2026-09-24 23:18:10 -06:00
|
|
|
/// @file dpf/fp61.hpp
|
2026-09-24 23:27:47 -06:00
|
|
|
/// @brief Prime field of order `2^61 - 1`, as an additive output type.
|
2026-09-24 23:18:10 -06:00
|
|
|
/// @copyright Copyright (c) 2019-2026 Ryan Henry and [others](@ref authors)
|
|
|
|
|
/// @license Released under a GNU General Public v2.0 (GPLv2) license;
|
|
|
|
|
/// see [LICENSE.md](@ref license) for details.
|
|
|
|
|
|
|
|
|
|
#ifndef LIBDPF_INCLUDE_DPF_FP61_HPP__
|
|
|
|
|
#define LIBDPF_INCLUDE_DPF_FP61_HPP__
|
|
|
|
|
|
|
|
|
|
#include <cstddef>
|
|
|
|
|
#include <cstdint>
|
|
|
|
|
#include <cstring>
|
|
|
|
|
#include <ostream>
|
2026-09-28 05:59:19 -06:00
|
|
|
#include <stdexcept>
|
2026-09-24 23:18:10 -06:00
|
|
|
#include <type_traits>
|
|
|
|
|
|
|
|
|
|
#include "hedley/hedley.h"
|
|
|
|
|
|
|
|
|
|
#include "dpf/utils.hpp"
|
|
|
|
|
#include "dpf/leaf_arithmetic.hpp"
|
2026-09-28 05:59:19 -06:00
|
|
|
#include "dpf/random.hpp"
|
2026-09-24 23:18:10 -06:00
|
|
|
|
|
|
|
|
namespace dpf
|
|
|
|
|
{
|
|
|
|
|
|
2026-09-28 05:59:19 -06:00
|
|
|
/// @brief Modulus \f$p = 2^{61}-1\f$. `p` itself reduces to 0.
|
2026-09-24 23:18:10 -06:00
|
|
|
inline constexpr std::uint64_t fp61_mod = (std::uint64_t{1} << 61) - 1;
|
|
|
|
|
|
2026-09-24 23:27:47 -06:00
|
|
|
/// @brief Additive element of the field of order `2^61 - 1`.
|
2026-09-24 23:18:10 -06:00
|
|
|
class fp61
|
|
|
|
|
{
|
|
|
|
|
public:
|
|
|
|
|
/// @brief Underlying unsigned word. Values are stored already reduced.
|
|
|
|
|
using integral_type = std::uint64_t;
|
|
|
|
|
static constexpr std::size_t num_bits = 61;
|
|
|
|
|
static constexpr bool dpf_modint = true;
|
|
|
|
|
static constexpr bool dpf_fp61 = true;
|
|
|
|
|
|
|
|
|
|
/// @brief Reduce `v` into the field.
|
|
|
|
|
/// @param v the integer to reduce. Defaults to 0
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
constexpr fp61(integral_type v = 0) noexcept
|
|
|
|
|
: val{reduce(v)}
|
|
|
|
|
{ }
|
|
|
|
|
|
|
|
|
|
/// @brief Copy constructor.
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
constexpr fp61(const fp61 &) noexcept = default;
|
|
|
|
|
/// @brief Move constructor.
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
constexpr fp61(fp61 &&) noexcept = default;
|
|
|
|
|
/// @brief Copy assignment.
|
|
|
|
|
/// @return `*this`
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
constexpr fp61 & operator=(const fp61 &) noexcept = default;
|
|
|
|
|
/// @brief Move assignment.
|
|
|
|
|
/// @return `*this`
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
constexpr fp61 & operator=(fp61 &&) noexcept = default;
|
|
|
|
|
|
|
|
|
|
/// @brief The reduced representative in `[0, p)`.
|
|
|
|
|
/// @return the stored field element
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_PURE
|
2026-09-28 05:59:19 -06:00
|
|
|
constexpr integral_type raw() const noexcept { return reduce(val); }
|
|
|
|
|
|
|
|
|
|
/// @brief Build a field element from PRG bytes (Mersenne reduction).
|
|
|
|
|
/// @param bytes the PRG output
|
|
|
|
|
/// @param n the number of bytes available
|
|
|
|
|
/// @return the field element
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
static fp61 from_seed(const void * bytes, std::size_t n) noexcept
|
|
|
|
|
{
|
|
|
|
|
unsigned char buf[16]{};
|
|
|
|
|
if (n > sizeof(buf))
|
|
|
|
|
n = sizeof(buf);
|
|
|
|
|
std::memcpy(buf, bytes, n);
|
|
|
|
|
std::uint64_t w[2]{};
|
|
|
|
|
std::memcpy(w, buf, sizeof(w));
|
|
|
|
|
using u128 = unsigned __int128;
|
|
|
|
|
const u128 wide = static_cast<u128>(w[0])
|
|
|
|
|
| (static_cast<u128>(w[1]) << 64);
|
|
|
|
|
const auto lo = static_cast<integral_type>(wide) & fp61_mod;
|
|
|
|
|
const auto mid = static_cast<integral_type>(wide >> 61) & fp61_mod;
|
|
|
|
|
const auto hi = static_cast<integral_type>(wide >> 122);
|
|
|
|
|
return fp61{lo + mid + hi};
|
|
|
|
|
}
|
2026-09-24 23:18:10 -06:00
|
|
|
|
|
|
|
|
/// @brief Same value as `raw()`.
|
|
|
|
|
/// @return the stored field element
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_PURE
|
|
|
|
|
explicit constexpr operator integral_type() const noexcept { return val; }
|
|
|
|
|
|
|
|
|
|
/// @brief Mersenne reduction of a 64-bit word.
|
|
|
|
|
/// @param x the integer to reduce
|
|
|
|
|
/// @return `x` modulo `2^61-1`, with `p` itself represented as 0
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_CONST
|
|
|
|
|
static constexpr integral_type reduce(integral_type x) noexcept
|
|
|
|
|
{
|
|
|
|
|
x = (x & fp61_mod) + (x >> 61);
|
|
|
|
|
if (x >= fp61_mod)
|
|
|
|
|
x -= fp61_mod;
|
|
|
|
|
return x;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// @brief Field addition.
|
|
|
|
|
/// @param a left addend
|
|
|
|
|
/// @param b right addend
|
|
|
|
|
/// @return `a + b` in the field
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_CONST
|
|
|
|
|
friend constexpr fp61 operator+(fp61 a, fp61 b) noexcept
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
return fp61{reduce(a.val) + reduce(b.val)};
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// @brief Field subtraction.
|
|
|
|
|
/// @param a minuend
|
|
|
|
|
/// @param b subtrahend
|
|
|
|
|
/// @return `a - b` in the field
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_CONST
|
|
|
|
|
friend constexpr fp61 operator-(fp61 a, fp61 b) noexcept
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
return fp61{reduce(a.val) + fp61_mod - reduce(b.val)};
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// @brief Field negation.
|
|
|
|
|
/// @param a the element to negate
|
|
|
|
|
/// @return `-a`, with `-0 = 0`
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_CONST
|
|
|
|
|
friend constexpr fp61 operator-(fp61 a) noexcept
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
const auto v = reduce(a.val);
|
|
|
|
|
return fp61{v == 0 ? 0 : fp61_mod - v};
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// @brief Field multiplication.
|
|
|
|
|
/// @param a left factor
|
|
|
|
|
/// @param b right factor
|
|
|
|
|
/// @return `a * b` in the field
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_CONST
|
|
|
|
|
friend constexpr fp61 operator*(fp61 a, fp61 b) noexcept
|
|
|
|
|
{
|
|
|
|
|
using u128 = unsigned __int128;
|
2026-09-28 05:59:19 -06:00
|
|
|
const u128 p = static_cast<u128>(reduce(a.val)) * static_cast<u128>(reduce(b.val));
|
2026-09-24 23:18:10 -06:00
|
|
|
const auto lo = static_cast<integral_type>(p) & fp61_mod;
|
|
|
|
|
const auto mid = static_cast<integral_type>(p >> 61) & fp61_mod;
|
|
|
|
|
const auto hi = static_cast<integral_type>(p >> 122);
|
|
|
|
|
return fp61{lo + mid + hi};
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// @brief Field equality.
|
|
|
|
|
/// @param a left element
|
|
|
|
|
/// @param b right element
|
|
|
|
|
/// @return `true` when the reduced values match
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_CONST
|
|
|
|
|
friend constexpr bool operator==(fp61 a, fp61 b) noexcept
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
return reduce(a.val) == reduce(b.val);
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// @brief Field inequality.
|
|
|
|
|
/// @param a left element
|
|
|
|
|
/// @param b right element
|
|
|
|
|
/// @return `true` when the reduced values differ
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
HEDLEY_CONST
|
|
|
|
|
friend constexpr bool operator!=(fp61 a, fp61 b) noexcept
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
return reduce(a.val) != reduce(b.val);
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// @brief Write the reduced representative in decimal.
|
|
|
|
|
/// @param os the output stream
|
|
|
|
|
/// @param a the element to write
|
|
|
|
|
/// @return `os`
|
|
|
|
|
friend std::ostream & operator<<(std::ostream & os, fp61 a)
|
|
|
|
|
{
|
|
|
|
|
return os << a.val;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private:
|
|
|
|
|
integral_type val;
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
namespace utils
|
|
|
|
|
{
|
|
|
|
|
|
|
|
|
|
template <>
|
|
|
|
|
struct bitlength_of<fp61>
|
|
|
|
|
: std::integral_constant<std::size_t, 61>
|
|
|
|
|
{ };
|
|
|
|
|
|
|
|
|
|
template <>
|
|
|
|
|
struct has_characteristic_two<fp61> : std::false_type
|
|
|
|
|
{ };
|
|
|
|
|
|
|
|
|
|
} // namespace utils
|
|
|
|
|
|
|
|
|
|
namespace leaf_arithmetic
|
|
|
|
|
{
|
|
|
|
|
|
2026-09-28 05:59:19 -06:00
|
|
|
namespace detail
|
|
|
|
|
{
|
|
|
|
|
|
|
|
|
|
template <std::size_t Lanes>
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
void fp61_lanes(const void * a, const void * b, void * out,
|
|
|
|
|
fp61 (*op)(fp61, fp61)) noexcept
|
|
|
|
|
{
|
|
|
|
|
std::uint64_t aa[Lanes], bb[Lanes], cc[Lanes];
|
|
|
|
|
std::memcpy(aa, a, sizeof(aa));
|
|
|
|
|
std::memcpy(bb, b, sizeof(bb));
|
|
|
|
|
for (std::size_t i = 0; i < Lanes; ++i)
|
|
|
|
|
cc[i] = op(fp61{aa[i]}, fp61{bb[i]}).raw();
|
|
|
|
|
std::memcpy(out, cc, sizeof(cc));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
template <std::size_t Lanes>
|
|
|
|
|
HEDLEY_ALWAYS_INLINE
|
|
|
|
|
void fp61_scale(const void * a, fp61 b, void * out) noexcept
|
|
|
|
|
{
|
|
|
|
|
std::uint64_t aa[Lanes], cc[Lanes];
|
|
|
|
|
std::memcpy(aa, a, sizeof(aa));
|
|
|
|
|
for (std::size_t i = 0; i < Lanes; ++i)
|
|
|
|
|
cc[i] = (fp61{aa[i]} * b).raw();
|
|
|
|
|
std::memcpy(out, cc, sizeof(cc));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
} // namespace detail
|
|
|
|
|
|
2026-09-24 23:18:10 -06:00
|
|
|
HEDLEY_PRAGMA(GCC diagnostic push)
|
|
|
|
|
HEDLEY_PRAGMA(GCC diagnostic ignored "-Wignored-attributes")
|
|
|
|
|
template <>
|
|
|
|
|
struct add_t<fp61, simde__m128i>
|
|
|
|
|
{
|
|
|
|
|
auto operator()(const simde__m128i & a, const simde__m128i & b) const
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
simde__m128i out;
|
|
|
|
|
detail::fp61_lanes<2>(&a, &b, &out, [](fp61 x, fp61 y) {
|
|
|
|
|
return x + y;
|
|
|
|
|
});
|
|
|
|
|
return out;
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
template <>
|
|
|
|
|
struct subtract_t<fp61, simde__m128i>
|
|
|
|
|
{
|
|
|
|
|
auto operator()(const simde__m128i & a, const simde__m128i & b) const
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
simde__m128i out;
|
|
|
|
|
detail::fp61_lanes<2>(&a, &b, &out, [](fp61 x, fp61 y) {
|
|
|
|
|
return x - y;
|
|
|
|
|
});
|
|
|
|
|
return out;
|
|
|
|
|
}
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
template <>
|
|
|
|
|
struct multiply_t<fp61, simde__m128i>
|
|
|
|
|
{
|
|
|
|
|
auto operator()(const simde__m128i & a, fp61 b) const
|
|
|
|
|
{
|
|
|
|
|
simde__m128i out;
|
|
|
|
|
detail::fp61_scale<2>(&a, b, &out);
|
|
|
|
|
return out;
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
template <>
|
|
|
|
|
struct add_t<fp61, simde__m256i>
|
|
|
|
|
{
|
|
|
|
|
auto operator()(const simde__m256i & a, const simde__m256i & b) const
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
simde__m256i out;
|
|
|
|
|
detail::fp61_lanes<4>(&a, &b, &out, [](fp61 x, fp61 y) {
|
|
|
|
|
return x + y;
|
|
|
|
|
});
|
|
|
|
|
return out;
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
template <>
|
|
|
|
|
struct subtract_t<fp61, simde__m256i>
|
|
|
|
|
{
|
|
|
|
|
auto operator()(const simde__m256i & a, const simde__m256i & b) const
|
|
|
|
|
{
|
2026-09-28 05:59:19 -06:00
|
|
|
simde__m256i out;
|
|
|
|
|
detail::fp61_lanes<4>(&a, &b, &out, [](fp61 x, fp61 y) {
|
|
|
|
|
return x - y;
|
|
|
|
|
});
|
|
|
|
|
return out;
|
|
|
|
|
}
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
template <>
|
|
|
|
|
struct multiply_t<fp61, simde__m256i>
|
|
|
|
|
{
|
|
|
|
|
auto operator()(const simde__m256i & a, fp61 b) const
|
|
|
|
|
{
|
|
|
|
|
simde__m256i out;
|
|
|
|
|
detail::fp61_scale<4>(&a, b, &out);
|
|
|
|
|
return out;
|
2026-09-24 23:18:10 -06:00
|
|
|
}
|
|
|
|
|
};
|
|
|
|
|
HEDLEY_PRAGMA(GCC diagnostic pop)
|
|
|
|
|
|
|
|
|
|
} // namespace leaf_arithmetic
|
|
|
|
|
|
2026-09-28 05:59:19 -06:00
|
|
|
/// @brief Sample a uniformly reduced field element by rejection.
|
|
|
|
|
/// @return an element of the field
|
|
|
|
|
template <>
|
|
|
|
|
HEDLEY_NO_THROW
|
|
|
|
|
inline auto uniform_sample<fp61>() noexcept
|
|
|
|
|
{
|
|
|
|
|
for (;;)
|
|
|
|
|
{
|
|
|
|
|
const auto v = uniform_sample<std::uint64_t>() & fp61_mod;
|
|
|
|
|
if (v < fp61_mod)
|
|
|
|
|
return fp61{v};
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
namespace detail
|
|
|
|
|
{
|
|
|
|
|
|
|
|
|
|
template <>
|
|
|
|
|
struct shamir_field<fp61> : std::true_type
|
|
|
|
|
{
|
|
|
|
|
/// @brief `a^{-1}` by Fermat, `a^{p-2}`.
|
|
|
|
|
/// @param a a non-zero field element
|
|
|
|
|
/// @return `a^{-1}`
|
|
|
|
|
/// @throws std::invalid_argument if `a` is zero
|
|
|
|
|
static fp61 inv(fp61 a)
|
|
|
|
|
{
|
|
|
|
|
if (a.raw() == 0)
|
|
|
|
|
throw std::invalid_argument("shamir: inverse of zero");
|
|
|
|
|
fp61 base = a;
|
|
|
|
|
fp61 out{1};
|
|
|
|
|
auto e = fp61_mod - 2;
|
|
|
|
|
while (e != 0)
|
|
|
|
|
{
|
|
|
|
|
if (e & 1u)
|
|
|
|
|
out = out * base;
|
|
|
|
|
base = base * base;
|
|
|
|
|
e >>= 1;
|
|
|
|
|
}
|
|
|
|
|
return out;
|
|
|
|
|
}
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
} // namespace detail
|
|
|
|
|
|
2026-09-24 23:18:10 -06:00
|
|
|
} // namespace dpf
|
|
|
|
|
|
|
|
|
|
#endif // LIBDPF_INCLUDE_DPF_FP61_HPP__
|