blob: bec19da2c3f979846ba5da63317d7cab5e8c9872 [file] [log] [blame]
Harrison Mutaib6748092025-04-25 16:03:03 +00001/*
2 * Copyright (c) 2015-2023, Arm Limited and Contributors. All rights reserved.
3 *
4 * SPDX-License-Identifier: BSD-3-Clause
5 */
6
7#ifndef CRYPTO_MOD_H
8#define CRYPTO_MOD_H
9
10#define CRYPTO_AUTH_VERIFY_ONLY 1
11#define CRYPTO_HASH_CALC_ONLY 2
12#define CRYPTO_AUTH_VERIFY_AND_HASH_CALC 3
13
14/* Return values */
15enum crypto_ret_value {
16 CRYPTO_SUCCESS = 0,
17 CRYPTO_ERR_INIT,
18 CRYPTO_ERR_HASH,
19 CRYPTO_ERR_SIGNATURE,
20 CRYPTO_ERR_DECRYPTION,
21 CRYPTO_ERR_UNKNOWN
22};
23
24#define CRYPTO_MAX_IV_SIZE 16U
25#define CRYPTO_MAX_TAG_SIZE 16U
26
27/* Decryption algorithm */
28enum crypto_dec_algo {
29 CRYPTO_GCM_DECRYPT = 0
30};
31
32/* Message digest algorithm */
33enum crypto_md_algo {
34 CRYPTO_MD_SHA256,
35 CRYPTO_MD_SHA384,
36 CRYPTO_MD_SHA512,
37};
38
39/* Maximum size as per the known stronger hash algorithm i.e.SHA512 */
40#define CRYPTO_MD_MAX_SIZE 64U
41
42/*
43 * Cryptographic library descriptor
44 */
45typedef struct crypto_lib_desc_s {
46 const char *name;
47
48 /* Initialize library. This function is not expected to fail. All errors
49 * must be handled inside the function, asserting or panicking in case of
50 * a non-recoverable error */
51 void (*init)(void);
52
53 /* Verify a digital signature. Return one of the
54 * 'enum crypto_ret_value' options */
55 int (*verify_signature)(void *data_ptr, unsigned int data_len,
56 void *sig_ptr, unsigned int sig_len,
57 void *sig_alg, unsigned int sig_alg_len,
58 void *pk_ptr, unsigned int pk_len);
59
60 /* Verify a hash. Return one of the 'enum crypto_ret_value' options */
61 int (*verify_hash)(void *data_ptr, unsigned int data_len,
62 void *digest_info_ptr, unsigned int digest_info_len);
63
64 /* Calculate a hash. Return hash value */
65 int (*calc_hash)(enum crypto_md_algo md_alg, void *data_ptr,
66 unsigned int data_len,
67 unsigned char output[CRYPTO_MD_MAX_SIZE]);
68
69 /* Convert Public key (optional) */
70 int (*convert_pk)(void *full_pk_ptr, unsigned int full_pk_len,
71 void **hashed_pk_ptr, unsigned int *hashed_pk_len);
72
73 /*
74 * Authenticated decryption. Return one of the
75 * 'enum crypto_ret_value' options.
76 */
77 int (*auth_decrypt)(enum crypto_dec_algo dec_algo, void *data_ptr,
78 size_t len, const void *key, unsigned int key_len,
79 unsigned int key_flags, const void *iv,
80 unsigned int iv_len, const void *tag,
81 unsigned int tag_len);
82} crypto_lib_desc_t;
83
84/* Public functions */
85#if CRYPTO_SUPPORT
86void crypto_mod_init(void);
87#else
88static inline void crypto_mod_init(void)
89{
90}
91#endif /* CRYPTO_SUPPORT */
92
93#if (CRYPTO_SUPPORT == CRYPTO_AUTH_VERIFY_ONLY) || \
94 (CRYPTO_SUPPORT == CRYPTO_AUTH_VERIFY_AND_HASH_CALC)
95int crypto_mod_verify_signature(void *data_ptr, unsigned int data_len,
96 void *sig_ptr, unsigned int sig_len,
97 void *sig_alg_ptr, unsigned int sig_alg_len,
98 void *pk_ptr, unsigned int pk_len);
99int crypto_mod_verify_hash(void *data_ptr, unsigned int data_len,
100 void *digest_info_ptr, unsigned int digest_info_len);
101#endif /* (CRYPTO_SUPPORT == CRYPTO_AUTH_VERIFY_ONLY) || \
102 (CRYPTO_SUPPORT == CRYPTO_AUTH_VERIFY_AND_HASH_CALC) */
103
104int crypto_mod_auth_decrypt(enum crypto_dec_algo dec_algo, void *data_ptr,
105 size_t len, const void *key, unsigned int key_len,
106 unsigned int key_flags, const void *iv,
107 unsigned int iv_len, const void *tag,
108 unsigned int tag_len);
109
110#if (CRYPTO_SUPPORT == CRYPTO_HASH_CALC_ONLY) || \
111 (CRYPTO_SUPPORT == CRYPTO_AUTH_VERIFY_AND_HASH_CALC)
112int crypto_mod_calc_hash(enum crypto_md_algo alg, void *data_ptr,
113 unsigned int data_len,
114 unsigned char output[CRYPTO_MD_MAX_SIZE]);
115#endif /* (CRYPTO_SUPPORT == CRYPTO_HASH_CALC_ONLY) || \
116 (CRYPTO_SUPPORT == CRYPTO_AUTH_VERIFY_AND_HASH_CALC) */
117
118int crypto_mod_convert_pk(void *full_pk_ptr, unsigned int full_pk_len,
119 void **hashed_pk_ptr, unsigned int *hashed_pk_len);
120
121/* Macro to register a cryptographic library */
122#define REGISTER_CRYPTO_LIB(_name, _init, _verify_signature, _verify_hash, \
123 _calc_hash, _auth_decrypt, _convert_pk) \
124 const crypto_lib_desc_t crypto_lib_desc = { \
125 .name = _name, \
126 .init = _init, \
127 .verify_signature = _verify_signature, \
128 .verify_hash = _verify_hash, \
129 .calc_hash = _calc_hash, \
130 .auth_decrypt = _auth_decrypt, \
131 .convert_pk = _convert_pk \
132 }
133
134extern const crypto_lib_desc_t crypto_lib_desc;
135
136#endif /* CRYPTO_MOD_H */