Optimized C++ Implementation

The optimized architecture-specific implementation supports x86-64 and aarch64 and uses ISA extensions to accelerate AES and other operations.

x86-64 (with AVX2 and AES-NI)

We measured the performance using a single core of a notebook with an Intel Core Ultra 9 285H processor of the Arrow Lake family running Linux 7.1.9. We compile with GCC 16.2.1 and pin the benchmark to a performance core with up to 5.4 GHz.

FAEST Variant

Runtimes Sizes in Bytes
Keygen Sign Verify sk
pk
sig
ns cyc ms Mcyc ms Mcyc
128f 77 389 0.352 1.7 0.239 1.2 32 32 5170
128s 77 388 2.172 10.6 1.679 8.1 32 32 4066
192f 138 696 1.817 9.1 1.422 7.3 40 48 11738
192s 137 695 10.824 53.9 8.428 42.6 40 48 9410
256f 165 839 1.981 9.7 1.603 7.9 48 48 20856
256s 165 837 12.860 62.6 12.417 60.6 48 48 16626
EM-128f 83 420 0.307 1.5 0.190 0.9 32 32 4170
EM-128s 83 421 1.532 7.5 1.176 5.7 32 32 3466
EM-192f 143 726 1.136 5.7 0.845 4.3 48 48 9818
EM-192s 143 723 6.374 31.9 5.793 29.1 48 48 7874
EM-256f 190 964 1.702 8.5 1.416 6.9 64 64 18084
EM-256s 190 965 10.761 51.4 9.980 49.4 64 64 14554

AArch64 (with AES)

For ARM, we benchmarked on a Macbook Pro with an Apple M1 processor at up to 3.2 GHz.

FAEST Variant

Runtimes Sizes in Bytes
Keygen Sign Verify sk
pk
sig
ns ms ms
128f 601 0.727 0.480 32 32 5170
128s 589 4.758 3.354 32 32 4066
192f 624 2.191 1.701 40 48 11738
192s 615 17.090 10.625 40 48 9410
256f 622 3.229 2.658 48 48 20856
256s 620 20.616 20.050 48 48 16626
EM-128f 582 0.685 0.386 32 32 4170
EM-128s 590 3.595 2.574 32 32 3466
EM-192f 594 1.520 1.174 48 48 9818
EM-192s 591 10.987 9.589 48 48 7874
EM-256f 593 2.701 2.147 64 64 18084
EM-256s 594 16.393 15.170 64 64 14554

Reference C Implementation

The reference implementation is slower than the optimized implementation above, but follows the algorithms given in the specification more closely.

Old Implementations

  • x86-64 C implementation with AVX2, AES-NI, and other ISA extensions for the NIST Round 1 submission. Superceded by the C++ version above.

  • Initial Rust implementation for our Crypto 2023 paper. Note that this is for an older version of our protocol, which uses different primitives and is incompatible with the specification.