Henry de Valence
d86bf15781
Merge pull request #257 from dalek-cryptography/use_upstream_intrinsics
...
Use upstream intrinsics
2019-08-06 17:24:02 -07:00
Henry de Valence
cfa09d859f
Use upstream IFMA intrinsics now that they exist.
2019-08-06 17:14:31 -07:00
Henry de Valence
4bbcc28cdc
Merge pull request #275 from Pratyush/fix-docs-link-on-avx2
...
Fix link to AVX2 docs
2019-08-06 17:08:30 -07:00
Pratyush Mishra
912fe4794f
Fix link to AVX2 and IFMA docs
2019-08-06 16:53:54 -07:00
Henry de Valence
4bc2ec0082
Merge pull request #276 from dalek-cryptography/quarkslab
...
Fix issues found in Quarkslab audit
2019-08-06 16:08:23 -07:00
Henry de Valence
68b71578af
Merge pull request #274 from 3for/comment-fix
...
`curve_models` Comment fix
2019-08-06 16:07:13 -07:00
Henry de Valence
a480844992
Tighten a too-permissive debug_assert in NafLookupTable8.
...
This issue was found by Laurent Grémy & Nicolas Surbayrole of Quarkslab.
2019-08-06 15:21:06 -07:00
Henry de Valence
90baabe50b
Ensure Scalar Add and Sub produce canonical results.
...
Closes #238 .
This issue was discovered independently by both Jack "str4d" Grigg
(issue #238 ), who noted that reduction was not performed on addition, and
Laurent Grémy & Nicolas Surbayrole of Quarkslab, who noted that it was possible
to cause an overflow and compute incorrect results.
2019-08-06 15:20:19 -07:00
Jack Grigg
a3246d82e5
Tests showing that scalar addition and subtraction don't reduce mod l
2019-08-06 15:18:46 -07:00
root
ccaf86ea86
curve_models link in comment mismatch
2019-08-06 16:40:47 +08:00
Henry de Valence
542a7b54a3
Merge pull request #273 from dalek-cryptography/fix-width-7-naf
...
Add a missing wrapping_sub in NAF computation.
2019-08-05 19:24:46 -07:00
Henry de Valence
01d9e904e1
Add a missing wrapping_sub in NAF computation.
...
Found by @3for; this only affected width-7 NAF computations, which were never
used in the source tree (only width 5, optimal for dynamic cases, and 8, better
for static cases).
Closes #272
2019-08-05 15:56:56 -07:00
root
2a46cd3b20
add non-zero assert in field batch_invert
2019-08-01 15:02:15 +08:00
Henry de Valence
a174911c2b
Merge branch 'master' into develop
2019-07-31 15:27:34 -07:00
Henry de Valence
c6d8bfb48b
Merge branch 'release/1.2.2'
2019-07-31 15:26:58 -07:00
Henry de Valence
e6d580b0cf
Bump version to 1.2.2
2019-07-31 15:25:22 -07:00
Henry de Valence
cbbdbfb67f
Merge pull request #269 from dalek-cryptography/update-doc-include-paths
...
Update doc(include) paths.
2019-07-31 15:19:25 -07:00
Henry de Valence
5c18bfb6a7
Update doc(include) paths.
...
Since https://github.com/rust-lang/rust/pull/60938 the path root changed and
these new paths are required to compile on nightly.
Closes #268 .
2019-07-31 14:54:24 -07:00
Henry de Valence
09e2615589
Merge pull request #267 from dalek-cryptography/add-crypto-tag
...
'crypto' means 'cryptography'
2019-07-30 12:54:28 -07:00
Henry de Valence
78d9804bf9
'crypto' means 'cryptography'
2019-07-30 12:43:56 -07:00
Henry de Valence
526ce175d9
Merge pull request #266 from dsprenkels/patch-1
...
Fix a typo in AVX2
2019-07-22 10:05:55 -07:00
Daan Sprenkels
e4c086ab59
Fix a typo in AVX2
...
Last two (least significant) limbs should be `z8`, `z9`. Were probably
copy-paste typos.
2019-07-22 14:17:23 +02:00
Henry de Valence
8c88e681f4
Merge branch 'master' into develop
2019-06-06 15:43:32 -07:00
Henry de Valence
a659b92305
Merge branch 'release/1.2.1'
2019-06-06 15:43:21 -07:00
Henry de Valence
45b316d26b
Update version to 1.2.1
2019-06-06 15:39:59 -07:00
Henry de Valence
3ed8056484
Merge pull request #259 from dalek-cryptography/pippenger-bugfix
...
Pippenger bugfix
2019-06-06 15:35:15 -07:00
Henry de Valence
e17c98a391
Ensure NAF works on manually-constructed extremal values.
...
The NAF computation can generate a 1 in the last digit (only) when s = 2^255-1,
so someone who manually constructed the value s = 2^255-1 and fed it into a NAF-using
computation could generate an incorrect result. Some version of this bug has
been present from the beginning of the library, but it has no security content,
because the NAF computations are not applied to secret data, and the error
occurs only on one value which is not constructed by any client caller.
2019-06-05 23:18:43 -07:00
Henry de Valence
389d2bc9e2
Ensure Pippenger works on manually-constructed extremal values.
...
When using Scalar::from_bits to manually create unreduced Scalars (e.g.,
X/Ed25519 keys with specified bit patterns), it's possible to construct Scalar
values that range up to 2^255-1. These shouldn't ever end up in a vartime
multiscalar mul call anyways, because it doesn't handle secret data, but it is
technically allowed by the type system and should be handled. When w=8, these
can generate terminal carries that can't be folded into the last digit, but
this can be handled by folding them into an extra digit instead.
2019-06-05 23:03:07 -07:00
Henry de Valence
5f1d73bca0
Fix a negate-with-overflow edgecase by widening before computation.
...
This fixes a bug in the Pippenger implementation reported by Fernando Krell and
diagnosed by Oleg Andreev. The problem is that at the largest problem sizes
(using w=8), the signed digits fill the value range of an i8, and so doing
computation on them to calculate the bucket index can hit an overflow.
This was not caught in CI because the test suite didn't check all problem
sizes; tests for these sizes which expose this bug were added in the previous
commit.
2019-06-05 20:59:07 -07:00
Henry de Valence
6fe93564cd
Add a more comprehensive random multiscalar test.
...
This exercises the constant- and variable- time code at large sizes, to hit
every path of Straus/Pippenger.
2019-06-05 20:54:00 -07:00
Henry de Valence
c159bd4b07
Merge branch 'master' into develop
2019-06-04 15:28:12 -07:00
Henry de Valence
22ce43f971
Merge branch 'release/1.2.0'
2019-06-04 15:28:02 -07:00
Henry de Valence
62fbd6ab63
Update version to 1.2.0
2019-06-04 15:27:12 -07:00
Henry de Valence
c084def3a3
Merge pull request #249 from oleganza/oleg/pippenger2
...
Pippenger multiscalar multiplication algorithm
2019-06-04 15:13:41 -07:00
Henry de Valence
19dcd62053
Add reference to 2012/549
2019-06-04 13:41:43 -07:00
Henry de Valence
5921d6d2ac
Replace std::iter with core::iter
2019-06-04 13:36:07 -07:00
isis agora lovecruft
33f21a9f34
Merge pull request #255 from xoloki/no-std-optional-serde
...
Turn off default serde features but keep it as an optional dependency
2019-06-04 19:39:30 +00:00
Joey Yandle
fd69503a40
turn off default serde features but keep it optional
2019-06-03 15:29:08 -07:00
Henry de Valence
baaeed23fc
Merge pull request #251 from fabric-and-ink/quench-warning
...
Quench snake case warning
2019-05-26 20:35:27 -07:00
Fabian Drinck
29dca772a9
Quench snake case warning
2019-05-26 13:03:40 +02:00
Oleg Andreev
eb82a9d8b6
Update src/backend/serial/scalar_mul/pippenger.rs
...
Co-Authored-By: Henry de Valence <hdevalence@hdevalence.ca>
2019-05-24 18:00:34 -05:00
Oleg Andreev
9836d6622c
cleaner name per Henry’s suggestion
2019-05-24 12:18:10 -07:00
Oleg Andreev
ca2926ac89
use one buffer instead of two
2019-05-22 11:48:30 -07:00
Henry de Valence
dfcac0d8e2
rustfmt and copyright fixes
2019-05-22 11:38:52 -07:00
Oleg Andreev
7fba2a1bcc
avoid unnecessary allocation
2019-05-22 11:14:26 -07:00
Oleg Andreev
df745e98a2
oops - forgot to switch on pippenger
2019-05-21 14:10:56 -07:00
Oleg Andreev
33b41ac10d
fix type conversions
2019-05-21 13:48:29 -07:00
Oleg Andreev
42648aa460
cgs
2019-05-21 13:32:50 -07:00
Oleg Andreev
b52c2053c1
new pippenger radix 6/7/8 implementation
2019-05-21 12:35:58 -07:00
Henry de Valence
e726147af8
Merge pull request #245 from dalek-cryptography/optimize-variable-base
...
Save 2.5% on variable-base scmul by squeezing some multiplications.
2019-05-21 08:52:53 -07:00