1
/* ====================================================================
2
* Copyright (c) 2004 The OpenSSL Project. All rights reserved.
4
* Redistribution and use in source and binary forms, with or without
5
* modification, are permitted provided that the following conditions
8
* 1. Redistributions of source code must retain the above copyright
9
* notice, this list of conditions and the following disclaimer.
11
* 2. Redistributions in binary form must reproduce the above copyright
12
* notice, this list of conditions and the following disclaimer in
13
* the documentation and/or other materials provided with the
16
* 3. All advertising materials mentioning features or use of this
17
* software must display the following acknowledgment:
18
* "This product includes software developed by the OpenSSL Project
19
* for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
21
* 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
22
* endorse or promote products derived from this software without
23
* prior written permission. For written permission, please contact
24
* openssl-core@openssl.org.
26
* 5. Products derived from this software may not be called "OpenSSL"
27
* nor may "OpenSSL" appear in their names without prior written
28
* permission of the OpenSSL Project.
30
* 6. Redistributions of any form whatsoever must retain the following
32
* "This product includes software developed by the OpenSSL Project
33
* for use in the OpenSSL Toolkit (http://www.openssl.org/)"
35
* THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
36
* EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
37
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
38
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
39
* ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
40
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
41
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
42
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
43
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
44
* STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
45
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
46
* OF THE POSSIBILITY OF SUCH DAMAGE.
49
/*---------------------------------------------
50
NIST DES Modes of Operation Validation System
53
Based on the AES Validation Suite, which was:
54
Donated to OpenSSL by:
56
20250 Century Blvd, Suite 300
59
----------------------------------------------*/
67
#include <openssl/des.h>
68
#include <openssl/evp.h>
69
#include <openssl/bn.h>
71
#include <openssl/err.h>
76
int main(int argc, char *argv[])
78
printf("No FIPS DES support\n");
84
#include <openssl/fips.h>
87
#define DES_BLOCK_SIZE 8
91
int DESTest(EVP_CIPHER_CTX *ctx,
92
char *amode, int akeysz, unsigned char *aKey,
94
int dir, /* 0 = decrypt, 1 = encrypt */
95
unsigned char *out, unsigned char *in, int len)
97
const EVP_CIPHER *cipher = NULL;
101
printf("Invalid key size: %d\n", akeysz);
105
if (strcasecmp(amode, "CBC") == 0)
106
cipher = EVP_des_ede3_cbc();
107
else if (strcasecmp(amode, "ECB") == 0)
108
cipher = EVP_des_ede3_ecb();
109
else if (strcasecmp(amode, "CFB64") == 0)
110
cipher = EVP_des_ede3_cfb64();
111
else if (strncasecmp(amode, "OFB", 3) == 0)
112
cipher = EVP_des_ede3_ofb();
114
else if(!strcasecmp(amode,"CFB1"))
117
ctx->cmode = EVP_CIPH_CFB_MODE;
120
else if(!strcasecmp(amode,"CFB8"))
121
cipher = EVP_des_ede3_cfb8();
124
printf("Unknown mode: %s\n", amode);
128
if (EVP_CipherInit_ex(ctx, cipher, NULL, aKey, iVec, dir) <= 0)
130
EVP_Cipher(ctx, out, in, len);
135
void DebugValue(char *tag, unsigned char *val, int len)
139
olen = bin2hex(val, len, obuf);
140
printf("%s = %.*s\n", tag, olen, obuf);
143
void shiftin(unsigned char *dst,unsigned char *src,int nbits)
147
/* move the bytes... */
148
memmove(dst,dst+nbits/8,3*8-nbits/8);
149
/* append new data */
150
memcpy(dst+3*8-nbits/8,src,(nbits+7)/8);
151
/* left shift the bits */
153
for(n=0 ; n < 3*8 ; ++n)
154
dst[n]=(dst[n] << (nbits%8))|(dst[n+1] >> (8-nbits%8));
157
/*-----------------------------------------------*/
158
char *t_tag[2] = {"PLAINTEXT", "CIPHERTEXT"};
159
char *t_mode[6] = {"CBC","ECB","OFB","CFB1","CFB8","CFB64"};
160
enum Mode {CBC, ECB, OFB, CFB1, CFB8, CFB64};
161
int Sizes[6]={64,64,64,1,8,64};
163
void do_mct(char *amode,
164
int akeysz, int numkeys, unsigned char *akey,unsigned char *ivec,
165
int dir, unsigned char *text, int len,
169
unsigned char nk[4*8]; /* longest key+8 */
170
unsigned char text0[8];
172
for (imode=0 ; imode < 6 ; ++imode)
173
if(!strcmp(amode,t_mode[imode]))
177
printf("Unrecognized mode: %s\n", amode);
181
for(i=0 ; i < 400 ; ++i)
186
unsigned char old_iv[8];
188
EVP_CIPHER_CTX_init(&ctx);
190
fprintf(rfp,"\nCOUNT = %d\n",i);
192
OutputValue("KEY",akey,8,rfp,0);
194
for(n=0 ; n < kp ; ++n)
196
fprintf(rfp,"KEY%d",n+1);
197
OutputValue("",akey+n*8,8,rfp,0);
201
OutputValue("IV",ivec,8,rfp,0);
202
OutputValue(t_tag[dir^1],text,len,rfp,imode == CFB1);
204
/* compensate for endianness */
208
memcpy(text0,text,8);
210
for(j=0 ; j < 10000 ; ++j)
212
unsigned char old_text[8];
214
memcpy(old_text,text,8);
217
memcpy(old_iv,ivec,8);
218
DESTest(&ctx,amode,akeysz,akey,ivec,dir,text,text,len);
222
memcpy(old_iv,ctx.iv,8);
223
EVP_Cipher(&ctx,text,text,len);
227
OutputValue(t_tag[dir],text,len,rfp,imode == CFB1);
228
/* memcpy(ivec,text,8); */
230
/* DebugValue("iv",ctx.iv,8); */
231
/* accumulate material for the next key */
232
shiftin(nk,text,Sizes[imode]);
233
/* DebugValue("nk",nk,24);*/
234
if((dir && (imode == CFB1 || imode == CFB8 || imode == CFB64
235
|| imode == CBC)) || imode == OFB)
236
memcpy(text,old_iv,8);
238
if(!dir && (imode == CFB1 || imode == CFB8 || imode == CFB64))
240
/* the test specifies using the output of the raw DES operation
241
which we don't have, so reconstruct it... */
242
for(n=0 ; n < 8 ; ++n)
243
text[n]^=old_text[n];
246
for(n=0 ; n < 8 ; ++n)
248
for(n=0 ; n < 8 ; ++n)
250
for(n=0 ; n < 8 ; ++n)
253
memcpy(&akey[2*8],akey,8);
255
memcpy(&akey[8],akey,8);
256
DES_set_odd_parity((DES_cblock *)akey);
257
DES_set_odd_parity((DES_cblock *)(akey+8));
258
DES_set_odd_parity((DES_cblock *)(akey+16));
259
memcpy(ivec,ctx.iv,8);
261
/* pointless exercise - the final text doesn't depend on the
262
initial text in OFB mode, so who cares what it is? (Who
263
designed these tests?) */
265
for(n=0 ; n < 8 ; ++n)
266
text[n]=text0[n]^old_iv[n];
270
int proc_file(char *rqfile, char *rspfile)
272
char afn[256], rfn[256];
273
FILE *afp = NULL, *rfp = NULL;
274
char ibuf[2048], tbuf[2048];
275
int ilen, len, ret = 0;
277
char atest[100] = "";
279
unsigned char iVec[20], aKey[40];
280
int dir = -1, err = 0, step = 0;
281
unsigned char plaintext[2048];
282
unsigned char ciphertext[2048];
286
EVP_CIPHER_CTX_init(&ctx);
288
if (!rqfile || !(*rqfile))
290
printf("No req file\n");
295
if ((afp = fopen(afn, "r")) == NULL)
297
printf("Cannot open file: %s, %s\n",
298
afn, strerror(errno));
304
rp=strstr(rfn,"req/");
305
#ifdef OPENSSL_SYS_WIN32
307
rp=strstr(rfn,"req\\");
311
rp = strstr(rfn, ".req");
312
memcpy(rp, ".rsp", 4);
315
if ((rfp = fopen(rspfile, "w")) == NULL)
317
printf("Cannot open file: %s, %s\n",
318
rfn, strerror(errno));
323
while (!err && (fgets(ibuf, sizeof(ibuf), afp)) != NULL)
325
tidy_line(tbuf, ibuf);
327
/* printf("step=%d ibuf=%s",step,ibuf);*/
328
if(step == 3 && !strcmp(amode,"ECB"))
330
memset(iVec, 0, sizeof(iVec));
331
step = (dir)? 4: 5; /* no ivec for ECB */
335
case 0: /* read preamble */
337
{ /* end of preamble */
340
printf("Missing Mode\n");
349
else if (ibuf[0] != '#')
351
printf("Invalid preamble item: %s\n", ibuf);
355
{ /* process preamble */
356
char *xp, *pp = ibuf+2;
359
{ /* insert current time & date */
360
time_t rtim = time(0);
361
fprintf(rfp, "# %s", ctime(&rtim));
366
if(!strncmp(pp,"INVERSE ",8) || !strncmp(pp,"DES ",4)
367
|| !strncmp(pp,"TDES ",5)
368
|| !strncmp(pp,"PERMUTATION ",12)
369
|| !strncmp(pp,"SUBSTITUTION ",13)
370
|| !strncmp(pp,"VARIABLE ",9))
373
if(!strncmp(pp,"DES ",4))
375
else if(!strncmp(pp,"TDES ",5))
377
xp = strchr(pp, ' ');
379
strncpy(atest, pp, n);
382
xp = strrchr(pp, ' '); /* get mode" */
384
strncpy(amode, xp+1, n);
386
/* amode[3] = '\0'; */
388
printf("Test=%s, Mode=%s\n",atest,amode);
394
case 1: /* [ENCRYPT] | [DECRYPT] */
401
if (strncasecmp(ibuf, "[ENCRYPT]", 9) == 0)
403
else if (strncasecmp(ibuf, "[DECRYPT]", 9) == 0)
407
printf("Invalid keyword: %s\n", ibuf);
415
printf("Missing ENCRYPT/DECRYPT keyword\n");
421
case 2: /* KEY = xxxx */
427
if(!strncasecmp(ibuf,"COUNT = ",8))
432
if(!strncasecmp(ibuf,"COUNT=",6))
437
if(!strncasecmp(ibuf,"NumKeys = ",10))
439
numkeys=atoi(ibuf+10);
444
if(!strncasecmp(ibuf,"KEY = ",6))
447
len = hex2bin((char*)ibuf+6, aKey);
450
printf("Invalid KEY\n");
454
PrintValue("KEY", aKey, len);
457
else if(!strncasecmp(ibuf,"KEYs = ",7))
460
len=hex2bin(ibuf+7,aKey);
463
printf("Invalid KEY\n");
467
memcpy(aKey+8,aKey,8);
468
memcpy(aKey+16,aKey,8);
470
PrintValue("KEYs",aKey,len);
473
else if(!strncasecmp(ibuf,"KEY",3))
478
len=hex2bin(ibuf+7,aKey+n*8);
481
printf("Invalid KEY\n");
486
PrintValue(ibuf,aKey,len);
492
printf("Missing KEY\n");
497
case 3: /* IV = xxxx */
499
if (strncasecmp(ibuf, "IV = ", 5) != 0)
501
printf("Missing IV\n");
506
len = hex2bin((char*)ibuf+5, iVec);
509
printf("Invalid IV\n");
513
PrintValue("IV", iVec, len);
518
case 4: /* PLAINTEXT = xxxx */
520
if (strncasecmp(ibuf, "PLAINTEXT = ", 12) != 0)
522
printf("Missing PLAINTEXT\n");
527
int nn = strlen(ibuf+12);
528
if(!strcmp(amode,"CFB1"))
529
len=bint2bin(ibuf+12,nn-1,plaintext);
531
len=hex2bin(ibuf+12, plaintext);
534
printf("Invalid PLAINTEXT: %s", ibuf+12);
538
if (len >= sizeof(plaintext))
540
printf("Buffer overflow\n");
542
PrintValue("PLAINTEXT", (unsigned char*)plaintext, len);
543
if (strcmp(atest, "Monte") == 0) /* Monte Carlo Test */
545
do_mct(amode,akeysz,numkeys,aKey,iVec,dir,plaintext,len,rfp);
550
ret = DESTest(&ctx, amode, akeysz, aKey, iVec,
551
dir, /* 0 = decrypt, 1 = encrypt */
552
ciphertext, plaintext, len);
553
OutputValue("CIPHERTEXT",ciphertext,len,rfp,
554
!strcmp(amode,"CFB1"));
560
case 5: /* CIPHERTEXT = xxxx */
562
if (strncasecmp(ibuf, "CIPHERTEXT = ", 13) != 0)
564
printf("Missing KEY\n");
569
if(!strcmp(amode,"CFB1"))
570
len=bint2bin(ibuf+13,strlen(ibuf+13)-1,ciphertext);
572
len = hex2bin(ibuf+13,ciphertext);
575
printf("Invalid CIPHERTEXT\n");
580
PrintValue("CIPHERTEXT", ciphertext, len);
581
if (strcmp(atest, "Monte") == 0) /* Monte Carlo Test */
583
do_mct(amode, akeysz, numkeys, aKey, iVec,
584
dir, ciphertext, len, rfp);
589
ret = DESTest(&ctx, amode, akeysz, aKey, iVec,
590
dir, /* 0 = decrypt, 1 = encrypt */
591
plaintext, ciphertext, len);
592
OutputValue("PLAINTEXT",(unsigned char *)plaintext,len,rfp,
593
!strcmp(amode,"CFB1"));
603
printf("Missing terminator\n");
605
else if (strcmp(atest, "MCT") != 0)
606
{ /* MCT already added terminating nl */
620
/*--------------------------------------------------
621
Processes either a single file or
622
a set of files whose names are passed in a file.
623
A single file is specified as:
625
A set of files is specified as:
626
aes_test -d xxxxx.xxx
627
The default is: -d req.txt
628
--------------------------------------------------*/
629
int main(int argc, char **argv)
631
char *rqlist = "req.txt", *rspfile = NULL;
633
char fn[250] = "", rfn[256] = "";
634
int f_opt = 0, d_opt = 1;
637
if(!FIPS_mode_set(1))
645
if (strcasecmp(argv[1], "-d") == 0)
649
else if (strcasecmp(argv[1], "-f") == 0)
656
printf("Invalid parameter: %s\n", argv[1]);
661
printf("Missing parameter\n");
673
{ /* list of files (directory) */
674
if (!(fp = fopen(rqlist, "r")))
676
printf("Cannot open req list file\n");
679
while (fgets(fn, sizeof(fn), fp))
683
printf("Processing: %s\n", rfn);
684
if (proc_file(rfn, rspfile))
686
printf(">>> Processing failed for: %s <<<\n", rfn);
692
else /* single file */
695
printf("Processing: %s\n", fn);
696
if (proc_file(fn, rspfile))
698
printf(">>> Processing failed for: %s <<<\n", fn);