16cb8815fSHerbert Xu /* SPDX-License-Identifier: GPL-2.0-or-later */ 26cb8815fSHerbert Xu /* 36cb8815fSHerbert Xu * Public Key Signature Algorithm 46cb8815fSHerbert Xu * 56cb8815fSHerbert Xu * Copyright (c) 2023 Herbert Xu <herbert@gondor.apana.org.au> 66cb8815fSHerbert Xu */ 76cb8815fSHerbert Xu 86cb8815fSHerbert Xu #include <crypto/akcipher.h> 96cb8815fSHerbert Xu #include <crypto/internal/sig.h> 106cb8815fSHerbert Xu #include <linux/cryptouser.h> 116cb8815fSHerbert Xu #include <linux/kernel.h> 126cb8815fSHerbert Xu #include <linux/module.h> 136cb8815fSHerbert Xu #include <linux/scatterlist.h> 146cb8815fSHerbert Xu #include <linux/seq_file.h> 156cb8815fSHerbert Xu #include <linux/string.h> 166cb8815fSHerbert Xu #include <net/netlink.h> 176cb8815fSHerbert Xu 186cb8815fSHerbert Xu #include "internal.h" 196cb8815fSHerbert Xu 206cb8815fSHerbert Xu #define CRYPTO_ALG_TYPE_SIG_MASK 0x0000000e 216cb8815fSHerbert Xu 226cb8815fSHerbert Xu static const struct crypto_type crypto_sig_type; 236cb8815fSHerbert Xu 246cb8815fSHerbert Xu static inline struct crypto_sig *__crypto_sig_tfm(struct crypto_tfm *tfm) 256cb8815fSHerbert Xu { 266cb8815fSHerbert Xu return container_of(tfm, struct crypto_sig, base); 276cb8815fSHerbert Xu } 286cb8815fSHerbert Xu 296cb8815fSHerbert Xu static int crypto_sig_init_tfm(struct crypto_tfm *tfm) 306cb8815fSHerbert Xu { 316cb8815fSHerbert Xu if (tfm->__crt_alg->cra_type != &crypto_sig_type) 326cb8815fSHerbert Xu return crypto_init_akcipher_ops_sig(tfm); 336cb8815fSHerbert Xu 346cb8815fSHerbert Xu return 0; 356cb8815fSHerbert Xu } 366cb8815fSHerbert Xu 376cb8815fSHerbert Xu static void __maybe_unused crypto_sig_show(struct seq_file *m, 386cb8815fSHerbert Xu struct crypto_alg *alg) 396cb8815fSHerbert Xu { 406cb8815fSHerbert Xu seq_puts(m, "type : sig\n"); 416cb8815fSHerbert Xu } 426cb8815fSHerbert Xu 436cb8815fSHerbert Xu static int __maybe_unused crypto_sig_report(struct sk_buff *skb, 446cb8815fSHerbert Xu struct crypto_alg *alg) 456cb8815fSHerbert Xu { 466cb8815fSHerbert Xu struct crypto_report_akcipher rsig = {}; 476cb8815fSHerbert Xu 486cb8815fSHerbert Xu strscpy(rsig.type, "sig", sizeof(rsig.type)); 496cb8815fSHerbert Xu 506cb8815fSHerbert Xu return nla_put(skb, CRYPTOCFGA_REPORT_AKCIPHER, sizeof(rsig), &rsig); 516cb8815fSHerbert Xu } 526cb8815fSHerbert Xu 536cb8815fSHerbert Xu static int __maybe_unused crypto_sig_report_stat(struct sk_buff *skb, 546cb8815fSHerbert Xu struct crypto_alg *alg) 556cb8815fSHerbert Xu { 566cb8815fSHerbert Xu struct crypto_stat_akcipher rsig = {}; 576cb8815fSHerbert Xu 586cb8815fSHerbert Xu strscpy(rsig.type, "sig", sizeof(rsig.type)); 596cb8815fSHerbert Xu 606cb8815fSHerbert Xu return nla_put(skb, CRYPTOCFGA_STAT_AKCIPHER, sizeof(rsig), &rsig); 616cb8815fSHerbert Xu } 626cb8815fSHerbert Xu 636cb8815fSHerbert Xu static const struct crypto_type crypto_sig_type = { 646cb8815fSHerbert Xu .extsize = crypto_alg_extsize, 656cb8815fSHerbert Xu .init_tfm = crypto_sig_init_tfm, 666cb8815fSHerbert Xu #ifdef CONFIG_PROC_FS 676cb8815fSHerbert Xu .show = crypto_sig_show, 686cb8815fSHerbert Xu #endif 696cb8815fSHerbert Xu #if IS_ENABLED(CONFIG_CRYPTO_USER) 706cb8815fSHerbert Xu .report = crypto_sig_report, 716cb8815fSHerbert Xu #endif 726cb8815fSHerbert Xu #ifdef CONFIG_CRYPTO_STATS 736cb8815fSHerbert Xu .report_stat = crypto_sig_report_stat, 746cb8815fSHerbert Xu #endif 756cb8815fSHerbert Xu .maskclear = ~CRYPTO_ALG_TYPE_MASK, 766cb8815fSHerbert Xu .maskset = CRYPTO_ALG_TYPE_SIG_MASK, 776cb8815fSHerbert Xu .type = CRYPTO_ALG_TYPE_SIG, 786cb8815fSHerbert Xu .tfmsize = offsetof(struct crypto_sig, base), 796cb8815fSHerbert Xu }; 806cb8815fSHerbert Xu 816cb8815fSHerbert Xu struct crypto_sig *crypto_alloc_sig(const char *alg_name, u32 type, u32 mask) 826cb8815fSHerbert Xu { 836cb8815fSHerbert Xu return crypto_alloc_tfm(alg_name, &crypto_sig_type, type, mask); 846cb8815fSHerbert Xu } 856cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_alloc_sig); 866cb8815fSHerbert Xu 876cb8815fSHerbert Xu int crypto_sig_maxsize(struct crypto_sig *tfm) 886cb8815fSHerbert Xu { 896cb8815fSHerbert Xu struct crypto_akcipher **ctx = crypto_sig_ctx(tfm); 906cb8815fSHerbert Xu 916cb8815fSHerbert Xu return crypto_akcipher_maxsize(*ctx); 926cb8815fSHerbert Xu } 936cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_maxsize); 946cb8815fSHerbert Xu 956cb8815fSHerbert Xu int crypto_sig_sign(struct crypto_sig *tfm, 966cb8815fSHerbert Xu const void *src, unsigned int slen, 976cb8815fSHerbert Xu void *dst, unsigned int dlen) 986cb8815fSHerbert Xu { 996cb8815fSHerbert Xu struct crypto_akcipher **ctx = crypto_sig_ctx(tfm); 1006cb8815fSHerbert Xu struct crypto_akcipher_sync_data data = { 1016cb8815fSHerbert Xu .tfm = *ctx, 1026cb8815fSHerbert Xu .src = src, 1036cb8815fSHerbert Xu .dst = dst, 1046cb8815fSHerbert Xu .slen = slen, 1056cb8815fSHerbert Xu .dlen = dlen, 1066cb8815fSHerbert Xu }; 1076cb8815fSHerbert Xu 1086cb8815fSHerbert Xu return crypto_akcipher_sync_prep(&data) ?: 1096cb8815fSHerbert Xu crypto_akcipher_sync_post(&data, 1106cb8815fSHerbert Xu crypto_akcipher_sign(data.req)); 1116cb8815fSHerbert Xu } 1126cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_sign); 1136cb8815fSHerbert Xu 1146cb8815fSHerbert Xu int crypto_sig_verify(struct crypto_sig *tfm, 1156cb8815fSHerbert Xu const void *src, unsigned int slen, 1166cb8815fSHerbert Xu const void *digest, unsigned int dlen) 1176cb8815fSHerbert Xu { 1186cb8815fSHerbert Xu struct crypto_akcipher **ctx = crypto_sig_ctx(tfm); 1196cb8815fSHerbert Xu struct crypto_akcipher_sync_data data = { 1206cb8815fSHerbert Xu .tfm = *ctx, 1216cb8815fSHerbert Xu .src = src, 1226cb8815fSHerbert Xu .slen = slen, 1236cb8815fSHerbert Xu .dlen = dlen, 1246cb8815fSHerbert Xu }; 1256cb8815fSHerbert Xu int err; 1266cb8815fSHerbert Xu 1276cb8815fSHerbert Xu err = crypto_akcipher_sync_prep(&data); 1286cb8815fSHerbert Xu if (err) 1296cb8815fSHerbert Xu return err; 1306cb8815fSHerbert Xu 131*891ebfdfSHerbert Xu memcpy(data.buf + slen, digest, dlen); 1326cb8815fSHerbert Xu 1336cb8815fSHerbert Xu return crypto_akcipher_sync_post(&data, 1346cb8815fSHerbert Xu crypto_akcipher_verify(data.req)); 1356cb8815fSHerbert Xu } 1366cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_verify); 1376cb8815fSHerbert Xu 1386cb8815fSHerbert Xu int crypto_sig_set_pubkey(struct crypto_sig *tfm, 1396cb8815fSHerbert Xu const void *key, unsigned int keylen) 1406cb8815fSHerbert Xu { 1416cb8815fSHerbert Xu struct crypto_akcipher **ctx = crypto_sig_ctx(tfm); 1426cb8815fSHerbert Xu 1436cb8815fSHerbert Xu return crypto_akcipher_set_pub_key(*ctx, key, keylen); 1446cb8815fSHerbert Xu } 1456cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_set_pubkey); 1466cb8815fSHerbert Xu 1476cb8815fSHerbert Xu int crypto_sig_set_privkey(struct crypto_sig *tfm, 1486cb8815fSHerbert Xu const void *key, unsigned int keylen) 1496cb8815fSHerbert Xu { 1506cb8815fSHerbert Xu struct crypto_akcipher **ctx = crypto_sig_ctx(tfm); 1516cb8815fSHerbert Xu 1526cb8815fSHerbert Xu return crypto_akcipher_set_priv_key(*ctx, key, keylen); 1536cb8815fSHerbert Xu } 1546cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_set_privkey); 1556cb8815fSHerbert Xu 1566cb8815fSHerbert Xu MODULE_LICENSE("GPL"); 1576cb8815fSHerbert Xu MODULE_DESCRIPTION("Public Key Signature Algorithms"); 158