|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Constant-time comparison for secret-dependent checks. More...
#include "protocore_config.h"Go to the source code of this file.
Constant-time comparison for secret-dependent checks.
One implementation, so every MAC, tag, digest and signature check in the library compares the same way. A second copy is a second chance to write the early-out version by accident, and an early-out compare is a timing oracle no test catches.
Zeroing storage is not here: mmgr_zero_buf() is a memory-manager operation and lives in locus_carcerum/locus_carcerum.h, beside the cellblock that zeroes on release.
The compare is static inline here, so it inlines into the caller's loop. ::CtEq is the same compare reached through the namespace, with the operands on the handle.
Definition in file ct_eq.h.