Dishes
Optimized C++ Implementation
The optimized architecture-specific implementation supports x86-64 and aarch64 and uses ISA extensions to accelerate AES and other operations.
x86-64 (with AVX2 and AES-NI)
We measured the performance using a single core of a notebook with an Intel Core Ultra 9 285H processor of the Arrow Lake family running Linux 7.1.9. We compile with GCC 16.2.1 and pin the benchmark to a performance core with up to 5.4 GHz.
| FAEST Variant
|
Runtimes | Sizes in Bytes | |||||||
|---|---|---|---|---|---|---|---|---|---|
| Keygen | Sign | Verify | sk
|
pk
|
sig
|
||||
| ns | cyc | ms | Mcyc | ms | Mcyc | ||||
| 128f | 77 | 389 | 0.352 | 1.7 | 0.239 | 1.2 | 32 | 32 | 5170 |
| 128s | 77 | 388 | 2.172 | 10.6 | 1.679 | 8.1 | 32 | 32 | 4066 |
| 192f | 138 | 696 | 1.817 | 9.1 | 1.422 | 7.3 | 40 | 48 | 11738 |
| 192s | 137 | 695 | 10.824 | 53.9 | 8.428 | 42.6 | 40 | 48 | 9410 |
| 256f | 165 | 839 | 1.981 | 9.7 | 1.603 | 7.9 | 48 | 48 | 20856 |
| 256s | 165 | 837 | 12.860 | 62.6 | 12.417 | 60.6 | 48 | 48 | 16626 |
| EM-128f | 83 | 420 | 0.307 | 1.5 | 0.190 | 0.9 | 32 | 32 | 4170 |
| EM-128s | 83 | 421 | 1.532 | 7.5 | 1.176 | 5.7 | 32 | 32 | 3466 |
| EM-192f | 143 | 726 | 1.136 | 5.7 | 0.845 | 4.3 | 48 | 48 | 9818 |
| EM-192s | 143 | 723 | 6.374 | 31.9 | 5.793 | 29.1 | 48 | 48 | 7874 |
| EM-256f | 190 | 964 | 1.702 | 8.5 | 1.416 | 6.9 | 64 | 64 | 18084 |
| EM-256s | 190 | 965 | 10.761 | 51.4 | 9.980 | 49.4 | 64 | 64 | 14554 |
AArch64 (with AES)
For ARM, we benchmarked on a Macbook Pro with an Apple M1 processor at up to 3.2 GHz.
| FAEST Variant
|
Runtimes | Sizes in Bytes | ||||
|---|---|---|---|---|---|---|
| Keygen | Sign | Verify | sk
|
pk
|
sig
|
|
| ns | ms | ms | ||||
| 128f | 601 | 0.727 | 0.480 | 32 | 32 | 5170 |
| 128s | 589 | 4.758 | 3.354 | 32 | 32 | 4066 |
| 192f | 624 | 2.191 | 1.701 | 40 | 48 | 11738 |
| 192s | 615 | 17.090 | 10.625 | 40 | 48 | 9410 |
| 256f | 622 | 3.229 | 2.658 | 48 | 48 | 20856 |
| 256s | 620 | 20.616 | 20.050 | 48 | 48 | 16626 |
| EM-128f | 582 | 0.685 | 0.386 | 32 | 32 | 4170 |
| EM-128s | 590 | 3.595 | 2.574 | 32 | 32 | 3466 |
| EM-192f | 594 | 1.520 | 1.174 | 48 | 48 | 9818 |
| EM-192s | 591 | 10.987 | 9.589 | 48 | 48 | 7874 |
| EM-256f | 593 | 2.701 | 2.147 | 64 | 64 | 18084 |
| EM-256s | 594 | 16.393 | 15.170 | 64 | 64 | 14554 |
Reference C Implementation
The reference implementation is slower than the optimized implementation above, but follows the algorithms given in the specification more closely.
Old Implementations
-
x86-64 C implementation with AVX2, AES-NI, and other ISA extensions for the NIST Round 1 submission. Superceded by the C++ version above.
-
Initial Rust implementation for our Crypto 2023 paper. Note that this is for an older version of our protocol, which uses different primitives and is incompatible with the specification.