2016-06-13 21:09:41 +02:00
|
|
|
/* This file is part of libbrandt.
|
|
|
|
* Copyright (C) 2016 GNUnet e.V.
|
|
|
|
*
|
|
|
|
* libbrandt is free software: you can redistribute it and/or modify it under
|
|
|
|
* the terms of the GNU General Public License as published by the Free Software
|
|
|
|
* Foundation, either version 3 of the License, or (at your option) any later
|
|
|
|
* version.
|
|
|
|
*
|
|
|
|
* libbrandt is distributed in the hope that it will be useful, but WITHOUT ANY
|
|
|
|
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
|
|
|
|
* A PARTICULAR PURPOSE. See the GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License along with
|
|
|
|
* libbrandt. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @file test_crypto.c
|
|
|
|
* @brief testing crypto and smc functions.
|
2016-06-22 23:18:46 +02:00
|
|
|
* @author Markus Teich
|
2016-06-13 21:09:41 +02:00
|
|
|
*/
|
2016-06-19 22:37:31 +02:00
|
|
|
|
|
|
|
/* For testing static functions and variables we include the whole source */
|
|
|
|
#include "crypto.c"
|
|
|
|
|
2016-06-12 20:52:22 +02:00
|
|
|
#include "brandt.h"
|
|
|
|
#include "crypto.h"
|
|
|
|
#include "test.h"
|
|
|
|
|
2016-06-19 22:37:31 +02:00
|
|
|
|
2016-06-22 14:22:52 +02:00
|
|
|
static uint16_t bidders;
|
|
|
|
static uint16_t prizes;
|
|
|
|
static struct AuctionData *ad;
|
|
|
|
|
2016-06-19 22:37:31 +02:00
|
|
|
int
|
|
|
|
test_smc_2d_array ()
|
|
|
|
{
|
|
|
|
gcry_mpi_point_t **array;
|
|
|
|
uint16_t size1 = 3;
|
|
|
|
uint16_t size2 = 7;
|
|
|
|
uint16_t i, j;
|
|
|
|
|
|
|
|
array = smc_init2 (size1, size2);
|
|
|
|
check (array, "memory allocation failed");
|
|
|
|
|
|
|
|
for (i = 0; i < size1; i++)
|
|
|
|
for (j = 0; j < size2; j++)
|
|
|
|
check (array[i][j], "point has not been initialized");
|
|
|
|
|
|
|
|
smc_free2 (array, size1, size2);
|
2016-06-22 14:22:52 +02:00
|
|
|
return 1;
|
2016-06-19 22:37:31 +02:00
|
|
|
}
|
|
|
|
|
2016-06-12 20:52:22 +02:00
|
|
|
|
2016-06-20 00:36:18 +02:00
|
|
|
int
|
|
|
|
test_smc_3d_array ()
|
|
|
|
{
|
|
|
|
gcry_mpi_point_t ***array;
|
|
|
|
uint16_t size1 = 3;
|
|
|
|
uint16_t size2 = 7;
|
|
|
|
uint16_t size3 = 11;
|
|
|
|
uint16_t i, j, k;
|
|
|
|
|
|
|
|
array = smc_init3 (size1, size2, size3);
|
|
|
|
check (array, "memory allocation failed");
|
|
|
|
|
|
|
|
for (i = 0; i < size1; i++)
|
|
|
|
for (j = 0; j < size2; j++)
|
|
|
|
for (k = 0; k < size3; k++)
|
|
|
|
check (array[i][j][k], "point has not been initialized");
|
|
|
|
|
|
|
|
smc_free3 (array, size1, size2, size3);
|
2016-06-22 14:22:52 +02:00
|
|
|
return 1;
|
2016-06-20 00:36:18 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2016-06-21 00:20:47 +02:00
|
|
|
int
|
|
|
|
test_serialization ()
|
|
|
|
{
|
|
|
|
gcry_mpi_point_t oldp = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_point_t newp = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_t oldi = gcry_mpi_new (0);
|
|
|
|
gcry_mpi_t newi = gcry_mpi_new (0);
|
|
|
|
struct ec_mpi serp;
|
|
|
|
struct ec_mpi seri;
|
|
|
|
|
|
|
|
ec_keypair_create (oldp, oldi);
|
|
|
|
|
|
|
|
ec_point_serialize (&serp, oldp);
|
|
|
|
mpi_serialize (&seri, oldi);
|
|
|
|
|
|
|
|
ec_point_parse (newp, &serp);
|
|
|
|
mpi_parse (newi, &seri);
|
|
|
|
|
|
|
|
check (!ec_point_cmp (oldp, newp), "serialization changed point");
|
|
|
|
check (!gcry_mpi_cmp (oldi, newi), "serialization changed mpi");
|
|
|
|
|
2016-06-21 23:06:15 +02:00
|
|
|
mpi_serialize (&seri, GCRYMPI_CONST_ONE);
|
|
|
|
mpi_parse (newi, &seri);
|
|
|
|
check (!gcry_mpi_cmp (GCRYMPI_CONST_ONE, newi), "serializing mpi 1 fail");
|
|
|
|
|
2016-06-21 00:20:47 +02:00
|
|
|
gcry_mpi_point_release (oldp);
|
|
|
|
gcry_mpi_point_release (newp);
|
|
|
|
gcry_mpi_release (oldi);
|
|
|
|
gcry_mpi_release (newi);
|
2016-06-22 14:22:52 +02:00
|
|
|
return 1;
|
2016-06-21 00:20:47 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2016-06-13 21:01:14 +02:00
|
|
|
int
|
|
|
|
test_smc_zkp_dl ()
|
|
|
|
{
|
2016-06-21 23:06:15 +02:00
|
|
|
struct proof_dl proof;
|
2016-06-16 00:09:29 +02:00
|
|
|
gcry_mpi_t x = gcry_mpi_new (0);
|
2016-06-13 21:09:41 +02:00
|
|
|
gcry_mpi_point_t v = gcry_mpi_point_new (0);
|
2016-06-13 21:01:14 +02:00
|
|
|
|
2016-06-22 02:05:00 +02:00
|
|
|
ec_skey_create (x);
|
2016-06-16 00:09:29 +02:00
|
|
|
|
2016-06-21 23:06:15 +02:00
|
|
|
smc_zkp_dl (v, x, &proof);
|
2016-06-16 00:09:29 +02:00
|
|
|
check (gcry_mpi_ec_curve_point (v, ec_ctx), "not on curve");
|
2016-06-21 23:06:15 +02:00
|
|
|
check (!smc_zkp_dl_check (v, &proof), "zkp dl wrong");
|
2016-06-13 21:09:41 +02:00
|
|
|
|
|
|
|
gcry_mpi_release (x);
|
|
|
|
gcry_mpi_point_release (v);
|
2016-06-22 14:22:52 +02:00
|
|
|
return 1;
|
2016-06-13 21:01:14 +02:00
|
|
|
}
|
|
|
|
|
2016-06-16 00:09:29 +02:00
|
|
|
|
2016-06-15 00:52:18 +02:00
|
|
|
int
|
|
|
|
test_smc_zkp_2dle ()
|
|
|
|
{
|
2016-06-21 23:06:15 +02:00
|
|
|
struct proof_2dle proof;
|
|
|
|
gcry_mpi_t x = gcry_mpi_new (0);
|
|
|
|
gcry_mpi_point_t g1 = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_point_t g2 = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_point_t v = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_point_t w = gcry_mpi_point_new (0);
|
2016-06-15 00:52:18 +02:00
|
|
|
|
2016-06-21 23:06:15 +02:00
|
|
|
ec_keypair_create (g1, x);
|
|
|
|
ec_keypair_create (g2, x);
|
2016-06-16 00:09:29 +02:00
|
|
|
|
2016-06-21 23:06:15 +02:00
|
|
|
smc_zkp_2dle (v, w, g1, g2, x, &proof);
|
2016-06-16 00:09:29 +02:00
|
|
|
check (gcry_mpi_ec_curve_point (g1, ec_ctx), "not on curve");
|
|
|
|
check (gcry_mpi_ec_curve_point (g2, ec_ctx), "not on curve");
|
|
|
|
check (gcry_mpi_ec_curve_point (v, ec_ctx), "not on curve");
|
|
|
|
check (gcry_mpi_ec_curve_point (w, ec_ctx), "not on curve");
|
2016-06-21 23:06:15 +02:00
|
|
|
check (!smc_zkp_2dle_check (v, w, g1, g2, &proof), "zkp 2dle wrong");
|
2016-06-15 00:52:18 +02:00
|
|
|
|
|
|
|
gcry_mpi_release (x);
|
|
|
|
gcry_mpi_point_release (g1);
|
|
|
|
gcry_mpi_point_release (g2);
|
|
|
|
gcry_mpi_point_release (v);
|
|
|
|
gcry_mpi_point_release (w);
|
2016-06-22 14:22:52 +02:00
|
|
|
return 1;
|
2016-06-15 00:52:18 +02:00
|
|
|
}
|
|
|
|
|
2016-06-16 00:09:29 +02:00
|
|
|
|
|
|
|
int
|
|
|
|
test_smc_zkp_0og ()
|
|
|
|
{
|
2016-06-21 23:06:15 +02:00
|
|
|
struct proof_0og proof;
|
2016-06-16 00:09:29 +02:00
|
|
|
gcry_mpi_point_t y = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_point_t alpha = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_point_t beta = gcry_mpi_point_new (0);
|
|
|
|
|
2016-06-21 23:06:15 +02:00
|
|
|
/* get random public key point. We don't need the secret key to check the
|
|
|
|
* proof here */
|
|
|
|
ec_keypair_create (y, NULL);
|
2016-06-16 00:09:29 +02:00
|
|
|
|
2016-06-21 23:06:15 +02:00
|
|
|
smc_zkp_0og (tests_run % 2, y, NULL, alpha, beta, &proof);
|
2016-06-16 00:09:29 +02:00
|
|
|
check (gcry_mpi_ec_curve_point (alpha, ec_ctx), "not on curve");
|
|
|
|
check (gcry_mpi_ec_curve_point (beta, ec_ctx), "not on curve");
|
2016-06-21 23:06:15 +02:00
|
|
|
check (!smc_zkp_0og_check (y, alpha, beta, &proof), "zkp 0og is wrong");
|
|
|
|
|
2016-06-16 00:09:29 +02:00
|
|
|
gcry_mpi_point_release (y);
|
|
|
|
gcry_mpi_point_release (alpha);
|
|
|
|
gcry_mpi_point_release (beta);
|
2016-06-22 14:22:52 +02:00
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
test_setup_auction_data ()
|
|
|
|
{
|
|
|
|
uint16_t i;
|
|
|
|
|
|
|
|
ad = calloc (bidders, sizeof (struct AuctionData));
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
ad[i].n = bidders;
|
|
|
|
ad[i].i = i;
|
|
|
|
ad[i].k = prizes;
|
|
|
|
ad[i].b = 2 * i;
|
|
|
|
}
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
test_prologue ()
|
|
|
|
{
|
|
|
|
uint16_t i, s;
|
|
|
|
unsigned char *bufs[bidders];
|
|
|
|
size_t lens[bidders];
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
bufs[i] = smc_gen_keyshare (&ad[i], &lens[i]);
|
|
|
|
check (bufs[i], "failed to gen keyshare");
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
for (s = 0; s < bidders; s++)
|
|
|
|
{
|
|
|
|
if (s == i)
|
|
|
|
continue;
|
|
|
|
check (smc_recv_keyshare (&ad[i], bufs[s], lens[s], s),
|
|
|
|
"failed checking keyshare");
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
free (bufs[i]);
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
test_round1 ()
|
|
|
|
{
|
|
|
|
uint16_t i, s;
|
|
|
|
unsigned char *bufs[bidders];
|
|
|
|
size_t lens[bidders];
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
bufs[i] = smc_encrypt_bid (&ad[i], &lens[i]);
|
|
|
|
check (bufs[i], "failed to encrypt bid");
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
for (s = 0; s < bidders; s++)
|
|
|
|
{
|
|
|
|
if (s == i)
|
|
|
|
continue;
|
|
|
|
check (smc_recv_encrypted_bid (&ad[i], bufs[s], lens[s], s),
|
|
|
|
"failed checking encrypted bid");
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
free (bufs[i]);
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2016-06-28 16:29:18 +02:00
|
|
|
int
|
|
|
|
test_round2 ()
|
|
|
|
{
|
|
|
|
uint16_t i, s;
|
|
|
|
unsigned char *bufs[bidders];
|
|
|
|
size_t lens[bidders];
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
bufs[i] = smc_compute_outcome (&ad[i], &lens[i]);
|
2016-06-28 17:24:59 +02:00
|
|
|
check (bufs[i], "failed to compute outcome");
|
2016-06-28 16:29:18 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
for (s = 0; s < bidders; s++)
|
|
|
|
{
|
|
|
|
if (s == i)
|
|
|
|
continue;
|
|
|
|
check (smc_recv_outcome (&ad[i], bufs[s], lens[s], s),
|
|
|
|
"failed checking outcome");
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
free (bufs[i]);
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2016-06-28 17:24:59 +02:00
|
|
|
int
|
|
|
|
test_round3 ()
|
|
|
|
{
|
|
|
|
uint16_t i, s;
|
|
|
|
unsigned char *bufs[bidders];
|
|
|
|
size_t lens[bidders];
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
bufs[i] = smc_decrypt_outcome (&ad[i], &lens[i]);
|
|
|
|
check (bufs[i], "failed to decrypt outcome");
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
{
|
|
|
|
for (s = 0; s < bidders; s++)
|
|
|
|
{
|
|
|
|
if (s == i)
|
|
|
|
continue;
|
|
|
|
check (smc_recv_decryption (&ad[i], bufs[s], lens[s], s),
|
|
|
|
"failed checking decrypted outcome");
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < bidders; i++)
|
|
|
|
free (bufs[i]);
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2016-06-22 14:22:52 +02:00
|
|
|
void
|
|
|
|
cleanup_auction_data ()
|
|
|
|
{
|
2016-06-22 23:18:46 +02:00
|
|
|
for (uint16_t i = 0; i < bidders; i++)
|
2016-06-22 14:22:52 +02:00
|
|
|
{
|
2016-06-22 23:18:46 +02:00
|
|
|
for (uint16_t h = 0; h < bidders; h++)
|
|
|
|
gcry_mpi_point_release (ad[i].y[h]);
|
|
|
|
|
|
|
|
gcry_mpi_point_release (ad[i].Y);
|
|
|
|
gcry_mpi_release (ad[i].x);
|
2016-06-22 14:22:52 +02:00
|
|
|
free (ad[i].y);
|
|
|
|
smc_free2 (ad[i].alpha, ad[i].n, ad[i].k);
|
|
|
|
smc_free2 (ad[i].beta, ad[i].n, ad[i].k);
|
|
|
|
}
|
|
|
|
free (ad);
|
2016-06-16 00:09:29 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2016-06-12 20:52:22 +02:00
|
|
|
int
|
|
|
|
main (int argc, char *argv[])
|
|
|
|
{
|
2016-06-22 14:22:52 +02:00
|
|
|
int repeat = 8;
|
|
|
|
|
|
|
|
bidders = 2;
|
|
|
|
prizes = 2 * bidders;
|
2016-06-12 20:52:22 +02:00
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
BRANDT_init ();
|
2016-06-12 20:52:22 +02:00
|
|
|
|
2016-06-19 22:37:31 +02:00
|
|
|
/* tests that need to run only once */
|
|
|
|
run (test_smc_2d_array);
|
2016-06-20 00:36:18 +02:00
|
|
|
run (test_smc_3d_array);
|
2016-06-19 22:37:31 +02:00
|
|
|
|
2016-06-16 00:09:29 +02:00
|
|
|
for (tests_run = 0; tests_run < repeat; tests_run++)
|
2016-06-12 20:52:22 +02:00
|
|
|
{
|
2016-06-21 00:20:47 +02:00
|
|
|
run (test_serialization);
|
2016-06-13 21:09:41 +02:00
|
|
|
run (test_smc_zkp_dl);
|
2016-06-15 01:58:42 +02:00
|
|
|
run (test_smc_zkp_2dle);
|
2016-06-16 00:09:29 +02:00
|
|
|
run (test_smc_zkp_0og);
|
2016-06-22 14:22:52 +02:00
|
|
|
|
|
|
|
run (test_setup_auction_data);
|
|
|
|
run (test_prologue);
|
|
|
|
run (test_round1);
|
2016-06-28 16:29:18 +02:00
|
|
|
run (test_round2);
|
2016-06-28 17:24:59 +02:00
|
|
|
run (test_round3);
|
2016-06-22 14:22:52 +02:00
|
|
|
cleanup_auction_data ();
|
2016-06-12 20:52:22 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|