NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #4387 most downloaded on crates.io
The secp256r1 curve
Last release 5 months ago
28 Apr 2026
Ships fairly regularly
a new release about every 1.4 years
Most releases are documented
notes for 2 of 3 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
4 releases · first in 2023
One column per quarter.
Nothing published for this version
\#736 (ark-ff) Deprecate divn(), and use core::{Shr, ShrAssign} instead.
ark-ff) Implementation of mul method for BigInteger.ark-ff) Fix wasm compilation.ark-serialize) Fix array deserialization panic.Algebra) Implementation of mul method for DenseMultilinearExtension<F> * F.ark-ff, ark-ec) Add AdditiveGroup, a trait for additive groups (equipped with scalar field).ark-ec) Change AffineRepr::xy() to return owned values.ark-ec) Generic pairing implementation for the curves from the BW6 family.ark-ec) Move auxiliary parity function from ark_ec::hashing::curve_maps::swu to ark_ec::hashing::curve_maps.ark-ec) Refactor fixed-based batch multiplication:
ScalarMul::batch_mul and ScalarMul::batch_mul_with_preprocessing.BatchMulPreprocessing for to hold preprocessed powers of base.
new that calculates window size and scalar size.with_window_and_scalar_size that allows setting these parameters.windowed_mul a private method of BatchMulPreprocessing.get_mul_window_size to compute_window_size and make it private.ark-ff) Add FromStr for BigInteger.ark-ec) Require Neg, Sub, SubAssign ops on AffineRepr.ark-curve25519) Change (negate) generator of curve25519 for inter-operability with curve25519-dalek.ark-serialize) Remove Send trait bound from Valid.ark-ec) Add Elligator2 hash-to-curve map.ark-serialize) Add CanonicalSerialize and CanonicalDeserialize impls for VecDeque and LinkedList.ark-poly) Implement Polynomial for SparseMultilinearExtension and DenseMultilinearExtension.ark-serialize) Add serialize_to_vec! convenience macro.ark-ff) Add support for bitwise operations AND, OR, and XOR between BigInteger.ark-poly) Add concat to concatenate evaluation tables of DenseMultilinearPolynomials.ark-serialize) Implement Valid & CanonicalDeserialize for Rc.ark-ff) Deprecate divn(), and use core::ops::{Shr, ShrAssign} instead.ark-ff) Deprecate muln(), and use core::ops::{Shl, ShlAssign} instead.ark-ec) Omit expensive scalar multiplication in is_in_correct_subgroup_assuming_on_curve() for short Weierstrass curves of cofactor one.ark-ec) Relax the visibility for G2 ell coeffs and related algorithms.use workspace dependencies
use workspace dependencies
temp remove cyclic dev-dependencies
temp remove cyclic dev-dependencies
ark-ec) Change the implementation of Hash trait of GroupProjective to use the affine coordinates.ark-ff) Rename find_wnaf to find_naf.ark-ec, ark-ff) Remove unnecessary internal PhantomData.ark-poly) Expose more properties of EvaluationDomains.ark-ec) Add missing UniformRand trait bound to GroupAffine.ark-ec, ark-serialize) Change the serialization format for Twisted Edwards Curves. We now encode the Y coordinate and take the sign bit of the X coordinate, the default flag is also now the Positive X value. The old methods for backwards compatibility are located hereark-ec) Rename msm:{Fixed,Variable}BaseMSM:multi_scalar_mul to msm:{Fixed,Variable}:msm to avoid redundancy.ark-test-templates) Simplify the field and curve test macros.ark-ec)
COFACTOR, COFACTOR_INV, and is_in_correct_subgroup_assuming_on_curve() from {SW,TE}CurveConfig to CurveConfig.mul_bits() to AffineCurve and provide a default implementation of mul() using this.scale_by_cofactor() from short_weierstrass::GroupAffine and twisted_edwards_extended::GroupAffinerust-version = 1.56 in the manifests of all crates.ark-ff) Refactor Field implementation and PrimeField trait:
FpXYZ to Fp<N> based on const generics.field_new macros to MontFp, QuadExt and CubicExt macros.const fns for generating many constants.Fp*Parameters to Fp*Config.From<u32>, From<u16>, and From<u8> impls for BigInt<N>.FftConfig; move its contents to FftField.ark-ff) Rename BigInteger::add_nocarry to add_with_carry and sub_noborrow to sub_with_borrow.ark-ff) Remove PrimeField::GENERATOR, since it already exists on FftField.ark-ec, ark-ff) Rename FpXParams to FpXConfig and FpXParamsWrapper to FpXConfigWrapper.ark-ec) Remove mul_bits feature, and remove default implementations of mul and mul_by_cofactor_to_projective.ark-ff) Change the output of Display formatting for BigInt and Fp from hex to decimal.ark-poly) Rename UV/MVPolynomial to DenseUV/MVPolynomial.ark-ff) Remove ToBytes and FromBytes.ark-ff) Add sums_of_products to Field and Fpark-ff) Remove SquareRootField, and move functionality to Fieldark-ec) Refactor VariableBase struct to VariableBaseMSM trait and implement it for GroupProjective.ark-ec) Rename modules, structs, and traits related to ec.
short_weierstrass_jacobian → short_weierstrasstwisted_edwards_extend → twisted_edwardsGroupAffine → AffineGroupProjective → ProjectiveModelParameters → CurveConfigSWModelParameters → SWCurveConfigTEModelParameters → TECurveConfigMontgomeryModelParameters → MontCurveConfigark-ff) Add a method to construct a field element from an element of the underlying base prime field.ark-ec) Improve ergonomics of scalar multiplication.
ProjectiveCurve::mul(AsRef[u64]) to ProjectiveCurve::mul_bigint(AsRef[u64]).ProjectiveCurve by
Mul<ScalarField>,for<'a> Mul<&'a ScalarField>MulAssign<ScalarField>,for<'a> MulAssign<&'a ScalarField>AffineCurve by
Mul<ScalarField, Output = ProjectiveCurve>for<'a> Mul<&'a ScalarField, Output = ProjectiveCurve>ark-ec) Change the ATE_LOOP_COUNT in MNT4/6 curves to use 2-NAF.ark-ff) Add CyclotomicMultSubgroup trait and implement it for extension fieldsark-ec, ark-algebra-test-templates) Rename and refactor group infrastructure, and test infrastructure for fields, groups, and pairings:
Group trait and move some functionality from ProjectiveCurve to it.add_assign_mixed → add_assign that's polymorphic over its RHS.ProjectiveCurve to CurveGroup: Group.
AffineCurve → Affinebatch_normalization_into_affine → normalize_batchprime_subgroup_generator → generatorAffineCurve to AffineRepr.
Projective → Groupfn x(&self) -> Self::BaseField that returns the x coordinate of the point.fn y(&self) -> Self::BaseField that returns the y coordinate of the point.zero() → identity()is_zero() → is_identity()into_projective() → into_group()prime_subgroup_generator() → generator()ScalarMul trait that encapsulates scalar multiplication routines for arbitrary Groups.
ScalarMul trait has a MulBase associated type to encapsulate bases for variable base and fixed-base scalar multiplication algorithms.ScalarMul requires Add<Self::MulBase, Output = Self>, AddAssign<Self::MulBase>, and From<Self::MulBase>.PairingEngine to Pairing:
Fr → ScalarFieldG1Projective → G1G2Projective → G2Fqk → TargetField: CyclotomicMultSubgroupFqe.miller_loop → multi_miller_looppairing → multi_pairingproduct_of_pairings → multi_pairing
miller_loop and multi_miller_loop now
impl Into<G1Prepared> and impl Into<G2Prepared> as input, andMillerLoopOutput, which is a newtype wrapper around TargetField.final_exponentiation now
MillerLoopOutput,PairingOutput, which is a newtype around TargetField, and which implements Group and ScalarMul, allowing it to be used with the existing MSM infrastructure.ark-algebra-test-templates macro syntax is now simplified; see the test files in test-curves for examples.ark-serialize, ark-ff, ark-ec) Refactor serialization infrastructure to enable more flexibility and less repetition of code:
enum Compress that indicates whether point compression should be enabled or not.enum Validate that indicates whether type-specific validation checks should be carried out or not.trait Valid that provides methods for checking whether a deserialized value of a given type passes appropriate validation checks. The trait has the following methods
check which checks a single value, andbatch_check which checks a batch of values.CanonicalSerialize:
serialize that takes in an argument compress: Compressserialize → serialize_compressedserialize_uncompressed → serialize_uncompressedserialize with the appropriate compress value.CanonicalDeserialize:
deserialize that takes in arguments compress: Compress and validate: Validate.deserialize → deserialize_compresseddeserialize_uncompressed → deserialize_uncompresseddeserialize_unchecked → deserialize_uncompressed_uncheckeddeserialize_compressed_unchecked that performs decompression but skips validation checks.deserialize with the appropriate compress and validate values.SWFlags enum has been moved to ark_ec::models::short_weierstrass, and has had its variants renamed to be somewhat more descriptive.EdwardsFlags enum has been moved to ark_ec::models::twisted_edwards, has been renamed to TEFlags, and has had its variants renamed to be somewhat more descriptive.ark-poly) Refactor EvaluationDomain trait for cosets:
generator_inv.divide_by_vanishing_poly_on_coset_in_place.coset_fft, coset_fft_in_place, coset_ifft, coset_ifft_in_place.ark-ff) Refactor ark-ff APIs:
ff/src/fields/mod.rs into smaller files for easier management.BitIterator out of ark_ff::fields and into ark_ff directly.impl<'a, 'b> Add/Sub/Mul/Div<&'a F> for &'b Fark-ec) Move the definition of the isogeny map of WB hash-to-curve to a separate structark-ec) Refactor variable-base MSM to be checked by default, returning a Result if the lengths of the bases and scalars do not match.ark-ec, ark-ff) Rename all *Parameters or *Params to *Config, including:
SWUParams → SWUConfigWBParams → WBConfigBls12Parameters → Bls12ConfigG1Parameters → G1ConfigG2Parameters → G2ConfigBnParameters → BnConfigBW6Parameters → BW6ConfigMNT4Parameters → MNT4ConfigMNT6Parameters → MNT6ConfigGLVParameters → GLVConfigark-ff) Change frobenius_map to return the result, instead of mutating the input. Add frobenius_map_in_place for the old behavior.ark-ec) Add GLVParameters trait definition.ark-ec) Add is_in_correct_subgroup_assuming_on_curve for all Parameters.ark-ff) Change bigint conversions to impl From instead of Into.ark-ec) Add WB and SWU hash-to-curve maps.ark-ec) Add msm:{Fixed,Variable}Base:msm_checked_len.ark-ec) Add ChunkedPippenger to variable-base MSM.ark-serialize) Add serialization impls for arraysark-ff-macros, ark-ff) Add a macro to derive MontConfig.ark-ec) Add a default mul function to {TE,SW}CurveConfig trait definition.ark-ec) Add HashMapPippenger to variable-base MSM.ark-ff) Add sums_of_products to Field and Fpark-ec) Add a clear_cofactor method to AffineCurve.ark-ec) Add functionality for mapping a field element to a curve element for hash-to-curve.ark-ff) Add a method to construct a field element from an element of the underlying base prime field.ark-ff) Add CyclotomicMultSubgroup trait and impl for extension fieldsark-ec)
serialize_with_mode(), deserialize_with_mode(), and serialized_size() into {SW,TE}CurveConfig to allow customization.ark-poly) Refactor EvaluationDomain trait for cosets:
new_coset.get_coset.coset_offset, coset_offset_inv and coset_offset_pow_size.ark-ec) Implement wNAF-based MSM, resulting in 5-10% speedups.ark-ec) Allow to overwrite the default implementation of the msm function provided by the VariableBaseMSM trait by a specialized version in SWCurveConfig.ark-ff) Add the relaxed NAF computation.ark-ff, ark-ff-asm) Make the assembly backend available on stable.ark-ff) Remove duplicated code from test_field module and replace its usage with ark-test-curves crate.ark-ff) Update QuadExtField::sqrt for better performance.ark-poly) Speedup division by vanishing polynomials for dense polynomials.ark-ec) Use 2-NAF for ate pairing in MNT4/6 curves.ark-ff, ark-ff-macros) Support prime fields with (64 * k)-bit modulus.ark-ec) Allow to overwrite the default implementation of the msm function for TwistedEdwards form provided by the VariableBaseMSM trait by a specialized version in TECurveConfig.ark-serialize) Fix issues with hygiene whenever a non-standard Result type is in scope.ark-ff) Fix the bug for QuadExtField::sqrt when c1 = 0 && c0.legendre.is_qnr()ark-ff) Fix norm() for cubic extension field towers.ark-ff, ark-serialize) Remove EmptyFlags construction checks.ark-ff) Fix deserialization for modulo with 64 shaving bits.ark-ec) Fix a corner case for ate pairing in BLS12 and BW6 models.ark-poly) Change DensePolynomial::evaluate_over_domain to not truncate terms higher than the size of the domain.ark-ff) Fix squaring for Fp128.Your coding agent can read these notes before it upgrades. Set up the MCP server →