Henry de Valence
beda5df2f1
Remove "scalar multiplication" since that's more of a scalar*point thing than just a scalar thing
2017-11-29 13:04:04 -08:00
Isis Lovecruft
88200f9fc9
Fix Scalar.to_bytes() after merging PR#88.
2017-11-26 04:16:12 +00:00
Isis Lovecruft
220c6c1d13
Merge remote-tracking branch 'hdevalence/feature/refactor-scalar-api' into develop
2017-11-26 04:15:04 +00:00
Isis Lovecruft
227acc117b
Whitespace fix.
2017-11-26 03:26:47 +00:00
Isis Lovecruft
7a0c0e9d0d
Change Debug for Scalar output to be valid Rust code.
2017-11-26 03:26:29 +00:00
Isis Lovecruft
87f93a5df2
Add to_bytes() convenience method for Scalar.
2017-11-26 03:23:31 +00:00
Henry de Valence
f165b63ee9
Encode scalars canonically using Serde.
2017-11-23 12:29:46 -08:00
Henry de Valence
c1f6302879
Add a Scalar::from_bytes_canonical method
2017-11-23 12:29:46 -08:00
Henry de Valence
9855260bfd
Add a method to test if a Scalar is canonical
2017-11-23 12:29:46 -08:00
Henry de Valence
34639725d4
clean up reduction test
2017-11-23 12:29:46 -08:00
Henry de Valence
d32fe9772b
Ensure that all Scalars are bounded by 2^255.
...
This commit defines a Scalar to hold an integer representing an element of
Z/lZ. Applications like X/Ed25519 that care about the bit-patterns of the
scalars they use can set a specific bit-pattern using the `from_bits`
constructor. Applications that want to treat scalars as integers mod l can use
the `from_bytes_mod_order` constructor. Either way, the constructor ensures
that the integer representing each Scalar is bounded by 2^255 so that the high
bit is set. This means that any Scalar object is always safe to use for scalar
multiplication, while maintaining compatibility with both the Ristretto
use-case and the X/Ed25519 usecase.
2017-11-23 12:29:46 -08:00
Henry de Valence
d88f92276a
Add Scalar::reduce method
2017-11-21 11:28:25 -08:00
Henry de Valence
df182b79d0
Rename Scalar::reduce to Scalar::reduce_wide
...
This opens the `Scalar::reduce` name for reduction mod l.
2017-11-21 11:06:54 -08:00
Henry de Valence
033a90890c
Remove Scalar::{add, sub, mul} methods
2017-11-21 10:43:49 -08:00
Henry de Valence
e94c6f0a96
Make more Scalar methods pub(crate)
2017-11-20 16:45:30 -08:00
Henry de Valence
2d69a8a7dc
Eliminate array_ref dependency
2017-11-20 14:53:08 -08:00
Henry de Valence
504a557b33
Hide UnpackedScalars
2017-11-17 15:51:29 -08:00
Henry de Valence
e196f8347c
Move 32/64-bit code into submodules in a backend module.
...
See the doc comment in `backend/mod.rs` for motivation on naming.
2017-11-16 16:07:55 -08:00
Isis Lovecruft
c59af2c6b8
Merge branch 'optimzed_scalar_r1' into develop
2017-11-15 22:02:36 +00:00
Isis Lovecruft
583a45ddc2
Add test that scalar Montgomery reduction matches reduction.
2017-10-31 01:18:52 +00:00
Isis Lovecruft
e2cbec81fc
Add test that UnpackedScalar::{to,from}_bytes() roundtrips.
2017-10-31 01:02:20 +00:00
Henry de Valence
a7835a1246
UPPERCASE_GLOBALS and add documentation
2017-10-30 17:33:23 -07:00
Henry de Valence
aaa2315703
add failing test case from fuzzer
2017-10-30 22:25:34 +00:00
Isis Lovecruft
6079b0269f
Revert "Revert "Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop""
...
This reverts commit 90b69c13ee .
Signed-off-by: Isis Lovecruft <isis@torproject.org>
2017-10-30 19:27:44 +00:00
Isis Lovecruft
90b69c13ee
Revert "Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop"
...
This reverts commit 804dab8924 , reversing
changes made to 5d15ca77ff .
This is due to a (previously undocumented) contract on the behaviours of
(potentially unreduced mod \ell) "packed" scalars w.r.t. to the manner in which
their bytes are interpreted.
Upon documentation fixes and corresponding fixes being made on top of the
floodyberry/optimized_scalar branch, this revert will again be reverted and then
the additional changes merged (à la
file:///usr/share/doc/git/html/howto/revert-a-faulty-merge.html).
Signed-off-by: Isis Lovecruft <isis@patternsinthevoid.net>
2017-10-16 21:41:52 +00:00
Andrew Moon
7e53499a10
optimized scalar implementations for 32/64 bit
2017-09-24 22:24:35 -05:00
Brian Smith
7ed9eb8617
Replace one multiplication with a squaring in scalar inversion.
...
This brings the code up to date with the 2017-09-04 version of
the source article.
2017-09-04 09:45:13 -10:00
Brian Smith
028140bb33
Reformat addition chain window building code to better show pattern.
...
Make the 2 digit, `_10`, the first argument to more closely match the
Haskell code in the source article. Align the code into columns to
further clarify the patterns.
2017-09-04 09:23:27 -10:00
Brian Smith
91a7c641c2
Use more efficient addition chain for scalar inversion.
...
Use the addition chain from
https://briansmith.org/ecc-inversion-addition-chains-01#curve25519_scalar_inversion .
In my benchmarking, this consistently runs at least 20% faster.
2017-09-03 17:00:42 -10:00
khyperia
6747133519
Optimize scalar inversion by implementing square()
...
This shows an 11% speedup for invert()
2017-08-21 21:35:26 -07:00
Isis Lovecruft
17290db44c
Update copyright/license headers in source files.
2017-08-15 05:09:20 +00:00
Isis Lovecruft
f2883028dc
Use subtle version 0.2.0.
...
* CLOSES PR#66 https://github.com/isislovecruft/curve25519-dalek/pull/66
2017-08-01 02:22:43 +00:00
Isis Lovecruft
4bcf8bed9d
Move subtle to its own crate.
2017-05-31 21:20:56 +00:00
Isis Lovecruft
674a00df5b
Some rustfmt fixes. I disagreed with all the other ones.
2017-05-28 22:42:09 +00:00
Isis Lovecruft
0c38718346
Rename subtle::arrays_equal_ct() to subtle::arrays_equal().
...
It's already obvious that it's constant-time because it's in the subtle
module.
2017-05-26 22:35:45 +00:00
Henry de Valence
69c62a8a17
Serde Scalar support
2017-05-15 22:40:09 -07:00
Isis Lovecruft
4a646806b8
Merge branch 'feature/scalarmult-lhs' into develop
2017-05-14 09:35:15 +00:00
Isis Lovecruft
61d07693ec
Merge remote-tracking branch 'hdevalence/feature/operator_scalar_mult_r2' into develop
2017-05-14 09:34:45 +00:00
Isis Lovecruft
ae11d4bc76
Merge remote-tracking branch 'hdevalence/feature/vartime-module' into develop
2017-05-14 09:34:14 +00:00
Isis Lovecruft
944e8e1649
Fix and allow some non-snakecased variables in scalar tests.
2017-05-09 00:05:11 +00:00
Isis Lovecruft
9a9959061d
Merge remote-tracking branch 'hdevalence/feature/clippy-fixes' into develop
2017-05-06 00:16:09 +00:00
Isis Lovecruft
8f4114a211
Merge remote-tracking branch 'hdevalence/feature/streamable-hash-to-scalar' into develop
2017-05-05 23:52:59 +00:00
Henry & Isis
c6dc9d318d
Add a helper function to construct a Scalar from a u64
2017-05-03 19:32:31 -07:00
Henry & Isis
7cbb8dd94e
Merge branch 'feature/streamable-hash-to-scalar' into develop
2017-05-03 19:32:09 -07:00
Henry de Valence
b05c897123
Implement operators for Scalars using multiply_add
2017-05-02 22:29:18 -07:00
Henry de Valence
91e11b6318
Change docstring to match the trait bound
2017-05-02 21:22:04 -07:00
Henry de Valence
6ea1d4dad2
Add an implementation of Scalar inversion
2017-04-28 22:59:56 -07:00
Henry de Valence
653f134bc7
Implement Mul, MulAssign, zero(), one() for UnpackedScalar
2017-04-28 22:57:17 -07:00
Henry de Valence
b5ccb42759
Rename lminus1 to l_minus_1
2017-04-28 22:54:00 -07:00
Henry de Valence
057c84abd5
Add a bits() function for scalars
2017-04-28 22:51:32 -07:00
Henry de Valence
7f4b96150d
Remove explicit lifetimes
2017-04-02 23:36:05 +02:00
Henry de Valence
b3041f2adc
Remove unnecessary if statements
2017-04-02 23:27:38 +02:00
Henry de Valence
eca28fd3e8
Refactor Scalar::hash_from_bytes to allow streaming input to the hash.
2017-03-27 04:49:00 -07:00
Isis Lovecruft
5ebbd5dd86
Remove an XXX comment about using something better than array_ref!().
...
It turns out array_ref!() is probably the best way, or, at least, we're
already using it everywhere.
2017-03-17 21:42:58 +00:00
Isis Lovecruft
d549fdc8f9
Whitespace fixes.
2017-03-17 21:42:40 +00:00
Isis Lovecruft
f6930997d2
Make #[feature(test)] depend on #[cfg(all(test, feature = "bench"))].
...
* FIXES Issue #38 :
https://github.com/isislovecruft/curve25519-dalek/pull/38
2017-03-14 01:59:08 +00:00
Isis Lovecruft
3882a41d27
Remove test_ prefix from tests in scalar module.
2017-03-14 01:58:39 +00:00
Isis Lovecruft
4afe4ae37f
Move scalar module benchmarks to separate module.
2017-03-14 01:52:42 +00:00
Henry de Valence
b61ed818b8
Remove all remaining warnings
2017-03-07 01:37:31 -08:00
Isis Lovecruft
f48947fb57
Merge remote-tracking branch 'hdevalence/feature/some-cleanup-tweaks' into develop
2017-02-28 05:50:22 +00:00
Henry de Valence
fe15bc1d0b
Add note on fn main() in doctest
2017-02-27 11:22:07 -08:00
Henry de Valence
a93798d209
Add a function to hash a byte slice to a scalar.
2017-02-27 11:19:06 -08:00
Henry de Valence
e5c0d789fd
Add a Scalar::as_bytes() method.
2017-02-26 15:25:05 -08:00
Henry de Valence
950519b97b
Implement Debug for Scalar
2017-02-26 15:25:05 -08:00
Isis Lovecruft
e4d041836e
Move load3 and load4 to new utils module and remove #[allow(dead_code)].
2017-02-21 06:15:08 +00:00
Isis Lovecruft
6f67a7d716
Rename util module to subtle.
...
* CHANGE subtle module documentation slightly to clarify the module's purpose.
* FIXES issue #25 .
2017-02-21 06:01:22 +00:00
Isis Lovecruft
5308fef210
Add CTEq trait and implement it for Scalar.
2017-02-21 05:44:35 +00:00
Isis Lovecruft
7b57be69fd
Implement constant time equality check for scalars.
2017-02-21 05:41:14 +00:00
Isis Lovecruft
32da4c7d50
Implement Neg for Scalar.
2017-02-21 05:41:14 +00:00
Isis Lovecruft
8c432ef78a
Another obsessive compulsive whitespace fix.
2017-02-21 01:46:01 +00:00
Isis Lovecruft
1e7199dcc4
Remove now unused core::clone::Clone from scalar.
2017-01-27 02:16:30 +00:00
Isis Lovecruft
d88b6c01c4
Merge remote-tracking branch 'tarcieri/no-std' into develop
2017-01-27 02:13:04 +00:00
Isis Lovecruft
39f417f75e
Merge remote-tracking branch 'hdevalence/feature/move-ct-traits' into develop
2017-01-20 21:51:19 +00:00
Tony Arcieri
d08bc7395e
Add #![no_std] ( fixes #16 )
...
Use ::core in lieu of ::std, allowing this crate to be usable in #![no_std]
environments.
Gates features that presently depend on ::std (presently just rand) behind a
"std" cargo feature, which is enabled by default.
2017-01-18 15:16:01 -08:00
Henry de Valence
63e7e9f8de
Implement CTAssignable for Scalar
2017-01-06 12:56:53 -05:00
Henry de Valence
ef2987349f
Add bench for unpacked multiply_add
2016-12-23 13:01:16 -08:00
Henry de Valence
85d4b7e98c
Split the Scalar type into Scalar and UnpackedScalar
...
The Scalar type is stored in memory as an array of bytes. This allows easy
access to the bits of a scalar for Scalar x Point operations, at the cost of
forcing a pack/unpack for Scalar x Scalar. This commit splits the Scalar type
into Scalar (packed) and UnpackedScalar (limbs).
2016-12-23 12:49:00 -08:00
Henry de Valence
e2dfa17879
Add fixme on load3/4 as utilities
2016-12-23 10:03:30 -08:00
Isis Lovecruft
c9b0e45afb
Specify the RNG for Scalar::random.
2016-12-14 05:54:22 +00:00
Henry de Valence
c6b1b497b0
Add benchmark for Scalar::random()
2016-12-09 17:45:54 -08:00
Henry de Valence
d8476fe6cf
Add a Scalar::random() constructor
...
This adds a dependency on the `rand` crate, used to construct an
OS-backed CSPRNG. The implementation in this commit is somewhat
inefficient as it constructs a new OsRng object every time; it might be
better to construct it once. (Seems like a lot of overhead for a few
getrandom(2) calls...)
2016-12-09 17:38:51 -08:00
Isis Lovecruft
387a56fe2c
Initial commit.
2016-12-08 05:12:00 +00:00