mirror of
https://github.com/saymrwulf/curve25519-dalek-source.git
synced 2026-09-06 20:41:14 +00:00
Merge remote-tracking branch 'hdevalence/feature/fixup-deps' into develop
This commit is contained in:
commit
f6030dbe85
9 changed files with 229 additions and 254 deletions
64
Cargo.toml
64
Cargo.toml
|
|
@ -24,54 +24,34 @@ rustdoc-args = ["--html-in-header", ".cargo/registry/src/github.com-1ecc6299db9e
|
||||||
[badges]
|
[badges]
|
||||||
travis-ci = { repository = "dalek-cryptography/curve25519-dalek", branch = "master"}
|
travis-ci = { repository = "dalek-cryptography/curve25519-dalek", branch = "master"}
|
||||||
|
|
||||||
[dependencies.stdsimd]
|
[dev-dependencies]
|
||||||
version = "0.0.4"
|
sha2 = "0.7"
|
||||||
optional = true
|
serde_cbor = "0.6"
|
||||||
|
|
||||||
[dependencies.serde]
|
# Note: we generate precomputed tables by building the crate twice: once as
|
||||||
version = "1.0"
|
# part of build.rs, and then once "for real".
|
||||||
optional = true
|
#
|
||||||
|
# This means that the [dependencies] and [build-dependencies] sections must
|
||||||
|
# match exactly, since the build.rs uses the crate itself as a library.
|
||||||
|
|
||||||
[dependencies.rand]
|
[dependencies]
|
||||||
optional = true
|
digest = "0.7"
|
||||||
version = "0.4"
|
generic-array = "0.9"
|
||||||
|
clear_on_drop = "=0.2.3"
|
||||||
[dependencies.digest]
|
subtle = { version = "0.5", features = ["generic-impls"], default-features = false }
|
||||||
version = "0.7"
|
stdsimd = { version = "0.0.4", optional = true }
|
||||||
|
serde = { version = "1.0", optional = true }
|
||||||
[dependencies.subtle]
|
rand = { version = "0.4", optional = true }
|
||||||
version = "0.5"
|
|
||||||
default-features = false
|
|
||||||
features = ["generic-impls"]
|
|
||||||
|
|
||||||
[dependencies.clear_on_drop]
|
|
||||||
version = "=0.2.3"
|
|
||||||
|
|
||||||
[dependencies.generic-array]
|
|
||||||
# same version that digest depends on
|
|
||||||
version = "0.9"
|
|
||||||
|
|
||||||
[dev-dependencies.sha2]
|
|
||||||
version = "0.7"
|
|
||||||
|
|
||||||
[dev-dependencies.serde_cbor]
|
|
||||||
version = "0.6"
|
|
||||||
|
|
||||||
[build-dependencies]
|
[build-dependencies]
|
||||||
subtle = "^0.3"
|
|
||||||
rand = "0.4"
|
|
||||||
generic-array = "0.9"
|
|
||||||
digest = "0.7"
|
digest = "0.7"
|
||||||
arrayref = "0.3.4"
|
generic-array = "0.9"
|
||||||
clear_on_drop = "=0.2.3"
|
clear_on_drop = "=0.2.3"
|
||||||
|
subtle = { version = "0.5", features = ["generic-impls"], default-features = false }
|
||||||
[build-dependencies.stdsimd]
|
stdsimd = { version = "0.0.4", optional = true }
|
||||||
version = "0.0.4"
|
serde = { version = "1.0", optional = true }
|
||||||
optional = true
|
# Allowing rand to be optional during builds causes a build failure when compiling for no_std targets
|
||||||
|
rand = { version = "0.4", optional = false }
|
||||||
[build-dependencies.serde]
|
|
||||||
version = "1.0"
|
|
||||||
optional = true
|
|
||||||
|
|
||||||
[features]
|
[features]
|
||||||
nightly = ["radix_51", "subtle/nightly", "clear_on_drop/nightly"]
|
nightly = ["radix_51", "subtle/nightly", "clear_on_drop/nightly"]
|
||||||
|
|
|
||||||
|
|
@ -37,16 +37,16 @@ use backend::avx2;
|
||||||
#[derive(Copy, Clone, Debug)]
|
#[derive(Copy, Clone, Debug)]
|
||||||
pub struct ExtendedPoint(pub(super) FieldElement32x4);
|
pub struct ExtendedPoint(pub(super) FieldElement32x4);
|
||||||
|
|
||||||
impl From<edwards::ExtendedPoint> for ExtendedPoint {
|
impl From<edwards::EdwardsPoint> for ExtendedPoint {
|
||||||
fn from(P: edwards::ExtendedPoint) -> ExtendedPoint {
|
fn from(P: edwards::EdwardsPoint) -> ExtendedPoint {
|
||||||
ExtendedPoint(FieldElement32x4::new(&P.X, &P.Y, &P.Z, &P.T))
|
ExtendedPoint(FieldElement32x4::new(&P.X, &P.Y, &P.Z, &P.T))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl From<ExtendedPoint> for edwards::ExtendedPoint {
|
impl From<ExtendedPoint> for edwards::EdwardsPoint {
|
||||||
fn from(P: ExtendedPoint) -> edwards::ExtendedPoint {
|
fn from(P: ExtendedPoint) -> edwards::EdwardsPoint {
|
||||||
let tmp = P.0.split();
|
let tmp = P.0.split();
|
||||||
edwards::ExtendedPoint{X: tmp[0], Y: tmp[1], Z: tmp[2], T: tmp[3]}
|
edwards::EdwardsPoint{X: tmp[0], Y: tmp[1], Z: tmp[2], T: tmp[3]}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -461,18 +461,18 @@ impl EdwardsBasepointTable {
|
||||||
///
|
///
|
||||||
/// # Input
|
/// # Input
|
||||||
///
|
///
|
||||||
/// A vector of `Scalar`s and a vector of `ExtendedPoints`. It is an
|
/// A vector of `Scalar`s and a vector of `EdwardsPoints`. It is an
|
||||||
/// error to call this function with two vectors of different lengths.
|
/// error to call this function with two vectors of different lengths.
|
||||||
///
|
///
|
||||||
/// XXX this takes `edwards::ExtendedPoints` because we have to alloc scratch space here anyways,
|
/// XXX this takes `edwards::EdwardsPoints` because we have to alloc scratch space here anyways,
|
||||||
/// and we need some space to store the converted points, so we may as well do the conversion here.
|
/// and we need some space to store the converted points, so we may as well do the conversion here.
|
||||||
/// maybe there's a better way to avoid code duplication... however we can't quite just write a
|
/// maybe there's a better way to avoid code duplication... however we can't quite just write a
|
||||||
/// generic `multiscalar_mult` because the non-vectorized code passes between models and this code
|
/// generic `multiscalar_mult` because the non-vectorized code passes between models and this code
|
||||||
/// doesn't.
|
/// doesn't.
|
||||||
#[cfg(any(feature = "alloc", feature = "std"))]
|
#[cfg(any(feature = "alloc", feature = "std"))]
|
||||||
pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> edwards::ExtendedPoint
|
pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> edwards::EdwardsPoint
|
||||||
where I: IntoIterator<Item = &'a Scalar>,
|
where I: IntoIterator<Item = &'a Scalar>,
|
||||||
J: IntoIterator<Item = &'b edwards::ExtendedPoint>
|
J: IntoIterator<Item = &'b edwards::EdwardsPoint>
|
||||||
{
|
{
|
||||||
//assert_eq!(scalars.len(), points.len());
|
//assert_eq!(scalars.len(), points.len());
|
||||||
|
|
||||||
|
|
@ -563,8 +563,8 @@ pub mod vartime {
|
||||||
///
|
///
|
||||||
/// This is the same as calling the iterator-based function, but slightly faster.
|
/// This is the same as calling the iterator-based function, but slightly faster.
|
||||||
pub fn double_scalar_mult_basepoint(a: &Scalar,
|
pub fn double_scalar_mult_basepoint(a: &Scalar,
|
||||||
A: &edwards::ExtendedPoint,
|
A: &edwards::EdwardsPoint,
|
||||||
b: &Scalar) -> edwards::ExtendedPoint {
|
b: &Scalar) -> edwards::EdwardsPoint {
|
||||||
let a_naf = a.non_adjacent_form();
|
let a_naf = a.non_adjacent_form();
|
||||||
let b_naf = b.non_adjacent_form();
|
let b_naf = b.non_adjacent_form();
|
||||||
|
|
||||||
|
|
@ -613,12 +613,12 @@ pub mod vartime {
|
||||||
///
|
///
|
||||||
/// # Input
|
/// # Input
|
||||||
///
|
///
|
||||||
/// A vector of `Scalar`s and a vector of `ExtendedPoints`. It is an
|
/// A vector of `Scalar`s and a vector of `EdwardsPoints`. It is an
|
||||||
/// error to call this function with two vectors of different lengths.
|
/// error to call this function with two vectors of different lengths.
|
||||||
#[cfg(any(feature = "alloc", feature = "std"))]
|
#[cfg(any(feature = "alloc", feature = "std"))]
|
||||||
pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> edwards::ExtendedPoint
|
pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> edwards::EdwardsPoint
|
||||||
where I: IntoIterator<Item = &'a Scalar>,
|
where I: IntoIterator<Item = &'a Scalar>,
|
||||||
J: IntoIterator<Item = &'b edwards::ExtendedPoint>
|
J: IntoIterator<Item = &'b edwards::EdwardsPoint>
|
||||||
{
|
{
|
||||||
//assert_eq!(scalars.len(), points.len());
|
//assert_eq!(scalars.len(), points.len());
|
||||||
|
|
||||||
|
|
@ -651,7 +651,7 @@ mod test {
|
||||||
|
|
||||||
use constants;
|
use constants;
|
||||||
|
|
||||||
fn serial_add(P: edwards::ExtendedPoint, Q: edwards::ExtendedPoint) -> edwards::ExtendedPoint {
|
fn serial_add(P: edwards::EdwardsPoint, Q: edwards::EdwardsPoint) -> edwards::EdwardsPoint {
|
||||||
use backend::u64::field::FieldElement64;
|
use backend::u64::field::FieldElement64;
|
||||||
|
|
||||||
let (X1, Y1, Z1, T1) = (P.X, P.Y, P.Z, P.T);
|
let (X1, Y1, Z1, T1) = (P.X, P.Y, P.Z, P.T);
|
||||||
|
|
@ -708,20 +708,20 @@ mod test {
|
||||||
let Z3 = &S15 * &S14; // R2 * R3
|
let Z3 = &S15 * &S14; // R2 * R3
|
||||||
let T3 = &S12 * &S13; // R1 * R4
|
let T3 = &S12 * &S13; // R1 * R4
|
||||||
|
|
||||||
edwards::ExtendedPoint{X: X3, Y: Y3, Z: Z3, T: T3}
|
edwards::EdwardsPoint{X: X3, Y: Y3, Z: Z3, T: T3}
|
||||||
}
|
}
|
||||||
|
|
||||||
fn addition_test_helper(P: edwards::ExtendedPoint, Q: edwards::ExtendedPoint) {
|
fn addition_test_helper(P: edwards::EdwardsPoint, Q: edwards::EdwardsPoint) {
|
||||||
// Test the serial implementation of the parallel addition formulas
|
// Test the serial implementation of the parallel addition formulas
|
||||||
let R_serial: edwards::ExtendedPoint = serial_add(P.into(), Q.into()).into();
|
let R_serial: edwards::EdwardsPoint = serial_add(P.into(), Q.into()).into();
|
||||||
// Test the vector implementation of the parallel addition formulas
|
// Test the vector implementation of the parallel addition formulas
|
||||||
let R_vector: edwards::ExtendedPoint = (&ExtendedPoint::from(P) + &ExtendedPoint::from(Q)).into();
|
let R_vector: edwards::EdwardsPoint = (&ExtendedPoint::from(P) + &ExtendedPoint::from(Q)).into();
|
||||||
// Test the vector implementation of the parallel subtraction formulas
|
// Test the vector implementation of the parallel subtraction formulas
|
||||||
let S_vector: edwards::ExtendedPoint = (&ExtendedPoint::from(P) - &ExtendedPoint::from(Q)).into();
|
let S_vector: edwards::EdwardsPoint = (&ExtendedPoint::from(P) - &ExtendedPoint::from(Q)).into();
|
||||||
|
|
||||||
// Test the vector implementation of the parallel readdition formulas
|
// Test the vector implementation of the parallel readdition formulas
|
||||||
let cached_Q = CachedPoint::from(ExtendedPoint::from(Q));
|
let cached_Q = CachedPoint::from(ExtendedPoint::from(Q));
|
||||||
let T_vector: edwards::ExtendedPoint = (&ExtendedPoint::from(P) + &cached_Q).into();
|
let T_vector: edwards::EdwardsPoint = (&ExtendedPoint::from(P) + &cached_Q).into();
|
||||||
|
|
||||||
println!("Testing point addition:");
|
println!("Testing point addition:");
|
||||||
println!("P = {:?}", P);
|
println!("P = {:?}", P);
|
||||||
|
|
@ -742,18 +742,18 @@ mod test {
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn sub_vs_add_minus() {
|
fn sub_vs_add_minus() {
|
||||||
let P: ExtendedPoint = edwards::ExtendedPoint::identity().into();
|
let P: ExtendedPoint = edwards::EdwardsPoint::identity().into();
|
||||||
let Q: ExtendedPoint = edwards::ExtendedPoint::identity().into();
|
let Q: ExtendedPoint = edwards::EdwardsPoint::identity().into();
|
||||||
|
|
||||||
let mQ = -&Q;
|
let mQ = -&Q;
|
||||||
|
|
||||||
println!("sub");
|
println!("sub");
|
||||||
let R1: edwards::ExtendedPoint = (&P - &Q).into();
|
let R1: edwards::EdwardsPoint = (&P - &Q).into();
|
||||||
println!("add neg");
|
println!("add neg");
|
||||||
let R2: edwards::ExtendedPoint = (&P + &mQ).into();
|
let R2: edwards::EdwardsPoint = (&P + &mQ).into();
|
||||||
|
|
||||||
assert_eq!(R2.compress(), edwards::ExtendedPoint::identity().compress());
|
assert_eq!(R2.compress(), edwards::EdwardsPoint::identity().compress());
|
||||||
assert_eq!(R1.compress(), edwards::ExtendedPoint::identity().compress());
|
assert_eq!(R1.compress(), edwards::EdwardsPoint::identity().compress());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
@ -763,12 +763,12 @@ mod test {
|
||||||
use scalar::Scalar;
|
use scalar::Scalar;
|
||||||
|
|
||||||
println!("Testing id +- id");
|
println!("Testing id +- id");
|
||||||
let P = edwards::ExtendedPoint::identity();
|
let P = edwards::EdwardsPoint::identity();
|
||||||
let Q = edwards::ExtendedPoint::identity();
|
let Q = edwards::EdwardsPoint::identity();
|
||||||
addition_test_helper(P, Q);
|
addition_test_helper(P, Q);
|
||||||
|
|
||||||
println!("Testing id +- B");
|
println!("Testing id +- B");
|
||||||
let P = edwards::ExtendedPoint::identity();
|
let P = edwards::EdwardsPoint::identity();
|
||||||
let Q = constants::ED25519_BASEPOINT_POINT;
|
let Q = constants::ED25519_BASEPOINT_POINT;
|
||||||
addition_test_helper(P, Q);
|
addition_test_helper(P, Q);
|
||||||
|
|
||||||
|
|
@ -783,7 +783,7 @@ mod test {
|
||||||
addition_test_helper(P, Q);
|
addition_test_helper(P, Q);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn serial_double(P: edwards::ExtendedPoint) -> edwards::ExtendedPoint {
|
fn serial_double(P: edwards::EdwardsPoint) -> edwards::EdwardsPoint {
|
||||||
let (X1, Y1, Z1, T1) = (P.X, P.Y, P.Z, P.T);
|
let (X1, Y1, Z1, T1) = (P.X, P.Y, P.Z, P.T);
|
||||||
|
|
||||||
macro_rules! print_var {
|
macro_rules! print_var {
|
||||||
|
|
@ -823,12 +823,12 @@ mod test {
|
||||||
let Z3 = &S8 * &S6;
|
let Z3 = &S8 * &S6;
|
||||||
let T3 = &S5 * &S9;
|
let T3 = &S5 * &S9;
|
||||||
|
|
||||||
edwards::ExtendedPoint{X: X3, Y: Y3, Z: Z3, T: T3}
|
edwards::EdwardsPoint{X: X3, Y: Y3, Z: Z3, T: T3}
|
||||||
}
|
}
|
||||||
|
|
||||||
fn doubling_test_helper(P: edwards::ExtendedPoint) {
|
fn doubling_test_helper(P: edwards::EdwardsPoint) {
|
||||||
let R1: edwards::ExtendedPoint = serial_double(P.into()).into();
|
let R1: edwards::EdwardsPoint = serial_double(P.into()).into();
|
||||||
let R2: edwards::ExtendedPoint = ExtendedPoint::from(P).double().into();
|
let R2: edwards::EdwardsPoint = ExtendedPoint::from(P).double().into();
|
||||||
println!("Testing point doubling:");
|
println!("Testing point doubling:");
|
||||||
println!("P = {:?}", P);
|
println!("P = {:?}", P);
|
||||||
println!("(serial) R1 = {:?}", R1);
|
println!("(serial) R1 = {:?}", R1);
|
||||||
|
|
@ -845,7 +845,7 @@ mod test {
|
||||||
use scalar::Scalar;
|
use scalar::Scalar;
|
||||||
|
|
||||||
println!("Testing [2]id");
|
println!("Testing [2]id");
|
||||||
let P = edwards::ExtendedPoint::identity();
|
let P = edwards::EdwardsPoint::identity();
|
||||||
doubling_test_helper(P);
|
doubling_test_helper(P);
|
||||||
|
|
||||||
println!("Testing [2]B");
|
println!("Testing [2]B");
|
||||||
|
|
@ -859,8 +859,8 @@ mod test {
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn identity_trait_vs_edwards_identity() {
|
fn identity_trait_vs_edwards_identity() {
|
||||||
let id1: edwards::ExtendedPoint = ExtendedPoint::identity().into();
|
let id1: edwards::EdwardsPoint = ExtendedPoint::identity().into();
|
||||||
let id2: edwards::ExtendedPoint = edwards::ExtendedPoint::identity();
|
let id2: edwards::EdwardsPoint = edwards::EdwardsPoint::identity();
|
||||||
assert_eq!(id1.compress(), id2.compress());
|
assert_eq!(id1.compress(), id2.compress());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -868,7 +868,7 @@ mod test {
|
||||||
fn neg_vs_edwards_neg() {
|
fn neg_vs_edwards_neg() {
|
||||||
let B: ExtendedPoint = constants::ED25519_BASEPOINT_POINT.into();
|
let B: ExtendedPoint = constants::ED25519_BASEPOINT_POINT.into();
|
||||||
let Bneg = -&B;
|
let Bneg = -&B;
|
||||||
assert_eq!(edwards::ExtendedPoint::from(Bneg).compress(),
|
assert_eq!(edwards::EdwardsPoint::from(Bneg).compress(),
|
||||||
(-&constants::ED25519_BASEPOINT_POINT).compress());
|
(-&constants::ED25519_BASEPOINT_POINT).compress());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -878,7 +878,7 @@ mod test {
|
||||||
// some random bytes
|
// some random bytes
|
||||||
let s = Scalar::from_bits([233, 1, 233, 147, 113, 78, 244, 120, 40, 45, 103, 51, 224, 199, 189, 218, 96, 140, 211, 112, 39, 194, 73, 216, 173, 33, 102, 93, 76, 200, 84, 12]);
|
let s = Scalar::from_bits([233, 1, 233, 147, 113, 78, 244, 120, 40, 45, 103, 51, 224, 199, 189, 218, 96, 140, 211, 112, 39, 194, 73, 216, 173, 33, 102, 93, 76, 200, 84, 12]);
|
||||||
|
|
||||||
let R1 = edwards::ExtendedPoint::from(&B * &s);
|
let R1 = edwards::EdwardsPoint::from(&B * &s);
|
||||||
let R2 = &constants::ED25519_BASEPOINT_TABLE * &s;
|
let R2 = &constants::ED25519_BASEPOINT_TABLE * &s;
|
||||||
|
|
||||||
assert_eq!(R1.compress(), R2.compress());
|
assert_eq!(R1.compress(), R2.compress());
|
||||||
|
|
@ -894,8 +894,8 @@ mod test {
|
||||||
let P1 = &B * &s;
|
let P1 = &B * &s;
|
||||||
let P2 = &B_table * &s;
|
let P2 = &B_table * &s;
|
||||||
|
|
||||||
assert_eq!(edwards::ExtendedPoint::from(P1).compress(),
|
assert_eq!(edwards::EdwardsPoint::from(P1).compress(),
|
||||||
edwards::ExtendedPoint::from(P2).compress());
|
edwards::EdwardsPoint::from(P2).compress());
|
||||||
}
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
|
|
@ -911,7 +911,7 @@ mod test {
|
||||||
|
|
||||||
let R_multiscalar = multiscalar_mult(&[s1, s2], &[P1.into(), P2.into()]);
|
let R_multiscalar = multiscalar_mult(&[s1, s2], &[P1.into(), P2.into()]);
|
||||||
|
|
||||||
assert_eq!(edwards::ExtendedPoint::from(R).compress(),
|
assert_eq!(edwards::EdwardsPoint::from(R).compress(),
|
||||||
R_multiscalar.compress());
|
R_multiscalar.compress());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -931,7 +931,7 @@ mod test {
|
||||||
|
|
||||||
let R_multiscalar = vartime::multiscalar_mult(&[s1, s2], &[P1.into(), P2.into()]);
|
let R_multiscalar = vartime::multiscalar_mult(&[s1, s2], &[P1.into(), P2.into()]);
|
||||||
|
|
||||||
assert_eq!(edwards::ExtendedPoint::from(R).compress(),
|
assert_eq!(edwards::EdwardsPoint::from(R).compress(),
|
||||||
R_multiscalar.compress());
|
R_multiscalar.compress());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -958,7 +958,7 @@ mod bench {
|
||||||
let B = constants::ED25519_BASEPOINT_POINT;
|
let B = constants::ED25519_BASEPOINT_POINT;
|
||||||
let B_avx2 = ExtendedPoint::from(B);
|
let B_avx2 = ExtendedPoint::from(B);
|
||||||
|
|
||||||
b.iter(|| edwards::ExtendedPoint::from(B_avx2));
|
b.iter(|| edwards::EdwardsPoint::from(B_avx2));
|
||||||
}
|
}
|
||||||
|
|
||||||
#[bench]
|
#[bench]
|
||||||
|
|
@ -1019,8 +1019,8 @@ mod bench {
|
||||||
// Create 10 random scalars
|
// Create 10 random scalars
|
||||||
let scalars: Vec<_> = (0..10).map(|_| Scalar::random(&mut csprng)).collect();
|
let scalars: Vec<_> = (0..10).map(|_| Scalar::random(&mut csprng)).collect();
|
||||||
// Create 10 points (by doing scalar mults)
|
// Create 10 points (by doing scalar mults)
|
||||||
let B = &constants::ED25519_BASEPOINT_POINT;
|
let B = &constants::ED25519_BASEPOINT_TABLE;
|
||||||
let points: Vec<_> = scalars.iter().map(|s| B * &s).collect();
|
let points: Vec<_> = scalars.iter().map(|s| B * s).collect();
|
||||||
|
|
||||||
b.iter(|| multiscalar_mult(&scalars, &points));
|
b.iter(|| multiscalar_mult(&scalars, &points));
|
||||||
}
|
}
|
||||||
|
|
@ -1035,8 +1035,7 @@ mod bench {
|
||||||
// Create 2 random scalars
|
// Create 2 random scalars
|
||||||
let s1 = Scalar::random(&mut csprng);
|
let s1 = Scalar::random(&mut csprng);
|
||||||
let s2 = Scalar::random(&mut csprng);
|
let s2 = Scalar::random(&mut csprng);
|
||||||
let B = constants::ED25519_BASEPOINT_POINT;
|
let P = &s1 * &constants::ED25519_BASEPOINT_TABLE;
|
||||||
let P = &B * &s1;
|
|
||||||
|
|
||||||
b.iter(|| vartime::double_scalar_mult_basepoint(&s2, &P, &s1) );
|
b.iter(|| vartime::double_scalar_mult_basepoint(&s2, &P, &s1) );
|
||||||
}
|
}
|
||||||
|
|
@ -1047,8 +1046,8 @@ mod bench {
|
||||||
// Create 10 random scalars
|
// Create 10 random scalars
|
||||||
let scalars: Vec<_> = (0..10).map(|_| Scalar::random(&mut csprng)).collect();
|
let scalars: Vec<_> = (0..10).map(|_| Scalar::random(&mut csprng)).collect();
|
||||||
// Create 10 points (by doing scalar mults)
|
// Create 10 points (by doing scalar mults)
|
||||||
let B = &constants::ED25519_BASEPOINT_POINT;
|
let B = &constants::ED25519_BASEPOINT_TABLE;
|
||||||
let points: Vec<_> = scalars.iter().map(|s| B * &s).collect();
|
let points: Vec<_> = scalars.iter().map(|s| B * s).collect();
|
||||||
|
|
||||||
b.iter(|| vartime::multiscalar_mult(&scalars, &points));
|
b.iter(|| vartime::multiscalar_mult(&scalars, &points));
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -14,7 +14,7 @@
|
||||||
|
|
||||||
use backend::u32::field::FieldElement32;
|
use backend::u32::field::FieldElement32;
|
||||||
use backend::u32::scalar::Scalar32;
|
use backend::u32::scalar::Scalar32;
|
||||||
use edwards::ExtendedPoint;
|
use edwards::EdwardsPoint;
|
||||||
|
|
||||||
/// Edwards `d` value, equal to `-121665/121666 mod p`.
|
/// Edwards `d` value, equal to `-121665/121666 mod p`.
|
||||||
pub(crate) const EDWARDS_D: FieldElement32 = FieldElement32([
|
pub(crate) const EDWARDS_D: FieldElement32 = FieldElement32([
|
||||||
|
|
@ -84,7 +84,7 @@ pub(crate) const RR: Scalar32 = Scalar32([ 0x0b5f9d12, 0x1e141b17, 0x158d7f3d, 0
|
||||||
/// The Ed25519 basepoint has y = 4/5. This is called `_POINT` to
|
/// The Ed25519 basepoint has y = 4/5. This is called `_POINT` to
|
||||||
/// distinguish it from `_TABLE`, which should be used for scalar
|
/// distinguish it from `_TABLE`, which should be used for scalar
|
||||||
/// multiplication (it's much faster).
|
/// multiplication (it's much faster).
|
||||||
pub const ED25519_BASEPOINT_POINT: ExtendedPoint = ExtendedPoint{
|
pub const ED25519_BASEPOINT_POINT: EdwardsPoint = EdwardsPoint{
|
||||||
X: FieldElement32([52811034, 25909283, 16144682, 17082669, 27570973, 30858332, 40966398, 8378388, 20764389, 8758491]),
|
X: FieldElement32([52811034, 25909283, 16144682, 17082669, 27570973, 30858332, 40966398, 8378388, 20764389, 8758491]),
|
||||||
Y: FieldElement32([40265304, 26843545, 13421772, 20132659, 26843545, 6710886, 53687091, 13421772, 40265318, 26843545]),
|
Y: FieldElement32([40265304, 26843545, 13421772, 20132659, 26843545, 6710886, 53687091, 13421772, 40265318, 26843545]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
|
|
@ -98,50 +98,50 @@ pub const ED25519_BASEPOINT_POINT: ExtendedPoint = ExtendedPoint{
|
||||||
///
|
///
|
||||||
/// Thus Ɛ[4] is the points indexed by 0,2,4,6 and Ɛ[2] is the points
|
/// Thus Ɛ[4] is the points indexed by 0,2,4,6 and Ɛ[2] is the points
|
||||||
/// indexed by 0,4.
|
/// indexed by 0,4.
|
||||||
pub const EIGHT_TORSION: [ExtendedPoint; 8] = [
|
pub const EIGHT_TORSION: [EdwardsPoint; 8] = [
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
X: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
Y: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Y: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
T: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0])
|
T: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0])
|
||||||
},
|
},
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: FieldElement32([21352778, 5345713, 4660180, 25206575, 24143089, 14568123, 30185756, 21306662, 33579924, 8345318]),
|
X: FieldElement32([21352778, 5345713, 4660180, 25206575, 24143089, 14568123, 30185756, 21306662, 33579924, 8345318]),
|
||||||
Y: FieldElement32([6952903, 1265500, 60246523, 7057497, 4037696, 5447722, 35427965, 15325401, 19365852, 31985330]),
|
Y: FieldElement32([6952903, 1265500, 60246523, 7057497, 4037696, 5447722, 35427965, 15325401, 19365852, 31985330]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
T: FieldElement32([41846657, 21581751, 11716001, 27684820, 48915701, 16297738, 20670665, 24995334, 3541542, 28543251])
|
T: FieldElement32([41846657, 21581751, 11716001, 27684820, 48915701, 16297738, 20670665, 24995334, 3541542, 28543251])
|
||||||
},
|
},
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: FieldElement32([32595773, 7943725, 57730914, 30054016, 54719391, 272472, 25146209, 2005654, 66782178, 22147949]),
|
X: FieldElement32([32595773, 7943725, 57730914, 30054016, 54719391, 272472, 25146209, 2005654, 66782178, 22147949]),
|
||||||
Y: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Y: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
T: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0])
|
T: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0])
|
||||||
},
|
},
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: FieldElement32([21352778, 5345713, 4660180, 25206575, 24143089, 14568123, 30185756, 21306662, 33579924, 8345318]),
|
X: FieldElement32([21352778, 5345713, 4660180, 25206575, 24143089, 14568123, 30185756, 21306662, 33579924, 8345318]),
|
||||||
Y: FieldElement32([60155942, 32288931, 6862340, 26496934, 63071167, 28106709, 31680898, 18229030, 47743011, 1569101]),
|
Y: FieldElement32([60155942, 32288931, 6862340, 26496934, 63071167, 28106709, 31680898, 18229030, 47743011, 1569101]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
T: FieldElement32([25262188, 11972680, 55392862, 5869611, 18193162, 17256693, 46438198, 8559097, 63567321, 5011180])
|
T: FieldElement32([25262188, 11972680, 55392862, 5869611, 18193162, 17256693, 46438198, 8559097, 63567321, 5011180])
|
||||||
},
|
},
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
X: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
Y: FieldElement32([67108844, 33554431, 67108863, 33554431, 67108863, 33554431, 67108863, 33554431, 67108863, 33554431]),
|
Y: FieldElement32([67108844, 33554431, 67108863, 33554431, 67108863, 33554431, 67108863, 33554431, 67108863, 33554431]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
T: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0])
|
T: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0])
|
||||||
},
|
},
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: FieldElement32([45756067, 28208718, 62448683, 8347856, 42965774, 18986308, 36923107, 12247769, 33528939, 25209113]),
|
X: FieldElement32([45756067, 28208718, 62448683, 8347856, 42965774, 18986308, 36923107, 12247769, 33528939, 25209113]),
|
||||||
Y: FieldElement32([60155942, 32288931, 6862340, 26496934, 63071167, 28106709, 31680898, 18229030, 47743011, 1569101]),
|
Y: FieldElement32([60155942, 32288931, 6862340, 26496934, 63071167, 28106709, 31680898, 18229030, 47743011, 1569101]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
T: FieldElement32([41846657, 21581751, 11716001, 27684820, 48915701, 16297738, 20670665, 24995334, 3541542, 28543251])
|
T: FieldElement32([41846657, 21581751, 11716001, 27684820, 48915701, 16297738, 20670665, 24995334, 3541542, 28543251])
|
||||||
},
|
},
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: FieldElement32([34513072, 25610706, 9377949, 3500415, 12389472, 33281959, 41962654, 31548777, 326685, 11406482]),
|
X: FieldElement32([34513072, 25610706, 9377949, 3500415, 12389472, 33281959, 41962654, 31548777, 326685, 11406482]),
|
||||||
Y: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Y: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
T: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0])
|
T: FieldElement32([0, 0, 0, 0, 0, 0, 0, 0, 0, 0])
|
||||||
},
|
},
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: FieldElement32([45756067, 28208718, 62448683, 8347856, 42965774, 18986308, 36923107, 12247769, 33528939, 25209113]),
|
X: FieldElement32([45756067, 28208718, 62448683, 8347856, 42965774, 18986308, 36923107, 12247769, 33528939, 25209113]),
|
||||||
Y: FieldElement32([6952903, 1265500, 60246523, 7057497, 4037696, 5447722, 35427965, 15325401, 19365852, 31985330]),
|
Y: FieldElement32([6952903, 1265500, 60246523, 7057497, 4037696, 5447722, 35427965, 15325401, 19365852, 31985330]),
|
||||||
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
Z: FieldElement32([1, 0, 0, 0, 0, 0, 0, 0, 0, 0]),
|
||||||
|
|
|
||||||
|
|
@ -12,7 +12,7 @@
|
||||||
|
|
||||||
use backend::u64::field::FieldElement64;
|
use backend::u64::field::FieldElement64;
|
||||||
use backend::u64::scalar::Scalar64;
|
use backend::u64::scalar::Scalar64;
|
||||||
use edwards::ExtendedPoint;
|
use edwards::EdwardsPoint;
|
||||||
|
|
||||||
/// Edwards `d` value, equal to `-121665/121666 mod p`.
|
/// Edwards `d` value, equal to `-121665/121666 mod p`.
|
||||||
pub(crate) const EDWARDS_D: FieldElement64 = FieldElement64([929955233495203, 466365720129213, 1662059464998953, 2033849074728123, 1442794654840575]);
|
pub(crate) const EDWARDS_D: FieldElement64 = FieldElement64([929955233495203, 466365720129213, 1662059464998953, 2033849074728123, 1442794654840575]);
|
||||||
|
|
@ -57,7 +57,7 @@ pub(crate) const RR: Scalar64 = Scalar64([ 0x0009d265e952d13b, 0x000d63c715bea69
|
||||||
/// The Ed25519 basepoint has y = 4/5. This is called `_POINT` to
|
/// The Ed25519 basepoint has y = 4/5. This is called `_POINT` to
|
||||||
/// distinguish it from `_TABLE`, which should be used for scalar
|
/// distinguish it from `_TABLE`, which should be used for scalar
|
||||||
/// multiplication (it's much faster).
|
/// multiplication (it's much faster).
|
||||||
pub const ED25519_BASEPOINT_POINT: ExtendedPoint = ExtendedPoint{
|
pub const ED25519_BASEPOINT_POINT: EdwardsPoint = EdwardsPoint{
|
||||||
X: FieldElement64([1738742601995546, 1146398526822698, 2070867633025821, 562264141797630, 587772402128613]),
|
X: FieldElement64([1738742601995546, 1146398526822698, 2070867633025821, 562264141797630, 587772402128613]),
|
||||||
Y: FieldElement64([1801439850948184, 1351079888211148, 450359962737049, 900719925474099, 1801439850948198]),
|
Y: FieldElement64([1801439850948184, 1351079888211148, 450359962737049, 900719925474099, 1801439850948198]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
|
|
@ -71,57 +71,57 @@ pub const ED25519_BASEPOINT_POINT: ExtendedPoint = ExtendedPoint{
|
||||||
///
|
///
|
||||||
/// Thus Ɛ[4] is the points indexed by 0,2,4,6 and Ɛ[2] is the points
|
/// Thus Ɛ[4] is the points indexed by 0,2,4,6 and Ɛ[2] is the points
|
||||||
/// indexed by 0,4.
|
/// indexed by 0,4.
|
||||||
pub const EIGHT_TORSION: [ExtendedPoint; 8] = [
|
pub const EIGHT_TORSION: [EdwardsPoint; 8] = [
|
||||||
ExtendedPoint {
|
EdwardsPoint {
|
||||||
X: FieldElement64([0, 0, 0, 0, 0]),
|
X: FieldElement64([0, 0, 0, 0, 0]),
|
||||||
Y: FieldElement64([1, 0, 0, 0, 0]),
|
Y: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
T: FieldElement64([0, 0, 0, 0, 0]),
|
T: FieldElement64([0, 0, 0, 0, 0]),
|
||||||
}
|
}
|
||||||
,
|
,
|
||||||
ExtendedPoint {
|
EdwardsPoint {
|
||||||
X: FieldElement64([358744748052810, 1691584618240980, 977650209285361, 1429865912637724, 560044844278676]),
|
X: FieldElement64([358744748052810, 1691584618240980, 977650209285361, 1429865912637724, 560044844278676]),
|
||||||
Y: FieldElement64([84926274344903, 473620666599931, 365590438845504, 1028470286882429, 2146499180330972]),
|
Y: FieldElement64([84926274344903, 473620666599931, 365590438845504, 1028470286882429, 2146499180330972]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
T: FieldElement64([1448326834587521, 1857896831960481, 1093722731865333, 1677408490711241, 1915505153018406]),
|
T: FieldElement64([1448326834587521, 1857896831960481, 1093722731865333, 1677408490711241, 1915505153018406]),
|
||||||
}
|
}
|
||||||
,
|
,
|
||||||
ExtendedPoint {
|
EdwardsPoint {
|
||||||
X: FieldElement64([533094393274173, 2016890930128738, 18285341111199, 134597186663265, 1486323764102114]),
|
X: FieldElement64([533094393274173, 2016890930128738, 18285341111199, 134597186663265, 1486323764102114]),
|
||||||
Y: FieldElement64([0, 0, 0, 0, 0]),
|
Y: FieldElement64([0, 0, 0, 0, 0]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
T: FieldElement64([0, 0, 0, 0, 0]),
|
T: FieldElement64([0, 0, 0, 0, 0]),
|
||||||
}
|
}
|
||||||
,
|
,
|
||||||
ExtendedPoint {
|
EdwardsPoint {
|
||||||
X: FieldElement64([358744748052810, 1691584618240980, 977650209285361, 1429865912637724, 560044844278676]),
|
X: FieldElement64([358744748052810, 1691584618240980, 977650209285361, 1429865912637724, 560044844278676]),
|
||||||
Y: FieldElement64([2166873539340326, 1778179147085316, 1886209374839743, 1223329526802818, 105300633354275]),
|
Y: FieldElement64([2166873539340326, 1778179147085316, 1886209374839743, 1223329526802818, 105300633354275]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
T: FieldElement64([803472979097708, 393902981724766, 1158077081819914, 574391322974006, 336294660666841]),
|
T: FieldElement64([803472979097708, 393902981724766, 1158077081819914, 574391322974006, 336294660666841]),
|
||||||
}
|
}
|
||||||
,
|
,
|
||||||
ExtendedPoint {
|
EdwardsPoint {
|
||||||
X: FieldElement64([0, 0, 0, 0, 0]),
|
X: FieldElement64([0, 0, 0, 0, 0]),
|
||||||
Y: FieldElement64([2251799813685228, 2251799813685247, 2251799813685247, 2251799813685247, 2251799813685247]),
|
Y: FieldElement64([2251799813685228, 2251799813685247, 2251799813685247, 2251799813685247, 2251799813685247]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
T: FieldElement64([0, 0, 0, 0, 0]),
|
T: FieldElement64([0, 0, 0, 0, 0]),
|
||||||
}
|
}
|
||||||
,
|
,
|
||||||
ExtendedPoint {
|
EdwardsPoint {
|
||||||
X: FieldElement64([1893055065632419, 560215195444267, 1274149604399886, 821933901047523, 1691754969406571]),
|
X: FieldElement64([1893055065632419, 560215195444267, 1274149604399886, 821933901047523, 1691754969406571]),
|
||||||
Y: FieldElement64([2166873539340326, 1778179147085316, 1886209374839743, 1223329526802818, 105300633354275]),
|
Y: FieldElement64([2166873539340326, 1778179147085316, 1886209374839743, 1223329526802818, 105300633354275]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
T: FieldElement64([1448326834587521, 1857896831960481, 1093722731865333, 1677408490711241, 1915505153018406]),
|
T: FieldElement64([1448326834587521, 1857896831960481, 1093722731865333, 1677408490711241, 1915505153018406]),
|
||||||
}
|
}
|
||||||
,
|
,
|
||||||
ExtendedPoint {
|
EdwardsPoint {
|
||||||
X: FieldElement64([1718705420411056, 234908883556509, 2233514472574048, 2117202627021982, 765476049583133]),
|
X: FieldElement64([1718705420411056, 234908883556509, 2233514472574048, 2117202627021982, 765476049583133]),
|
||||||
Y: FieldElement64([0, 0, 0, 0, 0]),
|
Y: FieldElement64([0, 0, 0, 0, 0]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
T: FieldElement64([0, 0, 0, 0, 0]),
|
T: FieldElement64([0, 0, 0, 0, 0]),
|
||||||
}
|
}
|
||||||
,
|
,
|
||||||
ExtendedPoint {
|
EdwardsPoint {
|
||||||
X: FieldElement64([1893055065632419, 560215195444267, 1274149604399886, 821933901047523, 1691754969406571]),
|
X: FieldElement64([1893055065632419, 560215195444267, 1274149604399886, 821933901047523, 1691754969406571]),
|
||||||
Y: FieldElement64([84926274344903, 473620666599931, 365590438845504, 1028470286882429, 2146499180330972]),
|
Y: FieldElement64([84926274344903, 473620666599931, 365590438845504, 1028470286882429, 2146499180330972]),
|
||||||
Z: FieldElement64([1, 0, 0, 0, 0]),
|
Z: FieldElement64([1, 0, 0, 0, 0]),
|
||||||
|
|
|
||||||
|
|
@ -56,7 +56,7 @@
|
||||||
//! introduced in [_Twisted Edwards Curves
|
//! introduced in [_Twisted Edwards Curves
|
||||||
//! Revisited_][hisil-wong-carter-dawson-2008] by Hisil, Wong, Carter,
|
//! Revisited_][hisil-wong-carter-dawson-2008] by Hisil, Wong, Carter,
|
||||||
//! and Dawson. In `curve25519-dalek`, it is represented as the
|
//! and Dawson. In `curve25519-dalek`, it is represented as the
|
||||||
//! `ExtendedPoint` struct. We can map from \\(\mathbb P\^3 \\) to
|
//! `EdwardsPoint` struct. We can map from \\(\mathbb P\^3 \\) to
|
||||||
//! \\(\mathbb P\^2 \\) by sending \\( (W\_0:W\_1:W\_2:W\_3) \\) to \\(
|
//! \\(\mathbb P\^2 \\) by sending \\( (W\_0:W\_1:W\_2:W\_3) \\) to \\(
|
||||||
//! (W\_1:W\_2:W\_3) \\). Notice that
|
//! (W\_1:W\_2:W\_3) \\). Notice that
|
||||||
//! $$
|
//! $$
|
||||||
|
|
@ -103,7 +103,7 @@
|
||||||
//!
|
//!
|
||||||
//! Our naming for the `CompletedPoint` (\\(\mathbb P\^1 \times \mathbb
|
//! Our naming for the `CompletedPoint` (\\(\mathbb P\^1 \times \mathbb
|
||||||
//! P\^1 \\)), `ProjectivePoint` (\\(\mathbb P\^2 \\)), and
|
//! P\^1 \\)), `ProjectivePoint` (\\(\mathbb P\^2 \\)), and
|
||||||
//! `ExtendedPoint` (\\(\mathbb P\^3 \\)) structs follows the naming in
|
//! `EdwardsPoint` (\\(\mathbb P\^3 \\)) structs follows the naming in
|
||||||
//! Adam Langley's [Golang ed25519][agl-ed25519] implementation, which
|
//! Adam Langley's [Golang ed25519][agl-ed25519] implementation, which
|
||||||
//! `curve25519-dalek` was originally derived from.
|
//! `curve25519-dalek` was originally derived from.
|
||||||
//!
|
//!
|
||||||
|
|
@ -130,7 +130,7 @@ use core::ops::{Add, Sub, Neg};
|
||||||
use constants;
|
use constants;
|
||||||
|
|
||||||
use field::FieldElement;
|
use field::FieldElement;
|
||||||
use edwards::ExtendedPoint;
|
use edwards::EdwardsPoint;
|
||||||
use subtle::ConditionallyAssignable;
|
use subtle::ConditionallyAssignable;
|
||||||
use traits::ValidityCheck;
|
use traits::ValidityCheck;
|
||||||
|
|
||||||
|
|
@ -302,8 +302,8 @@ impl ProjectivePoint {
|
||||||
/// \\( \mathbb P\^3 \\) model.
|
/// \\( \mathbb P\^3 \\) model.
|
||||||
///
|
///
|
||||||
/// This costs \\(3 \mathrm M + 1 \mathrm S\\).
|
/// This costs \\(3 \mathrm M + 1 \mathrm S\\).
|
||||||
pub fn to_extended(&self) -> ExtendedPoint {
|
pub fn to_extended(&self) -> EdwardsPoint {
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: &self.X * &self.Z,
|
X: &self.X * &self.Z,
|
||||||
Y: &self.Y * &self.Z,
|
Y: &self.Y * &self.Z,
|
||||||
Z: self.Z.square(),
|
Z: self.Z.square(),
|
||||||
|
|
@ -329,8 +329,8 @@ impl CompletedPoint {
|
||||||
/// \\) model to the \\( \mathbb P\^3 \\) model.
|
/// \\) model to the \\( \mathbb P\^3 \\) model.
|
||||||
///
|
///
|
||||||
/// This costs \\(4 \mathrm M \\).
|
/// This costs \\(4 \mathrm M \\).
|
||||||
pub fn to_extended(&self) -> ExtendedPoint {
|
pub fn to_extended(&self) -> EdwardsPoint {
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: &self.X * &self.T,
|
X: &self.X * &self.T,
|
||||||
Y: &self.Y * &self.Z,
|
Y: &self.Y * &self.Z,
|
||||||
Z: &self.Z * &self.T,
|
Z: &self.Z * &self.T,
|
||||||
|
|
@ -374,7 +374,7 @@ impl ProjectivePoint {
|
||||||
//
|
//
|
||||||
// upstream rust issue: https://github.com/rust-lang/rust/issues/46380
|
// upstream rust issue: https://github.com/rust-lang/rust/issues/46380
|
||||||
//#[doc(hidden)]
|
//#[doc(hidden)]
|
||||||
impl<'a, 'b> Add<&'b ProjectiveNielsPoint> for &'a ExtendedPoint {
|
impl<'a, 'b> Add<&'b ProjectiveNielsPoint> for &'a EdwardsPoint {
|
||||||
type Output = CompletedPoint;
|
type Output = CompletedPoint;
|
||||||
|
|
||||||
fn add(self, other: &'b ProjectiveNielsPoint) -> CompletedPoint {
|
fn add(self, other: &'b ProjectiveNielsPoint) -> CompletedPoint {
|
||||||
|
|
@ -396,7 +396,7 @@ impl<'a, 'b> Add<&'b ProjectiveNielsPoint> for &'a ExtendedPoint {
|
||||||
}
|
}
|
||||||
|
|
||||||
//#[doc(hidden)]
|
//#[doc(hidden)]
|
||||||
impl<'a, 'b> Sub<&'b ProjectiveNielsPoint> for &'a ExtendedPoint {
|
impl<'a, 'b> Sub<&'b ProjectiveNielsPoint> for &'a EdwardsPoint {
|
||||||
type Output = CompletedPoint;
|
type Output = CompletedPoint;
|
||||||
|
|
||||||
fn sub(self, other: &'b ProjectiveNielsPoint) -> CompletedPoint {
|
fn sub(self, other: &'b ProjectiveNielsPoint) -> CompletedPoint {
|
||||||
|
|
@ -418,7 +418,7 @@ impl<'a, 'b> Sub<&'b ProjectiveNielsPoint> for &'a ExtendedPoint {
|
||||||
}
|
}
|
||||||
|
|
||||||
//#[doc(hidden)]
|
//#[doc(hidden)]
|
||||||
impl<'a, 'b> Add<&'b AffineNielsPoint> for &'a ExtendedPoint {
|
impl<'a, 'b> Add<&'b AffineNielsPoint> for &'a EdwardsPoint {
|
||||||
type Output = CompletedPoint;
|
type Output = CompletedPoint;
|
||||||
|
|
||||||
fn add(self, other: &'b AffineNielsPoint) -> CompletedPoint {
|
fn add(self, other: &'b AffineNielsPoint) -> CompletedPoint {
|
||||||
|
|
@ -439,7 +439,7 @@ impl<'a, 'b> Add<&'b AffineNielsPoint> for &'a ExtendedPoint {
|
||||||
}
|
}
|
||||||
|
|
||||||
//#[doc(hidden)]
|
//#[doc(hidden)]
|
||||||
impl<'a, 'b> Sub<&'b AffineNielsPoint> for &'a ExtendedPoint {
|
impl<'a, 'b> Sub<&'b AffineNielsPoint> for &'a EdwardsPoint {
|
||||||
type Output = CompletedPoint;
|
type Output = CompletedPoint;
|
||||||
|
|
||||||
fn sub(self, other: &'b AffineNielsPoint) -> CompletedPoint {
|
fn sub(self, other: &'b AffineNielsPoint) -> CompletedPoint {
|
||||||
|
|
|
||||||
|
|
@ -92,12 +92,12 @@ impl<T: Debug> Debug for LookupTable<T> {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
use edwards::ExtendedPoint;
|
use edwards::EdwardsPoint;
|
||||||
use curve_models::ProjectiveNielsPoint;
|
use curve_models::ProjectiveNielsPoint;
|
||||||
use curve_models::AffineNielsPoint;
|
use curve_models::AffineNielsPoint;
|
||||||
|
|
||||||
impl<'a> From<&'a ExtendedPoint> for LookupTable<ProjectiveNielsPoint> {
|
impl<'a> From<&'a EdwardsPoint> for LookupTable<ProjectiveNielsPoint> {
|
||||||
fn from(P: &'a ExtendedPoint) -> Self {
|
fn from(P: &'a EdwardsPoint) -> Self {
|
||||||
let mut points = [P.to_projective_niels(); 8];
|
let mut points = [P.to_projective_niels(); 8];
|
||||||
for j in 0..7 {
|
for j in 0..7 {
|
||||||
points[j+1] = (P + &points[j])
|
points[j+1] = (P + &points[j])
|
||||||
|
|
@ -108,8 +108,8 @@ impl<'a> From<&'a ExtendedPoint> for LookupTable<ProjectiveNielsPoint> {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<'a> From<&'a ExtendedPoint> for LookupTable<AffineNielsPoint> {
|
impl<'a> From<&'a EdwardsPoint> for LookupTable<AffineNielsPoint> {
|
||||||
fn from(P: &'a ExtendedPoint) -> Self {
|
fn from(P: &'a EdwardsPoint) -> Self {
|
||||||
let mut points = [P.to_affine_niels(); 8];
|
let mut points = [P.to_affine_niels(); 8];
|
||||||
// XXX batch inversion would be good if perf mattered here
|
// XXX batch inversion would be good if perf mattered here
|
||||||
for j in 0..7 {
|
for j in 0..7 {
|
||||||
|
|
|
||||||
214
src/edwards.rs
214
src/edwards.rs
|
|
@ -77,11 +77,11 @@ impl CompressedEdwardsY {
|
||||||
self.0
|
self.0
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Attempt to decompress to an `ExtendedPoint`.
|
/// Attempt to decompress to an `EdwardsPoint`.
|
||||||
///
|
///
|
||||||
/// Returns `None` if the input is not the \\(y\\)-coordinate of a
|
/// Returns `None` if the input is not the \\(y\\)-coordinate of a
|
||||||
/// curve point.
|
/// curve point.
|
||||||
pub fn decompress(&self) -> Option<ExtendedPoint> {
|
pub fn decompress(&self) -> Option<EdwardsPoint> {
|
||||||
let Y = FieldElement::from_bytes(self.as_bytes());
|
let Y = FieldElement::from_bytes(self.as_bytes());
|
||||||
let Z = FieldElement::one();
|
let Z = FieldElement::one();
|
||||||
let YY = Y.square();
|
let YY = Y.square();
|
||||||
|
|
@ -96,16 +96,16 @@ impl CompressedEdwardsY {
|
||||||
let current_sign_bit = X.is_negative();
|
let current_sign_bit = X.is_negative();
|
||||||
X.conditional_negate(current_sign_bit ^ compressed_sign_bit);
|
X.conditional_negate(current_sign_bit ^ compressed_sign_bit);
|
||||||
|
|
||||||
Some(ExtendedPoint{ X: X, Y: Y, Z: Z, T: &X * &Y })
|
Some(EdwardsPoint{ X: X, Y: Y, Z: Z, T: &X * &Y })
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
// Serde support
|
// Serde support
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
// Serializes to and from `ExtendedPoint` directly, doing compression
|
// Serializes to and from `EdwardsPoint` directly, doing compression
|
||||||
// and decompression internally. This means that users can create
|
// and decompression internally. This means that users can create
|
||||||
// structs containing `ExtendedPoint`s and use Serde's derived
|
// structs containing `EdwardsPoint`s and use Serde's derived
|
||||||
// serializers to serialize those structures.
|
// serializers to serialize those structures.
|
||||||
|
|
||||||
#[cfg(feature = "serde")]
|
#[cfg(feature = "serde")]
|
||||||
|
|
@ -114,7 +114,7 @@ use serde::{self, Serialize, Deserialize, Serializer, Deserializer};
|
||||||
use serde::de::Visitor;
|
use serde::de::Visitor;
|
||||||
|
|
||||||
#[cfg(feature = "serde")]
|
#[cfg(feature = "serde")]
|
||||||
impl Serialize for ExtendedPoint {
|
impl Serialize for EdwardsPoint {
|
||||||
fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>
|
fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>
|
||||||
where S: Serializer
|
where S: Serializer
|
||||||
{
|
{
|
||||||
|
|
@ -123,20 +123,20 @@ impl Serialize for ExtendedPoint {
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(feature = "serde")]
|
#[cfg(feature = "serde")]
|
||||||
impl<'de> Deserialize<'de> for ExtendedPoint {
|
impl<'de> Deserialize<'de> for EdwardsPoint {
|
||||||
fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
|
fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
|
||||||
where D: Deserializer<'de>
|
where D: Deserializer<'de>
|
||||||
{
|
{
|
||||||
struct ExtendedPointVisitor;
|
struct EdwardsPointVisitor;
|
||||||
|
|
||||||
impl<'de> Visitor<'de> for ExtendedPointVisitor {
|
impl<'de> Visitor<'de> for EdwardsPointVisitor {
|
||||||
type Value = ExtendedPoint;
|
type Value = EdwardsPoint;
|
||||||
|
|
||||||
fn expecting(&self, formatter: &mut ::core::fmt::Formatter) -> ::core::fmt::Result {
|
fn expecting(&self, formatter: &mut ::core::fmt::Formatter) -> ::core::fmt::Result {
|
||||||
formatter.write_str("a valid point in Edwards y + sign format")
|
formatter.write_str("a valid point in Edwards y + sign format")
|
||||||
}
|
}
|
||||||
|
|
||||||
fn visit_bytes<E>(self, v: &[u8]) -> Result<ExtendedPoint, E>
|
fn visit_bytes<E>(self, v: &[u8]) -> Result<EdwardsPoint, E>
|
||||||
where E: serde::de::Error
|
where E: serde::de::Error
|
||||||
{
|
{
|
||||||
if v.len() == 32 {
|
if v.len() == 32 {
|
||||||
|
|
@ -151,7 +151,7 @@ impl<'de> Deserialize<'de> for ExtendedPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
deserializer.deserialize_bytes(ExtendedPointVisitor)
|
deserializer.deserialize_bytes(EdwardsPointVisitor)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -159,14 +159,10 @@ impl<'de> Deserialize<'de> for ExtendedPoint {
|
||||||
// Internal point representations
|
// Internal point representations
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
/// An `ExtendedPoint` represents a point on the Edwards form of Curve25519.
|
/// An `EdwardsPoint` represents a point on the Edwards form of Curve25519.
|
||||||
///
|
|
||||||
/// The name refers to the extended twisted Edwards coordinates of
|
|
||||||
/// Hisil, Wong, Carter, and Dawson, and more details on curve models
|
|
||||||
/// can be found in the `curve25519-dalek` internal documentation.
|
|
||||||
#[derive(Copy, Clone)]
|
#[derive(Copy, Clone)]
|
||||||
#[allow(missing_docs)]
|
#[allow(missing_docs)]
|
||||||
pub struct ExtendedPoint {
|
pub struct EdwardsPoint {
|
||||||
pub(crate) X: FieldElement,
|
pub(crate) X: FieldElement,
|
||||||
pub(crate) Y: FieldElement,
|
pub(crate) Y: FieldElement,
|
||||||
pub(crate) Z: FieldElement,
|
pub(crate) Z: FieldElement,
|
||||||
|
|
@ -186,9 +182,9 @@ impl Identity for CompressedEdwardsY {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Identity for ExtendedPoint {
|
impl Identity for EdwardsPoint {
|
||||||
fn identity() -> ExtendedPoint {
|
fn identity() -> EdwardsPoint {
|
||||||
ExtendedPoint{ X: FieldElement::zero(),
|
EdwardsPoint{ X: FieldElement::zero(),
|
||||||
Y: FieldElement::one(),
|
Y: FieldElement::one(),
|
||||||
Z: FieldElement::one(),
|
Z: FieldElement::one(),
|
||||||
T: FieldElement::zero() }
|
T: FieldElement::zero() }
|
||||||
|
|
@ -199,7 +195,7 @@ impl Identity for ExtendedPoint {
|
||||||
// Validity checks (for debugging, not CT)
|
// Validity checks (for debugging, not CT)
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl ValidityCheck for ExtendedPoint {
|
impl ValidityCheck for EdwardsPoint {
|
||||||
// XXX this should also check that T is correct
|
// XXX this should also check that T is correct
|
||||||
fn is_valid(&self) -> bool {
|
fn is_valid(&self) -> bool {
|
||||||
self.to_projective().is_valid()
|
self.to_projective().is_valid()
|
||||||
|
|
@ -210,8 +206,8 @@ impl ValidityCheck for ExtendedPoint {
|
||||||
// Constant-time assignment
|
// Constant-time assignment
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl ConditionallyAssignable for ExtendedPoint {
|
impl ConditionallyAssignable for EdwardsPoint {
|
||||||
fn conditional_assign(&mut self, other: &ExtendedPoint, choice: u8) {
|
fn conditional_assign(&mut self, other: &EdwardsPoint, choice: u8) {
|
||||||
self.X.conditional_assign(&other.X, choice);
|
self.X.conditional_assign(&other.X, choice);
|
||||||
self.Y.conditional_assign(&other.Y, choice);
|
self.Y.conditional_assign(&other.Y, choice);
|
||||||
self.Z.conditional_assign(&other.Z, choice);
|
self.Z.conditional_assign(&other.Z, choice);
|
||||||
|
|
@ -223,8 +219,8 @@ impl ConditionallyAssignable for ExtendedPoint {
|
||||||
// Constant-time Equality
|
// Constant-time Equality
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl Equal for ExtendedPoint {
|
impl Equal for EdwardsPoint {
|
||||||
fn ct_eq(&self, other: &ExtendedPoint) -> u8 {
|
fn ct_eq(&self, other: &EdwardsPoint) -> u8 {
|
||||||
slices_equal(self.compress().as_bytes(),
|
slices_equal(self.compress().as_bytes(),
|
||||||
other.compress().as_bytes())
|
other.compress().as_bytes())
|
||||||
}
|
}
|
||||||
|
|
@ -234,7 +230,7 @@ impl Equal for ExtendedPoint {
|
||||||
// Point conversions
|
// Point conversions
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl ExtendedPoint {
|
impl EdwardsPoint {
|
||||||
/// Convert to a ProjectiveNielsPoint
|
/// Convert to a ProjectiveNielsPoint
|
||||||
pub(crate) fn to_projective_niels(&self) -> ProjectiveNielsPoint {
|
pub(crate) fn to_projective_niels(&self) -> ProjectiveNielsPoint {
|
||||||
ProjectiveNielsPoint{
|
ProjectiveNielsPoint{
|
||||||
|
|
@ -271,7 +267,7 @@ impl ExtendedPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Convert this `ExtendedPoint` on the Edwards model to the
|
/// Convert this `EdwardsPoint` on the Edwards model to the
|
||||||
/// corresponding `MontgomeryPoint` on the Montgomery model.
|
/// corresponding `MontgomeryPoint` on the Montgomery model.
|
||||||
///
|
///
|
||||||
/// Note that this is a one-way conversion, since the Montgomery
|
/// Note that this is a one-way conversion, since the Montgomery
|
||||||
|
|
@ -360,9 +356,9 @@ impl ExtendedPoint {
|
||||||
// Doubling
|
// Doubling
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl ExtendedPoint {
|
impl EdwardsPoint {
|
||||||
/// Add this point to itself.
|
/// Add this point to itself.
|
||||||
pub(crate) fn double(&self) -> ExtendedPoint {
|
pub(crate) fn double(&self) -> EdwardsPoint {
|
||||||
self.to_projective().double().to_extended()
|
self.to_projective().double().to_extended()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -371,49 +367,49 @@ impl ExtendedPoint {
|
||||||
// Addition and Subtraction
|
// Addition and Subtraction
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl<'a, 'b> Add<&'b ExtendedPoint> for &'a ExtendedPoint {
|
impl<'a, 'b> Add<&'b EdwardsPoint> for &'a EdwardsPoint {
|
||||||
type Output = ExtendedPoint;
|
type Output = EdwardsPoint;
|
||||||
fn add(self, other: &'b ExtendedPoint) -> ExtendedPoint {
|
fn add(self, other: &'b EdwardsPoint) -> EdwardsPoint {
|
||||||
(self + &other.to_projective_niels()).to_extended()
|
(self + &other.to_projective_niels()).to_extended()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
define_add_variants!(LHS = ExtendedPoint, RHS = ExtendedPoint, Output = ExtendedPoint);
|
define_add_variants!(LHS = EdwardsPoint, RHS = EdwardsPoint, Output = EdwardsPoint);
|
||||||
|
|
||||||
impl<'b> AddAssign<&'b ExtendedPoint> for ExtendedPoint {
|
impl<'b> AddAssign<&'b EdwardsPoint> for EdwardsPoint {
|
||||||
fn add_assign(&mut self, _rhs: &'b ExtendedPoint) {
|
fn add_assign(&mut self, _rhs: &'b EdwardsPoint) {
|
||||||
*self = (self as &ExtendedPoint) + _rhs;
|
*self = (self as &EdwardsPoint) + _rhs;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
define_add_assign_variants!(LHS = ExtendedPoint, RHS = ExtendedPoint);
|
define_add_assign_variants!(LHS = EdwardsPoint, RHS = EdwardsPoint);
|
||||||
|
|
||||||
impl<'a, 'b> Sub<&'b ExtendedPoint> for &'a ExtendedPoint {
|
impl<'a, 'b> Sub<&'b EdwardsPoint> for &'a EdwardsPoint {
|
||||||
type Output = ExtendedPoint;
|
type Output = EdwardsPoint;
|
||||||
fn sub(self, other: &'b ExtendedPoint) -> ExtendedPoint {
|
fn sub(self, other: &'b EdwardsPoint) -> EdwardsPoint {
|
||||||
(self - &other.to_projective_niels()).to_extended()
|
(self - &other.to_projective_niels()).to_extended()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
define_sub_variants!(LHS = ExtendedPoint, RHS = ExtendedPoint, Output = ExtendedPoint);
|
define_sub_variants!(LHS = EdwardsPoint, RHS = EdwardsPoint, Output = EdwardsPoint);
|
||||||
|
|
||||||
impl<'b> SubAssign<&'b ExtendedPoint> for ExtendedPoint {
|
impl<'b> SubAssign<&'b EdwardsPoint> for EdwardsPoint {
|
||||||
fn sub_assign(&mut self, _rhs: &'b ExtendedPoint) {
|
fn sub_assign(&mut self, _rhs: &'b EdwardsPoint) {
|
||||||
*self = (self as &ExtendedPoint) - _rhs;
|
*self = (self as &EdwardsPoint) - _rhs;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
define_sub_assign_variants!(LHS = ExtendedPoint, RHS = ExtendedPoint);
|
define_sub_assign_variants!(LHS = EdwardsPoint, RHS = EdwardsPoint);
|
||||||
|
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
// Negation
|
// Negation
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl<'a> Neg for &'a ExtendedPoint {
|
impl<'a> Neg for &'a EdwardsPoint {
|
||||||
type Output = ExtendedPoint;
|
type Output = EdwardsPoint;
|
||||||
|
|
||||||
fn neg(self) -> ExtendedPoint {
|
fn neg(self) -> EdwardsPoint {
|
||||||
ExtendedPoint{
|
EdwardsPoint{
|
||||||
X: -(&self.X),
|
X: -(&self.X),
|
||||||
Y: self.Y,
|
Y: self.Y,
|
||||||
Z: self.Z,
|
Z: self.Z,
|
||||||
|
|
@ -422,10 +418,10 @@ impl<'a> Neg for &'a ExtendedPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Neg for ExtendedPoint {
|
impl Neg for EdwardsPoint {
|
||||||
type Output = ExtendedPoint;
|
type Output = EdwardsPoint;
|
||||||
|
|
||||||
fn neg(self) -> ExtendedPoint {
|
fn neg(self) -> EdwardsPoint {
|
||||||
-&self
|
-&self
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -434,30 +430,30 @@ impl Neg for ExtendedPoint {
|
||||||
// Scalar multiplication
|
// Scalar multiplication
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl<'b> MulAssign<&'b Scalar> for ExtendedPoint {
|
impl<'b> MulAssign<&'b Scalar> for EdwardsPoint {
|
||||||
fn mul_assign(&mut self, scalar: &'b Scalar) {
|
fn mul_assign(&mut self, scalar: &'b Scalar) {
|
||||||
let result = (self as &ExtendedPoint) * scalar;
|
let result = (self as &EdwardsPoint) * scalar;
|
||||||
*self = result;
|
*self = result;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
define_mul_assign_variants!(LHS = ExtendedPoint, RHS = Scalar);
|
define_mul_assign_variants!(LHS = EdwardsPoint, RHS = Scalar);
|
||||||
|
|
||||||
define_mul_variants!(LHS = ExtendedPoint, RHS = Scalar, Output = ExtendedPoint);
|
define_mul_variants!(LHS = EdwardsPoint, RHS = Scalar, Output = EdwardsPoint);
|
||||||
define_mul_variants!(LHS = Scalar, RHS = ExtendedPoint, Output = ExtendedPoint);
|
define_mul_variants!(LHS = Scalar, RHS = EdwardsPoint, Output = EdwardsPoint);
|
||||||
|
|
||||||
impl<'a, 'b> Mul<&'b Scalar> for &'a ExtendedPoint {
|
impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsPoint {
|
||||||
type Output = ExtendedPoint;
|
type Output = EdwardsPoint;
|
||||||
/// Scalar multiplication: compute `scalar * self`.
|
/// Scalar multiplication: compute `scalar * self`.
|
||||||
///
|
///
|
||||||
/// For scalar multiplication of a basepoint,
|
/// For scalar multiplication of a basepoint,
|
||||||
/// `EdwardsBasepointTable` is approximately 4x faster.
|
/// `EdwardsBasepointTable` is approximately 4x faster.
|
||||||
fn mul(self, scalar: &'b Scalar) -> ExtendedPoint {
|
fn mul(self, scalar: &'b Scalar) -> EdwardsPoint {
|
||||||
// If we built with AVX2, use the AVX2 backend.
|
// If we built with AVX2, use the AVX2 backend.
|
||||||
#[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] {
|
#[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] {
|
||||||
use backend::avx2::edwards as edwards_avx2;
|
use backend::avx2::edwards::ExtendedPoint;
|
||||||
let P_avx2 = edwards_avx2::ExtendedPoint::from(*self);
|
let P_avx2 = ExtendedPoint::from(*self);
|
||||||
return ExtendedPoint::from(&P_avx2 * scalar);
|
return EdwardsPoint::from(&P_avx2 * scalar);
|
||||||
}
|
}
|
||||||
// Otherwise, proceed as normal:
|
// Otherwise, proceed as normal:
|
||||||
#[cfg(not(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2"))))] {
|
#[cfg(not(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2"))))] {
|
||||||
|
|
@ -478,7 +474,7 @@ impl<'a, 'b> Mul<&'b Scalar> for &'a ExtendedPoint {
|
||||||
// s*P = P*s_0 + 16*(P*s_1 + 16*(P*s_2 + 16*( ... + P*s_63)...))
|
// s*P = P*s_0 + 16*(P*s_1 + 16*(P*s_2 + 16*( ... + P*s_63)...))
|
||||||
//
|
//
|
||||||
// We sum right-to-left.
|
// We sum right-to-left.
|
||||||
let mut Q = ExtendedPoint::identity();
|
let mut Q = EdwardsPoint::identity();
|
||||||
for i in (0..64).rev() {
|
for i in (0..64).rev() {
|
||||||
// Q <-- 16*Q
|
// Q <-- 16*Q
|
||||||
Q = Q.mult_by_pow_2(4);
|
Q = Q.mult_by_pow_2(4);
|
||||||
|
|
@ -491,14 +487,14 @@ impl<'a, 'b> Mul<&'b Scalar> for &'a ExtendedPoint {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<'a, 'b> Mul<&'b ExtendedPoint> for &'a Scalar {
|
impl<'a, 'b> Mul<&'b EdwardsPoint> for &'a Scalar {
|
||||||
type Output = ExtendedPoint;
|
type Output = EdwardsPoint;
|
||||||
|
|
||||||
/// Scalar multiplication: compute `scalar * self`.
|
/// Scalar multiplication: compute `scalar * self`.
|
||||||
///
|
///
|
||||||
/// For scalar multiplication of a basepoint,
|
/// For scalar multiplication of a basepoint,
|
||||||
/// `EdwardsBasepointTable` is approximately 4x faster.
|
/// `EdwardsBasepointTable` is approximately 4x faster.
|
||||||
fn mul(self, point: &'b ExtendedPoint) -> ExtendedPoint {
|
fn mul(self, point: &'b EdwardsPoint) -> EdwardsPoint {
|
||||||
point * self
|
point * self
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -514,15 +510,15 @@ impl<'a, 'b> Mul<&'b ExtendedPoint> for &'a Scalar {
|
||||||
///
|
///
|
||||||
/// # Input
|
/// # Input
|
||||||
///
|
///
|
||||||
/// A iterable of `Scalar`s and a iterable of `ExtendedPoints`. It is an
|
/// A iterable of `Scalar`s and a iterable of `EdwardsPoints`. It is an
|
||||||
/// error to call this function with two iterators of different lengths.
|
/// error to call this function with two iterators of different lengths.
|
||||||
///
|
///
|
||||||
// XXX later when we do more fancy multiscalar mults, we can delegate
|
// XXX later when we do more fancy multiscalar mults, we can delegate
|
||||||
// based on the iter's size hint -- hdevalence
|
// based on the iter's size hint -- hdevalence
|
||||||
#[cfg(any(feature = "alloc", feature = "std"))]
|
#[cfg(any(feature = "alloc", feature = "std"))]
|
||||||
pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> ExtendedPoint
|
pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> EdwardsPoint
|
||||||
where I: IntoIterator<Item = &'a Scalar>,
|
where I: IntoIterator<Item = &'a Scalar>,
|
||||||
J: IntoIterator<Item = &'b ExtendedPoint>
|
J: IntoIterator<Item = &'b EdwardsPoint>
|
||||||
{
|
{
|
||||||
// If we built with AVX2, use the AVX2 backend.
|
// If we built with AVX2, use the AVX2 backend.
|
||||||
#[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] {
|
#[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] {
|
||||||
|
|
@ -575,7 +571,7 @@ pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> ExtendedPoint
|
||||||
// This provides the speedup over doing n independent scalar
|
// This provides the speedup over doing n independent scalar
|
||||||
// mults: we perform 63 multiplications by 16 instead of 63*n
|
// mults: we perform 63 multiplications by 16 instead of 63*n
|
||||||
// multiplications, saving 252*(n-1) doublings.
|
// multiplications, saving 252*(n-1) doublings.
|
||||||
let mut Q = ExtendedPoint::identity();
|
let mut Q = EdwardsPoint::identity();
|
||||||
// XXX this impl makes no effort to be cache-aware; maybe it could be improved?
|
// XXX this impl makes no effort to be cache-aware; maybe it could be improved?
|
||||||
for j in (0..64).rev() {
|
for j in (0..64).rev() {
|
||||||
Q = Q.mult_by_pow_2(4);
|
Q = Q.mult_by_pow_2(4);
|
||||||
|
|
@ -628,11 +624,11 @@ impl EdwardsBasepointTable {
|
||||||
///
|
///
|
||||||
/// The radix-\\(16\\) representation requires that the scalar is bounded
|
/// The radix-\\(16\\) representation requires that the scalar is bounded
|
||||||
/// by \\(2\^{255}\\), which is always the case.
|
/// by \\(2\^{255}\\), which is always the case.
|
||||||
fn basepoint_mul(&self, scalar: &Scalar) -> ExtendedPoint {
|
fn basepoint_mul(&self, scalar: &Scalar) -> EdwardsPoint {
|
||||||
let a = scalar.to_radix_16();
|
let a = scalar.to_radix_16();
|
||||||
|
|
||||||
let tables = &self.0;
|
let tables = &self.0;
|
||||||
let mut P = ExtendedPoint::identity();
|
let mut P = EdwardsPoint::identity();
|
||||||
|
|
||||||
for i in (0..64).filter(|x| x % 2 == 1) {
|
for i in (0..64).filter(|x| x % 2 == 1) {
|
||||||
P = (&P + &tables[i/2].select(a[i])).to_extended();
|
P = (&P + &tables[i/2].select(a[i])).to_extended();
|
||||||
|
|
@ -649,29 +645,29 @@ impl EdwardsBasepointTable {
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsBasepointTable {
|
impl<'a, 'b> Mul<&'b Scalar> for &'a EdwardsBasepointTable {
|
||||||
type Output = ExtendedPoint;
|
type Output = EdwardsPoint;
|
||||||
|
|
||||||
/// Construct an `ExtendedPoint` from a `Scalar` \\(a\\) by
|
/// Construct an `EdwardsPoint` from a `Scalar` \\(a\\) by
|
||||||
/// computing the multiple \\(aB\\) of this basepoint \\(B\\).
|
/// computing the multiple \\(aB\\) of this basepoint \\(B\\).
|
||||||
fn mul(self, scalar: &'b Scalar) -> ExtendedPoint {
|
fn mul(self, scalar: &'b Scalar) -> EdwardsPoint {
|
||||||
// delegate to a private function so that its documentation appears in internal docs
|
// delegate to a private function so that its documentation appears in internal docs
|
||||||
self.basepoint_mul(scalar)
|
self.basepoint_mul(scalar)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<'a, 'b> Mul<&'a EdwardsBasepointTable> for &'b Scalar {
|
impl<'a, 'b> Mul<&'a EdwardsBasepointTable> for &'b Scalar {
|
||||||
type Output = ExtendedPoint;
|
type Output = EdwardsPoint;
|
||||||
|
|
||||||
/// Construct an `ExtendedPoint` from a `Scalar` \\(a\\) by
|
/// Construct an `EdwardsPoint` from a `Scalar` \\(a\\) by
|
||||||
/// computing the multiple \\(aB\\) of this basepoint \\(B\\).
|
/// computing the multiple \\(aB\\) of this basepoint \\(B\\).
|
||||||
fn mul(self, basepoint_table: &'a EdwardsBasepointTable) -> ExtendedPoint {
|
fn mul(self, basepoint_table: &'a EdwardsBasepointTable) -> EdwardsPoint {
|
||||||
basepoint_table * &self
|
basepoint_table * &self
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl EdwardsBasepointTable {
|
impl EdwardsBasepointTable {
|
||||||
/// Create a table of precomputed multiples of `basepoint`.
|
/// Create a table of precomputed multiples of `basepoint`.
|
||||||
pub fn create(basepoint: &ExtendedPoint) -> EdwardsBasepointTable {
|
pub fn create(basepoint: &EdwardsPoint) -> EdwardsBasepointTable {
|
||||||
// XXX use init_with
|
// XXX use init_with
|
||||||
let mut table = EdwardsBasepointTable([LookupTable::default(); 32]);
|
let mut table = EdwardsBasepointTable([LookupTable::default(); 32]);
|
||||||
let mut P = *basepoint;
|
let mut P = *basepoint;
|
||||||
|
|
@ -683,25 +679,25 @@ impl EdwardsBasepointTable {
|
||||||
table
|
table
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Get the basepoint for this table as an `ExtendedPoint`.
|
/// Get the basepoint for this table as an `EdwardsPoint`.
|
||||||
///
|
///
|
||||||
/// XXX maybe this would be better as a `From` impl
|
/// XXX maybe this would be better as a `From` impl
|
||||||
pub fn basepoint(&self) -> ExtendedPoint {
|
pub fn basepoint(&self) -> EdwardsPoint {
|
||||||
// self.0[0].select(1) = 1*(16^2)^0*B
|
// self.0[0].select(1) = 1*(16^2)^0*B
|
||||||
// but as an `AffineNielsPoint`, so add identity to convert to extended.
|
// but as an `AffineNielsPoint`, so add identity to convert to extended.
|
||||||
(&ExtendedPoint::identity() + &self.0[0].select(1)).to_extended()
|
(&EdwardsPoint::identity() + &self.0[0].select(1)).to_extended()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl ExtendedPoint {
|
impl EdwardsPoint {
|
||||||
/// Multiply by the cofactor: compute `8 * self`.
|
/// Multiply by the cofactor: compute `8 * self`.
|
||||||
pub fn mult_by_cofactor(&self) -> ExtendedPoint {
|
pub fn mult_by_cofactor(&self) -> EdwardsPoint {
|
||||||
self.mult_by_pow_2(3)
|
self.mult_by_pow_2(3)
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Compute `2^k * self` by successive doublings.
|
/// Compute `2^k * self` by successive doublings.
|
||||||
/// Requires `k > 0`.
|
/// Requires `k > 0`.
|
||||||
pub(crate) fn mult_by_pow_2(&self, k: u32) -> ExtendedPoint {
|
pub(crate) fn mult_by_pow_2(&self, k: u32) -> EdwardsPoint {
|
||||||
let mut r: CompletedPoint;
|
let mut r: CompletedPoint;
|
||||||
let mut s = self.to_projective();
|
let mut s = self.to_projective();
|
||||||
for _ in 0..(k-1) {
|
for _ in 0..(k-1) {
|
||||||
|
|
@ -738,7 +734,7 @@ impl ExtendedPoint {
|
||||||
|
|
||||||
// XXX should this be in another module, with types and `From` impls, like `CompressedEdwardsY`?
|
// XXX should this be in another module, with types and `From` impls, like `CompressedEdwardsY`?
|
||||||
|
|
||||||
impl ExtendedPoint {
|
impl EdwardsPoint {
|
||||||
/// Use Elligator2 to try to convert `self` to a uniformly random
|
/// Use Elligator2 to try to convert `self` to a uniformly random
|
||||||
/// string.
|
/// string.
|
||||||
///
|
///
|
||||||
|
|
@ -752,7 +748,7 @@ impl ExtendedPoint {
|
||||||
/// Use Elligator2 to convert a uniformly random string to a curve
|
/// Use Elligator2 to convert a uniformly random string to a curve
|
||||||
/// point.
|
/// point.
|
||||||
#[allow(unused_variables)] // REMOVE WHEN IMPLEMENTED
|
#[allow(unused_variables)] // REMOVE WHEN IMPLEMENTED
|
||||||
fn from_uniform_representative(bytes: &[u8; 32]) -> ExtendedPoint {
|
fn from_uniform_representative(bytes: &[u8; 32]) -> EdwardsPoint {
|
||||||
unimplemented!();
|
unimplemented!();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -761,9 +757,9 @@ impl ExtendedPoint {
|
||||||
// Debug traits
|
// Debug traits
|
||||||
// ------------------------------------------------------------------------
|
// ------------------------------------------------------------------------
|
||||||
|
|
||||||
impl Debug for ExtendedPoint {
|
impl Debug for EdwardsPoint {
|
||||||
fn fmt(&self, f: &mut ::core::fmt::Formatter) -> ::core::fmt::Result {
|
fn fmt(&self, f: &mut ::core::fmt::Formatter) -> ::core::fmt::Result {
|
||||||
write!(f, "ExtendedPoint{{\n\tX: {:?},\n\tY: {:?},\n\tZ: {:?},\n\tT: {:?}\n}}",
|
write!(f, "EdwardsPoint{{\n\tX: {:?},\n\tY: {:?},\n\tZ: {:?},\n\tT: {:?}\n}}",
|
||||||
&self.X, &self.Y, &self.Z, &self.T)
|
&self.X, &self.Y, &self.Z, &self.T)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -790,7 +786,7 @@ pub mod vartime {
|
||||||
struct OddMultiples([ProjectiveNielsPoint; 8]);
|
struct OddMultiples([ProjectiveNielsPoint; 8]);
|
||||||
|
|
||||||
impl OddMultiples {
|
impl OddMultiples {
|
||||||
fn create(A: &ExtendedPoint) -> OddMultiples {
|
fn create(A: &EdwardsPoint) -> OddMultiples {
|
||||||
let mut Ai = [ProjectiveNielsPoint::identity(); 8];
|
let mut Ai = [ProjectiveNielsPoint::identity(); 8];
|
||||||
let A2 = A.double();
|
let A2 = A.double();
|
||||||
Ai[0] = A.to_projective_niels();
|
Ai[0] = A.to_projective_niels();
|
||||||
|
|
@ -818,12 +814,12 @@ pub mod vartime {
|
||||||
///
|
///
|
||||||
/// # Input
|
/// # Input
|
||||||
///
|
///
|
||||||
/// A iterable of `Scalar`s and a iterable of `ExtendedPoints`. It is an
|
/// A iterable of `Scalar`s and a iterable of `EdwardsPoints`. It is an
|
||||||
/// error to call this function with two iterators of different lengths.
|
/// error to call this function with two iterators of different lengths.
|
||||||
#[cfg(any(feature = "alloc", feature = "std"))]
|
#[cfg(any(feature = "alloc", feature = "std"))]
|
||||||
pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> ExtendedPoint
|
pub fn multiscalar_mult<'a, 'b, I, J>(scalars: I, points: J) -> EdwardsPoint
|
||||||
where I: IntoIterator<Item = &'a Scalar>,
|
where I: IntoIterator<Item = &'a Scalar>,
|
||||||
J: IntoIterator<Item = &'b ExtendedPoint>
|
J: IntoIterator<Item = &'b EdwardsPoint>
|
||||||
{
|
{
|
||||||
// If we built with AVX2, use the AVX2 backend.
|
// If we built with AVX2, use the AVX2 backend.
|
||||||
#[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] {
|
#[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] {
|
||||||
|
|
@ -866,9 +862,9 @@ pub mod vartime {
|
||||||
#[cfg(feature="precomputed_tables")]
|
#[cfg(feature="precomputed_tables")]
|
||||||
pub fn double_scalar_mult_basepoint(
|
pub fn double_scalar_mult_basepoint(
|
||||||
a: &Scalar,
|
a: &Scalar,
|
||||||
A: &ExtendedPoint,
|
A: &EdwardsPoint,
|
||||||
b: &Scalar,
|
b: &Scalar,
|
||||||
) -> ExtendedPoint {
|
) -> EdwardsPoint {
|
||||||
// If we built with AVX2, use the AVX2 backend.
|
// If we built with AVX2, use the AVX2 backend.
|
||||||
#[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] {
|
#[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] {
|
||||||
use backend::avx2::edwards as edwards_avx2;
|
use backend::avx2::edwards as edwards_avx2;
|
||||||
|
|
@ -1033,7 +1029,7 @@ mod test {
|
||||||
assert_eq!(bp.compress(), constants::BASE_CMPRSSD);
|
assert_eq!(bp.compress(), constants::BASE_CMPRSSD);
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Test `impl Add<ExtendedPoint> for ExtendedPoint`
|
/// Test `impl Add<EdwardsPoint> for EdwardsPoint`
|
||||||
/// using basepoint + basepoint versus the 2*basepoint constant.
|
/// using basepoint + basepoint versus the 2*basepoint constant.
|
||||||
#[test]
|
#[test]
|
||||||
fn basepoint_plus_basepoint_vs_basepoint2() {
|
fn basepoint_plus_basepoint_vs_basepoint2() {
|
||||||
|
|
@ -1042,7 +1038,7 @@ mod test {
|
||||||
assert_eq!(bp_added.compress(), BASE2_CMPRSSD);
|
assert_eq!(bp_added.compress(), BASE2_CMPRSSD);
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Test `impl Add<ProjectiveNielsPoint> for ExtendedPoint`
|
/// Test `impl Add<ProjectiveNielsPoint> for EdwardsPoint`
|
||||||
/// using the basepoint, basepoint2 constants
|
/// using the basepoint, basepoint2 constants
|
||||||
#[test]
|
#[test]
|
||||||
fn basepoint_plus_basepoint_projective_niels_vs_basepoint2() {
|
fn basepoint_plus_basepoint_projective_niels_vs_basepoint2() {
|
||||||
|
|
@ -1051,7 +1047,7 @@ mod test {
|
||||||
assert_eq!(bp_added.compress(), BASE2_CMPRSSD);
|
assert_eq!(bp_added.compress(), BASE2_CMPRSSD);
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Test `impl Add<AffineNielsPoint> for ExtendedPoint`
|
/// Test `impl Add<AffineNielsPoint> for EdwardsPoint`
|
||||||
/// using the basepoint, basepoint2 constants
|
/// using the basepoint, basepoint2 constants
|
||||||
#[test]
|
#[test]
|
||||||
fn basepoint_plus_basepoint_affine_niels_vs_basepoint2() {
|
fn basepoint_plus_basepoint_affine_niels_vs_basepoint2() {
|
||||||
|
|
@ -1061,13 +1057,13 @@ mod test {
|
||||||
assert_eq!(bp_added.compress(), BASE2_CMPRSSD);
|
assert_eq!(bp_added.compress(), BASE2_CMPRSSD);
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Check that equality of `ExtendedPoints` handles projective
|
/// Check that equality of `EdwardsPoints` handles projective
|
||||||
/// coordinates correctly.
|
/// coordinates correctly.
|
||||||
#[test]
|
#[test]
|
||||||
fn extended_point_equality_handles_scaling() {
|
fn extended_point_equality_handles_scaling() {
|
||||||
let mut two_bytes = [0u8; 32]; two_bytes[0] = 2;
|
let mut two_bytes = [0u8; 32]; two_bytes[0] = 2;
|
||||||
let id1 = ExtendedPoint::identity();
|
let id1 = EdwardsPoint::identity();
|
||||||
let id2 = ExtendedPoint{
|
let id2 = EdwardsPoint{
|
||||||
X: FieldElement::zero(),
|
X: FieldElement::zero(),
|
||||||
Y: FieldElement::from_bytes(&two_bytes),
|
Y: FieldElement::from_bytes(&two_bytes),
|
||||||
Z: FieldElement::from_bytes(&two_bytes),
|
Z: FieldElement::from_bytes(&two_bytes),
|
||||||
|
|
@ -1083,7 +1079,7 @@ mod test {
|
||||||
// construct a point as aB so it has denominators (ie. Z != 1)
|
// construct a point as aB so it has denominators (ie. Z != 1)
|
||||||
let aB = &constants::ED25519_BASEPOINT_TABLE * &A_SCALAR;
|
let aB = &constants::ED25519_BASEPOINT_TABLE * &A_SCALAR;
|
||||||
let aB_affine_niels = aB.to_affine_niels();
|
let aB_affine_niels = aB.to_affine_niels();
|
||||||
let also_aB = (&ExtendedPoint::identity() + &aB_affine_niels).to_extended();
|
let also_aB = (&EdwardsPoint::identity() + &aB_affine_niels).to_extended();
|
||||||
assert_eq!( aB.compress(),
|
assert_eq!( aB.compress(),
|
||||||
also_aB.compress());
|
also_aB.compress());
|
||||||
}
|
}
|
||||||
|
|
@ -1178,13 +1174,13 @@ mod test {
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn compressed_identity() {
|
fn compressed_identity() {
|
||||||
assert_eq!(ExtendedPoint::identity().compress(),
|
assert_eq!(EdwardsPoint::identity().compress(),
|
||||||
CompressedEdwardsY::identity());
|
CompressedEdwardsY::identity());
|
||||||
}
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn is_identity() {
|
fn is_identity() {
|
||||||
assert!( ExtendedPoint::identity().is_identity() == true);
|
assert!( EdwardsPoint::identity().is_identity() == true);
|
||||||
assert!(constants::ED25519_BASEPOINT_POINT.is_identity() == false);
|
assert!(constants::ED25519_BASEPOINT_POINT.is_identity() == false);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -1210,7 +1206,7 @@ mod test {
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn scalarmult_extended_point_works_both_ways() {
|
fn scalarmult_extended_point_works_both_ways() {
|
||||||
let G: ExtendedPoint = constants::ED25519_BASEPOINT_POINT;
|
let G: EdwardsPoint = constants::ED25519_BASEPOINT_POINT;
|
||||||
let s: Scalar = A_SCALAR;
|
let s: Scalar = A_SCALAR;
|
||||||
|
|
||||||
let P1 = &G * &s;
|
let P1 = &G * &s;
|
||||||
|
|
@ -1265,7 +1261,7 @@ mod test {
|
||||||
#[cfg(feature = "serde")]
|
#[cfg(feature = "serde")]
|
||||||
fn serde_cbor_basepoint_roundtrip() {
|
fn serde_cbor_basepoint_roundtrip() {
|
||||||
let output = serde_cbor::to_vec(&constants::ED25519_BASEPOINT_POINT).unwrap();
|
let output = serde_cbor::to_vec(&constants::ED25519_BASEPOINT_POINT).unwrap();
|
||||||
let parsed: ExtendedPoint = serde_cbor::from_slice(&output).unwrap();
|
let parsed: EdwardsPoint = serde_cbor::from_slice(&output).unwrap();
|
||||||
assert_eq!(parsed.compress(), constants::BASE_CMPRSSD);
|
assert_eq!(parsed.compress(), constants::BASE_CMPRSSD);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -1276,7 +1272,7 @@ mod test {
|
||||||
// CBOR apparently has two bytes of overhead for a 32-byte string.
|
// CBOR apparently has two bytes of overhead for a 32-byte string.
|
||||||
// Set the low byte of the compressed point to 1 to make it invalid.
|
// Set the low byte of the compressed point to 1 to make it invalid.
|
||||||
output[2] = 1;
|
output[2] = 1;
|
||||||
let parsed: Result<ExtendedPoint, _> = serde_cbor::from_slice(&output);
|
let parsed: Result<EdwardsPoint, _> = serde_cbor::from_slice(&output);
|
||||||
assert!(parsed.is_err());
|
assert!(parsed.is_err());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -33,7 +33,7 @@ use core::ops::{Mul, MulAssign};
|
||||||
use constants;
|
use constants;
|
||||||
use constants::APLUS2_OVER_FOUR;
|
use constants::APLUS2_OVER_FOUR;
|
||||||
use field::FieldElement;
|
use field::FieldElement;
|
||||||
use edwards::{ExtendedPoint, CompressedEdwardsY};
|
use edwards::{EdwardsPoint, CompressedEdwardsY};
|
||||||
use scalar::Scalar;
|
use scalar::Scalar;
|
||||||
|
|
||||||
// XXX Move these to a common "group" module? At the same time, we should
|
// XXX Move these to a common "group" module? At the same time, we should
|
||||||
|
|
@ -72,13 +72,13 @@ impl CompressedMontgomeryU {
|
||||||
self.0
|
self.0
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Attempt to decompress to an `ExtendedPoint`.
|
/// Attempt to decompress to an `EdwardsPoint`.
|
||||||
///
|
///
|
||||||
/// # Note
|
/// # Note
|
||||||
///
|
///
|
||||||
/// Since there are two curve points with the same
|
/// Since there are two curve points with the same
|
||||||
/// `u`-coordinate, the `u`-coordinate does not fully specify a
|
/// `u`-coordinate, the `u`-coordinate does not fully specify a
|
||||||
/// point. That is, roundtripping between an `ExtendedPoint` and
|
/// point. That is, roundtripping between an `EdwardsPoint` and
|
||||||
/// a `CompressedMontgomeryU` discards its sign bit.
|
/// a `CompressedMontgomeryU` discards its sign bit.
|
||||||
///
|
///
|
||||||
/// # Warning
|
/// # Warning
|
||||||
|
|
@ -87,13 +87,13 @@ impl CompressedMontgomeryU {
|
||||||
///
|
///
|
||||||
/// # Return
|
/// # Return
|
||||||
///
|
///
|
||||||
/// An `Option<ExtendedPoint>`, which will be `None` if either condition holds:
|
/// An `Option<EdwardsPoint>`, which will be `None` if either condition holds:
|
||||||
///
|
///
|
||||||
/// * `u = -1`, or
|
/// * `u = -1`, or
|
||||||
/// * `v` is not square.
|
/// * `v` is not square.
|
||||||
//
|
//
|
||||||
// XXX any other exceptional points for the birational map?
|
// XXX any other exceptional points for the birational map?
|
||||||
pub fn decompress_edwards(&self) -> Option<ExtendedPoint> {
|
pub fn decompress_edwards(&self) -> Option<EdwardsPoint> {
|
||||||
let u: FieldElement = FieldElement::from_bytes(&self.0);
|
let u: FieldElement = FieldElement::from_bytes(&self.0);
|
||||||
|
|
||||||
// If u = -1, then v^2 = u*(u^2+486662*u+1) = 486660.
|
// If u = -1, then v^2 = u*(u^2+486662*u+1) = 486660.
|
||||||
|
|
@ -432,7 +432,7 @@ mod test {
|
||||||
/// identity.
|
/// identity.
|
||||||
#[test]
|
#[test]
|
||||||
fn identity_to_monty() {
|
fn identity_to_monty() {
|
||||||
let id = ExtendedPoint::identity();
|
let id = EdwardsPoint::identity();
|
||||||
assert_eq!(id.to_montgomery().compress(), MontgomeryPoint::identity().compress());
|
assert_eq!(id.to_montgomery().compress(), MontgomeryPoint::identity().compress());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -471,7 +471,7 @@ mod test {
|
||||||
let mut csprng: OsRng = OsRng::new().unwrap();
|
let mut csprng: OsRng = OsRng::new().unwrap();
|
||||||
|
|
||||||
let s: Scalar = Scalar::random(&mut csprng);
|
let s: Scalar = Scalar::random(&mut csprng);
|
||||||
let p_edwards: ExtendedPoint = &constants::ED25519_BASEPOINT_TABLE * &s;
|
let p_edwards: EdwardsPoint = &constants::ED25519_BASEPOINT_TABLE * &s;
|
||||||
let p_montgomery: MontgomeryPoint = p_edwards.to_montgomery();
|
let p_montgomery: MontgomeryPoint = p_edwards.to_montgomery();
|
||||||
|
|
||||||
let expected = &s * &p_edwards;
|
let expected = &s * &p_edwards;
|
||||||
|
|
@ -484,7 +484,7 @@ mod test {
|
||||||
fn ladder_basepoint_times_two_matches_double() {
|
fn ladder_basepoint_times_two_matches_double() {
|
||||||
let two: Scalar = Scalar::from_u64(2u64);
|
let two: Scalar = Scalar::from_u64(2u64);
|
||||||
let result: MontgomeryPoint = &BASE_COMPRESSED_MONTGOMERY.decompress() * &two;
|
let result: MontgomeryPoint = &BASE_COMPRESSED_MONTGOMERY.decompress() * &two;
|
||||||
let expected: ExtendedPoint = constants::ED25519_BASEPOINT_POINT.double();
|
let expected: EdwardsPoint = constants::ED25519_BASEPOINT_POINT.double();
|
||||||
|
|
||||||
assert_eq!(result.compress(), expected.to_montgomery().compress());
|
assert_eq!(result.compress(), expected.to_montgomery().compress());
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -406,7 +406,7 @@ use subtle::ConditionallyNegatable;
|
||||||
use subtle::Equal;
|
use subtle::Equal;
|
||||||
|
|
||||||
use edwards;
|
use edwards;
|
||||||
use edwards::ExtendedPoint;
|
use edwards::EdwardsPoint;
|
||||||
use edwards::EdwardsBasepointTable;
|
use edwards::EdwardsBasepointTable;
|
||||||
|
|
||||||
use scalar::Scalar;
|
use scalar::Scalar;
|
||||||
|
|
@ -487,7 +487,7 @@ impl CompressedRistretto {
|
||||||
if ok == 0u8 || t.is_negative() == 1u8 || y.is_zero() == 1u8 {
|
if ok == 0u8 || t.is_negative() == 1u8 || y.is_zero() == 1u8 {
|
||||||
return None;
|
return None;
|
||||||
} else {
|
} else {
|
||||||
return Some(RistrettoPoint(ExtendedPoint{X: x, Y: y, Z: one, T: t}));
|
return Some(RistrettoPoint(EdwardsPoint{X: x, Y: y, Z: one, T: t}));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -563,10 +563,10 @@ impl<'de> Deserialize<'de> for RistrettoPoint {
|
||||||
/// Edwards form of) Curve25519.
|
/// Edwards form of) Curve25519.
|
||||||
///
|
///
|
||||||
/// Internally, a `RistrettoPoint` is a wrapper type around
|
/// Internally, a `RistrettoPoint` is a wrapper type around
|
||||||
/// `ExtendedPoint`, with custom equality, compression, and
|
/// `EdwardsPoint`, with custom equality, compression, and
|
||||||
/// decompression routines to account for the quotient.
|
/// decompression routines to account for the quotient.
|
||||||
#[derive(Copy, Clone)]
|
#[derive(Copy, Clone)]
|
||||||
pub struct RistrettoPoint(pub(crate) ExtendedPoint);
|
pub struct RistrettoPoint(pub(crate) EdwardsPoint);
|
||||||
|
|
||||||
impl RistrettoPoint {
|
impl RistrettoPoint {
|
||||||
/// Compress in Ristretto format.
|
/// Compress in Ristretto format.
|
||||||
|
|
@ -748,7 +748,7 @@ impl RistrettoPoint {
|
||||||
|
|
||||||
|
|
||||||
/// Return the coset self + E[4], for debugging.
|
/// Return the coset self + E[4], for debugging.
|
||||||
fn coset4(&self) -> [ExtendedPoint; 4] {
|
fn coset4(&self) -> [EdwardsPoint; 4] {
|
||||||
[ self.0
|
[ self.0
|
||||||
, &self.0 + &constants::EIGHT_TORSION[2]
|
, &self.0 + &constants::EIGHT_TORSION[2]
|
||||||
, &self.0 + &constants::EIGHT_TORSION[4]
|
, &self.0 + &constants::EIGHT_TORSION[4]
|
||||||
|
|
@ -881,7 +881,7 @@ impl RistrettoPoint {
|
||||||
|
|
||||||
impl Identity for RistrettoPoint {
|
impl Identity for RistrettoPoint {
|
||||||
fn identity() -> RistrettoPoint {
|
fn identity() -> RistrettoPoint {
|
||||||
RistrettoPoint(ExtendedPoint::identity())
|
RistrettoPoint(EdwardsPoint::identity())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue