Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 1 | /* BEGIN_HEADER */ |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 2 | #include <polarssl/rsa.h> |
| 3 | #include <polarssl/md.h> |
| 4 | #include <polarssl/md2.h> |
| 5 | #include <polarssl/md4.h> |
| 6 | #include <polarssl/md5.h> |
| 7 | #include <polarssl/sha1.h> |
Paul Bakker | d2681d8 | 2013-06-30 14:49:12 +0200 | [diff] [blame] | 8 | #include <polarssl/sha256.h> |
| 9 | #include <polarssl/sha512.h> |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 10 | /* END_HEADER */ |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 11 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 12 | /* BEGIN_DEPENDENCIES |
| 13 | * depends_on:POLARSSL_PKCS1_V21:POLARSSL_RSA_C:POLARSSL_BIGNUM_C:POLARSSL_SHA1_C:POLARSSL_GENPRIME |
| 14 | * END_DEPENDENCIES |
| 15 | */ |
Paul Bakker | 5690efc | 2011-05-26 13:16:06 +0000 | [diff] [blame] | 16 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 17 | /* BEGIN_CASE */ |
| 18 | void pkcs1_rsaes_oaep_encrypt( int mod, int radix_N, char *input_N, int radix_E, |
| 19 | char *input_E, int hash, |
| 20 | char *message_hex_string, char *seed, |
| 21 | char *result_hex_str, int result ) |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 22 | { |
| 23 | unsigned char message_str[1000]; |
| 24 | unsigned char output[1000]; |
| 25 | unsigned char output_str[1000]; |
| 26 | unsigned char rnd_buf[1000]; |
| 27 | rsa_context ctx; |
Paul Bakker | f4a3f30 | 2011-04-24 15:53:29 +0000 | [diff] [blame] | 28 | size_t msg_len; |
Paul Bakker | 4cce2bb | 2011-03-13 16:56:35 +0000 | [diff] [blame] | 29 | rnd_buf_info info; |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 30 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 31 | info.length = unhexify( rnd_buf, seed ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 32 | info.buf = rnd_buf; |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 33 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 34 | rsa_init( &ctx, RSA_PKCS_V21, hash ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 35 | memset( message_str, 0x00, 1000 ); |
| 36 | memset( output, 0x00, 1000 ); |
| 37 | memset( output_str, 0x00, 1000 ); |
| 38 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 39 | ctx.len = mod / 8 + ( ( mod % 8 ) ? 1 : 0 ); |
| 40 | TEST_ASSERT( mpi_read_string( &ctx.N, radix_N, input_N ) == 0 ); |
| 41 | TEST_ASSERT( mpi_read_string( &ctx.E, radix_E, input_E ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 42 | |
| 43 | TEST_ASSERT( rsa_check_pubkey( &ctx ) == 0 ); |
| 44 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 45 | msg_len = unhexify( message_str, message_hex_string ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 46 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 47 | TEST_ASSERT( rsa_pkcs1_encrypt( &ctx, &rnd_buffer_rand, &info, RSA_PUBLIC, msg_len, message_str, output ) == result ); |
| 48 | if( result == 0 ) |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 49 | { |
| 50 | hexify( output_str, output, ctx.len ); |
| 51 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 52 | TEST_ASSERT( strcasecmp( (char *) output_str, result_hex_str ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 53 | } |
Paul Bakker | 58ef6ec | 2013-01-03 11:33:48 +0100 | [diff] [blame] | 54 | |
| 55 | rsa_free( &ctx ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 56 | } |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 57 | /* END_CASE */ |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 58 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 59 | /* BEGIN_CASE */ |
| 60 | void pkcs1_rsaes_oaep_decrypt( int mod, int radix_P, char *input_P, |
| 61 | int radix_Q, char *input_Q, int radix_N, |
| 62 | char *input_N, int radix_E, char *input_E, |
| 63 | int hash, char *result_hex_str, char *seed, |
| 64 | char *message_hex_string, int result ) |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 65 | { |
| 66 | unsigned char message_str[1000]; |
| 67 | unsigned char output[1000]; |
| 68 | unsigned char output_str[1000]; |
| 69 | rsa_context ctx; |
| 70 | mpi P1, Q1, H, G; |
Paul Bakker | f4a3f30 | 2011-04-24 15:53:29 +0000 | [diff] [blame] | 71 | size_t output_len; |
Paul Bakker | dbd443d | 2013-08-16 13:38:47 +0200 | [diff] [blame] | 72 | ((void) seed); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 73 | |
Paul Bakker | 6c591fa | 2011-05-05 11:49:20 +0000 | [diff] [blame] | 74 | mpi_init( &P1 ); mpi_init( &Q1 ); mpi_init( &H ); mpi_init( &G ); |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 75 | rsa_init( &ctx, RSA_PKCS_V21, hash ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 76 | |
| 77 | memset( message_str, 0x00, 1000 ); |
| 78 | memset( output, 0x00, 1000 ); |
| 79 | memset( output_str, 0x00, 1000 ); |
| 80 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 81 | ctx.len = mod / 8 + ( ( mod % 8 ) ? 1 : 0 ); |
| 82 | TEST_ASSERT( mpi_read_string( &ctx.P, radix_P, input_P ) == 0 ); |
| 83 | TEST_ASSERT( mpi_read_string( &ctx.Q, radix_Q, input_Q ) == 0 ); |
| 84 | TEST_ASSERT( mpi_read_string( &ctx.N, radix_N, input_N ) == 0 ); |
| 85 | TEST_ASSERT( mpi_read_string( &ctx.E, radix_E, input_E ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 86 | |
| 87 | TEST_ASSERT( mpi_sub_int( &P1, &ctx.P, 1 ) == 0 ); |
| 88 | TEST_ASSERT( mpi_sub_int( &Q1, &ctx.Q, 1 ) == 0 ); |
| 89 | TEST_ASSERT( mpi_mul_mpi( &H, &P1, &Q1 ) == 0 ); |
| 90 | TEST_ASSERT( mpi_gcd( &G, &ctx.E, &H ) == 0 ); |
| 91 | TEST_ASSERT( mpi_inv_mod( &ctx.D , &ctx.E, &H ) == 0 ); |
| 92 | TEST_ASSERT( mpi_mod_mpi( &ctx.DP, &ctx.D, &P1 ) == 0 ); |
| 93 | TEST_ASSERT( mpi_mod_mpi( &ctx.DQ, &ctx.D, &Q1 ) == 0 ); |
| 94 | TEST_ASSERT( mpi_inv_mod( &ctx.QP, &ctx.Q, &ctx.P ) == 0 ); |
| 95 | |
| 96 | TEST_ASSERT( rsa_check_privkey( &ctx ) == 0 ); |
| 97 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 98 | unhexify( message_str, message_hex_string ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 99 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 100 | TEST_ASSERT( rsa_pkcs1_decrypt( &ctx, RSA_PRIVATE, &output_len, message_str, output, 1000 ) == result ); |
| 101 | if( result == 0 ) |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 102 | { |
| 103 | hexify( output_str, output, ctx.len ); |
| 104 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 105 | TEST_ASSERT( strncasecmp( (char *) output_str, result_hex_str, strlen( result_hex_str ) ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 106 | } |
Paul Bakker | 6c591fa | 2011-05-05 11:49:20 +0000 | [diff] [blame] | 107 | |
| 108 | mpi_free( &P1 ); mpi_free( &Q1 ); mpi_free( &H ); mpi_free( &G ); |
Paul Bakker | 58ef6ec | 2013-01-03 11:33:48 +0100 | [diff] [blame] | 109 | rsa_free( &ctx ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 110 | } |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 111 | /* END_CASE */ |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 112 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 113 | /* BEGIN_CASE */ |
| 114 | void pkcs1_rsassa_pss_sign( int mod, int radix_P, char *input_P, int radix_Q, |
| 115 | char *input_Q, int radix_N, char *input_N, |
| 116 | int radix_E, char *input_E, int digest, int hash, |
| 117 | char *message_hex_string, char *salt, |
| 118 | char *result_hex_str, int result ) |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 119 | { |
| 120 | unsigned char message_str[1000]; |
| 121 | unsigned char hash_result[1000]; |
| 122 | unsigned char output[1000]; |
| 123 | unsigned char output_str[1000]; |
| 124 | unsigned char rnd_buf[1000]; |
| 125 | rsa_context ctx; |
| 126 | mpi P1, Q1, H, G; |
Paul Bakker | f4a3f30 | 2011-04-24 15:53:29 +0000 | [diff] [blame] | 127 | size_t msg_len; |
Paul Bakker | 4cce2bb | 2011-03-13 16:56:35 +0000 | [diff] [blame] | 128 | rnd_buf_info info; |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 129 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 130 | info.length = unhexify( rnd_buf, salt ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 131 | info.buf = rnd_buf; |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 132 | |
Paul Bakker | 6c591fa | 2011-05-05 11:49:20 +0000 | [diff] [blame] | 133 | mpi_init( &P1 ); mpi_init( &Q1 ); mpi_init( &H ); mpi_init( &G ); |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 134 | rsa_init( &ctx, RSA_PKCS_V21, hash ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 135 | |
| 136 | memset( message_str, 0x00, 1000 ); |
| 137 | memset( hash_result, 0x00, 1000 ); |
| 138 | memset( output, 0x00, 1000 ); |
| 139 | memset( output_str, 0x00, 1000 ); |
| 140 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 141 | ctx.len = mod / 8 + ( ( mod % 8 ) ? 1 : 0 ); |
| 142 | TEST_ASSERT( mpi_read_string( &ctx.P, radix_P, input_P ) == 0 ); |
| 143 | TEST_ASSERT( mpi_read_string( &ctx.Q, radix_Q, input_Q ) == 0 ); |
| 144 | TEST_ASSERT( mpi_read_string( &ctx.N, radix_N, input_N ) == 0 ); |
| 145 | TEST_ASSERT( mpi_read_string( &ctx.E, radix_E, input_E ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 146 | |
| 147 | TEST_ASSERT( mpi_sub_int( &P1, &ctx.P, 1 ) == 0 ); |
| 148 | TEST_ASSERT( mpi_sub_int( &Q1, &ctx.Q, 1 ) == 0 ); |
| 149 | TEST_ASSERT( mpi_mul_mpi( &H, &P1, &Q1 ) == 0 ); |
| 150 | TEST_ASSERT( mpi_gcd( &G, &ctx.E, &H ) == 0 ); |
| 151 | TEST_ASSERT( mpi_inv_mod( &ctx.D , &ctx.E, &H ) == 0 ); |
| 152 | TEST_ASSERT( mpi_mod_mpi( &ctx.DP, &ctx.D, &P1 ) == 0 ); |
| 153 | TEST_ASSERT( mpi_mod_mpi( &ctx.DQ, &ctx.D, &Q1 ) == 0 ); |
| 154 | TEST_ASSERT( mpi_inv_mod( &ctx.QP, &ctx.Q, &ctx.P ) == 0 ); |
| 155 | |
| 156 | TEST_ASSERT( rsa_check_privkey( &ctx ) == 0 ); |
| 157 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 158 | msg_len = unhexify( message_str, message_hex_string ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 159 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 160 | if( md_info_from_type( digest ) != NULL ) |
| 161 | TEST_ASSERT( md( md_info_from_type( digest ), message_str, msg_len, hash_result ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 162 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 163 | TEST_ASSERT( rsa_pkcs1_sign( &ctx, &rnd_buffer_rand, &info, RSA_PRIVATE, digest, 0, hash_result, output ) == result ); |
| 164 | if( result == 0 ) |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 165 | { |
| 166 | hexify( output_str, output, ctx.len); |
| 167 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 168 | TEST_ASSERT( strcasecmp( (char *) output_str, result_hex_str ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 169 | } |
Paul Bakker | 6c591fa | 2011-05-05 11:49:20 +0000 | [diff] [blame] | 170 | |
| 171 | mpi_free( &P1 ); mpi_free( &Q1 ); mpi_free( &H ); mpi_free( &G ); |
Paul Bakker | 58ef6ec | 2013-01-03 11:33:48 +0100 | [diff] [blame] | 172 | rsa_free( &ctx ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 173 | } |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 174 | /* END_CASE */ |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 175 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 176 | /* BEGIN_CASE */ |
| 177 | void pkcs1_rsassa_pss_verify( int mod, int radix_N, char *input_N, int radix_E, |
| 178 | char *input_E, int digest, int hash, |
| 179 | char *message_hex_string, char *salt, |
| 180 | char *result_hex_str, int result ) |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 181 | { |
| 182 | unsigned char message_str[1000]; |
| 183 | unsigned char hash_result[1000]; |
| 184 | unsigned char result_str[1000]; |
| 185 | rsa_context ctx; |
Paul Bakker | f4a3f30 | 2011-04-24 15:53:29 +0000 | [diff] [blame] | 186 | size_t msg_len; |
Paul Bakker | dbd443d | 2013-08-16 13:38:47 +0200 | [diff] [blame] | 187 | ((void) salt); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 188 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 189 | rsa_init( &ctx, RSA_PKCS_V21, hash ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 190 | memset( message_str, 0x00, 1000 ); |
| 191 | memset( hash_result, 0x00, 1000 ); |
| 192 | memset( result_str, 0x00, 1000 ); |
| 193 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 194 | ctx.len = mod / 8 + ( ( mod % 8 ) ? 1 : 0 ); |
| 195 | TEST_ASSERT( mpi_read_string( &ctx.N, radix_N, input_N ) == 0 ); |
| 196 | TEST_ASSERT( mpi_read_string( &ctx.E, radix_E, input_E ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 197 | |
| 198 | TEST_ASSERT( rsa_check_pubkey( &ctx ) == 0 ); |
| 199 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 200 | msg_len = unhexify( message_str, message_hex_string ); |
| 201 | unhexify( result_str, result_hex_str ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 202 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 203 | if( md_info_from_type( digest ) != NULL ) |
| 204 | TEST_ASSERT( md( md_info_from_type( digest ), message_str, msg_len, hash_result ) == 0 ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 205 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 206 | TEST_ASSERT( rsa_pkcs1_verify( &ctx, RSA_PUBLIC, digest, 0, hash_result, result_str ) == result ); |
Paul Bakker | 58ef6ec | 2013-01-03 11:33:48 +0100 | [diff] [blame] | 207 | |
| 208 | rsa_free( &ctx ); |
Paul Bakker | 9dcc322 | 2011-03-08 14:16:06 +0000 | [diff] [blame] | 209 | } |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame^] | 210 | /* END_CASE */ |