Re: Branch Prediction - Thy New Enemy?
- From: "xmath" <xmath.news@xxxxxxxxx>
- Date: 24 Aug 2006 14:04:55 -0700
Tom St Denis wrote:
A paper about using branch prediction as a side channel vector of
attack.
Whoop!
Heh, am I glad I've just (as of version 200608242056) removed the last
bits of data-dependent branching from my ecdh and sign/verify code.
Only generating a key-pair for signing remains vulnerable, but it's
awkward to avoid for 1/k mod q (patches are welcome of course :-)
- xmath
.
- Follow-Ups:
- Re: Branch Prediction - Thy New Enemy?
- From: David Wagner
- Re: Branch Prediction - Thy New Enemy?
- From: Kristian Gjøsteen
- Re: Branch Prediction - Thy New Enemy?
- References:
- Branch Prediction - Thy New Enemy?
- From: Tom St Denis
- Branch Prediction - Thy New Enemy?
- Prev by Date: Curve25519-based EC-KCDSA
- Next by Date: Short string of data as input of SHA 256
- Previous by thread: Branch Prediction - Thy New Enemy?
- Next by thread: Re: Branch Prediction - Thy New Enemy?
- Index(es):