Edit: Removed my comment regarding BLAKE as it was incorrect.
Edit: Removed my comment regarding BLAKE as it was incorrect.
ChaCha20, Poly1305, BLAKE2 benefit from improvements that benefit a wide-range of applications, while SHA-3, AES and GHASH do not. Thus the "cost" of high performance support for the former can be amortised over a much wider base.
Also, sharing HW resource for cryptographic purposes is not possible for any device that needs to pass certain security certification.
Edit: Typo and additional comment
Most vulnerabilities in cryptosystems happen in the joinery. Anything we can do to eliminate joinery is going to make our cryptosystems more resilient. Selecting new primitives that will require hardware support to be performant seems like an own-goal.
As someone who has done a number of audits for certified devices, I don't think your statement about shared hardware is accurate. Are you talking about FIPS 140?
"As someone who has done a number of audits for certified devices, I don't think your statement about shared hardware is accurate. Are you talking about FIPS 140?"
Yes. Is my understanding incorrect? I'd like to be informed if this is the case. Thanks.
I really don't care about what the standards say; thankfully, the important standards, like TLS, aren't bound by what NIST standardizes.