michael@0: /* This Source Code Form is subject to the terms of the Mozilla Public michael@0: * License, v. 2.0. If a copy of the MPL was not distributed with this michael@0: * file, You can obtain one at http://mozilla.org/MPL/2.0/. */ michael@0: michael@0: #include "mpi.h" michael@0: #include "mplogic.h" michael@0: #include "mpprime.h" michael@0: #include "ecl.h" michael@0: #include "ecl-curve.h" michael@0: #include "ecp.h" michael@0: #include michael@0: #include michael@0: #include michael@0: michael@0: #include michael@0: #include michael@0: #include michael@0: michael@0: /* Time k repetitions of operation op. */ michael@0: #define M_TimeOperation(op, k) { \ michael@0: double dStart, dNow, dUserTime; \ michael@0: struct rusage ru; \ michael@0: int i; \ michael@0: getrusage(RUSAGE_SELF, &ru); \ michael@0: dStart = (double)ru.ru_utime.tv_sec+(double)ru.ru_utime.tv_usec*0.000001; \ michael@0: for (i = 0; i < k; i++) { \ michael@0: { op; } \ michael@0: }; \ michael@0: getrusage(RUSAGE_SELF, &ru); \ michael@0: dNow = (double)ru.ru_utime.tv_sec+(double)ru.ru_utime.tv_usec*0.000001; \ michael@0: dUserTime = dNow-dStart; \ michael@0: if (dUserTime) printf(" %-45s k: %6i, t: %6.2f sec\n", #op, k, dUserTime); \ michael@0: } michael@0: michael@0: /* Test curve using generic field arithmetic. */ michael@0: #define ECTEST_GENERIC_GFP(name_c, name) \ michael@0: printf("Testing %s using generic implementation...\n", name_c); \ michael@0: params = EC_GetNamedCurveParams(name); \ michael@0: if (params == NULL) { \ michael@0: printf(" Error: could not construct params.\n"); \ michael@0: res = MP_NO; \ michael@0: goto CLEANUP; \ michael@0: } \ michael@0: ECGroup_free(group); \ michael@0: group = ECGroup_fromHex(params); \ michael@0: if (group == NULL) { \ michael@0: printf(" Error: could not construct group.\n"); \ michael@0: res = MP_NO; \ michael@0: goto CLEANUP; \ michael@0: } \ michael@0: MP_CHECKOK( ectest_curve_GFp(group, ectestPrint, ectestTime, 1) ); \ michael@0: printf("... okay.\n"); michael@0: michael@0: /* Test curve using specific field arithmetic. */ michael@0: #define ECTEST_NAMED_GFP(name_c, name) \ michael@0: printf("Testing %s using specific implementation...\n", name_c); \ michael@0: ECGroup_free(group); \ michael@0: group = ECGroup_fromName(name); \ michael@0: if (group == NULL) { \ michael@0: printf(" Warning: could not construct group.\n"); \ michael@0: printf("... failed; continuing with remaining tests.\n"); \ michael@0: } else { \ michael@0: MP_CHECKOK( ectest_curve_GFp(group, ectestPrint, ectestTime, 0) ); \ michael@0: printf("... okay.\n"); \ michael@0: } michael@0: michael@0: /* Performs basic tests of elliptic curve cryptography over prime fields. michael@0: * If tests fail, then it prints an error message, aborts, and returns an michael@0: * error code. Otherwise, returns 0. */ michael@0: int michael@0: ectest_curve_GFp(ECGroup *group, int ectestPrint, int ectestTime, michael@0: int generic) michael@0: { michael@0: michael@0: mp_int one, order_1, gx, gy, rx, ry, n; michael@0: int size; michael@0: mp_err res; michael@0: char s[1000]; michael@0: michael@0: /* initialize values */ michael@0: MP_CHECKOK(mp_init(&one)); michael@0: MP_CHECKOK(mp_init(&order_1)); michael@0: MP_CHECKOK(mp_init(&gx)); michael@0: MP_CHECKOK(mp_init(&gy)); michael@0: MP_CHECKOK(mp_init(&rx)); michael@0: MP_CHECKOK(mp_init(&ry)); michael@0: MP_CHECKOK(mp_init(&n)); michael@0: michael@0: MP_CHECKOK(mp_set_int(&one, 1)); michael@0: MP_CHECKOK(mp_sub(&group->order, &one, &order_1)); michael@0: michael@0: /* encode base point */ michael@0: if (group->meth->field_dec) { michael@0: MP_CHECKOK(group->meth->field_dec(&group->genx, &gx, group->meth)); michael@0: MP_CHECKOK(group->meth->field_dec(&group->geny, &gy, group->meth)); michael@0: } else { michael@0: MP_CHECKOK(mp_copy(&group->genx, &gx)); michael@0: MP_CHECKOK(mp_copy(&group->geny, &gy)); michael@0: } michael@0: if (ectestPrint) { michael@0: /* output base point */ michael@0: printf(" base point P:\n"); michael@0: MP_CHECKOK(mp_toradix(&gx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&gy, s, 16)); michael@0: printf(" %s\n", s); michael@0: if (group->meth->field_enc) { michael@0: printf(" base point P (encoded):\n"); michael@0: MP_CHECKOK(mp_toradix(&group->genx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&group->geny, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: } michael@0: michael@0: #ifdef ECL_ENABLE_GFP_PT_MUL_AFF michael@0: /* multiply base point by order - 1 and check for negative of base michael@0: * point */ michael@0: MP_CHECKOK(ec_GFp_pt_mul_aff michael@0: (&order_1, &group->genx, &group->geny, &rx, &ry, group)); michael@0: if (ectestPrint) { michael@0: printf(" (order-1)*P (affine):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: MP_CHECKOK(group->meth->field_neg(&ry, &ry, group->meth)); michael@0: if ((mp_cmp(&rx, &group->genx) != 0) michael@0: || (mp_cmp(&ry, &group->geny) != 0)) { michael@0: printf(" Error: invalid result (expected (- base point)).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: #endif michael@0: michael@0: #ifdef ECL_ENABLE_GFP_PT_MUL_AFF michael@0: /* multiply base point by order - 1 and check for negative of base michael@0: * point */ michael@0: MP_CHECKOK(ec_GFp_pt_mul_jac michael@0: (&order_1, &group->genx, &group->geny, &rx, &ry, group)); michael@0: if (ectestPrint) { michael@0: printf(" (order-1)*P (jacobian):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: MP_CHECKOK(group->meth->field_neg(&ry, &ry, group->meth)); michael@0: if ((mp_cmp(&rx, &group->genx) != 0) michael@0: || (mp_cmp(&ry, &group->geny) != 0)) { michael@0: printf(" Error: invalid result (expected (- base point)).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: #endif michael@0: michael@0: /* multiply base point by order - 1 and check for negative of base michael@0: * point */ michael@0: MP_CHECKOK(ECPoint_mul(group, &order_1, NULL, NULL, &rx, &ry)); michael@0: if (ectestPrint) { michael@0: printf(" (order-1)*P (ECPoint_mul):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry)); michael@0: if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) { michael@0: printf(" Error: invalid result (expected (- base point)).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: michael@0: /* multiply base point by order - 1 and check for negative of base michael@0: * point */ michael@0: MP_CHECKOK(ECPoint_mul(group, &order_1, &gx, &gy, &rx, &ry)); michael@0: if (ectestPrint) { michael@0: printf(" (order-1)*P (ECPoint_mul):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry)); michael@0: if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) { michael@0: printf(" Error: invalid result (expected (- base point)).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: michael@0: #ifdef ECL_ENABLE_GFP_PT_MUL_AFF michael@0: /* multiply base point by order and check for point at infinity */ michael@0: MP_CHECKOK(ec_GFp_pt_mul_aff michael@0: (&group->order, &group->genx, &group->geny, &rx, &ry, michael@0: group)); michael@0: if (ectestPrint) { michael@0: printf(" (order)*P (affine):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) { michael@0: printf(" Error: invalid result (expected point at infinity).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: #endif michael@0: michael@0: #ifdef ECL_ENABLE_GFP_PT_MUL_JAC michael@0: /* multiply base point by order and check for point at infinity */ michael@0: MP_CHECKOK(ec_GFp_pt_mul_jac michael@0: (&group->order, &group->genx, &group->geny, &rx, &ry, michael@0: group)); michael@0: if (ectestPrint) { michael@0: printf(" (order)*P (jacobian):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) { michael@0: printf(" Error: invalid result (expected point at infinity).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: #endif michael@0: michael@0: /* multiply base point by order and check for point at infinity */ michael@0: MP_CHECKOK(ECPoint_mul(group, &group->order, NULL, NULL, &rx, &ry)); michael@0: if (ectestPrint) { michael@0: printf(" (order)*P (ECPoint_mul):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) { michael@0: printf(" Error: invalid result (expected point at infinity).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: michael@0: /* multiply base point by order and check for point at infinity */ michael@0: MP_CHECKOK(ECPoint_mul(group, &group->order, &gx, &gy, &rx, &ry)); michael@0: if (ectestPrint) { michael@0: printf(" (order)*P (ECPoint_mul):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) { michael@0: printf(" Error: invalid result (expected point at infinity).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: michael@0: /* check that (order-1)P + (order-1)P + P == (order-1)P */ michael@0: MP_CHECKOK(ECPoints_mul michael@0: (group, &order_1, &order_1, &gx, &gy, &rx, &ry)); michael@0: MP_CHECKOK(ECPoints_mul(group, &one, &one, &rx, &ry, &rx, &ry)); michael@0: if (ectestPrint) { michael@0: printf michael@0: (" (order-1)*P + (order-1)*P + P == (order-1)*P (ECPoints_mul):\n"); michael@0: MP_CHECKOK(mp_toradix(&rx, s, 16)); michael@0: printf(" %s\n", s); michael@0: MP_CHECKOK(mp_toradix(&ry, s, 16)); michael@0: printf(" %s\n", s); michael@0: } michael@0: MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry)); michael@0: if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) { michael@0: printf(" Error: invalid result (expected (- base point)).\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: michael@0: /* test validate_point function */ michael@0: if (ECPoint_validate(group, &gx, &gy) != MP_YES) { michael@0: printf(" Error: validate point on base point failed.\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: MP_CHECKOK(mp_add_d(&gy, 1, &ry)); michael@0: if (ECPoint_validate(group, &gx, &ry) != MP_NO) { michael@0: printf(" Error: validate point on invalid point passed.\n"); michael@0: res = MP_NO; michael@0: goto CLEANUP; michael@0: } michael@0: michael@0: if (ectestTime) { michael@0: /* compute random scalar */ michael@0: size = mpl_significant_bits(&group->meth->irr); michael@0: if (size < MP_OKAY) { michael@0: goto CLEANUP; michael@0: } michael@0: MP_CHECKOK(mpp_random_size(&n, (size + ECL_BITS - 1) / ECL_BITS)); michael@0: MP_CHECKOK(group->meth->field_mod(&n, &n, group->meth)); michael@0: /* timed test */ michael@0: if (generic) { michael@0: #ifdef ECL_ENABLE_GFP_PT_MUL_AFF michael@0: M_TimeOperation(MP_CHECKOK michael@0: (ec_GFp_pt_mul_aff michael@0: (&n, &group->genx, &group->geny, &rx, &ry, michael@0: group)), 100); michael@0: #endif michael@0: M_TimeOperation(MP_CHECKOK michael@0: (ECPoint_mul(group, &n, NULL, NULL, &rx, &ry)), michael@0: 100); michael@0: M_TimeOperation(MP_CHECKOK michael@0: (ECPoints_mul michael@0: (group, &n, &n, &gx, &gy, &rx, &ry)), 100); michael@0: } else { michael@0: M_TimeOperation(MP_CHECKOK michael@0: (ECPoint_mul(group, &n, NULL, NULL, &rx, &ry)), michael@0: 100); michael@0: M_TimeOperation(MP_CHECKOK michael@0: (ECPoint_mul(group, &n, &gx, &gy, &rx, &ry)), michael@0: 100); michael@0: M_TimeOperation(MP_CHECKOK michael@0: (ECPoints_mul michael@0: (group, &n, &n, &gx, &gy, &rx, &ry)), 100); michael@0: } michael@0: } michael@0: michael@0: CLEANUP: michael@0: mp_clear(&one); michael@0: mp_clear(&order_1); michael@0: mp_clear(&gx); michael@0: mp_clear(&gy); michael@0: mp_clear(&rx); michael@0: mp_clear(&ry); michael@0: mp_clear(&n); michael@0: if (res != MP_OKAY) { michael@0: printf(" Error: exiting with error value %i\n", res); michael@0: } michael@0: return res; michael@0: } michael@0: michael@0: /* Prints help information. */ michael@0: void michael@0: printUsage() michael@0: { michael@0: printf("Usage: ecp_test [--print] [--time]\n"); michael@0: printf michael@0: (" --print Print out results of each point arithmetic test.\n"); michael@0: printf michael@0: (" --time Benchmark point operations and print results.\n"); michael@0: } michael@0: michael@0: /* Performs tests of elliptic curve cryptography over prime fields If michael@0: * tests fail, then it prints an error message, aborts, and returns an michael@0: * error code. Otherwise, returns 0. */ michael@0: int michael@0: main(int argv, char **argc) michael@0: { michael@0: michael@0: int ectestTime = 0; michael@0: int ectestPrint = 0; michael@0: int i; michael@0: ECGroup *group = NULL; michael@0: ECCurveParams *params = NULL; michael@0: mp_err res; michael@0: michael@0: /* read command-line arguments */ michael@0: for (i = 1; i < argv; i++) { michael@0: if ((strcasecmp(argc[i], "time") == 0) michael@0: || (strcasecmp(argc[i], "-time") == 0) michael@0: || (strcasecmp(argc[i], "--time") == 0)) { michael@0: ectestTime = 1; michael@0: } else if ((strcasecmp(argc[i], "print") == 0) michael@0: || (strcasecmp(argc[i], "-print") == 0) michael@0: || (strcasecmp(argc[i], "--print") == 0)) { michael@0: ectestPrint = 1; michael@0: } else { michael@0: printUsage(); michael@0: return 0; michael@0: } michael@0: } michael@0: michael@0: /* generic arithmetic tests */ michael@0: ECTEST_GENERIC_GFP("SECP-160R1", ECCurve_SECG_PRIME_160R1); michael@0: michael@0: /* specific arithmetic tests */ michael@0: ECTEST_NAMED_GFP("NIST-P192", ECCurve_NIST_P192); michael@0: ECTEST_NAMED_GFP("NIST-P224", ECCurve_NIST_P224); michael@0: ECTEST_NAMED_GFP("NIST-P256", ECCurve_NIST_P256); michael@0: ECTEST_NAMED_GFP("NIST-P384", ECCurve_NIST_P384); michael@0: ECTEST_NAMED_GFP("NIST-P521", ECCurve_NIST_P521); michael@0: ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v1", ECCurve_X9_62_PRIME_192V1); michael@0: ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v2", ECCurve_X9_62_PRIME_192V2); michael@0: ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v3", ECCurve_X9_62_PRIME_192V3); michael@0: ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v1", ECCurve_X9_62_PRIME_239V1); michael@0: ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v2", ECCurve_X9_62_PRIME_239V2); michael@0: ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v3", ECCurve_X9_62_PRIME_239V3); michael@0: ECTEST_NAMED_GFP("ANSI X9.62 PRIME256v1", ECCurve_X9_62_PRIME_256V1); michael@0: ECTEST_NAMED_GFP("SECP-112R1", ECCurve_SECG_PRIME_112R1); michael@0: ECTEST_NAMED_GFP("SECP-112R2", ECCurve_SECG_PRIME_112R2); michael@0: ECTEST_NAMED_GFP("SECP-128R1", ECCurve_SECG_PRIME_128R1); michael@0: ECTEST_NAMED_GFP("SECP-128R2", ECCurve_SECG_PRIME_128R2); michael@0: ECTEST_NAMED_GFP("SECP-160K1", ECCurve_SECG_PRIME_160K1); michael@0: ECTEST_NAMED_GFP("SECP-160R1", ECCurve_SECG_PRIME_160R1); michael@0: ECTEST_NAMED_GFP("SECP-160R2", ECCurve_SECG_PRIME_160R2); michael@0: ECTEST_NAMED_GFP("SECP-192K1", ECCurve_SECG_PRIME_192K1); michael@0: ECTEST_NAMED_GFP("SECP-192R1", ECCurve_SECG_PRIME_192R1); michael@0: ECTEST_NAMED_GFP("SECP-224K1", ECCurve_SECG_PRIME_224K1); michael@0: ECTEST_NAMED_GFP("SECP-224R1", ECCurve_SECG_PRIME_224R1); michael@0: ECTEST_NAMED_GFP("SECP-256K1", ECCurve_SECG_PRIME_256K1); michael@0: ECTEST_NAMED_GFP("SECP-256R1", ECCurve_SECG_PRIME_256R1); michael@0: ECTEST_NAMED_GFP("SECP-384R1", ECCurve_SECG_PRIME_384R1); michael@0: ECTEST_NAMED_GFP("SECP-521R1", ECCurve_SECG_PRIME_521R1); michael@0: ECTEST_NAMED_GFP("WTLS-6 (112)", ECCurve_WTLS_6); michael@0: ECTEST_NAMED_GFP("WTLS-7 (160)", ECCurve_WTLS_7); michael@0: ECTEST_NAMED_GFP("WTLS-8 (112)", ECCurve_WTLS_8); michael@0: ECTEST_NAMED_GFP("WTLS-9 (160)", ECCurve_WTLS_9); michael@0: ECTEST_NAMED_GFP("WTLS-12 (224)", ECCurve_WTLS_12); michael@0: michael@0: CLEANUP: michael@0: EC_FreeCurveParams(params); michael@0: ECGroup_free(group); michael@0: if (res != MP_OKAY) { michael@0: printf("Error: exiting with error value %i\n", res); michael@0: } michael@0: return res; michael@0: }