108fca7a5SJohn-Mark Gurney#!/usr/bin/env python 208fca7a5SJohn-Mark Gurney# 308fca7a5SJohn-Mark Gurney# Copyright (c) 2014 The FreeBSD Foundation 408fca7a5SJohn-Mark Gurney# All rights reserved. 508fca7a5SJohn-Mark Gurney# 608fca7a5SJohn-Mark Gurney# This software was developed by John-Mark Gurney under 708fca7a5SJohn-Mark Gurney# the sponsorship from the FreeBSD Foundation. 808fca7a5SJohn-Mark Gurney# Redistribution and use in source and binary forms, with or without 908fca7a5SJohn-Mark Gurney# modification, are permitted provided that the following conditions 1008fca7a5SJohn-Mark Gurney# are met: 1108fca7a5SJohn-Mark Gurney# 1. Redistributions of source code must retain the above copyright 1208fca7a5SJohn-Mark Gurney# notice, this list of conditions and the following disclaimer. 1308fca7a5SJohn-Mark Gurney# 2. Redistributions in binary form must reproduce the above copyright 1408fca7a5SJohn-Mark Gurney# notice, this list of conditions and the following disclaimer in the 1508fca7a5SJohn-Mark Gurney# documentation and/or other materials provided with the distribution. 1608fca7a5SJohn-Mark Gurney# 1708fca7a5SJohn-Mark Gurney# THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 1808fca7a5SJohn-Mark Gurney# ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 1908fca7a5SJohn-Mark Gurney# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 2008fca7a5SJohn-Mark Gurney# ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 2108fca7a5SJohn-Mark Gurney# FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 2208fca7a5SJohn-Mark Gurney# DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 2308fca7a5SJohn-Mark Gurney# OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 2408fca7a5SJohn-Mark Gurney# HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 2508fca7a5SJohn-Mark Gurney# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 2608fca7a5SJohn-Mark Gurney# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 2708fca7a5SJohn-Mark Gurney# SUCH DAMAGE. 2808fca7a5SJohn-Mark Gurney# 2908fca7a5SJohn-Mark Gurney# $FreeBSD$ 3008fca7a5SJohn-Mark Gurney# 3108fca7a5SJohn-Mark Gurney 32*d86680b0SEnji Cooperfrom __future__ import print_function 3308fca7a5SJohn-Mark Gurneyimport cryptodev 3408fca7a5SJohn-Mark Gurneyimport itertools 3508fca7a5SJohn-Mark Gurneyimport os 3608fca7a5SJohn-Mark Gurneyimport struct 3708fca7a5SJohn-Mark Gurneyimport unittest 3808fca7a5SJohn-Mark Gurneyfrom cryptodev import * 3908fca7a5SJohn-Mark Gurneyfrom glob import iglob 4008fca7a5SJohn-Mark Gurney 4108fca7a5SJohn-Mark Gurneykatdir = '/usr/local/share/nist-kat' 4208fca7a5SJohn-Mark Gurney 4308fca7a5SJohn-Mark Gurneydef katg(base, glob): 447abea82dSConrad Meyer assert os.path.exists(os.path.join(katdir, base)), "Please 'pkg install nist-kat'" 4508fca7a5SJohn-Mark Gurney return iglob(os.path.join(katdir, base, glob)) 4608fca7a5SJohn-Mark Gurney 476720b890SJohn Baldwinaesmodules = [ 'cryptosoft0', 'aesni0', 'ccr0' ] 4808fca7a5SJohn-Mark Gurneydesmodules = [ 'cryptosoft0', ] 496720b890SJohn Baldwinshamodules = [ 'cryptosoft0', 'ccr0' ] 5008fca7a5SJohn-Mark Gurney 5108fca7a5SJohn-Mark Gurneydef GenTestCase(cname): 5208fca7a5SJohn-Mark Gurney try: 5308fca7a5SJohn-Mark Gurney crid = cryptodev.Crypto.findcrid(cname) 5408fca7a5SJohn-Mark Gurney except IOError: 5508fca7a5SJohn-Mark Gurney return None 5608fca7a5SJohn-Mark Gurney 5708fca7a5SJohn-Mark Gurney class GendCryptoTestCase(unittest.TestCase): 5808fca7a5SJohn-Mark Gurney ############### 5908fca7a5SJohn-Mark Gurney ##### AES ##### 6008fca7a5SJohn-Mark Gurney ############### 61*d86680b0SEnji Cooper @unittest.skipIf(cname not in aesmodules, 'skipping AES on %s' % (cname)) 6208fca7a5SJohn-Mark Gurney def test_xts(self): 6308fca7a5SJohn-Mark Gurney for i in katg('XTSTestVectors/format tweak value input - data unit seq no', '*.rsp'): 6408fca7a5SJohn-Mark Gurney self.runXTS(i, cryptodev.CRYPTO_AES_XTS) 6508fca7a5SJohn-Mark Gurney 66*d86680b0SEnji Cooper @unittest.skipIf(cname not in aesmodules, 'skipping AES on %s' % (cname)) 6708fca7a5SJohn-Mark Gurney def test_cbc(self): 6808fca7a5SJohn-Mark Gurney for i in katg('KAT_AES', 'CBC[GKV]*.rsp'): 6908fca7a5SJohn-Mark Gurney self.runCBC(i) 7008fca7a5SJohn-Mark Gurney 71*d86680b0SEnji Cooper @unittest.skipIf(cname not in aesmodules, 'skipping AES on %s' % (cname)) 7208fca7a5SJohn-Mark Gurney def test_gcm(self): 7308fca7a5SJohn-Mark Gurney for i in katg('gcmtestvectors', 'gcmEncrypt*'): 7408fca7a5SJohn-Mark Gurney self.runGCM(i, 'ENCRYPT') 7508fca7a5SJohn-Mark Gurney 7608fca7a5SJohn-Mark Gurney for i in katg('gcmtestvectors', 'gcmDecrypt*'): 7708fca7a5SJohn-Mark Gurney self.runGCM(i, 'DECRYPT') 7808fca7a5SJohn-Mark Gurney 7908fca7a5SJohn-Mark Gurney _gmacsizes = { 32: cryptodev.CRYPTO_AES_256_NIST_GMAC, 8008fca7a5SJohn-Mark Gurney 24: cryptodev.CRYPTO_AES_192_NIST_GMAC, 8108fca7a5SJohn-Mark Gurney 16: cryptodev.CRYPTO_AES_128_NIST_GMAC, 8208fca7a5SJohn-Mark Gurney } 8308fca7a5SJohn-Mark Gurney def runGCM(self, fname, mode): 8408fca7a5SJohn-Mark Gurney curfun = None 8508fca7a5SJohn-Mark Gurney if mode == 'ENCRYPT': 8608fca7a5SJohn-Mark Gurney swapptct = False 8708fca7a5SJohn-Mark Gurney curfun = Crypto.encrypt 8808fca7a5SJohn-Mark Gurney elif mode == 'DECRYPT': 8908fca7a5SJohn-Mark Gurney swapptct = True 9008fca7a5SJohn-Mark Gurney curfun = Crypto.decrypt 9108fca7a5SJohn-Mark Gurney else: 92*d86680b0SEnji Cooper raise RuntimeError('unknown mode: %r' % repr(mode)) 9308fca7a5SJohn-Mark Gurney 9408fca7a5SJohn-Mark Gurney for bogusmode, lines in cryptodev.KATParser(fname, 9508fca7a5SJohn-Mark Gurney [ 'Count', 'Key', 'IV', 'CT', 'AAD', 'Tag', 'PT', ]): 9608fca7a5SJohn-Mark Gurney for data in lines: 9708fca7a5SJohn-Mark Gurney curcnt = int(data['Count']) 9808fca7a5SJohn-Mark Gurney cipherkey = data['Key'].decode('hex') 9908fca7a5SJohn-Mark Gurney iv = data['IV'].decode('hex') 10008fca7a5SJohn-Mark Gurney aad = data['AAD'].decode('hex') 10108fca7a5SJohn-Mark Gurney tag = data['Tag'].decode('hex') 10208fca7a5SJohn-Mark Gurney if 'FAIL' not in data: 10308fca7a5SJohn-Mark Gurney pt = data['PT'].decode('hex') 10408fca7a5SJohn-Mark Gurney ct = data['CT'].decode('hex') 10508fca7a5SJohn-Mark Gurney 10608fca7a5SJohn-Mark Gurney if len(iv) != 12: 10708fca7a5SJohn-Mark Gurney # XXX - isn't supported 10808fca7a5SJohn-Mark Gurney continue 10908fca7a5SJohn-Mark Gurney 11008fca7a5SJohn-Mark Gurney c = Crypto(cryptodev.CRYPTO_AES_NIST_GCM_16, 11108fca7a5SJohn-Mark Gurney cipherkey, 11208fca7a5SJohn-Mark Gurney mac=self._gmacsizes[len(cipherkey)], 11308fca7a5SJohn-Mark Gurney mackey=cipherkey, crid=crid) 11408fca7a5SJohn-Mark Gurney 11508fca7a5SJohn-Mark Gurney if mode == 'ENCRYPT': 11608fca7a5SJohn-Mark Gurney rct, rtag = c.encrypt(pt, iv, aad) 11708fca7a5SJohn-Mark Gurney rtag = rtag[:len(tag)] 11808fca7a5SJohn-Mark Gurney data['rct'] = rct.encode('hex') 11908fca7a5SJohn-Mark Gurney data['rtag'] = rtag.encode('hex') 120*d86680b0SEnji Cooper self.assertEqual(rct, ct, repr(data)) 121*d86680b0SEnji Cooper self.assertEqual(rtag, tag, repr(data)) 12208fca7a5SJohn-Mark Gurney else: 12308fca7a5SJohn-Mark Gurney if len(tag) != 16: 12408fca7a5SJohn-Mark Gurney continue 12508fca7a5SJohn-Mark Gurney args = (ct, iv, aad, tag) 12608fca7a5SJohn-Mark Gurney if 'FAIL' in data: 12708fca7a5SJohn-Mark Gurney self.assertRaises(IOError, 12808fca7a5SJohn-Mark Gurney c.decrypt, *args) 12908fca7a5SJohn-Mark Gurney else: 13008fca7a5SJohn-Mark Gurney rpt, rtag = c.decrypt(*args) 13108fca7a5SJohn-Mark Gurney data['rpt'] = rpt.encode('hex') 13208fca7a5SJohn-Mark Gurney data['rtag'] = rtag.encode('hex') 13308fca7a5SJohn-Mark Gurney self.assertEqual(rpt, pt, 134*d86680b0SEnji Cooper repr(data)) 13508fca7a5SJohn-Mark Gurney 13608fca7a5SJohn-Mark Gurney def runCBC(self, fname): 13708fca7a5SJohn-Mark Gurney curfun = None 13808fca7a5SJohn-Mark Gurney for mode, lines in cryptodev.KATParser(fname, 13908fca7a5SJohn-Mark Gurney [ 'COUNT', 'KEY', 'IV', 'PLAINTEXT', 'CIPHERTEXT', ]): 14008fca7a5SJohn-Mark Gurney if mode == 'ENCRYPT': 14108fca7a5SJohn-Mark Gurney swapptct = False 14208fca7a5SJohn-Mark Gurney curfun = Crypto.encrypt 14308fca7a5SJohn-Mark Gurney elif mode == 'DECRYPT': 14408fca7a5SJohn-Mark Gurney swapptct = True 14508fca7a5SJohn-Mark Gurney curfun = Crypto.decrypt 14608fca7a5SJohn-Mark Gurney else: 147*d86680b0SEnji Cooper raise RuntimeError('unknown mode: %r' % repr(mode)) 14808fca7a5SJohn-Mark Gurney 14908fca7a5SJohn-Mark Gurney for data in lines: 15008fca7a5SJohn-Mark Gurney curcnt = int(data['COUNT']) 15108fca7a5SJohn-Mark Gurney cipherkey = data['KEY'].decode('hex') 15208fca7a5SJohn-Mark Gurney iv = data['IV'].decode('hex') 15308fca7a5SJohn-Mark Gurney pt = data['PLAINTEXT'].decode('hex') 15408fca7a5SJohn-Mark Gurney ct = data['CIPHERTEXT'].decode('hex') 15508fca7a5SJohn-Mark Gurney 15608fca7a5SJohn-Mark Gurney if swapptct: 15708fca7a5SJohn-Mark Gurney pt, ct = ct, pt 15808fca7a5SJohn-Mark Gurney # run the fun 15908fca7a5SJohn-Mark Gurney c = Crypto(cryptodev.CRYPTO_AES_CBC, cipherkey, crid=crid) 16008fca7a5SJohn-Mark Gurney r = curfun(c, pt, iv) 16108fca7a5SJohn-Mark Gurney self.assertEqual(r, ct) 16208fca7a5SJohn-Mark Gurney 16308fca7a5SJohn-Mark Gurney def runXTS(self, fname, meth): 16408fca7a5SJohn-Mark Gurney curfun = None 16508fca7a5SJohn-Mark Gurney for mode, lines in cryptodev.KATParser(fname, 16608fca7a5SJohn-Mark Gurney [ 'COUNT', 'DataUnitLen', 'Key', 'DataUnitSeqNumber', 'PT', 16708fca7a5SJohn-Mark Gurney 'CT' ]): 16808fca7a5SJohn-Mark Gurney if mode == 'ENCRYPT': 16908fca7a5SJohn-Mark Gurney swapptct = False 17008fca7a5SJohn-Mark Gurney curfun = Crypto.encrypt 17108fca7a5SJohn-Mark Gurney elif mode == 'DECRYPT': 17208fca7a5SJohn-Mark Gurney swapptct = True 17308fca7a5SJohn-Mark Gurney curfun = Crypto.decrypt 17408fca7a5SJohn-Mark Gurney else: 175*d86680b0SEnji Cooper raise RuntimeError('unknown mode: %r' % repr(mode)) 17608fca7a5SJohn-Mark Gurney 17708fca7a5SJohn-Mark Gurney for data in lines: 17808fca7a5SJohn-Mark Gurney curcnt = int(data['COUNT']) 17908fca7a5SJohn-Mark Gurney nbits = int(data['DataUnitLen']) 18008fca7a5SJohn-Mark Gurney cipherkey = data['Key'].decode('hex') 18108fca7a5SJohn-Mark Gurney iv = struct.pack('QQ', int(data['DataUnitSeqNumber']), 0) 18208fca7a5SJohn-Mark Gurney pt = data['PT'].decode('hex') 18308fca7a5SJohn-Mark Gurney ct = data['CT'].decode('hex') 18408fca7a5SJohn-Mark Gurney 18508fca7a5SJohn-Mark Gurney if nbits % 128 != 0: 18608fca7a5SJohn-Mark Gurney # XXX - mark as skipped 18708fca7a5SJohn-Mark Gurney continue 18808fca7a5SJohn-Mark Gurney if swapptct: 18908fca7a5SJohn-Mark Gurney pt, ct = ct, pt 19008fca7a5SJohn-Mark Gurney # run the fun 19108fca7a5SJohn-Mark Gurney c = Crypto(meth, cipherkey, crid=crid) 19208fca7a5SJohn-Mark Gurney r = curfun(c, pt, iv) 19308fca7a5SJohn-Mark Gurney self.assertEqual(r, ct) 19408fca7a5SJohn-Mark Gurney 19508fca7a5SJohn-Mark Gurney ############### 19608fca7a5SJohn-Mark Gurney ##### DES ##### 19708fca7a5SJohn-Mark Gurney ############### 198*d86680b0SEnji Cooper @unittest.skipIf(cname not in desmodules, 'skipping DES on %s' % (cname)) 19908fca7a5SJohn-Mark Gurney def test_tdes(self): 20008fca7a5SJohn-Mark Gurney for i in katg('KAT_TDES', 'TCBC[a-z]*.rsp'): 20108fca7a5SJohn-Mark Gurney self.runTDES(i) 20208fca7a5SJohn-Mark Gurney 20308fca7a5SJohn-Mark Gurney def runTDES(self, fname): 20408fca7a5SJohn-Mark Gurney curfun = None 20508fca7a5SJohn-Mark Gurney for mode, lines in cryptodev.KATParser(fname, 20608fca7a5SJohn-Mark Gurney [ 'COUNT', 'KEYs', 'IV', 'PLAINTEXT', 'CIPHERTEXT', ]): 20708fca7a5SJohn-Mark Gurney if mode == 'ENCRYPT': 20808fca7a5SJohn-Mark Gurney swapptct = False 20908fca7a5SJohn-Mark Gurney curfun = Crypto.encrypt 21008fca7a5SJohn-Mark Gurney elif mode == 'DECRYPT': 21108fca7a5SJohn-Mark Gurney swapptct = True 21208fca7a5SJohn-Mark Gurney curfun = Crypto.decrypt 21308fca7a5SJohn-Mark Gurney else: 214*d86680b0SEnji Cooper raise RuntimeError('unknown mode: %r' % repr(mode)) 21508fca7a5SJohn-Mark Gurney 21608fca7a5SJohn-Mark Gurney for data in lines: 21708fca7a5SJohn-Mark Gurney curcnt = int(data['COUNT']) 21808fca7a5SJohn-Mark Gurney key = data['KEYs'] * 3 21908fca7a5SJohn-Mark Gurney cipherkey = key.decode('hex') 22008fca7a5SJohn-Mark Gurney iv = data['IV'].decode('hex') 22108fca7a5SJohn-Mark Gurney pt = data['PLAINTEXT'].decode('hex') 22208fca7a5SJohn-Mark Gurney ct = data['CIPHERTEXT'].decode('hex') 22308fca7a5SJohn-Mark Gurney 22408fca7a5SJohn-Mark Gurney if swapptct: 22508fca7a5SJohn-Mark Gurney pt, ct = ct, pt 22608fca7a5SJohn-Mark Gurney # run the fun 22708fca7a5SJohn-Mark Gurney c = Crypto(cryptodev.CRYPTO_3DES_CBC, cipherkey, crid=crid) 22808fca7a5SJohn-Mark Gurney r = curfun(c, pt, iv) 22908fca7a5SJohn-Mark Gurney self.assertEqual(r, ct) 23008fca7a5SJohn-Mark Gurney 23108fca7a5SJohn-Mark Gurney ############### 23208fca7a5SJohn-Mark Gurney ##### SHA ##### 23308fca7a5SJohn-Mark Gurney ############### 234*d86680b0SEnji Cooper @unittest.skipIf(cname not in shamodules, 'skipping SHA on %s' % str(cname)) 23508fca7a5SJohn-Mark Gurney def test_sha(self): 23608fca7a5SJohn-Mark Gurney # SHA not available in software 23708fca7a5SJohn-Mark Gurney pass 23808fca7a5SJohn-Mark Gurney #for i in iglob('SHA1*'): 23908fca7a5SJohn-Mark Gurney # self.runSHA(i) 24008fca7a5SJohn-Mark Gurney 241*d86680b0SEnji Cooper @unittest.skipIf(cname not in shamodules, 'skipping SHA on %s' % str(cname)) 24208fca7a5SJohn-Mark Gurney def test_sha1hmac(self): 24308fca7a5SJohn-Mark Gurney for i in katg('hmactestvectors', 'HMAC.rsp'): 24408fca7a5SJohn-Mark Gurney self.runSHA1HMAC(i) 24508fca7a5SJohn-Mark Gurney 24608fca7a5SJohn-Mark Gurney def runSHA1HMAC(self, fname): 247005fdbbcSConrad Meyer for hashlength, lines in cryptodev.KATParser(fname, 24808fca7a5SJohn-Mark Gurney [ 'Count', 'Klen', 'Tlen', 'Key', 'Msg', 'Mac' ]): 249005fdbbcSConrad Meyer # E.g., hashlength will be "L=20" (bytes) 250005fdbbcSConrad Meyer hashlen = int(hashlength.split("=")[1]) 251005fdbbcSConrad Meyer 252005fdbbcSConrad Meyer blocksize = None 253005fdbbcSConrad Meyer if hashlen == 20: 254005fdbbcSConrad Meyer alg = cryptodev.CRYPTO_SHA1_HMAC 255005fdbbcSConrad Meyer blocksize = 64 256005fdbbcSConrad Meyer elif hashlen == 28: 257005fdbbcSConrad Meyer # Cryptodev doesn't support SHA-224 258005fdbbcSConrad Meyer # Slurp remaining input in section 259005fdbbcSConrad Meyer for data in lines: 260005fdbbcSConrad Meyer continue 261005fdbbcSConrad Meyer continue 262005fdbbcSConrad Meyer elif hashlen == 32: 263005fdbbcSConrad Meyer alg = cryptodev.CRYPTO_SHA2_256_HMAC 264005fdbbcSConrad Meyer blocksize = 64 265005fdbbcSConrad Meyer elif hashlen == 48: 266005fdbbcSConrad Meyer alg = cryptodev.CRYPTO_SHA2_384_HMAC 267005fdbbcSConrad Meyer blocksize = 128 268005fdbbcSConrad Meyer elif hashlen == 64: 269005fdbbcSConrad Meyer alg = cryptodev.CRYPTO_SHA2_512_HMAC 270005fdbbcSConrad Meyer blocksize = 128 271005fdbbcSConrad Meyer else: 272005fdbbcSConrad Meyer # Skip unsupported hashes 273005fdbbcSConrad Meyer # Slurp remaining input in section 274005fdbbcSConrad Meyer for data in lines: 275005fdbbcSConrad Meyer continue 276005fdbbcSConrad Meyer continue 277005fdbbcSConrad Meyer 27808fca7a5SJohn-Mark Gurney for data in lines: 27908fca7a5SJohn-Mark Gurney key = data['Key'].decode('hex') 28008fca7a5SJohn-Mark Gurney msg = data['Msg'].decode('hex') 28108fca7a5SJohn-Mark Gurney mac = data['Mac'].decode('hex') 282005fdbbcSConrad Meyer tlen = int(data['Tlen']) 28308fca7a5SJohn-Mark Gurney 284005fdbbcSConrad Meyer if len(key) > blocksize: 28508fca7a5SJohn-Mark Gurney continue 28608fca7a5SJohn-Mark Gurney 287005fdbbcSConrad Meyer c = Crypto(mac=alg, mackey=key, 288005fdbbcSConrad Meyer crid=crid) 28908fca7a5SJohn-Mark Gurney 290005fdbbcSConrad Meyer _, r = c.encrypt(msg, iv="") 291005fdbbcSConrad Meyer 292005fdbbcSConrad Meyer # A limitation in cryptodev.py means we 293005fdbbcSConrad Meyer # can only store MACs up to 16 bytes. 294005fdbbcSConrad Meyer # That's good enough to validate the 295005fdbbcSConrad Meyer # correct behavior, more or less. 296005fdbbcSConrad Meyer maclen = min(tlen, 16) 297005fdbbcSConrad Meyer self.assertEqual(r[:maclen], mac[:maclen], "Actual: " + \ 298005fdbbcSConrad Meyer repr(r[:maclen].encode("hex")) + " Expected: " + repr(data)) 29908fca7a5SJohn-Mark Gurney 30008fca7a5SJohn-Mark Gurney return GendCryptoTestCase 30108fca7a5SJohn-Mark Gurney 30208fca7a5SJohn-Mark Gurneycryptosoft = GenTestCase('cryptosoft0') 30308fca7a5SJohn-Mark Gurneyaesni = GenTestCase('aesni0') 3046720b890SJohn Baldwinccr = GenTestCase('ccr0') 30508fca7a5SJohn-Mark Gurney 30608fca7a5SJohn-Mark Gurneyif __name__ == '__main__': 30708fca7a5SJohn-Mark Gurney unittest.main() 308