crypto.py 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778
  1. from binascii import hexlify
  2. from attic.testsuite import AtticTestCase
  3. from attic.crypto import pbkdf2_sha256, get_random_bytes, AES, AES_GCM_MODE, AES_CTR_MODE, \
  4. bytes_to_int, bytes16_to_int, int_to_bytes16, increment_iv
  5. class CryptoTestCase(AtticTestCase):
  6. def test_bytes_to_int(self):
  7. self.assert_equal(bytes_to_int(b'\0\0\0\1'), 1)
  8. def test_bytes16_to_int(self):
  9. i, b = 1, b'\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1'
  10. self.assert_equal(bytes16_to_int(b), i)
  11. self.assert_equal(int_to_bytes16(i), b)
  12. i, b = (1 << 64) + 2, b'\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\2'
  13. self.assert_equal(bytes16_to_int(b), i)
  14. self.assert_equal(int_to_bytes16(i), b)
  15. def test_increment_iv(self):
  16. tests = [
  17. # iv, amount, iv_expected
  18. (0, 0, 0),
  19. (0, 15, 1),
  20. (0, 16, 1),
  21. (0, 17, 2),
  22. (0xffffffffffffffff, 32, 0x10000000000000001),
  23. ]
  24. for iv, amount, iv_expected in tests:
  25. iv = int_to_bytes16(iv)
  26. iv_expected = int_to_bytes16(iv_expected)
  27. self.assert_equal(increment_iv(iv, amount), iv_expected)
  28. def test_pbkdf2_sha256(self):
  29. self.assert_equal(hexlify(pbkdf2_sha256(b'password', b'salt', 1, 32)),
  30. b'120fb6cffcf8b32c43e7225256c4f837a86548c92ccc35480805987cb70be17b')
  31. self.assert_equal(hexlify(pbkdf2_sha256(b'password', b'salt', 2, 32)),
  32. b'ae4d0c95af6b46d32d0adff928f06dd02a303f8ef3c251dfd6e2d85a95474c43')
  33. self.assert_equal(hexlify(pbkdf2_sha256(b'password', b'salt', 4096, 32)),
  34. b'c5e478d59288c841aa530db6845c4c8d962893a001ce4e11a4963873aa98134a')
  35. def test_get_random_bytes(self):
  36. bytes = get_random_bytes(10)
  37. bytes2 = get_random_bytes(10)
  38. self.assert_equal(len(bytes), 10)
  39. self.assert_equal(len(bytes2), 10)
  40. self.assert_not_equal(bytes, bytes2)
  41. def test_aes_ctr(self):
  42. key = b'X' * 32
  43. iv = b'\0' * 16
  44. data = b'foo' * 10
  45. # encrypt
  46. aes = AES(mode=AES_CTR_MODE, is_encrypt=True, key=key, iv=iv)
  47. _, cdata = aes.compute_mac_and_encrypt(data)
  48. self.assert_equal(hexlify(cdata), b'c6efb702de12498f34a2c2bbc8149e759996d08bf6dc5c610aefc0c3a466')
  49. # decrypt (correct mac/cdata)
  50. aes = AES(mode=AES_CTR_MODE, is_encrypt=False, key=key, iv=iv)
  51. pdata = aes.check_mac_and_decrypt(None, cdata)
  52. self.assert_equal(data, pdata)
  53. def test_aes_gcm(self):
  54. key = b'X' * 32
  55. iv = b'A' * 16
  56. data = b'foo' * 10
  57. # encrypt
  58. aes = AES(mode=AES_GCM_MODE, is_encrypt=True, key=key, iv=iv)
  59. mac, cdata = aes.compute_mac_and_encrypt(data)
  60. self.assert_equal(hexlify(mac), b'c98aa10eb6b7031bcc2160878d9438fb')
  61. self.assert_equal(hexlify(cdata), b'841bcce405df769d22ee9f7f012edf5dc7fb2594d924c7400ffd050f2741')
  62. # decrypt (correct mac/cdata)
  63. aes = AES(mode=AES_GCM_MODE, is_encrypt=False, key=key, iv=iv)
  64. pdata = aes.check_mac_and_decrypt(mac, cdata)
  65. self.assert_equal(data, pdata)
  66. # decrypt (incorrect mac/cdata)
  67. aes = AES(mode=AES_GCM_MODE, is_encrypt=False, key=key, iv=iv)
  68. cdata = b'x' + cdata[1:] # corrupt cdata
  69. self.assertRaises(Exception, aes.check_mac_and_decrypt, mac, cdata)