field_element.go 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340
  1. // Copyright 2020 The go-ethereum Authors
  2. // This file is part of the go-ethereum library.
  3. //
  4. // The go-ethereum library is free software: you can redistribute it and/or modify
  5. // it under the terms of the GNU Lesser General Public License as published by
  6. // the Free Software Foundation, either version 3 of the License, or
  7. // (at your option) any later version.
  8. //
  9. // The go-ethereum library is distributed in the hope that it will be useful,
  10. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. // GNU Lesser General Public License for more details.
  13. //
  14. // You should have received a copy of the GNU Lesser General Public License
  15. // along with the go-ethereum library. If not, see <http://www.gnu.org/licenses/>.
  16. package bls12381
  17. import (
  18. "crypto/rand"
  19. "encoding/hex"
  20. "fmt"
  21. "io"
  22. "math/big"
  23. )
  24. // fe is base field element representation
  25. type fe [6]uint64
  26. // fe2 is element representation of 'fp2' which is quadratic extension of base field 'fp'
  27. // Representation follows c[0] + c[1] * u encoding order.
  28. type fe2 [2]fe
  29. // fe6 is element representation of 'fp6' field which is cubic extension of 'fp2'
  30. // Representation follows c[0] + c[1] * v + c[2] * v^2 encoding order.
  31. type fe6 [3]fe2
  32. // fe12 is element representation of 'fp12' field which is quadratic extension of 'fp6'
  33. // Representation follows c[0] + c[1] * w encoding order.
  34. type fe12 [2]fe6
  35. func (fe *fe) setBytes(in []byte) *fe {
  36. size := 48
  37. l := len(in)
  38. if l >= size {
  39. l = size
  40. }
  41. padded := make([]byte, size)
  42. copy(padded[size-l:], in[:])
  43. var a int
  44. for i := 0; i < 6; i++ {
  45. a = size - i*8
  46. fe[i] = uint64(padded[a-1]) | uint64(padded[a-2])<<8 |
  47. uint64(padded[a-3])<<16 | uint64(padded[a-4])<<24 |
  48. uint64(padded[a-5])<<32 | uint64(padded[a-6])<<40 |
  49. uint64(padded[a-7])<<48 | uint64(padded[a-8])<<56
  50. }
  51. return fe
  52. }
  53. func (fe *fe) setBig(a *big.Int) *fe {
  54. return fe.setBytes(a.Bytes())
  55. }
  56. func (fe *fe) setString(s string) (*fe, error) {
  57. if s[:2] == "0x" {
  58. s = s[2:]
  59. }
  60. bytes, err := hex.DecodeString(s)
  61. if err != nil {
  62. return nil, err
  63. }
  64. return fe.setBytes(bytes), nil
  65. }
  66. func (fe *fe) set(fe2 *fe) *fe {
  67. fe[0] = fe2[0]
  68. fe[1] = fe2[1]
  69. fe[2] = fe2[2]
  70. fe[3] = fe2[3]
  71. fe[4] = fe2[4]
  72. fe[5] = fe2[5]
  73. return fe
  74. }
  75. func (fe *fe) bytes() []byte {
  76. out := make([]byte, 48)
  77. var a int
  78. for i := 0; i < 6; i++ {
  79. a = 48 - i*8
  80. out[a-1] = byte(fe[i])
  81. out[a-2] = byte(fe[i] >> 8)
  82. out[a-3] = byte(fe[i] >> 16)
  83. out[a-4] = byte(fe[i] >> 24)
  84. out[a-5] = byte(fe[i] >> 32)
  85. out[a-6] = byte(fe[i] >> 40)
  86. out[a-7] = byte(fe[i] >> 48)
  87. out[a-8] = byte(fe[i] >> 56)
  88. }
  89. return out
  90. }
  91. func (fe *fe) big() *big.Int {
  92. return new(big.Int).SetBytes(fe.bytes())
  93. }
  94. func (fe *fe) string() (s string) {
  95. for i := 5; i >= 0; i-- {
  96. s = fmt.Sprintf("%s%16.16x", s, fe[i])
  97. }
  98. return "0x" + s
  99. }
  100. func (fe *fe) zero() *fe {
  101. fe[0] = 0
  102. fe[1] = 0
  103. fe[2] = 0
  104. fe[3] = 0
  105. fe[4] = 0
  106. fe[5] = 0
  107. return fe
  108. }
  109. func (fe *fe) one() *fe {
  110. return fe.set(r1)
  111. }
  112. func (fe *fe) rand(r io.Reader) (*fe, error) {
  113. bi, err := rand.Int(r, modulus.big())
  114. if err != nil {
  115. return nil, err
  116. }
  117. return fe.setBig(bi), nil
  118. }
  119. func (fe *fe) isValid() bool {
  120. return fe.cmp(&modulus) < 0
  121. }
  122. func (fe *fe) isOdd() bool {
  123. var mask uint64 = 1
  124. return fe[0]&mask != 0
  125. }
  126. func (fe *fe) isEven() bool {
  127. var mask uint64 = 1
  128. return fe[0]&mask == 0
  129. }
  130. func (fe *fe) isZero() bool {
  131. return (fe[5] | fe[4] | fe[3] | fe[2] | fe[1] | fe[0]) == 0
  132. }
  133. func (fe *fe) isOne() bool {
  134. return fe.equal(r1)
  135. }
  136. func (fe *fe) cmp(fe2 *fe) int {
  137. for i := 5; i >= 0; i-- {
  138. if fe[i] > fe2[i] {
  139. return 1
  140. } else if fe[i] < fe2[i] {
  141. return -1
  142. }
  143. }
  144. return 0
  145. }
  146. func (fe *fe) equal(fe2 *fe) bool {
  147. return fe2[0] == fe[0] && fe2[1] == fe[1] && fe2[2] == fe[2] && fe2[3] == fe[3] && fe2[4] == fe[4] && fe2[5] == fe[5]
  148. }
  149. func (e *fe) sign() bool {
  150. r := new(fe)
  151. fromMont(r, e)
  152. return r[0]&1 == 0
  153. }
  154. func (fe *fe) div2(e uint64) {
  155. fe[0] = fe[0]>>1 | fe[1]<<63
  156. fe[1] = fe[1]>>1 | fe[2]<<63
  157. fe[2] = fe[2]>>1 | fe[3]<<63
  158. fe[3] = fe[3]>>1 | fe[4]<<63
  159. fe[4] = fe[4]>>1 | fe[5]<<63
  160. fe[5] = fe[5]>>1 | e<<63
  161. }
  162. func (fe *fe) mul2() uint64 {
  163. e := fe[5] >> 63
  164. fe[5] = fe[5]<<1 | fe[4]>>63
  165. fe[4] = fe[4]<<1 | fe[3]>>63
  166. fe[3] = fe[3]<<1 | fe[2]>>63
  167. fe[2] = fe[2]<<1 | fe[1]>>63
  168. fe[1] = fe[1]<<1 | fe[0]>>63
  169. fe[0] = fe[0] << 1
  170. return e
  171. }
  172. func (e *fe2) zero() *fe2 {
  173. e[0].zero()
  174. e[1].zero()
  175. return e
  176. }
  177. func (e *fe2) one() *fe2 {
  178. e[0].one()
  179. e[1].zero()
  180. return e
  181. }
  182. func (e *fe2) set(e2 *fe2) *fe2 {
  183. e[0].set(&e2[0])
  184. e[1].set(&e2[1])
  185. return e
  186. }
  187. func (e *fe2) rand(r io.Reader) (*fe2, error) {
  188. a0, err := new(fe).rand(r)
  189. if err != nil {
  190. return nil, err
  191. }
  192. a1, err := new(fe).rand(r)
  193. if err != nil {
  194. return nil, err
  195. }
  196. return &fe2{*a0, *a1}, nil
  197. }
  198. func (e *fe2) isOne() bool {
  199. return e[0].isOne() && e[1].isZero()
  200. }
  201. func (e *fe2) isZero() bool {
  202. return e[0].isZero() && e[1].isZero()
  203. }
  204. func (e *fe2) equal(e2 *fe2) bool {
  205. return e[0].equal(&e2[0]) && e[1].equal(&e2[1])
  206. }
  207. func (e *fe2) sign() bool {
  208. r := new(fe)
  209. if !e[0].isZero() {
  210. fromMont(r, &e[0])
  211. return r[0]&1 == 0
  212. }
  213. fromMont(r, &e[1])
  214. return r[0]&1 == 0
  215. }
  216. func (e *fe6) zero() *fe6 {
  217. e[0].zero()
  218. e[1].zero()
  219. e[2].zero()
  220. return e
  221. }
  222. func (e *fe6) one() *fe6 {
  223. e[0].one()
  224. e[1].zero()
  225. e[2].zero()
  226. return e
  227. }
  228. func (e *fe6) set(e2 *fe6) *fe6 {
  229. e[0].set(&e2[0])
  230. e[1].set(&e2[1])
  231. e[2].set(&e2[2])
  232. return e
  233. }
  234. func (e *fe6) rand(r io.Reader) (*fe6, error) {
  235. a0, err := new(fe2).rand(r)
  236. if err != nil {
  237. return nil, err
  238. }
  239. a1, err := new(fe2).rand(r)
  240. if err != nil {
  241. return nil, err
  242. }
  243. a2, err := new(fe2).rand(r)
  244. if err != nil {
  245. return nil, err
  246. }
  247. return &fe6{*a0, *a1, *a2}, nil
  248. }
  249. func (e *fe6) isOne() bool {
  250. return e[0].isOne() && e[1].isZero() && e[2].isZero()
  251. }
  252. func (e *fe6) isZero() bool {
  253. return e[0].isZero() && e[1].isZero() && e[2].isZero()
  254. }
  255. func (e *fe6) equal(e2 *fe6) bool {
  256. return e[0].equal(&e2[0]) && e[1].equal(&e2[1]) && e[2].equal(&e2[2])
  257. }
  258. func (e *fe12) zero() *fe12 {
  259. e[0].zero()
  260. e[1].zero()
  261. return e
  262. }
  263. func (e *fe12) one() *fe12 {
  264. e[0].one()
  265. e[1].zero()
  266. return e
  267. }
  268. func (e *fe12) set(e2 *fe12) *fe12 {
  269. e[0].set(&e2[0])
  270. e[1].set(&e2[1])
  271. return e
  272. }
  273. func (e *fe12) rand(r io.Reader) (*fe12, error) {
  274. a0, err := new(fe6).rand(r)
  275. if err != nil {
  276. return nil, err
  277. }
  278. a1, err := new(fe6).rand(r)
  279. if err != nil {
  280. return nil, err
  281. }
  282. return &fe12{*a0, *a1}, nil
  283. }
  284. func (e *fe12) isOne() bool {
  285. return e[0].isOne() && e[1].isZero()
  286. }
  287. func (e *fe12) isZero() bool {
  288. return e[0].isZero() && e[1].isZero()
  289. }
  290. func (e *fe12) equal(e2 *fe12) bool {
  291. return e[0].equal(&e2[0]) && e[1].equal(&e2[1])
  292. }