Secure Boot selecting key types and sizes

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

Secure Boot selecting key types and sizes

235 次查看
ThomasGu
Contributor I

Hi

As there is currently heated debate about which cryptographic methods will still be secure in the future, the question arises as to what keys should be used for Secure Boot.
Currently we have i.MX8M Plus (HAB4) and i.MX8 QuadMax (AHAB).
Questions:

  • Is it possible to mix key types (e.g. 2 RSA keys and 2 EC keys)?
  • Which key types should be used to ensure the security of Secure Boot over the next 10 years?

Thanks in Advance
Thomas

标签 (1)
0 项奖励
回复
3 回复数

163 次查看
ThomasGu
Contributor I

Hi Harvey

thanks a lot.
Are there any reasons not to use RSA 4096 or ECC-P521? Seems to be supported for i.MX8Plus and QuadMax.

Best Regards
Thomas

0 项奖励
回复

136 次查看
Harvey021
NXP TechSupport
NXP TechSupport

hi @ThomasGu 

Yes, the key length supported. To consider the key security, so I mentioned, at least, to choose 3k and p384. instead of 2k and p256.

 

Regards

Harvey

0 项奖励
回复

193 次查看
Harvey021
NXP TechSupport
NXP TechSupport

Hi

Would suggest to choose key length, at least, 3K for RSA and 384 for ECC for help. Our HAB/AHAB architecture based on PKI tree to generate key and certificate with one type of key.

 

Regards

Harvey

 

0 项奖励
回复