<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/> <meta http-equiv="X-UA-Compatible" content="IE=9"/> <meta name="generator" content="Doxygen 1.8.5"/> <title>PolarSSL v1.3.8: aesni.c Source File</title> <link href="tabs.css" rel="stylesheet" type="text/css"/> <script type="text/javascript" src="jquery.js"></script> <script type="text/javascript" src="dynsections.js"></script> <link href="doxygen.css" rel="stylesheet" type="text/css" /> </head> <body> <div id="top"><!-- do not remove this div, it is closed by doxygen! --> <div id="titlearea"> <table cellspacing="0" cellpadding="0"> <tbody> <tr style="height: 56px;"> <td style="padding-left: 0.5em;"> <div id="projectname">PolarSSL v1.3.8 </div> </td> </tr> </tbody> </table> </div> <!-- end header part --> <!-- Generated by Doxygen 1.8.5 --> <div id="navrow1" class="tabs"> <ul class="tablist"> <li><a href="index.html"><span>Main Page</span></a></li> <li><a href="modules.html"><span>Modules</span></a></li> <li><a href="annotated.html"><span>Data Structures</span></a></li> <li class="current"><a href="files.html"><span>Files</span></a></li> </ul> </div> <div id="navrow2" class="tabs2"> <ul class="tablist"> <li><a href="files.html"><span>File List</span></a></li> <li><a href="globals.html"><span>Globals</span></a></li> </ul> </div> <div id="nav-path" class="navpath"> <ul> <li class="navelem"><a class="el" href="dir_4478130ea462cc4195c75f9e6ba20061.html">library</a></li> </ul> </div> </div><!-- top --> <div class="header"> <div class="headertitle"> <div class="title">aesni.c</div> </div> </div><!--header--> <div class="contents"> <a href="aesni_8c.html">Go to the documentation of this file.</a><div class="fragment"><div class="line"><a name="l00001"></a><span class="lineno"> 1</span> <span class="comment">/*</span></div> <div class="line"><a name="l00002"></a><span class="lineno"> 2</span> <span class="comment"> * AES-NI support functions</span></div> <div class="line"><a name="l00003"></a><span class="lineno"> 3</span> <span class="comment"> *</span></div> <div class="line"><a name="l00004"></a><span class="lineno"> 4</span> <span class="comment"> * Copyright (C) 2006-2014, Brainspark B.V.</span></div> <div class="line"><a name="l00005"></a><span class="lineno"> 5</span> <span class="comment"> *</span></div> <div class="line"><a name="l00006"></a><span class="lineno"> 6</span> <span class="comment"> * This file is part of PolarSSL (http://www.polarssl.org)</span></div> <div class="line"><a name="l00007"></a><span class="lineno"> 7</span> <span class="comment"> * Lead Maintainer: Paul Bakker <polarssl_maintainer at polarssl.org></span></div> <div class="line"><a name="l00008"></a><span class="lineno"> 8</span> <span class="comment"> *</span></div> <div class="line"><a name="l00009"></a><span class="lineno"> 9</span> <span class="comment"> * All rights reserved.</span></div> <div class="line"><a name="l00010"></a><span class="lineno"> 10</span> <span class="comment"> *</span></div> <div class="line"><a name="l00011"></a><span class="lineno"> 11</span> <span class="comment"> * This program is free software; you can redistribute it and/or modify</span></div> <div class="line"><a name="l00012"></a><span class="lineno"> 12</span> <span class="comment"> * it under the terms of the GNU General Public License as published by</span></div> <div class="line"><a name="l00013"></a><span class="lineno"> 13</span> <span class="comment"> * the Free Software Foundation; either version 2 of the License, or</span></div> <div class="line"><a name="l00014"></a><span class="lineno"> 14</span> <span class="comment"> * (at your option) any later version.</span></div> <div class="line"><a name="l00015"></a><span class="lineno"> 15</span> <span class="comment"> *</span></div> <div class="line"><a name="l00016"></a><span class="lineno"> 16</span> <span class="comment"> * This program is distributed in the hope that it will be useful,</span></div> <div class="line"><a name="l00017"></a><span class="lineno"> 17</span> <span class="comment"> * but WITHOUT ANY WARRANTY; without even the implied warranty of</span></div> <div class="line"><a name="l00018"></a><span class="lineno"> 18</span> <span class="comment"> * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the</span></div> <div class="line"><a name="l00019"></a><span class="lineno"> 19</span> <span class="comment"> * GNU General Public License for more details.</span></div> <div class="line"><a name="l00020"></a><span class="lineno"> 20</span> <span class="comment"> *</span></div> <div class="line"><a name="l00021"></a><span class="lineno"> 21</span> <span class="comment"> * You should have received a copy of the GNU General Public License along</span></div> <div class="line"><a name="l00022"></a><span class="lineno"> 22</span> <span class="comment"> * with this program; if not, write to the Free Software Foundation, Inc.,</span></div> <div class="line"><a name="l00023"></a><span class="lineno"> 23</span> <span class="comment"> * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.</span></div> <div class="line"><a name="l00024"></a><span class="lineno"> 24</span> <span class="comment"> */</span></div> <div class="line"><a name="l00025"></a><span class="lineno"> 25</span> </div> <div class="line"><a name="l00026"></a><span class="lineno"> 26</span> <span class="comment">/*</span></div> <div class="line"><a name="l00027"></a><span class="lineno"> 27</span> <span class="comment"> * [AES-WP] http://software.intel.com/en-us/articles/intel-advanced-encryption-standard-aes-instructions-set</span></div> <div class="line"><a name="l00028"></a><span class="lineno"> 28</span> <span class="comment"> * [CLMUL-WP] http://software.intel.com/en-us/articles/intel-carry-less-multiplication-instruction-and-its-usage-for-computing-the-gcm-mode/</span></div> <div class="line"><a name="l00029"></a><span class="lineno"> 29</span> <span class="comment"> */</span></div> <div class="line"><a name="l00030"></a><span class="lineno"> 30</span> </div> <div class="line"><a name="l00031"></a><span class="lineno"> 31</span> <span class="preprocessor">#if !defined(POLARSSL_CONFIG_FILE)</span></div> <div class="line"><a name="l00032"></a><span class="lineno"> 32</span> <span class="preprocessor"></span><span class="preprocessor">#include "<a class="code" href="config_8h.html">polarssl/config.h</a>"</span></div> <div class="line"><a name="l00033"></a><span class="lineno"> 33</span> <span class="preprocessor">#else</span></div> <div class="line"><a name="l00034"></a><span class="lineno"> 34</span> <span class="preprocessor"></span><span class="preprocessor">#include POLARSSL_CONFIG_FILE</span></div> <div class="line"><a name="l00035"></a><span class="lineno"> 35</span> <span class="preprocessor"></span><span class="preprocessor">#endif</span></div> <div class="line"><a name="l00036"></a><span class="lineno"> 36</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00037"></a><span class="lineno"> 37</span> <span class="preprocessor">#if defined(POLARSSL_AESNI_C)</span></div> <div class="line"><a name="l00038"></a><span class="lineno"> 38</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00039"></a><span class="lineno"> 39</span> <span class="preprocessor">#include "<a class="code" href="aesni_8h.html">polarssl/aesni.h</a>"</span></div> <div class="line"><a name="l00040"></a><span class="lineno"> 40</span> <span class="preprocessor">#include <stdio.h></span></div> <div class="line"><a name="l00041"></a><span class="lineno"> 41</span> </div> <div class="line"><a name="l00042"></a><span class="lineno"> 42</span> <span class="preprocessor">#if defined(POLARSSL_HAVE_X86_64)</span></div> <div class="line"><a name="l00043"></a><span class="lineno"> 43</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00044"></a><span class="lineno"> 44</span> <span class="comment">/*</span></div> <div class="line"><a name="l00045"></a><span class="lineno"> 45</span> <span class="comment"> * AES-NI support detection routine</span></div> <div class="line"><a name="l00046"></a><span class="lineno"> 46</span> <span class="comment"> */</span></div> <div class="line"><a name="l00047"></a><span class="lineno"> 47</span> <span class="keywordtype">int</span> aesni_supports( <span class="keywordtype">unsigned</span> <span class="keywordtype">int</span> what )</div> <div class="line"><a name="l00048"></a><span class="lineno"> 48</span> {</div> <div class="line"><a name="l00049"></a><span class="lineno"> 49</span>  <span class="keyword">static</span> <span class="keywordtype">int</span> done = 0;</div> <div class="line"><a name="l00050"></a><span class="lineno"> 50</span>  <span class="keyword">static</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">int</span> c = 0;</div> <div class="line"><a name="l00051"></a><span class="lineno"> 51</span> </div> <div class="line"><a name="l00052"></a><span class="lineno"> 52</span>  <span class="keywordflow">if</span>( ! done )</div> <div class="line"><a name="l00053"></a><span class="lineno"> 53</span>  {</div> <div class="line"><a name="l00054"></a><span class="lineno"> 54</span>  <span class="keyword">asm</span>( <span class="stringliteral">"movl $1, %%eax \n\t"</span></div> <div class="line"><a name="l00055"></a><span class="lineno"> 55</span>  <span class="stringliteral">"cpuid \n\t"</span></div> <div class="line"><a name="l00056"></a><span class="lineno"> 56</span>  : <span class="stringliteral">"=c"</span> (c)</div> <div class="line"><a name="l00057"></a><span class="lineno"> 57</span>  :</div> <div class="line"><a name="l00058"></a><span class="lineno"> 58</span>  : <span class="stringliteral">"eax"</span>, <span class="stringliteral">"ebx"</span>, <span class="stringliteral">"edx"</span> );</div> <div class="line"><a name="l00059"></a><span class="lineno"> 59</span>  done = 1;</div> <div class="line"><a name="l00060"></a><span class="lineno"> 60</span>  }</div> <div class="line"><a name="l00061"></a><span class="lineno"> 61</span> </div> <div class="line"><a name="l00062"></a><span class="lineno"> 62</span>  <span class="keywordflow">return</span>( ( c & what ) != 0 );</div> <div class="line"><a name="l00063"></a><span class="lineno"> 63</span> }</div> <div class="line"><a name="l00064"></a><span class="lineno"> 64</span> </div> <div class="line"><a name="l00065"></a><span class="lineno"> 65</span> <span class="comment">/*</span></div> <div class="line"><a name="l00066"></a><span class="lineno"> 66</span> <span class="comment"> * Binutils needs to be at least 2.19 to support AES-NI instructions.</span></div> <div class="line"><a name="l00067"></a><span class="lineno"> 67</span> <span class="comment"> * Unfortunately, a lot of users have a lower version now (2014-04).</span></div> <div class="line"><a name="l00068"></a><span class="lineno"> 68</span> <span class="comment"> * Emit bytecode directly in order to support "old" version of gas.</span></div> <div class="line"><a name="l00069"></a><span class="lineno"> 69</span> <span class="comment"> *</span></div> <div class="line"><a name="l00070"></a><span class="lineno"> 70</span> <span class="comment"> * Opcodes from the Intel architecture reference manual, vol. 3.</span></div> <div class="line"><a name="l00071"></a><span class="lineno"> 71</span> <span class="comment"> * We always use registers, so we don't need prefixes for memory operands.</span></div> <div class="line"><a name="l00072"></a><span class="lineno"> 72</span> <span class="comment"> * Operand macros are in gas order (src, dst) as opposed to Intel order</span></div> <div class="line"><a name="l00073"></a><span class="lineno"> 73</span> <span class="comment"> * (dst, src) in order to blend better into the surrounding assembly code.</span></div> <div class="line"><a name="l00074"></a><span class="lineno"> 74</span> <span class="comment"> */</span></div> <div class="line"><a name="l00075"></a><span class="lineno"> 75</span> <span class="preprocessor">#define AESDEC ".byte 0x66,0x0F,0x38,0xDE,"</span></div> <div class="line"><a name="l00076"></a><span class="lineno"> 76</span> <span class="preprocessor"></span><span class="preprocessor">#define AESDECLAST ".byte 0x66,0x0F,0x38,0xDF,"</span></div> <div class="line"><a name="l00077"></a><span class="lineno"> 77</span> <span class="preprocessor"></span><span class="preprocessor">#define AESENC ".byte 0x66,0x0F,0x38,0xDC,"</span></div> <div class="line"><a name="l00078"></a><span class="lineno"> 78</span> <span class="preprocessor"></span><span class="preprocessor">#define AESENCLAST ".byte 0x66,0x0F,0x38,0xDD,"</span></div> <div class="line"><a name="l00079"></a><span class="lineno"> 79</span> <span class="preprocessor"></span><span class="preprocessor">#define AESIMC ".byte 0x66,0x0F,0x38,0xDB,"</span></div> <div class="line"><a name="l00080"></a><span class="lineno"> 80</span> <span class="preprocessor"></span><span class="preprocessor">#define AESKEYGENA ".byte 0x66,0x0F,0x3A,0xDF,"</span></div> <div class="line"><a name="l00081"></a><span class="lineno"> 81</span> <span class="preprocessor"></span><span class="preprocessor">#define PCLMULQDQ ".byte 0x66,0x0F,0x3A,0x44,"</span></div> <div class="line"><a name="l00082"></a><span class="lineno"> 82</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00083"></a><span class="lineno"> 83</span> <span class="preprocessor">#define xmm0_xmm0 "0xC0"</span></div> <div class="line"><a name="l00084"></a><span class="lineno"> 84</span> <span class="preprocessor"></span><span class="preprocessor">#define xmm0_xmm1 "0xC8"</span></div> <div class="line"><a name="l00085"></a><span class="lineno"> 85</span> <span class="preprocessor"></span><span class="preprocessor">#define xmm0_xmm2 "0xD0"</span></div> <div class="line"><a name="l00086"></a><span class="lineno"> 86</span> <span class="preprocessor"></span><span class="preprocessor">#define xmm0_xmm3 "0xD8"</span></div> <div class="line"><a name="l00087"></a><span class="lineno"> 87</span> <span class="preprocessor"></span><span class="preprocessor">#define xmm0_xmm4 "0xE0"</span></div> <div class="line"><a name="l00088"></a><span class="lineno"> 88</span> <span class="preprocessor"></span><span class="preprocessor">#define xmm1_xmm0 "0xC1"</span></div> <div class="line"><a name="l00089"></a><span class="lineno"> 89</span> <span class="preprocessor"></span><span class="preprocessor">#define xmm1_xmm2 "0xD1"</span></div> <div class="line"><a name="l00090"></a><span class="lineno"> 90</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00091"></a><span class="lineno"> 91</span> <span class="comment">/*</span></div> <div class="line"><a name="l00092"></a><span class="lineno"> 92</span> <span class="comment"> * AES-NI AES-ECB block en(de)cryption</span></div> <div class="line"><a name="l00093"></a><span class="lineno"> 93</span> <span class="comment"> */</span></div> <div class="line"><a name="l00094"></a><span class="lineno"> 94</span> <span class="keywordtype">int</span> aesni_crypt_ecb( <a class="code" href="structaes__context.html">aes_context</a> *ctx,</div> <div class="line"><a name="l00095"></a><span class="lineno"> 95</span>  <span class="keywordtype">int</span> mode,</div> <div class="line"><a name="l00096"></a><span class="lineno"> 96</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> input[16],</div> <div class="line"><a name="l00097"></a><span class="lineno"> 97</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> output[16] )</div> <div class="line"><a name="l00098"></a><span class="lineno"> 98</span> {</div> <div class="line"><a name="l00099"></a><span class="lineno"> 99</span>  <span class="keyword">asm</span>( <span class="stringliteral">"movdqu (%3), %%xmm0 \n\t"</span> <span class="comment">// load input</span></div> <div class="line"><a name="l00100"></a><span class="lineno"> 100</span>  <span class="stringliteral">"movdqu (%1), %%xmm1 \n\t"</span> <span class="comment">// load round key 0</span></div> <div class="line"><a name="l00101"></a><span class="lineno"> 101</span>  <span class="stringliteral">"pxor %%xmm1, %%xmm0 \n\t"</span> <span class="comment">// round 0</span></div> <div class="line"><a name="l00102"></a><span class="lineno"> 102</span>  <span class="stringliteral">"addq $16, %1 \n\t"</span> <span class="comment">// point to next round key</span></div> <div class="line"><a name="l00103"></a><span class="lineno"> 103</span>  <span class="stringliteral">"subl $1, %0 \n\t"</span> <span class="comment">// normal rounds = nr - 1</span></div> <div class="line"><a name="l00104"></a><span class="lineno"> 104</span>  <span class="stringliteral">"test %2, %2 \n\t"</span> <span class="comment">// mode?</span></div> <div class="line"><a name="l00105"></a><span class="lineno"> 105</span>  <span class="stringliteral">"jz 2f \n\t"</span> <span class="comment">// 0 = decrypt</span></div> <div class="line"><a name="l00106"></a><span class="lineno"> 106</span> </div> <div class="line"><a name="l00107"></a><span class="lineno"> 107</span>  <span class="stringliteral">"1: \n\t"</span> <span class="comment">// encryption loop</span></div> <div class="line"><a name="l00108"></a><span class="lineno"> 108</span>  <span class="stringliteral">"movdqu (%1), %%xmm1 \n\t"</span> <span class="comment">// load round key</span></div> <div class="line"><a name="l00109"></a><span class="lineno"> 109</span>  AESENC xmm1_xmm0 <span class="stringliteral">"\n\t"</span> <span class="comment">// do round</span></div> <div class="line"><a name="l00110"></a><span class="lineno"> 110</span>  <span class="stringliteral">"addq $16, %1 \n\t"</span> <span class="comment">// point to next round key</span></div> <div class="line"><a name="l00111"></a><span class="lineno"> 111</span>  <span class="stringliteral">"subl $1, %0 \n\t"</span> <span class="comment">// loop</span></div> <div class="line"><a name="l00112"></a><span class="lineno"> 112</span>  <span class="stringliteral">"jnz 1b \n\t"</span></div> <div class="line"><a name="l00113"></a><span class="lineno"> 113</span>  <span class="stringliteral">"movdqu (%1), %%xmm1 \n\t"</span> <span class="comment">// load round key</span></div> <div class="line"><a name="l00114"></a><span class="lineno"> 114</span>  AESENCLAST xmm1_xmm0 <span class="stringliteral">"\n\t"</span> <span class="comment">// last round</span></div> <div class="line"><a name="l00115"></a><span class="lineno"> 115</span>  <span class="stringliteral">"jmp 3f \n\t"</span></div> <div class="line"><a name="l00116"></a><span class="lineno"> 116</span> </div> <div class="line"><a name="l00117"></a><span class="lineno"> 117</span>  <span class="stringliteral">"2: \n\t"</span> <span class="comment">// decryption loop</span></div> <div class="line"><a name="l00118"></a><span class="lineno"> 118</span>  <span class="stringliteral">"movdqu (%1), %%xmm1 \n\t"</span></div> <div class="line"><a name="l00119"></a><span class="lineno"> 119</span>  AESDEC xmm1_xmm0 <span class="stringliteral">"\n\t"</span> <span class="comment">// do round</span></div> <div class="line"><a name="l00120"></a><span class="lineno"> 120</span>  <span class="stringliteral">"addq $16, %1 \n\t"</span></div> <div class="line"><a name="l00121"></a><span class="lineno"> 121</span>  <span class="stringliteral">"subl $1, %0 \n\t"</span></div> <div class="line"><a name="l00122"></a><span class="lineno"> 122</span>  <span class="stringliteral">"jnz 2b \n\t"</span></div> <div class="line"><a name="l00123"></a><span class="lineno"> 123</span>  <span class="stringliteral">"movdqu (%1), %%xmm1 \n\t"</span> <span class="comment">// load round key</span></div> <div class="line"><a name="l00124"></a><span class="lineno"> 124</span>  AESDECLAST xmm1_xmm0 <span class="stringliteral">"\n\t"</span> <span class="comment">// last round</span></div> <div class="line"><a name="l00125"></a><span class="lineno"> 125</span> </div> <div class="line"><a name="l00126"></a><span class="lineno"> 126</span>  <span class="stringliteral">"3: \n\t"</span></div> <div class="line"><a name="l00127"></a><span class="lineno"> 127</span>  <span class="stringliteral">"movdqu %%xmm0, (%4) \n\t"</span> <span class="comment">// export output</span></div> <div class="line"><a name="l00128"></a><span class="lineno"> 128</span>  :</div> <div class="line"><a name="l00129"></a><span class="lineno"> 129</span>  : <span class="stringliteral">"r"</span> (ctx-><a class="code" href="structaes__context.html#af05054b9a37a06446ef0abf43cd97520">nr</a>), <span class="stringliteral">"r"</span> (ctx-><a class="code" href="structaes__context.html#a93db0195022595f748c001221cc31abe">rk</a>), <span class="stringliteral">"r"</span> (mode), <span class="stringliteral">"r"</span> (input), <span class="stringliteral">"r"</span> (output)</div> <div class="line"><a name="l00130"></a><span class="lineno"> 130</span>  : <span class="stringliteral">"memory"</span>, <span class="stringliteral">"cc"</span>, <span class="stringliteral">"xmm0"</span>, <span class="stringliteral">"xmm1"</span> );</div> <div class="line"><a name="l00131"></a><span class="lineno"> 131</span> </div> <div class="line"><a name="l00132"></a><span class="lineno"> 132</span> </div> <div class="line"><a name="l00133"></a><span class="lineno"> 133</span>  <span class="keywordflow">return</span>( 0 );</div> <div class="line"><a name="l00134"></a><span class="lineno"> 134</span> }</div> <div class="line"><a name="l00135"></a><span class="lineno"> 135</span> </div> <div class="line"><a name="l00136"></a><span class="lineno"> 136</span> <span class="comment">/*</span></div> <div class="line"><a name="l00137"></a><span class="lineno"> 137</span> <span class="comment"> * GCM multiplication: c = a times b in GF(2^128)</span></div> <div class="line"><a name="l00138"></a><span class="lineno"> 138</span> <span class="comment"> * Based on [CLMUL-WP] algorithms 1 (with equation 27) and 5.</span></div> <div class="line"><a name="l00139"></a><span class="lineno"> 139</span> <span class="comment"> */</span></div> <div class="line"><a name="l00140"></a><span class="lineno"> 140</span> <span class="keywordtype">void</span> aesni_gcm_mult( <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> c[16],</div> <div class="line"><a name="l00141"></a><span class="lineno"> 141</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> a[16],</div> <div class="line"><a name="l00142"></a><span class="lineno"> 142</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> b[16] )</div> <div class="line"><a name="l00143"></a><span class="lineno"> 143</span> {</div> <div class="line"><a name="l00144"></a><span class="lineno"> 144</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> aa[16], bb[16], cc[16];</div> <div class="line"><a name="l00145"></a><span class="lineno"> 145</span>  <span class="keywordtype">size_t</span> i;</div> <div class="line"><a name="l00146"></a><span class="lineno"> 146</span> </div> <div class="line"><a name="l00147"></a><span class="lineno"> 147</span>  <span class="comment">/* The inputs are in big-endian order, so byte-reverse them */</span></div> <div class="line"><a name="l00148"></a><span class="lineno"> 148</span>  <span class="keywordflow">for</span>( i = 0; i < 16; i++ )</div> <div class="line"><a name="l00149"></a><span class="lineno"> 149</span>  {</div> <div class="line"><a name="l00150"></a><span class="lineno"> 150</span>  aa[i] = a[15 - i];</div> <div class="line"><a name="l00151"></a><span class="lineno"> 151</span>  bb[i] = b[15 - i];</div> <div class="line"><a name="l00152"></a><span class="lineno"> 152</span>  }</div> <div class="line"><a name="l00153"></a><span class="lineno"> 153</span> </div> <div class="line"><a name="l00154"></a><span class="lineno"> 154</span>  <span class="keyword">asm</span>( <span class="stringliteral">"movdqu (%0), %%xmm0 \n\t"</span> <span class="comment">// a1:a0</span></div> <div class="line"><a name="l00155"></a><span class="lineno"> 155</span>  <span class="stringliteral">"movdqu (%1), %%xmm1 \n\t"</span> <span class="comment">// b1:b0</span></div> <div class="line"><a name="l00156"></a><span class="lineno"> 156</span> </div> <div class="line"><a name="l00157"></a><span class="lineno"> 157</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00158"></a><span class="lineno"> 158</span> <span class="comment"> * Caryless multiplication xmm2:xmm1 = xmm0 * xmm1</span></div> <div class="line"><a name="l00159"></a><span class="lineno"> 159</span> <span class="comment"> * using [CLMUL-WP] algorithm 1 (p. 13).</span></div> <div class="line"><a name="l00160"></a><span class="lineno"> 160</span> <span class="comment"> */</span></div> <div class="line"><a name="l00161"></a><span class="lineno"> 161</span>  <span class="stringliteral">"movdqa %%xmm1, %%xmm2 \n\t"</span> <span class="comment">// copy of b1:b0</span></div> <div class="line"><a name="l00162"></a><span class="lineno"> 162</span>  <span class="stringliteral">"movdqa %%xmm1, %%xmm3 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00163"></a><span class="lineno"> 163</span>  <span class="stringliteral">"movdqa %%xmm1, %%xmm4 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00164"></a><span class="lineno"> 164</span>  PCLMULQDQ xmm0_xmm1 <span class="stringliteral">",0x00 \n\t"</span> <span class="comment">// a0*b0 = c1:c0</span></div> <div class="line"><a name="l00165"></a><span class="lineno"> 165</span>  PCLMULQDQ xmm0_xmm2 <span class="stringliteral">",0x11 \n\t"</span> <span class="comment">// a1*b1 = d1:d0</span></div> <div class="line"><a name="l00166"></a><span class="lineno"> 166</span>  PCLMULQDQ xmm0_xmm3 <span class="stringliteral">",0x10 \n\t"</span> <span class="comment">// a0*b1 = e1:e0</span></div> <div class="line"><a name="l00167"></a><span class="lineno"> 167</span>  PCLMULQDQ xmm0_xmm4 <span class="stringliteral">",0x01 \n\t"</span> <span class="comment">// a1*b0 = f1:f0</span></div> <div class="line"><a name="l00168"></a><span class="lineno"> 168</span>  <span class="stringliteral">"pxor %%xmm3, %%xmm4 \n\t"</span> <span class="comment">// e1+f1:e0+f0</span></div> <div class="line"><a name="l00169"></a><span class="lineno"> 169</span>  <span class="stringliteral">"movdqa %%xmm4, %%xmm3 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00170"></a><span class="lineno"> 170</span>  <span class="stringliteral">"psrldq $8, %%xmm4 \n\t"</span> <span class="comment">// 0:e1+f1</span></div> <div class="line"><a name="l00171"></a><span class="lineno"> 171</span>  <span class="stringliteral">"pslldq $8, %%xmm3 \n\t"</span> <span class="comment">// e0+f0:0</span></div> <div class="line"><a name="l00172"></a><span class="lineno"> 172</span>  <span class="stringliteral">"pxor %%xmm4, %%xmm2 \n\t"</span> <span class="comment">// d1:d0+e1+f1</span></div> <div class="line"><a name="l00173"></a><span class="lineno"> 173</span>  <span class="stringliteral">"pxor %%xmm3, %%xmm1 \n\t"</span> <span class="comment">// c1+e0+f1:c0</span></div> <div class="line"><a name="l00174"></a><span class="lineno"> 174</span> </div> <div class="line"><a name="l00175"></a><span class="lineno"> 175</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00176"></a><span class="lineno"> 176</span> <span class="comment"> * Now shift the result one bit to the left,</span></div> <div class="line"><a name="l00177"></a><span class="lineno"> 177</span> <span class="comment"> * taking advantage of [CLMUL-WP] eq 27 (p. 20)</span></div> <div class="line"><a name="l00178"></a><span class="lineno"> 178</span> <span class="comment"> */</span></div> <div class="line"><a name="l00179"></a><span class="lineno"> 179</span>  <span class="stringliteral">"movdqa %%xmm1, %%xmm3 \n\t"</span> <span class="comment">// r1:r0</span></div> <div class="line"><a name="l00180"></a><span class="lineno"> 180</span>  <span class="stringliteral">"movdqa %%xmm2, %%xmm4 \n\t"</span> <span class="comment">// r3:r2</span></div> <div class="line"><a name="l00181"></a><span class="lineno"> 181</span>  <span class="stringliteral">"psllq $1, %%xmm1 \n\t"</span> <span class="comment">// r1<<1:r0<<1</span></div> <div class="line"><a name="l00182"></a><span class="lineno"> 182</span>  <span class="stringliteral">"psllq $1, %%xmm2 \n\t"</span> <span class="comment">// r3<<1:r2<<1</span></div> <div class="line"><a name="l00183"></a><span class="lineno"> 183</span>  <span class="stringliteral">"psrlq $63, %%xmm3 \n\t"</span> <span class="comment">// r1>>63:r0>>63</span></div> <div class="line"><a name="l00184"></a><span class="lineno"> 184</span>  <span class="stringliteral">"psrlq $63, %%xmm4 \n\t"</span> <span class="comment">// r3>>63:r2>>63</span></div> <div class="line"><a name="l00185"></a><span class="lineno"> 185</span>  <span class="stringliteral">"movdqa %%xmm3, %%xmm5 \n\t"</span> <span class="comment">// r1>>63:r0>>63</span></div> <div class="line"><a name="l00186"></a><span class="lineno"> 186</span>  <span class="stringliteral">"pslldq $8, %%xmm3 \n\t"</span> <span class="comment">// r0>>63:0</span></div> <div class="line"><a name="l00187"></a><span class="lineno"> 187</span>  <span class="stringliteral">"pslldq $8, %%xmm4 \n\t"</span> <span class="comment">// r2>>63:0</span></div> <div class="line"><a name="l00188"></a><span class="lineno"> 188</span>  <span class="stringliteral">"psrldq $8, %%xmm5 \n\t"</span> <span class="comment">// 0:r1>>63</span></div> <div class="line"><a name="l00189"></a><span class="lineno"> 189</span>  <span class="stringliteral">"por %%xmm3, %%xmm1 \n\t"</span> <span class="comment">// r1<<1|r0>>63:r0<<1</span></div> <div class="line"><a name="l00190"></a><span class="lineno"> 190</span>  <span class="stringliteral">"por %%xmm4, %%xmm2 \n\t"</span> <span class="comment">// r3<<1|r2>>62:r2<<1</span></div> <div class="line"><a name="l00191"></a><span class="lineno"> 191</span>  <span class="stringliteral">"por %%xmm5, %%xmm2 \n\t"</span> <span class="comment">// r3<<1|r2>>62:r2<<1|r1>>63</span></div> <div class="line"><a name="l00192"></a><span class="lineno"> 192</span> </div> <div class="line"><a name="l00193"></a><span class="lineno"> 193</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00194"></a><span class="lineno"> 194</span> <span class="comment"> * Now reduce modulo the GCM polynomial x^128 + x^7 + x^2 + x + 1</span></div> <div class="line"><a name="l00195"></a><span class="lineno"> 195</span> <span class="comment"> * using [CLMUL-WP] algorithm 5 (p. 20).</span></div> <div class="line"><a name="l00196"></a><span class="lineno"> 196</span> <span class="comment"> * Currently xmm2:xmm1 holds x3:x2:x1:x0 (already shifted).</span></div> <div class="line"><a name="l00197"></a><span class="lineno"> 197</span> <span class="comment"> */</span></div> <div class="line"><a name="l00198"></a><span class="lineno"> 198</span>  <span class="comment">/* Step 2 (1) */</span></div> <div class="line"><a name="l00199"></a><span class="lineno"> 199</span>  <span class="stringliteral">"movdqa %%xmm1, %%xmm3 \n\t"</span> <span class="comment">// x1:x0</span></div> <div class="line"><a name="l00200"></a><span class="lineno"> 200</span>  <span class="stringliteral">"movdqa %%xmm1, %%xmm4 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00201"></a><span class="lineno"> 201</span>  <span class="stringliteral">"movdqa %%xmm1, %%xmm5 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00202"></a><span class="lineno"> 202</span>  <span class="stringliteral">"psllq $63, %%xmm3 \n\t"</span> <span class="comment">// x1<<63:x0<<63 = stuff:a</span></div> <div class="line"><a name="l00203"></a><span class="lineno"> 203</span>  <span class="stringliteral">"psllq $62, %%xmm4 \n\t"</span> <span class="comment">// x1<<62:x0<<62 = stuff:b</span></div> <div class="line"><a name="l00204"></a><span class="lineno"> 204</span>  <span class="stringliteral">"psllq $57, %%xmm5 \n\t"</span> <span class="comment">// x1<<57:x0<<57 = stuff:c</span></div> <div class="line"><a name="l00205"></a><span class="lineno"> 205</span> </div> <div class="line"><a name="l00206"></a><span class="lineno"> 206</span>  <span class="comment">/* Step 2 (2) */</span></div> <div class="line"><a name="l00207"></a><span class="lineno"> 207</span>  <span class="stringliteral">"pxor %%xmm4, %%xmm3 \n\t"</span> <span class="comment">// stuff:a+b</span></div> <div class="line"><a name="l00208"></a><span class="lineno"> 208</span>  <span class="stringliteral">"pxor %%xmm5, %%xmm3 \n\t"</span> <span class="comment">// stuff:a+b+c</span></div> <div class="line"><a name="l00209"></a><span class="lineno"> 209</span>  <span class="stringliteral">"pslldq $8, %%xmm3 \n\t"</span> <span class="comment">// a+b+c:0</span></div> <div class="line"><a name="l00210"></a><span class="lineno"> 210</span>  <span class="stringliteral">"pxor %%xmm3, %%xmm1 \n\t"</span> <span class="comment">// x1+a+b+c:x0 = d:x0</span></div> <div class="line"><a name="l00211"></a><span class="lineno"> 211</span> </div> <div class="line"><a name="l00212"></a><span class="lineno"> 212</span>  <span class="comment">/* Steps 3 and 4 */</span></div> <div class="line"><a name="l00213"></a><span class="lineno"> 213</span>  <span class="stringliteral">"movdqa %%xmm1,%%xmm0 \n\t"</span> <span class="comment">// d:x0</span></div> <div class="line"><a name="l00214"></a><span class="lineno"> 214</span>  <span class="stringliteral">"movdqa %%xmm1,%%xmm4 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00215"></a><span class="lineno"> 215</span>  <span class="stringliteral">"movdqa %%xmm1,%%xmm5 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00216"></a><span class="lineno"> 216</span>  <span class="stringliteral">"psrlq $1, %%xmm0 \n\t"</span> <span class="comment">// e1:x0>>1 = e1:e0'</span></div> <div class="line"><a name="l00217"></a><span class="lineno"> 217</span>  <span class="stringliteral">"psrlq $2, %%xmm4 \n\t"</span> <span class="comment">// f1:x0>>2 = f1:f0'</span></div> <div class="line"><a name="l00218"></a><span class="lineno"> 218</span>  <span class="stringliteral">"psrlq $7, %%xmm5 \n\t"</span> <span class="comment">// g1:x0>>7 = g1:g0'</span></div> <div class="line"><a name="l00219"></a><span class="lineno"> 219</span>  <span class="stringliteral">"pxor %%xmm4, %%xmm0 \n\t"</span> <span class="comment">// e1+f1:e0'+f0'</span></div> <div class="line"><a name="l00220"></a><span class="lineno"> 220</span>  <span class="stringliteral">"pxor %%xmm5, %%xmm0 \n\t"</span> <span class="comment">// e1+f1+g1:e0'+f0'+g0'</span></div> <div class="line"><a name="l00221"></a><span class="lineno"> 221</span>  <span class="comment">// e0'+f0'+g0' is almost e0+f0+g0, ex\tcept for some missing</span></div> <div class="line"><a name="l00222"></a><span class="lineno"> 222</span>  <span class="comment">// bits carried from d. Now get those\t bits back in.</span></div> <div class="line"><a name="l00223"></a><span class="lineno"> 223</span>  <span class="stringliteral">"movdqa %%xmm1,%%xmm3 \n\t"</span> <span class="comment">// d:x0</span></div> <div class="line"><a name="l00224"></a><span class="lineno"> 224</span>  <span class="stringliteral">"movdqa %%xmm1,%%xmm4 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00225"></a><span class="lineno"> 225</span>  <span class="stringliteral">"movdqa %%xmm1,%%xmm5 \n\t"</span> <span class="comment">// same</span></div> <div class="line"><a name="l00226"></a><span class="lineno"> 226</span>  <span class="stringliteral">"psllq $63, %%xmm3 \n\t"</span> <span class="comment">// d<<63:stuff</span></div> <div class="line"><a name="l00227"></a><span class="lineno"> 227</span>  <span class="stringliteral">"psllq $62, %%xmm4 \n\t"</span> <span class="comment">// d<<62:stuff</span></div> <div class="line"><a name="l00228"></a><span class="lineno"> 228</span>  <span class="stringliteral">"psllq $57, %%xmm5 \n\t"</span> <span class="comment">// d<<57:stuff</span></div> <div class="line"><a name="l00229"></a><span class="lineno"> 229</span>  <span class="stringliteral">"pxor %%xmm4, %%xmm3 \n\t"</span> <span class="comment">// d<<63+d<<62:stuff</span></div> <div class="line"><a name="l00230"></a><span class="lineno"> 230</span>  <span class="stringliteral">"pxor %%xmm5, %%xmm3 \n\t"</span> <span class="comment">// missing bits of d:stuff</span></div> <div class="line"><a name="l00231"></a><span class="lineno"> 231</span>  <span class="stringliteral">"psrldq $8, %%xmm3 \n\t"</span> <span class="comment">// 0:missing bits of d</span></div> <div class="line"><a name="l00232"></a><span class="lineno"> 232</span>  <span class="stringliteral">"pxor %%xmm3, %%xmm0 \n\t"</span> <span class="comment">// e1+f1+g1:e0+f0+g0</span></div> <div class="line"><a name="l00233"></a><span class="lineno"> 233</span>  <span class="stringliteral">"pxor %%xmm1, %%xmm0 \n\t"</span> <span class="comment">// h1:h0</span></div> <div class="line"><a name="l00234"></a><span class="lineno"> 234</span>  <span class="stringliteral">"pxor %%xmm2, %%xmm0 \n\t"</span> <span class="comment">// x3+h1:x2+h0</span></div> <div class="line"><a name="l00235"></a><span class="lineno"> 235</span> </div> <div class="line"><a name="l00236"></a><span class="lineno"> 236</span>  <span class="stringliteral">"movdqu %%xmm0, (%2) \n\t"</span> <span class="comment">// done</span></div> <div class="line"><a name="l00237"></a><span class="lineno"> 237</span>  :</div> <div class="line"><a name="l00238"></a><span class="lineno"> 238</span>  : <span class="stringliteral">"r"</span> (aa), <span class="stringliteral">"r"</span> (bb), <span class="stringliteral">"r"</span> (cc)</div> <div class="line"><a name="l00239"></a><span class="lineno"> 239</span>  : <span class="stringliteral">"memory"</span>, <span class="stringliteral">"cc"</span>, <span class="stringliteral">"xmm0"</span>, <span class="stringliteral">"xmm1"</span>, <span class="stringliteral">"xmm2"</span>, <span class="stringliteral">"xmm3"</span>, <span class="stringliteral">"xmm4"</span>, <span class="stringliteral">"xmm5"</span> );</div> <div class="line"><a name="l00240"></a><span class="lineno"> 240</span> </div> <div class="line"><a name="l00241"></a><span class="lineno"> 241</span>  <span class="comment">/* Now byte-reverse the outputs */</span></div> <div class="line"><a name="l00242"></a><span class="lineno"> 242</span>  <span class="keywordflow">for</span>( i = 0; i < 16; i++ )</div> <div class="line"><a name="l00243"></a><span class="lineno"> 243</span>  c[i] = cc[15 - i];</div> <div class="line"><a name="l00244"></a><span class="lineno"> 244</span> </div> <div class="line"><a name="l00245"></a><span class="lineno"> 245</span>  <span class="keywordflow">return</span>;</div> <div class="line"><a name="l00246"></a><span class="lineno"> 246</span> }</div> <div class="line"><a name="l00247"></a><span class="lineno"> 247</span> </div> <div class="line"><a name="l00248"></a><span class="lineno"> 248</span> <span class="comment">/*</span></div> <div class="line"><a name="l00249"></a><span class="lineno"> 249</span> <span class="comment"> * Compute decryption round keys from encryption round keys</span></div> <div class="line"><a name="l00250"></a><span class="lineno"> 250</span> <span class="comment"> */</span></div> <div class="line"><a name="l00251"></a><span class="lineno"> 251</span> <span class="keywordtype">void</span> aesni_inverse_key( <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *invkey,</div> <div class="line"><a name="l00252"></a><span class="lineno"> 252</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *fwdkey, <span class="keywordtype">int</span> nr )</div> <div class="line"><a name="l00253"></a><span class="lineno"> 253</span> {</div> <div class="line"><a name="l00254"></a><span class="lineno"> 254</span>  <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *ik = invkey;</div> <div class="line"><a name="l00255"></a><span class="lineno"> 255</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *fk = fwdkey + 16 * nr;</div> <div class="line"><a name="l00256"></a><span class="lineno"> 256</span> </div> <div class="line"><a name="l00257"></a><span class="lineno"> 257</span>  memcpy( ik, fk, 16 );</div> <div class="line"><a name="l00258"></a><span class="lineno"> 258</span> </div> <div class="line"><a name="l00259"></a><span class="lineno"> 259</span>  <span class="keywordflow">for</span>( fk -= 16, ik += 16; fk > fwdkey; fk -= 16, ik += 16 )</div> <div class="line"><a name="l00260"></a><span class="lineno"> 260</span>  <span class="keyword">asm</span>( <span class="stringliteral">"movdqu (%0), %%xmm0 \n\t"</span></div> <div class="line"><a name="l00261"></a><span class="lineno"> 261</span>  AESIMC xmm0_xmm0 <span class="stringliteral">"\n\t"</span></div> <div class="line"><a name="l00262"></a><span class="lineno"> 262</span>  <span class="stringliteral">"movdqu %%xmm0, (%1) \n\t"</span></div> <div class="line"><a name="l00263"></a><span class="lineno"> 263</span>  :</div> <div class="line"><a name="l00264"></a><span class="lineno"> 264</span>  : <span class="stringliteral">"r"</span> (fk), <span class="stringliteral">"r"</span> (ik)</div> <div class="line"><a name="l00265"></a><span class="lineno"> 265</span>  : <span class="stringliteral">"memory"</span>, <span class="stringliteral">"xmm0"</span> );</div> <div class="line"><a name="l00266"></a><span class="lineno"> 266</span> </div> <div class="line"><a name="l00267"></a><span class="lineno"> 267</span>  memcpy( ik, fk, 16 );</div> <div class="line"><a name="l00268"></a><span class="lineno"> 268</span> }</div> <div class="line"><a name="l00269"></a><span class="lineno"> 269</span> </div> <div class="line"><a name="l00270"></a><span class="lineno"> 270</span> <span class="comment">/*</span></div> <div class="line"><a name="l00271"></a><span class="lineno"> 271</span> <span class="comment"> * Key expansion, 128-bit case</span></div> <div class="line"><a name="l00272"></a><span class="lineno"> 272</span> <span class="comment"> */</span></div> <div class="line"><a name="l00273"></a><span class="lineno"> 273</span> <span class="keyword">static</span> <span class="keywordtype">void</span> aesni_setkey_enc_128( <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *rk,</div> <div class="line"><a name="l00274"></a><span class="lineno"> 274</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *key )</div> <div class="line"><a name="l00275"></a><span class="lineno"> 275</span> {</div> <div class="line"><a name="l00276"></a><span class="lineno"> 276</span>  <span class="keyword">asm</span>( <span class="stringliteral">"movdqu (%1), %%xmm0 \n\t"</span> <span class="comment">// copy the original key</span></div> <div class="line"><a name="l00277"></a><span class="lineno"> 277</span>  <span class="stringliteral">"movdqu %%xmm0, (%0) \n\t"</span> <span class="comment">// as round key 0</span></div> <div class="line"><a name="l00278"></a><span class="lineno"> 278</span>  <span class="stringliteral">"jmp 2f \n\t"</span> <span class="comment">// skip auxiliary routine</span></div> <div class="line"><a name="l00279"></a><span class="lineno"> 279</span> </div> <div class="line"><a name="l00280"></a><span class="lineno"> 280</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00281"></a><span class="lineno"> 281</span> <span class="comment"> * Finish generating the next round key.</span></div> <div class="line"><a name="l00282"></a><span class="lineno"> 282</span> <span class="comment"> *</span></div> <div class="line"><a name="l00283"></a><span class="lineno"> 283</span> <span class="comment"> * On entry xmm0 is r3:r2:r1:r0 and xmm1 is X:stuff:stuff:stuff</span></div> <div class="line"><a name="l00284"></a><span class="lineno"> 284</span> <span class="comment"> * with X = rot( sub( r3 ) ) ^ RCON.</span></div> <div class="line"><a name="l00285"></a><span class="lineno"> 285</span> <span class="comment"> *</span></div> <div class="line"><a name="l00286"></a><span class="lineno"> 286</span> <span class="comment"> * On exit, xmm0 is r7:r6:r5:r4</span></div> <div class="line"><a name="l00287"></a><span class="lineno"> 287</span> <span class="comment"> * with r4 = X + r0, r5 = r4 + r1, r6 = r5 + r2, r7 = r6 + r3</span></div> <div class="line"><a name="l00288"></a><span class="lineno"> 288</span> <span class="comment"> * and those are written to the round key buffer.</span></div> <div class="line"><a name="l00289"></a><span class="lineno"> 289</span> <span class="comment"> */</span></div> <div class="line"><a name="l00290"></a><span class="lineno"> 290</span>  <span class="stringliteral">"1: \n\t"</span></div> <div class="line"><a name="l00291"></a><span class="lineno"> 291</span>  <span class="stringliteral">"pshufd $0xff, %%xmm1, %%xmm1 \n\t"</span> <span class="comment">// X:X:X:X</span></div> <div class="line"><a name="l00292"></a><span class="lineno"> 292</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm1 \n\t"</span> <span class="comment">// X+r3:X+r2:X+r1:r4</span></div> <div class="line"><a name="l00293"></a><span class="lineno"> 293</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span> <span class="comment">// r2:r1:r0:0</span></div> <div class="line"><a name="l00294"></a><span class="lineno"> 294</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm1 \n\t"</span> <span class="comment">// X+r3+r2:X+r2+r1:r5:r4</span></div> <div class="line"><a name="l00295"></a><span class="lineno"> 295</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span> <span class="comment">// etc</span></div> <div class="line"><a name="l00296"></a><span class="lineno"> 296</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm1 \n\t"</span></div> <div class="line"><a name="l00297"></a><span class="lineno"> 297</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span></div> <div class="line"><a name="l00298"></a><span class="lineno"> 298</span>  <span class="stringliteral">"pxor %%xmm1, %%xmm0 \n\t"</span> <span class="comment">// update xmm0 for next time!</span></div> <div class="line"><a name="l00299"></a><span class="lineno"> 299</span>  <span class="stringliteral">"add $16, %0 \n\t"</span> <span class="comment">// point to next round key</span></div> <div class="line"><a name="l00300"></a><span class="lineno"> 300</span>  <span class="stringliteral">"movdqu %%xmm0, (%0) \n\t"</span> <span class="comment">// write it</span></div> <div class="line"><a name="l00301"></a><span class="lineno"> 301</span>  <span class="stringliteral">"ret \n\t"</span></div> <div class="line"><a name="l00302"></a><span class="lineno"> 302</span> </div> <div class="line"><a name="l00303"></a><span class="lineno"> 303</span>  <span class="comment">/* Main "loop" */</span></div> <div class="line"><a name="l00304"></a><span class="lineno"> 304</span>  <span class="stringliteral">"2: \n\t"</span></div> <div class="line"><a name="l00305"></a><span class="lineno"> 305</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x01 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00306"></a><span class="lineno"> 306</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x02 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00307"></a><span class="lineno"> 307</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x04 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00308"></a><span class="lineno"> 308</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x08 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00309"></a><span class="lineno"> 309</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x10 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00310"></a><span class="lineno"> 310</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x20 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00311"></a><span class="lineno"> 311</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x40 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00312"></a><span class="lineno"> 312</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x80 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00313"></a><span class="lineno"> 313</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x1B \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00314"></a><span class="lineno"> 314</span>  AESKEYGENA xmm0_xmm1 <span class="stringliteral">",0x36 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00315"></a><span class="lineno"> 315</span>  :</div> <div class="line"><a name="l00316"></a><span class="lineno"> 316</span>  : <span class="stringliteral">"r"</span> (rk), <span class="stringliteral">"r"</span> (key)</div> <div class="line"><a name="l00317"></a><span class="lineno"> 317</span>  : <span class="stringliteral">"memory"</span>, <span class="stringliteral">"cc"</span>, <span class="stringliteral">"0"</span> );</div> <div class="line"><a name="l00318"></a><span class="lineno"> 318</span> }</div> <div class="line"><a name="l00319"></a><span class="lineno"> 319</span> </div> <div class="line"><a name="l00320"></a><span class="lineno"> 320</span> <span class="comment">/*</span></div> <div class="line"><a name="l00321"></a><span class="lineno"> 321</span> <span class="comment"> * Key expansion, 192-bit case</span></div> <div class="line"><a name="l00322"></a><span class="lineno"> 322</span> <span class="comment"> */</span></div> <div class="line"><a name="l00323"></a><span class="lineno"> 323</span> <span class="keyword">static</span> <span class="keywordtype">void</span> aesni_setkey_enc_192( <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *rk,</div> <div class="line"><a name="l00324"></a><span class="lineno"> 324</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *key )</div> <div class="line"><a name="l00325"></a><span class="lineno"> 325</span> {</div> <div class="line"><a name="l00326"></a><span class="lineno"> 326</span>  <span class="keyword">asm</span>( <span class="stringliteral">"movdqu (%1), %%xmm0 \n\t"</span> <span class="comment">// copy original round key</span></div> <div class="line"><a name="l00327"></a><span class="lineno"> 327</span>  <span class="stringliteral">"movdqu %%xmm0, (%0) \n\t"</span></div> <div class="line"><a name="l00328"></a><span class="lineno"> 328</span>  <span class="stringliteral">"add $16, %0 \n\t"</span></div> <div class="line"><a name="l00329"></a><span class="lineno"> 329</span>  <span class="stringliteral">"movq 16(%1), %%xmm1 \n\t"</span></div> <div class="line"><a name="l00330"></a><span class="lineno"> 330</span>  <span class="stringliteral">"movq %%xmm1, (%0) \n\t"</span></div> <div class="line"><a name="l00331"></a><span class="lineno"> 331</span>  <span class="stringliteral">"add $8, %0 \n\t"</span></div> <div class="line"><a name="l00332"></a><span class="lineno"> 332</span>  <span class="stringliteral">"jmp 2f \n\t"</span> <span class="comment">// skip auxiliary routine</span></div> <div class="line"><a name="l00333"></a><span class="lineno"> 333</span> </div> <div class="line"><a name="l00334"></a><span class="lineno"> 334</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00335"></a><span class="lineno"> 335</span> <span class="comment"> * Finish generating the next 6 quarter-keys.</span></div> <div class="line"><a name="l00336"></a><span class="lineno"> 336</span> <span class="comment"> *</span></div> <div class="line"><a name="l00337"></a><span class="lineno"> 337</span> <span class="comment"> * On entry xmm0 is r3:r2:r1:r0, xmm1 is stuff:stuff:r5:r4</span></div> <div class="line"><a name="l00338"></a><span class="lineno"> 338</span> <span class="comment"> * and xmm2 is stuff:stuff:X:stuff with X = rot( sub( r3 ) ) ^ RCON.</span></div> <div class="line"><a name="l00339"></a><span class="lineno"> 339</span> <span class="comment"> *</span></div> <div class="line"><a name="l00340"></a><span class="lineno"> 340</span> <span class="comment"> * On exit, xmm0 is r9:r8:r7:r6 and xmm1 is stuff:stuff:r11:r10</span></div> <div class="line"><a name="l00341"></a><span class="lineno"> 341</span> <span class="comment"> * and those are written to the round key buffer.</span></div> <div class="line"><a name="l00342"></a><span class="lineno"> 342</span> <span class="comment"> */</span></div> <div class="line"><a name="l00343"></a><span class="lineno"> 343</span>  <span class="stringliteral">"1: \n\t"</span></div> <div class="line"><a name="l00344"></a><span class="lineno"> 344</span>  <span class="stringliteral">"pshufd $0x55, %%xmm2, %%xmm2 \n\t"</span> <span class="comment">// X:X:X:X</span></div> <div class="line"><a name="l00345"></a><span class="lineno"> 345</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm2 \n\t"</span> <span class="comment">// X+r3:X+r2:X+r1:r4</span></div> <div class="line"><a name="l00346"></a><span class="lineno"> 346</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span> <span class="comment">// etc</span></div> <div class="line"><a name="l00347"></a><span class="lineno"> 347</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00348"></a><span class="lineno"> 348</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span></div> <div class="line"><a name="l00349"></a><span class="lineno"> 349</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00350"></a><span class="lineno"> 350</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span></div> <div class="line"><a name="l00351"></a><span class="lineno"> 351</span>  <span class="stringliteral">"pxor %%xmm2, %%xmm0 \n\t"</span> <span class="comment">// update xmm0 = r9:r8:r7:r6</span></div> <div class="line"><a name="l00352"></a><span class="lineno"> 352</span>  <span class="stringliteral">"movdqu %%xmm0, (%0) \n\t"</span></div> <div class="line"><a name="l00353"></a><span class="lineno"> 353</span>  <span class="stringliteral">"add $16, %0 \n\t"</span></div> <div class="line"><a name="l00354"></a><span class="lineno"> 354</span>  <span class="stringliteral">"pshufd $0xff, %%xmm0, %%xmm2 \n\t"</span> <span class="comment">// r9:r9:r9:r9</span></div> <div class="line"><a name="l00355"></a><span class="lineno"> 355</span>  <span class="stringliteral">"pxor %%xmm1, %%xmm2 \n\t"</span> <span class="comment">// stuff:stuff:r9+r5:r10</span></div> <div class="line"><a name="l00356"></a><span class="lineno"> 356</span>  <span class="stringliteral">"pslldq $4, %%xmm1 \n\t"</span> <span class="comment">// r2:r1:r0:0</span></div> <div class="line"><a name="l00357"></a><span class="lineno"> 357</span>  <span class="stringliteral">"pxor %%xmm2, %%xmm1 \n\t"</span> <span class="comment">// xmm1 = stuff:stuff:r11:r10</span></div> <div class="line"><a name="l00358"></a><span class="lineno"> 358</span>  <span class="stringliteral">"movq %%xmm1, (%0) \n\t"</span></div> <div class="line"><a name="l00359"></a><span class="lineno"> 359</span>  <span class="stringliteral">"add $8, %0 \n\t"</span></div> <div class="line"><a name="l00360"></a><span class="lineno"> 360</span>  <span class="stringliteral">"ret \n\t"</span></div> <div class="line"><a name="l00361"></a><span class="lineno"> 361</span> </div> <div class="line"><a name="l00362"></a><span class="lineno"> 362</span>  <span class="stringliteral">"2: \n\t"</span></div> <div class="line"><a name="l00363"></a><span class="lineno"> 363</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x01 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00364"></a><span class="lineno"> 364</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x02 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00365"></a><span class="lineno"> 365</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x04 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00366"></a><span class="lineno"> 366</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x08 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00367"></a><span class="lineno"> 367</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x10 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00368"></a><span class="lineno"> 368</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x20 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00369"></a><span class="lineno"> 369</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x40 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00370"></a><span class="lineno"> 370</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x80 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00371"></a><span class="lineno"> 371</span> </div> <div class="line"><a name="l00372"></a><span class="lineno"> 372</span>  :</div> <div class="line"><a name="l00373"></a><span class="lineno"> 373</span>  : <span class="stringliteral">"r"</span> (rk), <span class="stringliteral">"r"</span> (key)</div> <div class="line"><a name="l00374"></a><span class="lineno"> 374</span>  : <span class="stringliteral">"memory"</span>, <span class="stringliteral">"cc"</span>, <span class="stringliteral">"0"</span> );</div> <div class="line"><a name="l00375"></a><span class="lineno"> 375</span> }</div> <div class="line"><a name="l00376"></a><span class="lineno"> 376</span> </div> <div class="line"><a name="l00377"></a><span class="lineno"> 377</span> <span class="comment">/*</span></div> <div class="line"><a name="l00378"></a><span class="lineno"> 378</span> <span class="comment"> * Key expansion, 256-bit case</span></div> <div class="line"><a name="l00379"></a><span class="lineno"> 379</span> <span class="comment"> */</span></div> <div class="line"><a name="l00380"></a><span class="lineno"> 380</span> <span class="keyword">static</span> <span class="keywordtype">void</span> aesni_setkey_enc_256( <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *rk,</div> <div class="line"><a name="l00381"></a><span class="lineno"> 381</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *key )</div> <div class="line"><a name="l00382"></a><span class="lineno"> 382</span> {</div> <div class="line"><a name="l00383"></a><span class="lineno"> 383</span>  <span class="keyword">asm</span>( <span class="stringliteral">"movdqu (%1), %%xmm0 \n\t"</span></div> <div class="line"><a name="l00384"></a><span class="lineno"> 384</span>  <span class="stringliteral">"movdqu %%xmm0, (%0) \n\t"</span></div> <div class="line"><a name="l00385"></a><span class="lineno"> 385</span>  <span class="stringliteral">"add $16, %0 \n\t"</span></div> <div class="line"><a name="l00386"></a><span class="lineno"> 386</span>  <span class="stringliteral">"movdqu 16(%1), %%xmm1 \n\t"</span></div> <div class="line"><a name="l00387"></a><span class="lineno"> 387</span>  <span class="stringliteral">"movdqu %%xmm1, (%0) \n\t"</span></div> <div class="line"><a name="l00388"></a><span class="lineno"> 388</span>  <span class="stringliteral">"jmp 2f \n\t"</span> <span class="comment">// skip auxiliary routine</span></div> <div class="line"><a name="l00389"></a><span class="lineno"> 389</span> </div> <div class="line"><a name="l00390"></a><span class="lineno"> 390</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00391"></a><span class="lineno"> 391</span> <span class="comment"> * Finish generating the next two round keys.</span></div> <div class="line"><a name="l00392"></a><span class="lineno"> 392</span> <span class="comment"> *</span></div> <div class="line"><a name="l00393"></a><span class="lineno"> 393</span> <span class="comment"> * On entry xmm0 is r3:r2:r1:r0, xmm1 is r7:r6:r5:r4 and</span></div> <div class="line"><a name="l00394"></a><span class="lineno"> 394</span> <span class="comment"> * xmm2 is X:stuff:stuff:stuff with X = rot( sub( r7 )) ^ RCON</span></div> <div class="line"><a name="l00395"></a><span class="lineno"> 395</span> <span class="comment"> *</span></div> <div class="line"><a name="l00396"></a><span class="lineno"> 396</span> <span class="comment"> * On exit, xmm0 is r11:r10:r9:r8 and xmm1 is r15:r14:r13:r12</span></div> <div class="line"><a name="l00397"></a><span class="lineno"> 397</span> <span class="comment"> * and those have been written to the output buffer.</span></div> <div class="line"><a name="l00398"></a><span class="lineno"> 398</span> <span class="comment"> */</span></div> <div class="line"><a name="l00399"></a><span class="lineno"> 399</span>  <span class="stringliteral">"1: \n\t"</span></div> <div class="line"><a name="l00400"></a><span class="lineno"> 400</span>  <span class="stringliteral">"pshufd $0xff, %%xmm2, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00401"></a><span class="lineno"> 401</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00402"></a><span class="lineno"> 402</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span></div> <div class="line"><a name="l00403"></a><span class="lineno"> 403</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00404"></a><span class="lineno"> 404</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span></div> <div class="line"><a name="l00405"></a><span class="lineno"> 405</span>  <span class="stringliteral">"pxor %%xmm0, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00406"></a><span class="lineno"> 406</span>  <span class="stringliteral">"pslldq $4, %%xmm0 \n\t"</span></div> <div class="line"><a name="l00407"></a><span class="lineno"> 407</span>  <span class="stringliteral">"pxor %%xmm2, %%xmm0 \n\t"</span></div> <div class="line"><a name="l00408"></a><span class="lineno"> 408</span>  <span class="stringliteral">"add $16, %0 \n\t"</span></div> <div class="line"><a name="l00409"></a><span class="lineno"> 409</span>  <span class="stringliteral">"movdqu %%xmm0, (%0) \n\t"</span></div> <div class="line"><a name="l00410"></a><span class="lineno"> 410</span> </div> <div class="line"><a name="l00411"></a><span class="lineno"> 411</span>  <span class="comment">/* Set xmm2 to stuff:Y:stuff:stuff with Y = subword( r11 )</span></div> <div class="line"><a name="l00412"></a><span class="lineno"> 412</span> <span class="comment"> * and proceed to generate next round key from there */</span></div> <div class="line"><a name="l00413"></a><span class="lineno"> 413</span>  AESKEYGENA xmm0_xmm2 <span class="stringliteral">",0x00 \n\t"</span></div> <div class="line"><a name="l00414"></a><span class="lineno"> 414</span>  <span class="stringliteral">"pshufd $0xaa, %%xmm2, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00415"></a><span class="lineno"> 415</span>  <span class="stringliteral">"pxor %%xmm1, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00416"></a><span class="lineno"> 416</span>  <span class="stringliteral">"pslldq $4, %%xmm1 \n\t"</span></div> <div class="line"><a name="l00417"></a><span class="lineno"> 417</span>  <span class="stringliteral">"pxor %%xmm1, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00418"></a><span class="lineno"> 418</span>  <span class="stringliteral">"pslldq $4, %%xmm1 \n\t"</span></div> <div class="line"><a name="l00419"></a><span class="lineno"> 419</span>  <span class="stringliteral">"pxor %%xmm1, %%xmm2 \n\t"</span></div> <div class="line"><a name="l00420"></a><span class="lineno"> 420</span>  <span class="stringliteral">"pslldq $4, %%xmm1 \n\t"</span></div> <div class="line"><a name="l00421"></a><span class="lineno"> 421</span>  <span class="stringliteral">"pxor %%xmm2, %%xmm1 \n\t"</span></div> <div class="line"><a name="l00422"></a><span class="lineno"> 422</span>  <span class="stringliteral">"add $16, %0 \n\t"</span></div> <div class="line"><a name="l00423"></a><span class="lineno"> 423</span>  <span class="stringliteral">"movdqu %%xmm1, (%0) \n\t"</span></div> <div class="line"><a name="l00424"></a><span class="lineno"> 424</span>  <span class="stringliteral">"ret \n\t"</span></div> <div class="line"><a name="l00425"></a><span class="lineno"> 425</span> </div> <div class="line"><a name="l00426"></a><span class="lineno"> 426</span>  <span class="comment">/*</span></div> <div class="line"><a name="l00427"></a><span class="lineno"> 427</span> <span class="comment"> * Main "loop" - Generating one more key than necessary,</span></div> <div class="line"><a name="l00428"></a><span class="lineno"> 428</span> <span class="comment"> * see definition of aes_context.buf</span></div> <div class="line"><a name="l00429"></a><span class="lineno"> 429</span> <span class="comment"> */</span></div> <div class="line"><a name="l00430"></a><span class="lineno"> 430</span>  <span class="stringliteral">"2: \n\t"</span></div> <div class="line"><a name="l00431"></a><span class="lineno"> 431</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x01 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00432"></a><span class="lineno"> 432</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x02 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00433"></a><span class="lineno"> 433</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x04 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00434"></a><span class="lineno"> 434</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x08 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00435"></a><span class="lineno"> 435</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x10 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00436"></a><span class="lineno"> 436</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x20 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00437"></a><span class="lineno"> 437</span>  AESKEYGENA xmm1_xmm2 <span class="stringliteral">",0x40 \n\tcall 1b \n\t"</span></div> <div class="line"><a name="l00438"></a><span class="lineno"> 438</span>  :</div> <div class="line"><a name="l00439"></a><span class="lineno"> 439</span>  : <span class="stringliteral">"r"</span> (rk), <span class="stringliteral">"r"</span> (key)</div> <div class="line"><a name="l00440"></a><span class="lineno"> 440</span>  : <span class="stringliteral">"memory"</span>, <span class="stringliteral">"cc"</span>, <span class="stringliteral">"0"</span> );</div> <div class="line"><a name="l00441"></a><span class="lineno"> 441</span> }</div> <div class="line"><a name="l00442"></a><span class="lineno"> 442</span> </div> <div class="line"><a name="l00443"></a><span class="lineno"> 443</span> <span class="comment">/*</span></div> <div class="line"><a name="l00444"></a><span class="lineno"> 444</span> <span class="comment"> * Key expansion, wrapper</span></div> <div class="line"><a name="l00445"></a><span class="lineno"> 445</span> <span class="comment"> */</span></div> <div class="line"><a name="l00446"></a><span class="lineno"> 446</span> <span class="keywordtype">int</span> aesni_setkey_enc( <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *rk,</div> <div class="line"><a name="l00447"></a><span class="lineno"> 447</span>  <span class="keyword">const</span> <span class="keywordtype">unsigned</span> <span class="keywordtype">char</span> *key,</div> <div class="line"><a name="l00448"></a><span class="lineno"> 448</span>  <span class="keywordtype">size_t</span> bits )</div> <div class="line"><a name="l00449"></a><span class="lineno"> 449</span> {</div> <div class="line"><a name="l00450"></a><span class="lineno"> 450</span>  <span class="keywordflow">switch</span>( bits )</div> <div class="line"><a name="l00451"></a><span class="lineno"> 451</span>  {</div> <div class="line"><a name="l00452"></a><span class="lineno"> 452</span>  <span class="keywordflow">case</span> 128: aesni_setkey_enc_128( rk, key ); <span class="keywordflow">break</span>;</div> <div class="line"><a name="l00453"></a><span class="lineno"> 453</span>  <span class="keywordflow">case</span> 192: aesni_setkey_enc_192( rk, key ); <span class="keywordflow">break</span>;</div> <div class="line"><a name="l00454"></a><span class="lineno"> 454</span>  <span class="keywordflow">case</span> 256: aesni_setkey_enc_256( rk, key ); <span class="keywordflow">break</span>;</div> <div class="line"><a name="l00455"></a><span class="lineno"> 455</span>  <span class="keywordflow">default</span> : <span class="keywordflow">return</span>( <a class="code" href="aes_8h.html#ac9743adb9edbf81a73b5d522902163e4">POLARSSL_ERR_AES_INVALID_KEY_LENGTH</a> );</div> <div class="line"><a name="l00456"></a><span class="lineno"> 456</span>  }</div> <div class="line"><a name="l00457"></a><span class="lineno"> 457</span> </div> <div class="line"><a name="l00458"></a><span class="lineno"> 458</span>  <span class="keywordflow">return</span>( 0 );</div> <div class="line"><a name="l00459"></a><span class="lineno"> 459</span> }</div> <div class="line"><a name="l00460"></a><span class="lineno"> 460</span> </div> <div class="line"><a name="l00461"></a><span class="lineno"> 461</span> <span class="preprocessor">#endif </span><span class="comment">/* POLARSSL_HAVE_X86_64 */</span><span class="preprocessor"></span></div> <div class="line"><a name="l00462"></a><span class="lineno"> 462</span> <span class="preprocessor"></span></div> <div class="line"><a name="l00463"></a><span class="lineno"> 463</span> <span class="preprocessor">#endif </span><span class="comment">/* POLARSSL_AESNI_C */</span><span class="preprocessor"></span></div> <div class="ttc" id="structaes__context_html"><div class="ttname"><a href="structaes__context.html">aes_context</a></div><div class="ttdoc">AES context structure. </div><div class="ttdef"><b>Definition:</b> <a href="aes_8h_source.html#l00068">aes.h:68</a></div></div> <div class="ttc" id="config_8h_html"><div class="ttname"><a href="config_8h.html">config.h</a></div><div class="ttdoc">Configuration options (set of defines) </div></div> <div class="ttc" id="aesni_8h_html"><div class="ttname"><a href="aesni_8h.html">aesni.h</a></div><div class="ttdoc">AES-NI for hardware AES acceleration on some Intel processors. </div></div> <div class="ttc" id="aes_8h_html_ac9743adb9edbf81a73b5d522902163e4"><div class="ttname"><a href="aes_8h.html#ac9743adb9edbf81a73b5d522902163e4">POLARSSL_ERR_AES_INVALID_KEY_LENGTH</a></div><div class="ttdeci">#define POLARSSL_ERR_AES_INVALID_KEY_LENGTH</div><div class="ttdoc">Invalid key length. </div><div class="ttdef"><b>Definition:</b> <a href="aes_8h_source.html#l00049">aes.h:49</a></div></div> <div class="ttc" id="structaes__context_html_a93db0195022595f748c001221cc31abe"><div class="ttname"><a href="structaes__context.html#a93db0195022595f748c001221cc31abe">aes_context::rk</a></div><div class="ttdeci">uint32_t * rk</div><div class="ttdef"><b>Definition:</b> <a href="aes_8h_source.html#l00071">aes.h:71</a></div></div> <div class="ttc" id="structaes__context_html_af05054b9a37a06446ef0abf43cd97520"><div class="ttname"><a href="structaes__context.html#af05054b9a37a06446ef0abf43cd97520">aes_context::nr</a></div><div class="ttdeci">int nr</div><div class="ttdef"><b>Definition:</b> <a href="aes_8h_source.html#l00070">aes.h:70</a></div></div> </div><!-- fragment --></div><!-- contents --> <!-- start footer part --> <hr class="footer"/><address class="footer"><small> Generated on Thu Jul 31 2014 11:35:51 for PolarSSL v1.3.8 by  <a href="http://www.doxygen.org/index.html"> <img class="footer" src="doxygen.png" alt="doxygen"/> </a> 1.8.5 </small></address> </body> </html>