|
| 1 | +# Copyright 2019 Amazon.com, Inc. or its affiliates. All Rights Reserved. |
| 2 | +# |
| 3 | +# Licensed under the Apache License, Version 2.0 (the "License"). You |
| 4 | +# may not use this file except in compliance with the License. A copy of |
| 5 | +# the License is located at |
| 6 | +# |
| 7 | +# http://aws.amazon.com/apache2.0/ |
| 8 | +# |
| 9 | +# or in the "license" file accompanying this file. This file is |
| 10 | +# distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF |
| 11 | +# ANY KIND, either express or implied. See the License for the specific |
| 12 | +# language governing permissions and limitations under the License. |
| 13 | +"""Functional tests for Multi keyring encryption decryption path.""" |
| 14 | + |
| 15 | +import pytest |
| 16 | +from cryptography.hazmat.backends import default_backend |
| 17 | +from cryptography.hazmat.primitives.asymmetric import rsa |
| 18 | + |
| 19 | +from aws_encryption_sdk.identifiers import KeyringTraceFlag, WrappingAlgorithm |
| 20 | +from aws_encryption_sdk.internal.defaults import ALGORITHM |
| 21 | +from aws_encryption_sdk.keyring.multi_keyring import MultiKeyring |
| 22 | +from aws_encryption_sdk.keyring.raw_keyring import RawAESKeyring, RawRSAKeyring |
| 23 | +from aws_encryption_sdk.materials_managers import DecryptionMaterials, EncryptionMaterials |
| 24 | +from aws_encryption_sdk.structures import KeyringTrace, MasterKeyInfo, RawDataKey |
| 25 | + |
| 26 | +pytestmark = [pytest.mark.functional, pytest.mark.local] |
| 27 | + |
| 28 | +_ENCRYPTION_CONTEXT = {"encryption": "context", "values": "here"} |
| 29 | +_PROVIDER_ID = "Random Raw Keys" |
| 30 | +_KEY_ID = b"5325b043-5843-4629-869c-64794af77ada" |
| 31 | +_WRAPPING_KEY_AES = b"\xeby-\x80A6\x15rA8\x83#,\xe4\xab\xac`\xaf\x99Z\xc1\xce\xdb\xb6\x0f\xb7\x805\xb2\x14J3" |
| 32 | + |
| 33 | +_ENCRYPTION_MATERIALS_WITHOUT_DATA_KEY = EncryptionMaterials( |
| 34 | + algorithm=ALGORITHM, encryption_context=_ENCRYPTION_CONTEXT |
| 35 | +) |
| 36 | + |
| 37 | +_ENCRYPTION_MATERIALS_WITH_DATA_KEY = EncryptionMaterials( |
| 38 | + algorithm=ALGORITHM, |
| 39 | + data_encryption_key=RawDataKey( |
| 40 | + key_provider=MasterKeyInfo(provider_id=_PROVIDER_ID, key_info=_KEY_ID), |
| 41 | + data_key=b'*!\xa1"^-(\xf3\x105\x05i@B\xc2\xa2\xb7\xdd\xd5\xd5\xa9\xddm\xfae\xa8\\$\xf9d\x1e(', |
| 42 | + ), |
| 43 | + encryption_context=_ENCRYPTION_CONTEXT, |
| 44 | + keyring_trace=[ |
| 45 | + KeyringTrace( |
| 46 | + wrapping_key=MasterKeyInfo(provider_id=_PROVIDER_ID, key_info=_KEY_ID), |
| 47 | + flags={KeyringTraceFlag.WRAPPING_KEY_GENERATED_DATA_KEY}, |
| 48 | + ) |
| 49 | + ], |
| 50 | +) |
| 51 | + |
| 52 | +_MULTI_KEYRING_WITH_GENERATOR_AND_CHILDREN = MultiKeyring( |
| 53 | + generator=RawAESKeyring( |
| 54 | + key_namespace=_PROVIDER_ID, |
| 55 | + key_name=_KEY_ID, |
| 56 | + wrapping_algorithm=WrappingAlgorithm.AES_256_GCM_IV12_TAG16_NO_PADDING, |
| 57 | + wrapping_key=_WRAPPING_KEY_AES, |
| 58 | + ), |
| 59 | + children=[ |
| 60 | + RawRSAKeyring( |
| 61 | + key_namespace=_PROVIDER_ID, |
| 62 | + key_name=_KEY_ID, |
| 63 | + wrapping_algorithm=WrappingAlgorithm.RSA_OAEP_SHA256_MGF1, |
| 64 | + private_wrapping_key=rsa.generate_private_key( |
| 65 | + public_exponent=65537, key_size=2048, backend=default_backend() |
| 66 | + ), |
| 67 | + ), |
| 68 | + RawRSAKeyring( |
| 69 | + key_namespace=_PROVIDER_ID, |
| 70 | + key_name=_KEY_ID, |
| 71 | + wrapping_algorithm=WrappingAlgorithm.RSA_OAEP_SHA256_MGF1, |
| 72 | + private_wrapping_key=rsa.generate_private_key( |
| 73 | + public_exponent=65537, key_size=2048, backend=default_backend() |
| 74 | + ), |
| 75 | + ), |
| 76 | + ], |
| 77 | +) |
| 78 | + |
| 79 | +_MULTI_KEYRING_WITHOUT_CHILDREN = MultiKeyring( |
| 80 | + generator=RawRSAKeyring( |
| 81 | + key_namespace=_PROVIDER_ID, |
| 82 | + key_name=_KEY_ID, |
| 83 | + wrapping_algorithm=WrappingAlgorithm.RSA_OAEP_SHA256_MGF1, |
| 84 | + private_wrapping_key=rsa.generate_private_key(public_exponent=65537, key_size=2048, backend=default_backend()), |
| 85 | + ) |
| 86 | +) |
| 87 | + |
| 88 | +_MULTI_KEYRING_WITHOUT_GENERATOR = MultiKeyring( |
| 89 | + children=[ |
| 90 | + RawRSAKeyring( |
| 91 | + key_namespace=_PROVIDER_ID, |
| 92 | + key_name=_KEY_ID, |
| 93 | + wrapping_algorithm=WrappingAlgorithm.RSA_OAEP_SHA256_MGF1, |
| 94 | + private_wrapping_key=rsa.generate_private_key( |
| 95 | + public_exponent=65537, key_size=2048, backend=default_backend() |
| 96 | + ), |
| 97 | + ), |
| 98 | + RawAESKeyring( |
| 99 | + key_namespace=_PROVIDER_ID, |
| 100 | + key_name=_KEY_ID, |
| 101 | + wrapping_algorithm=WrappingAlgorithm.AES_128_GCM_IV12_TAG16_NO_PADDING, |
| 102 | + wrapping_key=_WRAPPING_KEY_AES, |
| 103 | + ), |
| 104 | + ] |
| 105 | +) |
| 106 | + |
| 107 | + |
| 108 | +@pytest.mark.parametrize( |
| 109 | + "multi_keyring, encryption_materials", |
| 110 | + [ |
| 111 | + (_MULTI_KEYRING_WITH_GENERATOR_AND_CHILDREN, _ENCRYPTION_MATERIALS_WITHOUT_DATA_KEY), |
| 112 | + (_MULTI_KEYRING_WITH_GENERATOR_AND_CHILDREN, _ENCRYPTION_MATERIALS_WITH_DATA_KEY), |
| 113 | + (_MULTI_KEYRING_WITHOUT_CHILDREN, _ENCRYPTION_MATERIALS_WITH_DATA_KEY), |
| 114 | + (_MULTI_KEYRING_WITHOUT_GENERATOR, _ENCRYPTION_MATERIALS_WITH_DATA_KEY), |
| 115 | + ], |
| 116 | +) |
| 117 | +def test_multi_keyring_encryption_decryption(multi_keyring, encryption_materials): |
| 118 | + # Call on_encrypt function for the keyring |
| 119 | + encryption_materials = multi_keyring.on_encrypt(encryption_materials) |
| 120 | + |
| 121 | + # Generate decryption materials |
| 122 | + decryption_materials = DecryptionMaterials( |
| 123 | + algorithm=ALGORITHM, verification_key=b"ex_verification_key", encryption_context=_ENCRYPTION_CONTEXT |
| 124 | + ) |
| 125 | + |
| 126 | + # Call on_decrypt function for the keyring |
| 127 | + decryption_materials = multi_keyring.on_decrypt( |
| 128 | + decryption_materials=decryption_materials, encrypted_data_keys=encryption_materials.encrypted_data_keys |
| 129 | + ) |
| 130 | + |
| 131 | + # Check if the data keys match |
| 132 | + assert encryption_materials.data_encryption_key == decryption_materials.data_encryption_key |
0 commit comments