[PATCH v6] Sm3 sm4 ipsec support - #2385
nkaithakadan wants to merge 3 commits into
Conversation
9b2d84b to
5c7d71d
Compare
5c7d71d to
fd1cf02
Compare
fd1cf02 to
c3c0548
Compare
|
Hi @JannePeltonen , could you please review this patch set? |
| icv_len = 16; | ||
| break; | ||
| case ODP_AUTH_ALG_SM3_HMAC: | ||
| icv_len = 16; |
There was a problem hiding this comment.
Where does this come from? This appears to be half the output length of HMAC-SM3. Without knowing better, I think other plausible lenghts would be 12 and 32 bytes. Do you have a normative reference for how SM4-CBC and HMAC-SM3 are to be used with IPsec or other relevant documentation you could point to?
There was a problem hiding this comment.
The default ICV length of 16 bytes was chosen by analogy with ODP's SHA-256 IPsec default; SM3 default ICV is not yet specified in ODP or in the referenced SM3 docs.
reference doc:
https://www.chinesestandard.net/PDF.aspx/GMT0022-2023
https://www.ietf.org/archive/id/draft-guo-ipsecme-ikev2-using-shangmi-02.html
| int ipsec_check_esp_sm4_cbc_sm3(void) | ||
| { | ||
| return ipsec_check_esp(ODP_CIPHER_ALG_SM4_CBC, 128, | ||
| ODP_AUTH_ALG_SM3_HMAC, 256); |
There was a problem hiding this comment.
Here key length for HMAC-SM3 is 32 bytes but the key used in the test cases is 20 bytes long, so this is internally inconsistent. Which key length is correct? Do you have any source reference?
There was a problem hiding this comment.
HMAC-SM3 allows variable key lengths by RFC 2104.
I could not find an RFC or draft that explicitly says 32 byte key len, but read that since SM3 provides a 256-bit digest, implementations commonly choose a 256-bit (32-byte) key.
So i modified test vector ICV and sm3 key len (to 32B).
| }, | ||
| }; | ||
|
|
||
| static const ODP_UNUSED ipsec_test_packet pkt_ipv4_esp_sm4_cbc_sm3 = { |
There was a problem hiding this comment.
Where does this test vector come from? Have you generated it yourself or does it come from e.g. some standard? And the same question to the other test vectors in the PR.
There was a problem hiding this comment.
Yes Janne.. This test vector was generated internally and is not taken from any rfc.
There was a problem hiding this comment.
ok. It will take me a little while to check it.
Recognize SM4-CBC and HMAC-SM3 as known algorithms with IPsec. Add the algorithms in the IPsec algorithm capability check helper functions and return the default ICV length for SM3-HMAC too. Signed-off-by: Nithinsen Kaithakadan <nkaithakadan@marvell.com>
c3c0548 to
41f64cf
Compare
Add test cases for SM4-CBC and HMAC-SM3. Signed-off-by: Nithinsen Kaithakadan <nkaithakadan@marvell.com>
Add test cases for inbound and outbound AH transport mode using the HMAC-SM3 algorithm. Signed-off-by: Daphne Priscilla <df@marvell.com> Signed-off-by: Nithinsen Kaithakadan <nkaithakadan@marvell.com>
41f64cf to
e4782bb
Compare
|
Hi @JannePeltonen , could you re-review. |
Add IPsec support for SM3 and SM4