Gnarl-Hamadryad Benchmarks
AMD Ryzen 5 7520U, linux/amd64, Go 1.24
go test -bench=. ./crypto/ ./crypto/ring/
Hash Functions
| Benchmark | Time | Ops/sec | Notes |
| SHA-256 (32 B) | 75 ns | 13.3M | Standard reference |
| SHA-256 (128 B) | 139 ns | 7.2M | Standard reference |
| GnarlMid (128 B) | 2.1 us | 474K | 27-byte lattice hash, Z_271 |
| GnarlHash (128 B) | 2.4 us | 424K | 31-byte lattice hash, Z_271 |
| Hamadryad (128 B) | 65 us | 15.3K | 56-byte SWIFFT, Z_257 |
| Hamadryad (1 KB) | 298 us | 3.4K | Merkle-Damgard chaining |
| Ring SIS (128 B) | 70 us | 14.2K | Formal SIS interface |
SHA-256 is 15-30x faster per call. Gnarl hashes provide SVP-hard collision resistance and algebraic homomorphism that SHA-256 lacks. The hash cost is amortized in sign/verify where the torus algebra dominates.
Signatures: Schnorr Family
Key Generation
| Scheme | Time | vs BIP-340 |
| Gnarl (SL(2,ZP) torus, Z271) | 6.5 us | 10.3x faster |
| Cayley (SL(2,Zp), Z256) | 16.4 us | 4.1x faster |
| BIP-340 (secp256k1, btcec pure Go) | 67.1 us | baseline |
Signing
| Scheme | Time | vs BIP-340 |
| Gnarl | 8.3 us | 25.8x faster |
| Cayley | 17.8 us | 12.0x faster |
| BIP-340 (btcec) | 214.4 us | baseline |
Verification
| Scheme | Time | vs BIP-340 |
| Gnarl | 35.8 us | 4.2x faster |
| Cayley | 85.7 us | 1.7x faster |
| BIP-340 (btcec) | 149.5 us | baseline |
Wire Sizes
| BIP-340 | Gnarl | Savings |
| Secret key | 32 B | 27 B | -16% |
| Public key | 32 B | 27 B | -16% |
| Signature | 64 B | 54 B | -16% |
| Pubkey + sig | 96 B | 81 B | -16% |
Signatures: Ring/GPV (Lattice)
| Operation | Time |
| KeyGen | 12.7 us |
| Sign | 33.3 us |
| Verify | 9.1 us |
GPV verification is the fastest of all signature schemes benchmarked -- 4x faster than Gnarl verify, 16x faster than BIP-340 verify. This is because verification is a single NTT multiply + norm check, no exponentiation.
Key Encapsulation (Ring-LWE KEM)
| Operation | Time |
| KeyGen | 115 us |
| Encapsulate | 261 us |
| Decapsulate | 423 us |
CCA2-secure via Fujisaki-Okamoto transform over Falcon-512 ring (n=512, q=12289). Comparable to ML-KEM/Kyber. Happens once per session -- not the critical path.
Homomorphic Encryption (BGV, HE64 ring)
| Operation | Time | Notes |
| Encrypt (1 bit) | 14.3 us | |
| Add / XOR | 413 ns | Linear, no noise blowup |
| Multiply / AND | 54.8 us | Quadratic noise, requires relinearization |
HE64 ring: n=64, q=10,000,769. Depth-1 multiplicative circuits. Addition is ~130x cheaper than multiplication because it's just coefficient-wise add with no relinearization.
Authenticated Encryption (GnarlWire)
| Operation | Time |
| Seal (128 B) | 41.1 us |
| Open (128 B) | 39.2 us |
ChaCha20 + GnarlMid MAC. 64-byte fixed header. Symmetric, so these are the per-packet costs for encrypted transport.
Ring Internals
| Operation | Time |
| NTT-27 (forward) | 289 ns |
| INTT-27 (inverse) | 265 ns |
| mod 271 | 0.25 ns |
| Gnarl compress | 482 ns |
The n=27 NTT completes in under 300 ns. This is the core operation that would need to run in-EVM for on-chain verification. At ~135 mulmod operations per transform, this is tractable.