From: Stephan Mueller <smueller@chronox.de>
To: Herbert Xu <herbert@gondor.apana.org.au>
Cc: Daniel Borkmann <dborkman@redhat.com>,
quentin.gouchet@gmail.com, LKML <linux-kernel@vger.kernel.org>,
linux-crypto@vger.kernel.org, ABI/API <linux-api@vger.kernel.org>
Subject: Re: [PATCH v2 01/10] crypto: AF_ALG: add user space interface for AEAD
Date: Wed, 19 Nov 2014 01:34:20 +0100 [thread overview]
Message-ID: <2161216.flt1JCFqfn@tachyon.chronox.de> (raw)
In-Reply-To: <20141118140631.GA12100@gondor.apana.org.au>
Am Dienstag, 18. November 2014, 22:06:31 schrieb Herbert Xu:
Hi Herbert,
> On Sun, Nov 16, 2014 at 03:23:50AM +0100, Stephan Mueller wrote:
> > AEAD requires the following data in addition to normal symmetric
> >
> > ciphers:
> > * Associated authentication data of arbitrary length
> >
> > * Authentication tag for decryption
> >
> > * Length of authentication tag for encryption
> >
> > The authentication tag data is communicated as part of the actual
> > ciphertext as mandated by the kernel crypto API. Therefore we only need
> > to provide a user space interface for the associated authentication data
> > as well as for the authentication tag length.
> >
> > This patch adds both as a setsockopt interface that is identical to the
> > AF_ALG interface for setting an IV and for selecting the cipher
> > operation type (encrypt or decrypt).
> >
> > Signed-off-by: Stephan Mueller <smueller@chronox.de>
>
> I don't like the fact that we're putting arbitrary limits on
> the AD, as well as the fact that the way you're doing it the
> AD has to be copied.
>
> How about simply saying that the first X bytes of the input
> shall be the AD?
That is a very good idea.
To cover that approach, the kernel needs to be informed about the length of
the authentication data size to separate the ciphertext/plaintext from the
authentication data.
To cover that, I would recommend to simply send a u32 value to the kernel for
the AD size instead of the AD. The kernel then can adjust the pointers as
necessary.
I will update the patch in the next days to cover that scenario.
Thanks
--
Ciao
Stephan
next prev parent reply other threads:[~2014-11-19 0:34 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-11-16 2:23 [PATCH v2 00/10] crypto: AF_ALG: add AEAD and RNG support Stephan Mueller
2014-11-16 2:23 ` [PATCH v2 01/10] crypto: AF_ALG: add user space interface for AEAD Stephan Mueller
2014-11-18 14:06 ` Herbert Xu
2014-11-19 0:34 ` Stephan Mueller [this message]
2014-11-19 4:20 ` Stephan Mueller
2014-11-19 4:27 ` Herbert Xu
2014-11-19 6:30 ` Stephan Mueller
2014-11-19 6:45 ` Herbert Xu
2014-11-16 2:24 ` [PATCH v2 02/10] crypto: AF_ALG: user space interface for cipher info Stephan Mueller
2014-11-18 14:08 ` Herbert Xu
2014-11-19 1:02 ` Stephan Mueller
2014-11-19 1:05 ` Herbert Xu
2014-11-20 4:03 ` Stephan Mueller
2014-11-20 4:07 ` Herbert Xu
2014-11-20 4:14 ` Stephan Mueller
2014-11-20 4:18 ` Herbert Xu
2014-11-20 4:23 ` Stephan Mueller
2014-11-20 4:46 ` crypto: user - Allow get request with empty driver name Herbert Xu
2014-11-20 7:11 ` Steffen Klassert
2014-11-20 7:45 ` Herbert Xu
2014-11-20 8:04 ` Steffen Klassert
2014-11-20 13:07 ` Stephan Mueller
2014-11-20 13:02 ` Stephan Mueller
2014-11-20 13:10 ` Stephan Mueller
2014-11-20 13:40 ` Herbert Xu
2014-11-20 16:08 ` Stephan Mueller
2014-11-21 2:31 ` Herbert Xu
2014-11-21 2:42 ` Stephan Mueller
2014-11-21 4:40 ` Stephan Mueller
2014-11-20 6:32 ` [PATCH v2 02/10] crypto: AF_ALG: user space interface for cipher info Steffen Klassert
2014-11-20 7:05 ` Steffen Klassert
2014-11-16 2:25 ` [PATCH v2 03/10] crypto: AF_ALG: extend data structuers for AEAD Stephan Mueller
2014-11-16 2:25 ` [PATCH v2 04/10] crypto: AF_ALG: crypto API calls to inline functions Stephan Mueller
2014-11-16 2:26 ` [PATCH v2 05/10] crypto: AF_ALG: add AEAD support Stephan Mueller
2014-11-16 2:26 ` [PATCH v2 06/10] crypto: AF_ALG: make setkey optional Stephan Mueller
2014-11-18 14:10 ` Herbert Xu
2014-11-19 2:36 ` Stephan Mueller
2014-11-16 2:27 ` [PATCH v2 07/10] crypto: AF_ALG: add random number generator support Stephan Mueller
2014-11-16 2:28 ` [PATCH v2 08/10] crypto: AF_ALG: enable RNG interface compilation Stephan Mueller
2014-11-16 2:28 ` [PATCH v2 09/10] crypto: AF_ALG: user space interface for hash info Stephan Mueller
2014-11-16 2:29 ` [PATCH v2 10/10] crypto: AF_ALG: document the user space interface Stephan Mueller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2161216.flt1JCFqfn@tachyon.chronox.de \
--to=smueller@chronox.de \
--cc=dborkman@redhat.com \
--cc=herbert@gondor.apana.org.au \
--cc=linux-api@vger.kernel.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=quentin.gouchet@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome