blob: 969639f31977dd7b235d66e434bb6234d23f0539 [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 * Cryptographic API.
3 *
Jan Glauberc1e26e12006-01-06 00:19:17 -08004 * s390 implementation of the SHA1 Secure Hash Algorithm.
Linus Torvalds1da177e2005-04-16 15:20:36 -07005 *
6 * Derived from cryptoapi implementation, adapted for in-place
7 * scatterlist interface. Originally based on the public domain
8 * implementation written by Steve Reid.
9 *
10 * s390 Version:
Jan Glauber86aa9fc2007-02-05 21:18:14 +010011 * Copyright IBM Corp. 2003,2007
12 * Author(s): Thomas Spatzier
13 * Jan Glauber (jan.glauber@de.ibm.com)
Linus Torvalds1da177e2005-04-16 15:20:36 -070014 *
15 * Derived from "crypto/sha1.c"
16 * Copyright (c) Alan Smithee.
17 * Copyright (c) Andrew McDonald <andrew@mcdonald.org.uk>
18 * Copyright (c) Jean-Francois Dive <jef@linuxbe.org>
19 *
20 * This program is free software; you can redistribute it and/or modify it
21 * under the terms of the GNU General Public License as published by the Free
22 * Software Foundation; either version 2 of the License, or (at your option)
23 * any later version.
24 *
25 */
26#include <linux/init.h>
27#include <linux/module.h>
28#include <linux/mm.h>
29#include <linux/crypto.h>
30#include <asm/scatterlist.h>
31#include <asm/byteorder.h>
Jan Glauberc1e26e12006-01-06 00:19:17 -080032#include "crypt_s390.h"
Linus Torvalds1da177e2005-04-16 15:20:36 -070033
34#define SHA1_DIGEST_SIZE 20
35#define SHA1_BLOCK_SIZE 64
36
Jan Glauberc1e26e12006-01-06 00:19:17 -080037struct crypt_s390_sha1_ctx {
38 u64 count;
39 u32 state[5];
Linus Torvalds1da177e2005-04-16 15:20:36 -070040 u32 buf_len;
Jan Glauberc1e26e12006-01-06 00:19:17 -080041 u8 buffer[2 * SHA1_BLOCK_SIZE];
Linus Torvalds1da177e2005-04-16 15:20:36 -070042};
43
Herbert Xu6c2bb982006-05-16 22:09:29 +100044static void sha1_init(struct crypto_tfm *tfm)
Linus Torvalds1da177e2005-04-16 15:20:36 -070045{
Herbert Xu6c2bb982006-05-16 22:09:29 +100046 struct crypt_s390_sha1_ctx *ctx = crypto_tfm_ctx(tfm);
Jan Glauber86aa9fc2007-02-05 21:18:14 +010047
48 ctx->state[0] = 0x67452301;
49 ctx->state[1] = 0xEFCDAB89;
50 ctx->state[2] = 0x98BADCFE;
51 ctx->state[3] = 0x10325476;
52 ctx->state[4] = 0xC3D2E1F0;
Herbert Xu43600102006-05-16 22:06:54 +100053
54 ctx->count = 0;
Herbert Xu43600102006-05-16 22:06:54 +100055 ctx->buf_len = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -070056}
57
Herbert Xu6c2bb982006-05-16 22:09:29 +100058static void sha1_update(struct crypto_tfm *tfm, const u8 *data,
59 unsigned int len)
Linus Torvalds1da177e2005-04-16 15:20:36 -070060{
Jan Glauberc1e26e12006-01-06 00:19:17 -080061 struct crypt_s390_sha1_ctx *sctx;
Linus Torvalds1da177e2005-04-16 15:20:36 -070062 long imd_len;
63
Herbert Xu6c2bb982006-05-16 22:09:29 +100064 sctx = crypto_tfm_ctx(tfm);
Jan Glauber86aa9fc2007-02-05 21:18:14 +010065 sctx->count += len * 8; /* message bit length */
Linus Torvalds1da177e2005-04-16 15:20:36 -070066
Jan Glauber86aa9fc2007-02-05 21:18:14 +010067 /* anything in buffer yet? -> must be completed */
Linus Torvalds1da177e2005-04-16 15:20:36 -070068 if (sctx->buf_len && (sctx->buf_len + len) >= SHA1_BLOCK_SIZE) {
Jan Glauber86aa9fc2007-02-05 21:18:14 +010069 /* complete full block and hash */
Linus Torvalds1da177e2005-04-16 15:20:36 -070070 memcpy(sctx->buffer + sctx->buf_len, data,
Jan Glauber86aa9fc2007-02-05 21:18:14 +010071 SHA1_BLOCK_SIZE - sctx->buf_len);
Jan Glauberc1e26e12006-01-06 00:19:17 -080072 crypt_s390_kimd(KIMD_SHA_1, sctx->state, sctx->buffer,
Linus Torvalds1da177e2005-04-16 15:20:36 -070073 SHA1_BLOCK_SIZE);
74 data += SHA1_BLOCK_SIZE - sctx->buf_len;
75 len -= SHA1_BLOCK_SIZE - sctx->buf_len;
76 sctx->buf_len = 0;
77 }
78
Jan Glauber86aa9fc2007-02-05 21:18:14 +010079 /* rest of data contains full blocks? */
Linus Torvalds1da177e2005-04-16 15:20:36 -070080 imd_len = len & ~0x3ful;
Jan Glauber86aa9fc2007-02-05 21:18:14 +010081 if (imd_len) {
Jan Glauberc1e26e12006-01-06 00:19:17 -080082 crypt_s390_kimd(KIMD_SHA_1, sctx->state, data, imd_len);
Linus Torvalds1da177e2005-04-16 15:20:36 -070083 data += imd_len;
84 len -= imd_len;
85 }
Jan Glauber86aa9fc2007-02-05 21:18:14 +010086 /* anything left? store in buffer */
87 if (len) {
Linus Torvalds1da177e2005-04-16 15:20:36 -070088 memcpy(sctx->buffer + sctx->buf_len , data, len);
89 sctx->buf_len += len;
90 }
91}
92
93
Jan Glauber86aa9fc2007-02-05 21:18:14 +010094static void pad_message(struct crypt_s390_sha1_ctx* sctx)
Linus Torvalds1da177e2005-04-16 15:20:36 -070095{
96 int index;
97
98 index = sctx->buf_len;
Jan Glauber86aa9fc2007-02-05 21:18:14 +010099 sctx->buf_len = (sctx->buf_len < 56) ?
100 SHA1_BLOCK_SIZE:2 * SHA1_BLOCK_SIZE;
101 /* start pad with 1 */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700102 sctx->buffer[index] = 0x80;
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100103 /* pad with zeros */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700104 index++;
105 memset(sctx->buffer + index, 0x00, sctx->buf_len - index);
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100106 /* append length */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700107 memcpy(sctx->buffer + sctx->buf_len - 8, &sctx->count,
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100108 sizeof sctx->count);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700109}
110
111/* Add padding and return the message digest. */
Herbert Xu6c2bb982006-05-16 22:09:29 +1000112static void sha1_final(struct crypto_tfm *tfm, u8 *out)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700113{
Herbert Xu6c2bb982006-05-16 22:09:29 +1000114 struct crypt_s390_sha1_ctx *sctx = crypto_tfm_ctx(tfm);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700115
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100116 /* must perform manual padding */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700117 pad_message(sctx);
Jan Glauberc1e26e12006-01-06 00:19:17 -0800118 crypt_s390_kimd(KIMD_SHA_1, sctx->state, sctx->buffer, sctx->buf_len);
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100119 /* copy digest to out */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700120 memcpy(out, sctx->state, SHA1_DIGEST_SIZE);
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100121 /* wipe context */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700122 memset(sctx, 0, sizeof *sctx);
123}
124
125static struct crypto_alg alg = {
126 .cra_name = "sha1",
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100127 .cra_driver_name= "sha1-s390",
Herbert Xu65b75c32006-08-21 21:18:50 +1000128 .cra_priority = CRYPT_S390_PRIORITY,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700129 .cra_flags = CRYPTO_ALG_TYPE_DIGEST,
130 .cra_blocksize = SHA1_BLOCK_SIZE,
Jan Glauberc1e26e12006-01-06 00:19:17 -0800131 .cra_ctxsize = sizeof(struct crypt_s390_sha1_ctx),
Linus Torvalds1da177e2005-04-16 15:20:36 -0700132 .cra_module = THIS_MODULE,
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100133 .cra_list = LIST_HEAD_INIT(alg.cra_list),
Linus Torvalds1da177e2005-04-16 15:20:36 -0700134 .cra_u = { .digest = {
135 .dia_digestsize = SHA1_DIGEST_SIZE,
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100136 .dia_init = sha1_init,
137 .dia_update = sha1_update,
138 .dia_final = sha1_final } }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700139};
140
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100141static int __init init(void)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700142{
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100143 if (!crypt_s390_func_available(KIMD_SHA_1))
144 return -EOPNOTSUPP;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700145
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100146 return crypto_register_alg(&alg);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700147}
148
Jan Glauber86aa9fc2007-02-05 21:18:14 +0100149static void __exit fini(void)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700150{
151 crypto_unregister_alg(&alg);
152}
153
154module_init(init);
155module_exit(fini);
156
157MODULE_ALIAS("sha1");
158
159MODULE_LICENSE("GPL");
160MODULE_DESCRIPTION("SHA1 Secure Hash Algorithm");