pub struct Scalar(pub(crate) U256);Expand description
Scalars are elements in the finite field modulo n.
§Trait impls
Much of the important functionality of scalars is provided by traits from
the ff crate, which is re-exported as
p256::elliptic_curve::ff:
Field- represents elements of finite fields and provides:Field::random- generate a random scalardouble,square, andinvertoperations- Bounds for 
Add,Sub,Mul, andNeg(as well as*Assignequivalents) - Bounds for 
ConditionallySelectablefrom thesubtlecrate 
PrimeField- represents elements of prime fields and provides:from_repr/to_reprfor converting field elements from/to big integers.multiplicative_generatorandroot_of_unityconstants.
PrimeFieldBits- operations over field elements represented as bits (requiresbitsfeature)
Please see the documentation for the relevant traits for more information.
§serde support
When the serde feature of this crate is enabled, the Serialize and
Deserialize traits are impl’d for this type.
The serialization is a fixed-width big endian encoding. When used with textual formats, the binary data is encoded as hexadecimal.
Tuple Fields§
§0: U256Implementations§
Source§impl Scalar
 
impl Scalar
Sourcepub fn to_bytes(&self) -> FieldBytes
 
pub fn to_bytes(&self) -> FieldBytes
Returns the SEC1 encoding of this scalar.
Sourcepub const fn shr_vartime(&self, shift: usize) -> Scalar
 
pub const fn shr_vartime(&self, shift: usize) -> Scalar
Right shifts the scalar.
Note: not constant-time with respect to the shift parameter.
Sourcepub fn invert(&self) -> CtOption<Self>
 
pub fn invert(&self) -> CtOption<Self>
Returns the multiplicative inverse of self, if self is non-zero
Sourceconst fn invert_unchecked(&self) -> Self
 
const fn invert_unchecked(&self) -> Self
Returns the multiplicative inverse of self.
Does not check that self is non-zero.
Sourcepub const fn pow_vartime(&self, exp: &[u64]) -> Self
 
pub const fn pow_vartime(&self, exp: &[u64]) -> Self
Exponentiates self by exp, where exp is a little-endian order integer
exponent.
Trait Implementations§
Source§impl AddAssign<&Scalar> for Scalar
 
impl AddAssign<&Scalar> for Scalar
Source§fn add_assign(&mut self, rhs: &Scalar)
 
fn add_assign(&mut self, rhs: &Scalar)
+= operation. Read moreSource§impl AddAssign for Scalar
 
impl AddAssign for Scalar
Source§fn add_assign(&mut self, rhs: Scalar)
 
fn add_assign(&mut self, rhs: Scalar)
+= operation. Read moreSource§impl ConditionallySelectable for Scalar
 
impl ConditionallySelectable for Scalar
Source§fn conditional_select(a: &Self, b: &Self, choice: Choice) -> Self
 
fn conditional_select(a: &Self, b: &Self, choice: Choice) -> Self
Source§fn conditional_assign(&mut self, other: &Self, choice: Choice)
 
fn conditional_assign(&mut self, other: &Self, choice: Choice)
Source§fn conditional_swap(a: &mut Self, b: &mut Self, choice: Choice)
 
fn conditional_swap(a: &mut Self, b: &mut Self, choice: Choice)
self and other if choice == 1; otherwise,
reassign both unto themselves. Read moreSource§impl ConstantTimeEq for Scalar
 
impl ConstantTimeEq for Scalar
Source§impl Field for Scalar
 
impl Field for Scalar
Source§fn sqrt(&self) -> CtOption<Self>
 
fn sqrt(&self) -> CtOption<Self>
Tonelli-Shank’s algorithm for q mod 16 = 1 https://eprint.iacr.org/2012/685.pdf (page 12, algorithm 5)
Source§fn random(rng: impl RngCore) -> Self
 
fn random(rng: impl RngCore) -> Self
Source§fn invert(&self) -> CtOption<Self>
 
fn invert(&self) -> CtOption<Self>
Source§fn sqrt_ratio(num: &Self, div: &Self) -> (Choice, Self)
 
fn sqrt_ratio(num: &Self, div: &Self) -> (Choice, Self)
Source§fn is_zero_vartime(&self) -> bool
 
fn is_zero_vartime(&self) -> bool
Source§impl From<&Scalar> for FieldBytes
 
impl From<&Scalar> for FieldBytes
Source§impl From<Scalar> for FieldBytes
 
impl From<Scalar> for FieldBytes
Source§impl FromUintUnchecked for Scalar
 
impl FromUintUnchecked for Scalar
Source§impl Invert for Scalar
 
impl Invert for Scalar
Source§fn invert_vartime(&self) -> CtOption<Self>
 
fn invert_vartime(&self) -> CtOption<Self>
Fast variable-time inversion using Stein’s algorithm.
Returns none if the scalar is zero.
https://link.springer.com/article/10.1007/s13389-016-0135-4
⚠️ WARNING!
This method should not be used with (unblinded) secret scalars, as its variable-time operation can potentially leak secrets through sidechannels.
Source§impl MulAssign<&Scalar> for Scalar
 
impl MulAssign<&Scalar> for Scalar
Source§fn mul_assign(&mut self, rhs: &Scalar)
 
fn mul_assign(&mut self, rhs: &Scalar)
*= operation. Read moreSource§impl MulAssign for Scalar
 
impl MulAssign for Scalar
Source§fn mul_assign(&mut self, rhs: Scalar)
 
fn mul_assign(&mut self, rhs: Scalar)
*= operation. Read moreSource§impl Ord for Scalar
 
impl Ord for Scalar
Source§impl PartialOrd for Scalar
 
impl PartialOrd for Scalar
Source§impl PrimeField for Scalar
 
impl PrimeField for Scalar
Source§fn from_repr(bytes: FieldBytes) -> CtOption<Self>
 
fn from_repr(bytes: FieldBytes) -> CtOption<Self>
Attempts to parse the given byte array as an SEC1-encoded scalar.
Returns None if the byte array does not contain a big-endian integer in the range [0, p).
Source§const MODULUS: &'static str = ORDER_HEX
 
const MODULUS: &'static str = ORDER_HEX
Source§const CAPACITY: u32 = 255u32
 
const CAPACITY: u32 = 255u32
Source§const MULTIPLICATIVE_GENERATOR: Self
 
const MULTIPLICATIVE_GENERATOR: Self
modulus - 1 order. This element must also be
a quadratic nonresidue. Read moreSource§const ROOT_OF_UNITY: Self
 
const ROOT_OF_UNITY: Self
2^s root of unity. Read moreSource§const ROOT_OF_UNITY_INV: Self
 
const ROOT_OF_UNITY_INV: Self
Self::ROOT_OF_UNITY.Source§type Repr = GenericArray<u8, <NistP256 as Curve>::FieldBytesSize>
 
type Repr = GenericArray<u8, <NistP256 as Curve>::FieldBytesSize>
Source§fn to_repr(&self) -> FieldBytes
 
fn to_repr(&self) -> FieldBytes
Source§fn from_str_vartime(s: &str) -> Option<Self>
 
fn from_str_vartime(s: &str) -> Option<Self>
Source§impl Reduce<Uint<crypto_bigint::::uint::U256::{constant#0}>> for Scalar
 
impl Reduce<Uint<crypto_bigint::::uint::U256::{constant#0}>> for Scalar
Source§type Bytes = GenericArray<u8, <NistP256 as Curve>::FieldBytesSize>
 
type Bytes = GenericArray<u8, <NistP256 as Curve>::FieldBytesSize>
Reduce::reduce_bytes.Source§fn reduce_bytes(bytes: &FieldBytes) -> Self
 
fn reduce_bytes(bytes: &FieldBytes) -> Self
Source§impl ReduceNonZero<Uint<crypto_bigint::::uint::U256::{constant#0}>> for Scalar
 
impl ReduceNonZero<Uint<crypto_bigint::::uint::U256::{constant#0}>> for Scalar
Source§fn reduce_nonzero(w: U256) -> Self
 
fn reduce_nonzero(w: U256) -> Self
Source§fn reduce_nonzero_bytes(bytes: &FieldBytes) -> Self
 
fn reduce_nonzero_bytes(bytes: &FieldBytes) -> Self
Source§impl ShrAssign<usize> for Scalar
 
impl ShrAssign<usize> for Scalar
Source§fn shr_assign(&mut self, rhs: usize)
 
fn shr_assign(&mut self, rhs: usize)
>>= operation. Read moreSource§impl SignPrimitive<NistP256> for Scalar
 
impl SignPrimitive<NistP256> for Scalar
Source§fn try_sign_prehashed<K>(
    &self,
    k: K,
    z: &GenericArray<u8, <C as Curve>::FieldBytesSize>,
) -> Result<(Signature<C>, Option<RecoveryId>), Error>
 
fn try_sign_prehashed<K>( &self, k: K, z: &GenericArray<u8, <C as Curve>::FieldBytesSize>, ) -> Result<(Signature<C>, Option<RecoveryId>), Error>
Source§fn try_sign_prehashed_rfc6979<D>(
    &self,
    z: &GenericArray<u8, <C as Curve>::FieldBytesSize>,
    ad: &[u8],
) -> Result<(Signature<C>, Option<RecoveryId>), Error>where
    Self: From<ScalarPrimitive<C>> + Invert<Output = CtOption<Self>>,
    D: Digest<OutputSize = <C as Curve>::FieldBytesSize> + BlockSizeUser + FixedOutput + FixedOutputReset,
 
fn try_sign_prehashed_rfc6979<D>(
    &self,
    z: &GenericArray<u8, <C as Curve>::FieldBytesSize>,
    ad: &[u8],
) -> Result<(Signature<C>, Option<RecoveryId>), Error>where
    Self: From<ScalarPrimitive<C>> + Invert<Output = CtOption<Self>>,
    D: Digest<OutputSize = <C as Curve>::FieldBytesSize> + BlockSizeUser + FixedOutput + FixedOutputReset,
Source§impl SubAssign<&Scalar> for Scalar
 
impl SubAssign<&Scalar> for Scalar
Source§fn sub_assign(&mut self, rhs: &Scalar)
 
fn sub_assign(&mut self, rhs: &Scalar)
-= operation. Read moreSource§impl SubAssign for Scalar
 
impl SubAssign for Scalar
Source§fn sub_assign(&mut self, rhs: Scalar)
 
fn sub_assign(&mut self, rhs: Scalar)
-= operation. Read more