123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257 |
- <!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="generator" content="rustdoc"><meta name="description" content="Source to the Rust file `/Users/travis/.cargo/registry/src/github.com-1ecc6299db9ec823/num-bigint-0.1.44/src/monty.rs`."><meta name="keywords" content="rust, rustlang, rust-lang"><title>monty.rs.html -- source</title><link rel="stylesheet" type="text/css" href="../../normalize.css"><link rel="stylesheet" type="text/css" href="../../rustdoc.css" id="mainThemeStyle"><link rel="stylesheet" type="text/css" href="../../dark.css"><link rel="stylesheet" type="text/css" href="../../light.css" id="themeStyle"><script src="../../storage.js"></script></head><body class="rustdoc source"><!--[if lte IE 8]><div class="warning">This old browser is unsupported and will most likely display funky things.</div><![endif]--><nav class="sidebar"><div class="sidebar-menu">☰</div></nav><div class="theme-picker"><button id="theme-picker" aria-label="Pick another theme!"><img src="../../brush.svg" width="18" alt="Pick another theme!"></button><div id="theme-choices"></div></div><script src="../../theme.js"></script><nav class="sub"><form class="search-form js-only"><div class="search-container"><input class="search-input" name="search" autocomplete="off" placeholder="Click or press ‘S’ to search, ‘?’ for more options…" type="search"><a id="settings-menu" href="../../settings.html"><img src="../../wheel.svg" width="18" alt="Change settings"></a></div></form></nav><section id="main" class="content"><pre class="line-numbers"><span id="1"> 1</span>
- <span id="2"> 2</span>
- <span id="3"> 3</span>
- <span id="4"> 4</span>
- <span id="5"> 5</span>
- <span id="6"> 6</span>
- <span id="7"> 7</span>
- <span id="8"> 8</span>
- <span id="9"> 9</span>
- <span id="10"> 10</span>
- <span id="11"> 11</span>
- <span id="12"> 12</span>
- <span id="13"> 13</span>
- <span id="14"> 14</span>
- <span id="15"> 15</span>
- <span id="16"> 16</span>
- <span id="17"> 17</span>
- <span id="18"> 18</span>
- <span id="19"> 19</span>
- <span id="20"> 20</span>
- <span id="21"> 21</span>
- <span id="22"> 22</span>
- <span id="23"> 23</span>
- <span id="24"> 24</span>
- <span id="25"> 25</span>
- <span id="26"> 26</span>
- <span id="27"> 27</span>
- <span id="28"> 28</span>
- <span id="29"> 29</span>
- <span id="30"> 30</span>
- <span id="31"> 31</span>
- <span id="32"> 32</span>
- <span id="33"> 33</span>
- <span id="34"> 34</span>
- <span id="35"> 35</span>
- <span id="36"> 36</span>
- <span id="37"> 37</span>
- <span id="38"> 38</span>
- <span id="39"> 39</span>
- <span id="40"> 40</span>
- <span id="41"> 41</span>
- <span id="42"> 42</span>
- <span id="43"> 43</span>
- <span id="44"> 44</span>
- <span id="45"> 45</span>
- <span id="46"> 46</span>
- <span id="47"> 47</span>
- <span id="48"> 48</span>
- <span id="49"> 49</span>
- <span id="50"> 50</span>
- <span id="51"> 51</span>
- <span id="52"> 52</span>
- <span id="53"> 53</span>
- <span id="54"> 54</span>
- <span id="55"> 55</span>
- <span id="56"> 56</span>
- <span id="57"> 57</span>
- <span id="58"> 58</span>
- <span id="59"> 59</span>
- <span id="60"> 60</span>
- <span id="61"> 61</span>
- <span id="62"> 62</span>
- <span id="63"> 63</span>
- <span id="64"> 64</span>
- <span id="65"> 65</span>
- <span id="66"> 66</span>
- <span id="67"> 67</span>
- <span id="68"> 68</span>
- <span id="69"> 69</span>
- <span id="70"> 70</span>
- <span id="71"> 71</span>
- <span id="72"> 72</span>
- <span id="73"> 73</span>
- <span id="74"> 74</span>
- <span id="75"> 75</span>
- <span id="76"> 76</span>
- <span id="77"> 77</span>
- <span id="78"> 78</span>
- <span id="79"> 79</span>
- <span id="80"> 80</span>
- <span id="81"> 81</span>
- <span id="82"> 82</span>
- <span id="83"> 83</span>
- <span id="84"> 84</span>
- <span id="85"> 85</span>
- <span id="86"> 86</span>
- <span id="87"> 87</span>
- <span id="88"> 88</span>
- <span id="89"> 89</span>
- <span id="90"> 90</span>
- <span id="91"> 91</span>
- <span id="92"> 92</span>
- <span id="93"> 93</span>
- <span id="94"> 94</span>
- <span id="95"> 95</span>
- <span id="96"> 96</span>
- <span id="97"> 97</span>
- <span id="98"> 98</span>
- <span id="99"> 99</span>
- <span id="100">100</span>
- <span id="101">101</span>
- <span id="102">102</span>
- <span id="103">103</span>
- <span id="104">104</span>
- <span id="105">105</span>
- <span id="106">106</span>
- <span id="107">107</span>
- <span id="108">108</span>
- <span id="109">109</span>
- <span id="110">110</span>
- <span id="111">111</span>
- <span id="112">112</span>
- <span id="113">113</span>
- <span id="114">114</span>
- <span id="115">115</span>
- <span id="116">116</span>
- <span id="117">117</span>
- <span id="118">118</span>
- <span id="119">119</span>
- <span id="120">120</span>
- <span id="121">121</span>
- <span id="122">122</span>
- <span id="123">123</span>
- <span id="124">124</span>
- <span id="125">125</span>
- <span id="126">126</span>
- <span id="127">127</span>
- </pre><pre class="rust ">
- <span class="kw">use</span> <span class="ident">integer</span>::<span class="ident">Integer</span>;
- <span class="kw">use</span> <span class="ident">traits</span>::<span class="ident">Zero</span>;
- <span class="kw">use</span> <span class="ident">biguint</span>::<span class="ident">BigUint</span>;
- <span class="kw">struct</span> <span class="ident">MontyReducer</span><span class="op"><</span><span class="lifetime">'a</span><span class="op">></span> {
- <span class="ident">n</span>: <span class="kw-2">&</span><span class="lifetime">'a</span> <span class="ident">BigUint</span>,
- <span class="ident">n0inv</span>: <span class="ident">u32</span>
- }
- <span class="comment">// Calculate the modular inverse of `num`, using Extended GCD.</span>
- <span class="comment">//</span>
- <span class="comment">// Reference:</span>
- <span class="comment">// Brent & Zimmermann, Modern Computer Arithmetic, v0.5.9, Algorithm 1.20</span>
- <span class="kw">fn</span> <span class="ident">inv_mod_u32</span>(<span class="ident">num</span>: <span class="ident">u32</span>) <span class="op">-></span> <span class="ident">u32</span> {
- <span class="comment">// num needs to be relatively prime to 2**32 -- i.e. it must be odd.</span>
- <span class="macro">assert</span><span class="macro">!</span>(<span class="ident">num</span> <span class="op">%</span> <span class="number">2</span> <span class="op">!=</span> <span class="number">0</span>);
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">a</span>: <span class="ident">i64</span> <span class="op">=</span> <span class="ident">num</span> <span class="kw">as</span> <span class="ident">i64</span>;
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">b</span>: <span class="ident">i64</span> <span class="op">=</span> (<span class="ident">u32</span>::<span class="ident">max_value</span>() <span class="kw">as</span> <span class="ident">i64</span>) <span class="op">+</span> <span class="number">1</span>;
- <span class="comment">// ExtendedGcd</span>
- <span class="comment">// Input: positive integers a and b</span>
- <span class="comment">// Output: integers (g, u, v) such that g = gcd(a, b) = ua + vb</span>
- <span class="comment">// As we don't need v for modular inverse, we don't calculate it.</span>
- <span class="comment">// 1: (u, w) <- (1, 0)</span>
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">u</span> <span class="op">=</span> <span class="number">1</span>;
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">w</span> <span class="op">=</span> <span class="number">0</span>;
- <span class="comment">// 3: while b != 0</span>
- <span class="kw">while</span> <span class="ident">b</span> <span class="op">!=</span> <span class="number">0</span> {
- <span class="comment">// 4: (q, r) <- DivRem(a, b)</span>
- <span class="kw">let</span> <span class="ident">q</span> <span class="op">=</span> <span class="ident">a</span> <span class="op">/</span> <span class="ident">b</span>;
- <span class="kw">let</span> <span class="ident">r</span> <span class="op">=</span> <span class="ident">a</span> <span class="op">%</span> <span class="ident">b</span>;
- <span class="comment">// 5: (a, b) <- (b, r)</span>
- <span class="ident">a</span> <span class="op">=</span> <span class="ident">b</span>; <span class="ident">b</span> <span class="op">=</span> <span class="ident">r</span>;
- <span class="comment">// 6: (u, w) <- (w, u - qw)</span>
- <span class="kw">let</span> <span class="ident">m</span> <span class="op">=</span> <span class="ident">u</span> <span class="op">-</span> <span class="ident">w</span><span class="kw-2">*</span><span class="ident">q</span>;
- <span class="ident">u</span> <span class="op">=</span> <span class="ident">w</span>; <span class="ident">w</span> <span class="op">=</span> <span class="ident">m</span>;
- }
- <span class="macro">assert</span><span class="macro">!</span>(<span class="ident">a</span> <span class="op">==</span> <span class="number">1</span>);
- <span class="comment">// Downcasting acts like a mod 2^32 too.</span>
- <span class="ident">u</span> <span class="kw">as</span> <span class="ident">u32</span>
- }
- <span class="kw">impl</span><span class="op"><</span><span class="lifetime">'a</span><span class="op">></span> <span class="ident">MontyReducer</span><span class="op"><</span><span class="lifetime">'a</span><span class="op">></span> {
- <span class="kw">fn</span> <span class="ident">new</span>(<span class="ident">n</span>: <span class="kw-2">&</span><span class="lifetime">'a</span> <span class="ident">BigUint</span>) <span class="op">-></span> <span class="self">Self</span> {
- <span class="kw">let</span> <span class="ident">n0inv</span> <span class="op">=</span> <span class="ident">inv_mod_u32</span>(<span class="ident">n</span>.<span class="ident">data</span>[<span class="number">0</span>]);
- <span class="ident">MontyReducer</span> { <span class="ident">n</span>: <span class="ident">n</span>, <span class="ident">n0inv</span>: <span class="ident">n0inv</span> }
- }
- }
- <span class="comment">// Montgomery Reduction</span>
- <span class="comment">//</span>
- <span class="comment">// Reference:</span>
- <span class="comment">// Brent & Zimmermann, Modern Computer Arithmetic, v0.5.9, Algorithm 2.6</span>
- <span class="kw">fn</span> <span class="ident">monty_redc</span>(<span class="ident">a</span>: <span class="ident">BigUint</span>, <span class="ident">mr</span>: <span class="kw-2">&</span><span class="ident">MontyReducer</span>) <span class="op">-></span> <span class="ident">BigUint</span> {
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">c</span> <span class="op">=</span> <span class="ident">a</span>.<span class="ident">data</span>;
- <span class="kw">let</span> <span class="ident">n</span> <span class="op">=</span> <span class="kw-2">&</span><span class="ident">mr</span>.<span class="ident">n</span>.<span class="ident">data</span>;
- <span class="kw">let</span> <span class="ident">n_size</span> <span class="op">=</span> <span class="ident">n</span>.<span class="ident">len</span>();
- <span class="comment">// Allocate sufficient work space</span>
- <span class="ident">c</span>.<span class="ident">resize</span>(<span class="number">2</span> <span class="op">*</span> <span class="ident">n_size</span> <span class="op">+</span> <span class="number">2</span>, <span class="number">0</span>);
- <span class="comment">// β is the size of a word, in this case 32 bits. So "a mod β" is</span>
- <span class="comment">// equivalent to masking a to 32 bits.</span>
- <span class="comment">// mu <- -N^(-1) mod β</span>
- <span class="kw">let</span> <span class="ident">mu</span> <span class="op">=</span> <span class="number">0u32</span>.<span class="ident">wrapping_sub</span>(<span class="ident">mr</span>.<span class="ident">n0inv</span>);
- <span class="comment">// 1: for i = 0 to (n-1)</span>
- <span class="kw">for</span> <span class="ident">i</span> <span class="kw">in</span> <span class="number">0</span>..<span class="ident">n_size</span> {
- <span class="comment">// 2: q_i <- mu*c_i mod β</span>
- <span class="kw">let</span> <span class="ident">q_i</span> <span class="op">=</span> <span class="ident">c</span>[<span class="ident">i</span>].<span class="ident">wrapping_mul</span>(<span class="ident">mu</span>);
- <span class="comment">// 3: C <- C + q_i * N * β^i</span>
- <span class="kw">super</span>::<span class="ident">algorithms</span>::<span class="ident">mac_digit</span>(<span class="kw-2">&</span><span class="kw-2">mut</span> <span class="ident">c</span>[<span class="ident">i</span>..], <span class="ident">n</span>, <span class="ident">q_i</span>);
- }
- <span class="comment">// 4: R <- C * β^(-n)</span>
- <span class="comment">// This is an n-word bitshift, equivalent to skipping n words.</span>
- <span class="kw">let</span> <span class="ident">ret</span> <span class="op">=</span> <span class="ident">BigUint</span>::<span class="ident">new</span>(<span class="ident">c</span>[<span class="ident">n_size</span>..].<span class="ident">to_vec</span>());
- <span class="comment">// 5: if R >= β^n then return R-N else return R.</span>
- <span class="kw">if</span> <span class="kw-2">&</span><span class="ident">ret</span> <span class="op"><</span> <span class="ident">mr</span>.<span class="ident">n</span> {
- <span class="ident">ret</span>
- } <span class="kw">else</span> {
- <span class="ident">ret</span> <span class="op">-</span> <span class="ident">mr</span>.<span class="ident">n</span>
- }
- }
- <span class="comment">// Montgomery Multiplication</span>
- <span class="kw">fn</span> <span class="ident">monty_mult</span>(<span class="ident">a</span>: <span class="ident">BigUint</span>, <span class="ident">b</span>: <span class="kw-2">&</span><span class="ident">BigUint</span>, <span class="ident">mr</span>: <span class="kw-2">&</span><span class="ident">MontyReducer</span>) <span class="op">-></span> <span class="ident">BigUint</span> {
- <span class="ident">monty_redc</span>(<span class="ident">a</span> <span class="op">*</span> <span class="ident">b</span>, <span class="ident">mr</span>)
- }
- <span class="comment">// Montgomery Squaring</span>
- <span class="kw">fn</span> <span class="ident">monty_sqr</span>(<span class="ident">a</span>: <span class="ident">BigUint</span>, <span class="ident">mr</span>: <span class="kw-2">&</span><span class="ident">MontyReducer</span>) <span class="op">-></span> <span class="ident">BigUint</span> {
- <span class="comment">// TODO: Replace with an optimised squaring function</span>
- <span class="ident">monty_redc</span>(<span class="kw-2">&</span><span class="ident">a</span> <span class="op">*</span> <span class="kw-2">&</span><span class="ident">a</span>, <span class="ident">mr</span>)
- }
- <span class="kw">pub</span> <span class="kw">fn</span> <span class="ident">monty_modpow</span>(<span class="ident">a</span>: <span class="kw-2">&</span><span class="ident">BigUint</span>, <span class="ident">exp</span>: <span class="kw-2">&</span><span class="ident">BigUint</span>, <span class="ident">modulus</span>: <span class="kw-2">&</span><span class="ident">BigUint</span>) <span class="op">-></span> <span class="ident">BigUint</span>{
- <span class="kw">let</span> <span class="ident">mr</span> <span class="op">=</span> <span class="ident">MontyReducer</span>::<span class="ident">new</span>(<span class="ident">modulus</span>);
- <span class="comment">// Calculate the Montgomery parameter</span>
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">v</span> <span class="op">=</span> <span class="macro">vec</span><span class="macro">!</span>[<span class="number">0</span>; <span class="ident">modulus</span>.<span class="ident">data</span>.<span class="ident">len</span>()];
- <span class="ident">v</span>.<span class="ident">push</span>(<span class="number">1</span>);
- <span class="kw">let</span> <span class="ident">r</span> <span class="op">=</span> <span class="ident">BigUint</span>::<span class="ident">new</span>(<span class="ident">v</span>);
- <span class="comment">// Map the base to the Montgomery domain</span>
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">apri</span> <span class="op">=</span> <span class="ident">a</span> <span class="op">*</span> <span class="kw-2">&</span><span class="ident">r</span> <span class="op">%</span> <span class="ident">modulus</span>;
- <span class="comment">// Binary exponentiation</span>
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">ans</span> <span class="op">=</span> <span class="kw-2">&</span><span class="ident">r</span> <span class="op">%</span> <span class="ident">modulus</span>;
- <span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">e</span> <span class="op">=</span> <span class="ident">exp</span>.<span class="ident">clone</span>();
- <span class="kw">while</span> <span class="op">!</span><span class="ident">e</span>.<span class="ident">is_zero</span>() {
- <span class="kw">if</span> <span class="ident">e</span>.<span class="ident">is_odd</span>() {
- <span class="ident">ans</span> <span class="op">=</span> <span class="ident">monty_mult</span>(<span class="ident">ans</span>, <span class="kw-2">&</span><span class="ident">apri</span>, <span class="kw-2">&</span><span class="ident">mr</span>);
- }
- <span class="ident">apri</span> <span class="op">=</span> <span class="ident">monty_sqr</span>(<span class="ident">apri</span>, <span class="kw-2">&</span><span class="ident">mr</span>);
- <span class="ident">e</span> <span class="op">=</span> <span class="ident">e</span> <span class="op">>></span> <span class="number">1</span>;
- }
- <span class="comment">// Map the result back to the residues domain</span>
- <span class="ident">monty_redc</span>(<span class="ident">ans</span>, <span class="kw-2">&</span><span class="ident">mr</span>)
- }
- </pre>
- </section><section id="search" class="content hidden"></section><section class="footer"></section><aside id="help" class="hidden"><div><h1 class="hidden">Help</h1><div class="shortcuts"><h2>Keyboard Shortcuts</h2><dl><dt><kbd>?</kbd></dt><dd>Show this help dialog</dd><dt><kbd>S</kbd></dt><dd>Focus the search field</dd><dt><kbd>↑</kbd></dt><dd>Move up in search results</dd><dt><kbd>↓</kbd></dt><dd>Move down in search results</dd><dt><kbd>↹</kbd></dt><dd>Switch tab</dd><dt><kbd>⏎</kbd></dt><dd>Go to active search result</dd><dt><kbd>+</kbd></dt><dd>Expand all sections</dd><dt><kbd>-</kbd></dt><dd>Collapse all sections</dd></dl></div><div class="infos"><h2>Search Tricks</h2><p>Prefix searches with a type followed by a colon (e.g. <code>fn:</code>) to restrict the search to a given type.</p><p>Accepted types are: <code>fn</code>, <code>mod</code>, <code>struct</code>, <code>enum</code>, <code>trait</code>, <code>type</code>, <code>macro</code>, and <code>const</code>.</p><p>Search functions by type signature (e.g. <code>vec -> usize</code> or <code>* -> vec</code>)</p><p>Search multiple things at once by splitting your query with comma (e.g. <code>str,u8</code> or <code>String,struct:Vec,test</code>)</p></div></div></aside><script>window.rootPath = "../../";window.currentCrate = "num_bigint";</script><script src="../../aliases.js"></script><script src="../../main.js"></script><script defer src="../../search-index.js"></script></body></html>
|