Using ECDSA-P265 (and ED25519) signature in mcuboot

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

Using ECDSA-P265 (and ED25519) signature in mcuboot

811件の閲覧回数
mastupristi
Senior Contributor I

Hi,

 

I'm trying mcuboot_opensource and ota_mcuboot_basic examples.

The example use rsa2048 out-of-the-box and works well.

Since ecdsa key pair are also provided (files bootutil/nxp_port/keys/sign-ecdsa-p256-*), I would like to try this type of signature.

I have replaced 

#define CONFIG_BOOT_SIGNATURE_TYPE_RSA
#define CONFIG_BOOT_SIGNATURE_TYPE_RSA_LEN 2048


with

#define CONFIG_BOOT_SIGNATURE_TYPE_ECDSA_P256


then I have signed the ota_mcuboot_basic binary:

python3 imgtool.py sign \
	--key evkmimxrt1020_mcuboot_opensource_v2.2.0/bootutil/nxp_port/keys/sign-ecdsa-p256-priv.pem \
        --align 4 \
	--header-size 0x400 \
	--pad-header \
	--slot-size 0x100000 \
	--max-sectors 800 \
	--version "1.1" \
        evkmimxrt1020_ota_mcuboot_basic.bin \
	evkmimxrt1020_ota_mcuboot_basic_signed_ecdsap256.bin

 

But it doesn't work.

Which steps do I need to do to make it works?

 

The further test for me is to use ed25519, that is not provided out-of-the-box in the examples. Could you list the steps to make is works as well?

 

regards

Max

タグ(3)
0 件の賞賛
返信
3 返答(返信)

765件の閲覧回数
diego_charles
NXP TechSupport
NXP TechSupport

Hi @mastupristi 

Which MCU are you using?  I want to test with you on the same platform.

Have you updated the MCUBoot to contain the public ECDSA_P256 key? 

Diego

0 件の賞賛
返信

753件の閲覧回数
mastupristi
Senior Contributor I

Hi @diego_charles 

 

Which MCU are you using?

RT1021. I'm testing on MIMXRT1020-EVK

 

Have you updated the MCUBoot to contain the public ECDSA_P256 key?

Yes, this is done automatically by the example..

in source/mcux_config.h I have substituted #define CONFIG_BOOT_ENCRYPT_RSA with #define CONFIG_BOOT_ENCRYPT_ECDSA_P256
In file source/sblconfig.h I have substituted 

#define CONFIG_BOOT_SIGNATURE_TYPE_RSA
#define CONFIG_BOOT_SIGNATURE_TYPE_RSA_LEN 2048

with

#define CONFIG_BOOT_SIGNATURE_TYPE_ECDSA_P256

 

in file bootutil/nxp_port/keys.c the correct key file should be selected based on the definitions:

#if defined(MCUBOOT_SIGN_RSA)
#include "sign-rsa2048-pub.c"
#elif defined(MCUBOOT_SIGN_EC256)
#include "sign-ecdsa-p256-pub.c"
#else
#error "No public key available for given signing algorithm."
#endif

 

best regards

Max

0 件の賞賛
返信

433件の閲覧回数
diego_charles
NXP TechSupport
NXP TechSupport

Hi @mastupristi 

I am sorry for the delay.

I noticed that none of our i.MX RT samples for MCUboot use the key you want. But the MCXN and MCXA examples for MCUBoot use the ecdsa-p256. I think the source could help us as a reference. 

Diego

0 件の賞賛
返信
%3CLINGO-SUB%20id%3D%22lingo-sub-2156738%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3Emcuboot%20%E3%81%A7%20ECDSA-P265%20(%E3%81%8A%E3%82%88%E3%81%B3%20ED25519)%20%E7%BD%B2%E5%90%8D%E3%82%92%E4%BD%BF%E7%94%A8%E3%81%99%E3%82%8B%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2156738%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E3%81%93%E3%82%93%E3%81%AB%E3%81%A1%E3%81%AF%E3%80%81%3C%2FP%3E%3CBR%20%2F%3E%3CP%3Emcuboot_opensource%20%E3%81%A8%20ota_mcuboot_basic%20%E3%81%AE%E4%BE%8B%E3%82%92%E8%A9%A6%E3%81%97%E3%81%A6%E3%81%84%E3%81%BE%E3%81%99%E3%80%82%3CBR%20%2F%3E%3CBR%20%2F%3E%E3%81%93%E3%81%AE%E4%BE%8B%E3%81%A7%E3%81%AF%E3%80%81rsa2048%20%E3%82%92%E3%81%9D%E3%81%AE%E3%81%BE%E3%81%BE%E4%BD%BF%E7%94%A8%E3%81%97%E3%81%A6%E3%81%8A%E3%82%8A%E3%80%81%E6%AD%A3%E5%B8%B8%E3%81%AB%E5%8B%95%E4%BD%9C%E3%81%97%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%3CP%3Eecdsa%20%E3%82%AD%E3%83%BC%20%E3%83%9A%E3%82%A2%E3%82%82%E6%8F%90%E4%BE%9B%E3%81%95%E3%82%8C%E3%81%A6%E3%81%84%E3%82%8B%E3%81%9F%E3%82%81%20(%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%3CFONT%20face%3D%22courier%20new%2Ccourier%22%3Ebootutil%2Fnxp_port%2Fkeys%2F%3C%2FFONT%3E%20%3CFONT%20face%3D%22courier%20new%2Ccourier%22%3Esign-ecdsa-p256-*%3C%2FFONT%3E%20)%E3%80%81%E3%81%93%E3%81%AE%E3%82%BF%E3%82%A4%E3%83%97%E3%81%AE%E7%BD%B2%E5%90%8D%E3%82%92%E8%A9%A6%E3%81%97%E3%81%A6%E3%81%BF%E3%81%9F%E3%81%84%E3%81%A8%E6%80%9D%E3%81%84%E3%81%BE%E3%81%99%E3%80%82%3CBR%20%2F%3E%3CBR%20%2F%3E%E7%A7%81%E3%81%AF%E4%BA%A4%E6%8F%9B%E3%81%97%E3%81%BE%E3%81%97%E3%81%9F%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-c%22%3E%3CCODE%20translate%3D%22no%22%3E%23define%20CONFIG_BOOT_SIGNATURE_TYPE_RSA%0A%23define%20CONFIG_BOOT_SIGNATURE_TYPE_RSA_LEN%202048%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%3CBR%20%2F%3E%E3%81%A8%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-c%22%3E%3CCODE%20translate%3D%22no%22%3E%23define%20CONFIG_BOOT_SIGNATURE_TYPE_ECDSA_P256%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%3CBR%20%2F%3E%E6%AC%A1%E3%81%AB%E3%80%81ota_mcuboot_basic%20%E3%83%90%E3%82%A4%E3%83%8A%E3%83%AA%E3%81%AB%E7%BD%B2%E5%90%8D%E3%81%97%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-markup%22%3E%3CCODE%20translate%3D%22no%22%3Epython3%20imgtool.py%20sign%20%5C%0A%09--key%20evkmimxrt1020_mcuboot_opensource_v2.2.0%2Fbootutil%2Fnxp_port%2Fkeys%2Fsign-ecdsa-p256-priv.pem%20%5C%0A%20%20%20%20%20%20%20%20--align%204%20%5C%0A%09--header-size%200x400%20%5C%0A%09--pad-header%20%5C%0A%09--slot-size%200x100000%20%5C%0A%09--max-sectors%20800%20%5C%0A%09--version%20%221.1%22%20%5C%0A%20%20%20%20%20%20%20%20evkmimxrt1020_ota_mcuboot_basic.bin%20%5C%0A%09evkmimxrt1020_ota_mcuboot_basic_signed_ecdsap256.bin%3C%2FCODE%3E%3C%2FPRE%3E%3CBR%20%2F%3E%3CP%3E%E3%81%97%E3%81%8B%E3%81%97%E3%81%9D%E3%82%8C%E3%81%AF%E6%A9%9F%E8%83%BD%E3%81%97%E3%81%BE%E3%81%9B%E3%82%93%E3%80%82%3C%2FP%3E%3CP%3E%E3%81%9D%E3%82%8C%E3%82%92%E5%8B%95%E4%BD%9C%E3%81%95%E3%81%9B%E3%82%8B%E3%81%AB%E3%81%AF%E3%81%A9%E3%81%AE%E3%82%88%E3%81%86%E3%81%AA%E6%89%8B%E9%A0%86%E3%82%92%E5%AE%9F%E8%A1%8C%E3%81%99%E3%82%8B%E5%BF%85%E8%A6%81%E3%81%8C%E3%81%82%E3%82%8A%E3%81%BE%E3%81%99%E3%81%8B%3F%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%E7%A7%81%E3%81%AB%E3%81%A8%E3%81%A3%E3%81%A6%E3%81%AE%E3%81%95%E3%82%89%E3%81%AA%E3%82%8B%E3%83%86%E3%82%B9%E3%83%88%E3%81%AF%E3%80%81%E4%BE%8B%E3%81%AB%E3%81%AF%E3%81%9D%E3%81%AE%E3%81%BE%E3%81%BE%E3%81%A7%E3%81%AF%E6%8F%90%E4%BE%9B%E3%81%95%E3%82%8C%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%20ed25519%20%E3%82%92%E4%BD%BF%E7%94%A8%E3%81%99%E3%82%8B%E3%81%93%E3%81%A8%E3%81%A7%E3%81%99%E3%80%82%E3%81%93%E3%82%8C%E3%82%92%E5%8B%95%E4%BD%9C%E3%81%95%E3%81%9B%E3%82%8B%E3%81%9F%E3%82%81%E3%81%AE%E6%89%8B%E9%A0%86%E3%82%82%E6%8C%99%E3%81%92%E3%81%A6%E3%81%84%E3%81%9F%E3%81%A0%E3%81%91%E3%81%BE%E3%81%99%E3%81%8B%3F%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%E3%82%88%E3%82%8D%E3%81%97%E3%81%8F%E3%81%8A%E9%A1%98%E3%81%84%E3%81%97%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%3CP%3E%E6%9C%80%E5%A4%A7%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2178598%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Using%20ECDSA-P265%20(and%20ED25519)%20signature%20in%20mcuboot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2178598%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E3%81%93%E3%82%93%E3%81%AB%E3%81%A1%E3%81%AF%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F124967%22%20target%3D%22_blank%22%3E%40mastupristi%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%E9%81%85%E3%81%8F%E3%81%AA%E3%81%A3%E3%81%A6%E7%94%B3%E3%81%97%E8%A8%B3%E3%81%82%E3%82%8A%E3%81%BE%E3%81%9B%E3%82%93%E3%80%82%3C%2FP%3E%0A%3CP%3EMCUboot%20%E7%94%A8%E3%81%AE%20i.MX%20RT%20%E3%82%B5%E3%83%B3%E3%83%97%E3%83%AB%E3%81%AE%E3%81%84%E3%81%9A%E3%82%8C%E3%82%82%E3%80%81%E5%BF%85%E8%A6%81%E3%81%AA%E3%82%AD%E3%83%BC%E3%82%92%E4%BD%BF%E7%94%A8%E3%81%97%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%E3%81%93%E3%81%A8%E3%81%AB%E6%B0%97%E4%BB%98%E3%81%8D%E3%81%BE%E3%81%97%E3%81%9F%E3%80%82%E3%81%9F%E3%81%A0%E3%81%97%E3%80%81MCUBoot%20%E3%81%AE%20MCXN%20%E3%81%8A%E3%82%88%E3%81%B3%20MCXA%20%E3%81%AE%E4%BE%8B%E3%81%A7%E3%81%AF%E3%80%81ecdsa-p256%20%E3%81%8C%E4%BD%BF%E7%94%A8%E3%81%95%E3%82%8C%E3%81%BE%E3%81%99%E3%80%82%E3%81%93%E3%81%AE%E6%83%85%E5%A0%B1%E6%BA%90%E3%81%AF%E5%8F%82%E8%80%83%E8%B3%87%E6%96%99%E3%81%A8%E3%81%97%E3%81%A6%E5%BD%B9%E7%AB%8B%E3%81%A4%E3%81%A8%E6%80%9D%E3%81%84%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%0A%3CP%3E%E3%83%87%E3%82%A3%E3%82%A8%E3%82%B4%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2158833%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Using%20ECDSA-P265%20(and%20ED25519)%20signature%20in%20mcuboot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2158833%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E3%81%93%E3%82%93%E3%81%AB%E3%81%A1%E3%81%AF%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F89833%22%20target%3D%22_blank%22%3E%40diego_charles%3C%2FA%3E%3C%2FP%3E%3CBR%20%2F%3E%3CBLOCKQUOTE%3E%3CP%3E%E3%81%A9%E3%81%AE%20MCU%20%E3%82%92%E4%BD%BF%E7%94%A8%E3%81%97%E3%81%A6%E3%81%84%E3%81%BE%E3%81%99%E3%81%8B%3F%3C%2FP%3E%3C%2FBLOCKQUOTE%3E%3CP%3ERT1021%E3%80%82MIMXRT1020-EVK%E3%81%A7%E3%83%86%E3%82%B9%E3%83%88%E3%81%97%E3%81%A6%E3%81%84%E3%81%BE%E3%81%99%3C%2FP%3E%3CBR%20%2F%3E%3CBLOCKQUOTE%3E%3CP%3E%E5%85%AC%E9%96%8B%20ECDSA_P256%20%E3%82%AD%E3%83%BC%E3%81%8C%E5%90%AB%E3%81%BE%E3%82%8C%E3%82%8B%E3%82%88%E3%81%86%E3%81%AB%20MCUBoot%20%E3%82%92%E6%9B%B4%E6%96%B0%E3%81%97%E3%81%BE%E3%81%97%E3%81%9F%E3%81%8B%3F%3C%2FP%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%E3%81%AF%E3%81%84%E3%80%81%E3%81%93%E3%82%8C%E3%81%AF%E4%BE%8B%E3%81%AB%E3%82%88%E3%81%A3%E3%81%A6%E8%87%AA%E5%8B%95%E7%9A%84%E3%81%AB%E5%AE%9F%E8%A1%8C%E3%81%95%E3%82%8C%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%3CP%3Esource%2Fmcux_config.h%20%E5%86%85%3CFONT%20face%3D%22courier%20new%2Ccourier%22%3E%23define%20CONFIG_BOOT_ENCRYPT_RSA%20%E3%82%92%3C%2FFONT%3E%3CFONT%20face%3D%22courier%20new%2Ccourier%22%3E%23define%20CONFIG_BOOT_ENCRYPT_ECDSA_P256%3C%2FFONT%3E%E3%81%AB%E7%BD%AE%E3%81%8D%E6%8F%9B%E3%81%88%E3%81%BE%E3%81%97%E3%81%9F%E3%80%82%3CBR%20%2F%3E%E3%83%95%E3%82%A1%E3%82%A4%E3%83%ABsource%2Fsblconfig.h%E5%86%85%E7%A7%81%E3%81%AF%E4%BB%A3%E7%94%A8%E3%81%97%E3%81%BE%E3%81%97%E3%81%9F%3C%2FP%3E%3CP%3E%3CFONT%20face%3D%22comic%20sans%20ms%2Csans-serif%22%3E%23CONFIG_BOOT_SIGNATURE_TYPE_RSA%20%E3%82%92%E5%AE%9A%E7%BE%A9%E3%81%97%E3%81%BE%E3%81%99%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20face%3D%22comic%20sans%20ms%2Csans-serif%22%3E%23CONFIG_BOOT_SIGNATURE_TYPE_RSA_LEN%202048%20%E3%82%92%E5%AE%9A%E7%BE%A9%E3%81%97%E3%81%BE%E3%81%99%3C%2FFONT%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%E3%81%A8%3C%2FP%3E%3CP%3E%3CFONT%20face%3D%22courier%20new%2Ccourier%22%3E%23CONFIG_BOOT_SIGNATURE_TYPE_ECDSA_P256%20%E3%82%92%E5%AE%9A%E7%BE%A9%E3%81%97%E3%81%BE%E3%81%99%3C%2FFONT%3E%3C%2FP%3E%3CBR%20%2F%3E%3CP%3E%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%20bootutil%2Fnxp_port%2Fkeys.c%20%E3%81%A7%E3%81%AF%E3%80%81%E5%AE%9A%E7%BE%A9%E3%81%AB%E5%9F%BA%E3%81%A5%E3%81%84%E3%81%A6%E6%AD%A3%E3%81%97%E3%81%84%E3%82%AD%E3%83%BC%20%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%82%92%E9%81%B8%E6%8A%9E%E3%81%99%E3%82%8B%E5%BF%85%E8%A6%81%E3%81%8C%E3%81%82%E3%82%8A%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-c%22%3E%3CCODE%20translate%3D%22no%22%3E%23if%20defined(MCUBOOT_SIGN_RSA)%0A%23include%20%22sign-rsa2048-pub.c%22%0A%23elif%20defined(MCUBOOT_SIGN_EC256)%0A%23include%20%22sign-ecdsa-p256-pub.c%22%0A%23else%0A%23error%20%22No%20public%20key%20available%20for%20given%20signing%20algorithm.%22%0A%23endif%3C%2FCODE%3E%3C%2FPRE%3E%3CBR%20%2F%3E%3CP%3E%E3%82%88%E3%82%8D%E3%81%97%E3%81%8F%E3%81%8A%E9%A1%98%E3%81%84%E3%81%84%E3%81%9F%E3%81%97%E3%81%BE%E3%81%99%3C%2FP%3E%3CP%3E%E6%9C%80%E5%A4%A7%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2158536%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Using%20ECDSA-P265%20(and%20ED25519)%20signature%20in%20mcuboot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2158536%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%E3%81%93%E3%82%93%E3%81%AB%E3%81%A1%E3%81%AF%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F124967%22%20target%3D%22_blank%22%3E%40mastupristi%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%E3%81%A9%E3%81%AE%20MCU%20%E3%82%92%E4%BD%BF%E7%94%A8%E3%81%97%E3%81%A6%E3%81%84%E3%81%BE%E3%81%99%E3%81%8B%3F%E5%90%8C%E3%81%98%E3%83%97%E3%83%A9%E3%83%83%E3%83%88%E3%83%95%E3%82%A9%E3%83%BC%E3%83%A0%E3%81%A7%E4%B8%80%E7%B7%92%E3%81%AB%E3%83%86%E3%82%B9%E3%83%88%E3%81%97%E3%81%9F%E3%81%84%E3%81%A7%E3%81%99%E3%80%82%3C%2FP%3E%0A%3CP%3E%E5%85%AC%E9%96%8B%20ECDSA_P256%20%E3%82%AD%E3%83%BC%E3%81%8C%E5%90%AB%E3%81%BE%E3%82%8C%E3%82%8B%E3%82%88%E3%81%86%E3%81%AB%20MCUBoot%20%E3%82%92%E6%9B%B4%E6%96%B0%E3%81%97%E3%81%BE%E3%81%97%E3%81%9F%E3%81%8B%3F%3C%2FP%3E%0A%3CP%3E%E3%83%87%E3%82%A3%E3%82%A8%E3%82%B4%3C%2FP%3E%3C%2FLINGO-BODY%3E