2018-05-02 15:43:17 -04:00
|
|
|
#include "tommath_private.h"
|
2004-10-29 18:07:18 -04:00
|
|
|
#ifdef BN_MP_TOOM_MUL_C
|
2003-08-04 21:24:44 -04:00
|
|
|
/* LibTomMath, multiple-precision integer library -- Tom St Denis
|
|
|
|
*
|
|
|
|
* LibTomMath is a library that provides multiple-precision
|
|
|
|
* integer arithmetic as well as number theoretic functionality.
|
|
|
|
*
|
|
|
|
* The library was designed directly after the MPI library by
|
|
|
|
* Michael Fromberger but has been written from scratch with
|
|
|
|
* additional optimizations in place.
|
|
|
|
*
|
2018-12-29 11:56:20 -05:00
|
|
|
* SPDX-License-Identifier: Unlicense
|
2003-08-04 21:24:44 -04:00
|
|
|
*/
|
|
|
|
|
2015-11-11 19:18:15 -05:00
|
|
|
/* multiplication using the Toom-Cook 3-way algorithm
|
2004-10-29 18:07:18 -04:00
|
|
|
*
|
2015-11-11 19:18:15 -05:00
|
|
|
* Much more complicated than Karatsuba but has a lower
|
|
|
|
* asymptotic running time of O(N**1.464). This algorithm is
|
|
|
|
* only particularly useful on VERY large inputs
|
2005-03-12 06:55:11 -05:00
|
|
|
* (we're talking 1000s of digits here...).
|
2004-10-29 18:07:18 -04:00
|
|
|
*/
|
2017-09-20 10:59:43 -04:00
|
|
|
int mp_toom_mul(const mp_int *a, const mp_int *b, mp_int *c)
|
2003-08-04 21:24:44 -04:00
|
|
|
{
|
2017-08-30 13:15:27 -04:00
|
|
|
mp_int w0, w1, w2, w3, w4, tmp1, tmp2, a0, a1, a2, b0, b1, b2;
|
|
|
|
int res, B;
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* init temps */
|
|
|
|
if ((res = mp_init_multi(&w0, &w1, &w2, &w3, &w4,
|
|
|
|
&a0, &a1, &a2, &b0, &b1,
|
|
|
|
&b2, &tmp1, &tmp2, NULL)) != MP_OKAY) {
|
|
|
|
return res;
|
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* B */
|
|
|
|
B = MIN(a->used, b->used) / 3;
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* a = a2 * B**2 + a1 * B + a0 */
|
|
|
|
if ((res = mp_mod_2d(a, DIGIT_BIT * B, &a0)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2003-08-04 21:24:44 -04:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_copy(a, &a1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
mp_rshd(&a1, B);
|
|
|
|
if ((res = mp_mod_2d(&a1, DIGIT_BIT * B, &a1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2003-08-04 21:24:44 -04:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_copy(a, &a2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
mp_rshd(&a2, B*2);
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* b = b2 * B**2 + b1 * B + b0 */
|
|
|
|
if ((res = mp_mod_2d(b, DIGIT_BIT * B, &b0)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2003-08-04 21:24:44 -04:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_copy(b, &b1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
mp_rshd(&b1, B);
|
|
|
|
(void)mp_mod_2d(&b1, DIGIT_BIT * B, &b1);
|
2003-08-04 21:24:44 -04:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_copy(b, &b2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
mp_rshd(&b2, B*2);
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* w0 = a0*b0 */
|
|
|
|
if ((res = mp_mul(&a0, &b0, &w0)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* w4 = a2 * b2 */
|
|
|
|
if ((res = mp_mul(&a2, &b2, &w4)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* w1 = (a2 + 2(a1 + 2a0))(b2 + 2(b1 + 2b0)) */
|
|
|
|
if ((res = mp_mul_2(&a0, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp1, &a1, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_mul_2(&tmp1, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp1, &a2, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_mul_2(&b0, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp2, &b1, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_mul_2(&tmp2, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp2, &b2, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_mul(&tmp1, &tmp2, &w1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* w3 = (a0 + 2(a1 + 2a2))(b0 + 2(b1 + 2b2)) */
|
|
|
|
if ((res = mp_mul_2(&a2, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp1, &a1, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_mul_2(&tmp1, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp1, &a0, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_mul_2(&b2, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp2, &b1, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_mul_2(&tmp2, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp2, &b0, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_mul(&tmp1, &tmp2, &w3)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2003-08-04 21:24:44 -04:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* w2 = (a2 + a1 + a0)(b2 + b1 + b0) */
|
|
|
|
if ((res = mp_add(&a2, &a1, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp1, &a0, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&b2, &b1, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp2, &b0, &tmp2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_mul(&tmp1, &tmp2, &w2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* now solve the matrix
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
0 0 0 0 1
|
|
|
|
1 2 4 8 16
|
|
|
|
1 1 1 1 1
|
|
|
|
16 8 4 2 1
|
|
|
|
1 0 0 0 0
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
using 12 subtractions, 4 shifts,
|
|
|
|
2 small divisions and 1 small multiplication
|
|
|
|
*/
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* r1 - r4 */
|
|
|
|
if ((res = mp_sub(&w1, &w4, &w1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r3 - r0 */
|
|
|
|
if ((res = mp_sub(&w3, &w0, &w3)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r1/2 */
|
|
|
|
if ((res = mp_div_2(&w1, &w1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r3/2 */
|
|
|
|
if ((res = mp_div_2(&w3, &w3)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r2 - r0 - r4 */
|
|
|
|
if ((res = mp_sub(&w2, &w0, &w2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_sub(&w2, &w4, &w2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r1 - r2 */
|
|
|
|
if ((res = mp_sub(&w1, &w2, &w1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r3 - r2 */
|
|
|
|
if ((res = mp_sub(&w3, &w2, &w3)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r1 - 8r0 */
|
|
|
|
if ((res = mp_mul_2d(&w0, 3, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_sub(&w1, &tmp1, &w1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r3 - 8r4 */
|
|
|
|
if ((res = mp_mul_2d(&w4, 3, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_sub(&w3, &tmp1, &w3)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* 3r2 - r1 - r3 */
|
2017-10-15 10:11:09 -04:00
|
|
|
if ((res = mp_mul_d(&w2, 3uL, &w2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_sub(&w2, &w1, &w2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_sub(&w2, &w3, &w2)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r1 - r2 */
|
|
|
|
if ((res = mp_sub(&w1, &w2, &w1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r3 - r2 */
|
|
|
|
if ((res = mp_sub(&w3, &w2, &w3)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r1/3 */
|
|
|
|
if ((res = mp_div_3(&w1, &w1, NULL)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
/* r3/3 */
|
|
|
|
if ((res = mp_div_3(&w3, &w3, NULL)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
/* at this point shift W[n] by B*n */
|
|
|
|
if ((res = mp_lshd(&w1, 1*B)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_lshd(&w2, 2*B)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_lshd(&w3, 3*B)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_lshd(&w4, 4*B)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2017-08-30 13:15:27 -04:00
|
|
|
if ((res = mp_add(&w0, &w1, c)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&w2, &w3, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&w4, &tmp1, &tmp1)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
|
|
|
if ((res = mp_add(&tmp1, c, c)) != MP_OKAY) {
|
2018-04-11 16:46:35 -04:00
|
|
|
goto LBL_ERR;
|
2017-08-30 13:15:27 -04:00
|
|
|
}
|
2015-11-11 19:18:15 -05:00
|
|
|
|
2018-04-11 16:46:35 -04:00
|
|
|
LBL_ERR:
|
2017-08-30 13:15:27 -04:00
|
|
|
mp_clear_multi(&w0, &w1, &w2, &w3, &w4,
|
|
|
|
&a0, &a1, &a2, &b0, &b1,
|
|
|
|
&b2, &tmp1, &tmp2, NULL);
|
|
|
|
return res;
|
2015-11-11 19:18:15 -05:00
|
|
|
}
|
|
|
|
|
2004-10-29 18:07:18 -04:00
|
|
|
#endif
|
2005-08-01 12:37:28 -04:00
|
|
|
|
2017-08-28 10:27:26 -04:00
|
|
|
/* ref: $Format:%D$ */
|
|
|
|
/* git commit: $Format:%H$ */
|
|
|
|
/* commit time: $Format:%ai$ */
|