Keep vanetza-idf in obu-firmware, so a plain clone builds the firmware
obu-firmware builds against the vanetza-idf C-ITS library, which until now came from the colleague's microbu-esp32c5 tree beside the repository and was not tracked here, so a clone of this repository could not build the firmware it ships. The library alone is now part of obu-firmware, as obu-firmware/external/vanetza-idf: their external/vanetza-idf at commit cf4b99f, unchanged (9775 files; see its PROVENANCE.md). CMake takes it from there by default; -DVANETZA_IDF_DIR still points the build elsewhere. The rest of the colleague's tree (their own VAM firmware, PKI tooling, station-link Python tools, the V2X2MAP bridge) stays out of this repository and gitignored; nothing is pushed to their repository. NOTES.md, docs/06, TODO.md and the pcap verifier's usage line point at the new location.
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
if(NOT TARGET Boost::program_options)
|
||||
message(STATUS "Skip build of benchmark because of missing Boost::program_options dependency")
|
||||
return()
|
||||
endif()
|
||||
|
||||
add_executable(benchmark
|
||||
cases/security/base.cpp
|
||||
cases/security/signing.cpp
|
||||
cases/security/validation.cpp
|
||||
main.cpp
|
||||
options.cpp
|
||||
)
|
||||
|
||||
target_include_directories(benchmark PRIVATE ${CMAKE_CURRENT_SOURCE_DIR})
|
||||
target_link_libraries(benchmark Boost::program_options vanetza)
|
||||
@@ -0,0 +1 @@
|
||||
Content of this readme file has been moved to our [documentation](https://www.vanetza.org/tools/benchmark).
|
||||
@@ -0,0 +1,18 @@
|
||||
#ifndef BENCHMARK_CASE_HPP
|
||||
#define BENCHMARK_CASE_HPP
|
||||
|
||||
#include <chrono>
|
||||
#include <type_traits>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
class Case
|
||||
{
|
||||
public:
|
||||
virtual bool parse(const std::vector<std::string>&) = 0;
|
||||
virtual void prepare() = 0;
|
||||
virtual int execute() = 0;
|
||||
virtual ~Case() = default;
|
||||
};
|
||||
|
||||
#endif /* BENCHMARK_CASE_HPP */
|
||||
@@ -0,0 +1,49 @@
|
||||
#include "base.hpp"
|
||||
#include "vanetza/security/v2/sign_service.hpp"
|
||||
#include "vanetza/security/straight_verify_service.hpp"
|
||||
#include <boost/date_time/posix_time/posix_time.hpp>
|
||||
#include <iostream>
|
||||
|
||||
using namespace vanetza;
|
||||
using namespace vanetza::security;
|
||||
|
||||
SecurityBaseCase::SecurityBaseCase() :
|
||||
runtime(Clock::at(boost::posix_time::microsec_clock::universal_time())),
|
||||
crypto_backend(create_backend("default")),
|
||||
certificate_cache(runtime),
|
||||
certificate_provider(runtime),
|
||||
certificate_validator(*crypto_backend, certificate_cache, trust_store),
|
||||
sign_header_policy(runtime, positioning),
|
||||
security_entity(create_sign_service(), create_verify_service())
|
||||
{
|
||||
// nothing to do
|
||||
}
|
||||
|
||||
void SecurityBaseCase::prepare()
|
||||
{
|
||||
PositionFix position;
|
||||
position.latitude = 49.014420 * units::degree;
|
||||
position.longitude = 8.404417 * units::degree;
|
||||
position.confidence.semi_major = 25.0 * units::si::meter;
|
||||
position.confidence.semi_minor = 25.0 * units::si::meter;
|
||||
assert(position.confidence);
|
||||
|
||||
positioning.position_fix(position);
|
||||
}
|
||||
|
||||
std::unique_ptr<SignService> SecurityBaseCase::create_sign_service()
|
||||
{
|
||||
return std::unique_ptr<SignService> {
|
||||
new v2::StraightSignService(certificate_provider, *crypto_backend, sign_header_policy)
|
||||
};
|
||||
}
|
||||
|
||||
std::unique_ptr<VerifyService> SecurityBaseCase::create_verify_service()
|
||||
{
|
||||
std::unique_ptr<StraightVerifyService> verify_service { new StraightVerifyService(runtime, *crypto_backend, positioning) };
|
||||
verify_service->use_certificate_cache(&certificate_cache);
|
||||
verify_service->use_certificate_provider(&certificate_provider);
|
||||
verify_service->use_certificate_validator(&certificate_validator);
|
||||
verify_service->use_sign_header_policy(&sign_header_policy);
|
||||
return verify_service;
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
#ifndef BENCHMARK_CASES_SECURITY_BASE_HPP
|
||||
#define BENCHMARK_CASES_SECURITY_BASE_HPP
|
||||
|
||||
#include "case.hpp"
|
||||
#include <vanetza/common/manual_runtime.hpp>
|
||||
#include <vanetza/common/stored_position_provider.hpp>
|
||||
#include <vanetza/security/backend.hpp>
|
||||
#include <vanetza/security/delegating_security_entity.hpp>
|
||||
#include <vanetza/security/v2/certificate_cache.hpp>
|
||||
#include <vanetza/security/v2/default_certificate_validator.hpp>
|
||||
#include <vanetza/security/v2/naive_certificate_provider.hpp>
|
||||
#include <vanetza/security/v2/sign_header_policy.hpp>
|
||||
#include <vanetza/security/v2/trust_store.hpp>
|
||||
|
||||
class SecurityBaseCase : public Case
|
||||
{
|
||||
public:
|
||||
SecurityBaseCase();
|
||||
|
||||
void prepare() override;
|
||||
|
||||
protected:
|
||||
vanetza::ManualRuntime runtime;
|
||||
vanetza::StoredPositionProvider positioning;
|
||||
std::unique_ptr<vanetza::security::Backend> crypto_backend;
|
||||
vanetza::security::v2::TrustStore trust_store;
|
||||
vanetza::security::v2::CertificateCache certificate_cache;
|
||||
vanetza::security::v2::NaiveCertificateProvider certificate_provider;
|
||||
vanetza::security::v2::DefaultCertificateValidator certificate_validator;
|
||||
vanetza::security::v2::DefaultSignHeaderPolicy sign_header_policy;
|
||||
vanetza::security::DelegatingSecurityEntity security_entity;
|
||||
|
||||
std::unique_ptr<vanetza::security::SignService> create_sign_service();
|
||||
std::unique_ptr<vanetza::security::VerifyService> create_verify_service();
|
||||
};
|
||||
|
||||
#endif /* BENCHMARK_CASES_SECURITY_BASE_HPP */
|
||||
@@ -0,0 +1,78 @@
|
||||
#include "signing.hpp"
|
||||
#include <boost/program_options.hpp>
|
||||
#include <iostream>
|
||||
#include <random>
|
||||
|
||||
using namespace vanetza;
|
||||
using namespace vanetza::security;
|
||||
namespace po = boost::program_options;
|
||||
|
||||
bool SecuritySigningCase::parse(const std::vector<std::string>& opts)
|
||||
{
|
||||
po::options_description desc("Available options");
|
||||
desc.add_options()
|
||||
("help", "Print out available options.")
|
||||
("messages", po::value<unsigned>(&messages)->default_value(10000), "Number of messages.")
|
||||
("signer", po::value<std::string>(&signer_info_type)->default_value("certificate"), "Signer embedded into the messages, may be 'certificate', 'hash' or 'chain'.")
|
||||
;
|
||||
|
||||
po::variables_map vm;
|
||||
po::store(po::command_line_parser(opts).options(desc).run(), vm);
|
||||
|
||||
if (vm.count("help")) {
|
||||
std::cerr << desc << std::endl;
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
try {
|
||||
po::notify(vm);
|
||||
|
||||
if (signer_info_type != "certificate" && signer_info_type != "hash" && signer_info_type != "chain") {
|
||||
throw std::runtime_error("Invalid signer info type.");
|
||||
}
|
||||
} catch (const std::exception& e) {
|
||||
std::cerr << "Error: " << e.what() << std::endl << std::endl << desc << std::endl;
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
int SecuritySigningCase::execute()
|
||||
{
|
||||
if (signer_info_type == "hash") {
|
||||
// Sign one message with CAM profile, so the next message only includes the certificate hash
|
||||
DownPacket packet;
|
||||
packet.layer(OsiLayer::Application) = ByteBuffer { 0xC0, 0xFF, 0xEE };
|
||||
|
||||
SignRequest initial_sign_request;
|
||||
initial_sign_request.plain_message = std::move(packet);
|
||||
initial_sign_request.its_aid = aid::CA;
|
||||
security_entity.encapsulate_packet(std::move(initial_sign_request));
|
||||
}
|
||||
|
||||
if (signer_info_type == "certificate") {
|
||||
sign_header_policy.request_certificate();
|
||||
} else if (signer_info_type == "chain") {
|
||||
sign_header_policy.request_certificate_chain();
|
||||
}
|
||||
|
||||
std::cout << "Starting benchmark for messages ... ";
|
||||
|
||||
for (unsigned i = 0; i < messages; i++) {
|
||||
DownPacket packet;
|
||||
packet.layer(OsiLayer::Application) = ByteBuffer { 0xC0, 0xFF, 0xEE };
|
||||
|
||||
SignRequest sign_request;
|
||||
sign_request.plain_message= std::move(packet);
|
||||
sign_request.its_aid = aid::CA;
|
||||
|
||||
EncapConfirm encap_confirm = security_entity.encapsulate_packet(std::move(sign_request));
|
||||
}
|
||||
|
||||
std::cout << "[Done]" << std::endl;
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
#ifndef BENCHMARK_CASES_SECURITY_SIGNING_HPP
|
||||
#define BENCHMARK_CASES_SECURITY_SIGNING_HPP
|
||||
|
||||
#include "base.hpp"
|
||||
|
||||
class SecuritySigningCase : public SecurityBaseCase
|
||||
{
|
||||
public:
|
||||
bool parse(const std::vector<std::string>&) override;
|
||||
int execute() override;
|
||||
|
||||
private:
|
||||
unsigned messages;
|
||||
std::string signer_info_type;
|
||||
};
|
||||
|
||||
#endif /* BENCHMARK_CASES_SECURITY_SIGNING_HPP */
|
||||
+119
@@ -0,0 +1,119 @@
|
||||
#include "validation.hpp"
|
||||
#include <vanetza/security/delegating_security_entity.hpp>
|
||||
#include <vanetza/security/v2/secured_message.hpp>
|
||||
#include <vanetza/security/v2/sign_service.hpp>
|
||||
#include <boost/program_options.hpp>
|
||||
#include <iostream>
|
||||
#include <random>
|
||||
|
||||
using namespace vanetza;
|
||||
using namespace vanetza::security;
|
||||
namespace po = boost::program_options;
|
||||
|
||||
bool SecurityValidationCase::parse(const std::vector<std::string>& opts)
|
||||
{
|
||||
po::options_description desc("Available options");
|
||||
desc.add_options()
|
||||
("help", "Print out available options.")
|
||||
("identities", po::value<unsigned>(&identities)->default_value(1), "Number of identities (certificates).")
|
||||
("messages", po::value<unsigned>(&messages)->default_value(10000), "Number of messages.")
|
||||
("signer", po::value<std::string>(&signer_info_type)->default_value("certificate"), "Signer embedded into the messages, may be 'certificate', 'hash' or 'chain'.")
|
||||
;
|
||||
|
||||
po::variables_map vm;
|
||||
po::store(po::command_line_parser(opts).options(desc).run(), vm);
|
||||
|
||||
if (vm.count("help")) {
|
||||
std::cerr << desc << std::endl;
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
try {
|
||||
po::notify(vm);
|
||||
|
||||
if (signer_info_type != "certificate" && signer_info_type != "hash" && signer_info_type != "chain") {
|
||||
throw std::runtime_error("Invalid signer info type.");
|
||||
}
|
||||
} catch (const std::exception& e) {
|
||||
std::cerr << "Error: " << e.what() << std::endl << std::endl << desc << std::endl;
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
int SecurityValidationCase::execute()
|
||||
{
|
||||
DownPacket packet;
|
||||
packet.layer(OsiLayer::Application) = ByteBuffer { 0xC0, 0xFF, 0xEE };
|
||||
|
||||
certificate_cache.insert(certificate_provider.own_certificate());
|
||||
certificate_cache.insert(certificate_provider.aa_certificate());
|
||||
trust_store.insert(certificate_provider.root_certificate());
|
||||
|
||||
std::vector<std::unique_ptr<v2::CertificateProvider>> providers;
|
||||
std::vector<std::unique_ptr<SecurityEntity>> entities;
|
||||
std::vector<SecuredMessage> secured_messages(identities);
|
||||
|
||||
for (unsigned i = 0; i < identities; i++) {
|
||||
providers.emplace_back(new v2::NaiveCertificateProvider(runtime));
|
||||
entities.emplace_back(new DelegatingSecurityEntity { create_sign_service(), create_verify_service() });
|
||||
certificate_cache.insert(providers.back()->own_certificate());
|
||||
}
|
||||
|
||||
if (signer_info_type == "hash") {
|
||||
// Sign one message with CAM profile, so the next message only includes the certificate hash
|
||||
SignRequest initial_sign_request;
|
||||
initial_sign_request.plain_message = packet;
|
||||
initial_sign_request.its_aid = aid::CA;
|
||||
entities[0]->encapsulate_packet(std::move(initial_sign_request));
|
||||
}
|
||||
|
||||
for (unsigned i = 0; i < identities; i++) {
|
||||
if (signer_info_type == "certificate") {
|
||||
sign_header_policy.request_certificate();
|
||||
} else if (signer_info_type == "chain") {
|
||||
sign_header_policy.request_certificate_chain();
|
||||
}
|
||||
|
||||
SignRequest sign_request;
|
||||
sign_request.plain_message = packet;
|
||||
sign_request.its_aid = aid::CA;
|
||||
|
||||
EncapConfirm encap_confirm = entities[i]->encapsulate_packet(std::move(sign_request));
|
||||
auto secured_msg = encap_confirm.secured_message();
|
||||
if (!secured_msg) {
|
||||
std::cerr << "Failed to encapsulate packet." << std::endl;
|
||||
return 1;
|
||||
}
|
||||
auto v2_sec_msg = boost::get<v2::SecuredMessage>(*secured_msg);
|
||||
auto signer_info = v2_sec_msg.header_field<v2::HeaderFieldType::Signer_Info>();
|
||||
|
||||
if (signer_info_type == "hash") {
|
||||
assert(signer_info && get_type(*signer_info) == v2::SignerInfoType::Certificate_Digest_With_SHA256);
|
||||
} else if (signer_info_type == "certificate") {
|
||||
assert(signer_info && get_type(*signer_info) == v2::SignerInfoType::Certificate);
|
||||
} else if (signer_info_type == "chain") {
|
||||
assert(signer_info && get_type(*signer_info) == v2::SignerInfoType::Certificate_Chain);
|
||||
}
|
||||
|
||||
secured_messages.push_back(v2_sec_msg);
|
||||
}
|
||||
|
||||
std::mt19937 gen(0);
|
||||
std::uniform_int_distribution<> dis(0, identities - 1);
|
||||
|
||||
std::cout << "Starting benchmark for messages ... ";
|
||||
|
||||
for (unsigned i = 0; i < messages; i++) {
|
||||
DecapRequest decap_request { SecuredMessageView { secured_messages[dis(gen)] }};
|
||||
auto decap_confirm = security_entity.decapsulate_packet(std::move(decap_request));
|
||||
assert(decap_confirm.report == VerificationReport::Success);
|
||||
}
|
||||
|
||||
std::cout << "[Done]" << std::endl;
|
||||
|
||||
return 0;
|
||||
}
|
||||
+18
@@ -0,0 +1,18 @@
|
||||
#ifndef BENCHMARK_CASES_SECURITY_VALIDATION_HPP
|
||||
#define BENCHMARK_CASES_SECURITY_VALIDATION_HPP
|
||||
|
||||
#include "base.hpp"
|
||||
|
||||
class SecurityValidationCase : public SecurityBaseCase
|
||||
{
|
||||
public:
|
||||
bool parse(const std::vector<std::string>&) override;
|
||||
int execute() override;
|
||||
|
||||
private:
|
||||
unsigned identities;
|
||||
unsigned messages;
|
||||
std::string signer_info_type;
|
||||
};
|
||||
|
||||
#endif /* BENCHMARK_CASES_SECURITY_VALIDATION_HPP */
|
||||
@@ -0,0 +1,18 @@
|
||||
#include "options.hpp"
|
||||
#include <iostream>
|
||||
|
||||
int main(int argc, const char** argv)
|
||||
{
|
||||
try {
|
||||
std::unique_ptr<Case> executable = parse_options(argc, argv);
|
||||
|
||||
if (!executable) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
return executable->execute();
|
||||
} catch (const std::exception& e) {
|
||||
std::cerr << "Error: " << e.what() << std::endl;
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,63 @@
|
||||
#include "cases/security/signing.hpp"
|
||||
#include "cases/security/validation.hpp"
|
||||
#include "options.hpp"
|
||||
#include <boost/program_options.hpp>
|
||||
#include <iostream>
|
||||
#include <memory>
|
||||
|
||||
namespace po = boost::program_options;
|
||||
|
||||
std::unique_ptr<Case> parse_options(int argc, const char *argv[])
|
||||
{
|
||||
po::options_description global("Global options");
|
||||
global.add_options()
|
||||
("case", po::value<std::string>(), "Case to execute.")
|
||||
("subargs", po::value<std::vector<std::string>>(), "Arguments for case.");
|
||||
|
||||
po::positional_options_description pos;
|
||||
pos.add("case", 1);
|
||||
pos.add("subargs", -1);
|
||||
|
||||
po::variables_map vm;
|
||||
|
||||
po::parsed_options parsed = po::command_line_parser(argc, argv)
|
||||
.options(global)
|
||||
.positional(pos)
|
||||
.allow_unregistered()
|
||||
.run();
|
||||
|
||||
po::store(parsed, vm);
|
||||
po::notify(vm);
|
||||
|
||||
std::string available_commands = "Available cases: security-validation, security-signing";
|
||||
|
||||
if (!vm.count("case")) {
|
||||
std::cerr << global << std::endl;
|
||||
std::cerr << available_commands << std::endl;
|
||||
|
||||
return nullptr;
|
||||
}
|
||||
|
||||
std::string name = vm["case"].as<std::string>();
|
||||
std::unique_ptr<Case> instance;
|
||||
|
||||
if (name == "--help") {
|
||||
std::cerr << global << std::endl;
|
||||
std::cerr << available_commands << std::endl;
|
||||
} else if (name == "security-signing") {
|
||||
instance.reset(new SecuritySigningCase());
|
||||
} else if (name == "security-validation") {
|
||||
instance.reset(new SecurityValidationCase());
|
||||
} else {
|
||||
throw std::runtime_error("Unknown benchmark case.");
|
||||
}
|
||||
|
||||
std::vector<std::string> opts = po::collect_unrecognized(parsed.options, po::include_positional);
|
||||
opts.erase(opts.begin());
|
||||
|
||||
if (!instance->parse(opts)) {
|
||||
return nullptr;
|
||||
}
|
||||
|
||||
return instance;
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
#ifndef BENCHMARK_OPTIONS_HPP
|
||||
#define BENCHMARK_OPTIONS_HPP
|
||||
|
||||
#include "case.hpp"
|
||||
#include <memory>
|
||||
|
||||
std::unique_ptr<Case> parse_options(int argc, const char* argv[]);
|
||||
|
||||
#endif /* BENCHMARK_OPTIONS_HPP */
|
||||
Reference in New Issue
Block a user