jerpelea opened a new pull request, #20313: URL: https://github.com/apache/nuttx/pull/20313
## Summary <p dir="auto">NuttX emits no AES instruction on any core. arm64 has no runtime feature dispatch, so a part that implements the Cryptography Extension still runs <a href="https://github.com/apache/nuttx/blob/master/crypto/rijndael.c">https://github.com/apache/nuttx/blob/master/crypto/rijndael.c</a>, which indexes eight 256-entry tables with key-dependent values and so has cache-dependent timing.</p> <h2 dir="auto">How</h2> <p dir="auto"><code class="notranslate">aes_cypher()</code> for ECB, CBC and CTR on <code class="notranslate">AESE</code>, <code class="notranslate">AESD</code> and the MixColumns pair, registered with <code class="notranslate">/dev/crypto</code> beside <a href="https://github.com/apache/nuttx/blob/master/arch/arm/src/stm32h7/stm32_crypto.c">https://github.com/apache/nuttx/blob/master/arch/arm/src/stm32h7/stm32_crypto.c</a>, <a href="https://github.com/apache/nuttx/blob/master/arch/arm/src/sam34/sam_crypto.c">https://github.com/apache/nuttx/blob/master/arch/arm/src/sam34/sam_crypto.c</a> and <a href="https://github.com/apache/nuttx/blob/master/arch/xtensa/src/esp32/esp32_crypto.c">https://github.com/apache/nuttx/blob/master/arch/xtensa/src/esp32/esp32_crypto.c</a>.</p> <p dir="auto"><code class="notranslate">ID_AA64ISAR0_EL1.AES</code> is read on every call, returning <code class="notranslate">-ENOTSUP</code> rather than trapping.</p> <markdown-accessiblity-table data-catalyst=""> Point | -- | -- the first version defined the crypto/aes.h entry points | same five symbols as https://github.com/apache/nuttx/blob/master/crypto/aes.c, independent Kconfig gates, so enabling both failed to link. The aes_cypher() shape has no such clash SubWord borrows AESE with a zero round key | that yields the substituted word only if ShiftRows has nothing to move, so the word is replicated across all four columns first the CTR counter is the last four bytes | as https://github.com/apache/nuttx/blob/master/crypto/xform.c does, so both agree on what a stream looks like </markdown-accessiblity-table> <p dir="auto"><strong>Open, and why this is still a draft:</strong> <code class="notranslate">xform.c</code>, <code class="notranslate">gmac.c</code>, <code class="notranslate">cmac.c</code> and <code class="notranslate">key_wrap.c</code> reach AES through <code class="notranslate">AES_CTX</code> and keep the table version. Gating <code class="notranslate">crypto/aes.c</code> off when an arch provides those entry points would cover them. Happy to add that here.</p> ## Impact RELEASE ## Testing CI -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
