1
2
3
4
5
6
7
8
9
10
11
12#include <common.h>
13#include <image.h>
14#include <malloc.h>
15#include <crypto/internal/rsa.h>
16#include <u-boot/rsa-mod-exp.h>
17#include <asm/unaligned.h>
18
19
20
21
22
23
24static unsigned br_dec16be(const void *src)
25{
26 return get_unaligned_be16(src);
27}
28
29
30
31
32
33
34static uint32_t br_dec32be(const void *src)
35{
36 return get_unaligned_be32(src);
37}
38
39
40
41
42
43
44static void br_enc32be(void *dst, uint32_t x)
45{
46 __be32 tmp;
47
48 tmp = cpu_to_be32(x);
49 memcpy(dst, &tmp, sizeof(tmp));
50}
51
52
53
54
55
56
57static uint32_t NOT(uint32_t ctl)
58{
59 return ctl ^ 1;
60}
61
62
63
64
65static uint32_t MUX(uint32_t ctl, uint32_t x, uint32_t y)
66{
67 return y ^ (-ctl & (x ^ y));
68}
69
70
71
72
73static uint32_t EQ(uint32_t x, uint32_t y)
74{
75 uint32_t q;
76
77 q = x ^ y;
78 return NOT((q | -q) >> 31);
79}
80
81
82
83
84static uint32_t NEQ(uint32_t x, uint32_t y)
85{
86 uint32_t q;
87
88 q = x ^ y;
89 return (q | -q) >> 31;
90}
91
92
93
94
95static uint32_t GT(uint32_t x, uint32_t y)
96{
97
98
99
100
101
102
103
104
105
106
107
108
109 uint32_t z;
110
111 z = y - x;
112 return (z ^ ((x ^ y) & (x ^ z))) >> 31;
113}
114
115
116
117
118
119static uint32_t BIT_LENGTH(uint32_t x)
120{
121 uint32_t k, c;
122
123 k = NEQ(x, 0);
124 c = GT(x, 0xFFFF); x = MUX(c, x >> 16, x); k += c << 4;
125 c = GT(x, 0x00FF); x = MUX(c, x >> 8, x); k += c << 3;
126 c = GT(x, 0x000F); x = MUX(c, x >> 4, x); k += c << 2;
127 c = GT(x, 0x0003); x = MUX(c, x >> 2, x); k += c << 1;
128 k += GT(x, 0x0001);
129 return k;
130}
131
132#define GE(x, y) NOT(GT(y, x))
133#define LT(x, y) GT(y, x)
134#define MUL(x, y) ((uint64_t)(x) * (uint64_t)(y))
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167static uint32_t br_i32_word(const uint32_t *a, uint32_t off)
168{
169 size_t u;
170 unsigned j;
171
172 u = (size_t)(off >> 5) + 1;
173 j = (unsigned)off & 31;
174 if (j == 0) {
175 return a[u];
176 } else {
177 return (a[u] >> j) | (a[u + 1] << (32 - j));
178 }
179}
180
181
182
183
184
185
186
187
188
189
190static uint32_t br_i32_bit_length(uint32_t *x, size_t xlen)
191{
192 uint32_t tw, twk;
193
194 tw = 0;
195 twk = 0;
196 while (xlen -- > 0) {
197 uint32_t w, c;
198
199 c = EQ(tw, 0);
200 w = x[xlen];
201 tw = MUX(c, w, tw);
202 twk = MUX(c, (uint32_t)xlen, twk);
203 }
204 return (twk << 5) + BIT_LENGTH(tw);
205}
206
207
208
209
210
211
212
213
214
215
216static void br_i32_decode(uint32_t *x, const void *src, size_t len)
217{
218 const unsigned char *buf;
219 size_t u, v;
220
221 buf = src;
222 u = len;
223 v = 1;
224 for (;;) {
225 if (u < 4) {
226 uint32_t w;
227
228 if (u < 2) {
229 if (u == 0) {
230 break;
231 } else {
232 w = buf[0];
233 }
234 } else {
235 if (u == 2) {
236 w = br_dec16be(buf);
237 } else {
238 w = ((uint32_t)buf[0] << 16)
239 | br_dec16be(buf + 1);
240 }
241 }
242 x[v ++] = w;
243 break;
244 } else {
245 u -= 4;
246 x[v ++] = br_dec32be(buf + u);
247 }
248 }
249 x[0] = br_i32_bit_length(x + 1, v - 1);
250}
251
252
253
254
255
256
257
258
259
260static void br_i32_encode(void *dst, size_t len, const uint32_t *x)
261{
262 unsigned char *buf;
263 size_t k;
264
265 buf = dst;
266
267
268
269
270
271 k = (x[0] + 7) >> 3;
272 while (len > k) {
273 *buf ++ = 0;
274 len --;
275 }
276
277
278
279
280
281
282 k = (len + 3) >> 2;
283 switch (len & 3) {
284 case 3:
285 *buf ++ = x[k] >> 16;
286
287 case 2:
288 *buf ++ = x[k] >> 8;
289
290 case 1:
291 *buf ++ = x[k];
292 k --;
293 }
294
295
296
297
298 while (k > 0) {
299 br_enc32be(buf, x[k]);
300 k --;
301 buf += 4;
302 }
303}
304
305
306
307
308
309
310static uint32_t br_i32_ninv32(uint32_t x)
311{
312 uint32_t y;
313
314 y = 2 - x;
315 y *= 2 - y * x;
316 y *= 2 - y * x;
317 y *= 2 - y * x;
318 y *= 2 - y * x;
319 return MUX(x & 1, -y, 0);
320}
321
322
323
324
325
326
327
328
329
330
331static uint32_t br_i32_add(uint32_t *a, const uint32_t *b, uint32_t ctl)
332{
333 uint32_t cc;
334 size_t u, m;
335
336 cc = 0;
337 m = (a[0] + 63) >> 5;
338 for (u = 1; u < m; u ++) {
339 uint32_t aw, bw, naw;
340
341 aw = a[u];
342 bw = b[u];
343 naw = aw + bw + cc;
344
345
346
347
348
349 cc = (cc & EQ(naw, aw)) | LT(naw, aw);
350 a[u] = MUX(ctl, naw, aw);
351 }
352 return cc;
353}
354
355
356
357
358
359
360
361
362
363
364static uint32_t br_i32_sub(uint32_t *a, const uint32_t *b, uint32_t ctl)
365{
366 uint32_t cc;
367 size_t u, m;
368
369 cc = 0;
370 m = (a[0] + 63) >> 5;
371 for (u = 1; u < m; u ++) {
372 uint32_t aw, bw, naw;
373
374 aw = a[u];
375 bw = b[u];
376 naw = aw - bw - cc;
377
378
379
380
381
382 cc = (cc & EQ(naw, aw)) | GT(naw, aw);
383 a[u] = MUX(ctl, naw, aw);
384 }
385 return cc;
386}
387
388
389
390
391
392
393
394
395
396
397static uint32_t br_divrem(uint32_t hi, uint32_t lo, uint32_t d, uint32_t *r)
398{
399
400 uint32_t q;
401 uint32_t ch, cf;
402 int k;
403
404 q = 0;
405 ch = EQ(hi, d);
406 hi = MUX(ch, 0, hi);
407 for (k = 31; k > 0; k --) {
408 int j;
409 uint32_t w, ctl, hi2, lo2;
410
411 j = 32 - k;
412 w = (hi << j) | (lo >> k);
413 ctl = GE(w, d) | (hi >> k);
414 hi2 = (w - d) >> j;
415 lo2 = lo - (d << k);
416 hi = MUX(ctl, hi2, hi);
417 lo = MUX(ctl, lo2, lo);
418 q |= ctl << k;
419 }
420 cf = GE(lo, d) | hi;
421 q |= cf;
422 *r = MUX(cf, lo - d, lo);
423 return q;
424}
425
426
427
428
429
430static uint32_t br_rem(uint32_t hi, uint32_t lo, uint32_t d)
431{
432 uint32_t r;
433
434 br_divrem(hi, lo, d, &r);
435 return r;
436}
437
438
439
440
441
442static uint32_t br_div(uint32_t hi, uint32_t lo, uint32_t d)
443{
444 uint32_t r;
445
446 return br_divrem(hi, lo, d, &r);
447}
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462static void br_i32_muladd_small(uint32_t *x, uint32_t z, const uint32_t *m)
463{
464 uint32_t m_bitlen;
465 size_t u, mlen;
466 uint32_t a0, a1, b0, hi, g, q, tb;
467 uint32_t chf, clow, under, over;
468 uint64_t cc;
469
470
471
472
473
474 m_bitlen = m[0];
475 if (m_bitlen == 0) {
476 return;
477 }
478 if (m_bitlen <= 32) {
479 x[1] = br_rem(x[1], z, m[1]);
480 return;
481 }
482 mlen = (m_bitlen + 31) >> 5;
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510 a0 = br_i32_word(x, m_bitlen - 32);
511 hi = x[mlen];
512 memmove(x + 2, x + 1, (mlen - 1) * sizeof *x);
513 x[1] = z;
514 a1 = br_i32_word(x, m_bitlen - 32);
515 b0 = br_i32_word(m, m_bitlen - 32);
516
517
518
519
520
521
522
523
524
525
526
527 g = br_div(a0, a1, b0);
528 q = MUX(EQ(a0, b0), 0xFFFFFFFF, MUX(EQ(g, 0), 0, g - 1));
529
530
531
532
533
534
535
536
537
538
539 cc = 0;
540 tb = 1;
541 for (u = 1; u <= mlen; u ++) {
542 uint32_t mw, zw, xw, nxw;
543 uint64_t zl;
544
545 mw = m[u];
546 zl = MUL(mw, q) + cc;
547 cc = (uint32_t)(zl >> 32);
548 zw = (uint32_t)zl;
549 xw = x[u];
550 nxw = xw - zw;
551 cc += (uint64_t)GT(nxw, xw);
552 x[u] = nxw;
553 tb = MUX(EQ(nxw, mw), tb, GT(nxw, mw));
554 }
555
556
557
558
559
560
561
562
563
564
565 chf = (uint32_t)(cc >> 32);
566 clow = (uint32_t)cc;
567 over = chf | GT(clow, hi);
568 under = ~over & (tb | (~chf & LT(clow, hi)));
569 br_i32_add(x, m, over);
570 br_i32_sub(x, m, under);
571}
572
573
574
575
576
577
578
579
580
581
582
583static void br_i32_reduce(uint32_t *x, const uint32_t *a, const uint32_t *m)
584{
585 uint32_t m_bitlen, a_bitlen;
586 size_t mlen, alen, u;
587
588 m_bitlen = m[0];
589 mlen = (m_bitlen + 31) >> 5;
590
591 x[0] = m_bitlen;
592 if (m_bitlen == 0) {
593 return;
594 }
595
596
597
598
599
600 a_bitlen = a[0];
601 alen = (a_bitlen + 31) >> 5;
602 if (a_bitlen < m_bitlen) {
603 memcpy(x + 1, a + 1, alen * sizeof *a);
604 for (u = alen; u < mlen; u ++) {
605 x[u + 1] = 0;
606 }
607 return;
608 }
609
610
611
612
613
614
615 memcpy(x + 1, a + 2 + (alen - mlen), (mlen - 1) * sizeof *a);
616 x[mlen] = 0;
617 for (u = 1 + alen - mlen; u > 0; u --) {
618 br_i32_muladd_small(x, a[u], m);
619 }
620}
621
622
623
624
625
626
627
628void rsa_free_key_prop(struct key_prop *prop)
629{
630 if (!prop)
631 return;
632
633 free((void *)prop->modulus);
634 free((void *)prop->public_exponent);
635 free((void *)prop->rr);
636
637 free(prop);
638}
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653int rsa_gen_key_prop(const void *key, uint32_t keylen, struct key_prop **prop)
654{
655 struct rsa_key rsa_key;
656 uint32_t *n = NULL, *rr = NULL, *rrtmp = NULL;
657 int rlen, i, ret = 0;
658
659 *prop = calloc(sizeof(**prop), 1);
660 if (!(*prop)) {
661 ret = -ENOMEM;
662 goto out;
663 }
664
665 ret = rsa_parse_pub_key(&rsa_key, key, keylen);
666 if (ret)
667 goto out;
668
669
670
671 for (i = 0; i < rsa_key.n_sz && !rsa_key.n[i]; i++)
672 ;
673 (*prop)->num_bits = (rsa_key.n_sz - i) * 8;
674 (*prop)->modulus = malloc(rsa_key.n_sz - i);
675 if (!(*prop)->modulus) {
676 ret = -ENOMEM;
677 goto out;
678 }
679 memcpy((void *)(*prop)->modulus, &rsa_key.n[i], rsa_key.n_sz - i);
680
681 n = calloc(sizeof(uint32_t), 1 + ((*prop)->num_bits >> 5));
682 rr = calloc(sizeof(uint32_t), 1 + (((*prop)->num_bits * 2) >> 5));
683 rrtmp = calloc(sizeof(uint32_t), 2 + (((*prop)->num_bits * 2) >> 5));
684 if (!n || !rr || !rrtmp) {
685 ret = -ENOMEM;
686 goto out;
687 }
688
689
690 (*prop)->public_exponent = calloc(1, sizeof(uint64_t));
691 if (!(*prop)->public_exponent) {
692 ret = -ENOMEM;
693 goto out;
694 }
695 memcpy((void *)(*prop)->public_exponent + sizeof(uint64_t)
696 - rsa_key.e_sz,
697 rsa_key.e, rsa_key.e_sz);
698 (*prop)->exp_len = sizeof(uint64_t);
699
700
701 br_i32_decode(n, &rsa_key.n[i], rsa_key.n_sz - i);
702 (*prop)->n0inv = br_i32_ninv32(n[1]);
703
704
705 rlen = (*prop)->num_bits * 2;
706 rr[0] = 0;
707 *(uint8_t *)&rr[0] = (1 << (rlen % 8));
708 for (i = 1; i < (((rlen + 31) >> 5) + 1); i++)
709 rr[i] = 0;
710 br_i32_decode(rrtmp, rr, ((rlen + 7) >> 3) + 1);
711 br_i32_reduce(rr, rrtmp, n);
712
713 rlen = ((*prop)->num_bits + 7) >> 3;
714 (*prop)->rr = malloc(rlen);
715 if (!(*prop)->rr) {
716 ret = -ENOMEM;
717 goto out;
718 }
719 br_i32_encode((void *)(*prop)->rr, rlen, rr);
720
721out:
722 free(n);
723 free(rr);
724 free(rrtmp);
725 if (ret < 0)
726 rsa_free_key_prop(*prop);
727 return ret;
728}
729