src/crypto/secp256k1/field.bend checks
raw source on the hub · import 0xd9a2fae439ac7ff9e21e0853948f94fe/src/crypto/secp256k1/field.bend as Field
2 imports
import Base import ./limbs.bend as L
Definitions
def c source · line 16 · raw
List<&2, Nat>
2^256 - p = 2^32 + 977
def reduce source · line 19 · raw
@xs:List<&2, Nat> -> List<&2, Nat>
def small source · line 22 · raw
@+k:Nat -> List<&2, Nat>
def zero source · line 25 · raw
List<&2, Nat>
def one source · line 28 · raw
List<&2, Nat>
def add_u source · line 35 · raw
@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>
def add_b source · line 38 · raw
@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>
def add source · line 43 · raw
@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>
def sub source · line 50 · raw
@a:List<&2, Nat> -> @+b:List<&2, Nat> -> List<&2, Nat>
a - b = a + (p - b); the first argument is looked at first, so that a constant b is never unfolded while a is unknown
def neg_u source · line 55 · raw
@a:List<&2, Nat> -> List<&2, Nat>
def neg source · line 59 · raw
@a:List<&2, Nat> -> List<&2, Nat>
(one argument: nothing to look at first)
def mul_u source · line 62 · raw
@a:List<&2, Nat> -> @+b:List<&2, Nat> -> List<&2, Nat>
def mul_b source · line 65 · raw
@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>
def mul source · line 70 · raw
@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>
def sq source · line 75 · raw
@+a:List<&2, Nat> -> List<&2, Nat>
def pow_step source · line 79 · raw
@b:Nat -> @+x:List<&2, Nat> -> @+s:List<&2, Nat> -> List<&2, Nat>
x^e for the exponent e given by its bits, most significant first
def pow_go source · line 84 · raw
@+x:List<&2, Nat> -> @bits:List<&2, Nat> -> @+acc:List<&2, Nat> -> List<&2, Nat>
def pow source · line 90 · raw
@x:List<&2, Nat> -> @bits:List<&2, Nat> -> @+acc:List<&2, Nat> -> List<&2, Nat>
x is looked at first, so that on an unknown x nothing is unfolded
def inv_bits source · line 96 · raw
List<&2, Nat>
the bits of p - 2 = 2^256 - 1 - (c + 1): those of c + 1, flipped
def init2 source · line 99 · raw
@xs:List<&2, Nat> -> List<&2, Nat>
def sqrt_bits source · line 103 · raw
List<&2, Nat>
the bits of (p + 1) / 4: p + 1 = 2^256 - 1 - (c - 2), without its last two bits
def inv source · line 107 · raw
@+a:List<&2, Nat> -> List<&2, Nat>
a^(p - 2): the inverse of a nonzero a, 0 for 0
def sqrt source · line 111 · raw
@+a:List<&2, Nat> -> List<&2, Nat>
a^((p + 1) / 4): a square root of a when a is a square (p = 3 mod 4)
def is_zero source · line 114 · raw
@a:List<&2, Nat> -> Bool
def eq_b source · line 117 · raw
@a:List<&2, Nat> -> @b:List<&2, Nat> -> Bool
def eq source · line 122 · raw
@a:List<&2, Nat> -> @b:List<&2, Nat> -> Bool
def parity source · line 128 · raw
@a:List<&2, Nat> -> Nat
a mod 2 (the parity of the canonical representative)
def lt_p source · line 132 · raw
@a:List<&2, Nat> -> Bool
a < p, for 16 limbs below 2^16
def select source · line 136 · raw
@+b:Nat -> @x:List<&2, Nat> -> @y:List<&2, Nat> -> List<&2, Nat>
b ? x : y, branch-free, for b in {0, 1}