Question
AES-128-CTR using SAES through MCUboot is slower than software on STM32H533 — is this expected?
Hello,
I am evaluating cryptographic performance for a secure boot using a NUCLEO-H533RE board and the OEMiRoT example from STM32CubeH5.
I compared two AES-128-CTR implementations:
- Software:
mbedtls_aes_crypt_ctr(). - Hardware-backed:
bootutil_aes_ctr_encrypt()using SAES.
The mean encryption times are:
| Input size | Software | SAES-backed implementation |
|---|---|---|
| 32 bytes | 10.55 µs | 29.46 µs |
| 256 bytes | 76.70 µs | 222.88 µs |
| 1024 bytes | 303.50 µs | 886.02 µs |
For an academic comparison, is it accurate to describe this result as “software AES-CTR versus SAES ECB with software CTR and driver protection overhead”?
Thank you!
