3 ms·
Wow, that's some fantastic work!. Just to quote the conclusions of what Ben Hawkes found: Several previously undocumented header fields have been identified an
by mtnmts 12y ago
Wow, that's some fantastic work!.
Just to quote the conclusions of what Ben Hawkes found:
Several previously undocumented header fields have been identified and described.
The results suggest that microcode updates are authenticated using a 2048-bit RSA signature.
The RSA signature operation appears to be constant-time (i.e. unaffected by changes to the supplied exponent,
modulus or signature value).
Timing analysis reveals 512-bit steps correlating to supplied microcode length. This is a common message
block size for cryptographic hash functions such as SHA1 and SHA2
The RSA signature was located, and the signed data is a PKCS#1 1.5 encoded hash value. Older processor
models use a 160-bit digest (SHA1), and newer processor models use a 256-bit digest (SHA2).