Cryptographic performance on STM32L4 Series V5.x

This page reports measured performance when using the pure software cryptographic library algorithms with an STM32L4 MCU. In addition to performance figures, the required code footprint and memory are also given.


1. Measurement configuration

1.1. Hardware configuration

STM32 MCU STM32L476RGT6
Device ID 0x415
Revision ID 0x1007
Board STM32L476RG-Nucleo Rev C

1.2. Firmware configuration

Cryptographic library version 050000B2[ver. 1]
  1. This value corresponds to the information returned by a call to cmox_getInfos

1.3. System configuration

System core clock frequency 80 MHz
Flash latency 4 wait states
Voltage scaling Range 1
Instruction cache (ART/ICU) 1 (0: disabled / 1: enabled)
Data cache (ART/DCU) 1 (0: disabled / 1: enabled)
Prefetch cache (ART) 1 (0: disabled / 1: enabled)

1.4. Development toolchains and compilers

IAR Embedded Workbench IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM
Information
The measurements are done using a project built with the High Speed optimization setting enabled.


2. Performance values

2.1. AES symmetric key encryption and decryption

This section provides the performance results for AES-CBC using different operation modes:

  • Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
  • Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.

2.1.1. Sole buffer mode

In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.

AES mode Key size Buffer size Cipher operation Configuration Cycles Time
AES CBC 128 bits 32 bytes Encryption Small 4617 57 µs
AES CBC 128 bits 32 bytes Encryption Fast 4776 59 µs
AES CBC 128 bits 64 bytes Encryption Small 7799 97 µs
AES CBC 128 bits 64 bytes Encryption Fast 7912 98 µs
AES CBC 128 bits 128 bytes Encryption Small 13 953 174 µs
AES CBC 128 bits 128 bytes Encryption Fast 14 157 176 µs
AES CBC 192 bits 32 bytes Encryption Small 4990 62 µs
AES CBC 192 bits 32 bytes Encryption Fast 5403 67 µs
AES CBC 192 bits 64 bytes Encryption Small 8774 109 µs
AES CBC 192 bits 64 bytes Encryption Fast 9442 118 µs
AES CBC 192 bits 128 bytes Encryption Small 16 290 203 µs
AES CBC 192 bits 128 bytes Encryption Fast 17 488 218 µs
AES CBC 256 bits 32 bytes Encryption Small 5576 69 µs
AES CBC 256 bits 32 bytes Encryption Fast 5962 74 µs
AES CBC 256 bits 64 bytes Encryption Small 9439 117 µs
AES CBC 256 bits 64 bytes Encryption Fast 10 056 125 µs
AES CBC 256 bits 128 bytes Encryption Small 17 221 215 µs
AES CBC 256 bits 128 bytes Encryption Fast 18 201 227 µs
AES CBC 128 bits 32 bytes Decryption Small 5508 68 µs
AES CBC 128 bits 32 bytes Decryption Fast 6964 87 µs
AES CBC 128 bits 64 bytes Decryption Small 9410 117 µs
AES CBC 128 bits 64 bytes Decryption Fast 10 507 131 µs
AES CBC 128 bits 128 bytes Decryption Small 17 376 217 µs
AES CBC 128 bits 128 bytes Decryption Fast 17 586 219 µs
AES CBC 192 bits 32 bytes Decryption Small 6265 78 µs
AES CBC 192 bits 32 bytes Decryption Fast 7610 95 µs
AES CBC 192 bits 64 bytes Decryption Small 11 068 138 µs
AES CBC 192 bits 64 bytes Decryption Fast 11 234 140 µs
AES CBC 192 bits 128 bytes Decryption Small 20 481 256 µs
AES CBC 192 bits 128 bytes Decryption Fast 18 434 230 µs
AES CBC 256 bits 32 bytes Decryption Small 6821 85 µs
AES CBC 256 bits 32 bytes Decryption Fast 8986 112 µs
AES CBC 256 bits 64 bytes Decryption Small 12 016 150 µs
AES CBC 256 bits 64 bytes Decryption Fast 13 501 168 µs
AES CBC 256 bits 128 bytes Decryption Small 22 386 279 µs
AES CBC 256 bits 128 bytes Decryption Fast 22 479 280 µs


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2302 bytes 324 bytes 0 bytes 552 bytes
Encryption Fast 2246 bytes 1092 bytes 0 bytes 552 bytes
Decryption Small 2650 bytes 580 bytes 0 bytes 568 bytes
Decryption Fast 2600 bytes 2372 bytes 0 bytes 568 bytes


2.1.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_cipher_init
  • cmox_cipher_setKey
  • cmox_cipher_setIV
  • cmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.

AES mode Key size Message size Chunk size Cipher operation Configuration Cycles Bit rate
AES CBC 128 bits 8000 bytes 128 bytes Encryption Small 803 016 796 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Encryption Fast 802 736 797 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Small 792 736 807 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Fast 783 656 816 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Small 790 944 809 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Fast 780 416 820 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Small 790 024 810 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Fast 778 792 821 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Small 940 640 680 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Fast 1 015 496 630 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Small 930 192 688 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Fast 1 006 088 636 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Small 928 464 689 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Fast 1 004 488 637 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Small 927 584 689 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Fast 1 003 680 637 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Small 1 001 992 638 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Fast 1 046 264 611 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Small 991 336 645 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Fast 1 027 176 623 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Small 989 496 646 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Fast 1 023 936 625 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Small 988 616 647 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Fast 1 022 304 626 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Small 1 045 776 611 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Fast 917 896 697 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Small 1 030 064 621 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Fast 904 200 707 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Small 1 026 272 623 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Fast 900 688 710 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Small 1 022 424 625 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Fast 897 016 713 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Small 1 224 160 522 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Fast 950 840 673 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Small 1 209 104 529 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Fast 927 888 689 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Small 1 205 384 530 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Fast 922 816 693 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Small 1 201 616 532 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Fast 918 352 696 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Small 1 333 808 479 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Fast 1 160 872 551 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Small 1 318 336 485 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Fast 1 147 168 557 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Small 1 314 472 486 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Fast 1 143 664 559 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Small 1 310 664 488 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Fast 1 139 992 561 Kbytes/s


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2222 bytes 316 bytes 0 bytes 176 bytes
Encryption Fast 2166 bytes 1084 bytes 0 bytes 176 bytes
Decryption Small 2570 bytes 572 bytes 0 bytes 192 bytes
Decryption Fast 2520 bytes 2364 bytes 0 bytes 192 bytes


2.2. HASH digest

In this section we provide the performance results for HASH, using different modes of operation:

  • Sole buffer: one sole buffer is hashed. The performance time is given in us.
  • Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.

2.2.1. Sole buffer mode

In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.

HASH mode Buffer size Cycles Time
SHA256 32 bytes 4771 59 µs
SHA256 64 bytes 8160 102 µs
SHA256 128 bytes 11 243 140 µs
SHA384 32 bytes 18 419 230 µs
SHA384 64 bytes 18 641 233 µs
SHA384 128 bytes 35 359 441 µs


The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1358 280 bytes 0 bytes 532 bytes
SHA384 2504 728 bytes 0 bytes 1076 bytes


2.2.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_hash_init
  • cmox_hash_append: called several times to hash the whole message in fixed-size chunks
  • cmox_hash_generateTag

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.

HASH mode Message size Chunk size Cycles Bit rate
SHA256 8000 bytes 128 bytes 418 543 1529 Kbytes/s
SHA256 8000 bytes 512 bytes 392 834 1629 Kbytes/s
SHA256 8000 bytes 1024 bytes 388 458 1647 Kbytes/s
SHA256 8000 bytes 2048 bytes 386 270 1656 Kbytes/s
SHA384 8000 bytes 128 bytes 1 074 004 595 Kbytes/s
SHA384 8000 bytes 512 bytes 1 024 399 624 Kbytes/s
SHA384 8000 bytes 1024 bytes 1 015 799 630 Kbytes/s
SHA384 8000 bytes 2048 bytes 1 011 499 632 Kbytes/s


The table below shows the final tag generation done through the call to cmox_hash_generateTag.

HASH mode Cycles Time
SHA256 3761 47 µs
SHA384 17 146 214 µs

The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1354 bytes 272 bytes 0 bytes 340 bytes
SHA384 2500 bytes 720 bytes 0 bytes 780 bytes


2.3. ECDSA signature and verification

This section provides the performance results for ECDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Operation ECC mathematics configuration Curve definition Cycles Time
SECP256R1 Signature Small Low 3 090 784 38 ms
SECP256R1 Signature Small High 2 998 312 37 ms
SECP256R1 Signature SuperFast Low 3 124 320 39 ms
SECP256R1 Signature SuperFast High 3 026 808 37 ms
SECP256R1 Verification Small Low 7 508 648 93 ms
SECP256R1 Verification Small High 6 649 560 83 ms
SECP256R1 Verification SuperFast Low 7 567 904 94 ms
SECP256R1 Verification SuperFast High 6 705 008 83 ms
SECP384R1 Signature Small Low 8 426 064 105 ms
SECP384R1 Signature Small High 8 059 064 100 ms
SECP384R1 Signature Fast Low 8 392 008 104 ms
SECP384R1 Signature Fast High 7 958 640 99 ms
SECP384R1 Verification Small Low 20 331 528 254 ms
SECP384R1 Verification Small High 17 647 912 220 ms
SECP384R1 Verification Fast Low 20 270 344 253 ms
SECP384R1 Verification Fast High 17 475 008 218 ms


The table below shows ECDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
SECP256R1 Signature Small Low 13 442 bytes 1212 bytes 0 bytes 440 bytes 628 bytes
SECP256R1 Signature Small High 13 442 bytes 1596 bytes 0 bytes 440 bytes 696 bytes
SECP256R1 Signature SuperFast Low 14 752 bytes 1212 bytes 0 bytes 444 bytes 628 bytes
SECP256R1 Signature SuperFast High 14 752 bytes 1596 bytes 0 bytes 444 bytes 696 bytes
SECP256R1 Verification Small Low 13 430 bytes 1212 bytes 0 bytes 488 bytes 856 bytes
SECP256R1 Verification Small High 13 430 bytes 1596 bytes 0 bytes 488 bytes 1648 bytes
SECP256R1 Verification SuperFast Low 14 740 bytes 1212 bytes 0 bytes 492 bytes 856 bytes
SECP256R1 Verification SuperFast High 14 740 bytes 1596 bytes 0 bytes 492 bytes 1648 bytes
SECP384R1 Signature Small Low 13 442 bytes 1692 bytes 0 bytes 440 bytes 884 bytes
SECP384R1 Signature Small High 13 442 bytes 2268 bytes 0 bytes 440 bytes 984 bytes
SECP384R1 Signature Fast Low 13 812 bytes 1692 bytes 0 bytes 456 bytes 884 bytes
SECP384R1 Signature Fast High 13 812 bytes 2268 bytes 0 bytes 456 bytes 984 bytes
SECP384R1 Verification Small Low 13 430 bytes 1692 bytes 0 bytes 488 bytes 1192 bytes
SECP384R1 Verification Small High 13 430 bytes 2268 bytes 0 bytes 488 bytes 2272 bytes
SECP384R1 Verification Fast Low 13 800 bytes 1692 bytes 0 bytes 504 bytes 1192 bytes
SECP384R1 Verification Fast High 13 800 bytes 2268 bytes 0 bytes 504 bytes 2272 bytes


2.4. EdDSA signature and verification

This section provides the performance results for EdDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Message size Operation ECC mathematics configuration Curve definition Cycles Time
Ed25519 1023 bytes Signature Small OptLow 4 887 952 61 ms
Ed25519 1023 bytes Signature Small OptHigh 2 849 912 35 ms
Ed25519 1023 bytes Signature SuperFast OptLow 4 911 560 61 ms
Ed25519 1023 bytes Signature SuperFast OptHigh 2 867 440 35 ms
Ed25519 1023 bytes Verification Small OptLow 7 290 728 91 ms
Ed25519 1023 bytes Verification Small OptHigh 6 404 640 80 ms
Ed25519 1023 bytes Verification SuperFast OptLow 7 325 704 91 ms
Ed25519 1023 bytes Verification SuperFast OptHigh 6 436 616 80 ms


The table below shows EdDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Message size Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
Ed25519 1023 bytes Signature Small OptLow 14 752 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature Small OptHigh 15 172 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptLow 16 062 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptHigh 16 482 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Verification Small OptLow 14 748 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification Small OptHigh 15 168 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes
Ed25519 1023 bytes Verification SuperFast OptLow 16 058 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification SuperFast OptHigh 16 478 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes


2.5. RSA signature and verification

This section provides the performance results for RSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Cycles Time
v2.2 CRT SHA-256 3K Signature Small Low 187 609 936 2345 ms
v2.2 CRT SHA-256 3K Signature Small Mid 141 255 352 1765 ms
v2.2 CRT SHA-256 3K Signature Small High 118 643 304 1483 ms
v2.2 CRT SHA-256 3K Signature Fast Low 187 016 472 2337 ms
v2.2 CRT SHA-256 3K Signature Fast Mid 140 953 912 1761 ms
v2.2 CRT SHA-256 3K Signature Fast High 118 311 792 1478 ms
v2.2 No CRT SHA-256 3K Signature Small Low 713 467 752 8918 ms
v2.2 No CRT SHA-256 3K Signature Small Mid 535 913 344 6698 ms
v2.2 No CRT SHA-256 3K Signature Small High 448 307 112 5603 ms
v2.2 No CRT SHA-256 3K Signature Fast Low 712 358 480 8904 ms
v2.2 No CRT SHA-256 3K Signature Fast Mid 535 224 864 6690 ms
v2.2 No CRT SHA-256 3K Signature Fast High 447 653 368 5595 ms
v2.2 n/a SHA-256 3K Verification Small n/a 3 733 600 46 ms
v2.2 n/a SHA-256 3K Verification Fast n/a 3 730 176 46 ms


The table below shows RSA flash memory and RAM usage (in bytes).

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Code Constant data Global data Stack usage Working buffer
v2.2 CRT SHA-256 3K Signature Small Low 6850 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Small Mid 7086 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Small High 7086 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 CRT SHA-256 3K Signature Fast Low 7220 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Fast Mid 7456 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Fast High 7456 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 No CRT SHA-256 3K Signature Small Low 5918 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Small Mid 6154 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Small High 6154 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 No CRT SHA-256 3K Signature Fast Low 6288 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Fast Mid 6524 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Fast High 6524 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 n/a SHA-256 3K Verification Small n/a 6102 bytes 368 bytes 0 bytes 684 bytes 3108 bytes
v2.2 n/a SHA-256 3K Verification Fast n/a 6472 bytes 368 bytes 0 bytes 684 bytes 3108 bytes