iMx.95 FRDM post quantum algorithms support

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

iMx.95 FRDM post quantum algorithms support

102 Views
davidecryptalabs
Contributor I

I have an iMX.95 FRDM development board and I would like to use post quantum algorithm hardware acceleration.

I've tried this command:

pkcs11-tool --module /usr/lib/libsmw_pkcs11.so.5 --list-mechanism

but the ML-KEM or ML_DSA ar not listed.

I'#m currently building the imx image with yocto.

How can I enable post quantum algorithm support?

0 Kudos
Reply
2 Replies

20 Views
Oswalag
NXP TechSupport
NXP TechSupport

Hello,

You don't simply "enable PQC" with a Linux kernel option.

The i.MX 95 capability is integrated into the EdgeLock Secure Enclave / hardware root of trust.

The i.MX 95 Advanced Profile Secure Enclave enables a post-quantum hardware root of trust and supports hybrid ML-DSA + ECDSA for NXP-signed Secure Enclave firmware.

There is an i.MX 95 with SPSDK and ML-DSA hybrid secure boot implementation, which is much more useful than the general PQC documentation:

i.MX 95 Secure Boot with SPSDK

And the general NXP PQC architecture is here:

NXP Post-Quantum Cryptography

0 Kudos
Reply

4 Views
davidecryptalabs
Contributor I

Thanks for the links!
I know it's not that simple, but I would like to use the PQC hardware acceleration from a Linux user space application, and I was wondering what's the best way to achieve that. I'm developing an application where the two parties involved use ML-DSA to authenticate themselves and ML-KEM to get the shared secret keys for an encrypted communication session. 
I was reading this: RM00284: EdgeLock Enclave Hardware Security Module API  and my question is: Can I use the API from a LInux user application that runs on the application domain? Or is that available only from the Low-Power Real Time Domain?

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2417107%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EiMx.95%20FRDM%20post%20quantum%20algorithms%20support%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2417107%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EI%20have%20an%20iMX.95%20FRDM%20development%20board%20and%20I%20would%20like%20to%20use%20post%20quantum%20algorithm%20hardware%20acceleration.%3C%2FP%3E%3CP%3EI've%20tried%20this%20command%3A%3C%2FP%3E%3CP%3Epkcs11-tool%20--module%20%2Fusr%2Flib%2Flibsmw_pkcs11.so.5%20--list-mechanism%3C%2FP%3E%3CP%3Ebut%20the%20ML-KEM%20or%20ML_DSA%20ar%20not%20listed.%3C%2FP%3E%3CP%3EI'%23m%20currently%20building%20the%20imx%20image%20with%20yocto.%3C%2FP%3E%3CP%3EHow%20can%20I%20enable%20post%20quantum%20algorithm%20support%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2417595%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20iMx.95%20FRDM%20post%20quantum%20algorithms%20support%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2417595%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3C%2FP%3E%0A%3CP%3EYou%20don't%20simply%20%22enable%20PQC%22%20with%20a%20Linux%20kernel%20option.%3C%2FP%3E%0A%3CP%3EThe%20i.MX%2095%20capability%20is%20integrated%20into%20the%20EdgeLock%20Secure%20Enclave%20%2F%20hardware%20root%20of%20trust.%3C%2FP%3E%0A%3CP%3EThe%20i.MX%2095%20Advanced%20Profile%20Secure%20Enclave%20enables%20a%20post-quantum%20hardware%20root%20of%20trust%20and%20supports%20hybrid%20ML-DSA%20%2B%20ECDSA%20for%20NXP-signed%20Secure%20Enclave%20firmware.%3C%2FP%3E%0A%3CDIV%3E%0A%3CP%3EThere%20is%20an%20i.MX%2095%20with%20SPSDK%20and%20ML-DSA%20hybrid%20secure%20boot%20implementation%2C%20which%20is%20much%20more%20useful%20than%20the%20general%20PQC%20documentation%3A%3C%2FP%3E%0A%3CP%3E%3CA%20class%3D%22fui-Link%20___b4qm3y0%20f2hkw1w%20f3rmtva%20f1ewtqcl%20fyind8e%20f1k6fduh%20f1w7gpdv%20f1mo0ibp%20fjoy568%20ff5ikls%20f1s184ao%20f1mk8lai%20fnbmjn9%20f1o700av%20f13mvf36%20f1cmlufx%20f9n3di6%20f1ids18y%20f1tx3yz7%20f1deo86v%20f1eh06m1%20f1iescvh%20fhgqx19%20f1olyrje%20f1p93eir%20f1nev41a%20f132whgj%20f1v74mp6%22%20tabindex%3D%220%22%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2FNXP-Tech-Blog%2Fi-MX-95-SPSDK-%25E3%2581%25AB%25E3%2582%2588%25E3%2582%258B%25E3%2582%25BB%25E3%2582%25AD%25E3%2583%25A5%25E3%2582%25A2%25E3%2583%2596%25E3%2583%25BC%25E3%2583%2588-%25E6%2597%25A5%25E6%259C%25AC%25E8%25AA%259E%25E3%2583%2596%25E3%2583%25AD%25E3%2582%25B0%2Fba-p%2F2377244%22%20target%3D%22_self%22%20data-tabster%3D%22%7B%22%20restorer%3D%22%22%3Ei.MX%2095%20Secure%20Boot%20with%20SPSDK%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EAnd%20the%20general%20NXP%20PQC%20architecture%20is%20here%3A%3C%2FP%3E%0A%3CP%3E%3CA%20class%3D%22fui-Link%20___b4qm3y0%20f2hkw1w%20f3rmtva%20f1ewtqcl%20fyind8e%20f1k6fduh%20f1w7gpdv%20f1mo0ibp%20fjoy568%20ff5ikls%20f1s184ao%20f1mk8lai%20fnbmjn9%20f1o700av%20f13mvf36%20f1cmlufx%20f9n3di6%20f1ids18y%20f1tx3yz7%20f1deo86v%20f1eh06m1%20f1iescvh%20fhgqx19%20f1olyrje%20f1p93eir%20f1nev41a%20f132whgj%20f1v74mp6%22%20tabindex%3D%220%22%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fapplications%2Ftechnologies%2Fsecurity%2Fpost-quantum-cryptography%3APOST-QUANTUM-CRYPTOGRAPHY%22%20rel%3D%22noopener%20noreferrer%20nofollow%22%20data-tabster%3D%22%7B%22%20restorer%3D%22%22%20target%3D%22_blank%22%3ENXP%20Post-Quantum%20Cryptography%3C%2FA%3E%3C%2FP%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E