1 // Copyright 2021 Google LLC
2 //
3 // Licensed under the Apache License, Version 2.0 (the "License");
4 // you may not use this file except in compliance with the License.
5 // You may obtain a copy of the License at
6 //
7 // http://www.apache.org/licenses/LICENSE-2.0
8 //
9 // Unless required by applicable law or agreed to in writing, software
10 // distributed under the License is distributed on an "AS IS" BASIS,
11 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 // See the License for the specific language governing permissions and
13 // limitations under the License.
14 //
15 ///////////////////////////////////////////////////////////////////////////////
16
17 #include <memory>
18 #include <string>
19 #include <utility>
20
21 #include "gmock/gmock.h"
22 #include "gtest/gtest.h"
23 #include "tink/experimental/pqcrypto/signature/dilithium_sign_key_manager.h"
24 #include "tink/experimental/pqcrypto/signature/dilithium_verify_key_manager.h"
25 #include "tink/experimental/pqcrypto/signature/signature_config.h"
26 #include "tink/internal/fips_utils.h"
27 #include "tink/public_key_sign.h"
28 #include "tink/public_key_verify.h"
29 #include "tink/registry.h"
30 #include "tink/util/status.h"
31 #include "tink/util/test_matchers.h"
32 #include "tink/util/test_util.h"
33
34 namespace crypto {
35 namespace tink {
36 namespace {
37
38 using ::crypto::tink::test::DummyPublicKeySign;
39 using ::crypto::tink::test::DummyPublicKeyVerify;
40 using ::crypto::tink::test::IsOk;
41
42 class PcqSignatureConfigTest : public ::testing::Test {
43 protected:
SetUp()44 void SetUp() override { Registry::Reset(); }
45 };
46
TEST_F(PcqSignatureConfigTest,CheckStatus)47 TEST_F(PcqSignatureConfigTest, CheckStatus) {
48 if (internal::IsFipsModeEnabled() && !internal::IsFipsEnabledInSsl()) {
49 GTEST_SKIP() << "Not supported if FIPS-mode is used";
50 }
51
52 EXPECT_THAT(PqSignatureConfigRegister(), IsOk());
53 }
54
55 // Tests that the PublicKeySignWrapper has been properly registered and we
56 // can wrap primitives.
TEST_F(PcqSignatureConfigTest,PublicKeySignWrapperRegistered)57 TEST_F(PcqSignatureConfigTest, PublicKeySignWrapperRegistered) {
58 if (internal::IsFipsModeEnabled() && !internal::IsFipsEnabledInSsl()) {
59 GTEST_SKIP() << "Not supported if FIPS-mode is used";
60 }
61
62 ASSERT_THAT(PqSignatureConfigRegister(), IsOk());
63
64 google::crypto::tink::KeysetInfo::KeyInfo key_info;
65 key_info.set_status(google::crypto::tink::KeyStatusType::ENABLED);
66 key_info.set_key_id(1234);
67 key_info.set_output_prefix_type(google::crypto::tink::OutputPrefixType::TINK);
68
69 auto primitive_set = absl::make_unique<PrimitiveSet<PublicKeySign>>();
70 auto add_primitive = primitive_set->AddPrimitive(
71 absl::make_unique<DummyPublicKeySign>("dummy"), key_info);
72 ASSERT_THAT(add_primitive, IsOk());
73 ASSERT_THAT(primitive_set->set_primary(*add_primitive), IsOk());
74
75 util::StatusOr<std::unique_ptr<crypto::tink::PublicKeySign>> wrapped =
76 Registry::Wrap(std::move(primitive_set));
77 ASSERT_THAT(wrapped, IsOk());
78
79 util::StatusOr<std::string> signature_result = (*wrapped)->Sign("message");
80 ASSERT_THAT(signature_result, IsOk());
81
82 util::StatusOr<std::string> prefix = CryptoFormat::GetOutputPrefix(key_info);
83 ASSERT_THAT(prefix, IsOk());
84 util::StatusOr<std::string> signature =
85 DummyPublicKeySign("dummy").Sign("message");
86 ASSERT_THAT(signature, IsOk());
87
88 EXPECT_EQ(*signature_result, absl::StrCat(*prefix, *signature));
89 }
90
91 // Tests that the PublicKeyVerifyWrapper has been properly registered and we
92 // can wrap primitives.
TEST_F(PcqSignatureConfigTest,PublicKeyVerifyWrapperRegistered)93 TEST_F(PcqSignatureConfigTest, PublicKeyVerifyWrapperRegistered) {
94 if (internal::IsFipsModeEnabled() && !internal::IsFipsEnabledInSsl()) {
95 GTEST_SKIP() << "Not supported if FIPS-mode is used";
96 }
97
98 ASSERT_THAT(PqSignatureConfigRegister(), IsOk());
99
100 google::crypto::tink::KeysetInfo::KeyInfo key_info;
101 key_info.set_status(google::crypto::tink::KeyStatusType::ENABLED);
102 key_info.set_key_id(1234);
103 key_info.set_output_prefix_type(google::crypto::tink::OutputPrefixType::TINK);
104
105 auto primitive_set = absl::make_unique<PrimitiveSet<PublicKeyVerify>>();
106 auto add_primitive = primitive_set->AddPrimitive(
107 absl::make_unique<DummyPublicKeyVerify>("dummy"), key_info);
108 ASSERT_THAT(add_primitive, IsOk());
109 ASSERT_THAT(primitive_set->set_primary(*add_primitive), IsOk());
110
111 util::StatusOr<std::unique_ptr<crypto::tink::PublicKeyVerify>> wrapped =
112 Registry::Wrap(std::move(primitive_set));
113 ASSERT_THAT(wrapped, IsOk());
114
115 util::StatusOr<std::string> prefix = CryptoFormat::GetOutputPrefix(key_info);
116 ASSERT_THAT(prefix, IsOk());
117 util::StatusOr<std::string> signature =
118 DummyPublicKeySign("dummy").Sign("message");
119 ASSERT_THAT(signature, IsOk());
120
121 ASSERT_THAT((*wrapped)->Verify(absl::StrCat(*prefix, *signature), "message"),
122 IsOk());
123 }
124
125
126 } // namespace
127 } // namespace tink
128 } // namespace crypto
129