VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of NISTLWC hash candidates on one machine: amd64; Goldmont (506c9); 2016 Intel Celeron J3455; 4 x 1500MHz; wooden, supercop-20240425

[Page version: 20240726 23:45:59]

eBASH (ECRYPT Benchmarking of All Submitted Hashes) is a project to measure the performance of hash functions. This page presents an excerpt of the full eBASH benchmark results. The excerpt is for NISTLWC, specifically (starting with supercop-20221005) finalists.

Each table row lists the first quartile of many speed measurements, the median of many speed measurements, the third quartile of many speed measurements, and the name of the primitive. Measurements with large variance are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each hash function (and each implementation).


Implementation notes

Graphs: (bytes,cycles)
Cycles/byte for long messages
25%50%75%hash
4.024.024.02sha256
11.8411.8511.87sha512
12.7812.7812.78shake128
16.0016.0316.07T:xoodyakv1
21.5121.5221.52asconhashav12
21.5121.5221.52asconxofav12
32.0232.0532.72asconhashv12
32.1532.1933.55asconxofv12
43.9043.9143.99asconhashabi32v12
52.9552.9653.56T:romulush
63.7463.7864.45T:esch256v2
66.7166.7667.54asconhashbi32v12
79.3279.3480.67T:esch384v2
409.13410.00411.42T:photonbeetlehash256rate32v1
Cycles/byte for 4096 bytes
25%50%75%hash
4.104.104.11sha256
12.3212.3212.34sha512
13.0513.0613.06shake128
15.8216.1316.14T:xoodyakv1
21.7221.7221.73asconxofav12
21.7221.7221.73asconhashav12
32.2932.2932.29asconhashv12
32.4132.4132.42asconxofv12
44.2244.4644.46asconhashabi32v12
53.3653.3853.39T:romulush
64.1364.1364.14T:esch256v2
67.3967.3967.39asconhashbi32v12
80.0880.0880.09T:esch384v2
406.37407.04411.76T:photonbeetlehash256rate32v1
Cycles/byte for 1536 bytes
25%50%75%hash
4.234.244.24sha256
13.1013.1113.13sha512
13.9413.9513.97shake128
16.0016.3016.33T:xoodyakv1
22.0522.0722.07asconxofav12
22.0522.0722.07asconhashav12
32.7332.7332.75asconhashv12
32.8532.8632.88asconxofv12
45.1745.3745.41asconhashabi32v12
54.1154.1254.14T:romulush
64.7964.8064.80T:esch256v2
68.5168.5168.52asconhashbi32v12
81.3581.3781.38T:esch384v2
405.05405.07405.20T:photonbeetlehash256rate32v1
Cycles/byte for 576 bytes
25%50%75%hash
4.584.584.59sha256
13.9313.9413.97sha512
14.9314.9414.96shake128
16.5816.7916.82T:xoodyakv1
22.9522.9923.01asconhashav12
22.9622.9923.01asconxofav12
33.8933.9333.95asconhashv12
34.0134.0634.08asconxofv12
47.8247.8547.90asconhashabi32v12
56.1456.1756.19T:romulush
66.5666.5766.59T:esch256v2
71.5071.5171.52asconhashbi32v12
84.8084.8084.81T:esch384v2
401.54401.59401.65T:photonbeetlehash256rate32v1
Cycles/byte for 64 bytes
25%50%75%hash
9.099.129.12sha256
22.3122.3122.34T:xoodyakv1
30.1930.2230.28sha512
34.1634.2534.31shake128
34.2834.3434.38asconhashav12
34.2834.3434.38asconxofav12
48.6648.7248.78asconhashv12
48.7848.8448.91asconxofv12
79.0679.1979.28asconhashabi32v12
81.9482.0982.34T:romulush
89.1989.3189.44T:esch256v2
109.47109.62109.78asconhashbi32v12
128.62128.81128.94T:esch384v2
356.72356.97357.44T:photonbeetlehash256rate32v1
Cycles/byte for 8 bytes
25%50%75%hash
42.0042.0042.25sha256
79.7580.0080.00T:xoodyakv1
123.00123.25123.25asconxofav12
123.25123.25123.50asconhashav12
164.25164.50164.75asconhashv12
164.50164.75165.25asconxofv12
234.25234.50234.75T:romulush
239.75240.25241.00sha512
272.25272.50272.75shake128
326.25326.75327.25asconhashabi32v12
330.00330.50330.75T:esch256v2
409.25409.75410.50asconhashbi32v12
411.50412.25412.50T:photonbeetlehash256rate32v1
553.00553.75554.50T:esch384v2