Repository navigation
Reject Ed25519 signatures with S >= L (GH #1352) - #1355
Conversation
|
Thanks @Coralesoft.
I'd be interested to know what Bernstein and Moon think about the change. I'm thinking they already accounted for it by masking the high order byte. Have you performed any research? Jeff |
|
Hi Jeff, It's been a while, but I found my notes. You are right about donna: floodyberry's tree at HEAD still has only the The catch is that the mask and canonicity are different bounds. Chalkias, Garillot and Nikolaenko surveyed the major Ed25519 implementations in "Taming the many EdDSAs" (https://eprint.iacr.org/2020/1244.pdf, SSR 2020) and put donna in the same category as ref10:
Their Listing 1.1 shows how both masks can be used as fast paths around the full comparison: Current libsodium uses the Here is what happens on upstream commit The last byte of The mask is not useless, for what it is worth. It does reject Their archived test-vector repository is at https://github.com/novifinancial/ed25519-speccheck if you want to check this independently of my patch. Vectors 6 and 7 are the Col |
Donna only checks that the top three bits of S are clear, so a signature with the group order added to S still verified. Check S < L in ed25519Verifier::VerifyAndRestart and ed25519Verifier::VerifyStream. Refs weidai11#1352
f931d15 to
ab420c8
Compare
The Ed25519 verifier accepts a signature whose scalar S has had the group order L added to it. Donna only checks that the top three bits of S are clear, which leaves S between L and 2^253 accepted, and the verification equation holds modulo L.
This checks S < L in ed25519Verifier::VerifyAndRestart and ed25519Verifier::VerifyStream, as asked for on #1352. Donna is not touched.
RFC 8032 test vector 1 verifies before and after. The same signature with L added to S verifies on master and is rejected with this change. cryptest.exe v passes.
Refs #1352