ecp.py 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310
  1. """Framework classes for generation of ecp test cases."""
  2. # Copyright The Mbed TLS Contributors
  3. # SPDX-License-Identifier: Apache-2.0
  4. #
  5. # Licensed under the Apache License, Version 2.0 (the "License"); you may
  6. # not use this file except in compliance with the License.
  7. # You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  13. # WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. from typing import List
  17. from . import test_data_generation
  18. from . import bignum_common
  19. class EcpTarget(test_data_generation.BaseTarget):
  20. #pylint: disable=abstract-method, too-few-public-methods
  21. """Target for ecp test case generation."""
  22. target_basename = 'test_suite_ecp.generated'
  23. class EcpP192R1Raw(bignum_common.ModOperationCommon,
  24. EcpTarget):
  25. """Test cases for ecp quasi_reduction()."""
  26. symbol = "-"
  27. test_function = "ecp_mod_p192_raw"
  28. test_name = "ecp_mod_p192_raw"
  29. input_style = "fixed"
  30. arity = 1
  31. moduli = ["fffffffffffffffffffffffffffffffeffffffffffffffff"] # type: List[str]
  32. input_values = [
  33. "0", "1",
  34. # Modulus - 1
  35. "fffffffffffffffffffffffffffffffefffffffffffffffe",
  36. # First 8 number generated by random.getrandbits(384) - seed(2,2)
  37. ("cf1822ffbc6887782b491044d5e341245c6e433715ba2bdd"
  38. "177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
  39. ("ffed9235288bc781ae66267594c9c9500925e4749b575bd1"
  40. "3653f8dd9b1f282e4067c3584ee207f8da94e3e8ab73738f"),
  41. ("ef8acd128b4f2fc15f3f57ebf30b94fa82523e86feac7eb7"
  42. "dc38f519b91751dacdbd47d364be8049a372db8f6e405d93"),
  43. ("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045"
  44. "defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2"),
  45. ("2d3d854e061b90303b08c6e33c7295782d6c797f8f7d9b78"
  46. "2a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
  47. ("fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f1"
  48. "5c14bc4a829e07b0829a48d422fe99a22c70501e533c9135"),
  49. ("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561"
  50. "867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2"),
  51. ("bd143fa9b714210c665d7435c1066932f4767f26294365b2"
  52. "721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
  53. # Next 2 number generated by random.getrandbits(192)
  54. "47733e847d718d733ff98ff387c56473a7a83ee0761ebfd2",
  55. "cbd4d3e2d4dec9ef83f0be4e80371eb97f81375eecc1cb63"
  56. ]
  57. @property
  58. def arg_a(self) -> str:
  59. return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
  60. def result(self) -> List[str]:
  61. result = self.int_a % self.int_n
  62. return [self.format_result(result)]
  63. @property
  64. def is_valid(self) -> bool:
  65. return True
  66. class EcpP224R1Raw(bignum_common.ModOperationCommon,
  67. EcpTarget):
  68. """Test cases for ecp quasi_reduction()."""
  69. symbol = "-"
  70. test_function = "ecp_mod_p224_raw"
  71. test_name = "ecp_mod_p224_raw"
  72. input_style = "arch_split"
  73. arity = 1
  74. moduli = ["ffffffffffffffffffffffffffffffff000000000000000000000001"] # type: List[str]
  75. input_values = [
  76. "0", "1",
  77. # Modulus - 1
  78. "ffffffffffffffffffffffffffffffff000000000000000000000000",
  79. # Maximum canonical P224 multiplication result
  80. ("fffffffffffffffffffffffffffffffe000000000000000000000000"
  81. "00000001000000000000000000000000000000000000000000000000"),
  82. # Generate an overflow during reduction
  83. ("00000000000000000000000000010000000070000000002000001000"
  84. "ffffffffffff9fffffffffe00000efff000070000000002000001003"),
  85. # Generate an underflow during reduction
  86. ("00000001000000000000000000000000000000000000000000000000"
  87. "00000000000dc0000000000000000001000000010000000100000003"),
  88. # First 8 number generated by random.getrandbits(448) - seed(2,2)
  89. ("da94e3e8ab73738fcf1822ffbc6887782b491044d5e341245c6e4337"
  90. "15ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
  91. ("cdbd47d364be8049a372db8f6e405d93ffed9235288bc781ae662675"
  92. "94c9c9500925e4749b575bd13653f8dd9b1f282e4067c3584ee207f8"),
  93. ("defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2ef8acd12"
  94. "8b4f2fc15f3f57ebf30b94fa82523e86feac7eb7dc38f519b91751da"),
  95. ("2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a6"
  96. "6148a86fe8624fab5186ee32ee8d7ee9770348a05d300cb90706a045"),
  97. ("8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0829a48d4"
  98. "22fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578"),
  99. ("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561867e5e15"
  100. "bc01bfce6a27e0dfcbf8754472154e76e4c11ab2fec3f6b32e8d4b8a"),
  101. ("a7a83ee0761ebfd2bd143fa9b714210c665d7435c1066932f4767f26"
  102. "294365b2721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
  103. ("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e"
  104. "80371eb97f81375eecc1cb6347733e847d718d733ff98ff387c56473"),
  105. # Next 2 number generated by random.getrandbits(224)
  106. "eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a",
  107. "f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f258ebdbfe3"
  108. ]
  109. @property
  110. def arg_a(self) -> str:
  111. hex_digits = bignum_common.hex_digits_for_limb(448 // self.bits_in_limb, self.bits_in_limb)
  112. return super().format_arg('{:x}'.format(self.int_a)).zfill(hex_digits)
  113. def result(self) -> List[str]:
  114. result = self.int_a % self.int_n
  115. return [self.format_result(result)]
  116. @property
  117. def is_valid(self) -> bool:
  118. return True
  119. class EcpP256R1Raw(bignum_common.ModOperationCommon,
  120. EcpTarget):
  121. """Test cases for ECP P256 fast reduction."""
  122. symbol = "-"
  123. test_function = "ecp_mod_p256_raw"
  124. test_name = "ecp_mod_p256_raw"
  125. input_style = "fixed"
  126. arity = 1
  127. moduli = ["ffffffff00000001000000000000000000000000ffffffffffffffffffffffff"] # type: List[str]
  128. input_values = [
  129. "0", "1",
  130. # Modulus - 1
  131. "ffffffff00000001000000000000000000000000fffffffffffffffffffffffe",
  132. # Maximum canonical P256 multiplication result
  133. ("fffffffe00000002fffffffe0000000100000001fffffffe00000001fffffffc"
  134. "00000003fffffffcfffffffffffffffffffffffc000000000000000000000004"),
  135. # Generate an overflow during reduction
  136. ("0000000000000000000000010000000000000000000000000000000000000000"
  137. "00000000000000000000000000000000000000000000000000000000ffffffff"),
  138. # Generate an underflow during reduction
  139. ("0000000000000000000000000000000000000000000000000000000000000010"
  140. "ffffffff00000000000000000000000000000000000000000000000000000000"),
  141. # Generate an overflow during carry reduction
  142. ("aaaaaaaa00000000000000000000000000000000000000000000000000000000"
  143. "00000000000000000000000000000000aaaaaaacaaaaaaaaaaaaaaaa00000000"),
  144. # Generate an underflow during carry reduction
  145. ("000000000000000000000001ffffffff00000000000000000000000000000000"
  146. "0000000000000000000000000000000000000002000000020000000100000002"),
  147. # First 8 number generated by random.getrandbits(512) - seed(2,2)
  148. ("4067c3584ee207f8da94e3e8ab73738fcf1822ffbc6887782b491044d5e34124"
  149. "5c6e433715ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
  150. ("82523e86feac7eb7dc38f519b91751dacdbd47d364be8049a372db8f6e405d93"
  151. "ffed9235288bc781ae66267594c9c9500925e4749b575bd13653f8dd9b1f282e"),
  152. ("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045defc044a09325626"
  153. "e6b58de744ab6cce80877b6f71e1f6d2ef8acd128b4f2fc15f3f57ebf30b94fa"),
  154. ("829a48d422fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578"
  155. "2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
  156. ("e89204e2e8168561867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2"
  157. "fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0"),
  158. ("bd143fa9b714210c665d7435c1066932f4767f26294365b2721dea3bf63f23d0"
  159. "dbe53fcafb2147df5ca495fa5a91c89b97eeab64ca2ce6bc5d3fd983c34c769f"),
  160. ("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e80371eb9"
  161. "7f81375eecc1cb6347733e847d718d733ff98ff387c56473a7a83ee0761ebfd2"),
  162. ("d08f1bb2531d6460f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f25"
  163. "8ebdbfe3eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a"),
  164. # Next 2 number generated by random.getrandbits(256)
  165. "c5e2486c44a4a8f69dc8db48e86ec9c6e06f291b2a838af8d5c44a4eb3172062",
  166. "d4c0dca8b4c9e755cc9c3adcf515a8234da4daeb4f3f87777ad1f45ae9500ec9"
  167. ]
  168. @property
  169. def arg_a(self) -> str:
  170. return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
  171. def result(self) -> List[str]:
  172. result = self.int_a % self.int_n
  173. return [self.format_result(result)]
  174. @property
  175. def is_valid(self) -> bool:
  176. return True
  177. class EcpP521R1Raw(bignum_common.ModOperationCommon,
  178. EcpTarget):
  179. """Test cases for ecp quasi_reduction()."""
  180. test_function = "ecp_mod_p521_raw"
  181. test_name = "ecp_mod_p521_raw"
  182. input_style = "arch_split"
  183. arity = 1
  184. moduli = [("01ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
  185. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff")
  186. ] # type: List[str]
  187. input_values = [
  188. "0", "1",
  189. # Corner case: maximum canonical P521 multiplication result
  190. ("0003ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
  191. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
  192. "fffff800"
  193. "0000000000000000000000000000000000000000000000000000000000000000"
  194. "0000000000000000000000000000000000000000000000000000000000000004"),
  195. # Test case for overflow during addition
  196. ("0001efffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
  197. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
  198. "000001ef"
  199. "0000000000000000000000000000000000000000000000000000000000000000"
  200. "000000000000000000000000000000000000000000000000000000000f000000"),
  201. # First 8 number generated by random.getrandbits(1042) - seed(2,2)
  202. ("0003cc2e82523e86feac7eb7dc38f519b91751dacdbd47d364be8049a372db8f"
  203. "6e405d93ffed9235288bc781ae66267594c9c9500925e4749b575bd13653f8dd"
  204. "9b1f282e"
  205. "4067c3584ee207f8da94e3e8ab73738fcf1822ffbc6887782b491044d5e34124"
  206. "5c6e433715ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
  207. ("00017052829e07b0829a48d422fe99a22c70501e533c91352d3d854e061b9030"
  208. "3b08c6e33c7295782d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c5055"
  209. "6c71c4a6"
  210. "6148a86fe8624fab5186ee32ee8d7ee9770348a05d300cb90706a045defc044a"
  211. "09325626e6b58de744ab6cce80877b6f71e1f6d2ef8acd128b4f2fc15f3f57eb"),
  212. ("00021f15a7a83ee0761ebfd2bd143fa9b714210c665d7435c1066932f4767f26"
  213. "294365b2721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b97eeab64"
  214. "ca2ce6bc"
  215. "5d3fd983c34c769fe89204e2e8168561867e5e15bc01bfce6a27e0dfcbf87544"
  216. "72154e76e4c11ab2fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f1"),
  217. ("000381bc2a838af8d5c44a4eb3172062d08f1bb2531d6460f0caeef038c89b38"
  218. "a8acb5137c9260dc74e088a9b9492f258ebdbfe3eb9ac688b9d39cca91551e82"
  219. "59cc60b1"
  220. "7604e4b4e73695c3e652c71a74667bffe202849da9643a295a9ac6decbd4d3e2"
  221. "d4dec9ef83f0be4e80371eb97f81375eecc1cb6347733e847d718d733ff98ff3"),
  222. ("00034816c8c69069134bccd3e1cf4f589f8e4ce0af29d115ef24bd625dd961e6"
  223. "830b54fa7d28f93435339774bb1e386c4fd5079e681b8f5896838b769da59b74"
  224. "a6c3181c"
  225. "81e220df848b1df78feb994a81167346d4c0dca8b4c9e755cc9c3adcf515a823"
  226. "4da4daeb4f3f87777ad1f45ae9500ec9c5e2486c44a4a8f69dc8db48e86ec9c6"),
  227. ("000397846c4454b90f756132e16dce72f18e859835e1f291d322a7353ead4efe"
  228. "440e2b4fda9c025a22f1a83185b98f5fc11e60de1b343f52ea748db9e020307a"
  229. "aeb6db2c"
  230. "3a038a709779ac1f45e9dd320c855fdfa7251af0930cdbd30f0ad2a81b2d19a2"
  231. "beaa14a7ff3fe32a30ffc4eed0a7bd04e85bfcdd0227eeb7b9d7d01f5769da05"),
  232. ("00002c3296e6bc4d62b47204007ee4fab105d83e85e951862f0981aebc1b00d9"
  233. "2838e766ef9b6bf2d037fe2e20b6a8464174e75a5f834da70569c018eb2b5693"
  234. "babb7fbb"
  235. "0a76c196067cfdcb11457d9cf45e2fa01d7f4275153924800600571fac3a5b26"
  236. "3fdf57cd2c0064975c3747465cc36c270e8a35b10828d569c268a20eb78ac332"),
  237. ("00009d23b4917fc09f20dbb0dcc93f0e66dfe717c17313394391b6e2e6eacb0f"
  238. "0bb7be72bd6d25009aeb7fa0c4169b148d2f527e72daf0a54ef25c0707e33868"
  239. "7d1f7157"
  240. "5653a45c49390aa51cf5192bbf67da14be11d56ba0b4a2969d8055a9f03f2d71"
  241. "581d8e830112ff0f0948eccaf8877acf26c377c13f719726fd70bddacb4deeec"),
  242. # Next 2 number generated by random.getrandbits(521)
  243. ("12b84ae65e920a63ac1f2b64df6dff07870c9d531ae72a47403063238da1a1fe"
  244. "3f9d6a179fa50f96cd4aff9261aa92c0e6f17ec940639bc2ccdf572df00790813e3"),
  245. ("166049dd332a73fa0b26b75196cf87eb8a09b27ec714307c68c425424a1574f1"
  246. "eedf5b0f16cdfdb839424d201e653f53d6883ca1c107ca6e706649889c0c7f38608")
  247. ]
  248. @property
  249. def arg_a(self) -> str:
  250. # Number of limbs: 2 * N
  251. return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
  252. def result(self) -> List[str]:
  253. result = self.int_a % self.int_n
  254. return [self.format_result(result)]
  255. @property
  256. def is_valid(self) -> bool:
  257. return True