1*f9fbec18Smcpowers /*
2*f9fbec18Smcpowers * ***** BEGIN LICENSE BLOCK *****
3*f9fbec18Smcpowers * Version: MPL 1.1/GPL 2.0/LGPL 2.1
4*f9fbec18Smcpowers *
5*f9fbec18Smcpowers * The contents of this file are subject to the Mozilla Public License Version
6*f9fbec18Smcpowers * 1.1 (the "License"); you may not use this file except in compliance with
7*f9fbec18Smcpowers * the License. You may obtain a copy of the License at
8*f9fbec18Smcpowers * http://www.mozilla.org/MPL/
9*f9fbec18Smcpowers *
10*f9fbec18Smcpowers * Software distributed under the License is distributed on an "AS IS" basis,
11*f9fbec18Smcpowers * WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License
12*f9fbec18Smcpowers * for the specific language governing rights and limitations under the
13*f9fbec18Smcpowers * License.
14*f9fbec18Smcpowers *
15*f9fbec18Smcpowers * The Original Code is the elliptic curve math library for prime field curves.
16*f9fbec18Smcpowers *
17*f9fbec18Smcpowers * The Initial Developer of the Original Code is
18*f9fbec18Smcpowers * Sun Microsystems, Inc.
19*f9fbec18Smcpowers * Portions created by the Initial Developer are Copyright (C) 2003
20*f9fbec18Smcpowers * the Initial Developer. All Rights Reserved.
21*f9fbec18Smcpowers *
22*f9fbec18Smcpowers * Contributor(s):
23*f9fbec18Smcpowers * Douglas Stebila <douglas@stebila.ca>, Sun Microsystems Laboratories
24*f9fbec18Smcpowers *
25*f9fbec18Smcpowers * Alternatively, the contents of this file may be used under the terms of
26*f9fbec18Smcpowers * either the GNU General Public License Version 2 or later (the "GPL"), or
27*f9fbec18Smcpowers * the GNU Lesser General Public License Version 2.1 or later (the "LGPL"),
28*f9fbec18Smcpowers * in which case the provisions of the GPL or the LGPL are applicable instead
29*f9fbec18Smcpowers * of those above. If you wish to allow use of your version of this file only
30*f9fbec18Smcpowers * under the terms of either the GPL or the LGPL, and not to allow others to
31*f9fbec18Smcpowers * use your version of this file under the terms of the MPL, indicate your
32*f9fbec18Smcpowers * decision by deleting the provisions above and replace them with the notice
33*f9fbec18Smcpowers * and other provisions required by the GPL or the LGPL. If you do not delete
34*f9fbec18Smcpowers * the provisions above, a recipient may use your version of this file under
35*f9fbec18Smcpowers * the terms of any one of the MPL, the GPL or the LGPL.
36*f9fbec18Smcpowers *
37*f9fbec18Smcpowers * ***** END LICENSE BLOCK ***** */
38*f9fbec18Smcpowers /*
39*f9fbec18Smcpowers * Copyright 2007 Sun Microsystems, Inc. All rights reserved.
40*f9fbec18Smcpowers * Use is subject to license terms.
41*f9fbec18Smcpowers *
42*f9fbec18Smcpowers * Sun elects to use this software under the MPL license.
43*f9fbec18Smcpowers */
44*f9fbec18Smcpowers
45*f9fbec18Smcpowers #pragma ident "%Z%%M% %I% %E% SMI"
46*f9fbec18Smcpowers
47*f9fbec18Smcpowers #ifdef _KERNEL
48*f9fbec18Smcpowers #include <sys/types.h>
49*f9fbec18Smcpowers #include <sys/systm.h>
50*f9fbec18Smcpowers #include <sys/param.h>
51*f9fbec18Smcpowers #include <sys/modctl.h>
52*f9fbec18Smcpowers #include <sys/ddi.h>
53*f9fbec18Smcpowers #include <sys/crypto/spi.h>
54*f9fbec18Smcpowers #include <sys/sysmacros.h>
55*f9fbec18Smcpowers #include <sys/strsun.h>
56*f9fbec18Smcpowers #include <sys/md5.h>
57*f9fbec18Smcpowers #include <sys/sha1.h>
58*f9fbec18Smcpowers #include <sys/sha2.h>
59*f9fbec18Smcpowers #include <sys/random.h>
60*f9fbec18Smcpowers #include <sys/conf.h>
61*f9fbec18Smcpowers #include <sys/devops.h>
62*f9fbec18Smcpowers #include <sys/sunddi.h>
63*f9fbec18Smcpowers #include <sys/varargs.h>
64*f9fbec18Smcpowers #include <sys/kmem.h>
65*f9fbec18Smcpowers #include <sys/kstat.h>
66*f9fbec18Smcpowers #include <sys/crypto/common.h>
67*f9fbec18Smcpowers #else
68*f9fbec18Smcpowers #include <stdio.h>
69*f9fbec18Smcpowers #include <string.h>
70*f9fbec18Smcpowers #include <strings.h>
71*f9fbec18Smcpowers #include <assert.h>
72*f9fbec18Smcpowers #include <time.h>
73*f9fbec18Smcpowers #include <sys/time.h>
74*f9fbec18Smcpowers #include <sys/resource.h>
75*f9fbec18Smcpowers #endif /* _KERNEL */
76*f9fbec18Smcpowers
77*f9fbec18Smcpowers #include "mpi.h"
78*f9fbec18Smcpowers #include "mplogic.h"
79*f9fbec18Smcpowers #include "mpprime.h"
80*f9fbec18Smcpowers #include "ecl.h"
81*f9fbec18Smcpowers #include "ecl-curve.h"
82*f9fbec18Smcpowers #include "ecp.h"
83*f9fbec18Smcpowers #include "ecc_impl.h"
84*f9fbec18Smcpowers #include "ec.h"
85*f9fbec18Smcpowers
86*f9fbec18Smcpowers #ifndef KM_SLEEP
87*f9fbec18Smcpowers #define KM_SLEEP 0
88*f9fbec18Smcpowers #endif
89*f9fbec18Smcpowers
90*f9fbec18Smcpowers #ifndef _KERNEL
91*f9fbec18Smcpowers /* Time k repetitions of operation op. */
92*f9fbec18Smcpowers #define M_TimeOperation(op, k) { \
93*f9fbec18Smcpowers double dStart, dNow, dUserTime; \
94*f9fbec18Smcpowers struct rusage ru; \
95*f9fbec18Smcpowers int i; \
96*f9fbec18Smcpowers getrusage(RUSAGE_SELF, &ru); \
97*f9fbec18Smcpowers dStart = (double)ru.ru_utime.tv_sec+(double)ru.ru_utime.tv_usec*0.000001; \
98*f9fbec18Smcpowers for (i = 0; i < k; i++) { \
99*f9fbec18Smcpowers { op; } \
100*f9fbec18Smcpowers }; \
101*f9fbec18Smcpowers getrusage(RUSAGE_SELF, &ru); \
102*f9fbec18Smcpowers dNow = (double)ru.ru_utime.tv_sec+(double)ru.ru_utime.tv_usec*0.000001; \
103*f9fbec18Smcpowers dUserTime = dNow-dStart; \
104*f9fbec18Smcpowers if (dUserTime) printf(" %-45s k: %6i, t: %6.2f sec\n", #op, k, dUserTime); \
105*f9fbec18Smcpowers }
106*f9fbec18Smcpowers #else
107*f9fbec18Smcpowers #define M_TimeOperation(op, k)
108*f9fbec18Smcpowers #endif
109*f9fbec18Smcpowers
110*f9fbec18Smcpowers /* Test curve using generic field arithmetic. */
111*f9fbec18Smcpowers #define ECTEST_GENERIC_GFP(name_c, name) \
112*f9fbec18Smcpowers printf("Testing %s using generic implementation...\n", name_c); \
113*f9fbec18Smcpowers params = EC_GetNamedCurveParams(name, KM_SLEEP); \
114*f9fbec18Smcpowers if (params == NULL) { \
115*f9fbec18Smcpowers printf(" Error: could not construct params.\n"); \
116*f9fbec18Smcpowers res = MP_NO; \
117*f9fbec18Smcpowers goto CLEANUP; \
118*f9fbec18Smcpowers } \
119*f9fbec18Smcpowers ECGroup_free(group); \
120*f9fbec18Smcpowers group = ECGroup_fromHex(params, KM_SLEEP); \
121*f9fbec18Smcpowers if (group == NULL) { \
122*f9fbec18Smcpowers printf(" Error: could not construct group.\n"); \
123*f9fbec18Smcpowers res = MP_NO; \
124*f9fbec18Smcpowers goto CLEANUP; \
125*f9fbec18Smcpowers } \
126*f9fbec18Smcpowers MP_CHECKOK( ectest_curve_GFp(group, ectestPrint, ectestTime, 1, KM_SLEEP) ); \
127*f9fbec18Smcpowers printf("... okay.\n");
128*f9fbec18Smcpowers
129*f9fbec18Smcpowers /* Test curve using specific field arithmetic. */
130*f9fbec18Smcpowers #define ECTEST_NAMED_GFP(name_c, name) \
131*f9fbec18Smcpowers printf("Testing %s using specific implementation...\n", name_c); \
132*f9fbec18Smcpowers ECGroup_free(group); \
133*f9fbec18Smcpowers group = ECGroup_fromName(name, KM_SLEEP); \
134*f9fbec18Smcpowers if (group == NULL) { \
135*f9fbec18Smcpowers printf(" Warning: could not construct group.\n"); \
136*f9fbec18Smcpowers printf("... failed; continuing with remaining tests.\n"); \
137*f9fbec18Smcpowers } else { \
138*f9fbec18Smcpowers MP_CHECKOK( ectest_curve_GFp(group, ectestPrint, ectestTime, 0, KM_SLEEP) ); \
139*f9fbec18Smcpowers printf("... okay.\n"); \
140*f9fbec18Smcpowers }
141*f9fbec18Smcpowers
142*f9fbec18Smcpowers /* Performs basic tests of elliptic curve cryptography over prime fields.
143*f9fbec18Smcpowers * If tests fail, then it prints an error message, aborts, and returns an
144*f9fbec18Smcpowers * error code. Otherwise, returns 0. */
145*f9fbec18Smcpowers int
ectest_curve_GFp(ECGroup * group,int ectestPrint,int ectestTime,int generic,int kmflag)146*f9fbec18Smcpowers ectest_curve_GFp(ECGroup *group, int ectestPrint, int ectestTime,
147*f9fbec18Smcpowers int generic, int kmflag)
148*f9fbec18Smcpowers {
149*f9fbec18Smcpowers
150*f9fbec18Smcpowers mp_int one, order_1, gx, gy, rx, ry, n;
151*f9fbec18Smcpowers int size;
152*f9fbec18Smcpowers mp_err res;
153*f9fbec18Smcpowers char s[1000];
154*f9fbec18Smcpowers
155*f9fbec18Smcpowers /* initialize values */
156*f9fbec18Smcpowers MP_CHECKOK(mp_init(&one, kmflag));
157*f9fbec18Smcpowers MP_CHECKOK(mp_init(&order_1, kmflag));
158*f9fbec18Smcpowers MP_CHECKOK(mp_init(&gx, kmflag));
159*f9fbec18Smcpowers MP_CHECKOK(mp_init(&gy, kmflag));
160*f9fbec18Smcpowers MP_CHECKOK(mp_init(&rx, kmflag));
161*f9fbec18Smcpowers MP_CHECKOK(mp_init(&ry, kmflag));
162*f9fbec18Smcpowers MP_CHECKOK(mp_init(&n, kmflag));
163*f9fbec18Smcpowers
164*f9fbec18Smcpowers MP_CHECKOK(mp_set_int(&one, 1));
165*f9fbec18Smcpowers MP_CHECKOK(mp_sub(&group->order, &one, &order_1));
166*f9fbec18Smcpowers
167*f9fbec18Smcpowers /* encode base point */
168*f9fbec18Smcpowers if (group->meth->field_dec) {
169*f9fbec18Smcpowers MP_CHECKOK(group->meth->field_dec(&group->genx, &gx, group->meth));
170*f9fbec18Smcpowers MP_CHECKOK(group->meth->field_dec(&group->geny, &gy, group->meth));
171*f9fbec18Smcpowers } else {
172*f9fbec18Smcpowers MP_CHECKOK(mp_copy(&group->genx, &gx));
173*f9fbec18Smcpowers MP_CHECKOK(mp_copy(&group->geny, &gy));
174*f9fbec18Smcpowers }
175*f9fbec18Smcpowers if (ectestPrint) {
176*f9fbec18Smcpowers /* output base point */
177*f9fbec18Smcpowers printf(" base point P:\n");
178*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&gx, s, 16));
179*f9fbec18Smcpowers printf(" %s\n", s);
180*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&gy, s, 16));
181*f9fbec18Smcpowers printf(" %s\n", s);
182*f9fbec18Smcpowers if (group->meth->field_enc) {
183*f9fbec18Smcpowers printf(" base point P (encoded):\n");
184*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&group->genx, s, 16));
185*f9fbec18Smcpowers printf(" %s\n", s);
186*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&group->geny, s, 16));
187*f9fbec18Smcpowers printf(" %s\n", s);
188*f9fbec18Smcpowers }
189*f9fbec18Smcpowers }
190*f9fbec18Smcpowers
191*f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_AFF
192*f9fbec18Smcpowers /* multiply base point by order - 1 and check for negative of base
193*f9fbec18Smcpowers * point */
194*f9fbec18Smcpowers MP_CHECKOK(ec_GFp_pt_mul_aff
195*f9fbec18Smcpowers (&order_1, &group->genx, &group->geny, &rx, &ry, group));
196*f9fbec18Smcpowers if (ectestPrint) {
197*f9fbec18Smcpowers printf(" (order-1)*P (affine):\n");
198*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
199*f9fbec18Smcpowers printf(" %s\n", s);
200*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
201*f9fbec18Smcpowers printf(" %s\n", s);
202*f9fbec18Smcpowers }
203*f9fbec18Smcpowers MP_CHECKOK(group->meth->field_neg(&ry, &ry, group->meth));
204*f9fbec18Smcpowers if ((mp_cmp(&rx, &group->genx) != 0)
205*f9fbec18Smcpowers || (mp_cmp(&ry, &group->geny) != 0)) {
206*f9fbec18Smcpowers printf(" Error: invalid result (expected (- base point)).\n");
207*f9fbec18Smcpowers res = MP_NO;
208*f9fbec18Smcpowers goto CLEANUP;
209*f9fbec18Smcpowers }
210*f9fbec18Smcpowers #endif
211*f9fbec18Smcpowers
212*f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_AFF
213*f9fbec18Smcpowers /* multiply base point by order - 1 and check for negative of base
214*f9fbec18Smcpowers * point */
215*f9fbec18Smcpowers MP_CHECKOK(ec_GFp_pt_mul_jac
216*f9fbec18Smcpowers (&order_1, &group->genx, &group->geny, &rx, &ry, group));
217*f9fbec18Smcpowers if (ectestPrint) {
218*f9fbec18Smcpowers printf(" (order-1)*P (jacobian):\n");
219*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
220*f9fbec18Smcpowers printf(" %s\n", s);
221*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
222*f9fbec18Smcpowers printf(" %s\n", s);
223*f9fbec18Smcpowers }
224*f9fbec18Smcpowers MP_CHECKOK(group->meth->field_neg(&ry, &ry, group->meth));
225*f9fbec18Smcpowers if ((mp_cmp(&rx, &group->genx) != 0)
226*f9fbec18Smcpowers || (mp_cmp(&ry, &group->geny) != 0)) {
227*f9fbec18Smcpowers printf(" Error: invalid result (expected (- base point)).\n");
228*f9fbec18Smcpowers res = MP_NO;
229*f9fbec18Smcpowers goto CLEANUP;
230*f9fbec18Smcpowers }
231*f9fbec18Smcpowers #endif
232*f9fbec18Smcpowers
233*f9fbec18Smcpowers /* multiply base point by order - 1 and check for negative of base
234*f9fbec18Smcpowers * point */
235*f9fbec18Smcpowers MP_CHECKOK(ECPoint_mul(group, &order_1, NULL, NULL, &rx, &ry));
236*f9fbec18Smcpowers if (ectestPrint) {
237*f9fbec18Smcpowers printf(" (order-1)*P (ECPoint_mul):\n");
238*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
239*f9fbec18Smcpowers printf(" %s\n", s);
240*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
241*f9fbec18Smcpowers printf(" %s\n", s);
242*f9fbec18Smcpowers }
243*f9fbec18Smcpowers MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry));
244*f9fbec18Smcpowers if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) {
245*f9fbec18Smcpowers printf(" Error: invalid result (expected (- base point)).\n");
246*f9fbec18Smcpowers res = MP_NO;
247*f9fbec18Smcpowers goto CLEANUP;
248*f9fbec18Smcpowers }
249*f9fbec18Smcpowers
250*f9fbec18Smcpowers /* multiply base point by order - 1 and check for negative of base
251*f9fbec18Smcpowers * point */
252*f9fbec18Smcpowers MP_CHECKOK(ECPoint_mul(group, &order_1, &gx, &gy, &rx, &ry));
253*f9fbec18Smcpowers if (ectestPrint) {
254*f9fbec18Smcpowers printf(" (order-1)*P (ECPoint_mul):\n");
255*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
256*f9fbec18Smcpowers printf(" %s\n", s);
257*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
258*f9fbec18Smcpowers printf(" %s\n", s);
259*f9fbec18Smcpowers }
260*f9fbec18Smcpowers MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry));
261*f9fbec18Smcpowers if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) {
262*f9fbec18Smcpowers printf(" Error: invalid result (expected (- base point)).\n");
263*f9fbec18Smcpowers res = MP_NO;
264*f9fbec18Smcpowers goto CLEANUP;
265*f9fbec18Smcpowers }
266*f9fbec18Smcpowers
267*f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_AFF
268*f9fbec18Smcpowers /* multiply base point by order and check for point at infinity */
269*f9fbec18Smcpowers MP_CHECKOK(ec_GFp_pt_mul_aff
270*f9fbec18Smcpowers (&group->order, &group->genx, &group->geny, &rx, &ry,
271*f9fbec18Smcpowers group));
272*f9fbec18Smcpowers if (ectestPrint) {
273*f9fbec18Smcpowers printf(" (order)*P (affine):\n");
274*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
275*f9fbec18Smcpowers printf(" %s\n", s);
276*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
277*f9fbec18Smcpowers printf(" %s\n", s);
278*f9fbec18Smcpowers }
279*f9fbec18Smcpowers if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) {
280*f9fbec18Smcpowers printf(" Error: invalid result (expected point at infinity).\n");
281*f9fbec18Smcpowers res = MP_NO;
282*f9fbec18Smcpowers goto CLEANUP;
283*f9fbec18Smcpowers }
284*f9fbec18Smcpowers #endif
285*f9fbec18Smcpowers
286*f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_JAC
287*f9fbec18Smcpowers /* multiply base point by order and check for point at infinity */
288*f9fbec18Smcpowers MP_CHECKOK(ec_GFp_pt_mul_jac
289*f9fbec18Smcpowers (&group->order, &group->genx, &group->geny, &rx, &ry,
290*f9fbec18Smcpowers group));
291*f9fbec18Smcpowers if (ectestPrint) {
292*f9fbec18Smcpowers printf(" (order)*P (jacobian):\n");
293*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
294*f9fbec18Smcpowers printf(" %s\n", s);
295*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
296*f9fbec18Smcpowers printf(" %s\n", s);
297*f9fbec18Smcpowers }
298*f9fbec18Smcpowers if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) {
299*f9fbec18Smcpowers printf(" Error: invalid result (expected point at infinity).\n");
300*f9fbec18Smcpowers res = MP_NO;
301*f9fbec18Smcpowers goto CLEANUP;
302*f9fbec18Smcpowers }
303*f9fbec18Smcpowers #endif
304*f9fbec18Smcpowers
305*f9fbec18Smcpowers /* multiply base point by order and check for point at infinity */
306*f9fbec18Smcpowers MP_CHECKOK(ECPoint_mul(group, &group->order, NULL, NULL, &rx, &ry));
307*f9fbec18Smcpowers if (ectestPrint) {
308*f9fbec18Smcpowers printf(" (order)*P (ECPoint_mul):\n");
309*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
310*f9fbec18Smcpowers printf(" %s\n", s);
311*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
312*f9fbec18Smcpowers printf(" %s\n", s);
313*f9fbec18Smcpowers }
314*f9fbec18Smcpowers if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) {
315*f9fbec18Smcpowers printf(" Error: invalid result (expected point at infinity).\n");
316*f9fbec18Smcpowers res = MP_NO;
317*f9fbec18Smcpowers goto CLEANUP;
318*f9fbec18Smcpowers }
319*f9fbec18Smcpowers
320*f9fbec18Smcpowers /* multiply base point by order and check for point at infinity */
321*f9fbec18Smcpowers MP_CHECKOK(ECPoint_mul(group, &group->order, &gx, &gy, &rx, &ry));
322*f9fbec18Smcpowers if (ectestPrint) {
323*f9fbec18Smcpowers printf(" (order)*P (ECPoint_mul):\n");
324*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
325*f9fbec18Smcpowers printf(" %s\n", s);
326*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
327*f9fbec18Smcpowers printf(" %s\n", s);
328*f9fbec18Smcpowers }
329*f9fbec18Smcpowers if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) {
330*f9fbec18Smcpowers printf(" Error: invalid result (expected point at infinity).\n");
331*f9fbec18Smcpowers res = MP_NO;
332*f9fbec18Smcpowers goto CLEANUP;
333*f9fbec18Smcpowers }
334*f9fbec18Smcpowers
335*f9fbec18Smcpowers /* check that (order-1)P + (order-1)P + P == (order-1)P */
336*f9fbec18Smcpowers MP_CHECKOK(ECPoints_mul
337*f9fbec18Smcpowers (group, &order_1, &order_1, &gx, &gy, &rx, &ry));
338*f9fbec18Smcpowers MP_CHECKOK(ECPoints_mul(group, &one, &one, &rx, &ry, &rx, &ry));
339*f9fbec18Smcpowers if (ectestPrint) {
340*f9fbec18Smcpowers printf
341*f9fbec18Smcpowers (" (order-1)*P + (order-1)*P + P == (order-1)*P (ECPoints_mul):\n");
342*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&rx, s, 16));
343*f9fbec18Smcpowers printf(" %s\n", s);
344*f9fbec18Smcpowers MP_CHECKOK(mp_toradix(&ry, s, 16));
345*f9fbec18Smcpowers printf(" %s\n", s);
346*f9fbec18Smcpowers }
347*f9fbec18Smcpowers MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry));
348*f9fbec18Smcpowers if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) {
349*f9fbec18Smcpowers printf(" Error: invalid result (expected (- base point)).\n");
350*f9fbec18Smcpowers res = MP_NO;
351*f9fbec18Smcpowers goto CLEANUP;
352*f9fbec18Smcpowers }
353*f9fbec18Smcpowers
354*f9fbec18Smcpowers /* test validate_point function */
355*f9fbec18Smcpowers if (ECPoint_validate(group, &gx, &gy) != MP_YES) {
356*f9fbec18Smcpowers printf(" Error: validate point on base point failed.\n");
357*f9fbec18Smcpowers res = MP_NO;
358*f9fbec18Smcpowers goto CLEANUP;
359*f9fbec18Smcpowers }
360*f9fbec18Smcpowers MP_CHECKOK(mp_add_d(&gy, 1, &ry));
361*f9fbec18Smcpowers if (ECPoint_validate(group, &gx, &ry) != MP_NO) {
362*f9fbec18Smcpowers printf(" Error: validate point on invalid point passed.\n");
363*f9fbec18Smcpowers res = MP_NO;
364*f9fbec18Smcpowers goto CLEANUP;
365*f9fbec18Smcpowers }
366*f9fbec18Smcpowers
367*f9fbec18Smcpowers if (ectestTime) {
368*f9fbec18Smcpowers /* compute random scalar */
369*f9fbec18Smcpowers size = mpl_significant_bits(&group->meth->irr);
370*f9fbec18Smcpowers if (size < MP_OKAY) {
371*f9fbec18Smcpowers goto CLEANUP;
372*f9fbec18Smcpowers }
373*f9fbec18Smcpowers MP_CHECKOK(mpp_random_size(&n, (size + ECL_BITS - 1) / ECL_BITS));
374*f9fbec18Smcpowers MP_CHECKOK(group->meth->field_mod(&n, &n, group->meth));
375*f9fbec18Smcpowers /* timed test */
376*f9fbec18Smcpowers if (generic) {
377*f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_AFF
378*f9fbec18Smcpowers M_TimeOperation(MP_CHECKOK
379*f9fbec18Smcpowers (ec_GFp_pt_mul_aff
380*f9fbec18Smcpowers (&n, &group->genx, &group->geny, &rx, &ry,
381*f9fbec18Smcpowers group)), 100);
382*f9fbec18Smcpowers #endif
383*f9fbec18Smcpowers M_TimeOperation(MP_CHECKOK
384*f9fbec18Smcpowers (ECPoint_mul(group, &n, NULL, NULL, &rx, &ry)),
385*f9fbec18Smcpowers 100);
386*f9fbec18Smcpowers M_TimeOperation(MP_CHECKOK
387*f9fbec18Smcpowers (ECPoints_mul
388*f9fbec18Smcpowers (group, &n, &n, &gx, &gy, &rx, &ry)), 100);
389*f9fbec18Smcpowers } else {
390*f9fbec18Smcpowers M_TimeOperation(MP_CHECKOK
391*f9fbec18Smcpowers (ECPoint_mul(group, &n, NULL, NULL, &rx, &ry)),
392*f9fbec18Smcpowers 100);
393*f9fbec18Smcpowers M_TimeOperation(MP_CHECKOK
394*f9fbec18Smcpowers (ECPoint_mul(group, &n, &gx, &gy, &rx, &ry)),
395*f9fbec18Smcpowers 100);
396*f9fbec18Smcpowers M_TimeOperation(MP_CHECKOK
397*f9fbec18Smcpowers (ECPoints_mul
398*f9fbec18Smcpowers (group, &n, &n, &gx, &gy, &rx, &ry)), 100);
399*f9fbec18Smcpowers }
400*f9fbec18Smcpowers }
401*f9fbec18Smcpowers
402*f9fbec18Smcpowers CLEANUP:
403*f9fbec18Smcpowers mp_clear(&one);
404*f9fbec18Smcpowers mp_clear(&order_1);
405*f9fbec18Smcpowers mp_clear(&gx);
406*f9fbec18Smcpowers mp_clear(&gy);
407*f9fbec18Smcpowers mp_clear(&rx);
408*f9fbec18Smcpowers mp_clear(&ry);
409*f9fbec18Smcpowers mp_clear(&n);
410*f9fbec18Smcpowers if (res != MP_OKAY) {
411*f9fbec18Smcpowers #ifdef _KERNEL
412*f9fbec18Smcpowers printf(" Error: exiting with error value 0x%x\n", res);
413*f9fbec18Smcpowers #else
414*f9fbec18Smcpowers printf(" Error: exiting with error value %i\n", res);
415*f9fbec18Smcpowers #endif
416*f9fbec18Smcpowers }
417*f9fbec18Smcpowers return res;
418*f9fbec18Smcpowers }
419*f9fbec18Smcpowers
420*f9fbec18Smcpowers /* Performs tests of elliptic curve cryptography over prime fields If
421*f9fbec18Smcpowers * tests fail, then it prints an error message, aborts, and returns an
422*f9fbec18Smcpowers * error code. Otherwise, returns 0. */
423*f9fbec18Smcpowers int
ecp_test()424*f9fbec18Smcpowers ecp_test()
425*f9fbec18Smcpowers {
426*f9fbec18Smcpowers
427*f9fbec18Smcpowers int ectestTime = 0;
428*f9fbec18Smcpowers int ectestPrint = 0;
429*f9fbec18Smcpowers int i;
430*f9fbec18Smcpowers ECGroup *group = NULL;
431*f9fbec18Smcpowers ECCurveParams *params = NULL;
432*f9fbec18Smcpowers mp_err res;
433*f9fbec18Smcpowers
434*f9fbec18Smcpowers /* generic arithmetic tests */
435*f9fbec18Smcpowers ECTEST_GENERIC_GFP("SECP-160R1", ECCurve_SECG_PRIME_160R1);
436*f9fbec18Smcpowers
437*f9fbec18Smcpowers /* specific arithmetic tests */
438*f9fbec18Smcpowers ECTEST_NAMED_GFP("NIST-P192", ECCurve_NIST_P192);
439*f9fbec18Smcpowers ECTEST_NAMED_GFP("NIST-P224", ECCurve_NIST_P224);
440*f9fbec18Smcpowers ECTEST_NAMED_GFP("NIST-P256", ECCurve_NIST_P256);
441*f9fbec18Smcpowers ECTEST_NAMED_GFP("NIST-P384", ECCurve_NIST_P384);
442*f9fbec18Smcpowers ECTEST_NAMED_GFP("NIST-P521", ECCurve_NIST_P521);
443*f9fbec18Smcpowers ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v1", ECCurve_X9_62_PRIME_192V1);
444*f9fbec18Smcpowers ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v2", ECCurve_X9_62_PRIME_192V2);
445*f9fbec18Smcpowers ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v3", ECCurve_X9_62_PRIME_192V3);
446*f9fbec18Smcpowers ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v1", ECCurve_X9_62_PRIME_239V1);
447*f9fbec18Smcpowers ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v2", ECCurve_X9_62_PRIME_239V2);
448*f9fbec18Smcpowers ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v3", ECCurve_X9_62_PRIME_239V3);
449*f9fbec18Smcpowers ECTEST_NAMED_GFP("ANSI X9.62 PRIME256v1", ECCurve_X9_62_PRIME_256V1);
450*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-112R1", ECCurve_SECG_PRIME_112R1);
451*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-112R2", ECCurve_SECG_PRIME_112R2);
452*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-128R1", ECCurve_SECG_PRIME_128R1);
453*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-128R2", ECCurve_SECG_PRIME_128R2);
454*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-160K1", ECCurve_SECG_PRIME_160K1);
455*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-160R1", ECCurve_SECG_PRIME_160R1);
456*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-160R2", ECCurve_SECG_PRIME_160R2);
457*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-192K1", ECCurve_SECG_PRIME_192K1);
458*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-192R1", ECCurve_SECG_PRIME_192R1);
459*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-224K1", ECCurve_SECG_PRIME_224K1);
460*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-224R1", ECCurve_SECG_PRIME_224R1);
461*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-256K1", ECCurve_SECG_PRIME_256K1);
462*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-256R1", ECCurve_SECG_PRIME_256R1);
463*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-384R1", ECCurve_SECG_PRIME_384R1);
464*f9fbec18Smcpowers ECTEST_NAMED_GFP("SECP-521R1", ECCurve_SECG_PRIME_521R1);
465*f9fbec18Smcpowers ECTEST_NAMED_GFP("WTLS-6 (112)", ECCurve_WTLS_6);
466*f9fbec18Smcpowers ECTEST_NAMED_GFP("WTLS-7 (160)", ECCurve_WTLS_7);
467*f9fbec18Smcpowers ECTEST_NAMED_GFP("WTLS-8 (112)", ECCurve_WTLS_8);
468*f9fbec18Smcpowers ECTEST_NAMED_GFP("WTLS-9 (160)", ECCurve_WTLS_9);
469*f9fbec18Smcpowers ECTEST_NAMED_GFP("WTLS-12 (224)", ECCurve_WTLS_12);
470*f9fbec18Smcpowers
471*f9fbec18Smcpowers CLEANUP:
472*f9fbec18Smcpowers EC_FreeCurveParams(params);
473*f9fbec18Smcpowers ECGroup_free(group);
474*f9fbec18Smcpowers if (res != MP_OKAY) {
475*f9fbec18Smcpowers #ifdef _KERNEL
476*f9fbec18Smcpowers printf("Error: exiting with error value 0x%x\n", res);
477*f9fbec18Smcpowers #else
478*f9fbec18Smcpowers printf("Error: exiting with error value %i\n", res);
479*f9fbec18Smcpowers #endif
480*f9fbec18Smcpowers }
481*f9fbec18Smcpowers return res;
482*f9fbec18Smcpowers }
483