curve25519_dalek/backend/serial/scalar_mul/
vartime_double_base.rs1#![allow(non_snake_case)]
12
13use core::cmp::Ordering;
14
15use crate::backend::serial::curve_models::{ProjectiveNielsPoint, ProjectivePoint};
16use crate::constants;
17use crate::edwards::EdwardsPoint;
18use crate::scalar::Scalar;
19use crate::traits::Identity;
20use crate::window::NafLookupTable5;
21
22#[allow(dead_code)]
24pub fn mul(a: &Scalar, A: &EdwardsPoint, b: &Scalar) -> EdwardsPoint {
25 let a_naf = a.non_adjacent_form(5);
26
27 #[cfg(feature = "precomputed-tables")]
28 let b_naf = b.non_adjacent_form(8);
29 #[cfg(not(feature = "precomputed-tables"))]
30 let b_naf = b.non_adjacent_form(5);
31
32 let mut i: usize = 255;
34 let mut j: usize = 256;
35 while j > 0 {
36 j -= 1;
37 i = j;
38 if a_naf[i] != 0 || b_naf[i] != 0 {
39 break;
40 }
41 }
42
43 let table_A = NafLookupTable5::<ProjectiveNielsPoint>::from(A);
44 #[cfg(feature = "precomputed-tables")]
45 let table_B = &constants::AFFINE_ODD_MULTIPLES_OF_BASEPOINT;
46 #[cfg(not(feature = "precomputed-tables"))]
47 let table_B =
48 &NafLookupTable5::<ProjectiveNielsPoint>::from(&constants::ED25519_BASEPOINT_POINT);
49
50 let mut r = ProjectivePoint::identity();
51 loop {
52 let mut t = r.double();
53
54 match a_naf[i].cmp(&0) {
55 Ordering::Greater => t = &t.as_extended() + &table_A.select(a_naf[i] as usize),
56 Ordering::Less => t = &t.as_extended() - &table_A.select(-a_naf[i] as usize),
57 Ordering::Equal => {}
58 }
59
60 match b_naf[i].cmp(&0) {
61 Ordering::Greater => t = &t.as_extended() + &table_B.select(b_naf[i] as usize),
62 Ordering::Less => t = &t.as_extended() - &table_B.select(-b_naf[i] as usize),
63 Ordering::Equal => {}
64 }
65
66 r = t.as_projective();
67
68 if i == 0 {
69 break;
70 }
71 i -= 1;
72 }
73
74 r.as_extended()
75}