Commit graph

767 commits

Author SHA1 Message Date
Henry de Valence
64cb999866 Make platform-vector lanes constants private 2018-06-14 14:19:26 -07:00
Henry de Valence
00d8b6ea4f Change negate_D, negate_D_lazy to impl Neg, negate_lazy 2018-06-14 14:17:36 -07:00
Henry de Valence
14ce6d3da6 Add a shuffling abstraction for FieldElement32x4 2018-06-14 14:10:37 -07:00
Henry de Valence
c8dc2a6418 Implement addition for FieldElement32x4 2018-06-14 14:10:32 -07:00
Henry de Valence
bd1e3c5f3e some rustfmt changes 2018-06-14 14:05:52 -07:00
Isis Lovecruft
9a89a217f8
Merge remote-tracking branch 'dalek/multiscalar-trait-without-precomputation_r1' into develop 2018-05-15 20:23:05 +00:00
Henry de Valence
bbb64312f7 Use rand 0.5
Requires `0.5.0-pre.2`, which adds `impl CryptoRng for OsRng`.
2018-05-15 12:30:28 -07:00
Henry de Valence
bab642c5af Add doc comments 2018-05-15 11:33:38 -07:00
Henry de Valence
2eed24109e Move double-base scmul to the EdwardsPoint type 2018-05-15 11:33:38 -07:00
Henry de Valence
149c5004e8 Use multiscalar traits for the backend implementations. 2018-05-15 11:33:38 -07:00
Henry de Valence
e3bf9b0213 Add MultiscalarMul and VartimeMultiscalarMul traits.
These traits have the same interface, but with different names, so that it's
not possible to use them interchangeably.  (Constant-time and variable-time
routines should not be used interchangeably).

This commit changes the external API to use these traits, replacing
```
edwards::multiscalar_mul
edwards::vartime::multiscalar_mul
```
with
```
EdwardsPoint::multiscalar_mul (as an impl)
EdwardsPoint::vartime_multiscalar_mul (as an impl)
```
and similarly for Ristretto.

Refactoring the backend is for a later commit.

Multiscalar multiplication with precomputation is for a later commit.

The `edwards::vartime` module is retained since it's used for
`vartime_double_base_scalar_mul`.

It should be subsumed into the precomputation API in a later commit.
2018-05-15 11:33:38 -07:00
Henry de Valence
34c43c20a9 Rework backend selection code.
Each backend can now be selected by an individual feature:

- `u32_backend` for `backend::u32`;
- `u64_backend` for `backend::u64`;
- `avx2_backend` for `backend::avx2`;

The `u64_backend` is selected by default, since most people use X64 and we have
no way to select based on target (see discussion in #126).  However, these
changes mean that it is possible to select the backend explicitly, and if we
had the ability to select target-default features, we could do so easily.
2018-05-14 17:43:54 -07:00
Henry de Valence
9b6c932635 Rename 'precomputed_tables' to the more accurate 'stage2_build' 2018-05-14 15:41:45 -07:00
Henry de Valence
62bb6b79a1
Merge pull request #134 from Mandragorian/feature-scalar-traits
Implement Product and Sum traits
2018-05-03 13:56:45 -07:00
mandragore
96d2fe4905 Implement Sum trait for RistrettoPoint
Closes #131.
2018-05-03 03:42:37 +03:00
mandragore
aff69a58a4 Implement Sum trait for EdwardsPoint 2018-05-03 03:42:37 +03:00
Henry de Valence
185bbd3da8 Fix build on recent nightlies (was broken due to type inference failure) 2018-05-02 17:30:10 -07:00
mandragore
01fd44ffd2 Remove trailing whitespaces 2018-05-02 23:53:52 +03:00
mandragore
3ab087ea7f Implement Sum trait for Scalar 2018-05-02 23:53:49 +03:00
mandragore
afffe962f9 Implement Product trait for Scalar 2018-05-02 23:53:24 +03:00
Henry de Valence
285e57f2ff
Merge pull request #128 from hdevalence/feature/avx2-docs
Update docs for AVX2 backend
2018-04-08 17:16:05 -07:00
Henry de Valence
67ba201835 Update AVX2 documentation 2018-04-08 16:59:57 -07:00
Henry de Valence
6bb2c02a1f
Merge pull request #127 from hdevalence/feature/generalize-naf
Generalize NAF code to wider window sizes.
2018-04-08 16:39:45 -07:00
Henry de Valence
1464c4101d change LSB to least significant bit 2018-04-08 16:29:54 -07:00
Henry de Valence
9fc5602ce7 Split AVX2 docs into markdown file 2018-04-08 15:15:23 -07:00
Henry de Valence
68bbd1bd03 Document algorithm for NAFs 2018-04-06 12:11:59 -07:00
Henry de Valence
6b768c2a1a Change AVX2 backend to use width-8 tables 2018-04-05 16:20:47 -07:00
Henry de Valence
ff787c2f12 Clarify Ristretto / Decaf relation in user docs 2018-04-05 14:52:00 -07:00
Henry de Valence
c99bd62b25 Add example to RistrettoBasepointTable 2018-04-05 14:52:00 -07:00
Henry de Valence
46048e451b Clarify wording on canonical scalars 2018-04-05 14:52:00 -07:00
Henry de Valence
35e1b07e72 Clarify abstraction layers in Ristretto intro 2018-04-05 14:52:00 -07:00
Henry de Valence
c841998b07 Extract Ristretto notes into a markdown file 2018-04-05 14:52:00 -07:00
Henry de Valence
ef0dae241a Add an explanatory note that's built on stable
When building on stable, the README.md is not included in the documentation,
leaving a bare entry. This adds a warning stub, pointing people to use nightly
rust.
2018-04-05 14:52:00 -07:00
Henry & Isis
62d43752df
Add NafLookupTable8 and use for pre-computed basepoint table generation. 2018-04-05 05:12:13 +00:00
Henry & Isis
753a0292de
Rename OddLookupTable to NafLookupTable5.
An OddLookupTable corresponds to a non-adjacent form of width 5.
2018-04-05 04:48:28 +00:00
Henry de Valence
7e0ddf6b98 Rewrite NAF code to work with more window sizes
Change Scalar::non_adjacent_form() to take a width parameter.

This rewrite also makes it faster, although it's probably a ways off
from optimal. I don't know how much it matters.

TODO: write up description of why this computes the same thing.

Thanks to @oleganza for pointing out an error reading bits across words
in an earlier version of this code.
2018-04-04 21:13:09 -07:00
Henry de Valence
5f136fbd0c Remove some warnings.
Not all of the warnings are removed, since although this code works, it still
needs a significant amount of cleanup, editing, and polish.
2018-04-04 10:25:42 -07:00
Henry de Valence
b0bda0278c Drop the stdsimd crate in favor of core::{simd, arch}.
This change required some work, because the to-be-stabilized SIMD functions
don't allow non-constant `imm8`s.  Previously, the `stdsimd` functions had a
constifying macro that ensured that the immediates were known.  The dalek code
used this to build helper functions which would be inlined into different
places where the immediates were known.  Unfortunately, since constexprs aren't
fully supported in Rust yet, this is done by a hidden compiler attribute, and
there's no way to propagate "constness".

To deal with this, some of the functions are specialized (e.g.,
`square_and_negate_D` instead of taking a mask), and others use an enum.
2018-04-03 17:58:23 -07:00
Isis Lovecruft
3281708965
Define mul variants for MontgomeryPoints.
This results in less changes to the x25519-dalek code to upgrade to
the latest version.
2018-04-02 21:09:41 +00:00
Henry de Valence
4a648df713 Feature-gate multiscalar impls on alloc 2018-03-26 17:58:31 -07:00
Henry de Valence
7ef6a1e6fa Reorganize AVX2 point code 2018-03-26 17:41:05 -07:00
Henry de Valence
e8b053b281 Remove AVX2 addition formulas
Only the readdition formulas are actually used by scalar multiplication, so
there's no reason to implement vectorized addition.
2018-03-26 17:41:05 -07:00
Henry de Valence
c73a0fd0d6 Remove AVX2 fixed-base code.
This was faster than the non-AVX2 code, but the serial code is already so fast that there's no reason not to use it.
2018-03-26 17:41:05 -07:00
Henry de Valence
0c4e7188a0 Pull out vartime double-base scalar mul code 2018-03-26 17:41:05 -07:00
Henry de Valence
2d99892eab Pull out variable-time straus implementation 2018-03-26 17:41:05 -07:00
Henry de Valence
2864a422bc Pull out constant-time straus implementation 2018-03-26 16:04:17 -07:00
Henry de Valence
ac739a3edd Split out constant-time variable-base scalar mul.
The serial (`u32`/`u64`) implementations use a multiple curve models, passing
between extended and projective coordinates when performing addition and
doubling (respectively). But the AVX2 backend doesn't, so in order to write a
single scalar mult implementation, we have to either abstract over the curve
models or have two implementations.

A generic solution is possible but extremely unreadable: the scalar mul
implementation would be parameterized over the point types used by the serial
implementations, with many where clauses describing how the types relate. The
AVX2 types could then be substituted in the appropriate places.

Instead we just duplicate the code into the `avx2` backend.
2018-03-26 16:01:51 -07:00
Henry de Valence
76a8d43a04 Create a new scalar_mul module hierarchy.
This should contain generic implementations of scalar multiplication algorithms
that can be used with multiple backends.  The goal is to move the existing
scalar multiplication code into this submodule, then call it from the
user-facing API.  This can also contain code for things we can't do now, like
multiscalar multiplication with precomputation.
2018-03-26 14:34:28 -07:00
Henry de Valence
d6b8389428 Use criterion.rs instead of libtest for benchmarks.
Since Criterion can only benchmark public API, these changes just drop
all internal benchmarks (e.g., benchmarks for field operations). But
those are usually microbenchmarks whose meaning is kind of questionable
anyways, so I don't think this is a big loss.

The `bench` feature disappears, since Criterion works on stable Rust.
2018-03-25 17:14:37 -07:00
Henry de Valence
c9239f54e9 Merge branch 'fix/warnings' into develop 2018-03-22 12:34:31 -07:00
Henry de Valence
6f9c229e65 Remove Elligator stubs for now, since this isn't the API we want anyways 2018-03-22 12:17:23 -07:00
Henry de Valence
f2e44898ee Suppress warnings about square() on UnpackedScalars 2018-03-22 12:17:23 -07:00
Henry de Valence
0ba5c72122 This variable doesn't need to be mut since it's immediately consumed 2018-03-22 12:17:23 -07:00
Henry de Valence
e73b635fe0 Remove unused constants 2018-03-22 12:17:23 -07:00
Henry de Valence
844da9712b Fix AVX2 docs formatting, remove obsolete AVX512 note 2018-03-22 12:13:39 -07:00
Henry de Valence
d67e895619 Merge branch 'feature/rename-to-multiscalar-mul' into develop 2018-03-22 12:08:49 -07:00
Henry de Valence
132b1a9d77 Merge branch 'feature/ristretto-uniform-hash' into develop 2018-03-22 11:44:52 -07:00
Henry de Valence
2e73b2bc20 Use scalar_mul instead of scalar_mult 2018-03-22 11:40:13 -07:00
Henry de Valence
70eee5208a Rename double_scalar_mult_basepoint to double_scalar_mul_basepoint for consistency 2018-03-22 11:39:47 -07:00
Henry de Valence
296cd16463 Rename mult_by_cofactor to mul_by_cofactor for consistency 2018-03-22 11:36:34 -07:00
Henry de Valence
8de3d7576a Rename mult_by_pow_2 to mul_by_pow_2 for consistency 2018-03-22 11:35:42 -07:00
Henry de Valence
b48d568f47 Add debug_assert that Scalar::batch_invert inputs are nonzero 2018-03-22 11:32:00 -07:00
Henry de Valence
0e7d872ad0 Add batch inversion for Scalars 2018-03-22 11:32:00 -07:00
Henry de Valence
792ac0775e Change to the updated subtle API. 2018-03-22 11:13:26 -07:00
Henry de Valence
7f39656b4a Apply the Elligator map twice to ensure a uniform distribution
As noted in the Decaf paper, mapping twice and adding the results ensures a
uniform distribution over the group.  This changes our random point and
hash-to-point functions to do this, matching the Sage script.
2018-03-19 15:37:38 -07:00
Henry de Valence
c20e09f6cc Rename multiscalar_mult->multiscalar_mul to match Mul traits 2018-03-19 14:28:21 -07:00
Henry de Valence
c5fcc6602d Fix build for AVX2 backend.
A missing import of the Borrow trait caused the build to break with the
"yolocrypto" feature enabled; this was't caught by CI because the CI machine
that Travis used didn't have AVX2, so the code was never built.

This commit adds the missing import and changes `std` to `core` so that the
AVX2 backend builds with no_std, but this isn't tested and is, actually,
"yolocrypto".
2018-03-19 11:15:52 -07:00
Isis Lovecruft
de90f16994
Merge branch 'feature/dalek-rs-assets' into develop 2018-03-12 19:50:56 +00:00
Henry de Valence
a271ff907d add link to curve models docs 2018-02-22 15:37:16 -08:00
Henry de Valence
3969d80c89 Add links to dalek.rs 2018-02-21 11:11:17 -08:00
Henry de Valence
2b42966bb4 Load resources from our own domain 2018-02-21 11:03:18 -08:00
Henry de Valence
0f185d3e28 Generalize trait bounds on multiscalar multiplication.
This allows iterators returning either &Scalars or Scalars, so that it's
possible to use map() and friends to adjust scalars as they're being fed into
the multiscalar multiplication.
2018-02-20 18:31:23 -08:00
Henry de Valence
4a4ec74100 Add example to edwards::multiscalar_mult 2018-02-20 17:32:50 -08:00
Henry de Valence
6748dddb96 Simplify and optimize Montgomery code.
The `MontgomeryPoint` struct is now a point on the Kummer line of the Montgomery curve.

The `ProjectivePoint` struct is made private, since its only purpose is
internal to the Montgomery ladder.

The Montgomery ladder takes affine input, making it faster, and produces affine output.

The Edwards-Montgomery correspondence is simplified.
2018-02-05 10:40:25 -08:00
Isis Lovecruft
b5e664ab16
Add RISTRETTO_BASEPOINT_COMPRESSED constant. 2018-02-02 02:33:51 +00:00
Isis Lovecruft
23bc6ff848
Change README and docs sidebar image to transparent version. 2018-01-31 02:26:28 +00:00
Isis Lovecruft
cd112afff5
Whitespace EOL fixes. 2018-01-31 02:19:53 +00:00
Henry de Valence
9698435e38 Add note on point validity and "make illegal states unrepresentable".
Remove references to Montgomery conversions, as a prelude to putting the
Montgomery/Edwards conversion docs in the Montgomery module.
2018-01-30 12:31:53 -08:00
Henry de Valence
2d5dc5079f Add type to X25519 basepoint doc 2018-01-29 14:39:37 -08:00
Henry de Valence
1d480a8a71 Rename X25519 basepoint to X25519_BASEPOINT_MONTGOMERY 2018-01-29 14:36:45 -08:00
Henry de Valence
ae46ecd445 Rename BASE_CMPRSSD to ED25519_BASEPOINT_COMPRESSED. 2018-01-29 12:38:58 -08:00
Henry de Valence
06994e8139 Tidy docs for public constants in backends 2018-01-29 12:38:58 -08:00
Henry de Valence
739755cb1c Fix up constants docstrings 2018-01-29 12:38:58 -08:00
Henry de Valence
d3a8ee0d7b Remove BASEPOINT_ORDER_MINUS_* constants
These were originally added in 32da4c7d50
to implement Scalar negation in terms of multiply-add.

But we have a full implementation of scalar arithmetic now, so it's not
necessary to keep the constants around.
2018-01-29 12:38:58 -08:00
Henry de Valence
3b5a8f84a8 Add an is_torsion_free function and document cofactor-related functions. 2018-01-26 16:07:52 -08:00
Henry de Valence
3d2cf74261 Add docs on Edwards points 2018-01-26 15:36:06 -08:00
Henry de Valence
d4d9d86d72 Fix up coffee/ristretto reference 2018-01-26 15:35:51 -08:00
Henry de Valence
12e658401c Reword Ristretto intro 2018-01-26 14:53:31 -08:00
Henry de Valence
52904b5c3e Use math for multiscalar docs 2018-01-26 13:39:11 -08:00
Henry de Valence
4b47087b40 Refactor Ristretto notes into doc and doc-internal sections. 2018-01-26 13:35:30 -08:00
Henry de Valence
576e27982f Tweak module header names 2018-01-26 10:44:48 -08:00
Henry de Valence
fbd84af767 Ristretto API docs fixups 2018-01-25 17:34:57 -08:00
Henry de Valence
d04d3719a5 Add logo to sidebar 2018-01-25 17:34:20 -08:00
Henry de Valence
99921de6f3 Use README.md for the crate docs, and rewrite it. 2018-01-25 16:26:05 -08:00
Henry de Valence
ce45cfec8e This isn't true after renaming the struct 2018-01-25 12:16:11 -08:00
Henry de Valence
3f7923b628 Keep the AVX2 point type named as ExtendedPoint. 2018-01-25 12:00:40 -08:00
Isis Lovecruft
4f37785f0e
Rename ExtendedPoint to EdwardsPoint. 2018-01-25 02:56:38 +00:00
Isis Lovecruft
9cb915126e
Merge remote-tracking branch 'dalek/feature/borrow-operators' into develop 2018-01-25 02:00:52 +00:00
Henry de Valence
86fd06db00 s/eps/epsilon/ for clarity 2018-01-24 12:42:57 -08:00
Henry de Valence
52d600db95 Implement public-facing ops traits on all combos of &T/T
The public-facing types with arithmetic operations are:

- `Scalar`s
- `ExtendedPoint`s
- `RistrettoPoint`s

For these types we define operators with all combinations of borrowed and
non-borrowed inputs, to avoid forcing API consumers to write extra ampersands.
Since all of the operations involved with these types are expensive relative to
the cost of an unnecessary copy, this isn't a big deal.

The `MontgomeryPoint` struct isn't included in the above because it's only
useful for scalar multiplication.

This commit is based on work by @UnlawfulMonad.
2018-01-24 11:05:06 -08:00
Henry de Valence
0e9b8e0a6e Refactor multiply implementation to eliminate reduce() call 2018-01-19 18:23:41 -08:00
Henry de Valence
ec50ec96f7 Use parallel carry-ins and carry-outs in FieldElement64::reduce() 2018-01-19 17:50:48 -08:00
Henry de Valence
d8d235fb48 Move pow2k into the backends and use it to implement square() 2018-01-19 17:50:48 -08:00
Henry de Valence
1f821d34a5 Feature-gate batch inversion and compression on alloc 2018-01-19 17:22:28 -08:00
Henry de Valence
b20ccbd685 Implement batched encoding for RistrettoPoints 2018-01-19 17:22:28 -08:00
Henry de Valence
de377290ee Implement batch inversion using a product tree. 2018-01-19 17:22:28 -08:00
Isis Lovecruft
0012e1f12f
Merge remote-tracking branch 'hdevalence/feature/avx2_r7' into develop 2018-01-19 23:46:30 +00:00
Henry de Valence
a0c93cb730 fix inconsistency in variable naming 2018-01-10 06:04:03 -08:00
Henry de Valence
841c026c13 Remove dead code 2018-01-10 05:49:47 -08:00
Henry de Valence
f816083575 Use >> instead of srl intrinsic 2018-01-03 14:04:27 -08:00
Henry de Valence
4cbff3983d Remove fixme notes 2018-01-03 14:01:48 -08:00
Henry de Valence
628af18a1d Suppress some warnings 2018-01-03 13:57:50 -08:00
Henry de Valence
3686562b2f Clear memory from avx2 multiscalar mult 2018-01-03 13:37:12 -08:00
Henry de Valence
d41dbb1fe4 Replace some binary constants with named constants 2018-01-03 12:34:25 -08:00
Henry de Valence
dd80421094 Move field constants to constants module 2018-01-03 12:13:52 -08:00
Isis Lovecruft
28f114f127
Combine differential_add and differential_double in Montgomery ladder. 2017-12-24 00:17:15 +00:00
Henry de Valence
ce68b8d72b Document bounds yoga in doubling 2017-12-18 14:48:44 -08:00
Henry de Valence
af3c2b2821 Document readdition 2017-12-18 13:58:37 -08:00
Henry de Valence
c0f64009a7 Implement readdition using a CachedPoint type 2017-12-18 11:42:53 -08:00
Henry de Valence
80813e81b1 make diff_sum maskable 2017-12-15 15:24:13 -08:00
Henry de Valence
0f6171b788 Try to make stdsimd an optional dependency 2017-12-15 13:57:01 -08:00
Henry de Valence
caf296a546 Try to make target_feature work on stable 2017-12-15 13:57:01 -08:00
Henry de Valence
70f710eafe Use the LookupTable struct in AVX2 code 2017-12-15 13:57:01 -08:00
Henry de Valence
34f44dcf5d Merge branch 'develop' into feature/avx2_r8 2017-12-15 11:37:10 -08:00
Henry de Valence
640888198e Eliminate a carry pass through tighter bounds checks 2017-12-14 14:17:34 -08:00
Henry de Valence
a3f53c9134 Refactor select_precomputed_point into a LookupTable struct.
Originally this was for hygiene, so that we could erase points from
heap-allocated memory in multiscalar_mult, but it ends up providing a cleaner
API for scalar multiplication.

It's kept inside curve_models for now, but it could go somewhere else if that's a better place.
2017-12-07 12:46:57 -08:00
Henry de Valence
98a78d7a58 Clear scalar digits from memory in multiscalar_mult 2017-12-07 12:34:40 -08:00
Henry de Valence
d62fc7caf1 Rearrange signs to avoid a subtraction 2017-12-07 10:55:33 -08:00
Henry de Valence
1d39d2ec6e Implement Default for internal point types 2017-12-06 17:30:19 -08:00
Henry de Valence
7d2d87441b Connect double_scalar_mult_basepoint to AVX2 backend 2017-12-04 11:05:24 -08:00
Henry de Valence
2c29d9a2ad tweak docs 2017-12-04 10:37:37 -08:00
Henry de Valence
3814beeafe Fix typo and add note on AVX512VL 2017-12-04 10:37:37 -08:00
Henry de Valence
bf5e3581d2 Update AVX2 docs 2017-12-04 10:37:37 -08:00
Henry de Valence
1103c5c43a Implement Sub by pre-negating the point 2017-12-04 10:37:37 -08:00
Henry de Valence
e3579995c0 Add double-base scalar vartime for AVX2 2017-12-04 10:37:37 -08:00
Henry de Valence
9213dc0bbb Implement point subtraction 2017-12-04 10:37:37 -08:00
Henry de Valence
3094866442 Fix up after Scalar API changes 2017-12-04 10:37:37 -08:00
Henry de Valence
ba071f12aa Write up notes on the AVX2 backend 2017-12-04 10:37:37 -08:00
Henry de Valence
3d435a1f4f Fix up tests to use new Scalar API 2017-12-04 10:37:37 -08:00
Henry de Valence
b5305b4e30 Connect multiscalar_mult to the AVX2 backend 2017-12-04 10:37:37 -08:00
Henry de Valence
912fc5d412 Never build avx2 without avx2 2017-12-04 10:37:37 -08:00
Henry de Valence
97fe2f0bf4 Try to connect the AVX2 backend to the ExtendedPoint frontend 2017-12-04 10:37:37 -08:00
Henry de Valence
77766b3422 Add benchmark for conversion to avx2 format 2017-12-04 10:37:37 -08:00
Henry de Valence
208180dc72 Simplify mul, square implementations 2017-12-04 10:37:37 -08:00
Henry de Valence
f28635ab4e Add a new 'avx2_backend' yolocrypto feature 2017-12-04 10:37:37 -08:00
Henry de Valence
841e0d5b64 Fix wrong feature for benchmarks 2017-12-04 10:37:37 -08:00
Henry de Valence
81ecef89ee Connect AVX2 and u64 backends 2017-12-04 10:37:37 -08:00
Henry de Valence
ed24d1c5fa Move AVX2 code into a backend 2017-12-04 10:37:37 -08:00
Henry de Valence
2b37a65d66 Remove debugging code 2017-12-04 10:37:37 -08:00
Henry de Valence
1ba7cb1e2c Add stub implementations of multiscalar mult 2017-12-04 10:37:37 -08:00
Henry de Valence
7354b569bb Add 32bit reduction code 2017-12-04 10:37:37 -08:00
Henry de Valence
e7ec5b3dd1 Add basepoint table code 2017-12-04 10:37:37 -08:00
Henry de Valence
34ae1b15e0 Add a squaring implementation 2017-12-04 10:37:37 -08:00
Henry de Valence
2f32f6355c Add doubling skeleton and scalar mult 2017-12-04 10:37:37 -08:00
Henry de Valence
9e383ffccb Add doubling test harness 2017-12-04 10:37:37 -08:00
Henry de Valence
e2a2b3a3b5 Add comment to mul draft 2017-12-04 10:37:37 -08:00
Henry de Valence
4f6788c72d First working version 2017-12-04 10:37:37 -08:00
Henry de Valence
15b88be2d2 Add serial implementation of the algorithm and a test 2017-12-04 10:37:37 -08:00
Henry de Valence
51f04d7cce first avx2 code 2017-12-04 10:37:37 -08:00
Isis Lovecruft
c71d41ddcc
Whitespace fixes. 2017-12-04 01:17:17 +00:00
Isis Lovecruft
9824894eb1
Merge remote-tracking branch 'hdevalence/feature/texify-formulas' into develop 2017-12-04 01:10:54 +00:00
Henry de Valence
c0633ae2d7 KaTeXify some backend documentation 2017-12-01 11:46:36 -08:00
Henry de Valence
2d6d79dc21 KaTeXify more of edwards.rs 2017-11-30 17:36:56 -08:00
Henry de Valence
10bba1207b KaTeXify and document basepoint tables 2017-11-30 17:11:25 -08:00
Henry de Valence
786e4b65a8 Add reference to from_bytes_mod_order_wide ctor 2017-11-30 16:48:29 -08:00
Henry de Valence
bb9c171487 fix typo in internal Scalar docs 2017-11-30 16:46:46 -08:00
Henry de Valence
1caed9a4fc Remove Scalar::multiply_add 2017-11-30 16:44:51 -08:00
Henry de Valence
9e892dd5f3 Rename reduce_wide to from_bytes_mod_order_wide and keep it with the other constructors 2017-11-30 16:44:10 -08:00
Henry de Valence
a6b4467d23 KaTeXify Scalar docs 2017-11-30 16:43:21 -08:00
Isis Lovecruft
d21b74ea36
Line wrap an inline comment. 2017-11-30 22:41:06 +00:00
Henry de Valence
beda5df2f1 Remove "scalar multiplication" since that's more of a scalar*point thing than just a scalar thing 2017-11-29 13:04:04 -08:00
Henry de Valence
2e9a3cba35 Remove reference to field elts since they're private 2017-11-29 13:03:01 -08:00
Henry de Valence
da8b12a62d Align montgomery summary to match the edwards summary 2017-11-29 13:01:31 -08:00
Henry de Valence
c209b49264 Tweak description and fix formatting 2017-11-29 13:00:50 -08:00
Henry de Valence
442eba57c9 Comment out #[doc(hidden)] to allow impls to appear in internal docs.
This is related to https://github.com/rust-lang/rust/issues/46380 upstream.
2017-11-29 12:40:42 -08:00
Henry de Valence
d862912511 KaTeXify struct docs for internal point types 2017-11-29 12:30:51 -08:00
Henry de Valence
b2a85da09d Edit curve model description to use KaTeX 2017-11-29 12:07:55 -08:00
Isis Lovecruft
88200f9fc9
Fix Scalar.to_bytes() after merging PR#88. 2017-11-26 04:16:12 +00:00
Isis Lovecruft
220c6c1d13
Merge remote-tracking branch 'hdevalence/feature/refactor-scalar-api' into develop 2017-11-26 04:15:04 +00:00
Isis Lovecruft
227acc117b
Whitespace fix. 2017-11-26 03:26:47 +00:00
Isis Lovecruft
7a0c0e9d0d
Change Debug for Scalar output to be valid Rust code. 2017-11-26 03:26:29 +00:00
Isis Lovecruft
87f93a5df2
Add to_bytes() convenience method for Scalar. 2017-11-26 03:23:31 +00:00
Isis Lovecruft
9a49263752
Add to_bytes() convenience method for CompressedRistretto points. 2017-11-26 03:22:28 +00:00
Henry de Valence
f165b63ee9 Encode scalars canonically using Serde. 2017-11-23 12:29:46 -08:00
Henry de Valence
c1f6302879 Add a Scalar::from_bytes_canonical method 2017-11-23 12:29:46 -08:00
Henry de Valence
9855260bfd Add a method to test if a Scalar is canonical 2017-11-23 12:29:46 -08:00
Henry de Valence
34639725d4 clean up reduction test 2017-11-23 12:29:46 -08:00
Henry de Valence
d32fe9772b Ensure that all Scalars are bounded by 2^255.
This commit defines a Scalar to hold an integer representing an element of
Z/lZ.  Applications like X/Ed25519 that care about the bit-patterns of the
scalars they use can set a specific bit-pattern using the `from_bits`
constructor.  Applications that want to treat scalars as integers mod l can use
the `from_bytes_mod_order` constructor.  Either way, the constructor ensures
that the integer representing each Scalar is bounded by 2^255 so that the high
bit is set.  This means that any Scalar object is always safe to use for scalar
multiplication, while maintaining compatibility with both the Ristretto
use-case and the X/Ed25519 usecase.
2017-11-23 12:29:46 -08:00
Henry de Valence
d88f92276a Add Scalar::reduce method 2017-11-21 11:28:25 -08:00
Henry de Valence
df182b79d0 Rename Scalar::reduce to Scalar::reduce_wide
This opens the `Scalar::reduce` name for reduction mod l.
2017-11-21 11:06:54 -08:00
Henry de Valence
033a90890c Remove Scalar::{add, sub, mul} methods 2017-11-21 10:43:49 -08:00
Henry de Valence
e94c6f0a96 Make more Scalar methods pub(crate) 2017-11-20 16:45:30 -08:00
Henry de Valence
2d69a8a7dc Eliminate array_ref dependency 2017-11-20 14:53:08 -08:00
Henry de Valence
504a557b33 Hide UnpackedScalars 2017-11-17 15:51:29 -08:00
Henry de Valence
0cb70ae032 Hide the underlying ExtendedPoint from a Ristretto point 2017-11-17 15:50:58 -08:00
Henry de Valence
a9f8789524 hide unimplemented fns from docs 2017-11-17 15:50:04 -08:00
Henry de Valence
9fda4739d0 Hide fns using private types 2017-11-17 15:42:37 -08:00
Henry de Valence
78d9e70071 Move ExtendedPoint->MontgomeryPoint conversion to edwards.rs
Need to find a solution to the internal/external docs problem
2017-11-17 15:13:45 -08:00
Henry de Valence
2b0a4979b1 Fix indentation 2017-11-17 14:09:48 -08:00
Henry de Valence
8337a895d4 Only compress ExtendedPoints 2017-11-17 13:32:22 -08:00
Henry de Valence
7f52745770 Remove unused import 2017-11-16 20:11:18 -08:00
Henry de Valence
8d0808a077 Split internal curve models into a private submodule 2017-11-16 17:34:28 -08:00
Henry de Valence
e196f8347c Move 32/64-bit code into submodules in a backend module.
See the doc comment in `backend/mod.rs` for motivation on naming.
2017-11-16 16:07:55 -08:00
Henry de Valence
6ce7a4ee2d Remove catchall 'utils' module 2017-11-16 12:13:13 -08:00
Henry de Valence
e4f5f23b8d fixup! Merge branch 'optimzed_scalar_r1' into develop 2017-11-16 12:13:13 -08:00
Henry de Valence
207af566b9 Replace signed constants with unsigned constants 2017-11-16 12:13:13 -08:00
Henry de Valence
83e20b5387 cfg-gate all tests using precomputed tables 2017-11-16 12:13:13 -08:00
Henry de Valence
8952c7f476 initial work on rewriting 32bit arithmetic 2017-11-16 12:13:13 -08:00
Henry de Valence
399a9db478 Generate AFFINE_ODD_MULTIPLES_OF_BASEPOINT at compile time 2017-11-16 12:13:13 -08:00
Henry de Valence
e7387650f6 Remove warnings from build.rs 2017-11-16 12:13:13 -08:00
Henry de Valence
108a690941 First attempt at generating basepoint tables at compile time 2017-11-16 12:13:13 -08:00
Henry de Valence
b966f942a8 Impl Debug for EdwardsBasepointTable 2017-11-16 11:09:45 -08:00
Henry de Valence
6f5f0c51fd Tweak Debug impls to produce Rust source 2017-11-16 11:09:32 -08:00
Isis Lovecruft
cc8528f41f
Change implementation-specific scalar constants to be pub(crate). 2017-11-16 00:39:27 +00:00
Isis Lovecruft
c59af2c6b8
Merge branch 'optimzed_scalar_r1' into develop 2017-11-15 22:02:36 +00:00
Isis Lovecruft
2345a3f2fa
Fix typo in Scalar64::from_bytes_wide().
* FIXES issue #82:
   https://github.com/isislovecruft/curve25519-dalek/issues/82
2017-11-15 03:19:39 +00:00
Henry de Valence
f3a7108c55 Remove sha2 crate, which is only used in doctests 2017-10-31 14:12:29 -07:00
Henry de Valence
8f68b7a3ed Remove MSQRT_M1 constant 2017-10-31 14:10:33 -07:00
Isis Lovecruft
583a45ddc2
Add test that scalar Montgomery reduction matches reduction. 2017-10-31 01:18:52 +00:00
Isis Lovecruft
e2cbec81fc
Add test that UnpackedScalar::{to,from}_bytes() roundtrips. 2017-10-31 01:02:20 +00:00
Henry de Valence
bbbe4bf665 Make most numeric constants pub(crate) 2017-10-30 17:33:23 -07:00
Henry de Valence
a7835a1246 UPPERCASE_GLOBALS and add documentation 2017-10-30 17:33:23 -07:00
Isis Lovecruft
f0102806a2
Remove unnecessary mask operation in Scalar32::from_bytes_wide().
The significant bits here can only be
2017-10-31 00:00:14 +00:00
Henry de Valence
089efbbbbe Prune constants that are no longer used anywhere 2017-10-30 16:53:39 -07:00
Henry de Valence
d08c3d252b fix std/alloc dep for multiscalar_mult for RistrettoPoints 2017-10-30 16:34:36 -07:00
Henry de Valence
8c3ae7f010 Remove 'yolocrypto' from Ristretto 2017-10-30 16:34:36 -07:00
Henry de Valence
b6bfc79cd1 Fix up Elligator tests to match ristretto.sage 2017-10-30 16:34:36 -07:00
Henry de Valence
f4135da5c9 Remove is_negative_decaf since ristretto uses the low bit 2017-10-30 16:34:36 -07:00
Henry de Valence
21101a7d71 Add test vectors from ristretto.sage 2017-10-30 16:34:36 -07:00
Henry de Valence
8e21c0b4f0 Start writing down some notes on the compression procedure 2017-10-30 16:34:36 -07:00
Henry de Valence
98c34adf6d Change to Ristretto test vectors. 2017-10-30 16:34:36 -07:00
Henry de Valence
7097d8f98e Add Ristretto equality 2017-10-30 16:34:36 -07:00
Henry de Valence
fafdae7a60 Prototype of Ristretto encoding 2017-10-30 16:34:36 -07:00
Henry de Valence
58a55117be Rename Decaf to Ristretto 2017-10-30 16:34:36 -07:00
Isis Lovecruft
6ed006abc1
Fix two oversized buffer allocations in scalar code. 2017-10-30 23:17:46 +00:00
Henry de Valence
aaa2315703
add failing test case from fuzzer 2017-10-30 22:25:34 +00:00
Henry de Valence
3c085d264c
Change Scalar32 and Scalar64 to not mask the high 3 bits of a Scalar.
This should not cause overflow, since this just lets the high limb have the
same bounds as the other limbs, but we should check this carefully.
2017-10-30 22:25:33 +00:00
Isis Lovecruft
6079b0269f
Revert "Revert "Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop""
This reverts commit 90b69c13ee.

Signed-off-by: Isis Lovecruft <isis@torproject.org>
2017-10-30 19:27:44 +00:00
Isis Lovecruft
90b69c13ee
Revert "Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop"
This reverts commit 804dab8924, reversing
changes made to 5d15ca77ff.

This is due to a (previously undocumented) contract on the behaviours of
(potentially unreduced mod \ell) "packed" scalars w.r.t. to the manner in which
their bytes are interpreted.

Upon documentation fixes and corresponding fixes being made on top of the
floodyberry/optimized_scalar branch, this revert will again be reverted and then
the additional changes merged (à la
file:///usr/share/doc/git/html/howto/revert-a-faulty-merge.html).

Signed-off-by: Isis Lovecruft <isis@patternsinthevoid.net>
2017-10-16 21:41:52 +00:00
Isis Lovecruft
804dab8924
Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop 2017-10-05 02:57:55 +00:00
Isis Lovecruft
5d15ca77ff
Merge branch 'feature/montgomery-arithmetic_r1' into develop 2017-10-05 02:37:27 +00:00
Isis Lovecruft
d39e47ff11
Remove comment on non-canonical encodings in CompressedMontgomeryU.decompress(). 2017-10-05 02:27:27 +00:00
Isis Lovecruft
4965238b5a
Removed now unused subtle import from montgomery module. 2017-10-05 02:23:55 +00:00
Isis Lovecruft
29f9090411
Fix two typos in docstrings for constants. 2017-10-05 02:23:34 +00:00
Isis Lovecruft
9da24d8afa
Add test for Montgomery ladder with a scalar with high bit set. 2017-10-05 02:15:28 +00:00
Isis Lovecruft
ca5b58c2b7
Clarify doc note on degenerate cases for differential addition. 2017-10-05 01:54:26 +00:00
Isis Lovecruft
7b378ada6b
Rephrase doc note on exceptional projective Montgomery points. 2017-10-05 01:46:42 +00:00
Isis Lovecruft
5e6e6c3fa8
Eliminate extra inversions in MontgomeryPoint.ct_eq(). 2017-10-05 01:32:44 +00:00
Isis Lovecruft
7e4fd5677c
Add tests and benchmark for MontgomeryPoint.ct_eq(). 2017-10-05 01:26:15 +00:00
Isis Lovecruft
d39cb275c5
Remove DecafPoint.to_edwards() method. 2017-10-05 00:56:40 +00:00