Cryptographic performance on STM32L0 MCUs

This page shows the measured performance results when using the pure software cryptographic library algorithms with an STM32L0 MCU. In addition to performance figures, it also gives the required code footprint and memory.


1. Measurement configuration

1.1. Hardware configuration

STM32 MCU STM32L073RZ
Device ID 0x447
Revision ID 0x2008
Board STM32L073RZ-Nucleo Rev C

1.2. Firmware configuration

Cryptographic library version 050000B2[ver. 1]
  1. This value corresponds to the information returned by a call to cmox_getInfos

1.3. System configuration

System core clock frequency 32 MHz
Flash latency 1 wait states
Voltage scaling Range 1
Prefetch cache (ART) 1 (0: disabled / 1: enabled)

1.4. Development toolchains and compilers

IAR Embedded Workbench IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM
Information
The measurements are done using a project built with the High Speed optimization setting enabled.


2. Performance values

2.1. AES symmetric key encryption and decryption

This section provides the performance results for AES-CBC using different operation modes:

  • Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
  • Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.

2.1.1. Sole buffer mode

In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.

AES mode Key size Buffer size Cipher operation Configuration Cycles Time
AES CBC 128 bits 32 bytes Encryption Small 5697 178 µs
AES CBC 128 bits 32 bytes Encryption Fast 5735 179 µs
AES CBC 128 bits 64 bytes Encryption Small 10 070 314 µs
AES CBC 128 bits 64 bytes Encryption Fast 10 134 316 µs
AES CBC 128 bits 128 bytes Encryption Small 18 807 587 µs
AES CBC 128 bits 128 bytes Encryption Fast 18 923 591 µs
AES CBC 192 bits 32 bytes Encryption Small 6378 199 µs
AES CBC 192 bits 32 bytes Encryption Fast 6416 200 µs
AES CBC 192 bits 64 bytes Encryption Small 11 464 358 µs
AES CBC 192 bits 64 bytes Encryption Fast 11 528 360 µs
AES CBC 192 bits 128 bytes Encryption Small 21 632 676 µs
AES CBC 192 bits 128 bytes Encryption Fast 21 748 679 µs
AES CBC 256 bits 32 bytes Encryption Small 7315 228 µs
AES CBC 256 bits 32 bytes Encryption Fast 7353 229 µs
AES CBC 256 bits 64 bytes Encryption Small 13 109 409 µs
AES CBC 256 bits 64 bytes Encryption Fast 13 173 411 µs
AES CBC 256 bits 128 bytes Encryption Small 24 695 771 µs
AES CBC 256 bits 128 bytes Encryption Fast 24 811 775 µs
AES CBC 128 bits 32 bytes Decryption Small 7330 229 µs
AES CBC 128 bits 32 bytes Decryption Fast 7368 230 µs
AES CBC 128 bits 64 bytes Decryption Small 13 339 416 µs
AES CBC 128 bits 64 bytes Decryption Fast 13 403 418 µs
AES CBC 128 bits 128 bytes Decryption Small 25 355 792 µs
AES CBC 128 bits 128 bytes Decryption Fast 25 471 795 µs
AES CBC 192 bits 32 bytes Decryption Small 8370 261 µs
AES CBC 192 bits 32 bytes Decryption Fast 8408 262 µs
AES CBC 192 bits 64 bytes Decryption Small 15 456 483 µs
AES CBC 192 bits 64 bytes Decryption Fast 15 520 485 µs
AES CBC 192 bits 128 bytes Decryption Small 29 618 925 µs
AES CBC 192 bits 128 bytes Decryption Fast 29 734 929 µs
AES CBC 256 bits 32 bytes Decryption Small 9671 302 µs
AES CBC 256 bits 32 bytes Decryption Fast 9709 303 µs
AES CBC 256 bits 64 bytes Decryption Small 17 823 556 µs
AES CBC 256 bits 64 bytes Decryption Fast 17 887 558 µs
AES CBC 256 bits 128 bytes Decryption Small 34 140 1066 µs
AES CBC 256 bits 128 bytes Decryption Fast 34 256 1070 µs


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2338 bytes 324 bytes 0 bytes 544 bytes
Encryption Fast 2362 bytes 324 bytes 0 bytes 552 bytes
Decryption Small 2742 bytes 592 bytes 0 bytes 564 bytes
Decryption Fast 2766 bytes 592 bytes 0 bytes 572 bytes


2.1.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_cipher_init
  • cmox_cipher_setKey
  • cmox_cipher_setIV
  • cmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.

AES mode Key size Message size Chunk size Cipher operation Configuration Cycles Bit rate
AES CBC 128 bits 8000 bytes 128 bytes Encryption Small 1 103 224 232 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Encryption Fast 1 109 728 230 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Small 1 095 000 233 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Fast 1 101 504 232 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Small 1 093 608 234 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Fast 1 100 104 232 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Small 1 092 904 234 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Fast 1 099 408 232 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Small 1 281 520 199 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Fast 1 288 024 198 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Small 1 273 296 201 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Fast 1 279 800 200 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Small 1 271 896 201 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Fast 1 278 400 200 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Small 1 271 200 201 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Fast 1 277 696 200 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Small 1 460 128 175 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Fast 1 466 624 174 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Small 1 451 904 176 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Fast 1 458 400 175 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Small 1 450 504 176 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Fast 1 457 000 175 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Small 1 449 800 176 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Fast 1 456 296 175 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Small 1 540 432 166 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Fast 1 546 928 165 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Small 1 529 128 167 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Fast 1 535 632 166 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Small 1 525 808 167 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Fast 1 532 304 167 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Small 1 521 840 168 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Fast 1 528 336 167 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Small 1 808 896 141 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Fast 1 815 392 141 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Small 1 797 600 142 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Fast 1 804 104 141 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Small 1 794 272 142 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Fast 1 800 768 142 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Small 1 790 304 142 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Fast 1 796 800 142 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Small 2 077 464 123 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Fast 2 083 960 122 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Small 2 066 168 123 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Fast 2 072 672 123 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Small 2 062 840 124 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Fast 2 069 336 123 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Small 2 058 864 124 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Fast 2 065 376 123 Kbytes/s


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2274 bytes 316 bytes 0 bytes 168 bytes
Encryption Fast 2298 bytes 316 bytes 0 bytes 176 bytes
Decryption Small 2678 bytes 584 bytes 0 bytes 188 bytes
Decryption Fast 2702 bytes 584 bytes 0 bytes 196 bytes


2.2. HASH digest

In this section we provide the performance results for HASH, using different modes of operation:

  • Sole buffer: one sole buffer is hashed. The performance time is given in us.
  • Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.

2.2.1. Sole buffer mode

In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.

HASH mode Buffer size Cycles Time
SHA256 32 bytes 9126 285 µs
SHA256 64 bytes 17 014 531 µs
SHA256 128 bytes 24 847 776 µs
SHA384 32 bytes 36 572 1142 µs
SHA384 64 bytes 36 592 1143 µs
SHA384 128 bytes 70 568 2205 µs


The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1502 280 bytes 0 bytes 564 bytes
SHA384 2810 728 bytes 0 bytes 1116 bytes


2.2.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_hash_init
  • cmox_hash_append: called several times to hash the whole message in fixed-size chunks
  • cmox_hash_generateTag

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.

HASH mode Message size Chunk size Cycles Bit rate
SHA256 8000 bytes 128 bytes 995 229 257 Kbytes/s
SHA256 8000 bytes 512 bytes 983 244 260 Kbytes/s
SHA256 8000 bytes 1024 bytes 981 204 260 Kbytes/s
SHA256 8000 bytes 2048 bytes 980 184 261 Kbytes/s
SHA384 8000 bytes 128 bytes 2 120 506 120 Kbytes/s
SHA384 8000 bytes 512 bytes 2 105 280 121 Kbytes/s
SHA384 8000 bytes 1024 bytes 2 102 664 121 Kbytes/s
SHA384 8000 bytes 2048 bytes 2 101 356 121 Kbytes/s


The table below shows the final tag generation done through the call to cmox_hash_generateTag.

HASH mode Cycles Time
SHA256 8527 266 µs
SHA384 35 931 1122 µs

The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1526 bytes 272 bytes 0 bytes 372 bytes
SHA384 2834 bytes 720 bytes 0 bytes 820 bytes


2.3. ECDSA signature and verification

This section provides the performance results for ECDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Operation ECC mathematics configuration Curve definition Cycles Time
SECP256R1 Signature Small Low 11 307 648 353 ms
SECP256R1 Signature Small High 10 958 208 342 ms
SECP256R1 Signature SuperFast Low 8 605 040 268 ms
SECP256R1 Signature SuperFast High 8 322 256 260 ms
SECP256R1 Verification Small Low 26 728 104 835 ms
SECP256R1 Verification Small High 23 692 520 740 ms
SECP256R1 Verification SuperFast Low 20 561 128 642 ms
SECP256R1 Verification SuperFast High 18 167 688 567 ms
SECP384R1 Signature Small Low 35 817 080 1119 ms
SECP384R1 Signature Small High 34 193 912 1068 ms
SECP384R1 Signature Fast Low 30 685 488 958 ms
SECP384R1 Signature Fast High 29 556 648 923 ms
SECP384R1 Verification Small Low 84 481 424 2640 ms
SECP384R1 Verification Small High 73 387 432 2293 ms
SECP384R1 Verification Fast Low 72 865 600 2277 ms
SECP384R1 Verification Fast High 63 862 680 1995 ms


The table below shows ECDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
SECP256R1 Signature Small Low 13 670 bytes 1212 bytes 0 bytes 424 bytes 628 bytes
SECP256R1 Signature Small High 13 670 bytes 1596 bytes 0 bytes 424 bytes 696 bytes
SECP256R1 Signature SuperFast Low 17 010 bytes 1212 bytes 0 bytes 472 bytes 628 bytes
SECP256R1 Signature SuperFast High 17 010 bytes 1596 bytes 0 bytes 472 bytes 696 bytes
SECP256R1 Verification Small Low 13 658 bytes 1212 bytes 0 bytes 472 bytes 856 bytes
SECP256R1 Verification Small High 13 658 bytes 1596 bytes 0 bytes 472 bytes 1648 bytes
SECP256R1 Verification SuperFast Low 16 998 bytes 1212 bytes 0 bytes 520 bytes 856 bytes
SECP256R1 Verification SuperFast High 16 998 bytes 1596 bytes 0 bytes 520 bytes 1648 bytes
SECP384R1 Signature Small Low 13 670 bytes 1692 bytes 0 bytes 424 bytes 884 bytes
SECP384R1 Signature Small High 13 670 bytes 2268 bytes 0 bytes 424 bytes 984 bytes
SECP384R1 Signature Fast Low 14 508 bytes 1692 bytes 0 bytes 416 bytes 884 bytes
SECP384R1 Signature Fast High 14 508 bytes 2268 bytes 0 bytes 416 bytes 984 bytes
SECP384R1 Verification Small Low 13 658 bytes 1692 bytes 0 bytes 472 bytes 1192 bytes
SECP384R1 Verification Small High 13 658 bytes 2268 bytes 0 bytes 472 bytes 2272 bytes
SECP384R1 Verification Fast Low 14 496 bytes 1692 bytes 0 bytes 464 bytes 1192 bytes
SECP384R1 Verification Fast High 14 496 bytes 2268 bytes 0 bytes 464 bytes 2272 bytes


2.4. EdDSA signature and verification

This section provides the performance results for EdDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Message size Operation ECC mathematics configuration Curve definition Cycles Time
Ed25519 1023 bytes Signature Small OptLow 15 995 112 499 ms
Ed25519 1023 bytes Signature Small OptHigh 9 217 136 288 ms
Ed25519 1023 bytes Signature SuperFast OptLow 12 774 520 399 ms
Ed25519 1023 bytes Signature SuperFast OptHigh 7 388 816 230 ms
Ed25519 1023 bytes Verification Small OptLow 25 177 616 786 ms
Ed25519 1023 bytes Verification Small OptHigh 22 031 672 688 ms
Ed25519 1023 bytes Verification SuperFast OptLow 19 685 112 615 ms
Ed25519 1023 bytes Verification SuperFast OptHigh 17 187 656 537 ms


The table below shows EdDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Message size Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
Ed25519 1023 bytes Signature Small OptLow 15 360 bytes 1748 bytes 0 bytes 1212 bytes 1672 bytes
Ed25519 1023 bytes Signature Small OptHigh 15 798 bytes 2900 bytes 0 bytes 1212 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptLow 18 700 bytes 1748 bytes 0 bytes 1212 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptHigh 19 138 bytes 2900 bytes 0 bytes 1212 bytes 1672 bytes
Ed25519 1023 bytes Verification Small OptLow 15 356 bytes 1748 bytes 0 bytes 1204 bytes 984 bytes
Ed25519 1023 bytes Verification Small OptHigh 15 794 bytes 2900 bytes 0 bytes 1204 bytes 1992 bytes
Ed25519 1023 bytes Verification SuperFast OptLow 18 696 bytes 1748 bytes 0 bytes 1204 bytes 984 bytes
Ed25519 1023 bytes Verification SuperFast OptHigh 19 134 bytes 2900 bytes 0 bytes 1204 bytes 1992 bytes


2.5. RSA signature and verification

This section provides the performance results for RSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Cycles Time
v2.2 CRT SHA-256 3K Signature Small Low 1 023 662 448 31 989 ms
v2.2 CRT SHA-256 3K Signature Small Mid 769 482 048 24 046 ms
v2.2 CRT SHA-256 3K Signature Small High 645 888 136 20 184 ms
v2.2 CRT SHA-256 3K Signature Fast Low 861 721 072 26 928 ms
v2.2 CRT SHA-256 3K Signature Fast Mid 627 359 064 19 604 ms
v2.2 CRT SHA-256 3K Signature Fast High 513 095 896 16 034 ms
v2.2 No CRT SHA-256 3K Signature Small Low 4 026 121 352 125 816 ms
v2.2 No CRT SHA-256 3K Signature Small Mid 3 022 393 664 94 449 ms
v2.2 No CRT SHA-256 3K Signature Small High 2 527 583 256 78 986 ms
v2.2 No CRT SHA-256 3K Signature Fast Low 3 380 380 192 105 636 ms
v2.2 No CRT SHA-256 3K Signature Fast Mid 2 451 677 800 76 614 ms
v2.2 No CRT SHA-256 3K Signature Fast High 1 993 199 720 62 287 ms
v2.2 n/a SHA-256 3K Verification Small n/a 15 864 256 495 ms
v2.2 n/a SHA-256 3K Verification Fast n/a 13 128 352 410 ms


The table below shows RSA flash memory and RAM usage (in bytes).

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Code Constant data Global data Stack usage Working buffer
v2.2 CRT SHA-256 3K Signature Small Low 7178 bytes 372 bytes 0 bytes 692 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Small Mid 7430 bytes 372 bytes 0 bytes 692 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Small High 7430 bytes 372 bytes 0 bytes 692 bytes 6708 bytes
v2.2 CRT SHA-256 3K Signature Fast Low 8016 bytes 372 bytes 0 bytes 692 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Fast Mid 8268 bytes 372 bytes 0 bytes 692 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Fast High 8268 bytes 372 bytes 0 bytes 692 bytes 6708 bytes
v2.2 No CRT SHA-256 3K Signature Small Low 6268 bytes 364 bytes 0 bytes 692 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Small Mid 6520 bytes 364 bytes 0 bytes 692 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Small High 6520 bytes 364 bytes 0 bytes 692 bytes 9368 bytes
v2.2 No CRT SHA-256 3K Signature Fast Low 7106 bytes 364 bytes 0 bytes 692 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Fast Mid 7358 bytes 364 bytes 0 bytes 692 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Fast High 7358 bytes 364 bytes 0 bytes 692 bytes 9368 bytes
v2.2 n/a SHA-256 3K Verification Small n/a 6464 bytes 368 bytes 0 bytes 708 bytes 3108 bytes
v2.2 n/a SHA-256 3K Verification Fast n/a 7302 bytes 368 bytes 0 bytes 708 bytes 3108 bytes


2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification

This section provides the performance results for ML-DSA key Generation, signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites configurations. Note: for Signature, the clock cycles is measured for one "predefined" private key and one 32 bytes message.

Function Suite Cycles Time (in ms) Stack usage Working buffer
ML-DSA-44 keyGen 4 691 440 146 676 7116
ML-DSA-65 keyGen 7 827 608 244 676 8140
ML-DSA-44 Signature Low RAM 11 122 248 347 964 11 340
ML-DSA-44 Verification Low RAM 8 686 848 271 900 4812
ML-DSA-65 Verification Low RAM 15 042 952 470 900 4828
ML-DSA-87 Verification Low RAM 25 564 464 798 900 5100