blob: 606ddd22ae84a3295bb7d664064a64fc6879196f [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/ecp.h"
Paul Bakkerdbd443d2013-08-16 13:38:47 +02003
Manuel Pégourié-Gonnard6c7af4c2015-04-03 16:41:52 +02004#define ECP_PF_UNKNOWN -1
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +02005
6#define ECP_PT_RESET( x ) \
7 mbedtls_ecp_point_free( x ); \
8 mbedtls_ecp_point_init( x );
Paul Bakker33b43f12013-08-20 11:48:36 +02009/* END_HEADER */
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +010010
Paul Bakker33b43f12013-08-20 11:48:36 +020011/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020012 * depends_on:MBEDTLS_ECP_C
Paul Bakker33b43f12013-08-20 11:48:36 +020013 * END_DEPENDENCIES
14 */
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +010015
Hanno Becker57b684f2018-12-18 12:50:02 +000016/* BEGIN_CASE */
17void ecp_valid_param( )
18{
Hanno Becker807c1072018-12-18 23:45:14 +000019 TEST_VALID_PARAM( mbedtls_ecp_group_free( NULL ) );
Hanno Becker57b684f2018-12-18 12:50:02 +000020 TEST_VALID_PARAM( mbedtls_ecp_keypair_free( NULL ) );
21 TEST_VALID_PARAM( mbedtls_ecp_point_free( NULL ) );
22
23#if defined(MBEDTLS_ECP_RESTARTABLE)
24 TEST_VALID_PARAM( mbedtls_ecp_restart_free( NULL ) );
25#endif /* MBEDTLS_ECP_RESTARTABLE */
26
27exit:
28 return;
29}
30/* END_CASE */
31
Hanno Becker12dff032018-12-14 15:08:13 +000032/* BEGIN_CASE depends_on:MBEDTLS_CHECK_PARAMS:!MBEDTLS_PARAM_FAILED_ALT */
33void ecp_invalid_param( )
34{
35 mbedtls_ecp_group grp;
36 mbedtls_ecp_keypair kp;
37 mbedtls_ecp_point P;
38 mbedtls_mpi m;
39 const char *x = "deadbeef";
40 int valid_fmt = MBEDTLS_ECP_PF_UNCOMPRESSED;
41 int invalid_fmt = 42;
42 size_t olen;
43 unsigned char buf[42] = { 0 };
44 const unsigned char *null_buf = NULL;
45 mbedtls_ecp_group_id valid_group = MBEDTLS_ECP_DP_SECP192R1;
Hanno Becker0a4fa9b2018-12-18 23:45:29 +000046 mbedtls_ecp_restart_ctx restart_ctx;
Hanno Becker12dff032018-12-14 15:08:13 +000047
48 TEST_INVALID_PARAM( mbedtls_ecp_point_init( NULL ) );
49 TEST_INVALID_PARAM( mbedtls_ecp_keypair_init( NULL ) );
Hanno Becker807c1072018-12-18 23:45:14 +000050 TEST_INVALID_PARAM( mbedtls_ecp_group_init( NULL ) );
Hanno Becker12dff032018-12-14 15:08:13 +000051
Hanno Becker12dff032018-12-14 15:08:13 +000052#if defined(MBEDTLS_ECP_RESTARTABLE)
53 TEST_INVALID_PARAM( mbedtls_ecp_restart_init( NULL ) );
Hanno Becker0a4fa9b2018-12-18 23:45:29 +000054 TEST_INVALID_PARAM( mbedtls_ecp_check_budget( NULL, &restart_ctx, 42 ) );
Hanno Becker12dff032018-12-14 15:08:13 +000055#endif /* MBEDTLS_ECP_RESTARTABLE */
56
57 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
58 mbedtls_ecp_copy( NULL, &P ) );
59 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
60 mbedtls_ecp_copy( &P, NULL ) );
61
62 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
63 mbedtls_ecp_group_copy( NULL, &grp ) );
64 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
65 mbedtls_ecp_group_copy( &grp, NULL ) );
66
67 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
Hanno Becker549e4552018-12-18 23:45:43 +000068 mbedtls_ecp_gen_privkey( NULL,
69 &m,
70 rnd_std_rand,
71 NULL ) );
72 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
73 mbedtls_ecp_gen_privkey( &grp,
74 NULL,
75 rnd_std_rand,
76 NULL ) );
77 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
78 mbedtls_ecp_gen_privkey( &grp,
79 &m,
80 NULL,
81 NULL ) );
82
83 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
Hanno Becker12dff032018-12-14 15:08:13 +000084 mbedtls_ecp_set_zero( NULL ) );
85 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
86 mbedtls_ecp_is_zero( NULL ) );
87
88 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
89 mbedtls_ecp_point_cmp( NULL, &P ) );
90 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
91 mbedtls_ecp_point_cmp( &P, NULL ) );
92
93 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
94 mbedtls_ecp_point_read_string( NULL, 2,
95 x, x ) );
96 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
97 mbedtls_ecp_point_read_string( &P, 2,
98 NULL, x ) );
99 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
100 mbedtls_ecp_point_read_string( &P, 2,
101 x, NULL ) );
102
103 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
104 mbedtls_ecp_point_write_binary( NULL, &P,
105 valid_fmt,
106 &olen,
107 buf, sizeof( buf ) ) );
108 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
109 mbedtls_ecp_point_write_binary( &grp, NULL,
110 valid_fmt,
111 &olen,
112 buf, sizeof( buf ) ) );
113 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
114 mbedtls_ecp_point_write_binary( &grp, &P,
115 invalid_fmt,
116 &olen,
117 buf, sizeof( buf ) ) );
118 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
119 mbedtls_ecp_point_write_binary( &grp, &P,
120 valid_fmt,
121 NULL,
122 buf, sizeof( buf ) ) );
123 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
124 mbedtls_ecp_point_write_binary( &grp, &P,
125 valid_fmt,
126 &olen,
127 NULL, sizeof( buf ) ) );
128
129 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
130 mbedtls_ecp_point_read_binary( NULL, &P, buf,
131 sizeof( buf ) ) );
132 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
133 mbedtls_ecp_point_read_binary( &grp, NULL, buf,
134 sizeof( buf ) ) );
135 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
136 mbedtls_ecp_point_read_binary( &grp, &P, NULL,
137 sizeof( buf ) ) );
138
139 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
140 mbedtls_ecp_tls_read_point( NULL, &P,
141 (const unsigned char **) &buf,
142 sizeof( buf ) ) );
143 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
144 mbedtls_ecp_tls_read_point( &grp, NULL,
145 (const unsigned char **) &buf,
146 sizeof( buf ) ) );
147 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
148 mbedtls_ecp_tls_read_point( &grp, &P, &null_buf,
149 sizeof( buf ) ) );
150 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
151 mbedtls_ecp_tls_read_point( &grp, &P, NULL,
152 sizeof( buf ) ) );
153
154 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
155 mbedtls_ecp_tls_write_point( NULL, &P,
156 valid_fmt,
157 &olen,
158 buf,
159 sizeof( buf ) ) );
160 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
161 mbedtls_ecp_tls_write_point( &grp, NULL,
162 valid_fmt,
163 &olen,
164 buf,
165 sizeof( buf ) ) );
166 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
167 mbedtls_ecp_tls_write_point( &grp, &P,
168 invalid_fmt,
169 &olen,
170 buf,
171 sizeof( buf ) ) );
172 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
173 mbedtls_ecp_tls_write_point( &grp, &P,
174 valid_fmt,
175 NULL,
176 buf,
177 sizeof( buf ) ) );
178 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
179 mbedtls_ecp_tls_write_point( &grp, &P,
180 valid_fmt,
181 &olen,
182 NULL,
183 sizeof( buf ) ) );
184
185 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
186 mbedtls_ecp_group_load( NULL, valid_group ) );
187
188 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
189 mbedtls_ecp_tls_read_group( NULL,
190 (const unsigned char **) &buf,
191 sizeof( buf ) ) );
192 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
193 mbedtls_ecp_tls_read_group( &grp, NULL,
194 sizeof( buf ) ) );
195 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
196 mbedtls_ecp_tls_read_group( &grp, &null_buf,
197 sizeof( buf ) ) );
198
199 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
200 mbedtls_ecp_tls_read_group_id( NULL,
201 (const unsigned char **) &buf,
202 sizeof( buf ) ) );
203 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
204 mbedtls_ecp_tls_read_group_id( &valid_group, NULL,
205 sizeof( buf ) ) );
206 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
207 mbedtls_ecp_tls_read_group_id( &valid_group,
208 &null_buf,
209 sizeof( buf ) ) );
210
211 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
212 mbedtls_ecp_tls_write_group( NULL, &olen,
213 buf, sizeof( buf ) ) );
214 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
215 mbedtls_ecp_tls_write_group( &grp, NULL,
216 buf, sizeof( buf ) ) );
217 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
218 mbedtls_ecp_tls_write_group( &grp, &olen,
219 NULL, sizeof( buf ) ) );
220
221 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
222 mbedtls_ecp_mul( NULL, &P, &m, &P,
223 rnd_std_rand, NULL ) );
224 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
225 mbedtls_ecp_mul( &grp, NULL, &m, &P,
226 rnd_std_rand, NULL ) );
227 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
228 mbedtls_ecp_mul( &grp, &P, NULL, &P,
229 rnd_std_rand, NULL ) );
230 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
231 mbedtls_ecp_mul( &grp, &P, &m, NULL,
232 rnd_std_rand, NULL ) );
233
234 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
235 mbedtls_ecp_mul_restartable( NULL, &P, &m, &P,
236 rnd_std_rand, NULL , NULL ) );
237 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
238 mbedtls_ecp_mul_restartable( &grp, NULL, &m, &P,
239 rnd_std_rand, NULL , NULL ) );
240 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
241 mbedtls_ecp_mul_restartable( &grp, &P, NULL, &P,
242 rnd_std_rand, NULL , NULL ) );
243 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
244 mbedtls_ecp_mul_restartable( &grp, &P, &m, NULL,
245 rnd_std_rand, NULL , NULL ) );
246
247 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
248 mbedtls_ecp_muladd( NULL, &P, &m, &P,
249 &m, &P ) );
250 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
251 mbedtls_ecp_muladd( &grp, NULL, &m, &P,
252 &m, &P ) );
253 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
254 mbedtls_ecp_muladd( &grp, &P, NULL, &P,
255 &m, &P ) );
256 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
257 mbedtls_ecp_muladd( &grp, &P, &m, NULL,
258 &m, &P ) );
259 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
260 mbedtls_ecp_muladd( &grp, &P, &m, &P,
261 NULL, &P ) );
262 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
263 mbedtls_ecp_muladd( &grp, &P, &m, &P,
264 &m, NULL ) );
265
266 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
267 mbedtls_ecp_muladd_restartable( NULL, &P, &m, &P,
268 &m, &P, NULL ) );
269 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
270 mbedtls_ecp_muladd_restartable( &grp, NULL, &m, &P,
271 &m, &P, NULL ) );
272 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
273 mbedtls_ecp_muladd_restartable( &grp, &P, NULL, &P,
274 &m, &P, NULL ) );
275 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
276 mbedtls_ecp_muladd_restartable( &grp, &P, &m, NULL,
277 &m, &P, NULL ) );
278 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
279 mbedtls_ecp_muladd_restartable( &grp, &P, &m, &P,
280 NULL, &P, NULL ) );
281 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
282 mbedtls_ecp_muladd_restartable( &grp, &P, &m, &P,
283 &m, NULL, NULL ) );
284
285 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
286 mbedtls_ecp_check_pubkey( NULL, &P ) );
287 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
288 mbedtls_ecp_check_pubkey( &grp, NULL ) );
289
290 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
Hanno Becker19595352018-12-18 23:54:04 +0000291 mbedtls_ecp_check_pub_priv( NULL, &kp ) );
292 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
293 mbedtls_ecp_check_pub_priv( &kp, NULL ) );
294
295 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
Hanno Becker12dff032018-12-14 15:08:13 +0000296 mbedtls_ecp_check_privkey( NULL, &m ) );
297 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
298 mbedtls_ecp_check_privkey( &grp, NULL ) );
299
300 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
301 mbedtls_ecp_gen_keypair_base( NULL, &P,
302 &m, &P,
303 rnd_std_rand,
304 NULL ) );
305 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
306 mbedtls_ecp_gen_keypair_base( &grp, NULL,
307 &m, &P,
308 rnd_std_rand,
309 NULL ) );
310 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
311 mbedtls_ecp_gen_keypair_base( &grp, &P,
312 NULL, &P,
313 rnd_std_rand,
314 NULL ) );
315 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
316 mbedtls_ecp_gen_keypair_base( &grp, &P,
317 &m, NULL,
318 rnd_std_rand,
319 NULL ) );
320 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
321 mbedtls_ecp_gen_keypair_base( &grp, &P,
322 &m, &P,
323 NULL,
324 NULL ) );
325
326 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
327 mbedtls_ecp_gen_keypair( NULL,
328 &m, &P,
329 rnd_std_rand,
330 NULL ) );
331 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
332 mbedtls_ecp_gen_keypair( &grp,
333 NULL, &P,
334 rnd_std_rand,
335 NULL ) );
336 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
337 mbedtls_ecp_gen_keypair( &grp,
338 &m, NULL,
339 rnd_std_rand,
340 NULL ) );
341 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
342 mbedtls_ecp_gen_keypair( &grp,
343 &m, &P,
344 NULL,
345 NULL ) );
346
347 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
348 mbedtls_ecp_gen_key( valid_group, NULL,
349 rnd_std_rand, NULL ) );
350 TEST_INVALID_PARAM_RET( MBEDTLS_ERR_ECP_BAD_INPUT_DATA,
351 mbedtls_ecp_gen_key( valid_group, &kp,
352 NULL, NULL ) );
353
354exit:
355 return;
356}
357/* END_CASE */
358
Paul Bakker33b43f12013-08-20 11:48:36 +0200359/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100360void mbedtls_ecp_curve_info( int id, int tls_id, int size, char * name )
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +0100361{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200362 const mbedtls_ecp_curve_info *by_id, *by_tls, *by_name;
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +0100363
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200364 by_id = mbedtls_ecp_curve_info_from_grp_id( id );
365 by_tls = mbedtls_ecp_curve_info_from_tls_id( tls_id );
366 by_name = mbedtls_ecp_curve_info_from_name( name );
Paul Bakker94b916c2014-04-17 16:07:20 +0200367 TEST_ASSERT( by_id != NULL );
368 TEST_ASSERT( by_tls != NULL );
369 TEST_ASSERT( by_name != NULL );
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +0100370
371 TEST_ASSERT( by_id == by_tls );
372 TEST_ASSERT( by_id == by_name );
373
Manuel Pégourié-Gonnard797f48a2015-06-18 15:45:05 +0200374 TEST_ASSERT( by_id->bit_size == size );
Manuel Pégourié-Gonnard0267e3d2013-11-30 15:10:14 +0100375}
376/* END_CASE */
377
378/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100379void ecp_check_pub( int grp_id, char * x_hex, char * y_hex, char * z_hex,
380 int ret )
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100381{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200382 mbedtls_ecp_group grp;
383 mbedtls_ecp_point P;
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100384
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200385 mbedtls_ecp_group_init( &grp );
386 mbedtls_ecp_point_init( &P );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100387
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200388 TEST_ASSERT( mbedtls_ecp_group_load( &grp, grp_id ) == 0 );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100389
Janos Follath28fff142017-01-27 15:51:14 +0000390 TEST_ASSERT( mbedtls_mpi_read_string( &P.X, 16, x_hex ) == 0 );
391 TEST_ASSERT( mbedtls_mpi_read_string( &P.Y, 16, y_hex ) == 0 );
392 TEST_ASSERT( mbedtls_mpi_read_string( &P.Z, 16, z_hex ) == 0 );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100393
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200394 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &P ) == ret );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100395
Paul Bakkerbd51b262014-07-10 15:26:12 +0200396exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200397 mbedtls_ecp_group_free( &grp );
398 mbedtls_ecp_point_free( &P );
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100399}
400/* END_CASE */
401
Manuel Pégourié-Gonnard4b9c51e2017-04-20 15:50:26 +0200402/* BEGIN_CASE depends_on:MBEDTLS_ECP_RESTARTABLE */
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100403void ecp_test_vect_restart( int id,
404 char *dA_str, char *xA_str, char *yA_str,
405 char *dB_str, char *xZ_str, char *yZ_str,
406 int max_ops, int min_restarts, int max_restarts )
407{
408 /*
409 * Test for early restart. Based on test vectors like ecp_test_vect(),
410 * but for the sake of simplicity only does half of each side. It's
411 * important to test both base point and random point, though, as memory
412 * management is different in each case.
413 *
414 * Don't try using too precise bounds for restarts as the exact number
415 * will depend on settings such as MBEDTLS_ECP_FIXED_POINT_OPTIM and
416 * MBEDTLS_ECP_WINDOW_SIZE, as well as implementation details that may
417 * change in the future. A factor 2 is a minimum safety margin.
418 *
419 * For reference, with mbed TLS 2.4 and default settings, for P-256:
Manuel Pégourié-Gonnard9c5c78f2017-03-20 14:13:07 +0100420 * - Random point mult: ~3250M
421 * - Cold base point mult: ~3300M
422 * - Hot base point mult: ~1100M
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100423 * With MBEDTLS_ECP_WINDOW_SIZE set to 2 (minimum):
Manuel Pégourié-Gonnard9c5c78f2017-03-20 14:13:07 +0100424 * - Random point mult: ~3850M
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100425 */
Manuel Pégourié-Gonnardb739a712017-04-19 10:11:56 +0200426 mbedtls_ecp_restart_ctx ctx;
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100427 mbedtls_ecp_group grp;
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200428 mbedtls_ecp_point R, P;
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100429 mbedtls_mpi dA, xA, yA, dB, xZ, yZ;
430 int cnt_restarts;
431 int ret;
432
Manuel Pégourié-Gonnardb739a712017-04-19 10:11:56 +0200433 mbedtls_ecp_restart_init( &ctx );
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200434 mbedtls_ecp_group_init( &grp );
435 mbedtls_ecp_point_init( &R ); mbedtls_ecp_point_init( &P );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100436 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA ); mbedtls_mpi_init( &yA );
437 mbedtls_mpi_init( &dB ); mbedtls_mpi_init( &xZ ); mbedtls_mpi_init( &yZ );
438
439 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
440
441 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_str ) == 0 );
442 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_str ) == 0 );
443 TEST_ASSERT( mbedtls_mpi_read_string( &yA, 16, yA_str ) == 0 );
444
445 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_str ) == 0 );
446 TEST_ASSERT( mbedtls_mpi_read_string( &xZ, 16, xZ_str ) == 0 );
447 TEST_ASSERT( mbedtls_mpi_read_string( &yZ, 16, yZ_str ) == 0 );
448
449 mbedtls_ecp_set_max_ops( (unsigned) max_ops );
450
451 /* Base point case */
452 cnt_restarts = 0;
453 do {
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200454 ECP_PT_RESET( &R );
Manuel Pégourié-Gonnardb739a712017-04-19 10:11:56 +0200455 ret = mbedtls_ecp_mul_restartable( &grp, &R, &dA, &grp.G, NULL, NULL, &ctx );
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200456 } while( ret == MBEDTLS_ERR_ECP_IN_PROGRESS && ++cnt_restarts );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100457
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200458 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100459 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
460 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yA ) == 0 );
461
462 TEST_ASSERT( cnt_restarts >= min_restarts );
463 TEST_ASSERT( cnt_restarts <= max_restarts );
464
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100465 /* Non-base point case */
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200466 mbedtls_ecp_copy( &P, &R );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100467 cnt_restarts = 0;
468 do {
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200469 ECP_PT_RESET( &R );
470 ret = mbedtls_ecp_mul_restartable( &grp, &R, &dB, &P, NULL, NULL, &ctx );
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200471 } while( ret == MBEDTLS_ERR_ECP_IN_PROGRESS && ++cnt_restarts );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100472
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200473 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100474 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
475 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
476
477 TEST_ASSERT( cnt_restarts >= min_restarts );
478 TEST_ASSERT( cnt_restarts <= max_restarts );
479
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200480 /* Do we leak memory when aborting an operation?
481 * This test only makes sense when we actually restart */
482 if( min_restarts > 0 )
483 {
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200484 ret = mbedtls_ecp_mul_restartable( &grp, &R, &dB, &P, NULL, NULL, &ctx );
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200485 TEST_ASSERT( ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
486 }
Manuel Pégourié-Gonnard77af79a2017-03-14 10:58:00 +0100487
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100488exit:
Manuel Pégourié-Gonnardb739a712017-04-19 10:11:56 +0200489 mbedtls_ecp_restart_free( &ctx );
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200490 mbedtls_ecp_group_free( &grp );
491 mbedtls_ecp_point_free( &R ); mbedtls_ecp_point_free( &P );
Manuel Pégourié-Gonnard510d5ca2017-03-08 11:41:47 +0100492 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA ); mbedtls_mpi_free( &yA );
493 mbedtls_mpi_free( &dB ); mbedtls_mpi_free( &xZ ); mbedtls_mpi_free( &yZ );
494}
495/* END_CASE */
496
Manuel Pégourié-Gonnard4b9c51e2017-04-20 15:50:26 +0200497/* BEGIN_CASE depends_on:MBEDTLS_ECP_RESTARTABLE */
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200498void ecp_muladd_restart( int id, char *xR_str, char *yR_str,
499 char *u1_str, char *u2_str,
500 char *xQ_str, char *yQ_str,
501 int max_ops, int min_restarts, int max_restarts )
502{
503 /*
504 * Compute R = u1 * G + u2 * Q
505 * (test vectors mostly taken from ECDSA intermediate results)
506 *
507 * See comments at the top of ecp_test_vect_restart()
508 */
509 mbedtls_ecp_restart_ctx ctx;
510 mbedtls_ecp_group grp;
511 mbedtls_ecp_point R, Q;
512 mbedtls_mpi u1, u2, xR, yR;
513 int cnt_restarts;
514 int ret;
515
516 mbedtls_ecp_restart_init( &ctx );
517 mbedtls_ecp_group_init( &grp );
518 mbedtls_ecp_point_init( &R );
519 mbedtls_ecp_point_init( &Q );
520 mbedtls_mpi_init( &u1 ); mbedtls_mpi_init( &u2 );
521 mbedtls_mpi_init( &xR ); mbedtls_mpi_init( &yR );
522
523 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
524
525 TEST_ASSERT( mbedtls_mpi_read_string( &u1, 16, u1_str ) == 0 );
526 TEST_ASSERT( mbedtls_mpi_read_string( &u2, 16, u2_str ) == 0 );
527 TEST_ASSERT( mbedtls_mpi_read_string( &xR, 16, xR_str ) == 0 );
528 TEST_ASSERT( mbedtls_mpi_read_string( &yR, 16, yR_str ) == 0 );
529
530 TEST_ASSERT( mbedtls_mpi_read_string( &Q.X, 16, xQ_str ) == 0 );
531 TEST_ASSERT( mbedtls_mpi_read_string( &Q.Y, 16, yQ_str ) == 0 );
532 TEST_ASSERT( mbedtls_mpi_lset( &Q.Z, 1 ) == 0 );
533
534 mbedtls_ecp_set_max_ops( (unsigned) max_ops );
535
536 cnt_restarts = 0;
537 do {
Manuel Pégourié-Gonnard7a28e992018-10-16 11:22:45 +0200538 ECP_PT_RESET( &R );
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200539 ret = mbedtls_ecp_muladd_restartable( &grp, &R,
540 &u1, &grp.G, &u2, &Q, &ctx );
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200541 } while( ret == MBEDTLS_ERR_ECP_IN_PROGRESS && ++cnt_restarts );
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200542
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200543 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200544 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xR ) == 0 );
545 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yR ) == 0 );
546
547 TEST_ASSERT( cnt_restarts >= min_restarts );
548 TEST_ASSERT( cnt_restarts <= max_restarts );
549
Manuel Pégourié-Gonnard46ba7f32017-08-28 12:20:39 +0200550 /* Do we leak memory when aborting an operation?
551 * This test only makes sense when we actually restart */
552 if( min_restarts > 0 )
553 {
554 ret = mbedtls_ecp_muladd_restartable( &grp, &R,
555 &u1, &grp.G, &u2, &Q, &ctx );
556 TEST_ASSERT( ret == MBEDTLS_ERR_ECP_IN_PROGRESS );
557 }
Manuel Pégourié-Gonnard54dd6522017-04-20 13:36:18 +0200558
559exit:
560 mbedtls_ecp_restart_free( &ctx );
561 mbedtls_ecp_group_free( &grp );
562 mbedtls_ecp_point_free( &R );
563 mbedtls_ecp_point_free( &Q );
564 mbedtls_mpi_free( &u1 ); mbedtls_mpi_free( &u2 );
565 mbedtls_mpi_free( &xR ); mbedtls_mpi_free( &yR );
566}
567/* END_CASE */
568
Manuel Pégourié-Gonnard312d2e82013-12-04 11:08:01 +0100569/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100570void ecp_test_vect( int id, char * dA_str, char * xA_str, char * yA_str,
571 char * dB_str, char * xB_str, char * yB_str,
572 char * xZ_str, char * yZ_str )
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100573{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200574 mbedtls_ecp_group grp;
575 mbedtls_ecp_point R;
576 mbedtls_mpi dA, xA, yA, dB, xB, yB, xZ, yZ;
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200577 rnd_pseudo_info rnd_info;
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100578
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200579 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &R );
580 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA ); mbedtls_mpi_init( &yA ); mbedtls_mpi_init( &dB );
581 mbedtls_mpi_init( &xB ); mbedtls_mpi_init( &yB ); mbedtls_mpi_init( &xZ ); mbedtls_mpi_init( &yZ );
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200582 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100583
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200584 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100585
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200586 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &grp.G ) == 0 );
Manuel Pégourié-Gonnard1c330572012-11-24 12:05:44 +0100587
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200588 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_str ) == 0 );
589 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_str ) == 0 );
590 TEST_ASSERT( mbedtls_mpi_read_string( &yA, 16, yA_str ) == 0 );
591 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_str ) == 0 );
592 TEST_ASSERT( mbedtls_mpi_read_string( &xB, 16, xB_str ) == 0 );
593 TEST_ASSERT( mbedtls_mpi_read_string( &yB, 16, yB_str ) == 0 );
594 TEST_ASSERT( mbedtls_mpi_read_string( &xZ, 16, xZ_str ) == 0 );
595 TEST_ASSERT( mbedtls_mpi_read_string( &yZ, 16, yZ_str ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100596
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200597 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &grp.G,
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200598 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200599 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
600 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yA ) == 0 );
601 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
602 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &R, NULL, NULL ) == 0 );
603 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
604 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
605 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100606
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200607 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &grp.G, NULL, NULL ) == 0 );
608 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xB ) == 0 );
609 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yB ) == 0 );
610 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
611 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &R,
Manuel Pégourié-Gonnarde09d2f82013-09-02 14:29:09 +0200612 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200613 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xZ ) == 0 );
614 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.Y, &yZ ) == 0 );
615 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
Manuel Pégourié-Gonnarde739f012012-11-07 12:24:22 +0100616
Paul Bakkerbd51b262014-07-10 15:26:12 +0200617exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200618 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &R );
619 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA ); mbedtls_mpi_free( &yA ); mbedtls_mpi_free( &dB );
620 mbedtls_mpi_free( &xB ); mbedtls_mpi_free( &yB ); mbedtls_mpi_free( &xZ ); mbedtls_mpi_free( &yZ );
Manuel Pégourié-Gonnard4b8c3f22012-11-07 21:39:45 +0100621}
Paul Bakker33b43f12013-08-20 11:48:36 +0200622/* END_CASE */
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100623
Paul Bakker33b43f12013-08-20 11:48:36 +0200624/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100625void ecp_test_vec_x( int id, char * dA_hex, char * xA_hex, char * dB_hex,
626 char * xB_hex, char * xS_hex )
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100627{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200628 mbedtls_ecp_group grp;
629 mbedtls_ecp_point R;
630 mbedtls_mpi dA, xA, dB, xB, xS;
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100631 rnd_pseudo_info rnd_info;
632
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200633 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &R );
634 mbedtls_mpi_init( &dA ); mbedtls_mpi_init( &xA );
635 mbedtls_mpi_init( &dB ); mbedtls_mpi_init( &xB );
636 mbedtls_mpi_init( &xS );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100637 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
638
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200639 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100640
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200641 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &grp.G ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100642
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200643 TEST_ASSERT( mbedtls_mpi_read_string( &dA, 16, dA_hex ) == 0 );
644 TEST_ASSERT( mbedtls_mpi_read_string( &dB, 16, dB_hex ) == 0 );
645 TEST_ASSERT( mbedtls_mpi_read_string( &xA, 16, xA_hex ) == 0 );
646 TEST_ASSERT( mbedtls_mpi_read_string( &xB, 16, xB_hex ) == 0 );
647 TEST_ASSERT( mbedtls_mpi_read_string( &xS, 16, xS_hex ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100648
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200649 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &grp.G,
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100650 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200651 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
652 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xA ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100653
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200654 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &R,
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100655 &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200656 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
657 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xS ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100658
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200659 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dB, &grp.G, NULL, NULL ) == 0 );
660 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
661 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xB ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100662
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200663 TEST_ASSERT( mbedtls_ecp_mul( &grp, &R, &dA, &R, NULL, NULL ) == 0 );
664 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &R ) == 0 );
665 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R.X, &xS ) == 0 );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100666
Paul Bakkerbd51b262014-07-10 15:26:12 +0200667exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200668 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &R );
669 mbedtls_mpi_free( &dA ); mbedtls_mpi_free( &xA );
670 mbedtls_mpi_free( &dB ); mbedtls_mpi_free( &xB );
671 mbedtls_mpi_free( &xS );
Manuel Pégourié-Gonnarda0179b82013-12-04 11:49:20 +0100672}
673/* END_CASE */
674
675/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100676void ecp_fast_mod( int id, char * N_str )
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100677{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200678 mbedtls_ecp_group grp;
679 mbedtls_mpi N, R;
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100680
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200681 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &R );
682 mbedtls_ecp_group_init( &grp );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100683
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200684 TEST_ASSERT( mbedtls_mpi_read_string( &N, 16, N_str ) == 0 );
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200685 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarde783f062013-10-21 14:52:21 +0200686 TEST_ASSERT( grp.modp != NULL );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100687
688 /*
689 * Store correct result before we touch N
690 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200691 TEST_ASSERT( mbedtls_mpi_mod_mpi( &R, &N, &grp.P ) == 0 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100692
693 TEST_ASSERT( grp.modp( &N ) == 0 );
Manuel Pégourié-Gonnardc0696c22015-06-18 16:47:17 +0200694 TEST_ASSERT( mbedtls_mpi_bitlen( &N ) <= grp.pbits + 3 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100695
696 /*
Paul Bakkerd8b0c5e2014-04-11 15:31:33 +0200697 * Use mod rather than addition/subtraction in case previous test fails
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100698 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200699 TEST_ASSERT( mbedtls_mpi_mod_mpi( &N, &N, &grp.P ) == 0 );
700 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &N, &R ) == 0 );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100701
Paul Bakkerbd51b262014-07-10 15:26:12 +0200702exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200703 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &R );
704 mbedtls_ecp_group_free( &grp );
Manuel Pégourié-Gonnard84338242012-11-11 20:45:18 +0100705}
Paul Bakker33b43f12013-08-20 11:48:36 +0200706/* END_CASE */
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +0100707
Paul Bakker33b43f12013-08-20 11:48:36 +0200708/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100709void ecp_write_binary( int id, char * x, char * y, char * z, int format,
Azim Khan5fcca462018-06-29 11:05:32 +0100710 data_t * out, int blen, int ret )
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100711{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200712 mbedtls_ecp_group grp;
713 mbedtls_ecp_point P;
Azim Khanf1aaec92017-05-30 14:23:15 +0100714 unsigned char buf[256];
Manuel Pégourié-Gonnard420f1eb2013-02-10 12:22:46 +0100715 size_t olen;
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100716
717 memset( buf, 0, sizeof( buf ) );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100718
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200719 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100720
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200721 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100722
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200723 TEST_ASSERT( mbedtls_mpi_read_string( &P.X, 16, x ) == 0 );
724 TEST_ASSERT( mbedtls_mpi_read_string( &P.Y, 16, y ) == 0 );
725 TEST_ASSERT( mbedtls_mpi_read_string( &P.Z, 16, z ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100726
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200727 TEST_ASSERT( mbedtls_ecp_point_write_binary( &grp, &P, format,
Paul Bakker33b43f12013-08-20 11:48:36 +0200728 &olen, buf, blen ) == ret );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100729
Paul Bakker33b43f12013-08-20 11:48:36 +0200730 if( ret == 0 )
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100731 {
Azim Khand30ca132017-06-09 04:32:58 +0100732 TEST_ASSERT( hexcmp( buf, out->x, olen, out->len ) == 0 );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100733 }
734
Paul Bakkerbd51b262014-07-10 15:26:12 +0200735exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200736 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100737}
Paul Bakker33b43f12013-08-20 11:48:36 +0200738/* END_CASE */
Manuel Pégourié-Gonnarde19feb52012-11-24 14:10:14 +0100739
Paul Bakker33b43f12013-08-20 11:48:36 +0200740/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100741void ecp_read_binary( int id, data_t * buf, char * x, char * y, char * z,
Paul Bakker33b43f12013-08-20 11:48:36 +0200742 int ret )
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100743{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200744 mbedtls_ecp_group grp;
745 mbedtls_ecp_point P;
746 mbedtls_mpi X, Y, Z;
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100747
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100748
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200749 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
750 mbedtls_mpi_init( &X ); mbedtls_mpi_init( &Y ); mbedtls_mpi_init( &Z );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100751
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200752 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100753
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200754 TEST_ASSERT( mbedtls_mpi_read_string( &X, 16, x ) == 0 );
755 TEST_ASSERT( mbedtls_mpi_read_string( &Y, 16, y ) == 0 );
756 TEST_ASSERT( mbedtls_mpi_read_string( &Z, 16, z ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100757
Azim Khand30ca132017-06-09 04:32:58 +0100758 TEST_ASSERT( mbedtls_ecp_point_read_binary( &grp, &P, buf->x, buf->len ) == ret );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100759
Paul Bakker33b43f12013-08-20 11:48:36 +0200760 if( ret == 0 )
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100761 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200762 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.X, &X ) == 0 );
763 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Y, &Y ) == 0 );
764 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Z, &Z ) == 0 );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100765 }
766
Paul Bakkerbd51b262014-07-10 15:26:12 +0200767exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200768 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
769 mbedtls_mpi_free( &X ); mbedtls_mpi_free( &Y ); mbedtls_mpi_free( &Z );
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100770}
Paul Bakker33b43f12013-08-20 11:48:36 +0200771/* END_CASE */
Manuel Pégourié-Gonnard5e402d82012-11-24 16:19:42 +0100772
Paul Bakker33b43f12013-08-20 11:48:36 +0200773/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100774void mbedtls_ecp_tls_read_point( int id, data_t * buf, char * x, char * y,
Azim Khand30ca132017-06-09 04:32:58 +0100775 char * z, int ret )
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100776{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200777 mbedtls_ecp_group grp;
778 mbedtls_ecp_point P;
779 mbedtls_mpi X, Y, Z;
Azim Khand30ca132017-06-09 04:32:58 +0100780 const unsigned char *vbuf = buf->x;
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100781
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100782
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200783 mbedtls_ecp_group_init( &grp ); mbedtls_ecp_point_init( &P );
784 mbedtls_mpi_init( &X ); mbedtls_mpi_init( &Y ); mbedtls_mpi_init( &Z );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100785
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200786 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100787
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200788 TEST_ASSERT( mbedtls_mpi_read_string( &X, 16, x ) == 0 );
789 TEST_ASSERT( mbedtls_mpi_read_string( &Y, 16, y ) == 0 );
790 TEST_ASSERT( mbedtls_mpi_read_string( &Z, 16, z ) == 0 );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100791
Azim Khand30ca132017-06-09 04:32:58 +0100792 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &P, &vbuf, buf->len ) == ret );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100793
Paul Bakker33b43f12013-08-20 11:48:36 +0200794 if( ret == 0 )
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100795 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200796 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.X, &X ) == 0 );
797 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Y, &Y ) == 0 );
798 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P.Z, &Z ) == 0 );
Azim Khand30ca132017-06-09 04:32:58 +0100799 TEST_ASSERT( (uint32_t)( vbuf - buf->x ) == buf->len );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100800 }
801
Paul Bakkerbd51b262014-07-10 15:26:12 +0200802exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200803 mbedtls_ecp_group_free( &grp ); mbedtls_ecp_point_free( &P );
804 mbedtls_mpi_free( &X ); mbedtls_mpi_free( &Y ); mbedtls_mpi_free( &Z );
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100805}
Paul Bakker33b43f12013-08-20 11:48:36 +0200806/* END_CASE */
Manuel Pégourié-Gonnard8c16f962013-02-10 13:00:20 +0100807
Paul Bakker33b43f12013-08-20 11:48:36 +0200808/* BEGIN_CASE */
809void ecp_tls_write_read_point( int id )
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100810{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200811 mbedtls_ecp_group grp;
812 mbedtls_ecp_point pt;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100813 unsigned char buf[256];
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100814 const unsigned char *vbuf;
Manuel Pégourié-Gonnard420f1eb2013-02-10 12:22:46 +0100815 size_t olen;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100816
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200817 mbedtls_ecp_group_init( &grp );
818 mbedtls_ecp_point_init( &pt );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100819
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200820 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100821
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100822 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200823 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &grp.G,
824 MBEDTLS_ECP_PF_COMPRESSED, &olen, buf, 256 ) == 0 );
825 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen )
826 == MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100827 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100828
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100829 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200830 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &grp.G,
831 MBEDTLS_ECP_PF_UNCOMPRESSED, &olen, buf, 256 ) == 0 );
832 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
833 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.X, &pt.X ) == 0 );
834 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.Y, &pt.Y ) == 0 );
835 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp.G.Z, &pt.Z ) == 0 );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100836 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100837
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100838 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200839 TEST_ASSERT( mbedtls_ecp_set_zero( &pt ) == 0 );
840 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &pt,
841 MBEDTLS_ECP_PF_COMPRESSED, &olen, buf, 256 ) == 0 );
842 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
843 TEST_ASSERT( mbedtls_ecp_is_zero( &pt ) );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100844 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100845
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100846 memset( buf, 0x00, sizeof( buf ) ); vbuf = buf;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200847 TEST_ASSERT( mbedtls_ecp_set_zero( &pt ) == 0 );
848 TEST_ASSERT( mbedtls_ecp_tls_write_point( &grp, &pt,
849 MBEDTLS_ECP_PF_UNCOMPRESSED, &olen, buf, 256 ) == 0 );
850 TEST_ASSERT( mbedtls_ecp_tls_read_point( &grp, &pt, &vbuf, olen ) == 0 );
851 TEST_ASSERT( mbedtls_ecp_is_zero( &pt ) );
Manuel Pégourié-Gonnard98f51812013-02-10 13:38:29 +0100852 TEST_ASSERT( vbuf == buf + olen );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100853
Paul Bakkerbd51b262014-07-10 15:26:12 +0200854exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200855 mbedtls_ecp_group_free( &grp );
856 mbedtls_ecp_point_free( &pt );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100857}
Paul Bakker33b43f12013-08-20 11:48:36 +0200858/* END_CASE */
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100859
Paul Bakker33b43f12013-08-20 11:48:36 +0200860/* BEGIN_CASE */
Azim Khan5fcca462018-06-29 11:05:32 +0100861void mbedtls_ecp_tls_read_group( data_t * buf, int result, int bits,
Azim Khand30ca132017-06-09 04:32:58 +0100862 int record_len )
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100863{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200864 mbedtls_ecp_group grp;
Azim Khand30ca132017-06-09 04:32:58 +0100865 const unsigned char *vbuf = buf->x;
Azim Khanf1aaec92017-05-30 14:23:15 +0100866 int ret;
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100867
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200868 mbedtls_ecp_group_init( &grp );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100869
Azim Khand30ca132017-06-09 04:32:58 +0100870 ret = mbedtls_ecp_tls_read_group( &grp, &vbuf, buf->len );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100871
Paul Bakker33b43f12013-08-20 11:48:36 +0200872 TEST_ASSERT( ret == result );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100873 if( ret == 0)
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100874 {
Manuel Pégourié-Gonnardc0696c22015-06-18 16:47:17 +0200875 TEST_ASSERT( mbedtls_mpi_bitlen( &grp.P ) == (size_t) bits );
Azim Khand30ca132017-06-09 04:32:58 +0100876 TEST_ASSERT( vbuf - buf->x == record_len);
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100877 }
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100878
Paul Bakkerbd51b262014-07-10 15:26:12 +0200879exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200880 mbedtls_ecp_group_free( &grp );
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100881}
Paul Bakker33b43f12013-08-20 11:48:36 +0200882/* END_CASE */
Manuel Pégourié-Gonnard6282aca2013-02-10 11:15:11 +0100883
Paul Bakker33b43f12013-08-20 11:48:36 +0200884/* BEGIN_CASE */
885void ecp_tls_write_read_group( int id )
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100886{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200887 mbedtls_ecp_group grp1, grp2;
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100888 unsigned char buf[10];
Manuel Pégourié-Gonnard7c145c62013-02-10 13:20:52 +0100889 const unsigned char *vbuf = buf;
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100890 size_t len;
891 int ret;
892
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200893 mbedtls_ecp_group_init( &grp1 );
894 mbedtls_ecp_group_init( &grp2 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100895 memset( buf, 0x00, sizeof( buf ) );
896
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200897 TEST_ASSERT( mbedtls_ecp_group_load( &grp1, id ) == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100898
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200899 TEST_ASSERT( mbedtls_ecp_tls_write_group( &grp1, &len, buf, 10 ) == 0 );
900 ret = mbedtls_ecp_tls_read_group( &grp2, &vbuf, len );
Paul Bakker94b916c2014-04-17 16:07:20 +0200901 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100902
903 if( ret == 0 )
904 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200905 TEST_ASSERT( mbedtls_mpi_cmp_mpi( &grp1.N, &grp2.N ) == 0 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100906 TEST_ASSERT( grp1.id == grp2.id );
907 }
908
Paul Bakkerbd51b262014-07-10 15:26:12 +0200909exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200910 mbedtls_ecp_group_free( &grp1 );
911 mbedtls_ecp_group_free( &grp2 );
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100912}
Paul Bakker33b43f12013-08-20 11:48:36 +0200913/* END_CASE */
Manuel Pégourié-Gonnard46106a92013-02-10 12:51:17 +0100914
Paul Bakker33b43f12013-08-20 11:48:36 +0200915/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100916void mbedtls_ecp_check_privkey( int id, char * key_hex, int ret )
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200917{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200918 mbedtls_ecp_group grp;
919 mbedtls_mpi d;
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200920
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200921 mbedtls_ecp_group_init( &grp );
922 mbedtls_mpi_init( &d );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200923
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200924 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200925 TEST_ASSERT( mbedtls_mpi_read_string( &d, 16, key_hex ) == 0 );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200926
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200927 TEST_ASSERT( mbedtls_ecp_check_privkey( &grp, &d ) == ret );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200928
Paul Bakkerbd51b262014-07-10 15:26:12 +0200929exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200930 mbedtls_ecp_group_free( &grp );
931 mbedtls_mpi_free( &d );
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200932}
Paul Bakker33b43f12013-08-20 11:48:36 +0200933/* END_CASE */
Manuel Pégourié-Gonnardc8dc2952013-07-01 14:06:13 +0200934
Paul Bakker33b43f12013-08-20 11:48:36 +0200935/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100936void mbedtls_ecp_check_pub_priv( int id_pub, char * Qx_pub, char * Qy_pub,
937 int id, char * d, char * Qx, char * Qy,
938 int ret )
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100939{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200940 mbedtls_ecp_keypair pub, prv;
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100941
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200942 mbedtls_ecp_keypair_init( &pub );
943 mbedtls_ecp_keypair_init( &prv );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100944
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200945 if( id_pub != MBEDTLS_ECP_DP_NONE )
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200946 TEST_ASSERT( mbedtls_ecp_group_load( &pub.grp, id_pub ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200947 TEST_ASSERT( mbedtls_ecp_point_read_string( &pub.Q, 16, Qx_pub, Qy_pub ) == 0 );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100948
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200949 if( id != MBEDTLS_ECP_DP_NONE )
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200950 TEST_ASSERT( mbedtls_ecp_group_load( &prv.grp, id ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200951 TEST_ASSERT( mbedtls_ecp_point_read_string( &prv.Q, 16, Qx, Qy ) == 0 );
952 TEST_ASSERT( mbedtls_mpi_read_string( &prv.d, 16, d ) == 0 );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100953
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200954 TEST_ASSERT( mbedtls_ecp_check_pub_priv( &pub, &prv ) == ret );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100955
956exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200957 mbedtls_ecp_keypair_free( &pub );
958 mbedtls_ecp_keypair_free( &prv );
Manuel Pégourié-Gonnard30668d62014-11-06 15:25:32 +0100959}
960/* END_CASE */
961
962/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200963void mbedtls_ecp_gen_keypair( int id )
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100964{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200965 mbedtls_ecp_group grp;
966 mbedtls_ecp_point Q;
967 mbedtls_mpi d;
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100968 rnd_pseudo_info rnd_info;
969
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200970 mbedtls_ecp_group_init( &grp );
971 mbedtls_ecp_point_init( &Q );
972 mbedtls_mpi_init( &d );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100973 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
974
Manuel Pégourié-Gonnarde3a062b2015-05-11 18:46:47 +0200975 TEST_ASSERT( mbedtls_ecp_group_load( &grp, id ) == 0 );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100976
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200977 TEST_ASSERT( mbedtls_ecp_gen_keypair( &grp, &d, &Q, &rnd_pseudo_rand, &rnd_info )
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100978 == 0 );
979
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200980 TEST_ASSERT( mbedtls_ecp_check_pubkey( &grp, &Q ) == 0 );
981 TEST_ASSERT( mbedtls_ecp_check_privkey( &grp, &d ) == 0 );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100982
Paul Bakkerbd51b262014-07-10 15:26:12 +0200983exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200984 mbedtls_ecp_group_free( &grp );
985 mbedtls_ecp_point_free( &Q );
986 mbedtls_mpi_free( &d );
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100987}
Paul Bakker33b43f12013-08-20 11:48:36 +0200988/* END_CASE */
Manuel Pégourié-Gonnard45a035a2013-01-26 14:42:45 +0100989
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100990/* BEGIN_CASE */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200991void mbedtls_ecp_gen_key( int id )
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100992{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200993 mbedtls_ecp_keypair key;
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100994 rnd_pseudo_info rnd_info;
995
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200996 mbedtls_ecp_keypair_init( &key );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +0100997 memset( &rnd_info, 0x00, sizeof( rnd_pseudo_info ) );
998
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200999 TEST_ASSERT( mbedtls_ecp_gen_key( id, &key, &rnd_pseudo_rand, &rnd_info ) == 0 );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +01001000
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001001 TEST_ASSERT( mbedtls_ecp_check_pubkey( &key.grp, &key.Q ) == 0 );
1002 TEST_ASSERT( mbedtls_ecp_check_privkey( &key.grp, &key.d ) == 0 );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +01001003
Paul Bakkerbd51b262014-07-10 15:26:12 +02001004exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001005 mbedtls_ecp_keypair_free( &key );
Manuel Pégourié-Gonnard104ee1d2013-11-30 14:13:16 +01001006}
1007/* END_CASE */
1008
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001009/* BEGIN_CASE depends_on:MBEDTLS_SELF_TEST */
Azim Khanf1aaec92017-05-30 14:23:15 +01001010void ecp_selftest( )
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +01001011{
Andres AG93012e82016-09-09 09:10:28 +01001012 TEST_ASSERT( mbedtls_ecp_self_test( 1 ) == 0 );
Manuel Pégourié-Gonnardb4a310b2012-11-13 20:57:00 +01001013}
Paul Bakker33b43f12013-08-20 11:48:36 +02001014/* END_CASE */