xref: /linux-6.15/include/crypto/ctr.h (revision 37d45180)
12874c5fdSThomas Gleixner /* SPDX-License-Identifier: GPL-2.0-or-later */
25311f248SHerbert Xu /*
35311f248SHerbert Xu  * CTR: Counter mode
45311f248SHerbert Xu  *
55311f248SHerbert Xu  * Copyright (c) 2007 Herbert Xu <[email protected]>
65311f248SHerbert Xu  */
75311f248SHerbert Xu 
85311f248SHerbert Xu #ifndef _CRYPTO_CTR_H
95311f248SHerbert Xu #define _CRYPTO_CTR_H
105311f248SHerbert Xu 
11d9ec772dSArd Biesheuvel #include <crypto/algapi.h>
12d9ec772dSArd Biesheuvel #include <crypto/internal/skcipher.h>
13d9ec772dSArd Biesheuvel #include <linux/string.h>
14d9ec772dSArd Biesheuvel #include <linux/types.h>
15d9ec772dSArd Biesheuvel 
165311f248SHerbert Xu #define CTR_RFC3686_NONCE_SIZE 4
175311f248SHerbert Xu #define CTR_RFC3686_IV_SIZE 8
185311f248SHerbert Xu #define CTR_RFC3686_BLOCK_SIZE 16
195311f248SHerbert Xu 
crypto_ctr_encrypt_walk(struct skcipher_request * req,void (* fn)(struct crypto_skcipher *,const u8 *,u8 *))20d9ec772dSArd Biesheuvel static inline int crypto_ctr_encrypt_walk(struct skcipher_request *req,
21d9ec772dSArd Biesheuvel 					  void (*fn)(struct crypto_skcipher *,
22d9ec772dSArd Biesheuvel 						     const u8 *, u8 *))
23d9ec772dSArd Biesheuvel {
24d9ec772dSArd Biesheuvel 	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
25d9ec772dSArd Biesheuvel 	int blocksize = crypto_skcipher_chunksize(tfm);
26d9ec772dSArd Biesheuvel 	u8 buf[MAX_CIPHER_BLOCKSIZE];
27d9ec772dSArd Biesheuvel 	struct skcipher_walk walk;
28d9ec772dSArd Biesheuvel 	int err;
29d9ec772dSArd Biesheuvel 
30d9ec772dSArd Biesheuvel 	/* avoid integer division due to variable blocksize parameter */
31d9ec772dSArd Biesheuvel 	if (WARN_ON_ONCE(!is_power_of_2(blocksize)))
32d9ec772dSArd Biesheuvel 		return -EINVAL;
33d9ec772dSArd Biesheuvel 
34d9ec772dSArd Biesheuvel 	err = skcipher_walk_virt(&walk, req, false);
35d9ec772dSArd Biesheuvel 
36d9ec772dSArd Biesheuvel 	while (walk.nbytes > 0) {
37*37d45180SHerbert Xu 		const u8 *src = walk.src.virt.addr;
38d9ec772dSArd Biesheuvel 		u8 *dst = walk.dst.virt.addr;
39d9ec772dSArd Biesheuvel 		int nbytes = walk.nbytes;
40d9ec772dSArd Biesheuvel 		int tail = 0;
41d9ec772dSArd Biesheuvel 
42d9ec772dSArd Biesheuvel 		if (nbytes < walk.total) {
43d9ec772dSArd Biesheuvel 			tail = walk.nbytes & (blocksize - 1);
44d9ec772dSArd Biesheuvel 			nbytes -= tail;
45d9ec772dSArd Biesheuvel 		}
46d9ec772dSArd Biesheuvel 
47d9ec772dSArd Biesheuvel 		do {
48d9ec772dSArd Biesheuvel 			int bsize = min(nbytes, blocksize);
49d9ec772dSArd Biesheuvel 
50d9ec772dSArd Biesheuvel 			fn(tfm, walk.iv, buf);
51d9ec772dSArd Biesheuvel 
52d9ec772dSArd Biesheuvel 			crypto_xor_cpy(dst, src, buf, bsize);
53d9ec772dSArd Biesheuvel 			crypto_inc(walk.iv, blocksize);
54d9ec772dSArd Biesheuvel 
55d9ec772dSArd Biesheuvel 			dst += bsize;
56d9ec772dSArd Biesheuvel 			src += bsize;
57d9ec772dSArd Biesheuvel 			nbytes -= bsize;
58d9ec772dSArd Biesheuvel 		} while (nbytes > 0);
59d9ec772dSArd Biesheuvel 
60d9ec772dSArd Biesheuvel 		err = skcipher_walk_done(&walk, tail);
61d9ec772dSArd Biesheuvel 	}
62d9ec772dSArd Biesheuvel 	return err;
63d9ec772dSArd Biesheuvel }
64d9ec772dSArd Biesheuvel 
655311f248SHerbert Xu #endif  /* _CRYPTO_CTR_H */
66