Skip to content

elliptic-curve: respect byte order when padding secret key slices - #2495

Open
fmtappendf wants to merge 1 commit into
RustCrypto:masterfrom
fmtappendf:master
Open

fmtappendf wants to merge 1 commit into
RustCrypto:masterfrom
fmtappendf:master

Conversation

@fmtappendf

Copy link
Copy Markdown

SecretKey::from_slice currently right-aligns short inputs before decoding them. This is correct for big-endian curves, but changes the numeric value for little-endian curves such as BIGN P-256.

For example, a 24-byte little-endian encoding of 1 is currently padded at an offset of 8 bytes and decoded as 1 << 64.

Pad short inputs at the most-significant end according to C::FIELD_ENDIANNESS: prepend zeroes for big-endian curves and append zeroes for little-endian curves.

Add a regression test using a little-endian mock curve.

Signed-off-by: fmtappendf <fmtappendf@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant