Bitcoin ABC 0.33.6
P2P Digital Currency
bench_internal.c
Go to the documentation of this file.
1/***********************************************************************
2 * Copyright (c) 2014-2015 Pieter Wuille *
3 * Distributed under the MIT software license, see the accompanying *
4 * file COPYING or https://www.opensource.org/licenses/mit-license.php.*
5 ***********************************************************************/
6#include <stdio.h>
7
8#include "secp256k1.c"
9#include "../include/secp256k1.h"
10
11#include "assumptions.h"
12#include "util.h"
13#include "hash_impl.h"
14#include "field_impl.h"
15#include "group_impl.h"
16#include "scalar_impl.h"
17#include "ecmult_impl.h"
18#include "bench.h"
19
20typedef struct {
25 unsigned char data[64];
26 int wnaf[256];
27} bench_inv;
28
29static void bench_setup(void* arg) {
30 bench_inv *data = (bench_inv*)arg;
31
32 static const unsigned char init[4][32] = {
33 /* Initializer for scalar[0], fe[0], first half of data, the X coordinate of ge[0],
34 and the (implied affine) X coordinate of gej[0]. */
35 {
36 0x02, 0x03, 0x05, 0x07, 0x0b, 0x0d, 0x11, 0x13,
37 0x17, 0x1d, 0x1f, 0x25, 0x29, 0x2b, 0x2f, 0x35,
38 0x3b, 0x3d, 0x43, 0x47, 0x49, 0x4f, 0x53, 0x59,
39 0x61, 0x65, 0x67, 0x6b, 0x6d, 0x71, 0x7f, 0x83
40 },
41 /* Initializer for scalar[1], fe[1], first half of data, the X coordinate of ge[1],
42 and the (implied affine) X coordinate of gej[1]. */
43 {
44 0x82, 0x83, 0x85, 0x87, 0x8b, 0x8d, 0x81, 0x83,
45 0x97, 0xad, 0xaf, 0xb5, 0xb9, 0xbb, 0xbf, 0xc5,
46 0xdb, 0xdd, 0xe3, 0xe7, 0xe9, 0xef, 0xf3, 0xf9,
47 0x11, 0x15, 0x17, 0x1b, 0x1d, 0xb1, 0xbf, 0xd3
48 },
49 /* Initializer for fe[2] and the Z coordinate of gej[0]. */
50 {
51 0x3d, 0x2d, 0xef, 0xf4, 0x25, 0x98, 0x4f, 0x5d,
52 0xe2, 0xca, 0x5f, 0x41, 0x3f, 0x3f, 0xce, 0x44,
53 0xaa, 0x2c, 0x53, 0x8a, 0xc6, 0x59, 0x1f, 0x38,
54 0x38, 0x23, 0xe4, 0x11, 0x27, 0xc6, 0xa0, 0xe7
55 },
56 /* Initializer for fe[3] and the Z coordinate of gej[1]. */
57 {
58 0xbd, 0x21, 0xa5, 0xe1, 0x13, 0x50, 0x73, 0x2e,
59 0x52, 0x98, 0xc8, 0x9e, 0xab, 0x00, 0xa2, 0x68,
60 0x43, 0xf5, 0xd7, 0x49, 0x80, 0x72, 0xa7, 0xf3,
61 0xd7, 0x60, 0xe6, 0xab, 0x90, 0x92, 0xdf, 0xc5
62 }
63 };
64
65 secp256k1_scalar_set_b32(&data->scalar[0], init[0], NULL);
66 secp256k1_scalar_set_b32(&data->scalar[1], init[1], NULL);
67 secp256k1_fe_set_b32_limit(&data->fe[0], init[0]);
68 secp256k1_fe_set_b32_limit(&data->fe[1], init[1]);
69 secp256k1_fe_set_b32_limit(&data->fe[2], init[2]);
70 secp256k1_fe_set_b32_limit(&data->fe[3], init[3]);
71 CHECK(secp256k1_ge_set_xo_var(&data->ge[0], &data->fe[0], 0));
72 CHECK(secp256k1_ge_set_xo_var(&data->ge[1], &data->fe[1], 1));
73 secp256k1_gej_set_ge(&data->gej[0], &data->ge[0]);
74 secp256k1_gej_rescale(&data->gej[0], &data->fe[2]);
75 secp256k1_gej_set_ge(&data->gej[1], &data->ge[1]);
76 secp256k1_gej_rescale(&data->gej[1], &data->fe[3]);
77 memcpy(data->data, init[0], 32);
78 memcpy(data->data + 32, init[1], 32);
79}
80
81static void bench_scalar_add(void* arg, int iters) {
82 int i, j = 0;
83 bench_inv *data = (bench_inv*)arg;
84
85 for (i = 0; i < iters; i++) {
86 j += secp256k1_scalar_add(&data->scalar[0], &data->scalar[0], &data->scalar[1]);
87 }
88 CHECK(j <= iters);
89}
90
91static void bench_scalar_negate(void* arg, int iters) {
92 int i;
93 bench_inv *data = (bench_inv*)arg;
94
95 for (i = 0; i < iters; i++) {
96 secp256k1_scalar_negate(&data->scalar[0], &data->scalar[0]);
97 }
98}
99
100static void bench_scalar_half(void* arg, int iters) {
101 int i;
102 bench_inv *data = (bench_inv*)arg;
103 secp256k1_scalar s = data->scalar[0];
104
105 for (i = 0; i < iters; i++) {
106 secp256k1_scalar_half(&s, &s);
107 }
108
109 data->scalar[0] = s;
110}
111
112static void bench_scalar_mul(void* arg, int iters) {
113 int i;
114 bench_inv *data = (bench_inv*)arg;
115
116 for (i = 0; i < iters; i++) {
117 secp256k1_scalar_mul(&data->scalar[0], &data->scalar[0], &data->scalar[1]);
118 }
119}
120
121static void bench_scalar_split(void* arg, int iters) {
122 int i, j = 0;
123 bench_inv *data = (bench_inv*)arg;
125
126 for (i = 0; i < iters; i++) {
127 secp256k1_scalar_split_lambda(&tmp, &data->scalar[1], &data->scalar[0]);
128 j += secp256k1_scalar_add(&data->scalar[0], &tmp, &data->scalar[1]);
129 }
130 CHECK(j <= iters);
131}
132
133static void bench_scalar_inverse(void* arg, int iters) {
134 int i, j = 0;
135 bench_inv *data = (bench_inv*)arg;
136
137 for (i = 0; i < iters; i++) {
138 secp256k1_scalar_inverse(&data->scalar[0], &data->scalar[0]);
139 j += secp256k1_scalar_add(&data->scalar[0], &data->scalar[0], &data->scalar[1]);
140 }
141 CHECK(j <= iters);
142}
143
144static void bench_scalar_inverse_var(void* arg, int iters) {
145 int i, j = 0;
146 bench_inv *data = (bench_inv*)arg;
147
148 for (i = 0; i < iters; i++) {
149 secp256k1_scalar_inverse_var(&data->scalar[0], &data->scalar[0]);
150 j += secp256k1_scalar_add(&data->scalar[0], &data->scalar[0], &data->scalar[1]);
151 }
152 CHECK(j <= iters);
153}
154
155static void bench_field_half(void* arg, int iters) {
156 int i;
157 bench_inv *data = (bench_inv*)arg;
158
159 for (i = 0; i < iters; i++) {
160 secp256k1_fe_half(&data->fe[0]);
161 }
162}
163
164static void bench_field_normalize(void* arg, int iters) {
165 int i;
166 bench_inv *data = (bench_inv*)arg;
167
168 for (i = 0; i < iters; i++) {
169 secp256k1_fe_normalize(&data->fe[0]);
170 }
171}
172
173static void bench_field_normalize_weak(void* arg, int iters) {
174 int i;
175 bench_inv *data = (bench_inv*)arg;
176
177 for (i = 0; i < iters; i++) {
179 }
180}
181
182static void bench_field_mul(void* arg, int iters) {
183 int i;
184 bench_inv *data = (bench_inv*)arg;
185
186 for (i = 0; i < iters; i++) {
187 secp256k1_fe_mul(&data->fe[0], &data->fe[0], &data->fe[1]);
188 }
189}
190
191static void bench_field_sqr(void* arg, int iters) {
192 int i;
193 bench_inv *data = (bench_inv*)arg;
194
195 for (i = 0; i < iters; i++) {
196 secp256k1_fe_sqr(&data->fe[0], &data->fe[0]);
197 }
198}
199
200static void bench_field_inverse(void* arg, int iters) {
201 int i;
202 bench_inv *data = (bench_inv*)arg;
203
204 for (i = 0; i < iters; i++) {
205 secp256k1_fe_inv(&data->fe[0], &data->fe[0]);
206 secp256k1_fe_add(&data->fe[0], &data->fe[1]);
207 }
208}
209
210static void bench_field_inverse_var(void* arg, int iters) {
211 int i;
212 bench_inv *data = (bench_inv*)arg;
213
214 for (i = 0; i < iters; i++) {
215 secp256k1_fe_inv_var(&data->fe[0], &data->fe[0]);
216 secp256k1_fe_add(&data->fe[0], &data->fe[1]);
217 }
218}
219
220static void bench_field_sqrt(void* arg, int iters) {
221 int i, j = 0;
222 bench_inv *data = (bench_inv*)arg;
223 secp256k1_fe t;
224
225 for (i = 0; i < iters; i++) {
226 t = data->fe[0];
227 j += secp256k1_fe_sqrt(&data->fe[0], &t);
228 secp256k1_fe_add(&data->fe[0], &data->fe[1]);
229 }
230 CHECK(j <= iters);
231}
232
233static void bench_field_is_square_var(void* arg, int iters) {
234 int i, j = 0;
235 bench_inv *data = (bench_inv*)arg;
236 secp256k1_fe t = data->fe[0];
237
238 for (i = 0; i < iters; i++) {
240 secp256k1_fe_add(&t, &data->fe[1]);
242 }
243 CHECK(j <= iters);
244}
245
246static void bench_group_double_var(void* arg, int iters) {
247 int i;
248 bench_inv *data = (bench_inv*)arg;
249
250 for (i = 0; i < iters; i++) {
251 secp256k1_gej_double_var(&data->gej[0], &data->gej[0], NULL);
252 }
253}
254
255static void bench_group_add_var(void* arg, int iters) {
256 int i;
257 bench_inv *data = (bench_inv*)arg;
258
259 for (i = 0; i < iters; i++) {
260 secp256k1_gej_add_var(&data->gej[0], &data->gej[0], &data->gej[1], NULL);
261 }
262}
263
264static void bench_group_add_affine(void* arg, int iters) {
265 int i;
266 bench_inv *data = (bench_inv*)arg;
267
268 for (i = 0; i < iters; i++) {
269 secp256k1_gej_add_ge(&data->gej[0], &data->gej[0], &data->ge[1]);
270 }
271}
272
273static void bench_group_add_affine_var(void* arg, int iters) {
274 int i;
275 bench_inv *data = (bench_inv*)arg;
276
277 for (i = 0; i < iters; i++) {
278 secp256k1_gej_add_ge_var(&data->gej[0], &data->gej[0], &data->ge[1], NULL);
279 }
280}
281
282static void bench_group_add_zinv_var(void* arg, int iters) {
283 int i;
284 bench_inv *data = (bench_inv*)arg;
285
286 for (i = 0; i < iters; i++) {
287 secp256k1_gej_add_zinv_var(&data->gej[0], &data->gej[0], &data->ge[1], &data->gej[0].y);
288 }
289}
290
291static void bench_group_jacobi_var(void* arg, int iters) {
292 int i, j = 0;
293 bench_inv *data = (bench_inv*)arg;
294
295 for (i = 0; i < iters; i++) {
296 j += secp256k1_gej_has_quad_y_var(&data->gej[0]);
297 /* Vary the Y and Z coordinates of the input (the X coordinate doesn't matter to
298 secp256k1_gej_has_quad_y_var). Note that the resulting coordinates will
299 generally not correspond to a point on the curve, but this is not a problem
300 for the code being benchmarked here. Adding and normalizing have less
301 overhead than EC operations (which could guarantee the point remains on the
302 curve). */
303 secp256k1_fe_add(&data->gej[0].y, &data->fe[1]);
304 secp256k1_fe_add(&data->gej[0].z, &data->fe[2]);
307 }
308 CHECK(j <= iters);
309}
310
311static void bench_group_to_affine_var(void* arg, int iters) {
312 int i;
313 bench_inv *data = (bench_inv*)arg;
314
315 for (i = 0; i < iters; ++i) {
316 secp256k1_ge_set_gej_var(&data->ge[1], &data->gej[0]);
317 /* Use the output affine X/Y coordinates to vary the input X/Y/Z coordinates.
318 Similar to bench_group_jacobi_var, this approach does not result in
319 coordinates of points on the curve. */
320 secp256k1_fe_add(&data->gej[0].x, &data->ge[1].y);
321 secp256k1_fe_add(&data->gej[0].y, &data->fe[2]);
322 secp256k1_fe_add(&data->gej[0].z, &data->ge[1].x);
326 }
327}
328
329static void bench_ecmult_wnaf(void* arg, int iters) {
330 int i, bits = 0, overflow = 0;
331 bench_inv *data = (bench_inv*)arg;
332
333 for (i = 0; i < iters; i++) {
334 bits += secp256k1_ecmult_wnaf(data->wnaf, 256, &data->scalar[0], WINDOW_A);
335 overflow += secp256k1_scalar_add(&data->scalar[0], &data->scalar[0], &data->scalar[1]);
336 }
337 CHECK(overflow >= 0);
338 CHECK(bits <= 256*iters);
339}
340
341static void bench_sha256(void* arg, int iters) {
342 int i;
343 bench_inv *data = (bench_inv*)arg;
345
346 for (i = 0; i < iters; i++) {
348 secp256k1_sha256_write(&sha, data->data, 32);
349 secp256k1_sha256_finalize(&sha, data->data);
350 }
351}
352
353static void bench_hmac_sha256(void* arg, int iters) {
354 int i;
355 bench_inv *data = (bench_inv*)arg;
357
358 for (i = 0; i < iters; i++) {
359 secp256k1_hmac_sha256_initialize(&hmac, data->data, 32);
360 secp256k1_hmac_sha256_write(&hmac, data->data, 32);
362 }
363}
364
365static void bench_rfc6979_hmac_sha256(void* arg, int iters) {
366 int i;
367 bench_inv *data = (bench_inv*)arg;
369
370 for (i = 0; i < iters; i++) {
373 }
374}
375
376static void bench_context(void* arg, int iters) {
377 int i;
378 (void)arg;
379 for (i = 0; i < iters; i++) {
381 }
382}
383
384int main(int argc, char **argv) {
385 bench_inv data;
386 int iters = get_iters(20000);
387 int d = argc == 1; /* default */
389
390 if (d || have_flag(argc, argv, "scalar") || have_flag(argc, argv, "half")) run_benchmark("scalar_half", bench_scalar_half, bench_setup, NULL, &data, 10, iters*100);
391 if (d || have_flag(argc, argv, "scalar") || have_flag(argc, argv, "add")) run_benchmark("scalar_add", bench_scalar_add, bench_setup, NULL, &data, 10, iters*100);
392 if (d || have_flag(argc, argv, "scalar") || have_flag(argc, argv, "negate")) run_benchmark("scalar_negate", bench_scalar_negate, bench_setup, NULL, &data, 10, iters*100);
393 if (d || have_flag(argc, argv, "scalar") || have_flag(argc, argv, "mul")) run_benchmark("scalar_mul", bench_scalar_mul, bench_setup, NULL, &data, 10, iters*10);
394 if (d || have_flag(argc, argv, "scalar") || have_flag(argc, argv, "split")) run_benchmark("scalar_split", bench_scalar_split, bench_setup, NULL, &data, 10, iters);
395 if (d || have_flag(argc, argv, "scalar") || have_flag(argc, argv, "inverse")) run_benchmark("scalar_inverse", bench_scalar_inverse, bench_setup, NULL, &data, 10, iters);
396 if (d || have_flag(argc, argv, "scalar") || have_flag(argc, argv, "inverse")) run_benchmark("scalar_inverse_var", bench_scalar_inverse_var, bench_setup, NULL, &data, 10, iters);
397
398 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "half")) run_benchmark("field_half", bench_field_half, bench_setup, NULL, &data, 10, iters*100);
399 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "normalize")) run_benchmark("field_normalize", bench_field_normalize, bench_setup, NULL, &data, 10, iters*100);
400 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "normalize")) run_benchmark("field_normalize_weak", bench_field_normalize_weak, bench_setup, NULL, &data, 10, iters*100);
401 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "sqr")) run_benchmark("field_sqr", bench_field_sqr, bench_setup, NULL, &data, 10, iters*10);
402 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "mul")) run_benchmark("field_mul", bench_field_mul, bench_setup, NULL, &data, 10, iters*10);
403 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "inverse")) run_benchmark("field_inverse", bench_field_inverse, bench_setup, NULL, &data, 10, iters);
404 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "inverse")) run_benchmark("field_inverse_var", bench_field_inverse_var, bench_setup, NULL, &data, 10, iters);
405 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "issquare")) run_benchmark("field_is_square_var", bench_field_is_square_var, bench_setup, NULL, &data, 10, iters);
406 if (d || have_flag(argc, argv, "field") || have_flag(argc, argv, "sqrt")) run_benchmark("field_sqrt", bench_field_sqrt, bench_setup, NULL, &data, 10, iters);
407
408 if (d || have_flag(argc, argv, "group") || have_flag(argc, argv, "double")) run_benchmark("group_double_var", bench_group_double_var, bench_setup, NULL, &data, 10, iters*10);
409 if (d || have_flag(argc, argv, "group") || have_flag(argc, argv, "add")) run_benchmark("group_add_var", bench_group_add_var, bench_setup, NULL, &data, 10, iters*10);
410 if (d || have_flag(argc, argv, "group") || have_flag(argc, argv, "add")) run_benchmark("group_add_affine", bench_group_add_affine, bench_setup, NULL, &data, 10, iters*10);
411 if (d || have_flag(argc, argv, "group") || have_flag(argc, argv, "add")) run_benchmark("group_add_affine_var", bench_group_add_affine_var, bench_setup, NULL, &data, 10, iters*10);
412 if (d || have_flag(argc, argv, "group") || have_flag(argc, argv, "add")) run_benchmark("group_add_zinv_var", bench_group_add_zinv_var, bench_setup, NULL, &data, 10, iters*10);
413 if (d || have_flag(argc, argv, "group") || have_flag(argc, argv, "jacobi")) run_benchmark("group_jacobi_var", bench_group_jacobi_var, bench_setup, NULL, &data, 10, iters);
414 if (d || have_flag(argc, argv, "group") || have_flag(argc, argv, "to_affine")) run_benchmark("group_to_affine_var", bench_group_to_affine_var, bench_setup, NULL, &data, 10, iters);
415
416 if (d || have_flag(argc, argv, "ecmult") || have_flag(argc, argv, "wnaf")) run_benchmark("ecmult_wnaf", bench_ecmult_wnaf, bench_setup, NULL, &data, 10, iters);
417
418 if (d || have_flag(argc, argv, "hash") || have_flag(argc, argv, "sha256")) run_benchmark("hash_sha256", bench_sha256, bench_setup, NULL, &data, 10, iters);
419 if (d || have_flag(argc, argv, "hash") || have_flag(argc, argv, "hmac")) run_benchmark("hash_hmac_sha256", bench_hmac_sha256, bench_setup, NULL, &data, 10, iters);
420 if (d || have_flag(argc, argv, "hash") || have_flag(argc, argv, "rng6979")) run_benchmark("hash_rfc6979_hmac_sha256", bench_rfc6979_hmac_sha256, bench_setup, NULL, &data, 10, iters);
421
422 if (d || have_flag(argc, argv, "context")) run_benchmark("context_create", bench_context, bench_setup, NULL, &data, 10, iters);
423
424 return 0;
425}
static void bench_setup(void *arg)
static void bench_scalar_inverse(void *arg, int iters)
static void bench_scalar_inverse_var(void *arg, int iters)
static void bench_field_mul(void *arg, int iters)
static void bench_sha256(void *arg, int iters)
static void bench_rfc6979_hmac_sha256(void *arg, int iters)
static void bench_scalar_negate(void *arg, int iters)
static void bench_scalar_split(void *arg, int iters)
static void bench_group_jacobi_var(void *arg, int iters)
static void bench_scalar_add(void *arg, int iters)
int main(int argc, char **argv)
static void bench_field_normalize(void *arg, int iters)
static void bench_ecmult_wnaf(void *arg, int iters)
static void bench_group_add_zinv_var(void *arg, int iters)
static void bench_group_double_var(void *arg, int iters)
static void bench_field_inverse(void *arg, int iters)
static void bench_group_to_affine_var(void *arg, int iters)
static void bench_field_sqr(void *arg, int iters)
static void bench_scalar_mul(void *arg, int iters)
static void bench_field_normalize_weak(void *arg, int iters)
static void bench_group_add_affine_var(void *arg, int iters)
static void bench_field_is_square_var(void *arg, int iters)
static void bench_group_add_affine(void *arg, int iters)
static void bench_context(void *arg, int iters)
static void bench_field_half(void *arg, int iters)
static void bench_group_add_var(void *arg, int iters)
static void bench_field_inverse_var(void *arg, int iters)
static void bench_hmac_sha256(void *arg, int iters)
static void bench_field_sqrt(void *arg, int iters)
static void bench_scalar_half(void *arg, int iters)
static void run_benchmark(char *name, void(*benchmark)(void *), void(*setup)(void *), void(*teardown)(void *), void *data, int count, int iter)
Definition: bench.c:26
static int secp256k1_ecmult_wnaf(int *wnaf, int len, const secp256k1_scalar *a, int w)
Convert a number to WNAF notation.
Definition: ecmult_impl.h:159
#define WINDOW_A
Definition: ecmult_impl.h:32
#define secp256k1_fe_normalize_weak
Definition: field.h:79
#define secp256k1_fe_mul
Definition: field.h:94
static int secp256k1_fe_sqrt(secp256k1_fe *SECP256K1_RESTRICT r, const secp256k1_fe *SECP256K1_RESTRICT a)
Compute a square root of a field element.
#define secp256k1_fe_add
Definition: field.h:93
#define secp256k1_fe_normalize_var
Definition: field.h:80
#define secp256k1_fe_half
Definition: field.h:102
#define secp256k1_fe_inv_var
Definition: field.h:100
#define secp256k1_fe_set_b32_limit
Definition: field.h:89
#define secp256k1_fe_is_square_var
Definition: field.h:104
#define secp256k1_fe_inv
Definition: field.h:99
#define secp256k1_fe_sqr
Definition: field.h:95
#define secp256k1_fe_normalize
Definition: field.h:78
static void secp256k1_gej_double_var(secp256k1_gej *r, const secp256k1_gej *a, secp256k1_fe *rzr)
Set r equal to the double of a.
static void secp256k1_gej_add_zinv_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b, const secp256k1_fe *bzinv)
Set r equal to the sum of a and b (with the inverse of b's Z coordinate passed as bzinv).
static int secp256k1_ge_set_xo_var(secp256k1_ge *r, const secp256k1_fe *x, int odd)
Set a group element (affine) equal to the point with the given X coordinate, and given oddness for Y.
static void secp256k1_gej_add_ge_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b, secp256k1_fe *rzr)
Set r equal to the sum of a and b (with b given in affine coordinates).
static void secp256k1_gej_add_ge(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b)
Set r equal to the sum of a and b (with b given in affine coordinates, and not infinity).
static void secp256k1_gej_add_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_gej *b, secp256k1_fe *rzr)
Set r equal to the sum of a and b.
static void secp256k1_gej_rescale(secp256k1_gej *r, const secp256k1_fe *b)
Rescale a jacobian point by b which must be non-zero.
static void secp256k1_gej_set_ge(secp256k1_gej *r, const secp256k1_ge *a)
Set a group element (jacobian) equal to another which is given in affine coordinates.
static void secp256k1_ge_set_gej_var(secp256k1_ge *r, secp256k1_gej *a)
Set a group element equal to another which is given in jacobian coordinates.
static int secp256k1_gej_has_quad_y_var(const secp256k1_gej *a)
Check whether a group element's y coordinate is a quadratic residue.
Definition: common.cpp:23
static void secp256k1_scalar_half(secp256k1_scalar *r, const secp256k1_scalar *a)
Multiply a scalar with the multiplicative inverse of 2.
static void secp256k1_scalar_set_b32(secp256k1_scalar *r, const unsigned char *bin, int *overflow)
Set a scalar from a big endian byte array.
static void secp256k1_scalar_inverse_var(secp256k1_scalar *r, const secp256k1_scalar *a)
Compute the inverse of a scalar (modulo the group order), without constant-time guarantee.
static int secp256k1_scalar_add(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b)
Add two scalars together (modulo the group order).
static void secp256k1_scalar_mul(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b)
Multiply two scalars (modulo the group order).
static void secp256k1_scalar_negate(secp256k1_scalar *r, const secp256k1_scalar *a)
Compute the complement of a scalar (modulo the group order).
static void secp256k1_scalar_split_lambda(secp256k1_scalar *SECP256K1_RESTRICT r1, secp256k1_scalar *SECP256K1_RESTRICT r2, const secp256k1_scalar *SECP256K1_RESTRICT k)
Find r1 and r2 such that r1+r2*lambda = k, where r1 and r2 or their negations are maximum 128 bits lo...
static void secp256k1_scalar_inverse(secp256k1_scalar *r, const secp256k1_scalar *a)
Compute the inverse of a scalar (modulo the group order).
static int get_iters(int default_iters)
Definition: bench.h:170
static void print_output_table_header_row(void)
Definition: bench.h:179
static int have_flag(int argc, char **argv, char *flag)
Definition: bench.h:132
static void secp256k1_sha256_initialize(secp256k1_sha256 *hash)
static void secp256k1_rfc6979_hmac_sha256_generate(secp256k1_rfc6979_hmac_sha256 *rng, unsigned char *out, size_t outlen)
static void secp256k1_hmac_sha256_finalize(secp256k1_hmac_sha256 *hash, unsigned char *out32)
static void secp256k1_hmac_sha256_initialize(secp256k1_hmac_sha256 *hash, const unsigned char *key, size_t size)
static void secp256k1_sha256_finalize(secp256k1_sha256 *hash, unsigned char *out32)
static void secp256k1_rfc6979_hmac_sha256_initialize(secp256k1_rfc6979_hmac_sha256 *rng, const unsigned char *key, size_t keylen)
static void secp256k1_hmac_sha256_write(secp256k1_hmac_sha256 *hash, const unsigned char *data, size_t size)
static void secp256k1_sha256_write(secp256k1_sha256 *hash, const unsigned char *data, size_t size)
#define CHECK(cond)
Definition: util.h:128
SECP256K1_API void secp256k1_context_destroy(secp256k1_context *ctx) SECP256K1_ARG_NONNULL(1)
Destroy a secp256k1 context object (created in dynamically allocated memory).
Definition: secp256k1.c:186
SECP256K1_API secp256k1_context * secp256k1_context_create(unsigned int flags) SECP256K1_WARN_UNUSED_RESULT
Create a secp256k1 context object (in dynamically allocated memory).
Definition: secp256k1.c:140
#define SECP256K1_CONTEXT_NONE
Context flags to pass to secp256k1_context_create, secp256k1_context_preallocated_size,...
Definition: secp256k1.h:192
secp256k1_ge ge[2]
secp256k1_gej gej[2]
int wnaf[256]
secp256k1_scalar scalar[2]
unsigned char data[64]
secp256k1_fe fe[4]
This field implementation represents the value as 10 uint32_t limbs in base 2^26.
Definition: field_10x26.h:14
A group element in affine coordinates on the secp256k1 curve, or occasionally on an isomorphic curve ...
Definition: group.h:16
secp256k1_fe x
Definition: group.h:17
secp256k1_fe y
Definition: group.h:18
A group element of the secp256k1 curve, in jacobian coordinates.
Definition: group.h:28
secp256k1_fe y
Definition: group.h:30
secp256k1_fe x
Definition: group.h:29
secp256k1_fe z
Definition: group.h:31
A scalar modulo the group order of the secp256k1 curve.
Definition: scalar_4x64.h:13