test_vectors.c 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936
  1. /*
  2. * test_vectors - IEEE 802.11 test vector generator
  3. * Copyright (c) 2012, Jouni Malinen <j@w1.fi>
  4. *
  5. * This software may be distributed under the terms of the BSD license.
  6. * See README for more details.
  7. */
  8. #include "utils/includes.h"
  9. #include "utils/common.h"
  10. #include "utils/eloop.h"
  11. #include "common/ieee802_11_defs.h"
  12. #include "wlantest.h"
  13. static void test_vector_tkip(void)
  14. {
  15. u8 tk[] = {
  16. 0x12, 0x34, 0x56, 0x78, 0x90, 0x12, 0x34, 0x56,
  17. 0x78, 0x90, 0x12, 0x34, 0x56, 0x78, 0x90, 0x12,
  18. 0x34, 0x56, 0x78, 0x90, 0x12, 0x34, 0x56, 0x78,
  19. 0x90, 0x12, 0x34, 0x56, 0x78, 0x90, 0x12, 0x34
  20. };
  21. u8 pn[] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 };
  22. u8 frame[] = {
  23. 0x08, 0x42, 0x2c, 0x00, 0x02, 0x03, 0x04, 0x05,
  24. 0x06, 0x08, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
  25. 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0xd0, 0x02,
  26. /* 0x00, 0x20, 0x01, 0x20, 0x00, 0x00, 0x00, 0x00, */
  27. 0xaa, 0xaa, 0x03, 0x00, 0x00, 0x00, 0x08, 0x00,
  28. 0x45, 0x00, 0x00, 0x54, 0x00, 0x00, 0x40, 0x00,
  29. 0x40, 0x01, 0xa5, 0x55, 0xc0, 0xa8, 0x0a, 0x02,
  30. 0xc0, 0xa8, 0x0a, 0x01, 0x08, 0x00, 0x3a, 0xb0,
  31. 0x00, 0x00, 0x00, 0x00, 0xcd, 0x4c, 0x05, 0x00,
  32. 0x00, 0x00, 0x00, 0x00, 0x08, 0x09, 0x0a, 0x0b,
  33. 0x0c, 0x0d, 0x0e, 0x0f, 0x10, 0x11, 0x12, 0x13,
  34. 0x14, 0x15, 0x16, 0x17, 0x18, 0x19, 0x1a, 0x1b,
  35. 0x1c, 0x1d, 0x1e, 0x1f, 0x20, 0x21, 0x22, 0x23,
  36. 0x24, 0x25, 0x26, 0x27, 0x28, 0x29, 0x2a, 0x2b,
  37. 0x2c, 0x2d, 0x2e, 0x2f, 0x30, 0x31, 0x32, 0x33,
  38. 0x34, 0x35, 0x36, 0x37,
  39. /* 0x68, 0x81, 0xa3, 0xf3, 0xd6, 0x48, 0xd0, 0x3c */
  40. };
  41. u8 *enc, *plain;
  42. size_t enc_len, plain_len;
  43. wpa_printf(MSG_INFO, "\nIEEE Std 802.11-2012, M.6.3 TKIP test "
  44. "vector\n");
  45. wpa_hexdump(MSG_INFO, "TK", tk, sizeof(tk));
  46. wpa_hexdump(MSG_INFO, "PN", pn, sizeof(pn));
  47. wpa_hexdump(MSG_INFO, "Plaintext MPDU", frame, sizeof(frame));
  48. enc = tkip_encrypt(tk, frame, sizeof(frame), 24, NULL, pn, 0, &enc_len);
  49. if (enc == NULL) {
  50. wpa_printf(MSG_ERROR, "Failed to encrypt TKIP frame");
  51. return;
  52. }
  53. wpa_hexdump(MSG_INFO, "Encrypted MPDU (without FCS)", enc, enc_len);
  54. wpa_debug_level = MSG_INFO;
  55. plain = tkip_decrypt(tk, (const struct ieee80211_hdr *) enc,
  56. enc + 24, enc_len - 24, &plain_len);
  57. wpa_debug_level = MSG_EXCESSIVE;
  58. os_free(enc);
  59. if (plain == NULL) {
  60. wpa_printf(MSG_ERROR, "Failed to decrypt TKIP frame");
  61. return;
  62. }
  63. if (plain_len != sizeof(frame) - 24 ||
  64. os_memcmp(plain, frame + 24, plain_len) != 0) {
  65. wpa_hexdump(MSG_ERROR, "Decryption result did not match",
  66. plain, plain_len);
  67. }
  68. os_free(plain);
  69. }
  70. static void test_vector_ccmp(void)
  71. {
  72. u8 tk[] = { 0xc9, 0x7c, 0x1f, 0x67, 0xce, 0x37, 0x11, 0x85,
  73. 0x51, 0x4a, 0x8a, 0x19, 0xf2, 0xbd, 0xd5, 0x2f };
  74. u8 pn[] = { 0xB5, 0x03, 0x97, 0x76, 0xE7, 0x0C };
  75. u8 frame[] = {
  76. 0x08, 0x48, 0xc3, 0x2c, 0x0f, 0xd2, 0xe1, 0x28,
  77. 0xa5, 0x7c, 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08,
  78. 0xab, 0xae, 0xa5, 0xb8, 0xfc, 0xba, 0x80, 0x33,
  79. 0xf8, 0xba, 0x1a, 0x55, 0xd0, 0x2f, 0x85, 0xae,
  80. 0x96, 0x7b, 0xb6, 0x2f, 0xb6, 0xcd, 0xa8, 0xeb,
  81. 0x7e, 0x78, 0xa0, 0x50
  82. };
  83. u8 *enc, *plain;
  84. size_t enc_len, plain_len;
  85. u8 fcs[4];
  86. wpa_printf(MSG_INFO, "\nIEEE Std 802.11-2012, M.6.4 CCMP test "
  87. "vector\n");
  88. wpa_hexdump(MSG_INFO, "TK", tk, sizeof(tk));
  89. wpa_hexdump(MSG_INFO, "PN", pn, sizeof(pn));
  90. wpa_hexdump(MSG_INFO, "802.11 Header", frame, 24);
  91. wpa_hexdump(MSG_INFO, "Plaintext Data", frame + 24, sizeof(frame) - 24);
  92. enc = ccmp_encrypt(tk, frame, sizeof(frame), 24, NULL, pn, 0, &enc_len);
  93. if (enc == NULL) {
  94. wpa_printf(MSG_ERROR, "Failed to encrypt CCMP frame");
  95. return;
  96. }
  97. wpa_hexdump(MSG_INFO, "Encrypted MPDU (without FCS)", enc, enc_len);
  98. WPA_PUT_LE32(fcs, crc32(enc, enc_len));
  99. wpa_hexdump(MSG_INFO, "FCS", fcs, sizeof(fcs));
  100. wpa_debug_level = MSG_INFO;
  101. plain = ccmp_decrypt(tk, (const struct ieee80211_hdr *) enc,
  102. enc + 24, enc_len - 24, &plain_len);
  103. wpa_debug_level = MSG_EXCESSIVE;
  104. os_free(enc);
  105. if (plain == NULL) {
  106. wpa_printf(MSG_ERROR, "Failed to decrypt CCMP frame");
  107. return;
  108. }
  109. if (plain_len != sizeof(frame) - 24 ||
  110. os_memcmp(plain, frame + 24, plain_len) != 0) {
  111. wpa_hexdump(MSG_ERROR, "Decryption result did not match",
  112. plain, plain_len);
  113. }
  114. os_free(plain);
  115. }
  116. static void test_vector_ccmp_pv1(void)
  117. {
  118. u8 tk[] = { 0xc9, 0x7c, 0x1f, 0x67, 0xce, 0x37, 0x11, 0x85,
  119. 0x51, 0x4a, 0x8a, 0x19, 0xf2, 0xbd, 0xd5, 0x2f };
  120. u8 pn[8];
  121. u8 frame1[] = {
  122. 0x61, 0x00, 0xa2, 0xae, 0xa5, 0xb8, 0xfc, 0xba,
  123. 0x07, 0x00, 0x80, 0x33,
  124. 0xf8, 0xba, 0x1a, 0x55, 0xd0, 0x2f, 0x85, 0xae,
  125. 0x96, 0x7b, 0xb6, 0x2f, 0xb6, 0xcd, 0xa8, 0xeb,
  126. 0x7e, 0x78, 0xa0, 0x50
  127. };
  128. u8 frame2[] = {
  129. 0x61, 0x00, 0xa2, 0xae, 0xa5, 0xb8, 0xfc, 0xba,
  130. 0x07, 0x20, 0x80, 0x33, 0x02, 0xd2, 0xe1, 0x28,
  131. 0xa5, 0x7c,
  132. 0xf8, 0xba, 0x1a, 0x55, 0xd0, 0x2f, 0x85, 0xae,
  133. 0x96, 0x7b, 0xb6, 0x2f, 0xb6, 0xcd, 0xa8, 0xeb,
  134. 0x7e, 0x78, 0xa0, 0x50
  135. };
  136. u8 frame3[] = {
  137. 0x6d, 0x00, 0xa2, 0xae, 0xa5, 0xb8, 0xfc, 0xba,
  138. 0x52, 0x30, 0xf1, 0x84, 0x44, 0x08, 0x80, 0x33,
  139. 0xf8, 0xba, 0x1a, 0x55, 0xd0, 0x2f, 0x85, 0xae,
  140. 0x96, 0x7b, 0xb6, 0x2f, 0xb6, 0xcd, 0xa8, 0xeb,
  141. 0x7e, 0x78, 0xa0, 0x50
  142. };
  143. u8 *enc;
  144. size_t enc_len;
  145. u8 fcs[4];
  146. u8 bssid[ETH_ALEN] = { 0xa2, 0xae, 0xa5, 0xb8, 0xfc, 0xba };
  147. u8 da[ETH_ALEN] = { 0x02, 0xd2, 0xe1, 0x28, 0xa5, 0x7c };
  148. u8 sa[ETH_ALEN] = { 0x52, 0x30, 0xf1, 0x84, 0x44, 0x08 };
  149. u16 aid = 7;
  150. u32 bpn = 123;
  151. u16 sc = 0x3380;
  152. int key_id = 0;
  153. u16 fc;
  154. int tid = 3;
  155. u16 sid;
  156. wpa_printf(MSG_INFO,
  157. "\nIEEE P802.11ah/D10.0, J.6.4 CCMP PV1 test vectors\n");
  158. wpa_printf(MSG_INFO, "BSSID: " MACSTR, MAC2STR(bssid));
  159. wpa_printf(MSG_INFO, "DA: " MACSTR, MAC2STR(da));
  160. wpa_printf(MSG_INFO, "SA: " MACSTR, MAC2STR(sa));
  161. wpa_printf(MSG_INFO, "Association ID: %u", aid);
  162. wpa_printf(MSG_INFO, "Base PN: %u (0x%08x)", bpn, bpn);
  163. wpa_printf(MSG_INFO, "SC = 0x%04x (FragNum=%u SeqNum=%u)",
  164. sc, WLAN_GET_SEQ_FRAG(sc), WLAN_GET_SEQ_SEQ(sc));
  165. wpa_printf(MSG_INFO, "TID = %u", tid);
  166. wpa_printf(MSG_INFO, "Key ID: %u", key_id);
  167. wpa_hexdump(MSG_INFO, "TK", tk, sizeof(tk));
  168. wpa_printf(MSG_INFO, "PN = SC||BPN");
  169. WPA_PUT_LE16(&pn[0], sc);
  170. WPA_PUT_LE32(&pn[2], bpn);
  171. wpa_hexdump(MSG_INFO, "PN (PN0..PN5)", pn, sizeof(pn));
  172. wpa_printf(MSG_INFO,
  173. "\nPV1 test vector #1:\nHeader compression used and A3 was previously stored at the receiver\n");
  174. fc = WPA_GET_LE16(frame1);
  175. wpa_printf(MSG_INFO,
  176. "FC=0x%04x (PV=%u Type=%u PTID/Subtype=%u From_DS=%u More_Fragments=%u Power_Management=%u More_Data=%u Protected_Frame=%u End_of_SP=%u Relayed_Frame=%u Ack_Policy=%u)",
  177. fc,
  178. fc & WLAN_FC_PVER,
  179. (fc & (BIT(2) | BIT(3) | BIT(4))) >> 2,
  180. (fc & (BIT(5) | BIT(6) | BIT(7))) >> 5,
  181. !!(fc & BIT(8)),
  182. !!(fc & BIT(9)),
  183. !!(fc & BIT(10)),
  184. !!(fc & BIT(11)),
  185. !!(fc & BIT(12)),
  186. !!(fc & BIT(13)),
  187. !!(fc & BIT(14)),
  188. !!(fc & BIT(15)));
  189. wpa_printf(MSG_INFO, "A1=" MACSTR, MAC2STR(&frame1[2]));
  190. sid = WPA_GET_LE16(&frame1[8]);
  191. wpa_printf(MSG_INFO,
  192. "A2=%02x %02x (SID: AID=%u A3_Present=%u A4_Present=%u A-MSDU=%u); corresponds to 52:30:f1:84:44:08 in uncompressed header",
  193. frame1[8], frame1[9],
  194. sid & ~(BIT(13) | BIT(14) | BIT(15)),
  195. !!(sid & BIT(13)),
  196. !!(sid & BIT(14)),
  197. !!(sid & BIT(15)));
  198. sc = WPA_GET_LE16(&frame1[10]);
  199. wpa_printf(MSG_INFO, "Sequence Control: %02x %02x (FN=%u SN=%u)",
  200. frame1[10], frame1[11],
  201. WLAN_GET_SEQ_FRAG(sc), WLAN_GET_SEQ_SEQ(sc));
  202. wpa_printf(MSG_INFO, "A3 not present; corresponds to 02:d2:e1:28:a5:7c in uncompressed header");
  203. wpa_printf(MSG_INFO, "A4 not present");
  204. wpa_hexdump(MSG_INFO, "Plaintext Frame Header", frame1, 12);
  205. wpa_hexdump(MSG_INFO, "Plaintext Frame Body",
  206. frame1 + 12, sizeof(frame1) - 12);
  207. enc = ccmp_encrypt_pv1(tk, &frame1[2], sa, da, frame1, sizeof(frame1),
  208. 12, pn, key_id, &enc_len);
  209. if (enc == NULL) {
  210. wpa_printf(MSG_ERROR, "Failed to encrypt CCMP frame");
  211. return;
  212. }
  213. wpa_hexdump(MSG_INFO, "Encrypted Frame Header", enc, 12);
  214. wpa_hexdump(MSG_INFO, "Encrypted Frame Frame Body",
  215. enc + 12, enc_len - 12);
  216. WPA_PUT_LE32(fcs, crc32(enc, enc_len));
  217. wpa_hexdump(MSG_INFO, "Encrypted Frame FCS", fcs, sizeof(fcs));
  218. wpa_printf(MSG_INFO,
  219. "\nPV1 test vector #2:\nHeader compression used and A3 was not previously stored at the receiver\n");
  220. fc = WPA_GET_LE16(frame2);
  221. wpa_printf(MSG_INFO,
  222. "FC=0x%04x (PV=%u Type=%u PTID/Subtype=%u From_DS=%u More_Fragments=%u Power_Management=%u More_Data=%u Protected_Frame=%u End_of_SP=%u Relayed_Frame=%u Ack_Policy=%u)",
  223. fc,
  224. fc & WLAN_FC_PVER,
  225. (fc & (BIT(2) | BIT(3) | BIT(4))) >> 2,
  226. (fc & (BIT(5) | BIT(6) | BIT(7))) >> 5,
  227. !!(fc & BIT(8)),
  228. !!(fc & BIT(9)),
  229. !!(fc & BIT(10)),
  230. !!(fc & BIT(11)),
  231. !!(fc & BIT(12)),
  232. !!(fc & BIT(13)),
  233. !!(fc & BIT(14)),
  234. !!(fc & BIT(15)));
  235. wpa_printf(MSG_INFO, "A1=" MACSTR, MAC2STR(&frame2[2]));
  236. sid = WPA_GET_LE16(&frame2[8]);
  237. wpa_printf(MSG_INFO,
  238. "A2=%02x %02x (SID: AID=%u A3_Present=%u A4_Present=%u A-MSDU=%u); corresponds to 52:30:f1:84:44:08 in uncompressed header",
  239. frame2[8], frame2[9],
  240. sid & ~(BIT(13) | BIT(14) | BIT(15)),
  241. !!(sid & BIT(13)),
  242. !!(sid & BIT(14)),
  243. !!(sid & BIT(15)));
  244. sc = WPA_GET_LE16(&frame2[10]);
  245. wpa_printf(MSG_INFO, "Sequence Control: %02x %02x (FN=%u SN=%u)",
  246. frame2[10], frame2[11],
  247. WLAN_GET_SEQ_FRAG(sc), WLAN_GET_SEQ_SEQ(sc));
  248. wpa_printf(MSG_INFO, "A3=" MACSTR, MAC2STR(&frame2[12]));
  249. wpa_printf(MSG_INFO, "A4 not present");
  250. wpa_hexdump(MSG_INFO, "Plaintext Frame Header", frame2, 18);
  251. wpa_hexdump(MSG_INFO, "Plaintext Frame Body",
  252. frame2 + 18, sizeof(frame2) - 18);
  253. enc = ccmp_encrypt_pv1(tk, &frame2[2], sa, &frame2[12],
  254. frame2, sizeof(frame2), 18, pn, key_id,
  255. &enc_len);
  256. if (enc == NULL) {
  257. wpa_printf(MSG_ERROR, "Failed to encrypt CCMP frame");
  258. return;
  259. }
  260. wpa_hexdump(MSG_INFO, "Encrypted Frame Header", enc, 18);
  261. wpa_hexdump(MSG_INFO, "Encrypted Frame Frame Body",
  262. enc + 18, enc_len - 18);
  263. WPA_PUT_LE32(fcs, crc32(enc, enc_len));
  264. wpa_hexdump(MSG_INFO, "Encrypted Frame FCS", fcs, sizeof(fcs));
  265. wpa_printf(MSG_INFO,
  266. "\nPV1 test vector #3:\nType 3 frame from SA to DA(=BSSID) (i.e., no separate DA in this example)\n");
  267. fc = WPA_GET_LE16(frame3);
  268. wpa_printf(MSG_INFO,
  269. "FC=0x%04x (PV=%u Type=%u PTID/Subtype=%u From_DS=%u More_Fragments=%u Power_Management=%u More_Data=%u Protected_Frame=%u End_of_SP=%u Relayed_Frame=%u Ack_Policy=%u)",
  270. fc,
  271. fc & WLAN_FC_PVER,
  272. (fc & (BIT(2) | BIT(3) | BIT(4))) >> 2,
  273. (fc & (BIT(5) | BIT(6) | BIT(7))) >> 5,
  274. !!(fc & BIT(8)),
  275. !!(fc & BIT(9)),
  276. !!(fc & BIT(10)),
  277. !!(fc & BIT(11)),
  278. !!(fc & BIT(12)),
  279. !!(fc & BIT(13)),
  280. !!(fc & BIT(14)),
  281. !!(fc & BIT(15)));
  282. wpa_printf(MSG_INFO, "A1=" MACSTR, MAC2STR(&frame3[2]));
  283. wpa_printf(MSG_INFO, "A2=" MACSTR, MAC2STR(&frame3[8]));
  284. sc = WPA_GET_LE16(&frame3[14]);
  285. wpa_printf(MSG_INFO, "Sequence Control: %02x %02x (FN=%u SN=%u)",
  286. frame3[14], frame3[15],
  287. WLAN_GET_SEQ_FRAG(sc), WLAN_GET_SEQ_SEQ(sc));
  288. wpa_printf(MSG_INFO,
  289. "A3 not present; corresponds to 02:d2:e1:28:a5:7c in uncompressed header");
  290. wpa_printf(MSG_INFO, "A4 not present");
  291. wpa_hexdump(MSG_INFO, "Plaintext Frame Header", frame3, 16);
  292. wpa_hexdump(MSG_INFO, "Plaintext Frame Body",
  293. frame3 + 16, sizeof(frame3) - 16);
  294. enc = ccmp_encrypt_pv1(tk, &frame3[2], &frame3[8], da,
  295. frame3, sizeof(frame3), 16, pn, key_id,
  296. &enc_len);
  297. if (enc == NULL) {
  298. wpa_printf(MSG_ERROR, "Failed to encrypt CCMP frame");
  299. return;
  300. }
  301. wpa_hexdump(MSG_INFO, "Encrypted Frame Header", enc, 16);
  302. wpa_hexdump(MSG_INFO, "Encrypted Frame Frame Body",
  303. enc + 16, enc_len - 16);
  304. WPA_PUT_LE32(fcs, crc32(enc, enc_len));
  305. wpa_hexdump(MSG_INFO, "Encrypted Frame FCS", fcs, sizeof(fcs));
  306. wpa_debug_level = MSG_INFO;
  307. }
  308. static void test_vector_bip(void)
  309. {
  310. u8 igtk[] = {
  311. 0x4e, 0xa9, 0x54, 0x3e, 0x09, 0xcf, 0x2b, 0x1e,
  312. 0xca, 0x66, 0xff, 0xc5, 0x8b, 0xde, 0xcb, 0xcf
  313. };
  314. u8 ipn[] = { 0x04, 0x00, 0x00, 0x00, 0x00, 0x00 };
  315. u8 frame[] = {
  316. 0xc0, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff,
  317. 0xff, 0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00,
  318. 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x09, 0x00,
  319. 0x02, 0x00
  320. };
  321. u8 *prot;
  322. size_t prot_len;
  323. wpa_printf(MSG_INFO, "\nIEEE Std 802.11-2012, M.9.1 BIP with broadcast "
  324. "Deauthentication frame\n");
  325. wpa_hexdump(MSG_INFO, "IGTK", igtk, sizeof(igtk));
  326. wpa_hexdump(MSG_INFO, "IPN", ipn, sizeof(ipn));
  327. wpa_hexdump(MSG_INFO, "Plaintext frame", frame, sizeof(frame));
  328. prot = bip_protect(igtk, sizeof(igtk), frame, sizeof(frame),
  329. ipn, 4, &prot_len);
  330. if (prot == NULL) {
  331. wpa_printf(MSG_ERROR, "Failed to protect BIP frame");
  332. return;
  333. }
  334. wpa_hexdump(MSG_INFO, "Protected MPDU (without FCS)", prot, prot_len);
  335. os_free(prot);
  336. }
  337. static void test_vector_ccmp_mgmt(void)
  338. {
  339. u8 tk[] = { 0x66, 0xed, 0x21, 0x04, 0x2f, 0x9f, 0x26, 0xd7,
  340. 0x11, 0x57, 0x06, 0xe4, 0x04, 0x14, 0xcf, 0x2e };
  341. u8 pn[] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 };
  342. u8 frame[] = {
  343. 0xc0, 0x00, 0x00, 0x00, 0x02, 0x00, 0x00, 0x00,
  344. 0x01, 0x00, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00,
  345. 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x60, 0x00,
  346. 0x02, 0x00
  347. };
  348. u8 *enc, *plain;
  349. size_t enc_len, plain_len;
  350. wpa_printf(MSG_INFO, "\nIEEE Std 802.11-2012, M.9.2 CCMP with unicast "
  351. "Deauthentication frame\n");
  352. wpa_hexdump(MSG_INFO, "TK", tk, sizeof(tk));
  353. wpa_hexdump(MSG_INFO, "PN", pn, sizeof(pn));
  354. wpa_hexdump(MSG_INFO, "802.11 Header", frame, 24);
  355. wpa_hexdump(MSG_INFO, "Plaintext Data", frame + 24, sizeof(frame) - 24);
  356. enc = ccmp_encrypt(tk, frame, sizeof(frame), 24, NULL, pn, 0, &enc_len);
  357. if (enc == NULL) {
  358. wpa_printf(MSG_ERROR, "Failed to encrypt CCMP frame");
  359. return;
  360. }
  361. wpa_hexdump(MSG_INFO, "Encrypted MPDU (without FCS)", enc, enc_len);
  362. wpa_debug_level = MSG_INFO;
  363. plain = ccmp_decrypt(tk, (const struct ieee80211_hdr *) enc,
  364. enc + 24, enc_len - 24, &plain_len);
  365. wpa_debug_level = MSG_EXCESSIVE;
  366. os_free(enc);
  367. if (plain == NULL) {
  368. wpa_printf(MSG_ERROR, "Failed to decrypt CCMP frame");
  369. return;
  370. }
  371. if (plain_len != sizeof(frame) - 24 ||
  372. os_memcmp(plain, frame + 24, plain_len) != 0) {
  373. wpa_hexdump(MSG_ERROR, "Decryption result did not match",
  374. plain, plain_len);
  375. }
  376. os_free(plain);
  377. }
  378. struct gcmp_test {
  379. u8 tk[16];
  380. u8 pn[6];
  381. u8 frame[300];
  382. size_t hdr_len;
  383. size_t payload_len;
  384. u8 mic[16];
  385. u8 encr[300];
  386. };
  387. static const struct gcmp_test gcmp_vectors[] =
  388. {
  389. {
  390. .tk = { 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa,
  391. 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa },
  392. .pn = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 },
  393. .frame = {
  394. 0x20, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  395. 0x00, 0x00, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
  396. 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00, 0x00,
  397. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  398. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  399. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  400. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  401. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  402. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  403. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  404. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  405. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  406. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  407. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  408. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  409. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  410. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  411. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  412. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  413. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  414. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  415. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  416. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  417. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  418. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  419. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  420. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  421. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  422. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  423. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  424. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  425. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  426. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  427. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  428. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  429. },
  430. .hdr_len = 24,
  431. .payload_len = 256,
  432. .mic = {
  433. 0x80, 0xCB, 0x06, 0x62, 0xEA, 0x71, 0xAB, 0xFD,
  434. 0x9F, 0x04, 0xC7, 0xF8, 0x72, 0xF5, 0x80, 0x90 },
  435. .encr = {
  436. 0x5F, 0x55, 0x78, 0xC1, 0x8F, 0x13, 0x7A, 0xD2,
  437. 0x79, 0xBF, 0x3F, 0x2B, 0x24, 0xC7, 0xBD, 0x8F,
  438. 0x27, 0x7A, 0x1B, 0xE6, 0x77, 0x0D, 0xA1, 0xD9,
  439. 0x8B, 0x70, 0xC6, 0xD2, 0x8A, 0xE0, 0x1C, 0x55,
  440. 0x9E, 0xCB, 0xA6, 0xA0, 0x1D, 0xB0, 0x67, 0xC5,
  441. 0xA2, 0x7E, 0x4D, 0xB0, 0x8C, 0xDA, 0xDC, 0x77,
  442. 0x52, 0xAD, 0x63, 0x7E, 0xAF, 0x0A, 0x18, 0xED,
  443. 0x13, 0xFB, 0xAA, 0x14, 0x3B, 0xAF, 0xEF, 0x18,
  444. 0xF8, 0xFB, 0xCE, 0x4C, 0x65, 0xE8, 0x6B, 0xD0,
  445. 0x2A, 0x87, 0xB6, 0x01, 0xB7, 0xEA, 0xB9, 0x3F,
  446. 0x2B, 0xBC, 0x87, 0x4C, 0x8A, 0x71, 0x05, 0x80,
  447. 0xF5, 0x02, 0x34, 0x1A, 0x6A, 0x53, 0x39, 0x31,
  448. 0x43, 0xDE, 0x4C, 0x9E, 0xC6, 0xA2, 0x86, 0xF1,
  449. 0x25, 0x71, 0x83, 0x78, 0xAE, 0xDC, 0x84, 0xEB,
  450. 0xA2, 0xB3, 0x0F, 0x5C, 0x28, 0xBB, 0x5D, 0x75,
  451. 0xC6, 0xB0, 0x25, 0x46, 0x6D, 0x06, 0x51, 0xC7,
  452. 0x22, 0xDC, 0x71, 0x15, 0x1F, 0x21, 0x2D, 0x68,
  453. 0x87, 0x82, 0x8A, 0x03, 0x82, 0xE9, 0x28, 0x8A,
  454. 0x7F, 0x43, 0xD5, 0x2B, 0x7D, 0x25, 0x08, 0x61,
  455. 0x57, 0x64, 0x69, 0x54, 0xBB, 0x43, 0xB5, 0x7E,
  456. 0xA5, 0x87, 0xA0, 0x25, 0xF4, 0x0C, 0xE7, 0x45,
  457. 0x11, 0xE4, 0xDD, 0x22, 0x85, 0xB4, 0x0B, 0xA3,
  458. 0xF3, 0xB9, 0x62, 0x62, 0xCB, 0xC2, 0x8C, 0x6A,
  459. 0xA7, 0xBE, 0x44, 0x3E, 0x7B, 0x41, 0xE1, 0xEB,
  460. 0xFF, 0x52, 0x48, 0x57, 0xA6, 0x81, 0x68, 0x97,
  461. 0x75, 0x01, 0x15, 0xB0, 0x23, 0x1A, 0xB7, 0xC2,
  462. 0x84, 0x72, 0xC0, 0x6D, 0xD0, 0xB4, 0x9B, 0xE9,
  463. 0xF3, 0x69, 0xA8, 0xC3, 0x9C, 0xCD, 0x0D, 0xB7,
  464. 0x98, 0x35, 0x10, 0xE1, 0xAE, 0x8F, 0x05, 0xD7,
  465. 0x75, 0x45, 0xE0, 0x23, 0x5C, 0xDB, 0xD6, 0x12,
  466. 0xF3, 0x15, 0x07, 0x54, 0xCE, 0xE5, 0xCE, 0x6A,
  467. 0x12, 0x25, 0xD9, 0x95, 0x25, 0x02, 0x6F, 0x74
  468. }
  469. },
  470. {
  471. .tk = { 0xc9, 0x7c, 0x1f, 0x67, 0xce, 0x37, 0x11, 0x85,
  472. 0x51, 0x4a, 0x8a, 0x19, 0xf2, 0xbd, 0xd5, 0x2f },
  473. .pn = { 0x00, 0x89, 0x5F, 0x5F, 0x2B, 0x08 },
  474. .frame = {
  475. 0x88, 0x48, 0x0b, 0x00, 0x0f, 0xd2, 0xe1, 0x28,
  476. 0xa5, 0x7c, 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08,
  477. 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08, 0x80, 0x33,
  478. 0x03, 0x00,
  479. 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
  480. 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
  481. 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,
  482. 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f,
  483. 0x20, 0x21, 0x22, 0x23, 0x24, 0x25, 0x26, 0x27
  484. },
  485. .hdr_len = 26,
  486. .payload_len = 40,
  487. .mic = {
  488. 0xde, 0xf6, 0x19, 0xc2, 0xa3, 0x74, 0xb6, 0xdf,
  489. 0x66, 0xff, 0xa5, 0x3b, 0x6c, 0x69, 0xd7, 0x9e },
  490. .encr = {
  491. 0x60, 0xe9, 0x70, 0x0c, 0xc4, 0xd4, 0x0a, 0xc6,
  492. 0xd2, 0x88, 0xb2, 0x01, 0xc3, 0x8f, 0x5b, 0xf0,
  493. 0x8b, 0x80, 0x74, 0x42, 0x64, 0x0a, 0x15, 0x96,
  494. 0xe5, 0xdb, 0xda, 0xd4, 0x1d, 0x1f, 0x36, 0x23,
  495. 0xf4, 0x5d, 0x7a, 0x12, 0xdb, 0x7a, 0xfb, 0x23
  496. }
  497. }
  498. };
  499. static int run_gcmp(int idx, const struct gcmp_test *vector)
  500. {
  501. u8 *enc, *plain;
  502. size_t enc_len, plain_len;
  503. u8 fcs[4];
  504. int err = 0;
  505. wpa_printf(MSG_INFO,
  506. "\nIEEE Std 802.11ad-2012, M.11.1 GCMP test mpdu #%d\n",
  507. idx);
  508. wpa_hexdump(MSG_INFO, "TK", vector->tk, sizeof(vector->tk));
  509. wpa_hexdump(MSG_INFO, "PN", vector->pn, sizeof(vector->pn));
  510. wpa_hexdump(MSG_INFO, "802.11 Header", vector->frame, vector->hdr_len);
  511. wpa_hexdump(MSG_INFO, "Plaintext Data",
  512. vector->frame + vector->hdr_len,
  513. vector->payload_len);
  514. enc = gcmp_encrypt(vector->tk, sizeof(vector->tk),
  515. vector->frame,
  516. vector->hdr_len + vector->payload_len,
  517. vector->hdr_len,
  518. vector->hdr_len == 26 ?
  519. vector->frame + vector->hdr_len - 2 : NULL,
  520. vector->pn, 0, &enc_len);
  521. if (enc == NULL) {
  522. wpa_printf(MSG_ERROR, "Failed to encrypt GCMP frame");
  523. return 1;
  524. }
  525. wpa_hexdump(MSG_INFO, "Encrypted MPDU (without FCS)", enc, enc_len);
  526. if (os_memcmp(vector->encr, enc + vector->hdr_len + 8,
  527. vector->payload_len) != 0) {
  528. wpa_printf(MSG_ERROR, "GCMP test mpdu #%d enctypted data mismatch",
  529. idx);
  530. err++;
  531. }
  532. if (os_memcmp(vector->mic, enc + enc_len - sizeof(vector->mic),
  533. sizeof(vector->mic)) != 0) {
  534. wpa_printf(MSG_ERROR, "GCMP test mpdu #%d MIC mismatch", idx);
  535. err++;
  536. }
  537. WPA_PUT_LE32(fcs, crc32(enc, enc_len));
  538. wpa_hexdump(MSG_INFO, "FCS", fcs, sizeof(fcs));
  539. wpa_debug_level = MSG_INFO;
  540. plain = gcmp_decrypt(vector->tk, sizeof(vector->tk),
  541. (const struct ieee80211_hdr *) enc,
  542. enc + vector->hdr_len,
  543. enc_len - vector->hdr_len, &plain_len);
  544. wpa_debug_level = MSG_EXCESSIVE;
  545. os_free(enc);
  546. if (plain == NULL) {
  547. wpa_printf(MSG_ERROR, "Failed to decrypt GCMP frame");
  548. return 1;
  549. }
  550. if (plain_len != vector->payload_len ||
  551. os_memcmp(plain, vector->frame + vector->hdr_len, plain_len) != 0) {
  552. wpa_hexdump(MSG_ERROR, "Decryption result did not match",
  553. plain, plain_len);
  554. err++;
  555. }
  556. os_free(plain);
  557. return err;
  558. }
  559. static int test_vector_gcmp(void)
  560. {
  561. int err = 0;
  562. int i;
  563. for (i = 0; i < ARRAY_SIZE(gcmp_vectors); i++) {
  564. if (run_gcmp(i + 1, &gcmp_vectors[i]))
  565. err++;
  566. }
  567. return err;
  568. }
  569. static int test_vector_gcmp_256(void)
  570. {
  571. u8 tk[] = { 0xc9, 0x7c, 0x1f, 0x67, 0xce, 0x37, 0x11, 0x85,
  572. 0x51, 0x4a, 0x8a, 0x19, 0xf2, 0xbd, 0xd5, 0x2f,
  573. 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
  574. 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f };
  575. u8 pn[] = {
  576. 0x00, 0x89, 0x5F, 0x5F, 0x2B, 0x08
  577. };
  578. u8 frame[] = {
  579. 0x88, 0x48, 0x0b, 0x00, 0x0f, 0xd2, 0xe1, 0x28,
  580. 0xa5, 0x7c, 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08,
  581. 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08, 0x80, 0x33,
  582. 0x03, 0x00, 0x00, 0x01, 0x02, 0x03, 0x04, 0x05,
  583. 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d,
  584. 0x0e, 0x0f, 0x10, 0x11, 0x12, 0x13, 0x14, 0x15,
  585. 0x16, 0x17, 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d,
  586. 0x1e, 0x1f, 0x20, 0x21, 0x22, 0x23, 0x24, 0x25,
  587. 0x26, 0x27
  588. };
  589. u8 encr[] = {
  590. 0x88, 0x48, 0x0b, 0x00, 0x0f, 0xd2, 0xe1, 0x28,
  591. 0xa5, 0x7c, 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08,
  592. 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08, 0x80, 0x33,
  593. 0x03, 0x00, 0x08, 0x2b, 0x00, 0x20, 0x5f, 0x5f,
  594. 0x89, 0x00, 0x65, 0x83, 0x43, 0xc8, 0xb1, 0x44,
  595. 0x47, 0xd9, 0x21, 0x1d, 0xef, 0xd4, 0x6a, 0xd8,
  596. 0x9c, 0x71, 0x0c, 0x6f, 0xc3, 0x33, 0x33, 0x23,
  597. 0x6e, 0x39, 0x97, 0xb9, 0x17, 0x6a, 0x5a, 0x8b,
  598. 0xe7, 0x79, 0xb2, 0x12, 0x66, 0x55, 0x5e, 0x70,
  599. 0xad, 0x79, 0x11, 0x43, 0x16, 0x85, 0x90, 0x95,
  600. 0x47, 0x3d, 0x5b, 0x1b, 0xd5, 0x96, 0xb3, 0xde,
  601. 0xa3, 0xbf
  602. };
  603. u8 *enc, *plain;
  604. size_t enc_len, plain_len;
  605. u8 fcs[4];
  606. int err = 0;
  607. wpa_printf(MSG_INFO, "\nIEEE P802.11ac/D7.0, M.11.1 GCMP-256 test vector\n");
  608. wpa_hexdump(MSG_INFO, "TK", tk, sizeof(tk));
  609. wpa_hexdump(MSG_INFO, "PN", pn, sizeof(pn));
  610. wpa_hexdump(MSG_INFO, "802.11 Header", frame, 26);
  611. wpa_hexdump(MSG_INFO, "Plaintext Data", frame + 26, sizeof(frame) - 26);
  612. enc = gcmp_encrypt(tk, sizeof(tk), frame, sizeof(frame), 26, frame + 24,
  613. pn, 0, &enc_len);
  614. if (enc == NULL) {
  615. wpa_printf(MSG_ERROR, "Failed to encrypt GCMP frame");
  616. return 1;
  617. }
  618. wpa_hexdump(MSG_INFO, "Encrypted MPDU (without FCS)", enc, enc_len);
  619. if (enc_len != sizeof(encr) || os_memcmp(enc, encr, enc_len) != 0) {
  620. wpa_printf(MSG_ERROR, "GCMP-256 test vector mismatch");
  621. err++;
  622. }
  623. WPA_PUT_LE32(fcs, crc32(enc, enc_len));
  624. wpa_hexdump(MSG_INFO, "FCS", fcs, sizeof(fcs));
  625. wpa_debug_level = MSG_INFO;
  626. plain = gcmp_decrypt(tk, sizeof(tk), (const struct ieee80211_hdr *) enc,
  627. enc + 26, enc_len - 26, &plain_len);
  628. wpa_debug_level = MSG_EXCESSIVE;
  629. os_free(enc);
  630. if (plain == NULL) {
  631. wpa_printf(MSG_ERROR, "Failed to decrypt GCMP frame");
  632. return 1;
  633. }
  634. if (plain_len != sizeof(frame) - 26 ||
  635. os_memcmp(plain, frame + 26, plain_len) != 0) {
  636. wpa_hexdump(MSG_ERROR, "Decryption result did not match",
  637. plain, plain_len);
  638. err++;
  639. }
  640. os_free(plain);
  641. return err;
  642. }
  643. static int test_vector_ccmp_256(void)
  644. {
  645. u8 tk[] = { 0xc9, 0x7c, 0x1f, 0x67, 0xce, 0x37, 0x11, 0x85,
  646. 0x51, 0x4a, 0x8a, 0x19, 0xf2, 0xbd, 0xd5, 0x2f,
  647. 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
  648. 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f };
  649. u8 pn[] = { 0xB5, 0x03, 0x97, 0x76, 0xE7, 0x0C };
  650. u8 frame[] = {
  651. 0x08, 0x48, 0xc3, 0x2c, 0x0f, 0xd2, 0xe1, 0x28,
  652. 0xa5, 0x7c, 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08,
  653. 0xab, 0xae, 0xa5, 0xb8, 0xfc, 0xba, 0x80, 0x33,
  654. 0xf8, 0xba, 0x1a, 0x55, 0xd0, 0x2f, 0x85, 0xae,
  655. 0x96, 0x7b, 0xb6, 0x2f, 0xb6, 0xcd, 0xa8, 0xeb,
  656. 0x7e, 0x78, 0xa0, 0x50
  657. };
  658. u8 encr[] = {
  659. 0x08, 0x48, 0xc3, 0x2c, 0x0f, 0xd2, 0xe1, 0x28,
  660. 0xa5, 0x7c, 0x50, 0x30, 0xf1, 0x84, 0x44, 0x08,
  661. 0xab, 0xae, 0xa5, 0xb8, 0xfc, 0xba, 0x80, 0x33,
  662. 0x0c, 0xe7, 0x00, 0x20, 0x76, 0x97, 0x03, 0xb5,
  663. 0x6d, 0x15, 0x5d, 0x88, 0x32, 0x66, 0x82, 0x56,
  664. 0xd6, 0xa9, 0x2b, 0x78, 0xe1, 0x1d, 0x8e, 0x54,
  665. 0x49, 0x5d, 0xd1, 0x74, 0x80, 0xaa, 0x56, 0xc9,
  666. 0x49, 0x2e, 0x88, 0x2b, 0x97, 0x64, 0x2f, 0x80,
  667. 0xd5, 0x0f, 0xe9, 0x7b
  668. };
  669. u8 *enc, *plain;
  670. size_t enc_len, plain_len;
  671. u8 fcs[4];
  672. int err = 0;
  673. wpa_printf(MSG_INFO, "\nIEEE P802.11ac/D7.0, M.6.4 CCMP-256 test vector\n");
  674. wpa_hexdump(MSG_INFO, "TK", tk, sizeof(tk));
  675. wpa_hexdump(MSG_INFO, "PN", pn, sizeof(pn));
  676. wpa_hexdump(MSG_INFO, "802.11 Header", frame, 24);
  677. wpa_hexdump(MSG_INFO, "Plaintext Data", frame + 24, sizeof(frame) - 24);
  678. enc = ccmp_256_encrypt(tk, frame, sizeof(frame), 24, NULL, pn, 0,
  679. &enc_len);
  680. if (enc == NULL) {
  681. wpa_printf(MSG_ERROR, "Failed to encrypt CCMP frame");
  682. return 1;
  683. }
  684. wpa_hexdump(MSG_INFO, "Encrypted MPDU (without FCS)", enc, enc_len);
  685. if (enc_len != sizeof(encr) || os_memcmp(enc, encr, enc_len) != 0) {
  686. wpa_printf(MSG_ERROR, "CCMP-256 test vector mismatch");
  687. err++;
  688. }
  689. WPA_PUT_LE32(fcs, crc32(enc, enc_len));
  690. wpa_hexdump(MSG_INFO, "FCS", fcs, sizeof(fcs));
  691. wpa_debug_level = MSG_INFO;
  692. plain = ccmp_256_decrypt(tk, (const struct ieee80211_hdr *) enc,
  693. enc + 24, enc_len - 24, &plain_len);
  694. wpa_debug_level = MSG_EXCESSIVE;
  695. os_free(enc);
  696. if (plain == NULL) {
  697. wpa_printf(MSG_ERROR, "Failed to decrypt CCMP-256 frame");
  698. return 1;
  699. }
  700. if (plain_len != sizeof(frame) - 24 ||
  701. os_memcmp(plain, frame + 24, plain_len) != 0) {
  702. wpa_hexdump(MSG_ERROR, "Decryption result did not match",
  703. plain, plain_len);
  704. err++;
  705. }
  706. os_free(plain);
  707. return err;
  708. }
  709. static int test_vector_bip_gmac_128(void)
  710. {
  711. u8 igtk[] = {
  712. 0x4e, 0xa9, 0x54, 0x3e, 0x09, 0xcf, 0x2b, 0x1e,
  713. 0xca, 0x66, 0xff, 0xc5, 0x8b, 0xde, 0xcb, 0xcf
  714. };
  715. u8 ipn[] = { 0x04, 0x00, 0x00, 0x00, 0x00, 0x00 };
  716. u8 frame[] = {
  717. 0xc0, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff,
  718. 0xff, 0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00,
  719. 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x09, 0x00,
  720. 0x02, 0x00
  721. };
  722. u8 res[] = {
  723. 0xc0, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff,
  724. 0xff, 0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00,
  725. 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x09, 0x00,
  726. 0x02, 0x00, 0x4c, 0x18, 0x04, 0x00, 0x04, 0x00,
  727. 0x00, 0x00, 0x00, 0x00, 0x3e, 0xd8, 0x62, 0xfb,
  728. 0x0f, 0x33, 0x38, 0xdd, 0x33, 0x86, 0xc8, 0x97,
  729. 0xe2, 0xed, 0x05, 0x3d
  730. };
  731. u8 *prot;
  732. size_t prot_len;
  733. int err = 0;
  734. wpa_printf(MSG_INFO, "\nIEEE P802.11ac/D7.0, M.9.1 BIP-GMAC-128 with broadcast "
  735. "Deauthentication frame\n");
  736. wpa_hexdump(MSG_INFO, "IGTK", igtk, sizeof(igtk));
  737. wpa_hexdump(MSG_INFO, "IPN", ipn, sizeof(ipn));
  738. wpa_hexdump(MSG_INFO, "Plaintext frame", frame, sizeof(frame));
  739. prot = bip_gmac_protect(igtk, sizeof(igtk), frame, sizeof(frame),
  740. ipn, 4, &prot_len);
  741. if (prot == NULL) {
  742. wpa_printf(MSG_ERROR, "Failed to protect BIP-GMAC-128 frame");
  743. return 1;
  744. }
  745. wpa_hexdump(MSG_INFO, "Protected MPDU (without FCS)", prot, prot_len);
  746. if (prot_len != sizeof(res) || os_memcmp(res, prot, prot_len) != 0) {
  747. wpa_printf(MSG_ERROR, "BIP-GMAC-128 test vector mismatch");
  748. err++;
  749. }
  750. os_free(prot);
  751. return err;
  752. }
  753. static int test_vector_bip_gmac_256(void)
  754. {
  755. u8 igtk[] = {
  756. 0x4e, 0xa9, 0x54, 0x3e, 0x09, 0xcf, 0x2b, 0x1e,
  757. 0xca, 0x66, 0xff, 0xc5, 0x8b, 0xde, 0xcb, 0xcf,
  758. 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
  759. 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f
  760. };
  761. u8 ipn[] = { 0x04, 0x00, 0x00, 0x00, 0x00, 0x00 };
  762. u8 frame[] = {
  763. 0xc0, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff,
  764. 0xff, 0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00,
  765. 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x09, 0x00,
  766. 0x02, 0x00
  767. };
  768. u8 res[] = {
  769. 0xc0, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff,
  770. 0xff, 0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00,
  771. 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x09, 0x00,
  772. 0x02, 0x00, 0x4c, 0x18, 0x04, 0x00, 0x04, 0x00,
  773. 0x00, 0x00, 0x00, 0x00, 0x23, 0xbe, 0x59, 0xdc,
  774. 0xc7, 0x02, 0x2e, 0xe3, 0x83, 0x62, 0x7e, 0xbb,
  775. 0x10, 0x17, 0xdd, 0xfc
  776. };
  777. u8 *prot;
  778. size_t prot_len;
  779. int err = 0;
  780. wpa_printf(MSG_INFO, "\nIEEE P802.11ac/D7.0, M.9.1 BIP-GMAC-256 with broadcast Deauthentication frame\n");
  781. wpa_hexdump(MSG_INFO, "IGTK", igtk, sizeof(igtk));
  782. wpa_hexdump(MSG_INFO, "IPN", ipn, sizeof(ipn));
  783. wpa_hexdump(MSG_INFO, "Plaintext frame", frame, sizeof(frame));
  784. prot = bip_gmac_protect(igtk, sizeof(igtk), frame, sizeof(frame),
  785. ipn, 4, &prot_len);
  786. if (prot == NULL) {
  787. wpa_printf(MSG_ERROR, "Failed to protect BIP-GMAC-256 frame");
  788. return 1;
  789. }
  790. wpa_hexdump(MSG_INFO, "Protected MPDU (without FCS)", prot, prot_len);
  791. if (prot_len != sizeof(res) || os_memcmp(res, prot, prot_len) != 0) {
  792. wpa_printf(MSG_ERROR, "BIP-GMAC-128 test vector mismatch");
  793. err++;
  794. }
  795. os_free(prot);
  796. return err;
  797. }
  798. int main(int argc, char *argv[])
  799. {
  800. int errors = 0;
  801. wpa_debug_level = MSG_EXCESSIVE;
  802. wpa_debug_show_keys = 1;
  803. if (os_program_init())
  804. return -1;
  805. test_vector_tkip();
  806. test_vector_ccmp();
  807. test_vector_ccmp_pv1();
  808. test_vector_bip();
  809. test_vector_ccmp_mgmt();
  810. errors += test_vector_gcmp();
  811. errors += test_vector_gcmp_256();
  812. errors += test_vector_ccmp_256();
  813. errors += test_vector_bip_gmac_128();
  814. errors += test_vector_bip_gmac_256();
  815. if (errors)
  816. wpa_printf(MSG_INFO, "One or more test vectors failed");
  817. os_program_deinit();
  818. return errors ? -1 : 0;
  819. }