PACLMULQDQ 2015) (2014) (2013) (2012) (2010)

Skylake (Sept. Skylake Broadwell Haswell bridge Sandy Westmere / AES-NI Pre


23 0.50


0.65 0.65

0.76 0.76 1.00

1.02 1.02 1.50

per per byte 2.00


2.75 2.75 3.00 cost of CTR! of cost

3.08 3.08

GCM at the the at GCM 3.50

- AES ) 2015 (


GCM performance GCM - AES

Across Intel CPU CPU Intel Across GCM - AES enerations G


(without init) (without init) (with init) (with






Cycles per byte



Haswell 0.80

0.65 0.65 0.65

0.76 0.76

0.77 0.77 1.00

0.92 0.92

0.94 0.94 1.20

1.10 1.10

1.16 1.16 1.18 1.18 1.40

key GCM key - 2 KB message KB 8 an over SIV -

SIV Performance Performance SIV - GCM Highlights –


