Added more constant-time code and removed biases in the prime number generation routines.
diff --git a/library/rsa.c b/library/rsa.c
index 2338264..222cb26 100644
--- a/library/rsa.c
+++ b/library/rsa.c
@@ -761,7 +761,7 @@
for( i = 0; i < ilen - 2 * hlen - 2; i++ )
{
pad_done |= p[i];
- pad_len += ( pad_done == 0 );
+ pad_len += ((pad_done | (unsigned char)-pad_done) >> 7) ^ 1;
}
p += pad_len;
@@ -835,8 +835,8 @@
* (minus one, for the 00 byte) */
for( i = 0; i < ilen - 3; i++ )
{
- pad_done |= ( p[i] == 0 );
- pad_count += ( pad_done == 0 );
+ pad_done |= ((p[i] | (unsigned char)-p[i]) >> 7) ^ 1;
+ pad_count += ((pad_done | (unsigned char)-pad_done) >> 7) ^ 1;
}
p += pad_count;