1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
|
/*
* (C) 2014,2015 Jack Lloyd
*
* Botan is released under the Simplified BSD License (see license.txt)
*/
#include "tests.h"
#include "test_rng.h"
#if defined(BOTAN_HAS_ECDSA)
#include "test_pubkey.h"
#include <botan/ecdsa.h>
#include <botan/oids.h>
#endif
namespace Botan_Tests {
namespace {
#if defined(BOTAN_HAS_ECDSA)
class ECDSA_Signature_KAT_Tests : public PK_Signature_Generation_Test
{
public:
ECDSA_Signature_KAT_Tests() : PK_Signature_Generation_Test(
"ECDSA",
#if defined(BOTAN_HAS_RFC6979_GENERATOR)
"pubkey/ecdsa_rfc6979.vec",
"Group,X,Hash,Msg,Signature")
#else
"pubkey/ecdsa_prob.vec",
"Group,X,Hash,Msg,Nonce,Signature")
#endif
{}
bool clear_between_callbacks() const override { return false; }
std::unique_ptr<Botan::Private_Key> load_private_key(const VarMap& vars) override
{
const std::string group_id = get_req_str(vars, "Group");
const BigInt x = get_req_bn(vars, "X");
Botan::EC_Group group(Botan::OIDS::lookup(group_id));
std::unique_ptr<Botan::Private_Key> key(new Botan::ECDSA_PrivateKey(Test::rng(), group, x));
return key;
}
std::string default_padding(const VarMap& vars) const override
{
return "EMSA1(" + get_req_str(vars, "Hash") + ")";
}
#if !defined(BOTAN_HAS_RFC6979)
Botan::RandomNumberGenerator* test_rng(const std::vector<uint8_t>& nonce) const override
{
// probabilistic ecdsa signature generation extracts more random than just the nonce,
// but the nonce is extracted first
return new Fixed_Output_Position_RNG(nonce, 1);
}
#endif
};
class ECDSA_Keygen_Tests : public PK_Key_Generation_Test
{
public:
std::vector<std::string> keygen_params() const override { return { "secp256r1", "secp384r1", "secp521r1", "frp256v1" }; }
std::string algo_name() const override { return "ECDSA"; }
};
class ECDSA_Invalid_Key_Tests : public Text_Based_Test
{
public:
ECDSA_Invalid_Key_Tests() :
Text_Based_Test("pubkey/ecdsa_invalid.vec", "Group,InvalidKeyX,InvalidKeyY") {}
bool clear_between_callbacks() const override { return false; }
Test::Result run_one_test(const std::string&, const VarMap& vars) override
{
Test::Result result("ECDSA invalid keys");
const std::string group_id = get_req_str(vars, "Group");
Botan::EC_Group group(Botan::OIDS::lookup(group_id));
const Botan::BigInt x = get_req_bn(vars, "InvalidKeyX");
const Botan::BigInt y = get_req_bn(vars, "InvalidKeyY");
std::unique_ptr<Botan::PointGFp> public_point;
try
{
public_point.reset(new Botan::PointGFp(group.get_curve(), x, y));
}
catch(Botan::Invalid_Argument&)
{
// PointGFp() performs a range check on x, y in [0, p−1],
// which is also part of the EC public key checks, e.g.,
// in NIST SP800-56A rev2, sec. 5.6.2.3.2
result.test_success("public key fails check");
return result;
}
std::unique_ptr<Botan::Public_Key> key(new Botan::ECDSA_PublicKey(group, *public_point));
result.test_eq("public key fails check", key->check_key(Test::rng(), false), false);
return result;
}
};
BOTAN_REGISTER_TEST("ecdsa_sign", ECDSA_Signature_KAT_Tests);
BOTAN_REGISTER_TEST("ecdsa_keygen", ECDSA_Keygen_Tests);
BOTAN_REGISTER_TEST("ecdsa_invalid", ECDSA_Invalid_Key_Tests);
#endif
}
}
|