Add AES-GMAC (RTE_CRYPTO_AUTH_AES_GMAC) support to the dpaa2_sec driver
for both symmetric auth-only and IPsec lookaside protocol paths.

For the auth-only path, AES-GMAC uses the GCM shared descriptor
(cnstr_shdsc_gcm_encap/decap) with per-packet IV and data supplied
via sym_op->auth.{iv,data,digest}.

For the IPsec lookaside protocol path, AES-GMAC maps to
OP_PCL_IPSEC_AES_NULL_WITH_GMAC.  The SEC hardware protocol word
treats this as a cipher type, so the GMAC key and algtype are placed
in cipherdata rather than authdata.  This is handled in
dpaa2_sec_ipsec_proto_init() by overriding cipherdata with the auth
key and setting authdata algtype to HMAC_NULL.

Also add AES-GMAC to dpaa2_sec_capabilities[] as an AUTH xform.

Signed-off-by: Gagandeep Singh <[email protected]>
---
 doc/guides/cryptodevs/dpaa2_sec.rst          |  1 +
 doc/guides/cryptodevs/features/dpaa2_sec.ini |  3 ++
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c  | 43 +++++++++++++++++++-
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h    | 28 ++++++++++++-
 4 files changed, 73 insertions(+), 2 deletions(-)

diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst 
b/doc/guides/cryptodevs/dpaa2_sec.rst
index 925d3371bf..d9a661c272 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -125,6 +125,7 @@ Hash algorithms:
 * ``RTE_CRYPTO_AUTH_MD5_HMAC``
 * ``RTE_CRYPTO_AUTH_AES_XCBC_MAC``
 * ``RTE_CRYPTO_AUTH_AES_CMAC``
+* ``RTE_CRYPTO_AUTH_AES_GMAC``
 
 AEAD algorithms:
 
diff --git a/doc/guides/cryptodevs/features/dpaa2_sec.ini 
b/doc/guides/cryptodevs/features/dpaa2_sec.ini
index a280c7b51b..49434739f0 100644
--- a/doc/guides/cryptodevs/features/dpaa2_sec.ini
+++ b/doc/guides/cryptodevs/features/dpaa2_sec.ini
@@ -48,6 +48,9 @@ SHA384 HMAC  = Y
 SHA512       = Y
 SHA512 HMAC  = Y
 SNOW3G UIA2  = Y
+AES GMAC (128) = Y
+AES GMAC (192) = Y
+AES GMAC (256) = Y
 AES XCBC MAC = Y
 ZUC EIA3     = Y
 AES CMAC (128) = Y
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c 
b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 0ff54fb644..8e271a3b50 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1,7 +1,7 @@
 /* SPDX-License-Identifier: BSD-3-Clause
  *
  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- *   Copyright 2016-2025 NXP
+ *   Copyright 2016-2026 NXP
  *
  */
 
@@ -2483,6 +2483,30 @@ dpaa2_sec_auth_init(struct rte_crypto_sym_xform *xform,
                                           !session->dir,
                                           session->digest_length);
                break;
+       case RTE_CRYPTO_AUTH_AES_GMAC:
+               /* AES-GMAC is an authentication-only operation using the
+                * GCM algorithm with a zero-length payload.  The IV is
+                * passed per-packet via the auth xform iv field, and the
+                * data to authenticate is in sym_op->auth.data.
+                */
+               session->iv.offset = xform->auth.iv.offset;
+               session->iv.length = xform->auth.iv.length;
+               session->auth_alg = RTE_CRYPTO_AUTH_AES_GMAC;
+               authdata.algtype = OP_ALG_ALGSEL_AES;
+               authdata.algmode = OP_ALG_AAI_GCM;
+               if (session->dir == DIR_ENC)
+                       bufsize = cnstr_shdsc_gcm_encap(
+                                       priv->flc_desc[DESC_INITFINAL].desc,
+                                       1, 0, SHR_NEVER, &authdata,
+                                       session->iv.length,
+                                       session->digest_length);
+               else
+                       bufsize = cnstr_shdsc_gcm_decap(
+                                       priv->flc_desc[DESC_INITFINAL].desc,
+                                       1, 0, SHR_NEVER, &authdata,
+                                       session->iv.length,
+                                       session->digest_length);
+               break;
        default:
                DPAA2_SEC_ERR("Crypto: Unsupported Auth alg %s (%u)",
                        rte_cryptodev_get_auth_algo_string(xform->auth.algo),
@@ -3046,6 +3070,18 @@ dpaa2_sec_ipsec_proto_init(struct 
rte_crypto_cipher_xform *cipher_xform,
                authdata->algtype = OP_PCL_IPSEC_HMAC_MD5_96;
                authdata->algmode = OP_ALG_AAI_HMAC;
                break;
+       case RTE_CRYPTO_AUTH_AES_GMAC:
+               /* AES-GMAC uses OP_PCL_IPSEC_AES_NULL_WITH_GMAC which is
+                * treated as a cipher type in the SEC protocol word.
+                * Place the GMAC key in cipherdata and set authdata to NULL.
+                */
+               cipherdata->key = (size_t)session->auth_key.data;
+               cipherdata->keylen = session->auth_key.length;
+               cipherdata->key_enc_flags = 0;
+               cipherdata->key_type = RTA_DATA_IMM;
+               cipherdata->algtype = OP_PCL_IPSEC_AES_NULL_WITH_GMAC;
+               authdata->algtype = OP_PCL_IPSEC_HMAC_NULL;
+               return 0;
        case RTE_CRYPTO_AUTH_SHA224_HMAC:
                authdata->algmode = OP_ALG_AAI_HMAC;
                if (session->digest_length == 6)
@@ -3142,6 +3178,9 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 
        PMD_INIT_FUNC_TRACE();
 
+       memset(&authdata, 0, sizeof(authdata));
+       memset(&cipherdata, 0, sizeof(cipherdata));
+
        RTE_SET_USED(dev);
 
        /** Make FLC address to align with stashing, low 6 bits are used
@@ -3217,6 +3256,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
                case OP_PCL_IPSEC_AES_GCM8:
                case OP_PCL_IPSEC_AES_GCM12:
                case OP_PCL_IPSEC_AES_GCM16:
+               case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
                        memcpy(encap_pdb.gcm.salt,
                                (uint8_t *)&(ipsec_xform->salt), 4);
                        break;
@@ -3357,6 +3397,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
                case OP_PCL_IPSEC_AES_GCM8:
                case OP_PCL_IPSEC_AES_GCM12:
                case OP_PCL_IPSEC_AES_GCM16:
+               case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
                        memcpy(decap_pdb.gcm.salt,
                                (uint8_t *)&(ipsec_xform->salt), 4);
                        break;
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h 
b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 94ba321c72..913c91ebc2 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1,7 +1,7 @@
 /* SPDX-License-Identifier: BSD-3-Clause
  *
  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- *   Copyright 2016,2020-2024 NXP
+ *   Copyright 2016,2020-2026 NXP
  *
  */
 
@@ -528,6 +528,32 @@ static const struct rte_cryptodev_capabilities 
dpaa2_sec_capabilities[] = {
                        }, }
                }, }
        },
+       {       /* AES GMAC */
+               .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+               {.sym = {
+                       .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+                       {.auth = {
+                               .algo = RTE_CRYPTO_AUTH_AES_GMAC,
+                               .block_size = 16,
+                               .key_size = {
+                                       .min = 16,
+                                       .max = 32,
+                                       .increment = 8
+                               },
+                               .digest_size = {
+                                       .min = 8,
+                                       .max = 16,
+                                       .increment = 4
+                               },
+                               .aad_size = { 0 },
+                               .iv_size = {
+                                       .min = 12,
+                                       .max = 12,
+                                       .increment = 0
+                               },
+                       }, }
+               }, }
+       },
        {       /* AES XCBC HMAC */
                .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
                {.sym = {
-- 
2.25.1

Reply via email to