You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

170 lines
5.8 KiB

  1. // +build !amd64
  2. // Copyright 2020 ConsenSys AG
  3. //
  4. // Licensed under the Apache License, Version 2.0 (the "License");
  5. // you may not use this file except in compliance with the License.
  6. // You may obtain a copy of the License at
  7. //
  8. // http://www.apache.org/licenses/LICENSE-2.0
  9. //
  10. // Unless required by applicable law or agreed to in writing, software
  11. // distributed under the License is distributed on an "AS IS" BASIS,
  12. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. // See the License for the specific language governing permissions and
  14. // limitations under the License.
  15. // Code generated by goff (v0.2.0) DO NOT EDIT
  16. // Package ff contains field arithmetic operations
  17. package ff
  18. // /!\ WARNING /!\
  19. // this code has not been audited and is provided as-is. In particular,
  20. // there is no security guarantees such as constant time implementation
  21. // or side-channel attack resistance
  22. // /!\ WARNING /!\
  23. import "math/bits"
  24. // Mul z = x * y mod q
  25. // see https://hackmd.io/@zkteam/modular_multiplication
  26. func (z *Element) Mul(x, y *Element) *Element {
  27. var t [4]uint64
  28. var c [3]uint64
  29. {
  30. // round 0
  31. v := x[0]
  32. c[1], c[0] = bits.Mul64(v, y[0])
  33. m := c[0] * 14042775128853446655
  34. c[2] = madd0(m, 4891460686036598785, c[0])
  35. c[1], c[0] = madd1(v, y[1], c[1])
  36. c[2], t[0] = madd2(m, 2896914383306846353, c[2], c[0])
  37. c[1], c[0] = madd1(v, y[2], c[1])
  38. c[2], t[1] = madd2(m, 13281191951274694749, c[2], c[0])
  39. c[1], c[0] = madd1(v, y[3], c[1])
  40. t[3], t[2] = madd3(m, 3486998266802970665, c[0], c[2], c[1])
  41. }
  42. {
  43. // round 1
  44. v := x[1]
  45. c[1], c[0] = madd1(v, y[0], t[0])
  46. m := c[0] * 14042775128853446655
  47. c[2] = madd0(m, 4891460686036598785, c[0])
  48. c[1], c[0] = madd2(v, y[1], c[1], t[1])
  49. c[2], t[0] = madd2(m, 2896914383306846353, c[2], c[0])
  50. c[1], c[0] = madd2(v, y[2], c[1], t[2])
  51. c[2], t[1] = madd2(m, 13281191951274694749, c[2], c[0])
  52. c[1], c[0] = madd2(v, y[3], c[1], t[3])
  53. t[3], t[2] = madd3(m, 3486998266802970665, c[0], c[2], c[1])
  54. }
  55. {
  56. // round 2
  57. v := x[2]
  58. c[1], c[0] = madd1(v, y[0], t[0])
  59. m := c[0] * 14042775128853446655
  60. c[2] = madd0(m, 4891460686036598785, c[0])
  61. c[1], c[0] = madd2(v, y[1], c[1], t[1])
  62. c[2], t[0] = madd2(m, 2896914383306846353, c[2], c[0])
  63. c[1], c[0] = madd2(v, y[2], c[1], t[2])
  64. c[2], t[1] = madd2(m, 13281191951274694749, c[2], c[0])
  65. c[1], c[0] = madd2(v, y[3], c[1], t[3])
  66. t[3], t[2] = madd3(m, 3486998266802970665, c[0], c[2], c[1])
  67. }
  68. {
  69. // round 3
  70. v := x[3]
  71. c[1], c[0] = madd1(v, y[0], t[0])
  72. m := c[0] * 14042775128853446655
  73. c[2] = madd0(m, 4891460686036598785, c[0])
  74. c[1], c[0] = madd2(v, y[1], c[1], t[1])
  75. c[2], z[0] = madd2(m, 2896914383306846353, c[2], c[0])
  76. c[1], c[0] = madd2(v, y[2], c[1], t[2])
  77. c[2], z[1] = madd2(m, 13281191951274694749, c[2], c[0])
  78. c[1], c[0] = madd2(v, y[3], c[1], t[3])
  79. z[3], z[2] = madd3(m, 3486998266802970665, c[0], c[2], c[1])
  80. }
  81. // if z > q --> z -= q
  82. // note: this is NOT constant time
  83. if !(z[3] < 3486998266802970665 || (z[3] == 3486998266802970665 && (z[2] < 13281191951274694749 || (z[2] == 13281191951274694749 && (z[1] < 2896914383306846353 || (z[1] == 2896914383306846353 && (z[0] < 4891460686036598785))))))) {
  84. var b uint64
  85. z[0], b = bits.Sub64(z[0], 4891460686036598785, 0)
  86. z[1], b = bits.Sub64(z[1], 2896914383306846353, b)
  87. z[2], b = bits.Sub64(z[2], 13281191951274694749, b)
  88. z[3], _ = bits.Sub64(z[3], 3486998266802970665, b)
  89. }
  90. return z
  91. }
  92. // MulAssign z = z * x mod q
  93. // see https://hackmd.io/@zkteam/modular_multiplication
  94. func (z *Element) MulAssign(x *Element) *Element {
  95. var t [4]uint64
  96. var c [3]uint64
  97. {
  98. // round 0
  99. v := z[0]
  100. c[1], c[0] = bits.Mul64(v, x[0])
  101. m := c[0] * 14042775128853446655
  102. c[2] = madd0(m, 4891460686036598785, c[0])
  103. c[1], c[0] = madd1(v, x[1], c[1])
  104. c[2], t[0] = madd2(m, 2896914383306846353, c[2], c[0])
  105. c[1], c[0] = madd1(v, x[2], c[1])
  106. c[2], t[1] = madd2(m, 13281191951274694749, c[2], c[0])
  107. c[1], c[0] = madd1(v, x[3], c[1])
  108. t[3], t[2] = madd3(m, 3486998266802970665, c[0], c[2], c[1])
  109. }
  110. {
  111. // round 1
  112. v := z[1]
  113. c[1], c[0] = madd1(v, x[0], t[0])
  114. m := c[0] * 14042775128853446655
  115. c[2] = madd0(m, 4891460686036598785, c[0])
  116. c[1], c[0] = madd2(v, x[1], c[1], t[1])
  117. c[2], t[0] = madd2(m, 2896914383306846353, c[2], c[0])
  118. c[1], c[0] = madd2(v, x[2], c[1], t[2])
  119. c[2], t[1] = madd2(m, 13281191951274694749, c[2], c[0])
  120. c[1], c[0] = madd2(v, x[3], c[1], t[3])
  121. t[3], t[2] = madd3(m, 3486998266802970665, c[0], c[2], c[1])
  122. }
  123. {
  124. // round 2
  125. v := z[2]
  126. c[1], c[0] = madd1(v, x[0], t[0])
  127. m := c[0] * 14042775128853446655
  128. c[2] = madd0(m, 4891460686036598785, c[0])
  129. c[1], c[0] = madd2(v, x[1], c[1], t[1])
  130. c[2], t[0] = madd2(m, 2896914383306846353, c[2], c[0])
  131. c[1], c[0] = madd2(v, x[2], c[1], t[2])
  132. c[2], t[1] = madd2(m, 13281191951274694749, c[2], c[0])
  133. c[1], c[0] = madd2(v, x[3], c[1], t[3])
  134. t[3], t[2] = madd3(m, 3486998266802970665, c[0], c[2], c[1])
  135. }
  136. {
  137. // round 3
  138. v := z[3]
  139. c[1], c[0] = madd1(v, x[0], t[0])
  140. m := c[0] * 14042775128853446655
  141. c[2] = madd0(m, 4891460686036598785, c[0])
  142. c[1], c[0] = madd2(v, x[1], c[1], t[1])
  143. c[2], z[0] = madd2(m, 2896914383306846353, c[2], c[0])
  144. c[1], c[0] = madd2(v, x[2], c[1], t[2])
  145. c[2], z[1] = madd2(m, 13281191951274694749, c[2], c[0])
  146. c[1], c[0] = madd2(v, x[3], c[1], t[3])
  147. z[3], z[2] = madd3(m, 3486998266802970665, c[0], c[2], c[1])
  148. }
  149. // if z > q --> z -= q
  150. // note: this is NOT constant time
  151. if !(z[3] < 3486998266802970665 || (z[3] == 3486998266802970665 && (z[2] < 13281191951274694749 || (z[2] == 13281191951274694749 && (z[1] < 2896914383306846353 || (z[1] == 2896914383306846353 && (z[0] < 4891460686036598785))))))) {
  152. var b uint64
  153. z[0], b = bits.Sub64(z[0], 4891460686036598785, 0)
  154. z[1], b = bits.Sub64(z[1], 2896914383306846353, b)
  155. z[2], b = bits.Sub64(z[2], 13281191951274694749, b)
  156. z[3], _ = bits.Sub64(z[3], 3486998266802970665, b)
  157. }
  158. return z
  159. }