test_suite_ecdh.function 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160
  1. /* BEGIN_HEADER */
  2. #include "mbedtls/ecdh.h"
  3. /* END_HEADER */
  4. /* BEGIN_DEPENDENCIES
  5. * depends_on:MBEDTLS_ECDH_C
  6. * END_DEPENDENCIES
  7. */
  8. /* BEGIN_CASE */
  9. void ecdh_primitive_random( int id )
  10. {
  11. mbedtls_ecp_group grp;
  12. mbedtls_ecp_point qA, qB;
  13. mbedtls_mpi dA, dB, zA, zB;
  14. rnd_pseudo_info rnd_info;
  15. mbedtls_ecp_group_init( &grp );
  16. mbedtls_ecp_point_init( &qA ); mbedtls_ecp_point_init( &qB );
  17. mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &dB );
  18. mbedtls_mpi_init( &zA ); mbedtls_mpi_init( &zB );
  19. memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
  20. TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
  21. TEST_ASSERT( mbedtls_ecdh_gen_public( &grp, &dA, &qA, &rnd_pseudo_rand, &rnd_info )
  22. == 0 );
  23. TEST_ASSERT( mbedtls_ecdh_gen_public( &grp, &dB, &qB, &rnd_pseudo_rand, &rnd_info )
  24. == 0 );
  25. TEST_ASSERT( mbedtls_ecdh_compute_shared( &grp, &zA, &qB, &dA,
  26. &rnd_pseudo_rand, &rnd_info ) == 0 );
  27. TEST_ASSERT( mbedtls_ecdh_compute_shared( &grp, &zB, &qA, &dB,
  28. NULL, NULL ) == 0 );
  29. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &zA, &zB ) == 0 );
  30. exit:
  31. mbedtls_ecp_group_free( &grp );
  32. mbedtls_ecp_point_free( &qA ); mbedtls_ecp_point_free( &qB );
  33. mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &dB );
  34. mbedtls_mpi_free( &zA ); mbedtls_mpi_free( &zB );
  35. }
  36. /* END_CASE */
  37. /* BEGIN_CASE */
  38. void ecdh_primitive_testvec( int id, char *dA_str, char *xA_str, char *yA_str,
  39. char *dB_str, char *xB_str, char *yB_str,
  40. char *z_str )
  41. {
  42. mbedtls_ecp_group grp;
  43. mbedtls_ecp_point qA, qB;
  44. mbedtls_mpi dA, dB, zA, zB, check;
  45. unsigned char rnd_buf_A[MBEDTLS_ECP_MAX_BYTES];
  46. unsigned char rnd_buf_B[MBEDTLS_ECP_MAX_BYTES];
  47. rnd_buf_info rnd_info_A, rnd_info_B;
  48. mbedtls_ecp_group_init( &grp );
  49. mbedtls_ecp_point_init( &qA ); mbedtls_ecp_point_init( &qB );
  50. mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &dB );
  51. mbedtls_mpi_init( &zA ); mbedtls_mpi_init( &zB ); mbedtls_mpi_init( &check );
  52. TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
  53. rnd_info_A.buf = rnd_buf_A;
  54. rnd_info_A.length = unhexify( rnd_buf_A, dA_str );
  55. /* Fix rnd_buf_A by shifting it left if necessary */
  56. if( grp.nbits % 8 != 0 )
  57. {
  58. unsigned char shift = 8 - ( grp.nbits % 8 );
  59. size_t i;
  60. for( i = 0; i < rnd_info_A.length - 1; i++ )
  61. rnd_buf_A[i] = rnd_buf_A[i] << shift
  62. | rnd_buf_A[i+1] >> ( 8 - shift );
  63. rnd_buf_A[rnd_info_A.length-1] <<= shift;
  64. }
  65. rnd_info_B.buf = rnd_buf_B;
  66. rnd_info_B.length = unhexify( rnd_buf_B, dB_str );
  67. /* Fix rnd_buf_B by shifting it left if necessary */
  68. if( grp.nbits % 8 != 0 )
  69. {
  70. unsigned char shift = 8 - ( grp.nbits % 8 );
  71. size_t i;
  72. for( i = 0; i < rnd_info_B.length - 1; i++ )
  73. rnd_buf_B[i] = rnd_buf_B[i] << shift
  74. | rnd_buf_B[i+1] >> ( 8 - shift );
  75. rnd_buf_B[rnd_info_B.length-1] <<= shift;
  76. }
  77. TEST_ASSERT( mbedtls_ecdh_gen_public( &grp, &dA, &qA,
  78. rnd_buffer_rand, &rnd_info_A ) == 0 );
  79. TEST_ASSERT( ! mbedtls_ecp_is_zero( &qA ) );
  80. TEST_ASSERT( mbedtls_mpi_read_string( &check, 16, xA_str ) == 0 );
  81. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &qA.X, &check ) == 0 );
  82. TEST_ASSERT( mbedtls_mpi_read_string( &check, 16, yA_str ) == 0 );
  83. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &qA.Y, &check ) == 0 );
  84. TEST_ASSERT( mbedtls_ecdh_gen_public( &grp, &dB, &qB,
  85. rnd_buffer_rand, &rnd_info_B ) == 0 );
  86. TEST_ASSERT( ! mbedtls_ecp_is_zero( &qB ) );
  87. TEST_ASSERT( mbedtls_mpi_read_string( &check, 16, xB_str ) == 0 );
  88. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &qB.X, &check ) == 0 );
  89. TEST_ASSERT( mbedtls_mpi_read_string( &check, 16, yB_str ) == 0 );
  90. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &qB.Y, &check ) == 0 );
  91. TEST_ASSERT( mbedtls_mpi_read_string( &check, 16, z_str ) == 0 );
  92. TEST_ASSERT( mbedtls_ecdh_compute_shared( &grp, &zA, &qB, &dA, NULL, NULL ) == 0 );
  93. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &zA, &check ) == 0 );
  94. TEST_ASSERT( mbedtls_ecdh_compute_shared( &grp, &zB, &qA, &dB, NULL, NULL ) == 0 );
  95. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &zB, &check ) == 0 );
  96. exit:
  97. mbedtls_ecp_group_free( &grp );
  98. mbedtls_ecp_point_free( &qA ); mbedtls_ecp_point_free( &qB );
  99. mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &dB );
  100. mbedtls_mpi_free( &zA ); mbedtls_mpi_free( &zB ); mbedtls_mpi_free( &check );
  101. }
  102. /* END_CASE */
  103. /* BEGIN_CASE */
  104. void ecdh_exchange( int id )
  105. {
  106. mbedtls_ecdh_context srv, cli;
  107. unsigned char buf[1000];
  108. const unsigned char *vbuf;
  109. size_t len;
  110. rnd_pseudo_info rnd_info;
  111. mbedtls_ecdh_init( &srv );
  112. mbedtls_ecdh_init( &cli );
  113. memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
  114. TEST_ASSERT( mbedtls_ecp_group_load( &srv.grp, id ) == 0 );
  115. memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
  116. TEST_ASSERT( mbedtls_ecdh_make_params( &srv, &len, buf, 1000,
  117. &rnd_pseudo_rand, &rnd_info ) == 0 );
  118. TEST_ASSERT( mbedtls_ecdh_read_params( &cli, &vbuf, buf + len ) == 0 );
  119. memset( buf, 0x00, sizeof( buf ) );
  120. TEST_ASSERT( mbedtls_ecdh_make_public( &cli, &len, buf, 1000,
  121. &rnd_pseudo_rand, &rnd_info ) == 0 );
  122. TEST_ASSERT( mbedtls_ecdh_read_public( &srv, buf, len ) == 0 );
  123. TEST_ASSERT( mbedtls_ecdh_calc_secret( &srv, &len, buf, 1000,
  124. &rnd_pseudo_rand, &rnd_info ) == 0 );
  125. TEST_ASSERT( mbedtls_ecdh_calc_secret( &cli, &len, buf, 1000, NULL, NULL ) == 0 );
  126. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &srv.z, &cli.z ) == 0 );
  127. exit:
  128. mbedtls_ecdh_free( &srv );
  129. mbedtls_ecdh_free( &cli );
  130. }
  131. /* END_CASE */