18 #include <picotls/openssl.h> 25 const void *, size_t);
32 ptls_cipher_context_t
super;
45 uint8_t
iv[PTLS_MAX_IV_SIZE];
46 uint8_t static_iv[PTLS_MAX_IV_SIZE];
55 if (!strcmp (ctx->
super.algo->name,
"AES128-CTR"))
57 id = VNET_CRYPTO_OP_AES_128_CTR_ENC;
59 else if (!strcmp (ctx->
super.algo->name,
"AES256-CTR"))
61 id = VNET_CRYPTO_OP_AES_256_CTR_ENC;
65 TLS_DBG (1,
"%s, Invalid crypto cipher : ", __FUNCTION__,
83 const void *input,
size_t _len)
98 const EVP_CIPHER * cipher,
105 ctx->
super.do_transform = do_transform;
109 if (!strcmp (ctx->
super.algo->name,
"AES128-CTR"))
111 algo = VNET_CRYPTO_ALG_AES_128_CTR;
113 else if (!strcmp (ctx->
super.algo->name,
"AES256-CTR"))
115 algo = VNET_CRYPTO_ALG_AES_256_CTR;
119 TLS_DBG (1,
"%s, Invalid crypto cipher : ", __FUNCTION__,
126 (
u8 *) key, _ctx->algo->key_size);
134 const void *input,
size_t inlen, uint64_t seq,
135 const void *aad,
size_t aadlen)
139 int tag_size = ctx->
super.algo->tag_size;
141 ctx->
op.
dst = _output;
142 ctx->
op.
src = (
void *) input;
143 ctx->
op.
len = inlen - tag_size;;
146 ctx->
op.
aad = (
void *) aad;
148 ctx->
op.
tag = (
void *) input + inlen - tag_size;
154 return inlen - tag_size;
159 const void *aad,
size_t aadlen)
164 ctx->
op.
aad = (
void *) aad;
174 const void *input,
size_t inlen)
192 ctx->
op.
tag = _output;
198 return ctx->
super.algo->tag_size;
209 const void *
key,
const void *
iv,
218 if (alg == VNET_CRYPTO_ALG_AES_128_GCM)
225 else if (alg == VNET_CRYPTO_ALG_AES_256_GCM)
236 TLS_DBG (1,
"%s, invalied aead cipher %s", __FUNCTION__,
261 int is_enc,
const void *
key)
269 int is_enc,
const void *
key)
277 int is_enc,
const void *
key,
281 VNET_CRYPTO_ALG_AES_128_GCM);
286 int is_enc,
const void *
key,
290 VNET_CRYPTO_ALG_AES_256_GCM);
293 ptls_cipher_algorithm_t ptls_vpp_crypto_aes128ctr = {
295 PTLS_AES128_KEY_SIZE,
299 ptls_vpp_crypto_aes128ctr_setup_crypto
302 ptls_cipher_algorithm_t ptls_vpp_crypto_aes256ctr = {
304 PTLS_AES256_KEY_SIZE,
308 ptls_vpp_crypto_aes256ctr_setup_crypto
311 ptls_aead_algorithm_t ptls_vpp_crypto_aes128gcm = {
313 PTLS_AESGCM_CONFIDENTIALITY_LIMIT,
314 PTLS_AESGCM_INTEGRITY_LIMIT,
317 PTLS_AES128_KEY_SIZE,
319 PTLS_AESGCM_TAG_SIZE,
321 ptls_vpp_crypto_aead_aes128gcm_setup_crypto
324 ptls_aead_algorithm_t ptls_vpp_crypto_aes256gcm = {
326 PTLS_AESGCM_CONFIDENTIALITY_LIMIT,
327 PTLS_AESGCM_INTEGRITY_LIMIT,
330 PTLS_AES256_KEY_SIZE,
332 PTLS_AESGCM_TAG_SIZE,
334 ptls_vpp_crypto_aead_aes256gcm_setup_crypto
337 ptls_cipher_suite_t ptls_vpp_crypto_aes128gcmsha256 =
338 { PTLS_CIPHER_SUITE_AES_128_GCM_SHA256,
343 ptls_cipher_suite_t ptls_vpp_crypto_aes256gcmsha384 =
344 { PTLS_CIPHER_SUITE_AES_256_GCM_SHA384,
349 ptls_cipher_suite_t *ptls_vpp_crypto_cipher_suites[] =
u32 vnet_crypto_process_ops(vlib_main_t *vm, vnet_crypto_op_t ops[], u32 n_ops)
static size_t ptls_vpp_crypto_aead_encrypt_update(ptls_aead_context_t *_ctx, void *output, const void *input, size_t inlen)
ptls_cipher_context_t super
size_t ptls_vpp_crypto_aead_decrypt(ptls_aead_context_t *_ctx, void *_output, const void *input, size_t inlen, uint64_t seq, const void *aad, size_t aadlen)
static void ptls_vpp_crypto_aead_dispose_crypto(ptls_aead_context_t *_ctx)
ptls_cipher_suite_t ptls_vpp_crypto_aes128gcmsha256
static void clib_rwlock_writer_lock(clib_rwlock_t *p)
static void ptls_vpp_crypto_cipher_do_init(ptls_cipher_context_t *_ctx, const void *iv)
#define VNET_CRYPTO_OP_FLAG_CHAINED_BUFFERS
static void ptls_vpp_crypto_aead_encrypt_init(ptls_aead_context_t *_ctx, uint64_t seq, const void *aad, size_t aadlen)
ptls_aead_algorithm_t ptls_vpp_crypto_aes128gcm
ptls_cipher_suite_t ptls_vpp_crypto_aes256gcmsha384
void(* ptls_vpp_do_transform_fn)(ptls_cipher_context_t *, void *, const void *, size_t)
#define clib_memcpy(d, s, n)
static void ptls_vpp_crypto_cipher_dispose(ptls_cipher_context_t *_ctx)
static_always_inline void vnet_crypto_op_init(vnet_crypto_op_t *op, vnet_crypto_op_id_t type)
uint8_t iv[PTLS_MAX_IV_SIZE]
u32 vnet_crypto_key_add(vlib_main_t *vm, vnet_crypto_alg_t alg, u8 *data, u16 length)
static void ptls_vpp_crypto_cipher_encrypt(ptls_cipher_context_t *_ctx, void *output, const void *input, size_t _len)
ptls_cipher_algorithm_t ptls_vpp_crypto_aes256ctr
vlib_main_t * vm
X-connect all packets from the HOST to the PHY.
static int ptls_vpp_crypto_cipher_setup_crypto(ptls_cipher_context_t *_ctx, int is_enc, const void *key, const EVP_CIPHER *cipher, ptls_vpp_do_transform_fn do_transform)
static void clib_rwlock_writer_unlock(clib_rwlock_t *p)
ptls_cipher_algorithm_t ptls_vpp_crypto_aes128ctr
clib_rwlock_t crypto_keys_rw_lock
static int ptls_vpp_crypto_aes128ctr_setup_crypto(ptls_cipher_context_t *ctx, int is_enc, const void *key)
static int ptls_vpp_crypto_aead_aes256gcm_setup_crypto(ptls_aead_context_t *ctx, int is_enc, const void *key, const void *iv)
picotls_main_t picotls_main
u32 vnet_crypto_process_chained_ops(vlib_main_t *vm, vnet_crypto_op_t ops[], vnet_crypto_op_chunk_t *chunks, u32 n_ops)
static int ptls_vpp_crypto_aead_aes128gcm_setup_crypto(ptls_aead_context_t *ctx, int is_enc, const void *key, const void *iv)
static vlib_main_t * vlib_get_main(void)
static size_t ptls_vpp_crypto_aead_encrypt_final(ptls_aead_context_t *_ctx, void *_output)
ptls_aead_context_t super
ptls_aead_algorithm_t ptls_vpp_crypto_aes256gcm
vnet_crypto_op_chunk_t chunks[2]
vnet_crypto_op_status_t status
uint8_t static_iv[PTLS_MAX_IV_SIZE]
vnet_crypto_main_t crypto_main
static int ptls_vpp_crypto_aead_setup_crypto(ptls_aead_context_t *_ctx, int is_enc, const void *key, const void *iv, vnet_crypto_alg_t alg)
#define TLS_DBG(_lvl, _fmt, _args...)
static int ptls_vpp_crypto_aes256ctr_setup_crypto(ptls_cipher_context_t *ctx, int is_enc, const void *key)