1 /* SPDX-License-Identifier: BSD-3-Clause
2  *
3  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
4  *   Copyright 2016 NXP
5  *
6  */
7 
8 #ifndef _RTE_DPAA2_SEC_PMD_PRIVATE_H_
9 #define _RTE_DPAA2_SEC_PMD_PRIVATE_H_
10 
11 #include <rte_security_driver.h>
12 
13 #define CRYPTODEV_NAME_DPAA2_SEC_PMD	crypto_dpaa2_sec
14 /**< NXP DPAA2 - SEC PMD device name */
15 
16 #define MAX_QUEUES		64
17 #define MAX_DESC_SIZE		64
18 /** private data structure for each DPAA2_SEC device */
19 struct dpaa2_sec_dev_private {
20 	void *mc_portal; /**< MC Portal for configuring this device */
21 	void *hw; /**< Hardware handle for this device.Used by NADK framework */
22 	struct rte_mempool *fle_pool; /* per device memory pool for FLE */
23 	int32_t hw_id; /**< An unique ID of this device instance */
24 	int32_t vfio_fd; /**< File descriptor received via VFIO */
25 	uint16_t token; /**< Token required by DPxxx objects */
26 	unsigned int max_nb_queue_pairs;
27 	/**< Max number of queue pairs supported by device */
28 };
29 
30 struct dpaa2_sec_qp {
31 	struct dpaa2_queue rx_vq;
32 	struct dpaa2_queue tx_vq;
33 };
34 
35 enum shr_desc_type {
36 	DESC_UPDATE,
37 	DESC_FINAL,
38 	DESC_INITFINAL,
39 };
40 
41 #define DIR_ENC                 1
42 #define DIR_DEC                 0
43 
44 #define DPAA2_SET_FLC_EWS(flc)  (flc->word1_bits23_16 |= 0x1)
45 #define DPAA2_SET_FLC_RSC(flc)  (flc->word1_bits31_24 |= 0x1)
46 #define DPAA2_SET_FLC_REUSE_BS(flc) (flc->mode_bits |= 0x8000)
47 #define DPAA2_SET_FLC_REUSE_FF(flc) (flc->mode_bits |= 0x2000)
48 
49 /* SEC Flow Context Descriptor */
50 struct sec_flow_context {
51 	/* word 0 */
52 	uint16_t word0_sdid;		/* 11-0  SDID */
53 	uint16_t word0_res;		/* 31-12 reserved */
54 
55 	/* word 1 */
56 	uint8_t word1_sdl;		/* 5-0 SDL */
57 					/* 7-6 reserved */
58 
59 	uint8_t word1_bits_15_8;        /* 11-8 CRID */
60 					/* 14-12 reserved */
61 					/* 15 CRJD */
62 
63 	uint8_t word1_bits23_16;	/* 16  EWS */
64 					/* 17 DAC */
65 					/* 18,19,20 ? */
66 					/* 23-21 reserved */
67 
68 	uint8_t word1_bits31_24;	/* 24 RSC */
69 					/* 25 RBMT */
70 					/* 31-26 reserved */
71 
72 	/* word 2  RFLC[31-0] */
73 	uint32_t word2_rflc_31_0;
74 
75 	/* word 3  RFLC[63-32] */
76 	uint32_t word3_rflc_63_32;
77 
78 	/* word 4 */
79 	uint16_t word4_iicid;		/* 15-0  IICID */
80 	uint16_t word4_oicid;		/* 31-16 OICID */
81 
82 	/* word 5 */
83 	uint32_t word5_ofqid:24;		/* 23-0 OFQID */
84 	uint32_t word5_31_24:8;
85 					/* 24 OSC */
86 					/* 25 OBMT */
87 					/* 29-26 reserved */
88 					/* 31-30 ICR */
89 
90 	/* word 6 */
91 	uint32_t word6_oflc_31_0;
92 
93 	/* word 7 */
94 	uint32_t word7_oflc_63_32;
95 
96 	/* Word 8-15 storage profiles */
97 	uint16_t dl;			/**<  DataLength(correction) */
98 	uint16_t reserved;		/**< reserved */
99 	uint16_t dhr;			/**< DataHeadRoom(correction) */
100 	uint16_t mode_bits;		/**< mode bits */
101 	uint16_t bpv0;			/**< buffer pool0 valid */
102 	uint16_t bpid0;			/**< Bypass Memory Translation */
103 	uint16_t bpv1;			/**< buffer pool1 valid */
104 	uint16_t bpid1;			/**< Bypass Memory Translation */
105 	uint64_t word_12_15[2];		/**< word 12-15 are reserved */
106 };
107 
108 struct sec_flc_desc {
109 	struct sec_flow_context flc;
110 	uint32_t desc[MAX_DESC_SIZE];
111 };
112 
113 struct ctxt_priv {
114 	struct rte_mempool *fle_pool; /* per device memory pool for FLE */
115 	struct sec_flc_desc flc_desc[0];
116 };
117 
118 enum dpaa2_sec_op_type {
119 	DPAA2_SEC_NONE,  /*!< No Cipher operations*/
120 	DPAA2_SEC_CIPHER,/*!< CIPHER operations */
121 	DPAA2_SEC_AUTH,  /*!< Authentication Operations */
122 	DPAA2_SEC_AEAD,  /*!< AEAD (AES-GCM/CCM) type operations */
123 	DPAA2_SEC_CIPHER_HASH,  /*!< Authenticated Encryption with
124 				 * associated data
125 				 */
126 	DPAA2_SEC_HASH_CIPHER,  /*!< Encryption with Authenticated
127 				 * associated data
128 				 */
129 	DPAA2_SEC_IPSEC, /*!< IPSEC protocol operations*/
130 	DPAA2_SEC_PDCP,  /*!< PDCP protocol operations*/
131 	DPAA2_SEC_PKC,   /*!< Public Key Cryptographic Operations */
132 	DPAA2_SEC_MAX
133 };
134 
135 struct dpaa2_sec_aead_ctxt {
136 	uint16_t auth_only_len; /*!< Length of data for Auth only */
137 	uint8_t auth_cipher_text;       /**< Authenticate/cipher ordering */
138 };
139 
140 /*
141  * The structure is to be filled by user for PDCP Protocol
142  */
143 struct dpaa2_pdcp_ctxt {
144 	enum rte_security_pdcp_domain domain; /*!< Data/Control mode*/
145 	int8_t bearer;	/*!< PDCP bearer ID */
146 	int8_t pkt_dir;/*!< PDCP Frame Direction 0:UL 1:DL*/
147 	int8_t hfn_ovd;/*!< Overwrite HFN per packet*/
148 	uint32_t hfn;	/*!< Hyper Frame Number */
149 	uint32_t hfn_threshold;	/*!< HFN Threashold for key renegotiation */
150 	uint8_t sn_size;	/*!< Sequence number size, 7/12/15 */
151 };
152 
153 typedef struct dpaa2_sec_session_entry {
154 	void *ctxt;
155 	uint8_t ctxt_type;
156 	uint8_t dir;         /*!< Operation Direction */
157 	enum rte_crypto_cipher_algorithm cipher_alg; /*!< Cipher Algorithm*/
158 	enum rte_crypto_auth_algorithm auth_alg; /*!< Authentication Algorithm*/
159 	enum rte_crypto_aead_algorithm aead_alg; /*!< AEAD Algorithm*/
160 	union {
161 		struct {
162 			uint8_t *data;	/**< pointer to key data */
163 			size_t length;	/**< key length in bytes */
164 		} aead_key;
165 		struct {
166 			struct {
167 				uint8_t *data;	/**< pointer to key data */
168 				size_t length;	/**< key length in bytes */
169 			} cipher_key;
170 			struct {
171 				uint8_t *data;	/**< pointer to key data */
172 				size_t length;	/**< key length in bytes */
173 			} auth_key;
174 		};
175 	};
176 	union {
177 		struct {
178 			struct {
179 				uint16_t length; /**< IV length in bytes */
180 				uint16_t offset; /**< IV offset in bytes */
181 			} iv;
182 			uint16_t digest_length;
183 			uint8_t status;
184 			union {
185 				struct dpaa2_sec_aead_ctxt aead_ctxt;
186 			} ext_params;
187 		};
188 		struct dpaa2_pdcp_ctxt pdcp;
189 	};
190 } dpaa2_sec_session;
191 
192 static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
193 	{	/* MD5 HMAC */
194 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
195 		{.sym = {
196 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
197 			{.auth = {
198 				.algo = RTE_CRYPTO_AUTH_MD5_HMAC,
199 				.block_size = 64,
200 				.key_size = {
201 					.min = 1,
202 					.max = 64,
203 					.increment = 1
204 				},
205 				.digest_size = {
206 					.min = 1,
207 					.max = 16,
208 					.increment = 1
209 				},
210 				.iv_size = { 0 }
211 			}, }
212 		}, }
213 	},
214 	{	/* SHA1 HMAC */
215 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
216 		{.sym = {
217 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
218 			{.auth = {
219 				.algo = RTE_CRYPTO_AUTH_SHA1_HMAC,
220 				.block_size = 64,
221 				.key_size = {
222 					.min = 1,
223 					.max = 64,
224 					.increment = 1
225 				},
226 				.digest_size = {
227 					.min = 1,
228 					.max = 20,
229 					.increment = 1
230 				},
231 				.iv_size = { 0 }
232 			}, }
233 		}, }
234 	},
235 	{	/* SHA224 HMAC */
236 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
237 		{.sym = {
238 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
239 			{.auth = {
240 				.algo = RTE_CRYPTO_AUTH_SHA224_HMAC,
241 				.block_size = 64,
242 				.key_size = {
243 					.min = 1,
244 					.max = 64,
245 					.increment = 1
246 				},
247 				.digest_size = {
248 					.min = 1,
249 					.max = 28,
250 					.increment = 1
251 				},
252 				.iv_size = { 0 }
253 			}, }
254 		}, }
255 	},
256 	{	/* SHA256 HMAC */
257 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
258 		{.sym = {
259 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
260 			{.auth = {
261 				.algo = RTE_CRYPTO_AUTH_SHA256_HMAC,
262 				.block_size = 64,
263 				.key_size = {
264 					.min = 1,
265 					.max = 64,
266 					.increment = 1
267 				},
268 				.digest_size = {
269 					.min = 1,
270 					.max = 32,
271 					.increment = 1
272 				},
273 				.iv_size = { 0 }
274 				}, }
275 			}, }
276 		},
277 	{	/* SHA384 HMAC */
278 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
279 		{.sym = {
280 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
281 			{.auth = {
282 				.algo = RTE_CRYPTO_AUTH_SHA384_HMAC,
283 				.block_size = 128,
284 				.key_size = {
285 					.min = 1,
286 					.max = 128,
287 					.increment = 1
288 				},
289 				.digest_size = {
290 					.min = 1,
291 					.max = 48,
292 					.increment = 1
293 				},
294 				.iv_size = { 0 }
295 			}, }
296 		}, }
297 	},
298 	{	/* SHA512 HMAC */
299 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
300 		{.sym = {
301 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
302 			{.auth = {
303 				.algo = RTE_CRYPTO_AUTH_SHA512_HMAC,
304 				.block_size = 128,
305 				.key_size = {
306 					.min = 1,
307 					.max = 128,
308 					.increment = 1
309 				},
310 				.digest_size = {
311 					.min = 1,
312 					.max = 64,
313 					.increment = 1
314 				},
315 				.iv_size = { 0 }
316 			}, }
317 		}, }
318 	},
319 	{	/* AES GCM */
320 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
321 		{.sym = {
322 			.xform_type = RTE_CRYPTO_SYM_XFORM_AEAD,
323 			{.aead = {
324 				.algo = RTE_CRYPTO_AEAD_AES_GCM,
325 				.block_size = 16,
326 				.key_size = {
327 					.min = 16,
328 					.max = 32,
329 					.increment = 8
330 				},
331 				.digest_size = {
332 					.min = 8,
333 					.max = 16,
334 					.increment = 4
335 				},
336 				.aad_size = {
337 					.min = 0,
338 					.max = 240,
339 					.increment = 1
340 				},
341 				.iv_size = {
342 					.min = 12,
343 					.max = 12,
344 					.increment = 0
345 				},
346 			}, }
347 		}, }
348 	},
349 	{	/* AES CBC */
350 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
351 		{.sym = {
352 			.xform_type = RTE_CRYPTO_SYM_XFORM_CIPHER,
353 			{.cipher = {
354 				.algo = RTE_CRYPTO_CIPHER_AES_CBC,
355 				.block_size = 16,
356 				.key_size = {
357 					.min = 16,
358 					.max = 32,
359 					.increment = 8
360 				},
361 				.iv_size = {
362 					.min = 16,
363 					.max = 16,
364 					.increment = 0
365 				}
366 			}, }
367 		}, }
368 	},
369 	{	/* AES CTR */
370 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
371 		{.sym = {
372 			.xform_type = RTE_CRYPTO_SYM_XFORM_CIPHER,
373 			{.cipher = {
374 				.algo = RTE_CRYPTO_CIPHER_AES_CTR,
375 				.block_size = 16,
376 				.key_size = {
377 					.min = 16,
378 					.max = 32,
379 					.increment = 8
380 				},
381 				.iv_size = {
382 					.min = 16,
383 					.max = 16,
384 					.increment = 0
385 				},
386 			}, }
387 		}, }
388 	},
389 	{	/* 3DES CBC */
390 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
391 		{.sym = {
392 			.xform_type = RTE_CRYPTO_SYM_XFORM_CIPHER,
393 			{.cipher = {
394 				.algo = RTE_CRYPTO_CIPHER_3DES_CBC,
395 				.block_size = 8,
396 				.key_size = {
397 					.min = 16,
398 					.max = 24,
399 					.increment = 8
400 				},
401 				.iv_size = {
402 					.min = 8,
403 					.max = 8,
404 					.increment = 0
405 				}
406 			}, }
407 		}, }
408 	},
409 
410 	RTE_CRYPTODEV_END_OF_CAPABILITIES_LIST()
411 };
412 
413 static const struct rte_cryptodev_capabilities dpaa2_pdcp_capabilities[] = {
414 	{	/* SNOW 3G (UIA2) */
415 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
416 		{.sym = {
417 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
418 			{.auth = {
419 				.algo = RTE_CRYPTO_AUTH_SNOW3G_UIA2,
420 				.block_size = 16,
421 				.key_size = {
422 					.min = 16,
423 					.max = 16,
424 					.increment = 0
425 				},
426 				.digest_size = {
427 					.min = 4,
428 					.max = 4,
429 					.increment = 0
430 				},
431 				.iv_size = {
432 					.min = 16,
433 					.max = 16,
434 					.increment = 0
435 				}
436 			}, }
437 		}, }
438 	},
439 	{	/* SNOW 3G (UEA2) */
440 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
441 		{.sym = {
442 			.xform_type = RTE_CRYPTO_SYM_XFORM_CIPHER,
443 			{.cipher = {
444 				.algo = RTE_CRYPTO_CIPHER_SNOW3G_UEA2,
445 				.block_size = 16,
446 				.key_size = {
447 					.min = 16,
448 					.max = 16,
449 					.increment = 0
450 				},
451 				.iv_size = {
452 					.min = 16,
453 					.max = 16,
454 					.increment = 0
455 				}
456 			}, }
457 		}, }
458 	},
459 	{	/* AES CTR */
460 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
461 		{.sym = {
462 			.xform_type = RTE_CRYPTO_SYM_XFORM_CIPHER,
463 			{.cipher = {
464 				.algo = RTE_CRYPTO_CIPHER_AES_CTR,
465 				.block_size = 16,
466 				.key_size = {
467 					.min = 16,
468 					.max = 32,
469 					.increment = 8
470 				},
471 				.iv_size = {
472 					.min = 16,
473 					.max = 16,
474 					.increment = 0
475 				}
476 			}, }
477 		}, }
478 	},
479 	{	/* NULL (AUTH) */
480 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
481 		{.sym = {
482 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
483 			{.auth = {
484 				.algo = RTE_CRYPTO_AUTH_NULL,
485 				.block_size = 1,
486 				.key_size = {
487 					.min = 0,
488 					.max = 0,
489 					.increment = 0
490 				},
491 				.digest_size = {
492 					.min = 0,
493 					.max = 0,
494 					.increment = 0
495 				},
496 				.iv_size = { 0 }
497 			}, },
498 		}, },
499 	},
500 	{	/* NULL (CIPHER) */
501 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
502 		{.sym = {
503 			.xform_type = RTE_CRYPTO_SYM_XFORM_CIPHER,
504 			{.cipher = {
505 				.algo = RTE_CRYPTO_CIPHER_NULL,
506 				.block_size = 1,
507 				.key_size = {
508 					.min = 0,
509 					.max = 0,
510 					.increment = 0
511 				},
512 				.iv_size = {
513 					.min = 0,
514 					.max = 0,
515 					.increment = 0
516 				}
517 			}, },
518 		}, }
519 	},
520 	{	/* ZUC (EEA3) */
521 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
522 		{.sym = {
523 			.xform_type = RTE_CRYPTO_SYM_XFORM_CIPHER,
524 			{.cipher = {
525 				.algo = RTE_CRYPTO_CIPHER_ZUC_EEA3,
526 				.block_size = 16,
527 				.key_size = {
528 					.min = 16,
529 					.max = 16,
530 					.increment = 0
531 				},
532 				.iv_size = {
533 					.min = 16,
534 					.max = 16,
535 					.increment = 0
536 				}
537 			}, }
538 		}, }
539 	},
540 	{	/* ZUC (EIA3) */
541 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
542 		{.sym = {
543 			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
544 			{.auth = {
545 				.algo = RTE_CRYPTO_AUTH_ZUC_EIA3,
546 				.block_size = 16,
547 				.key_size = {
548 					.min = 16,
549 					.max = 16,
550 					.increment = 0
551 				},
552 				.digest_size = {
553 					.min = 4,
554 					.max = 4,
555 					.increment = 0
556 				},
557 				.iv_size = {
558 					.min = 16,
559 					.max = 16,
560 					.increment = 0
561 				}
562 			}, }
563 		}, }
564 	},
565 
566 	RTE_CRYPTODEV_END_OF_CAPABILITIES_LIST()
567 };
568 
569 static const struct rte_security_capability dpaa2_sec_security_cap[] = {
570 	{ /* IPsec Lookaside Protocol offload ESP Transport Egress */
571 		.action = RTE_SECURITY_ACTION_TYPE_LOOKASIDE_PROTOCOL,
572 		.protocol = RTE_SECURITY_PROTOCOL_IPSEC,
573 		.ipsec = {
574 			.proto = RTE_SECURITY_IPSEC_SA_PROTO_ESP,
575 			.mode = RTE_SECURITY_IPSEC_SA_MODE_TUNNEL,
576 			.direction = RTE_SECURITY_IPSEC_SA_DIR_EGRESS,
577 			.options = { 0 }
578 		},
579 		.crypto_capabilities = dpaa2_sec_capabilities
580 	},
581 	{ /* IPsec Lookaside Protocol offload ESP Tunnel Ingress */
582 		.action = RTE_SECURITY_ACTION_TYPE_LOOKASIDE_PROTOCOL,
583 		.protocol = RTE_SECURITY_PROTOCOL_IPSEC,
584 		.ipsec = {
585 			.proto = RTE_SECURITY_IPSEC_SA_PROTO_ESP,
586 			.mode = RTE_SECURITY_IPSEC_SA_MODE_TUNNEL,
587 			.direction = RTE_SECURITY_IPSEC_SA_DIR_INGRESS,
588 			.options = { 0 }
589 		},
590 		.crypto_capabilities = dpaa2_sec_capabilities
591 	},
592 	{ /* PDCP Lookaside Protocol offload Data */
593 		.action = RTE_SECURITY_ACTION_TYPE_LOOKASIDE_PROTOCOL,
594 		.protocol = RTE_SECURITY_PROTOCOL_PDCP,
595 		.pdcp = {
596 			.domain = RTE_SECURITY_PDCP_MODE_DATA,
597 			.capa_flags = 0
598 		},
599 		.crypto_capabilities = dpaa2_pdcp_capabilities
600 	},
601 	{ /* PDCP Lookaside Protocol offload Control */
602 		.action = RTE_SECURITY_ACTION_TYPE_LOOKASIDE_PROTOCOL,
603 		.protocol = RTE_SECURITY_PROTOCOL_PDCP,
604 		.pdcp = {
605 			.domain = RTE_SECURITY_PDCP_MODE_CONTROL,
606 			.capa_flags = 0
607 		},
608 		.crypto_capabilities = dpaa2_pdcp_capabilities
609 	},
610 	{
611 		.action = RTE_SECURITY_ACTION_TYPE_NONE
612 	}
613 };
614 
615 /**
616  * Checksum
617  *
618  * @param buffer calculate chksum for buffer
619  * @param len    buffer length
620  *
621  * @return checksum value in host cpu order
622  */
623 static inline uint16_t
624 calc_chksum(void *buffer, int len)
625 {
626 	uint16_t *buf = (uint16_t *)buffer;
627 	uint32_t sum = 0;
628 	uint16_t result;
629 
630 	for (sum = 0; len > 1; len -= 2)
631 		sum += *buf++;
632 
633 	if (len == 1)
634 		sum += *(unsigned char *)buf;
635 
636 	sum = (sum >> 16) + (sum & 0xFFFF);
637 	sum += (sum >> 16);
638 	result = ~sum;
639 
640 	return  result;
641 }
642 
643 #endif /* _RTE_DPAA2_SEC_PMD_PRIVATE_H_ */
644