Skip to main content

Module bitslice

Module bitslice 

Source
Expand description

A bitsliced AES encryption path, four blocks at a time.

§Why

super::portable computes one S-box at a time, and an S-box is an inversion in GF(2^8): seven squarings and six multiplications, with each multiplication a bit-serial loop. That is a few hundred operations per byte, and it is why the portable backend ran some twenty-five times behind RustCrypto’s software AES, which is fixsliced.

Bitslicing pays the same algebra once for sixty-four bytes instead of once per byte. The state is held transposed: eight u64 planes, where plane i bit j is bit i of byte j. A field multiplication is then sixty-four ANDs and a reduction on whole words, and each of those words carries four blocks’ worth of work.

§Constant time

Nothing here indexes memory with a value derived from the key or the plaintext, and nothing branches on one. The S-box is computed, as it is in the byte-at-a-time path – that property is the reason both exist rather than a lookup table.

§What it does not do

Decryption. The inverse S-box and inverse MixColumns are a separate piece of work, and the modes that move volume – CTR, GCM, GCM-SIV – only ever run the forward direction. Decryption stays on the byte-at-a-time path.

§Trusting it

Every piece below was derived mechanically from the byte-at-a-time code rather than transcribed, and each is checked against it: the field operations over their entire domain, the round operations differentially.

Structs§

RoundKeys
The round keys, transposed once so the round loop does not transpose them.

Constants§

GROUP
Bytes in a group.
LANES
Blocks processed together. Four blocks of sixteen bytes fill a u64 plane.

Functions§

encrypt_group
Encrypt exactly GROUP bytes in place.