test_suite_ccm.function 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506
  1. /* BEGIN_HEADER */
  2. #include "mbedtls/ccm.h"
  3. /* END_HEADER */
  4. /* BEGIN_DEPENDENCIES
  5. * depends_on:MBEDTLS_CCM_C
  6. * END_DEPENDENCIES
  7. */
  8. /* BEGIN_CASE depends_on:MBEDTLS_SELF_TEST:MBEDTLS_AES_C */
  9. void mbedtls_ccm_self_test( )
  10. {
  11. TEST_ASSERT( mbedtls_ccm_self_test( 1 ) == 0 );
  12. }
  13. /* END_CASE */
  14. /* BEGIN_CASE */
  15. void mbedtls_ccm_setkey( int cipher_id, int key_size, int result )
  16. {
  17. mbedtls_ccm_context ctx;
  18. unsigned char key[32];
  19. int ret;
  20. mbedtls_ccm_init( &ctx );
  21. memset( key, 0x2A, sizeof( key ) );
  22. TEST_ASSERT( (unsigned) key_size <= 8 * sizeof( key ) );
  23. ret = mbedtls_ccm_setkey( &ctx, cipher_id, key, key_size );
  24. TEST_ASSERT( ret == result );
  25. exit:
  26. mbedtls_ccm_free( &ctx );
  27. }
  28. /* END_CASE */
  29. /* BEGIN_CASE depends_on:MBEDTLS_AES_C */
  30. void ccm_lengths( int msg_len, int iv_len, int add_len, int tag_len, int res )
  31. {
  32. mbedtls_ccm_context ctx;
  33. unsigned char key[16];
  34. unsigned char msg[10];
  35. unsigned char iv[14];
  36. unsigned char add[10];
  37. unsigned char out[10];
  38. unsigned char tag[18];
  39. int decrypt_ret;
  40. mbedtls_ccm_init( &ctx );
  41. memset( key, 0, sizeof( key ) );
  42. memset( msg, 0, sizeof( msg ) );
  43. memset( iv, 0, sizeof( iv ) );
  44. memset( add, 0, sizeof( add ) );
  45. memset( out, 0, sizeof( out ) );
  46. memset( tag, 0, sizeof( tag ) );
  47. TEST_ASSERT( mbedtls_ccm_setkey( &ctx, MBEDTLS_CIPHER_ID_AES,
  48. key, 8 * sizeof( key ) ) == 0 );
  49. TEST_ASSERT( mbedtls_ccm_encrypt_and_tag( &ctx, msg_len, iv, iv_len, add, add_len,
  50. msg, out, tag, tag_len ) == res );
  51. decrypt_ret = mbedtls_ccm_auth_decrypt( &ctx, msg_len, iv, iv_len, add, add_len,
  52. msg, out, tag, tag_len );
  53. if( res == 0 )
  54. TEST_ASSERT( decrypt_ret == MBEDTLS_ERR_CCM_AUTH_FAILED );
  55. else
  56. TEST_ASSERT( decrypt_ret == res );
  57. exit:
  58. mbedtls_ccm_free( &ctx );
  59. }
  60. /* END_CASE */
  61. /* BEGIN_CASE depends_on:MBEDTLS_AES_C */
  62. void ccm_star_lengths( int msg_len, int iv_len, int add_len, int tag_len,
  63. int res )
  64. {
  65. mbedtls_ccm_context ctx;
  66. unsigned char key[16];
  67. unsigned char msg[10];
  68. unsigned char iv[14];
  69. unsigned char add[10];
  70. unsigned char out[10];
  71. unsigned char tag[18];
  72. int decrypt_ret;
  73. mbedtls_ccm_init( &ctx );
  74. memset( key, 0, sizeof( key ) );
  75. memset( msg, 0, sizeof( msg ) );
  76. memset( iv, 0, sizeof( iv ) );
  77. memset( add, 0, sizeof( add ) );
  78. memset( out, 0, sizeof( out ) );
  79. memset( tag, 0, sizeof( tag ) );
  80. TEST_ASSERT( mbedtls_ccm_setkey( &ctx, MBEDTLS_CIPHER_ID_AES,
  81. key, 8 * sizeof( key ) ) == 0 );
  82. TEST_ASSERT( mbedtls_ccm_star_encrypt_and_tag( &ctx, msg_len, iv, iv_len,
  83. add, add_len, msg, out, tag, tag_len ) == res );
  84. decrypt_ret = mbedtls_ccm_star_auth_decrypt( &ctx, msg_len, iv, iv_len, add,
  85. add_len, msg, out, tag, tag_len );
  86. if( res == 0 && tag_len != 0 )
  87. TEST_ASSERT( decrypt_ret == MBEDTLS_ERR_CCM_AUTH_FAILED );
  88. else
  89. TEST_ASSERT( decrypt_ret == res );
  90. exit:
  91. mbedtls_ccm_free( &ctx );
  92. }
  93. /* END_CASE */
  94. /* BEGIN_CASE */
  95. void mbedtls_ccm_encrypt_and_tag( int cipher_id, data_t * key,
  96. data_t * msg, data_t * iv,
  97. data_t * add, data_t * result )
  98. {
  99. mbedtls_ccm_context ctx;
  100. size_t tag_len;
  101. uint8_t * msg_n_tag = (uint8_t *)malloc( result->len + 2 );
  102. mbedtls_ccm_init( &ctx );
  103. memset( msg_n_tag, 0, result->len + 2 );
  104. memcpy( msg_n_tag, msg->x, msg->len );
  105. tag_len = result->len - msg->len;
  106. TEST_ASSERT( mbedtls_ccm_setkey( &ctx, cipher_id, key->x, key->len * 8 ) == 0 );
  107. /* Test with input == output */
  108. TEST_ASSERT( mbedtls_ccm_encrypt_and_tag( &ctx, msg->len, iv->x, iv->len, add->x, add->len,
  109. msg_n_tag, msg_n_tag, msg_n_tag + msg->len, tag_len ) == 0 );
  110. TEST_ASSERT( memcmp( msg_n_tag, result->x, result->len ) == 0 );
  111. /* Check we didn't write past the end */
  112. TEST_ASSERT( msg_n_tag[result->len] == 0 && msg_n_tag[result->len + 1] == 0 );
  113. exit:
  114. mbedtls_ccm_free( &ctx );
  115. free( msg_n_tag );
  116. }
  117. /* END_CASE */
  118. /* BEGIN_CASE */
  119. void mbedtls_ccm_auth_decrypt( int cipher_id, data_t * key,
  120. data_t * msg, data_t * iv,
  121. data_t * add, int tag_len, int result,
  122. data_t * expected_msg )
  123. {
  124. unsigned char tag[16];
  125. mbedtls_ccm_context ctx;
  126. mbedtls_ccm_init( &ctx );
  127. memset( tag, 0x00, sizeof( tag ) );
  128. msg->len -= tag_len;
  129. memcpy( tag, msg->x + msg->len, tag_len );
  130. TEST_ASSERT( mbedtls_ccm_setkey( &ctx, cipher_id, key->x, key->len * 8 ) == 0 );
  131. /* Test with input == output */
  132. TEST_ASSERT( mbedtls_ccm_auth_decrypt( &ctx, msg->len, iv->x, iv->len, add->x, add->len,
  133. msg->x, msg->x, msg->x + msg->len, tag_len ) == result );
  134. if( result == 0 )
  135. {
  136. TEST_ASSERT( memcmp( msg->x, expected_msg->x, expected_msg->len ) == 0 );
  137. }
  138. else
  139. {
  140. size_t i;
  141. for( i = 0; i < msg->len; i++ )
  142. TEST_ASSERT( msg->x[i] == 0 );
  143. }
  144. /* Check we didn't write past the end (where the original tag is) */
  145. TEST_ASSERT( memcmp( msg->x + msg->len, tag, tag_len ) == 0 );
  146. exit:
  147. mbedtls_ccm_free( &ctx );
  148. }
  149. /* END_CASE */
  150. /* BEGIN_CASE */
  151. void mbedtls_ccm_star_encrypt_and_tag( int cipher_id,
  152. data_t *key, data_t *msg,
  153. data_t *source_address, data_t *frame_counter,
  154. int sec_level, data_t *add,
  155. data_t *expected_result, int output_ret )
  156. {
  157. unsigned char iv[13];
  158. unsigned char result[50];
  159. mbedtls_ccm_context ctx;
  160. size_t iv_len, tag_len;
  161. int ret;
  162. mbedtls_ccm_init( &ctx );
  163. memset( result, 0x00, sizeof( result ) );
  164. if( sec_level % 4 == 0)
  165. tag_len = 0;
  166. else
  167. tag_len = 1 << ( sec_level % 4 + 1);
  168. TEST_ASSERT( source_address->len == 8 );
  169. TEST_ASSERT( frame_counter->len == 4 );
  170. memcpy( iv, source_address->x, source_address->len );
  171. memcpy( iv + source_address->len, frame_counter->x, frame_counter->len );
  172. iv[source_address->len + frame_counter->len] = sec_level;
  173. iv_len = sizeof( iv );
  174. TEST_ASSERT( mbedtls_ccm_setkey( &ctx, cipher_id,
  175. key->x, key->len * 8 ) == 0 );
  176. ret = mbedtls_ccm_star_encrypt_and_tag( &ctx, msg->len, iv, iv_len,
  177. add->x, add->len, msg->x,
  178. result, result + msg->len, tag_len );
  179. TEST_ASSERT( ret == output_ret );
  180. TEST_ASSERT( memcmp( result,
  181. expected_result->x, expected_result->len ) == 0 );
  182. /* Check we didn't write past the end */
  183. TEST_ASSERT( result[expected_result->len] == 0 &&
  184. result[expected_result->len + 1] == 0 );
  185. exit:
  186. mbedtls_ccm_free( &ctx );
  187. }
  188. /* END_CASE */
  189. /* BEGIN_CASE */
  190. void mbedtls_ccm_star_auth_decrypt( int cipher_id,
  191. data_t *key, data_t *msg,
  192. data_t *source_address, data_t *frame_counter,
  193. int sec_level, data_t *add,
  194. data_t *expected_result, int output_ret )
  195. {
  196. unsigned char iv[13];
  197. unsigned char result[50];
  198. mbedtls_ccm_context ctx;
  199. size_t iv_len, tag_len;
  200. int ret;
  201. mbedtls_ccm_init( &ctx );
  202. memset( iv, 0x00, sizeof( iv ) );
  203. memset( result, '+', sizeof( result ) );
  204. if( sec_level % 4 == 0)
  205. tag_len = 0;
  206. else
  207. tag_len = 1 << ( sec_level % 4 + 1);
  208. TEST_ASSERT( source_address->len == 8 );
  209. TEST_ASSERT( frame_counter->len == 4 );
  210. memcpy( iv, source_address->x, source_address->len );
  211. memcpy( iv + source_address->len, frame_counter->x, frame_counter->len );
  212. iv[source_address->len + frame_counter->len] = sec_level;
  213. iv_len = sizeof( iv );
  214. TEST_ASSERT( mbedtls_ccm_setkey( &ctx, cipher_id, key->x, key->len * 8 ) == 0 );
  215. ret = mbedtls_ccm_star_auth_decrypt( &ctx, msg->len - tag_len, iv, iv_len,
  216. add->x, add->len, msg->x, result,
  217. msg->x + msg->len - tag_len, tag_len );
  218. TEST_ASSERT( ret == output_ret );
  219. TEST_ASSERT( memcmp( result, expected_result->x,
  220. expected_result->len ) == 0 );
  221. /* Check we didn't write past the end (where the original tag is) */
  222. TEST_ASSERT( ( msg->len + 2 ) <= sizeof( result ) );
  223. TEST_ASSERT( result[msg->len] == '+' );
  224. TEST_ASSERT( result[msg->len + 1] == '+' );
  225. exit:
  226. mbedtls_ccm_free( &ctx );
  227. }
  228. /* END_CASE */
  229. /* BEGIN_CASE depends_on:MBEDTLS_CHECK_PARAMS:!MBEDTLS_PARAM_FAILED_ALT */
  230. void ccm_invalid_param( )
  231. {
  232. struct mbedtls_ccm_context ctx;
  233. unsigned char valid_buffer[] = { 0x01, 0x02, 0x03, 0x04, 0x05, 0x06 };
  234. mbedtls_cipher_id_t valid_cipher = MBEDTLS_CIPHER_ID_AES;
  235. int valid_len = sizeof(valid_buffer);
  236. int valid_bitlen = valid_len * 8;
  237. mbedtls_ccm_init( &ctx );
  238. /* mbedtls_ccm_init() */
  239. TEST_INVALID_PARAM( mbedtls_ccm_init( NULL ) );
  240. /* mbedtls_ccm_setkey() */
  241. TEST_INVALID_PARAM_RET(
  242. MBEDTLS_ERR_CCM_BAD_INPUT,
  243. mbedtls_ccm_setkey( NULL, valid_cipher, valid_buffer, valid_bitlen ) );
  244. TEST_INVALID_PARAM_RET(
  245. MBEDTLS_ERR_CCM_BAD_INPUT,
  246. mbedtls_ccm_setkey( &ctx, valid_cipher, NULL, valid_bitlen ) );
  247. /* mbedtls_ccm_encrypt_and_tag() */
  248. TEST_INVALID_PARAM_RET(
  249. MBEDTLS_ERR_CCM_BAD_INPUT,
  250. mbedtls_ccm_encrypt_and_tag( NULL, valid_len,
  251. valid_buffer, valid_len,
  252. valid_buffer, valid_len,
  253. valid_buffer, valid_buffer,
  254. valid_buffer, valid_len ) );
  255. TEST_INVALID_PARAM_RET(
  256. MBEDTLS_ERR_CCM_BAD_INPUT,
  257. mbedtls_ccm_encrypt_and_tag( &ctx, valid_len,
  258. NULL, valid_len,
  259. valid_buffer, valid_len,
  260. valid_buffer, valid_buffer,
  261. valid_buffer, valid_len ) );
  262. TEST_INVALID_PARAM_RET(
  263. MBEDTLS_ERR_CCM_BAD_INPUT,
  264. mbedtls_ccm_encrypt_and_tag( &ctx, valid_len,
  265. valid_buffer, valid_len,
  266. NULL, valid_len,
  267. valid_buffer, valid_buffer,
  268. valid_buffer, valid_len ) );
  269. TEST_INVALID_PARAM_RET(
  270. MBEDTLS_ERR_CCM_BAD_INPUT,
  271. mbedtls_ccm_encrypt_and_tag( &ctx, valid_len,
  272. valid_buffer, valid_len,
  273. valid_buffer, valid_len,
  274. NULL, valid_buffer,
  275. valid_buffer, valid_len ) );
  276. TEST_INVALID_PARAM_RET(
  277. MBEDTLS_ERR_CCM_BAD_INPUT,
  278. mbedtls_ccm_encrypt_and_tag( &ctx, valid_len,
  279. valid_buffer, valid_len,
  280. valid_buffer, valid_len,
  281. valid_buffer, NULL,
  282. valid_buffer, valid_len ) );
  283. TEST_INVALID_PARAM_RET(
  284. MBEDTLS_ERR_CCM_BAD_INPUT,
  285. mbedtls_ccm_encrypt_and_tag( &ctx, valid_len,
  286. valid_buffer, valid_len,
  287. valid_buffer, valid_len,
  288. valid_buffer, valid_buffer,
  289. NULL, valid_len ) );
  290. /* mbedtls_ccm_star_encrypt_and_tag() */
  291. TEST_INVALID_PARAM_RET(
  292. MBEDTLS_ERR_CCM_BAD_INPUT,
  293. mbedtls_ccm_star_encrypt_and_tag( NULL, valid_len,
  294. valid_buffer, valid_len,
  295. valid_buffer, valid_len,
  296. valid_buffer, valid_buffer,
  297. valid_buffer, valid_len) );
  298. TEST_INVALID_PARAM_RET(
  299. MBEDTLS_ERR_CCM_BAD_INPUT,
  300. mbedtls_ccm_star_encrypt_and_tag( &ctx, valid_len,
  301. NULL, valid_len,
  302. valid_buffer, valid_len,
  303. valid_buffer, valid_buffer,
  304. valid_buffer, valid_len ) );
  305. TEST_INVALID_PARAM_RET(
  306. MBEDTLS_ERR_CCM_BAD_INPUT,
  307. mbedtls_ccm_star_encrypt_and_tag( &ctx, valid_len,
  308. valid_buffer, valid_len,
  309. NULL, valid_len,
  310. valid_buffer, valid_buffer,
  311. valid_buffer, valid_len ) );
  312. TEST_INVALID_PARAM_RET(
  313. MBEDTLS_ERR_CCM_BAD_INPUT,
  314. mbedtls_ccm_star_encrypt_and_tag( &ctx, valid_len,
  315. valid_buffer, valid_len,
  316. valid_buffer, valid_len,
  317. NULL, valid_buffer,
  318. valid_buffer, valid_len ) );
  319. TEST_INVALID_PARAM_RET(
  320. MBEDTLS_ERR_CCM_BAD_INPUT,
  321. mbedtls_ccm_star_encrypt_and_tag( &ctx, valid_len,
  322. valid_buffer, valid_len,
  323. valid_buffer, valid_len,
  324. valid_buffer, NULL,
  325. valid_buffer, valid_len ) );
  326. TEST_INVALID_PARAM_RET(
  327. MBEDTLS_ERR_CCM_BAD_INPUT,
  328. mbedtls_ccm_star_encrypt_and_tag( &ctx, valid_len,
  329. valid_buffer, valid_len,
  330. valid_buffer, valid_len,
  331. valid_buffer, valid_buffer,
  332. NULL, valid_len ) );
  333. /* mbedtls_ccm_auth_decrypt() */
  334. TEST_INVALID_PARAM_RET(
  335. MBEDTLS_ERR_CCM_BAD_INPUT,
  336. mbedtls_ccm_auth_decrypt( NULL, valid_len,
  337. valid_buffer, valid_len,
  338. valid_buffer, valid_len,
  339. valid_buffer, valid_buffer,
  340. valid_buffer, valid_len ) );
  341. TEST_INVALID_PARAM_RET(
  342. MBEDTLS_ERR_CCM_BAD_INPUT,
  343. mbedtls_ccm_auth_decrypt( &ctx, valid_len,
  344. NULL, valid_len,
  345. valid_buffer, valid_len,
  346. valid_buffer, valid_buffer,
  347. valid_buffer, valid_len ) );
  348. TEST_INVALID_PARAM_RET(
  349. MBEDTLS_ERR_CCM_BAD_INPUT,
  350. mbedtls_ccm_auth_decrypt( &ctx, valid_len,
  351. valid_buffer, valid_len,
  352. NULL, valid_len,
  353. valid_buffer, valid_buffer,
  354. valid_buffer, valid_len ) );
  355. TEST_INVALID_PARAM_RET(
  356. MBEDTLS_ERR_CCM_BAD_INPUT,
  357. mbedtls_ccm_auth_decrypt( &ctx, valid_len,
  358. valid_buffer, valid_len,
  359. valid_buffer, valid_len,
  360. NULL, valid_buffer,
  361. valid_buffer, valid_len ) );
  362. TEST_INVALID_PARAM_RET(
  363. MBEDTLS_ERR_CCM_BAD_INPUT,
  364. mbedtls_ccm_auth_decrypt( &ctx, valid_len,
  365. valid_buffer, valid_len,
  366. valid_buffer, valid_len,
  367. valid_buffer, NULL,
  368. valid_buffer, valid_len ) );
  369. TEST_INVALID_PARAM_RET(
  370. MBEDTLS_ERR_CCM_BAD_INPUT,
  371. mbedtls_ccm_auth_decrypt( &ctx, valid_len,
  372. valid_buffer, valid_len,
  373. valid_buffer, valid_len,
  374. valid_buffer, valid_buffer,
  375. NULL, valid_len ) );
  376. /* mbedtls_ccm_star_auth_decrypt() */
  377. TEST_INVALID_PARAM_RET(
  378. MBEDTLS_ERR_CCM_BAD_INPUT,
  379. mbedtls_ccm_star_auth_decrypt( NULL, valid_len,
  380. valid_buffer, valid_len,
  381. valid_buffer, valid_len,
  382. valid_buffer, valid_buffer,
  383. valid_buffer, valid_len ) );
  384. TEST_INVALID_PARAM_RET(
  385. MBEDTLS_ERR_CCM_BAD_INPUT,
  386. mbedtls_ccm_star_auth_decrypt( &ctx, valid_len,
  387. NULL, valid_len,
  388. valid_buffer, valid_len,
  389. valid_buffer, valid_buffer,
  390. valid_buffer, valid_len ) );
  391. TEST_INVALID_PARAM_RET(
  392. MBEDTLS_ERR_CCM_BAD_INPUT,
  393. mbedtls_ccm_star_auth_decrypt( &ctx, valid_len,
  394. valid_buffer, valid_len,
  395. NULL, valid_len,
  396. valid_buffer, valid_buffer,
  397. valid_buffer, valid_len ) );
  398. TEST_INVALID_PARAM_RET(
  399. MBEDTLS_ERR_CCM_BAD_INPUT,
  400. mbedtls_ccm_star_auth_decrypt( &ctx, valid_len,
  401. valid_buffer, valid_len,
  402. valid_buffer, valid_len,
  403. NULL, valid_buffer,
  404. valid_buffer, valid_len ) );
  405. TEST_INVALID_PARAM_RET(
  406. MBEDTLS_ERR_CCM_BAD_INPUT,
  407. mbedtls_ccm_star_auth_decrypt( &ctx, valid_len,
  408. valid_buffer, valid_len,
  409. valid_buffer, valid_len,
  410. valid_buffer, NULL,
  411. valid_buffer, valid_len ) );
  412. TEST_INVALID_PARAM_RET(
  413. MBEDTLS_ERR_CCM_BAD_INPUT,
  414. mbedtls_ccm_star_auth_decrypt( &ctx, valid_len,
  415. valid_buffer, valid_len,
  416. valid_buffer, valid_len,
  417. valid_buffer, valid_buffer,
  418. NULL, valid_len ) );
  419. exit:
  420. mbedtls_ccm_free( &ctx );
  421. return;
  422. }
  423. /* END_CASE */
  424. /* BEGIN_CASE */
  425. void ccm_valid_param( )
  426. {
  427. TEST_VALID_PARAM( mbedtls_ccm_free( NULL ) );
  428. exit:
  429. return;
  430. }
  431. /* END_CASE */