2007-07-09 11:56:42 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
async_tx: add the async_tx api
The async_tx api provides methods for describing a chain of asynchronous
bulk memory transfers/transforms with support for inter-transactional
dependencies. It is implemented as a dmaengine client that smooths over
the details of different hardware offload engine implementations. Code
that is written to the api can optimize for asynchronous operation and the
api will fit the chain of operations to the available offload resources.
I imagine that any piece of ADMA hardware would register with the
'async_*' subsystem, and a call to async_X would be routed as
appropriate, or be run in-line. - Neil Brown
async_tx exploits the capabilities of struct dma_async_tx_descriptor to
provide an api of the following general format:
struct dma_async_tx_descriptor *
async_<operation>(..., struct dma_async_tx_descriptor *depend_tx,
dma_async_tx_callback cb_fn, void *cb_param)
{
struct dma_chan *chan = async_tx_find_channel(depend_tx, <operation>);
struct dma_device *device = chan ? chan->device : NULL;
int int_en = cb_fn ? 1 : 0;
struct dma_async_tx_descriptor *tx = device ?
device->device_prep_dma_<operation>(chan, len, int_en) : NULL;
if (tx) { /* run <operation> asynchronously */
...
tx->tx_set_dest(addr, tx, index);
...
tx->tx_set_src(addr, tx, index);
...
async_tx_submit(chan, tx, flags, depend_tx, cb_fn, cb_param);
} else { /* run <operation> synchronously */
...
<operation>
...
async_tx_sync_epilog(flags, depend_tx, cb_fn, cb_param);
}
return tx;
}
async_tx_find_channel() returns a capable channel from its pool. The
channel pool is organized as a per-cpu array of channel pointers. The
async_tx_rebalance() routine is tasked with managing these arrays. In the
uniprocessor case async_tx_rebalance() tries to spread responsibility
evenly over channels of similar capabilities. For example if there are two
copy+xor channels, one will handle copy operations and the other will
handle xor. In the SMP case async_tx_rebalance() attempts to spread the
operations evenly over the cpus, e.g. cpu0 gets copy channel0 and xor
channel0 while cpu1 gets copy channel 1 and xor channel 1. When a
dependency is specified async_tx_find_channel defaults to keeping the
operation on the same channel. A xor->copy->xor chain will stay on one
channel if it supports both operation types, otherwise the transaction will
transition between a copy and a xor resource.
Currently the raid5 implementation in the MD raid456 driver has been
converted to the async_tx api. A driver for the offload engines on the
Intel Xscale series of I/O processors, iop-adma, is provided in a later
commit. With the iop-adma driver and async_tx, raid456 is able to offload
copy, xor, and xor-zero-sum operations to hardware engines.
On iop342 tiobench showed higher throughput for sequential writes (20 - 30%
improvement) and sequential reads to a degraded array (40 - 55%
improvement). For the other cases performance was roughly equal, +/- a few
percentage points. On a x86-smp platform the performance of the async_tx
implementation (in synchronous mode) was also +/- a few percentage points
of the original implementation. According to 'top' on iop342 CPU
utilization drops from ~50% to ~15% during a 'resync' while the speed
according to /proc/mdstat doubles from ~25 MB/s to ~50 MB/s.
The tiobench command line used for testing was: tiobench --size 2048
--block 4096 --block 131072 --dir /mnt/raid --numruns 5
* iop342 had 1GB of memory available
Details:
* if CONFIG_DMA_ENGINE=n the asynchronous path is compiled away by making
async_tx_find_channel a static inline routine that always returns NULL
* when a callback is specified for a given transaction an interrupt will
fire at operation completion time and the callback will occur in a
tasklet. if the the channel does not support interrupts then a live
polling wait will be performed
* the api is written as a dmaengine client that requests all available
channels
* In support of dependencies the api implicitly schedules channel-switch
interrupts. The interrupt triggers the cleanup tasklet which causes
pending operations to be scheduled on the next channel
* Xor engines treat an xor destination address differently than a software
xor routine. To the software routine the destination address is an implied
source, whereas engines treat it as a write-only destination. This patch
modifies the xor_blocks routine to take a an explicit destination address
to mirror the hardware.
Changelog:
* fixed a leftover debug print
* don't allow callbacks in async_interrupt_cond
* fixed xor_block changes
* fixed usage of ASYNC_TX_XOR_DROP_DEST
* drop dma mapping methods, suggested by Chris Leech
* printk warning fixups from Andrew Morton
* don't use inline in C files, Adrian Bunk
* select the API when MD is enabled
* BUG_ON xor source counts <= 1
* implicitly handle hardware concerns like channel switching and
interrupts, Neil Brown
* remove the per operation type list, and distribute operation capabilities
evenly amongst the available channels
* simplify async_tx_find_channel to optimize the fast path
* introduce the channel_table_initialized flag to prevent early calls to
the api
* reorganize the code to mimic crypto
* include mm.h as not all archs include it in dma-mapping.h
* make the Kconfig options non-user visible, Adrian Bunk
* move async_tx under crypto since it is meant as 'core' functionality, and
the two may share algorithms in the future
* move large inline functions into c files
* checkpatch.pl fixes
* gpl v2 only correction
Cc: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Dan Williams <dan.j.williams@intel.com>
Acked-By: NeilBrown <neilb@suse.de>
2007-01-02 11:10:44 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
async_tx: add the async_tx api
The async_tx api provides methods for describing a chain of asynchronous
bulk memory transfers/transforms with support for inter-transactional
dependencies. It is implemented as a dmaengine client that smooths over
the details of different hardware offload engine implementations. Code
that is written to the api can optimize for asynchronous operation and the
api will fit the chain of operations to the available offload resources.
I imagine that any piece of ADMA hardware would register with the
'async_*' subsystem, and a call to async_X would be routed as
appropriate, or be run in-line. - Neil Brown
async_tx exploits the capabilities of struct dma_async_tx_descriptor to
provide an api of the following general format:
struct dma_async_tx_descriptor *
async_<operation>(..., struct dma_async_tx_descriptor *depend_tx,
dma_async_tx_callback cb_fn, void *cb_param)
{
struct dma_chan *chan = async_tx_find_channel(depend_tx, <operation>);
struct dma_device *device = chan ? chan->device : NULL;
int int_en = cb_fn ? 1 : 0;
struct dma_async_tx_descriptor *tx = device ?
device->device_prep_dma_<operation>(chan, len, int_en) : NULL;
if (tx) { /* run <operation> asynchronously */
...
tx->tx_set_dest(addr, tx, index);
...
tx->tx_set_src(addr, tx, index);
...
async_tx_submit(chan, tx, flags, depend_tx, cb_fn, cb_param);
} else { /* run <operation> synchronously */
...
<operation>
...
async_tx_sync_epilog(flags, depend_tx, cb_fn, cb_param);
}
return tx;
}
async_tx_find_channel() returns a capable channel from its pool. The
channel pool is organized as a per-cpu array of channel pointers. The
async_tx_rebalance() routine is tasked with managing these arrays. In the
uniprocessor case async_tx_rebalance() tries to spread responsibility
evenly over channels of similar capabilities. For example if there are two
copy+xor channels, one will handle copy operations and the other will
handle xor. In the SMP case async_tx_rebalance() attempts to spread the
operations evenly over the cpus, e.g. cpu0 gets copy channel0 and xor
channel0 while cpu1 gets copy channel 1 and xor channel 1. When a
dependency is specified async_tx_find_channel defaults to keeping the
operation on the same channel. A xor->copy->xor chain will stay on one
channel if it supports both operation types, otherwise the transaction will
transition between a copy and a xor resource.
Currently the raid5 implementation in the MD raid456 driver has been
converted to the async_tx api. A driver for the offload engines on the
Intel Xscale series of I/O processors, iop-adma, is provided in a later
commit. With the iop-adma driver and async_tx, raid456 is able to offload
copy, xor, and xor-zero-sum operations to hardware engines.
On iop342 tiobench showed higher throughput for sequential writes (20 - 30%
improvement) and sequential reads to a degraded array (40 - 55%
improvement). For the other cases performance was roughly equal, +/- a few
percentage points. On a x86-smp platform the performance of the async_tx
implementation (in synchronous mode) was also +/- a few percentage points
of the original implementation. According to 'top' on iop342 CPU
utilization drops from ~50% to ~15% during a 'resync' while the speed
according to /proc/mdstat doubles from ~25 MB/s to ~50 MB/s.
The tiobench command line used for testing was: tiobench --size 2048
--block 4096 --block 131072 --dir /mnt/raid --numruns 5
* iop342 had 1GB of memory available
Details:
* if CONFIG_DMA_ENGINE=n the asynchronous path is compiled away by making
async_tx_find_channel a static inline routine that always returns NULL
* when a callback is specified for a given transaction an interrupt will
fire at operation completion time and the callback will occur in a
tasklet. if the the channel does not support interrupts then a live
polling wait will be performed
* the api is written as a dmaengine client that requests all available
channels
* In support of dependencies the api implicitly schedules channel-switch
interrupts. The interrupt triggers the cleanup tasklet which causes
pending operations to be scheduled on the next channel
* Xor engines treat an xor destination address differently than a software
xor routine. To the software routine the destination address is an implied
source, whereas engines treat it as a write-only destination. This patch
modifies the xor_blocks routine to take a an explicit destination address
to mirror the hardware.
Changelog:
* fixed a leftover debug print
* don't allow callbacks in async_interrupt_cond
* fixed xor_block changes
* fixed usage of ASYNC_TX_XOR_DROP_DEST
* drop dma mapping methods, suggested by Chris Leech
* printk warning fixups from Andrew Morton
* don't use inline in C files, Adrian Bunk
* select the API when MD is enabled
* BUG_ON xor source counts <= 1
* implicitly handle hardware concerns like channel switching and
interrupts, Neil Brown
* remove the per operation type list, and distribute operation capabilities
evenly amongst the available channels
* simplify async_tx_find_channel to optimize the fast path
* introduce the channel_table_initialized flag to prevent early calls to
the api
* reorganize the code to mimic crypto
* include mm.h as not all archs include it in dma-mapping.h
* make the Kconfig options non-user visible, Adrian Bunk
* move async_tx under crypto since it is meant as 'core' functionality, and
the two may share algorithms in the future
* move large inline functions into c files
* checkpatch.pl fixes
* gpl v2 only correction
Cc: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Dan Williams <dan.j.williams@intel.com>
Acked-By: NeilBrown <neilb@suse.de>
2007-01-02 11:10:44 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
async_tx: add the async_tx api
The async_tx api provides methods for describing a chain of asynchronous
bulk memory transfers/transforms with support for inter-transactional
dependencies. It is implemented as a dmaengine client that smooths over
the details of different hardware offload engine implementations. Code
that is written to the api can optimize for asynchronous operation and the
api will fit the chain of operations to the available offload resources.
I imagine that any piece of ADMA hardware would register with the
'async_*' subsystem, and a call to async_X would be routed as
appropriate, or be run in-line. - Neil Brown
async_tx exploits the capabilities of struct dma_async_tx_descriptor to
provide an api of the following general format:
struct dma_async_tx_descriptor *
async_<operation>(..., struct dma_async_tx_descriptor *depend_tx,
dma_async_tx_callback cb_fn, void *cb_param)
{
struct dma_chan *chan = async_tx_find_channel(depend_tx, <operation>);
struct dma_device *device = chan ? chan->device : NULL;
int int_en = cb_fn ? 1 : 0;
struct dma_async_tx_descriptor *tx = device ?
device->device_prep_dma_<operation>(chan, len, int_en) : NULL;
if (tx) { /* run <operation> asynchronously */
...
tx->tx_set_dest(addr, tx, index);
...
tx->tx_set_src(addr, tx, index);
...
async_tx_submit(chan, tx, flags, depend_tx, cb_fn, cb_param);
} else { /* run <operation> synchronously */
...
<operation>
...
async_tx_sync_epilog(flags, depend_tx, cb_fn, cb_param);
}
return tx;
}
async_tx_find_channel() returns a capable channel from its pool. The
channel pool is organized as a per-cpu array of channel pointers. The
async_tx_rebalance() routine is tasked with managing these arrays. In the
uniprocessor case async_tx_rebalance() tries to spread responsibility
evenly over channels of similar capabilities. For example if there are two
copy+xor channels, one will handle copy operations and the other will
handle xor. In the SMP case async_tx_rebalance() attempts to spread the
operations evenly over the cpus, e.g. cpu0 gets copy channel0 and xor
channel0 while cpu1 gets copy channel 1 and xor channel 1. When a
dependency is specified async_tx_find_channel defaults to keeping the
operation on the same channel. A xor->copy->xor chain will stay on one
channel if it supports both operation types, otherwise the transaction will
transition between a copy and a xor resource.
Currently the raid5 implementation in the MD raid456 driver has been
converted to the async_tx api. A driver for the offload engines on the
Intel Xscale series of I/O processors, iop-adma, is provided in a later
commit. With the iop-adma driver and async_tx, raid456 is able to offload
copy, xor, and xor-zero-sum operations to hardware engines.
On iop342 tiobench showed higher throughput for sequential writes (20 - 30%
improvement) and sequential reads to a degraded array (40 - 55%
improvement). For the other cases performance was roughly equal, +/- a few
percentage points. On a x86-smp platform the performance of the async_tx
implementation (in synchronous mode) was also +/- a few percentage points
of the original implementation. According to 'top' on iop342 CPU
utilization drops from ~50% to ~15% during a 'resync' while the speed
according to /proc/mdstat doubles from ~25 MB/s to ~50 MB/s.
The tiobench command line used for testing was: tiobench --size 2048
--block 4096 --block 131072 --dir /mnt/raid --numruns 5
* iop342 had 1GB of memory available
Details:
* if CONFIG_DMA_ENGINE=n the asynchronous path is compiled away by making
async_tx_find_channel a static inline routine that always returns NULL
* when a callback is specified for a given transaction an interrupt will
fire at operation completion time and the callback will occur in a
tasklet. if the the channel does not support interrupts then a live
polling wait will be performed
* the api is written as a dmaengine client that requests all available
channels
* In support of dependencies the api implicitly schedules channel-switch
interrupts. The interrupt triggers the cleanup tasklet which causes
pending operations to be scheduled on the next channel
* Xor engines treat an xor destination address differently than a software
xor routine. To the software routine the destination address is an implied
source, whereas engines treat it as a write-only destination. This patch
modifies the xor_blocks routine to take a an explicit destination address
to mirror the hardware.
Changelog:
* fixed a leftover debug print
* don't allow callbacks in async_interrupt_cond
* fixed xor_block changes
* fixed usage of ASYNC_TX_XOR_DROP_DEST
* drop dma mapping methods, suggested by Chris Leech
* printk warning fixups from Andrew Morton
* don't use inline in C files, Adrian Bunk
* select the API when MD is enabled
* BUG_ON xor source counts <= 1
* implicitly handle hardware concerns like channel switching and
interrupts, Neil Brown
* remove the per operation type list, and distribute operation capabilities
evenly amongst the available channels
* simplify async_tx_find_channel to optimize the fast path
* introduce the channel_table_initialized flag to prevent early calls to
the api
* reorganize the code to mimic crypto
* include mm.h as not all archs include it in dma-mapping.h
* make the Kconfig options non-user visible, Adrian Bunk
* move async_tx under crypto since it is meant as 'core' functionality, and
the two may share algorithms in the future
* move large inline functions into c files
* checkpatch.pl fixes
* gpl v2 only correction
Cc: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Dan Williams <dan.j.williams@intel.com>
Acked-By: NeilBrown <neilb@suse.de>
2007-01-02 11:10:44 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-05-18 15:11:01 +10:00
|
|
|
|
2008-03-30 16:36:09 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-08-05 14:13:08 +08:00
|
|
|
|
|
|
|
|
|
2014-07-04 22:15:08 +08:00
|
|
|
|
2014-07-02 15:37:30 -04:00
|
|
|
|
2008-08-05 14:13:08 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-09-03 19:17:49 +08:00
|
|
|
|
2008-08-05 14:13:08 +08:00
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-08-30 15:36:14 +08:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
2007-08-30 15:36:14 +08:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-08-22 00:07:53 +10:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
2006-08-22 00:07:53 +10:00
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-02-19 14:44:02 +08:00
|
|
|
|
2006-08-22 00:07:53 +10:00
|
|
|
|
2006-08-19 22:24:23 +10:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
2006-08-19 22:24:23 +10:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-08-14 22:15:52 +10:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
2008-08-14 22:15:52 +10:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
crypto: compress - Add pcomp interface
The current "comp" crypto interface supports one-shot (de)compression only,
i.e. the whole data buffer to be (de)compressed must be passed at once, and
the whole (de)compressed data buffer will be received at once.
In several use-cases (e.g. compressed file systems that store files in big
compressed blocks), this workflow is not suitable.
Furthermore, the "comp" type doesn't provide for the configuration of
(de)compression parameters, and always allocates workspace memory for both
compression and decompression, which may waste memory.
To solve this, add a "pcomp" partial (de)compression interface that provides
the following operations:
- crypto_compress_{init,update,final}() for compression,
- crypto_decompress_{init,update,final}() for decompression,
- crypto_{,de}compress_setup(), to configure (de)compression parameters
(incl. allocating workspace memory).
The (de)compression methods take a struct comp_request, which was mimicked
after the z_stream object in zlib, and contains buffer pointer and length
pairs for input and output.
The setup methods take an opaque parameter pointer and length pair. Parameters
are supposed to be encoded using netlink attributes, whose meanings depend on
the actual (name of the) (de)compression algorithm.
Signed-off-by: Geert Uytterhoeven <Geert.Uytterhoeven@sonycom.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2009-03-04 15:05:33 +08:00
|
|
|
|
2010-06-03 20:33:06 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
crypto: compress - Add pcomp interface
The current "comp" crypto interface supports one-shot (de)compression only,
i.e. the whole data buffer to be (de)compressed must be passed at once, and
the whole (de)compressed data buffer will be received at once.
In several use-cases (e.g. compressed file systems that store files in big
compressed blocks), this workflow is not suitable.
Furthermore, the "comp" type doesn't provide for the configuration of
(de)compression parameters, and always allocates workspace memory for both
compression and decompression, which may waste memory.
To solve this, add a "pcomp" partial (de)compression interface that provides
the following operations:
- crypto_compress_{init,update,final}() for compression,
- crypto_decompress_{init,update,final}() for decompression,
- crypto_{,de}compress_setup(), to configure (de)compression parameters
(incl. allocating workspace memory).
The (de)compression methods take a struct comp_request, which was mimicked
after the z_stream object in zlib, and contains buffer pointer and length
pairs for input and output.
The setup methods take an opaque parameter pointer and length pair. Parameters
are supposed to be encoded using netlink attributes, whose meanings depend on
the actual (name of the) (de)compression algorithm.
Signed-off-by: Geert Uytterhoeven <Geert.Uytterhoeven@sonycom.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2009-03-04 15:05:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-09-21 11:31:44 +10:00
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
2006-09-21 11:31:44 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-06-03 20:33:06 +10:00
|
|
|
|
2008-12-10 23:29:44 +11:00
|
|
|
|
2011-09-27 07:23:50 +02:00
|
|
|
|
|
|
|
|
|
2011-11-01 12:12:43 +11:00
|
|
|
|
2011-09-27 07:23:50 +02:00
|
|
|
|
|
|
|
|
|
2011-11-09 01:29:20 -05:00
|
|
|
|
2011-09-27 07:23:50 +02:00
|
|
|
|
|
|
|
|
|
2010-08-06 09:40:28 +08:00
|
|
|
|
|
|
|
|
|
2010-08-06 10:34:00 +08:00
|
|
|
|
|
|
|
|
|
2010-06-03 20:53:43 +10:00
|
|
|
|
2010-08-06 09:40:28 +08:00
|
|
|
|
|
|
|
|
|
2010-06-03 20:53:43 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2011-12-13 12:53:22 +02:00
|
|
|
|
2006-10-28 13:15:24 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-10-28 13:15:24 +10:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2008-02-18 09:00:05 +08:00
|
|
|
|
2008-11-08 08:09:56 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-01-07 15:57:19 +11:00
|
|
|
|
2012-10-02 11:16:49 -07:00
|
|
|
|
|
|
|
|
|
2010-01-07 15:57:19 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-02-19 14:33:40 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-05-14 21:23:00 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2009-02-19 14:42:19 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2014-07-31 10:29:51 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-09-04 15:18:21 +08:00
|
|
|
|
2014-07-31 10:29:51 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-07-31 17:08:25 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-09-20 09:55:40 +02:00
|
|
|
|
2012-06-18 14:06:58 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-06-18 14:07:19 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2007-11-10 20:08:25 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-08-06 15:34:26 +10:00
|
|
|
|
2013-04-07 16:43:41 +03:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-08-14 22:21:31 +10:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-11-29 18:59:44 +11:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-09-21 11:44:08 +10:00
|
|
|
|
2006-10-16 21:28:58 +10:00
|
|
|
|
2006-09-21 11:44:08 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-09-21 11:44:08 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-09-21 11:44:08 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-10-16 21:28:58 +10:00
|
|
|
|
2006-09-21 11:44:08 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-09-21 11:44:08 +10:00
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-12-16 12:09:02 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-12-16 12:09:02 +11:00
|
|
|
|
2006-11-26 09:43:10 +11:00
|
|
|
|
2011-12-13 12:52:51 +02:00
|
|
|
|
2006-11-26 09:43:10 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-09-19 20:23:13 +08:00
|
|
|
|
2011-12-13 12:52:56 +02:00
|
|
|
|
2007-09-19 20:23:13 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2013-04-08 10:48:44 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
[CRYPTO] ctr: Add CTR (Counter) block cipher mode
This patch implements CTR mode for IPsec.
It is based off of RFC 3686.
Please note:
1. CTR turns a block cipher into a stream cipher.
Encryption is done in blocks, however the last block
may be a partial block.
A "counter block" is encrypted, creating a keystream
that is xor'ed with the plaintext. The counter portion
of the counter block is incremented after each block
of plaintext is encrypted.
Decryption is performed in same manner.
2. The CTR counterblock is composed of,
nonce + IV + counter
The size of the counterblock is equivalent to the
blocksize of the cipher.
sizeof(nonce) + sizeof(IV) + sizeof(counter) = blocksize
The CTR template requires the name of the cipher
algorithm, the sizeof the nonce, and the sizeof the iv.
ctr(cipher,sizeof_nonce,sizeof_iv)
So for example,
ctr(aes,4,8)
specifies the counterblock will be composed of 4 bytes
from a nonce, 8 bytes from the iv, and 4 bytes for counter
since aes has a blocksize of 16 bytes.
3. The counter portion of the counter block is stored
in big endian for conformance to rfc 3686.
Signed-off-by: Joy Latten <latten@austin.ibm.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2007-10-23 08:50:32 +08:00
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
[CRYPTO] ctr: Add CTR (Counter) block cipher mode
This patch implements CTR mode for IPsec.
It is based off of RFC 3686.
Please note:
1. CTR turns a block cipher into a stream cipher.
Encryption is done in blocks, however the last block
may be a partial block.
A "counter block" is encrypted, creating a keystream
that is xor'ed with the plaintext. The counter portion
of the counter block is incremented after each block
of plaintext is encrypted.
Decryption is performed in same manner.
2. The CTR counterblock is composed of,
nonce + IV + counter
The size of the counterblock is equivalent to the
blocksize of the cipher.
sizeof(nonce) + sizeof(IV) + sizeof(counter) = blocksize
The CTR template requires the name of the cipher
algorithm, the sizeof the nonce, and the sizeof the iv.
ctr(cipher,sizeof_nonce,sizeof_iv)
So for example,
ctr(aes,4,8)
specifies the counterblock will be composed of 4 bytes
from a nonce, 8 bytes from the iv, and 4 bytes for counter
since aes has a blocksize of 16 bytes.
3. The counter portion of the counter block is stored
in big endian for conformance to rfc 3686.
Signed-off-by: Joy Latten <latten@austin.ibm.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2007-10-23 08:50:32 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-03-24 21:26:16 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-03-24 21:26:16 +08:00
|
|
|
|
2009-09-02 20:05:22 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2007-11-26 22:24:11 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-07-08 20:54:28 +08:00
|
|
|
|
2012-03-23 15:02:25 -07:00
|
|
|
|
2007-12-12 20:25:13 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-11-07 15:11:47 +08:00
|
|
|
|
2007-12-12 20:25:13 +08:00
|
|
|
|
2008-08-07 09:57:03 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-08-22 20:47:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-01-10 18:54:59 +04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-07 12:56:26 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-08-06 15:32:38 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-12-03 19:55:27 +08:00
|
|
|
|
2007-04-16 20:49:20 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2007-04-16 20:49:20 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-12-03 19:57:12 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2014-12-21 22:54:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-08-19 21:51:26 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-12-07 19:35:38 +08:00
|
|
|
|
2006-12-16 12:13:14 +11:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-12-16 12:13:14 +11:00
|
|
|
|
2008-05-07 22:17:37 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2008-11-08 09:10:40 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
|
|
|
|
|
2008-05-07 22:17:37 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2011-07-09 04:02:31 +00:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2008-05-07 22:17:37 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2010-09-12 10:42:47 +08:00
|
|
|
|
2008-05-07 22:17:37 +08:00
|
|
|
|
|
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2008-11-08 09:18:51 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
|
|
|
|
|
2008-05-07 22:17:37 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-05-07 22:17:37 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
|
|
|
|
|
2008-05-09 21:30:27 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2010-09-12 10:42:47 +08:00
|
|
|
|
2008-05-09 21:30:27 +08:00
|
|
|
|
|
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2008-11-08 09:58:10 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-05-09 21:30:27 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2010-09-12 10:42:47 +08:00
|
|
|
|
2008-05-09 21:30:27 +08:00
|
|
|
|
|
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2008-11-08 10:11:09 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-05-09 21:30:27 +08:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
2010-09-12 10:42:47 +08:00
|
|
|
|
2008-05-07 22:17:37 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-12-02 21:08:20 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2011-08-04 20:19:25 +02:00
|
|
|
|
2014-03-20 15:14:00 -07:00
|
|
|
|
2011-08-04 20:19:25 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-03-20 15:14:00 -07:00
|
|
|
|
2011-08-04 20:19:25 +02:00
|
|
|
|
2013-03-26 13:59:17 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-26 14:00:02 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-26 13:59:17 -07:00
|
|
|
|
|
|
|
|
|
2012-08-19 15:41:53 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-09-07 04:17:02 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-29 17:14:14 +01:00
|
|
|
|
|
|
|
|
|
2014-08-05 21:15:19 +01:00
|
|
|
|
2014-07-29 17:14:14 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-09-13 23:00:49 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-31 10:29:51 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-12-03 19:57:49 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-06-20 20:37:23 +10:00
|
|
|
|
2008-07-16 19:28:00 +08:00
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2012-08-19 17:11:37 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-12-17 16:49:02 +11:00
|
|
|
|
2006-06-20 20:59:16 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-06-20 20:59:16 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-06-20 20:59:16 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-06-20 20:59:16 +10:00
|
|
|
|
2012-08-19 17:37:56 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-29 17:15:24 +01:00
|
|
|
|
|
|
|
|
|
2014-08-05 21:17:14 +01:00
|
|
|
|
2014-07-29 17:15:24 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-12-03 19:58:32 +08:00
|
|
|
|
2006-06-20 21:12:02 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-06-20 21:12:02 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-06-20 21:12:02 +10:00
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-06-20 21:12:02 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2008-12-07 19:34:37 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2010-09-12 10:42:47 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2009-10-19 11:53:06 +09:00
|
|
|
|
|
|
|
|
|
2011-06-08 20:56:29 +08:00
|
|
|
|
2009-10-19 11:53:06 +09:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
|
|
|
|
|
2007-11-10 19:07:16 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-07-06 13:55:00 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
|
|
|
|
|
2007-11-08 21:25:04 +08:00
|
|
|
|
2005-07-06 13:55:00 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-07-06 13:55:00 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-01-18 16:28:34 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-06-08 20:56:29 +08:00
|
|
|
|
crypto: aesni-intel - Ported implementation to x86-32
The AES-NI instructions are also available in legacy mode so the 32-bit
architecture may profit from those, too.
To illustrate the performance gain here's a short summary of a dm-crypt
speed test on a Core i7 M620 running at 2.67GHz comparing both assembler
implementations:
x86: i568 aes-ni delta
ECB, 256 bit: 93.8 MB/s 123.3 MB/s +31.4%
CBC, 256 bit: 84.8 MB/s 262.3 MB/s +209.3%
LRW, 256 bit: 108.6 MB/s 222.1 MB/s +104.5%
XTS, 256 bit: 105.0 MB/s 205.5 MB/s +95.7%
Additionally, due to some minor optimizations, the 64-bit version also
got a minor performance gain as seen below:
x86-64: old impl. new impl. delta
ECB, 256 bit: 121.1 MB/s 123.0 MB/s +1.5%
CBC, 256 bit: 285.3 MB/s 290.8 MB/s +1.9%
LRW, 256 bit: 263.7 MB/s 265.3 MB/s +0.6%
XTS, 256 bit: 251.1 MB/s 255.3 MB/s +1.7%
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Reviewed-by: Huang Ying <ying.huang@intel.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2010-11-27 16:34:46 +08:00
|
|
|
|
|
|
|
|
|
2009-01-18 16:28:34 +11:00
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2009-01-18 16:28:34 +11:00
|
|
|
|
2013-04-10 18:39:20 +03:00
|
|
|
|
2012-07-22 18:18:37 +03:00
|
|
|
|
|
|
|
|
|
2009-01-18 16:28:34 +11:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-07-06 13:55:00 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
crypto: aesni-intel - Ported implementation to x86-32
The AES-NI instructions are also available in legacy mode so the 32-bit
architecture may profit from those, too.
To illustrate the performance gain here's a short summary of a dm-crypt
speed test on a Core i7 M620 running at 2.67GHz comparing both assembler
implementations:
x86: i568 aes-ni delta
ECB, 256 bit: 93.8 MB/s 123.3 MB/s +31.4%
CBC, 256 bit: 84.8 MB/s 262.3 MB/s +209.3%
LRW, 256 bit: 108.6 MB/s 222.1 MB/s +104.5%
XTS, 256 bit: 105.0 MB/s 205.5 MB/s +95.7%
Additionally, due to some minor optimizations, the 64-bit version also
got a minor performance gain as seen below:
x86-64: old impl. new impl. delta
ECB, 256 bit: 121.1 MB/s 123.0 MB/s +1.5%
CBC, 256 bit: 285.3 MB/s 290.8 MB/s +1.9%
LRW, 256 bit: 263.7 MB/s 265.3 MB/s +0.6%
XTS, 256 bit: 251.1 MB/s 255.3 MB/s +1.7%
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Reviewed-by: Huang Ying <ying.huang@intel.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2010-11-27 16:34:46 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-03-29 15:41:20 +08:00
|
|
|
|
2012-08-21 03:58:13 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-09-07 04:17:02 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
ARM: add support for bit sliced AES using NEON instructions
Bit sliced AES gives around 45% speedup on Cortex-A15 for encryption
and around 25% for decryption. This implementation of the AES algorithm
does not rely on any lookup tables so it is believed to be invulnerable
to cache timing attacks.
This algorithm processes up to 8 blocks in parallel in constant time. This
means that it is not usable by chaining modes that are strictly sequential
in nature, such as CBC encryption. CBC decryption, however, can benefit from
this implementation and runs about 25% faster. The other chaining modes
implemented in this module, XTS and CTR, can execute fully in parallel in
both directions.
The core code has been adopted from the OpenSSL project (in collaboration
with the original author, on cc). For ease of maintenance, this version is
identical to the upstream OpenSSL code, i.e., all modifications that were
required to make it suitable for inclusion into the kernel have been made
upstream. The original can be found here:
http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=6f6a6130
Note to integrators:
While this implementation is significantly faster than the existing table
based ones (generic or ARM asm), especially in CTR mode, the effects on
power efficiency are unclear as of yet. This code does fundamentally more
work, by calculating values that the table based code obtains by a simple
lookup; only by doing all of that work in a SIMD fashion, it manages to
perform better.
Cc: Andy Polyakov <appro@openssl.org>
Acked-by: Nicolas Pitre <nico@linaro.org>
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
2013-09-16 18:31:38 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-09-12 10:42:47 +08:00
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-06-26 18:13:46 +02:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-09-02 01:45:07 +03:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-09-02 01:45:07 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-09-02 01:45:22 +03:00
|
|
|
|
|
|
|
|
|
2012-04-08 20:31:22 -04:00
|
|
|
|
2011-09-02 01:45:22 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-03-05 20:26:47 +02:00
|
|
|
|
|
|
|
|
|
2012-04-08 20:31:22 -04:00
|
|
|
|
2012-03-05 20:26:47 +02:00
|
|
|
|
|
|
|
|
|
2012-06-18 14:07:29 +03:00
|
|
|
|
2012-03-05 20:26:47 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-26 14:49:01 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2012-10-26 14:49:01 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-03-05 20:26:47 +02:00
|
|
|
|
|
|
|
|
|
2013-04-13 13:47:00 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2013-04-13 13:47:00 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-08-28 12:05:54 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-13 11:43:14 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2012-11-13 11:43:14 +02:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-07-11 19:37:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2012-11-13 11:43:14 +02:00
|
|
|
|
2012-07-11 19:37:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2012-11-13 11:43:14 +02:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-07-11 19:38:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2012-07-11 19:38:57 +02:00
|
|
|
|
2012-11-13 11:43:14 +02:00
|
|
|
|
2012-07-11 19:38:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-09-01 17:42:46 -07:00
|
|
|
|
2012-08-25 22:37:23 -07:00
|
|
|
|
|
|
|
|
|
2012-10-02 17:13:20 -04:00
|
|
|
|
2012-08-25 22:37:23 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-06-09 20:59:54 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-09-12 10:42:47 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2007-11-23 19:45:00 +08:00
|
|
|
|
2012-10-02 11:16:49 -07:00
|
|
|
|
2007-11-23 19:45:00 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-12-10 15:52:56 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-02 11:16:49 -07:00
|
|
|
|
2007-12-10 15:52:56 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-12-18 00:04:40 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-02 11:16:49 -07:00
|
|
|
|
2007-12-18 00:04:40 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-11-23 19:45:00 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-11-09 16:26:25 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-11-24 08:37:41 +02:00
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2012-06-18 14:07:19 +03:00
|
|
|
|
2011-11-09 16:26:25 +02:00
|
|
|
|
2011-12-13 12:53:12 +02:00
|
|
|
|
|
|
|
|
|
2011-11-09 16:26:25 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-11-09 16:26:31 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-11-24 08:37:41 +02:00
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2012-06-18 14:07:19 +03:00
|
|
|
|
2011-11-09 16:26:31 +02:00
|
|
|
|
2011-12-13 12:53:12 +02:00
|
|
|
|
|
|
|
|
|
2011-11-09 16:26:31 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-06-12 16:47:43 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2012-06-18 14:07:24 +03:00
|
|
|
|
2012-06-12 16:47:43 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-11-09 16:26:31 +02:00
|
|
|
|
2013-04-13 13:46:55 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2013-04-13 13:46:55 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-10-22 14:49:17 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-10-22 14:49:17 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-10-22 14:49:17 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-10-22 14:49:17 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-10-22 14:49:17 +10:00
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2006-10-22 14:49:17 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-09-26 16:47:25 +03:00
|
|
|
|
|
|
|
|
|
2012-04-08 20:31:22 -04:00
|
|
|
|
2011-09-26 16:47:25 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-06-18 14:07:34 +03:00
|
|
|
|
2011-12-13 12:53:01 +02:00
|
|
|
|
|
|
|
|
|
2011-09-26 16:47:25 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-05-28 15:54:24 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-20 09:55:41 +02:00
|
|
|
|
2012-06-18 14:07:39 +03:00
|
|
|
|
2012-05-28 15:54:24 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
[CRYPTO] aead: Add authenc
This patch adds the authenc algorithm which constructs an AEAD algorithm
from an asynchronous block cipher and a hash. The construction is done
by concatenating the encrypted result from the cipher with the output
from the hash, as is used by the IPsec ESP protocol.
The authenc algorithm exists as a template with four parameters:
authenc(auth, authsize, enc, enckeylen).
The authentication algorithm, the authentication size (i.e., truncating
the output of the authentication algorithm), the encryption algorithm,
and the encryption key length. Both the size field and the key length
field are in bytes. For example, AES-128 with SHA1-HMAC would be
represented by
authenc(hmac(sha1), 12, cbc(aes), 16)
The key for the authenc algorithm is the concatenation of the keys for
the authentication algorithm with the encryption algorithm. For the
above example, if a key of length 36 bytes is given, then hmac(sha1)
would receive the first 20 bytes while the last 16 would be given to
cbc(aes).
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2007-08-30 16:24:15 +08:00
|
|
|
|
2008-04-05 21:04:48 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
[CRYPTO] aead: Add authenc
This patch adds the authenc algorithm which constructs an AEAD algorithm
from an asynchronous block cipher and a hash. The construction is done
by concatenating the encrypted result from the cipher with the output
from the hash, as is used by the IPsec ESP protocol.
The authenc algorithm exists as a template with four parameters:
authenc(auth, authsize, enc, enckeylen).
The authentication algorithm, the authentication size (i.e., truncating
the output of the authentication algorithm), the encryption algorithm,
and the encryption key length. Both the size field and the key length
field are in bytes. For example, AES-128 with SHA1-HMAC would be
represented by
authenc(hmac(sha1), 12, cbc(aes), 16)
The key for the authenc algorithm is the concatenation of the keys for
the authentication algorithm with the encryption algorithm. For the
above example, if a key of length 36 bytes is given, then hmac(sha1)
would receive the first 20 bytes while the last 16 would be given to
cbc(aes).
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2007-08-30 16:24:15 +08:00
|
|
|
|
2009-03-04 15:15:49 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-12-07 16:53:23 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-07-19 09:42:41 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-07-08 16:01:51 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-07-19 09:42:41 -05:00
|
|
|
|
2008-08-14 22:15:52 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-08-20 17:54:16 +10:00
|
|
|
|
2008-08-14 22:15:52 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-01-27 01:00:10 +01:00
|
|
|
|
|
|
|
|
|
2008-08-14 22:15:52 +10:00
|
|
|
|
2014-07-04 22:15:08 +08:00
|
|
|
|
2014-05-31 17:22:31 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-04 22:15:08 +08:00
|
|
|
|
2014-05-31 17:22:31 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-04 22:15:08 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-05-31 17:22:31 +02:00
|
|
|
|
2010-10-19 21:12:39 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-10-19 21:23:00 +08:00
|
|
|
|
|
|
|
|
|
2010-11-29 22:56:03 +08:00
|
|
|
|
2010-10-19 21:23:00 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-10-19 21:31:55 +08:00
|
|
|
|
|
|
|
|
|
2010-11-29 22:56:03 +08:00
|
|
|
|
2010-10-19 21:31:55 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-12-25 23:00:39 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-06 15:40:01 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2012-09-13 15:17:21 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2006-08-21 21:08:13 +10:00
|
|
|
|