pub const fn square(x: u8) -> u8Expand description
x * x in GF(2^8), without the bit-serial loop.
Squaring is linear over GF(2) – (a + b)^2 = a^2 + b^2, since the cross
term appears twice and cancels – so squaring a polynomial doubles every
exponent and nothing else. That is the bits of x spread apart with zeros
between them, followed by a reduction, where the general multiply runs its
bit-serial loop eight times round.
It matters because inv squares seven times and multiplies six: more than
half of the S-box was the general routine doing work that squaring does not
need. Only the even positions above 7 can be set after spreading, so the
reduction folds in four constants rather than seven.
Constant time: each constant is masked by its own bit, no branches.
squaring_matches_the_general_multiply checks this against mul(x, x) for
every one of the 256 inputs, which is the whole domain.