10 gmp_randinit_default (rands);
13 for (i = 0; ecc_curves[i]; i++)
15 const struct ecc_curve *ecc = ecc_curves[i];
16 mp_size_t size = ecc_size (ecc);
17 mp_limb_t *p = xalloc_limbs (ecc_size_j (ecc));
18 mp_limb_t *q = xalloc_limbs (ecc_size_j (ecc));
19 mp_limb_t *n = xalloc_limbs (size);
20 mp_limb_t *scratch = xalloc_limbs (ecc->mul_itch);
26 ecc->mul (ecc, p, n, ecc->g, scratch);
27 ecc->h_to_a (ecc, 0, p, p, scratch);
29 if (mpn_cmp (p, ecc->g, 2*size != 0))
30 die ("curve %d: ecc->mul with n = 1 failed.\n", ecc->p.bit_size);
32 for (n[0] = 2; n[0] <= 4; n[0]++)
34 ecc->mul (ecc, p, n, ecc->g, scratch);
35 test_ecc_mul_h (i, n[0], p);
38 /* (order - 1) * g = - g */
39 mpn_sub_1 (n, ecc->q.m, size, 1);
40 ecc->mul (ecc, p, n, ecc->g, scratch);
41 ecc->h_to_a (ecc, 0, p, p, scratch);
42 if (ecc->p.bit_size == 255)
43 /* For edwards curves, - (x,y ) == (-x, y). FIXME: Swap x and
44 y, to get identical negation? */
45 mpn_sub_n (p, ecc->p.m, p, size);
47 mpn_sub_n (p + size, ecc->p.m, p + size, size);
48 if (mpn_cmp (p, ecc->g, 2*size) != 0)
50 fprintf (stderr, "ecc->mul with n = order - 1 failed.\n");
56 for (j = 0; j < 100; j++)
59 mpz_rrandomb (r, rands, size * GMP_NUMB_BITS);
61 mpz_urandomb (r, rands, size * GMP_NUMB_BITS);
63 /* Reduce so that (almost surely) n < q */
64 mpz_limbs_copy (n, r, size);
65 n[size - 1] %= ecc->q.m[size - 1];
67 ecc->mul (ecc, p, n, ecc->g, scratch);
68 ecc->h_to_a (ecc, 0, p, p, scratch);
70 ecc->mul_g (ecc, q, n, scratch);
71 ecc->h_to_a (ecc, 0, q, q, scratch);
73 if (mpn_cmp (p, q, 2*size))
76 "Different results from ecc->mul and ecc->mul_g.\n"
79 fprintf (stderr, " n = ");
80 mpn_out_str (stderr, 16, n, size);
82 fprintf (stderr, "\np = ");
83 mpn_out_str (stderr, 16, p, size);
84 fprintf (stderr, ",\n ");
85 mpn_out_str (stderr, 16, p + size, size);
87 fprintf (stderr, "\nq = ");
88 mpn_out_str (stderr, 16, q, size);
89 fprintf (stderr, ",\n ");
90 mpn_out_str (stderr, 16, q + size, size);
91 fprintf (stderr, "\n");
101 gmp_randclear (rands);