Home | History | Annotate | Download | only in cfb
      1 // Copyright (c) 2017, Google Inc.
      2 //
      3 // Permission to use, copy, modify, and/or distribute this software for any
      4 // purpose with or without fee is hereby granted, provided that the above
      5 // copyright notice and this permission notice appear in all copies.
      6 //
      7 // THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
      8 // WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
      9 // MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
     10 // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
     11 // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
     12 // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
     13 // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
     14 
     15 #include <openssl/cipher.h>
     16 
     17 #include <gtest/gtest.h>
     18 
     19 #include "../../crypto/internal.h"
     20 #include "../../crypto/test/test_util.h"
     21 
     22 
     23 struct CFBTestCase {
     24   uint8_t key[16];
     25   uint8_t iv[16];
     26   uint8_t plaintext[16*4];
     27   uint8_t ciphertext[16*4];
     28 };
     29 
     30 static const CFBTestCase kCFBTestCases[] = {
     31   {
     32     // This is the test case from
     33     // http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf,
     34     // section F.3.13.
     35     {0x2b, 0x7e, 0x15, 0x16, 0x28, 0xae, 0xd2, 0xa6, 0xab, 0xf7, 0x15, 0x88, 0x09, 0xcf, 0x4f, 0x3c},
     36     {0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f},
     37     {0x6b, 0xc1, 0xbe, 0xe2, 0x2e, 0x40, 0x9f, 0x96, 0xe9, 0x3d, 0x7e, 0x11, 0x73, 0x93, 0x17, 0x2a,
     38      0xae, 0x2d, 0x8a, 0x57, 0x1e, 0x03, 0xac, 0x9c, 0x9e, 0xb7, 0x6f, 0xac, 0x45, 0xaf, 0x8e, 0x51,
     39      0x30, 0xc8, 0x1c, 0x46, 0xa3, 0x5c, 0xe4, 0x11, 0xe5, 0xfb, 0xc1, 0x19, 0x1a, 0x0a, 0x52, 0xef,
     40      0xf6, 0x9f, 0x24, 0x45, 0xdf, 0x4f, 0x9b, 0x17, 0xad, 0x2b, 0x41, 0x7b, 0xe6, 0x6c, 0x37, 0x10},
     41     {0x3b, 0x3f, 0xd9, 0x2e, 0xb7, 0x2d, 0xad, 0x20, 0x33, 0x34, 0x49, 0xf8, 0xe8, 0x3c, 0xfb, 0x4a,
     42      0xc8, 0xa6, 0x45, 0x37, 0xa0, 0xb3, 0xa9, 0x3f, 0xcd, 0xe3, 0xcd, 0xad, 0x9f, 0x1c, 0xe5, 0x8b,
     43      0x26, 0x75, 0x1f, 0x67, 0xa3, 0xcb, 0xb1, 0x40, 0xb1, 0x80, 0x8c, 0xf1, 0x87, 0xa4, 0xf4, 0xdf,
     44      0xc0, 0x4b, 0x05, 0x35, 0x7c, 0x5d, 0x1c, 0x0e, 0xea, 0xc4, 0xc6, 0x6f, 0x9f, 0xf7, 0xf2, 0xe6},
     45   },
     46 };
     47 
     48 TEST(CFBTest, TestVectors) {
     49   unsigned test_num = 0;
     50   for (const auto &test : kCFBTestCases) {
     51     test_num++;
     52     SCOPED_TRACE(test_num);
     53 
     54     const size_t input_len = sizeof(test.plaintext);
     55     std::unique_ptr<uint8_t[]> out(new uint8_t[input_len]);
     56 
     57     for (size_t stride = 1; stride <= input_len; stride++) {
     58       bssl::ScopedEVP_CIPHER_CTX ctx;
     59       ASSERT_TRUE(EVP_EncryptInit_ex(ctx.get(), EVP_aes_128_cfb128(), nullptr,
     60                                      test.key, test.iv));
     61 
     62       size_t done = 0;
     63       while (done < input_len) {
     64         size_t todo = stride;
     65         if (todo > input_len - done) {
     66           todo = input_len - done;
     67         }
     68 
     69         int out_bytes;
     70         ASSERT_TRUE(EVP_EncryptUpdate(ctx.get(), out.get() + done, &out_bytes,
     71                                       test.plaintext + done, todo));
     72         ASSERT_EQ(static_cast<size_t>(out_bytes), todo);
     73 
     74         done += todo;
     75       }
     76 
     77       EXPECT_EQ(Bytes(test.ciphertext), Bytes(out.get(), input_len));
     78     }
     79 
     80     bssl::ScopedEVP_CIPHER_CTX decrypt_ctx;
     81     ASSERT_TRUE(EVP_DecryptInit_ex(decrypt_ctx.get(), EVP_aes_128_cfb128(),
     82                                    nullptr, test.key, test.iv));
     83 
     84     std::unique_ptr<uint8_t[]> plaintext(new uint8_t[input_len]);
     85     int num_bytes;
     86     ASSERT_TRUE(EVP_DecryptUpdate(decrypt_ctx.get(), plaintext.get(),
     87                                   &num_bytes, out.get(), input_len));
     88     EXPECT_EQ(static_cast<size_t>(num_bytes), input_len);
     89     EXPECT_EQ(Bytes(test.plaintext), Bytes(plaintext.get(), input_len));
     90   }
     91 }
     92