X-Git-Url: https://git.distorted.org.uk/u/mdw/catacomb/blobdiff_plain/b0ab12e6a6cb035df2b6312df7ad1736af0a6128..8823192f6413bed15cfa884ed3a3cbbb97885657:/f-prime.c diff --git a/f-prime.c b/f-prime.c index 1a7b9e8..7c1dae5 100644 --- a/f-prime.c +++ b/f-prime.c @@ -1,6 +1,6 @@ /* -*-c-*- * - * $Id: f-prime.c,v 1.1 2001/04/29 18:12:33 mdw Exp $ + * $Id: f-prime.c,v 1.3.4.2 2004/03/20 00:13:31 mdw Exp $ * * Prime fields with Montgomery arithmetic * @@ -30,6 +30,18 @@ /*----- Revision history --------------------------------------------------* * * $Log: f-prime.c,v $ + * Revision 1.3.4.2 2004/03/20 00:13:31 mdw + * Projective coordinates for prime curves + * + * Revision 1.3.4.1 2003/06/10 13:43:53 mdw + * Simple (non-projective) curves over prime fields now seem to work. + * + * Revision 1.3 2003/05/15 23:25:59 mdw + * Make elliptic curve stuff build. + * + * Revision 1.2 2002/01/13 13:48:44 mdw + * Further progress. + * * Revision 1.1 2001/04/29 18:12:33 mdw * Prototype version. * @@ -63,7 +75,8 @@ static void fdestroy(field *ff) static mp *fin(field *ff, mp *d, mp *x) { fctx *f = (fctx *)ff; - return (mpmont_mul(&f->mm, d, x, f->mm.r2)); + mp_div(0, &d, x, f->mm.m); + return (mpmont_mul(&f->mm, d, d, f->mm.r2)); } static mp *fout(field *ff, mp *d, mp *x) @@ -72,14 +85,37 @@ static mp *fout(field *ff, mp *d, mp *x) return (mpmont_reduce(&f->mm, d, x)); } +static int fzerop(field *ff, mp *x) +{ + return (!MP_LEN(x)); +} + +static mp *fneg(field *ff, mp *d, mp *x) +{ + fctx *f = (fctx *)ff; + return (mp_sub(d, f->mm.m, x)); +} + static mp *fadd(field *ff, mp *d, mp *x, mp *y) { - return (mp_add(d, x, y)); + fctx *f = (fctx *)ff; + d = mp_add(d, x, y); + if (d->f & MP_NEG) + d = mp_add(d, d, f->mm.m); + else if (MP_CMP(d, >, f->mm.m)) + d = mp_sub(d, d, f->mm.m); + return (d); } static mp *fsub(field *ff, mp *d, mp *x, mp *y) { - return (mp_sub(d, x, y)); + fctx *f = (fctx *)ff; + d = mp_sub(d, x, y); + if (d->f & MP_NEG) + d = mp_add(d, d, f->mm.m); + else if (MP_CMP(d, >, f->mm.m)) + d = mp_sub(d, d, f->mm.m); + return (d); } static mp *fmul(field *ff, mp *d, mp *x, mp *y) @@ -98,7 +134,7 @@ static mp *fsqr(field *ff, mp *d, mp *x) static mp *finv(field *ff, mp *d, mp *x) { fctx *f = (fctx *)ff; - d = mpmont_reduce(&f->mm, x); + d = mpmont_reduce(&f->mm, d, x); mp_gcd(0, 0, &d, f->mm.m, d); return (mpmont_mul(&f->mm, d, d, f->mm.r2)); } @@ -113,7 +149,10 @@ static mp *freduce(field *ff, mp *d, mp *x) static mp *fdbl(field *ff, mp *d, mp *x) { fctx *f = (fctx *)ff; - return (mp_lsl(d, x, 1)); + d = mp_lsl(d, x, 1); + if (MP_CMP(d, >, f->mm.m)) + d = mp_sub(d, d, f->mm.m); + return (d); } static mp *ftpl(field *ff, mp *d, mp *x) @@ -121,14 +160,42 @@ static mp *ftpl(field *ff, mp *d, mp *x) fctx *f = (fctx *)ff; MP_DEST(d, MP_LEN(x) + 1, x->f); MPX_UMULN(d->v, d->vl, x->v, x->vl, 3); + while (MP_CMP(d, >, f->mm.m)) + d = mp_sub(d, d, f->mm.m); return (d); } +static mp *fqdl(field *ff, mp *d, mp *x) +{ + fctx *f = (fctx *)ff; + d = mp_lsl(d, x, 2); + while (MP_CMP(d, >, f->mm.m)) + d = mp_sub(d, d, f->mm.m); + return (d); +} + +static mp *fhlv(field *ff, mp *d, mp *x) +{ + fctx *f = (fctx *)ff; + if (!MP_LEN(x)) { + MP_COPY(x); + MP_DROP(d); + return (x); + } + if (x->v[0] & 1) { + d = mp_add(d, x, f->mm.m); + x = d; + } + return (mp_lsr(d, x, 1)); +} + static mp *fsqrt(field *ff, mp *d, mp *x) { fctx *f = (fctx *)ff; - d = mpmont_reduce(&f->mm, x); + d = mpmont_reduce(&f->mm, d, x); d = mp_modsqrt(d, d, f->mm.m); + if (!d) + return (d); return (mpmont_mul(&f->mm, d, d, f->mm.r2)); } @@ -137,8 +204,8 @@ static mp *fsqrt(field *ff, mp *d, mp *x) static field_ops fops = { fdestroy, fin, fout, - fadd, fsub, fmul, fsqr, finv, freduce, - fdbl, ftpl, fsqrt + fzerop, fneg, fadd, fsub, fmul, fsqr, finv, freduce, + fdbl, ftpl, fqdl, fhlv, fsqrt }; /* --- @field_prime@ --- * @@ -153,11 +220,11 @@ static field_ops fops = { field *field_prime(mp *p) { - ftcx *f = CREATE(fctx); + fctx *f = CREATE(fctx); f->f.ops = &fops; mpmont_create(&f->mm, p); - f->zero = MP_ZERO; - f->one = &f->mm.r; + f->f.zero = MP_ZERO; + f->f.one = f->mm.r; return (&f->f); }