From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Ananyev, Konstantin" Subject: Re: [PATCH v2 3/4] ipsec: add 3DES-CBC algorithm support Date: Fri, 22 Feb 2019 12:38:04 +0000 Message-ID: <2601191342CEEE43887BDE71AB977258012413C292@irsmsx105.ger.corp.intel.com> References: <20190218163254.56905-1-roy.fan.zhang@intel.com> <20190219153236.84537-1-roy.fan.zhang@intel.com> <20190219153236.84537-4-roy.fan.zhang@intel.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Cc: "akhil.goyal@nxp.com" To: "Zhang, Roy Fan" , "dev@dpdk.org" Return-path: Received: from mga18.intel.com (mga18.intel.com [134.134.136.126]) by dpdk.org (Postfix) with ESMTP id 2272F292D for ; Fri, 22 Feb 2019 13:38:07 +0100 (CET) In-Reply-To: <20190219153236.84537-4-roy.fan.zhang@intel.com> Content-Language: en-US List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Sender: "dev" > This patch adds triple-des CBC mode cipher algorithm to ipsec > library. >=20 > Signed-off-by: Fan Zhang > --- > lib/librte_ipsec/sa.c | 10 ++++++++++ > lib/librte_ipsec/sa.h | 6 ++++++ > 2 files changed, 16 insertions(+) >=20 > diff --git a/lib/librte_ipsec/sa.c b/lib/librte_ipsec/sa.c > index e34dd320a..5c59c4b67 100644 > --- a/lib/librte_ipsec/sa.c > +++ b/lib/librte_ipsec/sa.c > @@ -307,6 +307,13 @@ esp_sa_init(struct rte_ipsec_sa *sa, const struct rt= e_ipsec_sa_prm *prm, > sa->algo_type =3D ALGO_TYPE_AES_CTR; > break; >=20 > + case RTE_CRYPTO_CIPHER_3DES_CBC: > + /* RFC 1851 */ > + sa->pad_align =3D IPSEC_PAD_3DES_CBC; > + sa->iv_len =3D IPSEC_3DES_IV_SIZE; > + sa->algo_type =3D ALGO_TYPE_3DES; > + break; > + > default: > return -EINVAL; > } > @@ -512,6 +519,8 @@ esp_outb_cop_prepare(struct rte_crypto_op *cop, > sa->iv_ofs); > aes_ctr_cnt_blk_fill(ctr, ivp[0], sa->salt); > break; > + case ALGO_TYPE_3DES: > + /* Cipher-Auth (3DES-CBC *) case */ > case ALGO_TYPE_NULL: > /* NULL case */ > sop->cipher.data.offset =3D sa->ctp.cipher.offset + hlen; > @@ -873,6 +882,7 @@ esp_inb_tun_cop_prepare(struct rte_crypto_op *cop, > aead_gcm_iv_fill(gcm, ivp[0], sa->salt); > break; > case ALGO_TYPE_AES_CBC: > + case ALGO_TYPE_3DES: > sop->cipher.data.offset =3D pofs + sa->ctp.cipher.offset; > sop->cipher.data.length =3D clen; > sop->auth.data.offset =3D pofs + sa->ctp.auth.offset; > diff --git a/lib/librte_ipsec/sa.h b/lib/librte_ipsec/sa.h > index 12c061ee6..8398748d1 100644 > --- a/lib/librte_ipsec/sa.h > +++ b/lib/librte_ipsec/sa.h > @@ -14,6 +14,7 @@ > /* padding alignment for different algorithms */ > enum { > IPSEC_PAD_DEFAULT =3D 4, > + IPSEC_PAD_3DES_CBC =3D IPSEC_PAD_DEFAULT, > IPSEC_PAD_AES_CBC =3D IPSEC_MAX_IV_SIZE, > IPSEC_PAD_AES_CTR =3D IPSEC_PAD_DEFAULT, > IPSEC_PAD_AES_GCM =3D IPSEC_PAD_DEFAULT, > @@ -24,6 +25,10 @@ enum { > enum { > IPSEC_IV_SIZE_DEFAULT =3D IPSEC_MAX_IV_SIZE, > IPSEC_AES_CTR_IV_SIZE =3D sizeof(uint64_t), > + /* TripleDES supports IV size of 32bits or 64bits but he library Typo: 's/ he / the /' > + * only supports 64bits. > + */ > + IPSEC_3DES_IV_SIZE =3D sizeof(uint64_t), > }; >=20 > /* these definitions probably has to be in rte_crypto_sym.h */ > @@ -57,6 +62,7 @@ struct replay_sqn { > /*IPSEC SA supported algorithms */ > enum sa_algo_type { > ALGO_TYPE_NULL =3D 0, > + ALGO_TYPE_3DES, > ALGO_TYPE_AES_CBC, > ALGO_TYPE_AES_CTR, > ALGO_TYPE_AES_GCM, > -- Acked-by: Konstantin Ananyev > 2.14.5