blob: 111b28cf861601c1ed68e5e77bf4940c1cb9df94 [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/*
2 * VIA PadLock support functions
3 *
Bence Szépkúti1e148272020-08-07 13:07:28 +02004 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02005 * SPDX-License-Identifier: Apache-2.0
6 *
7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
8 * not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
10 *
11 * http://www.apache.org/licenses/LICENSE-2.0
12 *
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
Paul Bakker5121ce52009-01-03 21:22:43 +000018 */
19/*
20 * This implementation is based on the VIA PadLock Programming Guide:
21 *
22 * http://www.via.com.tw/en/downloads/whitepapers/initiatives/padlock/
23 * programming_guide.pdf
24 */
25
Gilles Peskinedb09ef62020-06-03 01:43:33 +020026#include "common.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000027
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020028#if defined(MBEDTLS_PADLOCK_C)
Paul Bakker5121ce52009-01-03 21:22:43 +000029
Chris Jones16dbaeb2021-03-09 17:47:55 +000030#include "padlock.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000031
Manuel Pégourié-Gonnard45ec8da2015-02-10 13:50:47 +000032#include <string.h>
33
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020034#if defined(MBEDTLS_HAVE_X86)
Paul Bakker5121ce52009-01-03 21:22:43 +000035
Jerry Yu0d4f4e52023-03-31 14:32:47 +080036#if !defined(MBEDTLS_AES_HAS_NO_BUILTIN)
Paul Bakker5121ce52009-01-03 21:22:43 +000037/*
38 * PadLock detection routine
39 */
Gilles Peskine449bd832023-01-11 14:50:10 +010040int mbedtls_padlock_has_support(int feature)
Paul Bakker5121ce52009-01-03 21:22:43 +000041{
42 static int flags = -1;
Paul Bakker53e15132013-12-30 20:43:40 +010043 int ebx = 0, edx = 0;
Paul Bakker5121ce52009-01-03 21:22:43 +000044
Gilles Peskine449bd832023-01-11 14:50:10 +010045 if (flags == -1) {
46 asm ("movl %%ebx, %0 \n\t"
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +020047 "movl $0xC0000000, %%eax \n\t"
48 "cpuid \n\t"
49 "cmpl $0xC0000001, %%eax \n\t"
50 "movl $0, %%edx \n\t"
okhowang(王沛文)0c4bbda2020-06-24 16:02:10 +080051 "jb 1f \n\t"
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +020052 "movl $0xC0000001, %%eax \n\t"
53 "cpuid \n\t"
okhowang(王沛文)0c4bbda2020-06-24 16:02:10 +080054 "1: \n\t"
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +020055 "movl %%edx, %1 \n\t"
56 "movl %2, %%ebx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +000057 : "=m" (ebx), "=m" (edx)
58 : "m" (ebx)
Gilles Peskine449bd832023-01-11 14:50:10 +010059 : "eax", "ecx", "edx");
Paul Bakker5121ce52009-01-03 21:22:43 +000060
61 flags = edx;
62 }
63
Gilles Peskine449bd832023-01-11 14:50:10 +010064 return flags & feature;
Paul Bakker5121ce52009-01-03 21:22:43 +000065}
Jerry Yu0d4f4e52023-03-31 14:32:47 +080066#endif
Paul Bakker5121ce52009-01-03 21:22:43 +000067
68/*
69 * PadLock AES-ECB block en(de)cryption
70 */
Gilles Peskine449bd832023-01-11 14:50:10 +010071int mbedtls_padlock_xcryptecb(mbedtls_aes_context *ctx,
72 int mode,
73 const unsigned char input[16],
74 unsigned char output[16])
Paul Bakker5121ce52009-01-03 21:22:43 +000075{
Paul Bakker53e15132013-12-30 20:43:40 +010076 int ebx = 0;
Paul Bakker5c2364c2012-10-01 14:41:15 +000077 uint32_t *rk;
78 uint32_t *blk;
79 uint32_t *ctrl;
Paul Bakker5121ce52009-01-03 21:22:43 +000080 unsigned char buf[256];
81
Werner Lewisc1999d52022-07-05 11:55:15 +010082 rk = ctx->buf + ctx->rk_offset;
83
Gilles Peskine449bd832023-01-11 14:50:10 +010084 if (((long) rk & 15) != 0) {
85 return MBEDTLS_ERR_PADLOCK_DATA_MISALIGNED;
86 }
Werner Lewisc1999d52022-07-05 11:55:15 +010087
Gilles Peskine449bd832023-01-11 14:50:10 +010088 blk = MBEDTLS_PADLOCK_ALIGN16(buf);
89 memcpy(blk, input, 16);
Paul Bakker5121ce52009-01-03 21:22:43 +000090
Gilles Peskine449bd832023-01-11 14:50:10 +010091 ctrl = blk + 4;
92 *ctrl = 0x80 | ctx->nr | ((ctx->nr + (mode^1) - 10) << 9);
Paul Bakker5121ce52009-01-03 21:22:43 +000093
Gilles Peskine449bd832023-01-11 14:50:10 +010094 asm ("pushfl \n\t"
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +020095 "popfl \n\t"
96 "movl %%ebx, %0 \n\t"
97 "movl $1, %%ecx \n\t"
98 "movl %2, %%edx \n\t"
99 "movl %3, %%ebx \n\t"
100 "movl %4, %%esi \n\t"
101 "movl %4, %%edi \n\t"
102 ".byte 0xf3,0x0f,0xa7,0xc8 \n\t"
103 "movl %1, %%ebx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000104 : "=m" (ebx)
105 : "m" (ebx), "m" (ctrl), "m" (rk), "m" (blk)
Gilles Peskine449bd832023-01-11 14:50:10 +0100106 : "memory", "ecx", "edx", "esi", "edi");
Paul Bakker5121ce52009-01-03 21:22:43 +0000107
Gilles Peskine449bd832023-01-11 14:50:10 +0100108 memcpy(output, blk, 16);
Paul Bakker5121ce52009-01-03 21:22:43 +0000109
Gilles Peskine449bd832023-01-11 14:50:10 +0100110 return 0;
Paul Bakker5121ce52009-01-03 21:22:43 +0000111}
112
113/*
114 * PadLock AES-CBC buffer en(de)cryption
115 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100116int mbedtls_padlock_xcryptcbc(mbedtls_aes_context *ctx,
117 int mode,
118 size_t length,
119 unsigned char iv[16],
120 const unsigned char *input,
121 unsigned char *output)
Paul Bakker5121ce52009-01-03 21:22:43 +0000122{
Paul Bakker53e15132013-12-30 20:43:40 +0100123 int ebx = 0;
Paul Bakker23986e52011-04-24 08:57:21 +0000124 size_t count;
Paul Bakker5c2364c2012-10-01 14:41:15 +0000125 uint32_t *rk;
126 uint32_t *iw;
127 uint32_t *ctrl;
Paul Bakker5121ce52009-01-03 21:22:43 +0000128 unsigned char buf[256];
129
Werner Lewisc1999d52022-07-05 11:55:15 +0100130 rk = ctx->buf + ctx->rk_offset;
131
Gilles Peskine449bd832023-01-11 14:50:10 +0100132 if (((long) input & 15) != 0 ||
133 ((long) output & 15) != 0 ||
134 ((long) rk & 15) != 0) {
135 return MBEDTLS_ERR_PADLOCK_DATA_MISALIGNED;
136 }
Paul Bakker5121ce52009-01-03 21:22:43 +0000137
Gilles Peskine449bd832023-01-11 14:50:10 +0100138 iw = MBEDTLS_PADLOCK_ALIGN16(buf);
139 memcpy(iw, iv, 16);
Paul Bakker5121ce52009-01-03 21:22:43 +0000140
Gilles Peskine449bd832023-01-11 14:50:10 +0100141 ctrl = iw + 4;
142 *ctrl = 0x80 | ctx->nr | ((ctx->nr + (mode ^ 1) - 10) << 9);
Paul Bakker5121ce52009-01-03 21:22:43 +0000143
Gilles Peskine449bd832023-01-11 14:50:10 +0100144 count = (length + 15) >> 4;
Paul Bakker5121ce52009-01-03 21:22:43 +0000145
Gilles Peskine449bd832023-01-11 14:50:10 +0100146 asm ("pushfl \n\t"
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +0200147 "popfl \n\t"
148 "movl %%ebx, %0 \n\t"
149 "movl %2, %%ecx \n\t"
150 "movl %3, %%edx \n\t"
151 "movl %4, %%ebx \n\t"
152 "movl %5, %%esi \n\t"
153 "movl %6, %%edi \n\t"
154 "movl %7, %%eax \n\t"
155 ".byte 0xf3,0x0f,0xa7,0xd0 \n\t"
156 "movl %1, %%ebx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000157 : "=m" (ebx)
158 : "m" (ebx), "m" (count), "m" (ctrl),
Gilles Peskine449bd832023-01-11 14:50:10 +0100159 "m" (rk), "m" (input), "m" (output), "m" (iw)
160 : "memory", "eax", "ecx", "edx", "esi", "edi");
Paul Bakker5121ce52009-01-03 21:22:43 +0000161
Gilles Peskine449bd832023-01-11 14:50:10 +0100162 memcpy(iv, iw, 16);
Paul Bakker5121ce52009-01-03 21:22:43 +0000163
Gilles Peskine449bd832023-01-11 14:50:10 +0100164 return 0;
Paul Bakker5121ce52009-01-03 21:22:43 +0000165}
166
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200167#endif /* MBEDTLS_HAVE_X86 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000168
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200169#endif /* MBEDTLS_PADLOCK_C */