func crypto/internal/fips140/mlkem.nttMul

9 uses

	crypto/internal/fips140/mlkem (current package)
		field.go#L429: func nttMul(f, g nttElement) nttElement {
		mlkem1024.go#L246: 			t[i] = polyAdd(t[i], nttMul(A[i*k1024+j], s[j]))
		mlkem1024.go#L378: 			u[i] = polyAdd(u[i], inverseNTT(nttMul(ex.a[j*k1024+i], r[j])))
		mlkem1024.go#L386: 		vNTT = polyAdd(vNTT, nttMul(ex.t[i], r[i]))
		mlkem1024.go#L453: 		mask = polyAdd(mask, nttMul(dx.s[i], ntt(u[i])))
		mlkem768.go#L305: 			t[i] = polyAdd(t[i], nttMul(A[i*k+j], s[j]))
		mlkem768.go#L437: 			u[i] = polyAdd(u[i], inverseNTT(nttMul(ex.a[j*k+i], r[j])))
		mlkem768.go#L445: 		vNTT = polyAdd(vNTT, nttMul(ex.t[i], r[i]))
		mlkem768.go#L512: 		mask = polyAdd(mask, nttMul(dx.s[i], ntt(u[i])))