Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ Information on how to configure, build, and test wolfProvider can be found here:

### Symmetric Ciphers
* AES (128, 192, 256-bit keys)
* ECB, CBC, CTR, CFB, CTS
* ECB, CBC, CTR, CFB, OFB, CTS
* GCM, CCM (AEAD)
* Key Wrap
* 3DES-CBC
Expand Down
8 changes: 8 additions & 0 deletions include/wolfprovider/alg_funcs.h
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,10 @@ typedef void (*DFUNC)(void);
#define WP_NAMES_AES_192_CFB "AES-192-CFB:2.16.840.1.101.3.4.1.24"
#define WP_NAMES_AES_128_CFB "AES-128-CFB:2.16.840.1.101.3.4.1.4"

#define WP_NAMES_AES_256_OFB "AES-256-OFB:2.16.840.1.101.3.4.1.43"
#define WP_NAMES_AES_192_OFB "AES-192-OFB:2.16.840.1.101.3.4.1.23"
#define WP_NAMES_AES_128_OFB "AES-128-OFB:2.16.840.1.101.3.4.1.3"

#define WP_NAMES_AES_256_WRAP \
"AES-256-WRAP:id-aes256-wrap:AES256-WRAP:2.16.840.1.101.3.4.1.45"
#define WP_NAMES_AES_192_WRAP \
Expand Down Expand Up @@ -423,6 +427,10 @@ extern const OSSL_DISPATCH wp_aes256cfb_functions[];
extern const OSSL_DISPATCH wp_aes192cfb_functions[];
extern const OSSL_DISPATCH wp_aes128cfb_functions[];

extern const OSSL_DISPATCH wp_aes256ofb_functions[];
extern const OSSL_DISPATCH wp_aes192ofb_functions[];
extern const OSSL_DISPATCH wp_aes128ofb_functions[];

extern const OSSL_DISPATCH wp_aes256wrap_functions[];
extern const OSSL_DISPATCH wp_aes192wrap_functions[];
extern const OSSL_DISPATCH wp_aes128wrap_functions[];
Expand Down
3 changes: 3 additions & 0 deletions include/wolfprovider/settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -134,6 +134,9 @@
#ifdef WOLFSSL_AES_CFB
#define WP_HAVE_AESCFB
#endif
#ifdef WOLFSSL_AES_OFB
#define WP_HAVE_AESOFB
#endif

#ifndef WC_NO_RNG
#define WP_HAVE_RANDOM
Expand Down
56 changes: 50 additions & 6 deletions src/wp_aes_stream.c
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,8 @@
#include <wolfprovider/settings.h>
#include <wolfprovider/alg_funcs.h>

#if defined(WP_HAVE_AESCTR) || defined(WP_HAVE_AESCFB) || defined(WP_HAVE_AESCTS)
#if defined(WP_HAVE_AESCTR) || defined(WP_HAVE_AESCFB) || \
defined(WP_HAVE_AESOFB) || defined(WP_HAVE_AESCTS)

/**
* Data structure for AES ciphers that are streaming.
Expand All @@ -38,7 +39,7 @@ typedef struct wp_AesStreamCtx {
/** wolfSSL AES object. */
Aes aes;

/** Cipher mode - CTR, CFB or CTS. */
/** Cipher mode - CTR, CFB, OFB or CTS. */
int mode;

/** Length of key in bytes. */
Expand Down Expand Up @@ -323,7 +324,8 @@ static int wp_aes_stream_init(wp_AesStreamCtx *ctx, const unsigned char *key,
}
if (ok && (iv == NULL) && ctx->ivSet &&
((ctx->mode == EVP_CIPH_CBC_MODE) ||
(ctx->mode == EVP_CIPH_CFB_MODE))) {
(ctx->mode == EVP_CIPH_CFB_MODE) ||
(ctx->mode == EVP_CIPH_OFB_MODE))) {
if (!wp_aes_init_iv(ctx, ctx->oiv, ctx->ivLen)) {
ok = 0;
}
Expand Down Expand Up @@ -586,7 +588,7 @@ static int wp_aes_cts_decrypt(wp_AesStreamCtx *ctx, unsigned char *out,
#endif /* ifdef WP_HAVE_AESCTS */

/**
* Encrypt/decrypt using AES-CTR, AES-CFB or AES-CTS with wolfSSL.
* Encrypt/decrypt using AES-CTR, AES-CFB, AES-OFB or AES-CTS with wolfSSL.
*
* Assumes out has inLen bytes available.
* Assumes whole blocks only.
Expand Down Expand Up @@ -657,6 +659,35 @@ static int wp_aes_stream_doit(wp_AesStreamCtx *ctx, unsigned char *out,
}
else
#endif
#ifdef WP_HAVE_AESOFB
if (ctx->mode == EVP_CIPH_OFB_MODE) {
XMEMCPY(&ctx->aes.reg, ctx->iv, ctx->ivLen);
while (ok && (inLen > 0)) {
/* Cap chunk to largest word32 multiple of AES_BLOCK_SIZE so the
* IV state is consistent across chunk boundaries. */
word32 chunk = (inLen > 0xFFFFFFF0U) ? 0xFFFFFFF0U : (word32)inLen;
int rc;
if (ctx->enc) {
rc = wc_AesOfbEncrypt(&ctx->aes, out, in, chunk);
}
else {
rc = wc_AesOfbDecrypt(&ctx->aes, out, in, chunk);
}
if (rc != 0) {
WOLFPROV_MSG_DEBUG_RETCODE(WP_LOG_LEVEL_DEBUG,
"wc_AesOfbEncrypt/wc_AesOfbDecrypt", rc);
Comment on lines +670 to +678
ok = 0;
}
in += chunk;
out += chunk;
inLen -= chunk;
}
if (ok) {
XMEMCPY(ctx->iv, ctx->aes.reg, ctx->ivLen);
}
}
else
#endif
#ifdef WP_HAVE_AESCTS
if (ctx->mode == EVP_CIPH_CBC_MODE) {
if (ctx->updated) {
Expand Down Expand Up @@ -923,7 +954,7 @@ static int wp_aes_stream_set_ctx_params(wp_AesStreamCtx *ctx,
* @param [in, out] ctx AES stream context object.
* @param [in] kBits Number of bits in a valid key.
* @param [in] ivBits Number of bits in a valid IV. 0 indicates no IV.
* @param [in] mode AES stream mode: CTR, CFB or CTS.
* @param [in] mode AES stream mode: CTR, CFB, OFB or CTS.
* @return 1 on success.
* @return 0 on failure.
*/
Expand Down Expand Up @@ -1031,6 +1062,18 @@ IMPLEMENT_AES_STREAM(cfb, CFB, 0, 192, 128)
IMPLEMENT_AES_STREAM(cfb, CFB, 0, 128, 128)
#endif /* WP_HAVE_AESCFB */

/*
* AES OFB
*/
#ifdef WP_HAVE_AESOFB
/** wp_aes256ofb_functions */
IMPLEMENT_AES_STREAM(ofb, OFB, 0, 256, 128)
/** wp_aes192ofb_functions */
IMPLEMENT_AES_STREAM(ofb, OFB, 0, 192, 128)
/** wp_aes128ofb_functions */
IMPLEMENT_AES_STREAM(ofb, OFB, 0, 128, 128)
Comment on lines +1072 to +1074
#endif /* WP_HAVE_AESOFB */

/*
* AES CTS
*
Expand All @@ -1046,5 +1089,6 @@ IMPLEMENT_AES_STREAM(cts, CBC, EVP_CIPH_FLAG_CTS, 192, 128)
IMPLEMENT_AES_STREAM(cts, CBC, EVP_CIPH_FLAG_CTS, 128, 128)
#endif /* WP_HAVE_AESCTS */

#endif /* WP_HAVE_AESCTR || WP_HAVE_AESCFB || WP_HAVE_AESCTS */
#endif /* WP_HAVE_AESCTR || WP_HAVE_AESCFB || WP_HAVE_AESOFB ||
* WP_HAVE_AESCTS */

10 changes: 10 additions & 0 deletions src/wp_wolfprov.c
Original file line number Diff line number Diff line change
Expand Up @@ -531,6 +531,16 @@ static const OSSL_ALGORITHM wolfprov_ciphers[] = {
"" },
#endif

#ifdef WP_HAVE_AESOFB
/* AES-OFB */
{ WP_NAMES_AES_256_OFB, WOLFPROV_PROPERTIES, wp_aes256ofb_functions,
"" },
{ WP_NAMES_AES_192_OFB, WOLFPROV_PROPERTIES, wp_aes192ofb_functions,
"" },
{ WP_NAMES_AES_128_OFB, WOLFPROV_PROPERTIES, wp_aes128ofb_functions,
"" },
#endif

#ifdef WP_HAVE_AESCTS
/* AES-CTS */
{ WP_NAMES_AES_256_CTS, WOLFPROV_PROPERTIES, wp_aes256cts_functions,
Expand Down
Loading
Loading