Browse Source
Implement the proposed instruction in Zvkg, vghmac.vv, Vector Carryless Multiply Accumulate over GHASH Galois-Field. The instruction performs one step of GHASH routine as described in "NIST Special Publication 800-38D" a.k.a the AES-GCM specification. The logic was written to closely track the pseudo-code in the Zvk specification. Signed-off-by: Eric Gouriou <ego@rivosinc.com> Co-authored-by: Kornel Duleba <mindal@semihalf.com> Signed-off-by: Eric Gouriou <ego@rivosinc.com>pull/1303/head
4 changed files with 89 additions and 2 deletions
@ -0,0 +1,38 @@ |
|||
// vghsh.vv vd, vs2, vs1
|
|||
|
|||
#include "zvk_ext_macros.h" |
|||
|
|||
require_zvkg; |
|||
require(P.VU.vsew == 32); |
|||
require_egw_fits(128); |
|||
|
|||
VI_ZVK_VD_VS1_VS2_EGU32x4_NOVM_LOOP( |
|||
{}, |
|||
{ |
|||
EGU32x4_t Y = vd; // Current partial hash
|
|||
EGU32x4_t X = vs1; // Block cipher output
|
|||
EGU32x4_t H = vs2; // Hash subkey
|
|||
|
|||
EGU32x4_BREV8(H); |
|||
EGU32x4_t Z = {}; |
|||
|
|||
// S = brev8(Y ^ X)
|
|||
EGU32x4_t S; |
|||
EGU32x4_XOR(S, Y, X); |
|||
EGU32x4_BREV8(S); |
|||
|
|||
for (int bit = 0; bit < 128; bit++) { |
|||
if (EGU32x4_ISSET(S, bit)) { |
|||
EGU32x4_XOREQ(Z, H); |
|||
} |
|||
|
|||
const bool reduce = EGU32x4_ISSET(H, 127); |
|||
EGU32x4_LSHIFT(H); // Left shift by 1.
|
|||
if (reduce) { |
|||
H[0] ^= 0x87; // Reduce using x^7 + x^2 + x^1 + 1 polynomial
|
|||
} |
|||
} |
|||
EGU32x4_BREV8(Z); |
|||
vd = Z; |
|||
} |
|||
); |
|||
@ -0,0 +1,32 @@ |
|||
// vgmul.vv vd, vs2
|
|||
|
|||
#include "zvk_ext_macros.h" |
|||
|
|||
require_zvkg; |
|||
require(P.VU.vsew == 32); |
|||
require_egw_fits(128); |
|||
|
|||
VI_ZVK_VD_VS2_EGU32x4_NOVM_LOOP( |
|||
{}, |
|||
{ |
|||
EGU32x4_t Y = vd; // Multiplier
|
|||
EGU32x4_BREV8(Y); |
|||
EGU32x4_t H = vs2; // Multiplicand
|
|||
EGU32x4_BREV8(H); |
|||
EGU32x4_t Z = {}; |
|||
|
|||
for (int bit = 0; bit < 128; bit++) { |
|||
if (EGU32x4_ISSET(Y, bit)) { |
|||
EGU32x4_XOREQ(Z, H); |
|||
} |
|||
|
|||
bool reduce = EGU32x4_ISSET(H, 127); |
|||
EGU32x4_LSHIFT(H); // Lef shift by 1
|
|||
if (reduce) { |
|||
H[0] ^= 0x87; // Reduce using x^7 + x^2 + x^1 + 1 polynomial
|
|||
} |
|||
} |
|||
EGU32x4_BREV8(Z); |
|||
vd = Z; |
|||
} |
|||
); |
|||
Loading…
Reference in new issue