Skip to content
  1. Jul 12, 2018
  2. Jul 11, 2018
  3. Jul 10, 2018
  4. Jul 06, 2018
  5. Jul 04, 2018
  6. Jul 03, 2018
  7. Jul 02, 2018
  8. Jul 01, 2018
  9. Jun 29, 2018
  10. Jun 28, 2018
  11. Jun 25, 2018
  12. Jun 24, 2018
  13. Jun 23, 2018
  14. Jun 22, 2018
  15. Jun 21, 2018
  16. Jun 18, 2018
  17. Jun 15, 2018
  18. Jun 13, 2018
    • Matt Caswell's avatar
      Add blinding to an ECDSA signature · 0c27d793
      Matt Caswell authored
      
      
      Keegan Ryan (NCC Group) has demonstrated a side channel attack on an
      ECDSA signature operation. During signing the signer calculates:
      
      s:= k^-1 * (m + r * priv_key) mod order
      
      The addition operation above provides a sufficient signal for a
      flush+reload attack to derive the private key given sufficient signature
      operations.
      
      As a mitigation (based on a suggestion from Keegan) we add blinding to
      the operation so that:
      
      s := k^-1 * blind^-1 (blind * m + blind * r * priv_key) mod order
      
      Since this attack is a localhost side channel only no CVE is assigned.
      
      Reviewed-by: default avatarRich Salz <rsalz@openssl.org>
      0c27d793
  19. Jun 12, 2018
  20. Jun 11, 2018