This page shows the measured performance results when using the pure software cryptographic library algorithms with an STM32L0 MCU. In addition to performance figures, it also gives the required code footprint and memory.
1. Measurement configuration
1.1. Hardware configuration
| STM32 MCU | STM32L073RZ |
| Device ID | 0x447 |
| Revision ID | 0x2008 |
| Board | STM32L073RZ-Nucleo Rev C |
1.2. Firmware configuration
| Cryptographic library version | 050000B2[ver. 1] |
- ↑ This value corresponds to the information returned by a call to
cmox_getInfos
1.3. System configuration
| System core clock frequency | 32 MHz |
| Flash latency | 1 wait states |
| Voltage scaling | Range 1 |
| Prefetch cache (ART) | 1 (0: disabled / 1: enabled) |
1.4. Development toolchains and compilers
| IAR Embedded Workbench | IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM |
2. Performance values
2.1. AES symmetric key encryption and decryption
This section provides the performance results for AES-CBC using different operation modes:
- Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
- Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.
2.1.1. Sole buffer mode
In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.
| AES mode | Key size | Buffer size | Cipher operation | Configuration | Cycles | Time |
|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 32 bytes | Encryption | Small | 5697 | 178 µs |
| AES CBC | 128 bits | 32 bytes | Encryption | Fast | 5735 | 179 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Small | 10 070 | 314 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Fast | 10 134 | 316 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Small | 18 807 | 587 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Fast | 18 923 | 591 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Small | 6378 | 199 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Fast | 6416 | 200 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Small | 11 464 | 358 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Fast | 11 528 | 360 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Small | 21 632 | 676 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Fast | 21 748 | 679 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Small | 7315 | 228 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Fast | 7353 | 229 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Small | 13 109 | 409 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Fast | 13 173 | 411 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Small | 24 695 | 771 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Fast | 24 811 | 775 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Small | 7330 | 229 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Fast | 7368 | 230 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Small | 13 339 | 416 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Fast | 13 403 | 418 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Small | 25 355 | 792 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Fast | 25 471 | 795 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Small | 8370 | 261 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Fast | 8408 | 262 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Small | 15 456 | 483 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Fast | 15 520 | 485 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Small | 29 618 | 925 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Fast | 29 734 | 929 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Small | 9671 | 302 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Fast | 9709 | 303 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Small | 17 823 | 556 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Fast | 17 887 | 558 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Small | 34 140 | 1066 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Fast | 34 256 | 1070 µs |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2338 bytes | 324 bytes | 0 bytes | 544 bytes |
| Encryption | Fast | 2362 bytes | 324 bytes | 0 bytes | 552 bytes |
| Decryption | Small | 2742 bytes | 592 bytes | 0 bytes | 564 bytes |
| Decryption | Fast | 2766 bytes | 592 bytes | 0 bytes | 572 bytes |
2.1.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_cipher_initcmox_cipher_setKeycmox_cipher_setIVcmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.
| AES mode | Key size | Message size | Chunk size | Cipher operation | Configuration | Cycles | Bit rate |
|---|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Small | 1 103 224 | 232 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Fast | 1 109 728 | 230 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Small | 1 095 000 | 233 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Fast | 1 101 504 | 232 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Small | 1 093 608 | 234 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 1 100 104 | 232 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Small | 1 092 904 | 234 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 1 099 408 | 232 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Small | 1 281 520 | 199 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Fast | 1 288 024 | 198 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Small | 1 273 296 | 201 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Fast | 1 279 800 | 200 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Small | 1 271 896 | 201 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 1 278 400 | 200 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Small | 1 271 200 | 201 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 1 277 696 | 200 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Small | 1 460 128 | 175 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Fast | 1 466 624 | 174 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Small | 1 451 904 | 176 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Fast | 1 458 400 | 175 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Small | 1 450 504 | 176 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 1 457 000 | 175 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Small | 1 449 800 | 176 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 1 456 296 | 175 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 540 432 | 166 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Fast | 1 546 928 | 165 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 529 128 | 167 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Fast | 1 535 632 | 166 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 525 808 | 167 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 1 532 304 | 167 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 521 840 | 168 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 1 528 336 | 167 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 808 896 | 141 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Fast | 1 815 392 | 141 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 797 600 | 142 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Fast | 1 804 104 | 141 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 794 272 | 142 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 1 800 768 | 142 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 790 304 | 142 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 1 796 800 | 142 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Small | 2 077 464 | 123 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Fast | 2 083 960 | 122 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Small | 2 066 168 | 123 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Fast | 2 072 672 | 123 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Small | 2 062 840 | 124 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 2 069 336 | 123 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Small | 2 058 864 | 124 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 2 065 376 | 123 Kbytes/s |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2274 bytes | 316 bytes | 0 bytes | 168 bytes |
| Encryption | Fast | 2298 bytes | 316 bytes | 0 bytes | 176 bytes |
| Decryption | Small | 2678 bytes | 584 bytes | 0 bytes | 188 bytes |
| Decryption | Fast | 2702 bytes | 584 bytes | 0 bytes | 196 bytes |
2.2. HASH digest
In this section we provide the performance results for HASH, using different modes of operation:
- Sole buffer: one sole buffer is hashed. The performance time is given in us.
- Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.
2.2.1. Sole buffer mode
In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.
| HASH mode | Buffer size | Cycles | Time |
|---|---|---|---|
| SHA256 | 32 bytes | 9126 | 285 µs |
| SHA256 | 64 bytes | 17 014 | 531 µs |
| SHA256 | 128 bytes | 24 847 | 776 µs |
| SHA384 | 32 bytes | 36 572 | 1142 µs |
| SHA384 | 64 bytes | 36 592 | 1143 µs |
| SHA384 | 128 bytes | 70 568 | 2205 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1502 | 280 bytes | 0 bytes | 564 bytes |
| SHA384 | 2810 | 728 bytes | 0 bytes | 1116 bytes |
2.2.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_hash_initcmox_hash_append: called several times to hash the whole message in fixed-size chunkscmox_hash_generateTag
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.
| HASH mode | Message size | Chunk size | Cycles | Bit rate |
|---|---|---|---|---|
| SHA256 | 8000 bytes | 128 bytes | 995 229 | 257 Kbytes/s |
| SHA256 | 8000 bytes | 512 bytes | 983 244 | 260 Kbytes/s |
| SHA256 | 8000 bytes | 1024 bytes | 981 204 | 260 Kbytes/s |
| SHA256 | 8000 bytes | 2048 bytes | 980 184 | 261 Kbytes/s |
| SHA384 | 8000 bytes | 128 bytes | 2 120 506 | 120 Kbytes/s |
| SHA384 | 8000 bytes | 512 bytes | 2 105 280 | 121 Kbytes/s |
| SHA384 | 8000 bytes | 1024 bytes | 2 102 664 | 121 Kbytes/s |
| SHA384 | 8000 bytes | 2048 bytes | 2 101 356 | 121 Kbytes/s |
The table below shows the final tag generation done through the call to cmox_hash_generateTag.
| HASH mode | Cycles | Time |
|---|---|---|
| SHA256 | 8527 | 266 µs |
| SHA384 | 35 931 | 1122 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1526 bytes | 272 bytes | 0 bytes | 372 bytes |
| SHA384 | 2834 bytes | 720 bytes | 0 bytes | 820 bytes |
2.3. ECDSA signature and verification
This section provides the performance results for ECDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 11 307 648 | 353 ms |
| SECP256R1 | Signature | Small | High | 10 958 208 | 342 ms |
| SECP256R1 | Signature | SuperFast | Low | 8 605 040 | 268 ms |
| SECP256R1 | Signature | SuperFast | High | 8 322 256 | 260 ms |
| SECP256R1 | Verification | Small | Low | 26 728 104 | 835 ms |
| SECP256R1 | Verification | Small | High | 23 692 520 | 740 ms |
| SECP256R1 | Verification | SuperFast | Low | 20 561 128 | 642 ms |
| SECP256R1 | Verification | SuperFast | High | 18 167 688 | 567 ms |
| SECP384R1 | Signature | Small | Low | 35 817 080 | 1119 ms |
| SECP384R1 | Signature | Small | High | 34 193 912 | 1068 ms |
| SECP384R1 | Signature | Fast | Low | 30 685 488 | 958 ms |
| SECP384R1 | Signature | Fast | High | 29 556 648 | 923 ms |
| SECP384R1 | Verification | Small | Low | 84 481 424 | 2640 ms |
| SECP384R1 | Verification | Small | High | 73 387 432 | 2293 ms |
| SECP384R1 | Verification | Fast | Low | 72 865 600 | 2277 ms |
| SECP384R1 | Verification | Fast | High | 63 862 680 | 1995 ms |
The table below shows ECDSA flash memory and RAM usage (in bytes).
| Curve | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 13 670 bytes | 1212 bytes | 0 bytes | 424 bytes | 628 bytes |
| SECP256R1 | Signature | Small | High | 13 670 bytes | 1596 bytes | 0 bytes | 424 bytes | 696 bytes |
| SECP256R1 | Signature | SuperFast | Low | 17 010 bytes | 1212 bytes | 0 bytes | 472 bytes | 628 bytes |
| SECP256R1 | Signature | SuperFast | High | 17 010 bytes | 1596 bytes | 0 bytes | 472 bytes | 696 bytes |
| SECP256R1 | Verification | Small | Low | 13 658 bytes | 1212 bytes | 0 bytes | 472 bytes | 856 bytes |
| SECP256R1 | Verification | Small | High | 13 658 bytes | 1596 bytes | 0 bytes | 472 bytes | 1648 bytes |
| SECP256R1 | Verification | SuperFast | Low | 16 998 bytes | 1212 bytes | 0 bytes | 520 bytes | 856 bytes |
| SECP256R1 | Verification | SuperFast | High | 16 998 bytes | 1596 bytes | 0 bytes | 520 bytes | 1648 bytes |
| SECP384R1 | Signature | Small | Low | 13 670 bytes | 1692 bytes | 0 bytes | 424 bytes | 884 bytes |
| SECP384R1 | Signature | Small | High | 13 670 bytes | 2268 bytes | 0 bytes | 424 bytes | 984 bytes |
| SECP384R1 | Signature | Fast | Low | 14 508 bytes | 1692 bytes | 0 bytes | 416 bytes | 884 bytes |
| SECP384R1 | Signature | Fast | High | 14 508 bytes | 2268 bytes | 0 bytes | 416 bytes | 984 bytes |
| SECP384R1 | Verification | Small | Low | 13 658 bytes | 1692 bytes | 0 bytes | 472 bytes | 1192 bytes |
| SECP384R1 | Verification | Small | High | 13 658 bytes | 2268 bytes | 0 bytes | 472 bytes | 2272 bytes |
| SECP384R1 | Verification | Fast | Low | 14 496 bytes | 1692 bytes | 0 bytes | 464 bytes | 1192 bytes |
| SECP384R1 | Verification | Fast | High | 14 496 bytes | 2268 bytes | 0 bytes | 464 bytes | 2272 bytes |
2.4. EdDSA signature and verification
This section provides the performance results for EdDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 15 995 112 | 499 ms |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 9 217 136 | 288 ms |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptLow | 12 774 520 | 399 ms |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptHigh | 7 388 816 | 230 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 25 177 616 | 786 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 22 031 672 | 688 ms |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptLow | 19 685 112 | 615 ms |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptHigh | 17 187 656 | 537 ms |
The table below shows EdDSA flash memory and RAM usage (in bytes).
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 15 360 bytes | 1748 bytes | 0 bytes | 1212 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 15 798 bytes | 2900 bytes | 0 bytes | 1212 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptLow | 18 700 bytes | 1748 bytes | 0 bytes | 1212 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptHigh | 19 138 bytes | 2900 bytes | 0 bytes | 1212 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 15 356 bytes | 1748 bytes | 0 bytes | 1204 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 15 794 bytes | 2900 bytes | 0 bytes | 1204 bytes | 1992 bytes |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptLow | 18 696 bytes | 1748 bytes | 0 bytes | 1204 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptHigh | 19 134 bytes | 2900 bytes | 0 bytes | 1204 bytes | 1992 bytes |
2.5. RSA signature and verification
This section provides the performance results for RSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Cycles | Time |
|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 1 023 662 448 | 31 989 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 769 482 048 | 24 046 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 645 888 136 | 20 184 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Low | 861 721 072 | 26 928 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Mid | 627 359 064 | 19 604 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | High | 513 095 896 | 16 034 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 4 026 121 352 | 125 816 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 3 022 393 664 | 94 449 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 2 527 583 256 | 78 986 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Low | 3 380 380 192 | 105 636 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Mid | 2 451 677 800 | 76 614 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | High | 1 993 199 720 | 62 287 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 15 864 256 | 495 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Fast | n/a | 13 128 352 | 410 ms |
The table below shows RSA flash memory and RAM usage (in bytes).
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 7178 bytes | 372 bytes | 0 bytes | 692 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 7430 bytes | 372 bytes | 0 bytes | 692 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 7430 bytes | 372 bytes | 0 bytes | 692 bytes | 6708 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Low | 8016 bytes | 372 bytes | 0 bytes | 692 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Mid | 8268 bytes | 372 bytes | 0 bytes | 692 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | High | 8268 bytes | 372 bytes | 0 bytes | 692 bytes | 6708 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 6268 bytes | 364 bytes | 0 bytes | 692 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 6520 bytes | 364 bytes | 0 bytes | 692 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 6520 bytes | 364 bytes | 0 bytes | 692 bytes | 9368 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Low | 7106 bytes | 364 bytes | 0 bytes | 692 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Mid | 7358 bytes | 364 bytes | 0 bytes | 692 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | High | 7358 bytes | 364 bytes | 0 bytes | 692 bytes | 9368 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 6464 bytes | 368 bytes | 0 bytes | 708 bytes | 3108 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Fast | n/a | 7302 bytes | 368 bytes | 0 bytes | 708 bytes | 3108 bytes |
2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification
This section provides the performance results for ML-DSA key Generation, signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites configurations. Note: for Signature, the clock cycles is measured for one "predefined" private key and one 32 bytes message.
| Function | Suite | Cycles | Time (in ms) | Stack usage | Working buffer |
|---|---|---|---|---|---|
| ML-DSA-44 | keyGen | 4 691 440 | 146 | 676 | 7116 |
| ML-DSA-65 | keyGen | 7 827 608 | 244 | 676 | 8140 |
| ML-DSA-44 | Signature Low RAM | 11 122 248 | 347 | 964 | 11 340 |
| ML-DSA-44 | Verification Low RAM | 8 686 848 | 271 | 900 | 4812 |
| ML-DSA-65 | Verification Low RAM | 15 042 952 | 470 | 900 | 4828 |
| ML-DSA-87 | Verification Low RAM | 25 564 464 | 798 | 900 | 5100 |