This page reports measured performance when using the pure software cryptographic library algorithms with an STM32H5 MCU. In addition to performance figures, the required code footprint and memory are also given.
1. Measurement configuration
1.1. Hardware configuration
| STM32 MCU | STM32H563ZI |
| Device ID | 0x484 |
| Revision ID | 0x1007 |
| Board | NUCLEO-H563ZI |
1.2. Firmware configuration
| Cryptographic library version | 050000B2[ver. 1] |
- ↑ This value corresponds to the information returned by a call to
cmox_getInfos
1.3. System configuration
| System core clock frequency | 240 MHz |
| Flash latency | 5 wait states |
| Voltage scaling | Range 3 |
| ICACHE peripheral | 1 (0: disabled / 1: enabled) |
| Prefetch cache (ART) | 1 (0: disabled / 1: enabled) |
1.4. Development toolchains and compilers
| IAR Embedded Workbench | IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM |
2. Performance values
2.1. AES symmetric key encryption and decryption
This section provides the performance results for AES-CBC using different operation modes:
- Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
- Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.
2.1.1. Sole buffer mode
In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.
| AES mode | Key size | Buffer size | Cipher operation | Configuration | Cycles | Time |
|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 32 bytes | Encryption | Small | 3659 | 15 µs |
| AES CBC | 128 bits | 32 bytes | Encryption | Fast | 3411 | 14 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Small | 6324 | 26 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Fast | 5473 | 22 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Small | 11 606 | 48 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Fast | 9739 | 40 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Small | 4052 | 16 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Fast | 3587 | 14 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Small | 7126 | 29 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Fast | 5970 | 24 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Small | 13 254 | 55 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Fast | 10 802 | 45 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Small | 4609 | 19 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Fast | 4019 | 16 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Small | 8093 | 33 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Fast | 6731 | 28 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Small | 15 069 | 62 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Fast | 12 102 | 50 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Small | 4911 | 20 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Fast | 4751 | 19 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Small | 8750 | 36 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Fast | 6903 | 28 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Small | 16 416 | 68 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Fast | 11 187 | 46 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Small | 5545 | 23 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Fast | 5290 | 22 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Small | 10 052 | 41 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Fast | 7752 | 32 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Small | 19 073 | 79 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Fast | 12 583 | 52 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Small | 6374 | 26 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Fast | 5829 | 24 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Small | 11 565 | 48 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Fast | 8564 | 35 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Small | 21 948 | 91 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Fast | 14 018 | 58 µs |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2386 bytes | 324 bytes | 0 bytes | 552 bytes |
| Encryption | Fast | 2330 bytes | 1092 bytes | 0 bytes | 552 bytes |
| Decryption | Small | 2746 bytes | 580 bytes | 0 bytes | 568 bytes |
| Decryption | Fast | 2696 bytes | 2372 bytes | 0 bytes | 568 bytes |
2.1.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_cipher_initcmox_cipher_setKeycmox_cipher_setIVcmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.
| AES mode | Key size | Message size | Chunk size | Cipher operation | Configuration | Cycles | Bit rate |
|---|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Small | 668 808 | 2870 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Fast | 537 032 | 3575 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Small | 663 552 | 2893 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Fast | 529 152 | 3628 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Small | 662 640 | 2897 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 527 776 | 3637 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Small | 662 184 | 2899 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 527 080 | 3642 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Small | 773 808 | 2481 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Fast | 611 160 | 3141 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Small | 768 584 | 2498 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Fast | 603 360 | 3182 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Small | 767 672 | 2501 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 601 968 | 3189 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Small | 767 216 | 2502 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 601 256 | 3193 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Small | 878 800 | 2184 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Fast | 685 000 | 2802 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Small | 873 552 | 2197 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Fast | 677 176 | 2835 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Small | 872 640 | 2200 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 675 776 | 2841 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Small | 872 184 | 2201 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 675 096 | 2844 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Small | 985 720 | 1947 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Fast | 557 856 | 3441 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Small | 977 896 | 1963 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Fast | 549 824 | 3492 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Small | 975 488 | 1968 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 547 288 | 3508 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Small | 972 600 | 1974 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 544 464 | 3526 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 155 712 | 1661 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Fast | 631 792 | 3038 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 147 904 | 1672 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Fast | 623 768 | 3078 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 145 488 | 1676 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 621 272 | 3090 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 142 560 | 1680 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 618 424 | 3104 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 325 784 | 1448 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Fast | 705 784 | 2720 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 317 928 | 1456 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Fast | 697 768 | 2751 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 315 536 | 1459 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 695 256 | 2761 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 312 600 | 1462 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 692 400 | 2772 Kbytes/s |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2306 bytes | 316 bytes | 0 bytes | 176 bytes |
| Encryption | Fast | 2250 bytes | 1084 bytes | 0 bytes | 176 bytes |
| Decryption | Small | 2666 bytes | 572 bytes | 0 bytes | 192 bytes |
| Decryption | Fast | 2616 bytes | 2364 bytes | 0 bytes | 192 bytes |
2.2. HASH digest
In this section we provide the performance results for HASH, using different modes of operation:
- Sole buffer: one sole buffer is hashed. The performance time is given in us.
- Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.
2.2.1. Sole buffer mode
In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.
| HASH mode | Buffer size | Cycles | Time |
|---|---|---|---|
| SHA256 | 32 bytes | 4152 | 17 µs |
| SHA256 | 64 bytes | 7251 | 30 µs |
| SHA256 | 128 bytes | 10 093 | 42 µs |
| SHA384 | 32 bytes | 15 341 | 63 µs |
| SHA384 | 64 bytes | 15 506 | 64 µs |
| SHA384 | 128 bytes | 28 934 | 120 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1378 | 280 bytes | 0 bytes | 532 bytes |
| SHA384 | 2590 | 728 bytes | 0 bytes | 1076 bytes |
2.2.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_hash_initcmox_hash_append: called several times to hash the whole message in fixed-size chunkscmox_hash_generateTag
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.
| HASH mode | Message size | Chunk size | Cycles | Bit rate |
|---|---|---|---|---|
| SHA256 | 8000 bytes | 128 bytes | 386 204 | 4971 Kbytes/s |
| SHA256 | 8000 bytes | 512 bytes | 364 428 | 5268 Kbytes/s |
| SHA256 | 8000 bytes | 1024 bytes | 360 740 | 5322 Kbytes/s |
| SHA256 | 8000 bytes | 2048 bytes | 358 898 | 5349 Kbytes/s |
| SHA384 | 8000 bytes | 128 bytes | 859 243 | 2234 Kbytes/s |
| SHA384 | 8000 bytes | 512 bytes | 819 881 | 2341 Kbytes/s |
| SHA384 | 8000 bytes | 1024 bytes | 813 028 | 2361 Kbytes/s |
| SHA384 | 8000 bytes | 2048 bytes | 809 630 | 2371 Kbytes/s |
The table below shows the final tag generation done through the call to cmox_hash_generateTag.
| HASH mode | Cycles | Time |
|---|---|---|
| SHA256 | 3369 | 14 µs |
| SHA384 | 14 371 | 59 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1374 bytes | 272 bytes | 0 bytes | 340 bytes |
| SHA384 | 2586 bytes | 720 bytes | 0 bytes | 780 bytes |
2.3. ECDSA signature and verification
This section provides the performance results for ECDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 2 884 128 | 12 ms |
| SECP256R1 | Signature | Small | High | 2 813 224 | 11 ms |
| SECP256R1 | Signature | SuperFast | Low | 1 902 032 | 7 ms |
| SECP256R1 | Signature | SuperFast | High | 1 823 472 | 7 ms |
| SECP256R1 | Verification | Small | Low | 6 903 120 | 28 ms |
| SECP256R1 | Verification | Small | High | 6 167 624 | 25 ms |
| SECP256R1 | Verification | SuperFast | Low | 4 671 688 | 19 ms |
| SECP256R1 | Verification | SuperFast | High | 4 060 672 | 16 ms |
| SECP384R1 | Signature | Small | Low | 8 181 712 | 34 ms |
| SECP384R1 | Signature | Small | High | 7 859 128 | 32 ms |
| SECP384R1 | Signature | Fast | Low | 7 016 984 | 29 ms |
| SECP384R1 | Signature | Fast | High | 6 585 192 | 27 ms |
| SECP384R1 | Verification | Small | Low | 19 580 976 | 81 ms |
| SECP384R1 | Verification | Small | High | 17 071 128 | 71 ms |
| SECP384R1 | Verification | Fast | Low | 16 863 848 | 70 ms |
| SECP384R1 | Verification | Fast | High | 14 426 960 | 60 ms |
The table below shows ECDSA flash memory and RAM usage (in bytes).
| Curve | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 13 468 bytes | 1212 bytes | 0 bytes | 440 bytes | 628 bytes |
| SECP256R1 | Signature | Small | High | 13 468 bytes | 1596 bytes | 0 bytes | 440 bytes | 696 bytes |
| SECP256R1 | Signature | SuperFast | Low | 14 778 bytes | 1212 bytes | 0 bytes | 444 bytes | 628 bytes |
| SECP256R1 | Signature | SuperFast | High | 14 778 bytes | 1596 bytes | 0 bytes | 444 bytes | 696 bytes |
| SECP256R1 | Verification | Small | Low | 13 456 bytes | 1212 bytes | 0 bytes | 488 bytes | 856 bytes |
| SECP256R1 | Verification | Small | High | 13 456 bytes | 1596 bytes | 0 bytes | 488 bytes | 1648 bytes |
| SECP256R1 | Verification | SuperFast | Low | 14 766 bytes | 1212 bytes | 0 bytes | 492 bytes | 856 bytes |
| SECP256R1 | Verification | SuperFast | High | 14 766 bytes | 1596 bytes | 0 bytes | 492 bytes | 1648 bytes |
| SECP384R1 | Signature | Small | Low | 13 468 bytes | 1692 bytes | 0 bytes | 440 bytes | 884 bytes |
| SECP384R1 | Signature | Small | High | 13 468 bytes | 2268 bytes | 0 bytes | 440 bytes | 984 bytes |
| SECP384R1 | Signature | Fast | Low | 13 838 bytes | 1692 bytes | 0 bytes | 456 bytes | 884 bytes |
| SECP384R1 | Signature | Fast | High | 13 838 bytes | 2268 bytes | 0 bytes | 456 bytes | 984 bytes |
| SECP384R1 | Verification | Small | Low | 13 456 bytes | 1692 bytes | 0 bytes | 488 bytes | 1192 bytes |
| SECP384R1 | Verification | Small | High | 13 456 bytes | 2268 bytes | 0 bytes | 488 bytes | 2272 bytes |
| SECP384R1 | Verification | Fast | Low | 13 826 bytes | 1692 bytes | 0 bytes | 504 bytes | 1192 bytes |
| SECP384R1 | Verification | Fast | High | 13 826 bytes | 2268 bytes | 0 bytes | 504 bytes | 2272 bytes |
2.4. EdDSA signature and verification
This section provides the performance results for EdDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 4 419 616 | 18 ms |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 2 570 504 | 10 ms |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptLow | 3 166 680 | 13 ms |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptHigh | 1 860 776 | 7 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 6 664 168 | 27 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 5 845 912 | 24 ms |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptLow | 4 590 808 | 19 ms |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptHigh | 3 989 928 | 16 ms |
The table below shows EdDSA flash memory and RAM usage (in bytes).
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 14 840 bytes | 1748 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 15 260 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptLow | 16 150 bytes | 1748 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptHigh | 16 570 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 14 836 bytes | 1748 bytes | 0 bytes | 1172 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 15 256 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1992 bytes |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptLow | 16 146 bytes | 1748 bytes | 0 bytes | 1172 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptHigh | 16 566 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1992 bytes |
2.5. RSA signature and verification
This section provides the performance results for RSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Cycles | Time |
|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 197 724 144 | 823 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 148 815 304 | 620 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 124 974 744 | 520 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Low | 158 843 208 | 661 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Mid | 119 613 456 | 498 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | High | 100 473 560 | 418 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 762 179 080 | 3175 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 572 421 368 | 2385 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 478 813 192 | 1995 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Low | 606 769 976 | 2528 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Mid | 455 788 680 | 1899 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | High | 381 290 608 | 1588 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 3 746 168 | 15 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Fast | n/a | 3 240 328 | 13 ms |
The table below shows RSA flash memory and RAM usage (in bytes).
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 6890 bytes | 372 bytes | 0 bytes | 668 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 7126 bytes | 372 bytes | 0 bytes | 668 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 7126 bytes | 372 bytes | 0 bytes | 668 bytes | 6708 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Low | 7260 bytes | 372 bytes | 0 bytes | 668 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Mid | 7496 bytes | 372 bytes | 0 bytes | 668 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | High | 7496 bytes | 372 bytes | 0 bytes | 668 bytes | 6708 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 5958 bytes | 364 bytes | 0 bytes | 668 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 6194 bytes | 364 bytes | 0 bytes | 668 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 6194 bytes | 364 bytes | 0 bytes | 668 bytes | 9368 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Low | 6328 bytes | 364 bytes | 0 bytes | 668 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Mid | 6564 bytes | 364 bytes | 0 bytes | 668 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | High | 6564 bytes | 364 bytes | 0 bytes | 668 bytes | 9368 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 6142 bytes | 368 bytes | 0 bytes | 684 bytes | 3108 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Fast | n/a | 6512 bytes | 368 bytes | 0 bytes | 684 bytes | 3108 bytes |
2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification
This section provides the performance results for ML-DSA key pair generation, signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites and functions configurations. Note: For signature generation, the number of clock cycles is not bounded in time. The measurement was taken using one predefined private key and one 32-byte message, and the reported value corresponds to the minimum observed time.
| Suite | Function | Cycles | Time (in ms) | Stack usage | Working buffer |
|---|---|---|---|---|---|
| ML-DSA-44 | keyGen | 1 990 880 | 8 | 476 | 7116 |
| ML-DSA-65 | keyGen | 3 452 144 | 14 | 476 | 8140 |
| ML-DSA-87 | keyGen | 5 808 192 | 24 | 476 | 10 188 |
| ML-DSA-44 | Signature | 3 552 128 | 14 | 772 | 30 796 |
| ML-DSA-44 | Signature Low RAM | 3 815 944 | 15 | 756 | 11 340 |
| ML-DSA-65 | Signature | 5 465 360 | 22 | 772 | 43 084 |
| ML-DSA-65 | Signature Low RAM | 5 799 552 | 24 | 756 | 15 436 |
| ML-DSA-87 | Signature | 8 553 688 | 35 | 772 | 57 420 |
| ML-DSA-87 | Signature Low RAM | 9 016 872 | 37 | 756 | 19 532 |
| ML-DSA-44 | Verification | 2 245 568 | 9 | 700 | 8908 |
| ML-DSA-44 | Verification Low RAM | 3 040 112 | 12 | 700 | 4812 |
| ML-DSA-65 | Verification | 3 690 496 | 15 | 700 | 9948 |
| ML-DSA-65 | Verification Low RAM | 5 308 648 | 22 | 700 | 4828 |
| ML-DSA-87 | Verification | 6 128 984 | 25 | 700 | 12 268 |
| ML-DSA-87 | Verification Low RAM | 9 137 280 | 38 | 700 | 5100 |
2.7. Post-Quantum Cryptography ML-KEM key pair generation, encapsulation, decapsulation
This section provides the performance results for ML-KEM key pair generation, encapsulation and decapsulation.
The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different functions and suites.
| Function | Suites | Cycles | Time (in ms) | Stack usage |
|---|---|---|---|---|
| Key-pair-Generation | ML-KEM-512 | 654 768 | 3 | 3 060 |
| Key-pair-Generation | ML-KEM-768 | 1 076 200 | 4 | 3 572 |
| Key-pair-Generation | ML-KEM-1024 | 1 684 672 | 7 | 4 084 |
| Key-Encapsulation | ML-KEM-512 | 2 060 816 | 9 | 4 588 |
| Key-Encapsulation | ML-KEM-768 | 2 969 112 | 12 | 5 100 |
| Key-Encapsulation | ML-KEM-1024 | 4 037 544 | 17 | 5 612 |
| Key-Decapsulation | ML-KEM-512 | 2 332 744 | 10 | 4 684 |
| Key-Decapsulation | ML-KEM-768 | 3 335 800 | 14 | 5 516 |
| Key-Decapsulation | ML-KEM-1024 | 4 504 720 | 19 | 6 508 |
2.8. Post-Quantum Cryptography HBS-LMS signature verification
This section provides the performance results for ML-LMS signature verification.
The table below shows the number of clock cycles minimum, average and maximum and average time (in ms) needed to perform the described function in different functions and suite. Note: Clock cycles were measured for 10 different generated key and message pairs, and the reported Cycles avg values are averages over these measurements.
| Function | Suite | Cycles min | Cycles avg | Time avg (in ms) | Cycles max | Stack usage |
|---|---|---|---|---|---|---|
| LMS-Verify | LMS_N32_H10_W1_SHA256 | 1 023 304 | 1 065 928 | 4 | 1 112 976 | 1 668 |
| LMS-Verify | LMS_N32_H10_W2_SHA256 | 1 036 192 | 1 105 653 | 5 | 1 203 976 | 1 668 |
| LMS-Verify | LMS_N32_H10_W4_SHA256 | 1 777 880 | 2 062 884 | 9 | 2 392 536 | 1 668 |
| LMS-Verify | LMS_N32_H10_W8_SHA256 | 15 345 912 | 17 624 414 | 73 | 20 092 776 | 1 668 |