2013-08-20 09:48:36 +00:00
|
|
|
/* BEGIN_HEADER */
|
2015-03-09 17:05:11 +00:00
|
|
|
#include "mbedtls/dhm.h"
|
2021-03-30 21:28:51 +00:00
|
|
|
|
2021-04-13 20:16:45 +00:00
|
|
|
/* Sanity checks on a Diffie-Hellman parameter: check the length-value
|
|
|
|
* syntax and check that the value is the expected one (taken from the
|
|
|
|
* DHM context by the caller). */
|
2021-03-30 21:28:51 +00:00
|
|
|
static int check_dhm_param_output( const mbedtls_mpi *expected,
|
|
|
|
const unsigned char *buffer,
|
|
|
|
size_t size,
|
|
|
|
size_t *offset )
|
|
|
|
{
|
|
|
|
size_t n;
|
|
|
|
mbedtls_mpi actual;
|
|
|
|
int ok = 0;
|
|
|
|
mbedtls_mpi_init( &actual );
|
|
|
|
|
|
|
|
++mbedtls_test_info.step;
|
|
|
|
|
|
|
|
TEST_ASSERT( size >= *offset + 2 );
|
|
|
|
n = ( buffer[*offset] << 8 ) | buffer[*offset + 1];
|
|
|
|
*offset += 2;
|
2021-04-13 20:10:24 +00:00
|
|
|
/* The DHM param output from Mbed TLS has leading zeros stripped, as
|
|
|
|
* permitted but not required by RFC 5246 \S4.4. */
|
2021-03-30 21:28:51 +00:00
|
|
|
TEST_EQUAL( n, mbedtls_mpi_size( expected ) );
|
|
|
|
TEST_ASSERT( size >= *offset + n );
|
|
|
|
TEST_EQUAL( 0, mbedtls_mpi_read_binary( &actual, buffer + *offset, n ) );
|
|
|
|
TEST_EQUAL( 0, mbedtls_mpi_cmp_mpi( expected, &actual ) );
|
|
|
|
*offset += n;
|
|
|
|
|
|
|
|
ok = 1;
|
|
|
|
exit:
|
|
|
|
mbedtls_mpi_free( &actual );
|
|
|
|
return( ok );
|
|
|
|
}
|
|
|
|
|
2021-04-13 20:16:45 +00:00
|
|
|
/* Sanity checks on Diffie-Hellman parameters: syntax, range, and comparison
|
|
|
|
* against the context. */
|
2021-03-30 21:28:51 +00:00
|
|
|
static int check_dhm_params( const mbedtls_dhm_context *ctx,
|
|
|
|
size_t x_size,
|
|
|
|
const unsigned char *ske, size_t ske_len )
|
|
|
|
{
|
|
|
|
size_t offset = 0;
|
|
|
|
|
|
|
|
/* Check that ctx->X and ctx->GX are within range. */
|
|
|
|
TEST_ASSERT( mbedtls_mpi_cmp_int( &ctx->X, 1 ) > 0 );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_cmp_mpi( &ctx->X, &ctx->P ) < 0 );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_size( &ctx->X ) <= x_size );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_cmp_int( &ctx->GX, 1 ) > 0 );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_cmp_mpi( &ctx->GX, &ctx->P ) < 0 );
|
|
|
|
|
|
|
|
/* Check ske: it must contain P, G and G^X, each prefixed with a
|
|
|
|
* 2-byte size. */
|
|
|
|
if( !check_dhm_param_output( &ctx->P, ske, ske_len, &offset ) )
|
|
|
|
goto exit;
|
|
|
|
if( !check_dhm_param_output( &ctx->G, ske, ske_len, &offset ) )
|
|
|
|
goto exit;
|
|
|
|
if( !check_dhm_param_output( &ctx->GX, ske, ske_len, &offset ) )
|
|
|
|
goto exit;
|
|
|
|
TEST_EQUAL( offset, ske_len );
|
|
|
|
|
|
|
|
return( 1 );
|
|
|
|
exit:
|
|
|
|
return( 0 );
|
|
|
|
}
|
|
|
|
|
2013-08-20 09:48:36 +00:00
|
|
|
/* END_HEADER */
|
2009-07-08 19:47:36 +00:00
|
|
|
|
2013-08-20 09:48:36 +00:00
|
|
|
/* BEGIN_DEPENDENCIES
|
2015-04-08 10:49:31 +00:00
|
|
|
* depends_on:MBEDTLS_DHM_C:MBEDTLS_BIGNUM_C
|
2013-08-20 09:48:36 +00:00
|
|
|
* END_DEPENDENCIES
|
|
|
|
*/
|
2011-05-26 13:16:06 +00:00
|
|
|
|
2013-08-20 09:48:36 +00:00
|
|
|
/* BEGIN_CASE */
|
2021-03-30 21:44:22 +00:00
|
|
|
void dhm_do_dhm( int radix_P, char *input_P, int x_size,
|
2017-09-20 12:46:37 +00:00
|
|
|
int radix_G, char *input_G, int result )
|
2009-07-08 19:47:36 +00:00
|
|
|
{
|
2015-04-08 10:49:31 +00:00
|
|
|
mbedtls_dhm_context ctx_srv;
|
|
|
|
mbedtls_dhm_context ctx_cli;
|
2009-07-08 19:47:36 +00:00
|
|
|
unsigned char ske[1000];
|
|
|
|
unsigned char *p = ske;
|
|
|
|
unsigned char pub_cli[1000];
|
|
|
|
unsigned char sec_srv[1000];
|
|
|
|
unsigned char sec_cli[1000];
|
2011-04-24 15:53:29 +00:00
|
|
|
size_t ske_len = 0;
|
|
|
|
size_t pub_cli_len = 0;
|
2015-06-02 15:17:08 +00:00
|
|
|
size_t sec_srv_len;
|
|
|
|
size_t sec_cli_len;
|
2021-03-30 21:44:22 +00:00
|
|
|
int i;
|
2020-06-10 10:12:18 +00:00
|
|
|
mbedtls_test_rnd_pseudo_info rnd_info;
|
2009-07-08 19:47:36 +00:00
|
|
|
|
2015-04-08 10:49:31 +00:00
|
|
|
mbedtls_dhm_init( &ctx_srv );
|
|
|
|
mbedtls_dhm_init( &ctx_cli );
|
2009-07-08 19:47:36 +00:00
|
|
|
memset( ske, 0x00, 1000 );
|
|
|
|
memset( pub_cli, 0x00, 1000 );
|
|
|
|
memset( sec_srv, 0x00, 1000 );
|
|
|
|
memset( sec_cli, 0x00, 1000 );
|
2020-06-10 10:12:18 +00:00
|
|
|
memset( &rnd_info, 0x00, sizeof( mbedtls_test_rnd_pseudo_info ) );
|
2009-07-08 19:47:36 +00:00
|
|
|
|
2013-09-04 14:29:59 +00:00
|
|
|
/*
|
|
|
|
* Set params
|
|
|
|
*/
|
2015-04-08 10:49:31 +00:00
|
|
|
TEST_ASSERT( mbedtls_mpi_read_string( &ctx_srv.P, radix_P, input_P ) == 0 );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_read_string( &ctx_srv.G, radix_G, input_G ) == 0 );
|
2021-03-30 21:44:22 +00:00
|
|
|
pub_cli_len = mbedtls_mpi_size( &ctx_srv.P );
|
2009-07-08 19:47:36 +00:00
|
|
|
|
2013-09-04 14:29:59 +00:00
|
|
|
/*
|
|
|
|
* First key exchange
|
|
|
|
*/
|
2021-03-30 21:28:51 +00:00
|
|
|
mbedtls_test_set_step( 10 );
|
2020-06-10 12:08:26 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_make_params( &ctx_srv, x_size, ske, &ske_len,
|
|
|
|
&mbedtls_test_rnd_pseudo_rand,
|
|
|
|
&rnd_info ) == result );
|
2017-09-20 12:46:37 +00:00
|
|
|
if ( result != 0 )
|
|
|
|
goto exit;
|
2021-03-30 21:28:51 +00:00
|
|
|
if( !check_dhm_params( &ctx_srv, x_size, ske, ske_len ) )
|
|
|
|
goto exit;
|
2017-09-20 12:46:37 +00:00
|
|
|
|
2009-07-08 19:47:36 +00:00
|
|
|
ske[ske_len++] = 0;
|
|
|
|
ske[ske_len++] = 0;
|
2015-04-08 10:49:31 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_read_params( &ctx_cli, &p, ske + ske_len ) == 0 );
|
2009-07-08 19:47:36 +00:00
|
|
|
|
2020-06-10 12:08:26 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_make_public( &ctx_cli, x_size, pub_cli, pub_cli_len,
|
|
|
|
&mbedtls_test_rnd_pseudo_rand,
|
|
|
|
&rnd_info ) == 0 );
|
2015-04-08 10:49:31 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_read_public( &ctx_srv, pub_cli, pub_cli_len ) == 0 );
|
2013-09-04 14:29:59 +00:00
|
|
|
|
2020-06-10 12:08:26 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_calc_secret( &ctx_srv, sec_srv, sizeof( sec_srv ),
|
|
|
|
&sec_srv_len,
|
|
|
|
&mbedtls_test_rnd_pseudo_rand,
|
|
|
|
&rnd_info ) == 0 );
|
2015-06-02 15:17:08 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_calc_secret( &ctx_cli, sec_cli, sizeof( sec_cli ), &sec_cli_len, NULL, NULL ) == 0 );
|
2013-09-04 14:29:59 +00:00
|
|
|
|
|
|
|
TEST_ASSERT( sec_srv_len == sec_cli_len );
|
|
|
|
TEST_ASSERT( sec_srv_len != 0 );
|
|
|
|
TEST_ASSERT( memcmp( sec_srv, sec_cli, sec_srv_len ) == 0 );
|
|
|
|
|
2013-09-17 09:34:11 +00:00
|
|
|
/* Re-do calc_secret on server a few times to test update of blinding values */
|
|
|
|
for( i = 0; i < 3; i++ )
|
|
|
|
{
|
2021-03-30 21:28:51 +00:00
|
|
|
mbedtls_test_set_step( 20 + i );
|
2013-09-17 09:34:11 +00:00
|
|
|
sec_srv_len = 1000;
|
2020-06-10 12:08:26 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_calc_secret( &ctx_srv, sec_srv,
|
|
|
|
sizeof( sec_srv ), &sec_srv_len,
|
|
|
|
&mbedtls_test_rnd_pseudo_rand,
|
|
|
|
&rnd_info ) == 0 );
|
2009-07-08 19:47:36 +00:00
|
|
|
|
2013-09-17 09:34:11 +00:00
|
|
|
TEST_ASSERT( sec_srv_len == sec_cli_len );
|
|
|
|
TEST_ASSERT( sec_srv_len != 0 );
|
|
|
|
TEST_ASSERT( memcmp( sec_srv, sec_cli, sec_srv_len ) == 0 );
|
|
|
|
}
|
2013-09-04 14:29:59 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Second key exchange to test change of blinding values on server
|
|
|
|
*/
|
|
|
|
p = ske;
|
|
|
|
|
2021-03-30 21:28:51 +00:00
|
|
|
mbedtls_test_set_step( 30 );
|
2020-06-10 12:08:26 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_make_params( &ctx_srv, x_size, ske, &ske_len,
|
|
|
|
&mbedtls_test_rnd_pseudo_rand,
|
|
|
|
&rnd_info ) == 0 );
|
2021-03-30 21:28:51 +00:00
|
|
|
if( !check_dhm_params( &ctx_srv, x_size, ske, ske_len ) )
|
|
|
|
goto exit;
|
2013-09-04 14:29:59 +00:00
|
|
|
ske[ske_len++] = 0;
|
|
|
|
ske[ske_len++] = 0;
|
2015-04-08 10:49:31 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_read_params( &ctx_cli, &p, ske + ske_len ) == 0 );
|
2013-09-04 14:29:59 +00:00
|
|
|
|
2020-06-10 12:08:26 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_make_public( &ctx_cli, x_size, pub_cli, pub_cli_len,
|
|
|
|
&mbedtls_test_rnd_pseudo_rand,
|
|
|
|
&rnd_info ) == 0 );
|
2015-04-08 10:49:31 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_read_public( &ctx_srv, pub_cli, pub_cli_len ) == 0 );
|
2009-07-08 19:47:36 +00:00
|
|
|
|
2020-06-10 12:08:26 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_calc_secret( &ctx_srv, sec_srv, sizeof( sec_srv ),
|
|
|
|
&sec_srv_len,
|
|
|
|
&mbedtls_test_rnd_pseudo_rand,
|
|
|
|
&rnd_info ) == 0 );
|
2015-06-02 15:17:08 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_calc_secret( &ctx_cli, sec_cli, sizeof( sec_cli ), &sec_cli_len, NULL, NULL ) == 0 );
|
2009-07-08 19:47:36 +00:00
|
|
|
|
|
|
|
TEST_ASSERT( sec_srv_len == sec_cli_len );
|
|
|
|
TEST_ASSERT( sec_srv_len != 0 );
|
|
|
|
TEST_ASSERT( memcmp( sec_srv, sec_cli, sec_srv_len ) == 0 );
|
2011-02-20 16:34:26 +00:00
|
|
|
|
2014-07-10 13:26:12 +00:00
|
|
|
exit:
|
2015-04-08 10:49:31 +00:00
|
|
|
mbedtls_dhm_free( &ctx_srv );
|
|
|
|
mbedtls_dhm_free( &ctx_cli );
|
2009-07-08 19:47:36 +00:00
|
|
|
}
|
2013-08-20 09:48:36 +00:00
|
|
|
/* END_CASE */
|
2013-09-15 15:43:54 +00:00
|
|
|
|
2020-12-02 10:41:50 +00:00
|
|
|
/* BEGIN_CASE */
|
|
|
|
void dhm_make_public( int P_bytes, int radix_G, char *input_G, int result )
|
|
|
|
{
|
|
|
|
mbedtls_mpi P, G;
|
|
|
|
mbedtls_dhm_context ctx;
|
|
|
|
unsigned char output[MBEDTLS_MPI_MAX_SIZE];
|
|
|
|
|
|
|
|
mbedtls_mpi_init( &P );
|
|
|
|
mbedtls_mpi_init( &G );
|
|
|
|
mbedtls_dhm_init( &ctx );
|
|
|
|
|
|
|
|
TEST_ASSERT( mbedtls_mpi_lset( &P, 1 ) == 0 );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_shift_l( &P, ( P_bytes * 8 ) - 1 ) == 0 );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_set_bit( &P, 0, 1 ) == 0 );
|
|
|
|
|
|
|
|
TEST_ASSERT( mbedtls_mpi_read_string( &G, radix_G, input_G ) == 0 );
|
|
|
|
|
|
|
|
TEST_ASSERT( mbedtls_dhm_set_group( &ctx, &P, &G ) == 0 );
|
|
|
|
TEST_ASSERT( mbedtls_dhm_make_public( &ctx, (int) mbedtls_mpi_size( &P ),
|
|
|
|
output, sizeof(output),
|
|
|
|
&mbedtls_test_rnd_pseudo_rand,
|
|
|
|
NULL ) == result );
|
|
|
|
|
|
|
|
exit:
|
|
|
|
mbedtls_mpi_free( &P );
|
|
|
|
mbedtls_mpi_free( &G );
|
|
|
|
mbedtls_dhm_free( &ctx );
|
|
|
|
}
|
|
|
|
/* END_CASE */
|
|
|
|
|
2015-04-08 10:49:31 +00:00
|
|
|
/* BEGIN_CASE depends_on:MBEDTLS_FS_IO */
|
2017-05-30 13:23:15 +00:00
|
|
|
void dhm_file( char * filename, char * p, char * g, int len )
|
2014-03-29 15:42:38 +00:00
|
|
|
{
|
2015-04-08 10:49:31 +00:00
|
|
|
mbedtls_dhm_context ctx;
|
|
|
|
mbedtls_mpi P, G;
|
2014-03-29 15:42:38 +00:00
|
|
|
|
2015-04-08 10:49:31 +00:00
|
|
|
mbedtls_dhm_init( &ctx );
|
|
|
|
mbedtls_mpi_init( &P ); mbedtls_mpi_init( &G );
|
2014-03-29 15:42:38 +00:00
|
|
|
|
2015-04-08 10:49:31 +00:00
|
|
|
TEST_ASSERT( mbedtls_mpi_read_string( &P, 16, p ) == 0 );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_read_string( &G, 16, g ) == 0 );
|
2014-03-29 15:42:38 +00:00
|
|
|
|
2015-04-08 10:49:31 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_parse_dhmfile( &ctx, filename ) == 0 );
|
2014-03-29 15:42:38 +00:00
|
|
|
|
|
|
|
TEST_ASSERT( ctx.len == (size_t) len );
|
2015-04-08 10:49:31 +00:00
|
|
|
TEST_ASSERT( mbedtls_mpi_cmp_mpi( &ctx.P, &P ) == 0 );
|
|
|
|
TEST_ASSERT( mbedtls_mpi_cmp_mpi( &ctx.G, &G ) == 0 );
|
2014-03-29 15:42:38 +00:00
|
|
|
|
2014-07-10 13:26:12 +00:00
|
|
|
exit:
|
2015-04-08 10:49:31 +00:00
|
|
|
mbedtls_mpi_free( &P ); mbedtls_mpi_free( &G );
|
|
|
|
mbedtls_dhm_free( &ctx );
|
2014-03-29 15:42:38 +00:00
|
|
|
}
|
|
|
|
/* END_CASE */
|
|
|
|
|
2015-04-08 10:49:31 +00:00
|
|
|
/* BEGIN_CASE depends_on:MBEDTLS_SELF_TEST */
|
2017-05-30 13:23:15 +00:00
|
|
|
void dhm_selftest( )
|
2013-09-15 15:43:54 +00:00
|
|
|
{
|
2016-09-09 08:10:28 +00:00
|
|
|
TEST_ASSERT( mbedtls_dhm_self_test( 1 ) == 0 );
|
2013-09-15 15:43:54 +00:00
|
|
|
}
|
|
|
|
/* END_CASE */
|