p256 benchmarks
The generated measurement tables for the p256 module — every case, the harness that measured it, and how to reproduce it.
Micro-benchmarks of the p256 module (tests/benchmarks/p256_bench.cpp, release build, one core):
Measured by tests/benchmarks/p256_bench.cpp; reproduce with scripts/bench_run.sh publish p256.
Op | median | spread | throughput |
|---|---|---|---|
| 69.45 µs | ±116.48 ns IQR | 14.4 k/s |
| 109.44 µs | ±474.81 ns IQR | 9.1 k/s |
Verification runs once per P-256 chain link plus once for CertificateVerify — negligible next to a network round trip; signing is the per-message JWT path.
Both figures rose about a fifth when the field arithmetic became constant-time: each modular reduction now computes its result whether or not it is needed and selects with a mask, and the multi-limb compare always reads every limb instead of stopping at the first difference. That cost buys a signing path whose timing does not depend on the private key. Verification moved too, sharing the same arithmetic, even though it handles only public data and gains nothing from the change.
