Expand description
Constant-time GF(2^8) arithmetic for AES.
The AES S-box is computed algebraically rather than read from a lookup table:
S(x) = A · x^-1 ⊕ 0x63 (inversion, then the affine map)
S^-1(y) = (A^-1 · y ⊕ 0x05)^-1with x^-1 = x^254 evaluated by square-and-multiply over the Rijndael
field. Every operation is a branch-free bitwise sequence, so no secret ever
reaches an address bus. That closes the cache-timing channel that table-based
AES (the default in many portable C implementations) leaves open.
What is here is the byte-at-a-time form. It still runs AES decryption and
the key schedule, but encryption goes through crate::aes::bitslice,
which does the same algebra for sixty-four bytes at once and is some forty
times faster for it.
Functions§
- inv
- Multiplicative inverse in GF(2^8), with
inv(0) == 0. - inv_
sbox - The AES inverse S-box, computed in constant time.
- mul
- Constant-time multiplication in GF(2^8).
- sbox
- The AES forward S-box, computed in constant time.
- square
x * xin GF(2^8), without the bit-serial loop.- xtime
x * 2in GF(2^8), the AESxtimeoperation.