Isis Lovecruft
3324e7d0ae
Remove impl Default for ProjectivePoint.
2018-07-20 19:51:51 +00:00
Isis Lovecruft
16f00cac16
Merge branch 'fix/166-scalar-random-nostd' into develop
2018-07-20 19:27:37 +00:00
Henry de Valence
5a58f42155
Point to https://ristretto.group since our notes live there now.
2018-07-20 12:24:28 -07:00
Henry de Valence
6eb876f3cb
Fix doctests (missed during merge)
2018-07-20 11:50:42 -07:00
Henry de Valence
bb50700d77
Merge pull request #163 from hdevalence/fallible-multiscalar-mul
...
Allow Options in the VartimeMultiscalarMul trait
2018-07-20 11:28:19 -07:00
Isis Lovecruft
6f82c30a88
Fix doctests for From<u64> for Scalar.
2018-07-20 04:45:06 +00:00
Isis Lovecruft
4d390fbd94
Merge remote-tracking branch 'hdevalence/scalar-from-impls' into develop
2018-07-20 01:09:44 +00:00
Isis Lovecruft
38aa0ee2b7
Implement Default for remaining point types.
...
* FIXES https://github.com/dalek-cryptography/curve25519-dalek/issues/154
2018-07-20 00:47:36 +00:00
Isis Lovecruft
9105d0977a
Merge remote-tracking branch 'hdevalence/more-pre-1.0-cleanups' into develop
2018-07-20 00:15:12 +00:00
Isis Lovecruft
e5d3f8f72e
Merge branch 'feature/148-cleanup-for-1.0.0-pre.0_1' into develop
2018-07-20 00:09:21 +00:00
Isis Lovecruft
73a5f4711a
Remove unnecessary extern crate sha2 from test code.
2018-07-20 00:06:31 +00:00
Isis Lovecruft
7b22fe6e87
Change the wording on the Scalar::as_bytes() docstring.
2018-07-20 00:04:25 +00:00
Isis Lovecruft
04f75767f3
Scalar::random should work with nostd.
...
* FIXES #166 .
2018-07-19 23:51:13 +00:00
Isis Lovecruft
133afff5a7
Feature gate some uses on alloc/std which aren't used in nostd.
...
* FIXES part of #166 .
2018-07-19 23:50:58 +00:00
Henry de Valence
1e74cb3e56
Replace Scalar::from_u64 with From impls
...
Unfortunately, Rust selects `i32` as the type for an integer literal
when the literal has no other type constraints. This means that someone
cannot write `Scalar::from(1)`, as Rust will choose `i32` as the type for
`1`, and we don't `impl From<i32> for Scalar`.
We could implement `From` conversions for signed integers, but since
`Scalar` operations should be constant-time by default, this would
require us to extract the sign bit of the integer and use it to
conditionally select between the positive and negative of Scalar
constructed from the value bits. This is more expensive than the
unsigned operation, and I don't think it's what anyone really wants.
Making API consumers specify that their literals are unsigned is
slightly annoying, but better than the above alternative.
It would also be nice to change `Scalar::from_hash` to be
`impl<D: Digest<OutputSize = U64>> From<D> for Scalar`,
but this isn't currently allowed by Rust (since that `impl` "could"
conflict with the `impl From<u8>` if someone decided that `u8` should
`impl Digest`).
2018-07-19 08:39:09 -07:00
Henry de Valence
b4db0afe18
Allow Options in the VartimeMultiscalarMul trait
...
This changes the primary function for the `VartimeMultiscalarMul` trait
to an `optional_multiscalar_mul` trait that accepts
`Option<Self::Point>` (and returns `None` if any input points are
`None`).
The existing `vartime_multiscalar_mul` is changed to be a wrapper around
this function to avoid code duplication. This may result in an
extra copy of each input point, but that cost is probably not
significant compared to the cost of the multiscalar multiplication.
The motivation is to allow performing multiscalar multiplications with
inline decompression. Currently, API consumers have to allocate
temporary buffers for all of their points, decompress into those
buffers, then pass (iterators over) those buffers into the multiscalar
multiplication code, which then creates new buffers for lookup tables.
2018-07-17 08:19:48 -07:00
Henry de Valence
7bbf7495b0
Change VartimeMultiscalarMul docs to use vartime_
2018-07-16 22:54:45 -07:00
Henry de Valence
dfc9e7c0b7
fixup extendedpoint validity check
2018-07-16 22:28:22 -07:00
Henry de Valence
0c58de0367
it wouldn't be
2018-07-16 22:22:58 -07:00
Henry de Valence
f7f3f79da8
Add missing Ristretto vartime-double-base fn
2018-07-16 22:22:21 -07:00
Henry de Valence
5bb6cd42a2
we won't remove this function
2018-07-16 22:13:40 -07:00
Henry de Valence
bc731f9d79
Remove fixme notes from FieldElement code
2018-07-16 22:11:48 -07:00
Isis Lovecruft
46c98224f5
Remove erroneous and extraneous alloc import from edwards module.
...
The "alloc" feature doesn't compile otherwise.
* FIXES #160 .
2018-07-17 00:28:04 +00:00
Isis Lovecruft
74a28559c4
Add example code for Scalar.to_bytes() and Scalar.as_bytes().
2018-07-17 00:22:34 +00:00
Isis Lovecruft
ff16e93102
Add doctest for Scalar::from_hash().
2018-07-17 00:21:37 +00:00
Isis Lovecruft
61daa9dce6
Add a doctest for Scalar::from_u64().
2018-07-06 00:12:35 +00:00
Isis Lovecruft
3854eb0fd8
Remove extra line and unneeded XXX comment from Scalar::hash_from_bytes.
2018-07-06 00:10:41 +00:00
Isis Lovecruft
37935674eb
Add doctest for Scalar::random().
2018-07-06 00:10:21 +00:00
Henry de Valence
5b009a033e
Remove extra line in doctest
2018-07-05 13:34:14 -07:00
Henry de Valence
0ab60b93ee
Update wording on Scalar::invert to use self
2018-07-05 13:34:02 -07:00
Henry de Valence
b70b32a0c5
Change Scalar example to use the hasher functions
2018-07-05 13:27:09 -07:00
Isis Lovecruft
f43f4f9770
Update year in copyright notices to 2018.
2018-07-05 00:30:27 +00:00
Isis Lovecruft
03154d47ec
Add an example doctest for Scalar.invert().
2018-07-05 00:30:27 +00:00
Isis Lovecruft
faf8609246
Copy the inversions of 0 warning to the invert() method.
2018-07-05 00:14:55 +00:00
Isis Lovecruft
626e070896
Document Scalar contructors with doctests.
2018-07-04 23:57:04 +00:00
Isis Lovecruft
5b263dabd0
Line wrap some docstrings in scalar.rs.
2018-07-04 21:43:13 +00:00
Isis Lovecruft
f4669c8b4d
Move the Scalar constructor documentation to the module level.
2018-07-04 21:29:36 +00:00
Isis Lovecruft
11aa71fb8d
Merge remote-tracking branch 'ebfull/sequential-montgomery-trick' into develop
2018-07-04 20:24:19 +00:00
Sean Bowe
61d6d89cd8
Fix comment describing Montgomery adjustment factor's value.
2018-07-02 10:41:45 -06:00
Sean Bowe
c4f86b231c
Only test debug assertion in batch_invert when debug assertions are enabled.
2018-07-01 15:07:04 -06:00
Sean Bowe
02af12b81a
Replace batch inversion for FieldElement with sequential variant of Montgomery's trick.
2018-07-01 15:07:04 -06:00
Sean Bowe
6294c02b52
Replace batch inversion implementation for Scalar with sequential variant of Montgomery's trick.
2018-07-01 15:07:04 -06:00
Sean Bowe
611fc40318
Add test that an empty vector field inversion returns one.
2018-06-30 16:29:02 -06:00
Sean Bowe
11b1dc142f
Add test for behavior of Scalar::batch_invert().
2018-06-30 09:49:54 -06:00
Henry de Valence
16f39c82e5
Remove yolocrypto from avx2_backend
2018-06-18 13:32:04 -07:00
Henry de Valence
d791047aac
Rewrite notes and documentation.
2018-06-18 13:22:03 -07:00
Henry de Valence
15f97221ba
Suppress extraneous warnings
2018-06-15 13:44:31 -07:00
Henry de Valence
7198719419
Document bounds on FieldElement32x4 functions
2018-06-15 13:36:38 -07:00
Henry de Valence
9f5bd8c4c0
Rename reduce32 to reduce and have it return its result.
...
This means that all FieldElement32x4 operations return values, vs mutating interior state.
2018-06-14 15:54:36 -07:00
Henry de Valence
bab1ebbeb8
Replace scale_by_curve_constants by a Mul<(u32,u32,u32,u32)> impl
2018-06-14 15:42:20 -07:00
Henry de Valence
6ef9e9dcfb
Make publicity a little more consistent
2018-06-14 15:22:16 -07:00
Henry de Valence
97292fef91
Move packing functions to top of the module
2018-06-14 15:21:51 -07:00
Henry de Valence
4dc219910a
Move blend_lanes into the blend function
2018-06-14 15:13:53 -07:00
Henry de Valence
64b1b481ba
Rewrite diff_sum in terms of shuffle, blend, negate
2018-06-14 14:59:11 -07:00
Henry de Valence
fe51adad31
Don't expose u32x8 unpacking functions
2018-06-14 14:32:13 -07:00
Henry de Valence
c46ec9638c
Add documentation
2018-06-14 14:23:24 -07:00
Henry de Valence
eea3eadf5b
Replace special-case swap_{AB,CD} methods with general shuffles
2018-06-14 14:23:24 -07:00
Henry de Valence
02296fafb5
Delete unused constant
2018-06-14 14:23:24 -07:00
Henry de Valence
25d9f3f6ca
Eliminate vector constants from edwards module
2018-06-14 14:23:24 -07:00
Henry de Valence
cc8728b2a6
Add comment about rustc-constant-info to blend function
2018-06-14 14:23:24 -07:00
Henry de Valence
28f10bc183
Change Lanes::ALL to Lanes::ABCD for consistency
2018-06-14 14:23:24 -07:00
Henry de Valence
794ed5c8e3
Rewrite the doubling horrorshow
2018-06-14 14:23:24 -07:00
Henry de Valence
30a2b01c05
Add more selectors to the Lanes enum
2018-06-14 14:19:46 -07:00
Henry de Valence
64cb999866
Make platform-vector lanes constants private
2018-06-14 14:19:26 -07:00
Henry de Valence
00d8b6ea4f
Change negate_D, negate_D_lazy to impl Neg, negate_lazy
2018-06-14 14:17:36 -07:00
Henry de Valence
14ce6d3da6
Add a shuffling abstraction for FieldElement32x4
2018-06-14 14:10:37 -07:00
Henry de Valence
c8dc2a6418
Implement addition for FieldElement32x4
2018-06-14 14:10:32 -07:00
Henry de Valence
bd1e3c5f3e
some rustfmt changes
2018-06-14 14:05:52 -07:00
Isis Lovecruft
9a89a217f8
Merge remote-tracking branch 'dalek/multiscalar-trait-without-precomputation_r1' into develop
2018-05-15 20:23:05 +00:00
Henry de Valence
bbb64312f7
Use rand 0.5
...
Requires `0.5.0-pre.2`, which adds `impl CryptoRng for OsRng`.
2018-05-15 12:30:28 -07:00
Henry de Valence
bab642c5af
Add doc comments
2018-05-15 11:33:38 -07:00
Henry de Valence
2eed24109e
Move double-base scmul to the EdwardsPoint type
2018-05-15 11:33:38 -07:00
Henry de Valence
149c5004e8
Use multiscalar traits for the backend implementations.
2018-05-15 11:33:38 -07:00
Henry de Valence
e3bf9b0213
Add MultiscalarMul and VartimeMultiscalarMul traits.
...
These traits have the same interface, but with different names, so that it's
not possible to use them interchangeably. (Constant-time and variable-time
routines should not be used interchangeably).
This commit changes the external API to use these traits, replacing
```
edwards::multiscalar_mul
edwards::vartime::multiscalar_mul
```
with
```
EdwardsPoint::multiscalar_mul (as an impl)
EdwardsPoint::vartime_multiscalar_mul (as an impl)
```
and similarly for Ristretto.
Refactoring the backend is for a later commit.
Multiscalar multiplication with precomputation is for a later commit.
The `edwards::vartime` module is retained since it's used for
`vartime_double_base_scalar_mul`.
It should be subsumed into the precomputation API in a later commit.
2018-05-15 11:33:38 -07:00
Henry de Valence
34c43c20a9
Rework backend selection code.
...
Each backend can now be selected by an individual feature:
- `u32_backend` for `backend::u32`;
- `u64_backend` for `backend::u64`;
- `avx2_backend` for `backend::avx2`;
The `u64_backend` is selected by default, since most people use X64 and we have
no way to select based on target (see discussion in #126 ). However, these
changes mean that it is possible to select the backend explicitly, and if we
had the ability to select target-default features, we could do so easily.
2018-05-14 17:43:54 -07:00
Henry de Valence
9b6c932635
Rename 'precomputed_tables' to the more accurate 'stage2_build'
2018-05-14 15:41:45 -07:00
Henry de Valence
62bb6b79a1
Merge pull request #134 from Mandragorian/feature-scalar-traits
...
Implement Product and Sum traits
2018-05-03 13:56:45 -07:00
mandragore
96d2fe4905
Implement Sum trait for RistrettoPoint
...
Closes #131 .
2018-05-03 03:42:37 +03:00
mandragore
aff69a58a4
Implement Sum trait for EdwardsPoint
2018-05-03 03:42:37 +03:00
Henry de Valence
185bbd3da8
Fix build on recent nightlies (was broken due to type inference failure)
2018-05-02 17:30:10 -07:00
mandragore
01fd44ffd2
Remove trailing whitespaces
2018-05-02 23:53:52 +03:00
mandragore
3ab087ea7f
Implement Sum trait for Scalar
2018-05-02 23:53:49 +03:00
mandragore
afffe962f9
Implement Product trait for Scalar
2018-05-02 23:53:24 +03:00
Henry de Valence
285e57f2ff
Merge pull request #128 from hdevalence/feature/avx2-docs
...
Update docs for AVX2 backend
2018-04-08 17:16:05 -07:00
Henry de Valence
67ba201835
Update AVX2 documentation
2018-04-08 16:59:57 -07:00
Henry de Valence
6bb2c02a1f
Merge pull request #127 from hdevalence/feature/generalize-naf
...
Generalize NAF code to wider window sizes.
2018-04-08 16:39:45 -07:00
Henry de Valence
1464c4101d
change LSB to least significant bit
2018-04-08 16:29:54 -07:00
Henry de Valence
9fc5602ce7
Split AVX2 docs into markdown file
2018-04-08 15:15:23 -07:00
Henry de Valence
68bbd1bd03
Document algorithm for NAFs
2018-04-06 12:11:59 -07:00
Henry de Valence
6b768c2a1a
Change AVX2 backend to use width-8 tables
2018-04-05 16:20:47 -07:00
Henry de Valence
ff787c2f12
Clarify Ristretto / Decaf relation in user docs
2018-04-05 14:52:00 -07:00
Henry de Valence
c99bd62b25
Add example to RistrettoBasepointTable
2018-04-05 14:52:00 -07:00
Henry de Valence
46048e451b
Clarify wording on canonical scalars
2018-04-05 14:52:00 -07:00
Henry de Valence
35e1b07e72
Clarify abstraction layers in Ristretto intro
2018-04-05 14:52:00 -07:00
Henry de Valence
c841998b07
Extract Ristretto notes into a markdown file
2018-04-05 14:52:00 -07:00
Henry de Valence
ef0dae241a
Add an explanatory note that's built on stable
...
When building on stable, the README.md is not included in the documentation,
leaving a bare entry. This adds a warning stub, pointing people to use nightly
rust.
2018-04-05 14:52:00 -07:00
Henry & Isis
62d43752df
Add NafLookupTable8 and use for pre-computed basepoint table generation.
2018-04-05 05:12:13 +00:00
Henry & Isis
753a0292de
Rename OddLookupTable to NafLookupTable5.
...
An OddLookupTable corresponds to a non-adjacent form of width 5.
2018-04-05 04:48:28 +00:00
Henry de Valence
7e0ddf6b98
Rewrite NAF code to work with more window sizes
...
Change Scalar::non_adjacent_form() to take a width parameter.
This rewrite also makes it faster, although it's probably a ways off
from optimal. I don't know how much it matters.
TODO: write up description of why this computes the same thing.
Thanks to @oleganza for pointing out an error reading bits across words
in an earlier version of this code.
2018-04-04 21:13:09 -07:00
Henry de Valence
5f136fbd0c
Remove some warnings.
...
Not all of the warnings are removed, since although this code works, it still
needs a significant amount of cleanup, editing, and polish.
2018-04-04 10:25:42 -07:00