pqc/crypto_kem
Douglas Stebila 96e5f1d7ae Fix timing leak in decapsulation.
As identified in: Qian Guo, Thomas Johansson, Alexander Nilsson. A 
key-recovery timing attack on post-quantum primitives using the 
Fujisaki-Okamoto transformation and its application on FrodoKEM. In 
CRYPTO 2020.

Based on 
155c24c3df
2021-03-24 21:02:46 +00:00
..
babybear Put all common primitives on the heap (#266) 2021-03-24 21:02:45 +00:00
babybear-ephem Put all common primitives on the heap (#266) 2021-03-24 21:02:45 +00:00
firesaber Clean up SABER 2021-03-24 21:02:46 +00:00
frodokem640aes Fix timing leak in decapsulation. 2021-03-24 21:02:46 +00:00
frodokem640shake Fix timing leak in decapsulation. 2021-03-24 21:02:46 +00:00
frodokem976aes Fix timing leak in decapsulation. 2021-03-24 21:02:46 +00:00
frodokem976shake Fix timing leak in decapsulation. 2021-03-24 21:02:46 +00:00
frodokem1344aes Fix timing leak in decapsulation. 2021-03-24 21:02:46 +00:00
frodokem1344shake Fix timing leak in decapsulation. 2021-03-24 21:02:46 +00:00
hqc-128-1-cca2 HQC submission (#202) 2021-03-24 21:02:46 +00:00
hqc-192-1-cca2 HQC submission (#202) 2021-03-24 21:02:46 +00:00
hqc-192-2-cca2 HQC submission (#202) 2021-03-24 21:02:46 +00:00
hqc-256-1-cca2 HQC submission (#202) 2021-03-24 21:02:46 +00:00
hqc-256-2-cca2 HQC submission (#202) 2021-03-24 21:02:46 +00:00
hqc-256-3-cca2 HQC submission (#202) 2021-03-24 21:02:46 +00:00
kyber512 Fix reduce.c's overflowing multiplication 2021-03-24 21:02:46 +00:00
kyber512-90s Use the right AES CTX 2021-03-24 21:02:46 +00:00
kyber768 Kyber768 and Kyber1024 don't need -maes (see #296) 2021-03-24 21:02:46 +00:00
kyber768-90s Use the right AES CTX 2021-03-24 21:02:46 +00:00
kyber1024 Kyber768 and Kyber1024 don't need -maes (see #296) 2021-03-24 21:02:46 +00:00
kyber1024-90s Use the right AES CTX 2021-03-24 21:02:46 +00:00
ledakemlt12 Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
ledakemlt32 Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
ledakemlt52 Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
lightsaber Clean up SABER 2021-03-24 21:02:46 +00:00
mamabear Put all common primitives on the heap (#266) 2021-03-24 21:02:45 +00:00
mamabear-ephem Put all common primitives on the heap (#266) 2021-03-24 21:02:45 +00:00
mceliece348864 Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece348864f Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece460896 Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece460896f Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece6688128 Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece6688128f Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece6960119 Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece6960119f Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece8192128 Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
mceliece8192128f Split aes*_keyexp up into ecb and ctr variants 2021-03-24 21:02:46 +00:00
newhope512cca Update KAT values 2021-03-24 21:02:46 +00:00
newhope512cpa Update KAT values 2021-03-24 21:02:46 +00:00
newhope1024cca Fix whitespace to satisfy test_duplicate_consistency 2021-03-24 21:02:46 +00:00
newhope1024cpa Update KAT values 2021-03-24 21:02:46 +00:00
ntruhps2048509 Enable optimizers on Windows (#244) 2019-10-21 14:23:59 +02:00
ntruhps2048677 Enable optimizers on Windows (#244) 2019-10-21 14:23:59 +02:00
ntruhps4096821 Enable optimizers on Windows (#244) 2019-10-21 14:23:59 +02:00
ntruhrss701 Fix overflowing mults in NTRUHRSS701 2021-03-24 21:02:46 +00:00
papabear Put all common primitives on the heap (#266) 2021-03-24 21:02:45 +00:00
papabear-ephem Put all common primitives on the heap (#266) 2021-03-24 21:02:45 +00:00
saber Clean up SABER 2021-03-24 21:02:46 +00:00