1 /*-
2 * Copyright (c) 2000-2015 Mark R V Murray
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer
10 * in this position and unchanged.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 * notice, this list of conditions and the following disclaimer in the
13 * documentation and/or other materials provided with the distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
16 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
19 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25 *
26 */
27
28 #include <sys/cdefs.h>
29 #ifdef _KERNEL
30 #include <sys/param.h>
31 #include <sys/malloc.h>
32 #include <sys/systm.h>
33 #else /* !_KERNEL */
34 #include <sys/param.h>
35 #include <sys/types.h>
36 #include <assert.h>
37 #include <inttypes.h>
38 #include <signal.h>
39 #include <stdbool.h>
40 #include <stdio.h>
41 #include <stdlib.h>
42 #include <string.h>
43 #define KASSERT(x, y) assert(x)
44 #define CTASSERT(x) _Static_assert(x, "CTASSERT " #x)
45 #endif /* _KERNEL */
46
47 #define CHACHA_EMBED
48 #define KEYSTREAM_ONLY
49 #define CHACHA_NONCE0_CTR128
50 #include <crypto/rijndael/rijndael-api-fst.h>
51 #include <crypto/sha2/sha256.h>
52
53 #include <dev/random/hash.h>
54 #ifdef _KERNEL
55 #include <dev/random/randomdev.h>
56 #endif
57
58 /* This code presumes that RANDOM_KEYSIZE is twice as large as RANDOM_BLOCKSIZE */
59 //CTASSERT(RANDOM_KEYSIZE == 2*RANDOM_BLOCKSIZE);
60
61 /* Initialise the hash */
62 void
randomdev_hash_init(struct randomdev_hash * context)63 randomdev_hash_init(struct randomdev_hash *context)
64 {
65
66 SHA256_Init(&context->sha);
67 }
68
69 /* Iterate the hash */
70 void
randomdev_hash_iterate(struct randomdev_hash * context,const void * data,size_t size)71 randomdev_hash_iterate(struct randomdev_hash *context, const void *data, size_t size)
72 {
73
74 SHA256_Update(&context->sha, data, size);
75 }
76
77 /* Conclude by returning the hash in the supplied <*buf> which must be
78 * RANDOM_KEYSIZE bytes long.
79 */
80 void
randomdev_hash_finish(struct randomdev_hash * context,void * buf)81 randomdev_hash_finish(struct randomdev_hash *context, void *buf)
82 {
83
84 SHA256_Final(buf, &context->sha);
85 }
86
87 /* Initialise the encryption routine by setting up the key schedule
88 * from the supplied <*data> which must be RANDOM_KEYSIZE bytes of binary
89 * data.
90 */
91 void
randomdev_encrypt_init(struct randomdev_key * context,const void * data)92 randomdev_encrypt_init(struct randomdev_key *context, const void *data)
93 {
94
95 rijndael_cipherInit(&context->cipher, MODE_CBC, NULL);
96 rijndael_makeKey(&context->key, DIR_ENCRYPT, RANDOM_KEYSIZE*8, data);
97 }
98
99 /* Encrypt the supplied data using the key schedule preset in the context.
100 * <length> bytes are encrypted from <*d_in> to <*d_out>. <length> must be
101 * a multiple of RANDOM_BLOCKSIZE.
102 */
103 void
randomdev_encrypt(struct randomdev_key * context,const void * d_in,void * d_out,u_int length)104 randomdev_encrypt(struct randomdev_key *context, const void *d_in, void *d_out, u_int length)
105 {
106
107 rijndael_blockEncrypt(&context->cipher, &context->key, d_in, length*8, d_out);
108 }
109