Documentation
¶
Index ¶
- Variables
- func JointScalarMultiplication(p *bls12381.G1Jac, a1, a2 *bls12381.G1Affine, s1, s2 *big.Int) *bls12381.G1Jac
- type BBSCurve
- type Curve
- func (c *Curve) CompressedG1ByteSize() int
- func (c *Curve) CompressedG2ByteSize() int
- func (c *Curve) CoordinateByteSize() int
- func (c *Curve) FExp(a driver.Gt) driver.Gt
- func (c *Curve) G1ByteSize() int
- func (c *Curve) G2ByteSize() int
- func (c *Curve) GenG1() driver.G1
- func (c *Curve) GenG2() driver.G2
- func (c *Curve) GenGt() driver.Gt
- func (c *Curve) GroupOrder() driver.Zr
- func (c *Curve) HashToG1(data []byte) driver.G1
- func (c *Curve) HashToG1WithDomain(data, domain []byte) driver.G1
- func (c *Curve) HashToG2(data []byte) driver.G2
- func (c *Curve) HashToG2WithDomain(data, domain []byte) driver.G2
- func (c *Curve) HashToZr(data []byte) driver.Zr
- func (c *Curve) ModAdd(a1, b1, m driver.Zr) driver.Zr
- func (c *Curve) ModAdd2(a1, b1, c1, m driver.Zr)
- func (c *Curve) ModAddMul(a1, b1 []driver.Zr, m driver.Zr) driver.Zr
- func (c *Curve) ModAddMul2(a1 driver.Zr, c1 driver.Zr, b1 driver.Zr, c2 driver.Zr, m driver.Zr) driver.Zr
- func (c *Curve) ModAddMul2InPlace(result driver.Zr, a1, c1, b1, c2, m driver.Zr)
- func (c *Curve) ModAddMul3(a1 driver.Zr, a2 driver.Zr, b1 driver.Zr, b2 driver.Zr, d1 driver.Zr, ...) driver.Zr
- func (c *Curve) ModAddMul3InPlace(result driver.Zr, a1, a2, b1, b2, d1, d2, m driver.Zr)
- func (c *Curve) ModMul(a1, b1, m driver.Zr) driver.Zr
- func (c *Curve) ModMulInPlace(result, a, b, m driver.Zr)
- func (c *Curve) ModNeg(a1, m driver.Zr) driver.Zr
- func (c *Curve) ModSub(a1, b1, m driver.Zr) driver.Zr
- func (c *Curve) MultiScalarMul(a []driver.G1, b []driver.Zr) driver.G1
- func (c *Curve) NewG1() driver.G1
- func (c *Curve) NewG1FromBytes(b []byte) driver.G1
- func (c *Curve) NewG1FromCompressed(b []byte) driver.G1
- func (c *Curve) NewG2() driver.G2
- func (c *Curve) NewG2FromBytes(b []byte) driver.G2
- func (c *Curve) NewG2FromCompressed(b []byte) driver.G2
- func (c *Curve) NewGtFromBytes(b []byte) driver.Gt
- func (c *Curve) NewRandomZr(rng io.Reader) driver.Zr
- func (c *Curve) NewZrFromBigInt(i *big.Int) driver.Zr
- func (c *Curve) NewZrFromBytes(b []byte) driver.Zr
- func (c *Curve) NewZrFromInt64(i int64) driver.Zr
- func (c *Curve) NewZrFromUint64(i uint64) driver.Zr
- func (c *Curve) Pairing(p2 driver.G2, p1 driver.G1) driver.Gt
- func (c *Curve) Pairing2(p2a, p2b driver.G2, p1a, p1b driver.G1) driver.Gt
- func (p *Curve) Rand() (io.Reader, error)
- func (c *Curve) ScalarByteSize() int
- type G1
- func (g *G1) Add(a driver.G1)
- func (g *G1) Bytes() []byte
- func (g *G1) Clone(a driver.G1)
- func (g *G1) Compressed() []byte
- func (e *G1) Copy() driver.G1
- func (g *G1) Equals(a driver.G1) bool
- func (g *G1) IsInfinity() bool
- func (g *G1) Mul(a driver.Zr) driver.G1
- func (g *G1) Mul2(e driver.Zr, Q driver.G1, f driver.Zr) driver.G1
- func (g *G1) Mul2InPlace(e driver.Zr, Q driver.G1, f driver.Zr)
- func (g *G1) Neg()
- func (g *G1) String() string
- func (g *G1) Sub(a driver.G1)
- type G2
- func (g *G2) Add(a driver.G2)
- func (g *G2) Affine()
- func (g *G2) Bytes() []byte
- func (g *G2) Clone(a driver.G2)
- func (g *G2) Compressed() []byte
- func (e *G2) Copy() driver.G2
- func (g *G2) Equals(a driver.G2) bool
- func (g *G2) Mul(a driver.Zr) driver.G2
- func (g *G2) String() string
- func (g *G2) Sub(a driver.G2)
- type Gt
- type Zr
- func (b *Zr) BigInt() *big.Int
- func (b *Zr) Bytes() []byte
- func (b *Zr) Clone(a driver.Zr)
- func (b *Zr) Copy() driver.Zr
- func (b *Zr) Equals(p driver.Zr) bool
- func (b *Zr) InvModOrder()
- func (b *Zr) InvModP(p driver.Zr)
- func (b *Zr) IsOne() bool
- func (b *Zr) IsZero() bool
- func (b *Zr) Minus(a driver.Zr) driver.Zr
- func (b *Zr) Mod(a driver.Zr)
- func (b *Zr) Mul(x driver.Zr) driver.Zr
- func (b *Zr) Neg()
- func (b *Zr) Plus(a driver.Zr) driver.Zr
- func (b *Zr) PowMod(x driver.Zr) driver.Zr
- func (b *Zr) String() string
Constants ¶
This section is empty.
Variables ¶
var G1Jacs g1JacPool
G1Jacs is a shared *bls12381.G1Jac{} memory pool
Functions ¶
func JointScalarMultiplication ¶
func JointScalarMultiplication(p *bls12381.G1Jac, a1, a2 *bls12381.G1Affine, s1, s2 *big.Int) *bls12381.G1Jac
JointScalarMultiplication computes [s1]a1+[s2]a2 using Strauss-Shamir technique where a1 and a2 are affine points. This does not use the GLV endomorphism (unlike G1Jac.ScalarMultiplication), so it is an allocation optimization over two independent scalar multiplications plus an addition, not a wall-clock optimization.
Types ¶
type BBSCurve ¶
type BBSCurve struct {
Curve
}
func NewBBSCurve ¶
func NewBBSCurve() *BBSCurve
func (*BBSCurve) HashToG1WithDomain ¶
type Curve ¶
func (*Curve) CompressedG1ByteSize ¶
func (*Curve) CompressedG2ByteSize ¶
func (*Curve) CoordinateByteSize ¶
func (*Curve) G1ByteSize ¶
func (*Curve) G2ByteSize ¶
func (*Curve) GroupOrder ¶
func (*Curve) HashToG1WithDomain ¶
func (*Curve) HashToG2WithDomain ¶
func (*Curve) ModAddMul2 ¶
func (*Curve) ModAddMul2InPlace ¶
func (*Curve) ModAddMul3 ¶
func (*Curve) ModAddMul3InPlace ¶
func (*Curve) ModMulInPlace ¶
func (*Curve) MultiScalarMul ¶
MultiScalarMul computes the sum of the scalar multiplications of the given bases by the given scalars via gnark's bucket-method MultiExp. MultiExp carries a fixed cost (window and chunk setup, goroutine fan-out) that a pairwise Mul2+Add loop does not, so for very small n a caller that knows its sizes may be better served by Mul/Mul2 directly; callers that care make that choice themselves, and this method does not second-guess them beyond the trivial n==0 and n==1 cases.
func (*Curve) NewRandomZr ¶
NewRandomZr draws a uniformly random scalar using rng as the exclusive source of entropy (so the same reader/seed always produces the same scalar), via rejection sampling on a stack buffer - the same strategy fr.Element.SetRandom uses internally, but reading from the caller's reader instead of crypto/rand. Acceptance probability is q/2^255 ~= 0.90, i.e. ~1.1 iterations expected. Allocation-free, unlike a rand.Int-based implementation.
func (*Curve) ScalarByteSize ¶
type G1 ¶
func (*G1) Compressed ¶
func (*G1) IsInfinity ¶
func (*G1) Mul2 ¶
Mul2 computes [e]g + [f]Q via a joint Strauss-Shamir scalar multiplication. Benchmarked against two independent Mul calls plus an Add: allocates far less (1 vs ~26 allocs) but is not faster in wall-clock time, because — unlike Mul — it does not use the GLV endomorphism speedup, so it forgoes the ~2x speedup that GLV gives each individual scalar multiplication.
type G2 ¶
func (*G2) Compressed ¶
type Zr ¶
type Zr struct {
// contains filtered or unexported fields
}
Zr represents a scalar field element backed by fr.Element ([4]uint64). The rawBigInt field is non-nil only for special values like GroupOrder (which equals p and is 0 in the field but needs its actual big.Int value for operations like Mod and InvModP).
Only methods that explicitly branch on rawBigInt (IsZero, IsOne, Bytes, Equals, Copy, Clone, String, Mod, InvModP, InvModOrder, PowMod, toBigInt) preserve the true big-int value. Plus/Minus/Mul operate on val directly (val == 0 whenever rawBigInt != nil, since p mod p == 0), so arithmetic combining a rawBigInt-backed Zr with another Zr via Plus/Minus/Mul silently ignores the raw value. This is safe today because GroupOrder is only ever used as a PowMod exponent (where the result is invariant to the field reduction by Fermat's little theorem) or passed to the rawBigInt-aware methods above — do not add a new arithmetic use of GroupOrder via Plus/Minus/Mul without accounting for this.
func (*Zr) InvModOrder ¶
func (b *Zr) InvModOrder()