diff --git a/ChangeLog.d/harden-check-small-primes.txt b/ChangeLog.d/harden-check-small-primes.txt new file mode 100644 index 0000000000..7d04841811 --- /dev/null +++ b/ChangeLog.d/harden-check-small-primes.txt @@ -0,0 +1,5 @@ +Security + * Fix timing side channel in RSA key generation, prime generation and + primality testing, on platforms where division is not constant-time. At + this point this side channel is not known to be exploitable. Reported by + Bhargava Shastry, Ethereum Foundation. diff --git a/library/bignum.c b/library/bignum.c index f6b8f99981..5ba85daecc 100644 --- a/library/bignum.c +++ b/library/bignum.c @@ -2059,6 +2059,25 @@ int mbedtls_mpi_inv_mod(mbedtls_mpi *X, const mbedtls_mpi *A, const mbedtls_mpi #if defined(MBEDTLS_GENPRIME) +/* Product of small primes up to 997 included */ +static const mbedtls_mpi_sint small_primes_limit = 997; +static const unsigned char small_primes_product_bin[] = { + 0x05, 0xf0, 0x78, 0x61, 0x8e, 0x81, 0x21, 0xe1, 0xf0, 0xc5, 0x8a, 0xf3, + 0xf5, 0xc7, 0xea, 0x54, 0xbf, 0x9d, 0x72, 0x52, 0xd3, 0x0b, 0xa9, 0xf7, + 0xf2, 0xcb, 0x32, 0xc7, 0x69, 0x02, 0x6d, 0xe4, 0x48, 0xa9, 0x66, 0x72, + 0x7b, 0x6a, 0x2f, 0xf9, 0x8f, 0x3a, 0xf2, 0x3d, 0x78, 0x6c, 0xf7, 0x03, + 0xb4, 0xe6, 0x11, 0xac, 0xf6, 0xa8, 0xd9, 0xe8, 0x3b, 0x38, 0x7d, 0x1c, + 0x20, 0xdf, 0xd8, 0xd5, 0x92, 0xe4, 0x0d, 0x19, 0x14, 0x35, 0xe3, 0xb5, + 0x00, 0x68, 0x84, 0xce, 0x6d, 0x32, 0xbc, 0xa2, 0x0d, 0x62, 0x80, 0xe0, + 0x17, 0xe1, 0x37, 0x85, 0x7a, 0xfc, 0x66, 0x1d, 0xf0, 0x45, 0x05, 0xfc, + 0xa2, 0x31, 0xe5, 0x0c, 0x83, 0xa2, 0x46, 0x67, 0x43, 0x3a, 0x54, 0xf1, + 0x4a, 0xe0, 0x57, 0x07, 0x34, 0xf4, 0x3e, 0x41, 0x39, 0x9d, 0x61, 0x8a, + 0x96, 0x5d, 0xc9, 0x77, 0x8d, 0xe5, 0xe8, 0x18, 0x99, 0x1d, 0x8c, 0xc2, + 0xad, 0xfb, 0x89, 0xbb, 0xfb, 0x2c, 0xba, 0x37, 0xdb, 0xbf, 0xd5, 0xa8, + 0x30, 0xfb, 0x79, 0x35, 0xfc, 0x65, 0x61, 0xf5, 0xc0, 0xdf, 0xd6, 0x18, + 0x9d, 0x7b, 0x9f, 0xa4, 0x20, 0xa4, 0x10, 0x2c, 0xa7, 0x95, 0xdf, 0xd0, + 0xbb, 0x97, 0x6a, 0x13, 0x4b, +}; /* Gaps between primes, starting at 3. https://oeis.org/A001223 */ static const unsigned char small_prime_gaps[] = { 2, 2, 4, 2, 4, 2, 4, 6, @@ -2097,26 +2116,46 @@ static const unsigned char small_prime_gaps[] = { static int mpi_check_small_factors(const mbedtls_mpi *X) { int ret = 0; - size_t i; - mbedtls_mpi_uint r; - unsigned p = 3; /* The first odd prime */ + mbedtls_mpi prod, g; + + mbedtls_mpi_init(&prod); + mbedtls_mpi_init(&g); if ((X->p[0] & 1) == 0) { return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE; } - for (i = 0; i < sizeof(small_prime_gaps); p += small_prime_gaps[i], i++) { - MBEDTLS_MPI_CHK(mbedtls_mpi_mod_int(&r, X, p)); - if (r == 0) { + /* The GCD test below only works if X > small_primes_limit. */ + if (mbedtls_mpi_cmp_int(X, small_primes_limit) <= 0) { + unsigned p = 3; + for (size_t i = 0; i < sizeof(small_prime_gaps); i++) { if (mbedtls_mpi_cmp_int(X, p) == 0) { return 1; - } else { - return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE; } + p += small_prime_gaps[i]; } + return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE; + } + + MBEDTLS_MPI_CHK(mbedtls_mpi_read_binary(&prod, small_primes_product_bin, + sizeof(small_primes_product_bin))); + + /* We can't directly use mbedtls_mpi_gcd_modinv_odd() because we don't know + * if X is larger than prod or not (prod is 1379 bits). So, use this generic + * wrapper - it does a bit more than what we need (handles even inputs as + * well, while we know our inputs are both odd), but that's OK. */ + MBEDTLS_MPI_CHK(mbedtls_mpi_gcd(&g, &prod, X)); + + if (mbedtls_mpi_cmp_int(&g, 1) == 0) { + /* X is not divisible by a small prime */ + ret = 0; + } else { + ret = MBEDTLS_ERR_MPI_NOT_ACCEPTABLE; } cleanup: + mbedtls_mpi_free(&prod); + mbedtls_mpi_free(&g); return ret; }