Skip to main content

Module ct

Module ct 

Source
Expand description

Constant-time primitives.

Every routine here executes in time independent of the values of its secret inputs (lengths are considered public). The implementations avoid branches and table lookups on secret data, and pass results through core::hint::black_box to stop the optimizer from re-introducing a branch when it proves a value is boolean.

Structs§

Choice
A branch-free boolean whose value is never observable through control flow.

Functions§

cmov
Copy src over dst only when c is true, in constant time.
cswap
Conditionally swap two equal-length buffers in constant time.
eq
Constant-time equality over two byte slices.
is_zero
Constant-time check that every byte of x is zero.
lt_be
Constant-time a < b over big-endian byte strings of equal length.
select_u8
Branch-free select: returns a when c is true, otherwise b.
select_u32
Branch-free select over u32.
select_u64
Branch-free select over u64.
verify
Constant-time byte-slice comparison returning a plain bool.