You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Removed support for legacy Makefile-based builds and legacy Windows .mak build scripts.
Updated CI workflows, project documentation, and RPM packaging instructions to use CMake-only build flows.
Updated GCC and Clang builds to use the C11 standard, aligning them with the MSVC builds.
Replaced full BSD-3-Clause license text in source files with SPDX license identifiers.
Added imb-provider, an OpenSSL 3.x test provider built on top of the library, supporting
AES, SM4, ChaCha20, Poly1305, ChaCha20-Poly1305, SHA, HMAC-SHA, ML-DSA and ML-KEM
operations, including asynchronous operation support.
Library
Changed library initialization to fail closed on self-test failure: all job, burst, direct and
ML-KEM/ML-DSA APIs on the affected manager perform no operation, produce no output and report IMB_ERR_SELFTEST (previously only the error code was set and the APIs remained operational).
A subsequent successful init_mb_mgr_*() call restores the manager.
Added AVX10 architecture, based primarily on AVX512 implementations with
some AVX2 Type 4 implementations for some algorithms.
Post-Quantum Cryptography (PQC) support added:
Added ML-DSA (FIPS 204) support for ML-DSA-44, ML-DSA-65 and ML-DSA-87.
Added ML-KEM (FIPS 203) support for ML-KEM-512, ML-KEM-768 and ML-KEM-1024 with new AVX2
NTT optimization.
SHA3 and SHAKE support added:
Added SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, HMAC-SHA3-224,
HMAC-SHA3-256, HMAC-SHA3-384 and HMAC-SHA3-512 base and AVX512 implementations,
including single buffer and 4-lane multi-buffer variants.
Added AVX2 4-lane multi-buffer implementations of SHA3-224, SHA3-256, SHA3-384,
SHA3-512, SHAKE128 and SHAKE256.
Added new AVX2 type 2 implementations for AES-CFB, AES-CBC, AES-CMAC, AES-CCM and CRC
implementations using VPCLMULQDQ 256-bit polynomial folding for all CRC types.
New wireless algorithm implementations:
Added ZUC-NEA6 SSE, AVX2 and AVX512 implementations.
Added ZUC-NIA6 SSE type 1 and AVX512 type 2 implementations.
Added ZUC-NCA6 SSE type 1, SSE type 3 and AVX512 type 2 implementations.
Added SNOW5G-NEA4 SSE type 1 and AVX512 type 2 implementations.
Added SNOW5G-NIA4 SSE type 1 and AVX512 type 2 implementations.
Added SNOW5G-NCA4 SSE type 1 and AVX512 type 2 implementations.
Added AES-NEA5 SSE, AVX2 and AVX512 implementations.
Added AES-NIA5 SSE type 1 and AVX512 type 2 implementations.
Added AES-NCA5 SSE type 1 and AVX512 type 2 implementations.
Added new SSE type 1 implementation of DES block encryption that is used in
DES, DOCSIS-DES and 3DES/TDES algorithms across SSE and AVX2 architecture types.
Added support for variable sized tags (from 4 to 20 bytes) for HMAC-SHA1.
Added support for zero-length messages in HMAC-SHA, HMAC-SHA3, HMAC-MD5 and HMAC-SM3 algorithms.
Added support for zero-length messages in AES-CBC.
Added message length limit check (2^16 - 2 bytes) for AES-CBC and AES-CFB encrypt direction jobs.
Added CONSTANT_TIME_VALIDATION build option that marks secret data for Valgrind
memcheck, so that secret dependent branches and memory accesses in the ML-DSA,
ML-KEM and job APIs are reported at run time. Validation is limited by Valgrind's ISA support and
is currently applicable only to code paths using instruction sets up to AVX2.
API changes:
Restricted des_cfb_one() to partial blocks (0 to 7 bytes).
Changed des_cfb_one() to return operation status.
Changed imb_aes128_cfb_one() and imb_aes256_cfb_one() to return operation status.
Removed features:
Removed AES-CTR bit-length variant.
Removed AES-CBCS 1:9 cipher.
Removed SNOW-V cipher together with AEAD SNOW-V.
Removed ZUC-EEA3-256 and ZUC-EIA3-256 algorithms.
Removed non-byte-aligned message length/offset support from wireless job APIs and
direct APIs (AES-CMAC, ZUC-EIA3, SNOW3G-UIA2/UEA2, KASUMI-UEA1).
Removed ZUC-EEA3 and ZUC-EIA3 direct API support. The algorithms remain available
through the job API.
Removed SNOW3G-UEA2 and SNOW3G-UIA2 direct API support. The algorithms remain
available through the job API.
Removed KASUMI-F8 and KASUMI-F9 direct API support. The algorithms remain available
through the job API.
Removed CRC direct API support. All CRC types remain available through the job API.
Removed QUIC API support.
Removed custom cipher mode support (IMB_CIPHER_CUSTOM and IMB_JOB::cipher_func).
Removed custom hash algorithm support (IMB_AUTH_CUSTOM and IMB_JOB::hash_func).
Test Applications
Added new mp-app test applications for testing primary/secondary process scenario and
crypto job handover.
Added new imb-safe-check application scanning all algorithms, message sizes,
cipher directions and job numbers for sensitive data left in registers and memory.
Removed --safe-check and --safe-retries options from imb-xvalid application
(functionality moved to imb-safe-check application).
Added new imb-oob application that detects out-of-bounds reads and writes past
declared message boundaries by placing guard pages next to job buffers. It covers
single job, type-specific burst and generic burst submit paths, as well as the
direct ML-DSA and ML-KEM APIs.
Added new zero length message test application.
Added zero-length job acceptance checks to the checked submit paths of the imb-zerolen application, so that jobs rejected by parameter validation can
no longer be reported as passing memory safety coverage.
Added zero-length message HMAC-SHA and HMAC-MD5 test vectors.
Added ABI check application to verify callee-saved registers are correctly preserved.
Added SHA3, SHAKE and HMAC-SHA3 support to imb-kat, imb-xvalid and imb-acvp applications.
Added mixed SHA3/SHAKE algorithm batch test to imb-kat application.
Added ML-DSA (FIPS 204) support for ML-DSA-44, ML-DSA-65 and ML-DSA-87 to imb-kat
and imb-acvp applications.
Added ML-KEM (FIPS 203) support for ML-KEM-512, ML-KEM-768 and ML-KEM-1024 to imb-kat
and imb-acvp applications.
Added ML-DSA and ML-KEM API fuzz tests to the fuzz application.
Added functional tests for the imb-provider OpenSSL provider, covering supported
cipher, hash, HMAC and PQC operations as well as asynchronous operation.
Added --offset parameter to imb-xvalid application.
Added AVX10 architecture support.
Removed imb-wycheproof application. Its Project Wycheproof test vectors were
converted to JSON and are now run by imb-kat as part of the AES-GCM, AES-CCM,
CHACHA20-POLY1305, AES-CMAC, AES-GMAC and HMAC-SHA test types, across all
supported architectures.
Updated the Project Wycheproof test vectors to the upstream v1 vector set,
adding 154 new test cases.
Removed bit-length message/offset test coverage paths for wireless algorithms and
switched applications to byte-only lengths.
Removed AES-CTR bit-length variant.
Removed AES-CBCS 1:9 cipher.
Removed SNOW-V cipher together with AEAD SNOW-V.
Removed custom cipher mode test coverage.
Removed custom hash algorithm test coverage.
Performance Applications
Added AVX10 architecture support.
Added SHA3/SHAKE support to imb-perf application.
Added imb-speed-pqc application for benchmarking PQC algorithms.
Added imb-perf-cmp.py tool that compares post processed performance metrics.
Added imb-slope-to-stat.pl, imb-stat-algo-report.pl and imb-stat-avg.pl scripts.
Added --skip option to imb-perf-tool.py to skip specific algorithms.
Renamed ipsec_perf_tool.py to imb-perf-tool.py.
Modified --cores option to accept a list of cores instead of a coremask.
Improved stability of imb-perf application.
Removed AES-CTR bit-length variant.
Removed AES-CBCS 1:9 cipher.
Removed SNOW-V cipher together with AEAD SNOW-V.
Removed QUIC API tests.
Tools
Added asm-format.py tool that formats assembly source files.
Added asm-cov.py tool that produces x86 assembly line and branch coverage reports.
Added special-chars.py tool, with special-chars and special-chars-fix build
targets, that detects and replaces non-ASCII characters in source files.
Fixed MD5-HMAC in performance application (wrong test-algo mapping).
Fixed AES-GCM key structure alignment.
Fixed AES-GCM, AES-GCM-SGL and SM4-GCM decrypt direction to use dec_keys key pointer consistently across all implementations.
Fixed PON XGEM PLI validation not being applied when msg_len_to_cipher_in_bytes is 0 (no AES-CTR case). An oversized PLI could result in out-of-bounds read and write access.