VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of NISTLWC cipher candidates on one machine: amd64; Raptor Cove (b06a2); 2023 Intel Core i7-13700H, P cores; 6 x 4800MHz; raptor, supercop-20231107

[Page version: 20240726 23:46:23]

eBAEAD (ECRYPT Benchmarking of Authenticated Ciphers) is a project to measure the performance of authenticated ciphers. This page presents an excerpt of the full eBAEAD benchmark results. The excerpt is for NISTLWC, specifically (starting with supercop-20221005) finalists.

Each table row lists the first quartile of many speed measurements, the median of many speed measurements, the third quartile of many speed measurements, and the name of the primitive. Measurements with large variance are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each cipher and each implementation.


Implementation notes

Graphs: (bytes,cycles)
Cycles/byte for long+0 encrypt
25%50%75%aead
1.411.421.43T:aes128gcmv1
1.461.541.56aes256gcmv1
6.456.516.59ascon128av12
9.829.879.90ascon80pqv12
9.959.9910.02ascon128v12
12.4012.4412.54T:schwaemm256128v2
12.8513.0213.18ascon128abi32v12
13.2113.2513.29T:xoodyakround3
16.3916.4816.55T:schwaemm192192v2
17.2817.3717.43T:schwaemm256256v2
18.2218.2718.30T:schwaemm128128v2
19.0919.1219.18ascon128bi32v12
23.1523.1923.24T:grain128aeadv2
33.0233.0733.12T:giftcofb128v1
38.7338.7538.81romulusn
39.2939.4039.58T:isapa128v20
39.4139.4939.54T:isapa128av20
47.4548.0048.14T:isapk128av20
62.1762.2262.28romulusm
64.4664.8265.24T:isapk128v20
65.4665.6165.70T:tinyjambu128v2
77.9978.0478.14T:tinyjambu192v2
83.8583.8984.03T:tinyjambu256v2
129.64129.77129.86romulust
161.35161.93162.57T:isapxv20
165.95167.86168.63T:elephant200v2
5699.425706.575732.88T:elephant176v2
5894.335897.405908.06T:elephant160v2
Cycles/byte for long+0 decrypt
25%50%75%aead
1.201.211.25T:aes128gcmv1
1.401.411.42aes256gcmv1
6.416.466.47ascon128av12
9.599.619.63ascon80pqv12
9.679.729.89ascon128v12
12.4412.4812.56T:schwaemm256128v2
13.0513.1913.31ascon128abi32v12
13.1613.2313.26T:xoodyakround3
16.4016.4816.51T:schwaemm192192v2
17.2717.3617.43T:schwaemm256256v2
18.2418.2718.34T:schwaemm128128v2
19.1819.2619.31ascon128bi32v12
22.5122.5322.57T:grain128aeadv2
33.0633.0833.13T:giftcofb128v1
38.8038.8538.94romulusn
39.2239.3239.48T:isapa128v20
39.4039.4739.57T:isapa128av20
47.3947.7248.06T:isapk128av20
62.1562.2862.35romulusm
64.1864.8465.65T:isapk128v20
65.4265.4665.49T:tinyjambu128v2
77.8477.9377.96T:tinyjambu192v2
84.0184.0784.10T:tinyjambu256v2
129.64129.75130.19romulust
163.38163.93164.52T:isapxv20
168.55169.18169.92T:elephant200v2
5697.515706.965734.97T:elephant176v2
5890.705895.725902.89T:elephant160v2
Cycles/byte for long+0 forgery
25%50%75%aead
1.191.201.26T:aes128gcmv1
1.401.411.42aes256gcmv1
6.436.456.50ascon128av12
9.569.599.65ascon80pqv12
9.669.819.91ascon128v12
12.4512.5112.59T:schwaemm256128v2
13.0713.1613.19ascon128abi32v12
13.1113.1813.26T:xoodyakround3
16.3316.4316.47T:schwaemm192192v2
17.3017.3617.40T:schwaemm256256v2
18.2518.2818.33T:schwaemm128128v2
19.0919.1419.19ascon128bi32v12
19.4819.6119.72T:isapa128v20
22.5022.5522.58T:grain128aeadv2
26.2826.3826.48T:isapa128av20
31.8032.3732.41T:isapk128av20
33.0733.1633.23T:giftcofb128v1
38.8038.8538.92romulusn
40.5440.5840.68T:isapk128v20
44.6044.6844.87romulust
62.1962.2562.32romulusm
65.4165.4465.75T:tinyjambu128v2
77.8877.9377.98T:tinyjambu192v2
83.8483.8883.94T:tinyjambu256v2
98.7698.8998.96T:isapxv20
167.61168.41169.03T:elephant200v2
5698.695704.355714.10T:elephant176v2
5891.855894.495896.83T:elephant160v2
Cycles/byte for long+long encrypt
25%50%75%aead
0.850.860.87T:aes128gcmv1
0.920.930.93aes256gcmv1
6.476.496.53ascon128av12
9.769.799.82ascon80pqv12
9.749.849.90ascon128v12
10.1710.2010.24T:xoodyakround3
12.3212.3612.39T:schwaemm256128v2
13.3113.3413.37ascon128abi32v12
16.3416.4416.46T:schwaemm192192v2
17.2617.3317.40T:schwaemm256256v2
18.2018.2318.26T:schwaemm128128v2
19.2519.2819.32ascon128bi32v12
23.0623.1523.19T:grain128aeadv2
29.4229.5029.58T:isapa128v20
31.1031.1331.16romulusn
32.7232.7732.82T:isapa128av20
32.9432.9833.02T:giftcofb128v1
40.3440.5940.85T:isapk128av20
42.8142.8742.93romulusm
52.3352.9053.16T:isapk128v20
53.5653.6253.66T:tinyjambu128v2
61.0261.0461.11T:tinyjambu192v2
63.3163.3363.48T:tinyjambu256v2
87.0387.1487.19romulust
124.07124.41126.80T:elephant200v2
128.93130.09130.44T:isapxv20
4258.614268.094273.79T:elephant176v2
4420.224423.264428.60T:elephant160v2
Cycles/byte for long+long decrypt
25%50%75%aead
0.750.770.78T:aes128gcmv1
0.850.860.86aes256gcmv1
6.436.456.46ascon128av12
9.709.739.75ascon80pqv12
9.729.799.82ascon128v12
10.1210.1510.18T:xoodyakround3
12.3312.3712.42T:schwaemm256128v2
13.1513.2513.30ascon128abi32v12
16.3216.3916.44T:schwaemm192192v2
17.2117.2617.38T:schwaemm256256v2
18.1818.2118.23T:schwaemm128128v2
19.2419.2819.31ascon128bi32v12
22.8022.8622.88T:grain128aeadv2
29.4429.5229.60T:isapa128v20
31.1231.1431.18romulusn
32.7132.7432.81T:isapa128av20
33.0033.0633.10T:giftcofb128v1
40.1940.4540.65T:isapk128av20
42.8842.9443.08romulusm
52.3752.8353.08T:isapk128v20
53.4853.5153.53T:tinyjambu128v2
60.9660.9861.01T:tinyjambu192v2
63.4063.4263.45T:tinyjambu256v2
86.9787.0387.14romulust
123.70124.46125.42T:elephant200v2
131.15131.39132.01T:isapxv20
4260.174268.674273.65T:elephant176v2
4418.164423.964432.43T:elephant160v2
Cycles/byte for long+long forgery
25%50%75%aead
0.750.750.77T:aes128gcmv1
0.850.850.86aes256gcmv1
6.446.456.46ascon128av12
9.709.749.76ascon80pqv12
9.709.779.82ascon128v12
10.1410.1910.22T:xoodyakround3
12.3412.3712.43T:schwaemm256128v2
13.2313.2813.32ascon128abi32v12
16.3316.3816.44T:schwaemm192192v2
17.2717.3417.43T:schwaemm256256v2
18.2118.2318.27T:schwaemm128128v2
19.2619.2919.33ascon128bi32v12
19.5419.5819.66T:isapa128v20
22.7722.8022.82T:grain128aeadv2
26.1426.2026.25T:isapa128av20
31.1231.1531.17romulusn
32.2232.3232.68T:isapk128av20
32.9833.0133.03T:giftcofb128v1
40.5340.5940.71T:isapk128v20
42.8642.8943.00romulusm
44.5144.5844.67romulust
53.4953.5453.62T:tinyjambu128v2
60.9660.9861.10T:tinyjambu192v2
63.3163.3463.44T:tinyjambu256v2
98.7898.8698.95T:isapxv20
125.10125.80126.87T:elephant200v2
4261.054266.314275.95T:elephant176v2
4421.384427.534435.52T:elephant160v2
Cycles/byte for 0+long encrypt
25%50%75%aead
0.290.310.32T:aes128gcmv1
0.28?0.31?0.32?aes256gcmv1
6.436.456.47ascon128av12
7.077.167.20T:xoodyakround3
9.689.729.75ascon80pqv12
9.739.769.78ascon128v12
12.1812.2512.31T:schwaemm256128v2
13.3113.3413.38ascon128abi32v12
16.2616.3216.39T:schwaemm192192v2
17.1717.3317.37T:schwaemm256256v2
18.1518.1718.20T:schwaemm128128v2
19.3719.4919.87ascon128bi32v12
19.5619.6219.73T:isapa128v20
22.9723.0823.12T:grain128aeadv2
23.4523.4923.54romulusn
23.4623.5023.57romulusm
26.0226.1326.32T:isapa128av20
32.2632.3532.46T:isapk128av20
32.9432.9733.08T:giftcofb128v1
40.3640.4640.53T:isapk128v20
41.3741.4141.46T:tinyjambu128v2
42.5842.6042.63T:tinyjambu256v2
43.8343.8643.95T:tinyjambu192v2
44.4544.5444.62romulust
81.7481.8783.27T:elephant200v2
96.6398.29100.07T:isapxv20
2816.572817.822827.75T:elephant176v2
2945.412949.742954.31T:elephant160v2
Cycles/byte for 0+long decrypt
25%50%75%aead
0.290.300.32T:aes128gcmv1
0.300.310.33aes256gcmv1
6.446.466.49ascon128av12
7.117.177.21T:xoodyakround3
9.749.769.79ascon128v12
9.729.799.83ascon80pqv12
12.1812.2512.30T:schwaemm256128v2
13.3213.3813.41ascon128abi32v12
16.2516.3416.54T:schwaemm192192v2
17.2017.2617.36T:schwaemm256256v2
18.1218.1618.21T:schwaemm128128v2
19.3219.3819.50ascon128bi32v12
19.5919.6619.73T:isapa128v20
23.0323.1223.18T:grain128aeadv2
23.4523.4923.74romulusm
23.4523.5023.53romulusn
25.9926.0326.11T:isapa128av20
32.2232.3032.41T:isapk128av20
32.9032.9533.00T:giftcofb128v1
40.4140.5040.54T:isapk128v20
41.3541.3941.42T:tinyjambu128v2
42.7342.7842.82T:tinyjambu256v2
43.8343.8743.92T:tinyjambu192v2
44.4644.5244.73romulust
83.2783.7484.15T:elephant200v2
98.6998.8198.93T:isapxv20
2815.732820.052828.84T:elephant176v2
2947.532949.052955.53T:elephant160v2
Cycles/byte for 0+long forgery
25%50%75%aead
0.300.310.32T:aes128gcmv1
0.300.310.33aes256gcmv1
6.446.466.49ascon128av12
7.097.147.21T:xoodyakround3
9.769.789.81ascon128v12
9.749.799.82ascon80pqv12
12.2112.2612.30T:schwaemm256128v2
13.2813.3313.40ascon128abi32v12
16.2816.3416.36T:schwaemm192192v2
17.2017.3217.39T:schwaemm256256v2
18.1218.1518.18T:schwaemm128128v2
19.3619.4019.49ascon128bi32v12
19.5119.5819.67T:isapa128v20
22.9723.0323.09T:grain128aeadv2
23.4323.4923.52romulusn
23.4123.5023.57romulusm
25.9926.0526.13T:isapa128av20
32.2832.3632.43T:isapk128av20
32.9433.0333.09T:giftcofb128v1
40.4140.5040.56T:isapk128v20
41.3441.3841.46T:tinyjambu128v2
42.5642.5942.68T:tinyjambu256v2
43.8943.9944.44T:tinyjambu192v2
44.4444.5344.59romulust
81.3883.5983.84T:elephant200v2
98.8398.9299.05T:isapxv20
2818.372823.732832.34T:elephant176v2
2946.152948.332954.58T:elephant160v2
Cycles/byte for 1536+1536 encrypt
25%50%75%aead
0.970.980.98T:aes128gcmv1
1.051.051.06aes256gcmv1
6.646.656.66ascon128av12
9.919.939.97ascon80pqv12
9.869.969.99ascon128v12
10.2910.3110.34T:xoodyakround3
12.7412.7812.82T:schwaemm256128v2
13.5913.6413.70ascon128abi32v12
16.8016.8116.84T:schwaemm192192v2
17.8017.8417.86T:schwaemm256256v2
18.4318.4518.48T:schwaemm128128v2
19.6119.6419.67ascon128bi32v12
23.4723.4923.53T:grain128aeadv2
31.3931.4231.44romulusn
33.2333.3033.32T:giftcofb128v1
34.7734.8434.87T:isapa128av20
42.8842.9543.01T:isapa128v20
43.1743.2143.26romulusm
45.6745.8345.85T:isapk128av20
54.1054.1254.21T:tinyjambu128v2
61.5961.6261.68T:tinyjambu192v2
63.8663.8763.88T:tinyjambu256v2
88.3188.3888.49romulust
91.4691.6891.75T:isapk128v20
127.55128.33129.05T:elephant200v2
217.16217.28217.45T:isapxv20
4291.274302.564315.01T:elephant176v2
4469.054471.184473.27T:elephant160v2
Cycles/byte for 1536+1536 decrypt
25%50%75%aead
0.880.890.91T:aes128gcmv1
0.990.991.00aes256gcmv1
6.606.626.64ascon128av12
9.829.859.89ascon80pqv12
9.879.939.99ascon128v12
10.2410.2610.29T:xoodyakround3
12.7312.7712.80T:schwaemm256128v2
13.5713.5913.63ascon128abi32v12
16.7116.7616.80T:schwaemm192192v2
17.7317.8017.85T:schwaemm256256v2
18.4418.4518.50T:schwaemm128128v2
19.5919.6319.66ascon128bi32v12
23.1523.1823.20T:grain128aeadv2
31.4331.4731.53romulusn
33.2733.3133.41T:giftcofb128v1
34.7834.8334.87T:isapa128av20
42.8542.9142.95T:isapa128v20
43.2643.3143.35romulusm
45.7345.7945.84T:isapk128av20
54.0154.0254.03T:tinyjambu128v2
61.4861.5061.54T:tinyjambu192v2
63.9763.9864.03T:tinyjambu256v2
88.3488.4288.45romulust
91.4091.4791.68T:isapk128v20
126.35128.07128.39T:elephant200v2
219.75219.79219.96T:isapxv20
4292.034298.944304.51T:elephant176v2
4469.264470.324472.80T:elephant160v2
Cycles/byte for 1536+1536 forgery
25%50%75%aead
0.880.890.91T:aes128gcmv1
0.990.991.00aes256gcmv1
6.596.616.63ascon128av12
9.859.879.88ascon80pqv12
9.859.889.94ascon128v12
10.2510.2810.30T:xoodyakround3
12.7112.7312.77T:schwaemm256128v2
13.5513.5913.61ascon128abi32v12
16.7516.8016.87T:schwaemm192192v2
17.7417.7817.80T:schwaemm256256v2
18.4318.4618.49T:schwaemm128128v2
19.5919.6219.65ascon128bi32v12
23.1123.1523.18T:grain128aeadv2
26.3726.4026.51T:isapa128v20
27.3327.3727.41T:isapa128av20
31.4631.4931.54romulusn
33.2633.3333.37T:giftcofb128v1
35.6335.7735.85T:isapk128av20
43.2343.2643.29romulusm
45.8545.8845.92romulust
53.9954.0154.12T:tinyjambu128v2
61.0961.1161.13T:isapk128v20
61.5061.5161.65T:tinyjambu192v2
63.8763.8963.90T:tinyjambu256v2
126.74127.73127.93T:elephant200v2
144.06144.50144.64T:isapxv20
4291.924294.454304.38T:elephant176v2
4468.604472.024482.56T:elephant160v2
Cycles/byte for 64+64 encrypt
25%50%75%aead
5.645.695.80T:aes128gcmv1
5.895.956.13aes256gcmv1
9.8910.0710.27ascon128av12
12.8812.9513.10ascon128v12
12.9413.0613.30ascon80pqv12
14.7714.8915.29T:xoodyakround3
20.3420.4820.79ascon128abi32v12
20.6921.0221.43T:schwaemm256128v2
23.6623.7724.24T:schwaemm128128v2
26.5026.7627.12ascon128bi32v12
27.2327.4827.96T:schwaemm192192v2
28.4128.8028.95T:schwaemm256256v2
31.2631.4031.58T:grain128aeadv2
37.7738.0138.25romulusn
39.4639.5539.66T:giftcofb128v1
50.4550.5950.87romulusm
65.4865.8266.73T:tinyjambu128v2
74.0374.2674.53T:tinyjambu192v2
76.8777.2377.69T:tinyjambu256v2
81.8081.9882.29T:isapa128av20
117.78117.91118.33romulust
157.30157.98161.16T:isapk128av20
176.65180.67181.79T:elephant200v2
350.02350.90352.19T:isapa128v20
967.95968.98979.95T:isapk128v20
2191.302192.262193.93T:isapxv20
5336.235339.545350.16T:elephant176v2
5977.365979.616012.68T:elephant160v2
Cycles/byte for 64+64 decrypt
25%50%75%aead
5.425.485.55T:aes128gcmv1
5.475.515.55aes256gcmv1
9.9110.0010.20ascon128av12
12.8913.0013.09ascon128v12
12.9313.0913.39ascon80pqv12
14.7014.8614.98T:xoodyakround3
20.2320.5220.73ascon128abi32v12
20.7120.9921.63T:schwaemm256128v2
23.7123.7724.21T:schwaemm128128v2
26.6226.8327.08ascon128bi32v12
27.2927.4627.83T:schwaemm192192v2
28.0628.7729.40T:schwaemm256256v2
31.2131.2931.38T:grain128aeadv2
38.3938.4938.63romulusn
39.6039.7640.00T:giftcofb128v1
52.6052.8253.02romulusm
65.6265.9266.39T:tinyjambu128v2
74.1674.4274.71T:tinyjambu192v2
76.5876.9177.26T:tinyjambu256v2
81.8482.0982.35T:isapa128av20
117.65118.44119.05romulust
157.28157.71158.59T:isapk128av20
176.30179.95180.47T:elephant200v2
350.55351.49352.10T:isapa128v20
967.96969.08976.85T:isapk128v20
2225.232228.522229.22T:isapxv20
5334.095336.465343.90T:elephant176v2
5976.435978.796009.52T:elephant160v2
Cycles/byte for 64+64 forgery
25%50%75%aead
5.415.455.53T:aes128gcmv1
5.455.545.66aes256gcmv1
9.919.9910.05ascon128av12
12.8212.8913.08ascon128v12
12.9313.0613.25ascon80pqv12
14.7714.8715.27T:xoodyakround3
20.3420.5820.74ascon128abi32v12
20.5221.1221.27T:schwaemm256128v2
23.6823.8324.02T:schwaemm128128v2
26.7927.0027.12ascon128bi32v12
27.3027.5728.02T:schwaemm192192v2
27.9828.1728.58T:schwaemm256256v2
31.1431.2331.38T:grain128aeadv2
38.3438.4738.73romulusn
39.7439.7739.90T:giftcofb128v1
52.5552.6852.87romulusm
54.2654.5954.97T:isapa128av20
65.6265.9166.54T:tinyjambu128v2
74.2374.3874.68T:tinyjambu192v2
74.6375.2775.57romulust
76.7277.1277.32T:tinyjambu256v2
101.86102.11102.91T:isapk128av20
177.53178.39179.03T:elephant200v2
182.99183.29183.97T:isapa128v20
516.41516.77517.31T:isapk128v20
1165.321166.021166.77T:isapxv20
5340.135372.215467.98T:elephant176v2
5973.485977.235979.30T:elephant160v2