Check vl first
The current vl determines the number of body elements. Typical code executes vsetvli, vsetivli, or vsetvl before this instruction.
Vector AES final-round encryption using one scalar 128-bit round-key element group from vs2 for all state groups.
vaesef.vs performs AES final-round encryption. Each 128-bit element group in vd undergoes SubBytes, then ShiftRows, then XOR with the scalar 128-bit round-key element group from vs2; the new state is written back to vd. SEW must be 32.
This bounded model shows only official ISA-visible fields, state, and conditions; it does not model a complete cryptographic protocol or microarchitecture.
state -> SubBytes, ShiftRows, then AddRoundKey -> vd
VAESEF.VS is a Zvkned vector instruction for vector AES final-round encryption. This page is checked against the official vector crypto extension and V-extension execution model.
When reading VAESEF.VS, do not stop at the mnemonic. Official V-extension semantics also depend on the current vl, vtype, and mask state. The suffix and operand form determine whether sources are vector, scalar, or immediate values.
The current vl determines the number of body elements. Typical code executes vsetvli, vsetivli, or vsetvl before this instruction.
The current vtype supplies SEW, LMUL, tail policy, and mask policy; these affect element width, register-group size, and inactive/tail destination elements.
For ordinary vector instructions with vm, vm=0 uses v0 as the execution mask and vm=1 is unmasked. A few forms such as VMERGE use v0 as data-selection input.
Understand this scenario with real code like «vaesef.vs vd, vs2».
Understand this scenario with real code like «vaesef.vs vd, vs2».
No. This element-group crypto instruction has no vm operand; ordinary RVV mask syntax should not be added to examples.
This instruction fixes SEW=32 and executes on 128-bit element groups; encodings with other SEW values are reserved.