xref: /openbmc/linux/crypto/sig.c (revision 20508b75)
16cb8815fSHerbert Xu /* SPDX-License-Identifier: GPL-2.0-or-later */
26cb8815fSHerbert Xu /*
36cb8815fSHerbert Xu  * Public Key Signature Algorithm
46cb8815fSHerbert Xu  *
56cb8815fSHerbert Xu  * Copyright (c) 2023 Herbert Xu <herbert@gondor.apana.org.au>
66cb8815fSHerbert Xu  */
76cb8815fSHerbert Xu 
86cb8815fSHerbert Xu #include <crypto/akcipher.h>
96cb8815fSHerbert Xu #include <crypto/internal/sig.h>
106cb8815fSHerbert Xu #include <linux/cryptouser.h>
116cb8815fSHerbert Xu #include <linux/kernel.h>
126cb8815fSHerbert Xu #include <linux/module.h>
136cb8815fSHerbert Xu #include <linux/scatterlist.h>
146cb8815fSHerbert Xu #include <linux/seq_file.h>
156cb8815fSHerbert Xu #include <linux/string.h>
166cb8815fSHerbert Xu #include <net/netlink.h>
176cb8815fSHerbert Xu 
186cb8815fSHerbert Xu #include "internal.h"
196cb8815fSHerbert Xu 
206cb8815fSHerbert Xu #define CRYPTO_ALG_TYPE_SIG_MASK	0x0000000e
216cb8815fSHerbert Xu 
226cb8815fSHerbert Xu static const struct crypto_type crypto_sig_type;
236cb8815fSHerbert Xu 
crypto_sig_init_tfm(struct crypto_tfm * tfm)246cb8815fSHerbert Xu static int crypto_sig_init_tfm(struct crypto_tfm *tfm)
256cb8815fSHerbert Xu {
266cb8815fSHerbert Xu 	if (tfm->__crt_alg->cra_type != &crypto_sig_type)
276cb8815fSHerbert Xu 		return crypto_init_akcipher_ops_sig(tfm);
286cb8815fSHerbert Xu 
296cb8815fSHerbert Xu 	return 0;
306cb8815fSHerbert Xu }
316cb8815fSHerbert Xu 
crypto_sig_show(struct seq_file * m,struct crypto_alg * alg)326cb8815fSHerbert Xu static void __maybe_unused crypto_sig_show(struct seq_file *m,
336cb8815fSHerbert Xu 					   struct crypto_alg *alg)
346cb8815fSHerbert Xu {
356cb8815fSHerbert Xu 	seq_puts(m, "type         : sig\n");
366cb8815fSHerbert Xu }
376cb8815fSHerbert Xu 
crypto_sig_report(struct sk_buff * skb,struct crypto_alg * alg)386cb8815fSHerbert Xu static int __maybe_unused crypto_sig_report(struct sk_buff *skb,
396cb8815fSHerbert Xu 					    struct crypto_alg *alg)
406cb8815fSHerbert Xu {
416cb8815fSHerbert Xu 	struct crypto_report_akcipher rsig = {};
426cb8815fSHerbert Xu 
436cb8815fSHerbert Xu 	strscpy(rsig.type, "sig", sizeof(rsig.type));
446cb8815fSHerbert Xu 
456cb8815fSHerbert Xu 	return nla_put(skb, CRYPTOCFGA_REPORT_AKCIPHER, sizeof(rsig), &rsig);
466cb8815fSHerbert Xu }
476cb8815fSHerbert Xu 
crypto_sig_report_stat(struct sk_buff * skb,struct crypto_alg * alg)486cb8815fSHerbert Xu static int __maybe_unused crypto_sig_report_stat(struct sk_buff *skb,
496cb8815fSHerbert Xu 						 struct crypto_alg *alg)
506cb8815fSHerbert Xu {
516cb8815fSHerbert Xu 	struct crypto_stat_akcipher rsig = {};
526cb8815fSHerbert Xu 
536cb8815fSHerbert Xu 	strscpy(rsig.type, "sig", sizeof(rsig.type));
546cb8815fSHerbert Xu 
556cb8815fSHerbert Xu 	return nla_put(skb, CRYPTOCFGA_STAT_AKCIPHER, sizeof(rsig), &rsig);
566cb8815fSHerbert Xu }
576cb8815fSHerbert Xu 
586cb8815fSHerbert Xu static const struct crypto_type crypto_sig_type = {
596cb8815fSHerbert Xu 	.extsize = crypto_alg_extsize,
606cb8815fSHerbert Xu 	.init_tfm = crypto_sig_init_tfm,
616cb8815fSHerbert Xu #ifdef CONFIG_PROC_FS
626cb8815fSHerbert Xu 	.show = crypto_sig_show,
636cb8815fSHerbert Xu #endif
646cb8815fSHerbert Xu #if IS_ENABLED(CONFIG_CRYPTO_USER)
656cb8815fSHerbert Xu 	.report = crypto_sig_report,
666cb8815fSHerbert Xu #endif
676cb8815fSHerbert Xu #ifdef CONFIG_CRYPTO_STATS
686cb8815fSHerbert Xu 	.report_stat = crypto_sig_report_stat,
696cb8815fSHerbert Xu #endif
706cb8815fSHerbert Xu 	.maskclear = ~CRYPTO_ALG_TYPE_MASK,
716cb8815fSHerbert Xu 	.maskset = CRYPTO_ALG_TYPE_SIG_MASK,
726cb8815fSHerbert Xu 	.type = CRYPTO_ALG_TYPE_SIG,
736cb8815fSHerbert Xu 	.tfmsize = offsetof(struct crypto_sig, base),
746cb8815fSHerbert Xu };
756cb8815fSHerbert Xu 
crypto_alloc_sig(const char * alg_name,u32 type,u32 mask)766cb8815fSHerbert Xu struct crypto_sig *crypto_alloc_sig(const char *alg_name, u32 type, u32 mask)
776cb8815fSHerbert Xu {
786cb8815fSHerbert Xu 	return crypto_alloc_tfm(alg_name, &crypto_sig_type, type, mask);
796cb8815fSHerbert Xu }
806cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_alloc_sig);
816cb8815fSHerbert Xu 
crypto_sig_maxsize(struct crypto_sig * tfm)826cb8815fSHerbert Xu int crypto_sig_maxsize(struct crypto_sig *tfm)
836cb8815fSHerbert Xu {
846cb8815fSHerbert Xu 	struct crypto_akcipher **ctx = crypto_sig_ctx(tfm);
856cb8815fSHerbert Xu 
866cb8815fSHerbert Xu 	return crypto_akcipher_maxsize(*ctx);
876cb8815fSHerbert Xu }
886cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_maxsize);
896cb8815fSHerbert Xu 
crypto_sig_sign(struct crypto_sig * tfm,const void * src,unsigned int slen,void * dst,unsigned int dlen)906cb8815fSHerbert Xu int crypto_sig_sign(struct crypto_sig *tfm,
916cb8815fSHerbert Xu 		    const void *src, unsigned int slen,
926cb8815fSHerbert Xu 		    void *dst, unsigned int dlen)
936cb8815fSHerbert Xu {
946cb8815fSHerbert Xu 	struct crypto_akcipher **ctx = crypto_sig_ctx(tfm);
956cb8815fSHerbert Xu 	struct crypto_akcipher_sync_data data = {
966cb8815fSHerbert Xu 		.tfm = *ctx,
976cb8815fSHerbert Xu 		.src = src,
986cb8815fSHerbert Xu 		.dst = dst,
996cb8815fSHerbert Xu 		.slen = slen,
1006cb8815fSHerbert Xu 		.dlen = dlen,
1016cb8815fSHerbert Xu 	};
1026cb8815fSHerbert Xu 
1036cb8815fSHerbert Xu 	return crypto_akcipher_sync_prep(&data) ?:
1046cb8815fSHerbert Xu 	       crypto_akcipher_sync_post(&data,
1056cb8815fSHerbert Xu 					 crypto_akcipher_sign(data.req));
1066cb8815fSHerbert Xu }
1076cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_sign);
1086cb8815fSHerbert Xu 
crypto_sig_verify(struct crypto_sig * tfm,const void * src,unsigned int slen,const void * digest,unsigned int dlen)1096cb8815fSHerbert Xu int crypto_sig_verify(struct crypto_sig *tfm,
1106cb8815fSHerbert Xu 		      const void *src, unsigned int slen,
1116cb8815fSHerbert Xu 		      const void *digest, unsigned int dlen)
1126cb8815fSHerbert Xu {
1136cb8815fSHerbert Xu 	struct crypto_akcipher **ctx = crypto_sig_ctx(tfm);
1146cb8815fSHerbert Xu 	struct crypto_akcipher_sync_data data = {
1156cb8815fSHerbert Xu 		.tfm = *ctx,
1166cb8815fSHerbert Xu 		.src = src,
1176cb8815fSHerbert Xu 		.slen = slen,
1186cb8815fSHerbert Xu 		.dlen = dlen,
1196cb8815fSHerbert Xu 	};
1206cb8815fSHerbert Xu 	int err;
1216cb8815fSHerbert Xu 
1226cb8815fSHerbert Xu 	err = crypto_akcipher_sync_prep(&data);
1236cb8815fSHerbert Xu 	if (err)
1246cb8815fSHerbert Xu 		return err;
1256cb8815fSHerbert Xu 
126*891ebfdfSHerbert Xu 	memcpy(data.buf + slen, digest, dlen);
1276cb8815fSHerbert Xu 
1286cb8815fSHerbert Xu 	return crypto_akcipher_sync_post(&data,
1296cb8815fSHerbert Xu 					 crypto_akcipher_verify(data.req));
1306cb8815fSHerbert Xu }
1316cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_verify);
1326cb8815fSHerbert Xu 
crypto_sig_set_pubkey(struct crypto_sig * tfm,const void * key,unsigned int keylen)1336cb8815fSHerbert Xu int crypto_sig_set_pubkey(struct crypto_sig *tfm,
1346cb8815fSHerbert Xu 			  const void *key, unsigned int keylen)
1356cb8815fSHerbert Xu {
1366cb8815fSHerbert Xu 	struct crypto_akcipher **ctx = crypto_sig_ctx(tfm);
1376cb8815fSHerbert Xu 
1386cb8815fSHerbert Xu 	return crypto_akcipher_set_pub_key(*ctx, key, keylen);
1396cb8815fSHerbert Xu }
1406cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_set_pubkey);
1416cb8815fSHerbert Xu 
crypto_sig_set_privkey(struct crypto_sig * tfm,const void * key,unsigned int keylen)1426cb8815fSHerbert Xu int crypto_sig_set_privkey(struct crypto_sig *tfm,
1436cb8815fSHerbert Xu 			  const void *key, unsigned int keylen)
1446cb8815fSHerbert Xu {
1456cb8815fSHerbert Xu 	struct crypto_akcipher **ctx = crypto_sig_ctx(tfm);
1466cb8815fSHerbert Xu 
1476cb8815fSHerbert Xu 	return crypto_akcipher_set_priv_key(*ctx, key, keylen);
1486cb8815fSHerbert Xu }
1496cb8815fSHerbert Xu EXPORT_SYMBOL_GPL(crypto_sig_set_privkey);
1506cb8815fSHerbert Xu 
1516cb8815fSHerbert Xu MODULE_LICENSE("GPL");
1526cb8815fSHerbert Xu MODULE_DESCRIPTION("Public Key Signature Algorithms");
153