Skip to content

Conversation

randombit
Copy link
Contributor

As the group order is anyway public, there is no reason to prevent it from leaking to a side channel.

On my laptop (i7-10610U) the benchmark of is_torsion_free improves from 34 μs to 24 μs.

As the group order is anyway public, there is no reason to prevent
it from leaking to a side channel.
@randombit randombit force-pushed the jack/use-vartime-mul-for-torsion-check branch from 81287a7 to 5a5a768 Compare June 6, 2024 18:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant