This page reports measured performance when using the pure software cryptographic library algorithms with an STM32G4 MCU. In addition to performance figures, the required code footprint and memory are also given.
1. Measurement configuration
1.1. Hardware configuration
| STM32 MCU | STM32G474RET6 |
| Device ID | 0x469 |
| Revision ID | 0x2001 |
| Board | NUCLEO-G474RE RevC |
1.2. Firmware configuration
| Cryptographic library version | 050000B2[ver. 1] |
- ↑ This value corresponds to the information returned by a call to
cmox_getInfos
1.3. System configuration
| System core clock frequency | 170 MHz |
| Flash latency | 8 wait states |
| Voltage scaling | Range 0 |
| Dual bank | 0 (0: Single / 1: Dual) |
| Instruction cache (ART/ICU) | 1 (0: disabled / 1: enabled) |
| Data cache (ART/DCU) | 1 (0: disabled / 1: enabled) |
| Prefetch cache (ART) | 1 (0: disabled / 1: enabled) |
1.4. Development toolchains and compilers
| IAR Embedded Workbench | IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM |
2. Performance values
2.1. AES symmetric key encryption and decryption
This section provides the performance results for AES-CBC using different operation modes:
- Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
- Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.
2.1.1. Sole buffer mode
In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.
| AES mode | Key size | Buffer size | Cipher operation | Configuration | Cycles | Time |
|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 32 bytes | Encryption | Small | 4938 | 29 µs |
| AES CBC | 128 bits | 32 bytes | Encryption | Fast | 6247 | 36 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Small | 8042 | 47 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Fast | 10 512 | 61 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Small | 14 529 | 85 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Fast | 18 965 | 111 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Small | 5252 | 30 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Fast | 6818 | 40 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Small | 8856 | 52 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Fast | 11 691 | 68 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Small | 16 203 | 95 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Fast | 21 381 | 125 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Small | 5839 | 34 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Fast | 7891 | 46 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Small | 9411 | 55 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Fast | 13 471 | 79 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Small | 16 539 | 97 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Fast | 24 525 | 144 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Small | 5692 | 33 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Fast | 9189 | 54 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Small | 9771 | 57 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Fast | 13 351 | 78 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Small | 17 865 | 105 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Fast | 21 745 | 127 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Small | 6685 | 39 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Fast | 10 369 | 60 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Small | 11 537 | 67 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Fast | 15 227 | 89 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Small | 21 144 | 124 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Fast | 24 958 | 146 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Small | 7117 | 41 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Fast | 12 206 | 71 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Small | 12 434 | 73 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Fast | 17 833 | 104 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Small | 22 877 | 134 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Fast | 28 935 | 170 µs |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2302 bytes | 324 bytes | 0 bytes | 552 bytes |
| Encryption | Fast | 2246 bytes | 1092 bytes | 0 bytes | 552 bytes |
| Decryption | Small | 2650 bytes | 580 bytes | 0 bytes | 568 bytes |
| Decryption | Fast | 2600 bytes | 2372 bytes | 0 bytes | 568 bytes |
2.1.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_cipher_initcmox_cipher_setKeycmox_cipher_setIVcmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.
| AES mode | Key size | Message size | Chunk size | Cipher operation | Configuration | Cycles | Bit rate |
|---|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Small | 808 840 | 1681 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Fast | 1 078 448 | 1261 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Small | 796 024 | 1708 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Fast | 1 056 864 | 1286 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Small | 793 912 | 1713 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 1 052 944 | 1291 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Small | 792 728 | 1715 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 1 050 680 | 1294 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Small | 932 792 | 1457 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Fast | 1 249 880 | 1088 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Small | 916 480 | 1483 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Fast | 1 229 440 | 1106 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Small | 913 784 | 1488 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 1 225 744 | 1109 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Small | 912 464 | 1490 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 1 223 376 | 1111 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Small | 941 984 | 1443 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Fast | 1 423 744 | 955 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Small | 922 656 | 1474 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Fast | 1 404 720 | 968 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Small | 919 328 | 1479 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 1 401 184 | 970 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Small | 917 728 | 1481 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 1 398 800 | 972 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 068 600 | 1272 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Fast | 1 099 952 | 1236 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 051 816 | 1293 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Fast | 1 074 288 | 1265 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 047 816 | 1297 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 1 068 432 | 1272 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 043 848 | 1302 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 1 063 024 | 1279 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 260 816 | 1078 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Fast | 1 272 536 | 1068 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 243 432 | 1093 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Fast | 1 246 112 | 1091 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 239 248 | 1097 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 1 240 240 | 1096 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 235 112 | 1101 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 1 235 352 | 1100 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 352 168 | 1005 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Fast | 1 444 520 | 941 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 334 776 | 1018 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Fast | 1 418 928 | 958 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 330 608 | 1022 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 1 413 392 | 962 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 326 600 | 1025 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 1 408 712 | 965 Kbytes/s |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2222 bytes | 316 bytes | 0 bytes | 176 bytes |
| Encryption | Fast | 2166 bytes | 1084 bytes | 0 bytes | 176 bytes |
| Decryption | Small | 2570 bytes | 572 bytes | 0 bytes | 192 bytes |
| Decryption | Fast | 2520 bytes | 2364 bytes | 0 bytes | 192 bytes |
2.2. HASH digest
In this section we provide the performance results for HASH, using different modes of operation:
- Sole buffer: one sole buffer is hashed. The performance time is given in us.
- Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.
2.2.1. Sole buffer mode
In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.
| HASH mode | Buffer size | Cycles | Time |
|---|---|---|---|
| SHA256 | 32 bytes | 5061 | 29 µs |
| SHA256 | 64 bytes | 8378 | 49 µs |
| SHA256 | 128 bytes | 11 498 | 67 µs |
| SHA384 | 32 bytes | 18 708 | 110 µs |
| SHA384 | 64 bytes | 18 935 | 111 µs |
| SHA384 | 128 bytes | 35 658 | 209 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1358 | 280 bytes | 0 bytes | 532 bytes |
| SHA384 | 2504 | 728 bytes | 0 bytes | 1076 bytes |
2.2.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_hash_initcmox_hash_append: called several times to hash the whole message in fixed-size chunkscmox_hash_generateTag
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.
| HASH mode | Message size | Chunk size | Cycles | Bit rate |
|---|---|---|---|---|
| SHA256 | 8000 bytes | 128 bytes | 421 826 | 3224 Kbytes/s |
| SHA256 | 8000 bytes | 512 bytes | 396 679 | 3428 Kbytes/s |
| SHA256 | 8000 bytes | 1024 bytes | 392 401 | 3465 Kbytes/s |
| SHA256 | 8000 bytes | 2048 bytes | 390 259 | 3484 Kbytes/s |
| SHA384 | 8000 bytes | 128 bytes | 1 074 447 | 1265 Kbytes/s |
| SHA384 | 8000 bytes | 512 bytes | 1 023 271 | 1329 Kbytes/s |
| SHA384 | 8000 bytes | 1024 bytes | 1 014 394 | 1340 Kbytes/s |
| SHA384 | 8000 bytes | 2048 bytes | 1 009 963 | 1346 Kbytes/s |
The table below shows the final tag generation done through the call to cmox_hash_generateTag.
| HASH mode | Cycles | Time |
|---|---|---|
| SHA256 | 3883 | 22 µs |
| SHA384 | 17 248 | 101 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1354 bytes | 272 bytes | 0 bytes | 340 bytes |
| SHA384 | 2500 bytes | 720 bytes | 0 bytes | 780 bytes |
2.3. ECDSA signature and verification
This section provides the performance results for ECDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 3 129 000 | 18 ms |
| SECP256R1 | Signature | Small | High | 3 022 392 | 17 ms |
| SECP256R1 | Signature | SuperFast | Low | 3 015 808 | 17 ms |
| SECP256R1 | Signature | SuperFast | High | 2 921 992 | 17 ms |
| SECP256R1 | Verification | Small | Low | 7 627 192 | 44 ms |
| SECP256R1 | Verification | Small | High | 6 721 640 | 39 ms |
| SECP256R1 | Verification | SuperFast | Low | 7 363 440 | 43 ms |
| SECP256R1 | Verification | SuperFast | High | 6 496 232 | 38 ms |
| SECP384R1 | Signature | Small | Low | 8 488 968 | 49 ms |
| SECP384R1 | Signature | Small | High | 8 093 304 | 47 ms |
| SECP384R1 | Signature | Fast | Low | 8 483 720 | 49 ms |
| SECP384R1 | Signature | Fast | High | 7 987 312 | 46 ms |
| SECP384R1 | Verification | Small | Low | 20 529 736 | 120 ms |
| SECP384R1 | Verification | Small | High | 17 754 552 | 104 ms |
| SECP384R1 | Verification | Fast | Low | 20 544 848 | 120 ms |
| SECP384R1 | Verification | Fast | High | 17 595 712 | 103 ms |
The table below shows ECDSA flash memory and RAM usage (in bytes).
| Curve | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 13 442 bytes | 1212 bytes | 0 bytes | 440 bytes | 628 bytes |
| SECP256R1 | Signature | Small | High | 13 442 bytes | 1596 bytes | 0 bytes | 440 bytes | 696 bytes |
| SECP256R1 | Signature | SuperFast | Low | 14 752 bytes | 1212 bytes | 0 bytes | 444 bytes | 628 bytes |
| SECP256R1 | Signature | SuperFast | High | 14 752 bytes | 1596 bytes | 0 bytes | 444 bytes | 696 bytes |
| SECP256R1 | Verification | Small | Low | 13 430 bytes | 1212 bytes | 0 bytes | 488 bytes | 856 bytes |
| SECP256R1 | Verification | Small | High | 13 430 bytes | 1596 bytes | 0 bytes | 488 bytes | 1648 bytes |
| SECP256R1 | Verification | SuperFast | Low | 14 740 bytes | 1212 bytes | 0 bytes | 492 bytes | 856 bytes |
| SECP256R1 | Verification | SuperFast | High | 14 740 bytes | 1596 bytes | 0 bytes | 492 bytes | 1648 bytes |
| SECP384R1 | Signature | Small | Low | 13 442 bytes | 1692 bytes | 0 bytes | 440 bytes | 884 bytes |
| SECP384R1 | Signature | Small | High | 13 442 bytes | 2268 bytes | 0 bytes | 440 bytes | 984 bytes |
| SECP384R1 | Signature | Fast | Low | 13 812 bytes | 1692 bytes | 0 bytes | 456 bytes | 884 bytes |
| SECP384R1 | Signature | Fast | High | 13 812 bytes | 2268 bytes | 0 bytes | 456 bytes | 984 bytes |
| SECP384R1 | Verification | Small | Low | 13 430 bytes | 1692 bytes | 0 bytes | 488 bytes | 1192 bytes |
| SECP384R1 | Verification | Small | High | 13 430 bytes | 2268 bytes | 0 bytes | 488 bytes | 2272 bytes |
| SECP384R1 | Verification | Fast | Low | 13 800 bytes | 1692 bytes | 0 bytes | 504 bytes | 1192 bytes |
| SECP384R1 | Verification | Fast | High | 13 800 bytes | 2268 bytes | 0 bytes | 504 bytes | 2272 bytes |
2.4. EdDSA signature and verification
This section provides the performance results for EdDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 4 954 240 | 29 ms |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 2 888 976 | 16 ms |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptLow | 4 804 744 | 28 ms |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptHigh | 2 813 952 | 16 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 7 390 072 | 43 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 6 490 056 | 38 ms |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptLow | 7 114 264 | 41 ms |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptHigh | 6 268 144 | 36 ms |
The table below shows EdDSA flash memory and RAM usage (in bytes).
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 14 752 bytes | 1748 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 15 172 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptLow | 16 062 bytes | 1748 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptHigh | 16 482 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 14 748 bytes | 1748 bytes | 0 bytes | 1172 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 15 168 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1992 bytes |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptLow | 16 058 bytes | 1748 bytes | 0 bytes | 1172 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptHigh | 16 478 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1992 bytes |
2.5. RSA signature and verification
This section provides the performance results for RSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Cycles | Time |
|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 187 613 064 | 1103 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 141 259 120 | 830 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 118 646 368 | 697 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Low | 186 906 640 | 1099 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Mid | 141 048 128 | 829 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | High | 118 335 696 | 696 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 713 470 488 | 4196 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 535 916 712 | 3152 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 448 309 792 | 2637 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Low | 712 248 424 | 4189 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Mid | 535 318 584 | 3148 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | High | 447 677 088 | 2633 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 3 737 672 | 21 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Fast | n/a | 3 732 880 | 21 ms |
The table below shows RSA flash memory and RAM usage (in bytes).
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 6850 bytes | 372 bytes | 0 bytes | 668 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 7086 bytes | 372 bytes | 0 bytes | 668 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 7086 bytes | 372 bytes | 0 bytes | 668 bytes | 6708 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Low | 7220 bytes | 372 bytes | 0 bytes | 668 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Mid | 7456 bytes | 372 bytes | 0 bytes | 668 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | High | 7456 bytes | 372 bytes | 0 bytes | 668 bytes | 6708 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 5918 bytes | 364 bytes | 0 bytes | 668 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 6154 bytes | 364 bytes | 0 bytes | 668 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 6154 bytes | 364 bytes | 0 bytes | 668 bytes | 9368 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Low | 6288 bytes | 364 bytes | 0 bytes | 668 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Mid | 6524 bytes | 364 bytes | 0 bytes | 668 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | High | 6524 bytes | 364 bytes | 0 bytes | 668 bytes | 9368 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 6102 bytes | 368 bytes | 0 bytes | 684 bytes | 3108 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Fast | n/a | 6472 bytes | 368 bytes | 0 bytes | 684 bytes | 3108 bytes |
2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification
This section provides the performance results for ML-DSA key pair generation, signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites and functions configurations. Note: For signature generation, the number of clock cycles is not bounded in time. The measurement was taken using one predefined private key and one 32-byte message, and the reported value corresponds to the minimum observed time.
| Suite | Function | Cycles | Time (in ms) | Stack usage | Working buffer |
|---|---|---|---|---|---|
| ML-DSA-44 | keyGen | 2 662 480 | 15 | 476 | 7116 |
| ML-DSA-65 | keyGen | 4 683 568 | 27 | 476 | 8140 |
| ML-DSA-87 | keyGen | 7 918 272 | 46 | 476 | 10 188 |
| ML-DSA-44 | Signature | 4 367 168 | 25 | 772 | 30 796 |
| ML-DSA-44 | Signature Low RAM | 4 755 568 | 27 | 756 | 11 340 |
| ML-DSA-44 | Verification | 2 915 632 | 17 | 700 | 8908 |
| ML-DSA-44 | Verification Low RAM | 3 782 504 | 22 | 700 | 4812 |
| ML-DSA-65 | Verification | 4 857 016 | 28 | 700 | 9948 |
| ML-DSA-65 | Verification Low RAM | 6 612 248 | 38 | 700 | 4828 |
| ML-DSA-87 | Verification | 8 176 928 | 48 | 700 | 12 268 |
| ML-DSA-87 | Verification Low RAM | 11 435 632 | 67 | 700 | 5100 |
2.7. Post-Quantum Cryptography ML-KEM key pair generation, encapsulation, decapsulation
This section provides the performance results for ML-KEM key pair generation, encapsulation and decapsulation.
The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different functions and suites.
| Function | Suites | Cycles | Time (in ms) | Stack usage |
|---|---|---|---|---|
| Key-pair-Generation | ML-KEM-512 | 833 496 | 5 | 3 060 |
| Key-pair-Generation | ML-KEM-768 | 1 366 000 | 8 | 3 572 |
| Key-pair-Generation | ML-KEM-1024 | 2 150 984 | 13 | 4 084 |
| Key-Encapsulation | ML-KEM-512 | 2321368 | 14 | 4 588 |
| Key-Encapsulation | ML-KEM-768 | 3 380 336 | 20 | 5 100 |
| Key-Encapsulation | ML-KEM-1024 | 4 654 112 | 27 | 5 612 |
| Key-Decapsulation | ML-KEM-512 | 2 639 024 | 16 | 4 684 |
| Key-Decapsulation | ML-KEM-768 | 3 814 712 | 22 | 5 516 |
| Key-Decapsulation | ML-KEM-1024 | 5 209 576 | 31 | 6 508 |
2.8. Post-Quantum Cryptography HBS-LMS signature verification
This section provides the performance results for ML-LMS signature verification.
The table below shows the number of clock cycles minimum, average and maximum and average time (in ms) needed to perform the described function in different functions and suite. Note: Clock cycles were measured for 10 different generated key and message pairs, and the reported Cycles avg values are averages over these measurements.
| Function | Suite | Cycles min | Cycles avg | Time avg (in ms) | Cycles max | Stack usage |
|---|---|---|---|---|---|---|
| LMS-Verify | LMS_N32_H10_W1_SHA256 | 1 251 544 | 1 306 564 | 8 | 1 582 280 | 1 668 |
| LMS-Verify | LMS_N32_H10_W2_SHA256 | 1 280 720 | 1 367 754 | 8 | 1 491 336 | 1 668 |
| LMS-Verify | LMS_N32_H10_W4_SHA256 | 2 196 408 | 2 548 531 | 15 | 2 956 624 | 1 668 |
| LMS-Verify | LMS_N32_H10_W8_SHA256 | 19 008 408 | 21 830 974 | 128 | 24 888 584 | 1 668 |