1 /* SPDX-License-Identifier: BSD-2-Clause */
2 /*
3 * Copyright (c) 2014, STMicroelectronics International N.V.
4 * Copyright (c) 2021, SumUp Services GmbH
5 */
6 #ifndef UTEE_DEFINES_H
7 #define UTEE_DEFINES_H
8
9 #include <compiler.h>
10 #include <tee_api_defines.h>
11 #include <tee_api_defines_extensions.h>
12 #include <types_ext.h>
13
14 /*
15 * Copied from TEE Internal API specificaion v1.0 table 6-9 "Structure of
16 * Algorithm Identifier".
17 */
18 #define TEE_MAIN_ALGO_MD5 0x01
19 #define TEE_MAIN_ALGO_SHA1 0x02
20 #define TEE_MAIN_ALGO_SHA224 0x03
21 #define TEE_MAIN_ALGO_SHA256 0x04
22 #define TEE_MAIN_ALGO_SHA384 0x05
23 #define TEE_MAIN_ALGO_SHA512 0x06
24 #define TEE_MAIN_ALGO_SM3 0x07
25 #define TEE_MAIN_ALGO_SHA3_224 0x08
26 #define TEE_MAIN_ALGO_SHA3_256 0x09
27 #define TEE_MAIN_ALGO_SHA3_384 0x0A
28 #define TEE_MAIN_ALGO_SHA3_512 0x0B
29 #define TEE_MAIN_ALGO_AES 0x10
30 #define TEE_MAIN_ALGO_DES 0x11
31 #define TEE_MAIN_ALGO_DES2 0x12
32 #define TEE_MAIN_ALGO_DES3 0x13
33 #define TEE_MAIN_ALGO_SM4 0x14 /* Not in v1.2, extrapolated */
34 #define TEE_MAIN_ALGO_RSA 0x30
35 #define TEE_MAIN_ALGO_DSA 0x31
36 #define TEE_MAIN_ALGO_DH 0x32
37 #define TEE_MAIN_ALGO_ECDSA 0x41
38 #define TEE_MAIN_ALGO_ECDH 0x42
39 #define TEE_MAIN_ALGO_ED25519 0x43
40 #define TEE_MAIN_ALGO_SM2_DSA_SM3 0x45 /* Not in v1.2 spec */
41 #define TEE_MAIN_ALGO_SM2_KEP 0x46 /* Not in v1.2 spec */
42 #define TEE_MAIN_ALGO_SM2_PKE 0x47 /* Not in v1.2 spec */
43 #define TEE_MAIN_ALGO_HKDF 0xC0 /* OP-TEE extension */
44 #define TEE_MAIN_ALGO_CONCAT_KDF 0xC1 /* OP-TEE extension */
45 #define TEE_MAIN_ALGO_PBKDF2 0xC2 /* OP-TEE extension */
46 #define TEE_MAIN_ALGO_X25519 0x44 /* Not in v1.2 spec */
47 #define TEE_MAIN_ALGO_SHAKE128 0xC3 /* OP-TEE extension */
48 #define TEE_MAIN_ALGO_SHAKE256 0xC4 /* OP-TEE extension */
49 #define TEE_MAIN_ALGO_X448 0x49
50
51
52 #define TEE_CHAIN_MODE_ECB_NOPAD 0x0
53 #define TEE_CHAIN_MODE_CBC_NOPAD 0x1
54 #define TEE_CHAIN_MODE_CTR 0x2
55 #define TEE_CHAIN_MODE_CTS 0x3
56 #define TEE_CHAIN_MODE_XTS 0x4
57 #define TEE_CHAIN_MODE_CBC_MAC_PKCS5 0x5
58 #define TEE_CHAIN_MODE_CMAC 0x6
59 #define TEE_CHAIN_MODE_CCM 0x7
60 #define TEE_CHAIN_MODE_GCM 0x8
61 #define TEE_CHAIN_MODE_PKCS1_PSS_MGF1 0x9 /* ??? */
62
63
__tee_alg_get_class(uint32_t algo)64 static inline uint32_t __tee_alg_get_class(uint32_t algo)
65 {
66 if (algo == TEE_ALG_SM2_PKE)
67 return TEE_OPERATION_ASYMMETRIC_CIPHER;
68 if (algo == TEE_ALG_SM2_KEP)
69 return TEE_OPERATION_KEY_DERIVATION;
70 if (algo == TEE_ALG_RSASSA_PKCS1_V1_5)
71 return TEE_OPERATION_ASYMMETRIC_SIGNATURE;
72 if (algo == TEE_ALG_DES3_CMAC)
73 return TEE_OPERATION_MAC;
74 if (algo == TEE_ALG_SM4_XTS)
75 return TEE_OPERATION_CIPHER;
76 if (algo == TEE_ALG_RSASSA_PKCS1_PSS_MGF1_MD5)
77 return TEE_OPERATION_ASYMMETRIC_SIGNATURE;
78 if (algo == TEE_ALG_RSAES_PKCS1_OAEP_MGF1_MD5)
79 return TEE_OPERATION_ASYMMETRIC_CIPHER;
80
81 return (algo >> 28) & 0xF; /* Bits [31:28] */
82 }
83
84 #define TEE_ALG_GET_CLASS(algo) __tee_alg_get_class(algo)
85
__tee_alg_get_main_alg(uint32_t algo)86 static inline uint32_t __tee_alg_get_main_alg(uint32_t algo)
87 {
88 switch (algo) {
89 case TEE_ALG_SM2_PKE:
90 return TEE_MAIN_ALGO_SM2_PKE;
91 case TEE_ALG_SM2_KEP:
92 return TEE_MAIN_ALGO_SM2_KEP;
93 case TEE_ALG_X25519:
94 return TEE_MAIN_ALGO_X25519;
95 case TEE_ALG_ED25519:
96 return TEE_MAIN_ALGO_ED25519;
97 case TEE_ALG_ECDSA_SHA1:
98 case TEE_ALG_ECDSA_SHA224:
99 case TEE_ALG_ECDSA_SHA256:
100 case TEE_ALG_ECDSA_SHA384:
101 case TEE_ALG_ECDSA_SHA512:
102 return TEE_MAIN_ALGO_ECDSA;
103 case TEE_ALG_HKDF:
104 return TEE_MAIN_ALGO_HKDF;
105 case TEE_ALG_SHAKE128:
106 return TEE_MAIN_ALGO_SHAKE128;
107 case TEE_ALG_SHAKE256:
108 return TEE_MAIN_ALGO_SHAKE256;
109 case TEE_ALG_X448:
110 return TEE_MAIN_ALGO_X448;
111 default:
112 break;
113 }
114
115 return algo & 0xff;
116 }
117
118 #define TEE_ALG_GET_MAIN_ALG(algo) __tee_alg_get_main_alg(algo)
119
120 /* Bits [11:8] */
121 #define TEE_ALG_GET_CHAIN_MODE(algo) (((algo) >> 8) & 0xF)
122
123 /*
124 * Value not defined in the GP spec, and not used as bits 15-12 of any TEE_ALG*
125 * value. TEE_ALG_SM2_DSA_SM3 has value 0x6 for bits 15-12 which would yield the
126 * SHA512 digest if we were to apply the bit masks that were valid up to the TEE
127 * Internal Core API v1.1.
128 */
129 #define __TEE_MAIN_HASH_SM3 0x7
130
__tee_alg_get_digest_hash(uint32_t algo)131 static inline uint32_t __tee_alg_get_digest_hash(uint32_t algo)
132 {
133 if (algo == TEE_ALG_SM2_DSA_SM3)
134 return __TEE_MAIN_HASH_SM3;
135
136 /* Bits [15:12] */
137 return (algo >> 12) & 0xF;
138 }
139
140 #define TEE_ALG_GET_DIGEST_HASH(algo) __tee_alg_get_digest_hash(algo)
141
142 /* Bits [23:20] */
143 #define TEE_ALG_GET_INTERNAL_HASH(algo) (((algo) >> 20) & 0x7)
144
__tee_alg_get_key_type(uint32_t algo,bool with_priv)145 static inline uint32_t __tee_alg_get_key_type(uint32_t algo, bool with_priv)
146 {
147 uint32_t key_type = 0xA0000000 | TEE_ALG_GET_MAIN_ALG(algo);
148
149 if (with_priv)
150 key_type |= 0x01000000;
151
152 return key_type;
153 }
154
155 #define TEE_ALG_GET_KEY_TYPE(algo, with_private_key) \
156 __tee_alg_get_key_type(algo, with_private_key)
157
__tee_alg_hash_algo(uint32_t main_hash)158 static inline uint32_t __tee_alg_hash_algo(uint32_t main_hash)
159 {
160 if (main_hash == __TEE_MAIN_HASH_SM3)
161 return TEE_ALG_SM3;
162
163 return (TEE_OPERATION_DIGEST << 28) | main_hash;
164 }
165
166 /* Return hash algorithm based on main hash */
167 #define TEE_ALG_HASH_ALGO(main_hash) __tee_alg_hash_algo(main_hash)
168
169 /* Extract internal hash and return hash algorithm */
170 #define TEE_INTERNAL_HASH_TO_ALGO(algo) \
171 TEE_ALG_HASH_ALGO(TEE_ALG_GET_INTERNAL_HASH(algo))
172
173 /* Extract digest hash and return hash algorithm */
174 #define TEE_DIGEST_HASH_TO_ALGO(algo) \
175 TEE_ALG_HASH_ALGO(TEE_ALG_GET_DIGEST_HASH(algo))
176
177 /* Return HMAC algorithm based on main hash */
178 #define TEE_ALG_HMAC_ALGO(main_hash) \
179 (TEE_OPERATION_MAC << 28 | (main_hash))
180
181 #define TEE_AES_BLOCK_SIZE 16UL
182 #define TEE_DES_BLOCK_SIZE 8UL
183 #define TEE_SM4_BLOCK_SIZE 16UL
184
185 #define TEE_AES_MAX_KEY_SIZE 32UL
186
187 /* SHA-512 */
188 #ifndef TEE_MD5_HASH_SIZE
189 typedef enum {
190 TEE_MD5_HASH_SIZE = 16,
191 TEE_SHA1_HASH_SIZE = 20,
192 TEE_SHA224_HASH_SIZE = 28,
193 TEE_SHA256_HASH_SIZE = 32,
194 TEE_SM3_HASH_SIZE = 32,
195 TEE_SHA384_HASH_SIZE = 48,
196 TEE_SHA512_HASH_SIZE = 64,
197 TEE_MD5SHA1_HASH_SIZE = (TEE_MD5_HASH_SIZE + TEE_SHA1_HASH_SIZE),
198 TEE_MAX_HASH_SIZE = 64,
199 } t_hash_size;
200 #endif
201
202 #define TEE_MAC_SIZE_AES_CBC_MAC_NOPAD
203 #define TEE_MAC_SIZE_AES_CBC_MAC_PKCS5
204 #define TEE_MAC_SIZE_AES_CMAC
205 #define TEE_MAC_SIZE_DES_CBC_MAC_PKCS5
206
__tee_alg_get_digest_size(uint32_t algo)207 static inline size_t __tee_alg_get_digest_size(uint32_t algo)
208 {
209 switch (algo) {
210 case TEE_ALG_MD5:
211 case TEE_ALG_HMAC_MD5:
212 return TEE_MD5_HASH_SIZE;
213 case TEE_ALG_SHA1:
214 case TEE_ALG_HMAC_SHA1:
215 case TEE_ALG_DSA_SHA1:
216 case TEE_ALG_ECDSA_SHA1:
217 return TEE_SHA1_HASH_SIZE;
218 case TEE_ALG_SHA224:
219 case TEE_ALG_SHA3_224:
220 case TEE_ALG_HMAC_SHA224:
221 case TEE_ALG_HMAC_SHA3_224:
222 case TEE_ALG_DSA_SHA224:
223 case TEE_ALG_ECDSA_SHA224:
224 return TEE_SHA224_HASH_SIZE;
225 case TEE_ALG_SHA256:
226 case TEE_ALG_SHA3_256:
227 case TEE_ALG_HMAC_SHA256:
228 case TEE_ALG_HMAC_SHA3_256:
229 case TEE_ALG_DSA_SHA256:
230 case TEE_ALG_ECDSA_SHA256:
231 return TEE_SHA256_HASH_SIZE;
232 case TEE_ALG_SHA384:
233 case TEE_ALG_SHA3_384:
234 case TEE_ALG_HMAC_SHA384:
235 case TEE_ALG_HMAC_SHA3_384:
236 case TEE_ALG_ECDSA_SHA384:
237 return TEE_SHA384_HASH_SIZE;
238 case TEE_ALG_SHA512:
239 case TEE_ALG_SHA3_512:
240 case TEE_ALG_HMAC_SHA512:
241 case TEE_ALG_HMAC_SHA3_512:
242 case TEE_ALG_ECDSA_SHA512:
243 return TEE_SHA512_HASH_SIZE;
244 case TEE_ALG_SM3:
245 case TEE_ALG_HMAC_SM3:
246 return TEE_SM3_HASH_SIZE;
247 case TEE_ALG_AES_CBC_MAC_NOPAD:
248 case TEE_ALG_AES_CBC_MAC_PKCS5:
249 case TEE_ALG_AES_CMAC:
250 return TEE_AES_BLOCK_SIZE;
251 case TEE_ALG_DES_CBC_MAC_NOPAD:
252 case TEE_ALG_DES_CBC_MAC_PKCS5:
253 case TEE_ALG_DES3_CBC_MAC_NOPAD:
254 case TEE_ALG_DES3_CBC_MAC_PKCS5:
255 case TEE_ALG_DES3_CMAC:
256 return TEE_DES_BLOCK_SIZE;
257 default:
258 return 0;
259 }
260 }
261
262 /* Return algorithm digest size */
263 #define TEE_ALG_GET_DIGEST_SIZE(algo) __tee_alg_get_digest_size(algo)
264
265 /*
266 * Bit indicating that the attribute is a value attribute
267 * See TEE Internal API specificaion v1.0 table 6-12 "Partial Structure of
268 * Attribute Identifier"
269 */
270
271
272 #ifdef __compiler_bswap64
273 #define TEE_U64_BSWAP(x) __compiler_bswap64((x))
274 #else
275 #define TEE_U64_BSWAP(x) ((uint64_t)( \
276 (((uint64_t)(x) & UINT64_C(0xff00000000000000ULL)) >> 56) | \
277 (((uint64_t)(x) & UINT64_C(0x00ff000000000000ULL)) >> 40) | \
278 (((uint64_t)(x) & UINT64_C(0x0000ff0000000000ULL)) >> 24) | \
279 (((uint64_t)(x) & UINT64_C(0x000000ff00000000ULL)) >> 8) | \
280 (((uint64_t)(x) & UINT64_C(0x00000000ff000000ULL)) << 8) | \
281 (((uint64_t)(x) & UINT64_C(0x0000000000ff0000ULL)) << 24) | \
282 (((uint64_t)(x) & UINT64_C(0x000000000000ff00ULL)) << 40) | \
283 (((uint64_t)(x) & UINT64_C(0x00000000000000ffULL)) << 56)))
284 #endif
285
286 #ifdef __compiler_bswap32
287 #define TEE_U32_BSWAP(x) __compiler_bswap32((x))
288 #else
289 #define TEE_U32_BSWAP(x) ((uint32_t)( \
290 (((uint32_t)(x) & UINT32_C(0xff000000)) >> 24) | \
291 (((uint32_t)(x) & UINT32_C(0x00ff0000)) >> 8) | \
292 (((uint32_t)(x) & UINT32_C(0x0000ff00)) << 8) | \
293 (((uint32_t)(x) & UINT32_C(0x000000ff)) << 24)))
294 #endif
295
296 #ifdef __compiler_bswap16
297 #define TEE_U16_BSWAP(x) __compiler_bswap16((x))
298 #else
299 #define TEE_U16_BSWAP(x) ((uint16_t)( \
300 (((uint16_t)(x) & UINT16_C(0xff00)) >> 8) | \
301 (((uint16_t)(x) & UINT16_C(0x00ff)) << 8)))
302 #endif
303
304 /* If we we're on a big endian platform we'll have to update these */
305 #define TEE_U64_FROM_LITTLE_ENDIAN(x) ((uint64_t)(x))
306 #define TEE_U32_FROM_LITTLE_ENDIAN(x) ((uint32_t)(x))
307 #define TEE_U16_FROM_LITTLE_ENDIAN(x) ((uint16_t)(x))
308 #define TEE_U64_TO_LITTLE_ENDIAN(x) ((uint64_t)(x))
309 #define TEE_U32_TO_LITTLE_ENDIAN(x) ((uint32_t)(x))
310 #define TEE_U16_TO_LITTLE_ENDIAN(x) ((uint16_t)(x))
311 #define TEE_U64_FROM_BIG_ENDIAN(x) TEE_U64_BSWAP(x)
312 #define TEE_U32_FROM_BIG_ENDIAN(x) TEE_U32_BSWAP(x)
313 #define TEE_U16_FROM_BIG_ENDIAN(x) TEE_U16_BSWAP(x)
314 #define TEE_U64_TO_BIG_ENDIAN(x) TEE_U64_BSWAP(x)
315 #define TEE_U32_TO_BIG_ENDIAN(x) TEE_U32_BSWAP(x)
316 #define TEE_U16_TO_BIG_ENDIAN(x) TEE_U16_BSWAP(x)
317
318 #define TEE_TIME_MILLIS_BASE 1000
319
320 #define TEE_TIME_LT(t1, t2) \
321 (((t1).seconds == (t2).seconds) ? \
322 ((t1).millis < (t2).millis) : \
323 ((t1).seconds < (t2).seconds))
324
325 #define TEE_TIME_LE(t1, t2) \
326 (((t1).seconds == (t2).seconds) ? \
327 ((t1).millis <= (t2).millis) : \
328 ((t1).seconds <= (t2).seconds))
329
330 #define TEE_TIME_ADD(t1, t2, dst) do { \
331 (dst).seconds = (t1).seconds + (t2).seconds; \
332 (dst).millis = (t1).millis + (t2).millis; \
333 if ((dst).millis >= TEE_TIME_MILLIS_BASE) { \
334 (dst).seconds++; \
335 (dst).millis -= TEE_TIME_MILLIS_BASE; \
336 } \
337 } while (0)
338
339 #define TEE_TIME_SUB(t1, t2, dst) do { \
340 (dst).seconds = (t1).seconds - (t2).seconds; \
341 if ((t1).millis < (t2).millis) { \
342 (dst).seconds--; \
343 (dst).millis = (t1).millis + TEE_TIME_MILLIS_BASE - (t2).millis;\
344 } else { \
345 (dst).millis = (t1).millis - (t2).millis; \
346 } \
347 } while (0)
348
349 /* ------------------------------------------------------------ */
350 /* OTP mapping */
351 /* ------------------------------------------------------------ */
352 #define HW_UNIQUE_KEY_WORD1 (8)
353 #define HW_UNIQUE_KEY_LENGTH (16)
354 #define HW_UNIQUE_KEY_WORD2 (HW_UNIQUE_KEY_WORD1 + 1)
355 #define HW_UNIQUE_KEY_WORD3 (HW_UNIQUE_KEY_WORD1 + 2)
356 #define HW_UNIQUE_KEY_WORD4 (HW_UNIQUE_KEY_WORD1 + 3)
357
358 #define UTEE_SE_READER_PRESENT (1 << 0)
359 #define UTEE_SE_READER_TEE_ONLY (1 << 1)
360 #define UTEE_SE_READER_SELECT_RESPONE_ENABLE (1 << 2)
361
362 #endif /* UTEE_DEFINES_H */
363