rsa_mp_test.c 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329
  1. /*
  2. * Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.
  3. * Copyright 2017 BaishanCloud. All rights reserved.
  4. *
  5. * Licensed under the Apache License 2.0 (the "License"). You may not use
  6. * this file except in compliance with the License. You can obtain a copy
  7. * in the file LICENSE in the source distribution or at
  8. * https://www.openssl.org/source/license.html
  9. */
  10. /* This aims to test the setting functions, including internal ones */
  11. /*
  12. * RSA low level APIs are deprecated for public use, but still ok for
  13. * internal use.
  14. */
  15. #include "internal/deprecated.h"
  16. #include <stdio.h>
  17. #include <string.h>
  18. #include <openssl/crypto.h>
  19. #include <openssl/err.h>
  20. #include <openssl/rand.h>
  21. #include <openssl/bn.h>
  22. #include "testutil.h"
  23. #include <openssl/rsa.h>
  24. #include "crypto/rsa.h"
  25. #define NUM_EXTRA_PRIMES 1
  26. DEFINE_STACK_OF(BIGNUM)
  27. /* C90 requires string should <= 509 bytes */
  28. static const unsigned char n[] =
  29. "\x92\x60\xd0\x75\x0a\xe1\x17\xee\xe5\x5c\x3f\x3d\xea\xba\x74\x91"
  30. "\x75\x21\xa2\x62\xee\x76\x00\x7c\xdf\x8a\x56\x75\x5a\xd7\x3a\x15"
  31. "\x98\xa1\x40\x84\x10\xa0\x14\x34\xc3\xf5\xbc\x54\xa8\x8b\x57\xfa"
  32. "\x19\xfc\x43\x28\xda\xea\x07\x50\xa4\xc4\x4e\x88\xcf\xf3\xb2\x38"
  33. "\x26\x21\xb8\x0f\x67\x04\x64\x43\x3e\x43\x36\xe6\xd0\x03\xe8\xcd"
  34. "\x65\xbf\xf2\x11\xda\x14\x4b\x88\x29\x1c\x22\x59\xa0\x0a\x72\xb7"
  35. "\x11\xc1\x16\xef\x76\x86\xe8\xfe\xe3\x4e\x4d\x93\x3c\x86\x81\x87"
  36. "\xbd\xc2\x6f\x7b\xe0\x71\x49\x3c\x86\xf7\xa5\x94\x1c\x35\x10\x80"
  37. "\x6a\xd6\x7b\x0f\x94\xd8\x8f\x5c\xf5\xc0\x2a\x09\x28\x21\xd8\x62"
  38. "\x6e\x89\x32\xb6\x5c\x5b\xd8\xc9\x20\x49\xc2\x10\x93\x2b\x7a\xfa"
  39. "\x7a\xc5\x9c\x0e\x88\x6a\xe5\xc1\xed\xb0\x0d\x8c\xe2\xc5\x76\x33"
  40. "\xdb\x26\xbd\x66\x39\xbf\xf7\x3c\xee\x82\xbe\x92\x75\xc4\x02\xb4"
  41. "\xcf\x2a\x43\x88\xda\x8c\xf8\xc6\x4e\xef\xe1\xc5\xa0\xf5\xab\x80"
  42. "\x57\xc3\x9f\xa5\xc0\x58\x9c\x3e\x25\x3f\x09\x60\x33\x23\x00\xf9"
  43. "\x4b\xea\x44\x87\x7b\x58\x8e\x1e\xdb\xde\x97\xcf\x23\x60\x72\x7a"
  44. "\x09\xb7\x75\x26\x2d\x7e\xe5\x52\xb3\x31\x9b\x92\x66\xf0\x5a\x25";
  45. static const unsigned char e[] = "\x01\x00\x01";
  46. static const unsigned char d[] =
  47. "\x6a\x7d\xf2\xca\x63\xea\xd4\xdd\xa1\x91\xd6\x14\xb6\xb3\x85\xe0"
  48. "\xd9\x05\x6a\x3d\x6d\x5c\xfe\x07\xdb\x1d\xaa\xbe\xe0\x22\xdb\x08"
  49. "\x21\x2d\x97\x61\x3d\x33\x28\xe0\x26\x7c\x9d\xd2\x3d\x78\x7a\xbd"
  50. "\xe2\xaf\xcb\x30\x6a\xeb\x7d\xfc\xe6\x92\x46\xcc\x73\xf5\xc8\x7f"
  51. "\xdf\x06\x03\x01\x79\xa2\x11\x4b\x76\x7d\xb1\xf0\x83\xff\x84\x1c"
  52. "\x02\x5d\x7d\xc0\x0c\xd8\x24\x35\xb9\xa9\x0f\x69\x53\x69\xe9\x4d"
  53. "\xf2\x3d\x2c\xe4\x58\xbc\x3b\x32\x83\xad\x8b\xba\x2b\x8f\xa1\xba"
  54. "\x62\xe2\xdc\xe9\xac\xcf\xf3\x79\x9a\xae\x7c\x84\x00\x16\xf3\xba"
  55. "\x8e\x00\x48\xc0\xb6\xcc\x43\x39\xaf\x71\x61\x00\x3a\x5b\xeb\x86"
  56. "\x4a\x01\x64\xb2\xc1\xc9\x23\x7b\x64\xbc\x87\x55\x69\x94\x35\x1b"
  57. "\x27\x50\x6c\x33\xd4\xbc\xdf\xce\x0f\x9c\x49\x1a\x7d\x6b\x06\x28"
  58. "\xc7\xc8\x52\xbe\x4f\x0a\x9c\x31\x32\xb2\xed\x3a\x2c\x88\x81\xe9"
  59. "\xaa\xb0\x7e\x20\xe1\x7d\xeb\x07\x46\x91\xbe\x67\x77\x76\xa7\x8b"
  60. "\x5c\x50\x2e\x05\xd9\xbd\xde\x72\x12\x6b\x37\x38\x69\x5e\x2d\xd1"
  61. "\xa0\xa9\x8a\x14\x24\x7c\x65\xd8\xa7\xee\x79\x43\x2a\x09\x2c\xb0"
  62. "\x72\x1a\x12\xdf\x79\x8e\x44\xf7\xcf\xce\x0c\x49\x81\x47\xa9\xb1";
  63. static const unsigned char p[] =
  64. "\x06\x77\xcd\xd5\x46\x9b\xc1\xd5\x58\x00\x81\xe2\xf3\x0a\x36\xb1"
  65. "\x6e\x29\x89\xd5\x2f\x31\x5f\x92\x22\x3b\x9b\x75\x30\x82\xfa\xc5"
  66. "\xf5\xde\x8a\x36\xdb\xc6\xe5\x8f\xef\x14\x37\xd6\x00\xf9\xab\x90"
  67. "\x9b\x5d\x57\x4c\xf5\x1f\x77\xc4\xbb\x8b\xdd\x9b\x67\x11\x45\xb2"
  68. "\x64\xe8\xac\xa8\x03\x0f\x16\x0d\x5d\x2d\x53\x07\x23\xfb\x62\x0d"
  69. "\xe6\x16\xd3\x23\xe8\xb3";
  70. static const unsigned char q[] =
  71. "\x06\x66\x9a\x70\x53\xd6\x72\x74\xfd\xea\x45\xc3\xc0\x17\xae\xde"
  72. "\x79\x17\xae\x79\xde\xfc\x0e\xf7\xa4\x3a\x8c\x43\x8f\xc7\x8a\xa2"
  73. "\x2c\x51\xc4\xd0\x72\x89\x73\x5c\x61\xbe\xfd\x54\x3f\x92\x65\xde"
  74. "\x4d\x65\x71\x70\xf6\xf2\xe5\x98\xb9\x0f\xd1\x0b\xe6\x95\x09\x4a"
  75. "\x7a\xdf\xf3\x10\x16\xd0\x60\xfc\xa5\x10\x34\x97\x37\x6f\x0a\xd5"
  76. "\x5d\x8f\xd4\xc3\xa0\x5b";
  77. static const unsigned char dmp1[] =
  78. "\x05\x7c\x9e\x1c\xbd\x90\x25\xe7\x40\x86\xf5\xa8\x3b\x7a\x3f\x99"
  79. "\x56\x95\x60\x3a\x7b\x95\x4b\xb8\xa0\xd7\xa5\xf1\xcc\xdc\x5f\xb5"
  80. "\x8c\xf4\x62\x95\x54\xed\x2e\x12\x62\xc2\xe8\xf6\xde\xce\xed\x8e"
  81. "\x77\x6d\xc0\x40\x25\x74\xb3\x5a\x2d\xaa\xe1\xac\x11\xcb\xe2\x2f"
  82. "\x0a\x51\x23\x1e\x47\xb2\x05\x88\x02\xb2\x0f\x4b\xf0\x67\x30\xf0"
  83. "\x0f\x6e\xef\x5f\xf7\xe7";
  84. static const unsigned char dmq1[] =
  85. "\x01\xa5\x6b\xbc\xcd\xe3\x0e\x46\xc6\x72\xf5\x04\x56\x28\x01\x22"
  86. "\x58\x74\x5d\xbc\x1c\x3c\x29\x41\x49\x6c\x81\x5c\x72\xe2\xf7\xe5"
  87. "\xa3\x8e\x58\x16\xe0\x0e\x37\xac\x1f\xbb\x75\xfd\xaf\xe7\xdf\xe9"
  88. "\x1f\x70\xa2\x8f\x52\x03\xc0\x46\xd9\xf9\x96\x63\x00\x27\x7e\x5f"
  89. "\x38\x60\xd6\x6b\x61\xe2\xaf\xbe\xea\x58\xd3\x9d\xbc\x75\x03\x8d"
  90. "\x42\x65\xd6\x6b\x85\x97";
  91. static const unsigned char iqmp[] =
  92. "\x03\xa1\x8b\x80\xe4\xd8\x87\x25\x17\x5d\xcc\x8d\xa9\x8a\x22\x2b"
  93. "\x6c\x15\x34\x6f\x80\xcc\x1c\x44\x04\x68\xbc\x03\xcd\x95\xbb\x69"
  94. "\x37\x61\x48\xb4\x23\x13\x08\x16\x54\x6a\xa1\x7c\xf5\xd4\x3a\xe1"
  95. "\x4f\xa4\x0c\xf5\xaf\x80\x85\x27\x06\x0d\x70\xc0\xc5\x19\x28\xfe"
  96. "\xee\x8e\x86\x21\x98\x8a\x37\xb7\xe5\x30\x25\x70\x93\x51\x2d\x49"
  97. "\x85\x56\xb3\x0c\x2b\x96";
  98. static const unsigned char ex_prime[] =
  99. "\x03\x89\x22\xa0\xb7\x3a\x91\xcb\x5e\x0c\xfd\x73\xde\xa7\x38\xa9"
  100. "\x47\x43\xd6\x02\xbf\x2a\xb9\x3c\x48\xf3\x06\xd6\x58\x35\x50\x56"
  101. "\x16\x5c\x34\x9b\x61\x87\xc8\xaa\x0a\x5d\x8a\x0a\xcd\x9c\x41\xd9"
  102. "\x96\x24\xe0\xa9\x9b\x26\xb7\xa8\x08\xc9\xea\xdc\xa7\x15\xfb\x62"
  103. "\xa0\x2d\x90\xe6\xa7\x55\x6e\xc6\x6c\xff\xd6\x10\x6d\xfa\x2e\x04"
  104. "\x50\xec\x5c\x66\xe4\x05";
  105. static const unsigned char ex_exponent[] =
  106. "\x02\x0a\xcd\xc3\x82\xd2\x03\xb0\x31\xac\xd3\x20\x80\x34\x9a\x57"
  107. "\xbc\x60\x04\x57\x25\xd0\x29\x9a\x16\x90\xb9\x1c\x49\x6a\xd1\xf2"
  108. "\x47\x8c\x0e\x9e\xc9\x20\xc2\xd8\xe4\x8f\xce\xd2\x1a\x9c\xec\xb4"
  109. "\x1f\x33\x41\xc8\xf5\x62\xd1\xa5\xef\x1d\xa1\xd8\xbd\x71\xc6\xf7"
  110. "\xda\x89\x37\x2e\xe2\xec\x47\xc5\xb8\xe3\xb4\xe3\x5c\x82\xaa\xdd"
  111. "\xb7\x58\x2e\xaf\x07\x79";
  112. static const unsigned char ex_coefficient[] =
  113. "\x00\x9c\x09\x88\x9b\xc8\x57\x08\x69\x69\xab\x2d\x9e\x29\x1c\x3c"
  114. "\x6d\x59\x33\x12\x0d\x2b\x09\x2e\xaf\x01\x2c\x27\x01\xfc\xbd\x26"
  115. "\x13\xf9\x2d\x09\x22\x4e\x49\x11\x03\x82\x88\x87\xf4\x43\x1d\xac"
  116. "\xca\xec\x86\xf7\x23\xf1\x64\xf3\xf5\x81\xf0\x37\x36\xcf\x67\xff"
  117. "\x1a\xff\x7a\xc7\xf9\xf9\x67\x2d\xa0\x9d\x61\xf8\xf6\x47\x5c\x2f"
  118. "\xe7\x66\xe8\x3c\x3a\xe8";
  119. static int key2048_key(RSA *key)
  120. {
  121. if (!TEST_int_eq(RSA_set0_key(key,
  122. BN_bin2bn(n, sizeof(n) - 1, NULL),
  123. BN_bin2bn(e, sizeof(e) - 1, NULL),
  124. BN_bin2bn(d, sizeof(d) - 1, NULL)), 1))
  125. return 0;
  126. return RSA_size(key);
  127. }
  128. static int key2048p3_v1(RSA *key)
  129. {
  130. BIGNUM **pris = NULL, **exps = NULL, **coeffs = NULL;
  131. int rv = RSA_size(key);
  132. if (!TEST_int_eq(RSA_set0_factors(key,
  133. BN_bin2bn(p, sizeof(p) - 1, NULL),
  134. BN_bin2bn(q, sizeof(q) - 1, NULL)), 1))
  135. goto err;
  136. if (!TEST_int_eq(RSA_set0_crt_params(key,
  137. BN_bin2bn(dmp1, sizeof(dmp1) - 1, NULL),
  138. BN_bin2bn(dmq1, sizeof(dmq1) - 1, NULL),
  139. BN_bin2bn(iqmp, sizeof(iqmp) - 1,
  140. NULL)), 1))
  141. return 0;
  142. pris = OPENSSL_zalloc(sizeof(BIGNUM *));
  143. exps = OPENSSL_zalloc(sizeof(BIGNUM *));
  144. coeffs = OPENSSL_zalloc(sizeof(BIGNUM *));
  145. if (!TEST_ptr(pris) || !TEST_ptr(exps) || !TEST_ptr(coeffs))
  146. goto err;
  147. pris[0] = BN_bin2bn(ex_prime, sizeof(ex_prime) - 1, NULL);
  148. exps[0] = BN_bin2bn(ex_exponent, sizeof(ex_exponent) - 1, NULL);
  149. coeffs[0] = BN_bin2bn(ex_coefficient, sizeof(ex_coefficient) - 1, NULL);
  150. if (!TEST_ptr(pris[0]) || !TEST_ptr(exps[0]) || !TEST_ptr(coeffs[0]))
  151. goto err;
  152. if (!TEST_true(RSA_set0_multi_prime_params(key, pris, exps,
  153. coeffs, NUM_EXTRA_PRIMES)))
  154. goto err;
  155. ret:
  156. OPENSSL_free(pris);
  157. OPENSSL_free(exps);
  158. OPENSSL_free(coeffs);
  159. return rv;
  160. err:
  161. if (pris != NULL)
  162. BN_free(pris[0]);
  163. if (exps != NULL)
  164. BN_free(exps[0]);
  165. if (coeffs != NULL)
  166. BN_free(coeffs[0]);
  167. rv = 0;
  168. goto ret;
  169. }
  170. static int key2048p3_v2(RSA *key)
  171. {
  172. STACK_OF(BIGNUM) *primes = NULL, *exps = NULL, *coeffs = NULL;
  173. BIGNUM *num = NULL;
  174. int rv = RSA_size(key);
  175. if (!TEST_ptr(primes = sk_BIGNUM_new_null())
  176. || !TEST_ptr(exps = sk_BIGNUM_new_null())
  177. || !TEST_ptr(coeffs = sk_BIGNUM_new_null()))
  178. goto err;
  179. if (!TEST_ptr(num = BN_bin2bn(p, sizeof(p) - 1, NULL))
  180. || !TEST_int_ne(sk_BIGNUM_push(primes, num), 0)
  181. || !TEST_ptr(num = BN_bin2bn(q, sizeof(q) - 1, NULL))
  182. || !TEST_int_ne(sk_BIGNUM_push(primes, num), 0)
  183. || !TEST_ptr(num = BN_bin2bn(ex_prime, sizeof(ex_prime) - 1, NULL))
  184. || !TEST_int_ne(sk_BIGNUM_push(primes, num), 0))
  185. goto err;
  186. if (!TEST_ptr(num = BN_bin2bn(dmp1, sizeof(dmp1) - 1, NULL))
  187. || !TEST_int_ne(sk_BIGNUM_push(exps, num), 0)
  188. || !TEST_ptr(num = BN_bin2bn(dmq1, sizeof(dmq1) - 1, NULL))
  189. || !TEST_int_ne(sk_BIGNUM_push(exps, num), 0)
  190. || !TEST_ptr(num = BN_bin2bn(ex_exponent, sizeof(ex_exponent) - 1, NULL))
  191. || !TEST_int_ne(sk_BIGNUM_push(exps, num), 0))
  192. goto err;
  193. if (!TEST_ptr(num = BN_bin2bn(iqmp, sizeof(iqmp) - 1, NULL))
  194. || !TEST_int_ne(sk_BIGNUM_push(coeffs, num), 0)
  195. || !TEST_ptr(num = BN_bin2bn(ex_coefficient, sizeof(ex_coefficient) - 1, NULL))
  196. || !TEST_int_ne(sk_BIGNUM_push(coeffs, num), 0))
  197. goto err;
  198. if (!TEST_true(ossl_rsa_set0_all_params(key, primes, exps, coeffs)))
  199. goto err;
  200. ret:
  201. sk_BIGNUM_free(primes);
  202. sk_BIGNUM_free(exps);
  203. sk_BIGNUM_free(coeffs);
  204. return rv;
  205. err:
  206. sk_BIGNUM_pop_free(primes, BN_free);
  207. sk_BIGNUM_pop_free(exps, BN_free);
  208. sk_BIGNUM_pop_free(coeffs, BN_free);
  209. primes = exps = coeffs = NULL;
  210. rv = 0;
  211. goto ret;
  212. }
  213. static int test_rsa_mp(int i)
  214. {
  215. int ret = 0;
  216. RSA *key;
  217. unsigned char ptext[256];
  218. unsigned char ctext[256];
  219. static unsigned char ptext_ex[] = "\x54\x85\x9b\x34\x2c\x49\xea\x2a";
  220. int plen;
  221. int clen = 0;
  222. int num;
  223. static int (*param_set[])(RSA *) = {
  224. key2048p3_v1,
  225. key2048p3_v2,
  226. };
  227. plen = sizeof(ptext_ex) - 1;
  228. key = RSA_new();
  229. if (!TEST_ptr(key))
  230. goto err;
  231. if (!TEST_int_eq((clen = key2048_key(key)), 256)
  232. || !TEST_int_eq((clen = param_set[i](key)), 256))
  233. goto err;
  234. if (!TEST_true(RSA_check_key_ex(key, NULL)))
  235. goto err;
  236. num = RSA_public_encrypt(plen, ptext_ex, ctext, key,
  237. RSA_PKCS1_PADDING);
  238. if (!TEST_int_eq(num, clen))
  239. goto err;
  240. num = RSA_private_decrypt(num, ctext, ptext, key, RSA_PKCS1_PADDING);
  241. if (!TEST_mem_eq(ptext, num, ptext_ex, plen))
  242. goto err;
  243. ret = 1;
  244. err:
  245. RSA_free(key);
  246. return ret;
  247. }
  248. static int test_rsa_mp_gen_bad_input(void)
  249. {
  250. int ret = 0;
  251. RSA *rsa = NULL;
  252. BIGNUM *ebn = NULL;
  253. if (!TEST_ptr(rsa = RSA_new()))
  254. goto err;
  255. if (!TEST_ptr(ebn = BN_new()))
  256. goto err;
  257. if (!TEST_true(BN_set_word(ebn, 65537)))
  258. goto err;
  259. /* Test that a NULL exponent fails and does not segfault */
  260. if (!TEST_int_eq(RSA_generate_multi_prime_key(rsa, 1024, 2, NULL, NULL), 0))
  261. goto err;
  262. /* Test invalid bitsize fails */
  263. if (!TEST_int_eq(RSA_generate_multi_prime_key(rsa, 500, 2, ebn, NULL), 0))
  264. goto err;
  265. /* Test invalid prime count fails */
  266. if (!TEST_int_eq(RSA_generate_multi_prime_key(rsa, 1024, 1, ebn, NULL), 0))
  267. goto err;
  268. ret = 1;
  269. err:
  270. BN_free(ebn);
  271. RSA_free(rsa);
  272. return ret;
  273. }
  274. int setup_tests(void)
  275. {
  276. ADD_TEST(test_rsa_mp_gen_bad_input);
  277. ADD_ALL_TESTS(test_rsa_mp, 2);
  278. return 1;
  279. }