Isis Lovecruft
17290db44c
Update copyright/license headers in source files.
2017-08-15 05:09:20 +00:00
Henry de Valence
c29103d109
Rename _BASEPOINT to _BASEPOINT_POINT.
...
Having _BASEPOINT_TABLE and _BASEPOINT_POINT means that it's not possible to
use the slow, generic scalar mult in place of the fast, precomputed scalar
mults.
2017-08-14 00:20:18 -07:00
Henry de Valence
afecd4f438
Fixup types and publication
2017-08-13 23:57:57 -07:00
Henry de Valence
ea845b4163
Fix missing import in tests
2017-08-02 23:08:46 -07:00
Henry de Valence
3dddecb4a8
Move Montgomery code to a montgomery.rs module
2017-08-02 22:58:15 -07:00
Henry de Valence
8ad02e2f57
Move curve.rs to edwards.rs
2017-08-02 22:35:12 -07:00
Isis Lovecruft
2d15619c6c
Add DecafPoint.to_bytes().
2017-08-01 19:30:51 +00:00
Isis Lovecruft
4d8c18fff3
Add documentation warnings on FieldElement32 and FieldElement64.
2017-08-01 02:46:14 +00:00
Isis Lovecruft
f2883028dc
Use subtle version 0.2.0.
...
* CLOSES PR#66 https://github.com/isislovecruft/curve25519-dalek/pull/66
2017-08-01 02:22:43 +00:00
Isis Lovecruft
7202ab8e63
Merge remote-tracking branch 'hdevalence/feature/constant-time-k-fold-scalar-mult' into develop
2017-08-01 01:51:58 +00:00
Henry de Valence
ddaf602a09
Add multiscalar_mult to Decaf.
2017-07-31 18:40:53 -07:00
Henry de Valence
d2ce1ce5dc
Revert "Add size checking to multiscalar multiplication."
...
This reverts commit 720da348c0 .
Unfortunately, iter::chain on two ExactSizeIterators does not produce an ExactSizeIterator, for reasons described here: https://github.com/rust-lang/rust/issues/34433 .
2017-07-31 18:23:26 -07:00
Henry de Valence
720da348c0
Add size checking to multiscalar multiplication.
2017-07-30 23:54:13 -07:00
Henry de Valence
2d01aa1bf7
Add fixme note on cache awareness
2017-07-30 22:26:18 -07:00
Henry de Valence
63ee9d21ae
tweak code arrangement to keep comments together
2017-07-30 22:24:58 -07:00
Henry de Valence
aaefb90ed3
Rename k_fold_scalar_mult to multiscalar_mult
2017-07-30 22:16:22 -07:00
Henry de Valence
9c4046c3d9
Add constant-time k-fold scalar multiplication
2017-07-30 21:13:56 -07:00
Henry de Valence
f72de04003
Remove unneeded imports to suppress warnings
2017-07-30 16:29:37 -07:00
Henry de Valence
77103986a3
Split field arithmetic into per-implementation files
...
Split the field arithmetic implementations into `FieldElement`,
`FieldElement32`, and `FieldElement64`. `FieldElement` is a type alias for one
of `FieldElement32` or `FieldElement64`, depending on feature selection.
`field.rs` contains tests and code which is generic with respect to the
implementation (e.g., inversions), while `field_32bit.rs` and `field_64bit.rs`
contain the implementation-specific code.
The implementation is not completely hidden, since `FieldElement32` and
`FieldElement64` are tuple structs whose elements are public; `pub(crate)`
doesn't seem to work for tuple structs.
Similarly, the constants file is split over multiple files, depending on the
implementation.
2017-07-30 16:25:42 -07:00
Henry de Valence
513ce26942
avoid 128-bit multiplications
2017-07-20 21:33:15 -07:00
Isis Lovecruft
4e63cbfe4c
Merge remote-tracking branch 'chain/no_std-fix' into develop
2017-06-26 20:14:38 +00:00
Tony Arcieri
d9742c2367
Switch from libcollections to liballoc (gated on an "alloc" feature)
...
libcollections was recently merged into liballoc:
https://github.com/rust-lang/rust/pull/42648
I went ahead and also added an "alloc" feature which no_std users can use to opt
into liballoc features (i.e. any code using Vec). This should have no effect on
anything but no_std usage. It does make it possible for people without
allocators to use curve25519-dalek if they want though. Might be nice for
"bare metal" development.
All that said, from what I can gather liballoc, while not "stable", should
likely stick around for the forseeable future.
Some backstory on the liballoc/libcollections merge here:
https://github.com/rust-lang/rust/pull/42565
2017-06-19 16:59:45 -07:00
Isis Lovecruft
4bcf8bed9d
Move subtle to its own crate.
2017-05-31 21:20:56 +00:00
Isis Lovecruft
161c0cd96d
Add a doctest for subtle::bytes_equal().
2017-05-31 01:31:40 +00:00
Isis Lovecruft
43481a9ff6
Change the whitespace because Boats made fun of it on twitter.
2017-05-31 01:31:37 +00:00
Isis Lovecruft
4ecf6ab326
Implement constant-time selection between two things.
2017-05-31 01:29:59 +00:00
Isis Lovecruft
16904432be
Remove an unnecessary explicit return in FieldElement.to_bytes().
2017-05-28 22:45:13 +00:00
Isis Lovecruft
674a00df5b
Some rustfmt fixes. I disagreed with all the other ones.
2017-05-28 22:42:09 +00:00
Isis Lovecruft
648f95887a
Rename subtle::bytes_equal_ct() to bytes_equal().
2017-05-27 18:35:34 +00:00
Isis Lovecruft
1c4f283be4
Change debug_assert to assert in arrays_equal().
2017-05-27 18:28:37 +00:00
Isis Lovecruft
60692ce891
Put math/code in a docstring in ticks.
2017-05-27 18:24:08 +00:00
Isis Lovecruft
2485472023
Remove explicit lifetime, caught by clippy.
2017-05-27 18:23:31 +00:00
Isis Lovecruft
044128dc58
Remove excessive clone() on Copy, caught by clippy.
2017-05-27 18:21:37 +00:00
Isis Lovecruft
3a664a054a
Whitespace fix in decaf module.
2017-05-27 01:20:14 +00:00
Isis Lovecruft
3decdbed0d
Make arrays_equal() work for any size &[u8], as long as sizes are equal.
2017-05-26 22:39:20 +00:00
Isis Lovecruft
0c38718346
Rename subtle::arrays_equal_ct() to subtle::arrays_equal().
...
It's already obvious that it's constant-time because it's in the subtle
module.
2017-05-26 22:35:45 +00:00
Isis Lovecruft
e74be0024d
Better documentation for arrays_equal_ct.
2017-05-26 21:22:31 +00:00
Isis Lovecruft
a12c2979fb
Fix the doctest for byte_is_nonzero.
2017-05-26 20:53:18 +00:00
Isis Lovecruft
c6057cb2d0
Merge remote-tracking branch 'hdevalence/feature/fast-decaf' into develop
2017-05-25 21:51:57 +00:00
Isis Lovecruft
8772e863e7
Merge remote-tracking branch 'manishearth/fuzz' into develop
2017-05-25 21:50:48 +00:00
Isis Lovecruft
00f3a20329
Merge branch 'feature/add-sub-assign' into develop
2017-05-21 23:04:06 +00:00
Henry de Valence
58982cbc2b
Lower the trial number in decaf_random
...
The radix_51 implementation has many more debug checks, so this takes quite
long to run, and it's rude to run a fuzzer on the CI server.
2017-05-20 21:39:58 -07:00
Henry de Valence
27dbfa9536
Use Mike Hamburg's trick for Decaf compression.
2017-05-20 21:39:58 -07:00
Henry de Valence
52e51bdb16
Add constants for 1/sqrt(a-d) and 1/(a-d)
2017-05-20 21:39:58 -07:00
Henry de Valence
e4913dfc2b
Batch inversions in Decaf decompression.
2017-05-20 21:39:58 -07:00
Henry de Valence
273db53cfd
Benchmark Edwards decompression and compression
2017-05-20 21:39:58 -07:00
Henry de Valence
f741e50eb5
Add a test against current encodings of small multiples of the ed25519 basepoint
2017-05-20 21:39:58 -07:00
Manish Goregaokar
e076079772
Add cargo-fuzz
2017-05-19 16:44:05 -07:00
Henry de Valence
714bf3dd07
Set the number of trials back to 10,000
2017-05-19 14:23:51 -07:00
Henry de Valence
fbd8d0a605
Rewrite decaf elligator code to avoid two consecutive additions
2017-05-19 14:23:51 -07:00