~/bend-docscommunity

src/crypto/secp256k1/field.bend checks

raw source on the hub · import 0xd9a2fae439ac7ff9e21e0853948f94fe/src/crypto/secp256k1/field.bend as Field

2 imports
import Base
import ./limbs.bend as L

Definitions

def c source · line 16 · raw

List<&2, Nat>

2^256 - p = 2^32 + 977

def reduce source · line 19 · raw

@xs:List<&2, Nat> -> List<&2, Nat>

def small source · line 22 · raw

@+k:Nat -> List<&2, Nat>

def zero source · line 25 · raw

List<&2, Nat>

def one source · line 28 · raw

List<&2, Nat>

def add_u source · line 35 · raw

@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>

def add_b source · line 38 · raw

@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>

def add source · line 43 · raw

@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>

def sub source · line 50 · raw

@a:List<&2, Nat> -> @+b:List<&2, Nat> -> List<&2, Nat>

a - b = a + (p - b); the first argument is looked at first, so that a constant b is never unfolded while a is unknown

def neg_u source · line 55 · raw

@a:List<&2, Nat> -> List<&2, Nat>

def neg source · line 59 · raw

@a:List<&2, Nat> -> List<&2, Nat>

(one argument: nothing to look at first)

def mul_u source · line 62 · raw

@a:List<&2, Nat> -> @+b:List<&2, Nat> -> List<&2, Nat>

def mul_b source · line 65 · raw

@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>

def mul source · line 70 · raw

@a:List<&2, Nat> -> @b:List<&2, Nat> -> List<&2, Nat>

def sq source · line 75 · raw

@+a:List<&2, Nat> -> List<&2, Nat>

def pow_step source · line 79 · raw

@b:Nat -> @+x:List<&2, Nat> -> @+s:List<&2, Nat> -> List<&2, Nat>

x^e for the exponent e given by its bits, most significant first

def pow_go source · line 84 · raw

@+x:List<&2, Nat> -> @bits:List<&2, Nat> -> @+acc:List<&2, Nat> -> List<&2, Nat>

def pow source · line 90 · raw

@x:List<&2, Nat> -> @bits:List<&2, Nat> -> @+acc:List<&2, Nat> -> List<&2, Nat>

x is looked at first, so that on an unknown x nothing is unfolded

def inv_bits source · line 96 · raw

List<&2, Nat>

the bits of p - 2 = 2^256 - 1 - (c + 1): those of c + 1, flipped

def init2 source · line 99 · raw

@xs:List<&2, Nat> -> List<&2, Nat>

def sqrt_bits source · line 103 · raw

List<&2, Nat>

the bits of (p + 1) / 4: p + 1 = 2^256 - 1 - (c - 2), without its last two bits

def inv source · line 107 · raw

@+a:List<&2, Nat> -> List<&2, Nat>

a^(p - 2): the inverse of a nonzero a, 0 for 0

def sqrt source · line 111 · raw

@+a:List<&2, Nat> -> List<&2, Nat>

a^((p + 1) / 4): a square root of a when a is a square (p = 3 mod 4)

def is_zero source · line 114 · raw

@a:List<&2, Nat> -> Bool

def eq_b source · line 117 · raw

@a:List<&2, Nat> -> @b:List<&2, Nat> -> Bool

def eq source · line 122 · raw

@a:List<&2, Nat> -> @b:List<&2, Nat> -> Bool

def parity source · line 128 · raw

@a:List<&2, Nat> -> Nat

a mod 2 (the parity of the canonical representative)

def lt_p source · line 132 · raw

@a:List<&2, Nat> -> Bool

a < p, for 16 limbs below 2^16

def select source · line 136 · raw

@+b:Nat -> @x:List<&2, Nat> -> @y:List<&2, Nat> -> List<&2, Nat>

b ? x : y, branch-free, for b in {0, 1}