Skip to content

elliptic-curve: add Invert trait - #228

Merged
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait
Jul 28, 2020
Merged

elliptic-curve: add Invert trait#228
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait

Conversation

@tarcieri

Copy link
Copy Markdown
Member

Add a trait for performing scalar/field inversions.

The main motivation for this is to allow for things like BlindedScalar type which use random blinding for either efficiency reasons (to allow a vartime inversion) and/or as a side-channel defense.

@tarcieri
tarcieri requested a review from nickrayJuly 28, 2020 16:41
@tarcieri

tarcieri commented Jul 28, 2020

Copy link
Copy Markdown
MemberAuthor

@nickray FYI, my intended use for this is to remove masking_scalar from the SignPrimitive API.

Instead we can have something like a BlindedScalar type constructed from a Scalar and a CryptoRng which supports an Into<Scalar> conversion, but whose Invert::invert() impl can use the vartime inversion. If we have that, it can be passed in lieu of a Scalar as the ephemeral_scalar.

I think if we prototype that in the p256 crate, we could potentially hoist it into this crate and have a generic BlindedScalar implementation that works with any curve.

Add a trait for performing scalar/field inversions.
The main motivation for this is to allow for things like `BlindedScalar`
type which use random blinding for either efficiency reasons (to allow a
vartime inversion) and/or as a side-channel defense.
@tarcieri
tarcieriforce-pushed the elliptic-curve/invert-trait branch from 4d38482 to 151058aCompareJuly 28, 2020 16:47
@tarcieri
tarcieri merged commit f8a916b into masterJul 28, 2020
@tarcieri
tarcieri deleted the elliptic-curve/invert-trait branch July 28, 2020 16:50
@nickray

Copy link
Copy Markdown
Member

The intended use is an interesting approach - I like it!

So far I never used any RNG traits (felt too implicit, I like to see exactly where entropy is consumed), but would be interested to see how you'd do this! Oh and my last attempt at field traits failed too 😅.

@nickray

nickray commented Jul 28, 2020

Copy link
Copy Markdown
Member

I wonder how, for practical purposes, this CtOption approach compares to restricting the domain of this trait to just invertible elements?

@tarcieri

Copy link
Copy Markdown
MemberAuthor

I didn't put a whole lot of thought into this trait and for me it's mostly it's a means to an end for implementing RustCrypto/elliptic-curves#99

It's mostly a trait extraction of what exists in the p256 and k256 codebases, for both Scalar and FieldElement. I only impl'd it on the former, since that's all I care about for RustCrypto/elliptic-curves#99

I'll make a note of it in RustCrypto/elliptic-curves#22 as I'm sure there's some prior art here I've overlooked (or potentially another crate we can source the trait from).

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@nickray
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
elliptic-curve: add `Invert` trait by tarcieri · Pull Request #228 · RustCrypto/traits · GitHub
Skip to content

elliptic-curve: add Invert trait - #228

Merged
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait
Jul 28, 2020
Merged

elliptic-curve: add Invert trait#228
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait

Conversation

@tarcieri

Copy link
Copy Markdown
Member

Add a trait for performing scalar/field inversions.

The main motivation for this is to allow for things like BlindedScalar type which use random blinding for either efficiency reasons (to allow a vartime inversion) and/or as a side-channel defense.

@tarcieri
tarcieri requested a review from nickrayJuly 28, 2020 16:41
@tarcieri

tarcieri commented Jul 28, 2020

Copy link
Copy Markdown
MemberAuthor

@nickray FYI, my intended use for this is to remove masking_scalar from the SignPrimitive API.

Instead we can have something like a BlindedScalar type constructed from a Scalar and a CryptoRng which supports an Into<Scalar> conversion, but whose Invert::invert() impl can use the vartime inversion. If we have that, it can be passed in lieu of a Scalar as the ephemeral_scalar.

I think if we prototype that in the p256 crate, we could potentially hoist it into this crate and have a generic BlindedScalar implementation that works with any curve.

Add a trait for performing scalar/field inversions.
The main motivation for this is to allow for things like `BlindedScalar`
type which use random blinding for either efficiency reasons (to allow a
vartime inversion) and/or as a side-channel defense.
@tarcieri
tarcieriforce-pushed the elliptic-curve/invert-trait branch from 4d38482 to 151058aCompareJuly 28, 2020 16:47
@tarcieri
tarcieri merged commit f8a916b into masterJul 28, 2020
@tarcieri
tarcieri deleted the elliptic-curve/invert-trait branch July 28, 2020 16:50
@nickray

Copy link
Copy Markdown
Member

The intended use is an interesting approach - I like it!

So far I never used any RNG traits (felt too implicit, I like to see exactly where entropy is consumed), but would be interested to see how you'd do this! Oh and my last attempt at field traits failed too 😅.

@nickray

nickray commented Jul 28, 2020

Copy link
Copy Markdown
Member

I wonder how, for practical purposes, this CtOption approach compares to restricting the domain of this trait to just invertible elements?

@tarcieri

Copy link
Copy Markdown
MemberAuthor

I didn't put a whole lot of thought into this trait and for me it's mostly it's a means to an end for implementing RustCrypto/elliptic-curves#99

It's mostly a trait extraction of what exists in the p256 and k256 codebases, for both Scalar and FieldElement. I only impl'd it on the former, since that's all I care about for RustCrypto/elliptic-curves#99

I'll make a note of it in RustCrypto/elliptic-curves#22 as I'm sure there's some prior art here I've overlooked (or potentially another crate we can source the trait from).

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@nickray
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' elliptic-curve: add `Invert` trait by tarcieri · Pull Request #228 · RustCrypto/traits · GitHub
Skip to content

elliptic-curve: add Invert trait - #228

Merged
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait
Jul 28, 2020
Merged

elliptic-curve: add Invert trait#228
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait

Conversation

@tarcieri

Copy link
Copy Markdown
Member

Add a trait for performing scalar/field inversions.

The main motivation for this is to allow for things like BlindedScalar type which use random blinding for either efficiency reasons (to allow a vartime inversion) and/or as a side-channel defense.

@tarcieri
tarcieri requested a review from nickrayJuly 28, 2020 16:41
@tarcieri

tarcieri commented Jul 28, 2020

Copy link
Copy Markdown
MemberAuthor

@nickray FYI, my intended use for this is to remove masking_scalar from the SignPrimitive API.

Instead we can have something like a BlindedScalar type constructed from a Scalar and a CryptoRng which supports an Into<Scalar> conversion, but whose Invert::invert() impl can use the vartime inversion. If we have that, it can be passed in lieu of a Scalar as the ephemeral_scalar.

I think if we prototype that in the p256 crate, we could potentially hoist it into this crate and have a generic BlindedScalar implementation that works with any curve.

Add a trait for performing scalar/field inversions.
The main motivation for this is to allow for things like `BlindedScalar`
type which use random blinding for either efficiency reasons (to allow a
vartime inversion) and/or as a side-channel defense.
@tarcieri
tarcieriforce-pushed the elliptic-curve/invert-trait branch from 4d38482 to 151058aCompareJuly 28, 2020 16:47
@tarcieri
tarcieri merged commit f8a916b into masterJul 28, 2020
@tarcieri
tarcieri deleted the elliptic-curve/invert-trait branch July 28, 2020 16:50
@nickray

Copy link
Copy Markdown
Member

The intended use is an interesting approach - I like it!

So far I never used any RNG traits (felt too implicit, I like to see exactly where entropy is consumed), but would be interested to see how you'd do this! Oh and my last attempt at field traits failed too 😅.

@nickray

nickray commented Jul 28, 2020

Copy link
Copy Markdown
Member

I wonder how, for practical purposes, this CtOption approach compares to restricting the domain of this trait to just invertible elements?

@tarcieri

Copy link
Copy Markdown
MemberAuthor

I didn't put a whole lot of thought into this trait and for me it's mostly it's a means to an end for implementing RustCrypto/elliptic-curves#99

It's mostly a trait extraction of what exists in the p256 and k256 codebases, for both Scalar and FieldElement. I only impl'd it on the former, since that's all I care about for RustCrypto/elliptic-curves#99

I'll make a note of it in RustCrypto/elliptic-curves#22 as I'm sure there's some prior art here I've overlooked (or potentially another crate we can source the trait from).

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@nickray
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' elliptic-curve: add `Invert` trait by tarcieri · Pull Request #228 · RustCrypto/traits · GitHub
Skip to content

elliptic-curve: add Invert trait - #228

Merged
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait
Jul 28, 2020
Merged

elliptic-curve: add Invert trait#228
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait

Conversation

@tarcieri

Copy link
Copy Markdown
Member

Add a trait for performing scalar/field inversions.

The main motivation for this is to allow for things like BlindedScalar type which use random blinding for either efficiency reasons (to allow a vartime inversion) and/or as a side-channel defense.

@tarcieri
tarcieri requested a review from nickrayJuly 28, 2020 16:41
@tarcieri

tarcieri commented Jul 28, 2020

Copy link
Copy Markdown
MemberAuthor

@nickray FYI, my intended use for this is to remove masking_scalar from the SignPrimitive API.

Instead we can have something like a BlindedScalar type constructed from a Scalar and a CryptoRng which supports an Into<Scalar> conversion, but whose Invert::invert() impl can use the vartime inversion. If we have that, it can be passed in lieu of a Scalar as the ephemeral_scalar.

I think if we prototype that in the p256 crate, we could potentially hoist it into this crate and have a generic BlindedScalar implementation that works with any curve.

Add a trait for performing scalar/field inversions.
The main motivation for this is to allow for things like `BlindedScalar`
type which use random blinding for either efficiency reasons (to allow a
vartime inversion) and/or as a side-channel defense.
@tarcieri
tarcieriforce-pushed the elliptic-curve/invert-trait branch from 4d38482 to 151058aCompareJuly 28, 2020 16:47
@tarcieri
tarcieri merged commit f8a916b into masterJul 28, 2020
@tarcieri
tarcieri deleted the elliptic-curve/invert-trait branch July 28, 2020 16:50
@nickray

Copy link
Copy Markdown
Member

The intended use is an interesting approach - I like it!

So far I never used any RNG traits (felt too implicit, I like to see exactly where entropy is consumed), but would be interested to see how you'd do this! Oh and my last attempt at field traits failed too 😅.

@nickray

nickray commented Jul 28, 2020

Copy link
Copy Markdown
Member

I wonder how, for practical purposes, this CtOption approach compares to restricting the domain of this trait to just invertible elements?

@tarcieri

Copy link
Copy Markdown
MemberAuthor

I didn't put a whole lot of thought into this trait and for me it's mostly it's a means to an end for implementing RustCrypto/elliptic-curves#99

It's mostly a trait extraction of what exists in the p256 and k256 codebases, for both Scalar and FieldElement. I only impl'd it on the former, since that's all I care about for RustCrypto/elliptic-curves#99

I'll make a note of it in RustCrypto/elliptic-curves#22 as I'm sure there's some prior art here I've overlooked (or potentially another crate we can source the trait from).

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@nickray
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' elliptic-curve: add `Invert` trait by tarcieri · Pull Request #228 · RustCrypto/traits · GitHub
Skip to content

elliptic-curve: add Invert trait - #228

Merged
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait
Jul 28, 2020
Merged

elliptic-curve: add Invert trait#228
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait

Conversation

@tarcieri

Copy link
Copy Markdown
Member

Add a trait for performing scalar/field inversions.

The main motivation for this is to allow for things like BlindedScalar type which use random blinding for either efficiency reasons (to allow a vartime inversion) and/or as a side-channel defense.

@tarcieri
tarcieri requested a review from nickrayJuly 28, 2020 16:41
@tarcieri

tarcieri commented Jul 28, 2020

Copy link
Copy Markdown
MemberAuthor

@nickray FYI, my intended use for this is to remove masking_scalar from the SignPrimitive API.

Instead we can have something like a BlindedScalar type constructed from a Scalar and a CryptoRng which supports an Into<Scalar> conversion, but whose Invert::invert() impl can use the vartime inversion. If we have that, it can be passed in lieu of a Scalar as the ephemeral_scalar.

I think if we prototype that in the p256 crate, we could potentially hoist it into this crate and have a generic BlindedScalar implementation that works with any curve.

Add a trait for performing scalar/field inversions.
The main motivation for this is to allow for things like `BlindedScalar`
type which use random blinding for either efficiency reasons (to allow a
vartime inversion) and/or as a side-channel defense.
@tarcieri
tarcieriforce-pushed the elliptic-curve/invert-trait branch from 4d38482 to 151058aCompareJuly 28, 2020 16:47
@tarcieri
tarcieri merged commit f8a916b into masterJul 28, 2020
@tarcieri
tarcieri deleted the elliptic-curve/invert-trait branch July 28, 2020 16:50
@nickray

Copy link
Copy Markdown
Member

The intended use is an interesting approach - I like it!

So far I never used any RNG traits (felt too implicit, I like to see exactly where entropy is consumed), but would be interested to see how you'd do this! Oh and my last attempt at field traits failed too 😅.

@nickray

nickray commented Jul 28, 2020

Copy link
Copy Markdown
Member

I wonder how, for practical purposes, this CtOption approach compares to restricting the domain of this trait to just invertible elements?

@tarcieri

Copy link
Copy Markdown
MemberAuthor

I didn't put a whole lot of thought into this trait and for me it's mostly it's a means to an end for implementing RustCrypto/elliptic-curves#99

It's mostly a trait extraction of what exists in the p256 and k256 codebases, for both Scalar and FieldElement. I only impl'd it on the former, since that's all I care about for RustCrypto/elliptic-curves#99

I'll make a note of it in RustCrypto/elliptic-curves#22 as I'm sure there's some prior art here I've overlooked (or potentially another crate we can source the trait from).

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@nickray
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' elliptic-curve: add `Invert` trait by tarcieri · Pull Request #228 · RustCrypto/traits · GitHub
Skip to content

elliptic-curve: add Invert trait - #228

Merged
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait
Jul 28, 2020
Merged

elliptic-curve: add Invert trait#228
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait

Conversation

@tarcieri

Copy link
Copy Markdown
Member

Add a trait for performing scalar/field inversions.

The main motivation for this is to allow for things like BlindedScalar type which use random blinding for either efficiency reasons (to allow a vartime inversion) and/or as a side-channel defense.

@tarcieri
tarcieri requested a review from nickrayJuly 28, 2020 16:41
@tarcieri

tarcieri commented Jul 28, 2020

Copy link
Copy Markdown
MemberAuthor

@nickray FYI, my intended use for this is to remove masking_scalar from the SignPrimitive API.

Instead we can have something like a BlindedScalar type constructed from a Scalar and a CryptoRng which supports an Into<Scalar> conversion, but whose Invert::invert() impl can use the vartime inversion. If we have that, it can be passed in lieu of a Scalar as the ephemeral_scalar.

I think if we prototype that in the p256 crate, we could potentially hoist it into this crate and have a generic BlindedScalar implementation that works with any curve.

Add a trait for performing scalar/field inversions.
The main motivation for this is to allow for things like `BlindedScalar`
type which use random blinding for either efficiency reasons (to allow a
vartime inversion) and/or as a side-channel defense.
@tarcieri
tarcieriforce-pushed the elliptic-curve/invert-trait branch from 4d38482 to 151058aCompareJuly 28, 2020 16:47
@tarcieri
tarcieri merged commit f8a916b into masterJul 28, 2020
@tarcieri
tarcieri deleted the elliptic-curve/invert-trait branch July 28, 2020 16:50
@nickray

Copy link
Copy Markdown
Member

The intended use is an interesting approach - I like it!

So far I never used any RNG traits (felt too implicit, I like to see exactly where entropy is consumed), but would be interested to see how you'd do this! Oh and my last attempt at field traits failed too 😅.

@nickray

nickray commented Jul 28, 2020

Copy link
Copy Markdown
Member

I wonder how, for practical purposes, this CtOption approach compares to restricting the domain of this trait to just invertible elements?

@tarcieri

Copy link
Copy Markdown
MemberAuthor

I didn't put a whole lot of thought into this trait and for me it's mostly it's a means to an end for implementing RustCrypto/elliptic-curves#99

It's mostly a trait extraction of what exists in the p256 and k256 codebases, for both Scalar and FieldElement. I only impl'd it on the former, since that's all I care about for RustCrypto/elliptic-curves#99

I'll make a note of it in RustCrypto/elliptic-curves#22 as I'm sure there's some prior art here I've overlooked (or potentially another crate we can source the trait from).

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@nickray
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); elliptic-curve: add `Invert` trait by tarcieri · Pull Request #228 · RustCrypto/traits · GitHub
Skip to content

elliptic-curve: add Invert trait - #228

Merged
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait
Jul 28, 2020
Merged

elliptic-curve: add Invert trait#228
tarcieri merged 1 commit into
masterfrom
elliptic-curve/invert-trait

Conversation

@tarcieri

Copy link
Copy Markdown
Member

Add a trait for performing scalar/field inversions.

The main motivation for this is to allow for things like BlindedScalar type which use random blinding for either efficiency reasons (to allow a vartime inversion) and/or as a side-channel defense.

@tarcieri
tarcieri requested a review from nickrayJuly 28, 2020 16:41
@tarcieri

tarcieri commented Jul 28, 2020

Copy link
Copy Markdown
MemberAuthor

@nickray FYI, my intended use for this is to remove masking_scalar from the SignPrimitive API.

Instead we can have something like a BlindedScalar type constructed from a Scalar and a CryptoRng which supports an Into<Scalar> conversion, but whose Invert::invert() impl can use the vartime inversion. If we have that, it can be passed in lieu of a Scalar as the ephemeral_scalar.

I think if we prototype that in the p256 crate, we could potentially hoist it into this crate and have a generic BlindedScalar implementation that works with any curve.

Add a trait for performing scalar/field inversions.
The main motivation for this is to allow for things like `BlindedScalar`
type which use random blinding for either efficiency reasons (to allow a
vartime inversion) and/or as a side-channel defense.
@tarcieri
tarcieriforce-pushed the elliptic-curve/invert-trait branch from 4d38482 to 151058aCompareJuly 28, 2020 16:47
@tarcieri
tarcieri merged commit f8a916b into masterJul 28, 2020
@tarcieri
tarcieri deleted the elliptic-curve/invert-trait branch July 28, 2020 16:50
@nickray

Copy link
Copy Markdown
Member

The intended use is an interesting approach - I like it!

So far I never used any RNG traits (felt too implicit, I like to see exactly where entropy is consumed), but would be interested to see how you'd do this! Oh and my last attempt at field traits failed too 😅.

@nickray

nickray commented Jul 28, 2020

Copy link
Copy Markdown
Member

I wonder how, for practical purposes, this CtOption approach compares to restricting the domain of this trait to just invertible elements?

@tarcieri

Copy link
Copy Markdown
MemberAuthor

I didn't put a whole lot of thought into this trait and for me it's mostly it's a means to an end for implementing RustCrypto/elliptic-curves#99

It's mostly a trait extraction of what exists in the p256 and k256 codebases, for both Scalar and FieldElement. I only impl'd it on the former, since that's all I care about for RustCrypto/elliptic-curves#99

I'll make a note of it in RustCrypto/elliptic-curves#22 as I'm sure there's some prior art here I've overlooked (or potentially another crate we can source the trait from).

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@nickray