Skip to main content

blake2s_compress_2x_seq

Function blake2s_compress_2x_seq 

Source
pub fn blake2s_compress_2x_seq(
    builder: &CircuitBuilder,
    h: [Wire; 8],
    blocks: [[Wire; 16]; 2],
    t_los: [Wire; 2],
    t_his: [Wire; 2],
    lasts: [Wire; 2],
) -> [Wire; 8]
Expand description

Two sequential BLAKE2s block compressions, evaluated in one parallel core.

The second block’s compression takes the first block’s output state as its own input state.

Both compressions run as the two 32-bit lanes of a single parallel compression.

    high lane [32:64]:  S1 = compress(input state, first block)
    low  lane [0:32] :  S2 = compress(S1,          second block)

So two chained blocks cost one compression, instead of two.

The two lanes run at the same time.

Yet the low lane needs the high lane’s output as its own input, before that output exists.

A hint breaks this circular dependency by computing that output off-circuit first.

The hinted value seeds the low lane’s input.

It is then constrained two ways, so it cannot lie:

  • Its high half must equal the real input state.
  • Its low half must equal what the first compression actually produces in-circuit.

§Arguments

  • builder - Circuit builder.
  • h - The 8-word input state for the first compression, one 32-bit value per wire.
  • blocks - The two 16-word message blocks.

The first feeds the first compression, the second feeds the second.

  • t_los - Each compression’s low 32 bits of its byte counter.
  • t_his - Each compression’s high 32 bits of its byte counter.
  • lasts - Each compression’s finalization flag.

§Preconditions

Every input wire holds a valid 32-bit value in its low 32 bits.

High halves need not be empty:

  • h’s high half is discarded by the shift that lifts it into the high lane.
  • The first block’s words, and the first compression’s counter and flag, are likewise only ever shifted, never read directly.
  • The second block’s words, and the second compression’s counter and flag, are masked before use.

§Returns

8 wires, each packing both output states.

  • Low 32 bits: the second compression’s output.
  • High 32 bits: the first compression’s output.