Monero
crypto-ops.h
Go to the documentation of this file.
1 // Copyright (c) 2014-2018, The Monero Project
2 //
3 // All rights reserved.
4 //
5 // Redistribution and use in source and binary forms, with or without modification, are
6 // permitted provided that the following conditions are met:
7 //
8 // 1. Redistributions of source code must retain the above copyright notice, this list of
9 // conditions and the following disclaimer.
10 //
11 // 2. Redistributions in binary form must reproduce the above copyright notice, this list
12 // of conditions and the following disclaimer in the documentation and/or other
13 // materials provided with the distribution.
14 //
15 // 3. Neither the name of the copyright holder nor the names of its contributors may be
16 // used to endorse or promote products derived from this software without specific
17 // prior written permission.
18 //
19 // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY
20 // EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
21 // MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
22 // THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
23 // SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
24 // PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
25 // INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
26 // STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
27 // THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28 //
29 // Parts of this file are originally copyright (c) 2012-2013 The Cryptonote developers
30 
31 #pragma once
32 
33 /* From fe.h */
34 
35 typedef int32_t fe[10];
36 
37 /* From ge.h */
38 
39 typedef struct {
40  fe X;
41  fe Y;
42  fe Z;
43 } ge_p2;
44 
45 typedef struct {
46  fe X;
47  fe Y;
48  fe Z;
49  fe T;
50 } ge_p3;
51 
52 typedef struct {
53  fe X;
54  fe Y;
55  fe Z;
56  fe T;
57 } ge_p1p1;
58 
59 typedef struct {
63 } ge_precomp;
64 
65 typedef struct {
68  fe Z;
70 } ge_cached;
71 
72 /* From ge_add.c */
73 
74 void ge_add(ge_p1p1 *, const ge_p3 *, const ge_cached *);
75 
76 /* From ge_double_scalarmult.c, modified */
77 
78 typedef ge_cached ge_dsmp[8];
79 extern const ge_precomp ge_Bi[8];
80 void ge_dsm_precomp(ge_dsmp r, const ge_p3 *s);
81 void ge_double_scalarmult_base_vartime(ge_p2 *, const unsigned char *, const ge_p3 *, const unsigned char *);
82 void ge_double_scalarmult_base_vartime_p3(ge_p3 *, const unsigned char *, const ge_p3 *, const unsigned char *);
83 
84 /* From ge_frombytes.c, modified */
85 
86 extern const fe fe_sqrtm1;
87 extern const fe fe_d;
88 int ge_frombytes_vartime(ge_p3 *, const unsigned char *);
89 
90 /* From ge_p1p1_to_p2.c */
91 
92 void ge_p1p1_to_p2(ge_p2 *, const ge_p1p1 *);
93 
94 /* From ge_p1p1_to_p3.c */
95 
96 void ge_p1p1_to_p3(ge_p3 *, const ge_p1p1 *);
97 
98 /* From ge_p2_dbl.c */
99 
100 void ge_p2_dbl(ge_p1p1 *, const ge_p2 *);
101 
102 /* From ge_p3_to_cached.c */
103 
104 extern const fe fe_d2;
105 void ge_p3_to_cached(ge_cached *, const ge_p3 *);
106 
107 /* From ge_p3_to_p2.c */
108 
109 void ge_p3_to_p2(ge_p2 *, const ge_p3 *);
110 
111 /* From ge_p3_tobytes.c */
112 
113 void ge_p3_tobytes(unsigned char *, const ge_p3 *);
114 
115 /* From ge_scalarmult_base.c */
116 
117 extern const ge_precomp ge_base[32][8];
118 void ge_scalarmult_base(ge_p3 *, const unsigned char *);
119 
120 /* From ge_tobytes.c */
121 
122 void ge_tobytes(unsigned char *, const ge_p2 *);
123 
124 /* From sc_reduce.c */
125 
126 void sc_reduce(unsigned char *);
127 
128 /* New code */
129 
130 void ge_scalarmult(ge_p2 *, const unsigned char *, const ge_p3 *);
131 void ge_scalarmult_p3(ge_p3 *, const unsigned char *, const ge_p3 *);
132 void ge_double_scalarmult_precomp_vartime(ge_p2 *, const unsigned char *, const ge_p3 *, const unsigned char *, const ge_dsmp);
133 void ge_double_scalarmult_precomp_vartime2(ge_p2 *, const unsigned char *, const ge_dsmp, const unsigned char *, const ge_dsmp);
134 void ge_double_scalarmult_precomp_vartime2_p3(ge_p3 *, const unsigned char *, const ge_dsmp, const unsigned char *, const ge_dsmp);
135 void ge_mul8(ge_p1p1 *, const ge_p2 *);
136 extern const fe fe_ma2;
137 extern const fe fe_ma;
138 extern const fe fe_fffb1;
139 extern const fe fe_fffb2;
140 extern const fe fe_fffb3;
141 extern const fe fe_fffb4;
142 extern const ge_p3 ge_p3_identity;
143 extern const ge_p3 ge_p3_H;
144 void ge_fromfe_frombytes_vartime(ge_p2 *, const unsigned char *);
145 void sc_0(unsigned char *);
146 void sc_reduce32(unsigned char *);
147 void sc_add(unsigned char *, const unsigned char *, const unsigned char *);
148 void sc_sub(unsigned char *, const unsigned char *, const unsigned char *);
149 void sc_mulsub(unsigned char *, const unsigned char *, const unsigned char *, const unsigned char *);
150 void sc_mul(unsigned char *, const unsigned char *, const unsigned char *);
151 void sc_muladd(unsigned char *s, const unsigned char *a, const unsigned char *b, const unsigned char *c);
152 int sc_check(const unsigned char *);
153 int sc_isnonzero(const unsigned char *); /* Doesn't normalize */
154 
155 // internal
156 uint64_t load_3(const unsigned char *in);
157 uint64_t load_4(const unsigned char *in);
158 void ge_sub(ge_p1p1 *r, const ge_p3 *p, const ge_cached *q);
159 void fe_add(fe h, const fe f, const fe g);
160 void fe_tobytes(unsigned char *, const fe);
161 void fe_invert(fe out, const fe z);
162 
163 int ge_p3_is_point_at_infinity(const ge_p3 *p);
fe YplusX
Definition: crypto-ops.h:66
const fe fe_d
Definition: crypto-ops-data.c:37
fe Y
Definition: crypto-ops.h:54
const fe fe_ma
Definition: crypto-ops-data.c:868
void ge_sub(ge_p1p1 *r, const ge_p3 *p, const ge_cached *q)
Definition: crypto-ops.c:1637
Definition: crypto-ops.h:52
void fe_add(fe h, const fe f, const fe g)
Definition: crypto-ops.c:121
Definition: crypto-ops.h:39
void ge_tobytes(unsigned char *, const ge_p2 *)
Definition: crypto-ops.c:1654
int sc_check(const unsigned char *)
Definition: crypto-ops.c:3714
int32_t fe[10]
Definition: crypto-ops.h:35
fe T
Definition: crypto-ops.h:56
void sc_reduce(unsigned char *)
Definition: crypto-ops.c:1678
const fe fe_fffb4
Definition: crypto-ops-data.c:872
fe yminusx
Definition: crypto-ops.h:61
void ge_double_scalarmult_base_vartime_p3(ge_p3 *, const unsigned char *, const ge_p3 *, const unsigned char *)
Definition: crypto-ops.c:1237
void sc_sub(unsigned char *, const unsigned char *, const unsigned char *)
Definition: crypto-ops.c:2587
Definition: crypto-ops.h:45
void ge_scalarmult_base(ge_p3 *, const unsigned char *)
Definition: crypto-ops.c:1589
fe Z
Definition: crypto-ops.h:48
void ge_fromfe_frombytes_vartime(ge_p2 *, const unsigned char *)
Definition: crypto-ops.c:2210
void sc_muladd(unsigned char *s, const unsigned char *a, const unsigned char *b, const unsigned char *c)
Definition: crypto-ops.c:3389
int sc_isnonzero(const unsigned char *)
Definition: crypto-ops.c:3726
fe yplusx
Definition: crypto-ops.h:60
const fe fe_fffb1
Definition: crypto-ops-data.c:869
void ge_scalarmult_p3(ge_p3 *, const unsigned char *, const ge_p3 *)
Definition: crypto-ops.c:2048
Definition: crypto-ops.h:59
const fe fe_fffb2
Definition: crypto-ops-data.c:870
void ge_double_scalarmult_precomp_vartime2(ge_p2 *, const unsigned char *, const ge_dsmp, const unsigned char *, const ge_dsmp)
Definition: crypto-ops.c:2112
void ge_p1p1_to_p2(ge_p2 *, const ge_p1p1 *)
Definition: crypto-ops.c:1422
fe X
Definition: crypto-ops.h:53
void sc_reduce32(unsigned char *)
Definition: crypto-ops.c:2333
void ge_double_scalarmult_precomp_vartime(ge_p2 *, const unsigned char *, const ge_p3 *, const unsigned char *, const ge_dsmp)
Definition: crypto-ops.c:2194
Definition: crypto-ops.h:65
fe T2d
Definition: crypto-ops.h:69
const ge_precomp ge_Bi[8]
Definition: crypto-ops-data.c:846
void sc_mulsub(unsigned char *, const unsigned char *, const unsigned char *, const unsigned char *)
Definition: crypto-ops.c:2737
void ge_double_scalarmult_base_vartime(ge_p2 *, const unsigned char *, const ge_p3 *, const unsigned char *)
Definition: crypto-ops.c:1196
int b
Definition: base.py:1
fe Z
Definition: crypto-ops.h:42
fe Y
Definition: crypto-ops.h:41
void ge_mul8(ge_p1p1 *, const ge_p2 *)
Definition: crypto-ops.c:2201
void sc_0(unsigned char *)
Definition: crypto-ops.c:2326
void fe_tobytes(unsigned char *, const fe)
Definition: crypto-ops.c:1032
void fe_invert(fe out, const fe z)
Definition: crypto-ops.c:259
fe Z
Definition: crypto-ops.h:68
fe Z
Definition: crypto-ops.h:55
fe xy2d
Definition: crypto-ops.h:62
int q
Definition: base.py:2
const fe fe_d2
Definition: crypto-ops-data.c:39
void ge_p2_dbl(ge_p1p1 *, const ge_p2 *)
Definition: crypto-ops.c:1455
ge_cached ge_dsmp[8]
Definition: crypto-ops.h:78
const ge_p3 ge_p3_H
Definition: crypto-ops-data.c:874
void ge_dsm_precomp(ge_dsmp r, const ge_p3 *s)
Definition: crypto-ops.c:1175
void ge_add(ge_p1p1 *, const ge_p3 *, const ge_cached *)
Definition: crypto-ops.c:1126
string a
Definition: MakeCryptoOps.py:15
void ge_double_scalarmult_precomp_vartime2_p3(ge_p3 *, const unsigned char *, const ge_dsmp, const unsigned char *, const ge_dsmp)
Definition: crypto-ops.c:2151
const ge_p3 ge_p3_identity
Definition: crypto-ops-data.c:873
void ge_p1p1_to_p3(ge_p3 *, const ge_p1p1 *)
Definition: crypto-ops.c:1434
uint64_t load_3(const unsigned char *in)
Definition: crypto-ops.c:51
fe T
Definition: crypto-ops.h:49
void ge_scalarmult(ge_p2 *, const unsigned char *, const ge_p3 *)
Definition: crypto-ops.c:1988
int ge_frombytes_vartime(ge_p3 *, const unsigned char *)
Definition: crypto-ops.c:1284
int ge_p3_is_point_at_infinity(const ge_p3 *p)
Definition: crypto-ops.c:3733
const fe fe_ma2
Definition: crypto-ops-data.c:867
const fe fe_sqrtm1
Definition: crypto-ops-data.c:38
void sc_mul(unsigned char *, const unsigned char *, const unsigned char *)
Definition: crypto-ops.c:3068
void sc_add(unsigned char *, const unsigned char *, const unsigned char *)
Definition: crypto-ops.c:2448
uint64_t load_4(const unsigned char *in)
Definition: crypto-ops.c:59
const ge_precomp ge_base[32][8]
Definition: crypto-ops-data.c:42
fe X
Definition: crypto-ops.h:46
fe Y
Definition: crypto-ops.h:47
fe YminusX
Definition: crypto-ops.h:67
void ge_p3_tobytes(unsigned char *, const ge_p3 *)
Definition: crypto-ops.c:1516
#define s(x, c)
Definition: aesb.c:46
fe X
Definition: crypto-ops.h:40
void ge_p3_to_p2(ge_p2 *, const ge_p3 *)
Definition: crypto-ops.c:1508
const fe fe_fffb3
Definition: crypto-ops-data.c:871
void ge_p3_to_cached(ge_cached *, const ge_p3 *)
Definition: crypto-ops.c:1495