3 ms·
OpenSSL has a GCM implementation which is very fast and I believe is not susceptible to timing attacks due to using vpclmulqdq: http://git.openssl.org/gitweb/?p
by sweis 13y ago
OpenSSL has a GCM implementation which is very fast and I believe is not susceptible to timing attacks due to using vpclmulqdq:
http://git.openssl.org/gitweb/?p=openssl.git;a=blob;f=crypto/modes/asm/aesni-gcm-x86_64.pl;h=3781933917227dd127352fa8d7d066804dacba13;hb=HEAD http://git.openssl.org/gitweb/?p=openssl.git;a=blob;f=crypto...
You can debate whether it's a "software implementation" since it's using AESNI and PCLMULQDQ.
- tptacek 13y agoI think PCLMULQDQ is noncontroversial, but also considered "hardware supported".