Cryptographic performance on STM32L5 Series V5.x

This page reports measured performance when using the pure software cryptographic library algorithms with an STM32L5 MCU. In addition to performance figures, the required code footprint and memory are also given.


1. Measurement configuration

1.1. Hardware configuration

STM32 MCU STM32L552ZET6Q
Device ID 0x472
Revision ID 0x2001
Board NUCLEO-L552ZE-Q

1.2. Firmware configuration

Cryptographic library version 050000B2[ver. 1]
  1. This value corresponds to the information returned by a call to cmox_getInfos

1.3. System configuration

System core clock frequency 110 MHz
Flash latency 5 wait states
Voltage scaling Range 0
Dual bank 1 (0: Single / 1: Dual)
ICACHE peripheral 1 (0: disabled / 1: enabled)

1.4. Development toolchains and compilers

IAR Embedded Workbench IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM
Information
The measurements are done using a project built with the High Speed optimization setting enabled.


2. Performance values

2.1. AES symmetric key encryption and decryption

This section provides the performance results for AES-CBC using different operation modes:

  • Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
  • Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.

2.1.1. Sole buffer mode

In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.

AES mode Key size Buffer size Cipher operation Configuration Cycles Time
AES CBC 128 bits 32 bytes Encryption Small 3742 34 µs
AES CBC 128 bits 32 bytes Encryption Fast 3534 32 µs
AES CBC 128 bits 64 bytes Encryption Small 6382 58 µs
AES CBC 128 bits 64 bytes Encryption Fast 5568 50 µs
AES CBC 128 bits 128 bytes Encryption Small 11 667 106 µs
AES CBC 128 bits 128 bytes Encryption Fast 9801 89 µs
AES CBC 192 bits 32 bytes Encryption Small 4118 37 µs
AES CBC 192 bits 32 bytes Encryption Fast 3769 34 µs
AES CBC 192 bits 64 bytes Encryption Small 7181 65 µs
AES CBC 192 bits 64 bytes Encryption Fast 6118 55 µs
AES CBC 192 bits 128 bytes Encryption Small 13 318 121 µs
AES CBC 192 bits 128 bytes Encryption Fast 10 955 99 µs
AES CBC 256 bits 32 bytes Encryption Small 4683 42 µs
AES CBC 256 bits 32 bytes Encryption Fast 4145 37 µs
AES CBC 256 bits 64 bytes Encryption Small 8172 74 µs
AES CBC 256 bits 64 bytes Encryption Fast 6864 62 µs
AES CBC 256 bits 128 bytes Encryption Small 15 155 137 µs
AES CBC 256 bits 128 bytes Encryption Fast 12 272 111 µs
AES CBC 128 bits 32 bytes Decryption Small 4950 45 µs
AES CBC 128 bits 32 bytes Decryption Fast 5106 46 µs
AES CBC 128 bits 64 bytes Decryption Small 8790 79 µs
AES CBC 128 bits 64 bytes Decryption Fast 7173 65 µs
AES CBC 128 bits 128 bytes Decryption Small 16 463 149 µs
AES CBC 128 bits 128 bytes Decryption Fast 11 400 103 µs
AES CBC 192 bits 32 bytes Decryption Small 5713 51 µs
AES CBC 192 bits 32 bytes Decryption Fast 5518 50 µs
AES CBC 192 bits 64 bytes Decryption Small 10 220 92 µs
AES CBC 192 bits 64 bytes Decryption Fast 7945 72 µs
AES CBC 192 bits 128 bytes Decryption Small 19 243 174 µs
AES CBC 192 bits 128 bytes Decryption Fast 12 807 116 µs
AES CBC 256 bits 32 bytes Decryption Small 6607 60 µs
AES CBC 256 bits 32 bytes Decryption Fast 6293 57 µs
AES CBC 256 bits 64 bytes Decryption Small 11 788 107 µs
AES CBC 256 bits 64 bytes Decryption Fast 8991 81 µs
AES CBC 256 bits 128 bytes Decryption Small 22 180 201 µs
AES CBC 256 bits 128 bytes Decryption Fast 14 441 131 µs


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2386 bytes 324 bytes 0 bytes 552 bytes
Encryption Fast 2330 bytes 1092 bytes 0 bytes 552 bytes
Decryption Small 2746 bytes 580 bytes 0 bytes 568 bytes
Decryption Fast 2696 bytes 2372 bytes 0 bytes 568 bytes


2.1.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_cipher_init
  • cmox_cipher_setKey
  • cmox_cipher_setIV
  • cmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.

AES mode Key size Message size Chunk size Cipher operation Configuration Cycles Bit rate
AES CBC 128 bits 8000 bytes 128 bytes Encryption Small 671 120 1311 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Encryption Fast 536 008 1641 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Small 666 328 1320 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Encryption Fast 531 272 1656 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Small 665 408 1322 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Encryption Fast 530 360 1659 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Small 664 928 1323 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Encryption Fast 529 912 1660 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Small 776 144 1133 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Encryption Fast 610 072 1442 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Small 771 368 1140 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Encryption Fast 605 432 1453 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Small 770 448 1142 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Encryption Fast 604 520 1455 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Small 769 976 1142 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Encryption Fast 604 064 1456 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Small 881 136 998 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Encryption Fast 684 072 1286 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Small 876 328 1004 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Encryption Fast 679 232 1295 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Small 875 416 1005 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Encryption Fast 678 328 1297 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Small 874 936 1005 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Encryption Fast 677 864 1298 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Small 989 824 889 Kbytes/s
AES CBC 128 bits 8000 bytes 128 bytes Decryption Fast 562 688 1563 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Small 982 512 895 Kbytes/s
AES CBC 128 bits 8000 bytes 512 bytes Decryption Fast 555 192 1585 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Small 980 016 897 Kbytes/s
AES CBC 128 bits 8000 bytes 1024 bytes Decryption Fast 552 552 1592 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Small 976 936 900 Kbytes/s
AES CBC 128 bits 8000 bytes 2048 bytes Decryption Fast 549 664 1600 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Small 1 159 736 758 Kbytes/s
AES CBC 192 bits 8000 bytes 128 bytes Decryption Fast 636 768 1381 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Small 1 152 504 763 Kbytes/s
AES CBC 192 bits 8000 bytes 512 bytes Decryption Fast 629 352 1398 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Small 1 149 992 765 Kbytes/s
AES CBC 192 bits 8000 bytes 1024 bytes Decryption Fast 626 712 1404 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Small 1 146 896 767 Kbytes/s
AES CBC 192 bits 8000 bytes 2048 bytes Decryption Fast 623 800 1410 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Small 1 329 784 661 Kbytes/s
AES CBC 256 bits 8000 bytes 128 bytes Decryption Fast 710 584 1238 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Small 1 322 480 665 Kbytes/s
AES CBC 256 bits 8000 bytes 512 bytes Decryption Fast 703 096 1251 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Small 1 319 976 666 Kbytes/s
AES CBC 256 bits 8000 bytes 1024 bytes Decryption Fast 700 480 1256 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Small 1 316 872 668 Kbytes/s
AES CBC 256 bits 8000 bytes 2048 bytes Decryption Fast 697 632 1261 Kbytes/s


The table below shows flash memory and RAM usage (in bytes).

Cipher operation Configuration Code Constant data Global data Stack usage
Encryption Small 2306 bytes 316 bytes 0 bytes 176 bytes
Encryption Fast 2250 bytes 1084 bytes 0 bytes 176 bytes
Decryption Small 2666 bytes 572 bytes 0 bytes 192 bytes
Decryption Fast 2616 bytes 2364 bytes 0 bytes 192 bytes


2.2. HASH digest

In this section we provide the performance results for HASH, using different modes of operation:

  • Sole buffer: one sole buffer is hashed. The performance time is given in us.
  • Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.

2.2.1. Sole buffer mode

In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.

The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.

HASH mode Buffer size Cycles Time
SHA256 32 bytes 4176 37 µs
SHA256 64 bytes 7224 65 µs
SHA256 128 bytes 10 106 91 µs
SHA384 32 bytes 15 737 143 µs
SHA384 64 bytes 15 912 144 µs
SHA384 128 bytes 29 340 266 µs


The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1378 280 bytes 0 bytes 532 bytes
SHA384 2590 728 bytes 0 bytes 1076 bytes


2.2.2. Data flow mode

In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:

  • cmox_hash_init
  • cmox_hash_append: called several times to hash the whole message in fixed-size chunks
  • cmox_hash_generateTag

The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.

HASH mode Message size Chunk size Cycles Bit rate
SHA256 8000 bytes 128 bytes 388 744 2263 Kbytes/s
SHA256 8000 bytes 512 bytes 366 530 2400 Kbytes/s
SHA256 8000 bytes 1024 bytes 362 882 2425 Kbytes/s
SHA256 8000 bytes 2048 bytes 361 062 2437 Kbytes/s
SHA384 8000 bytes 128 bytes 862 714 1020 Kbytes/s
SHA384 8000 bytes 512 bytes 823 062 1069 Kbytes/s
SHA384 8000 bytes 1024 bytes 815 971 1078 Kbytes/s
SHA384 8000 bytes 2048 bytes 812 507 1083 Kbytes/s


The table below shows the final tag generation done through the call to cmox_hash_generateTag.

HASH mode Cycles Time
SHA256 3382 30 µs
SHA384 14 385 130 µs

The table below shows flash memory and RAM usage (in bytes).

HASH mode Code Constant data Global data Stack usage
SHA256 1374 bytes 272 bytes 0 bytes 340 bytes
SHA384 2586 bytes 720 bytes 0 bytes 780 bytes


2.3. ECDSA signature and verification

This section provides the performance results for ECDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Operation ECC mathematics configuration Curve definition Cycles Time
SECP256R1 Signature Small Low 2 898 200 26 ms
SECP256R1 Signature Small High 2 815 672 25 ms
SECP256R1 Signature SuperFast Low 1 888 504 17 ms
SECP256R1 Signature SuperFast High 1 869 328 16 ms
SECP256R1 Verification Small Low 6 975 256 63 ms
SECP256R1 Verification Small High 6 179 080 56 ms
SECP256R1 Verification SuperFast Low 4 652 800 42 ms
SECP256R1 Verification SuperFast High 4 113 008 37 ms
SECP384R1 Signature Small Low 8 187 736 74 ms
SECP384R1 Signature Small High 7 875 256 71 ms
SECP384R1 Signature Fast Low 7 002 024 63 ms
SECP384R1 Signature Fast High 6 654 960 60 ms
SECP384R1 Verification Small Low 19 630 448 178 ms
SECP384R1 Verification Small High 17 143 520 155 ms
SECP384R1 Verification Fast Low 16 833 288 153 ms
SECP384R1 Verification Fast High 14 521 208 132 ms


The table below shows ECDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
SECP256R1 Signature Small Low 13 468 bytes 1212 bytes 0 bytes 440 bytes 628 bytes
SECP256R1 Signature Small High 13 468 bytes 1596 bytes 0 bytes 440 bytes 696 bytes
SECP256R1 Signature SuperFast Low 14 778 bytes 1212 bytes 0 bytes 444 bytes 628 bytes
SECP256R1 Signature SuperFast High 14 778 bytes 1596 bytes 0 bytes 444 bytes 696 bytes
SECP256R1 Verification Small Low 13 456 bytes 1212 bytes 0 bytes 488 bytes 856 bytes
SECP256R1 Verification Small High 13 456 bytes 1596 bytes 0 bytes 488 bytes 1648 bytes
SECP256R1 Verification SuperFast Low 14 766 bytes 1212 bytes 0 bytes 492 bytes 856 bytes
SECP256R1 Verification SuperFast High 14 766 bytes 1596 bytes 0 bytes 492 bytes 1648 bytes
SECP384R1 Signature Small Low 13 468 bytes 1692 bytes 0 bytes 440 bytes 884 bytes
SECP384R1 Signature Small High 13 468 bytes 2268 bytes 0 bytes 440 bytes 984 bytes
SECP384R1 Signature Fast Low 13 838 bytes 1692 bytes 0 bytes 456 bytes 884 bytes
SECP384R1 Signature Fast High 13 838 bytes 2268 bytes 0 bytes 456 bytes 984 bytes
SECP384R1 Verification Small Low 13 456 bytes 1692 bytes 0 bytes 488 bytes 1192 bytes
SECP384R1 Verification Small High 13 456 bytes 2268 bytes 0 bytes 488 bytes 2272 bytes
SECP384R1 Verification Fast Low 13 826 bytes 1692 bytes 0 bytes 504 bytes 1192 bytes
SECP384R1 Verification Fast High 13 826 bytes 2268 bytes 0 bytes 504 bytes 2272 bytes


2.4. EdDSA signature and verification

This section provides the performance results for EdDSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

Curve Message size Operation ECC mathematics configuration Curve definition Cycles Time
Ed25519 1023 bytes Signature Small OptLow 4 429 536 40 ms
Ed25519 1023 bytes Signature Small OptHigh 2 575 536 23 ms
Ed25519 1023 bytes Signature SuperFast OptLow 3 230 048 29 ms
Ed25519 1023 bytes Signature SuperFast OptHigh 1 938 280 17 ms
Ed25519 1023 bytes Verification Small OptLow 6 679 320 60 ms
Ed25519 1023 bytes Verification Small OptHigh 5 838 976 53 ms
Ed25519 1023 bytes Verification SuperFast OptLow 4 621 488 42 ms
Ed25519 1023 bytes Verification SuperFast OptHigh 4 161 632 37 ms


The table below shows EdDSA flash memory and RAM usage (in bytes).

Note
The footpring is measured using the general-purpose CMOX_ECC_XXX_HIGHMEM or CMOX_ECC_XXX_LOWMEM configuration, which shows the footprint increase compared with the V4.x.x. To reduce the footprint, the optimized confinguration CMOX_ECC_XXX_YYY_SIGN or CMOX_ECC_XXX_YYY_VERIFY is recommended.
Curve Message size Operation ECC mathematics configuration Curve definition Code Constant data Global data Stack usage Working buffer
Ed25519 1023 bytes Signature Small OptLow 14 840 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature Small OptHigh 15 260 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptLow 16 150 bytes 1748 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Signature SuperFast OptHigh 16 570 bytes 2900 bytes 0 bytes 1172 bytes 1672 bytes
Ed25519 1023 bytes Verification Small OptLow 14 836 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification Small OptHigh 15 256 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes
Ed25519 1023 bytes Verification SuperFast OptLow 16 146 bytes 1748 bytes 0 bytes 1172 bytes 984 bytes
Ed25519 1023 bytes Verification SuperFast OptHigh 16 566 bytes 2900 bytes 0 bytes 1172 bytes 1992 bytes


2.5. RSA signature and verification

This section provides the performance results for RSA signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Cycles Time
v2.2 CRT SHA-256 3K Signature Small Low 197 729 536 1797 ms
v2.2 CRT SHA-256 3K Signature Small Mid 148 817 744 1352 ms
v2.2 CRT SHA-256 3K Signature Small High 124 977 248 1136 ms
v2.2 CRT SHA-256 3K Signature Fast Low 158 848 768 1444 ms
v2.2 CRT SHA-256 3K Signature Fast Mid 119 616 224 1087 ms
v2.2 CRT SHA-256 3K Signature Fast High 100 476 384 913 ms
v2.2 No CRT SHA-256 3K Signature Small Low 762 183 288 6928 ms
v2.2 No CRT SHA-256 3K Signature Small Mid 572 422 584 5203 ms
v2.2 No CRT SHA-256 3K Signature Small High 478 814 432 4352 ms
v2.2 No CRT SHA-256 3K Signature Fast Low 606 774 592 5516 ms
v2.2 No CRT SHA-256 3K Signature Fast Mid 455 790 200 4143 ms
v2.2 No CRT SHA-256 3K Signature Fast High 381 292 200 3466 ms
v2.2 n/a SHA-256 3K Verification Small n/a 3 748 184 34 ms
v2.2 n/a SHA-256 3K Verification Fast n/a 3 242 656 29 ms


The table below shows RSA flash memory and RAM usage (in bytes).

PKCS#1 Priv. key mod. exp. method Hash method Modulus size Operation RSA mathematics configuration Priv. key mod. exp. implementation Code Constant data Global data Stack usage Working buffer
v2.2 CRT SHA-256 3K Signature Small Low 6890 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Small Mid 7126 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Small High 7126 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 CRT SHA-256 3K Signature Fast Low 7260 bytes 372 bytes 0 bytes 668 bytes 3704 bytes
v2.2 CRT SHA-256 3K Signature Fast Mid 7496 bytes 372 bytes 0 bytes 668 bytes 4308 bytes
v2.2 CRT SHA-256 3K Signature Fast High 7496 bytes 372 bytes 0 bytes 668 bytes 6708 bytes
v2.2 No CRT SHA-256 3K Signature Small Low 5958 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Small Mid 6194 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Small High 6194 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 No CRT SHA-256 3K Signature Fast Low 6328 bytes 364 bytes 0 bytes 668 bytes 3484 bytes
v2.2 No CRT SHA-256 3K Signature Fast Mid 6564 bytes 364 bytes 0 bytes 668 bytes 4664 bytes
v2.2 No CRT SHA-256 3K Signature Fast High 6564 bytes 364 bytes 0 bytes 668 bytes 9368 bytes
v2.2 n/a SHA-256 3K Verification Small n/a 6142 bytes 368 bytes 0 bytes 684 bytes 3108 bytes
v2.2 n/a SHA-256 3K Verification Fast n/a 6512 bytes 368 bytes 0 bytes 684 bytes 3108 bytes


2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification

This section provides the performance results for ML-DSA key pair generation, signature and verification.

The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites and functions configurations. Note: For signature generation, the number of clock cycles is not bounded in time. The measurement was taken using one predefined private key and one 32-byte message, and the reported value corresponds to the minimum observed time.

Suite Function Cycles Time (in ms) Stack usage Working buffer
ML-DSA-44 keyGen 2 009 456 18 476 7116
ML-DSA-65 keyGen 3 497 976 31 476 8140
ML-DSA-87 keyGen 5 856 744 53 476 10 188
ML-DSA-44 Signature 3 568 280 32 772 30 796
ML-DSA-44 Signature Low RAM 3 852 096 35 756 11 340
ML-DSA-65 Signature 5 506 688 50 772 43 084
ML-DSA-65 Signature Low RAM 5 856 224 53 756 15 436
ML-DSA-87 Signature 8 595 800 78 772 57 420
ML-DSA-87 Signature Low RAM 9 099 584 82 756 19 532
ML-DSA-44 Verification 2 263 136 20 700 8908
ML-DSA-44 Verification Low RAM 3 092 200 28 700 4812
ML-DSA-65 Verification 3 731 824 33 700 9948
ML-DSA-65 Verification Low RAM 5 407 768 49 700 4828
ML-DSA-87 Verification 6 173 360 56 700 12 268
ML-DSA-87 Verification Low RAM 9 303 352 84 700 5100

2.7. Post-Quantum Cryptography ML-KEM key pair generation, encapsulation, decapsulation

This section is under construction.

2.8. Post-Quantum Cryptography HBS-LMS signature verification

This section is under construction.