xref: /freebsd/crypto/openssl/doc/man3/RSA_blinding_on.pod (revision b077aed33b7b6aefca7b17ddb250cf521f938613)
1e71b7053SJung-uk Kim=pod
2e71b7053SJung-uk Kim
3e71b7053SJung-uk Kim=head1 NAME
4e71b7053SJung-uk Kim
5e71b7053SJung-uk KimRSA_blinding_on, RSA_blinding_off - protect the RSA operation from timing attacks
6e71b7053SJung-uk Kim
7e71b7053SJung-uk Kim=head1 SYNOPSIS
8e71b7053SJung-uk Kim
9e71b7053SJung-uk Kim #include <openssl/rsa.h>
10e71b7053SJung-uk Kim
11*b077aed3SPierre ProncheryThe following functions have been deprecated since OpenSSL 3.0, and can be
12*b077aed3SPierre Proncheryhidden entirely by defining B<OPENSSL_API_COMPAT> with a suitable version value,
13*b077aed3SPierre Proncherysee L<openssl_user_macros(7)>:
14*b077aed3SPierre Pronchery
15e71b7053SJung-uk Kim int RSA_blinding_on(RSA *rsa, BN_CTX *ctx);
16e71b7053SJung-uk Kim
17e71b7053SJung-uk Kim void RSA_blinding_off(RSA *rsa);
18e71b7053SJung-uk Kim
19e71b7053SJung-uk Kim=head1 DESCRIPTION
20e71b7053SJung-uk Kim
21*b077aed3SPierre ProncheryAll of the functions described on this page are deprecated.
22*b077aed3SPierre Pronchery
23e71b7053SJung-uk KimRSA is vulnerable to timing attacks. In a setup where attackers can
24e71b7053SJung-uk Kimmeasure the time of RSA decryption or signature operations, blinding
25e71b7053SJung-uk Kimmust be used to protect the RSA operation from that attack.
26e71b7053SJung-uk Kim
27e71b7053SJung-uk KimRSA_blinding_on() turns blinding on for key B<rsa> and generates a
2858f35182SJung-uk Kimrandom blinding factor. B<ctx> is B<NULL> or a preallocated and
29da327cd2SJung-uk Kiminitialized B<BN_CTX>.
30e71b7053SJung-uk Kim
31e71b7053SJung-uk KimRSA_blinding_off() turns blinding off and frees the memory used for
32e71b7053SJung-uk Kimthe blinding factor.
33e71b7053SJung-uk Kim
34e71b7053SJung-uk Kim=head1 RETURN VALUES
35e71b7053SJung-uk Kim
36e71b7053SJung-uk KimRSA_blinding_on() returns 1 on success, and 0 if an error occurred.
37e71b7053SJung-uk Kim
38e71b7053SJung-uk KimRSA_blinding_off() returns no value.
39e71b7053SJung-uk Kim
40*b077aed3SPierre Pronchery=head1 HISTORY
41*b077aed3SPierre Pronchery
42*b077aed3SPierre ProncheryAll of these functions were deprecated in OpenSSL 3.0.
43*b077aed3SPierre Pronchery
44e71b7053SJung-uk Kim=head1 COPYRIGHT
45e71b7053SJung-uk Kim
46*b077aed3SPierre ProncheryCopyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.
47e71b7053SJung-uk Kim
48*b077aed3SPierre ProncheryLicensed under the Apache License 2.0 (the "License").  You may not use
49e71b7053SJung-uk Kimthis file except in compliance with the License.  You can obtain a copy
50e71b7053SJung-uk Kimin the file LICENSE in the source distribution or at
51e71b7053SJung-uk KimL<https://www.openssl.org/source/license.html>.
52e71b7053SJung-uk Kim
53e71b7053SJung-uk Kim=cut
54