You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

hmac_drbg_test.c 59KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385
  1. /*
  2. * Copyright (C) 2012 Michael Brown <mbrown@fensystems.co.uk>.
  3. *
  4. * This program is free software; you can redistribute it and/or
  5. * modify it under the terms of the GNU General Public License as
  6. * published by the Free Software Foundation; either version 2 of the
  7. * License, or any later version.
  8. *
  9. * This program is distributed in the hope that it will be useful, but
  10. * WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  12. * General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public License
  15. * along with this program; if not, write to the Free Software
  16. * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
  17. */
  18. FILE_LICENCE ( GPL2_OR_LATER );
  19. /** @file
  20. *
  21. * HMAC_DRBG tests
  22. *
  23. * These test vectors are provided by NIST as part of the
  24. * Cryptographic Toolkit Examples, downloadable from:
  25. *
  26. * http://csrc.nist.gov/groups/ST/toolkit/documents/Examples/HMAC_DRBG.pdf
  27. *
  28. */
  29. /* Forcibly enable assertions */
  30. #undef NDEBUG
  31. #include <assert.h>
  32. #include <string.h>
  33. #include <ipxe/hmac_drbg.h>
  34. #include <ipxe/sha1.h>
  35. #include <ipxe/sha256.h>
  36. #include <ipxe/test.h>
  37. /** Define inline expected data */
  38. #define EXPECT(...) { __VA_ARGS__ }
  39. /** An HMAC_DRBG instantiation test */
  40. struct hmac_drbg_test_instantiate {
  41. /** Underlying hash algorithm */
  42. struct digest_algorithm *hash;
  43. /** Output block length */
  44. size_t out_len;
  45. /** Entropy */
  46. const void *entropy;
  47. /** Length of entropy */
  48. size_t entropy_len;
  49. /** Nonce */
  50. const void *nonce;
  51. /** Length of nonce */
  52. size_t nonce_len;
  53. /** Personalisation string */
  54. const void *personal;
  55. /** Length of personalisation string */
  56. size_t personal_len;
  57. /** Expected key */
  58. const void *expected_key;
  59. /** Length of expected key */
  60. size_t expected_key_len;
  61. /** Expected value */
  62. const void *expected_value;
  63. /** Length of expected value */
  64. size_t expected_value_len;
  65. };
  66. /**
  67. * Define an HMAC_DRBG instantiation test
  68. *
  69. * @v name Test name
  70. * @v hmac_drbg HMAC_DRBG algorithm
  71. * @v entropy_array Entropy input
  72. * @v nonce_array Nonce
  73. * @v personal_array Personalisation string
  74. * @v key Expected key
  75. * @v value Expected value
  76. * @ret test Instantiation test
  77. */
  78. #define HMAC_DRBG_TEST_INSTANTIATE( name, hmac_drbg, entropy_array, \
  79. nonce_array, personal_array, \
  80. key, value ) \
  81. static const uint8_t name ## _key [] = key; \
  82. static const uint8_t name ## _value [] = value; \
  83. static struct hmac_drbg_test_instantiate name = { \
  84. .hash = HMAC_DRBG_HASH ( hmac_drbg ), \
  85. .out_len = HMAC_DRBG_OUTLEN_BYTES ( hmac_drbg ), \
  86. .entropy = entropy_array, \
  87. .entropy_len = sizeof ( entropy_array ), \
  88. .nonce = nonce_array, \
  89. .nonce_len = sizeof ( nonce_array ), \
  90. .personal = personal_array, \
  91. .personal_len = sizeof ( personal_array ), \
  92. .expected_key = name ## _key, \
  93. .expected_key_len = sizeof ( name ## _key ), \
  94. .expected_value = name ## _value, \
  95. .expected_value_len = sizeof ( name ## _value ), \
  96. }
  97. /**
  98. * Report instantiation test result
  99. *
  100. * @v state HMAC_DRBG internal state
  101. * @v test Instantiation test
  102. */
  103. #define instantiate_ok( state, test ) do { \
  104. struct { \
  105. uint8_t entropy[(test)->entropy_len]; \
  106. uint8_t nonce[(test)->nonce_len]; \
  107. } __attribute__ (( packed )) entropy_nonce; \
  108. \
  109. assert ( (test)->expected_key_len == (test)->out_len ); \
  110. assert ( (test)->expected_value_len == (test)->out_len ); \
  111. memcpy ( entropy_nonce.entropy, (test)->entropy, \
  112. sizeof ( entropy_nonce.entropy ) ); \
  113. memcpy ( entropy_nonce.nonce, (test)->nonce, \
  114. sizeof ( entropy_nonce.nonce ) ); \
  115. hmac_drbg_instantiate ( (test)->hash, (state), &entropy_nonce, \
  116. sizeof ( entropy_nonce ), \
  117. (test)->personal, \
  118. (test)->personal_len ); \
  119. ok ( memcmp ( (state)->key, (test)->expected_key, \
  120. (test)->expected_key_len ) == 0 ); \
  121. ok ( memcmp ( (state)->value, (test)->expected_value, \
  122. (test)->expected_value_len ) == 0 ); \
  123. } while ( 0 )
  124. /** An HMAC_DRBG reseed test */
  125. struct hmac_drbg_test_reseed {
  126. /** Underlying hash algorithm */
  127. struct digest_algorithm *hash;
  128. /** Output block length */
  129. size_t out_len;
  130. /** Entropy */
  131. const void *entropy;
  132. /** Length of entropy */
  133. size_t entropy_len;
  134. /** Additional input */
  135. const void *additional;
  136. /** Length of additional_input */
  137. size_t additional_len;
  138. /** Expected key */
  139. const void *expected_key;
  140. /** Length of expected key */
  141. size_t expected_key_len;
  142. /** Expected value */
  143. const void *expected_value;
  144. /** Length of expected value */
  145. size_t expected_value_len;
  146. };
  147. /**
  148. * Define an HMAC_DRBG reseed test
  149. *
  150. * @v name Test name
  151. * @v hmac_drbg HMAC_DRBG algorithm
  152. * @v entropy_array Entropy input
  153. * @v additional_array Additional input
  154. * @v key Expected key
  155. * @v value Expected value
  156. * @ret test Reseed test
  157. */
  158. #define HMAC_DRBG_TEST_RESEED( name, hmac_drbg, entropy_array, \
  159. additional_array, key, value ) \
  160. static const uint8_t name ## _key [] = key; \
  161. static const uint8_t name ## _value [] = value; \
  162. static struct hmac_drbg_test_reseed name = { \
  163. .hash = HMAC_DRBG_HASH ( hmac_drbg ), \
  164. .out_len = HMAC_DRBG_OUTLEN_BYTES ( hmac_drbg ), \
  165. .entropy = entropy_array, \
  166. .entropy_len = sizeof ( entropy_array ), \
  167. .additional = additional_array, \
  168. .additional_len = sizeof ( additional_array ), \
  169. .expected_key = name ## _key, \
  170. .expected_key_len = sizeof ( name ## _key ), \
  171. .expected_value = name ## _value, \
  172. .expected_value_len = sizeof ( name ## _value ), \
  173. }
  174. /**
  175. * Report reseed test result
  176. *
  177. * @v state HMAC_DRBG internal state
  178. * @v test Reseed test
  179. */
  180. #define reseed_ok( state, test ) do { \
  181. assert ( (test)->expected_key_len == (test)->out_len ); \
  182. assert ( (test)->expected_value_len == (test)->out_len ); \
  183. hmac_drbg_reseed ( (test)->hash, (state), (test)->entropy, \
  184. (test)->entropy_len, (test)->additional, \
  185. (test)->additional_len ); \
  186. ok ( memcmp ( (state)->key, (test)->expected_key, \
  187. (test)->expected_key_len ) == 0 ); \
  188. ok ( memcmp ( (state)->value, (test)->expected_value, \
  189. (test)->expected_value_len ) == 0 ); \
  190. } while ( 0 )
  191. /** An HMAC_DRBG generation test */
  192. struct hmac_drbg_test_generate {
  193. /** Underlying hash algorithm */
  194. struct digest_algorithm *hash;
  195. /** Output block length */
  196. size_t out_len;
  197. /** Additional input */
  198. const void *additional;
  199. /** Length of additional_input */
  200. size_t additional_len;
  201. /** Expected key */
  202. const void *expected_key;
  203. /** Length of expected key */
  204. size_t expected_key_len;
  205. /** Expected value */
  206. const void *expected_value;
  207. /** Length of expected value */
  208. size_t expected_value_len;
  209. /** Expected pseudorandom data */
  210. const void *expected_data;
  211. /** Length of data */
  212. size_t expected_data_len;
  213. };
  214. /**
  215. * Define an HMAC_DRBG generation test
  216. *
  217. * @v name Test name
  218. * @v hmac_drbg HMAC_DRBG algorithm
  219. * @v additional_array Additional input
  220. * @v key Expected key
  221. * @v value Expected value
  222. * @v data Expected pseudorandom data
  223. * @ret test Generation test
  224. */
  225. #define HMAC_DRBG_TEST_GENERATE( name, hmac_drbg, additional_array, \
  226. key, value, data ) \
  227. static const uint8_t name ## _key [] = key; \
  228. static const uint8_t name ## _value [] = value; \
  229. static const uint8_t name ## _data [] = data; \
  230. static struct hmac_drbg_test_generate name = { \
  231. .hash = HMAC_DRBG_HASH ( hmac_drbg ), \
  232. .out_len = HMAC_DRBG_OUTLEN_BYTES ( hmac_drbg ), \
  233. .additional = additional_array, \
  234. .additional_len = sizeof ( additional_array ), \
  235. .expected_key = name ## _key, \
  236. .expected_key_len = sizeof ( name ## _key ), \
  237. .expected_value = name ## _value, \
  238. .expected_value_len = sizeof ( name ## _value ), \
  239. .expected_data = name ## _data, \
  240. .expected_data_len = sizeof ( name ## _data ), \
  241. }
  242. /**
  243. * Report generation test result
  244. *
  245. * @v state HMAC_DRBG internal state
  246. * @v test Generation test
  247. */
  248. #define generate_ok( state, test ) do { \
  249. uint8_t data[ (test)->expected_data_len ]; \
  250. int rc; \
  251. \
  252. assert ( (test)->expected_key_len == (test)->out_len ); \
  253. assert ( (test)->expected_value_len == (test)->out_len ); \
  254. rc = hmac_drbg_generate ( (test)->hash, (state), \
  255. (test)->additional, \
  256. (test)->additional_len, \
  257. data, sizeof ( data ) ); \
  258. ok ( rc == 0 ); \
  259. ok ( memcmp ( (state)->key, (test)->expected_key, \
  260. (test)->expected_key_len ) == 0 ); \
  261. ok ( memcmp ( (state)->value, (test)->expected_value, \
  262. (test)->expected_value_len ) == 0 ); \
  263. ok ( memcmp ( data, (test)->expected_data, \
  264. (test)->expected_data_len ) == 0 ); \
  265. } while ( 0 )
  266. /** An HMAC_DRBG generation failure test */
  267. struct hmac_drbg_test_generate_fail {
  268. /** Underlying hash algorithm */
  269. struct digest_algorithm *hash;
  270. /** Additional input */
  271. const void *additional;
  272. /** Length of additional_input */
  273. size_t additional_len;
  274. /** Length of requested data */
  275. size_t requested_len;
  276. };
  277. /**
  278. * Define an HMAC_DRBG generation failure test
  279. *
  280. * @v name Test name
  281. * @v hmac_drbg HMAC_DRBG algorithm
  282. * @v additional_array Additional input
  283. * @ret test Generation failure test
  284. */
  285. #define HMAC_DRBG_TEST_GENERATE_FAIL( name, hmac_drbg, \
  286. additional_array, len ) \
  287. static struct hmac_drbg_test_generate_fail name = { \
  288. .hash = HMAC_DRBG_HASH ( hmac_drbg ), \
  289. .additional = additional_array, \
  290. .additional_len = sizeof ( additional_array ), \
  291. .requested_len = len, \
  292. }
  293. /**
  294. * Report generation failure test result
  295. *
  296. * @v state HMAC_DRBG internal state
  297. * @v test Generation failure test
  298. */
  299. #define generate_fail_ok( state, test ) do { \
  300. uint8_t data[ (test)->requested_len ]; \
  301. int rc; \
  302. \
  303. rc = hmac_drbg_generate ( (test)->hash, (state), \
  304. (test)->additional, \
  305. (test)->additional_len, data, \
  306. sizeof ( data ) ); \
  307. ok ( rc != 0 ); \
  308. } while ( 0 )
  309. /** "EntropyInput" */
  310. static const uint8_t entropy_input[] = {
  311. 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b,
  312. 0x0c, 0x0d, 0x0e, 0x0f, 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,
  313. 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f, 0x20, 0x21, 0x22, 0x23,
  314. 0x24, 0x25, 0x26, 0x27, 0x28, 0x29, 0x2a, 0x2b, 0x2c, 0x2d, 0x2e, 0x2f,
  315. 0x30, 0x31, 0x32, 0x33, 0x34, 0x35, 0x36
  316. };
  317. /** "Nonce" for SHA-1 */
  318. static const uint8_t nonce_sha1[] = {
  319. 0x20, 0x21, 0x22, 0x23, 0x24
  320. };
  321. /** "Nonce" for SHA-256 */
  322. static const uint8_t nonce_sha256[] = {
  323. 0x20, 0x21, 0x22, 0x23, 0x24, 0x25, 0x26, 0x27
  324. };
  325. /** "EntropyInput1 (for Reseed1) */
  326. static const uint8_t entropy_input_1[] = {
  327. 0x80, 0x81, 0x82, 0x83, 0x84, 0x85, 0x86, 0x87, 0x88, 0x89, 0x8a, 0x8b,
  328. 0x8c, 0x8d, 0x8e, 0x8f, 0x90, 0x91, 0x92, 0x93, 0x94, 0x95, 0x96, 0x97,
  329. 0x98, 0x99, 0x9a, 0x9b, 0x9c, 0x9d, 0x9e, 0x9f, 0xa0, 0xa1, 0xa2, 0xa3,
  330. 0xa4, 0xa5, 0xa6, 0xa7, 0xa8, 0xa9, 0xaa, 0xab, 0xac, 0xad, 0xae, 0xaf,
  331. 0xb0, 0xb1, 0xb2, 0xb3, 0xb4, 0xb5, 0xb6
  332. };
  333. /** "EntropyInput2 (for Reseed2) */
  334. static const uint8_t entropy_input_2[] = {
  335. 0xc0, 0xc1, 0xc2, 0xc3, 0xc4, 0xc5, 0xc6, 0xc7, 0xc8, 0xc9, 0xca, 0xcb,
  336. 0xcc, 0xcd, 0xce, 0xcf, 0xd0, 0xd1, 0xd2, 0xd3, 0xd4, 0xd5, 0xd6, 0xd7,
  337. 0xd8, 0xd9, 0xda, 0xdb, 0xdc, 0xdd, 0xde, 0xdf, 0xe0, 0xe1, 0xe2, 0xe3,
  338. 0xe4, 0xe5, 0xe6, 0xe7, 0xe8, 0xe9, 0xea, 0xeb, 0xec, 0xed, 0xee, 0xef,
  339. 0xf0, 0xf1, 0xf2, 0xf3, 0xf4, 0xf5, 0xf6
  340. };
  341. /** "PersonalizationString = <empty>" */
  342. static const uint8_t personalisation_string_empty[] = {};
  343. /** "PersonalizationString" */
  344. static const uint8_t personalisation_string[] = {
  345. 0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47, 0x48, 0x49, 0x4a, 0x4b,
  346. 0x4c, 0x4d, 0x4e, 0x4f, 0x50, 0x51, 0x52, 0x53, 0x54, 0x55, 0x56, 0x57,
  347. 0x58, 0x59, 0x5a, 0x5b, 0x5c, 0x5d, 0x5e, 0x5f, 0x60, 0x61, 0x62, 0x63,
  348. 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b, 0x6c, 0x6d, 0x6e, 0x6f,
  349. 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76
  350. };
  351. /** "AdditionalInput = <empty>" */
  352. static const uint8_t additional_input_empty[] = {};
  353. /** "AdditionalInput1" */
  354. static const uint8_t additional_input_1[] = {
  355. 0x60, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67, 0x68, 0x69, 0x6a, 0x6b,
  356. 0x6c, 0x6d, 0x6e, 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77,
  357. 0x78, 0x79, 0x7a, 0x7b, 0x7c, 0x7d, 0x7e, 0x7f, 0x80, 0x81, 0x82, 0x83,
  358. 0x84, 0x85, 0x86, 0x87, 0x88, 0x89, 0x8a, 0x8b, 0x8c, 0x8d, 0x8e, 0x8f,
  359. 0x90, 0x91, 0x92, 0x93, 0x94, 0x95, 0x96
  360. };
  361. /** "AdditionalInput2" */
  362. static const uint8_t additional_input_2[] = {
  363. 0xa0, 0xa1, 0xa2, 0xa3, 0xa4, 0xa5, 0xa6, 0xa7, 0xa8, 0xa9, 0xaa, 0xab,
  364. 0xac, 0xad, 0xae, 0xaf, 0xb0, 0xb1, 0xb2, 0xb3, 0xb4, 0xb5, 0xb6, 0xb7,
  365. 0xb8, 0xb9, 0xba, 0xbb, 0xbc, 0xbd, 0xbe, 0xbf, 0xc0, 0xc1, 0xc2, 0xc3,
  366. 0xc4, 0xc5, 0xc6, 0xc7, 0xc8, 0xc9, 0xca, 0xcb, 0xcc, 0xcd, 0xce, 0xcf,
  367. 0xd0, 0xd1, 0xd2, 0xd3, 0xd4, 0xd5, 0xd6
  368. };
  369. /** SHA-1 Test 1 : Instantiation */
  370. HMAC_DRBG_TEST_INSTANTIATE ( sha1_instantiate_1, HMAC_DRBG_SHA1,
  371. entropy_input, nonce_sha1, personalisation_string_empty,
  372. EXPECT ( 0xab, 0x16, 0x0d, 0xd2, 0x1c, 0x30, 0x98, 0x0c, 0xa3, 0xca,
  373. 0x5a, 0x9c, 0x77, 0xb7, 0xbd, 0xf0, 0x50, 0xe6, 0x4e, 0xe9 ),
  374. EXPECT ( 0x61, 0x44, 0x99, 0xea, 0x98, 0x0c, 0xfb, 0x3d, 0xaa, 0x2c,
  375. 0xa8, 0x6d, 0x65, 0xa4, 0x6b, 0xf4, 0x48, 0x8d, 0x8c, 0xc5 ) );
  376. /** SHA-1 Test 1.1 : First call to Generate */
  377. HMAC_DRBG_TEST_GENERATE ( sha1_generate_1_1, HMAC_DRBG_SHA1,
  378. additional_input_empty,
  379. EXPECT ( 0x7b, 0xb1, 0x80, 0x28, 0xe0, 0x1d, 0x03, 0x42, 0xdf, 0x4f,
  380. 0x54, 0xda, 0x51, 0x22, 0xfa, 0x5f, 0x2c, 0x3a, 0x05, 0xe4 ),
  381. EXPECT ( 0x2f, 0x89, 0x4f, 0x28, 0xcc, 0x2f, 0x53, 0x82, 0x96, 0x40,
  382. 0x64, 0x3a, 0xd1, 0x7b, 0x84, 0xb0, 0xcd, 0x3c, 0x79, 0x79 ),
  383. EXPECT ( 0x5a, 0x7d, 0x3b, 0x44, 0x9f, 0x48, 0x1c, 0xb3, 0x8d, 0xf7,
  384. 0x9a, 0xd2, 0xb1, 0xfc, 0xc0, 0x1e, 0x57, 0xf8, 0x13, 0x5e,
  385. 0x8c, 0x0b, 0x22, 0xcd, 0x06, 0x30, 0xbf, 0xb0, 0x12, 0x7f,
  386. 0xb5, 0x40, 0x8c, 0x8e, 0xfc, 0x17, 0xa9, 0x29, 0x89, 0x6e ) );
  387. /** SHA-1 Test 1.2 : Second call to Generate */
  388. HMAC_DRBG_TEST_GENERATE ( sha1_generate_1_2, HMAC_DRBG_SHA1,
  389. additional_input_empty,
  390. EXPECT ( 0x3d, 0x4d, 0x73, 0x77, 0xe9, 0x17, 0x2a, 0xaf, 0xa7, 0x76,
  391. 0xb0, 0xdd, 0xcb, 0x89, 0x42, 0x00, 0x4a, 0x44, 0xb7, 0xfd ),
  392. EXPECT ( 0x1a, 0x26, 0xbd, 0x9b, 0xfc, 0x97, 0x44, 0xbd, 0x29, 0xf6,
  393. 0xae, 0xbe, 0x24, 0x37, 0xe2, 0x09, 0xf1, 0xf7, 0x16, 0x25 ),
  394. EXPECT ( 0x82, 0xcf, 0x77, 0x2e, 0xc3, 0xe8, 0x4b, 0x00, 0xfc, 0x74,
  395. 0xf5, 0xdf, 0x10, 0x4e, 0xfb, 0xfb, 0x24, 0x28, 0x55, 0x4e,
  396. 0x9c, 0xe3, 0x67, 0xd0, 0x3a, 0xea, 0xde, 0x37, 0x82, 0x7f,
  397. 0xa8, 0xe9, 0xcb, 0x6a, 0x08, 0x19, 0x61, 0x15, 0xd9, 0x48 ) );
  398. /** SHA-1 Test 2 : Instantiation */
  399. #define sha1_instantiate_2 sha1_instantiate_1
  400. /** SHA-1 Test 2.1 : First call to Generate */
  401. HMAC_DRBG_TEST_GENERATE ( sha1_generate_2_1, HMAC_DRBG_SHA1,
  402. additional_input_1,
  403. EXPECT ( 0x3a, 0x06, 0x2e, 0x6b, 0x79, 0xfe, 0x70, 0xdb, 0xff, 0xeb,
  404. 0x3a, 0x2b, 0x6b, 0xe8, 0x03, 0x23, 0xf7, 0xd6, 0x74, 0xc5 ),
  405. EXPECT ( 0xbd, 0x36, 0x31, 0x28, 0xbf, 0x58, 0x0d, 0x7a, 0x54, 0x42,
  406. 0x9d, 0xdd, 0x58, 0xe8, 0x19, 0x3b, 0x98, 0x43, 0xbd, 0x2b ),
  407. EXPECT ( 0xc7, 0xaa, 0xac, 0x58, 0x3c, 0x6e, 0xf6, 0x30, 0x07, 0x14,
  408. 0xc2, 0xcc, 0x5d, 0x06, 0xc1, 0x48, 0xcf, 0xfb, 0x40, 0x44,
  409. 0x9a, 0xd0, 0xbb, 0x26, 0xfa, 0xc0, 0x49, 0x7b, 0x5c, 0x57,
  410. 0xe1, 0x61, 0xe3, 0x66, 0x81, 0xbc, 0xc9, 0x30, 0xce, 0x80 ) );
  411. /** SHA-1 Test 2.2 : Second call to Generate */
  412. HMAC_DRBG_TEST_GENERATE ( sha1_generate_2_2, HMAC_DRBG_SHA1,
  413. additional_input_2,
  414. EXPECT ( 0x8a, 0xd7, 0xe3, 0x47, 0x72, 0xb5, 0xfc, 0x7c, 0x3b, 0x3b,
  415. 0x27, 0x62, 0x4f, 0x0b, 0x91, 0x77, 0x6a, 0x8a, 0x71, 0x12 ),
  416. EXPECT ( 0xd7, 0x13, 0x76, 0xa4, 0x6d, 0x76, 0x4b, 0x17, 0xc3, 0xb7,
  417. 0x39, 0x34, 0x7b, 0x38, 0x4e, 0x51, 0x51, 0xe8, 0x7e, 0x88 ),
  418. EXPECT ( 0x6e, 0xbd, 0x2b, 0x7b, 0x5e, 0x0a, 0x2a, 0xd7, 0xa2, 0x4b,
  419. 0x1b, 0xf9, 0xa1, 0xdb, 0xa4, 0x7d, 0x43, 0x27, 0x17, 0x19,
  420. 0xb9, 0xc3, 0x7b, 0x7f, 0xe8, 0x1b, 0xa9, 0x40, 0x45, 0xa1,
  421. 0x4a, 0x7c, 0xb5, 0x14, 0xb4, 0x46, 0x66, 0x6e, 0xa5, 0xa7 ) );
  422. /** SHA-1 Test 3 : Instantiation */
  423. HMAC_DRBG_TEST_INSTANTIATE ( sha1_instantiate_3, HMAC_DRBG_SHA1,
  424. entropy_input, nonce_sha1, personalisation_string,
  425. EXPECT ( 0xb7, 0xd9, 0x66, 0xd7, 0x0d, 0x4e, 0x27, 0xa7, 0xfa, 0x83,
  426. 0x8f, 0x7d, 0x61, 0x12, 0x6c, 0x0e, 0xdc, 0x84, 0x76, 0x1c ),
  427. EXPECT ( 0xda, 0xb2, 0xa7, 0x18, 0x83, 0xf1, 0x00, 0x5c, 0x5d, 0xd0,
  428. 0x39, 0x32, 0x4d, 0x3c, 0x36, 0x4d, 0x6e, 0x18, 0xf9, 0x54 ) );
  429. /** SHA-1 Test 3.1 : First call to Generate */
  430. HMAC_DRBG_TEST_GENERATE ( sha1_generate_3_1, HMAC_DRBG_SHA1,
  431. additional_input_empty,
  432. EXPECT ( 0x87, 0xd3, 0x82, 0x8b, 0xe0, 0x3a, 0x80, 0x7d, 0xd3, 0x40,
  433. 0x29, 0x41, 0xbe, 0xd6, 0xde, 0x98, 0x6e, 0xe7, 0xa2, 0x86 ),
  434. EXPECT ( 0x6a, 0xe1, 0xd0, 0x08, 0x6f, 0x53, 0xb1, 0xb7, 0x63, 0xa4,
  435. 0x51, 0x5b, 0x19, 0x06, 0xfe, 0xe4, 0x76, 0x61, 0xfd, 0x47 ),
  436. EXPECT ( 0xb3, 0xbd, 0x05, 0x24, 0x6c, 0xba, 0x12, 0xa6, 0x47, 0x35,
  437. 0xa4, 0xe3, 0xfd, 0xe5, 0x99, 0xbc, 0x1b, 0xe3, 0x0f, 0x43,
  438. 0x9b, 0xd0, 0x60, 0x20, 0x8e, 0xea, 0x7d, 0x71, 0xf9, 0xd1,
  439. 0x23, 0xdf, 0x47, 0xb3, 0xce, 0x06, 0x9d, 0x98, 0xed, 0xe6 ) );
  440. /** SHA-1 Test 3.2 : Second call to Generate */
  441. HMAC_DRBG_TEST_GENERATE ( sha1_generate_3_2, HMAC_DRBG_SHA1,
  442. additional_input_empty,
  443. EXPECT ( 0x26, 0xab, 0xbf, 0x54, 0xb2, 0x8b, 0x93, 0xff, 0x90, 0x08,
  444. 0x67, 0x0e, 0xbf, 0xee, 0x86, 0xcd, 0xd7, 0x22, 0x8e, 0xd5 ),
  445. EXPECT ( 0xe9, 0x25, 0x47, 0x29, 0xe0, 0x02, 0x04, 0xa1, 0xb6, 0xc0,
  446. 0x21, 0x58, 0xa6, 0xc7, 0x27, 0x86, 0x47, 0x14, 0xf1, 0xf7 ),
  447. EXPECT ( 0xb5, 0xda, 0xda, 0x38, 0x0e, 0x28, 0x72, 0xdf, 0x93, 0x5b,
  448. 0xca, 0x55, 0xb8, 0x82, 0xc8, 0xc9, 0x37, 0x69, 0x02, 0xab,
  449. 0x63, 0x97, 0x65, 0x47, 0x2b, 0x71, 0xac, 0xeb, 0xe2, 0xea,
  450. 0x8b, 0x1b, 0x6b, 0x49, 0x62, 0x9c, 0xb6, 0x73, 0x17, 0xe0 ) );
  451. /** SHA-1 Test 4 : Instantiation */
  452. #define sha1_instantiate_4 sha1_instantiate_3
  453. /** SHA-1 Test 4.1 : First call to Generate */
  454. HMAC_DRBG_TEST_GENERATE ( sha1_generate_4_1, HMAC_DRBG_SHA1,
  455. additional_input_1,
  456. EXPECT ( 0x17, 0xa5, 0xd7, 0x9f, 0x07, 0x67, 0x87, 0x6f, 0x3a, 0x45,
  457. 0xe0, 0xc9, 0xc3, 0x3e, 0xc8, 0x8b, 0x03, 0xce, 0xea, 0x13 ),
  458. EXPECT ( 0x4d, 0x2f, 0x3b, 0xc7, 0x77, 0x50, 0x5c, 0x45, 0xf7, 0xe1,
  459. 0x7d, 0xcd, 0x3d, 0x86, 0xbf, 0x37, 0x9c, 0xb6, 0x02, 0x5e ),
  460. EXPECT ( 0x1f, 0x8f, 0xec, 0x7b, 0xc7, 0xcf, 0xa9, 0xa8, 0x80, 0x34,
  461. 0x5d, 0x28, 0x0b, 0x13, 0xc6, 0x32, 0xb8, 0x52, 0x77, 0x0a,
  462. 0x6d, 0xfc, 0x30, 0x2e, 0xad, 0x4c, 0xe3, 0xf5, 0x54, 0xc7,
  463. 0x9b, 0x0d, 0x44, 0x23, 0x9e, 0xba, 0x56, 0xa7, 0xea, 0x2d ) );
  464. /** SHA-1 Test 4.2 : Second call to Generate */
  465. HMAC_DRBG_TEST_GENERATE ( sha1_generate_4_2, HMAC_DRBG_SHA1,
  466. additional_input_2,
  467. EXPECT ( 0x07, 0x9b, 0x57, 0xd9, 0x40, 0x6e, 0x11, 0xc2, 0xf8, 0x7c,
  468. 0x8c, 0x82, 0x8c, 0x8c, 0x6f, 0xa7, 0x6e, 0x40, 0xea, 0x01 ),
  469. EXPECT ( 0xa6, 0x54, 0xfe, 0x72, 0xf8, 0xa7, 0x7b, 0xb8, 0xf0, 0x3d,
  470. 0xff, 0x07, 0xc7, 0x9a, 0x51, 0x53, 0x00, 0x9e, 0xdd, 0xda ),
  471. EXPECT ( 0xaf, 0x97, 0xcd, 0xe1, 0xe8, 0xab, 0x32, 0x2a, 0x2e, 0xac,
  472. 0xa8, 0xe6, 0xf4, 0xe5, 0xbf, 0x78, 0xa1, 0x1b, 0xde, 0xf7,
  473. 0xdc, 0x91, 0x21, 0x5d, 0x44, 0xb1, 0x07, 0xb4, 0xd5, 0xa7,
  474. 0x79, 0x01, 0x59, 0x25, 0x09, 0x76, 0x52, 0x80, 0xf9, 0x69 ) );
  475. /** SHA-1 Test 5 : Instantiation */
  476. #define sha1_instantiate_5 sha1_instantiate_1
  477. /** SHA-1 Test 5.1 : First call to Generate */
  478. HMAC_DRBG_TEST_GENERATE_FAIL ( sha1_generate_fail_5_1, HMAC_DRBG_SHA1,
  479. additional_input_empty, ( 320 / 8 ) );
  480. /** SHA-1 Test 5.2 : Reseed */
  481. HMAC_DRBG_TEST_RESEED ( sha1_reseed_5_2, HMAC_DRBG_SHA1,
  482. entropy_input_1, additional_input_empty,
  483. EXPECT ( 0xcd, 0x4c, 0xab, 0x38, 0xc8, 0xad, 0x65, 0x71, 0x22, 0xbf,
  484. 0x5d, 0x3d, 0x00, 0xd0, 0xac, 0x9b, 0x13, 0xd6, 0x29, 0xbb ),
  485. EXPECT ( 0xf6, 0x60, 0xe2, 0x3e, 0x91, 0x00, 0x6b, 0x62, 0xc6, 0x54,
  486. 0x3a, 0xb1, 0x34, 0x4d, 0x23, 0xa3, 0x1a, 0xb4, 0xcf, 0x2c ) );
  487. /** SHA-1 Test 5.3 : Retried first call to Generate */
  488. HMAC_DRBG_TEST_GENERATE ( sha1_generate_5_3, HMAC_DRBG_SHA1,
  489. additional_input_empty,
  490. EXPECT ( 0x58, 0x7f, 0xd8, 0x21, 0xef, 0x6c, 0x9d, 0xa4, 0xa8, 0x3c,
  491. 0x19, 0x21, 0x1f, 0x10, 0x56, 0xca, 0xcd, 0x23, 0xfc, 0x1a ),
  492. EXPECT ( 0x84, 0x8f, 0xd1, 0x4c, 0x13, 0xb7, 0xea, 0x93, 0x72, 0x0c,
  493. 0xcf, 0xde, 0x71, 0xf2, 0xf6, 0x44, 0x39, 0xdb, 0x79, 0x5d ),
  494. EXPECT ( 0xfe, 0xc4, 0x59, 0x7f, 0x06, 0xa3, 0xa8, 0xcc, 0x85, 0x29,
  495. 0xd5, 0x95, 0x57, 0xb9, 0xe6, 0x61, 0x05, 0x38, 0x09, 0xc0,
  496. 0xbc, 0x0e, 0xfc, 0x28, 0x2a, 0xbd, 0x87, 0x60, 0x5c, 0xc9,
  497. 0x0c, 0xba, 0x9b, 0x86, 0x33, 0xdc, 0xb1, 0xda, 0xe0, 0x2e ) );
  498. /** SHA-1 Test 5.4 : Second call to Generate */
  499. HMAC_DRBG_TEST_GENERATE_FAIL ( sha1_generate_fail_5_4, HMAC_DRBG_SHA1,
  500. additional_input_empty, ( 320 / 8 ) );
  501. /** SHA-1 Test 5.5 : Reseed */
  502. HMAC_DRBG_TEST_RESEED ( sha1_reseed_5_5, HMAC_DRBG_SHA1,
  503. entropy_input_2, additional_input_empty,
  504. EXPECT ( 0xdb, 0xa1, 0xcf, 0xf4, 0x87, 0x95, 0x46, 0xa0, 0x38, 0xa5,
  505. 0x59, 0xb2, 0xa2, 0x4d, 0xf2, 0xc0, 0x30, 0x08, 0x9a, 0x41 ),
  506. EXPECT ( 0x2f, 0x88, 0x3c, 0x46, 0x48, 0xe1, 0x31, 0xe8, 0x6d, 0xdf,
  507. 0x9d, 0xca, 0x0d, 0x74, 0xf3, 0x0c, 0xa1, 0xce, 0x6e, 0xfb ) );
  508. /** SHA-1 Test 5.6 : Retried second call to Generate */
  509. HMAC_DRBG_TEST_GENERATE ( sha1_generate_5_6, HMAC_DRBG_SHA1,
  510. additional_input_empty,
  511. EXPECT ( 0xf9, 0x39, 0xa5, 0xab, 0x08, 0xa3, 0x9f, 0x23, 0x10, 0x70,
  512. 0xb0, 0xd4, 0xc9, 0x6d, 0xc2, 0x37, 0x90, 0xba, 0x01, 0x53 ),
  513. EXPECT ( 0xce, 0x6d, 0x08, 0xb4, 0xae, 0x2c, 0xe3, 0x83, 0xfd, 0xab,
  514. 0xb0, 0x1e, 0xaa, 0xfc, 0x9c, 0x8e, 0x76, 0xa0, 0xd4, 0x72 ),
  515. EXPECT ( 0x84, 0xad, 0xd5, 0xe2, 0xd2, 0x04, 0x1c, 0x01, 0x72, 0x3a,
  516. 0x4d, 0xe4, 0x33, 0x5b, 0x13, 0xef, 0xdf, 0x16, 0xb0, 0xe5,
  517. 0x1a, 0x0a, 0xd3, 0x9b, 0xd1, 0x5e, 0x86, 0x2e, 0x64, 0x4f,
  518. 0x31, 0xe4, 0xa2, 0xd7, 0xd8, 0x43, 0xe5, 0x7c, 0x59, 0x68 ) );
  519. /** SHA-1 Test 6 : Instantiate */
  520. #define sha1_instantiate_6 sha1_instantiate_1
  521. /** SHA-1 Test 6.1 : First call to Generate */
  522. HMAC_DRBG_TEST_GENERATE_FAIL ( sha1_generate_fail_6_1, HMAC_DRBG_SHA1,
  523. additional_input_1, ( 320 / 8 ) );
  524. /** SHA-1 Test 6.2 : Reseed */
  525. HMAC_DRBG_TEST_RESEED ( sha1_reseed_6_2, HMAC_DRBG_SHA1,
  526. entropy_input_1, additional_input_1,
  527. EXPECT ( 0x52, 0x28, 0xa4, 0xb6, 0xa4, 0x46, 0x92, 0x90, 0x5e, 0xc0,
  528. 0x44, 0xbf, 0xf0, 0xbb, 0x4e, 0x25, 0xa3, 0x87, 0xca, 0xc1 ),
  529. EXPECT ( 0x24, 0x77, 0x32, 0xd0, 0x4c, 0xb8, 0x4e, 0xd4, 0x1a, 0xdd,
  530. 0x95, 0xa4, 0xb7, 0x8b, 0x50, 0xcd, 0x9b, 0x3d, 0x3f, 0x32 ) );
  531. /** SHA-1 Test 6.3 : Retried first call to Generate */
  532. HMAC_DRBG_TEST_GENERATE ( sha1_generate_6_3, HMAC_DRBG_SHA1,
  533. additional_input_empty,
  534. EXPECT ( 0xab, 0x3d, 0xd4, 0x89, 0x5b, 0xc8, 0xcd, 0x22, 0x71, 0xde,
  535. 0xba, 0x5f, 0x3c, 0x13, 0x63, 0x52, 0x6b, 0x8b, 0x74, 0x52 ),
  536. EXPECT ( 0xa8, 0x66, 0xc5, 0xef, 0xf2, 0xaf, 0x04, 0x2b, 0x11, 0x86,
  537. 0x44, 0x94, 0x45, 0x23, 0x7f, 0x9c, 0x02, 0x44, 0x98, 0x64 ),
  538. EXPECT ( 0xa1, 0xba, 0x8f, 0xa5, 0x8b, 0xb5, 0x01, 0x3f, 0x43, 0xf7,
  539. 0xb6, 0xed, 0x52, 0xb4, 0x53, 0x9f, 0xa1, 0x6d, 0xc7, 0x79,
  540. 0x57, 0xae, 0xe8, 0x15, 0xb9, 0xc0, 0x70, 0x04, 0xc7, 0xe9,
  541. 0x92, 0xeb, 0x8c, 0x7e, 0x59, 0x19, 0x64, 0xaf, 0xee, 0xa2 ) );
  542. /** SHA-1 Test 6.4 : Second call to Generate */
  543. HMAC_DRBG_TEST_GENERATE_FAIL ( sha1_generate_fail_6_4, HMAC_DRBG_SHA1,
  544. additional_input_2, ( 320 / 8 ) );
  545. /** SHA-1 Test 6.5 : Reseed */
  546. HMAC_DRBG_TEST_RESEED ( sha1_reseed_6_5, HMAC_DRBG_SHA1,
  547. entropy_input_2, additional_input_2,
  548. EXPECT ( 0xe5, 0x73, 0x9f, 0x9c, 0xf7, 0xff, 0x43, 0x84, 0xd1, 0x27,
  549. 0x3e, 0x02, 0x6b, 0x45, 0x31, 0x21, 0x36, 0x49, 0x4f, 0x41 ),
  550. EXPECT ( 0x30, 0xc3, 0x43, 0x05, 0xc2, 0xc6, 0x48, 0xb0, 0x57, 0xa6,
  551. 0x40, 0x22, 0x1b, 0x5c, 0x56, 0x57, 0x26, 0xcd, 0x32, 0xb2 ) );
  552. /** SHA-1 Test 6.6 : Retried second call to Generate */
  553. HMAC_DRBG_TEST_GENERATE ( sha1_generate_6_6, HMAC_DRBG_SHA1,
  554. additional_input_empty,
  555. EXPECT ( 0x61, 0x91, 0xca, 0x9b, 0xf0, 0x00, 0xd1, 0x0a, 0x71, 0x69,
  556. 0x0a, 0xc1, 0x0e, 0x09, 0xff, 0xc8, 0x92, 0xab, 0xde, 0x9a ),
  557. EXPECT ( 0x1e, 0xc0, 0x49, 0x0f, 0xa0, 0xb7, 0x65, 0x52, 0x7e, 0x5e,
  558. 0xa1, 0x8b, 0x53, 0x22, 0xb2, 0x8b, 0xdd, 0x0e, 0x7b, 0xc0 ),
  559. EXPECT ( 0x84, 0x26, 0x4a, 0x73, 0xa8, 0x18, 0xc9, 0x5c, 0x2f, 0x42,
  560. 0x4b, 0x37, 0xd3, 0xcc, 0x99, 0x0b, 0x04, 0x6f, 0xb5, 0x0c,
  561. 0x2d, 0xc6, 0x4a, 0x16, 0x42, 0x11, 0x88, 0x9a, 0x01, 0x0f,
  562. 0x24, 0x71, 0xa0, 0x91, 0x2f, 0xfe, 0xa1, 0xbf, 0x01, 0x95 ) );
  563. /** SHA-1 Test 7 : Instantiation */
  564. #define sha1_instantiate_7 sha1_instantiate_3
  565. /** SHA-1 Test 7.1 : First call to Generate */
  566. HMAC_DRBG_TEST_GENERATE_FAIL ( sha1_generate_fail_7_1, HMAC_DRBG_SHA1,
  567. additional_input_empty, ( 320 / 8 ) );
  568. /** SHA-1 Test 7.2 : Reseed */
  569. HMAC_DRBG_TEST_RESEED ( sha1_reseed_7_2, HMAC_DRBG_SHA1,
  570. entropy_input_1, additional_input_empty,
  571. EXPECT ( 0xb9, 0x25, 0x4d, 0x8a, 0xac, 0xba, 0x43, 0xfb, 0xda, 0xe6,
  572. 0x39, 0x4f, 0x2b, 0x3a, 0xfc, 0x5d, 0x58, 0x08, 0x00, 0xbf ),
  573. EXPECT ( 0x28, 0x40, 0x3b, 0x60, 0x36, 0x38, 0xd0, 0x7d, 0x79, 0x66,
  574. 0x66, 0x1e, 0xf6, 0x7b, 0x9d, 0x39, 0x05, 0xf4, 0x6d, 0xb9 ) );
  575. /** SHA-1 Test 7.3 : Retried first call to Generate */
  576. HMAC_DRBG_TEST_GENERATE ( sha1_generate_7_3, HMAC_DRBG_SHA1,
  577. additional_input_empty,
  578. EXPECT ( 0x64, 0xfe, 0x07, 0x4a, 0x6e, 0x77, 0x97, 0xd1, 0xa4, 0x35,
  579. 0xda, 0x89, 0x64, 0x48, 0x4d, 0x6c, 0xf8, 0xbd, 0xc0, 0x1b ),
  580. EXPECT ( 0x43, 0xe0, 0xc0, 0x52, 0x15, 0x86, 0xe9, 0x47, 0x3b, 0x06,
  581. 0x0d, 0x87, 0xd0, 0x8a, 0x23, 0x25, 0xfa, 0xe1, 0x49, 0xd1 ),
  582. EXPECT ( 0x6c, 0x37, 0xfd, 0xd7, 0x29, 0xaa, 0x40, 0xf8, 0x0b, 0xc6,
  583. 0xab, 0x08, 0xca, 0x7c, 0xc6, 0x49, 0x79, 0x4f, 0x69, 0x98,
  584. 0xb5, 0x70, 0x81, 0xe4, 0x22, 0x0f, 0x22, 0xc5, 0xc2, 0x83,
  585. 0xe2, 0xc9, 0x1b, 0x8e, 0x30, 0x5a, 0xb8, 0x69, 0xc6, 0x25 ) );
  586. /** SHA-1 Test 7.4 : Second call to Generate */
  587. HMAC_DRBG_TEST_GENERATE_FAIL ( sha1_generate_fail_7_4, HMAC_DRBG_SHA1,
  588. additional_input_empty, ( 320 / 8 ) );
  589. /** SHA-1 Test 7.5 : Reseed */
  590. HMAC_DRBG_TEST_RESEED ( sha1_reseed_7_5, HMAC_DRBG_SHA1,
  591. entropy_input_2, additional_input_empty,
  592. EXPECT ( 0x02, 0xbc, 0x57, 0x7f, 0xd1, 0x0e, 0xf7, 0x19, 0x3c, 0x1d,
  593. 0xb0, 0x98, 0xbd, 0x5b, 0x75, 0xc7, 0xc4, 0xb6, 0x79, 0x59 ),
  594. EXPECT ( 0xbc, 0xbd, 0xf0, 0x52, 0xe0, 0xe0, 0x2a, 0xe8, 0x9a, 0x77,
  595. 0x67, 0x94, 0x3f, 0x98, 0x65, 0xb8, 0xb7, 0x22, 0x90, 0x2d ) );
  596. /** SHA-1 Test 7.6 : Retried second call to Generate */
  597. HMAC_DRBG_TEST_GENERATE ( sha1_generate_7_6, HMAC_DRBG_SHA1,
  598. additional_input_empty,
  599. EXPECT ( 0x1a, 0xa4, 0x24, 0x1c, 0x69, 0x5e, 0x29, 0xc0, 0xa5, 0x9a,
  600. 0xd1, 0x8a, 0x60, 0x70, 0xe3, 0x38, 0xa5, 0x48, 0xbe, 0x92 ),
  601. EXPECT ( 0x03, 0x47, 0x35, 0x9b, 0xc9, 0xc7, 0xf8, 0x8c, 0xc8, 0x33,
  602. 0x0d, 0x4f, 0x59, 0xfb, 0xc7, 0x70, 0xb0, 0xb7, 0x7b, 0x03 ),
  603. EXPECT ( 0xca, 0xf5, 0x7d, 0xcf, 0xea, 0x39, 0x3b, 0x92, 0x36, 0xbf,
  604. 0x69, 0x1f, 0xa4, 0x56, 0xfe, 0xa7, 0xfd, 0xf1, 0xdf, 0x83,
  605. 0x61, 0x48, 0x2c, 0xa5, 0x4d, 0x5f, 0xa7, 0x23, 0xf4, 0xc8,
  606. 0x8b, 0x4f, 0xa5, 0x04, 0xbf, 0x03, 0x27, 0x7f, 0xa7, 0x83 ) );
  607. /** SHA-1 Test 8 : Instantiate */
  608. #define sha1_instantiate_8 sha1_instantiate_3
  609. /** SHA-1 Test 8.1 : First call to Generate */
  610. HMAC_DRBG_TEST_GENERATE_FAIL ( sha1_generate_fail_8_1, HMAC_DRBG_SHA1,
  611. additional_input_1, ( 320 / 8 ) );
  612. /** SHA-1 Test 8.2 : Reseed */
  613. HMAC_DRBG_TEST_RESEED ( sha1_reseed_8_2, HMAC_DRBG_SHA1,
  614. entropy_input_1, additional_input_1,
  615. EXPECT ( 0xc0, 0x95, 0x48, 0xc0, 0xd3, 0xc8, 0x61, 0xd7, 0x40, 0xf2,
  616. 0x83, 0x7d, 0x72, 0xb5, 0x07, 0x23, 0x5c, 0x26, 0xdb, 0x82 ),
  617. EXPECT ( 0x17, 0x4b, 0x3f, 0x84, 0xc3, 0x53, 0x1f, 0x7c, 0x0a, 0x2e,
  618. 0x54, 0x21, 0x23, 0x4e, 0xa1, 0x6b, 0x70, 0x8d, 0xdf, 0x0d ) );
  619. /** SHA-1 Test 8.3 : Retried first call to Generate */
  620. HMAC_DRBG_TEST_GENERATE ( sha1_generate_8_3, HMAC_DRBG_SHA1,
  621. additional_input_empty,
  622. EXPECT ( 0x60, 0x3f, 0x09, 0x49, 0x27, 0x9c, 0x70, 0xe8, 0xc6, 0x6c,
  623. 0x0f, 0x56, 0x37, 0xc0, 0xf3, 0x75, 0x60, 0x07, 0xe5, 0xac ),
  624. EXPECT ( 0xf2, 0xb3, 0x3b, 0x21, 0x15, 0x1f, 0xaf, 0x61, 0x20, 0x01,
  625. 0x83, 0x10, 0xf4, 0x4e, 0x4c, 0xd0, 0xbf, 0xe3, 0x68, 0xea ),
  626. EXPECT ( 0xbd, 0x07, 0xc2, 0x5c, 0xfd, 0x7c, 0x5e, 0x3a, 0x4e, 0xaa,
  627. 0x6e, 0x2e, 0xdc, 0x5a, 0xb7, 0xea, 0x49, 0x42, 0xa0, 0x91,
  628. 0x34, 0x71, 0xfd, 0xa5, 0x5c, 0x6d, 0xdd, 0x2c, 0x03, 0xef,
  629. 0xa3, 0xb9, 0x64, 0x3a, 0xb3, 0xbb, 0x22, 0xf6, 0xc9, 0xf2 ) );
  630. /** SHA-1 Test 8.4 : Second call to Generate */
  631. HMAC_DRBG_TEST_GENERATE_FAIL ( sha1_generate_fail_8_4, HMAC_DRBG_SHA1,
  632. additional_input_2, ( 320 / 8 ) );
  633. /** SHA-1 Test 8.5 : Reseed */
  634. HMAC_DRBG_TEST_RESEED ( sha1_reseed_8_5, HMAC_DRBG_SHA1,
  635. entropy_input_2, additional_input_2,
  636. EXPECT ( 0x89, 0x42, 0xa5, 0x4f, 0x34, 0x9e, 0x28, 0x1b, 0x84, 0xaa,
  637. 0x46, 0x95, 0x87, 0xfb, 0xdd, 0xaf, 0x9d, 0x11, 0x40, 0x82 ),
  638. EXPECT ( 0x07, 0x73, 0x0e, 0x3c, 0xbf, 0xfd, 0x3c, 0xaf, 0xd7, 0xa8,
  639. 0xaa, 0xe2, 0xbf, 0x01, 0xd6, 0x01, 0x43, 0x01, 0xe2, 0x4d ) );
  640. /** SHA-1 Test 8.6 : Retried second call to Generate */
  641. HMAC_DRBG_TEST_GENERATE ( sha1_generate_8_6, HMAC_DRBG_SHA1,
  642. additional_input_empty,
  643. EXPECT ( 0xbd, 0xe1, 0xb4, 0x6c, 0xdc, 0x54, 0x13, 0xb3, 0xd9, 0xf7,
  644. 0x35, 0xac, 0xdb, 0x80, 0xb1, 0x3c, 0x57, 0xbf, 0xe4, 0x73 ),
  645. EXPECT ( 0x72, 0x5a, 0x3c, 0x78, 0x20, 0xde, 0x1a, 0x06, 0xd0, 0x95,
  646. 0x81, 0x9c, 0xcf, 0x6f, 0x2c, 0x9b, 0x3a, 0x67, 0xf2, 0xce ),
  647. EXPECT ( 0xd1, 0xa9, 0xc1, 0xa2, 0x2c, 0x84, 0xfc, 0x23, 0xff, 0x22,
  648. 0x27, 0xef, 0x98, 0xec, 0x8b, 0xa9, 0xdf, 0x2a, 0x20, 0x9b,
  649. 0xa1, 0xdb, 0x09, 0x80, 0x9f, 0x57, 0xbf, 0xea, 0xe5, 0xb3,
  650. 0xe5, 0xf1, 0x46, 0xc7, 0x5f, 0x2d, 0x8d, 0xbb, 0x5e, 0x4a ) );
  651. /** SHA-256 Test 1 : Instantiation */
  652. HMAC_DRBG_TEST_INSTANTIATE ( sha256_instantiate_1, HMAC_DRBG_SHA256,
  653. entropy_input, nonce_sha256, personalisation_string_empty,
  654. EXPECT ( 0x3d, 0xda, 0x54, 0x3e, 0x7e, 0xef, 0x14, 0xf9, 0x36, 0x23,
  655. 0x7b, 0xe6, 0x5d, 0x09, 0x4b, 0x4d, 0xdc, 0x96, 0x9c, 0x0b,
  656. 0x2b, 0x5e, 0xaf, 0xb5, 0xd8, 0x05, 0xe8, 0x6c, 0xfa, 0x64,
  657. 0xd7, 0x41 ),
  658. EXPECT ( 0x2d, 0x02, 0xc2, 0xf8, 0x22, 0x51, 0x7d, 0x54, 0xb8, 0x17,
  659. 0x27, 0x9a, 0x59, 0x49, 0x1c, 0x41, 0xa1, 0x98, 0x9b, 0x3e,
  660. 0x38, 0x2d, 0xeb, 0xe8, 0x0d, 0x2c, 0x7f, 0x66, 0x0f, 0x44,
  661. 0x76, 0xc4 ) );
  662. /** SHA-256 Test 1.1 : First call to Generate */
  663. HMAC_DRBG_TEST_GENERATE ( sha256_generate_1_1, HMAC_DRBG_SHA256,
  664. additional_input_empty,
  665. EXPECT ( 0xdd, 0x30, 0x95, 0x79, 0x35, 0x38, 0x02, 0xcc, 0xdd, 0x43,
  666. 0x99, 0xc3, 0x69, 0x1c, 0x9d, 0xd9, 0x09, 0xdd, 0x3b, 0x2d,
  667. 0xd0, 0x03, 0xcc, 0xd5, 0x9d, 0x6f, 0x08, 0xd8, 0x5f, 0x2e,
  668. 0x35, 0x09 ),
  669. EXPECT ( 0xa1, 0xc2, 0x0f, 0xf2, 0x70, 0xa3, 0x9d, 0x2b, 0x8d, 0x03,
  670. 0xd6, 0x59, 0xb9, 0xdd, 0xd0, 0x11, 0xc2, 0xcc, 0xdf, 0x24,
  671. 0x48, 0x55, 0x7e, 0xf6, 0xa1, 0xa9, 0x15, 0xd1, 0x89, 0x40,
  672. 0xa6, 0x88 ),
  673. EXPECT ( 0xd6, 0x7b, 0x8c, 0x17, 0x34, 0xf4, 0x6f, 0xa3, 0xf7, 0x63,
  674. 0xcf, 0x57, 0xc6, 0xf9, 0xf4, 0xf2, 0xdc, 0x10, 0x89, 0xbd,
  675. 0x8b, 0xc1, 0xf6, 0xf0, 0x23, 0x95, 0x0b, 0xfc, 0x56, 0x17,
  676. 0x63, 0x52, 0x08, 0xc8, 0x50, 0x12, 0x38, 0xad, 0x7a, 0x44,
  677. 0x00, 0xde, 0xfe, 0xe4, 0x6c, 0x64, 0x0b, 0x61, 0xaf, 0x77,
  678. 0xc2, 0xd1, 0xa3, 0xbf, 0xaa, 0x90, 0xed, 0xe5, 0xd2, 0x07,
  679. 0x40, 0x6e, 0x54, 0x03 ) );
  680. /** SHA-256 Test 1.2 : Second call to Generate */
  681. HMAC_DRBG_TEST_GENERATE ( sha256_generate_1_2, HMAC_DRBG_SHA256,
  682. additional_input_empty,
  683. EXPECT ( 0x5c, 0xd5, 0xe5, 0x0a, 0x3e, 0x44, 0x8a, 0x07, 0xc3, 0xd2,
  684. 0xf2, 0xa3, 0xf9, 0xde, 0xbc, 0xc0, 0x46, 0x5f, 0x9c, 0xf1,
  685. 0x1c, 0xa1, 0x36, 0xe9, 0xb5, 0x04, 0xb4, 0xd3, 0x1c, 0x7f,
  686. 0xf1, 0xb8 ),
  687. EXPECT ( 0x33, 0xb3, 0x09, 0xf2, 0xff, 0x01, 0xce, 0x10, 0x4b, 0x44,
  688. 0x29, 0xb6, 0x75, 0xfa, 0xfa, 0x19, 0x01, 0x1e, 0x34, 0x8b,
  689. 0x28, 0x12, 0x71, 0x5a, 0x76, 0x37, 0xf6, 0xa6, 0xe6, 0x3b,
  690. 0x5d, 0x57 ),
  691. EXPECT ( 0x8f, 0xda, 0xec, 0x20, 0xf8, 0xb4, 0x21, 0x40, 0x70, 0x59,
  692. 0xe3, 0x58, 0x89, 0x20, 0xda, 0x7e, 0xda, 0x9d, 0xce, 0x3c,
  693. 0xf8, 0x27, 0x4d, 0xfa, 0x1c, 0x59, 0xc1, 0x08, 0xc1, 0xd0,
  694. 0xaa, 0x9b, 0x0f, 0xa3, 0x8d, 0xa5, 0xc7, 0x92, 0x03, 0x7c,
  695. 0x4d, 0x33, 0xcd, 0x07, 0x0c, 0xa7, 0xcd, 0x0c, 0x56, 0x08,
  696. 0xdb, 0xa8, 0xb8, 0x85, 0x65, 0x46, 0x39, 0xde, 0x21, 0x87,
  697. 0xb7, 0x4c, 0xb2, 0x63 ) );
  698. /** SHA-256 Test 2 : Instantiation */
  699. #define sha256_instantiate_2 sha256_instantiate_1
  700. /** SHA-256 Test 2.1 : First call to Generate */
  701. HMAC_DRBG_TEST_GENERATE ( sha256_generate_2_1, HMAC_DRBG_SHA256,
  702. additional_input_1,
  703. EXPECT ( 0x79, 0x1d, 0x31, 0x44, 0xb3, 0x02, 0xad, 0x6c, 0xe4, 0x32,
  704. 0x41, 0x34, 0x42, 0x10, 0xaa, 0xd0, 0xd3, 0x99, 0xed, 0xb7,
  705. 0xb5, 0x90, 0x6f, 0xb2, 0x51, 0xdb, 0x1c, 0xb6, 0x00, 0x04,
  706. 0xea, 0x51 ),
  707. EXPECT ( 0x58, 0xfd, 0x96, 0x5f, 0x4f, 0x99, 0x89, 0x3c, 0x17, 0xe6,
  708. 0xa3, 0x3c, 0xb8, 0xe9, 0x04, 0x15, 0xb5, 0x16, 0xd0, 0x06,
  709. 0x14, 0xa4, 0x49, 0xd4, 0x06, 0xe0, 0x3c, 0x68, 0x5b, 0xd8,
  710. 0x59, 0xbd ),
  711. EXPECT ( 0x41, 0x87, 0x87, 0x35, 0x81, 0x35, 0x41, 0x9b, 0x93, 0x81,
  712. 0x33, 0x53, 0x53, 0x06, 0x17, 0x6a, 0xfb, 0x25, 0x1c, 0xdd,
  713. 0x2b, 0xa3, 0x79, 0x88, 0x59, 0xb5, 0x66, 0xa0, 0x5c, 0xfb,
  714. 0x1d, 0x68, 0x0e, 0xa9, 0x25, 0x85, 0x6d, 0x5b, 0x84, 0xd5,
  715. 0x6a, 0xda, 0xe8, 0x70, 0x45, 0xa6, 0xba, 0x28, 0xd2, 0xc9,
  716. 0x08, 0xab, 0x75, 0xb7, 0xcc, 0x41, 0x43, 0x1f, 0xac, 0x59,
  717. 0xf3, 0x89, 0x18, 0xa3 ) );
  718. /** SHA-256 Test 2.2 : Second call to Generate */
  719. HMAC_DRBG_TEST_GENERATE ( sha256_generate_2_2, HMAC_DRBG_SHA256,
  720. additional_input_2,
  721. EXPECT ( 0xe7, 0x45, 0x8f, 0xb4, 0x4a, 0x36, 0x9a, 0x65, 0x3f, 0x2f,
  722. 0x8f, 0x57, 0x7b, 0xf9, 0x75, 0xc4, 0xb3, 0x62, 0xc4, 0xfe,
  723. 0x61, 0x8b, 0x2f, 0x1f, 0xf6, 0x76, 0x9b, 0x13, 0xc9, 0x4d,
  724. 0xec, 0xf4 ),
  725. EXPECT ( 0x19, 0x33, 0x4b, 0x8c, 0x31, 0xb7, 0x49, 0x32, 0xdd, 0xd7,
  726. 0xb2, 0xa4, 0x68, 0xf6, 0x43, 0x6d, 0xf9, 0x2e, 0x10, 0x0d,
  727. 0x39, 0xd3, 0xac, 0xb3, 0x68, 0xc7, 0x02, 0x9c, 0xb8, 0x83,
  728. 0xec, 0x89 ),
  729. EXPECT ( 0x7c, 0x06, 0x7b, 0xdd, 0xca, 0x81, 0x72, 0x48, 0x23, 0xd6,
  730. 0x4c, 0x69, 0x82, 0x92, 0x85, 0xbd, 0xbf, 0xf5, 0x37, 0x71,
  731. 0x61, 0x02, 0xc1, 0x88, 0x2e, 0x20, 0x22, 0x50, 0xe0, 0xfa,
  732. 0x5e, 0xf3, 0xa3, 0x84, 0xcd, 0x34, 0xa2, 0x0f, 0xfd, 0x1f,
  733. 0xbc, 0x91, 0xe0, 0xc5, 0x32, 0xa8, 0xa4, 0x21, 0xbc, 0x4a,
  734. 0xfe, 0x3c, 0xd4, 0x7f, 0x22, 0x32, 0x3e, 0xb4, 0xba, 0xe1,
  735. 0xa0, 0x07, 0x89, 0x81 ) );
  736. /** SHA-256 Test 3 : Instantiation */
  737. HMAC_DRBG_TEST_INSTANTIATE ( sha256_instantiate_3, HMAC_DRBG_SHA256,
  738. entropy_input, nonce_sha256, personalisation_string,
  739. EXPECT ( 0x65, 0x67, 0x3c, 0x34, 0x8e, 0x51, 0xcf, 0xac, 0xc4, 0x10,
  740. 0xbd, 0x20, 0x02, 0x49, 0xa5, 0x9a, 0x9d, 0x6b, 0xae, 0x77,
  741. 0x69, 0x04, 0x27, 0x1b, 0xb1, 0xf7, 0x18, 0xda, 0x1d, 0x18,
  742. 0x20, 0x42 ),
  743. EXPECT ( 0xe0, 0xf9, 0x1a, 0xc9, 0x96, 0x30, 0xee, 0xe6, 0x7c, 0xf8,
  744. 0x30, 0xcf, 0xd5, 0x04, 0x4f, 0xeb, 0xf5, 0x5c, 0x0c, 0x11,
  745. 0x50, 0x07, 0x99, 0x7a, 0xda, 0x11, 0x29, 0x6f, 0xc4, 0x16,
  746. 0x4a, 0x9a ) );
  747. /** SHA-256 Test 3.1 : First call to Generate */
  748. HMAC_DRBG_TEST_GENERATE ( sha256_generate_3_1, HMAC_DRBG_SHA256,
  749. additional_input_empty,
  750. EXPECT ( 0xf0, 0xb2, 0xf2, 0x42, 0xca, 0xd9, 0x92, 0xa7, 0x24, 0xf7,
  751. 0xe5, 0x59, 0x1d, 0x2f, 0x3b, 0x0c, 0x21, 0x57, 0xae, 0x70,
  752. 0xd5, 0x32, 0x78, 0x99, 0x40, 0xf1, 0x64, 0x45, 0x9b, 0x00,
  753. 0xc7, 0x49 ),
  754. EXPECT ( 0x1a, 0x03, 0xf9, 0x1c, 0x51, 0x20, 0xba, 0xca, 0x2b, 0xf6,
  755. 0xc6, 0x4d, 0xd7, 0x3a, 0xb1, 0x1d, 0xf6, 0xfd, 0x3f, 0xf1,
  756. 0xac, 0x3b, 0x57, 0x20, 0xa3, 0xf7, 0xfb, 0xe3, 0x9e, 0x7e,
  757. 0x7f, 0xe9 ),
  758. EXPECT ( 0x0d, 0xd9, 0xc8, 0x55, 0x89, 0xf3, 0x57, 0xc3, 0x89, 0xd6,
  759. 0xaf, 0x8d, 0xe9, 0xd7, 0x34, 0xa9, 0x17, 0xc7, 0x71, 0xef,
  760. 0x2d, 0x88, 0x16, 0xb9, 0x82, 0x59, 0x6e, 0xd1, 0x2d, 0xb4,
  761. 0x5d, 0x73, 0x4a, 0x62, 0x68, 0x08, 0x35, 0xc0, 0x2f, 0xda,
  762. 0x66, 0xb0, 0x8e, 0x1a, 0x36, 0x9a, 0xe2, 0x18, 0xf2, 0x6d,
  763. 0x52, 0x10, 0xad, 0x56, 0x42, 0x48, 0x87, 0x2d, 0x7a, 0x28,
  764. 0x78, 0x41, 0x59, 0xc3 ) );
  765. /** SHA-256 Test 3.2 : Second call to Generate */
  766. HMAC_DRBG_TEST_GENERATE ( sha256_generate_3_2, HMAC_DRBG_SHA256,
  767. additional_input_empty,
  768. EXPECT ( 0x5c, 0x0d, 0xec, 0x09, 0x37, 0x08, 0xc1, 0x7c, 0xa7, 0x6b,
  769. 0x57, 0xc0, 0xcb, 0x60, 0xcf, 0x88, 0x9d, 0xcc, 0x47, 0xad,
  770. 0x10, 0xbd, 0x64, 0xbc, 0x6a, 0x14, 0xb2, 0x3f, 0x20, 0x26,
  771. 0x07, 0x8a ),
  772. EXPECT ( 0x45, 0x67, 0x52, 0xa5, 0x11, 0xb8, 0x48, 0xbd, 0x05, 0xf1,
  773. 0x81, 0x9b, 0x9f, 0x6b, 0x15, 0x42, 0xc7, 0xd5, 0xec, 0xf9,
  774. 0x32, 0x73, 0x39, 0x26, 0x7a, 0x0c, 0x77, 0x23, 0x5b, 0x87,
  775. 0xdc, 0x5a ),
  776. EXPECT ( 0x46, 0xb4, 0xf4, 0x75, 0x6a, 0xe7, 0x15, 0xe0, 0xe5, 0x16,
  777. 0x81, 0xab, 0x29, 0x32, 0xde, 0x15, 0x23, 0xbe, 0x5d, 0x13,
  778. 0xba, 0xf0, 0xf4, 0x58, 0x8b, 0x11, 0xfe, 0x37, 0x2f, 0xda,
  779. 0x37, 0xab, 0xe3, 0x68, 0x31, 0x73, 0x41, 0xbc, 0x8b, 0xa9,
  780. 0x1f, 0xc5, 0xd8, 0x5b, 0x7f, 0xb8, 0xca, 0x8f, 0xbc, 0x30,
  781. 0x9a, 0x75, 0x8f, 0xd6, 0xfc, 0xa9, 0xdf, 0x43, 0xc7, 0x66,
  782. 0x0b, 0x22, 0x13, 0x22 ) );
  783. /** SHA-256 Test 4 : Instantiation */
  784. #define sha256_instantiate_4 sha256_instantiate_3
  785. /** SHA-256 Test 4.1 : First call to Generate */
  786. HMAC_DRBG_TEST_GENERATE ( sha256_generate_4_1, HMAC_DRBG_SHA256,
  787. additional_input_1,
  788. EXPECT ( 0x57, 0x2c, 0x03, 0x74, 0xc1, 0xa1, 0x01, 0x25, 0xbf, 0xa6,
  789. 0xae, 0xcd, 0x7c, 0xeb, 0xfe, 0x32, 0xf7, 0x52, 0xc3, 0xfb,
  790. 0x31, 0x67, 0x31, 0xb7, 0xcf, 0xdb, 0xde, 0xc2, 0x63, 0x56,
  791. 0x93, 0x2b ),
  792. EXPECT ( 0xd6, 0x8b, 0xf0, 0x41, 0xf3, 0xeb, 0x50, 0x88, 0x08, 0x8d,
  793. 0x8b, 0x8e, 0x71, 0x2c, 0x36, 0xae, 0x95, 0x83, 0xbb, 0x08,
  794. 0xfd, 0x1f, 0x90, 0x34, 0xa4, 0xe9, 0x42, 0xe9, 0xa6, 0x74,
  795. 0x7c, 0xe7 ),
  796. EXPECT ( 0x14, 0x78, 0xf2, 0x9e, 0x94, 0xb0, 0x2c, 0xb4, 0x0d, 0x3a,
  797. 0xab, 0x86, 0x24, 0x55, 0x57, 0xce, 0x13, 0xa8, 0xca, 0x2f,
  798. 0xdb, 0x65, 0x7d, 0x98, 0xef, 0xc1, 0x92, 0x34, 0x6b, 0x9f,
  799. 0xac, 0x33, 0xea, 0x58, 0xad, 0xa2, 0xcc, 0xa4, 0x32, 0xcc,
  800. 0xde, 0xfb, 0xcd, 0xaa, 0x8b, 0x82, 0xf5, 0x53, 0xef, 0x96,
  801. 0x61, 0x34, 0xe2, 0xcd, 0x13, 0x9f, 0x15, 0xf0, 0x1c, 0xad,
  802. 0x56, 0x85, 0x65, 0xa8 ) );
  803. /** SHA-256 Test 4.2 : Second call to Generate */
  804. HMAC_DRBG_TEST_GENERATE ( sha256_generate_4_2, HMAC_DRBG_SHA256,
  805. additional_input_2,
  806. EXPECT ( 0x28, 0x2e, 0x07, 0x34, 0x80, 0x80, 0x93, 0x75, 0x58, 0xb1,
  807. 0x39, 0x2e, 0x95, 0xab, 0x91, 0xe7, 0xc1, 0xf6, 0x22, 0xb2,
  808. 0x4f, 0xfb, 0x87, 0x20, 0xa5, 0xf0, 0xa5, 0xe0, 0x75, 0x50,
  809. 0xc7, 0xc2 ),
  810. EXPECT ( 0xdf, 0xc3, 0xbd, 0xb5, 0xf3, 0xbc, 0xf1, 0xaa, 0x68, 0x29,
  811. 0x8e, 0x79, 0x0d, 0x72, 0x0a, 0x67, 0xa7, 0x6e, 0x31, 0xb9,
  812. 0x2b, 0x9b, 0x35, 0xa8, 0xe5, 0x47, 0x1b, 0xb1, 0x7e, 0x30,
  813. 0x3c, 0x6b ),
  814. EXPECT ( 0x49, 0x7c, 0x7a, 0x16, 0xe8, 0x8a, 0x64, 0x11, 0xf8, 0xfc,
  815. 0xe1, 0x0e, 0xf5, 0x67, 0x63, 0xc6, 0x10, 0x25, 0x80, 0x1d,
  816. 0x8f, 0x51, 0xa7, 0x43, 0x52, 0xd6, 0x82, 0xcc, 0x23, 0xa0,
  817. 0xa8, 0xe6, 0x73, 0xca, 0xe0, 0x32, 0x28, 0x93, 0x90, 0x64,
  818. 0x7d, 0xc6, 0x83, 0xb7, 0x34, 0x28, 0x85, 0xd6, 0xb7, 0x6a,
  819. 0xb1, 0xda, 0x69, 0x6d, 0x3e, 0x97, 0xe2, 0x2d, 0xff, 0xdd,
  820. 0xff, 0xfd, 0x8d, 0xf0 ) );
  821. /** SHA-256 Test 5 : Instantiation */
  822. #define sha256_instantiate_5 sha256_instantiate_1
  823. /** SHA-256 Test 5.1 : First call to Generate */
  824. HMAC_DRBG_TEST_GENERATE_FAIL ( sha256_generate_fail_5_1, HMAC_DRBG_SHA256,
  825. additional_input_empty, ( 512 / 8 ) );
  826. /** SHA-256 Test 5.2 : Reseed */
  827. HMAC_DRBG_TEST_RESEED ( sha256_reseed_5_2, HMAC_DRBG_SHA256,
  828. entropy_input_1, additional_input_empty,
  829. EXPECT ( 0xb8, 0x40, 0x07, 0xe3, 0xe2, 0x7f, 0x34, 0xf9, 0xa7, 0x82,
  830. 0x0b, 0x7a, 0xb5, 0x9b, 0xbe, 0xfc, 0xd0, 0xc4, 0xac, 0xae,
  831. 0xde, 0x4b, 0x0b, 0x36, 0xb1, 0x47, 0xb8, 0x97, 0x79, 0xfd,
  832. 0x74, 0x9d ),
  833. EXPECT ( 0xa7, 0x2b, 0x8f, 0xee, 0x92, 0x39, 0x2f, 0x0a, 0x9d, 0x2d,
  834. 0x61, 0xbf, 0x09, 0xa4, 0xdf, 0xcc, 0x9d, 0xe6, 0x9a, 0x16,
  835. 0xa5, 0xf1, 0x50, 0x22, 0x4c, 0x3e, 0xf6, 0x04, 0x2d, 0x15,
  836. 0x21, 0xfc ) );
  837. /** SHA-256 Test 5.3 : Retried first call to Generate */
  838. HMAC_DRBG_TEST_GENERATE ( sha256_generate_5_3, HMAC_DRBG_SHA256,
  839. additional_input_empty,
  840. EXPECT ( 0x43, 0x48, 0xaf, 0x84, 0x20, 0x84, 0x2f, 0xa0, 0x77, 0xb9,
  841. 0xd3, 0xdb, 0xa8, 0xdc, 0xe9, 0xb3, 0xe1, 0xdf, 0x73, 0x4f,
  842. 0xfc, 0xe1, 0xbe, 0xa5, 0xb9, 0xe2, 0xb1, 0x54, 0xdc, 0x5e,
  843. 0xc6, 0x15 ),
  844. EXPECT ( 0xd2, 0xc1, 0xac, 0x27, 0x88, 0x5d, 0x43, 0x32, 0x76, 0x71,
  845. 0x31, 0x46, 0x32, 0xea, 0x60, 0x43, 0x3c, 0xca, 0x72, 0x73,
  846. 0x04, 0x56, 0x9e, 0xa7, 0xd4, 0x71, 0xfe, 0xa7, 0xdb, 0x7d,
  847. 0x31, 0x5d ),
  848. EXPECT ( 0xfa, 0xbd, 0x0a, 0xe2, 0x5c, 0x69, 0xdc, 0x2e, 0xfd, 0xef,
  849. 0xb7, 0xf2, 0x0c, 0x5a, 0x31, 0xb5, 0x7a, 0xc9, 0x38, 0xab,
  850. 0x77, 0x1a, 0xa1, 0x9b, 0xf8, 0xf5, 0xf1, 0x46, 0x8f, 0x66,
  851. 0x5c, 0x93, 0x8c, 0x9a, 0x1a, 0x5d, 0xf0, 0x62, 0x8a, 0x56,
  852. 0x90, 0xf1, 0x5a, 0x1a, 0xd8, 0xa6, 0x13, 0xf3, 0x1b, 0xbd,
  853. 0x65, 0xee, 0xad, 0x54, 0x57, 0xd5, 0xd2, 0x69, 0x47, 0xf2,
  854. 0x9f, 0xe9, 0x1a, 0xa7 ) );
  855. /** SHA-256 Test 5.4 : Second call to Generate */
  856. HMAC_DRBG_TEST_GENERATE_FAIL ( sha256_generate_fail_5_4, HMAC_DRBG_SHA256,
  857. additional_input_empty, ( 512 / 8 ) );
  858. /** SHA-256 Test 5.5 : Reseed */
  859. HMAC_DRBG_TEST_RESEED ( sha256_reseed_5_5, HMAC_DRBG_SHA256,
  860. entropy_input_2, additional_input_empty,
  861. EXPECT ( 0xbf, 0xa0, 0x2c, 0xe7, 0xe9, 0x2d, 0xe9, 0x2b, 0x18, 0x24,
  862. 0x28, 0x86, 0x89, 0x0e, 0x58, 0x6f, 0x83, 0x69, 0x06, 0xac,
  863. 0xe9, 0xe5, 0x54, 0xf1, 0xb0, 0xed, 0x63, 0x57, 0x3c, 0xb8,
  864. 0xb5, 0x03 ),
  865. EXPECT ( 0xd3, 0x24, 0x03, 0xee, 0xa9, 0xdc, 0xe1, 0x61, 0x6e, 0x4e,
  866. 0x11, 0x55, 0xb9, 0x23, 0xd8, 0x84, 0x2c, 0xc6, 0xe7, 0x84,
  867. 0xc6, 0x7a, 0x93, 0x85, 0xb2, 0xa6, 0x37, 0xf1, 0x02, 0xfa,
  868. 0x45, 0xd5 ) );
  869. /** SHA-256 Test 5.6 : Retried second call to Generate */
  870. HMAC_DRBG_TEST_GENERATE ( sha256_generate_5_6, HMAC_DRBG_SHA256,
  871. additional_input_empty,
  872. EXPECT ( 0x81, 0x21, 0xf7, 0x76, 0x4c, 0x08, 0x1e, 0xe9, 0xd1, 0x17,
  873. 0x1e, 0xd1, 0x87, 0xba, 0xe0, 0x88, 0x95, 0xca, 0xe2, 0x30,
  874. 0xd0, 0xa2, 0x5e, 0x37, 0x39, 0xc5, 0x7d, 0x54, 0x16, 0x10,
  875. 0x9b, 0x82 ),
  876. EXPECT ( 0x37, 0x84, 0x97, 0x7c, 0xc0, 0xe5, 0x9f, 0xbc, 0x9c, 0xda,
  877. 0x4e, 0x11, 0x92, 0x47, 0x5c, 0x6e, 0xfa, 0xf8, 0x07, 0x20,
  878. 0x19, 0x86, 0x21, 0x22, 0xcb, 0x6b, 0xce, 0xaa, 0xcc, 0x4a,
  879. 0x17, 0x5e ),
  880. EXPECT ( 0x6b, 0xd9, 0x25, 0xb0, 0xe1, 0xc2, 0x32, 0xef, 0xd6, 0x7c,
  881. 0xcd, 0x84, 0xf7, 0x22, 0xe9, 0x27, 0xec, 0xb4, 0x6a, 0xb2,
  882. 0xb7, 0x40, 0x01, 0x47, 0x77, 0xaf, 0x14, 0xba, 0x0b, 0xbf,
  883. 0x53, 0xa4, 0x5b, 0xdb, 0xb6, 0x2b, 0x3f, 0x7d, 0x0b, 0x9c,
  884. 0x8e, 0xea, 0xd0, 0x57, 0xc0, 0xec, 0x75, 0x4e, 0xf8, 0xb5,
  885. 0x3e, 0x60, 0xa1, 0xf4, 0x34, 0xf0, 0x59, 0x46, 0xa8, 0xb6,
  886. 0x86, 0xaf, 0xbc, 0x7a ) );
  887. /** SHA-256 Test 6 : Instantiate */
  888. #define sha256_instantiate_6 sha256_instantiate_1
  889. /** SHA-256 Test 6.1 : First call to Generate */
  890. HMAC_DRBG_TEST_GENERATE_FAIL ( sha256_generate_fail_6_1, HMAC_DRBG_SHA256,
  891. additional_input_1, ( 512 / 8 ) );
  892. /** SHA-256 Test 6.2 : Reseed */
  893. HMAC_DRBG_TEST_RESEED ( sha256_reseed_6_2, HMAC_DRBG_SHA256,
  894. entropy_input_1, additional_input_1,
  895. EXPECT ( 0xc1, 0x25, 0xea, 0x99, 0x75, 0x8e, 0xbb, 0x9a, 0x6f, 0x69,
  896. 0xae, 0x31, 0x2a, 0xc2, 0x04, 0xb5, 0x94, 0xc0, 0x0a, 0xb6,
  897. 0x8b, 0x81, 0x6e, 0x3a, 0x52, 0x12, 0x8e, 0x02, 0x78, 0xa5,
  898. 0x84, 0xac ),
  899. EXPECT ( 0xb2, 0xcb, 0x2b, 0x89, 0x12, 0x3f, 0x5b, 0x4a, 0xf5, 0x87,
  900. 0xb8, 0xf6, 0xbd, 0xc5, 0x42, 0x7a, 0x99, 0x14, 0x19, 0xd3,
  901. 0x53, 0x07, 0x7c, 0x68, 0x5e, 0x70, 0x7a, 0xcd, 0xf8, 0xe9,
  902. 0xfd, 0xa9 ) );
  903. /** SHA-256 Test 6.3 : Retried first call to Generate */
  904. HMAC_DRBG_TEST_GENERATE ( sha256_generate_6_3, HMAC_DRBG_SHA256,
  905. additional_input_empty,
  906. EXPECT ( 0xc6, 0xed, 0x8f, 0xed, 0x71, 0x57, 0xa4, 0xd0, 0x9e, 0xa1,
  907. 0xdd, 0xe8, 0x94, 0x6b, 0x54, 0x43, 0x3e, 0xcc, 0x54, 0x49,
  908. 0xa4, 0xa3, 0x52, 0xaf, 0x45, 0x76, 0x4e, 0xe6, 0x73, 0x4b,
  909. 0xbb, 0x04 ),
  910. EXPECT ( 0xeb, 0xc7, 0x75, 0x25, 0x6b, 0xb7, 0x81, 0x24, 0x1e, 0x9c,
  911. 0x70, 0xbb, 0xcf, 0x73, 0x2b, 0xdc, 0x90, 0xad, 0x10, 0xd9,
  912. 0xdd, 0x3a, 0x89, 0x6e, 0xcc, 0x12, 0xb9, 0x2f, 0xfb, 0x63,
  913. 0x45, 0xab ),
  914. EXPECT ( 0x08, 0x5d, 0x57, 0xaf, 0x6b, 0xab, 0xcf, 0x2b, 0x9a, 0xee,
  915. 0xf3, 0x87, 0xd5, 0x31, 0x65, 0x0e, 0x6a, 0x50, 0x5c, 0x54,
  916. 0x40, 0x6a, 0xb3, 0x7a, 0x52, 0x89, 0x9e, 0x0e, 0xca, 0xb3,
  917. 0x63, 0x2b, 0x7a, 0x06, 0x8a, 0x28, 0x14, 0xc6, 0xdf, 0x6a,
  918. 0xe5, 0x32, 0xb6, 0x58, 0xd0, 0xd9, 0x74, 0x1c, 0x84, 0x77,
  919. 0x5f, 0xee, 0x45, 0xb6, 0x84, 0xcd, 0xbd, 0xc2, 0x5f, 0xbc,
  920. 0xb4, 0xd8, 0xf3, 0x10 ) );
  921. /** SHA-256 Test 6.4 : Second call to Generate */
  922. HMAC_DRBG_TEST_GENERATE_FAIL ( sha256_generate_fail_6_4, HMAC_DRBG_SHA256,
  923. additional_input_2, ( 512 / 8 ) );
  924. /** SHA-256 Test 6.5 : Reseed */
  925. HMAC_DRBG_TEST_RESEED ( sha256_reseed_6_5, HMAC_DRBG_SHA256,
  926. entropy_input_2, additional_input_2,
  927. EXPECT ( 0xfc, 0x51, 0xda, 0x84, 0xf9, 0x69, 0x6b, 0xcc, 0x84, 0xc8,
  928. 0xf2, 0xac, 0xb9, 0x24, 0xbc, 0xdf, 0x72, 0xf8, 0x2e, 0xa2,
  929. 0xca, 0x64, 0x3f, 0x08, 0x3b, 0x0c, 0x16, 0xc3, 0x63, 0x4e,
  930. 0xfc, 0x62 ),
  931. EXPECT ( 0xb9, 0x74, 0xe4, 0x37, 0x0a, 0xd5, 0x76, 0xbb, 0x99, 0xc4,
  932. 0xe4, 0x9e, 0xa6, 0x80, 0xbf, 0xf9, 0x8d, 0xe9, 0xe1, 0x2f,
  933. 0xec, 0xd0, 0x13, 0xde, 0xd4, 0x3c, 0x80, 0xf6, 0x9a, 0x7a,
  934. 0xde, 0x8a ) );
  935. /** SHA-256 Test 6.6 : Retried second call to Generate */
  936. HMAC_DRBG_TEST_GENERATE ( sha256_generate_6_6, HMAC_DRBG_SHA256,
  937. additional_input_empty,
  938. EXPECT ( 0x56, 0xa2, 0xb4, 0x46, 0x32, 0xcb, 0x8f, 0xc3, 0xa6, 0x40,
  939. 0x09, 0xbf, 0xd6, 0xec, 0x95, 0xe5, 0x6c, 0xef, 0x8e, 0x7c,
  940. 0x91, 0x2a, 0xa8, 0x2b, 0x16, 0xf6, 0x14, 0x91, 0x5d, 0x9c,
  941. 0xd6, 0xe3 ),
  942. EXPECT ( 0xb5, 0xb3, 0x96, 0xa0, 0x15, 0x76, 0xb0, 0xfe, 0x42, 0xf4,
  943. 0x08, 0x44, 0x55, 0x6c, 0x4c, 0xf4, 0xb6, 0x80, 0x4c, 0x94,
  944. 0xde, 0x9d, 0x62, 0x38, 0xf1, 0xf7, 0xe7, 0xaf, 0x5c, 0x72,
  945. 0x57, 0xf3 ),
  946. EXPECT ( 0x9b, 0x21, 0x9f, 0xd9, 0x0d, 0xe2, 0xa0, 0x8e, 0x49, 0x34,
  947. 0x05, 0xcf, 0x87, 0x44, 0x17, 0xb5, 0x82, 0x67, 0x70, 0xf3,
  948. 0x94, 0x48, 0x15, 0x55, 0xdc, 0x66, 0x8a, 0xcd, 0x96, 0xb9,
  949. 0xa3, 0xe5, 0x6f, 0x9d, 0x2c, 0x32, 0x5e, 0x26, 0xd4, 0x7c,
  950. 0x1d, 0xfc, 0xfc, 0x8f, 0xbf, 0x86, 0x12, 0x6f, 0x40, 0xa1,
  951. 0xe6, 0x39, 0x60, 0xf6, 0x27, 0x49, 0x34, 0x2e, 0xcd, 0xb7,
  952. 0x1b, 0x24, 0x0d, 0xc6 ) );
  953. /** SHA-256 Test 7 : Instantiation */
  954. #define sha256_instantiate_7 sha256_instantiate_3
  955. /** SHA-256 Test 7.1 : First call to Generate */
  956. HMAC_DRBG_TEST_GENERATE_FAIL ( sha256_generate_fail_7_1, HMAC_DRBG_SHA256,
  957. additional_input_empty, ( 512 / 8 ) );
  958. /** SHA-256 Test 7.2 : Reseed */
  959. HMAC_DRBG_TEST_RESEED ( sha256_reseed_7_2, HMAC_DRBG_SHA256,
  960. entropy_input_1, additional_input_empty,
  961. EXPECT ( 0x44, 0x76, 0xc6, 0xd1, 0x1f, 0xc3, 0x5d, 0x44, 0x09, 0xd9,
  962. 0x03, 0x2e, 0x45, 0x3b, 0x0f, 0x0d, 0xc3, 0x31, 0x4d, 0xb8,
  963. 0x62, 0xcb, 0xdb, 0x60, 0x9c, 0x56, 0x02, 0x20, 0x8d, 0x4c,
  964. 0x88, 0xd8 ),
  965. EXPECT ( 0x95, 0xef, 0x78, 0x5a, 0x61, 0xc2, 0xf7, 0xb3, 0x6b, 0xc5,
  966. 0x96, 0xba, 0x4b, 0xa2, 0x08, 0xa5, 0x2c, 0x6d, 0xc2, 0x03,
  967. 0x63, 0x6d, 0x8f, 0x17, 0x87, 0x45, 0x3b, 0x85, 0x2b, 0x7e,
  968. 0x49, 0xec ) );
  969. /** SHA-256 Test 7.3 : Retried first call to Generate */
  970. HMAC_DRBG_TEST_GENERATE ( sha256_generate_7_3, HMAC_DRBG_SHA256,
  971. additional_input_empty,
  972. EXPECT ( 0x0d, 0xf9, 0x11, 0x0e, 0x2f, 0x22, 0x58, 0x98, 0x24, 0xa9,
  973. 0x47, 0x6c, 0x8e, 0x32, 0x08, 0x8e, 0x51, 0xa0, 0xda, 0x36,
  974. 0x63, 0x3f, 0x8c, 0xd1, 0xf7, 0x54, 0x7d, 0xff, 0x69, 0x6e,
  975. 0x4b, 0x29 ),
  976. EXPECT ( 0xc0, 0xe3, 0xc8, 0xed, 0x5a, 0x8b, 0x57, 0x9e, 0x3f, 0xef,
  977. 0x9d, 0xf3, 0xb7, 0xc2, 0xc2, 0x12, 0x98, 0x07, 0x17, 0xcc,
  978. 0x91, 0xae, 0x18, 0x66, 0x45, 0xfa, 0xbb, 0x2c, 0xc7, 0x84,
  979. 0xd5, 0xd7 ),
  980. EXPECT ( 0xd8, 0xb6, 0x71, 0x30, 0x71, 0x41, 0x94, 0xff, 0xe5, 0xb2,
  981. 0xa3, 0x5d, 0xbc, 0xd5, 0xe1, 0xa2, 0x99, 0x42, 0xad, 0x5c,
  982. 0x68, 0xf3, 0xde, 0xb9, 0x4a, 0xdd, 0x9e, 0x9e, 0xba, 0xd8,
  983. 0x60, 0x67, 0xed, 0xf0, 0x49, 0x15, 0xfb, 0x40, 0xc3, 0x91,
  984. 0xea, 0xe7, 0x0c, 0x65, 0x9e, 0xaa, 0xe7, 0xef, 0x11, 0xa3,
  985. 0xd4, 0x6a, 0x5b, 0x08, 0x5e, 0xdd, 0x90, 0xcc, 0x72, 0xce,
  986. 0xa9, 0x89, 0x21, 0x0b ) );
  987. /** SHA-256 Test 7.4 : Second call to Generate */
  988. HMAC_DRBG_TEST_GENERATE_FAIL ( sha256_generate_fail_7_4, HMAC_DRBG_SHA256,
  989. additional_input_empty, ( 512 / 8 ) );
  990. /** SHA-256 Test 7.5 : Reseed */
  991. HMAC_DRBG_TEST_RESEED ( sha256_reseed_7_5, HMAC_DRBG_SHA256,
  992. entropy_input_2, additional_input_empty,
  993. EXPECT ( 0x3d, 0x77, 0x63, 0xe5, 0x30, 0x3d, 0xb5, 0x4b, 0xe2, 0x05,
  994. 0x44, 0xa8, 0x1e, 0x9f, 0x00, 0xca, 0xdc, 0xfc, 0x1c, 0xb2,
  995. 0x8d, 0xec, 0xb9, 0xcf, 0xc6, 0x99, 0xf6, 0x1d, 0xba, 0xf8,
  996. 0x80, 0x21 ),
  997. EXPECT ( 0xfe, 0xbc, 0x02, 0x79, 0xb7, 0x71, 0x0d, 0xec, 0x5c, 0x06,
  998. 0x7e, 0xbe, 0xfa, 0x06, 0x8e, 0x4b, 0x59, 0x67, 0x49, 0x1b,
  999. 0x7e, 0xef, 0x94, 0x75, 0x83, 0x50, 0x6d, 0x04, 0x97, 0xce,
  1000. 0x67, 0xba ) );
  1001. /** SHA-256 Test 7.6 : Retried second call to Generate */
  1002. HMAC_DRBG_TEST_GENERATE ( sha256_generate_7_6, HMAC_DRBG_SHA256,
  1003. additional_input_empty,
  1004. EXPECT ( 0x2d, 0x21, 0xac, 0x94, 0x99, 0x2f, 0xd8, 0x2b, 0x09, 0x80,
  1005. 0xd3, 0xd5, 0x95, 0x51, 0xb9, 0xd0, 0x7c, 0x8d, 0x54, 0xb2,
  1006. 0x52, 0xb6, 0x16, 0x28, 0x93, 0x44, 0xf8, 0xac, 0x86, 0x9e,
  1007. 0xd3, 0x5b ),
  1008. EXPECT ( 0x61, 0x0c, 0x34, 0xcd, 0xbf, 0x6f, 0x75, 0x33, 0x54, 0x7f,
  1009. 0x23, 0x32, 0xea, 0xc5, 0x7e, 0xe3, 0x1e, 0x72, 0x4f, 0xb2,
  1010. 0x92, 0x55, 0x56, 0x6b, 0x59, 0x78, 0x33, 0x16, 0x6c, 0xd0,
  1011. 0x39, 0x9f ),
  1012. EXPECT ( 0x8b, 0xba, 0x71, 0xc2, 0x58, 0x3f, 0x25, 0x30, 0xc2, 0x59,
  1013. 0xc9, 0x07, 0x84, 0xa5, 0x9a, 0xc4, 0x4d, 0x1c, 0x80, 0x56,
  1014. 0x91, 0x7c, 0xcf, 0x38, 0x87, 0x88, 0x10, 0x2d, 0x73, 0x82,
  1015. 0x4c, 0x6c, 0x11, 0xd5, 0xd6, 0x3b, 0xe1, 0xf0, 0x10, 0x17,
  1016. 0xd8, 0x84, 0xcd, 0x69, 0xd9, 0x33, 0x4b, 0x9e, 0xbc, 0x01,
  1017. 0xe7, 0xbd, 0x8f, 0xdf, 0x2a, 0x8e, 0x52, 0x57, 0x22, 0x93,
  1018. 0xdc, 0x21, 0xc0, 0xe1 ) );
  1019. /** SHA-256 Test 8 : Instantiate */
  1020. #define sha256_instantiate_8 sha256_instantiate_3
  1021. /** SHA-256 Test 8.1 : First call to Generate */
  1022. HMAC_DRBG_TEST_GENERATE_FAIL ( sha256_generate_fail_8_1, HMAC_DRBG_SHA256,
  1023. additional_input_1, ( 512 / 8 ) );
  1024. /** SHA-256 Test 8.2 : Reseed */
  1025. HMAC_DRBG_TEST_RESEED ( sha256_reseed_8_2, HMAC_DRBG_SHA256,
  1026. entropy_input_1, additional_input_1,
  1027. EXPECT ( 0xb3, 0x81, 0x38, 0x8c, 0x1d, 0x7c, 0xfd, 0x56, 0x59, 0x30,
  1028. 0x99, 0x3b, 0xd9, 0x26, 0x90, 0x66, 0x50, 0x88, 0xd9, 0xb8,
  1029. 0x39, 0x96, 0x9b, 0x87, 0xf1, 0x6d, 0xb6, 0xdf, 0x4e, 0x43,
  1030. 0x00, 0xd7 ),
  1031. EXPECT ( 0xfa, 0x04, 0x25, 0x64, 0x00, 0xe3, 0x42, 0xe6, 0x55, 0xf4,
  1032. 0x33, 0x26, 0x94, 0xe3, 0xb2, 0x4c, 0x04, 0xfb, 0x85, 0xbf,
  1033. 0x87, 0x80, 0x21, 0xe4, 0x52, 0xe7, 0x3b, 0x8f, 0x46, 0xd4,
  1034. 0xbd, 0xc6 ) );
  1035. /** SHA-256 Test 8.3 : Retried first call to Generate */
  1036. HMAC_DRBG_TEST_GENERATE ( sha256_generate_8_3, HMAC_DRBG_SHA256,
  1037. additional_input_empty,
  1038. EXPECT ( 0xd4, 0x1f, 0x6f, 0x33, 0x65, 0x82, 0x21, 0x70, 0x50, 0xb1,
  1039. 0xf6, 0x59, 0x28, 0xfd, 0x6e, 0x94, 0xcb, 0xc9, 0x45, 0x68,
  1040. 0xfe, 0x3b, 0x6b, 0x53, 0x38, 0x9e, 0x1e, 0x3a, 0x5b, 0x49,
  1041. 0xe1, 0x01 ),
  1042. EXPECT ( 0xa6, 0x55, 0xc9, 0xe7, 0xd1, 0x33, 0xf1, 0xcd, 0x8b, 0x11,
  1043. 0x61, 0xf2, 0x7d, 0x54, 0xe7, 0x5a, 0x7e, 0x7c, 0x80, 0x42,
  1044. 0xbf, 0x74, 0xd4, 0x7f, 0x9f, 0xfd, 0x60, 0xe2, 0x45, 0xeb,
  1045. 0xa5, 0x7e ),
  1046. EXPECT ( 0x44, 0xd7, 0x8b, 0xbc, 0x3e, 0xb6, 0x7c, 0x59, 0xc2, 0x2f,
  1047. 0x6c, 0x31, 0x00, 0x3d, 0x21, 0x2a, 0x78, 0x37, 0xcc, 0xd8,
  1048. 0x4c, 0x43, 0x8b, 0x55, 0x15, 0x0f, 0xd0, 0x13, 0xa8, 0xa7,
  1049. 0x8f, 0xe8, 0xed, 0xea, 0x81, 0xc6, 0x72, 0xe4, 0xb8, 0xdd,
  1050. 0xc8, 0x18, 0x38, 0x86, 0xe6, 0x9c, 0x2e, 0x17, 0x7d, 0xf5,
  1051. 0x74, 0xc1, 0xf1, 0x90, 0xdf, 0x27, 0x18, 0x50, 0xf8, 0xce,
  1052. 0x55, 0xef, 0x20, 0xb8 ) );
  1053. /** SHA-256 Test 8.4 : Second call to Generate */
  1054. HMAC_DRBG_TEST_GENERATE_FAIL ( sha256_generate_fail_8_4, HMAC_DRBG_SHA256,
  1055. additional_input_2, ( 512 / 8 ) );
  1056. /** SHA-256 Test 8.5 : Reseed */
  1057. HMAC_DRBG_TEST_RESEED ( sha256_reseed_8_5, HMAC_DRBG_SHA256,
  1058. entropy_input_2, additional_input_2,
  1059. EXPECT ( 0xfb, 0xa8, 0x05, 0x45, 0x3e, 0x3c, 0x9a, 0x73, 0x64, 0x58,
  1060. 0x5c, 0xed, 0xbc, 0xd2, 0x92, 0x30, 0xfb, 0xc9, 0x3d, 0x6f,
  1061. 0x12, 0x9d, 0x21, 0xed, 0xdd, 0xf6, 0x61, 0x3b, 0x3a, 0x8f,
  1062. 0xf2, 0x83 ),
  1063. EXPECT ( 0x83, 0x64, 0x7a, 0x33, 0x8c, 0x15, 0x3c, 0xba, 0xf0, 0xe4,
  1064. 0x9a, 0x54, 0xa4, 0x4f, 0xea, 0x66, 0x70, 0xcf, 0xd7, 0xc1,
  1065. 0x71, 0x4d, 0x4a, 0xb3, 0x5f, 0x11, 0x12, 0x3d, 0xf2, 0x7b,
  1066. 0x69, 0xcf ) );
  1067. /** SHA-256 Test 8.6 : Retried second call to Generate */
  1068. HMAC_DRBG_TEST_GENERATE ( sha256_generate_8_6, HMAC_DRBG_SHA256,
  1069. additional_input_empty,
  1070. EXPECT ( 0xae, 0x59, 0xc7, 0x0a, 0x7c, 0x60, 0xed, 0x49, 0x83, 0x78,
  1071. 0xea, 0x84, 0x5b, 0xe9, 0x7d, 0x8f, 0xf8, 0x81, 0xe0, 0xea,
  1072. 0x37, 0x2e, 0x26, 0x5f, 0xa6, 0x72, 0x84, 0x29, 0x3e, 0x1a,
  1073. 0x46, 0xac ),
  1074. EXPECT ( 0xe2, 0xf0, 0x4d, 0xe3, 0xce, 0x21, 0x79, 0x61, 0xae, 0x2b,
  1075. 0x2d, 0x20, 0xa7, 0xba, 0x7c, 0x6c, 0x82, 0x0b, 0x5b, 0x14,
  1076. 0x92, 0x6e, 0x59, 0x56, 0xae, 0x6d, 0xfa, 0x2e, 0xd1, 0xd6,
  1077. 0x39, 0x93 ),
  1078. EXPECT ( 0x91, 0x77, 0x80, 0xdc, 0x0c, 0xe9, 0x98, 0x9f, 0xee, 0x6c,
  1079. 0x08, 0x06, 0xd6, 0xda, 0x12, 0x3a, 0x18, 0x25, 0x29, 0x47,
  1080. 0x58, 0xd4, 0xe1, 0xb5, 0x82, 0x68, 0x72, 0x31, 0x78, 0x0a,
  1081. 0x2a, 0x9c, 0x33, 0xf1, 0xd1, 0x56, 0xcc, 0xad, 0x32, 0x77,
  1082. 0x64, 0xb2, 0x9a, 0x4c, 0xb2, 0x69, 0x01, 0x77, 0xae, 0x96,
  1083. 0xef, 0x9e, 0xe9, 0x2a, 0xd0, 0xc3, 0x40, 0xba, 0x0f, 0xd1,
  1084. 0x20, 0x3c, 0x02, 0xc6 ) );
  1085. /**
  1086. * Force a "reseed required" state
  1087. *
  1088. * @v state HMAC_DRBG internal state
  1089. */
  1090. static inline void force_reseed_required ( struct hmac_drbg_state *state ) {
  1091. state->reseed_counter = ( HMAC_DRBG_RESEED_INTERVAL + 1 );
  1092. }
  1093. /**
  1094. * Perform HMAC_DRBG self-test
  1095. *
  1096. */
  1097. static void hmac_drbg_test_exec ( void ) {
  1098. struct hmac_drbg_state state;
  1099. /*
  1100. * IMPORTANT NOTE
  1101. *
  1102. * The NIST test vector set includes several calls to
  1103. * HMAC_DRBG_Generate() that are expected to fail with a
  1104. * status of "Reseed required". The pattern seems to be that
  1105. * when prediction resistance is requested, any call to
  1106. * HMAC_DRBG_Generate() is at first expected to fail. After
  1107. * an explicit reseeding, the call to HMAC_DRBG_Generate() is
  1108. * retried, and on this second time it is expected to succeed.
  1109. *
  1110. * This pattern does not match the specifications for
  1111. * HMAC_DRBG_Generate(): neither HMAC_DRBG_Generate_algorithm
  1112. * (defined in ANS X9.82 Part 3-2007 Section 10.2.2.2.5 (NIST
  1113. * SP 800-90 Section 10.1.2.5)) nor the higher-level wrapper
  1114. * Generate_function defined in ANS X9.82 Part 3-2007 Section
  1115. * 9.4 (NIST SP 800-90 Section 9.3)) can possibly exhibit this
  1116. * behaviour:
  1117. *
  1118. * a) HMAC_DRBG_Generate_algorithm can return a "reseed
  1119. * required" status only as a result of the test
  1120. *
  1121. * "1. If reseed_counter > reseed_interval, then return
  1122. * an indication that a reseed is required."
  1123. *
  1124. * Since the reseed interval is independent of any request
  1125. * for prediction resistance, and since the reseed interval
  1126. * is not specified as part of the NIST test vector set,
  1127. * then this cannot be the source of the "Reseed required"
  1128. * failure expected by the NIST test vector set.
  1129. *
  1130. * b) Generate_function cannot return a "reseed required"
  1131. * status under any circumstances. If the underlying
  1132. * HMAC_DRBG_Generate_algorithm call returns "reseed
  1133. * required", then Generate_function will automatically
  1134. * reseed and try again.
  1135. *
  1136. * To produce the behaviour expected by the NIST test vector
  1137. * set, we therefore contrive to produce a "reseed required"
  1138. * state where necessary by setting the reseed_counter to
  1139. * greater than the reseed_interval.
  1140. */
  1141. /* SHA-1 Test 1 */
  1142. instantiate_ok ( &state, &sha1_instantiate_1 );
  1143. generate_ok ( &state, &sha1_generate_1_1 );
  1144. generate_ok ( &state, &sha1_generate_1_2 );
  1145. /* SHA-1 Test 2 */
  1146. instantiate_ok ( &state, &sha1_instantiate_2 );
  1147. generate_ok ( &state, &sha1_generate_2_1 );
  1148. generate_ok ( &state, &sha1_generate_2_2 );
  1149. /* SHA-1 Test 3 */
  1150. instantiate_ok ( &state, &sha1_instantiate_3 );
  1151. generate_ok ( &state, &sha1_generate_3_1 );
  1152. generate_ok ( &state, &sha1_generate_3_2 );
  1153. /* SHA-1 Test 4 */
  1154. instantiate_ok ( &state, &sha1_instantiate_4 );
  1155. generate_ok ( &state, &sha1_generate_4_1 );
  1156. generate_ok ( &state, &sha1_generate_4_2 );
  1157. /* SHA-1 Test 5 */
  1158. instantiate_ok ( &state, &sha1_instantiate_5 );
  1159. force_reseed_required ( &state ); /* See above comments */
  1160. generate_fail_ok ( &state, &sha1_generate_fail_5_1 );
  1161. reseed_ok ( &state, &sha1_reseed_5_2 );
  1162. generate_ok ( &state, &sha1_generate_5_3 );
  1163. force_reseed_required ( &state ); /* See above comments */
  1164. generate_fail_ok ( &state, &sha1_generate_fail_5_4 );
  1165. reseed_ok ( &state, &sha1_reseed_5_5 );
  1166. generate_ok ( &state, &sha1_generate_5_6 );
  1167. /* SHA-1 Test 6 */
  1168. instantiate_ok ( &state, &sha1_instantiate_6 );
  1169. force_reseed_required ( &state ); /* See above comments */
  1170. generate_fail_ok ( &state, &sha1_generate_fail_6_1 );
  1171. reseed_ok ( &state, &sha1_reseed_6_2 );
  1172. generate_ok ( &state, &sha1_generate_6_3 );
  1173. force_reseed_required ( &state ); /* See above comments */
  1174. generate_fail_ok ( &state, &sha1_generate_fail_6_4 );
  1175. reseed_ok ( &state, &sha1_reseed_6_5 );
  1176. generate_ok ( &state, &sha1_generate_6_6 );
  1177. /* SHA-1 Test 7 */
  1178. instantiate_ok ( &state, &sha1_instantiate_7 );
  1179. force_reseed_required ( &state ); /* See above comments */
  1180. generate_fail_ok ( &state, &sha1_generate_fail_7_1 );
  1181. reseed_ok ( &state, &sha1_reseed_7_2 );
  1182. generate_ok ( &state, &sha1_generate_7_3 );
  1183. force_reseed_required ( &state ); /* See above comments */
  1184. generate_fail_ok ( &state, &sha1_generate_fail_7_4 );
  1185. reseed_ok ( &state, &sha1_reseed_7_5 );
  1186. generate_ok ( &state, &sha1_generate_7_6 );
  1187. /* SHA-1 Test 8 */
  1188. instantiate_ok ( &state, &sha1_instantiate_8 );
  1189. force_reseed_required ( &state ); /* See above comments */
  1190. generate_fail_ok ( &state, &sha1_generate_fail_8_1 );
  1191. reseed_ok ( &state, &sha1_reseed_8_2 );
  1192. generate_ok ( &state, &sha1_generate_8_3 );
  1193. force_reseed_required ( &state ); /* See above comments */
  1194. generate_fail_ok ( &state, &sha1_generate_fail_8_4 );
  1195. reseed_ok ( &state, &sha1_reseed_8_5 );
  1196. generate_ok ( &state, &sha1_generate_8_6 );
  1197. /* SHA-256 Test 1 */
  1198. instantiate_ok ( &state, &sha256_instantiate_1 );
  1199. generate_ok ( &state, &sha256_generate_1_1 );
  1200. generate_ok ( &state, &sha256_generate_1_2 );
  1201. /* SHA-256 Test 2 */
  1202. instantiate_ok ( &state, &sha256_instantiate_2 );
  1203. generate_ok ( &state, &sha256_generate_2_1 );
  1204. generate_ok ( &state, &sha256_generate_2_2 );
  1205. /* SHA-256 Test 3 */
  1206. instantiate_ok ( &state, &sha256_instantiate_3 );
  1207. generate_ok ( &state, &sha256_generate_3_1 );
  1208. generate_ok ( &state, &sha256_generate_3_2 );
  1209. /* SHA-256 Test 4 */
  1210. instantiate_ok ( &state, &sha256_instantiate_4 );
  1211. generate_ok ( &state, &sha256_generate_4_1 );
  1212. generate_ok ( &state, &sha256_generate_4_2 );
  1213. /* SHA-256 Test 5 */
  1214. instantiate_ok ( &state, &sha256_instantiate_5 );
  1215. force_reseed_required ( &state ); /* See above comments */
  1216. generate_fail_ok ( &state, &sha256_generate_fail_5_1 );
  1217. reseed_ok ( &state, &sha256_reseed_5_2 );
  1218. generate_ok ( &state, &sha256_generate_5_3 );
  1219. force_reseed_required ( &state ); /* See above comments */
  1220. generate_fail_ok ( &state, &sha256_generate_fail_5_4 );
  1221. reseed_ok ( &state, &sha256_reseed_5_5 );
  1222. generate_ok ( &state, &sha256_generate_5_6 );
  1223. /* SHA-256 Test 6 */
  1224. instantiate_ok ( &state, &sha256_instantiate_6 );
  1225. force_reseed_required ( &state ); /* See above comments */
  1226. generate_fail_ok ( &state, &sha256_generate_fail_6_1 );
  1227. reseed_ok ( &state, &sha256_reseed_6_2 );
  1228. generate_ok ( &state, &sha256_generate_6_3 );
  1229. force_reseed_required ( &state ); /* See above comments */
  1230. generate_fail_ok ( &state, &sha256_generate_fail_6_4 );
  1231. reseed_ok ( &state, &sha256_reseed_6_5 );
  1232. generate_ok ( &state, &sha256_generate_6_6 );
  1233. /* SHA-256 Test 7 */
  1234. instantiate_ok ( &state, &sha256_instantiate_7 );
  1235. force_reseed_required ( &state ); /* See above comments */
  1236. generate_fail_ok ( &state, &sha256_generate_fail_7_1 );
  1237. reseed_ok ( &state, &sha256_reseed_7_2 );
  1238. generate_ok ( &state, &sha256_generate_7_3 );
  1239. force_reseed_required ( &state ); /* See above comments */
  1240. generate_fail_ok ( &state, &sha256_generate_fail_7_4 );
  1241. reseed_ok ( &state, &sha256_reseed_7_5 );
  1242. generate_ok ( &state, &sha256_generate_7_6 );
  1243. /* SHA-256 Test 8 */
  1244. instantiate_ok ( &state, &sha256_instantiate_8 );
  1245. force_reseed_required ( &state ); /* See above comments */
  1246. generate_fail_ok ( &state, &sha256_generate_fail_8_1 );
  1247. reseed_ok ( &state, &sha256_reseed_8_2 );
  1248. generate_ok ( &state, &sha256_generate_8_3 );
  1249. force_reseed_required ( &state ); /* See above comments */
  1250. generate_fail_ok ( &state, &sha256_generate_fail_8_4 );
  1251. reseed_ok ( &state, &sha256_reseed_8_5 );
  1252. generate_ok ( &state, &sha256_generate_8_6 );
  1253. }
  1254. /** HMAC_DRBG self-test */
  1255. struct self_test hmac_drbg_test __self_test = {
  1256. .name = "hmac_drbg",
  1257. .exec = hmac_drbg_test_exec,
  1258. };