VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of NISTLWC hash candidates on one machine: amd64; K10 45nm (100f63); 2010 AMD Athlon II Neo K125; 1 x 1700MHz; h3neo, supercop-20240909

[Page version: 20241021 10:28:05]

eBASH (ECRYPT Benchmarking of All Submitted Hashes) is a project to measure the performance of hash functions. This page presents an excerpt of the full eBASH benchmark results. The excerpt is for NISTLWC, specifically (starting with supercop-20221005) finalists.

Each table row lists the first quartile of many speed measurements, the median of many speed measurements, the third quartile of many speed measurements, and the name of the primitive. Measurements with large variance are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each hash function (and each implementation).


Test results

Graphs: (bytes,cycles)
Cycles/byte for long messages
25%50%75%hash
9.319.339.33sha512
10.4510.4510.45shake128
14.6614.6814.74sha256
17.9617.9617.96asconhashav12
17.9617.9617.96asconxofav12
26.6926.6926.69asconhashv12
26.6926.6926.69asconxofv12
31.1231.1831.33T:xoodyakv1
36.8836.8836.90asconhashabi32v12
55.3955.4055.42asconhashbi32v12
70.3770.4170.60T:esch256v2
101.69101.77102.05T:esch384v2
131.49131.52131.63T:romulush
405.71405.89406.54T:photonbeetlehash256rate32v1
Cycles/byte for 4096 bytes
25%50%75%hash
10.2410.2410.27sha512
10.6910.6910.70shake128
15.5415.5515.61sha256
18.1418.1418.15asconhashav12
18.1418.1418.15asconxofav12
26.9326.9326.93asconxofv12
26.9326.9326.93asconhashv12
31.2831.2831.47T:xoodyakv1
37.3437.3437.34asconhashabi32v12
55.8455.8555.86asconhashbi32v12
70.8570.8571.04T:esch256v2
102.71102.77103.01T:esch384v2
132.44132.46132.49T:romulush
405.02405.11405.66T:photonbeetlehash256rate32v1
Cycles/byte for 1536 bytes
25%50%75%hash
11.4311.4611.47shake128
11.7711.7811.85sha512
17.0117.0417.05sha256
18.4518.4518.46asconhashav12
18.4518.4518.46asconxofav12
27.3227.3227.33asconxofv12
27.3327.3327.34asconhashv12
31.5431.5431.54T:xoodyakv1
38.1138.1138.11asconhashabi32v12
56.5856.5956.59asconhashbi32v12
71.6271.6371.81T:esch256v2
104.39104.45104.70T:esch384v2
134.07134.10134.11T:romulush
403.80403.85404.30T:photonbeetlehash256rate32v1
Cycles/byte for 576 bytes
25%50%75%hash
12.3312.3512.37shake128
14.8714.9115.00sha512
19.2719.2719.29asconhashav12
19.2719.2719.29asconxofav12
20.9521.0021.01sha256
28.3828.3828.39asconxofv12
28.3928.4028.42asconhashv12
32.3632.3632.36T:xoodyakv1
40.1640.1640.16asconhashabi32v12
58.5758.5758.58asconhashbi32v12
73.6473.7073.83T:esch256v2
108.86108.91109.18T:esch384v2
138.44138.47138.54T:romulush
400.19400.22400.69T:photonbeetlehash256rate32v1
Cycles/byte for 64 bytes
25%50%75%hash
28.6928.7329.00shake128
29.4229.4229.42asconhashav12
29.4229.4229.44asconxofav12
41.1741.2241.22T:xoodyakv1
41.5541.5841.59asconxofv12
41.5941.6241.66asconhashv12
58.1258.3359.16sha512
66.1466.1466.34asconhashabi32v12
70.0571.0271.25sha256
83.6783.6984.27asconhashbi32v12
99.5099.6999.92T:esch256v2
166.14166.25166.62T:esch384v2
194.30194.48194.78T:romulush
355.78356.52357.06T:photonbeetlehash256rate32v1
Cycles/byte for 8 bytes
25%50%75%hash
109.50109.50111.25asconhashav12
109.50110.88111.38asconxofav12
138.00138.25141.62T:xoodyakv1
145.75145.88147.25asconxofv12
145.38146.38147.75asconhashv12
228.88229.25230.75shake128
271.00271.00272.75asconhashabi32v12
281.50281.62283.00asconhashbi32v12
374.88376.62378.25T:esch256v2
412.12412.50413.00T:photonbeetlehash256rate32v1
438.62443.75449.88sha256
465.25466.25475.12sha512
504.25505.12506.12T:romulush
714.75716.12716.75T:esch384v2