mirror of
https://github.com/saymrwulf/curve25519-dalek-source.git
synced 2026-09-04 20:24:10 +00:00
Move ExtendedPoint->MontgomeryPoint conversion to edwards.rs
Need to find a solution to the internal/external docs problem
This commit is contained in:
parent
2b0a4979b1
commit
78d9e70071
2 changed files with 69 additions and 73 deletions
|
|
@ -77,16 +77,10 @@ use core::ops::{Add, Sub, Neg};
|
|||
use constants;
|
||||
|
||||
use field::FieldElement;
|
||||
|
||||
use edwards::ExtendedPoint;
|
||||
use edwards::CompressedEdwardsY;
|
||||
use montgomery::MontgomeryPoint;
|
||||
|
||||
use subtle::ConditionallyAssignable;
|
||||
|
||||
use traits::ValidityCheck;
|
||||
|
||||
|
||||
// ------------------------------------------------------------------------
|
||||
// Internal point representations
|
||||
// ------------------------------------------------------------------------
|
||||
|
|
@ -235,70 +229,6 @@ impl ProjectivePoint {
|
|||
T: &self.X * &self.Y,
|
||||
}
|
||||
}
|
||||
|
||||
/// Convert this projective point in the Edwards model to its equivalent
|
||||
/// projective point on the Montgomery form of the curve.
|
||||
///
|
||||
/// Taking the Montgomery curve equation in affine coordinates:
|
||||
///
|
||||
/// E_(A,B) = Bv² = u³ + Au² + u <span style="float: right">(1)</span>
|
||||
///
|
||||
/// and given its relations to the coordinates of the Edwards model:
|
||||
///
|
||||
/// u = (1+y)/(1-y) <span style="float: right">(2)</span>
|
||||
/// v = (λu)/(x)
|
||||
///
|
||||
/// Converting from affine to projective coordinates in the Montgomery
|
||||
/// model, we arrive at:
|
||||
///
|
||||
/// u = (Z+Y)/(Z-Y) <span style="float: right">(3)</span>
|
||||
/// v = λ * ((Z+Y)/(Z-Y)) * (Z/X)
|
||||
///
|
||||
/// The transition between affine and projective is given by
|
||||
///
|
||||
/// u → U/W <span style="float: right">(4)</span>
|
||||
/// v → V/W
|
||||
///
|
||||
/// thus the Montgomery curve equation (1) becomes
|
||||
///
|
||||
/// E_(A,B) : BV²W = U³ + AU²W + UW² ⊆ 𝗣^2 <span style="float: right">(5)</span>
|
||||
///
|
||||
/// Here, again, to differentiate from points in the twisted Edwards model, we
|
||||
/// call the point `(x,y)` in affine coordinates `(u,v)` and similarly in projective
|
||||
/// space we use `(U:V:W)`. However, since (as per Montgomery's original work) the
|
||||
/// v-coordinate is superfluous to the definition of the group law, we merely
|
||||
/// use `(U:W)`.
|
||||
///
|
||||
/// Therefore, the direct translation between projective Montgomery points
|
||||
/// and projective twisted Edwards points is
|
||||
///
|
||||
/// (U:W) = (Z+Y:Z-Y) <span style="float: right">(6)</span>
|
||||
///
|
||||
/// Note, however, that there appears to be an exception where `Z=Y`,
|
||||
/// since—from equation 2—this would imply that `y=1` (thus causing the
|
||||
/// denominator to be zero). If this is the case, then it follows from the
|
||||
/// twisted Edwards curve equation
|
||||
///
|
||||
/// -x² + y² = 1 + dx²y² <span style="float: right">(7)</span>
|
||||
///
|
||||
/// that
|
||||
///
|
||||
/// -x² + 1 = 1 + dx²
|
||||
///
|
||||
/// and, assuming that `d ≠ -1`,
|
||||
///
|
||||
/// -x² = x²
|
||||
/// x = 0
|
||||
///
|
||||
/// Therefore, the only valid point with `y=1` is the twisted Edwards
|
||||
/// identity point, which correctly becomes `(1:0)`, that is, the identity,
|
||||
/// in the Montgomery model.
|
||||
pub fn to_montgomery(&self) -> MontgomeryPoint {
|
||||
MontgomeryPoint{
|
||||
U: &self.Z + &self.Y,
|
||||
W: &self.Z - &self.Y,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl CompletedPoint {
|
||||
|
|
|
|||
|
|
@ -269,10 +269,76 @@ impl ExtendedPoint {
|
|||
}
|
||||
}
|
||||
|
||||
/// Convert this point to its equivalent on the Montgomery form of the
|
||||
/// curve.
|
||||
/// Convert this `ExtendedPoint` on the Edwards model to the
|
||||
/// corresponding `MontgomeryPoint` on the Montgomery model.
|
||||
///
|
||||
/// Note that this is a one-way conversion, since the Montgomery
|
||||
/// model does not retain sign information.
|
||||
///
|
||||
// XXX need to figure out how to keep this in internal docs, and
|
||||
// also to rewrite it to use tex
|
||||
//
|
||||
// # Implementation notes
|
||||
//
|
||||
// Taking the Montgomery curve equation in affine coordinates:
|
||||
//
|
||||
// E_(A,B) = Bv² = u³ + Au² + u <span style="float: right">(1)</span>
|
||||
//
|
||||
// and given its relations to the coordinates of the Edwards model:
|
||||
//
|
||||
// u = (1+y)/(1-y) <span style="float: right">(2)</span>
|
||||
// v = (λu)/(x)
|
||||
//
|
||||
// Converting from affine to projective coordinates in the Montgomery
|
||||
// model, we arrive at:
|
||||
//
|
||||
// u = (Z+Y)/(Z-Y) <span style="float: right">(3)</span>
|
||||
// v = λ * ((Z+Y)/(Z-Y)) * (Z/X)
|
||||
//
|
||||
// The transition between affine and projective is given by
|
||||
//
|
||||
// u → U/W <span style="float: right">(4)</span>
|
||||
// v → V/W
|
||||
//
|
||||
// thus the Montgomery curve equation (1) becomes
|
||||
//
|
||||
// E_(A,B) : BV²W = U³ + AU²W + UW² ⊆ 𝗣^2 <span style="float: right">(5)</span>
|
||||
//
|
||||
// Here, again, to differentiate from points in the twisted Edwards model, we
|
||||
// call the point `(x,y)` in affine coordinates `(u,v)` and similarly in projective
|
||||
// space we use `(U:V:W)`. However, since (as per Montgomery's original work) the
|
||||
// v-coordinate is not required to perform scalar multiplication, we merely
|
||||
// use `(U:W)`.
|
||||
//
|
||||
// Therefore, the direct translation between projective Montgomery points
|
||||
// and projective twisted Edwards points is
|
||||
//
|
||||
// (U:W) = (Z+Y:Z-Y) <span style="float: right">(6)</span>
|
||||
//
|
||||
// Note, however, that there appears to be an exception where `Z=Y`,
|
||||
// since—from equation 2—this would imply that `y=1` (thus causing the
|
||||
// denominator to be zero). If this is the case, then it follows from the
|
||||
// twisted Edwards curve equation
|
||||
//
|
||||
// -x² + y² = 1 + dx²y² <span style="float: right">(7)</span>
|
||||
//
|
||||
// that
|
||||
//
|
||||
// -x² + 1 = 1 + dx²
|
||||
//
|
||||
// and, assuming that `d ≠ -1`,
|
||||
//
|
||||
// -x² = x²
|
||||
// x = 0
|
||||
//
|
||||
// Therefore, the only valid point with `y=1` is the twisted Edwards
|
||||
// identity point, which correctly becomes `(1:0)`, that is, the identity,
|
||||
// in the Montgomery model.
|
||||
pub fn to_montgomery(&self) -> MontgomeryPoint {
|
||||
self.to_projective().to_montgomery()
|
||||
MontgomeryPoint{
|
||||
U: &self.Z + &self.Y,
|
||||
W: &self.Z - &self.Y,
|
||||
}
|
||||
}
|
||||
|
||||
/// Compress this point to `CompressedEdwardsY` format.
|
||||
|
|
|
|||
Loading…
Reference in a new issue