diff --git a/src/encauth/chachapoly/chacha20poly1305_test.c b/src/encauth/chachapoly/chacha20poly1305_test.c index 36d5129..e117e48 100644 --- a/src/encauth/chachapoly/chacha20poly1305_test.c +++ b/src/encauth/chachapoly/chacha20poly1305_test.c @@ -18,7 +18,8 @@ int chacha20poly1305_test(void) #else chacha20poly1305_state st1, st2; unsigned char k[] = { 0x80, 0x81, 0x82, 0x83, 0x84, 0x85, 0x86, 0x87, 0x88, 0x89, 0x8a, 0x8b, 0x8c, 0x8d, 0x8e, 0x8f, 0x90, 0x91, 0x92, 0x93, 0x94, 0x95, 0x96, 0x97, 0x98, 0x99, 0x9a, 0x9b, 0x9c, 0x9d, 0x9e, 0x9f }; - unsigned char iv[] = { 0x07, 0x00, 0x00, 0x00, 0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47 }; + unsigned char i12[] = { 0x07, 0x00, 0x00, 0x00, 0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47 }; + unsigned char i8[] = { 0x07, 0x00, 0x00, 0x00, 0x40, 0x41, 0x42, 0x43 }; unsigned char aad[] = { 0x50, 0x51, 0x52, 0x53, 0xc0, 0xc1, 0xc2, 0xc3, 0xc4, 0xc5, 0xc6, 0xc7 }; unsigned char enc[] = { 0xD3, 0x1A, 0x8D, 0x34, 0x64, 0x8E, 0x60, 0xDB, 0x7B, 0x86, 0xAF, 0xBC, 0x53, 0xEF, 0x7E, 0xC2, 0xA4, 0xAD, 0xED, 0x51, 0x29, 0x6E, 0x08, 0xFE, 0xA9, 0xE2, 0xB5, 0xA7, 0x36, 0xEE, 0x62, 0xD6, @@ -37,9 +38,9 @@ int chacha20poly1305_test(void) unsigned char rfc7905_tag[] = { 0x16, 0x2C, 0x92, 0x48, 0x2A, 0xDB, 0xD3, 0x5D, 0x48, 0xBE, 0xC6, 0xFF, 0x10, 0x9C, 0xBA, 0xE4 }; unsigned char ct[1000], pt[1000], emac[16], dmac[16]; - /* encrypt */ + /* encrypt IV 96bit */ chacha20poly1305_init(&st1, k, sizeof(k)); - chacha20poly1305_setiv(&st1, iv, sizeof(iv)); + chacha20poly1305_setiv(&st1, i12, sizeof(i12)); chacha20poly1305_add_aad(&st1, aad, sizeof(aad)); /* encrypt piece by piece */ chacha20poly1305_encrypt(&st1, (unsigned char *)m, 25, ct); @@ -54,9 +55,9 @@ int chacha20poly1305_test(void) if (compare_testvector(ct, mlen, enc, sizeof(enc), "ENC-CT", 1) != 0) return CRYPT_FAIL_TESTVECTOR; if (compare_testvector(emac, len, tag, sizeof(tag), "ENC-TAG", 2) != 0) return CRYPT_FAIL_TESTVECTOR; - /* decrypt */ + /* decrypt IV 96bit */ chacha20poly1305_init(&st2, k, len = sizeof(k)); - chacha20poly1305_setiv(&st2, iv, len = sizeof(iv)); + chacha20poly1305_setiv(&st2, i12, len = sizeof(i12)); chacha20poly1305_add_aad(&st2, aad, len = sizeof(aad)); chacha20poly1305_decrypt(&st2, ct, 21, pt); chacha20poly1305_decrypt(&st2, ct + 21, mlen - 21, pt + 21); @@ -68,21 +69,21 @@ int chacha20poly1305_test(void) /* chacha20poly1305_memory - encrypt */ len = sizeof(emac); - chacha20poly1305_memory(k, sizeof(k), iv, sizeof(iv), aad, sizeof(aad), + chacha20poly1305_memory(k, sizeof(k), i12, sizeof(i12), aad, sizeof(aad), (unsigned char *)m, mlen, ct, emac, &len, CHCHA20POLY1305_ENCRYPT); if (compare_testvector(ct, mlen, enc, sizeof(enc), "ENC-CT2", 1) != 0) return CRYPT_FAIL_TESTVECTOR; if (compare_testvector(emac, len, tag, sizeof(tag), "ENC-TAG2", 2) != 0) return CRYPT_FAIL_TESTVECTOR; /* chacha20poly1305_memory - decrypt */ len = sizeof(dmac); - chacha20poly1305_memory(k, sizeof(k), iv, sizeof(iv), aad, sizeof(aad), + chacha20poly1305_memory(k, sizeof(k), i12, sizeof(i12), aad, sizeof(aad), ct, mlen, pt, dmac, &len, CHCHA20POLY1305_DECRYPT); if (compare_testvector(pt, mlen, m, mlen, "DEC-PT2", 3) != 0) return CRYPT_FAIL_TESTVECTOR; if (compare_testvector(dmac, len, tag, sizeof(tag), "DEC-TAG2", 4) != 0) return CRYPT_FAIL_TESTVECTOR; /* encrypt - rfc7905 */ chacha20poly1305_init(&st1, k, sizeof(k)); - chacha20poly1305_setiv_rfc7905(&st1, iv, sizeof(iv), CONST64(0x1122334455667788)); + chacha20poly1305_setiv_rfc7905(&st1, i12, sizeof(i12), CONST64(0x1122334455667788)); chacha20poly1305_add_aad(&st1, aad, sizeof(aad)); chacha20poly1305_encrypt(&st1, rfc7905_pt, 16, ct); len = sizeof(emac); @@ -93,7 +94,7 @@ int chacha20poly1305_test(void) /* decrypt - rfc7905 */ chacha20poly1305_init(&st1, k, sizeof(k)); - chacha20poly1305_setiv_rfc7905(&st1, iv, sizeof(iv), CONST64(0x1122334455667788)); + chacha20poly1305_setiv_rfc7905(&st1, i12, sizeof(i12), CONST64(0x1122334455667788)); chacha20poly1305_add_aad(&st1, aad, sizeof(aad)); chacha20poly1305_decrypt(&st1, ct, 16, pt); len = sizeof(dmac); @@ -102,6 +103,25 @@ int chacha20poly1305_test(void) if (compare_testvector(pt, 16, rfc7905_pt, 16, "DEC-CT3", 1) != 0) return CRYPT_FAIL_TESTVECTOR; if (compare_testvector(dmac, len, rfc7905_tag, 16, "DEC-TAG3", 2) != 0) return CRYPT_FAIL_TESTVECTOR; + /* encrypt IV 64bit */ + chacha20poly1305_init(&st1, k, sizeof(k)); + chacha20poly1305_setiv(&st1, i8, sizeof(i8)); + chacha20poly1305_add_aad(&st1, aad, sizeof(aad)); + chacha20poly1305_encrypt(&st1, (unsigned char *)m, mlen, ct); + len = sizeof(emac); + chacha20poly1305_done(&st1, emac, &len); + + /* decrypt IV 96bit */ + chacha20poly1305_init(&st2, k, len = sizeof(k)); + chacha20poly1305_setiv(&st2, i8, len = sizeof(i8)); + chacha20poly1305_add_aad(&st2, aad, len = sizeof(aad)); + chacha20poly1305_decrypt(&st2, ct, mlen, pt); + len = sizeof(dmac); + chacha20poly1305_done(&st2, dmac, &len); + + if (compare_testvector(pt, mlen, m, mlen, "DEC-PT4", 1) != 0) return CRYPT_FAIL_TESTVECTOR; + if (compare_testvector(dmac, len, emac, len, "DEC-TAG4", 2) != 0) return CRYPT_FAIL_TESTVECTOR; + return CRYPT_OK; #endif }