Skip to main content

FieldElement

Struct FieldElement 

Source
pub struct FieldElement(pub(super) MontyFieldElement<FieldParams, { FieldParams::LIMBS }>);
Expand description

Element in the finite field modulo p = 2^{384} − 2^{128} − 2^{96} + 2^{32} − 1.

§Trait impls

Much of the important functionality is provided by traits from the [ff] crate:

  • [Field] represents elements of finite fields and provides:
    • [Field::random] generate a random field element
    • double, square, and invert operations
    • Bounds for [Add], [Sub], [Mul], and [Neg] (and *Assign equivalents)
    • Bounds for [ConditionallySelectable] from the subtle crate
  • PrimeField represents elements of prime fields and provides:
    • from_repr/to_repr for converting field elements from/to big integers.
    • MULTIPLICATIVE_GENERATOR and ROOT_OF_UNITY constants.

Please see the documentation for the relevant traits for more information.

Tuple Fields§

§0: MontyFieldElement<FieldParams, { FieldParams::LIMBS }>

Implementations§

Source§

impl FieldElement

Source

pub const ZERO: Self

Zero element.

Source

pub const ONE: Self

Multiplicative identity.

Source

pub fn from_bytes( repr: &MontyFieldBytes<FieldParams, { FieldParams::LIMBS }>, ) -> CtOption<Self>

Create a FieldElement from a canonical byte representation using the field’s configured byte order.

Source

pub fn from_slice(slice: &[u8]) -> Option<Self>

Decode FieldElement from a byte slice using the field’s configured byte order.

Source

pub const fn from_hex_vartime(hex: &str) -> Self

Decode a FieldElement from hex-encoded bytes using the field’s configured byte order.

This is primarily intended for defining constants using hex literals.

§Panics
  • When hex is malformed
  • When input is the wrong length
  • If input overflows the modulus
Source

pub fn from_uint(uint: &U384) -> CtOption<Self>

Decode FieldElement from U384 converting it into Montgomery form:

w * R^2 * R^-1 mod p = wR mod p
Source

pub const fn from_u64(w: u64) -> Self

Convert a u64 into a FieldElement.

Source

pub fn to_bytes(self) -> MontyFieldBytes<FieldParams, { FieldParams::LIMBS }>

Returns the big-endian encoding of this FieldElement.

Source

pub fn is_odd(&self) -> Choice

Determine if this FieldElement is odd in the SEC1 sense: self mod 2 == 1.

§Returns

If odd, return Choice(1). Otherwise, return Choice(0).

Source

pub fn is_even(&self) -> Choice

Determine if this FieldElement is even in the SEC1 sense: self mod 2 == 0.

§Returns

If even, return Choice(1). Otherwise, return Choice(0).

Source

pub fn is_zero(&self) -> Choice

Determine if this FieldElement is zero.

§Returns

If zero, return Choice(1). Otherwise, return Choice(0).

Source

pub const fn pow_vartime<const RHS_LIMBS: usize>( &self, exp: &Uint<RHS_LIMBS>, ) -> Self

Returns self^exp, where exp is a little-endian integer exponent.

This operation is variable time with respect to the exponent exp.

If the exponent is fixed, this operation is constant time.

Source

pub const fn sqn_vartime(&self, n: usize) -> Self

Returns self^(2^n) mod p.

This operation is variable time with respect to the exponent n.

If the exponent is fixed, this operation is constant time.

Source§

impl FieldElement

Source

pub(crate) const fn from_uint_unchecked(w: U384) -> Self

Decode FieldElement from U384 converting it into Montgomery form.

Does not perform a check that the field element does not overflow the order.

Used incorrectly this can lead to invalid results!

Source

pub const fn to_canonical(self) -> U384

Translate FieldElement out of the Montgomery domain, returning a U384 in canonical form.

Source

pub const fn add(&self, rhs: &Self) -> Self

Add elements.

Source

pub const fn double(&self) -> Self

Double element (add it to itself).

Source

pub const fn sub(&self, rhs: &Self) -> Self

Subtract elements.

Source

pub const fn multiply(&self, rhs: &Self) -> Self

Multiply elements.

Source

pub const fn neg(&self) -> Self

Negate element.

Source

pub const fn square(&self) -> Self

Compute modular square.

Source

pub fn invert(&self) -> CtOption<Self>

Compute FieldElement inversion: 1 / self.

Source

pub fn invert_vartime(&self) -> CtOption<Self>

Compute FieldElement inversion: 1 / self in variable-time.

Source

pub const fn const_invert(&self) -> Self

Compute field inversion as a const fn. Panics if self is zero.

This is mainly intended for inverting constants at compile time.

Trait Implementations§

Source§

impl Add<&FieldElement> for &FieldElement

Source§

type Output = FieldElement

The resulting type after applying the + operator.
Source§

fn add(self, rhs: &FieldElement) -> FieldElement

Performs the + operation. Read more
Source§

impl Add<&FieldElement> for FieldElement

Source§

type Output = FieldElement

The resulting type after applying the + operator.
Source§

fn add(self, rhs: &FieldElement) -> FieldElement

Performs the + operation. Read more
Source§

impl Add for FieldElement

Source§

type Output = FieldElement

The resulting type after applying the + operator.
Source§

fn add(self, rhs: FieldElement) -> FieldElement

Performs the + operation. Read more
Source§

impl AddAssign<&FieldElement> for FieldElement

Source§

fn add_assign(&mut self, other: &FieldElement)

Performs the += operation. Read more
Source§

impl AddAssign for FieldElement

Source§

fn add_assign(&mut self, other: FieldElement)

Performs the += operation. Read more
Source§

impl BatchInvert for FieldElement

Source§

fn batch_invert_in_place( elements: &mut [Self], scratch_space: &mut [Self], ) -> Self

Inverts each field element in elements (when non-zero). Zero-valued elements are left as zero. Read more
Source§

fn batch_invert_in_place_vartime( elements: &mut [Self], scratch_space: &mut [Self], ) -> Self

Variable-time batch inversion. Read more
Source§

impl Clone for FieldElement

Source§

fn clone(&self) -> FieldElement

Returns a duplicate of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl ConditionallySelectable for FieldElement

Source§

fn conditional_select(a: &Self, b: &Self, choice: Choice) -> Self

Select a or b according to choice. Read more
Source§

fn conditional_assign(&mut self, other: &Self, choice: Choice)

Conditionally assign other to self, according to choice. Read more
Source§

fn conditional_swap(a: &mut Self, b: &mut Self, choice: Choice)

Conditionally swap self and other if choice == 1; otherwise, reassign both unto themselves. Read more
Source§

impl ConstMontyParams<{ <$params>::LIMBS }> for FieldElement

Source§

const LIMBS: usize = FieldParams::LIMBS

Number of limbs required to encode the Montgomery form
Source§

const PARAMS: FixedMontyParams<{ U384::LIMBS }> = FieldParams::PARAMS

Montgomery parameters constant.
Source§

impl ConstantTimeEq for FieldElement

Source§

fn ct_eq(&self, other: &Self) -> Choice

Determine if two items are equal. Read more
Source§

fn ct_ne(&self, other: &Self) -> Choice

Determine if two items are NOT equal. Read more
Source§

impl ConstantTimeGreater for FieldElement

Source§

fn ct_gt(&self, other: &Self) -> Choice

Determine whether self > other. Read more
Source§

impl ConstantTimeLess for FieldElement

Source§

fn ct_lt(&self, other: &Self) -> Choice

Determine whether self < other. Read more
Source§

impl CtEq for FieldElement

Source§

fn ct_eq(&self, other: &Self) -> Choice

Determine if self is equal to other in constant-time.
Source§

fn ct_ne(&self, other: &Rhs) -> Choice

Determine if self is NOT equal to other in constant-time.
Source§

impl CtGt for FieldElement

Source§

fn ct_gt(&self, other: &Self) -> Choice

Compute whether self > other in constant time.
Source§

impl CtLt for FieldElement

Source§

fn ct_lt(&self, other: &Self) -> Choice

Compute whether self < other in constant time.
Source§

impl CtSelect for FieldElement

Source§

fn ct_select(&self, other: &Self, choice: Choice) -> Self

Select between self and other based on choice, returning a copy of the value. Read more
Source§

fn ct_swap(&mut self, other: &mut Self, choice: Choice)

Conditionally swap self and other if choice is Choice::TRUE.
Source§

impl Debug for FieldElement

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for FieldElement

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl Field for FieldElement

Source§

const ZERO: Self = Self::ZERO

The zero element of the field, the additive identity.
Source§

const ONE: Self = Self::ONE

The one element of the field, the multiplicative identity.
Source§

fn try_random<R: TryRng + ?Sized>(rng: &mut R) -> Result<Self, R::Error>

Returns an element chosen uniformly at random using a user-provided fallible RNG. Read more
Source§

fn is_zero(&self) -> Choice

Returns true iff this element is zero.
Source§

fn square(&self) -> Self

Squares this element.
Source§

fn double(&self) -> Self

Doubles this element.
Source§

fn invert(&self) -> CtOption<Self>

Computes the multiplicative inverse of this element, failing if the element is zero.
Source§

fn sqrt(&self) -> CtOption<Self>

Returns the square root of the field element, if it is quadratic residue. Read more
Source§

fn sqrt_ratio(num: &Self, div: &Self) -> (Choice, Self)

Computes: Read more
Source§

fn random<R>(rng: &mut R) -> Self
where R: Rng + ?Sized,

Returns an element chosen uniformly at random using a user-provided infallible RNG. Read more
Source§

fn is_zero_vartime(&self) -> bool

Returns true iff this element is zero. Read more
Source§

fn cube(&self) -> Self

Cubes this element.
Source§

fn sqrt_alt(&self) -> (Choice, Self)

Equivalent to Self::sqrt_ratio(self, one()). Read more
Source§

fn pow<S>(&self, exp: S) -> Self
where S: AsRef<[u64]>,

Exponentiates self by exp, where exp is a little-endian order integer exponent. Read more
Source§

fn pow_vartime<S>(&self, exp: S) -> Self
where S: AsRef<[u64]>,

Exponentiates self by exp, where exp is a little-endian order integer exponent. Read more
Source§

impl From<&FieldElement> for MontyFieldBytes<FieldParams, { FieldParams::LIMBS }>

Source§

fn from(fe: &FieldElement) -> Self

Converts to this type from the input type.
Source§

impl From<&FieldElement> for U384

Source§

fn from(fe: &FieldElement) -> U384

Converts to this type from the input type.
Source§

impl From<FieldElement> for MontyFieldBytes<FieldParams, { FieldParams::LIMBS }>

Source§

fn from(fe: FieldElement) -> Self

Converts to this type from the input type.
Source§

impl From<FieldElement> for MontyFieldElement<FieldParams, { FieldParams::LIMBS }>

Source§

fn from( fe: FieldElement, ) -> MontyFieldElement<FieldParams, { FieldParams::LIMBS }>

Converts to this type from the input type.
Source§

impl From<FieldElement> for U384

Source§

fn from(fe: FieldElement) -> U384

Converts to this type from the input type.
Source§

impl From<MontyFieldElement<FieldParams, { <$params>::LIMBS }>> for FieldElement

Source§

fn from( fe: MontyFieldElement<FieldParams, { FieldParams::LIMBS }>, ) -> FieldElement

Converts to this type from the input type.
Source§

impl From<u128> for FieldElement

Source§

fn from(n: u128) -> FieldElement

Converts to this type from the input type.
Source§

impl From<u32> for FieldElement

Source§

fn from(n: u32) -> FieldElement

Converts to this type from the input type.
Source§

impl From<u64> for FieldElement

Source§

fn from(n: u64) -> FieldElement

Converts to this type from the input type.
Source§

impl Generate for FieldElement

Source§

fn try_generate_from_rng<R: TryCryptoRng + ?Sized>( rng: &mut R, ) -> Result<Self, R::Error>

Generate random key using the provided TryCryptoRng. Read more
Source§

fn generate_from_rng<R>(rng: &mut R) -> Self
where R: CryptoRng + ?Sized,

Generate random key using the provided CryptoRng.
Source§

fn try_generate() -> Result<Self, Error>

Randomly generate a value of this type using the system’s ambient cryptographically secure random number generator. Read more
Source§

fn generate() -> Self

Randomly generate a value of this type using the system’s ambient cryptographically secure random number generator. Read more
Source§

impl Invert for FieldElement

Source§

type Output = CtOption<FieldElement>

Output of the inversion.
Source§

fn invert(&self) -> CtOption<Self>

Computes the inverse.
Source§

fn invert_vartime(&self) -> CtOption<Self>

Computes the inverse in variable-time.
Source§

impl Mul<&FieldElement> for &FieldElement

Source§

type Output = FieldElement

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: &FieldElement) -> FieldElement

Performs the * operation. Read more
Source§

impl Mul<&FieldElement> for FieldElement

Source§

type Output = FieldElement

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: &FieldElement) -> FieldElement

Performs the * operation. Read more
Source§

impl Mul for FieldElement

Source§

type Output = FieldElement

The resulting type after applying the * operator.
Source§

fn mul(self, rhs: FieldElement) -> FieldElement

Performs the * operation. Read more
Source§

impl MulAssign<&FieldElement> for FieldElement

Source§

fn mul_assign(&mut self, other: &FieldElement)

Performs the *= operation. Read more
Source§

impl MulAssign for FieldElement

Source§

fn mul_assign(&mut self, other: FieldElement)

Performs the *= operation. Read more
Source§

impl Neg for &FieldElement

Source§

type Output = FieldElement

The resulting type after applying the - operator.
Source§

fn neg(self) -> FieldElement

Performs the unary - operation. Read more
Source§

impl Neg for FieldElement

Source§

type Output = FieldElement

The resulting type after applying the - operator.
Source§

fn neg(self) -> FieldElement

Performs the unary - operation. Read more
Source§

impl Ord for FieldElement

Source§

fn cmp(&self, other: &FieldElement) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

impl PartialEq for FieldElement

Source§

fn eq(&self, rhs: &Self) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl PartialOrd for FieldElement

Source§

fn partial_cmp(&self, other: &FieldElement) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl PrimeField for FieldElement

Source§

const MODULUS: &'static str

Modulus of the field written as a string for debugging purposes. Read more
Source§

const NUM_BITS: u32 = ::primefield::MontyFieldElement<FieldParams, { FieldParams::LIMBS }>::NUM_BITS

How many bits are needed to represent an element of this field.
Source§

const CAPACITY: u32 = ::primefield::MontyFieldElement<FieldParams, { FieldParams::LIMBS }>::CAPACITY

How many bits of information can be reliably stored in the field element. Read more
Source§

const TWO_INV: Self

Inverse of $2$ in the field.
Source§

const MULTIPLICATIVE_GENERATOR: Self

A fixed multiplicative generator of modulus - 1 order. This element must also be a quadratic nonresidue. Read more
Source§

const S: u32 = ::primefield::MontyFieldElement<FieldParams, { FieldParams::LIMBS }>::S

An integer s satisfying the equation 2^s * t = modulus - 1 with t odd. Read more
Source§

const ROOT_OF_UNITY: Self

The 2^s root of unity. Read more
Source§

const ROOT_OF_UNITY_INV: Self

Source§

const DELTA: Self

Generator of the t-order multiplicative subgroup. Read more
Source§

type Repr = Array<u8, <FieldParams as MontyFieldParams<{ <$params>::LIMBS }>>::ByteSize>

The prime field can be converted back and forth into this binary representation.
Source§

fn from_repr(bytes: Self::Repr) -> CtOption<Self>

Attempts to convert a byte representation of a field element into an element of this prime field, failing if the input is not canonical (is not smaller than the field’s modulus). Read more
Source§

fn to_repr(&self) -> Self::Repr

Converts an element of the prime field into the standard byte representation for this field. Read more
Source§

fn is_odd(&self) -> Choice

Returns true iff this element is odd.
Source§

fn from_str_vartime(s: &str) -> Option<Self>

Interpret a string of numbers as a (congruent) prime field element. Does not accept unnecessary leading zeroes or a blank string. Read more
Source§

fn from_u128(v: u128) -> Self

Obtains a field element congruent to the integer v. Read more
Source§

fn from_repr_vartime(repr: Self::Repr) -> Option<Self>

Attempts to convert a byte representation of a field element into an element of this prime field, failing if the input is not canonical (is not smaller than the field’s modulus). Read more
Source§

fn is_even(&self) -> Choice

Returns true iff this element is even.
Source§

impl PrimeFieldExt for FieldElement

Source§

const REPR_ENDIANNESS: ByteOrder

Endianness used when encoding ff::PrimeField::Repr.
Source§

fn to_be_repr(&self) -> Self::Repr

Encode self using a big endian representation.
Source§

fn to_le_repr(&self) -> Self::Repr

Encode self using a little endian representation.
Source§

impl<'a> Product<&'a FieldElement> for FieldElement

Source§

fn product<I: Iterator<Item = &'a Self>>(iter: I) -> Self

Takes an iterator and generates Self from the elements by multiplying the items.
Source§

impl Product for FieldElement

Source§

fn product<I: Iterator<Item = Self>>(iter: I) -> Self

Takes an iterator and generates Self from the elements by multiplying the items.
Source§

impl Retrieve for FieldElement

Source§

type Output = Uint<crypto_bigint::::uint::U384::{constant#0}>

The original type.
Source§

fn retrieve(&self) -> U384

Convert the number back from the optimized representation.
Source§

impl Sub<&FieldElement> for &FieldElement

Source§

type Output = FieldElement

The resulting type after applying the - operator.
Source§

fn sub(self, rhs: &FieldElement) -> FieldElement

Performs the - operation. Read more
Source§

impl Sub<&FieldElement> for FieldElement

Source§

type Output = FieldElement

The resulting type after applying the - operator.
Source§

fn sub(self, rhs: &FieldElement) -> FieldElement

Performs the - operation. Read more
Source§

impl Sub for FieldElement

Source§

type Output = FieldElement

The resulting type after applying the - operator.
Source§

fn sub(self, rhs: FieldElement) -> FieldElement

Performs the - operation. Read more
Source§

impl SubAssign<&FieldElement> for FieldElement

Source§

fn sub_assign(&mut self, other: &FieldElement)

Performs the -= operation. Read more
Source§

impl SubAssign for FieldElement

Source§

fn sub_assign(&mut self, other: FieldElement)

Performs the -= operation. Read more
Source§

impl<'a> Sum<&'a FieldElement> for FieldElement

Source§

fn sum<I: Iterator<Item = &'a FieldElement>>(iter: I) -> Self

Takes an iterator and generates Self from the elements by “summing up” the items.
Source§

impl Sum for FieldElement

Source§

fn sum<I: Iterator<Item = Self>>(iter: I) -> Self

Takes an iterator and generates Self from the elements by “summing up” the items.
Source§

impl TryFrom<&Uint<crypto_bigint::::uint::U384::{constant#0}>> for FieldElement

Source§

type Error = Error

The type returned in the event of a conversion error.
Source§

fn try_from(w: &U384) -> Result<Self>

Performs the conversion.
Source§

impl TryFrom<Uint<crypto_bigint::::uint::U384::{constant#0}>> for FieldElement

Source§

type Error = Error

The type returned in the event of a conversion error.
Source§

fn try_from(w: U384) -> Result<Self>

Performs the conversion.
Source§

impl Copy for FieldElement

Source§

impl DefaultIsZeroes for FieldElement

Source§

impl Eq for FieldElement

Source§

impl FieldExt for FieldElement

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> ConditionallyNegatable for T
where T: ConditionallySelectable, &'a T: for<'a> Neg<Output = T>,

Source§

fn conditional_negate(&mut self, choice: Choice)

Negate self if choice == Choice(1); otherwise, leave it unchanged. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<Z> Zeroize for Z
where Z: DefaultIsZeroes,

Source§

fn zeroize(&mut self)

Zero out this object from memory using Rust intrinsics which ensure the zeroization operation is not “optimized away” by the compiler.
Source§

impl<T, Rhs, Output> GroupOps<Rhs, Output> for T
where T: Add<Rhs, Output = Output> + Sub<Rhs, Output = Output> + AddAssign<Rhs> + SubAssign<Rhs>,

Source§

impl<T, Rhs, Output> GroupOpsOwned<Rhs, Output> for T
where T: for<'r> GroupOps<&'r Rhs, Output>,

Source§

impl<T, Rhs, Output> ScalarMul<Rhs, Output> for T
where T: Mul<Rhs, Output = Output> + MulAssign<Rhs>,

Source§

impl<T, Rhs, Output> ScalarMulOwned<Rhs, Output> for T
where T: for<'r> ScalarMul<&'r Rhs, Output>,