3 ms·
One whole technique not mentioned in the paper or comments is bitslicing. For non-branching code (e.g. symmetric ciphers) it's guaranteed constant-time and it w
by i2km 2y ago
One whole technique not mentioned in the paper or comments is bitslicing. For non-branching code (e.g. symmetric ciphers) it's guaranteed constant-time and it would be a remarkable compiler indeed which could introduce optimizations and timing variations to bit-sliced code...
- gavinhoward 2y agoThe author of the paper knows about bitslicing [1], so not mentioning it seems deliberate. My guess is that bitslicing only gets you so far. [1]: https://bearssl.org/constanttime.html#bitslicing https://bearssl.org/constanttime.html#bitslicing