Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

kyber: remove division by q in ciphertext compression #468

Merged
merged 1 commit into from Jan 1, 2024
Merged

Commits on Dec 30, 2023

  1. kyber: remove division by q in ciphertext compression

    On some platforms, division by q leaks some information on the
    ciphertext by its timing. If a keypair is reused, and an attacker has access to
    a decapsulation oracle, this reveals information on the private key.
    This is known as "kyberslash2".
    
    Note that this does not affect to the typical ephemeral usage in TLS.
    bwesterb committed Dec 30, 2023
    Configuration menu
    Copy the full SHA
    2068787 View commit details
    Browse the repository at this point in the history