[RFC PATCH] crypto: add RSA-specific capability parameters

Radu Nicolau radu.nicolau at intel.com
Tue Aug 11 16:02:18 CEST 2026


On 31-Jul-26 10:11 AM, Sucharitha Sarananaga wrote:
> The existing asymmetric capability structure reports generic
> modulus length and hash algorithm support, but it cannot
> describe RSA-specific parameters required by OAEP and PSS.
>
> RSA operations may support different padding schemes and MGF1
> hash algorithms independent of the primary hash algorithm.
> Applications currently have no standard way to discover these
> capabilities from a PMD.
>
> Add rsa_capa to report RSA modulus length, supported padding
> schemes, and MGF1 hash algorithms. Keep hash_algos for reporting
> primary digest support.
>
> Also clarify that the generic modlen field applies to other
> modulus-based transforms such as MODEXP, MODINV, DH, and DSA.
>
> Signed-off-by: Sucharitha Sarananaga <ssarananaga at marvell.com>
> ---
>   lib/cryptodev/rte_cryptodev.h | 42 +++++++++++++++++++++++++++++++++--
>   1 file changed, 40 insertions(+), 2 deletions(-)
>
> diff --git a/lib/cryptodev/rte_cryptodev.h b/lib/cryptodev/rte_cryptodev.h
> index 37a6a5e49b..e577dd8553 100644
> --- a/lib/cryptodev/rte_cryptodev.h
> +++ b/lib/cryptodev/rte_cryptodev.h
> @@ -157,6 +157,40 @@ struct rte_cryptodev_symmetric_capability {
>   	};
>   };
>   
> +/**
> + * RSA transform capability parameters.
> + *
> + * Used when rte_cryptodev_asymmetric_xform_capability::xform_type is
> + * RTE_CRYPTO_ASYM_XFORM_RSA. Advertises supported modulus lengths,
> + * MGF1 hash algorithms, and padding schemes.
> + *
> + * Primary hash algorithms for RSA operations (e.g. OAEP, PSS) are
> + * reported separately via hash_algos in
> + * rte_cryptodev_asymmetric_xform_capability.
> + */
> +struct rte_crypto_rsa_capa {
> +	struct rte_crypto_param_range modlen;
> +	/**< Supported RSA modulus length range, in bits.
> +	 * A min, max, or increment value of 0 means no limit is
> +	 * imposed for that field and the PMD default applies.
> +	 */
> +
> +	uint8_t pad_types;
> +	/**< Bitmask of supported RSA padding schemes.
> +	 * Each bit corresponds to enum rte_crypto_rsa_padding_type.
> +	 * A value of 0 means padding capability is not reported.

Here and below, would it make sense to add something like " and the PMD 
default may apply"?

Apart from that,

Acked-by: Radu Nicolau <radu.nicolau at intel.com>




More information about the dev mailing list