Skip to content

testvectors: check exported private dh key matches x or clamped(x) - #1

Open
robinhundt wants to merge 1 commit into
robin/libcrux-add-p256-dh-providerfrom
robin/check-exported-key
Open

robinhundt wants to merge 1 commit into
robin/libcrux-add-p256-dh-providerfrom
robin/check-exported-key

Conversation

@robinhundt

Copy link
Copy Markdown

Here I tried out the suggestion by @chrysn lake-rs#114 (comment) .

I'm not sure I like this approach. While it could catch an abnormal export implementation that would be permitted by the previous property, this feels a bit overcomplicated for the test.

Previously, I tried just testing exported == private_clamped_bytes.unwrap_or(private_bytes), but that failed for the rust-crypto backend, as it doesn't store the private key in the clamped form, as the implementation does the clamping internally. So the exported bytes there are the unclamped bytes.

I wonder whether the contract on import/export should maybe be tightened, so that it is guaranteed that they're idempotent. This would require a change in either the nrf or rust-crypto backend for these curves. The non-idempotency could easily trip people up, as it did for me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant