2 * QEMU Crypto PBKDF support (Password-Based Key Derivation Function)
4 * Copyright (c) 2015-2016 Red Hat, Inc.
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2 of the License, or (at your option) any later version.
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
21 #include "qemu/osdep.h"
22 #include "crypto/pbkdf.h"
24 #include <sys/resource.h>
28 static int qcrypto_pbkdf2_get_thread_cpu(unsigned long long *val_ms
,
32 FILETIME creation_time
, exit_time
, kernel_time
, user_time
;
33 ULARGE_INTEGER thread_time
;
35 if (!GetThreadTimes(GetCurrentThread(), &creation_time
, &exit_time
,
36 &kernel_time
, &user_time
)) {
37 error_setg(errp
, "Unable to get thread CPU usage");
41 thread_time
.LowPart
= user_time
.dwLowDateTime
;
42 thread_time
.HighPart
= user_time
.dwHighDateTime
;
44 /* QuadPart is units of 100ns and we want ms as unit */
45 *val_ms
= thread_time
.QuadPart
/ 10000ll;
47 #elif defined(RUSAGE_THREAD)
49 if (getrusage(RUSAGE_THREAD
, &ru
) < 0) {
50 error_setg_errno(errp
, errno
, "Unable to get thread CPU usage");
54 *val_ms
= ((ru
.ru_utime
.tv_sec
* 1000ll) +
55 (ru
.ru_utime
.tv_usec
/ 1000));
59 error_setg(errp
, "Unable to calculate thread CPU usage on this platform");
64 int qcrypto_pbkdf2_count_iters(QCryptoHashAlgorithm hash
,
65 const uint8_t *key
, size_t nkey
,
66 const uint8_t *salt
, size_t nsalt
,
70 long long int iterations
= (1 << 15);
71 unsigned long long delta_ms
, start_ms
, end_ms
;
74 if (qcrypto_pbkdf2_get_thread_cpu(&start_ms
, errp
) < 0) {
77 if (qcrypto_pbkdf2(hash
,
85 if (qcrypto_pbkdf2_get_thread_cpu(&end_ms
, errp
) < 0) {
89 delta_ms
= end_ms
- start_ms
;
93 } else if (delta_ms
< 100) {
94 iterations
= iterations
* 10;
96 iterations
= (iterations
* 1000 / delta_ms
);
100 iterations
= iterations
* 1000 / delta_ms
;
102 if (iterations
> INT32_MAX
) {
103 error_setg(errp
, "Iterations %lld too large for a 32-bit int",