From 261fe436f607a8bf4f16e1b139973aea024e5588 Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Thu, 16 Nov 2023 15:07:14 -0500 Subject: [PATCH] Don't prematurely run keccak_f in squeeze When squeezing a multiple of the rate bytes (e.g. in the Kyber XOF), we were running the Keccak permutation one more time than necessary. Before: Did 18900 Kyber generate + decap operations in 2001506us (9442.9 ops/sec) Did 32000 Kyber parse + encap operations in 2041500us (15674.7 ops/sec) After: Did 19796 Kyber generate + decap operations in 2017501us (9812.1 ops/sec) [+3.9%] Did 34000 Kyber parse + encap operations in 2032085us (16731.6 ops/sec) [+6.7%] Change-Id: I69787536508c4eadcc37a2f752c3678c60906c38 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/64007 Reviewed-by: Adam Langley Auto-Submit: David Benjamin Commit-Queue: Adam Langley Commit-Queue: David Benjamin --- crypto/keccak/keccak.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/crypto/keccak/keccak.c b/crypto/keccak/keccak.c index e4824044a..7ab8edcb7 100644 --- a/crypto/keccak/keccak.c +++ b/crypto/keccak/keccak.c @@ -240,6 +240,11 @@ void BORINGSSL_keccak_squeeze(struct BORINGSSL_keccak_st *ctx, uint8_t *out, // because we require |uint8_t| to be a character type. const uint8_t *state_bytes = (const uint8_t *)ctx->state; while (out_len) { + if (ctx->squeeze_offset == ctx->rate_bytes) { + keccak_f(ctx->state); + ctx->squeeze_offset = 0; + } + size_t remaining = ctx->rate_bytes - ctx->squeeze_offset; size_t todo = out_len; if (todo > remaining) { @@ -249,9 +254,5 @@ void BORINGSSL_keccak_squeeze(struct BORINGSSL_keccak_st *ctx, uint8_t *out, out += todo; out_len -= todo; ctx->squeeze_offset += todo; - if (ctx->squeeze_offset == ctx->rate_bytes) { - keccak_f(ctx->state); - ctx->squeeze_offset = 0; - } } }