# Gnarl-Hamadryad Benchmarks AMD Ryzen 5 7520U, linux/amd64, Go 1.24 ``` go test -bench=. ./crypto/ ./crypto/ring/ ``` --- ## Hash Functions | Benchmark | Time | Ops/sec | Notes | |-----------|-----:|--------:|-------| | SHA-256 (32 B) | 75 ns | 13.3M | Standard reference | | SHA-256 (128 B) | 139 ns | 7.2M | Standard reference | | GnarlMid (128 B) | 2.1 us | 474K | 27-byte lattice hash, Z_271 | | GnarlHash (128 B) | 2.4 us | 424K | 31-byte lattice hash, Z_271 | | Hamadryad (128 B) | 65 us | 15.3K | 56-byte SWIFFT, Z_257 | | Hamadryad (1 KB) | 298 us | 3.4K | Merkle-Damgard chaining | | Ring SIS (128 B) | 70 us | 14.2K | Formal SIS interface | SHA-256 is 15-30x faster per call. Gnarl hashes provide SVP-hard collision resistance and algebraic homomorphism that SHA-256 lacks. The hash cost is amortized in sign/verify where the torus algebra dominates. --- ## Signatures: Schnorr Family ### Key Generation | Scheme | Time | vs BIP-340 | |--------|-----:|-----------:| | **Gnarl** (SL(2,Z_P) torus, Z_271) | **6.5 us** | **10.3x faster** | | Cayley (SL(2,Z_p), Z_256) | 16.4 us | 4.1x faster | | BIP-340 (secp256k1, btcec pure Go) | 67.1 us | baseline | ### Signing | Scheme | Time | vs BIP-340 | |--------|-----:|-----------:| | **Gnarl** | **8.3 us** | **25.8x faster** | | Cayley | 17.8 us | 12.0x faster | | BIP-340 (btcec) | 214.4 us | baseline | ### Verification | Scheme | Time | vs BIP-340 | |--------|-----:|-----------:| | **Gnarl** | **35.8 us** | **4.2x faster** | | Cayley | 85.7 us | 1.7x faster | | BIP-340 (btcec) | 149.5 us | baseline | ### Wire Sizes | | BIP-340 | Gnarl | Savings | |--|-------:|------:|--------:| | Secret key | 32 B | 27 B | -16% | | Public key | 32 B | 27 B | -16% | | Signature | 64 B | 54 B | -16% | | Pubkey + sig | 96 B | 81 B | -16% | --- ## Signatures: Ring/GPV (Lattice) | Operation | Time | |-----------|-----:| | KeyGen | 12.7 us | | Sign | 33.3 us | | Verify | 9.1 us | GPV verification is the fastest of all signature schemes benchmarked -- 4x faster than Gnarl verify, 16x faster than BIP-340 verify. This is because verification is a single NTT multiply + norm check, no exponentiation. --- ## Key Encapsulation (Ring-LWE KEM) | Operation | Time | |-----------|-----:| | KeyGen | 115 us | | Encapsulate | 261 us | | Decapsulate | 423 us | CCA2-secure via Fujisaki-Okamoto transform over Falcon-512 ring (n=512, q=12289). Comparable to ML-KEM/Kyber. Happens once per session -- not the critical path. --- ## Homomorphic Encryption (BGV, HE64 ring) | Operation | Time | Notes | |-----------|-----:|-------| | Encrypt (1 bit) | 14.3 us | | | Add / XOR | 413 ns | Linear, no noise blowup | | Multiply / AND | 54.8 us | Quadratic noise, requires relinearization | HE64 ring: n=64, q=10,000,769. Depth-1 multiplicative circuits. Addition is ~130x cheaper than multiplication because it's just coefficient-wise add with no relinearization. --- ## Authenticated Encryption (GnarlWire) | Operation | Time | |-----------|-----:| | Seal (128 B) | 41.1 us | | Open (128 B) | 39.2 us | ChaCha20 + GnarlMid MAC. 64-byte fixed header. Symmetric, so these are the per-packet costs for encrypted transport. --- ## Ring Internals | Operation | Time | |-----------|-----:| | NTT-27 (forward) | 289 ns | | INTT-27 (inverse) | 265 ns | | mod 271 | 0.25 ns | | Gnarl compress | 482 ns | The n=27 NTT completes in under 300 ns. This is the core operation that would need to run in-EVM for on-chain verification. At ~135 mulmod operations per transform, this is tractable.