Check the equality of EdwardsPoints in the projective coordinates to avoid expensive compressions.

This commit is contained in:
Sean Bowe 2019-01-23 14:56:31 -07:00
parent ff0dc4a3db
commit d71b6650d6
No known key found for this signature in database
GPG key ID: 95684257D8F8B031

View file

@ -394,7 +394,14 @@ impl ConditionallySelectable for EdwardsPoint {
impl ConstantTimeEq for EdwardsPoint {
fn ct_eq(&self, other: &EdwardsPoint) -> Choice {
self.compress().ct_eq(&other.compress())
// We would like to check that the point (X/Z, Y/Z) is equal to
// the point (X'/Z', Y'/Z') without converting into affine
// coordinates (x, y) and (x', y'), which requires two inversions.
// We have that X = xZ and X' = x'Z'. Thus, x = x' is equivalent to
// (xZ)Z' = (x'Z')Z, and similarly for the y-coordinate.
(&self.X * &other.Z).ct_eq(&(&other.X * &self.Z))
& (&self.Y * &other.Z).ct_eq(&(&other.Y * &self.Z))
}
}