blob: b6253feef916faf70fb313d497e43c8ee5382e2f [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/ecp.h"
Paul Bakkerdbd443d2013-08-16 13:38:47 +02003
Manuel Pégourié-Gonnard6c7af4c2015-04-03 16:41:52 +02004#define ECP_PF_UNKNOWN -1
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +02005
6#define ECP_PT_RESET( x ) \
7 mbedtls_ecp_point_free( x ); \
8 mbedtls_ecp_point_init( x );
Paul Bakker33b43f12013-08-20 11:48:36 +02009/* END_HEADER */
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +010010
Paul Bakker33b43f12013-08-20 11:48:36 +020011/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020012 * depends_on:MBEDTLS_ECP_C
Paul Bakker33b43f12013-08-20 11:48:36 +020013 * END_DEPENDENCIES
14 */
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +010015
Hanno Becker57b684f2018-12-18 12:50:02 +000016/* BEGIN_CASE */
17void ecp_valid_param( )
18{
Hanno Becker807c1072018-12-18 23:45:14 +000019 TEST_VALID_PARAM( mbedtls_ecp_group_free( NULL ) );
Hanno Becker57b684f2018-12-18 12:50:02 +000020 TEST_VALID_PARAM( mbedtls_ecp_keypair_free( NULL ) );
21 TEST_VALID_PARAM( mbedtls_ecp_point_free( NULL ) );
22
23#if defined(MBEDTLS_ECP_RESTARTABLE)
24 TEST_VALID_PARAM( mbedtls_ecp_restart_free( NULL ) );
25#endif /* MBEDTLS_ECP_RESTARTABLE */
26
27exit:
28 return;
29}
30/* END_CASE */
31
Hanno Becker12dff032018-12-14 15:08:13 +000032/* BEGIN_CASE depends_on:MBEDTLS_CHECK_PARAMS:!MBEDTLS_PARAM_FAILED_ALT */
33void ecp_invalid_param( )
34{
35 mbedtls_ecp_group grp;
36 mbedtls_ecp_keypair kp;
37 mbedtls_ecp_point P;
38 mbedtls_mpi m;
39 const char *x = "deadbeef";
40 int valid_fmt = MBEDTLS_ECP_PF_UNCOMPRESSED;
41 int invalid_fmt = 42;
42 size_t olen;
43 unsigned char buf[42] = { 0 };
44 const unsigned char *null_buf = NULL;
45 mbedtls_ecp_group_id valid_group = MBEDTLS_ECP_DP_SECP192R1;
Hanno Becker0a4fa9b2018-12-18 23:45:29 +000046 mbedtls_ecp_restart_ctx restart_ctx;
Hanno Becker12dff032018-12-14 15:08:13 +000047
48 TEST_INVALID_PARAM( mbedtls_ecp_point_init( NULL ) );
49 TEST_INVALID_PARAM( mbedtls_ecp_keypair_init( NULL ) );
Hanno Becker807c1072018-12-18 23:45:14 +000050 TEST_INVALID_PARAM( mbedtls_ecp_group_init( NULL ) );
Hanno Becker12dff032018-12-14 15:08:13 +000051
Hanno Becker12dff032018-12-14 15:08:13 +000052#if defined(MBEDTLS_ECP_RESTARTABLE)
53 TEST_INVALID_PARAM( mbedtls_ecp_restart_init( NULL ) );
Hanno Becker0a4fa9b2018-12-18 23:45:29 +000054 TEST_INVALID_PARAM( mbedtls_ecp_check_budget( NULL, &restart_ctx, 42 ) );
Hanno Becker12dff032018-12-14 15:08:13 +000055#endif /* MBEDTLS_ECP_RESTARTABLE */
56
57 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
58 mbedtls_ecp_copy( NULL, &P ) );
59 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
60 mbedtls_ecp_copy( &P, NULL ) );
61
62 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
63 mbedtls_ecp_group_copy( NULL, &grp ) );
64 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
65 mbedtls_ecp_group_copy( &grp, NULL ) );
66
67 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
Hanno Becker549e4552018-12-18 23:45:43 +000068 mbedtls_ecp_gen_privkey( NULL,
69 &m,
70 rnd_std_rand,
71 NULL ) );
72 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
73 mbedtls_ecp_gen_privkey( &grp,
74 NULL,
75 rnd_std_rand,
76 NULL ) );
77 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
78 mbedtls_ecp_gen_privkey( &grp,
79 &m,
80 NULL,
81 NULL ) );
82
83 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
Hanno Becker12dff032018-12-14 15:08:13 +000084 mbedtls_ecp_set_zero( NULL ) );
85 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
86 mbedtls_ecp_is_zero( NULL ) );
87
88 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
89 mbedtls_ecp_point_cmp( NULL, &P ) );
90 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
91 mbedtls_ecp_point_cmp( &P, NULL ) );
92
93 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
94 mbedtls_ecp_point_read_string( NULL, 2,
95 x, x ) );
96 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
97 mbedtls_ecp_point_read_string( &P, 2,
98 NULL, x ) );
99 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
100 mbedtls_ecp_point_read_string( &P, 2,
101 x, NULL ) );
102
103 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
104 mbedtls_ecp_point_write_binary( NULL, &P,
105 valid_fmt,
106 &olen,
107 buf, sizeof( buf ) ) );
108 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
109 mbedtls_ecp_point_write_binary( &grp, NULL,
110 valid_fmt,
111 &olen,
112 buf, sizeof( buf ) ) );
113 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
114 mbedtls_ecp_point_write_binary( &grp, &P,
115 invalid_fmt,
116 &olen,
117 buf, sizeof( buf ) ) );
118 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
119 mbedtls_ecp_point_write_binary( &grp, &P,
120 valid_fmt,
121 NULL,
122 buf, sizeof( buf ) ) );
123 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
124 mbedtls_ecp_point_write_binary( &grp, &P,
125 valid_fmt,
126 &olen,
127 NULL, sizeof( buf ) ) );
128
129 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
130 mbedtls_ecp_point_read_binary( NULL, &P, buf,
131 sizeof( buf ) ) );
132 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
133 mbedtls_ecp_point_read_binary( &grp, NULL, buf,
134 sizeof( buf ) ) );
135 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
136 mbedtls_ecp_point_read_binary( &grp, &P, NULL,
137 sizeof( buf ) ) );
138
139 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
140 mbedtls_ecp_tls_read_point( NULL, &P,
141 (const unsigned char **) &buf,
142 sizeof( buf ) ) );
143 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
144 mbedtls_ecp_tls_read_point( &grp, NULL,
145 (const unsigned char **) &buf,
146 sizeof( buf ) ) );
147 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
148 mbedtls_ecp_tls_read_point( &grp, &P, &null_buf,
149 sizeof( buf ) ) );
150 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
151 mbedtls_ecp_tls_read_point( &grp, &P, NULL,
152 sizeof( buf ) ) );
153
154 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
155 mbedtls_ecp_tls_write_point( NULL, &P,
156 valid_fmt,
157 &olen,
158 buf,
159 sizeof( buf ) ) );
160 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
161 mbedtls_ecp_tls_write_point( &grp, NULL,
162 valid_fmt,
163 &olen,
164 buf,
165 sizeof( buf ) ) );
166 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
167 mbedtls_ecp_tls_write_point( &grp, &P,
168 invalid_fmt,
169 &olen,
170 buf,
171 sizeof( buf ) ) );
172 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
173 mbedtls_ecp_tls_write_point( &grp, &P,
174 valid_fmt,
175 NULL,
176 buf,
177 sizeof( buf ) ) );
178 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
179 mbedtls_ecp_tls_write_point( &grp, &P,
180 valid_fmt,
181 &olen,
182 NULL,
183 sizeof( buf ) ) );
184
185 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
186 mbedtls_ecp_group_load( NULL, valid_group ) );
187
188 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
189 mbedtls_ecp_tls_read_group( NULL,
190 (const unsigned char **) &buf,
191 sizeof( buf ) ) );
192 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
193 mbedtls_ecp_tls_read_group( &grp, NULL,
194 sizeof( buf ) ) );
195 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
196 mbedtls_ecp_tls_read_group( &grp, &null_buf,
197 sizeof( buf ) ) );
198
199 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
200 mbedtls_ecp_tls_read_group_id( NULL,
201 (const unsigned char **) &buf,
202 sizeof( buf ) ) );
203 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
204 mbedtls_ecp_tls_read_group_id( &valid_group, NULL,
205 sizeof( buf ) ) );
206 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
207 mbedtls_ecp_tls_read_group_id( &valid_group,
208 &null_buf,
209 sizeof( buf ) ) );
210
211 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
212 mbedtls_ecp_tls_write_group( NULL, &olen,
213 buf, sizeof( buf ) ) );
214 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
215 mbedtls_ecp_tls_write_group( &grp, NULL,
216 buf, sizeof( buf ) ) );
217 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
218 mbedtls_ecp_tls_write_group( &grp, &olen,
219 NULL, sizeof( buf ) ) );
220
221 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
222 mbedtls_ecp_mul( NULL, &P, &m, &P,
223 rnd_std_rand, NULL ) );
224 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
225 mbedtls_ecp_mul( &grp, NULL, &m, &P,
226 rnd_std_rand, NULL ) );
227 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
228 mbedtls_ecp_mul( &grp, &P, NULL, &P,
229 rnd_std_rand, NULL ) );
230 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
231 mbedtls_ecp_mul( &grp, &P, &m, NULL,
232 rnd_std_rand, NULL ) );
233
234 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
235 mbedtls_ecp_mul_restartable( NULL, &P, &m, &P,
236 rnd_std_rand, NULL , NULL ) );
237 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
238 mbedtls_ecp_mul_restartable( &grp, NULL, &m, &P,
239 rnd_std_rand, NULL , NULL ) );
240 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
241 mbedtls_ecp_mul_restartable( &grp, &P, NULL, &P,
242 rnd_std_rand, NULL , NULL ) );
243 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
244 mbedtls_ecp_mul_restartable( &grp, &P, &m, NULL,
245 rnd_std_rand, NULL , NULL ) );
246
247 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
248 mbedtls_ecp_muladd( NULL, &P, &m, &P,
249 &m, &P ) );
250 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
251 mbedtls_ecp_muladd( &grp, NULL, &m, &P,
252 &m, &P ) );
253 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
254 mbedtls_ecp_muladd( &grp, &P, NULL, &P,
255 &m, &P ) );
256 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
257 mbedtls_ecp_muladd( &grp, &P, &m, NULL,
258 &m, &P ) );
259 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
260 mbedtls_ecp_muladd( &grp, &P, &m, &P,
261 NULL, &P ) );
262 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
263 mbedtls_ecp_muladd( &grp, &P, &m, &P,
264 &m, NULL ) );
265
266 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
267 mbedtls_ecp_muladd_restartable( NULL, &P, &m, &P,
268 &m, &P, NULL ) );
269 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
270 mbedtls_ecp_muladd_restartable( &grp, NULL, &m, &P,
271 &m, &P, NULL ) );
272 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
273 mbedtls_ecp_muladd_restartable( &grp, &P, NULL, &P,
274 &m, &P, NULL ) );
275 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
276 mbedtls_ecp_muladd_restartable( &grp, &P, &m, NULL,
277 &m, &P, NULL ) );
278 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
279 mbedtls_ecp_muladd_restartable( &grp, &P, &m, &P,
280 NULL, &P, NULL ) );
281 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
282 mbedtls_ecp_muladd_restartable( &grp, &P, &m, &P,
283 &m, NULL, NULL ) );
284
285 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
286 mbedtls_ecp_check_pubkey( NULL, &P ) );
287 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
288 mbedtls_ecp_check_pubkey( &grp, NULL ) );
289
290 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
291 mbedtls_ecp_check_privkey( NULL, &m ) );
292 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
293 mbedtls_ecp_check_privkey( &grp, NULL ) );
294
295 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
296 mbedtls_ecp_gen_keypair_base( NULL, &P,
297 &m, &P,
298 rnd_std_rand,
299 NULL ) );
300 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
301 mbedtls_ecp_gen_keypair_base( &grp, NULL,
302 &m, &P,
303 rnd_std_rand,
304 NULL ) );
305 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
306 mbedtls_ecp_gen_keypair_base( &grp, &P,
307 NULL, &P,
308 rnd_std_rand,
309 NULL ) );
310 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
311 mbedtls_ecp_gen_keypair_base( &grp, &P,
312 &m, NULL,
313 rnd_std_rand,
314 NULL ) );
315 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
316 mbedtls_ecp_gen_keypair_base( &grp, &P,
317 &m, &P,
318 NULL,
319 NULL ) );
320
321 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
322 mbedtls_ecp_gen_keypair( NULL,
323 &m, &P,
324 rnd_std_rand,
325 NULL ) );
326 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
327 mbedtls_ecp_gen_keypair( &grp,
328 NULL, &P,
329 rnd_std_rand,
330 NULL ) );
331 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
332 mbedtls_ecp_gen_keypair( &grp,
333 &m, NULL,
334 rnd_std_rand,
335 NULL ) );
336 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
337 mbedtls_ecp_gen_keypair( &grp,
338 &m, &P,
339 NULL,
340 NULL ) );
341
342 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
343 mbedtls_ecp_gen_key( valid_group, NULL,
344 rnd_std_rand, NULL ) );
345 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
346 mbedtls_ecp_gen_key( valid_group, &kp,
347 NULL, NULL ) );
348
349exit:
350 return;
351}
352/* END_CASE */
353
Paul Bakker33b43f12013-08-20 11:48:36 +0200354/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100355void mbedtls_ecp_curve_info( int id, int tls_id, int size, char * name )
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +0100356{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200357 const mbedtls_ecp_curve_info *by_id, *by_tls, *by_name;
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +0100358
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200359 by_id = mbedtls_ecp_curve_info_from_grp_id( id );
360 by_tls = mbedtls_ecp_curve_info_from_tls_id( tls_id );
361 by_name = mbedtls_ecp_curve_info_from_name( name );
Paul Bakker94b916c2014-04-17 16:07:20 +0200362 TEST_ASSERT( by_id != NULL );
363 TEST_ASSERT( by_tls != NULL );
364 TEST_ASSERT( by_name != NULL );
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +0100365
366 TEST_ASSERT( by_id == by_tls );
367 TEST_ASSERT( by_id == by_name );
368
Manuel Pégourié-Gonnard797f48a2015-06-18 15:45:05 +0200369 TEST_ASSERT( by_id->bit_size == size );
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +0100370}
371/* END_CASE */
372
373/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100374void ecp_check_pub( int grp_id, char * x_hex, char * y_hex, char * z_hex,
375 int ret )
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100376{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200377 mbedtls_ecp_group grp;
378 mbedtls_ecp_point P;
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100379
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200380 mbedtls_ecp_group_init( &grp );
381 mbedtls_ecp_point_init( &P );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100382
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200383 TEST_ASSERT( mbedtls_ecp_group_load( &grp, grp_id ) == 0 );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100384
Janos Follath28fff142017-01-27 15:51:14 +0000385 TEST_ASSERT( mbedtls_mpi_read_string( &P.X, 16, x_hex ) == 0 );
386 TEST_ASSERT( mbedtls_mpi_read_string( &P.Y, 16, y_hex ) == 0 );
387 TEST_ASSERT( mbedtls_mpi_read_string( &P.Z, 16, z_hex ) == 0 );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100388
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200389 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &P ) == ret );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100390
Paul Bakkerbd51b262014-07-10 15:26:12 +0200391exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200392 mbedtls_ecp_group_free( &grp );
393 mbedtls_ecp_point_free( &P );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100394}
395/* END_CASE */
396
Manuel Pégourié-Gonnard4b9c51e2017-04-20 15:50:26 +0200397/* BEGIN_CASE depends_on:MBEDTLS_ECP_RESTARTABLE */
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100398void ecp_test_vect_restart( int id,
399 char *dA_str, char *xA_str, char *yA_str,
400 char *dB_str, char *xZ_str, char *yZ_str,
401 int max_ops, int min_restarts, int max_restarts )
402{
403 /*
404 * Test for early restart. Based on test vectors like ecp_test_vect(),
405 * but for the sake of simplicity only does half of each side. It's
406 * important to test both base point and random point, though, as memory
407 * management is different in each case.
408 *
409 * Don't try using too precise bounds for restarts as the exact number
410 * will depend on settings such as MBEDTLS_ECP_FIXED_POINT_OPTIM and
411 * MBEDTLS_ECP_WINDOW_SIZE, as well as implementation details that may
412 * change in the future. A factor 2 is a minimum safety margin.
413 *
414 * For reference, with mbed TLS 2.4 and default settings, for P-256:
Manuel Pégourié-Gonnard9c5c78f2017-03-20 14:13:07 +0100415 * - Random point mult: ~3250M
416 * - Cold base point mult: ~3300M
417 * - Hot base point mult: ~1100M
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100418 * With MBEDTLS_ECP_WINDOW_SIZE set to 2 (minimum):
Manuel Pégourié-Gonnard9c5c78f2017-03-20 14:13:07 +0100419 * - Random point mult: ~3850M
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100420 */
Manuel Pégourié-Gonnardb739a712017-04-19 10:11:56 +0200421 mbedtls_ecp_restart_ctx ctx;
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100422 mbedtls_ecp_group grp;
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200423 mbedtls_ecp_point R, P;
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100424 mbedtls_mpi dA, xA, yA, dB, xZ, yZ;
425 int cnt_restarts;
426 int ret;
427
Manuel Pégourié-Gonnardb739a712017-04-19 10:11:56 +0200428 mbedtls_ecp_restart_init( &ctx );
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200429 mbedtls_ecp_group_init( &grp );
430 mbedtls_ecp_point_init( &R ); mbedtls_ecp_point_init( &P );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100431 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA ); mbedtls_mpi_init( &yA );
432 mbedtls_mpi_init( &dB ); mbedtls_mpi_init( &xZ ); mbedtls_mpi_init( &yZ );
433
434 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
435
436 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_str ) == 0 );
437 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_str ) == 0 );
438 TEST_ASSERT( mbedtls_mpi_read_string( &yA, 16, yA_str ) == 0 );
439
440 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_str ) == 0 );
441 TEST_ASSERT( mbedtls_mpi_read_string( &xZ, 16, xZ_str ) == 0 );
442 TEST_ASSERT( mbedtls_mpi_read_string( &yZ, 16, yZ_str ) == 0 );
443
444 mbedtls_ecp_set_max_ops( (unsigned) max_ops );
445
446 /* Base point case */
447 cnt_restarts = 0;
448 do {
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200449 ECP_PT_RESET( &R );
Manuel Pégourié-Gonnardb739a712017-04-19 10:11:56 +0200450 ret = mbedtls_ecp_mul_restartable( &grp, &R, &dA, &grp.G, NULL, NULL, &ctx );
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200451 } while( ret == MBEDTLS_ERR_ECP_IN_PROGRESS && ++cnt_restarts );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100452
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200453 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100454 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
455 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yA ) == 0 );
456
457 TEST_ASSERT( cnt_restarts >= min_restarts );
458 TEST_ASSERT( cnt_restarts <= max_restarts );
459
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100460 /* Non-base point case */
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200461 mbedtls_ecp_copy( &P, &R );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100462 cnt_restarts = 0;
463 do {
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200464 ECP_PT_RESET( &R );
465 ret = mbedtls_ecp_mul_restartable( &grp, &R, &dB, &P, NULL, NULL, &ctx );
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200466 } while( ret == MBEDTLS_ERR_ECP_IN_PROGRESS && ++cnt_restarts );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100467
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200468 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100469 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
470 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
471
472 TEST_ASSERT( cnt_restarts >= min_restarts );
473 TEST_ASSERT( cnt_restarts <= max_restarts );
474
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200475 /* Do we leak memory when aborting an operation?
476 * This test only makes sense when we actually restart */
477 if( min_restarts > 0 )
478 {
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200479 ret = mbedtls_ecp_mul_restartable( &grp, &R, &dB, &P, NULL, NULL, &ctx );
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200480 TEST_ASSERT( ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
481 }
Manuel Pégourié-Gonnard77af79a2017-03-14 10:58:00 +0100482
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100483exit:
Manuel Pégourié-Gonnardb739a712017-04-19 10:11:56 +0200484 mbedtls_ecp_restart_free( &ctx );
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200485 mbedtls_ecp_group_free( &grp );
486 mbedtls_ecp_point_free( &R ); mbedtls_ecp_point_free( &P );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100487 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA ); mbedtls_mpi_free( &yA );
488 mbedtls_mpi_free( &dB ); mbedtls_mpi_free( &xZ ); mbedtls_mpi_free( &yZ );
489}
490/* END_CASE */
491
Manuel Pégourié-Gonnard4b9c51e2017-04-20 15:50:26 +0200492/* BEGIN_CASE depends_on:MBEDTLS_ECP_RESTARTABLE */
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200493void ecp_muladd_restart( int id, char *xR_str, char *yR_str,
494 char *u1_str, char *u2_str,
495 char *xQ_str, char *yQ_str,
496 int max_ops, int min_restarts, int max_restarts )
497{
498 /*
499 * Compute R = u1 * G + u2 * Q
500 * (test vectors mostly taken from ECDSA intermediate results)
501 *
502 * See comments at the top of ecp_test_vect_restart()
503 */
504 mbedtls_ecp_restart_ctx ctx;
505 mbedtls_ecp_group grp;
506 mbedtls_ecp_point R, Q;
507 mbedtls_mpi u1, u2, xR, yR;
508 int cnt_restarts;
509 int ret;
510
511 mbedtls_ecp_restart_init( &ctx );
512 mbedtls_ecp_group_init( &grp );
513 mbedtls_ecp_point_init( &R );
514 mbedtls_ecp_point_init( &Q );
515 mbedtls_mpi_init( &u1 ); mbedtls_mpi_init( &u2 );
516 mbedtls_mpi_init( &xR ); mbedtls_mpi_init( &yR );
517
518 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
519
520 TEST_ASSERT( mbedtls_mpi_read_string( &u1, 16, u1_str ) == 0 );
521 TEST_ASSERT( mbedtls_mpi_read_string( &u2, 16, u2_str ) == 0 );
522 TEST_ASSERT( mbedtls_mpi_read_string( &xR, 16, xR_str ) == 0 );
523 TEST_ASSERT( mbedtls_mpi_read_string( &yR, 16, yR_str ) == 0 );
524
525 TEST_ASSERT( mbedtls_mpi_read_string( &Q.X, 16, xQ_str ) == 0 );
526 TEST_ASSERT( mbedtls_mpi_read_string( &Q.Y, 16, yQ_str ) == 0 );
527 TEST_ASSERT( mbedtls_mpi_lset( &Q.Z, 1 ) == 0 );
528
529 mbedtls_ecp_set_max_ops( (unsigned) max_ops );
530
531 cnt_restarts = 0;
532 do {
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200533 ECP_PT_RESET( &R );
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200534 ret = mbedtls_ecp_muladd_restartable( &grp, &R,
535 &u1, &grp.G, &u2, &Q, &ctx );
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200536 } while( ret == MBEDTLS_ERR_ECP_IN_PROGRESS && ++cnt_restarts );
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200537
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200538 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200539 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xR ) == 0 );
540 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yR ) == 0 );
541
542 TEST_ASSERT( cnt_restarts >= min_restarts );
543 TEST_ASSERT( cnt_restarts <= max_restarts );
544
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200545 /* Do we leak memory when aborting an operation?
546 * This test only makes sense when we actually restart */
547 if( min_restarts > 0 )
548 {
549 ret = mbedtls_ecp_muladd_restartable( &grp, &R,
550 &u1, &grp.G, &u2, &Q, &ctx );
551 TEST_ASSERT( ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
552 }
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200553
554exit:
555 mbedtls_ecp_restart_free( &ctx );
556 mbedtls_ecp_group_free( &grp );
557 mbedtls_ecp_point_free( &R );
558 mbedtls_ecp_point_free( &Q );
559 mbedtls_mpi_free( &u1 ); mbedtls_mpi_free( &u2 );
560 mbedtls_mpi_free( &xR ); mbedtls_mpi_free( &yR );
561}
562/* END_CASE */
563
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100564/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100565void ecp_test_vect( int id, char * dA_str, char * xA_str, char * yA_str,
566 char * dB_str, char * xB_str, char * yB_str,
567 char * xZ_str, char * yZ_str )
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100568{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200569 mbedtls_ecp_group grp;
570 mbedtls_ecp_point R;
571 mbedtls_mpi dA, xA, yA, dB, xB, yB, xZ, yZ;
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200572 rnd_pseudo_info rnd_info;
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100573
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200574 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &R );
575 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA ); mbedtls_mpi_init( &yA ); mbedtls_mpi_init( &dB );
576 mbedtls_mpi_init( &xB ); mbedtls_mpi_init( &yB ); mbedtls_mpi_init( &xZ ); mbedtls_mpi_init( &yZ );
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200577 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100578
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200579 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100580
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200581 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &grp.G ) == 0 );
Manuel Pégourié-Gonnard1c330572012-11-24 12:05:44 +0100582
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200583 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_str ) == 0 );
584 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_str ) == 0 );
585 TEST_ASSERT( mbedtls_mpi_read_string( &yA, 16, yA_str ) == 0 );
586 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_str ) == 0 );
587 TEST_ASSERT( mbedtls_mpi_read_string( &xB, 16, xB_str ) == 0 );
588 TEST_ASSERT( mbedtls_mpi_read_string( &yB, 16, yB_str ) == 0 );
589 TEST_ASSERT( mbedtls_mpi_read_string( &xZ, 16, xZ_str ) == 0 );
590 TEST_ASSERT( mbedtls_mpi_read_string( &yZ, 16, yZ_str ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100591
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200592 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &grp.G,
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200593 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200594 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
595 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yA ) == 0 );
596 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
597 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &R, NULL, NULL ) == 0 );
598 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
599 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
600 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100601
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200602 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &grp.G, NULL, NULL ) == 0 );
603 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xB ) == 0 );
604 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yB ) == 0 );
605 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
606 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &R,
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200607 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200608 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
609 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
610 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100611
Paul Bakkerbd51b262014-07-10 15:26:12 +0200612exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200613 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &R );
614 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA ); mbedtls_mpi_free( &yA ); mbedtls_mpi_free( &dB );
615 mbedtls_mpi_free( &xB ); mbedtls_mpi_free( &yB ); mbedtls_mpi_free( &xZ ); mbedtls_mpi_free( &yZ );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100616}
Paul Bakker33b43f12013-08-20 11:48:36 +0200617/* END_CASE */
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100618
Paul Bakker33b43f12013-08-20 11:48:36 +0200619/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100620void ecp_test_vec_x( int id, char * dA_hex, char * xA_hex, char * dB_hex,
621 char * xB_hex, char * xS_hex )
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100622{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200623 mbedtls_ecp_group grp;
624 mbedtls_ecp_point R;
625 mbedtls_mpi dA, xA, dB, xB, xS;
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100626 rnd_pseudo_info rnd_info;
627
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200628 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &R );
629 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA );
630 mbedtls_mpi_init( &dB ); mbedtls_mpi_init( &xB );
631 mbedtls_mpi_init( &xS );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100632 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
633
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200634 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100635
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200636 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &grp.G ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100637
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200638 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_hex ) == 0 );
639 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_hex ) == 0 );
640 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_hex ) == 0 );
641 TEST_ASSERT( mbedtls_mpi_read_string( &xB, 16, xB_hex ) == 0 );
642 TEST_ASSERT( mbedtls_mpi_read_string( &xS, 16, xS_hex ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100643
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200644 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &grp.G,
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100645 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200646 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
647 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100648
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200649 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &R,
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100650 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200651 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
652 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xS ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100653
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200654 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &grp.G, NULL, NULL ) == 0 );
655 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
656 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xB ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100657
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200658 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &R, NULL, NULL ) == 0 );
659 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
660 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xS ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100661
Paul Bakkerbd51b262014-07-10 15:26:12 +0200662exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200663 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &R );
664 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA );
665 mbedtls_mpi_free( &dB ); mbedtls_mpi_free( &xB );
666 mbedtls_mpi_free( &xS );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100667}
668/* END_CASE */
669
670/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100671void ecp_fast_mod( int id, char * N_str )
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100672{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200673 mbedtls_ecp_group grp;
674 mbedtls_mpi N, R;
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100675
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200676 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &R );
677 mbedtls_ecp_group_init( &grp );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100678
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200679 TEST_ASSERT( mbedtls_mpi_read_string( &N, 16, N_str ) == 0 );
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200680 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarde783f062013-10-21 14:52:21 +0200681 TEST_ASSERT( grp.modp != NULL );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100682
683 /*
684 * Store correct result before we touch N
685 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200686 TEST_ASSERT( mbedtls_mpi_mod_mpi( &R, &N, &grp.P ) == 0 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100687
688 TEST_ASSERT( grp.modp( &N ) == 0 );
Manuel Pégourié-Gonnardc0696c22015-06-18 16:47:17 +0200689 TEST_ASSERT( mbedtls_mpi_bitlen( &N ) <= grp.pbits + 3 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100690
691 /*
Paul Bakkerd8b0c5e2014-04-11 15:31:33 +0200692 * Use mod rather than addition/subtraction in case previous test fails
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100693 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200694 TEST_ASSERT( mbedtls_mpi_mod_mpi( &N, &N, &grp.P ) == 0 );
695 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &N, &R ) == 0 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100696
Paul Bakkerbd51b262014-07-10 15:26:12 +0200697exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200698 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &R );
699 mbedtls_ecp_group_free( &grp );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100700}
Paul Bakker33b43f12013-08-20 11:48:36 +0200701/* END_CASE */
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +0100702
Paul Bakker33b43f12013-08-20 11:48:36 +0200703/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100704void ecp_write_binary( int id, char * x, char * y, char * z, int format,
Azim Khan5fcca462018-06-29 11:05:32 +0100705 data_t * out, int blen, int ret )
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100706{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200707 mbedtls_ecp_group grp;
708 mbedtls_ecp_point P;
Azim Khanf1aaec92017-05-30 14:23:15 +0100709 unsigned char buf[256];
Manuel Pégourié-Gonnard420f1eb2013-02-10 12:22:46 +0100710 size_t olen;
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100711
712 memset( buf, 0, sizeof( buf ) );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100713
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200714 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100715
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200716 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100717
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200718 TEST_ASSERT( mbedtls_mpi_read_string( &P.X, 16, x ) == 0 );
719 TEST_ASSERT( mbedtls_mpi_read_string( &P.Y, 16, y ) == 0 );
720 TEST_ASSERT( mbedtls_mpi_read_string( &P.Z, 16, z ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100721
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200722 TEST_ASSERT( mbedtls_ecp_point_write_binary( &grp, &P, format,
Paul Bakker33b43f12013-08-20 11:48:36 +0200723 &olen, buf, blen ) == ret );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100724
Paul Bakker33b43f12013-08-20 11:48:36 +0200725 if( ret == 0 )
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100726 {
Azim Khand30ca132017-06-09 04:32:58 +0100727 TEST_ASSERT( hexcmp( buf, out->x, olen, out->len ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100728 }
729
Paul Bakkerbd51b262014-07-10 15:26:12 +0200730exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200731 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100732}
Paul Bakker33b43f12013-08-20 11:48:36 +0200733/* END_CASE */
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100734
Paul Bakker33b43f12013-08-20 11:48:36 +0200735/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100736void ecp_read_binary( int id, data_t * buf, char * x, char * y, char * z,
Paul Bakker33b43f12013-08-20 11:48:36 +0200737 int ret )
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100738{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200739 mbedtls_ecp_group grp;
740 mbedtls_ecp_point P;
741 mbedtls_mpi X, Y, Z;
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100742
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100743
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200744 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
745 mbedtls_mpi_init( &X ); mbedtls_mpi_init( &Y ); mbedtls_mpi_init( &Z );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100746
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200747 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100748
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200749 TEST_ASSERT( mbedtls_mpi_read_string( &X, 16, x ) == 0 );
750 TEST_ASSERT( mbedtls_mpi_read_string( &Y, 16, y ) == 0 );
751 TEST_ASSERT( mbedtls_mpi_read_string( &Z, 16, z ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100752
Azim Khand30ca132017-06-09 04:32:58 +0100753 TEST_ASSERT( mbedtls_ecp_point_read_binary( &grp, &P, buf->x, buf->len ) == ret );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100754
Paul Bakker33b43f12013-08-20 11:48:36 +0200755 if( ret == 0 )
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100756 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200757 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.X, &X ) == 0 );
758 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Y, &Y ) == 0 );
759 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Z, &Z ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100760 }
761
Paul Bakkerbd51b262014-07-10 15:26:12 +0200762exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200763 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
764 mbedtls_mpi_free( &X ); mbedtls_mpi_free( &Y ); mbedtls_mpi_free( &Z );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100765}
Paul Bakker33b43f12013-08-20 11:48:36 +0200766/* END_CASE */
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100767
Paul Bakker33b43f12013-08-20 11:48:36 +0200768/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100769void mbedtls_ecp_tls_read_point( int id, data_t * buf, char * x, char * y,
Azim Khand30ca132017-06-09 04:32:58 +0100770 char * z, int ret )
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100771{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200772 mbedtls_ecp_group grp;
773 mbedtls_ecp_point P;
774 mbedtls_mpi X, Y, Z;
Azim Khand30ca132017-06-09 04:32:58 +0100775 const unsigned char *vbuf = buf->x;
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100776
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100777
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200778 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
779 mbedtls_mpi_init( &X ); mbedtls_mpi_init( &Y ); mbedtls_mpi_init( &Z );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100780
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200781 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100782
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200783 TEST_ASSERT( mbedtls_mpi_read_string( &X, 16, x ) == 0 );
784 TEST_ASSERT( mbedtls_mpi_read_string( &Y, 16, y ) == 0 );
785 TEST_ASSERT( mbedtls_mpi_read_string( &Z, 16, z ) == 0 );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100786
Azim Khand30ca132017-06-09 04:32:58 +0100787 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &P, &vbuf, buf->len ) == ret );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100788
Paul Bakker33b43f12013-08-20 11:48:36 +0200789 if( ret == 0 )
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100790 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200791 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.X, &X ) == 0 );
792 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Y, &Y ) == 0 );
793 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Z, &Z ) == 0 );
Azim Khand30ca132017-06-09 04:32:58 +0100794 TEST_ASSERT( (uint32_t)( vbuf - buf->x ) == buf->len );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100795 }
796
Paul Bakkerbd51b262014-07-10 15:26:12 +0200797exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200798 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
799 mbedtls_mpi_free( &X ); mbedtls_mpi_free( &Y ); mbedtls_mpi_free( &Z );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100800}
Paul Bakker33b43f12013-08-20 11:48:36 +0200801/* END_CASE */
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100802
Paul Bakker33b43f12013-08-20 11:48:36 +0200803/* BEGIN_CASE */
804void ecp_tls_write_read_point( int id )
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100805{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200806 mbedtls_ecp_group grp;
807 mbedtls_ecp_point pt;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100808 unsigned char buf[256];
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100809 const unsigned char *vbuf;
Manuel Pégourié-Gonnard420f1eb2013-02-10 12:22:46 +0100810 size_t olen;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100811
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200812 mbedtls_ecp_group_init( &grp );
813 mbedtls_ecp_point_init( &pt );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100814
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200815 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100816
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100817 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200818 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &grp.G,
819 MBEDTLS_ECP_PF_COMPRESSED, &olen, buf, 256 ) == 0 );
820 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen )
821 == MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100822 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100823
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100824 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200825 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &grp.G,
826 MBEDTLS_ECP_PF_UNCOMPRESSED, &olen, buf, 256 ) == 0 );
827 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
828 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.X, &pt.X ) == 0 );
829 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.Y, &pt.Y ) == 0 );
830 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.Z, &pt.Z ) == 0 );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100831 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100832
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100833 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200834 TEST_ASSERT( mbedtls_ecp_set_zero( &pt ) == 0 );
835 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &pt,
836 MBEDTLS_ECP_PF_COMPRESSED, &olen, buf, 256 ) == 0 );
837 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
838 TEST_ASSERT( mbedtls_ecp_is_zero( &pt ) );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100839 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100840
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100841 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200842 TEST_ASSERT( mbedtls_ecp_set_zero( &pt ) == 0 );
843 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &pt,
844 MBEDTLS_ECP_PF_UNCOMPRESSED, &olen, buf, 256 ) == 0 );
845 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
846 TEST_ASSERT( mbedtls_ecp_is_zero( &pt ) );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100847 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100848
Paul Bakkerbd51b262014-07-10 15:26:12 +0200849exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200850 mbedtls_ecp_group_free( &grp );
851 mbedtls_ecp_point_free( &pt );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100852}
Paul Bakker33b43f12013-08-20 11:48:36 +0200853/* END_CASE */
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100854
Paul Bakker33b43f12013-08-20 11:48:36 +0200855/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100856void mbedtls_ecp_tls_read_group( data_t * buf, int result, int bits,
Azim Khand30ca132017-06-09 04:32:58 +0100857 int record_len )
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100858{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200859 mbedtls_ecp_group grp;
Azim Khand30ca132017-06-09 04:32:58 +0100860 const unsigned char *vbuf = buf->x;
Azim Khanf1aaec92017-05-30 14:23:15 +0100861 int ret;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100862
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200863 mbedtls_ecp_group_init( &grp );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100864
Azim Khand30ca132017-06-09 04:32:58 +0100865 ret = mbedtls_ecp_tls_read_group( &grp, &vbuf, buf->len );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100866
Paul Bakker33b43f12013-08-20 11:48:36 +0200867 TEST_ASSERT( ret == result );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100868 if( ret == 0)
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100869 {
Manuel Pégourié-Gonnardc0696c22015-06-18 16:47:17 +0200870 TEST_ASSERT( mbedtls_mpi_bitlen( &grp.P ) == (size_t) bits );
Azim Khand30ca132017-06-09 04:32:58 +0100871 TEST_ASSERT( vbuf - buf->x == record_len);
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100872 }
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100873
Paul Bakkerbd51b262014-07-10 15:26:12 +0200874exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200875 mbedtls_ecp_group_free( &grp );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100876}
Paul Bakker33b43f12013-08-20 11:48:36 +0200877/* END_CASE */
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100878
Paul Bakker33b43f12013-08-20 11:48:36 +0200879/* BEGIN_CASE */
880void ecp_tls_write_read_group( int id )
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100881{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200882 mbedtls_ecp_group grp1, grp2;
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100883 unsigned char buf[10];
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100884 const unsigned char *vbuf = buf;
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100885 size_t len;
886 int ret;
887
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200888 mbedtls_ecp_group_init( &grp1 );
889 mbedtls_ecp_group_init( &grp2 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100890 memset( buf, 0x00, sizeof( buf ) );
891
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200892 TEST_ASSERT( mbedtls_ecp_group_load( &grp1, id ) == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100893
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200894 TEST_ASSERT( mbedtls_ecp_tls_write_group( &grp1, &len, buf, 10 ) == 0 );
895 ret = mbedtls_ecp_tls_read_group( &grp2, &vbuf, len );
Paul Bakker94b916c2014-04-17 16:07:20 +0200896 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100897
898 if( ret == 0 )
899 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200900 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp1.N, &grp2.N ) == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100901 TEST_ASSERT( grp1.id == grp2.id );
902 }
903
Paul Bakkerbd51b262014-07-10 15:26:12 +0200904exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200905 mbedtls_ecp_group_free( &grp1 );
906 mbedtls_ecp_group_free( &grp2 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100907}
Paul Bakker33b43f12013-08-20 11:48:36 +0200908/* END_CASE */
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100909
Paul Bakker33b43f12013-08-20 11:48:36 +0200910/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100911void mbedtls_ecp_check_privkey( int id, char * key_hex, int ret )
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200912{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200913 mbedtls_ecp_group grp;
914 mbedtls_mpi d;
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200915
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200916 mbedtls_ecp_group_init( &grp );
917 mbedtls_mpi_init( &d );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200918
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200919 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200920 TEST_ASSERT( mbedtls_mpi_read_string( &d, 16, key_hex ) == 0 );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200921
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200922 TEST_ASSERT( mbedtls_ecp_check_privkey( &grp, &d ) == ret );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200923
Paul Bakkerbd51b262014-07-10 15:26:12 +0200924exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200925 mbedtls_ecp_group_free( &grp );
926 mbedtls_mpi_free( &d );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200927}
Paul Bakker33b43f12013-08-20 11:48:36 +0200928/* END_CASE */
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200929
Paul Bakker33b43f12013-08-20 11:48:36 +0200930/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100931void mbedtls_ecp_check_pub_priv( int id_pub, char * Qx_pub, char * Qy_pub,
932 int id, char * d, char * Qx, char * Qy,
933 int ret )
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100934{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200935 mbedtls_ecp_keypair pub, prv;
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100936
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200937 mbedtls_ecp_keypair_init( &pub );
938 mbedtls_ecp_keypair_init( &prv );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100939
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200940 if( id_pub != MBEDTLS_ECP_DP_NONE )
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200941 TEST_ASSERT( mbedtls_ecp_group_load( &pub.grp, id_pub ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200942 TEST_ASSERT( mbedtls_ecp_point_read_string( &pub.Q, 16, Qx_pub, Qy_pub ) == 0 );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100943
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200944 if( id != MBEDTLS_ECP_DP_NONE )
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200945 TEST_ASSERT( mbedtls_ecp_group_load( &prv.grp, id ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200946 TEST_ASSERT( mbedtls_ecp_point_read_string( &prv.Q, 16, Qx, Qy ) == 0 );
947 TEST_ASSERT( mbedtls_mpi_read_string( &prv.d, 16, d ) == 0 );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100948
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200949 TEST_ASSERT( mbedtls_ecp_check_pub_priv( &pub, &prv ) == ret );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100950
951exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200952 mbedtls_ecp_keypair_free( &pub );
953 mbedtls_ecp_keypair_free( &prv );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100954}
955/* END_CASE */
956
957/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200958void mbedtls_ecp_gen_keypair( int id )
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100959{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200960 mbedtls_ecp_group grp;
961 mbedtls_ecp_point Q;
962 mbedtls_mpi d;
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100963 rnd_pseudo_info rnd_info;
964
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200965 mbedtls_ecp_group_init( &grp );
966 mbedtls_ecp_point_init( &Q );
967 mbedtls_mpi_init( &d );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100968 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
969
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200970 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100971
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200972 TEST_ASSERT( mbedtls_ecp_gen_keypair( &grp, &d, &Q, &rnd_pseudo_rand, &rnd_info )
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100973 == 0 );
974
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200975 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &Q ) == 0 );
976 TEST_ASSERT( mbedtls_ecp_check_privkey( &grp, &d ) == 0 );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100977
Paul Bakkerbd51b262014-07-10 15:26:12 +0200978exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200979 mbedtls_ecp_group_free( &grp );
980 mbedtls_ecp_point_free( &Q );
981 mbedtls_mpi_free( &d );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100982}
Paul Bakker33b43f12013-08-20 11:48:36 +0200983/* END_CASE */
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100984
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100985/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200986void mbedtls_ecp_gen_key( int id )
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100987{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200988 mbedtls_ecp_keypair key;
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100989 rnd_pseudo_info rnd_info;
990
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200991 mbedtls_ecp_keypair_init( &key );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100992 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
993
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200994 TEST_ASSERT( mbedtls_ecp_gen_key( id, &key, &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100995
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200996 TEST_ASSERT( mbedtls_ecp_check_pubkey( &key.grp, &key.Q ) == 0 );
997 TEST_ASSERT( mbedtls_ecp_check_privkey( &key.grp, &key.d ) == 0 );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100998
Paul Bakkerbd51b262014-07-10 15:26:12 +0200999exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001000 mbedtls_ecp_keypair_free( &key );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +01001001}
1002/* END_CASE */
1003
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001004/* BEGIN_CASE depends_on:MBEDTLS_SELF_TEST */
Azim Khanf1aaec92017-05-30 14:23:15 +01001005void ecp_selftest( )
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +01001006{
Andres AG93012e82016-09-09 09:10:28 +01001007 TEST_ASSERT( mbedtls_ecp_self_test( 1 ) == 0 );
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +01001008}
Paul Bakker33b43f12013-08-20 11:48:36 +02001009/* END_CASE */