Cryptographic performance on STM32L1 Series V5.x

This page reports measured performance when using the pure software cryptographic library algorithms with an STM32L1 MCU. In addition to performance figures, the required code footprint and memory are also given.

1. Measurement configuration

1.1. Hardware configuration

STM32 MCU STM32L152RET6
Device ID 0x437
Revision ID 0x1008
Board STM32L152RE-Nucleo Rev C

1.2. Firmware configuration

Cryptographic library version 050000B2[ver. 1]
  1. This value corresponds to the information returned by a call to cmox_getInfos

1.3. System configuration

System core clock frequency 32 MHz
Flash latency 1 wait states
Voltage scaling Range 1
Prefetch cache (ART) 1 (0: disabled / 1: enabled)

1.4. Development toolchains and compilers

IAR Embedded Workbench IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM
Information
The measurements are done using a project built with the High Speed optimization setting enabled.


2. Performance values

2.1. AES symmetric key encryption and decryption

This section provides the performance results for AES-CBC using different operation modes:

  • Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
  • Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.

2.1.1. Sole buffer mode

In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.

AES mode Key size Buffer size Cipher operation Configuration Cycles Time
AES CBC 128 bits 32 bytes Encryption Small 5764 180 µs
AES CBC 128 bits 32 bytes Encryption Fast 4798 149 µs
AES CBC 128 bits 64 bytes Encryption Small 9842 307 µs
AES CBC 128 bits 64 bytes Encryption Fast 7897 246 µs
AES CBC 128 bits 128 bytes Encryption Small 17 983 561 µs
AES CBC 128 bits 128 bytes Encryption Fast 14 091 440 µs
AES CBC 192 bits 32 bytes Encryption Small 6413 200 µs
AES CBC 192 bits 32 bytes Encryption Fast 5293 165 µs
AES CBC 192 bits 64 bytes Encryption Small 11 143 348 µs
AES CBC 192 bits 64 bytes Encryption Fast 8909 278 µs
AES CBC 192 bits 128 bytes Encryption Small 20 599 643 µs
AES CBC 192 bits 128 bytes Encryption Fast 16 137 504 µs
AES CBC 256 bits 32 bytes Encryption Small 7388 230 µs
AES CBC 256 bits 32 bytes Encryption Fast 6102 190 µs
AES CBC 256 bits 64 bytes Encryption Small 12 809 400 µs
AES CBC 256 bits 64 bytes Encryption Fast 10 238 319 µs
AES CBC 256 bits 128 bytes Encryption Small 23 642 738 µs
AES CBC 256 bits 128 bytes Encryption Fast 18 510 578 µs
AES CBC 128 bits 32 bytes Decryption Small 9497 296 µs
AES CBC 128 bits 32 bytes Decryption Fast 6340 198 µs
AES CBC 128 bits 64 bytes Decryption Small 17 293 540 µs
AES CBC 128 bits 64 bytes Decryption Fast 9462 295 µs
AES CBC 128 bits 128 bytes Decryption Small 32 873 1027 µs
AES CBC 128 bits 128 bytes Decryption Fast 15 709 490 µs
AES CBC 192 bits 32 bytes Decryption Small 11 041 345 µs
AES CBC 192 bits 32 bytes Decryption Fast 7202 225 µs
AES CBC 192 bits 64 bytes Decryption Small 20 392 637 µs
AES CBC 192 bits 64 bytes Decryption Fast 10 871 339 µs
AES CBC 192 bits 128 bytes Decryption Small 39 099 1221 µs
AES CBC 192 bits 128 bytes Decryption Fast 18 212 569 µs
AES CBC 256 bits 32 bytes Decryption Small 12 890 402 µs
AES CBC 256 bits 32 bytes Decryption Fast 8347 260 µs
AES CBC 256 bits 64 bytes Decryption Small 23 809 744 µs
AES CBC 256 bits 64 bytes Decryption Fast 12 549 392 µs
AES CBC 256 bits 128 bytes Decryption Small 45 655 1426 µs
AES CBC 256 bits 128 bytes Decryption Fast 20 953 654 µs


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2042 bytes 364 bytes 36 bytes 504 bytes
Encryption Fast 2124 bytes 1388 bytes 0 bytes 548 bytes
Decryption Small 2072 bytes 620 bytes 0 bytes 560 bytes
Decryption Fast 2642 bytes 1644 bytes 0 bytes 564 bytes


2.1.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_cipher_init
  • cmox_cipher_setKey
  • cmox_cipher_setIV
  • cmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.

AES mode Key size Message size Chunk size Cipher operation Configuration Cycles Bit rate
AES CBC 128 bits 8000 bytes 128 bytes Encryption Small 1 027 592 249 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Encryption Fast 783 920 326 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Small 1 020 728 250 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Fast 777 064 329 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Small 1 019 560 251 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Fast 775 888 329 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Small 1 018 976 251 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Fast 775 312 330 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Small 1 192 288 214 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Fast 912 784 280 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Small 1 185 424 215 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Fast 905 928 282 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Small 1 184 264 216 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Fast 904 760 282 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Small 1 183 680 216 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Fast 904 176 283 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Small 1 365 800 187 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Fast 1 043 728 245 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Small 1 358 928 188 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Fast 1 036 872 246 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Small 1 357 768 188 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Fast 1 035 704 247 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Small 1 357 192 188 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Fast 1 035 112 247 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Small 1 981 040 129 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Fast 813 688 314 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Small 1 971 672 129 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Fast 804 336 318 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Small 1 968 856 130 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Fast 801 504 319 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Small 1 965 424 130 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Fast 798 080 320 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Small 2 371 392 107 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Fast 949 920 269 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Small 2 362 016 108 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Fast 940 552 272 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Small 2 359 192 108 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Fast 937 720 273 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Small 2 355 760 108 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Fast 934 304 274 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Small 2 762 992 92 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Fast 1 082 856 236 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Small 2 753 624 92 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Fast 1 073 488 238 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Small 2 750 808 93 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Fast 1 070 664 239 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Small 2 747 376 93 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Fast 1 067 240 239 Kbytes/s


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 1962 bytes 356 bytes 36 bytes 128 bytes
Encryption Fast 2044 bytes 1380 bytes 0 bytes 172 bytes
Decryption Small 1992 bytes 612 bytes 0 bytes 184 bytes
Decryption Fast 2562 bytes 1636 bytes 0 bytes 188 bytes


2.2. HASH digest

In this section we provide the performance results for HASH, using different modes of operation:

  • Sole buffer: one sole buffer is hashed. The performance time is given in us.
  • Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.

2.2.1. Sole buffer mode

In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.

HASH mode Buffer size Cycles Time
SHA256 32 bytes 4656 145 µs
SHA256 64 bytes 8086 252 µs
SHA256 128 bytes 11 204 350 µs
SHA384 32 bytes 18 494 577 µs
SHA384 64 bytes 18 768 586 µs
SHA384 128 bytes 35 678 1114 µs


The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1358 280 bytes 0 bytes 532 bytes
SHA384 2532 728 bytes 0 bytes 1076 bytes


2.2.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_hash_init
  • cmox_hash_append: called several times to hash the whole message in fixed-size chunks
  • cmox_hash_generateTag

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.

HASH mode Message size Chunk size Cycles Bit rate
SHA256 8000 bytes 128 bytes 433 556 590 Kbytes/s
SHA256 8000 bytes 512 bytes 400 985 638 Kbytes/s
SHA256 8000 bytes 1024 bytes 395 441 647 Kbytes/s
SHA256 8000 bytes 2048 bytes 392 669 651 Kbytes/s
SHA384 8000 bytes 128 bytes 1 089 868 234 Kbytes/s
SHA384 8000 bytes 512 bytes 1 031 338 248 Kbytes/s
SHA384 8000 bytes 1024 bytes 1 021 178 250 Kbytes/s
SHA384 8000 bytes 2048 bytes 1 016 098 251 Kbytes/s


The table below shows the final tag generation done through the call to cmox_hash_generateTag.

HASH mode Cycles Time
SHA256 3681 115 µs
SHA384 17 227 538 µs

The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1354 bytes 272 bytes 0 bytes 340 bytes
SHA384 2528 bytes 720 bytes 0 bytes 780 bytes


2.3. ECDSA signature and verification

This section provides the performance results for ECDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Operation ECC mathematics configuration Curve definition Cycles Time
SECP256R1 Signature Small Low 6 512 424 203 ms
SECP256R1 Signature Small High 6 237 968 194 ms
SECP256R1 Verification Small Low 15 394 288 481 ms
SECP256R1 Verification Small High 13 511 560 422 ms
SECP384R1 Signature Small Low 19 123 112 597 ms
SECP384R1 Signature Small High 18 190 720 568 ms
SECP384R1 Verification Small Low 45 107 344 1409 ms
SECP384R1 Verification Small High 39 114 312 1222 ms


The table below shows ECDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
SECP256R1 Signature Small Low 14 816 bytes 1212 bytes 0 bytes 472 bytes 628 bytes
SECP256R1 Signature Small High 14 816 bytes 1596 bytes 0 bytes 472 bytes 696 bytes
SECP256R1 Verification Small Low 14 804 bytes 1212 bytes 0 bytes 520 bytes 856 bytes
SECP256R1 Verification Small High 14 804 bytes 1596 bytes 0 bytes 520 bytes 1648 bytes
SECP384R1 Signature Small Low 14 816 bytes 1692 bytes 0 bytes 472 bytes 884 bytes
SECP384R1 Signature Small High 14 816 bytes 2268 bytes 0 bytes 472 bytes 984 bytes
SECP384R1 Verification Small Low 14 804 bytes 1692 bytes 0 bytes 520 bytes 1192 bytes
SECP384R1 Verification Small High 14 804 bytes 2268 bytes 0 bytes 520 bytes 2272 bytes


2.4. EdDSA signature and verification

This section provides the performance results for EdDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Message size Operation ECC mathematics configuration Curve definition Cycles Time
Ed25519 1023 bytes Signature Small OptLow 9 450 040 295 ms
Ed25519 1023 bytes Signature Small OptHigh 5 412 912 169 ms
Ed25519 1023 bytes Signature Fast OptLow 88 0 ms
Ed25519 1023 bytes Verification Small OptLow 14 826 376 463 ms
Ed25519 1023 bytes Verification Small OptHigh 12 986 800 405 ms
Ed25519 1023 bytes Verification Fast OptLow 88 0 ms


The table below shows EdDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Message size Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
Ed25519 1023 bytes Signature Small OptLow 16 154 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature Small OptHigh 16 574 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature Fast OptLow 14 242 bytes 1748 bytes 0 bytes 28 bytes 0 bytes
Ed25519 1023 bytes Verification Small OptLow 16 150 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification Small OptHigh 16 570 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes
Ed25519 1023 bytes Verification Fast OptLow 14 238 bytes 1748 bytes 0 bytes 24 bytes 0 bytes


2.5. RSA signature and verification

This section provides the performance results for RSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Cycles Time
v2.2 CRT SHA-256 3K Signature Small Low 476 082 256 14 877 ms
v2.2 CRT SHA-256 3K Signature Small Mid 356 393 008 11 137 ms
v2.2 CRT SHA-256 3K Signature Small High 299 184 224 9349 ms
v2.2 No CRT SHA-256 3K Signature Small Low 1 827 309 912 57 103 ms
v2.2 No CRT SHA-256 3K Signature Small Mid 1 363 421 384 42 606 ms
v2.2 No CRT SHA-256 3K Signature Small High 1 140 251 536 35 632 ms
v2.2 n/a SHA-256 3K Verification Small n/a 7 609 784 237 ms


The table below shows RSA flash memory and RAM usage (in bytes).

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Code Constant data Global data Stack usage Working buffer
v2.2 CRT SHA-256 3K Signature Small Low 8224 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Small Mid 8460 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Small High 8460 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 No CRT SHA-256 3K Signature Small Low 7292 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Small Mid 7528 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Small High 7528 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 n/a SHA-256 3K Verification Small n/a 7476 bytes 368 bytes 0 bytes 684 bytes 3108 bytes


2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification

This section provides the performance results for ML-DSA key pair generation, signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites and functions configurations. Note: For signature generation, the number of clock cycles is not bounded in time. The measurement was taken using one predefined private key and one 32-byte message, and the reported value corresponds to the minimum observed time.

Suite Function Cycles Time (in ms) Stack usage Working buffer
ML-DSA-44 keyGen 2 410 936 75 476 7116
ML-DSA-65 keyGen 4 080 840 127 476 8140
ML-DSA-87 keyGen 6 865 336 214 476 10 188
ML-DSA-44 Signature 4 746 240 148 772 30 796
ML-DSA-44 Signature Low RAM 5 018 248 156 756 11 340
ML-DSA-65 Signature 7 224 904 225 772 43 084
ML-DSA-65 Signature Low RAM 7 465 152 233 756 15 436
ML-DSA-44 Verification 2 804 480 87 700 8908
ML-DSA-44 Verification Low RAM 3 943 496 123 700 4812
ML-DSA-65 Verification 4 555 152 142 700 9948
ML-DSA-65 Verification Low RAM 6 846 928 213 700 4828
ML-DSA-87 Verification 7 401 848 231 700 12 268
ML-DSA-87 Verification Low RAM 11 793 968 368 700 5100

2.7. Post-Quantum Cryptography ML-KEM key pair generation, encapsulation, decapsulation

This section provides the performance results for ML-KEM key pair generation, encapsulation and decapsulation.

The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different functions and suites.

Function Suites Cycles Time (in ms) Stack usage
Key-pair-Generation ML-KEM-512 748 600 23 3 060
Key-pair-Generation ML-KEM-768 1 236 080 39 3 572
Key-pair-Generation ML-KEM-1024 1 926 832 60 4 084
Key-Encapsulation ML-KEM-512 2 664 896 83 4 588
Key-Encapsulation ML-KEM-768 3 807 328 119 5 100
Key-Encapsulation ML-KEM-1024 5 126 648 160 5 612
Key-Decapsulation ML-KEM-512 2 991 480 93 4 684
Key-Decapsulation ML-KEM-768 4 247 720 133 5 516
Key-Decapsulation ML-KEM-1024 5 686 768 178 6 508

2.8. Post-Quantum Cryptography HBS-LMS signature verification

This section provides the performance results for ML-LMS signature verification.

The table below shows the number of clock cycles minimum, average and maximum and average time (in ms) needed to perform the described function in different functions and suite. Note: Clock cycles were measured for 10 different generated key and message pairs, and the reported Cycles avg values are averages over these measurements.

Function Suite Cycles min Cycles avg Time avg (in ms) Cycles max Stack usage
LMS-Verify LMS_N32_H10_W1_SHA256 1 153 392 1 201 049 38 1 253 720 1 668
LMS-Verify LMS_N32_H10_W2_SHA256 1 161 336 1 238 717 39 1 348 320 1 668
LMS-Verify LMS_N32_H10_W4_SHA256 1 984 104 2 301 476 72 2 668 624 1 668
LMS-Verify LMS_N32_H10_W8_SHA256 17 099 424 19 638 012 614 22 388 152 1 668