Does OpenSSL use exponent blinding?

Shuai Wang wangshuai901 at
Fri Nov 26 12:07:59 UTC 2021


I am writing to inquire if OpenSSL uses exponent blinding to mitigate
leakage of secrets during RSA decryption. For what I can see, Botan and
Libgcrypt use exponent blinding for RSA and also ElGamal. However, I can
only find "base blinding" in OpenSSL. Would anyone shed some lights on
this? Thank you very much.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the openssl-users mailing list