Thread (22 messages) 22 messages, 3 authors, 2015-09-20

Re: [PATCH v2 6/7] crypto: omap-aes: Add support for GCM mode

From: Lokesh Vutla <hidden>
Date: 2015-07-08 08:34:00
Also in: linux-omap, lkml

On Wednesday 08 July 2015 01:23 PM, Herbert Xu wrote:
On Wed, Jul 08, 2015 at 03:48:05PM +0800, Herbert Xu wrote:
quoted
On Wed, Jul 08, 2015 at 12:29:47PM +0530, Lokesh Vutla wrote:
quoted
quoted
quoted
+	if (req->assoclen + req->cryptlen == 0) {
+		scatterwalk_map_and_copy(ctx->auth_tag, req->dst, 0, authlen,
+					 1);
+		return 0;
+	}
How can this be right? Did you enable the selftest?
Why not? Self tests are passed for this case.

As per the equation given in GCM spec[1], we can see that
if assoclen and cryptlen is 0, then output of GCM  is just E(K, Y0)
where Y0 = IV||(0^31)1
I have E(K, Y0) calculated in previous step. And copying it
to destination if assoclen and cryptlen is 0.

Correct me if I am wrong.
It should be E(K, Y0) ^ GHASH(0).  So unless GHASH(0) == 0, your
code doesn't work.
OK, GHASH(0) is indeed zero so I guess your code does work after
all.
Sorry. I did not see this message and replied on the other thread.

Thanks and regards,
Lokesh
Cheers,
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help