| { | |
| "algorithm": "AES-FF1", | |
| "generatorVersion": "0.9rc5", | |
| "numberOfTests": 2868, | |
| "header": [ | |
| "Test vectors of type FpeListTest are intended for format preserving encryption." | |
| ], | |
| "notes": { | |
| "EdgeCasePrf": { | |
| "bugType": "EDGE_CASE", | |
| "description": "FF1 computes a pseudorandom function, converts the result into an integer y, which is then reduced modulo radix**v, where v is the size of the longer block in the Feistel structure. This test vector contains cases where the value y is an edge case. The goal of the test vector is to check for arithmetic errors such as integer overflow or incorrect modular reduction." | |
| }, | |
| "EdgeCaseState": { | |
| "bugType": "EDGE_CASE", | |
| "description": "FF1 requires integer arithmetic of various sizes. This test vector contains values such that edge cases are reached during encryption and decryption. The goal of the test vector is to check for incorrect integer arithmetic e.g., because of integer overflows." | |
| }, | |
| "InvalidKeySize": { | |
| "bugType": "MODIFIED_PARAMETER", | |
| "description": "The key size is invalid." | |
| }, | |
| "InvalidMessageSize": { | |
| "bugType": "MISSING_STEP", | |
| "description": "FF1 imposes a minimal size of the inputs. The original specification of FF1 required radix**minlen >= 100, NIST SP 800-38G rev 1, requires radix**minlen >= 1'000'000. This test vector contains a short message such that both limits are violated and hence should be rejected." | |
| }, | |
| "InvalidPlaintext": { | |
| "bugType": "MODIFIED_PARAMETER", | |
| "description": "FF1 expects inputs from a fixed range of digits. This test vector contains a plaintext containing invalid digits." | |
| }, | |
| "LargeMessageSize": { | |
| "bugType": "FUNCTIONALITY", | |
| "description": "The specification of FF1 uses integer arithmetic of arbitrary size for long messages. Some implementations may choose to restrict the message length to simplify the implementation of FF1. This test vector contains a message of size msglen such that radix**msglen > 2**128." | |
| }, | |
| "NormalMessageSize": { | |
| "bugType": "BASIC", | |
| "description": "The specification of FF1 uses integer arithmetic of arbitrary size for long messages. Some implementations may choose to restrict the message length to simplify the implementation of FF1. This test vector contains a message of size msglen such that 1'000'000 <= radix**msglen <= 2**128." | |
| }, | |
| "SmallMessageSize": { | |
| "bugType": "LEGACY", | |
| "description": "FF1 imposes a minimal size of the inputs. The original specification of FF1 required radix**msglen >= 100, NIST SP 800-38G rev 1 changes this and requires radix**msglen >= 1'000'000. This test vector contains a message of size msglen, such that radix**msglen lies between these two limits." | |
| } | |
| }, | |
| "schema": "fpe_list_test_schema.json", | |
| "testGroups": [ | |
| { | |
| "keySize": 128, | |
| "msgSize": 0, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 1, | |
| "comment": "Invalid message size", | |
| "flags": [ | |
| "InvalidMessageSize" | |
| ], | |
| "key": "fb9fc869af3e4828da6efa18b5fa71a0", | |
| "tweak": "379f81cab6ed2517", | |
| "msg": [], | |
| "ct": [], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 1, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 2, | |
| "comment": "Invalid message size", | |
| "flags": [ | |
| "InvalidMessageSize" | |
| ], | |
| "key": "7325733095d90aff456a1e00fa977365", | |
| "tweak": "a5f8950069a56f6c", | |
| "msg": [8], | |
| "ct": [], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 192, | |
| "msgSize": 0, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 3, | |
| "comment": "Invalid message size", | |
| "flags": [ | |
| "InvalidMessageSize" | |
| ], | |
| "key": "af2463f51df63a015178e30edcf25dacbeb2abbc5144d0a6", | |
| "tweak": "5d9c3dfb797c952a", | |
| "msg": [], | |
| "ct": [], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 192, | |
| "msgSize": 1, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 4, | |
| "comment": "Invalid message size", | |
| "flags": [ | |
| "InvalidMessageSize" | |
| ], | |
| "key": "e9e279f5fad3e7fd7922e838cf07da528ddcc5387f6145bf", | |
| "tweak": "a25989a2e4360bae", | |
| "msg": [19], | |
| "ct": [], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 256, | |
| "msgSize": 0, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 5, | |
| "comment": "Invalid message size", | |
| "flags": [ | |
| "InvalidMessageSize" | |
| ], | |
| "key": "f25e816c4d42629a428e48f2d48a31f79d6b1e8ef47e5ed3e7e5bbdf37f1806d", | |
| "tweak": "42dbc8913a275520", | |
| "msg": [], | |
| "ct": [], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 256, | |
| "msgSize": 1, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 6, | |
| "comment": "Invalid message size", | |
| "flags": [ | |
| "InvalidMessageSize" | |
| ], | |
| "key": "b8c800bed3286920bd1d9ad89a78808e9f815ec638663a725f256cc7078fdaf0", | |
| "tweak": "90120912eba3c19c", | |
| "msg": [3], | |
| "ct": [], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 2, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 7, | |
| "comment": "small message size", | |
| "flags": [ | |
| "SmallMessageSize" | |
| ], | |
| "key": "ad65778960d778c614e2673dee073acb", | |
| "tweak": "4505f45a8fa30b90", | |
| "msg": [1, 31], | |
| "ct": [31, 22], | |
| "result": "valid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 3, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 8, | |
| "comment": "small message size", | |
| "flags": [ | |
| "SmallMessageSize" | |
| ], | |
| "key": "aa6f23f573da39b110f4e155c418ba1f", | |
| "tweak": "8402018f66fd2cb9", | |
| "msg": [0, 4, 1], | |
| "ct": [7, 23, 28], | |
| "result": "valid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 192, | |
| "msgSize": 2, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 9, | |
| "comment": "small message size", | |
| "flags": [ | |
| "SmallMessageSize" | |
| ], | |
| "key": "911c9e0a87977587050ebb48f4f9e199fde8472781ecaf7a", | |
| "tweak": "cf98ea96ef005bc6", | |
| "msg": [1, 26], | |
| "ct": [10, 22], | |
| "result": "valid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 192, | |
| "msgSize": 3, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 10, | |
| "comment": "small message size", | |
| "flags": [ | |
| "SmallMessageSize" | |
| ], | |
| "key": "3c453964f4e42587db3a6de5de00673ede7e17672a4deb84", | |
| "tweak": "fe6290783f11946c", | |
| "msg": [15, 24, 7], | |
| "ct": [26, 31, 5], | |
| "result": "valid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 256, | |
| "msgSize": 2, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 11, | |
| "comment": "small message size", | |
| "flags": [ | |
| "SmallMessageSize" | |
| ], | |
| "key": "d05ae6e3819e2dcdd218be7c62465e8f1474f1fec8e79a1a3f7b88040d0f4160", | |
| "tweak": "823988f1ffb8ce23", | |
| "msg": [13, 29], | |
| "ct": [6, 20], | |
| "result": "valid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 256, | |
| "msgSize": 3, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 12, | |
| "comment": "small message size", | |
| "flags": [ | |
| "SmallMessageSize" | |
| ], | |
| "key": "1399758fa1ebf7cfda5f601c643443adaea4f4f8c19fc8772c5d5e3cc0cc6955", | |
| "tweak": "8c5a263a91b7cb4f", | |
| "msg": [5, 15, 4], | |
| "ct": [19, 5, 6], | |
| "result": "valid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 4, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 13, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "5dd5899794ff9b5007b4481aaa97f882", | |
| "tweak": "742f7f8b2ab0dc48", | |
| "msg": [3, 31, 18, 22], | |
| "ct": [14, 12, 8, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 14, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [0, 0, 0, 0], | |
| "ct": [16, 27, 28, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 15, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [31, 31, 31, 31], | |
| "ct": [16, 20, 15, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 16, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [16, 0, 16, 0], | |
| "ct": [1, 12, 16, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 17, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [15, 31, 15, 31], | |
| "ct": [16, 14, 12, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 18, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [27, 23, 24, 24], | |
| "ct": [3, 13, 28, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 19, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [28, 14, 17, 24], | |
| "ct": [25, 26, 2, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 20, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [15, 3, 13, 6], | |
| "ct": [5, 30, 5, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 21, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [17, 24, 10, 18], | |
| "ct": [16, 25, 7, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 22, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [18, 21, 12, 5], | |
| "ct": [26, 23, 4, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 23, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [19, 10, 16, 2], | |
| "ct": [10, 28, 11, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 24, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [29, 29, 24, 27], | |
| "ct": [1, 15, 5, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 25, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [19, 10, 15, 13], | |
| "ct": [22, 15, 7, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 26, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [0, 16, 15, 5], | |
| "ct": [0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 27, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [5, 20, 19, 21], | |
| "ct": [31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 28, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [22, 25, 24, 7], | |
| "ct": [16, 0, 16, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 29, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "16e4e676552c2fef6f1942adef4c440a", | |
| "tweak": "aba4ba6db9422dc4", | |
| "msg": [23, 1, 24, 21], | |
| "ct": [15, 31, 15, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 30, | |
| "comment": "y = 1 and a = 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "0b1a495502be595e2dd2d0dd35", | |
| "msg": [29, 17, 22, 11], | |
| "ct": [19, 6, 16, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 31, | |
| "comment": "y = 1 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "0b1a495502be595e2dd2d0dd35", | |
| "msg": [3, 17, 31, 2], | |
| "ct": [26, 3, 7, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 32, | |
| "comment": "y = 1 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "0b1a495502be595e2dd2d0dd35", | |
| "msg": [27, 29, 10, 14], | |
| "ct": [20, 27, 15, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 33, | |
| "comment": "y = 1 and (y + a) % radix**2 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "0b1a495502be595e2dd2d0dd35", | |
| "msg": [23, 27, 11, 28], | |
| "ct": [4, 13, 29, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 34, | |
| "comment": "y = 1 and (y + a) % radix**2 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "0b1a495502be595e2dd2d0dd35", | |
| "msg": [25, 10, 14, 23], | |
| "ct": [5, 7, 13, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 35, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "492299ebf06853b6f34a50fa5d", | |
| "msg": [3, 13, 24, 1], | |
| "ct": [14, 21, 12, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 36, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "492299ebf06853b6f34a50fa5d", | |
| "msg": [6, 26, 10, 6], | |
| "ct": [8, 24, 11, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 37, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**2 is maximal in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "492299ebf06853b6f34a50fa5d", | |
| "msg": [13, 14, 11, 30], | |
| "ct": [11, 13, 15, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 38, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**2 == 0 in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "492299ebf06853b6f34a50fa5d", | |
| "msg": [3, 3, 21, 10], | |
| "ct": [21, 16, 5, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 39, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "492299ebf06853b6f34a50fa5d", | |
| "msg": [8, 7, 23, 3], | |
| "ct": [19, 9, 15, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 40, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "492299ebf06853b6f34a50fa5d", | |
| "msg": [2, 25, 13, 24], | |
| "ct": [14, 9, 25, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 41, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**2 is maximal in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "770fad23275198b6d2395d3273", | |
| "msg": [19, 24, 6, 13], | |
| "ct": [22, 21, 2, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 42, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**2 == 0 in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "770fad23275198b6d2395d3273", | |
| "msg": [28, 21, 25, 23], | |
| "ct": [16, 4, 26, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 43, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "770fad23275198b6d2395d3273", | |
| "msg": [20, 18, 1, 12], | |
| "ct": [13, 13, 9, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 44, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a88f0018e583ed7310f3f5336e592a25", | |
| "tweak": "770fad23275198b6d2395d3273", | |
| "msg": [4, 6, 3, 0], | |
| "ct": [29, 29, 28, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 45, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8a74f1cae832ef8d58c26b49157c187b", | |
| "tweak": "d7b8bdae53aba381", | |
| "msg": [-1, 12, 11, 24], | |
| "ct": [17, 8, 7, 13], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 46, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8a74f1cae832ef8d58c26b49157c187b", | |
| "tweak": "d7b8bdae53aba381", | |
| "msg": [4, -1, 11, 24], | |
| "ct": [28, 28, 13, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 47, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8a74f1cae832ef8d58c26b49157c187b", | |
| "tweak": "d7b8bdae53aba381", | |
| "msg": [4, 12, 11, -1], | |
| "ct": [23, 5, 11, 0], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 48, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ec708b273a7f4b48ce3f1fdce2d0be94", | |
| "tweak": "ab4287d00006ea8c", | |
| "msg": [32, 26, 28, 10], | |
| "ct": [27, 9, 27, 17], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 49, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ec708b273a7f4b48ce3f1fdce2d0be94", | |
| "tweak": "ab4287d00006ea8c", | |
| "msg": [7, 32, 28, 10], | |
| "ct": [19, 20, 3, 4], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 50, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ec708b273a7f4b48ce3f1fdce2d0be94", | |
| "tweak": "ab4287d00006ea8c", | |
| "msg": [7, 26, 28, 32], | |
| "ct": [11, 5, 23, 18], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 5, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 51, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "0319599d6c7ca301230ec2b06c681097", | |
| "tweak": "125fd8f86c787e2d", | |
| "msg": [0, 9, 19, 9, 2], | |
| "ct": [0, 14, 19, 23, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 52, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [0, 0, 0, 0, 0], | |
| "ct": [25, 15, 27, 12, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 53, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [31, 31, 31, 31, 31], | |
| "ct": [11, 23, 6, 26, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 54, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [16, 0, 16, 0, 0], | |
| "ct": [1, 4, 3, 9, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 55, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [15, 31, 15, 31, 31], | |
| "ct": [30, 17, 7, 9, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 56, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [16, 16, 3, 14, 7], | |
| "ct": [1, 17, 23, 21, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 57, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [21, 29, 5, 11, 28], | |
| "ct": [3, 27, 9, 12, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 58, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [18, 31, 16, 10, 21], | |
| "ct": [23, 26, 15, 31, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 59, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [10, 19, 6, 17, 3], | |
| "ct": [11, 3, 15, 10, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 60, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [10, 6, 31, 18, 16], | |
| "ct": [16, 29, 14, 6, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 61, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [31, 7, 6, 17, 31], | |
| "ct": [31, 8, 16, 1, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 62, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [11, 2, 13, 15, 29], | |
| "ct": [19, 21, 7, 30, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 63, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [11, 27, 18, 21, 10], | |
| "ct": [8, 16, 6, 13, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 64, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [23, 15, 3, 11, 30], | |
| "ct": [0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 65, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [14, 24, 23, 10, 26], | |
| "ct": [31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 66, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [14, 8, 24, 18, 31], | |
| "ct": [16, 0, 16, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 67, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "ed3d0c6668748336d74abc8a161dea33", | |
| "tweak": "61a3e1c030481108", | |
| "msg": [22, 22, 29, 15, 2], | |
| "ct": [15, 31, 15, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 68, | |
| "comment": "y = 0 and (y + a) % radix**2 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "6c0208a407908c52965caa76cd", | |
| "msg": [9, 6, 19, 30, 13], | |
| "ct": [0, 0, 23, 23, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 69, | |
| "comment": "y = 0 and a = 1 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "6c0208a407908c52965caa76cd", | |
| "msg": [25, 21, 28, 8, 26], | |
| "ct": [0, 1, 29, 31, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 70, | |
| "comment": "y = 0 and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "6c0208a407908c52965caa76cd", | |
| "msg": [21, 30, 7, 31, 0], | |
| "ct": [16, 0, 11, 2, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 71, | |
| "comment": "y = 0 and (y + a) % radix**2 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "6c0208a407908c52965caa76cd", | |
| "msg": [25, 14, 16, 11, 15], | |
| "ct": [31, 31, 26, 8, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 72, | |
| "comment": "y = 1 and a = 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "3ef9c58e7e9c16eed02fc8dd06", | |
| "msg": [23, 14, 3, 30, 30], | |
| "ct": [3, 28, 20, 28, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 73, | |
| "comment": "y = 1 and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "3ef9c58e7e9c16eed02fc8dd06", | |
| "msg": [18, 26, 19, 3, 17], | |
| "ct": [6, 24, 14, 21, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 74, | |
| "comment": "y = 1 and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "3ef9c58e7e9c16eed02fc8dd06", | |
| "msg": [6, 24, 9, 25, 30], | |
| "ct": [0, 21, 16, 19, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 75, | |
| "comment": "y = 1 and (y + a) % radix**2 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "3ef9c58e7e9c16eed02fc8dd06", | |
| "msg": [12, 21, 21, 2, 22], | |
| "ct": [25, 1, 25, 3, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 76, | |
| "comment": "y = 1 and (y + a) % radix**2 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "3ef9c58e7e9c16eed02fc8dd06", | |
| "msg": [18, 29, 16, 4, 19], | |
| "ct": [4, 27, 5, 5, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 77, | |
| "comment": "y is maximal and (y + a) % radix**2 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "c670341626f72241b2f74d92ca", | |
| "msg": [23, 5, 15, 30, 10], | |
| "ct": [0, 2, 9, 26, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 78, | |
| "comment": "y is maximal and (y + a) % radix**2 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "c670341626f72241b2f74d92ca", | |
| "msg": [17, 31, 4, 15, 1], | |
| "ct": [3, 23, 27, 0, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 79, | |
| "comment": "y is maximal and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "c670341626f72241b2f74d92ca", | |
| "msg": [30, 23, 10, 9, 11], | |
| "ct": [31, 23, 26, 18, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 80, | |
| "comment": "y is maximal and a is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "c670341626f72241b2f74d92ca", | |
| "msg": [19, 16, 22, 31, 8], | |
| "ct": [6, 7, 29, 18, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 81, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d2946e285ba718e9a55871bc7b", | |
| "msg": [20, 23, 25, 29, 13], | |
| "ct": [19, 24, 10, 17, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 82, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d2946e285ba718e9a55871bc7b", | |
| "msg": [15, 17, 0, 2, 18], | |
| "ct": [4, 27, 17, 22, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 83, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**2 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d2946e285ba718e9a55871bc7b", | |
| "msg": [7, 15, 11, 4, 4], | |
| "ct": [7, 1, 24, 14, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 84, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**2 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d2946e285ba718e9a55871bc7b", | |
| "msg": [7, 8, 19, 19, 10], | |
| "ct": [18, 27, 20, 6, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 85, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d2946e285ba718e9a55871bc7b", | |
| "msg": [14, 0, 4, 10, 6], | |
| "ct": [11, 27, 29, 23, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 86, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d2946e285ba718e9a55871bc7b", | |
| "msg": [14, 29, 30, 3, 8], | |
| "ct": [0, 10, 25, 16, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 87, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**2 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d31fc918313589f413a911f559", | |
| "msg": [0, 0, 19, 19, 0], | |
| "ct": [6, 1, 12, 18, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 88, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**2 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d31fc918313589f413a911f559", | |
| "msg": [0, 1, 19, 19, 0], | |
| "ct": [26, 9, 7, 22, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 89, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d31fc918313589f413a911f559", | |
| "msg": [16, 0, 19, 19, 0], | |
| "ct": [27, 27, 3, 17, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 90, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "2dcc7a48fa759e58062f64099e2654fb", | |
| "tweak": "d31fc918313589f413a911f559", | |
| "msg": [31, 31, 19, 19, 0], | |
| "ct": [17, 12, 29, 31, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 91, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8d8a7cd63e6554b77d0345f3d799bfad", | |
| "tweak": "ea7fef1b2f555ad8", | |
| "msg": [-1, 25, 22, 1, 19], | |
| "ct": [15, 18, 8, 12, 14], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 92, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8d8a7cd63e6554b77d0345f3d799bfad", | |
| "tweak": "ea7fef1b2f555ad8", | |
| "msg": [4, -1, 22, 1, 19], | |
| "ct": [19, 11, 9, 25, 5], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 93, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8d8a7cd63e6554b77d0345f3d799bfad", | |
| "tweak": "ea7fef1b2f555ad8", | |
| "msg": [4, 25, 22, 1, -1], | |
| "ct": [15, 7, 5, 31, 14], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 94, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "d9661015b6a08549fe72e83da279e8cc", | |
| "tweak": "c8517c169b1534bb", | |
| "msg": [32, 30, 29, 7, 25], | |
| "ct": [23, 23, 12, 12, 19], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 95, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "d9661015b6a08549fe72e83da279e8cc", | |
| "tweak": "c8517c169b1534bb", | |
| "msg": [7, 32, 29, 7, 25], | |
| "ct": [30, 7, 24, 26, 1], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 96, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "d9661015b6a08549fe72e83da279e8cc", | |
| "tweak": "c8517c169b1534bb", | |
| "msg": [7, 30, 29, 7, 32], | |
| "ct": [7, 2, 8, 26, 23], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 6, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 97, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "474bbf2aff5c252419c49a07d50e2bdf", | |
| "tweak": "d64296c362368a3d", | |
| "msg": [7, 4, 18, 23, 10, 1], | |
| "ct": [19, 9, 19, 26, 26, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 98, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [0, 0, 0, 0, 0, 0], | |
| "ct": [18, 2, 18, 5, 30, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 99, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [31, 31, 31, 31, 31, 31], | |
| "ct": [10, 28, 23, 20, 1, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 100, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [16, 0, 0, 16, 0, 0], | |
| "ct": [22, 21, 1, 18, 16, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 101, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [15, 31, 31, 15, 31, 31], | |
| "ct": [0, 19, 8, 10, 15, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 102, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [10, 16, 17, 11, 19, 31], | |
| "ct": [23, 31, 20, 6, 1, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 103, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [28, 4, 14, 21, 19, 19], | |
| "ct": [6, 15, 0, 27, 2, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 104, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [29, 28, 26, 15, 19, 22], | |
| "ct": [10, 2, 25, 20, 3, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 105, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [1, 4, 6, 16, 1, 20], | |
| "ct": [3, 30, 19, 29, 14, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 106, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [20, 14, 6, 8, 6, 27], | |
| "ct": [0, 28, 21, 17, 7, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 107, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [14, 6, 23, 2, 27, 4], | |
| "ct": [4, 24, 5, 20, 28, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 108, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [15, 1, 17, 5, 8, 8], | |
| "ct": [15, 29, 26, 30, 7, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 109, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [20, 8, 21, 13, 6, 13], | |
| "ct": [14, 30, 9, 25, 3, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 110, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [8, 7, 8, 19, 13, 9], | |
| "ct": [0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 111, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [2, 1, 3, 8, 6, 8], | |
| "ct": [31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 112, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [4, 28, 4, 6, 26, 19], | |
| "ct": [16, 0, 0, 16, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 113, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "26dbd1998c3a046ac3ff11937079c034", | |
| "tweak": "5e551c3daad7e5fa", | |
| "msg": [12, 19, 10, 20, 15, 13], | |
| "ct": [15, 31, 31, 15, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 114, | |
| "comment": "y = 0 and (y + a) % radix**3 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4cb1eafdb7a22e17a5a5eb5fc9", | |
| "msg": [0, 0, 0, 13, 9, 4], | |
| "ct": [15, 0, 16, 29, 24, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 115, | |
| "comment": "y = 0 and a = 1 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4cb1eafdb7a22e17a5a5eb5fc9", | |
| "msg": [0, 0, 1, 13, 9, 4], | |
| "ct": [19, 20, 16, 27, 1, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 116, | |
| "comment": "y = 0 and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4cb1eafdb7a22e17a5a5eb5fc9", | |
| "msg": [16, 0, 0, 13, 9, 4], | |
| "ct": [15, 20, 8, 3, 11, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 117, | |
| "comment": "y = 0 and (y + a) % radix**3 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4cb1eafdb7a22e17a5a5eb5fc9", | |
| "msg": [31, 31, 31, 13, 9, 4], | |
| "ct": [26, 1, 5, 22, 25, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 118, | |
| "comment": "y = 1 and a = 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa69619c16a5d81e989682e3", | |
| "msg": [11, 26, 13, 16, 25, 31], | |
| "ct": [0, 0, 1, 26, 6, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 119, | |
| "comment": "y = 1 and a = 1 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa69619c16a5d81e989682e3", | |
| "msg": [3, 23, 7, 7, 5, 15], | |
| "ct": [0, 0, 2, 0, 7, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 120, | |
| "comment": "y = 1 and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa69619c16a5d81e989682e3", | |
| "msg": [24, 16, 20, 12, 5, 1], | |
| "ct": [16, 0, 1, 8, 9, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 121, | |
| "comment": "y = 1 and (y + a) % radix**3 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa69619c16a5d81e989682e3", | |
| "msg": [10, 9, 21, 23, 22, 4], | |
| "ct": [31, 31, 31, 30, 10, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 122, | |
| "comment": "y = 1 and (y + a) % radix**3 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa69619c16a5d81e989682e3", | |
| "msg": [31, 17, 9, 16, 27, 22], | |
| "ct": [0, 0, 0, 26, 16, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 123, | |
| "comment": "y is maximal and (y + a) % radix**3 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "a9ec554f6021d0d1fd10ea0a09", | |
| "msg": [29, 25, 4, 14, 21, 13], | |
| "ct": [31, 26, 1, 19, 24, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 124, | |
| "comment": "y is maximal and (y + a) % radix**3 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "a9ec554f6021d0d1fd10ea0a09", | |
| "msg": [22, 23, 9, 3, 10, 20], | |
| "ct": [5, 27, 16, 29, 18, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 125, | |
| "comment": "y is maximal and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "a9ec554f6021d0d1fd10ea0a09", | |
| "msg": [16, 27, 3, 13, 19, 0], | |
| "ct": [30, 16, 23, 15, 13, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 126, | |
| "comment": "y is maximal and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "a9ec554f6021d0d1fd10ea0a09", | |
| "msg": [16, 12, 23, 24, 12, 4], | |
| "ct": [28, 3, 16, 23, 31, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 127, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4fc109949c9b9fc3ceeff7ef3f", | |
| "msg": [2, 24, 10, 25, 21, 31], | |
| "ct": [31, 31, 0, 5, 12, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 128, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4fc109949c9b9fc3ceeff7ef3f", | |
| "msg": [28, 29, 27, 22, 15, 26], | |
| "ct": [31, 31, 1, 9, 5, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 129, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**3 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4fc109949c9b9fc3ceeff7ef3f", | |
| "msg": [13, 10, 21, 17, 4, 30], | |
| "ct": [31, 31, 31, 30, 17, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 130, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**3 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4fc109949c9b9fc3ceeff7ef3f", | |
| "msg": [20, 0, 12, 9, 4, 26], | |
| "ct": [0, 0, 0, 10, 20, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 131, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4fc109949c9b9fc3ceeff7ef3f", | |
| "msg": [27, 13, 31, 21, 26, 7], | |
| "ct": [15, 31, 0, 29, 8, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 132, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "4fc109949c9b9fc3ceeff7ef3f", | |
| "msg": [27, 22, 15, 20, 10, 27], | |
| "ct": [31, 30, 31, 15, 31, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 133, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**3 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa7a6a8d7d5229e0205e74ee", | |
| "msg": [12, 7, 3, 10, 14, 16], | |
| "ct": [14, 0, 21, 10, 2, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 134, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**3 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa7a6a8d7d5229e0205e74ee", | |
| "msg": [25, 29, 29, 11, 12, 18], | |
| "ct": [6, 4, 4, 15, 10, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 135, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa7a6a8d7d5229e0205e74ee", | |
| "msg": [2, 22, 10, 19, 14, 21], | |
| "ct": [9, 18, 23, 7, 1, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 136, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6a24278db37f29768c4263256ffbd956", | |
| "tweak": "97fa7a6a8d7d5229e0205e74ee", | |
| "msg": [1, 29, 31, 12, 29, 1], | |
| "ct": [4, 25, 17, 21, 8, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 137, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ed4561abc903a9e722ddb8aa94cc662d", | |
| "tweak": "975f6d7701e004f7", | |
| "msg": [-1, 18, 4, 12, 15, 1], | |
| "ct": [16, 10, 16, 3, 11, 16], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 138, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ed4561abc903a9e722ddb8aa94cc662d", | |
| "tweak": "975f6d7701e004f7", | |
| "msg": [0, 18, -1, 12, 15, 1], | |
| "ct": [11, 26, 14, 10, 5, 29], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 139, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ed4561abc903a9e722ddb8aa94cc662d", | |
| "tweak": "975f6d7701e004f7", | |
| "msg": [0, 18, 4, 12, 15, -1], | |
| "ct": [14, 25, 1, 17, 22, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 140, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "9c9a6bb4c005fd578a59e60bfa1bdcee", | |
| "tweak": "e56a524556ddc899", | |
| "msg": [32, 30, 24, 19, 28, 20], | |
| "ct": [4, 6, 25, 26, 13, 14], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 141, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "9c9a6bb4c005fd578a59e60bfa1bdcee", | |
| "tweak": "e56a524556ddc899", | |
| "msg": [19, 30, 32, 19, 28, 20], | |
| "ct": [15, 31, 30, 12, 27, 20], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 142, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "9c9a6bb4c005fd578a59e60bfa1bdcee", | |
| "tweak": "e56a524556ddc899", | |
| "msg": [19, 30, 24, 19, 28, 32], | |
| "ct": [28, 22, 22, 25, 28, 31], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 7, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 143, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "20b2c30d44c72c32a4564541332f45c3", | |
| "tweak": "3de9de4b8736f463", | |
| "msg": [17, 27, 22, 22, 5, 8, 18], | |
| "ct": [3, 26, 10, 31, 4, 3, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 144, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [0, 0, 0, 0, 0, 0, 0], | |
| "ct": [11, 12, 9, 13, 7, 6, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 145, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [31, 31, 31, 31, 31, 31, 31], | |
| "ct": [5, 27, 17, 27, 1, 20, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 146, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [16, 0, 0, 16, 0, 0, 0], | |
| "ct": [8, 1, 28, 17, 11, 11, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 147, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [15, 31, 31, 15, 31, 31, 31], | |
| "ct": [20, 20, 11, 19, 11, 22, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 148, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [25, 8, 21, 2, 10, 26, 15], | |
| "ct": [7, 27, 17, 0, 3, 1, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 149, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [16, 22, 17, 22, 31, 23, 25], | |
| "ct": [19, 19, 5, 17, 6, 13, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 150, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [20, 0, 6, 18, 15, 14, 3], | |
| "ct": [0, 20, 8, 16, 31, 22, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 151, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [15, 12, 30, 29, 23, 6, 29], | |
| "ct": [5, 21, 15, 20, 0, 8, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 152, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [28, 20, 25, 0, 19, 24, 16], | |
| "ct": [17, 25, 21, 29, 27, 22, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 153, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [26, 1, 18, 15, 9, 0, 26], | |
| "ct": [14, 25, 13, 4, 22, 6, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 154, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [20, 12, 31, 11, 28, 26, 20], | |
| "ct": [10, 23, 22, 20, 28, 29, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 155, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [25, 2, 28, 19, 22, 24, 30], | |
| "ct": [7, 29, 13, 1, 6, 14, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 156, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [11, 30, 15, 2, 8, 21, 14], | |
| "ct": [0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 157, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [25, 11, 16, 21, 13, 16, 26], | |
| "ct": [31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 158, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [27, 8, 1, 20, 1, 2, 6], | |
| "ct": [16, 0, 0, 16, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 159, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "53b43d40c44c62982d5123e5716d25db", | |
| "tweak": "c34af5583d26dacc", | |
| "msg": [20, 26, 7, 12, 30, 2, 17], | |
| "ct": [15, 31, 31, 15, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 160, | |
| "comment": "y = 0 and (y + a) % radix**3 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2159faee8f7e03237a1bcb3a", | |
| "msg": [17, 11, 28, 28, 7, 19, 9], | |
| "ct": [0, 0, 0, 16, 4, 14, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 161, | |
| "comment": "y = 0 and a = 1 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2159faee8f7e03237a1bcb3a", | |
| "msg": [11, 30, 5, 18, 17, 9, 24], | |
| "ct": [0, 0, 1, 7, 18, 18, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 162, | |
| "comment": "y = 0 and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2159faee8f7e03237a1bcb3a", | |
| "msg": [23, 13, 4, 0, 12, 1, 16], | |
| "ct": [16, 0, 0, 18, 28, 28, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 163, | |
| "comment": "y = 0 and (y + a) % radix**3 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2159faee8f7e03237a1bcb3a", | |
| "msg": [28, 29, 14, 10, 12, 10, 5], | |
| "ct": [31, 31, 31, 9, 19, 20, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 164, | |
| "comment": "y = 1 and a = 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2d3d3b00a269b3d776ca1ace", | |
| "msg": [0, 0, 0, 8, 5, 3, 27], | |
| "ct": [19, 6, 22, 3, 21, 25, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 165, | |
| "comment": "y = 1 and a = 1 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2d3d3b00a269b3d776ca1ace", | |
| "msg": [0, 0, 1, 8, 5, 3, 27], | |
| "ct": [5, 30, 20, 4, 22, 28, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 166, | |
| "comment": "y = 1 and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2d3d3b00a269b3d776ca1ace", | |
| "msg": [16, 0, 0, 8, 5, 3, 27], | |
| "ct": [1, 8, 9, 30, 25, 26, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 167, | |
| "comment": "y = 1 and (y + a) % radix**3 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2d3d3b00a269b3d776ca1ace", | |
| "msg": [31, 31, 30, 8, 5, 3, 27], | |
| "ct": [28, 29, 13, 29, 14, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 168, | |
| "comment": "y = 1 and (y + a) % radix**3 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "2d3d3b00a269b3d776ca1ace", | |
| "msg": [31, 31, 31, 8, 5, 3, 27], | |
| "ct": [11, 9, 25, 12, 5, 8, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 169, | |
| "comment": "y is maximal and (y + a) % radix**3 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "9be87f53b322df33d3b58889", | |
| "msg": [14, 23, 21, 6, 4, 15, 3], | |
| "ct": [31, 31, 31, 1, 29, 12, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 170, | |
| "comment": "y is maximal and (y + a) % radix**3 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "9be87f53b322df33d3b58889", | |
| "msg": [6, 25, 27, 1, 14, 15, 30], | |
| "ct": [0, 0, 0, 2, 27, 21, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 171, | |
| "comment": "y is maximal and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "9be87f53b322df33d3b58889", | |
| "msg": [6, 0, 14, 7, 31, 12, 0], | |
| "ct": [15, 31, 31, 13, 19, 12, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 172, | |
| "comment": "y is maximal and a is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "9be87f53b322df33d3b58889", | |
| "msg": [26, 30, 11, 24, 31, 16, 10], | |
| "ct": [31, 31, 30, 8, 10, 8, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 173, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "0472004746df5b1bf8755f30", | |
| "msg": [0, 0, 0, 4, 24, 2, 23], | |
| "ct": [0, 27, 3, 26, 4, 13, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 174, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "0472004746df5b1bf8755f30", | |
| "msg": [0, 0, 1, 4, 24, 2, 23], | |
| "ct": [25, 23, 29, 13, 18, 2, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 175, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**3 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "0472004746df5b1bf8755f30", | |
| "msg": [0, 0, 31, 4, 24, 2, 23], | |
| "ct": [12, 10, 5, 29, 21, 23, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 176, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**3 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "0472004746df5b1bf8755f30", | |
| "msg": [0, 1, 0, 4, 24, 2, 23], | |
| "ct": [23, 19, 18, 15, 1, 22, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 177, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "0472004746df5b1bf8755f30", | |
| "msg": [16, 0, 0, 4, 24, 2, 23], | |
| "ct": [24, 17, 0, 7, 21, 28, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 178, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "0472004746df5b1bf8755f30", | |
| "msg": [31, 31, 31, 4, 24, 2, 23], | |
| "ct": [29, 3, 21, 23, 1, 29, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 179, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**3 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "5815c2698eb3948ff7cb5c54", | |
| "msg": [0, 0, 0, 26, 19, 24, 31], | |
| "ct": [9, 23, 31, 18, 9, 26, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 180, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**3 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "5815c2698eb3948ff7cb5c54", | |
| "msg": [0, 0, 1, 26, 19, 24, 31], | |
| "ct": [28, 26, 1, 18, 15, 25, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 181, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "5815c2698eb3948ff7cb5c54", | |
| "msg": [16, 0, 0, 26, 19, 24, 31], | |
| "ct": [3, 5, 18, 18, 6, 29, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 182, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ad837c09903b33e60eecfa1d04308e32", | |
| "tweak": "5815c2698eb3948ff7cb5c54", | |
| "msg": [31, 31, 31, 26, 19, 24, 31], | |
| "ct": [8, 0, 0, 13, 28, 3, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 183, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ea35a8f24783be82abd93cc74e4944cb", | |
| "tweak": "a704f808982bb10f", | |
| "msg": [-1, 10, 17, 29, 13, 18, 4], | |
| "ct": [9, 3, 19, 1, 0, 22, 24], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 184, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ea35a8f24783be82abd93cc74e4944cb", | |
| "tweak": "a704f808982bb10f", | |
| "msg": [26, 10, -1, 29, 13, 18, 4], | |
| "ct": [6, 8, 14, 13, 27, 7, 25], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 185, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ea35a8f24783be82abd93cc74e4944cb", | |
| "tweak": "a704f808982bb10f", | |
| "msg": [26, 10, 17, 29, 13, 18, -1], | |
| "ct": [30, 20, 4, 0, 16, 31, 26], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 186, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8d52668225ea12e680df928edff72b7b", | |
| "tweak": "0a5902682964a1aa", | |
| "msg": [32, 2, 6, 5, 21, 13, 15], | |
| "ct": [31, 23, 28, 14, 4, 0, 18], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 187, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8d52668225ea12e680df928edff72b7b", | |
| "tweak": "0a5902682964a1aa", | |
| "msg": [26, 2, 32, 5, 21, 13, 15], | |
| "ct": [4, 0, 2, 26, 31, 25, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 188, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8d52668225ea12e680df928edff72b7b", | |
| "tweak": "0a5902682964a1aa", | |
| "msg": [26, 2, 6, 5, 21, 13, 32], | |
| "ct": [31, 2, 22, 13, 4, 8, 27], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 8, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 189, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "60d83b209822c0d9b7033dca86444fa1", | |
| "tweak": "23ef05b155a108c4", | |
| "msg": [1, 26, 13, 21, 14, 26, 8, 23], | |
| "ct": [9, 22, 20, 22, 5, 19, 4, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 190, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [25, 30, 5, 19, 31, 12, 22, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 191, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [1, 29, 18, 1, 31, 9, 1, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 192, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [16, 0, 0, 0, 16, 0, 0, 0], | |
| "ct": [29, 11, 27, 30, 8, 28, 21, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 193, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [15, 31, 31, 31, 15, 31, 31, 31], | |
| "ct": [19, 5, 5, 9, 15, 10, 27, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 194, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [26, 28, 29, 0, 28, 13, 2, 5], | |
| "ct": [12, 22, 6, 7, 4, 24, 21, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 195, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [1, 31, 2, 22, 21, 31, 12, 0], | |
| "ct": [8, 20, 26, 14, 2, 17, 5, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 196, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [2, 10, 4, 27, 24, 4, 11, 23], | |
| "ct": [25, 28, 9, 11, 4, 15, 8, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 197, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [22, 22, 8, 28, 13, 20, 17, 8], | |
| "ct": [18, 7, 9, 5, 30, 8, 14, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 198, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [9, 14, 1, 12, 12, 3, 3, 19], | |
| "ct": [8, 19, 23, 5, 25, 20, 25, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 199, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [31, 18, 7, 4, 29, 2, 19, 21], | |
| "ct": [16, 30, 24, 11, 18, 15, 0, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 200, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [15, 16, 4, 31, 5, 11, 30, 3], | |
| "ct": [18, 4, 26, 6, 27, 8, 20, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 201, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [8, 31, 8, 16, 23, 23, 30, 22], | |
| "ct": [31, 6, 11, 2, 16, 5, 27, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 202, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [2, 29, 23, 26, 14, 6, 9, 5], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 203, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [23, 26, 4, 1, 16, 27, 24, 14], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 204, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [22, 3, 11, 30, 9, 14, 4, 19], | |
| "ct": [16, 0, 0, 0, 16, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 205, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3bfee9ab1eadaa8cff5b05281fcb0140", | |
| "tweak": "2024d5e34b3ba6a0", | |
| "msg": [13, 6, 0, 27, 22, 9, 25, 16], | |
| "ct": [15, 31, 31, 31, 15, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 206, | |
| "comment": "y = 0 and (y + a) % radix**4 == 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "ed55decef10feac24c7eb947", | |
| "msg": [12, 7, 15, 30, 31, 12, 28, 29], | |
| "ct": [4, 26, 21, 31, 26, 22, 4, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 207, | |
| "comment": "y = 0 and a = 1 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "ed55decef10feac24c7eb947", | |
| "msg": [1, 10, 15, 31, 31, 19, 30, 28], | |
| "ct": [20, 15, 8, 17, 9, 2, 18, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 208, | |
| "comment": "y = 0 and a has large Hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "ed55decef10feac24c7eb947", | |
| "msg": [12, 23, 1, 14, 31, 18, 0, 10], | |
| "ct": [31, 23, 10, 0, 6, 9, 5, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 209, | |
| "comment": "y = 0 and (y + a) % radix**4 is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "ed55decef10feac24c7eb947", | |
| "msg": [29, 20, 31, 4, 1, 30, 11, 10], | |
| "ct": [16, 25, 11, 20, 27, 20, 6, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 210, | |
| "comment": "y = 1 and a = 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "6df45a5aeaf9db18f53e6446", | |
| "msg": [0, 0, 0, 0, 11, 25, 13, 5], | |
| "ct": [5, 10, 16, 17, 10, 14, 21, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 211, | |
| "comment": "y = 1 and a = 1 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "6df45a5aeaf9db18f53e6446", | |
| "msg": [0, 0, 0, 1, 11, 25, 13, 5], | |
| "ct": [15, 30, 15, 19, 7, 8, 14, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 212, | |
| "comment": "y = 1 and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "6df45a5aeaf9db18f53e6446", | |
| "msg": [16, 0, 0, 0, 11, 25, 13, 5], | |
| "ct": [10, 8, 9, 25, 4, 4, 29, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 213, | |
| "comment": "y = 1 and (y + a) % radix**4 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "6df45a5aeaf9db18f53e6446", | |
| "msg": [31, 31, 31, 30, 11, 25, 13, 5], | |
| "ct": [23, 24, 29, 0, 15, 28, 29, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 214, | |
| "comment": "y = 1 and (y + a) % radix**4 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "6df45a5aeaf9db18f53e6446", | |
| "msg": [31, 31, 31, 31, 11, 25, 13, 5], | |
| "ct": [25, 10, 17, 28, 22, 0, 23, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 215, | |
| "comment": "y is maximal and (y + a) % radix**4 is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "85aa724ba3746d33739f50bc", | |
| "msg": [25, 4, 0, 26, 16, 27, 3, 21], | |
| "ct": [24, 16, 6, 2, 14, 30, 9, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 216, | |
| "comment": "y is maximal and (y + a) % radix**4 == 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "85aa724ba3746d33739f50bc", | |
| "msg": [16, 23, 2, 23, 24, 17, 21, 13], | |
| "ct": [24, 0, 1, 2, 22, 11, 12, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 217, | |
| "comment": "y is maximal and a has large Hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "85aa724ba3746d33739f50bc", | |
| "msg": [15, 2, 19, 6, 25, 11, 31, 18], | |
| "ct": [25, 7, 2, 5, 2, 30, 15, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 218, | |
| "comment": "y is maximal and a is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "85aa724ba3746d33739f50bc", | |
| "msg": [11, 26, 1, 15, 17, 6, 7, 6], | |
| "ct": [15, 16, 1, 10, 20, 6, 15, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 219, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "1aa2b53bc5e862545a52254d", | |
| "msg": [28, 5, 27, 17, 8, 8, 11, 30], | |
| "ct": [27, 15, 3, 15, 23, 9, 3, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 220, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "1aa2b53bc5e862545a52254d", | |
| "msg": [5, 0, 13, 31, 23, 14, 26, 6], | |
| "ct": [15, 28, 12, 31, 23, 16, 25, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 221, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**4 is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "1aa2b53bc5e862545a52254d", | |
| "msg": [14, 8, 25, 24, 1, 6, 11, 5], | |
| "ct": [12, 26, 22, 5, 24, 13, 17, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 222, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**4 == 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "1aa2b53bc5e862545a52254d", | |
| "msg": [12, 22, 0, 16, 5, 7, 1, 19], | |
| "ct": [22, 7, 20, 14, 29, 10, 28, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 223, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "1aa2b53bc5e862545a52254d", | |
| "msg": [4, 29, 14, 6, 21, 12, 6, 12], | |
| "ct": [26, 26, 0, 2, 1, 26, 28, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 224, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "1aa2b53bc5e862545a52254d", | |
| "msg": [0, 27, 23, 21, 15, 20, 9, 31], | |
| "ct": [19, 31, 31, 4, 8, 14, 31, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 225, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**4 is maximal in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "e62b80da278129ce3cac7635", | |
| "msg": [28, 14, 23, 11, 25, 1, 27, 26], | |
| "ct": [18, 23, 13, 28, 28, 29, 23, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 226, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**4 == 0 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "e62b80da278129ce3cac7635", | |
| "msg": [31, 12, 14, 10, 8, 16, 2, 4], | |
| "ct": [31, 15, 31, 2, 17, 31, 8, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 227, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "e62b80da278129ce3cac7635", | |
| "msg": [16, 10, 28, 30, 14, 29, 9, 28], | |
| "ct": [20, 17, 17, 17, 22, 5, 22, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 228, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "475b7573760904fa57ad2cb88ea52f32", | |
| "tweak": "e62b80da278129ce3cac7635", | |
| "msg": [14, 21, 31, 15, 12, 25, 15, 23], | |
| "ct": [6, 29, 21, 26, 19, 24, 24, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 229, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ebc261665fab01ae2bfe156e54de3006", | |
| "tweak": "5080dd547abdeddd", | |
| "msg": [-1, 1, 15, 14, 21, 31, 22, 29], | |
| "ct": [30, 29, 17, 16, 17, 0, 16, 20], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 230, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ebc261665fab01ae2bfe156e54de3006", | |
| "tweak": "5080dd547abdeddd", | |
| "msg": [24, 1, -1, 14, 21, 31, 22, 29], | |
| "ct": [21, 25, 6, 22, 14, 18, 11, 21], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 231, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "ebc261665fab01ae2bfe156e54de3006", | |
| "tweak": "5080dd547abdeddd", | |
| "msg": [24, 1, 15, 14, 21, 31, 22, -1], | |
| "ct": [2, 17, 28, 9, 6, 10, 12, 14], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 232, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "672ac68e85d7f434a17d17af4573216c", | |
| "tweak": "a22625a564fc6e16", | |
| "msg": [32, 9, 15, 24, 27, 26, 19, 23], | |
| "ct": [5, 7, 20, 3, 31, 11, 2, 19], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 233, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "672ac68e85d7f434a17d17af4573216c", | |
| "tweak": "a22625a564fc6e16", | |
| "msg": [12, 9, 32, 24, 27, 26, 19, 23], | |
| "ct": [25, 8, 7, 1, 31, 1, 27, 4], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 234, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "672ac68e85d7f434a17d17af4573216c", | |
| "tweak": "a22625a564fc6e16", | |
| "msg": [12, 9, 15, 24, 27, 26, 19, 32], | |
| "ct": [18, 8, 17, 2, 4, 29, 25, 21], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 9, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 235, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "2215b9528000f5f306fcdfe2969c6785", | |
| "tweak": "0539d85c7b076285", | |
| "msg": [15, 29, 24, 26, 6, 4, 11, 7, 26], | |
| "ct": [2, 24, 29, 16, 29, 0, 0, 21, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 236, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [28, 23, 13, 13, 13, 12, 5, 24, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 237, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [3, 28, 18, 5, 16, 26, 10, 29, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 238, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [16, 0, 0, 0, 16, 0, 0, 0, 0], | |
| "ct": [7, 7, 9, 11, 16, 6, 16, 25, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 239, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [15, 31, 31, 31, 15, 31, 31, 31, 31], | |
| "ct": [16, 26, 9, 16, 17, 31, 16, 10, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 240, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [0, 0, 18, 5, 19, 4, 7, 3, 3], | |
| "ct": [1, 20, 1, 1, 4, 29, 16, 0, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 241, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [28, 0, 13, 18, 19, 3, 28, 18, 22], | |
| "ct": [9, 28, 30, 16, 31, 23, 15, 13, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 242, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [30, 7, 18, 30, 17, 7, 0, 9, 26], | |
| "ct": [30, 0, 29, 7, 18, 16, 18, 12, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 243, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [21, 19, 15, 14, 0, 0, 29, 7, 12], | |
| "ct": [10, 26, 30, 27, 0, 18, 20, 2, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 244, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [20, 4, 29, 7, 12, 19, 18, 30, 5], | |
| "ct": [30, 25, 13, 0, 2, 25, 16, 9, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 245, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [13, 24, 19, 13, 2, 17, 25, 3, 17], | |
| "ct": [21, 4, 12, 27, 5, 27, 24, 8, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 246, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [6, 25, 29, 3, 19, 25, 17, 12, 11], | |
| "ct": [21, 8, 7, 3, 19, 15, 8, 21, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 247, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [29, 26, 23, 6, 18, 4, 9, 16, 9], | |
| "ct": [28, 8, 17, 24, 28, 0, 23, 18, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 248, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [24, 2, 16, 28, 23, 0, 13, 31, 13], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 249, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [7, 9, 14, 27, 8, 0, 14, 7, 13], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 250, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [5, 2, 28, 18, 29, 4, 12, 9, 25], | |
| "ct": [16, 0, 0, 0, 16, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 251, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "4c00ade3e32b12866bb56e736e18eaf4", | |
| "tweak": "3f0bf1e88240178e", | |
| "msg": [30, 24, 25, 11, 28, 23, 7, 28, 22], | |
| "ct": [15, 31, 31, 31, 15, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 252, | |
| "comment": "y = 1 and a = 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ffd1210aa39547d2b9561f", | |
| "msg": [4, 12, 29, 28, 17, 27, 24, 3, 25], | |
| "ct": [0, 0, 0, 1, 12, 22, 1, 8, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 253, | |
| "comment": "y = 1 and a = 1 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ffd1210aa39547d2b9561f", | |
| "msg": [18, 16, 12, 1, 29, 7, 28, 25, 3], | |
| "ct": [0, 0, 0, 2, 10, 5, 22, 11, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 254, | |
| "comment": "y = 1 and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ffd1210aa39547d2b9561f", | |
| "msg": [26, 16, 12, 18, 16, 14, 29, 18, 13], | |
| "ct": [16, 0, 0, 1, 20, 28, 21, 12, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 255, | |
| "comment": "y = 1 and (y + a) % radix**4 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ffd1210aa39547d2b9561f", | |
| "msg": [30, 16, 31, 23, 14, 11, 15, 17, 23], | |
| "ct": [31, 31, 31, 31, 24, 5, 14, 5, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 256, | |
| "comment": "y = 1 and (y + a) % radix**4 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ffd1210aa39547d2b9561f", | |
| "msg": [17, 10, 15, 2, 14, 0, 4, 5, 16], | |
| "ct": [0, 0, 0, 0, 19, 3, 18, 21, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 257, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ecda610b044ca9db1f3042", | |
| "msg": [18, 18, 21, 29, 11, 4, 19, 28, 11], | |
| "ct": [25, 7, 28, 20, 23, 2, 7, 2, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 258, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ecda610b044ca9db1f3042", | |
| "msg": [26, 21, 4, 31, 24, 7, 20, 1, 11], | |
| "ct": [20, 7, 14, 25, 13, 20, 25, 24, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 259, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**4 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ecda610b044ca9db1f3042", | |
| "msg": [27, 22, 11, 19, 29, 16, 3, 24, 11], | |
| "ct": [27, 0, 16, 8, 30, 18, 6, 23, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 260, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**4 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ecda610b044ca9db1f3042", | |
| "msg": [20, 19, 31, 4, 24, 9, 14, 23, 10], | |
| "ct": [8, 1, 21, 12, 24, 31, 15, 11, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 261, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ecda610b044ca9db1f3042", | |
| "msg": [0, 3, 17, 19, 15, 0, 13, 15, 13], | |
| "ct": [6, 7, 12, 31, 30, 19, 4, 4, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 262, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "36e6ec14d7abaf2fa03904af42244b5f", | |
| "tweak": "ecda610b044ca9db1f3042", | |
| "msg": [0, 13, 13, 3, 13, 29, 12, 1, 24], | |
| "ct": [22, 28, 22, 18, 2, 4, 26, 8, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 263, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "7fd4e71784e95a3dd0b41315a67131d2", | |
| "tweak": "47d48ea4716ab8df", | |
| "msg": [-1, 3, 25, 22, 19, 27, 19, 9, 25], | |
| "ct": [28, 1, 15, 13, 2, 5, 30, 29, 17], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 264, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "7fd4e71784e95a3dd0b41315a67131d2", | |
| "tweak": "47d48ea4716ab8df", | |
| "msg": [22, 3, 25, -1, 19, 27, 19, 9, 25], | |
| "ct": [29, 22, 9, 14, 16, 16, 24, 5, 19], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 265, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "7fd4e71784e95a3dd0b41315a67131d2", | |
| "tweak": "47d48ea4716ab8df", | |
| "msg": [22, 3, 25, 22, 19, 27, 19, 9, -1], | |
| "ct": [15, 1, 2, 29, 26, 5, 8, 1, 3], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 266, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "09cdc15c0a4ce577e6177399e3257c7b", | |
| "tweak": "a7f011795cb24ee1", | |
| "msg": [32, 9, 14, 5, 24, 14, 30, 20, 11], | |
| "ct": [2, 9, 26, 17, 6, 29, 20, 29, 23], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 267, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "09cdc15c0a4ce577e6177399e3257c7b", | |
| "tweak": "a7f011795cb24ee1", | |
| "msg": [21, 9, 14, 32, 24, 14, 30, 20, 11], | |
| "ct": [31, 5, 30, 19, 8, 5, 3, 25, 12], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 268, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "09cdc15c0a4ce577e6177399e3257c7b", | |
| "tweak": "a7f011795cb24ee1", | |
| "msg": [21, 9, 14, 5, 24, 14, 30, 20, 32], | |
| "ct": [20, 20, 30, 25, 29, 4, 0, 18, 22], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 10, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 269, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "5474525ca99fb5da2babdbd45c727d16", | |
| "tweak": "f2cb4d9ba04b81f8", | |
| "msg": [29, 24, 16, 12, 20, 29, 8, 0, 2, 22], | |
| "ct": [11, 4, 24, 21, 31, 7, 12, 10, 28, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 270, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [24, 15, 26, 14, 22, 7, 25, 3, 4, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 271, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [1, 20, 2, 18, 12, 29, 11, 21, 13, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 272, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [16, 0, 0, 0, 0, 16, 0, 0, 0, 0], | |
| "ct": [11, 21, 12, 19, 13, 5, 14, 17, 9, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 273, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [15, 31, 31, 31, 31, 15, 31, 31, 31, 31], | |
| "ct": [29, 0, 14, 1, 6, 19, 3, 17, 11, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 274, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [26, 6, 7, 4, 25, 9, 29, 18, 2, 30], | |
| "ct": [1, 0, 13, 23, 8, 18, 8, 4, 8, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 275, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [19, 21, 6, 5, 6, 25, 25, 0, 8, 15], | |
| "ct": [21, 19, 13, 0, 19, 11, 29, 0, 5, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 276, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [9, 18, 21, 22, 22, 14, 23, 5, 5, 14], | |
| "ct": [17, 27, 31, 30, 22, 3, 10, 0, 9, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 277, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [9, 11, 21, 20, 29, 28, 15, 11, 0, 9], | |
| "ct": [29, 8, 20, 9, 13, 10, 25, 31, 25, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 278, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [17, 14, 1, 16, 23, 20, 12, 27, 1, 24], | |
| "ct": [13, 28, 25, 10, 13, 11, 19, 7, 15, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 279, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [28, 9, 4, 11, 3, 27, 29, 16, 24, 22], | |
| "ct": [9, 20, 19, 15, 20, 3, 18, 30, 26, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 280, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [4, 0, 21, 9, 19, 26, 14, 21, 3, 29], | |
| "ct": [11, 4, 16, 2, 19, 14, 8, 14, 0, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 281, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [15, 22, 13, 8, 14, 12, 17, 0, 5, 28], | |
| "ct": [17, 1, 20, 15, 22, 23, 14, 9, 7, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 282, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [5, 10, 22, 4, 9, 2, 5, 23, 5, 10], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 283, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [17, 21, 6, 11, 24, 23, 20, 0, 15, 8], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 284, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [6, 25, 20, 19, 25, 15, 12, 13, 17, 25], | |
| "ct": [16, 0, 0, 0, 0, 16, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 285, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "3e7ffa3f410e329464ad1d205799b3d5", | |
| "tweak": "0d5a58b58855ef5a", | |
| "msg": [0, 31, 24, 8, 17, 13, 20, 26, 18, 4], | |
| "ct": [15, 31, 31, 31, 31, 15, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 286, | |
| "comment": "y = 0 and (y + a) % radix**5 == 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "560186b4313b1b65091222", | |
| "msg": [6, 3, 28, 18, 6, 5, 15, 6, 7, 25], | |
| "ct": [10, 27, 9, 13, 16, 14, 25, 22, 0, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 287, | |
| "comment": "y = 0 and a = 1 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "560186b4313b1b65091222", | |
| "msg": [0, 4, 19, 9, 5, 17, 29, 11, 0, 28], | |
| "ct": [5, 30, 6, 16, 25, 14, 22, 15, 19, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 288, | |
| "comment": "y = 0 and a has large Hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "560186b4313b1b65091222", | |
| "msg": [14, 13, 14, 3, 6, 24, 13, 20, 11, 22], | |
| "ct": [31, 7, 4, 3, 2, 17, 8, 8, 16, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 289, | |
| "comment": "y = 0 and (y + a) % radix**5 is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "560186b4313b1b65091222", | |
| "msg": [20, 7, 19, 15, 18, 0, 20, 25, 13, 5], | |
| "ct": [28, 2, 9, 4, 0, 20, 23, 12, 21, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 290, | |
| "comment": "y = 1 and a = 0 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "334756c8f669e463b94e34", | |
| "msg": [28, 14, 24, 14, 5, 26, 9, 16, 5, 14], | |
| "ct": [0, 2, 29, 9, 20, 14, 20, 30, 11, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 291, | |
| "comment": "y = 1 and a = 1 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "334756c8f669e463b94e34", | |
| "msg": [26, 1, 12, 8, 8, 29, 2, 14, 28, 5], | |
| "ct": [19, 23, 10, 23, 4, 3, 1, 23, 16, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 292, | |
| "comment": "y = 1 and a has large Hamming weight in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "334756c8f669e463b94e34", | |
| "msg": [2, 23, 0, 3, 18, 4, 2, 27, 20, 25], | |
| "ct": [0, 21, 18, 17, 13, 6, 25, 9, 7, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 293, | |
| "comment": "y = 1 and (y + a) % radix**5 is maximal in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "334756c8f669e463b94e34", | |
| "msg": [25, 1, 26, 31, 10, 2, 28, 10, 27, 29], | |
| "ct": [7, 6, 23, 10, 31, 8, 1, 29, 17, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 294, | |
| "comment": "y = 1 and (y + a) % radix**5 == 0 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "334756c8f669e463b94e34", | |
| "msg": [20, 16, 11, 25, 5, 22, 20, 17, 18, 18], | |
| "ct": [7, 13, 13, 3, 6, 9, 3, 27, 7, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 295, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "3cfe7483845b5e5723f5b5", | |
| "msg": [25, 30, 2, 21, 21, 0, 0, 0, 0, 0], | |
| "ct": [6, 22, 12, 5, 5, 18, 28, 22, 2, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 296, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "3cfe7483845b5e5723f5b5", | |
| "msg": [5, 15, 8, 10, 4, 0, 0, 0, 0, 1], | |
| "ct": [16, 23, 29, 9, 24, 9, 11, 9, 22, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 297, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**5 is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "3cfe7483845b5e5723f5b5", | |
| "msg": [5, 13, 13, 29, 28, 0, 0, 0, 0, 31], | |
| "ct": [18, 9, 10, 15, 0, 22, 28, 3, 13, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 298, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**5 == 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "3cfe7483845b5e5723f5b5", | |
| "msg": [19, 16, 14, 14, 18, 0, 0, 0, 1, 0], | |
| "ct": [11, 1, 15, 1, 19, 17, 2, 2, 28, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 299, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "3cfe7483845b5e5723f5b5", | |
| "msg": [24, 29, 0, 23, 30, 16, 0, 0, 0, 0], | |
| "ct": [20, 4, 8, 28, 21, 9, 20, 3, 24, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 300, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "7b64450714b0a262376044de6e260f0a", | |
| "tweak": "3cfe7483845b5e5723f5b5", | |
| "msg": [31, 18, 11, 0, 16, 31, 31, 31, 31, 31], | |
| "ct": [16, 20, 2, 16, 10, 9, 24, 24, 18, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 301, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "c2153daac19904cf16ea81dbc73a58dc", | |
| "tweak": "38b7196a238d3892", | |
| "msg": [-1, 26, 9, 9, 15, 17, 23, 19, 23, 0], | |
| "ct": [0, 16, 1, 12, 6, 22, 27, 23, 4, 5], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 302, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "c2153daac19904cf16ea81dbc73a58dc", | |
| "tweak": "38b7196a238d3892", | |
| "msg": [27, 26, 9, -1, 15, 17, 23, 19, 23, 0], | |
| "ct": [14, 27, 2, 4, 3, 12, 16, 14, 16, 16], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 303, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "c2153daac19904cf16ea81dbc73a58dc", | |
| "tweak": "38b7196a238d3892", | |
| "msg": [27, 26, 9, 9, 15, 17, 23, 19, 23, -1], | |
| "ct": [5, 0, 5, 2, 16, 23, 19, 13, 17, 3], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 304, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "66e79940e040e0c89ff962426f4f3384", | |
| "tweak": "102f66ecf2e54fe1", | |
| "msg": [32, 26, 0, 16, 23, 20, 6, 13, 12, 0], | |
| "ct": [23, 15, 27, 26, 13, 22, 16, 10, 23, 13], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 305, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "66e79940e040e0c89ff962426f4f3384", | |
| "tweak": "102f66ecf2e54fe1", | |
| "msg": [13, 26, 0, 32, 23, 20, 6, 13, 12, 0], | |
| "ct": [14, 9, 17, 31, 12, 27, 29, 23, 12, 27], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 306, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "66e79940e040e0c89ff962426f4f3384", | |
| "tweak": "102f66ecf2e54fe1", | |
| "msg": [13, 26, 0, 16, 23, 20, 6, 13, 12, 32], | |
| "ct": [29, 18, 31, 13, 9, 1, 5, 9, 16, 4], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 11, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 307, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "63396f38c44f0c2d97468c4804b5d022", | |
| "tweak": "73068af95fd924fc", | |
| "msg": [2, 11, 26, 27, 31, 7, 24, 10, 30, 25, 6], | |
| "ct": [1, 9, 13, 21, 7, 22, 26, 10, 23, 23, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 308, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [11, 21, 0, 19, 3, 19, 2, 11, 30, 8, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 309, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [14, 7, 16, 23, 0, 31, 5, 19, 16, 1, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 310, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [16, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0], | |
| "ct": [14, 9, 22, 6, 30, 18, 10, 8, 25, 7, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 311, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [15, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31], | |
| "ct": [1, 25, 13, 28, 9, 27, 14, 16, 2, 12, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 312, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [7, 20, 16, 3, 2, 25, 31, 29, 10, 7, 29], | |
| "ct": [23, 5, 19, 13, 7, 1, 26, 31, 20, 16, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 313, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [12, 15, 21, 6, 23, 8, 10, 25, 24, 30, 15], | |
| "ct": [22, 27, 28, 9, 6, 0, 26, 31, 11, 20, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 314, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [24, 18, 8, 16, 11, 16, 18, 28, 25, 14, 17], | |
| "ct": [25, 19, 21, 8, 15, 16, 30, 7, 0, 7, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 315, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [1, 27, 29, 6, 27, 29, 2, 20, 12, 31, 23], | |
| "ct": [8, 26, 16, 6, 28, 28, 8, 20, 13, 19, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 316, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [28, 19, 9, 9, 30, 6, 19, 17, 30, 29, 11], | |
| "ct": [5, 24, 4, 10, 0, 4, 10, 24, 16, 25, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 317, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [2, 18, 17, 1, 24, 21, 22, 15, 31, 24, 6], | |
| "ct": [10, 20, 23, 6, 10, 31, 30, 11, 29, 16, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 318, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [15, 4, 9, 27, 1, 12, 11, 18, 17, 31, 4], | |
| "ct": [17, 9, 5, 25, 26, 18, 0, 27, 12, 19, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 319, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [24, 0, 22, 20, 0, 31, 31, 8, 27, 28, 16], | |
| "ct": [16, 20, 18, 17, 2, 6, 21, 2, 31, 1, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 320, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [26, 25, 28, 0, 6, 25, 19, 7, 29, 8, 14], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 321, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [6, 4, 25, 28, 9, 12, 26, 13, 15, 29, 3], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 322, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [7, 10, 31, 7, 17, 1, 15, 25, 12, 19, 21], | |
| "ct": [16, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 323, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd69e5d5444781e0645ba24b2a32dee8", | |
| "tweak": "e1310d099e8e72c6", | |
| "msg": [22, 9, 1, 7, 16, 10, 4, 24, 14, 17, 17], | |
| "ct": [15, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 324, | |
| "comment": "y = 0 and (y + a) % radix**5 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "fc5aa304ade619d11a392d", | |
| "msg": [13, 10, 8, 10, 6, 13, 19, 28, 3, 21, 21], | |
| "ct": [29, 31, 16, 21, 18, 31, 8, 20, 28, 11, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 325, | |
| "comment": "y = 0 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "fc5aa304ade619d11a392d", | |
| "msg": [23, 1, 31, 2, 9, 19, 26, 3, 31, 19, 8], | |
| "ct": [14, 6, 24, 8, 15, 16, 23, 21, 20, 5, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 326, | |
| "comment": "y = 0 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "fc5aa304ade619d11a392d", | |
| "msg": [19, 23, 24, 9, 7, 18, 7, 7, 15, 29, 22], | |
| "ct": [10, 13, 28, 7, 5, 24, 11, 6, 14, 18, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 327, | |
| "comment": "y = 0 and (y + a) % radix**5 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "fc5aa304ade619d11a392d", | |
| "msg": [16, 25, 24, 29, 11, 27, 10, 17, 29, 5, 29], | |
| "ct": [23, 0, 13, 7, 30, 25, 21, 18, 1, 29, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 328, | |
| "comment": "y = 1 and a = 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "25749a787e1a65363026d9", | |
| "msg": [29, 15, 3, 4, 9, 1, 16, 7, 3, 21, 0], | |
| "ct": [16, 2, 30, 26, 10, 23, 2, 15, 28, 24, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 329, | |
| "comment": "y = 1 and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "25749a787e1a65363026d9", | |
| "msg": [26, 10, 16, 31, 20, 6, 9, 8, 30, 18, 21], | |
| "ct": [19, 20, 5, 20, 29, 16, 1, 17, 12, 29, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 330, | |
| "comment": "y = 1 and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "25749a787e1a65363026d9", | |
| "msg": [17, 30, 27, 17, 6, 17, 16, 16, 30, 10, 13], | |
| "ct": [14, 5, 11, 12, 8, 29, 1, 3, 3, 2, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 331, | |
| "comment": "y = 1 and (y + a) % radix**5 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "25749a787e1a65363026d9", | |
| "msg": [1, 15, 12, 3, 15, 14, 6, 1, 28, 27, 31], | |
| "ct": [3, 5, 14, 0, 2, 17, 11, 26, 12, 23, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 332, | |
| "comment": "y = 1 and (y + a) % radix**5 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "25749a787e1a65363026d9", | |
| "msg": [10, 6, 9, 8, 17, 13, 29, 3, 19, 26, 2], | |
| "ct": [31, 3, 0, 2, 14, 0, 18, 17, 15, 21, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 333, | |
| "comment": "y is maximal and (y + a) % radix**5 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1bc8a76d45a2b3a163b538", | |
| "msg": [13, 7, 19, 14, 15, 3, 31, 5, 3, 29, 12], | |
| "ct": [31, 31, 31, 31, 31, 3, 0, 27, 16, 16, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 334, | |
| "comment": "y is maximal and (y + a) % radix**5 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1bc8a76d45a2b3a163b538", | |
| "msg": [4, 0, 27, 5, 20, 15, 1, 2, 7, 24, 18], | |
| "ct": [0, 0, 0, 0, 0, 16, 18, 28, 27, 28, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 335, | |
| "comment": "y is maximal and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1bc8a76d45a2b3a163b538", | |
| "msg": [7, 22, 22, 23, 9, 6, 14, 28, 29, 12, 1], | |
| "ct": [15, 31, 31, 31, 31, 20, 30, 4, 28, 4, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 336, | |
| "comment": "y is maximal and a is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1bc8a76d45a2b3a163b538", | |
| "msg": [8, 4, 3, 30, 25, 28, 21, 9, 1, 14, 3], | |
| "ct": [31, 31, 31, 31, 30, 6, 13, 8, 15, 24, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 337, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1674fba02ac8f95c8ccc98", | |
| "msg": [24, 20, 27, 22, 2, 17, 29, 29, 6, 25, 22], | |
| "ct": [0, 13, 2, 20, 21, 3, 0, 22, 19, 5, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 338, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1674fba02ac8f95c8ccc98", | |
| "msg": [31, 30, 20, 23, 21, 3, 19, 10, 14, 2, 31], | |
| "ct": [16, 21, 10, 18, 21, 29, 13, 17, 17, 29, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 339, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**5 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1674fba02ac8f95c8ccc98", | |
| "msg": [22, 14, 23, 24, 4, 0, 27, 1, 27, 13, 2], | |
| "ct": [10, 20, 4, 10, 13, 18, 30, 14, 12, 21, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 340, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**5 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1674fba02ac8f95c8ccc98", | |
| "msg": [17, 5, 7, 9, 16, 11, 23, 19, 12, 12, 3], | |
| "ct": [22, 15, 9, 7, 5, 7, 11, 14, 14, 18, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 341, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1674fba02ac8f95c8ccc98", | |
| "msg": [24, 24, 25, 9, 19, 31, 28, 29, 10, 17, 12], | |
| "ct": [0, 30, 25, 28, 13, 23, 28, 5, 24, 6, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 342, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "1674fba02ac8f95c8ccc98", | |
| "msg": [14, 31, 12, 10, 23, 11, 4, 27, 5, 0, 20], | |
| "ct": [31, 30, 23, 26, 13, 8, 3, 5, 1, 10, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 343, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**5 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "2ddaf6b2fa94a4dc739e0d", | |
| "msg": [21, 7, 1, 30, 31, 6, 17, 12, 18, 8, 19], | |
| "ct": [18, 2, 28, 24, 9, 26, 25, 25, 22, 9, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 344, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**5 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "2ddaf6b2fa94a4dc739e0d", | |
| "msg": [29, 29, 25, 17, 30, 16, 29, 21, 31, 27, 1], | |
| "ct": [0, 31, 13, 4, 23, 3, 25, 18, 15, 13, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 345, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "2ddaf6b2fa94a4dc739e0d", | |
| "msg": [20, 17, 3, 16, 26, 22, 17, 26, 1, 9, 23], | |
| "ct": [12, 11, 25, 13, 14, 11, 5, 10, 27, 19, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 346, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "6c6ec910e1fcdff2f0df935de10d0560", | |
| "tweak": "2ddaf6b2fa94a4dc739e0d", | |
| "msg": [16, 7, 11, 6, 11, 3, 2, 5, 5, 26, 2], | |
| "ct": [30, 17, 16, 7, 17, 5, 24, 9, 17, 13, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 347, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "0b55b77a1d06778b795b541037eabb26", | |
| "tweak": "3e26f18ba99add01", | |
| "msg": [-1, 10, 24, 9, 0, 14, 1, 20, 5, 12, 11], | |
| "ct": [25, 2, 26, 16, 7, 26, 9, 12, 12, 4, 16], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 348, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "0b55b77a1d06778b795b541037eabb26", | |
| "tweak": "3e26f18ba99add01", | |
| "msg": [30, 10, 24, -1, 0, 14, 1, 20, 5, 12, 11], | |
| "ct": [20, 13, 2, 24, 19, 25, 18, 3, 21, 3, 5], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 349, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "0b55b77a1d06778b795b541037eabb26", | |
| "tweak": "3e26f18ba99add01", | |
| "msg": [30, 10, 24, 9, 0, 14, 1, 20, 5, 12, -1], | |
| "ct": [13, 28, 30, 4, 5, 31, 11, 14, 28, 2, 31], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 350, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "2faf4481c971440341b268fcf125b655", | |
| "tweak": "795eb0a22eb3f831", | |
| "msg": [32, 24, 24, 14, 31, 11, 5, 15, 1, 18, 31], | |
| "ct": [15, 28, 17, 31, 5, 29, 11, 29, 3, 9, 25], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 351, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "2faf4481c971440341b268fcf125b655", | |
| "tweak": "795eb0a22eb3f831", | |
| "msg": [25, 24, 24, 32, 31, 11, 5, 15, 1, 18, 31], | |
| "ct": [2, 17, 9, 29, 31, 11, 23, 11, 14, 3, 22], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 352, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "2faf4481c971440341b268fcf125b655", | |
| "tweak": "795eb0a22eb3f831", | |
| "msg": [25, 24, 24, 14, 31, 11, 5, 15, 1, 18, 32], | |
| "ct": [21, 11, 0, 3, 25, 25, 21, 24, 26, 21, 4], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 12, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 353, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "ddc31fc7751a2bf5c8d2d815035622e8", | |
| "tweak": "0e10628c19795c4e", | |
| "msg": [19, 5, 23, 25, 11, 13, 30, 6, 15, 7, 24, 31], | |
| "ct": [11, 11, 9, 3, 3, 11, 17, 10, 6, 12, 13, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 354, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [26, 16, 10, 12, 0, 3, 17, 30, 25, 7, 22, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 355, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [28, 15, 2, 18, 25, 21, 19, 5, 19, 4, 14, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 356, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [16, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0], | |
| "ct": [7, 27, 17, 4, 14, 14, 4, 1, 20, 2, 10, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 357, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [15, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31], | |
| "ct": [1, 8, 21, 11, 3, 14, 1, 31, 30, 3, 28, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 358, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [7, 27, 5, 2, 4, 1, 12, 26, 20, 23, 26, 5], | |
| "ct": [23, 24, 31, 9, 11, 17, 19, 14, 19, 14, 24, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 359, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [19, 17, 9, 15, 10, 26, 15, 19, 27, 18, 21, 24], | |
| "ct": [29, 29, 9, 13, 2, 31, 1, 10, 18, 4, 8, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 360, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [4, 0, 1, 11, 11, 28, 20, 24, 12, 28, 23, 29], | |
| "ct": [20, 0, 16, 14, 30, 22, 30, 16, 31, 25, 19, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 361, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [21, 15, 18, 0, 16, 3, 7, 22, 29, 18, 3, 16], | |
| "ct": [12, 27, 11, 17, 6, 13, 27, 14, 17, 28, 5, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 362, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [8, 26, 18, 13, 9, 29, 22, 26, 10, 5, 20, 21], | |
| "ct": [3, 19, 25, 14, 8, 23, 7, 4, 13, 29, 25, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 363, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [10, 11, 1, 29, 21, 4, 28, 5, 1, 24, 29, 9], | |
| "ct": [22, 1, 26, 1, 5, 9, 3, 12, 0, 23, 21, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 364, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [28, 11, 14, 10, 4, 5, 15, 27, 15, 19, 16, 28], | |
| "ct": [8, 18, 23, 12, 22, 8, 22, 9, 15, 13, 26, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 365, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [30, 17, 15, 18, 30, 2, 29, 16, 8, 30, 3, 13], | |
| "ct": [2, 23, 0, 12, 1, 23, 30, 5, 5, 26, 4, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 366, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [28, 7, 1, 22, 1, 10, 7, 1, 3, 29, 26, 25], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 367, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [22, 7, 0, 12, 31, 6, 24, 23, 24, 13, 22, 27], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 368, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [2, 24, 14, 10, 24, 26, 12, 28, 29, 27, 31, 4], | |
| "ct": [16, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 369, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "d954ee3f3fabdcd92a2ad30b675ef74d", | |
| "tweak": "bb3a5b86df3e19bc", | |
| "msg": [28, 25, 7, 13, 17, 11, 27, 23, 17, 13, 13, 12], | |
| "ct": [15, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 370, | |
| "comment": "y = 0 and (y + a) % radix**6 == 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "5817c2cca0c58699db24ed", | |
| "msg": [2, 5, 2, 10, 7, 24, 22, 15, 15, 16, 3, 27], | |
| "ct": [5, 25, 3, 19, 4, 9, 24, 26, 13, 3, 13, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 371, | |
| "comment": "y = 0 and a = 1 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "5817c2cca0c58699db24ed", | |
| "msg": [18, 15, 11, 15, 16, 12, 5, 12, 26, 20, 8, 2], | |
| "ct": [23, 28, 18, 14, 17, 15, 21, 25, 8, 21, 11, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 372, | |
| "comment": "y = 0 and a has large Hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "5817c2cca0c58699db24ed", | |
| "msg": [14, 26, 31, 2, 10, 21, 18, 13, 30, 29, 3, 15], | |
| "ct": [20, 14, 26, 28, 21, 23, 30, 30, 27, 6, 30, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 373, | |
| "comment": "y = 0 and (y + a) % radix**6 is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "5817c2cca0c58699db24ed", | |
| "msg": [26, 7, 5, 2, 20, 20, 5, 1, 5, 18, 8, 15], | |
| "ct": [6, 0, 13, 10, 8, 13, 16, 19, 27, 25, 7, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 374, | |
| "comment": "y = 1 and a = 0 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "3046d34434c6e634dc3f65", | |
| "msg": [28, 28, 28, 30, 16, 8, 27, 9, 20, 16, 12, 18], | |
| "ct": [8, 0, 24, 7, 29, 31, 13, 17, 14, 4, 7, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 375, | |
| "comment": "y = 1 and a = 1 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "3046d34434c6e634dc3f65", | |
| "msg": [27, 0, 9, 16, 13, 28, 5, 6, 0, 31, 12, 2], | |
| "ct": [12, 23, 26, 19, 10, 27, 23, 5, 31, 22, 28, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 376, | |
| "comment": "y = 1 and a has large Hamming weight in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "3046d34434c6e634dc3f65", | |
| "msg": [22, 13, 7, 6, 24, 18, 8, 13, 23, 12, 2, 28], | |
| "ct": [22, 15, 1, 0, 31, 6, 24, 12, 1, 9, 20, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 377, | |
| "comment": "y = 1 and (y + a) % radix**6 is maximal in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "3046d34434c6e634dc3f65", | |
| "msg": [19, 26, 26, 7, 2, 15, 20, 10, 15, 23, 2, 5], | |
| "ct": [10, 8, 25, 18, 18, 7, 22, 14, 26, 22, 23, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 378, | |
| "comment": "y = 1 and (y + a) % radix**6 == 0 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "3046d34434c6e634dc3f65", | |
| "msg": [3, 19, 26, 1, 4, 11, 16, 0, 11, 21, 12, 28], | |
| "ct": [10, 17, 13, 25, 9, 20, 3, 19, 5, 23, 1, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 379, | |
| "comment": "y is maximal and (y + a) % radix**6 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5f3789ede8a0e6b11f35e", | |
| "msg": [20, 7, 1, 29, 12, 0, 25, 28, 29, 20, 31, 11], | |
| "ct": [31, 31, 31, 31, 31, 31, 10, 23, 26, 18, 31, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 380, | |
| "comment": "y is maximal and (y + a) % radix**6 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5f3789ede8a0e6b11f35e", | |
| "msg": [25, 30, 2, 19, 1, 28, 26, 5, 1, 24, 12, 0], | |
| "ct": [0, 0, 0, 0, 0, 0, 1, 10, 10, 8, 17, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 381, | |
| "comment": "y is maximal and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5f3789ede8a0e6b11f35e", | |
| "msg": [5, 6, 9, 4, 29, 8, 27, 24, 22, 20, 31, 29], | |
| "ct": [15, 31, 31, 31, 31, 31, 5, 1, 13, 30, 19, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 382, | |
| "comment": "y is maximal and a is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5f3789ede8a0e6b11f35e", | |
| "msg": [15, 29, 9, 11, 7, 0, 12, 13, 9, 3, 24, 22], | |
| "ct": [31, 31, 31, 31, 31, 30, 7, 6, 4, 27, 20, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 383, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5c850f3935f25bc7c6e96", | |
| "msg": [6, 21, 15, 9, 31, 10, 19, 13, 19, 24, 19, 25], | |
| "ct": [13, 10, 31, 23, 0, 31, 20, 26, 17, 7, 2, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 384, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5c850f3935f25bc7c6e96", | |
| "msg": [5, 2, 12, 22, 29, 5, 22, 13, 10, 15, 3, 17], | |
| "ct": [31, 11, 2, 19, 5, 0, 2, 28, 6, 30, 6, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 385, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**6 is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5c850f3935f25bc7c6e96", | |
| "msg": [17, 16, 21, 22, 22, 23, 10, 14, 4, 23, 9, 3], | |
| "ct": [31, 4, 0, 15, 31, 8, 4, 19, 20, 15, 0, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 386, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**6 == 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5c850f3935f25bc7c6e96", | |
| "msg": [8, 30, 14, 30, 11, 30, 30, 1, 9, 3, 11, 19], | |
| "ct": [24, 24, 19, 23, 9, 18, 29, 9, 25, 19, 7, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 387, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5c850f3935f25bc7c6e96", | |
| "msg": [9, 12, 0, 21, 0, 7, 26, 5, 13, 17, 30, 27], | |
| "ct": [3, 6, 19, 13, 10, 27, 8, 18, 12, 24, 0, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 388, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "a5c850f3935f25bc7c6e96", | |
| "msg": [31, 23, 1, 12, 4, 14, 3, 3, 0, 14, 16, 22], | |
| "ct": [21, 8, 21, 25, 20, 10, 3, 1, 15, 17, 14, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 389, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**6 is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "b32438f381f9cbb2da4368", | |
| "msg": [14, 19, 25, 12, 7, 29, 0, 0, 0, 0, 0, 0], | |
| "ct": [15, 24, 27, 17, 7, 30, 3, 5, 24, 26, 23, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 390, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**6 == 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "b32438f381f9cbb2da4368", | |
| "msg": [2, 16, 16, 4, 0, 18, 0, 0, 0, 0, 0, 1], | |
| "ct": [14, 7, 27, 21, 14, 29, 10, 25, 20, 21, 3, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 391, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "b32438f381f9cbb2da4368", | |
| "msg": [16, 11, 14, 15, 1, 24, 16, 0, 0, 0, 0, 0], | |
| "ct": [27, 15, 12, 31, 17, 17, 27, 17, 9, 31, 22, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 392, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "a3e590e923e5c47a216ec271e9da8180", | |
| "tweak": "b32438f381f9cbb2da4368", | |
| "msg": [21, 3, 27, 26, 10, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [26, 23, 1, 23, 25, 2, 14, 0, 12, 31, 5, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 393, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "dbac185fba36fe7028184de1a577dbaa", | |
| "tweak": "6ba28735b4acc0ff", | |
| "msg": [-1, 4, 5, 12, 5, 5, 22, 31, 22, 9, 5, 27], | |
| "ct": [30, 24, 22, 12, 13, 30, 10, 31, 0, 4, 5, 25], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 394, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "dbac185fba36fe7028184de1a577dbaa", | |
| "tweak": "6ba28735b4acc0ff", | |
| "msg": [10, 4, 5, 12, -1, 5, 22, 31, 22, 9, 5, 27], | |
| "ct": [16, 27, 29, 11, 18, 26, 21, 20, 15, 4, 11, 7], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 395, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "dbac185fba36fe7028184de1a577dbaa", | |
| "tweak": "6ba28735b4acc0ff", | |
| "msg": [10, 4, 5, 12, 5, 5, 22, 31, 22, 9, 5, -1], | |
| "ct": [22, 1, 19, 17, 7, 5, 21, 28, 14, 27, 3, 4], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 396, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "045cfbfbaff9061ab8e489912a3b0a7f", | |
| "tweak": "60d28fa4e9a8d81b", | |
| "msg": [32, 17, 21, 24, 15, 4, 25, 15, 31, 27, 23, 9], | |
| "ct": [8, 23, 0, 10, 6, 28, 13, 25, 20, 13, 20, 18], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 397, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "045cfbfbaff9061ab8e489912a3b0a7f", | |
| "tweak": "60d28fa4e9a8d81b", | |
| "msg": [21, 17, 21, 24, 32, 4, 25, 15, 31, 27, 23, 9], | |
| "ct": [28, 25, 9, 17, 5, 6, 12, 28, 0, 8, 17, 5], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 398, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "045cfbfbaff9061ab8e489912a3b0a7f", | |
| "tweak": "60d28fa4e9a8d81b", | |
| "msg": [21, 17, 21, 24, 15, 4, 25, 15, 31, 27, 23, 32], | |
| "ct": [27, 12, 11, 12, 2, 29, 1, 21, 6, 17, 28, 2], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 13, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 399, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "d5e6c882f005525ce577f704ef6b525d", | |
| "tweak": "7ce1a7a4e6508c83", | |
| "msg": [21, 12, 13, 1, 13, 20, 31, 10, 18, 10, 31, 24, 21], | |
| "ct": [20, 25, 10, 19, 6, 16, 11, 14, 8, 24, 27, 9, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 400, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [27, 23, 7, 15, 15, 25, 14, 27, 3, 27, 1, 4, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 401, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [26, 21, 19, 13, 1, 19, 23, 0, 24, 20, 31, 0, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 402, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [16, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0], | |
| "ct": [19, 19, 2, 0, 27, 6, 17, 4, 29, 11, 26, 15, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 403, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [15, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31], | |
| "ct": [0, 21, 29, 29, 23, 7, 16, 12, 0, 9, 23, 3, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 404, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [16, 25, 10, 18, 30, 21, 19, 31, 21, 3, 24, 6, 28], | |
| "ct": [10, 26, 20, 16, 30, 13, 1, 14, 2, 4, 31, 30, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 405, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [0, 22, 30, 19, 25, 11, 4, 15, 9, 22, 9, 20, 2], | |
| "ct": [26, 28, 23, 7, 29, 0, 21, 21, 21, 16, 30, 11, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 406, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [7, 22, 18, 29, 26, 29, 21, 25, 19, 26, 8, 0, 14], | |
| "ct": [17, 19, 16, 12, 27, 31, 29, 9, 22, 24, 22, 11, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 407, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [17, 12, 27, 27, 28, 21, 10, 26, 28, 2, 1, 15, 18], | |
| "ct": [0, 25, 4, 28, 15, 28, 17, 2, 21, 12, 12, 2, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 408, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [22, 25, 14, 28, 31, 16, 6, 16, 26, 12, 15, 14, 30], | |
| "ct": [27, 2, 1, 23, 18, 12, 18, 0, 17, 20, 4, 30, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 409, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [10, 8, 23, 3, 19, 27, 4, 30, 28, 20, 28, 1, 24], | |
| "ct": [28, 20, 5, 8, 29, 5, 4, 21, 11, 25, 22, 23, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 410, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [29, 10, 16, 10, 2, 19, 16, 26, 16, 11, 30, 16, 23], | |
| "ct": [3, 22, 3, 12, 4, 4, 6, 1, 16, 12, 0, 14, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 411, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [1, 12, 21, 16, 21, 29, 9, 6, 11, 11, 16, 0, 2], | |
| "ct": [30, 26, 19, 16, 14, 29, 26, 13, 8, 0, 8, 6, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 412, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [15, 8, 6, 5, 4, 14, 5, 20, 26, 24, 21, 23, 4], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 413, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [6, 17, 24, 7, 12, 15, 14, 24, 5, 16, 7, 21, 16], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 414, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [2, 5, 14, 9, 20, 8, 14, 7, 2, 22, 16, 9, 11], | |
| "ct": [16, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 415, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bb7ca258d353deb4a4f52b08290ab6a1", | |
| "tweak": "a211ccbb8d59238e", | |
| "msg": [8, 22, 3, 22, 9, 31, 22, 16, 20, 18, 25, 24, 18], | |
| "ct": [15, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 416, | |
| "comment": "y = 0 and (y + a) % radix**6 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "f2edaaee51f576c86c5e", | |
| "msg": [2, 8, 9, 2, 20, 11, 24, 3, 7, 30, 31, 21, 30], | |
| "ct": [9, 8, 10, 21, 15, 4, 7, 13, 21, 15, 29, 6, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 417, | |
| "comment": "y = 0 and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "f2edaaee51f576c86c5e", | |
| "msg": [2, 14, 2, 5, 22, 15, 29, 31, 11, 21, 28, 2, 18], | |
| "ct": [22, 9, 6, 31, 23, 10, 3, 19, 18, 10, 24, 20, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 418, | |
| "comment": "y = 0 and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "f2edaaee51f576c86c5e", | |
| "msg": [14, 4, 28, 20, 21, 5, 0, 16, 6, 5, 24, 8, 11], | |
| "ct": [1, 27, 22, 20, 19, 28, 17, 5, 0, 21, 1, 25, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 419, | |
| "comment": "y = 0 and (y + a) % radix**6 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "f2edaaee51f576c86c5e", | |
| "msg": [0, 25, 21, 12, 0, 15, 26, 30, 10, 12, 3, 30, 23], | |
| "ct": [23, 0, 27, 10, 14, 14, 14, 20, 19, 29, 7, 11, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 420, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "2f7d941e1651dbca7b13", | |
| "msg": [13, 30, 4, 0, 2, 2, 13, 13, 23, 10, 15, 14, 17], | |
| "ct": [28, 2, 10, 24, 25, 9, 21, 13, 6, 30, 31, 9, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 421, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "2f7d941e1651dbca7b13", | |
| "msg": [12, 10, 9, 16, 29, 0, 18, 21, 12, 30, 21, 10, 3], | |
| "ct": [15, 6, 19, 4, 15, 1, 5, 19, 15, 4, 22, 3, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 422, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**6 is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "2f7d941e1651dbca7b13", | |
| "msg": [4, 9, 31, 27, 16, 28, 7, 23, 9, 6, 21, 4, 4], | |
| "ct": [31, 2, 26, 11, 27, 8, 0, 13, 19, 12, 28, 23, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 423, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**6 == 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "2f7d941e1651dbca7b13", | |
| "msg": [22, 10, 11, 4, 22, 25, 30, 4, 17, 30, 28, 4, 26], | |
| "ct": [12, 0, 27, 6, 21, 8, 29, 7, 12, 5, 16, 17, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 424, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "2f7d941e1651dbca7b13", | |
| "msg": [6, 17, 5, 15, 21, 31, 2, 4, 29, 9, 16, 8, 3], | |
| "ct": [3, 0, 26, 30, 12, 30, 29, 20, 30, 10, 11, 17, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 425, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "2f7d941e1651dbca7b13", | |
| "msg": [11, 5, 16, 4, 8, 2, 16, 28, 19, 0, 8, 12, 13], | |
| "ct": [28, 27, 10, 19, 16, 17, 2, 21, 31, 9, 15, 17, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 426, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**6 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "58fca2e1083a79ebc5c6", | |
| "msg": [0, 22, 28, 14, 18, 18, 16, 14, 26, 20, 23, 20, 4], | |
| "ct": [20, 18, 16, 1, 14, 2, 19, 31, 0, 4, 17, 5, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 427, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**6 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "58fca2e1083a79ebc5c6", | |
| "msg": [11, 17, 11, 25, 25, 31, 13, 5, 19, 11, 30, 6, 6], | |
| "ct": [11, 23, 8, 12, 25, 29, 10, 12, 23, 6, 5, 11, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 428, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "58fca2e1083a79ebc5c6", | |
| "msg": [13, 29, 7, 13, 11, 21, 6, 18, 4, 0, 12, 23, 14], | |
| "ct": [29, 8, 27, 0, 13, 8, 21, 1, 23, 10, 20, 3, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 429, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "002d4f865568a9c32a7edeb2b39d73d7", | |
| "tweak": "58fca2e1083a79ebc5c6", | |
| "msg": [21, 0, 30, 21, 2, 18, 30, 13, 4, 2, 15, 10, 29], | |
| "ct": [15, 20, 10, 29, 2, 14, 23, 1, 20, 20, 2, 3, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 430, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b8d9b3c80209587bbe3c0f7125eed049", | |
| "tweak": "522499e28e9e7712", | |
| "msg": [-1, 6, 25, 14, 3, 22, 15, 27, 10, 18, 26, 27, 5], | |
| "ct": [2, 21, 15, 5, 0, 4, 14, 16, 25, 1, 26, 29, 13], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 431, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b8d9b3c80209587bbe3c0f7125eed049", | |
| "tweak": "522499e28e9e7712", | |
| "msg": [19, 6, 25, 14, -1, 22, 15, 27, 10, 18, 26, 27, 5], | |
| "ct": [27, 29, 16, 28, 25, 31, 19, 24, 12, 2, 4, 28, 11], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 432, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b8d9b3c80209587bbe3c0f7125eed049", | |
| "tweak": "522499e28e9e7712", | |
| "msg": [19, 6, 25, 14, 3, 22, 15, 27, 10, 18, 26, 27, -1], | |
| "ct": [16, 8, 15, 21, 2, 4, 2, 21, 13, 3, 30, 27, 24], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 433, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "962fe9983b16ebb1ea50118f9dc25117", | |
| "tweak": "7b52369705ddfff1", | |
| "msg": [32, 19, 2, 11, 2, 24, 21, 26, 3, 9, 10, 7, 21], | |
| "ct": [19, 10, 21, 14, 31, 29, 18, 15, 31, 22, 23, 16, 10], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 434, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "962fe9983b16ebb1ea50118f9dc25117", | |
| "tweak": "7b52369705ddfff1", | |
| "msg": [8, 19, 2, 11, 32, 24, 21, 26, 3, 9, 10, 7, 21], | |
| "ct": [13, 24, 19, 29, 16, 8, 11, 8, 2, 27, 12, 30, 22], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 435, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "962fe9983b16ebb1ea50118f9dc25117", | |
| "tweak": "7b52369705ddfff1", | |
| "msg": [8, 19, 2, 11, 2, 24, 21, 26, 3, 9, 10, 7, 32], | |
| "ct": [14, 14, 18, 20, 3, 24, 18, 15, 27, 20, 17, 14, 30], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 14, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 436, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "7a1122636a4417351c97156308d4f6aa", | |
| "tweak": "a9508e64d1ab8e34", | |
| "msg": [6, 6, 3, 17, 11, 14, 8, 24, 12, 27, 25, 10, 6, 12], | |
| "ct": [5, 19, 22, 29, 27, 25, 16, 1, 21, 22, 27, 4, 27, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 437, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [1, 31, 28, 13, 2, 0, 26, 0, 31, 26, 24, 31, 2, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 438, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [1, 24, 12, 24, 19, 7, 14, 30, 16, 2, 14, 5, 24, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 439, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0], | |
| "ct": [28, 12, 1, 4, 30, 25, 24, 31, 10, 15, 26, 29, 16, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 440, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31], | |
| "ct": [12, 17, 0, 24, 4, 16, 24, 9, 23, 8, 21, 26, 11, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 441, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [9, 31, 21, 21, 24, 26, 18, 29, 24, 13, 3, 2, 5, 26], | |
| "ct": [22, 26, 25, 3, 23, 26, 17, 19, 4, 31, 30, 1, 31, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 442, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [31, 26, 8, 1, 6, 14, 28, 12, 4, 9, 9, 31, 13, 23], | |
| "ct": [23, 2, 13, 24, 23, 31, 0, 7, 28, 17, 7, 4, 6, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 443, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [10, 31, 8, 28, 3, 29, 16, 29, 18, 4, 11, 15, 31, 30], | |
| "ct": [31, 7, 19, 15, 13, 17, 18, 0, 14, 5, 0, 27, 24, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 444, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [22, 22, 15, 6, 30, 19, 31, 29, 23, 27, 16, 6, 25, 20], | |
| "ct": [21, 21, 1, 20, 5, 10, 19, 8, 6, 25, 24, 30, 5, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 445, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [21, 14, 16, 5, 21, 8, 22, 17, 28, 0, 17, 13, 5, 1], | |
| "ct": [20, 13, 31, 30, 24, 5, 12, 29, 22, 24, 24, 25, 25, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 446, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [26, 22, 31, 14, 26, 23, 27, 20, 6, 25, 1, 12, 18, 24], | |
| "ct": [24, 1, 16, 0, 0, 19, 9, 27, 5, 17, 15, 6, 1, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 447, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [30, 15, 14, 12, 14, 4, 17, 3, 18, 3, 27, 28, 12, 3], | |
| "ct": [7, 22, 7, 2, 23, 23, 6, 16, 14, 7, 2, 15, 12, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 448, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [0, 26, 15, 26, 11, 15, 24, 25, 2, 6, 7, 25, 0, 29], | |
| "ct": [2, 26, 9, 6, 31, 11, 6, 24, 9, 22, 1, 24, 30, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 449, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [19, 4, 15, 23, 16, 23, 18, 5, 13, 0, 14, 11, 1, 15], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 450, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [2, 30, 20, 29, 3, 22, 1, 14, 5, 14, 2, 9, 4, 28], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 451, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [0, 11, 21, 31, 15, 19, 19, 6, 17, 16, 20, 2, 0, 0], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 452, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "8a9c22148e4fed1fc918f33eba1f06cc", | |
| "tweak": "c37a26d7ade80ea1", | |
| "msg": [25, 28, 18, 17, 2, 12, 5, 18, 9, 16, 0, 7, 26, 9], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 453, | |
| "comment": "y = 1 and a = 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "666f7b01e538fb266e2d", | |
| "msg": [1, 11, 0, 29, 2, 15, 9, 3, 6, 3, 19, 30, 13, 18], | |
| "ct": [29, 26, 17, 10, 12, 7, 16, 20, 26, 4, 11, 21, 8, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 454, | |
| "comment": "y = 1 and a = 1 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "666f7b01e538fb266e2d", | |
| "msg": [21, 11, 23, 25, 1, 25, 20, 25, 31, 12, 14, 6, 29, 31], | |
| "ct": [31, 25, 7, 7, 8, 8, 1, 5, 11, 1, 28, 12, 6, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 455, | |
| "comment": "y = 1 and a has large Hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "666f7b01e538fb266e2d", | |
| "msg": [29, 6, 12, 11, 14, 22, 3, 6, 12, 22, 28, 1, 2, 4], | |
| "ct": [21, 25, 19, 3, 31, 17, 7, 19, 6, 0, 6, 18, 0, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 456, | |
| "comment": "y = 1 and (y + a) % radix**7 is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "666f7b01e538fb266e2d", | |
| "msg": [29, 21, 19, 22, 20, 14, 16, 7, 10, 7, 5, 12, 12, 14], | |
| "ct": [31, 21, 14, 13, 9, 16, 12, 23, 26, 18, 6, 6, 2, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 457, | |
| "comment": "y = 1 and (y + a) % radix**7 == 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "666f7b01e538fb266e2d", | |
| "msg": [16, 20, 28, 3, 8, 23, 17, 12, 17, 18, 23, 9, 2, 5], | |
| "ct": [28, 14, 30, 12, 14, 31, 15, 28, 23, 12, 30, 22, 28, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 458, | |
| "comment": "y is maximal and (y + a) % radix**7 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "d1b37f6d1f88d5e450d5", | |
| "msg": [11, 30, 15, 18, 30, 13, 11, 19, 20, 20, 22, 26, 27, 2], | |
| "ct": [2, 14, 29, 9, 7, 31, 30, 23, 14, 3, 4, 24, 0, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 459, | |
| "comment": "y is maximal and (y + a) % radix**7 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "d1b37f6d1f88d5e450d5", | |
| "msg": [31, 8, 21, 1, 17, 24, 26, 10, 28, 21, 24, 5, 2, 22], | |
| "ct": [20, 24, 5, 4, 4, 20, 20, 2, 30, 9, 27, 20, 4, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 460, | |
| "comment": "y is maximal and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "d1b37f6d1f88d5e450d5", | |
| "msg": [30, 27, 2, 9, 10, 30, 5, 18, 13, 14, 15, 14, 28, 26], | |
| "ct": [18, 23, 7, 12, 13, 24, 17, 16, 26, 18, 4, 31, 6, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 461, | |
| "comment": "y is maximal and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "d1b37f6d1f88d5e450d5", | |
| "msg": [18, 18, 1, 9, 11, 9, 20, 10, 10, 29, 21, 0, 10, 23], | |
| "ct": [6, 19, 22, 10, 29, 13, 10, 9, 29, 17, 30, 4, 1, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 462, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "550094c6c934a4a23e2c", | |
| "msg": [22, 6, 14, 21, 9, 30, 12, 7, 5, 2, 18, 8, 16, 25], | |
| "ct": [1, 1, 4, 13, 3, 13, 29, 31, 31, 31, 31, 31, 31, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 463, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "550094c6c934a4a23e2c", | |
| "msg": [20, 1, 8, 24, 0, 6, 26, 3, 15, 29, 14, 18, 10, 24], | |
| "ct": [1, 1, 4, 13, 3, 13, 29, 31, 31, 31, 31, 31, 31, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 464, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**7 is maximal in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "550094c6c934a4a23e2c", | |
| "msg": [25, 24, 8, 30, 21, 3, 10, 25, 18, 13, 6, 3, 21, 15], | |
| "ct": [1, 1, 4, 13, 3, 13, 29, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 465, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**7 == 0 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "550094c6c934a4a23e2c", | |
| "msg": [5, 21, 26, 5, 22, 10, 8, 12, 21, 4, 17, 27, 23, 27], | |
| "ct": [1, 1, 4, 13, 3, 13, 29, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 466, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "550094c6c934a4a23e2c", | |
| "msg": [6, 20, 7, 6, 22, 20, 31, 3, 12, 6, 1, 27, 7, 21], | |
| "ct": [1, 1, 4, 13, 3, 13, 29, 15, 31, 31, 31, 31, 31, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 467, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "4dfedd6f97765da94b445cc712ea4e7f", | |
| "tweak": "550094c6c934a4a23e2c", | |
| "msg": [1, 10, 31, 12, 25, 6, 30, 21, 8, 30, 26, 16, 2, 18], | |
| "ct": [1, 1, 4, 13, 3, 13, 29, 31, 31, 31, 31, 31, 30, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 468, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "3a6e047dffbfcdaf0ee7e0c93fc4c0e0", | |
| "tweak": "0e5628b6bce472c6", | |
| "msg": [-1, 12, 13, 6, 26, 23, 22, 31, 8, 15, 27, 28, 6, 3], | |
| "ct": [31, 13, 21, 27, 7, 1, 1, 29, 31, 26, 17, 26, 12, 7], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 469, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "3a6e047dffbfcdaf0ee7e0c93fc4c0e0", | |
| "tweak": "0e5628b6bce472c6", | |
| "msg": [26, 12, 13, 6, -1, 23, 22, 31, 8, 15, 27, 28, 6, 3], | |
| "ct": [31, 31, 31, 25, 17, 0, 17, 27, 3, 13, 9, 31, 16, 21], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 470, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "3a6e047dffbfcdaf0ee7e0c93fc4c0e0", | |
| "tweak": "0e5628b6bce472c6", | |
| "msg": [26, 12, 13, 6, 26, 23, 22, 31, 8, 15, 27, 28, 6, -1], | |
| "ct": [28, 27, 6, 11, 7, 25, 0, 29, 9, 1, 25, 20, 10, 2], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 471, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "e9216b56a6b5cce5d84e3b23d3df9434", | |
| "tweak": "90dfe806501ba94c", | |
| "msg": [32, 3, 11, 6, 17, 23, 4, 8, 20, 28, 23, 15, 12, 31], | |
| "ct": [22, 1, 10, 10, 28, 12, 4, 28, 11, 19, 12, 12, 11, 14], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 472, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "e9216b56a6b5cce5d84e3b23d3df9434", | |
| "tweak": "90dfe806501ba94c", | |
| "msg": [5, 3, 11, 6, 32, 23, 4, 8, 20, 28, 23, 15, 12, 31], | |
| "ct": [25, 26, 8, 20, 5, 14, 10, 6, 14, 14, 27, 29, 13, 17], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 473, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "e9216b56a6b5cce5d84e3b23d3df9434", | |
| "tweak": "90dfe806501ba94c", | |
| "msg": [5, 3, 11, 6, 17, 23, 4, 8, 20, 28, 23, 15, 12, 32], | |
| "ct": [16, 20, 11, 5, 10, 9, 18, 0, 19, 7, 31, 23, 31, 29], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 15, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 474, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "7b0c5d430ef9383b04b2691ce3402a9a", | |
| "tweak": "ec71532112064259", | |
| "msg": [12, 5, 14, 30, 2, 12, 27, 4, 27, 2, 7, 17, 10, 26, 28], | |
| "ct": [15, 14, 7, 21, 3, 7, 14, 30, 27, 18, 17, 3, 21, 8, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 475, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [12, 15, 21, 4, 3, 21, 1, 8, 4, 20, 17, 7, 26, 22, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 476, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [8, 16, 13, 3, 15, 4, 24, 27, 27, 7, 15, 24, 0, 8, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 477, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [27, 24, 12, 8, 25, 19, 28, 17, 29, 19, 26, 21, 29, 13, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 478, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [27, 0, 26, 27, 16, 5, 20, 23, 2, 5, 9, 15, 29, 23, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 479, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [27, 14, 19, 9, 10, 1, 11, 28, 23, 23, 13, 22, 24, 18, 29], | |
| "ct": [28, 5, 17, 30, 15, 1, 28, 21, 8, 20, 5, 19, 22, 15, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 480, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [14, 16, 11, 9, 13, 26, 14, 3, 13, 21, 10, 8, 24, 1, 0], | |
| "ct": [4, 26, 25, 25, 14, 16, 31, 23, 9, 27, 29, 16, 11, 0, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 481, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [14, 21, 23, 21, 7, 3, 17, 13, 3, 28, 3, 17, 30, 3, 24], | |
| "ct": [8, 31, 20, 24, 2, 1, 0, 2, 4, 17, 10, 27, 14, 24, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 482, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [16, 17, 26, 19, 12, 6, 4, 30, 21, 22, 17, 8, 15, 21, 9], | |
| "ct": [1, 16, 15, 29, 21, 2, 14, 28, 14, 13, 8, 17, 29, 30, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 483, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [5, 29, 15, 5, 29, 27, 13, 11, 31, 6, 3, 15, 28, 2, 13], | |
| "ct": [1, 18, 10, 31, 18, 29, 11, 20, 30, 0, 0, 17, 6, 22, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 484, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [12, 10, 27, 29, 1, 1, 29, 27, 2, 0, 0, 2, 12, 4, 19], | |
| "ct": [27, 23, 19, 22, 18, 6, 12, 6, 6, 27, 9, 15, 16, 30, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 485, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [1, 31, 16, 22, 15, 15, 28, 5, 20, 19, 15, 7, 29, 17, 10], | |
| "ct": [28, 25, 1, 5, 22, 23, 31, 20, 21, 11, 23, 18, 15, 13, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 486, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [28, 20, 6, 1, 19, 5, 13, 23, 16, 19, 4, 2, 31, 3, 31], | |
| "ct": [29, 29, 25, 28, 27, 17, 15, 5, 10, 13, 0, 4, 20, 21, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 487, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [3, 12, 25, 28, 14, 23, 0, 1, 14, 12, 17, 3, 12, 27, 12], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 488, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [0, 11, 21, 20, 7, 19, 6, 5, 31, 12, 12, 19, 17, 2, 15], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 489, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [31, 21, 26, 0, 15, 27, 4, 13, 3, 29, 26, 13, 20, 0, 24], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 490, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "bd2dc7f87af6e676fa6bf4e92c43f183", | |
| "tweak": "71e1ede1a7e70a42", | |
| "msg": [30, 28, 19, 18, 27, 28, 12, 0, 29, 14, 3, 27, 20, 29, 31], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 491, | |
| "comment": "y = 0 and (y + a) % radix**7 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "7aef234545f65e9313e0", | |
| "msg": [1, 26, 1, 21, 27, 26, 17, 31, 19, 7, 6, 31, 2, 18, 23], | |
| "ct": [19, 13, 0, 29, 6, 23, 22, 16, 5, 22, 20, 23, 3, 17, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 492, | |
| "comment": "y = 0 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "7aef234545f65e9313e0", | |
| "msg": [2, 4, 21, 11, 3, 2, 1, 19, 1, 28, 11, 9, 23, 21, 11], | |
| "ct": [10, 27, 6, 5, 26, 17, 21, 31, 8, 15, 7, 11, 21, 12, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 493, | |
| "comment": "y = 0 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "7aef234545f65e9313e0", | |
| "msg": [13, 19, 11, 21, 18, 1, 3, 15, 30, 3, 11, 14, 30, 14, 9], | |
| "ct": [2, 2, 14, 27, 25, 5, 20, 29, 24, 18, 19, 22, 9, 10, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 494, | |
| "comment": "y = 0 and (y + a) % radix**7 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "7aef234545f65e9313e0", | |
| "msg": [3, 27, 3, 12, 30, 5, 26, 19, 29, 3, 26, 29, 23, 25, 15], | |
| "ct": [19, 29, 16, 10, 9, 20, 30, 23, 13, 17, 27, 5, 12, 20, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 495, | |
| "comment": "y = 1 and a = 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "329edbb9e6c205f8bf71", | |
| "msg": [1, 29, 7, 13, 9, 8, 27, 29, 5, 1, 20, 6, 10, 10, 11], | |
| "ct": [0, 0, 0, 0, 0, 0, 1, 30, 1, 25, 14, 27, 7, 25, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 496, | |
| "comment": "y = 1 and a = 1 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "329edbb9e6c205f8bf71", | |
| "msg": [31, 12, 28, 18, 24, 6, 10, 30, 6, 5, 8, 11, 16, 9, 14], | |
| "ct": [0, 0, 0, 0, 0, 0, 2, 16, 30, 27, 8, 30, 0, 15, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 497, | |
| "comment": "y = 1 and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "329edbb9e6c205f8bf71", | |
| "msg": [28, 19, 12, 5, 9, 3, 29, 31, 19, 14, 13, 5, 18, 18, 18], | |
| "ct": [16, 0, 0, 0, 0, 0, 1, 25, 2, 22, 24, 0, 11, 27, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 498, | |
| "comment": "y = 1 and (y + a) % radix**7 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "329edbb9e6c205f8bf71", | |
| "msg": [17, 23, 13, 19, 2, 1, 27, 31, 14, 21, 24, 22, 14, 20, 13], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 7, 1, 29, 11, 19, 17, 27, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 499, | |
| "comment": "y = 1 and (y + a) % radix**7 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "329edbb9e6c205f8bf71", | |
| "msg": [28, 13, 8, 17, 18, 14, 0, 9, 25, 7, 4, 30, 19, 23, 22], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 2, 29, 0, 16, 20, 10, 21, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 500, | |
| "comment": "y is maximal and (y + a) % radix**7 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "f913918c774f3d9e8664", | |
| "msg": [5, 29, 30, 23, 2, 0, 16, 14, 5, 26, 3, 0, 27, 27, 25], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 12, 2, 23, 19, 27, 1, 20, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 501, | |
| "comment": "y is maximal and (y + a) % radix**7 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "f913918c774f3d9e8664", | |
| "msg": [9, 27, 2, 24, 0, 29, 2, 1, 1, 24, 0, 26, 15, 29, 23], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 30, 29, 19, 6, 16, 1, 22, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 502, | |
| "comment": "y is maximal and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "f913918c774f3d9e8664", | |
| "msg": [15, 3, 9, 7, 5, 2, 6, 18, 6, 13, 28, 16, 1, 26, 20], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 3, 1, 6, 21, 13, 6, 21, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 503, | |
| "comment": "y is maximal and a is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "f913918c774f3d9e8664", | |
| "msg": [3, 7, 7, 17, 13, 3, 30, 26, 13, 12, 6, 16, 5, 28, 28], | |
| "ct": [31, 31, 31, 31, 31, 31, 30, 1, 3, 18, 7, 19, 25, 0, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 504, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "5c9bd8e4825688a67dc2", | |
| "msg": [22, 17, 22, 25, 22, 19, 21, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [30, 26, 21, 28, 16, 21, 13, 1, 13, 10, 26, 3, 24, 2, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 505, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "5c9bd8e4825688a67dc2", | |
| "msg": [2, 20, 8, 10, 11, 22, 10, 0, 0, 0, 0, 0, 0, 0, 1], | |
| "ct": [13, 13, 1, 14, 31, 24, 12, 20, 23, 0, 29, 19, 25, 13, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 506, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**8 is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "5c9bd8e4825688a67dc2", | |
| "msg": [31, 18, 29, 17, 27, 11, 14, 0, 0, 0, 0, 0, 0, 0, 31], | |
| "ct": [23, 6, 0, 8, 5, 5, 13, 24, 14, 23, 0, 21, 13, 2, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 507, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**8 == 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "5c9bd8e4825688a67dc2", | |
| "msg": [12, 6, 28, 3, 0, 15, 25, 0, 0, 0, 0, 0, 0, 1, 0], | |
| "ct": [27, 9, 23, 21, 19, 19, 31, 15, 28, 18, 31, 0, 17, 12, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 508, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "5c9bd8e4825688a67dc2", | |
| "msg": [27, 10, 20, 27, 21, 3, 4, 16, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [1, 2, 13, 2, 20, 8, 29, 21, 9, 14, 14, 30, 1, 17, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 509, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "5c9bd8e4825688a67dc2", | |
| "msg": [25, 13, 28, 8, 12, 26, 16, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [27, 15, 14, 25, 21, 25, 1, 26, 1, 4, 3, 0, 25, 31, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 510, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**7 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "2ea5fdea1b4b668ae229", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 27, 0, 24, 1, 18, 10, 23, 4], | |
| "ct": [13, 15, 10, 21, 20, 12, 26, 7, 2, 1, 4, 4, 8, 25, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 511, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**7 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "2ea5fdea1b4b668ae229", | |
| "msg": [0, 0, 0, 0, 0, 0, 1, 27, 0, 24, 1, 18, 10, 23, 4], | |
| "ct": [25, 7, 23, 1, 29, 23, 5, 20, 3, 29, 18, 27, 22, 19, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 512, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "2ea5fdea1b4b668ae229", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 27, 0, 24, 1, 18, 10, 23, 4], | |
| "ct": [5, 25, 5, 9, 5, 16, 18, 18, 19, 13, 25, 18, 14, 25, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 513, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "b4aac83ef6dc59fd0ab9a7692e6ef3c4", | |
| "tweak": "2ea5fdea1b4b668ae229", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 27, 0, 24, 1, 18, 10, 23, 4], | |
| "ct": [31, 16, 2, 19, 2, 0, 2, 16, 27, 15, 23, 12, 28, 28, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 514, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "18f316e92e027b0d4d068bb94f8dd864", | |
| "tweak": "17d37026864474b3", | |
| "msg": [-1, 23, 3, 22, 24, 10, 7, 10, 11, 12, 21, 26, 7, 7, 15], | |
| "ct": [1, 20, 20, 28, 10, 27, 21, 7, 27, 30, 3, 28, 0, 28, 18], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 515, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "18f316e92e027b0d4d068bb94f8dd864", | |
| "tweak": "17d37026864474b3", | |
| "msg": [1, 23, 3, 22, 24, -1, 7, 10, 11, 12, 21, 26, 7, 7, 15], | |
| "ct": [9, 11, 22, 12, 31, 29, 26, 6, 0, 31, 4, 24, 6, 20, 23], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 516, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "18f316e92e027b0d4d068bb94f8dd864", | |
| "tweak": "17d37026864474b3", | |
| "msg": [1, 23, 3, 22, 24, 10, 7, 10, 11, 12, 21, 26, 7, 7, -1], | |
| "ct": [2, 13, 23, 18, 18, 30, 15, 15, 27, 13, 30, 16, 12, 4, 2], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 517, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "4175f5b9d8b521720a6066803bd12e00", | |
| "tweak": "d0f8f6486f19fb4e", | |
| "msg": [32, 11, 20, 5, 17, 18, 30, 27, 28, 26, 6, 2, 0, 21, 23], | |
| "ct": [30, 27, 0, 10, 17, 22, 23, 23, 3, 2, 14, 20, 18, 14, 15], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 518, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "4175f5b9d8b521720a6066803bd12e00", | |
| "tweak": "d0f8f6486f19fb4e", | |
| "msg": [27, 11, 20, 5, 17, 32, 30, 27, 28, 26, 6, 2, 0, 21, 23], | |
| "ct": [3, 6, 22, 30, 13, 12, 31, 26, 8, 7, 10, 1, 5, 5, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 519, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "4175f5b9d8b521720a6066803bd12e00", | |
| "tweak": "d0f8f6486f19fb4e", | |
| "msg": [27, 11, 20, 5, 17, 18, 30, 27, 28, 26, 6, 2, 0, 21, 32], | |
| "ct": [19, 25, 30, 29, 27, 4, 1, 27, 9, 7, 7, 16, 25, 27, 12], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 16, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 520, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "48f0d03e41cc55c4b58f737b5acdea32", | |
| "tweak": "30944debca89ca90", | |
| "msg": [16, 4, 15, 30, 1, 17, 4, 1, 9, 22, 10, 1, 15, 5, 15, 24], | |
| "ct": [31, 13, 22, 30, 28, 3, 25, 18, 17, 12, 11, 26, 5, 10, 16, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 521, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [2, 21, 19, 4, 17, 1, 7, 26, 12, 29, 20, 19, 23, 25, 11, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 522, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [25, 29, 22, 16, 7, 17, 0, 14, 29, 8, 25, 7, 7, 4, 2, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 523, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [25, 11, 0, 15, 21, 20, 5, 16, 24, 0, 6, 31, 28, 17, 5, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 524, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [0, 20, 0, 12, 29, 1, 27, 15, 13, 4, 28, 17, 13, 14, 24, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 525, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [14, 15, 12, 9, 5, 23, 15, 0, 5, 24, 22, 8, 2, 6, 5, 3], | |
| "ct": [22, 5, 19, 31, 1, 27, 9, 25, 15, 6, 14, 14, 20, 30, 16, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 526, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [24, 11, 8, 3, 0, 3, 15, 12, 7, 25, 11, 5, 5, 0, 27, 12], | |
| "ct": [11, 7, 24, 4, 5, 23, 20, 10, 16, 29, 18, 1, 30, 14, 5, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 527, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [13, 16, 2, 0, 10, 30, 3, 24, 24, 12, 29, 24, 8, 20, 17, 20], | |
| "ct": [12, 13, 3, 2, 12, 22, 6, 25, 1, 4, 26, 18, 9, 27, 26, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 528, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [31, 11, 2, 8, 25, 21, 7, 20, 11, 7, 12, 14, 4, 14, 22, 20], | |
| "ct": [7, 24, 15, 12, 21, 11, 5, 11, 14, 7, 30, 27, 9, 6, 21, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 529, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [15, 20, 5, 15, 9, 16, 15, 23, 31, 26, 16, 26, 26, 5, 1, 0], | |
| "ct": [10, 20, 27, 1, 26, 11, 31, 9, 3, 14, 11, 14, 31, 14, 6, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 530, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [24, 16, 17, 1, 10, 4, 27, 8, 12, 16, 10, 7, 2, 24, 11, 31], | |
| "ct": [0, 29, 11, 14, 16, 22, 11, 30, 0, 28, 15, 7, 26, 10, 18, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 531, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [5, 13, 25, 1, 3, 4, 25, 24, 25, 9, 13, 31, 19, 0, 31, 5], | |
| "ct": [31, 14, 6, 18, 13, 20, 4, 27, 17, 16, 8, 24, 6, 6, 6, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 532, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [4, 10, 2, 27, 3, 28, 7, 1, 20, 26, 29, 22, 9, 23, 31, 8], | |
| "ct": [7, 13, 20, 15, 27, 9, 24, 7, 30, 29, 23, 5, 28, 5, 11, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 533, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [23, 23, 20, 10, 23, 0, 17, 0, 7, 8, 19, 13, 5, 2, 26, 13], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 534, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [17, 20, 1, 17, 5, 2, 22, 25, 31, 10, 9, 23, 7, 28, 26, 11], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 535, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [25, 29, 25, 12, 1, 22, 12, 24, 12, 17, 25, 1, 10, 12, 27, 12], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 536, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "58a68a9bf81642540bcff165563af592", | |
| "tweak": "a4a9513e222fab29", | |
| "msg": [5, 11, 5, 11, 24, 27, 29, 27, 12, 25, 27, 18, 12, 6, 6, 4], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 537, | |
| "comment": "y = 0 and (y + a) % radix**8 == 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "4308ddeb395477bc7660", | |
| "msg": [2, 18, 22, 16, 21, 13, 17, 1, 23, 24, 16, 23, 1, 3, 22, 29], | |
| "ct": [3, 1, 17, 18, 3, 28, 10, 29, 20, 6, 13, 1, 19, 21, 2, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 538, | |
| "comment": "y = 0 and a = 1 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "4308ddeb395477bc7660", | |
| "msg": [5, 10, 6, 8, 22, 19, 7, 20, 10, 0, 0, 23, 10, 21, 3, 10], | |
| "ct": [27, 20, 11, 17, 8, 15, 29, 18, 22, 29, 20, 15, 3, 25, 20, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 539, | |
| "comment": "y = 0 and a has large Hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "4308ddeb395477bc7660", | |
| "msg": [23, 3, 9, 12, 3, 13, 2, 10, 22, 19, 4, 2, 22, 18, 17, 8], | |
| "ct": [2, 5, 12, 27, 7, 3, 21, 23, 15, 24, 24, 21, 30, 18, 31, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 540, | |
| "comment": "y = 0 and (y + a) % radix**8 is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "4308ddeb395477bc7660", | |
| "msg": [29, 25, 21, 9, 31, 13, 20, 31, 10, 23, 23, 27, 10, 30, 7, 17], | |
| "ct": [6, 5, 7, 15, 28, 17, 4, 20, 27, 14, 3, 21, 11, 24, 12, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 541, | |
| "comment": "y = 1 and a = 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "3d8975d97355fe073e9d", | |
| "msg": [11, 27, 21, 29, 18, 22, 13, 22, 15, 3, 31, 23, 13, 14, 1, 16], | |
| "ct": [6, 12, 22, 24, 3, 15, 1, 9, 10, 3, 25, 3, 2, 31, 9, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 542, | |
| "comment": "y = 1 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "3d8975d97355fe073e9d", | |
| "msg": [16, 7, 30, 7, 28, 8, 2, 4, 20, 31, 20, 7, 11, 11, 14, 22], | |
| "ct": [15, 15, 7, 19, 0, 19, 29, 1, 29, 24, 11, 20, 4, 25, 0, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 543, | |
| "comment": "y = 1 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "3d8975d97355fe073e9d", | |
| "msg": [31, 25, 12, 10, 8, 7, 20, 18, 17, 18, 6, 26, 14, 22, 8, 21], | |
| "ct": [19, 6, 29, 12, 10, 27, 1, 8, 31, 5, 11, 13, 30, 16, 9, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 544, | |
| "comment": "y = 1 and (y + a) % radix**8 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "3d8975d97355fe073e9d", | |
| "msg": [25, 16, 28, 5, 30, 14, 0, 28, 15, 10, 31, 18, 21, 0, 21, 16], | |
| "ct": [8, 13, 12, 21, 23, 18, 13, 30, 19, 11, 2, 1, 21, 2, 4, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 545, | |
| "comment": "y = 1 and (y + a) % radix**8 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "3d8975d97355fe073e9d", | |
| "msg": [18, 8, 14, 3, 5, 31, 18, 16, 26, 27, 14, 28, 30, 14, 10, 5], | |
| "ct": [31, 3, 12, 27, 14, 6, 8, 11, 9, 23, 23, 4, 27, 18, 28, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 546, | |
| "comment": "y is maximal and (y + a) % radix**8 is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "2243d145c3a8ca09d458", | |
| "msg": [11, 15, 0, 20, 19, 20, 20, 1, 26, 7, 3, 3, 27, 2, 25, 15], | |
| "ct": [10, 7, 22, 1, 19, 26, 14, 5, 18, 21, 13, 11, 10, 5, 4, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 547, | |
| "comment": "y is maximal and (y + a) % radix**8 == 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "2243d145c3a8ca09d458", | |
| "msg": [27, 25, 1, 17, 0, 1, 23, 14, 12, 28, 17, 4, 21, 7, 16, 24], | |
| "ct": [1, 23, 17, 15, 2, 24, 11, 1, 8, 16, 4, 7, 19, 19, 26, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 548, | |
| "comment": "y is maximal and a has large Hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "2243d145c3a8ca09d458", | |
| "msg": [18, 2, 31, 21, 15, 31, 23, 7, 4, 24, 28, 29, 10, 9, 15, 16], | |
| "ct": [25, 18, 14, 5, 7, 16, 18, 18, 2, 6, 16, 5, 27, 17, 1, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 549, | |
| "comment": "y is maximal and a is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "2243d145c3a8ca09d458", | |
| "msg": [2, 8, 29, 7, 4, 20, 22, 17, 22, 26, 31, 3, 12, 0, 5, 26], | |
| "ct": [30, 13, 6, 29, 10, 8, 8, 13, 5, 26, 25, 3, 2, 0, 23, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 550, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "0e57a45af3244eb76ef5", | |
| "msg": [27, 31, 0, 8, 31, 20, 5, 15, 17, 3, 29, 1, 10, 21, 16, 22], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 0, 26, 6, 9, 19, 11, 16, 0, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 551, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "0e57a45af3244eb76ef5", | |
| "msg": [20, 26, 1, 21, 27, 21, 6, 31, 19, 7, 22, 4, 0, 30, 0, 14], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 1, 7, 13, 12, 23, 5, 18, 14, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 552, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**8 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "0e57a45af3244eb76ef5", | |
| "msg": [21, 23, 13, 10, 30, 17, 31, 27, 30, 29, 20, 11, 14, 13, 17, 3], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 25, 27, 19, 17, 30, 23, 11, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 553, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**8 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "0e57a45af3244eb76ef5", | |
| "msg": [5, 25, 25, 17, 20, 16, 17, 24, 23, 20, 13, 23, 4, 17, 28, 17], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 1, 2, 19, 11, 10, 30, 24, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 554, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "0e57a45af3244eb76ef5", | |
| "msg": [14, 11, 12, 8, 24, 1, 13, 28, 9, 30, 24, 8, 14, 30, 27, 26], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 0, 24, 9, 27, 15, 7, 9, 30, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 555, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "0e57a45af3244eb76ef5", | |
| "msg": [14, 8, 20, 19, 3, 29, 3, 16, 6, 2, 1, 17, 7, 8, 3, 15], | |
| "ct": [31, 31, 31, 31, 31, 31, 30, 31, 8, 16, 28, 3, 20, 22, 13, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 556, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**8 is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "7c2453d72d7a3c947ec1", | |
| "msg": [6, 31, 19, 18, 14, 17, 22, 24, 16, 31, 29, 7, 1, 17, 13, 22], | |
| "ct": [18, 21, 15, 12, 7, 10, 26, 1, 22, 29, 12, 22, 15, 14, 14, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 557, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**8 == 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "7c2453d72d7a3c947ec1", | |
| "msg": [15, 25, 10, 15, 23, 18, 3, 14, 10, 13, 20, 26, 25, 18, 28, 31], | |
| "ct": [31, 12, 0, 21, 15, 4, 16, 28, 29, 16, 26, 1, 1, 29, 10, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 558, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "7c2453d72d7a3c947ec1", | |
| "msg": [28, 5, 23, 29, 14, 24, 2, 13, 20, 1, 17, 6, 7, 0, 30, 27], | |
| "ct": [19, 19, 21, 7, 22, 3, 21, 21, 7, 20, 11, 30, 30, 11, 6, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 559, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "ce2295b38289779ad19a532cd6be845b", | |
| "tweak": "7c2453d72d7a3c947ec1", | |
| "msg": [23, 10, 26, 24, 0, 10, 15, 30, 26, 16, 4, 15, 28, 17, 30, 23], | |
| "ct": [21, 0, 16, 29, 6, 11, 4, 7, 27, 18, 19, 27, 31, 9, 9, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 560, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "c3a8f68c88eeea1a255db6a7e012ec22", | |
| "tweak": "a841e8a1819dfb69", | |
| "msg": [-1, 5, 20, 21, 9, 29, 6, 5, 7, 7, 27, 31, 21, 21, 2, 8], | |
| "ct": [29, 8, 27, 11, 0, 20, 17, 6, 8, 17, 18, 26, 6, 18, 20, 17], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 561, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "c3a8f68c88eeea1a255db6a7e012ec22", | |
| "tweak": "a841e8a1819dfb69", | |
| "msg": [28, 5, 20, 21, 9, -1, 6, 5, 7, 7, 27, 31, 21, 21, 2, 8], | |
| "ct": [16, 25, 14, 8, 25, 13, 1, 4, 27, 4, 13, 5, 7, 2, 17, 19], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 562, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "c3a8f68c88eeea1a255db6a7e012ec22", | |
| "tweak": "a841e8a1819dfb69", | |
| "msg": [28, 5, 20, 21, 9, 29, 6, 5, 7, 7, 27, 31, 21, 21, 2, -1], | |
| "ct": [1, 13, 21, 11, 29, 30, 27, 12, 7, 21, 18, 6, 0, 26, 3, 14], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 563, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "13277a6dcfbe53b477f7d73c42ec6cf1", | |
| "tweak": "3def405778efc5b6", | |
| "msg": [32, 15, 31, 12, 29, 30, 8, 27, 4, 25, 1, 31, 12, 5, 20, 7], | |
| "ct": [15, 10, 16, 16, 17, 0, 17, 27, 23, 13, 26, 18, 25, 28, 30, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 564, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "13277a6dcfbe53b477f7d73c42ec6cf1", | |
| "tweak": "3def405778efc5b6", | |
| "msg": [4, 15, 31, 12, 29, 32, 8, 27, 4, 25, 1, 31, 12, 5, 20, 7], | |
| "ct": [17, 13, 13, 7, 25, 24, 27, 9, 6, 19, 9, 21, 26, 9, 20, 6], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 565, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "13277a6dcfbe53b477f7d73c42ec6cf1", | |
| "tweak": "3def405778efc5b6", | |
| "msg": [4, 15, 31, 12, 29, 30, 8, 27, 4, 25, 1, 31, 12, 5, 20, 32], | |
| "ct": [31, 3, 2, 18, 7, 9, 10, 19, 26, 13, 24, 22, 18, 13, 23, 5], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 17, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 566, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "22351a53774415942eb879b483eda9a2", | |
| "tweak": "b4a5dce9958d53fc", | |
| "msg": [17, 12, 16, 11, 18, 21, 23, 27, 17, 21, 25, 2, 24, 20, 15, 12, 26], | |
| "ct": [31, 13, 18, 22, 15, 2, 13, 0, 21, 27, 1, 15, 9, 29, 15, 19, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 567, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [14, 17, 1, 11, 13, 28, 0, 27, 17, 9, 31, 24, 0, 8, 25, 27, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 568, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [4, 30, 21, 8, 31, 26, 21, 31, 7, 27, 23, 2, 7, 26, 17, 17, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 569, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [20, 16, 17, 10, 23, 18, 16, 27, 29, 24, 3, 0, 21, 30, 18, 2, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 570, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [12, 7, 4, 19, 16, 29, 11, 10, 20, 8, 31, 29, 30, 20, 23, 19, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 571, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [24, 3, 12, 20, 29, 26, 4, 21, 28, 6, 10, 23, 14, 18, 9, 6, 7], | |
| "ct": [26, 28, 5, 11, 9, 31, 6, 2, 21, 3, 26, 4, 6, 10, 1, 15, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 572, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [27, 18, 4, 22, 12, 8, 4, 26, 6, 5, 16, 21, 19, 23, 18, 5, 12], | |
| "ct": [26, 15, 0, 29, 15, 27, 30, 7, 11, 2, 20, 3, 16, 6, 23, 0, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 573, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [14, 27, 2, 18, 16, 0, 4, 28, 30, 11, 2, 30, 8, 5, 14, 27, 12], | |
| "ct": [12, 3, 19, 3, 24, 25, 24, 9, 25, 13, 27, 10, 24, 12, 27, 16, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 574, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [30, 10, 11, 13, 22, 20, 30, 13, 14, 22, 8, 8, 16, 3, 7, 11, 9], | |
| "ct": [22, 14, 10, 13, 31, 12, 5, 2, 12, 14, 2, 24, 10, 13, 0, 29, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 575, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [10, 15, 6, 24, 10, 21, 24, 24, 3, 27, 6, 13, 14, 9, 16, 8, 17], | |
| "ct": [0, 4, 23, 27, 15, 12, 26, 8, 6, 30, 7, 10, 18, 31, 16, 14, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 576, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [18, 31, 26, 4, 22, 27, 27, 1, 8, 15, 21, 1, 11, 5, 2, 0, 17], | |
| "ct": [30, 28, 5, 10, 26, 26, 26, 7, 8, 18, 14, 11, 29, 30, 20, 20, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 577, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [7, 21, 0, 31, 16, 12, 2, 20, 28, 20, 20, 4, 3, 31, 2, 27, 6], | |
| "ct": [18, 21, 27, 9, 22, 23, 18, 20, 3, 24, 5, 29, 28, 24, 9, 23, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 578, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [17, 7, 13, 17, 22, 22, 3, 13, 22, 31, 7, 24, 8, 14, 30, 28, 8], | |
| "ct": [19, 26, 15, 6, 11, 23, 29, 31, 13, 19, 31, 5, 5, 24, 26, 25, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 579, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [21, 24, 26, 26, 13, 18, 10, 31, 2, 14, 12, 26, 5, 30, 8, 11, 31], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 580, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [29, 4, 27, 19, 9, 18, 16, 5, 10, 4, 29, 1, 11, 0, 21, 19, 9], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 581, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [26, 13, 14, 15, 30, 15, 2, 8, 0, 15, 29, 2, 3, 1, 9, 4, 26], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 582, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "586c34235df3fd6ed8995a643fd52d41", | |
| "tweak": "c41f1671a352a8fb", | |
| "msg": [12, 19, 6, 28, 7, 30, 17, 18, 23, 27, 30, 15, 11, 24, 0, 22, 12], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 583, | |
| "comment": "y = 0 and (y + a) % radix**8 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "477e20918dcca631ba", | |
| "msg": [26, 8, 17, 12, 7, 22, 31, 24, 19, 8, 19, 13, 0, 17, 11, 12, 0], | |
| "ct": [0, 1, 15, 19, 28, 31, 30, 20, 11, 8, 5, 22, 21, 16, 26, 4, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 584, | |
| "comment": "y = 0 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "477e20918dcca631ba", | |
| "msg": [15, 4, 31, 17, 13, 12, 0, 14, 24, 31, 19, 29, 3, 30, 3, 5, 5], | |
| "ct": [10, 6, 6, 12, 6, 0, 17, 19, 26, 24, 0, 13, 17, 19, 13, 7, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 585, | |
| "comment": "y = 0 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "477e20918dcca631ba", | |
| "msg": [12, 17, 10, 5, 9, 20, 22, 9, 4, 20, 1, 12, 1, 23, 13, 30, 18], | |
| "ct": [30, 30, 5, 8, 21, 8, 5, 2, 21, 3, 23, 16, 29, 0, 12, 20, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 586, | |
| "comment": "y = 0 and (y + a) % radix**8 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "477e20918dcca631ba", | |
| "msg": [23, 27, 0, 30, 29, 25, 15, 24, 12, 10, 13, 5, 22, 18, 5, 4, 5], | |
| "ct": [24, 0, 28, 12, 23, 28, 1, 13, 21, 16, 27, 12, 21, 14, 27, 12, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 587, | |
| "comment": "y = 1 and a = 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "e960a1b87de6788747", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 7, 23, 19, 8, 13, 27, 28, 5, 26], | |
| "ct": [31, 12, 14, 17, 26, 19, 5, 31, 22, 29, 5, 3, 17, 13, 7, 29, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 588, | |
| "comment": "y = 1 and a = 1 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "e960a1b87de6788747", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 1, 7, 23, 19, 8, 13, 27, 28, 5, 26], | |
| "ct": [22, 6, 28, 11, 26, 14, 15, 20, 2, 25, 23, 13, 8, 10, 18, 13, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 589, | |
| "comment": "y = 1 and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "e960a1b87de6788747", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 7, 23, 19, 8, 13, 27, 28, 5, 26], | |
| "ct": [11, 7, 28, 16, 23, 26, 25, 28, 13, 11, 4, 0, 1, 26, 22, 16, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 590, | |
| "comment": "y = 1 and (y + a) % radix**8 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "e960a1b87de6788747", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 30, 7, 23, 19, 8, 13, 27, 28, 5, 26], | |
| "ct": [5, 26, 2, 14, 13, 13, 7, 8, 7, 18, 14, 17, 7, 1, 5, 5, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 591, | |
| "comment": "y = 1 and (y + a) % radix**8 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "e960a1b87de6788747", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 7, 23, 19, 8, 13, 27, 28, 5, 26], | |
| "ct": [14, 17, 3, 5, 19, 11, 5, 25, 14, 23, 9, 9, 18, 24, 20, 11, 14], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 592, | |
| "comment": "y is maximal and (y + a) % radix**8 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "81218a695988158276", | |
| "msg": [22, 18, 15, 17, 6, 13, 6, 20, 18, 2, 16, 15, 6, 31, 3, 17, 0], | |
| "ct": [2, 3, 14, 27, 26, 3, 25, 14, 3, 19, 19, 29, 26, 13, 26, 21, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 593, | |
| "comment": "y is maximal and (y + a) % radix**8 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "81218a695988158276", | |
| "msg": [12, 20, 22, 8, 6, 18, 31, 7, 16, 15, 9, 23, 26, 30, 26, 23, 21], | |
| "ct": [19, 16, 17, 19, 14, 6, 3, 18, 11, 20, 4, 20, 22, 20, 9, 19, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 594, | |
| "comment": "y is maximal and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "81218a695988158276", | |
| "msg": [6, 18, 31, 3, 11, 3, 3, 1, 18, 2, 11, 21, 23, 9, 31, 28, 20], | |
| "ct": [15, 12, 24, 12, 20, 23, 11, 1, 12, 21, 11, 17, 26, 20, 25, 21, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 595, | |
| "comment": "y is maximal and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "81218a695988158276", | |
| "msg": [17, 16, 17, 23, 1, 22, 10, 28, 20, 22, 22, 17, 22, 28, 27, 29, 8], | |
| "ct": [10, 28, 18, 16, 2, 24, 26, 21, 4, 24, 29, 19, 5, 1, 10, 11, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 596, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "ef5c786ff37bd7e162", | |
| "msg": [9, 30, 26, 20, 7, 8, 11, 20, 30, 29, 27, 30, 29, 11, 27, 3, 3], | |
| "ct": [5, 20, 12, 15, 10, 5, 4, 3, 7, 1, 18, 13, 6, 3, 25, 30, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 597, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "ef5c786ff37bd7e162", | |
| "msg": [20, 6, 13, 23, 28, 18, 18, 28, 23, 1, 28, 2, 12, 7, 11, 25, 24], | |
| "ct": [2, 18, 13, 21, 22, 19, 28, 8, 26, 28, 11, 24, 29, 14, 14, 24, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 598, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**8 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "ef5c786ff37bd7e162", | |
| "msg": [15, 5, 19, 16, 0, 12, 23, 17, 5, 17, 22, 15, 24, 14, 1, 30, 7], | |
| "ct": [30, 5, 7, 1, 20, 26, 9, 19, 14, 26, 19, 15, 11, 18, 2, 19, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 599, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**8 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "ef5c786ff37bd7e162", | |
| "msg": [26, 10, 2, 15, 30, 7, 15, 19, 22, 13, 27, 12, 15, 27, 15, 0, 28], | |
| "ct": [9, 2, 12, 17, 30, 26, 24, 17, 24, 29, 22, 23, 9, 8, 9, 5, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 600, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "ef5c786ff37bd7e162", | |
| "msg": [14, 10, 6, 12, 27, 23, 29, 24, 28, 11, 7, 10, 28, 17, 19, 15, 7], | |
| "ct": [25, 1, 20, 30, 9, 3, 7, 26, 0, 0, 4, 18, 4, 28, 22, 29, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 601, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "ef5c786ff37bd7e162", | |
| "msg": [22, 6, 4, 11, 28, 20, 16, 29, 18, 4, 21, 21, 2, 7, 6, 28, 6], | |
| "ct": [16, 18, 6, 15, 22, 29, 13, 27, 14, 15, 26, 25, 22, 13, 26, 10, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 602, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**8 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "d2eadadf47104aa6b4", | |
| "msg": [14, 16, 4, 2, 13, 17, 28, 9, 8, 30, 31, 8, 23, 24, 6, 6, 5], | |
| "ct": [5, 0, 14, 29, 12, 14, 1, 31, 20, 30, 4, 29, 12, 22, 13, 11, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 603, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**8 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "d2eadadf47104aa6b4", | |
| "msg": [4, 17, 22, 20, 21, 31, 19, 13, 24, 18, 15, 5, 30, 16, 8, 8, 12], | |
| "ct": [30, 31, 9, 20, 25, 25, 25, 23, 7, 28, 29, 26, 26, 0, 4, 23, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 604, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "d2eadadf47104aa6b4", | |
| "msg": [19, 2, 26, 6, 5, 7, 13, 16, 29, 0, 5, 28, 20, 29, 14, 7, 27], | |
| "ct": [20, 28, 5, 27, 19, 4, 12, 20, 5, 5, 18, 20, 4, 27, 17, 7, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 605, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "47b31cab4872b3dfea0ebed259ac5cb7", | |
| "tweak": "d2eadadf47104aa6b4", | |
| "msg": [22, 23, 2, 23, 1, 14, 15, 11, 10, 11, 18, 23, 31, 31, 2, 24, 29], | |
| "ct": [24, 5, 2, 10, 26, 27, 26, 8, 24, 22, 29, 28, 0, 22, 20, 4, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 606, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "2ec80962dad2bf783abd539d85a7c8d6", | |
| "tweak": "1a36d2cb8088c664", | |
| "msg": [-1, 22, 1, 12, 29, 17, 20, 18, 28, 11, 25, 4, 18, 13, 8, 9, 4], | |
| "ct": [14, 6, 5, 26, 11, 7, 17, 16, 24, 3, 23, 30, 28, 30, 28, 14, 4], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 607, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "2ec80962dad2bf783abd539d85a7c8d6", | |
| "tweak": "1a36d2cb8088c664", | |
| "msg": [21, 22, 1, 12, 29, -1, 20, 18, 28, 11, 25, 4, 18, 13, 8, 9, 4], | |
| "ct": [19, 29, 5, 22, 27, 4, 1, 0, 24, 6, 1, 13, 3, 27, 0, 8, 7], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 608, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "2ec80962dad2bf783abd539d85a7c8d6", | |
| "tweak": "1a36d2cb8088c664", | |
| "msg": [21, 22, 1, 12, 29, 17, 20, 18, 28, 11, 25, 4, 18, 13, 8, 9, -1], | |
| "ct": [20, 23, 21, 14, 25, 6, 3, 17, 28, 1, 12, 19, 3, 8, 10, 28, 14], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 609, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "480bd0f34f9a16d2c1349ddabf619202", | |
| "tweak": "ee0cc5ab890ae0ad", | |
| "msg": [32, 20, 14, 27, 2, 20, 13, 12, 9, 24, 16, 9, 30, 29, 13, 20, 16], | |
| "ct": [15, 31, 9, 17, 26, 24, 27, 13, 29, 22, 31, 10, 31, 26, 16, 2, 23], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 610, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "480bd0f34f9a16d2c1349ddabf619202", | |
| "tweak": "ee0cc5ab890ae0ad", | |
| "msg": [24, 20, 14, 27, 2, 32, 13, 12, 9, 24, 16, 9, 30, 29, 13, 20, 16], | |
| "ct": [7, 22, 0, 21, 22, 1, 1, 24, 24, 2, 26, 2, 10, 27, 15, 29, 25], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 611, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "480bd0f34f9a16d2c1349ddabf619202", | |
| "tweak": "ee0cc5ab890ae0ad", | |
| "msg": [24, 20, 14, 27, 2, 20, 13, 12, 9, 24, 16, 9, 30, 29, 13, 20, 32], | |
| "ct": [2, 30, 31, 5, 30, 6, 14, 24, 8, 7, 30, 0, 1, 9, 25, 27, 6], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 18, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 612, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "40dcd7ccae73e5e9bba5523fbab77a3c", | |
| "tweak": "60ddd7c8df1437cf", | |
| "msg": [3, 25, 16, 25, 21, 26, 8, 22, 2, 24, 2, 0, 5, 5, 7, 11, 13, 15], | |
| "ct": [5, 17, 20, 3, 21, 9, 8, 3, 17, 21, 25, 18, 15, 26, 6, 20, 14, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 613, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [14, 6, 10, 28, 4, 23, 10, 23, 20, 20, 23, 21, 13, 6, 9, 10, 14, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 614, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [8, 16, 19, 6, 17, 11, 27, 20, 8, 27, 23, 0, 3, 9, 9, 9, 30, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 615, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [21, 17, 10, 21, 1, 8, 15, 23, 29, 9, 23, 13, 30, 3, 8, 13, 6, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 616, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [6, 4, 5, 29, 31, 19, 10, 11, 19, 14, 7, 16, 2, 3, 14, 17, 29, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 617, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [0, 20, 26, 10, 24, 11, 2, 20, 21, 30, 17, 27, 22, 10, 0, 19, 11, 24], | |
| "ct": [6, 28, 9, 15, 7, 23, 28, 22, 20, 25, 20, 1, 14, 29, 12, 24, 20, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 618, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [29, 14, 6, 7, 12, 6, 15, 20, 8, 19, 4, 30, 30, 8, 14, 21, 26, 6], | |
| "ct": [10, 7, 18, 23, 3, 2, 1, 5, 15, 23, 30, 14, 18, 28, 5, 2, 27, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 619, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [25, 29, 29, 1, 0, 21, 17, 15, 20, 16, 6, 10, 23, 11, 25, 28, 7, 8], | |
| "ct": [29, 9, 30, 22, 16, 20, 4, 26, 11, 6, 23, 31, 0, 24, 3, 18, 26, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 620, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [27, 22, 27, 14, 24, 1, 13, 26, 17, 12, 16, 24, 6, 10, 9, 31, 31, 15], | |
| "ct": [24, 29, 17, 5, 0, 14, 29, 27, 30, 24, 1, 16, 26, 22, 8, 19, 7, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 621, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [5, 19, 12, 20, 17, 7, 17, 23, 0, 24, 20, 20, 12, 24, 8, 31, 15, 12], | |
| "ct": [29, 16, 18, 9, 30, 11, 8, 21, 7, 13, 6, 8, 9, 21, 8, 21, 0, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 622, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [1, 30, 31, 11, 0, 26, 20, 11, 26, 20, 16, 28, 7, 17, 6, 22, 7, 3], | |
| "ct": [18, 3, 11, 1, 23, 30, 26, 7, 24, 31, 28, 14, 26, 24, 20, 28, 15, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 623, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [0, 12, 4, 18, 2, 18, 21, 28, 19, 11, 24, 22, 13, 28, 8, 21, 4, 19], | |
| "ct": [21, 11, 11, 0, 4, 26, 29, 30, 21, 18, 27, 8, 14, 22, 25, 18, 23, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 624, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [20, 8, 7, 27, 20, 11, 3, 18, 20, 5, 24, 0, 6, 28, 21, 16, 26, 19], | |
| "ct": [30, 13, 16, 26, 29, 8, 22, 28, 12, 21, 18, 1, 0, 28, 30, 26, 17, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 625, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [10, 1, 24, 21, 19, 2, 14, 28, 15, 24, 28, 30, 2, 11, 15, 0, 16, 31], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 626, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [9, 29, 4, 19, 1, 31, 13, 17, 25, 29, 1, 30, 13, 25, 1, 18, 12, 2], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 627, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [28, 30, 10, 6, 29, 26, 25, 3, 7, 4, 8, 28, 26, 30, 25, 22, 9, 29], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 628, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "fbe6a74c32f28d6fcb00598b1d6c531a", | |
| "tweak": "308cfb8c6402c842", | |
| "msg": [20, 2, 30, 2, 23, 31, 4, 22, 3, 24, 20, 22, 30, 21, 24, 25, 30, 18], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 629, | |
| "comment": "y = 0 and (y + a) % radix**9 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "c7d172d36205c51338", | |
| "msg": [21, 31, 3, 21, 26, 24, 10, 25, 21, 24, 15, 7, 5, 8, 6, 13, 6, 9], | |
| "ct": [20, 12, 13, 29, 6, 7, 0, 18, 29, 17, 10, 8, 19, 21, 1, 9, 12, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 630, | |
| "comment": "y = 0 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "c7d172d36205c51338", | |
| "msg": [28, 28, 29, 8, 6, 27, 23, 17, 7, 13, 28, 13, 21, 21, 3, 8, 25, 15], | |
| "ct": [9, 16, 10, 23, 1, 9, 26, 21, 27, 2, 6, 30, 21, 12, 20, 23, 13, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 631, | |
| "comment": "y = 0 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "c7d172d36205c51338", | |
| "msg": [14, 7, 6, 7, 14, 23, 29, 14, 0, 28, 24, 14, 16, 22, 14, 13, 24, 10], | |
| "ct": [8, 17, 26, 29, 20, 15, 16, 5, 6, 9, 5, 9, 10, 17, 31, 23, 9, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 632, | |
| "comment": "y = 0 and (y + a) % radix**9 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "c7d172d36205c51338", | |
| "msg": [8, 14, 18, 3, 13, 27, 0, 24, 11, 31, 13, 12, 28, 12, 25, 22, 31, 26], | |
| "ct": [22, 1, 1, 19, 25, 9, 2, 19, 15, 6, 0, 27, 19, 26, 25, 9, 29, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 633, | |
| "comment": "y = 1 and a = 0 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "ca26acbda16d877a3e", | |
| "msg": [3, 4, 16, 21, 31, 21, 21, 8, 7, 31, 6, 25, 26, 22, 1, 20, 12, 11], | |
| "ct": [4, 30, 13, 7, 26, 14, 23, 3, 18, 0, 0, 0, 0, 0, 0, 0, 0, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 634, | |
| "comment": "y = 1 and a = 1 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "ca26acbda16d877a3e", | |
| "msg": [25, 1, 23, 2, 20, 8, 16, 16, 10, 18, 24, 25, 20, 28, 11, 1, 10, 2], | |
| "ct": [4, 30, 13, 7, 26, 14, 23, 3, 18, 0, 0, 0, 0, 0, 0, 0, 0, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 635, | |
| "comment": "y = 1 and a has large Hamming weight in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "ca26acbda16d877a3e", | |
| "msg": [25, 2, 14, 16, 31, 23, 2, 2, 29, 10, 29, 12, 25, 10, 9, 21, 2, 22], | |
| "ct": [4, 30, 13, 7, 26, 14, 23, 3, 18, 16, 0, 0, 0, 0, 0, 0, 0, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 636, | |
| "comment": "y = 1 and (y + a) % radix**9 is maximal in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "ca26acbda16d877a3e", | |
| "msg": [20, 11, 14, 18, 16, 3, 21, 2, 7, 3, 15, 6, 14, 24, 19, 1, 0, 26], | |
| "ct": [4, 30, 13, 7, 26, 14, 23, 3, 18, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 637, | |
| "comment": "y = 1 and (y + a) % radix**9 == 0 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "ca26acbda16d877a3e", | |
| "msg": [2, 26, 2, 9, 25, 31, 9, 30, 14, 3, 4, 9, 3, 0, 19, 31, 22, 20], | |
| "ct": [4, 30, 13, 7, 26, 14, 23, 3, 18, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 638, | |
| "comment": "y is maximal and (y + a) % radix**9 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "2ea2e4274d483f0d75", | |
| "msg": [29, 30, 20, 0, 9, 12, 28, 11, 2, 22, 7, 23, 0, 27, 15, 13, 14, 18], | |
| "ct": [30, 28, 10, 17, 22, 9, 2, 25, 0, 24, 27, 25, 22, 17, 6, 16, 8, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 639, | |
| "comment": "y is maximal and (y + a) % radix**9 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "2ea2e4274d483f0d75", | |
| "msg": [6, 9, 23, 22, 1, 29, 10, 20, 25, 7, 27, 17, 7, 21, 22, 23, 4, 29], | |
| "ct": [14, 22, 16, 21, 13, 22, 9, 11, 30, 12, 5, 10, 24, 16, 28, 10, 5, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 640, | |
| "comment": "y is maximal and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "2ea2e4274d483f0d75", | |
| "msg": [11, 17, 31, 22, 20, 26, 1, 9, 4, 30, 22, 31, 4, 1, 14, 15, 31, 31], | |
| "ct": [29, 23, 27, 5, 3, 10, 5, 24, 29, 2, 15, 29, 31, 23, 19, 13, 21, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 641, | |
| "comment": "y is maximal and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "2ea2e4274d483f0d75", | |
| "msg": [23, 5, 6, 11, 14, 1, 19, 14, 4, 23, 21, 22, 17, 25, 23, 18, 4, 1], | |
| "ct": [30, 29, 28, 7, 8, 23, 31, 16, 12, 10, 6, 17, 3, 6, 13, 20, 1, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 642, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "81cbed0465832557bd", | |
| "msg": [11, 30, 20, 19, 2, 15, 8, 1, 18, 4, 28, 1, 26, 19, 2, 28, 9, 24], | |
| "ct": [8, 22, 13, 10, 13, 26, 6, 6, 23, 19, 10, 6, 2, 16, 8, 29, 30, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 643, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "81cbed0465832557bd", | |
| "msg": [15, 3, 8, 13, 15, 22, 1, 14, 7, 13, 20, 30, 25, 18, 16, 5, 13, 26], | |
| "ct": [24, 15, 21, 31, 1, 23, 20, 26, 30, 3, 6, 25, 27, 26, 15, 31, 13, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 644, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**9 is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "81cbed0465832557bd", | |
| "msg": [9, 27, 25, 0, 26, 23, 30, 9, 1, 2, 13, 27, 8, 2, 12, 4, 20, 30], | |
| "ct": [28, 16, 31, 15, 6, 24, 16, 14, 4, 29, 16, 21, 28, 17, 31, 19, 30, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 645, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**9 == 0 in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "81cbed0465832557bd", | |
| "msg": [14, 18, 16, 25, 21, 2, 3, 23, 10, 24, 20, 1, 10, 19, 28, 27, 7, 23], | |
| "ct": [25, 20, 21, 15, 13, 9, 13, 0, 14, 19, 7, 31, 1, 8, 26, 31, 8, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 646, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "81cbed0465832557bd", | |
| "msg": [21, 1, 22, 18, 13, 2, 25, 20, 6, 7, 18, 19, 18, 23, 18, 15, 28, 4], | |
| "ct": [31, 12, 25, 3, 20, 7, 12, 22, 26, 1, 17, 28, 13, 7, 21, 17, 28, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 647, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 5", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "81cbed0465832557bd", | |
| "msg": [30, 11, 6, 1, 11, 24, 14, 30, 14, 21, 30, 22, 24, 7, 13, 29, 1, 11], | |
| "ct": [11, 2, 18, 3, 21, 28, 28, 4, 27, 20, 31, 29, 18, 15, 14, 8, 26, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 648, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**9 is maximal in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "389d8a48c546218ae8", | |
| "msg": [11, 21, 10, 3, 20, 19, 5, 20, 16, 29, 11, 23, 0, 15, 30, 14, 13, 22], | |
| "ct": [17, 16, 31, 28, 26, 11, 6, 13, 20, 8, 17, 24, 9, 30, 22, 10, 22, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 649, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**9 == 0 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "389d8a48c546218ae8", | |
| "msg": [10, 11, 4, 28, 7, 12, 7, 6, 11, 0, 24, 16, 20, 14, 10, 10, 29, 7], | |
| "ct": [7, 10, 4, 2, 23, 8, 6, 3, 2, 8, 13, 2, 1, 31, 25, 11, 28, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 650, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "389d8a48c546218ae8", | |
| "msg": [0, 5, 8, 31, 28, 25, 18, 9, 8, 12, 22, 11, 5, 7, 29, 4, 12, 24], | |
| "ct": [20, 7, 7, 19, 30, 27, 26, 18, 5, 29, 4, 6, 19, 10, 21, 9, 20, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 651, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "93f59a2f91ad3ca69e10b50b2ada2f7f", | |
| "tweak": "389d8a48c546218ae8", | |
| "msg": [5, 27, 5, 25, 15, 31, 11, 7, 5, 15, 23, 2, 27, 1, 28, 1, 3, 14], | |
| "ct": [25, 14, 8, 9, 24, 16, 8, 16, 11, 30, 29, 30, 12, 10, 13, 7, 22, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 652, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8f3a40ed121d763ce94121d1a884ac4f", | |
| "tweak": "5e37cf940f79d378", | |
| "msg": [-1, 27, 17, 16, 30, 13, 8, 8, 30, 19, 29, 8, 8, 6, 9, 13, 23, 21], | |
| "ct": [30, 12, 28, 21, 23, 29, 21, 22, 24, 13, 23, 27, 1, 5, 10, 13, 19, 30], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 653, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8f3a40ed121d763ce94121d1a884ac4f", | |
| "tweak": "5e37cf940f79d378", | |
| "msg": [19, 27, 17, 16, 30, 13, -1, 8, 30, 19, 29, 8, 8, 6, 9, 13, 23, 21], | |
| "ct": [3, 5, 7, 20, 18, 12, 23, 25, 1, 18, 24, 4, 25, 9, 19, 24, 12, 9], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 654, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "8f3a40ed121d763ce94121d1a884ac4f", | |
| "tweak": "5e37cf940f79d378", | |
| "msg": [19, 27, 17, 16, 30, 13, 8, 8, 30, 19, 29, 8, 8, 6, 9, 13, 23, -1], | |
| "ct": [28, 30, 16, 20, 0, 16, 7, 20, 5, 12, 7, 15, 3, 1, 1, 6, 13, 24], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 655, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b7cb5c7a2a0ec341f49ce40e9e8fd48a", | |
| "tweak": "8a7bed58ddbcd297", | |
| "msg": [32, 19, 16, 31, 11, 6, 4, 17, 31, 28, 28, 30, 1, 20, 20, 11, 25, 29], | |
| "ct": [0, 11, 0, 31, 14, 26, 17, 2, 3, 27, 17, 17, 31, 26, 17, 30, 12, 24], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 656, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b7cb5c7a2a0ec341f49ce40e9e8fd48a", | |
| "tweak": "8a7bed58ddbcd297", | |
| "msg": [22, 19, 16, 31, 11, 6, 32, 17, 31, 28, 28, 30, 1, 20, 20, 11, 25, 29], | |
| "ct": [9, 5, 8, 0, 16, 0, 11, 10, 13, 26, 1, 22, 2, 31, 8, 7, 13, 14], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 657, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b7cb5c7a2a0ec341f49ce40e9e8fd48a", | |
| "tweak": "8a7bed58ddbcd297", | |
| "msg": [22, 19, 16, 31, 11, 6, 4, 17, 31, 28, 28, 30, 1, 20, 20, 11, 25, 32], | |
| "ct": [9, 27, 7, 16, 26, 15, 30, 20, 0, 30, 12, 17, 17, 9, 18, 5, 9, 24], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 19, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 658, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "3591cc97af4a5d1492305f87269ee691", | |
| "tweak": "13786144a50ef10a", | |
| "msg": [28, 19, 13, 1, 25, 7, 29, 15, 25, 11, 10, 12, 16, 30, 20, 19, 10, 17, 10], | |
| "ct": [23, 20, 17, 28, 21, 22, 16, 6, 25, 5, 10, 30, 26, 16, 27, 21, 22, 11, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 659, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [2, 21, 11, 13, 27, 20, 25, 13, 20, 31, 25, 23, 29, 27, 8, 7, 10, 2, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 660, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [29, 5, 6, 31, 5, 15, 17, 26, 28, 23, 15, 8, 25, 9, 19, 28, 4, 21, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 661, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [29, 20, 5, 4, 26, 4, 20, 25, 11, 12, 7, 18, 8, 19, 2, 12, 19, 22, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 662, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [1, 31, 16, 14, 1, 12, 28, 28, 1, 4, 26, 29, 22, 17, 29, 0, 31, 27, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 663, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [25, 6, 10, 25, 5, 4, 6, 31, 14, 23, 18, 1, 6, 23, 10, 17, 1, 29, 16], | |
| "ct": [4, 4, 6, 9, 19, 4, 6, 28, 7, 13, 24, 11, 26, 10, 3, 13, 19, 26, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 664, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [19, 9, 25, 20, 31, 7, 18, 15, 2, 5, 11, 20, 5, 6, 3, 1, 17, 17, 15], | |
| "ct": [29, 0, 18, 29, 13, 31, 14, 11, 1, 31, 13, 1, 9, 24, 28, 9, 29, 28, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 665, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [18, 2, 21, 9, 14, 4, 9, 28, 12, 28, 26, 31, 19, 22, 9, 27, 26, 3, 21], | |
| "ct": [2, 20, 13, 13, 15, 26, 12, 12, 12, 24, 22, 9, 9, 15, 10, 15, 4, 0, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 666, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [22, 22, 1, 9, 9, 23, 16, 0, 9, 7, 3, 13, 9, 11, 15, 29, 31, 28, 25], | |
| "ct": [7, 19, 19, 8, 17, 0, 24, 16, 3, 15, 21, 4, 8, 10, 28, 17, 30, 26, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 667, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [11, 24, 5, 16, 15, 28, 12, 13, 10, 5, 8, 24, 21, 7, 4, 26, 30, 4, 2], | |
| "ct": [31, 0, 10, 6, 15, 21, 24, 29, 6, 3, 14, 27, 14, 17, 17, 14, 23, 24, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 668, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [9, 19, 4, 14, 20, 28, 12, 25, 22, 22, 16, 24, 26, 8, 1, 14, 16, 25, 28], | |
| "ct": [25, 5, 3, 31, 25, 9, 1, 26, 18, 22, 16, 31, 16, 2, 4, 2, 9, 16, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 669, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [24, 4, 10, 2, 11, 7, 25, 31, 5, 10, 17, 18, 18, 20, 10, 25, 29, 25, 20], | |
| "ct": [26, 22, 13, 18, 2, 25, 9, 8, 22, 5, 26, 9, 2, 17, 30, 26, 21, 19, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 670, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [6, 24, 30, 26, 10, 12, 5, 22, 6, 22, 0, 20, 10, 31, 1, 25, 5, 26, 3], | |
| "ct": [28, 13, 5, 7, 19, 12, 21, 24, 3, 27, 28, 3, 0, 30, 20, 18, 5, 6, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 671, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [21, 16, 16, 24, 27, 0, 26, 9, 25, 5, 14, 19, 24, 27, 16, 23, 25, 6, 6], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 672, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [12, 27, 27, 29, 29, 0, 16, 19, 14, 14, 25, 27, 2, 19, 9, 30, 21, 25, 14], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 673, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [11, 21, 9, 10, 5, 5, 15, 6, 11, 19, 28, 24, 29, 29, 12, 22, 12, 11, 14], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 674, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "cd031dce5e1bca3a7e04c997ac13ef2d", | |
| "tweak": "3d906a02e77bcc5c", | |
| "msg": [22, 29, 31, 3, 31, 20, 2, 26, 13, 7, 22, 29, 16, 28, 0, 29, 18, 4, 27], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 675, | |
| "comment": "y = 1 and a = 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "5157dd4a5507b6cc", | |
| "msg": [18, 1, 19, 26, 4, 4, 25, 17, 12, 4, 2, 16, 11, 17, 18, 3, 1, 14, 25], | |
| "ct": [3, 14, 15, 26, 15, 2, 10, 8, 29, 8, 20, 26, 4, 21, 19, 30, 25, 30, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 676, | |
| "comment": "y = 1 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "5157dd4a5507b6cc", | |
| "msg": [23, 0, 1, 18, 13, 8, 16, 20, 26, 2, 19, 3, 15, 22, 28, 6, 8, 5, 29], | |
| "ct": [25, 10, 25, 29, 5, 0, 20, 2, 7, 10, 11, 24, 9, 13, 28, 5, 3, 4, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 677, | |
| "comment": "y = 1 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "5157dd4a5507b6cc", | |
| "msg": [29, 30, 6, 19, 11, 23, 30, 30, 14, 30, 25, 20, 3, 0, 5, 26, 3, 23, 1], | |
| "ct": [10, 10, 1, 23, 24, 6, 1, 0, 18, 12, 3, 25, 13, 17, 21, 12, 12, 1, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 678, | |
| "comment": "y = 1 and (y + a) % radix**9 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "5157dd4a5507b6cc", | |
| "msg": [30, 23, 26, 15, 24, 16, 8, 21, 24, 4, 1, 21, 5, 7, 12, 30, 18, 5, 17], | |
| "ct": [25, 4, 4, 10, 23, 13, 16, 3, 24, 10, 25, 16, 23, 20, 27, 6, 12, 25, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 679, | |
| "comment": "y = 1 and (y + a) % radix**9 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "5157dd4a5507b6cc", | |
| "msg": [11, 29, 2, 4, 11, 30, 0, 25, 1, 5, 30, 15, 12, 7, 1, 19, 21, 27, 14], | |
| "ct": [14, 6, 25, 1, 0, 3, 10, 10, 5, 15, 21, 3, 16, 28, 16, 22, 3, 9, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 680, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "02e1ee0a623bf947", | |
| "msg": [23, 14, 0, 27, 12, 31, 9, 13, 26, 30, 23, 25, 23, 8, 2, 10, 31, 21, 20], | |
| "ct": [18, 20, 17, 0, 25, 17, 12, 23, 22, 28, 15, 27, 24, 1, 17, 23, 24, 20, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 681, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "02e1ee0a623bf947", | |
| "msg": [17, 20, 5, 31, 6, 17, 13, 3, 0, 31, 26, 16, 31, 24, 30, 23, 12, 27, 17], | |
| "ct": [7, 3, 4, 25, 12, 4, 26, 21, 24, 13, 21, 14, 0, 7, 0, 24, 5, 2, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 682, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**9 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "02e1ee0a623bf947", | |
| "msg": [31, 26, 30, 22, 11, 9, 14, 16, 27, 13, 21, 10, 2, 0, 26, 20, 30, 3, 4], | |
| "ct": [11, 28, 22, 16, 31, 0, 25, 31, 22, 27, 30, 21, 22, 16, 5, 19, 30, 9, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 683, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**9 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "02e1ee0a623bf947", | |
| "msg": [6, 18, 19, 2, 15, 23, 6, 11, 4, 8, 15, 13, 29, 2, 13, 28, 15, 5, 3], | |
| "ct": [10, 4, 16, 19, 28, 14, 7, 13, 23, 18, 0, 11, 4, 29, 17, 15, 16, 3, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 684, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "02e1ee0a623bf947", | |
| "msg": [12, 0, 6, 17, 7, 16, 4, 27, 7, 5, 26, 29, 26, 20, 27, 20, 5, 31, 14], | |
| "ct": [4, 23, 28, 12, 1, 11, 8, 3, 13, 29, 18, 2, 29, 28, 17, 31, 7, 3, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 685, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "02e1ee0a623bf947", | |
| "msg": [24, 11, 18, 6, 5, 20, 1, 20, 20, 31, 30, 13, 1, 0, 10, 2, 13, 18, 11], | |
| "ct": [12, 15, 6, 2, 19, 1, 15, 13, 3, 15, 27, 17, 16, 11, 23, 9, 7, 4, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 686, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**10 is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "e8bf7aa5c5eba8fb", | |
| "msg": [3, 18, 5, 1, 2, 1, 27, 26, 4, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [18, 24, 28, 18, 6, 29, 31, 6, 5, 15, 11, 20, 3, 14, 26, 11, 13, 12, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 687, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**10 == 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "e8bf7aa5c5eba8fb", | |
| "msg": [14, 28, 10, 13, 19, 13, 1, 1, 29, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1], | |
| "ct": [21, 24, 10, 20, 18, 5, 24, 25, 0, 1, 26, 6, 8, 7, 8, 23, 13, 2, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 688, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "e8bf7aa5c5eba8fb", | |
| "msg": [27, 11, 11, 22, 19, 14, 30, 3, 7, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [30, 12, 0, 11, 11, 21, 30, 8, 11, 26, 15, 30, 30, 21, 11, 0, 4, 3, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 689, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "522debdfba3b6828bb97848da895884a", | |
| "tweak": "e8bf7aa5c5eba8fb", | |
| "msg": [8, 16, 30, 9, 29, 28, 5, 22, 29, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [15, 1, 11, 16, 5, 16, 26, 7, 10, 15, 1, 17, 14, 11, 0, 8, 8, 4, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 690, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "1cf89329cac719e6c7544a9303e78801", | |
| "tweak": "169faf154b10cac4", | |
| "msg": [-1, 31, 30, 1, 12, 5, 24, 30, 25, 31, 1, 15, 7, 24, 27, 11, 30, 2, 11], | |
| "ct": [9, 30, 14, 23, 1, 17, 27, 21, 24, 27, 5, 26, 19, 23, 14, 0, 0, 6, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 691, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "1cf89329cac719e6c7544a9303e78801", | |
| "tweak": "169faf154b10cac4", | |
| "msg": [2, 31, 30, 1, 12, 5, -1, 30, 25, 31, 1, 15, 7, 24, 27, 11, 30, 2, 11], | |
| "ct": [2, 28, 6, 16, 24, 18, 15, 27, 20, 29, 5, 25, 31, 13, 16, 19, 5, 0, 25], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 692, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "1cf89329cac719e6c7544a9303e78801", | |
| "tweak": "169faf154b10cac4", | |
| "msg": [2, 31, 30, 1, 12, 5, 24, 30, 25, 31, 1, 15, 7, 24, 27, 11, 30, 2, -1], | |
| "ct": [24, 30, 26, 27, 19, 24, 23, 3, 8, 20, 0, 19, 3, 21, 18, 3, 11, 8, 2], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 693, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "fa45ad4cb694fbf5094352a7196faee4", | |
| "tweak": "69208fe63aad0b36", | |
| "msg": [32, 25, 31, 12, 0, 2, 2, 1, 13, 21, 20, 1, 20, 21, 28, 9, 15, 11, 3], | |
| "ct": [4, 24, 1, 8, 20, 12, 12, 18, 26, 19, 25, 29, 24, 19, 10, 4, 31, 1, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 694, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "fa45ad4cb694fbf5094352a7196faee4", | |
| "tweak": "69208fe63aad0b36", | |
| "msg": [20, 25, 31, 12, 0, 2, 32, 1, 13, 21, 20, 1, 20, 21, 28, 9, 15, 11, 3], | |
| "ct": [22, 21, 0, 10, 28, 23, 16, 13, 27, 12, 18, 4, 10, 0, 6, 0, 29, 31, 27], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 695, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "fa45ad4cb694fbf5094352a7196faee4", | |
| "tweak": "69208fe63aad0b36", | |
| "msg": [20, 25, 31, 12, 0, 2, 2, 1, 13, 21, 20, 1, 20, 21, 28, 9, 15, 11, 32], | |
| "ct": [7, 7, 1, 27, 29, 1, 20, 20, 7, 25, 28, 21, 22, 13, 7, 25, 6, 30, 26], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 20, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 696, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "ccdf8f792a48fd841d49e060315b0c3d", | |
| "tweak": "508c6ff22207dc5b", | |
| "msg": [29, 17, 10, 24, 27, 16, 24, 1, 12, 31, 19, 13, 19, 20, 28, 27, 27, 26, 0, 29], | |
| "ct": [26, 11, 10, 31, 10, 26, 13, 5, 1, 4, 6, 21, 12, 30, 13, 5, 3, 11, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 697, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [21, 0, 14, 25, 20, 4, 31, 10, 24, 26, 8, 16, 17, 21, 23, 27, 6, 11, 6, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 698, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [15, 2, 12, 11, 9, 13, 10, 11, 5, 26, 12, 14, 4, 18, 11, 24, 25, 24, 1, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 699, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [21, 5, 19, 20, 6, 21, 8, 0, 29, 9, 22, 0, 4, 13, 18, 3, 9, 30, 26, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 700, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [24, 6, 8, 14, 30, 1, 0, 29, 10, 1, 3, 15, 5, 28, 23, 28, 14, 3, 30, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 701, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [20, 26, 28, 22, 31, 15, 24, 13, 1, 30, 30, 3, 10, 2, 18, 11, 20, 12, 8, 7], | |
| "ct": [5, 12, 23, 7, 13, 26, 2, 13, 17, 4, 20, 20, 26, 31, 29, 2, 3, 19, 29, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 702, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [10, 20, 23, 18, 28, 18, 1, 19, 19, 15, 12, 8, 20, 0, 15, 9, 4, 21, 6, 12], | |
| "ct": [21, 24, 25, 17, 6, 27, 4, 13, 23, 29, 17, 25, 6, 28, 19, 1, 10, 26, 19, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 703, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [15, 4, 24, 10, 28, 1, 5, 20, 23, 30, 22, 19, 28, 12, 4, 7, 15, 20, 21, 16], | |
| "ct": [21, 29, 18, 20, 12, 29, 30, 13, 26, 30, 29, 13, 28, 31, 0, 20, 3, 30, 15, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 704, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [1, 23, 5, 26, 27, 17, 17, 6, 16, 2, 9, 9, 6, 9, 17, 26, 14, 28, 28, 5], | |
| "ct": [9, 25, 24, 12, 21, 13, 6, 1, 18, 22, 7, 13, 0, 17, 2, 12, 19, 24, 6, 28], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 705, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [16, 19, 16, 0, 18, 13, 12, 1, 6, 5, 22, 18, 3, 30, 25, 25, 3, 7, 30, 28], | |
| "ct": [30, 31, 27, 27, 31, 11, 0, 12, 22, 22, 26, 26, 27, 24, 7, 4, 9, 6, 27, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 706, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [30, 22, 29, 10, 1, 0, 11, 20, 19, 21, 18, 17, 14, 18, 29, 17, 18, 30, 26, 17], | |
| "ct": [22, 25, 20, 11, 18, 7, 21, 7, 22, 30, 9, 12, 19, 0, 23, 23, 20, 3, 13, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 707, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [8, 20, 29, 21, 19, 28, 8, 20, 28, 30, 31, 14, 12, 10, 0, 10, 0, 13, 15, 0], | |
| "ct": [26, 19, 8, 0, 23, 15, 22, 14, 11, 9, 5, 19, 6, 13, 17, 8, 2, 9, 22, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 708, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [7, 24, 10, 5, 31, 10, 13, 31, 22, 14, 29, 28, 31, 14, 0, 24, 26, 17, 20, 14], | |
| "ct": [6, 19, 3, 28, 17, 20, 17, 4, 6, 21, 23, 6, 8, 7, 11, 3, 9, 24, 31, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 709, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [28, 19, 25, 16, 9, 1, 3, 25, 17, 27, 2, 13, 13, 27, 24, 23, 30, 8, 22, 19], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 710, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [17, 13, 6, 30, 3, 10, 15, 24, 24, 25, 25, 27, 22, 18, 15, 23, 31, 16, 1, 26], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 711, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [18, 21, 30, 23, 24, 10, 6, 13, 21, 0, 6, 1, 30, 0, 3, 17, 25, 27, 1, 19], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 712, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "e957b00cf440abed5e9a5d06cd5f5cdb", | |
| "tweak": "f6fa77d46df38c3b", | |
| "msg": [22, 18, 30, 8, 31, 22, 16, 19, 16, 4, 31, 5, 30, 0, 0, 4, 14, 0, 19, 24], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 713, | |
| "comment": "y = 0 and (y + a) % radix**10 == 0 in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "aca6a23b0461a482", | |
| "msg": [9, 9, 30, 12, 11, 9, 30, 18, 25, 22, 4, 27, 3, 3, 3, 16, 1, 4, 0, 11], | |
| "ct": [6, 31, 0, 6, 17, 18, 3, 14, 17, 18, 17, 12, 6, 7, 0, 7, 7, 18, 10, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 714, | |
| "comment": "y = 0 and a = 1 in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "aca6a23b0461a482", | |
| "msg": [4, 21, 23, 31, 31, 31, 14, 1, 21, 13, 4, 31, 15, 22, 6, 1, 15, 2, 19, 17], | |
| "ct": [16, 29, 26, 13, 2, 17, 31, 24, 18, 18, 28, 8, 22, 20, 2, 22, 15, 14, 24, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 715, | |
| "comment": "y = 0 and a has large Hamming weight in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "aca6a23b0461a482", | |
| "msg": [9, 2, 7, 0, 27, 30, 3, 10, 31, 17, 2, 25, 22, 13, 12, 5, 29, 16, 30, 28], | |
| "ct": [16, 25, 23, 16, 5, 14, 28, 13, 26, 19, 10, 21, 4, 10, 22, 4, 31, 2, 19, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 716, | |
| "comment": "y = 0 and (y + a) % radix**10 is maximal in round 7", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "aca6a23b0461a482", | |
| "msg": [0, 13, 22, 19, 16, 13, 25, 1, 24, 1, 20, 18, 26, 3, 15, 14, 0, 8, 29, 26], | |
| "ct": [9, 17, 20, 22, 19, 12, 11, 16, 17, 21, 25, 18, 17, 29, 23, 25, 15, 21, 25, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 717, | |
| "comment": "y is maximal and (y + a) % radix**10 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "deb291b0b76a770a", | |
| "msg": [11, 7, 26, 29, 13, 12, 28, 31, 15, 22, 16, 21, 25, 16, 16, 20, 22, 11, 5, 13], | |
| "ct": [29, 13, 6, 30, 11, 28, 25, 22, 23, 28, 11, 13, 11, 23, 5, 0, 28, 23, 31, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 718, | |
| "comment": "y is maximal and (y + a) % radix**10 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "deb291b0b76a770a", | |
| "msg": [25, 29, 9, 13, 22, 11, 19, 18, 25, 15, 21, 19, 29, 10, 18, 22, 6, 17, 1, 14], | |
| "ct": [27, 3, 25, 4, 14, 5, 14, 28, 24, 17, 16, 9, 5, 1, 28, 13, 10, 5, 27, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 719, | |
| "comment": "y is maximal and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "deb291b0b76a770a", | |
| "msg": [28, 15, 23, 23, 10, 28, 0, 18, 27, 30, 14, 23, 11, 5, 27, 26, 26, 18, 22, 22], | |
| "ct": [21, 5, 1, 2, 12, 16, 25, 22, 7, 23, 20, 18, 20, 18, 24, 2, 14, 31, 2, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 720, | |
| "comment": "y is maximal and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "deb291b0b76a770a", | |
| "msg": [25, 23, 20, 2, 10, 29, 29, 28, 17, 6, 9, 8, 28, 16, 26, 31, 15, 31, 16, 13], | |
| "ct": [4, 27, 24, 27, 11, 31, 20, 11, 13, 30, 0, 28, 19, 30, 17, 18, 2, 7, 30, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 721, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "fd14496fc1f91eab", | |
| "msg": [15, 7, 25, 23, 5, 23, 7, 20, 19, 22, 11, 4, 4, 14, 2, 29, 4, 22, 9, 26], | |
| "ct": [12, 29, 19, 1, 18, 13, 27, 1, 20, 20, 3, 10, 4, 30, 23, 4, 14, 24, 19, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 722, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "fd14496fc1f91eab", | |
| "msg": [12, 18, 14, 17, 5, 27, 23, 9, 6, 5, 17, 26, 20, 15, 17, 8, 11, 23, 18, 19], | |
| "ct": [24, 28, 23, 16, 12, 0, 2, 15, 0, 17, 10, 23, 26, 15, 20, 26, 21, 30, 10, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 723, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**10 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "fd14496fc1f91eab", | |
| "msg": [30, 26, 24, 27, 5, 1, 14, 15, 2, 6, 15, 29, 3, 28, 3, 16, 26, 24, 27, 25], | |
| "ct": [13, 1, 12, 8, 28, 17, 12, 12, 30, 30, 21, 9, 13, 7, 1, 16, 9, 17, 13, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 724, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**10 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "fd14496fc1f91eab", | |
| "msg": [17, 27, 1, 15, 27, 30, 4, 27, 19, 21, 15, 31, 12, 8, 29, 16, 17, 8, 20, 17], | |
| "ct": [15, 0, 0, 1, 14, 10, 15, 17, 6, 6, 9, 9, 30, 15, 10, 27, 17, 6, 2, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 725, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "fd14496fc1f91eab", | |
| "msg": [25, 15, 5, 0, 4, 26, 28, 24, 7, 12, 13, 26, 26, 12, 26, 7, 24, 2, 17, 31], | |
| "ct": [7, 27, 18, 26, 16, 9, 3, 12, 19, 3, 22, 21, 30, 27, 12, 5, 11, 31, 0, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 726, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "541d381b9f5c1e6ae2cc1b92e7c7e5e3", | |
| "tweak": "fd14496fc1f91eab", | |
| "msg": [28, 30, 11, 19, 18, 13, 17, 17, 8, 23, 25, 19, 2, 12, 29, 26, 8, 23, 12, 28], | |
| "ct": [16, 28, 17, 27, 19, 22, 20, 26, 5, 17, 19, 29, 5, 10, 2, 18, 19, 31, 25, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 727, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "4e8c0fdab138c9df8d4a888e6c2df1dd", | |
| "tweak": "76f494b34dbcd3bc", | |
| "msg": [-1, 17, 4, 25, 30, 4, 28, 12, 4, 21, 25, 7, 9, 4, 11, 8, 12, 10, 14, 27], | |
| "ct": [10, 9, 9, 3, 24, 4, 4, 10, 6, 8, 16, 8, 31, 6, 18, 25, 16, 8, 19, 5], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 728, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "4e8c0fdab138c9df8d4a888e6c2df1dd", | |
| "tweak": "76f494b34dbcd3bc", | |
| "msg": [7, 17, 4, 25, 30, 4, -1, 12, 4, 21, 25, 7, 9, 4, 11, 8, 12, 10, 14, 27], | |
| "ct": [4, 18, 16, 31, 7, 5, 16, 4, 25, 15, 29, 21, 11, 4, 26, 16, 11, 30, 12, 13], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 729, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "4e8c0fdab138c9df8d4a888e6c2df1dd", | |
| "tweak": "76f494b34dbcd3bc", | |
| "msg": [7, 17, 4, 25, 30, 4, 28, 12, 4, 21, 25, 7, 9, 4, 11, 8, 12, 10, 14, -1], | |
| "ct": [18, 29, 25, 6, 12, 14, 20, 23, 13, 12, 24, 18, 6, 10, 20, 12, 14, 11, 28, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 730, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "3753ce1de8190b30c81806920cd300d8", | |
| "tweak": "cb360070e7e4a47d", | |
| "msg": [32, 11, 31, 29, 17, 3, 5, 12, 17, 31, 0, 5, 21, 1, 20, 16, 5, 11, 8, 11], | |
| "ct": [26, 25, 6, 17, 17, 10, 1, 31, 31, 18, 10, 29, 12, 11, 14, 25, 20, 9, 19, 23], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 731, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "3753ce1de8190b30c81806920cd300d8", | |
| "tweak": "cb360070e7e4a47d", | |
| "msg": [8, 11, 31, 29, 17, 3, 32, 12, 17, 31, 0, 5, 21, 1, 20, 16, 5, 11, 8, 11], | |
| "ct": [28, 30, 19, 6, 24, 24, 17, 0, 15, 22, 27, 26, 21, 25, 11, 3, 13, 14, 13, 11], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 732, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "3753ce1de8190b30c81806920cd300d8", | |
| "tweak": "cb360070e7e4a47d", | |
| "msg": [8, 11, 31, 29, 17, 3, 5, 12, 17, 31, 0, 5, 21, 1, 20, 16, 5, 11, 8, 32], | |
| "ct": [9, 18, 11, 20, 16, 17, 8, 15, 15, 22, 3, 18, 16, 7, 1, 24, 9, 27, 24, 17], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 21, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 733, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "c0e4c4a9b86c17e4efe9a12733e7aff4", | |
| "tweak": "f71b48c8172125d4", | |
| "msg": [0, 29, 27, 28, 20, 27, 2, 5, 30, 13, 10, 2, 20, 13, 28, 11, 10, 15, 16, 24, 4], | |
| "ct": [24, 19, 17, 24, 22, 31, 28, 13, 9, 21, 30, 24, 10, 9, 13, 4, 12, 14, 11, 7, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 734, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [12, 10, 18, 11, 29, 13, 8, 3, 1, 25, 25, 23, 14, 22, 22, 22, 1, 4, 1, 28, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 735, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [3, 4, 12, 17, 31, 7, 8, 29, 23, 17, 19, 30, 27, 12, 18, 8, 5, 16, 13, 0, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 736, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [5, 3, 12, 26, 21, 12, 5, 0, 7, 3, 11, 18, 14, 8, 6, 7, 6, 17, 6, 12, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 737, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [19, 14, 2, 1, 17, 24, 16, 21, 18, 28, 1, 8, 28, 24, 12, 22, 27, 27, 29, 7, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 738, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [8, 0, 18, 18, 15, 18, 13, 13, 10, 21, 13, 25, 7, 10, 2, 11, 29, 15, 18, 8, 9], | |
| "ct": [15, 26, 28, 12, 25, 19, 11, 8, 1, 24, 27, 25, 19, 19, 4, 19, 23, 12, 25, 11, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 739, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [12, 23, 4, 23, 29, 24, 30, 28, 26, 3, 10, 15, 29, 22, 3, 27, 1, 24, 3, 12, 10], | |
| "ct": [30, 29, 18, 30, 13, 28, 5, 14, 30, 18, 6, 17, 2, 8, 11, 8, 20, 6, 24, 14, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 740, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [27, 15, 31, 6, 7, 17, 13, 21, 28, 29, 25, 7, 30, 3, 22, 18, 20, 13, 15, 21, 5], | |
| "ct": [3, 10, 27, 12, 18, 10, 15, 4, 19, 8, 16, 26, 12, 2, 21, 26, 23, 13, 18, 3, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 741, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [14, 18, 10, 1, 22, 23, 6, 12, 1, 15, 4, 8, 25, 8, 24, 2, 8, 2, 27, 10, 14], | |
| "ct": [20, 19, 28, 27, 3, 20, 12, 14, 19, 20, 9, 22, 13, 26, 27, 12, 15, 2, 25, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 742, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [8, 22, 14, 13, 12, 11, 10, 25, 30, 2, 5, 20, 29, 10, 16, 10, 26, 17, 3, 31, 10], | |
| "ct": [22, 10, 18, 0, 30, 0, 23, 29, 9, 2, 9, 9, 30, 7, 31, 1, 17, 26, 11, 31, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 743, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [3, 25, 24, 26, 10, 5, 26, 0, 27, 25, 22, 1, 1, 30, 11, 1, 0, 13, 31, 16, 18], | |
| "ct": [11, 29, 0, 17, 14, 24, 30, 30, 17, 15, 13, 25, 19, 3, 14, 14, 15, 25, 22, 7, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 744, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [0, 24, 16, 15, 10, 31, 26, 20, 18, 11, 11, 15, 16, 9, 22, 21, 0, 14, 1, 27, 19], | |
| "ct": [17, 24, 21, 13, 18, 10, 24, 15, 19, 31, 8, 11, 16, 13, 21, 25, 14, 8, 5, 13, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 745, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [2, 7, 24, 16, 18, 13, 10, 21, 17, 20, 24, 7, 30, 7, 14, 8, 31, 27, 31, 31, 26], | |
| "ct": [20, 29, 22, 16, 3, 30, 24, 22, 17, 25, 23, 0, 3, 19, 12, 23, 29, 11, 5, 23, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 746, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [31, 14, 3, 9, 13, 19, 11, 6, 9, 16, 21, 19, 11, 16, 29, 7, 8, 23, 9, 12, 7], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 747, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [15, 19, 6, 9, 22, 23, 16, 23, 14, 14, 16, 9, 22, 21, 11, 29, 24, 29, 30, 17, 0], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 748, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [15, 1, 10, 17, 15, 2, 21, 30, 21, 15, 16, 13, 27, 5, 11, 26, 27, 2, 16, 29, 0], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 749, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "25d4448872edf13aa8be04f271b3568c", | |
| "tweak": "e243d35dba4fcc44", | |
| "msg": [0, 14, 2, 21, 8, 22, 11, 7, 8, 29, 2, 15, 11, 0, 1, 26, 29, 1, 17, 9, 31], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 750, | |
| "comment": "y = 0 and (y + a) % radix**10 == 0 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "24743849568086a5", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 22, 2, 9, 23, 26, 30, 13, 21, 23, 10, 20], | |
| "ct": [17, 10, 27, 10, 21, 7, 29, 28, 18, 24, 5, 30, 27, 3, 13, 20, 8, 0, 9, 14, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 751, | |
| "comment": "y = 0 and a = 1 in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "24743849568086a5", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 1, 22, 2, 9, 23, 26, 30, 13, 21, 23, 10, 20], | |
| "ct": [9, 20, 23, 4, 25, 8, 21, 31, 16, 19, 6, 5, 21, 16, 28, 11, 5, 12, 2, 6, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 752, | |
| "comment": "y = 0 and a has large Hamming weight in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "24743849568086a5", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 22, 2, 9, 23, 26, 30, 13, 21, 23, 10, 20], | |
| "ct": [13, 21, 24, 30, 23, 18, 28, 0, 12, 19, 13, 10, 30, 31, 23, 13, 27, 2, 26, 7, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 753, | |
| "comment": "y = 0 and (y + a) % radix**10 is maximal in round 0", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "24743849568086a5", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 22, 2, 9, 23, 26, 30, 13, 21, 23, 10, 20], | |
| "ct": [18, 30, 29, 24, 5, 21, 12, 23, 30, 6, 12, 29, 0, 1, 16, 28, 17, 1, 31, 7, 26], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 754, | |
| "comment": "y = 1 and a = 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "41d3ef67f430168f", | |
| "msg": [26, 29, 31, 9, 29, 23, 6, 11, 21, 5, 3, 6, 4, 20, 5, 4, 23, 25, 19, 3, 1], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 1, 23, 27, 2, 18, 20, 25, 14, 26, 9, 0, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 755, | |
| "comment": "y = 1 and a = 1 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "41d3ef67f430168f", | |
| "msg": [30, 12, 25, 24, 24, 24, 0, 26, 5, 0, 27, 2, 1, 22, 20, 22, 5, 30, 29, 26, 6], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 2, 31, 16, 1, 29, 30, 26, 12, 23, 11, 4, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 756, | |
| "comment": "y = 1 and a has large Hamming weight in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "41d3ef67f430168f", | |
| "msg": [29, 15, 31, 8, 9, 21, 9, 22, 5, 23, 22, 1, 19, 0, 13, 0, 29, 12, 10, 20, 25], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 0, 1, 30, 25, 31, 29, 23, 2, 26, 5, 21, 23, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 757, | |
| "comment": "y = 1 and (y + a) % radix**10 is maximal in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "41d3ef67f430168f", | |
| "msg": [21, 23, 25, 15, 6, 22, 30, 18, 15, 15, 17, 30, 1, 14, 2, 24, 3, 10, 21, 20, 12], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 16, 12, 26, 25, 1, 20, 8, 5, 26, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 758, | |
| "comment": "y = 1 and (y + a) % radix**10 == 0 in round 8", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "41d3ef67f430168f", | |
| "msg": [17, 24, 12, 10, 25, 1, 8, 7, 27, 10, 31, 20, 7, 24, 28, 0, 20, 13, 10, 16, 1], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 27, 24, 18, 8, 28, 9, 12, 2, 6, 0, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 759, | |
| "comment": "y is maximal and (y + a) % radix**10 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "0409533ac936f98d", | |
| "msg": [0, 8, 2, 17, 0, 3, 27, 25, 7, 25, 27, 13, 10, 27, 9, 31, 4, 24, 11, 12, 30], | |
| "ct": [2, 2, 2, 22, 23, 20, 23, 6, 13, 3, 28, 31, 4, 11, 27, 9, 19, 5, 21, 12, 16], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 760, | |
| "comment": "y is maximal and (y + a) % radix**10 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "0409533ac936f98d", | |
| "msg": [15, 18, 25, 0, 4, 21, 10, 13, 30, 10, 18, 28, 22, 10, 31, 15, 0, 7, 26, 13, 16], | |
| "ct": [18, 24, 21, 2, 19, 7, 3, 10, 9, 7, 19, 9, 30, 10, 17, 9, 12, 24, 23, 31, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 761, | |
| "comment": "y is maximal and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "0409533ac936f98d", | |
| "msg": [15, 23, 11, 8, 12, 23, 4, 20, 28, 8, 10, 12, 17, 7, 24, 3, 24, 14, 9, 13, 2], | |
| "ct": [6, 8, 7, 29, 22, 16, 12, 17, 0, 15, 21, 15, 27, 4, 26, 7, 2, 3, 10, 23, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 762, | |
| "comment": "y is maximal and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "0409533ac936f98d", | |
| "msg": [28, 13, 18, 27, 19, 12, 31, 3, 2, 23, 21, 19, 14, 3, 18, 9, 11, 19, 29, 11, 29], | |
| "ct": [22, 31, 11, 22, 19, 24, 15, 31, 7, 20, 30, 27, 2, 17, 19, 19, 28, 15, 28, 11, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 763, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "63ff192825b3b92a", | |
| "msg": [31, 12, 3, 26, 1, 4, 5, 24, 30, 9, 28, 12, 2, 29, 13, 4, 30, 27, 5, 0, 18], | |
| "ct": [14, 6, 22, 12, 28, 18, 11, 3, 19, 2, 23, 28, 9, 6, 12, 7, 6, 18, 22, 13, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 764, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "63ff192825b3b92a", | |
| "msg": [8, 12, 20, 11, 8, 8, 26, 28, 2, 28, 20, 29, 10, 4, 29, 14, 7, 9, 21, 24, 5], | |
| "ct": [4, 24, 18, 17, 26, 1, 3, 8, 26, 13, 23, 18, 23, 22, 10, 17, 26, 3, 26, 10, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 765, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**10 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "63ff192825b3b92a", | |
| "msg": [10, 20, 11, 2, 13, 21, 30, 31, 30, 10, 0, 10, 7, 7, 16, 31, 30, 28, 11, 14, 17], | |
| "ct": [18, 14, 21, 9, 19, 6, 17, 18, 11, 31, 22, 18, 3, 30, 7, 16, 3, 14, 22, 20, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 766, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**10 == 0 in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "63ff192825b3b92a", | |
| "msg": [23, 28, 25, 2, 21, 30, 6, 27, 7, 27, 7, 23, 4, 14, 31, 28, 2, 21, 17, 21, 26], | |
| "ct": [31, 23, 28, 21, 27, 13, 15, 3, 11, 12, 0, 2, 17, 19, 31, 6, 10, 25, 13, 25, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 767, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "63ff192825b3b92a", | |
| "msg": [24, 11, 19, 15, 4, 22, 10, 28, 17, 21, 3, 24, 21, 12, 23, 9, 20, 31, 4, 12, 29], | |
| "ct": [15, 28, 27, 22, 5, 4, 13, 11, 14, 15, 28, 4, 8, 6, 8, 3, 14, 21, 10, 27, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 768, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "63ff192825b3b92a", | |
| "msg": [16, 12, 1, 19, 28, 18, 21, 4, 1, 11, 17, 0, 1, 19, 8, 27, 4, 12, 16, 1, 25], | |
| "ct": [7, 9, 12, 21, 13, 10, 19, 13, 6, 15, 24, 12, 26, 7, 16, 13, 4, 4, 7, 25, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 769, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**10 is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "58e7af18c92e49ec", | |
| "msg": [31, 19, 8, 11, 9, 15, 2, 27, 20, 29, 8, 16, 1, 7, 13, 3, 9, 3, 1, 0, 6], | |
| "ct": [28, 15, 17, 30, 23, 12, 2, 2, 2, 12, 3, 3, 6, 0, 5, 25, 1, 29, 27, 5, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 770, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**10 == 0 in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "58e7af18c92e49ec", | |
| "msg": [31, 26, 24, 5, 12, 17, 5, 5, 10, 26, 3, 23, 13, 5, 5, 12, 5, 31, 12, 20, 2], | |
| "ct": [22, 12, 6, 21, 25, 13, 15, 0, 9, 8, 29, 4, 20, 5, 27, 8, 18, 16, 22, 1, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 771, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "58e7af18c92e49ec", | |
| "msg": [23, 6, 9, 25, 0, 4, 10, 6, 23, 9, 12, 28, 4, 13, 19, 28, 3, 21, 5, 18, 4], | |
| "ct": [9, 24, 15, 3, 21, 18, 21, 31, 20, 1, 30, 6, 26, 20, 28, 5, 23, 3, 29, 5, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 772, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 6", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "54897a7e63855142189bc30a692271dd", | |
| "tweak": "58e7af18c92e49ec", | |
| "msg": [4, 7, 19, 5, 17, 11, 19, 17, 0, 4, 2, 23, 26, 27, 19, 16, 4, 14, 3, 27, 30], | |
| "ct": [9, 23, 23, 25, 11, 10, 5, 13, 3, 29, 10, 9, 27, 25, 25, 2, 21, 9, 22, 30, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 773, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "fd90f1e9599e12563bf788a1a521d6ab", | |
| "tweak": "d0a005b45247f038", | |
| "msg": [-1, 6, 6, 30, 19, 31, 25, 31, 28, 27, 0, 19, 20, 17, 10, 13, 21, 20, 28, 3, 29], | |
| "ct": [25, 16, 17, 11, 29, 23, 10, 15, 24, 11, 17, 3, 24, 23, 14, 27, 3, 3, 7, 27, 10], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 774, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "fd90f1e9599e12563bf788a1a521d6ab", | |
| "tweak": "d0a005b45247f038", | |
| "msg": [5, 6, 6, 30, 19, 31, 25, -1, 28, 27, 0, 19, 20, 17, 10, 13, 21, 20, 28, 3, 29], | |
| "ct": [20, 3, 0, 4, 13, 17, 15, 21, 27, 25, 0, 20, 5, 13, 6, 0, 3, 17, 8, 11, 25], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 775, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "fd90f1e9599e12563bf788a1a521d6ab", | |
| "tweak": "d0a005b45247f038", | |
| "msg": [5, 6, 6, 30, 19, 31, 25, 31, 28, 27, 0, 19, 20, 17, 10, 13, 21, 20, 28, 3, -1], | |
| "ct": [24, 27, 7, 25, 7, 15, 10, 31, 7, 25, 11, 21, 4, 17, 1, 9, 8, 22, 10, 21, 28], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 776, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b0a898a02c207118bf6a389abbd20a0e", | |
| "tweak": "bde37fe366da0c1d", | |
| "msg": [32, 0, 26, 8, 27, 4, 28, 19, 31, 24, 3, 12, 7, 8, 3, 30, 22, 25, 22, 19, 29], | |
| "ct": [11, 16, 31, 29, 6, 28, 23, 5, 17, 15, 27, 15, 5, 13, 27, 8, 27, 4, 22, 25, 15], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 777, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b0a898a02c207118bf6a389abbd20a0e", | |
| "tweak": "bde37fe366da0c1d", | |
| "msg": [24, 0, 26, 8, 27, 4, 28, 32, 31, 24, 3, 12, 7, 8, 3, 30, 22, 25, 22, 19, 29], | |
| "ct": [28, 21, 7, 27, 3, 0, 21, 23, 10, 25, 20, 17, 20, 1, 26, 1, 8, 1, 27, 10, 30], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 778, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "b0a898a02c207118bf6a389abbd20a0e", | |
| "tweak": "bde37fe366da0c1d", | |
| "msg": [24, 0, 26, 8, 27, 4, 28, 19, 31, 24, 3, 12, 7, 8, 3, 30, 22, 25, 22, 19, 32], | |
| "ct": [17, 18, 12, 12, 9, 16, 21, 22, 5, 31, 2, 28, 7, 11, 28, 13, 27, 10, 11, 8, 12], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 22, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 779, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "9ed2a54df9219a3d61b5f1758b73bda6", | |
| "tweak": "5ecd852b587b8148", | |
| "msg": [30, 1, 28, 11, 6, 16, 15, 27, 11, 3, 7, 20, 3, 17, 1, 1, 14, 31, 13, 6, 5, 1], | |
| "ct": [25, 18, 8, 16, 9, 19, 3, 7, 15, 30, 26, 8, 12, 13, 26, 25, 18, 18, 21, 2, 15, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 780, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [13, 15, 10, 1, 2, 17, 26, 4, 23, 16, 7, 29, 27, 7, 25, 3, 19, 31, 29, 14, 12, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 781, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [31, 20, 7, 1, 27, 28, 18, 14, 1, 2, 23, 15, 16, 2, 0, 15, 25, 21, 0, 9, 0, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 782, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [5, 0, 20, 31, 0, 10, 8, 25, 13, 14, 8, 30, 26, 9, 2, 16, 5, 18, 1, 3, 16, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 783, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [28, 15, 13, 8, 20, 7, 24, 16, 6, 6, 11, 3, 10, 24, 0, 4, 4, 1, 29, 4, 28, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 784, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [30, 23, 12, 25, 4, 16, 0, 28, 3, 5, 6, 4, 8, 13, 24, 18, 15, 27, 20, 26, 15, 8], | |
| "ct": [18, 3, 6, 24, 19, 7, 9, 28, 4, 9, 21, 9, 2, 18, 28, 1, 7, 25, 26, 4, 4, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 785, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [7, 24, 24, 16, 19, 18, 6, 11, 21, 16, 22, 11, 20, 9, 8, 13, 22, 22, 6, 18, 27, 10], | |
| "ct": [18, 16, 18, 24, 23, 29, 13, 6, 12, 17, 26, 8, 24, 0, 3, 18, 26, 26, 28, 23, 11, 17], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 786, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [28, 22, 0, 25, 5, 18, 16, 22, 12, 8, 17, 7, 18, 30, 6, 24, 27, 22, 31, 6, 2, 23], | |
| "ct": [26, 20, 24, 18, 30, 6, 12, 30, 1, 5, 15, 21, 20, 19, 0, 22, 5, 12, 2, 26, 7, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 787, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [2, 18, 27, 4, 20, 18, 0, 19, 18, 24, 25, 0, 20, 15, 30, 4, 16, 2, 13, 6, 12, 7], | |
| "ct": [5, 18, 31, 11, 5, 15, 8, 10, 29, 12, 9, 31, 29, 26, 11, 29, 20, 4, 22, 16, 11, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 788, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [4, 23, 9, 13, 24, 8, 18, 25, 16, 26, 9, 1, 3, 8, 4, 28, 29, 16, 16, 19, 19, 8], | |
| "ct": [21, 12, 24, 2, 18, 20, 0, 24, 6, 28, 8, 23, 1, 5, 15, 7, 7, 17, 10, 4, 19, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 789, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [5, 20, 9, 10, 10, 26, 26, 16, 9, 29, 0, 2, 27, 31, 2, 16, 25, 6, 22, 0, 6, 24], | |
| "ct": [11, 6, 1, 23, 9, 30, 6, 23, 11, 26, 7, 2, 17, 19, 2, 30, 20, 29, 13, 24, 31, 7], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 790, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [22, 23, 12, 23, 3, 1, 28, 16, 4, 13, 2, 28, 21, 29, 6, 29, 27, 14, 8, 17, 13, 31], | |
| "ct": [30, 29, 11, 12, 5, 11, 18, 20, 5, 2, 9, 5, 23, 21, 5, 23, 1, 4, 1, 9, 2, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 791, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [12, 25, 11, 19, 15, 11, 6, 3, 16, 16, 15, 11, 10, 28, 28, 18, 26, 21, 0, 28, 17, 27], | |
| "ct": [15, 22, 19, 4, 27, 3, 3, 24, 8, 23, 5, 30, 19, 1, 1, 19, 30, 17, 4, 1, 8, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 792, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [14, 1, 17, 26, 28, 2, 22, 1, 9, 15, 25, 9, 18, 12, 16, 27, 27, 25, 24, 5, 16, 7], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 793, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [31, 7, 7, 31, 27, 24, 5, 22, 5, 17, 18, 20, 31, 15, 4, 26, 23, 20, 7, 1, 4, 24], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 794, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [30, 4, 24, 9, 19, 17, 6, 12, 13, 10, 30, 25, 20, 29, 1, 24, 9, 25, 9, 22, 20, 28], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 795, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "97ad828cba00ca3d4ee15115dc5845a7", | |
| "tweak": "695c7692d9cebe71", | |
| "msg": [27, 1, 8, 25, 21, 21, 11, 5, 30, 6, 13, 0, 22, 20, 21, 30, 14, 29, 18, 19, 8, 5], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 796, | |
| "comment": "y = 0 and (y + a) % radix**11 == 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "a401d171f4119f32", | |
| "msg": [29, 23, 19, 17, 21, 18, 15, 9, 20, 5, 27, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [12, 30, 22, 26, 22, 22, 21, 11, 11, 22, 12, 21, 5, 2, 28, 0, 29, 10, 28, 0, 20, 18], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 797, | |
| "comment": "y = 0 and a = 1 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "a401d171f4119f32", | |
| "msg": [12, 27, 6, 28, 25, 11, 26, 25, 0, 11, 27, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1], | |
| "ct": [11, 0, 2, 17, 18, 2, 30, 9, 24, 2, 13, 8, 15, 21, 23, 4, 5, 15, 30, 0, 28, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 798, | |
| "comment": "y = 0 and a has large Hamming weight in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "a401d171f4119f32", | |
| "msg": [25, 19, 25, 12, 25, 5, 19, 29, 4, 3, 23, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [8, 5, 10, 30, 24, 31, 23, 6, 14, 1, 6, 23, 3, 3, 21, 10, 23, 14, 5, 18, 3, 13], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 799, | |
| "comment": "y = 0 and (y + a) % radix**11 is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "a401d171f4119f32", | |
| "msg": [30, 9, 5, 27, 3, 6, 30, 6, 13, 24, 20, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [27, 7, 2, 13, 3, 12, 31, 5, 23, 18, 16, 8, 26, 14, 12, 17, 25, 0, 31, 17, 12, 30], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 800, | |
| "comment": "y = 1 and a = 0 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "316e18a27f04feab", | |
| "msg": [6, 26, 27, 17, 14, 21, 30, 12, 27, 19, 7, 31, 8, 24, 24, 1, 28, 25, 31, 22, 6, 21], | |
| "ct": [9, 13, 28, 10, 17, 28, 12, 16, 8, 0, 13, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 801, | |
| "comment": "y = 1 and a = 1 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "316e18a27f04feab", | |
| "msg": [1, 22, 18, 18, 2, 12, 13, 10, 24, 10, 15, 5, 19, 23, 31, 8, 21, 16, 10, 23, 7, 9], | |
| "ct": [9, 13, 28, 10, 17, 28, 12, 16, 8, 0, 13, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 802, | |
| "comment": "y = 1 and a has large Hamming weight in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "316e18a27f04feab", | |
| "msg": [4, 16, 28, 5, 8, 28, 9, 23, 2, 18, 2, 15, 25, 20, 23, 18, 7, 29, 21, 12, 19, 8], | |
| "ct": [9, 13, 28, 10, 17, 28, 12, 16, 8, 0, 13, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 803, | |
| "comment": "y = 1 and (y + a) % radix**11 is maximal in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "316e18a27f04feab", | |
| "msg": [3, 30, 29, 0, 3, 28, 10, 10, 5, 19, 6, 29, 6, 29, 6, 21, 21, 21, 22, 16, 16, 4], | |
| "ct": [9, 13, 28, 10, 17, 28, 12, 16, 8, 0, 13, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 804, | |
| "comment": "y = 1 and (y + a) % radix**11 == 0 in round 9", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "316e18a27f04feab", | |
| "msg": [31, 26, 4, 15, 19, 8, 4, 18, 6, 3, 25, 31, 8, 5, 7, 12, 16, 3, 21, 13, 6, 22], | |
| "ct": [9, 13, 28, 10, 17, 28, 12, 16, 8, 0, 13, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 805, | |
| "comment": "y is maximal and (y + a) % radix**11 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "d72a3a54f4ec4e0e", | |
| "msg": [13, 29, 3, 7, 18, 6, 26, 11, 5, 6, 12, 26, 27, 1, 16, 27, 17, 16, 5, 12, 17, 12], | |
| "ct": [28, 14, 24, 30, 16, 30, 27, 3, 8, 22, 26, 3, 7, 2, 23, 6, 27, 3, 14, 3, 17, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 806, | |
| "comment": "y is maximal and (y + a) % radix**11 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "d72a3a54f4ec4e0e", | |
| "msg": [8, 30, 17, 9, 22, 11, 29, 3, 26, 18, 23, 8, 30, 18, 9, 22, 30, 15, 24, 18, 26, 25], | |
| "ct": [5, 2, 27, 1, 12, 10, 25, 19, 20, 1, 5, 30, 25, 21, 29, 8, 3, 29, 18, 26, 26, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 807, | |
| "comment": "y is maximal and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "d72a3a54f4ec4e0e", | |
| "msg": [15, 8, 27, 9, 31, 16, 25, 21, 21, 10, 8, 13, 3, 5, 10, 5, 30, 7, 5, 24, 6, 24], | |
| "ct": [28, 1, 22, 18, 23, 26, 6, 23, 14, 17, 20, 16, 27, 13, 0, 2, 15, 7, 8, 13, 9, 23], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 808, | |
| "comment": "y is maximal and a is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "d72a3a54f4ec4e0e", | |
| "msg": [10, 18, 27, 29, 4, 24, 19, 14, 24, 12, 5, 31, 2, 30, 13, 17, 18, 21, 29, 23, 7, 26], | |
| "ct": [20, 23, 26, 22, 15, 17, 9, 20, 15, 29, 5, 10, 12, 28, 8, 5, 24, 28, 4, 9, 12, 2], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 809, | |
| "comment": "y is edge case for modular reduction and a = 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "790cab2dd60cc461", | |
| "msg": [20, 18, 16, 29, 27, 21, 7, 3, 27, 29, 6, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [20, 9, 20, 28, 15, 9, 31, 20, 10, 19, 30, 24, 30, 28, 9, 14, 1, 25, 30, 18, 7, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 810, | |
| "comment": "y is edge case for modular reduction and a = 1 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "790cab2dd60cc461", | |
| "msg": [8, 30, 24, 18, 19, 23, 10, 12, 29, 8, 5, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1], | |
| "ct": [22, 10, 17, 1, 12, 2, 2, 8, 0, 21, 15, 11, 28, 31, 3, 18, 13, 26, 0, 11, 7, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 811, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**11 is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "790cab2dd60cc461", | |
| "msg": [19, 7, 4, 21, 21, 28, 15, 28, 14, 28, 11, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 31], | |
| "ct": [14, 12, 22, 15, 27, 20, 2, 30, 9, 29, 11, 27, 18, 10, 0, 26, 28, 19, 13, 11, 4, 11], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 812, | |
| "comment": "y is edge case for modular reduction and (y + a) % radix**11 == 0 in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "790cab2dd60cc461", | |
| "msg": [19, 18, 19, 6, 9, 31, 0, 0, 18, 11, 27, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1, 0], | |
| "ct": [4, 2, 29, 7, 2, 11, 12, 22, 14, 0, 22, 21, 5, 19, 13, 27, 14, 14, 0, 3, 23, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 813, | |
| "comment": "y is edge case for modular reduction and a has large Hamming weight in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "790cab2dd60cc461", | |
| "msg": [22, 14, 0, 16, 21, 1, 2, 8, 21, 12, 25, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [30, 29, 17, 12, 24, 29, 24, 23, 22, 3, 20, 4, 6, 3, 22, 28, 18, 28, 15, 27, 5, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 814, | |
| "comment": "y is edge case for modular reduction and a is maximal in round 1", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "790cab2dd60cc461", | |
| "msg": [18, 19, 25, 10, 19, 8, 18, 29, 20, 10, 25, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [4, 19, 23, 27, 18, 5, 7, 2, 31, 31, 28, 30, 18, 23, 13, 0, 21, 23, 19, 15, 15, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 815, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**11 is maximal in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "a5096c818acb5d5e", | |
| "msg": [2, 12, 21, 17, 10, 17, 11, 21, 18, 7, 12, 12, 26, 0, 17, 27, 30, 2, 17, 12, 14, 6], | |
| "ct": [13, 19, 9, 21, 4, 22, 1, 14, 21, 29, 9, 19, 3, 10, 16, 17, 7, 3, 0, 14, 28, 15], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 816, | |
| "comment": "y is maximal after modular reduction and (y + a) % radix**11 == 0 in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "a5096c818acb5d5e", | |
| "msg": [15, 8, 20, 23, 10, 19, 30, 6, 21, 4, 22, 11, 31, 31, 11, 10, 29, 16, 25, 22, 8, 23], | |
| "ct": [31, 4, 14, 13, 28, 21, 0, 21, 14, 22, 19, 10, 31, 17, 11, 22, 6, 11, 3, 14, 0, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 817, | |
| "comment": "y is maximal after modular reduction and a has large Hamming weight in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "a5096c818acb5d5e", | |
| "msg": [10, 3, 3, 15, 29, 15, 7, 14, 27, 18, 8, 2, 3, 19, 0, 24, 12, 0, 26, 1, 0, 17], | |
| "ct": [30, 16, 0, 25, 21, 8, 6, 6, 22, 13, 31, 3, 5, 7, 6, 14, 23, 2, 2, 25, 14, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 818, | |
| "comment": "y is maximal after modular reduction and a is maximal in round 3", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "42ace51e4cacf58876336222ae9b433e", | |
| "tweak": "a5096c818acb5d5e", | |
| "msg": [11, 20, 2, 19, 12, 20, 26, 29, 23, 10, 29, 1, 1, 14, 18, 22, 7, 16, 24, 3, 26, 1], | |
| "ct": [2, 13, 23, 13, 11, 29, 3, 22, 26, 29, 14, 5, 18, 18, 3, 31, 15, 0, 30, 4, 16, 29], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 819, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "1a09b8fb562701a282ce28747f0b0a52", | |
| "tweak": "ec1b2b9ede1b38ea", | |
| "msg": [-1, 11, 20, 28, 12, 0, 2, 16, 9, 7, 20, 17, 20, 5, 27, 18, 14, 17, 7, 10, 21, 1], | |
| "ct": [18, 17, 8, 1, 18, 10, 8, 5, 12, 2, 21, 11, 17, 22, 5, 17, 16, 15, 24, 2, 19, 4], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 820, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "1a09b8fb562701a282ce28747f0b0a52", | |
| "tweak": "ec1b2b9ede1b38ea", | |
| "msg": [6, 11, 20, 28, 12, 0, 2, -1, 9, 7, 20, 17, 20, 5, 27, 18, 14, 17, 7, 10, 21, 1], | |
| "ct": [2, 5, 22, 8, 19, 26, 6, 31, 21, 2, 6, 10, 31, 25, 17, 5, 27, 13, 26, 17, 28, 6], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 821, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "1a09b8fb562701a282ce28747f0b0a52", | |
| "tweak": "ec1b2b9ede1b38ea", | |
| "msg": [6, 11, 20, 28, 12, 0, 2, 16, 9, 7, 20, 17, 20, 5, 27, 18, 14, 17, 7, 10, 21, -1], | |
| "ct": [10, 15, 1, 21, 8, 9, 11, 8, 14, 10, 12, 29, 13, 0, 20, 30, 15, 19, 16, 9, 10, 13], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 822, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "f712cd878b3e679d5423f15c8b4aa76f", | |
| "tweak": "c3f33c5a0592cae5", | |
| "msg": [32, 3, 21, 19, 26, 20, 22, 0, 8, 19, 21, 29, 29, 13, 19, 8, 3, 12, 0, 3, 13, 14], | |
| "ct": [25, 7, 24, 30, 8, 22, 27, 1, 12, 7, 25, 0, 12, 1, 20, 8, 30, 1, 23, 26, 29, 16], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 823, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "f712cd878b3e679d5423f15c8b4aa76f", | |
| "tweak": "c3f33c5a0592cae5", | |
| "msg": [6, 3, 21, 19, 26, 20, 22, 32, 8, 19, 21, 29, 29, 13, 19, 8, 3, 12, 0, 3, 13, 14], | |
| "ct": [1, 4, 17, 5, 11, 26, 11, 0, 16, 2, 20, 20, 28, 0, 20, 19, 27, 3, 25, 10, 17, 11], | |
| "result": "invalid" | |
| }, | |
| { | |
| "tcId": 824, | |
| "comment": "plaintext contains invalid values", | |
| "flags": [ | |
| "InvalidPlaintext" | |
| ], | |
| "key": "f712cd878b3e679d5423f15c8b4aa76f", | |
| "tweak": "c3f33c5a0592cae5", | |
| "msg": [6, 3, 21, 19, 26, 20, 22, 0, 8, 19, 21, 29, 29, 13, 19, 8, 3, 12, 0, 3, 13, 32], | |
| "ct": [23, 20, 18, 3, 27, 7, 9, 7, 28, 23, 6, 3, 18, 28, 27, 13, 23, 31, 8, 1, 10, 25], | |
| "result": "invalid" | |
| } | |
| ] | |
| }, | |
| { | |
| "keySize": 128, | |
| "msgSize": 23, | |
| "radix": 32, | |
| "type": "FpeListTest", | |
| "tests": [ | |
| { | |
| "tcId": 825, | |
| "comment": "normal message size", | |
| "flags": [ | |
| "NormalMessageSize" | |
| ], | |
| "key": "b9259b7f8c36246e73802b650cec0f3a", | |
| "tweak": "338104fb3b076bc4", | |
| "msg": [5, 31, 6, 22, 16, 27, 29, 13, 22, 20, 18, 10, 17, 18, 6, 7, 8, 0, 0, 26, 18, 4, 6], | |
| "ct": [25, 26, 4, 17, 7, 13, 10, 25, 10, 5, 6, 16, 1, 13, 12, 9, 0, 13, 12, 26, 23, 13, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 826, | |
| "comment": "minimal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [29, 16, 12, 11, 9, 7, 18, 21, 4, 13, 23, 26, 20, 0, 29, 6, 24, 30, 26, 11, 0, 13, 1], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 827, | |
| "comment": "maximal integer values in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [3, 13, 10, 24, 6, 28, 9, 31, 14, 2, 19, 28, 24, 19, 15, 11, 13, 24, 25, 9, 5, 14, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 828, | |
| "comment": "powers of two in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "ct": [16, 3, 7, 31, 25, 5, 24, 24, 7, 4, 11, 22, 10, 0, 22, 3, 22, 5, 0, 22, 3, 8, 5], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 829, | |
| "comment": "integers with large hamming weight in plaintext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "ct": [30, 2, 15, 3, 25, 4, 18, 6, 26, 13, 0, 18, 2, 16, 30, 25, 26, 27, 18, 15, 17, 18, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 830, | |
| "comment": "minimal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [5, 4, 13, 29, 6, 16, 20, 28, 17, 10, 22, 10, 20, 13, 7, 18, 18, 5, 7, 24, 8, 15, 18], | |
| "ct": [19, 0, 12, 11, 20, 17, 29, 17, 14, 15, 18, 6, 5, 23, 2, 22, 19, 19, 0, 2, 24, 21, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 831, | |
| "comment": "maximal integer values in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [6, 16, 18, 5, 25, 7, 17, 8, 26, 2, 0, 22, 5, 27, 26, 29, 19, 2, 16, 27, 30, 19, 27], | |
| "ct": [12, 21, 5, 10, 14, 11, 0, 11, 24, 11, 10, 16, 2, 9, 25, 28, 13, 12, 17, 22, 12, 10, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 832, | |
| "comment": "powers of two in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [3, 16, 24, 23, 8, 0, 12, 0, 3, 13, 26, 6, 11, 30, 24, 29, 29, 4, 8, 5, 16, 13, 1], | |
| "ct": [26, 16, 1, 2, 5, 23, 6, 4, 17, 21, 8, 25, 4, 28, 22, 12, 15, 11, 0, 8, 17, 7, 10], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 833, | |
| "comment": "integers with large hamming weight in round 5", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [14, 31, 6, 9, 21, 8, 23, 25, 8, 9, 6, 3, 4, 26, 16, 27, 11, 27, 29, 9, 22, 27, 11], | |
| "ct": [9, 26, 4, 0, 16, 16, 24, 27, 22, 15, 9, 26, 26, 6, 31, 0, 19, 14, 8, 27, 22, 22, 12], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 834, | |
| "comment": "minimal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [18, 13, 29, 13, 1, 14, 28, 0, 28, 5, 2, 24, 31, 28, 0, 23, 22, 22, 23, 11, 1, 4, 11], | |
| "ct": [15, 12, 30, 24, 19, 20, 3, 25, 25, 16, 12, 17, 3, 17, 24, 20, 30, 8, 16, 14, 30, 22, 8], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 835, | |
| "comment": "maximal integer values in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [9, 22, 28, 11, 20, 9, 14, 18, 0, 26, 31, 23, 19, 13, 18, 0, 1, 2, 3, 30, 27, 3, 18], | |
| "ct": [6, 19, 11, 29, 22, 8, 17, 8, 30, 23, 7, 14, 1, 17, 14, 0, 8, 16, 13, 7, 24, 2, 25], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 836, | |
| "comment": "powers of two in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [15, 13, 8, 12, 31, 7, 7, 16, 6, 0, 17, 6, 30, 23, 19, 5, 15, 26, 20, 11, 13, 30, 10], | |
| "ct": [5, 4, 22, 20, 25, 8, 24, 20, 24, 23, 23, 5, 31, 19, 8, 17, 19, 14, 26, 6, 8, 26, 6], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 837, | |
| "comment": "integers with large hamming weight in round 6", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [18, 31, 23, 25, 29, 21, 30, 11, 20, 27, 22, 11, 10, 9, 3, 10, 1, 8, 11, 8, 27, 19, 27], | |
| "ct": [2, 7, 22, 19, 6, 12, 19, 7, 5, 7, 21, 2, 28, 10, 1, 6, 29, 20, 16, 0, 21, 20, 21], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 838, | |
| "comment": "minimal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [10, 14, 22, 28, 7, 22, 1, 0, 16, 4, 15, 30, 19, 22, 22, 13, 8, 21, 27, 4, 24, 14, 17], | |
| "ct": [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 839, | |
| "comment": "maximal integer values in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [20, 8, 7, 31, 19, 31, 13, 2, 1, 7, 17, 8, 29, 18, 28, 10, 31, 21, 29, 25, 31, 19, 3], | |
| "ct": [31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 840, | |
| "comment": "powers of two in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [5, 15, 1, 17, 18, 26, 31, 18, 22, 25, 28, 3, 3, 12, 14, 1, 5, 2, 11, 25, 23, 21, 3], | |
| "ct": [16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 16, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 841, | |
| "comment": "integers with large hamming weight in ciphertext", | |
| "flags": [ | |
| "EdgeCaseState" | |
| ], | |
| "key": "54dc637b4efc6ee03d4bd532295d63b8", | |
| "tweak": "cc32b4959acf967c", | |
| "msg": [22, 29, 14, 20, 17, 21, 26, 10, 15, 12, 15, 0, 9, 10, 19, 22, 31, 21, 21, 10, 24, 17, 22], | |
| "ct": [15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 15, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31, 31], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 842, | |
| "comment": "y = 0 and (y + a) % radix**11 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "18408bd00b5409", | |
| "msg": [7, 20, 27, 1, 31, 0, 7, 20, 17, 4, 1, 1, 1, 1, 8, 28, 4, 20, 20, 17, 25, 18, 24], | |
| "ct": [30, 21, 13, 1, 7, 7, 19, 28, 31, 10, 18, 17, 30, 14, 24, 29, 5, 15, 25, 1, 0, 30, 22], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 843, | |
| "comment": "y = 0 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "18408bd00b5409", | |
| "msg": [9, 0, 24, 23, 15, 18, 26, 22, 9, 9, 20, 6, 6, 20, 27, 5, 0, 29, 0, 11, 31, 3, 1], | |
| "ct": [10, 25, 1, 22, 25, 2, 16, 11, 10, 22, 21, 16, 20, 30, 23, 26, 25, 21, 22, 29, 27, 1, 24], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 844, | |
| "comment": "y = 0 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "18408bd00b5409", | |
| "msg": [28, 1, 10, 8, 31, 22, 0, 20, 11, 28, 2, 26, 7, 14, 19, 26, 7, 24, 7, 23, 24, 27, 29], | |
| "ct": [22, 8, 0, 5, 5, 19, 19, 8, 30, 13, 28, 2, 10, 14, 14, 18, 19, 23, 20, 3, 9, 10, 9], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 845, | |
| "comment": "y = 0 and (y + a) % radix**11 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "18408bd00b5409", | |
| "msg": [9, 15, 25, 16, 13, 2, 15, 1, 9, 20, 14, 8, 20, 31, 2, 5, 8, 17, 29, 25, 8, 0, 20], | |
| "ct": [3, 18, 15, 5, 11, 3, 8, 5, 3, 23, 18, 18, 22, 6, 18, 26, 20, 0, 4, 16, 0, 12, 27], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 846, | |
| "comment": "y = 1 and a = 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "e8a10fc90f7682", | |
| "msg": [24, 26, 10, 0, 9, 26, 30, 25, 18, 31, 8, 7, 9, 11, 16, 30, 8, 15, 5, 8, 22, 15, 5], | |
| "ct": [28, 5, 22, 29, 2, 29, 8, 31, 13, 27, 22, 31, 10, 26, 9, 29, 19, 30, 9, 27, 30, 8, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 847, | |
| "comment": "y = 1 and a = 1 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "e8a10fc90f7682", | |
| "msg": [7, 18, 1, 2, 4, 14, 29, 30, 9, 7, 23, 12, 30, 4, 6, 9, 11, 8, 26, 24, 16, 12, 0], | |
| "ct": [26, 30, 0, 17, 4, 9, 14, 26, 4, 27, 2, 1, 27, 10, 15, 30, 0, 25, 22, 1, 5, 25, 19], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 848, | |
| "comment": "y = 1 and a has large Hamming weight in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "e8a10fc90f7682", | |
| "msg": [6, 30, 1, 2, 16, 0, 20, 22, 2, 15, 16, 0, 17, 12, 17, 29, 22, 7, 27, 21, 5, 2, 3], | |
| "ct": [8, 28, 10, 8, 18, 30, 1, 23, 23, 29, 11, 2, 21, 24, 26, 8, 20, 31, 28, 13, 9, 21, 4], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 849, | |
| "comment": "y = 1 and (y + a) % radix**11 is maximal in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "e8a10fc90f7682", | |
| "msg": [1, 0, 26, 26, 2, 25, 21, 21, 30, 1, 30, 6, 19, 26, 16, 10, 30, 12, 23, 8, 20, 1, 10], | |
| "ct": [16, 30, 16, 9, 21, 3, 1, 24, 23, 22, 19, 13, 7, 2, 16, 2, 31, 13, 5, 1, 29, 25, 3], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 850, | |
| "comment": "y = 1 and (y + a) % radix**11 == 0 in round 2", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "e8a10fc90f7682", | |
| "msg": [2, 3, 2, 17, 17, 1, 20, 11, 2, 14, 14, 31, 12, 28, 17, 13, 10, 3, 10, 22, 0, 22, 1], | |
| "ct": [1, 1, 5, 10, 20, 9, 22, 24, 4, 13, 29, 11, 27, 0, 26, 1, 4, 3, 21, 2, 28, 10, 20], | |
| "result": "valid" | |
| }, | |
| { | |
| "tcId": 851, | |
| "comment": "y is maximal and (y + a) % radix**11 is maximal in round 4", | |
| "flags": [ | |
| "EdgeCasePrf" | |
| ], | |
| "key": "803b8c7284f7da1e37b0a019e63e34aa", | |
| "tweak": "f346b95d4268eb", | |