Three components, all bench-validated to varying depths: - applet/: CSA Aliro v1.0 Java Card applet for J3R180. AUTH0 + AUTH1 expedited-standard flow end-to-end green via PC/SC bench reader (aliro-bench-test). Userland AES-256-GCM and HMAC-SHA-256 layered on top of J3R180's primitives because the card lacks both natively. P-256 curve params seeded explicitly per J3R180's quirk. - harness/: Python orchestrator (aliro-trustgen, aliro-personalize, aliro-bench-test) for trust-bundle generation, card personalization via PersonalizationApplet, and PC/SC AUTH0+AUTH1 transactions. 126 pytest cases passing. - reader/STM32CubeExpansion_ALIRO_V1_0_0/: ST X-CUBE-ALIRO V1.0.0 with our NFC10A1 port (NUCLEO-U545RE-Q + X-NUCLEO-NFC10A1, ST25R200 shared with NFC09A1). nfc10-only/ project, NFC10A1 BSP shim, ALIRO_TRUST_OVERRIDE include into vendor's provisioning.c, and an ALIRO_APDU_TRACE wrapper around demoTransceiveBlocking. Boots, detects the J3R180, completes SELECT + AUTH0; AUTH1 currently fails with RFAL ERR_PROTO (0xB) — under investigation, see docs/plans/2026-04-20-nucleo-nfc10a1-port.md and bench-notes/. Excluded: x-cube-aliro.zip vendor archive, harness/.venv, build dirs, generated aliro_trust.h (contains private reader scalar), all PEMs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
40 lines
1.6 KiB
Python
40 lines
1.6 KiB
Python
from cryptography.hazmat.primitives.asymmetric import ec
|
|
|
|
from aliro_harness.reader.crypto import (
|
|
derive_kdh,
|
|
ecdh_shared_x,
|
|
hkdf_sha256,
|
|
)
|
|
|
|
|
|
# RFC 5869 Test Case 1
|
|
RFC5869_T1_IKM = bytes.fromhex("0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b")
|
|
RFC5869_T1_SALT = bytes.fromhex("000102030405060708090a0b0c")
|
|
RFC5869_T1_INFO = bytes.fromhex("f0f1f2f3f4f5f6f7f8f9")
|
|
RFC5869_T1_OKM_42 = bytes.fromhex(
|
|
"3cb25f25faacd57a90434f64d0362f2a"
|
|
"2d2d0a90cf1a5a4c5db02d56ecc4c5bf"
|
|
"34007208d5b887185865"
|
|
)
|
|
|
|
|
|
def test_hkdf_sha256_matches_rfc5869_test_case_1():
|
|
assert hkdf_sha256(RFC5869_T1_IKM, RFC5869_T1_SALT, RFC5869_T1_INFO, 42) == RFC5869_T1_OKM_42
|
|
|
|
|
|
def test_ecdh_commutative():
|
|
a = ec.generate_private_key(ec.SECP256R1())
|
|
b = ec.generate_private_key(ec.SECP256R1())
|
|
a_pub_uncomp = bytes([0x04]) + a.public_key().public_numbers().x.to_bytes(32, "big") + a.public_key().public_numbers().y.to_bytes(32, "big")
|
|
b_pub_uncomp = bytes([0x04]) + b.public_key().public_numbers().x.to_bytes(32, "big") + b.public_key().public_numbers().y.to_bytes(32, "big")
|
|
assert ecdh_shared_x(a, b_pub_uncomp) == ecdh_shared_x(b, a_pub_uncomp)
|
|
|
|
|
|
def test_derive_kdh_agrees_on_both_sides():
|
|
a = ec.generate_private_key(ec.SECP256R1())
|
|
b = ec.generate_private_key(ec.SECP256R1())
|
|
a_pub = bytes([0x04]) + a.public_key().public_numbers().x.to_bytes(32, "big") + a.public_key().public_numbers().y.to_bytes(32, "big")
|
|
b_pub = bytes([0x04]) + b.public_key().public_numbers().x.to_bytes(32, "big") + b.public_key().public_numbers().y.to_bytes(32, "big")
|
|
txn = b"\x01" * 16
|
|
assert derive_kdh(a, b_pub, txn) == derive_kdh(b, a_pub, txn)
|