test_CBC.py 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410
  1. # ===================================================================
  2. #
  3. # Copyright (c) 2014, Legrandin <helderijs@gmail.com>
  4. # All rights reserved.
  5. #
  6. # Redistribution and use in source and binary forms, with or without
  7. # modification, are permitted provided that the following conditions
  8. # are met:
  9. #
  10. # 1. Redistributions of source code must retain the above copyright
  11. # notice, this list of conditions and the following disclaimer.
  12. # 2. Redistributions in binary form must reproduce the above copyright
  13. # notice, this list of conditions and the following disclaimer in
  14. # the documentation and/or other materials provided with the
  15. # distribution.
  16. #
  17. # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
  18. # "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
  19. # LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
  20. # FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
  21. # COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
  22. # INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
  23. # BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  24. # LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  25. # CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
  26. # LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
  27. # ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
  28. # POSSIBILITY OF SUCH DAMAGE.
  29. # ===================================================================
  30. import unittest
  31. from Crypto.SelfTest.loader import load_tests
  32. from Crypto.SelfTest.st_common import list_test_cases
  33. from Crypto.Util.py3compat import tobytes, b, unhexlify
  34. from Crypto.Cipher import AES, DES3, DES
  35. from Crypto.Hash import SHAKE128
  36. def get_tag_random(tag, length):
  37. return SHAKE128.new(data=tobytes(tag)).read(length)
  38. class BlockChainingTests(unittest.TestCase):
  39. key_128 = get_tag_random("key_128", 16)
  40. key_192 = get_tag_random("key_192", 24)
  41. iv_128 = get_tag_random("iv_128", 16)
  42. iv_64 = get_tag_random("iv_64", 8)
  43. data_128 = get_tag_random("data_128", 16)
  44. def test_loopback_128(self):
  45. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  46. pt = get_tag_random("plaintext", 16 * 100)
  47. ct = cipher.encrypt(pt)
  48. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  49. pt2 = cipher.decrypt(ct)
  50. self.assertEqual(pt, pt2)
  51. def test_loopback_64(self):
  52. cipher = DES3.new(self.key_192, self.des3_mode, self.iv_64)
  53. pt = get_tag_random("plaintext", 8 * 100)
  54. ct = cipher.encrypt(pt)
  55. cipher = DES3.new(self.key_192, self.des3_mode, self.iv_64)
  56. pt2 = cipher.decrypt(ct)
  57. self.assertEqual(pt, pt2)
  58. def test_iv(self):
  59. # If not passed, the iv is created randomly
  60. cipher = AES.new(self.key_128, self.aes_mode)
  61. iv1 = cipher.iv
  62. cipher = AES.new(self.key_128, self.aes_mode)
  63. iv2 = cipher.iv
  64. self.assertNotEqual(iv1, iv2)
  65. self.assertEqual(len(iv1), 16)
  66. # IV can be passed in uppercase or lowercase
  67. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  68. ct = cipher.encrypt(self.data_128)
  69. cipher = AES.new(self.key_128, self.aes_mode, iv=self.iv_128)
  70. self.assertEquals(ct, cipher.encrypt(self.data_128))
  71. cipher = AES.new(self.key_128, self.aes_mode, IV=self.iv_128)
  72. self.assertEquals(ct, cipher.encrypt(self.data_128))
  73. def test_iv_must_be_bytes(self):
  74. self.assertRaises(TypeError, AES.new, self.key_128, self.aes_mode,
  75. iv = u'test1234567890-*')
  76. def test_only_one_iv(self):
  77. # Only one IV/iv keyword allowed
  78. self.assertRaises(TypeError, AES.new, self.key_128, self.aes_mode,
  79. iv=self.iv_128, IV=self.iv_128)
  80. def test_iv_with_matching_length(self):
  81. self.assertRaises(ValueError, AES.new, self.key_128, self.aes_mode,
  82. b(""))
  83. self.assertRaises(ValueError, AES.new, self.key_128, self.aes_mode,
  84. self.iv_128[:15])
  85. self.assertRaises(ValueError, AES.new, self.key_128, self.aes_mode,
  86. self.iv_128 + b("0"))
  87. def test_block_size_128(self):
  88. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  89. self.assertEqual(cipher.block_size, AES.block_size)
  90. def test_block_size_64(self):
  91. cipher = DES3.new(self.key_192, self.des3_mode, self.iv_64)
  92. self.assertEqual(cipher.block_size, DES3.block_size)
  93. def test_unaligned_data_128(self):
  94. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  95. for wrong_length in xrange(1,16):
  96. self.assertRaises(ValueError, cipher.encrypt, b("5") * wrong_length)
  97. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  98. for wrong_length in xrange(1,16):
  99. self.assertRaises(ValueError, cipher.decrypt, b("5") * wrong_length)
  100. def test_unaligned_data_64(self):
  101. cipher = DES3.new(self.key_192, self.des3_mode, self.iv_64)
  102. for wrong_length in xrange(1,8):
  103. self.assertRaises(ValueError, cipher.encrypt, b("5") * wrong_length)
  104. cipher = DES3.new(self.key_192, self.des3_mode, self.iv_64)
  105. for wrong_length in xrange(1,8):
  106. self.assertRaises(ValueError, cipher.decrypt, b("5") * wrong_length)
  107. def test_IV_iv_attributes(self):
  108. data = get_tag_random("data", 16 * 100)
  109. for func in "encrypt", "decrypt":
  110. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  111. getattr(cipher, func)(data)
  112. self.assertEqual(cipher.iv, self.iv_128)
  113. self.assertEqual(cipher.IV, self.iv_128)
  114. def test_unknown_parameters(self):
  115. self.assertRaises(TypeError, AES.new, self.key_128, self.aes_mode,
  116. self.iv_128, 7)
  117. self.assertRaises(TypeError, AES.new, self.key_128, self.aes_mode,
  118. iv=self.iv_128, unknown=7)
  119. # But some are only known by the base cipher (e.g. use_aesni consumed by the AES module)
  120. AES.new(self.key_128, self.aes_mode, iv=self.iv_128, use_aesni=False)
  121. def test_null_encryption_decryption(self):
  122. for func in "encrypt", "decrypt":
  123. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  124. result = getattr(cipher, func)(b(""))
  125. self.assertEqual(result, b(""))
  126. def test_either_encrypt_or_decrypt(self):
  127. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  128. cipher.encrypt(b(""))
  129. self.assertRaises(TypeError, cipher.decrypt, b(""))
  130. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  131. cipher.decrypt(b(""))
  132. self.assertRaises(TypeError, cipher.encrypt, b(""))
  133. def test_data_must_be_bytes(self):
  134. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  135. self.assertRaises(TypeError, cipher.encrypt, u'test1234567890-*')
  136. cipher = AES.new(self.key_128, self.aes_mode, self.iv_128)
  137. self.assertRaises(TypeError, cipher.decrypt, u'test1234567890-*')
  138. class CbcTests(BlockChainingTests):
  139. aes_mode = AES.MODE_CBC
  140. des3_mode = DES3.MODE_CBC
  141. class NistBlockChainingVectors(unittest.TestCase):
  142. def _do_kat_aes_test(self, file_name):
  143. test_vectors = load_tests(("Crypto", "SelfTest", "Cipher", "test_vectors", "AES"),
  144. file_name,
  145. "AES KAT",
  146. { "count" : lambda x: int(x) } )
  147. assert(test_vectors)
  148. direction = None
  149. for tv in test_vectors:
  150. # The test vector file contains some directive lines
  151. if isinstance(tv, basestring):
  152. direction = tv
  153. continue
  154. self.description = tv.desc
  155. cipher = AES.new(tv.key, self.aes_mode, tv.iv)
  156. if direction == "[ENCRYPT]":
  157. self.assertEqual(cipher.encrypt(tv.plaintext), tv.ciphertext)
  158. elif direction == "[DECRYPT]":
  159. self.assertEqual(cipher.decrypt(tv.ciphertext), tv.plaintext)
  160. else:
  161. assert False
  162. # See Section 6.4.2 in AESAVS
  163. def _do_mct_aes_test(self, file_name):
  164. test_vectors = load_tests(("Crypto", "SelfTest", "Cipher", "test_vectors", "AES"),
  165. file_name,
  166. "AES Montecarlo",
  167. { "count" : lambda x: int(x) } )
  168. assert(test_vectors)
  169. direction = None
  170. for tv in test_vectors:
  171. # The test vector file contains some directive lines
  172. if isinstance(tv, basestring):
  173. direction = tv
  174. continue
  175. self.description = tv.desc
  176. cipher = AES.new(tv.key, self.aes_mode, tv.iv)
  177. if direction == '[ENCRYPT]':
  178. cts = [ tv.iv ]
  179. for count in xrange(1000):
  180. cts.append(cipher.encrypt(tv.plaintext))
  181. tv.plaintext = cts[-2]
  182. self.assertEqual(cts[-1], tv.ciphertext)
  183. elif direction == '[DECRYPT]':
  184. pts = [ tv.iv]
  185. for count in xrange(1000):
  186. pts.append(cipher.decrypt(tv.ciphertext))
  187. tv.ciphertext = pts[-2]
  188. self.assertEqual(pts[-1], tv.plaintext)
  189. else:
  190. assert False
  191. def _do_tdes_test(self, file_name):
  192. test_vectors = load_tests(("Crypto", "SelfTest", "Cipher", "test_vectors", "TDES"),
  193. file_name,
  194. "TDES CBC KAT",
  195. { "count" : lambda x: int(x) } )
  196. assert(test_vectors)
  197. direction = None
  198. for tv in test_vectors:
  199. # The test vector file contains some directive lines
  200. if isinstance(tv, basestring):
  201. direction = tv
  202. continue
  203. self.description = tv.desc
  204. if hasattr(tv, "keys"):
  205. cipher = DES.new(tv.keys, self.des_mode, tv.iv)
  206. else:
  207. if tv.key1 != tv.key3:
  208. key = tv.key1 + tv.key2 + tv.key3 # Option 3
  209. else:
  210. key = tv.key1 + tv.key2 # Option 2
  211. cipher = DES3.new(key, self.des3_mode, tv.iv)
  212. if direction == "[ENCRYPT]":
  213. self.assertEqual(cipher.encrypt(tv.plaintext), tv.ciphertext)
  214. elif direction == "[DECRYPT]":
  215. self.assertEqual(cipher.decrypt(tv.ciphertext), tv.plaintext)
  216. else:
  217. assert False
  218. class NistCbcVectors(NistBlockChainingVectors):
  219. aes_mode = AES.MODE_CBC
  220. des_mode = DES.MODE_CBC
  221. des3_mode = DES3.MODE_CBC
  222. # Create one test method per file
  223. nist_aes_kat_mmt_files = (
  224. # KAT
  225. "CBCGFSbox128.rsp",
  226. "CBCGFSbox192.rsp",
  227. "CBCGFSbox256.rsp",
  228. "CBCKeySbox128.rsp",
  229. "CBCKeySbox192.rsp",
  230. "CBCKeySbox256.rsp",
  231. "CBCVarKey128.rsp",
  232. "CBCVarKey192.rsp",
  233. "CBCVarKey256.rsp",
  234. "CBCVarTxt128.rsp",
  235. "CBCVarTxt192.rsp",
  236. "CBCVarTxt256.rsp",
  237. # MMT
  238. "CBCMMT128.rsp",
  239. "CBCMMT192.rsp",
  240. "CBCMMT256.rsp",
  241. )
  242. nist_aes_mct_files = (
  243. "CBCMCT128.rsp",
  244. "CBCMCT192.rsp",
  245. "CBCMCT256.rsp",
  246. )
  247. for file_name in nist_aes_kat_mmt_files:
  248. def new_func(self, file_name=file_name):
  249. self._do_kat_aes_test(file_name)
  250. setattr(NistCbcVectors, "test_AES_" + file_name, new_func)
  251. for file_name in nist_aes_mct_files:
  252. def new_func(self, file_name=file_name):
  253. self._do_mct_aes_test(file_name)
  254. setattr(NistCbcVectors, "test_AES_" + file_name, new_func)
  255. del file_name, new_func
  256. nist_tdes_files = (
  257. "TCBCMMT2.rsp", # 2TDES
  258. "TCBCMMT3.rsp", # 3TDES
  259. "TCBCinvperm.rsp", # Single DES
  260. "TCBCpermop.rsp",
  261. "TCBCsubtab.rsp",
  262. "TCBCvarkey.rsp",
  263. "TCBCvartext.rsp",
  264. )
  265. for file_name in nist_tdes_files:
  266. def new_func(self, file_name=file_name):
  267. self._do_tdes_test(file_name)
  268. setattr(NistCbcVectors, "test_TDES_" + file_name, new_func)
  269. # END OF NIST CBC TEST VECTORS
  270. class SP800TestVectors(unittest.TestCase):
  271. """Class exercising the CBC test vectors found in Section F.2
  272. of NIST SP 800-3A"""
  273. def test_aes_128(self):
  274. key = '2b7e151628aed2a6abf7158809cf4f3c'
  275. iv = '000102030405060708090a0b0c0d0e0f'
  276. plaintext = '6bc1bee22e409f96e93d7e117393172a' +\
  277. 'ae2d8a571e03ac9c9eb76fac45af8e51' +\
  278. '30c81c46a35ce411e5fbc1191a0a52ef' +\
  279. 'f69f2445df4f9b17ad2b417be66c3710'
  280. ciphertext = '7649abac8119b246cee98e9b12e9197d' +\
  281. '5086cb9b507219ee95db113a917678b2' +\
  282. '73bed6b8e3c1743b7116e69e22229516' +\
  283. '3ff1caa1681fac09120eca307586e1a7'
  284. key = unhexlify(key)
  285. iv = unhexlify(iv)
  286. plaintext = unhexlify(plaintext)
  287. ciphertext = unhexlify(ciphertext)
  288. cipher = AES.new(key, AES.MODE_CBC, iv)
  289. self.assertEqual(cipher.encrypt(plaintext), ciphertext)
  290. cipher = AES.new(key, AES.MODE_CBC, iv)
  291. self.assertEqual(cipher.decrypt(ciphertext), plaintext)
  292. def test_aes_192(self):
  293. key = '8e73b0f7da0e6452c810f32b809079e562f8ead2522c6b7b'
  294. iv = '000102030405060708090a0b0c0d0e0f'
  295. plaintext = '6bc1bee22e409f96e93d7e117393172a' +\
  296. 'ae2d8a571e03ac9c9eb76fac45af8e51' +\
  297. '30c81c46a35ce411e5fbc1191a0a52ef' +\
  298. 'f69f2445df4f9b17ad2b417be66c3710'
  299. ciphertext = '4f021db243bc633d7178183a9fa071e8' +\
  300. 'b4d9ada9ad7dedf4e5e738763f69145a' +\
  301. '571b242012fb7ae07fa9baac3df102e0' +\
  302. '08b0e27988598881d920a9e64f5615cd'
  303. key = unhexlify(key)
  304. iv = unhexlify(iv)
  305. plaintext = unhexlify(plaintext)
  306. ciphertext = unhexlify(ciphertext)
  307. cipher = AES.new(key, AES.MODE_CBC, iv)
  308. self.assertEqual(cipher.encrypt(plaintext), ciphertext)
  309. cipher = AES.new(key, AES.MODE_CBC, iv)
  310. self.assertEqual(cipher.decrypt(ciphertext), plaintext)
  311. def test_aes_256(self):
  312. key = '603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4'
  313. iv = '000102030405060708090a0b0c0d0e0f'
  314. plaintext = '6bc1bee22e409f96e93d7e117393172a' +\
  315. 'ae2d8a571e03ac9c9eb76fac45af8e51' +\
  316. '30c81c46a35ce411e5fbc1191a0a52ef' +\
  317. 'f69f2445df4f9b17ad2b417be66c3710'
  318. ciphertext = 'f58c4c04d6e5f1ba779eabfb5f7bfbd6' +\
  319. '9cfc4e967edb808d679f777bc6702c7d' +\
  320. '39f23369a9d9bacfa530e26304231461' +\
  321. 'b2eb05e2c39be9fcda6c19078c6a9d1b'
  322. key = unhexlify(key)
  323. iv = unhexlify(iv)
  324. plaintext = unhexlify(plaintext)
  325. ciphertext = unhexlify(ciphertext)
  326. cipher = AES.new(key, AES.MODE_CBC, iv)
  327. self.assertEqual(cipher.encrypt(plaintext), ciphertext)
  328. cipher = AES.new(key, AES.MODE_CBC, iv)
  329. self.assertEqual(cipher.decrypt(ciphertext), plaintext)
  330. def get_tests(config={}):
  331. tests = []
  332. tests += list_test_cases(CbcTests)
  333. tests += list_test_cases(NistCbcVectors)
  334. tests += list_test_cases(SP800TestVectors)
  335. return tests
  336. if __name__ == '__main__':
  337. suite = lambda: unittest.TestSuite(get_tests())
  338. unittest.main(defaultTest='suite')