Skip to main content

g_mixing

Function g_mixing 

Source
pub fn g_mixing(
    builder: &CircuitBuilder,
    v: &mut [Wire; 16],
    a: usize,
    b: usize,
    c: usize,
    d: usize,
    x: Wire,
    y: Wire,
)
Expand description

BLAKE2b G mixing function

This implements the core mixing operation:

a = a + b + x
d = rotr64(d ^ a, 32)
c = c + d
b = rotr64(b ^ c, 24)
a = a + b + y
d = rotr64(d ^ a, 16)
c = c + d
b = rotr64(b ^ c, 63)

Cost: 8 AND constraints (4 additions × 2 constraints each)