3 ms·
The idea is that the DSL compiler would be responsible for ensuring constant-timeness. Note that C, C++, and Rust offer no guarantee of constant-timeness. Even
by briansmith 11y ago
The idea is that the DSL compiler would be responsible for ensuring constant-timeness. Note that C, C++, and Rust offer no guarantee of constant-timeness. Even processors don't offer constant-timeness guarantees and some instructions (often division) are not constant-time. See also http://blog.erratasec.com/2015/03/x86-is-high-level-language.html http://blog.erratasec.com/2015/03/x86-is-high-level-language....
I wrote the paper mostly in the context of implementing signature verification, which doesn't require side-channel protection since there are no secrets in verification. But, I think the DSL approach is even more important for ECDH and signing, where side-channel protection is important.
Finally, given that processors don't even promise us that any instruction is constant-time, and given that other types of attacks are possible where constant-timesness doesn't help so much (e.g. power analysis), I think it is worth considering other approaches to side-channel protection (e.g. blinding). For many applications, constant-timeness isn't sufficient and I'd love to learn that it isn't necessary.