Commit graph

33 commits

Author SHA1 Message Date
8e299cd0f5 Aeneas-compat: factor from_bytes_wide through named, closure-free helpers
Pure refactor, semantics identical (cargo check green):
- from_bytes_wide_parts(bytes) -> (Scalar52, Scalar52): the byte-unpack
  loops + the 52-bit lo/hi split, as a named prefix
- split_words_lo / split_words_hi: the two split halves, built with
  Scalar52([...]) struct literals instead of per-index mutation
- from_bytes_wide: parts -> montgomery_mul(lo, R) ->
  montgomery_mul(hi, RR) -> add

Why: the verification side measured that (a) a WP walk whose motives
contain a montgomery_mul call replays its whole body at every kernel
step, and (b) straight-line chains of IndexMut closure back-functions
make kernel defeq exponential in chain depth. Named prefix functions fix
(a); struct-literal construction eliminates the closures and fixes (b).
With this shape the full from_bytes_wide certificate kernel-checks in
77 seconds (was: aborted after 30+ minutes).
2026-07-04 10:23:24 +02:00
0cf451c896 Aeneas-compat: mask the bare shift in Scalar52::from_bytes_wide
hi[4] = words[7] >> 20  is the only shift in the function whose result is
stored without a trailing mask/or; at the pinned Aeneas (bf13c42e) a bare
`x >> c` as a full RHS extracts ill-typed (wrapping_shr applied to an i32
with an emitted-but-unsubstituted U32 cast). Masking is a semantic no-op:
words[7] >> 20 < 2^44 < 2^52.  Semantics unchanged; needed to bring
from_bytes_wide (the hash-to-scalar reduction) into verification scope.
2026-07-03 22:40:00 +02:00
e5f4598766 patch: remove ConditionallyNegatable for Aeneas/Charon transpilation
Upstream: anza-xyz/cryptography
Required for: formal verification via Aeneas bf13c42e + Charon 9dd7f23c
2026-06-30 17:30:34 +02:00
Edvard Fagerholm
0a54ccaf04
ed25519: add 128-bit NAF path (#27)
* ed25519: add 128-bit NAF path

Add Scalar::non_adjacent_form_128 and use it in the serial and vector triple-base verifier paths for scalars known to fit in 128 bits. The helper computes only the HEEA-readable digit range instead of producing a full 256-entry NAF array for each scalar.

Benchmark notes:

- Ran this repository's Criterion benchmark program, benches/bench.rs, filtering to Single Verification, pinned to CPU 4 with 1s warmup, 2s measurement, and sample size 10.

- local_verify_zebra estimate was 19.740 us, with 95% CI 19.686..19.789 us.

- master measured 20.051 us, with 95% CI 19.938..20.134 us, so this branch was about 1.55% faster in that run.

* Use 128-bit NAF in triple-base paths

---------

Co-authored-by: zz-sol <allaboutshop10@163.com>
2026-06-24 16:47:31 +09:00
zz-sol
9c7161d652
simply lookup table constructor (#56) 2026-06-22 09:47:37 -04:00
zz-sol
69e1efe684
better error handling for batch verify (#57) 2026-06-22 09:47:19 -04:00
zz-sol
bfc9f01bbb
[ed25519] improve signing key life cycle (#51)
* make sk non-copy

* lint

* simplify zeroization
2026-06-18 09:25:12 -04:00
zz-sol
f08b2c94fc
[ed25519] fix pkcs8 (#52)
* fix pkcs8

* Propagate PKCS#8 errors; add decoding test

Replace unwraps with ? to propagate pkcs8::Error when parsing PKCS#8 key material (in TryFrom<&KeypairBytes> and from_pkcs8_der), use the parsed SigningKey directly for public-key verification, and return Ok(signing_key). Add a test to ensure malformed/non-PKCS#8 bytes are rejected without panicking, and import BitStringRef in tests to simplify references.
2026-06-18 07:33:08 -04:00
zz-sol
ff4e6654d1
[ed25519] improve rng bounds for random function (#54) 2026-06-18 07:32:53 -04:00
zz-sol
34e36a7c32
[ed25519] implement add for SW form (#55)
* impl add for SW

* Update short_weierstrass.rs
2026-06-18 07:32:25 -04:00
zz-sol
06cc7111db
improve test coverage (#50) 2026-06-17 08:25:25 -04:00
zz-sol
7cca75ad6e
[ed25519] improve docs (#53)
* improve docs

* more docs

* improve docs
2026-06-16 23:13:07 -04:00
zz-sol
befbe09d36
[ed25519] fix point conversions (#46)
* Update short_weierstrass.rs

* remove option for to_affine_le_bytes
2026-06-16 09:05:18 -04:00
zz-sol
53383206b8
fix 128bits scalar precondition (#44)
* Add prechecked optimized triple-base mul

Introduce a prechecked 128/128/256 optimized path for vartime triple-base multiplication: vartime_triple_base_mul_128_128_256 now checks whether a1 and a2 fit in 128 bits and falls back to general multiplication if not. Add vartime_triple_base_mul_128_128_256_prechecked and corresponding serial/vector backend implementations (renamed to *_prechecked). Add scalar_fits_in_128_bits helper and update callers (verification_key) to use the prechecked path. Update docs/comments and add a test to ensure full-width scalars are handled by the fallback path.

* bring back the docs

* CI
2026-06-16 08:59:35 -04:00
zz-sol
eed50b4d8d
[ed25519] improve docs (#47)
* improve docs

* more docs
2026-06-11 22:10:13 -04:00
zz-sol
c41adab68f
Validate SPKI OID/bytes and add pkcs8 tests (#43)
Add strict SPKI validation and tests for PKCS#8 public keys. Introduce OID and ALGORITHM_ID constants and refactor SPKI parsing into verification_key_bytes_from_spki which verifies the algorithm OID, parameters, and key byte length/format, returning appropriate pkcs8::spki::Error values. Update TryFrom/EncodePublicKey/DecodePublicKey implementations to use the new helper and to propagate/mapping errors correctly. Add two tests (behind the pkcs8 feature) to assert rejection of SPKI docs with the wrong algorithm OID and with malformed key bytes.
2026-06-10 06:44:35 -04:00
zz-sol
34a01d5b75
fix pkcs8 (#41) 2026-06-10 06:44:17 -04:00
zz-sol
bcc21e28bb
[ed25519] fix serdes error (#42) 2026-06-09 08:28:19 -04:00
Edvard Fagerholm
de07b0a389
ed25519: precompute AVX2 basepoint-128 table (#25)
Add a static AVX2 NafLookupTable5<CachedPoint> for B * 2^128 and use it from the vector triple-base verifier path instead of rebuilding that table every verification.

Benchmark notes:

- Ran this repository's Criterion benchmark program, benches/bench.rs, filtering to Single Verification, pinned to CPU 4 with 1s warmup, 2s measurement, and sample size 10.

- local_verify_zebra estimate was 19.382 us, with 95% CI 19.327..19.426 us.

- master measured 20.051 us, with 95% CI 19.938..20.134 us, so this branch was about 3.34% faster in that run.
2026-06-08 13:04:02 -04:00
Edvard Fagerholm
7d80488798
ed25519: avoid split-scalar canonical checks (#24)
The triple-base verifier splits b into zero-extended 128-bit halves, so b_lo and b_hi are already canonical. Add a crate-private unchecked constructor and use it for that internal AVX2 path.

Benchmark notes:

- Ran this repository's Criterion benchmark program, benches/bench.rs, filtering to Single Verification, pinned to CPU 4 with 1s warmup, 2s measurement, and sample size 10.

- local_verify_zebra estimate was 19.996 us, with 95% CI 19.862..20.077 us.

- master measured 20.051 us, with 95% CI 19.938..20.134 us, so this branch was about 0.27% faster in that run.
2026-06-08 13:02:22 -04:00
Yihau Chen
4413a1284a
ci: check each feature individually (#18)
* ci: check each feature individually

* fix test all targets

* Update ristretto.rs

* Update lizard_ristretto.rs

---------

Co-authored-by: zz-sol <allaboutshop10@163.com>
2026-05-20 10:23:03 +08:00
zz-sol
154b58b3f4
[ed25519] downgrade rand_core (#21)
* downgrade rand_core

* Update bench.rs

* remove `try_from_rng`
2026-05-18 21:50:26 -04:00
zz-sol
1b728159eb
impl zeroize for signing key (#16) 2026-05-13 18:11:16 -04:00
Sam Kim
09198923bb
Add workspace.package information and do minor clean-up (#14)
* remove README.md in the syscall directory

* use workspace dependency in `bls12-381`

* add `workspace.package` information

* use 2021 edition for bls12-381

* inherit workspace.package for `ed25519-pokos`

* cargo fmt
2026-04-26 10:11:05 +09:00
zz-sol
cbee436037
[chore] remove unused features and downgrade to stable deps (#12)
* remove unnecessary features

* downgrade repos and remove rc/pre release
2026-04-22 20:23:12 -04:00
zz-sol
1384fe1040
[chore] ci for crate release (#7)
* refactor and merge curve and ed crates

* fmt

* ci

* fmt again

* ci

* Update bench.rs

* fix ubuntu

* CI for crate release

* Update README.md
2026-04-15 08:44:33 -04:00
zz-sol
bccf7e13c0
[feat] impl legacy dalek verification method for ed25519 (#8)
* Initial commit

* skeleton

* refactor and merge curve and ed crates

* fmt

* ci

* fmt again

* ci

* Update bench.rs

* fix ubuntu

* implement dalek api

* clean up
2026-03-31 07:46:24 -04:00
zz-sol
b801651332
refactor cargo toml to use worksapce (#9) 2026-03-30 08:48:31 -04:00
zz-sol
1587b4c24f
refactor and merge curve and ed crates (#6)
* refactor and merge curve and ed crates

* fmt

* ci

* fmt again

* ci

* Update bench.rs

* fix ubuntu
2026-03-26 08:09:10 -04:00
Sam Kim
8024e4ed31
move all curve25519 related crates into curve25519 directory (#5) 2026-03-24 07:42:07 -04:00
zz-sol
e56e48a473
integrate heea (#4)
* Initial commit

* skeleton

* integrate heea

* ci

* fix nits

* Update signing_key.rs
2026-03-23 08:18:33 -04:00
zz-sol
45af346e81
integrate curve25519 related crates (#2)
* wip

* fix ci

* fmt

* Update crate descriptions in README.md
2026-03-13 17:49:11 -04:00
zz-sol
7518f90e7a
Skeleton for cryptography repo (#1)
* Initial commit

* skeleton
2026-03-07 15:52:28 -05:00