Expand description
NIST P-521 (secp521r1).
The largest of the NIST prime curves, and the only one here whose field
width is not a multiple of 64 bits: p = 2^521 - 1, which needs nine limbs
of which the top carries nine significant bits. That awkwardness is confined
to this module’s constants and to the byte conversion in
crate::nist::arith; the group law and the schemes are the same generic
code P-256 and P-384 use.
Paired with SHA-512. The hash is 512 bits and the group order is 521, so
RFC 6979’s bits2int takes the digest whole with no truncation and no
shift — the one case where a shorter hash than the order is handled by doing
nothing.
§A Mersenne prime has conveniences
p = 2^521 - 1 means (p + 1) / 4 = 2^519 exactly, so a square root is 519
squarings with no multiplications at all. P521::sqrt says so directly
rather than running the generic square-and-multiply over an exponent that
happens to be a power of two.
Structs§
- Ecdh
P521 - ECDH over P-521.
- Ecdsa
P521 Sha512 - ECDSA over P-521 with SHA-512.
- Fn
- The P-521 scalar ring, Z/nZ where n is the order of the base point.
- Fp
- The P-521 coordinate field, GF(p) with p = 2^521 - 1.
- P521
- The P-521 curve.
Type Aliases§
- Affine
Point - A P-521 point in affine coordinates.
- Point
- A P-521 point in Jacobian coordinates.