mirror of
https://github.com/saymrwulf/curve25519-dalek-source.git
synced 2026-09-06 20:41:14 +00:00
Implement TryFrom<&[u8]> and ValidityCheck for MontgomeryPoint.
This commit is contained in:
parent
db3d26f4b9
commit
1fa0048262
1 changed files with 41 additions and 0 deletions
|
|
@ -48,6 +48,7 @@
|
||||||
// affine and projective cakes and eat both of them too.
|
// affine and projective cakes and eat both of them too.
|
||||||
#![allow(non_snake_case)]
|
#![allow(non_snake_case)]
|
||||||
|
|
||||||
|
use core::convert::TryFrom;
|
||||||
use core::ops::{Mul, MulAssign};
|
use core::ops::{Mul, MulAssign};
|
||||||
|
|
||||||
use constants::APLUS2_OVER_FOUR;
|
use constants::APLUS2_OVER_FOUR;
|
||||||
|
|
@ -56,6 +57,7 @@ use field::FieldElement;
|
||||||
use scalar::Scalar;
|
use scalar::Scalar;
|
||||||
|
|
||||||
use traits::Identity;
|
use traits::Identity;
|
||||||
|
use traits::ValidityCheck;
|
||||||
|
|
||||||
use subtle::Choice;
|
use subtle::Choice;
|
||||||
use subtle::ConditionallySelectable;
|
use subtle::ConditionallySelectable;
|
||||||
|
|
@ -91,6 +93,45 @@ impl PartialEq for MontgomeryPoint {
|
||||||
|
|
||||||
impl Eq for MontgomeryPoint {}
|
impl Eq for MontgomeryPoint {}
|
||||||
|
|
||||||
|
impl ValidityCheck for MontgomeryPoint {
|
||||||
|
/// Decode the \\(u\\)-coordinate field element and re-encode it
|
||||||
|
/// to its canonical form to check whether the original was valid.
|
||||||
|
///
|
||||||
|
/// There are no other required checks for the Mongomery form of the curve,
|
||||||
|
/// as every element in \\( \mathbb{F}\_{q} \\) lies either on the curve or
|
||||||
|
/// its quadratic twist. (cf. §5.2 of "Montgomery Curves and Their
|
||||||
|
/// Arithmetic" by [Costello and Smith][costello-smith].)
|
||||||
|
///
|
||||||
|
/// [costello-smith]: https://eprint.iacr.org/2017/212.pdf
|
||||||
|
fn is_valid(&self) -> bool {
|
||||||
|
let maybe_u: FieldElement = FieldElement::from_bytes(&self.0);
|
||||||
|
let u: [u8; 32] = maybe_u.to_bytes();
|
||||||
|
|
||||||
|
u.ct_eq(&self.0).into()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl TryFrom<&[u8]> for MontgomeryPoint {
|
||||||
|
type Error = ();
|
||||||
|
|
||||||
|
fn try_from(bytes: &[u8]) -> Result<MontgomeryPoint, ()> {
|
||||||
|
if bytes.len() != 32 {
|
||||||
|
return Err(());
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut array = [0u8; 32];
|
||||||
|
array.copy_from_slice(&bytes[..32]);
|
||||||
|
|
||||||
|
let P = MontgomeryPoint(array);
|
||||||
|
|
||||||
|
if P.is_valid() {
|
||||||
|
return Ok(P);
|
||||||
|
}
|
||||||
|
|
||||||
|
Err(())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
impl MontgomeryPoint {
|
impl MontgomeryPoint {
|
||||||
/// View this `MontgomeryPoint` as an array of bytes.
|
/// View this `MontgomeryPoint` as an array of bytes.
|
||||||
pub fn as_bytes<'a>(&'a self) -> &'a [u8; 32] {
|
pub fn as_bytes<'a>(&'a self) -> &'a [u8; 32] {
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue