2020-04-15 19:38:02 +02:00
|
|
|
# Constantine
|
|
|
|
# Copyright (c) 2018-2019 Status Research & Development GmbH
|
|
|
|
# Copyright (c) 2020-Present Mamy André-Ratsimbazafy
|
|
|
|
# Licensed and distributed under either of
|
|
|
|
# * MIT license (license terms in the root directory or at http://opensource.org/licenses/MIT).
|
|
|
|
# * Apache v2 license (license terms in the root directory or at http://www.apache.org/licenses/LICENSE-2.0).
|
|
|
|
# at your option. This file may not be copied, modified, or distributed except according to those terms.
|
|
|
|
|
|
|
|
# ############################################################
|
|
|
|
#
|
|
|
|
# Benchmark of elliptic curves
|
|
|
|
#
|
|
|
|
# ############################################################
|
|
|
|
|
|
|
|
import
|
|
|
|
# Internals
|
2020-07-24 22:02:30 +02:00
|
|
|
../constantine/config/[curves, common],
|
2020-06-04 20:37:29 +02:00
|
|
|
../constantine/arithmetic,
|
|
|
|
../constantine/io/io_bigints,
|
2021-01-30 14:21:55 +01:00
|
|
|
../constantine/elliptic/[
|
|
|
|
ec_shortweierstrass_affine,
|
|
|
|
ec_shortweierstrass_projective,
|
|
|
|
ec_shortweierstrass_jacobian,
|
|
|
|
ec_scalar_mul, ec_endomorphism_accel],
|
2020-04-15 19:38:02 +02:00
|
|
|
# Helpers
|
2020-04-15 21:24:18 +02:00
|
|
|
../helpers/[prng_unsafe, static_for],
|
|
|
|
./platforms,
|
2020-12-15 19:18:36 +01:00
|
|
|
./bench_blueprint,
|
2020-06-14 15:39:06 +02:00
|
|
|
# Reference unsafe scalar multiplication
|
|
|
|
../tests/support/ec_reference_scalar_mult
|
2020-04-15 19:38:02 +02:00
|
|
|
|
2020-12-15 19:18:36 +01:00
|
|
|
export notes
|
|
|
|
proc separator*() = separator(177)
|
2020-07-24 22:02:30 +02:00
|
|
|
|
2020-04-15 19:38:02 +02:00
|
|
|
macro fixEllipticDisplay(T: typedesc): untyped =
|
|
|
|
# At compile-time, enums are integers and their display is buggy
|
|
|
|
# we get the Curve ID instead of the curve name.
|
|
|
|
let instantiated = T.getTypeInst()
|
|
|
|
var name = $instantiated[1][0] # EllipticEquationFormCoordinates
|
|
|
|
let fieldName = $instantiated[1][1][0]
|
|
|
|
let curveName = $Curve(instantiated[1][1][1].intVal)
|
|
|
|
name.add "[" & fieldName & "[" & curveName & "]]"
|
|
|
|
result = newLit name
|
|
|
|
|
2020-12-15 19:18:36 +01:00
|
|
|
proc report(op, elliptic: string, start, stop: MonoTime, startClk, stopClk: int64, iters: int) =
|
|
|
|
let ns = inNanoseconds((stop-start) div iters)
|
|
|
|
let throughput = 1e9 / float64(ns)
|
2020-06-04 22:09:30 +02:00
|
|
|
when SupportsGetTicks:
|
2020-12-15 19:18:36 +01:00
|
|
|
echo &"{op:<60} {elliptic:<40} {throughput:>15.3f} ops/s {ns:>9} ns/op {(stopClk - startClk) div iters:>9} CPU cycles (approx)"
|
|
|
|
else:
|
|
|
|
echo &"{op:<60} {elliptic:<40} {throughput:>15.3f} ops/s {ns:>9} ns/op"
|
2020-06-04 22:09:30 +02:00
|
|
|
|
2020-12-15 19:18:36 +01:00
|
|
|
template bench(op: string, T: typedesc, iters: int, body: untyped): untyped =
|
|
|
|
measure(iters, startTime, stopTime, startClk, stopClk, body)
|
|
|
|
report(op, fixEllipticDisplay(T), startTime, stopTime, startClk, stopClk, iters)
|
2020-04-15 19:38:02 +02:00
|
|
|
|
|
|
|
proc addBench*(T: typedesc, iters: int) =
|
2020-06-15 22:58:56 +02:00
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
2020-04-15 19:38:02 +02:00
|
|
|
var r {.noInit.}: T
|
2020-04-15 22:23:46 +02:00
|
|
|
let P = rng.random_unsafe(T)
|
|
|
|
let Q = rng.random_unsafe(T)
|
2020-06-15 22:58:56 +02:00
|
|
|
bench("EC Add " & G1_or_G2, T, iters):
|
2020-04-15 22:23:46 +02:00
|
|
|
r.sum(P, Q)
|
|
|
|
|
2020-09-26 09:16:29 +02:00
|
|
|
proc mixedAddBench*(T: typedesc, iters: int) =
|
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
|
|
|
var r {.noInit.}: T
|
|
|
|
let P = rng.random_unsafe(T)
|
|
|
|
let Q = rng.random_unsafe(T)
|
2020-10-09 07:51:47 +02:00
|
|
|
var Qaff: ECP_ShortW_Aff[T.F, T.Tw]
|
2021-02-06 16:29:53 +01:00
|
|
|
when Q is ECP_ShortW_Prj:
|
2021-01-30 14:21:55 +01:00
|
|
|
Qaff.affineFromProjective(Q)
|
|
|
|
else:
|
|
|
|
Qaff.affineFromJacobian(Q)
|
2020-09-26 09:16:29 +02:00
|
|
|
bench("EC Mixed Addition " & G1_or_G2, T, iters):
|
|
|
|
r.madd(P, Qaff)
|
|
|
|
|
2020-04-15 22:23:46 +02:00
|
|
|
proc doublingBench*(T: typedesc, iters: int) =
|
2020-06-15 22:58:56 +02:00
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
2020-04-15 22:23:46 +02:00
|
|
|
var r {.noInit.}: T
|
|
|
|
let P = rng.random_unsafe(T)
|
2020-06-15 22:58:56 +02:00
|
|
|
bench("EC Double " & G1_or_G2, T, iters):
|
2020-04-15 22:23:46 +02:00
|
|
|
r.double(P)
|
2020-06-04 20:37:29 +02:00
|
|
|
|
2020-10-02 00:01:09 +02:00
|
|
|
proc affFromProjBench*(T: typedesc, iters: int) =
|
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
2020-10-09 07:51:47 +02:00
|
|
|
var r {.noInit.}: ECP_ShortW_Aff[T.F, T.Tw]
|
2020-10-02 00:01:09 +02:00
|
|
|
let P = rng.random_unsafe(T)
|
|
|
|
bench("EC Projective to Affine " & G1_or_G2, T, iters):
|
|
|
|
r.affineFromProjective(P)
|
|
|
|
|
|
|
|
proc affFromJacBench*(T: typedesc, iters: int) =
|
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
2020-10-09 07:51:47 +02:00
|
|
|
var r {.noInit.}: ECP_ShortW_Aff[T.F, T.Tw]
|
2020-10-02 00:01:09 +02:00
|
|
|
let P = rng.random_unsafe(T)
|
|
|
|
bench("EC Jacobian to Affine " & G1_or_G2, T, iters):
|
|
|
|
r.affineFromJacobian(P)
|
|
|
|
|
2020-09-03 23:10:48 +02:00
|
|
|
proc scalarMulGenericBench*(T: typedesc, window: static int, iters: int) =
|
2020-06-04 20:37:29 +02:00
|
|
|
const bits = T.F.C.getCurveOrderBitwidth()
|
2020-06-15 22:58:56 +02:00
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
2020-06-04 20:37:29 +02:00
|
|
|
|
|
|
|
var r {.noInit.}: T
|
2020-06-14 15:39:06 +02:00
|
|
|
let P = rng.random_unsafe(T) # TODO: clear cofactor
|
2020-06-04 20:37:29 +02:00
|
|
|
|
|
|
|
let exponent = rng.random_unsafe(BigInt[bits])
|
|
|
|
|
2020-10-10 18:53:48 +02:00
|
|
|
bench("EC ScalarMul " & $bits & "-bit " & G1_or_G2 & " (window-" & $window & ", generic)", T, iters):
|
2020-06-04 20:37:29 +02:00
|
|
|
r = P
|
2020-09-03 23:10:48 +02:00
|
|
|
r.scalarMulGeneric(exponent, window)
|
2020-06-04 20:37:29 +02:00
|
|
|
|
2020-06-15 22:58:56 +02:00
|
|
|
proc scalarMulEndo*(T: typedesc, iters: int) =
|
2020-06-14 15:39:06 +02:00
|
|
|
const bits = T.F.C.getCurveOrderBitwidth()
|
2020-06-15 22:58:56 +02:00
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
2020-06-14 15:39:06 +02:00
|
|
|
|
|
|
|
var r {.noInit.}: T
|
|
|
|
let P = rng.random_unsafe(T) # TODO: clear cofactor
|
|
|
|
|
|
|
|
let exponent = rng.random_unsafe(BigInt[bits])
|
|
|
|
|
2020-10-10 16:19:23 +02:00
|
|
|
bench("EC ScalarMul " & $bits & "-bit " & G1_or_G2 & " (endomorphism accelerated)", T, iters):
|
2020-06-14 15:39:06 +02:00
|
|
|
r = P
|
2020-09-03 23:10:48 +02:00
|
|
|
r.scalarMulEndo(exponent)
|
2020-06-14 15:39:06 +02:00
|
|
|
|
2020-08-25 00:02:30 +02:00
|
|
|
proc scalarMulEndoWindow*(T: typedesc, iters: int) =
|
|
|
|
const bits = T.F.C.getCurveOrderBitwidth()
|
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
|
|
|
|
|
|
|
var r {.noInit.}: T
|
|
|
|
let P = rng.random_unsafe(T) # TODO: clear cofactor
|
|
|
|
|
|
|
|
let exponent = rng.random_unsafe(BigInt[bits])
|
|
|
|
|
2020-10-10 16:19:23 +02:00
|
|
|
bench("EC ScalarMul " & $bits & "-bit " & G1_or_G2 & " (window-2, endomorphism accelerated)", T, iters):
|
2020-08-25 00:02:30 +02:00
|
|
|
r = P
|
|
|
|
when T.F is Fp:
|
|
|
|
r.scalarMulGLV_m2w2(exponent)
|
|
|
|
else:
|
|
|
|
{.error: "Not implemented".}
|
|
|
|
|
2020-06-14 15:39:06 +02:00
|
|
|
proc scalarMulUnsafeDoubleAddBench*(T: typedesc, iters: int) =
|
|
|
|
const bits = T.F.C.getCurveOrderBitwidth()
|
2020-06-15 22:58:56 +02:00
|
|
|
const G1_or_G2 = when T.F is Fp: "G1" else: "G2"
|
2020-06-14 15:39:06 +02:00
|
|
|
|
|
|
|
var r {.noInit.}: T
|
|
|
|
let P = rng.random_unsafe(T) # TODO: clear cofactor
|
|
|
|
|
|
|
|
let exponent = rng.random_unsafe(BigInt[bits])
|
|
|
|
|
2020-10-10 16:19:23 +02:00
|
|
|
bench("EC ScalarMul " & $bits & "-bit " & G1_or_G2 & " (unsafe reference DoubleAdd)", T, iters):
|
2020-06-14 15:39:06 +02:00
|
|
|
r = P
|
2020-09-03 23:10:48 +02:00
|
|
|
r.unsafe_ECmul_double_add(exponent)
|