Secure Boot selecting key types and sizes

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Secure Boot selecting key types and sizes

1,330 Views
ThomasGu
Contributor I

Hi

As there is currently heated debate about which cryptographic methods will still be secure in the future, the question arises as to what keys should be used for Secure Boot.
Currently we have i.MX8M Plus (HAB4) and i.MX8 QuadMax (AHAB).
Questions:

  • Is it possible to mix key types (e.g. 2 RSA keys and 2 EC keys)?
  • Which key types should be used to ensure the security of Secure Boot over the next 10 years?

Thanks in Advance
Thomas

Labels (1)
0 Kudos
Reply
3 Replies

1,258 Views
ThomasGu
Contributor I

Hi Harvey

thanks a lot.
Are there any reasons not to use RSA 4096 or ECC-P521? Seems to be supported for i.MX8Plus and QuadMax.

Best Regards
Thomas

0 Kudos
Reply

1,231 Views
Harvey021
NXP TechSupport
NXP TechSupport

hi @ThomasGu 

Yes, the key length supported. To consider the key security, so I mentioned, at least, to choose 3k and p384. instead of 2k and p256.

 

Regards

Harvey

0 Kudos
Reply

1,288 Views
Harvey021
NXP TechSupport
NXP TechSupport

Hi

Would suggest to choose key length, at least, 3K for RSA and 384 for ECC for help. Our HAB/AHAB architecture based on PKI tree to generate key and certificate with one type of key.

 

Regards

Harvey

 

0 Kudos
Reply