mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-10 00:16:59 +00:00
Replaces generic square-and-multiply exponentiation in inv() and sqrt() with hand-crafted addition chains derived from libsecp256k1. The key insight: p-2 and (p+1)/4 have long runs of 1-bits (since p ≈ 2^256), so generic powModP wastes ~230+ multiplications on redundant mul-by-base steps. The addition chain instead builds a^(2^k - 1) for k = 2,3,6,9,11,22,44,88,176, 220,223 via a ladder of squarings, then combines them with a short tail. Savings per call: inv: 255 sqr + 15 mul = 270 ops (was 255 sqr + 248 mul = 503 ops) → -233 muls sqrt: 254 sqr + 13 mul = 267 ops (was 253 sqr + 246 mul = 499 ops) → -233 muls Each verify does one inv (toAffine) + one sqrt (liftX), saving ~466 field multiplications = ~29,800 fewer inner products per verification. Also removes the now-unused generic powModP function and its P_MINUS_2 / P_PLUS_1_DIV_4 exponent constants. Benchmark: verifySchnorr 3,254 → 3,429 ops/s (~5% faster, 8.2x vs native) https://claude.ai/code/session_01BhU63WUe9AhikZxRdw3Lpg