HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulecrypton-1.0.4Haskell2010

Crypto.PubKey.ECC.Prim

Elliptic Curve Arithmetic.

WARNING: These functions are vulnerable to timing attacks.

  • 11 values
  • Packagecrypton-1.0.4
  • Exports11
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourcePrim.hs
valuepointNegate :: Curve -> Point -> Point
#

Elliptic Curve point negation: pointNegate c p returns point q such that pointAdd c p q == PointO.

valuepointDouble :: Curve -> Point -> Point
#

Elliptic Curve point doubling.

WARNING: Vulnerable to timing attacks.

This perform the following calculation: > lambda = (3 * xp ^ 2 + a) / 2 yp > xr = lambda ^ 2 - 2 xp > yr = lambda (xp - xr) - yp

With binary curve: > xp == 0 => P = O > otherwise => > s = xp + (yp / xp) > xr = s ^ 2 + s + a > yr = xp ^ 2 + (s+1) * xr

valuepointMul :: Curve -> Integer -> Point -> Point
#

Elliptic curve point multiplication (double and add algorithm).

WARNING: Vulnerable to timing attacks.

valuepointAddTwoMuls :: Curve -> Integer -> Point -> Integer -> Point -> Point
#

Elliptic curve double-scalar multiplication (uses Shamir's trick).

pointAddTwoMuls c n1 p1 n2 p2 == pointAdd c (pointMul c n1 p1)
                                            (pointMul c n2 p2)

WARNING: Vulnerable to timing attacks.

valueisPointValid :: Curve -> Point -> Bool
#

check if a point is on specific curve

This perform three checks:

  • x is not out of range

  • y is not out of range

  • the equation y^2 = x^3 + a*x + b (mod p) holds