Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 1 | /** |
| 2 | * Constant-time functions |
Gilles Peskine | 49540ac | 2022-10-26 18:02:56 +0200 | [diff] [blame] | 3 | */ |
| 4 | /* |
Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 5 | * Copyright The Mbed TLS Contributors |
| 6 | * SPDX-License-Identifier: Apache-2.0 |
| 7 | * |
| 8 | * Licensed under the Apache License, Version 2.0 (the "License"); you may |
| 9 | * not use this file except in compliance with the License. |
| 10 | * You may obtain a copy of the License at |
| 11 | * |
| 12 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 13 | * |
| 14 | * Unless required by applicable law or agreed to in writing, software |
| 15 | * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT |
| 16 | * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 17 | * See the License for the specific language governing permissions and |
| 18 | * limitations under the License. |
| 19 | */ |
| 20 | |
| 21 | #ifndef MBEDTLS_CONSTANT_TIME_H |
| 22 | #define MBEDTLS_CONSTANT_TIME_H |
| 23 | |
Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 24 | #include <stddef.h> |
| 25 | |
Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 26 | /** Constant-time buffer comparison without branches. |
| 27 | * |
Gabor Mezei | 642eeb2 | 2021-11-03 16:13:32 +0100 | [diff] [blame] | 28 | * This is equivalent to the standard memcmp function, but is likely to be |
Dave Rodgman | 56e5d68 | 2023-08-01 15:04:11 +0100 | [diff] [blame^] | 29 | * compiled to code using bitwise operations rather than a branch, such that |
Dave Rodgman | ad9e5b9 | 2023-07-31 12:33:47 +0100 | [diff] [blame] | 30 | * the time taken is constant w.r.t. the data pointed to by \p a and \p b, |
| 31 | * and w.r.t. whether \p a and \p b are equal or not. It is not constant-time |
| 32 | * w.r.t. \p n . |
Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 33 | * |
| 34 | * This function can be used to write constant-time code by replacing branches |
| 35 | * with bit operations using masks. |
| 36 | * |
Dave Rodgman | ad9e5b9 | 2023-07-31 12:33:47 +0100 | [diff] [blame] | 37 | * \param a Pointer to the first buffer, containing at least \p n bytes. May not be NULL. |
| 38 | * \param b Pointer to the second buffer, containing at least \p n bytes. May not be NULL. |
| 39 | * \param n The number of bytes to compare. |
Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 40 | * |
Dave Rodgman | ad9e5b9 | 2023-07-31 12:33:47 +0100 | [diff] [blame] | 41 | * \return Zero if the contents of the two buffers are the same, |
Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 42 | * otherwise non-zero. |
| 43 | */ |
Gilles Peskine | 449bd83 | 2023-01-11 14:50:10 +0100 | [diff] [blame] | 44 | int mbedtls_ct_memcmp(const void *a, |
| 45 | const void *b, |
| 46 | size_t n); |
Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 47 | |
Gabor Mezei | 765862c | 2021-10-19 12:22:25 +0200 | [diff] [blame] | 48 | #endif /* MBEDTLS_CONSTANT_TIME_H */ |