Skip to main content

Module gf

Module gf 

Source
Expand description

Constant-time GF(2^8) arithmetic for AES.

The AES S-box is computed algebraically rather than read from a lookup table:

S(x)    = A · x^-1  ⊕ 0x63       (inversion, then the affine map)
S^-1(y) = (A^-1 · y ⊕ 0x05)^-1

with x^-1 = x^254 evaluated by square-and-multiply over the Rijndael field. Every operation is a branch-free bitwise sequence, so no secret ever reaches an address bus. That closes the cache-timing channel that table-based AES (the default in many portable C implementations) leaves open, at the cost of throughput — see the crate docs for the backend roadmap.

Functions§

inv
Multiplicative inverse in GF(2^8), with inv(0) == 0.
inv_sbox
The AES inverse S-box, computed in constant time.
mul
Constant-time multiplication in GF(2^8).
sbox
The AES forward S-box, computed in constant time.
xtime
x * 2 in GF(2^8), the AES xtime operation.