Cryptographic performance on STM32H5 Series V5.x

This page reports measured performance when using the pure software cryptographic library algorithms with an STM32H5 MCU. In addition to performance figures, the required code footprint and memory are also given.


1. Measurement configuration

1.1. Hardware configuration

STM32 MCU STM32H563ZI
Device ID 0x484
Revision ID 0x1007
Board NUCLEO-H563ZI

1.2. Firmware configuration

Cryptographic library version 050000B2[ver. 1]
  1. This value corresponds to the information returned by a call to cmox_getInfos

1.3. System configuration

System core clock frequency 240 MHz
Flash latency 5 wait states
Voltage scaling Range 3
ICACHE peripheral 1 (0: disabled / 1: enabled)
Prefetch cache (ART) 1 (0: disabled / 1: enabled)

1.4. Development toolchains and compilers

IAR Embedded Workbench IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM
Information
The measurements are done using a project built with the High Speed optimization setting enabled.


2. Performance values

2.1. AES symmetric key encryption and decryption

This section provides the performance results for AES-CBC using different operation modes:

  • Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
  • Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.

2.1.1. Sole buffer mode

In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.

AES mode Key size Buffer size Cipher operation Configuration Cycles Time
AES CBC 128 bits 32 bytes Encryption Small 3659 15 µs
AES CBC 128 bits 32 bytes Encryption Fast 3411 14 µs
AES CBC 128 bits 64 bytes Encryption Small 6324 26 µs
AES CBC 128 bits 64 bytes Encryption Fast 5473 22 µs
AES CBC 128 bits 128 bytes Encryption Small 11 606 48 µs
AES CBC 128 bits 128 bytes Encryption Fast 9739 40 µs
AES CBC 192 bits 32 bytes Encryption Small 4052 16 µs
AES CBC 192 bits 32 bytes Encryption Fast 3587 14 µs
AES CBC 192 bits 64 bytes Encryption Small 7126 29 µs
AES CBC 192 bits 64 bytes Encryption Fast 5970 24 µs
AES CBC 192 bits 128 bytes Encryption Small 13 254 55 µs
AES CBC 192 bits 128 bytes Encryption Fast 10 802 45 µs
AES CBC 256 bits 32 bytes Encryption Small 4609 19 µs
AES CBC 256 bits 32 bytes Encryption Fast 4019 16 µs
AES CBC 256 bits 64 bytes Encryption Small 8093 33 µs
AES CBC 256 bits 64 bytes Encryption Fast 6731 28 µs
AES CBC 256 bits 128 bytes Encryption Small 15 069 62 µs
AES CBC 256 bits 128 bytes Encryption Fast 12 102 50 µs
AES CBC 128 bits 32 bytes Decryption Small 4911 20 µs
AES CBC 128 bits 32 bytes Decryption Fast 4751 19 µs
AES CBC 128 bits 64 bytes Decryption Small 8750 36 µs
AES CBC 128 bits 64 bytes Decryption Fast 6903 28 µs
AES CBC 128 bits 128 bytes Decryption Small 16 416 68 µs
AES CBC 128 bits 128 bytes Decryption Fast 11 187 46 µs
AES CBC 192 bits 32 bytes Decryption Small 5545 23 µs
AES CBC 192 bits 32 bytes Decryption Fast 5290 22 µs
AES CBC 192 bits 64 bytes Decryption Small 10 052 41 µs
AES CBC 192 bits 64 bytes Decryption Fast 7752 32 µs
AES CBC 192 bits 128 bytes Decryption Small 19 073 79 µs
AES CBC 192 bits 128 bytes Decryption Fast 12 583 52 µs
AES CBC 256 bits 32 bytes Decryption Small 6374 26 µs
AES CBC 256 bits 32 bytes Decryption Fast 5829 24 µs
AES CBC 256 bits 64 bytes Decryption Small 11 565 48 µs
AES CBC 256 bits 64 bytes Decryption Fast 8564 35 µs
AES CBC 256 bits 128 bytes Decryption Small 21 948 91 µs
AES CBC 256 bits 128 bytes Decryption Fast 14 018 58 µs


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2386 bytes 324 bytes 0 bytes 552 bytes
Encryption Fast 2330 bytes 1092 bytes 0 bytes 552 bytes
Decryption Small 2746 bytes 580 bytes 0 bytes 568 bytes
Decryption Fast 2696 bytes 2372 bytes 0 bytes 568 bytes


2.1.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_cipher_init
  • cmox_cipher_setKey
  • cmox_cipher_setIV
  • cmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.

AES mode Key size Message size Chunk size Cipher operation Configuration Cycles Bit rate
AES CBC 128 bits 8000 bytes 128 bytes Encryption Small 668 808 2870 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Encryption Fast 537 032 3575 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Small 663 552 2893 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Fast 529 152 3628 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Small 662 640 2897 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Fast 527 776 3637 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Small 662 184 2899 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Fast 527 080 3642 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Small 773 808 2481 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Fast 611 160 3141 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Small 768 584 2498 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Fast 603 360 3182 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Small 767 672 2501 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Fast 601 968 3189 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Small 767 216 2502 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Fast 601 256 3193 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Small 878 800 2184 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Fast 685 000 2802 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Small 873 552 2197 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Fast 677 176 2835 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Small 872 640 2200 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Fast 675 776 2841 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Small 872 184 2201 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Fast 675 096 2844 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Small 985 720 1947 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Fast 557 856 3441 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Small 977 896 1963 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Fast 549 824 3492 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Small 975 488 1968 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Fast 547 288 3508 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Small 972 600 1974 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Fast 544 464 3526 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Small 1 155 712 1661 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Fast 631 792 3038 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Small 1 147 904 1672 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Fast 623 768 3078 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Small 1 145 488 1676 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Fast 621 272 3090 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Small 1 142 560 1680 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Fast 618 424 3104 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Small 1 325 784 1448 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Fast 705 784 2720 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Small 1 317 928 1456 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Fast 697 768 2751 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Small 1 315 536 1459 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Fast 695 256 2761 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Small 1 312 600 1462 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Fast 692 400 2772 Kbytes/s


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2306 bytes 316 bytes 0 bytes 176 bytes
Encryption Fast 2250 bytes 1084 bytes 0 bytes 176 bytes
Decryption Small 2666 bytes 572 bytes 0 bytes 192 bytes
Decryption Fast 2616 bytes 2364 bytes 0 bytes 192 bytes


2.2. HASH digest

In this section we provide the performance results for HASH, using different modes of operation:

  • Sole buffer: one sole buffer is hashed. The performance time is given in us.
  • Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.

2.2.1. Sole buffer mode

In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.

HASH mode Buffer size Cycles Time
SHA256 32 bytes 4152 17 µs
SHA256 64 bytes 7251 30 µs
SHA256 128 bytes 10 093 42 µs
SHA384 32 bytes 15 341 63 µs
SHA384 64 bytes 15 506 64 µs
SHA384 128 bytes 28 934 120 µs


The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1378 280 bytes 0 bytes 532 bytes
SHA384 2590 728 bytes 0 bytes 1076 bytes


2.2.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_hash_init
  • cmox_hash_append: called several times to hash the whole message in fixed-size chunks
  • cmox_hash_generateTag

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.

HASH mode Message size Chunk size Cycles Bit rate
SHA256 8000 bytes 128 bytes 386 204 4971 Kbytes/s
SHA256 8000 bytes 512 bytes 364 428 5268 Kbytes/s
SHA256 8000 bytes 1024 bytes 360 740 5322 Kbytes/s
SHA256 8000 bytes 2048 bytes 358 898 5349 Kbytes/s
SHA384 8000 bytes 128 bytes 859 243 2234 Kbytes/s
SHA384 8000 bytes 512 bytes 819 881 2341 Kbytes/s
SHA384 8000 bytes 1024 bytes 813 028 2361 Kbytes/s
SHA384 8000 bytes 2048 bytes 809 630 2371 Kbytes/s


The table below shows the final tag generation done through the call to cmox_hash_generateTag.

HASH mode Cycles Time
SHA256 3369 14 µs
SHA384 14 371 59 µs

The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1374 bytes 272 bytes 0 bytes 340 bytes
SHA384 2586 bytes 720 bytes 0 bytes 780 bytes


2.3. ECDSA signature and verification

This section provides the performance results for ECDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Operation ECC mathematics configuration Curve definition Cycles Time
SECP256R1 Signature Small Low 2 884 128 12 ms
SECP256R1 Signature Small High 2 813 224 11 ms
SECP256R1 Signature SuperFast Low 1 902 032 7 ms
SECP256R1 Signature SuperFast High 1 823 472 7 ms
SECP256R1 Verification Small Low 6 903 120 28 ms
SECP256R1 Verification Small High 6 167 624 25 ms
SECP256R1 Verification SuperFast Low 4 671 688 19 ms
SECP256R1 Verification SuperFast High 4 060 672 16 ms
SECP384R1 Signature Small Low 8 181 712 34 ms
SECP384R1 Signature Small High 7 859 128 32 ms
SECP384R1 Signature Fast Low 7 016 984 29 ms
SECP384R1 Signature Fast High 6 585 192 27 ms
SECP384R1 Verification Small Low 19 580 976 81 ms
SECP384R1 Verification Small High 17 071 128 71 ms
SECP384R1 Verification Fast Low 16 863 848 70 ms
SECP384R1 Verification Fast High 14 426 960 60 ms


The table below shows ECDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
SECP256R1 Signature Small Low 13 468 bytes 1212 bytes 0 bytes 440 bytes 628 bytes
SECP256R1 Signature Small High 13 468 bytes 1596 bytes 0 bytes 440 bytes 696 bytes
SECP256R1 Signature SuperFast Low 14 778 bytes 1212 bytes 0 bytes 444 bytes 628 bytes
SECP256R1 Signature SuperFast High 14 778 bytes 1596 bytes 0 bytes 444 bytes 696 bytes
SECP256R1 Verification Small Low 13 456 bytes 1212 bytes 0 bytes 488 bytes 856 bytes
SECP256R1 Verification Small High 13 456 bytes 1596 bytes 0 bytes 488 bytes 1648 bytes
SECP256R1 Verification SuperFast Low 14 766 bytes 1212 bytes 0 bytes 492 bytes 856 bytes
SECP256R1 Verification SuperFast High 14 766 bytes 1596 bytes 0 bytes 492 bytes 1648 bytes
SECP384R1 Signature Small Low 13 468 bytes 1692 bytes 0 bytes 440 bytes 884 bytes
SECP384R1 Signature Small High 13 468 bytes 2268 bytes 0 bytes 440 bytes 984 bytes
SECP384R1 Signature Fast Low 13 838 bytes 1692 bytes 0 bytes 456 bytes 884 bytes
SECP384R1 Signature Fast High 13 838 bytes 2268 bytes 0 bytes 456 bytes 984 bytes
SECP384R1 Verification Small Low 13 456 bytes 1692 bytes 0 bytes 488 bytes 1192 bytes
SECP384R1 Verification Small High 13 456 bytes 2268 bytes 0 bytes 488 bytes 2272 bytes
SECP384R1 Verification Fast Low 13 826 bytes 1692 bytes 0 bytes 504 bytes 1192 bytes
SECP384R1 Verification Fast High 13 826 bytes 2268 bytes 0 bytes 504 bytes 2272 bytes


2.4. EdDSA signature and verification

This section provides the performance results for EdDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Message size Operation ECC mathematics configuration Curve definition Cycles Time
Ed25519 1023 bytes Signature Small OptLow 4 419 616 18 ms
Ed25519 1023 bytes Signature Small OptHigh 2 570 504 10 ms
Ed25519 1023 bytes Signature SuperFast OptLow 3 166 680 13 ms
Ed25519 1023 bytes Signature SuperFast OptHigh 1 860 776 7 ms
Ed25519 1023 bytes Verification Small OptLow 6 664 168 27 ms
Ed25519 1023 bytes Verification Small OptHigh 5 845 912 24 ms
Ed25519 1023 bytes Verification SuperFast OptLow 4 590 808 19 ms
Ed25519 1023 bytes Verification SuperFast OptHigh 3 989 928 16 ms


The table below shows EdDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Message size Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
Ed25519 1023 bytes Signature Small OptLow 14 840 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature Small OptHigh 15 260 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptLow 16 150 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptHigh 16 570 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Verification Small OptLow 14 836 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification Small OptHigh 15 256 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes
Ed25519 1023 bytes Verification SuperFast OptLow 16 146 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification SuperFast OptHigh 16 566 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes


2.5. RSA signature and verification

This section provides the performance results for RSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Cycles Time
v2.2 CRT SHA-256 3K Signature Small Low 197 724 144 823 ms
v2.2 CRT SHA-256 3K Signature Small Mid 148 815 304 620 ms
v2.2 CRT SHA-256 3K Signature Small High 124 974 744 520 ms
v2.2 CRT SHA-256 3K Signature Fast Low 158 843 208 661 ms
v2.2 CRT SHA-256 3K Signature Fast Mid 119 613 456 498 ms
v2.2 CRT SHA-256 3K Signature Fast High 100 473 560 418 ms
v2.2 No CRT SHA-256 3K Signature Small Low 762 179 080 3175 ms
v2.2 No CRT SHA-256 3K Signature Small Mid 572 421 368 2385 ms
v2.2 No CRT SHA-256 3K Signature Small High 478 813 192 1995 ms
v2.2 No CRT SHA-256 3K Signature Fast Low 606 769 976 2528 ms
v2.2 No CRT SHA-256 3K Signature Fast Mid 455 788 680 1899 ms
v2.2 No CRT SHA-256 3K Signature Fast High 381 290 608 1588 ms
v2.2 n/a SHA-256 3K Verification Small n/a 3 746 168 15 ms
v2.2 n/a SHA-256 3K Verification Fast n/a 3 240 328 13 ms


The table below shows RSA flash memory and RAM usage (in bytes).

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Code Constant data Global data Stack usage Working buffer
v2.2 CRT SHA-256 3K Signature Small Low 6890 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Small Mid 7126 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Small High 7126 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 CRT SHA-256 3K Signature Fast Low 7260 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Fast Mid 7496 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Fast High 7496 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 No CRT SHA-256 3K Signature Small Low 5958 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Small Mid 6194 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Small High 6194 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 No CRT SHA-256 3K Signature Fast Low 6328 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Fast Mid 6564 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Fast High 6564 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 n/a SHA-256 3K Verification Small n/a 6142 bytes 368 bytes 0 bytes 684 bytes 3108 bytes
v2.2 n/a SHA-256 3K Verification Fast n/a 6512 bytes 368 bytes 0 bytes 684 bytes 3108 bytes


2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification

This section provides the performance results for ML-DSA key pair generation, signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites and functions configurations. Note: For signature generation, the number of clock cycles is not bounded in time. The measurement was taken using one predefined private key and one 32-byte message, and the reported value corresponds to the minimum observed time.

Suite Function Cycles Time (in ms) Stack usage Working buffer
ML-DSA-44 keyGen 1 990 880 8 476 7116
ML-DSA-65 keyGen 3 452 144 14 476 8140
ML-DSA-87 keyGen 5 808 192 24 476 10 188
ML-DSA-44 Signature 3 552 128 14 772 30 796
ML-DSA-44 Signature Low RAM 3 815 944 15 756 11 340
ML-DSA-65 Signature 5 465 360 22 772 43 084
ML-DSA-65 Signature Low RAM 5 799 552 24 756 15 436
ML-DSA-87 Signature 8 553 688 35 772 57 420
ML-DSA-87 Signature Low RAM 9 016 872 37 756 19 532
ML-DSA-44 Verification 2 245 568 9 700 8908
ML-DSA-44 Verification Low RAM 3 040 112 12 700 4812
ML-DSA-65 Verification 3 690 496 15 700 9948
ML-DSA-65 Verification Low RAM 5 308 648 22 700 4828
ML-DSA-87 Verification 6 128 984 25 700 12 268
ML-DSA-87 Verification Low RAM 9 137 280 38 700 5100

2.7. Post-Quantum Cryptography ML-KEM key pair generation, encapsulation, decapsulation

This section provides the performance results for ML-KEM key pair generation, encapsulation and decapsulation.

The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different functions and suites.

Function Suites Cycles Time (in ms) Stack usage
Key-pair-Generation ML-KEM-512 654 768 3 3 060
Key-pair-Generation ML-KEM-768 1 076 200 4 3 572
Key-pair-Generation ML-KEM-1024 1 684 672 7 4 084
Key-Encapsulation ML-KEM-512 2 060 816 9 4 588
Key-Encapsulation ML-KEM-768 2 969 112 12 5 100
Key-Encapsulation ML-KEM-1024 4 037 544 17 5 612
Key-Decapsulation ML-KEM-512 2 332 744 10 4 684
Key-Decapsulation ML-KEM-768 3 335 800 14 5 516
Key-Decapsulation ML-KEM-1024 4 504 720 19 6 508

2.8. Post-Quantum Cryptography HBS-LMS signature verification

This section provides the performance results for ML-LMS signature verification.

The table below shows the number of clock cycles minimum, average and maximum and average time (in ms) needed to perform the described function in different functions and suite. Note: Clock cycles were measured for 10 different generated key and message pairs, and the reported Cycles avg values are averages over these measurements.

Function Suite Cycles min Cycles avg Time avg (in ms) Cycles max Stack usage
LMS-Verify LMS_N32_H10_W1_SHA256 1 023 304 1 065 928 4 1 112 976 1 668
LMS-Verify LMS_N32_H10_W2_SHA256 1 036 192 1 105 653 5 1 203 976 1 668
LMS-Verify LMS_N32_H10_W4_SHA256 1 777 880 2 062 884 9 2 392 536 1 668
LMS-Verify LMS_N32_H10_W8_SHA256 15 345 912 17 624 414 73 20 092 776 1 668