Fast constant-time gcd computation and modular inversion

Torbjörn Granlund tg at
Sun Sep 4 10:03:04 CEST 2022

Marco Bodrato <bodrato at> writes:

  We should start writing mpn_sec_binvert :-)

I think mpn_binvert is almost sec_ naturally.

The exception is when sbpi1_bdiv_q.or dbpi1_bdiv_q c are invoked.  The
former has some < on data (for carry computations) and the latter has a
mpn_incr_u which is very leaky.

Please encrypt, key id 0xC8601622

More information about the gmp-devel mailing list