From 3f7923b628693c885f1935396fad5780e451ab5e Mon Sep 17 00:00:00 2001 From: Henry de Valence Date: Thu, 25 Jan 2018 12:00:40 -0800 Subject: [PATCH] Keep the AVX2 point type named as `ExtendedPoint`. --- src/backend/avx2/constants.rs | 20 ++-- src/backend/avx2/edwards.rs | 167 +++++++++++++++++----------------- src/edwards.rs | 4 +- 3 files changed, 95 insertions(+), 96 deletions(-) diff --git a/src/backend/avx2/constants.rs b/src/backend/avx2/constants.rs index aff80c0..087d96c 100644 --- a/src/backend/avx2/constants.rs +++ b/src/backend/avx2/constants.rs @@ -13,7 +13,7 @@ use stdsimd::simd::u32x8; use backend::avx2::field::FieldElement32x4; -use backend::avx2::edwards::EdwardsPoint; +use backend::avx2::edwards::ExtendedPoint; /// The low limbs of (2p, 2p, 2p, 2p), so that /// ```no_run @@ -52,57 +52,57 @@ pub(crate) static P_TIMES_2_MASKED: FieldElement32x4 = FieldElement32x4([ ]); /// Odd multiples of the Ed25519 basepoint: -pub static ODD_MULTIPLES_OF_BASEPOINT: [EdwardsPoint; 8] = [ - EdwardsPoint(FieldElement32x4([ +pub static ODD_MULTIPLES_OF_BASEPOINT: [ExtendedPoint; 8] = [ + ExtendedPoint(FieldElement32x4([ u32x8::new(52811034, 40265304, 25909283, 26843545, 1, 28827043, 0, 27438313), u32x8::new(16144682, 13421772, 17082669, 20132659, 0, 39759291, 0, 244362), u32x8::new(27570973, 26843545, 30858332, 6710886, 0, 8635006, 0, 11264893), u32x8::new(40966398, 53687091, 8378388, 13421772, 0, 19351346, 0, 13413597), u32x8::new(20764389, 40265318, 8758491, 26843545, 0, 16611511, 0, 27139452), ])), - EdwardsPoint(FieldElement32x4([ + ExtendedPoint(FieldElement32x4([ u32x8::new(63703867, 19156774, 608100, 2486757, 12685460, 3173753, 21649412, 16313381), u32x8::new(52397038, 65858675, 26775664, 16661035, 14269998, 9080558, 1059463, 28938752), u32x8::new( 5461635, 28034025, 23358301, 1245198, 1367765, 20288887, 31111942, 18395221), u32x8::new( 1886934, 32436996, 681756, 18977693, 8129860, 40112764, 25764567, 11876840), u32x8::new(63042604, 52399761, 22087481, 29829870, 8565820, 33723612, 28645162, 8502864), ])), - EdwardsPoint(FieldElement32x4([ + ExtendedPoint(FieldElement32x4([ u32x8::new(14879397, 3951036, 9454671, 16606238, 23529732, 44147004, 11890541, 17067526), u32x8::new(58509479, 57216664, 9671992, 32001147, 60966207, 11801823, 10808378, 15115613), u32x8::new(54854992, 39210911, 8112050, 1353604, 1337416, 35520540, 32967851, 17786030), u32x8::new(59007462, 40864509, 26240923, 30403852, 28456403, 21546582, 32732450, 21005910), u32x8::new(40711675, 22446613, 9664668, 12483629, 26142305, 56254715, 15439904, 214849), ])), - EdwardsPoint(FieldElement32x4([ + ExtendedPoint(FieldElement32x4([ u32x8::new(52231579, 51632644, 173613, 7677257, 26374424, 45994428, 5303371, 1425942), u32x8::new(38126791, 48854506, 23252518, 30611978, 49977504, 66706952, 1076178, 27100873), u32x8::new(26349427, 63077566, 20258199, 3884787, 33226507, 2371423, 5787271, 18628170), u32x8::new(15005754, 22729577, 4978944, 2522289, 1404784, 56367795, 22517039, 29271243), u32x8::new(22748934, 35977548, 25561257, 31734126, 22775284, 32000077, 927866, 2278697), ])), - EdwardsPoint(FieldElement32x4([ + ExtendedPoint(FieldElement32x4([ u32x8::new(66090281, 61980626, 23780289, 6519561, 62542590, 47174086, 28818882, 15661068), u32x8::new(17433715, 12931425, 12232056, 7885877, 44179512, 35590146, 32787344, 22631048), u32x8::new(43729883, 6870635, 15782399, 11810556, 2652935, 31800505, 23683367, 13638649), u32x8::new(64007953, 40242373, 32810277, 20180235, 20399465, 48133835, 32913956, 19094667), u32x8::new(56562708, 40269142, 18953105, 9027935, 35700921, 12896915, 14757156, 22773619), ])), - EdwardsPoint(FieldElement32x4([ + ExtendedPoint(FieldElement32x4([ u32x8::new(65129016, 34709402, 25132940, 13788431, 3661652, 16914498, 27409409, 18941039), u32x8::new(42488074, 49427602, 6177212, 20812339, 41644653, 2977316, 12162542, 5293661), u32x8::new( 7981168, 12223605, 6239200, 20403609, 20710415, 4828170, 11627702, 4431044), u32x8::new(65817142, 96824, 25021652, 16364722, 50410869, 24651857, 6979034, 33176209), u32x8::new(33008344, 8687253, 27859668, 28796356, 30192014, 11975680, 11991047, 27710707), ])), - EdwardsPoint(FieldElement32x4([ + ExtendedPoint(FieldElement32x4([ u32x8::new(14676653, 50945941, 13489249, 31456262, 47726639, 21761847, 3324839, 7843947), u32x8::new(53352326, 8688989, 12944061, 12994004, 50113821, 37990636, 1537898, 20483689), u32x8::new(46786852, 15572264, 24004728, 7566233, 32596174, 34437796, 23201722, 3431551), u32x8::new(49025674, 52497128, 13273618, 10266201, 66795206, 2887684, 30966565, 33449990), u32x8::new(53210238, 65839385, 15458877, 18409918, 24777464, 25586795, 15335748, 12323382), ])), - EdwardsPoint(FieldElement32x4([ + ExtendedPoint(FieldElement32x4([ u32x8::new(57816016, 23106045, 24948505, 27413507, 32551424, 26145165, 22632568, 27527446), u32x8::new(53022711, 40974949, 14110533, 30646997, 51399118, 53289754, 32528560, 15822835), u32x8::new(23810949, 51779690, 17532625, 21326637, 60314333, 43761996, 4852905, 3474945), diff --git a/src/backend/avx2/edwards.rs b/src/backend/avx2/edwards.rs index d8cd782..76c81b0 100644 --- a/src/backend/avx2/edwards.rs +++ b/src/backend/avx2/edwards.rs @@ -35,36 +35,36 @@ use backend::avx2; /// A point on Curve25519, represented in an AVX2-friendly format. #[derive(Copy, Clone, Debug)] -pub struct EdwardsPoint(pub(super) FieldElement32x4); +pub struct ExtendedPoint(pub(super) FieldElement32x4); -impl From for EdwardsPoint { - fn from(P: edwards::EdwardsPoint) -> EdwardsPoint { - EdwardsPoint(FieldElement32x4::new(&P.X, &P.Y, &P.Z, &P.T)) +impl From for ExtendedPoint { + fn from(P: edwards::EdwardsPoint) -> ExtendedPoint { + ExtendedPoint(FieldElement32x4::new(&P.X, &P.Y, &P.Z, &P.T)) } } -impl From for edwards::EdwardsPoint { - fn from(P: EdwardsPoint) -> edwards::EdwardsPoint { +impl From for edwards::EdwardsPoint { + fn from(P: ExtendedPoint) -> edwards::EdwardsPoint { let tmp = P.0.split(); edwards::EdwardsPoint{X: tmp[0], Y: tmp[1], Z: tmp[2], T: tmp[3]} } } -impl ConditionallyAssignable for EdwardsPoint { - fn conditional_assign(&mut self, other: &EdwardsPoint, choice: u8) { +impl ConditionallyAssignable for ExtendedPoint { + fn conditional_assign(&mut self, other: &ExtendedPoint, choice: u8) { self.0.conditional_assign(&other.0, choice); } } -impl Default for EdwardsPoint { - fn default() -> EdwardsPoint { - EdwardsPoint::identity() +impl Default for ExtendedPoint { + fn default() -> ExtendedPoint { + ExtendedPoint::identity() } } -impl Identity for EdwardsPoint { - fn identity() -> EdwardsPoint { - EdwardsPoint(FieldElement32x4([ +impl Identity for ExtendedPoint { + fn identity() -> ExtendedPoint { + ExtendedPoint(FieldElement32x4([ u32x8::new(0,1,0,0,1,0,0,0), u32x8::splat(0), u32x8::splat(0), @@ -78,8 +78,8 @@ impl Identity for EdwardsPoint { #[derive(Copy, Clone, Debug)] pub struct CachedPoint(pub(super) FieldElement32x4); -impl From for CachedPoint { - fn from(P: EdwardsPoint) -> CachedPoint { +impl From for CachedPoint { + fn from(P: ExtendedPoint) -> CachedPoint { let mut x = P.0; // x = (S2 S3 Z2 T2) @@ -130,10 +130,10 @@ impl<'a> Neg for &'a CachedPoint { } } -impl<'a> Neg for &'a EdwardsPoint { - type Output = EdwardsPoint; +impl<'a> Neg for &'a ExtendedPoint { + type Output = ExtendedPoint; - fn neg(self) -> EdwardsPoint { + fn neg(self) -> ExtendedPoint { let mut neg = *self; // (X Y Z T) -> (-X Y Z -T) neg.0.negate(A_LANES | D_LANES); @@ -141,8 +141,8 @@ impl<'a> Neg for &'a EdwardsPoint { } } -impl EdwardsPoint { - fn double(&self) -> EdwardsPoint { +impl ExtendedPoint { + fn double(&self) -> ExtendedPoint { unsafe { use stdsimd::vendor::_mm256_permute2x128_si256; use stdsimd::vendor::_mm256_permutevar8x32_epi32; @@ -232,12 +232,12 @@ impl EdwardsPoint { t1.0[i] = _mm256_permutevar8x32_epi32(tmp, c1); } - EdwardsPoint(&t0 * &t1) + ExtendedPoint(&t0 * &t1) } } - pub fn mult_by_pow_2(&self, k: u32) -> EdwardsPoint { - let mut tmp: EdwardsPoint = *self; + pub fn mult_by_pow_2(&self, k: u32) -> ExtendedPoint { + let mut tmp: ExtendedPoint = *self; for _ in 0..k { tmp = tmp.double(); } @@ -245,11 +245,11 @@ impl EdwardsPoint { } } -impl<'a, 'b> Add<&'b CachedPoint> for &'a EdwardsPoint { - type Output = EdwardsPoint; +impl<'a, 'b> Add<&'b CachedPoint> for &'a ExtendedPoint { + type Output = ExtendedPoint; /// Uses a slight tweak of the parallel unified formulas of HWCD'08 - fn add(self, other: &'b CachedPoint) -> EdwardsPoint { + fn add(self, other: &'b CachedPoint) -> ExtendedPoint { unsafe { use stdsimd::vendor::_mm256_permutevar8x32_epi32; @@ -280,16 +280,16 @@ impl<'a, 'b> Add<&'b CachedPoint> for &'a EdwardsPoint { } // return (S12*S14 S15*S13 S15*S14 S12*S13) = (X3 Y3 Z3 T3) - EdwardsPoint(&t0 * &t1) + ExtendedPoint(&t0 * &t1) } } } -impl<'a, 'b> Add<&'b EdwardsPoint> for &'a EdwardsPoint { - type Output = EdwardsPoint; +impl<'a, 'b> Add<&'b ExtendedPoint> for &'a ExtendedPoint { + type Output = ExtendedPoint; /// Uses a slight tweak of the parallel unified formulas of HWCD'08 - fn add(self, other: &'b EdwardsPoint) -> EdwardsPoint { + fn add(self, other: &'b ExtendedPoint) -> ExtendedPoint { unsafe { use stdsimd::vendor::_mm256_permute2x128_si256; use stdsimd::vendor::_mm256_permutevar8x32_epi32; @@ -342,25 +342,25 @@ impl<'a, 'b> Add<&'b EdwardsPoint> for &'a EdwardsPoint { } // return (S12*S14 S15*S13 S15*S14 S12*S13) = (X3 Y3 Z3 T3) - EdwardsPoint(&t0 * &t1) + ExtendedPoint(&t0 * &t1) } } } -impl<'a, 'b> Sub<&'b EdwardsPoint> for &'a EdwardsPoint { - type Output = EdwardsPoint; +impl<'a, 'b> Sub<&'b ExtendedPoint> for &'a ExtendedPoint { + type Output = ExtendedPoint; /// Implement subtraction by negating the point and adding. /// /// Empirically, this seems about the same cost as a custom subtraction impl (maybe because the /// benefit is cancelled by increased code size?) - fn sub(self, other: &'b EdwardsPoint) -> EdwardsPoint { + fn sub(self, other: &'b ExtendedPoint) -> ExtendedPoint { self + &(-other) } } -impl From for LookupTable { - fn from(P: EdwardsPoint) -> Self { +impl From for LookupTable { + fn from(P: ExtendedPoint) -> Self { let mut points = [CachedPoint::from(P); 8]; for i in 0..7 { points[i+1] = (&P + &points[i]).into(); @@ -369,12 +369,12 @@ impl From for LookupTable { } } -impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsPoint { - type Output = EdwardsPoint; +impl<'a, 'b> Mul<&'b Scalar> for &'a ExtendedPoint { + type Output = ExtendedPoint; /// Scalar multiplication: compute `scalar * self`. /// /// Uses a window of size 4. - fn mul(self, scalar: &'b Scalar) -> EdwardsPoint { + fn mul(self, scalar: &'b Scalar) -> ExtendedPoint { // Construct a lookup table of [P,2P,3P,4P,5P,6P,7P,8P] let lookup_table = LookupTable::::from(*self); @@ -392,7 +392,7 @@ impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsPoint { // s*P = P*s_0 + 16*(P*s_1 + 16*(P*s_2 + 16*( ... + P*s_63)...)) // // We sum right-to-left. - let mut Q = EdwardsPoint::identity(); + let mut Q = ExtendedPoint::identity(); for i in (0..64).rev() { // Q = 16*Q Q = Q.mult_by_pow_2(4); @@ -407,13 +407,13 @@ impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsPoint { pub struct EdwardsBasepointTable(pub [LookupTable; 32]); impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsBasepointTable { - type Output = EdwardsPoint; + type Output = ExtendedPoint; - fn mul(self, scalar: &'b Scalar) -> EdwardsPoint { + fn mul(self, scalar: &'b Scalar) -> ExtendedPoint { let a = scalar.to_radix_16(); let tables = &self.0; - let mut P = EdwardsPoint::identity(); + let mut P = ExtendedPoint::identity(); for i in (0..64).filter(|x| x % 2 == 1) { P = &P + &tables[i/2].select(a[i]); @@ -430,17 +430,17 @@ impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsBasepointTable { } impl<'a, 'b> Mul<&'a EdwardsBasepointTable> for &'b Scalar { - type Output = EdwardsPoint; + type Output = ExtendedPoint; /// Given `self` a table of precomputed multiples of the point `B`, compute `B * s`. - fn mul(self, basepoint_table: &'a EdwardsBasepointTable) -> EdwardsPoint { + fn mul(self, basepoint_table: &'a EdwardsBasepointTable) -> ExtendedPoint { basepoint_table * &self } } impl EdwardsBasepointTable { /// Create a table of precomputed multiples of `basepoint`. - pub fn create(basepoint: &EdwardsPoint) -> EdwardsBasepointTable { + pub fn create(basepoint: &ExtendedPoint) -> EdwardsBasepointTable { // XXX use init_with let mut table = EdwardsBasepointTable([LookupTable::default(); 32]); let mut P = *basepoint; @@ -478,7 +478,7 @@ pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> edwards::Edwards use clear_on_drop::ClearOnDrop; let lookup_tables_vec: Vec<_> = points.into_iter() - .map(|P| LookupTable::from(EdwardsPoint::from(*P)) ) + .map(|P| LookupTable::from(ExtendedPoint::from(*P)) ) .collect(); let lookup_tables = ClearOnDrop::new(lookup_tables_vec); @@ -516,7 +516,7 @@ pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> edwards::Edwards // This provides the speedup over doing n independent scalar // mults: we perform 63 multiplications by 16 instead of 63*n // multiplications, saving 252*(n-1) doublings. - let mut Q = EdwardsPoint::identity(); + let mut Q = ExtendedPoint::identity(); // XXX this algorithm makes no effort to be cache-aware; maybe it could be improved? for j in (0..64).rev() { Q = Q.mult_by_pow_2(4); @@ -534,10 +534,10 @@ pub mod vartime { use super::*; /// Holds odd multiples 1A, 3A, ..., 15A of a point A. - struct OddMultiples([EdwardsPoint; 8]); + struct OddMultiples([ExtendedPoint; 8]); impl OddMultiples { - fn create(A: EdwardsPoint) -> OddMultiples { + fn create(A: ExtendedPoint) -> OddMultiples { // XXX would be great to skip this initialization let mut Ai = [A; 8]; let A2 = A.double(); @@ -550,9 +550,9 @@ pub mod vartime { } impl Index for OddMultiples { - type Output = EdwardsPoint; + type Output = ExtendedPoint; - fn index(&self, _index: usize) -> &EdwardsPoint { + fn index(&self, _index: usize) -> &ExtendedPoint { &(self.0[_index]) } } @@ -580,7 +580,7 @@ pub mod vartime { let odd_multiples_of_A = OddMultiples::create((*A).into()); let odd_multiples_of_B = &avx2::constants::ODD_MULTIPLES_OF_BASEPOINT; - let mut Q = EdwardsPoint::identity(); + let mut Q = ExtendedPoint::identity(); loop { Q = Q.double(); @@ -628,7 +628,7 @@ pub mod vartime { let odd_multiples: Vec<_> = points.into_iter() .map(|P| OddMultiples::create((*P).into()) ).collect(); - let mut Q = EdwardsPoint::identity(); + let mut Q = ExtendedPoint::identity(); for i in (0..255).rev() { Q = Q.double(); @@ -715,13 +715,13 @@ mod test { // Test the serial implementation of the parallel addition formulas let R_serial: edwards::EdwardsPoint = serial_add(P.into(), Q.into()).into(); // Test the vector implementation of the parallel addition formulas - let R_vector: edwards::EdwardsPoint = (&EdwardsPoint::from(P) + &EdwardsPoint::from(Q)).into(); + let R_vector: edwards::EdwardsPoint = (&ExtendedPoint::from(P) + &ExtendedPoint::from(Q)).into(); // Test the vector implementation of the parallel subtraction formulas - let S_vector: edwards::EdwardsPoint = (&EdwardsPoint::from(P) - &EdwardsPoint::from(Q)).into(); + let S_vector: edwards::EdwardsPoint = (&ExtendedPoint::from(P) - &ExtendedPoint::from(Q)).into(); // Test the vector implementation of the parallel readdition formulas - let cached_Q = CachedPoint::from(EdwardsPoint::from(Q)); - let T_vector: edwards::EdwardsPoint = (&EdwardsPoint::from(P) + &cached_Q).into(); + let cached_Q = CachedPoint::from(ExtendedPoint::from(Q)); + let T_vector: edwards::EdwardsPoint = (&ExtendedPoint::from(P) + &cached_Q).into(); println!("Testing point addition:"); println!("P = {:?}", P); @@ -742,8 +742,8 @@ mod test { #[test] fn sub_vs_add_minus() { - let P: EdwardsPoint = edwards::EdwardsPoint::identity().into(); - let Q: EdwardsPoint = edwards::EdwardsPoint::identity().into(); + let P: ExtendedPoint = edwards::EdwardsPoint::identity().into(); + let Q: ExtendedPoint = edwards::EdwardsPoint::identity().into(); let mQ = -&Q; @@ -828,7 +828,7 @@ mod test { fn doubling_test_helper(P: edwards::EdwardsPoint) { let R1: edwards::EdwardsPoint = serial_double(P.into()).into(); - let R2: edwards::EdwardsPoint = EdwardsPoint::from(P).double().into(); + let R2: edwards::EdwardsPoint = ExtendedPoint::from(P).double().into(); println!("Testing point doubling:"); println!("P = {:?}", P); println!("(serial) R1 = {:?}", R1); @@ -859,14 +859,14 @@ mod test { #[test] fn identity_trait_vs_edwards_identity() { - let id1: edwards::EdwardsPoint = EdwardsPoint::identity().into(); + let id1: edwards::EdwardsPoint = ExtendedPoint::identity().into(); let id2: edwards::EdwardsPoint = edwards::EdwardsPoint::identity(); assert_eq!(id1.compress(), id2.compress()); } #[test] fn neg_vs_edwards_neg() { - let B: EdwardsPoint = constants::ED25519_BASEPOINT_POINT.into(); + let B: ExtendedPoint = constants::ED25519_BASEPOINT_POINT.into(); let Bneg = -&B; assert_eq!(edwards::EdwardsPoint::from(Bneg).compress(), (-&constants::ED25519_BASEPOINT_POINT).compress()); @@ -874,7 +874,7 @@ mod test { #[test] fn scalar_mult_vs_edwards_scalar_mult() { - let B: EdwardsPoint = constants::ED25519_BASEPOINT_POINT.into(); + let B: ExtendedPoint = constants::ED25519_BASEPOINT_POINT.into(); // some random bytes let s = Scalar::from_bits([233, 1, 233, 147, 113, 78, 244, 120, 40, 45, 103, 51, 224, 199, 189, 218, 96, 140, 211, 112, 39, 194, 73, 216, 173, 33, 102, 93, 76, 200, 84, 12]); @@ -886,7 +886,7 @@ mod test { #[test] fn scalar_mult_vs_basepoint_table_scalar_mult() { - let B: EdwardsPoint = constants::ED25519_BASEPOINT_POINT.into(); + let B: ExtendedPoint = constants::ED25519_BASEPOINT_POINT.into(); let B_table = EdwardsBasepointTable::create(&B); // some random bytes let s = Scalar::from_bits([233, 1, 233, 147, 113, 78, 244, 120, 40, 45, 103, 51, 224, 199, 189, 218, 96, 140, 211, 112, 39, 194, 73, 216, 173, 33, 102, 93, 76, 200, 84, 12]); @@ -900,7 +900,7 @@ mod test { #[test] fn multiscalar_mult_vs_adding_scalar_mults() { - let B: EdwardsPoint = constants::ED25519_BASEPOINT_POINT.into(); + let B: ExtendedPoint = constants::ED25519_BASEPOINT_POINT.into(); let s1 = Scalar::from_bits([233, 1, 233, 147, 113, 78, 244, 120, 40, 45, 103, 51, 224, 199, 189, 218, 96, 140, 211, 112, 39, 194, 73, 216, 173, 33, 102, 93, 76, 200, 84, 12]); let s2 = Scalar::from_bits([165, 30, 79, 89, 58, 24, 195, 245, 248, 146, 203, 236, 119, 43, 64, 119, 196, 111, 188, 251, 248, 53, 234, 59, 215, 28, 218, 13, 59, 120, 14, 4]); @@ -920,7 +920,7 @@ mod test { #[test] fn multiscalar_mult_vs_adding_scalar_mults() { - let B: EdwardsPoint = constants::ED25519_BASEPOINT_POINT.into(); + let B: ExtendedPoint = constants::ED25519_BASEPOINT_POINT.into(); let s1 = Scalar::from_bits([233, 1, 233, 147, 113, 78, 244, 120, 40, 45, 103, 51, 224, 199, 189, 218, 96, 140, 211, 112, 39, 194, 73, 216, 173, 33, 102, 93, 76, 200, 84, 12]); let s2 = Scalar::from_bits([165, 30, 79, 89, 58, 24, 195, 245, 248, 146, 203, 236, 119, 43, 64, 119, 196, 111, 188, 251, 248, 53, 234, 59, 215, 28, 218, 13, 59, 120, 14, 4]); @@ -950,13 +950,13 @@ mod bench { fn conversion_into__avx2_format(b: &mut Bencher) { let B = constants::ED25519_BASEPOINT_POINT; - b.iter(|| EdwardsPoint::from(B)); + b.iter(|| ExtendedPoint::from(B)); } #[bench] fn conversion_outof_avx2_format(b: &mut Bencher) { let B = constants::ED25519_BASEPOINT_POINT; - let B_avx2 = EdwardsPoint::from(B); + let B_avx2 = ExtendedPoint::from(B); b.iter(|| edwards::EdwardsPoint::from(B_avx2)); } @@ -964,8 +964,8 @@ mod bench { #[bench] fn point_readdition(b: &mut Bencher) { let B = &constants::ED25519_BASEPOINT_TABLE; - let P = EdwardsPoint::from(B * &Scalar::from_u64(83973422)); - let Q = EdwardsPoint::from(B * &Scalar::from_u64(98932328)); + let P = ExtendedPoint::from(B * &Scalar::from_u64(83973422)); + let Q = ExtendedPoint::from(B * &Scalar::from_u64(98932328)); let Q_cached = CachedPoint::from(Q); b.iter(|| &P + &Q_cached ); @@ -974,8 +974,8 @@ mod bench { #[bench] fn point_addition(b: &mut Bencher) { let B = &constants::ED25519_BASEPOINT_TABLE; - let P = EdwardsPoint::from(B * &Scalar::from_u64(83973422)); - let Q = EdwardsPoint::from(B * &Scalar::from_u64(98932328)); + let P = ExtendedPoint::from(B * &Scalar::from_u64(83973422)); + let Q = ExtendedPoint::from(B * &Scalar::from_u64(98932328)); b.iter(|| &P + &Q ); } @@ -983,7 +983,7 @@ mod bench { #[bench] fn point_doubling(b: &mut Bencher) { let B = &constants::ED25519_BASEPOINT_TABLE; - let P = EdwardsPoint::from(B * &Scalar::from_u64(83973422)); + let P = ExtendedPoint::from(B * &Scalar::from_u64(83973422)); b.iter(|| P.double() ); } @@ -991,7 +991,7 @@ mod bench { #[bench] fn scalar_mult(b: &mut Bencher) { let B = &constants::ED25519_BASEPOINT_TABLE; - let P = EdwardsPoint::from(B * &Scalar::from_u64(83973422)); + let P = ExtendedPoint::from(B * &Scalar::from_u64(83973422)); let s = Scalar::from_bits([233, 1, 233, 147, 113, 78, 244, 120, 40, 45, 103, 51, 224, 199, 189, 218, 96, 140, 211, 112, 39, 194, 73, 216, 173, 33, 102, 93, 76, 200, 84, 12]); b.iter(|| &P * &s ); @@ -999,14 +999,14 @@ mod bench { #[bench] fn basepoint_table_creation(b: &mut Bencher) { - let B = EdwardsPoint::from(constants::ED25519_BASEPOINT_POINT); + let B = ExtendedPoint::from(constants::ED25519_BASEPOINT_POINT); b.iter(|| EdwardsBasepointTable::create(&B) ); } #[bench] fn basepoint_mult(b: &mut Bencher) { - let B = EdwardsPoint::from(constants::ED25519_BASEPOINT_POINT); + let B = ExtendedPoint::from(constants::ED25519_BASEPOINT_POINT); let table = EdwardsBasepointTable::create(&B); let s = Scalar::from_bits([233, 1, 233, 147, 113, 78, 244, 120, 40, 45, 103, 51, 224, 199, 189, 218, 96, 140, 211, 112, 39, 194, 73, 216, 173, 33, 102, 93, 76, 200, 84, 12]); @@ -1019,8 +1019,8 @@ mod bench { // Create 10 random scalars let scalars: Vec<_> = (0..10).map(|_| Scalar::random(&mut csprng)).collect(); // Create 10 points (by doing scalar mults) - let B = &constants::ED25519_BASEPOINT_POINT; - let points: Vec<_> = scalars.iter().map(|s| B * &s).collect(); + let B = &constants::ED25519_BASEPOINT_TABLE; + let points: Vec<_> = scalars.iter().map(|s| B * s).collect(); b.iter(|| multiscalar_mult(&scalars, &points)); } @@ -1035,8 +1035,7 @@ mod bench { // Create 2 random scalars let s1 = Scalar::random(&mut csprng); let s2 = Scalar::random(&mut csprng); - let B = constants::ED25519_BASEPOINT_POINT; - let P = &B * &s1; + let P = &s1 * &constants::ED25519_BASEPOINT_TABLE; b.iter(|| vartime::double_scalar_mult_basepoint(&s2, &P, &s1) ); } @@ -1047,8 +1046,8 @@ mod bench { // Create 10 random scalars let scalars: Vec<_> = (0..10).map(|_| Scalar::random(&mut csprng)).collect(); // Create 10 points (by doing scalar mults) - let B = &constants::ED25519_BASEPOINT_POINT; - let points: Vec<_> = scalars.iter().map(|s| B * &s).collect(); + let B = &constants::ED25519_BASEPOINT_TABLE; + let points: Vec<_> = scalars.iter().map(|s| B * s).collect(); b.iter(|| vartime::multiscalar_mult(&scalars, &points)); } diff --git a/src/edwards.rs b/src/edwards.rs index 4973121..8c12ee9 100644 --- a/src/edwards.rs +++ b/src/edwards.rs @@ -455,8 +455,8 @@ impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsPoint { fn mul(self, scalar: &'b Scalar) -> EdwardsPoint { // If we built with AVX2, use the AVX2 backend. #[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] { - use backend::avx2::edwards as edwards_avx2; - let P_avx2 = edwards_avx2::EdwardsPoint::from(*self); + use backend::avx2::edwards::ExtendedPoint; + let P_avx2 = ExtendedPoint::from(*self); return EdwardsPoint::from(&P_avx2 * scalar); } // Otherwise, proceed as normal: