This page reports measured performance when using the pure software cryptographic library algorithms with an STM32L1 MCU. In addition to performance figures, the required code footprint and memory are also given.
1. Measurement configuration
1.1. Hardware configuration
| STM32 MCU | STM32L152RET6 |
| Device ID | 0x437 |
| Revision ID | 0x1008 |
| Board | STM32L152RE-Nucleo Rev C |
1.2. Firmware configuration
| Cryptographic library version | 050000B2[ver. 1] |
- ↑ This value corresponds to the information returned by a call to
cmox_getInfos
1.3. System configuration
| System core clock frequency | 32 MHz |
| Flash latency | 1 wait states |
| Voltage scaling | Range 1 |
| Prefetch cache (ART) | 1 (0: disabled / 1: enabled) |
1.4. Development toolchains and compilers
| IAR Embedded Workbench | IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM |
2. Performance values
2.1. AES symmetric key encryption and decryption
This section provides the performance results for AES-CBC using different operation modes:
- Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
- Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.
2.1.1. Sole buffer mode
In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.
| AES mode | Key size | Buffer size | Cipher operation | Configuration | Cycles | Time |
|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 32 bytes | Encryption | Small | 5764 | 180 µs |
| AES CBC | 128 bits | 32 bytes | Encryption | Fast | 4798 | 149 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Small | 9842 | 307 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Fast | 7897 | 246 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Small | 17 983 | 561 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Fast | 14 091 | 440 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Small | 6413 | 200 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Fast | 5293 | 165 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Small | 11 143 | 348 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Fast | 8909 | 278 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Small | 20 599 | 643 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Fast | 16 137 | 504 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Small | 7388 | 230 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Fast | 6102 | 190 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Small | 12 809 | 400 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Fast | 10 238 | 319 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Small | 23 642 | 738 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Fast | 18 510 | 578 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Small | 9497 | 296 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Fast | 6340 | 198 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Small | 17 293 | 540 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Fast | 9462 | 295 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Small | 32 873 | 1027 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Fast | 15 709 | 490 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Small | 11 041 | 345 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Fast | 7202 | 225 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Small | 20 392 | 637 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Fast | 10 871 | 339 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Small | 39 099 | 1221 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Fast | 18 212 | 569 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Small | 12 890 | 402 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Fast | 8347 | 260 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Small | 23 809 | 744 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Fast | 12 549 | 392 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Small | 45 655 | 1426 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Fast | 20 953 | 654 µs |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2042 bytes | 364 bytes | 36 bytes | 504 bytes |
| Encryption | Fast | 2124 bytes | 1388 bytes | 0 bytes | 548 bytes |
| Decryption | Small | 2072 bytes | 620 bytes | 0 bytes | 560 bytes |
| Decryption | Fast | 2642 bytes | 1644 bytes | 0 bytes | 564 bytes |
2.1.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_cipher_initcmox_cipher_setKeycmox_cipher_setIVcmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.
| AES mode | Key size | Message size | Chunk size | Cipher operation | Configuration | Cycles | Bit rate |
|---|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Small | 1 027 592 | 249 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Fast | 783 920 | 326 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Small | 1 020 728 | 250 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Fast | 777 064 | 329 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Small | 1 019 560 | 251 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 775 888 | 329 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Small | 1 018 976 | 251 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 775 312 | 330 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Small | 1 192 288 | 214 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Fast | 912 784 | 280 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Small | 1 185 424 | 215 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Fast | 905 928 | 282 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Small | 1 184 264 | 216 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 904 760 | 282 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Small | 1 183 680 | 216 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 904 176 | 283 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Small | 1 365 800 | 187 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Fast | 1 043 728 | 245 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Small | 1 358 928 | 188 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Fast | 1 036 872 | 246 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Small | 1 357 768 | 188 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 1 035 704 | 247 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Small | 1 357 192 | 188 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 1 035 112 | 247 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 981 040 | 129 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Fast | 813 688 | 314 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 971 672 | 129 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Fast | 804 336 | 318 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 968 856 | 130 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 801 504 | 319 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 965 424 | 130 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 798 080 | 320 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Small | 2 371 392 | 107 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Fast | 949 920 | 269 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Small | 2 362 016 | 108 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Fast | 940 552 | 272 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Small | 2 359 192 | 108 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 937 720 | 273 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Small | 2 355 760 | 108 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 934 304 | 274 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Small | 2 762 992 | 92 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Fast | 1 082 856 | 236 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Small | 2 753 624 | 92 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Fast | 1 073 488 | 238 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Small | 2 750 808 | 93 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 1 070 664 | 239 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Small | 2 747 376 | 93 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 1 067 240 | 239 Kbytes/s |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 1962 bytes | 356 bytes | 36 bytes | 128 bytes |
| Encryption | Fast | 2044 bytes | 1380 bytes | 0 bytes | 172 bytes |
| Decryption | Small | 1992 bytes | 612 bytes | 0 bytes | 184 bytes |
| Decryption | Fast | 2562 bytes | 1636 bytes | 0 bytes | 188 bytes |
2.2. HASH digest
In this section we provide the performance results for HASH, using different modes of operation:
- Sole buffer: one sole buffer is hashed. The performance time is given in us.
- Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.
2.2.1. Sole buffer mode
In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.
| HASH mode | Buffer size | Cycles | Time |
|---|---|---|---|
| SHA256 | 32 bytes | 4656 | 145 µs |
| SHA256 | 64 bytes | 8086 | 252 µs |
| SHA256 | 128 bytes | 11 204 | 350 µs |
| SHA384 | 32 bytes | 18 494 | 577 µs |
| SHA384 | 64 bytes | 18 768 | 586 µs |
| SHA384 | 128 bytes | 35 678 | 1114 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1358 | 280 bytes | 0 bytes | 532 bytes |
| SHA384 | 2532 | 728 bytes | 0 bytes | 1076 bytes |
2.2.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_hash_initcmox_hash_append: called several times to hash the whole message in fixed-size chunkscmox_hash_generateTag
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.
| HASH mode | Message size | Chunk size | Cycles | Bit rate |
|---|---|---|---|---|
| SHA256 | 8000 bytes | 128 bytes | 433 556 | 590 Kbytes/s |
| SHA256 | 8000 bytes | 512 bytes | 400 985 | 638 Kbytes/s |
| SHA256 | 8000 bytes | 1024 bytes | 395 441 | 647 Kbytes/s |
| SHA256 | 8000 bytes | 2048 bytes | 392 669 | 651 Kbytes/s |
| SHA384 | 8000 bytes | 128 bytes | 1 089 868 | 234 Kbytes/s |
| SHA384 | 8000 bytes | 512 bytes | 1 031 338 | 248 Kbytes/s |
| SHA384 | 8000 bytes | 1024 bytes | 1 021 178 | 250 Kbytes/s |
| SHA384 | 8000 bytes | 2048 bytes | 1 016 098 | 251 Kbytes/s |
The table below shows the final tag generation done through the call to cmox_hash_generateTag.
| HASH mode | Cycles | Time |
|---|---|---|
| SHA256 | 3681 | 115 µs |
| SHA384 | 17 227 | 538 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1354 bytes | 272 bytes | 0 bytes | 340 bytes |
| SHA384 | 2528 bytes | 720 bytes | 0 bytes | 780 bytes |
2.3. ECDSA signature and verification
This section provides the performance results for ECDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 6 512 424 | 203 ms |
| SECP256R1 | Signature | Small | High | 6 237 968 | 194 ms |
| SECP256R1 | Verification | Small | Low | 15 394 288 | 481 ms |
| SECP256R1 | Verification | Small | High | 13 511 560 | 422 ms |
| SECP384R1 | Signature | Small | Low | 19 123 112 | 597 ms |
| SECP384R1 | Signature | Small | High | 18 190 720 | 568 ms |
| SECP384R1 | Verification | Small | Low | 45 107 344 | 1409 ms |
| SECP384R1 | Verification | Small | High | 39 114 312 | 1222 ms |
The table below shows ECDSA flash memory and RAM usage (in bytes).
| Curve | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 14 816 bytes | 1212 bytes | 0 bytes | 472 bytes | 628 bytes |
| SECP256R1 | Signature | Small | High | 14 816 bytes | 1596 bytes | 0 bytes | 472 bytes | 696 bytes |
| SECP256R1 | Verification | Small | Low | 14 804 bytes | 1212 bytes | 0 bytes | 520 bytes | 856 bytes |
| SECP256R1 | Verification | Small | High | 14 804 bytes | 1596 bytes | 0 bytes | 520 bytes | 1648 bytes |
| SECP384R1 | Signature | Small | Low | 14 816 bytes | 1692 bytes | 0 bytes | 472 bytes | 884 bytes |
| SECP384R1 | Signature | Small | High | 14 816 bytes | 2268 bytes | 0 bytes | 472 bytes | 984 bytes |
| SECP384R1 | Verification | Small | Low | 14 804 bytes | 1692 bytes | 0 bytes | 520 bytes | 1192 bytes |
| SECP384R1 | Verification | Small | High | 14 804 bytes | 2268 bytes | 0 bytes | 520 bytes | 2272 bytes |
2.4. EdDSA signature and verification
This section provides the performance results for EdDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 9 450 040 | 295 ms |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 5 412 912 | 169 ms |
| Ed25519 | 1023 bytes | Signature | Fast | OptLow | 88 | 0 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 14 826 376 | 463 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 12 986 800 | 405 ms |
| Ed25519 | 1023 bytes | Verification | Fast | OptLow | 88 | 0 ms |
The table below shows EdDSA flash memory and RAM usage (in bytes).
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 16 154 bytes | 1748 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 16 574 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | Fast | OptLow | 14 242 bytes | 1748 bytes | 0 bytes | 28 bytes | 0 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 16 150 bytes | 1748 bytes | 0 bytes | 1172 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 16 570 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1992 bytes |
| Ed25519 | 1023 bytes | Verification | Fast | OptLow | 14 238 bytes | 1748 bytes | 0 bytes | 24 bytes | 0 bytes |
2.5. RSA signature and verification
This section provides the performance results for RSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Cycles | Time |
|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 476 082 256 | 14 877 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 356 393 008 | 11 137 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 299 184 224 | 9349 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 1 827 309 912 | 57 103 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 1 363 421 384 | 42 606 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 1 140 251 536 | 35 632 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 7 609 784 | 237 ms |
The table below shows RSA flash memory and RAM usage (in bytes).
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 8224 bytes | 372 bytes | 0 bytes | 668 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 8460 bytes | 372 bytes | 0 bytes | 668 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 8460 bytes | 372 bytes | 0 bytes | 668 bytes | 6708 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 7292 bytes | 364 bytes | 0 bytes | 668 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 7528 bytes | 364 bytes | 0 bytes | 668 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 7528 bytes | 364 bytes | 0 bytes | 668 bytes | 9368 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 7476 bytes | 368 bytes | 0 bytes | 684 bytes | 3108 bytes |
2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification
This section provides the performance results for ML-DSA key pair generation, signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites and functions configurations. Note: For signature generation, the number of clock cycles is not bounded in time. The measurement was taken using one predefined private key and one 32-byte message, and the reported value corresponds to the minimum observed time.
| Suite | Function | Cycles | Time (in ms) | Stack usage | Working buffer |
|---|---|---|---|---|---|
| ML-DSA-44 | keyGen | 2 410 936 | 75 | 476 | 7116 |
| ML-DSA-65 | keyGen | 4 080 840 | 127 | 476 | 8140 |
| ML-DSA-87 | keyGen | 6 865 336 | 214 | 476 | 10 188 |
| ML-DSA-44 | Signature | 4 746 240 | 148 | 772 | 30 796 |
| ML-DSA-44 | Signature Low RAM | 5 018 248 | 156 | 756 | 11 340 |
| ML-DSA-65 | Signature | 7 224 904 | 225 | 772 | 43 084 |
| ML-DSA-65 | Signature Low RAM | 7 465 152 | 233 | 756 | 15 436 |
| ML-DSA-44 | Verification | 2 804 480 | 87 | 700 | 8908 |
| ML-DSA-44 | Verification Low RAM | 3 943 496 | 123 | 700 | 4812 |
| ML-DSA-65 | Verification | 4 555 152 | 142 | 700 | 9948 |
| ML-DSA-65 | Verification Low RAM | 6 846 928 | 213 | 700 | 4828 |
| ML-DSA-87 | Verification | 7 401 848 | 231 | 700 | 12 268 |
| ML-DSA-87 | Verification Low RAM | 11 793 968 | 368 | 700 | 5100 |
2.7. Post-Quantum Cryptography ML-KEM key pair generation, encapsulation, decapsulation
This section provides the performance results for ML-KEM key pair generation, encapsulation and decapsulation.
The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different functions and suites.
| Function | Suites | Cycles | Time (in ms) | Stack usage |
|---|---|---|---|---|
| Key-pair-Generation | ML-KEM-512 | 748 600 | 23 | 3 060 |
| Key-pair-Generation | ML-KEM-768 | 1 236 080 | 39 | 3 572 |
| Key-pair-Generation | ML-KEM-1024 | 1 926 832 | 60 | 4 084 |
| Key-Encapsulation | ML-KEM-512 | 2 664 896 | 83 | 4 588 |
| Key-Encapsulation | ML-KEM-768 | 3 807 328 | 119 | 5 100 |
| Key-Encapsulation | ML-KEM-1024 | 5 126 648 | 160 | 5 612 |
| Key-Decapsulation | ML-KEM-512 | 2 991 480 | 93 | 4 684 |
| Key-Decapsulation | ML-KEM-768 | 4 247 720 | 133 | 5 516 |
| Key-Decapsulation | ML-KEM-1024 | 5 686 768 | 178 | 6 508 |
2.8. Post-Quantum Cryptography HBS-LMS signature verification
This section provides the performance results for ML-LMS signature verification.
The table below shows the number of clock cycles minimum, average and maximum and average time (in ms) needed to perform the described function in different functions and suite. Note: Clock cycles were measured for 10 different generated key and message pairs, and the reported Cycles avg values are averages over these measurements.
| Function | Suite | Cycles min | Cycles avg | Time avg (in ms) | Cycles max | Stack usage |
|---|---|---|---|---|---|---|
| LMS-Verify | LMS_N32_H10_W1_SHA256 | 1 153 392 | 1 201 049 | 38 | 1 253 720 | 1 668 |
| LMS-Verify | LMS_N32_H10_W2_SHA256 | 1 161 336 | 1 238 717 | 39 | 1 348 320 | 1 668 |
| LMS-Verify | LMS_N32_H10_W4_SHA256 | 1 984 104 | 2 301 476 | 72 | 2 668 624 | 1 668 |
| LMS-Verify | LMS_N32_H10_W8_SHA256 | 17 099 424 | 19 638 012 | 614 | 22 388 152 | 1 668 |