2018-06-21 14:28:34 +00:00
|
|
|
# This file is part of the Trezor project.
|
2017-10-03 22:37:45 +00:00
|
|
|
#
|
2019-05-29 16:44:09 +00:00
|
|
|
# Copyright (C) 2012-2019 SatoshiLabs and contributors
|
2017-10-03 22:37:45 +00:00
|
|
|
#
|
|
|
|
# This library is free software: you can redistribute it and/or modify
|
2018-06-21 14:28:34 +00:00
|
|
|
# it under the terms of the GNU Lesser General Public License version 3
|
|
|
|
# as published by the Free Software Foundation.
|
2017-10-03 22:37:45 +00:00
|
|
|
#
|
|
|
|
# This library is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU Lesser General Public License for more details.
|
|
|
|
#
|
2018-06-21 14:28:34 +00:00
|
|
|
# You should have received a copy of the License along with this library.
|
|
|
|
# If not, see <https://www.gnu.org/licenses/lgpl-3.0.html>.
|
2017-10-03 22:37:45 +00:00
|
|
|
|
2017-12-23 20:20:49 +00:00
|
|
|
from hashlib import sha256
|
2018-04-18 12:00:11 +00:00
|
|
|
|
2018-08-13 16:21:24 +00:00
|
|
|
import pytest
|
2017-10-03 22:37:45 +00:00
|
|
|
|
2018-08-13 16:21:24 +00:00
|
|
|
from trezorlib import cosi
|
2022-01-31 12:25:30 +00:00
|
|
|
from trezorlib.debuglink import TrezorClientDebugLink as Client
|
2022-11-25 20:09:34 +00:00
|
|
|
from trezorlib.exceptions import TrezorFailure
|
2023-02-02 12:29:09 +00:00
|
|
|
from trezorlib.tools import H_, Address, parse_path
|
2018-04-18 13:53:40 +00:00
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
DIGEST = sha256(b"this is not a pipe").digest()
|
2017-10-03 22:37:45 +00:00
|
|
|
|
|
|
|
|
2022-12-11 11:34:12 +00:00
|
|
|
@pytest.mark.skip_t1
|
2022-06-23 07:28:49 +00:00
|
|
|
def test_cosi_pubkey(client: Client):
|
|
|
|
c0 = cosi.commit(client, parse_path("m/10018h/0h"))
|
|
|
|
c1 = cosi.commit(client, parse_path("m/10018h/1h"))
|
|
|
|
c2 = cosi.commit(client, parse_path("m/10018h/2h"))
|
2017-10-03 22:37:45 +00:00
|
|
|
|
2021-11-10 21:19:53 +00:00
|
|
|
assert c0.pubkey != c1.pubkey
|
|
|
|
assert c0.pubkey != c2.pubkey
|
|
|
|
assert c1.pubkey != c2.pubkey
|
2017-10-03 22:37:45 +00:00
|
|
|
|
|
|
|
|
2022-12-11 11:34:12 +00:00
|
|
|
@pytest.mark.skip_t1
|
2022-06-23 07:28:49 +00:00
|
|
|
def test_cosi_nonce(client: Client):
|
|
|
|
# The nonce/commitment must change after each signing.
|
|
|
|
c0 = cosi.commit(client, parse_path("m/10018h/0h"))
|
|
|
|
cosi.sign(client, parse_path("m/10018h/0h"), DIGEST, c0.commitment, c0.pubkey)
|
|
|
|
c1 = cosi.commit(client, parse_path("m/10018h/0h"))
|
|
|
|
assert c0.commitment != c1.commitment
|
2017-10-03 22:37:45 +00:00
|
|
|
|
|
|
|
|
2022-12-11 11:34:12 +00:00
|
|
|
@pytest.mark.skip_t1
|
2022-06-23 07:28:49 +00:00
|
|
|
def test_cosi_sign1(client: Client):
|
|
|
|
# Single party signature.
|
|
|
|
commit = cosi.commit(client, parse_path("m/10018h/0h"))
|
|
|
|
sig = cosi.sign(
|
|
|
|
client, parse_path("m/10018h/0h"), DIGEST, commit.commitment, commit.pubkey
|
|
|
|
)
|
|
|
|
signature = cosi.combine_sig(commit.commitment, [sig.signature])
|
|
|
|
cosi.verify_combined(signature, DIGEST, commit.pubkey)
|
2017-10-03 22:37:45 +00:00
|
|
|
|
|
|
|
|
2022-12-11 11:34:12 +00:00
|
|
|
@pytest.mark.skip_t1
|
2022-06-23 07:28:49 +00:00
|
|
|
def test_cosi_sign2(client: Client):
|
|
|
|
# Two party signature.
|
|
|
|
remote_commit = cosi.commit(client, parse_path("m/10018h/1h"))
|
2017-10-03 22:37:45 +00:00
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
local_privkey = sha256(b"private key").digest()[:32]
|
|
|
|
local_pubkey = cosi.pubkey_from_privkey(local_privkey)
|
|
|
|
local_nonce, local_commitment = cosi.get_nonce(local_privkey, DIGEST, 42)
|
2017-10-03 22:37:45 +00:00
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
global_pk = cosi.combine_keys([remote_commit.pubkey, local_pubkey])
|
|
|
|
global_R = cosi.combine_keys([remote_commit.commitment, local_commitment])
|
2017-10-03 22:37:45 +00:00
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
remote_sig = cosi.sign(
|
|
|
|
client, parse_path("m/10018h/1h"), DIGEST, global_R, global_pk
|
|
|
|
)
|
|
|
|
local_sig = cosi.sign_with_privkey(
|
|
|
|
DIGEST, local_privkey, global_pk, local_nonce, global_R
|
|
|
|
)
|
|
|
|
signature = cosi.combine_sig(global_R, [remote_sig.signature, local_sig])
|
2018-05-28 15:41:52 +00:00
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
cosi.verify_combined(signature, DIGEST, global_pk)
|
2018-05-28 15:41:52 +00:00
|
|
|
|
|
|
|
|
2022-12-11 11:34:12 +00:00
|
|
|
@pytest.mark.skip_t1
|
2022-06-23 07:28:49 +00:00
|
|
|
def test_cosi_sign3(client: Client):
|
|
|
|
# Three party signature.
|
|
|
|
remote_commit = cosi.commit(client, parse_path("m/10018h/2h"))
|
2018-05-28 15:41:52 +00:00
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
local_privkey1 = sha256(b"private key").digest()[:32]
|
|
|
|
local_pubkey1 = cosi.pubkey_from_privkey(local_privkey1)
|
|
|
|
local_nonce1, local_commitment1 = cosi.get_nonce(local_privkey1, DIGEST, 42)
|
2018-05-28 15:41:52 +00:00
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
local_privkey2 = sha256(b"private key").digest()[:32]
|
|
|
|
local_pubkey2 = cosi.pubkey_from_privkey(local_privkey2)
|
|
|
|
local_nonce2, local_commitment2 = cosi.get_nonce(local_privkey2, DIGEST, 42)
|
2021-11-10 21:19:53 +00:00
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
global_pk = cosi.combine_keys([remote_commit.pubkey, local_pubkey1, local_pubkey2])
|
|
|
|
global_R = cosi.combine_keys(
|
|
|
|
[remote_commit.commitment, local_commitment1, local_commitment2]
|
|
|
|
)
|
2021-11-10 21:19:53 +00:00
|
|
|
|
2022-01-31 12:25:30 +00:00
|
|
|
remote_sig = cosi.sign(
|
2022-06-23 07:28:49 +00:00
|
|
|
client, parse_path("m/10018h/2h"), DIGEST, global_R, global_pk
|
2022-01-31 12:25:30 +00:00
|
|
|
)
|
2022-06-23 07:28:49 +00:00
|
|
|
local_sig1 = cosi.sign_with_privkey(
|
|
|
|
DIGEST, local_privkey1, global_pk, local_nonce1, global_R
|
|
|
|
)
|
|
|
|
local_sig2 = cosi.sign_with_privkey(
|
|
|
|
DIGEST, local_privkey2, global_pk, local_nonce2, global_R
|
|
|
|
)
|
|
|
|
signature = cosi.combine_sig(
|
|
|
|
global_R, [remote_sig.signature, local_sig1, local_sig2]
|
2021-11-10 21:19:53 +00:00
|
|
|
)
|
|
|
|
|
2022-06-23 07:28:49 +00:00
|
|
|
cosi.verify_combined(signature, DIGEST, global_pk)
|
2022-11-25 20:09:34 +00:00
|
|
|
|
|
|
|
|
2024-03-11 15:20:08 +00:00
|
|
|
@pytest.mark.skip_t1b1
|
2022-11-25 20:09:34 +00:00
|
|
|
def test_cosi_different_key(client: Client):
|
|
|
|
with pytest.raises(TrezorFailure):
|
|
|
|
commit = cosi.commit(client, parse_path("m/10018h/0h"))
|
|
|
|
cosi.sign(
|
|
|
|
client, parse_path("m/10018h/1h"), DIGEST, commit.commitment, commit.pubkey
|
|
|
|
)
|
2023-02-02 12:29:09 +00:00
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.parametrize(
|
2023-04-05 15:41:20 +00:00
|
|
|
"model, image_type",
|
2023-02-02 12:29:09 +00:00
|
|
|
(
|
2023-04-05 15:41:20 +00:00
|
|
|
(b"T1B1", 0),
|
|
|
|
(b"T2T1", 0),
|
|
|
|
(b"T2B1", 0),
|
|
|
|
(b"T3W1", 0),
|
|
|
|
(b"\xfe\xfe\xfe\xfe", 0),
|
|
|
|
(b"\x00", 0),
|
|
|
|
(b"\x00", 3),
|
|
|
|
(b"dog", 0),
|
|
|
|
(b"42", 0),
|
|
|
|
(b"T2B1", 1),
|
|
|
|
(b"T2B1", 2),
|
|
|
|
(b"T2B1", 3),
|
2023-02-02 12:29:09 +00:00
|
|
|
),
|
|
|
|
)
|
2024-03-11 15:20:08 +00:00
|
|
|
@pytest.mark.skip_t1b1
|
2023-04-05 15:41:20 +00:00
|
|
|
def test_slip26_paths(client: Client, model: bytes, image_type: int):
|
2023-02-02 12:29:09 +00:00
|
|
|
slip26_model = int.from_bytes(model, "little")
|
2023-04-05 15:41:20 +00:00
|
|
|
path = Address([H_(10026), H_(slip26_model), H_(image_type), H_(0)])
|
|
|
|
commit = cosi.commit(client, path)
|
|
|
|
cosi.sign(client, path, DIGEST, commit.commitment, commit.pubkey)
|
2023-02-03 10:34:38 +00:00
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
|
|
"path",
|
|
|
|
(
|
|
|
|
"m/44h/0h/0h/0/0",
|
|
|
|
"m/44h/60h/0h/0/0",
|
|
|
|
"m/44h/60h/1h",
|
|
|
|
"m/84h/60h/1h/0",
|
|
|
|
"m/1",
|
|
|
|
"m/10018/0",
|
|
|
|
),
|
|
|
|
)
|
|
|
|
def test_invalid_path(client: Client, path: str) -> None:
|
|
|
|
with pytest.raises(TrezorFailure, match="DataError"):
|
|
|
|
cosi.commit(client, parse_path(path))
|