test_CMAC.py 13 KB


  1. #
  2. # SelfTest/Hash/CMAC.py: Self-test for the CMAC module
  3. #
  4. # ===================================================================
  5. #
  6. # Copyright (c) 2014, Legrandin <helderijs@gmail.com>
  7. # All rights reserved.
  8. #
  9. # Redistribution and use in source and binary forms, with or without
  10. # modification, are permitted provided that the following conditions
  11. # are met:
  12. #
  13. # 1. Redistributions of source code must retain the above copyright
  14. # notice, this list of conditions and the following disclaimer.
  15. # 2. Redistributions in binary form must reproduce the above copyright
  16. # notice, this list of conditions and the following disclaimer in
  17. # the documentation and/or other materials provided with the
  18. # distribution.
  19. #
  20. # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
  21. # "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
  22. # LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
  23. # FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
  24. # COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
  25. # INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
  26. # BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  27. # LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  28. # CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
  29. # LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
  30. # ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
  31. # POSSIBILITY OF SUCH DAMAGE.
  32. # ===================================================================
  33. """Self-test suite for Crypto.Hash.CMAC"""
  34. import json
  35. import unittest
  36. from binascii import unhexlify
  37. from Crypto.Util.py3compat import tobytes
  38. from Crypto.Hash import CMAC
  39. from Crypto.Cipher import AES, DES3
  40. from Crypto.Hash import SHAKE128
  41. from Crypto.Util.strxor import strxor
  42. from Crypto.SelfTest.st_common import list_test_cases
  43. from Crypto.SelfTest.loader import load_test_vectors_wycheproof
  44. # This is a list of (key, data, result, description, module) tuples.
  45. test_data = [
  46. ## Test vectors from RFC 4493 ##
  47. ## The are also in NIST SP 800 38B D.2 ##
  48. ( '2b7e151628aed2a6abf7158809cf4f3c',
  49. '',
  50. 'bb1d6929e95937287fa37d129b756746',
  51. 'RFC 4493 #1',
  52. AES
  53. ),
  54. ( '2b7e151628aed2a6abf7158809cf4f3c',
  55. '6bc1bee22e409f96e93d7e117393172a',
  56. '070a16b46b4d4144f79bdd9dd04a287c',
  57. 'RFC 4493 #2',
  58. AES
  59. ),
  60. ( '2b7e151628aed2a6abf7158809cf4f3c',
  61. '6bc1bee22e409f96e93d7e117393172a'+
  62. 'ae2d8a571e03ac9c9eb76fac45af8e51'+
  63. '30c81c46a35ce411',
  64. 'dfa66747de9ae63030ca32611497c827',
  65. 'RFC 4493 #3',
  66. AES
  67. ),
  68. ( '2b7e151628aed2a6abf7158809cf4f3c',
  69. '6bc1bee22e409f96e93d7e117393172a'+
  70. 'ae2d8a571e03ac9c9eb76fac45af8e51'+
  71. '30c81c46a35ce411e5fbc1191a0a52ef'+
  72. 'f69f2445df4f9b17ad2b417be66c3710',
  73. '51f0bebf7e3b9d92fc49741779363cfe',
  74. 'RFC 4493 #4',
  75. AES
  76. ),
  77. ## The rest of Appendix D of NIST SP 800 38B
  78. ## was not totally correct.
  79. ## Values in Examples 14, 15, 18, and 19 were wrong.
  80. ## The updated test values are published in:
  81. ## http://csrc.nist.gov/publications/nistpubs/800-38B/Updated_CMAC_Examples.pdf
  82. ( '8e73b0f7da0e6452c810f32b809079e5'+
  83. '62f8ead2522c6b7b',
  84. '',
  85. 'd17ddf46adaacde531cac483de7a9367',
  86. 'NIST SP 800 38B D.2 Example 5',
  87. AES
  88. ),
  89. ( '8e73b0f7da0e6452c810f32b809079e5'+
  90. '62f8ead2522c6b7b',
  91. '6bc1bee22e409f96e93d7e117393172a',
  92. '9e99a7bf31e710900662f65e617c5184',
  93. 'NIST SP 800 38B D.2 Example 6',
  94. AES
  95. ),
  96. ( '8e73b0f7da0e6452c810f32b809079e5'+
  97. '62f8ead2522c6b7b',
  98. '6bc1bee22e409f96e93d7e117393172a'+
  99. 'ae2d8a571e03ac9c9eb76fac45af8e51'+
  100. '30c81c46a35ce411',
  101. '8a1de5be2eb31aad089a82e6ee908b0e',
  102. 'NIST SP 800 38B D.2 Example 7',
  103. AES
  104. ),
  105. ( '8e73b0f7da0e6452c810f32b809079e5'+
  106. '62f8ead2522c6b7b',
  107. '6bc1bee22e409f96e93d7e117393172a'+
  108. 'ae2d8a571e03ac9c9eb76fac45af8e51'+
  109. '30c81c46a35ce411e5fbc1191a0a52ef'+
  110. 'f69f2445df4f9b17ad2b417be66c3710',
  111. 'a1d5df0eed790f794d77589659f39a11',
  112. 'NIST SP 800 38B D.2 Example 8',
  113. AES
  114. ),
  115. ( '603deb1015ca71be2b73aef0857d7781'+
  116. '1f352c073b6108d72d9810a30914dff4',
  117. '',
  118. '028962f61b7bf89efc6b551f4667d983',
  119. 'NIST SP 800 38B D.3 Example 9',
  120. AES
  121. ),
  122. ( '603deb1015ca71be2b73aef0857d7781'+
  123. '1f352c073b6108d72d9810a30914dff4',
  124. '6bc1bee22e409f96e93d7e117393172a',
  125. '28a7023f452e8f82bd4bf28d8c37c35c',
  126. 'NIST SP 800 38B D.3 Example 10',
  127. AES
  128. ),
  129. ( '603deb1015ca71be2b73aef0857d7781'+
  130. '1f352c073b6108d72d9810a30914dff4',
  131. '6bc1bee22e409f96e93d7e117393172a'+
  132. 'ae2d8a571e03ac9c9eb76fac45af8e51'+
  133. '30c81c46a35ce411',
  134. 'aaf3d8f1de5640c232f5b169b9c911e6',
  135. 'NIST SP 800 38B D.3 Example 11',
  136. AES
  137. ),
  138. ( '603deb1015ca71be2b73aef0857d7781'+
  139. '1f352c073b6108d72d9810a30914dff4',
  140. '6bc1bee22e409f96e93d7e117393172a'+
  141. 'ae2d8a571e03ac9c9eb76fac45af8e51'+
  142. '30c81c46a35ce411e5fbc1191a0a52ef'+
  143. 'f69f2445df4f9b17ad2b417be66c3710',
  144. 'e1992190549f6ed5696a2c056c315410',
  145. 'NIST SP 800 38B D.3 Example 12',
  146. AES
  147. ),
  148. ( '8aa83bf8cbda1062'+
  149. '0bc1bf19fbb6cd58'+
  150. 'bc313d4a371ca8b5',
  151. '',
  152. 'b7a688e122ffaf95',
  153. 'NIST SP 800 38B D.4 Example 13',
  154. DES3
  155. ),
  156. ( '8aa83bf8cbda1062'+
  157. '0bc1bf19fbb6cd58'+
  158. 'bc313d4a371ca8b5',
  159. '6bc1bee22e409f96',
  160. '8e8f293136283797',
  161. 'NIST SP 800 38B D.4 Example 14',
  162. DES3
  163. ),
  164. ( '8aa83bf8cbda1062'+
  165. '0bc1bf19fbb6cd58'+
  166. 'bc313d4a371ca8b5',
  167. '6bc1bee22e409f96'+
  168. 'e93d7e117393172a'+
  169. 'ae2d8a57',
  170. '743ddbe0ce2dc2ed',
  171. 'NIST SP 800 38B D.4 Example 15',
  172. DES3
  173. ),
  174. ( '8aa83bf8cbda1062'+
  175. '0bc1bf19fbb6cd58'+
  176. 'bc313d4a371ca8b5',
  177. '6bc1bee22e409f96'+
  178. 'e93d7e117393172a'+
  179. 'ae2d8a571e03ac9c'+
  180. '9eb76fac45af8e51',
  181. '33e6b1092400eae5',
  182. 'NIST SP 800 38B D.4 Example 16',
  183. DES3
  184. ),
  185. ( '4cf15134a2850dd5'+
  186. '8a3d10ba80570d38',
  187. '',
  188. 'bd2ebf9a3ba00361',
  189. 'NIST SP 800 38B D.7 Example 17',
  190. DES3
  191. ),
  192. ( '4cf15134a2850dd5'+
  193. '8a3d10ba80570d38',
  194. '6bc1bee22e409f96',
  195. '4ff2ab813c53ce83',
  196. 'NIST SP 800 38B D.7 Example 18',
  197. DES3
  198. ),
  199. ( '4cf15134a2850dd5'+
  200. '8a3d10ba80570d38',
  201. '6bc1bee22e409f96'+
  202. 'e93d7e117393172a'+
  203. 'ae2d8a57',
  204. '62dd1b471902bd4e',
  205. 'NIST SP 800 38B D.7 Example 19',
  206. DES3
  207. ),
  208. ( '4cf15134a2850dd5'+
  209. '8a3d10ba80570d38',
  210. '6bc1bee22e409f96'+
  211. 'e93d7e117393172a'+
  212. 'ae2d8a571e03ac9c'+
  213. '9eb76fac45af8e51',
  214. '31b1e431dabc4eb8',
  215. 'NIST SP 800 38B D.7 Example 20',
  216. DES3
  217. ),
  218. ]
  219. def get_tag_random(tag, length):
  220. return SHAKE128.new(data=tobytes(tag)).read(length)
  221. class TestCMAC(unittest.TestCase):
  222. def test_internal_caching(self):
  223. """Verify that internal caching is implemented correctly"""
  224. data_to_mac = get_tag_random("data_to_mac", 128)
  225. key = get_tag_random("key", 16)
  226. ref_mac = CMAC.new(key, msg=data_to_mac, ciphermod=AES).digest()
  227. # Break up in chunks of different length
  228. # The result must always be the same
  229. for chunk_length in 1, 2, 3, 7, 10, 13, 16, 40, 80, 128:
  230. chunks = [data_to_mac[i:i+chunk_length] for i in
  231. range(0, len(data_to_mac), chunk_length)]
  232. mac = CMAC.new(key, ciphermod=AES)
  233. for chunk in chunks:
  234. mac.update(chunk)
  235. self.assertEqual(ref_mac, mac.digest())
  236. def test_update_after_digest(self):
  237. msg = b"rrrrttt"
  238. key = b"4" * 16
  239. # Normally, update() cannot be done after digest()
  240. h = CMAC.new(key, msg[:4], ciphermod=AES)
  241. dig1 = h.digest()
  242. self.assertRaises(TypeError, h.update, msg[4:])
  243. dig2 = CMAC.new(key, msg, ciphermod=AES).digest()
  244. # With the proper flag, it is allowed
  245. h2 = CMAC.new(key, msg[:4], ciphermod=AES, update_after_digest=True)
  246. self.assertEquals(h2.digest(), dig1)
  247. # ... and the subsequent digest applies to the entire message
  248. # up to that point
  249. h2.update(msg[4:])
  250. self.assertEquals(h2.digest(), dig2)
  251. class ByteArrayTests(unittest.TestCase):
  252. def runTest(self):
  253. key = b"0" * 16
  254. data = b"\x00\x01\x02"
  255. # Data and key can be a bytearray (during initialization)
  256. key_ba = bytearray(key)
  257. data_ba = bytearray(data)
  258. h1 = CMAC.new(key, data, ciphermod=AES)
  259. h2 = CMAC.new(key_ba, data_ba, ciphermod=AES)
  260. key_ba[:1] = b'\xFF'
  261. data_ba[:1] = b'\xFF'
  262. self.assertEqual(h1.digest(), h2.digest())
  263. # Data can be a bytearray (during operation)
  264. key_ba = bytearray(key)
  265. data_ba = bytearray(data)
  266. h1 = CMAC.new(key, ciphermod=AES)
  267. h2 = CMAC.new(key, ciphermod=AES)
  268. h1.update(data)
  269. h2.update(data_ba)
  270. data_ba[:1] = b'\xFF'
  271. self.assertEqual(h1.digest(), h2.digest())
  272. class MemoryViewTests(unittest.TestCase):
  273. def runTest(self):
  274. key = b"0" * 16
  275. data = b"\x00\x01\x02"
  276. def get_mv_ro(data):
  277. return memoryview(data)
  278. def get_mv_rw(data):
  279. return memoryview(bytearray(data))
  280. for get_mv in (get_mv_ro, get_mv_rw):
  281. # Data and key can be a memoryview (during initialization)
  282. key_mv = get_mv(key)
  283. data_mv = get_mv(data)
  284. h1 = CMAC.new(key, data, ciphermod=AES)
  285. h2 = CMAC.new(key_mv, data_mv, ciphermod=AES)
  286. if not data_mv.readonly:
  287. key_mv[:1] = b'\xFF'
  288. data_mv[:1] = b'\xFF'
  289. self.assertEqual(h1.digest(), h2.digest())
  290. # Data can be a memoryview (during operation)
  291. data_mv = get_mv(data)
  292. h1 = CMAC.new(key, ciphermod=AES)
  293. h2 = CMAC.new(key, ciphermod=AES)
  294. h1.update(data)
  295. h2.update(data_mv)
  296. if not data_mv.readonly:
  297. data_mv[:1] = b'\xFF'
  298. self.assertEqual(h1.digest(), h2.digest())
  299. class TestVectorsWycheproof(unittest.TestCase):
  300. def __init__(self, wycheproof_warnings):
  301. unittest.TestCase.__init__(self)
  302. self._wycheproof_warnings = wycheproof_warnings
  303. self._id = "None"
  304. def setUp(self):
  305. def filter_tag(group):
  306. return group['tagSize'] // 8
  307. self.tv = load_test_vectors_wycheproof(("Hash", "wycheproof"),
  308. "aes_cmac_test.json",
  309. "Wycheproof CMAC",
  310. group_tag={'tag_size': filter_tag})
  311. def shortDescription(self):
  312. return self._id
  313. def warn(self, tv):
  314. if tv.warning and self._wycheproof_warnings:
  315. import warnings
  316. warnings.warn("Wycheproof warning: %s (%s)" % (self._id, tv.comment))
  317. def test_create_mac(self, tv):
  318. self._id = "Wycheproof MAC creation Test #" + str(tv.id)
  319. try:
  320. tag = CMAC.new(tv.key, tv.msg, ciphermod=AES, mac_len=tv.tag_size).digest()
  321. except ValueError as e:
  322. if len(tv.key) not in (16, 24, 32) and "key length" in str(e):
  323. return
  324. raise e
  325. if tv.valid:
  326. self.assertEqual(tag, tv.tag)
  327. self.warn(tv)
  328. def test_verify_mac(self, tv):
  329. self._id = "Wycheproof MAC verification Test #" + str(tv.id)
  330. try:
  331. mac = CMAC.new(tv.key, tv.msg, ciphermod=AES, mac_len=tv.tag_size)
  332. except ValueError as e:
  333. if len(tv.key) not in (16, 24, 32) and "key length" in str(e):
  334. return
  335. raise e
  336. try:
  337. mac.verify(tv.tag)
  338. except ValueError:
  339. assert not tv.valid
  340. else:
  341. assert tv.valid
  342. self.warn(tv)
  343. def runTest(self):
  344. for tv in self.tv:
  345. self.test_create_mac(tv)
  346. self.test_verify_mac(tv)
  347. def get_tests(config={}):
  348. global test_data
  349. import types
  350. from .common import make_mac_tests
  351. wycheproof_warnings = config.get('wycheproof_warnings')
  352. # Add new() parameters to the back of each test vector
  353. params_test_data = []
  354. for row in test_data:
  355. t = list(row)
  356. t[4] = dict(ciphermod=t[4])
  357. params_test_data.append(t)
  358. tests = make_mac_tests(CMAC, "CMAC", params_test_data)
  359. tests.append(ByteArrayTests())
  360. tests.append(list_test_cases(TestCMAC))
  361. tests.append(MemoryViewTests())
  362. tests += [ TestVectorsWycheproof(wycheproof_warnings) ]
  363. return tests
  364. if __name__ == '__main__':
  365. import unittest
  366. suite = lambda: unittest.TestSuite(get_tests())
  367. unittest.main(defaultTest='suite')