Re: crypto: ecc - constant-time modular inversion?

From: Ignat Korchagin

Date: Fri Sep 25 2026 - 08:24:39 EST


On Thu, Sep 24, 2026 at 11:51 PM Erwin Pawliczek
<pawliczekerwin@xxxxxxxxx> wrote:
>
> Hello,
>
> vli_mod_inv() in crypto/ecc.c is currently responsible for modular inversion, it is currently a binary greatest common denominator loop where the iteration count depends on input. I'd like to replace it with a constant time algorithm, this one: https://eprint.iacr.org/2019/266

Is it used outside of ECDSA signature verification (with secret
input)? If no, the replacement needs to be faster to justify the
change

> It runs a fixed number of divsteps for a given operand size, independent of input.
>
> I already started working on a replacement, please let me know if this is something you'd be interested in.
>
> Thanks,
>
> Erwin

Ignat