Skip to main content

airbender_crypto/bn254/curves/
g1.rs

1#[cfg(any(
2    all(target_arch = "riscv32", feature = "bigint_ops"),
3    test,
4    feature = "proving"
5))]
6use crate::ark_ff_delegation::MontFp;
7use ark_ec::{
8    bn,
9    models::{short_weierstrass::SWCurveConfig, CurveConfig},
10    scalar_mul::glv::GLVConfig,
11    short_weierstrass::{Affine, Projective},
12    AffineRepr,
13};
14#[cfg(not(any(
15    all(target_arch = "riscv32", feature = "bigint_ops"),
16    test,
17    feature = "proving"
18)))]
19use ark_ff::MontFp;
20use ark_ff::{AdditiveGroup, BigInt, Field, PrimeField, Zero};
21use ruint::aliases::U512;
22
23use crate::{
24    bn254::fields::{Fq, Fr},
25    glv_decomposition::GLVConfigNoAllocator,
26};
27
28#[derive(Clone, Default, PartialEq, Eq)]
29pub struct Config;
30
31pub type G1Affine = Affine<Config>;
32
33impl CurveConfig for Config {
34    type BaseField = Fq;
35    type ScalarField = Fr;
36
37    /// COFACTOR = 1
38    const COFACTOR: &'static [u64] = &[0x1];
39
40    /// COFACTOR_INV = COFACTOR^{-1} mod r = 1
41    const COFACTOR_INV: Fr = Fr::ONE;
42}
43
44impl SWCurveConfig for Config {
45    /// COEFF_A = 0
46    const COEFF_A: Fq = Fq::ZERO;
47
48    /// COEFF_B = 3
49    const COEFF_B: Fq = MontFp!("3");
50
51    /// AFFINE_GENERATOR_COEFFS = (G1_GENERATOR_X, G1_GENERATOR_Y)
52    const GENERATOR: G1Affine = G1Affine::new_unchecked(G1_GENERATOR_X, G1_GENERATOR_Y);
53
54    #[inline(always)]
55    fn mul_by_a(_: Self::BaseField) -> Self::BaseField {
56        Self::BaseField::zero()
57    }
58
59    #[inline]
60    fn mul_projective(
61        p: &bn::G1Projective<super::Config>,
62        scalar: &[u64],
63    ) -> bn::G1Projective<super::Config> {
64        let s = Self::ScalarField::from_sign_and_limbs(true, scalar);
65        GLVConfig::glv_mul_projective(*p, s)
66    }
67
68    #[inline]
69    fn mul_affine(base: &Affine<Self>, scalar: &[u64]) -> bn::G1Projective<super::Config> {
70        Self::mul_projective(&base.into_group(), scalar)
71    }
72
73    #[inline]
74    fn is_in_correct_subgroup_assuming_on_curve(_p: &G1Affine) -> bool {
75        // G1 = E(Fq) so if the point is on the curve, it is also in the subgroup.
76        true
77    }
78}
79
80impl GLVConfig for Config {
81    const ENDO_COEFFS: &'static [Self::BaseField] = &[MontFp!(
82        "21888242871839275220042445260109153167277707414472061641714758635765020556616"
83    )];
84
85    const LAMBDA: Self::ScalarField = ark_ff::MontFp!(
86        "21888242871839275217838484774961031246154997185409878258781734729429964517155"
87    );
88
89    const SCALAR_DECOMP_COEFFS: [(bool, <Self::ScalarField as PrimeField>::BigInt); 4] = [
90        (false, BigInt!("147946756881789319000765030803803410728")),
91        (true, BigInt!("9931322734385697763")),
92        (false, BigInt!("9931322734385697763")),
93        (false, BigInt!("147946756881789319010696353538189108491")),
94    ];
95
96    fn endomorphism(p: &Projective<Self>) -> Projective<Self> {
97        let mut res = (*p).clone();
98        res.x *= Self::ENDO_COEFFS[0];
99        res
100    }
101    fn endomorphism_affine(p: &Affine<Self>) -> Affine<Self> {
102        let mut res = (*p).clone();
103        res.x *= Self::ENDO_COEFFS[0];
104        res
105    }
106
107    fn scalar_decomposition(
108        k: Self::ScalarField,
109    ) -> ((bool, Self::ScalarField), (bool, Self::ScalarField)) {
110        Self::scalar_decomposition_no_allocator(k)
111    }
112}
113
114impl GLVConfigNoAllocator for Config {
115    const BETA_1: (bool, U512) = (
116        false,
117        U512::from_limbs([
118            7440537858994729442,
119            12177485554411886469,
120            1601953548471081566,
121            1485435879091901900,
122            6023842690951505253,
123            5534624963584316114,
124            2,
125            0,
126        ]),
127    );
128
129    const BETA_2: (bool, U512) = (
130        false,
131        U512::from_limbs([
132            10866705332225114937,
133            3332646303595026058,
134            10351474459561409124,
135            7978627105577135858,
136            15644699364383830999,
137            2,
138            0,
139            0,
140        ]),
141    );
142}
143
144/// G1_GENERATOR_X = 1
145pub const G1_GENERATOR_X: Fq = Fq::ONE;
146
147/// G1_GENERATOR_Y = 2
148pub const G1_GENERATOR_Y: Fq = MontFp!("2");
149
150#[cfg(test)]
151mod tests {
152    use super::GLVConfigNoAllocator;
153    use super::{Config, CurveConfig, GLVConfig, PrimeField};
154    use proptest::{prop_assert_eq, proptest};
155    type ScalarField = <Config as CurveConfig>::ScalarField;
156
157    #[test]
158    fn compare_scalar_decomposition() {
159        proptest!(|(bytes: [u8; 32])| {
160            let k = ScalarField::from_be_bytes_mod_order(&bytes);
161
162            let (k1, k2) = Config::scalar_decomposition(k.clone());
163            let (k1_ref, k2_ref) = Config::scalar_decomposition_ref(k);
164
165            prop_assert_eq!(k1, k1_ref);
166            prop_assert_eq!(k2, k2_ref);
167        })
168    }
169
170    #[test]
171    fn test_betas() {
172        use ark_std::ops::Neg;
173        use num_bigint::{BigInt, BigUint, Sign};
174        use num_integer::Integer;
175        use ruint::aliases::U512;
176
177        let coeff_bigints: [BigInt; 4] = Config::SCALAR_DECOMP_COEFFS.map(|x| {
178            BigInt::from_biguint(x.0.then_some(Sign::Plus).unwrap_or(Sign::Minus), x.1.into())
179        });
180
181        let [_, n12, _, n22] = coeff_bigints;
182
183        let n = 512u64;
184        let r = BigInt::from(<<Config as CurveConfig>::ScalarField>::MODULUS);
185
186        let beta_1_ref = (n22 << n).div_rem(&r).0;
187
188        let sign = Config::BETA_1
189            .0
190            .then_some(Sign::Plus)
191            .unwrap_or(Sign::Minus);
192        let data = BigUint::from_bytes_be(&Config::BETA_1.1.to_be_bytes::<{ U512::BYTES }>());
193        let beta_1 = BigInt::from_biguint(sign, data);
194        assert_eq!(beta_1, beta_1_ref);
195
196        let beta_2_ref = ((n12 << n).neg()).div_rem(&r).0;
197
198        let sign = Config::BETA_2
199            .0
200            .then_some(Sign::Plus)
201            .unwrap_or(Sign::Minus);
202        let data = BigUint::from_bytes_be(&Config::BETA_2.1.to_be_bytes::<{ U512::BYTES }>());
203        let beta_2 = BigInt::from_biguint(sign, data);
204        assert_eq!(beta_2, beta_2_ref);
205    }
206}