Skip to content

Fuzz Fix - Hash-To-Curve - Isogeny EC add non-fully-reduced input - #250

Merged
mratsim merged 2 commits into
masterfrom
fuzz-fail-2-h2c
Jul 3, 2023
Merged

mratsim merged 2 commits into
masterfrom
fuzz-fail-2-h2c

Conversation

@mratsim

@mratsim mratsim commented Jul 2, 2023

Copy link
Copy Markdown
Owner

Skipping the final substraction in this codepath (only taken for EC add on isogeny in SSWU hash-to-curve):

HHH_or_Mpre.prod(a, b, true) # HHH or X₁²

is incorrect as HHH_or_Mpre is later used in field addition/substraction and so need fully reduced Montgomery representation.

Furthermore we fix a similar bug when the curve has a coefficient a=-3 (we have no such curve fully implemented though P256 and other NIST curves all have a=-3).

Lastly we accelerate BLS12-381 hashToG2 by enabling mulCheckSparse

We also change the notation of intermediate point from P to Q to be in line with the spec documentation
image

@mratsim
mratsim merged commit d69c7bf into master Jul 3, 2023
@mratsim
mratsim deleted the fuzz-fail-2-h2c branch July 3, 2023 04:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant