Commit graph

77 commits

Author SHA1 Message Date
bunnie
a77d53829a Merge remote-tracking branch 'dalek/release/3.2' into main 2022-03-09 21:36:05 +08:00
Isis Lovecruft
9f93a5c0f5
Merge branch 'main' into develop 2021-08-03 22:53:58 +00:00
Isis Lovecruft
b9710d59f2
Minor documentation fixes. 2021-08-03 22:49:09 +00:00
bunnie
053d65f3a7 commit a debug branch 2021-07-10 23:46:48 +08:00
bunnie
c950ac9268 add a 'u32e' backend -- u32 + curve25519 engine 2021-07-10 17:57:19 +08:00
bunnie
1a79b76e90 move microcode to the Xous side of things
minimizing the mount of data movement speeds up operations by
about 2x
2021-06-28 18:31:45 +08:00
bunnie
41cc7c4ab3 accelerate the affine transform in hardware 2021-06-28 04:42:01 +08:00
bunnie
9ffc75dd3c more fixes to try to clean up the build system 2021-06-28 01:27:03 +08:00
bunnie
ea4bc9b079 attempt to clean up some dependency issues 2021-06-27 01:58:27 +08:00
bunnie
0b748f6365 stash a version of the XousEngine25519 trait in case we want it later 2021-06-27 00:30:26 +08:00
bunnie
0b0cda3118 initial swag at gluing things together
Note: breaks for anyone's build environment but mine!
2021-06-26 13:41:19 +08:00
bunnie
6e2cf5ab43 add macros 2021-06-26 02:11:37 +08:00
bunnie
b4e8accf38 Merge branch 'main' into HEAD 2021-06-20 19:20:06 +08:00
Isis Lovecruft
d7c2a1394f
Add another test for equivalence with the Edwards identity. 2021-04-21 00:06:44 +00:00
Isis Lovecruft
0d8f33153c
Implement Identity for MontgomeryPoint.
This can be used in checks for non-contributory behaviour in protocols
where that is a concern.
2021-04-21 00:02:22 +00:00
Isis Lovecruft
ee90202a58
Trivial cleanups to Elligator2 encoding.
cf. https://github.com/dalek-cryptography/curve25519-dalek/pull/336
2021-04-13 00:24:50 +00:00
isis agora lovecruft
b79a276806
Merge pull request #336 from huitseeker/elligator2
Elligator2 mapping for curve25519
2021-03-25 03:13:41 +00:00
Isis Lovecruft
ab468cd24c
Fix copyright years in some of the files I touched. 2021-03-25 02:29:37 +00:00
François Garillot
e2651cceb6
Rename elligator_map -> elligator_encode
leaves an obvious name open for the reverse mapping
2021-01-12 13:46:04 -08:00
François Garillot
8aa1458941
Implements an Elligator2 map for Curve25519
This implementation:
- is agnostic on the hash used to pick a field element, even though SHA512 is commonly used,
- follows https://tools.ietf.org/id/draft-irtf-cfrg-hash-to-curve-10.html closely
- tests the outputs of the function using libsignal's implementation.
2020-10-21 17:38:22 -04:00
bunnie
2a1aaa72e8 leave a breadcrumb for the next work to do 2020-08-21 02:31:37 +08:00
bunnie
eb45d338ee mods to get hardware integration to actually work. 2020-08-21 01:37:10 +08:00
bunnie
247c8ca2b7 add full montgomery scalar multiply implementation in hardware 2020-08-21 00:07:54 +08:00
bunnie
9c3d34345c add hardware acceleration to differential point add and double
hacky implementation, but it'll let us do a performance benchmark
2020-08-20 15:47:02 +08:00
Rui Morais
6a8e466063 add derive Hash to Scalar, MontgomeryPoint and CompressedEdwardsY 2020-02-25 22:39:19 +00:00
isis agora lovecruft
77203aa1cb
Merge pull request #306 from isislovecruft/feature/236-merge-rebase
Implement Zeroize for Scalar and MontgomeryPoint
2019-10-28 20:28:34 +00:00
Isis Lovecruft
57f19e018f
Merge remote-tracking branch 'DebugSteven/zeroize' into feature/236-merge-rebase 2019-10-28 19:09:39 +00:00
Isis Lovecruft
409ebd94c0
Remove dev-dependency on deprecated rand_os crate.
The functionality we were using is now contained in the `rand_core` crate, which
we already depend upon.  As far as testing code goes, only benchmarks still
depend upon `rand`, as they use `thread_rng`.
2019-10-28 18:06:29 +00:00
Henry de Valence
70e46c9826 Fill in missing Serde impl for MontgomeryPoint. 2019-10-23 15:55:03 -07:00
Henry de Valence
620d17ef40
Merge pull request #293 from dalek-cryptography/remove-build-rs
Remove build.rs constants generation.
2019-10-23 14:44:46 -07:00
Henry de Valence
574217694e Remove build.rs.
This was more useful at the time when we were determining, e.g., optimal lookup
table sizes and could regenerate them more easily, but it came at a massive
complexity cost.  It also meant that we were unable to implement backend
autoselection.  This commit removes the `build.rs` entirely.  In the future, a
different `build.rs` could be added that auto-selects a backend, but it seems
like the current default-u64 setup has been working fine.
2019-10-23 14:20:38 -07:00
Isis Lovecruft
019b81aa20
Clarify docs for the choice of sign for MontgomeryPoint.to_edwards(). 2019-10-23 19:49:06 +00:00
Isis Lovecruft
7c5ba69491
Update copyright year. 2019-10-23 19:43:56 +00:00
DebugSteven
ba389040de implement Zeroize for Scalar and MontgomeryPoint 2019-03-03 17:09:34 -07:00
Артём Павлов [Artyom Pavlov]
d6ca36fa0b replace rand with rand_core+rand_os 2019-01-05 14:27:24 +03:00
DebugSteven
39145da396 implement default for MontgomeryPoint using zero byte array 2018-11-14 23:16:50 -05:00
DebugSteven
2adc985f63 default & identity trait for MontgomeryPoint 2018-11-14 14:43:11 -05:00
Henry de Valence
a116fd9679 test subtle 2.0 2018-11-05 12:06:23 -08:00
Henry de Valence
53fcd1060d Change internal API to use ConditionallySelectable 2018-11-02 14:17:43 -07:00
Tony Arcieri
10e8abf926 Unify alloc and std cargo features
This change provides a common convention for using allocator-dependent
features with:

    #![cfg(feature = "alloc")]

When available, `Vec` is imported consistently as `prelude::Vec`, which
means modules that need access to `Vec` can simply do:

    use prelude::*;

and if an allocator is available, `Vec` will be in the crate prelude.

This allows all `alloc` vs `std` gating to be handled in `lib.rs`,
`build.rs`, and `prelude.rs` so the rest of the codebase doesn't have to
do any gating whatsoever.
2018-07-23 10:50:21 -07:00
Isis Lovecruft
38aa0ee2b7
Implement Default for remaining point types.
* FIXES https://github.com/dalek-cryptography/curve25519-dalek/issues/154
2018-07-20 00:47:36 +00:00
Isis Lovecruft
f43f4f9770
Update year in copyright notices to 2018. 2018-07-05 00:30:27 +00:00
Henry de Valence
bbb64312f7 Use rand 0.5
Requires `0.5.0-pre.2`, which adds `impl CryptoRng for OsRng`.
2018-05-15 12:30:28 -07:00
Henry de Valence
9b6c932635 Rename 'precomputed_tables' to the more accurate 'stage2_build' 2018-05-14 15:41:45 -07:00
Isis Lovecruft
3281708965
Define mul variants for MontgomeryPoints.
This results in less changes to the x25519-dalek code to upgrade to
the latest version.
2018-04-02 21:09:41 +00:00
Henry de Valence
d6b8389428 Use criterion.rs instead of libtest for benchmarks.
Since Criterion can only benchmark public API, these changes just drop
all internal benchmarks (e.g., benchmarks for field operations). But
those are usually microbenchmarks whose meaning is kind of questionable
anyways, so I don't think this is a big loss.

The `bench` feature disappears, since Criterion works on stable Rust.
2018-03-25 17:14:37 -07:00
Henry de Valence
e73b635fe0 Remove unused constants 2018-03-22 12:17:23 -07:00
Henry de Valence
792ac0775e Change to the updated subtle API. 2018-03-22 11:13:26 -07:00
Henry de Valence
6748dddb96 Simplify and optimize Montgomery code.
The `MontgomeryPoint` struct is now a point on the Kummer line of the Montgomery curve.

The `ProjectivePoint` struct is made private, since its only purpose is
internal to the Montgomery ladder.

The Montgomery ladder takes affine input, making it faster, and produces affine output.

The Edwards-Montgomery correspondence is simplified.
2018-02-05 10:40:25 -08:00
Isis Lovecruft
cd112afff5
Whitespace EOL fixes. 2018-01-31 02:19:53 +00:00