mirror of
https://github.com/saymrwulf/curve25519-dalek-source.git
synced 2026-09-06 20:41:14 +00:00
Move ExtendedPoint->MontgomeryPoint conversion to edwards.rs
Need to find a solution to the internal/external docs problem
This commit is contained in:
parent
2b0a4979b1
commit
78d9e70071
2 changed files with 69 additions and 73 deletions
|
|
@ -77,16 +77,10 @@ use core::ops::{Add, Sub, Neg};
|
||||||
use constants;
|
use constants;
|
||||||
|
|
||||||
use field::FieldElement;
|
use field::FieldElement;
|
||||||
|
|
||||||
use edwards::ExtendedPoint;
|
use edwards::ExtendedPoint;
|
||||||
use edwards::CompressedEdwardsY;
|
|
||||||
use montgomery::MontgomeryPoint;
|
|
||||||
|
|
||||||
use subtle::ConditionallyAssignable;
|
use subtle::ConditionallyAssignable;
|
||||||
|
|
||||||
use traits::ValidityCheck;
|
use traits::ValidityCheck;
|
||||||
|
|
||||||
|
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
// Internal point representations
|
// Internal point representations
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
@ -235,70 +229,6 @@ impl ProjectivePoint {
|
||||||
T: &self.X * &self.Y,
|
T: &self.X * &self.Y,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Convert this projective point in the Edwards model to its equivalent
|
|
||||||
/// projective point on the Montgomery form of the curve.
|
|
||||||
///
|
|
||||||
/// Taking the Montgomery curve equation in affine coordinates:
|
|
||||||
///
|
|
||||||
/// E_(A,B) = Bv² = u³ + Au² + u <span style="float: right">(1)</span>
|
|
||||||
///
|
|
||||||
/// and given its relations to the coordinates of the Edwards model:
|
|
||||||
///
|
|
||||||
/// u = (1+y)/(1-y) <span style="float: right">(2)</span>
|
|
||||||
/// v = (λu)/(x)
|
|
||||||
///
|
|
||||||
/// Converting from affine to projective coordinates in the Montgomery
|
|
||||||
/// model, we arrive at:
|
|
||||||
///
|
|
||||||
/// u = (Z+Y)/(Z-Y) <span style="float: right">(3)</span>
|
|
||||||
/// v = λ * ((Z+Y)/(Z-Y)) * (Z/X)
|
|
||||||
///
|
|
||||||
/// The transition between affine and projective is given by
|
|
||||||
///
|
|
||||||
/// u → U/W <span style="float: right">(4)</span>
|
|
||||||
/// v → V/W
|
|
||||||
///
|
|
||||||
/// thus the Montgomery curve equation (1) becomes
|
|
||||||
///
|
|
||||||
/// E_(A,B) : BV²W = U³ + AU²W + UW² ⊆ 𝗣^2 <span style="float: right">(5)</span>
|
|
||||||
///
|
|
||||||
/// Here, again, to differentiate from points in the twisted Edwards model, we
|
|
||||||
/// call the point `(x,y)` in affine coordinates `(u,v)` and similarly in projective
|
|
||||||
/// space we use `(U:V:W)`. However, since (as per Montgomery's original work) the
|
|
||||||
/// v-coordinate is superfluous to the definition of the group law, we merely
|
|
||||||
/// use `(U:W)`.
|
|
||||||
///
|
|
||||||
/// Therefore, the direct translation between projective Montgomery points
|
|
||||||
/// and projective twisted Edwards points is
|
|
||||||
///
|
|
||||||
/// (U:W) = (Z+Y:Z-Y) <span style="float: right">(6)</span>
|
|
||||||
///
|
|
||||||
/// Note, however, that there appears to be an exception where `Z=Y`,
|
|
||||||
/// since—from equation 2—this would imply that `y=1` (thus causing the
|
|
||||||
/// denominator to be zero). If this is the case, then it follows from the
|
|
||||||
/// twisted Edwards curve equation
|
|
||||||
///
|
|
||||||
/// -x² + y² = 1 + dx²y² <span style="float: right">(7)</span>
|
|
||||||
///
|
|
||||||
/// that
|
|
||||||
///
|
|
||||||
/// -x² + 1 = 1 + dx²
|
|
||||||
///
|
|
||||||
/// and, assuming that `d ≠ -1`,
|
|
||||||
///
|
|
||||||
/// -x² = x²
|
|
||||||
/// x = 0
|
|
||||||
///
|
|
||||||
/// Therefore, the only valid point with `y=1` is the twisted Edwards
|
|
||||||
/// identity point, which correctly becomes `(1:0)`, that is, the identity,
|
|
||||||
/// in the Montgomery model.
|
|
||||||
pub fn to_montgomery(&self) -> MontgomeryPoint {
|
|
||||||
MontgomeryPoint{
|
|
||||||
U: &self.Z + &self.Y,
|
|
||||||
W: &self.Z - &self.Y,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
impl CompletedPoint {
|
impl CompletedPoint {
|
||||||
|
|
|
||||||
|
|
@ -269,10 +269,76 @@ impl ExtendedPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Convert this point to its equivalent on the Montgomery form of the
|
/// Convert this `ExtendedPoint` on the Edwards model to the
|
||||||
/// curve.
|
/// corresponding `MontgomeryPoint` on the Montgomery model.
|
||||||
|
///
|
||||||
|
/// Note that this is a one-way conversion, since the Montgomery
|
||||||
|
/// model does not retain sign information.
|
||||||
|
///
|
||||||
|
// XXX need to figure out how to keep this in internal docs, and
|
||||||
|
// also to rewrite it to use tex
|
||||||
|
//
|
||||||
|
// # Implementation notes
|
||||||
|
//
|
||||||
|
// Taking the Montgomery curve equation in affine coordinates:
|
||||||
|
//
|
||||||
|
// E_(A,B) = Bv² = u³ + Au² + u <span style="float: right">(1)</span>
|
||||||
|
//
|
||||||
|
// and given its relations to the coordinates of the Edwards model:
|
||||||
|
//
|
||||||
|
// u = (1+y)/(1-y) <span style="float: right">(2)</span>
|
||||||
|
// v = (λu)/(x)
|
||||||
|
//
|
||||||
|
// Converting from affine to projective coordinates in the Montgomery
|
||||||
|
// model, we arrive at:
|
||||||
|
//
|
||||||
|
// u = (Z+Y)/(Z-Y) <span style="float: right">(3)</span>
|
||||||
|
// v = λ * ((Z+Y)/(Z-Y)) * (Z/X)
|
||||||
|
//
|
||||||
|
// The transition between affine and projective is given by
|
||||||
|
//
|
||||||
|
// u → U/W <span style="float: right">(4)</span>
|
||||||
|
// v → V/W
|
||||||
|
//
|
||||||
|
// thus the Montgomery curve equation (1) becomes
|
||||||
|
//
|
||||||
|
// E_(A,B) : BV²W = U³ + AU²W + UW² ⊆ 𝗣^2 <span style="float: right">(5)</span>
|
||||||
|
//
|
||||||
|
// Here, again, to differentiate from points in the twisted Edwards model, we
|
||||||
|
// call the point `(x,y)` in affine coordinates `(u,v)` and similarly in projective
|
||||||
|
// space we use `(U:V:W)`. However, since (as per Montgomery's original work) the
|
||||||
|
// v-coordinate is not required to perform scalar multiplication, we merely
|
||||||
|
// use `(U:W)`.
|
||||||
|
//
|
||||||
|
// Therefore, the direct translation between projective Montgomery points
|
||||||
|
// and projective twisted Edwards points is
|
||||||
|
//
|
||||||
|
// (U:W) = (Z+Y:Z-Y) <span style="float: right">(6)</span>
|
||||||
|
//
|
||||||
|
// Note, however, that there appears to be an exception where `Z=Y`,
|
||||||
|
// since—from equation 2—this would imply that `y=1` (thus causing the
|
||||||
|
// denominator to be zero). If this is the case, then it follows from the
|
||||||
|
// twisted Edwards curve equation
|
||||||
|
//
|
||||||
|
// -x² + y² = 1 + dx²y² <span style="float: right">(7)</span>
|
||||||
|
//
|
||||||
|
// that
|
||||||
|
//
|
||||||
|
// -x² + 1 = 1 + dx²
|
||||||
|
//
|
||||||
|
// and, assuming that `d ≠ -1`,
|
||||||
|
//
|
||||||
|
// -x² = x²
|
||||||
|
// x = 0
|
||||||
|
//
|
||||||
|
// Therefore, the only valid point with `y=1` is the twisted Edwards
|
||||||
|
// identity point, which correctly becomes `(1:0)`, that is, the identity,
|
||||||
|
// in the Montgomery model.
|
||||||
pub fn to_montgomery(&self) -> MontgomeryPoint {
|
pub fn to_montgomery(&self) -> MontgomeryPoint {
|
||||||
self.to_projective().to_montgomery()
|
MontgomeryPoint{
|
||||||
|
U: &self.Z + &self.Y,
|
||||||
|
W: &self.Z - &self.Y,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Compress this point to `CompressedEdwardsY` format.
|
/// Compress this point to `CompressedEdwardsY` format.
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue