curve25519-donna-helpers.h 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115
  1. /*
  2. Public domain by Andrew M. <liquidsun@gmail.com>
  3. See: https://github.com/floodyberry/curve25519-donna
  4. Curve25519 implementation agnostic helpers
  5. */
  6. /*
  7. * In: b = 2^5 - 2^0
  8. * Out: b = 2^250 - 2^0
  9. */
  10. static void
  11. curve25519_pow_two5mtwo0_two250mtwo0(bignum25519 b) {
  12. bignum25519 ALIGN(16) t0,c;
  13. /* 2^5 - 2^0 */ /* b */
  14. /* 2^10 - 2^5 */ curve25519_square_times(t0, b, 5);
  15. /* 2^10 - 2^0 */ curve25519_mul_noinline(b, t0, b);
  16. /* 2^20 - 2^10 */ curve25519_square_times(t0, b, 10);
  17. /* 2^20 - 2^0 */ curve25519_mul_noinline(c, t0, b);
  18. /* 2^40 - 2^20 */ curve25519_square_times(t0, c, 20);
  19. /* 2^40 - 2^0 */ curve25519_mul_noinline(t0, t0, c);
  20. /* 2^50 - 2^10 */ curve25519_square_times(t0, t0, 10);
  21. /* 2^50 - 2^0 */ curve25519_mul_noinline(b, t0, b);
  22. /* 2^100 - 2^50 */ curve25519_square_times(t0, b, 50);
  23. /* 2^100 - 2^0 */ curve25519_mul_noinline(c, t0, b);
  24. /* 2^200 - 2^100 */ curve25519_square_times(t0, c, 100);
  25. /* 2^200 - 2^0 */ curve25519_mul_noinline(t0, t0, c);
  26. /* 2^250 - 2^50 */ curve25519_square_times(t0, t0, 50);
  27. /* 2^250 - 2^0 */ curve25519_mul_noinline(b, t0, b);
  28. }
  29. /*
  30. * z^(p - 2) = z(2^255 - 21)
  31. */
  32. static void
  33. curve25519_recip(bignum25519 out, const bignum25519 z) {
  34. bignum25519 ALIGN(16) a,t0,b;
  35. /* 2 */ curve25519_square_times(a, z, 1); /* a = 2 */
  36. /* 8 */ curve25519_square_times(t0, a, 2);
  37. /* 9 */ curve25519_mul_noinline(b, t0, z); /* b = 9 */
  38. /* 11 */ curve25519_mul_noinline(a, b, a); /* a = 11 */
  39. /* 22 */ curve25519_square_times(t0, a, 1);
  40. /* 2^5 - 2^0 = 31 */ curve25519_mul_noinline(b, t0, b);
  41. /* 2^250 - 2^0 */ curve25519_pow_two5mtwo0_two250mtwo0(b);
  42. /* 2^255 - 2^5 */ curve25519_square_times(b, b, 5);
  43. /* 2^255 - 21 */ curve25519_mul_noinline(out, b, a);
  44. }
  45. static const unsigned char curve25519_packedone[32] = {
  46. 1, 0, 0, 0, 0, 0, 0, 0,
  47. 0, 0, 0, 0, 0, 0, 0, 0,
  48. 0, 0, 0, 0, 0, 0, 0, 0,
  49. 0, 0, 0, 0, 0, 0, 0, 0,
  50. };
  51. static void
  52. curve25519_setone(bignum25519 out) {
  53. // (cathugger) this hopefuly will get inlined by compiler because im lazy
  54. curve25519_expand(out, curve25519_packedone);
  55. }
  56. /*
  57. * (cathugger)
  58. * idk if recip is same as invert but I hope it is
  59. * if that's the case then we're doing batch invert there
  60. */
  61. static void
  62. curve25519_batchrecip(bignum25519 *out, const bignum25519 *in, bignum25519 *tmp, size_t num, size_t offset) {
  63. bignum25519 ALIGN(16) acc,tmpacc;
  64. size_t i;
  65. const bignum25519 *inp;
  66. bignum25519 *outp;
  67. curve25519_setone(acc);
  68. inp = in;
  69. for (i = 0; i < num; ++i) {
  70. curve25519_copy(tmp[i], acc);
  71. curve25519_mul(acc, acc, *inp);
  72. inp = (const bignum25519 *)((const char *)inp + offset);
  73. }
  74. curve25519_recip(acc, acc);
  75. i = num;
  76. inp = (const bignum25519 *)((const char *)in + offset * num);
  77. outp = (bignum25519 *)((char *)out + offset * num);
  78. while (i--) {
  79. inp = (const bignum25519 *)((const char *)inp - offset);
  80. outp = (bignum25519 *)((char *)outp - offset);
  81. curve25519_mul(tmpacc, acc, *inp);
  82. curve25519_mul(*outp, acc, tmp[i]);
  83. curve25519_copy(acc, tmpacc);
  84. }
  85. }
  86. /*
  87. * z^((p-5)/8) = z^(2^252 - 3)
  88. */
  89. static void
  90. curve25519_pow_two252m3(bignum25519 two252m3, const bignum25519 z) {
  91. bignum25519 ALIGN(16) b,c,t0;
  92. /* 2 */ curve25519_square_times(c, z, 1); /* c = 2 */
  93. /* 8 */ curve25519_square_times(t0, c, 2); /* t0 = 8 */
  94. /* 9 */ curve25519_mul_noinline(b, t0, z); /* b = 9 */
  95. /* 11 */ curve25519_mul_noinline(c, b, c); /* c = 11 */
  96. /* 22 */ curve25519_square_times(t0, c, 1);
  97. /* 2^5 - 2^0 = 31 */ curve25519_mul_noinline(b, t0, b);
  98. /* 2^250 - 2^0 */ curve25519_pow_two5mtwo0_two250mtwo0(b);
  99. /* 2^252 - 2^2 */ curve25519_square_times(b, b, 2);
  100. /* 2^252 - 3 */ curve25519_mul_noinline(two252m3, b, z);
  101. }