package nistec
import (
)
var p384B, _ = new(fiat.P384Element).SetBytes([]byte{
0xb3, 0x31, 0x2f, 0xa7, 0xe2, 0x3e, 0xe7, 0xe4, 0x98, 0x8e, 0x05, 0x6b,
0xe3, 0xf8, 0x2d, 0x19, 0x18, 0x1d, 0x9c, 0x6e, 0xfe, 0x81, 0x41, 0x12,
0x03, 0x14, 0x08, 0x8f, 0x50, 0x13, 0x87, 0x5a, 0xc6, 0x56, 0x39, 0x8d,
0x8a, 0x2e, 0xd1, 0x9d, 0x2a, 0x85, 0xc8, 0xed, 0xd3, 0xec, 0x2a, 0xef})
var p384G, _ = NewP384Point().SetBytes([]byte{0x4,
0xaa, 0x87, 0xca, 0x22, 0xbe, 0x8b, 0x05, 0x37, 0x8e, 0xb1, 0xc7, 0x1e,
0xf3, 0x20, 0xad, 0x74, 0x6e, 0x1d, 0x3b, 0x62, 0x8b, 0xa7, 0x9b, 0x98,
0x59, 0xf7, 0x41, 0xe0, 0x82, 0x54, 0x2a, 0x38, 0x55, 0x02, 0xf2, 0x5d,
0xbf, 0x55, 0x29, 0x6c, 0x3a, 0x54, 0x5e, 0x38, 0x72, 0x76, 0x0a, 0xb7,
0x36, 0x17, 0xde, 0x4a, 0x96, 0x26, 0x2c, 0x6f, 0x5d, 0x9e, 0x98, 0xbf,
0x92, 0x92, 0xdc, 0x29, 0xf8, 0xf4, 0x1d, 0xbd, 0x28, 0x9a, 0x14, 0x7c,
0xe9, 0xda, 0x31, 0x13, 0xb5, 0xf0, 0xb8, 0xc0, 0x0a, 0x60, 0xb1, 0xce,
0x1d, 0x7e, 0x81, 0x9d, 0x7a, 0x43, 0x1d, 0x7c, 0x90, 0xea, 0x0e, 0x5f})
const p384ElementLength = 48
type P384Point struct {
x, y, z *fiat.P384Element
}
func () *P384Point {
return &P384Point{
x: new(fiat.P384Element),
y: new(fiat.P384Element).One(),
z: new(fiat.P384Element),
}
}
func () *P384Point {
return (&P384Point{
x: new(fiat.P384Element),
y: new(fiat.P384Element),
z: new(fiat.P384Element),
}).Set(p384G)
}
func ( *P384Point) ( *P384Point) *P384Point {
.x.Set(.x)
.y.Set(.y)
.z.Set(.z)
return
}
func ( *P384Point) ( []byte) (*P384Point, error) {
switch {
case len() == 1 && [0] == 0:
return .Set(NewP384Point()), nil
case len() == 1+2*p384ElementLength && [0] == 4:
, := new(fiat.P384Element).SetBytes([1 : 1+p384ElementLength])
if != nil {
return nil,
}
, := new(fiat.P384Element).SetBytes([1+p384ElementLength:])
if != nil {
return nil,
}
if := p384CheckOnCurve(, ); != nil {
return nil,
}
.x.Set()
.y.Set()
.z.One()
return , nil
case len() == 1+p384ElementLength && [0] == 0:
return nil, errors.New("unimplemented")
default:
return nil, errors.New("invalid P384 point encoding")
}
}
func (, *fiat.P384Element) error {
:= new(fiat.P384Element).Square()
.Mul(, )
:= new(fiat.P384Element).Add(, )
.Add(, )
.Sub(, )
.Add(, p384B)
:= new(fiat.P384Element).Square()
if .Equal() != 1 {
return errors.New("P384 point not on curve")
}
return nil
}
func ( *P384Point) () []byte {
var [133]byte
return .bytes(&)
}
func ( *P384Point) ( *[133]byte) []byte {
if .z.IsZero() == 1 {
return append([:0], 0)
}
:= new(fiat.P384Element).Invert(.z)
:= new(fiat.P384Element).Mul(.x, )
:= new(fiat.P384Element).Mul(.y, )
:= append([:0], 4)
= append(, .Bytes()...)
= append(, .Bytes()...)
return
}
func ( *P384Point) (, *P384Point) *P384Point {
:= new(fiat.P384Element).Mul(.x, .x)
:= new(fiat.P384Element).Mul(.y, .y)
:= new(fiat.P384Element).Mul(.z, .z)
:= new(fiat.P384Element).Add(.x, .y)
:= new(fiat.P384Element).Add(.x, .y)
.Mul(, )
.Add(, )
.Sub(, )
.Add(.y, .z)
:= new(fiat.P384Element).Add(.y, .z)
.Mul(, )
.Add(, )
.Sub(, )
.Add(.x, .z)
:= new(fiat.P384Element).Add(.x, .z)
.Mul(, )
.Add(, )
.Sub(, )
:= new(fiat.P384Element).Mul(p384B, )
.Sub(, )
.Add(, )
.Add(, )
.Sub(, )
.Add(, )
.Mul(p384B, )
.Add(, )
.Add(, )
.Sub(, )
.Sub(, )
.Add(, )
.Add(, )
.Add(, )
.Add(, )
.Sub(, )
.Mul(, )
.Mul(, )
.Mul(, )
.Add(, )
.Mul(, )
.Sub(, )
.Mul(, )
.Mul(, )
.Add(, )
.x.Set()
.y.Set()
.z.Set()
return
}
func ( *P384Point) ( *P384Point) *P384Point {
:= new(fiat.P384Element).Square(.x)
:= new(fiat.P384Element).Square(.y)
:= new(fiat.P384Element).Square(.z)
:= new(fiat.P384Element).Mul(.x, .y)
.Add(, )
:= new(fiat.P384Element).Mul(.x, .z)
.Add(, )
:= new(fiat.P384Element).Mul(p384B, )
.Sub(, )
:= new(fiat.P384Element).Add(, )
.Add(, )
.Sub(, )
.Add(, )
.Mul(, )
.Mul(, )
.Add(, )
.Add(, )
.Mul(p384B, )
.Sub(, )
.Sub(, )
.Add(, )
.Add(, )
.Add(, )
.Add(, )
.Sub(, )
.Mul(, )
.Add(, )
.Mul(.y, .z)
.Add(, )
.Mul(, )
.Sub(, )
.Mul(, )
.Add(, )
.Add(, )
.x.Set()
.y.Set()
.z.Set()
return
}
func ( *P384Point) (, *P384Point, int) *P384Point {
.x.Select(.x, .x, )
.y.Select(.y, .y, )
.z.Select(.z, .z, )
return
}
func ( *P384Point) ( *P384Point, []byte) *P384Point {
var = [16]*P384Point{
NewP384Point(), NewP384Point(), NewP384Point(), NewP384Point(),
NewP384Point(), NewP384Point(), NewP384Point(), NewP384Point(),
NewP384Point(), NewP384Point(), NewP384Point(), NewP384Point(),
NewP384Point(), NewP384Point(), NewP384Point(), NewP384Point(),
}
for := 1; < 16; ++ {
[].Add([-1], )
}
:= NewP384Point()
.Set(NewP384Point())
for , := range {
.Double()
.Double()
.Double()
.Double()
for := uint8(0); < 16; ++ {
:= subtle.ConstantTimeByteEq(>>4, )
.Select([], , )
}
.Add(, )
.Double()
.Double()
.Double()
.Double()
for := uint8(0); < 16; ++ {
:= subtle.ConstantTimeByteEq(&0b1111, )
.Select([], , )
}
.Add(, )
}
return
}