Commit graph

337 commits

Author SHA1 Message Date
Henry de Valence
b6bfc79cd1 Fix up Elligator tests to match ristretto.sage 2017-10-30 16:34:36 -07:00
Henry de Valence
f4135da5c9 Remove is_negative_decaf since ristretto uses the low bit 2017-10-30 16:34:36 -07:00
Henry de Valence
21101a7d71 Add test vectors from ristretto.sage 2017-10-30 16:34:36 -07:00
Henry de Valence
8e21c0b4f0 Start writing down some notes on the compression procedure 2017-10-30 16:34:36 -07:00
Henry de Valence
98c34adf6d Change to Ristretto test vectors. 2017-10-30 16:34:36 -07:00
Henry de Valence
7097d8f98e Add Ristretto equality 2017-10-30 16:34:36 -07:00
Henry de Valence
fafdae7a60 Prototype of Ristretto encoding 2017-10-30 16:34:36 -07:00
Henry de Valence
58a55117be Rename Decaf to Ristretto 2017-10-30 16:34:36 -07:00
Isis Lovecruft
90b69c13ee
Revert "Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop"
This reverts commit 804dab8924, reversing
changes made to 5d15ca77ff.

This is due to a (previously undocumented) contract on the behaviours of
(potentially unreduced mod \ell) "packed" scalars w.r.t. to the manner in which
their bytes are interpreted.

Upon documentation fixes and corresponding fixes being made on top of the
floodyberry/optimized_scalar branch, this revert will again be reverted and then
the additional changes merged (à la
file:///usr/share/doc/git/html/howto/revert-a-faulty-merge.html).

Signed-off-by: Isis Lovecruft <isis@patternsinthevoid.net>
2017-10-16 21:41:52 +00:00
Isis Lovecruft
804dab8924
Merge remote-tracking branch 'floodyberry/optimized_scalar' into develop 2017-10-05 02:57:55 +00:00
Isis Lovecruft
5d15ca77ff
Merge branch 'feature/montgomery-arithmetic_r1' into develop 2017-10-05 02:37:27 +00:00
Isis Lovecruft
d39e47ff11
Remove comment on non-canonical encodings in CompressedMontgomeryU.decompress(). 2017-10-05 02:27:27 +00:00
Isis Lovecruft
4965238b5a
Removed now unused subtle import from montgomery module. 2017-10-05 02:23:55 +00:00
Isis Lovecruft
29f9090411
Fix two typos in docstrings for constants. 2017-10-05 02:23:34 +00:00
Isis Lovecruft
9da24d8afa
Add test for Montgomery ladder with a scalar with high bit set. 2017-10-05 02:15:28 +00:00
Isis Lovecruft
ca5b58c2b7
Clarify doc note on degenerate cases for differential addition. 2017-10-05 01:54:26 +00:00
Isis Lovecruft
7b378ada6b
Rephrase doc note on exceptional projective Montgomery points. 2017-10-05 01:46:42 +00:00
Isis Lovecruft
5e6e6c3fa8
Eliminate extra inversions in MontgomeryPoint.ct_eq(). 2017-10-05 01:32:44 +00:00
Isis Lovecruft
7e4fd5677c
Add tests and benchmark for MontgomeryPoint.ct_eq(). 2017-10-05 01:26:15 +00:00
Isis Lovecruft
d39cb275c5
Remove DecafPoint.to_edwards() method. 2017-10-05 00:56:40 +00:00
Isis Lovecruft
c08591a7d8
Improve documentation for Mongomery code. 2017-10-04 07:31:11 +00:00
Isis Lovecruft
ecef4d836e
Make FieldElement limbs private to the curve25519-dalek crate.
Limbs are no longer accessible outside of the curve25519-dalek crate.
If you were relying on this behaviour, first you probably shouldn't be
doing that, second please contact us so we can determine the best way
forward for your use case.
2017-10-01 23:36:57 +00:00
Andrew Moon
7e53499a10 optimized scalar implementations for 32/64 bit 2017-09-24 22:24:35 -05:00
Isis Lovecruft
6be10341e2
Add benchmarks for Mongomery point (de)compression and laddering. 2017-09-14 04:55:11 +00:00
Isis Lovecruft
2939d26b5c
Remove direct compression methods between points in curve models.
compress_edwards() is now named compress() and works only on points
which are in Edwards form.  Similarly, compress_montgomery() is now
also called compress(), and it only works on point already in
Mongomery form.

To switch between forms, use to_montgomery().

Conversion from Montgomery directly to Edwards is not yet implemented.

 * CHANGE the API requested in
   https://github.com/isislovecruft/curve25519-dalek/issues/47,
   hopefully for the better.
2017-09-14 04:55:11 +00:00
Isis Lovecruft
acd3826fe2 Implement Montgomery arithmetic and laddering.
* ADDs part of https://github.com/isislovecruft/curve25519-dalek/issues/47
2017-09-14 02:09:14 +00:00
Brian Smith
7ed9eb8617 Replace one multiplication with a squaring in scalar inversion.
This brings the code up to date with the 2017-09-04 version of
the source article.
2017-09-04 09:45:13 -10:00
Brian Smith
028140bb33 Reformat addition chain window building code to better show pattern.
Make the 2 digit, `_10`, the first argument to more closely match the
Haskell code in the source article. Align the code into columns to
further clarify the patterns.
2017-09-04 09:23:27 -10:00
Brian Smith
91a7c641c2 Use more efficient addition chain for scalar inversion.
Use the addition chain from
https://briansmith.org/ecc-inversion-addition-chains-01#curve25519_scalar_inversion.

In my benchmarking, this consistently runs at least 20% faster.
2017-09-03 17:00:42 -10:00
khyperia
6747133519 Optimize scalar inversion by implementing square()
This shows an 11% speedup for invert()
2017-08-21 21:35:26 -07:00
Isis Lovecruft
17290db44c
Update copyright/license headers in source files. 2017-08-15 05:09:20 +00:00
Henry de Valence
c29103d109 Rename _BASEPOINT to _BASEPOINT_POINT.
Having _BASEPOINT_TABLE and _BASEPOINT_POINT means that it's not possible to
use the slow, generic scalar mult in place of the fast, precomputed scalar
mults.
2017-08-14 00:20:18 -07:00
Henry de Valence
afecd4f438 Fixup types and publication 2017-08-13 23:57:57 -07:00
Henry de Valence
ea845b4163 Fix missing import in tests 2017-08-02 23:08:46 -07:00
Henry de Valence
3dddecb4a8 Move Montgomery code to a montgomery.rs module 2017-08-02 22:58:15 -07:00
Henry de Valence
8ad02e2f57 Move curve.rs to edwards.rs 2017-08-02 22:35:12 -07:00
Isis Lovecruft
2d15619c6c
Add DecafPoint.to_bytes(). 2017-08-01 19:30:51 +00:00
Isis Lovecruft
4d8c18fff3
Add documentation warnings on FieldElement32 and FieldElement64. 2017-08-01 02:46:14 +00:00
Isis Lovecruft
f2883028dc
Use subtle version 0.2.0.
* CLOSES PR#66 https://github.com/isislovecruft/curve25519-dalek/pull/66
2017-08-01 02:22:43 +00:00
Isis Lovecruft
7202ab8e63
Merge remote-tracking branch 'hdevalence/feature/constant-time-k-fold-scalar-mult' into develop 2017-08-01 01:51:58 +00:00
Henry de Valence
ddaf602a09 Add multiscalar_mult to Decaf. 2017-07-31 18:40:53 -07:00
Henry de Valence
d2ce1ce5dc Revert "Add size checking to multiscalar multiplication."
This reverts commit 720da348c0.

Unfortunately, iter::chain on two ExactSizeIterators does not produce an ExactSizeIterator, for reasons described here: https://github.com/rust-lang/rust/issues/34433 .
2017-07-31 18:23:26 -07:00
Henry de Valence
720da348c0 Add size checking to multiscalar multiplication. 2017-07-30 23:54:13 -07:00
Henry de Valence
2d01aa1bf7 Add fixme note on cache awareness 2017-07-30 22:26:18 -07:00
Henry de Valence
63ee9d21ae tweak code arrangement to keep comments together 2017-07-30 22:24:58 -07:00
Henry de Valence
aaefb90ed3 Rename k_fold_scalar_mult to multiscalar_mult 2017-07-30 22:16:22 -07:00
Henry de Valence
9c4046c3d9 Add constant-time k-fold scalar multiplication 2017-07-30 21:13:56 -07:00
Henry de Valence
f72de04003 Remove unneeded imports to suppress warnings 2017-07-30 16:29:37 -07:00
Henry de Valence
77103986a3 Split field arithmetic into per-implementation files
Split the field arithmetic implementations into `FieldElement`,
`FieldElement32`, and `FieldElement64`.  `FieldElement` is a type alias for one
of `FieldElement32` or `FieldElement64`, depending on feature selection.
`field.rs` contains tests and code which is generic with respect to the
implementation (e.g., inversions), while `field_32bit.rs` and `field_64bit.rs`
contain the implementation-specific code.

The implementation is not completely hidden, since `FieldElement32` and
`FieldElement64` are tuple structs whose elements are public; `pub(crate)`
doesn't seem to work for tuple structs.

Similarly, the constants file is split over multiple files, depending on the
implementation.
2017-07-30 16:25:42 -07:00
Henry de Valence
513ce26942 avoid 128-bit multiplications 2017-07-20 21:33:15 -07:00