VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of public-key Diffie–Hellman secret-sharing systems on one machine: aarch64; Neoverse-N1 (413fd0c1); 2021 Ampere Altra Max M128-30; 64 x 3000MHz; cfarm425, supercop-20261004

[Page version: 20261009 01:11:50]

eBATS (ECRYPT Benchmarking of Asymmetric Systems) is a project to measure the performance of public-key systems. This page presents benchmark results collected in eBATS for public-key Diffie–Hellman secret-sharing systems:

Each table row lists the first quartile of many speed measurements (or StQ1 starting with supercop-20260214), the median of many speed measurements (or StQ2 starting with supercop-20260214), the third quartile of many speed measurements (or StQ3 starting with supercop-20260214), and the name of the primitive. Measurements with large interquartile range (or stabilized interquartile range) are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each Diffie–Hellman system and each implementation. Designers and implementors interested in submitting new Diffie–Hellman systems and new implementations of existing systems should read the call for submissions.


Test results

Graphs: (pkcycles,pkbytes) (scycles,pkbytes)

Cycles to generate a key pair
25%50%75%system
496334968249736curve25519
685456860368701nistp256
184035184506185036
T:
kummer
673093681009688703
T:
sclaus1024
183491018373161839989
T:
ed521gs
231821423193082321021
T:
nist521gs
355104335779763606048
T:
sclaus2048
398281939913794002041
T:
claus
Cycles to compute a shared secret
25%50%75%system
111606111620111633curve25519
185155185385185563
T:
kummer
243841243968244093nistp256
684307688901699440
T:
sclaus1024
183532918385821841392
T:
ed521gs
231840023192222320586
T:
nist521gs
359597336373853651219
T:
sclaus2048
398911339965924006963
T:
claus