Commit graph

2349 commits

Author SHA1 Message Date
Henry de Valence
1e74cb3e56 Replace Scalar::from_u64 with From impls
Unfortunately, Rust selects `i32` as the type for an integer literal
when the literal has no other type constraints.  This means that someone
cannot write `Scalar::from(1)`, as Rust will choose `i32` as the type for
`1`, and we don't `impl From<i32> for Scalar`.

We could implement `From` conversions for signed integers, but since
`Scalar` operations should be constant-time by default, this would
require us to extract the sign bit of the integer and use it to
conditionally select between the positive and negative of Scalar
constructed from the value bits.  This is more expensive than the
unsigned operation, and I don't think it's what anyone really wants.

Making API consumers specify that their literals are unsigned is
slightly annoying, but better than the above alternative.

It would also be nice to change `Scalar::from_hash` to be
`impl<D: Digest<OutputSize = U64>> From<D> for Scalar`,
but this isn't currently allowed by Rust (since that `impl` "could"
conflict with the `impl From<u8>` if someone decided that `u8` should
`impl Digest`).
2018-07-19 08:39:09 -07:00
Isis Lovecruft
ce46a12d92
Implement batch verification.
The API for this isn't the greatest and I apologise for that.  Suggestions for
improvement welcome.  One thing which @hdevalence and I considered was to
change the function signature to:

    pub fn verify_batch<D, C, M, S, K>(messages: M,
                                       signatures: S,
                                       public_keys: K,
                                       csprng: &mut C) -> Result<(), SignatureError>
        where D: Digest<OutputSize = U64> + Default,
              C: Rng + CryptoRng,
              M: IntoIterator<Item = &[u8]>,
              S: IntoIterator,
              S::Item: Borrow<Signature>,
              K: IntoIterator,
              K::Item: Borrow<Signature>,

The other improvement which could be made is to implement 128-bit scalars for
the randomnesses.

 * CLOSES #27
2018-07-17 19:03:46 +00:00
Henry de Valence
b4db0afe18 Allow Options in the VartimeMultiscalarMul trait
This changes the primary function for the `VartimeMultiscalarMul` trait
to an `optional_multiscalar_mul` trait that accepts
`Option<Self::Point>` (and returns `None` if any input points are
`None`).

The existing `vartime_multiscalar_mul` is changed to be a wrapper around
this function to avoid code duplication.  This may result in an
extra copy of each input point, but that cost is probably not
significant compared to the cost of the multiscalar multiplication.

The motivation is to allow performing multiscalar multiplications with
inline decompression.  Currently, API consumers have to allocate
temporary buffers for all of their points, decompress into those
buffers, then pass (iterators over) those buffers into the multiscalar
multiplication code, which then creates new buffers for lookup tables.
2018-07-17 08:19:48 -07:00
Henry de Valence
7bbf7495b0 Change VartimeMultiscalarMul docs to use vartime_ 2018-07-16 22:54:45 -07:00
Henry de Valence
dfc9e7c0b7 fixup extendedpoint validity check 2018-07-16 22:28:22 -07:00
Henry de Valence
0c58de0367 it wouldn't be 2018-07-16 22:22:58 -07:00
Henry de Valence
f7f3f79da8 Add missing Ristretto vartime-double-base fn 2018-07-16 22:22:21 -07:00
Henry de Valence
5bb6cd42a2 we won't remove this function 2018-07-16 22:13:40 -07:00
Henry de Valence
bc731f9d79 Remove fixme notes from FieldElement code 2018-07-16 22:11:48 -07:00
Henry de Valence
8d46eacd2c Clarify wording on the nightly feature and CT
Closes #147
2018-07-16 21:56:28 -07:00
Henry de Valence
ca8c46220b Add safety notes to the README 2018-07-16 21:56:28 -07:00
Henry de Valence
e0b7af8957
Merge pull request #161 from isislovecruft/fix/160-alloc-import
Fix alloc import
2018-07-16 21:55:37 -07:00
Isis Lovecruft
46c98224f5
Remove erroneous and extraneous alloc import from edwards module.
The "alloc" feature doesn't compile otherwise.

 * FIXES #160.
2018-07-17 00:28:04 +00:00
Isis Lovecruft
74a28559c4
Add example code for Scalar.to_bytes() and Scalar.as_bytes(). 2018-07-17 00:22:34 +00:00
Isis Lovecruft
ff16e93102
Add doctest for Scalar::from_hash(). 2018-07-17 00:21:37 +00:00
Isis Lovecruft
494c4628c2
Fix a typo in the README.
This wasn't the machine I ran it on, or else it wouldn't have been a
remotely fair comparison because my laptop is a 10-year-old piece of
crap x220 running Qubes.
2018-07-16 20:45:03 +00:00
Isis Lovecruft
c024b671c0
Remove outdated paragraph about the bench deature in README. 2018-07-16 20:44:54 +00:00
Isis Lovecruft
b1ab585835
Merge branch 'master' into develop 2018-07-15 23:25:04 +00:00
Isis Lovecruft
e6f224616d
Merge branch 'release/0.7.0' 2018-07-15 23:24:51 +00:00
Isis Lovecruft
5050049a6c
Update benchmarks in README. 2018-07-15 23:22:22 +00:00
Isis Lovecruft
b32e39c801
Fix match statements on public key decompression. 2018-07-15 22:21:32 +00:00
Isis Lovecruft
6c8ae573d9
Bump ed25519-dalek version to 0.7.0. 2018-07-15 22:15:54 +00:00
Isis Lovecruft
cdebf245cc
Merge branch 'feature/cleanup-sig-code' into develop 2018-07-15 22:13:37 +00:00
Isis Lovecruft
535f4752a6
Don't run cargo bench on Travis CI servers. 2018-07-15 22:07:42 +00:00
Isis Lovecruft
2e5363c679
Cleanup verification variable declarations. 2018-07-15 22:04:55 +00:00
Isis Lovecruft
cdbc302da7
Fix a couple docstrings which mentioned r instead of R. 2018-07-15 21:51:23 +00:00
Isis Lovecruft
5c26349b6c
Derive Eq, PartialEq for Signature. 2018-07-15 21:50:20 +00:00
Isis Lovecruft
80075a0b41
Cleanup signing code to use new dalek APIs and Rust syntax. 2018-07-15 21:41:44 +00:00
Isis Lovecruft
3840cb9733
Merge remote-tracking branch 'hdevalence/verify-result' into develop 2018-07-15 21:21:14 +00:00
Henry de Valence
030eff547f Make verify return a Result.
This also simplifies the verification logic.  Because the verification check
happens in variable time, we don't need to do a constant-time eq check at the
end, so we can drop the `subtle` dependency entirely.

The `DecodingError` type becomes `SignatureError` and is also used to
signal failing verifications.
2018-07-15 13:07:58 -07:00
Isis Lovecruft
21a1e7145c
Merge branch 'feature/21-ed25519ph' into develop 2018-07-14 00:03:01 +00:00
Isis Lovecruft
f8373a9e70
Fix two more links in the README. 2018-07-13 23:57:27 +00:00
Isis Lovecruft
a1ea26ef0f
Merge remote-tracking branch 'millette/patch-1' into develop 2018-07-13 23:56:11 +00:00
Isis Lovecruft
fad39851aa
Add doctests for sign_prehashed() and verify_prehashed(). 2018-07-13 23:07:07 +00:00
Isis Lovecruft
68d2ff93f5
Implement ed25519ph from RFC8032 §5.1.
* FIXES #21: https://github.com/dalek-cryptography/ed25519-dalek/issues/21
2018-07-13 23:06:39 +00:00
Isis Lovecruft
9d58954578
Avoid compressing R twice. 2018-07-12 21:47:52 +00:00
Isis Lovecruft
b8e42e9a7e
Merge branch 'feature/criterion' into develop 2018-07-12 20:32:03 +00:00
Isis Lovecruft
bda9bba9d5
Remove ZeroRng from benchmarks. 2018-07-12 20:19:42 +00:00
Isis Lovecruft
164303eeac
Switch to using criterion for benchmarks. 2018-07-11 22:46:32 +00:00
Isis Lovecruft
a4be92b271
Update curve25519-dalek dependency to 0.18. 2018-07-11 20:36:17 +00:00
Isis Lovecruft
1dfe211aa1
Remove failure/std from the default enabled features. 2018-07-11 20:32:12 +00:00
Isis Lovecruft
61daa9dce6
Add a doctest for Scalar::from_u64(). 2018-07-06 00:12:35 +00:00
Isis Lovecruft
3854eb0fd8
Remove extra line and unneeded XXX comment from Scalar::hash_from_bytes. 2018-07-06 00:10:41 +00:00
Isis Lovecruft
37935674eb
Add doctest for Scalar::random(). 2018-07-06 00:10:21 +00:00
Henry de Valence
87a1815b40
Merge pull request #155 from isislovecruft/feature/148-cleanup-for-1.0.0-pre.0
some pre-1.0.0 cleanup
2018-07-05 14:29:01 -07:00
Henry de Valence
fa904c2c42 Add note on backend selection requirement 2018-07-05 13:39:29 -07:00
Henry de Valence
5b009a033e Remove extra line in doctest 2018-07-05 13:34:14 -07:00
Henry de Valence
0ab60b93ee Update wording on Scalar::invert to use self 2018-07-05 13:34:02 -07:00
Henry de Valence
b70b32a0c5 Change Scalar example to use the hasher functions 2018-07-05 13:27:09 -07:00
Henry de Valence
f6f20f4598
Merge pull request #152 from isislovecruft/feature/update-rand-0.5.3
Update rand dependency to 0.5.3.
2018-07-05 11:52:46 -07:00