Bipoint.cpp 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365
  1. #include "Bipoint.hpp"
  2. CurveBipoint::CurveBipoint()
  3. {
  4. curvepoint_fp_setneutral(point[0]);
  5. curvepoint_fp_setneutral(point[1]);
  6. }
  7. TwistBipoint::TwistBipoint()
  8. {
  9. twistpoint_fp2_setneutral(point[0]);
  10. twistpoint_fp2_setneutral(point[1]);
  11. }
  12. CurveBipoint::CurveBipoint(curvepoint_fp_t p1, curvepoint_fp_t p2)
  13. {
  14. curvepoint_fp_set(point[0], p1);
  15. curvepoint_fp_set(point[1], p2);
  16. }
  17. TwistBipoint::TwistBipoint(twistpoint_fp2_t p1, twistpoint_fp2_t p2)
  18. {
  19. twistpoint_fp2_set(point[0], p1);
  20. twistpoint_fp2_set(point[1], p2);
  21. }
  22. CurveBipoint::CurveBipoint(const Curvepoint& p1, const Curvepoint& p2)
  23. {
  24. curvepoint_fp_set(point[0], p1.toCurvepointFpT());
  25. curvepoint_fp_set(point[1], p2.toCurvepointFpT());
  26. }
  27. curvepoint_fp_t& CurveBipoint::operator[](int n)
  28. {
  29. return point[n];
  30. }
  31. twistpoint_fp2_t& TwistBipoint::operator[](int n)
  32. {
  33. return point[n];
  34. }
  35. const curvepoint_fp_t& CurveBipoint::operator[](int n) const
  36. {
  37. return point[n];
  38. }
  39. const twistpoint_fp2_t& TwistBipoint::operator[](int n) const
  40. {
  41. return point[n];
  42. }
  43. CurveBipoint CurveBipoint::operator+(const CurveBipoint& b) const
  44. {
  45. CurveBipoint retval;
  46. if (equal(point[0], b[0]))
  47. curvepoint_fp_double(retval[0], point[0]);
  48. else
  49. curvepoint_fp_add_vartime(retval[0], point[0], b[0]);
  50. if (equal(point[1], b[1]))
  51. curvepoint_fp_double(retval[1], point[1]);
  52. else
  53. curvepoint_fp_add_vartime(retval[1], point[1], b[1]);
  54. return retval;
  55. }
  56. TwistBipoint TwistBipoint::operator+(const TwistBipoint& b) const
  57. {
  58. TwistBipoint retval;
  59. if (equal(point[0], b[0]))
  60. twistpoint_fp2_double(retval[0], point[0]);
  61. else
  62. twistpoint_fp2_add_vartime(retval[0], point[0], b[0]);
  63. if (equal(point[1], b[1]))
  64. twistpoint_fp2_double(retval[1], point[1]);
  65. else
  66. twistpoint_fp2_add_vartime(retval[1], point[1], b[1]);
  67. return retval;
  68. }
  69. CurveBipoint CurveBipoint::operator-(const CurveBipoint& b) const
  70. {
  71. CurveBipoint retval, inverseB;
  72. if (!equal(point[0], b[0]))
  73. {
  74. curvepoint_fp_neg(inverseB[0], b[0]);
  75. curvepoint_fp_add_vartime(retval[0], point[0], inverseB[0]);
  76. }
  77. if (!equal(point[1], b[1]))
  78. {
  79. curvepoint_fp_neg(inverseB[1], b[1]);
  80. curvepoint_fp_add_vartime(retval[1], point[1], inverseB[1]);
  81. }
  82. return retval;
  83. }
  84. TwistBipoint TwistBipoint::operator-(const TwistBipoint& b) const
  85. {
  86. TwistBipoint retval, inverseB;
  87. if (!equal(point[0], b[0]))
  88. {
  89. twistpoint_fp2_neg(inverseB[0], b[0]);
  90. twistpoint_fp2_add_vartime(retval[0], point[0], inverseB[0]);
  91. }
  92. if (!equal(point[1], b[1]))
  93. {
  94. twistpoint_fp2_neg(inverseB[1], b[1]);
  95. twistpoint_fp2_add_vartime(retval[1], point[1], inverseB[1]);
  96. }
  97. return retval;
  98. }
  99. CurveBipoint CurveBipoint::operator*(const Scalar& exp) const
  100. {
  101. CurveBipoint retval;
  102. exp.mult(retval[0], point[0]);
  103. exp.mult(retval[1], point[1]);
  104. return retval;
  105. }
  106. TwistBipoint TwistBipoint::operator*(const Scalar& exp) const
  107. {
  108. TwistBipoint retval;
  109. exp.mult(retval[0], point[0]);
  110. exp.mult(retval[1], point[1]);
  111. return retval;
  112. }
  113. bool CurveBipoint::equal(const curvepoint_fp_t& op1, const curvepoint_fp_t& op2) const
  114. {
  115. bool retval;
  116. curvepoint_fp_t affine_op1, affine_op2;
  117. curvepoint_fp_set(affine_op1, op1);
  118. curvepoint_fp_set(affine_op2, op2);
  119. if (!(fpe_isone(affine_op1->m_z) || fpe_iszero(affine_op1->m_z)))
  120. curvepoint_fp_makeaffine(affine_op1);
  121. if (!(fpe_isone(affine_op2->m_z) || fpe_iszero(affine_op2->m_z)))
  122. curvepoint_fp_makeaffine(affine_op2);
  123. retval = fpe_iseq(affine_op1->m_x, affine_op2->m_x);
  124. retval = retval && fpe_iseq(affine_op1->m_y, affine_op2->m_y);
  125. retval = retval || (fpe_iszero(affine_op1->m_z) && fpe_iszero(affine_op2->m_z));
  126. return retval;
  127. }
  128. bool TwistBipoint::equal(const twistpoint_fp2_t& op1, const twistpoint_fp2_t& op2) const
  129. {
  130. bool retval;
  131. twistpoint_fp2_t affine_op1, affine_op2;
  132. twistpoint_fp2_set(affine_op1, op1);
  133. twistpoint_fp2_set(affine_op2, op2);
  134. if (!(fp2e_isone(affine_op1->m_z) || fp2e_iszero(affine_op1->m_z)))
  135. twistpoint_fp2_makeaffine(affine_op1);
  136. if (!(fp2e_isone(affine_op2->m_z) || fp2e_iszero(affine_op2->m_z)))
  137. twistpoint_fp2_makeaffine(affine_op2);
  138. retval = fp2e_iseq(affine_op1->m_x, affine_op2->m_x);
  139. retval = retval && fp2e_iseq(affine_op1->m_y, affine_op2->m_y);
  140. retval = retval || (fp2e_iszero(affine_op1->m_z) && fp2e_iszero(affine_op2->m_z));
  141. return retval;
  142. }
  143. bool CurveBipoint::operator==(const CurveBipoint& b) const
  144. {
  145. return equal(point[0], b[0]) && equal(point[1], b[1]);
  146. }
  147. bool TwistBipoint::operator==(const TwistBipoint& b) const
  148. {
  149. return equal(point[0], b[0]) && equal(point[1], b[1]);
  150. }
  151. bool CurveBipoint::operator!=(const CurveBipoint& b) const
  152. {
  153. return !(*this == b);
  154. }
  155. bool TwistBipoint::operator!=(const TwistBipoint& b) const
  156. {
  157. return !(*this == b);
  158. }
  159. void CurveBipoint::make_affine()
  160. {
  161. if (!(fpe_isone(point[0]->m_z) || fpe_iszero(point[0]->m_z)))
  162. curvepoint_fp_makeaffine(point[0]);
  163. if (!(fpe_isone(point[1]->m_z) || fpe_iszero(point[1]->m_z)))
  164. curvepoint_fp_makeaffine(point[1]);
  165. }
  166. void TwistBipoint::make_affine()
  167. {
  168. if (!(fp2e_isone(point[0]->m_z) || fp2e_iszero(point[0]->m_z)))
  169. twistpoint_fp2_makeaffine(point[0]);
  170. if (!(fp2e_isone(point[1]->m_z) || fp2e_iszero(point[1]->m_z)))
  171. twistpoint_fp2_makeaffine(point[1]);
  172. }
  173. std::ostream& operator<<(std::ostream& os, const CurveBipoint& output)
  174. {
  175. CurveBipoint affine_out = output;
  176. affine_out.make_affine();
  177. for (int i = 0; i < 2; i++)
  178. {
  179. if ((os.flags() & std::ios::hex) && fpe_iszero(affine_out[i]->m_z))
  180. os << "Infinity";
  181. else
  182. os << Fpe(affine_out[i]->m_x) << Fpe(affine_out[i]->m_y) << Fpe(affine_out[i]->m_z);
  183. }
  184. return os;
  185. }
  186. std::istream& operator>>(std::istream& is, CurveBipoint& input)
  187. {
  188. Fpe x, y, z;
  189. for (int i = 0; i < 2; i++)
  190. {
  191. is >> x >> y >> z;
  192. fpe_set(input[i]->m_x, x.data);
  193. fpe_set(input[i]->m_y, y.data);
  194. fpe_set(input[i]->m_z, z.data);
  195. }
  196. return is;
  197. }
  198. std::ostream& operator<<(std::ostream& os, const TwistBipoint& output)
  199. {
  200. TwistBipoint affine_out = output;
  201. affine_out.make_affine();
  202. for (int i = 0; i < 2; i++)
  203. {
  204. if ((os.flags() & std::ios::hex) && fp2e_iszero(affine_out[i]->m_z))
  205. os << "Infinity";
  206. else
  207. os << Fp2e(affine_out[i]->m_x) << Fp2e(affine_out[i]->m_y) << Fp2e(affine_out[i]->m_z);
  208. }
  209. return os;
  210. }
  211. std::istream& operator>>(std::istream& is, TwistBipoint& input)
  212. {
  213. Fp2e x, y, z;
  214. for (int i = 0; i < 2; i++)
  215. {
  216. is >> x >> y >> z;
  217. fp2e_set(input[i]->m_x, x.data);
  218. fp2e_set(input[i]->m_y, y.data);
  219. fp2e_set(input[i]->m_z, z.data);
  220. }
  221. return is;
  222. }
  223. size_t CurveBipointHash::operator()(const CurveBipoint& x) const
  224. {
  225. size_t retval[2];
  226. bool infinity[2];
  227. CurveBipoint affine_x = x;
  228. std::hash<double> hasher;
  229. if (fpe_iszero(affine_x[0]->m_z))
  230. {
  231. retval[0] = 0;
  232. infinity[0] = true;
  233. }
  234. else
  235. {
  236. retval[0] = 0;
  237. infinity[0] = false;
  238. }
  239. if (fpe_iszero(affine_x[1]->m_z))
  240. {
  241. retval[1] = 0;
  242. infinity[1] = true;
  243. }
  244. else
  245. {
  246. retval[1] = 0;
  247. infinity[1] = false;
  248. }
  249. affine_x.make_affine();
  250. for (int i = 0; i < 2; i++)
  251. {
  252. for (int j = 0; j < 12 && !infinity[i]; j++)
  253. {
  254. retval[i] ^= hasher(affine_x[i]->m_x->v[j]);
  255. retval[i] ^= hasher(affine_x[i]->m_y->v[j]);
  256. }
  257. }
  258. return retval[0] ^ retval[1];
  259. }
  260. size_t TwistBipointHash::operator()(const TwistBipoint& x) const
  261. {
  262. size_t retval[2];
  263. bool infinity[2];
  264. TwistBipoint affine_x = x;
  265. std::hash<double> hasher;
  266. if (fp2e_iszero(affine_x[0]->m_z))
  267. {
  268. retval[0] = 0;
  269. infinity[0] = true;
  270. }
  271. else
  272. {
  273. retval[0] = 0;
  274. infinity[0] = false;
  275. }
  276. if (fp2e_iszero(affine_x[1]->m_z))
  277. {
  278. retval[1] = 0;
  279. infinity[1] = true;
  280. }
  281. else
  282. {
  283. retval[1] = 0;
  284. infinity[1] = false;
  285. }
  286. affine_x.make_affine();
  287. for (int i = 0; i < 2; i++)
  288. {
  289. for (int j = 0; j < 24 && !infinity[i]; j++)
  290. {
  291. retval[i] ^= hasher(affine_x[i]->m_x->v[j]);
  292. retval[i] ^= hasher(affine_x[i]->m_y->v[j]);
  293. }
  294. }
  295. return retval[0] ^ retval[1];
  296. }