This page reports measured performance when using the pure software cryptographic library algorithms with an STM32L5 MCU. In addition to performance figures, the required code footprint and memory are also given.
1. Measurement configuration
1.1. Hardware configuration
| STM32 MCU | STM32L552ZET6Q |
| Device ID | 0x472 |
| Revision ID | 0x2001 |
| Board | NUCLEO-L552ZE-Q |
1.2. Firmware configuration
| Cryptographic library version | 050000B2[ver. 1] |
- ↑ This value corresponds to the information returned by a call to
cmox_getInfos
1.3. System configuration
| System core clock frequency | 110 MHz |
| Flash latency | 5 wait states |
| Voltage scaling | Range 0 |
| Dual bank | 1 (0: Single / 1: Dual) |
| ICACHE peripheral | 1 (0: disabled / 1: enabled) |
1.4. Development toolchains and compilers
| IAR Embedded Workbench | IAR ANSI C/C++ Compiler V9.40.1.364/W64 for ARM |
2. Performance values
2.1. AES symmetric key encryption and decryption
This section provides the performance results for AES-CBC using different operation modes:
- Sole buffer: one sole buffer is encrypted or decrypted. The performance time is given in µs.
- Data flow: a big message is encrypted or decrypted in chunks. The bit rate is given in kilobytes per second.
2.1.1. Sole buffer mode
In this mode, the entire encryption or decryption process, for the full message size, is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation in small and fast configurations.
| AES mode | Key size | Buffer size | Cipher operation | Configuration | Cycles | Time |
|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 32 bytes | Encryption | Small | 3742 | 34 µs |
| AES CBC | 128 bits | 32 bytes | Encryption | Fast | 3534 | 32 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Small | 6382 | 58 µs |
| AES CBC | 128 bits | 64 bytes | Encryption | Fast | 5568 | 50 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Small | 11 667 | 106 µs |
| AES CBC | 128 bits | 128 bytes | Encryption | Fast | 9801 | 89 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Small | 4118 | 37 µs |
| AES CBC | 192 bits | 32 bytes | Encryption | Fast | 3769 | 34 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Small | 7181 | 65 µs |
| AES CBC | 192 bits | 64 bytes | Encryption | Fast | 6118 | 55 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Small | 13 318 | 121 µs |
| AES CBC | 192 bits | 128 bytes | Encryption | Fast | 10 955 | 99 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Small | 4683 | 42 µs |
| AES CBC | 256 bits | 32 bytes | Encryption | Fast | 4145 | 37 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Small | 8172 | 74 µs |
| AES CBC | 256 bits | 64 bytes | Encryption | Fast | 6864 | 62 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Small | 15 155 | 137 µs |
| AES CBC | 256 bits | 128 bytes | Encryption | Fast | 12 272 | 111 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Small | 4950 | 45 µs |
| AES CBC | 128 bits | 32 bytes | Decryption | Fast | 5106 | 46 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Small | 8790 | 79 µs |
| AES CBC | 128 bits | 64 bytes | Decryption | Fast | 7173 | 65 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Small | 16 463 | 149 µs |
| AES CBC | 128 bits | 128 bytes | Decryption | Fast | 11 400 | 103 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Small | 5713 | 51 µs |
| AES CBC | 192 bits | 32 bytes | Decryption | Fast | 5518 | 50 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Small | 10 220 | 92 µs |
| AES CBC | 192 bits | 64 bytes | Decryption | Fast | 7945 | 72 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Small | 19 243 | 174 µs |
| AES CBC | 192 bits | 128 bytes | Decryption | Fast | 12 807 | 116 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Small | 6607 | 60 µs |
| AES CBC | 256 bits | 32 bytes | Decryption | Fast | 6293 | 57 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Small | 11 788 | 107 µs |
| AES CBC | 256 bits | 64 bytes | Decryption | Fast | 8991 | 81 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Small | 22 180 | 201 µs |
| AES CBC | 256 bits | 128 bytes | Decryption | Fast | 14 441 | 131 µs |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2386 bytes | 324 bytes | 0 bytes | 552 bytes |
| Encryption | Fast | 2330 bytes | 1092 bytes | 0 bytes | 552 bytes |
| Decryption | Small | 2746 bytes | 580 bytes | 0 bytes | 568 bytes |
| Decryption | Fast | 2696 bytes | 2372 bytes | 0 bytes | 568 bytes |
2.1.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_cipher_initcmox_cipher_setKeycmox_cipher_setIVcmox_cipher_append: called several times to encrypt or decrypt the whole message in fixed-size chunks
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation in small and fast configuration.
| AES mode | Key size | Message size | Chunk size | Cipher operation | Configuration | Cycles | Bit rate |
|---|---|---|---|---|---|---|---|
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Small | 671 120 | 1311 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Encryption | Fast | 536 008 | 1641 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Small | 666 328 | 1320 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Encryption | Fast | 531 272 | 1656 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Small | 665 408 | 1322 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 530 360 | 1659 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Small | 664 928 | 1323 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 529 912 | 1660 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Small | 776 144 | 1133 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Encryption | Fast | 610 072 | 1442 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Small | 771 368 | 1140 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Encryption | Fast | 605 432 | 1453 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Small | 770 448 | 1142 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 604 520 | 1455 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Small | 769 976 | 1142 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 604 064 | 1456 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Small | 881 136 | 998 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Encryption | Fast | 684 072 | 1286 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Small | 876 328 | 1004 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Encryption | Fast | 679 232 | 1295 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Small | 875 416 | 1005 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Encryption | Fast | 678 328 | 1297 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Small | 874 936 | 1005 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Encryption | Fast | 677 864 | 1298 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Small | 989 824 | 889 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 128 bytes | Decryption | Fast | 562 688 | 1563 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Small | 982 512 | 895 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 512 bytes | Decryption | Fast | 555 192 | 1585 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Small | 980 016 | 897 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 552 552 | 1592 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Small | 976 936 | 900 Kbytes/s |
| AES CBC | 128 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 549 664 | 1600 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 159 736 | 758 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 128 bytes | Decryption | Fast | 636 768 | 1381 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 152 504 | 763 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 512 bytes | Decryption | Fast | 629 352 | 1398 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 149 992 | 765 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 626 712 | 1404 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 146 896 | 767 Kbytes/s |
| AES CBC | 192 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 623 800 | 1410 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Small | 1 329 784 | 661 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 128 bytes | Decryption | Fast | 710 584 | 1238 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Small | 1 322 480 | 665 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 512 bytes | Decryption | Fast | 703 096 | 1251 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Small | 1 319 976 | 666 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 1024 bytes | Decryption | Fast | 700 480 | 1256 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Small | 1 316 872 | 668 Kbytes/s |
| AES CBC | 256 bits | 8000 bytes | 2048 bytes | Decryption | Fast | 697 632 | 1261 Kbytes/s |
The table below shows flash memory and RAM usage (in bytes).
| Cipher operation | Configuration | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|---|
| Encryption | Small | 2306 bytes | 316 bytes | 0 bytes | 176 bytes |
| Encryption | Fast | 2250 bytes | 1084 bytes | 0 bytes | 176 bytes |
| Decryption | Small | 2666 bytes | 572 bytes | 0 bytes | 192 bytes |
| Decryption | Fast | 2616 bytes | 2364 bytes | 0 bytes | 192 bytes |
2.2. HASH digest
In this section we provide the performance results for HASH, using different modes of operation:
- Sole buffer: one sole buffer is hashed. The performance time is given in us.
- Data flow: a big message is hashed in chunks. The bit rate is given in bytes per second.
2.2.1. Sole buffer mode
In this mode, the entire message hashing process is managed through a single API call provided by the CMOX library.
The table below shows the number of clock cycles and time (in µs) needed to perform the described operation.
| HASH mode | Buffer size | Cycles | Time |
|---|---|---|---|
| SHA256 | 32 bytes | 4176 | 37 µs |
| SHA256 | 64 bytes | 7224 | 65 µs |
| SHA256 | 128 bytes | 10 106 | 91 µs |
| SHA384 | 32 bytes | 15 737 | 143 µs |
| SHA384 | 64 bytes | 15 912 | 144 µs |
| SHA384 | 128 bytes | 29 340 | 266 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1378 | 280 bytes | 0 bytes | 532 bytes |
| SHA384 | 2590 | 728 bytes | 0 bytes | 1076 bytes |
2.2.2. Data flow mode
In this mode, the operation is performed in several calls to the CMOX library APIs, as shown below:
cmox_hash_initcmox_hash_append: called several times to hash the whole message in fixed-size chunkscmox_hash_generateTag
The table below shows the number of clock cycles and the bit rate (in kilobytes per second) needed to perform the described operation.
| HASH mode | Message size | Chunk size | Cycles | Bit rate |
|---|---|---|---|---|
| SHA256 | 8000 bytes | 128 bytes | 388 744 | 2263 Kbytes/s |
| SHA256 | 8000 bytes | 512 bytes | 366 530 | 2400 Kbytes/s |
| SHA256 | 8000 bytes | 1024 bytes | 362 882 | 2425 Kbytes/s |
| SHA256 | 8000 bytes | 2048 bytes | 361 062 | 2437 Kbytes/s |
| SHA384 | 8000 bytes | 128 bytes | 862 714 | 1020 Kbytes/s |
| SHA384 | 8000 bytes | 512 bytes | 823 062 | 1069 Kbytes/s |
| SHA384 | 8000 bytes | 1024 bytes | 815 971 | 1078 Kbytes/s |
| SHA384 | 8000 bytes | 2048 bytes | 812 507 | 1083 Kbytes/s |
The table below shows the final tag generation done through the call to cmox_hash_generateTag.
| HASH mode | Cycles | Time |
|---|---|---|
| SHA256 | 3382 | 30 µs |
| SHA384 | 14 385 | 130 µs |
The table below shows flash memory and RAM usage (in bytes).
| HASH mode | Code | Constant data | Global data | Stack usage |
|---|---|---|---|---|
| SHA256 | 1374 bytes | 272 bytes | 0 bytes | 340 bytes |
| SHA384 | 2586 bytes | 720 bytes | 0 bytes | 780 bytes |
2.3. ECDSA signature and verification
This section provides the performance results for ECDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 2 898 200 | 26 ms |
| SECP256R1 | Signature | Small | High | 2 815 672 | 25 ms |
| SECP256R1 | Signature | SuperFast | Low | 1 888 504 | 17 ms |
| SECP256R1 | Signature | SuperFast | High | 1 869 328 | 16 ms |
| SECP256R1 | Verification | Small | Low | 6 975 256 | 63 ms |
| SECP256R1 | Verification | Small | High | 6 179 080 | 56 ms |
| SECP256R1 | Verification | SuperFast | Low | 4 652 800 | 42 ms |
| SECP256R1 | Verification | SuperFast | High | 4 113 008 | 37 ms |
| SECP384R1 | Signature | Small | Low | 8 187 736 | 74 ms |
| SECP384R1 | Signature | Small | High | 7 875 256 | 71 ms |
| SECP384R1 | Signature | Fast | Low | 7 002 024 | 63 ms |
| SECP384R1 | Signature | Fast | High | 6 654 960 | 60 ms |
| SECP384R1 | Verification | Small | Low | 19 630 448 | 178 ms |
| SECP384R1 | Verification | Small | High | 17 143 520 | 155 ms |
| SECP384R1 | Verification | Fast | Low | 16 833 288 | 153 ms |
| SECP384R1 | Verification | Fast | High | 14 521 208 | 132 ms |
The table below shows ECDSA flash memory and RAM usage (in bytes).
| Curve | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|
| SECP256R1 | Signature | Small | Low | 13 468 bytes | 1212 bytes | 0 bytes | 440 bytes | 628 bytes |
| SECP256R1 | Signature | Small | High | 13 468 bytes | 1596 bytes | 0 bytes | 440 bytes | 696 bytes |
| SECP256R1 | Signature | SuperFast | Low | 14 778 bytes | 1212 bytes | 0 bytes | 444 bytes | 628 bytes |
| SECP256R1 | Signature | SuperFast | High | 14 778 bytes | 1596 bytes | 0 bytes | 444 bytes | 696 bytes |
| SECP256R1 | Verification | Small | Low | 13 456 bytes | 1212 bytes | 0 bytes | 488 bytes | 856 bytes |
| SECP256R1 | Verification | Small | High | 13 456 bytes | 1596 bytes | 0 bytes | 488 bytes | 1648 bytes |
| SECP256R1 | Verification | SuperFast | Low | 14 766 bytes | 1212 bytes | 0 bytes | 492 bytes | 856 bytes |
| SECP256R1 | Verification | SuperFast | High | 14 766 bytes | 1596 bytes | 0 bytes | 492 bytes | 1648 bytes |
| SECP384R1 | Signature | Small | Low | 13 468 bytes | 1692 bytes | 0 bytes | 440 bytes | 884 bytes |
| SECP384R1 | Signature | Small | High | 13 468 bytes | 2268 bytes | 0 bytes | 440 bytes | 984 bytes |
| SECP384R1 | Signature | Fast | Low | 13 838 bytes | 1692 bytes | 0 bytes | 456 bytes | 884 bytes |
| SECP384R1 | Signature | Fast | High | 13 838 bytes | 2268 bytes | 0 bytes | 456 bytes | 984 bytes |
| SECP384R1 | Verification | Small | Low | 13 456 bytes | 1692 bytes | 0 bytes | 488 bytes | 1192 bytes |
| SECP384R1 | Verification | Small | High | 13 456 bytes | 2268 bytes | 0 bytes | 488 bytes | 2272 bytes |
| SECP384R1 | Verification | Fast | Low | 13 826 bytes | 1692 bytes | 0 bytes | 504 bytes | 1192 bytes |
| SECP384R1 | Verification | Fast | High | 13 826 bytes | 2268 bytes | 0 bytes | 504 bytes | 2272 bytes |
2.4. EdDSA signature and verification
This section provides the performance results for EdDSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Cycles | Time |
|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 4 429 536 | 40 ms |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 2 575 536 | 23 ms |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptLow | 3 230 048 | 29 ms |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptHigh | 1 938 280 | 17 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 6 679 320 | 60 ms |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 5 838 976 | 53 ms |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptLow | 4 621 488 | 42 ms |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptHigh | 4 161 632 | 37 ms |
The table below shows EdDSA flash memory and RAM usage (in bytes).
| Curve | Message size | Operation | ECC mathematics configuration | Curve definition | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|
| Ed25519 | 1023 bytes | Signature | Small | OptLow | 14 840 bytes | 1748 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | Small | OptHigh | 15 260 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptLow | 16 150 bytes | 1748 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Signature | SuperFast | OptHigh | 16 570 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1672 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptLow | 14 836 bytes | 1748 bytes | 0 bytes | 1172 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | Small | OptHigh | 15 256 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1992 bytes |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptLow | 16 146 bytes | 1748 bytes | 0 bytes | 1172 bytes | 984 bytes |
| Ed25519 | 1023 bytes | Verification | SuperFast | OptHigh | 16 566 bytes | 2900 bytes | 0 bytes | 1172 bytes | 1992 bytes |
2.5. RSA signature and verification
This section provides the performance results for RSA signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described operation in different configurations.
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Cycles | Time |
|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 197 729 536 | 1797 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 148 817 744 | 1352 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 124 977 248 | 1136 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Low | 158 848 768 | 1444 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Mid | 119 616 224 | 1087 ms |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | High | 100 476 384 | 913 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 762 183 288 | 6928 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 572 422 584 | 5203 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 478 814 432 | 4352 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Low | 606 774 592 | 5516 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Mid | 455 790 200 | 4143 ms |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | High | 381 292 200 | 3466 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 3 748 184 | 34 ms |
| v2.2 | n/a | SHA-256 | 3K | Verification | Fast | n/a | 3 242 656 | 29 ms |
The table below shows RSA flash memory and RAM usage (in bytes).
| PKCS#1 | Priv. key mod. exp. method | Hash method | Modulus size | Operation | RSA mathematics configuration | Priv. key mod. exp. implementation | Code | Constant data | Global data | Stack usage | Working buffer |
|---|---|---|---|---|---|---|---|---|---|---|---|
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Low | 6890 bytes | 372 bytes | 0 bytes | 668 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | Mid | 7126 bytes | 372 bytes | 0 bytes | 668 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Small | High | 7126 bytes | 372 bytes | 0 bytes | 668 bytes | 6708 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Low | 7260 bytes | 372 bytes | 0 bytes | 668 bytes | 3704 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | Mid | 7496 bytes | 372 bytes | 0 bytes | 668 bytes | 4308 bytes |
| v2.2 | CRT | SHA-256 | 3K | Signature | Fast | High | 7496 bytes | 372 bytes | 0 bytes | 668 bytes | 6708 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Low | 5958 bytes | 364 bytes | 0 bytes | 668 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | Mid | 6194 bytes | 364 bytes | 0 bytes | 668 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Small | High | 6194 bytes | 364 bytes | 0 bytes | 668 bytes | 9368 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Low | 6328 bytes | 364 bytes | 0 bytes | 668 bytes | 3484 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | Mid | 6564 bytes | 364 bytes | 0 bytes | 668 bytes | 4664 bytes |
| v2.2 | No CRT | SHA-256 | 3K | Signature | Fast | High | 6564 bytes | 364 bytes | 0 bytes | 668 bytes | 9368 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Small | n/a | 6142 bytes | 368 bytes | 0 bytes | 684 bytes | 3108 bytes |
| v2.2 | n/a | SHA-256 | 3K | Verification | Fast | n/a | 6512 bytes | 368 bytes | 0 bytes | 684 bytes | 3108 bytes |
2.6. Post-Quantum Cryptography ML-DSA key pair generation, Signature and verification
This section provides the performance results for ML-DSA key pair generation, signature and verification.
The table below shows the number of clock cycles and time (in ms) needed to perform the described function in different suites and functions configurations. Note: For signature generation, the number of clock cycles is not bounded in time. The measurement was taken using one predefined private key and one 32-byte message, and the reported value corresponds to the minimum observed time.
| Suite | Function | Cycles | Time (in ms) | Stack usage | Working buffer |
|---|---|---|---|---|---|
| ML-DSA-44 | keyGen | 2 009 456 | 18 | 476 | 7116 |
| ML-DSA-65 | keyGen | 3 497 976 | 31 | 476 | 8140 |
| ML-DSA-87 | keyGen | 5 856 744 | 53 | 476 | 10 188 |
| ML-DSA-44 | Signature | 3 568 280 | 32 | 772 | 30 796 |
| ML-DSA-44 | Signature Low RAM | 3 852 096 | 35 | 756 | 11 340 |
| ML-DSA-65 | Signature | 5 506 688 | 50 | 772 | 43 084 |
| ML-DSA-65 | Signature Low RAM | 5 856 224 | 53 | 756 | 15 436 |
| ML-DSA-87 | Signature | 8 595 800 | 78 | 772 | 57 420 |
| ML-DSA-87 | Signature Low RAM | 9 099 584 | 82 | 756 | 19 532 |
| ML-DSA-44 | Verification | 2 263 136 | 20 | 700 | 8908 |
| ML-DSA-44 | Verification Low RAM | 3 092 200 | 28 | 700 | 4812 |
| ML-DSA-65 | Verification | 3 731 824 | 33 | 700 | 9948 |
| ML-DSA-65 | Verification Low RAM | 5 407 768 | 49 | 700 | 4828 |
| ML-DSA-87 | Verification | 6 173 360 | 56 | 700 | 12 268 |
| ML-DSA-87 | Verification Low RAM | 9 303 352 | 84 | 700 | 5100 |
2.7. Post-Quantum Cryptography ML-KEM key pair generation, encapsulation, decapsulation
This section is under construction.
2.8. Post-Quantum Cryptography HBS-LMS signature verification
This section is under construction.