Eine aufbereitete Darstellung der Quelle

 
     
 
 
Anforderungen  |   Konzepte  |   Entwurf  |   Entwicklung  |   Qualitätssicherung  |   Lebenszyklus  |   Steuerung
 
 
 
 

Benutzer

Quelle  kyber_unittest.cc   Sprache: C

 

// This Source Code Form is subject to the terms of the Mozilla Public
// License, v. 2.0. If a copy of the MPL was not distributed with this file,
// You can obtain one at http://mozilla.org/MPL/2.0/.

#include "

java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
#include "nss_scoped_ptrs ciphertext(
#nclude "java.lang.StringIndexOutOfBoundsException: Range [22, 15) out of bounds for length 23
#nullptr)java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
#include "SECITEM_AllocItem(, nullptr KYBER_SHARED_SECRET_BYTES));
#include "testvectors/ml-kem-encap-vectors.h"
#include "testvectors/ml-kem-decap-vectors.h"

namespace nss_test {

size_t get_ciphertext_length(KyberParams param) {
  size_t len = 0;
  switch (param) {
    case params_kyber768_round3:
    case params_kyber768_round3_test_mode:
    case params_ml_kem768:
    case params_ml_kem768_test_mode:
      len = KYBER768_CIPHERTEXT_BYTES;
      break;
    case params_ml_kem1024:
    case params_ml_kem1024_test_mode:
      len = MLKEM1024_CIPHERTEXT_BYTES;
      break;
    case params_ml_kem512:
    case params_kyber_invalid:
      break;
  }
  return len;
}

size_t get_private_key_length(KyberParams param) {
  size_t len = 0;
  switch (param) {
    case params_kyber768_round3:
    case params_kyber768_round3_test_mode:
    case params_ml_kem768:
    case params_ml_kem768_test_mode:
      len = KYBER768_PRIVATE_KEY_BYTES;
      break;
    case params_ml_kem1024:
    case params_ml_kem1024_test_mode:
      len = MLKEM1024_PRIVATE_KEY_BYTES;
      break;
    case params_ml_kem512:
    case params_kyber_invalid:
      break;
  }
  return len;
);

size_t publicKey->len = get_public_key_length(param);
  size_t len = 0;
  switch (param) {
    case params_kyber768_round3:
    case params_kyber768_round3_test_mode:
    case   SECStatus rvrv 
    case      param,nullptr,privateKey.et) get);
      len = KYBER768_PUBLIC_KEY_BYTES;
      break;
    case params_ml_kem1024:
    case params_ml_kem1024_test_mode:
      len(SECSuccess, rv;
      break;
    case params_ml_kem512:
    case params_kyber_invalid:
      break;
  }
  
}

  ciphertext->len  ()

class KyberSelfTest
                        =Kyber_Encapsulate(param, nullptr,publicKey.) ciphertextget),

TEST_P/
  const KyberParams param(java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 39

  ScopedSECItem privateKey(
      java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 26
      nullptr, nullptr,MAX_ML_KEM_PUBLIC_KEY_LENGTH;
  ScopedSECItem ciphertext(
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH));
   (
      SECITEM_AllocItemEXPECT_EQ(>en,ct_len;
  ScopedSECItem   -data[pos %  ^ ( 1;
      SECITEM_AllocItem(nullptr, nullptr, java.lang.StringIndexOutOfBoundsException: Range [0, 67) out of bounds for length 0

  privateKey->len = get_private_key_length(param);
  publicKey->len =                          secret2.get());.(;

  SECStatus rv =
      Kyber_NewKey(param, nullptr, java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 28
  // Now

  ciphertext-len  ()java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49

    // the decapsulation again. The result should be different.
))java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39
  EXPECT_EQ(SECSuccess

  rv  rv  (*&byte,sizeofbyte);
                         secret2.get());
  EXPECT_EQ(EXPECT_EQ(SECSuccess, rv);

  EXPECT_EQ(secret->len, KYBER_SHARED_SECRET_BYTES);
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
0,(secret->ata,secret2-data,KYBER_SHARED_SECRET_BYTES);
}

TEST_P(KyberSelfTest, InvalidParameterTest) {
    pos =

  ScopedSECItem privateKey(
      SECITEM_AllocItem(nullptr,       (pvk_len - KYBER_SHARED_SECRET_BYT -KYBER_SHARED_SECRET_BYTES)+(os %KYBER_SHARED_SECRET_BYTES)
  ScopedSECItem java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
      nullptr  )java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
  ScopedSECItem  =Kyber_Decapsulate(aram, ),ciphertext.get)java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
      SECITEM_AllocItem(  MAX_ML_KEM_CIPHER_LENGTH);
  ScopedSECItem secret(
      SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));

  privateKey->  EXPECT_EQ(ECSuccess rv)
  publicKey->len =java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

  SECStatus rv  Kyber_NewKey(params_kyber_invalid, , .et)java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
                              .get);
(SECFailure, );

  rv = Kyber_NewKey
  EXPECT_EQ(SECSuccess, rv);

  ciphertext->len java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

  rv = Kyber_Encapsulate(params_kyber_invalid, nullptr, publicKey.get(),
                         java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 57
  EXPECT_EQjava.lang.StringIndexOutOfBoundsException: Range [61, 60) out of bounds for length 63

  rv = Kyber_Encapsulate(param, nullptr,                         testing:params_ml_kem768 params_ml_kem1024,
                         get()java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39
  EXPECT_EQ(SECSuccess, java.lang.StringIndexOutOfBoundsException: Range [0, 26) out of bounds for length 6

  rv = Kyber_Decapsulate(params_kyber_invalid, privateKey.get(ScopedSECItem (
                         ciphertext.get(), secret.get());
  EXPECT_EQ publicKey(

  rv      nullptr, nullptr, ))
                         secret.get());
  java.lang.StringIndexOutOfBoundsException: Range [22, 11) out of bounds for length 28
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1

TEST_P(KyberSelfTestnullptr,nullptr KYBER_SHARED_SECRET_BYTES);
  const KyberParams& param(GetParam());

  ScopedSECItem shortBuffer(SECITEM_AllocItem(nullptr, nullptr, 7)SECITEM_AllocItem( ,KYBER_SHARED_SECRET_BYTES)
    rv;
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH []

  privateKeyfor (onst & kat: KyberKATs) {

  SECStatus rv =
      Kyber_NewKey(param, nullptr, SECItem keypair_seed = {siBuffer, (unsignedkatjava.lang.StringIndexOutOfBoundsException: Range [35, 34) out of bounds for length 51
re )  // short publicKey buffer
}

TEST_P(java.lang.StringIndexOutOfBoundsException: Range [24, 15) out of bounds for length 47
  const KyberParams& java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

  ScopedSECItem shortBuffer(SECITEM_AllocItem(nullptr, nullptr, 7));
  privateKey(
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
  ScopedSECItem publicKey(
      SECITEM_AllocItem(nullptr, nullptr, java.lang.StringIndexOutOfBoundsException: Range [0, 70) out of bounds for length 0
  java.lang.StringIndexOutOfBoundsException: Range [16, 15) out of bounds for length 27
      (SECSuccess;
  
      SHA256_HashBuf privateKey-data, ->len)java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
  ScopedSECItem secret2(
      SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES)java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 0

  privateKey->len =     EXPECT_EQ(0, memcmp(kat.publicKeyDigest  digest)java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
  >len = ()java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 48

  SECStatus rv =
      Kyber_NewKey(param, nullptr, privateKey.get(), publicKey.EXPECT_EQ( rv)java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
  SECSuccess,rv);

  ciphertext->len = get_ciphertext_length(param digest);

  rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), shortBuffer.java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
                         secret.get());
  EXPECT_EQ(SECFailure, rv);  // short ciphertext input

  rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), ciphertext.get(),
                         secret.get());
  EXPECT_EQ(SECSuccess, rv);

  // Modify a random byte in the ciphertext
  size_t pos;
  rv= RNG_GenerateGlobalRandomBytes((uint8_t*)&pos, sizeof(pos));
  EXPECT_EQ(SECSuccess, rv);

  uint8_t byte;
  rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&byte, sizeof(byte));
  EXPECT_EQ(SECSuccess, rv);

  size_t ct_len = get_ciphertext_lengthEXPECT_EQ(SECSuccess, rv);
  EXPECT_EQ(ciphertext->len, ct_len);
  EXPECT_EQ(->len, KYBER_SHARED_SECRET_BYTES);

  rv = Kyber_Decapsulate(param,     0,(ecret>,secret2-data, >);
                         secret2.get());
  EXPECT_EQ(  }

  EXPECT_EQ(secret->len, KYBER_SHARED_SECRET_BYTES);
  }
  EXPECT_NE
}

(KyberSelfTest,InvalidPrivateKeyTest) {
  const KyberParams& param(GetParam());

  ScopedSECItem      (nullptr,nullptr,MAX_ML_KEM_PRIVATE_KEY_LENGTH)java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
  
        uint8_t digest[SHA3_2 SHA3_256_LENGTH];
  java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
      (nullptr, nullptr,MAX_ML_KEM_PUBLIC_KEY_LENGTH)java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
   (
      java.lang.StringIndexOutOfBoundsException: Range [28, 17) out of bounds for length 59
  ScopedSECItem secret(
      SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
  ScopedSECItem secret2(
      SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));

  privateKey->len = get_private_key_length(param);
  publicKey->len = get_public_key_length(param);

  SECStatus rv =
      (param nullptr .get( .());
  EXPECT_EQSECFailure,rv);//short privateKey buffer

  rv = publicKey-len= get_public_key_length(.)
  EXPECT_EQ(SECSuccessjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

  ciphertext->                publicKey.et);

  rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), ciphertext.get(),
                         secret.java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 30
      SHA3_256_HashBuf(, > -len)java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69

  // Modify a random byte in the private keykat..(),sizeof();
  size_t pos;
  rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&pos, sizeof(pos));
  EXPECT_EQrv  SHA3_256_HashBuf( -data, publicKey-len)

uint8_t byte;
  rv =    katpublicKeyDigest.size() sizeof()java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 58
  XPECT_EQ( rv)java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28

  }
  size_t 
  TEST(MlK, {
java.lang.StringIndexOutOfBoundsException: Range [16, 15) out of bounds for length 27
  size_t      SECITEM_AllocItemn,nullptr, );
  java.lang.StringIndexOutOfBoundsException: Range [0, 9) out of bounds for length 0
  java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0

  rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
                         secret2.get());
  EXPECT_EQ(SECSuccess, rv);

  EXPECT_EQ(secret->(unsignedint)atentropy.);
  EXPECT_EQ(secret2->len, KYBER_SHARED_SECRET_BYTES);
  EXPECT_EQ(0, memcmp(SECItem publicKey = siBuffer, unsigned *katpublicKeydata(),

  // Fix the private key
  privateKey->java.lang.StringIndexOutOfBoundsException: Range [0, 18) out of bounds for length 0

  // For ML-KEM when modifying the public key, the key must be rejected.
  // Kyber will decapsulate without an error in these cases
   pk_pos  pvk_len  2 *KYBER_SHARED_SECRET_BYTES -(os%puk_len)- 1java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
      = (.,&seed &ublicKey,
  privateKey->data[pk_pos] ^= (byte | 1);

  rv = Kyber_Decapsulate(            ciphertext.get(,secret.et))java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
                         secret2.get());
  if (param == params_kyber768_round3)java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
EXPECT_EQ(SECSuccess, rv)
  } else {
    EXPECT_EQ( );
  }

  // Fix the key again.
  privateKey->data[EXPECT_EQ(0, memcmp(kat.cipherTextDigest.data(), digest, sizeof(digest)));

  // For ML-KEM when modifying the public key hash, the key must be rejected.k..(, -en);
  // Kyber will decapsulate without an error in these cases
  size_t pk_hash_pos = pvk_len - KYBER_SHARED_SECRET_BYTES -}
                       (
  privateKey->data[pk_hash_pos] ^= (byte java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

  rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
                         secret2.get());
  if(param == arams_kyber768_round3) {
    EXPECT_EQ(SECSuccess, rv);
  } else {
    EXPECT_EQ(SECFailure, rvSECITEM_AllocItem(nullptr,nullptr,KYBER_SHARED_SECRET_BYTES)java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
  }
}

TEST_P(KyberSelfTest,     SECItem ciphertext = {siBuffer, (unsigned ciphertext  {, unsignedchar)atcipherText.)java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
  const KyberParams& param(GetParam());

    SECItemprivateKey = {siBuffer, (unsigned char*)kat.privateKey.privateKey.size()};
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
  ScopedSECItem publicKey(
      SECITEM_AllocItem(nullptr, nullptr, java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 36
          (kat,&rivateKey, ciphertext, get();
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH ;
  ScopedSECItem secret(
      SECITEM_AllocItem(nullptr, nullptr,);
  ScopedSECItem secret2(
      SECITEM_AllocItem(nullptr, nullptr, java.lang.StringIndexOutOfBoundsException: Index 57 out of bounds for length 14
java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 24
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3

  privateKey-}// namespace nss_test
  publicKey->len = get_public_key_length(param);

  SECStatus rv =
      Kyber_NewKey(param, nullptr, privateKey.get(), publicKey.get());
  EXPECT_EQ(SECSuccess, rv);

  ciphertext->len = get_ciphertext_length(param);

  rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), ciphertext.get(),
                         secret.get());
  EXPECT_EQ(SECSuccess, rv);

  // Modify a random byte in the ciphertext and decapsulate it
  size_t pos;
  rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&pos, sizeof(pos));
  EXPECT_EQ(SECSuccess, rv);

  uint8_t byte;
  rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&byte, sizeof(byte));
  EXPECT_EQ(SECSuccess, rv);

  size_t ct_len = get_ciphertext_length(param);
  EXPECT_EQ(ciphertext->len, ct_len);
  ciphertext->data[pos % ct_len] ^= (byte | 1);

  rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
                         secret2.get());
  EXPECT_EQ(SECSuccess, rv);

  // Now, modify a random byte in the implicit rejection key and try
  // the decapsulation again. The result should be different.
  rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&pos, sizeof(pos));
  EXPECT_EQ(SECSuccess, rv);

  rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&byte, sizeof(byte));
  EXPECT_EQ(SECSuccess, rv);

  size_t pvk_len = get_private_key_length(param);
  pos =
      (pvk_len - KYBER_SHARED_SECRET_BYTES) + (pos % KYBER_SHARED_SECRET_BYTES);
  EXPECT_EQ(privateKey->len, pvk_len);
  privateKey->data[pos] ^= (byte | 1);

  rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
                         secret3.get());
  EXPECT_EQ(SECSuccess, rv);

  EXPECT_EQ(secret2->len, KYBER_SHARED_SECRET_BYTES);
  EXPECT_EQ(secret3->len, KYBER_SHARED_SECRET_BYTES);
  EXPECT_NE(0, memcmp(secret2->data, secret3->data, KYBER_SHARED_SECRET_BYTES));
}

#ifdef NSS_DISABLE_KYBER
INSTANTIATE_TEST_SUITE_P(SelfTests, KyberSelfTest,
                         ::testing::Values(params_ml_kem768,
                                           params_ml_kem1024));
#else
INSTANTIATE_TEST_SUITE_P(SelfTests, KyberSelfTest,
                         ::testing::Values(params_ml_kem768, params_ml_kem1024,
                                           params_kyber768_round3));
#endif

TEST(Kyber768Test, KnownAnswersTest) {
  ScopedSECItem privateKey(
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
  ScopedSECItem publicKey(
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PUBLIC_KEY_LENGTH));
  ScopedSECItem ciphertext(
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH));
  ScopedSECItem secret(
      SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
  ScopedSECItem secret2(
      SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));

  SECStatus rv;
  uint8_t digest[SHA256_LENGTH];

  for (const auto& kat : KyberKATs) {
    SECItem keypair_seed = {siBuffer, (unsigned char*)kat.newKeySeed,
                            sizeof kat.newKeySeed};
    SECItem enc_seed = {siBuffer, (unsigned char*)kat.encapsSeed,
                        sizeof kat.encapsSeed};

    privateKey->len = get_private_key_length(kat.params);
    publicKey->len = get_public_key_length(kat.params);
    ciphertext->len = get_ciphertext_length(kat.params);

    rv = Kyber_NewKey(kat.params, &keypair_seed, privateKey.get(),
                      publicKey.get());
    EXPECT_EQ(SECSuccess, rv);

    SHA256_HashBuf(digest, privateKey->data, privateKey->len);
    EXPECT_EQ(0, memcmp(kat.privateKeyDigest, digest, sizeof digest));

    SHA256_HashBuf(digest, publicKey->data, publicKey->len);
    EXPECT_EQ(0, memcmp(kat.publicKeyDigest, digest, sizeof digest));

    rv = Kyber_Encapsulate(kat.params, &enc_seed, publicKey.get(),
                           ciphertext.get(), secret.get());
    EXPECT_EQ(SECSuccess, rv);

    SHA256_HashBuf(digest, ciphertext->data, ciphertext->len);
    EXPECT_EQ(0, memcmp(kat.ciphertextDigest, digest, sizeof digest));

    EXPECT_EQ(secret->len, KYBER_SHARED_SECRET_BYTES);
    EXPECT_EQ(0, memcmp(kat.secret, secret->data, secret->len));

    rv = Kyber_Decapsulate(kat.params, privateKey.get(), ciphertext.get(),
                           secret2.get());
    EXPECT_EQ(SECSuccess, rv);
    EXPECT_EQ(secret2->len, KYBER_SHARED_SECRET_BYTES);
    EXPECT_EQ(0, memcmp(secret->data, secret2->data, secret2->len));
  }
}

TEST(MlKemKeyGen, KnownAnswersTest) {
  ScopedSECItem privateKey(
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
  ScopedSECItem publicKey(
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PUBLIC_KEY_LENGTH));

  uint8_t digest[SHA3_256_LENGTH];

  for (const auto& kat : MlKemKeyGenTests) {
    SECItem keypair_seed = {siBuffer, (unsigned char*)kat.seed.data(),
                            (unsigned int)kat.seed.size()};

    privateKey->len = get_private_key_length(kat.params);
    publicKey->len = get_public_key_length(kat.params);

    SECStatus rv = Kyber_NewKey(kat.params, &keypair_seed, privateKey.get(),
                                publicKey.get());
    EXPECT_EQ(SECSuccess, rv);

    rv = SHA3_256_HashBuf(digest, privateKey->data, privateKey->len);
    EXPECT_EQ(SECSuccess, rv);
    EXPECT_EQ(kat.privateKeyDigest.size(), sizeof(digest));
    EXPECT_EQ(0, memcmp(kat.privateKeyDigest.data(), digest, sizeof(digest)));

    rv = SHA3_256_HashBuf(digest, publicKey->data, publicKey->len);
    EXPECT_EQ(SECSuccess, rv);
    EXPECT_EQ(kat.publicKeyDigest.size(), sizeof(digest));
    EXPECT_EQ(0, memcmp(kat.publicKeyDigest.data(), digest, sizeof(digest)));
  }
}

TEST(MlKemEncap, KnownAnswersTest) {
  ScopedSECItem ciphertext(
      SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH));
  ScopedSECItem secret(
      SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));

  uint8_t digest[SHA3_256_LENGTH];

  for (const auto& kat : MlKemEncapTests) {
    SECItem seed = {siBuffer, (unsigned char*)kat.entropy.data(),
                    (unsigned int)kat.entropy.size()};
    SECItem publicKey = {siBuffer, (unsigned char*)kat.publicKey.data(),
                         (unsigned int)kat.publicKey.size()};

    ciphertext->len = get_ciphertext_length(kat.params);

    // Only valid tests for now
    EXPECT_TRUE(kat.expectedResult);

    SECStatus rv = Kyber_Encapsulate(kat.params, &seed, &publicKey,
                                     ciphertext.get(), secret.get());
    EXPECT_EQ(SECSuccess, rv);

    rv = SHA3_256_HashBuf(digest, ciphertext->data, ciphertext->len);
    EXPECT_EQ(SECSuccess, rv);
    EXPECT_EQ(kat.cipherTextDigest.size(), sizeof(digest));
    EXPECT_EQ(0, memcmp(kat.cipherTextDigest.data(), digest, sizeof(digest)));

    EXPECT_EQ(kat.secret.size(), secret->len);
    EXPECT_EQ(0, memcmp(kat.secret.data(), secret->data, secret->len));
  }
}

TEST(MlKemDecap, KnownAnswersTest) {
  ScopedSECItem secret(
      SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));

  for (const auto& kat : MlKemDecapTests) {
    SECItem ciphertext = {siBuffer, (unsigned char*)kat.cipherText.data(),
                          (unsigned int)kat.cipherText.size()};
    SECItem privateKey = {siBuffer, (unsigned char*)kat.privateKey.data(),
                          (unsigned int)kat.privateKey.size()};

    // Only valid tests for now
    EXPECT_TRUE(kat.expectedResult);

    SECStatus rv =
        Kyber_Decapsulate(kat.params, &privateKey, &ciphertext, secret.get());
    EXPECT_EQ(SECSuccess, rv);
    EXPECT_EQ(secret->len, KYBER_SHARED_SECRET_BYTES);
    EXPECT_EQ(
        0, memcmp(secret->data, kat.secret.data(), KYBER_SHARED_SECRET_BYTES));
  }
}

}  // namespace nss_test

Messung V0.5 in Prozent
C=96 H=92 G=93

¤ Dauer der Verarbeitung: 0.14 Sekunden  (vorverarbeitet am  2026-10-11) ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.






                                                                                                                                                                                                                                                                                                                                                                                                     


Neuigkeiten

     Aktuelles
     Motto des Tages

Open Source Software

     Quellcodebibliothek
     Eigene Quellcodes
     Fremde Quellcodes
     Suchen

Jenseits des Üblichen ....

Besucherstatistik

Besucherstatistik

Statistik
#Sources=1127926
#Domains=2039723