Expand description
A bitsliced AES encryption path, four blocks at a time.
§Why
super::portable computes one S-box at a time, and an S-box is an
inversion in GF(2^8): seven squarings and six multiplications, with each
multiplication a bit-serial loop. That is a few hundred operations per byte,
and it is why the portable backend ran some twenty-five times behind
RustCrypto’s software AES, which is fixsliced.
Bitslicing pays the same algebra once for sixty-four bytes instead of once
per byte. The state is held transposed: eight u64 planes, where plane i
bit j is bit i of byte j. A field multiplication is then sixty-four
ANDs and a reduction on whole words, and each of those words carries four
blocks’ worth of work.
§Constant time
Nothing here indexes memory with a value derived from the key or the plaintext, and nothing branches on one. The S-box is computed, as it is in the byte-at-a-time path – that property is the reason both exist rather than a lookup table.
§What it does not do
Decryption. The inverse S-box and inverse MixColumns are a separate piece of work, and the modes that move volume – CTR, GCM, GCM-SIV – only ever run the forward direction. Decryption stays on the byte-at-a-time path.
§Trusting it
Every piece below was derived mechanically from the byte-at-a-time code rather than transcribed, and each is checked against it: the field operations over their entire domain, the round operations differentially.
Structs§
- Round
Keys - The round keys, transposed once so the round loop does not transpose them.
Constants§
- GROUP
- Bytes in a group.
- LANES
- Blocks processed together. Four blocks of sixteen bytes fill a
u64plane.
Functions§
- encrypt_
group - Encrypt exactly
GROUPbytes in place.