VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of NISTLWC hash candidates on one machine: amd64; K10 45nm (100f63); 2010 AMD Athlon II Neo K125; 1 x 1700MHz; h3neo, supercop-20250415

[Page version: 20250523 10:17:48]

eBASH (ECRYPT Benchmarking of All Submitted Hashes) is a project to measure the performance of hash functions. This page presents an excerpt of the full eBASH benchmark results. The excerpt is for NISTLWC, specifically (starting with supercop-20221005) finalists.

Each table row lists the first quartile of many speed measurements, the median of many speed measurements, the third quartile of many speed measurements, and the name of the primitive. Measurements with large variance are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each hash function (and each implementation).


Test results

Graphs: (bytes,cycles)
Cycles/byte for long messages
25%50%75%hash
9.329.329.33sha512
10.4510.4510.45shake128
14.6514.6614.66sha256
17.9617.9617.96asconxofav12
17.9617.9617.96asconhashav12
26.6926.6926.69asconxofv12
26.6926.6926.69asconhashv12
31.1031.1631.33T:xoodyakv1
36.8836.8836.90asconhashabi32v12
55.3955.4055.42asconhashbi32v12
70.3770.4170.59T:esch256v2
101.74101.78102.04T:esch384v2
131.48131.49131.50T:romulush
403.40403.65406.35T:photonbeetlehash256rate32v1
Cycles/byte for 4096 bytes
25%50%75%hash
10.2910.2910.31sha512
10.7010.7010.70shake128
15.5715.5715.58sha256
18.1418.1418.15asconhashav12
18.1418.1418.15asconxofav12
26.9326.9326.93asconxofv12
26.9326.9326.93asconhashv12
31.2831.4731.47T:xoodyakv1
37.3437.3437.34asconhashabi32v12
55.8455.8455.85asconhashbi32v12
70.8570.8571.04T:esch256v2
102.76102.77103.01T:esch384v2
132.45132.51132.53T:romulush
402.78403.02405.15T:photonbeetlehash256rate32v1
Cycles/byte for 1536 bytes
25%50%75%hash
11.4411.4511.45shake128
11.8911.9311.94sha512
17.0517.0717.11sha256
18.4518.4518.46asconhashav12
18.4518.4518.46asconxofav12
27.3227.3227.33asconxofv12
27.3227.3327.34asconhashv12
31.5431.5431.72T:xoodyakv1
38.1038.1138.11asconhashabi32v12
56.5956.5956.60asconhashbi32v12
71.6371.6471.83T:esch256v2
104.45104.46104.70T:esch384v2
134.05134.08134.11T:romulush
402.21402.44403.84T:photonbeetlehash256rate32v1
Cycles/byte for 576 bytes
25%50%75%hash
12.3212.3412.35shake128
15.1515.1815.28sha512
19.2719.2719.29asconhashav12
19.2719.2719.29asconxofav12
21.1021.1221.21sha256
28.3828.3828.40asconxofv12
28.3928.4028.41asconhashv12
32.2532.4132.53T:xoodyakv1
40.1540.1640.16asconhashabi32v12
58.5858.5958.60asconhashbi32v12
73.6473.7173.89T:esch256v2
108.92108.93109.19T:esch384v2
138.42138.51138.53T:romulush
397.67398.69399.95T:photonbeetlehash256rate32v1
Cycles/byte for 64 bytes
25%50%75%hash
28.7328.7529.09shake128
29.4229.4229.42asconhashav12
29.4229.4429.44asconxofav12
41.1441.2041.22T:xoodyakv1
41.5841.5841.75asconxofv12
41.5641.6641.66asconhashv12
60.3361.2761.70sha512
66.1466.1466.14asconhashabi32v12
71.5571.8472.38sha256
83.6683.6783.86asconhashbi32v12
99.7899.81100.17T:esch256v2
166.27166.31166.50T:esch384v2
194.36194.41194.61T:romulush
354.20355.22355.86T:photonbeetlehash256rate32v1
Cycles/byte for 8 bytes
25%50%75%hash
109.50109.50111.38asconhashav12
109.50109.62111.38asconxofav12
137.38138.25140.12T:xoodyakv1
145.88145.88147.50asconxofv12
145.75147.12147.62asconhashv12
228.88229.00230.88shake128
271.00271.00271.00asconhashabi32v12
281.50282.50283.12asconhashbi32v12
372.62374.00374.25T:esch256v2
401.75404.38411.62T:photonbeetlehash256rate32v1
450.38451.25456.12sha256
481.75489.12495.00sha512
503.50504.38505.12T:romulush
714.38715.25715.62T:esch384v2