Skip to content

Tracking issue for constant-time implementation problems #711

Description

@tarcieri

draft-irtf-cfrg-rsa-guidance contains plenty of guidance for how to implement RSA in constant time correctly. This is an issue tracking what parts of its recommendations we're currently missing.

Note we have a separate issue #626 specifically to track padding defects and the lack of implicit rejection on padding failures.

  1. Make private-result integer-to-octet conversion fixed-width and constant-time (see §6.1, §7.2, partly addressed in Fix RSA constant-time padding and length checks #710)
  2. Ignore the first encoded-message octet when depadding OAEP (see §7)
  3. Apply base blinding by default across private-key operations (see §6.1, partly addressed in Blind the default PKCS#1 v1.5 / OAEP decryption paths #702)
  4. Audit and replace CRT reductions using division by secret primes including rem_vartime for mod reduce (see §6.1, §6.2)
  5. Derive private arithmetic buffer widths from the public modulus (§6.2.1)
  6. Add fresh exponent blinding for each private operation (see §6.4)
  7. Add CRT modulus blinding (see §6.5)
  8. Require exactly k ciphertext octets for PKCS#1 v1.5 decryption (see §7.2, addressed in Fix RSA constant-time padding and length checks #710)

NOTE: I'd kindly request that people do NOT open PRs that try to vibe code solutions to these problems. We already have people including myself working on these issues and vibe coded PRs clutter the tracker and just generally waste my time.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions