1 /* SPDX-License-Identifier: BSD-2-Clause */ 2 /* 3 * Copyright (c) 2014, STMicroelectronics International N.V. 4 * Copyright (c) 2021, SumUp Services GmbH 5 */ 6 #ifndef UTEE_DEFINES_H 7 #define UTEE_DEFINES_H 8 9 #include <compiler.h> 10 #include <tee_api_defines.h> 11 #include <tee_api_defines_extensions.h> 12 #include <types_ext.h> 13 14 /* 15 * Copied from TEE Internal API specificaion v1.0 table 6-9 "Structure of 16 * Algorithm Identifier". 17 */ 18 #define TEE_MAIN_ALGO_MD5 0x01 19 #define TEE_MAIN_ALGO_SHA1 0x02 20 #define TEE_MAIN_ALGO_SHA224 0x03 21 #define TEE_MAIN_ALGO_SHA256 0x04 22 #define TEE_MAIN_ALGO_SHA384 0x05 23 #define TEE_MAIN_ALGO_SHA512 0x06 24 #define TEE_MAIN_ALGO_SM3 0x07 25 #define TEE_MAIN_ALGO_SHA3_224 0x08 26 #define TEE_MAIN_ALGO_SHA3_256 0x09 27 #define TEE_MAIN_ALGO_SHA3_384 0x0A 28 #define TEE_MAIN_ALGO_SHA3_512 0x0B 29 #define TEE_MAIN_ALGO_AES 0x10 30 #define TEE_MAIN_ALGO_DES 0x11 31 #define TEE_MAIN_ALGO_DES2 0x12 32 #define TEE_MAIN_ALGO_DES3 0x13 33 #define TEE_MAIN_ALGO_SM4 0x14 /* Not in v1.2, extrapolated */ 34 #define TEE_MAIN_ALGO_RSA 0x30 35 #define TEE_MAIN_ALGO_DSA 0x31 36 #define TEE_MAIN_ALGO_DH 0x32 37 #define TEE_MAIN_ALGO_ECDSA 0x41 38 #define TEE_MAIN_ALGO_ECDH 0x42 39 #define TEE_MAIN_ALGO_ED25519 0x43 40 #define TEE_MAIN_ALGO_SM2_DSA_SM3 0x45 /* Not in v1.2 spec */ 41 #define TEE_MAIN_ALGO_SM2_KEP 0x46 /* Not in v1.2 spec */ 42 #define TEE_MAIN_ALGO_SM2_PKE 0x47 /* Not in v1.2 spec */ 43 #define TEE_MAIN_ALGO_HKDF 0xC0 /* OP-TEE extension */ 44 #define TEE_MAIN_ALGO_CONCAT_KDF 0xC1 /* OP-TEE extension */ 45 #define TEE_MAIN_ALGO_PBKDF2 0xC2 /* OP-TEE extension */ 46 #define TEE_MAIN_ALGO_X25519 0x44 /* Not in v1.2 spec */ 47 #define TEE_MAIN_ALGO_SHAKE128 0xC3 /* OP-TEE extension */ 48 #define TEE_MAIN_ALGO_SHAKE256 0xC4 /* OP-TEE extension */ 49 #define TEE_MAIN_ALGO_X448 0x49 50 51 52 #define TEE_CHAIN_MODE_ECB_NOPAD 0x0 53 #define TEE_CHAIN_MODE_CBC_NOPAD 0x1 54 #define TEE_CHAIN_MODE_CTR 0x2 55 #define TEE_CHAIN_MODE_CTS 0x3 56 #define TEE_CHAIN_MODE_XTS 0x4 57 #define TEE_CHAIN_MODE_CBC_MAC_PKCS5 0x5 58 #define TEE_CHAIN_MODE_CMAC 0x6 59 #define TEE_CHAIN_MODE_CCM 0x7 60 #define TEE_CHAIN_MODE_GCM 0x8 61 #define TEE_CHAIN_MODE_PKCS1_PSS_MGF1 0x9 /* ??? */ 62 63 64 static inline uint32_t __tee_alg_get_class(uint32_t algo) 65 { 66 if (algo == TEE_ALG_SM2_PKE) 67 return TEE_OPERATION_ASYMMETRIC_CIPHER; 68 if (algo == TEE_ALG_SM2_KEP) 69 return TEE_OPERATION_KEY_DERIVATION; 70 if (algo == TEE_ALG_RSASSA_PKCS1_V1_5) 71 return TEE_OPERATION_ASYMMETRIC_SIGNATURE; 72 if (algo == TEE_ALG_DES3_CMAC) 73 return TEE_OPERATION_MAC; 74 if (algo == TEE_ALG_SM4_XTS) 75 return TEE_OPERATION_CIPHER; 76 if (algo == TEE_ALG_RSASSA_PKCS1_PSS_MGF1_MD5) 77 return TEE_OPERATION_ASYMMETRIC_SIGNATURE; 78 if (algo == TEE_ALG_RSAES_PKCS1_OAEP_MGF1_MD5) 79 return TEE_OPERATION_ASYMMETRIC_CIPHER; 80 81 return (algo >> 28) & 0xF; /* Bits [31:28] */ 82 } 83 84 #define TEE_ALG_GET_CLASS(algo) __tee_alg_get_class(algo) 85 86 static inline uint32_t __tee_alg_get_main_alg(uint32_t algo) 87 { 88 switch (algo) { 89 case TEE_ALG_SM2_PKE: 90 return TEE_MAIN_ALGO_SM2_PKE; 91 case TEE_ALG_SM2_KEP: 92 return TEE_MAIN_ALGO_SM2_KEP; 93 case TEE_ALG_X25519: 94 return TEE_MAIN_ALGO_X25519; 95 case TEE_ALG_ED25519: 96 return TEE_MAIN_ALGO_ED25519; 97 case TEE_ALG_ECDSA_SHA1: 98 case TEE_ALG_ECDSA_SHA224: 99 case TEE_ALG_ECDSA_SHA256: 100 case TEE_ALG_ECDSA_SHA384: 101 case TEE_ALG_ECDSA_SHA512: 102 return TEE_MAIN_ALGO_ECDSA; 103 case TEE_ALG_HKDF: 104 return TEE_MAIN_ALGO_HKDF; 105 case TEE_ALG_SHAKE128: 106 return TEE_MAIN_ALGO_SHAKE128; 107 case TEE_ALG_SHAKE256: 108 return TEE_MAIN_ALGO_SHAKE256; 109 case TEE_ALG_X448: 110 return TEE_MAIN_ALGO_X448; 111 default: 112 break; 113 } 114 115 return algo & 0xff; 116 } 117 118 #define TEE_ALG_GET_MAIN_ALG(algo) __tee_alg_get_main_alg(algo) 119 120 /* Bits [11:8] */ 121 #define TEE_ALG_GET_CHAIN_MODE(algo) (((algo) >> 8) & 0xF) 122 123 /* 124 * Value not defined in the GP spec, and not used as bits 15-12 of any TEE_ALG* 125 * value. TEE_ALG_SM2_DSA_SM3 has value 0x6 for bits 15-12 which would yield the 126 * SHA512 digest if we were to apply the bit masks that were valid up to the TEE 127 * Internal Core API v1.1. 128 */ 129 #define __TEE_MAIN_HASH_SM3 0x7 130 131 static inline uint32_t __tee_alg_get_digest_hash(uint32_t algo) 132 { 133 if (algo == TEE_ALG_SM2_DSA_SM3) 134 return __TEE_MAIN_HASH_SM3; 135 136 /* Bits [15:12] */ 137 return (algo >> 12) & 0xF; 138 } 139 140 #define TEE_ALG_GET_DIGEST_HASH(algo) __tee_alg_get_digest_hash(algo) 141 142 /* Bits [23:20] */ 143 #define TEE_ALG_GET_INTERNAL_HASH(algo) (((algo) >> 20) & 0x7) 144 145 static inline uint32_t __tee_alg_get_key_type(uint32_t algo, bool with_priv) 146 { 147 uint32_t key_type = 0xA0000000 | TEE_ALG_GET_MAIN_ALG(algo); 148 149 if (with_priv) 150 key_type |= 0x01000000; 151 152 return key_type; 153 } 154 155 #define TEE_ALG_GET_KEY_TYPE(algo, with_private_key) \ 156 __tee_alg_get_key_type(algo, with_private_key) 157 158 static inline uint32_t __tee_alg_hash_algo(uint32_t main_hash) 159 { 160 if (main_hash == __TEE_MAIN_HASH_SM3) 161 return TEE_ALG_SM3; 162 163 return (TEE_OPERATION_DIGEST << 28) | main_hash; 164 } 165 166 /* Return hash algorithm based on main hash */ 167 #define TEE_ALG_HASH_ALGO(main_hash) __tee_alg_hash_algo(main_hash) 168 169 /* Extract internal hash and return hash algorithm */ 170 #define TEE_INTERNAL_HASH_TO_ALGO(algo) \ 171 TEE_ALG_HASH_ALGO(TEE_ALG_GET_INTERNAL_HASH(algo)) 172 173 /* Extract digest hash and return hash algorithm */ 174 #define TEE_DIGEST_HASH_TO_ALGO(algo) \ 175 TEE_ALG_HASH_ALGO(TEE_ALG_GET_DIGEST_HASH(algo)) 176 177 /* Return HMAC algorithm based on main hash */ 178 #define TEE_ALG_HMAC_ALGO(main_hash) \ 179 (TEE_OPERATION_MAC << 28 | (main_hash)) 180 181 #define TEE_AES_BLOCK_SIZE 16UL 182 #define TEE_DES_BLOCK_SIZE 8UL 183 #define TEE_SM4_BLOCK_SIZE 16UL 184 185 #define TEE_AES_MAX_KEY_SIZE 32UL 186 187 /* SHA-512 */ 188 #ifndef TEE_MD5_HASH_SIZE 189 typedef enum { 190 TEE_MD5_HASH_SIZE = 16, 191 TEE_SHA1_HASH_SIZE = 20, 192 TEE_SHA224_HASH_SIZE = 28, 193 TEE_SHA256_HASH_SIZE = 32, 194 TEE_SM3_HASH_SIZE = 32, 195 TEE_SHA384_HASH_SIZE = 48, 196 TEE_SHA512_HASH_SIZE = 64, 197 TEE_MD5SHA1_HASH_SIZE = (TEE_MD5_HASH_SIZE + TEE_SHA1_HASH_SIZE), 198 TEE_MAX_HASH_SIZE = 64, 199 } t_hash_size; 200 #endif 201 202 #define TEE_MAC_SIZE_AES_CBC_MAC_NOPAD 203 #define TEE_MAC_SIZE_AES_CBC_MAC_PKCS5 204 #define TEE_MAC_SIZE_AES_CMAC 205 #define TEE_MAC_SIZE_DES_CBC_MAC_PKCS5 206 207 static inline size_t __tee_alg_get_digest_size(uint32_t algo) 208 { 209 switch (algo) { 210 case TEE_ALG_MD5: 211 case TEE_ALG_HMAC_MD5: 212 return TEE_MD5_HASH_SIZE; 213 case TEE_ALG_SHA1: 214 case TEE_ALG_HMAC_SHA1: 215 case TEE_ALG_DSA_SHA1: 216 case TEE_ALG_ECDSA_SHA1: 217 return TEE_SHA1_HASH_SIZE; 218 case TEE_ALG_SHA224: 219 case TEE_ALG_SHA3_224: 220 case TEE_ALG_HMAC_SHA224: 221 case TEE_ALG_HMAC_SHA3_224: 222 case TEE_ALG_DSA_SHA224: 223 case TEE_ALG_ECDSA_SHA224: 224 return TEE_SHA224_HASH_SIZE; 225 case TEE_ALG_SHA256: 226 case TEE_ALG_SHA3_256: 227 case TEE_ALG_HMAC_SHA256: 228 case TEE_ALG_HMAC_SHA3_256: 229 case TEE_ALG_DSA_SHA256: 230 case TEE_ALG_ECDSA_SHA256: 231 return TEE_SHA256_HASH_SIZE; 232 case TEE_ALG_SHA384: 233 case TEE_ALG_SHA3_384: 234 case TEE_ALG_HMAC_SHA384: 235 case TEE_ALG_HMAC_SHA3_384: 236 case TEE_ALG_ECDSA_SHA384: 237 return TEE_SHA384_HASH_SIZE; 238 case TEE_ALG_SHA512: 239 case TEE_ALG_SHA3_512: 240 case TEE_ALG_HMAC_SHA512: 241 case TEE_ALG_HMAC_SHA3_512: 242 case TEE_ALG_ECDSA_SHA512: 243 return TEE_SHA512_HASH_SIZE; 244 case TEE_ALG_SM3: 245 case TEE_ALG_HMAC_SM3: 246 return TEE_SM3_HASH_SIZE; 247 case TEE_ALG_AES_CBC_MAC_NOPAD: 248 case TEE_ALG_AES_CBC_MAC_PKCS5: 249 case TEE_ALG_AES_CMAC: 250 return TEE_AES_BLOCK_SIZE; 251 case TEE_ALG_DES_CBC_MAC_NOPAD: 252 case TEE_ALG_DES_CBC_MAC_PKCS5: 253 case TEE_ALG_DES3_CBC_MAC_NOPAD: 254 case TEE_ALG_DES3_CBC_MAC_PKCS5: 255 case TEE_ALG_DES3_CMAC: 256 return TEE_DES_BLOCK_SIZE; 257 default: 258 return 0; 259 } 260 } 261 262 /* Return algorithm digest size */ 263 #define TEE_ALG_GET_DIGEST_SIZE(algo) __tee_alg_get_digest_size(algo) 264 265 /* 266 * Bit indicating that the attribute is a value attribute 267 * See TEE Internal API specificaion v1.0 table 6-12 "Partial Structure of 268 * Attribute Identifier" 269 */ 270 271 272 #ifdef __compiler_bswap64 273 #define TEE_U64_BSWAP(x) __compiler_bswap64((x)) 274 #else 275 #define TEE_U64_BSWAP(x) ((uint64_t)( \ 276 (((uint64_t)(x) & UINT64_C(0xff00000000000000ULL)) >> 56) | \ 277 (((uint64_t)(x) & UINT64_C(0x00ff000000000000ULL)) >> 40) | \ 278 (((uint64_t)(x) & UINT64_C(0x0000ff0000000000ULL)) >> 24) | \ 279 (((uint64_t)(x) & UINT64_C(0x000000ff00000000ULL)) >> 8) | \ 280 (((uint64_t)(x) & UINT64_C(0x00000000ff000000ULL)) << 8) | \ 281 (((uint64_t)(x) & UINT64_C(0x0000000000ff0000ULL)) << 24) | \ 282 (((uint64_t)(x) & UINT64_C(0x000000000000ff00ULL)) << 40) | \ 283 (((uint64_t)(x) & UINT64_C(0x00000000000000ffULL)) << 56))) 284 #endif 285 286 #ifdef __compiler_bswap32 287 #define TEE_U32_BSWAP(x) __compiler_bswap32((x)) 288 #else 289 #define TEE_U32_BSWAP(x) ((uint32_t)( \ 290 (((uint32_t)(x) & UINT32_C(0xff000000)) >> 24) | \ 291 (((uint32_t)(x) & UINT32_C(0x00ff0000)) >> 8) | \ 292 (((uint32_t)(x) & UINT32_C(0x0000ff00)) << 8) | \ 293 (((uint32_t)(x) & UINT32_C(0x000000ff)) << 24))) 294 #endif 295 296 #ifdef __compiler_bswap16 297 #define TEE_U16_BSWAP(x) __compiler_bswap16((x)) 298 #else 299 #define TEE_U16_BSWAP(x) ((uint16_t)( \ 300 (((uint16_t)(x) & UINT16_C(0xff00)) >> 8) | \ 301 (((uint16_t)(x) & UINT16_C(0x00ff)) << 8))) 302 #endif 303 304 /* If we we're on a big endian platform we'll have to update these */ 305 #define TEE_U64_FROM_LITTLE_ENDIAN(x) ((uint64_t)(x)) 306 #define TEE_U32_FROM_LITTLE_ENDIAN(x) ((uint32_t)(x)) 307 #define TEE_U16_FROM_LITTLE_ENDIAN(x) ((uint16_t)(x)) 308 #define TEE_U64_TO_LITTLE_ENDIAN(x) ((uint64_t)(x)) 309 #define TEE_U32_TO_LITTLE_ENDIAN(x) ((uint32_t)(x)) 310 #define TEE_U16_TO_LITTLE_ENDIAN(x) ((uint16_t)(x)) 311 #define TEE_U64_FROM_BIG_ENDIAN(x) TEE_U64_BSWAP(x) 312 #define TEE_U32_FROM_BIG_ENDIAN(x) TEE_U32_BSWAP(x) 313 #define TEE_U16_FROM_BIG_ENDIAN(x) TEE_U16_BSWAP(x) 314 #define TEE_U64_TO_BIG_ENDIAN(x) TEE_U64_BSWAP(x) 315 #define TEE_U32_TO_BIG_ENDIAN(x) TEE_U32_BSWAP(x) 316 #define TEE_U16_TO_BIG_ENDIAN(x) TEE_U16_BSWAP(x) 317 318 #define TEE_TIME_MILLIS_BASE 1000 319 320 #define TEE_TIME_LT(t1, t2) \ 321 (((t1).seconds == (t2).seconds) ? \ 322 ((t1).millis < (t2).millis) : \ 323 ((t1).seconds < (t2).seconds)) 324 325 #define TEE_TIME_LE(t1, t2) \ 326 (((t1).seconds == (t2).seconds) ? \ 327 ((t1).millis <= (t2).millis) : \ 328 ((t1).seconds <= (t2).seconds)) 329 330 #define TEE_TIME_ADD(t1, t2, dst) do { \ 331 (dst).seconds = (t1).seconds + (t2).seconds; \ 332 (dst).millis = (t1).millis + (t2).millis; \ 333 if ((dst).millis >= TEE_TIME_MILLIS_BASE) { \ 334 (dst).seconds++; \ 335 (dst).millis -= TEE_TIME_MILLIS_BASE; \ 336 } \ 337 } while (0) 338 339 #define TEE_TIME_SUB(t1, t2, dst) do { \ 340 (dst).seconds = (t1).seconds - (t2).seconds; \ 341 if ((t1).millis < (t2).millis) { \ 342 (dst).seconds--; \ 343 (dst).millis = (t1).millis + TEE_TIME_MILLIS_BASE - (t2).millis;\ 344 } else { \ 345 (dst).millis = (t1).millis - (t2).millis; \ 346 } \ 347 } while (0) 348 349 /* ------------------------------------------------------------ */ 350 /* OTP mapping */ 351 /* ------------------------------------------------------------ */ 352 #define HW_UNIQUE_KEY_WORD1 (8) 353 #define HW_UNIQUE_KEY_LENGTH (16) 354 #define HW_UNIQUE_KEY_WORD2 (HW_UNIQUE_KEY_WORD1 + 1) 355 #define HW_UNIQUE_KEY_WORD3 (HW_UNIQUE_KEY_WORD1 + 2) 356 #define HW_UNIQUE_KEY_WORD4 (HW_UNIQUE_KEY_WORD1 + 3) 357 358 #define UTEE_SE_READER_PRESENT (1 << 0) 359 #define UTEE_SE_READER_TEE_ONLY (1 << 1) 360 #define UTEE_SE_READER_SELECT_RESPONE_ENABLE (1 << 2) 361 362 #endif /* UTEE_DEFINES_H */ 363