2022-04-23 11:59:50 +03:00
|
|
|
// SPDX-FileCopyrightText: Copyright 2018 yuzu Emulator Project
|
|
|
|
// SPDX-License-Identifier: GPL-2.0-or-later
|
2018-07-28 06:55:23 +03:00
|
|
|
|
2020-08-03 21:14:39 +03:00
|
|
|
#include <array>
|
2018-07-29 04:39:42 +03:00
|
|
|
#include <mbedtls/cipher.h>
|
2018-08-04 23:41:17 +03:00
|
|
|
#include "common/assert.h"
|
|
|
|
#include "common/logging/log.h"
|
2018-07-28 23:23:00 +03:00
|
|
|
#include "core/crypto/aes_util.h"
|
2018-07-29 04:39:42 +03:00
|
|
|
#include "core/crypto/key_manager.h"
|
2018-07-28 23:23:00 +03:00
|
|
|
|
|
|
|
namespace Core::Crypto {
|
2018-08-04 23:52:19 +03:00
|
|
|
namespace {
|
2020-08-03 21:14:39 +03:00
|
|
|
using NintendoTweak = std::array<u8, 16>;
|
|
|
|
|
|
|
|
NintendoTweak CalculateNintendoTweak(std::size_t sector_id) {
|
|
|
|
NintendoTweak out{};
|
2018-09-15 16:21:06 +03:00
|
|
|
for (std::size_t i = 0xF; i <= 0xF; --i) {
|
2018-08-04 23:52:19 +03:00
|
|
|
out[i] = sector_id & 0xFF;
|
|
|
|
sector_id >>= 8;
|
|
|
|
}
|
|
|
|
return out;
|
|
|
|
}
|
|
|
|
} // Anonymous namespace
|
2018-07-28 23:23:00 +03:00
|
|
|
|
2018-09-15 16:21:06 +03:00
|
|
|
static_assert(static_cast<std::size_t>(Mode::CTR) ==
|
|
|
|
static_cast<std::size_t>(MBEDTLS_CIPHER_AES_128_CTR),
|
2018-07-29 04:39:42 +03:00
|
|
|
"CTR has incorrect value.");
|
2018-09-15 16:21:06 +03:00
|
|
|
static_assert(static_cast<std::size_t>(Mode::ECB) ==
|
|
|
|
static_cast<std::size_t>(MBEDTLS_CIPHER_AES_128_ECB),
|
2018-07-29 04:39:42 +03:00
|
|
|
"ECB has incorrect value.");
|
2018-09-15 16:21:06 +03:00
|
|
|
static_assert(static_cast<std::size_t>(Mode::XTS) ==
|
|
|
|
static_cast<std::size_t>(MBEDTLS_CIPHER_AES_128_XTS),
|
2018-07-29 04:39:42 +03:00
|
|
|
"XTS has incorrect value.");
|
|
|
|
|
|
|
|
// Structure to hide mbedtls types from header file
|
|
|
|
struct CipherContext {
|
|
|
|
mbedtls_cipher_context_t encryption_context;
|
|
|
|
mbedtls_cipher_context_t decryption_context;
|
|
|
|
};
|
|
|
|
|
2018-09-15 16:21:06 +03:00
|
|
|
template <typename Key, std::size_t KeySize>
|
2018-07-29 04:39:42 +03:00
|
|
|
Crypto::AESCipher<Key, KeySize>::AESCipher(Key key, Mode mode)
|
|
|
|
: ctx(std::make_unique<CipherContext>()) {
|
|
|
|
mbedtls_cipher_init(&ctx->encryption_context);
|
|
|
|
mbedtls_cipher_init(&ctx->decryption_context);
|
2018-07-28 23:23:00 +03:00
|
|
|
|
|
|
|
ASSERT_MSG((mbedtls_cipher_setup(
|
2018-07-29 04:39:42 +03:00
|
|
|
&ctx->encryption_context,
|
|
|
|
mbedtls_cipher_info_from_type(static_cast<mbedtls_cipher_type_t>(mode))) ||
|
|
|
|
mbedtls_cipher_setup(
|
|
|
|
&ctx->decryption_context,
|
|
|
|
mbedtls_cipher_info_from_type(static_cast<mbedtls_cipher_type_t>(mode)))) == 0,
|
2018-07-28 23:23:00 +03:00
|
|
|
"Failed to initialize mbedtls ciphers.");
|
|
|
|
|
|
|
|
ASSERT(
|
2018-07-29 04:39:42 +03:00
|
|
|
!mbedtls_cipher_setkey(&ctx->encryption_context, key.data(), KeySize * 8, MBEDTLS_ENCRYPT));
|
2018-07-28 23:23:00 +03:00
|
|
|
ASSERT(
|
2018-07-29 04:39:42 +03:00
|
|
|
!mbedtls_cipher_setkey(&ctx->decryption_context, key.data(), KeySize * 8, MBEDTLS_DECRYPT));
|
2018-07-28 23:23:00 +03:00
|
|
|
//"Failed to set key on mbedtls ciphers.");
|
|
|
|
}
|
|
|
|
|
2018-09-15 16:21:06 +03:00
|
|
|
template <typename Key, std::size_t KeySize>
|
2018-07-28 23:23:00 +03:00
|
|
|
AESCipher<Key, KeySize>::~AESCipher() {
|
2018-07-29 04:39:42 +03:00
|
|
|
mbedtls_cipher_free(&ctx->encryption_context);
|
|
|
|
mbedtls_cipher_free(&ctx->decryption_context);
|
2018-07-28 23:23:00 +03:00
|
|
|
}
|
|
|
|
|
2018-09-15 16:21:06 +03:00
|
|
|
template <typename Key, std::size_t KeySize>
|
|
|
|
void AESCipher<Key, KeySize>::Transcode(const u8* src, std::size_t size, u8* dest, Op op) const {
|
2018-08-04 23:49:39 +03:00
|
|
|
auto* const context = op == Op::Encrypt ? &ctx->encryption_context : &ctx->decryption_context;
|
2018-07-28 23:23:00 +03:00
|
|
|
|
|
|
|
mbedtls_cipher_reset(context);
|
|
|
|
|
2018-09-15 16:21:06 +03:00
|
|
|
std::size_t written = 0;
|
2018-07-28 23:23:00 +03:00
|
|
|
if (mbedtls_cipher_get_cipher_mode(context) == MBEDTLS_MODE_XTS) {
|
2018-07-29 04:39:42 +03:00
|
|
|
mbedtls_cipher_update(context, src, size, dest, &written);
|
2018-08-04 23:49:39 +03:00
|
|
|
if (written != size) {
|
2018-07-28 23:23:00 +03:00
|
|
|
LOG_WARNING(Crypto, "Not all data was decrypted requested={:016X}, actual={:016X}.",
|
|
|
|
size, written);
|
2018-08-04 23:49:39 +03:00
|
|
|
}
|
2018-07-28 23:23:00 +03:00
|
|
|
} else {
|
|
|
|
const auto block_size = mbedtls_cipher_get_block_size(context);
|
2018-08-26 01:56:25 +03:00
|
|
|
if (size < block_size) {
|
|
|
|
std::vector<u8> block(block_size);
|
|
|
|
std::memcpy(block.data(), src, size);
|
|
|
|
Transcode(block.data(), block.size(), block.data(), op);
|
|
|
|
std::memcpy(dest, block.data(), size);
|
|
|
|
return;
|
|
|
|
}
|
2018-07-28 23:23:00 +03:00
|
|
|
|
2018-09-15 16:21:06 +03:00
|
|
|
for (std::size_t offset = 0; offset < size; offset += block_size) {
|
|
|
|
auto length = std::min<std::size_t>(block_size, size - offset);
|
2018-07-29 04:39:42 +03:00
|
|
|
mbedtls_cipher_update(context, src + offset, length, dest + offset, &written);
|
2018-08-04 23:49:39 +03:00
|
|
|
if (written != length) {
|
2018-08-26 01:56:25 +03:00
|
|
|
if (length < block_size) {
|
|
|
|
std::vector<u8> block(block_size);
|
|
|
|
std::memcpy(block.data(), src + offset, length);
|
|
|
|
Transcode(block.data(), block.size(), block.data(), op);
|
|
|
|
std::memcpy(dest + offset, block.data(), length);
|
|
|
|
return;
|
|
|
|
}
|
2018-07-29 04:39:42 +03:00
|
|
|
LOG_WARNING(Crypto, "Not all data was decrypted requested={:016X}, actual={:016X}.",
|
2018-07-28 23:23:00 +03:00
|
|
|
length, written);
|
2018-08-04 23:49:39 +03:00
|
|
|
}
|
2018-07-28 23:23:00 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-09-15 16:21:06 +03:00
|
|
|
template <typename Key, std::size_t KeySize>
|
|
|
|
void AESCipher<Key, KeySize>::XTSTranscode(const u8* src, std::size_t size, u8* dest,
|
|
|
|
std::size_t sector_id, std::size_t sector_size, Op op) {
|
2018-08-17 00:00:35 +03:00
|
|
|
ASSERT_MSG(size % sector_size == 0, "XTS decryption size must be a multiple of sector size.");
|
2018-07-28 23:23:00 +03:00
|
|
|
|
2018-09-15 16:21:06 +03:00
|
|
|
for (std::size_t i = 0; i < size; i += sector_size) {
|
2018-07-28 23:23:00 +03:00
|
|
|
SetIV(CalculateNintendoTweak(sector_id++));
|
2020-08-06 09:31:16 +03:00
|
|
|
Transcode(src + i, sector_size, dest + i, op);
|
2018-07-28 23:23:00 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-08-03 21:14:39 +03:00
|
|
|
template <typename Key, std::size_t KeySize>
|
2021-04-23 16:58:38 +03:00
|
|
|
void AESCipher<Key, KeySize>::SetIV(std::span<const u8> data) {
|
|
|
|
ASSERT_MSG((mbedtls_cipher_set_iv(&ctx->encryption_context, data.data(), data.size()) ||
|
|
|
|
mbedtls_cipher_set_iv(&ctx->decryption_context, data.data(), data.size())) == 0,
|
2020-08-03 21:14:39 +03:00
|
|
|
"Failed to set IV on mbedtls ciphers.");
|
|
|
|
}
|
|
|
|
|
2018-07-28 23:23:00 +03:00
|
|
|
template class AESCipher<Key128>;
|
|
|
|
template class AESCipher<Key256>;
|
2018-08-17 00:00:35 +03:00
|
|
|
} // namespace Core::Crypto
|