FWIW, the STM32F415 claims to have a hardware RNG and some capabilities to protect secrets stored in the onboard flash. The SC4-HSM apparently has TweetNaCl running on it: https://sc4.us/hsm/ No information on the performance of Curve25519 that I’m aware of.