2015-11-12 00:49:07 +00:00
|
|
|
#include <tommath_private.h>
|
2004-10-29 22:07:18 +00:00
|
|
|
#ifdef BN_FAST_MP_MONTGOMERY_REDUCE_C
|
2003-02-28 16:08:34 +00:00
|
|
|
/* LibTomMath, multiple-precision integer library -- Tom St Denis
|
|
|
|
*
|
2003-08-05 01:24:44 +00:00
|
|
|
* LibTomMath is a library that provides multiple-precision
|
2003-02-28 16:08:34 +00:00
|
|
|
* integer arithmetic as well as number theoretic functionality.
|
|
|
|
*
|
2003-08-05 01:24:44 +00:00
|
|
|
* The library was designed directly after the MPI library by
|
2003-02-28 16:08:34 +00:00
|
|
|
* Michael Fromberger but has been written from scratch with
|
|
|
|
* additional optimizations in place.
|
|
|
|
*
|
|
|
|
* The library is free for all purposes without any express
|
|
|
|
* guarantee it works.
|
|
|
|
*
|
2015-10-30 21:55:29 +00:00
|
|
|
* Tom St Denis, tstdenis82@gmail.com, http://libtom.org
|
2003-02-28 16:08:34 +00:00
|
|
|
*/
|
|
|
|
|
2003-12-24 18:59:22 +00:00
|
|
|
/* computes xR**-1 == x (mod N) via Montgomery Reduction
|
|
|
|
*
|
2004-10-29 22:07:18 +00:00
|
|
|
* This is an optimized implementation of montgomery_reduce
|
2003-02-28 16:09:08 +00:00
|
|
|
* which uses the comba method to quickly calculate the columns of the
|
2003-12-24 18:59:22 +00:00
|
|
|
* reduction.
|
2003-02-28 16:09:08 +00:00
|
|
|
*
|
|
|
|
* Based on Algorithm 14.32 on pp.601 of HAC.
|
|
|
|
*/
|
2017-08-30 17:07:12 +00:00
|
|
|
int fast_mp_montgomery_reduce(mp_int *x, mp_int *n, mp_digit rho)
|
2003-02-28 16:08:34 +00:00
|
|
|
{
|
2003-02-28 16:09:08 +00:00
|
|
|
int ix, res, olduse;
|
2003-05-17 12:33:54 +00:00
|
|
|
mp_word W[MP_WARRAY];
|
2003-02-28 16:08:34 +00:00
|
|
|
|
|
|
|
/* get old used count */
|
2003-05-29 13:35:26 +00:00
|
|
|
olduse = x->used;
|
2003-02-28 16:08:34 +00:00
|
|
|
|
|
|
|
/* grow a as required */
|
2015-11-13 09:28:23 +00:00
|
|
|
if (x->alloc < (n->used + 1)) {
|
2017-08-30 18:08:58 +00:00
|
|
|
if ((res = mp_grow(x, n->used + 1)) != MP_OKAY) {
|
2003-02-28 16:08:34 +00:00
|
|
|
return res;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2003-08-05 01:24:44 +00:00
|
|
|
/* first we have to get the digits of the input into
|
|
|
|
* an array of double precision words W[...]
|
|
|
|
*/
|
2003-02-28 16:09:08 +00:00
|
|
|
{
|
2015-11-25 20:59:46 +00:00
|
|
|
mp_word *_W;
|
|
|
|
mp_digit *tmpx;
|
2003-02-28 16:09:08 +00:00
|
|
|
|
2003-08-29 14:06:56 +00:00
|
|
|
/* alias for the W[] array */
|
|
|
|
_W = W;
|
|
|
|
|
|
|
|
/* alias for the digits of x*/
|
2003-05-29 13:35:26 +00:00
|
|
|
tmpx = x->dp;
|
2003-02-28 16:09:08 +00:00
|
|
|
|
2003-03-29 18:16:01 +00:00
|
|
|
/* copy the digits of a into W[0..a->used-1] */
|
2003-05-29 13:35:26 +00:00
|
|
|
for (ix = 0; ix < x->used; ix++) {
|
|
|
|
*_W++ = *tmpx++;
|
2003-02-28 16:09:08 +00:00
|
|
|
}
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2003-03-29 18:16:01 +00:00
|
|
|
/* zero the high words of W[a->used..m->used*2] */
|
2015-11-13 09:28:23 +00:00
|
|
|
for (; ix < ((n->used * 2) + 1); ix++) {
|
2003-02-28 16:09:08 +00:00
|
|
|
*_W++ = 0;
|
|
|
|
}
|
2003-02-28 16:08:34 +00:00
|
|
|
}
|
|
|
|
|
2003-08-05 01:24:44 +00:00
|
|
|
/* now we proceed to zero successive digits
|
|
|
|
* from the least significant upwards
|
|
|
|
*/
|
2003-05-29 13:35:26 +00:00
|
|
|
for (ix = 0; ix < n->used; ix++) {
|
|
|
|
/* mu = ai * m' mod b
|
2003-02-28 16:08:34 +00:00
|
|
|
*
|
|
|
|
* We avoid a double precision multiplication (which isn't required)
|
2003-12-24 18:59:22 +00:00
|
|
|
* by casting the value down to a mp_digit. Note this requires
|
2003-05-29 13:35:26 +00:00
|
|
|
* that W[ix-1] have the carry cleared (see after the inner loop)
|
2003-02-28 16:08:34 +00:00
|
|
|
*/
|
2015-11-25 20:59:46 +00:00
|
|
|
mp_digit mu;
|
2017-08-30 18:08:58 +00:00
|
|
|
mu = (mp_digit)(((W[ix] & MP_MASK) * rho) & MP_MASK);
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2003-05-29 13:35:26 +00:00
|
|
|
/* a = a + mu * m * b**i
|
2003-02-28 16:08:34 +00:00
|
|
|
*
|
|
|
|
* This is computed in place and on the fly. The multiplication
|
2003-05-29 13:35:26 +00:00
|
|
|
* by b**i is handled by offseting which columns the results
|
2003-02-28 16:08:34 +00:00
|
|
|
* are added to.
|
|
|
|
*
|
2003-12-24 18:59:22 +00:00
|
|
|
* Note the comba method normally doesn't handle carries in the
|
|
|
|
* inner loop In this case we fix the carry from the previous
|
|
|
|
* column since the Montgomery reduction requires digits of the
|
2003-05-29 13:35:26 +00:00
|
|
|
* result (so far) [see above] to work. This is
|
2003-12-24 18:59:22 +00:00
|
|
|
* handled by fixing up one carry after the inner loop. The
|
|
|
|
* carry fixups are done in order so after these loops the
|
2003-05-29 13:35:26 +00:00
|
|
|
* first m->used words of W[] have the carries fixed
|
2003-02-28 16:08:34 +00:00
|
|
|
*/
|
|
|
|
{
|
2015-11-25 20:59:46 +00:00
|
|
|
int iy;
|
|
|
|
mp_digit *tmpn;
|
|
|
|
mp_word *_W;
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2003-02-28 16:09:08 +00:00
|
|
|
/* alias for the digits of the modulus */
|
2003-05-29 13:35:26 +00:00
|
|
|
tmpn = n->dp;
|
2003-02-28 16:09:08 +00:00
|
|
|
|
|
|
|
/* Alias for the columns set by an offset of ix */
|
2003-02-28 16:08:34 +00:00
|
|
|
_W = W + ix;
|
|
|
|
|
|
|
|
/* inner loop */
|
2003-05-29 13:35:26 +00:00
|
|
|
for (iy = 0; iy < n->used; iy++) {
|
2003-07-12 14:31:43 +00:00
|
|
|
*_W++ += ((mp_word)mu) * ((mp_word)*tmpn++);
|
2003-02-28 16:08:34 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/* now fix carry for next digit, W[ix+1] */
|
|
|
|
W[ix + 1] += W[ix] >> ((mp_word) DIGIT_BIT);
|
|
|
|
}
|
|
|
|
|
2003-08-05 01:24:44 +00:00
|
|
|
/* now we have to propagate the carries and
|
|
|
|
* shift the words downward [all those least
|
|
|
|
* significant digits we zeroed].
|
|
|
|
*/
|
2003-02-28 16:09:08 +00:00
|
|
|
{
|
2015-11-25 20:59:46 +00:00
|
|
|
mp_digit *tmpx;
|
|
|
|
mp_word *_W, *_W1;
|
2003-03-13 02:11:11 +00:00
|
|
|
|
|
|
|
/* nox fix rest of carries */
|
2003-08-05 01:24:44 +00:00
|
|
|
|
|
|
|
/* alias for current word */
|
2003-03-13 02:11:11 +00:00
|
|
|
_W1 = W + ix;
|
2003-08-05 01:24:44 +00:00
|
|
|
|
|
|
|
/* alias for next word, where the carry goes */
|
2003-03-13 02:11:11 +00:00
|
|
|
_W = W + ++ix;
|
|
|
|
|
2015-11-13 09:28:23 +00:00
|
|
|
for (; ix <= ((n->used * 2) + 1); ix++) {
|
2003-03-13 02:11:11 +00:00
|
|
|
*_W++ += *_W1++ >> ((mp_word) DIGIT_BIT);
|
|
|
|
}
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2003-05-29 13:35:26 +00:00
|
|
|
/* copy out, A = A/b**n
|
2003-02-28 16:09:08 +00:00
|
|
|
*
|
2003-12-24 18:59:22 +00:00
|
|
|
* The result is A/b**n but instead of converting from an
|
|
|
|
* array of mp_word to mp_digit than calling mp_rshd
|
2003-05-29 13:35:26 +00:00
|
|
|
* we just copy them in the right order
|
2003-02-28 16:09:08 +00:00
|
|
|
*/
|
2003-08-05 01:24:44 +00:00
|
|
|
|
|
|
|
/* alias for destination word */
|
2003-05-29 13:35:26 +00:00
|
|
|
tmpx = x->dp;
|
2003-08-05 01:24:44 +00:00
|
|
|
|
|
|
|
/* alias for shifted double precision result */
|
2003-05-29 13:35:26 +00:00
|
|
|
_W = W + n->used;
|
2003-02-28 16:09:08 +00:00
|
|
|
|
2015-11-13 09:28:23 +00:00
|
|
|
for (ix = 0; ix < (n->used + 1); ix++) {
|
2003-06-19 10:04:50 +00:00
|
|
|
*tmpx++ = (mp_digit)(*_W++ & ((mp_word) MP_MASK));
|
2003-02-28 16:09:08 +00:00
|
|
|
}
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2003-02-28 16:09:08 +00:00
|
|
|
/* zero oldused digits, if the input a was larger than
|
2003-08-05 01:24:44 +00:00
|
|
|
* m->used+1 we'll have to clear the digits
|
|
|
|
*/
|
2003-02-28 16:09:08 +00:00
|
|
|
for (; ix < olduse; ix++) {
|
2003-05-29 13:35:26 +00:00
|
|
|
*tmpx++ = 0;
|
2003-02-28 16:09:08 +00:00
|
|
|
}
|
2003-02-28 16:08:34 +00:00
|
|
|
}
|
2003-02-28 16:09:08 +00:00
|
|
|
|
|
|
|
/* set the max used and clamp */
|
2003-05-29 13:35:26 +00:00
|
|
|
x->used = n->used + 1;
|
2017-08-30 18:08:58 +00:00
|
|
|
mp_clamp(x);
|
2003-02-28 16:08:34 +00:00
|
|
|
|
|
|
|
/* if A >= m then A = A - m */
|
2017-08-30 18:08:58 +00:00
|
|
|
if (mp_cmp_mag(x, n) != MP_LT) {
|
|
|
|
return s_mp_sub(x, n, x);
|
2003-02-28 16:08:34 +00:00
|
|
|
}
|
|
|
|
return MP_OKAY;
|
|
|
|
}
|
2004-10-29 22:07:18 +00:00
|
|
|
#endif
|
2005-08-01 16:37:28 +00:00
|
|
|
|
2017-08-28 14:27:26 +00:00
|
|
|
/* ref: $Format:%D$ */
|
|
|
|
/* git commit: $Format:%H$ */
|
|
|
|
/* commit time: $Format:%ai$ */
|