geliboot_crypto.c 3.88 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
/*-
 * Copyright (c) 2005-2010 Pawel Jakub Dawidek <pjd@FreeBSD.org>
 * Copyright (c) 2015 Allan Jude <allanjude@FreeBSD.org>
 * All rights reserved.
 *
 * Redistribution and use in source and binary forms, with or without
 * modification, are permitted provided that the following conditions
 * are met:
 * 1. Redistributions of source code must retain the above copyright
 *    notice, this list of conditions and the following disclaimer.
 * 2. Redistributions in binary form must reproduce the above copyright
 *    notice, this list of conditions and the following disclaimer in the
 *    documentation and/or other materials provided with the distribution.
 *
 * THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND
 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE LIABLE
 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 * SUCH DAMAGE.
 *
 * $FreeBSD$
 */

30
31
32
33
#include <stdio.h>
#include <string.h>
#include <strings.h>

34
#include "geliboot_internal.h"
35
36
37
#include "geliboot.h"

int
Toomas Soome's avatar
Toomas Soome committed
38
geliboot_crypt(u_int algo, geli_op_t enc, u_char *data, size_t datasize,
39
    const u_char *key, size_t keysize, u_char *iv)
40
41
42
43
44
{
	keyInstance aeskey;
	cipherInstance cipher;
	struct aes_xts_ctx xtsctx, *ctxp;
	size_t xts_len;
45
	int err, blks;
46
47
48
49
50
51

	switch (algo) {
	case CRYPTO_AES_CBC:
		err = rijndael_makeKey(&aeskey, !enc, keysize, 
		    (const char *)key);
		if (err < 0) {
Toomas Soome's avatar
Toomas Soome committed
52
			printf("Failed to setup crypo keys: %d\n", err);
53
54
55
56
57
58
59
60
61
			return (err);
		}

		err = rijndael_cipherInit(&cipher, MODE_CBC, iv);
		if (err < 0) {
			printf("Failed to setup IV: %d\n", err);
			return (err);
		}

Toomas Soome's avatar
Toomas Soome committed
62
63
		switch (enc) {
		case GELI_DECRYPT:
64
65
			blks = rijndael_blockDecrypt(&cipher, &aeskey, data, 
			    datasize * 8, data);
Toomas Soome's avatar
Toomas Soome committed
66
67
			break;
		case GELI_ENCRYPT:
68
69
			blks = rijndael_blockEncrypt(&cipher, &aeskey, data, 
			    datasize * 8, data);
Toomas Soome's avatar
Toomas Soome committed
70
			break;
71
72
		}
		if (datasize != (blks / 8)) {
Toomas Soome's avatar
Toomas Soome committed
73
74
75
			printf("Failed to %s the entire input: %u != %zu\n",
			    enc ? "decrypt" : "encrypt",
			    blks, datasize);
76
77
78
79
80
81
82
			return (1);
		}
		break;
	case CRYPTO_AES_XTS:
		xts_len = keysize << 1;
		ctxp = &xtsctx;

83
		enc_xform_aes_xts.setkey(ctxp, key, xts_len / 8);
84
		enc_xform_aes_xts.reinit(ctxp, iv, AES_XTS_IV_LEN);
85
86

		switch (enc) {
Toomas Soome's avatar
Toomas Soome committed
87
		case GELI_DECRYPT:
88
89
			enc_xform_aes_xts.decrypt_multi(ctxp, data, data,
			    datasize);
90
			break;
Toomas Soome's avatar
Toomas Soome committed
91
		case GELI_ENCRYPT:
92
93
			enc_xform_aes_xts.encrypt_multi(ctxp, data, data,
			    datasize);
94
95
96
97
98
99
100
101
102
103
104
105
			break;
		}
		break;
	default:
		printf("Unsupported crypto algorithm #%d\n", algo);
		return (1);
	}

	return (0);
}

static int
Toomas Soome's avatar
Toomas Soome committed
106
g_eli_crypto_cipher(u_int algo, geli_op_t enc, u_char *data, size_t datasize,
107
108
    const u_char *key, size_t keysize)
{
109
	u_char iv[G_ELI_IVKEYLEN];
110

111
	explicit_bzero(iv, sizeof(iv));
112
	return (geliboot_crypt(algo, enc, data, datasize, key, keysize, iv));
113
114
115
116
117
118
119
120
121
122
123
}

int
g_eli_crypto_encrypt(u_int algo, u_char *data, size_t datasize,
    const u_char *key, size_t keysize)
{

	/* We prefer AES-CBC for metadata protection. */
	if (algo == CRYPTO_AES_XTS)
		algo = CRYPTO_AES_CBC;

Toomas Soome's avatar
Toomas Soome committed
124
125
	return (g_eli_crypto_cipher(algo, GELI_ENCRYPT, data, datasize, key,
	    keysize));
126
127
128
129
130
131
132
133
134
135
136
}

int
g_eli_crypto_decrypt(u_int algo, u_char *data, size_t datasize,
    const u_char *key, size_t keysize)
{

	/* We prefer AES-CBC for metadata protection. */
	if (algo == CRYPTO_AES_XTS)
		algo = CRYPTO_AES_CBC;

Toomas Soome's avatar
Toomas Soome committed
137
138
	return (g_eli_crypto_cipher(algo, GELI_DECRYPT, data, datasize, key,
	    keysize));
139
}