Commit graph

513 commits

Author SHA1 Message Date
Henry de Valence
844da9712b Fix AVX2 docs formatting, remove obsolete AVX512 note 2018-03-22 12:13:39 -07:00
Henry de Valence
d67e895619 Merge branch 'feature/rename-to-multiscalar-mul' into develop 2018-03-22 12:08:49 -07:00
Henry de Valence
132b1a9d77 Merge branch 'feature/ristretto-uniform-hash' into develop 2018-03-22 11:44:52 -07:00
Henry de Valence
2e73b2bc20 Use scalar_mul instead of scalar_mult 2018-03-22 11:40:13 -07:00
Henry de Valence
70eee5208a Rename double_scalar_mult_basepoint to double_scalar_mul_basepoint for consistency 2018-03-22 11:39:47 -07:00
Henry de Valence
296cd16463 Rename mult_by_cofactor to mul_by_cofactor for consistency 2018-03-22 11:36:34 -07:00
Henry de Valence
8de3d7576a Rename mult_by_pow_2 to mul_by_pow_2 for consistency 2018-03-22 11:35:42 -07:00
Henry de Valence
b48d568f47 Add debug_assert that Scalar::batch_invert inputs are nonzero 2018-03-22 11:32:00 -07:00
Henry de Valence
0e7d872ad0 Add batch inversion for Scalars 2018-03-22 11:32:00 -07:00
Henry de Valence
792ac0775e Change to the updated subtle API. 2018-03-22 11:13:26 -07:00
Henry de Valence
7f39656b4a Apply the Elligator map twice to ensure a uniform distribution
As noted in the Decaf paper, mapping twice and adding the results ensures a
uniform distribution over the group.  This changes our random point and
hash-to-point functions to do this, matching the Sage script.
2018-03-19 15:37:38 -07:00
Henry de Valence
c20e09f6cc Rename multiscalar_mult->multiscalar_mul to match Mul traits 2018-03-19 14:28:21 -07:00
Henry de Valence
c5fcc6602d Fix build for AVX2 backend.
A missing import of the Borrow trait caused the build to break with the
"yolocrypto" feature enabled; this was't caught by CI because the CI machine
that Travis used didn't have AVX2, so the code was never built.

This commit adds the missing import and changes `std` to `core` so that the
AVX2 backend builds with no_std, but this isn't tested and is, actually,
"yolocrypto".
2018-03-19 11:15:52 -07:00
Isis Lovecruft
de90f16994
Merge branch 'feature/dalek-rs-assets' into develop 2018-03-12 19:50:56 +00:00
Henry de Valence
a271ff907d add link to curve models docs 2018-02-22 15:37:16 -08:00
Henry de Valence
3969d80c89 Add links to dalek.rs 2018-02-21 11:11:17 -08:00
Henry de Valence
2b42966bb4 Load resources from our own domain 2018-02-21 11:03:18 -08:00
Henry de Valence
0f185d3e28 Generalize trait bounds on multiscalar multiplication.
This allows iterators returning either &Scalars or Scalars, so that it's
possible to use map() and friends to adjust scalars as they're being fed into
the multiscalar multiplication.
2018-02-20 18:31:23 -08:00
Henry de Valence
4a4ec74100 Add example to edwards::multiscalar_mult 2018-02-20 17:32:50 -08:00
Henry de Valence
6748dddb96 Simplify and optimize Montgomery code.
The `MontgomeryPoint` struct is now a point on the Kummer line of the Montgomery curve.

The `ProjectivePoint` struct is made private, since its only purpose is
internal to the Montgomery ladder.

The Montgomery ladder takes affine input, making it faster, and produces affine output.

The Edwards-Montgomery correspondence is simplified.
2018-02-05 10:40:25 -08:00
Isis Lovecruft
b5e664ab16
Add RISTRETTO_BASEPOINT_COMPRESSED constant. 2018-02-02 02:33:51 +00:00
Isis Lovecruft
23bc6ff848
Change README and docs sidebar image to transparent version. 2018-01-31 02:26:28 +00:00
Isis Lovecruft
cd112afff5
Whitespace EOL fixes. 2018-01-31 02:19:53 +00:00
Henry de Valence
9698435e38 Add note on point validity and "make illegal states unrepresentable".
Remove references to Montgomery conversions, as a prelude to putting the
Montgomery/Edwards conversion docs in the Montgomery module.
2018-01-30 12:31:53 -08:00
Henry de Valence
2d5dc5079f Add type to X25519 basepoint doc 2018-01-29 14:39:37 -08:00
Henry de Valence
1d480a8a71 Rename X25519 basepoint to X25519_BASEPOINT_MONTGOMERY 2018-01-29 14:36:45 -08:00
Henry de Valence
ae46ecd445 Rename BASE_CMPRSSD to ED25519_BASEPOINT_COMPRESSED. 2018-01-29 12:38:58 -08:00
Henry de Valence
06994e8139 Tidy docs for public constants in backends 2018-01-29 12:38:58 -08:00
Henry de Valence
739755cb1c Fix up constants docstrings 2018-01-29 12:38:58 -08:00
Henry de Valence
d3a8ee0d7b Remove BASEPOINT_ORDER_MINUS_* constants
These were originally added in 32da4c7d50
to implement Scalar negation in terms of multiply-add.

But we have a full implementation of scalar arithmetic now, so it's not
necessary to keep the constants around.
2018-01-29 12:38:58 -08:00
Henry de Valence
3b5a8f84a8 Add an is_torsion_free function and document cofactor-related functions. 2018-01-26 16:07:52 -08:00
Henry de Valence
3d2cf74261 Add docs on Edwards points 2018-01-26 15:36:06 -08:00
Henry de Valence
d4d9d86d72 Fix up coffee/ristretto reference 2018-01-26 15:35:51 -08:00
Henry de Valence
12e658401c Reword Ristretto intro 2018-01-26 14:53:31 -08:00
Henry de Valence
52904b5c3e Use math for multiscalar docs 2018-01-26 13:39:11 -08:00
Henry de Valence
4b47087b40 Refactor Ristretto notes into doc and doc-internal sections. 2018-01-26 13:35:30 -08:00
Henry de Valence
576e27982f Tweak module header names 2018-01-26 10:44:48 -08:00
Henry de Valence
fbd84af767 Ristretto API docs fixups 2018-01-25 17:34:57 -08:00
Henry de Valence
d04d3719a5 Add logo to sidebar 2018-01-25 17:34:20 -08:00
Henry de Valence
99921de6f3 Use README.md for the crate docs, and rewrite it. 2018-01-25 16:26:05 -08:00
Henry de Valence
ce45cfec8e This isn't true after renaming the struct 2018-01-25 12:16:11 -08:00
Henry de Valence
3f7923b628 Keep the AVX2 point type named as ExtendedPoint. 2018-01-25 12:00:40 -08:00
Isis Lovecruft
4f37785f0e
Rename ExtendedPoint to EdwardsPoint. 2018-01-25 02:56:38 +00:00
Isis Lovecruft
9cb915126e
Merge remote-tracking branch 'dalek/feature/borrow-operators' into develop 2018-01-25 02:00:52 +00:00
Henry de Valence
86fd06db00 s/eps/epsilon/ for clarity 2018-01-24 12:42:57 -08:00
Henry de Valence
52d600db95 Implement public-facing ops traits on all combos of &T/T
The public-facing types with arithmetic operations are:

- `Scalar`s
- `ExtendedPoint`s
- `RistrettoPoint`s

For these types we define operators with all combinations of borrowed and
non-borrowed inputs, to avoid forcing API consumers to write extra ampersands.
Since all of the operations involved with these types are expensive relative to
the cost of an unnecessary copy, this isn't a big deal.

The `MontgomeryPoint` struct isn't included in the above because it's only
useful for scalar multiplication.

This commit is based on work by @UnlawfulMonad.
2018-01-24 11:05:06 -08:00
Henry de Valence
0e9b8e0a6e Refactor multiply implementation to eliminate reduce() call 2018-01-19 18:23:41 -08:00
Henry de Valence
ec50ec96f7 Use parallel carry-ins and carry-outs in FieldElement64::reduce() 2018-01-19 17:50:48 -08:00
Henry de Valence
d8d235fb48 Move pow2k into the backends and use it to implement square() 2018-01-19 17:50:48 -08:00
Henry de Valence
1f821d34a5 Feature-gate batch inversion and compression on alloc 2018-01-19 17:22:28 -08:00