VAMPIRE

eBACS: ECRYPT Benchmarking of Cryptographic Systems


ECRYPT II
General information:IntroductioneBASHeBASCeBAEADeBATSSUPERCOPXBXComputersArch
How to submit new software:Tipshashstreamaeaddhkemencryptsign
List of primitives measured:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
Measurements:lwcsha3hashstreamlwccaesaraeaddhkemencryptsign
List of subroutines:verifydecodeencodesortcorehashblocksxofscalarmult

Measurements of NISTLWC cipher candidates on one machine: amd64; Tremont (906c0); 2021 Intel Pentium Silver N6000; 4 x 1100MHz; jasper, supercop-20241022

[Page version: 20241215 22:59:49]

eBAEAD (ECRYPT Benchmarking of Authenticated Ciphers) is a project to measure the performance of authenticated ciphers. This page presents an excerpt of the full eBAEAD benchmark results. The excerpt is for NISTLWC, specifically (starting with supercop-20221005) finalists.

Each table row lists the first quartile of many speed measurements, the median of many speed measurements, the third quartile of many speed measurements, and the name of the primitive. Measurements with large variance are indicated in red with question marks. The symbol T: (starting with supercop-20200816) means that the SUPERCOP database at the time of benchmarking did not list constant time as a goal for this implementation. The symbol T!!! means that constant time was listed as a goal for this implementation, but that the implementation failed TIMECOP. (TIMECOP failures are not necessarily security issues; they can sometimes be resolved by, e.g., declaring that a rejection-sampling condition is safe to declassify.)

There is a separate page with more information about each cipher and each implementation.


Test results

Graphs: (bytes,cycles)
Cycles/byte for long+0 encrypt
25%50%75%aead
1.461.481.49T:aes128gcmv1
1.631.641.66aes256gcmv1
10.7610.7710.78ascon128av12
15.1315.1715.26ascon80pqv12
15.3415.3515.35ascon128v12
21.6421.6921.87T:xoodyakround3
22.1622.1822.20T:schwaemm256128v2
23.4023.4223.42ascon128abi32v12
29.2429.3829.40T:schwaemm192192v2
32.3932.4132.43T:schwaemm256256v2
33.3233.4733.48T:schwaemm128128v2
34.1234.1334.19ascon128bi32v12
38.8939.0839.16T:grain128aeadv2
47.4747.5347.55romulusn
47.9148.1348.17T:giftcofb128v1
61.9462.0662.26T:isapa128av20
68.5668.8068.88T:isapa128v20
76.0076.0476.20T:tinyjambu128v2
76.6276.8576.97romulusm
95.3895.5395.61T:tinyjambu192v2
103.93104.06104.11T:tinyjambu256v2
104.18107.22111.60T:isapk128av20
134.84141.88147.45T:isapk128v20
145.66145.74146.05T!!!romulust
197.48197.75199.13T:elephant200v2
212.64213.00213.44T:isapxv20
10398.1410400.8110405.33T:elephant176v2
11801.3511805.0111810.31T:elephant160v2
Cycles/byte for long+0 decrypt
25%50%75%aead
1.591.601.62T:aes128gcmv1
1.701.721.74aes256gcmv1
10.2510.2710.31ascon128av12
15.1515.1515.20ascon128v12
15.3515.3815.48ascon80pqv12
20.6620.7320.78T:xoodyakround3
22.1422.1822.22T:schwaemm256128v2
23.4323.4423.45ascon128abi32v12
29.2329.3829.40T:schwaemm192192v2
32.4232.4332.44T:schwaemm256256v2
33.3833.4033.47T:schwaemm128128v2
33.8533.9233.95ascon128bi32v12
39.3339.4239.53T:grain128aeadv2
47.4547.4747.49romulusn
48.1048.4348.46T:giftcofb128v1
62.0062.3462.55T:isapa128av20
67.9868.1868.76T:isapa128v20
76.4076.4676.51T:tinyjambu128v2
77.1577.1977.41romulusm
95.0995.3495.39T:tinyjambu192v2
104.28104.39104.49T:tinyjambu256v2
104.15106.75111.14T:isapk128av20
135.59141.65147.30T:isapk128v20
145.63145.86146.39T!!!romulust
196.84197.57198.91T:elephant200v2
211.90212.33212.86T:isapxv20
10394.7110398.5510400.83T:elephant176v2
11802.9211806.4311808.89T:elephant160v2
Cycles/byte for long+0 forgery
25%50%75%aead
1.601.611.62T:aes128gcmv1
1.691.701.71aes256gcmv1
10.2610.2810.30ascon128av12
15.1915.1915.20ascon128v12
15.3815.3815.39ascon80pqv12
20.7520.7920.83T:xoodyakround3
22.1622.1922.21T:schwaemm256128v2
23.4423.4523.47ascon128abi32v12
29.2729.3729.40T:schwaemm192192v2
32.4132.4232.43T:schwaemm256256v2
33.3833.4033.48T:schwaemm128128v2
33.8733.9333.96ascon128bi32v12
34.2234.3134.34T:isapa128v20
39.4039.5039.53T:grain128aeadv2
40.2841.0541.18T:isapa128av20
47.4447.4747.74romulusn
47.6847.8348.02T:giftcofb128v1
51.8851.9452.12T!!!romulust
68.1670.9875.08T:isapk128av20
76.4076.4776.50T:tinyjambu128v2
77.1177.2277.36romulusm
82.94?88.08?93.80?T:isapk128v20
95.1495.3095.43T:tinyjambu192v2
104.26104.32104.39T:tinyjambu256v2
125.85126.15126.22T:isapxv20
197.48197.65198.95T:elephant200v2
10393.1610399.9610409.74T:elephant176v2
11800.4211804.1711808.81T:elephant160v2
Cycles/byte for long+long encrypt
25%50%75%aead
1.001.021.03T:aes128gcmv1
1.081.101.11aes256gcmv1
10.4110.4210.43ascon128av12
14.9915.0215.07ascon80pqv12
15.0815.1115.12ascon128v12
15.5015.5415.57T:xoodyakround3
21.9922.0022.06T:schwaemm256128v2
23.0623.1123.19ascon128abi32v12
29.1729.1829.23T:schwaemm192192v2
32.1932.2432.28T:schwaemm256256v2
33.2933.4133.45T:schwaemm128128v2
34.0934.1434.24ascon128bi32v12
38.7738.8538.92romulusn
38.8738.9439.09T:grain128aeadv2
47.8948.1248.20T:giftcofb128v1
51.0851.1351.22T:isapa128v20
50.9751.3751.47T:isapa128av20
53.3153.3753.44romulusm
62.2362.2662.31T:tinyjambu128v2
74.6274.6574.74T:tinyjambu192v2
78.5578.6378.67T:tinyjambu256v2
87.4288.8192.65T:isapk128av20
98.3598.4198.62T!!!romulust
112.86114.78115.23T:isapk128v20
148.81149.16149.40T:elephant200v2
169.56169.61169.79T:isapxv20
7756.487765.567774.45T:elephant176v2
8847.768850.078852.87T:elephant160v2
Cycles/byte for long+long decrypt
25%50%75%aead
1.051.071.08T:aes128gcmv1
1.111.131.14aes256gcmv1
10.2610.2910.30ascon128av12
14.9515.0115.07ascon80pqv12
15.0115.0315.05ascon128v12
15.3315.3515.40T:xoodyakround3
22.0422.0922.10T:schwaemm256128v2
23.0523.0823.15ascon128abi32v12
29.1629.2029.23T:schwaemm192192v2
32.2232.2432.28T:schwaemm256256v2
33.3733.3933.58T:schwaemm128128v2
33.5533.6033.61ascon128bi32v12
38.6338.8338.90romulusn
39.0539.1239.19T:grain128aeadv2
47.9348.0548.14T:giftcofb128v1
51.0051.1551.24T:isapa128v20
51.0151.4651.58T:isapa128av20
53.4453.5253.57romulusm
62.4062.4662.48T:tinyjambu128v2
74.4774.5774.61T:tinyjambu192v2
78.7178.7578.82T:tinyjambu256v2
87.4888.9492.70T:isapk128av20
98.4698.5698.85T!!!romulust
112.93114.95115.22T:isapk128v20
148.58149.10149.44T:elephant200v2
168.89169.10169.33T:isapxv20
7754.837764.187767.76T:elephant176v2
8848.138849.938851.82T:elephant160v2
Cycles/byte for long+long forgery
25%50%75%aead
1.061.071.07T:aes128gcmv1
1.131.131.14aes256gcmv1
10.2910.3010.31ascon128av12
14.9415.0315.04ascon128v12
14.9815.0515.13ascon80pqv12
15.3615.3715.43T:xoodyakround3
22.0422.0722.10T:schwaemm256128v2
23.0723.0723.13ascon128abi32v12
29.1629.2029.22T:schwaemm192192v2
32.1932.2432.29T:schwaemm256256v2
33.2033.3233.69T:schwaemm128128v2
33.5633.5733.57ascon128bi32v12
34.2834.3034.63T:isapa128v20
38.6638.8538.89romulusn
39.0639.1139.20T:grain128aeadv2
40.6440.8641.00T:isapa128av20
48.0148.1448.23T:giftcofb128v1
51.6251.6451.75T!!!romulust
53.4453.5253.58romulusm
62.4162.4662.50T:tinyjambu128v2
69.4771.0074.43T:isapk128av20
74.4874.5274.61T:tinyjambu192v2
78.7178.8078.87T:tinyjambu256v2
86.9188.3588.50T:isapk128v20
125.88125.94126.03T:isapxv20
148.43149.25149.30T:elephant200v2
7759.287760.947765.37T:elephant176v2
8849.868851.458852.80T:elephant160v2
Cycles/byte for 0+long encrypt
25%50%75%aead
0.550.570.57T:aes128gcmv1
0.550.570.57aes256gcmv1
9.9910.0210.06T:xoodyakround3
10.0410.0510.07ascon128av12
14.8014.8214.82ascon128v12
14.8214.8414.85ascon80pqv12
21.8321.9222.03T:schwaemm256128v2
22.9422.9622.97ascon128abi32v12
29.0329.0629.08T:schwaemm192192v2
29.8029.8529.88romulusm
29.8830.2730.34romulusn
31.9631.9832.07T:schwaemm256256v2
33.1933.4333.60T:schwaemm128128v2
33.9233.9534.33ascon128bi32v12
34.1034.2634.47T:isapa128v20
38.6938.8138.91T:grain128aeadv2
40.9941.0541.14T:isapa128av20
48.0848.1348.38T:giftcofb128v1
48.3448.4348.49T:tinyjambu128v2
51.1451.2551.35T!!!romulust
53.1253.2053.26T:tinyjambu256v2
53.7853.8753.96T:tinyjambu192v2
69.0070.9874.51T:isapk128av20
85.7888.9891.11T:isapk128v20
100.20100.61100.91T:elephant200v2
125.97126.44126.98T:isapxv20
5129.395131.045135.97T:elephant176v2
5896.105898.995901.36T:elephant160v2
Cycles/byte for 0+long decrypt
25%50%75%aead
0.530.550.55T:aes128gcmv1
0.550.560.58aes256gcmv1
10.0110.0410.13T:xoodyakround3
10.2310.3010.31ascon128av12
14.6514.6814.70ascon128v12
14.4814.7014.72ascon80pqv12
21.8521.9221.98T:schwaemm256128v2
22.6922.8222.83ascon128abi32v12
29.0429.0429.04T:schwaemm192192v2
29.7629.8129.91romulusm
29.8630.2330.33romulusn
31.9631.9932.08T:schwaemm256256v2
33.2533.2633.27ascon128bi32v12
33.3033.4433.59T:schwaemm128128v2
33.7734.2534.46T:isapa128v20
38.6538.7238.96T:grain128aeadv2
40.6740.9741.13T:isapa128av20
48.0048.2348.55T:giftcofb128v1
48.3748.4248.51T:tinyjambu128v2
51.0951.2151.44T!!!romulust
53.1353.1753.28T:tinyjambu256v2
53.8253.9153.97T:tinyjambu192v2
69.7370.8974.64T:isapk128av20
86.2888.4492.31T:isapk128v20
100.01100.16100.19T:elephant200v2
125.80126.03126.12T:isapxv20
5132.135136.725138.24T:elephant176v2
5891.015898.685902.00T:elephant160v2
Cycles/byte for 0+long forgery
25%50%75%aead
0.530.540.55T:aes128gcmv1
0.550.560.57aes256gcmv1
9.9810.0310.05T:xoodyakround3
10.2310.3110.32ascon128av12
14.5714.6714.73ascon80pqv12
14.6814.6914.89ascon128v12
21.8721.9221.96T:schwaemm256128v2
22.6922.8222.83ascon128abi32v12
29.0329.0329.04T:schwaemm192192v2
29.8129.8929.96romulusm
29.9130.2830.38romulusn
31.9832.0932.17T:schwaemm256256v2
33.2433.2533.27ascon128bi32v12
33.2733.4433.76T:schwaemm128128v2
34.0834.1234.49T:isapa128v20
38.6438.7238.98T:grain128aeadv2
40.9641.0041.11T:isapa128av20
47.8947.9648.14T:giftcofb128v1
48.3448.4148.46T:tinyjambu128v2
51.1751.3151.42T!!!romulust
53.1153.1453.29T:tinyjambu256v2
53.8453.9554.00T:tinyjambu192v2
69.7070.8174.73T:isapk128av20
86.2388.4592.30T:isapk128v20
100.19100.26100.90T:elephant200v2
125.69126.05126.19T:isapxv20
5130.935138.585142.25T:elephant176v2
5896.645897.885899.61T:elephant160v2
Cycles/byte for 1536+1536 encrypt
25%50%75%aead
1.151.151.16T:aes128gcmv1
1.251.261.27aes256gcmv1
10.6710.6810.69ascon128av12
15.2315.2315.28ascon80pqv12
15.3115.3115.34ascon128v12
15.6615.6815.75T:xoodyakround3
22.6922.7222.75T:schwaemm256128v2
23.5923.6123.68ascon128abi32v12
29.8129.8629.87T:schwaemm192192v2
33.0833.1133.15T:schwaemm256256v2
33.7433.8034.00T:schwaemm128128v2
34.6034.6434.72ascon128bi32v12
39.0839.2539.28romulusn
39.2839.3539.42T:grain128aeadv2
48.5348.7448.78T:giftcofb128v1
53.7153.7853.92romulusm
55.2755.3755.40T:isapa128av20
62.6162.7462.82T:tinyjambu128v2
74.4374.4674.48T:isapa128v20
75.2375.2675.31T:tinyjambu192v2
79.1779.2279.27T:tinyjambu256v2
99.89100.02104.55T:isapk128av20
100.06100.13100.30T!!!romulust
151.97152.30152.90T:elephant200v2
202.70202.78202.98T:isapk128v20
278.22278.40278.50T:isapxv20
7817.097822.637830.50T:elephant176v2
8950.778951.398952.69T:elephant160v2
Cycles/byte for 1536+1536 decrypt
25%50%75%aead
1.201.201.21T:aes128gcmv1
1.291.291.30aes256gcmv1
10.5310.5510.56ascon128av12
15.1815.2515.30ascon80pqv12
15.2615.2615.27ascon128v12
15.5015.5315.57T:xoodyakround3
22.6622.6922.73T:schwaemm256128v2
23.5823.5823.64ascon128abi32v12
29.8029.8129.85T:schwaemm192192v2
33.0833.1133.14T:schwaemm256256v2
33.8533.9433.99T:schwaemm128128v2
34.0834.1034.10ascon128bi32v12
39.0939.2539.29romulusn
39.5439.5739.66T:grain128aeadv2
48.4648.6348.72T:giftcofb128v1
53.9754.0154.11romulusm
54.9555.2455.38T:isapa128av20
62.8962.9162.96T:tinyjambu128v2
74.3374.4674.56T:isapa128v20
75.0675.1375.22T:tinyjambu192v2
79.3179.3979.46T:tinyjambu256v2
99.90100.09103.73T:isapk128av20
100.05100.23100.27T!!!romulust
151.77151.99152.61T:elephant200v2
202.71202.77203.07T:isapk128v20
277.67277.77277.96T:isapxv20
7821.207825.027837.63T:elephant176v2
8951.628952.918953.70T:elephant160v2
Cycles/byte for 1536+1536 forgery
25%50%75%aead
1.201.201.21T:aes128gcmv1
1.281.291.29aes256gcmv1
10.5410.5510.57ascon128av12
15.1715.1715.26ascon128v12
15.2115.2615.28ascon80pqv12
15.5415.5615.58T:xoodyakround3
22.6722.6922.75T:schwaemm256128v2
23.5823.5823.64ascon128abi32v12
29.8029.8529.86T:schwaemm192192v2
33.0833.1133.15T:schwaemm256256v2
33.7333.7533.76T:schwaemm128128v2
34.0734.1034.10ascon128bi32v12
39.0239.2539.28romulusn
39.5339.5939.65T:grain128aeadv2
42.6742.9843.40T:isapa128av20
46.0246.1746.18T:isapa128v20
48.4948.5948.67T:giftcofb128v1
53.1553.1953.22T!!!romulust
53.9354.0154.06romulusm
62.9262.9562.98T:tinyjambu128v2
75.0975.2175.25T:tinyjambu192v2
76.8176.8481.09T:isapk128av20
79.3579.4379.48T:tinyjambu256v2
133.70134.74134.78T:isapk128v20
151.75152.22152.83T:elephant200v2
181.44181.50181.66T:isapxv20
7817.647823.997831.96T:elephant176v2
8945.088948.858950.55T:elephant160v2
Cycles/byte for 64+64 encrypt
25%50%75%aead
7.097.197.37aes256gcmv1
7.597.667.73T:aes128gcmv1
16.1716.3016.57ascon128av12
20.3020.4020.79ascon80pqv12
20.2520.4120.53ascon128v12
23.1123.2823.48T:xoodyakround3
34.9635.0635.48ascon128abi32v12
36.9537.1137.38T:schwaemm256128v2
43.7143.8844.42T:schwaemm128128v2
45.9445.9946.34ascon128bi32v12
47.5047.6447.88romulusn
48.0148.1948.45T:schwaemm192192v2
49.7449.8449.99T:grain128aeadv2
52.4752.7052.80T:schwaemm256256v2
58.9359.0959.45T:giftcofb128v1
62.8562.9563.22romulusm
73.9874.1274.38T:tinyjambu128v2
88.2288.3488.60T:tinyjambu192v2
92.4292.7192.95T:tinyjambu256v2
137.41137.82139.09T!!!romulust
141.34141.53141.94T:isapa128av20
216.75216.99217.29T:elephant200v2
338.15?338.86?415.62?T:isapk128av20
610.62610.83611.42T:isapa128v20
2198.052199.462260.25T:isapk128v20
2741.982742.912748.34T:isapxv20
9735.569743.419749.06T:elephant176v2
11972.8811979.2911990.09T:elephant160v2
Cycles/byte for 64+64 decrypt
25%50%75%aead
6.746.907.19aes256gcmv1
7.487.597.68T:aes128gcmv1
16.0616.1516.30ascon128av12
20.3120.4520.73ascon80pqv12
20.3920.4920.73ascon128v12
22.8523.0123.39T:xoodyakround3
35.0935.1735.52ascon128abi32v12
36.9837.0237.24T:schwaemm256128v2
43.7043.7743.85T:schwaemm128128v2
45.4245.5545.89ascon128bi32v12
47.6247.8148.04romulusn
47.9648.0748.14T:schwaemm192192v2
49.9850.1850.27T:grain128aeadv2
52.4852.5252.59T:schwaemm256256v2
59.3159.6059.84T:giftcofb128v1
65.3165.5965.70romulusm
74.3474.4374.59T:tinyjambu128v2
88.1288.3688.59T:tinyjambu192v2
93.0393.1593.18T:tinyjambu256v2
137.44137.79138.52T!!!romulust
141.67142.08142.35T:isapa128av20
216.66216.80216.88T:elephant200v2
338.90?339.86?385.98?T:isapk128av20
610.79611.13611.57T:isapa128v20
2197.902204.232259.80T:isapk128v20
2742.122746.912748.59T:isapxv20
9731.709746.759754.06T:elephant176v2
11974.8411980.6011992.45T:elephant160v2
Cycles/byte for 64+64 forgery
25%50%75%aead
6.716.736.81aes256gcmv1
7.487.547.67T:aes128gcmv1
15.9816.0716.16ascon128av12
20.1520.2020.27ascon128v12
20.1720.3220.41ascon80pqv12
23.0923.1823.32T:xoodyakround3
35.0935.1935.32ascon128abi32v12
36.9736.9837.09T:schwaemm256128v2
43.9143.9744.15T:schwaemm128128v2
45.4845.4945.61ascon128bi32v12
47.8047.8948.04romulusn
47.9848.1148.22T:schwaemm192192v2
49.8349.9850.21T:grain128aeadv2
52.4752.5252.59T:schwaemm256256v2
59.3959.5259.67T:giftcofb128v1
65.2565.4165.64romulusm
74.1774.3774.59T:tinyjambu128v2
88.1288.3388.50T:tinyjambu192v2
88.7388.9889.46T!!!romulust
91.4591.5491.99T:isapa128av20
92.9193.0293.17T:tinyjambu256v2
202.01?202.44?241.61?T:isapk128av20
216.58216.74216.95T:elephant200v2
318.72318.80319.02T:isapa128v20
1182.051183.001207.02T:isapk128v20
1434.471435.221436.12T:isapxv20
9737.259742.449748.05T:elephant176v2
11970.2011984.7211989.91T:elephant160v2