{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T16:45:43Z","timestamp":1781714743793,"version":"3.54.5"},"reference-count":38,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2022,8,10]],"date-time":"2022-08-10T00:00:00Z","timestamp":1660089600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100006602","name":"U.S. Air Force Research Laboratory","doi-asserted-by":"publisher","award":["FA8750-19-2-0503"],"award-info":[{"award-number":["FA8750-19-2-0503"]}],"id":[{"id":"10.13039\/100006602","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Cryptography"],"abstract":"<jats:p>The ever-increasing need for securing computing systems using cryptographic algorithms is spurring interest in the efficient implementation of common algorithms. While the algorithms can be implemented in software using base instruction sets, there is considerable potential to reduce memory cost and improve speed using specialized instructions and associated hardware. However, there is a need to assess the benefits and costs of software implementations and new instructions that implement key cryptographic algorithms in fewer cycles. The primary aim of this paper is to improve the understanding of the performance and cost of implementing cryptographic algorithms for the RISC-V instruction set architecture (ISA) in two cases: software implementations of the algorithms using the rv32i instruction set and using cryptographic instructions supported by dedicated hardware in additional functional units. For both cases, we describe a RISC-V processor with cryptography hardware extensions and hand-optimized RISC-V assembly language implementations of eleven cryptographic algorithms. Compared to implementations with only the rv32i instruction set, implementations with the cryptography set extension provide a 1.5\u00d7 to 8.6\u00d7 faster execution speed and 1.2\u00d7 to 5.8\u00d7 less program memory for five of the eleven algorithms. Based on our performance analyses, a new instruction is proposed to increase the implementation efficiency of the algorithms.<\/jats:p>","DOI":"10.3390\/cryptography6030041","type":"journal-article","created":{"date-parts":[[2022,8,10]],"date-time":"2022-08-10T09:42:56Z","timestamp":1660124576000},"page":"41","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Symmetric Cryptography on RISC-V: Performance Evaluation of Standardized Algorithms"],"prefix":"10.3390","volume":"6","author":[{"given":"G\u00f6rkem","family":"Ni\u015fanc\u0131","sequence":"first","affiliation":[{"name":"Intel Corporation, Chandler, AZ 85226, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paul G.","family":"Flikkema","sequence":"additional","affiliation":[{"name":"School of Informatics, Computing and Cyber Systems, Northern Arizona University, Flagstaff, AZ 86011, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tolga","family":"Yal\u00e7\u0131n","sequence":"additional","affiliation":[{"name":"Google LLC, San Diego, CA 92121, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,8,10]]},"reference":[{"key":"ref_1","unstructured":"(2021, March 26). History-RISC-V International. Available online: https:\/\/riscv.org\/about\/history\/."},{"key":"ref_2","unstructured":"Waterman, A., Lee, Y., Patterson, D.A., and Asanovic, K. (2011). UCB\/EECS-2011-62; The RISC-V Instruction Set Manual, Volume i Base User-Level Isa, EECS Department."},{"key":"ref_3","unstructured":"(2021, March 26). RISC-V INTERNATIONAL. Available online: https:\/\/riscv.org\/."},{"key":"ref_4","unstructured":"(2022, August 03). The RISC-V Instruction Set Manual Volume I: Unprivileged ISA 2019, volume 1. Available online: https:\/\/riscv.org\/wp-content\/uploads\/2019\/12\/riscv-spec-20191213.pdf."},{"key":"ref_5","unstructured":"Zeh, A., Glew, A., Spinney, B., Marshall, B., Page, D., Atkins, D., Dockser, K., Saarinen, M.-J.O., Menhorn, N., and Deutsch, L.P. (2022, July 20). RISC-V Cryptographic Extension Proposals Volume I: Scalar & Entropy Source Instructions Version v1.0.0-rc6. Available online: https:\/\/github.com\/riscv\/riscv-crypto\/releases\/tag\/v1.0.0-rc6-scalar."},{"key":"ref_6","unstructured":"Zeh, A., Glew, A., Spinney, B., Marshall, B., Page, D., Atkins, D., Dockser, K., Saarinen, M.J.O., Menhorn, N., and Newell, R. (2022, July 20). RISC-V Cryptographic Extension Proposals Volume II: Vector Instructions. Available online: https:\/\/github.com\/riscv\/riscv-crypto\/releases\/tag\/v0.7.0."},{"key":"ref_7","unstructured":"(2022, July 24). RISC-V Bitmanip Extension Document Version 0.94 Draft. Available online: https:\/\/github.com\/riscv\/riscv-bitmanip\/blob\/main-history\/bitmanip-draft.pdf."},{"key":"ref_8","unstructured":"Pub, N.F. (2022, August 03). FIPS 197: Advanced Encryption Standard (AES), FIPS PUB 197, US Department of Commerce\/NIST, November 2001, Available online: https:\/\/nvlpubs.nist.gov\/nistpubs\/FIPS\/NIST.FIPS.197.pdf."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1080\/01611194.2012.687431","article-title":"Changes in Federal Information Processing Standard (FIPS) 180-4, Secure Hash Standard","volume":"37","author":"Dang","year":"2013","journal-title":"Cryptologia"},{"key":"ref_10","unstructured":"(2022, August 03). Specification of SM3 Cryptographic Hash Function. 2010. Organization of State Commercial Administration of China. Available online: https:\/\/www.chinesestandard.net\/PDF.aspx\/GBT32905-2016."},{"key":"ref_11","unstructured":"Diffie, W., and Translators, G.L. (2022, August 03). SMS4 Encryption Algorithm for Wireless Networks. Cryptology ePrint Archive, Available online: https:\/\/eprint.iacr.org\/2008\/329."},{"key":"ref_12","unstructured":"Zeh, A., Glew, A., Spinney, B., Marshall, B., Page, D., Atkins, D., Dockser, K., Saarinen, M.J.O., Menhorn, N., and Newell, R. (2022, August 03). RISC-V Cryptographic Extension Proposals Volume I: Scalar & Entropy Source Instructions Version 0.7.2. Available online: https:\/\/github.com\/riscv\/riscv-crypto\/releases\/tag\/v0.7.2-scalar."},{"key":"ref_13","unstructured":"Saarinen, M.J.O. (2020). A Lightweight ISA Extension for AES and SM4. arXiv, arXiv.2002.07041."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Marshall, B., Newell, G.R., Page, D., Saarinen, M.J.O., and Wolf, C. (2022, August 03). The Design of Scalar AES Instruction Set Extensions for RISC-V. Cryptology ePrint Archive, Available online: https:\/\/eprint.iacr.org\/2020\/930.","DOI":"10.46586\/tches.v2021.i1.109-136"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Marshall, B., Page, D., and Hung Pham, T. (2021, January 7\u20139). A lightweight ISE for ChaCha on RISC-V. Proceedings of the 2021 IEEE 32nd International Conference on Application-Specific Systems, Architectures and Processors (ASAP), Virtual.","DOI":"10.1109\/ASAP52443.2021.00011"},{"key":"ref_16","first-page":"3","article-title":"ChaCha, a Variant of Salsa20","volume":"Volume 8","author":"Bernstein","year":"2008","journal-title":"Workshop Record of SASC"},{"key":"ref_17","first-page":"1083","article-title":"A Fast and Compact Accelerator for Ascon and Friends","volume":"2020","author":"Steinegger","year":"2020","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"239","DOI":"10.46586\/tches.v2020.i4.239-280","article-title":"RISQ-V: Tightly Coupled RISC-V Accelerators for Post-Quantum Cryptography","volume":"2020","author":"Fritzmann","year":"2020","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"105165","DOI":"10.1016\/j.mejo.2021.105165","article-title":"An energy-efficient crypto-extension design for RISC-V","volume":"115","author":"Wang","year":"2021","journal-title":"Microelectron. J."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Schwabe, P., and Th\u00e9riault, N. (2019). Efficient Cryptography on the RISC-V Architecture. Progress in Cryptology\u2013LATINCRYPT 2019, Springer International Publishing.","DOI":"10.1007\/978-3-030-30530-7"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Kuo, Y.M., Garcia-Herrero, F., Ruano, O., and Maestro, J.A. (2022). RISC-V Galois Field ISA Extension for Non-Binary Error-Correction Codes and Classical and Post-Quantum Cryptography. IEEE Trans. Comput.","DOI":"10.1109\/TC.2022.3174587"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Saraiva, D.A.F., Leithardt, V.R.Q., de Paula, D., Sales Mendes, A., Gonz\u00e1lez, G.V., and Crocker, P. (2019). PRISEC: Comparison of Symmetric Key Algorithms for IoT Devices. Sensors, 19.","DOI":"10.3390\/s19194312"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Barker, E., and Mouha, N. (2017). Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher, NIST Special Publication 800-67 Revision 2; National Institute of Standards and Technology.","DOI":"10.6028\/NIST.SP.800-67r2"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Biham, E. (1997). New block encryption algorithm MISTY. Fast Software Encryption, Springer.","DOI":"10.1007\/BFb0052329"},{"key":"ref_25","unstructured":"Adams, C. (2022, August 03). The CAST-128 Encryption Algorithm. Available online: https:\/\/www.ietf.org\/rfc\/rfc2144.txt."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Goubin, L., and Matsui, M. (2006). HIGHT: A New Block Cipher Suitable for Low-Resource Device. Cryptographic Hardware and Embedded Systems-CHES 2006, Springer.","DOI":"10.1007\/11894063"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Paillier, P., and Verbauwhede, I. (2007). PRESENT: An Ultra-Lightweight Block Cipher. Cryptographic Hardware and Embedded Systems-CHES 2007, Springer.","DOI":"10.1007\/978-3-540-74735-2"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Stinson, D.R., and Tavares, S. (2001). Camellia: A 128-Bit Block Cipher Suitable for Multiple Platforms\u2014Design andAnalysis. Selected Areas in Cryptography, Springer.","DOI":"10.1007\/3-540-44983-3"},{"key":"ref_29","unstructured":"Lee, S., Yoon, J., Cheon, D.H., Lee, J., and Lee, H. (2022, July 24). The SEED Encryption Algorithm. RFC 4269. Available online: https:\/\/citeseerx.ist.psu.edu\/viewdoc\/summary?doi=10.1.1.374.1600."},{"key":"ref_30","unstructured":"Dworkin, M. (2022, August 03). SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions, Available online: https:\/\/www.nist.gov\/publications\/sha-3-standard-permutation-based-hash-and-extendable-output-functions."},{"key":"ref_31","unstructured":"Wolf, C., Glaser, J., and Kepler, J. (2013, January 10). Yosys-a free Verilog synthesis suite. Proceedings of the 21st Austrian Workshop on Microelectronics (Austrochip), Linz, Austria."},{"key":"ref_32","unstructured":"(2010). Information Security\u2014Lightweight Cryptography\u2014Part 3: Block Ciphers. Standard No. ISO\/IEC 18033-3:2010."},{"key":"ref_33","unstructured":"(2019). Information security\u2014Lightweight Cryptography\u2014Part 2: Block Ciphers. Standard No. ISO\/IEC 29192-2:2019."},{"key":"ref_34","unstructured":"Daemen, J., and Rijmen, V. (2022, August 03). AES Proposal: Rijndael 1999. AES Submission Document on Rijndael, Available online: https:\/\/csrc.nist.gov\/csrc\/media\/projects\/cryptographic-standards-and-guidelines\/documents\/aes-development\/rijndael-ammended.pdf."},{"key":"ref_35","unstructured":"Paar, C. (1994). Efficient VLSI Architectures for Bit-Parallel Computation in Galois Fields. [PhD Thesis, Institute for Experimental Mathematics, University of Duisburg-Essen]."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Rao, J.R., and Sunar, B. (2005). A Very Compact S-Box for AES. Cryptographic Hardware and Embedded Systems\u2013CHES 2005, Springer.","DOI":"10.1007\/11545262"},{"key":"ref_37","unstructured":"Gueron, S., and Kounavis, M.E. (2022, August 03). Intel\u00ae Carry-Less Multiplication Instruction and Its Usage for Computing the GCM Mode. White Paper, April 2014. Revision 2.02. Available online: https:\/\/www.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/clmul-wp-rev-2-02-2014-04-20.pdf."},{"key":"ref_38","unstructured":"(2022, July 24). RISC-V Cryptography Extensions Standardisation Work. Available online: https:\/\/github.com\/riscv\/riscv-crypto."}],"container-title":["Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2410-387X\/6\/3\/41\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:06:49Z","timestamp":1760141209000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2410-387X\/6\/3\/41"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,10]]},"references-count":38,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2022,9]]}},"alternative-id":["cryptography6030041"],"URL":"https:\/\/doi.org\/10.3390\/cryptography6030041","relation":{},"ISSN":["2410-387X"],"issn-type":[{"value":"2410-387X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,8,10]]}}}