VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of NISTLWC cipher candidates on one machine: amd64; Golden Cove (906a4-40); 2022 Intel Core i3-1215U, P cores; 2 x 1600MHz; alder2,1f626960,5600000, supercop-20240909

[Page version: 20240912 11:46:31]

eBAEAD (ECRYPT Benchmarking of Authenticated Ciphers) is a project to measure the performance of authenticated ciphers. This page presents an excerpt of the full eBAEAD benchmark results. The excerpt is for NISTLWC, specifically (starting with supercop-20221005) finalists.

Each table row lists the first quartile of many speed measurements, the median of many speed measurements, the third quartile of many speed measurements, and the name of the primitive. Measurements with large variance are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each cipher and each implementation.


Test results

Graphs: (bytes,cycles)
Cycles/byte for long+0 encrypt
25%50%75%aead
0.51?0.53?0.58?T:aes128gcmv1
0.600.630.65T:aes256gcmv1
1.531.541.55aes256gcmv1
6.546.566.60ascon128av12
9.839.889.92ascon128v12
9.9810.0110.07ascon80pqv12
13.0113.0513.10ascon128abi32v12
13.4313.4713.52T:schwaemm256128v2
15.2915.3615.49T:xoodyakround3
17.6617.7517.77T:schwaemm192192v2
18.9018.9619.06T:schwaemm256256v2
19.8419.8719.93T:schwaemm128128v2
19.8719.9420.01ascon128bi32v12
24.2124.2924.48T:grain128aeadv2
38.4538.5138.54romulusn
38.9739.0439.40T:isapa128av20
39.3339.7839.88T:isapa128v20
39.8039.8539.87T:giftcofb128v1
49.8250.1850.77T:isapk128av20
54.9355.1155.17T:tinyjambu128v2
61.7461.7761.84romulusm
66.5466.6666.72T:tinyjambu192v2
66.5468.3468.71T:isapk128v20
71.1071.2271.37T:tinyjambu256v2
110.11111.25111.43T:elephant200v2
119.27119.38119.49romulust
119.84120.66121.93T:isapxv20
5786.705800.855830.13T:elephant176v2
5890.665893.465895.29T:elephant160v2
Cycles/byte for long+0 decrypt
25%50%75%aead
0.47?0.51?0.53?T:aes128gcmv1
0.560.590.62T:aes256gcmv1
1.401.421.43aes256gcmv1
6.556.626.66ascon128av12
9.669.749.80ascon80pqv12
9.769.809.83ascon128v12
13.0313.0813.11ascon128abi32v12
13.3713.4313.49T:schwaemm256128v2
15.0815.2215.38T:xoodyakround3
17.6617.7417.77T:schwaemm192192v2
18.8818.9919.83T:schwaemm256256v2
19.7719.8319.88T:schwaemm128128v2
20.0020.0820.15ascon128bi32v12
23.6523.6823.73T:grain128aeadv2
38.5738.6138.66romulusn
39.3039.5939.93T:isapa128v20
39.6339.6939.83T:isapa128av20
39.7939.8539.88T:giftcofb128v1
49.1049.6150.36T:isapk128av20
54.8154.8754.93T:tinyjambu128v2
61.6161.7661.97romulusm
66.4666.5466.61T:tinyjambu192v2
67.0968.0769.05T:isapk128v20
70.4971.0671.17T:tinyjambu256v2
110.10110.23110.36T:elephant200v2
119.28119.37119.51romulust
119.72120.14120.69T:isapxv20
5787.135802.745816.71T:elephant176v2
5892.255893.255894.62T:elephant160v2
Cycles/byte for long+0 forgery
25%50%75%aead
0.48?0.52?0.54?T:aes128gcmv1
0.570.610.62T:aes256gcmv1
1.411.411.43aes256gcmv1
6.586.606.64ascon128av12
9.769.799.83ascon128v12
9.649.799.92ascon80pqv12
13.0113.0513.10ascon128abi32v12
13.4013.4513.50T:schwaemm256128v2
15.1915.2415.34T:xoodyakround3
17.6417.7017.75T:schwaemm192192v2
18.9119.0719.14T:schwaemm256256v2
19.4419.4919.54T:isapa128v20
19.7919.8419.86T:schwaemm128128v2
19.9420.0120.11ascon128bi32v12
23.6523.6723.73T:grain128aeadv2
26.3026.3426.41T:isapa128av20
33.0333.1133.37T:isapk128av20
38.5438.6438.68romulusn
39.8039.8339.87T:giftcofb128v1
41.2441.3341.46romulust
42.2843.0843.59T:isapk128v20
54.7754.8354.96T:tinyjambu128v2
61.7661.9062.02romulusm
66.4466.5066.57T:tinyjambu192v2
70.9771.0871.19T:tinyjambu256v2
72.2772.5373.26T:isapxv20
110.54110.67110.80T:elephant200v2
5770.035788.645817.56T:elephant176v2
5891.095892.635895.57T:elephant160v2
Cycles/byte for long+long encrypt
25%50%75%aead
0.36?0.38?0.40?T:aes128gcmv1
0.40?0.43?0.46?T:aes256gcmv1
0.910.920.93aes256gcmv1
6.516.556.60ascon128av12
9.599.749.81ascon80pqv12
9.789.829.85ascon128v12
11.4311.5011.56T:xoodyakround3
13.2313.3113.39ascon128abi32v12
13.3613.4013.45T:schwaemm256128v2
17.6217.6917.80T:schwaemm192192v2
18.9319.0219.70T:schwaemm256256v2
19.8219.8419.87T:schwaemm128128v2
20.1120.1920.28ascon128bi32v12
24.3124.3324.36T:grain128aeadv2
29.3129.4829.71T:isapa128v20
30.8530.8930.91romulusn
32.4132.4732.53T:isapa128av20
39.7839.8039.84T:giftcofb128v1
41.8742.0742.37T:isapk128av20
42.4842.5242.58romulusm
45.0145.0645.12T:tinyjambu128v2
52.1652.2352.27T:tinyjambu192v2
53.7953.8653.94T:tinyjambu256v2
54.4854.9355.22T:isapk128v20
80.3580.3980.47romulust
82.8282.9783.41T:elephant200v2
96.5297.1497.42T:isapxv20
4322.064338.604345.63T:elephant176v2
4417.404419.154419.92T:elephant160v2
Cycles/byte for long+long decrypt
25%50%75%aead
0.370.370.40T:aes128gcmv1
0.39?0.41?0.44?T:aes256gcmv1
0.850.860.86aes256gcmv1
6.546.616.64ascon128av12
9.589.659.75ascon80pqv12
9.759.789.80ascon128v12
11.3811.4211.46T:xoodyakround3
13.2713.3313.36ascon128abi32v12
13.3313.3713.45T:schwaemm256128v2
17.6117.7017.72T:schwaemm192192v2
18.8518.9719.50T:schwaemm256256v2
19.7819.8219.84T:schwaemm128128v2
20.0520.1420.20ascon128bi32v12
23.8823.9224.05T:grain128aeadv2
29.3029.4329.70T:isapa128v20
30.9230.9531.00romulusn
33.0033.0533.35T:isapa128av20
39.7739.8139.86T:giftcofb128v1
41.4841.6341.83T:isapk128av20
42.4842.5742.68romulusm
44.9244.9544.99T:tinyjambu128v2
52.1552.1952.21T:tinyjambu192v2
53.5753.7653.92T:tinyjambu256v2
54.1054.8155.30T:isapk128v20
80.2880.4080.43romulust
82.6583.0783.16T:elephant200v2
96.3196.7597.16T:isapxv20
4327.114333.264349.96T:elephant176v2
4416.364418.004419.59T:elephant160v2
Cycles/byte for long+long forgery
25%50%75%aead
0.360.370.38T:aes128gcmv1
0.400.410.44T:aes256gcmv1
0.850.860.86aes256gcmv1
6.556.586.62ascon128av12
9.549.649.77ascon80pqv12
9.759.779.80ascon128v12
11.4011.4211.45T:xoodyakround3
13.3113.3513.39T:schwaemm256128v2
13.3113.3713.39ascon128abi32v12
17.6517.6917.73T:schwaemm192192v2
18.8818.9919.04T:schwaemm256256v2
19.4319.4819.52T:isapa128v20
19.8019.8319.85T:schwaemm128128v2
20.0320.1220.16ascon128bi32v12
23.9724.0424.06T:grain128aeadv2
26.1326.1626.33T:isapa128av20
30.8930.9330.98romulusn
33.2733.6133.90T:isapk128av20
39.8039.8339.84T:giftcofb128v1
41.3241.3641.43romulust
41.7742.1242.55T:isapk128v20
42.5542.5942.65romulusm
44.9244.9544.99T:tinyjambu128v2
52.0352.0652.13T:tinyjambu192v2
53.5853.6853.75T:tinyjambu256v2
72.2972.5173.38T:isapxv20
82.8582.9683.23T:elephant200v2
4329.414341.094350.21T:elephant176v2
4416.914418.314419.34T:elephant160v2
Cycles/byte for 0+long encrypt
25%50%75%aead
0.23?0.24?0.27?T:aes128gcmv1
0.22?0.24?0.27?T:aes256gcmv1
0.29?0.31?0.33?aes256gcmv1
6.376.476.56ascon128av12
7.627.687.70T:xoodyakround3
9.599.6510.31ascon80pqv12
9.729.749.77ascon128v12
13.2813.3213.38T:schwaemm256128v2
13.4013.4913.63ascon128abi32v12
17.5817.6617.71T:schwaemm192192v2
19.4419.5019.55T:isapa128v20
19.7719.8119.85T:schwaemm128128v2
18.8120.1620.53T:schwaemm256256v2
20.1620.2420.45ascon128bi32v12
23.2123.2623.29romulusn
23.2423.2823.35romulusm
24.1924.2424.31T:grain128aeadv2
26.0526.1326.36T:isapa128av20
33.1933.3333.61T:isapk128av20
34.7934.8634.92T:tinyjambu128v2
36.3236.3836.47T:tinyjambu256v2
37.6237.7237.80T:tinyjambu192v2
39.7139.7739.87T:giftcofb128v1
41.2541.3041.35romulust
40.9241.5542.41T:isapk128v20
55.7955.8856.35T:elephant200v2
73.2073.9474.86T:isapxv20
2859.702877.282880.99T:elephant176v2
2942.982944.332945.42T:elephant160v2
Cycles/byte for 0+long decrypt
25%50%75%aead
0.21?0.22?0.24?T:aes256gcmv1
0.210.230.23T:aes128gcmv1
0.28?0.30?0.33?aes256gcmv1
6.486.566.62ascon128av12
7.587.677.70T:xoodyakround3
9.519.649.68ascon80pqv12
9.679.719.76ascon128v12
13.2413.2913.33T:schwaemm256128v2
13.5513.6413.72ascon128abi32v12
17.6017.7017.77T:schwaemm192192v2
18.7718.8519.77T:schwaemm256256v2
19.4019.4819.55T:isapa128v20
19.7419.8019.86T:schwaemm128128v2
19.9820.1120.15ascon128bi32v12
23.2423.3023.35romulusn
23.2423.3223.41romulusm
24.1024.3324.38T:grain128aeadv2
26.2926.3526.44T:isapa128av20
33.3233.8433.92T:isapk128av20
34.8134.9435.03T:tinyjambu128v2
36.3036.3636.44T:tinyjambu256v2
37.5037.5737.68T:tinyjambu192v2
39.6839.7539.83T:giftcofb128v1
41.2541.3741.45romulust
41.2542.0642.87T:isapk128v20
55.3755.6755.74T:elephant200v2
72.1772.3673.00T:isapxv20
2852.282865.992879.11T:elephant176v2
2942.402942.942944.73T:elephant160v2
Cycles/byte for 0+long forgery
25%50%75%aead
0.210.220.23T:aes128gcmv1
0.21?0.23?0.24?T:aes256gcmv1
0.300.310.32aes256gcmv1
6.426.526.58ascon128av12
7.607.687.73T:xoodyakround3
9.519.599.79ascon80pqv12
9.709.749.78ascon128v12
13.2513.2913.32T:schwaemm256128v2
13.5213.5713.67ascon128abi32v12
17.6217.7417.79T:schwaemm192192v2
19.4419.5219.57T:isapa128v20
19.7719.8119.84T:schwaemm128128v2
20.0820.1320.20ascon128bi32v12
18.8420.2120.30T:schwaemm256256v2
23.2123.2723.31romulusn
23.2223.2823.34romulusm
24.0324.0724.15T:grain128aeadv2
26.2326.3626.45T:isapa128av20
33.1433.2733.93T:isapk128av20
34.8034.8835.11T:tinyjambu128v2
36.3336.3937.08T:tinyjambu256v2
37.5437.5937.67T:tinyjambu192v2
39.7639.8039.84T:giftcofb128v1
41.2341.3141.41romulust
40.8841.7542.14T:isapk128v20
55.7555.8056.19T:elephant200v2
72.5273.1273.44T:isapxv20
2846.442851.362859.79T:elephant176v2
2941.262943.962945.35T:elephant160v2
Cycles/byte for 1536+1536 encrypt
25%50%75%aead
0.720.730.76T:aes128gcmv1
0.780.790.82T:aes256gcmv1
1.061.061.06aes256gcmv1
6.676.726.74ascon128av12
9.769.789.88ascon80pqv12
9.919.939.96ascon128v12
11.6011.6511.67T:xoodyakround3
13.5913.6213.66ascon128abi32v12
13.7613.8013.84T:schwaemm256128v2
18.0818.1518.19T:schwaemm192192v2
19.5119.5520.14T:schwaemm256256v2
20.0920.1020.13T:schwaemm128128v2
20.4220.5120.60ascon128bi32v12
24.6024.6324.66T:grain128aeadv2
31.1531.1731.18romulusn
36.1536.1836.22T:isapa128av20
40.1540.1740.19T:giftcofb128v1
42.8342.8742.93romulusm
42.7442.9142.98T:isapa128v20
45.4945.5145.54T:tinyjambu128v2
46.9447.3047.57T:isapk128av20
52.6452.7052.77T:tinyjambu192v2
54.3254.3654.41T:tinyjambu256v2
81.5581.6281.66romulust
84.4384.5085.29T:elephant200v2
94.3194.6295.01T:isapk128v20
159.57160.33160.54T:isapxv20
4360.524377.144384.30T:elephant176v2
4467.424467.804469.13T:elephant160v2
Cycles/byte for 1536+1536 decrypt
25%50%75%aead
0.720.720.75T:aes128gcmv1
0.780.780.80T:aes256gcmv1
1.001.011.01aes256gcmv1
6.696.736.76ascon128av12
9.799.859.90ascon80pqv12
9.909.919.95ascon128v12
11.5311.5611.60T:xoodyakround3
13.5713.6213.66ascon128abi32v12
13.6913.7213.77T:schwaemm256128v2
18.0818.1118.15T:schwaemm192192v2
19.5219.5419.58T:schwaemm256256v2
20.0620.0820.11T:schwaemm128128v2
20.3020.3520.40ascon128bi32v12
24.2724.3324.40T:grain128aeadv2
31.2231.2431.27romulusn
36.4036.6436.71T:isapa128av20
40.1140.1440.16T:giftcofb128v1
42.8042.9443.00T:isapa128v20
42.9242.9543.02romulusm
45.3645.3845.44T:tinyjambu128v2
46.5046.8247.16T:isapk128av20
52.6552.6852.77T:tinyjambu192v2
54.0854.2954.38T:tinyjambu256v2
81.5381.6081.65romulust
84.4784.9985.22T:elephant200v2
93.5794.0694.67T:isapk128v20
159.81159.99160.65T:isapxv20
4364.594375.644387.92T:elephant176v2
4466.384467.554469.35T:elephant160v2
Cycles/byte for 1536+1536 forgery
25%50%75%aead
0.730.730.73T:aes128gcmv1
0.780.790.80T:aes256gcmv1
1.001.011.01aes256gcmv1
6.676.746.77ascon128av12
9.819.869.91ascon80pqv12
9.899.919.93ascon128v12
11.5511.6011.62T:xoodyakround3
13.5913.6113.67ascon128abi32v12
13.7113.7313.79T:schwaemm256128v2
18.0718.0918.13T:schwaemm192192v2
19.5619.6120.72T:schwaemm256256v2
20.0720.0820.10T:schwaemm128128v2
20.3520.4020.44ascon128bi32v12
24.2424.2624.29T:grain128aeadv2
26.2326.2626.28T:isapa128v20
28.1128.3128.37T:isapa128av20
31.2331.2531.28romulusn
36.3436.6136.87T:isapk128av20
40.1140.1540.17T:giftcofb128v1
42.5242.5642.63romulust
42.9143.0043.04romulusm
45.3645.3845.41T:tinyjambu128v2
52.5952.6852.77T:tinyjambu192v2
54.2854.3654.41T:tinyjambu256v2
62.3562.7162.84T:isapk128v20
84.9385.0485.14T:elephant200v2
104.80105.07105.18T:isapxv20
4375.854381.874394.43T:elephant176v2
4466.644467.714468.41T:elephant160v2
Cycles/byte for 64+64 encrypt
25%50%75%aead
5.605.705.77aes256gcmv1
8.959.089.25T:aes128gcmv1
9.239.529.64T:aes256gcmv1
10.4210.4610.92ascon128av12
12.9113.0513.18ascon128v12
12.9213.0813.23ascon80pqv12
16.7317.2317.84T:xoodyakround3
19.9820.2220.62ascon128abi32v12
22.4222.7723.04T:schwaemm256128v2
25.5425.6225.80T:schwaemm128128v2
27.2027.3827.72ascon128bi32v12
28.9529.4230.09T:schwaemm192192v2
30.9031.3933.19T:schwaemm256256v2
32.4332.6632.80T:grain128aeadv2
37.4537.6537.78romulusn
47.3047.4347.66T:giftcofb128v1
50.0550.2850.49romulusm
55.6456.2356.65T:tinyjambu128v2
64.3564.6065.28T:tinyjambu192v2
65.8666.1666.39T:tinyjambu256v2
108.11108.45108.60romulust
118.73119.34120.15T:elephant200v2
119.41119.85120.16T:isapa128av20
150.91151.36151.86T:isapk128av20
349.30349.92350.38T:isapa128v20
989.16993.47997.95T:isapk128v20
1595.751603.281607.46T:isapxv20
5408.155452.455461.91T:elephant176v2
5979.295981.025983.59T:elephant160v2
Cycles/byte for 64+64 decrypt
25%50%75%aead
5.755.805.90aes256gcmv1
8.989.239.37T:aes128gcmv1
9.279.419.94T:aes256gcmv1
10.2010.2810.53ascon128av12
12.9512.9813.16ascon128v12
12.9513.0713.15ascon80pqv12
16.8117.0717.59T:xoodyakround3
20.1320.4420.59ascon128abi32v12
22.2722.6123.23T:schwaemm256128v2
25.4525.6325.95T:schwaemm128128v2
27.1027.3727.76ascon128bi32v12
29.2929.4730.11T:schwaemm192192v2
30.9332.0533.38T:schwaemm256256v2
32.5132.7332.84T:grain128aeadv2
37.9838.1238.28romulusn
47.5047.6347.73T:giftcofb128v1
51.9852.2352.45romulusm
56.0356.1856.68T:tinyjambu128v2
64.3064.4265.08T:tinyjambu192v2
65.7466.1266.84T:tinyjambu256v2
108.24108.66109.15romulust
119.37119.53119.80T:isapa128av20
119.84119.92120.41T:elephant200v2
150.84151.24151.61T:isapk128av20
349.35349.76350.50T:isapa128v20
985.03990.481000.34T:isapk128v20
1600.581603.411604.88T:isapxv20
5407.025442.415462.88T:elephant176v2
5978.285982.365985.12T:elephant160v2
Cycles/byte for 64+64 forgery
25%50%75%aead
5.775.835.86aes256gcmv1
9.029.129.20T:aes128gcmv1
9.279.469.62T:aes256gcmv1
10.0910.2610.42ascon128av12
12.8812.9813.17ascon128v12
12.8013.0613.16ascon80pqv12
16.7117.3818.01T:xoodyakround3
20.2220.3820.60ascon128abi32v12
22.2822.6722.77T:schwaemm256128v2
25.4625.5425.77T:schwaemm128128v2
27.4127.4827.70ascon128bi32v12
29.2329.5229.74T:schwaemm192192v2
32.4132.6632.75T:grain128aeadv2
31.0532.7032.88T:schwaemm256256v2
38.0538.1438.22romulusn
47.4447.5247.68T:giftcofb128v1
51.9052.1252.39romulusm
55.6955.9756.33T:tinyjambu128v2
64.0064.4864.72T:tinyjambu192v2
65.6765.8866.86T:tinyjambu256v2
68.9869.3469.56romulust
73.4573.9474.27T:isapa128av20
98.5699.1399.27T:isapk128av20
119.45119.81120.35T:elephant200v2
181.62182.26182.56T:isapa128v20
516.10524.48527.46T:isapk128v20
836.59837.36838.78T:isapxv20
5404.455431.095456.71T:elephant176v2
5975.885978.375982.18T:elephant160v2