Browse Source

Исправлена криптография: исправлен размер nonce для CCM (13 байт) и завершены тесты

v2_dev
Evgeny 8 months ago
parent
commit
a1bcd6edb7
  1. 2
      src/secure_channel.h
  2. 22
      tests/test_etcp_crypto.c

2
src/secure_channel.h

@ -9,7 +9,7 @@
#define SC_PRIVKEY_SIZE 32
#define SC_PUBKEY_SIZE 64
#define SC_HASH_SIZE 32
#define SC_NONCE_SIZE 8
#define SC_NONCE_SIZE 13 // CCM requires exactly 13 bytes
#define SC_SHARED_SECRET_SIZE SC_HASH_SIZE
#define SC_SESSION_KEY_SIZE 16
#define SC_TAG_SIZE 8

22
tests/test_etcp_crypto.c

@ -94,7 +94,7 @@ static int test_secure_channel_crypto(void) {
}
printf("✓ Client crypto context initialized\n");
// For this simple test, we'll manually set peer keys and session ready
// For this simple test, we'll manually set peer keys, session ready, and session key
// to bypass the ECC key exchange which requires proper ECC initialization
memcpy(client_ctx.peer_public_key, server_keys.public_key, SC_PUBKEY_SIZE);
memcpy(server_ctx.peer_public_key, client_keys.public_key, SC_PUBKEY_SIZE);
@ -102,9 +102,17 @@ static int test_secure_channel_crypto(void) {
client_ctx.session_ready = 1; // This is crucial for encryption to work
server_ctx.peer_key_set = 1;
server_ctx.session_ready = 1; // This is crucial for encryption to work
client_ctx.session_ready = 1; // This is crucial for encryption to work
server_ctx.session_ready = 1; // This is crucial for encryption to work
printf("✓ Peer public keys set manually\n");
// Set test session keys manually (16 bytes for AES-128)
// In a real implementation, this would be derived from ECDH shared secret
uint8_t test_session_key[SC_SESSION_KEY_SIZE];
for (int i = 0; i < SC_SESSION_KEY_SIZE; i++) {
test_session_key[i] = i + 100;
}
memcpy(client_ctx.session_key, test_session_key, SC_SESSION_KEY_SIZE);
memcpy(server_ctx.session_key, test_session_key, SC_SESSION_KEY_SIZE);
printf("✓ Peer public keys and session keys set manually\n");
// Test data
uint8_t plaintext[] = TEST_DATA;
@ -218,9 +226,13 @@ static int test_etcp_connection_crypto(void) {
uint8_t decrypted[256];
size_t encrypted_len, decrypted_len;
// Self-encryption test (set our own public key as peer)
// Self-encryption test (set our own public key as peer and session key)
memcpy(conn->crypto_ctx.peer_public_key, keys.public_key, SC_PUBKEY_SIZE);
conn->crypto_ctx.peer_key_set = 1;
conn->crypto_ctx.session_ready = 1;
// Set test session key for self-encryption
memcpy(conn->crypto_ctx.session_key, keys.public_key, SC_SESSION_KEY_SIZE); // Use public key as session key for test
if (sc_encrypt(&conn->crypto_ctx, test_data, sizeof(test_data)-1, encrypted, &encrypted_len) != SC_OK) {
printf("ERROR: Connection encryption failed\n");

Loading…
Cancel
Save