blob: 6f09d9476da8141c958b0864e482a8545ec93fe9 [file] [log] [blame]
Manuel Pégourié-Gonnard21718762023-11-10 11:21:17 +01001/**
2 * \file block_cipher.c
3 *
4 * \brief Lightweight abstraction layer for block ciphers with 128 bit blocks,
5 * for use by the GCM and CCM modules.
6 */
7/*
8 * Copyright The Mbed TLS Contributors
9 * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
10 */
11
12#include "common.h"
13
Valerio Settic1db99d2023-12-12 11:19:17 +010014#if defined(MBEDTLS_BLOCK_CIPHER_SOME_PSA)
Valerio Settic1db99d2023-12-12 11:19:17 +010015#include "psa/crypto.h"
Valerio Setti849a1ab2023-12-13 16:34:07 +010016#include "psa_crypto_core.h"
Valerio Settic1db99d2023-12-12 11:19:17 +010017#include "psa_util_internal.h"
18#endif
19
Manuel Pégourié-Gonnard21718762023-11-10 11:21:17 +010020#include "block_cipher_internal.h"
21
22#if defined(MBEDTLS_BLOCK_CIPHER_C)
23
Valerio Settic1db99d2023-12-12 11:19:17 +010024#if defined(MBEDTLS_BLOCK_CIPHER_SOME_PSA)
25static psa_key_type_t psa_key_type_from_cipher_id(mbedtls_cipher_id_t cipher_id)
26{
27 switch (cipher_id) {
28#if defined(MBEDTLS_BLOCK_CIPHER_AES_VIA_PSA)
29 case MBEDTLS_CIPHER_ID_AES:
30 return PSA_KEY_TYPE_AES;
31#endif
32#if defined(MBEDTLS_BLOCK_CIPHER_ARIA_VIA_PSA)
33 case MBEDTLS_CIPHER_ID_ARIA:
34 return PSA_KEY_TYPE_ARIA;
35#endif
36#if defined(MBEDTLS_BLOCK_CIPHER_CAMELLIA_VIA_PSA)
37 case MBEDTLS_CIPHER_ID_CAMELLIA:
38 return PSA_KEY_TYPE_CAMELLIA;
39#endif
40 default:
41 return PSA_KEY_TYPE_NONE;
42 }
43}
44
45int mbedtls_cipher_error_from_psa(psa_status_t status)
46{
47 return PSA_TO_MBEDTLS_ERR_LIST(status, psa_to_cipher_errors,
48 psa_generic_status_to_mbedtls);
49}
50#endif /* MBEDTLS_BLOCK_CIPHER_SOME_PSA */
51
Manuel Pégourié-Gonnard21718762023-11-10 11:21:17 +010052void mbedtls_block_cipher_free(mbedtls_block_cipher_context_t *ctx)
53{
Valerio Settic1db99d2023-12-12 11:19:17 +010054#if defined(MBEDTLS_BLOCK_CIPHER_SOME_PSA)
55 if (ctx->engine == MBEDTLS_BLOCK_CIPHER_ENGINE_PSA) {
Valerio Settic1db99d2023-12-12 11:19:17 +010056 psa_destroy_key(ctx->psa_key_id);
57 return;
58 }
59#endif
Manuel Pégourié-Gonnard21718762023-11-10 11:21:17 +010060 switch (ctx->id) {
61#if defined(MBEDTLS_AES_C)
62 case MBEDTLS_BLOCK_CIPHER_ID_AES:
63 mbedtls_aes_free(&ctx->ctx.aes);
64 break;
65#endif
66#if defined(MBEDTLS_ARIA_C)
67 case MBEDTLS_BLOCK_CIPHER_ID_ARIA:
68 mbedtls_aria_free(&ctx->ctx.aria);
69 break;
70#endif
71#if defined(MBEDTLS_CAMELLIA_C)
72 case MBEDTLS_BLOCK_CIPHER_ID_CAMELLIA:
73 mbedtls_camellia_free(&ctx->ctx.camellia);
74 break;
75#endif
76 default:
77 break;
78 }
79 ctx->id = MBEDTLS_BLOCK_CIPHER_ID_NONE;
80}
81
82int mbedtls_block_cipher_setup(mbedtls_block_cipher_context_t *ctx,
83 mbedtls_cipher_id_t cipher_id)
84{
Valerio Settic1db99d2023-12-12 11:19:17 +010085#if defined(MBEDTLS_BLOCK_CIPHER_SOME_PSA)
86 if (psa_can_do_cipher(cipher_id)) {
87 ctx->psa_key_type = psa_key_type_from_cipher_id(cipher_id);
88 if (ctx->psa_key_type != PSA_KEY_TYPE_NONE) {
89 ctx->engine = MBEDTLS_BLOCK_CIPHER_ENGINE_PSA;
90 return 0;
91 }
92 }
93 ctx->engine = MBEDTLS_BLOCK_CIPHER_ENGINE_LEGACY;
94#endif
95
Manuel Pégourié-Gonnard21718762023-11-10 11:21:17 +010096 switch (cipher_id) {
97#if defined(MBEDTLS_AES_C)
98 case MBEDTLS_CIPHER_ID_AES:
99 ctx->id = MBEDTLS_BLOCK_CIPHER_ID_AES;
100 mbedtls_aes_init(&ctx->ctx.aes);
101 return 0;
102#endif
103#if defined(MBEDTLS_ARIA_C)
104 case MBEDTLS_CIPHER_ID_ARIA:
105 ctx->id = MBEDTLS_BLOCK_CIPHER_ID_ARIA;
106 mbedtls_aria_init(&ctx->ctx.aria);
107 return 0;
108#endif
109#if defined(MBEDTLS_CAMELLIA_C)
110 case MBEDTLS_CIPHER_ID_CAMELLIA:
111 ctx->id = MBEDTLS_BLOCK_CIPHER_ID_CAMELLIA;
112 mbedtls_camellia_init(&ctx->ctx.camellia);
113 return 0;
114#endif
115 default:
116 return MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA;
117 }
118}
119
Manuel Pégourié-Gonnard3e0884f2023-11-10 11:52:10 +0100120int mbedtls_block_cipher_setkey(mbedtls_block_cipher_context_t *ctx,
121 const unsigned char *key,
122 unsigned key_bitlen)
123{
Valerio Settic1db99d2023-12-12 11:19:17 +0100124#if defined(MBEDTLS_BLOCK_CIPHER_SOME_PSA)
125 if (ctx->engine == MBEDTLS_BLOCK_CIPHER_ENGINE_PSA) {
126 psa_key_attributes_t key_attr = PSA_KEY_ATTRIBUTES_INIT;
127 psa_status_t status;
128
129 psa_set_key_type(&key_attr, ctx->psa_key_type);
130 psa_set_key_bits(&key_attr, key_bitlen);
131 psa_set_key_algorithm(&key_attr, PSA_ALG_ECB_NO_PADDING);
132 psa_set_key_usage_flags(&key_attr, PSA_KEY_USAGE_ENCRYPT);
133
Valerio Setti785ec172023-12-13 16:49:05 +0100134 status = psa_import_key(&key_attr, key, PSA_BITS_TO_BYTES(key_bitlen), &ctx->psa_key_id);
Valerio Settic1db99d2023-12-12 11:19:17 +0100135 if (status != PSA_SUCCESS) {
136 return mbedtls_cipher_error_from_psa(status);
137 }
138 psa_reset_key_attributes(&key_attr);
139
Valerio Settic1db99d2023-12-12 11:19:17 +0100140 return 0;
141 }
142#endif /* MBEDTLS_BLOCK_CIPHER_SOME_PSA */
143
Manuel Pégourié-Gonnard3e0884f2023-11-10 11:52:10 +0100144 switch (ctx->id) {
145#if defined(MBEDTLS_AES_C)
146 case MBEDTLS_BLOCK_CIPHER_ID_AES:
147 return mbedtls_aes_setkey_enc(&ctx->ctx.aes, key, key_bitlen);
148#endif
149#if defined(MBEDTLS_ARIA_C)
150 case MBEDTLS_BLOCK_CIPHER_ID_ARIA:
151 return mbedtls_aria_setkey_enc(&ctx->ctx.aria, key, key_bitlen);
152#endif
153#if defined(MBEDTLS_CAMELLIA_C)
154 case MBEDTLS_BLOCK_CIPHER_ID_CAMELLIA:
155 return mbedtls_camellia_setkey_enc(&ctx->ctx.camellia, key, key_bitlen);
156#endif
157 default:
158 return MBEDTLS_ERR_CIPHER_INVALID_CONTEXT;
159 }
160}
Manuel Pégourié-Gonnard76fa16c2023-11-10 12:02:53 +0100161
162int mbedtls_block_cipher_encrypt(mbedtls_block_cipher_context_t *ctx,
163 const unsigned char input[16],
164 unsigned char output[16])
165{
Valerio Settic1db99d2023-12-12 11:19:17 +0100166#if defined(MBEDTLS_BLOCK_CIPHER_SOME_PSA)
167 if (ctx->engine == MBEDTLS_BLOCK_CIPHER_ENGINE_PSA) {
168 psa_status_t status;
169 size_t olen;
170
171 status = psa_cipher_encrypt(ctx->psa_key_id, PSA_ALG_ECB_NO_PADDING,
172 input, 16, output, 16, &olen);
173 if (status != PSA_SUCCESS) {
174 return mbedtls_cipher_error_from_psa(status);
175 }
176 return 0;
177 }
178#endif /* MBEDTLS_BLOCK_CIPHER_SOME_PSA */
179
Manuel Pégourié-Gonnard76fa16c2023-11-10 12:02:53 +0100180 switch (ctx->id) {
181#if defined(MBEDTLS_AES_C)
182 case MBEDTLS_BLOCK_CIPHER_ID_AES:
183 return mbedtls_aes_crypt_ecb(&ctx->ctx.aes, MBEDTLS_AES_ENCRYPT,
184 input, output);
185#endif
186#if defined(MBEDTLS_ARIA_C)
187 case MBEDTLS_BLOCK_CIPHER_ID_ARIA:
188 return mbedtls_aria_crypt_ecb(&ctx->ctx.aria, input, output);
189#endif
190#if defined(MBEDTLS_CAMELLIA_C)
191 case MBEDTLS_BLOCK_CIPHER_ID_CAMELLIA:
192 return mbedtls_camellia_crypt_ecb(&ctx->ctx.camellia,
193 MBEDTLS_CAMELLIA_ENCRYPT,
194 input, output);
195#endif
196 default:
197 return MBEDTLS_ERR_CIPHER_INVALID_CONTEXT;
198 }
199}
200
Manuel Pégourié-Gonnard21718762023-11-10 11:21:17 +0100201#endif /* MBEDTLS_BLOCK_CIPHER_C */