implement Zeroize for Scalar and MontgomeryPoint

This commit is contained in:
DebugSteven 2019-03-03 17:09:34 -07:00
parent 6239a92055
commit ba389040de
5 changed files with 25 additions and 3 deletions

View file

@ -48,6 +48,7 @@ clear_on_drop = "=0.2.3"
subtle = { version = "2.0.0-pre.0", default-features = false }
serde = { version = "1.0", optional = true }
packed_simd = { version = "0.3.0", features = ["into_bits"], optional = true }
zeroize = { version = "0.5.2", default-features = false }
[build-dependencies]
rand = { version = "0.6.0", default-features = false }
@ -57,9 +58,10 @@ clear_on_drop = "=0.2.3"
subtle = { version = "2.0.0-pre.0", default-features = false }
serde = { version = "1.0", optional = true }
packed_simd = { version = "0.3.0", features = ["into_bits"], optional = true }
zeroize = { version = "0.5.2", default-features = false }
[features]
nightly = ["subtle/nightly", "clear_on_drop/nightly"]
nightly = ["subtle/nightly", "clear_on_drop/nightly", "zeroize/nightly"]
default = ["std", "u64_backend"]
std = ["alloc", "subtle/std", "rand/std"]
alloc = []

View file

@ -16,6 +16,8 @@ extern crate subtle;
#[cfg(all(feature = "nightly", feature = "avx2_backend"))]
extern crate packed_simd;
extern crate zeroize;
use std::env;
use std::fs::File;
use std::io::Write;

View file

@ -54,6 +54,8 @@ extern crate serde;
#[cfg(all(test, feature = "serde"))]
extern crate bincode;
extern crate zeroize;
// Internal macros. Must come first!
#[macro_use]
pub(crate) mod macros;

View file

@ -17,7 +17,7 @@
//! Montgomery arithmetic works not on the curve itself, but on the
//! \\(u\\)-line, which discards sign information and unifies the curve
//! and its quadratic twist. See [_Montgomery curves and their
//! arithmetic_][costello-smith] by Costello and Smith for more details.
//! arithmetic_][costello-smith] by Costello and Smith for more details.
//!
//! The `MontgomeryPoint` struct contains the affine \\(u\\)-coordinate
//! \\(u\_0(P)\\) of a point \\(P\\) on either the curve or the twist.
@ -61,6 +61,8 @@ use subtle::Choice;
use subtle::ConditionallySelectable;
use subtle::ConstantTimeEq;
use zeroize::Zeroize;
/// Holds the \\(u\\)-coordinate of a point on the Montgomery form of
/// Curve25519 or its twist.
#[derive(Copy, Clone, Debug)]
@ -90,6 +92,12 @@ impl PartialEq for MontgomeryPoint {
impl Eq for MontgomeryPoint {}
impl Zeroize for MontgomeryPoint {
fn zeroize(&mut self) {
self.0.zeroize();
}
}
impl MontgomeryPoint {
/// View this `MontgomeryPoint` as an array of bytes.
pub fn as_bytes<'a>(&'a self) -> &'a [u8; 32] {
@ -335,7 +343,7 @@ mod test {
#[test]
fn montgomery_to_edwards_rejects_twist() {
let one = FieldElement::one();
// u = 2 corresponds to a point on the twist.
let two = MontgomeryPoint((&one+&one).to_bytes());

View file

@ -160,6 +160,8 @@ use subtle::Choice;
use subtle::ConditionallySelectable;
use subtle::ConstantTimeEq;
use zeroize::Zeroize;
use backend;
use constants;
@ -502,6 +504,12 @@ impl From<u128> for Scalar {
}
}
impl Zeroize for Scalar {
fn zeroize(&mut self) {
self.bytes.zeroize();
}
}
impl Scalar {
/// Return a `Scalar` chosen uniformly at random using a user-provided RNG.
///