oxedyne/fe2o3/fe2o3_crypto/tests/data/PROVENANCE.md
2.5 KiB, 3 runs
created by r1870400018:50223, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | # `ecdsa_verify_tests.txt` |
| 2 | |
| 3 | NIST CAVP 186-4 ECDSA `SigVer` (signature verification) test vectors, in the |
| 4 | line-oriented form BoringSSL reformatted them into, vendored here verbatim from |
| 5 | the `ring` crate (`ring-0.17.14/crypto/fipsmodule/ecdsa/ecdsa_verify_tests.txt`). |
| 6 | The file's own header, naming the NIST source, is preserved unchanged. |
| 7 | |
| 8 | Each block gives a curve, a public point `X`/`Y`, a message `Digest`, and a |
| 9 | signature `R`/`S`; a block carrying an `Invalid = Y` line is one whose signature |
| 10 | must be rejected. This crate's `tests/p256_verify.rs` reads the `Curve = P-256` |
| 11 | blocks and asserts each verdict. |
| 12 | |
| 13 | ## Licence |
| 14 | |
| 15 | The test data originates in BoringSSL and is used under BoringSSL's permissive |
| 16 | (OpenSSL / ISC-style) licence; `ring` redistributes it on the same terms. It is |
| 17 | included here only as a test oracle and is not part of the compiled library. |
| 18 | |
| 19 | # `linkring_vectors.txt` |
| 20 | |
| 21 | `linkring/1` signatures produced by `tools/linkring_oracle.py sign`, an |
| 22 | independent Python implementation written from RFC 9496 (ristretto255), |
| 23 | RFC 9380 (`hash_to_ristretto255`) and Bootle et al., ESORICS 2015 (the radix-n |
| 24 | one-out-of-many proof), whose group layer first checks itself against RFC 9496's |
| 25 | published multiples of the generator. No published vectors exist for this |
| 26 | construction, so these stand in for them. `tests/linkring.rs` re-signs each case |
| 27 | in Rust and requires the same ring, digest, tag and body byte for byte, and, |
| 28 | where `python3` is present, also runs the oracle live on fresh random cases. |
| 29 | Written for this crate; no third-party licence applies. |
| 30 | |
| 31 | # `ed25519vectors.json` |
| 32 | |
| 33 | The C2SP Community Cryptography Test Vectors (CCTV) for Ed25519 verification |
| 34 | edge cases, vendored verbatim from |
| 35 | `https://github.com/C2SP/CCTV/blob/5ea85644bd035c555900a2f707f7e4c31ea65ced/ed25519vectors/ed25519vectors.json` |
| 36 | (SHA-256 `b38e84caf3e7e89170ff520292dbeae421b0a794c27408ce5ce973018fe3d7f9`), the |
| 37 | commit `ed25519-dalek` cites for its own validation tests. Each of the 914 |
| 38 | vectors gives a public key, a signature and a message, and flags the edge cases |
| 39 | it exercises: low-order or non-canonical A and R, low-order components, a |
| 40 | low-order residue, a re-encoded k. `tests/ed25519_strict.rs` derives the verdict |
| 41 | a strict verifier owes each vector from its flags alone and asserts it, singly |
| 42 | and in batches. |
| 43 | |
| 44 | ## Licence |
| 45 | |
| 46 | Copyright 2019 Google LLC and 2022 Filippo Valsorda, under the three-clause BSD |
| 47 | licence reproduced in `ed25519vectors_LICENSE.txt`, which travels with the file. |
| 48 | It is included here only as a test oracle and is not part of the compiled |
| 49 | library. |