VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of public-key Diffie–Hellman secret-sharing systems on one machine: amd64; Zen 4 (a60f12); 2023 AMD Ryzen 7 7700; 8 x 3800MHz; hertz, supercop-20260831

[Page version: 20260903 21:39:10]

eBATS (ECRYPT Benchmarking of Asymmetric Systems) is a project to measure the performance of public-key systems. This page presents benchmark results collected in eBATS for public-key Diffie–Hellman secret-sharing systems:

Each table row lists the first quartile of many speed measurements (or StQ1 starting with supercop-20260214), the median of many speed measurements (or StQ2 starting with supercop-20260214), the third quartile of many speed measurements (or StQ3 starting with supercop-20260214), and the name of the primitive. Measurements with large interquartile range (or stabilized interquartile range) are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each Diffie–Hellman system and each implementation. Designers and implementors interested in submitting new Diffie–Hellman systems and new implementations of existing systems should read the call for submissions.


Test results

Graphs: (pkcycles,pkbytes) (scycles,pkbytes)

Cycles to generate a key pair
25%50%75%system
225962260722624curve25519
240132525426768
T:
jacfp127i
261582750228832
T:
kumjacfp127g
273492849229806
T:
prjfp127i
284812977631140
T:
hecfp127i
308353099031459
T:
gls254
314223147931685
T:
gls254prot
306533183633131
T:
jacfp128bk
305113204835443
T:
ecfp256e
341793555439735
T:
curve2251
351913666938453
T:
hecfp128i
353683683438770
T:
hecfp128fkt
359303755739419
T:
prjfp128bk
359313814144041
T:
ecfp256s
367003818339943
T:
hecfp128bk
371863961345347
T:
ecfp256q
404764066440740nistp256
424984253742577
T:
kummer
426944274842819
T:
k277taa
482674843349507
T:
k298
612426135361383
T:
k277mon
792527936979462
T:
kumfp127g
104242104313104397
T:
kumfp128g
144297145232146141
T:
ecfp256i
160263160693161151
T:
ed448goldilocks
162499163381164427
T:
ecfp256h
208301210399212138
T:
sclaus1024
778266782175791258
T:
ed521gs
938799940256942100
T:
nist521gs
101417910164071022563
T:
claus
109391011018651110945
T:
sclaus2048
Cycles to compute a shared secret
25%50%75%system
294592954329710
T:
gls254
312023134931401
T:
gls254prot
424544247842526
T:
kummer
426704272842816
T:
k277taa
481434821948317
T:
k298
535805358453610curve25519
611396134161353
T:
k277mon
787777886079014
T:
jacfp128bk
814978158381728
T:
kumfp127g
823528256682728
T:
kumjacfp127g
933429351493852
T:
prjfp128bk
976509780697977
T:
hecfp128fkt
990629925499540
T:
hecfp128bk
109049109097109132
T:
kumfp128g
120940121055121337
T:
jacfp127i
128546128676129144
T:
ecfp256e
135697135919136568
T:
curve2251
137485137607137750
T:
ecfp256i
140616140700140779
T:
ecfp256q
150208150314150437
T:
prjfp127i
152880152945153046
T:
hecfp127i
154692154786155213
T:
ecfp256h
155449155500155515nistp256
196842196862196905
T:
ecfp256s
210725210881211031
T:
hecfp128i
218543220545222496
T:
sclaus1024
536535542152544711
T:
ed448goldilocks
778785782592790714
T:
ed521gs
938283941234943167
T:
nist521gs
101229710133931015294
T:
claus
111111311196411125362
T:
sclaus2048