VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of public-key Diffie–Hellman secret-sharing systems on one machine: amd64; Bonnell (106ca); 2010 Intel Atom N455; 1 x 1000MHz; h2atom, supercop-20260330

[Page version: 20260922 09:00:17]

eBATS (ECRYPT Benchmarking of Asymmetric Systems) is a project to measure the performance of public-key systems. This page presents benchmark results collected in eBATS for public-key Diffie–Hellman secret-sharing systems:

Each table row lists the first quartile of many speed measurements (or StQ1 starting with supercop-20260214), the median of many speed measurements (or StQ2 starting with supercop-20260214), the third quartile of many speed measurements (or StQ3 starting with supercop-20260214), and the name of the primitive. Measurements with large interquartile range (or stabilized interquartile range) are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each Diffie–Hellman system and each implementation. Designers and implementors interested in submitting new Diffie–Hellman systems and new implementations of existing systems should read the call for submissions.


Test results

Graphs: old (pkcycles,pkbytes) (scycles,pkbytes)

Cycles to generate a key pair
25%50%75%system
126272126812128061
T:
jacfp127i
131444132046133382
T:
kumjacfp127g
141997142536143601
T:
prjfp127i
147351148216149742
T:
hecfp127i
215782216549217650
T:
jacfp128bk
234402237154241090
T:
ecfp256e
244683245806247244
T:
prjfp128bk
246333247307248523
T:
hecfp128fkt
246324247490248919
T:
hecfp128bk
246639247715249051
T:
hecfp128i
249540252164257228
T:
curve2251
256118259076262722
T:
ecfp256s
259739259995261450curve25519
263594266629270751
T:
ecfp256h
264741268541272726
T:
ecfp256q
325933330310334542
T:
gls1271
424909426074427164nistp256
549142549740550290
T:
kumfp127g
103694010370161037393
T:
kumfp128g
115553211626391170770
T:
ecfp256i
131440813156791317068
T:
ed448goldilocks
170568417059531707304
T:
kummer
208769021111582132258
T:
sclaus1024
733687973404217349691
T:
ed521gs
856449285693858584263
T:
nist521gs
108148241088029610957514
T:
sclaus2048
122203421225015112285061
T:
claus
Cycles to compute a shared secret
25%50%75%system
556757557438557888
T:
kumfp127g
560044561106561542
T:
kumjacfp127g
728016729100729590
T:
jacfp128bk
775637778611783669
T:
gls1271
871077871480871710
T:
prjfp128bk
904246904464904928
T:
hecfp128fkt
920800920942921919
T:
hecfp128bk
938337938509938911
T:
jacfp127i
101906510191301019574curve25519
100633910234291024131
T:
curve2251
106186510619421062448
T:
kumfp128g
108389210846751085559
T:
ecfp256e
111388511141311116103
T:
prjfp127i
111809611185411119401
T:
ecfp256q
114208411426841144136
T:
ecfp256i
115447411547321156493
T:
hecfp127i
133608913372771339176
T:
ecfp256s
144236014433561445039
T:
ecfp256h
170520217055651705794
T:
kummer
171080217113471711842nistp256
195834219585241958997
T:
hecfp128i
213341921483912170140
T:
sclaus1024
451058045111254516927
T:
ed448goldilocks
733491773362027342735
T:
ed521gs
856338485668938582533
T:
nist521gs
109458121096616610989751
T:
sclaus2048
122342111225827912300257
T:
claus