Reports › hash-11 · Constant-time review
Garnet (hash-11)
| Candidate | Garnet |
|---|---|
| Family | Symmetric (AES-derived hash) |
| Archive | Garnet.zip (SHA-256: 9cb659f7e01a64bdcce2a4fea8a7d6e6b5687b2a0ed8ce4ffe5fa86dd3e77646) |
hash-11-1: Secret state indexes AES T-tables
| Severity | Medium |
|---|---|
| Scope | side-channel |
| Status | Confirmed |
| Affected | Reference Garnet variants |
| Discovery | Trivial |
| Exploitation | Cache side-channel dependent |
| Credit | Markku-Juhani O. Saarinen markku-juhani.saarinen@tuni.fi, with AI assistance |
| Date | 2026-09-23 |
Each AES-like round indexes four 1-KiB T-tables with bytes of the evolving hash state (Garnet_1024.c:278-281; Garnet_512.c:322-325). These indices depend on the message and select different cache lines, exposing state-dependent memory addresses in a shared-cache setting. A two-entry reduction table is also indexed by a state bit. No preimage-recovery exploit is claimed. See constant_time.md.
Reproducing
Commands below run in a checkout of the ngcc-harness repository with the candidate built (see its README).
Inspect the cited TE0–TE3 loads; identical-length inputs with different first blocks produce different state-derived table indices. This is an address-trace witness, not a timing-extraction benchmark.