ScMulAdd computes xa+yB, where B is the ed25519 base point, and places the result in z, returning that.
(a *Point, x, y *Scalar)
| 54 | // ScMulAdd computes xa+yB, where B is the ed25519 base point, and |
| 55 | // places the result in z, returning that. |
| 56 | func (z *Point) ScMulAdd(a *Point, x, y *Scalar) *Point { |
| 57 | // TODO: replace with constant-time implementation to avoid |
| 58 | // sidechannel attacks |
| 59 | |
| 60 | var p edwards25519.ProjectiveGroupElement |
| 61 | edwards25519.GeDoubleScalarMultVartime(&p, (*[32]byte)(x), (*edwards25519.ExtendedGroupElement)(a), (*[32]byte)(y)) |
| 62 | |
| 63 | var buf [32]byte |
| 64 | p.ToBytes(&buf) |
| 65 | // TODO(bobg): double-check that it's OK to ignore the return value |
| 66 | // from ExtendedGroupElement.FromBytes here. (It's a bool indicating |
| 67 | // that its input represented a legal value.) |
| 68 | (*edwards25519.ExtendedGroupElement)(z).FromBytes(&buf) |
| 69 | return z |
| 70 | } |
| 71 | |
| 72 | // ScMulCofactor computes 8*p, where p is the ed25519 point and 8 is a cofactor, |
| 73 | // and places the result in z, returning that. |
no test coverage detected