VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of NISTLWC hash candidates on one machine: aarch64; Skylark (503f0002); 2018 Ampere eMAG 8180; 32 x 3300MHz; unstable; gcc185, supercop-20240107

[Page version: 20240726 23:45:59]

eBASH (ECRYPT Benchmarking of All Submitted Hashes) is a project to measure the performance of hash functions. This page presents an excerpt of the full eBASH benchmark results. The excerpt is for NISTLWC, specifically (starting with supercop-20221005) finalists.

Each table row lists the first quartile of many speed measurements, the median of many speed measurements, the third quartile of many speed measurements, and the name of the primitive. Measurements with large variance are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each hash function (and each implementation).


Implementation notes

Graphs: (bytes,cycles)
Cycles/byte for long messages
25%50%75%hash
4.224.224.23sha256
9.609.619.62shake128
10.7210.7210.72sha512
19.2019.2119.21asconhashav12
19.2019.2119.21asconxofav12
28.7528.7528.75asconhashv12
28.7528.7528.76asconxofv12
29.6029.6029.60T:xoodyakv1
39.7739.7739.78asconhashabi32v12
60.1160.1160.12asconhashbi32v12
74.0974.0974.09T:esch256v2
108.23108.24108.24T:esch384v2
115.03115.03115.04T:romulush
384.36384.38384.45T:photonbeetlehash256rate32v1
Cycles/byte for 4096 bytes
25%50%75%hash
4.344.364.36sha256
9.839.839.85shake128
11.1311.1311.13sha512
19.3919.3919.39asconhashav12
19.3919.3919.41asconxofav12
28.9928.9928.99asconhashv12
28.9928.9928.99asconxofv12
29.7429.7429.74T:xoodyakv1
40.1740.1740.17asconhashabi32v12
60.6860.6860.70asconhashbi32v12
74.5474.5474.56T:esch256v2
109.20109.31109.31T:esch384v2
115.89115.89115.91T:romulush
383.61383.61383.61T:photonbeetlehash256rate32v1
Cycles/byte for 1536 bytes
25%50%75%hash
4.544.594.59sha256
10.5010.5010.55shake128
11.8211.8211.82sha512
19.6819.7319.73asconhashav12
19.7319.7319.73asconxofav12
29.3529.3929.39asconhashv12
29.3529.3929.39asconxofv12
29.9329.9829.98T:xoodyakv1
40.8240.8240.87asconhashabi32v12
61.6261.6261.67asconhashbi32v12
75.2975.2975.34T:esch256v2
111.04111.08111.08T:esch384v2
117.33117.33117.33T:romulush
382.32382.37382.37T:photonbeetlehash256rate32v1
Cycles/byte for 576 bytes
25%50%75%hash
5.085.085.21sha256
11.2011.2011.33shake128
12.3712.5012.50sha512
20.4420.5720.57asconhashav12
20.4420.5720.57asconxofav12
30.3430.4730.47asconhashv12
30.3430.4730.47asconxofv12
30.4730.6030.60T:xoodyakv1
42.5842.5842.58asconhashabi32v12
64.1964.1964.19asconhashbi32v12
77.3477.3477.34T:esch256v2
115.76115.76115.89T:esch384v2
121.09121.09121.22T:romulush
378.91379.04379.04T:photonbeetlehash256rate32v1
Cycles/byte for 64 bytes
25%50%75%hash
11.7212.8912.89sha256
25.7825.7825.78sha512
25.7825.7825.78shake128
30.4730.4731.64asconhashav12
30.4730.4731.64asconxofav12
37.5038.6738.67T:xoodyakv1
43.3643.3643.36asconhashv12
43.3643.3643.36asconxofv12
64.4564.4565.62asconhashabi32v12
96.0996.0997.27asconhashbi32v12
103.12103.12104.30T:esch256v2
168.75169.92169.92T:romulush
176.95176.95176.95T:esch384v2
336.33336.33336.33T:photonbeetlehash256rate32v1
Cycles/byte for 8 bytes
25%50%75%hash
65.6265.6265.62sha256
112.50112.50112.50asconhashav12
112.50112.50112.50asconxofav12
121.88121.88131.25T:xoodyakv1
140.62150.00150.00asconhashv12
140.62150.00150.00asconxofv12
206.25206.25206.25sha512
206.25206.25206.25shake128
234.38243.75243.75asconhashabi32v12
346.88356.25356.25asconhashbi32v12
375.00384.38384.38T:photonbeetlehash256rate32v1
384.38384.38393.75T:esch256v2
440.62440.62440.62T:romulush
759.38768.75768.75T:esch384v2