Re: Branch Prediction - Thy New Enemy?



Tom St Denis wrote:
A paper about using branch prediction as a side channel vector of
attack.

Whoop!

Heh, am I glad I've just (as of version 200608242056) removed the last
bits of data-dependent branching from my ecdh and sign/verify code.
Only generating a key-pair for signing remains vulnerable, but it's
awkward to avoid for 1/k mod q (patches are welcome of course :-)

- xmath

.


Quantcast