airbender_crypto/bn254/curves/
g1.rs1#[cfg(any(
2 all(target_arch = "riscv32", feature = "bigint_ops"),
3 test,
4 feature = "proving"
5))]
6use crate::ark_ff_delegation::MontFp;
7use ark_ec::{
8 bn,
9 models::{short_weierstrass::SWCurveConfig, CurveConfig},
10 scalar_mul::glv::GLVConfig,
11 short_weierstrass::{Affine, Projective},
12 AffineRepr,
13};
14#[cfg(not(any(
15 all(target_arch = "riscv32", feature = "bigint_ops"),
16 test,
17 feature = "proving"
18)))]
19use ark_ff::MontFp;
20use ark_ff::{AdditiveGroup, BigInt, Field, PrimeField, Zero};
21use ruint::aliases::U512;
22
23use crate::{
24 bn254::fields::{Fq, Fr},
25 glv_decomposition::GLVConfigNoAllocator,
26};
27
28#[derive(Clone, Default, PartialEq, Eq)]
29pub struct Config;
30
31pub type G1Affine = Affine<Config>;
32
33impl CurveConfig for Config {
34 type BaseField = Fq;
35 type ScalarField = Fr;
36
37 const COFACTOR: &'static [u64] = &[0x1];
39
40 const COFACTOR_INV: Fr = Fr::ONE;
42}
43
44impl SWCurveConfig for Config {
45 const COEFF_A: Fq = Fq::ZERO;
47
48 const COEFF_B: Fq = MontFp!("3");
50
51 const GENERATOR: G1Affine = G1Affine::new_unchecked(G1_GENERATOR_X, G1_GENERATOR_Y);
53
54 #[inline(always)]
55 fn mul_by_a(_: Self::BaseField) -> Self::BaseField {
56 Self::BaseField::zero()
57 }
58
59 #[inline]
60 fn mul_projective(
61 p: &bn::G1Projective<super::Config>,
62 scalar: &[u64],
63 ) -> bn::G1Projective<super::Config> {
64 let s = Self::ScalarField::from_sign_and_limbs(true, scalar);
65 GLVConfig::glv_mul_projective(*p, s)
66 }
67
68 #[inline]
69 fn mul_affine(base: &Affine<Self>, scalar: &[u64]) -> bn::G1Projective<super::Config> {
70 Self::mul_projective(&base.into_group(), scalar)
71 }
72
73 #[inline]
74 fn is_in_correct_subgroup_assuming_on_curve(_p: &G1Affine) -> bool {
75 true
77 }
78}
79
80impl GLVConfig for Config {
81 const ENDO_COEFFS: &'static [Self::BaseField] = &[MontFp!(
82 "21888242871839275220042445260109153167277707414472061641714758635765020556616"
83 )];
84
85 const LAMBDA: Self::ScalarField = ark_ff::MontFp!(
86 "21888242871839275217838484774961031246154997185409878258781734729429964517155"
87 );
88
89 const SCALAR_DECOMP_COEFFS: [(bool, <Self::ScalarField as PrimeField>::BigInt); 4] = [
90 (false, BigInt!("147946756881789319000765030803803410728")),
91 (true, BigInt!("9931322734385697763")),
92 (false, BigInt!("9931322734385697763")),
93 (false, BigInt!("147946756881789319010696353538189108491")),
94 ];
95
96 fn endomorphism(p: &Projective<Self>) -> Projective<Self> {
97 let mut res = (*p).clone();
98 res.x *= Self::ENDO_COEFFS[0];
99 res
100 }
101 fn endomorphism_affine(p: &Affine<Self>) -> Affine<Self> {
102 let mut res = (*p).clone();
103 res.x *= Self::ENDO_COEFFS[0];
104 res
105 }
106
107 fn scalar_decomposition(
108 k: Self::ScalarField,
109 ) -> ((bool, Self::ScalarField), (bool, Self::ScalarField)) {
110 Self::scalar_decomposition_no_allocator(k)
111 }
112}
113
114impl GLVConfigNoAllocator for Config {
115 const BETA_1: (bool, U512) = (
116 false,
117 U512::from_limbs([
118 7440537858994729442,
119 12177485554411886469,
120 1601953548471081566,
121 1485435879091901900,
122 6023842690951505253,
123 5534624963584316114,
124 2,
125 0,
126 ]),
127 );
128
129 const BETA_2: (bool, U512) = (
130 false,
131 U512::from_limbs([
132 10866705332225114937,
133 3332646303595026058,
134 10351474459561409124,
135 7978627105577135858,
136 15644699364383830999,
137 2,
138 0,
139 0,
140 ]),
141 );
142}
143
144pub const G1_GENERATOR_X: Fq = Fq::ONE;
146
147pub const G1_GENERATOR_Y: Fq = MontFp!("2");
149
150#[cfg(test)]
151mod tests {
152 use super::GLVConfigNoAllocator;
153 use super::{Config, CurveConfig, GLVConfig, PrimeField};
154 use proptest::{prop_assert_eq, proptest};
155 type ScalarField = <Config as CurveConfig>::ScalarField;
156
157 #[test]
158 fn compare_scalar_decomposition() {
159 proptest!(|(bytes: [u8; 32])| {
160 let k = ScalarField::from_be_bytes_mod_order(&bytes);
161
162 let (k1, k2) = Config::scalar_decomposition(k.clone());
163 let (k1_ref, k2_ref) = Config::scalar_decomposition_ref(k);
164
165 prop_assert_eq!(k1, k1_ref);
166 prop_assert_eq!(k2, k2_ref);
167 })
168 }
169
170 #[test]
171 fn test_betas() {
172 use ark_std::ops::Neg;
173 use num_bigint::{BigInt, BigUint, Sign};
174 use num_integer::Integer;
175 use ruint::aliases::U512;
176
177 let coeff_bigints: [BigInt; 4] = Config::SCALAR_DECOMP_COEFFS.map(|x| {
178 BigInt::from_biguint(x.0.then_some(Sign::Plus).unwrap_or(Sign::Minus), x.1.into())
179 });
180
181 let [_, n12, _, n22] = coeff_bigints;
182
183 let n = 512u64;
184 let r = BigInt::from(<<Config as CurveConfig>::ScalarField>::MODULUS);
185
186 let beta_1_ref = (n22 << n).div_rem(&r).0;
187
188 let sign = Config::BETA_1
189 .0
190 .then_some(Sign::Plus)
191 .unwrap_or(Sign::Minus);
192 let data = BigUint::from_bytes_be(&Config::BETA_1.1.to_be_bytes::<{ U512::BYTES }>());
193 let beta_1 = BigInt::from_biguint(sign, data);
194 assert_eq!(beta_1, beta_1_ref);
195
196 let beta_2_ref = ((n12 << n).neg()).div_rem(&r).0;
197
198 let sign = Config::BETA_2
199 .0
200 .then_some(Sign::Plus)
201 .unwrap_or(Sign::Minus);
202 let data = BigUint::from_bytes_be(&Config::BETA_2.1.to_be_bytes::<{ U512::BYTES }>());
203 let beta_2 = BigInt::from_biguint(sign, data);
204 assert_eq!(beta_2, beta_2_ref);
205 }
206}