blob: 13bc40062328ba62f640dfe8d65e4311f3698fa1 [file] [log] [blame]
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +01001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/hmac_drbg.h"
Mohammad Azim Khan67735d52017-04-06 11:55:43 +01003#include "string.h"
Rich Evans00ab4702015-02-06 13:43:58 +00004
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +01005typedef struct
6{
7 unsigned char *p;
8 size_t len;
9} entropy_ctx;
10
Reut Caspie278b362017-10-19 08:49:19 +010011static int mbedtls_test_entropy_func( void *data, unsigned char *buf, size_t len )
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +010012{
13 entropy_ctx *ctx = (entropy_ctx *) data;
14
15 if( len > ctx->len )
16 return( -1 );
17
18 memcpy( buf, ctx->p, len );
19
20 ctx->p += len;
21 ctx->len -= len;
22
23 return( 0 );
24}
25/* END_HEADER */
26
27/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020028 * depends_on:MBEDTLS_HMAC_DRBG_C
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +010029 * END_DEPENDENCIES
30 */
31
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010032/* BEGIN_CASE */
33void hmac_drbg_entropy_usage( int md_alg )
34{
35 unsigned char out[16];
36 unsigned char buf[1024];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020037 const mbedtls_md_info_t *md_info;
38 mbedtls_hmac_drbg_context ctx;
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010039 entropy_ctx entropy;
40 size_t last_len, i, reps = 10;
41
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +020042 mbedtls_hmac_drbg_init( &ctx );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010043 memset( buf, 0, sizeof( buf ) );
44 memset( out, 0, sizeof( out ) );
45
46 entropy.len = sizeof( buf );
47 entropy.p = buf;
48
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020049 md_info = mbedtls_md_info_from_type( md_alg );
Paul Bakker94b916c2014-04-17 16:07:20 +020050 TEST_ASSERT( md_info != NULL );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010051
52 /* Init must use entropy */
53 last_len = entropy.len;
Reut Caspie278b362017-10-19 08:49:19 +010054 TEST_ASSERT( mbedtls_hmac_drbg_seed( &ctx, md_info, mbedtls_test_entropy_func, &entropy,
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010055 NULL, 0 ) == 0 );
56 TEST_ASSERT( entropy.len < last_len );
57
58 /* By default, PR is off and reseed_interval is large,
59 * so the next few calls should not use entropy */
60 last_len = entropy.len;
61 for( i = 0; i < reps; i++ )
62 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020063 TEST_ASSERT( mbedtls_hmac_drbg_random( &ctx, out, sizeof( out ) - 4 ) == 0 );
64 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, out, sizeof( out ) - 4,
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010065 buf, 16 ) == 0 );
66 }
67 TEST_ASSERT( entropy.len == last_len );
68
69 /* While at it, make sure we didn't write past the requested length */
70 TEST_ASSERT( out[sizeof( out ) - 4] == 0 );
71 TEST_ASSERT( out[sizeof( out ) - 3] == 0 );
72 TEST_ASSERT( out[sizeof( out ) - 2] == 0 );
73 TEST_ASSERT( out[sizeof( out ) - 1] == 0 );
74
75 /* Set reseed_interval to the number of calls done,
76 * so the next call should reseed */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020077 mbedtls_hmac_drbg_set_reseed_interval( &ctx, 2 * reps );
78 TEST_ASSERT( mbedtls_hmac_drbg_random( &ctx, out, sizeof( out ) ) == 0 );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010079 TEST_ASSERT( entropy.len < last_len );
80
81 /* The new few calls should not reseed */
82 last_len = entropy.len;
83 for( i = 0; i < reps / 2; i++ )
84 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020085 TEST_ASSERT( mbedtls_hmac_drbg_random( &ctx, out, sizeof( out ) ) == 0 );
86 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, out, sizeof( out ) ,
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010087 buf, 16 ) == 0 );
88 }
89 TEST_ASSERT( entropy.len == last_len );
90
91 /* Now enable PR, so the next few calls should all reseed */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020092 mbedtls_hmac_drbg_set_prediction_resistance( &ctx, MBEDTLS_HMAC_DRBG_PR_ON );
93 TEST_ASSERT( mbedtls_hmac_drbg_random( &ctx, out, sizeof( out ) ) == 0 );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010094 TEST_ASSERT( entropy.len < last_len );
95
96 /* Finally, check setting entropy_len */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020097 mbedtls_hmac_drbg_set_entropy_len( &ctx, 42 );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +010098 last_len = entropy.len;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020099 TEST_ASSERT( mbedtls_hmac_drbg_random( &ctx, out, sizeof( out ) ) == 0 );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100100 TEST_ASSERT( (int) last_len - entropy.len == 42 );
101
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200102 mbedtls_hmac_drbg_set_entropy_len( &ctx, 13 );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100103 last_len = entropy.len;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200104 TEST_ASSERT( mbedtls_hmac_drbg_random( &ctx, out, sizeof( out ) ) == 0 );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100105 TEST_ASSERT( (int) last_len - entropy.len == 13 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200106
107exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200108 mbedtls_hmac_drbg_free( &ctx );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100109}
110/* END_CASE */
111
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200112/* BEGIN_CASE depends_on:MBEDTLS_FS_IO */
Azim Khanf1aaec92017-05-30 14:23:15 +0100113void hmac_drbg_seed_file( int md_alg, char * path, int ret )
Manuel Pégourié-Gonnard48bc3e82014-01-30 21:11:16 +0100114{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200115 const mbedtls_md_info_t *md_info;
116 mbedtls_hmac_drbg_context ctx;
Manuel Pégourié-Gonnard48bc3e82014-01-30 21:11:16 +0100117
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +0200118 mbedtls_hmac_drbg_init( &ctx );
119
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200120 md_info = mbedtls_md_info_from_type( md_alg );
Paul Bakker94b916c2014-04-17 16:07:20 +0200121 TEST_ASSERT( md_info != NULL );
122
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +0200123 TEST_ASSERT( mbedtls_hmac_drbg_seed( &ctx, md_info, rnd_std_rand, NULL,
Manuel Pégourié-Gonnard48bc3e82014-01-30 21:11:16 +0100124 NULL, 0 ) == 0 );
125
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200126 TEST_ASSERT( mbedtls_hmac_drbg_write_seed_file( &ctx, path ) == ret );
127 TEST_ASSERT( mbedtls_hmac_drbg_update_seed_file( &ctx, path ) == ret );
Manuel Pégourié-Gonnard48bc3e82014-01-30 21:11:16 +0100128
Paul Bakkerbd51b262014-07-10 15:26:12 +0200129exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200130 mbedtls_hmac_drbg_free( &ctx );
Manuel Pégourié-Gonnard48bc3e82014-01-30 21:11:16 +0100131}
132/* END_CASE */
133
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100134/* BEGIN_CASE */
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100135void hmac_drbg_buf( int md_alg )
136{
137 unsigned char out[16];
138 unsigned char buf[100];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200139 const mbedtls_md_info_t *md_info;
140 mbedtls_hmac_drbg_context ctx;
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100141 size_t i;
142
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +0200143 mbedtls_hmac_drbg_init( &ctx );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100144 memset( buf, 0, sizeof( buf ) );
145 memset( out, 0, sizeof( out ) );
146
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200147 md_info = mbedtls_md_info_from_type( md_alg );
Paul Bakker94b916c2014-04-17 16:07:20 +0200148 TEST_ASSERT( md_info != NULL );
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +0200149 TEST_ASSERT( mbedtls_hmac_drbg_seed_buf( &ctx, md_info, buf, sizeof( buf ) ) == 0 );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100150
151 /* Make sure it never tries to reseed (would segfault otherwise) */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200152 mbedtls_hmac_drbg_set_reseed_interval( &ctx, 3 );
153 mbedtls_hmac_drbg_set_prediction_resistance( &ctx, MBEDTLS_HMAC_DRBG_PR_ON );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100154
155 for( i = 0; i < 30; i++ )
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200156 TEST_ASSERT( mbedtls_hmac_drbg_random( &ctx, out, sizeof( out ) ) == 0 );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100157
Paul Bakkerbd51b262014-07-10 15:26:12 +0200158exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200159 mbedtls_hmac_drbg_free( &ctx );
Manuel Pégourié-Gonnard4f880a52014-01-30 22:39:42 +0100160}
161/* END_CASE */
162
163/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100164void hmac_drbg_no_reseed( int md_alg, data_t * entropy,
165 data_t * custom, data_t * add1,
166 data_t * add2, data_t * output )
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100167{
Manuel Pégourié-Gonnarde6cdbbd2014-02-01 11:30:03 +0100168 unsigned char data[1024];
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100169 unsigned char my_output[512];
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100170 entropy_ctx p_entropy;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200171 const mbedtls_md_info_t *md_info;
172 mbedtls_hmac_drbg_context ctx;
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100173
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +0200174 mbedtls_hmac_drbg_init( &ctx );
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100175
Azim Khand30ca132017-06-09 04:32:58 +0100176 p_entropy.p = entropy->x;
177 p_entropy.len = entropy->len;
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100178
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200179 md_info = mbedtls_md_info_from_type( md_alg );
Paul Bakker94b916c2014-04-17 16:07:20 +0200180 TEST_ASSERT( md_info != NULL );
Manuel Pégourié-Gonnarde6cdbbd2014-02-01 11:30:03 +0100181
182 /* Test the simplified buffer-based variant */
Azim Khand30ca132017-06-09 04:32:58 +0100183 memcpy( data, entropy->x, p_entropy.len );
184 memcpy( data + p_entropy.len, custom->x, custom->len );
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +0200185 TEST_ASSERT( mbedtls_hmac_drbg_seed_buf( &ctx, md_info,
Azim Khand30ca132017-06-09 04:32:58 +0100186 data, p_entropy.len + custom->len ) == 0 );
187 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, my_output, output->len,
188 add1->x, add1->len ) == 0 );
189 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, my_output, output->len,
190 add2->x, add2->len ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200191
192 /* clear for second run */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200193 mbedtls_hmac_drbg_free( &ctx );
Manuel Pégourié-Gonnarde6cdbbd2014-02-01 11:30:03 +0100194
Azim Khand30ca132017-06-09 04:32:58 +0100195 TEST_ASSERT( memcmp( my_output, output->x, output->len ) == 0 );
Manuel Pégourié-Gonnarde6cdbbd2014-02-01 11:30:03 +0100196
197 /* And now the normal entropy-based variant */
Reut Caspie278b362017-10-19 08:49:19 +0100198 TEST_ASSERT( mbedtls_hmac_drbg_seed( &ctx, md_info, mbedtls_test_entropy_func, &p_entropy,
Azim Khand30ca132017-06-09 04:32:58 +0100199 custom->x, custom->len ) == 0 );
200 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, my_output, output->len,
201 add1->x, add1->len ) == 0 );
202 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, my_output, output->len,
203 add2->x, add2->len ) == 0 );
204 TEST_ASSERT( memcmp( my_output, output->x, output->len ) == 0 );
Manuel Pégourié-Gonnarde6cdbbd2014-02-01 11:30:03 +0100205
Paul Bakkerbd51b262014-07-10 15:26:12 +0200206exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200207 mbedtls_hmac_drbg_free( &ctx );
Manuel Pégourié-Gonnard24600b72014-01-31 09:54:14 +0100208}
209/* END_CASE */
210
211/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100212void hmac_drbg_nopr( int md_alg, data_t * entropy, data_t * custom,
213 data_t * add1, data_t * add2, data_t * add3,
214 data_t * output )
Manuel Pégourié-Gonnard24600b72014-01-31 09:54:14 +0100215{
Manuel Pégourié-Gonnard24600b72014-01-31 09:54:14 +0100216 unsigned char my_output[512];
Manuel Pégourié-Gonnard24600b72014-01-31 09:54:14 +0100217 entropy_ctx p_entropy;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200218 const mbedtls_md_info_t *md_info;
219 mbedtls_hmac_drbg_context ctx;
Manuel Pégourié-Gonnard24600b72014-01-31 09:54:14 +0100220
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +0200221 mbedtls_hmac_drbg_init( &ctx );
Manuel Pégourié-Gonnard24600b72014-01-31 09:54:14 +0100222
Azim Khand30ca132017-06-09 04:32:58 +0100223 p_entropy.p = entropy->x;
224 p_entropy.len = entropy->len;
Manuel Pégourié-Gonnard24600b72014-01-31 09:54:14 +0100225
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200226 md_info = mbedtls_md_info_from_type( md_alg );
Paul Bakker94b916c2014-04-17 16:07:20 +0200227 TEST_ASSERT( md_info != NULL );
228
Reut Caspie278b362017-10-19 08:49:19 +0100229 TEST_ASSERT( mbedtls_hmac_drbg_seed( &ctx, md_info, mbedtls_test_entropy_func, &p_entropy,
Azim Khand30ca132017-06-09 04:32:58 +0100230 custom->x, custom->len ) == 0 );
231 TEST_ASSERT( mbedtls_hmac_drbg_reseed( &ctx, add1->x, add1->len ) == 0 );
232 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, my_output, output->len,
233 add2->x, add2->len ) == 0 );
234 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, my_output, output->len,
235 add3->x, add3->len ) == 0 );
Manuel Pégourié-Gonnard24600b72014-01-31 09:54:14 +0100236
Azim Khand30ca132017-06-09 04:32:58 +0100237 TEST_ASSERT( memcmp( my_output, output->x, output->len ) == 0 );
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100238
Paul Bakkerbd51b262014-07-10 15:26:12 +0200239exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200240 mbedtls_hmac_drbg_free( &ctx );
Manuel Pégourié-Gonnard6801f392014-01-30 17:22:14 +0100241}
242/* END_CASE */
243
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100244/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100245void hmac_drbg_pr( int md_alg, data_t * entropy, data_t * custom,
246 data_t * add1, data_t * add2, data_t * output )
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100247{
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100248 unsigned char my_output[512];
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100249 entropy_ctx p_entropy;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200250 const mbedtls_md_info_t *md_info;
251 mbedtls_hmac_drbg_context ctx;
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100252
Manuel Pégourié-Gonnardf9e94812015-04-28 22:07:14 +0200253 mbedtls_hmac_drbg_init( &ctx );
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100254
Azim Khand30ca132017-06-09 04:32:58 +0100255 p_entropy.p = entropy->x;
256 p_entropy.len = entropy->len;
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100257
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200258 md_info = mbedtls_md_info_from_type( md_alg );
Paul Bakker94b916c2014-04-17 16:07:20 +0200259 TEST_ASSERT( md_info != NULL );
260
Reut Caspie278b362017-10-19 08:49:19 +0100261 TEST_ASSERT( mbedtls_hmac_drbg_seed( &ctx, md_info, mbedtls_test_entropy_func, &p_entropy,
Azim Khand30ca132017-06-09 04:32:58 +0100262 custom->x, custom->len ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200263 mbedtls_hmac_drbg_set_prediction_resistance( &ctx, MBEDTLS_HMAC_DRBG_PR_ON );
Azim Khand30ca132017-06-09 04:32:58 +0100264 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, my_output, output->len,
265 add1->x, add1->len ) == 0 );
266 TEST_ASSERT( mbedtls_hmac_drbg_random_with_add( &ctx, my_output, output->len,
267 add2->x, add2->len ) == 0 );
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100268
Azim Khand30ca132017-06-09 04:32:58 +0100269 TEST_ASSERT( memcmp( my_output, output->x, output->len ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200270
271exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200272 mbedtls_hmac_drbg_free( &ctx );
Manuel Pégourié-Gonnard62273b82014-01-31 10:16:57 +0100273}
274/* END_CASE */
275
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200276/* BEGIN_CASE depends_on:MBEDTLS_SELF_TEST */
Azim Khanf1aaec92017-05-30 14:23:15 +0100277void hmac_drbg_selftest( )
Manuel Pégourié-Gonnard79afaa02014-01-31 11:12:09 +0100278{
Andres AG93012e82016-09-09 09:10:28 +0100279 TEST_ASSERT( mbedtls_hmac_drbg_self_test( 1 ) == 0 );
Manuel Pégourié-Gonnard79afaa02014-01-31 11:12:09 +0100280}
281/* END_CASE */