authorgravatar for 124872+jedisct1@users.noreply.github.comFrank Denis <124872+jedisct1@users.noreply.github.com> 2021-04-26 22:25:48+02:00
committergravatar for noreply@github.comGitHub <noreply@github.com> 2021-04-26 22:25:48+02:00
log030fa5e7ebc21339728c79f33bf5d5d22e0a760e
treea0793e131036a29abc740888cfeea97fa85ce987
parent95b42f9e6b901435b6ff7841a6b180553761070b
signaturebadge-question-mark Signed by PGP key 4AEE18F83AFDEB23

25519: remove unused const, safeguard against unreduced scalars (#8624)

* 25519: remove unused const, safeguard against unreduced scalars No behavior change, but it makes the existing code better match the forthcoming code for other curves. Rename nonAdjacentForm() to slide(), remove an unneeded and confusing constant, and do a reduction in slide() if 257 bits would be required. Note that in all the high-level functions, the top bit is always cleared, so the reduction is never necessary. But since the low-level functions are public, the check is a safe thing to have. * 25519: make identityElement public, deprecate neutralElement Also fix a few comments by the way.

3 files changed, 11 insertions(+), 18 deletions(-)

lib/std/crypto/25519/edwards25519.zig+9-16
......@@ -75,16 +75,8 @@ pub const Edwards25519 = struct {
7575 .is_base = true,
7676 };
7777
78 /// The edwards25519 neutral element.
79 pub const neutralElement = Edwards25519{
80 .x = Fe{ .limbs = .{ 2251799813685229, 2251799813685247, 2251799813685247, 2251799813685247, 2251799813685247 } },
81 .y = Fe{ .limbs = .{ 1507481815385608, 2223447444246085, 1083941587175919, 2059929906842505, 1581435440146976 } },
82 .z = Fe{ .limbs = .{ 1507481815385608, 2223447444246085, 1083941587175919, 2059929906842505, 1581435440146976 } },
83 .t = Fe{ .limbs = .{ 2251799813685229, 2251799813685247, 2251799813685247, 2251799813685247, 2251799813685247 } },
84 .is_base = false,
85 };
86
87 const identityElement = Edwards25519{ .x = Fe.zero, .y = Fe.one, .z = Fe.one, .t = Fe.zero };
78 pub const neutralElement = @compileError("deprecated: use identityElement instead");
79 pub const identityElement = Edwards25519{ .x = Fe.zero, .y = Fe.one, .z = Fe.one, .t = Fe.zero };
8880
8981 /// Reject the neutral element.
9082 pub fn rejectIdentity(p: Edwards25519) IdentityElementError!void {
......@@ -160,9 +152,10 @@ pub const Edwards25519 = struct {
160152 return t;
161153 }
162154
163 fn nonAdjacentForm(s: [32]u8) [2 * 32]i8 {
155 fn slide(s: [32]u8) [2 * 32]i8 {
156 const reduced = if ((s[s.len - 1] & 0x80) != 0) s else scalar.reduce(s);
164157 var e: [2 * 32]i8 = undefined;
165 for (s) |x, i| {
158 for (reduced) |x, i| {
166159 e[i * 2 + 0] = @as(i8, @truncate(u4, x));
167160 e[i * 2 + 1] = @as(i8, @truncate(u4, x >> 4));
168161 }
......@@ -185,7 +178,7 @@ pub const Edwards25519 = struct {
185178 // avoid these to keep the standard library lightweight.
186179 fn pcMul(pc: [9]Edwards25519, s: [32]u8, comptime vartime: bool) IdentityElementError!Edwards25519 {
187180 std.debug.assert(vartime);
188 const e = nonAdjacentForm(s);
181 const e = slide(s);
189182 var q = Edwards25519.identityElement;
190183 var pos: usize = 2 * 32 - 1;
191184 while (true) : (pos -= 1) {
......@@ -280,8 +273,8 @@ pub const Edwards25519 = struct {
280273 xpc[4].rejectIdentity() catch return error.WeakPublicKey;
281274 break :pc xpc;
282275 };
283 const e1 = nonAdjacentForm(s1);
284 const e2 = nonAdjacentForm(s2);
276 const e1 = slide(s1);
277 const e2 = slide(s2);
285278 var q = Edwards25519.identityElement;
286279 var pos: usize = 2 * 32 - 1;
287280 while (true) : (pos -= 1) {
......@@ -318,7 +311,7 @@ pub const Edwards25519 = struct {
318311 }
319312 var es: [count][2 * 32]i8 = undefined;
320313 for (ss) |s, i| {
321 es[i] = nonAdjacentForm(s);
314 es[i] = slide(s);
322315 }
323316 var q = Edwards25519.identityElement;
324317 var pos: usize = 2 * 32 - 1;
lib/std/crypto/25519/field.zig+1-1
......@@ -355,7 +355,7 @@ pub const Fe = struct {
355355 return fe;
356356 }
357357
358 /// Compute the inverse of a field element
358 /// Return the inverse of a field element, or 0 if a=0.
359359 pub fn invert(a: Fe) Fe {
360360 var t0 = a.sq();
361361 var t1 = t0.sqn(2).mul(a);
lib/std/crypto/25519/scalar.zig+1-1
......@@ -98,7 +98,7 @@ pub fn sub(a: [32]u8, b: [32]u8) [32]u8 {
9898 return add(a, neg(b));
9999}
100100
101/// A scalar in unpacked reprentation
101/// A scalar in unpacked representation
102102pub const Scalar = struct {
103103 const Limbs = [5]u64;
104104 limbs: Limbs = undefined,