ge25519_scalarmult_base.c 2.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768
  1. #include "fe25519.h"
  2. #include "sc25519.h"
  3. #include "ge25519.h"
  4. /* Multiples of the base point in Niels' representation */
  5. static const ge25519_niels ge25519_base_multiples_niels[] = {
  6. #ifdef SMALLTABLES
  7. #include "ge25519_base_niels_smalltables.data"
  8. #else
  9. #include "ge25519_base_niels.data"
  10. #endif
  11. };
  12. /* d */
  13. static const fe25519 ecd = {{0x75EB4DCA135978A3, 0x00700A4D4141D8AB, 0x8CC740797779E898, 0x52036CEE2B6FFE73}};
  14. void ge25519_scalarmult_base(ge25519_p3 *r, const sc25519 *s)
  15. {
  16. signed char b[64];
  17. int i;
  18. ge25519_niels t;
  19. fe25519 d;
  20. sc25519_window4(b,s);
  21. #ifdef SMALLTABLES
  22. ge25519_p1p1 tp1p1;
  23. choose_t((ge25519_niels *)r, 0, (signed long long) b[1], ge25519_base_multiples_niels);
  24. fe25519_sub(&d, &r->y, &r->x);
  25. fe25519_add(&r->y, &r->y, &r->x);
  26. r->x = d;
  27. r->t = r->z;
  28. fe25519_setint(&r->z,2);
  29. for(i=3;i<64;i+=2)
  30. {
  31. choose_t(&t, (unsigned long long) i/2, (signed long long) b[i], ge25519_base_multiples_niels);
  32. ge25519_nielsadd2(r, &t);
  33. }
  34. ge25519_dbl_p1p1(&tp1p1,(ge25519_p2 *)r);
  35. ge25519_p1p1_to_p2((ge25519_p2 *)r, &tp1p1);
  36. ge25519_dbl_p1p1(&tp1p1,(ge25519_p2 *)r);
  37. ge25519_p1p1_to_p2((ge25519_p2 *)r, &tp1p1);
  38. ge25519_dbl_p1p1(&tp1p1,(ge25519_p2 *)r);
  39. ge25519_p1p1_to_p2((ge25519_p2 *)r, &tp1p1);
  40. ge25519_dbl_p1p1(&tp1p1,(ge25519_p2 *)r);
  41. ge25519_p1p1_to_p3(r, &tp1p1);
  42. choose_t(&t, (unsigned long long) 0, (signed long long) b[0], ge25519_base_multiples_niels);
  43. fe25519_mul(&t.t2d, &t.t2d, &ecd);
  44. ge25519_nielsadd2(r, &t);
  45. for(i=2;i<64;i+=2)
  46. {
  47. choose_t(&t, (unsigned long long) i/2, (signed long long) b[i], ge25519_base_multiples_niels);
  48. ge25519_nielsadd2(r, &t);
  49. }
  50. #else
  51. choose_t((ge25519_niels *)r, 0, (signed long long) b[0], ge25519_base_multiples_niels);
  52. fe25519_sub(&d, &r->y, &r->x);
  53. fe25519_add(&r->y, &r->y, &r->x);
  54. r->x = d;
  55. r->t = r->z;
  56. fe25519_setint(&r->z,2);
  57. for(i=1;i<64;i++)
  58. {
  59. choose_t(&t, (unsigned long long) i, (signed long long) b[i], ge25519_base_multiples_niels);
  60. ge25519_nielsadd2(r, &t);
  61. }
  62. #endif
  63. }