curve25519_dalek::ristretto

Struct RistrettoPoint

Source
pub struct RistrettoPoint(/* private fields */);
Expand description

A RistrettoPoint represents a point in the Ristretto group for Curve25519. Ristretto, a variant of Decaf, constructs a prime-order group as a quotient group of a subgroup of (the Edwards form of) Curve25519.

Internally, a RistrettoPoint is implemented as a wrapper type around EdwardsPoint, with custom equality, compression, and decompression routines to account for the quotient. This means that operations on RistrettoPoints are exactly as fast as operations on EdwardsPoints.

Implementations§

Source§

impl RistrettoPoint

Source

pub fn compress(&self) -> CompressedRistretto

Compress this point using the Ristretto encoding.

Source

pub fn double_and_compress_batch<'a, I>(points: I) -> Vec<CompressedRistretto>
where I: IntoIterator<Item = &'a RistrettoPoint>,

Double-and-compress a batch of points. The Ristretto encoding is not batchable, since it requires an inverse square root.

However, given input points \( P_1, \ldots, P_n, \) it is possible to compute the encodings of their doubles \( \mathrm{enc}( [2]P_1), \ldots, \mathrm{enc}( [2]P_n ) \) in a batch.

use rand_core::OsRng;

let mut rng = OsRng;

let points: Vec<RistrettoPoint> =
    (0..32).map(|_| RistrettoPoint::random(&mut rng)).collect();

let compressed = RistrettoPoint::double_and_compress_batch(&points);

for (P, P2_compressed) in points.iter().zip(compressed.iter()) {
    assert_eq!(*P2_compressed, (P + P).compress());
}
Source

pub fn hash_from_bytes<D>(input: &[u8]) -> RistrettoPoint
where D: Digest<OutputSize = U64> + Default,

Hash a slice of bytes into a RistrettoPoint.

Takes a type parameter D, which is any Digest producing 64 bytes of output.

Convenience wrapper around from_hash.

§Implementation

Uses the Ristretto-flavoured Elligator 2 map, so that the discrete log of the output point with respect to any other point should be unknown. The map is applied twice and the results are added, to ensure a uniform distribution.

§Example
use sha2::Sha512;

let msg = "To really appreciate architecture, you may even need to commit a murder";
let P = RistrettoPoint::hash_from_bytes::<Sha512>(msg.as_bytes());
Source

pub fn from_hash<D>(hash: D) -> RistrettoPoint
where D: Digest<OutputSize = U64> + Default,

Construct a RistrettoPoint from an existing Digest instance.

Use this instead of hash_from_bytes if it is more convenient to stream data into the Digest than to pass a single byte slice.

Source

pub fn from_uniform_bytes(bytes: &[u8; 64]) -> RistrettoPoint

Construct a RistrettoPoint from 64 bytes of data.

If the input bytes are uniformly distributed, the resulting point will be uniformly distributed over the group, and its discrete log with respect to other points should be unknown.

§Implementation

This function splits the input array into two 32-byte halves, takes the low 255 bits of each half mod p, applies the Ristretto-flavored Elligator map to each, and adds the results.

Source§

impl RistrettoPoint

Source

pub fn mul_base(scalar: &Scalar) -> Self

Fixed-base scalar multiplication by the Ristretto base point.

Uses precomputed basepoint tables when the precomputed-tables feature is enabled, trading off increased code size for ~4x better performance.

Source§

impl RistrettoPoint

Source

pub fn vartime_double_scalar_mul_basepoint( a: &Scalar, A: &RistrettoPoint, b: &Scalar, ) -> RistrettoPoint

Compute \(aA + bB\) in variable time, where \(B\) is the Ristretto basepoint.

Trait Implementations§

Source§

impl<'a, 'b> Add<&'b RistrettoPoint> for &'a RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the + operator.
Source§

fn add(self, other: &'b RistrettoPoint) -> RistrettoPoint

Performs the + operation. Read more
Source§

impl<'b> Add<&'b RistrettoPoint> for RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the + operator.
Source§

fn add(self, rhs: &'b RistrettoPoint) -> RistrettoPoint

Performs the + operation. Read more
Source§

impl<'a> Add<RistrettoPoint> for &'a RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the + operator.
Source§

fn add(self, rhs: RistrettoPoint) -> RistrettoPoint

Performs the + operation. Read more
Source§

impl Add for RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the + operator.
Source§

fn add(self, rhs: RistrettoPoint) -> RistrettoPoint

Performs the + operation. Read more
Source§

impl<'b> AddAssign<&'b RistrettoPoint> for RistrettoPoint

Source§

fn add_assign(&mut self, _rhs: &RistrettoPoint)

Performs the += operation. Read more
Source§

impl AddAssign for RistrettoPoint

Source§

fn add_assign(&mut self, rhs: RistrettoPoint)

Performs the += operation. Read more
Source§

impl Clone for RistrettoPoint

Source§

fn clone(&self) -> RistrettoPoint

Returns a copy of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl ConditionallySelectable for RistrettoPoint

Source§

fn conditional_select( a: &RistrettoPoint, b: &RistrettoPoint, choice: Choice, ) -> RistrettoPoint

Conditionally select between self and other.

§Example
use subtle::ConditionallySelectable;
use subtle::Choice;

let A = RistrettoPoint::identity();
let B = constants::RISTRETTO_BASEPOINT_POINT;

let mut P = A;

P = RistrettoPoint::conditional_select(&A, &B, Choice::from(0));
assert_eq!(P, A);
P = RistrettoPoint::conditional_select(&A, &B, Choice::from(1));
assert_eq!(P, B);
Source§

fn conditional_assign(&mut self, other: &Self, choice: Choice)

Conditionally assign other to self, according to choice. Read more
Source§

fn conditional_swap(a: &mut Self, b: &mut Self, choice: Choice)

Conditionally swap self and other if choice == 1; otherwise, reassign both unto themselves. Read more
Source§

impl ConstantTimeEq for RistrettoPoint

Source§

fn ct_eq(&self, other: &RistrettoPoint) -> Choice

Test equality between two RistrettoPoints.

§Returns
  • Choice(1) if the two RistrettoPoints are equal;
  • Choice(0) otherwise.
Source§

fn ct_ne(&self, other: &Self) -> Choice

Determine if two items are NOT equal. Read more
Source§

impl Debug for RistrettoPoint

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for RistrettoPoint

Source§

fn default() -> RistrettoPoint

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for RistrettoPoint

Source§

fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
where D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Identity for RistrettoPoint

Source§

fn identity() -> RistrettoPoint

Returns the identity element of the curve. Can be used as a constructor.
Source§

impl<'a, 'b> Mul<&'b RistrettoPoint> for &'a Scalar

Source§

fn mul(self, point: &'b RistrettoPoint) -> RistrettoPoint

Scalar multiplication: compute self * scalar.

Source§

type Output = RistrettoPoint

The resulting type after applying the * operator.
Source§

impl<'b> Mul<&'b RistrettoPoint> for Scalar

Source§

type Output = RistrettoPoint

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: &'b RistrettoPoint) -> RistrettoPoint

Performs the * operation. Read more
Source§

impl<'a, 'b> Mul<&'b Scalar> for &'a RistrettoPoint

Source§

fn mul(self, scalar: &'b Scalar) -> RistrettoPoint

Scalar multiplication: compute scalar * self.

Source§

type Output = RistrettoPoint

The resulting type after applying the * operator.
Source§

impl<'b> Mul<&'b Scalar> for RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: &'b Scalar) -> RistrettoPoint

Performs the * operation. Read more
Source§

impl<'a> Mul<RistrettoPoint> for &'a Scalar

Source§

type Output = RistrettoPoint

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: RistrettoPoint) -> RistrettoPoint

Performs the * operation. Read more
Source§

impl Mul<RistrettoPoint> for Scalar

Source§

type Output = RistrettoPoint

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: RistrettoPoint) -> RistrettoPoint

Performs the * operation. Read more
Source§

impl<'a> Mul<Scalar> for &'a RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: Scalar) -> RistrettoPoint

Performs the * operation. Read more
Source§

impl Mul<Scalar> for RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: Scalar) -> RistrettoPoint

Performs the * operation. Read more
Source§

impl<'b> MulAssign<&'b Scalar> for RistrettoPoint

Source§

fn mul_assign(&mut self, scalar: &'b Scalar)

Performs the *= operation. Read more
Source§

impl MulAssign<Scalar> for RistrettoPoint

Source§

fn mul_assign(&mut self, rhs: Scalar)

Performs the *= operation. Read more
Source§

impl MultiscalarMul for RistrettoPoint

Source§

type Point = RistrettoPoint

The type of point being multiplied, e.g., RistrettoPoint.
Source§

fn multiscalar_mul<I, J>(scalars: I, points: J) -> RistrettoPoint

Given an iterator of (possibly secret) scalars and an iterator of public points, compute $$ Q = c_1 P_1 + \cdots + c_n P_n. $$ Read more
Source§

impl<'a> Neg for &'a RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the - operator.
Source§

fn neg(self) -> RistrettoPoint

Performs the unary - operation. Read more
Source§

impl Neg for RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the - operator.
Source§

fn neg(self) -> RistrettoPoint

Performs the unary - operation. Read more
Source§

impl PartialEq for RistrettoPoint

Source§

fn eq(&self, other: &RistrettoPoint) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl Serialize for RistrettoPoint

Source§

fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>
where S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl<'a, 'b> Sub<&'b RistrettoPoint> for &'a RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the - operator.
Source§

fn sub(self, other: &'b RistrettoPoint) -> RistrettoPoint

Performs the - operation. Read more
Source§

impl<'b> Sub<&'b RistrettoPoint> for RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the - operator.
Source§

fn sub(self, rhs: &'b RistrettoPoint) -> RistrettoPoint

Performs the - operation. Read more
Source§

impl<'a> Sub<RistrettoPoint> for &'a RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the - operator.
Source§

fn sub(self, rhs: RistrettoPoint) -> RistrettoPoint

Performs the - operation. Read more
Source§

impl Sub for RistrettoPoint

Source§

type Output = RistrettoPoint

The resulting type after applying the - operator.
Source§

fn sub(self, rhs: RistrettoPoint) -> RistrettoPoint

Performs the - operation. Read more
Source§

impl<'b> SubAssign<&'b RistrettoPoint> for RistrettoPoint

Source§

fn sub_assign(&mut self, _rhs: &RistrettoPoint)

Performs the -= operation. Read more
Source§

impl SubAssign for RistrettoPoint

Source§

fn sub_assign(&mut self, rhs: RistrettoPoint)

Performs the -= operation. Read more
Source§

impl<T> Sum<T> for RistrettoPoint

Source§

fn sum<I>(iter: I) -> Self
where I: Iterator<Item = T>,

Takes an iterator and generates Self from the elements by “summing up” the items.
Source§

impl VartimeMultiscalarMul for RistrettoPoint

Source§

type Point = RistrettoPoint

The type of point being multiplied, e.g., RistrettoPoint.
Source§

fn optional_multiscalar_mul<I, J>( scalars: I, points: J, ) -> Option<RistrettoPoint>

Given an iterator of public scalars and an iterator of Options of points, compute either Some(Q), where $$ Q = c_1 P_1 + \cdots + c_n P_n, $$ if all points were Some(P_i), or else return None. Read more
Source§

fn vartime_multiscalar_mul<I, J>(scalars: I, points: J) -> Self::Point
where I: IntoIterator, I::Item: Borrow<Scalar>, J: IntoIterator, J::Item: Borrow<Self::Point>, Self::Point: Clone,

Given an iterator of public scalars and an iterator of public points, compute $$ Q = c_1 P_1 + \cdots + c_n P_n, $$ using variable-time operations. Read more
Source§

impl Zeroize for RistrettoPoint

Source§

fn zeroize(&mut self)

Zero out this object from memory using Rust intrinsics which ensure the zeroization operation is not “optimized away” by the compiler.
Source§

impl Copy for RistrettoPoint

Source§

impl Eq for RistrettoPoint

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dst: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dst. Read more
Source§

impl<T> ConditionallyNegatable for T
where T: ConditionallySelectable, &'a T: for<'a> Neg<Output = T>,

Source§

fn conditional_negate(&mut self, choice: Choice)

Negate self if choice == Choice(1); otherwise, leave it unchanged. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IsIdentity for T

Source§

fn is_identity(&self) -> bool

Return true if this element is the identity element of the curve.
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,