b4cc925c30
This function is only called twice per ECDH or ECDSA operation, and it only saves a few scalar multiplications and additions compared to the alternative, so it doesn't need to be specialized. As the TODO comment above the callers notes, the two calls can be reduced to one. Implementing |ecp_nistz256_from_mont| in terms of |ecp_nistz256_mul_mont| helps show that that change is safe. This also saves a small amount of code size and improves testing and verification efficiency. Note that this is already how the function is implemented for targets other than x86-64 in OpenSSL. Change-Id: If1404951f1a787d2618c853afd1f0e99a019e012 Reviewed-on: https://boringssl-review.googlesource.com/13021 Reviewed-by: Adam Langley <alangley@gmail.com> |
||
---|---|---|
.. | ||
p256-x86_64-asm.pl |