jerpelea opened a new pull request, #20313:
URL: https://github.com/apache/nuttx/pull/20313

   ## Summary
   
   <p dir="auto">NuttX emits no AES instruction on any core. arm64 has no 
runtime feature dispatch, so a part that implements the Cryptography Extension 
still runs <a 
href="https://github.com/apache/nuttx/blob/master/crypto/rijndael.c";>https://github.com/apache/nuttx/blob/master/crypto/rijndael.c</a>,
 which indexes eight 256-entry tables with key-dependent values and so has 
cache-dependent timing.</p>
   <h2 dir="auto">How</h2>
   <p dir="auto"><code class="notranslate">aes_cypher()</code> for ECB, CBC and 
CTR on <code class="notranslate">AESE</code>, <code 
class="notranslate">AESD</code> and the MixColumns pair, registered with <code 
class="notranslate">/dev/crypto</code> beside <a 
href="https://github.com/apache/nuttx/blob/master/arch/arm/src/stm32h7/stm32_crypto.c";>https://github.com/apache/nuttx/blob/master/arch/arm/src/stm32h7/stm32_crypto.c</a>,
 <a 
href="https://github.com/apache/nuttx/blob/master/arch/arm/src/sam34/sam_crypto.c";>https://github.com/apache/nuttx/blob/master/arch/arm/src/sam34/sam_crypto.c</a>
 and <a 
href="https://github.com/apache/nuttx/blob/master/arch/xtensa/src/esp32/esp32_crypto.c";>https://github.com/apache/nuttx/blob/master/arch/xtensa/src/esp32/esp32_crypto.c</a>.</p>
   <p dir="auto"><code class="notranslate">ID_AA64ISAR0_EL1.AES</code> is read 
on every call, returning <code class="notranslate">-ENOTSUP</code> rather than 
trapping.</p>
   <markdown-accessiblity-table data-catalyst="">
   Point |  
   -- | --
   the first version defined the crypto/aes.h entry points | same five symbols 
as https://github.com/apache/nuttx/blob/master/crypto/aes.c, independent 
Kconfig gates, so enabling both failed to link. The aes_cypher() shape has no 
such clash
   SubWord borrows AESE with a zero round key | that yields the substituted 
word only if ShiftRows has nothing to move, so the word is replicated across 
all four columns first
   the CTR counter is the last four bytes | as 
https://github.com/apache/nuttx/blob/master/crypto/xform.c does, so both agree 
on what a stream looks like
   
   </markdown-accessiblity-table>
   <p dir="auto"><strong>Open, and why this is still a draft:</strong> <code 
class="notranslate">xform.c</code>, <code class="notranslate">gmac.c</code>, 
<code class="notranslate">cmac.c</code> and <code 
class="notranslate">key_wrap.c</code> reach AES through <code 
class="notranslate">AES_CTX</code> and keep the table version. Gating <code 
class="notranslate">crypto/aes.c</code> off when an arch provides those entry 
points would cover them. Happy to add that here.</p>
   
   ## Impact
   
   RELEASE
   
   ## Testing
   
   CI


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to