From ba389040de82947e764600c679894e4f6d2a9c2d Mon Sep 17 00:00:00 2001 From: DebugSteven Date: Sun, 3 Mar 2019 17:09:34 -0700 Subject: [PATCH] implement Zeroize for Scalar and MontgomeryPoint --- Cargo.toml | 4 +++- build.rs | 2 ++ src/lib.rs | 2 ++ src/montgomery.rs | 12 ++++++++++-- src/scalar.rs | 8 ++++++++ 5 files changed, 25 insertions(+), 3 deletions(-) diff --git a/Cargo.toml b/Cargo.toml index 4be6b1d..f320f49 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -48,6 +48,7 @@ clear_on_drop = "=0.2.3" subtle = { version = "2.0.0-pre.0", default-features = false } serde = { version = "1.0", optional = true } packed_simd = { version = "0.3.0", features = ["into_bits"], optional = true } +zeroize = { version = "0.5.2", default-features = false } [build-dependencies] rand = { version = "0.6.0", default-features = false } @@ -57,9 +58,10 @@ clear_on_drop = "=0.2.3" subtle = { version = "2.0.0-pre.0", default-features = false } serde = { version = "1.0", optional = true } packed_simd = { version = "0.3.0", features = ["into_bits"], optional = true } +zeroize = { version = "0.5.2", default-features = false } [features] -nightly = ["subtle/nightly", "clear_on_drop/nightly"] +nightly = ["subtle/nightly", "clear_on_drop/nightly", "zeroize/nightly"] default = ["std", "u64_backend"] std = ["alloc", "subtle/std", "rand/std"] alloc = [] diff --git a/build.rs b/build.rs index 284bce7..8747509 100644 --- a/build.rs +++ b/build.rs @@ -16,6 +16,8 @@ extern crate subtle; #[cfg(all(feature = "nightly", feature = "avx2_backend"))] extern crate packed_simd; +extern crate zeroize; + use std::env; use std::fs::File; use std::io::Write; diff --git a/src/lib.rs b/src/lib.rs index 4f52c96..3ab18d9 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -54,6 +54,8 @@ extern crate serde; #[cfg(all(test, feature = "serde"))] extern crate bincode; +extern crate zeroize; + // Internal macros. Must come first! #[macro_use] pub(crate) mod macros; diff --git a/src/montgomery.rs b/src/montgomery.rs index da3c9a5..03913d6 100644 --- a/src/montgomery.rs +++ b/src/montgomery.rs @@ -17,7 +17,7 @@ //! Montgomery arithmetic works not on the curve itself, but on the //! \\(u\\)-line, which discards sign information and unifies the curve //! and its quadratic twist. See [_Montgomery curves and their -//! arithmetic_][costello-smith] by Costello and Smith for more details. +//! arithmetic_][costello-smith] by Costello and Smith for more details. //! //! The `MontgomeryPoint` struct contains the affine \\(u\\)-coordinate //! \\(u\_0(P)\\) of a point \\(P\\) on either the curve or the twist. @@ -61,6 +61,8 @@ use subtle::Choice; use subtle::ConditionallySelectable; use subtle::ConstantTimeEq; +use zeroize::Zeroize; + /// Holds the \\(u\\)-coordinate of a point on the Montgomery form of /// Curve25519 or its twist. #[derive(Copy, Clone, Debug)] @@ -90,6 +92,12 @@ impl PartialEq for MontgomeryPoint { impl Eq for MontgomeryPoint {} +impl Zeroize for MontgomeryPoint { + fn zeroize(&mut self) { + self.0.zeroize(); + } +} + impl MontgomeryPoint { /// View this `MontgomeryPoint` as an array of bytes. pub fn as_bytes<'a>(&'a self) -> &'a [u8; 32] { @@ -335,7 +343,7 @@ mod test { #[test] fn montgomery_to_edwards_rejects_twist() { let one = FieldElement::one(); - + // u = 2 corresponds to a point on the twist. let two = MontgomeryPoint((&one+&one).to_bytes()); diff --git a/src/scalar.rs b/src/scalar.rs index 2e4d256..826bd8d 100644 --- a/src/scalar.rs +++ b/src/scalar.rs @@ -160,6 +160,8 @@ use subtle::Choice; use subtle::ConditionallySelectable; use subtle::ConstantTimeEq; +use zeroize::Zeroize; + use backend; use constants; @@ -502,6 +504,12 @@ impl From for Scalar { } } +impl Zeroize for Scalar { + fn zeroize(&mut self) { + self.bytes.zeroize(); + } +} + impl Scalar { /// Return a `Scalar` chosen uniformly at random using a user-provided RNG. ///