Skip to main content
Associate II
October 11, 2026
Question

AES-128-CTR using SAES through MCUboot is slower than software on STM32H533 — is this expected?

  • October 11, 2026
  • 0 replies
  • 10 views

Hello,

I am evaluating cryptographic performance for a secure boot using a NUCLEO-H533RE board and the OEMiRoT example from STM32CubeH5.

I compared two AES-128-CTR implementations:

  • Software: mbedtls_aes_crypt_ctr().
  • Hardware-backed: bootutil_aes_ctr_encrypt() using SAES.

The mean encryption times are:

Input size Software SAES-backed implementation
32 bytes 10.55 µs 29.46 µs
256 bytes 76.70 µs 222.88 µs
1024 bytes 303.50 µs 886.02 µs

 

For an academic comparison, is it accurate to describe this result as “software AES-CTR versus SAES ECB with software CTR and driver protection overhead”?

 

Thank you!