1 /*-
2 * Copyright (c) 2000-2015 Mark R V Murray
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer
10 * in this position and unchanged.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 * notice, this list of conditions and the following disclaimer in the
13 * documentation and/or other materials provided with the distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
16 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
19 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25 *
26 */
27
28 #include <sys/cdefs.h>
29 __FBSDID("$FreeBSD$");
30
31 #ifdef _KERNEL
32 #include <sys/param.h>
33 #include <sys/malloc.h>
34 #include <sys/systm.h>
35 #else /* !_KERNEL */
36 #include <sys/param.h>
37 #include <sys/types.h>
38 #include <assert.h>
39 #include <inttypes.h>
40 #include <signal.h>
41 #include <stdbool.h>
42 #include <stdio.h>
43 #include <stdlib.h>
44 #include <string.h>
45 #define KASSERT(x, y) assert(x)
46 #define CTASSERT(x) _Static_assert(x, "CTASSERT " #x)
47 #endif /* _KERNEL */
48
49 #define CHACHA_EMBED
50 #define KEYSTREAM_ONLY
51 #define CHACHA_NONCE0_CTR128
52 #include <crypto/rijndael/rijndael-api-fst.h>
53 #include <crypto/sha2/sha256.h>
54
55 #include <dev/random/hash.h>
56 #ifdef _KERNEL
57 #include <dev/random/randomdev.h>
58 #endif
59
60 /* This code presumes that RANDOM_KEYSIZE is twice as large as RANDOM_BLOCKSIZE */
61 //CTASSERT(RANDOM_KEYSIZE == 2*RANDOM_BLOCKSIZE);
62
63 /* Initialise the hash */
64 void
randomdev_hash_init(struct randomdev_hash * context)65 randomdev_hash_init(struct randomdev_hash *context)
66 {
67
68 SHA256_Init(&context->sha);
69 }
70
71 /* Iterate the hash */
72 void
randomdev_hash_iterate(struct randomdev_hash * context,const void * data,size_t size)73 randomdev_hash_iterate(struct randomdev_hash *context, const void *data, size_t size)
74 {
75
76 SHA256_Update(&context->sha, data, size);
77 }
78
79 /* Conclude by returning the hash in the supplied <*buf> which must be
80 * RANDOM_KEYSIZE bytes long.
81 */
82 void
randomdev_hash_finish(struct randomdev_hash * context,void * buf)83 randomdev_hash_finish(struct randomdev_hash *context, void *buf)
84 {
85
86 SHA256_Final(buf, &context->sha);
87 }
88
89 /* Initialise the encryption routine by setting up the key schedule
90 * from the supplied <*data> which must be RANDOM_KEYSIZE bytes of binary
91 * data.
92 */
93 void
randomdev_encrypt_init(struct randomdev_key * context,const void * data)94 randomdev_encrypt_init(struct randomdev_key *context, const void *data)
95 {
96
97 rijndael_cipherInit(&context->cipher, MODE_CBC, NULL);
98 rijndael_makeKey(&context->key, DIR_ENCRYPT, RANDOM_KEYSIZE*8, data);
99 }
100
101 /* Encrypt the supplied data using the key schedule preset in the context.
102 * <length> bytes are encrypted from <*d_in> to <*d_out>. <length> must be
103 * a multiple of RANDOM_BLOCKSIZE.
104 */
105 void
randomdev_encrypt(struct randomdev_key * context,const void * d_in,void * d_out,u_int length)106 randomdev_encrypt(struct randomdev_key *context, const void *d_in, void *d_out, u_int length)
107 {
108
109 rijndael_blockEncrypt(&context->cipher, &context->key, d_in, length*8, d_out);
110 }
111