mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-10-02 23:17:23 +00:00
Fix side-channel in prime checking/generation
Signed-off-by: Manuel Pégourié-Gonnard <[email protected]>
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
Security
|
||||
* Fix timing side channel in RSA key generation, prime generation and
|
||||
primality testing, on platforms where division is not constant-time. At
|
||||
this point this side channel is not known to be exploitable. Reported by
|
||||
Bhargava Shastry, Ethereum Foundation.
|
||||
+47
-8
@@ -2059,6 +2059,25 @@ int mbedtls_mpi_inv_mod(mbedtls_mpi *X, const mbedtls_mpi *A, const mbedtls_mpi
|
||||
|
||||
#if defined(MBEDTLS_GENPRIME)
|
||||
|
||||
/* Product of small primes up to 997 included */
|
||||
static const mbedtls_mpi_sint small_primes_limit = 997;
|
||||
static const unsigned char small_primes_product_bin[] = {
|
||||
0x05, 0xf0, 0x78, 0x61, 0x8e, 0x81, 0x21, 0xe1, 0xf0, 0xc5, 0x8a, 0xf3,
|
||||
0xf5, 0xc7, 0xea, 0x54, 0xbf, 0x9d, 0x72, 0x52, 0xd3, 0x0b, 0xa9, 0xf7,
|
||||
0xf2, 0xcb, 0x32, 0xc7, 0x69, 0x02, 0x6d, 0xe4, 0x48, 0xa9, 0x66, 0x72,
|
||||
0x7b, 0x6a, 0x2f, 0xf9, 0x8f, 0x3a, 0xf2, 0x3d, 0x78, 0x6c, 0xf7, 0x03,
|
||||
0xb4, 0xe6, 0x11, 0xac, 0xf6, 0xa8, 0xd9, 0xe8, 0x3b, 0x38, 0x7d, 0x1c,
|
||||
0x20, 0xdf, 0xd8, 0xd5, 0x92, 0xe4, 0x0d, 0x19, 0x14, 0x35, 0xe3, 0xb5,
|
||||
0x00, 0x68, 0x84, 0xce, 0x6d, 0x32, 0xbc, 0xa2, 0x0d, 0x62, 0x80, 0xe0,
|
||||
0x17, 0xe1, 0x37, 0x85, 0x7a, 0xfc, 0x66, 0x1d, 0xf0, 0x45, 0x05, 0xfc,
|
||||
0xa2, 0x31, 0xe5, 0x0c, 0x83, 0xa2, 0x46, 0x67, 0x43, 0x3a, 0x54, 0xf1,
|
||||
0x4a, 0xe0, 0x57, 0x07, 0x34, 0xf4, 0x3e, 0x41, 0x39, 0x9d, 0x61, 0x8a,
|
||||
0x96, 0x5d, 0xc9, 0x77, 0x8d, 0xe5, 0xe8, 0x18, 0x99, 0x1d, 0x8c, 0xc2,
|
||||
0xad, 0xfb, 0x89, 0xbb, 0xfb, 0x2c, 0xba, 0x37, 0xdb, 0xbf, 0xd5, 0xa8,
|
||||
0x30, 0xfb, 0x79, 0x35, 0xfc, 0x65, 0x61, 0xf5, 0xc0, 0xdf, 0xd6, 0x18,
|
||||
0x9d, 0x7b, 0x9f, 0xa4, 0x20, 0xa4, 0x10, 0x2c, 0xa7, 0x95, 0xdf, 0xd0,
|
||||
0xbb, 0x97, 0x6a, 0x13, 0x4b,
|
||||
};
|
||||
/* Gaps between primes, starting at 3. https://oeis.org/A001223 */
|
||||
static const unsigned char small_prime_gaps[] = {
|
||||
2, 2, 4, 2, 4, 2, 4, 6,
|
||||
@@ -2097,26 +2116,46 @@ static const unsigned char small_prime_gaps[] = {
|
||||
static int mpi_check_small_factors(const mbedtls_mpi *X)
|
||||
{
|
||||
int ret = 0;
|
||||
size_t i;
|
||||
mbedtls_mpi_uint r;
|
||||
unsigned p = 3; /* The first odd prime */
|
||||
mbedtls_mpi prod, g;
|
||||
|
||||
mbedtls_mpi_init(&prod);
|
||||
mbedtls_mpi_init(&g);
|
||||
|
||||
if ((X->p[0] & 1) == 0) {
|
||||
return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE;
|
||||
}
|
||||
|
||||
for (i = 0; i < sizeof(small_prime_gaps); p += small_prime_gaps[i], i++) {
|
||||
MBEDTLS_MPI_CHK(mbedtls_mpi_mod_int(&r, X, p));
|
||||
if (r == 0) {
|
||||
/* The GCD test below only works if X > small_primes_limit. */
|
||||
if (mbedtls_mpi_cmp_int(X, small_primes_limit) <= 0) {
|
||||
unsigned p = 3;
|
||||
for (size_t i = 0; i < sizeof(small_prime_gaps); i++) {
|
||||
if (mbedtls_mpi_cmp_int(X, p) == 0) {
|
||||
return 1;
|
||||
} else {
|
||||
return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE;
|
||||
}
|
||||
p += small_prime_gaps[i];
|
||||
}
|
||||
return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE;
|
||||
}
|
||||
|
||||
MBEDTLS_MPI_CHK(mbedtls_mpi_read_binary(&prod, small_primes_product_bin,
|
||||
sizeof(small_primes_product_bin)));
|
||||
|
||||
/* We can't directly use mbedtls_mpi_gcd_modinv_odd() because we don't know
|
||||
* if X is larger than prod or not (prod is 1379 bits). So, use this generic
|
||||
* wrapper - it does a bit more than what we need (handles even inputs as
|
||||
* well, while we know our inputs are both odd), but that's OK. */
|
||||
MBEDTLS_MPI_CHK(mbedtls_mpi_gcd(&g, &prod, X));
|
||||
|
||||
if (mbedtls_mpi_cmp_int(&g, 1) == 0) {
|
||||
/* X is not divisible by a small prime */
|
||||
ret = 0;
|
||||
} else {
|
||||
ret = MBEDTLS_ERR_MPI_NOT_ACCEPTABLE;
|
||||
}
|
||||
|
||||
cleanup:
|
||||
mbedtls_mpi_free(&prod);
|
||||
mbedtls_mpi_free(&g);
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user