aesni-x86.pl 74 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525
  1. #!/usr/bin/env perl
  2. # ====================================================================
  3. # Written by Andy Polyakov <appro@openssl.org> for the OpenSSL
  4. # project. The module is, however, dual licensed under OpenSSL and
  5. # CRYPTOGAMS licenses depending on where you obtain it. For further
  6. # details see http://www.openssl.org/~appro/cryptogams/.
  7. # ====================================================================
  8. #
  9. # This module implements support for Intel AES-NI extension. In
  10. # OpenSSL context it's used with Intel engine, but can also be used as
  11. # drop-in replacement for crypto/aes/asm/aes-586.pl [see below for
  12. # details].
  13. #
  14. # Performance.
  15. #
  16. # To start with see corresponding paragraph in aesni-x86_64.pl...
  17. # Instead of filling table similar to one found there I've chosen to
  18. # summarize *comparison* results for raw ECB, CTR and CBC benchmarks.
  19. # The simplified table below represents 32-bit performance relative
  20. # to 64-bit one in every given point. Ratios vary for different
  21. # encryption modes, therefore interval values.
  22. #
  23. # 16-byte 64-byte 256-byte 1-KB 8-KB
  24. # 53-67% 67-84% 91-94% 95-98% 97-99.5%
  25. #
  26. # Lower ratios for smaller block sizes are perfectly understandable,
  27. # because function call overhead is higher in 32-bit mode. Largest
  28. # 8-KB block performance is virtually same: 32-bit code is less than
  29. # 1% slower for ECB, CBC and CCM, and ~3% slower otherwise.
  30. # January 2011
  31. #
  32. # See aesni-x86_64.pl for details. Unlike x86_64 version this module
  33. # interleaves at most 6 aes[enc|dec] instructions, because there are
  34. # not enough registers for 8x interleave [which should be optimal for
  35. # Sandy Bridge]. Actually, performance results for 6x interleave
  36. # factor presented in aesni-x86_64.pl (except for CTR) are for this
  37. # module.
  38. # April 2011
  39. #
  40. # Add aesni_xts_[en|de]crypt. Westmere spends 1.50 cycles processing
  41. # one byte out of 8KB with 128-bit key, Sandy Bridge - 1.09.
  42. ######################################################################
  43. # Current large-block performance in cycles per byte processed with
  44. # 128-bit key (less is better).
  45. #
  46. # CBC en-/decrypt CTR XTS ECB
  47. # Westmere 3.77/1.37 1.37 1.52 1.27
  48. # * Bridge 5.07/0.98 0.99 1.09 0.91
  49. # Haswell 4.44/0.80 0.97 1.03 0.72
  50. # Silvermont 5.77/3.56 3.67 4.03 3.46
  51. # Bulldozer 5.80/0.98 1.05 1.24 0.93
  52. $PREFIX="aesni"; # if $PREFIX is set to "AES", the script
  53. # generates drop-in replacement for
  54. # crypto/aes/asm/aes-586.pl:-)
  55. $inline=1; # inline _aesni_[en|de]crypt
  56. $0 =~ m/(.*[\/\\])[^\/\\]+$/; $dir=$1;
  57. push(@INC,"${dir}","${dir}../../perlasm");
  58. require "x86asm.pl";
  59. &asm_init($ARGV[0],$0);
  60. &external_label("OPENSSL_ia32cap_P");
  61. &static_label("key_const");
  62. if ($PREFIX eq "aesni") { $movekey=\&movups; }
  63. else { $movekey=\&movups; }
  64. $len="eax";
  65. $rounds="ecx";
  66. $key="edx";
  67. $inp="esi";
  68. $out="edi";
  69. $rounds_="ebx"; # backup copy for $rounds
  70. $key_="ebp"; # backup copy for $key
  71. $rndkey0="xmm0";
  72. $rndkey1="xmm1";
  73. $inout0="xmm2";
  74. $inout1="xmm3";
  75. $inout2="xmm4";
  76. $inout3="xmm5"; $in1="xmm5";
  77. $inout4="xmm6"; $in0="xmm6";
  78. $inout5="xmm7"; $ivec="xmm7";
  79. # AESNI extension
  80. sub aeskeygenassist
  81. { my($dst,$src,$imm)=@_;
  82. if ("$dst:$src" =~ /xmm([0-7]):xmm([0-7])/)
  83. { &data_byte(0x66,0x0f,0x3a,0xdf,0xc0|($1<<3)|$2,$imm); }
  84. }
  85. sub aescommon
  86. { my($opcodelet,$dst,$src)=@_;
  87. if ("$dst:$src" =~ /xmm([0-7]):xmm([0-7])/)
  88. { &data_byte(0x66,0x0f,0x38,$opcodelet,0xc0|($1<<3)|$2);}
  89. }
  90. sub aesimc { aescommon(0xdb,@_); }
  91. sub aesenc { aescommon(0xdc,@_); }
  92. sub aesenclast { aescommon(0xdd,@_); }
  93. sub aesdec { aescommon(0xde,@_); }
  94. sub aesdeclast { aescommon(0xdf,@_); }
  95. # Inline version of internal aesni_[en|de]crypt1
  96. { my $sn;
  97. sub aesni_inline_generate1
  98. { my ($p,$inout,$ivec)=@_; $inout=$inout0 if (!defined($inout));
  99. $sn++;
  100. &$movekey ($rndkey0,&QWP(0,$key));
  101. &$movekey ($rndkey1,&QWP(16,$key));
  102. &xorps ($ivec,$rndkey0) if (defined($ivec));
  103. &lea ($key,&DWP(32,$key));
  104. &xorps ($inout,$ivec) if (defined($ivec));
  105. &xorps ($inout,$rndkey0) if (!defined($ivec));
  106. &set_label("${p}1_loop_$sn");
  107. eval"&aes${p} ($inout,$rndkey1)";
  108. &dec ($rounds);
  109. &$movekey ($rndkey1,&QWP(0,$key));
  110. &lea ($key,&DWP(16,$key));
  111. &jnz (&label("${p}1_loop_$sn"));
  112. eval"&aes${p}last ($inout,$rndkey1)";
  113. }}
  114. sub aesni_generate1 # fully unrolled loop
  115. { my ($p,$inout)=@_; $inout=$inout0 if (!defined($inout));
  116. &function_begin_B("_aesni_${p}rypt1");
  117. &movups ($rndkey0,&QWP(0,$key));
  118. &$movekey ($rndkey1,&QWP(0x10,$key));
  119. &xorps ($inout,$rndkey0);
  120. &$movekey ($rndkey0,&QWP(0x20,$key));
  121. &lea ($key,&DWP(0x30,$key));
  122. &cmp ($rounds,11);
  123. &jb (&label("${p}128"));
  124. &lea ($key,&DWP(0x20,$key));
  125. &je (&label("${p}192"));
  126. &lea ($key,&DWP(0x20,$key));
  127. eval"&aes${p} ($inout,$rndkey1)";
  128. &$movekey ($rndkey1,&QWP(-0x40,$key));
  129. eval"&aes${p} ($inout,$rndkey0)";
  130. &$movekey ($rndkey0,&QWP(-0x30,$key));
  131. &set_label("${p}192");
  132. eval"&aes${p} ($inout,$rndkey1)";
  133. &$movekey ($rndkey1,&QWP(-0x20,$key));
  134. eval"&aes${p} ($inout,$rndkey0)";
  135. &$movekey ($rndkey0,&QWP(-0x10,$key));
  136. &set_label("${p}128");
  137. eval"&aes${p} ($inout,$rndkey1)";
  138. &$movekey ($rndkey1,&QWP(0,$key));
  139. eval"&aes${p} ($inout,$rndkey0)";
  140. &$movekey ($rndkey0,&QWP(0x10,$key));
  141. eval"&aes${p} ($inout,$rndkey1)";
  142. &$movekey ($rndkey1,&QWP(0x20,$key));
  143. eval"&aes${p} ($inout,$rndkey0)";
  144. &$movekey ($rndkey0,&QWP(0x30,$key));
  145. eval"&aes${p} ($inout,$rndkey1)";
  146. &$movekey ($rndkey1,&QWP(0x40,$key));
  147. eval"&aes${p} ($inout,$rndkey0)";
  148. &$movekey ($rndkey0,&QWP(0x50,$key));
  149. eval"&aes${p} ($inout,$rndkey1)";
  150. &$movekey ($rndkey1,&QWP(0x60,$key));
  151. eval"&aes${p} ($inout,$rndkey0)";
  152. &$movekey ($rndkey0,&QWP(0x70,$key));
  153. eval"&aes${p} ($inout,$rndkey1)";
  154. eval"&aes${p}last ($inout,$rndkey0)";
  155. &ret();
  156. &function_end_B("_aesni_${p}rypt1");
  157. }
  158. # void $PREFIX_encrypt (const void *inp,void *out,const AES_KEY *key);
  159. &aesni_generate1("enc") if (!$inline);
  160. &function_begin_B("${PREFIX}_encrypt");
  161. &mov ("eax",&wparam(0));
  162. &mov ($key,&wparam(2));
  163. &movups ($inout0,&QWP(0,"eax"));
  164. &mov ($rounds,&DWP(240,$key));
  165. &mov ("eax",&wparam(1));
  166. if ($inline)
  167. { &aesni_inline_generate1("enc"); }
  168. else
  169. { &call ("_aesni_encrypt1"); }
  170. &pxor ($rndkey0,$rndkey0); # clear register bank
  171. &pxor ($rndkey1,$rndkey1);
  172. &movups (&QWP(0,"eax"),$inout0);
  173. &pxor ($inout0,$inout0);
  174. &ret ();
  175. &function_end_B("${PREFIX}_encrypt");
  176. # void $PREFIX_decrypt (const void *inp,void *out,const AES_KEY *key);
  177. &aesni_generate1("dec") if(!$inline);
  178. &function_begin_B("${PREFIX}_decrypt");
  179. &mov ("eax",&wparam(0));
  180. &mov ($key,&wparam(2));
  181. &movups ($inout0,&QWP(0,"eax"));
  182. &mov ($rounds,&DWP(240,$key));
  183. &mov ("eax",&wparam(1));
  184. if ($inline)
  185. { &aesni_inline_generate1("dec"); }
  186. else
  187. { &call ("_aesni_decrypt1"); }
  188. &pxor ($rndkey0,$rndkey0); # clear register bank
  189. &pxor ($rndkey1,$rndkey1);
  190. &movups (&QWP(0,"eax"),$inout0);
  191. &pxor ($inout0,$inout0);
  192. &ret ();
  193. &function_end_B("${PREFIX}_decrypt");
  194. # _aesni_[en|de]cryptN are private interfaces, N denotes interleave
  195. # factor. Why 3x subroutine were originally used in loops? Even though
  196. # aes[enc|dec] latency was originally 6, it could be scheduled only
  197. # every *2nd* cycle. Thus 3x interleave was the one providing optimal
  198. # utilization, i.e. when subroutine's throughput is virtually same as
  199. # of non-interleaved subroutine [for number of input blocks up to 3].
  200. # This is why it originally made no sense to implement 2x subroutine.
  201. # But times change and it became appropriate to spend extra 192 bytes
  202. # on 2x subroutine on Atom Silvermont account. For processors that
  203. # can schedule aes[enc|dec] every cycle optimal interleave factor
  204. # equals to corresponding instructions latency. 8x is optimal for
  205. # * Bridge, but it's unfeasible to accommodate such implementation
  206. # in XMM registers addreassable in 32-bit mode and therefore maximum
  207. # of 6x is used instead...
  208. sub aesni_generate2
  209. { my $p=shift;
  210. &function_begin_B("_aesni_${p}rypt2");
  211. &$movekey ($rndkey0,&QWP(0,$key));
  212. &shl ($rounds,4);
  213. &$movekey ($rndkey1,&QWP(16,$key));
  214. &xorps ($inout0,$rndkey0);
  215. &pxor ($inout1,$rndkey0);
  216. &$movekey ($rndkey0,&QWP(32,$key));
  217. &lea ($key,&DWP(32,$key,$rounds));
  218. &neg ($rounds);
  219. &add ($rounds,16);
  220. &set_label("${p}2_loop");
  221. eval"&aes${p} ($inout0,$rndkey1)";
  222. eval"&aes${p} ($inout1,$rndkey1)";
  223. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  224. &add ($rounds,32);
  225. eval"&aes${p} ($inout0,$rndkey0)";
  226. eval"&aes${p} ($inout1,$rndkey0)";
  227. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  228. &jnz (&label("${p}2_loop"));
  229. eval"&aes${p} ($inout0,$rndkey1)";
  230. eval"&aes${p} ($inout1,$rndkey1)";
  231. eval"&aes${p}last ($inout0,$rndkey0)";
  232. eval"&aes${p}last ($inout1,$rndkey0)";
  233. &ret();
  234. &function_end_B("_aesni_${p}rypt2");
  235. }
  236. sub aesni_generate3
  237. { my $p=shift;
  238. &function_begin_B("_aesni_${p}rypt3");
  239. &$movekey ($rndkey0,&QWP(0,$key));
  240. &shl ($rounds,4);
  241. &$movekey ($rndkey1,&QWP(16,$key));
  242. &xorps ($inout0,$rndkey0);
  243. &pxor ($inout1,$rndkey0);
  244. &pxor ($inout2,$rndkey0);
  245. &$movekey ($rndkey0,&QWP(32,$key));
  246. &lea ($key,&DWP(32,$key,$rounds));
  247. &neg ($rounds);
  248. &add ($rounds,16);
  249. &set_label("${p}3_loop");
  250. eval"&aes${p} ($inout0,$rndkey1)";
  251. eval"&aes${p} ($inout1,$rndkey1)";
  252. eval"&aes${p} ($inout2,$rndkey1)";
  253. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  254. &add ($rounds,32);
  255. eval"&aes${p} ($inout0,$rndkey0)";
  256. eval"&aes${p} ($inout1,$rndkey0)";
  257. eval"&aes${p} ($inout2,$rndkey0)";
  258. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  259. &jnz (&label("${p}3_loop"));
  260. eval"&aes${p} ($inout0,$rndkey1)";
  261. eval"&aes${p} ($inout1,$rndkey1)";
  262. eval"&aes${p} ($inout2,$rndkey1)";
  263. eval"&aes${p}last ($inout0,$rndkey0)";
  264. eval"&aes${p}last ($inout1,$rndkey0)";
  265. eval"&aes${p}last ($inout2,$rndkey0)";
  266. &ret();
  267. &function_end_B("_aesni_${p}rypt3");
  268. }
  269. # 4x interleave is implemented to improve small block performance,
  270. # most notably [and naturally] 4 block by ~30%. One can argue that one
  271. # should have implemented 5x as well, but improvement would be <20%,
  272. # so it's not worth it...
  273. sub aesni_generate4
  274. { my $p=shift;
  275. &function_begin_B("_aesni_${p}rypt4");
  276. &$movekey ($rndkey0,&QWP(0,$key));
  277. &$movekey ($rndkey1,&QWP(16,$key));
  278. &shl ($rounds,4);
  279. &xorps ($inout0,$rndkey0);
  280. &pxor ($inout1,$rndkey0);
  281. &pxor ($inout2,$rndkey0);
  282. &pxor ($inout3,$rndkey0);
  283. &$movekey ($rndkey0,&QWP(32,$key));
  284. &lea ($key,&DWP(32,$key,$rounds));
  285. &neg ($rounds);
  286. &data_byte (0x0f,0x1f,0x40,0x00);
  287. &add ($rounds,16);
  288. &set_label("${p}4_loop");
  289. eval"&aes${p} ($inout0,$rndkey1)";
  290. eval"&aes${p} ($inout1,$rndkey1)";
  291. eval"&aes${p} ($inout2,$rndkey1)";
  292. eval"&aes${p} ($inout3,$rndkey1)";
  293. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  294. &add ($rounds,32);
  295. eval"&aes${p} ($inout0,$rndkey0)";
  296. eval"&aes${p} ($inout1,$rndkey0)";
  297. eval"&aes${p} ($inout2,$rndkey0)";
  298. eval"&aes${p} ($inout3,$rndkey0)";
  299. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  300. &jnz (&label("${p}4_loop"));
  301. eval"&aes${p} ($inout0,$rndkey1)";
  302. eval"&aes${p} ($inout1,$rndkey1)";
  303. eval"&aes${p} ($inout2,$rndkey1)";
  304. eval"&aes${p} ($inout3,$rndkey1)";
  305. eval"&aes${p}last ($inout0,$rndkey0)";
  306. eval"&aes${p}last ($inout1,$rndkey0)";
  307. eval"&aes${p}last ($inout2,$rndkey0)";
  308. eval"&aes${p}last ($inout3,$rndkey0)";
  309. &ret();
  310. &function_end_B("_aesni_${p}rypt4");
  311. }
  312. sub aesni_generate6
  313. { my $p=shift;
  314. &function_begin_B("_aesni_${p}rypt6");
  315. &static_label("_aesni_${p}rypt6_enter");
  316. &$movekey ($rndkey0,&QWP(0,$key));
  317. &shl ($rounds,4);
  318. &$movekey ($rndkey1,&QWP(16,$key));
  319. &xorps ($inout0,$rndkey0);
  320. &pxor ($inout1,$rndkey0); # pxor does better here
  321. &pxor ($inout2,$rndkey0);
  322. eval"&aes${p} ($inout0,$rndkey1)";
  323. &pxor ($inout3,$rndkey0);
  324. &pxor ($inout4,$rndkey0);
  325. eval"&aes${p} ($inout1,$rndkey1)";
  326. &lea ($key,&DWP(32,$key,$rounds));
  327. &neg ($rounds);
  328. eval"&aes${p} ($inout2,$rndkey1)";
  329. &pxor ($inout5,$rndkey0);
  330. &$movekey ($rndkey0,&QWP(0,$key,$rounds));
  331. &add ($rounds,16);
  332. &jmp (&label("_aesni_${p}rypt6_inner"));
  333. &set_label("${p}6_loop",16);
  334. eval"&aes${p} ($inout0,$rndkey1)";
  335. eval"&aes${p} ($inout1,$rndkey1)";
  336. eval"&aes${p} ($inout2,$rndkey1)";
  337. &set_label("_aesni_${p}rypt6_inner");
  338. eval"&aes${p} ($inout3,$rndkey1)";
  339. eval"&aes${p} ($inout4,$rndkey1)";
  340. eval"&aes${p} ($inout5,$rndkey1)";
  341. &set_label("_aesni_${p}rypt6_enter");
  342. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  343. &add ($rounds,32);
  344. eval"&aes${p} ($inout0,$rndkey0)";
  345. eval"&aes${p} ($inout1,$rndkey0)";
  346. eval"&aes${p} ($inout2,$rndkey0)";
  347. eval"&aes${p} ($inout3,$rndkey0)";
  348. eval"&aes${p} ($inout4,$rndkey0)";
  349. eval"&aes${p} ($inout5,$rndkey0)";
  350. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  351. &jnz (&label("${p}6_loop"));
  352. eval"&aes${p} ($inout0,$rndkey1)";
  353. eval"&aes${p} ($inout1,$rndkey1)";
  354. eval"&aes${p} ($inout2,$rndkey1)";
  355. eval"&aes${p} ($inout3,$rndkey1)";
  356. eval"&aes${p} ($inout4,$rndkey1)";
  357. eval"&aes${p} ($inout5,$rndkey1)";
  358. eval"&aes${p}last ($inout0,$rndkey0)";
  359. eval"&aes${p}last ($inout1,$rndkey0)";
  360. eval"&aes${p}last ($inout2,$rndkey0)";
  361. eval"&aes${p}last ($inout3,$rndkey0)";
  362. eval"&aes${p}last ($inout4,$rndkey0)";
  363. eval"&aes${p}last ($inout5,$rndkey0)";
  364. &ret();
  365. &function_end_B("_aesni_${p}rypt6");
  366. }
  367. &aesni_generate2("enc") if ($PREFIX eq "aesni");
  368. &aesni_generate2("dec");
  369. &aesni_generate3("enc") if ($PREFIX eq "aesni");
  370. &aesni_generate3("dec");
  371. &aesni_generate4("enc") if ($PREFIX eq "aesni");
  372. &aesni_generate4("dec");
  373. &aesni_generate6("enc") if ($PREFIX eq "aesni");
  374. &aesni_generate6("dec");
  375. if ($PREFIX eq "aesni") {
  376. ######################################################################
  377. # void aesni_ecb_encrypt (const void *in, void *out,
  378. # size_t length, const AES_KEY *key,
  379. # int enc);
  380. &function_begin("aesni_ecb_encrypt");
  381. &mov ($inp,&wparam(0));
  382. &mov ($out,&wparam(1));
  383. &mov ($len,&wparam(2));
  384. &mov ($key,&wparam(3));
  385. &mov ($rounds_,&wparam(4));
  386. &and ($len,-16);
  387. &jz (&label("ecb_ret"));
  388. &mov ($rounds,&DWP(240,$key));
  389. &test ($rounds_,$rounds_);
  390. &jz (&label("ecb_decrypt"));
  391. &mov ($key_,$key); # backup $key
  392. &mov ($rounds_,$rounds); # backup $rounds
  393. &cmp ($len,0x60);
  394. &jb (&label("ecb_enc_tail"));
  395. &movdqu ($inout0,&QWP(0,$inp));
  396. &movdqu ($inout1,&QWP(0x10,$inp));
  397. &movdqu ($inout2,&QWP(0x20,$inp));
  398. &movdqu ($inout3,&QWP(0x30,$inp));
  399. &movdqu ($inout4,&QWP(0x40,$inp));
  400. &movdqu ($inout5,&QWP(0x50,$inp));
  401. &lea ($inp,&DWP(0x60,$inp));
  402. &sub ($len,0x60);
  403. &jmp (&label("ecb_enc_loop6_enter"));
  404. &set_label("ecb_enc_loop6",16);
  405. &movups (&QWP(0,$out),$inout0);
  406. &movdqu ($inout0,&QWP(0,$inp));
  407. &movups (&QWP(0x10,$out),$inout1);
  408. &movdqu ($inout1,&QWP(0x10,$inp));
  409. &movups (&QWP(0x20,$out),$inout2);
  410. &movdqu ($inout2,&QWP(0x20,$inp));
  411. &movups (&QWP(0x30,$out),$inout3);
  412. &movdqu ($inout3,&QWP(0x30,$inp));
  413. &movups (&QWP(0x40,$out),$inout4);
  414. &movdqu ($inout4,&QWP(0x40,$inp));
  415. &movups (&QWP(0x50,$out),$inout5);
  416. &lea ($out,&DWP(0x60,$out));
  417. &movdqu ($inout5,&QWP(0x50,$inp));
  418. &lea ($inp,&DWP(0x60,$inp));
  419. &set_label("ecb_enc_loop6_enter");
  420. &call ("_aesni_encrypt6");
  421. &mov ($key,$key_); # restore $key
  422. &mov ($rounds,$rounds_); # restore $rounds
  423. &sub ($len,0x60);
  424. &jnc (&label("ecb_enc_loop6"));
  425. &movups (&QWP(0,$out),$inout0);
  426. &movups (&QWP(0x10,$out),$inout1);
  427. &movups (&QWP(0x20,$out),$inout2);
  428. &movups (&QWP(0x30,$out),$inout3);
  429. &movups (&QWP(0x40,$out),$inout4);
  430. &movups (&QWP(0x50,$out),$inout5);
  431. &lea ($out,&DWP(0x60,$out));
  432. &add ($len,0x60);
  433. &jz (&label("ecb_ret"));
  434. &set_label("ecb_enc_tail");
  435. &movups ($inout0,&QWP(0,$inp));
  436. &cmp ($len,0x20);
  437. &jb (&label("ecb_enc_one"));
  438. &movups ($inout1,&QWP(0x10,$inp));
  439. &je (&label("ecb_enc_two"));
  440. &movups ($inout2,&QWP(0x20,$inp));
  441. &cmp ($len,0x40);
  442. &jb (&label("ecb_enc_three"));
  443. &movups ($inout3,&QWP(0x30,$inp));
  444. &je (&label("ecb_enc_four"));
  445. &movups ($inout4,&QWP(0x40,$inp));
  446. &xorps ($inout5,$inout5);
  447. &call ("_aesni_encrypt6");
  448. &movups (&QWP(0,$out),$inout0);
  449. &movups (&QWP(0x10,$out),$inout1);
  450. &movups (&QWP(0x20,$out),$inout2);
  451. &movups (&QWP(0x30,$out),$inout3);
  452. &movups (&QWP(0x40,$out),$inout4);
  453. jmp (&label("ecb_ret"));
  454. &set_label("ecb_enc_one",16);
  455. if ($inline)
  456. { &aesni_inline_generate1("enc"); }
  457. else
  458. { &call ("_aesni_encrypt1"); }
  459. &movups (&QWP(0,$out),$inout0);
  460. &jmp (&label("ecb_ret"));
  461. &set_label("ecb_enc_two",16);
  462. &call ("_aesni_encrypt2");
  463. &movups (&QWP(0,$out),$inout0);
  464. &movups (&QWP(0x10,$out),$inout1);
  465. &jmp (&label("ecb_ret"));
  466. &set_label("ecb_enc_three",16);
  467. &call ("_aesni_encrypt3");
  468. &movups (&QWP(0,$out),$inout0);
  469. &movups (&QWP(0x10,$out),$inout1);
  470. &movups (&QWP(0x20,$out),$inout2);
  471. &jmp (&label("ecb_ret"));
  472. &set_label("ecb_enc_four",16);
  473. &call ("_aesni_encrypt4");
  474. &movups (&QWP(0,$out),$inout0);
  475. &movups (&QWP(0x10,$out),$inout1);
  476. &movups (&QWP(0x20,$out),$inout2);
  477. &movups (&QWP(0x30,$out),$inout3);
  478. &jmp (&label("ecb_ret"));
  479. ######################################################################
  480. &set_label("ecb_decrypt",16);
  481. &mov ($key_,$key); # backup $key
  482. &mov ($rounds_,$rounds); # backup $rounds
  483. &cmp ($len,0x60);
  484. &jb (&label("ecb_dec_tail"));
  485. &movdqu ($inout0,&QWP(0,$inp));
  486. &movdqu ($inout1,&QWP(0x10,$inp));
  487. &movdqu ($inout2,&QWP(0x20,$inp));
  488. &movdqu ($inout3,&QWP(0x30,$inp));
  489. &movdqu ($inout4,&QWP(0x40,$inp));
  490. &movdqu ($inout5,&QWP(0x50,$inp));
  491. &lea ($inp,&DWP(0x60,$inp));
  492. &sub ($len,0x60);
  493. &jmp (&label("ecb_dec_loop6_enter"));
  494. &set_label("ecb_dec_loop6",16);
  495. &movups (&QWP(0,$out),$inout0);
  496. &movdqu ($inout0,&QWP(0,$inp));
  497. &movups (&QWP(0x10,$out),$inout1);
  498. &movdqu ($inout1,&QWP(0x10,$inp));
  499. &movups (&QWP(0x20,$out),$inout2);
  500. &movdqu ($inout2,&QWP(0x20,$inp));
  501. &movups (&QWP(0x30,$out),$inout3);
  502. &movdqu ($inout3,&QWP(0x30,$inp));
  503. &movups (&QWP(0x40,$out),$inout4);
  504. &movdqu ($inout4,&QWP(0x40,$inp));
  505. &movups (&QWP(0x50,$out),$inout5);
  506. &lea ($out,&DWP(0x60,$out));
  507. &movdqu ($inout5,&QWP(0x50,$inp));
  508. &lea ($inp,&DWP(0x60,$inp));
  509. &set_label("ecb_dec_loop6_enter");
  510. &call ("_aesni_decrypt6");
  511. &mov ($key,$key_); # restore $key
  512. &mov ($rounds,$rounds_); # restore $rounds
  513. &sub ($len,0x60);
  514. &jnc (&label("ecb_dec_loop6"));
  515. &movups (&QWP(0,$out),$inout0);
  516. &movups (&QWP(0x10,$out),$inout1);
  517. &movups (&QWP(0x20,$out),$inout2);
  518. &movups (&QWP(0x30,$out),$inout3);
  519. &movups (&QWP(0x40,$out),$inout4);
  520. &movups (&QWP(0x50,$out),$inout5);
  521. &lea ($out,&DWP(0x60,$out));
  522. &add ($len,0x60);
  523. &jz (&label("ecb_ret"));
  524. &set_label("ecb_dec_tail");
  525. &movups ($inout0,&QWP(0,$inp));
  526. &cmp ($len,0x20);
  527. &jb (&label("ecb_dec_one"));
  528. &movups ($inout1,&QWP(0x10,$inp));
  529. &je (&label("ecb_dec_two"));
  530. &movups ($inout2,&QWP(0x20,$inp));
  531. &cmp ($len,0x40);
  532. &jb (&label("ecb_dec_three"));
  533. &movups ($inout3,&QWP(0x30,$inp));
  534. &je (&label("ecb_dec_four"));
  535. &movups ($inout4,&QWP(0x40,$inp));
  536. &xorps ($inout5,$inout5);
  537. &call ("_aesni_decrypt6");
  538. &movups (&QWP(0,$out),$inout0);
  539. &movups (&QWP(0x10,$out),$inout1);
  540. &movups (&QWP(0x20,$out),$inout2);
  541. &movups (&QWP(0x30,$out),$inout3);
  542. &movups (&QWP(0x40,$out),$inout4);
  543. &jmp (&label("ecb_ret"));
  544. &set_label("ecb_dec_one",16);
  545. if ($inline)
  546. { &aesni_inline_generate1("dec"); }
  547. else
  548. { &call ("_aesni_decrypt1"); }
  549. &movups (&QWP(0,$out),$inout0);
  550. &jmp (&label("ecb_ret"));
  551. &set_label("ecb_dec_two",16);
  552. &call ("_aesni_decrypt2");
  553. &movups (&QWP(0,$out),$inout0);
  554. &movups (&QWP(0x10,$out),$inout1);
  555. &jmp (&label("ecb_ret"));
  556. &set_label("ecb_dec_three",16);
  557. &call ("_aesni_decrypt3");
  558. &movups (&QWP(0,$out),$inout0);
  559. &movups (&QWP(0x10,$out),$inout1);
  560. &movups (&QWP(0x20,$out),$inout2);
  561. &jmp (&label("ecb_ret"));
  562. &set_label("ecb_dec_four",16);
  563. &call ("_aesni_decrypt4");
  564. &movups (&QWP(0,$out),$inout0);
  565. &movups (&QWP(0x10,$out),$inout1);
  566. &movups (&QWP(0x20,$out),$inout2);
  567. &movups (&QWP(0x30,$out),$inout3);
  568. &set_label("ecb_ret");
  569. &pxor ("xmm0","xmm0"); # clear register bank
  570. &pxor ("xmm1","xmm1");
  571. &pxor ("xmm2","xmm2");
  572. &pxor ("xmm3","xmm3");
  573. &pxor ("xmm4","xmm4");
  574. &pxor ("xmm5","xmm5");
  575. &pxor ("xmm6","xmm6");
  576. &pxor ("xmm7","xmm7");
  577. &function_end("aesni_ecb_encrypt");
  578. ######################################################################
  579. # void aesni_ccm64_[en|de]crypt_blocks (const void *in, void *out,
  580. # size_t blocks, const AES_KEY *key,
  581. # const char *ivec,char *cmac);
  582. #
  583. # Handles only complete blocks, operates on 64-bit counter and
  584. # does not update *ivec! Nor does it finalize CMAC value
  585. # (see engine/eng_aesni.c for details)
  586. #
  587. { my $cmac=$inout1;
  588. &function_begin("aesni_ccm64_encrypt_blocks");
  589. &mov ($inp,&wparam(0));
  590. &mov ($out,&wparam(1));
  591. &mov ($len,&wparam(2));
  592. &mov ($key,&wparam(3));
  593. &mov ($rounds_,&wparam(4));
  594. &mov ($rounds,&wparam(5));
  595. &mov ($key_,"esp");
  596. &sub ("esp",60);
  597. &and ("esp",-16); # align stack
  598. &mov (&DWP(48,"esp"),$key_);
  599. &movdqu ($ivec,&QWP(0,$rounds_)); # load ivec
  600. &movdqu ($cmac,&QWP(0,$rounds)); # load cmac
  601. &mov ($rounds,&DWP(240,$key));
  602. # compose byte-swap control mask for pshufb on stack
  603. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  604. &mov (&DWP(4,"esp"),0x08090a0b);
  605. &mov (&DWP(8,"esp"),0x04050607);
  606. &mov (&DWP(12,"esp"),0x00010203);
  607. # compose counter increment vector on stack
  608. &mov ($rounds_,1);
  609. &xor ($key_,$key_);
  610. &mov (&DWP(16,"esp"),$rounds_);
  611. &mov (&DWP(20,"esp"),$key_);
  612. &mov (&DWP(24,"esp"),$key_);
  613. &mov (&DWP(28,"esp"),$key_);
  614. &shl ($rounds,4);
  615. &mov ($rounds_,16);
  616. &lea ($key_,&DWP(0,$key));
  617. &movdqa ($inout3,&QWP(0,"esp"));
  618. &movdqa ($inout0,$ivec);
  619. &lea ($key,&DWP(32,$key,$rounds));
  620. &sub ($rounds_,$rounds);
  621. &pshufb ($ivec,$inout3);
  622. &set_label("ccm64_enc_outer");
  623. &$movekey ($rndkey0,&QWP(0,$key_));
  624. &mov ($rounds,$rounds_);
  625. &movups ($in0,&QWP(0,$inp));
  626. &xorps ($inout0,$rndkey0);
  627. &$movekey ($rndkey1,&QWP(16,$key_));
  628. &xorps ($rndkey0,$in0);
  629. &xorps ($cmac,$rndkey0); # cmac^=inp
  630. &$movekey ($rndkey0,&QWP(32,$key_));
  631. &set_label("ccm64_enc2_loop");
  632. &aesenc ($inout0,$rndkey1);
  633. &aesenc ($cmac,$rndkey1);
  634. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  635. &add ($rounds,32);
  636. &aesenc ($inout0,$rndkey0);
  637. &aesenc ($cmac,$rndkey0);
  638. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  639. &jnz (&label("ccm64_enc2_loop"));
  640. &aesenc ($inout0,$rndkey1);
  641. &aesenc ($cmac,$rndkey1);
  642. &paddq ($ivec,&QWP(16,"esp"));
  643. &dec ($len);
  644. &aesenclast ($inout0,$rndkey0);
  645. &aesenclast ($cmac,$rndkey0);
  646. &lea ($inp,&DWP(16,$inp));
  647. &xorps ($in0,$inout0); # inp^=E(ivec)
  648. &movdqa ($inout0,$ivec);
  649. &movups (&QWP(0,$out),$in0); # save output
  650. &pshufb ($inout0,$inout3);
  651. &lea ($out,&DWP(16,$out));
  652. &jnz (&label("ccm64_enc_outer"));
  653. &mov ("esp",&DWP(48,"esp"));
  654. &mov ($out,&wparam(5));
  655. &movups (&QWP(0,$out),$cmac);
  656. &pxor ("xmm0","xmm0"); # clear register bank
  657. &pxor ("xmm1","xmm1");
  658. &pxor ("xmm2","xmm2");
  659. &pxor ("xmm3","xmm3");
  660. &pxor ("xmm4","xmm4");
  661. &pxor ("xmm5","xmm5");
  662. &pxor ("xmm6","xmm6");
  663. &pxor ("xmm7","xmm7");
  664. &function_end("aesni_ccm64_encrypt_blocks");
  665. &function_begin("aesni_ccm64_decrypt_blocks");
  666. &mov ($inp,&wparam(0));
  667. &mov ($out,&wparam(1));
  668. &mov ($len,&wparam(2));
  669. &mov ($key,&wparam(3));
  670. &mov ($rounds_,&wparam(4));
  671. &mov ($rounds,&wparam(5));
  672. &mov ($key_,"esp");
  673. &sub ("esp",60);
  674. &and ("esp",-16); # align stack
  675. &mov (&DWP(48,"esp"),$key_);
  676. &movdqu ($ivec,&QWP(0,$rounds_)); # load ivec
  677. &movdqu ($cmac,&QWP(0,$rounds)); # load cmac
  678. &mov ($rounds,&DWP(240,$key));
  679. # compose byte-swap control mask for pshufb on stack
  680. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  681. &mov (&DWP(4,"esp"),0x08090a0b);
  682. &mov (&DWP(8,"esp"),0x04050607);
  683. &mov (&DWP(12,"esp"),0x00010203);
  684. # compose counter increment vector on stack
  685. &mov ($rounds_,1);
  686. &xor ($key_,$key_);
  687. &mov (&DWP(16,"esp"),$rounds_);
  688. &mov (&DWP(20,"esp"),$key_);
  689. &mov (&DWP(24,"esp"),$key_);
  690. &mov (&DWP(28,"esp"),$key_);
  691. &movdqa ($inout3,&QWP(0,"esp")); # bswap mask
  692. &movdqa ($inout0,$ivec);
  693. &mov ($key_,$key);
  694. &mov ($rounds_,$rounds);
  695. &pshufb ($ivec,$inout3);
  696. if ($inline)
  697. { &aesni_inline_generate1("enc"); }
  698. else
  699. { &call ("_aesni_encrypt1"); }
  700. &shl ($rounds_,4);
  701. &mov ($rounds,16);
  702. &movups ($in0,&QWP(0,$inp)); # load inp
  703. &paddq ($ivec,&QWP(16,"esp"));
  704. &lea ($inp,&QWP(16,$inp));
  705. &sub ($rounds,$rounds_);
  706. &lea ($key,&DWP(32,$key_,$rounds_));
  707. &mov ($rounds_,$rounds);
  708. &jmp (&label("ccm64_dec_outer"));
  709. &set_label("ccm64_dec_outer",16);
  710. &xorps ($in0,$inout0); # inp ^= E(ivec)
  711. &movdqa ($inout0,$ivec);
  712. &movups (&QWP(0,$out),$in0); # save output
  713. &lea ($out,&DWP(16,$out));
  714. &pshufb ($inout0,$inout3);
  715. &sub ($len,1);
  716. &jz (&label("ccm64_dec_break"));
  717. &$movekey ($rndkey0,&QWP(0,$key_));
  718. &mov ($rounds,$rounds_);
  719. &$movekey ($rndkey1,&QWP(16,$key_));
  720. &xorps ($in0,$rndkey0);
  721. &xorps ($inout0,$rndkey0);
  722. &xorps ($cmac,$in0); # cmac^=out
  723. &$movekey ($rndkey0,&QWP(32,$key_));
  724. &set_label("ccm64_dec2_loop");
  725. &aesenc ($inout0,$rndkey1);
  726. &aesenc ($cmac,$rndkey1);
  727. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  728. &add ($rounds,32);
  729. &aesenc ($inout0,$rndkey0);
  730. &aesenc ($cmac,$rndkey0);
  731. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  732. &jnz (&label("ccm64_dec2_loop"));
  733. &movups ($in0,&QWP(0,$inp)); # load inp
  734. &paddq ($ivec,&QWP(16,"esp"));
  735. &aesenc ($inout0,$rndkey1);
  736. &aesenc ($cmac,$rndkey1);
  737. &aesenclast ($inout0,$rndkey0);
  738. &aesenclast ($cmac,$rndkey0);
  739. &lea ($inp,&QWP(16,$inp));
  740. &jmp (&label("ccm64_dec_outer"));
  741. &set_label("ccm64_dec_break",16);
  742. &mov ($rounds,&DWP(240,$key_));
  743. &mov ($key,$key_);
  744. if ($inline)
  745. { &aesni_inline_generate1("enc",$cmac,$in0); }
  746. else
  747. { &call ("_aesni_encrypt1",$cmac); }
  748. &mov ("esp",&DWP(48,"esp"));
  749. &mov ($out,&wparam(5));
  750. &movups (&QWP(0,$out),$cmac);
  751. &pxor ("xmm0","xmm0"); # clear register bank
  752. &pxor ("xmm1","xmm1");
  753. &pxor ("xmm2","xmm2");
  754. &pxor ("xmm3","xmm3");
  755. &pxor ("xmm4","xmm4");
  756. &pxor ("xmm5","xmm5");
  757. &pxor ("xmm6","xmm6");
  758. &pxor ("xmm7","xmm7");
  759. &function_end("aesni_ccm64_decrypt_blocks");
  760. }
  761. ######################################################################
  762. # void aesni_ctr32_encrypt_blocks (const void *in, void *out,
  763. # size_t blocks, const AES_KEY *key,
  764. # const char *ivec);
  765. #
  766. # Handles only complete blocks, operates on 32-bit counter and
  767. # does not update *ivec! (see crypto/modes/ctr128.c for details)
  768. #
  769. # stack layout:
  770. # 0 pshufb mask
  771. # 16 vector addend: 0,6,6,6
  772. # 32 counter-less ivec
  773. # 48 1st triplet of counter vector
  774. # 64 2nd triplet of counter vector
  775. # 80 saved %esp
  776. &function_begin("aesni_ctr32_encrypt_blocks");
  777. &mov ($inp,&wparam(0));
  778. &mov ($out,&wparam(1));
  779. &mov ($len,&wparam(2));
  780. &mov ($key,&wparam(3));
  781. &mov ($rounds_,&wparam(4));
  782. &mov ($key_,"esp");
  783. &sub ("esp",88);
  784. &and ("esp",-16); # align stack
  785. &mov (&DWP(80,"esp"),$key_);
  786. &cmp ($len,1);
  787. &je (&label("ctr32_one_shortcut"));
  788. &movdqu ($inout5,&QWP(0,$rounds_)); # load ivec
  789. # compose byte-swap control mask for pshufb on stack
  790. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  791. &mov (&DWP(4,"esp"),0x08090a0b);
  792. &mov (&DWP(8,"esp"),0x04050607);
  793. &mov (&DWP(12,"esp"),0x00010203);
  794. # compose counter increment vector on stack
  795. &mov ($rounds,6);
  796. &xor ($key_,$key_);
  797. &mov (&DWP(16,"esp"),$rounds);
  798. &mov (&DWP(20,"esp"),$rounds);
  799. &mov (&DWP(24,"esp"),$rounds);
  800. &mov (&DWP(28,"esp"),$key_);
  801. &pextrd ($rounds_,$inout5,3); # pull 32-bit counter
  802. &pinsrd ($inout5,$key_,3); # wipe 32-bit counter
  803. &mov ($rounds,&DWP(240,$key)); # key->rounds
  804. # compose 2 vectors of 3x32-bit counters
  805. &bswap ($rounds_);
  806. &pxor ($rndkey0,$rndkey0);
  807. &pxor ($rndkey1,$rndkey1);
  808. &movdqa ($inout0,&QWP(0,"esp")); # load byte-swap mask
  809. &pinsrd ($rndkey0,$rounds_,0);
  810. &lea ($key_,&DWP(3,$rounds_));
  811. &pinsrd ($rndkey1,$key_,0);
  812. &inc ($rounds_);
  813. &pinsrd ($rndkey0,$rounds_,1);
  814. &inc ($key_);
  815. &pinsrd ($rndkey1,$key_,1);
  816. &inc ($rounds_);
  817. &pinsrd ($rndkey0,$rounds_,2);
  818. &inc ($key_);
  819. &pinsrd ($rndkey1,$key_,2);
  820. &movdqa (&QWP(48,"esp"),$rndkey0); # save 1st triplet
  821. &pshufb ($rndkey0,$inout0); # byte swap
  822. &movdqu ($inout4,&QWP(0,$key)); # key[0]
  823. &movdqa (&QWP(64,"esp"),$rndkey1); # save 2nd triplet
  824. &pshufb ($rndkey1,$inout0); # byte swap
  825. &pshufd ($inout0,$rndkey0,3<<6); # place counter to upper dword
  826. &pshufd ($inout1,$rndkey0,2<<6);
  827. &cmp ($len,6);
  828. &jb (&label("ctr32_tail"));
  829. &pxor ($inout5,$inout4); # counter-less ivec^key[0]
  830. &shl ($rounds,4);
  831. &mov ($rounds_,16);
  832. &movdqa (&QWP(32,"esp"),$inout5); # save counter-less ivec^key[0]
  833. &mov ($key_,$key); # backup $key
  834. &sub ($rounds_,$rounds); # backup twisted $rounds
  835. &lea ($key,&DWP(32,$key,$rounds));
  836. &sub ($len,6);
  837. &jmp (&label("ctr32_loop6"));
  838. &set_label("ctr32_loop6",16);
  839. # inlining _aesni_encrypt6's prologue gives ~6% improvement...
  840. &pshufd ($inout2,$rndkey0,1<<6);
  841. &movdqa ($rndkey0,&QWP(32,"esp")); # pull counter-less ivec
  842. &pshufd ($inout3,$rndkey1,3<<6);
  843. &pxor ($inout0,$rndkey0); # merge counter-less ivec
  844. &pshufd ($inout4,$rndkey1,2<<6);
  845. &pxor ($inout1,$rndkey0);
  846. &pshufd ($inout5,$rndkey1,1<<6);
  847. &$movekey ($rndkey1,&QWP(16,$key_));
  848. &pxor ($inout2,$rndkey0);
  849. &pxor ($inout3,$rndkey0);
  850. &aesenc ($inout0,$rndkey1);
  851. &pxor ($inout4,$rndkey0);
  852. &pxor ($inout5,$rndkey0);
  853. &aesenc ($inout1,$rndkey1);
  854. &$movekey ($rndkey0,&QWP(32,$key_));
  855. &mov ($rounds,$rounds_);
  856. &aesenc ($inout2,$rndkey1);
  857. &aesenc ($inout3,$rndkey1);
  858. &aesenc ($inout4,$rndkey1);
  859. &aesenc ($inout5,$rndkey1);
  860. &call (&label("_aesni_encrypt6_enter"));
  861. &movups ($rndkey1,&QWP(0,$inp));
  862. &movups ($rndkey0,&QWP(0x10,$inp));
  863. &xorps ($inout0,$rndkey1);
  864. &movups ($rndkey1,&QWP(0x20,$inp));
  865. &xorps ($inout1,$rndkey0);
  866. &movups (&QWP(0,$out),$inout0);
  867. &movdqa ($rndkey0,&QWP(16,"esp")); # load increment
  868. &xorps ($inout2,$rndkey1);
  869. &movdqa ($rndkey1,&QWP(64,"esp")); # load 2nd triplet
  870. &movups (&QWP(0x10,$out),$inout1);
  871. &movups (&QWP(0x20,$out),$inout2);
  872. &paddd ($rndkey1,$rndkey0); # 2nd triplet increment
  873. &paddd ($rndkey0,&QWP(48,"esp")); # 1st triplet increment
  874. &movdqa ($inout0,&QWP(0,"esp")); # load byte swap mask
  875. &movups ($inout1,&QWP(0x30,$inp));
  876. &movups ($inout2,&QWP(0x40,$inp));
  877. &xorps ($inout3,$inout1);
  878. &movups ($inout1,&QWP(0x50,$inp));
  879. &lea ($inp,&DWP(0x60,$inp));
  880. &movdqa (&QWP(48,"esp"),$rndkey0); # save 1st triplet
  881. &pshufb ($rndkey0,$inout0); # byte swap
  882. &xorps ($inout4,$inout2);
  883. &movups (&QWP(0x30,$out),$inout3);
  884. &xorps ($inout5,$inout1);
  885. &movdqa (&QWP(64,"esp"),$rndkey1); # save 2nd triplet
  886. &pshufb ($rndkey1,$inout0); # byte swap
  887. &movups (&QWP(0x40,$out),$inout4);
  888. &pshufd ($inout0,$rndkey0,3<<6);
  889. &movups (&QWP(0x50,$out),$inout5);
  890. &lea ($out,&DWP(0x60,$out));
  891. &pshufd ($inout1,$rndkey0,2<<6);
  892. &sub ($len,6);
  893. &jnc (&label("ctr32_loop6"));
  894. &add ($len,6);
  895. &jz (&label("ctr32_ret"));
  896. &movdqu ($inout5,&QWP(0,$key_));
  897. &mov ($key,$key_);
  898. &pxor ($inout5,&QWP(32,"esp")); # restore count-less ivec
  899. &mov ($rounds,&DWP(240,$key_)); # restore $rounds
  900. &set_label("ctr32_tail");
  901. &por ($inout0,$inout5);
  902. &cmp ($len,2);
  903. &jb (&label("ctr32_one"));
  904. &pshufd ($inout2,$rndkey0,1<<6);
  905. &por ($inout1,$inout5);
  906. &je (&label("ctr32_two"));
  907. &pshufd ($inout3,$rndkey1,3<<6);
  908. &por ($inout2,$inout5);
  909. &cmp ($len,4);
  910. &jb (&label("ctr32_three"));
  911. &pshufd ($inout4,$rndkey1,2<<6);
  912. &por ($inout3,$inout5);
  913. &je (&label("ctr32_four"));
  914. &por ($inout4,$inout5);
  915. &call ("_aesni_encrypt6");
  916. &movups ($rndkey1,&QWP(0,$inp));
  917. &movups ($rndkey0,&QWP(0x10,$inp));
  918. &xorps ($inout0,$rndkey1);
  919. &movups ($rndkey1,&QWP(0x20,$inp));
  920. &xorps ($inout1,$rndkey0);
  921. &movups ($rndkey0,&QWP(0x30,$inp));
  922. &xorps ($inout2,$rndkey1);
  923. &movups ($rndkey1,&QWP(0x40,$inp));
  924. &xorps ($inout3,$rndkey0);
  925. &movups (&QWP(0,$out),$inout0);
  926. &xorps ($inout4,$rndkey1);
  927. &movups (&QWP(0x10,$out),$inout1);
  928. &movups (&QWP(0x20,$out),$inout2);
  929. &movups (&QWP(0x30,$out),$inout3);
  930. &movups (&QWP(0x40,$out),$inout4);
  931. &jmp (&label("ctr32_ret"));
  932. &set_label("ctr32_one_shortcut",16);
  933. &movups ($inout0,&QWP(0,$rounds_)); # load ivec
  934. &mov ($rounds,&DWP(240,$key));
  935. &set_label("ctr32_one");
  936. if ($inline)
  937. { &aesni_inline_generate1("enc"); }
  938. else
  939. { &call ("_aesni_encrypt1"); }
  940. &movups ($in0,&QWP(0,$inp));
  941. &xorps ($in0,$inout0);
  942. &movups (&QWP(0,$out),$in0);
  943. &jmp (&label("ctr32_ret"));
  944. &set_label("ctr32_two",16);
  945. &call ("_aesni_encrypt2");
  946. &movups ($inout3,&QWP(0,$inp));
  947. &movups ($inout4,&QWP(0x10,$inp));
  948. &xorps ($inout0,$inout3);
  949. &xorps ($inout1,$inout4);
  950. &movups (&QWP(0,$out),$inout0);
  951. &movups (&QWP(0x10,$out),$inout1);
  952. &jmp (&label("ctr32_ret"));
  953. &set_label("ctr32_three",16);
  954. &call ("_aesni_encrypt3");
  955. &movups ($inout3,&QWP(0,$inp));
  956. &movups ($inout4,&QWP(0x10,$inp));
  957. &xorps ($inout0,$inout3);
  958. &movups ($inout5,&QWP(0x20,$inp));
  959. &xorps ($inout1,$inout4);
  960. &movups (&QWP(0,$out),$inout0);
  961. &xorps ($inout2,$inout5);
  962. &movups (&QWP(0x10,$out),$inout1);
  963. &movups (&QWP(0x20,$out),$inout2);
  964. &jmp (&label("ctr32_ret"));
  965. &set_label("ctr32_four",16);
  966. &call ("_aesni_encrypt4");
  967. &movups ($inout4,&QWP(0,$inp));
  968. &movups ($inout5,&QWP(0x10,$inp));
  969. &movups ($rndkey1,&QWP(0x20,$inp));
  970. &xorps ($inout0,$inout4);
  971. &movups ($rndkey0,&QWP(0x30,$inp));
  972. &xorps ($inout1,$inout5);
  973. &movups (&QWP(0,$out),$inout0);
  974. &xorps ($inout2,$rndkey1);
  975. &movups (&QWP(0x10,$out),$inout1);
  976. &xorps ($inout3,$rndkey0);
  977. &movups (&QWP(0x20,$out),$inout2);
  978. &movups (&QWP(0x30,$out),$inout3);
  979. &set_label("ctr32_ret");
  980. &pxor ("xmm0","xmm0"); # clear register bank
  981. &pxor ("xmm1","xmm1");
  982. &pxor ("xmm2","xmm2");
  983. &pxor ("xmm3","xmm3");
  984. &pxor ("xmm4","xmm4");
  985. &movdqa (&QWP(32,"esp"),"xmm0"); # clear stack
  986. &pxor ("xmm5","xmm5");
  987. &movdqa (&QWP(48,"esp"),"xmm0");
  988. &pxor ("xmm6","xmm6");
  989. &movdqa (&QWP(64,"esp"),"xmm0");
  990. &pxor ("xmm7","xmm7");
  991. &mov ("esp",&DWP(80,"esp"));
  992. &function_end("aesni_ctr32_encrypt_blocks");
  993. ######################################################################
  994. # void aesni_xts_[en|de]crypt(const char *inp,char *out,size_t len,
  995. # const AES_KEY *key1, const AES_KEY *key2
  996. # const unsigned char iv[16]);
  997. #
  998. { my ($tweak,$twtmp,$twres,$twmask)=($rndkey1,$rndkey0,$inout0,$inout1);
  999. &function_begin("aesni_xts_encrypt");
  1000. &mov ($key,&wparam(4)); # key2
  1001. &mov ($inp,&wparam(5)); # clear-text tweak
  1002. &mov ($rounds,&DWP(240,$key)); # key2->rounds
  1003. &movups ($inout0,&QWP(0,$inp));
  1004. if ($inline)
  1005. { &aesni_inline_generate1("enc"); }
  1006. else
  1007. { &call ("_aesni_encrypt1"); }
  1008. &mov ($inp,&wparam(0));
  1009. &mov ($out,&wparam(1));
  1010. &mov ($len,&wparam(2));
  1011. &mov ($key,&wparam(3)); # key1
  1012. &mov ($key_,"esp");
  1013. &sub ("esp",16*7+8);
  1014. &mov ($rounds,&DWP(240,$key)); # key1->rounds
  1015. &and ("esp",-16); # align stack
  1016. &mov (&DWP(16*6+0,"esp"),0x87); # compose the magic constant
  1017. &mov (&DWP(16*6+4,"esp"),0);
  1018. &mov (&DWP(16*6+8,"esp"),1);
  1019. &mov (&DWP(16*6+12,"esp"),0);
  1020. &mov (&DWP(16*7+0,"esp"),$len); # save original $len
  1021. &mov (&DWP(16*7+4,"esp"),$key_); # save original %esp
  1022. &movdqa ($tweak,$inout0);
  1023. &pxor ($twtmp,$twtmp);
  1024. &movdqa ($twmask,&QWP(6*16,"esp")); # 0x0...010...87
  1025. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1026. &and ($len,-16);
  1027. &mov ($key_,$key); # backup $key
  1028. &mov ($rounds_,$rounds); # backup $rounds
  1029. &sub ($len,16*6);
  1030. &jc (&label("xts_enc_short"));
  1031. &shl ($rounds,4);
  1032. &mov ($rounds_,16);
  1033. &sub ($rounds_,$rounds);
  1034. &lea ($key,&DWP(32,$key,$rounds));
  1035. &jmp (&label("xts_enc_loop6"));
  1036. &set_label("xts_enc_loop6",16);
  1037. for ($i=0;$i<4;$i++) {
  1038. &pshufd ($twres,$twtmp,0x13);
  1039. &pxor ($twtmp,$twtmp);
  1040. &movdqa (&QWP(16*$i,"esp"),$tweak);
  1041. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1042. &pand ($twres,$twmask); # isolate carry and residue
  1043. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1044. &pxor ($tweak,$twres);
  1045. }
  1046. &pshufd ($inout5,$twtmp,0x13);
  1047. &movdqa (&QWP(16*$i++,"esp"),$tweak);
  1048. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1049. &$movekey ($rndkey0,&QWP(0,$key_));
  1050. &pand ($inout5,$twmask); # isolate carry and residue
  1051. &movups ($inout0,&QWP(0,$inp)); # load input
  1052. &pxor ($inout5,$tweak);
  1053. # inline _aesni_encrypt6 prologue and flip xor with tweak and key[0]
  1054. &mov ($rounds,$rounds_); # restore $rounds
  1055. &movdqu ($inout1,&QWP(16*1,$inp));
  1056. &xorps ($inout0,$rndkey0); # input^=rndkey[0]
  1057. &movdqu ($inout2,&QWP(16*2,$inp));
  1058. &pxor ($inout1,$rndkey0);
  1059. &movdqu ($inout3,&QWP(16*3,$inp));
  1060. &pxor ($inout2,$rndkey0);
  1061. &movdqu ($inout4,&QWP(16*4,$inp));
  1062. &pxor ($inout3,$rndkey0);
  1063. &movdqu ($rndkey1,&QWP(16*5,$inp));
  1064. &pxor ($inout4,$rndkey0);
  1065. &lea ($inp,&DWP(16*6,$inp));
  1066. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1067. &movdqa (&QWP(16*$i,"esp"),$inout5); # save last tweak
  1068. &pxor ($inout5,$rndkey1);
  1069. &$movekey ($rndkey1,&QWP(16,$key_));
  1070. &pxor ($inout1,&QWP(16*1,"esp"));
  1071. &pxor ($inout2,&QWP(16*2,"esp"));
  1072. &aesenc ($inout0,$rndkey1);
  1073. &pxor ($inout3,&QWP(16*3,"esp"));
  1074. &pxor ($inout4,&QWP(16*4,"esp"));
  1075. &aesenc ($inout1,$rndkey1);
  1076. &pxor ($inout5,$rndkey0);
  1077. &$movekey ($rndkey0,&QWP(32,$key_));
  1078. &aesenc ($inout2,$rndkey1);
  1079. &aesenc ($inout3,$rndkey1);
  1080. &aesenc ($inout4,$rndkey1);
  1081. &aesenc ($inout5,$rndkey1);
  1082. &call (&label("_aesni_encrypt6_enter"));
  1083. &movdqa ($tweak,&QWP(16*5,"esp")); # last tweak
  1084. &pxor ($twtmp,$twtmp);
  1085. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1086. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1087. &xorps ($inout1,&QWP(16*1,"esp"));
  1088. &movups (&QWP(16*0,$out),$inout0); # write output
  1089. &xorps ($inout2,&QWP(16*2,"esp"));
  1090. &movups (&QWP(16*1,$out),$inout1);
  1091. &xorps ($inout3,&QWP(16*3,"esp"));
  1092. &movups (&QWP(16*2,$out),$inout2);
  1093. &xorps ($inout4,&QWP(16*4,"esp"));
  1094. &movups (&QWP(16*3,$out),$inout3);
  1095. &xorps ($inout5,$tweak);
  1096. &movups (&QWP(16*4,$out),$inout4);
  1097. &pshufd ($twres,$twtmp,0x13);
  1098. &movups (&QWP(16*5,$out),$inout5);
  1099. &lea ($out,&DWP(16*6,$out));
  1100. &movdqa ($twmask,&QWP(16*6,"esp")); # 0x0...010...87
  1101. &pxor ($twtmp,$twtmp);
  1102. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1103. &pand ($twres,$twmask); # isolate carry and residue
  1104. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1105. &pxor ($tweak,$twres);
  1106. &sub ($len,16*6);
  1107. &jnc (&label("xts_enc_loop6"));
  1108. &mov ($rounds,&DWP(240,$key_)); # restore $rounds
  1109. &mov ($key,$key_); # restore $key
  1110. &mov ($rounds_,$rounds);
  1111. &set_label("xts_enc_short");
  1112. &add ($len,16*6);
  1113. &jz (&label("xts_enc_done6x"));
  1114. &movdqa ($inout3,$tweak); # put aside previous tweak
  1115. &cmp ($len,0x20);
  1116. &jb (&label("xts_enc_one"));
  1117. &pshufd ($twres,$twtmp,0x13);
  1118. &pxor ($twtmp,$twtmp);
  1119. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1120. &pand ($twres,$twmask); # isolate carry and residue
  1121. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1122. &pxor ($tweak,$twres);
  1123. &je (&label("xts_enc_two"));
  1124. &pshufd ($twres,$twtmp,0x13);
  1125. &pxor ($twtmp,$twtmp);
  1126. &movdqa ($inout4,$tweak); # put aside previous tweak
  1127. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1128. &pand ($twres,$twmask); # isolate carry and residue
  1129. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1130. &pxor ($tweak,$twres);
  1131. &cmp ($len,0x40);
  1132. &jb (&label("xts_enc_three"));
  1133. &pshufd ($twres,$twtmp,0x13);
  1134. &pxor ($twtmp,$twtmp);
  1135. &movdqa ($inout5,$tweak); # put aside previous tweak
  1136. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1137. &pand ($twres,$twmask); # isolate carry and residue
  1138. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1139. &pxor ($tweak,$twres);
  1140. &movdqa (&QWP(16*0,"esp"),$inout3);
  1141. &movdqa (&QWP(16*1,"esp"),$inout4);
  1142. &je (&label("xts_enc_four"));
  1143. &movdqa (&QWP(16*2,"esp"),$inout5);
  1144. &pshufd ($inout5,$twtmp,0x13);
  1145. &movdqa (&QWP(16*3,"esp"),$tweak);
  1146. &paddq ($tweak,$tweak); # &psllq($inout0,1);
  1147. &pand ($inout5,$twmask); # isolate carry and residue
  1148. &pxor ($inout5,$tweak);
  1149. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1150. &movdqu ($inout1,&QWP(16*1,$inp));
  1151. &movdqu ($inout2,&QWP(16*2,$inp));
  1152. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1153. &movdqu ($inout3,&QWP(16*3,$inp));
  1154. &pxor ($inout1,&QWP(16*1,"esp"));
  1155. &movdqu ($inout4,&QWP(16*4,$inp));
  1156. &pxor ($inout2,&QWP(16*2,"esp"));
  1157. &lea ($inp,&DWP(16*5,$inp));
  1158. &pxor ($inout3,&QWP(16*3,"esp"));
  1159. &movdqa (&QWP(16*4,"esp"),$inout5); # save last tweak
  1160. &pxor ($inout4,$inout5);
  1161. &call ("_aesni_encrypt6");
  1162. &movaps ($tweak,&QWP(16*4,"esp")); # last tweak
  1163. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1164. &xorps ($inout1,&QWP(16*1,"esp"));
  1165. &xorps ($inout2,&QWP(16*2,"esp"));
  1166. &movups (&QWP(16*0,$out),$inout0); # write output
  1167. &xorps ($inout3,&QWP(16*3,"esp"));
  1168. &movups (&QWP(16*1,$out),$inout1);
  1169. &xorps ($inout4,$tweak);
  1170. &movups (&QWP(16*2,$out),$inout2);
  1171. &movups (&QWP(16*3,$out),$inout3);
  1172. &movups (&QWP(16*4,$out),$inout4);
  1173. &lea ($out,&DWP(16*5,$out));
  1174. &jmp (&label("xts_enc_done"));
  1175. &set_label("xts_enc_one",16);
  1176. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1177. &lea ($inp,&DWP(16*1,$inp));
  1178. &xorps ($inout0,$inout3); # input^=tweak
  1179. if ($inline)
  1180. { &aesni_inline_generate1("enc"); }
  1181. else
  1182. { &call ("_aesni_encrypt1"); }
  1183. &xorps ($inout0,$inout3); # output^=tweak
  1184. &movups (&QWP(16*0,$out),$inout0); # write output
  1185. &lea ($out,&DWP(16*1,$out));
  1186. &movdqa ($tweak,$inout3); # last tweak
  1187. &jmp (&label("xts_enc_done"));
  1188. &set_label("xts_enc_two",16);
  1189. &movaps ($inout4,$tweak); # put aside last tweak
  1190. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1191. &movups ($inout1,&QWP(16*1,$inp));
  1192. &lea ($inp,&DWP(16*2,$inp));
  1193. &xorps ($inout0,$inout3); # input^=tweak
  1194. &xorps ($inout1,$inout4);
  1195. &call ("_aesni_encrypt2");
  1196. &xorps ($inout0,$inout3); # output^=tweak
  1197. &xorps ($inout1,$inout4);
  1198. &movups (&QWP(16*0,$out),$inout0); # write output
  1199. &movups (&QWP(16*1,$out),$inout1);
  1200. &lea ($out,&DWP(16*2,$out));
  1201. &movdqa ($tweak,$inout4); # last tweak
  1202. &jmp (&label("xts_enc_done"));
  1203. &set_label("xts_enc_three",16);
  1204. &movaps ($inout5,$tweak); # put aside last tweak
  1205. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1206. &movups ($inout1,&QWP(16*1,$inp));
  1207. &movups ($inout2,&QWP(16*2,$inp));
  1208. &lea ($inp,&DWP(16*3,$inp));
  1209. &xorps ($inout0,$inout3); # input^=tweak
  1210. &xorps ($inout1,$inout4);
  1211. &xorps ($inout2,$inout5);
  1212. &call ("_aesni_encrypt3");
  1213. &xorps ($inout0,$inout3); # output^=tweak
  1214. &xorps ($inout1,$inout4);
  1215. &xorps ($inout2,$inout5);
  1216. &movups (&QWP(16*0,$out),$inout0); # write output
  1217. &movups (&QWP(16*1,$out),$inout1);
  1218. &movups (&QWP(16*2,$out),$inout2);
  1219. &lea ($out,&DWP(16*3,$out));
  1220. &movdqa ($tweak,$inout5); # last tweak
  1221. &jmp (&label("xts_enc_done"));
  1222. &set_label("xts_enc_four",16);
  1223. &movaps ($inout4,$tweak); # put aside last tweak
  1224. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1225. &movups ($inout1,&QWP(16*1,$inp));
  1226. &movups ($inout2,&QWP(16*2,$inp));
  1227. &xorps ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1228. &movups ($inout3,&QWP(16*3,$inp));
  1229. &lea ($inp,&DWP(16*4,$inp));
  1230. &xorps ($inout1,&QWP(16*1,"esp"));
  1231. &xorps ($inout2,$inout5);
  1232. &xorps ($inout3,$inout4);
  1233. &call ("_aesni_encrypt4");
  1234. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1235. &xorps ($inout1,&QWP(16*1,"esp"));
  1236. &xorps ($inout2,$inout5);
  1237. &movups (&QWP(16*0,$out),$inout0); # write output
  1238. &xorps ($inout3,$inout4);
  1239. &movups (&QWP(16*1,$out),$inout1);
  1240. &movups (&QWP(16*2,$out),$inout2);
  1241. &movups (&QWP(16*3,$out),$inout3);
  1242. &lea ($out,&DWP(16*4,$out));
  1243. &movdqa ($tweak,$inout4); # last tweak
  1244. &jmp (&label("xts_enc_done"));
  1245. &set_label("xts_enc_done6x",16); # $tweak is pre-calculated
  1246. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1247. &and ($len,15);
  1248. &jz (&label("xts_enc_ret"));
  1249. &movdqa ($inout3,$tweak);
  1250. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1251. &jmp (&label("xts_enc_steal"));
  1252. &set_label("xts_enc_done",16);
  1253. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1254. &pxor ($twtmp,$twtmp);
  1255. &and ($len,15);
  1256. &jz (&label("xts_enc_ret"));
  1257. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1258. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1259. &pshufd ($inout3,$twtmp,0x13);
  1260. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1261. &pand ($inout3,&QWP(16*6,"esp")); # isolate carry and residue
  1262. &pxor ($inout3,$tweak);
  1263. &set_label("xts_enc_steal");
  1264. &movz ($rounds,&BP(0,$inp));
  1265. &movz ($key,&BP(-16,$out));
  1266. &lea ($inp,&DWP(1,$inp));
  1267. &mov (&BP(-16,$out),&LB($rounds));
  1268. &mov (&BP(0,$out),&LB($key));
  1269. &lea ($out,&DWP(1,$out));
  1270. &sub ($len,1);
  1271. &jnz (&label("xts_enc_steal"));
  1272. &sub ($out,&DWP(16*7+0,"esp")); # rewind $out
  1273. &mov ($key,$key_); # restore $key
  1274. &mov ($rounds,$rounds_); # restore $rounds
  1275. &movups ($inout0,&QWP(-16,$out)); # load input
  1276. &xorps ($inout0,$inout3); # input^=tweak
  1277. if ($inline)
  1278. { &aesni_inline_generate1("enc"); }
  1279. else
  1280. { &call ("_aesni_encrypt1"); }
  1281. &xorps ($inout0,$inout3); # output^=tweak
  1282. &movups (&QWP(-16,$out),$inout0); # write output
  1283. &set_label("xts_enc_ret");
  1284. &pxor ("xmm0","xmm0"); # clear register bank
  1285. &pxor ("xmm1","xmm1");
  1286. &pxor ("xmm2","xmm2");
  1287. &movdqa (&QWP(16*0,"esp"),"xmm0"); # clear stack
  1288. &pxor ("xmm3","xmm3");
  1289. &movdqa (&QWP(16*1,"esp"),"xmm0");
  1290. &pxor ("xmm4","xmm4");
  1291. &movdqa (&QWP(16*2,"esp"),"xmm0");
  1292. &pxor ("xmm5","xmm5");
  1293. &movdqa (&QWP(16*3,"esp"),"xmm0");
  1294. &pxor ("xmm6","xmm6");
  1295. &movdqa (&QWP(16*4,"esp"),"xmm0");
  1296. &pxor ("xmm7","xmm7");
  1297. &movdqa (&QWP(16*5,"esp"),"xmm0");
  1298. &mov ("esp",&DWP(16*7+4,"esp")); # restore %esp
  1299. &function_end("aesni_xts_encrypt");
  1300. &function_begin("aesni_xts_decrypt");
  1301. &mov ($key,&wparam(4)); # key2
  1302. &mov ($inp,&wparam(5)); # clear-text tweak
  1303. &mov ($rounds,&DWP(240,$key)); # key2->rounds
  1304. &movups ($inout0,&QWP(0,$inp));
  1305. if ($inline)
  1306. { &aesni_inline_generate1("enc"); }
  1307. else
  1308. { &call ("_aesni_encrypt1"); }
  1309. &mov ($inp,&wparam(0));
  1310. &mov ($out,&wparam(1));
  1311. &mov ($len,&wparam(2));
  1312. &mov ($key,&wparam(3)); # key1
  1313. &mov ($key_,"esp");
  1314. &sub ("esp",16*7+8);
  1315. &and ("esp",-16); # align stack
  1316. &xor ($rounds_,$rounds_); # if(len%16) len-=16;
  1317. &test ($len,15);
  1318. &setnz (&LB($rounds_));
  1319. &shl ($rounds_,4);
  1320. &sub ($len,$rounds_);
  1321. &mov (&DWP(16*6+0,"esp"),0x87); # compose the magic constant
  1322. &mov (&DWP(16*6+4,"esp"),0);
  1323. &mov (&DWP(16*6+8,"esp"),1);
  1324. &mov (&DWP(16*6+12,"esp"),0);
  1325. &mov (&DWP(16*7+0,"esp"),$len); # save original $len
  1326. &mov (&DWP(16*7+4,"esp"),$key_); # save original %esp
  1327. &mov ($rounds,&DWP(240,$key)); # key1->rounds
  1328. &mov ($key_,$key); # backup $key
  1329. &mov ($rounds_,$rounds); # backup $rounds
  1330. &movdqa ($tweak,$inout0);
  1331. &pxor ($twtmp,$twtmp);
  1332. &movdqa ($twmask,&QWP(6*16,"esp")); # 0x0...010...87
  1333. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1334. &and ($len,-16);
  1335. &sub ($len,16*6);
  1336. &jc (&label("xts_dec_short"));
  1337. &shl ($rounds,4);
  1338. &mov ($rounds_,16);
  1339. &sub ($rounds_,$rounds);
  1340. &lea ($key,&DWP(32,$key,$rounds));
  1341. &jmp (&label("xts_dec_loop6"));
  1342. &set_label("xts_dec_loop6",16);
  1343. for ($i=0;$i<4;$i++) {
  1344. &pshufd ($twres,$twtmp,0x13);
  1345. &pxor ($twtmp,$twtmp);
  1346. &movdqa (&QWP(16*$i,"esp"),$tweak);
  1347. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1348. &pand ($twres,$twmask); # isolate carry and residue
  1349. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1350. &pxor ($tweak,$twres);
  1351. }
  1352. &pshufd ($inout5,$twtmp,0x13);
  1353. &movdqa (&QWP(16*$i++,"esp"),$tweak);
  1354. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1355. &$movekey ($rndkey0,&QWP(0,$key_));
  1356. &pand ($inout5,$twmask); # isolate carry and residue
  1357. &movups ($inout0,&QWP(0,$inp)); # load input
  1358. &pxor ($inout5,$tweak);
  1359. # inline _aesni_encrypt6 prologue and flip xor with tweak and key[0]
  1360. &mov ($rounds,$rounds_);
  1361. &movdqu ($inout1,&QWP(16*1,$inp));
  1362. &xorps ($inout0,$rndkey0); # input^=rndkey[0]
  1363. &movdqu ($inout2,&QWP(16*2,$inp));
  1364. &pxor ($inout1,$rndkey0);
  1365. &movdqu ($inout3,&QWP(16*3,$inp));
  1366. &pxor ($inout2,$rndkey0);
  1367. &movdqu ($inout4,&QWP(16*4,$inp));
  1368. &pxor ($inout3,$rndkey0);
  1369. &movdqu ($rndkey1,&QWP(16*5,$inp));
  1370. &pxor ($inout4,$rndkey0);
  1371. &lea ($inp,&DWP(16*6,$inp));
  1372. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1373. &movdqa (&QWP(16*$i,"esp"),$inout5); # save last tweak
  1374. &pxor ($inout5,$rndkey1);
  1375. &$movekey ($rndkey1,&QWP(16,$key_));
  1376. &pxor ($inout1,&QWP(16*1,"esp"));
  1377. &pxor ($inout2,&QWP(16*2,"esp"));
  1378. &aesdec ($inout0,$rndkey1);
  1379. &pxor ($inout3,&QWP(16*3,"esp"));
  1380. &pxor ($inout4,&QWP(16*4,"esp"));
  1381. &aesdec ($inout1,$rndkey1);
  1382. &pxor ($inout5,$rndkey0);
  1383. &$movekey ($rndkey0,&QWP(32,$key_));
  1384. &aesdec ($inout2,$rndkey1);
  1385. &aesdec ($inout3,$rndkey1);
  1386. &aesdec ($inout4,$rndkey1);
  1387. &aesdec ($inout5,$rndkey1);
  1388. &call (&label("_aesni_decrypt6_enter"));
  1389. &movdqa ($tweak,&QWP(16*5,"esp")); # last tweak
  1390. &pxor ($twtmp,$twtmp);
  1391. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1392. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1393. &xorps ($inout1,&QWP(16*1,"esp"));
  1394. &movups (&QWP(16*0,$out),$inout0); # write output
  1395. &xorps ($inout2,&QWP(16*2,"esp"));
  1396. &movups (&QWP(16*1,$out),$inout1);
  1397. &xorps ($inout3,&QWP(16*3,"esp"));
  1398. &movups (&QWP(16*2,$out),$inout2);
  1399. &xorps ($inout4,&QWP(16*4,"esp"));
  1400. &movups (&QWP(16*3,$out),$inout3);
  1401. &xorps ($inout5,$tweak);
  1402. &movups (&QWP(16*4,$out),$inout4);
  1403. &pshufd ($twres,$twtmp,0x13);
  1404. &movups (&QWP(16*5,$out),$inout5);
  1405. &lea ($out,&DWP(16*6,$out));
  1406. &movdqa ($twmask,&QWP(16*6,"esp")); # 0x0...010...87
  1407. &pxor ($twtmp,$twtmp);
  1408. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1409. &pand ($twres,$twmask); # isolate carry and residue
  1410. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1411. &pxor ($tweak,$twres);
  1412. &sub ($len,16*6);
  1413. &jnc (&label("xts_dec_loop6"));
  1414. &mov ($rounds,&DWP(240,$key_)); # restore $rounds
  1415. &mov ($key,$key_); # restore $key
  1416. &mov ($rounds_,$rounds);
  1417. &set_label("xts_dec_short");
  1418. &add ($len,16*6);
  1419. &jz (&label("xts_dec_done6x"));
  1420. &movdqa ($inout3,$tweak); # put aside previous tweak
  1421. &cmp ($len,0x20);
  1422. &jb (&label("xts_dec_one"));
  1423. &pshufd ($twres,$twtmp,0x13);
  1424. &pxor ($twtmp,$twtmp);
  1425. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1426. &pand ($twres,$twmask); # isolate carry and residue
  1427. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1428. &pxor ($tweak,$twres);
  1429. &je (&label("xts_dec_two"));
  1430. &pshufd ($twres,$twtmp,0x13);
  1431. &pxor ($twtmp,$twtmp);
  1432. &movdqa ($inout4,$tweak); # put aside previous tweak
  1433. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1434. &pand ($twres,$twmask); # isolate carry and residue
  1435. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1436. &pxor ($tweak,$twres);
  1437. &cmp ($len,0x40);
  1438. &jb (&label("xts_dec_three"));
  1439. &pshufd ($twres,$twtmp,0x13);
  1440. &pxor ($twtmp,$twtmp);
  1441. &movdqa ($inout5,$tweak); # put aside previous tweak
  1442. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1443. &pand ($twres,$twmask); # isolate carry and residue
  1444. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1445. &pxor ($tweak,$twres);
  1446. &movdqa (&QWP(16*0,"esp"),$inout3);
  1447. &movdqa (&QWP(16*1,"esp"),$inout4);
  1448. &je (&label("xts_dec_four"));
  1449. &movdqa (&QWP(16*2,"esp"),$inout5);
  1450. &pshufd ($inout5,$twtmp,0x13);
  1451. &movdqa (&QWP(16*3,"esp"),$tweak);
  1452. &paddq ($tweak,$tweak); # &psllq($inout0,1);
  1453. &pand ($inout5,$twmask); # isolate carry and residue
  1454. &pxor ($inout5,$tweak);
  1455. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1456. &movdqu ($inout1,&QWP(16*1,$inp));
  1457. &movdqu ($inout2,&QWP(16*2,$inp));
  1458. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1459. &movdqu ($inout3,&QWP(16*3,$inp));
  1460. &pxor ($inout1,&QWP(16*1,"esp"));
  1461. &movdqu ($inout4,&QWP(16*4,$inp));
  1462. &pxor ($inout2,&QWP(16*2,"esp"));
  1463. &lea ($inp,&DWP(16*5,$inp));
  1464. &pxor ($inout3,&QWP(16*3,"esp"));
  1465. &movdqa (&QWP(16*4,"esp"),$inout5); # save last tweak
  1466. &pxor ($inout4,$inout5);
  1467. &call ("_aesni_decrypt6");
  1468. &movaps ($tweak,&QWP(16*4,"esp")); # last tweak
  1469. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1470. &xorps ($inout1,&QWP(16*1,"esp"));
  1471. &xorps ($inout2,&QWP(16*2,"esp"));
  1472. &movups (&QWP(16*0,$out),$inout0); # write output
  1473. &xorps ($inout3,&QWP(16*3,"esp"));
  1474. &movups (&QWP(16*1,$out),$inout1);
  1475. &xorps ($inout4,$tweak);
  1476. &movups (&QWP(16*2,$out),$inout2);
  1477. &movups (&QWP(16*3,$out),$inout3);
  1478. &movups (&QWP(16*4,$out),$inout4);
  1479. &lea ($out,&DWP(16*5,$out));
  1480. &jmp (&label("xts_dec_done"));
  1481. &set_label("xts_dec_one",16);
  1482. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1483. &lea ($inp,&DWP(16*1,$inp));
  1484. &xorps ($inout0,$inout3); # input^=tweak
  1485. if ($inline)
  1486. { &aesni_inline_generate1("dec"); }
  1487. else
  1488. { &call ("_aesni_decrypt1"); }
  1489. &xorps ($inout0,$inout3); # output^=tweak
  1490. &movups (&QWP(16*0,$out),$inout0); # write output
  1491. &lea ($out,&DWP(16*1,$out));
  1492. &movdqa ($tweak,$inout3); # last tweak
  1493. &jmp (&label("xts_dec_done"));
  1494. &set_label("xts_dec_two",16);
  1495. &movaps ($inout4,$tweak); # put aside last tweak
  1496. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1497. &movups ($inout1,&QWP(16*1,$inp));
  1498. &lea ($inp,&DWP(16*2,$inp));
  1499. &xorps ($inout0,$inout3); # input^=tweak
  1500. &xorps ($inout1,$inout4);
  1501. &call ("_aesni_decrypt2");
  1502. &xorps ($inout0,$inout3); # output^=tweak
  1503. &xorps ($inout1,$inout4);
  1504. &movups (&QWP(16*0,$out),$inout0); # write output
  1505. &movups (&QWP(16*1,$out),$inout1);
  1506. &lea ($out,&DWP(16*2,$out));
  1507. &movdqa ($tweak,$inout4); # last tweak
  1508. &jmp (&label("xts_dec_done"));
  1509. &set_label("xts_dec_three",16);
  1510. &movaps ($inout5,$tweak); # put aside last tweak
  1511. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1512. &movups ($inout1,&QWP(16*1,$inp));
  1513. &movups ($inout2,&QWP(16*2,$inp));
  1514. &lea ($inp,&DWP(16*3,$inp));
  1515. &xorps ($inout0,$inout3); # input^=tweak
  1516. &xorps ($inout1,$inout4);
  1517. &xorps ($inout2,$inout5);
  1518. &call ("_aesni_decrypt3");
  1519. &xorps ($inout0,$inout3); # output^=tweak
  1520. &xorps ($inout1,$inout4);
  1521. &xorps ($inout2,$inout5);
  1522. &movups (&QWP(16*0,$out),$inout0); # write output
  1523. &movups (&QWP(16*1,$out),$inout1);
  1524. &movups (&QWP(16*2,$out),$inout2);
  1525. &lea ($out,&DWP(16*3,$out));
  1526. &movdqa ($tweak,$inout5); # last tweak
  1527. &jmp (&label("xts_dec_done"));
  1528. &set_label("xts_dec_four",16);
  1529. &movaps ($inout4,$tweak); # put aside last tweak
  1530. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1531. &movups ($inout1,&QWP(16*1,$inp));
  1532. &movups ($inout2,&QWP(16*2,$inp));
  1533. &xorps ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1534. &movups ($inout3,&QWP(16*3,$inp));
  1535. &lea ($inp,&DWP(16*4,$inp));
  1536. &xorps ($inout1,&QWP(16*1,"esp"));
  1537. &xorps ($inout2,$inout5);
  1538. &xorps ($inout3,$inout4);
  1539. &call ("_aesni_decrypt4");
  1540. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1541. &xorps ($inout1,&QWP(16*1,"esp"));
  1542. &xorps ($inout2,$inout5);
  1543. &movups (&QWP(16*0,$out),$inout0); # write output
  1544. &xorps ($inout3,$inout4);
  1545. &movups (&QWP(16*1,$out),$inout1);
  1546. &movups (&QWP(16*2,$out),$inout2);
  1547. &movups (&QWP(16*3,$out),$inout3);
  1548. &lea ($out,&DWP(16*4,$out));
  1549. &movdqa ($tweak,$inout4); # last tweak
  1550. &jmp (&label("xts_dec_done"));
  1551. &set_label("xts_dec_done6x",16); # $tweak is pre-calculated
  1552. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1553. &and ($len,15);
  1554. &jz (&label("xts_dec_ret"));
  1555. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1556. &jmp (&label("xts_dec_only_one_more"));
  1557. &set_label("xts_dec_done",16);
  1558. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1559. &pxor ($twtmp,$twtmp);
  1560. &and ($len,15);
  1561. &jz (&label("xts_dec_ret"));
  1562. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1563. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1564. &pshufd ($twres,$twtmp,0x13);
  1565. &pxor ($twtmp,$twtmp);
  1566. &movdqa ($twmask,&QWP(16*6,"esp"));
  1567. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1568. &pand ($twres,$twmask); # isolate carry and residue
  1569. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1570. &pxor ($tweak,$twres);
  1571. &set_label("xts_dec_only_one_more");
  1572. &pshufd ($inout3,$twtmp,0x13);
  1573. &movdqa ($inout4,$tweak); # put aside previous tweak
  1574. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1575. &pand ($inout3,$twmask); # isolate carry and residue
  1576. &pxor ($inout3,$tweak);
  1577. &mov ($key,$key_); # restore $key
  1578. &mov ($rounds,$rounds_); # restore $rounds
  1579. &movups ($inout0,&QWP(0,$inp)); # load input
  1580. &xorps ($inout0,$inout3); # input^=tweak
  1581. if ($inline)
  1582. { &aesni_inline_generate1("dec"); }
  1583. else
  1584. { &call ("_aesni_decrypt1"); }
  1585. &xorps ($inout0,$inout3); # output^=tweak
  1586. &movups (&QWP(0,$out),$inout0); # write output
  1587. &set_label("xts_dec_steal");
  1588. &movz ($rounds,&BP(16,$inp));
  1589. &movz ($key,&BP(0,$out));
  1590. &lea ($inp,&DWP(1,$inp));
  1591. &mov (&BP(0,$out),&LB($rounds));
  1592. &mov (&BP(16,$out),&LB($key));
  1593. &lea ($out,&DWP(1,$out));
  1594. &sub ($len,1);
  1595. &jnz (&label("xts_dec_steal"));
  1596. &sub ($out,&DWP(16*7+0,"esp")); # rewind $out
  1597. &mov ($key,$key_); # restore $key
  1598. &mov ($rounds,$rounds_); # restore $rounds
  1599. &movups ($inout0,&QWP(0,$out)); # load input
  1600. &xorps ($inout0,$inout4); # input^=tweak
  1601. if ($inline)
  1602. { &aesni_inline_generate1("dec"); }
  1603. else
  1604. { &call ("_aesni_decrypt1"); }
  1605. &xorps ($inout0,$inout4); # output^=tweak
  1606. &movups (&QWP(0,$out),$inout0); # write output
  1607. &set_label("xts_dec_ret");
  1608. &pxor ("xmm0","xmm0"); # clear register bank
  1609. &pxor ("xmm1","xmm1");
  1610. &pxor ("xmm2","xmm2");
  1611. &movdqa (&QWP(16*0,"esp"),"xmm0"); # clear stack
  1612. &pxor ("xmm3","xmm3");
  1613. &movdqa (&QWP(16*1,"esp"),"xmm0");
  1614. &pxor ("xmm4","xmm4");
  1615. &movdqa (&QWP(16*2,"esp"),"xmm0");
  1616. &pxor ("xmm5","xmm5");
  1617. &movdqa (&QWP(16*3,"esp"),"xmm0");
  1618. &pxor ("xmm6","xmm6");
  1619. &movdqa (&QWP(16*4,"esp"),"xmm0");
  1620. &pxor ("xmm7","xmm7");
  1621. &movdqa (&QWP(16*5,"esp"),"xmm0");
  1622. &mov ("esp",&DWP(16*7+4,"esp")); # restore %esp
  1623. &function_end("aesni_xts_decrypt");
  1624. }
  1625. }
  1626. ######################################################################
  1627. # void $PREFIX_cbc_encrypt (const void *inp, void *out,
  1628. # size_t length, const AES_KEY *key,
  1629. # unsigned char *ivp,const int enc);
  1630. &function_begin("${PREFIX}_cbc_encrypt");
  1631. &mov ($inp,&wparam(0));
  1632. &mov ($rounds_,"esp");
  1633. &mov ($out,&wparam(1));
  1634. &sub ($rounds_,24);
  1635. &mov ($len,&wparam(2));
  1636. &and ($rounds_,-16);
  1637. &mov ($key,&wparam(3));
  1638. &mov ($key_,&wparam(4));
  1639. &test ($len,$len);
  1640. &jz (&label("cbc_abort"));
  1641. &cmp (&wparam(5),0);
  1642. &xchg ($rounds_,"esp"); # alloca
  1643. &movups ($ivec,&QWP(0,$key_)); # load IV
  1644. &mov ($rounds,&DWP(240,$key));
  1645. &mov ($key_,$key); # backup $key
  1646. &mov (&DWP(16,"esp"),$rounds_); # save original %esp
  1647. &mov ($rounds_,$rounds); # backup $rounds
  1648. &je (&label("cbc_decrypt"));
  1649. &movaps ($inout0,$ivec);
  1650. &cmp ($len,16);
  1651. &jb (&label("cbc_enc_tail"));
  1652. &sub ($len,16);
  1653. &jmp (&label("cbc_enc_loop"));
  1654. &set_label("cbc_enc_loop",16);
  1655. &movups ($ivec,&QWP(0,$inp)); # input actually
  1656. &lea ($inp,&DWP(16,$inp));
  1657. if ($inline)
  1658. { &aesni_inline_generate1("enc",$inout0,$ivec); }
  1659. else
  1660. { &xorps($inout0,$ivec); &call("_aesni_encrypt1"); }
  1661. &mov ($rounds,$rounds_); # restore $rounds
  1662. &mov ($key,$key_); # restore $key
  1663. &movups (&QWP(0,$out),$inout0); # store output
  1664. &lea ($out,&DWP(16,$out));
  1665. &sub ($len,16);
  1666. &jnc (&label("cbc_enc_loop"));
  1667. &add ($len,16);
  1668. &jnz (&label("cbc_enc_tail"));
  1669. &movaps ($ivec,$inout0);
  1670. &pxor ($inout0,$inout0);
  1671. &jmp (&label("cbc_ret"));
  1672. &set_label("cbc_enc_tail");
  1673. &mov ("ecx",$len); # zaps $rounds
  1674. &data_word(0xA4F3F689); # rep movsb
  1675. &mov ("ecx",16); # zero tail
  1676. &sub ("ecx",$len);
  1677. &xor ("eax","eax"); # zaps $len
  1678. &data_word(0xAAF3F689); # rep stosb
  1679. &lea ($out,&DWP(-16,$out)); # rewind $out by 1 block
  1680. &mov ($rounds,$rounds_); # restore $rounds
  1681. &mov ($inp,$out); # $inp and $out are the same
  1682. &mov ($key,$key_); # restore $key
  1683. &jmp (&label("cbc_enc_loop"));
  1684. ######################################################################
  1685. &set_label("cbc_decrypt",16);
  1686. &cmp ($len,0x50);
  1687. &jbe (&label("cbc_dec_tail"));
  1688. &movaps (&QWP(0,"esp"),$ivec); # save IV
  1689. &sub ($len,0x50);
  1690. &jmp (&label("cbc_dec_loop6_enter"));
  1691. &set_label("cbc_dec_loop6",16);
  1692. &movaps (&QWP(0,"esp"),$rndkey0); # save IV
  1693. &movups (&QWP(0,$out),$inout5);
  1694. &lea ($out,&DWP(0x10,$out));
  1695. &set_label("cbc_dec_loop6_enter");
  1696. &movdqu ($inout0,&QWP(0,$inp));
  1697. &movdqu ($inout1,&QWP(0x10,$inp));
  1698. &movdqu ($inout2,&QWP(0x20,$inp));
  1699. &movdqu ($inout3,&QWP(0x30,$inp));
  1700. &movdqu ($inout4,&QWP(0x40,$inp));
  1701. &movdqu ($inout5,&QWP(0x50,$inp));
  1702. &call ("_aesni_decrypt6");
  1703. &movups ($rndkey1,&QWP(0,$inp));
  1704. &movups ($rndkey0,&QWP(0x10,$inp));
  1705. &xorps ($inout0,&QWP(0,"esp")); # ^=IV
  1706. &xorps ($inout1,$rndkey1);
  1707. &movups ($rndkey1,&QWP(0x20,$inp));
  1708. &xorps ($inout2,$rndkey0);
  1709. &movups ($rndkey0,&QWP(0x30,$inp));
  1710. &xorps ($inout3,$rndkey1);
  1711. &movups ($rndkey1,&QWP(0x40,$inp));
  1712. &xorps ($inout4,$rndkey0);
  1713. &movups ($rndkey0,&QWP(0x50,$inp)); # IV
  1714. &xorps ($inout5,$rndkey1);
  1715. &movups (&QWP(0,$out),$inout0);
  1716. &movups (&QWP(0x10,$out),$inout1);
  1717. &lea ($inp,&DWP(0x60,$inp));
  1718. &movups (&QWP(0x20,$out),$inout2);
  1719. &mov ($rounds,$rounds_); # restore $rounds
  1720. &movups (&QWP(0x30,$out),$inout3);
  1721. &mov ($key,$key_); # restore $key
  1722. &movups (&QWP(0x40,$out),$inout4);
  1723. &lea ($out,&DWP(0x50,$out));
  1724. &sub ($len,0x60);
  1725. &ja (&label("cbc_dec_loop6"));
  1726. &movaps ($inout0,$inout5);
  1727. &movaps ($ivec,$rndkey0);
  1728. &add ($len,0x50);
  1729. &jle (&label("cbc_dec_clear_tail_collected"));
  1730. &movups (&QWP(0,$out),$inout0);
  1731. &lea ($out,&DWP(0x10,$out));
  1732. &set_label("cbc_dec_tail");
  1733. &movups ($inout0,&QWP(0,$inp));
  1734. &movaps ($in0,$inout0);
  1735. &cmp ($len,0x10);
  1736. &jbe (&label("cbc_dec_one"));
  1737. &movups ($inout1,&QWP(0x10,$inp));
  1738. &movaps ($in1,$inout1);
  1739. &cmp ($len,0x20);
  1740. &jbe (&label("cbc_dec_two"));
  1741. &movups ($inout2,&QWP(0x20,$inp));
  1742. &cmp ($len,0x30);
  1743. &jbe (&label("cbc_dec_three"));
  1744. &movups ($inout3,&QWP(0x30,$inp));
  1745. &cmp ($len,0x40);
  1746. &jbe (&label("cbc_dec_four"));
  1747. &movups ($inout4,&QWP(0x40,$inp));
  1748. &movaps (&QWP(0,"esp"),$ivec); # save IV
  1749. &movups ($inout0,&QWP(0,$inp));
  1750. &xorps ($inout5,$inout5);
  1751. &call ("_aesni_decrypt6");
  1752. &movups ($rndkey1,&QWP(0,$inp));
  1753. &movups ($rndkey0,&QWP(0x10,$inp));
  1754. &xorps ($inout0,&QWP(0,"esp")); # ^= IV
  1755. &xorps ($inout1,$rndkey1);
  1756. &movups ($rndkey1,&QWP(0x20,$inp));
  1757. &xorps ($inout2,$rndkey0);
  1758. &movups ($rndkey0,&QWP(0x30,$inp));
  1759. &xorps ($inout3,$rndkey1);
  1760. &movups ($ivec,&QWP(0x40,$inp)); # IV
  1761. &xorps ($inout4,$rndkey0);
  1762. &movups (&QWP(0,$out),$inout0);
  1763. &movups (&QWP(0x10,$out),$inout1);
  1764. &pxor ($inout1,$inout1);
  1765. &movups (&QWP(0x20,$out),$inout2);
  1766. &pxor ($inout2,$inout2);
  1767. &movups (&QWP(0x30,$out),$inout3);
  1768. &pxor ($inout3,$inout3);
  1769. &lea ($out,&DWP(0x40,$out));
  1770. &movaps ($inout0,$inout4);
  1771. &pxor ($inout4,$inout4);
  1772. &sub ($len,0x50);
  1773. &jmp (&label("cbc_dec_tail_collected"));
  1774. &set_label("cbc_dec_one",16);
  1775. if ($inline)
  1776. { &aesni_inline_generate1("dec"); }
  1777. else
  1778. { &call ("_aesni_decrypt1"); }
  1779. &xorps ($inout0,$ivec);
  1780. &movaps ($ivec,$in0);
  1781. &sub ($len,0x10);
  1782. &jmp (&label("cbc_dec_tail_collected"));
  1783. &set_label("cbc_dec_two",16);
  1784. &call ("_aesni_decrypt2");
  1785. &xorps ($inout0,$ivec);
  1786. &xorps ($inout1,$in0);
  1787. &movups (&QWP(0,$out),$inout0);
  1788. &movaps ($inout0,$inout1);
  1789. &pxor ($inout1,$inout1);
  1790. &lea ($out,&DWP(0x10,$out));
  1791. &movaps ($ivec,$in1);
  1792. &sub ($len,0x20);
  1793. &jmp (&label("cbc_dec_tail_collected"));
  1794. &set_label("cbc_dec_three",16);
  1795. &call ("_aesni_decrypt3");
  1796. &xorps ($inout0,$ivec);
  1797. &xorps ($inout1,$in0);
  1798. &xorps ($inout2,$in1);
  1799. &movups (&QWP(0,$out),$inout0);
  1800. &movaps ($inout0,$inout2);
  1801. &pxor ($inout2,$inout2);
  1802. &movups (&QWP(0x10,$out),$inout1);
  1803. &pxor ($inout1,$inout1);
  1804. &lea ($out,&DWP(0x20,$out));
  1805. &movups ($ivec,&QWP(0x20,$inp));
  1806. &sub ($len,0x30);
  1807. &jmp (&label("cbc_dec_tail_collected"));
  1808. &set_label("cbc_dec_four",16);
  1809. &call ("_aesni_decrypt4");
  1810. &movups ($rndkey1,&QWP(0x10,$inp));
  1811. &movups ($rndkey0,&QWP(0x20,$inp));
  1812. &xorps ($inout0,$ivec);
  1813. &movups ($ivec,&QWP(0x30,$inp));
  1814. &xorps ($inout1,$in0);
  1815. &movups (&QWP(0,$out),$inout0);
  1816. &xorps ($inout2,$rndkey1);
  1817. &movups (&QWP(0x10,$out),$inout1);
  1818. &pxor ($inout1,$inout1);
  1819. &xorps ($inout3,$rndkey0);
  1820. &movups (&QWP(0x20,$out),$inout2);
  1821. &pxor ($inout2,$inout2);
  1822. &lea ($out,&DWP(0x30,$out));
  1823. &movaps ($inout0,$inout3);
  1824. &pxor ($inout3,$inout3);
  1825. &sub ($len,0x40);
  1826. &jmp (&label("cbc_dec_tail_collected"));
  1827. &set_label("cbc_dec_clear_tail_collected",16);
  1828. &pxor ($inout1,$inout1);
  1829. &pxor ($inout2,$inout2);
  1830. &pxor ($inout3,$inout3);
  1831. &pxor ($inout4,$inout4);
  1832. &set_label("cbc_dec_tail_collected");
  1833. &and ($len,15);
  1834. &jnz (&label("cbc_dec_tail_partial"));
  1835. &movups (&QWP(0,$out),$inout0);
  1836. &pxor ($rndkey0,$rndkey0);
  1837. &jmp (&label("cbc_ret"));
  1838. &set_label("cbc_dec_tail_partial",16);
  1839. &movaps (&QWP(0,"esp"),$inout0);
  1840. &pxor ($rndkey0,$rndkey0);
  1841. &mov ("ecx",16);
  1842. &mov ($inp,"esp");
  1843. &sub ("ecx",$len);
  1844. &data_word(0xA4F3F689); # rep movsb
  1845. &movdqa (&QWP(0,"esp"),$inout0);
  1846. &set_label("cbc_ret");
  1847. &mov ("esp",&DWP(16,"esp")); # pull original %esp
  1848. &mov ($key_,&wparam(4));
  1849. &pxor ($inout0,$inout0);
  1850. &pxor ($rndkey1,$rndkey1);
  1851. &movups (&QWP(0,$key_),$ivec); # output IV
  1852. &pxor ($ivec,$ivec);
  1853. &set_label("cbc_abort");
  1854. &function_end("${PREFIX}_cbc_encrypt");
  1855. ######################################################################
  1856. # Mechanical port from aesni-x86_64.pl.
  1857. #
  1858. # _aesni_set_encrypt_key is private interface,
  1859. # input:
  1860. # "eax" const unsigned char *userKey
  1861. # $rounds int bits
  1862. # $key AES_KEY *key
  1863. # output:
  1864. # "eax" return code
  1865. # $round rounds
  1866. &function_begin_B("_aesni_set_encrypt_key");
  1867. &push ("ebp");
  1868. &push ("ebx");
  1869. &test ("eax","eax");
  1870. &jz (&label("bad_pointer"));
  1871. &test ($key,$key);
  1872. &jz (&label("bad_pointer"));
  1873. &call (&label("pic"));
  1874. &set_label("pic");
  1875. &blindpop("ebx");
  1876. &lea ("ebx",&DWP(&label("key_const")."-".&label("pic"),"ebx"));
  1877. &picmeup("ebp","OPENSSL_ia32cap_P","ebx",&label("key_const"));
  1878. &movups ("xmm0",&QWP(0,"eax")); # pull first 128 bits of *userKey
  1879. &xorps ("xmm4","xmm4"); # low dword of xmm4 is assumed 0
  1880. &mov ("ebp",&DWP(4,"ebp"));
  1881. &lea ($key,&DWP(16,$key));
  1882. &and ("ebp",1<<28|1<<11); # AVX and XOP bits
  1883. &cmp ($rounds,256);
  1884. &je (&label("14rounds"));
  1885. &cmp ($rounds,192);
  1886. &je (&label("12rounds"));
  1887. &cmp ($rounds,128);
  1888. &jne (&label("bad_keybits"));
  1889. &set_label("10rounds",16);
  1890. &cmp ("ebp",1<<28);
  1891. &je (&label("10rounds_alt"));
  1892. &mov ($rounds,9);
  1893. &$movekey (&QWP(-16,$key),"xmm0"); # round 0
  1894. &aeskeygenassist("xmm1","xmm0",0x01); # round 1
  1895. &call (&label("key_128_cold"));
  1896. &aeskeygenassist("xmm1","xmm0",0x2); # round 2
  1897. &call (&label("key_128"));
  1898. &aeskeygenassist("xmm1","xmm0",0x04); # round 3
  1899. &call (&label("key_128"));
  1900. &aeskeygenassist("xmm1","xmm0",0x08); # round 4
  1901. &call (&label("key_128"));
  1902. &aeskeygenassist("xmm1","xmm0",0x10); # round 5
  1903. &call (&label("key_128"));
  1904. &aeskeygenassist("xmm1","xmm0",0x20); # round 6
  1905. &call (&label("key_128"));
  1906. &aeskeygenassist("xmm1","xmm0",0x40); # round 7
  1907. &call (&label("key_128"));
  1908. &aeskeygenassist("xmm1","xmm0",0x80); # round 8
  1909. &call (&label("key_128"));
  1910. &aeskeygenassist("xmm1","xmm0",0x1b); # round 9
  1911. &call (&label("key_128"));
  1912. &aeskeygenassist("xmm1","xmm0",0x36); # round 10
  1913. &call (&label("key_128"));
  1914. &$movekey (&QWP(0,$key),"xmm0");
  1915. &mov (&DWP(80,$key),$rounds);
  1916. &jmp (&label("good_key"));
  1917. &set_label("key_128",16);
  1918. &$movekey (&QWP(0,$key),"xmm0");
  1919. &lea ($key,&DWP(16,$key));
  1920. &set_label("key_128_cold");
  1921. &shufps ("xmm4","xmm0",0b00010000);
  1922. &xorps ("xmm0","xmm4");
  1923. &shufps ("xmm4","xmm0",0b10001100);
  1924. &xorps ("xmm0","xmm4");
  1925. &shufps ("xmm1","xmm1",0b11111111); # critical path
  1926. &xorps ("xmm0","xmm1");
  1927. &ret();
  1928. &set_label("10rounds_alt",16);
  1929. &movdqa ("xmm5",&QWP(0x00,"ebx"));
  1930. &mov ($rounds,8);
  1931. &movdqa ("xmm4",&QWP(0x20,"ebx"));
  1932. &movdqa ("xmm2","xmm0");
  1933. &movdqu (&QWP(-16,$key),"xmm0");
  1934. &set_label("loop_key128");
  1935. &pshufb ("xmm0","xmm5");
  1936. &aesenclast ("xmm0","xmm4");
  1937. &pslld ("xmm4",1);
  1938. &lea ($key,&DWP(16,$key));
  1939. &movdqa ("xmm3","xmm2");
  1940. &pslldq ("xmm2",4);
  1941. &pxor ("xmm3","xmm2");
  1942. &pslldq ("xmm2",4);
  1943. &pxor ("xmm3","xmm2");
  1944. &pslldq ("xmm2",4);
  1945. &pxor ("xmm2","xmm3");
  1946. &pxor ("xmm0","xmm2");
  1947. &movdqu (&QWP(-16,$key),"xmm0");
  1948. &movdqa ("xmm2","xmm0");
  1949. &dec ($rounds);
  1950. &jnz (&label("loop_key128"));
  1951. &movdqa ("xmm4",&QWP(0x30,"ebx"));
  1952. &pshufb ("xmm0","xmm5");
  1953. &aesenclast ("xmm0","xmm4");
  1954. &pslld ("xmm4",1);
  1955. &movdqa ("xmm3","xmm2");
  1956. &pslldq ("xmm2",4);
  1957. &pxor ("xmm3","xmm2");
  1958. &pslldq ("xmm2",4);
  1959. &pxor ("xmm3","xmm2");
  1960. &pslldq ("xmm2",4);
  1961. &pxor ("xmm2","xmm3");
  1962. &pxor ("xmm0","xmm2");
  1963. &movdqu (&QWP(0,$key),"xmm0");
  1964. &movdqa ("xmm2","xmm0");
  1965. &pshufb ("xmm0","xmm5");
  1966. &aesenclast ("xmm0","xmm4");
  1967. &movdqa ("xmm3","xmm2");
  1968. &pslldq ("xmm2",4);
  1969. &pxor ("xmm3","xmm2");
  1970. &pslldq ("xmm2",4);
  1971. &pxor ("xmm3","xmm2");
  1972. &pslldq ("xmm2",4);
  1973. &pxor ("xmm2","xmm3");
  1974. &pxor ("xmm0","xmm2");
  1975. &movdqu (&QWP(16,$key),"xmm0");
  1976. &mov ($rounds,9);
  1977. &mov (&DWP(96,$key),$rounds);
  1978. &jmp (&label("good_key"));
  1979. &set_label("12rounds",16);
  1980. &movq ("xmm2",&QWP(16,"eax")); # remaining 1/3 of *userKey
  1981. &cmp ("ebp",1<<28);
  1982. &je (&label("12rounds_alt"));
  1983. &mov ($rounds,11);
  1984. &$movekey (&QWP(-16,$key),"xmm0"); # round 0
  1985. &aeskeygenassist("xmm1","xmm2",0x01); # round 1,2
  1986. &call (&label("key_192a_cold"));
  1987. &aeskeygenassist("xmm1","xmm2",0x02); # round 2,3
  1988. &call (&label("key_192b"));
  1989. &aeskeygenassist("xmm1","xmm2",0x04); # round 4,5
  1990. &call (&label("key_192a"));
  1991. &aeskeygenassist("xmm1","xmm2",0x08); # round 5,6
  1992. &call (&label("key_192b"));
  1993. &aeskeygenassist("xmm1","xmm2",0x10); # round 7,8
  1994. &call (&label("key_192a"));
  1995. &aeskeygenassist("xmm1","xmm2",0x20); # round 8,9
  1996. &call (&label("key_192b"));
  1997. &aeskeygenassist("xmm1","xmm2",0x40); # round 10,11
  1998. &call (&label("key_192a"));
  1999. &aeskeygenassist("xmm1","xmm2",0x80); # round 11,12
  2000. &call (&label("key_192b"));
  2001. &$movekey (&QWP(0,$key),"xmm0");
  2002. &mov (&DWP(48,$key),$rounds);
  2003. &jmp (&label("good_key"));
  2004. &set_label("key_192a",16);
  2005. &$movekey (&QWP(0,$key),"xmm0");
  2006. &lea ($key,&DWP(16,$key));
  2007. &set_label("key_192a_cold",16);
  2008. &movaps ("xmm5","xmm2");
  2009. &set_label("key_192b_warm");
  2010. &shufps ("xmm4","xmm0",0b00010000);
  2011. &movdqa ("xmm3","xmm2");
  2012. &xorps ("xmm0","xmm4");
  2013. &shufps ("xmm4","xmm0",0b10001100);
  2014. &pslldq ("xmm3",4);
  2015. &xorps ("xmm0","xmm4");
  2016. &pshufd ("xmm1","xmm1",0b01010101); # critical path
  2017. &pxor ("xmm2","xmm3");
  2018. &pxor ("xmm0","xmm1");
  2019. &pshufd ("xmm3","xmm0",0b11111111);
  2020. &pxor ("xmm2","xmm3");
  2021. &ret();
  2022. &set_label("key_192b",16);
  2023. &movaps ("xmm3","xmm0");
  2024. &shufps ("xmm5","xmm0",0b01000100);
  2025. &$movekey (&QWP(0,$key),"xmm5");
  2026. &shufps ("xmm3","xmm2",0b01001110);
  2027. &$movekey (&QWP(16,$key),"xmm3");
  2028. &lea ($key,&DWP(32,$key));
  2029. &jmp (&label("key_192b_warm"));
  2030. &set_label("12rounds_alt",16);
  2031. &movdqa ("xmm5",&QWP(0x10,"ebx"));
  2032. &movdqa ("xmm4",&QWP(0x20,"ebx"));
  2033. &mov ($rounds,8);
  2034. &movdqu (&QWP(-16,$key),"xmm0");
  2035. &set_label("loop_key192");
  2036. &movq (&QWP(0,$key),"xmm2");
  2037. &movdqa ("xmm1","xmm2");
  2038. &pshufb ("xmm2","xmm5");
  2039. &aesenclast ("xmm2","xmm4");
  2040. &pslld ("xmm4",1);
  2041. &lea ($key,&DWP(24,$key));
  2042. &movdqa ("xmm3","xmm0");
  2043. &pslldq ("xmm0",4);
  2044. &pxor ("xmm3","xmm0");
  2045. &pslldq ("xmm0",4);
  2046. &pxor ("xmm3","xmm0");
  2047. &pslldq ("xmm0",4);
  2048. &pxor ("xmm0","xmm3");
  2049. &pshufd ("xmm3","xmm0",0xff);
  2050. &pxor ("xmm3","xmm1");
  2051. &pslldq ("xmm1",4);
  2052. &pxor ("xmm3","xmm1");
  2053. &pxor ("xmm0","xmm2");
  2054. &pxor ("xmm2","xmm3");
  2055. &movdqu (&QWP(-16,$key),"xmm0");
  2056. &dec ($rounds);
  2057. &jnz (&label("loop_key192"));
  2058. &mov ($rounds,11);
  2059. &mov (&DWP(32,$key),$rounds);
  2060. &jmp (&label("good_key"));
  2061. &set_label("14rounds",16);
  2062. &movups ("xmm2",&QWP(16,"eax")); # remaining half of *userKey
  2063. &lea ($key,&DWP(16,$key));
  2064. &cmp ("ebp",1<<28);
  2065. &je (&label("14rounds_alt"));
  2066. &mov ($rounds,13);
  2067. &$movekey (&QWP(-32,$key),"xmm0"); # round 0
  2068. &$movekey (&QWP(-16,$key),"xmm2"); # round 1
  2069. &aeskeygenassist("xmm1","xmm2",0x01); # round 2
  2070. &call (&label("key_256a_cold"));
  2071. &aeskeygenassist("xmm1","xmm0",0x01); # round 3
  2072. &call (&label("key_256b"));
  2073. &aeskeygenassist("xmm1","xmm2",0x02); # round 4
  2074. &call (&label("key_256a"));
  2075. &aeskeygenassist("xmm1","xmm0",0x02); # round 5
  2076. &call (&label("key_256b"));
  2077. &aeskeygenassist("xmm1","xmm2",0x04); # round 6
  2078. &call (&label("key_256a"));
  2079. &aeskeygenassist("xmm1","xmm0",0x04); # round 7
  2080. &call (&label("key_256b"));
  2081. &aeskeygenassist("xmm1","xmm2",0x08); # round 8
  2082. &call (&label("key_256a"));
  2083. &aeskeygenassist("xmm1","xmm0",0x08); # round 9
  2084. &call (&label("key_256b"));
  2085. &aeskeygenassist("xmm1","xmm2",0x10); # round 10
  2086. &call (&label("key_256a"));
  2087. &aeskeygenassist("xmm1","xmm0",0x10); # round 11
  2088. &call (&label("key_256b"));
  2089. &aeskeygenassist("xmm1","xmm2",0x20); # round 12
  2090. &call (&label("key_256a"));
  2091. &aeskeygenassist("xmm1","xmm0",0x20); # round 13
  2092. &call (&label("key_256b"));
  2093. &aeskeygenassist("xmm1","xmm2",0x40); # round 14
  2094. &call (&label("key_256a"));
  2095. &$movekey (&QWP(0,$key),"xmm0");
  2096. &mov (&DWP(16,$key),$rounds);
  2097. &xor ("eax","eax");
  2098. &jmp (&label("good_key"));
  2099. &set_label("key_256a",16);
  2100. &$movekey (&QWP(0,$key),"xmm2");
  2101. &lea ($key,&DWP(16,$key));
  2102. &set_label("key_256a_cold");
  2103. &shufps ("xmm4","xmm0",0b00010000);
  2104. &xorps ("xmm0","xmm4");
  2105. &shufps ("xmm4","xmm0",0b10001100);
  2106. &xorps ("xmm0","xmm4");
  2107. &shufps ("xmm1","xmm1",0b11111111); # critical path
  2108. &xorps ("xmm0","xmm1");
  2109. &ret();
  2110. &set_label("key_256b",16);
  2111. &$movekey (&QWP(0,$key),"xmm0");
  2112. &lea ($key,&DWP(16,$key));
  2113. &shufps ("xmm4","xmm2",0b00010000);
  2114. &xorps ("xmm2","xmm4");
  2115. &shufps ("xmm4","xmm2",0b10001100);
  2116. &xorps ("xmm2","xmm4");
  2117. &shufps ("xmm1","xmm1",0b10101010); # critical path
  2118. &xorps ("xmm2","xmm1");
  2119. &ret();
  2120. &set_label("14rounds_alt",16);
  2121. &movdqa ("xmm5",&QWP(0x00,"ebx"));
  2122. &movdqa ("xmm4",&QWP(0x20,"ebx"));
  2123. &mov ($rounds,7);
  2124. &movdqu (&QWP(-32,$key),"xmm0");
  2125. &movdqa ("xmm1","xmm2");
  2126. &movdqu (&QWP(-16,$key),"xmm2");
  2127. &set_label("loop_key256");
  2128. &pshufb ("xmm2","xmm5");
  2129. &aesenclast ("xmm2","xmm4");
  2130. &movdqa ("xmm3","xmm0");
  2131. &pslldq ("xmm0",4);
  2132. &pxor ("xmm3","xmm0");
  2133. &pslldq ("xmm0",4);
  2134. &pxor ("xmm3","xmm0");
  2135. &pslldq ("xmm0",4);
  2136. &pxor ("xmm0","xmm3");
  2137. &pslld ("xmm4",1);
  2138. &pxor ("xmm0","xmm2");
  2139. &movdqu (&QWP(0,$key),"xmm0");
  2140. &dec ($rounds);
  2141. &jz (&label("done_key256"));
  2142. &pshufd ("xmm2","xmm0",0xff);
  2143. &pxor ("xmm3","xmm3");
  2144. &aesenclast ("xmm2","xmm3");
  2145. &movdqa ("xmm3","xmm1")
  2146. &pslldq ("xmm1",4);
  2147. &pxor ("xmm3","xmm1");
  2148. &pslldq ("xmm1",4);
  2149. &pxor ("xmm3","xmm1");
  2150. &pslldq ("xmm1",4);
  2151. &pxor ("xmm1","xmm3");
  2152. &pxor ("xmm2","xmm1");
  2153. &movdqu (&QWP(16,$key),"xmm2");
  2154. &lea ($key,&DWP(32,$key));
  2155. &movdqa ("xmm1","xmm2");
  2156. &jmp (&label("loop_key256"));
  2157. &set_label("done_key256");
  2158. &mov ($rounds,13);
  2159. &mov (&DWP(16,$key),$rounds);
  2160. &set_label("good_key");
  2161. &pxor ("xmm0","xmm0");
  2162. &pxor ("xmm1","xmm1");
  2163. &pxor ("xmm2","xmm2");
  2164. &pxor ("xmm3","xmm3");
  2165. &pxor ("xmm4","xmm4");
  2166. &pxor ("xmm5","xmm5");
  2167. &xor ("eax","eax");
  2168. &pop ("ebx");
  2169. &pop ("ebp");
  2170. &ret ();
  2171. &set_label("bad_pointer",4);
  2172. &mov ("eax",-1);
  2173. &pop ("ebx");
  2174. &pop ("ebp");
  2175. &ret ();
  2176. &set_label("bad_keybits",4);
  2177. &pxor ("xmm0","xmm0");
  2178. &mov ("eax",-2);
  2179. &pop ("ebx");
  2180. &pop ("ebp");
  2181. &ret ();
  2182. &function_end_B("_aesni_set_encrypt_key");
  2183. # int $PREFIX_set_encrypt_key (const unsigned char *userKey, int bits,
  2184. # AES_KEY *key)
  2185. &function_begin_B("${PREFIX}_set_encrypt_key");
  2186. &mov ("eax",&wparam(0));
  2187. &mov ($rounds,&wparam(1));
  2188. &mov ($key,&wparam(2));
  2189. &call ("_aesni_set_encrypt_key");
  2190. &ret ();
  2191. &function_end_B("${PREFIX}_set_encrypt_key");
  2192. # int $PREFIX_set_decrypt_key (const unsigned char *userKey, int bits,
  2193. # AES_KEY *key)
  2194. &function_begin_B("${PREFIX}_set_decrypt_key");
  2195. &mov ("eax",&wparam(0));
  2196. &mov ($rounds,&wparam(1));
  2197. &mov ($key,&wparam(2));
  2198. &call ("_aesni_set_encrypt_key");
  2199. &mov ($key,&wparam(2));
  2200. &shl ($rounds,4); # rounds-1 after _aesni_set_encrypt_key
  2201. &test ("eax","eax");
  2202. &jnz (&label("dec_key_ret"));
  2203. &lea ("eax",&DWP(16,$key,$rounds)); # end of key schedule
  2204. &$movekey ("xmm0",&QWP(0,$key)); # just swap
  2205. &$movekey ("xmm1",&QWP(0,"eax"));
  2206. &$movekey (&QWP(0,"eax"),"xmm0");
  2207. &$movekey (&QWP(0,$key),"xmm1");
  2208. &lea ($key,&DWP(16,$key));
  2209. &lea ("eax",&DWP(-16,"eax"));
  2210. &set_label("dec_key_inverse");
  2211. &$movekey ("xmm0",&QWP(0,$key)); # swap and inverse
  2212. &$movekey ("xmm1",&QWP(0,"eax"));
  2213. &aesimc ("xmm0","xmm0");
  2214. &aesimc ("xmm1","xmm1");
  2215. &lea ($key,&DWP(16,$key));
  2216. &lea ("eax",&DWP(-16,"eax"));
  2217. &$movekey (&QWP(16,"eax"),"xmm0");
  2218. &$movekey (&QWP(-16,$key),"xmm1");
  2219. &cmp ("eax",$key);
  2220. &ja (&label("dec_key_inverse"));
  2221. &$movekey ("xmm0",&QWP(0,$key)); # inverse middle
  2222. &aesimc ("xmm0","xmm0");
  2223. &$movekey (&QWP(0,$key),"xmm0");
  2224. &pxor ("xmm0","xmm0");
  2225. &pxor ("xmm1","xmm1");
  2226. &xor ("eax","eax"); # return success
  2227. &set_label("dec_key_ret");
  2228. &ret ();
  2229. &function_end_B("${PREFIX}_set_decrypt_key");
  2230. &set_label("key_const",64);
  2231. &data_word(0x0c0f0e0d,0x0c0f0e0d,0x0c0f0e0d,0x0c0f0e0d);
  2232. &data_word(0x04070605,0x04070605,0x04070605,0x04070605);
  2233. &data_word(1,1,1,1);
  2234. &data_word(0x1b,0x1b,0x1b,0x1b);
  2235. &asciz("AES for Intel AES-NI, CRYPTOGAMS by <appro\@openssl.org>");
  2236. &asm_finish();