Skip to main content

Module gf

Module gf 

Source
Expand description

Constant-time GF(2^8) arithmetic for AES.

The AES S-box is computed algebraically rather than read from a lookup table:

S(x)    = A · x^-1  ⊕ 0x63       (inversion, then the affine map)
S^-1(y) = (A^-1 · y ⊕ 0x05)^-1

with x^-1 = x^254 evaluated by square-and-multiply over the Rijndael field. Every operation is a branch-free bitwise sequence, so no secret ever reaches an address bus. That closes the cache-timing channel that table-based AES (the default in many portable C implementations) leaves open.

What is here is the byte-at-a-time form. It still runs AES decryption and the key schedule, but encryption goes through crate::aes::bitslice, which does the same algebra for sixty-four bytes at once and is some forty times faster for it.

Functions§

inv
Multiplicative inverse in GF(2^8), with inv(0) == 0.
inv_sbox
The AES inverse S-box, computed in constant time.
mul
Constant-time multiplication in GF(2^8).
sbox
The AES forward S-box, computed in constant time.
square
x * x in GF(2^8), without the bit-serial loop.
xtime
x * 2 in GF(2^8), the AES xtime operation.