During a penetration test, an assessor successfully exploits a timing side-channel attack to extract an ECDSA private key from a secure enclave. Which TWO mitigations should the development team implement to prevent such attacks? (Select TWO.)
Constant-time cryptographic operations eliminate the data-dependent execution timing that leaks ECDSA nonce and scalar information, directly satisfying the stem's timing side-channel constraint. By ensuring every operation takes identical duration regardless of secret values, the attacker gains no exploitable timing variance to correlate against the private key.
Why this answer
Option A is correct because constant-time cryptographic operations ensure that execution time and memory access patterns do not depend on secret data, which directly eliminates the timing side-channel that leaked the ECDSA private key from the enclave. Option D is correct because ECDSA signing blinding (e.g., randomizing the nonce k and/or the private key d with a random value before the scalar multiplication) decorrelates the timing of the modular exponentiation/scalar multiplication from the actual secret, so an attacker cannot recover the key even if timing varies. Option B is not appropriate because adding random delays only obfuscates timing and is statistically defeatable by averaging many traces; it is not a sound cryptographic countermeasure.
Option C does not belong because disabling debug interfaces addresses physical/JTAG-style access, not a timing side-channel observed through normal cryptographic execution. Option E does not belong because Ed25519 is also vulnerable to timing side-channels if implemented without constant-time code and blinding, so simply swapping algorithms does not fix the root cause.