Systematic Testing of Post-Quantum Cryptographic Implementations Using Metamorphic Testing
Sydney Pugh, Mohammad S. Raunak, D. Richard Kuhn, Raghu N. Kacker · 2019
Cryptographic algorithms are usually complex, and their code is highly compact. Moreover, there is often no test oracle to easily test some of these algorithms. Together these attributes make it extremely challenging to run tests and to discover bugs in them. Structural coverage based approaches such as statement or branch coverage are typically not very effective in discovering bugs in these types of programs. In this paper, we investigate the effectiveness of a systematic testing approach for discovering bugs in highly complex cryptographic algorithm implementations. In this work, we identify metamorphic relations based on the specifications of the algorithms, and design test cases such that a systematic coverage of the input space is achieved. Our results show that this approach is highly effective in discovering faults in complex cryptographic implementations.