blob: a7e93aafc485f5e1ed9b59f26c9c91ccd37b566b [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/rsa.h"
Manuel Pégourié-Gonnarde741c612022-07-27 13:13:55 +02003#include "legacy_or_psa.h"
Paul Bakker33b43f12013-08-20 11:48:36 +02004/* END_HEADER */
Paul Bakker9dcc3222011-03-08 14:16:06 +00005
Paul Bakker33b43f12013-08-20 11:48:36 +02006/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnarde741c612022-07-27 13:13:55 +02007 * depends_on:MBEDTLS_PKCS1_V21:MBEDTLS_RSA_C
Paul Bakker33b43f12013-08-20 11:48:36 +02008 * END_DEPENDENCIES
9 */
Paul Bakker5690efc2011-05-26 13:16:06 +000010
Paul Bakker33b43f12013-08-20 11:48:36 +020011/* BEGIN_CASE */
Cédric Meuterbc13cd92020-12-28 14:39:33 +010012void pkcs1_rsaes_oaep_encrypt( int mod, data_t * input_N, data_t * input_E,
13 int hash, data_t * message_str, data_t * rnd_buf,
Ronald Cronac6ae352020-06-26 14:33:03 +020014 data_t * result_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +000015{
Ron Eldor5b8f1202018-11-22 15:49:49 +020016 unsigned char output[256];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020017 mbedtls_rsa_context ctx;
Ronald Cron351f0ee2020-06-10 12:12:18 +020018 mbedtls_test_rnd_buf_info info;
Hanno Becker6326a6d2017-08-23 06:38:22 +010019 mbedtls_mpi N, E;
Paul Bakker9dcc3222011-03-08 14:16:06 +000020
Gilles Peskineecacc3c2021-03-24 00:48:57 +010021 info.fallback_f_rng = mbedtls_test_rnd_std_rand;
22 info.fallback_p_rng = NULL;
Azim Khand30ca132017-06-09 04:32:58 +010023 info.buf = rnd_buf->x;
24 info.length = rnd_buf->len;
Paul Bakker9dcc3222011-03-08 14:16:06 +000025
Hanno Becker6326a6d2017-08-23 06:38:22 +010026 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Ronald Cronc1905a12021-06-05 11:11:14 +020027 mbedtls_rsa_init( &ctx );
Ronald Cron266b6d22021-06-08 10:03:49 +020028 TEST_ASSERT( mbedtls_rsa_set_padding( &ctx,
29 MBEDTLS_RSA_PKCS_V21, hash ) == 0 );
Ron Eldor5b8f1202018-11-22 15:49:49 +020030 memset( output, 0x00, sizeof( output ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +000031
Cédric Meuterbc13cd92020-12-28 14:39:33 +010032 TEST_ASSERT( mbedtls_mpi_read_binary( &N, input_N->x, input_N->len ) == 0 );
33 TEST_ASSERT( mbedtls_mpi_read_binary( &E, input_E->x, input_E->len ) == 0 );
Hanno Becker6326a6d2017-08-23 06:38:22 +010034 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
35 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020036 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000037
Gilles Peskine85a6dd42018-10-15 16:32:42 +020038 if( message_str->len == 0 )
39 message_str->x = NULL;
Ronald Cron6c5bd7f2020-06-10 14:08:26 +020040 TEST_ASSERT( mbedtls_rsa_pkcs1_encrypt( &ctx,
41 &mbedtls_test_rnd_buffer_rand,
Thomas Daubney21772772021-05-13 17:30:32 +010042 &info, message_str->len,
43 message_str->x,
Ronald Cron6c5bd7f2020-06-10 14:08:26 +020044 output ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +020045 if( result == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +000046 {
Cédric Meuter6882b462021-01-10 11:31:12 +010047 ASSERT_COMPARE( output, ctx.len, result_str->x, result_str->len );
Paul Bakker9dcc3222011-03-08 14:16:06 +000048 }
Paul Bakker58ef6ec2013-01-03 11:33:48 +010049
Paul Bakkerbd51b262014-07-10 15:26:12 +020050exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +010051 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020052 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +000053}
Paul Bakker33b43f12013-08-20 11:48:36 +020054/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +000055
Paul Bakker33b43f12013-08-20 11:48:36 +020056/* BEGIN_CASE */
Cédric Meuterbc13cd92020-12-28 14:39:33 +010057void pkcs1_rsaes_oaep_decrypt( int mod, data_t * input_P, data_t * input_Q,
58 data_t * input_N, data_t * input_E, int hash,
59 data_t * result_str, char * seed, data_t * message_str,
Azim Khand30ca132017-06-09 04:32:58 +010060 int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +000061{
Ron Eldor5b8f1202018-11-22 15:49:49 +020062 unsigned char output[64];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020063 mbedtls_rsa_context ctx;
Paul Bakkerf4a3f302011-04-24 15:53:29 +000064 size_t output_len;
Ronald Cron351f0ee2020-06-10 12:12:18 +020065 mbedtls_test_rnd_pseudo_info rnd_info;
Hanno Becker6326a6d2017-08-23 06:38:22 +010066 mbedtls_mpi N, P, Q, E;
Paul Bakkerdbd443d2013-08-16 13:38:47 +020067 ((void) seed);
Paul Bakker9dcc3222011-03-08 14:16:06 +000068
Hanno Becker6326a6d2017-08-23 06:38:22 +010069 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
70 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
71
Ronald Cronc1905a12021-06-05 11:11:14 +020072 mbedtls_rsa_init( &ctx );
Ronald Cron266b6d22021-06-08 10:03:49 +020073 TEST_ASSERT( mbedtls_rsa_set_padding( &ctx,
74 MBEDTLS_RSA_PKCS_V21, hash ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000075
Ron Eldor5b8f1202018-11-22 15:49:49 +020076 memset( output, 0x00, sizeof( output ) );
Ronald Cron351f0ee2020-06-10 12:12:18 +020077 memset( &rnd_info, 0, sizeof( mbedtls_test_rnd_pseudo_info ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +000078
Cédric Meuterbc13cd92020-12-28 14:39:33 +010079 TEST_ASSERT( mbedtls_mpi_read_binary( &P, input_P->x, input_P->len ) == 0 );
80 TEST_ASSERT( mbedtls_mpi_read_binary( &Q, input_Q->x, input_Q->len ) == 0 );
81 TEST_ASSERT( mbedtls_mpi_read_binary( &N, input_N->x, input_N->len ) == 0 );
82 TEST_ASSERT( mbedtls_mpi_read_binary( &E, input_E->x, input_E->len ) == 0 );
Paul Bakker548957d2013-08-30 10:30:02 +020083
Hanno Becker6326a6d2017-08-23 06:38:22 +010084 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
85 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Hanno Becker7f25f852017-10-10 16:56:22 +010086 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020087 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000088
Ronald Cronac6ae352020-06-26 14:33:03 +020089 if( result_str->len == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +000090 {
Ronald Cron6c5bd7f2020-06-10 14:08:26 +020091 TEST_ASSERT( mbedtls_rsa_pkcs1_decrypt( &ctx,
92 &mbedtls_test_rnd_pseudo_rand,
93 &rnd_info,
Ronald Cron6c5bd7f2020-06-10 14:08:26 +020094 &output_len, message_str->x,
95 NULL, 0 ) == result );
Gilles Peskine85a6dd42018-10-15 16:32:42 +020096 }
97 else
98 {
Ronald Cron6c5bd7f2020-06-10 14:08:26 +020099 TEST_ASSERT( mbedtls_rsa_pkcs1_decrypt( &ctx,
100 &mbedtls_test_rnd_pseudo_rand,
101 &rnd_info,
Ronald Cron6c5bd7f2020-06-10 14:08:26 +0200102 &output_len, message_str->x,
103 output,
Ron Eldor5b8f1202018-11-22 15:49:49 +0200104 sizeof( output ) ) == result );
Gilles Peskine85a6dd42018-10-15 16:32:42 +0200105 if( result == 0 )
106 {
Cédric Meuter6882b462021-01-10 11:31:12 +0100107 ASSERT_COMPARE( output, output_len, result_str->x, result_str->len );
Gilles Peskine85a6dd42018-10-15 16:32:42 +0200108 }
Paul Bakker9dcc3222011-03-08 14:16:06 +0000109 }
Paul Bakker6c591fa2011-05-05 11:49:20 +0000110
Paul Bakkerbd51b262014-07-10 15:26:12 +0200111exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100112 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
113 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200114 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000115}
Paul Bakker33b43f12013-08-20 11:48:36 +0200116/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +0000117
Paul Bakker33b43f12013-08-20 11:48:36 +0200118/* BEGIN_CASE */
Cédric Meuterbc13cd92020-12-28 14:39:33 +0100119void pkcs1_rsassa_pss_sign( int mod, data_t * input_P, data_t * input_Q,
120 data_t * input_N, data_t * input_E, int digest,
Neil Armstrong0270b9f2022-07-19 17:49:25 +0200121 int hash, data_t * hash_digest, data_t * rnd_buf,
Cédric Meuter61adfd62021-01-10 11:52:39 +0100122 data_t * result_str, int fixed_salt_length,
123 int result )
Cédric Meuter668a78d2020-04-30 11:57:04 +0200124{
Cédric Meuter668a78d2020-04-30 11:57:04 +0200125 unsigned char output[512];
126 mbedtls_rsa_context ctx;
127 mbedtls_test_rnd_buf_info info;
128 mbedtls_mpi N, P, Q, E;
129
Gilles Peskineecacc3c2021-03-24 00:48:57 +0100130 info.fallback_f_rng = mbedtls_test_rnd_std_rand;
131 info.fallback_p_rng = NULL;
Cédric Meuter668a78d2020-04-30 11:57:04 +0200132 info.buf = rnd_buf->x;
133 info.length = rnd_buf->len;
134
135 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
136 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
Ronald Cronc1905a12021-06-05 11:11:14 +0200137 mbedtls_rsa_init( &ctx );
Ronald Cron266b6d22021-06-08 10:03:49 +0200138 TEST_ASSERT( mbedtls_rsa_set_padding( &ctx,
139 MBEDTLS_RSA_PKCS_V21, hash ) == 0 );
Cédric Meuter668a78d2020-04-30 11:57:04 +0200140
Cédric Meuter668a78d2020-04-30 11:57:04 +0200141 memset( output, 0x00, sizeof( output ) );
142
Cédric Meuterbc13cd92020-12-28 14:39:33 +0100143 TEST_ASSERT( mbedtls_mpi_read_binary( &P, input_P->x, input_P->len ) == 0 );
144 TEST_ASSERT( mbedtls_mpi_read_binary( &Q, input_Q->x, input_Q->len ) == 0 );
145 TEST_ASSERT( mbedtls_mpi_read_binary( &N, input_N->x, input_N->len ) == 0 );
146 TEST_ASSERT( mbedtls_mpi_read_binary( &E, input_E->x, input_E->len ) == 0 );
Cédric Meuter668a78d2020-04-30 11:57:04 +0200147
148 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
149 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
150 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
151 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
152
Cédric Meuter61adfd62021-01-10 11:52:39 +0100153 if (fixed_salt_length == MBEDTLS_RSA_SALT_LEN_ANY)
154 {
Gilles Peskine6e3187b2021-06-22 18:39:53 +0200155 TEST_ASSERT( mbedtls_rsa_pkcs1_sign(
156 &ctx, &mbedtls_test_rnd_buffer_rand, &info,
Neil Armstrong0270b9f2022-07-19 17:49:25 +0200157 digest, hash_digest->len, hash_digest->x, output ) == result );
Cédric Meuter61adfd62021-01-10 11:52:39 +0100158 if( result == 0 )
159 {
160 ASSERT_COMPARE( output, ctx.len, result_str->x, result_str->len );
161 }
162
163 info.buf = rnd_buf->x;
164 info.length = rnd_buf->len;
165 }
166
Gilles Peskine6e3187b2021-06-22 18:39:53 +0200167 TEST_ASSERT( mbedtls_rsa_rsassa_pss_sign_ext(
168 &ctx, &mbedtls_test_rnd_buffer_rand, &info,
Neil Armstrong0270b9f2022-07-19 17:49:25 +0200169 digest, hash_digest->len, hash_digest->x,
Gilles Peskine6e3187b2021-06-22 18:39:53 +0200170 fixed_salt_length, output ) == result );
Cédric Meuter668a78d2020-04-30 11:57:04 +0200171 if( result == 0 )
172 {
Cédric Meuter6882b462021-01-10 11:31:12 +0100173 ASSERT_COMPARE( output, ctx.len, result_str->x, result_str->len );
Cédric Meuter668a78d2020-04-30 11:57:04 +0200174 }
175
176exit:
177 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
178 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
179 mbedtls_rsa_free( &ctx );
180}
181/* END_CASE */
182
183/* BEGIN_CASE */
Cédric Meuterbc13cd92020-12-28 14:39:33 +0100184void pkcs1_rsassa_pss_verify( int mod, data_t * input_N, data_t * input_E,
Neil Armstrong0270b9f2022-07-19 17:49:25 +0200185 int digest, int hash, data_t * hash_digest,
Cédric Meuterbc13cd92020-12-28 14:39:33 +0100186 char * salt, data_t * result_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000187{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200188 mbedtls_rsa_context ctx;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100189 mbedtls_mpi N, E;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200190 ((void) salt);
Paul Bakker9dcc3222011-03-08 14:16:06 +0000191
Hanno Becker6326a6d2017-08-23 06:38:22 +0100192 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Ronald Cronc1905a12021-06-05 11:11:14 +0200193 mbedtls_rsa_init( &ctx );
Ronald Cron266b6d22021-06-08 10:03:49 +0200194 TEST_ASSERT( mbedtls_rsa_set_padding( &ctx,
195 MBEDTLS_RSA_PKCS_V21, hash ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000196
Cédric Meuterbc13cd92020-12-28 14:39:33 +0100197 TEST_ASSERT( mbedtls_mpi_read_binary( &N, input_N->x, input_N->len ) == 0 );
198 TEST_ASSERT( mbedtls_mpi_read_binary( &E, input_E->x, input_E->len ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000199
Hanno Becker6326a6d2017-08-23 06:38:22 +0100200 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
201 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200202 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000203
Paul Bakker9dcc3222011-03-08 14:16:06 +0000204
Neil Armstrong0270b9f2022-07-19 17:49:25 +0200205 TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, digest, hash_digest->len, hash_digest->x, result_str->x ) == result );
Paul Bakker58ef6ec2013-01-03 11:33:48 +0100206
Paul Bakkerbd51b262014-07-10 15:26:12 +0200207exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100208 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200209 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000210}
Paul Bakker33b43f12013-08-20 11:48:36 +0200211/* END_CASE */
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200212
213/* BEGIN_CASE */
Cédric Meuterbc13cd92020-12-28 14:39:33 +0100214void pkcs1_rsassa_pss_verify_ext( int mod, data_t * input_N, data_t * input_E,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200215 int msg_digest_id, int ctx_hash,
216 int mgf_hash, int salt_len,
Neil Armstrong0270b9f2022-07-19 17:49:25 +0200217 data_t * hash_digest,
Azim Khan5fcca462018-06-29 11:05:32 +0100218 data_t * result_str, int result_simple,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200219 int result_full )
220{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200221 mbedtls_rsa_context ctx;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100222 mbedtls_mpi N, E;
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200223
Hanno Becker6326a6d2017-08-23 06:38:22 +0100224 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Ronald Cronc1905a12021-06-05 11:11:14 +0200225 mbedtls_rsa_init( &ctx );
Ronald Cron266b6d22021-06-08 10:03:49 +0200226 TEST_ASSERT( mbedtls_rsa_set_padding( &ctx,
227 MBEDTLS_RSA_PKCS_V21, ctx_hash ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200228
Cédric Meuterbc13cd92020-12-28 14:39:33 +0100229 TEST_ASSERT( mbedtls_mpi_read_binary( &N, input_N->x, input_N->len ) == 0 );
230 TEST_ASSERT( mbedtls_mpi_read_binary( &E, input_E->x, input_E->len ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200231
Hanno Becker6326a6d2017-08-23 06:38:22 +0100232 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
233 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200234 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200235
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200236
Thomas Daubney68d9cbc2021-05-18 18:45:09 +0100237 TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, msg_digest_id,
Neil Armstrong0270b9f2022-07-19 17:49:25 +0200238 hash_digest->len, hash_digest->x,
Thomas Daubney68d9cbc2021-05-18 18:45:09 +0100239 result_str->x ) == result_simple );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200240
Neil Armstrong0270b9f2022-07-19 17:49:25 +0200241 TEST_ASSERT( mbedtls_rsa_rsassa_pss_verify_ext( &ctx, msg_digest_id, hash_digest->len,
242 hash_digest->x, mgf_hash, salt_len,
Thomas Daubney782a7f52021-05-19 12:27:35 +0100243 result_str->x ) == result_full );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200244
Paul Bakkerbd51b262014-07-10 15:26:12 +0200245exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100246 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200247 mbedtls_rsa_free( &ctx );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200248}
249/* END_CASE */