ -struct cipher_algorithm aes_cbc_algorithm = { - .name = "aes_cbc", - .ctxsize = sizeof ( struct aes_cbc_context ), - .blocksize = AES_BLOCKSIZE, - .setkey = aes_cbc_setkey, - .setiv = aes_cbc_setiv, - .encrypt = aes_cbc_encrypt, - .decrypt = aes_cbc_decrypt, -}; +CBC_CIPHER ( aes_cbc, aes_cbc_algorithm, + aes_algorithm, struct aes_context, AES_BLOCKSIZE ); diff --git a/src/crypto/cbc.c b/src/crypto/cbc.c index a25d826e..c7116ea9 100644 --- a/src/crypto/cbc.c +++ b/src/crypto/cbc.c @@ -53,18 +53,18 @@ static void cbc_xor ( const void *src, void *dst, size_t len ) { * @v src Data to encrypt * @v dst Buffer for encrypted data * @v len Length of data - * @v cipher Underlying cipher algorithm + * @v raw_cipher Underlying cipher algorithm * @v cbc_ctx CBC context */ void cbc_encrypt ( void *ctx, const void *src, void *dst, size_t len, - struct cipher_algorithm *cipher, void *cbc_ctx ) { - size_t blocksize = cipher->blocksize; + struct cipher_algorithm *raw_cipher, void *cbc_ctx ) { + size_t blocksize = raw_cipher->blocksize; assert ( ( len % blocksize ) == 0 ); while ( len ) { cbc_xor ( src, cbc_ctx, blocksize ); - cipher_encrypt ( cipher, ctx, cbc_ctx, dst, blocksize ); + cipher_encrypt ( raw_cipher, ctx, cbc_ctx, dst, blocksize ); memcpy ( cbc_ctx, dst, blocksize ); dst += blocksize; src += blocksize; @@ -79,17 +79,17 @@ void cbc_encrypt ( void *ctx, const void *src, void *dst, size_t len, * @v src Data to decrypt * @v dst Buffer for decrypted data * @v len Length of data - * @v cipher Underlying cipher algorithm + * @v raw_cipher Underlying cipher algorithm * @v cbc_ctx CBC context */ void cbc_decrypt ( void *ctx, const void *src, void *dst, size_t len, - struct cipher_algorithm *cipher, void *cbc_ctx ) { - size_t blocksize = cipher->blocksize; + struct cipher_algorithm *raw_cipher, void *cbc_ctx ) { + size_t blocksize = raw_cipher->blocksize; assert ( ( len % blocksize ) == 0 ); while ( len ) { - cipher_decrypt ( cipher, ctx, src, dst, blocksize ); + cipher_decrypt ( raw_cipher, ctx, src, dst, blocksize ); cbc_xor ( cbc_ctx, dst, blocksize ); memcpy ( cbc_ctx, src, blocksize ); dst += blocksize; |