ge25519.h 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110
  1. #ifndef GE25519_H
  2. #define GE25519_H
  3. /*
  4. * Arithmetic on the twisted Edwards curve -x^2 + y^2 = 1 + dx^2y^2
  5. * with d = -(121665/121666) =
  6. * 37095705934669439343138083508754565189542113879843219016388785533085940283555
  7. * Base point:
  8. * (15112221349535400772501151409588531511454012693041857206046113283949847762202,46316835694926478169428394003475163141307993866256225615783033603165251855960);
  9. */
  10. #include "fe25519.h"
  11. #include "sc25519.h"
  12. #include "compat.h"
  13. #define ge25519 CRYPTO_NAMESPACE(batch_ge25519)
  14. #define ge25519_base CRYPTO_NAMESPACE(batch_ge25519_base)
  15. #define ge25519_unpackneg_vartime CRYPTO_NAMESPACE(batch_unpackneg_vartime)
  16. #define ge25519_pack CRYPTO_NAMESPACE(batch_pack)
  17. #define ge25519_isneutral_vartime CRYPTO_NAMESPACE(batch_isneutral_vartime)
  18. #define ge25519_add CRYPTO_NAMESPACE(batch_ge25519_add)
  19. #define ge25519_double CRYPTO_NAMESPACE(batch_ge25519_double)
  20. #define ge25519_double_scalarmult_vartime CRYPTO_NAMESPACE(batch_double_scalarmult_vartime)
  21. #define ge25519_multi_scalarmult_vartime CRYPTO_NAMESPACE(batch_ge25519_multi_scalarmult_vartime)
  22. #define ge25519_scalarmult_base CRYPTO_NAMESPACE(batch_scalarmult_base)
  23. #define ge25519_p1p1_to_p2 CRYPTO_NAMESPACE(batch_ge25519_p1p1_to_p2)
  24. #define ge25519_p1p1_to_p3 CRYPTO_NAMESPACE(batch_ge25519_p1p1_to_p3)
  25. #define ge25519_p1p1_to_pniels CRYPTO_NAMESPACE(batch_ge25519_p1p1_to_pniels)
  26. #define ge25519_add_p1p1 CRYPTO_NAMESPACE(batch_ge25519_add_p1p1)
  27. #define ge25519_dbl_p1p1 CRYPTO_NAMESPACE(batch_ge25519_dbl_p1p1)
  28. #define choose_t CRYPTO_NAMESPACE(batch_choose_t)
  29. #define ge25519_nielsadd2 CRYPTO_NAMESPACE(batch_ge25519_nielsadd2)
  30. #define ge25519_nielsadd_p1p1 CRYPTO_NAMESPACE(batch_ge25519_nielsadd_p1p1)
  31. #define ge25519_pnielsadd_p1p1 CRYPTO_NAMESPACE(batch_ge25519_pnielsadd_p1p1)
  32. #define ge25519_p3 ge25519
  33. typedef struct
  34. {
  35. fe25519 x;
  36. fe25519 y;
  37. fe25519 z;
  38. fe25519 t;
  39. } ge25519;
  40. typedef struct
  41. {
  42. fe25519 x;
  43. fe25519 z;
  44. fe25519 y;
  45. fe25519 t;
  46. } ge25519_p1p1;
  47. typedef struct
  48. {
  49. fe25519 x;
  50. fe25519 y;
  51. fe25519 z;
  52. } ge25519_p2;
  53. typedef struct
  54. {
  55. fe25519 ysubx;
  56. fe25519 xaddy;
  57. fe25519 t2d;
  58. } ge25519_niels;
  59. typedef struct
  60. {
  61. fe25519 ysubx;
  62. fe25519 xaddy;
  63. fe25519 z;
  64. fe25519 t2d;
  65. } ge25519_pniels;
  66. typedef unsigned char bytes32[32];
  67. extern void ge25519_p1p1_to_p2(ge25519_p2 *r, const ge25519_p1p1 *p) SYSVABI;
  68. extern void ge25519_p1p1_to_p3(ge25519_p3 *r, const ge25519_p1p1 *p) SYSVABI;
  69. extern void ge25519_p1p1_to_pniels(ge25519_pniels *r, const ge25519_p1p1 *p) SYSVABI;
  70. extern void ge25519_add_p1p1(ge25519_p1p1 *r, const ge25519_p3 *p, const ge25519_p3 *q) SYSVABI;
  71. extern void ge25519_dbl_p1p1(ge25519_p1p1 *r, const ge25519_p2 *p) SYSVABI;
  72. extern void choose_t(ge25519_niels *t, unsigned long long pos, signed long long b, const ge25519_niels *base_multiples) SYSVABI;
  73. extern void ge25519_nielsadd2(ge25519_p3 *r, const ge25519_niels *q) SYSVABI;
  74. extern void ge25519_nielsadd_p1p1(ge25519_p1p1 *r, const ge25519_p3 *p, const ge25519_niels *q) SYSVABI;
  75. extern void ge25519_pnielsadd_p1p1(ge25519_p1p1 *r, const ge25519_p3 *p, const ge25519_pniels *q) SYSVABI;
  76. extern const ge25519 ge25519_base;
  77. extern int ge25519_unpackneg_vartime(ge25519 *r, const unsigned char p[32]);
  78. extern void ge25519_pack(unsigned char r[32], const ge25519 *p);
  79. extern void ge25519_batchpack_destructive_1(bytes32 *out, ge25519_p3 *in, fe25519 *tmp, size_t num);
  80. extern void ge25519_batchpack_destructive_finish(bytes32 out, ge25519_p3 *unf);
  81. extern int ge25519_isneutral_vartime(const ge25519 *p);
  82. extern void ge25519_add(ge25519 *r, const ge25519 *p, const ge25519 *q);
  83. extern void ge25519_double(ge25519 *r, const ge25519 *p);
  84. /* computes [s1]p1 + [s2]ge25519_base */
  85. extern void ge25519_double_scalarmult_vartime(ge25519 *r, const ge25519 *p1, const sc25519 *s1, const sc25519 *s2);
  86. extern void ge25519_multi_scalarmult_vartime(ge25519 *r, ge25519 *p, sc25519 *s, const unsigned long long npoints);
  87. extern void ge25519_scalarmult_base(ge25519 *r, const sc25519 *s);
  88. #endif