`
GCM-SIV:
Full Nonce Mis isuse-Resistant Authenticated Encry ryption at t Under One Cycle per Byt yte
Shay Gueron
Haifa Univ. and Intel
Yehuda Lindell
Bar-Ilan University
Appeared at ACM CCS 2015
GCM-SIV: Full Nonce Mis isuse-Resistant Authenticated Encry - - PowerPoint PPT Presentation
` GCM-SIV: Full Nonce Mis isuse-Resistant Authenticated Encry ryption at t Under One Cycle per Byt yte Shay Gueron Yehuda Lindell Bar-Ilan University Haifa Univ. and Intel Appeared at ACM CCS 2015 ` How to Encry rypt wit ith a Blo
`
Shay Gueron
Haifa Univ. and Intel
Yehuda Lindell
Bar-Ilan University
Appeared at ACM CCS 2015
`
`
`
`
`
`
`
`
`
`
𝒓 𝟑
𝑶 ≈
𝒓𝟑 𝟑𝑶
𝟐𝟑,𝟗𝟏𝟏,𝟏𝟏𝟏𝟑 𝟑𝑶
`
`
`
`
`
`
`
`
`
`
`
`
23
3.08 2.75 1.02 0.76 0.65
0.00 0.50 1.00 1.50 2.00 2.50 3.00 3.50 4.00
Pre AES-NI / PACLMULQDQ Westmere (2010) Sandy bridge (2012) Haswell (2013) Broadwell (2014) Skylake (Sept. 2015)
cycles per byte AES-GCM performance
(2015) AES- GCM at the cost of CTR!
`
`
` 1.18 1.10 1.16 0.92 0.77 0.76 0.94 0.65 0.65
0.40 0.60 0.80 1.00 1.20 1.40
GCM-SIV encrypt (with init) GCM-SIV decrypt (with init) AES-GCM (without init)
Cycles per byte
Haswell Broadwell Skylake
`
`
`
`