17 Commits (dc3deb8c81e99c0b8de46ed2cc536ffb406a3169)

Author SHA1 Message Date
  Michael Hamburg b55ac5ebd1 Ristretto for Ed448 7 years ago
  Michael Hamburg 03ba02f90d more ristretto 7 years ago
  Michael Hamburg ff1208c269 simpler ristretto 7 years ago
  Michael Hamburg dd193a3ec5 ristretto work 7 years ago
  Michael Hamburg 488e2548bd fix(?! needs testing) a critical bug in SHAKE XOF: the state would never transition to SQUEEZING, resulting in incorrect outputs 7 years ago
  Michael Hamburg b86b9648c3 decaffeination in with test cases 7 years ago
  Michael Hamburg acff03b3c7 eddsa_to_decaf_opt working 7 years ago
  Michael Hamburg 7691fb1380 eddsa_to_decaf_opt working 7 years ago
  Michael Hamburg b423ac359c working on decaffeinating ed25519 7 years ago
  Michael Hamburg 1f57b70289 move p480 and p521 to attic 9 years ago
  Mike Hamburg eab2a41d13 switch from xy positive to 1/xy positive; this is because it can make laddered direct_scalarmul almost sane. almost. 9 years ago
  Michael Hamburg 629a782fff Elligator now passes tests, but there are likely still missing preimages of rotations of the identity point. Also, projscaling elligator probably works, but it needs testing 9 years ago
  Michael Hamburg 4b0bf31fc9 progress checkin. compiles. working on point decode. have switched some of the Ds over. BTW, you can see that this is using PinkBikeShed instead of the real Curve25519; this is temporary 9 years ago
  Michael Hamburg e65e322f94 addition chain for curve25519 9 years ago
  Michael Hamburg 6c81eec339 addition chain for curve25519 9 years ago
  Michael Hamburg 2b5f3beb31 sagelike and clike routines for decaffeinating curve25519 9 years ago
  Michael Hamburg d95a1f229d auxilliary sage scripts, working on decaffeinate_curve25519.sage" 9 years ago