blob: 1a0b5a5824e874501443d835a3a68c9ee5ae09e3 [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/*
2 * VIA PadLock support functions
3 *
Bence Szépkúti1e148272020-08-07 13:07:28 +02004 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02005 * SPDX-License-Identifier: Apache-2.0
6 *
7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
8 * not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
10 *
11 * http://www.apache.org/licenses/LICENSE-2.0
12 *
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
Paul Bakker5121ce52009-01-03 21:22:43 +000018 */
19/*
20 * This implementation is based on the VIA PadLock Programming Guide:
21 *
22 * http://www.via.com.tw/en/downloads/whitepapers/initiatives/padlock/
23 * programming_guide.pdf
24 */
25
Gilles Peskinedb09ef62020-06-03 01:43:33 +020026#include "common.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000027
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020028#if defined(MBEDTLS_PADLOCK_C)
Paul Bakker5121ce52009-01-03 21:22:43 +000029
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020030# include "padlock.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000031
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020032# include <string.h>
Manuel Pégourié-Gonnard45ec8da2015-02-10 13:50:47 +000033
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020034# ifndef asm
35# define asm __asm
36# endif
Manuel Pégourié-Gonnardba194322015-05-29 09:47:57 +020037
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020038# if defined(MBEDTLS_HAVE_X86)
Paul Bakker5121ce52009-01-03 21:22:43 +000039
Paul Bakker5121ce52009-01-03 21:22:43 +000040/*
41 * PadLock detection routine
42 */
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020043int mbedtls_padlock_has_support(int feature)
Paul Bakker5121ce52009-01-03 21:22:43 +000044{
45 static int flags = -1;
Paul Bakker53e15132013-12-30 20:43:40 +010046 int ebx = 0, edx = 0;
Paul Bakker5121ce52009-01-03 21:22:43 +000047
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020048 if (flags == -1) {
49 asm("movl %%ebx, %0 \n\t"
50 "movl $0xC0000000, %%eax \n\t"
51 "cpuid \n\t"
52 "cmpl $0xC0000001, %%eax \n\t"
53 "movl $0, %%edx \n\t"
54 "jb 1f \n\t"
55 "movl $0xC0000001, %%eax \n\t"
56 "cpuid \n\t"
57 "1: \n\t"
58 "movl %%edx, %1 \n\t"
59 "movl %2, %%ebx \n\t"
60 : "=m"(ebx), "=m"(edx)
61 : "m"(ebx)
62 : "eax", "ecx", "edx");
Paul Bakker5121ce52009-01-03 21:22:43 +000063
64 flags = edx;
65 }
66
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020067 return flags & feature;
Paul Bakker5121ce52009-01-03 21:22:43 +000068}
69
70/*
71 * PadLock AES-ECB block en(de)cryption
72 */
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020073int mbedtls_padlock_xcryptecb(mbedtls_aes_context *ctx,
74 int mode,
75 const unsigned char input[16],
76 unsigned char output[16])
Paul Bakker5121ce52009-01-03 21:22:43 +000077{
Paul Bakker53e15132013-12-30 20:43:40 +010078 int ebx = 0;
Paul Bakker5c2364c2012-10-01 14:41:15 +000079 uint32_t *rk;
80 uint32_t *blk;
81 uint32_t *ctrl;
Paul Bakker5121ce52009-01-03 21:22:43 +000082 unsigned char buf[256];
83
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020084 rk = ctx->rk;
85 blk = MBEDTLS_PADLOCK_ALIGN16(buf);
86 memcpy(blk, input, 16);
Paul Bakker5121ce52009-01-03 21:22:43 +000087
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020088 ctrl = blk + 4;
89 *ctrl = 0x80 | ctx->nr | ((ctx->nr + (mode ^ 1) - 10) << 9);
Paul Bakker5121ce52009-01-03 21:22:43 +000090
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020091 asm("pushfl \n\t"
92 "popfl \n\t"
93 "movl %%ebx, %0 \n\t"
94 "movl $1, %%ecx \n\t"
95 "movl %2, %%edx \n\t"
96 "movl %3, %%ebx \n\t"
97 "movl %4, %%esi \n\t"
98 "movl %4, %%edi \n\t"
99 ".byte 0xf3,0x0f,0xa7,0xc8 \n\t"
100 "movl %1, %%ebx \n\t"
101 : "=m"(ebx)
102 : "m"(ebx), "m"(ctrl), "m"(rk), "m"(blk)
103 : "memory", "ecx", "edx", "esi", "edi");
Paul Bakker5121ce52009-01-03 21:22:43 +0000104
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200105 memcpy(output, blk, 16);
Paul Bakker5121ce52009-01-03 21:22:43 +0000106
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200107 return 0;
Paul Bakker5121ce52009-01-03 21:22:43 +0000108}
109
110/*
111 * PadLock AES-CBC buffer en(de)cryption
112 */
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200113int mbedtls_padlock_xcryptcbc(mbedtls_aes_context *ctx,
114 int mode,
115 size_t length,
116 unsigned char iv[16],
117 const unsigned char *input,
118 unsigned char *output)
Paul Bakker5121ce52009-01-03 21:22:43 +0000119{
Paul Bakker53e15132013-12-30 20:43:40 +0100120 int ebx = 0;
Paul Bakker23986e52011-04-24 08:57:21 +0000121 size_t count;
Paul Bakker5c2364c2012-10-01 14:41:15 +0000122 uint32_t *rk;
123 uint32_t *iw;
124 uint32_t *ctrl;
Paul Bakker5121ce52009-01-03 21:22:43 +0000125 unsigned char buf[256];
126
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200127 if (((long)input & 15) != 0 || ((long)output & 15) != 0)
128 return MBEDTLS_ERR_PADLOCK_DATA_MISALIGNED;
Paul Bakker5121ce52009-01-03 21:22:43 +0000129
130 rk = ctx->rk;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200131 iw = MBEDTLS_PADLOCK_ALIGN16(buf);
132 memcpy(iw, iv, 16);
Paul Bakker5121ce52009-01-03 21:22:43 +0000133
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200134 ctrl = iw + 4;
135 *ctrl = 0x80 | ctx->nr | ((ctx->nr + (mode ^ 1) - 10) << 9);
Paul Bakker5121ce52009-01-03 21:22:43 +0000136
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200137 count = (length + 15) >> 4;
Paul Bakker5121ce52009-01-03 21:22:43 +0000138
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200139 asm("pushfl \n\t"
140 "popfl \n\t"
141 "movl %%ebx, %0 \n\t"
142 "movl %2, %%ecx \n\t"
143 "movl %3, %%edx \n\t"
144 "movl %4, %%ebx \n\t"
145 "movl %5, %%esi \n\t"
146 "movl %6, %%edi \n\t"
147 "movl %7, %%eax \n\t"
148 ".byte 0xf3,0x0f,0xa7,0xd0 \n\t"
149 "movl %1, %%ebx \n\t"
150 : "=m"(ebx)
151 : "m"(ebx), "m"(count), "m"(ctrl), "m"(rk), "m"(input), "m"(output),
152 "m"(iw)
153 : "memory", "eax", "ecx", "edx", "esi", "edi");
Paul Bakker5121ce52009-01-03 21:22:43 +0000154
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200155 memcpy(iv, iw, 16);
Paul Bakker5121ce52009-01-03 21:22:43 +0000156
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200157 return 0;
Paul Bakker5121ce52009-01-03 21:22:43 +0000158}
159
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200160# endif /* MBEDTLS_HAVE_X86 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000161
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200162#endif /* MBEDTLS_PADLOCK_C */