From 96f385d7a48ffe259295991043a86b2cefce1891 Mon Sep 17 00:00:00 2001 From: Michael Brown Date: Wed, 27 Nov 2024 12:56:22 +0000 Subject: [crypto] Use inverse size as effective size for bigint_mod_invert() Montgomery reduction requires only the least significant element of an inverse modulo 2^k, which in turn depends upon only the least significant element of the invertend. Use the inverse size (rather than the invertend size) as the effective size for bigint_mod_invert(). This eliminates around 97% of the loop iterations for a typical 2048-bit RSA modulus. Signed-off-by: Michael Brown --- src/include/ipxe/bigint.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'src/include') diff --git a/src/include/ipxe/bigint.h b/src/include/ipxe/bigint.h index e55c536c7..14f3c5f28 100644 --- a/src/include/ipxe/bigint.h +++ b/src/include/ipxe/bigint.h @@ -248,7 +248,7 @@ FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL ); * @v inverse Big integer to hold result */ #define bigint_mod_invert( invertend, inverse ) do { \ - unsigned int size = bigint_size ( invertend ); \ + unsigned int size = bigint_size ( inverse ); \ bigint_mod_invert_raw ( (invertend)->element, \ (inverse)->element, size ); \ } while ( 0 ) -- cgit v1.2.3-55-g7522