You can write constant time code in Rust by carefully making sure your code only compiles to constant time instructions without branches, but you'd really want some kind of annotation on the code to enforce that.
That's mostly a guess though.
You can write constant time code in Rust by carefully making sure your code only compiles to constant time instructions without branches, but you'd really want some kind of annotation on the code to enforce that.
That's mostly a guess though.
Is it correct to say: "all branchless code runs in constant time, but not all constant time code is branchless"?
I'm an attacker doing targeted research. I want to see if a multi-auth system has an association between two email addresses tied to the same account.
Pulling a database record or in-memory record (e.g. via LFU/LRU cache) in some cases may cache the account record, which means a subsequent record might be warm when fetched with the second email.
I run a time analysis against the endpoint with garbage addresses, known addresses (that I've set up) and the two target addresses to check subsequent fetch speeds.
In some cases, this will cause enough of a time difference to tell me if there's a connection.
Timing attacks are hard, and even a well-architected system can expose information indirectly. Encryption is a bit one if the inputs are static (e.g. keys or the like) and are a common way to target endpoints.
Writing truly constant time code on modern processors ranges is difficult at best, and usually less efficient than variable-time code.
No - e.g. division is not constant time.
You have to have branchless code and only use certain instructions.
E.g. here is the list for RISC-V.
https://github.com/rvkrypto/riscv-zkt-list/blob/main/zkt-lis...
Most things except div/rem, branches and floating point are ok. Oh and obviously store/load.