cipher_wrap.h 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178
  1. /**
  2. * \file cipher_wrap.h
  3. *
  4. * \brief Cipher wrappers.
  5. *
  6. * \author Adriaan de Jong <[email protected]>
  7. */
  8. /*
  9. * Copyright The Mbed TLS Contributors
  10. * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
  11. */
  12. #ifndef MBEDTLS_CIPHER_WRAP_H
  13. #define MBEDTLS_CIPHER_WRAP_H
  14. #include "mbedtls/build_info.h"
  15. #include "mbedtls/cipher.h"
  16. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  17. #include "psa/crypto.h"
  18. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  19. #ifdef __cplusplus
  20. extern "C" {
  21. #endif
  22. /* Support for GCM either through Mbed TLS SW implementation or PSA */
  23. #if defined(MBEDTLS_GCM_C) || \
  24. (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_GCM))
  25. #define MBEDTLS_CIPHER_HAVE_GCM_VIA_LEGACY_OR_USE_PSA
  26. #endif
  27. #if (defined(MBEDTLS_GCM_C) && defined(MBEDTLS_AES_C)) || \
  28. (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_GCM) && defined(PSA_WANT_KEY_TYPE_AES))
  29. #define MBEDTLS_CIPHER_HAVE_GCM_AES_VIA_LEGACY_OR_USE_PSA
  30. #endif
  31. #if defined(MBEDTLS_CCM_C) || \
  32. (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_CCM))
  33. #define MBEDTLS_CIPHER_HAVE_CCM_VIA_LEGACY_OR_USE_PSA
  34. #endif
  35. #if (defined(MBEDTLS_CCM_C) && defined(MBEDTLS_AES_C)) || \
  36. (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_CCM) && defined(PSA_WANT_KEY_TYPE_AES))
  37. #define MBEDTLS_CIPHER_HAVE_CCM_AES_VIA_LEGACY_OR_USE_PSA
  38. #endif
  39. #if defined(MBEDTLS_CCM_C) || \
  40. (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_CCM_STAR_NO_TAG))
  41. #define MBEDTLS_CIPHER_HAVE_CCM_STAR_NO_TAG_VIA_LEGACY_OR_USE_PSA
  42. #endif
  43. #if (defined(MBEDTLS_CCM_C) && defined(MBEDTLS_AES_C)) || \
  44. (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_CCM_STAR_NO_TAG) && \
  45. defined(PSA_WANT_KEY_TYPE_AES))
  46. #define MBEDTLS_CIPHER_HAVE_CCM_STAR_NO_TAG_AES_VIA_LEGACY_OR_USE_PSA
  47. #endif
  48. #if defined(MBEDTLS_CHACHAPOLY_C) || \
  49. (defined(MBEDTLS_USE_PSA_CRYPTO) && defined(PSA_WANT_ALG_CHACHA20_POLY1305))
  50. #define MBEDTLS_CIPHER_HAVE_CHACHAPOLY_VIA_LEGACY_OR_USE_PSA
  51. #endif
  52. #if defined(MBEDTLS_CIPHER_HAVE_GCM_VIA_LEGACY_OR_USE_PSA) || \
  53. defined(MBEDTLS_CIPHER_HAVE_CCM_VIA_LEGACY_OR_USE_PSA) || \
  54. defined(MBEDTLS_CIPHER_HAVE_CCM_STAR_NO_TAG_VIA_LEGACY_OR_USE_PSA) || \
  55. defined(MBEDTLS_CIPHER_HAVE_CHACHAPOLY_VIA_LEGACY_OR_USE_PSA)
  56. #define MBEDTLS_CIPHER_HAVE_SOME_AEAD_VIA_LEGACY_OR_USE_PSA
  57. #endif
  58. /**
  59. * Base cipher information. The non-mode specific functions and values.
  60. */
  61. struct mbedtls_cipher_base_t {
  62. /** Base Cipher type (e.g. MBEDTLS_CIPHER_ID_AES) */
  63. mbedtls_cipher_id_t cipher;
  64. /** Encrypt using ECB */
  65. int (*ecb_func)(void *ctx, mbedtls_operation_t mode,
  66. const unsigned char *input, unsigned char *output);
  67. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  68. /** Encrypt using CBC */
  69. int (*cbc_func)(void *ctx, mbedtls_operation_t mode, size_t length,
  70. unsigned char *iv, const unsigned char *input,
  71. unsigned char *output);
  72. #endif
  73. #if defined(MBEDTLS_CIPHER_MODE_CFB)
  74. /** Encrypt using CFB (Full length) */
  75. int (*cfb_func)(void *ctx, mbedtls_operation_t mode, size_t length, size_t *iv_off,
  76. unsigned char *iv, const unsigned char *input,
  77. unsigned char *output);
  78. #endif
  79. #if defined(MBEDTLS_CIPHER_MODE_OFB)
  80. /** Encrypt using OFB (Full length) */
  81. int (*ofb_func)(void *ctx, size_t length, size_t *iv_off,
  82. unsigned char *iv,
  83. const unsigned char *input,
  84. unsigned char *output);
  85. #endif
  86. #if defined(MBEDTLS_CIPHER_MODE_CTR)
  87. /** Encrypt using CTR */
  88. int (*ctr_func)(void *ctx, size_t length, size_t *nc_off,
  89. unsigned char *nonce_counter, unsigned char *stream_block,
  90. const unsigned char *input, unsigned char *output);
  91. #endif
  92. #if defined(MBEDTLS_CIPHER_MODE_XTS)
  93. /** Encrypt or decrypt using XTS. */
  94. int (*xts_func)(void *ctx, mbedtls_operation_t mode, size_t length,
  95. const unsigned char data_unit[16],
  96. const unsigned char *input, unsigned char *output);
  97. #endif
  98. #if defined(MBEDTLS_CIPHER_MODE_STREAM)
  99. /** Encrypt using STREAM */
  100. int (*stream_func)(void *ctx, size_t length,
  101. const unsigned char *input, unsigned char *output);
  102. #endif
  103. /** Set key for encryption purposes */
  104. int (*setkey_enc_func)(void *ctx, const unsigned char *key,
  105. unsigned int key_bitlen);
  106. #if !defined(MBEDTLS_BLOCK_CIPHER_NO_DECRYPT)
  107. /** Set key for decryption purposes */
  108. int (*setkey_dec_func)(void *ctx, const unsigned char *key,
  109. unsigned int key_bitlen);
  110. #endif
  111. /** Allocate a new context */
  112. void * (*ctx_alloc_func)(void);
  113. /** Free the given context */
  114. void (*ctx_free_func)(void *ctx);
  115. };
  116. typedef struct {
  117. mbedtls_cipher_type_t type;
  118. const mbedtls_cipher_info_t *info;
  119. } mbedtls_cipher_definition_t;
  120. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  121. typedef enum {
  122. MBEDTLS_CIPHER_PSA_KEY_UNSET = 0,
  123. MBEDTLS_CIPHER_PSA_KEY_OWNED, /* Used for PSA-based cipher contexts which */
  124. /* use raw key material internally imported */
  125. /* as a volatile key, and which hence need */
  126. /* to destroy that key when the context is */
  127. /* freed. */
  128. MBEDTLS_CIPHER_PSA_KEY_NOT_OWNED, /* Used for PSA-based cipher contexts */
  129. /* which use a key provided by the */
  130. /* user, and which hence will not be */
  131. /* destroyed when the context is freed. */
  132. } mbedtls_cipher_psa_key_ownership;
  133. typedef struct {
  134. psa_algorithm_t alg;
  135. mbedtls_svc_key_id_t slot;
  136. mbedtls_cipher_psa_key_ownership slot_state;
  137. } mbedtls_cipher_context_psa;
  138. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  139. extern const mbedtls_cipher_definition_t mbedtls_cipher_definitions[];
  140. extern int mbedtls_cipher_supported[];
  141. extern const mbedtls_cipher_base_t *mbedtls_cipher_base_lookup_table[];
  142. #ifdef __cplusplus
  143. }
  144. #endif
  145. #endif /* MBEDTLS_CIPHER_WRAP_H */