
nadim@infosec.exchange ("Nadim Kobeissi") wrote:
Are there any AES implementations out there that implement the S-Box lookup algebraically (GF(2⁸) byte inversion followed by affine transformation) so as to avoid the timing side-channels associated with table lookups? Performance not an issue!