3 ms·
That fits with my understanding. What I don't know is how this interacts with the acceleration functionality the chip has. For instance, do the instructions end
by DanielDent 10y ago
That fits with my understanding. What I don't know is how this interacts with the acceleration functionality the chip has. For instance, do the instructions end up being "please do sha256 on this data", or are they closer to AES-NI where it's "please perform one round of an AES encryption flow".
- akovaski 10y agoJudging from the source code[1] in the author's repository, it is the latter. (what I see is: perform 96 instructions, then subtract 64 from the message length, and repeat until the message length is 0) Intel seems to be the same way [2](2013) - i.e. looping over multiple instructions per 64 byte block. [1] https://github.com/minio/sha256-simd/blob/master/sha256block_arm64.s https://github.com/minio/sha256-simd/blob/master/sha256block... [2] https://software.intel.com/en-us/articles/intel-sha-extensions https://software.intel.com/en-us/articles/intel-sha-extensio...
- DanielDent 10y agoInteresting, thanks for pointing that out. This code is such a good example of the potential value of formal verification tools for crypto primitives.