VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of public-key Diffie–Hellman secret-sharing systems on one machine: amd64; Bobcat (500f20); 2011 AMD E-450; 2 x 1650MHz; h4e450, supercop-20260330

[Page version: 20260805 22:01:51]

eBATS (ECRYPT Benchmarking of Asymmetric Systems) is a project to measure the performance of public-key systems. This page presents benchmark results collected in eBATS for public-key Diffie–Hellman secret-sharing systems:

Each table row lists the first quartile of many speed measurements (or StQ1 starting with supercop-20260214), the median of many speed measurements (or StQ2 starting with supercop-20260214), the third quartile of many speed measurements (or StQ3 starting with supercop-20260214), and the name of the primitive. Measurements with large interquartile range (or stabilized interquartile range) are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each Diffie–Hellman system and each implementation. Designers and implementors interested in submitting new Diffie–Hellman systems and new implementations of existing systems should read the call for submissions.


Test results

Graphs: old (pkcycles,pkbytes) (scycles,pkbytes)

Cycles to generate a key pair
25%50%75%system
533625443055914
T:
jacfp127i
566515706157539
T:
kumjacfp127g
591786021361365
T:
prjfp127i
610496194063200
T:
hecfp127i
761817709578485
T:
jacfp128bk
888798971490917
T:
hecfp128fkt
888978972390918
T:
hecfp128bk
891478997491150
T:
prjfp128bk
900279046590929
T:
hecfp128i
982879836598467curve25519
100128101467103042
T:
ecfp256e
106252107700109985
T:
ecfp256h
106759108767110548
T:
ecfp256s
111512113544115940
T:
ecfp256q
131187131346131667nistp256
173087175024177219
T:
gls1271
199533199577199641
T:
kumfp127g
316598316681316918
T:
kumfp128g
430962433432436514
T:
ecfp256i
515368516879520181
T:
curve2251
554936556553557901
T:
ed448goldilocks
703333730172741493
T:
sclaus1024
872172872315873557
T:
kummer
240183424037972407587
T:
ed521gs
277675227801952789849
T:
nist521gs
327934432973623318937
T:
sclaus2048
393068939609354283080
T:
claus
Cycles to compute a shared secret
25%50%75%system
201528201568201637
T:
kumfp127g
207524207579207695
T:
kumjacfp127g
242148242309242732
T:
jacfp128bk
300072300218300889
T:
prjfp128bk
305260305418306124
T:
hecfp128fkt
309513309527309670curve25519
310736310848311942
T:
hecfp128bk
325604325608325675
T:
kumfp128g
358450359521361072
T:
jacfp127i
397919400659403327
T:
gls1271
401578401815402865
T:
ecfp256e
418035418160419179
T:
ecfp256q
422200422306422803
T:
ecfp256i
433471433574434577
T:
prjfp127i
441112441176441811
T:
hecfp127i
484364484499485630
T:
ecfp256h
496124496380497705
T:
ecfp256s
508435508440509451nistp256
667257668096669041
T:
hecfp128i
743014767076774106
T:
sclaus1024
872018872409873141
T:
kummer
162861716297571630893
T:
ed448goldilocks
207920320894952106237
T:
curve2251
240076524021372421985
T:
ed521gs
277564527776612784876
T:
nist521gs
335080333696953438461
T:
sclaus2048
396036239774404290946
T:
claus