Skip to content

[PATCH v6] Sm3 sm4 ipsec support - #2385

Open
nkaithakadan wants to merge 3 commits into
OpenDataPlane:masterfrom
nkaithakadan:sm3-sm4-ipsec-support
Open

nkaithakadan wants to merge 3 commits into
OpenDataPlane:masterfrom
nkaithakadan:sm3-sm4-ipsec-support

Conversation

@nkaithakadan

@nkaithakadan nkaithakadan commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

Add IPsec support for SM3 and SM4

@github-actions github-actions Bot changed the title Sm3 sm4 ipsec support [PATCH v1] Sm3 sm4 ipsec support Aug 12, 2026
@nkaithakadan
nkaithakadan force-pushed the sm3-sm4-ipsec-support branch from 9b2d84b to 5c7d71d Compare August 12, 2026 04:33
@github-actions github-actions Bot changed the title [PATCH v1] Sm3 sm4 ipsec support [PATCH v2] Sm3 sm4 ipsec support Aug 12, 2026
@nkaithakadan
nkaithakadan force-pushed the sm3-sm4-ipsec-support branch from 5c7d71d to fd1cf02 Compare August 12, 2026 05:39
@github-actions github-actions Bot changed the title [PATCH v2] Sm3 sm4 ipsec support [PATCH v3] Sm3 sm4 ipsec support Aug 12, 2026
@nkaithakadan
nkaithakadan force-pushed the sm3-sm4-ipsec-support branch from fd1cf02 to c3c0548 Compare August 14, 2026 09:15
@github-actions github-actions Bot changed the title [PATCH v3] Sm3 sm4 ipsec support [PATCH v4] Sm3 sm4 ipsec support Aug 14, 2026
@nkaithakadan

Copy link
Copy Markdown
Contributor Author

Hi @JannePeltonen , could you please review this patch set?

Comment thread helper/ipsec.c
icv_len = 16;
break;
case ODP_AUTH_ALG_SM3_HMAC:
icv_len = 16;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Where does this come from? This appears to be half the output length of HMAC-SM3. Without knowing better, I think other plausible lenghts would be 12 and 32 bytes. Do you have a normative reference for how SM4-CBC and HMAC-SM3 are to be used with IPsec or other relevant documentation you could point to?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The default ICV length of 16 bytes was chosen by analogy with ODP's SHA-256 IPsec default; SM3 default ICV is not yet specified in ODP or in the referenced SM3 docs.
reference doc:
https://www.chinesestandard.net/PDF.aspx/GMT0022-2023
https://www.ietf.org/archive/id/draft-guo-ipsecme-ikev2-using-shangmi-02.html

Comment thread test/validation/api/ipsec/ipsec.c Outdated
int ipsec_check_esp_sm4_cbc_sm3(void)
{
return ipsec_check_esp(ODP_CIPHER_ALG_SM4_CBC, 128,
ODP_AUTH_ALG_SM3_HMAC, 256);

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here key length for HMAC-SM3 is 32 bytes but the key used in the test cases is 20 bytes long, so this is internally inconsistent. Which key length is correct? Do you have any source reference?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HMAC-SM3 allows variable key lengths by RFC 2104.
I could not find an RFC or draft that explicitly says 32 byte key len, but read that since SM3 provides a 256-bit digest, implementations commonly choose a 256-bit (32-byte) key.
So i modified test vector ICV and sm3 key len (to 32B).

Comment thread test/validation/api/ipsec/ipsec_test_in.c Outdated
Comment thread test/validation/api/ipsec/ipsec_test_out.c Outdated
Comment thread test/validation/api/ipsec/ipsec_test_out.c Outdated
},
};

static const ODP_UNUSED ipsec_test_packet pkt_ipv4_esp_sm4_cbc_sm3 = {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Where does this test vector come from? Have you generated it yourself or does it come from e.g. some standard? And the same question to the other test vectors in the PR.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes Janne.. This test vector was generated internally and is not taken from any rfc.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok. It will take me a little while to check it.

Comment thread test/validation/api/ipsec/test_vectors.h
Recognize SM4-CBC and HMAC-SM3 as known algorithms with IPsec.
Add the algorithms in the IPsec algorithm capability check helper
functions and return the default ICV length for SM3-HMAC too.

Signed-off-by: Nithinsen Kaithakadan <nkaithakadan@marvell.com>
@github-actions github-actions Bot changed the title [PATCH v4] Sm3 sm4 ipsec support [PATCH v5] Sm3 sm4 ipsec support Sep 9, 2026
nkaithakadan and others added 2 commits September 22, 2026 14:31
Add test cases for SM4-CBC and HMAC-SM3.

Signed-off-by: Nithinsen Kaithakadan <nkaithakadan@marvell.com>
Add test cases for inbound and outbound AH transport mode
using the HMAC-SM3 algorithm.

Signed-off-by: Daphne Priscilla <df@marvell.com>
Signed-off-by: Nithinsen Kaithakadan <nkaithakadan@marvell.com>
@github-actions github-actions Bot changed the title [PATCH v5] Sm3 sm4 ipsec support [PATCH v6] Sm3 sm4 ipsec support Sep 22, 2026
@nkaithakadan

Copy link
Copy Markdown
Contributor Author

Hi @JannePeltonen , could you re-review.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants