Skip to main content

Point

Struct Point 

Source
pub struct Point { /* private fields */ }
Expand description

A point in extended twisted Edwards coordinates.

Implementations§

Source§

impl Point

Source

pub const IDENTITY: Point

The neutral element (0, 1).

Source

pub fn add(&self, other: &Point) -> Point

The complete add-2008-hwcd-3 group law for a = -1.

Source

pub fn double(&self) -> Point

Point doubling, dbl-2008-hwcd for a = -1.

Adding a point to itself works and was what this did, but the general addition costs nine multiplications and needs both operands’ T. The dedicated formula is four multiplications and four squarings, and does not read T at all – doubling is a function of X, Y and Z alone.

Worth the separate formula because scalar multiplication is doublings almost entirely: the non-adjacent form leaves about forty additions against two hundred and fifty-six doublings.

Source

pub fn mul_scalar(&self, s: &[u8; 32]) -> Point

Scalar multiplication, constant-time in the scalar.

Every iteration performs a doubling and an addition, selecting between the two results with a conditional move, so the instruction trace is identical for every scalar.

Source

pub fn mul_scalar_vartime(&self, scalar: &[u8; 32]) -> Point

Scalar multiplication that is not constant time.

§When this is allowed

Only on values an attacker already has. Verification is the case: the signature, the public key and the message are all public, so there is no secret whose timing could leak, and the constant-time ladder buys nothing there but work. Signing must never call this – the scalar is derived from the seed.

§What it does instead

A width-5 non-adjacent form. Recoding the scalar into signed odd digits leaves roughly one position in six non-zero, so the additions drop from one per bit to about forty in total; the doublings remain, because an arbitrary point has no precomputed table to take them away. Only odd multiples are stored, eight of them, since a negative digit negates on the way out.

The saving is real but bounded: the doublings dominate and they cannot be avoided here. The basepoint half of verification is the one that got a table.

Source

pub fn compress(&self) -> [u8; 32]

Compress to the 32-byte RFC 8032 encoding.

Source

pub fn decompress(bytes: &[u8; 32]) -> Option<Point>

Decompress a 32-byte encoding, rejecting non-curve points.

Trait Implementations§

Source§

impl Clone for Point

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Point

Source§

impl Debug for Point

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

§

impl Freeze for Point

§

impl RefUnwindSafe for Point

§

impl Send for Point

§

impl Sync for Point

§

impl Unpin for Point

§

impl UnsafeUnpin for Point

§

impl UnwindSafe for Point

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.