1"""Framework classes for generation of ecp test cases."""
2# Copyright The Mbed TLS Contributors
3# SPDX-License-Identifier: Apache-2.0
4#
5# Licensed under the Apache License, Version 2.0 (the "License"); you may
6# not use this file except in compliance with the License.
7# You may obtain a copy of the License at
8#
9# http://www.apache.org/licenses/LICENSE-2.0
10#
11# Unless required by applicable law or agreed to in writing, software
12# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
13# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14# See the License for the specific language governing permissions and
15# limitations under the License.
16
17from typing import List
18
19from . import test_data_generation
20from . import bignum_common
21
22
23class EcpTarget(test_data_generation.BaseTarget):
24    #pylint: disable=abstract-method, too-few-public-methods
25    """Target for ecp test case generation."""
26    target_basename = 'test_suite_ecp.generated'
27
28
29class EcpP192R1Raw(bignum_common.ModOperationCommon,
30                   EcpTarget):
31    """Test cases for ecp quasi_reduction()."""
32    symbol = "-"
33    test_function = "ecp_mod_p192_raw"
34    test_name = "ecp_mod_p192_raw"
35    input_style = "fixed"
36    arity = 1
37
38    moduli = ["fffffffffffffffffffffffffffffffeffffffffffffffff"] # type: List[str]
39
40    input_values = [
41        "0", "1",
42
43        # Modulus - 1
44        "fffffffffffffffffffffffffffffffefffffffffffffffe",
45
46        # First 8 number generated by random.getrandbits(384) - seed(2,2)
47        ("cf1822ffbc6887782b491044d5e341245c6e433715ba2bdd"
48         "177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
49        ("ffed9235288bc781ae66267594c9c9500925e4749b575bd1"
50         "3653f8dd9b1f282e4067c3584ee207f8da94e3e8ab73738f"),
51        ("ef8acd128b4f2fc15f3f57ebf30b94fa82523e86feac7eb7"
52         "dc38f519b91751dacdbd47d364be8049a372db8f6e405d93"),
53        ("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045"
54         "defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2"),
55        ("2d3d854e061b90303b08c6e33c7295782d6c797f8f7d9b78"
56         "2a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
57        ("fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f1"
58         "5c14bc4a829e07b0829a48d422fe99a22c70501e533c9135"),
59        ("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561"
60         "867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2"),
61        ("bd143fa9b714210c665d7435c1066932f4767f26294365b2"
62         "721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
63
64        # Next 2 number generated by random.getrandbits(192)
65        "47733e847d718d733ff98ff387c56473a7a83ee0761ebfd2",
66        "cbd4d3e2d4dec9ef83f0be4e80371eb97f81375eecc1cb63"
67    ]
68
69    @property
70    def arg_a(self) -> str:
71        return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
72
73    def result(self) -> List[str]:
74        result = self.int_a % self.int_n
75        return [self.format_result(result)]
76
77    @property
78    def is_valid(self) -> bool:
79        return True
80
81
82class EcpP224R1Raw(bignum_common.ModOperationCommon,
83                   EcpTarget):
84    """Test cases for ecp quasi_reduction()."""
85    symbol = "-"
86    test_function = "ecp_mod_p224_raw"
87    test_name = "ecp_mod_p224_raw"
88    input_style = "arch_split"
89    arity = 1
90
91    moduli = ["ffffffffffffffffffffffffffffffff000000000000000000000001"] # type: List[str]
92
93    input_values = [
94        "0", "1",
95
96        # Modulus - 1
97        "ffffffffffffffffffffffffffffffff000000000000000000000000",
98
99        # Maximum canonical P224 multiplication result
100        ("fffffffffffffffffffffffffffffffe000000000000000000000000"
101         "00000001000000000000000000000000000000000000000000000000"),
102
103        # Generate an overflow during reduction
104        ("00000000000000000000000000010000000070000000002000001000"
105         "ffffffffffff9fffffffffe00000efff000070000000002000001003"),
106
107        # Generate an underflow during reduction
108        ("00000001000000000000000000000000000000000000000000000000"
109         "00000000000dc0000000000000000001000000010000000100000003"),
110
111        # First 8 number generated by random.getrandbits(448) - seed(2,2)
112        ("da94e3e8ab73738fcf1822ffbc6887782b491044d5e341245c6e4337"
113         "15ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
114        ("cdbd47d364be8049a372db8f6e405d93ffed9235288bc781ae662675"
115         "94c9c9500925e4749b575bd13653f8dd9b1f282e4067c3584ee207f8"),
116        ("defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2ef8acd12"
117         "8b4f2fc15f3f57ebf30b94fa82523e86feac7eb7dc38f519b91751da"),
118        ("2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a6"
119         "6148a86fe8624fab5186ee32ee8d7ee9770348a05d300cb90706a045"),
120        ("8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0829a48d4"
121         "22fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578"),
122        ("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561867e5e15"
123         "bc01bfce6a27e0dfcbf8754472154e76e4c11ab2fec3f6b32e8d4b8a"),
124        ("a7a83ee0761ebfd2bd143fa9b714210c665d7435c1066932f4767f26"
125         "294365b2721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
126        ("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e"
127         "80371eb97f81375eecc1cb6347733e847d718d733ff98ff387c56473"),
128
129        # Next 2 number generated by random.getrandbits(224)
130        "eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a",
131        "f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f258ebdbfe3"
132    ]
133
134    @property
135    def arg_a(self) -> str:
136        hex_digits = bignum_common.hex_digits_for_limb(448 // self.bits_in_limb, self.bits_in_limb)
137        return super().format_arg('{:x}'.format(self.int_a)).zfill(hex_digits)
138
139    def result(self) -> List[str]:
140        result = self.int_a % self.int_n
141        return [self.format_result(result)]
142
143    @property
144    def is_valid(self) -> bool:
145        return True
146
147
148class EcpP256R1Raw(bignum_common.ModOperationCommon,
149                   EcpTarget):
150    """Test cases for ECP P256 fast reduction."""
151    symbol = "-"
152    test_function = "ecp_mod_p256_raw"
153    test_name = "ecp_mod_p256_raw"
154    input_style = "fixed"
155    arity = 1
156
157    moduli = ["ffffffff00000001000000000000000000000000ffffffffffffffffffffffff"] # type: List[str]
158
159    input_values = [
160        "0", "1",
161
162        # Modulus - 1
163        "ffffffff00000001000000000000000000000000fffffffffffffffffffffffe",
164
165        # Maximum canonical P256 multiplication result
166        ("fffffffe00000002fffffffe0000000100000001fffffffe00000001fffffffc"
167         "00000003fffffffcfffffffffffffffffffffffc000000000000000000000004"),
168
169        # Generate an overflow during reduction
170        ("0000000000000000000000010000000000000000000000000000000000000000"
171         "00000000000000000000000000000000000000000000000000000000ffffffff"),
172
173        # Generate an underflow during reduction
174        ("0000000000000000000000000000000000000000000000000000000000000010"
175         "ffffffff00000000000000000000000000000000000000000000000000000000"),
176
177        # Generate an overflow during carry reduction
178        ("aaaaaaaa00000000000000000000000000000000000000000000000000000000"
179         "00000000000000000000000000000000aaaaaaacaaaaaaaaaaaaaaaa00000000"),
180
181        # Generate an underflow during carry reduction
182        ("000000000000000000000001ffffffff00000000000000000000000000000000"
183         "0000000000000000000000000000000000000002000000020000000100000002"),
184
185        # First 8 number generated by random.getrandbits(512) - seed(2,2)
186        ("4067c3584ee207f8da94e3e8ab73738fcf1822ffbc6887782b491044d5e34124"
187         "5c6e433715ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
188        ("82523e86feac7eb7dc38f519b91751dacdbd47d364be8049a372db8f6e405d93"
189         "ffed9235288bc781ae66267594c9c9500925e4749b575bd13653f8dd9b1f282e"),
190        ("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045defc044a09325626"
191         "e6b58de744ab6cce80877b6f71e1f6d2ef8acd128b4f2fc15f3f57ebf30b94fa"),
192        ("829a48d422fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578"
193         "2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
194        ("e89204e2e8168561867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2"
195         "fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0"),
196        ("bd143fa9b714210c665d7435c1066932f4767f26294365b2721dea3bf63f23d0"
197         "dbe53fcafb2147df5ca495fa5a91c89b97eeab64ca2ce6bc5d3fd983c34c769f"),
198        ("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e80371eb9"
199         "7f81375eecc1cb6347733e847d718d733ff98ff387c56473a7a83ee0761ebfd2"),
200        ("d08f1bb2531d6460f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f25"
201         "8ebdbfe3eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a"),
202
203        # Next 2 number generated by random.getrandbits(256)
204        "c5e2486c44a4a8f69dc8db48e86ec9c6e06f291b2a838af8d5c44a4eb3172062",
205        "d4c0dca8b4c9e755cc9c3adcf515a8234da4daeb4f3f87777ad1f45ae9500ec9"
206    ]
207
208    @property
209    def arg_a(self) -> str:
210        return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
211
212    def result(self) -> List[str]:
213        result = self.int_a % self.int_n
214        return [self.format_result(result)]
215
216    @property
217    def is_valid(self) -> bool:
218        return True
219
220
221class EcpP521R1Raw(bignum_common.ModOperationCommon,
222                   EcpTarget):
223    """Test cases for ecp quasi_reduction()."""
224    test_function = "ecp_mod_p521_raw"
225    test_name = "ecp_mod_p521_raw"
226    input_style = "arch_split"
227    arity = 1
228
229    moduli = [("01ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
230               "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff")
231             ] # type: List[str]
232
233    input_values = [
234        "0", "1",
235
236        # Corner case: maximum canonical P521 multiplication result
237        ("0003ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
238         "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
239         "fffff800"
240         "0000000000000000000000000000000000000000000000000000000000000000"
241         "0000000000000000000000000000000000000000000000000000000000000004"),
242
243        # Test case for overflow during addition
244        ("0001efffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
245         "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
246         "000001ef"
247         "0000000000000000000000000000000000000000000000000000000000000000"
248         "000000000000000000000000000000000000000000000000000000000f000000"),
249
250        # First 8 number generated by random.getrandbits(1042) - seed(2,2)
251        ("0003cc2e82523e86feac7eb7dc38f519b91751dacdbd47d364be8049a372db8f"
252         "6e405d93ffed9235288bc781ae66267594c9c9500925e4749b575bd13653f8dd"
253         "9b1f282e"
254         "4067c3584ee207f8da94e3e8ab73738fcf1822ffbc6887782b491044d5e34124"
255         "5c6e433715ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
256        ("00017052829e07b0829a48d422fe99a22c70501e533c91352d3d854e061b9030"
257         "3b08c6e33c7295782d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c5055"
258         "6c71c4a6"
259         "6148a86fe8624fab5186ee32ee8d7ee9770348a05d300cb90706a045defc044a"
260         "09325626e6b58de744ab6cce80877b6f71e1f6d2ef8acd128b4f2fc15f3f57eb"),
261        ("00021f15a7a83ee0761ebfd2bd143fa9b714210c665d7435c1066932f4767f26"
262         "294365b2721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b97eeab64"
263         "ca2ce6bc"
264         "5d3fd983c34c769fe89204e2e8168561867e5e15bc01bfce6a27e0dfcbf87544"
265         "72154e76e4c11ab2fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f1"),
266        ("000381bc2a838af8d5c44a4eb3172062d08f1bb2531d6460f0caeef038c89b38"
267         "a8acb5137c9260dc74e088a9b9492f258ebdbfe3eb9ac688b9d39cca91551e82"
268         "59cc60b1"
269         "7604e4b4e73695c3e652c71a74667bffe202849da9643a295a9ac6decbd4d3e2"
270         "d4dec9ef83f0be4e80371eb97f81375eecc1cb6347733e847d718d733ff98ff3"),
271        ("00034816c8c69069134bccd3e1cf4f589f8e4ce0af29d115ef24bd625dd961e6"
272         "830b54fa7d28f93435339774bb1e386c4fd5079e681b8f5896838b769da59b74"
273         "a6c3181c"
274         "81e220df848b1df78feb994a81167346d4c0dca8b4c9e755cc9c3adcf515a823"
275         "4da4daeb4f3f87777ad1f45ae9500ec9c5e2486c44a4a8f69dc8db48e86ec9c6"),
276        ("000397846c4454b90f756132e16dce72f18e859835e1f291d322a7353ead4efe"
277         "440e2b4fda9c025a22f1a83185b98f5fc11e60de1b343f52ea748db9e020307a"
278         "aeb6db2c"
279         "3a038a709779ac1f45e9dd320c855fdfa7251af0930cdbd30f0ad2a81b2d19a2"
280         "beaa14a7ff3fe32a30ffc4eed0a7bd04e85bfcdd0227eeb7b9d7d01f5769da05"),
281        ("00002c3296e6bc4d62b47204007ee4fab105d83e85e951862f0981aebc1b00d9"
282         "2838e766ef9b6bf2d037fe2e20b6a8464174e75a5f834da70569c018eb2b5693"
283         "babb7fbb"
284         "0a76c196067cfdcb11457d9cf45e2fa01d7f4275153924800600571fac3a5b26"
285         "3fdf57cd2c0064975c3747465cc36c270e8a35b10828d569c268a20eb78ac332"),
286        ("00009d23b4917fc09f20dbb0dcc93f0e66dfe717c17313394391b6e2e6eacb0f"
287         "0bb7be72bd6d25009aeb7fa0c4169b148d2f527e72daf0a54ef25c0707e33868"
288         "7d1f7157"
289         "5653a45c49390aa51cf5192bbf67da14be11d56ba0b4a2969d8055a9f03f2d71"
290         "581d8e830112ff0f0948eccaf8877acf26c377c13f719726fd70bddacb4deeec"),
291
292        # Next 2 number generated by random.getrandbits(521)
293        ("12b84ae65e920a63ac1f2b64df6dff07870c9d531ae72a47403063238da1a1fe"
294         "3f9d6a179fa50f96cd4aff9261aa92c0e6f17ec940639bc2ccdf572df00790813e3"),
295        ("166049dd332a73fa0b26b75196cf87eb8a09b27ec714307c68c425424a1574f1"
296         "eedf5b0f16cdfdb839424d201e653f53d6883ca1c107ca6e706649889c0c7f38608")
297    ]
298
299    @property
300    def arg_a(self) -> str:
301        # Number of limbs: 2 * N
302        return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
303
304    def result(self) -> List[str]:
305        result = self.int_a % self.int_n
306        return [self.format_result(result)]
307
308    @property
309    def is_valid(self) -> bool:
310        return True
311