Side channel silent karatsuba / mpn_addmul_2 karatsuba

Torbjörn Granlund tg at
Sat Dec 15 14:37:07 UTC 2018

"Marco Bodrato" <bodrato at> writes:

  Are branches based on the _initial_ bit size allowed? Do we think that the
  multiplication will be used also for large enough numbers requiring more
  recursions of Karatsuba?

If we enable Karatsuba in sec_mul, then we should not leak for operands
which require Karatsuba to recurse into itself.

I'd say that we should preferably not leak the most significant bit's
position, as that could cause concerns for some callers.

Please encrypt, key id 0xC8601622

More information about the gmp-devel mailing list