From patchwork Tue Aug 28 13:01:03 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Akhil Goyal X-Patchwork-Id: 43925 X-Patchwork-Delegate: gakhil@marvell.com Return-Path: X-Original-To: patchwork@dpdk.org Delivered-To: patchwork@dpdk.org Received: from [92.243.14.124] (localhost [127.0.0.1]) by dpdk.org (Postfix) with ESMTP id DF1234C72; Tue, 28 Aug 2018 15:04:19 +0200 (CEST) Received: from EUR03-VE1-obe.outbound.protection.outlook.com (mail-eopbgr50081.outbound.protection.outlook.com [40.107.5.81]) by dpdk.org (Postfix) with ESMTP id 4177A98 for ; Tue, 28 Aug 2018 15:04:17 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nxp.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=XZHmG7tjKPOBc4bkl+QhsAxXn+dzrGi1y44G5Ki/vWM=; b=rWgukgBl3XjsUS0a97idAnxJ5fvf5MauobhxlGQERSuXqK7RzKss7HycHsHQ5qB63Nt6z8lz4lQBKtOSnLaF0g1sQ77ovpaf4uloXQoVZoAR6XJChldKM0IfSKCDBPBrR6YbI1yTgoSjN3xZ5eF1ddW2wKJwDQPVzHC4OrZz9Os= Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=akhil.goyal@nxp.com; Received: from GDB1.ap.freescale.net (14.143.30.134) by VI1PR04MB1390.eurprd04.prod.outlook.com (2a01:111:e400:5348::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1080.17; Tue, 28 Aug 2018 13:04:15 +0000 From: akhil.goyal@nxp.com To: dev@dpdk.org Cc: Akhil Goyal Date: Tue, 28 Aug 2018 18:31:03 +0530 Message-Id: <20180828130105.30779-2-akhil.goyal@nxp.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20180828130105.30779-1-akhil.goyal@nxp.com> References: <20180828130105.30779-1-akhil.goyal@nxp.com> MIME-Version: 1.0 X-Originating-IP: [14.143.30.134] X-ClientProxiedBy: MAXPR0101CA0046.INDPRD01.PROD.OUTLOOK.COM (2603:1096:a00:d::32) To VI1PR04MB1390.eurprd04.prod.outlook.com (2a01:111:e400:5348::21) X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 3cbd772d-b8bd-4f40-35b1-08d60ce6c242 X-MS-Office365-Filtering-HT: Tenant X-Microsoft-Antispam: BCL:0; PCL:0; RULEID:(7020095)(4652040)(8989137)(4534165)(7168020)(4627221)(201703031133081)(201702281549075)(8990107)(5600074)(711020)(4618075)(2017052603328)(7153060)(7193020); SRVR:VI1PR04MB1390; X-Microsoft-Exchange-Diagnostics: 1; VI1PR04MB1390; 3:PPcIX7rKb0giHx3/vetRFXDQwzseIAZE3X3ocelbCUcbkTPFrYE1zaIBlDnrRQDns9crnJjImCdZ9vpMpOQe3FlkeDPEtmC4bqbGLYhEPBBe0p941s50m8DKYU/asNhX5izHq6KEzni7oT0riMmF3URVYkUFeK6HwcAxR2B+FGVx0OiWeWAiglPtqVkMBQzJhIpf/yWAIebVmN3xi4oFmLpErnfxU6a81SD/MRsK2xhgEAK1u4b8+LpmUSSByX2t; 25:zLyGQgeA2MIctd/NNWwqUfM5Y3VopystgKIf6LUDfY4yFt2cf/pr2DNeIwnaldKPJR4G0wUgP2sPYtFTRcw9vBLQ/YwmFcrgnw50wYw0WPmWxD+wSYyos7/vVUrLO5ncPT+cFl3TtLT/D91YwiIxQ5yd2n+IYktzPAvr/mPP4QMHFTVkOfCkMcAnJdPeWBej3s8bGAnVFJFzjoh+Q0j6/O0FKS5uscqkFwMlzpEYfwN4+7MasV9V6F8RTaduWTjJFsv8KHQdRxjGJcjmfbuqWRalsXqfp4SuXzu5HYZfrAj8PI8fzW61ae5AKFuyJ1Y36Y/kMJdC+wFEBKghNyXDlQ==; 31:2R1pEJODesPk2YIaT+daVu0mvdU4w8xc0FHQKfbM93yDG6qL1SSL7l+7sPpHRBJRo7daCnucCOEgg27dy87PtATPVpahMhCMbVUB20Qx6BekpYAjsGw7bs2ELQmg9Ahs4OM7eZGKJFURS4LySbU7PfshR8X2UI0K4C5SfhRY/bxHEgif1ktGU0YRtvxbRWw62aY80t88oV+qgAxfpKvbsXs4aRsjrCxOVw8za+F+/eA= X-MS-TrafficTypeDiagnostic: VI1PR04MB1390: X-Microsoft-Exchange-Diagnostics: 1; VI1PR04MB1390; 20:HdvwIh8gGjFYFqyswXNBaEFb7GXZPPAn4BYeZxhjMohctMbxKCW7Lfo1No5xHlRs8aBrcCqfrBHT3CfI9UOkvopHcT5pURZaOL/eFWZu2jWiokG+Hz0ydx10DyKJlFlfC5O+e/CtLRWuRLoQ0/fglfO3zYVaFTSR9/uKS0MFHF/QnsQ/kCi/i/XIWvnwPuJHDjQwwBZ7VkgejAvAwW6VujkAFRzFTTvioQ5ZKX4+QIQFa8NCKrnrXZssyg5z0OxOwhEqpXDy7n+QrhfEBbhUeDZr8DJtvMrQjHvPuJtOFlWvbt9qjeFmVxI7VlORyQfQvGxMzN3D75DeQd1RfoeBZMyoPcHqrcajCnK2IzFiMancV6Q3lZXGpFGJeQT6WeuduRUbbGZXyv9rcv9KJ4z9bSqbtYBpULbft+9x8eHPYUkZen1v78YB4lsJju6l4+4F1o3AGkkLMB6JWk8YVkyenrVt30AqQ+nRquFSSnrha64dn7QYMHwG53pG+5Wl/1uA; 4:6Tmra6niDnDe8ONUafcHNolCIlsBOl5u6RHyyqHOMwB+Jcwy9u3FAqlHwIFzngrCJ7d06r9tmZvmcXbd6hnkNC63gI9Km4TDQFmj6AuU8kKqfYl4AjDD0YB6Z1NepMN7o6dX6x54VbyOPdUPQ8Ri5DBVDdjm2YpETU0g6TkTN76VS7J1k4+JzoffIZi1t4vpigc65i4uZa+ThVU8NWV/bVDIWYXuQSRKsbRpXM1QpPfHHwLq7Ibud6L/IvkN5bYmMpvsL0nWA79uD8mOml8SKMQB83VlNCvehnG24kydKvlcoVUZgM2JDYk1VimpNqW813kFE7wrr0DW+xOFYw8Vj1XTW2yJEMnHjaC5J6L35Oo= X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-Test: UriScan:(192374486261705)(185117386973197); X-MS-Exchange-SenderADCheck: 1 X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(823301075)(10201501046)(93006095)(93001095)(3231311)(944501410)(52105095)(3002001)(6055026)(149027)(150027)(6041310)(20161123564045)(20161123560045)(20161123562045)(20161123558120)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(201708071742011)(7699016); SRVR:VI1PR04MB1390; BCL:0; PCL:0; RULEID:; SRVR:VI1PR04MB1390; X-Forefront-PRVS: 077884B8B5 X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(39860400002)(346002)(136003)(376002)(366004)(396003)(189003)(199004)(5009440100003)(8676002)(55236004)(97736004)(316002)(186003)(26005)(15650500001)(6506007)(386003)(50466002)(50226002)(51416003)(16526019)(16586007)(48376002)(76176011)(8936002)(478600001)(52116002)(33896004)(53936002)(25786009)(956004)(47776003)(2351001)(6666003)(7736002)(14444005)(36756003)(85782001)(1076002)(5660300001)(2361001)(11346002)(105586002)(9686003)(66066001)(6512007)(446003)(2906002)(106356001)(305945005)(486006)(4326008)(81156014)(81166006)(68736007)(6486002)(2616005)(476003)(6916009)(86362001)(575784001)(6116002)(3846002)(110426005)(85772001); DIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR04MB1390; H:GDB1.ap.freescale.net; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1; Received-SPF: None (protection.outlook.com: nxp.com does not designate permitted sender hosts) X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1; VI1PR04MB1390; 23:DHoaucf7avJDk/Fi81bYyst33WK6wlD3LdMuXmXbM?= PP8yrF8FlkYmtGJSXoDbKNcIlFywZy6MEyBNup3E9lZRiN8M3S5IVDLLCL+ZttaYFvGiAr1Anziuf88TlO1DKO5VQGRBYlfBPEh8WhcVyTGw7EPSgN2PkXDOID9Cu2ABkjuqHzR++3Lpr/q/pWbSL39cpwSWtSkWk60sF6qJmxNvW+YhghWagKA384fdvVNTXARMFk45k1Msj1cNCsQ/n4BP/Vax2Oo8pAzRZBDDS22YZ3sjnfulc1ejjXVzqRdkLHQNRJrao9nAWmojW9+J+G8CwYUlUGu0dsr7ipZ6ZnCrqNaZedMOuGzCLkxa1X1b7bUb34mUJAF1EGvfeIlDjN6yoOopyz6DjdBZU9gHWyV/b6YXSiKBwlkcBukH/MMuQRbgz1TfhVmwTX4c0RIi8/eZnP0WHw7H4xnrtaU2j0xEl1Z/BWlfPRG/VLaANrK9chNTyn+j3lA/HqNcc4+NddPGkmzZPTlEN1zOZajx0Xg+Vs3tC0lsScmkg73XGn7hXnPas7xhyaXf9P11uxzYLgBMIt3ET8OEf81ReBH/Fp6M8miPFMic11/+hPpB58Kf5wjKnlZrp4zrYBBJJkjU0zSHlTGp7RKI1S4nIjng+sWG29kurTCbqNPyZen1GCu7iIs4SyBf5tyO/TdJF3XQvinFOgOuU8Vrf7XfnBdYwpw88vcKwflakziuxdFpAqUoBG6wOYVpyocrt8OVuG0pHmsP2IK6i8ub+VUXNJskIIwSlmmNDH+g9qt1J+g4HSscskN7QFpQP6uDAcdbEwfbq3YTpH7P4mC+gNBXsSmC6cNo9MRkghMH1xR80kN6KXeAOrhGC0g7mBN8oGNM3lOJzllwAloPWUUz8CFI375b5xUQse6u7wMha61nq3VQXSInerNkaaT0m17tYcSg07ODyu2VjARryt5xjrmTL1n/QjixSDOvCYmgT1nbaovsp+VeLopCOBsVK9QsxqbsqTfOMrasJrPyeHmyunIEISlwdsQhAylqY4rsUEEZRub/CSo2XA0HgY/1DJ9dUn0VNICag8UJ5yq7Vr3srhmzlcEEBWR2exR9rHXnXsWUcw/LotO5HrCHBrBlFJzbX0Q8F6QTrRTaxFjXONwY4g5xHNEQrlV730dEzsvydrt3L57OAaxozGZ9t/GZAXdkna7GQ20MrUveVbgrhLdecB2W+9bovw4Wf2/xiqCJGtZeCRTV5/ufPEv5NHZW/cs9WDI0pDwxJT4oJOgknwc0aB9+e4JJVRA3CUMo3Icp8aGzVzQJs2DKoI83LAA5YmE1C3w4calX/cJQmMozzWbSwYD7XDJhszCaD32p7sd/FRsJwj4ZZVA0HTPHXZmX/Hro8FeGtWiqaF0DnAa/qLE+6UDx1qQENNqDU6jGSY3nH5M7SVBj1u4xeuxvQUkZURi3N0ajy6LX002 X-Microsoft-Antispam-Message-Info: T5krZaZGLqIUkMvkMf70zAZLkKoLw6C4oIP/1sG7PQ1ADSUokmydkFaiN40LtNAXTzAzMvYwcxKxzJAn3sDlK5b+0BBunr67WRShQAuI6GoKol+Nzt0bt1Rpm/JstbYW9RaOIA7F/q0+QxTqOHEo/e5sL/GqfE41PzSEUdcdN3RH0Qch+m31tfZ0cgmKQOrA8fq7JpFFCjrnT0WqukeWKwDomga3fp08vNzi2NS+6XkuK0z1E7DQBVl4QGTQ/05UyrpShRdVJHvNJyxgpJgvKVupuuhPoZSe7x+Q4cg+HbEhhZ2GuzJW5Qjs6aJUGbu3wxoOTV03diOrnfFZCvp+TwdDUyGlwnrn4p5o9HjTb+w= X-Microsoft-Exchange-Diagnostics: 1; VI1PR04MB1390; 6:igLpKWibKSkxtDqSbrjllOhHTdsMmdfWscHX4jZrW1ScO2mqHcgqztkaHxuL4/54o1xOsi/awx+KIfLS0+ZdsveDtx5LHMMzBQm5t+EcFfMbQCOQnICJAIyT5qXiwvoob5nQyUdBZh4AUo3WUHjspZc0ECP8b4j3+527muvzyQYxgcMXNHQZxdD7JrEHu52dx11h2BxZtvAsWgGU/RbSHUUvXLNaQosXkMJXpYVdFD2g/0PmgPeEgaQJVaowIP+kG6BdUqsE3FssxVFoP7Hfea1DP0CCZaPwqBpD0uTO/J2vzznfn0cs6djHSzRvIbvb6HtEJophpe8raSQ+s+6zEV/mKfIbulfKuuJm/lm9hoPKksLSw3BkxANN9e8auAWJuWclXbYn5dw4XGVr0u+VElgwQ3vi9KmfT3i4JOx3DiQmG18PLZnop/kx23nNDVuXpn0xvOAU3EhXZjJzb9cyOA==; 5:Suf/1QqFa401tGUtmWcgZOE2pEIn+8f13ghd5842HsiK1qNq6e+WCpsRQB0Lp6OhV2oRszovzkZdurhKJJHCFdDci0VdrsX7gjr5FGXqv8jLa9c4Z5/JaLDvCeFSI96oPSPRbsLsduJRas8uCHtBoxaGsV+ZeB7unaJ7E7pcBP0=; 7:g5jZtW8JcHPCgmpdABe9cYIh3+pbFb8IIJytaDgQHZBtQj5l20rPr3hqwIGjHNgePJfmuXNwu6hsKw4UmBa/dvgMrKiEuWJcv80e9m8MnyenxEXFjbAu9UqMN8GsCseqCotVxs0YUtEAlX/qHeIUwO1702qn+SyaKTCoxkHuSW6o112dT//pgHCrNEVtx+M64y7Whk0Bs7u8eJVWf67RdVObr7+22isSDKaHN1C09wLsrOFwK0i/aDZVtx1sJu6P SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-OriginatorOrg: nxp.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Aug 2018 13:04:15.1076 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 3cbd772d-b8bd-4f40-35b1-08d60ce6c242 X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 686ea1d3-bc2b-4c6f-a92c-d99c5c301635 X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR04MB1390 Subject: [dpdk-dev] [PATCH 1/3] security: support pdcp protocol X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Sender: "dev" From: Akhil Goyal Signed-off-by: Hemant Agrawal Signed-off-by: Akhil Goyal --- doc/guides/prog_guide/rte_security.rst | 90 ++++++++++++++++++++++++-- lib/librte_security/rte_security.c | 4 ++ lib/librte_security/rte_security.h | 62 ++++++++++++++++++ 3 files changed, 149 insertions(+), 7 deletions(-) diff --git a/doc/guides/prog_guide/rte_security.rst b/doc/guides/prog_guide/rte_security.rst index 0812abe77..412fff016 100644 --- a/doc/guides/prog_guide/rte_security.rst +++ b/doc/guides/prog_guide/rte_security.rst @@ -10,8 +10,8 @@ The security library provides a framework for management and provisioning of security protocol operations offloaded to hardware based devices. The library defines generic APIs to create and free security sessions which can support full protocol offload as well as inline crypto operation with -NIC or crypto devices. The framework currently only supports the IPSec protocol -and associated operations, other protocols will be added in future. +NIC or crypto devices. The framework currently only supports the IPSec and PDCP +protocol and associated operations, other protocols will be added in future. Design Principles ----------------- @@ -253,6 +253,46 @@ for any protocol header addition. +--------|--------+ V +PDCP Flow Diagram +~~~~~~~~~~~~~~~~~ + +.. code-block:: c + + Transmitting PDCP Entity Receiving PDCP Entity + | ^ + | +-----------|-----------+ + V | In order delivery and | + +---------|----------+ | Duplicate detection | + | Sequence Numbering | | (Data Plane only) | + +---------|----------+ +-----------|-----------+ + | | + +---------|----------+ +-----------|----------+ + | Header Compression*| | Header Decompression*| + | (Data-Plane only) | | (Data Plane only) | + +---------|----------+ +-----------|----------+ + | | + +---------|-----------+ +-----------|----------+ + | Integrity Protection| |Integrity Verification| + | (Control Plane only)| | (Control Plane only) | + +---------|-----------+ +-----------|----------+ + +---------|-----------+ +----------|----------+ + | Ciphering | | Deciphering | + +---------|-----------+ +----------|----------+ + +---------|-----------+ +----------|----------+ + | Add PDCP header | | Remove PDCP Header | + +---------|-----------+ +----------|----------+ + | | + +----------------->>----------------+ + + +.. note:: + + * Header Compression and decompression are not supported currently. + +Just like IPSec, in case of PDCP also header addition/deletion, cipher/ +de-cipher, integrity protection/verification is done based on the action +type chosen. + Device Features and Capabilities --------------------------------- @@ -271,7 +311,7 @@ structure in the *DPDK API Reference*. Each driver (crypto or ethernet) defines its own private array of capabilities for the operations it supports. Below is an example of the capabilities for a -PMD which supports the IPSec protocol. +PMD which supports the IPSec and PDCP protocol. .. code-block:: c @@ -298,6 +338,22 @@ PMD which supports the IPSec protocol. }, .crypto_capabilities = pmd_capabilities }, + { /* PDCP Lookaside Protocol offload Data Plane */ + .action = RTE_SECURITY_ACTION_TYPE_LOOKASIDE_PROTOCOL, + .protocol = RTE_SECURITY_PROTOCOL_PDCP, + .pdcp = { + .domain = RTE_SECURITY_PDCP_MODE_DATA, + }, + .crypto_capabilities = pmd_capabilities + }, + { /* PDCP Lookaside Protocol offload Control */ + .action = RTE_SECURITY_ACTION_TYPE_LOOKASIDE_PROTOCOL, + .protocol = RTE_SECURITY_PROTOCOL_PDCP, + .pdcp = { + .domain = RTE_SECURITY_PDCP_MODE_CONTROL, + }, + .crypto_capabilities = pmd_capabilities + }, { .action = RTE_SECURITY_ACTION_TYPE_NONE } @@ -429,6 +485,7 @@ Security Session configuration structure is defined as ``rte_security_session_co union { struct rte_security_ipsec_xform ipsec; struct rte_security_macsec_xform macsec; + struct rte_security_pdcp_xform pdcp; }; /**< Configuration parameters for security session */ struct rte_crypto_sym_xform *crypto_xform; @@ -463,15 +520,17 @@ The ``rte_security_session_protocol`` is defined as .. code-block:: c enum rte_security_session_protocol { - RTE_SECURITY_PROTOCOL_IPSEC, + RTE_SECURITY_PROTOCOL_IPSEC = 1, /**< IPsec Protocol */ RTE_SECURITY_PROTOCOL_MACSEC, /**< MACSec Protocol */ + RTE_SECURITY_PROTOCOL_PDCP, + /**< PDCP Protocol */ }; -Currently the library defines configuration parameters for IPSec only. For other -protocols like MACSec, structures and enums are defined as place holders which -will be updated in the future. +Currently the library defines configuration parameters for IPSec and PDCP only. +For other protocols like MACSec, structures and enums are defined as place holders +which will be updated in the future. IPsec related configuration parameters are defined in ``rte_security_ipsec_xform`` @@ -494,6 +553,23 @@ IPsec related configuration parameters are defined in ``rte_security_ipsec_xform /**< Tunnel parameters, NULL for transport mode */ }; +PDCP related configuration parameters are defined in ``rte_security_pdcp_xform`` + +.. code-block:: c + + struct rte_security_pdcp_xform { + int8_t bearer; /**< PDCP bearer ID */ + enum rte_security_pdcp_domain domain; + /** < PDCP mode of operation: Control or data */ + enum rte_security_pdcp_direction pkt_dir; + /**< PDCP Frame Direction 0:UL 1:DL */ + enum rte_security_pdcp_sn_size sn_size; + /**< Sequence number size, 5/7/12/15 */ + int8_t hfn_ovd; /**< Overwrite HFN per operation */ + uint32_t hfn; /**< Hyper Frame Number */ + uint32_t hfn_threshold; /**< HFN Threashold for key renegotiation */ + }; + Security API ~~~~~~~~~~~~ diff --git a/lib/librte_security/rte_security.c b/lib/librte_security/rte_security.c index 1954960a5..c6355de95 100644 --- a/lib/librte_security/rte_security.c +++ b/lib/librte_security/rte_security.c @@ -131,6 +131,10 @@ rte_security_capability_get(struct rte_security_ctx *instance, capability->ipsec.direction == idx->ipsec.direction) return capability; + } else if (idx->protocol == RTE_SECURITY_PROTOCOL_PDCP) { + if (capability->pdcp.domain == + idx->pdcp.domain) + return capability; } } } diff --git a/lib/librte_security/rte_security.h b/lib/librte_security/rte_security.h index b0d1b97ee..e625bc656 100644 --- a/lib/librte_security/rte_security.h +++ b/lib/librte_security/rte_security.h @@ -206,6 +206,52 @@ struct rte_security_macsec_xform { int dummy; }; +/** + * PDCP Mode of session + */ +enum rte_security_pdcp_domain { + RTE_SECURITY_PDCP_MODE_CONTROL, /**< PDCP control plane */ + RTE_SECURITY_PDCP_MODE_DATA, /**< PDCP data plane */ +}; + +/** PDCP Frame direction */ +enum rte_security_pdcp_direction { + RTE_SECURITY_PDCP_UPLINK, /**< Uplink */ + RTE_SECURITY_PDCP_DOWNLINK, /**< Downlink */ +}; + +/** + * PDCP Sequence Number Size selectors + * @PDCP_SN_SIZE_5: 5bit sequence number + * @PDCP_SN_SIZE_7: 7bit sequence number + * @PDCP_SN_SIZE_12: 12bit sequence number + * @PDCP_SN_SIZE_15: 15bit sequence number + */ +enum rte_security_pdcp_sn_size { + RTE_SECURITY_PDCP_SN_SIZE_5 = 5, + RTE_SECURITY_PDCP_SN_SIZE_7 = 7, + RTE_SECURITY_PDCP_SN_SIZE_12 = 12, + RTE_SECURITY_PDCP_SN_SIZE_15 = 15 +}; + +/** + * PDCP security association configuration data. + * + * This structure contains data required to create a PDCP security session. + */ +struct rte_security_pdcp_xform { + int8_t bearer; /**< PDCP bearer ID */ + enum rte_security_pdcp_domain domain; + /** < PDCP mode of operation: Control or data */ + enum rte_security_pdcp_direction pkt_dir; + /**< PDCP Frame Direction 0:UL 1:DL */ + enum rte_security_pdcp_sn_size sn_size; + /**< Sequence number size, 5/7/12/15 */ + int8_t hfn_ovd; /**< Overwrite HFN per operation */ + uint32_t hfn; /**< Hyper Frame Number */ + uint32_t hfn_threshold; /**< HFN Threashold for key renegotiation */ +}; + /** * Security session action type. */ @@ -232,6 +278,8 @@ enum rte_security_session_protocol { /**< IPsec Protocol */ RTE_SECURITY_PROTOCOL_MACSEC, /**< MACSec Protocol */ + RTE_SECURITY_PROTOCOL_PDCP, + /**< PDCP Protocol */ }; /** @@ -246,6 +294,7 @@ struct rte_security_session_conf { union { struct rte_security_ipsec_xform ipsec; struct rte_security_macsec_xform macsec; + struct rte_security_pdcp_xform pdcp; }; /**< Configuration parameters for security session */ struct rte_crypto_sym_xform *crypto_xform; @@ -413,6 +462,10 @@ struct rte_security_ipsec_stats { }; +struct rte_security_pdcp_stats { + uint64_t reserved; +}; + struct rte_security_stats { enum rte_security_session_protocol protocol; /**< Security protocol to be configured */ @@ -421,6 +474,7 @@ struct rte_security_stats { union { struct rte_security_macsec_stats macsec; struct rte_security_ipsec_stats ipsec; + struct rte_security_pdcp_stats pdcp; }; }; @@ -465,6 +519,11 @@ struct rte_security_capability { int dummy; } macsec; /**< MACsec capability */ + struct { + enum rte_security_pdcp_domain domain; + /** < PDCP mode of operation: Control or data */ + } pdcp; + /**< PDCP capability */ }; const struct rte_cryptodev_capabilities *crypto_capabilities; @@ -506,6 +565,9 @@ struct rte_security_capability_idx { enum rte_security_ipsec_sa_mode mode; enum rte_security_ipsec_sa_direction direction; } ipsec; + struct { + enum rte_security_pdcp_domain domain; + } pdcp; }; };