xref: /freebsd/crypto/libecc/src/tests/ed25519ctx_test_vectors.h (revision f0865ec9906d5a18fa2a3b61381f22ce16e606ad)
1*f0865ec9SKyle Evans /*
2*f0865ec9SKyle Evans  *  Copyright (C) 2021 - This file is part of libecc project
3*f0865ec9SKyle Evans  *
4*f0865ec9SKyle Evans  *  Authors:
5*f0865ec9SKyle Evans  *      Arnaud EBALARD <arnaud.ebalard@ssi.gouv.fr>
6*f0865ec9SKyle Evans  *      Ryad BENADJILA <ryadbenadjila@gmail.com>
7*f0865ec9SKyle Evans  *
8*f0865ec9SKyle Evans  *  This software is licensed under a dual BSD and GPL v2 license.
9*f0865ec9SKyle Evans  *  See LICENSE file at the root folder of the project.
10*f0865ec9SKyle Evans  */
11*f0865ec9SKyle Evans #ifndef __ED25519CTX_TEST_VECTORS_H__
12*f0865ec9SKyle Evans #define __ED25519CTX_TEST_VECTORS_H__
13*f0865ec9SKyle Evans 
14*f0865ec9SKyle Evans /************************************************/
15*f0865ec9SKyle Evans static const u8 ed25519ctx_1_test_vectors_priv_key[] = {
16*f0865ec9SKyle Evans 	0x03, 0x05, 0x33, 0x4e, 0x38, 0x1a, 0xf7, 0x8f, 0x14, 0x1c, 0xb6, 0x66, 0xf6, 0x19, 0x9f, 0x57, 0xbc, 0x34, 0x95, 0x33, 0x5a, 0x25, 0x6a, 0x95, 0xbd, 0x2a, 0x55, 0xbf, 0x54, 0x66, 0x63, 0xf6,
17*f0865ec9SKyle Evans };
18*f0865ec9SKyle Evans static const u8 ed25519ctx_1_test_vectors_message[] = {
19*f0865ec9SKyle Evans 	0xf7, 0x26, 0x93, 0x6d, 0x19, 0xc8, 0x00, 0x49, 0x4e, 0x3f, 0xda, 0xff, 0x20, 0xb2, 0x76, 0xa8,
20*f0865ec9SKyle Evans };
21*f0865ec9SKyle Evans static const u8 ed25519ctx_1_test_vectors_expected_sig[] = {
22*f0865ec9SKyle Evans 	0x55, 0xa4, 0xcc, 0x2f, 0x70, 0xa5, 0x4e, 0x04, 0x28, 0x8c, 0x5f, 0x4c, 0xd1, 0xe4, 0x5a, 0x7b, 0xb5, 0x20, 0xb3, 0x62, 0x92, 0x91, 0x18, 0x76, 0xca, 0xda, 0x73, 0x23, 0x19, 0x8d, 0xd8, 0x7a, 0x8b, 0x36, 0x95, 0x0b, 0x95, 0x13, 0x00, 0x22, 0x90, 0x7a, 0x7f, 0xb7, 0xc4, 0xe9, 0xb2, 0xd5, 0xf6, 0xcc, 0xa6, 0x85, 0xa5, 0x87, 0xb4, 0xb2, 0x1f, 0x4b, 0x88, 0x8e, 0x4e, 0x7e, 0xdb, 0x0d,
23*f0865ec9SKyle Evans };
24*f0865ec9SKyle Evans static const u8 ed25519ctx_1_test_vectors_adata[] = {
25*f0865ec9SKyle Evans 	0x66, 0x6f, 0x6f,
26*f0865ec9SKyle Evans };
27*f0865ec9SKyle Evans static const ec_test_case ed25519ctx_1_test_case = {
28*f0865ec9SKyle Evans 	.name = "EDDSA25519CTX-SHA512/wei25519 1",
29*f0865ec9SKyle Evans 	.ec_str_p = &wei25519_str_params,
30*f0865ec9SKyle Evans 	.priv_key = ed25519ctx_1_test_vectors_priv_key,
31*f0865ec9SKyle Evans 	.priv_key_len = sizeof(ed25519ctx_1_test_vectors_priv_key),
32*f0865ec9SKyle Evans 	.nn_random = NULL,
33*f0865ec9SKyle Evans 	.hash_type = SHA512,
34*f0865ec9SKyle Evans 	.msg = (const char *)ed25519ctx_1_test_vectors_message,
35*f0865ec9SKyle Evans 	.msglen = sizeof(ed25519ctx_1_test_vectors_message),
36*f0865ec9SKyle Evans 	.sig_type = EDDSA25519CTX,
37*f0865ec9SKyle Evans 	.exp_sig = ed25519ctx_1_test_vectors_expected_sig,
38*f0865ec9SKyle Evans 	.exp_siglen = sizeof(ed25519ctx_1_test_vectors_expected_sig),
39*f0865ec9SKyle Evans 	.adata = ed25519ctx_1_test_vectors_adata,
40*f0865ec9SKyle Evans 	.adata_len = sizeof(ed25519ctx_1_test_vectors_adata),
41*f0865ec9SKyle Evans };
42*f0865ec9SKyle Evans 
43*f0865ec9SKyle Evans /************************************************/
44*f0865ec9SKyle Evans static const u8 ed25519ctx_2_test_vectors_priv_key[] = {
45*f0865ec9SKyle Evans 	0x03, 0x05, 0x33, 0x4e, 0x38, 0x1a, 0xf7, 0x8f, 0x14, 0x1c, 0xb6, 0x66, 0xf6, 0x19, 0x9f, 0x57, 0xbc, 0x34, 0x95, 0x33, 0x5a, 0x25, 0x6a, 0x95, 0xbd, 0x2a, 0x55, 0xbf, 0x54, 0x66, 0x63, 0xf6,
46*f0865ec9SKyle Evans };
47*f0865ec9SKyle Evans static const u8 ed25519ctx_2_test_vectors_message[] = {
48*f0865ec9SKyle Evans 	0xf7, 0x26, 0x93, 0x6d, 0x19, 0xc8, 0x00, 0x49, 0x4e, 0x3f, 0xda, 0xff, 0x20, 0xb2, 0x76, 0xa8,
49*f0865ec9SKyle Evans };
50*f0865ec9SKyle Evans static const u8 ed25519ctx_2_test_vectors_expected_sig[] = {
51*f0865ec9SKyle Evans 	0xfc, 0x60, 0xd5, 0x87, 0x2f, 0xc4, 0x6b, 0x3a, 0xa6, 0x9f, 0x8b, 0x5b, 0x43, 0x51, 0xd5, 0x80, 0x8f, 0x92, 0xbc, 0xc0, 0x44, 0x60, 0x6d, 0xb0, 0x97, 0xab, 0xab, 0x6d, 0xbc, 0xb1, 0xae, 0xe3, 0x21, 0x6c, 0x48, 0xe8, 0xb3, 0xb6, 0x64, 0x31, 0xb5, 0xb1, 0x86, 0xd1, 0xd2, 0x8f, 0x8e, 0xe1, 0x5a, 0x5c, 0xa2, 0xdf, 0x66, 0x68, 0x34, 0x62, 0x91, 0xc2, 0x04, 0x3d, 0x4e, 0xb3, 0xe9, 0x0d,
52*f0865ec9SKyle Evans };
53*f0865ec9SKyle Evans static const u8 ed25519ctx_2_test_vectors_adata[] = {
54*f0865ec9SKyle Evans 	0x62, 0x61, 0x72,
55*f0865ec9SKyle Evans };
56*f0865ec9SKyle Evans static const ec_test_case ed25519ctx_2_test_case = {
57*f0865ec9SKyle Evans 	.name = "EDDSA25519CTX-SHA512/wei25519 2",
58*f0865ec9SKyle Evans 	.ec_str_p = &wei25519_str_params,
59*f0865ec9SKyle Evans 	.priv_key = ed25519ctx_2_test_vectors_priv_key,
60*f0865ec9SKyle Evans 	.priv_key_len = sizeof(ed25519ctx_2_test_vectors_priv_key),
61*f0865ec9SKyle Evans 	.nn_random = NULL,
62*f0865ec9SKyle Evans 	.hash_type = SHA512,
63*f0865ec9SKyle Evans 	.msg = (const char *)ed25519ctx_2_test_vectors_message,
64*f0865ec9SKyle Evans 	.msglen = sizeof(ed25519ctx_2_test_vectors_message),
65*f0865ec9SKyle Evans 	.sig_type = EDDSA25519CTX,
66*f0865ec9SKyle Evans 	.exp_sig = ed25519ctx_2_test_vectors_expected_sig,
67*f0865ec9SKyle Evans 	.exp_siglen = sizeof(ed25519ctx_2_test_vectors_expected_sig),
68*f0865ec9SKyle Evans 	.adata = ed25519ctx_2_test_vectors_adata,
69*f0865ec9SKyle Evans 	.adata_len = sizeof(ed25519ctx_2_test_vectors_adata),
70*f0865ec9SKyle Evans };
71*f0865ec9SKyle Evans 
72*f0865ec9SKyle Evans /************************************************/
73*f0865ec9SKyle Evans static const u8 ed25519ctx_3_test_vectors_priv_key[] = {
74*f0865ec9SKyle Evans 	0x03, 0x05, 0x33, 0x4e, 0x38, 0x1a, 0xf7, 0x8f, 0x14, 0x1c, 0xb6, 0x66, 0xf6, 0x19, 0x9f, 0x57, 0xbc, 0x34, 0x95, 0x33, 0x5a, 0x25, 0x6a, 0x95, 0xbd, 0x2a, 0x55, 0xbf, 0x54, 0x66, 0x63, 0xf6,
75*f0865ec9SKyle Evans };
76*f0865ec9SKyle Evans static const u8 ed25519ctx_3_test_vectors_message[] = {
77*f0865ec9SKyle Evans 	0x50, 0x8e, 0x9e, 0x68, 0x82, 0xb9, 0x79, 0xfe, 0xa9, 0x00, 0xf6, 0x2a, 0xdc, 0xea, 0xca, 0x35,
78*f0865ec9SKyle Evans };
79*f0865ec9SKyle Evans static const u8 ed25519ctx_3_test_vectors_expected_sig[] = {
80*f0865ec9SKyle Evans 	0x8b, 0x70, 0xc1, 0xcc, 0x83, 0x10, 0xe1, 0xde, 0x20, 0xac, 0x53, 0xce, 0x28, 0xae, 0x6e, 0x72, 0x07, 0xf3, 0x3c, 0x32, 0x95, 0xe0, 0x3b, 0xb5, 0xc0, 0x73, 0x2a, 0x1d, 0x20, 0xdc, 0x64, 0x90, 0x89, 0x22, 0xa8, 0xb0, 0x52, 0xcf, 0x99, 0xb7, 0xc4, 0xfe, 0x10, 0x7a, 0x5a, 0xbb, 0x5b, 0x2c, 0x40, 0x85, 0xae, 0x75, 0x89, 0x0d, 0x02, 0xdf, 0x26, 0x26, 0x9d, 0x89, 0x45, 0xf8, 0x4b, 0x0b,
81*f0865ec9SKyle Evans };
82*f0865ec9SKyle Evans static const u8 ed25519ctx_3_test_vectors_adata[] = {
83*f0865ec9SKyle Evans 	0x66, 0x6f, 0x6f,
84*f0865ec9SKyle Evans };
85*f0865ec9SKyle Evans static const ec_test_case ed25519ctx_3_test_case = {
86*f0865ec9SKyle Evans 	.name = "EDDSA25519CTX-SHA512/wei25519 3",
87*f0865ec9SKyle Evans 	.ec_str_p = &wei25519_str_params,
88*f0865ec9SKyle Evans 	.priv_key = ed25519ctx_3_test_vectors_priv_key,
89*f0865ec9SKyle Evans 	.priv_key_len = sizeof(ed25519ctx_3_test_vectors_priv_key),
90*f0865ec9SKyle Evans 	.nn_random = NULL,
91*f0865ec9SKyle Evans 	.hash_type = SHA512,
92*f0865ec9SKyle Evans 	.msg = (const char *)ed25519ctx_3_test_vectors_message,
93*f0865ec9SKyle Evans 	.msglen = sizeof(ed25519ctx_3_test_vectors_message),
94*f0865ec9SKyle Evans 	.sig_type = EDDSA25519CTX,
95*f0865ec9SKyle Evans 	.exp_sig = ed25519ctx_3_test_vectors_expected_sig,
96*f0865ec9SKyle Evans 	.exp_siglen = sizeof(ed25519ctx_3_test_vectors_expected_sig),
97*f0865ec9SKyle Evans 	.adata = ed25519ctx_3_test_vectors_adata,
98*f0865ec9SKyle Evans 	.adata_len = sizeof(ed25519ctx_3_test_vectors_adata),
99*f0865ec9SKyle Evans };
100*f0865ec9SKyle Evans 
101*f0865ec9SKyle Evans /************************************************/
102*f0865ec9SKyle Evans static const u8 ed25519ctx_4_test_vectors_priv_key[] = {
103*f0865ec9SKyle Evans 	0xab, 0x9c, 0x28, 0x53, 0xce, 0x29, 0x7d, 0xda, 0xb8, 0x5c, 0x99, 0x3b, 0x3a, 0xe1, 0x4b, 0xca, 0xd3, 0x9b, 0x2c, 0x68, 0x2b, 0xea, 0xbc, 0x27, 0xd6, 0xd4, 0xeb, 0x20, 0x71, 0x1d, 0x65, 0x60,
104*f0865ec9SKyle Evans };
105*f0865ec9SKyle Evans static const u8 ed25519ctx_4_test_vectors_message[] = {
106*f0865ec9SKyle Evans 	0xf7, 0x26, 0x93, 0x6d, 0x19, 0xc8, 0x00, 0x49, 0x4e, 0x3f, 0xda, 0xff, 0x20, 0xb2, 0x76, 0xa8,
107*f0865ec9SKyle Evans };
108*f0865ec9SKyle Evans static const u8 ed25519ctx_4_test_vectors_expected_sig[] = {
109*f0865ec9SKyle Evans 	0x21, 0x65, 0x5b, 0x5f, 0x1a, 0xa9, 0x65, 0x99, 0x6b, 0x3f, 0x97, 0xb3, 0xc8, 0x49, 0xea, 0xfb, 0xa9, 0x22, 0xa0, 0xa6, 0x29, 0x92, 0xf7, 0x3b, 0x3d, 0x1b, 0x73, 0x10, 0x6a, 0x84, 0xad, 0x85, 0xe9, 0xb8, 0x6a, 0x7b, 0x60, 0x05, 0xea, 0x86, 0x83, 0x37, 0xff, 0x2d, 0x20, 0xa7, 0xf5, 0xfb, 0xd4, 0xcd, 0x10, 0xb0, 0xbe, 0x49, 0xa6, 0x8d, 0xa2, 0xb2, 0xe0, 0xdc, 0x0a, 0xd8, 0x96, 0x0f,
110*f0865ec9SKyle Evans };
111*f0865ec9SKyle Evans static const u8 ed25519ctx_4_test_vectors_adata[] = {
112*f0865ec9SKyle Evans 	0x66, 0x6f, 0x6f,
113*f0865ec9SKyle Evans };
114*f0865ec9SKyle Evans static const ec_test_case ed25519ctx_4_test_case = {
115*f0865ec9SKyle Evans 	.name = "EDDSA25519CTX-SHA512/wei25519 4",
116*f0865ec9SKyle Evans 	.ec_str_p = &wei25519_str_params,
117*f0865ec9SKyle Evans 	.priv_key = ed25519ctx_4_test_vectors_priv_key,
118*f0865ec9SKyle Evans 	.priv_key_len = sizeof(ed25519ctx_4_test_vectors_priv_key),
119*f0865ec9SKyle Evans 	.nn_random = NULL,
120*f0865ec9SKyle Evans 	.hash_type = SHA512,
121*f0865ec9SKyle Evans 	.msg = (const char *)ed25519ctx_4_test_vectors_message,
122*f0865ec9SKyle Evans 	.msglen = sizeof(ed25519ctx_4_test_vectors_message),
123*f0865ec9SKyle Evans 	.sig_type = EDDSA25519CTX,
124*f0865ec9SKyle Evans 	.exp_sig = ed25519ctx_4_test_vectors_expected_sig,
125*f0865ec9SKyle Evans 	.exp_siglen = sizeof(ed25519ctx_4_test_vectors_expected_sig),
126*f0865ec9SKyle Evans 	.adata = ed25519ctx_4_test_vectors_adata,
127*f0865ec9SKyle Evans 	.adata_len = sizeof(ed25519ctx_4_test_vectors_adata),
128*f0865ec9SKyle Evans };
129*f0865ec9SKyle Evans 
130*f0865ec9SKyle Evans 
131*f0865ec9SKyle Evans /************************************************/
132*f0865ec9SKyle Evans #define EDDSA25519CTX_SHA512_WEI25519_ALL_TESTS() \
133*f0865ec9SKyle Evans 	&ed25519ctx_1_test_case,\
134*f0865ec9SKyle Evans 	&ed25519ctx_2_test_case,\
135*f0865ec9SKyle Evans 	&ed25519ctx_3_test_case,\
136*f0865ec9SKyle Evans 	&ed25519ctx_4_test_case,
137*f0865ec9SKyle Evans 
138*f0865ec9SKyle Evans #endif /* __ED25519CTX_TEST_VECTORS_H__ */
139