I've loaded in fiat64 into the latest kbench curve testing branch, and it seems to be the fastest generic C version, at least on my Skylake laptop, inching out slightly in front of hacl64:
donna64: 121790 cycles per call hacl64: 109782 cycles per call fiat64: 108984 cycles per call sandy2x: 102996 cycles per call amd64: 108563 cycles per call fiat32: 232826 cycles per call donna32: 412092 cycles per call _______________________________________________ Curves mailing list Curves@moderncrypto.org https://moderncrypto.org/mailman/listinfo/curves