igetest.c revision 1.1.1.2 1 1.1.1.2 christos /*
2 1.1.1.2 christos * Copyright 2006-2017 The OpenSSL Project Authors. All Rights Reserved.
3 1.1 christos *
4 1.1.1.2 christos * Licensed under the OpenSSL license (the "License"). You may not use
5 1.1.1.2 christos * this file except in compliance with the License. You can obtain a copy
6 1.1.1.2 christos * in the file LICENSE in the source distribution or at
7 1.1.1.2 christos * https://www.openssl.org/source/license.html
8 1.1 christos */
9 1.1 christos
10 1.1.1.2 christos #include <openssl/crypto.h>
11 1.1 christos #include <openssl/aes.h>
12 1.1 christos #include <openssl/rand.h>
13 1.1 christos #include <stdio.h>
14 1.1 christos #include <string.h>
15 1.1.1.2 christos #include "internal/nelem.h"
16 1.1.1.2 christos #include "testutil.h"
17 1.1 christos
18 1.1 christos #define TEST_SIZE 128
19 1.1 christos #define BIG_TEST_SIZE 10240
20 1.1 christos
21 1.1.1.2 christos #if BIG_TEST_SIZE < TEST_SIZE
22 1.1.1.2 christos #error BIG_TEST_SIZE is smaller than TEST_SIZE
23 1.1.1.2 christos #endif
24 1.1.1.2 christos
25 1.1.1.2 christos static unsigned char rkey[16];
26 1.1.1.2 christos static unsigned char rkey2[16];
27 1.1.1.2 christos static unsigned char plaintext[BIG_TEST_SIZE];
28 1.1.1.2 christos static unsigned char saved_iv[AES_BLOCK_SIZE * 4];
29 1.1 christos
30 1.1 christos #define MAX_VECTOR_SIZE 64
31 1.1 christos
32 1.1 christos struct ige_test {
33 1.1 christos const unsigned char key[16];
34 1.1 christos const unsigned char iv[32];
35 1.1 christos const unsigned char in[MAX_VECTOR_SIZE];
36 1.1 christos const unsigned char out[MAX_VECTOR_SIZE];
37 1.1 christos const size_t length;
38 1.1 christos const int encrypt;
39 1.1 christos };
40 1.1 christos
41 1.1 christos static struct ige_test const ige_test_vectors[] = {
42 1.1 christos {{0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
43 1.1 christos 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f}, /* key */
44 1.1 christos {0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
45 1.1 christos 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
46 1.1 christos 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,
47 1.1 christos 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f}, /* iv */
48 1.1 christos {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
49 1.1 christos 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
50 1.1 christos 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
51 1.1 christos 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}, /* in */
52 1.1 christos {0x1a, 0x85, 0x19, 0xa6, 0x55, 0x7b, 0xe6, 0x52,
53 1.1 christos 0xe9, 0xda, 0x8e, 0x43, 0xda, 0x4e, 0xf4, 0x45,
54 1.1 christos 0x3c, 0xf4, 0x56, 0xb4, 0xca, 0x48, 0x8a, 0xa3,
55 1.1 christos 0x83, 0xc7, 0x9c, 0x98, 0xb3, 0x47, 0x97, 0xcb}, /* out */
56 1.1 christos 32, AES_ENCRYPT}, /* test vector 0 */
57 1.1 christos
58 1.1 christos {{0x54, 0x68, 0x69, 0x73, 0x20, 0x69, 0x73, 0x20,
59 1.1 christos 0x61, 0x6e, 0x20, 0x69, 0x6d, 0x70, 0x6c, 0x65}, /* key */
60 1.1 christos {0x6d, 0x65, 0x6e, 0x74, 0x61, 0x74, 0x69, 0x6f,
61 1.1 christos 0x6e, 0x20, 0x6f, 0x66, 0x20, 0x49, 0x47, 0x45,
62 1.1 christos 0x20, 0x6d, 0x6f, 0x64, 0x65, 0x20, 0x66, 0x6f,
63 1.1 christos 0x72, 0x20, 0x4f, 0x70, 0x65, 0x6e, 0x53, 0x53}, /* iv */
64 1.1 christos {0x4c, 0x2e, 0x20, 0x4c, 0x65, 0x74, 0x27, 0x73,
65 1.1 christos 0x20, 0x68, 0x6f, 0x70, 0x65, 0x20, 0x42, 0x65,
66 1.1 christos 0x6e, 0x20, 0x67, 0x6f, 0x74, 0x20, 0x69, 0x74,
67 1.1 christos 0x20, 0x72, 0x69, 0x67, 0x68, 0x74, 0x21, 0x0a}, /* in */
68 1.1 christos {0x99, 0x70, 0x64, 0x87, 0xa1, 0xcd, 0xe6, 0x13,
69 1.1 christos 0xbc, 0x6d, 0xe0, 0xb6, 0xf2, 0x4b, 0x1c, 0x7a,
70 1.1 christos 0xa4, 0x48, 0xc8, 0xb9, 0xc3, 0x40, 0x3e, 0x34,
71 1.1 christos 0x67, 0xa8, 0xca, 0xd8, 0x93, 0x40, 0xf5, 0x3b}, /* out */
72 1.1 christos 32, AES_DECRYPT}, /* test vector 1 */
73 1.1 christos };
74 1.1 christos
75 1.1 christos struct bi_ige_test {
76 1.1 christos const unsigned char key1[32];
77 1.1 christos const unsigned char key2[32];
78 1.1 christos const unsigned char iv[64];
79 1.1 christos const unsigned char in[MAX_VECTOR_SIZE];
80 1.1 christos const unsigned char out[MAX_VECTOR_SIZE];
81 1.1 christos const size_t keysize;
82 1.1 christos const size_t length;
83 1.1 christos const int encrypt;
84 1.1 christos };
85 1.1 christos
86 1.1 christos static struct bi_ige_test const bi_ige_test_vectors[] = {
87 1.1 christos {{0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
88 1.1 christos 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f}, /* key1 */
89 1.1 christos {0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,
90 1.1 christos 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f}, /* key2 */
91 1.1 christos {0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
92 1.1 christos 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
93 1.1 christos 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,
94 1.1 christos 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f,
95 1.1 christos 0x20, 0x21, 0x22, 0x23, 0x24, 0x25, 0x26, 0x27,
96 1.1 christos 0x28, 0x29, 0x2a, 0x2b, 0x2c, 0x2d, 0x2e, 0x2f,
97 1.1 christos 0x30, 0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37,
98 1.1 christos 0x38, 0x39, 0x3a, 0x3b, 0x3c, 0x3d, 0x3e, 0x3f}, /* iv */
99 1.1 christos {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
100 1.1 christos 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
101 1.1 christos 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
102 1.1 christos 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}, /* in */
103 1.1 christos {0x14, 0x40, 0x6f, 0xae, 0xa2, 0x79, 0xf2, 0x56,
104 1.1 christos 0x1f, 0x86, 0xeb, 0x3b, 0x7d, 0xff, 0x53, 0xdc,
105 1.1 christos 0x4e, 0x27, 0x0c, 0x03, 0xde, 0x7c, 0xe5, 0x16,
106 1.1 christos 0x6a, 0x9c, 0x20, 0x33, 0x9d, 0x33, 0xfe, 0x12}, /* out */
107 1.1 christos 16, 32, AES_ENCRYPT}, /* test vector 0 */
108 1.1 christos {{0x58, 0x0a, 0x06, 0xe9, 0x97, 0x07, 0x59, 0x5c,
109 1.1 christos 0x9e, 0x19, 0xd2, 0xa7, 0xbb, 0x40, 0x2b, 0x7a,
110 1.1 christos 0xc7, 0xd8, 0x11, 0x9e, 0x4c, 0x51, 0x35, 0x75,
111 1.1 christos 0x64, 0x28, 0x0f, 0x23, 0xad, 0x74, 0xac, 0x37}, /* key1 */
112 1.1 christos {0xd1, 0x80, 0xa0, 0x31, 0x47, 0xa3, 0x11, 0x13,
113 1.1 christos 0x86, 0x26, 0x9e, 0x6d, 0xff, 0xaf, 0x72, 0x74,
114 1.1 christos 0x5b, 0xa2, 0x35, 0x81, 0xd2, 0xa6, 0x3d, 0x21,
115 1.1 christos 0x67, 0x7b, 0x58, 0xa8, 0x18, 0xf9, 0x72, 0xe4}, /* key2 */
116 1.1 christos {0x80, 0x3d, 0xbd, 0x4c, 0xe6, 0x7b, 0x06, 0xa9,
117 1.1 christos 0x53, 0x35, 0xd5, 0x7e, 0x71, 0xc1, 0x70, 0x70,
118 1.1 christos 0x74, 0x9a, 0x00, 0x28, 0x0c, 0xbf, 0x6c, 0x42,
119 1.1 christos 0x9b, 0xa4, 0xdd, 0x65, 0x11, 0x77, 0x7c, 0x67,
120 1.1 christos 0xfe, 0x76, 0x0a, 0xf0, 0xd5, 0xc6, 0x6e, 0x6a,
121 1.1 christos 0xe7, 0x5e, 0x4c, 0xf2, 0x7e, 0x9e, 0xf9, 0x20,
122 1.1 christos 0x0e, 0x54, 0x6f, 0x2d, 0x8a, 0x8d, 0x7e, 0xbd,
123 1.1 christos 0x48, 0x79, 0x37, 0x99, 0xff, 0x27, 0x93, 0xa3}, /* iv */
124 1.1 christos {0xf1, 0x54, 0x3d, 0xca, 0xfe, 0xb5, 0xef, 0x1c,
125 1.1 christos 0x4f, 0xa6, 0x43, 0xf6, 0xe6, 0x48, 0x57, 0xf0,
126 1.1 christos 0xee, 0x15, 0x7f, 0xe3, 0xe7, 0x2f, 0xd0, 0x2f,
127 1.1 christos 0x11, 0x95, 0x7a, 0x17, 0x00, 0xab, 0xa7, 0x0b,
128 1.1 christos 0xbe, 0x44, 0x09, 0x9c, 0xcd, 0xac, 0xa8, 0x52,
129 1.1 christos 0xa1, 0x8e, 0x7b, 0x75, 0xbc, 0xa4, 0x92, 0x5a,
130 1.1 christos 0xab, 0x46, 0xd3, 0x3a, 0xa0, 0xd5, 0x35, 0x1c,
131 1.1 christos 0x55, 0xa4, 0xb3, 0xa8, 0x40, 0x81, 0xa5, 0x0b}, /* in */
132 1.1 christos {0x42, 0xe5, 0x28, 0x30, 0x31, 0xc2, 0xa0, 0x23,
133 1.1 christos 0x68, 0x49, 0x4e, 0xb3, 0x24, 0x59, 0x92, 0x79,
134 1.1 christos 0xc1, 0xa5, 0xcc, 0xe6, 0x76, 0x53, 0xb1, 0xcf,
135 1.1 christos 0x20, 0x86, 0x23, 0xe8, 0x72, 0x55, 0x99, 0x92,
136 1.1 christos 0x0d, 0x16, 0x1c, 0x5a, 0x2f, 0xce, 0xcb, 0x51,
137 1.1 christos 0xe2, 0x67, 0xfa, 0x10, 0xec, 0xcd, 0x3d, 0x67,
138 1.1 christos 0xa5, 0xe6, 0xf7, 0x31, 0x26, 0xb0, 0x0d, 0x76,
139 1.1 christos 0x5e, 0x28, 0xdc, 0x7f, 0x01, 0xc5, 0xa5, 0x4c}, /* out */
140 1.1 christos 32, 64, AES_ENCRYPT}, /* test vector 1 */
141 1.1 christos
142 1.1 christos };
143 1.1 christos
144 1.1.1.2 christos static int test_ige_vectors(int n)
145 1.1 christos {
146 1.1.1.2 christos const struct ige_test *const v = &ige_test_vectors[n];
147 1.1.1.2 christos AES_KEY key;
148 1.1.1.2 christos unsigned char buf[MAX_VECTOR_SIZE];
149 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 2];
150 1.1.1.2 christos int testresult = 1;
151 1.1.1.2 christos
152 1.1.1.2 christos if (!TEST_int_le(v->length, MAX_VECTOR_SIZE))
153 1.1.1.2 christos return 0;
154 1.1.1.2 christos
155 1.1.1.2 christos if (v->encrypt == AES_ENCRYPT)
156 1.1.1.2 christos AES_set_encrypt_key(v->key, 8 * sizeof(v->key), &key);
157 1.1.1.2 christos else
158 1.1.1.2 christos AES_set_decrypt_key(v->key, 8 * sizeof(v->key), &key);
159 1.1.1.2 christos memcpy(iv, v->iv, sizeof(iv));
160 1.1.1.2 christos AES_ige_encrypt(v->in, buf, v->length, &key, iv, v->encrypt);
161 1.1.1.2 christos
162 1.1.1.2 christos if (!TEST_mem_eq(v->out, v->length, buf, v->length)) {
163 1.1.1.2 christos TEST_info("IGE test vector %d failed", n);
164 1.1.1.2 christos test_output_memory("key", v->key, sizeof(v->key));
165 1.1.1.2 christos test_output_memory("iv", v->iv, sizeof(v->iv));
166 1.1.1.2 christos test_output_memory("in", v->in, v->length);
167 1.1.1.2 christos testresult = 0;
168 1.1.1.2 christos }
169 1.1.1.2 christos
170 1.1.1.2 christos /* try with in == out */
171 1.1.1.2 christos memcpy(iv, v->iv, sizeof(iv));
172 1.1.1.2 christos memcpy(buf, v->in, v->length);
173 1.1.1.2 christos AES_ige_encrypt(buf, buf, v->length, &key, iv, v->encrypt);
174 1.1.1.2 christos
175 1.1.1.2 christos if (!TEST_mem_eq(v->out, v->length, buf, v->length)) {
176 1.1.1.2 christos TEST_info("IGE test vector %d failed (with in == out)", n);
177 1.1.1.2 christos test_output_memory("key", v->key, sizeof(v->key));
178 1.1.1.2 christos test_output_memory("iv", v->iv, sizeof(v->iv));
179 1.1.1.2 christos test_output_memory("in", v->in, v->length);
180 1.1.1.2 christos testresult = 0;
181 1.1.1.2 christos }
182 1.1 christos
183 1.1.1.2 christos return testresult;
184 1.1.1.2 christos }
185 1.1 christos
186 1.1.1.2 christos static int test_bi_ige_vectors(int n)
187 1.1.1.2 christos {
188 1.1.1.2 christos const struct bi_ige_test *const v = &bi_ige_test_vectors[n];
189 1.1.1.2 christos AES_KEY key1;
190 1.1.1.2 christos AES_KEY key2;
191 1.1.1.2 christos unsigned char buf[MAX_VECTOR_SIZE];
192 1.1.1.2 christos
193 1.1.1.2 christos if (!TEST_int_le(v->length, MAX_VECTOR_SIZE))
194 1.1.1.2 christos return 0;
195 1.1.1.2 christos
196 1.1.1.2 christos if (v->encrypt == AES_ENCRYPT) {
197 1.1.1.2 christos AES_set_encrypt_key(v->key1, 8 * v->keysize, &key1);
198 1.1.1.2 christos AES_set_encrypt_key(v->key2, 8 * v->keysize, &key2);
199 1.1.1.2 christos } else {
200 1.1.1.2 christos AES_set_decrypt_key(v->key1, 8 * v->keysize, &key1);
201 1.1.1.2 christos AES_set_decrypt_key(v->key2, 8 * v->keysize, &key2);
202 1.1 christos }
203 1.1 christos
204 1.1.1.2 christos AES_bi_ige_encrypt(v->in, buf, v->length, &key1, &key2, v->iv,
205 1.1.1.2 christos v->encrypt);
206 1.1 christos
207 1.1.1.2 christos if (!TEST_mem_eq(v->out, v->length, buf, v->length)) {
208 1.1.1.2 christos test_output_memory("key 1", v->key1, sizeof(v->key1));
209 1.1.1.2 christos test_output_memory("key 2", v->key2, sizeof(v->key2));
210 1.1.1.2 christos test_output_memory("iv", v->iv, sizeof(v->iv));
211 1.1.1.2 christos test_output_memory("in", v->in, v->length);
212 1.1.1.2 christos return 0;
213 1.1 christos }
214 1.1 christos
215 1.1.1.2 christos return 1;
216 1.1 christos }
217 1.1 christos
218 1.1.1.2 christos static int test_ige_enc_dec(void)
219 1.1 christos {
220 1.1 christos AES_KEY key;
221 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 4];
222 1.1 christos unsigned char ciphertext[BIG_TEST_SIZE];
223 1.1 christos unsigned char checktext[BIG_TEST_SIZE];
224 1.1 christos
225 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
226 1.1.1.2 christos AES_set_encrypt_key(rkey, 8 * sizeof(rkey), &key);
227 1.1 christos AES_ige_encrypt(plaintext, ciphertext, TEST_SIZE, &key, iv, AES_ENCRYPT);
228 1.1 christos
229 1.1.1.2 christos AES_set_decrypt_key(rkey, 8 * sizeof(rkey), &key);
230 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
231 1.1 christos AES_ige_encrypt(ciphertext, checktext, TEST_SIZE, &key, iv, AES_DECRYPT);
232 1.1 christos
233 1.1.1.2 christos return TEST_mem_eq(checktext, TEST_SIZE, plaintext, TEST_SIZE);
234 1.1.1.2 christos }
235 1.1.1.2 christos
236 1.1.1.2 christos static int test_ige_enc_chaining(void)
237 1.1.1.2 christos {
238 1.1.1.2 christos AES_KEY key;
239 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 4];
240 1.1.1.2 christos unsigned char ciphertext[BIG_TEST_SIZE];
241 1.1.1.2 christos unsigned char checktext[BIG_TEST_SIZE];
242 1.1 christos
243 1.1.1.2 christos AES_set_encrypt_key(rkey, 8 * sizeof(rkey), &key);
244 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
245 1.1 christos AES_ige_encrypt(plaintext, ciphertext, TEST_SIZE / 2, &key, iv,
246 1.1 christos AES_ENCRYPT);
247 1.1 christos AES_ige_encrypt(plaintext + TEST_SIZE / 2,
248 1.1 christos ciphertext + TEST_SIZE / 2, TEST_SIZE / 2,
249 1.1 christos &key, iv, AES_ENCRYPT);
250 1.1 christos
251 1.1.1.2 christos AES_set_decrypt_key(rkey, 8 * sizeof(rkey), &key);
252 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
253 1.1 christos AES_ige_encrypt(ciphertext, checktext, TEST_SIZE, &key, iv, AES_DECRYPT);
254 1.1 christos
255 1.1.1.2 christos return TEST_mem_eq(checktext, TEST_SIZE, plaintext, TEST_SIZE);
256 1.1.1.2 christos }
257 1.1 christos
258 1.1.1.2 christos static int test_ige_dec_chaining(void)
259 1.1.1.2 christos {
260 1.1.1.2 christos AES_KEY key;
261 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 4];
262 1.1.1.2 christos unsigned char ciphertext[BIG_TEST_SIZE];
263 1.1.1.2 christos unsigned char checktext[BIG_TEST_SIZE];
264 1.1.1.2 christos
265 1.1.1.2 christos AES_set_encrypt_key(rkey, 8 * sizeof(rkey), &key);
266 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
267 1.1 christos AES_ige_encrypt(plaintext, ciphertext, TEST_SIZE / 2, &key, iv,
268 1.1 christos AES_ENCRYPT);
269 1.1 christos AES_ige_encrypt(plaintext + TEST_SIZE / 2,
270 1.1 christos ciphertext + TEST_SIZE / 2, TEST_SIZE / 2,
271 1.1 christos &key, iv, AES_ENCRYPT);
272 1.1 christos
273 1.1.1.2 christos AES_set_decrypt_key(rkey, 8 * sizeof(rkey), &key);
274 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
275 1.1 christos AES_ige_encrypt(ciphertext, checktext, TEST_SIZE / 2, &key, iv,
276 1.1 christos AES_DECRYPT);
277 1.1 christos AES_ige_encrypt(ciphertext + TEST_SIZE / 2,
278 1.1 christos checktext + TEST_SIZE / 2, TEST_SIZE / 2, &key, iv,
279 1.1 christos AES_DECRYPT);
280 1.1 christos
281 1.1.1.2 christos return TEST_mem_eq(checktext, TEST_SIZE, plaintext, TEST_SIZE);
282 1.1.1.2 christos }
283 1.1 christos
284 1.1.1.2 christos static int test_ige_garble_forwards(void)
285 1.1.1.2 christos {
286 1.1.1.2 christos AES_KEY key;
287 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 4];
288 1.1.1.2 christos unsigned char ciphertext[BIG_TEST_SIZE];
289 1.1.1.2 christos unsigned char checktext[BIG_TEST_SIZE];
290 1.1.1.2 christos unsigned int n;
291 1.1.1.2 christos int testresult = 1;
292 1.1.1.2 christos const size_t ctsize = sizeof(checktext);
293 1.1.1.2 christos size_t matches;
294 1.1.1.2 christos
295 1.1.1.2 christos AES_set_encrypt_key(rkey, 8 * sizeof(rkey), &key);
296 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
297 1.1.1.2 christos AES_ige_encrypt(plaintext, ciphertext, sizeof(plaintext), &key, iv,
298 1.1 christos AES_ENCRYPT);
299 1.1 christos
300 1.1 christos /* corrupt halfway through */
301 1.1.1.2 christos ++ciphertext[sizeof(ciphertext) / 2];
302 1.1.1.2 christos AES_set_decrypt_key(rkey, 8 * sizeof(rkey), &key);
303 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
304 1.1.1.2 christos AES_ige_encrypt(ciphertext, checktext, sizeof(checktext), &key, iv,
305 1.1 christos AES_DECRYPT);
306 1.1 christos
307 1.1 christos matches = 0;
308 1.1.1.2 christos for (n = 0; n < sizeof(checktext); ++n)
309 1.1 christos if (checktext[n] == plaintext[n])
310 1.1 christos ++matches;
311 1.1 christos
312 1.1.1.2 christos /* Fail if there is more than 51% matching bytes */
313 1.1.1.2 christos if (!TEST_size_t_le(matches, ctsize / 2 + ctsize / 100))
314 1.1.1.2 christos testresult = 0;
315 1.1.1.2 christos
316 1.1.1.2 christos /* Fail if the garble goes backwards */
317 1.1.1.2 christos if (!TEST_size_t_gt(matches, ctsize / 2))
318 1.1.1.2 christos testresult = 0;
319 1.1.1.2 christos return testresult;
320 1.1.1.2 christos }
321 1.1 christos
322 1.1.1.2 christos static int test_bi_ige_enc_dec(void)
323 1.1.1.2 christos {
324 1.1.1.2 christos AES_KEY key, key2;
325 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 4];
326 1.1.1.2 christos unsigned char ciphertext[BIG_TEST_SIZE];
327 1.1.1.2 christos unsigned char checktext[BIG_TEST_SIZE];
328 1.1 christos
329 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
330 1.1.1.2 christos AES_set_encrypt_key(rkey, 8 * sizeof(rkey), &key);
331 1.1.1.2 christos AES_set_encrypt_key(rkey2, 8 * sizeof(rkey2), &key2);
332 1.1 christos AES_bi_ige_encrypt(plaintext, ciphertext, TEST_SIZE, &key, &key2, iv,
333 1.1 christos AES_ENCRYPT);
334 1.1 christos
335 1.1.1.2 christos AES_set_decrypt_key(rkey, 8 * sizeof(rkey), &key);
336 1.1.1.2 christos AES_set_decrypt_key(rkey2, 8 * sizeof(rkey2), &key2);
337 1.1 christos AES_bi_ige_encrypt(ciphertext, checktext, TEST_SIZE, &key, &key2, iv,
338 1.1 christos AES_DECRYPT);
339 1.1 christos
340 1.1.1.2 christos return TEST_mem_eq(checktext, TEST_SIZE, plaintext, TEST_SIZE);
341 1.1.1.2 christos }
342 1.1 christos
343 1.1.1.2 christos static int test_bi_ige_garble1(void)
344 1.1.1.2 christos {
345 1.1.1.2 christos AES_KEY key, key2;
346 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 4];
347 1.1.1.2 christos unsigned char ciphertext[BIG_TEST_SIZE];
348 1.1.1.2 christos unsigned char checktext[BIG_TEST_SIZE];
349 1.1.1.2 christos unsigned int n;
350 1.1.1.2 christos size_t matches;
351 1.1.1.2 christos
352 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
353 1.1.1.2 christos AES_set_encrypt_key(rkey, 8 * sizeof(rkey), &key);
354 1.1.1.2 christos AES_set_encrypt_key(rkey2, 8 * sizeof(rkey2), &key2);
355 1.1.1.2 christos AES_ige_encrypt(plaintext, ciphertext, sizeof(plaintext), &key, iv,
356 1.1 christos AES_ENCRYPT);
357 1.1 christos
358 1.1 christos /* corrupt halfway through */
359 1.1.1.2 christos ++ciphertext[sizeof(ciphertext) / 2];
360 1.1.1.2 christos AES_set_decrypt_key(rkey, 8 * sizeof(rkey), &key);
361 1.1.1.2 christos AES_set_decrypt_key(rkey2, 8 * sizeof(rkey2), &key2);
362 1.1.1.2 christos AES_ige_encrypt(ciphertext, checktext, sizeof(checktext), &key, iv,
363 1.1 christos AES_DECRYPT);
364 1.1 christos
365 1.1 christos matches = 0;
366 1.1.1.2 christos for (n = 0; n < sizeof(checktext); ++n)
367 1.1 christos if (checktext[n] == plaintext[n])
368 1.1 christos ++matches;
369 1.1 christos
370 1.1.1.2 christos /* Fail if there is more than 1% matching bytes */
371 1.1.1.2 christos return TEST_size_t_le(matches, sizeof(checktext) / 100);
372 1.1.1.2 christos }
373 1.1 christos
374 1.1.1.2 christos static int test_bi_ige_garble2(void)
375 1.1.1.2 christos {
376 1.1.1.2 christos AES_KEY key, key2;
377 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 4];
378 1.1.1.2 christos unsigned char ciphertext[BIG_TEST_SIZE];
379 1.1.1.2 christos unsigned char checktext[BIG_TEST_SIZE];
380 1.1.1.2 christos unsigned int n;
381 1.1.1.2 christos size_t matches;
382 1.1.1.2 christos
383 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
384 1.1.1.2 christos AES_set_encrypt_key(rkey, 8 * sizeof(rkey), &key);
385 1.1.1.2 christos AES_set_encrypt_key(rkey2, 8 * sizeof(rkey2), &key2);
386 1.1.1.2 christos AES_ige_encrypt(plaintext, ciphertext, sizeof(plaintext), &key, iv,
387 1.1 christos AES_ENCRYPT);
388 1.1 christos
389 1.1 christos /* corrupt right at the end */
390 1.1.1.2 christos ++ciphertext[sizeof(ciphertext) - 1];
391 1.1.1.2 christos AES_set_decrypt_key(rkey, 8 * sizeof(rkey), &key);
392 1.1.1.2 christos AES_set_decrypt_key(rkey2, 8 * sizeof(rkey2), &key2);
393 1.1.1.2 christos AES_ige_encrypt(ciphertext, checktext, sizeof(checktext), &key, iv,
394 1.1 christos AES_DECRYPT);
395 1.1 christos
396 1.1 christos matches = 0;
397 1.1.1.2 christos for (n = 0; n < sizeof(checktext); ++n)
398 1.1 christos if (checktext[n] == plaintext[n])
399 1.1 christos ++matches;
400 1.1 christos
401 1.1.1.2 christos /* Fail if there is more than 1% matching bytes */
402 1.1.1.2 christos return TEST_size_t_le(matches, sizeof(checktext) / 100);
403 1.1.1.2 christos }
404 1.1 christos
405 1.1.1.2 christos static int test_bi_ige_garble3(void)
406 1.1.1.2 christos {
407 1.1.1.2 christos AES_KEY key, key2;
408 1.1.1.2 christos unsigned char iv[AES_BLOCK_SIZE * 4];
409 1.1.1.2 christos unsigned char ciphertext[BIG_TEST_SIZE];
410 1.1.1.2 christos unsigned char checktext[BIG_TEST_SIZE];
411 1.1.1.2 christos unsigned int n;
412 1.1.1.2 christos size_t matches;
413 1.1.1.2 christos
414 1.1.1.2 christos memcpy(iv, saved_iv, sizeof(iv));
415 1.1.1.2 christos AES_set_encrypt_key(rkey, 8 * sizeof(rkey), &key);
416 1.1.1.2 christos AES_set_encrypt_key(rkey2, 8 * sizeof(rkey2), &key2);
417 1.1.1.2 christos AES_ige_encrypt(plaintext, ciphertext, sizeof(plaintext), &key, iv,
418 1.1 christos AES_ENCRYPT);
419 1.1 christos
420 1.1 christos /* corrupt right at the start */
421 1.1 christos ++ciphertext[0];
422 1.1.1.2 christos AES_set_decrypt_key(rkey, 8 * sizeof(rkey), &key);
423 1.1.1.2 christos AES_set_decrypt_key(rkey2, 8 * sizeof(rkey2), &key2);
424 1.1.1.2 christos AES_ige_encrypt(ciphertext, checktext, sizeof(checktext), &key, iv,
425 1.1 christos AES_DECRYPT);
426 1.1 christos
427 1.1 christos matches = 0;
428 1.1.1.2 christos for (n = 0; n < sizeof(checktext); ++n)
429 1.1 christos if (checktext[n] == plaintext[n])
430 1.1 christos ++matches;
431 1.1 christos
432 1.1.1.2 christos /* Fail if there is more than 1% matching bytes */
433 1.1.1.2 christos return TEST_size_t_le(matches, sizeof(checktext) / 100);
434 1.1.1.2 christos }
435 1.1 christos
436 1.1.1.2 christos int setup_tests(void)
437 1.1.1.2 christos {
438 1.1.1.2 christos RAND_bytes(rkey, sizeof(rkey));
439 1.1.1.2 christos RAND_bytes(rkey2, sizeof(rkey2));
440 1.1.1.2 christos RAND_bytes(plaintext, sizeof(plaintext));
441 1.1.1.2 christos RAND_bytes(saved_iv, sizeof(saved_iv));
442 1.1.1.2 christos
443 1.1.1.2 christos ADD_TEST(test_ige_enc_dec);
444 1.1.1.2 christos ADD_TEST(test_ige_enc_chaining);
445 1.1.1.2 christos ADD_TEST(test_ige_dec_chaining);
446 1.1.1.2 christos ADD_TEST(test_ige_garble_forwards);
447 1.1.1.2 christos ADD_TEST(test_bi_ige_enc_dec);
448 1.1.1.2 christos ADD_TEST(test_bi_ige_garble1);
449 1.1.1.2 christos ADD_TEST(test_bi_ige_garble2);
450 1.1.1.2 christos ADD_TEST(test_bi_ige_garble3);
451 1.1.1.2 christos ADD_ALL_TESTS(test_ige_vectors, OSSL_NELEM(ige_test_vectors));
452 1.1.1.2 christos ADD_ALL_TESTS(test_bi_ige_vectors, OSSL_NELEM(bi_ige_test_vectors));
453 1.1.1.2 christos return 1;
454 1.1 christos }
455