Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 25 additions & 6 deletions src/uint/boxed/mul_mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ impl BoxedUint {
/// Computes `self * rhs mod p` for the special modulus
/// `p = MAX+1-c` where `c` is small enough to fit in a single [`Limb`].
///
/// When `c` is zero, `p = MAX+1` and the result is wrapping multiplication.
///
/// For the modulus reduction, this function implements Algorithm 14.47 from
/// the "Handbook of Applied Cryptography", by A. Menezes, P. van Oorschot,
/// and S. Vanstone, CRC Press, 1996.
Expand All @@ -23,11 +25,14 @@ impl BoxedUint {
debug_assert_eq!(self.bits_precision(), rhs.bits_precision());

if self.nlimbs() == 1 {
let reduced = mul_rem(
self.limbs[0],
rhs.limbs[0],
NonZero::<Limb>::new_unwrap(Limb::ZERO.wrapping_sub(c)),
);
let a = self.limbs[0];
let b = rhs.limbs[0];

// For c = 0, use a nonzero placeholder divisor and select the
// wrapping product in constant time.
let (p, c_is_nonzero) = Limb::ZERO.wrapping_sub(c).to_nz_or_one();
let reduced = mul_rem(a, b, p);
let reduced = Limb::select(a.wrapping_mul(b), reduced, c_is_nonzero);
return Self::from(reduced);
}

Expand Down Expand Up @@ -93,7 +98,7 @@ fn mac_by_limb(a: &UintRef, b: &UintRef, c: Limb, carry: Limb) -> (BoxedUint, Li

#[cfg(all(test, feature = "rand_core"))]
mod tests {
use crate::{BoxedUint, ConcatenatingMul, Limb, NonZero, Random, RandomMod};
use crate::{BoxedUint, ConcatenatingMul, Limb, NonZero, Random, RandomMod, Resize};
use rand_core::SeedableRng;

#[test]
Expand Down Expand Up @@ -148,4 +153,18 @@ mod tests {
}
}
}

#[test]
fn mul_mod_special_zero_c_is_wrapping_multiplication() {
for bits in [Limb::BITS, 2 * Limb::BITS, 4 * Limb::BITS] {
let a = BoxedUint::from(0x1234_5678u32).resize(bits);
let b = BoxedUint::from(0xfedc_ba91u32).resize(bits);

assert_eq!(
a.mul_mod_special(&b, Limb::ZERO),
a.wrapping_mul(&b),
"c = 0 represents the power-of-two modulus"
);
}
}
}
38 changes: 32 additions & 6 deletions src/uint/mul_mod.rs
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
//! [`Uint`] modular multiplication operations.

use crate::{Limb, MulMod, NonZero, SquareMod, Uint, WideWord, Word, div_limb::mul_rem};
use crate::{Limb, MulMod, NonZero, SquareMod, Uint, WideWord, div_limb::mul_rem};

impl<const LIMBS: usize> Uint<LIMBS> {
/// Computes `self * rhs mod p`.
Expand All @@ -20,6 +20,8 @@ impl<const LIMBS: usize> Uint<LIMBS> {
/// Computes `self * rhs mod p` for the special modulus
/// `p = MAX+1-c` where `c` is small enough to fit in a single [`Limb`].
///
/// When `c` is zero, `p = MAX+1` and the result is wrapping multiplication.
///
/// For the modulus reduction, this function implements Algorithm 14.47 from
/// the "Handbook of Applied Cryptography", by A. Menezes, P. van Oorschot,
/// and S. Vanstone, CRC Press, 1996.
Expand All @@ -28,11 +30,14 @@ impl<const LIMBS: usize> Uint<LIMBS> {
// We implicitly assume `LIMBS > 0`, because `Uint<0>` doesn't compile.
// Still the case `LIMBS == 1` needs special handling.
if LIMBS == 1 {
let reduced = mul_rem(
self.limbs[0],
rhs.limbs[0],
NonZero::<Limb>::new_unwrap(Limb(Word::MIN.wrapping_sub(c.0))),
);
let a = self.limbs[0];
let b = rhs.limbs[0];

// For c = 0, use a nonzero placeholder divisor and select the
// wrapping product in constant time.
let (p, c_is_nonzero) = Limb::ZERO.wrapping_sub(c).to_nz_or_one();
let reduced = mul_rem(a, b, p);
let reduced = Limb::select(a.wrapping_mul(b), reduced, c_is_nonzero);
return Self::from_word(reduced.0);
}

Expand Down Expand Up @@ -163,4 +168,25 @@ mod tests {
test_size::<16>();
}
}

#[test]
fn mul_mod_special_zero_c_is_wrapping_multiplication() {
let a = Uint::<1>::from_u32(0x1234_5678);
let b = Uint::<1>::from_u32(0xfedc_ba91);

assert_eq!(
a.mul_mod_special(&b, Limb::ZERO),
a.wrapping_mul(&b),
"c = 0 represents the power-of-two modulus"
);

let a = Uint::<2>::from_u32(0x1234_5678);
let b = Uint::<2>::from_u32(0xfedc_ba91);

assert_eq!(
a.mul_mod_special(&b, Limb::ZERO),
a.wrapping_mul(&b),
"c = 0 represents the power-of-two modulus"
);
}
}
Loading