crypto: arm/chacha20 - faster 8-bit rotations and other optimizations
authorEric Biggers <ebiggers@google.com>
Sat, 1 Sep 2018 07:17:07 +0000 (00:17 -0700)
committerHerbert Xu <herbert@gondor.apana.org.au>
Tue, 4 Sep 2018 03:37:05 +0000 (11:37 +0800)
commita1b22a5f45fe884147a99e7c381bcc48d9b2acef
treea285e59c34660ad0b822769b2746334e428b916d
parent11dcb1037f40a19f298845a9b2ec093f7b8b958b
crypto: arm/chacha20 - faster 8-bit rotations and other optimizations

Optimize ChaCha20 NEON performance by:

- Implementing the 8-bit rotations using the 'vtbl.8' instruction.
- Streamlining the part that adds the original state and XORs the data.
- Making some other small tweaks.

On ARM Cortex-A7, these optimizations improve ChaCha20 performance from
about 12.08 cycles per byte to about 11.37 -- a 5.9% improvement.

There is a tradeoff involved with the 'vtbl.8' rotation method since
there is at least one CPU (Cortex-A53) where it's not fastest.  But it
seems to be a better default; see the added comment.  Overall, this
patch reduces Cortex-A53 performance by less than 0.5%.

Signed-off-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
arch/arm/crypto/chacha20-neon-core.S