aesni-x86.pl 66 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189
  1. #!/usr/bin/env perl
  2. # ====================================================================
  3. # Written by Andy Polyakov <[email protected]> for the OpenSSL
  4. # project. The module is, however, dual licensed under OpenSSL and
  5. # CRYPTOGAMS licenses depending on where you obtain it. For further
  6. # details see http://www.openssl.org/~appro/cryptogams/.
  7. # ====================================================================
  8. #
  9. # This module implements support for Intel AES-NI extension. In
  10. # OpenSSL context it's used with Intel engine, but can also be used as
  11. # drop-in replacement for crypto/aes/asm/aes-586.pl [see below for
  12. # details].
  13. #
  14. # Performance.
  15. #
  16. # To start with see corresponding paragraph in aesni-x86_64.pl...
  17. # Instead of filling table similar to one found there I've chosen to
  18. # summarize *comparison* results for raw ECB, CTR and CBC benchmarks.
  19. # The simplified table below represents 32-bit performance relative
  20. # to 64-bit one in every given point. Ratios vary for different
  21. # encryption modes, therefore interval values.
  22. #
  23. # 16-byte 64-byte 256-byte 1-KB 8-KB
  24. # 53-67% 67-84% 91-94% 95-98% 97-99.5%
  25. #
  26. # Lower ratios for smaller block sizes are perfectly understandable,
  27. # because function call overhead is higher in 32-bit mode. Largest
  28. # 8-KB block performance is virtually same: 32-bit code is less than
  29. # 1% slower for ECB, CBC and CCM, and ~3% slower otherwise.
  30. # January 2011
  31. #
  32. # See aesni-x86_64.pl for details. Unlike x86_64 version this module
  33. # interleaves at most 6 aes[enc|dec] instructions, because there are
  34. # not enough registers for 8x interleave [which should be optimal for
  35. # Sandy Bridge]. Actually, performance results for 6x interleave
  36. # factor presented in aesni-x86_64.pl (except for CTR) are for this
  37. # module.
  38. # April 2011
  39. #
  40. # Add aesni_xts_[en|de]crypt. Westmere spends 1.50 cycles processing
  41. # one byte out of 8KB with 128-bit key, Sandy Bridge - 1.09.
  42. $PREFIX="aesni"; # if $PREFIX is set to "AES", the script
  43. # generates drop-in replacement for
  44. # crypto/aes/asm/aes-586.pl:-)
  45. $inline=1; # inline _aesni_[en|de]crypt
  46. $0 =~ m/(.*[\/\\])[^\/\\]+$/; $dir=$1;
  47. push(@INC,"${dir}","${dir}../../perlasm");
  48. require "x86asm.pl";
  49. &asm_init($ARGV[0],$0);
  50. if ($PREFIX eq "aesni") { $movekey=*movups; }
  51. else { $movekey=*movups; }
  52. $len="eax";
  53. $rounds="ecx";
  54. $key="edx";
  55. $inp="esi";
  56. $out="edi";
  57. $rounds_="ebx"; # backup copy for $rounds
  58. $key_="ebp"; # backup copy for $key
  59. $rndkey0="xmm0";
  60. $rndkey1="xmm1";
  61. $inout0="xmm2";
  62. $inout1="xmm3";
  63. $inout2="xmm4";
  64. $inout3="xmm5"; $in1="xmm5";
  65. $inout4="xmm6"; $in0="xmm6";
  66. $inout5="xmm7"; $ivec="xmm7";
  67. # AESNI extenstion
  68. sub aeskeygenassist
  69. { my($dst,$src,$imm)=@_;
  70. if ("$dst:$src" =~ /xmm([0-7]):xmm([0-7])/)
  71. { &data_byte(0x66,0x0f,0x3a,0xdf,0xc0|($1<<3)|$2,$imm); }
  72. }
  73. sub aescommon
  74. { my($opcodelet,$dst,$src)=@_;
  75. if ("$dst:$src" =~ /xmm([0-7]):xmm([0-7])/)
  76. { &data_byte(0x66,0x0f,0x38,$opcodelet,0xc0|($1<<3)|$2);}
  77. }
  78. sub aesimc { aescommon(0xdb,@_); }
  79. sub aesenc { aescommon(0xdc,@_); }
  80. sub aesenclast { aescommon(0xdd,@_); }
  81. sub aesdec { aescommon(0xde,@_); }
  82. sub aesdeclast { aescommon(0xdf,@_); }
  83. # Inline version of internal aesni_[en|de]crypt1
  84. { my $sn;
  85. sub aesni_inline_generate1
  86. { my ($p,$inout,$ivec)=@_; $inout=$inout0 if (!defined($inout));
  87. $sn++;
  88. &$movekey ($rndkey0,&QWP(0,$key));
  89. &$movekey ($rndkey1,&QWP(16,$key));
  90. &xorps ($ivec,$rndkey0) if (defined($ivec));
  91. &lea ($key,&DWP(32,$key));
  92. &xorps ($inout,$ivec) if (defined($ivec));
  93. &xorps ($inout,$rndkey0) if (!defined($ivec));
  94. &set_label("${p}1_loop_$sn");
  95. eval"&aes${p} ($inout,$rndkey1)";
  96. &dec ($rounds);
  97. &$movekey ($rndkey1,&QWP(0,$key));
  98. &lea ($key,&DWP(16,$key));
  99. &jnz (&label("${p}1_loop_$sn"));
  100. eval"&aes${p}last ($inout,$rndkey1)";
  101. }}
  102. sub aesni_generate1 # fully unrolled loop
  103. { my ($p,$inout)=@_; $inout=$inout0 if (!defined($inout));
  104. &function_begin_B("_aesni_${p}rypt1");
  105. &movups ($rndkey0,&QWP(0,$key));
  106. &$movekey ($rndkey1,&QWP(0x10,$key));
  107. &xorps ($inout,$rndkey0);
  108. &$movekey ($rndkey0,&QWP(0x20,$key));
  109. &lea ($key,&DWP(0x30,$key));
  110. &cmp ($rounds,11);
  111. &jb (&label("${p}128"));
  112. &lea ($key,&DWP(0x20,$key));
  113. &je (&label("${p}192"));
  114. &lea ($key,&DWP(0x20,$key));
  115. eval"&aes${p} ($inout,$rndkey1)";
  116. &$movekey ($rndkey1,&QWP(-0x40,$key));
  117. eval"&aes${p} ($inout,$rndkey0)";
  118. &$movekey ($rndkey0,&QWP(-0x30,$key));
  119. &set_label("${p}192");
  120. eval"&aes${p} ($inout,$rndkey1)";
  121. &$movekey ($rndkey1,&QWP(-0x20,$key));
  122. eval"&aes${p} ($inout,$rndkey0)";
  123. &$movekey ($rndkey0,&QWP(-0x10,$key));
  124. &set_label("${p}128");
  125. eval"&aes${p} ($inout,$rndkey1)";
  126. &$movekey ($rndkey1,&QWP(0,$key));
  127. eval"&aes${p} ($inout,$rndkey0)";
  128. &$movekey ($rndkey0,&QWP(0x10,$key));
  129. eval"&aes${p} ($inout,$rndkey1)";
  130. &$movekey ($rndkey1,&QWP(0x20,$key));
  131. eval"&aes${p} ($inout,$rndkey0)";
  132. &$movekey ($rndkey0,&QWP(0x30,$key));
  133. eval"&aes${p} ($inout,$rndkey1)";
  134. &$movekey ($rndkey1,&QWP(0x40,$key));
  135. eval"&aes${p} ($inout,$rndkey0)";
  136. &$movekey ($rndkey0,&QWP(0x50,$key));
  137. eval"&aes${p} ($inout,$rndkey1)";
  138. &$movekey ($rndkey1,&QWP(0x60,$key));
  139. eval"&aes${p} ($inout,$rndkey0)";
  140. &$movekey ($rndkey0,&QWP(0x70,$key));
  141. eval"&aes${p} ($inout,$rndkey1)";
  142. eval"&aes${p}last ($inout,$rndkey0)";
  143. &ret();
  144. &function_end_B("_aesni_${p}rypt1");
  145. }
  146. # void $PREFIX_encrypt (const void *inp,void *out,const AES_KEY *key);
  147. &aesni_generate1("enc") if (!$inline);
  148. &function_begin_B("${PREFIX}_encrypt");
  149. &mov ("eax",&wparam(0));
  150. &mov ($key,&wparam(2));
  151. &movups ($inout0,&QWP(0,"eax"));
  152. &mov ($rounds,&DWP(240,$key));
  153. &mov ("eax",&wparam(1));
  154. if ($inline)
  155. { &aesni_inline_generate1("enc"); }
  156. else
  157. { &call ("_aesni_encrypt1"); }
  158. &movups (&QWP(0,"eax"),$inout0);
  159. &ret ();
  160. &function_end_B("${PREFIX}_encrypt");
  161. # void $PREFIX_decrypt (const void *inp,void *out,const AES_KEY *key);
  162. &aesni_generate1("dec") if(!$inline);
  163. &function_begin_B("${PREFIX}_decrypt");
  164. &mov ("eax",&wparam(0));
  165. &mov ($key,&wparam(2));
  166. &movups ($inout0,&QWP(0,"eax"));
  167. &mov ($rounds,&DWP(240,$key));
  168. &mov ("eax",&wparam(1));
  169. if ($inline)
  170. { &aesni_inline_generate1("dec"); }
  171. else
  172. { &call ("_aesni_decrypt1"); }
  173. &movups (&QWP(0,"eax"),$inout0);
  174. &ret ();
  175. &function_end_B("${PREFIX}_decrypt");
  176. # _aesni_[en|de]cryptN are private interfaces, N denotes interleave
  177. # factor. Why 3x subroutine were originally used in loops? Even though
  178. # aes[enc|dec] latency was originally 6, it could be scheduled only
  179. # every *2nd* cycle. Thus 3x interleave was the one providing optimal
  180. # utilization, i.e. when subroutine's throughput is virtually same as
  181. # of non-interleaved subroutine [for number of input blocks up to 3].
  182. # This is why it makes no sense to implement 2x subroutine.
  183. # aes[enc|dec] latency in next processor generation is 8, but the
  184. # instructions can be scheduled every cycle. Optimal interleave for
  185. # new processor is therefore 8x, but it's unfeasible to accommodate it
  186. # in XMM registers addreassable in 32-bit mode and therefore 6x is
  187. # used instead...
  188. sub aesni_generate3
  189. { my $p=shift;
  190. &function_begin_B("_aesni_${p}rypt3");
  191. &$movekey ($rndkey0,&QWP(0,$key));
  192. &shr ($rounds,1);
  193. &$movekey ($rndkey1,&QWP(16,$key));
  194. &lea ($key,&DWP(32,$key));
  195. &xorps ($inout0,$rndkey0);
  196. &pxor ($inout1,$rndkey0);
  197. &pxor ($inout2,$rndkey0);
  198. &$movekey ($rndkey0,&QWP(0,$key));
  199. &set_label("${p}3_loop");
  200. eval"&aes${p} ($inout0,$rndkey1)";
  201. eval"&aes${p} ($inout1,$rndkey1)";
  202. &dec ($rounds);
  203. eval"&aes${p} ($inout2,$rndkey1)";
  204. &$movekey ($rndkey1,&QWP(16,$key));
  205. eval"&aes${p} ($inout0,$rndkey0)";
  206. eval"&aes${p} ($inout1,$rndkey0)";
  207. &lea ($key,&DWP(32,$key));
  208. eval"&aes${p} ($inout2,$rndkey0)";
  209. &$movekey ($rndkey0,&QWP(0,$key));
  210. &jnz (&label("${p}3_loop"));
  211. eval"&aes${p} ($inout0,$rndkey1)";
  212. eval"&aes${p} ($inout1,$rndkey1)";
  213. eval"&aes${p} ($inout2,$rndkey1)";
  214. eval"&aes${p}last ($inout0,$rndkey0)";
  215. eval"&aes${p}last ($inout1,$rndkey0)";
  216. eval"&aes${p}last ($inout2,$rndkey0)";
  217. &ret();
  218. &function_end_B("_aesni_${p}rypt3");
  219. }
  220. # 4x interleave is implemented to improve small block performance,
  221. # most notably [and naturally] 4 block by ~30%. One can argue that one
  222. # should have implemented 5x as well, but improvement would be <20%,
  223. # so it's not worth it...
  224. sub aesni_generate4
  225. { my $p=shift;
  226. &function_begin_B("_aesni_${p}rypt4");
  227. &$movekey ($rndkey0,&QWP(0,$key));
  228. &$movekey ($rndkey1,&QWP(16,$key));
  229. &shr ($rounds,1);
  230. &lea ($key,&DWP(32,$key));
  231. &xorps ($inout0,$rndkey0);
  232. &pxor ($inout1,$rndkey0);
  233. &pxor ($inout2,$rndkey0);
  234. &pxor ($inout3,$rndkey0);
  235. &$movekey ($rndkey0,&QWP(0,$key));
  236. &set_label("${p}4_loop");
  237. eval"&aes${p} ($inout0,$rndkey1)";
  238. eval"&aes${p} ($inout1,$rndkey1)";
  239. &dec ($rounds);
  240. eval"&aes${p} ($inout2,$rndkey1)";
  241. eval"&aes${p} ($inout3,$rndkey1)";
  242. &$movekey ($rndkey1,&QWP(16,$key));
  243. eval"&aes${p} ($inout0,$rndkey0)";
  244. eval"&aes${p} ($inout1,$rndkey0)";
  245. &lea ($key,&DWP(32,$key));
  246. eval"&aes${p} ($inout2,$rndkey0)";
  247. eval"&aes${p} ($inout3,$rndkey0)";
  248. &$movekey ($rndkey0,&QWP(0,$key));
  249. &jnz (&label("${p}4_loop"));
  250. eval"&aes${p} ($inout0,$rndkey1)";
  251. eval"&aes${p} ($inout1,$rndkey1)";
  252. eval"&aes${p} ($inout2,$rndkey1)";
  253. eval"&aes${p} ($inout3,$rndkey1)";
  254. eval"&aes${p}last ($inout0,$rndkey0)";
  255. eval"&aes${p}last ($inout1,$rndkey0)";
  256. eval"&aes${p}last ($inout2,$rndkey0)";
  257. eval"&aes${p}last ($inout3,$rndkey0)";
  258. &ret();
  259. &function_end_B("_aesni_${p}rypt4");
  260. }
  261. sub aesni_generate6
  262. { my $p=shift;
  263. &function_begin_B("_aesni_${p}rypt6");
  264. &static_label("_aesni_${p}rypt6_enter");
  265. &$movekey ($rndkey0,&QWP(0,$key));
  266. &shr ($rounds,1);
  267. &$movekey ($rndkey1,&QWP(16,$key));
  268. &lea ($key,&DWP(32,$key));
  269. &xorps ($inout0,$rndkey0);
  270. &pxor ($inout1,$rndkey0); # pxor does better here
  271. eval"&aes${p} ($inout0,$rndkey1)";
  272. &pxor ($inout2,$rndkey0);
  273. eval"&aes${p} ($inout1,$rndkey1)";
  274. &pxor ($inout3,$rndkey0);
  275. &dec ($rounds);
  276. eval"&aes${p} ($inout2,$rndkey1)";
  277. &pxor ($inout4,$rndkey0);
  278. eval"&aes${p} ($inout3,$rndkey1)";
  279. &pxor ($inout5,$rndkey0);
  280. eval"&aes${p} ($inout4,$rndkey1)";
  281. &$movekey ($rndkey0,&QWP(0,$key));
  282. eval"&aes${p} ($inout5,$rndkey1)";
  283. &jmp (&label("_aesni_${p}rypt6_enter"));
  284. &set_label("${p}6_loop",16);
  285. eval"&aes${p} ($inout0,$rndkey1)";
  286. eval"&aes${p} ($inout1,$rndkey1)";
  287. &dec ($rounds);
  288. eval"&aes${p} ($inout2,$rndkey1)";
  289. eval"&aes${p} ($inout3,$rndkey1)";
  290. eval"&aes${p} ($inout4,$rndkey1)";
  291. eval"&aes${p} ($inout5,$rndkey1)";
  292. &set_label("_aesni_${p}rypt6_enter",16);
  293. &$movekey ($rndkey1,&QWP(16,$key));
  294. eval"&aes${p} ($inout0,$rndkey0)";
  295. eval"&aes${p} ($inout1,$rndkey0)";
  296. &lea ($key,&DWP(32,$key));
  297. eval"&aes${p} ($inout2,$rndkey0)";
  298. eval"&aes${p} ($inout3,$rndkey0)";
  299. eval"&aes${p} ($inout4,$rndkey0)";
  300. eval"&aes${p} ($inout5,$rndkey0)";
  301. &$movekey ($rndkey0,&QWP(0,$key));
  302. &jnz (&label("${p}6_loop"));
  303. eval"&aes${p} ($inout0,$rndkey1)";
  304. eval"&aes${p} ($inout1,$rndkey1)";
  305. eval"&aes${p} ($inout2,$rndkey1)";
  306. eval"&aes${p} ($inout3,$rndkey1)";
  307. eval"&aes${p} ($inout4,$rndkey1)";
  308. eval"&aes${p} ($inout5,$rndkey1)";
  309. eval"&aes${p}last ($inout0,$rndkey0)";
  310. eval"&aes${p}last ($inout1,$rndkey0)";
  311. eval"&aes${p}last ($inout2,$rndkey0)";
  312. eval"&aes${p}last ($inout3,$rndkey0)";
  313. eval"&aes${p}last ($inout4,$rndkey0)";
  314. eval"&aes${p}last ($inout5,$rndkey0)";
  315. &ret();
  316. &function_end_B("_aesni_${p}rypt6");
  317. }
  318. &aesni_generate3("enc") if ($PREFIX eq "aesni");
  319. &aesni_generate3("dec");
  320. &aesni_generate4("enc") if ($PREFIX eq "aesni");
  321. &aesni_generate4("dec");
  322. &aesni_generate6("enc") if ($PREFIX eq "aesni");
  323. &aesni_generate6("dec");
  324. if ($PREFIX eq "aesni") {
  325. ######################################################################
  326. # void aesni_ecb_encrypt (const void *in, void *out,
  327. # size_t length, const AES_KEY *key,
  328. # int enc);
  329. &function_begin("aesni_ecb_encrypt");
  330. &mov ($inp,&wparam(0));
  331. &mov ($out,&wparam(1));
  332. &mov ($len,&wparam(2));
  333. &mov ($key,&wparam(3));
  334. &mov ($rounds_,&wparam(4));
  335. &and ($len,-16);
  336. &jz (&label("ecb_ret"));
  337. &mov ($rounds,&DWP(240,$key));
  338. &test ($rounds_,$rounds_);
  339. &jz (&label("ecb_decrypt"));
  340. &mov ($key_,$key); # backup $key
  341. &mov ($rounds_,$rounds); # backup $rounds
  342. &cmp ($len,0x60);
  343. &jb (&label("ecb_enc_tail"));
  344. &movdqu ($inout0,&QWP(0,$inp));
  345. &movdqu ($inout1,&QWP(0x10,$inp));
  346. &movdqu ($inout2,&QWP(0x20,$inp));
  347. &movdqu ($inout3,&QWP(0x30,$inp));
  348. &movdqu ($inout4,&QWP(0x40,$inp));
  349. &movdqu ($inout5,&QWP(0x50,$inp));
  350. &lea ($inp,&DWP(0x60,$inp));
  351. &sub ($len,0x60);
  352. &jmp (&label("ecb_enc_loop6_enter"));
  353. &set_label("ecb_enc_loop6",16);
  354. &movups (&QWP(0,$out),$inout0);
  355. &movdqu ($inout0,&QWP(0,$inp));
  356. &movups (&QWP(0x10,$out),$inout1);
  357. &movdqu ($inout1,&QWP(0x10,$inp));
  358. &movups (&QWP(0x20,$out),$inout2);
  359. &movdqu ($inout2,&QWP(0x20,$inp));
  360. &movups (&QWP(0x30,$out),$inout3);
  361. &movdqu ($inout3,&QWP(0x30,$inp));
  362. &movups (&QWP(0x40,$out),$inout4);
  363. &movdqu ($inout4,&QWP(0x40,$inp));
  364. &movups (&QWP(0x50,$out),$inout5);
  365. &lea ($out,&DWP(0x60,$out));
  366. &movdqu ($inout5,&QWP(0x50,$inp));
  367. &lea ($inp,&DWP(0x60,$inp));
  368. &set_label("ecb_enc_loop6_enter");
  369. &call ("_aesni_encrypt6");
  370. &mov ($key,$key_); # restore $key
  371. &mov ($rounds,$rounds_); # restore $rounds
  372. &sub ($len,0x60);
  373. &jnc (&label("ecb_enc_loop6"));
  374. &movups (&QWP(0,$out),$inout0);
  375. &movups (&QWP(0x10,$out),$inout1);
  376. &movups (&QWP(0x20,$out),$inout2);
  377. &movups (&QWP(0x30,$out),$inout3);
  378. &movups (&QWP(0x40,$out),$inout4);
  379. &movups (&QWP(0x50,$out),$inout5);
  380. &lea ($out,&DWP(0x60,$out));
  381. &add ($len,0x60);
  382. &jz (&label("ecb_ret"));
  383. &set_label("ecb_enc_tail");
  384. &movups ($inout0,&QWP(0,$inp));
  385. &cmp ($len,0x20);
  386. &jb (&label("ecb_enc_one"));
  387. &movups ($inout1,&QWP(0x10,$inp));
  388. &je (&label("ecb_enc_two"));
  389. &movups ($inout2,&QWP(0x20,$inp));
  390. &cmp ($len,0x40);
  391. &jb (&label("ecb_enc_three"));
  392. &movups ($inout3,&QWP(0x30,$inp));
  393. &je (&label("ecb_enc_four"));
  394. &movups ($inout4,&QWP(0x40,$inp));
  395. &xorps ($inout5,$inout5);
  396. &call ("_aesni_encrypt6");
  397. &movups (&QWP(0,$out),$inout0);
  398. &movups (&QWP(0x10,$out),$inout1);
  399. &movups (&QWP(0x20,$out),$inout2);
  400. &movups (&QWP(0x30,$out),$inout3);
  401. &movups (&QWP(0x40,$out),$inout4);
  402. jmp (&label("ecb_ret"));
  403. &set_label("ecb_enc_one",16);
  404. if ($inline)
  405. { &aesni_inline_generate1("enc"); }
  406. else
  407. { &call ("_aesni_encrypt1"); }
  408. &movups (&QWP(0,$out),$inout0);
  409. &jmp (&label("ecb_ret"));
  410. &set_label("ecb_enc_two",16);
  411. &xorps ($inout2,$inout2);
  412. &call ("_aesni_encrypt3");
  413. &movups (&QWP(0,$out),$inout0);
  414. &movups (&QWP(0x10,$out),$inout1);
  415. &jmp (&label("ecb_ret"));
  416. &set_label("ecb_enc_three",16);
  417. &call ("_aesni_encrypt3");
  418. &movups (&QWP(0,$out),$inout0);
  419. &movups (&QWP(0x10,$out),$inout1);
  420. &movups (&QWP(0x20,$out),$inout2);
  421. &jmp (&label("ecb_ret"));
  422. &set_label("ecb_enc_four",16);
  423. &call ("_aesni_encrypt4");
  424. &movups (&QWP(0,$out),$inout0);
  425. &movups (&QWP(0x10,$out),$inout1);
  426. &movups (&QWP(0x20,$out),$inout2);
  427. &movups (&QWP(0x30,$out),$inout3);
  428. &jmp (&label("ecb_ret"));
  429. ######################################################################
  430. &set_label("ecb_decrypt",16);
  431. &mov ($key_,$key); # backup $key
  432. &mov ($rounds_,$rounds); # backup $rounds
  433. &cmp ($len,0x60);
  434. &jb (&label("ecb_dec_tail"));
  435. &movdqu ($inout0,&QWP(0,$inp));
  436. &movdqu ($inout1,&QWP(0x10,$inp));
  437. &movdqu ($inout2,&QWP(0x20,$inp));
  438. &movdqu ($inout3,&QWP(0x30,$inp));
  439. &movdqu ($inout4,&QWP(0x40,$inp));
  440. &movdqu ($inout5,&QWP(0x50,$inp));
  441. &lea ($inp,&DWP(0x60,$inp));
  442. &sub ($len,0x60);
  443. &jmp (&label("ecb_dec_loop6_enter"));
  444. &set_label("ecb_dec_loop6",16);
  445. &movups (&QWP(0,$out),$inout0);
  446. &movdqu ($inout0,&QWP(0,$inp));
  447. &movups (&QWP(0x10,$out),$inout1);
  448. &movdqu ($inout1,&QWP(0x10,$inp));
  449. &movups (&QWP(0x20,$out),$inout2);
  450. &movdqu ($inout2,&QWP(0x20,$inp));
  451. &movups (&QWP(0x30,$out),$inout3);
  452. &movdqu ($inout3,&QWP(0x30,$inp));
  453. &movups (&QWP(0x40,$out),$inout4);
  454. &movdqu ($inout4,&QWP(0x40,$inp));
  455. &movups (&QWP(0x50,$out),$inout5);
  456. &lea ($out,&DWP(0x60,$out));
  457. &movdqu ($inout5,&QWP(0x50,$inp));
  458. &lea ($inp,&DWP(0x60,$inp));
  459. &set_label("ecb_dec_loop6_enter");
  460. &call ("_aesni_decrypt6");
  461. &mov ($key,$key_); # restore $key
  462. &mov ($rounds,$rounds_); # restore $rounds
  463. &sub ($len,0x60);
  464. &jnc (&label("ecb_dec_loop6"));
  465. &movups (&QWP(0,$out),$inout0);
  466. &movups (&QWP(0x10,$out),$inout1);
  467. &movups (&QWP(0x20,$out),$inout2);
  468. &movups (&QWP(0x30,$out),$inout3);
  469. &movups (&QWP(0x40,$out),$inout4);
  470. &movups (&QWP(0x50,$out),$inout5);
  471. &lea ($out,&DWP(0x60,$out));
  472. &add ($len,0x60);
  473. &jz (&label("ecb_ret"));
  474. &set_label("ecb_dec_tail");
  475. &movups ($inout0,&QWP(0,$inp));
  476. &cmp ($len,0x20);
  477. &jb (&label("ecb_dec_one"));
  478. &movups ($inout1,&QWP(0x10,$inp));
  479. &je (&label("ecb_dec_two"));
  480. &movups ($inout2,&QWP(0x20,$inp));
  481. &cmp ($len,0x40);
  482. &jb (&label("ecb_dec_three"));
  483. &movups ($inout3,&QWP(0x30,$inp));
  484. &je (&label("ecb_dec_four"));
  485. &movups ($inout4,&QWP(0x40,$inp));
  486. &xorps ($inout5,$inout5);
  487. &call ("_aesni_decrypt6");
  488. &movups (&QWP(0,$out),$inout0);
  489. &movups (&QWP(0x10,$out),$inout1);
  490. &movups (&QWP(0x20,$out),$inout2);
  491. &movups (&QWP(0x30,$out),$inout3);
  492. &movups (&QWP(0x40,$out),$inout4);
  493. &jmp (&label("ecb_ret"));
  494. &set_label("ecb_dec_one",16);
  495. if ($inline)
  496. { &aesni_inline_generate1("dec"); }
  497. else
  498. { &call ("_aesni_decrypt1"); }
  499. &movups (&QWP(0,$out),$inout0);
  500. &jmp (&label("ecb_ret"));
  501. &set_label("ecb_dec_two",16);
  502. &xorps ($inout2,$inout2);
  503. &call ("_aesni_decrypt3");
  504. &movups (&QWP(0,$out),$inout0);
  505. &movups (&QWP(0x10,$out),$inout1);
  506. &jmp (&label("ecb_ret"));
  507. &set_label("ecb_dec_three",16);
  508. &call ("_aesni_decrypt3");
  509. &movups (&QWP(0,$out),$inout0);
  510. &movups (&QWP(0x10,$out),$inout1);
  511. &movups (&QWP(0x20,$out),$inout2);
  512. &jmp (&label("ecb_ret"));
  513. &set_label("ecb_dec_four",16);
  514. &call ("_aesni_decrypt4");
  515. &movups (&QWP(0,$out),$inout0);
  516. &movups (&QWP(0x10,$out),$inout1);
  517. &movups (&QWP(0x20,$out),$inout2);
  518. &movups (&QWP(0x30,$out),$inout3);
  519. &set_label("ecb_ret");
  520. &function_end("aesni_ecb_encrypt");
  521. ######################################################################
  522. # void aesni_ccm64_[en|de]crypt_blocks (const void *in, void *out,
  523. # size_t blocks, const AES_KEY *key,
  524. # const char *ivec,char *cmac);
  525. #
  526. # Handles only complete blocks, operates on 64-bit counter and
  527. # does not update *ivec! Nor does it finalize CMAC value
  528. # (see engine/eng_aesni.c for details)
  529. #
  530. { my $cmac=$inout1;
  531. &function_begin("aesni_ccm64_encrypt_blocks");
  532. &mov ($inp,&wparam(0));
  533. &mov ($out,&wparam(1));
  534. &mov ($len,&wparam(2));
  535. &mov ($key,&wparam(3));
  536. &mov ($rounds_,&wparam(4));
  537. &mov ($rounds,&wparam(5));
  538. &mov ($key_,"esp");
  539. &sub ("esp",60);
  540. &and ("esp",-16); # align stack
  541. &mov (&DWP(48,"esp"),$key_);
  542. &movdqu ($ivec,&QWP(0,$rounds_)); # load ivec
  543. &movdqu ($cmac,&QWP(0,$rounds)); # load cmac
  544. &mov ($rounds,&DWP(240,$key));
  545. # compose byte-swap control mask for pshufb on stack
  546. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  547. &mov (&DWP(4,"esp"),0x08090a0b);
  548. &mov (&DWP(8,"esp"),0x04050607);
  549. &mov (&DWP(12,"esp"),0x00010203);
  550. # compose counter increment vector on stack
  551. &mov ($rounds_,1);
  552. &xor ($key_,$key_);
  553. &mov (&DWP(16,"esp"),$rounds_);
  554. &mov (&DWP(20,"esp"),$key_);
  555. &mov (&DWP(24,"esp"),$key_);
  556. &mov (&DWP(28,"esp"),$key_);
  557. &shr ($rounds,1);
  558. &lea ($key_,&DWP(0,$key));
  559. &movdqa ($inout3,&QWP(0,"esp"));
  560. &movdqa ($inout0,$ivec);
  561. &mov ($rounds_,$rounds);
  562. &pshufb ($ivec,$inout3);
  563. &set_label("ccm64_enc_outer");
  564. &$movekey ($rndkey0,&QWP(0,$key_));
  565. &mov ($rounds,$rounds_);
  566. &movups ($in0,&QWP(0,$inp));
  567. &xorps ($inout0,$rndkey0);
  568. &$movekey ($rndkey1,&QWP(16,$key_));
  569. &xorps ($rndkey0,$in0);
  570. &lea ($key,&DWP(32,$key_));
  571. &xorps ($cmac,$rndkey0); # cmac^=inp
  572. &$movekey ($rndkey0,&QWP(0,$key));
  573. &set_label("ccm64_enc2_loop");
  574. &aesenc ($inout0,$rndkey1);
  575. &dec ($rounds);
  576. &aesenc ($cmac,$rndkey1);
  577. &$movekey ($rndkey1,&QWP(16,$key));
  578. &aesenc ($inout0,$rndkey0);
  579. &lea ($key,&DWP(32,$key));
  580. &aesenc ($cmac,$rndkey0);
  581. &$movekey ($rndkey0,&QWP(0,$key));
  582. &jnz (&label("ccm64_enc2_loop"));
  583. &aesenc ($inout0,$rndkey1);
  584. &aesenc ($cmac,$rndkey1);
  585. &paddq ($ivec,&QWP(16,"esp"));
  586. &aesenclast ($inout0,$rndkey0);
  587. &aesenclast ($cmac,$rndkey0);
  588. &dec ($len);
  589. &lea ($inp,&DWP(16,$inp));
  590. &xorps ($in0,$inout0); # inp^=E(ivec)
  591. &movdqa ($inout0,$ivec);
  592. &movups (&QWP(0,$out),$in0); # save output
  593. &lea ($out,&DWP(16,$out));
  594. &pshufb ($inout0,$inout3);
  595. &jnz (&label("ccm64_enc_outer"));
  596. &mov ("esp",&DWP(48,"esp"));
  597. &mov ($out,&wparam(5));
  598. &movups (&QWP(0,$out),$cmac);
  599. &function_end("aesni_ccm64_encrypt_blocks");
  600. &function_begin("aesni_ccm64_decrypt_blocks");
  601. &mov ($inp,&wparam(0));
  602. &mov ($out,&wparam(1));
  603. &mov ($len,&wparam(2));
  604. &mov ($key,&wparam(3));
  605. &mov ($rounds_,&wparam(4));
  606. &mov ($rounds,&wparam(5));
  607. &mov ($key_,"esp");
  608. &sub ("esp",60);
  609. &and ("esp",-16); # align stack
  610. &mov (&DWP(48,"esp"),$key_);
  611. &movdqu ($ivec,&QWP(0,$rounds_)); # load ivec
  612. &movdqu ($cmac,&QWP(0,$rounds)); # load cmac
  613. &mov ($rounds,&DWP(240,$key));
  614. # compose byte-swap control mask for pshufb on stack
  615. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  616. &mov (&DWP(4,"esp"),0x08090a0b);
  617. &mov (&DWP(8,"esp"),0x04050607);
  618. &mov (&DWP(12,"esp"),0x00010203);
  619. # compose counter increment vector on stack
  620. &mov ($rounds_,1);
  621. &xor ($key_,$key_);
  622. &mov (&DWP(16,"esp"),$rounds_);
  623. &mov (&DWP(20,"esp"),$key_);
  624. &mov (&DWP(24,"esp"),$key_);
  625. &mov (&DWP(28,"esp"),$key_);
  626. &movdqa ($inout3,&QWP(0,"esp")); # bswap mask
  627. &movdqa ($inout0,$ivec);
  628. &mov ($key_,$key);
  629. &mov ($rounds_,$rounds);
  630. &pshufb ($ivec,$inout3);
  631. if ($inline)
  632. { &aesni_inline_generate1("enc"); }
  633. else
  634. { &call ("_aesni_encrypt1"); }
  635. &movups ($in0,&QWP(0,$inp)); # load inp
  636. &paddq ($ivec,&QWP(16,"esp"));
  637. &lea ($inp,&QWP(16,$inp));
  638. &jmp (&label("ccm64_dec_outer"));
  639. &set_label("ccm64_dec_outer",16);
  640. &xorps ($in0,$inout0); # inp ^= E(ivec)
  641. &movdqa ($inout0,$ivec);
  642. &mov ($rounds,$rounds_);
  643. &movups (&QWP(0,$out),$in0); # save output
  644. &lea ($out,&DWP(16,$out));
  645. &pshufb ($inout0,$inout3);
  646. &sub ($len,1);
  647. &jz (&label("ccm64_dec_break"));
  648. &$movekey ($rndkey0,&QWP(0,$key_));
  649. &shr ($rounds,1);
  650. &$movekey ($rndkey1,&QWP(16,$key_));
  651. &xorps ($in0,$rndkey0);
  652. &lea ($key,&DWP(32,$key_));
  653. &xorps ($inout0,$rndkey0);
  654. &xorps ($cmac,$in0); # cmac^=out
  655. &$movekey ($rndkey0,&QWP(0,$key));
  656. &set_label("ccm64_dec2_loop");
  657. &aesenc ($inout0,$rndkey1);
  658. &dec ($rounds);
  659. &aesenc ($cmac,$rndkey1);
  660. &$movekey ($rndkey1,&QWP(16,$key));
  661. &aesenc ($inout0,$rndkey0);
  662. &lea ($key,&DWP(32,$key));
  663. &aesenc ($cmac,$rndkey0);
  664. &$movekey ($rndkey0,&QWP(0,$key));
  665. &jnz (&label("ccm64_dec2_loop"));
  666. &movups ($in0,&QWP(0,$inp)); # load inp
  667. &paddq ($ivec,&QWP(16,"esp"));
  668. &aesenc ($inout0,$rndkey1);
  669. &aesenc ($cmac,$rndkey1);
  670. &lea ($inp,&QWP(16,$inp));
  671. &aesenclast ($inout0,$rndkey0);
  672. &aesenclast ($cmac,$rndkey0);
  673. &jmp (&label("ccm64_dec_outer"));
  674. &set_label("ccm64_dec_break",16);
  675. &mov ($key,$key_);
  676. if ($inline)
  677. { &aesni_inline_generate1("enc",$cmac,$in0); }
  678. else
  679. { &call ("_aesni_encrypt1",$cmac); }
  680. &mov ("esp",&DWP(48,"esp"));
  681. &mov ($out,&wparam(5));
  682. &movups (&QWP(0,$out),$cmac);
  683. &function_end("aesni_ccm64_decrypt_blocks");
  684. }
  685. ######################################################################
  686. # void aesni_ctr32_encrypt_blocks (const void *in, void *out,
  687. # size_t blocks, const AES_KEY *key,
  688. # const char *ivec);
  689. #
  690. # Handles only complete blocks, operates on 32-bit counter and
  691. # does not update *ivec! (see engine/eng_aesni.c for details)
  692. #
  693. # stack layout:
  694. # 0 pshufb mask
  695. # 16 vector addend: 0,6,6,6
  696. # 32 counter-less ivec
  697. # 48 1st triplet of counter vector
  698. # 64 2nd triplet of counter vector
  699. # 80 saved %esp
  700. &function_begin("aesni_ctr32_encrypt_blocks");
  701. &mov ($inp,&wparam(0));
  702. &mov ($out,&wparam(1));
  703. &mov ($len,&wparam(2));
  704. &mov ($key,&wparam(3));
  705. &mov ($rounds_,&wparam(4));
  706. &mov ($key_,"esp");
  707. &sub ("esp",88);
  708. &and ("esp",-16); # align stack
  709. &mov (&DWP(80,"esp"),$key_);
  710. &cmp ($len,1);
  711. &je (&label("ctr32_one_shortcut"));
  712. &movdqu ($inout5,&QWP(0,$rounds_)); # load ivec
  713. # compose byte-swap control mask for pshufb on stack
  714. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  715. &mov (&DWP(4,"esp"),0x08090a0b);
  716. &mov (&DWP(8,"esp"),0x04050607);
  717. &mov (&DWP(12,"esp"),0x00010203);
  718. # compose counter increment vector on stack
  719. &mov ($rounds,6);
  720. &xor ($key_,$key_);
  721. &mov (&DWP(16,"esp"),$rounds);
  722. &mov (&DWP(20,"esp"),$rounds);
  723. &mov (&DWP(24,"esp"),$rounds);
  724. &mov (&DWP(28,"esp"),$key_);
  725. &pextrd ($rounds_,$inout5,3); # pull 32-bit counter
  726. &pinsrd ($inout5,$key_,3); # wipe 32-bit counter
  727. &mov ($rounds,&DWP(240,$key)); # key->rounds
  728. # compose 2 vectors of 3x32-bit counters
  729. &bswap ($rounds_);
  730. &pxor ($rndkey1,$rndkey1);
  731. &pxor ($rndkey0,$rndkey0);
  732. &movdqa ($inout0,&QWP(0,"esp")); # load byte-swap mask
  733. &pinsrd ($rndkey1,$rounds_,0);
  734. &lea ($key_,&DWP(3,$rounds_));
  735. &pinsrd ($rndkey0,$key_,0);
  736. &inc ($rounds_);
  737. &pinsrd ($rndkey1,$rounds_,1);
  738. &inc ($key_);
  739. &pinsrd ($rndkey0,$key_,1);
  740. &inc ($rounds_);
  741. &pinsrd ($rndkey1,$rounds_,2);
  742. &inc ($key_);
  743. &pinsrd ($rndkey0,$key_,2);
  744. &movdqa (&QWP(48,"esp"),$rndkey1); # save 1st triplet
  745. &pshufb ($rndkey1,$inout0); # byte swap
  746. &movdqa (&QWP(64,"esp"),$rndkey0); # save 2nd triplet
  747. &pshufb ($rndkey0,$inout0); # byte swap
  748. &pshufd ($inout0,$rndkey1,3<<6); # place counter to upper dword
  749. &pshufd ($inout1,$rndkey1,2<<6);
  750. &cmp ($len,6);
  751. &jb (&label("ctr32_tail"));
  752. &movdqa (&QWP(32,"esp"),$inout5); # save counter-less ivec
  753. &shr ($rounds,1);
  754. &mov ($key_,$key); # backup $key
  755. &mov ($rounds_,$rounds); # backup $rounds
  756. &sub ($len,6);
  757. &jmp (&label("ctr32_loop6"));
  758. &set_label("ctr32_loop6",16);
  759. &pshufd ($inout2,$rndkey1,1<<6);
  760. &movdqa ($rndkey1,&QWP(32,"esp")); # pull counter-less ivec
  761. &pshufd ($inout3,$rndkey0,3<<6);
  762. &por ($inout0,$rndkey1); # merge counter-less ivec
  763. &pshufd ($inout4,$rndkey0,2<<6);
  764. &por ($inout1,$rndkey1);
  765. &pshufd ($inout5,$rndkey0,1<<6);
  766. &por ($inout2,$rndkey1);
  767. &por ($inout3,$rndkey1);
  768. &por ($inout4,$rndkey1);
  769. &por ($inout5,$rndkey1);
  770. # inlining _aesni_encrypt6's prologue gives ~4% improvement...
  771. &$movekey ($rndkey0,&QWP(0,$key_));
  772. &$movekey ($rndkey1,&QWP(16,$key_));
  773. &lea ($key,&DWP(32,$key_));
  774. &dec ($rounds);
  775. &pxor ($inout0,$rndkey0);
  776. &pxor ($inout1,$rndkey0);
  777. &aesenc ($inout0,$rndkey1);
  778. &pxor ($inout2,$rndkey0);
  779. &aesenc ($inout1,$rndkey1);
  780. &pxor ($inout3,$rndkey0);
  781. &aesenc ($inout2,$rndkey1);
  782. &pxor ($inout4,$rndkey0);
  783. &aesenc ($inout3,$rndkey1);
  784. &pxor ($inout5,$rndkey0);
  785. &aesenc ($inout4,$rndkey1);
  786. &$movekey ($rndkey0,&QWP(0,$key));
  787. &aesenc ($inout5,$rndkey1);
  788. &call (&label("_aesni_encrypt6_enter"));
  789. &movups ($rndkey1,&QWP(0,$inp));
  790. &movups ($rndkey0,&QWP(0x10,$inp));
  791. &xorps ($inout0,$rndkey1);
  792. &movups ($rndkey1,&QWP(0x20,$inp));
  793. &xorps ($inout1,$rndkey0);
  794. &movups (&QWP(0,$out),$inout0);
  795. &movdqa ($rndkey0,&QWP(16,"esp")); # load increment
  796. &xorps ($inout2,$rndkey1);
  797. &movdqa ($rndkey1,&QWP(48,"esp")); # load 1st triplet
  798. &movups (&QWP(0x10,$out),$inout1);
  799. &movups (&QWP(0x20,$out),$inout2);
  800. &paddd ($rndkey1,$rndkey0); # 1st triplet increment
  801. &paddd ($rndkey0,&QWP(64,"esp")); # 2nd triplet increment
  802. &movdqa ($inout0,&QWP(0,"esp")); # load byte swap mask
  803. &movups ($inout1,&QWP(0x30,$inp));
  804. &movups ($inout2,&QWP(0x40,$inp));
  805. &xorps ($inout3,$inout1);
  806. &movups ($inout1,&QWP(0x50,$inp));
  807. &lea ($inp,&DWP(0x60,$inp));
  808. &movdqa (&QWP(48,"esp"),$rndkey1); # save 1st triplet
  809. &pshufb ($rndkey1,$inout0); # byte swap
  810. &xorps ($inout4,$inout2);
  811. &movups (&QWP(0x30,$out),$inout3);
  812. &xorps ($inout5,$inout1);
  813. &movdqa (&QWP(64,"esp"),$rndkey0); # save 2nd triplet
  814. &pshufb ($rndkey0,$inout0); # byte swap
  815. &movups (&QWP(0x40,$out),$inout4);
  816. &pshufd ($inout0,$rndkey1,3<<6);
  817. &movups (&QWP(0x50,$out),$inout5);
  818. &lea ($out,&DWP(0x60,$out));
  819. &mov ($rounds,$rounds_);
  820. &pshufd ($inout1,$rndkey1,2<<6);
  821. &sub ($len,6);
  822. &jnc (&label("ctr32_loop6"));
  823. &add ($len,6);
  824. &jz (&label("ctr32_ret"));
  825. &mov ($key,$key_);
  826. &lea ($rounds,&DWP(1,"",$rounds,2)); # restore $rounds
  827. &movdqa ($inout5,&QWP(32,"esp")); # pull count-less ivec
  828. &set_label("ctr32_tail");
  829. &por ($inout0,$inout5);
  830. &cmp ($len,2);
  831. &jb (&label("ctr32_one"));
  832. &pshufd ($inout2,$rndkey1,1<<6);
  833. &por ($inout1,$inout5);
  834. &je (&label("ctr32_two"));
  835. &pshufd ($inout3,$rndkey0,3<<6);
  836. &por ($inout2,$inout5);
  837. &cmp ($len,4);
  838. &jb (&label("ctr32_three"));
  839. &pshufd ($inout4,$rndkey0,2<<6);
  840. &por ($inout3,$inout5);
  841. &je (&label("ctr32_four"));
  842. &por ($inout4,$inout5);
  843. &call ("_aesni_encrypt6");
  844. &movups ($rndkey1,&QWP(0,$inp));
  845. &movups ($rndkey0,&QWP(0x10,$inp));
  846. &xorps ($inout0,$rndkey1);
  847. &movups ($rndkey1,&QWP(0x20,$inp));
  848. &xorps ($inout1,$rndkey0);
  849. &movups ($rndkey0,&QWP(0x30,$inp));
  850. &xorps ($inout2,$rndkey1);
  851. &movups ($rndkey1,&QWP(0x40,$inp));
  852. &xorps ($inout3,$rndkey0);
  853. &movups (&QWP(0,$out),$inout0);
  854. &xorps ($inout4,$rndkey1);
  855. &movups (&QWP(0x10,$out),$inout1);
  856. &movups (&QWP(0x20,$out),$inout2);
  857. &movups (&QWP(0x30,$out),$inout3);
  858. &movups (&QWP(0x40,$out),$inout4);
  859. &jmp (&label("ctr32_ret"));
  860. &set_label("ctr32_one_shortcut",16);
  861. &movups ($inout0,&QWP(0,$rounds_)); # load ivec
  862. &mov ($rounds,&DWP(240,$key));
  863. &set_label("ctr32_one");
  864. if ($inline)
  865. { &aesni_inline_generate1("enc"); }
  866. else
  867. { &call ("_aesni_encrypt1"); }
  868. &movups ($in0,&QWP(0,$inp));
  869. &xorps ($in0,$inout0);
  870. &movups (&QWP(0,$out),$in0);
  871. &jmp (&label("ctr32_ret"));
  872. &set_label("ctr32_two",16);
  873. &call ("_aesni_encrypt3");
  874. &movups ($inout3,&QWP(0,$inp));
  875. &movups ($inout4,&QWP(0x10,$inp));
  876. &xorps ($inout0,$inout3);
  877. &xorps ($inout1,$inout4);
  878. &movups (&QWP(0,$out),$inout0);
  879. &movups (&QWP(0x10,$out),$inout1);
  880. &jmp (&label("ctr32_ret"));
  881. &set_label("ctr32_three",16);
  882. &call ("_aesni_encrypt3");
  883. &movups ($inout3,&QWP(0,$inp));
  884. &movups ($inout4,&QWP(0x10,$inp));
  885. &xorps ($inout0,$inout3);
  886. &movups ($inout5,&QWP(0x20,$inp));
  887. &xorps ($inout1,$inout4);
  888. &movups (&QWP(0,$out),$inout0);
  889. &xorps ($inout2,$inout5);
  890. &movups (&QWP(0x10,$out),$inout1);
  891. &movups (&QWP(0x20,$out),$inout2);
  892. &jmp (&label("ctr32_ret"));
  893. &set_label("ctr32_four",16);
  894. &call ("_aesni_encrypt4");
  895. &movups ($inout4,&QWP(0,$inp));
  896. &movups ($inout5,&QWP(0x10,$inp));
  897. &movups ($rndkey1,&QWP(0x20,$inp));
  898. &xorps ($inout0,$inout4);
  899. &movups ($rndkey0,&QWP(0x30,$inp));
  900. &xorps ($inout1,$inout5);
  901. &movups (&QWP(0,$out),$inout0);
  902. &xorps ($inout2,$rndkey1);
  903. &movups (&QWP(0x10,$out),$inout1);
  904. &xorps ($inout3,$rndkey0);
  905. &movups (&QWP(0x20,$out),$inout2);
  906. &movups (&QWP(0x30,$out),$inout3);
  907. &set_label("ctr32_ret");
  908. &mov ("esp",&DWP(80,"esp"));
  909. &function_end("aesni_ctr32_encrypt_blocks");
  910. ######################################################################
  911. # void aesni_xts_[en|de]crypt(const char *inp,char *out,size_t len,
  912. # const AES_KEY *key1, const AES_KEY *key2
  913. # const unsigned char iv[16]);
  914. #
  915. { my ($tweak,$twtmp,$twres,$twmask)=($rndkey1,$rndkey0,$inout0,$inout1);
  916. &function_begin("aesni_xts_encrypt");
  917. &mov ($key,&wparam(4)); # key2
  918. &mov ($inp,&wparam(5)); # clear-text tweak
  919. &mov ($rounds,&DWP(240,$key)); # key2->rounds
  920. &movups ($inout0,&QWP(0,$inp));
  921. if ($inline)
  922. { &aesni_inline_generate1("enc"); }
  923. else
  924. { &call ("_aesni_encrypt1"); }
  925. &mov ($inp,&wparam(0));
  926. &mov ($out,&wparam(1));
  927. &mov ($len,&wparam(2));
  928. &mov ($key,&wparam(3)); # key1
  929. &mov ($key_,"esp");
  930. &sub ("esp",16*7+8);
  931. &mov ($rounds,&DWP(240,$key)); # key1->rounds
  932. &and ("esp",-16); # align stack
  933. &mov (&DWP(16*6+0,"esp"),0x87); # compose the magic constant
  934. &mov (&DWP(16*6+4,"esp"),0);
  935. &mov (&DWP(16*6+8,"esp"),1);
  936. &mov (&DWP(16*6+12,"esp"),0);
  937. &mov (&DWP(16*7+0,"esp"),$len); # save original $len
  938. &mov (&DWP(16*7+4,"esp"),$key_); # save original %esp
  939. &movdqa ($tweak,$inout0);
  940. &pxor ($twtmp,$twtmp);
  941. &movdqa ($twmask,&QWP(6*16,"esp")); # 0x0...010...87
  942. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  943. &and ($len,-16);
  944. &mov ($key_,$key); # backup $key
  945. &mov ($rounds_,$rounds); # backup $rounds
  946. &sub ($len,16*6);
  947. &jc (&label("xts_enc_short"));
  948. &shr ($rounds,1);
  949. &mov ($rounds_,$rounds);
  950. &jmp (&label("xts_enc_loop6"));
  951. &set_label("xts_enc_loop6",16);
  952. for ($i=0;$i<4;$i++) {
  953. &pshufd ($twres,$twtmp,0x13);
  954. &pxor ($twtmp,$twtmp);
  955. &movdqa (&QWP(16*$i,"esp"),$tweak);
  956. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  957. &pand ($twres,$twmask); # isolate carry and residue
  958. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  959. &pxor ($tweak,$twres);
  960. }
  961. &pshufd ($inout5,$twtmp,0x13);
  962. &movdqa (&QWP(16*$i++,"esp"),$tweak);
  963. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  964. &$movekey ($rndkey0,&QWP(0,$key_));
  965. &pand ($inout5,$twmask); # isolate carry and residue
  966. &movups ($inout0,&QWP(0,$inp)); # load input
  967. &pxor ($inout5,$tweak);
  968. # inline _aesni_encrypt6 prologue and flip xor with tweak and key[0]
  969. &movdqu ($inout1,&QWP(16*1,$inp));
  970. &xorps ($inout0,$rndkey0); # input^=rndkey[0]
  971. &movdqu ($inout2,&QWP(16*2,$inp));
  972. &pxor ($inout1,$rndkey0);
  973. &movdqu ($inout3,&QWP(16*3,$inp));
  974. &pxor ($inout2,$rndkey0);
  975. &movdqu ($inout4,&QWP(16*4,$inp));
  976. &pxor ($inout3,$rndkey0);
  977. &movdqu ($rndkey1,&QWP(16*5,$inp));
  978. &pxor ($inout4,$rndkey0);
  979. &lea ($inp,&DWP(16*6,$inp));
  980. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  981. &movdqa (&QWP(16*$i,"esp"),$inout5); # save last tweak
  982. &pxor ($inout5,$rndkey1);
  983. &$movekey ($rndkey1,&QWP(16,$key_));
  984. &lea ($key,&DWP(32,$key_));
  985. &pxor ($inout1,&QWP(16*1,"esp"));
  986. &aesenc ($inout0,$rndkey1);
  987. &pxor ($inout2,&QWP(16*2,"esp"));
  988. &aesenc ($inout1,$rndkey1);
  989. &pxor ($inout3,&QWP(16*3,"esp"));
  990. &dec ($rounds);
  991. &aesenc ($inout2,$rndkey1);
  992. &pxor ($inout4,&QWP(16*4,"esp"));
  993. &aesenc ($inout3,$rndkey1);
  994. &pxor ($inout5,$rndkey0);
  995. &aesenc ($inout4,$rndkey1);
  996. &$movekey ($rndkey0,&QWP(0,$key));
  997. &aesenc ($inout5,$rndkey1);
  998. &call (&label("_aesni_encrypt6_enter"));
  999. &movdqa ($tweak,&QWP(16*5,"esp")); # last tweak
  1000. &pxor ($twtmp,$twtmp);
  1001. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1002. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1003. &xorps ($inout1,&QWP(16*1,"esp"));
  1004. &movups (&QWP(16*0,$out),$inout0); # write output
  1005. &xorps ($inout2,&QWP(16*2,"esp"));
  1006. &movups (&QWP(16*1,$out),$inout1);
  1007. &xorps ($inout3,&QWP(16*3,"esp"));
  1008. &movups (&QWP(16*2,$out),$inout2);
  1009. &xorps ($inout4,&QWP(16*4,"esp"));
  1010. &movups (&QWP(16*3,$out),$inout3);
  1011. &xorps ($inout5,$tweak);
  1012. &movups (&QWP(16*4,$out),$inout4);
  1013. &pshufd ($twres,$twtmp,0x13);
  1014. &movups (&QWP(16*5,$out),$inout5);
  1015. &lea ($out,&DWP(16*6,$out));
  1016. &movdqa ($twmask,&QWP(16*6,"esp")); # 0x0...010...87
  1017. &pxor ($twtmp,$twtmp);
  1018. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1019. &pand ($twres,$twmask); # isolate carry and residue
  1020. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1021. &mov ($rounds,$rounds_); # restore $rounds
  1022. &pxor ($tweak,$twres);
  1023. &sub ($len,16*6);
  1024. &jnc (&label("xts_enc_loop6"));
  1025. &lea ($rounds,&DWP(1,"",$rounds,2)); # restore $rounds
  1026. &mov ($key,$key_); # restore $key
  1027. &mov ($rounds_,$rounds);
  1028. &set_label("xts_enc_short");
  1029. &add ($len,16*6);
  1030. &jz (&label("xts_enc_done6x"));
  1031. &movdqa ($inout3,$tweak); # put aside previous tweak
  1032. &cmp ($len,0x20);
  1033. &jb (&label("xts_enc_one"));
  1034. &pshufd ($twres,$twtmp,0x13);
  1035. &pxor ($twtmp,$twtmp);
  1036. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1037. &pand ($twres,$twmask); # isolate carry and residue
  1038. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1039. &pxor ($tweak,$twres);
  1040. &je (&label("xts_enc_two"));
  1041. &pshufd ($twres,$twtmp,0x13);
  1042. &pxor ($twtmp,$twtmp);
  1043. &movdqa ($inout4,$tweak); # put aside previous tweak
  1044. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1045. &pand ($twres,$twmask); # isolate carry and residue
  1046. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1047. &pxor ($tweak,$twres);
  1048. &cmp ($len,0x40);
  1049. &jb (&label("xts_enc_three"));
  1050. &pshufd ($twres,$twtmp,0x13);
  1051. &pxor ($twtmp,$twtmp);
  1052. &movdqa ($inout5,$tweak); # put aside previous tweak
  1053. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1054. &pand ($twres,$twmask); # isolate carry and residue
  1055. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1056. &pxor ($tweak,$twres);
  1057. &movdqa (&QWP(16*0,"esp"),$inout3);
  1058. &movdqa (&QWP(16*1,"esp"),$inout4);
  1059. &je (&label("xts_enc_four"));
  1060. &movdqa (&QWP(16*2,"esp"),$inout5);
  1061. &pshufd ($inout5,$twtmp,0x13);
  1062. &movdqa (&QWP(16*3,"esp"),$tweak);
  1063. &paddq ($tweak,$tweak); # &psllq($inout0,1);
  1064. &pand ($inout5,$twmask); # isolate carry and residue
  1065. &pxor ($inout5,$tweak);
  1066. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1067. &movdqu ($inout1,&QWP(16*1,$inp));
  1068. &movdqu ($inout2,&QWP(16*2,$inp));
  1069. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1070. &movdqu ($inout3,&QWP(16*3,$inp));
  1071. &pxor ($inout1,&QWP(16*1,"esp"));
  1072. &movdqu ($inout4,&QWP(16*4,$inp));
  1073. &pxor ($inout2,&QWP(16*2,"esp"));
  1074. &lea ($inp,&DWP(16*5,$inp));
  1075. &pxor ($inout3,&QWP(16*3,"esp"));
  1076. &movdqa (&QWP(16*4,"esp"),$inout5); # save last tweak
  1077. &pxor ($inout4,$inout5);
  1078. &call ("_aesni_encrypt6");
  1079. &movaps ($tweak,&QWP(16*4,"esp")); # last tweak
  1080. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1081. &xorps ($inout1,&QWP(16*1,"esp"));
  1082. &xorps ($inout2,&QWP(16*2,"esp"));
  1083. &movups (&QWP(16*0,$out),$inout0); # write output
  1084. &xorps ($inout3,&QWP(16*3,"esp"));
  1085. &movups (&QWP(16*1,$out),$inout1);
  1086. &xorps ($inout4,$tweak);
  1087. &movups (&QWP(16*2,$out),$inout2);
  1088. &movups (&QWP(16*3,$out),$inout3);
  1089. &movups (&QWP(16*4,$out),$inout4);
  1090. &lea ($out,&DWP(16*5,$out));
  1091. &jmp (&label("xts_enc_done"));
  1092. &set_label("xts_enc_one",16);
  1093. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1094. &lea ($inp,&DWP(16*1,$inp));
  1095. &xorps ($inout0,$inout3); # input^=tweak
  1096. if ($inline)
  1097. { &aesni_inline_generate1("enc"); }
  1098. else
  1099. { &call ("_aesni_encrypt1"); }
  1100. &xorps ($inout0,$inout3); # output^=tweak
  1101. &movups (&QWP(16*0,$out),$inout0); # write output
  1102. &lea ($out,&DWP(16*1,$out));
  1103. &movdqa ($tweak,$inout3); # last tweak
  1104. &jmp (&label("xts_enc_done"));
  1105. &set_label("xts_enc_two",16);
  1106. &movaps ($inout4,$tweak); # put aside last tweak
  1107. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1108. &movups ($inout1,&QWP(16*1,$inp));
  1109. &lea ($inp,&DWP(16*2,$inp));
  1110. &xorps ($inout0,$inout3); # input^=tweak
  1111. &xorps ($inout1,$inout4);
  1112. &xorps ($inout2,$inout2);
  1113. &call ("_aesni_encrypt3");
  1114. &xorps ($inout0,$inout3); # output^=tweak
  1115. &xorps ($inout1,$inout4);
  1116. &movups (&QWP(16*0,$out),$inout0); # write output
  1117. &movups (&QWP(16*1,$out),$inout1);
  1118. &lea ($out,&DWP(16*2,$out));
  1119. &movdqa ($tweak,$inout4); # last tweak
  1120. &jmp (&label("xts_enc_done"));
  1121. &set_label("xts_enc_three",16);
  1122. &movaps ($inout5,$tweak); # put aside last tweak
  1123. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1124. &movups ($inout1,&QWP(16*1,$inp));
  1125. &movups ($inout2,&QWP(16*2,$inp));
  1126. &lea ($inp,&DWP(16*3,$inp));
  1127. &xorps ($inout0,$inout3); # input^=tweak
  1128. &xorps ($inout1,$inout4);
  1129. &xorps ($inout2,$inout5);
  1130. &call ("_aesni_encrypt3");
  1131. &xorps ($inout0,$inout3); # output^=tweak
  1132. &xorps ($inout1,$inout4);
  1133. &xorps ($inout2,$inout5);
  1134. &movups (&QWP(16*0,$out),$inout0); # write output
  1135. &movups (&QWP(16*1,$out),$inout1);
  1136. &movups (&QWP(16*2,$out),$inout2);
  1137. &lea ($out,&DWP(16*3,$out));
  1138. &movdqa ($tweak,$inout5); # last tweak
  1139. &jmp (&label("xts_enc_done"));
  1140. &set_label("xts_enc_four",16);
  1141. &movaps ($inout4,$tweak); # put aside last tweak
  1142. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1143. &movups ($inout1,&QWP(16*1,$inp));
  1144. &movups ($inout2,&QWP(16*2,$inp));
  1145. &xorps ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1146. &movups ($inout3,&QWP(16*3,$inp));
  1147. &lea ($inp,&DWP(16*4,$inp));
  1148. &xorps ($inout1,&QWP(16*1,"esp"));
  1149. &xorps ($inout2,$inout5);
  1150. &xorps ($inout3,$inout4);
  1151. &call ("_aesni_encrypt4");
  1152. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1153. &xorps ($inout1,&QWP(16*1,"esp"));
  1154. &xorps ($inout2,$inout5);
  1155. &movups (&QWP(16*0,$out),$inout0); # write output
  1156. &xorps ($inout3,$inout4);
  1157. &movups (&QWP(16*1,$out),$inout1);
  1158. &movups (&QWP(16*2,$out),$inout2);
  1159. &movups (&QWP(16*3,$out),$inout3);
  1160. &lea ($out,&DWP(16*4,$out));
  1161. &movdqa ($tweak,$inout4); # last tweak
  1162. &jmp (&label("xts_enc_done"));
  1163. &set_label("xts_enc_done6x",16); # $tweak is pre-calculated
  1164. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1165. &and ($len,15);
  1166. &jz (&label("xts_enc_ret"));
  1167. &movdqa ($inout3,$tweak);
  1168. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1169. &jmp (&label("xts_enc_steal"));
  1170. &set_label("xts_enc_done",16);
  1171. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1172. &pxor ($twtmp,$twtmp);
  1173. &and ($len,15);
  1174. &jz (&label("xts_enc_ret"));
  1175. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1176. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1177. &pshufd ($inout3,$twtmp,0x13);
  1178. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1179. &pand ($inout3,&QWP(16*6,"esp")); # isolate carry and residue
  1180. &pxor ($inout3,$tweak);
  1181. &set_label("xts_enc_steal");
  1182. &movz ($rounds,&BP(0,$inp));
  1183. &movz ($key,&BP(-16,$out));
  1184. &lea ($inp,&DWP(1,$inp));
  1185. &mov (&BP(-16,$out),&LB($rounds));
  1186. &mov (&BP(0,$out),&LB($key));
  1187. &lea ($out,&DWP(1,$out));
  1188. &sub ($len,1);
  1189. &jnz (&label("xts_enc_steal"));
  1190. &sub ($out,&DWP(16*7+0,"esp")); # rewind $out
  1191. &mov ($key,$key_); # restore $key
  1192. &mov ($rounds,$rounds_); # restore $rounds
  1193. &movups ($inout0,&QWP(-16,$out)); # load input
  1194. &xorps ($inout0,$inout3); # input^=tweak
  1195. if ($inline)
  1196. { &aesni_inline_generate1("enc"); }
  1197. else
  1198. { &call ("_aesni_encrypt1"); }
  1199. &xorps ($inout0,$inout3); # output^=tweak
  1200. &movups (&QWP(-16,$out),$inout0); # write output
  1201. &set_label("xts_enc_ret");
  1202. &mov ("esp",&DWP(16*7+4,"esp")); # restore %esp
  1203. &function_end("aesni_xts_encrypt");
  1204. &function_begin("aesni_xts_decrypt");
  1205. &mov ($key,&wparam(4)); # key2
  1206. &mov ($inp,&wparam(5)); # clear-text tweak
  1207. &mov ($rounds,&DWP(240,$key)); # key2->rounds
  1208. &movups ($inout0,&QWP(0,$inp));
  1209. if ($inline)
  1210. { &aesni_inline_generate1("enc"); }
  1211. else
  1212. { &call ("_aesni_encrypt1"); }
  1213. &mov ($inp,&wparam(0));
  1214. &mov ($out,&wparam(1));
  1215. &mov ($len,&wparam(2));
  1216. &mov ($key,&wparam(3)); # key1
  1217. &mov ($key_,"esp");
  1218. &sub ("esp",16*7+8);
  1219. &and ("esp",-16); # align stack
  1220. &xor ($rounds_,$rounds_); # if(len%16) len-=16;
  1221. &test ($len,15);
  1222. &setnz (&LB($rounds_));
  1223. &shl ($rounds_,4);
  1224. &sub ($len,$rounds_);
  1225. &mov (&DWP(16*6+0,"esp"),0x87); # compose the magic constant
  1226. &mov (&DWP(16*6+4,"esp"),0);
  1227. &mov (&DWP(16*6+8,"esp"),1);
  1228. &mov (&DWP(16*6+12,"esp"),0);
  1229. &mov (&DWP(16*7+0,"esp"),$len); # save original $len
  1230. &mov (&DWP(16*7+4,"esp"),$key_); # save original %esp
  1231. &mov ($rounds,&DWP(240,$key)); # key1->rounds
  1232. &mov ($key_,$key); # backup $key
  1233. &mov ($rounds_,$rounds); # backup $rounds
  1234. &movdqa ($tweak,$inout0);
  1235. &pxor ($twtmp,$twtmp);
  1236. &movdqa ($twmask,&QWP(6*16,"esp")); # 0x0...010...87
  1237. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1238. &and ($len,-16);
  1239. &sub ($len,16*6);
  1240. &jc (&label("xts_dec_short"));
  1241. &shr ($rounds,1);
  1242. &mov ($rounds_,$rounds);
  1243. &jmp (&label("xts_dec_loop6"));
  1244. &set_label("xts_dec_loop6",16);
  1245. for ($i=0;$i<4;$i++) {
  1246. &pshufd ($twres,$twtmp,0x13);
  1247. &pxor ($twtmp,$twtmp);
  1248. &movdqa (&QWP(16*$i,"esp"),$tweak);
  1249. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1250. &pand ($twres,$twmask); # isolate carry and residue
  1251. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1252. &pxor ($tweak,$twres);
  1253. }
  1254. &pshufd ($inout5,$twtmp,0x13);
  1255. &movdqa (&QWP(16*$i++,"esp"),$tweak);
  1256. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1257. &$movekey ($rndkey0,&QWP(0,$key_));
  1258. &pand ($inout5,$twmask); # isolate carry and residue
  1259. &movups ($inout0,&QWP(0,$inp)); # load input
  1260. &pxor ($inout5,$tweak);
  1261. # inline _aesni_encrypt6 prologue and flip xor with tweak and key[0]
  1262. &movdqu ($inout1,&QWP(16*1,$inp));
  1263. &xorps ($inout0,$rndkey0); # input^=rndkey[0]
  1264. &movdqu ($inout2,&QWP(16*2,$inp));
  1265. &pxor ($inout1,$rndkey0);
  1266. &movdqu ($inout3,&QWP(16*3,$inp));
  1267. &pxor ($inout2,$rndkey0);
  1268. &movdqu ($inout4,&QWP(16*4,$inp));
  1269. &pxor ($inout3,$rndkey0);
  1270. &movdqu ($rndkey1,&QWP(16*5,$inp));
  1271. &pxor ($inout4,$rndkey0);
  1272. &lea ($inp,&DWP(16*6,$inp));
  1273. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1274. &movdqa (&QWP(16*$i,"esp"),$inout5); # save last tweak
  1275. &pxor ($inout5,$rndkey1);
  1276. &$movekey ($rndkey1,&QWP(16,$key_));
  1277. &lea ($key,&DWP(32,$key_));
  1278. &pxor ($inout1,&QWP(16*1,"esp"));
  1279. &aesdec ($inout0,$rndkey1);
  1280. &pxor ($inout2,&QWP(16*2,"esp"));
  1281. &aesdec ($inout1,$rndkey1);
  1282. &pxor ($inout3,&QWP(16*3,"esp"));
  1283. &dec ($rounds);
  1284. &aesdec ($inout2,$rndkey1);
  1285. &pxor ($inout4,&QWP(16*4,"esp"));
  1286. &aesdec ($inout3,$rndkey1);
  1287. &pxor ($inout5,$rndkey0);
  1288. &aesdec ($inout4,$rndkey1);
  1289. &$movekey ($rndkey0,&QWP(0,$key));
  1290. &aesdec ($inout5,$rndkey1);
  1291. &call (&label("_aesni_decrypt6_enter"));
  1292. &movdqa ($tweak,&QWP(16*5,"esp")); # last tweak
  1293. &pxor ($twtmp,$twtmp);
  1294. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1295. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1296. &xorps ($inout1,&QWP(16*1,"esp"));
  1297. &movups (&QWP(16*0,$out),$inout0); # write output
  1298. &xorps ($inout2,&QWP(16*2,"esp"));
  1299. &movups (&QWP(16*1,$out),$inout1);
  1300. &xorps ($inout3,&QWP(16*3,"esp"));
  1301. &movups (&QWP(16*2,$out),$inout2);
  1302. &xorps ($inout4,&QWP(16*4,"esp"));
  1303. &movups (&QWP(16*3,$out),$inout3);
  1304. &xorps ($inout5,$tweak);
  1305. &movups (&QWP(16*4,$out),$inout4);
  1306. &pshufd ($twres,$twtmp,0x13);
  1307. &movups (&QWP(16*5,$out),$inout5);
  1308. &lea ($out,&DWP(16*6,$out));
  1309. &movdqa ($twmask,&QWP(16*6,"esp")); # 0x0...010...87
  1310. &pxor ($twtmp,$twtmp);
  1311. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1312. &pand ($twres,$twmask); # isolate carry and residue
  1313. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1314. &mov ($rounds,$rounds_); # restore $rounds
  1315. &pxor ($tweak,$twres);
  1316. &sub ($len,16*6);
  1317. &jnc (&label("xts_dec_loop6"));
  1318. &lea ($rounds,&DWP(1,"",$rounds,2)); # restore $rounds
  1319. &mov ($key,$key_); # restore $key
  1320. &mov ($rounds_,$rounds);
  1321. &set_label("xts_dec_short");
  1322. &add ($len,16*6);
  1323. &jz (&label("xts_dec_done6x"));
  1324. &movdqa ($inout3,$tweak); # put aside previous tweak
  1325. &cmp ($len,0x20);
  1326. &jb (&label("xts_dec_one"));
  1327. &pshufd ($twres,$twtmp,0x13);
  1328. &pxor ($twtmp,$twtmp);
  1329. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1330. &pand ($twres,$twmask); # isolate carry and residue
  1331. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1332. &pxor ($tweak,$twres);
  1333. &je (&label("xts_dec_two"));
  1334. &pshufd ($twres,$twtmp,0x13);
  1335. &pxor ($twtmp,$twtmp);
  1336. &movdqa ($inout4,$tweak); # put aside previous tweak
  1337. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1338. &pand ($twres,$twmask); # isolate carry and residue
  1339. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1340. &pxor ($tweak,$twres);
  1341. &cmp ($len,0x40);
  1342. &jb (&label("xts_dec_three"));
  1343. &pshufd ($twres,$twtmp,0x13);
  1344. &pxor ($twtmp,$twtmp);
  1345. &movdqa ($inout5,$tweak); # put aside previous tweak
  1346. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1347. &pand ($twres,$twmask); # isolate carry and residue
  1348. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1349. &pxor ($tweak,$twres);
  1350. &movdqa (&QWP(16*0,"esp"),$inout3);
  1351. &movdqa (&QWP(16*1,"esp"),$inout4);
  1352. &je (&label("xts_dec_four"));
  1353. &movdqa (&QWP(16*2,"esp"),$inout5);
  1354. &pshufd ($inout5,$twtmp,0x13);
  1355. &movdqa (&QWP(16*3,"esp"),$tweak);
  1356. &paddq ($tweak,$tweak); # &psllq($inout0,1);
  1357. &pand ($inout5,$twmask); # isolate carry and residue
  1358. &pxor ($inout5,$tweak);
  1359. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1360. &movdqu ($inout1,&QWP(16*1,$inp));
  1361. &movdqu ($inout2,&QWP(16*2,$inp));
  1362. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1363. &movdqu ($inout3,&QWP(16*3,$inp));
  1364. &pxor ($inout1,&QWP(16*1,"esp"));
  1365. &movdqu ($inout4,&QWP(16*4,$inp));
  1366. &pxor ($inout2,&QWP(16*2,"esp"));
  1367. &lea ($inp,&DWP(16*5,$inp));
  1368. &pxor ($inout3,&QWP(16*3,"esp"));
  1369. &movdqa (&QWP(16*4,"esp"),$inout5); # save last tweak
  1370. &pxor ($inout4,$inout5);
  1371. &call ("_aesni_decrypt6");
  1372. &movaps ($tweak,&QWP(16*4,"esp")); # last tweak
  1373. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1374. &xorps ($inout1,&QWP(16*1,"esp"));
  1375. &xorps ($inout2,&QWP(16*2,"esp"));
  1376. &movups (&QWP(16*0,$out),$inout0); # write output
  1377. &xorps ($inout3,&QWP(16*3,"esp"));
  1378. &movups (&QWP(16*1,$out),$inout1);
  1379. &xorps ($inout4,$tweak);
  1380. &movups (&QWP(16*2,$out),$inout2);
  1381. &movups (&QWP(16*3,$out),$inout3);
  1382. &movups (&QWP(16*4,$out),$inout4);
  1383. &lea ($out,&DWP(16*5,$out));
  1384. &jmp (&label("xts_dec_done"));
  1385. &set_label("xts_dec_one",16);
  1386. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1387. &lea ($inp,&DWP(16*1,$inp));
  1388. &xorps ($inout0,$inout3); # input^=tweak
  1389. if ($inline)
  1390. { &aesni_inline_generate1("dec"); }
  1391. else
  1392. { &call ("_aesni_decrypt1"); }
  1393. &xorps ($inout0,$inout3); # output^=tweak
  1394. &movups (&QWP(16*0,$out),$inout0); # write output
  1395. &lea ($out,&DWP(16*1,$out));
  1396. &movdqa ($tweak,$inout3); # last tweak
  1397. &jmp (&label("xts_dec_done"));
  1398. &set_label("xts_dec_two",16);
  1399. &movaps ($inout4,$tweak); # put aside last tweak
  1400. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1401. &movups ($inout1,&QWP(16*1,$inp));
  1402. &lea ($inp,&DWP(16*2,$inp));
  1403. &xorps ($inout0,$inout3); # input^=tweak
  1404. &xorps ($inout1,$inout4);
  1405. &call ("_aesni_decrypt3");
  1406. &xorps ($inout0,$inout3); # output^=tweak
  1407. &xorps ($inout1,$inout4);
  1408. &movups (&QWP(16*0,$out),$inout0); # write output
  1409. &movups (&QWP(16*1,$out),$inout1);
  1410. &lea ($out,&DWP(16*2,$out));
  1411. &movdqa ($tweak,$inout4); # last tweak
  1412. &jmp (&label("xts_dec_done"));
  1413. &set_label("xts_dec_three",16);
  1414. &movaps ($inout5,$tweak); # put aside last tweak
  1415. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1416. &movups ($inout1,&QWP(16*1,$inp));
  1417. &movups ($inout2,&QWP(16*2,$inp));
  1418. &lea ($inp,&DWP(16*3,$inp));
  1419. &xorps ($inout0,$inout3); # input^=tweak
  1420. &xorps ($inout1,$inout4);
  1421. &xorps ($inout2,$inout5);
  1422. &call ("_aesni_decrypt3");
  1423. &xorps ($inout0,$inout3); # output^=tweak
  1424. &xorps ($inout1,$inout4);
  1425. &xorps ($inout2,$inout5);
  1426. &movups (&QWP(16*0,$out),$inout0); # write output
  1427. &movups (&QWP(16*1,$out),$inout1);
  1428. &movups (&QWP(16*2,$out),$inout2);
  1429. &lea ($out,&DWP(16*3,$out));
  1430. &movdqa ($tweak,$inout5); # last tweak
  1431. &jmp (&label("xts_dec_done"));
  1432. &set_label("xts_dec_four",16);
  1433. &movaps ($inout4,$tweak); # put aside last tweak
  1434. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1435. &movups ($inout1,&QWP(16*1,$inp));
  1436. &movups ($inout2,&QWP(16*2,$inp));
  1437. &xorps ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1438. &movups ($inout3,&QWP(16*3,$inp));
  1439. &lea ($inp,&DWP(16*4,$inp));
  1440. &xorps ($inout1,&QWP(16*1,"esp"));
  1441. &xorps ($inout2,$inout5);
  1442. &xorps ($inout3,$inout4);
  1443. &call ("_aesni_decrypt4");
  1444. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1445. &xorps ($inout1,&QWP(16*1,"esp"));
  1446. &xorps ($inout2,$inout5);
  1447. &movups (&QWP(16*0,$out),$inout0); # write output
  1448. &xorps ($inout3,$inout4);
  1449. &movups (&QWP(16*1,$out),$inout1);
  1450. &movups (&QWP(16*2,$out),$inout2);
  1451. &movups (&QWP(16*3,$out),$inout3);
  1452. &lea ($out,&DWP(16*4,$out));
  1453. &movdqa ($tweak,$inout4); # last tweak
  1454. &jmp (&label("xts_dec_done"));
  1455. &set_label("xts_dec_done6x",16); # $tweak is pre-calculated
  1456. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1457. &and ($len,15);
  1458. &jz (&label("xts_dec_ret"));
  1459. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1460. &jmp (&label("xts_dec_only_one_more"));
  1461. &set_label("xts_dec_done",16);
  1462. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1463. &pxor ($twtmp,$twtmp);
  1464. &and ($len,15);
  1465. &jz (&label("xts_dec_ret"));
  1466. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1467. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1468. &pshufd ($twres,$twtmp,0x13);
  1469. &pxor ($twtmp,$twtmp);
  1470. &movdqa ($twmask,&QWP(16*6,"esp"));
  1471. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1472. &pand ($twres,$twmask); # isolate carry and residue
  1473. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1474. &pxor ($tweak,$twres);
  1475. &set_label("xts_dec_only_one_more");
  1476. &pshufd ($inout3,$twtmp,0x13);
  1477. &movdqa ($inout4,$tweak); # put aside previous tweak
  1478. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1479. &pand ($inout3,$twmask); # isolate carry and residue
  1480. &pxor ($inout3,$tweak);
  1481. &mov ($key,$key_); # restore $key
  1482. &mov ($rounds,$rounds_); # restore $rounds
  1483. &movups ($inout0,&QWP(0,$inp)); # load input
  1484. &xorps ($inout0,$inout3); # input^=tweak
  1485. if ($inline)
  1486. { &aesni_inline_generate1("dec"); }
  1487. else
  1488. { &call ("_aesni_decrypt1"); }
  1489. &xorps ($inout0,$inout3); # output^=tweak
  1490. &movups (&QWP(0,$out),$inout0); # write output
  1491. &set_label("xts_dec_steal");
  1492. &movz ($rounds,&BP(16,$inp));
  1493. &movz ($key,&BP(0,$out));
  1494. &lea ($inp,&DWP(1,$inp));
  1495. &mov (&BP(0,$out),&LB($rounds));
  1496. &mov (&BP(16,$out),&LB($key));
  1497. &lea ($out,&DWP(1,$out));
  1498. &sub ($len,1);
  1499. &jnz (&label("xts_dec_steal"));
  1500. &sub ($out,&DWP(16*7+0,"esp")); # rewind $out
  1501. &mov ($key,$key_); # restore $key
  1502. &mov ($rounds,$rounds_); # restore $rounds
  1503. &movups ($inout0,&QWP(0,$out)); # load input
  1504. &xorps ($inout0,$inout4); # input^=tweak
  1505. if ($inline)
  1506. { &aesni_inline_generate1("dec"); }
  1507. else
  1508. { &call ("_aesni_decrypt1"); }
  1509. &xorps ($inout0,$inout4); # output^=tweak
  1510. &movups (&QWP(0,$out),$inout0); # write output
  1511. &set_label("xts_dec_ret");
  1512. &mov ("esp",&DWP(16*7+4,"esp")); # restore %esp
  1513. &function_end("aesni_xts_decrypt");
  1514. }
  1515. }
  1516. ######################################################################
  1517. # void $PREFIX_cbc_encrypt (const void *inp, void *out,
  1518. # size_t length, const AES_KEY *key,
  1519. # unsigned char *ivp,const int enc);
  1520. &function_begin("${PREFIX}_cbc_encrypt");
  1521. &mov ($inp,&wparam(0));
  1522. &mov ($rounds_,"esp");
  1523. &mov ($out,&wparam(1));
  1524. &sub ($rounds_,24);
  1525. &mov ($len,&wparam(2));
  1526. &and ($rounds_,-16);
  1527. &mov ($key,&wparam(3));
  1528. &mov ($key_,&wparam(4));
  1529. &test ($len,$len);
  1530. &jz (&label("cbc_abort"));
  1531. &cmp (&wparam(5),0);
  1532. &xchg ($rounds_,"esp"); # alloca
  1533. &movups ($ivec,&QWP(0,$key_)); # load IV
  1534. &mov ($rounds,&DWP(240,$key));
  1535. &mov ($key_,$key); # backup $key
  1536. &mov (&DWP(16,"esp"),$rounds_); # save original %esp
  1537. &mov ($rounds_,$rounds); # backup $rounds
  1538. &je (&label("cbc_decrypt"));
  1539. &movaps ($inout0,$ivec);
  1540. &cmp ($len,16);
  1541. &jb (&label("cbc_enc_tail"));
  1542. &sub ($len,16);
  1543. &jmp (&label("cbc_enc_loop"));
  1544. &set_label("cbc_enc_loop",16);
  1545. &movups ($ivec,&QWP(0,$inp)); # input actually
  1546. &lea ($inp,&DWP(16,$inp));
  1547. if ($inline)
  1548. { &aesni_inline_generate1("enc",$inout0,$ivec); }
  1549. else
  1550. { &xorps($inout0,$ivec); &call("_aesni_encrypt1"); }
  1551. &mov ($rounds,$rounds_); # restore $rounds
  1552. &mov ($key,$key_); # restore $key
  1553. &movups (&QWP(0,$out),$inout0); # store output
  1554. &lea ($out,&DWP(16,$out));
  1555. &sub ($len,16);
  1556. &jnc (&label("cbc_enc_loop"));
  1557. &add ($len,16);
  1558. &jnz (&label("cbc_enc_tail"));
  1559. &movaps ($ivec,$inout0);
  1560. &jmp (&label("cbc_ret"));
  1561. &set_label("cbc_enc_tail");
  1562. &mov ("ecx",$len); # zaps $rounds
  1563. &data_word(0xA4F3F689); # rep movsb
  1564. &mov ("ecx",16); # zero tail
  1565. &sub ("ecx",$len);
  1566. &xor ("eax","eax"); # zaps $len
  1567. &data_word(0xAAF3F689); # rep stosb
  1568. &lea ($out,&DWP(-16,$out)); # rewind $out by 1 block
  1569. &mov ($rounds,$rounds_); # restore $rounds
  1570. &mov ($inp,$out); # $inp and $out are the same
  1571. &mov ($key,$key_); # restore $key
  1572. &jmp (&label("cbc_enc_loop"));
  1573. ######################################################################
  1574. &set_label("cbc_decrypt",16);
  1575. &cmp ($len,0x50);
  1576. &jbe (&label("cbc_dec_tail"));
  1577. &movaps (&QWP(0,"esp"),$ivec); # save IV
  1578. &sub ($len,0x50);
  1579. &jmp (&label("cbc_dec_loop6_enter"));
  1580. &set_label("cbc_dec_loop6",16);
  1581. &movaps (&QWP(0,"esp"),$rndkey0); # save IV
  1582. &movups (&QWP(0,$out),$inout5);
  1583. &lea ($out,&DWP(0x10,$out));
  1584. &set_label("cbc_dec_loop6_enter");
  1585. &movdqu ($inout0,&QWP(0,$inp));
  1586. &movdqu ($inout1,&QWP(0x10,$inp));
  1587. &movdqu ($inout2,&QWP(0x20,$inp));
  1588. &movdqu ($inout3,&QWP(0x30,$inp));
  1589. &movdqu ($inout4,&QWP(0x40,$inp));
  1590. &movdqu ($inout5,&QWP(0x50,$inp));
  1591. &call ("_aesni_decrypt6");
  1592. &movups ($rndkey1,&QWP(0,$inp));
  1593. &movups ($rndkey0,&QWP(0x10,$inp));
  1594. &xorps ($inout0,&QWP(0,"esp")); # ^=IV
  1595. &xorps ($inout1,$rndkey1);
  1596. &movups ($rndkey1,&QWP(0x20,$inp));
  1597. &xorps ($inout2,$rndkey0);
  1598. &movups ($rndkey0,&QWP(0x30,$inp));
  1599. &xorps ($inout3,$rndkey1);
  1600. &movups ($rndkey1,&QWP(0x40,$inp));
  1601. &xorps ($inout4,$rndkey0);
  1602. &movups ($rndkey0,&QWP(0x50,$inp)); # IV
  1603. &xorps ($inout5,$rndkey1);
  1604. &movups (&QWP(0,$out),$inout0);
  1605. &movups (&QWP(0x10,$out),$inout1);
  1606. &lea ($inp,&DWP(0x60,$inp));
  1607. &movups (&QWP(0x20,$out),$inout2);
  1608. &mov ($rounds,$rounds_) # restore $rounds
  1609. &movups (&QWP(0x30,$out),$inout3);
  1610. &mov ($key,$key_); # restore $key
  1611. &movups (&QWP(0x40,$out),$inout4);
  1612. &lea ($out,&DWP(0x50,$out));
  1613. &sub ($len,0x60);
  1614. &ja (&label("cbc_dec_loop6"));
  1615. &movaps ($inout0,$inout5);
  1616. &movaps ($ivec,$rndkey0);
  1617. &add ($len,0x50);
  1618. &jle (&label("cbc_dec_tail_collected"));
  1619. &movups (&QWP(0,$out),$inout0);
  1620. &lea ($out,&DWP(0x10,$out));
  1621. &set_label("cbc_dec_tail");
  1622. &movups ($inout0,&QWP(0,$inp));
  1623. &movaps ($in0,$inout0);
  1624. &cmp ($len,0x10);
  1625. &jbe (&label("cbc_dec_one"));
  1626. &movups ($inout1,&QWP(0x10,$inp));
  1627. &movaps ($in1,$inout1);
  1628. &cmp ($len,0x20);
  1629. &jbe (&label("cbc_dec_two"));
  1630. &movups ($inout2,&QWP(0x20,$inp));
  1631. &cmp ($len,0x30);
  1632. &jbe (&label("cbc_dec_three"));
  1633. &movups ($inout3,&QWP(0x30,$inp));
  1634. &cmp ($len,0x40);
  1635. &jbe (&label("cbc_dec_four"));
  1636. &movups ($inout4,&QWP(0x40,$inp));
  1637. &movaps (&QWP(0,"esp"),$ivec); # save IV
  1638. &movups ($inout0,&QWP(0,$inp));
  1639. &xorps ($inout5,$inout5);
  1640. &call ("_aesni_decrypt6");
  1641. &movups ($rndkey1,&QWP(0,$inp));
  1642. &movups ($rndkey0,&QWP(0x10,$inp));
  1643. &xorps ($inout0,&QWP(0,"esp")); # ^= IV
  1644. &xorps ($inout1,$rndkey1);
  1645. &movups ($rndkey1,&QWP(0x20,$inp));
  1646. &xorps ($inout2,$rndkey0);
  1647. &movups ($rndkey0,&QWP(0x30,$inp));
  1648. &xorps ($inout3,$rndkey1);
  1649. &movups ($ivec,&QWP(0x40,$inp)); # IV
  1650. &xorps ($inout4,$rndkey0);
  1651. &movups (&QWP(0,$out),$inout0);
  1652. &movups (&QWP(0x10,$out),$inout1);
  1653. &movups (&QWP(0x20,$out),$inout2);
  1654. &movups (&QWP(0x30,$out),$inout3);
  1655. &lea ($out,&DWP(0x40,$out));
  1656. &movaps ($inout0,$inout4);
  1657. &sub ($len,0x50);
  1658. &jmp (&label("cbc_dec_tail_collected"));
  1659. &set_label("cbc_dec_one",16);
  1660. if ($inline)
  1661. { &aesni_inline_generate1("dec"); }
  1662. else
  1663. { &call ("_aesni_decrypt1"); }
  1664. &xorps ($inout0,$ivec);
  1665. &movaps ($ivec,$in0);
  1666. &sub ($len,0x10);
  1667. &jmp (&label("cbc_dec_tail_collected"));
  1668. &set_label("cbc_dec_two",16);
  1669. &xorps ($inout2,$inout2);
  1670. &call ("_aesni_decrypt3");
  1671. &xorps ($inout0,$ivec);
  1672. &xorps ($inout1,$in0);
  1673. &movups (&QWP(0,$out),$inout0);
  1674. &movaps ($inout0,$inout1);
  1675. &lea ($out,&DWP(0x10,$out));
  1676. &movaps ($ivec,$in1);
  1677. &sub ($len,0x20);
  1678. &jmp (&label("cbc_dec_tail_collected"));
  1679. &set_label("cbc_dec_three",16);
  1680. &call ("_aesni_decrypt3");
  1681. &xorps ($inout0,$ivec);
  1682. &xorps ($inout1,$in0);
  1683. &xorps ($inout2,$in1);
  1684. &movups (&QWP(0,$out),$inout0);
  1685. &movaps ($inout0,$inout2);
  1686. &movups (&QWP(0x10,$out),$inout1);
  1687. &lea ($out,&DWP(0x20,$out));
  1688. &movups ($ivec,&QWP(0x20,$inp));
  1689. &sub ($len,0x30);
  1690. &jmp (&label("cbc_dec_tail_collected"));
  1691. &set_label("cbc_dec_four",16);
  1692. &call ("_aesni_decrypt4");
  1693. &movups ($rndkey1,&QWP(0x10,$inp));
  1694. &movups ($rndkey0,&QWP(0x20,$inp));
  1695. &xorps ($inout0,$ivec);
  1696. &movups ($ivec,&QWP(0x30,$inp));
  1697. &xorps ($inout1,$in0);
  1698. &movups (&QWP(0,$out),$inout0);
  1699. &xorps ($inout2,$rndkey1);
  1700. &movups (&QWP(0x10,$out),$inout1);
  1701. &xorps ($inout3,$rndkey0);
  1702. &movups (&QWP(0x20,$out),$inout2);
  1703. &lea ($out,&DWP(0x30,$out));
  1704. &movaps ($inout0,$inout3);
  1705. &sub ($len,0x40);
  1706. &set_label("cbc_dec_tail_collected");
  1707. &and ($len,15);
  1708. &jnz (&label("cbc_dec_tail_partial"));
  1709. &movups (&QWP(0,$out),$inout0);
  1710. &jmp (&label("cbc_ret"));
  1711. &set_label("cbc_dec_tail_partial",16);
  1712. &movaps (&QWP(0,"esp"),$inout0);
  1713. &mov ("ecx",16);
  1714. &mov ($inp,"esp");
  1715. &sub ("ecx",$len);
  1716. &data_word(0xA4F3F689); # rep movsb
  1717. &set_label("cbc_ret");
  1718. &mov ("esp",&DWP(16,"esp")); # pull original %esp
  1719. &mov ($key_,&wparam(4));
  1720. &movups (&QWP(0,$key_),$ivec); # output IV
  1721. &set_label("cbc_abort");
  1722. &function_end("${PREFIX}_cbc_encrypt");
  1723. ######################################################################
  1724. # Mechanical port from aesni-x86_64.pl.
  1725. #
  1726. # _aesni_set_encrypt_key is private interface,
  1727. # input:
  1728. # "eax" const unsigned char *userKey
  1729. # $rounds int bits
  1730. # $key AES_KEY *key
  1731. # output:
  1732. # "eax" return code
  1733. # $round rounds
  1734. &function_begin_B("_aesni_set_encrypt_key");
  1735. &test ("eax","eax");
  1736. &jz (&label("bad_pointer"));
  1737. &test ($key,$key);
  1738. &jz (&label("bad_pointer"));
  1739. &movups ("xmm0",&QWP(0,"eax")); # pull first 128 bits of *userKey
  1740. &xorps ("xmm4","xmm4"); # low dword of xmm4 is assumed 0
  1741. &lea ($key,&DWP(16,$key));
  1742. &cmp ($rounds,256);
  1743. &je (&label("14rounds"));
  1744. &cmp ($rounds,192);
  1745. &je (&label("12rounds"));
  1746. &cmp ($rounds,128);
  1747. &jne (&label("bad_keybits"));
  1748. &set_label("10rounds",16);
  1749. &mov ($rounds,9);
  1750. &$movekey (&QWP(-16,$key),"xmm0"); # round 0
  1751. &aeskeygenassist("xmm1","xmm0",0x01); # round 1
  1752. &call (&label("key_128_cold"));
  1753. &aeskeygenassist("xmm1","xmm0",0x2); # round 2
  1754. &call (&label("key_128"));
  1755. &aeskeygenassist("xmm1","xmm0",0x04); # round 3
  1756. &call (&label("key_128"));
  1757. &aeskeygenassist("xmm1","xmm0",0x08); # round 4
  1758. &call (&label("key_128"));
  1759. &aeskeygenassist("xmm1","xmm0",0x10); # round 5
  1760. &call (&label("key_128"));
  1761. &aeskeygenassist("xmm1","xmm0",0x20); # round 6
  1762. &call (&label("key_128"));
  1763. &aeskeygenassist("xmm1","xmm0",0x40); # round 7
  1764. &call (&label("key_128"));
  1765. &aeskeygenassist("xmm1","xmm0",0x80); # round 8
  1766. &call (&label("key_128"));
  1767. &aeskeygenassist("xmm1","xmm0",0x1b); # round 9
  1768. &call (&label("key_128"));
  1769. &aeskeygenassist("xmm1","xmm0",0x36); # round 10
  1770. &call (&label("key_128"));
  1771. &$movekey (&QWP(0,$key),"xmm0");
  1772. &mov (&DWP(80,$key),$rounds);
  1773. &xor ("eax","eax");
  1774. &ret();
  1775. &set_label("key_128",16);
  1776. &$movekey (&QWP(0,$key),"xmm0");
  1777. &lea ($key,&DWP(16,$key));
  1778. &set_label("key_128_cold");
  1779. &shufps ("xmm4","xmm0",0b00010000);
  1780. &xorps ("xmm0","xmm4");
  1781. &shufps ("xmm4","xmm0",0b10001100);
  1782. &xorps ("xmm0","xmm4");
  1783. &shufps ("xmm1","xmm1",0b11111111); # critical path
  1784. &xorps ("xmm0","xmm1");
  1785. &ret();
  1786. &set_label("12rounds",16);
  1787. &movq ("xmm2",&QWP(16,"eax")); # remaining 1/3 of *userKey
  1788. &mov ($rounds,11);
  1789. &$movekey (&QWP(-16,$key),"xmm0") # round 0
  1790. &aeskeygenassist("xmm1","xmm2",0x01); # round 1,2
  1791. &call (&label("key_192a_cold"));
  1792. &aeskeygenassist("xmm1","xmm2",0x02); # round 2,3
  1793. &call (&label("key_192b"));
  1794. &aeskeygenassist("xmm1","xmm2",0x04); # round 4,5
  1795. &call (&label("key_192a"));
  1796. &aeskeygenassist("xmm1","xmm2",0x08); # round 5,6
  1797. &call (&label("key_192b"));
  1798. &aeskeygenassist("xmm1","xmm2",0x10); # round 7,8
  1799. &call (&label("key_192a"));
  1800. &aeskeygenassist("xmm1","xmm2",0x20); # round 8,9
  1801. &call (&label("key_192b"));
  1802. &aeskeygenassist("xmm1","xmm2",0x40); # round 10,11
  1803. &call (&label("key_192a"));
  1804. &aeskeygenassist("xmm1","xmm2",0x80); # round 11,12
  1805. &call (&label("key_192b"));
  1806. &$movekey (&QWP(0,$key),"xmm0");
  1807. &mov (&DWP(48,$key),$rounds);
  1808. &xor ("eax","eax");
  1809. &ret();
  1810. &set_label("key_192a",16);
  1811. &$movekey (&QWP(0,$key),"xmm0");
  1812. &lea ($key,&DWP(16,$key));
  1813. &set_label("key_192a_cold",16);
  1814. &movaps ("xmm5","xmm2");
  1815. &set_label("key_192b_warm");
  1816. &shufps ("xmm4","xmm0",0b00010000);
  1817. &movdqa ("xmm3","xmm2");
  1818. &xorps ("xmm0","xmm4");
  1819. &shufps ("xmm4","xmm0",0b10001100);
  1820. &pslldq ("xmm3",4);
  1821. &xorps ("xmm0","xmm4");
  1822. &pshufd ("xmm1","xmm1",0b01010101); # critical path
  1823. &pxor ("xmm2","xmm3");
  1824. &pxor ("xmm0","xmm1");
  1825. &pshufd ("xmm3","xmm0",0b11111111);
  1826. &pxor ("xmm2","xmm3");
  1827. &ret();
  1828. &set_label("key_192b",16);
  1829. &movaps ("xmm3","xmm0");
  1830. &shufps ("xmm5","xmm0",0b01000100);
  1831. &$movekey (&QWP(0,$key),"xmm5");
  1832. &shufps ("xmm3","xmm2",0b01001110);
  1833. &$movekey (&QWP(16,$key),"xmm3");
  1834. &lea ($key,&DWP(32,$key));
  1835. &jmp (&label("key_192b_warm"));
  1836. &set_label("14rounds",16);
  1837. &movups ("xmm2",&QWP(16,"eax")); # remaining half of *userKey
  1838. &mov ($rounds,13);
  1839. &lea ($key,&DWP(16,$key));
  1840. &$movekey (&QWP(-32,$key),"xmm0"); # round 0
  1841. &$movekey (&QWP(-16,$key),"xmm2"); # round 1
  1842. &aeskeygenassist("xmm1","xmm2",0x01); # round 2
  1843. &call (&label("key_256a_cold"));
  1844. &aeskeygenassist("xmm1","xmm0",0x01); # round 3
  1845. &call (&label("key_256b"));
  1846. &aeskeygenassist("xmm1","xmm2",0x02); # round 4
  1847. &call (&label("key_256a"));
  1848. &aeskeygenassist("xmm1","xmm0",0x02); # round 5
  1849. &call (&label("key_256b"));
  1850. &aeskeygenassist("xmm1","xmm2",0x04); # round 6
  1851. &call (&label("key_256a"));
  1852. &aeskeygenassist("xmm1","xmm0",0x04); # round 7
  1853. &call (&label("key_256b"));
  1854. &aeskeygenassist("xmm1","xmm2",0x08); # round 8
  1855. &call (&label("key_256a"));
  1856. &aeskeygenassist("xmm1","xmm0",0x08); # round 9
  1857. &call (&label("key_256b"));
  1858. &aeskeygenassist("xmm1","xmm2",0x10); # round 10
  1859. &call (&label("key_256a"));
  1860. &aeskeygenassist("xmm1","xmm0",0x10); # round 11
  1861. &call (&label("key_256b"));
  1862. &aeskeygenassist("xmm1","xmm2",0x20); # round 12
  1863. &call (&label("key_256a"));
  1864. &aeskeygenassist("xmm1","xmm0",0x20); # round 13
  1865. &call (&label("key_256b"));
  1866. &aeskeygenassist("xmm1","xmm2",0x40); # round 14
  1867. &call (&label("key_256a"));
  1868. &$movekey (&QWP(0,$key),"xmm0");
  1869. &mov (&DWP(16,$key),$rounds);
  1870. &xor ("eax","eax");
  1871. &ret();
  1872. &set_label("key_256a",16);
  1873. &$movekey (&QWP(0,$key),"xmm2");
  1874. &lea ($key,&DWP(16,$key));
  1875. &set_label("key_256a_cold");
  1876. &shufps ("xmm4","xmm0",0b00010000);
  1877. &xorps ("xmm0","xmm4");
  1878. &shufps ("xmm4","xmm0",0b10001100);
  1879. &xorps ("xmm0","xmm4");
  1880. &shufps ("xmm1","xmm1",0b11111111); # critical path
  1881. &xorps ("xmm0","xmm1");
  1882. &ret();
  1883. &set_label("key_256b",16);
  1884. &$movekey (&QWP(0,$key),"xmm0");
  1885. &lea ($key,&DWP(16,$key));
  1886. &shufps ("xmm4","xmm2",0b00010000);
  1887. &xorps ("xmm2","xmm4");
  1888. &shufps ("xmm4","xmm2",0b10001100);
  1889. &xorps ("xmm2","xmm4");
  1890. &shufps ("xmm1","xmm1",0b10101010); # critical path
  1891. &xorps ("xmm2","xmm1");
  1892. &ret();
  1893. &set_label("bad_pointer",4);
  1894. &mov ("eax",-1);
  1895. &ret ();
  1896. &set_label("bad_keybits",4);
  1897. &mov ("eax",-2);
  1898. &ret ();
  1899. &function_end_B("_aesni_set_encrypt_key");
  1900. # int $PREFIX_set_encrypt_key (const unsigned char *userKey, int bits,
  1901. # AES_KEY *key)
  1902. &function_begin_B("${PREFIX}_set_encrypt_key");
  1903. &mov ("eax",&wparam(0));
  1904. &mov ($rounds,&wparam(1));
  1905. &mov ($key,&wparam(2));
  1906. &call ("_aesni_set_encrypt_key");
  1907. &ret ();
  1908. &function_end_B("${PREFIX}_set_encrypt_key");
  1909. # int $PREFIX_set_decrypt_key (const unsigned char *userKey, int bits,
  1910. # AES_KEY *key)
  1911. &function_begin_B("${PREFIX}_set_decrypt_key");
  1912. &mov ("eax",&wparam(0));
  1913. &mov ($rounds,&wparam(1));
  1914. &mov ($key,&wparam(2));
  1915. &call ("_aesni_set_encrypt_key");
  1916. &mov ($key,&wparam(2));
  1917. &shl ($rounds,4) # rounds-1 after _aesni_set_encrypt_key
  1918. &test ("eax","eax");
  1919. &jnz (&label("dec_key_ret"));
  1920. &lea ("eax",&DWP(16,$key,$rounds)); # end of key schedule
  1921. &$movekey ("xmm0",&QWP(0,$key)); # just swap
  1922. &$movekey ("xmm1",&QWP(0,"eax"));
  1923. &$movekey (&QWP(0,"eax"),"xmm0");
  1924. &$movekey (&QWP(0,$key),"xmm1");
  1925. &lea ($key,&DWP(16,$key));
  1926. &lea ("eax",&DWP(-16,"eax"));
  1927. &set_label("dec_key_inverse");
  1928. &$movekey ("xmm0",&QWP(0,$key)); # swap and inverse
  1929. &$movekey ("xmm1",&QWP(0,"eax"));
  1930. &aesimc ("xmm0","xmm0");
  1931. &aesimc ("xmm1","xmm1");
  1932. &lea ($key,&DWP(16,$key));
  1933. &lea ("eax",&DWP(-16,"eax"));
  1934. &$movekey (&QWP(16,"eax"),"xmm0");
  1935. &$movekey (&QWP(-16,$key),"xmm1");
  1936. &cmp ("eax",$key);
  1937. &ja (&label("dec_key_inverse"));
  1938. &$movekey ("xmm0",&QWP(0,$key)); # inverse middle
  1939. &aesimc ("xmm0","xmm0");
  1940. &$movekey (&QWP(0,$key),"xmm0");
  1941. &xor ("eax","eax"); # return success
  1942. &set_label("dec_key_ret");
  1943. &ret ();
  1944. &function_end_B("${PREFIX}_set_decrypt_key");
  1945. &asciz("AES for Intel AES-NI, CRYPTOGAMS by <appro\@openssl.org>");
  1946. &asm_finish();