VGHSH.VV

RISC-V VGHSH.VV Instruction Details

Instruction ManualOP-VE OPMVV (funct6=101100, vm=1, funct3=010)

Vector GHASH add-multiply: update partial hash in vd using ciphertext vs1 and hash subkey vs2.

Instruction Syntax

vghsh.vv vd, vs2, vs1
Operand Breakdown
vd: destination vector register group.
vs2/vs1 or scalar source: selected by suffixes such as .vv, .vx, .vi, or .vf.
vm: when present, vm=0 uses v0 as the execution mask and vm=1 is unmasked.
ZvkgVector CryptoGCM/GHASH

Instruction Behavior

vghsh.vv performs a GHASH add-multiply over 128-bit element groups with SEW=32. It reads partial hash Y_i from vd, ciphertext X_i from vs1, hash subkey H from vs2, and writes updated partial hash Y_{i+1} to vd.

VGHSH.VV Decode & Execute Animation

This bounded model shows ISA-visible state for one 128-bit element group; it does not model a pipeline, cryptographic protocol, or unspecified implementation detail.

Bounded execution context
32-bit OP-VE encoding fields
31..26
funct6
101100
25
vm
1
24..20
vs2
01000
19..15
vs1
01100
14..12
funct3
010
11..7
vd
00100
6..0
OP-VE
1110111
Execution data path

funct6=101100, funct3=010, Zvkg

v4[0..3] <- pending

Quick Understanding & Search Notes

VGHSH.VV is a Zvkg vector instruction for vector GHASH add-multiply. This page is checked against the official vector crypto extension and V-extension execution model.

Performs the GHASH ((Y_i XOR X_i) · H) update over 128-bit element groups with SEW=32.
This element-group crypto instruction has no vm mask operand and executes at element-group granularity.
SEW=32, EGW=128, EGS=4; vl and vstart must be multiples of 4, and LMUL*VLEN must hold at least one element group.

Vector Execution Context

When reading VGHSH.VV, do not stop at the mnemonic. Official V-extension semantics also depend on the current vl, vtype, and mask state. .vv: two vector sources participate element by element.

Check vl first

The current vl determines the number of body elements. Typical code executes vsetvli, vsetivli, or vsetvl before this instruction.

Then check vtype

The current vtype supplies SEW, LMUL, tail policy, and mask policy; these affect element width, register-group size, and inactive/tail destination elements.

Then check vm/v0

For ordinary vector instructions with vm, vm=0 uses v0 as the execution mask and vm=1 is unmasked. A few forms such as VMERGE use v0 as data-selection input.

Official source: RISC-V V Standard Extension for Vector Operations

Common Usage Scenarios

Crypto & Security

Understand this scenario with real code like «vghsh.vv vd, vs2, vs1».

Vector Acceleration

Understand this scenario with real code like «vghsh.vv vd, vs2, vs1».

Pre-Use Checklist

Syntax Check
  • Confirm the current instruction format is OP-VE OPMVV (funct6=101100, vm=1, funct3=010).
  • Confirm the operand order matches the example.
Semantic Check
  • Ensure the destination register usage is compatible with the calling convention.
  • Confirm this is not the lower-level form of a pseudo-instruction expansion.

Pitfalls / Common Confusions

No vm operand; this element-group crypto instruction is not maskable.
Requires SEW=32, EGW=128. Operates on 128-bit group granularity.
GHASH uses a special polynomial in GF(2^128), not ordinary integer arithmetic.
SEW=32, EGW=128, EGS=4; vl and vstart must be multiples of 4, and LMUL*VLEN must be at least 128.

FAQ

Can VGHSH.VV always use a v0.t mask?

No. This element-group crypto instruction has no vm operand; ordinary RVV mask syntax should not be added to examples.

What determines the element width for VGHSH.VV?

This instruction fixes SEW=32 and executes on 128-bit element groups; other SEW values are reserved/illegal cases.