3 ms·
You don't really want to verify the signature you've just generated, if you care about perf, because verification is twice as costly as signing.
by Lery 9y ago
You don't really want to verify the signature you've just generated, if you care about perf, because verification is twice as costly as signing.
- loup-vaillant 9y agoI know, it would slow down the whole thing by a factor of 3. Monocypher can "only" produce 7000 signatures per seconds on a single thread on my laptop (i5 Skylake Intel). With the verification, I would waste a whooping 0.3ms on each signature, reducing the throughput to 2000 signatures per seconds. Unless you're running a signing intensive application on the scale of Let's Encrypt, you won't really care about the slow-down. If you don't fully trust your hardware however, faults might be a real problem.
- rightos 9y agoEven let's encrypt is issuing only a handful of certificates per second. Perhaps it'd matter more if used on a per connection basis.
- tptacek 9y ago1. Nobody is attacking Lets Encrypt with fault attacks. 2. If you can induce faults on Lets Encrypt's signing infrastructure you have better attacks to deploy. 3. Lets Encrypt doesn't use Elliptic Curve in the first place.
- loup-vaillant 9y agoOf course, I was only speculating about the scale required to make several thousands of signature per second. Your second point stands, though. It's probably a waste of CPU to mitigate fault attacks in a Lets Encrypt like use case.
- deleted 9y ago[deleted]
- rightos 9y agoI wasn't suggesting any of those things weren't true, merely a back-of-the-napkin estimate of the sort of load a function like this would be sufficient for.
- wolf550e 9y agoLet's Encrypt use HSMs to sign, and more than 90% of signatures produced are for OCSP, not for issuance. Though I have failed to find the link for this, I saw them publish these numbers.
- marcosdumay 9y agoYet, if you then proceed to send your signed document over a network, for it to be rejected 10 minutes later because of a bad signature and then you have to start from the beginning again, that verification cost is irrelevant.
- loup-vaillant 9y agoHow frequent do you expect failures to be? (That would attack induced failures). There's a threshold below which the "10 minutes later" cost less than wasting 3ms every single time.
- AstralStorm 9y agoIt is much more likely that the fault is due to corruption during data transfer anyway and you get to handle this case.