Eight-limb Montgomery arithmetic: runtime definitions (zero-import) #
The runtime definitions of the eight-limb Montgomery arithmetic, split out of
CompPoly.Fields.Montgomery.Native64x8 verbatim. All correctness statements about them
live in that sibling module, which imports this one.
This module deliberately has zero imports: downstream consumers put it into
precompileModules native-compilation lanes, and precompileModules compiles the
entire import closure — so the runtime definitions must not pull in mathlib.
Word helpers #
Low limb of add-with-carry: (x + y + c) mod 2 ^ 32.
Instances For
Carry-out of add-with-carry: (x + y + c) / 2 ^ 32.
Instances For
Low limb of subtract-with-borrow: (x - y - b) mod 2 ^ 32.
Instances For
Borrow-out of subtract-with-borrow, read off the sign bit of the 64-bit difference.
Instances For
Low limb of multiply-accumulate: (t + x * y + c) mod 2 ^ 32.
Instances For
High word of multiply-accumulate: (t + x * y + c) / 2 ^ 32.
Instances For
The Montgomery multiplier of a limb: (s * negInv) mod 2 ^ 32.
Instances For
Eight-limb values #
A 256-bit value as eight little-endian 32-bit limbs, each stored in a UInt64.
- l0 : UInt64
Limb of weight
2 ^ 0. - l1 : UInt64
Limb of weight
2 ^ 32. - l2 : UInt64
Limb of weight
2 ^ 64. - l3 : UInt64
Limb of weight
2 ^ 96. - l4 : UInt64
Limb of weight
2 ^ 128. - l5 : UInt64
Limb of weight
2 ^ 160. - l6 : UInt64
Limb of weight
2 ^ 192. - l7 : UInt64
Limb of weight
2 ^ 224.
Instances For
Instances For
Split a natural number into eight 32-bit limbs, discarding bits above 2 ^ 256.
Instances For
The natural number represented by the limbs: ∑ lᵢ * 2 ^ (32 * i).
Instances For
Every limb holds at most 32 significant bits.
Instances For
Limbwise addition and subtraction #
Limbwise add-with-carry, discarding the carry out of the top limb.
Instances For
Limbwise subtract-with-borrow.
Instances For
Conditional subtraction and field operations #
Subtract the modulus once if the value is at least the modulus. The borrow chain decides the branch, so no comparison is needed.
Instances For
Modular addition.
Instances For
Modular subtraction: on a borrow, the modulus is added back.
Instances For
CIOS multiplication #
The CIOS accumulator: eight limbs plus one head limb.
- t0 : UInt64
Limb of weight
2 ^ 0. - t1 : UInt64
Limb of weight
2 ^ 32. - t2 : UInt64
Limb of weight
2 ^ 64. - t3 : UInt64
Limb of weight
2 ^ 96. - t4 : UInt64
Limb of weight
2 ^ 128. - t5 : UInt64
Limb of weight
2 ^ 160. - t6 : UInt64
Limb of weight
2 ^ 192. - t7 : UInt64
Limb of weight
2 ^ 224. - t8 : UInt64
Head limb of weight
2 ^ 256.
Instances For
Instances For
The eight low limbs of the accumulator.
Instances For
The natural number represented by the accumulator.
Instances For
Every limb of the accumulator holds at most 32 significant bits.