fp_test.go 30 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411
  1. package bls12381
  2. import (
  3. "bytes"
  4. "crypto/rand"
  5. "math/big"
  6. "testing"
  7. )
  8. func TestFpSerialization(t *testing.T) {
  9. t.Run("zero", func(t *testing.T) {
  10. in := make([]byte, 48)
  11. fe, err := fromBytes(in)
  12. if err != nil {
  13. t.Fatal(err)
  14. }
  15. if !fe.isZero() {
  16. t.Fatal("bad serialization")
  17. }
  18. if !bytes.Equal(in, toBytes(fe)) {
  19. t.Fatal("bad serialization")
  20. }
  21. })
  22. t.Run("bytes", func(t *testing.T) {
  23. for i := 0; i < fuz; i++ {
  24. a, _ := new(fe).rand(rand.Reader)
  25. b, err := fromBytes(toBytes(a))
  26. if err != nil {
  27. t.Fatal(err)
  28. }
  29. if !a.equal(b) {
  30. t.Fatal("bad serialization")
  31. }
  32. }
  33. })
  34. t.Run("string", func(t *testing.T) {
  35. for i := 0; i < fuz; i++ {
  36. a, _ := new(fe).rand(rand.Reader)
  37. b, err := fromString(toString(a))
  38. if err != nil {
  39. t.Fatal(err)
  40. }
  41. if !a.equal(b) {
  42. t.Fatal("bad encoding or decoding")
  43. }
  44. }
  45. })
  46. t.Run("big", func(t *testing.T) {
  47. for i := 0; i < fuz; i++ {
  48. a, _ := new(fe).rand(rand.Reader)
  49. b, err := fromBig(toBig(a))
  50. if err != nil {
  51. t.Fatal(err)
  52. }
  53. if !a.equal(b) {
  54. t.Fatal("bad encoding or decoding")
  55. }
  56. }
  57. })
  58. }
  59. func TestFpAdditionCrossAgainstBigInt(t *testing.T) {
  60. for i := 0; i < fuz; i++ {
  61. a, _ := new(fe).rand(rand.Reader)
  62. b, _ := new(fe).rand(rand.Reader)
  63. c := new(fe)
  64. big_a := toBig(a)
  65. big_b := toBig(b)
  66. big_c := new(big.Int)
  67. add(c, a, b)
  68. out_1 := toBytes(c)
  69. out_2 := padBytes(big_c.Add(big_a, big_b).Mod(big_c, modulus.big()).Bytes(), 48)
  70. if !bytes.Equal(out_1, out_2) {
  71. t.Fatal("cross test against big.Int is not satisfied A")
  72. }
  73. double(c, a)
  74. out_1 = toBytes(c)
  75. out_2 = padBytes(big_c.Add(big_a, big_a).Mod(big_c, modulus.big()).Bytes(), 48)
  76. if !bytes.Equal(out_1, out_2) {
  77. t.Fatal("cross test against big.Int is not satisfied B")
  78. }
  79. sub(c, a, b)
  80. out_1 = toBytes(c)
  81. out_2 = padBytes(big_c.Sub(big_a, big_b).Mod(big_c, modulus.big()).Bytes(), 48)
  82. if !bytes.Equal(out_1, out_2) {
  83. t.Fatal("cross test against big.Int is not satisfied C")
  84. }
  85. neg(c, a)
  86. out_1 = toBytes(c)
  87. out_2 = padBytes(big_c.Neg(big_a).Mod(big_c, modulus.big()).Bytes(), 48)
  88. if !bytes.Equal(out_1, out_2) {
  89. t.Fatal("cross test against big.Int is not satisfied D")
  90. }
  91. }
  92. }
  93. func TestFpAdditionCrossAgainstBigIntAssigned(t *testing.T) {
  94. for i := 0; i < fuz; i++ {
  95. a, _ := new(fe).rand(rand.Reader)
  96. b, _ := new(fe).rand(rand.Reader)
  97. big_a, big_b := toBig(a), toBig(b)
  98. addAssign(a, b)
  99. out_1 := toBytes(a)
  100. out_2 := padBytes(big_a.Add(big_a, big_b).Mod(big_a, modulus.big()).Bytes(), 48)
  101. if !bytes.Equal(out_1, out_2) {
  102. t.Fatal("cross test against big.Int is not satisfied A")
  103. }
  104. a, _ = new(fe).rand(rand.Reader)
  105. big_a = toBig(a)
  106. doubleAssign(a)
  107. out_1 = toBytes(a)
  108. out_2 = padBytes(big_a.Add(big_a, big_a).Mod(big_a, modulus.big()).Bytes(), 48)
  109. if !bytes.Equal(out_1, out_2) {
  110. t.Fatal("cross test against big.Int is not satisfied B")
  111. }
  112. a, _ = new(fe).rand(rand.Reader)
  113. b, _ = new(fe).rand(rand.Reader)
  114. big_a, big_b = toBig(a), toBig(b)
  115. subAssign(a, b)
  116. out_1 = toBytes(a)
  117. out_2 = padBytes(big_a.Sub(big_a, big_b).Mod(big_a, modulus.big()).Bytes(), 48)
  118. if !bytes.Equal(out_1, out_2) {
  119. t.Fatal("cross test against big.Int is not satisfied A")
  120. }
  121. }
  122. }
  123. func TestFpAdditionProperties(t *testing.T) {
  124. for i := 0; i < fuz; i++ {
  125. zero := new(fe).zero()
  126. a, _ := new(fe).rand(rand.Reader)
  127. b, _ := new(fe).rand(rand.Reader)
  128. c_1, c_2 := new(fe), new(fe)
  129. add(c_1, a, zero)
  130. if !c_1.equal(a) {
  131. t.Fatal("a + 0 == a")
  132. }
  133. sub(c_1, a, zero)
  134. if !c_1.equal(a) {
  135. t.Fatal("a - 0 == a")
  136. }
  137. double(c_1, zero)
  138. if !c_1.equal(zero) {
  139. t.Fatal("2 * 0 == 0")
  140. }
  141. neg(c_1, zero)
  142. if !c_1.equal(zero) {
  143. t.Fatal("-0 == 0")
  144. }
  145. sub(c_1, zero, a)
  146. neg(c_2, a)
  147. if !c_1.equal(c_2) {
  148. t.Fatal("0-a == -a")
  149. }
  150. double(c_1, a)
  151. add(c_2, a, a)
  152. if !c_1.equal(c_2) {
  153. t.Fatal("2 * a == a + a")
  154. }
  155. add(c_1, a, b)
  156. add(c_2, b, a)
  157. if !c_1.equal(c_2) {
  158. t.Fatal("a + b = b + a")
  159. }
  160. sub(c_1, a, b)
  161. sub(c_2, b, a)
  162. neg(c_2, c_2)
  163. if !c_1.equal(c_2) {
  164. t.Fatal("a - b = - ( b - a )")
  165. }
  166. c_x, _ := new(fe).rand(rand.Reader)
  167. add(c_1, a, b)
  168. add(c_1, c_1, c_x)
  169. add(c_2, a, c_x)
  170. add(c_2, c_2, b)
  171. if !c_1.equal(c_2) {
  172. t.Fatal("(a + b) + c == (a + c ) + b")
  173. }
  174. sub(c_1, a, b)
  175. sub(c_1, c_1, c_x)
  176. sub(c_2, a, c_x)
  177. sub(c_2, c_2, b)
  178. if !c_1.equal(c_2) {
  179. t.Fatal("(a - b) - c == (a - c ) -b")
  180. }
  181. }
  182. }
  183. func TestFpAdditionPropertiesAssigned(t *testing.T) {
  184. for i := 0; i < fuz; i++ {
  185. zero := new(fe).zero()
  186. a, b := new(fe), new(fe)
  187. _, _ = a.rand(rand.Reader)
  188. b.set(a)
  189. addAssign(a, zero)
  190. if !a.equal(b) {
  191. t.Fatal("a + 0 == a")
  192. }
  193. subAssign(a, zero)
  194. if !a.equal(b) {
  195. t.Fatal("a - 0 == a")
  196. }
  197. a.set(zero)
  198. doubleAssign(a)
  199. if !a.equal(zero) {
  200. t.Fatal("2 * 0 == 0")
  201. }
  202. a.set(zero)
  203. subAssign(a, b)
  204. neg(b, b)
  205. if !a.equal(b) {
  206. t.Fatal("0-a == -a")
  207. }
  208. _, _ = a.rand(rand.Reader)
  209. b.set(a)
  210. doubleAssign(a)
  211. addAssign(b, b)
  212. if !a.equal(b) {
  213. t.Fatal("2 * a == a + a")
  214. }
  215. _, _ = a.rand(rand.Reader)
  216. _, _ = b.rand(rand.Reader)
  217. c_1, c_2 := new(fe).set(a), new(fe).set(b)
  218. addAssign(c_1, b)
  219. addAssign(c_2, a)
  220. if !c_1.equal(c_2) {
  221. t.Fatal("a + b = b + a")
  222. }
  223. _, _ = a.rand(rand.Reader)
  224. _, _ = b.rand(rand.Reader)
  225. c_1.set(a)
  226. c_2.set(b)
  227. subAssign(c_1, b)
  228. subAssign(c_2, a)
  229. neg(c_2, c_2)
  230. if !c_1.equal(c_2) {
  231. t.Fatal("a - b = - ( b - a )")
  232. }
  233. _, _ = a.rand(rand.Reader)
  234. _, _ = b.rand(rand.Reader)
  235. c, _ := new(fe).rand(rand.Reader)
  236. a0 := new(fe).set(a)
  237. addAssign(a, b)
  238. addAssign(a, c)
  239. addAssign(b, c)
  240. addAssign(b, a0)
  241. if !a.equal(b) {
  242. t.Fatal("(a + b) + c == (b + c) + a")
  243. }
  244. _, _ = a.rand(rand.Reader)
  245. _, _ = b.rand(rand.Reader)
  246. _, _ = c.rand(rand.Reader)
  247. a0.set(a)
  248. subAssign(a, b)
  249. subAssign(a, c)
  250. subAssign(a0, c)
  251. subAssign(a0, b)
  252. if !a.equal(a0) {
  253. t.Fatal("(a - b) - c == (a - c) -b")
  254. }
  255. }
  256. }
  257. func TestFpLazyOperations(t *testing.T) {
  258. for i := 0; i < fuz; i++ {
  259. a, _ := new(fe).rand(rand.Reader)
  260. b, _ := new(fe).rand(rand.Reader)
  261. c, _ := new(fe).rand(rand.Reader)
  262. c0 := new(fe)
  263. c1 := new(fe)
  264. ladd(c0, a, b)
  265. add(c1, a, b)
  266. mul(c0, c0, c)
  267. mul(c1, c1, c)
  268. if !c0.equal(c1) {
  269. // l+ operator stands for lazy addition
  270. t.Fatal("(a + b) * c == (a l+ b) * c")
  271. }
  272. _, _ = a.rand(rand.Reader)
  273. b.set(a)
  274. ldouble(a, a)
  275. ladd(b, b, b)
  276. if !a.equal(b) {
  277. t.Fatal("2 l* a = a l+ a")
  278. }
  279. _, _ = a.rand(rand.Reader)
  280. _, _ = b.rand(rand.Reader)
  281. _, _ = c.rand(rand.Reader)
  282. a0 := new(fe).set(a)
  283. lsubAssign(a, b)
  284. laddAssign(a, &modulus)
  285. mul(a, a, c)
  286. subAssign(a0, b)
  287. mul(a0, a0, c)
  288. if !a.equal(a0) {
  289. t.Fatal("((a l- b) + p) * c = (a-b) * c")
  290. }
  291. }
  292. }
  293. func TestFpMultiplicationCrossAgainstBigInt(t *testing.T) {
  294. for i := 0; i < fuz; i++ {
  295. a, _ := new(fe).rand(rand.Reader)
  296. b, _ := new(fe).rand(rand.Reader)
  297. c := new(fe)
  298. big_a := toBig(a)
  299. big_b := toBig(b)
  300. big_c := new(big.Int)
  301. mul(c, a, b)
  302. out_1 := toBytes(c)
  303. out_2 := padBytes(big_c.Mul(big_a, big_b).Mod(big_c, modulus.big()).Bytes(), 48)
  304. if !bytes.Equal(out_1, out_2) {
  305. t.Fatal("cross test against big.Int is not satisfied")
  306. }
  307. }
  308. }
  309. func TestFpMultiplicationProperties(t *testing.T) {
  310. for i := 0; i < fuz; i++ {
  311. a, _ := new(fe).rand(rand.Reader)
  312. b, _ := new(fe).rand(rand.Reader)
  313. zero, one := new(fe).zero(), new(fe).one()
  314. c_1, c_2 := new(fe), new(fe)
  315. mul(c_1, a, zero)
  316. if !c_1.equal(zero) {
  317. t.Fatal("a * 0 == 0")
  318. }
  319. mul(c_1, a, one)
  320. if !c_1.equal(a) {
  321. t.Fatal("a * 1 == a")
  322. }
  323. mul(c_1, a, b)
  324. mul(c_2, b, a)
  325. if !c_1.equal(c_2) {
  326. t.Fatal("a * b == b * a")
  327. }
  328. c_x, _ := new(fe).rand(rand.Reader)
  329. mul(c_1, a, b)
  330. mul(c_1, c_1, c_x)
  331. mul(c_2, c_x, b)
  332. mul(c_2, c_2, a)
  333. if !c_1.equal(c_2) {
  334. t.Fatal("(a * b) * c == (a * c) * b")
  335. }
  336. square(a, zero)
  337. if !a.equal(zero) {
  338. t.Fatal("0^2 == 0")
  339. }
  340. square(a, one)
  341. if !a.equal(one) {
  342. t.Fatal("1^2 == 1")
  343. }
  344. _, _ = a.rand(rand.Reader)
  345. square(c_1, a)
  346. mul(c_2, a, a)
  347. if !c_1.equal(c_1) {
  348. t.Fatal("a^2 == a*a")
  349. }
  350. }
  351. }
  352. func TestFpExponentiation(t *testing.T) {
  353. for i := 0; i < fuz; i++ {
  354. a, _ := new(fe).rand(rand.Reader)
  355. u := new(fe)
  356. exp(u, a, big.NewInt(0))
  357. if !u.isOne() {
  358. t.Fatal("a^0 == 1")
  359. }
  360. exp(u, a, big.NewInt(1))
  361. if !u.equal(a) {
  362. t.Fatal("a^1 == a")
  363. }
  364. v := new(fe)
  365. mul(u, a, a)
  366. mul(u, u, u)
  367. mul(u, u, u)
  368. exp(v, a, big.NewInt(8))
  369. if !u.equal(v) {
  370. t.Fatal("((a^2)^2)^2 == a^8")
  371. }
  372. p := modulus.big()
  373. exp(u, a, p)
  374. if !u.equal(a) {
  375. t.Fatal("a^p == a")
  376. }
  377. exp(u, a, p.Sub(p, big.NewInt(1)))
  378. if !u.isOne() {
  379. t.Fatal("a^(p-1) == 1")
  380. }
  381. }
  382. }
  383. func TestFpInversion(t *testing.T) {
  384. for i := 0; i < fuz; i++ {
  385. u := new(fe)
  386. zero, one := new(fe).zero(), new(fe).one()
  387. inverse(u, zero)
  388. if !u.equal(zero) {
  389. t.Fatal("(0^-1) == 0)")
  390. }
  391. inverse(u, one)
  392. if !u.equal(one) {
  393. t.Fatal("(1^-1) == 1)")
  394. }
  395. a, _ := new(fe).rand(rand.Reader)
  396. inverse(u, a)
  397. mul(u, u, a)
  398. if !u.equal(one) {
  399. t.Fatal("(r*a) * r*(a^-1) == r)")
  400. }
  401. v := new(fe)
  402. p := modulus.big()
  403. exp(u, a, p.Sub(p, big.NewInt(2)))
  404. inverse(v, a)
  405. if !v.equal(u) {
  406. t.Fatal("a^(p-2) == a^-1")
  407. }
  408. }
  409. }
  410. func TestFpSquareRoot(t *testing.T) {
  411. r := new(fe)
  412. if sqrt(r, nonResidue1) {
  413. t.Fatal("non residue cannot have a sqrt")
  414. }
  415. for i := 0; i < fuz; i++ {
  416. a, _ := new(fe).rand(rand.Reader)
  417. aa, rr, r := &fe{}, &fe{}, &fe{}
  418. square(aa, a)
  419. if !sqrt(r, aa) {
  420. t.Fatal("bad sqrt 1")
  421. }
  422. square(rr, r)
  423. if !rr.equal(aa) {
  424. t.Fatal("bad sqrt 2")
  425. }
  426. }
  427. }
  428. func TestFpNonResidue(t *testing.T) {
  429. if !isQuadraticNonResidue(nonResidue1) {
  430. t.Fatal("element is quadratic non residue, 1")
  431. }
  432. if isQuadraticNonResidue(new(fe).one()) {
  433. t.Fatal("one is not quadratic non residue")
  434. }
  435. if !isQuadraticNonResidue(new(fe).zero()) {
  436. t.Fatal("should accept zero as quadratic non residue")
  437. }
  438. for i := 0; i < fuz; i++ {
  439. a, _ := new(fe).rand(rand.Reader)
  440. square(a, a)
  441. if isQuadraticNonResidue(new(fe).one()) {
  442. t.Fatal("element is not quadratic non residue")
  443. }
  444. }
  445. for i := 0; i < fuz; i++ {
  446. a, _ := new(fe).rand(rand.Reader)
  447. if !sqrt(new(fe), a) {
  448. if !isQuadraticNonResidue(a) {
  449. t.Fatal("element is quadratic non residue, 2", i)
  450. }
  451. } else {
  452. i -= 1
  453. }
  454. }
  455. }
  456. func TestFp2Serialization(t *testing.T) {
  457. field := newFp2()
  458. for i := 0; i < fuz; i++ {
  459. a, _ := new(fe2).rand(rand.Reader)
  460. b, err := field.fromBytes(field.toBytes(a))
  461. if err != nil {
  462. t.Fatal(err)
  463. }
  464. if !a.equal(b) {
  465. t.Fatal("bad serialization")
  466. }
  467. }
  468. }
  469. func TestFp2AdditionProperties(t *testing.T) {
  470. field := newFp2()
  471. for i := 0; i < fuz; i++ {
  472. zero := field.zero()
  473. a, _ := new(fe2).rand(rand.Reader)
  474. b, _ := new(fe2).rand(rand.Reader)
  475. c_1 := field.new()
  476. c_2 := field.new()
  477. field.add(c_1, a, zero)
  478. if !c_1.equal(a) {
  479. t.Fatal("a + 0 == a")
  480. }
  481. field.sub(c_1, a, zero)
  482. if !c_1.equal(a) {
  483. t.Fatal("a - 0 == a")
  484. }
  485. field.double(c_1, zero)
  486. if !c_1.equal(zero) {
  487. t.Fatal("2 * 0 == 0")
  488. }
  489. field.neg(c_1, zero)
  490. if !c_1.equal(zero) {
  491. t.Fatal("-0 == 0")
  492. }
  493. field.sub(c_1, zero, a)
  494. field.neg(c_2, a)
  495. if !c_1.equal(c_2) {
  496. t.Fatal("0-a == -a")
  497. }
  498. field.double(c_1, a)
  499. field.add(c_2, a, a)
  500. if !c_1.equal(c_2) {
  501. t.Fatal("2 * a == a + a")
  502. }
  503. field.add(c_1, a, b)
  504. field.add(c_2, b, a)
  505. if !c_1.equal(c_2) {
  506. t.Fatal("a + b = b + a")
  507. }
  508. field.sub(c_1, a, b)
  509. field.sub(c_2, b, a)
  510. field.neg(c_2, c_2)
  511. if !c_1.equal(c_2) {
  512. t.Fatal("a - b = - ( b - a )")
  513. }
  514. c_x, _ := new(fe2).rand(rand.Reader)
  515. field.add(c_1, a, b)
  516. field.add(c_1, c_1, c_x)
  517. field.add(c_2, a, c_x)
  518. field.add(c_2, c_2, b)
  519. if !c_1.equal(c_2) {
  520. t.Fatal("(a + b) + c == (a + c ) + b")
  521. }
  522. field.sub(c_1, a, b)
  523. field.sub(c_1, c_1, c_x)
  524. field.sub(c_2, a, c_x)
  525. field.sub(c_2, c_2, b)
  526. if !c_1.equal(c_2) {
  527. t.Fatal("(a - b) - c == (a - c ) -b")
  528. }
  529. }
  530. }
  531. func TestFp2AdditionPropertiesAssigned(t *testing.T) {
  532. field := newFp2()
  533. for i := 0; i < fuz; i++ {
  534. zero := new(fe2).zero()
  535. a, b := new(fe2), new(fe2)
  536. _, _ = a.rand(rand.Reader)
  537. b.set(a)
  538. field.addAssign(a, zero)
  539. if !a.equal(b) {
  540. t.Fatal("a + 0 == a")
  541. }
  542. field.subAssign(a, zero)
  543. if !a.equal(b) {
  544. t.Fatal("a - 0 == a")
  545. }
  546. a.set(zero)
  547. field.doubleAssign(a)
  548. if !a.equal(zero) {
  549. t.Fatal("2 * 0 == 0")
  550. }
  551. a.set(zero)
  552. field.subAssign(a, b)
  553. field.neg(b, b)
  554. if !a.equal(b) {
  555. t.Fatal("0-a == -a")
  556. }
  557. _, _ = a.rand(rand.Reader)
  558. b.set(a)
  559. field.doubleAssign(a)
  560. field.addAssign(b, b)
  561. if !a.equal(b) {
  562. t.Fatal("2 * a == a + a")
  563. }
  564. _, _ = a.rand(rand.Reader)
  565. _, _ = b.rand(rand.Reader)
  566. c_1, c_2 := new(fe2).set(a), new(fe2).set(b)
  567. field.addAssign(c_1, b)
  568. field.addAssign(c_2, a)
  569. if !c_1.equal(c_2) {
  570. t.Fatal("a + b = b + a")
  571. }
  572. _, _ = a.rand(rand.Reader)
  573. _, _ = b.rand(rand.Reader)
  574. c_1.set(a)
  575. c_2.set(b)
  576. field.subAssign(c_1, b)
  577. field.subAssign(c_2, a)
  578. field.neg(c_2, c_2)
  579. if !c_1.equal(c_2) {
  580. t.Fatal("a - b = - ( b - a )")
  581. }
  582. _, _ = a.rand(rand.Reader)
  583. _, _ = b.rand(rand.Reader)
  584. c, _ := new(fe2).rand(rand.Reader)
  585. a0 := new(fe2).set(a)
  586. field.addAssign(a, b)
  587. field.addAssign(a, c)
  588. field.addAssign(b, c)
  589. field.addAssign(b, a0)
  590. if !a.equal(b) {
  591. t.Fatal("(a + b) + c == (b + c) + a")
  592. }
  593. _, _ = a.rand(rand.Reader)
  594. _, _ = b.rand(rand.Reader)
  595. _, _ = c.rand(rand.Reader)
  596. a0.set(a)
  597. field.subAssign(a, b)
  598. field.subAssign(a, c)
  599. field.subAssign(a0, c)
  600. field.subAssign(a0, b)
  601. if !a.equal(a0) {
  602. t.Fatal("(a - b) - c == (a - c) -b")
  603. }
  604. }
  605. }
  606. func TestFp2LazyOperations(t *testing.T) {
  607. field := newFp2()
  608. for i := 0; i < fuz; i++ {
  609. a, _ := new(fe2).rand(rand.Reader)
  610. b, _ := new(fe2).rand(rand.Reader)
  611. c, _ := new(fe2).rand(rand.Reader)
  612. c0 := new(fe2)
  613. c1 := new(fe2)
  614. field.ladd(c0, a, b)
  615. field.add(c1, a, b)
  616. field.mulAssign(c0, c)
  617. field.mulAssign(c1, c)
  618. if !c0.equal(c1) {
  619. // l+ operator stands for lazy addition
  620. t.Fatal("(a + b) * c == (a l+ b) * c")
  621. }
  622. _, _ = a.rand(rand.Reader)
  623. b.set(a)
  624. field.ldouble(a, a)
  625. field.ladd(b, b, b)
  626. if !a.equal(b) {
  627. t.Fatal("2 l* a = a l+ a")
  628. }
  629. }
  630. }
  631. func TestFp2MultiplicationProperties(t *testing.T) {
  632. field := newFp2()
  633. for i := 0; i < fuz; i++ {
  634. a, _ := new(fe2).rand(rand.Reader)
  635. b, _ := new(fe2).rand(rand.Reader)
  636. zero := field.zero()
  637. one := field.one()
  638. c_1, c_2 := field.new(), field.new()
  639. field.mul(c_1, a, zero)
  640. if !c_1.equal(zero) {
  641. t.Fatal("a * 0 == 0")
  642. }
  643. field.mul(c_1, a, one)
  644. if !c_1.equal(a) {
  645. t.Fatal("a * 1 == a")
  646. }
  647. field.mul(c_1, a, b)
  648. field.mul(c_2, b, a)
  649. if !c_1.equal(c_2) {
  650. t.Fatal("a * b == b * a")
  651. }
  652. c_x, _ := new(fe2).rand(rand.Reader)
  653. field.mul(c_1, a, b)
  654. field.mul(c_1, c_1, c_x)
  655. field.mul(c_2, c_x, b)
  656. field.mul(c_2, c_2, a)
  657. if !c_1.equal(c_2) {
  658. t.Fatal("(a * b) * c == (a * c) * b")
  659. }
  660. field.square(a, zero)
  661. if !a.equal(zero) {
  662. t.Fatal("0^2 == 0")
  663. }
  664. field.square(a, one)
  665. if !a.equal(one) {
  666. t.Fatal("1^2 == 1")
  667. }
  668. _, _ = a.rand(rand.Reader)
  669. field.square(c_1, a)
  670. field.mul(c_2, a, a)
  671. if !c_2.equal(c_1) {
  672. t.Fatal("a^2 == a*a")
  673. }
  674. }
  675. }
  676. func TestFp2MultiplicationPropertiesAssigned(t *testing.T) {
  677. field := newFp2()
  678. for i := 0; i < fuz; i++ {
  679. a, _ := new(fe2).rand(rand.Reader)
  680. zero, one := new(fe2).zero(), new(fe2).one()
  681. field.mulAssign(a, zero)
  682. if !a.equal(zero) {
  683. t.Fatal("a * 0 == 0")
  684. }
  685. _, _ = a.rand(rand.Reader)
  686. a0 := new(fe2).set(a)
  687. field.mulAssign(a, one)
  688. if !a.equal(a0) {
  689. t.Fatal("a * 1 == a")
  690. }
  691. _, _ = a.rand(rand.Reader)
  692. b, _ := new(fe2).rand(rand.Reader)
  693. a0.set(a)
  694. field.mulAssign(a, b)
  695. field.mulAssign(b, a0)
  696. if !a.equal(b) {
  697. t.Fatal("a * b == b * a")
  698. }
  699. c, _ := new(fe2).rand(rand.Reader)
  700. a0.set(a)
  701. field.mulAssign(a, b)
  702. field.mulAssign(a, c)
  703. field.mulAssign(a0, c)
  704. field.mulAssign(a0, b)
  705. if !a.equal(a0) {
  706. t.Fatal("(a * b) * c == (a * c) * b")
  707. }
  708. a0.set(a)
  709. field.squareAssign(a)
  710. field.mulAssign(a0, a0)
  711. if !a.equal(a0) {
  712. t.Fatal("a^2 == a*a")
  713. }
  714. }
  715. }
  716. func TestFp2Exponentiation(t *testing.T) {
  717. field := newFp2()
  718. for i := 0; i < fuz; i++ {
  719. a, _ := new(fe2).rand(rand.Reader)
  720. u := field.new()
  721. field.exp(u, a, big.NewInt(0))
  722. if !u.equal(field.one()) {
  723. t.Fatal("a^0 == 1")
  724. }
  725. field.exp(u, a, big.NewInt(1))
  726. if !u.equal(a) {
  727. t.Fatal("a^1 == a")
  728. }
  729. v := field.new()
  730. field.mul(u, a, a)
  731. field.mul(u, u, u)
  732. field.mul(u, u, u)
  733. field.exp(v, a, big.NewInt(8))
  734. if !u.equal(v) {
  735. t.Fatal("((a^2)^2)^2 == a^8")
  736. }
  737. }
  738. }
  739. func TestFp2Inversion(t *testing.T) {
  740. field := newFp2()
  741. u := field.new()
  742. zero := field.zero()
  743. one := field.one()
  744. field.inverse(u, zero)
  745. if !u.equal(zero) {
  746. t.Fatal("(0 ^ -1) == 0)")
  747. }
  748. field.inverse(u, one)
  749. if !u.equal(one) {
  750. t.Fatal("(1 ^ -1) == 1)")
  751. }
  752. for i := 0; i < fuz; i++ {
  753. a, _ := new(fe2).rand(rand.Reader)
  754. field.inverse(u, a)
  755. field.mul(u, u, a)
  756. if !u.equal(one) {
  757. t.Fatal("(r * a) * r * (a ^ -1) == r)")
  758. }
  759. }
  760. }
  761. func TestFp2SquareRoot(t *testing.T) {
  762. field := newFp2()
  763. for z := 0; z < 1000; z++ {
  764. zi := new(fe)
  765. sub(zi, &modulus, &fe{uint64(z * z)})
  766. // r = (-z*z, 0)
  767. r := &fe2{*zi, fe{0}}
  768. toMont(&r[0], &r[0])
  769. toMont(&r[1], &r[1])
  770. c := field.new()
  771. // sqrt((-z*z, 0)) = (0, z)
  772. if !field.sqrt(c, r) {
  773. t.Fatal("z*z does have a square root")
  774. }
  775. e := &fe2{fe{uint64(0)}, fe{uint64(z)}}
  776. toMont(&e[0], &e[0])
  777. toMont(&e[1], &e[1])
  778. field.square(e, e)
  779. field.square(c, c)
  780. if !e.equal(c) {
  781. t.Fatal("square root failed")
  782. }
  783. }
  784. if field.sqrt(field.new(), nonResidue2) {
  785. t.Fatal("non residue cannot have a sqrt")
  786. }
  787. for i := 0; i < fuz; i++ {
  788. a, _ := new(fe2).rand(rand.Reader)
  789. aa, rr, r := field.new(), field.new(), field.new()
  790. field.square(aa, a)
  791. if !field.sqrt(r, aa) {
  792. t.Fatal("bad sqrt 1")
  793. }
  794. field.square(rr, r)
  795. if !rr.equal(aa) {
  796. t.Fatal("bad sqrt 2")
  797. }
  798. }
  799. }
  800. func TestFp2NonResidue(t *testing.T) {
  801. field := newFp2()
  802. if !field.isQuadraticNonResidue(nonResidue2) {
  803. t.Fatal("element is quadratic non residue, 1")
  804. }
  805. if field.isQuadraticNonResidue(new(fe2).one()) {
  806. t.Fatal("one is not quadratic non residue")
  807. }
  808. if !field.isQuadraticNonResidue(new(fe2).zero()) {
  809. t.Fatal("should accept zero as quadratic non residue")
  810. }
  811. for i := 0; i < fuz; i++ {
  812. a, _ := new(fe2).rand(rand.Reader)
  813. field.squareAssign(a)
  814. if field.isQuadraticNonResidue(new(fe2).one()) {
  815. t.Fatal("element is not quadratic non residue")
  816. }
  817. }
  818. for i := 0; i < fuz; i++ {
  819. a, _ := new(fe2).rand(rand.Reader)
  820. if !field.sqrt(new(fe2), a) {
  821. if !field.isQuadraticNonResidue(a) {
  822. t.Fatal("element is quadratic non residue, 2", i)
  823. }
  824. } else {
  825. i -= 1
  826. }
  827. }
  828. }
  829. func TestFp6Serialization(t *testing.T) {
  830. field := newFp6(nil)
  831. for i := 0; i < fuz; i++ {
  832. a, _ := new(fe6).rand(rand.Reader)
  833. b, err := field.fromBytes(field.toBytes(a))
  834. if err != nil {
  835. t.Fatal(err)
  836. }
  837. if !a.equal(b) {
  838. t.Fatal("bad serialization")
  839. }
  840. }
  841. }
  842. func TestFp6AdditionProperties(t *testing.T) {
  843. field := newFp6(nil)
  844. for i := 0; i < fuz; i++ {
  845. zero := field.zero()
  846. a, _ := new(fe6).rand(rand.Reader)
  847. b, _ := new(fe6).rand(rand.Reader)
  848. c_1 := field.new()
  849. c_2 := field.new()
  850. field.add(c_1, a, zero)
  851. if !c_1.equal(a) {
  852. t.Fatal("a + 0 == a")
  853. }
  854. field.sub(c_1, a, zero)
  855. if !c_1.equal(a) {
  856. t.Fatal("a - 0 == a")
  857. }
  858. field.double(c_1, zero)
  859. if !c_1.equal(zero) {
  860. t.Fatal("2 * 0 == 0")
  861. }
  862. field.neg(c_1, zero)
  863. if !c_1.equal(zero) {
  864. t.Fatal("-0 == 0")
  865. }
  866. field.sub(c_1, zero, a)
  867. field.neg(c_2, a)
  868. if !c_1.equal(c_2) {
  869. t.Fatal("0-a == -a")
  870. }
  871. field.double(c_1, a)
  872. field.add(c_2, a, a)
  873. if !c_1.equal(c_2) {
  874. t.Fatal("2 * a == a + a")
  875. }
  876. field.add(c_1, a, b)
  877. field.add(c_2, b, a)
  878. if !c_1.equal(c_2) {
  879. t.Fatal("a + b = b + a")
  880. }
  881. field.sub(c_1, a, b)
  882. field.sub(c_2, b, a)
  883. field.neg(c_2, c_2)
  884. if !c_1.equal(c_2) {
  885. t.Fatal("a - b = - ( b - a )")
  886. }
  887. c_x, _ := new(fe6).rand(rand.Reader)
  888. field.add(c_1, a, b)
  889. field.add(c_1, c_1, c_x)
  890. field.add(c_2, a, c_x)
  891. field.add(c_2, c_2, b)
  892. if !c_1.equal(c_2) {
  893. t.Fatal("(a + b) + c == (a + c ) + b")
  894. }
  895. field.sub(c_1, a, b)
  896. field.sub(c_1, c_1, c_x)
  897. field.sub(c_2, a, c_x)
  898. field.sub(c_2, c_2, b)
  899. if !c_1.equal(c_2) {
  900. t.Fatal("(a - b) - c == (a - c ) -b")
  901. }
  902. }
  903. }
  904. func TestFp6AdditionPropertiesAssigned(t *testing.T) {
  905. field := newFp6(nil)
  906. for i := 0; i < fuz; i++ {
  907. zero := new(fe6).zero()
  908. a, b := new(fe6), new(fe6)
  909. _, _ = a.rand(rand.Reader)
  910. b.set(a)
  911. field.addAssign(a, zero)
  912. if !a.equal(b) {
  913. t.Fatal("a + 0 == a")
  914. }
  915. field.subAssign(a, zero)
  916. if !a.equal(b) {
  917. t.Fatal("a - 0 == a")
  918. }
  919. a.set(zero)
  920. field.doubleAssign(a)
  921. if !a.equal(zero) {
  922. t.Fatal("2 * 0 == 0")
  923. }
  924. a.set(zero)
  925. field.subAssign(a, b)
  926. field.neg(b, b)
  927. if !a.equal(b) {
  928. t.Fatal("0-a == -a")
  929. }
  930. _, _ = a.rand(rand.Reader)
  931. b.set(a)
  932. field.doubleAssign(a)
  933. field.addAssign(b, b)
  934. if !a.equal(b) {
  935. t.Fatal("2 * a == a + a")
  936. }
  937. _, _ = a.rand(rand.Reader)
  938. _, _ = b.rand(rand.Reader)
  939. c_1, c_2 := new(fe6).set(a), new(fe6).set(b)
  940. field.addAssign(c_1, b)
  941. field.addAssign(c_2, a)
  942. if !c_1.equal(c_2) {
  943. t.Fatal("a + b = b + a")
  944. }
  945. _, _ = a.rand(rand.Reader)
  946. _, _ = b.rand(rand.Reader)
  947. c_1.set(a)
  948. c_2.set(b)
  949. field.subAssign(c_1, b)
  950. field.subAssign(c_2, a)
  951. field.neg(c_2, c_2)
  952. if !c_1.equal(c_2) {
  953. t.Fatal("a - b = - ( b - a )")
  954. }
  955. _, _ = a.rand(rand.Reader)
  956. _, _ = b.rand(rand.Reader)
  957. c, _ := new(fe6).rand(rand.Reader)
  958. a0 := new(fe6).set(a)
  959. field.addAssign(a, b)
  960. field.addAssign(a, c)
  961. field.addAssign(b, c)
  962. field.addAssign(b, a0)
  963. if !a.equal(b) {
  964. t.Fatal("(a + b) + c == (b + c) + a")
  965. }
  966. _, _ = a.rand(rand.Reader)
  967. _, _ = b.rand(rand.Reader)
  968. _, _ = c.rand(rand.Reader)
  969. a0.set(a)
  970. field.subAssign(a, b)
  971. field.subAssign(a, c)
  972. field.subAssign(a0, c)
  973. field.subAssign(a0, b)
  974. if !a.equal(a0) {
  975. t.Fatal("(a - b) - c == (a - c) -b")
  976. }
  977. }
  978. }
  979. func TestFp6SparseMultiplication(t *testing.T) {
  980. fp6 := newFp6(nil)
  981. var a, b, u *fe6
  982. for j := 0; j < fuz; j++ {
  983. a, _ = new(fe6).rand(rand.Reader)
  984. b, _ = new(fe6).rand(rand.Reader)
  985. u, _ = new(fe6).rand(rand.Reader)
  986. b[2].zero()
  987. fp6.mul(u, a, b)
  988. fp6.mulBy01(a, a, &b[0], &b[1])
  989. if !a.equal(u) {
  990. t.Fatal("bad mul by 01")
  991. }
  992. }
  993. for j := 0; j < fuz; j++ {
  994. a, _ = new(fe6).rand(rand.Reader)
  995. b, _ = new(fe6).rand(rand.Reader)
  996. u, _ = new(fe6).rand(rand.Reader)
  997. b[2].zero()
  998. b[0].zero()
  999. fp6.mul(u, a, b)
  1000. fp6.mulBy1(a, a, &b[1])
  1001. if !a.equal(u) {
  1002. t.Fatal("bad mul by 1")
  1003. }
  1004. }
  1005. }
  1006. func TestFp6MultiplicationProperties(t *testing.T) {
  1007. field := newFp6(nil)
  1008. for i := 0; i < fuz; i++ {
  1009. a, _ := new(fe6).rand(rand.Reader)
  1010. b, _ := new(fe6).rand(rand.Reader)
  1011. zero := field.zero()
  1012. one := field.one()
  1013. c_1, c_2 := field.new(), field.new()
  1014. field.mul(c_1, a, zero)
  1015. if !c_1.equal(zero) {
  1016. t.Fatal("a * 0 == 0")
  1017. }
  1018. field.mul(c_1, a, one)
  1019. if !c_1.equal(a) {
  1020. t.Fatal("a * 1 == a")
  1021. }
  1022. field.mul(c_1, a, b)
  1023. field.mul(c_2, b, a)
  1024. if !c_1.equal(c_2) {
  1025. t.Fatal("a * b == b * a")
  1026. }
  1027. c_x, _ := new(fe6).rand(rand.Reader)
  1028. field.mul(c_1, a, b)
  1029. field.mul(c_1, c_1, c_x)
  1030. field.mul(c_2, c_x, b)
  1031. field.mul(c_2, c_2, a)
  1032. if !c_1.equal(c_2) {
  1033. t.Fatal("(a * b) * c == (a * c) * b")
  1034. }
  1035. field.square(a, zero)
  1036. if !a.equal(zero) {
  1037. t.Fatal("0^2 == 0")
  1038. }
  1039. field.square(a, one)
  1040. if !a.equal(one) {
  1041. t.Fatal("1^2 == 1")
  1042. }
  1043. _, _ = a.rand(rand.Reader)
  1044. field.square(c_1, a)
  1045. field.mul(c_2, a, a)
  1046. if !c_2.equal(c_1) {
  1047. t.Fatal("a^2 == a*a")
  1048. }
  1049. }
  1050. }
  1051. func TestFp6MultiplicationPropertiesAssigned(t *testing.T) {
  1052. field := newFp6(nil)
  1053. for i := 0; i < fuz; i++ {
  1054. a, _ := new(fe6).rand(rand.Reader)
  1055. zero, one := new(fe6).zero(), new(fe6).one()
  1056. field.mulAssign(a, zero)
  1057. if !a.equal(zero) {
  1058. t.Fatal("a * 0 == 0")
  1059. }
  1060. _, _ = a.rand(rand.Reader)
  1061. a0 := new(fe6).set(a)
  1062. field.mulAssign(a, one)
  1063. if !a.equal(a0) {
  1064. t.Fatal("a * 1 == a")
  1065. }
  1066. _, _ = a.rand(rand.Reader)
  1067. b, _ := new(fe6).rand(rand.Reader)
  1068. a0.set(a)
  1069. field.mulAssign(a, b)
  1070. field.mulAssign(b, a0)
  1071. if !a.equal(b) {
  1072. t.Fatal("a * b == b * a")
  1073. }
  1074. c, _ := new(fe6).rand(rand.Reader)
  1075. a0.set(a)
  1076. field.mulAssign(a, b)
  1077. field.mulAssign(a, c)
  1078. field.mulAssign(a0, c)
  1079. field.mulAssign(a0, b)
  1080. if !a.equal(a0) {
  1081. t.Fatal("(a * b) * c == (a * c) * b")
  1082. }
  1083. }
  1084. }
  1085. func TestFp6Exponentiation(t *testing.T) {
  1086. field := newFp6(nil)
  1087. for i := 0; i < fuz; i++ {
  1088. a, _ := new(fe6).rand(rand.Reader)
  1089. u := field.new()
  1090. field.exp(u, a, big.NewInt(0))
  1091. if !u.equal(field.one()) {
  1092. t.Fatal("a^0 == 1")
  1093. }
  1094. field.exp(u, a, big.NewInt(1))
  1095. if !u.equal(a) {
  1096. t.Fatal("a^1 == a")
  1097. }
  1098. v := field.new()
  1099. field.mul(u, a, a)
  1100. field.mul(u, u, u)
  1101. field.mul(u, u, u)
  1102. field.exp(v, a, big.NewInt(8))
  1103. if !u.equal(v) {
  1104. t.Fatal("((a^2)^2)^2 == a^8")
  1105. }
  1106. }
  1107. }
  1108. func TestFp6Inversion(t *testing.T) {
  1109. field := newFp6(nil)
  1110. for i := 0; i < fuz; i++ {
  1111. u := field.new()
  1112. zero := field.zero()
  1113. one := field.one()
  1114. field.inverse(u, zero)
  1115. if !u.equal(zero) {
  1116. t.Fatal("(0^-1) == 0)")
  1117. }
  1118. field.inverse(u, one)
  1119. if !u.equal(one) {
  1120. t.Fatal("(1^-1) == 1)")
  1121. }
  1122. a, _ := new(fe6).rand(rand.Reader)
  1123. field.inverse(u, a)
  1124. field.mul(u, u, a)
  1125. if !u.equal(one) {
  1126. t.Fatal("(r*a) * r*(a^-1) == r)")
  1127. }
  1128. }
  1129. }
  1130. func TestFp12Serialization(t *testing.T) {
  1131. field := newFp12(nil)
  1132. for i := 0; i < fuz; i++ {
  1133. a, _ := new(fe12).rand(rand.Reader)
  1134. b, err := field.fromBytes(field.toBytes(a))
  1135. if err != nil {
  1136. t.Fatal(err)
  1137. }
  1138. if !a.equal(b) {
  1139. t.Fatal("bad serialization")
  1140. }
  1141. }
  1142. }
  1143. func TestFp12AdditionProperties(t *testing.T) {
  1144. field := newFp12(nil)
  1145. for i := 0; i < fuz; i++ {
  1146. zero := field.zero()
  1147. a, _ := new(fe12).rand(rand.Reader)
  1148. b, _ := new(fe12).rand(rand.Reader)
  1149. c_1 := field.new()
  1150. c_2 := field.new()
  1151. field.add(c_1, a, zero)
  1152. if !c_1.equal(a) {
  1153. t.Fatal("a + 0 == a")
  1154. }
  1155. field.sub(c_1, a, zero)
  1156. if !c_1.equal(a) {
  1157. t.Fatal("a - 0 == a")
  1158. }
  1159. field.double(c_1, zero)
  1160. if !c_1.equal(zero) {
  1161. t.Fatal("2 * 0 == 0")
  1162. }
  1163. field.neg(c_1, zero)
  1164. if !c_1.equal(zero) {
  1165. t.Fatal("-0 == 0")
  1166. }
  1167. field.sub(c_1, zero, a)
  1168. field.neg(c_2, a)
  1169. if !c_1.equal(c_2) {
  1170. t.Fatal("0-a == -a")
  1171. }
  1172. field.double(c_1, a)
  1173. field.add(c_2, a, a)
  1174. if !c_1.equal(c_2) {
  1175. t.Fatal("2 * a == a + a")
  1176. }
  1177. field.add(c_1, a, b)
  1178. field.add(c_2, b, a)
  1179. if !c_1.equal(c_2) {
  1180. t.Fatal("a + b = b + a")
  1181. }
  1182. field.sub(c_1, a, b)
  1183. field.sub(c_2, b, a)
  1184. field.neg(c_2, c_2)
  1185. if !c_1.equal(c_2) {
  1186. t.Fatal("a - b = - ( b - a )")
  1187. }
  1188. c_x, _ := new(fe12).rand(rand.Reader)
  1189. field.add(c_1, a, b)
  1190. field.add(c_1, c_1, c_x)
  1191. field.add(c_2, a, c_x)
  1192. field.add(c_2, c_2, b)
  1193. if !c_1.equal(c_2) {
  1194. t.Fatal("(a + b) + c == (a + c ) + b")
  1195. }
  1196. field.sub(c_1, a, b)
  1197. field.sub(c_1, c_1, c_x)
  1198. field.sub(c_2, a, c_x)
  1199. field.sub(c_2, c_2, b)
  1200. if !c_1.equal(c_2) {
  1201. t.Fatal("(a - b) - c == (a - c ) -b")
  1202. }
  1203. }
  1204. }
  1205. func TestFp12MultiplicationProperties(t *testing.T) {
  1206. field := newFp12(nil)
  1207. for i := 0; i < fuz; i++ {
  1208. a, _ := new(fe12).rand(rand.Reader)
  1209. b, _ := new(fe12).rand(rand.Reader)
  1210. zero := field.zero()
  1211. one := field.one()
  1212. c_1, c_2 := field.new(), field.new()
  1213. field.mul(c_1, a, zero)
  1214. if !c_1.equal(zero) {
  1215. t.Fatal("a * 0 == 0")
  1216. }
  1217. field.mul(c_1, a, one)
  1218. if !c_1.equal(a) {
  1219. t.Fatal("a * 1 == a")
  1220. }
  1221. field.mul(c_1, a, b)
  1222. field.mul(c_2, b, a)
  1223. if !c_1.equal(c_2) {
  1224. t.Fatal("a * b == b * a")
  1225. }
  1226. c_x, _ := new(fe12).rand(rand.Reader)
  1227. field.mul(c_1, a, b)
  1228. field.mul(c_1, c_1, c_x)
  1229. field.mul(c_2, c_x, b)
  1230. field.mul(c_2, c_2, a)
  1231. if !c_1.equal(c_2) {
  1232. t.Fatal("(a * b) * c == (a * c) * b")
  1233. }
  1234. field.square(a, zero)
  1235. if !a.equal(zero) {
  1236. t.Fatal("0^2 == 0")
  1237. }
  1238. field.square(a, one)
  1239. if !a.equal(one) {
  1240. t.Fatal("1^2 == 1")
  1241. }
  1242. _, _ = a.rand(rand.Reader)
  1243. field.square(c_1, a)
  1244. field.mul(c_2, a, a)
  1245. if !c_2.equal(c_1) {
  1246. t.Fatal("a^2 == a*a")
  1247. }
  1248. }
  1249. }
  1250. func TestFp12MultiplicationPropertiesAssigned(t *testing.T) {
  1251. field := newFp12(nil)
  1252. for i := 0; i < fuz; i++ {
  1253. a, _ := new(fe12).rand(rand.Reader)
  1254. zero, one := new(fe12).zero(), new(fe12).one()
  1255. field.mulAssign(a, zero)
  1256. if !a.equal(zero) {
  1257. t.Fatal("a * 0 == 0")
  1258. }
  1259. _, _ = a.rand(rand.Reader)
  1260. a0 := new(fe12).set(a)
  1261. field.mulAssign(a, one)
  1262. if !a.equal(a0) {
  1263. t.Fatal("a * 1 == a")
  1264. }
  1265. _, _ = a.rand(rand.Reader)
  1266. b, _ := new(fe12).rand(rand.Reader)
  1267. a0.set(a)
  1268. field.mulAssign(a, b)
  1269. field.mulAssign(b, a0)
  1270. if !a.equal(b) {
  1271. t.Fatal("a * b == b * a")
  1272. }
  1273. c, _ := new(fe12).rand(rand.Reader)
  1274. a0.set(a)
  1275. field.mulAssign(a, b)
  1276. field.mulAssign(a, c)
  1277. field.mulAssign(a0, c)
  1278. field.mulAssign(a0, b)
  1279. if !a.equal(a0) {
  1280. t.Fatal("(a * b) * c == (a * c) * b")
  1281. }
  1282. }
  1283. }
  1284. func TestFp12SparseMultiplication(t *testing.T) {
  1285. fp12 := newFp12(nil)
  1286. var a, b, u *fe12
  1287. for j := 0; j < fuz; j++ {
  1288. a, _ = new(fe12).rand(rand.Reader)
  1289. b, _ = new(fe12).rand(rand.Reader)
  1290. u, _ = new(fe12).rand(rand.Reader)
  1291. b[0][2].zero()
  1292. b[1][0].zero()
  1293. b[1][2].zero()
  1294. fp12.mul(u, a, b)
  1295. fp12.mulBy014Assign(a, &b[0][0], &b[0][1], &b[1][1])
  1296. if !a.equal(u) {
  1297. t.Fatal("bad mul by 01")
  1298. }
  1299. }
  1300. }
  1301. func TestFp12Exponentiation(t *testing.T) {
  1302. field := newFp12(nil)
  1303. for i := 0; i < fuz; i++ {
  1304. a, _ := new(fe12).rand(rand.Reader)
  1305. u := field.new()
  1306. field.exp(u, a, big.NewInt(0))
  1307. if !u.equal(field.one()) {
  1308. t.Fatal("a^0 == 1")
  1309. }
  1310. field.exp(u, a, big.NewInt(1))
  1311. if !u.equal(a) {
  1312. t.Fatal("a^1 == a")
  1313. }
  1314. v := field.new()
  1315. field.mul(u, a, a)
  1316. field.mul(u, u, u)
  1317. field.mul(u, u, u)
  1318. field.exp(v, a, big.NewInt(8))
  1319. if !u.equal(v) {
  1320. t.Fatal("((a^2)^2)^2 == a^8")
  1321. }
  1322. }
  1323. }
  1324. func TestFp12Inversion(t *testing.T) {
  1325. field := newFp12(nil)
  1326. for i := 0; i < fuz; i++ {
  1327. u := field.new()
  1328. zero := field.zero()
  1329. one := field.one()
  1330. field.inverse(u, zero)
  1331. if !u.equal(zero) {
  1332. t.Fatal("(0^-1) == 0)")
  1333. }
  1334. field.inverse(u, one)
  1335. if !u.equal(one) {
  1336. t.Fatal("(1^-1) == 1)")
  1337. }
  1338. a, _ := new(fe12).rand(rand.Reader)
  1339. field.inverse(u, a)
  1340. field.mul(u, u, a)
  1341. if !u.equal(one) {
  1342. t.Fatal("(r*a) * r*(a^-1) == r)")
  1343. }
  1344. }
  1345. }
  1346. func BenchmarkMultiplication(t *testing.B) {
  1347. a, _ := new(fe).rand(rand.Reader)
  1348. b, _ := new(fe).rand(rand.Reader)
  1349. c, _ := new(fe).rand(rand.Reader)
  1350. t.ResetTimer()
  1351. for i := 0; i < t.N; i++ {
  1352. mul(c, a, b)
  1353. }
  1354. }
  1355. func BenchmarkInverse(t *testing.B) {
  1356. a, _ := new(fe).rand(rand.Reader)
  1357. b, _ := new(fe).rand(rand.Reader)
  1358. t.ResetTimer()
  1359. for i := 0; i < t.N; i++ {
  1360. inverse(a, b)
  1361. }
  1362. }
  1363. func padBytes(in []byte, size int) []byte {
  1364. out := make([]byte, size)
  1365. if len(in) > size {
  1366. panic("bad input for padding")
  1367. }
  1368. copy(out[size-len(in):], in)
  1369. return out
  1370. }