Patched source for Aeneas/Charon formal verification transpilation
Find a file
Michael Rosenberg 415892acf1
SECURITY: fix timing variability in backend/serial/u64/scalar.rs (#659)
Timing variability of any kind is problematic when working with
potentially secret values such as elliptic curve scalars, and such
issues can potentially leak private keys and other secrets. Such a
problem was recently discovered in `curve25519-dalek`.

The `Scalar52::sub` function contained usage of a mask value inside of a
loop where LLVM saw an opportunity to insert a branch instruction
(`jns` on x86) to conditionally bypass this code section when the mask
value is set to zero, as can be seen in godbolt:

https://godbolt.org/z/PczYj7Pda

A similar problem was recently discovered in the Kyber reference
implementation:

https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/hqbtIGFKIpU/m/cnE3pbueBgAJ

As discussed on that thread, one portable solution, which is also used
in this PR, is to introduce a volatile read as an optimization barrier,
which prevents the compiler from optimizing it away.

The fix can be validated in godbolt here:

https://godbolt.org/z/x8d46Yfah

The problem was discovered and the solution independently verified by
Alexander Wagner <alexander.wagner@aisec.fraunhofer.de> and
Lea Themint <lea.thiemt@tum.de> using their DATA tool:

https://github.com/Fraunhofer-AISEC/DATA

Co-authored-by: Tony Arcieri <bascule@gmail.com>
2024-06-18 19:49:31 +02:00
.github/workflows CI: fix minimal-versions resolution (#593) 2023-10-31 12:04:34 -04:00
curve25519-dalek SECURITY: fix timing variability in backend/serial/u64/scalar.rs (#659) 2024-06-18 19:49:31 +02:00
curve25519-dalek-derive Updates license field to valid SPDX format (#647) 2024-06-03 14:30:13 -06:00
docs/assets Move CI & assets into workspace 2023-06-28 08:59:51 +00:00
ed25519-dalek Fix a minor typo in signing.rs (#649) 2024-04-13 19:37:33 -06:00
x25519-dalek Mitigate check-cfg until MSRV 1.77 (#652) 2024-05-09 07:24:16 -06:00
.gitignore Move CI & assets into workspace 2023-06-28 08:59:51 +00:00
Cargo.toml Re-organize Cargo manifests to workspace 2023-06-28 09:38:06 +00:00
CONTRIBUTING.md Add new workspace README and CONTRIBUTING 2023-06-28 09:40:52 +00:00
README.md README.md: remove broken image (#595) 2023-11-01 13:33:43 -04:00

dalek-cryptography logo: a dalek with edwards curves as sparkles coming out of its radar-schnozzley blaster thingies

Dalek elliptic curve cryptography

This repo contains pure-Rust crates for elliptic curve cryptography:

Crate Description Crates.io Docs CI
curve25519dalek A library for arithmetic over the Curve25519 and Ristretto elliptic curves and their associated scalars. CI
ed25519dalek An implementation of the EdDSA digital signature scheme over Curve25519. CI
x25519dalek An implementation of elliptic curve Diffie-Hellman key exchange over Curve25519. CI

There is also the curve25519-dalek-derive crate, which is just a helper crate with some macros that make curve25519-dalek easier to write.

Contributing

Please see CONTRIBUTING.md.

Code of Conduct

We follow the Rust Code of Conduct, with the following additional clauses:

  • We respect the rights to privacy and anonymity for contributors and people in the community. If someone wishes to contribute under a pseudonym different to their primary identity, that wish is to be respected by all contributors.