3 ms·
Did you compare performance to SHA512? Despite being a theoretically more secure/"harder" algorithm, on 64 bit platforms it can sometimes be faster than SHA256.
by DanielDent 10y ago
Did you compare performance to SHA512? Despite being a theoretically more secure/"harder" algorithm, on 64 bit platforms it can sometimes be faster than SHA256. If you don't want to use 512 bits, using 256 bits of the output of SHA512 is standardized as SHA512/256 and is considered valid/secure.
(I'm unclear if this performance oddity remains true with the crypto hardware extensions being used here.)
- cyphar 10y agoThe oddity is that I believe sha512 uses 64-bit words while sha256 uses 32-bit words. So on 64 bit hardware sha512 will be faster (presumably because using the 32 bit registers is slower somehow, I don't know). This is why ZFS is adding support for sha512/256 as it's Merkel tree hashing function.
- DanielDent 10y agoThat fits with my understanding. What I don't know is how this interacts with the acceleration functionality the chip has. For instance, do the instructions end up being "please do sha256 on this data", or are they closer to AES-NI where it's "please perform one round of an AES encryption flow".
- akovaski 10y agoJudging from the source code[1] in the author's repository, it is the latter. (what I see is: perform 96 instructions, then subtract 64 from the message length, and repeat until the message length is 0) Intel seems to be the same way [2](2013) - i.e. looping over multiple instructions per 64 byte block. [1] https://github.com/minio/sha256-simd/blob/master/sha256block_arm64.s https://github.com/minio/sha256-simd/blob/master/sha256block... [2] https://software.intel.com/en-us/articles/intel-sha-extensions https://software.intel.com/en-us/articles/intel-sha-extensio...
- DanielDent 10y agoInteresting, thanks for pointing that out. This code is such a good example of the potential value of formal verification tools for crypto primitives.
- tedunangst 10y agoSHA512 eats data 512 bits at a time, while SHA256 eats it 256 bits at time. Both internally use 8 "registers", which are either 64 or 32 bits wide. Assuming you have the hardware registers to match, this would make SHA512 about twice as fast. But internally, it mixes data using 80 rounds, vs 64 for SHA256, so the speedup isn't quite 2x.
- pbsd 10y agoFor the sake of pedantry, SHA-512 eats 1024 bits, resp. 512 bits for SHA-256, at a time. It's the chaining variables that are of those lengths.
- fwessels 10y agoNo we did not compare to SHA512 (since we don't need it). I would expect SHA512 to be 2x faster compared to the SHA256 software version, but that is still way slower than the ARM SHA extensions accelerated version.
- y4m4b4 10y agoFor comparison with other checksums you should look here https://github.com/minio/sha256-simd#comparison-to-other-hashing-techniques https://github.com/minio/sha256-simd#comparison-to-other-has...
- pbsd 10y agoSHA-512 should be much faster than SHA-256 on AVX2-capable processors. Go's implementation is subpar; try OpenSSL instead. On Skylake, SHA-512 is about as fast as MD5 now -- https://bench.cr.yp.to/results-hash.html#amd64-skylake https://bench.cr.yp.to/results-hash.html#amd64-skylake
- y4m4b4 10y agoYes true. OpenSSL version gives a great boost. Rather than SHA512 we ended up using Blake2b - https://github.com/minio/blake2b-simd https://github.com/minio/blake2b-simd (also optimized with SIMD instructions) internally for bit-rot verification in https://github.com/minio/minio https://github.com/minio/minio
- Buge 10y agoSHA512/256 is also secure against length extension, which SHA256 isn't.