While batch verification is out of scope atm for bs255, 4-way parallel keccak (AVX2) fits in nicely when re-deriving the `e` values.
If ds/msg in a batch are the same, `e = H(ds, msg, R, P) mod n` would allow more optimization for large ds and msg, but large is like > 89-ish bytes combined...
over 1 year ago