test_pss.py 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378
  1. # ===================================================================
  2. #
  3. # Copyright (c) 2014, Legrandin <helderijs@gmail.com>
  4. # All rights reserved.
  5. #
  6. # Redistribution and use in source and binary forms, with or without
  7. # modification, are permitted provided that the following conditions
  8. # are met:
  9. #
  10. # 1. Redistributions of source code must retain the above copyright
  11. # notice, this list of conditions and the following disclaimer.
  12. # 2. Redistributions in binary form must reproduce the above copyright
  13. # notice, this list of conditions and the following disclaimer in
  14. # the documentation and/or other materials provided with the
  15. # distribution.
  16. #
  17. # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
  18. # "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
  19. # LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
  20. # FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
  21. # COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
  22. # INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
  23. # BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  24. # LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  25. # CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
  26. # LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
  27. # ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
  28. # POSSIBILITY OF SUCH DAMAGE.
  29. # ===================================================================
  30. import unittest
  31. from Crypto.Util.py3compat import b, bchr
  32. from Crypto.Util.number import bytes_to_long
  33. from Crypto.Util.strxor import strxor
  34. from Crypto.SelfTest.st_common import list_test_cases
  35. from Crypto.SelfTest.loader import load_test_vectors, load_test_vectors_wycheproof
  36. from Crypto.Hash import SHA1, SHA224, SHA256, SHA384, SHA512
  37. from Crypto.PublicKey import RSA
  38. from Crypto.Signature import pss
  39. from Crypto.Signature import PKCS1_PSS
  40. from Crypto.Signature.pss import MGF1
  41. def load_hash_by_name(hash_name):
  42. return __import__("Crypto.Hash." + hash_name, globals(), locals(), ["new"])
  43. class PRNG(object):
  44. def __init__(self, stream):
  45. self.stream = stream
  46. self.idx = 0
  47. def __call__(self, rnd_size):
  48. result = self.stream[self.idx:self.idx + rnd_size]
  49. self.idx += rnd_size
  50. return result
  51. class PSS_Tests(unittest.TestCase):
  52. rsa_key = b'-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEAsvI34FgiTK8+txBvmooNGpNwk23YTU51dwNZi5yha3W4lA/Q\nvcZrDalkmD7ekWQwnduxVKa6pRSI13KBgeUOIqJoGXSWhntEtY3FEwvWOHW5AE7Q\njUzTzCiYT6TVaCcpa/7YLai+p6ai2g5f5Zfh4jSawa9uYeuggFygQq4IVW796MgV\nyqxYMM/arEj+/sKz3Viua9Rp9fFosertCYCX4DUTgW0mX9bwEnEOgjSI3pLOPXz1\n8vx+DRZS5wMCmwCUa0sKonLn3cAUPq+sGix7+eo7T0Z12MU8ud7IYVX/75r3cXiF\nPaYE2q8Le0kgOApIXbb+x74x0rNgyIh1yGygkwIDAQABAoIBABz4t1A0pLT6qHI2\nEIOaNz3mwhK0dZEqkz0GB1Dhtoax5ATgvKCFB98J3lYB08IBURe1snOsnMpOVUtg\naBRSM+QqnCUG6bnzKjAkuFP5liDE+oNQv1YpKp9CsUovuzdmI8Au3ewihl+ZTIN2\nUVNYMEOR1b5m+z2SSwWNOYsiJwpBrT7zkpdlDyjat7FiiPhMMIMXjhQFVxURMIcB\njUBtPzGvV/PG90cVDWi1wRGeeP1dDqti/jsnvykQ15KW1MqGrpeNKRmDdTy/Ucl1\nWIoYklKw3U456lgZ/rDTDB818+Tlnk35z4yF7d5ANPM8CKfqOPcnO1BCKVFzf4eq\n54wvUtkCgYEA1Zv2lp06l7rXMsvNtyYQjbFChezRDRnPwZmN4NCdRtTgGG1G0Ryd\nYz6WWoPGqZp0b4LAaaHd3W2GTcpXF8WXMKfMX1W+tMAxMozfsXRKMcHoypwuS5wT\nfJRXJCG4pvd57AB0iVUEJW2we+uGKU5Zxcx//id2nXGCpoRyViIplQsCgYEA1nVC\neHupHChht0Fh4N09cGqZHZzuwXjOUMzR3Vsfz+4WzVS3NvIgN4g5YgmQFOeKwo5y\niRq5yvubcNdFvf85eHWClg0zPAyxJCVUWigCrrOanGEhJo6re4idJvNVzu4Ucg0v\n6B3SJ1HsCda+ZSNz24bSyqRep8A+RoAaoVSFx5kCgYEAn3RvXPs9s+obnqWYiPF3\nRe5etE6Vt2vfNKwFxx6zaR6bsmBQjuUHcABWiHb6I71S0bMPI0tbrWGG8ibrYKl1\nNTLtUvVVCOS3VP7oNTWT9RTFTAnOXU7DFSo+6o/poWn3r36ff6zhDXeWWMr2OXtt\ndEQ1/2lCGEGVv+v61eVmmQUCgYABFHITPTwqwiFL1O5zPWnzyPWgaovhOYSAb6eW\n38CXQXGn8wdBJZL39J2lWrr4//l45VK6UgIhfYbY2JynSkO10ZGow8RARygVMILu\nOUlaK9lZdDvAf/NpGdUAvzTtZ9F+iYZ2OsA2JnlzyzsGM1l//3vMPWukmJk3ral0\nqoJJ8QKBgGRG3eVHnIegBbFVuMDp2NTcfuSuDVUQ1fGAwtPiFa8u81IodJnMk2pq\niXu2+0ytNA/M+SVrAnE2AgIzcaJbtr0p2srkuVM7KMWnG1vWFNjtXN8fAhf/joOv\nD+NmPL/N4uE57e40tbiU/H7KdyZaDt+5QiTmdhuyAe6CBjKsF2jy\n-----END RSA PRIVATE KEY-----'
  53. msg = b'AAA'
  54. tag = b'\x00[c5\xd8\xb0\x8b!D\x81\x83\x07\xc0\xdd\xb9\xb4\xb2`\x92\xe7\x02\xf1\xe1P\xea\xc3\xf0\xe3>\xddX5\xdd\x8e\xc5\x89\xef\xf3\xc2\xdc\xfeP\x02\x7f\x12+\xc9\xaf\xbb\xec\xfe\xb0\xa5\xb9\x08\x11P\x8fL\xee5\x9b\xb0k{=_\xd2\x14\xfb\x01R\xb7\xfe\x14}b\x03\x8d5Y\x89~}\xfc\xf2l\xd01-\xbd\xeb\x11\xcdV\x11\xe9l\x19k/o5\xa2\x0f\x15\xe7Q$\t=\xec\x1dAB\x19\xa5P\x9a\xaf\xa3G\x86"\xd6~\xf0<p5\x00\x86\xe0\xf3\x99\xc7+\xcfc,\\\x13)v\xcd\xff\x08o\x90\xc5\xd1\xca\x869\xf45\x1e\xfd\xa2\xf1n\xa3\xa6e\xc5\x11Q\xe4@\xbd\x17\x83x\xc9\x9b\xb5\xc7\xea\x03U\x9b\xa0\xccC\x17\xc9T\x86/\x05\x1c\xc7\x95hC\xf9b1\xbb\x05\xc3\xf0\x9a>j\xfcqkbs\x13\x84b\xe4\xbdm(\xed`\xa4F\xfb\x8f.\xe1\x8c)/_\x9eS\x98\xa4v\xb8\xdc\xfe\xf7/D\x18\x19\xb3T\x97:\xe2\x96s\xe8<\xa2\xb4\xb9\xf8/'
  55. def test_positive_1(self):
  56. key = RSA.import_key(self.rsa_key)
  57. h = SHA256.new(self.msg)
  58. verifier = pss.new(key)
  59. verifier.verify(h, self.tag)
  60. def test_negative_1(self):
  61. key = RSA.import_key(self.rsa_key)
  62. h = SHA256.new(self.msg + b'A')
  63. verifier = pss.new(key)
  64. tag = bytearray(self.tag)
  65. self.assertRaises(ValueError, verifier.verify, h, tag)
  66. def test_negative_2(self):
  67. key = RSA.import_key(self.rsa_key)
  68. h = SHA256.new(self.msg)
  69. verifier = pss.new(key, salt_bytes=1000)
  70. tag = bytearray(self.tag)
  71. self.assertRaises(ValueError, verifier.verify, h, tag)
  72. class FIPS_PKCS1_Verify_Tests(unittest.TestCase):
  73. def shortDescription(self):
  74. return "FIPS PKCS1 Tests (Verify)"
  75. def verify_positive(self, hashmod, message, public_key, salt, signature):
  76. prng = PRNG(salt)
  77. hashed = hashmod.new(message)
  78. verifier = pss.new(public_key, salt_bytes=len(salt), rand_func=prng)
  79. verifier.verify(hashed, signature)
  80. def verify_negative(self, hashmod, message, public_key, salt, signature):
  81. prng = PRNG(salt)
  82. hashed = hashmod.new(message)
  83. verifier = pss.new(public_key, salt_bytes=len(salt), rand_func=prng)
  84. self.assertRaises(ValueError, verifier.verify, hashed, signature)
  85. def test_can_sign(self):
  86. test_public_key = RSA.generate(1024).public_key()
  87. verifier = pss.new(test_public_key)
  88. self.assertEqual(verifier.can_sign(), False)
  89. class FIPS_PKCS1_Verify_Tests_KAT(unittest.TestCase):
  90. pass
  91. test_vectors_verify = load_test_vectors(("Signature", "PKCS1-PSS"),
  92. "SigVerPSS_186-3.rsp",
  93. "Signature Verification 186-3",
  94. {'shaalg': lambda x: x,
  95. 'result': lambda x: x}) or []
  96. for count, tv in enumerate(test_vectors_verify):
  97. if isinstance(tv, str):
  98. continue
  99. if hasattr(tv, "n"):
  100. modulus = tv.n
  101. continue
  102. if hasattr(tv, "p"):
  103. continue
  104. hash_module = load_hash_by_name(tv.shaalg.upper())
  105. hash_obj = hash_module.new(tv.msg)
  106. public_key = RSA.construct([bytes_to_long(x) for x in (modulus, tv.e)]) # type: ignore
  107. if tv.saltval != b("\x00"):
  108. prng = PRNG(tv.saltval)
  109. verifier = pss.new(public_key, salt_bytes=len(tv.saltval), rand_func=prng)
  110. else:
  111. verifier = pss.new(public_key, salt_bytes=0)
  112. def positive_test(self, hash_obj=hash_obj, verifier=verifier, signature=tv.s):
  113. verifier.verify(hash_obj, signature)
  114. def negative_test(self, hash_obj=hash_obj, verifier=verifier, signature=tv.s):
  115. self.assertRaises(ValueError, verifier.verify, hash_obj, signature)
  116. if tv.result == 'p':
  117. setattr(FIPS_PKCS1_Verify_Tests_KAT, "test_positive_%d" % count, positive_test)
  118. else:
  119. setattr(FIPS_PKCS1_Verify_Tests_KAT, "test_negative_%d" % count, negative_test)
  120. class FIPS_PKCS1_Sign_Tests(unittest.TestCase):
  121. def shortDescription(self):
  122. return "FIPS PKCS1 Tests (Sign)"
  123. def test_can_sign(self):
  124. test_private_key = RSA.generate(1024)
  125. signer = pss.new(test_private_key)
  126. self.assertEqual(signer.can_sign(), True)
  127. class FIPS_PKCS1_Sign_Tests_KAT(unittest.TestCase):
  128. pass
  129. test_vectors_sign = load_test_vectors(("Signature", "PKCS1-PSS"),
  130. "SigGenPSS_186-2.txt",
  131. "Signature Generation 186-2",
  132. {'shaalg': lambda x: x}) or []
  133. test_vectors_sign += load_test_vectors(("Signature", "PKCS1-PSS"),
  134. "SigGenPSS_186-3.txt",
  135. "Signature Generation 186-3",
  136. {'shaalg': lambda x: x}) or []
  137. for count, tv in enumerate(test_vectors_sign):
  138. if isinstance(tv, str):
  139. continue
  140. if hasattr(tv, "n"):
  141. modulus = tv.n
  142. continue
  143. if hasattr(tv, "e"):
  144. private_key = RSA.construct([bytes_to_long(x) for x in (modulus, tv.e, tv.d)]) # type: ignore
  145. continue
  146. hash_module = load_hash_by_name(tv.shaalg.upper())
  147. hash_obj = hash_module.new(tv.msg)
  148. if tv.saltval != b("\x00"):
  149. prng = PRNG(tv.saltval)
  150. signer = pss.new(private_key, salt_bytes=len(tv.saltval), rand_func=prng)
  151. else:
  152. signer = pss.new(private_key, salt_bytes=0)
  153. def new_test(self, hash_obj=hash_obj, signer=signer, result=tv.s):
  154. signature = signer.sign(hash_obj)
  155. self.assertEqual(signature, result)
  156. setattr(FIPS_PKCS1_Sign_Tests_KAT, "test_%d" % count, new_test)
  157. class PKCS1_Legacy_Module_Tests(unittest.TestCase):
  158. """Verify that the legacy module Crypto.Signature.PKCS1_PSS
  159. behaves as expected. The only difference is that the verify()
  160. method returns True/False and does not raise exceptions."""
  161. def shortDescription(self):
  162. return "Test legacy Crypto.Signature.PKCS1_PSS"
  163. def runTest(self):
  164. key = RSA.generate(1024)
  165. hashed = SHA1.new(b("Test"))
  166. good_signature = PKCS1_PSS.new(key).sign(hashed)
  167. verifier = PKCS1_PSS.new(key.public_key())
  168. self.assertEqual(verifier.verify(hashed, good_signature), True)
  169. # Flip a few bits in the signature
  170. bad_signature = strxor(good_signature, bchr(1) * len(good_signature))
  171. self.assertEqual(verifier.verify(hashed, bad_signature), False)
  172. class PKCS1_All_Hashes_Tests(unittest.TestCase):
  173. def shortDescription(self):
  174. return "Test PKCS#1 PSS signature in combination with all hashes"
  175. def runTest(self):
  176. key = RSA.generate(1280)
  177. signer = pss.new(key)
  178. hash_names = ("MD2", "MD4", "MD5", "RIPEMD160", "SHA1",
  179. "SHA224", "SHA256", "SHA384", "SHA512",
  180. "SHA3_224", "SHA3_256", "SHA3_384", "SHA3_512")
  181. for name in hash_names:
  182. hashed = load_hash_by_name(name).new(b("Test"))
  183. signer.sign(hashed)
  184. from Crypto.Hash import BLAKE2b, BLAKE2s
  185. for hash_size in (20, 32, 48, 64):
  186. hashed_b = BLAKE2b.new(digest_bytes=hash_size, data=b("Test"))
  187. signer.sign(hashed_b)
  188. for hash_size in (16, 20, 28, 32):
  189. hashed_s = BLAKE2s.new(digest_bytes=hash_size, data=b("Test"))
  190. signer.sign(hashed_s)
  191. def get_hash_module(hash_name):
  192. if hash_name == "SHA-512":
  193. hash_module = SHA512
  194. elif hash_name == "SHA-512/224":
  195. hash_module = SHA512.new(truncate="224")
  196. elif hash_name == "SHA-512/256":
  197. hash_module = SHA512.new(truncate="256")
  198. elif hash_name == "SHA-384":
  199. hash_module = SHA384
  200. elif hash_name == "SHA-256":
  201. hash_module = SHA256
  202. elif hash_name == "SHA-224":
  203. hash_module = SHA224
  204. elif hash_name == "SHA-1":
  205. hash_module = SHA1
  206. else:
  207. raise ValueError("Unknown hash algorithm: " + hash_name)
  208. return hash_module
  209. class TestVectorsPSSWycheproof(unittest.TestCase):
  210. def __init__(self, wycheproof_warnings):
  211. unittest.TestCase.__init__(self)
  212. self._wycheproof_warnings = wycheproof_warnings
  213. self._id = "None"
  214. def add_tests(self, filename):
  215. def filter_rsa(group):
  216. return RSA.import_key(group['keyPem'])
  217. def filter_sha(group):
  218. return get_hash_module(group['sha'])
  219. def filter_type(group):
  220. type_name = group['type']
  221. if type_name not in ("RsassaPssVerify", ):
  222. raise ValueError("Unknown type name " + type_name)
  223. def filter_slen(group):
  224. return group['sLen']
  225. def filter_mgf(group):
  226. mgf = group['mgf']
  227. if mgf not in ("MGF1", ):
  228. raise ValueError("Unknown MGF " + mgf)
  229. mgf1_hash = get_hash_module(group['mgfSha'])
  230. def mgf(x, y, mh=mgf1_hash):
  231. return MGF1(x, y, mh)
  232. return mgf
  233. result = load_test_vectors_wycheproof(("Signature", "wycheproof"),
  234. filename,
  235. "Wycheproof PSS signature (%s)" % filename,
  236. group_tag={'key': filter_rsa,
  237. 'hash_module': filter_sha,
  238. 'sLen': filter_slen,
  239. 'mgf': filter_mgf,
  240. 'type': filter_type})
  241. return result
  242. def setUp(self):
  243. self.tv = []
  244. self.add_tests("rsa_pss_2048_sha1_mgf1_20_test.json")
  245. self.add_tests("rsa_pss_2048_sha256_mgf1_0_test.json")
  246. self.add_tests("rsa_pss_2048_sha256_mgf1_32_test.json")
  247. self.add_tests("rsa_pss_2048_sha512_256_mgf1_28_test.json")
  248. self.add_tests("rsa_pss_2048_sha512_256_mgf1_32_test.json")
  249. self.add_tests("rsa_pss_3072_sha256_mgf1_32_test.json")
  250. self.add_tests("rsa_pss_4096_sha256_mgf1_32_test.json")
  251. self.add_tests("rsa_pss_4096_sha512_mgf1_32_test.json")
  252. self.add_tests("rsa_pss_misc_test.json")
  253. def shortDescription(self):
  254. return self._id
  255. def warn(self, tv):
  256. if tv.warning and self._wycheproof_warnings:
  257. import warnings
  258. warnings.warn("Wycheproof warning: %s (%s)" % (self._id, tv.comment))
  259. def test_verify(self, tv):
  260. self._id = "Wycheproof RSA PSS Test #%d (%s)" % (tv.id, tv.comment)
  261. hashed_msg = tv.hash_module.new(tv.msg)
  262. signer = pss.new(tv.key, mask_func=tv.mgf, salt_bytes=tv.sLen)
  263. try:
  264. signature = signer.verify(hashed_msg, tv.sig)
  265. except ValueError as e:
  266. if tv.warning:
  267. return
  268. assert not tv.valid
  269. else:
  270. assert tv.valid
  271. self.warn(tv)
  272. def runTest(self):
  273. for tv in self.tv:
  274. self.test_verify(tv)
  275. def get_tests(config={}):
  276. wycheproof_warnings = config.get('wycheproof_warnings')
  277. tests = []
  278. tests += list_test_cases(PSS_Tests)
  279. tests += list_test_cases(FIPS_PKCS1_Verify_Tests)
  280. tests += list_test_cases(FIPS_PKCS1_Sign_Tests)
  281. tests += list_test_cases(PKCS1_Legacy_Module_Tests)
  282. tests += list_test_cases(PKCS1_All_Hashes_Tests)
  283. if config.get('slow_tests'):
  284. tests += list_test_cases(FIPS_PKCS1_Verify_Tests_KAT)
  285. tests += list_test_cases(FIPS_PKCS1_Sign_Tests_KAT)
  286. tests += [TestVectorsPSSWycheproof(wycheproof_warnings)]
  287. return tests
  288. if __name__ == '__main__':
  289. def suite():
  290. return unittest.TestSuite(get_tests())
  291. unittest.main(defaultTest='suite')