Commit graph

440 commits

Author SHA1 Message Date
Henry de Valence
f4135da5c9 Remove is_negative_decaf since ristretto uses the low bit 2017-10-30 16:34:36 -07:00
Henry de Valence
21101a7d71 Add test vectors from ristretto.sage 2017-10-30 16:34:36 -07:00
Henry de Valence
8e21c0b4f0 Start writing down some notes on the compression procedure 2017-10-30 16:34:36 -07:00
Henry de Valence
98c34adf6d Change to Ristretto test vectors. 2017-10-30 16:34:36 -07:00
Henry de Valence
7097d8f98e Add Ristretto equality 2017-10-30 16:34:36 -07:00
Henry de Valence
fafdae7a60 Prototype of Ristretto encoding 2017-10-30 16:34:36 -07:00
Henry de Valence
58a55117be Rename Decaf to Ristretto 2017-10-30 16:34:36 -07:00
Isis Lovecruft
6ed006abc1
Fix two oversized buffer allocations in scalar code. 2017-10-30 23:17:46 +00:00
Henry de Valence
aaa2315703
add failing test case from fuzzer 2017-10-30 22:25:34 +00:00
Henry de Valence
3c085d264c
Change Scalar32 and Scalar64 to not mask the high 3 bits of a Scalar.
This should not cause overflow, since this just lets the high limb have the
same bounds as the other limbs, but we should check this carefully.
2017-10-30 22:25:33 +00:00
Isis Lovecruft
6079b0269f
Revert "Revert "Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop""
This reverts commit 90b69c13ee.

Signed-off-by: Isis Lovecruft <isis@torproject.org>
2017-10-30 19:27:44 +00:00
Isis Lovecruft
90b69c13ee
Revert "Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop"
This reverts commit 804dab8924, reversing
changes made to 5d15ca77ff.

This is due to a (previously undocumented) contract on the behaviours of
(potentially unreduced mod \ell) "packed" scalars w.r.t. to the manner in which
their bytes are interpreted.

Upon documentation fixes and corresponding fixes being made on top of the
floodyberry/optimized_scalar branch, this revert will again be reverted and then
the additional changes merged (à la
file:///usr/share/doc/git/html/howto/revert-a-faulty-merge.html).

Signed-off-by: Isis Lovecruft <isis@patternsinthevoid.net>
2017-10-16 21:41:52 +00:00
Isis Lovecruft
804dab8924
Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop 2017-10-05 02:57:55 +00:00
Isis Lovecruft
5d15ca77ff
Merge branch 'feature/montgomery-arithmetic_r1' into develop 2017-10-05 02:37:27 +00:00
Isis Lovecruft
d39e47ff11
Remove comment on non-canonical encodings in CompressedMontgomeryU.decompress(). 2017-10-05 02:27:27 +00:00
Isis Lovecruft
4965238b5a
Removed now unused subtle import from montgomery module. 2017-10-05 02:23:55 +00:00
Isis Lovecruft
29f9090411
Fix two typos in docstrings for constants. 2017-10-05 02:23:34 +00:00
Isis Lovecruft
9da24d8afa
Add test for Montgomery ladder with a scalar with high bit set. 2017-10-05 02:15:28 +00:00
Isis Lovecruft
ca5b58c2b7
Clarify doc note on degenerate cases for differential addition. 2017-10-05 01:54:26 +00:00
Isis Lovecruft
7b378ada6b
Rephrase doc note on exceptional projective Montgomery points. 2017-10-05 01:46:42 +00:00
Isis Lovecruft
5e6e6c3fa8
Eliminate extra inversions in MontgomeryPoint.ct_eq(). 2017-10-05 01:32:44 +00:00
Isis Lovecruft
7e4fd5677c
Add tests and benchmark for MontgomeryPoint.ct_eq(). 2017-10-05 01:26:15 +00:00
Isis Lovecruft
d39cb275c5
Remove DecafPoint.to_edwards() method. 2017-10-05 00:56:40 +00:00
Isis Lovecruft
c08591a7d8
Improve documentation for Mongomery code. 2017-10-04 07:31:11 +00:00
Isis Lovecruft
ecef4d836e
Make FieldElement limbs private to the curve25519-dalek crate.
Limbs are no longer accessible outside of the curve25519-dalek crate.
If you were relying on this behaviour, first you probably shouldn't be
doing that, second please contact us so we can determine the best way
forward for your use case.
2017-10-01 23:36:57 +00:00
Andrew Moon
7e53499a10 optimized scalar implementations for 32/64 bit 2017-09-24 22:24:35 -05:00
Isis Lovecruft
6be10341e2
Add benchmarks for Mongomery point (de)compression and laddering. 2017-09-14 04:55:11 +00:00
Isis Lovecruft
2939d26b5c
Remove direct compression methods between points in curve models.
compress_edwards() is now named compress() and works only on points
which are in Edwards form.  Similarly, compress_montgomery() is now
also called compress(), and it only works on point already in
Mongomery form.

To switch between forms, use to_montgomery().

Conversion from Montgomery directly to Edwards is not yet implemented.

 * CHANGE the API requested in
   https://github.com/isislovecruft/curve25519-dalek/issues/47,
   hopefully for the better.
2017-09-14 04:55:11 +00:00
Isis Lovecruft
acd3826fe2 Implement Montgomery arithmetic and laddering.
* ADDs part of https://github.com/isislovecruft/curve25519-dalek/issues/47
2017-09-14 02:09:14 +00:00
Brian Smith
7ed9eb8617 Replace one multiplication with a squaring in scalar inversion.
This brings the code up to date with the 2017-09-04 version of
the source article.
2017-09-04 09:45:13 -10:00
Brian Smith
028140bb33 Reformat addition chain window building code to better show pattern.
Make the 2 digit, `_10`, the first argument to more closely match the
Haskell code in the source article. Align the code into columns to
further clarify the patterns.
2017-09-04 09:23:27 -10:00
Brian Smith
91a7c641c2 Use more efficient addition chain for scalar inversion.
Use the addition chain from
https://briansmith.org/ecc-inversion-addition-chains-01#curve25519_scalar_inversion.

In my benchmarking, this consistently runs at least 20% faster.
2017-09-03 17:00:42 -10:00
khyperia
6747133519 Optimize scalar inversion by implementing square()
This shows an 11% speedup for invert()
2017-08-21 21:35:26 -07:00
Isis Lovecruft
17290db44c
Update copyright/license headers in source files. 2017-08-15 05:09:20 +00:00
Henry de Valence
c29103d109 Rename _BASEPOINT to _BASEPOINT_POINT.
Having _BASEPOINT_TABLE and _BASEPOINT_POINT means that it's not possible to
use the slow, generic scalar mult in place of the fast, precomputed scalar
mults.
2017-08-14 00:20:18 -07:00
Henry de Valence
afecd4f438 Fixup types and publication 2017-08-13 23:57:57 -07:00
Henry de Valence
ea845b4163 Fix missing import in tests 2017-08-02 23:08:46 -07:00
Henry de Valence
3dddecb4a8 Move Montgomery code to a montgomery.rs module 2017-08-02 22:58:15 -07:00
Henry de Valence
8ad02e2f57 Move curve.rs to edwards.rs 2017-08-02 22:35:12 -07:00
Isis Lovecruft
2d15619c6c
Add DecafPoint.to_bytes(). 2017-08-01 19:30:51 +00:00
Isis Lovecruft
4d8c18fff3
Add documentation warnings on FieldElement32 and FieldElement64. 2017-08-01 02:46:14 +00:00
Isis Lovecruft
f2883028dc
Use subtle version 0.2.0.
* CLOSES PR#66 https://github.com/isislovecruft/curve25519-dalek/pull/66
2017-08-01 02:22:43 +00:00
Isis Lovecruft
7202ab8e63
Merge remote-tracking branch 'hdevalence/feature/constant-time-k-fold-scalar-mult' into develop 2017-08-01 01:51:58 +00:00
Henry de Valence
ddaf602a09 Add multiscalar_mult to Decaf. 2017-07-31 18:40:53 -07:00
Henry de Valence
d2ce1ce5dc Revert "Add size checking to multiscalar multiplication."
This reverts commit 720da348c0.

Unfortunately, iter::chain on two ExactSizeIterators does not produce an ExactSizeIterator, for reasons described here: https://github.com/rust-lang/rust/issues/34433 .
2017-07-31 18:23:26 -07:00
Henry de Valence
720da348c0 Add size checking to multiscalar multiplication. 2017-07-30 23:54:13 -07:00
Henry de Valence
2d01aa1bf7 Add fixme note on cache awareness 2017-07-30 22:26:18 -07:00
Henry de Valence
63ee9d21ae tweak code arrangement to keep comments together 2017-07-30 22:24:58 -07:00
Henry de Valence
aaefb90ed3 Rename k_fold_scalar_mult to multiscalar_mult 2017-07-30 22:16:22 -07:00
Henry de Valence
9c4046c3d9 Add constant-time k-fold scalar multiplication 2017-07-30 21:13:56 -07:00
Henry de Valence
f72de04003 Remove unneeded imports to suppress warnings 2017-07-30 16:29:37 -07:00
Henry de Valence
77103986a3 Split field arithmetic into per-implementation files
Split the field arithmetic implementations into `FieldElement`,
`FieldElement32`, and `FieldElement64`.  `FieldElement` is a type alias for one
of `FieldElement32` or `FieldElement64`, depending on feature selection.
`field.rs` contains tests and code which is generic with respect to the
implementation (e.g., inversions), while `field_32bit.rs` and `field_64bit.rs`
contain the implementation-specific code.

The implementation is not completely hidden, since `FieldElement32` and
`FieldElement64` are tuple structs whose elements are public; `pub(crate)`
doesn't seem to work for tuple structs.

Similarly, the constants file is split over multiple files, depending on the
implementation.
2017-07-30 16:25:42 -07:00
Henry de Valence
513ce26942 avoid 128-bit multiplications 2017-07-20 21:33:15 -07:00
Isis Lovecruft
4e63cbfe4c
Merge remote-tracking branch 'chain/no_std-fix' into develop 2017-06-26 20:14:38 +00:00
Tony Arcieri
d9742c2367 Switch from libcollections to liballoc (gated on an "alloc" feature)
libcollections was recently merged into liballoc:

https://github.com/rust-lang/rust/pull/42648

I went ahead and also added an "alloc" feature which no_std users can use to opt
into liballoc features (i.e. any code using Vec). This should have no effect on
anything but no_std usage. It does make it possible for people without
allocators to use curve25519-dalek if they want though. Might be nice for
"bare metal" development.

All that said, from what I can gather liballoc, while not "stable", should
likely stick around for the forseeable future.

Some backstory on the liballoc/libcollections merge here:

https://github.com/rust-lang/rust/pull/42565
2017-06-19 16:59:45 -07:00
Isis Lovecruft
4bcf8bed9d
Move subtle to its own crate. 2017-05-31 21:20:56 +00:00
Isis Lovecruft
161c0cd96d
Add a doctest for subtle::bytes_equal(). 2017-05-31 01:31:40 +00:00
Isis Lovecruft
43481a9ff6
Change the whitespace because Boats made fun of it on twitter. 2017-05-31 01:31:37 +00:00
Isis Lovecruft
4ecf6ab326
Implement constant-time selection between two things. 2017-05-31 01:29:59 +00:00
Isis Lovecruft
16904432be
Remove an unnecessary explicit return in FieldElement.to_bytes(). 2017-05-28 22:45:13 +00:00
Isis Lovecruft
674a00df5b
Some rustfmt fixes. I disagreed with all the other ones. 2017-05-28 22:42:09 +00:00
Isis Lovecruft
648f95887a
Rename subtle::bytes_equal_ct() to bytes_equal(). 2017-05-27 18:35:34 +00:00
Isis Lovecruft
1c4f283be4
Change debug_assert to assert in arrays_equal(). 2017-05-27 18:28:37 +00:00
Isis Lovecruft
60692ce891
Put math/code in a docstring in ticks. 2017-05-27 18:24:08 +00:00
Isis Lovecruft
2485472023
Remove explicit lifetime, caught by clippy. 2017-05-27 18:23:31 +00:00
Isis Lovecruft
044128dc58
Remove excessive clone() on Copy, caught by clippy. 2017-05-27 18:21:37 +00:00
Isis Lovecruft
3a664a054a
Whitespace fix in decaf module. 2017-05-27 01:20:14 +00:00
Isis Lovecruft
3decdbed0d
Make arrays_equal() work for any size &[u8], as long as sizes are equal. 2017-05-26 22:39:20 +00:00
Isis Lovecruft
0c38718346
Rename subtle::arrays_equal_ct() to subtle::arrays_equal().
It's already obvious that it's constant-time because it's in the subtle
module.
2017-05-26 22:35:45 +00:00
Isis Lovecruft
e74be0024d
Better documentation for arrays_equal_ct. 2017-05-26 21:22:31 +00:00
Isis Lovecruft
a12c2979fb
Fix the doctest for byte_is_nonzero. 2017-05-26 20:53:18 +00:00
Isis Lovecruft
c6057cb2d0
Merge remote-tracking branch 'hdevalence/feature/fast-decaf' into develop 2017-05-25 21:51:57 +00:00
Isis Lovecruft
8772e863e7
Merge remote-tracking branch 'manishearth/fuzz' into develop 2017-05-25 21:50:48 +00:00
Isis Lovecruft
00f3a20329
Merge branch 'feature/add-sub-assign' into develop 2017-05-21 23:04:06 +00:00
Henry de Valence
58982cbc2b Lower the trial number in decaf_random
The radix_51 implementation has many more debug checks, so this takes quite
long to run, and it's rude to run a fuzzer on the CI server.
2017-05-20 21:39:58 -07:00
Henry de Valence
27dbfa9536 Use Mike Hamburg's trick for Decaf compression. 2017-05-20 21:39:58 -07:00
Henry de Valence
52e51bdb16 Add constants for 1/sqrt(a-d) and 1/(a-d) 2017-05-20 21:39:58 -07:00
Henry de Valence
e4913dfc2b Batch inversions in Decaf decompression. 2017-05-20 21:39:58 -07:00
Henry de Valence
273db53cfd Benchmark Edwards decompression and compression 2017-05-20 21:39:58 -07:00
Henry de Valence
f741e50eb5 Add a test against current encodings of small multiples of the ed25519 basepoint 2017-05-20 21:39:58 -07:00
Manish Goregaokar
e076079772 Add cargo-fuzz 2017-05-19 16:44:05 -07:00
Henry de Valence
714bf3dd07 Set the number of trials back to 10,000 2017-05-19 14:23:51 -07:00
Henry de Valence
fbd8d0a605 Rewrite decaf elligator code to avoid two consecutive additions 2017-05-19 14:23:51 -07:00
Henry de Valence
b6cb7a7983 Increase number of trials for decaf elligator 2017-05-19 14:23:51 -07:00
Isis Lovecruft
e374451249
Implement {AddAssign, SubAssign} for DecafPoint. 2017-05-18 23:02:39 +00:00
Isis Lovecruft
27e4ea5181
Add a divider to separate Neg code from Add/Sub. 2017-05-18 23:01:31 +00:00
Isis Lovecruft
ed315ffcae
Implement {AddAssign, SubAssign} for ExtendedPoint. 2017-05-18 23:00:55 +00:00
Isis Lovecruft
b97868beb8
Remove unused import of ExtendedPoint in decaf::test module. 2017-05-18 03:44:42 +00:00
Isis Lovecruft
cc86091224
Remove unused import of DecafPoint in curve module. 2017-05-18 03:43:42 +00:00
Isis Lovecruft
767c99adf5
Remove unused assignment in a decaf test. 2017-05-18 03:43:15 +00:00
Isis Lovecruft
891cf76aab
Remove unused imports in curve::bench module. 2017-05-18 03:42:31 +00:00
Isis Lovecruft
0b70ab3638
Move DecafPoint * Scalar definition to decaf module. 2017-05-18 02:57:10 +00:00
Isis Lovecruft
e3adf3eea3
Merge remote-tracking branch 'hdevalence/feature/decaf_elligator_hash_to_point' into develop 2017-05-18 02:50:28 +00:00
Henry de Valence
aea15e8612 remove debugging println!s 2017-05-15 22:40:09 -07:00
Henry de Valence
69c62a8a17 Serde Scalar support 2017-05-15 22:40:09 -07:00
Henry de Valence
d3515e8cbf Add test that decompressing an invalid point with serde fails 2017-05-15 22:40:09 -07:00
Henry de Valence
69fd268aa4 Make serde an optional feature 2017-05-15 22:40:09 -07:00
Henry de Valence
7c32271346 Initial work on Serde support 2017-05-15 22:37:50 -07:00
Henry de Valence
608634a7bd Implement DecafPoint::{random, hash_from_bytes, from_hash} using Decaf-flavoured elligator 2017-05-15 21:06:26 -07:00
Isis Lovecruft
fe58e81bbc
Add missing conditional import for collection::Vec. 2017-05-14 11:16:07 +00:00
Isis Lovecruft
4a646806b8
Merge branch 'feature/scalarmult-lhs' into develop 2017-05-14 09:35:15 +00:00
Isis Lovecruft
61d07693ec
Merge remote-tracking branch 'hdevalence/feature/operator_scalar_mult_r2' into develop 2017-05-14 09:34:45 +00:00
Isis Lovecruft
ae11d4bc76
Merge remote-tracking branch 'hdevalence/feature/vartime-module' into develop 2017-05-14 09:34:14 +00:00
Isis Lovecruft
1b7b57c351
Make basepoint multiplication for precomputed tables go both ways. 2017-05-14 03:10:26 +00:00
Isis Lovecruft
7478814dfc
Implement CTAssignable for DecafPoint. 2017-05-14 02:59:54 +00:00
Isis Lovecruft
b6faf7c05e
Implement CTAssignable for ExtendedPoint. 2017-05-14 02:31:36 +00:00
Isis Lovecruft
738049619b
Also make scalar multiplication with DecafPoints go both ways. 2017-05-09 02:04:22 +00:00
Isis Lovecruft
944e8e1649
Fix and allow some non-snakecased variables in scalar tests. 2017-05-09 00:05:11 +00:00
Isis Lovecruft
4da1d795a1
Make scalar multiplication go both ways.
Being able to do `P * s`, but not `s * P`, is slightly annoying, particularly
with longer equations when it is desired to be able to glance at the maths and
see that the code is the same.

Now either syntax is allowed.
2017-05-09 00:01:48 +00:00
Isis Lovecruft
9a9959061d
Merge remote-tracking branch 'hdevalence/feature/clippy-fixes' into develop 2017-05-06 00:16:09 +00:00
Isis Lovecruft
8f4114a211
Merge remote-tracking branch 'hdevalence/feature/streamable-hash-to-scalar' into develop 2017-05-05 23:52:59 +00:00
Henry de Valence
c18627f7c2 Generalize k_fold_scalar_mult 2017-05-04 00:02:29 -07:00
Henry & Isis
c6dc9d318d Add a helper function to construct a Scalar from a u64 2017-05-03 19:32:31 -07:00
Henry de Valence
0ae0d2b72a Add function to get the basepoint from a basepoint table 2017-05-03 19:32:30 -07:00
Henry de Valence
127169c151 Remove boxes 2017-05-03 19:32:30 -07:00
Henry de Valence
0678e619cc Implement Mul for basepoint tables 2017-05-03 19:32:30 -07:00
Henry de Valence
59453d755d Implement Mul for scalar multiplication 2017-05-03 19:32:30 -07:00
Henry & Isis
7cbb8dd94e Merge branch 'feature/streamable-hash-to-scalar' into develop 2017-05-03 19:32:09 -07:00
Henry de Valence
a479b627a8 Add Decaf wrapper for k-fold vartime 2017-05-03 17:39:06 -07:00
Henry de Valence
5100ba4a07 Move variable time code into a module 2017-05-03 17:31:16 -07:00
Henry de Valence
68f74d9b22 Merge branch 'feature/vartime_k_fold_scalarmult' into feature/vartime-module 2017-05-03 16:27:43 -07:00
Henry de Valence
b05c897123 Implement operators for Scalars using multiply_add 2017-05-02 22:29:18 -07:00
Henry de Valence
91e11b6318 Change docstring to match the trait bound 2017-05-02 21:22:04 -07:00
Henry de Valence
6ea1d4dad2 Add an implementation of Scalar inversion 2017-04-28 22:59:56 -07:00
Henry de Valence
653f134bc7 Implement Mul, MulAssign, zero(), one() for UnpackedScalar 2017-04-28 22:57:17 -07:00
Henry de Valence
b5ccb42759 Rename lminus1 to l_minus_1 2017-04-28 22:54:00 -07:00
Henry de Valence
057c84abd5 Add a bits() function for scalars 2017-04-28 22:51:32 -07:00
Henry de Valence
60ad000609 Remove redundant & 2017-04-25 15:56:36 -07:00
Henry de Valence
cb656bafa7 Delete bytes_equal_less_than
This function is unused and untested.  It's also incorrect, since the loop
32..0 iterates over an empty range.  Remove it for now; if we need it later, it
still lives in the history.
2017-04-25 15:08:59 -07:00
Henry de Valence
57c96616b9 Remove unused import 2017-04-25 14:50:59 -07:00
Henry de Valence
e00cd114d7 Have radix 25.5 reduce() consume its argument 2017-04-02 23:46:01 +02:00
Henry de Valence
162dfc8331 Remove clones on Copy types 2017-04-02 23:45:34 +02:00
Henry de Valence
3705346afa Remove unnecessary returns 2017-04-02 23:39:45 +02:00
Henry de Valence
7f4b96150d Remove explicit lifetimes 2017-04-02 23:36:05 +02:00
Henry de Valence
c8e7e22ddf Remove unnecessary returns 2017-04-02 23:28:01 +02:00
Henry de Valence
b3041f2adc Remove unnecessary if statements 2017-04-02 23:27:38 +02:00
Henry de Valence
e74bf8e789 Remove unnecessary if statement 2017-04-02 23:15:26 +02:00
Henry de Valence
73e172484c Add tick marks around code items in docs 2017-04-02 23:12:18 +02:00
Henry de Valence
eca28fd3e8 Refactor Scalar::hash_from_bytes to allow streaming input to the hash. 2017-03-27 04:49:00 -07:00
Isis Lovecruft
5ebbd5dd86
Remove an XXX comment about using something better than array_ref!().
It turns out array_ref!() is probably the best way, or, at least, we're
already using it everywhere.
2017-03-17 21:42:58 +00:00
Isis Lovecruft
d549fdc8f9
Whitespace fixes. 2017-03-17 21:42:40 +00:00
Henry de Valence
2f5b9e198c Remove warnings from load3/load4 and load8 functions 2017-03-14 01:05:31 -07:00
Henry de Valence
abb1b6fef9 Add a variable-time k-fold scalar mult function. 2017-03-13 21:45:41 -07:00
Henry de Valence
57ebc9d7f9 Add an OddMultiples helper struct 2017-03-13 21:45:41 -07:00
Isis Lovecruft
6991b4264b
Merge remote-tracking branch 'hdevalence/feature/64bit-multiplication_r3' into develop 2017-03-14 04:23:11 +00:00
Isis Lovecruft
3cfaf0cf6d
Merge branch 'feature/generic-basepoint_r3' into develop 2017-03-14 03:26:51 +00:00
Henry de Valence
b8b5af24b6 fixup! Enable radix_51 on nightly 2017-03-13 20:24:59 -07:00
Isis Lovecruft
26a77cd7f3
Feature-gate box syntax on both std and basepoint_table_creation. 2017-03-14 03:21:32 +00:00
Isis Lovecruft
f6930997d2
Make #[feature(test)] depend on #[cfg(all(test, feature = "bench"))].
* FIXES Issue #38:
   https://github.com/isislovecruft/curve25519-dalek/pull/38
2017-03-14 01:59:08 +00:00
Isis Lovecruft
3882a41d27
Remove test_ prefix from tests in scalar module. 2017-03-14 01:58:39 +00:00