Commit graph

1 commit

Author SHA1 Message Date
631506d36f feat(crypto): constant-time RSA-PSS signing (rv2 9 phase G1a)
- bn_modexp_ct: constant-time modexp for the SECRET exponent — squares and
  multiplies every bit, selects the product with a mask (bn_cmov), so the
  op sequence is independent of d (the existing bn_modexp branches on the
  bit, fine only for the public e)
- wo_rsa_pss_sha256_sign: EMSA-PSS-ENCODE (RFC 8017 §9.1.1) + modexp with d;
  caller supplies the salt (fresh in production; fixed makes the KAT
  deterministic). Private key (n,d)
- KAT: deterministic sign vs a python from-spec oracle byte-for-byte
  (fixed salt), our sign round-trips through our verify, tamper rejected.
  test_crypto 108, ASan/UBSan clean

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit cf8fdfcc47b2b076b63b9c63bf56411615b0d6f9)
2026-09-15 01:15:52 +02:00