mirror of
https://github.com/saymrwulf/curve25519-dalek-source.git
synced 2026-09-07 20:50:39 +00:00
Reorganize AVX2 point code
This commit is contained in:
parent
e8b053b281
commit
7ef6a1e6fa
5 changed files with 68 additions and 77 deletions
|
|
@ -24,7 +24,7 @@ use subtle::Choice;
|
||||||
|
|
||||||
use edwards;
|
use edwards;
|
||||||
use scalar::Scalar;
|
use scalar::Scalar;
|
||||||
use scalar_mul::window::LookupTable;
|
use scalar_mul::window::{LookupTable, OddLookupTable};
|
||||||
|
|
||||||
use traits::Identity;
|
use traits::Identity;
|
||||||
|
|
||||||
|
|
@ -76,62 +76,6 @@ impl Identity for ExtendedPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// A cached point with some precomputed variables used for readdition.
|
|
||||||
#[derive(Copy, Clone, Debug)]
|
|
||||||
pub struct CachedPoint(pub(super) FieldElement32x4);
|
|
||||||
|
|
||||||
impl From<ExtendedPoint> for CachedPoint {
|
|
||||||
fn from(P: ExtendedPoint) -> CachedPoint {
|
|
||||||
let mut x = P.0;
|
|
||||||
|
|
||||||
// x = (S2 S3 Z2 T2)
|
|
||||||
x.diff_sum(0b00001111);
|
|
||||||
|
|
||||||
// x = (121666*S2 121666*S3 2*121666*Z2 2*121665*T2)
|
|
||||||
x.scale_by_curve_constants();
|
|
||||||
|
|
||||||
// x = (121666*S2 121666*S3 2*121666*Z2 -2*121665*T2)
|
|
||||||
x.negate(D_LANES);
|
|
||||||
|
|
||||||
CachedPoint(x)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Default for CachedPoint {
|
|
||||||
fn default() -> CachedPoint {
|
|
||||||
CachedPoint::identity()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Identity for CachedPoint {
|
|
||||||
fn identity() -> CachedPoint {
|
|
||||||
CachedPoint(FieldElement32x4([
|
|
||||||
u32x8::new(121647, 121666, 0, 0, 243332, 67108845, 0, 33554431),
|
|
||||||
u32x8::new(67108864, 0, 33554431, 0, 0, 67108863, 0, 33554431),
|
|
||||||
u32x8::new(67108863, 0, 33554431, 0, 0, 67108863, 0, 33554431),
|
|
||||||
u32x8::new(67108863, 0, 33554431, 0, 0, 67108863, 0, 33554431),
|
|
||||||
u32x8::new(67108863, 0, 33554431, 0, 0, 67108863, 0, 33554431),
|
|
||||||
]))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl ConditionallyAssignable for CachedPoint {
|
|
||||||
fn conditional_assign(&mut self, other: &CachedPoint, choice: Choice) {
|
|
||||||
self.0.conditional_assign(&other.0, choice);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl<'a> Neg for &'a CachedPoint {
|
|
||||||
type Output = CachedPoint;
|
|
||||||
|
|
||||||
fn neg(self) -> CachedPoint {
|
|
||||||
let mut neg = *self;
|
|
||||||
neg.0.swap_AB();
|
|
||||||
neg.0.negate_lazy(D_LANES);
|
|
||||||
neg
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl ExtendedPoint {
|
impl ExtendedPoint {
|
||||||
pub fn double(&self) -> ExtendedPoint {
|
pub fn double(&self) -> ExtendedPoint {
|
||||||
unsafe {
|
unsafe {
|
||||||
|
|
@ -236,6 +180,62 @@ impl ExtendedPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// A cached point with some precomputed variables used for readdition.
|
||||||
|
#[derive(Copy, Clone, Debug)]
|
||||||
|
pub struct CachedPoint(pub(super) FieldElement32x4);
|
||||||
|
|
||||||
|
impl From<ExtendedPoint> for CachedPoint {
|
||||||
|
fn from(P: ExtendedPoint) -> CachedPoint {
|
||||||
|
let mut x = P.0;
|
||||||
|
|
||||||
|
// x = (S2 S3 Z2 T2)
|
||||||
|
x.diff_sum(0b00001111);
|
||||||
|
|
||||||
|
// x = (121666*S2 121666*S3 2*121666*Z2 2*121665*T2)
|
||||||
|
x.scale_by_curve_constants();
|
||||||
|
|
||||||
|
// x = (121666*S2 121666*S3 2*121666*Z2 -2*121665*T2)
|
||||||
|
x.negate(D_LANES);
|
||||||
|
|
||||||
|
CachedPoint(x)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Default for CachedPoint {
|
||||||
|
fn default() -> CachedPoint {
|
||||||
|
CachedPoint::identity()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Identity for CachedPoint {
|
||||||
|
fn identity() -> CachedPoint {
|
||||||
|
CachedPoint(FieldElement32x4([
|
||||||
|
u32x8::new(121647, 121666, 0, 0, 243332, 67108845, 0, 33554431),
|
||||||
|
u32x8::new(67108864, 0, 33554431, 0, 0, 67108863, 0, 33554431),
|
||||||
|
u32x8::new(67108863, 0, 33554431, 0, 0, 67108863, 0, 33554431),
|
||||||
|
u32x8::new(67108863, 0, 33554431, 0, 0, 67108863, 0, 33554431),
|
||||||
|
u32x8::new(67108863, 0, 33554431, 0, 0, 67108863, 0, 33554431),
|
||||||
|
]))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl ConditionallyAssignable for CachedPoint {
|
||||||
|
fn conditional_assign(&mut self, other: &CachedPoint, choice: Choice) {
|
||||||
|
self.0.conditional_assign(&other.0, choice);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl<'a> Neg for &'a CachedPoint {
|
||||||
|
type Output = CachedPoint;
|
||||||
|
|
||||||
|
fn neg(self) -> CachedPoint {
|
||||||
|
let mut neg = *self;
|
||||||
|
neg.0.swap_AB();
|
||||||
|
neg.0.negate_lazy(D_LANES);
|
||||||
|
neg
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
impl<'a, 'b> Add<&'b CachedPoint> for &'a ExtendedPoint {
|
impl<'a, 'b> Add<&'b CachedPoint> for &'a ExtendedPoint {
|
||||||
type Output = ExtendedPoint;
|
type Output = ExtendedPoint;
|
||||||
|
|
||||||
|
|
@ -288,8 +288,9 @@ impl<'a, 'b> Sub<&'b CachedPoint> for &'a ExtendedPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl From<ExtendedPoint> for LookupTable<CachedPoint> {
|
impl<'a> From<&'a edwards::EdwardsPoint> for LookupTable<CachedPoint> {
|
||||||
fn from(P: ExtendedPoint) -> Self {
|
fn from(point: &'a edwards::EdwardsPoint) -> Self {
|
||||||
|
let P = ExtendedPoint::from(*point);
|
||||||
let mut points = [CachedPoint::from(P); 8];
|
let mut points = [CachedPoint::from(P); 8];
|
||||||
for i in 0..7 {
|
for i in 0..7 {
|
||||||
points[i+1] = (&P + &points[i]).into();
|
points[i+1] = (&P + &points[i]).into();
|
||||||
|
|
@ -298,11 +299,10 @@ impl From<ExtendedPoint> for LookupTable<CachedPoint> {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
use scalar_mul::window::OddLookupTable;
|
impl<'a> From<&'a edwards::EdwardsPoint> for OddLookupTable<CachedPoint> {
|
||||||
|
fn from(point: &'a edwards::EdwardsPoint) -> Self {
|
||||||
impl<'a> From<&'a ExtendedPoint> for OddLookupTable<CachedPoint> {
|
let A = ExtendedPoint::from(*point);
|
||||||
fn from(A: &'a ExtendedPoint) -> Self {
|
let mut Ai = [CachedPoint::from(A); 8];
|
||||||
let mut Ai = [CachedPoint::from(*A); 8];
|
|
||||||
let A2 = A.double();
|
let A2 = A.double();
|
||||||
for i in 0..7 {
|
for i in 0..7 {
|
||||||
Ai[i + 1] = (&A2 + &Ai[i]).into();
|
Ai[i + 1] = (&A2 + &Ai[i]).into();
|
||||||
|
|
|
||||||
|
|
@ -31,10 +31,7 @@ where
|
||||||
// for each input point P
|
// for each input point P
|
||||||
let lookup_tables: Vec<_> = points
|
let lookup_tables: Vec<_> = points
|
||||||
.into_iter()
|
.into_iter()
|
||||||
.map(|point| {
|
.map(|point| LookupTable::<CachedPoint>::from(point.borrow()))
|
||||||
let avx2_point = ExtendedPoint::from(*point.borrow());
|
|
||||||
LookupTable::<CachedPoint>::from(avx2_point)
|
|
||||||
})
|
|
||||||
.collect();
|
.collect();
|
||||||
|
|
||||||
let scalar_digits_vec: Vec<_> = scalars
|
let scalar_digits_vec: Vec<_> = scalars
|
||||||
|
|
|
||||||
|
|
@ -8,10 +8,8 @@ use scalar_mul::window::LookupTable;
|
||||||
|
|
||||||
/// Perform constant-time, variable-base scalar multiplication.
|
/// Perform constant-time, variable-base scalar multiplication.
|
||||||
pub fn mul(point: &EdwardsPoint, scalar: &Scalar) -> EdwardsPoint {
|
pub fn mul(point: &EdwardsPoint, scalar: &Scalar) -> EdwardsPoint {
|
||||||
// XXX combine these conversions
|
|
||||||
let avx2_point = ExtendedPoint::from(*point);
|
|
||||||
// Construct a lookup table of [P,2P,3P,4P,5P,6P,7P,8P]
|
// Construct a lookup table of [P,2P,3P,4P,5P,6P,7P,8P]
|
||||||
let lookup_table = LookupTable::<CachedPoint>::from(avx2_point);
|
let lookup_table = LookupTable::<CachedPoint>::from(point);
|
||||||
// Setting s = scalar, compute
|
// Setting s = scalar, compute
|
||||||
//
|
//
|
||||||
// s = s_0 + s_1*16^1 + ... + s_63*16^63,
|
// s = s_0 + s_1*16^1 + ... + s_63*16^63,
|
||||||
|
|
|
||||||
|
|
@ -30,8 +30,7 @@ pub fn mul(a: &Scalar, A: &EdwardsPoint, b: &Scalar) -> EdwardsPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
let avx2_A = ExtendedPoint::from(*A);
|
let table_A = OddLookupTable::<CachedPoint>::from(A);
|
||||||
let table_A = OddLookupTable::<CachedPoint>::from(&avx2_A);
|
|
||||||
let table_B = &BASEPOINT_ODD_LOOKUP_TABLE;
|
let table_B = &BASEPOINT_ODD_LOOKUP_TABLE;
|
||||||
|
|
||||||
let mut Q = ExtendedPoint::identity();
|
let mut Q = ExtendedPoint::identity();
|
||||||
|
|
|
||||||
|
|
@ -31,10 +31,7 @@ where
|
||||||
.collect();
|
.collect();
|
||||||
let lookup_tables: Vec<_> = points
|
let lookup_tables: Vec<_> = points
|
||||||
.into_iter()
|
.into_iter()
|
||||||
.map(|point| {
|
.map(|point| OddLookupTable::<CachedPoint>::from(point.borrow()))
|
||||||
let avx2_point = ExtendedPoint::from(*point.borrow());
|
|
||||||
OddLookupTable::<CachedPoint>::from(&avx2_point)
|
|
||||||
})
|
|
||||||
.collect();
|
.collect();
|
||||||
|
|
||||||
let mut Q = ExtendedPoint::identity();
|
let mut Q = ExtendedPoint::identity();
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue