Commit graph

319 commits

Author SHA1 Message Date
Henry de Valence
8a5332b220 Remove unused, incorrect a value
This was presumably added for use with formulas that use two multiplications by
small constants (i.e., 121665 and 121666) instead of one multiplication by a
large constant (i.e., -121665/121666), but we don't use those formulas.
2017-01-08 15:11:16 -05:00
Henry de Valence
8fb9e44dd2 Test that d = -121665/121666 2017-01-08 15:11:16 -05:00
Henry de Valence
3f7d06138a Test that SQRT_M1 is a square root of -1 2017-01-08 15:11:15 -05:00
Henry de Valence
a9e3c330a6 Move constants into its own module 2017-01-08 14:39:25 -05:00
Henry de Valence
63e7e9f8de Implement CTAssignable for Scalar 2017-01-06 12:56:53 -05:00
Henry de Valence
74049e039e Make FieldElement's conditional_assign a trait impl 2017-01-06 12:34:57 -05:00
Henry de Valence
c92ebdd0ac Remove unused conditional_choose function 2017-01-06 12:29:24 -05:00
Henry de Valence
098ff2ffca Move CTAssignable trait to util.rs from curve.rs 2017-01-06 12:26:43 -05:00
Henry de Valence
4a5d7052a9 Add convenience wrapper around mult_by_pow_2 to clear cofactor 2017-01-06 10:47:05 -05:00
Henry de Valence
d1599410ee Rename CompressedPoint -> CompressedEdwardsY
This allows other compression formats (e.g., CompressedMontgomeryX).
2016-12-23 17:50:24 -08:00
Henry de Valence
ef2987349f Add bench for unpacked multiply_add 2016-12-23 13:01:16 -08:00
Henry de Valence
85d4b7e98c Split the Scalar type into Scalar and UnpackedScalar
The Scalar type is stored in memory as an array of bytes.  This allows easy
access to the bits of a scalar for Scalar x Point operations, at the cost of
forcing a pack/unpack for Scalar x Scalar.  This commit splits the Scalar type
into Scalar (packed) and UnpackedScalar (limbs).
2016-12-23 12:49:00 -08:00
Henry de Valence
e2dfa17879 Add fixme on load3/4 as utilities 2016-12-23 10:03:30 -08:00
Isis Lovecruft
c9b0e45afb
Specify the RNG for Scalar::random. 2016-12-14 05:54:22 +00:00
Henry de Valence
c6b1b497b0 Add benchmark for Scalar::random() 2016-12-09 17:45:54 -08:00
Henry de Valence
d8476fe6cf Add a Scalar::random() constructor
This adds a dependency on the `rand` crate, used to construct an
OS-backed CSPRNG.  The implementation in this commit is somewhat
inefficient as it constructs a new OsRng object every time; it might be
better to construct it once.  (Seems like a lot of overhead for a few
getrandom(2) calls...)
2016-12-09 17:38:51 -08:00
Henry de Valence
71bf0d5e53 Remove port of Montgomery conversion from Adam's code
This should be brought back later as part of reworking the compressed
point formats / serialization code.  Right now there's just
"CompressedPoint" which is in the ed25519 format.  Ideally, users should
be able to serialize points to formats used for X25519, for decaf, etc.
and not have to worry too much about the internal model.
2016-12-09 14:49:27 -08:00
Isis Lovecruft
f7972041ab
Fix a typo in lib.rs module documention. 2016-12-08 21:59:52 +00:00
Isis Lovecruft
387a56fe2c
Initial commit. 2016-12-08 05:12:00 +00:00