Does OpenSSL use exponent blinding?

Shuai Wang wangshuai901 at gmail.com
Fri Nov 26 12:07:59 UTC 2021


Hello!

I am writing to inquire if OpenSSL uses exponent blinding to mitigate
leakage of secrets during RSA decryption. For what I can see, Botan and
Libgcrypt use exponent blinding for RSA and also ElGamal. However, I can
only find "base blinding" in OpenSSL. Would anyone shed some lights on
this? Thank you very much.

Best,
Shuai
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mta.openssl.org/pipermail/openssl-users/attachments/20211126/7a309e09/attachment.html>


More information about the openssl-users mailing list