2 * CAAM Protocol Data Block (PDB) definition header file
4 * Copyright 2008-2012 Freescale Semiconductor, Inc.
12 * PDB- IPSec ESP Header Modification Options
14 #define PDBHMO_ESP_DECAP_SHIFT 12
15 #define PDBHMO_ESP_ENCAP_SHIFT 4
17 * Encap and Decap - Decrement TTL (Hop Limit) - Based on the value of the
18 * Options Byte IP version (IPvsn) field:
19 * if IPv4, decrement the inner IP header TTL field (byte 8);
20 * if IPv6 decrement the inner IP header Hop Limit field (byte 7).
22 #define PDBHMO_ESP_DECAP_DEC_TTL (0x02 << PDBHMO_ESP_DECAP_SHIFT)
23 #define PDBHMO_ESP_ENCAP_DEC_TTL (0x02 << PDBHMO_ESP_ENCAP_SHIFT)
25 * Decap - DiffServ Copy - Copy the IPv4 TOS or IPv6 Traffic Class byte
26 * from the outer IP header to the inner IP header.
28 #define PDBHMO_ESP_DIFFSERV (0x01 << PDBHMO_ESP_DECAP_SHIFT)
30 * Encap- Copy DF bit -if an IPv4 tunnel mode outer IP header is coming from
31 * the PDB, copy the DF bit from the inner IP header to the outer IP header.
33 #define PDBHMO_ESP_DFBIT (0x04 << PDBHMO_ESP_ENCAP_SHIFT)
36 * PDB - IPSec ESP Encap/Decap Options
38 #define PDBOPTS_ESP_ARSNONE 0x00 /* no antireplay window */
39 #define PDBOPTS_ESP_ARS32 0x40 /* 32-entry antireplay window */
40 #define PDBOPTS_ESP_ARS64 0xc0 /* 64-entry antireplay window */
41 #define PDBOPTS_ESP_IVSRC 0x20 /* IV comes from internal random gen */
42 #define PDBOPTS_ESP_ESN 0x10 /* extended sequence included */
43 #define PDBOPTS_ESP_OUTFMT 0x08 /* output only decapsulation (decap) */
44 #define PDBOPTS_ESP_IPHDRSRC 0x08 /* IP header comes from PDB (encap) */
45 #define PDBOPTS_ESP_INCIPHDR 0x04 /* Prepend IP header to output frame */
46 #define PDBOPTS_ESP_IPVSN 0x02 /* process IPv6 header */
47 #define PDBOPTS_ESP_TUNNEL 0x01 /* tunnel mode next-header byte */
48 #define PDBOPTS_ESP_IPV6 0x02 /* ip header version is V6 */
49 #define PDBOPTS_ESP_DIFFSERV 0x40 /* copy TOS/TC from inner iphdr */
50 #define PDBOPTS_ESP_UPDATE_CSUM 0x80 /* encap-update ip header checksum */
51 #define PDBOPTS_ESP_VERIFY_CSUM 0x20 /* decap-validate ip header checksum */
54 * General IPSec encap/decap PDB definitions
56 struct ipsec_encap_cbc {
60 struct ipsec_encap_ctr {
66 struct ipsec_encap_ccm {
67 u32 salt; /* lower 24 bits */
74 struct ipsec_encap_gcm {
75 u32 salt; /* lower 24 bits */
80 struct ipsec_encap_pdb {
88 struct ipsec_encap_cbc cbc;
89 struct ipsec_encap_ctr ctr;
90 struct ipsec_encap_ccm ccm;
91 struct ipsec_encap_gcm gcm;
96 u32 ip_hdr[0]; /* optional IP Header content */
99 struct ipsec_decap_cbc {
103 struct ipsec_decap_ctr {
108 struct ipsec_decap_ccm {
115 struct ipsec_decap_gcm {
120 struct ipsec_decap_pdb {
125 struct ipsec_decap_cbc cbc;
126 struct ipsec_decap_ctr ctr;
127 struct ipsec_decap_ccm ccm;
128 struct ipsec_decap_gcm gcm;
137 * IPSec ESP Datapath Protocol Override Register (DPOVRD)
139 struct ipsec_deco_dpovrd {
140 #define IPSEC_ENCAP_DECO_DPOVRD_USE 0x80
144 u8 next_header; /* reserved if decap */
148 * IEEE 802.11i WiFi Protocol Data Block
150 #define WIFI_PDBOPTS_FCS 0x01
151 #define WIFI_PDBOPTS_AR 0x40
153 struct wifi_encap_pdb {
171 struct wifi_decap_pdb {
188 * IEEE 802.16 WiMAX Protocol Data Block
190 #define WIMAX_PDBOPTS_FCS 0x01
191 #define WIMAX_PDBOPTS_AR 0x40 /* decap only */
193 struct wimax_encap_pdb {
200 /* begin DECO writeback region */
202 /* end DECO writeback region */
205 struct wimax_decap_pdb {
212 /* begin DECO writeback region */
216 u64 antireplay_scorecard;
217 /* end DECO writeback region */
221 * IEEE 801.AE MacSEC Protocol Data Block
223 #define MACSEC_PDBOPTS_FCS 0x01
224 #define MACSEC_PDBOPTS_AR 0x40 /* used in decap only */
226 struct macsec_encap_pdb {
234 /* begin DECO writeback region */
236 /* end DECO writeback region */
239 struct macsec_decap_pdb {
245 /* begin DECO writeback region */
248 u64 antireplay_scorecard;
249 /* end DECO writeback region */
253 * SSL/TLS/DTLS Protocol Data Blocks
256 #define TLS_PDBOPTS_ARS32 0x40
257 #define TLS_PDBOPTS_ARS64 0xc0
258 #define TLS_PDBOPTS_OUTFMT 0x08
259 #define TLS_PDBOPTS_IV_WRTBK 0x02 /* 1.1/1.2/DTLS only */
260 #define TLS_PDBOPTS_EXP_RND_IV 0x01 /* 1.1/1.2/DTLS only */
262 struct tls_block_encap_pdb {
270 struct tls_stream_encap_pdb {
280 struct dtls_block_encap_pdb {
289 struct tls_block_decap_pdb {
296 struct tls_stream_decap_pdb {
305 struct dtls_block_decap_pdb {
311 u64 antireplay_scorecard;
315 * SRTP Protocol Data Blocks
317 #define SRTP_PDBOPTS_MKI 0x08
318 #define SRTP_PDBOPTS_AR 0x40
320 struct srtp_encap_pdb {
335 struct srtp_decap_pdb {
348 u64 antireplay_scorecard;
352 * DSA/ECDSA Protocol Data Blocks
353 * Two of these exist: DSA-SIGN, and DSA-VERIFY. They are similar
354 * except for the treatment of "w" for verify, "s" for sign,
355 * and the placement of "a,b".
357 #define DSA_PDB_SGF_SHIFT 24
358 #define DSA_PDB_SGF_MASK (0xff << DSA_PDB_SGF_SHIFT)
359 #define DSA_PDB_SGF_Q (0x80 << DSA_PDB_SGF_SHIFT)
360 #define DSA_PDB_SGF_R (0x40 << DSA_PDB_SGF_SHIFT)
361 #define DSA_PDB_SGF_G (0x20 << DSA_PDB_SGF_SHIFT)
362 #define DSA_PDB_SGF_W (0x10 << DSA_PDB_SGF_SHIFT)
363 #define DSA_PDB_SGF_S (0x10 << DSA_PDB_SGF_SHIFT)
364 #define DSA_PDB_SGF_F (0x08 << DSA_PDB_SGF_SHIFT)
365 #define DSA_PDB_SGF_C (0x04 << DSA_PDB_SGF_SHIFT)
366 #define DSA_PDB_SGF_D (0x02 << DSA_PDB_SGF_SHIFT)
367 #define DSA_PDB_SGF_AB_SIGN (0x02 << DSA_PDB_SGF_SHIFT)
368 #define DSA_PDB_SGF_AB_VERIFY (0x01 << DSA_PDB_SGF_SHIFT)
370 #define DSA_PDB_L_SHIFT 7
371 #define DSA_PDB_L_MASK (0x3ff << DSA_PDB_L_SHIFT)
373 #define DSA_PDB_N_MASK 0x7f
375 struct dsa_sign_pdb {
376 u32 sgf_ln; /* Use DSA_PDB_ defintions per above */
384 u8 *ab; /* ECC only */
388 struct dsa_verify_pdb {
397 u8 *tmp; /* temporary data block */
398 u8 *ab; /* only used if ECC processing */