fp_test.go 30 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412
  1. package bls12381
  2. import (
  3. "bytes"
  4. "crypto/rand"
  5. "math/big"
  6. "testing"
  7. )
  8. func TestFpSerialization(t *testing.T) {
  9. t.Run("zero", func(t *testing.T) {
  10. in := make([]byte, 48)
  11. fe, err := fromBytes(in)
  12. if err != nil {
  13. t.Fatal(err)
  14. }
  15. if !fe.isZero() {
  16. t.Fatal("bad serialization")
  17. }
  18. if !bytes.Equal(in, toBytes(fe)) {
  19. t.Fatal("bad serialization")
  20. }
  21. })
  22. t.Run("bytes", func(t *testing.T) {
  23. for i := 0; i < fuz; i++ {
  24. a, _ := new(fe).rand(rand.Reader)
  25. b, err := fromBytes(toBytes(a))
  26. if err != nil {
  27. t.Fatal(err)
  28. }
  29. if !a.equal(b) {
  30. t.Fatal("bad serialization")
  31. }
  32. }
  33. })
  34. t.Run("string", func(t *testing.T) {
  35. for i := 0; i < fuz; i++ {
  36. a, _ := new(fe).rand(rand.Reader)
  37. b, err := fromString(toString(a))
  38. if err != nil {
  39. t.Fatal(err)
  40. }
  41. if !a.equal(b) {
  42. t.Fatal("bad encoding or decoding")
  43. }
  44. }
  45. })
  46. t.Run("big", func(t *testing.T) {
  47. for i := 0; i < fuz; i++ {
  48. a, _ := new(fe).rand(rand.Reader)
  49. b, err := fromBig(toBig(a))
  50. if err != nil {
  51. t.Fatal(err)
  52. }
  53. if !a.equal(b) {
  54. t.Fatal("bad encoding or decoding")
  55. }
  56. }
  57. })
  58. }
  59. func TestFpAdditionCrossAgainstBigInt(t *testing.T) {
  60. for i := 0; i < fuz; i++ {
  61. a, _ := new(fe).rand(rand.Reader)
  62. b, _ := new(fe).rand(rand.Reader)
  63. c := new(fe)
  64. big_a := toBig(a)
  65. big_b := toBig(b)
  66. big_c := new(big.Int)
  67. add(c, a, b)
  68. out_1 := toBytes(c)
  69. out_2 := padBytes(big_c.Add(big_a, big_b).Mod(big_c, modulus.big()).Bytes(), 48)
  70. if !bytes.Equal(out_1, out_2) {
  71. t.Fatal("cross test against big.Int is not satisfied A")
  72. }
  73. double(c, a)
  74. out_1 = toBytes(c)
  75. out_2 = padBytes(big_c.Add(big_a, big_a).Mod(big_c, modulus.big()).Bytes(), 48)
  76. if !bytes.Equal(out_1, out_2) {
  77. t.Fatal("cross test against big.Int is not satisfied B")
  78. }
  79. sub(c, a, b)
  80. out_1 = toBytes(c)
  81. out_2 = padBytes(big_c.Sub(big_a, big_b).Mod(big_c, modulus.big()).Bytes(), 48)
  82. if !bytes.Equal(out_1, out_2) {
  83. t.Fatal("cross test against big.Int is not satisfied C")
  84. }
  85. neg(c, a)
  86. out_1 = toBytes(c)
  87. out_2 = padBytes(big_c.Neg(big_a).Mod(big_c, modulus.big()).Bytes(), 48)
  88. if !bytes.Equal(out_1, out_2) {
  89. t.Fatal("cross test against big.Int is not satisfied D")
  90. }
  91. }
  92. }
  93. func TestFpAdditionCrossAgainstBigIntAssigned(t *testing.T) {
  94. for i := 0; i < fuz; i++ {
  95. a, _ := new(fe).rand(rand.Reader)
  96. b, _ := new(fe).rand(rand.Reader)
  97. big_a, big_b := toBig(a), toBig(b)
  98. addAssign(a, b)
  99. out_1 := toBytes(a)
  100. out_2 := padBytes(big_a.Add(big_a, big_b).Mod(big_a, modulus.big()).Bytes(), 48)
  101. if !bytes.Equal(out_1, out_2) {
  102. t.Fatal("cross test against big.Int is not satisfied A")
  103. }
  104. a, _ = new(fe).rand(rand.Reader)
  105. big_a = toBig(a)
  106. doubleAssign(a)
  107. out_1 = toBytes(a)
  108. out_2 = padBytes(big_a.Add(big_a, big_a).Mod(big_a, modulus.big()).Bytes(), 48)
  109. if !bytes.Equal(out_1, out_2) {
  110. t.Fatal("cross test against big.Int is not satisfied B")
  111. }
  112. a, _ = new(fe).rand(rand.Reader)
  113. b, _ = new(fe).rand(rand.Reader)
  114. big_a, big_b = toBig(a), toBig(b)
  115. subAssign(a, b)
  116. out_1 = toBytes(a)
  117. out_2 = padBytes(big_a.Sub(big_a, big_b).Mod(big_a, modulus.big()).Bytes(), 48)
  118. if !bytes.Equal(out_1, out_2) {
  119. t.Fatal("cross test against big.Int is not satisfied A")
  120. }
  121. }
  122. }
  123. func TestFpAdditionProperties(t *testing.T) {
  124. for i := 0; i < fuz; i++ {
  125. zero := new(fe).zero()
  126. a, _ := new(fe).rand(rand.Reader)
  127. b, _ := new(fe).rand(rand.Reader)
  128. c_1, c_2 := new(fe), new(fe)
  129. add(c_1, a, zero)
  130. if !c_1.equal(a) {
  131. t.Fatal("a + 0 == a")
  132. }
  133. sub(c_1, a, zero)
  134. if !c_1.equal(a) {
  135. t.Fatal("a - 0 == a")
  136. }
  137. double(c_1, zero)
  138. if !c_1.equal(zero) {
  139. t.Fatal("2 * 0 == 0")
  140. }
  141. neg(c_1, zero)
  142. if !c_1.equal(zero) {
  143. t.Fatal("-0 == 0")
  144. }
  145. sub(c_1, zero, a)
  146. neg(c_2, a)
  147. if !c_1.equal(c_2) {
  148. t.Fatal("0-a == -a")
  149. }
  150. double(c_1, a)
  151. add(c_2, a, a)
  152. if !c_1.equal(c_2) {
  153. t.Fatal("2 * a == a + a")
  154. }
  155. add(c_1, a, b)
  156. add(c_2, b, a)
  157. if !c_1.equal(c_2) {
  158. t.Fatal("a + b = b + a")
  159. }
  160. sub(c_1, a, b)
  161. sub(c_2, b, a)
  162. neg(c_2, c_2)
  163. if !c_1.equal(c_2) {
  164. t.Fatal("a - b = - ( b - a )")
  165. }
  166. c_x, _ := new(fe).rand(rand.Reader)
  167. add(c_1, a, b)
  168. add(c_1, c_1, c_x)
  169. add(c_2, a, c_x)
  170. add(c_2, c_2, b)
  171. if !c_1.equal(c_2) {
  172. t.Fatal("(a + b) + c == (a + c ) + b")
  173. }
  174. sub(c_1, a, b)
  175. sub(c_1, c_1, c_x)
  176. sub(c_2, a, c_x)
  177. sub(c_2, c_2, b)
  178. if !c_1.equal(c_2) {
  179. t.Fatal("(a - b) - c == (a - c ) -b")
  180. }
  181. }
  182. }
  183. func TestFpAdditionPropertiesAssigned(t *testing.T) {
  184. for i := 0; i < fuz; i++ {
  185. zero := new(fe).zero()
  186. a, b := new(fe), new(fe)
  187. _, _ = a.rand(rand.Reader)
  188. b.set(a)
  189. addAssign(a, zero)
  190. if !a.equal(b) {
  191. t.Fatal("a + 0 == a")
  192. }
  193. subAssign(a, zero)
  194. if !a.equal(b) {
  195. t.Fatal("a - 0 == a")
  196. }
  197. a.set(zero)
  198. doubleAssign(a)
  199. if !a.equal(zero) {
  200. t.Fatal("2 * 0 == 0")
  201. }
  202. a.set(zero)
  203. subAssign(a, b)
  204. neg(b, b)
  205. if !a.equal(b) {
  206. t.Fatal("0-a == -a")
  207. }
  208. _, _ = a.rand(rand.Reader)
  209. b.set(a)
  210. doubleAssign(a)
  211. addAssign(b, b)
  212. if !a.equal(b) {
  213. t.Fatal("2 * a == a + a")
  214. }
  215. _, _ = a.rand(rand.Reader)
  216. _, _ = b.rand(rand.Reader)
  217. c_1, c_2 := new(fe).set(a), new(fe).set(b)
  218. addAssign(c_1, b)
  219. addAssign(c_2, a)
  220. if !c_1.equal(c_2) {
  221. t.Fatal("a + b = b + a")
  222. }
  223. _, _ = a.rand(rand.Reader)
  224. _, _ = b.rand(rand.Reader)
  225. c_1.set(a)
  226. c_2.set(b)
  227. subAssign(c_1, b)
  228. subAssign(c_2, a)
  229. neg(c_2, c_2)
  230. if !c_1.equal(c_2) {
  231. t.Fatal("a - b = - ( b - a )")
  232. }
  233. _, _ = a.rand(rand.Reader)
  234. _, _ = b.rand(rand.Reader)
  235. c, _ := new(fe).rand(rand.Reader)
  236. a0 := new(fe).set(a)
  237. addAssign(a, b)
  238. addAssign(a, c)
  239. addAssign(b, c)
  240. addAssign(b, a0)
  241. if !a.equal(b) {
  242. t.Fatal("(a + b) + c == (b + c) + a")
  243. }
  244. _, _ = a.rand(rand.Reader)
  245. _, _ = b.rand(rand.Reader)
  246. _, _ = c.rand(rand.Reader)
  247. a0.set(a)
  248. subAssign(a, b)
  249. subAssign(a, c)
  250. subAssign(a0, c)
  251. subAssign(a0, b)
  252. if !a.equal(a0) {
  253. t.Fatal("(a - b) - c == (a - c) -b")
  254. }
  255. }
  256. }
  257. func TestFpLazyOperations(t *testing.T) {
  258. for i := 0; i < fuz; i++ {
  259. a, _ := new(fe).rand(rand.Reader)
  260. b, _ := new(fe).rand(rand.Reader)
  261. c, _ := new(fe).rand(rand.Reader)
  262. c0 := new(fe)
  263. c1 := new(fe)
  264. ladd(c0, a, b)
  265. add(c1, a, b)
  266. mul(c0, c0, c)
  267. mul(c1, c1, c)
  268. if !c0.equal(c1) {
  269. // l+ operator stands for lazy addition
  270. t.Fatal("(a + b) * c == (a l+ b) * c")
  271. }
  272. _, _ = a.rand(rand.Reader)
  273. b.set(a)
  274. ldouble(a, a)
  275. ladd(b, b, b)
  276. if !a.equal(b) {
  277. t.Fatal("2 l* a = a l+ a")
  278. }
  279. _, _ = a.rand(rand.Reader)
  280. _, _ = b.rand(rand.Reader)
  281. _, _ = c.rand(rand.Reader)
  282. a0 := new(fe).set(a)
  283. lsubAssign(a, b)
  284. laddAssign(a, &modulus)
  285. mul(a, a, c)
  286. subAssign(a0, b)
  287. mul(a0, a0, c)
  288. if !a.equal(a0) {
  289. t.Fatal("((a l- b) + p) * c = (a-b) * c")
  290. }
  291. }
  292. }
  293. func TestFpMultiplicationCrossAgainstBigInt(t *testing.T) {
  294. for i := 0; i < fuz; i++ {
  295. a, _ := new(fe).rand(rand.Reader)
  296. b, _ := new(fe).rand(rand.Reader)
  297. c := new(fe)
  298. big_a := toBig(a)
  299. big_b := toBig(b)
  300. big_c := new(big.Int)
  301. mul(c, a, b)
  302. out_1 := toBytes(c)
  303. out_2 := padBytes(big_c.Mul(big_a, big_b).Mod(big_c, modulus.big()).Bytes(), 48)
  304. if !bytes.Equal(out_1, out_2) {
  305. t.Fatal("cross test against big.Int is not satisfied")
  306. }
  307. }
  308. }
  309. func TestFpMultiplicationProperties(t *testing.T) {
  310. for i := 0; i < fuz; i++ {
  311. a, _ := new(fe).rand(rand.Reader)
  312. b, _ := new(fe).rand(rand.Reader)
  313. zero, one := new(fe).zero(), new(fe).one()
  314. c_1, c_2 := new(fe), new(fe)
  315. mul(c_1, a, zero)
  316. if !c_1.equal(zero) {
  317. t.Fatal("a * 0 == 0")
  318. }
  319. mul(c_1, a, one)
  320. if !c_1.equal(a) {
  321. t.Fatal("a * 1 == a")
  322. }
  323. mul(c_1, a, b)
  324. mul(c_2, b, a)
  325. if !c_1.equal(c_2) {
  326. t.Fatal("a * b == b * a")
  327. }
  328. c_x, _ := new(fe).rand(rand.Reader)
  329. mul(c_1, a, b)
  330. mul(c_1, c_1, c_x)
  331. mul(c_2, c_x, b)
  332. mul(c_2, c_2, a)
  333. if !c_1.equal(c_2) {
  334. t.Fatal("(a * b) * c == (a * c) * b")
  335. }
  336. square(a, zero)
  337. if !a.equal(zero) {
  338. t.Fatal("0^2 == 0")
  339. }
  340. square(a, one)
  341. if !a.equal(one) {
  342. t.Fatal("1^2 == 1")
  343. }
  344. _, _ = a.rand(rand.Reader)
  345. square(c_1, a)
  346. mul(c_2, a, a)
  347. if !c_1.equal(c_1) {
  348. t.Fatal("a^2 == a*a")
  349. }
  350. }
  351. }
  352. func TestFpExponentiation(t *testing.T) {
  353. for i := 0; i < fuz; i++ {
  354. a, _ := new(fe).rand(rand.Reader)
  355. u := new(fe)
  356. exp(u, a, big.NewInt(0))
  357. if !u.isOne() {
  358. t.Fatal("a^0 == 1")
  359. }
  360. exp(u, a, big.NewInt(1))
  361. if !u.equal(a) {
  362. t.Fatal("a^1 == a")
  363. }
  364. v := new(fe)
  365. mul(u, a, a)
  366. mul(u, u, u)
  367. mul(u, u, u)
  368. exp(v, a, big.NewInt(8))
  369. if !u.equal(v) {
  370. t.Fatal("((a^2)^2)^2 == a^8")
  371. }
  372. p := modulus.big()
  373. exp(u, a, p)
  374. if !u.equal(a) {
  375. t.Fatal("a^p == a")
  376. }
  377. exp(u, a, p.Sub(p, big.NewInt(1)))
  378. if !u.isOne() {
  379. t.Fatal("a^(p-1) == 1")
  380. }
  381. }
  382. }
  383. func TestFpInversion(t *testing.T) {
  384. for i := 0; i < fuz; i++ {
  385. u := new(fe)
  386. zero, one := new(fe).zero(), new(fe).one()
  387. inverse(u, zero)
  388. if !u.equal(zero) {
  389. t.Fatal("(0^-1) == 0)")
  390. }
  391. inverse(u, one)
  392. if !u.equal(one) {
  393. t.Fatal("(1^-1) == 1)")
  394. }
  395. a, _ := new(fe).rand(rand.Reader)
  396. inverse(u, a)
  397. mul(u, u, a)
  398. if !u.equal(one) {
  399. t.Fatal("(r*a) * r*(a^-1) == r)")
  400. }
  401. v := new(fe)
  402. p := modulus.big()
  403. exp(u, a, p.Sub(p, big.NewInt(2)))
  404. inverse(v, a)
  405. if !v.equal(u) {
  406. t.Fatal("a^(p-2) == a^-1")
  407. }
  408. }
  409. }
  410. func TestFpSquareRoot(t *testing.T) {
  411. r := new(fe)
  412. if sqrt(r, nonResidue1) {
  413. t.Fatal("non residue cannot have a sqrt")
  414. }
  415. for i := 0; i < fuz; i++ {
  416. a, _ := new(fe).rand(rand.Reader)
  417. aa, rr, r := &fe{}, &fe{}, &fe{}
  418. square(aa, a)
  419. if !sqrt(r, aa) {
  420. t.Fatal("bad sqrt 1")
  421. }
  422. square(rr, r)
  423. if !rr.equal(aa) {
  424. t.Fatal("bad sqrt 2")
  425. }
  426. }
  427. }
  428. func TestFpNonResidue(t *testing.T) {
  429. if !isQuadraticNonResidue(nonResidue1) {
  430. t.Fatal("element is quadratic non residue, 1")
  431. }
  432. if isQuadraticNonResidue(new(fe).one()) {
  433. t.Fatal("one is not quadratic non residue")
  434. }
  435. if !isQuadraticNonResidue(new(fe).zero()) {
  436. t.Fatal("should accept zero as quadratic non residue")
  437. }
  438. for i := 0; i < fuz; i++ {
  439. a, _ := new(fe).rand(rand.Reader)
  440. square(a, a)
  441. if isQuadraticNonResidue(new(fe).one()) {
  442. t.Fatal("element is not quadratic non residue")
  443. }
  444. }
  445. for i := 0; i < fuz; i++ {
  446. a, _ := new(fe).rand(rand.Reader)
  447. if !sqrt(new(fe), a) {
  448. if !isQuadraticNonResidue(a) {
  449. t.Fatal("element is quadratic non residue, 2", i)
  450. }
  451. } else {
  452. i -= 1
  453. }
  454. }
  455. }
  456. func TestFp2Serialization(t *testing.T) {
  457. field := newFp2()
  458. for i := 0; i < fuz; i++ {
  459. a, _ := new(fe2).rand(rand.Reader)
  460. b, err := field.fromBytes(field.toBytes(a))
  461. if err != nil {
  462. t.Fatal(err)
  463. }
  464. if !a.equal(b) {
  465. t.Fatal("bad serialization")
  466. }
  467. }
  468. }
  469. func TestFp2AdditionProperties(t *testing.T) {
  470. field := newFp2()
  471. for i := 0; i < fuz; i++ {
  472. zero := field.zero()
  473. a, _ := new(fe2).rand(rand.Reader)
  474. b, _ := new(fe2).rand(rand.Reader)
  475. c_1 := field.new()
  476. c_2 := field.new()
  477. field.add(c_1, a, zero)
  478. if !c_1.equal(a) {
  479. t.Fatal("a + 0 == a")
  480. }
  481. field.sub(c_1, a, zero)
  482. if !c_1.equal(a) {
  483. t.Fatal("a - 0 == a")
  484. }
  485. field.double(c_1, zero)
  486. if !c_1.equal(zero) {
  487. t.Fatal("2 * 0 == 0")
  488. }
  489. field.neg(c_1, zero)
  490. if !c_1.equal(zero) {
  491. t.Fatal("-0 == 0")
  492. }
  493. field.sub(c_1, zero, a)
  494. field.neg(c_2, a)
  495. if !c_1.equal(c_2) {
  496. t.Fatal("0-a == -a")
  497. }
  498. field.double(c_1, a)
  499. field.add(c_2, a, a)
  500. if !c_1.equal(c_2) {
  501. t.Fatal("2 * a == a + a")
  502. }
  503. field.add(c_1, a, b)
  504. field.add(c_2, b, a)
  505. if !c_1.equal(c_2) {
  506. t.Fatal("a + b = b + a")
  507. }
  508. field.sub(c_1, a, b)
  509. field.sub(c_2, b, a)
  510. field.neg(c_2, c_2)
  511. if !c_1.equal(c_2) {
  512. t.Fatal("a - b = - ( b - a )")
  513. }
  514. c_x, _ := new(fe2).rand(rand.Reader)
  515. field.add(c_1, a, b)
  516. field.add(c_1, c_1, c_x)
  517. field.add(c_2, a, c_x)
  518. field.add(c_2, c_2, b)
  519. if !c_1.equal(c_2) {
  520. t.Fatal("(a + b) + c == (a + c ) + b")
  521. }
  522. field.sub(c_1, a, b)
  523. field.sub(c_1, c_1, c_x)
  524. field.sub(c_2, a, c_x)
  525. field.sub(c_2, c_2, b)
  526. if !c_1.equal(c_2) {
  527. t.Fatal("(a - b) - c == (a - c ) -b")
  528. }
  529. }
  530. }
  531. func TestFp2AdditionPropertiesAssigned(t *testing.T) {
  532. field := newFp2()
  533. for i := 0; i < fuz; i++ {
  534. zero := new(fe2).zero()
  535. a, b := new(fe2), new(fe2)
  536. _, _ = a.rand(rand.Reader)
  537. b.set(a)
  538. field.addAssign(a, zero)
  539. if !a.equal(b) {
  540. t.Fatal("a + 0 == a")
  541. }
  542. field.subAssign(a, zero)
  543. if !a.equal(b) {
  544. t.Fatal("a - 0 == a")
  545. }
  546. a.set(zero)
  547. field.doubleAssign(a)
  548. if !a.equal(zero) {
  549. t.Fatal("2 * 0 == 0")
  550. }
  551. a.set(zero)
  552. field.subAssign(a, b)
  553. field.neg(b, b)
  554. if !a.equal(b) {
  555. t.Fatal("0-a == -a")
  556. }
  557. _, _ = a.rand(rand.Reader)
  558. b.set(a)
  559. field.doubleAssign(a)
  560. field.addAssign(b, b)
  561. if !a.equal(b) {
  562. t.Fatal("2 * a == a + a")
  563. }
  564. _, _ = a.rand(rand.Reader)
  565. _, _ = b.rand(rand.Reader)
  566. c_1, c_2 := new(fe2).set(a), new(fe2).set(b)
  567. field.addAssign(c_1, b)
  568. field.addAssign(c_2, a)
  569. if !c_1.equal(c_2) {
  570. t.Fatal("a + b = b + a")
  571. }
  572. _, _ = a.rand(rand.Reader)
  573. _, _ = b.rand(rand.Reader)
  574. c_1.set(a)
  575. c_2.set(b)
  576. field.subAssign(c_1, b)
  577. field.subAssign(c_2, a)
  578. field.neg(c_2, c_2)
  579. if !c_1.equal(c_2) {
  580. t.Fatal("a - b = - ( b - a )")
  581. }
  582. _, _ = a.rand(rand.Reader)
  583. _, _ = b.rand(rand.Reader)
  584. c, _ := new(fe2).rand(rand.Reader)
  585. a0 := new(fe2).set(a)
  586. field.addAssign(a, b)
  587. field.addAssign(a, c)
  588. field.addAssign(b, c)
  589. field.addAssign(b, a0)
  590. if !a.equal(b) {
  591. t.Fatal("(a + b) + c == (b + c) + a")
  592. }
  593. _, _ = a.rand(rand.Reader)
  594. _, _ = b.rand(rand.Reader)
  595. _, _ = c.rand(rand.Reader)
  596. a0.set(a)
  597. field.subAssign(a, b)
  598. field.subAssign(a, c)
  599. field.subAssign(a0, c)
  600. field.subAssign(a0, b)
  601. if !a.equal(a0) {
  602. t.Fatal("(a - b) - c == (a - c) -b")
  603. }
  604. }
  605. }
  606. func TestFp2LazyOperations(t *testing.T) {
  607. field := newFp2()
  608. for i := 0; i < fuz; i++ {
  609. a, _ := new(fe2).rand(rand.Reader)
  610. b, _ := new(fe2).rand(rand.Reader)
  611. c, _ := new(fe2).rand(rand.Reader)
  612. c0 := new(fe2)
  613. c1 := new(fe2)
  614. field.ladd(c0, a, b)
  615. field.add(c1, a, b)
  616. field.mulAssign(c0, c)
  617. field.mulAssign(c1, c)
  618. if !c0.equal(c1) {
  619. // l+ operator stands for lazy addition
  620. t.Fatal("(a + b) * c == (a l+ b) * c")
  621. }
  622. _, _ = a.rand(rand.Reader)
  623. b.set(a)
  624. field.ldouble(a, a)
  625. field.ladd(b, b, b)
  626. if !a.equal(b) {
  627. t.Fatal("2 l* a = a l+ a")
  628. }
  629. }
  630. }
  631. func TestFp2MultiplicationProperties(t *testing.T) {
  632. field := newFp2()
  633. for i := 0; i < fuz; i++ {
  634. a, _ := new(fe2).rand(rand.Reader)
  635. b, _ := new(fe2).rand(rand.Reader)
  636. zero := field.zero()
  637. one := field.one()
  638. c_1, c_2 := field.new(), field.new()
  639. field.mul(c_1, a, zero)
  640. if !c_1.equal(zero) {
  641. t.Fatal("a * 0 == 0")
  642. }
  643. field.mul(c_1, a, one)
  644. if !c_1.equal(a) {
  645. t.Fatal("a * 1 == a")
  646. }
  647. field.mul(c_1, a, b)
  648. field.mul(c_2, b, a)
  649. if !c_1.equal(c_2) {
  650. t.Fatal("a * b == b * a")
  651. }
  652. c_x, _ := new(fe2).rand(rand.Reader)
  653. field.mul(c_1, a, b)
  654. field.mul(c_1, c_1, c_x)
  655. field.mul(c_2, c_x, b)
  656. field.mul(c_2, c_2, a)
  657. if !c_1.equal(c_2) {
  658. t.Fatal("(a * b) * c == (a * c) * b")
  659. }
  660. field.square(a, zero)
  661. if !a.equal(zero) {
  662. t.Fatal("0^2 == 0")
  663. }
  664. field.square(a, one)
  665. if !a.equal(one) {
  666. t.Fatal("1^2 == 1")
  667. }
  668. _, _ = a.rand(rand.Reader)
  669. field.square(c_1, a)
  670. field.mul(c_2, a, a)
  671. if !c_2.equal(c_1) {
  672. t.Fatal("a^2 == a*a")
  673. }
  674. }
  675. }
  676. func TestFp2MultiplicationPropertiesAssigned(t *testing.T) {
  677. field := newFp2()
  678. for i := 0; i < fuz; i++ {
  679. a, _ := new(fe2).rand(rand.Reader)
  680. zero, one := new(fe2).zero(), new(fe2).one()
  681. field.mulAssign(a, zero)
  682. if !a.equal(zero) {
  683. t.Fatal("a * 0 == 0")
  684. }
  685. _, _ = a.rand(rand.Reader)
  686. a0 := new(fe2).set(a)
  687. field.mulAssign(a, one)
  688. if !a.equal(a0) {
  689. t.Fatal("a * 1 == a")
  690. }
  691. _, _ = a.rand(rand.Reader)
  692. b, _ := new(fe2).rand(rand.Reader)
  693. a0.set(a)
  694. field.mulAssign(a, b)
  695. field.mulAssign(b, a0)
  696. if !a.equal(b) {
  697. t.Fatal("a * b == b * a")
  698. }
  699. c, _ := new(fe2).rand(rand.Reader)
  700. a0.set(a)
  701. field.mulAssign(a, b)
  702. field.mulAssign(a, c)
  703. field.mulAssign(a0, c)
  704. field.mulAssign(a0, b)
  705. if !a.equal(a0) {
  706. t.Fatal("(a * b) * c == (a * c) * b")
  707. }
  708. a0.set(a)
  709. field.squareAssign(a)
  710. field.mulAssign(a0, a0)
  711. if !a.equal(a0) {
  712. t.Fatal("a^2 == a*a")
  713. }
  714. }
  715. }
  716. func TestFp2Exponentiation(t *testing.T) {
  717. field := newFp2()
  718. for i := 0; i < fuz; i++ {
  719. a, _ := new(fe2).rand(rand.Reader)
  720. u := field.new()
  721. field.exp(u, a, big.NewInt(0))
  722. if !u.equal(field.one()) {
  723. t.Fatal("a^0 == 1")
  724. }
  725. field.exp(u, a, big.NewInt(1))
  726. if !u.equal(a) {
  727. t.Fatal("a^1 == a")
  728. }
  729. v := field.new()
  730. field.mul(u, a, a)
  731. field.mul(u, u, u)
  732. field.mul(u, u, u)
  733. field.exp(v, a, big.NewInt(8))
  734. if !u.equal(v) {
  735. t.Fatal("((a^2)^2)^2 == a^8")
  736. }
  737. }
  738. }
  739. func TestFp2Inversion(t *testing.T) {
  740. field := newFp2()
  741. u := field.new()
  742. zero := field.zero()
  743. one := field.one()
  744. field.inverse(u, zero)
  745. if !u.equal(zero) {
  746. t.Fatal("(0 ^ -1) == 0)")
  747. }
  748. field.inverse(u, one)
  749. if !u.equal(one) {
  750. t.Fatal("(1 ^ -1) == 1)")
  751. }
  752. for i := 0; i < fuz; i++ {
  753. a, _ := new(fe2).rand(rand.Reader)
  754. field.inverse(u, a)
  755. field.mul(u, u, a)
  756. if !u.equal(one) {
  757. t.Fatal("(r * a) * r * (a ^ -1) == r)")
  758. }
  759. }
  760. }
  761. func TestFp2SquareRoot(t *testing.T) {
  762. field := newFp2()
  763. for z := 0; z < 1000; z++ {
  764. zi := new(fe)
  765. sub(zi, &modulus, &fe{uint64(z * z)})
  766. // r = (-z*z, 0)
  767. r := &fe2{*zi, fe{0}}
  768. toMont(&r[0], &r[0])
  769. toMont(&r[1], &r[1])
  770. c := field.new()
  771. // sqrt((-z*z, 0)) = (0, z)
  772. if !field.sqrt(c, r) {
  773. t.Fatal("z*z does have a square root")
  774. }
  775. e := &fe2{fe{uint64(0)}, fe{uint64(z)}}
  776. toMont(&e[0], &e[0])
  777. toMont(&e[1], &e[1])
  778. field.square(e, e)
  779. field.square(c, c)
  780. if !e.equal(c) {
  781. t.Fatal("square root failed")
  782. }
  783. }
  784. if field.sqrt(field.new(), nonResidue2) {
  785. t.Fatal("non residue cannot have a sqrt")
  786. }
  787. for i := 0; i < fuz; i++ {
  788. a, _ := new(fe2).rand(rand.Reader)
  789. aa, rr, r := field.new(), field.new(), field.new()
  790. field.square(aa, a)
  791. if !field.sqrt(r, aa) {
  792. t.Fatal("bad sqrt 1")
  793. }
  794. field.square(rr, r)
  795. if !rr.equal(aa) {
  796. t.Fatal("bad sqrt 2")
  797. }
  798. }
  799. }
  800. func TestFp2NonResidue(t *testing.T) {
  801. field := newFp2()
  802. if !field.isQuadraticNonResidue(nonResidue2) {
  803. t.Fatal("element is quadratic non residue, 1")
  804. }
  805. if field.isQuadraticNonResidue(new(fe2).one()) {
  806. t.Fatal("one is not quadratic non residue")
  807. }
  808. if !field.isQuadraticNonResidue(new(fe2).zero()) {
  809. t.Fatal("should accept zero as quadratic non residue")
  810. }
  811. for i := 0; i < fuz; i++ {
  812. a, _ := new(fe2).rand(rand.Reader)
  813. field.squareAssign(a)
  814. if field.isQuadraticNonResidue(new(fe2).one()) {
  815. t.Fatal("element is not quadratic non residue")
  816. }
  817. }
  818. for i := 0; i < fuz; i++ {
  819. a, _ := new(fe2).rand(rand.Reader)
  820. if !field.sqrt(new(fe2), a) {
  821. if !field.isQuadraticNonResidue(a) {
  822. t.Fatal("element is quadratic non residue, 2", i)
  823. }
  824. } else {
  825. i -= 1
  826. }
  827. }
  828. }
  829. func TestFp6Serialization(t *testing.T) {
  830. field := newFp6(nil)
  831. for i := 0; i < fuz; i++ {
  832. a, _ := new(fe6).rand(rand.Reader)
  833. b, err := field.fromBytes(field.toBytes(a))
  834. if err != nil {
  835. t.Fatal(err)
  836. }
  837. if !a.equal(b) {
  838. t.Fatal("bad serialization")
  839. }
  840. }
  841. }
  842. func TestFp6AdditionProperties(t *testing.T) {
  843. field := newFp6(nil)
  844. for i := 0; i < fuz; i++ {
  845. zero := field.zero()
  846. a, _ := new(fe6).rand(rand.Reader)
  847. b, _ := new(fe6).rand(rand.Reader)
  848. c_1 := field.new()
  849. c_2 := field.new()
  850. field.add(c_1, a, zero)
  851. if !c_1.equal(a) {
  852. t.Fatal("a + 0 == a")
  853. }
  854. field.sub(c_1, a, zero)
  855. if !c_1.equal(a) {
  856. t.Fatal("a - 0 == a")
  857. }
  858. field.double(c_1, zero)
  859. if !c_1.equal(zero) {
  860. t.Fatal("2 * 0 == 0")
  861. }
  862. field.neg(c_1, zero)
  863. if !c_1.equal(zero) {
  864. t.Fatal("-0 == 0")
  865. }
  866. field.sub(c_1, zero, a)
  867. field.neg(c_2, a)
  868. if !c_1.equal(c_2) {
  869. t.Fatal("0-a == -a")
  870. }
  871. field.double(c_1, a)
  872. field.add(c_2, a, a)
  873. if !c_1.equal(c_2) {
  874. t.Fatal("2 * a == a + a")
  875. }
  876. field.add(c_1, a, b)
  877. field.add(c_2, b, a)
  878. if !c_1.equal(c_2) {
  879. t.Fatal("a + b = b + a")
  880. }
  881. field.sub(c_1, a, b)
  882. field.sub(c_2, b, a)
  883. field.neg(c_2, c_2)
  884. if !c_1.equal(c_2) {
  885. t.Fatal("a - b = - ( b - a )")
  886. }
  887. c_x, _ := new(fe6).rand(rand.Reader)
  888. field.add(c_1, a, b)
  889. field.add(c_1, c_1, c_x)
  890. field.add(c_2, a, c_x)
  891. field.add(c_2, c_2, b)
  892. if !c_1.equal(c_2) {
  893. t.Fatal("(a + b) + c == (a + c ) + b")
  894. }
  895. field.sub(c_1, a, b)
  896. field.sub(c_1, c_1, c_x)
  897. field.sub(c_2, a, c_x)
  898. field.sub(c_2, c_2, b)
  899. if !c_1.equal(c_2) {
  900. t.Fatal("(a - b) - c == (a - c ) -b")
  901. }
  902. }
  903. }
  904. func TestFp6AdditionPropertiesAssigned(t *testing.T) {
  905. field := newFp6(nil)
  906. for i := 0; i < fuz; i++ {
  907. zero := new(fe6).zero()
  908. a, b := new(fe6), new(fe6)
  909. _, _ = a.rand(rand.Reader)
  910. b.set(a)
  911. field.addAssign(a, zero)
  912. if !a.equal(b) {
  913. t.Fatal("a + 0 == a")
  914. }
  915. field.subAssign(a, zero)
  916. if !a.equal(b) {
  917. t.Fatal("a - 0 == a")
  918. }
  919. a.set(zero)
  920. field.doubleAssign(a)
  921. if !a.equal(zero) {
  922. t.Fatal("2 * 0 == 0")
  923. }
  924. a.set(zero)
  925. field.subAssign(a, b)
  926. field.neg(b, b)
  927. if !a.equal(b) {
  928. t.Fatal("0-a == -a")
  929. }
  930. _, _ = a.rand(rand.Reader)
  931. b.set(a)
  932. field.doubleAssign(a)
  933. field.addAssign(b, b)
  934. if !a.equal(b) {
  935. t.Fatal("2 * a == a + a")
  936. }
  937. _, _ = a.rand(rand.Reader)
  938. _, _ = b.rand(rand.Reader)
  939. c_1, c_2 := new(fe6).set(a), new(fe6).set(b)
  940. field.addAssign(c_1, b)
  941. field.addAssign(c_2, a)
  942. if !c_1.equal(c_2) {
  943. t.Fatal("a + b = b + a")
  944. }
  945. _, _ = a.rand(rand.Reader)
  946. _, _ = b.rand(rand.Reader)
  947. c_1.set(a)
  948. c_2.set(b)
  949. field.subAssign(c_1, b)
  950. field.subAssign(c_2, a)
  951. field.neg(c_2, c_2)
  952. if !c_1.equal(c_2) {
  953. t.Fatal("a - b = - ( b - a )")
  954. }
  955. _, _ = a.rand(rand.Reader)
  956. _, _ = b.rand(rand.Reader)
  957. c, _ := new(fe6).rand(rand.Reader)
  958. a0 := new(fe6).set(a)
  959. field.addAssign(a, b)
  960. field.addAssign(a, c)
  961. field.addAssign(b, c)
  962. field.addAssign(b, a0)
  963. if !a.equal(b) {
  964. t.Fatal("(a + b) + c == (b + c) + a")
  965. }
  966. _, _ = a.rand(rand.Reader)
  967. _, _ = b.rand(rand.Reader)
  968. _, _ = c.rand(rand.Reader)
  969. a0.set(a)
  970. field.subAssign(a, b)
  971. field.subAssign(a, c)
  972. field.subAssign(a0, c)
  973. field.subAssign(a0, b)
  974. if !a.equal(a0) {
  975. t.Fatal("(a - b) - c == (a - c) -b")
  976. }
  977. }
  978. }
  979. func TestFp6SparseMultiplication(t *testing.T) {
  980. fp6 := newFp6(nil)
  981. var a, b, u *fe6
  982. for j := 0; j < fuz; j++ {
  983. a, _ = new(fe6).rand(rand.Reader)
  984. b, _ = new(fe6).rand(rand.Reader)
  985. u, _ = new(fe6).rand(rand.Reader)
  986. b[2].zero()
  987. fp6.mul(u, a, b)
  988. fp6.mulBy01(a, a, &b[0], &b[1])
  989. if !a.equal(u) {
  990. t.Fatal("bad mul by 01")
  991. }
  992. }
  993. for j := 0; j < fuz; j++ {
  994. a, _ = new(fe6).rand(rand.Reader)
  995. b, _ = new(fe6).rand(rand.Reader)
  996. u, _ = new(fe6).rand(rand.Reader)
  997. b[2].zero()
  998. b[0].zero()
  999. fp6.mul(u, a, b)
  1000. fp6.mulBy1(a, a, &b[1])
  1001. if !a.equal(u) {
  1002. t.Fatal("bad mul by 1")
  1003. }
  1004. }
  1005. }
  1006. func TestFp6MultiplicationProperties(t *testing.T) {
  1007. field := newFp6(nil)
  1008. for i := 0; i < fuz; i++ {
  1009. a, _ := new(fe6).rand(rand.Reader)
  1010. b, _ := new(fe6).rand(rand.Reader)
  1011. zero := field.zero()
  1012. one := field.one()
  1013. c_1, c_2 := field.new(), field.new()
  1014. field.mul(c_1, a, zero)
  1015. if !c_1.equal(zero) {
  1016. t.Fatal("a * 0 == 0")
  1017. }
  1018. field.mul(c_1, a, one)
  1019. if !c_1.equal(a) {
  1020. t.Fatal("a * 1 == a")
  1021. }
  1022. field.mul(c_1, a, b)
  1023. field.mul(c_2, b, a)
  1024. if !c_1.equal(c_2) {
  1025. t.Fatal("a * b == b * a")
  1026. }
  1027. c_x, _ := new(fe6).rand(rand.Reader)
  1028. field.mul(c_1, a, b)
  1029. field.mul(c_1, c_1, c_x)
  1030. field.mul(c_2, c_x, b)
  1031. field.mul(c_2, c_2, a)
  1032. if !c_1.equal(c_2) {
  1033. t.Fatal("(a * b) * c == (a * c) * b")
  1034. }
  1035. field.square(a, zero)
  1036. if !a.equal(zero) {
  1037. t.Fatal("0^2 == 0")
  1038. }
  1039. field.square(a, one)
  1040. if !a.equal(one) {
  1041. t.Fatal("1^2 == 1")
  1042. }
  1043. _, _ = a.rand(rand.Reader)
  1044. field.square(c_1, a)
  1045. field.mul(c_2, a, a)
  1046. if !c_2.equal(c_1) {
  1047. t.Fatal("a^2 == a*a")
  1048. }
  1049. }
  1050. }
  1051. func TestFp6MultiplicationPropertiesAssigned(t *testing.T) {
  1052. field := newFp6(nil)
  1053. for i := 0; i < fuz; i++ {
  1054. a, _ := new(fe6).rand(rand.Reader)
  1055. zero, one := new(fe6).zero(), new(fe6).one()
  1056. field.mulAssign(a, zero)
  1057. if !a.equal(zero) {
  1058. t.Fatal("a * 0 == 0")
  1059. }
  1060. _, _ = a.rand(rand.Reader)
  1061. a0 := new(fe6).set(a)
  1062. field.mulAssign(a, one)
  1063. if !a.equal(a0) {
  1064. t.Fatal("a * 1 == a")
  1065. }
  1066. _, _ = a.rand(rand.Reader)
  1067. b, _ := new(fe6).rand(rand.Reader)
  1068. a0.set(a)
  1069. field.mulAssign(a, b)
  1070. field.mulAssign(b, a0)
  1071. if !a.equal(b) {
  1072. t.Fatal("a * b == b * a")
  1073. }
  1074. c, _ := new(fe6).rand(rand.Reader)
  1075. a0.set(a)
  1076. field.mulAssign(a, b)
  1077. field.mulAssign(a, c)
  1078. field.mulAssign(a0, c)
  1079. field.mulAssign(a0, b)
  1080. if !a.equal(a0) {
  1081. t.Fatal("(a * b) * c == (a * c) * b")
  1082. }
  1083. }
  1084. }
  1085. func TestFp6Exponentiation(t *testing.T) {
  1086. field := newFp6(nil)
  1087. for i := 0; i < fuz; i++ {
  1088. a, _ := new(fe6).rand(rand.Reader)
  1089. u := field.new()
  1090. field.exp(u, a, big.NewInt(0))
  1091. if !u.equal(field.one()) {
  1092. t.Fatal("a^0 == 1")
  1093. }
  1094. field.exp(u, a, big.NewInt(1))
  1095. if !u.equal(a) {
  1096. t.Fatal("a^1 == a")
  1097. }
  1098. v := field.new()
  1099. field.mul(u, a, a)
  1100. field.mul(u, u, u)
  1101. field.mul(u, u, u)
  1102. field.exp(v, a, big.NewInt(8))
  1103. if !u.equal(v) {
  1104. t.Fatal("((a^2)^2)^2 == a^8")
  1105. }
  1106. }
  1107. }
  1108. func TestFp6Inversion(t *testing.T) {
  1109. field := newFp6(nil)
  1110. for i := 0; i < fuz; i++ {
  1111. u := field.new()
  1112. zero := field.zero()
  1113. one := field.one()
  1114. field.inverse(u, zero)
  1115. if !u.equal(zero) {
  1116. t.Fatal("(0^-1) == 0)")
  1117. }
  1118. field.inverse(u, one)
  1119. if !u.equal(one) {
  1120. t.Fatal("(1^-1) == 1)")
  1121. }
  1122. a, _ := new(fe6).rand(rand.Reader)
  1123. field.inverse(u, a)
  1124. field.mul(u, u, a)
  1125. if !u.equal(one) {
  1126. t.Fatal("(r*a) * r*(a^-1) == r)")
  1127. }
  1128. }
  1129. }
  1130. func TestFp12Serialization(t *testing.T) {
  1131. field := newFp12(nil)
  1132. for i := 0; i < fuz; i++ {
  1133. a, _ := new(fe12).rand(rand.Reader)
  1134. b, err := field.fromBytes(field.toBytes(a))
  1135. if err != nil {
  1136. t.Fatal(err)
  1137. }
  1138. if !a.equal(b) {
  1139. t.Fatal("bad serialization")
  1140. }
  1141. }
  1142. }
  1143. func TestFp12AdditionProperties(t *testing.T) {
  1144. field := newFp12(nil)
  1145. for i := 0; i < fuz; i++ {
  1146. zero := field.zero()
  1147. a, _ := new(fe12).rand(rand.Reader)
  1148. b, _ := new(fe12).rand(rand.Reader)
  1149. c_1 := field.new()
  1150. c_2 := field.new()
  1151. field.add(c_1, a, zero)
  1152. if !c_1.equal(a) {
  1153. t.Fatal("a + 0 == a")
  1154. }
  1155. field.sub(c_1, a, zero)
  1156. if !c_1.equal(a) {
  1157. t.Fatal("a - 0 == a")
  1158. }
  1159. field.double(c_1, zero)
  1160. if !c_1.equal(zero) {
  1161. t.Fatal("2 * 0 == 0")
  1162. }
  1163. field.neg(c_1, zero)
  1164. if !c_1.equal(zero) {
  1165. t.Fatal("-0 == 0")
  1166. }
  1167. field.sub(c_1, zero, a)
  1168. field.neg(c_2, a)
  1169. if !c_1.equal(c_2) {
  1170. t.Fatal("0-a == -a")
  1171. }
  1172. field.double(c_1, a)
  1173. field.add(c_2, a, a)
  1174. if !c_1.equal(c_2) {
  1175. t.Fatal("2 * a == a + a")
  1176. }
  1177. field.add(c_1, a, b)
  1178. field.add(c_2, b, a)
  1179. if !c_1.equal(c_2) {
  1180. t.Fatal("a + b = b + a")
  1181. }
  1182. field.sub(c_1, a, b)
  1183. field.sub(c_2, b, a)
  1184. field.neg(c_2, c_2)
  1185. if !c_1.equal(c_2) {
  1186. t.Fatal("a - b = - ( b - a )")
  1187. }
  1188. c_x, _ := new(fe12).rand(rand.Reader)
  1189. field.add(c_1, a, b)
  1190. field.add(c_1, c_1, c_x)
  1191. field.add(c_2, a, c_x)
  1192. field.add(c_2, c_2, b)
  1193. if !c_1.equal(c_2) {
  1194. t.Fatal("(a + b) + c == (a + c ) + b")
  1195. }
  1196. field.sub(c_1, a, b)
  1197. field.sub(c_1, c_1, c_x)
  1198. field.sub(c_2, a, c_x)
  1199. field.sub(c_2, c_2, b)
  1200. if !c_1.equal(c_2) {
  1201. t.Fatal("(a - b) - c == (a - c ) -b")
  1202. }
  1203. }
  1204. }
  1205. func TestFp12MultiplicationProperties(t *testing.T) {
  1206. field := newFp12(nil)
  1207. for i := 0; i < fuz; i++ {
  1208. a, _ := new(fe12).rand(rand.Reader)
  1209. b, _ := new(fe12).rand(rand.Reader)
  1210. zero := field.zero()
  1211. one := field.one()
  1212. c_1, c_2 := field.new(), field.new()
  1213. field.mul(c_1, a, zero)
  1214. if !c_1.equal(zero) {
  1215. t.Fatal("a * 0 == 0")
  1216. }
  1217. field.mul(c_1, a, one)
  1218. if !c_1.equal(a) {
  1219. t.Fatal("a * 1 == a")
  1220. }
  1221. field.mul(c_1, a, b)
  1222. field.mul(c_2, b, a)
  1223. if !c_1.equal(c_2) {
  1224. t.Fatal("a * b == b * a")
  1225. }
  1226. c_x, _ := new(fe12).rand(rand.Reader)
  1227. field.mul(c_1, a, b)
  1228. field.mul(c_1, c_1, c_x)
  1229. field.mul(c_2, c_x, b)
  1230. field.mul(c_2, c_2, a)
  1231. if !c_1.equal(c_2) {
  1232. t.Fatal("(a * b) * c == (a * c) * b")
  1233. }
  1234. field.square(a, zero)
  1235. if !a.equal(zero) {
  1236. t.Fatal("0^2 == 0")
  1237. }
  1238. field.square(a, one)
  1239. if !a.equal(one) {
  1240. t.Fatal("1^2 == 1")
  1241. }
  1242. _, _ = a.rand(rand.Reader)
  1243. field.square(c_1, a)
  1244. field.mul(c_2, a, a)
  1245. if !c_2.equal(c_1) {
  1246. t.Fatal("a^2 == a*a")
  1247. }
  1248. }
  1249. }
  1250. func TestFp12MultiplicationPropertiesAssigned(t *testing.T) {
  1251. field := newFp12(nil)
  1252. for i := 0; i < fuz; i++ {
  1253. a, _ := new(fe12).rand(rand.Reader)
  1254. zero, one := new(fe12).zero(), new(fe12).one()
  1255. field.mulAssign(a, zero)
  1256. if !a.equal(zero) {
  1257. t.Fatal("a * 0 == 0")
  1258. }
  1259. _, _ = a.rand(rand.Reader)
  1260. a0 := new(fe12).set(a)
  1261. field.mulAssign(a, one)
  1262. if !a.equal(a0) {
  1263. t.Fatal("a * 1 == a")
  1264. }
  1265. _, _ = a.rand(rand.Reader)
  1266. b, _ := new(fe12).rand(rand.Reader)
  1267. a0.set(a)
  1268. field.mulAssign(a, b)
  1269. field.mulAssign(b, a0)
  1270. if !a.equal(b) {
  1271. t.Fatal("a * b == b * a")
  1272. }
  1273. c, _ := new(fe12).rand(rand.Reader)
  1274. a0.set(a)
  1275. field.mulAssign(a, b)
  1276. field.mulAssign(a, c)
  1277. field.mulAssign(a0, c)
  1278. field.mulAssign(a0, b)
  1279. if !a.equal(a0) {
  1280. t.Fatal("(a * b) * c == (a * c) * b")
  1281. }
  1282. }
  1283. }
  1284. func TestFp12SparseMultiplication(t *testing.T) {
  1285. fp12 := newFp12(nil)
  1286. var a, b, u *fe12
  1287. for j := 0; j < fuz; j++ {
  1288. a, _ = new(fe12).rand(rand.Reader)
  1289. b, _ = new(fe12).rand(rand.Reader)
  1290. u, _ = new(fe12).rand(rand.Reader)
  1291. b[0][2].zero()
  1292. b[1][0].zero()
  1293. b[1][2].zero()
  1294. fp12.mul(u, a, b)
  1295. fp12.mulBy014Assign(a, &b[0][0], &b[0][1], &b[1][1])
  1296. if !a.equal(u) {
  1297. t.Fatal("bad mul by 01")
  1298. }
  1299. }
  1300. }
  1301. func TestFp12Exponentiation(t *testing.T) {
  1302. field := newFp12(nil)
  1303. for i := 0; i < fuz; i++ {
  1304. a, _ := new(fe12).rand(rand.Reader)
  1305. u := field.new()
  1306. field.exp(u, a, big.NewInt(0))
  1307. if !u.equal(field.one()) {
  1308. t.Fatal("a^0 == 1")
  1309. }
  1310. field.exp(u, a, big.NewInt(1))
  1311. if !u.equal(a) {
  1312. t.Fatal("a^1 == a")
  1313. }
  1314. v := field.new()
  1315. field.mul(u, a, a)
  1316. field.mul(u, u, u)
  1317. field.mul(u, u, u)
  1318. field.exp(v, a, big.NewInt(8))
  1319. if !u.equal(v) {
  1320. t.Fatal("((a^2)^2)^2 == a^8")
  1321. }
  1322. }
  1323. }
  1324. func TestFp12Inversion(t *testing.T) {
  1325. field := newFp12(nil)
  1326. for i := 0; i < fuz; i++ {
  1327. u := field.new()
  1328. zero := field.zero()
  1329. one := field.one()
  1330. field.inverse(u, zero)
  1331. if !u.equal(zero) {
  1332. t.Fatal("(0^-1) == 0)")
  1333. }
  1334. field.inverse(u, one)
  1335. if !u.equal(one) {
  1336. t.Fatal("(1^-1) == 1)")
  1337. }
  1338. a, _ := new(fe12).rand(rand.Reader)
  1339. field.inverse(u, a)
  1340. field.mul(u, u, a)
  1341. if !u.equal(one) {
  1342. t.Fatal("(r*a) * r*(a^-1) == r)")
  1343. }
  1344. }
  1345. }
  1346. func BenchmarkMultiplication(t *testing.B) {
  1347. a, _ := new(fe).rand(rand.Reader)
  1348. b, _ := new(fe).rand(rand.Reader)
  1349. c, _ := new(fe).rand(rand.Reader)
  1350. t.ResetTimer()
  1351. for i := 0; i < t.N; i++ {
  1352. mul(c, a, b)
  1353. }
  1354. }
  1355. func BenchmarkInverse(t *testing.B) {
  1356. a, _ := new(fe).rand(rand.Reader)
  1357. b, _ := new(fe).rand(rand.Reader)
  1358. t.ResetTimer()
  1359. for i := 0; i < t.N; i++ {
  1360. inverse(a, b)
  1361. }
  1362. }
  1363. func padBytes(in []byte, size int) []byte {
  1364. out := make([]byte, size)
  1365. if len(in) > size {
  1366. panic("bad input for padding")
  1367. }
  1368. copy(out[size-len(in):], in)
  1369. return out
  1370. }