~/bend-docscommunity

src/crypto/ed25519/scalar.bend checks

raw source on the hub · import 0xd9a2fae439ac7ff9e21e0853948f94fe/src/crypto/ed25519/scalar.bend as Scalar

3 imports
import Base
import ../curve25519/field.bend as F
import ../curve25519/x25519.bend as X

Definitions

def ell source · line 20 · raw

List<&2, U32>

L, little-endian bytes

def comp_l source · line 25 · raw

List<&2, U32>

2^256 - L

def csub source · line 30 · raw

@+x:List<&2, U32> -> List<&2, U32>

x - L when x >= L, else x (x tight, x < 2 L)

def addm source · line 33 · raw

@a:List<&2, U32> -> @b:List<&2, U32> -> List<&2, U32>

def mac source · line 37 · raw

@n:Nat -> @+bs:List<&2, U32> -> @+s:List<&2, U32> -> @+acc:List<&2, U32> -> List<&2, U32>

bits t = n - 1 down to 0 of bs: acc = 2 acc + bit s (mod L)

def reduce source · line 45 · raw

@+bs:List<&2, U32> -> List<&2, U32>

def mul_add source · line 48 · raw

@+k:List<&2, U32> -> @+s:List<&2, U32> -> @r:List<&2, U32> -> List<&2, U32>

def lt_l source · line 52 · raw

@+x:List<&2, U32> -> Bool

x < L: the carry of x + 2^256 - L is 0