mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(mbedtls): migrates ESP-TEE with PSA APIs
This commit is contained in:
@@ -3,7 +3,10 @@ set(TEST_CRTS "crts/server_cert_chain.pem"
|
||||
"crts/server_cert_bundle"
|
||||
"crts/bad_md_crt.pem"
|
||||
"crts/wrong_sig_crt_esp32_com.pem"
|
||||
"crts/correct_sig_crt_esp32_com.pem")
|
||||
"crts/correct_sig_crt_esp32_com.pem"
|
||||
"crts/ecdsa_cert_bundle"
|
||||
"crts/ecdsa_correct_sig_crt.pem"
|
||||
"crts/ecdsa_wrong_sig_crt.pem")
|
||||
|
||||
idf_component_register(
|
||||
SRC_DIRS "."
|
||||
|
||||
@@ -3,22 +3,46 @@
|
||||
*
|
||||
* SPDX-License-Identifier: Unlicense OR CC0-1.0
|
||||
*/
|
||||
#include <string.h>
|
||||
#include "psa/crypto.h"
|
||||
#include "freertos/FreeRTOS.h"
|
||||
#include "freertos/task.h"
|
||||
#include "unity.h"
|
||||
#include "mbedtls/aes.h"
|
||||
// // #include "mbedtls/aes.h"
|
||||
#include "memory_checks.h"
|
||||
#include "soc/soc_caps.h"
|
||||
#include "esp_newlib.h"
|
||||
#include "esp_random.h"
|
||||
#include "mbedtls/entropy.h"
|
||||
// // #include "mbedtls/entropy.h"
|
||||
|
||||
#define CALL_SZ (32 * 1024)
|
||||
|
||||
/* setUp runs before every test */
|
||||
void setUp(void)
|
||||
{
|
||||
// psa_crypto_init();
|
||||
// Execute mbedtls_aes_init operation to allocate AES interrupt
|
||||
// allocation memory which is considered as leak otherwise
|
||||
#if SOC_AES_SUPPORTED
|
||||
uint8_t iv[16];
|
||||
uint8_t key[16];
|
||||
memset(iv, 0xEE, 16);
|
||||
memset(key, 0x44, 16);
|
||||
|
||||
uint8_t *buf = heap_caps_malloc(CALL_SZ, MALLOC_CAP_DMA | MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL);
|
||||
TEST_ASSERT_NOT_NULL(buf);
|
||||
psa_key_id_t key_id;
|
||||
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
|
||||
psa_set_key_algorithm(&attributes, PSA_ALG_ECB_NO_PADDING);
|
||||
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
|
||||
psa_set_key_bits(&attributes, 128);
|
||||
psa_import_key(&attributes, key, sizeof(key), &key_id);
|
||||
|
||||
size_t output_length = 0;
|
||||
psa_cipher_encrypt(key_id, PSA_ALG_ECB_NO_PADDING, buf, CALL_SZ, buf, CALL_SZ, &output_length);
|
||||
heap_caps_free(buf);
|
||||
psa_destroy_key(key_id);
|
||||
// mbedtls_aes_context ctx;
|
||||
// mbedtls_aes_init(&ctx);
|
||||
#endif // SOC_AES_SUPPORTED
|
||||
|
||||
Binary file not shown.
@@ -0,0 +1,15 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIICQjCCAcmgAwIBAgIUTbvKUa+55zFxQhgDIQ91RdGXEXIwCgYIKoZIzj0EAwQw
|
||||
YDELMAkGA1UEBhMCVVMxDTALBgNVBAgMBFRlc3QxDTALBgNVBAcMBFRlc3QxFjAU
|
||||
BgNVBAoMDVRlc3QgRUNEU0EgQ0ExGzAZBgNVBAMMElRlc3QgRUNEU0EgUm9vdCBD
|
||||
QTAeFw0yNTExMDMwODAzNTdaFw0yNjExMDMwODAzNTdaMGIxCzAJBgNVBAYTAlVT
|
||||
MQ0wCwYDVQQIDARUZXN0MQ0wCwYDVQQHDARUZXN0MRQwEgYDVQQKDAtUZXN0IFNl
|
||||
cnZlcjEfMB0GA1UEAwwWZWNkc2EtdGVzdC5leGFtcGxlLmNvbTB2MBAGByqGSM49
|
||||
AgEGBSuBBAAiA2IABFd+Bd6HtASMpEytx+QfDk8I0DX73EKQ3tR2TUJuhg7B2epc
|
||||
qqmMXZ5KQpOY/+V0kv1WyLCDisw7vP6d4yQjokSJqEnaO3af5TJh0WCjWJsVtNZy
|
||||
VAQMS9lxSZW1a1lle6NCMEAwHQYDVR0OBBYEFNJ2LzJjqMZXRjY0NNvVTS3Crsjh
|
||||
MB8GA1UdIwQYMBaAFElMhoUHf0Loi7Kzcpp0t4AfUBsuMAoGCCqGSM49BAMEA2cA
|
||||
MGQCMCiXh9m1BOkedod4lVzKLx535sLbFM7OxnYFxYOCK4Q3djtgxjy0OFmlyD5I
|
||||
YLUfxAIwO35NHh06OMyOI85NJbOYD2oPDiju/1JYHhER9rPAFrJJtwKGhNlMufqk
|
||||
V+9SwUK2
|
||||
-----END CERTIFICATE-----
|
||||
@@ -0,0 +1,15 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIICQjCCAcmgAwIBAgIUTbvKUa+55zFxQhgDIQ91RdGXEXIwCgYIKoZIzj0EAwQw
|
||||
YDELMAkGA1UEBhMCVVMxDTALBgNVBAgMBFRlc3QxDTALBgNVBAcMBFRlc3QxFjAU
|
||||
BgNVBAoMDVRlc3QgRUNEU0EgQ0ExGzAZBgNVBAMMElRlc3QgRUNEU0EgUm9vdCBD
|
||||
QTAeFw0yNTExMDMwODAzNTdaFw0yNjExMDMwODAzNTdaMGIxCzAJBgNVBAYTAlVT
|
||||
MQ0wCwYDVQQIDARUZXN0MQ0wCwYDVQQHDARUZXN0MRQwEgYDVQQKDAtUZXN0IFNl
|
||||
cnZlcjEfMB0GA1UEAwwWZWNkc2EtdGVzdC5leGFtcGxlLmNvbTB2MBAGByqGSM49
|
||||
AgEGBSuBBAAiA2IABFd+Bd6HtASMpEytx+QfDk8I0DX73EKQ3tR2TUJuhg7B2epc
|
||||
qqmMXZ5KQpOY/+V0kv1WyLCDisw7vP6d4yQjokSJqEnaO3af5TJh0WCjWJsVtNZy
|
||||
VAQMS9lxSZW1a1lle6NCMEAwHQYDVR0OBBYEFNJ2LzJjqMZXRjY0NNvVTS3Crsjh
|
||||
MB8GA1UdIwQYMBaAFElMhoUHf0Loi7Kzcpp0t4AfUBsuMAoGCCqGSM49BAMEA2cA
|
||||
MGQCMCiXh9m1BOkedod4lVzKMx535sLbFM7OxnYFxYOCK4Q3djtgxjy0OFmlyD5I
|
||||
YLUfxAIwO35NHh06OMyOI85NJbOYD2oPDiju/1JYHhER9rPAFrJJtwKGhNlMufqk
|
||||
V+9SwUK2
|
||||
-----END CERTIFICATE-----
|
||||
+1
-1
@@ -11,7 +11,7 @@
|
||||
#include <stdio.h>
|
||||
#include <stdbool.h>
|
||||
#include <esp_system.h>
|
||||
#include "mbedtls/aes.h"
|
||||
// #include "mbedtls/aes.h"
|
||||
#include "mbedtls/gcm.h"
|
||||
#include "unity.h"
|
||||
#include "sdkconfig.h"
|
||||
+1
-1
@@ -9,7 +9,7 @@
|
||||
#include <stdbool.h>
|
||||
#include <esp_system.h>
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "mbedtls/aes.h"
|
||||
// #include "mbedtls/aes.h"
|
||||
#include "mbedtls/gcm.h"
|
||||
#include "unity.h"
|
||||
#include "sdkconfig.h"
|
||||
@@ -25,10 +25,7 @@ TEST_CASE("mbedtls AES performance", "[aes][timeout=60]")
|
||||
uint8_t iv[16];
|
||||
uint8_t key[16];
|
||||
|
||||
psa_status_t status = PSA_SUCCESS;
|
||||
// if (status != PSA_SUCCESS) {
|
||||
// TEST_FAIL_MESSAGE("PSA crypto initialization failed");
|
||||
// }
|
||||
psa_status_t status;
|
||||
|
||||
memset(iv, 0xEE, 16);
|
||||
memset(key, 0x44, 16);
|
||||
@@ -65,7 +62,7 @@ TEST_CASE("mbedtls AES performance", "[aes][timeout=60]")
|
||||
memset(buf, 0xAA, CALL_SZ);
|
||||
psa_cipher_update(&operation, buf, CALL_SZ, buf, CALL_SZ, &output_length);
|
||||
}
|
||||
psa_cipher_finish(&operation, buf + CALL_SZ - 16, 16, &output_length);
|
||||
psa_cipher_finish(&operation, buf + output_length, CALL_SZ - output_length, &output_length);
|
||||
elapsed_usec = ccomp_timer_stop();
|
||||
|
||||
/* Sanity check: make sure the last ciphertext block matches
|
||||
|
||||
@@ -7,8 +7,8 @@
|
||||
#include <stdbool.h>
|
||||
#include <esp_system.h>
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "mbedtls/aes.h"
|
||||
#include "mbedtls/sha256.h"
|
||||
// // #include "mbedtls/aes.h"
|
||||
// // #include "mbedtls/sha256.h"
|
||||
#include "unity.h"
|
||||
#include "sdkconfig.h"
|
||||
#include "esp_heap_caps.h"
|
||||
@@ -64,10 +64,21 @@ static void tskRunAES256Test(void *pvParameters)
|
||||
0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f,
|
||||
};
|
||||
|
||||
psa_key_id_t key_id;
|
||||
psa_algorithm_t alg = PSA_ALG_CBC_NO_PADDING;
|
||||
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
|
||||
psa_set_key_algorithm(&attributes, alg);
|
||||
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
|
||||
psa_set_key_bits(&attributes, sizeof(key_256) * 8);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_import_key(&attributes, key_256, sizeof(key_256), &key_id));
|
||||
psa_reset_key_attributes(&attributes);
|
||||
|
||||
for (int i = 0; i <1000; i++)
|
||||
{
|
||||
const unsigned SZ = 1600;
|
||||
mbedtls_aes_context ctx;
|
||||
// mbedtls_aes_context ctx;
|
||||
psa_cipher_operation_t ctx = PSA_CIPHER_OPERATION_INIT;
|
||||
uint8_t nonce[16];
|
||||
|
||||
const uint8_t expected_cipher_end[] = {
|
||||
@@ -88,24 +99,32 @@ static void tskRunAES256Test(void *pvParameters)
|
||||
TEST_ASSERT_NOT_NULL(plaintext);
|
||||
TEST_ASSERT_NOT_NULL(decryptedtext);
|
||||
|
||||
mbedtls_aes_init(&ctx);
|
||||
mbedtls_aes_setkey_enc(&ctx, key_256, 256);
|
||||
psa_cipher_encrypt_setup(&ctx, key_id, PSA_ALG_CBC_NO_PADDING);
|
||||
psa_cipher_set_iv(&ctx, nonce, sizeof(nonce));
|
||||
// mbedtls_aes_init(&ctx);
|
||||
// mbedtls_aes_setkey_enc(&ctx, key_256, 256);
|
||||
|
||||
memset(plaintext, 0x3A, SZ);
|
||||
memset(decryptedtext, 0x0, SZ);
|
||||
|
||||
// Encrypt
|
||||
mbedtls_aes_crypt_cbc(&ctx, MBEDTLS_AES_ENCRYPT, SZ, nonce, plaintext, ciphertext);
|
||||
// mbedtls_aes_crypt_cbc(&ctx, MBEDTLS_AES_ENCRYPT, SZ, nonce, plaintext, ciphertext);
|
||||
size_t enc_len = 0;
|
||||
psa_cipher_update(&ctx, plaintext, SZ, ciphertext, SZ, &enc_len);
|
||||
psa_cipher_finish(&ctx, ciphertext + enc_len, SZ - enc_len, &enc_len);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(expected_cipher_end, ciphertext + SZ - 32, 32);
|
||||
|
||||
// Decrypt
|
||||
memcpy(nonce, iv, 16);
|
||||
mbedtls_aes_setkey_dec(&ctx, key_256, 256);
|
||||
mbedtls_aes_crypt_cbc(&ctx, MBEDTLS_AES_DECRYPT, SZ, nonce, ciphertext, decryptedtext);
|
||||
psa_cipher_decrypt_setup(&ctx, key_id, PSA_ALG_CBC_NO_PADDING);
|
||||
psa_cipher_set_iv(&ctx, nonce, sizeof(nonce));
|
||||
psa_cipher_update(&ctx, ciphertext, SZ, decryptedtext, SZ, &enc_len);
|
||||
psa_cipher_finish(&ctx, decryptedtext + enc_len, SZ - enc_len, &enc_len);
|
||||
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(plaintext, decryptedtext, SZ);
|
||||
|
||||
mbedtls_aes_free(&ctx);
|
||||
// mbedtls_aes_free(&ctx);
|
||||
psa_cipher_abort(&ctx);
|
||||
free(plaintext);
|
||||
free(ciphertext);
|
||||
free(decryptedtext);
|
||||
|
||||
@@ -23,8 +23,8 @@
|
||||
#include "esp_log.h"
|
||||
#include "sha/sha_parallel_engine.h"
|
||||
#include "aes/esp_aes.h"
|
||||
#include "mbedtls/rsa.h"
|
||||
#include "mbedtls/sha256.h"
|
||||
// #include "mbedtls/rsa.h"
|
||||
// #include "mbedtls/sha256.h"
|
||||
#include "psa/crypto.h"
|
||||
|
||||
static const char *TAG = "test";
|
||||
@@ -163,7 +163,7 @@ static void rsa_task(void *pvParameters)
|
||||
SemaphoreHandle_t *sema = (SemaphoreHandle_t *) pvParameters;
|
||||
ESP_LOGI(TAG, "rsa_task is started");
|
||||
while (exit_flag == false) {
|
||||
mbedtls_rsa_self_test(0);
|
||||
// mbedtls_rsa_self_test(0);
|
||||
}
|
||||
xSemaphoreGive(*sema);
|
||||
vTaskDelete(NULL);
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
|
||||
#include <string.h>
|
||||
#include "unity.h"
|
||||
#include "mbedtls/rsa.h"
|
||||
#include "mbedtls/private/rsa.h"
|
||||
#include "esp_random.h"
|
||||
#include "sdkconfig.h"
|
||||
|
||||
@@ -16,10 +16,7 @@
|
||||
static heap_trace_record_t trace_record[NUM_RECORDS]; // This buffer must be in internal RAM
|
||||
#endif
|
||||
|
||||
// Disabled these tests for now as with PSA, DS peripheral probably can not be used like this
|
||||
// Instead we will have to create a driver
|
||||
#if 0
|
||||
// #ifdef SOC_DIG_SIGN_SUPPORTED
|
||||
#ifdef SOC_DIG_SIGN_SUPPORTED
|
||||
#include "soc/soc_caps.h"
|
||||
#include "esp_ds.h"
|
||||
#include "esp_ds/esp_ds_rsa.h"
|
||||
@@ -41,9 +38,12 @@ TEST_CASE("ds sign test pkcs1_v15", "[ds_rsa]")
|
||||
mbedtls_esp_random(NULL, hash, sizeof(hash)); // Fill hash with random data
|
||||
unsigned int hashlen = sizeof(hash);
|
||||
unsigned char signature[256] = {0};
|
||||
mbedtls_pk_context pk;
|
||||
mbedtls_pk_init(&pk);
|
||||
pk.MBEDTLS_PRIVATE(pk_ctx) = &rsa_ctx;
|
||||
|
||||
// esp_ds is not initialized, so we expect an error
|
||||
int err = esp_ds_rsa_sign(&rsa_ctx, mbedtls_esp_random, NULL, MBEDTLS_MD_SHA256, hashlen, hash, signature);
|
||||
int err = esp_ds_rsa_sign(&pk, mbedtls_esp_random, NULL, MBEDTLS_MD_SHA256, hashlen, hash, signature);
|
||||
TEST_ASSERT_EQUAL(-1, err);
|
||||
|
||||
// Initialize the esp_ds context
|
||||
@@ -58,7 +58,7 @@ TEST_CASE("ds sign test pkcs1_v15", "[ds_rsa]")
|
||||
TEST_ASSERT_EQUAL(ESP_OK, err);
|
||||
|
||||
// Now we can call esp_ds_rsa_sign again
|
||||
err = esp_ds_rsa_sign(&rsa_ctx, mbedtls_esp_random, NULL, MBEDTLS_MD_SHA256, hashlen, hash, signature);
|
||||
err = esp_ds_rsa_sign(&pk, mbedtls_esp_random, NULL, MBEDTLS_MD_SHA256, hashlen, hash, signature);
|
||||
TEST_ASSERT_EQUAL(0, err);
|
||||
TEST_ASSERT_NOT_NULL(signature);
|
||||
|
||||
@@ -92,9 +92,12 @@ TEST_CASE("ds sign test pkcs1_v21", "[ds_rsa]")
|
||||
mbedtls_esp_random(NULL, hash, sizeof(hash)); // Fill hash with random data
|
||||
unsigned int hashlen = sizeof(hash);
|
||||
unsigned char signature[256] = {0};
|
||||
mbedtls_pk_context pk;
|
||||
mbedtls_pk_init(&pk);
|
||||
pk.MBEDTLS_PRIVATE(pk_ctx) = &rsa_ctx;
|
||||
|
||||
// esp_ds is not initialized, so we expect an error
|
||||
int err = esp_ds_rsa_sign(&rsa_ctx, mbedtls_esp_random, NULL, MBEDTLS_MD_SHA256, hashlen, hash, signature);
|
||||
int err = esp_ds_rsa_sign(&pk, mbedtls_esp_random, NULL, MBEDTLS_MD_SHA256, hashlen, hash, signature);
|
||||
TEST_ASSERT_EQUAL(-1, err);
|
||||
|
||||
// Initialize the esp_ds context
|
||||
@@ -109,7 +112,7 @@ TEST_CASE("ds sign test pkcs1_v21", "[ds_rsa]")
|
||||
TEST_ASSERT_EQUAL(ESP_OK, err);
|
||||
|
||||
// Now we can call esp_ds_rsa_sign again
|
||||
err = esp_ds_rsa_sign(&rsa_ctx, mbedtls_esp_random, NULL, MBEDTLS_MD_SHA256, hashlen, hash, signature);
|
||||
err = esp_ds_rsa_sign(&pk, mbedtls_esp_random, NULL, MBEDTLS_MD_SHA256, hashlen, hash, signature);
|
||||
TEST_ASSERT_EQUAL(0, err);
|
||||
TEST_ASSERT_NOT_NULL(signature);
|
||||
|
||||
|
||||
@@ -13,12 +13,13 @@
|
||||
#include <inttypes.h>
|
||||
#include <esp_random.h>
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include <mbedtls/entropy.h>
|
||||
#include <mbedtls/ctr_drbg.h>
|
||||
#include <mbedtls/ecdh.h>
|
||||
#include <mbedtls/ecdsa.h>
|
||||
// #include <mbedtls/entropy.h>
|
||||
// #include <mbedtls/ctr_drbg.h>
|
||||
#include <mbedtls/private/ecdh.h>
|
||||
#include <mbedtls/private/ecdsa.h>
|
||||
#include <mbedtls/error.h>
|
||||
#include "psa/crypto.h"
|
||||
#include "mbedtls/psa_util.h"
|
||||
|
||||
#include "test_utils.h"
|
||||
#include "ccomp_timer.h"
|
||||
@@ -97,29 +98,29 @@ TEST_CASE("mbedtls ECP self-tests", "[mbedtls]")
|
||||
TEST_CASE("mbedtls ECP mul w/ koblitz", "[mbedtls]")
|
||||
{
|
||||
/* Test case code via https://github.com/espressif/esp-idf/issues/1556 */
|
||||
mbedtls_entropy_context ctxEntropy;
|
||||
mbedtls_ctr_drbg_context ctxRandom;
|
||||
// mbedtls_entropy_context ctxEntropy;
|
||||
// mbedtls_ctr_drbg_context ctxRandom;
|
||||
mbedtls_ecdsa_context ctxECDSA;
|
||||
const char* pers = "myecdsa";
|
||||
// const char* pers = "myecdsa";
|
||||
|
||||
mbedtls_entropy_init(&ctxEntropy);
|
||||
mbedtls_ctr_drbg_init(&ctxRandom);
|
||||
TEST_ASSERT_MBEDTLS_OK( mbedtls_ctr_drbg_seed(&ctxRandom, mbedtls_entropy_func, &ctxEntropy,
|
||||
(const unsigned char*) pers, strlen(pers)) );
|
||||
// mbedtls_entropy_init(&ctxEntropy);
|
||||
// mbedtls_ctr_drbg_init(&ctxRandom);
|
||||
// TEST_ASSERT_MBEDTLS_OK( mbedtls_ctr_drbg_seed(&ctxRandom, mbedtls_entropy_func, &ctxEntropy,
|
||||
// (const unsigned char*) pers, strlen(pers)) );
|
||||
|
||||
mbedtls_ecdsa_init(&ctxECDSA);
|
||||
|
||||
TEST_ASSERT_MBEDTLS_OK( mbedtls_ecdsa_genkey(&ctxECDSA, MBEDTLS_ECP_DP_SECP256K1,
|
||||
mbedtls_ctr_drbg_random, &ctxRandom) );
|
||||
mbedtls_psa_get_random, MBEDTLS_PSA_RANDOM_STATE) );
|
||||
|
||||
|
||||
TEST_ASSERT_MBEDTLS_OK(mbedtls_ecp_mul(&ctxECDSA.MBEDTLS_PRIVATE(grp), &ctxECDSA.MBEDTLS_PRIVATE(Q),
|
||||
&ctxECDSA.MBEDTLS_PRIVATE(d), &ctxECDSA.MBEDTLS_PRIVATE(grp).G,
|
||||
mbedtls_ctr_drbg_random, &ctxRandom) );
|
||||
mbedtls_psa_get_random, MBEDTLS_PSA_RANDOM_STATE) );
|
||||
|
||||
mbedtls_ecdsa_free(&ctxECDSA);
|
||||
mbedtls_ctr_drbg_free(&ctxRandom);
|
||||
mbedtls_entropy_free(&ctxEntropy);
|
||||
// mbedtls_ctr_drbg_free(&ctxRandom);
|
||||
// mbedtls_entropy_free(&ctxEntropy);
|
||||
}
|
||||
|
||||
#if CONFIG_MBEDTLS_HARDWARE_ECC
|
||||
|
||||
@@ -16,8 +16,8 @@
|
||||
#include "freertos/task.h"
|
||||
#include "freertos/semphr.h"
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "mbedtls/entropy.h"
|
||||
#include "mbedtls/ctr_drbg.h"
|
||||
// // #include "mbedtls/entropy.h"
|
||||
// // #include "mbedtls/ctr_drbg.h"
|
||||
#include "mbedtls/x509.h"
|
||||
#include "mbedtls/ssl.h"
|
||||
#include "entropy_poll.h"
|
||||
@@ -29,6 +29,8 @@
|
||||
#include "esp_crt_bundle.h"
|
||||
#include "esp_random.h"
|
||||
|
||||
#include "psa/crypto.h"
|
||||
|
||||
#include "unity.h"
|
||||
#include "test_utils.h"
|
||||
#include "unity_test_utils.h"
|
||||
@@ -55,14 +57,24 @@ extern const uint8_t wrong_sig_crt_pem_end[] asm("_binary_wrong_sig_crt_esp32_
|
||||
extern const uint8_t correct_sig_crt_pem_start[] asm("_binary_correct_sig_crt_esp32_com_pem_start");
|
||||
extern const uint8_t correct_sig_crt_pem_end[] asm("_binary_correct_sig_crt_esp32_com_pem_end");
|
||||
|
||||
// ECDSA test certificates
|
||||
extern const uint8_t ecdsa_correct_sig_crt_pem_start[] asm("_binary_ecdsa_correct_sig_crt_pem_start");
|
||||
extern const uint8_t ecdsa_correct_sig_crt_pem_end[] asm("_binary_ecdsa_correct_sig_crt_pem_end");
|
||||
|
||||
extern const uint8_t ecdsa_wrong_sig_crt_pem_start[] asm("_binary_ecdsa_wrong_sig_crt_pem_start");
|
||||
extern const uint8_t ecdsa_wrong_sig_crt_pem_end[] asm("_binary_ecdsa_wrong_sig_crt_pem_end");
|
||||
|
||||
extern const uint8_t ecdsa_cert_bundle_start[] asm("_binary_ecdsa_cert_bundle_start");
|
||||
extern const uint8_t ecdsa_cert_bundle_end[] asm("_binary_ecdsa_cert_bundle_end");
|
||||
|
||||
#define SEM_TIMEOUT 10000
|
||||
typedef struct {
|
||||
mbedtls_ssl_context ssl;
|
||||
mbedtls_net_context listen_fd;
|
||||
mbedtls_net_context client_fd;
|
||||
|
||||
mbedtls_entropy_context entropy;
|
||||
mbedtls_ctr_drbg_context ctr_drbg;
|
||||
// mbedtls_entropy_context entropy;
|
||||
// mbedtls_ctr_drbg_context ctr_drbg;
|
||||
|
||||
mbedtls_ssl_config conf;
|
||||
mbedtls_x509_crt cert;
|
||||
@@ -102,8 +114,8 @@ esp_err_t server_setup(mbedtls_endpoint_t *server)
|
||||
mbedtls_ssl_init( &server->ssl );
|
||||
mbedtls_x509_crt_init( &server->cert );
|
||||
mbedtls_pk_init( &server->pkey );
|
||||
mbedtls_entropy_init( &server->entropy );
|
||||
mbedtls_ctr_drbg_init( &server->ctr_drbg );
|
||||
// mbedtls_entropy_init( &server->entropy );
|
||||
// mbedtls_ctr_drbg_init( &server->ctr_drbg );
|
||||
|
||||
ESP_LOGI(TAG, "Loading the server cert and key");
|
||||
ret = mbedtls_x509_crt_parse( &server->cert, server_cert_chain_pem_start,
|
||||
@@ -128,12 +140,12 @@ esp_err_t server_setup(mbedtls_endpoint_t *server)
|
||||
}
|
||||
mbedtls_net_set_nonblock(&server->listen_fd);
|
||||
|
||||
ESP_LOGI(TAG, "Seeding the random number generator");
|
||||
if ( ( ret = mbedtls_ctr_drbg_seed( &server->ctr_drbg, mbedtls_entropy_func, &server->entropy,
|
||||
NULL, 0) ) != 0 ) {
|
||||
ESP_LOGE(TAG, "mbedtls_ctr_drbg_seed returned %d", ret );
|
||||
return ESP_FAIL;
|
||||
}
|
||||
// ESP_LOGI(TAG, "Seeding the random number generator");
|
||||
// if ( ( ret = mbedtls_ctr_drbg_seed( &server->ctr_drbg, mbedtls_entropy_func, &server->entropy,
|
||||
// NULL, 0) ) != 0 ) {
|
||||
// ESP_LOGE(TAG, "mbedtls_ctr_drbg_seed returned %d", ret );
|
||||
// return ESP_FAIL;
|
||||
// }
|
||||
|
||||
ESP_LOGI(TAG, "Setting up the SSL data");
|
||||
if ( ( ret = mbedtls_ssl_config_defaults( &server->conf,
|
||||
@@ -209,8 +221,8 @@ esp_err_t endpoint_teardown(mbedtls_endpoint_t *endpoint)
|
||||
mbedtls_ssl_free( &endpoint->ssl );
|
||||
mbedtls_ssl_config_free( &endpoint->conf );
|
||||
|
||||
mbedtls_ctr_drbg_free( &endpoint->ctr_drbg );
|
||||
mbedtls_entropy_free( &endpoint->entropy );
|
||||
// mbedtls_ctr_drbg_free( &endpoint->ctr_drbg );
|
||||
// mbedtls_entropy_free( &endpoint->entropy );
|
||||
|
||||
return ESP_OK;
|
||||
}
|
||||
@@ -223,18 +235,19 @@ esp_err_t client_setup(mbedtls_endpoint_t *client)
|
||||
mbedtls_esp_enable_debug_log( &client->conf, CONFIG_MBEDTLS_DEBUG_LEVEL );
|
||||
#endif
|
||||
mbedtls_net_init( &client->client_fd );
|
||||
mbedtls_net_init( &client->listen_fd );
|
||||
mbedtls_ssl_init( &client->ssl );
|
||||
mbedtls_x509_crt_init( &client->cert );
|
||||
mbedtls_pk_init( &client->pkey );
|
||||
mbedtls_entropy_init( &client->entropy );
|
||||
mbedtls_ctr_drbg_init( &client->ctr_drbg );
|
||||
// mbedtls_entropy_init( &client->entropy );
|
||||
// mbedtls_ctr_drbg_init( &client->ctr_drbg );
|
||||
|
||||
ESP_LOGI(TAG, "Seeding the random number generator");
|
||||
if ((ret = mbedtls_ctr_drbg_seed(&client->ctr_drbg, mbedtls_entropy_func, &client->entropy,
|
||||
NULL, 0)) != 0) {
|
||||
ESP_LOGE(TAG, "mbedtls_ctr_drbg_seed returned %d", ret);
|
||||
return ESP_FAIL;
|
||||
}
|
||||
// ESP_LOGI(TAG, "Seeding the random number generator");
|
||||
// if ((ret = mbedtls_ctr_drbg_seed(&client->ctr_drbg, mbedtls_entropy_func, &client->entropy,
|
||||
// NULL, 0)) != 0) {
|
||||
// ESP_LOGE(TAG, "mbedtls_ctr_drbg_seed returned %d", ret);
|
||||
// return ESP_FAIL;
|
||||
// }
|
||||
|
||||
ESP_LOGI(TAG, "Setting hostname for TLS session...");
|
||||
/* Hostname set here should match CN in server certificate */
|
||||
@@ -336,7 +349,7 @@ void client_task(void *pvParameters)
|
||||
}
|
||||
|
||||
ESP_LOGI(TAG, "Verifying peer X.509 certificate for bundle ...");
|
||||
ret = mbedtls_ssl_get_verify_result(&client->ssl);
|
||||
ret = mbedtls_ssl_get_verify_result(&client->ssl);
|
||||
|
||||
res = (ret == 0) ? ESP_CRT_VALIDATE_OK : ESP_CRT_VALIDATE_FAIL;
|
||||
|
||||
@@ -447,6 +460,56 @@ TEST_CASE("custom certificate bundle - wrong signature", "[mbedtls]")
|
||||
esp_crt_bundle_detach(NULL);
|
||||
}
|
||||
|
||||
TEST_CASE("custom certificate bundle - ECDSA signature verification", "[mbedtls]")
|
||||
{
|
||||
/* Verify that ECDSA certificates with SHA-512 work correctly with PSA-based verification.
|
||||
* This tests both the ECDSA algorithm path and a different hash algorithm (SHA-512) than
|
||||
* the RSA tests which use SHA-256. */
|
||||
|
||||
// CRITICAL: Initialize PSA crypto subsystem before any PSA operations
|
||||
// psa_status_t psa_status = psa_crypto_init();
|
||||
// if (psa_status != PSA_SUCCESS) {
|
||||
// printf("PSA crypto initialization failed with status 0x%x\n", (unsigned int)psa_status);
|
||||
// TEST_FAIL_MESSAGE("PSA crypto init failed");
|
||||
// }
|
||||
// printf("PSA crypto initialized successfully\n");
|
||||
|
||||
mbedtls_x509_crt crt;
|
||||
uint32_t flags = 0;
|
||||
|
||||
esp_crt_bundle_attach(NULL);
|
||||
|
||||
// Set the ECDSA bundle
|
||||
esp_crt_bundle_set(ecdsa_cert_bundle_start, ecdsa_cert_bundle_end - ecdsa_cert_bundle_start);
|
||||
|
||||
// Test: ECDSA certificate with wrong signature should FAIL
|
||||
mbedtls_x509_crt_init(&crt);
|
||||
printf("Testing ECDSA certificate with wrong signature\n");
|
||||
mbedtls_x509_crt_parse(&crt, ecdsa_wrong_sig_crt_pem_start,
|
||||
ecdsa_wrong_sig_crt_pem_end - ecdsa_wrong_sig_crt_pem_start);
|
||||
|
||||
// Verify with the ECDSA bundle - this should fail
|
||||
int verify_result = mbedtls_x509_crt_verify(&crt, NULL, NULL, NULL, &flags,
|
||||
esp_crt_verify_callback, NULL);
|
||||
TEST_ASSERT_NOT_EQUAL(0, verify_result);
|
||||
mbedtls_x509_crt_free(&crt);
|
||||
|
||||
// Test: ECDSA certificate with correct signature should PASS
|
||||
mbedtls_x509_crt_init(&crt);
|
||||
printf("Testing ECDSA certificate with correct signature\n");
|
||||
mbedtls_x509_crt_parse(&crt, ecdsa_correct_sig_crt_pem_start,
|
||||
ecdsa_correct_sig_crt_pem_end - ecdsa_correct_sig_crt_pem_start);
|
||||
|
||||
// Verify with the ECDSA bundle - this should succeed
|
||||
verify_result = mbedtls_x509_crt_verify(&crt, NULL, NULL, NULL, &flags,
|
||||
esp_crt_verify_callback, NULL);
|
||||
|
||||
TEST_ASSERT_EQUAL(0, verify_result);
|
||||
mbedtls_x509_crt_free(&crt);
|
||||
|
||||
esp_crt_bundle_detach(NULL);
|
||||
}
|
||||
|
||||
TEST_CASE("custom certificate bundle init API - bound checking - NULL certificate bundle", "[mbedtls]")
|
||||
{
|
||||
esp_err_t esp_ret;
|
||||
|
||||
@@ -9,6 +9,7 @@
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "esp_heap_caps.h"
|
||||
#include "mbedtls/gcm.h"
|
||||
#include "mbedtls/private/gcm.h"
|
||||
#include "sdkconfig.h"
|
||||
#include "unity.h"
|
||||
|
||||
|
||||
@@ -15,12 +15,12 @@
|
||||
#include <stdbool.h>
|
||||
#include <esp_system.h>
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "mbedtls/sha1.h"
|
||||
#include "mbedtls/sha256.h"
|
||||
#include "mbedtls/sha512.h"
|
||||
#include "mbedtls/aes.h"
|
||||
#include "mbedtls/bignum.h"
|
||||
#include "mbedtls/rsa.h"
|
||||
// // #include "mbedtls/sha1.h"
|
||||
// // #include "mbedtls/sha256.h"
|
||||
// #include "mbedtls/sha512.h"
|
||||
// // #include "mbedtls/aes.h"
|
||||
// #include "mbedtls/bignum.h"
|
||||
// #include "mbedtls/rsa.h"
|
||||
#include "freertos/FreeRTOS.h"
|
||||
#include "freertos/task.h"
|
||||
#include "freertos/semphr.h"
|
||||
@@ -29,23 +29,23 @@
|
||||
#include "test_apb_dport_access.h"
|
||||
#include "test_utils.h"
|
||||
|
||||
TEST_CASE("mbedtls AES self-tests", "[aes]")
|
||||
{
|
||||
start_apb_access_loop();
|
||||
TEST_ASSERT_FALSE_MESSAGE(mbedtls_aes_self_test(1), "AES self-tests should pass.");
|
||||
verify_apb_access_loop();
|
||||
}
|
||||
// TEST_CASE("mbedtls AES self-tests", "[aes]")
|
||||
// {
|
||||
// start_apb_access_loop();
|
||||
// TEST_ASSERT_FALSE_MESSAGE(mbedtls_aes_self_test(1), "AES self-tests should pass.");
|
||||
// verify_apb_access_loop();
|
||||
// }
|
||||
|
||||
TEST_CASE("mbedtls MPI self-tests", "[bignum]")
|
||||
{
|
||||
start_apb_access_loop();
|
||||
TEST_ASSERT_FALSE_MESSAGE(mbedtls_mpi_self_test(1), "MPI self-tests should pass.");
|
||||
verify_apb_access_loop();
|
||||
}
|
||||
// TEST_CASE("mbedtls MPI self-tests", "[bignum]")
|
||||
// {
|
||||
// start_apb_access_loop();
|
||||
// TEST_ASSERT_FALSE_MESSAGE(mbedtls_mpi_self_test(1), "MPI self-tests should pass.");
|
||||
// verify_apb_access_loop();
|
||||
// }
|
||||
|
||||
TEST_CASE("mbedtls RSA self-tests", "[bignum]")
|
||||
{
|
||||
start_apb_access_loop();
|
||||
TEST_ASSERT_FALSE_MESSAGE(mbedtls_rsa_self_test(1), "RSA self-tests should pass.");
|
||||
verify_apb_access_loop();
|
||||
}
|
||||
// TEST_CASE("mbedtls RSA self-tests", "[bignum]")
|
||||
// {
|
||||
// start_apb_access_loop();
|
||||
// TEST_ASSERT_FALSE_MESSAGE(mbedtls_rsa_self_test(1), "RSA self-tests should pass.");
|
||||
// verify_apb_access_loop();
|
||||
// }
|
||||
|
||||
@@ -10,11 +10,13 @@
|
||||
#include <inttypes.h>
|
||||
#include <esp_log.h>
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include <mbedtls/entropy.h>
|
||||
#include <mbedtls/ctr_drbg.h>
|
||||
#include <mbedtls/ecdh.h>
|
||||
#include <mbedtls/ecdsa.h>
|
||||
// #include <mbedtls/entropy.h>
|
||||
// #include <mbedtls/ctr_drbg.h>
|
||||
#include <mbedtls/private/ecdh.h>
|
||||
#include <mbedtls/private/ecdsa.h>
|
||||
#include <mbedtls/private/pk_private.h>
|
||||
#include <mbedtls/error.h>
|
||||
#include "psa/crypto.h"
|
||||
|
||||
#include "hal/efuse_ll.h"
|
||||
#include "esp_efuse.h"
|
||||
@@ -194,6 +196,31 @@ void test_ecdsa_verify(mbedtls_ecp_group_id id, const uint8_t *hash, const uint8
|
||||
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_read_binary(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Y), pub_y, plen));
|
||||
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_lset(&ecdsa_context.MBEDTLS_PRIVATE(Q).MBEDTLS_PRIVATE(Z), 1));
|
||||
|
||||
psa_key_id_t key_id;
|
||||
psa_key_attributes_t key_attr = PSA_KEY_ATTRIBUTES_INIT;
|
||||
if (id != MBEDTLS_ECP_DP_SECP192R1) {
|
||||
psa_key_type_t curve_family = PSA_ECC_FAMILY_SECP_R1;
|
||||
psa_set_key_type(&key_attr, PSA_KEY_TYPE_ECC_PUBLIC_KEY(curve_family));
|
||||
if (id == MBEDTLS_ECP_DP_SECP256R1) {
|
||||
psa_set_key_bits(&key_attr, 256);
|
||||
}
|
||||
#if SOC_ECDSA_SUPPORT_CURVE_P384
|
||||
else if (id == MBEDTLS_ECP_DP_SECP384R1) {
|
||||
psa_set_key_bits(&key_attr, 384);
|
||||
}
|
||||
#endif /* SOC_ECDSA_SUPPORT_CURVE_P384 */
|
||||
psa_set_key_usage_flags(&key_attr, PSA_KEY_USAGE_VERIFY_HASH);
|
||||
psa_set_key_algorithm(&key_attr, PSA_ALG_ECDSA(PSA_ALG_SHA_256));
|
||||
|
||||
uint8_t psa_key[2 * plen + 1];
|
||||
psa_key[0] = 0x04; // Uncompressed point indicator
|
||||
memcpy(&psa_key[1], pub_x, plen);
|
||||
memcpy(&psa_key[1 + plen], pub_y, plen);
|
||||
|
||||
psa_status_t status = psa_import_key(&key_attr, psa_key, sizeof(psa_key), &key_id);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
}
|
||||
|
||||
if (id == MBEDTLS_ECP_DP_SECP192R1 || id == MBEDTLS_ECP_DP_SECP256R1) {
|
||||
hash_len = HASH_LEN;
|
||||
}
|
||||
@@ -218,6 +245,31 @@ void test_ecdsa_verify(mbedtls_ecp_group_id id, const uint8_t *hash, const uint8
|
||||
}
|
||||
#endif
|
||||
|
||||
if (id != MBEDTLS_ECP_DP_SECP192R1) {
|
||||
uint8_t signature[2 * plen];
|
||||
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_write_binary(&r, signature, plen));
|
||||
TEST_ASSERT_MBEDTLS_OK(mbedtls_mpi_write_binary(&s, signature + plen, plen));
|
||||
|
||||
ccomp_timer_start();
|
||||
psa_status_t status = psa_verify_hash(key_id, PSA_ALG_ECDSA(PSA_ALG_SHA_256), hash, hash_len,
|
||||
signature, sizeof(signature));
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
elapsed_time = ccomp_timer_stop();
|
||||
|
||||
if (id == MBEDTLS_ECP_DP_SECP192R1) {
|
||||
TEST_PERFORMANCE_CCOMP_LESS_THAN(ECDSA_P192_VERIFY_OP, "%" NEWLIB_NANO_COMPAT_FORMAT" us", NEWLIB_NANO_COMPAT_CAST(elapsed_time));
|
||||
} else if (id == MBEDTLS_ECP_DP_SECP256R1) {
|
||||
TEST_PERFORMANCE_CCOMP_LESS_THAN(ECDSA_P256_VERIFY_OP, "%" NEWLIB_NANO_COMPAT_FORMAT" us", NEWLIB_NANO_COMPAT_CAST(elapsed_time));
|
||||
}
|
||||
#if SOC_ECDSA_SUPPORT_CURVE_P384
|
||||
else if (id == MBEDTLS_ECP_DP_SECP384R1) {
|
||||
TEST_PERFORMANCE_CCOMP_LESS_THAN(ECDSA_P384_VERIFY_OP, "%" NEWLIB_NANO_COMPAT_FORMAT" us", NEWLIB_NANO_COMPAT_CAST(elapsed_time));
|
||||
}
|
||||
#endif
|
||||
psa_destroy_key(key_id);
|
||||
psa_reset_key_attributes(&key_attr);
|
||||
}
|
||||
|
||||
mbedtls_mpi_free(&r);
|
||||
mbedtls_mpi_free(&s);
|
||||
mbedtls_ecdsa_free(&ecdsa_context);
|
||||
@@ -504,8 +556,8 @@ void test_ecdsa_export_pubkey(mbedtls_ecp_group_id id, const uint8_t *pub_x, con
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(pub_x, export_pub_x, len);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(pub_y, export_pub_y, len);
|
||||
|
||||
mbedtls_ecdsa_free(keypair);
|
||||
mbedtls_pk_free(&key_ctx);
|
||||
/* Use esp_ecdsa_free_pk_context instead of manual cleanup to avoid memory leak */
|
||||
esp_ecdsa_free_pk_context(&key_ctx);
|
||||
}
|
||||
|
||||
TEST_CASE("mbedtls ECDSA export public key on SECP192R1", "[mbedtls][efuse_key]")
|
||||
|
||||
@@ -11,6 +11,7 @@
|
||||
#include <esp_system.h>
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "mbedtls/bignum.h"
|
||||
// #include "mbedtls/private/bignum.h"
|
||||
#include "freertos/FreeRTOS.h"
|
||||
#include "freertos/task.h"
|
||||
#include "freertos/semphr.h"
|
||||
|
||||
@@ -7,13 +7,14 @@
|
||||
/*
|
||||
* mbedTLS SHA unit tests
|
||||
*/
|
||||
#if 0
|
||||
#include <string.h>
|
||||
#include <stdio.h>
|
||||
#include <stdbool.h>
|
||||
#include <esp_system.h>
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "mbedtls/sha1.h"
|
||||
#include "mbedtls/sha256.h"
|
||||
// #include "mbedtls/sha1.h"
|
||||
// #include "mbedtls/sha256.h"
|
||||
#include "mbedtls/sha512.h"
|
||||
#include "freertos/FreeRTOS.h"
|
||||
#include "freertos/task.h"
|
||||
@@ -24,7 +25,6 @@
|
||||
#include "soc/soc_caps.h"
|
||||
#include "test_utils.h"
|
||||
#include "esp_memory_utils.h"
|
||||
#if 0
|
||||
|
||||
TEST_CASE("mbedtls SHA self-tests", "[mbedtls]")
|
||||
{
|
||||
|
||||
@@ -11,8 +11,8 @@
|
||||
#include "esp_log.h"
|
||||
#include "esp_private/periph_ctrl.h"
|
||||
|
||||
#include "mbedtls/aes.h"
|
||||
#include "mbedtls/cipher.h"
|
||||
// // #include "mbedtls/aes.h"
|
||||
// #include "mbedtls/cipher.h"
|
||||
|
||||
#include "psa/crypto.h"
|
||||
|
||||
@@ -27,7 +27,7 @@ static const uint8_t key_256[] = {
|
||||
|
||||
TEST_CASE("PSA AES-CTR multipart", "[psa-aes]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 100;
|
||||
const size_t iv_SZ = 16;
|
||||
@@ -107,7 +107,7 @@ TEST_CASE("PSA AES-CTR multipart", "[psa-aes]")
|
||||
|
||||
TEST_CASE("PSA AES-ECB multipart", "[psa-aes]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 112;
|
||||
const size_t iv_SZ = 16;
|
||||
@@ -185,7 +185,7 @@ TEST_CASE("PSA AES-ECB multipart", "[psa-aes]")
|
||||
|
||||
TEST_CASE("PSA AES-CBC multipart", "[psa-aes]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 112; // Multiple of block size (16)
|
||||
const size_t iv_SZ = 16;
|
||||
@@ -264,10 +264,10 @@ TEST_CASE("PSA AES-CBC multipart", "[psa-aes]")
|
||||
// mbedtls_psa_crypto_free();
|
||||
}
|
||||
|
||||
#if 0
|
||||
#if 1
|
||||
TEST_CASE("PSA AES-CBC-PKCS7 multipart", "[psa-aes]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
// Test both aligned and unaligned sizes
|
||||
const size_t SZ1 = 112; // Multiple of block size (16)
|
||||
@@ -277,19 +277,21 @@ TEST_CASE("PSA AES-CBC-PKCS7 multipart", "[psa-aes]")
|
||||
|
||||
uint8_t *plaintext1 = malloc(SZ1);
|
||||
uint8_t *ciphertext1 = malloc(SZ1 + 16); // Extra block for padding
|
||||
uint8_t *decryptedtext1 = malloc(SZ1);
|
||||
uint8_t *decryptedtext1 = malloc(SZ1 + 16); // Extra space for intermediate buffering
|
||||
|
||||
uint8_t *plaintext2 = malloc(SZ2);
|
||||
uint8_t *ciphertext2 = malloc(SZ2 + 16); // Extra block for padding
|
||||
uint8_t *decryptedtext2 = malloc(SZ2);
|
||||
uint8_t *decryptedtext2 = malloc(SZ2 + 16); // Extra space for intermediate buffering
|
||||
|
||||
uint8_t iv[iv_SZ];
|
||||
|
||||
// Initialize test data
|
||||
memset(plaintext1, 0x3A, SZ1);
|
||||
memset(plaintext2, 0x3B, SZ2);
|
||||
memset(decryptedtext1, 0x0, SZ1);
|
||||
memset(decryptedtext2, 0x0, SZ2);
|
||||
memset(ciphertext1, 0x0, SZ1 + 16);
|
||||
memset(ciphertext2, 0x0, SZ2 + 16);
|
||||
memset(decryptedtext1, 0x0, SZ1 + 16);
|
||||
memset(decryptedtext2, 0x0, SZ2 + 16);
|
||||
|
||||
/* Import a key */
|
||||
psa_key_id_t key_id;
|
||||
@@ -315,23 +317,21 @@ TEST_CASE("PSA AES-CBC-PKCS7 multipart", "[psa-aes]")
|
||||
// Process all blocks except the last one
|
||||
for (size_t offset = 0; offset < SZ1 - part_size; offset += part_size) {
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_cipher_update(&enc_op, plaintext1 + offset, part_size,
|
||||
ciphertext1 + total_out_len, part_size, &out_len));
|
||||
ciphertext1 + total_out_len, SZ1 + 16 - total_out_len, &out_len));
|
||||
total_out_len += out_len;
|
||||
}
|
||||
|
||||
// Process the last block separately
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_cipher_update(&enc_op, plaintext1 + SZ1 - part_size, part_size,
|
||||
ciphertext1 + total_out_len, part_size + 16, &out_len));
|
||||
ciphertext1 + total_out_len, SZ1 + 16 - total_out_len, &out_len));
|
||||
total_out_len += out_len;
|
||||
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_cipher_finish(&enc_op, ciphertext1 + total_out_len,
|
||||
16, &out_len)); // Space for padding block
|
||||
SZ1 + 16 - total_out_len, &out_len)); // Space for padding block
|
||||
total_out_len += out_len;
|
||||
|
||||
// The output size should be the input size rounded up to the next multiple of 16
|
||||
TEST_ASSERT_EQUAL_size_t((SZ1 + 16), total_out_len); // Should include padding block
|
||||
|
||||
ESP_LOGI("TAG", "Decryption");
|
||||
/* Decrypt */
|
||||
psa_cipher_operation_t dec_op = PSA_CIPHER_OPERATION_INIT;
|
||||
size_t dec_len = 0;
|
||||
@@ -342,12 +342,12 @@ TEST_CASE("PSA AES-CBC-PKCS7 multipart", "[psa-aes]")
|
||||
for (size_t offset = 0; offset < total_out_len; offset += part_size) {
|
||||
size_t this_part = total_out_len - offset < part_size ? total_out_len - offset : part_size;
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_cipher_update(&dec_op, ciphertext1 + offset, this_part,
|
||||
decryptedtext1 + dec_len, SZ1 - dec_len, &out_len));
|
||||
decryptedtext1 + dec_len, SZ1 + 16 - dec_len, &out_len));
|
||||
dec_len += out_len;
|
||||
}
|
||||
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_cipher_finish(&dec_op, decryptedtext1 + dec_len,
|
||||
SZ1 - dec_len, &out_len));
|
||||
SZ1 + 16 - dec_len, &out_len));
|
||||
dec_len += out_len;
|
||||
|
||||
TEST_ASSERT_EQUAL_size_t(SZ1, dec_len);
|
||||
@@ -387,12 +387,12 @@ TEST_CASE("PSA AES-CBC-PKCS7 multipart", "[psa-aes]")
|
||||
for (size_t offset = 0; offset < total_out_len; offset += part_size) {
|
||||
size_t this_part = total_out_len - offset < part_size ? total_out_len - offset : part_size;
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_cipher_update(&dec_op, ciphertext2 + offset, this_part,
|
||||
decryptedtext2 + dec_len, SZ2 - dec_len, &out_len));
|
||||
decryptedtext2 + dec_len, SZ2 + 16 - dec_len, &out_len));
|
||||
dec_len += out_len;
|
||||
}
|
||||
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_cipher_finish(&dec_op, decryptedtext2 + dec_len,
|
||||
SZ2 - dec_len, &out_len));
|
||||
SZ2 + 16 - dec_len, &out_len));
|
||||
dec_len += out_len;
|
||||
|
||||
TEST_ASSERT_EQUAL_size_t(SZ2, dec_len);
|
||||
@@ -417,7 +417,7 @@ TEST_CASE("PSA AES-CBC-PKCS7 multipart", "[psa-aes]")
|
||||
|
||||
TEST_CASE("PSA AES-CFB multipart", "[psa-aes]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 100;
|
||||
const size_t iv_SZ = 16;
|
||||
@@ -497,7 +497,7 @@ TEST_CASE("PSA AES-CFB multipart", "[psa-aes]")
|
||||
|
||||
TEST_CASE("PSA AES-OFB multipart", "[psa-aes]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 100;
|
||||
const size_t iv_SZ = 16;
|
||||
@@ -578,7 +578,7 @@ TEST_CASE("PSA AES-OFB multipart", "[psa-aes]")
|
||||
|
||||
TEST_CASE("PSA AES-CBC one-shot", "[psa-aes]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 1600;
|
||||
const size_t iv_SZ = 16;
|
||||
|
||||
@@ -9,8 +9,8 @@
|
||||
|
||||
#include "esp_log.h"
|
||||
|
||||
#include "mbedtls/aes.h"
|
||||
#include "mbedtls/gcm.h"
|
||||
// // #include "mbedtls/aes.h"
|
||||
// #include "mbedtls/gcm.h"
|
||||
|
||||
#include "psa/crypto.h"
|
||||
|
||||
@@ -25,7 +25,7 @@ static const uint8_t key_256[] = {
|
||||
|
||||
TEST_CASE("PSA AES-GCM multipart", "[psa-aes-gcm]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 100;
|
||||
const size_t iv_SZ = 12; // GCM typically uses 12 bytes IV
|
||||
@@ -136,7 +136,7 @@ TEST_CASE("PSA AES-GCM multipart", "[psa-aes-gcm]")
|
||||
|
||||
TEST_CASE("PSA AES-GCM one-shot", "[psa-aes-gcm]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 100;
|
||||
const size_t iv_SZ = 12; // GCM typically uses 12 bytes IV
|
||||
|
||||
@@ -64,8 +64,8 @@ TEST_CASE("PSA CMAC AES-128 test", "[psa_cmac]")
|
||||
psa_key_id_t key_id = 0;
|
||||
|
||||
// Initialize PSA Crypto
|
||||
status = psa_crypto_init();
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
// status = psa_crypto_init();
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
// Set up key attributes
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE);
|
||||
@@ -114,8 +114,8 @@ TEST_CASE("PSA CMAC AES-256 test", "[psa_cmac]")
|
||||
psa_key_id_t key_id = 0;
|
||||
|
||||
// Initialize PSA Crypto
|
||||
status = psa_crypto_init();
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
// status = psa_crypto_init();
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
// Set up key attributes
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE);
|
||||
@@ -163,8 +163,8 @@ TEST_CASE("PSA CMAC AES-128 multipart test", "[psa_cmac]")
|
||||
psa_mac_operation_t operation = PSA_MAC_OPERATION_INIT;
|
||||
|
||||
// Initialize PSA Crypto
|
||||
status = psa_crypto_init();
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
// status = psa_crypto_init();
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
// Set up key attributes
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE);
|
||||
@@ -219,8 +219,8 @@ TEST_CASE("PSA CMAC AES-128 multipart verify test", "[psa_cmac]")
|
||||
psa_key_id_t key_id = 0;
|
||||
|
||||
// Initialize PSA Crypto
|
||||
status = psa_crypto_init();
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
// status = psa_crypto_init();
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
// Set up key attributes
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE);
|
||||
@@ -283,8 +283,8 @@ TEST_CASE("PSA CMAC zero-length test", "[psa_cmac]")
|
||||
psa_key_id_t key_id = 0;
|
||||
|
||||
// Initialize PSA Crypto
|
||||
status = psa_crypto_init();
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
// status = psa_crypto_init();
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
// Set up key attributes
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE);
|
||||
@@ -331,8 +331,8 @@ TEST_CASE("PSA CMAC memory alignment test", "[psa_cmac]")
|
||||
psa_key_id_t key_id = 0;
|
||||
|
||||
// Initialize PSA Crypto
|
||||
status = psa_crypto_init();
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
// status = psa_crypto_init();
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
// Set up key attributes
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE);
|
||||
@@ -389,8 +389,8 @@ TEST_CASE("PSA CMAC verify failure test", "[psa_cmac]")
|
||||
psa_key_id_t key_id = 0;
|
||||
|
||||
// Initialize PSA Crypto
|
||||
status = psa_crypto_init();
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
// status = psa_crypto_init();
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
// Set up key attributes
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_VERIFY_MESSAGE);
|
||||
|
||||
@@ -21,7 +21,7 @@ static const uint8_t key_256[] = {
|
||||
|
||||
TEST_CASE("PSA ARIA-GCM multipart", "[psa-gcm]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 100;
|
||||
const size_t iv_SZ = 12; // GCM typically uses 12 bytes IV
|
||||
@@ -134,7 +134,7 @@ TEST_CASE("PSA ARIA-GCM multipart", "[psa-gcm]")
|
||||
|
||||
TEST_CASE("PSA ARIA-GCM one-shot", "[psa-gcm]")
|
||||
{
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_crypto_init());
|
||||
|
||||
const size_t SZ = 100;
|
||||
const size_t iv_SZ = 12; // GCM typically uses 12 bytes IV
|
||||
|
||||
@@ -0,0 +1,63 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Unlicense OR CC0-1.0
|
||||
*/
|
||||
/* PSA HMAC test
|
||||
*/
|
||||
|
||||
#include "psa/crypto.h"
|
||||
#include "unity.h"
|
||||
static const uint8_t key_128[] = {
|
||||
0x44, 0x44, 0x44, 0x44, 0x44, 0x44, 0x44, 0x44,
|
||||
0x44, 0x44, 0x44, 0x44, 0x44, 0x44, 0x44, 0x44,
|
||||
};
|
||||
|
||||
static const uint8_t test_data[] = {
|
||||
0x6b, 0xc1, 0xbe, 0xe2, 0x2e, 0x40, 0x9f, 0x96,
|
||||
0xe9, 0x3d, 0x7e, 0x11, 0x73, 0x93, 0x17, 0x2a,
|
||||
0xae, 0x2d, 0x8a, 0x57, 0x1e, 0x03, 0xac, 0x9c,
|
||||
0x9e, 0xb7, 0x6f, 0xac, 0x45, 0xaf, 0x8e, 0x51
|
||||
};
|
||||
|
||||
static const uint8_t expected_hmac_128[] = {
|
||||
0x00, 0x7a, 0x5a, 0xd6, 0x54, 0x96, 0x5b, 0xcd,
|
||||
0x30, 0xc1, 0x60, 0x62, 0xec, 0xac, 0x75, 0xfb,
|
||||
0x87, 0x71, 0x0e, 0x13
|
||||
};
|
||||
|
||||
TEST_CASE("PSA HMAC SHA-1 test", "[psa_hmac]")
|
||||
{
|
||||
psa_status_t status;
|
||||
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
|
||||
psa_key_id_t key_id = 0;
|
||||
|
||||
// Initialize PSA Crypto
|
||||
status = PSA_SUCCESS;
|
||||
// TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
// Set up key attributes
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE);
|
||||
psa_set_key_algorithm(&attributes, PSA_ALG_HMAC(PSA_ALG_SHA_1));
|
||||
psa_set_key_type(&attributes, PSA_KEY_TYPE_HMAC);
|
||||
psa_set_key_bits(&attributes, 128);
|
||||
|
||||
uint8_t *hmac = malloc(PSA_HASH_LENGTH(PSA_ALG_SHA_1));
|
||||
TEST_ASSERT_NOT_NULL(hmac);
|
||||
|
||||
status = psa_import_key(&attributes, key_128, sizeof(key_128), &key_id);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
size_t mac_length = 0;
|
||||
status = psa_mac_compute(key_id, PSA_ALG_HMAC(PSA_ALG_SHA_1),
|
||||
test_data, sizeof(test_data),
|
||||
hmac, PSA_HASH_LENGTH(PSA_ALG_SHA_1), &mac_length);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
status = psa_mac_verify(key_id, PSA_ALG_HMAC(PSA_ALG_SHA_1),
|
||||
test_data, sizeof(test_data),
|
||||
expected_hmac_128, sizeof(expected_hmac_128));
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
psa_destroy_key(key_id);
|
||||
psa_reset_key_attributes(&attributes);
|
||||
free(hmac);
|
||||
}
|
||||
@@ -0,0 +1,297 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Unlicense OR CC0-1.0
|
||||
*/
|
||||
#include <stdio.h>
|
||||
#include <stdint.h>
|
||||
#include <string.h>
|
||||
|
||||
#include "esp_log.h"
|
||||
|
||||
#include "psa/crypto.h"
|
||||
#include "mbedtls/pk.h"
|
||||
#include "mbedtls/pem.h"
|
||||
// #include "mbedtls/rsa.h"
|
||||
#include "mbedtls/error.h"
|
||||
#include "unity.h"
|
||||
#include "ccomp_timer.h"
|
||||
|
||||
typedef enum {
|
||||
PSA_RSA_KEY_SIZE_2048,
|
||||
PSA_RSA_KEY_SIZE_3072,
|
||||
PSA_RSA_KEY_SIZE_4096,
|
||||
} psa_rsa_key_size_t;
|
||||
|
||||
static const char privkey_4096_buf[] = "-----BEGIN RSA PRIVATE KEY-----\n"
|
||||
"MIIJKAIBAAKCAgEA1blr9wfIzTylroJHxcoq+YFA765gF5vj9b6tfaPG0XQExSkjndHv5sra4ar7T+k2sBB4OcKKeGHkNk6wk8tGmOS79r2L74XZs1eB0UruG+huV7Sd+YiWzwN8y9jGImA9hIkf1qxIvkco5WTmT7cVwUnCQ7qiiVadD/LgyeGD04yKZpzv9UJzfjXz5ITTn/ejcn7423M9qz41nhRWwK4zw1jv7IB57d1dWOCbN3RO4dvfVndCz8DOmLzJrZAkLsz39vppbIwbMqTXKFxWqzZY2xrYmnMx9p3v4hLeju7ls3fsekESonoP0C76u50wJfZWO2XcIUo4pue/jHi2o9KouhLXW/vyasplXvE6FFrBjSpsm1Nar4KQMUolEkUbO9baGcQvH9G5WOH0kwPt7AOSqM2EUPvBd7Jv0tbMI/BRZVVltC/t6WhannCM/I6nZrlNe5tie/qYlFu474jp5/tpa8RykkDxwl9whejIqd4iQbvDiP/GXgBYtDJ9VU/S2KqHJhQFLDi+F3+ewOcF391fgt1e1J2vNYLKZOfxTOl/1vJbU/2IjRWTRQ7cXnmpR/GNCRfgH2as6Z/0oknBSVephguDnO5QlveP4Cx2EOVY/A/KgDpu8PumSrlIk+YQgLxdKsXaVI6eDY4rY7q2uCJH3yIAfZJXEeD+ResUuSZltvECAwEAAQKCAgBwR89+oipOGHR6b5tBP+q/1bXFtXhqLs3eBuSiQu5qj2cKJYi+mtJMD3paYDdTThQa/ywKPDf+8n6wQTrnCj32iQRupjnkBg/O9kQPLixVoRCHJy5vL+D6tLxVY3cEDEeFX3zIjQ5SWJQVn6KXcnoNZ7CVYHGPcV9mR5TsuntFImp7aituUBDY14NgJKABRFosBqS6tZpKYo5MlCbXZy1ujUTOnNhxrIAj9yvUQFhIs/hrNpB1ELf46gWSF03LAIesyvWjvx9yxcL7QzeNDyozQbFVwvsWsvaZcIxXzw4B8RjdSV5+2V2BY4z6D6SB7R50ahjxrEqC9PFe3PQmsL9OvFjV9idYwFOhxiWXGjIm3wwFFLOj3e0TShscj2Iw+Ghd3wApvSdBZxzdjap1NHC+Q6yYU+BnivxUHcopVPPM3rsLndyRC6zfrQw/OkOlAP3bNL1hRedPRmRDOz0V1ihEpgC1VfXx6XOu4eg8xWiJgWX+BGvT5GWjfQg2hB1Jm344r3l0eLhr25dO80GIac2QGT2+WmYkXcsQ3AiqAn2VF8UB5mU+Iyh96jmSFVVltGZgfp98yFYN63/7wB++lhVQmJZwbglutng1qjQBFslIULddIHiYvF+AVvkrO3Hc2zg8rT91tbE13k06A1zlNGcQuQKLax8e+2/BNjsZU2E4uQKCAQEA7L4obKWYRHgG6j1VEDRrQU8Vkm4L11B+ZD/rsEh3q7LbzViOPv+1dZ40jX2qYScWyaefI46bukJlk/mlNv4Dh3EnSFvHPCInDM3oImCYImwUx0hkbSRyRNwlwRwx81LJzIR84cCqpNWrXXcplomUSM62ea1E1vtNSZs9Bg2OLoWvFOTPgk/xDi6ezdb6JFiId6cARup/bmZ363mg8jCq0wpTLVdUGrezfMj4GpB1uQET5xqXleumQu/04cHPOfXwpV0ikIOId/ldY/PetiRd86B32aB2Xd4fHUpxHMY+63MFmL6SsqMQJMPubv+eIrOId4HhT+nXNFBZXolT5XG5NwKCAQEA5xvvccHNyCTL0AebxD6EihWnp0/Dd0DwXWxZw0Yhhc9xa/W/QtygB6kPb35oKGvCKdm4dWCIGln03dU5D6CMNkJlbkxpo8gybz34SJ/6OvU836rBLHZXE3Xiqbe5XkdMdarA7kTEhEUqekDXPxhws9dWh0YjtAnBPpm1GQppiykI2edkiIhRgju5ghe+/UjAjxrEgCKZeAODh46hwZHERRKQN2MFUOFcOVDq+2wTJem9r3h1uBQAiZn8PDyx0rlRkwH2dZSSauVW+I713N0JGucOV7FeMO0ebioqqckh0i91ZJNH//Io8Sp8WuBsU/vcP9jT+5BDkCbc71BRO/AFFwKCAQBj4a6oeA0QBhvUw9+ZoKQHv9f4GZnBU+KfZSCJFWn39NQrhMsu5S+n2gGOGJDDwHwqxB+uHsKxCMZWciM0WmMex6ytKJucUURscIsZxespyrPRiEdmjNPxHXiISt8AK9OcB+GwVVsphERygI35Rz5aoWv3VhUPJqNrBKXwYdO06Q3/ILIz5oprU1wIuER9BSU+ZiUFxnXRHEZIAN7Yj5Piyh5hqNCBHTQK17dlbcFdNokxHdUKmYth/l8wyFYnvA21lt+4XOY8x+aQ/xjde+ZvnSozlTGbVNWHxBqI61MsfzDDStQVrhpniIqWJh6PwXM4CIII9z2mgqfR7NqKmTptAoIBAQDTYQOigmZbFvyrayoXVi8XtTLAnv3jByxR5pY7OtvSbagJ3J1w5CYim4iYq39M6TKP4KkMApy5rWl/tFQabPeRcS0gsxc0TBmFEaMTme7fGgrxcFZ6+koubHZCUN5k0sWmIeWQiKlNaY2uf7vf49TBSMXFuGtTclCjlybCnnlmZMPJuhCDqFsUyNelm15+f5pPyWXM5NiFooEc7WIZj996Zb4uSo1EKruVWONzzqe814s9AOp60SCkuoiv97uVRxbLZNItPRSmXNktQmSx/CEl0AuYPYwvJ9HbZQncfTBH9ExlDyidernjyr4uyHGMZyJN614ICy0gncsZv9ZtAd1FAoIBAA4toGPU/VcKFmK92zgO05jsg5vJzw5xeoxRWKrLg7iby6Su6BuNgaVwfYWeZuOhnXakid7FvFXKH6x44o9gyFm5bKqFhaXDzAnxzqcLeM5V+gititOsstpZCbVOoKQOhgTHyxpFNVX3E/nB8EunydWyhQMxKme//NsRroFm1vWljQKyL3zER82AzyseEpEYZoB/6g0n5uF2lR7KllxeBlINsceQ8g3JkmJTdS1hoXcyUSsZ+EgrRbCykNB5aVC5G3/W1OSZsFHbbMrYHCMnaYKwMqLmOkb11o6nOrJJ4pgHj8CVcp2TNjfy3y0Ru6RZ42b0Q+3LktJBGu9r5d04FgI=\n"
|
||||
"-----END RSA PRIVATE KEY-----";
|
||||
|
||||
static const char privkey_2048_buf[] = "-----BEGIN RSA PRIVATE KEY-----\r\n"
|
||||
"MIIEowIBAAKCAQEA8N8hdkemvj6Tpk975/OWhv9BrTsCBCu+ZYfDb5VI7U2meKBg\r\n"
|
||||
"3dAkyyhRlY3fNwSRzBUMCzsHjpgnsB40wxOgiwlB9n6PMhq0qUVKAdCpKwFztsKd\r\n"
|
||||
"JJAsCUC+Zlwxn4RpH6ZnMl3a/njRYjuDyI32kucMP/lBRo7ks1798Gy/j+x1h5xA\r\n"
|
||||
"vZSlFoEXKjCC6S1DWhALePuZnk4m/jGP6g+YfyJXSTqsenKa/DcWndfn/JoElZ0J\r\n"
|
||||
"nhud8lBXwVe6mMheE1yqfL+VTU1nwg/TPNZrZsFz2sXig/RQCKt6LuSuzhRpsLp+\r\n"
|
||||
"BdwqEs9xrwlhZnp7j4kQBomISd6kAxQfYVROHQIDAQABAoIBAHgtO4rB8QWWPyCJ\r\n"
|
||||
"I670r7OnA2OkvzrJgHMzq2SuvPX4+gfRLMM+qDzcXugZIrdWhk+maJ3p07lnXNXY\r\n"
|
||||
"HEcAMedstQaA2n0LKfwSX/xL2TtlvBABRVoKvI3ZSaXUdcW60KBD69ULUsoICZ/T\r\n"
|
||||
"Rcr4WX+t20TH3bOQc7ayvEwKVgE95xIUpTH9asw8uOPvKxW2j5OLQgZuWrWyUDg0\r\n"
|
||||
"MFh92PhWtw3i5zq6OpTTsFJeceKYV/VstIYjZ+FslmhjQxJbr+2DJRbpHXKceqy6\r\n"
|
||||
"9yWlSV0EM7neFCHlDa2WPhK8we+6IvMiNVQKj46fHGYNBaW/ZSX7TiG5J0Uqj2e9\r\n"
|
||||
"0MUGJ8ECgYEA+frJabhfzW5+JfGjTObeznJZE6fAOjFzaBIwFu8Kz2mIjYpQlwVK\r\n"
|
||||
"EepMkv2KkrJuqS4GnI+Nkq7G0BAUyUj9tTJ3HQzvtJrxsnxVi99Yofx1s1P4YAnu\r\n"
|
||||
"c8t3ElJoQ4BRoQIs/hIvyYn22IxllBHiGESrnPQ38D82xyXQgd6S8JkCgYEA9qww\r\n"
|
||||
"j7jx6Xpy/D1Dq8Dvalm7pz3J+yHnti4w2cqZ67grUoyGnNPtciNDdfi4JzLiKkUu\r\n"
|
||||
"SDS3DacvFpFyND0m8sbpMjnR8Rvhj+bfH8KcOAowD+YR/+6vSb/P/aBt6gYXcaBn\r\n"
|
||||
"cjepx+sE81mnC7UrHb4TjG4hO5t3ZTc6X28gyCUCgYAMZn9lSisecrO5SCJUp0M4\r\n"
|
||||
"NH3stq6XdGqIKBbQnG0J2u9WLh1PUIjbGKdRx1f/bPCGXe0gCRL5yse7/IA7d+51\r\n"
|
||||
"9ZnpDAI8EE+bDgXkWWD5MB/alHjGstdsURSICSR47L2f4g6/T8GlGr3vAg/r53My\r\n"
|
||||
"xv1IXOkFdu1NtbeBKbxaSQKBgENDmw5mAVmIcXiFAEICn4ahp4EoYT6g9T2BhQKu\r\n"
|
||||
"s6BKnU2qUj7Lr5ETOp8dzqGpx3B9Yux/q3cGotmFmd3S2x8SzJ5MlAoqbyy9aRSR\r\n"
|
||||
"DeZeKNL9CuV+YcA7lOz1ZWOOe7AZbHwB38NLPBNb3CheI769iTkfAuLtNvabw8go\r\n"
|
||||
"VokdAoGBALyvBhW+Squ5tx8NOEgAisakhAVOnT6jcoeKy6FyjcvKaWagmCOCC7Gz\r\n"
|
||||
"QB9Yf1tJ+3di+aLtWWdmU494iKJHBtPMhfrYltCpxHHQGlUc/GLPY3Z5bBYYYWpb\r\n"
|
||||
"Wzw4ZvDraKlAs7a9CRwS5cpktk5ptK4rc5noSXkvV+yOT75zXat2\r\n"
|
||||
"-----END RSA PRIVATE KEY-----\r\n";
|
||||
|
||||
static const char privkey_3072_buf[] = "-----BEGIN RSA PRIVATE KEY-----\r\n"
|
||||
"MIIG4wIBAAKCAYEAoMPuYRnHVPP49qiPACIsYBLVuj8xH4XqAuXmurOyPPFfKSch\r\n"
|
||||
"52dn97sXvfXQw6hj+iPBeMSzbSAompjx4mUHtwn2+EvyXjqUe8qtI0y12uzXgOr8\r\n"
|
||||
"vdwNLJO1kTmUWxQIa/e6dZpiKcEYYZ6qWNUGVH9IiMB9HdIFLNIdCAAC+gsK+Q0w\r\n"
|
||||
"OT2CwnGOoZ/PzOXHyfte9pJTDk6nQJDKVTBoOLgVcJoCLwctGf7VJ9YI9+YXJKvW\r\n"
|
||||
"1ZYq8PXM8KAVE7KHN7KiskJxDLSR4xuplxdT//LIBJMRvxAEPYohe7QvejFjtQc6\r\n"
|
||||
"WbEJxV/Y4vWHOb2PVGUHATNK2kQ7/N5HgEdxABgLrXQSkGfKKmWwoy/W5TVDS+qX\r\n"
|
||||
"fR/7WeJa/2e2+ZZVSQtiXdrWSKdgEmVdmM43Aso5ppC2C5QBajHAw2MKMZwxLHbI\r\n"
|
||||
"nhQJQMJdmRvXI8Kg/+WEgknxQLFWrRW4ss3wR+2KvZ0eynEuzHkQxtUAWB8xgNAH\r\n"
|
||||
"Bch/tr+xq1g3DFNXAgMBAAECggGAFvaFiScWesLyb8D51AoNjpeCIb0+9gK5vzo5\r\n"
|
||||
"b7eVIPFVJ1qolBYIGrGFnaOL8zaNOUB8NRTbkB3EzvhDrJPDu1hYB3VJpD330YrM\r\n"
|
||||
"mjstypyD16049qGE3DYo/BpeX3gID+vtnTi1BsPHCMKSEGg1JEKeCLJ97JGAHbvR\r\n"
|
||||
"W8AsrKyBH7vLhJGNqNpxhhJ+qwSzOd2G3e9en6+KYkWMMQjeCiP5JAFLiI4c2ha1\r\n"
|
||||
"OaBv3YDnE1zcLdvqPErPwBsNh6e7QLYbEvQj5mZ84/kCbrwFy//+Bf7to0u6weOy\r\n"
|
||||
"8E1HU8UKdJfWsKwh+5BGDnKs8qgVQWJdPJWy25PVgkzp0ZnSKzp2AddMCrI2YHRM\r\n"
|
||||
"Q+G+9bET/D96y7/08EAobDdXCplcPeOVb8ETbQTNTrHJibUCB4fqkN8tR2ZZTQ1F\r\n"
|
||||
"axhmHDThsVFqWk+629j8c6XOQbx2dvzb7YfLK06ShiBcD0V6E7VFXHzR+x/xA9ir\r\n"
|
||||
"zUcgLt9zvzj9puxlkhtzBZKcF3nBAoHBANCtY4NDnFoO+QUS59iz9hsoPAe8+S+U\r\n"
|
||||
"PkvMSN7iziUkiXbXjQsr0v/PLHCuuXRyARBORaI4moLxzbTA1l1C+gBulI29j9zH\r\n"
|
||||
"GwNnl587u5VCpbzuzr5YwHtp85Y1la2/ti+x0Qaw5uoa8G2TqoU4V6SG0qwinQl2\r\n"
|
||||
"9mdNZzVmIBMbE0tTTTzc+CRIPBl9lRQR3Ff3o6eUs6uPE6g1lGZR1ydb2MLBM/wV\r\n"
|
||||
"NgUUf7L5h/s8abrRjS+dnPmtxNgrRZQe9wKBwQDFOQyBzD3xkBgTSFQkU8OgNZyW\r\n"
|
||||
"gNYglE1vLA+wv49NVAErHfKzYf/yw3fkYLDo9JfTJ3KckU6J815VnPXJFNMvjr2J\r\n"
|
||||
"ExXG2JSbZHeUBRgExLU0iFlhQaxbAhuJ6PDrkGy+1ZtsJxYCPpifyNwjkZ0QKQlf\r\n"
|
||||
"n3SwTMXIp0wd80FXVSwKPSuWUlrhByBcJDVwdCIeD8Oi9DrmVe0E9fXDboY2HARb\r\n"
|
||||
"cgrN3n9jnEF/asIsfaHg8EI2z/EVC+C1mHuZdqECgcA5d4ZwH65vHrB1NT+j7etY\r\n"
|
||||
"jzv45ZG6CJkfRqLKvqsGj4lLsRCmgusYh3U1kuh/qOWiF+wVQIFMjkqX/IMMK+Wt\r\n"
|
||||
"OMawQgPcSPind1/J+ikucawy25ET2l0nn4X1V8xgjOsfN1jY/t6YmdKcWo4bIekA\r\n"
|
||||
"5iAeR2n3sUsqJ6bEjdtHZ61okQg0OqYbV8k1O+BSJpkHoKrw+4J/PGetaxPzGZam\r\n"
|
||||
"wCRxfcNTKIQ34e1I3G8WQQzc5dh7xGv2VmRfI4uFvwECgcEAuNGAVfZ3KfNVjGRg\r\n"
|
||||
"bXaNwYncBvIPN5KiigbpYUHyYY3SVnyHHvE8cFwa80plHrlvubGi5vQIfKAzC9m+\r\n"
|
||||
"PsSkL1H9bgITizcU9BYPNQgc/QL1qJgJ4mkvwk1UT0Wa17WNIrx8HLr4Ffxg/IO3\r\n"
|
||||
"QCHJ5QX/wbtlF32qbyHP49U8q0GmtqWiPglJHs2V1qMb7Rj3i+JL/F4RAB8PsXFo\r\n"
|
||||
"8M6XOQfCUYuqckgKaudYPbZm5liJJYkhE8qD6qwp1SNi2GphAoHABjUL8DTHgBWn\r\n"
|
||||
"sr9/XQyornm0sruHcwr7SmGqIJ/hZUUYd4UfDW76e8SjvhRQ7nkpR3f4+LEBCqaJ\r\n"
|
||||
"LDJDhg+6AColwKaWRWV9M1GXHhVD4vaTM46JAvH9wbhmJDUORHq8viyHlwO9QKpK\r\n"
|
||||
"iHE/MtcYb5QBGP5md5wc8LY1lcQazDsJMLlcYNk6ZICNWWrcc2loG4VeOERpHU02\r\n"
|
||||
"6AsKaaMGqBp/T9wYwFPUzk1i+jWCu66xfCYKvEubNdxT/R5juXrd\r\n"
|
||||
"-----END RSA PRIVATE KEY-----\r\n";
|
||||
|
||||
// Keep the old version for reference (has issues with PSA-based PK)
|
||||
static int pem_to_der_rsa_key(const char *pem_key, size_t pem_key_len,
|
||||
uint8_t *der_buf, size_t der_buf_size,
|
||||
uint8_t **der_data_ptr, size_t *der_len)
|
||||
{
|
||||
// Use direct PEM parsing instead of PK layer for PSA compatibility
|
||||
// return pem_to_der_rsa_key_direct(pem_key, pem_key_len, der_buf, der_buf_size,
|
||||
// der_data_ptr, der_len);
|
||||
|
||||
mbedtls_pk_context pk;
|
||||
int ret;
|
||||
|
||||
mbedtls_pk_init(&pk);
|
||||
|
||||
// Parse PEM key
|
||||
ret = mbedtls_pk_parse_key(&pk,
|
||||
(const uint8_t *)pem_key,
|
||||
pem_key_len,
|
||||
NULL, 0); // No password
|
||||
if (ret != 0) {
|
||||
char error_buf[100];
|
||||
mbedtls_strerror(ret, error_buf, sizeof(error_buf));
|
||||
printf("mbedtls_pk_parse_key failed: -0x%04x - %s\n", -ret, error_buf);
|
||||
mbedtls_pk_free(&pk);
|
||||
return ret;
|
||||
}
|
||||
|
||||
// printf("PEM key parsed successfully, key type: %d\n", mbedtls_pk_get_type(&pk));
|
||||
|
||||
// Write key to DER format
|
||||
// NOTE: mbedtls_pk_write_key_der writes to the END of the buffer!
|
||||
// Returns the length on success, or negative error code
|
||||
printf("Attempting to write DER key (buffer size: %zu)...\n", der_buf_size);
|
||||
ret = mbedtls_pk_write_key_der(&pk, der_buf, der_buf_size);
|
||||
if (ret < 0) {
|
||||
char error_buf[100];
|
||||
mbedtls_strerror(ret, error_buf, sizeof(error_buf));
|
||||
printf("mbedtls_pk_write_key_der failed: -0x%04x - %s\n", -ret, error_buf);
|
||||
mbedtls_pk_free(&pk);
|
||||
return ret;
|
||||
}
|
||||
|
||||
printf("DER key written successfully, length: %d\n", ret);
|
||||
|
||||
// ret contains the length of DER data
|
||||
*der_len = ret;
|
||||
|
||||
// Calculate the start position of DER data (at end of buffer)
|
||||
*der_data_ptr = der_buf + der_buf_size - ret;
|
||||
|
||||
mbedtls_pk_free(&pk);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static psa_key_id_t import_rsa_key(psa_rsa_key_size_t key_size)
|
||||
{
|
||||
psa_key_id_t key_id;
|
||||
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
|
||||
psa_status_t status;
|
||||
int ret;
|
||||
|
||||
// Convert PEM to DER format
|
||||
uint8_t *der_buf = calloc(1, 10000); // Buffer for DER-encoded key (data written at end)
|
||||
uint8_t *der_key = NULL; // Pointer to actual DER data location
|
||||
size_t der_key_len = 0;
|
||||
|
||||
char *key_buf = NULL;
|
||||
|
||||
if (key_size == PSA_RSA_KEY_SIZE_2048) {
|
||||
key_buf = (char *)privkey_2048_buf;
|
||||
} else if (key_size == PSA_RSA_KEY_SIZE_3072) {
|
||||
key_buf = (char *)privkey_3072_buf;
|
||||
} else if (key_size == PSA_RSA_KEY_SIZE_4096) {
|
||||
key_buf = (char *)privkey_4096_buf;
|
||||
} else {
|
||||
printf("Unsupported key size for import_rsa_key\n");
|
||||
free(der_buf);
|
||||
return 0;
|
||||
}
|
||||
|
||||
ret = pem_to_der_rsa_key(key_buf,
|
||||
strlen(key_buf) + 1, // Include null terminator
|
||||
der_buf,
|
||||
10000,
|
||||
&der_key, // Returns pointer to DER data
|
||||
&der_key_len);
|
||||
TEST_ASSERT_EQUAL(0, ret);
|
||||
|
||||
// Configure key attributes for RSA encryption/decryption
|
||||
psa_set_key_type(&attributes, PSA_KEY_TYPE_RSA_KEY_PAIR);
|
||||
psa_set_key_algorithm(&attributes, PSA_ALG_RSA_PKCS1V15_CRYPT);
|
||||
psa_set_key_usage_flags(&attributes,
|
||||
PSA_KEY_USAGE_ENCRYPT | PSA_KEY_USAGE_DECRYPT);
|
||||
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_VOLATILE);
|
||||
size_t key_bits = 0;
|
||||
if (key_size == PSA_RSA_KEY_SIZE_2048) {
|
||||
key_bits = 2048;
|
||||
} else if (key_size == PSA_RSA_KEY_SIZE_3072) {
|
||||
key_bits = 3072;
|
||||
} else if (key_size == PSA_RSA_KEY_SIZE_4096) {
|
||||
key_bits = 4096;
|
||||
}
|
||||
psa_set_key_bits(&attributes, key_bits);
|
||||
|
||||
status = psa_import_key(&attributes,
|
||||
der_key, // Pointer to DER data (at end of buffer)
|
||||
der_key_len,
|
||||
&key_id);
|
||||
if (status != PSA_SUCCESS) {
|
||||
printf("PSA import failed with error: %ld (0x%x)\n", status, (unsigned int)status);
|
||||
printf("Expected error codes:\n");
|
||||
printf(" PSA_ERROR_INVALID_ARGUMENT = %ld\n", PSA_ERROR_INVALID_ARGUMENT);
|
||||
printf(" PSA_ERROR_NOT_SUPPORTED = %ld\n", PSA_ERROR_NOT_SUPPORTED);
|
||||
printf(" PSA_ERROR_INSUFFICIENT_MEMORY = %ld\n", PSA_ERROR_INSUFFICIENT_MEMORY);
|
||||
}
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
free(der_buf);
|
||||
psa_reset_key_attributes(&attributes);
|
||||
return key_id;
|
||||
}
|
||||
|
||||
TEST_CASE("test performance RSA key operations", "[bignum]")
|
||||
{
|
||||
psa_status_t status;
|
||||
psa_rsa_key_size_t keysize = PSA_RSA_KEY_SIZE_2048;
|
||||
for (int i = 0; i < 3; i++) {
|
||||
// Use der_key (not der_buf) as it points to the actual DER data at end of buffer
|
||||
psa_key_id_t key_id = import_rsa_key(keysize);
|
||||
printf("RSA key imported successfully (key_id: %u)\n", (unsigned int)key_id);
|
||||
|
||||
size_t ciphertext_size = 0;
|
||||
if (keysize == PSA_RSA_KEY_SIZE_2048) {
|
||||
ciphertext_size = 256; // 2048 bits / 8
|
||||
} else if (keysize == PSA_RSA_KEY_SIZE_3072) {
|
||||
ciphertext_size = 384; // 3072 bits / 8
|
||||
} else if (keysize == PSA_RSA_KEY_SIZE_4096) {
|
||||
ciphertext_size = 512; // 4096 bits / 8
|
||||
} else {
|
||||
printf("Unsupported key size for ciphertext size calculation\n");
|
||||
return;
|
||||
}
|
||||
|
||||
uint8_t plaintext[] = "Test message for RSA encryption";
|
||||
size_t plaintext_len = sizeof(plaintext);
|
||||
uint8_t ciphertext[ciphertext_size]; // RSA 2048-bit key produces 256-byte ciphertext
|
||||
size_t ciphertext_len = sizeof(ciphertext);
|
||||
uint8_t decrypted[ciphertext_size];
|
||||
size_t decrypted_len = sizeof(decrypted);
|
||||
size_t encrypt_len = 0;
|
||||
|
||||
#ifdef SOC_CCOMP_TIMER_SUPPORTED
|
||||
int public_perf, private_perf;
|
||||
ccomp_timer_start();
|
||||
#endif
|
||||
// Encrypt the plaintext
|
||||
status = psa_asymmetric_encrypt(key_id,
|
||||
PSA_ALG_RSA_PKCS1V15_CRYPT,
|
||||
plaintext,
|
||||
plaintext_len,
|
||||
NULL,
|
||||
0,
|
||||
ciphertext,
|
||||
ciphertext_len,
|
||||
&encrypt_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
#ifdef SOC_CCOMP_TIMER_SUPPORTED
|
||||
public_perf = ccomp_timer_stop();
|
||||
#endif // SOC_CCOMP_TIMER_SUPPORTED
|
||||
|
||||
size_t decrypt_len = 0;
|
||||
#ifdef SOC_CCOMP_TIMER_SUPPORTED
|
||||
ccomp_timer_start();
|
||||
#endif
|
||||
// Decrypt the ciphertext
|
||||
status = psa_asymmetric_decrypt(key_id,
|
||||
PSA_ALG_RSA_PKCS1V15_CRYPT,
|
||||
ciphertext,
|
||||
encrypt_len,
|
||||
NULL,
|
||||
0,
|
||||
decrypted,
|
||||
decrypted_len,
|
||||
&decrypt_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
#ifdef SOC_CCOMP_TIMER_SUPPORTED
|
||||
private_perf = ccomp_timer_stop();
|
||||
#endif // SOC_CCOMP_TIMER_SUPPORTED
|
||||
|
||||
// Verify decrypted data matches original plaintext
|
||||
TEST_ASSERT_EQUAL(plaintext_len, decrypt_len);
|
||||
|
||||
#ifdef SOC_CCOMP_TIMER_SUPPORTED
|
||||
printf("RSA Key Size: %d bits\n", (keysize == PSA_RSA_KEY_SIZE_2048) ? 2048 :
|
||||
(keysize == PSA_RSA_KEY_SIZE_3072) ? 3072 : 4096);
|
||||
printf("Encryption took %d us, Decryption took %d us\n", public_perf, private_perf);
|
||||
#endif // SOC_CCOMP_TIMER_SUPPORTED
|
||||
psa_destroy_key(key_id);
|
||||
keysize++;
|
||||
}
|
||||
}
|
||||
@@ -19,22 +19,23 @@
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "unity.h"
|
||||
#include "test_utils.h"
|
||||
#include "mbedtls/sha1.h"
|
||||
#include "mbedtls/sha256.h"
|
||||
// // #include "mbedtls/sha1.h"
|
||||
// // #include "mbedtls/sha256.h"
|
||||
|
||||
#if SOC_SHA_SUPPORT_SHA512
|
||||
#include "mbedtls/sha512.h"
|
||||
// #include "mbedtls/sha512.h"
|
||||
#endif
|
||||
|
||||
#include "sha/sha_parallel_engine.h"
|
||||
|
||||
#include "psa/crypto.h"
|
||||
#include "mbedtls/md.h"
|
||||
#define TAG "sha_test"
|
||||
#if MBEDTLS_MAJOR_VERSION < 4
|
||||
|
||||
/* Note: Most of the SHA functions are called as part of mbedTLS, so
|
||||
are tested as part of mbedTLS tests. Only esp_sha() is different.
|
||||
*/
|
||||
|
||||
#define TAG "sha_test"
|
||||
|
||||
#if SOC_SHA_SUPPORTED
|
||||
TEST_CASE("Test esp_sha()", "[hw_crypto]")
|
||||
@@ -276,3 +277,377 @@ TEST_CASE("Test esp_sha() function with long input", "[hw_crypto]")
|
||||
|
||||
#endif // SOC_SHA_SUPPORTED
|
||||
#endif // MBEDTLS_MAJOR_VERSION
|
||||
|
||||
// New test for PSA SHA-512 implementation
|
||||
TEST_CASE("Test PSA SHA-512 with known test vectors", "[hw_crypto][psa]")
|
||||
{
|
||||
ESP_LOGI(TAG, "Testing PSA SHA-512 implementation with known test vectors");
|
||||
|
||||
// Test Vector 1: SHA-512("abc")
|
||||
// Expected: ddaf35a193617abacc417349ae20413112e6fa4e89a97ea20a9eeee64b55d39a2192992a274fc1a836ba3c23a3feebbd454d4423643ce80e2a9ac94fa54ca49f
|
||||
const unsigned char test1_input[] = "abc";
|
||||
const size_t test1_input_len = 3;
|
||||
const unsigned char test1_expected[64] = {
|
||||
0xdd, 0xaf, 0x35, 0xa1, 0x93, 0x61, 0x7a, 0xba, 0xcc, 0x41, 0x73, 0x49, 0xae, 0x20, 0x41, 0x31,
|
||||
0x12, 0xe6, 0xfa, 0x4e, 0x89, 0xa9, 0x7e, 0xa2, 0x0a, 0x9e, 0xee, 0xe6, 0x4b, 0x55, 0xd3, 0x9a,
|
||||
0x21, 0x92, 0x99, 0x2a, 0x27, 0x4f, 0xc1, 0xa8, 0x36, 0xba, 0x3c, 0x23, 0xa3, 0xfe, 0xeb, 0xbd,
|
||||
0x45, 0x4d, 0x44, 0x23, 0x64, 0x3c, 0xe8, 0x0e, 0x2a, 0x9a, 0xc9, 0x4f, 0xa5, 0x4c, 0xa4, 0x9f
|
||||
};
|
||||
|
||||
// Test Vector 2: SHA-512("")
|
||||
// Expected: cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e
|
||||
const unsigned char test2_input[] = "";
|
||||
const size_t test2_input_len = 0;
|
||||
const unsigned char test2_expected[64] = {
|
||||
0xcf, 0x83, 0xe1, 0x35, 0x7e, 0xef, 0xb8, 0xbd, 0xf1, 0x54, 0x28, 0x50, 0xd6, 0x6d, 0x80, 0x07,
|
||||
0xd6, 0x20, 0xe4, 0x05, 0x0b, 0x57, 0x15, 0xdc, 0x83, 0xf4, 0xa9, 0x21, 0xd3, 0x6c, 0xe9, 0xce,
|
||||
0x47, 0xd0, 0xd1, 0x3c, 0x5d, 0x85, 0xf2, 0xb0, 0xff, 0x83, 0x18, 0xd2, 0x87, 0x7e, 0xec, 0x2f,
|
||||
0x63, 0xb9, 0x31, 0xbd, 0x47, 0x41, 0x7a, 0x81, 0xa5, 0x38, 0x32, 0x7a, 0xf9, 0x27, 0xda, 0x3e
|
||||
};
|
||||
|
||||
unsigned char psa_output[64];
|
||||
unsigned char mbedtls_output[64];
|
||||
size_t psa_output_len;
|
||||
psa_status_t psa_status;
|
||||
int mbedtls_ret;
|
||||
|
||||
ESP_LOGI(TAG, "=== Test 1: SHA-512(\"abc\") ===");
|
||||
|
||||
// Test with PSA
|
||||
ESP_LOGI(TAG, "Testing PSA psa_hash_compute()...");
|
||||
psa_status = psa_hash_compute(PSA_ALG_SHA_512, test1_input, test1_input_len,
|
||||
psa_output, sizeof(psa_output), &psa_output_len);
|
||||
ESP_LOGI(TAG, "PSA status: 0x%x, output_len: %zu", (unsigned int)psa_status, psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(64, psa_output_len);
|
||||
|
||||
ESP_LOGI(TAG, "PSA result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
psa_output[0], psa_output[1], psa_output[2], psa_output[3],
|
||||
psa_output[4], psa_output[5], psa_output[6], psa_output[7]);
|
||||
ESP_LOGI(TAG, "Expected result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
test1_expected[0], test1_expected[1], test1_expected[2], test1_expected[3],
|
||||
test1_expected[4], test1_expected[5], test1_expected[6], test1_expected[7]);
|
||||
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test1_expected, psa_output, 64);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-512(\"abc\") PASSED");
|
||||
|
||||
// Test with mbedtls_md
|
||||
ESP_LOGI(TAG, "Testing mbedtls_md()...");
|
||||
const mbedtls_md_info_t *md_info = mbedtls_md_info_from_type(MBEDTLS_MD_SHA512);
|
||||
TEST_ASSERT_NOT_NULL(md_info);
|
||||
|
||||
mbedtls_ret = mbedtls_md(md_info, test1_input, test1_input_len, mbedtls_output);
|
||||
ESP_LOGI(TAG, "mbedtls_md return: %d", mbedtls_ret);
|
||||
TEST_ASSERT_EQUAL(0, mbedtls_ret);
|
||||
|
||||
ESP_LOGI(TAG, "mbedtls result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
mbedtls_output[0], mbedtls_output[1], mbedtls_output[2], mbedtls_output[3],
|
||||
mbedtls_output[4], mbedtls_output[5], mbedtls_output[6], mbedtls_output[7]);
|
||||
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test1_expected, mbedtls_output, 64);
|
||||
ESP_LOGI(TAG, "✓ mbedtls_md SHA-512(\"abc\") PASSED");
|
||||
|
||||
// Verify both methods produce the same result
|
||||
TEST_ASSERT_EQUAL_MEMORY(psa_output, mbedtls_output, 64);
|
||||
ESP_LOGI(TAG, "✓ PSA and mbedtls_md results match");
|
||||
|
||||
ESP_LOGI(TAG, "=== Test 2: SHA-512(\"\") (empty string) ===");
|
||||
|
||||
// Test with PSA
|
||||
psa_status = psa_hash_compute(PSA_ALG_SHA_512, test2_input, test2_input_len,
|
||||
psa_output, sizeof(psa_output), &psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(64, psa_output_len);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test2_expected, psa_output, 64);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-512(\"\") PASSED");
|
||||
|
||||
// Test with mbedtls_md
|
||||
mbedtls_ret = mbedtls_md(md_info, test2_input, test2_input_len, mbedtls_output);
|
||||
TEST_ASSERT_EQUAL(0, mbedtls_ret);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test2_expected, mbedtls_output, 64);
|
||||
ESP_LOGI(TAG, "✓ mbedtls_md SHA-512(\"\") PASSED");
|
||||
|
||||
// Verify both methods produce the same result
|
||||
TEST_ASSERT_EQUAL_MEMORY(psa_output, mbedtls_output, 64);
|
||||
ESP_LOGI(TAG, "✓ All PSA SHA-512 tests PASSED!");
|
||||
}
|
||||
|
||||
TEST_CASE("Test PSA SHA-256 with known test vectors", "[hw_crypto][psa]")
|
||||
{
|
||||
ESP_LOGI(TAG, "Testing PSA SHA-256 implementation with known test vectors");
|
||||
|
||||
// Test Vector 1: SHA-256("abc")
|
||||
// Expected: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
|
||||
const unsigned char test1_input[] = "abc";
|
||||
const size_t test1_input_len = 3;
|
||||
const unsigned char test1_expected[32] = {
|
||||
0xba, 0x78, 0x16, 0xbf, 0x8f, 0x01, 0xcf, 0xea,
|
||||
0x41, 0x41, 0x40, 0xde, 0x5d, 0xae, 0x22, 0x23,
|
||||
0xb0, 0x03, 0x61, 0xa3, 0x96, 0x17, 0x7a, 0x9c,
|
||||
0xb4, 0x10, 0xff, 0x61, 0xf2, 0x00, 0x15, 0xad
|
||||
};
|
||||
|
||||
// Test Vector 2: SHA-256("")
|
||||
// Expected: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
||||
const unsigned char test2_input[] = "";
|
||||
const size_t test2_input_len = 0;
|
||||
const unsigned char test2_expected[32] = {
|
||||
0xe3, 0xb0, 0xc4, 0x42, 0x98, 0xfc, 0x1c, 0x14,
|
||||
0x9a, 0xfb, 0xf4, 0xc8, 0x99, 0x6f, 0xb9, 0x24,
|
||||
0x27, 0xae, 0x41, 0xe4, 0x64, 0x9b, 0x93, 0x4c,
|
||||
0xa4, 0x95, 0x99, 0x1b, 0x78, 0x52, 0xb8, 0x55
|
||||
};
|
||||
|
||||
// Test Vector 3: SHA-256("hello world")
|
||||
// Expected: b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9
|
||||
const unsigned char test3_input[] = "hello world";
|
||||
const unsigned char test3_expected[32] = {
|
||||
0xb9, 0x4d, 0x27, 0xb9, 0x93, 0x4d, 0x3e, 0x08,
|
||||
0xa5, 0x2e, 0x52, 0xd7, 0xda, 0x7d, 0xab, 0xfa,
|
||||
0xc4, 0x84, 0xef, 0xe3, 0x7a, 0x53, 0x80, 0xee,
|
||||
0x90, 0x88, 0xf7, 0xac, 0xe2, 0xef, 0xcd, 0xe9
|
||||
};
|
||||
|
||||
unsigned char psa_output[32];
|
||||
unsigned char mbedtls_output[32];
|
||||
size_t psa_output_len;
|
||||
psa_status_t psa_status;
|
||||
int mbedtls_ret;
|
||||
|
||||
ESP_LOGI(TAG, "=== Test 1: SHA-256(\"abc\") ===");
|
||||
|
||||
// Test with PSA
|
||||
ESP_LOGI(TAG, "Testing PSA psa_hash_compute()...");
|
||||
psa_status = psa_hash_compute(PSA_ALG_SHA_256, test1_input, test1_input_len,
|
||||
psa_output, sizeof(psa_output), &psa_output_len);
|
||||
ESP_LOGI(TAG, "PSA status: 0x%x, output_len: %zu", (unsigned int)psa_status, psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(32, psa_output_len);
|
||||
|
||||
ESP_LOGI(TAG, "PSA result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
psa_output[0], psa_output[1], psa_output[2], psa_output[3],
|
||||
psa_output[4], psa_output[5], psa_output[6], psa_output[7]);
|
||||
ESP_LOGI(TAG, "Expected result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
test1_expected[0], test1_expected[1], test1_expected[2], test1_expected[3],
|
||||
test1_expected[4], test1_expected[5], test1_expected[6], test1_expected[7]);
|
||||
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test1_expected, psa_output, 32);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-256(\"abc\") PASSED");
|
||||
|
||||
// Test with mbedtls_md
|
||||
ESP_LOGI(TAG, "Testing mbedtls_md()...");
|
||||
const mbedtls_md_info_t *md_info = mbedtls_md_info_from_type(MBEDTLS_MD_SHA256);
|
||||
TEST_ASSERT_NOT_NULL(md_info);
|
||||
|
||||
mbedtls_ret = mbedtls_md(md_info, test1_input, test1_input_len, mbedtls_output);
|
||||
ESP_LOGI(TAG, "mbedtls_md return: %d", mbedtls_ret);
|
||||
TEST_ASSERT_EQUAL(0, mbedtls_ret);
|
||||
|
||||
ESP_LOGI(TAG, "mbedtls result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
mbedtls_output[0], mbedtls_output[1], mbedtls_output[2], mbedtls_output[3],
|
||||
mbedtls_output[4], mbedtls_output[5], mbedtls_output[6], mbedtls_output[7]);
|
||||
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test1_expected, mbedtls_output, 32);
|
||||
ESP_LOGI(TAG, "✓ mbedtls_md SHA-256(\"abc\") PASSED");
|
||||
|
||||
// Verify both methods produce the same result
|
||||
TEST_ASSERT_EQUAL_MEMORY(psa_output, mbedtls_output, 32);
|
||||
ESP_LOGI(TAG, "✓ PSA and mbedtls_md results match");
|
||||
|
||||
ESP_LOGI(TAG, "=== Test 2: SHA-256(\"\") (empty string) ===");
|
||||
|
||||
// Test with PSA
|
||||
psa_status = psa_hash_compute(PSA_ALG_SHA_256, test2_input, test2_input_len,
|
||||
psa_output, sizeof(psa_output), &psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(32, psa_output_len);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test2_expected, psa_output, 32);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-256(\"\") PASSED");
|
||||
|
||||
// Test with mbedtls_md
|
||||
mbedtls_ret = mbedtls_md(md_info, test2_input, test2_input_len, mbedtls_output);
|
||||
TEST_ASSERT_EQUAL(0, mbedtls_ret);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test2_expected, mbedtls_output, 32);
|
||||
ESP_LOGI(TAG, "✓ mbedtls_md SHA-256(\"\") PASSED");
|
||||
|
||||
// Verify both methods produce the same result
|
||||
TEST_ASSERT_EQUAL_MEMORY(psa_output, mbedtls_output, 32);
|
||||
ESP_LOGI(TAG, "✓ All PSA SHA-256 tests PASSED!");
|
||||
|
||||
// Test Vector 3: SHA-256("hello world")
|
||||
// This will do with PSA only but _update will be called multiple time
|
||||
|
||||
ESP_LOGI(TAG, "=== Test 3: SHA-256(\"hello world\") ===");
|
||||
psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT;
|
||||
psa_status = psa_hash_setup(&operation, PSA_ALG_SHA_256);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
psa_status = psa_hash_update(&operation, (const uint8_t *)test3_input, 5); // "hello"
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
psa_status = psa_hash_update(&operation, (const uint8_t *)(test3_input + 5), 6); // " world"
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
psa_status = psa_hash_finish(&operation, psa_output, sizeof(psa_output), &psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(32, psa_output_len);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test3_expected, psa_output, 32);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-256(\"hello world\") PASSED");
|
||||
}
|
||||
|
||||
TEST_CASE("Test PSA SHA-384 with known test vectors", "[hw_crypto][psa]")
|
||||
{
|
||||
ESP_LOGI(TAG, "Testing PSA SHA-384 implementation with known test vectors");
|
||||
|
||||
// Test Vector 1: SHA-384("abc")
|
||||
// Expected: cb00753f45a35e8bb5a03d699ac65007272c32ab0eded1631a8b605a43ff5bed8086072ba1e7cc2358baeca134c825a7
|
||||
const unsigned char test1_input[] = "abc";
|
||||
const size_t test1_input_len = 3;
|
||||
const unsigned char test1_expected[48] = {
|
||||
0xcb, 0x00, 0x75, 0x3f, 0x45, 0xa3, 0x5e, 0x8b,
|
||||
0xb5, 0xa0, 0x3d, 0x69, 0x9a, 0xc6, 0x50, 0x07,
|
||||
0x27, 0x2c, 0x32, 0xab, 0x0e, 0xde, 0xd1, 0x63,
|
||||
0x1a, 0x8b, 0x60, 0x5a, 0x43, 0xff, 0x5b, 0xed,
|
||||
0x80, 0x86, 0x07, 0x2b, 0xa1, 0xe7, 0xcc, 0x23,
|
||||
0x58, 0xba, 0xec, 0xa1, 0x34, 0xc8, 0x25, 0xa7
|
||||
};
|
||||
|
||||
// Test Vector 2: SHA-384("")
|
||||
// Expected: 38b060a751ac96384cd9327eb1b1e36a21fdb71114be07434c0cc7bf63f6e1da274edebfe76f65fbd51ad2f14898b95b
|
||||
const unsigned char test2_input[] = "";
|
||||
const size_t test2_input_len = 0;
|
||||
const unsigned char test2_expected[48] = {
|
||||
0x38, 0xb0, 0x60, 0xa7, 0x51, 0xac, 0x96, 0x38,
|
||||
0x4c, 0xd9, 0x32, 0x7e, 0xb1, 0xb1, 0xe3, 0x6a,
|
||||
0x21, 0xfd, 0xb7, 0x11, 0x14, 0xbe, 0x07, 0x43,
|
||||
0x4c, 0x0c, 0xc7, 0xbf, 0x63, 0xf6, 0xe1, 0xda,
|
||||
0x27, 0x4e, 0xde, 0xbf, 0xe7, 0x6f, 0x65, 0xfb,
|
||||
0xd5, 0x1a, 0xd2, 0xf1, 0x48, 0x98, 0xb9, 0x5b
|
||||
};
|
||||
|
||||
// Test Vector 3: SHA-384("hello world")
|
||||
// Expected: fdbd8e75a67f29f701a4e040385e2e23986303ea10239211af907fcbb83578b3e417cb71ce646efd0819dd8c088de1bd
|
||||
const unsigned char test3_input[] = "hello world";
|
||||
const unsigned char test3_expected[48] = {
|
||||
0xfd, 0xbd, 0x8e, 0x75, 0xa6, 0x7f, 0x29, 0xf7,
|
||||
0x01, 0xa4, 0xe0, 0x40, 0x38, 0x5e, 0x2e, 0x23,
|
||||
0x98, 0x63, 0x03, 0xea, 0x10, 0x23, 0x92, 0x11,
|
||||
0xaf, 0x90, 0x7f, 0xcb, 0xb8, 0x35, 0x78, 0xb3,
|
||||
0xe4, 0x17, 0xcb, 0x71, 0xce, 0x64, 0x6e, 0xfd,
|
||||
0x08, 0x19, 0xdd, 0x8c, 0x08, 0x8d, 0xe1, 0xbd
|
||||
};
|
||||
|
||||
unsigned char psa_output[48];
|
||||
unsigned char mbedtls_output[48];
|
||||
size_t psa_output_len;
|
||||
psa_status_t psa_status;
|
||||
int mbedtls_ret;
|
||||
|
||||
ESP_LOGI(TAG, "=== Test 1: SHA-384(\"abc\") ===");
|
||||
|
||||
// Test with PSA
|
||||
ESP_LOGI(TAG, "Testing PSA psa_hash_compute()...");
|
||||
psa_status = psa_hash_compute(PSA_ALG_SHA_384, test1_input, test1_input_len,
|
||||
psa_output, sizeof(psa_output), &psa_output_len);
|
||||
ESP_LOGI(TAG, "PSA status: 0x%x, output_len: %zu", (unsigned int)psa_status, psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(48, psa_output_len);
|
||||
|
||||
ESP_LOGI(TAG, "PSA result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
psa_output[0], psa_output[1], psa_output[2], psa_output[3],
|
||||
psa_output[4], psa_output[5], psa_output[6], psa_output[7]);
|
||||
ESP_LOGI(TAG, "Expected result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
test1_expected[0], test1_expected[1], test1_expected[2], test1_expected[3],
|
||||
test1_expected[4], test1_expected[5], test1_expected[6], test1_expected[7]);
|
||||
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test1_expected, psa_output, 48);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-384(\"abc\") PASSED");
|
||||
|
||||
// Test with mbedtls_md
|
||||
ESP_LOGI(TAG, "Testing mbedtls_md()...");
|
||||
const mbedtls_md_info_t *md_info = mbedtls_md_info_from_type(MBEDTLS_MD_SHA384);
|
||||
TEST_ASSERT_NOT_NULL(md_info);
|
||||
|
||||
mbedtls_ret = mbedtls_md(md_info, test1_input, test1_input_len, mbedtls_output);
|
||||
ESP_LOGI(TAG, "mbedtls_md return: %d", mbedtls_ret);
|
||||
TEST_ASSERT_EQUAL(0, mbedtls_ret);
|
||||
|
||||
ESP_LOGI(TAG, "mbedtls result: %02x %02x %02x %02x %02x %02x %02x %02x...",
|
||||
mbedtls_output[0], mbedtls_output[1], mbedtls_output[2], mbedtls_output[3],
|
||||
mbedtls_output[4], mbedtls_output[5], mbedtls_output[6], mbedtls_output[7]);
|
||||
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test1_expected, mbedtls_output, 48);
|
||||
ESP_LOGI(TAG, "✓ mbedtls_md SHA-384(\"abc\") PASSED");
|
||||
|
||||
// Verify both methods produce the same result
|
||||
TEST_ASSERT_EQUAL_MEMORY(psa_output, mbedtls_output, 48);
|
||||
ESP_LOGI(TAG, "✓ PSA and mbedtls_md results match");
|
||||
|
||||
ESP_LOGI(TAG, "=== Test 2: SHA-384(\"\") (empty string) ===");
|
||||
|
||||
// Test with PSA
|
||||
psa_status = psa_hash_compute(PSA_ALG_SHA_384, test2_input, test2_input_len,
|
||||
psa_output, sizeof(psa_output), &psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(48, psa_output_len);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test2_expected, psa_output, 48);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-384(\"\") PASSED");
|
||||
|
||||
// Test with mbedtls_md
|
||||
mbedtls_ret = mbedtls_md(md_info, test2_input, test2_input_len, mbedtls_output);
|
||||
TEST_ASSERT_EQUAL(0, mbedtls_ret);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test2_expected, mbedtls_output, 48);
|
||||
ESP_LOGI(TAG, "✓ mbedtls_md SHA-384(\"\") PASSED");
|
||||
|
||||
// Verify both methods produce the same result
|
||||
TEST_ASSERT_EQUAL_MEMORY(psa_output, mbedtls_output, 48);
|
||||
ESP_LOGI(TAG, "✓ All PSA SHA-384 tests PASSED!");
|
||||
|
||||
// Test Vector 3: SHA-384("hello world")
|
||||
// This will do with PSA only but _update will be called multiple time
|
||||
|
||||
ESP_LOGI(TAG, "=== Test 3: SHA-384(\"hello world\") ===");
|
||||
psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT;
|
||||
psa_status = psa_hash_setup(&operation, PSA_ALG_SHA_384);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
psa_status = psa_hash_update(&operation, (const uint8_t *)test3_input, 5); // "hello"
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
psa_status = psa_hash_update(&operation, (const uint8_t *)(test3_input + 5), 6); // " world"
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
psa_status = psa_hash_finish(&operation, psa_output, sizeof(psa_output), &psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(48, psa_output_len);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test3_expected, psa_output, 48);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-384(\"hello world\") PASSED");
|
||||
}
|
||||
|
||||
TEST_CASE("Test PSA SHA-384 with clone", "[hw_crypto][psa]")
|
||||
{
|
||||
// Test Vector 1: SHA-384("hello world")
|
||||
// Expected: fdbd8e75a67f29f701a4e040385e2e23986303ea10239211af907fcbb83578b3e417cb71ce646efd0819dd8c088de1bd
|
||||
const unsigned char test3_input[] = "hello world";
|
||||
const unsigned char test3_expected[48] = {
|
||||
0xfd, 0xbd, 0x8e, 0x75, 0xa6, 0x7f, 0x29, 0xf7,
|
||||
0x01, 0xa4, 0xe0, 0x40, 0x38, 0x5e, 0x2e, 0x23,
|
||||
0x98, 0x63, 0x03, 0xea, 0x10, 0x23, 0x92, 0x11,
|
||||
0xaf, 0x90, 0x7f, 0xcb, 0xb8, 0x35, 0x78, 0xb3,
|
||||
0xe4, 0x17, 0xcb, 0x71, 0xce, 0x64, 0x6e, 0xfd,
|
||||
0x08, 0x19, 0xdd, 0x8c, 0x08, 0x8d, 0xe1, 0xbd
|
||||
};
|
||||
|
||||
psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT;
|
||||
psa_status_t psa_status = psa_hash_setup(&operation, PSA_ALG_SHA_384);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
psa_status = psa_hash_update(&operation, (const uint8_t *)test3_input, 5); // "hello"
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
|
||||
psa_hash_operation_t clone = PSA_HASH_OPERATION_INIT;
|
||||
psa_status = psa_hash_clone(&operation, &clone);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
psa_status = psa_hash_update(&clone, (const uint8_t *)(test3_input + 5), 6); // " world"
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
unsigned char psa_output[48];
|
||||
size_t psa_output_len;
|
||||
psa_status = psa_hash_finish(&clone, psa_output, sizeof(psa_output), &psa_output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, psa_status);
|
||||
TEST_ASSERT_EQUAL(48, psa_output_len);
|
||||
TEST_ASSERT_EQUAL_HEX8_ARRAY(test3_expected, psa_output, 48);
|
||||
ESP_LOGI(TAG, "✓ PSA SHA-384(\"hello world\") with original PASSED");
|
||||
}
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
#include <stdbool.h>
|
||||
#include <string.h>
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include "mbedtls/sha256.h"
|
||||
// // #include "mbedtls/sha256.h"
|
||||
#include "unity.h"
|
||||
#include "sdkconfig.h"
|
||||
#include "esp_heap_caps.h"
|
||||
|
||||
@@ -91,17 +91,17 @@ def test_mbedtls_ecdsa_sign(dut: Dut) -> None:
|
||||
dut.run_all_single_board_cases(group='efuse_key')
|
||||
|
||||
|
||||
@pytest.mark.generic
|
||||
@pytest.mark.parametrize(
|
||||
'config',
|
||||
[
|
||||
'rom_impl',
|
||||
],
|
||||
indirect=True,
|
||||
)
|
||||
@idf_parametrize('target', ['esp32c2'], indirect=['target'])
|
||||
def test_mbedtls_rom_impl_esp32c2(dut: Dut) -> None:
|
||||
dut.run_all_single_board_cases()
|
||||
# @pytest.mark.generic
|
||||
# @pytest.mark.parametrize(
|
||||
# 'config',
|
||||
# [
|
||||
# 'rom_impl',
|
||||
# ],
|
||||
# indirect=True,
|
||||
# )
|
||||
# @idf_parametrize('target', ['esp32c2'], indirect=['target'])
|
||||
# def test_mbedtls_rom_impl_esp32c2(dut: Dut) -> None:
|
||||
# dut.run_all_single_board_cases()
|
||||
|
||||
|
||||
@pytest.mark.generic
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
CONFIG_IDF_TARGET="esp32c2"
|
||||
CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL=y
|
||||
# CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL=y
|
||||
|
||||
@@ -8,5 +8,5 @@ CONFIG_COMPILER_STACK_CHECK=y
|
||||
|
||||
CONFIG_ESP_TASK_WDT_EN=y
|
||||
CONFIG_ESP_TASK_WDT_INIT=n
|
||||
CONFIG_COMPILER_OPTIMIZATION_PERF=y
|
||||
# CONFIG_COMPILER_OPTIMIZATION_PERF=y
|
||||
CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_PERF=y
|
||||
|
||||
Reference in New Issue
Block a user