From: Emma Finn <emma.finn@intel.com>
To: Kai Ji <kai.ji@intel.com>,
Pablo de Lara <pablo.de.lara.guarch@intel.com>
Cc: dev@dpdk.org, Emma Finn <emma.finn@intel.com>
Subject: [PATCH 1/2] crypto/ipsec_mb: Add SHA3 support.
Date: Mon, 5 Oct 2026 12:30:39 +0000 [thread overview]
Message-ID: <20261005123041.429121-1-emma.finn@intel.com> (raw)
Add SHA3-224, SHA3-256, SHA3-384, SHA3-512 and HMAC variants
to the ipsec_mb PMD.
Signed-off-by: Emma Finn <emma.finn@intel.com>
---
doc/guides/cryptodevs/aesni_mb.rst | 8 +
doc/guides/cryptodevs/features/aesni_mb.ini | 8 +
doc/guides/rel_notes/release_26_11.rst | 5 +
drivers/crypto/ipsec_mb/pmd_aesni_mb.c | 29 +++
drivers/crypto/ipsec_mb/pmd_aesni_mb_priv.h | 219 +++++++++++++++++++-
5 files changed, 259 insertions(+), 10 deletions(-)
diff --git a/doc/guides/cryptodevs/aesni_mb.rst b/doc/guides/cryptodevs/aesni_mb.rst
index ab7a6138a8e..663b9f19d4b 100644
--- a/doc/guides/cryptodevs/aesni_mb.rst
+++ b/doc/guides/cryptodevs/aesni_mb.rst
@@ -61,6 +61,14 @@ Hash algorithms:
* RTE_CRYPTO_AUTH_KASUMI_F9
* RTE_CRYPTO_AUTH_SM3
* RTE_CRYPTO_AUTH_SM3 HMAC
+* RTE_CRYPTO_AUTH_SHA3_224
+* RTE_CRYPTO_AUTH_SHA3_224 HMAC
+* RTE_CRYPTO_AUTH_SHA3_256
+* RTE_CRYPTO_AUTH_SHA3_256 HMAC
+* RTE_CRYPTO_AUTH_SHA3_384
+* RTE_CRYPTO_AUTH_SHA3_384 HMAC
+* RTE_CRYPTO_AUTH_SHA3_512
+* RTE_CRYPTO_AUTH_SHA3_512 HMAC
AEAD algorithms:
diff --git a/doc/guides/cryptodevs/features/aesni_mb.ini b/doc/guides/cryptodevs/features/aesni_mb.ini
index ce6b43e48bd..ff7fcceb036 100644
--- a/doc/guides/cryptodevs/features/aesni_mb.ini
+++ b/doc/guides/cryptodevs/features/aesni_mb.ini
@@ -69,6 +69,14 @@ SNOW3G UIA2 = Y
KASUMI F9 = Y
SM3 = Y
SM3 HMAC = Y
+SHA3-224 = Y
+SHA3-224 HMAC = Y
+SHA3-256 = Y
+SHA3-256 HMAC = Y
+SHA3-384 = Y
+SHA3-384 HMAC = Y
+SHA3-512 = Y
+SHA3-512 HMAC = Y
;
; Supported AEAD algorithms of the 'aesni_mb' crypto driver.
diff --git a/doc/guides/rel_notes/release_26_11.rst b/doc/guides/rel_notes/release_26_11.rst
index c8cc86295da..826a0cf05cf 100644
--- a/doc/guides/rel_notes/release_26_11.rst
+++ b/doc/guides/rel_notes/release_26_11.rst
@@ -24,6 +24,11 @@ DPDK Release 26.11
New Features
------------
+* **Updated AESNI_MB crypto driver.**
+
+ * Added support for SHA3-224, SHA3-256, SHA3-384, and SHA3-512 hash
+ algorithms and their HMAC variants.
+
.. This section should contain new features added in this release.
Sample format:
diff --git a/drivers/crypto/ipsec_mb/pmd_aesni_mb.c b/drivers/crypto/ipsec_mb/pmd_aesni_mb.c
index 4c5b6e70b51..a63f9671528 100644
--- a/drivers/crypto/ipsec_mb/pmd_aesni_mb.c
+++ b/drivers/crypto/ipsec_mb/pmd_aesni_mb.c
@@ -302,6 +302,35 @@ aesni_mb_set_session_auth_parameters(IMB_MGR *mb_mgr,
case RTE_CRYPTO_AUTH_SM3_HMAC:
sess->template_job.hash_alg = IMB_AUTH_HMAC_SM3;
break;
+#if IMB_VERSION(3, 0, 0) <= IMB_VERSION_NUM
+ case RTE_CRYPTO_AUTH_SHA3_224:
+ sess->template_job.hash_alg = IMB_AUTH_SHA3_224;
+ auth_precompute = 0;
+ break;
+ case RTE_CRYPTO_AUTH_SHA3_224_HMAC:
+ sess->template_job.hash_alg = IMB_AUTH_HMAC_SHA3_224;
+ break;
+ case RTE_CRYPTO_AUTH_SHA3_256:
+ sess->template_job.hash_alg = IMB_AUTH_SHA3_256;
+ auth_precompute = 0;
+ break;
+ case RTE_CRYPTO_AUTH_SHA3_256_HMAC:
+ sess->template_job.hash_alg = IMB_AUTH_HMAC_SHA3_256;
+ break;
+ case RTE_CRYPTO_AUTH_SHA3_384:
+ sess->template_job.hash_alg = IMB_AUTH_SHA3_384;
+ auth_precompute = 0;
+ break;
+ case RTE_CRYPTO_AUTH_SHA3_384_HMAC:
+ sess->template_job.hash_alg = IMB_AUTH_HMAC_SHA3_384;
+ break;
+ case RTE_CRYPTO_AUTH_SHA3_512:
+ sess->template_job.hash_alg = IMB_AUTH_SHA3_512;
+ auth_precompute = 0;
+ break;
+ case RTE_CRYPTO_AUTH_SHA3_512_HMAC:
+ sess->template_job.hash_alg = IMB_AUTH_HMAC_SHA3_512;
+ break;
#endif
default:
IPSEC_MB_LOG(ERR,
diff --git a/drivers/crypto/ipsec_mb/pmd_aesni_mb_priv.h b/drivers/crypto/ipsec_mb/pmd_aesni_mb_priv.h
index 6dc90a98492..6fdb4b8e1fb 100644
--- a/drivers/crypto/ipsec_mb/pmd_aesni_mb_priv.h
+++ b/drivers/crypto/ipsec_mb/pmd_aesni_mb_priv.h
@@ -768,6 +768,176 @@ static const struct rte_cryptodev_capabilities aesni_mb_capabilities[] = {
}, }
}, }
},
+#if IMB_VERSION(3, 0, 0) <= IMB_VERSION_NUM
+ { /* SHA3-224 */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_SHA3_224,
+ .block_size = 144,
+ .key_size = {
+ .min = 0,
+ .max = 0,
+ .increment = 0
+ },
+ .digest_size = {
+ .min = 1,
+ .max = 28,
+ .increment = 1
+ },
+ .iv_size = { 0 }
+ }, }
+ }, }
+ },
+ { /* HMAC SHA3-224 */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_SHA3_224_HMAC,
+ .block_size = 144,
+ .key_size = {
+ .min = 1,
+ .max = 65535,
+ .increment = 1
+ },
+ .digest_size = {
+ .min = 1,
+ .max = 28,
+ .increment = 1
+ },
+ .iv_size = { 0 }
+ }, }
+ }, }
+ },
+ { /* SHA3-256 */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_SHA3_256,
+ .block_size = 136,
+ .key_size = {
+ .min = 0,
+ .max = 0,
+ .increment = 0
+ },
+ .digest_size = {
+ .min = 1,
+ .max = 32,
+ .increment = 1
+ },
+ .iv_size = { 0 }
+ }, }
+ }, }
+ },
+ { /* HMAC SHA3-256 */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_SHA3_256_HMAC,
+ .block_size = 136,
+ .key_size = {
+ .min = 1,
+ .max = 65535,
+ .increment = 1
+ },
+ .digest_size = {
+ .min = 1,
+ .max = 32,
+ .increment = 1
+ },
+ .iv_size = { 0 }
+ }, }
+ }, }
+ },
+ { /* SHA3-384 */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_SHA3_384,
+ .block_size = 104,
+ .key_size = {
+ .min = 0,
+ .max = 0,
+ .increment = 0
+ },
+ .digest_size = {
+ .min = 1,
+ .max = 48,
+ .increment = 1
+ },
+ .iv_size = { 0 }
+ }, }
+ }, }
+ },
+ { /* HMAC SHA3-384 */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_SHA3_384_HMAC,
+ .block_size = 104,
+ .key_size = {
+ .min = 1,
+ .max = 65535,
+ .increment = 1
+ },
+ .digest_size = {
+ .min = 1,
+ .max = 48,
+ .increment = 1
+ },
+ .iv_size = { 0 }
+ }, }
+ }, }
+ },
+ { /* SHA3-512 */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_SHA3_512,
+ .block_size = 72,
+ .key_size = {
+ .min = 0,
+ .max = 0,
+ .increment = 0
+ },
+ .digest_size = {
+ .min = 1,
+ .max = 64,
+ .increment = 1
+ },
+ .iv_size = { 0 }
+ }, }
+ }, }
+ },
+ { /* HMAC SHA3-512 */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_SHA3_512_HMAC,
+ .block_size = 72,
+ .key_size = {
+ .min = 1,
+ .max = 65535,
+ .increment = 1
+ },
+ .digest_size = {
+ .min = 1,
+ .max = 64,
+ .increment = 1
+ },
+ .iv_size = { 0 }
+ }, }
+ }, }
+ },
+#endif
{ /* SM4 CBC */
.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
{.sym = {
@@ -892,9 +1062,19 @@ static const unsigned int auth_blocksize[] = {
[IMB_AUTH_SHA_256] = 64,
[IMB_AUTH_SHA_384] = 128,
[IMB_AUTH_SHA_512] = 128,
- [IMB_AUTH_ZUC_EIA3_BITLEN] = 16,
- [IMB_AUTH_SNOW3G_UIA2_BITLEN] = 16,
- [IMB_AUTH_KASUMI_UIA1] = 16
+ [IMB_AUTH_ZUC_EIA3] = 16,
+ [IMB_AUTH_SNOW3G_UIA2] = 16,
+ [IMB_AUTH_KASUMI_UIA1] = 16,
+#if IMB_VERSION(3, 0, 0) <= IMB_VERSION_NUM
+ [IMB_AUTH_SHA3_224] = 144,
+ [IMB_AUTH_SHA3_256] = 136,
+ [IMB_AUTH_SHA3_384] = 104,
+ [IMB_AUTH_SHA3_512] = 72,
+ [IMB_AUTH_HMAC_SHA3_224] = 144,
+ [IMB_AUTH_HMAC_SHA3_256] = 136,
+ [IMB_AUTH_HMAC_SHA3_384] = 104,
+ [IMB_AUTH_HMAC_SHA3_512] = 72
+#endif
};
/**
@@ -926,9 +1106,19 @@ static const unsigned int auth_truncated_digest_byte_lengths[] = {
[IMB_AUTH_SHA_256] = 32,
[IMB_AUTH_SHA_384] = 48,
[IMB_AUTH_SHA_512] = 64,
- [IMB_AUTH_ZUC_EIA3_BITLEN] = 4,
- [IMB_AUTH_SNOW3G_UIA2_BITLEN] = 4,
- [IMB_AUTH_KASUMI_UIA1] = 4
+ [IMB_AUTH_ZUC_EIA3] = 4,
+ [IMB_AUTH_SNOW3G_UIA2] = 4,
+ [IMB_AUTH_KASUMI_UIA1] = 4,
+#if IMB_VERSION(3, 0, 0) <= IMB_VERSION_NUM
+ [IMB_AUTH_SHA3_224] = 28,
+ [IMB_AUTH_SHA3_256] = 32,
+ [IMB_AUTH_SHA3_384] = 48,
+ [IMB_AUTH_SHA3_512] = 64,
+ [IMB_AUTH_HMAC_SHA3_224] = 28,
+ [IMB_AUTH_HMAC_SHA3_256] = 32,
+ [IMB_AUTH_HMAC_SHA3_384] = 48,
+ [IMB_AUTH_HMAC_SHA3_512] = 64
+#endif
};
/**
@@ -967,6 +1157,15 @@ static const unsigned int auth_digest_byte_lengths[] = {
#if IMB_VERSION(1, 5, 0) <= IMB_VERSION_NUM
[IMB_AUTH_SM3] = 32,
[IMB_AUTH_HMAC_SM3] = 32,
+#if IMB_VERSION(3, 0, 0) <= IMB_VERSION_NUM
+ [IMB_AUTH_SHA3_224] = 28,
+ [IMB_AUTH_SHA3_256] = 32,
+ [IMB_AUTH_SHA3_384] = 48,
+ [IMB_AUTH_SHA3_512] = 64,
+ [IMB_AUTH_HMAC_SHA3_224] = 28,
+ [IMB_AUTH_HMAC_SHA3_256] = 32,
+ [IMB_AUTH_HMAC_SHA3_384] = 48,
+ [IMB_AUTH_HMAC_SHA3_512] = 64
#endif
/**< Vector mode dependent pointer table of the multi-buffer APIs */
@@ -1049,15 +1248,15 @@ struct __rte_cache_aligned aesni_mb_session {
/* *< auth operation generate or verify */
union {
struct {
- alignas(16) uint8_t inner[128];
+ alignas(16) uint8_t inner[144];
/* *< inner pad */
- alignas(16) uint8_t outer[128];
+ alignas(16) uint8_t outer[144];
/* *< outer pad */
} pads;
/* *< HMAC Authentication pads -
* allocating space for the maximum pad
- * size supported which is 128 bytes for
- * SHA512
+ * size supported which is 144 bytes for
+ * SHA3-224
*/
struct {
--
2.43.0
next reply other threads:[~2026-10-05 12:30 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 12:30 Emma Finn [this message]
2026-10-05 12:30 ` [PATCH 2/2] crypto/ipsec_mb: Add SHAKE support Emma Finn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005123041.429121-1-emma.finn@intel.com \
--to=emma.finn@intel.com \
--cc=dev@dpdk.org \
--cc=kai.ji@intel.com \
--cc=pablo.de.lara.guarch@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox