test_suite_psa_crypto_pake.function 51 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177
  1. /* BEGIN_HEADER */
  2. #include <stdint.h>
  3. #include "psa/crypto.h"
  4. typedef enum {
  5. ERR_NONE = 0,
  6. /* errors forced internally in the code */
  7. ERR_INJECT_UNINITIALIZED_ACCESS,
  8. ERR_INJECT_DUPLICATE_SETUP,
  9. ERR_INJECT_SET_USER,
  10. ERR_INJECT_SET_PEER,
  11. ERR_INJECT_SET_ROLE,
  12. ERR_DUPLICATE_SET_USER,
  13. ERR_DUPLICATE_SET_PEER,
  14. ERR_INJECT_EMPTY_IO_BUFFER,
  15. ERR_INJECT_UNKNOWN_STEP,
  16. ERR_INJECT_INVALID_FIRST_STEP,
  17. ERR_INJECT_WRONG_BUFFER_SIZE,
  18. ERR_INJECT_VALID_OPERATION_AFTER_FAILURE,
  19. ERR_INJECT_ANTICIPATE_KEY_DERIVATION_1,
  20. ERR_INJECT_ANTICIPATE_KEY_DERIVATION_2,
  21. ERR_INJECT_ROUND1_CLIENT_KEY_SHARE_PART1,
  22. ERR_INJECT_ROUND1_CLIENT_ZK_PUBLIC_PART1,
  23. ERR_INJECT_ROUND1_CLIENT_ZK_PROOF_PART1,
  24. ERR_INJECT_ROUND1_CLIENT_KEY_SHARE_PART2,
  25. ERR_INJECT_ROUND1_CLIENT_ZK_PUBLIC_PART2,
  26. ERR_INJECT_ROUND1_CLIENT_ZK_PROOF_PART2,
  27. ERR_INJECT_ROUND2_CLIENT_KEY_SHARE,
  28. ERR_INJECT_ROUND2_CLIENT_ZK_PUBLIC,
  29. ERR_INJECT_ROUND2_CLIENT_ZK_PROOF,
  30. ERR_INJECT_ROUND1_SERVER_KEY_SHARE_PART1,
  31. ERR_INJECT_ROUND1_SERVER_ZK_PUBLIC_PART1,
  32. ERR_INJECT_ROUND1_SERVER_ZK_PROOF_PART1,
  33. ERR_INJECT_ROUND1_SERVER_KEY_SHARE_PART2,
  34. ERR_INJECT_ROUND1_SERVER_ZK_PUBLIC_PART2,
  35. ERR_INJECT_ROUND1_SERVER_ZK_PROOF_PART2,
  36. ERR_INJECT_ROUND2_SERVER_KEY_SHARE,
  37. ERR_INJECT_ROUND2_SERVER_ZK_PUBLIC,
  38. ERR_INJECT_ROUND2_SERVER_ZK_PROOF,
  39. /* erros issued from the .data file */
  40. ERR_IN_SETUP,
  41. ERR_IN_SET_USER,
  42. ERR_IN_SET_PEER,
  43. ERR_IN_SET_ROLE,
  44. ERR_IN_SET_PASSWORD_KEY,
  45. ERR_IN_INPUT,
  46. ERR_IN_OUTPUT,
  47. } ecjpake_error_stage_t;
  48. typedef enum {
  49. PAKE_ROUND_ONE,
  50. PAKE_ROUND_TWO
  51. } pake_round_t;
  52. /* The only two JPAKE user/peer identifiers supported for the time being. */
  53. static const uint8_t jpake_server_id[] = { 's', 'e', 'r', 'v', 'e', 'r' };
  54. static const uint8_t jpake_client_id[] = { 'c', 'l', 'i', 'e', 'n', 't' };
  55. /*
  56. * Inject an error on the specified buffer ONLY it this is the correct stage.
  57. * Offset 7 is arbitrary, but chosen because it's "in the middle" of the part
  58. * we're corrupting.
  59. */
  60. #define DO_ROUND_CONDITIONAL_INJECT(this_stage, buf) \
  61. if (this_stage == err_stage) \
  62. { \
  63. *(buf + 7) ^= 1; \
  64. }
  65. #define DO_ROUND_UPDATE_OFFSETS(main_buf_offset, step_offset, step_size) \
  66. { \
  67. step_offset = main_buf_offset; \
  68. main_buf_offset += step_size; \
  69. }
  70. #define DO_ROUND_CHECK_FAILURE() \
  71. if (err_stage != ERR_NONE && status != PSA_SUCCESS) \
  72. { \
  73. TEST_EQUAL(status, expected_error_arg); \
  74. break; \
  75. } \
  76. else \
  77. { \
  78. TEST_EQUAL(status, PSA_SUCCESS); \
  79. }
  80. #if defined(PSA_WANT_ALG_JPAKE)
  81. static void ecjpake_do_round(psa_algorithm_t alg, unsigned int primitive,
  82. psa_pake_operation_t *server,
  83. psa_pake_operation_t *client,
  84. int client_input_first,
  85. pake_round_t round,
  86. ecjpake_error_stage_t err_stage,
  87. int expected_error_arg)
  88. {
  89. unsigned char *buffer0 = NULL, *buffer1 = NULL;
  90. size_t buffer_length = (
  91. PSA_PAKE_OUTPUT_SIZE(alg, primitive, PSA_PAKE_STEP_KEY_SHARE) +
  92. PSA_PAKE_OUTPUT_SIZE(alg, primitive, PSA_PAKE_STEP_ZK_PUBLIC) +
  93. PSA_PAKE_OUTPUT_SIZE(alg, primitive, PSA_PAKE_STEP_ZK_PROOF)) * 2;
  94. /* The output should be exactly this size according to the spec */
  95. const size_t expected_size_key_share =
  96. PSA_PAKE_OUTPUT_SIZE(alg, primitive, PSA_PAKE_STEP_KEY_SHARE);
  97. /* The output should be exactly this size according to the spec */
  98. const size_t expected_size_zk_public =
  99. PSA_PAKE_OUTPUT_SIZE(alg, primitive, PSA_PAKE_STEP_ZK_PUBLIC);
  100. /* The output can be smaller: the spec allows stripping leading zeroes */
  101. const size_t max_expected_size_zk_proof =
  102. PSA_PAKE_OUTPUT_SIZE(alg, primitive, PSA_PAKE_STEP_ZK_PROOF);
  103. size_t buffer0_off = 0;
  104. size_t buffer1_off = 0;
  105. size_t s_g1_len, s_g2_len, s_a_len;
  106. size_t s_g1_off, s_g2_off, s_a_off;
  107. size_t s_x1_pk_len, s_x2_pk_len, s_x2s_pk_len;
  108. size_t s_x1_pk_off, s_x2_pk_off, s_x2s_pk_off;
  109. size_t s_x1_pr_len, s_x2_pr_len, s_x2s_pr_len;
  110. size_t s_x1_pr_off, s_x2_pr_off, s_x2s_pr_off;
  111. size_t c_g1_len, c_g2_len, c_a_len;
  112. size_t c_g1_off, c_g2_off, c_a_off;
  113. size_t c_x1_pk_len, c_x2_pk_len, c_x2s_pk_len;
  114. size_t c_x1_pk_off, c_x2_pk_off, c_x2s_pk_off;
  115. size_t c_x1_pr_len, c_x2_pr_len, c_x2s_pr_len;
  116. size_t c_x1_pr_off, c_x2_pr_off, c_x2s_pr_off;
  117. psa_status_t status;
  118. ASSERT_ALLOC(buffer0, buffer_length);
  119. ASSERT_ALLOC(buffer1, buffer_length);
  120. switch (round) {
  121. case PAKE_ROUND_ONE:
  122. /* Server first round Output */
  123. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_KEY_SHARE,
  124. buffer0 + buffer0_off,
  125. 512 - buffer0_off, &s_g1_len));
  126. TEST_EQUAL(s_g1_len, expected_size_key_share);
  127. DO_ROUND_CONDITIONAL_INJECT(
  128. ERR_INJECT_ROUND1_SERVER_KEY_SHARE_PART1,
  129. buffer0 + buffer0_off);
  130. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_g1_off, s_g1_len);
  131. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_ZK_PUBLIC,
  132. buffer0 + buffer0_off,
  133. 512 - buffer0_off, &s_x1_pk_len));
  134. TEST_EQUAL(s_x1_pk_len, expected_size_zk_public);
  135. DO_ROUND_CONDITIONAL_INJECT(
  136. ERR_INJECT_ROUND1_SERVER_ZK_PUBLIC_PART1,
  137. buffer0 + buffer0_off);
  138. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_x1_pk_off, s_x1_pk_len);
  139. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_ZK_PROOF,
  140. buffer0 + buffer0_off,
  141. 512 - buffer0_off, &s_x1_pr_len));
  142. TEST_LE_U(s_x1_pr_len, max_expected_size_zk_proof);
  143. DO_ROUND_CONDITIONAL_INJECT(
  144. ERR_INJECT_ROUND1_SERVER_ZK_PROOF_PART1,
  145. buffer0 + buffer0_off);
  146. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_x1_pr_off, s_x1_pr_len);
  147. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_KEY_SHARE,
  148. buffer0 + buffer0_off,
  149. 512 - buffer0_off, &s_g2_len));
  150. TEST_EQUAL(s_g2_len, expected_size_key_share);
  151. DO_ROUND_CONDITIONAL_INJECT(
  152. ERR_INJECT_ROUND1_SERVER_KEY_SHARE_PART2,
  153. buffer0 + buffer0_off);
  154. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_g2_off, s_g2_len);
  155. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_ZK_PUBLIC,
  156. buffer0 + buffer0_off,
  157. 512 - buffer0_off, &s_x2_pk_len));
  158. TEST_EQUAL(s_x2_pk_len, expected_size_zk_public);
  159. DO_ROUND_CONDITIONAL_INJECT(
  160. ERR_INJECT_ROUND1_SERVER_ZK_PUBLIC_PART2,
  161. buffer0 + buffer0_off);
  162. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_x2_pk_off, s_x2_pk_len);
  163. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_ZK_PROOF,
  164. buffer0 + buffer0_off,
  165. 512 - buffer0_off, &s_x2_pr_len));
  166. TEST_LE_U(s_x2_pr_len, max_expected_size_zk_proof);
  167. DO_ROUND_CONDITIONAL_INJECT(
  168. ERR_INJECT_ROUND1_SERVER_ZK_PROOF_PART2,
  169. buffer0 + buffer0_off);
  170. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_x2_pr_off, s_x2_pr_len);
  171. /*
  172. * When injecting errors in inputs, the implementation is
  173. * free to detect it right away of with a delay.
  174. * This permits delaying the error until the end of the input
  175. * sequence, if no error appears then, this will be treated
  176. * as an error.
  177. */
  178. if (client_input_first == 1) {
  179. /* Client first round Input */
  180. status = psa_pake_input(client, PSA_PAKE_STEP_KEY_SHARE,
  181. buffer0 + s_g1_off, s_g1_len);
  182. DO_ROUND_CHECK_FAILURE();
  183. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PUBLIC,
  184. buffer0 + s_x1_pk_off,
  185. s_x1_pk_len);
  186. DO_ROUND_CHECK_FAILURE();
  187. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PROOF,
  188. buffer0 + s_x1_pr_off,
  189. s_x1_pr_len);
  190. DO_ROUND_CHECK_FAILURE();
  191. status = psa_pake_input(client, PSA_PAKE_STEP_KEY_SHARE,
  192. buffer0 + s_g2_off,
  193. s_g2_len);
  194. DO_ROUND_CHECK_FAILURE();
  195. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PUBLIC,
  196. buffer0 + s_x2_pk_off,
  197. s_x2_pk_len);
  198. DO_ROUND_CHECK_FAILURE();
  199. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PROOF,
  200. buffer0 + s_x2_pr_off,
  201. s_x2_pr_len);
  202. DO_ROUND_CHECK_FAILURE();
  203. /* Error didn't trigger, make test fail */
  204. if ((err_stage >= ERR_INJECT_ROUND1_SERVER_KEY_SHARE_PART1) &&
  205. (err_stage <= ERR_INJECT_ROUND1_SERVER_ZK_PROOF_PART2)) {
  206. TEST_ASSERT(
  207. !"One of the last psa_pake_input() calls should have returned the expected error.");
  208. }
  209. }
  210. /* Client first round Output */
  211. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_KEY_SHARE,
  212. buffer1 + buffer1_off,
  213. 512 - buffer1_off, &c_g1_len));
  214. TEST_EQUAL(c_g1_len, expected_size_key_share);
  215. DO_ROUND_CONDITIONAL_INJECT(
  216. ERR_INJECT_ROUND1_CLIENT_KEY_SHARE_PART1,
  217. buffer1 + buffer1_off);
  218. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_g1_off, c_g1_len);
  219. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_ZK_PUBLIC,
  220. buffer1 + buffer1_off,
  221. 512 - buffer1_off, &c_x1_pk_len));
  222. TEST_EQUAL(c_x1_pk_len, expected_size_zk_public);
  223. DO_ROUND_CONDITIONAL_INJECT(
  224. ERR_INJECT_ROUND1_CLIENT_ZK_PUBLIC_PART1,
  225. buffer1 + buffer1_off);
  226. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_x1_pk_off, c_x1_pk_len);
  227. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_ZK_PROOF,
  228. buffer1 + buffer1_off,
  229. 512 - buffer1_off, &c_x1_pr_len));
  230. TEST_LE_U(c_x1_pr_len, max_expected_size_zk_proof);
  231. DO_ROUND_CONDITIONAL_INJECT(
  232. ERR_INJECT_ROUND1_CLIENT_ZK_PROOF_PART1,
  233. buffer1 + buffer1_off);
  234. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_x1_pr_off, c_x1_pr_len);
  235. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_KEY_SHARE,
  236. buffer1 + buffer1_off,
  237. 512 - buffer1_off, &c_g2_len));
  238. TEST_EQUAL(c_g2_len, expected_size_key_share);
  239. DO_ROUND_CONDITIONAL_INJECT(
  240. ERR_INJECT_ROUND1_CLIENT_KEY_SHARE_PART2,
  241. buffer1 + buffer1_off);
  242. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_g2_off, c_g2_len);
  243. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_ZK_PUBLIC,
  244. buffer1 + buffer1_off,
  245. 512 - buffer1_off, &c_x2_pk_len));
  246. TEST_EQUAL(c_x2_pk_len, expected_size_zk_public);
  247. DO_ROUND_CONDITIONAL_INJECT(
  248. ERR_INJECT_ROUND1_CLIENT_ZK_PUBLIC_PART2,
  249. buffer1 + buffer1_off);
  250. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_x2_pk_off, c_x2_pk_len);
  251. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_ZK_PROOF,
  252. buffer1 + buffer1_off,
  253. 512 - buffer1_off, &c_x2_pr_len));
  254. TEST_LE_U(c_x2_pr_len, max_expected_size_zk_proof);
  255. DO_ROUND_CONDITIONAL_INJECT(
  256. ERR_INJECT_ROUND1_CLIENT_ZK_PROOF_PART2,
  257. buffer1 + buffer1_off);
  258. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_x2_pr_off, buffer1_off);
  259. if (client_input_first == 0) {
  260. /* Client first round Input */
  261. status = psa_pake_input(client, PSA_PAKE_STEP_KEY_SHARE,
  262. buffer0 + s_g1_off, s_g1_len);
  263. DO_ROUND_CHECK_FAILURE();
  264. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PUBLIC,
  265. buffer0 + s_x1_pk_off,
  266. s_x1_pk_len);
  267. DO_ROUND_CHECK_FAILURE();
  268. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PROOF,
  269. buffer0 + s_x1_pr_off,
  270. s_x1_pr_len);
  271. DO_ROUND_CHECK_FAILURE();
  272. status = psa_pake_input(client, PSA_PAKE_STEP_KEY_SHARE,
  273. buffer0 + s_g2_off,
  274. s_g2_len);
  275. DO_ROUND_CHECK_FAILURE();
  276. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PUBLIC,
  277. buffer0 + s_x2_pk_off,
  278. s_x2_pk_len);
  279. DO_ROUND_CHECK_FAILURE();
  280. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PROOF,
  281. buffer0 + s_x2_pr_off,
  282. s_x2_pr_len);
  283. DO_ROUND_CHECK_FAILURE();
  284. /* Error didn't trigger, make test fail */
  285. if ((err_stage >= ERR_INJECT_ROUND1_SERVER_KEY_SHARE_PART1) &&
  286. (err_stage <= ERR_INJECT_ROUND1_SERVER_ZK_PROOF_PART2)) {
  287. TEST_ASSERT(
  288. !"One of the last psa_pake_input() calls should have returned the expected error.");
  289. }
  290. }
  291. /* Server first round Input */
  292. status = psa_pake_input(server, PSA_PAKE_STEP_KEY_SHARE,
  293. buffer1 + c_g1_off, c_g1_len);
  294. DO_ROUND_CHECK_FAILURE();
  295. status = psa_pake_input(server, PSA_PAKE_STEP_ZK_PUBLIC,
  296. buffer1 + c_x1_pk_off, c_x1_pk_len);
  297. DO_ROUND_CHECK_FAILURE();
  298. status = psa_pake_input(server, PSA_PAKE_STEP_ZK_PROOF,
  299. buffer1 + c_x1_pr_off, c_x1_pr_len);
  300. DO_ROUND_CHECK_FAILURE();
  301. status = psa_pake_input(server, PSA_PAKE_STEP_KEY_SHARE,
  302. buffer1 + c_g2_off, c_g2_len);
  303. DO_ROUND_CHECK_FAILURE();
  304. status = psa_pake_input(server, PSA_PAKE_STEP_ZK_PUBLIC,
  305. buffer1 + c_x2_pk_off, c_x2_pk_len);
  306. DO_ROUND_CHECK_FAILURE();
  307. status = psa_pake_input(server, PSA_PAKE_STEP_ZK_PROOF,
  308. buffer1 + c_x2_pr_off, c_x2_pr_len);
  309. DO_ROUND_CHECK_FAILURE();
  310. /* Error didn't trigger, make test fail */
  311. if ((err_stage >= ERR_INJECT_ROUND1_CLIENT_KEY_SHARE_PART1) &&
  312. (err_stage <= ERR_INJECT_ROUND1_CLIENT_ZK_PROOF_PART2)) {
  313. TEST_ASSERT(
  314. !"One of the last psa_pake_input() calls should have returned the expected error.");
  315. }
  316. break;
  317. case PAKE_ROUND_TWO:
  318. /* Server second round Output */
  319. buffer0_off = 0;
  320. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_KEY_SHARE,
  321. buffer0 + buffer0_off,
  322. 512 - buffer0_off, &s_a_len));
  323. TEST_EQUAL(s_a_len, expected_size_key_share);
  324. DO_ROUND_CONDITIONAL_INJECT(
  325. ERR_INJECT_ROUND2_SERVER_KEY_SHARE,
  326. buffer0 + buffer0_off);
  327. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_a_off, s_a_len);
  328. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_ZK_PUBLIC,
  329. buffer0 + buffer0_off,
  330. 512 - buffer0_off, &s_x2s_pk_len));
  331. TEST_EQUAL(s_x2s_pk_len, expected_size_zk_public);
  332. DO_ROUND_CONDITIONAL_INJECT(
  333. ERR_INJECT_ROUND2_SERVER_ZK_PUBLIC,
  334. buffer0 + buffer0_off);
  335. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_x2s_pk_off, s_x2s_pk_len);
  336. PSA_ASSERT(psa_pake_output(server, PSA_PAKE_STEP_ZK_PROOF,
  337. buffer0 + buffer0_off,
  338. 512 - buffer0_off, &s_x2s_pr_len));
  339. TEST_LE_U(s_x2s_pr_len, max_expected_size_zk_proof);
  340. DO_ROUND_CONDITIONAL_INJECT(
  341. ERR_INJECT_ROUND2_SERVER_ZK_PROOF,
  342. buffer0 + buffer0_off);
  343. DO_ROUND_UPDATE_OFFSETS(buffer0_off, s_x2s_pr_off, s_x2s_pr_len);
  344. if (client_input_first == 1) {
  345. /* Client second round Input */
  346. status = psa_pake_input(client, PSA_PAKE_STEP_KEY_SHARE,
  347. buffer0 + s_a_off, s_a_len);
  348. DO_ROUND_CHECK_FAILURE();
  349. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PUBLIC,
  350. buffer0 + s_x2s_pk_off,
  351. s_x2s_pk_len);
  352. DO_ROUND_CHECK_FAILURE();
  353. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PROOF,
  354. buffer0 + s_x2s_pr_off,
  355. s_x2s_pr_len);
  356. DO_ROUND_CHECK_FAILURE();
  357. /* Error didn't trigger, make test fail */
  358. if ((err_stage >= ERR_INJECT_ROUND2_SERVER_KEY_SHARE) &&
  359. (err_stage <= ERR_INJECT_ROUND2_SERVER_ZK_PROOF)) {
  360. TEST_ASSERT(
  361. !"One of the last psa_pake_input() calls should have returned the expected error.");
  362. }
  363. }
  364. /* Client second round Output */
  365. buffer1_off = 0;
  366. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_KEY_SHARE,
  367. buffer1 + buffer1_off,
  368. 512 - buffer1_off, &c_a_len));
  369. TEST_EQUAL(c_a_len, expected_size_key_share);
  370. DO_ROUND_CONDITIONAL_INJECT(
  371. ERR_INJECT_ROUND2_CLIENT_KEY_SHARE,
  372. buffer1 + buffer1_off);
  373. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_a_off, c_a_len);
  374. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_ZK_PUBLIC,
  375. buffer1 + buffer1_off,
  376. 512 - buffer1_off, &c_x2s_pk_len));
  377. TEST_EQUAL(c_x2s_pk_len, expected_size_zk_public);
  378. DO_ROUND_CONDITIONAL_INJECT(
  379. ERR_INJECT_ROUND2_CLIENT_ZK_PUBLIC,
  380. buffer1 + buffer1_off);
  381. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_x2s_pk_off, c_x2s_pk_len);
  382. PSA_ASSERT(psa_pake_output(client, PSA_PAKE_STEP_ZK_PROOF,
  383. buffer1 + buffer1_off,
  384. 512 - buffer1_off, &c_x2s_pr_len));
  385. TEST_LE_U(c_x2s_pr_len, max_expected_size_zk_proof);
  386. DO_ROUND_CONDITIONAL_INJECT(
  387. ERR_INJECT_ROUND2_CLIENT_ZK_PROOF,
  388. buffer1 + buffer1_off);
  389. DO_ROUND_UPDATE_OFFSETS(buffer1_off, c_x2s_pr_off, c_x2s_pr_len);
  390. if (client_input_first == 0) {
  391. /* Client second round Input */
  392. status = psa_pake_input(client, PSA_PAKE_STEP_KEY_SHARE,
  393. buffer0 + s_a_off, s_a_len);
  394. DO_ROUND_CHECK_FAILURE();
  395. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PUBLIC,
  396. buffer0 + s_x2s_pk_off,
  397. s_x2s_pk_len);
  398. DO_ROUND_CHECK_FAILURE();
  399. status = psa_pake_input(client, PSA_PAKE_STEP_ZK_PROOF,
  400. buffer0 + s_x2s_pr_off,
  401. s_x2s_pr_len);
  402. DO_ROUND_CHECK_FAILURE();
  403. /* Error didn't trigger, make test fail */
  404. if ((err_stage >= ERR_INJECT_ROUND2_SERVER_KEY_SHARE) &&
  405. (err_stage <= ERR_INJECT_ROUND2_SERVER_ZK_PROOF)) {
  406. TEST_ASSERT(
  407. !"One of the last psa_pake_input() calls should have returned the expected error.");
  408. }
  409. }
  410. /* Server second round Input */
  411. status = psa_pake_input(server, PSA_PAKE_STEP_KEY_SHARE,
  412. buffer1 + c_a_off, c_a_len);
  413. DO_ROUND_CHECK_FAILURE();
  414. status = psa_pake_input(server, PSA_PAKE_STEP_ZK_PUBLIC,
  415. buffer1 + c_x2s_pk_off, c_x2s_pk_len);
  416. DO_ROUND_CHECK_FAILURE();
  417. status = psa_pake_input(server, PSA_PAKE_STEP_ZK_PROOF,
  418. buffer1 + c_x2s_pr_off, c_x2s_pr_len);
  419. DO_ROUND_CHECK_FAILURE();
  420. /* Error didn't trigger, make test fail */
  421. if ((err_stage >= ERR_INJECT_ROUND2_CLIENT_KEY_SHARE) &&
  422. (err_stage <= ERR_INJECT_ROUND2_CLIENT_ZK_PROOF)) {
  423. TEST_ASSERT(
  424. !"One of the last psa_pake_input() calls should have returned the expected error.");
  425. }
  426. break;
  427. }
  428. exit:
  429. mbedtls_free(buffer0);
  430. mbedtls_free(buffer1);
  431. }
  432. #endif /* PSA_WANT_ALG_JPAKE */
  433. /*
  434. * This check is used for functions that might either succeed or fail depending
  435. * on the parameters that are passed in from the *.data file:
  436. * - in case of success following functions depend on the current one
  437. * - in case of failure the test is always terminated. There are two options
  438. * here
  439. * - terminated successfully if this exact error was expected at this stage
  440. * - terminated with failure otherwise (either no error was expected at this
  441. * stage or a different error code was expected)
  442. */
  443. #define SETUP_ALWAYS_CHECK_STEP(test_function, this_check_err_stage) \
  444. status = test_function; \
  445. if (err_stage != this_check_err_stage) \
  446. { \
  447. PSA_ASSERT(status); \
  448. } \
  449. else \
  450. { \
  451. TEST_EQUAL(status, expected_error); \
  452. goto exit; \
  453. }
  454. /*
  455. * This check is used for failures that are injected at code level. There's only
  456. * 1 input parameter that is relevant in this case and it's the stage at which
  457. * the error should be injected.
  458. * The check is conditional in this case because, once the error is triggered,
  459. * the pake's context structure is compromised and the setup function cannot
  460. * proceed further. As a consequence the test is terminated.
  461. * The test succeeds if the returned error is exactly the expected one,
  462. * otherwise it fails.
  463. */
  464. #define SETUP_CONDITIONAL_CHECK_STEP(test_function, this_check_err_stage) \
  465. if (err_stage == this_check_err_stage) \
  466. { \
  467. TEST_EQUAL(test_function, expected_error); \
  468. goto exit; \
  469. }
  470. /* END_HEADER */
  471. /* BEGIN_DEPENDENCIES
  472. * depends_on:MBEDTLS_PSA_CRYPTO_C
  473. * END_DEPENDENCIES
  474. */
  475. /* BEGIN_CASE depends_on:PSA_WANT_ALG_JPAKE */
  476. void ecjpake_setup(int alg_arg, int key_type_pw_arg, int key_usage_pw_arg,
  477. int primitive_arg, int hash_arg, char *user_arg, char *peer_arg,
  478. int test_input,
  479. int err_stage_arg,
  480. int expected_error_arg)
  481. {
  482. psa_pake_cipher_suite_t cipher_suite = psa_pake_cipher_suite_init();
  483. psa_pake_operation_t operation = psa_pake_operation_init();
  484. psa_algorithm_t alg = alg_arg;
  485. psa_pake_primitive_t primitive = primitive_arg;
  486. psa_key_type_t key_type_pw = key_type_pw_arg;
  487. psa_key_usage_t key_usage_pw = key_usage_pw_arg;
  488. psa_algorithm_t hash_alg = hash_arg;
  489. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  490. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  491. ecjpake_error_stage_t err_stage = err_stage_arg;
  492. psa_status_t expected_error = expected_error_arg;
  493. psa_status_t status;
  494. unsigned char *output_buffer = NULL;
  495. size_t output_len = 0;
  496. const uint8_t password[] = "abcd";
  497. uint8_t *user = (uint8_t *) user_arg;
  498. uint8_t *peer = (uint8_t *) peer_arg;
  499. size_t user_len = strlen(user_arg);
  500. size_t peer_len = strlen(peer_arg);
  501. psa_key_derivation_operation_t key_derivation =
  502. PSA_KEY_DERIVATION_OPERATION_INIT;
  503. PSA_INIT();
  504. size_t buf_size = PSA_PAKE_OUTPUT_SIZE(alg, primitive_arg,
  505. PSA_PAKE_STEP_KEY_SHARE);
  506. ASSERT_ALLOC(output_buffer, buf_size);
  507. psa_set_key_usage_flags(&attributes, key_usage_pw);
  508. psa_set_key_algorithm(&attributes, alg);
  509. psa_set_key_type(&attributes, key_type_pw);
  510. PSA_ASSERT(psa_import_key(&attributes, password, sizeof(password),
  511. &key));
  512. psa_pake_cs_set_algorithm(&cipher_suite, alg);
  513. psa_pake_cs_set_primitive(&cipher_suite, primitive);
  514. psa_pake_cs_set_hash(&cipher_suite, hash_alg);
  515. PSA_ASSERT(psa_pake_abort(&operation));
  516. if (err_stage == ERR_INJECT_UNINITIALIZED_ACCESS) {
  517. TEST_EQUAL(psa_pake_set_user(&operation, user, user_len),
  518. expected_error);
  519. TEST_EQUAL(psa_pake_set_peer(&operation, peer, peer_len),
  520. expected_error);
  521. TEST_EQUAL(psa_pake_set_password_key(&operation, key),
  522. expected_error);
  523. TEST_EQUAL(psa_pake_set_role(&operation, PSA_PAKE_ROLE_SERVER),
  524. expected_error);
  525. TEST_EQUAL(psa_pake_output(&operation, PSA_PAKE_STEP_KEY_SHARE,
  526. output_buffer, 0, &output_len),
  527. expected_error);
  528. TEST_EQUAL(psa_pake_input(&operation, PSA_PAKE_STEP_KEY_SHARE,
  529. output_buffer, 0),
  530. expected_error);
  531. TEST_EQUAL(psa_pake_get_implicit_key(&operation, &key_derivation),
  532. expected_error);
  533. goto exit;
  534. }
  535. SETUP_ALWAYS_CHECK_STEP(psa_pake_setup(&operation, &cipher_suite),
  536. ERR_IN_SETUP);
  537. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_setup(&operation, &cipher_suite),
  538. ERR_INJECT_DUPLICATE_SETUP);
  539. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_set_role(&operation, PSA_PAKE_ROLE_SERVER),
  540. ERR_INJECT_SET_ROLE);
  541. SETUP_ALWAYS_CHECK_STEP(psa_pake_set_role(&operation, PSA_PAKE_ROLE_NONE),
  542. ERR_IN_SET_ROLE);
  543. SETUP_ALWAYS_CHECK_STEP(psa_pake_set_user(&operation, user, user_len),
  544. ERR_IN_SET_USER);
  545. SETUP_ALWAYS_CHECK_STEP(psa_pake_set_peer(&operation, peer, peer_len),
  546. ERR_IN_SET_PEER);
  547. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_set_user(&operation, user, user_len),
  548. ERR_DUPLICATE_SET_USER);
  549. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_set_peer(&operation, peer, peer_len),
  550. ERR_DUPLICATE_SET_PEER);
  551. SETUP_ALWAYS_CHECK_STEP(psa_pake_set_password_key(&operation, key),
  552. ERR_IN_SET_PASSWORD_KEY);
  553. const size_t size_key_share = PSA_PAKE_INPUT_SIZE(alg, primitive,
  554. PSA_PAKE_STEP_KEY_SHARE);
  555. const size_t size_zk_public = PSA_PAKE_INPUT_SIZE(alg, primitive,
  556. PSA_PAKE_STEP_ZK_PUBLIC);
  557. const size_t size_zk_proof = PSA_PAKE_INPUT_SIZE(alg, primitive,
  558. PSA_PAKE_STEP_ZK_PROOF);
  559. if (test_input) {
  560. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_input(&operation,
  561. PSA_PAKE_STEP_ZK_PROOF,
  562. output_buffer, 0),
  563. ERR_INJECT_EMPTY_IO_BUFFER);
  564. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_input(&operation,
  565. PSA_PAKE_STEP_ZK_PROOF + 10,
  566. output_buffer, size_zk_proof),
  567. ERR_INJECT_UNKNOWN_STEP);
  568. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_input(&operation,
  569. PSA_PAKE_STEP_ZK_PROOF,
  570. output_buffer, size_zk_proof),
  571. ERR_INJECT_INVALID_FIRST_STEP)
  572. SETUP_ALWAYS_CHECK_STEP(psa_pake_input(&operation,
  573. PSA_PAKE_STEP_KEY_SHARE,
  574. output_buffer, size_key_share),
  575. ERR_IN_INPUT);
  576. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_input(&operation,
  577. PSA_PAKE_STEP_ZK_PUBLIC,
  578. output_buffer, size_zk_public + 1),
  579. ERR_INJECT_WRONG_BUFFER_SIZE);
  580. SETUP_CONDITIONAL_CHECK_STEP(
  581. (psa_pake_input(&operation, PSA_PAKE_STEP_ZK_PUBLIC,
  582. output_buffer, size_zk_public + 1),
  583. psa_pake_input(&operation, PSA_PAKE_STEP_ZK_PUBLIC,
  584. output_buffer, size_zk_public)),
  585. ERR_INJECT_VALID_OPERATION_AFTER_FAILURE);
  586. } else {
  587. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_output(&operation,
  588. PSA_PAKE_STEP_ZK_PROOF,
  589. output_buffer, 0,
  590. &output_len),
  591. ERR_INJECT_EMPTY_IO_BUFFER);
  592. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_output(&operation,
  593. PSA_PAKE_STEP_ZK_PROOF + 10,
  594. output_buffer, buf_size, &output_len),
  595. ERR_INJECT_UNKNOWN_STEP);
  596. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_output(&operation,
  597. PSA_PAKE_STEP_ZK_PROOF,
  598. output_buffer, buf_size, &output_len),
  599. ERR_INJECT_INVALID_FIRST_STEP);
  600. SETUP_ALWAYS_CHECK_STEP(psa_pake_output(&operation,
  601. PSA_PAKE_STEP_KEY_SHARE,
  602. output_buffer, buf_size, &output_len),
  603. ERR_IN_OUTPUT);
  604. TEST_ASSERT(output_len > 0);
  605. SETUP_CONDITIONAL_CHECK_STEP(psa_pake_output(&operation,
  606. PSA_PAKE_STEP_ZK_PUBLIC,
  607. output_buffer, size_zk_public - 1,
  608. &output_len),
  609. ERR_INJECT_WRONG_BUFFER_SIZE);
  610. SETUP_CONDITIONAL_CHECK_STEP(
  611. (psa_pake_output(&operation, PSA_PAKE_STEP_ZK_PUBLIC,
  612. output_buffer, size_zk_public - 1, &output_len),
  613. psa_pake_output(&operation, PSA_PAKE_STEP_ZK_PUBLIC,
  614. output_buffer, buf_size, &output_len)),
  615. ERR_INJECT_VALID_OPERATION_AFTER_FAILURE);
  616. }
  617. exit:
  618. PSA_ASSERT(psa_destroy_key(key));
  619. PSA_ASSERT(psa_pake_abort(&operation));
  620. mbedtls_free(output_buffer);
  621. PSA_DONE();
  622. }
  623. /* END_CASE */
  624. /* BEGIN_CASE depends_on:PSA_WANT_ALG_JPAKE */
  625. void ecjpake_rounds_inject(int alg_arg, int primitive_arg, int hash_arg,
  626. int client_input_first,
  627. data_t *pw_data,
  628. int err_stage_arg,
  629. int expected_error_arg)
  630. {
  631. psa_pake_cipher_suite_t cipher_suite = psa_pake_cipher_suite_init();
  632. psa_pake_operation_t server = psa_pake_operation_init();
  633. psa_pake_operation_t client = psa_pake_operation_init();
  634. psa_algorithm_t alg = alg_arg;
  635. psa_algorithm_t hash_alg = hash_arg;
  636. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  637. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  638. ecjpake_error_stage_t err_stage = err_stage_arg;
  639. PSA_INIT();
  640. psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DERIVE);
  641. psa_set_key_algorithm(&attributes, alg);
  642. psa_set_key_type(&attributes, PSA_KEY_TYPE_PASSWORD);
  643. PSA_ASSERT(psa_import_key(&attributes, pw_data->x, pw_data->len,
  644. &key));
  645. psa_pake_cs_set_algorithm(&cipher_suite, alg);
  646. psa_pake_cs_set_primitive(&cipher_suite, primitive_arg);
  647. psa_pake_cs_set_hash(&cipher_suite, hash_alg);
  648. PSA_ASSERT(psa_pake_setup(&server, &cipher_suite));
  649. PSA_ASSERT(psa_pake_setup(&client, &cipher_suite));
  650. PSA_ASSERT(psa_pake_set_user(&server, jpake_server_id, sizeof(jpake_server_id)));
  651. PSA_ASSERT(psa_pake_set_peer(&server, jpake_client_id, sizeof(jpake_client_id)));
  652. PSA_ASSERT(psa_pake_set_user(&client, jpake_client_id, sizeof(jpake_client_id)));
  653. PSA_ASSERT(psa_pake_set_peer(&client, jpake_server_id, sizeof(jpake_server_id)));
  654. PSA_ASSERT(psa_pake_set_password_key(&server, key));
  655. PSA_ASSERT(psa_pake_set_password_key(&client, key));
  656. ecjpake_do_round(alg, primitive_arg, &server, &client,
  657. client_input_first, PAKE_ROUND_ONE,
  658. err_stage, expected_error_arg);
  659. if (err_stage != ERR_NONE) {
  660. goto exit;
  661. }
  662. ecjpake_do_round(alg, primitive_arg, &server, &client,
  663. client_input_first, PAKE_ROUND_TWO,
  664. err_stage, expected_error_arg);
  665. exit:
  666. psa_destroy_key(key);
  667. psa_pake_abort(&server);
  668. psa_pake_abort(&client);
  669. PSA_DONE();
  670. }
  671. /* END_CASE */
  672. /* BEGIN_CASE depends_on:PSA_WANT_ALG_JPAKE */
  673. void ecjpake_rounds(int alg_arg, int primitive_arg, int hash_arg,
  674. int derive_alg_arg, data_t *pw_data,
  675. int client_input_first, int destroy_key,
  676. int err_stage_arg)
  677. {
  678. psa_pake_cipher_suite_t cipher_suite = psa_pake_cipher_suite_init();
  679. psa_pake_operation_t server = psa_pake_operation_init();
  680. psa_pake_operation_t client = psa_pake_operation_init();
  681. psa_algorithm_t alg = alg_arg;
  682. psa_algorithm_t hash_alg = hash_arg;
  683. psa_algorithm_t derive_alg = derive_alg_arg;
  684. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  685. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  686. psa_key_derivation_operation_t server_derive =
  687. PSA_KEY_DERIVATION_OPERATION_INIT;
  688. psa_key_derivation_operation_t client_derive =
  689. PSA_KEY_DERIVATION_OPERATION_INIT;
  690. ecjpake_error_stage_t err_stage = err_stage_arg;
  691. PSA_INIT();
  692. psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DERIVE);
  693. psa_set_key_algorithm(&attributes, alg);
  694. psa_set_key_type(&attributes, PSA_KEY_TYPE_PASSWORD);
  695. PSA_ASSERT(psa_import_key(&attributes, pw_data->x, pw_data->len,
  696. &key));
  697. psa_pake_cs_set_algorithm(&cipher_suite, alg);
  698. psa_pake_cs_set_primitive(&cipher_suite, primitive_arg);
  699. psa_pake_cs_set_hash(&cipher_suite, hash_alg);
  700. /* Get shared key */
  701. PSA_ASSERT(psa_key_derivation_setup(&server_derive, derive_alg));
  702. PSA_ASSERT(psa_key_derivation_setup(&client_derive, derive_alg));
  703. if (PSA_ALG_IS_TLS12_PRF(derive_alg) ||
  704. PSA_ALG_IS_TLS12_PSK_TO_MS(derive_alg)) {
  705. PSA_ASSERT(psa_key_derivation_input_bytes(&server_derive,
  706. PSA_KEY_DERIVATION_INPUT_SEED,
  707. (const uint8_t *) "", 0));
  708. PSA_ASSERT(psa_key_derivation_input_bytes(&client_derive,
  709. PSA_KEY_DERIVATION_INPUT_SEED,
  710. (const uint8_t *) "", 0));
  711. }
  712. PSA_ASSERT(psa_pake_setup(&server, &cipher_suite));
  713. PSA_ASSERT(psa_pake_setup(&client, &cipher_suite));
  714. PSA_ASSERT(psa_pake_set_user(&server, jpake_server_id, sizeof(jpake_server_id)));
  715. PSA_ASSERT(psa_pake_set_peer(&server, jpake_client_id, sizeof(jpake_client_id)));
  716. PSA_ASSERT(psa_pake_set_user(&client, jpake_client_id, sizeof(jpake_client_id)));
  717. PSA_ASSERT(psa_pake_set_peer(&client, jpake_server_id, sizeof(jpake_server_id)));
  718. PSA_ASSERT(psa_pake_set_password_key(&server, key));
  719. PSA_ASSERT(psa_pake_set_password_key(&client, key));
  720. if (destroy_key == 1) {
  721. psa_destroy_key(key);
  722. }
  723. if (err_stage == ERR_INJECT_ANTICIPATE_KEY_DERIVATION_1) {
  724. TEST_EQUAL(psa_pake_get_implicit_key(&server, &server_derive),
  725. PSA_ERROR_BAD_STATE);
  726. TEST_EQUAL(psa_pake_get_implicit_key(&client, &client_derive),
  727. PSA_ERROR_BAD_STATE);
  728. goto exit;
  729. }
  730. /* First round */
  731. ecjpake_do_round(alg, primitive_arg, &server, &client,
  732. client_input_first, PAKE_ROUND_ONE,
  733. ERR_NONE, PSA_SUCCESS);
  734. if (err_stage == ERR_INJECT_ANTICIPATE_KEY_DERIVATION_2) {
  735. TEST_EQUAL(psa_pake_get_implicit_key(&server, &server_derive),
  736. PSA_ERROR_BAD_STATE);
  737. TEST_EQUAL(psa_pake_get_implicit_key(&client, &client_derive),
  738. PSA_ERROR_BAD_STATE);
  739. goto exit;
  740. }
  741. /* Second round */
  742. ecjpake_do_round(alg, primitive_arg, &server, &client,
  743. client_input_first, PAKE_ROUND_TWO,
  744. ERR_NONE, PSA_SUCCESS);
  745. PSA_ASSERT(psa_pake_get_implicit_key(&server, &server_derive));
  746. PSA_ASSERT(psa_pake_get_implicit_key(&client, &client_derive));
  747. exit:
  748. psa_key_derivation_abort(&server_derive);
  749. psa_key_derivation_abort(&client_derive);
  750. psa_destroy_key(key);
  751. psa_pake_abort(&server);
  752. psa_pake_abort(&client);
  753. PSA_DONE();
  754. }
  755. /* END_CASE */
  756. /* BEGIN_CASE */
  757. void ecjpake_size_macros()
  758. {
  759. const psa_algorithm_t alg = PSA_ALG_JPAKE;
  760. const size_t bits = 256;
  761. const psa_pake_primitive_t prim = PSA_PAKE_PRIMITIVE(
  762. PSA_PAKE_PRIMITIVE_TYPE_ECC, PSA_ECC_FAMILY_SECP_R1, bits);
  763. const psa_key_type_t key_type = PSA_KEY_TYPE_ECC_KEY_PAIR(
  764. PSA_ECC_FAMILY_SECP_R1);
  765. // https://armmbed.github.io/mbed-crypto/1.1_PAKE_Extension.0-bet.0/html/pake.html#pake-step-types
  766. /* The output for KEY_SHARE and ZK_PUBLIC is the same as a public key */
  767. TEST_EQUAL(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_KEY_SHARE),
  768. PSA_EXPORT_PUBLIC_KEY_OUTPUT_SIZE(key_type, bits));
  769. TEST_EQUAL(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PUBLIC),
  770. PSA_EXPORT_PUBLIC_KEY_OUTPUT_SIZE(key_type, bits));
  771. /* The output for ZK_PROOF is the same bitsize as the curve */
  772. TEST_EQUAL(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PROOF),
  773. PSA_BITS_TO_BYTES(bits));
  774. /* Input sizes are the same as output sizes */
  775. TEST_EQUAL(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_KEY_SHARE),
  776. PSA_PAKE_INPUT_SIZE(alg, prim, PSA_PAKE_STEP_KEY_SHARE));
  777. TEST_EQUAL(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PUBLIC),
  778. PSA_PAKE_INPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PUBLIC));
  779. TEST_EQUAL(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PROOF),
  780. PSA_PAKE_INPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PROOF));
  781. /* These inequalities will always hold even when other PAKEs are added */
  782. TEST_LE_U(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_KEY_SHARE),
  783. PSA_PAKE_OUTPUT_MAX_SIZE);
  784. TEST_LE_U(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PUBLIC),
  785. PSA_PAKE_OUTPUT_MAX_SIZE);
  786. TEST_LE_U(PSA_PAKE_OUTPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PROOF),
  787. PSA_PAKE_OUTPUT_MAX_SIZE);
  788. TEST_LE_U(PSA_PAKE_INPUT_SIZE(alg, prim, PSA_PAKE_STEP_KEY_SHARE),
  789. PSA_PAKE_INPUT_MAX_SIZE);
  790. TEST_LE_U(PSA_PAKE_INPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PUBLIC),
  791. PSA_PAKE_INPUT_MAX_SIZE);
  792. TEST_LE_U(PSA_PAKE_INPUT_SIZE(alg, prim, PSA_PAKE_STEP_ZK_PROOF),
  793. PSA_PAKE_INPUT_MAX_SIZE);
  794. }
  795. /* END_CASE */
  796. /* BEGIN_CASE depends_on:PSA_WANT_ALG_JPAKE */
  797. void pake_input_getters_password()
  798. {
  799. psa_pake_cipher_suite_t cipher_suite = psa_pake_cipher_suite_init();
  800. psa_pake_operation_t operation = psa_pake_operation_init();
  801. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  802. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  803. const char *password = "password";
  804. uint8_t password_ret[20] = { 0 }; // max key length is 20 bytes
  805. size_t password_len_ret = 0;
  806. size_t buffer_len_ret = 0;
  807. psa_pake_primitive_t primitive = PSA_PAKE_PRIMITIVE(
  808. PSA_PAKE_PRIMITIVE_TYPE_ECC,
  809. PSA_ECC_FAMILY_SECP_R1, 256);
  810. PSA_INIT();
  811. psa_pake_cs_set_algorithm(&cipher_suite, PSA_ALG_JPAKE);
  812. psa_pake_cs_set_primitive(&cipher_suite, primitive);
  813. psa_pake_cs_set_hash(&cipher_suite, PSA_ALG_SHA_256);
  814. psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DERIVE);
  815. psa_set_key_algorithm(&attributes, PSA_ALG_JPAKE);
  816. psa_set_key_type(&attributes, PSA_KEY_TYPE_PASSWORD);
  817. PSA_ASSERT(psa_pake_setup(&operation, &cipher_suite));
  818. PSA_ASSERT(psa_import_key(&attributes, (uint8_t *) password, strlen(password), &key));
  819. TEST_EQUAL(psa_crypto_driver_pake_get_password(&operation.data.inputs,
  820. (uint8_t *) &password_ret,
  821. 10, &buffer_len_ret),
  822. PSA_ERROR_BAD_STATE);
  823. TEST_EQUAL(psa_crypto_driver_pake_get_password_len(&operation.data.inputs, &password_len_ret),
  824. PSA_ERROR_BAD_STATE);
  825. PSA_ASSERT(psa_pake_set_password_key(&operation, key));
  826. TEST_EQUAL(psa_crypto_driver_pake_get_password_len(&operation.data.inputs, &password_len_ret),
  827. PSA_SUCCESS);
  828. TEST_EQUAL(password_len_ret, strlen(password));
  829. TEST_EQUAL(psa_crypto_driver_pake_get_password(&operation.data.inputs,
  830. (uint8_t *) &password_ret,
  831. password_len_ret - 1,
  832. &buffer_len_ret),
  833. PSA_ERROR_BUFFER_TOO_SMALL);
  834. TEST_EQUAL(psa_crypto_driver_pake_get_password(&operation.data.inputs,
  835. (uint8_t *) &password_ret,
  836. password_len_ret,
  837. &buffer_len_ret),
  838. PSA_SUCCESS);
  839. TEST_EQUAL(buffer_len_ret, strlen(password));
  840. PSA_ASSERT(memcmp(password_ret, password, buffer_len_ret));
  841. exit:
  842. PSA_ASSERT(psa_destroy_key(key));
  843. PSA_ASSERT(psa_pake_abort(&operation));
  844. PSA_DONE();
  845. }
  846. /* END_CASE */
  847. /* BEGIN_CASE depends_on:PSA_WANT_ALG_JPAKE */
  848. void pake_input_getters_cipher_suite()
  849. {
  850. psa_pake_cipher_suite_t cipher_suite = psa_pake_cipher_suite_init();
  851. psa_pake_operation_t operation = psa_pake_operation_init();
  852. psa_pake_cipher_suite_t cipher_suite_ret = psa_pake_cipher_suite_init();
  853. psa_pake_primitive_t primitive = PSA_PAKE_PRIMITIVE(
  854. PSA_PAKE_PRIMITIVE_TYPE_ECC,
  855. PSA_ECC_FAMILY_SECP_R1, 256);
  856. PSA_INIT();
  857. psa_pake_cs_set_algorithm(&cipher_suite, PSA_ALG_JPAKE);
  858. psa_pake_cs_set_primitive(&cipher_suite, primitive);
  859. psa_pake_cs_set_hash(&cipher_suite, PSA_ALG_SHA_256);
  860. TEST_EQUAL(psa_crypto_driver_pake_get_cipher_suite(&operation.data.inputs, &cipher_suite_ret),
  861. PSA_ERROR_BAD_STATE);
  862. PSA_ASSERT(psa_pake_setup(&operation, &cipher_suite));
  863. TEST_EQUAL(psa_crypto_driver_pake_get_cipher_suite(&operation.data.inputs, &cipher_suite_ret),
  864. PSA_SUCCESS);
  865. PSA_ASSERT(memcmp(&cipher_suite_ret, &cipher_suite, sizeof(cipher_suite)));
  866. exit:
  867. PSA_ASSERT(psa_pake_abort(&operation));
  868. PSA_DONE();
  869. }
  870. /* END_CASE */
  871. /* BEGIN_CASE depends_on:PSA_WANT_ALG_JPAKE */
  872. void pake_input_getters_role()
  873. {
  874. psa_pake_cipher_suite_t cipher_suite = psa_pake_cipher_suite_init();
  875. psa_pake_operation_t operation = psa_pake_operation_init();
  876. psa_pake_role_t role_ret = PSA_PAKE_ROLE_NONE;
  877. psa_pake_primitive_t primitive = PSA_PAKE_PRIMITIVE(
  878. PSA_PAKE_PRIMITIVE_TYPE_ECC,
  879. PSA_ECC_FAMILY_SECP_R1, 256);
  880. PSA_INIT();
  881. psa_pake_cs_set_algorithm(&cipher_suite, PSA_ALG_JPAKE);
  882. psa_pake_cs_set_primitive(&cipher_suite, primitive);
  883. psa_pake_cs_set_hash(&cipher_suite, PSA_ALG_SHA_256);
  884. PSA_ASSERT(psa_pake_setup(&operation, &cipher_suite));
  885. TEST_EQUAL(psa_crypto_driver_pake_get_role(&operation.data.inputs, &role_ret),
  886. PSA_ERROR_BAD_STATE);
  887. /* Role can not be set directly using psa_pake_set_role(). It is set by the core
  888. based on given user/peer identifiers. Simulate that Role is already set. */
  889. operation.data.inputs.role = PSA_PAKE_ROLE_SERVER;
  890. TEST_EQUAL(psa_crypto_driver_pake_get_role(&operation.data.inputs, &role_ret),
  891. PSA_SUCCESS);
  892. TEST_EQUAL(role_ret, PSA_PAKE_ROLE_SERVER);
  893. exit:
  894. PSA_ASSERT(psa_pake_abort(&operation));
  895. PSA_DONE();
  896. }
  897. /* END_CASE */
  898. /* BEGIN_CASE depends_on:PSA_WANT_ALG_JPAKE */
  899. void pake_input_getters_user()
  900. {
  901. psa_pake_cipher_suite_t cipher_suite = psa_pake_cipher_suite_init();
  902. psa_pake_operation_t operation = psa_pake_operation_init();
  903. const uint8_t user[] = { 's', 'e', 'r', 'v', 'e', 'r' };
  904. const size_t user_len = sizeof(user);
  905. uint8_t user_ret[20] = { 0 }; // max user length is 20 bytes
  906. size_t user_len_ret = 0;
  907. size_t buffer_len_ret = 0;
  908. psa_pake_primitive_t primitive = PSA_PAKE_PRIMITIVE(
  909. PSA_PAKE_PRIMITIVE_TYPE_ECC,
  910. PSA_ECC_FAMILY_SECP_R1, 256);
  911. PSA_INIT();
  912. psa_pake_cs_set_algorithm(&cipher_suite, PSA_ALG_JPAKE);
  913. psa_pake_cs_set_primitive(&cipher_suite, primitive);
  914. psa_pake_cs_set_hash(&cipher_suite, PSA_ALG_SHA_256);
  915. PSA_ASSERT(psa_pake_setup(&operation, &cipher_suite));
  916. TEST_EQUAL(psa_crypto_driver_pake_get_user(&operation.data.inputs,
  917. (uint8_t *) &user_ret,
  918. 10, &buffer_len_ret),
  919. PSA_ERROR_BAD_STATE);
  920. TEST_EQUAL(psa_crypto_driver_pake_get_user_len(&operation.data.inputs, &user_len_ret),
  921. PSA_ERROR_BAD_STATE);
  922. PSA_ASSERT(psa_pake_set_user(&operation, user, user_len));
  923. TEST_EQUAL(psa_crypto_driver_pake_get_user_len(&operation.data.inputs, &user_len_ret),
  924. PSA_SUCCESS);
  925. TEST_EQUAL(user_len_ret, user_len);
  926. TEST_EQUAL(psa_crypto_driver_pake_get_user(&operation.data.inputs,
  927. (uint8_t *) &user_ret,
  928. user_len_ret - 1,
  929. &buffer_len_ret),
  930. PSA_ERROR_BUFFER_TOO_SMALL);
  931. TEST_EQUAL(psa_crypto_driver_pake_get_user(&operation.data.inputs,
  932. (uint8_t *) &user_ret,
  933. user_len_ret,
  934. &buffer_len_ret),
  935. PSA_SUCCESS);
  936. TEST_EQUAL(buffer_len_ret, user_len);
  937. PSA_ASSERT(memcmp(user_ret, user, buffer_len_ret));
  938. exit:
  939. PSA_ASSERT(psa_pake_abort(&operation));
  940. PSA_DONE();
  941. }
  942. /* END_CASE */
  943. /* BEGIN_CASE depends_on:PSA_WANT_ALG_JPAKE */
  944. void pake_input_getters_peer()
  945. {
  946. psa_pake_cipher_suite_t cipher_suite = psa_pake_cipher_suite_init();
  947. psa_pake_operation_t operation = psa_pake_operation_init();
  948. const uint8_t peer[] = { 's', 'e', 'r', 'v', 'e', 'r' };
  949. const size_t peer_len = sizeof(peer);
  950. uint8_t peer_ret[20] = { 0 }; // max peer length is 20 bytes
  951. size_t peer_len_ret = 0;
  952. size_t buffer_len_ret = 0;
  953. psa_pake_primitive_t primitive = PSA_PAKE_PRIMITIVE(
  954. PSA_PAKE_PRIMITIVE_TYPE_ECC,
  955. PSA_ECC_FAMILY_SECP_R1, 256);
  956. PSA_INIT();
  957. psa_pake_cs_set_algorithm(&cipher_suite, PSA_ALG_JPAKE);
  958. psa_pake_cs_set_primitive(&cipher_suite, primitive);
  959. psa_pake_cs_set_hash(&cipher_suite, PSA_ALG_SHA_256);
  960. PSA_ASSERT(psa_pake_setup(&operation, &cipher_suite));
  961. TEST_EQUAL(psa_crypto_driver_pake_get_peer(&operation.data.inputs,
  962. (uint8_t *) &peer_ret,
  963. 10, &buffer_len_ret),
  964. PSA_ERROR_BAD_STATE);
  965. TEST_EQUAL(psa_crypto_driver_pake_get_peer_len(&operation.data.inputs, &peer_len_ret),
  966. PSA_ERROR_BAD_STATE);
  967. PSA_ASSERT(psa_pake_set_peer(&operation, peer, peer_len));
  968. TEST_EQUAL(psa_crypto_driver_pake_get_peer_len(&operation.data.inputs, &peer_len_ret),
  969. PSA_SUCCESS);
  970. TEST_EQUAL(peer_len_ret, peer_len);
  971. TEST_EQUAL(psa_crypto_driver_pake_get_peer(&operation.data.inputs,
  972. (uint8_t *) &peer_ret,
  973. peer_len_ret - 1,
  974. &buffer_len_ret),
  975. PSA_ERROR_BUFFER_TOO_SMALL);
  976. TEST_EQUAL(psa_crypto_driver_pake_get_peer(&operation.data.inputs,
  977. (uint8_t *) &peer_ret,
  978. peer_len_ret,
  979. &buffer_len_ret),
  980. PSA_SUCCESS);
  981. TEST_EQUAL(buffer_len_ret, peer_len);
  982. PSA_ASSERT(memcmp(peer_ret, peer, buffer_len_ret));
  983. exit:
  984. PSA_ASSERT(psa_pake_abort(&operation));
  985. PSA_DONE();
  986. }
  987. /* END_CASE */