blob: 3dfef18772a26fb4a0adf0baee0f57ad21a4d508 [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/ecp.h"
Paul Bakkerdbd443d2013-08-16 13:38:47 +02003
Manuel Pégourié-Gonnard6c7af4c2015-04-03 16:41:52 +02004#define ECP_PF_UNKNOWN -1
Paul Bakker33b43f12013-08-20 11:48:36 +02005/* END_HEADER */
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +01006
Paul Bakker33b43f12013-08-20 11:48:36 +02007/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02008 * depends_on:MBEDTLS_ECP_C
Paul Bakker33b43f12013-08-20 11:48:36 +02009 * END_DEPENDENCIES
10 */
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +010011
Paul Bakker33b43f12013-08-20 11:48:36 +020012/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020013void mbedtls_ecp_curve_info( int id, int tls_id, int size, char *name )
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +010014{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020015 const mbedtls_ecp_curve_info *by_id, *by_tls, *by_name;
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +010016
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020017 by_id = mbedtls_ecp_curve_info_from_grp_id( id );
18 by_tls = mbedtls_ecp_curve_info_from_tls_id( tls_id );
19 by_name = mbedtls_ecp_curve_info_from_name( name );
Paul Bakker94b916c2014-04-17 16:07:20 +020020 TEST_ASSERT( by_id != NULL );
21 TEST_ASSERT( by_tls != NULL );
22 TEST_ASSERT( by_name != NULL );
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +010023
24 TEST_ASSERT( by_id == by_tls );
25 TEST_ASSERT( by_id == by_name );
26
Manuel Pégourié-Gonnard797f48a2015-06-18 15:45:05 +020027 TEST_ASSERT( by_id->bit_size == size );
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +010028}
29/* END_CASE */
30
31/* BEGIN_CASE */
Janos Follath28fff142017-01-27 15:51:14 +000032void ecp_check_pub( int grp_id, char *x_hex, char *y_hex, char *z_hex, int ret )
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +010033{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020034 mbedtls_ecp_group grp;
35 mbedtls_ecp_point P;
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +010036
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020037 mbedtls_ecp_group_init( &grp );
38 mbedtls_ecp_point_init( &P );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +010039
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +020040 TEST_ASSERT( mbedtls_ecp_group_load( &grp, grp_id ) == 0 );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +010041
Janos Follath28fff142017-01-27 15:51:14 +000042 TEST_ASSERT( mbedtls_mpi_read_string( &P.X, 16, x_hex ) == 0 );
43 TEST_ASSERT( mbedtls_mpi_read_string( &P.Y, 16, y_hex ) == 0 );
44 TEST_ASSERT( mbedtls_mpi_read_string( &P.Z, 16, z_hex ) == 0 );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +010045
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020046 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &P ) == ret );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +010047
Paul Bakkerbd51b262014-07-10 15:26:12 +020048exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020049 mbedtls_ecp_group_free( &grp );
50 mbedtls_ecp_point_free( &P );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +010051}
52/* END_CASE */
53
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +010054/* BEGIN_CASE depends_on:MBEDTLS_ECP_EARLY_RETURN */
55void ecp_test_vect_restart( int id,
56 char *dA_str, char *xA_str, char *yA_str,
57 char *dB_str, char *xZ_str, char *yZ_str,
58 int max_ops, int min_restarts, int max_restarts )
59{
60 /*
61 * Test for early restart. Based on test vectors like ecp_test_vect(),
62 * but for the sake of simplicity only does half of each side. It's
63 * important to test both base point and random point, though, as memory
64 * management is different in each case.
65 *
66 * Don't try using too precise bounds for restarts as the exact number
67 * will depend on settings such as MBEDTLS_ECP_FIXED_POINT_OPTIM and
68 * MBEDTLS_ECP_WINDOW_SIZE, as well as implementation details that may
69 * change in the future. A factor 2 is a minimum safety margin.
70 *
71 * For reference, with mbed TLS 2.4 and default settings, for P-256:
Manuel Pégourié-Gonnard9c5c78f2017-03-20 14:13:07 +010072 * - Random point mult: ~3250M
73 * - Cold base point mult: ~3300M
74 * - Hot base point mult: ~1100M
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +010075 * With MBEDTLS_ECP_WINDOW_SIZE set to 2 (minimum):
Manuel Pégourié-Gonnard9c5c78f2017-03-20 14:13:07 +010076 * - Random point mult: ~3850M
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +010077 */
78 mbedtls_ecp_group grp;
79 mbedtls_ecp_point R;
80 mbedtls_mpi dA, xA, yA, dB, xZ, yZ;
81 int cnt_restarts;
82 int ret;
83
84 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &R );
85 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA ); mbedtls_mpi_init( &yA );
86 mbedtls_mpi_init( &dB ); mbedtls_mpi_init( &xZ ); mbedtls_mpi_init( &yZ );
87
88 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
89
90 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_str ) == 0 );
91 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_str ) == 0 );
92 TEST_ASSERT( mbedtls_mpi_read_string( &yA, 16, yA_str ) == 0 );
93
94 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_str ) == 0 );
95 TEST_ASSERT( mbedtls_mpi_read_string( &xZ, 16, xZ_str ) == 0 );
96 TEST_ASSERT( mbedtls_mpi_read_string( &yZ, 16, yZ_str ) == 0 );
97
98 mbedtls_ecp_set_max_ops( (unsigned) max_ops );
99
100 /* Base point case */
101 cnt_restarts = 0;
102 do {
103 ret = mbedtls_ecp_mul( &grp, &R, &dA, &grp.G, NULL, NULL );
104 TEST_ASSERT( ret == 0 || ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
105
106 if( ret == MBEDTLS_ERR_ECP_IN_PROGRESS )
107 cnt_restarts++;
108 }
109 while( ret != 0 );
110
111 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
112 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yA ) == 0 );
113
114 TEST_ASSERT( cnt_restarts >= min_restarts );
115 TEST_ASSERT( cnt_restarts <= max_restarts );
116
117 /* Do we leak memory when doing it twice in a row? */
118 do {
119 ret = mbedtls_ecp_mul( &grp, &R, &dA, &grp.G, NULL, NULL );
120 TEST_ASSERT( ret == 0 || ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
121 }
122 while( ret != 0 );
123
Manuel Pégourié-Gonnard78d564a2017-03-14 11:48:38 +0100124 /* Ok, now start an operation with some arguments, and drop it.
125 * We'll see if the result of the next operation, with different args,
126 * are correct regardless (do we discard old context on new args?).
127 * This also tests that we don't write to R prematurely */
128 ret = mbedtls_ecp_mul( &grp, &R, &dA, &grp.G, NULL, NULL );
129 TEST_ASSERT( ret == 0 || ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
130
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100131 /* Non-base point case */
132 cnt_restarts = 0;
133 do {
134 ret = mbedtls_ecp_mul( &grp, &R, &dB, &R, NULL, NULL );
135 TEST_ASSERT( ret == 0 || ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
136
137 if( ret == MBEDTLS_ERR_ECP_IN_PROGRESS )
138 cnt_restarts++;
139 }
140 while( ret != 0 );
141
142 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
143 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
144
145 TEST_ASSERT( cnt_restarts >= min_restarts );
146 TEST_ASSERT( cnt_restarts <= max_restarts );
147
148 /* Do we leak memory when doing it twice in a row? */
149 do {
150 ret = mbedtls_ecp_mul( &grp, &R, &dB, &R, NULL, NULL );
151 TEST_ASSERT( ret == 0 || ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
152 }
153 while( ret != 0 );
154
Manuel Pégourié-Gonnard77af79a2017-03-14 10:58:00 +0100155 /* Do we leak memory when not finishing an operation? */
156 ret = mbedtls_ecp_mul( &grp, &R, &dB, &R, NULL, NULL );
157 TEST_ASSERT( ret == 0 || ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
158
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100159exit:
160 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &R );
161 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA ); mbedtls_mpi_free( &yA );
162 mbedtls_mpi_free( &dB ); mbedtls_mpi_free( &xZ ); mbedtls_mpi_free( &yZ );
163}
164/* END_CASE */
165
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100166/* BEGIN_CASE */
Paul Bakker33b43f12013-08-20 11:48:36 +0200167void ecp_test_vect( int id, char *dA_str, char *xA_str, char *yA_str,
168 char *dB_str, char *xB_str, char *yB_str, char *xZ_str,
169 char *yZ_str )
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100170{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200171 mbedtls_ecp_group grp;
172 mbedtls_ecp_point R;
173 mbedtls_mpi dA, xA, yA, dB, xB, yB, xZ, yZ;
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200174 rnd_pseudo_info rnd_info;
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100175
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200176 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &R );
177 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA ); mbedtls_mpi_init( &yA ); mbedtls_mpi_init( &dB );
178 mbedtls_mpi_init( &xB ); mbedtls_mpi_init( &yB ); mbedtls_mpi_init( &xZ ); mbedtls_mpi_init( &yZ );
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200179 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100180
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200181 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100182
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200183 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &grp.G ) == 0 );
Manuel Pégourié-Gonnard1c330572012-11-24 12:05:44 +0100184
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200185 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_str ) == 0 );
186 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_str ) == 0 );
187 TEST_ASSERT( mbedtls_mpi_read_string( &yA, 16, yA_str ) == 0 );
188 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_str ) == 0 );
189 TEST_ASSERT( mbedtls_mpi_read_string( &xB, 16, xB_str ) == 0 );
190 TEST_ASSERT( mbedtls_mpi_read_string( &yB, 16, yB_str ) == 0 );
191 TEST_ASSERT( mbedtls_mpi_read_string( &xZ, 16, xZ_str ) == 0 );
192 TEST_ASSERT( mbedtls_mpi_read_string( &yZ, 16, yZ_str ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100193
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200194 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &grp.G,
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200195 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200196 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
197 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yA ) == 0 );
198 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
199 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &R, NULL, NULL ) == 0 );
200 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
201 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
202 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100203
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200204 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &grp.G, NULL, NULL ) == 0 );
205 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xB ) == 0 );
206 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yB ) == 0 );
207 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
208 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &R,
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200209 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200210 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
211 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
212 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100213
Paul Bakkerbd51b262014-07-10 15:26:12 +0200214exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200215 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &R );
216 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA ); mbedtls_mpi_free( &yA ); mbedtls_mpi_free( &dB );
217 mbedtls_mpi_free( &xB ); mbedtls_mpi_free( &yB ); mbedtls_mpi_free( &xZ ); mbedtls_mpi_free( &yZ );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100218}
Paul Bakker33b43f12013-08-20 11:48:36 +0200219/* END_CASE */
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100220
Paul Bakker33b43f12013-08-20 11:48:36 +0200221/* BEGIN_CASE */
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100222void ecp_test_vec_x( int id, char *dA_hex, char *xA_hex,
223 char *dB_hex, char *xB_hex, char *xS_hex )
224{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200225 mbedtls_ecp_group grp;
226 mbedtls_ecp_point R;
227 mbedtls_mpi dA, xA, dB, xB, xS;
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100228 rnd_pseudo_info rnd_info;
229
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200230 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &R );
231 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA );
232 mbedtls_mpi_init( &dB ); mbedtls_mpi_init( &xB );
233 mbedtls_mpi_init( &xS );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100234 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
235
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200236 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100237
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200238 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &grp.G ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100239
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200240 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_hex ) == 0 );
241 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_hex ) == 0 );
242 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_hex ) == 0 );
243 TEST_ASSERT( mbedtls_mpi_read_string( &xB, 16, xB_hex ) == 0 );
244 TEST_ASSERT( mbedtls_mpi_read_string( &xS, 16, xS_hex ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100245
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200246 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &grp.G,
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100247 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200248 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
249 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100250
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200251 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &R,
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100252 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200253 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
254 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xS ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100255
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200256 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &grp.G, NULL, NULL ) == 0 );
257 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
258 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xB ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100259
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200260 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &R, NULL, NULL ) == 0 );
261 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
262 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xS ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100263
Paul Bakkerbd51b262014-07-10 15:26:12 +0200264exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200265 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &R );
266 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA );
267 mbedtls_mpi_free( &dB ); mbedtls_mpi_free( &xB );
268 mbedtls_mpi_free( &xS );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100269}
270/* END_CASE */
271
272/* BEGIN_CASE */
Paul Bakker33b43f12013-08-20 11:48:36 +0200273void ecp_fast_mod( int id, char *N_str )
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100274{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200275 mbedtls_ecp_group grp;
276 mbedtls_mpi N, R;
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100277
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200278 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &R );
279 mbedtls_ecp_group_init( &grp );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100280
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200281 TEST_ASSERT( mbedtls_mpi_read_string( &N, 16, N_str ) == 0 );
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200282 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarde783f062013-10-21 14:52:21 +0200283 TEST_ASSERT( grp.modp != NULL );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100284
285 /*
286 * Store correct result before we touch N
287 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200288 TEST_ASSERT( mbedtls_mpi_mod_mpi( &R, &N, &grp.P ) == 0 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100289
290 TEST_ASSERT( grp.modp( &N ) == 0 );
Manuel Pégourié-Gonnardc0696c22015-06-18 16:47:17 +0200291 TEST_ASSERT( mbedtls_mpi_bitlen( &N ) <= grp.pbits + 3 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100292
293 /*
Paul Bakkerd8b0c5e2014-04-11 15:31:33 +0200294 * Use mod rather than addition/subtraction in case previous test fails
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100295 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200296 TEST_ASSERT( mbedtls_mpi_mod_mpi( &N, &N, &grp.P ) == 0 );
297 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &N, &R ) == 0 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100298
Paul Bakkerbd51b262014-07-10 15:26:12 +0200299exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200300 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &R );
301 mbedtls_ecp_group_free( &grp );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100302}
Paul Bakker33b43f12013-08-20 11:48:36 +0200303/* END_CASE */
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +0100304
Paul Bakker33b43f12013-08-20 11:48:36 +0200305/* BEGIN_CASE */
306void ecp_write_binary( int id, char *x, char *y, char *z, int format,
307 char *out, int blen, int ret )
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100308{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200309 mbedtls_ecp_group grp;
310 mbedtls_ecp_point P;
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100311 unsigned char buf[256], str[512];
Manuel Pégourié-Gonnard420f1eb2013-02-10 12:22:46 +0100312 size_t olen;
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100313
314 memset( buf, 0, sizeof( buf ) );
315 memset( str, 0, sizeof( str ) );
316
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200317 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100318
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200319 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100320
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200321 TEST_ASSERT( mbedtls_mpi_read_string( &P.X, 16, x ) == 0 );
322 TEST_ASSERT( mbedtls_mpi_read_string( &P.Y, 16, y ) == 0 );
323 TEST_ASSERT( mbedtls_mpi_read_string( &P.Z, 16, z ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100324
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200325 TEST_ASSERT( mbedtls_ecp_point_write_binary( &grp, &P, format,
Paul Bakker33b43f12013-08-20 11:48:36 +0200326 &olen, buf, blen ) == ret );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100327
Paul Bakker33b43f12013-08-20 11:48:36 +0200328 if( ret == 0 )
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100329 {
Manuel Pégourié-Gonnard37d218a2012-11-24 15:19:55 +0100330 hexify( str, buf, olen );
Paul Bakker33b43f12013-08-20 11:48:36 +0200331 TEST_ASSERT( strcasecmp( (char *) str, out ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100332 }
333
Paul Bakkerbd51b262014-07-10 15:26:12 +0200334exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200335 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100336}
Paul Bakker33b43f12013-08-20 11:48:36 +0200337/* END_CASE */
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100338
Paul Bakker33b43f12013-08-20 11:48:36 +0200339/* BEGIN_CASE */
340void ecp_read_binary( int id, char *input, char *x, char *y, char *z,
341 int ret )
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100342{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200343 mbedtls_ecp_group grp;
344 mbedtls_ecp_point P;
345 mbedtls_mpi X, Y, Z;
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100346 int ilen;
347 unsigned char buf[256];
348
349 memset( buf, 0, sizeof( buf ) );
350
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200351 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
352 mbedtls_mpi_init( &X ); mbedtls_mpi_init( &Y ); mbedtls_mpi_init( &Z );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100353
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200354 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100355
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200356 TEST_ASSERT( mbedtls_mpi_read_string( &X, 16, x ) == 0 );
357 TEST_ASSERT( mbedtls_mpi_read_string( &Y, 16, y ) == 0 );
358 TEST_ASSERT( mbedtls_mpi_read_string( &Z, 16, z ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100359
Paul Bakker33b43f12013-08-20 11:48:36 +0200360 ilen = unhexify( buf, input );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100361
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200362 TEST_ASSERT( mbedtls_ecp_point_read_binary( &grp, &P, buf, ilen ) == ret );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100363
Paul Bakker33b43f12013-08-20 11:48:36 +0200364 if( ret == 0 )
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100365 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200366 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.X, &X ) == 0 );
367 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Y, &Y ) == 0 );
368 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Z, &Z ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100369 }
370
Paul Bakkerbd51b262014-07-10 15:26:12 +0200371exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200372 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
373 mbedtls_mpi_free( &X ); mbedtls_mpi_free( &Y ); mbedtls_mpi_free( &Z );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100374}
Paul Bakker33b43f12013-08-20 11:48:36 +0200375/* END_CASE */
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100376
Paul Bakker33b43f12013-08-20 11:48:36 +0200377/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200378void mbedtls_ecp_tls_read_point( int id, char *input, char *x, char *y, char *z,
Paul Bakker33b43f12013-08-20 11:48:36 +0200379 int ret )
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100380{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200381 mbedtls_ecp_group grp;
382 mbedtls_ecp_point P;
383 mbedtls_mpi X, Y, Z;
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100384 size_t ilen;
385 unsigned char buf[256];
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100386 const unsigned char *vbuf = buf;
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100387
388 memset( buf, 0, sizeof( buf ) );
389
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200390 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
391 mbedtls_mpi_init( &X ); mbedtls_mpi_init( &Y ); mbedtls_mpi_init( &Z );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100392
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200393 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100394
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200395 TEST_ASSERT( mbedtls_mpi_read_string( &X, 16, x ) == 0 );
396 TEST_ASSERT( mbedtls_mpi_read_string( &Y, 16, y ) == 0 );
397 TEST_ASSERT( mbedtls_mpi_read_string( &Z, 16, z ) == 0 );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100398
Paul Bakker33b43f12013-08-20 11:48:36 +0200399 ilen = unhexify( buf, input );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100400
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200401 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &P, &vbuf, ilen ) == ret );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100402
Paul Bakker33b43f12013-08-20 11:48:36 +0200403 if( ret == 0 )
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100404 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200405 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.X, &X ) == 0 );
406 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Y, &Y ) == 0 );
407 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Z, &Z ) == 0 );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100408 TEST_ASSERT( *vbuf == 0x00 );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100409 }
410
Paul Bakkerbd51b262014-07-10 15:26:12 +0200411exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200412 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
413 mbedtls_mpi_free( &X ); mbedtls_mpi_free( &Y ); mbedtls_mpi_free( &Z );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100414}
Paul Bakker33b43f12013-08-20 11:48:36 +0200415/* END_CASE */
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100416
Paul Bakker33b43f12013-08-20 11:48:36 +0200417/* BEGIN_CASE */
418void ecp_tls_write_read_point( int id )
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100419{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200420 mbedtls_ecp_group grp;
421 mbedtls_ecp_point pt;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100422 unsigned char buf[256];
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100423 const unsigned char *vbuf;
Manuel Pégourié-Gonnard420f1eb2013-02-10 12:22:46 +0100424 size_t olen;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100425
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200426 mbedtls_ecp_group_init( &grp );
427 mbedtls_ecp_point_init( &pt );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100428
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200429 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100430
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100431 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200432 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &grp.G,
433 MBEDTLS_ECP_PF_COMPRESSED, &olen, buf, 256 ) == 0 );
434 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen )
435 == MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100436 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100437
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100438 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200439 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &grp.G,
440 MBEDTLS_ECP_PF_UNCOMPRESSED, &olen, buf, 256 ) == 0 );
441 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
442 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.X, &pt.X ) == 0 );
443 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.Y, &pt.Y ) == 0 );
444 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.Z, &pt.Z ) == 0 );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100445 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100446
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100447 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200448 TEST_ASSERT( mbedtls_ecp_set_zero( &pt ) == 0 );
449 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &pt,
450 MBEDTLS_ECP_PF_COMPRESSED, &olen, buf, 256 ) == 0 );
451 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
452 TEST_ASSERT( mbedtls_ecp_is_zero( &pt ) );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100453 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100454
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100455 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200456 TEST_ASSERT( mbedtls_ecp_set_zero( &pt ) == 0 );
457 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &pt,
458 MBEDTLS_ECP_PF_UNCOMPRESSED, &olen, buf, 256 ) == 0 );
459 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
460 TEST_ASSERT( mbedtls_ecp_is_zero( &pt ) );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100461 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100462
Paul Bakkerbd51b262014-07-10 15:26:12 +0200463exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200464 mbedtls_ecp_group_free( &grp );
465 mbedtls_ecp_point_free( &pt );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100466}
Paul Bakker33b43f12013-08-20 11:48:36 +0200467/* END_CASE */
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100468
Paul Bakker33b43f12013-08-20 11:48:36 +0200469/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200470void mbedtls_ecp_tls_read_group( char *record, int result, int bits )
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100471{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200472 mbedtls_ecp_group grp;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100473 unsigned char buf[10];
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100474 const unsigned char *vbuf = buf;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100475 int len, ret;
476
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200477 mbedtls_ecp_group_init( &grp );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100478 memset( buf, 0x00, sizeof( buf ) );
479
Paul Bakker33b43f12013-08-20 11:48:36 +0200480 len = unhexify( buf, record );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100481
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200482 ret = mbedtls_ecp_tls_read_group( &grp, &vbuf, len );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100483
Paul Bakker33b43f12013-08-20 11:48:36 +0200484 TEST_ASSERT( ret == result );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100485 if( ret == 0)
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100486 {
Manuel Pégourié-Gonnardc0696c22015-06-18 16:47:17 +0200487 TEST_ASSERT( mbedtls_mpi_bitlen( &grp.P ) == (size_t) bits );
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100488 TEST_ASSERT( *vbuf == 0x00 );
489 }
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100490
Paul Bakkerbd51b262014-07-10 15:26:12 +0200491exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200492 mbedtls_ecp_group_free( &grp );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100493}
Paul Bakker33b43f12013-08-20 11:48:36 +0200494/* END_CASE */
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100495
Paul Bakker33b43f12013-08-20 11:48:36 +0200496/* BEGIN_CASE */
497void ecp_tls_write_read_group( int id )
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100498{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200499 mbedtls_ecp_group grp1, grp2;
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100500 unsigned char buf[10];
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100501 const unsigned char *vbuf = buf;
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100502 size_t len;
503 int ret;
504
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200505 mbedtls_ecp_group_init( &grp1 );
506 mbedtls_ecp_group_init( &grp2 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100507 memset( buf, 0x00, sizeof( buf ) );
508
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200509 TEST_ASSERT( mbedtls_ecp_group_load( &grp1, id ) == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100510
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200511 TEST_ASSERT( mbedtls_ecp_tls_write_group( &grp1, &len, buf, 10 ) == 0 );
512 ret = mbedtls_ecp_tls_read_group( &grp2, &vbuf, len );
Paul Bakker94b916c2014-04-17 16:07:20 +0200513 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100514
515 if( ret == 0 )
516 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200517 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp1.N, &grp2.N ) == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100518 TEST_ASSERT( grp1.id == grp2.id );
519 }
520
Paul Bakkerbd51b262014-07-10 15:26:12 +0200521exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200522 mbedtls_ecp_group_free( &grp1 );
523 mbedtls_ecp_group_free( &grp2 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100524}
Paul Bakker33b43f12013-08-20 11:48:36 +0200525/* END_CASE */
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100526
Paul Bakker33b43f12013-08-20 11:48:36 +0200527/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200528void mbedtls_ecp_check_privkey( int id, char *key_hex, int ret )
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200529{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200530 mbedtls_ecp_group grp;
531 mbedtls_mpi d;
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200532
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200533 mbedtls_ecp_group_init( &grp );
534 mbedtls_mpi_init( &d );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200535
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200536 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200537 TEST_ASSERT( mbedtls_mpi_read_string( &d, 16, key_hex ) == 0 );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200538
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200539 TEST_ASSERT( mbedtls_ecp_check_privkey( &grp, &d ) == ret );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200540
Paul Bakkerbd51b262014-07-10 15:26:12 +0200541exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200542 mbedtls_ecp_group_free( &grp );
543 mbedtls_mpi_free( &d );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200544}
Paul Bakker33b43f12013-08-20 11:48:36 +0200545/* END_CASE */
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200546
Paul Bakker33b43f12013-08-20 11:48:36 +0200547/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200548void mbedtls_ecp_check_pub_priv( int id_pub, char *Qx_pub, char *Qy_pub,
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100549 int id, char *d, char *Qx, char *Qy, int ret )
550{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200551 mbedtls_ecp_keypair pub, prv;
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100552
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200553 mbedtls_ecp_keypair_init( &pub );
554 mbedtls_ecp_keypair_init( &prv );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100555
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200556 if( id_pub != MBEDTLS_ECP_DP_NONE )
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200557 TEST_ASSERT( mbedtls_ecp_group_load( &pub.grp, id_pub ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200558 TEST_ASSERT( mbedtls_ecp_point_read_string( &pub.Q, 16, Qx_pub, Qy_pub ) == 0 );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100559
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200560 if( id != MBEDTLS_ECP_DP_NONE )
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200561 TEST_ASSERT( mbedtls_ecp_group_load( &prv.grp, id ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200562 TEST_ASSERT( mbedtls_ecp_point_read_string( &prv.Q, 16, Qx, Qy ) == 0 );
563 TEST_ASSERT( mbedtls_mpi_read_string( &prv.d, 16, d ) == 0 );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100564
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200565 TEST_ASSERT( mbedtls_ecp_check_pub_priv( &pub, &prv ) == ret );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100566
567exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200568 mbedtls_ecp_keypair_free( &pub );
569 mbedtls_ecp_keypair_free( &prv );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100570}
571/* END_CASE */
572
573/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200574void mbedtls_ecp_gen_keypair( int id )
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100575{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200576 mbedtls_ecp_group grp;
577 mbedtls_ecp_point Q;
578 mbedtls_mpi d;
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100579 rnd_pseudo_info rnd_info;
580
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200581 mbedtls_ecp_group_init( &grp );
582 mbedtls_ecp_point_init( &Q );
583 mbedtls_mpi_init( &d );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100584 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
585
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200586 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100587
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200588 TEST_ASSERT( mbedtls_ecp_gen_keypair( &grp, &d, &Q, &rnd_pseudo_rand, &rnd_info )
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100589 == 0 );
590
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200591 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &Q ) == 0 );
592 TEST_ASSERT( mbedtls_ecp_check_privkey( &grp, &d ) == 0 );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100593
Paul Bakkerbd51b262014-07-10 15:26:12 +0200594exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200595 mbedtls_ecp_group_free( &grp );
596 mbedtls_ecp_point_free( &Q );
597 mbedtls_mpi_free( &d );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100598}
Paul Bakker33b43f12013-08-20 11:48:36 +0200599/* END_CASE */
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100600
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100601/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200602void mbedtls_ecp_gen_key( int id )
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100603{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200604 mbedtls_ecp_keypair key;
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100605 rnd_pseudo_info rnd_info;
606
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200607 mbedtls_ecp_keypair_init( &key );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100608 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
609
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200610 TEST_ASSERT( mbedtls_ecp_gen_key( id, &key, &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100611
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200612 TEST_ASSERT( mbedtls_ecp_check_pubkey( &key.grp, &key.Q ) == 0 );
613 TEST_ASSERT( mbedtls_ecp_check_privkey( &key.grp, &key.d ) == 0 );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100614
Paul Bakkerbd51b262014-07-10 15:26:12 +0200615exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200616 mbedtls_ecp_keypair_free( &key );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100617}
618/* END_CASE */
619
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200620/* BEGIN_CASE depends_on:MBEDTLS_SELF_TEST */
Paul Bakker33b43f12013-08-20 11:48:36 +0200621void ecp_selftest()
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +0100622{
Andres AG93012e82016-09-09 09:10:28 +0100623 TEST_ASSERT( mbedtls_ecp_self_test( 1 ) == 0 );
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +0100624}
Paul Bakker33b43f12013-08-20 11:48:36 +0200625/* END_CASE */