Cryptographic performance on STM32G4 Series V5.x

This page reports measured performance when using the pure software cryptographic library algorithms with an STM32G4 MCU. In addition to performance figures, the required code footprint and memory are also given.


1. Measurement configuration

1.1. Hardware configuration

STM32 MCU STM32G474RET6
Device ID 0x469
Revision ID 0x2001
Board NUCLEO-G474RE RevC

1.2. Firmware configuration

Cryptographic library version 050000B2[ver. 1]
  1. This value corresponds to the information returned by a call to cmox_getInfos

1.3. System configuration

System core clock frequency 170 MHz
Flash latency 8 wait states
Voltage scaling Range 0
Dual bank 0 (0: Single / 1: Dual)
Instruction cache (ART/ICU) 1 (0: disabled / 1: enabled)
Data cache (ART/DCU) 1 (0: disabled / 1: enabled)
Prefetch cache (ART) 1 (0: disabled / 1: enabled)

1.4. Development toolchains and compilers

IAR Embedded Workbench IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM
Information
The measurements are done using a project built with the High Speed optimization setting enabled.


2. Performance values

2.1. AES symmetric key encryption and decryption

This section provides the performance results for AES-CBC using different operation modes:

  • Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
  • Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.

2.1.1. Sole buffer mode

In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.

AES mode Key size Buffer size Cipher operation Configuration Cycles Time
AES CBC 128 bits 32 bytes Encryption Small 4938 29 µs
AES CBC 128 bits 32 bytes Encryption Fast 6247 36 µs
AES CBC 128 bits 64 bytes Encryption Small 8042 47 µs
AES CBC 128 bits 64 bytes Encryption Fast 10 512 61 µs
AES CBC 128 bits 128 bytes Encryption Small 14 529 85 µs
AES CBC 128 bits 128 bytes Encryption Fast 18 965 111 µs
AES CBC 192 bits 32 bytes Encryption Small 5252 30 µs
AES CBC 192 bits 32 bytes Encryption Fast 6818 40 µs
AES CBC 192 bits 64 bytes Encryption Small 8856 52 µs
AES CBC 192 bits 64 bytes Encryption Fast 11 691 68 µs
AES CBC 192 bits 128 bytes Encryption Small 16 203 95 µs
AES CBC 192 bits 128 bytes Encryption Fast 21 381 125 µs
AES CBC 256 bits 32 bytes Encryption Small 5839 34 µs
AES CBC 256 bits 32 bytes Encryption Fast 7891 46 µs
AES CBC 256 bits 64 bytes Encryption Small 9411 55 µs
AES CBC 256 bits 64 bytes Encryption Fast 13 471 79 µs
AES CBC 256 bits 128 bytes Encryption Small 16 539 97 µs
AES CBC 256 bits 128 bytes Encryption Fast 24 525 144 µs
AES CBC 128 bits 32 bytes Decryption Small 5692 33 µs
AES CBC 128 bits 32 bytes Decryption Fast 9189 54 µs
AES CBC 128 bits 64 bytes Decryption Small 9771 57 µs
AES CBC 128 bits 64 bytes Decryption Fast 13 351 78 µs
AES CBC 128 bits 128 bytes Decryption Small 17 865 105 µs
AES CBC 128 bits 128 bytes Decryption Fast 21 745 127 µs
AES CBC 192 bits 32 bytes Decryption Small 6685 39 µs
AES CBC 192 bits 32 bytes Decryption Fast 10 369 60 µs
AES CBC 192 bits 64 bytes Decryption Small 11 537 67 µs
AES CBC 192 bits 64 bytes Decryption Fast 15 227 89 µs
AES CBC 192 bits 128 bytes Decryption Small 21 144 124 µs
AES CBC 192 bits 128 bytes Decryption Fast 24 958 146 µs
AES CBC 256 bits 32 bytes Decryption Small 7117 41 µs
AES CBC 256 bits 32 bytes Decryption Fast 12 206 71 µs
AES CBC 256 bits 64 bytes Decryption Small 12 434 73 µs
AES CBC 256 bits 64 bytes Decryption Fast 17 833 104 µs
AES CBC 256 bits 128 bytes Decryption Small 22 877 134 µs
AES CBC 256 bits 128 bytes Decryption Fast 28 935 170 µs


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2302 bytes 324 bytes 0 bytes 552 bytes
Encryption Fast 2246 bytes 1092 bytes 0 bytes 552 bytes
Decryption Small 2650 bytes 580 bytes 0 bytes 568 bytes
Decryption Fast 2600 bytes 2372 bytes 0 bytes 568 bytes


2.1.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_cipher_init
  • cmox_cipher_setKey
  • cmox_cipher_setIV
  • cmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.

AES mode Key size Message size Chunk size Cipher operation Configuration Cycles Bit rate
AES CBC 128 bits 8000 bytes 128 bytes Encryption Small 808 840 1681 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Encryption Fast 1 078 448 1261 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Small 796 024 1708 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Fast 1 056 864 1286 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Small 793 912 1713 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Fast 1 052 944 1291 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Small 792 728 1715 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Fast 1 050 680 1294 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Small 932 792 1457 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Fast 1 249 880 1088 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Small 916 480 1483 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Fast 1 229 440 1106 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Small 913 784 1488 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Fast 1 225 744 1109 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Small 912 464 1490 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Fast 1 223 376 1111 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Small 941 984 1443 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Fast 1 423 744 955 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Small 922 656 1474 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Fast 1 404 720 968 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Small 919 328 1479 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Fast 1 401 184 970 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Small 917 728 1481 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Fast 1 398 800 972 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Small 1 068 600 1272 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Fast 1 099 952 1236 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Small 1 051 816 1293 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Fast 1 074 288 1265 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Small 1 047 816 1297 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Fast 1 068 432 1272 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Small 1 043 848 1302 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Fast 1 063 024 1279 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Small 1 260 816 1078 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Fast 1 272 536 1068 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Small 1 243 432 1093 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Fast 1 246 112 1091 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Small 1 239 248 1097 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Fast 1 240 240 1096 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Small 1 235 112 1101 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Fast 1 235 352 1100 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Small 1 352 168 1005 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Fast 1 444 520 941 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Small 1 334 776 1018 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Fast 1 418 928 958 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Small 1 330 608 1022 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Fast 1 413 392 962 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Small 1 326 600 1025 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Fast 1 408 712 965 Kbytes/s


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2222 bytes 316 bytes 0 bytes 176 bytes
Encryption Fast 2166 bytes 1084 bytes 0 bytes 176 bytes
Decryption Small 2570 bytes 572 bytes 0 bytes 192 bytes
Decryption Fast 2520 bytes 2364 bytes 0 bytes 192 bytes


2.2. HASH digest

In this section we provide the performance results for HASH, using different modes of operation:

  • Sole buffer: one sole buffer is hashed. The performance time is given in us.
  • Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.

2.2.1. Sole buffer mode

In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.

HASH mode Buffer size Cycles Time
SHA256 32 bytes 5061 29 µs
SHA256 64 bytes 8378 49 µs
SHA256 128 bytes 11 498 67 µs
SHA384 32 bytes 18 708 110 µs
SHA384 64 bytes 18 935 111 µs
SHA384 128 bytes 35 658 209 µs


The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1358 280 bytes 0 bytes 532 bytes
SHA384 2504 728 bytes 0 bytes 1076 bytes


2.2.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_hash_init
  • cmox_hash_append: called several times to hash the whole message in fixed-size chunks
  • cmox_hash_generateTag

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.

HASH mode Message size Chunk size Cycles Bit rate
SHA256 8000 bytes 128 bytes 421 826 3224 Kbytes/s
SHA256 8000 bytes 512 bytes 396 679 3428 Kbytes/s
SHA256 8000 bytes 1024 bytes 392 401 3465 Kbytes/s
SHA256 8000 bytes 2048 bytes 390 259 3484 Kbytes/s
SHA384 8000 bytes 128 bytes 1 074 447 1265 Kbytes/s
SHA384 8000 bytes 512 bytes 1 023 271 1329 Kbytes/s
SHA384 8000 bytes 1024 bytes 1 014 394 1340 Kbytes/s
SHA384 8000 bytes 2048 bytes 1 009 963 1346 Kbytes/s


The table below shows the final tag generation done through the call to cmox_hash_generateTag.

HASH mode Cycles Time
SHA256 3883 22 µs
SHA384 17 248 101 µs

The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1354 bytes 272 bytes 0 bytes 340 bytes
SHA384 2500 bytes 720 bytes 0 bytes 780 bytes


2.3. ECDSA signature and verification

This section provides the performance results for ECDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Operation ECC mathematics configuration Curve definition Cycles Time
SECP256R1 Signature Small Low 3 129 000 18 ms
SECP256R1 Signature Small High 3 022 392 17 ms
SECP256R1 Signature SuperFast Low 3 015 808 17 ms
SECP256R1 Signature SuperFast High 2 921 992 17 ms
SECP256R1 Verification Small Low 7 627 192 44 ms
SECP256R1 Verification Small High 6 721 640 39 ms
SECP256R1 Verification SuperFast Low 7 363 440 43 ms
SECP256R1 Verification SuperFast High 6 496 232 38 ms
SECP384R1 Signature Small Low 8 488 968 49 ms
SECP384R1 Signature Small High 8 093 304 47 ms
SECP384R1 Signature Fast Low 8 483 720 49 ms
SECP384R1 Signature Fast High 7 987 312 46 ms
SECP384R1 Verification Small Low 20 529 736 120 ms
SECP384R1 Verification Small High 17 754 552 104 ms
SECP384R1 Verification Fast Low 20 544 848 120 ms
SECP384R1 Verification Fast High 17 595 712 103 ms


The table below shows ECDSA flash memory and RAM usage (in bytes).

Note
he footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
SECP256R1 Signature Small Low 13 442 bytes 1212 bytes 0 bytes 440 bytes 628 bytes
SECP256R1 Signature Small High 13 442 bytes 1596 bytes 0 bytes 440 bytes 696 bytes
SECP256R1 Signature SuperFast Low 14 752 bytes 1212 bytes 0 bytes 444 bytes 628 bytes
SECP256R1 Signature SuperFast High 14 752 bytes 1596 bytes 0 bytes 444 bytes 696 bytes
SECP256R1 Verification Small Low 13 430 bytes 1212 bytes 0 bytes 488 bytes 856 bytes
SECP256R1 Verification Small High 13 430 bytes 1596 bytes 0 bytes 488 bytes 1648 bytes
SECP256R1 Verification SuperFast Low 14 740 bytes 1212 bytes 0 bytes 492 bytes 856 bytes
SECP256R1 Verification SuperFast High 14 740 bytes 1596 bytes 0 bytes 492 bytes 1648 bytes
SECP384R1 Signature Small Low 13 442 bytes 1692 bytes 0 bytes 440 bytes 884 bytes
SECP384R1 Signature Small High 13 442 bytes 2268 bytes 0 bytes 440 bytes 984 bytes
SECP384R1 Signature Fast Low 13 812 bytes 1692 bytes 0 bytes 456 bytes 884 bytes
SECP384R1 Signature Fast High 13 812 bytes 2268 bytes 0 bytes 456 bytes 984 bytes
SECP384R1 Verification Small Low 13 430 bytes 1692 bytes 0 bytes 488 bytes 1192 bytes
SECP384R1 Verification Small High 13 430 bytes 2268 bytes 0 bytes 488 bytes 2272 bytes
SECP384R1 Verification Fast Low 13 800 bytes 1692 bytes 0 bytes 504 bytes 1192 bytes
SECP384R1 Verification Fast High 13 800 bytes 2268 bytes 0 bytes 504 bytes 2272 bytes


2.4. EdDSA signature and verification

This section provides the performance results for EdDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Message size Operation ECC mathematics configuration Curve definition Cycles Time
Ed25519 1023 bytes Signature Small OptLow 4 954 240 29 ms
Ed25519 1023 bytes Signature Small OptHigh 2 888 976 16 ms
Ed25519 1023 bytes Signature SuperFast OptLow 4 804 744 28 ms
Ed25519 1023 bytes Signature SuperFast OptHigh 2 813 952 16 ms
Ed25519 1023 bytes Verification Small OptLow 7 390 072 43 ms
Ed25519 1023 bytes Verification Small OptHigh 6 490 056 38 ms
Ed25519 1023 bytes Verification SuperFast OptLow 7 114 264 41 ms
Ed25519 1023 bytes Verification SuperFast OptHigh 6 268 144 36 ms


The table below shows EdDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Message size Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
Ed25519 1023 bytes Signature Small OptLow 14 752 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature Small OptHigh 15 172 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptLow 16 062 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptHigh 16 482 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Verification Small OptLow 14 748 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification Small OptHigh 15 168 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes
Ed25519 1023 bytes Verification SuperFast OptLow 16 058 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification SuperFast OptHigh 16 478 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes


2.5. RSA signature and verification

This section provides the performance results for RSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Cycles Time
v2.2 CRT SHA-256 3K Signature Small Low 187 613 064 1103 ms
v2.2 CRT SHA-256 3K Signature Small Mid 141 259 120 830 ms
v2.2 CRT SHA-256 3K Signature Small High 118 646 368 697 ms
v2.2 CRT SHA-256 3K Signature Fast Low 186 906 640 1099 ms
v2.2 CRT SHA-256 3K Signature Fast Mid 141 048 128 829 ms
v2.2 CRT SHA-256 3K Signature Fast High 118 335 696 696 ms
v2.2 No CRT SHA-256 3K Signature Small Low 713 470 488 4196 ms
v2.2 No CRT SHA-256 3K Signature Small Mid 535 916 712 3152 ms
v2.2 No CRT SHA-256 3K Signature Small High 448 309 792 2637 ms
v2.2 No CRT SHA-256 3K Signature Fast Low 712 248 424 4189 ms
v2.2 No CRT SHA-256 3K Signature Fast Mid 535 318 584 3148 ms
v2.2 No CRT SHA-256 3K Signature Fast High 447 677 088 2633 ms
v2.2 n/a SHA-256 3K Verification Small n/a 3 737 672 21 ms
v2.2 n/a SHA-256 3K Verification Fast n/a 3 732 880 21 ms


The table below shows RSA flash memory and RAM usage (in bytes).

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Code Constant data Global data Stack usage Working buffer
v2.2 CRT SHA-256 3K Signature Small Low 6850 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Small Mid 7086 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Small High 7086 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 CRT SHA-256 3K Signature Fast Low 7220 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Fast Mid 7456 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Fast High 7456 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 No CRT SHA-256 3K Signature Small Low 5918 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Small Mid 6154 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Small High 6154 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 No CRT SHA-256 3K Signature Fast Low 6288 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Fast Mid 6524 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Fast High 6524 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 n/a SHA-256 3K Verification Small n/a 6102 bytes 368 bytes 0 bytes 684 bytes 3108 bytes
v2.2 n/a SHA-256 3K Verification Fast n/a 6472 bytes 368 bytes 0 bytes 684 bytes 3108 bytes


2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification

This section provides the performance results for ML-DSA key pair generation, signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites and functions configurations. Note: For signature generation, the number of clock cycles is not bounded in time. The measurement was taken using one predefined private key and one 32-byte message, and the reported value corresponds to the minimum observed time.

Suite Function Cycles Time (in ms) Stack usage Working buffer
ML-DSA-44 keyGen 2 662 480 15 476 7116
ML-DSA-65 keyGen 4 683 568 27 476 8140
ML-DSA-87 keyGen 7 918 272 46 476 10 188
ML-DSA-44 Signature 4 367 168 25 772 30 796
ML-DSA-44 Signature Low RAM 4 755 568 27 756 11 340
ML-DSA-44 Verification 2 915 632 17 700 8908
ML-DSA-44 Verification Low RAM 3 782 504 22 700 4812
ML-DSA-65 Verification 4 857 016 28 700 9948
ML-DSA-65 Verification Low RAM 6 612 248 38 700 4828
ML-DSA-87 Verification 8 176 928 48 700 12 268
ML-DSA-87 Verification Low RAM 11 435 632 67 700 5100

2.7. Post-Quantum Cryptography ML-KEM key pair generation, encapsulation, decapsulation

This section provides the performance results for ML-KEM key pair generation, encapsulation and decapsulation.

The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different functions and suites.

Function Suites Cycles Time (in ms) Stack usage
Key-pair-Generation ML-KEM-512 833 496 5 3 060
Key-pair-Generation ML-KEM-768 1 366 000 8 3 572
Key-pair-Generation ML-KEM-1024 2 150 984 13 4 084
Key-Encapsulation ML-KEM-512 2321368 14 4 588
Key-Encapsulation ML-KEM-768 3 380 336 20 5 100
Key-Encapsulation ML-KEM-1024 4 654 112 27 5 612
Key-Decapsulation ML-KEM-512 2 639 024 16 4 684
Key-Decapsulation ML-KEM-768 3 814 712 22 5 516
Key-Decapsulation ML-KEM-1024 5 209 576 31 6 508

2.8. Post-Quantum Cryptography HBS-LMS signature verification

This section provides the performance results for ML-LMS signature verification.

The table below shows the number of clock cycles minimum, average and maximum and average time (in ms) needed to perform the described function in different functions and suite. Note: Clock cycles were measured for 10 different generated key and message pairs, and the reported Cycles avg values are averages over these measurements.

Function Suite Cycles min Cycles avg Time avg (in ms) Cycles max Stack usage
LMS-Verify LMS_N32_H10_W1_SHA256 1 251 544 1 306 564 8 1 582 280 1 668
LMS-Verify LMS_N32_H10_W2_SHA256 1 280 720 1 367 754 8 1 491 336 1 668
LMS-Verify LMS_N32_H10_W4_SHA256 2 196 408 2 548 531 15 2 956 624 1 668
LMS-Verify LMS_N32_H10_W8_SHA256 19 008 408 21 830 974 128 24 888 584 1 668