As there is currently heated debate about which cryptographic methods will still be secure in the future, the question arises as to what keys should be used for Secure Boot. Currently we have i.MX8M Plus (HAB4) and i.MX8 QuadMax (AHAB). Questions:
Is it possible to mix key types (e.g. 2 RSA keys and 2 EC keys)?
Which key types should be used to ensure the security of Secure Boot over the next 10 years?
Would suggest to choose key length, at least, 3K for RSA and 384 for ECC for help. Our HAB/AHAB architecture based on PKI tree to generate key and certificate with one type of key.