Nettle release plans

This is an attempt at defining a development target for Nettle-3.2, inspired by similar pages for recent GMP releases. [Last updated 2015-09-02]

This really ought to be done before release

Try to get this done before release

Done!

Leave for some later release!

Plans for nettle-3.2

New features

"CRT-hardened" RSA secret key operations. Check that the result of rsa_compute_root is correct. Should be easy for the rsa_pkcs1_sign_tr and rsa_decrypt_tr functions, other RSA functions would need interface changes.

Add larger "safe" curves, e.g., M-383, curve41417 and E-521.

Add functions for converting ECC points to and from ANSI x9.62.

Use side-channel silent GMP functions for RSA and DSA. May require additional interface changes, to use mpn functions.

Side-channel silent mem_equalp.

Optimizations

Assembly optimizations for ARMv8 (64-bit).

Further optimizations of curve25519 and EdDSA, in particular, radix 51 modp operations, and more efficient point addition.

Miscellaneous

Use more functions from GMP-6 and later, when available: mpn_sec_add_1, mpn_sec_tabselect, mpn_sec_invert, mpn_cnd_swap, ...

Documentation

Update SHA3 documentation.

Build system

Update AX_CREATE_STDINT_H to the latest version.

Testing

Since xenofarm isn't up and running, do some manual testing:

Changes under consideration for later releases

These are some other changes under consideration.

Interface changes

For Merkle-Damgaard hash functions, separate the state and the buffering. E.g., when using them for HMAC keyed "inner" and "outer" states, we now get three buffers but we only need one.

Reorganize private key operations. Need to support RSA with and without blinding, and DSA according to spec and some deterministic variant (like putty or RFC6979), and possibly also smartcard versions where the private key is not available to the library. And without an explosion of the number of functions.