1/*-
2 * Copyright (c) 2000-2015 Mark R V Murray
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 *    notice, this list of conditions and the following disclaimer
10 *    in this position and unchanged.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 *    notice, this list of conditions and the following disclaimer in the
13 *    documentation and/or other materials provided with the distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
16 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
19 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25 */
26
27#ifndef SYS_DEV_RANDOM_HASH_H_INCLUDED
28#define	SYS_DEV_RANDOM_HASH_H_INCLUDED
29
30#include <crypto/chacha20/_chacha.h>
31#include <dev/random/uint128.h>
32
33#ifndef _KERNEL
34#define	__read_frequently
35#endif
36
37/* Keys are formed from cipher blocks */
38#define	RANDOM_KEYSIZE		32	/* (in bytes) == 256 bits */
39#define	RANDOM_KEYSIZE_WORDS	(RANDOM_KEYSIZE/sizeof(uint32_t))
40#define	RANDOM_BLOCKSIZE	16	/* (in bytes) == 128 bits */
41#define	RANDOM_BLOCKSIZE_WORDS	(RANDOM_BLOCKSIZE/sizeof(uint32_t))
42#define	RANDOM_KEYS_PER_BLOCK	(RANDOM_KEYSIZE/RANDOM_BLOCKSIZE)
43
44/* The size of the zero block portion used to form H_d(m) */
45#define	RANDOM_ZERO_BLOCKSIZE	64	/* (in bytes) == 512 zero bits */
46
47struct randomdev_hash {
48	SHA256_CTX	sha;
49};
50
51union randomdev_key {
52	struct {
53		keyInstance key;	/* Key schedule */
54		cipherInstance cipher;	/* Rijndael internal */
55	};
56	struct chacha_ctx chacha;
57};
58
59extern bool random_chachamode;
60
61void randomdev_hash_init(struct randomdev_hash *);
62void randomdev_hash_iterate(struct randomdev_hash *, const void *, size_t);
63void randomdev_hash_finish(struct randomdev_hash *, void *);
64
65void randomdev_encrypt_init(union randomdev_key *, const void *);
66void randomdev_keystream(union randomdev_key *context, uint128_t *, void *, size_t);
67void randomdev_getkey(union randomdev_key *, const void **, size_t *);
68
69#endif /* SYS_DEV_RANDOM_HASH_H_INCLUDED */
70