Home | History | Annotate | Line # | Download | only in net80211
ieee80211_crypto.c revision 1.5.10.1
      1  1.5.10.1    kent /*	$NetBSD: ieee80211_crypto.c,v 1.5.10.1 2005/04/29 11:29:32 kent Exp $	*/
      2       1.1  dyoung /*-
      3       1.1  dyoung  * Copyright (c) 2001 Atsushi Onoe
      4       1.1  dyoung  * Copyright (c) 2002, 2003 Sam Leffler, Errno Consulting
      5       1.1  dyoung  * All rights reserved.
      6       1.1  dyoung  *
      7       1.1  dyoung  * Redistribution and use in source and binary forms, with or without
      8       1.1  dyoung  * modification, are permitted provided that the following conditions
      9       1.1  dyoung  * are met:
     10       1.1  dyoung  * 1. Redistributions of source code must retain the above copyright
     11       1.1  dyoung  *    notice, this list of conditions and the following disclaimer.
     12       1.1  dyoung  * 2. Redistributions in binary form must reproduce the above copyright
     13       1.1  dyoung  *    notice, this list of conditions and the following disclaimer in the
     14       1.1  dyoung  *    documentation and/or other materials provided with the distribution.
     15       1.1  dyoung  * 3. The name of the author may not be used to endorse or promote products
     16       1.1  dyoung  *    derived from this software without specific prior written permission.
     17       1.1  dyoung  *
     18       1.1  dyoung  * Alternatively, this software may be distributed under the terms of the
     19       1.1  dyoung  * GNU General Public License ("GPL") version 2 as published by the Free
     20       1.1  dyoung  * Software Foundation.
     21       1.1  dyoung  *
     22       1.1  dyoung  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
     23       1.1  dyoung  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
     24       1.1  dyoung  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
     25       1.1  dyoung  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
     26       1.1  dyoung  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     27       1.1  dyoung  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     28       1.1  dyoung  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     29       1.1  dyoung  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     30       1.1  dyoung  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     31       1.1  dyoung  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     32       1.1  dyoung  */
     33       1.1  dyoung 
     34       1.1  dyoung #include <sys/cdefs.h>
     35       1.3  dyoung #ifdef __FreeBSD__
     36       1.5  dyoung __FBSDID("$FreeBSD: src/sys/net80211/ieee80211_crypto.c,v 1.3 2003/10/17 23:15:30 sam Exp $");
     37       1.3  dyoung #else
     38  1.5.10.1    kent __KERNEL_RCSID(0, "$NetBSD: ieee80211_crypto.c,v 1.5.10.1 2005/04/29 11:29:32 kent Exp $");
     39       1.3  dyoung #endif
     40       1.1  dyoung 
     41       1.1  dyoung #include "opt_inet.h"
     42       1.1  dyoung 
     43       1.1  dyoung #include <sys/param.h>
     44  1.5.10.1    kent #include <sys/systm.h>
     45  1.5.10.1    kent #include <sys/mbuf.h>
     46       1.1  dyoung #include <sys/malloc.h>
     47       1.1  dyoung #include <sys/kernel.h>
     48       1.1  dyoung #include <sys/socket.h>
     49       1.1  dyoung #include <sys/sockio.h>
     50       1.1  dyoung #include <sys/endian.h>
     51       1.1  dyoung #include <sys/errno.h>
     52       1.4  dyoung #ifdef __FreeBSD__
     53       1.1  dyoung #include <sys/bus.h>
     54       1.4  dyoung #endif
     55       1.1  dyoung #include <sys/proc.h>
     56       1.1  dyoung #include <sys/sysctl.h>
     57       1.1  dyoung 
     58       1.2  dyoung #ifdef __FreeBSD__
     59       1.1  dyoung #include <machine/atomic.h>
     60       1.2  dyoung #endif
     61  1.5.10.1    kent 
     62       1.1  dyoung #include <net/if.h>
     63       1.1  dyoung #include <net/if_dl.h>
     64       1.1  dyoung #include <net/if_media.h>
     65       1.1  dyoung #include <net/if_arp.h>
     66       1.2  dyoung #ifdef __FreeBSD__
     67       1.1  dyoung #include <net/ethernet.h>
     68       1.4  dyoung #else
     69       1.4  dyoung #include <net/if_ether.h>
     70       1.2  dyoung #endif
     71       1.1  dyoung #include <net/if_llc.h>
     72       1.1  dyoung 
     73       1.1  dyoung #include <net80211/ieee80211_var.h>
     74       1.4  dyoung #include <net80211/ieee80211_compat.h>
     75       1.1  dyoung 
     76       1.1  dyoung #include <net/bpf.h>
     77       1.1  dyoung 
     78       1.1  dyoung #ifdef INET
     79  1.5.10.1    kent #include <netinet/in.h>
     80       1.4  dyoung #ifdef __FreeBSD__
     81       1.1  dyoung #include <netinet/if_ether.h>
     82       1.4  dyoung #else
     83       1.4  dyoung #include <net/if_ether.h>
     84       1.4  dyoung #endif
     85       1.1  dyoung #endif
     86       1.1  dyoung 
     87       1.2  dyoung #ifdef __FreeBSD__
     88       1.1  dyoung #include <crypto/rc4/rc4.h>
     89       1.1  dyoung #define	arc4_ctxlen()			sizeof (struct rc4_state)
     90       1.1  dyoung #define	arc4_setkey(_c,_k,_l)		rc4_init(_c,_k,_l)
     91       1.1  dyoung #define	arc4_encrypt(_c,_d,_s,_l)	rc4_crypt(_c,_s,_d,_l)
     92       1.2  dyoung #else
     93       1.2  dyoung #include <crypto/arc4/arc4.h>
     94       1.2  dyoung #endif
     95       1.1  dyoung 
     96       1.1  dyoung static	void ieee80211_crc_init(void);
     97       1.1  dyoung static	u_int32_t ieee80211_crc_update(u_int32_t crc, u_int8_t *buf, int len);
     98       1.1  dyoung 
     99       1.1  dyoung void
    100       1.1  dyoung ieee80211_crypto_attach(struct ifnet *ifp)
    101       1.1  dyoung {
    102       1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
    103       1.1  dyoung 
    104       1.1  dyoung 	/*
    105       1.1  dyoung 	 * Setup crypto support.
    106       1.1  dyoung 	 */
    107       1.1  dyoung 	ieee80211_crc_init();
    108       1.1  dyoung 	ic->ic_iv = arc4random();
    109       1.1  dyoung }
    110       1.1  dyoung 
    111       1.1  dyoung void
    112       1.1  dyoung ieee80211_crypto_detach(struct ifnet *ifp)
    113       1.1  dyoung {
    114       1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
    115       1.1  dyoung 
    116       1.1  dyoung 	if (ic->ic_wep_ctx != NULL) {
    117       1.1  dyoung 		free(ic->ic_wep_ctx, M_DEVBUF);
    118       1.1  dyoung 		ic->ic_wep_ctx = NULL;
    119       1.1  dyoung 	}
    120       1.1  dyoung }
    121       1.1  dyoung 
    122       1.1  dyoung struct mbuf *
    123       1.1  dyoung ieee80211_wep_crypt(struct ifnet *ifp, struct mbuf *m0, int txflag)
    124       1.1  dyoung {
    125       1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
    126       1.1  dyoung 	struct mbuf *m, *n, *n0;
    127       1.1  dyoung 	struct ieee80211_frame *wh;
    128       1.1  dyoung 	int i, left, len, moff, noff, kid;
    129       1.1  dyoung 	u_int32_t iv, crc;
    130       1.1  dyoung 	u_int8_t *ivp;
    131       1.1  dyoung 	void *ctx;
    132       1.1  dyoung 	u_int8_t keybuf[IEEE80211_WEP_IVLEN + IEEE80211_KEYBUF_SIZE];
    133       1.1  dyoung 	u_int8_t crcbuf[IEEE80211_WEP_CRCLEN];
    134       1.1  dyoung 
    135       1.1  dyoung 	n0 = NULL;
    136       1.1  dyoung 	if ((ctx = ic->ic_wep_ctx) == NULL) {
    137       1.1  dyoung 		ctx = malloc(arc4_ctxlen(), M_DEVBUF, M_NOWAIT);
    138       1.5  dyoung 		if (ctx == NULL) {
    139       1.5  dyoung 			ic->ic_stats.is_crypto_nomem++;
    140       1.1  dyoung 			goto fail;
    141       1.5  dyoung 		}
    142       1.1  dyoung 		ic->ic_wep_ctx = ctx;
    143       1.1  dyoung 	}
    144       1.1  dyoung 	m = m0;
    145       1.1  dyoung 	left = m->m_pkthdr.len;
    146       1.1  dyoung 	MGET(n, M_DONTWAIT, m->m_type);
    147       1.1  dyoung 	n0 = n;
    148       1.5  dyoung 	if (n == NULL) {
    149       1.5  dyoung 		if (txflag)
    150       1.5  dyoung 			ic->ic_stats.is_tx_nombuf++;
    151       1.5  dyoung 		else
    152       1.5  dyoung 			ic->ic_stats.is_rx_nombuf++;
    153       1.1  dyoung 		goto fail;
    154       1.5  dyoung 	}
    155       1.4  dyoung #ifdef __FreeBSD__
    156       1.1  dyoung 	M_MOVE_PKTHDR(n, m);
    157       1.4  dyoung #else
    158       1.4  dyoung 	M_COPY_PKTHDR(n, m);
    159       1.4  dyoung #endif
    160       1.1  dyoung 	len = IEEE80211_WEP_IVLEN + IEEE80211_WEP_KIDLEN + IEEE80211_WEP_CRCLEN;
    161       1.1  dyoung 	if (txflag) {
    162       1.1  dyoung 		n->m_pkthdr.len += len;
    163       1.1  dyoung 	} else {
    164       1.1  dyoung 		n->m_pkthdr.len -= len;
    165       1.1  dyoung 		left -= len;
    166       1.1  dyoung 	}
    167       1.1  dyoung 	n->m_len = MHLEN;
    168       1.1  dyoung 	if (n->m_pkthdr.len >= MINCLSIZE) {
    169       1.1  dyoung 		MCLGET(n, M_DONTWAIT);
    170       1.1  dyoung 		if (n->m_flags & M_EXT)
    171       1.1  dyoung 			n->m_len = n->m_ext.ext_size;
    172       1.1  dyoung 	}
    173       1.1  dyoung 	len = sizeof(struct ieee80211_frame);
    174       1.1  dyoung 	memcpy(mtod(n, caddr_t), mtod(m, caddr_t), len);
    175       1.1  dyoung 	wh = mtod(n, struct ieee80211_frame *);
    176       1.1  dyoung 	left -= len;
    177       1.1  dyoung 	moff = len;
    178       1.1  dyoung 	noff = len;
    179       1.1  dyoung 	if (txflag) {
    180       1.1  dyoung 		kid = ic->ic_wep_txkey;
    181       1.1  dyoung 		wh->i_fc[1] |= IEEE80211_FC1_WEP;
    182       1.1  dyoung                 iv = ic->ic_iv;
    183       1.1  dyoung 		/*
    184       1.1  dyoung 		 * Skip 'bad' IVs from Fluhrer/Mantin/Shamir:
    185       1.1  dyoung 		 * (B, 255, N) with 3 <= B < 8
    186       1.1  dyoung 		 */
    187       1.1  dyoung 		if (iv >= 0x03ff00 &&
    188       1.1  dyoung 		    (iv & 0xf8ff00) == 0x00ff00)
    189       1.1  dyoung 			iv += 0x000100;
    190       1.1  dyoung 		ic->ic_iv = iv + 1;
    191       1.1  dyoung 		/* put iv in little endian to prepare 802.11i */
    192       1.1  dyoung 		ivp = mtod(n, u_int8_t *) + noff;
    193       1.1  dyoung 		for (i = 0; i < IEEE80211_WEP_IVLEN; i++) {
    194       1.1  dyoung 			ivp[i] = iv & 0xff;
    195       1.1  dyoung 			iv >>= 8;
    196       1.1  dyoung 		}
    197       1.1  dyoung 		ivp[IEEE80211_WEP_IVLEN] = kid << 6;	/* pad and keyid */
    198       1.1  dyoung 		noff += IEEE80211_WEP_IVLEN + IEEE80211_WEP_KIDLEN;
    199       1.1  dyoung 	} else {
    200       1.1  dyoung 		wh->i_fc[1] &= ~IEEE80211_FC1_WEP;
    201       1.1  dyoung 		ivp = mtod(m, u_int8_t *) + moff;
    202       1.1  dyoung 		kid = ivp[IEEE80211_WEP_IVLEN] >> 6;
    203       1.1  dyoung 		moff += IEEE80211_WEP_IVLEN + IEEE80211_WEP_KIDLEN;
    204       1.1  dyoung 	}
    205       1.1  dyoung 	memcpy(keybuf, ivp, IEEE80211_WEP_IVLEN);
    206       1.1  dyoung 	memcpy(keybuf + IEEE80211_WEP_IVLEN, ic->ic_nw_keys[kid].wk_key,
    207       1.1  dyoung 	    ic->ic_nw_keys[kid].wk_len);
    208       1.1  dyoung 	arc4_setkey(ctx, keybuf,
    209       1.1  dyoung 	    IEEE80211_WEP_IVLEN + ic->ic_nw_keys[kid].wk_len);
    210       1.1  dyoung 
    211       1.1  dyoung 	/* encrypt with calculating CRC */
    212       1.1  dyoung 	crc = ~0;
    213       1.1  dyoung 	while (left > 0) {
    214       1.1  dyoung 		len = m->m_len - moff;
    215       1.1  dyoung 		if (len == 0) {
    216       1.1  dyoung 			m = m->m_next;
    217       1.1  dyoung 			moff = 0;
    218       1.1  dyoung 			continue;
    219       1.1  dyoung 		}
    220       1.1  dyoung 		if (len > n->m_len - noff) {
    221       1.1  dyoung 			len = n->m_len - noff;
    222       1.1  dyoung 			if (len == 0) {
    223       1.1  dyoung 				MGET(n->m_next, M_DONTWAIT, n->m_type);
    224       1.5  dyoung 				if (n->m_next == NULL) {
    225       1.5  dyoung 					if (txflag)
    226       1.5  dyoung 						ic->ic_stats.is_tx_nombuf++;
    227       1.5  dyoung 					else
    228       1.5  dyoung 						ic->ic_stats.is_rx_nombuf++;
    229       1.1  dyoung 					goto fail;
    230       1.5  dyoung 				}
    231       1.1  dyoung 				n = n->m_next;
    232       1.1  dyoung 				n->m_len = MLEN;
    233       1.1  dyoung 				if (left >= MINCLSIZE) {
    234       1.1  dyoung 					MCLGET(n, M_DONTWAIT);
    235       1.1  dyoung 					if (n->m_flags & M_EXT)
    236       1.1  dyoung 						n->m_len = n->m_ext.ext_size;
    237       1.1  dyoung 				}
    238       1.1  dyoung 				noff = 0;
    239       1.1  dyoung 				continue;
    240       1.1  dyoung 			}
    241       1.1  dyoung 		}
    242       1.1  dyoung 		if (len > left)
    243       1.1  dyoung 			len = left;
    244       1.1  dyoung 		arc4_encrypt(ctx, mtod(n, caddr_t) + noff,
    245       1.1  dyoung 		    mtod(m, caddr_t) + moff, len);
    246       1.1  dyoung 		if (txflag)
    247       1.1  dyoung 			crc = ieee80211_crc_update(crc,
    248       1.1  dyoung 			    mtod(m, u_int8_t *) + moff, len);
    249       1.1  dyoung 		else
    250       1.1  dyoung 			crc = ieee80211_crc_update(crc,
    251       1.1  dyoung 			    mtod(n, u_int8_t *) + noff, len);
    252       1.1  dyoung 		left -= len;
    253       1.1  dyoung 		moff += len;
    254       1.1  dyoung 		noff += len;
    255       1.1  dyoung 	}
    256       1.1  dyoung 	crc = ~crc;
    257       1.1  dyoung 	if (txflag) {
    258       1.1  dyoung 		*(u_int32_t *)crcbuf = htole32(crc);
    259       1.1  dyoung 		if (n->m_len >= noff + sizeof(crcbuf))
    260       1.1  dyoung 			n->m_len = noff + sizeof(crcbuf);
    261       1.1  dyoung 		else {
    262       1.1  dyoung 			n->m_len = noff;
    263       1.1  dyoung 			MGET(n->m_next, M_DONTWAIT, n->m_type);
    264       1.5  dyoung 			if (n->m_next == NULL) {
    265       1.5  dyoung 				ic->ic_stats.is_tx_nombuf++;
    266       1.1  dyoung 				goto fail;
    267       1.5  dyoung 			}
    268       1.1  dyoung 			n = n->m_next;
    269       1.1  dyoung 			n->m_len = sizeof(crcbuf);
    270       1.1  dyoung 			noff = 0;
    271       1.1  dyoung 		}
    272       1.1  dyoung 		arc4_encrypt(ctx, mtod(n, caddr_t) + noff, crcbuf,
    273       1.1  dyoung 		    sizeof(crcbuf));
    274       1.1  dyoung 	} else {
    275       1.1  dyoung 		n->m_len = noff;
    276       1.1  dyoung 		for (noff = 0; noff < sizeof(crcbuf); noff += len) {
    277       1.1  dyoung 			len = sizeof(crcbuf) - noff;
    278       1.1  dyoung 			if (len > m->m_len - moff)
    279       1.1  dyoung 				len = m->m_len - moff;
    280       1.1  dyoung 			if (len > 0)
    281       1.1  dyoung 				arc4_encrypt(ctx, crcbuf + noff,
    282       1.1  dyoung 				    mtod(m, caddr_t) + moff, len);
    283       1.1  dyoung 			m = m->m_next;
    284       1.1  dyoung 			moff = 0;
    285       1.1  dyoung 		}
    286       1.1  dyoung 		if (crc != le32toh(*(u_int32_t *)crcbuf)) {
    287       1.1  dyoung #ifdef IEEE80211_DEBUG
    288       1.1  dyoung 			if (ieee80211_debug) {
    289       1.1  dyoung 				if_printf(ifp, "decrypt CRC error\n");
    290       1.1  dyoung 				if (ieee80211_debug > 1)
    291       1.1  dyoung 					ieee80211_dump_pkt(n0->m_data,
    292       1.1  dyoung 					    n0->m_len, -1, -1);
    293       1.1  dyoung 			}
    294       1.1  dyoung #endif
    295       1.5  dyoung 			ic->ic_stats.is_rx_decryptcrc++;
    296       1.1  dyoung 			goto fail;
    297       1.1  dyoung 		}
    298       1.1  dyoung 	}
    299       1.1  dyoung 	m_freem(m0);
    300       1.1  dyoung 	return n0;
    301       1.1  dyoung 
    302       1.1  dyoung   fail:
    303       1.1  dyoung 	m_freem(m0);
    304       1.1  dyoung 	m_freem(n0);
    305       1.1  dyoung 	return NULL;
    306       1.1  dyoung }
    307       1.1  dyoung 
    308       1.1  dyoung /*
    309       1.1  dyoung  * CRC 32 -- routine from RFC 2083
    310       1.1  dyoung  */
    311       1.1  dyoung 
    312       1.1  dyoung /* Table of CRCs of all 8-bit messages */
    313       1.1  dyoung static u_int32_t ieee80211_crc_table[256];
    314       1.1  dyoung 
    315       1.1  dyoung /* Make the table for a fast CRC. */
    316       1.1  dyoung static void
    317       1.1  dyoung ieee80211_crc_init(void)
    318       1.1  dyoung {
    319       1.1  dyoung 	u_int32_t c;
    320       1.1  dyoung 	int n, k;
    321       1.1  dyoung 
    322       1.1  dyoung 	for (n = 0; n < 256; n++) {
    323       1.1  dyoung 		c = (u_int32_t)n;
    324       1.1  dyoung 		for (k = 0; k < 8; k++) {
    325       1.1  dyoung 			if (c & 1)
    326       1.1  dyoung 				c = 0xedb88320UL ^ (c >> 1);
    327       1.1  dyoung 			else
    328       1.1  dyoung 				c = c >> 1;
    329       1.1  dyoung 		}
    330       1.1  dyoung 		ieee80211_crc_table[n] = c;
    331       1.1  dyoung 	}
    332       1.1  dyoung }
    333       1.1  dyoung 
    334       1.1  dyoung /*
    335       1.1  dyoung  * Update a running CRC with the bytes buf[0..len-1]--the CRC
    336       1.1  dyoung  * should be initialized to all 1's, and the transmitted value
    337       1.1  dyoung  * is the 1's complement of the final running CRC
    338       1.1  dyoung  */
    339       1.1  dyoung 
    340       1.1  dyoung static u_int32_t
    341       1.1  dyoung ieee80211_crc_update(u_int32_t crc, u_int8_t *buf, int len)
    342       1.1  dyoung {
    343       1.1  dyoung 	u_int8_t *endbuf;
    344       1.1  dyoung 
    345       1.1  dyoung 	for (endbuf = buf + len; buf < endbuf; buf++)
    346       1.1  dyoung 		crc = ieee80211_crc_table[(crc ^ *buf) & 0xff] ^ (crc >> 8);
    347       1.1  dyoung 	return crc;
    348       1.1  dyoung }
    349