Optimizing AES-GCM on 32-Bit ARM Cortex-M4 Microcontrollers: Fixslicing and FACE-Based Approach
Hyunjun Kim, Hwajeong Seo · ACM Transactions on Embedded Computing Systems · 2025
Advanced Encryption Standard (AES) in Galois/Counter Mode (GCM) delivers both confidentiality and integrity, yet poses performance and security challenges on resource-limited microcontrollers. In this article, we present an optimized AES-GCM implementation for the 32-bit ARM Cortex-M4 that combines the Fixslicing AES approach with the FACE (Fast AES-CTR Encryption) strategy, significantly reducing redundant computations in AES-CTR. We further examine two GHASH implementations, a 4-bit table-based approach and a Karatsuba-based constant-time variant, to balance speed, memory usage, and resistance to timing attacks. Our evaluations on an STM32F4 microcontroller show that the Fixslicing and FACE method reduces the AES-128 GCTR cycle counts by up to 19.41%, while the Table-based GHASH achieves nearly double the speed of its Karatsuba counterpart. These results confirm that with the right mix of bit-slicing optimizations, counter-mode caching, and lightweight polynomial multiplication, secure and efficient AES-GCM can be obtained even on low-power embedded devices.