Expand description
Constant-time GF(2^8) arithmetic for AES.
The AES S-box is computed algebraically rather than read from a lookup table:
S(x) = A · x^-1 ⊕ 0x63 (inversion, then the affine map)
S^-1(y) = (A^-1 · y ⊕ 0x05)^-1with x^-1 = x^254 evaluated by square-and-multiply over the Rijndael
field. Every operation is a branch-free bitwise sequence, so no secret ever
reaches an address bus. That closes the cache-timing channel that table-based
AES (the default in many portable C implementations) leaves open, at the cost
of throughput — see the crate docs for the backend roadmap.