VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of public-key Diffie–Hellman secret-sharing systems on one machine: amd64; Core 2 45nm (1067a); 2009 Intel Core 2 Duo E7600; 2 x 3060MHz; wolfdale, supercop-20260627

[Page version: 20260805 22:01:51]

eBATS (ECRYPT Benchmarking of Asymmetric Systems) is a project to measure the performance of public-key systems. This page presents benchmark results collected in eBATS for public-key Diffie–Hellman secret-sharing systems:

Each table row lists the first quartile of many speed measurements (or StQ1 starting with supercop-20260214), the median of many speed measurements (or StQ2 starting with supercop-20260214), the third quartile of many speed measurements (or StQ3 starting with supercop-20260214), and the name of the primitive. Measurements with large interquartile range (or stabilized interquartile range) are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each Diffie–Hellman system and each implementation. Designers and implementors interested in submitting new Diffie–Hellman systems and new implementations of existing systems should read the call for submissions.


Test results

Graphs: (pkcycles,pkbytes) (scycles,pkbytes)

Cycles to generate a key pair
25%50%75%system
405424124642050
T:
jacfp127i
424174306043832
T:
kumjacfp127g
472884822149776
T:
prjfp127i
486634951251187
T:
hecfp127i
701667027270394curve25519
706567122072203
T:
ecfp256e
732537381274484
T:
jacfp128bk
751037584377125
T:
ecfp256h
764787715078269
T:
ecfp256s
829778368284912
T:
ecfp256q
862668727288602
T:
prjfp128bk
866988762889193
T:
hecfp128bk
866068765789096
T:
hecfp128fkt
867748767789297
T:
hecfp128i
122810124147125588
T:
gls1271
125709126678128133
T:
curve2251
138791138918139064nistp256
179164179213179342
T:
kumfp127g
314729314893315061
T:
kumfp128g
319112321744323018
T:
sclaus1024
331140332015332640
T:
ed448goldilocks
369320371275373452
T:
ecfp256i
386356394570407554
T:
hector
401347402922406082
T:
kummer
415591417589419588
T:
surf127eps
753911757492760230
T:
surf2113
164329016527651660169
T:
sclaus2048
165954116608971662539
T:
ed521gs
191322619149411916985
T:
nist521gs
212698421295692132599
T:
claus
Cycles to compute a shared secret
25%50%75%system
183505183551183669
T:
kumfp127g
187603187748188039
T:
kumjacfp127g
242560242812243172
T:
jacfp128bk
262655262666262727curve25519
293015293084293217
T:
jacfp127i
302279302492302711
T:
prjfp128bk
310198310340310632
T:
hecfp128fkt
315171315311315561
T:
hecfp128bk
318111320045326563
T:
gls1271
327169327260327380
T:
kumfp128g
349959350026350079
T:
ecfp256e
360834361030361259
T:
ecfp256q
362519362787363043
T:
ecfp256i
381624381755381987
T:
prjfp127i
392451392528392609
T:
hecfp127i
405890406648410244
T:
kummer
414714416408418433
T:
surf127eps
422030423658433718
T:
sclaus1024
433061433240433417
T:
ecfp256h
448038448227448500
T:
ecfp256s
522133523717525849
T:
curve2251
527798527845527963nistp256
692685692793693334
T:
hecfp128i
751559758717762012
T:
surf2113
103048110337081038242
T:
ed448goldilocks
128351012867291322714
T:
hector
165157416524061654547
T:
ed521gs
191260519148941918532
T:
nist521gs
218624121907932196964
T:
sclaus2048
254025325435702546439
T:
claus