Expand description
Constant-time primitives.
Every routine here executes in time independent of the values of its
secret inputs (lengths are considered public). The implementations avoid
branches and table lookups on secret data, and pass results through
core::hint::black_box to stop the optimizer from re-introducing a branch
when it proves a value is boolean.
Structs§
- Choice
- A branch-free boolean whose value is never observable through control flow.
Functions§
- cmov
- Copy
srcoverdstonly whencis true, in constant time. - cswap
- Conditionally swap two equal-length buffers in constant time.
- eq
- Constant-time equality over two byte slices.
- is_zero
- Constant-time check that every byte of
xis zero. - lt_be
- Constant-time
a < bover big-endian byte strings of equal length. - select_
u8 - Branch-free select: returns
awhencis true, otherwiseb. - select_
u32 - Branch-free select over
u32. - select_
u64 - Branch-free select over
u64. - verify
- Constant-time byte-slice comparison returning a plain
bool.