2016-12-08 05:12:00 +00:00
|
|
|
|
2018-03-09 23:59:20 +00:00
|
|
|
# curve25519-dalek [](https://crates.io/crates/curve25519-dalek) [](https://doc.dalek.rs) [](https://travis-ci.org/dalek-cryptography/curve25519-dalek)
|
2016-12-08 05:12:00 +00:00
|
|
|
|
2018-01-19 23:01:47 +00:00
|
|
|
<img
|
2018-01-25 21:40:30 +00:00
|
|
|
width="33%"
|
2018-01-19 23:01:47 +00:00
|
|
|
align="right"
|
2018-02-21 19:03:18 +00:00
|
|
|
src="https://doc.dalek.rs/assets/dalek-logo-clear.png"/>
|
2018-01-19 23:01:47 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
**A pure-Rust implementation of group operations on Ristretto and Curve25519.**
|
2016-12-08 05:12:00 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
`curve25519-dalek` is a library providing group operations on the Edwards and
|
|
|
|
|
Montgomery forms of Curve25519, and on the prime-order Ristretto group.
|
2016-12-08 05:12:00 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
`curve25519-dalek` is not intended to provide implementations of any particular
|
|
|
|
|
crypto protocol. Rather, implementations of those protocols (such as
|
|
|
|
|
[`x25519-dalek`][x25519-dalek] and [`ed25519-dalek`][ed25519-dalek]) should use
|
|
|
|
|
`curve25519-dalek` as a library.
|
2016-12-08 05:12:00 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
`curve25519-dalek` is intended to provide a clean and safe _mid-level_ API for use
|
|
|
|
|
implementing a wide range of ECC-based crypto protocols, such as key agreement,
|
|
|
|
|
signatures, anonymous credentials, rangeproofs, and zero-knowledge proof
|
|
|
|
|
systems.
|
2016-12-08 22:18:57 +00:00
|
|
|
|
2018-01-26 01:34:06 +00:00
|
|
|
In particular, `curve25519-dalek` implements Ristretto, which constructs a
|
|
|
|
|
prime-order group from a non-prime-order Edwards curve. This provides the
|
|
|
|
|
speed and safety benefits of Edwards curve arithmetic, without the pitfalls of
|
|
|
|
|
cofactor-related abstraction mismatches.
|
|
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
# Documentation
|
2016-12-08 22:18:57 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
The semver-stable, public-facing `curve25519-dalek` API is documented
|
|
|
|
|
[here][docs-external]. In addition, the unstable internal implementation
|
|
|
|
|
details are documented [here][docs-internal].
|
2016-12-08 22:18:57 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
The `curve25519-dalek` documentation requires a custom HTML header to include
|
|
|
|
|
KaTeX for math support. Unfortunately `cargo doc` does not currently support
|
|
|
|
|
this, but docs can be built using
|
|
|
|
|
```sh
|
|
|
|
|
make doc
|
|
|
|
|
make doc-internal
|
|
|
|
|
```
|
2016-12-08 22:18:57 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
# Use
|
2016-12-08 22:18:57 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
To import `curve25519-dalek`, add the following to the dependencies section of
|
|
|
|
|
your project's `Cargo.toml`:
|
2017-12-02 03:19:19 +00:00
|
|
|
```toml
|
2019-10-25 22:58:41 +00:00
|
|
|
curve25519-dalek = "2"
|
2017-12-02 03:19:19 +00:00
|
|
|
```
|
2016-12-08 22:18:57 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
# Backends and Features
|
2017-12-02 03:19:19 +00:00
|
|
|
|
2018-07-04 21:36:57 +00:00
|
|
|
The `nightly` feature enables features available only when using a Rust nightly
|
|
|
|
|
compiler. **It is recommended for security**.
|
2018-05-15 00:35:34 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
Curve arithmetic is implemented using one of the following backends:
|
2016-12-08 22:18:57 +00:00
|
|
|
|
2019-10-25 22:58:41 +00:00
|
|
|
* a `u32` backend using serial formulas and `u64` products;
|
|
|
|
|
* a `u64` backend using serial formulas and `u128` products;
|
|
|
|
|
* an `avx2` backend using [parallel formulas][parallel_doc] and `avx2` instructions (sets speed records);
|
|
|
|
|
* an `ifma` backend using [parallel formulas][parallel_doc] and `ifma` instructions (sets speed records);
|
2017-12-02 03:19:19 +00:00
|
|
|
|
2018-05-15 00:35:34 +00:00
|
|
|
By default the `u64` backend is selected. To select a specific backend, use:
|
|
|
|
|
```sh
|
|
|
|
|
cargo build --no-default-features --features "std u32_backend"
|
|
|
|
|
cargo build --no-default-features --features "std u64_backend"
|
2019-10-25 22:58:41 +00:00
|
|
|
# Requires nightly, RUSTFLAGS="-C target_feature=+avx2" to use avx2
|
|
|
|
|
cargo build --no-default-features --features "std simd_backend"
|
|
|
|
|
# Requires nightly, RUSTFLAGS="-C target_feature=+avx512ifma" to use ifma
|
|
|
|
|
cargo build --no-default-features --features "std simd_backend"
|
2018-05-15 00:35:34 +00:00
|
|
|
```
|
2018-06-18 20:30:45 +00:00
|
|
|
Crates using `curve25519-dalek` can either select a backend on behalf of their
|
|
|
|
|
users, or expose feature flags that control the `curve25519-dalek` backend.
|
2018-05-15 00:35:34 +00:00
|
|
|
|
2018-07-05 20:39:29 +00:00
|
|
|
The `std` feature is enabled by default, but it can be disabled for no-`std`
|
|
|
|
|
builds using `--no-default-features`. Note that this requires explicitly
|
|
|
|
|
selecting an arithmetic backend using one of the `_backend` features.
|
|
|
|
|
If no backend is selected, compilation will fail.
|
|
|
|
|
|
2018-07-12 19:44:56 +00:00
|
|
|
# Safety
|
|
|
|
|
|
|
|
|
|
The `curve25519-dalek` types are designed to make illegal states
|
|
|
|
|
unrepresentable. For example, any instance of an `EdwardsPoint` is
|
|
|
|
|
guaranteed to hold a point on the Edwards curve, and any instance of a
|
|
|
|
|
`RistrettoPoint` is guaranteed to hold a valid point in the Ristretto
|
|
|
|
|
group.
|
|
|
|
|
|
|
|
|
|
All operations are implemented using constant-time logic (no
|
|
|
|
|
secret-dependent branches, no secret-dependent memory accesses),
|
|
|
|
|
unless specifically marked as being variable-time code.
|
2018-07-16 21:30:14 +00:00
|
|
|
We believe that our constant-time logic is lowered to constant-time
|
|
|
|
|
assembly, at least on `x86_64` targets.
|
|
|
|
|
|
|
|
|
|
As an additional guard against possible future compiler optimizations, the
|
|
|
|
|
`nightly` feature places an optimization barrier before every
|
|
|
|
|
conditional move or assignment. More details can be found in [the
|
|
|
|
|
documentation for the `subtle` crate][subtle_doc]. This is
|
|
|
|
|
recommended, but not required.
|
2018-07-12 19:44:56 +00:00
|
|
|
|
|
|
|
|
Some functionality (e.g., multiscalar multiplication or batch
|
2018-07-16 21:30:14 +00:00
|
|
|
inversion) requires heap allocation for temporary buffers. All
|
2018-07-12 19:44:56 +00:00
|
|
|
heap-allocated buffers of potentially secret data are explicitly
|
2018-07-16 21:30:14 +00:00
|
|
|
zeroed before release.
|
2018-07-12 19:44:56 +00:00
|
|
|
|
|
|
|
|
However, we do not attempt to zero stack data, for two reasons.
|
|
|
|
|
First, it's not possible to do so correctly: we don't have control
|
|
|
|
|
over stack allocations, so there's no way to know how much data to
|
|
|
|
|
wipe. Second, because `curve25519-dalek` provides a mid-level API,
|
|
|
|
|
the correct place to start zeroing stack data is likely not at the
|
|
|
|
|
entrypoints of `curve25519-dalek` functions, but at the entrypoints of
|
|
|
|
|
functions in other crates.
|
|
|
|
|
|
|
|
|
|
The implementation is memory-safe, and contains no significant
|
2019-10-25 22:58:41 +00:00
|
|
|
`unsafe` code. The SIMD backend uses `unsafe` internally to call SIMD
|
|
|
|
|
intrinsics. These are marked `unsafe` because invoking them on an
|
|
|
|
|
inappropriate CPU would cause `SIGILL`, but the entire backend is only
|
|
|
|
|
compiled with appropriate `target_feature`s.
|
2018-07-12 19:44:56 +00:00
|
|
|
|
|
|
|
|
# Performance
|
|
|
|
|
|
2018-03-26 00:10:30 +00:00
|
|
|
Benchmarks are run using [`criterion.rs`][criterion]:
|
2017-12-02 03:19:19 +00:00
|
|
|
|
|
|
|
|
```sh
|
2018-05-15 00:35:34 +00:00
|
|
|
cargo bench --no-default-features --features "std u32_backend"
|
|
|
|
|
cargo bench --no-default-features --features "std u64_backend"
|
2019-10-25 22:58:41 +00:00
|
|
|
# Uses avx2 or ifma only if compiled for an appropriate target.
|
|
|
|
|
export RUSTFLAGS="-C target_cpu=native"
|
|
|
|
|
cargo bench --no-default-features --features "std simd_backend"
|
2017-12-02 03:19:19 +00:00
|
|
|
```
|
2017-03-14 08:53:26 +00:00
|
|
|
|
2018-07-12 19:44:56 +00:00
|
|
|
Performance is a secondary goal behind correctness, safety, and
|
|
|
|
|
clarity, but we aim to be competitive with other implementations.
|
2018-07-04 20:54:05 +00:00
|
|
|
|
2018-08-03 18:00:29 +00:00
|
|
|
# FFI
|
|
|
|
|
|
|
|
|
|
Unfortunately, we have no plans to add FFI to `curve25519-dalek` directly. The
|
|
|
|
|
reason is that we use Rust features to provide an API that maintains safety
|
|
|
|
|
invariants, which are not possible to maintain across an FFI boundary. For
|
|
|
|
|
instance, as described in the _Safety_ section above, invalid points are
|
|
|
|
|
impossible to construct, and this would not be the case if we exposed point
|
|
|
|
|
operations over FFI.
|
|
|
|
|
|
|
|
|
|
However, `curve25519-dalek` is designed as a *mid-level* API, aimed at
|
|
|
|
|
implementing other, higher-level primitives. Instead of providing FFI at the
|
|
|
|
|
mid-level, our suggestion is to implement the higher-level primitive (a
|
|
|
|
|
signature, PAKE, ZKP, etc) in Rust, using `curve25519-dalek` as a dependency,
|
|
|
|
|
and have that crate provide a minimal, byte-buffer-oriented FFI specific to
|
|
|
|
|
that primitive.
|
|
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
# Contributing
|
2016-12-08 05:12:00 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
Please see [CONTRIBUTING.md][contributing].
|
2017-08-01 03:03:11 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
Patches and pull requests should be make against the `develop`
|
|
|
|
|
branch, **not** `master`.
|
2017-11-16 00:47:01 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
# About
|
2017-11-16 00:47:01 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
**SPOILER ALERT:** *The Twelfth Doctor's first encounter with the Daleks is in
|
|
|
|
|
his second full episode, "Into the Dalek". A beleaguered ship of the "Combined
|
|
|
|
|
Galactic Resistance" has discovered a broken Dalek that has turned "good",
|
|
|
|
|
desiring to kill all other Daleks. The Doctor, Clara and a team of soldiers
|
|
|
|
|
are miniaturized and enter the Dalek, which the Doctor names Rusty. They
|
|
|
|
|
repair the damage, but accidentally restore it to its original nature, causing
|
|
|
|
|
it to go on the rampage and alert the Dalek fleet to the whereabouts of the
|
|
|
|
|
rebel ship. However, the Doctor manages to return Rusty to its previous state
|
|
|
|
|
by linking his mind with the Dalek's: Rusty shares the Doctor's view of the
|
|
|
|
|
universe's beauty, but also his deep hatred of the Daleks. Rusty destroys the
|
|
|
|
|
other Daleks and departs the ship, determined to track down and bring an end
|
|
|
|
|
to the Dalek race.*
|
2017-11-16 00:47:01 +00:00
|
|
|
|
2018-01-25 21:40:30 +00:00
|
|
|
`curve25519-dalek` is authored by Isis Agora Lovecruft and Henry de Valence.
|
|
|
|
|
|
|
|
|
|
Portions of this library were originally a port of [Adam Langley's
|
|
|
|
|
Golang ed25519 library](https://github.com/agl/ed25519), which was in
|
2018-06-18 20:30:45 +00:00
|
|
|
turn a port of the reference `ref10` implementation. Most of this code,
|
|
|
|
|
including the 32-bit field arithmetic, has since been rewritten.
|
2018-01-25 21:40:30 +00:00
|
|
|
|
|
|
|
|
The fast `u32` and `u64` scalar arithmetic was implemented by Andrew Moon, and
|
2018-07-04 20:59:37 +00:00
|
|
|
the addition chain for scalar inversion was provided by Brian Smith. The
|
|
|
|
|
optimised batch inversion was contributed by Sean Bowe and Daira Hopwood.
|
2018-01-26 02:00:17 +00:00
|
|
|
|
2019-10-25 22:58:41 +00:00
|
|
|
The `no_std` and `zeroize` support was contributed by Tony Arcieri.
|
2018-01-26 02:00:17 +00:00
|
|
|
|
|
|
|
|
Thanks also to Ashley Hauck, Lucas Salibian, and Manish Goregaokar for their
|
|
|
|
|
contributions.
|
2018-01-25 21:40:30 +00:00
|
|
|
|
|
|
|
|
[ed25519-dalek]: https://github.com/dalek-cryptography/ed25519-dalek
|
|
|
|
|
[x25519-dalek]: https://github.com/dalek-cryptography/x25519-dalek
|
|
|
|
|
[contributing]: https://github.com/dalek-cryptography/curve25519-dalek/blob/master/CONTRIBUTING.md
|
2018-02-21 19:11:17 +00:00
|
|
|
[docs-external]: https://doc.dalek.rs/curve25519_dalek/
|
|
|
|
|
[docs-internal]: https://doc-internal.dalek.rs/curve25519_dalek/
|
2018-03-26 00:10:30 +00:00
|
|
|
[criterion]: https://github.com/japaric/criterion.rs
|
2019-08-09 08:19:18 +00:00
|
|
|
[parallel_doc]: https://doc-internal.dalek.rs/curve25519_dalek/backend/vector/avx2/index.html
|
2018-07-16 21:30:14 +00:00
|
|
|
[subtle_doc]: https://doc.dalek.rs/subtle/
|