summaryrefslogtreecommitdiff
path: root/Kconfig
diff options
context:
space:
mode:
authorVitaly Chikunov <vt@altlinux.org>2018-11-11 20:40:02 +0300
committerHerbert Xu <herbert@gondor.apana.org.au>2018-11-16 14:11:04 +0800
commit3da2c1dfdb802b184eea0653d1e589515b52d74b (patch)
tree2f5689d4508f993fc477ce5dbdb35c6e76d6ff8b /Kconfig
parent8a5a79d5556b822143b4403fc46068d4eef2e4e2 (diff)
downloadlwn-3da2c1dfdb802b184eea0653d1e589515b52d74b.tar.gz
lwn-3da2c1dfdb802b184eea0653d1e589515b52d74b.zip
crypto: ecc - regularize scalar for scalar multiplication
ecc_point_mult is supposed to be used with a regularized scalar, otherwise, it's possible to deduce the position of the top bit of the scalar with timing attack. This is important when the scalar is a private key. ecc_point_mult is already using a regular algorithm (i.e. having an operation flow independent of the input scalar) but regularization step is not implemented. Arrange scalar to always have fixed top bit by adding a multiple of the curve order (n). References: The constant time regularization step is based on micro-ecc by Kenneth MacKay and also referenced in the literature (Bernstein, D. J., & Lange, T. (2017). Montgomery curves and the Montgomery ladder. (Cryptology ePrint Archive; Vol. 2017/293). s.l.: IACR. Chapter 4.6.2.) Signed-off-by: Vitaly Chikunov <vt@altlinux.org> Cc: kernel-hardening@lists.openwall.com Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Diffstat (limited to 'Kconfig')
0 files changed, 0 insertions, 0 deletions