Nothing-up-my-sleeving blinding for a*G

This commit is contained in:
Pieter Wuille
2014-08-29 01:47:20 +02:00
parent d531b04ea9
commit 62c3f55a9d
2 changed files with 52 additions and 32 deletions

View File

@@ -36,7 +36,7 @@ Implementation details
* Point multiplication for signing
* Use a precomputed table of multiples of powers of 16 multiplied with the generator, so general multiplication becomes a series of additions.
* Slice the precomputed table in memory per byte, so memory access to the table becomes uniform.
* Not fully constant-time.
* Not fully constant-time, but the precomputed tables add and eventually subtract points for which no known scalar (private key) is known, blinding non-constant time effects even from an attacker with control over the private key used.
Build steps
-----------