SharkSSL™ Embedded SSL/TLS Stack
SharkSSL Kinetis Crypto Port

This guide covers the K60 cryptographic backend and its Cortex-M assembly routines. Follow the build steps first, then compare the configuration examples if you need to tune processing speed or code size.

Build integration

1. Add big-integer assembly

Compile SharkSslBigInt_M3.s together with SharkSslBigInt.c and enable the assembly backend:

/* Use the Cortex-M big-integer assembly routines. */
#define SHARKSSL_OPTIMIZED_BIGINT_ASM 1

2. Set the target configuration

Add these definitions to TargConfig.h:

/* Configure the little-endian K60 target and 32-bit arithmetic words. */
#define B_LITTLE_ENDIAN
#define SHARKSSL_BIGINT_WORDSIZE 32
#define SHARKSSL_UNALIGNED_ACCESS 1

3. Select the K60 crypto implementation

Compile SharkSslCrypto_K60.c in place of SharkSslCrypto.c. Enable the Memory-Mapped Cryptographic Acceleration Unit (MMCAU):

/* Select the K60 hardware crypto implementation. */
#define SHARKSSL_USE_MMCAU 1

The hash footprint options apply when the corresponding hash is enabled. For each option, 1 selects smaller, slower code; 0 selects larger, faster code.

Hash Enabled by Footprint option
MD5 SHARKSSL_USE_MD5 SHARKSSL_MD5_SMALL_FOOTPRINT
SHA-1 SHARKSSL_USE_SHA1 SHARKSSL_SHA1_SMALL_FOOTPRINT
SHA-256 SHARKSSL_USE_SHA256 SHARKSSL_SHA256_SMALL_FOOTPRINT

4. Configure operation without MQX

If your application does not use MQX, set:

/* Use the RNG adapter's bare-metal integration path. */
#define RNGA_BARE_METAL 1

5. Add ChaCha20 and Poly1305 assembly

Compile SharkSslCrypto_M3.s and enable both assembly implementations:

/* Use assembly for encryption and message authentication. */
#define SHARKSSL_OPTIMIZED_POLY1305_ASM 1
#define SHARKSSL_OPTIMIZED_CHACHA_ASM 1

Compare configuration examples

The historical speed and size examples are shown side by side below. They differ in SHARKSSL_BIGINT_EXP_SLIDING_WINDOW_K; all other values are shared. Enable CCM only if your application needs it.

These values are reference examples, not a production TLS preset. In particular, SHARKSSL_USE_RNG_TINYMT=1 selects a generator unsuitable for cryptographic use. For a current build, follow build configuration and the configuration API.

Setting Speed example Size example
B_LITTLE_ENDIAN 1 1
SHARKSSL_BIGINT_EXP_SLIDING_WINDOW_K 5 1
SHARKSSL_BIGINT_WORDSIZE 32 32
SHARKSSL_ENABLE_AES_CCM 1 /* IF NEEDED */ 1 /* IF NEEDED */
SHARKSSL_ENABLE_AES_CTR_MODE 0 0
SHARKSSL_ENABLE_AES_GCM 1 1
SHARKSSL_ENABLE_RSA_BLINDING 1 1
SHARKSSL_OPTIMIZED_BIGINT_ASM 1 1
SHARKSSL_OPTIMIZED_CHACHA_ASM 1 1
SHARKSSL_OPTIMIZED_POLY1305_ASM 1 1
SHARKSSL_UNALIGNED_ACCESS 1 1
SHARKSSL_USE_3DES 1 1
SHARKSSL_USE_AES_128 1 1
SHARKSSL_USE_AES_256 1 1
SHARKSSL_USE_ARC4 0 0
SHARKSSL_USE_MMCAU 1 1
SHARKSSL_USE_CHACHA20 1 1
SHARKSSL_USE_DES 0 0
SHARKSSL_USE_ECC 1 1
SHARKSSL_USE_POLY1305 1 1
SHARKSSL_USE_RNG_TINYMT 1 1
SHARKSSL_USE_SHA_256 1 1

Performance and benefit

The K60 backend combines MMCAU hardware acceleration for supported ciphers and hashes with Thumb-2 arithmetic routines. Its intended benefit is less CPU time spent on cryptography, leaving more time for application tasks. Performance depends on the algorithms, footprint settings, and target configuration. Measure the selected configuration on the target board to determine the benefit over C implementations.