1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
(**
Base field: 2^254 + 45560315531506369815346746415080538113 = 28948022309329048855892746252171976963363056481941647379679742748393362948097 (254 bits - 32 bytes)
Scalar field: 2^254 + 45560315531419706090280762371685220353 = 28948022309329048855892746252171976963363056481941560715954676764349967630337 (254 bits - 32 bytes)
Base field multiplicative subgroup decomposition:
2^32 * 3^2 * 1709 * 24859 * 17627503553531704781201602214972145569028026719617221564519
Prime field multiplication subgroup decomposition:
2^32 * 3 * 463 * 4852402207910482324454106387152561316357015077916052529702775169
*)
let two_z = Z.succ Z.one
module Fq = Ff.MakeFp (struct
let prime_order =
Z.((two_z ** 254) + Z.of_string "45560315531506369815346746415080538113")
end)
module Fp = Ff.MakeFp (struct
let prime_order =
Z.((two_z ** 254) + Z.of_string "45560315531419706090280762371685220353")
end)
module Jacobian =
Ec.MakeJacobianWeierstrass (Fq) (Fp)
(struct
let a = Fq.zero
let b = Fq.of_z (Z.of_int 5)
let cofactor = Z.one
let bytes_generator =
Bytes.concat
Bytes.empty
[
Fq.(to_bytes (negate (of_string "1")));
Fq.(to_bytes (of_string "2"));
Fq.(to_bytes one);
]
end)
module Projective =
Ec.MakeProjectiveWeierstrass (Fq) (Fp)
(struct
let a = Fq.zero
let b = Fq.of_z (Z.of_int 5)
let cofactor = Z.one
let bytes_generator =
Bytes.concat
Bytes.empty
[
Fq.(to_bytes (negate (of_string "1")));
Fq.(to_bytes (of_string "2"));
Fq.(to_bytes one);
]
end)
module Affine =
Ec.MakeAffineWeierstrass (Fq) (Fp)
(struct
let a = Fq.zero
let b = Fq.of_z (Z.of_int 5)
let cofactor = Z.one
let bytes_generator =
Bytes.concat
Bytes.empty
[
Fq.(to_bytes (negate (of_string "1"))); Fq.(to_bytes (of_string "2"));
]
end)
let from_affine_weierstrass_to_jacobian_weierstrass p =
Ec.from_affine_weierstrass_to_jacobian_weierstrass
(module Affine)
(module Jacobian)
p
let from_affine_weierstrass_to_projective_weierstrass p =
Ec.from_affine_weierstrass_to_projective_weierstrass
(module Affine)
(module Projective)
p
let from_jacobian_weierstrass_to_affine_weierstrass p =
Ec.from_jacobian_weierstrass_to_affine_weierstrass
(module Jacobian)
(module Affine)
p
let from_projective_weierstrass_to_affine_weierstrass p =
Ec.from_projective_weierstrass_to_affine_weierstrass
(module Projective)
(module Affine)
p