Supported keys¶
LAAVAT PKI and Signing Platform supports following keys and hash algorithms.
| Key Type | Key Size/Curve | Hash Algorithm | NIST Recommended | Notes |
|---|---|---|---|---|
| AES | 128 bits | N/A | Yes | |
| AES | 256 bits | N/A | Yes | |
| Passphrase | 32 bytes | N/A | N/A | Used for firmware update encryption |
| RSA | 1024 bits | SHA-256 | No | Legacy, not recommended |
| RSA | 1024 bits | SHA-512 | No | Legacy, not recommended |
| RSA | 2048 bits | SHA-256 | No | |
| RSA | 2048 bits | SHA-512 | No | |
| RSA | 3072 bits | SHA-256 | Yes | |
| RSA | 3072 bits | SHA-512 | Yes | |
| RSA | 4096 bits | SHA-256 | Yes | |
| RSA | 4096 bits | SHA-512 | Yes | |
| EC | secp224r1 | SHA-256 | No | |
| EC | secp224r1 | SHA-512 | No | |
| EC | secp256r1 | SHA-256 | Yes | |
| EC | secp256r1 | SHA-512 | Yes | |
| EC | secp384r1 | SHA-256 | No | |
| EC | secp384r1 | SHA-512 | Yes | |
| EC | secp521r1 | SHA-256 | No | |
| EC | secp521r1 | SHA-512 | Yes | |
| ML-DSA | ML-DSA-44 | None | Yes | Post-quantum (FIPS 204), see below |
| ML-DSA | ML-DSA-65 | None | Yes | Post-quantum (FIPS 204), see below |
| ML-DSA | ML-DSA-87 | None | Yes | Post-quantum (FIPS 204), see below |
Post-quantum: ML-DSA¶
ML-DSA (FIPS 204) is the NIST post-quantum signature standard. The platform supports the three parameter sets as the key
types MLDSA44, MLDSA65 and MLDSA87.
| Key type | Security category | Public key | Signature |
|---|---|---|---|
MLDSA44 |
2 | 1312 bytes | 2420 bytes |
MLDSA65 |
3 | 1952 bytes | 3309 bytes |
MLDSA87 |
5 | 2592 bytes | 4627 bytes |
What an ML-DSA key can do:
- Certificates: CA and end-entity keys in a PKI hierarchy, and the certificates, CSRs and CRLs they sign. A CA with an ML-DSA key can also issue certificates for RSA and EC keys. See the PKI guide.
- Message signing: a
DigestSigningoperation with an ML-DSA key signs the message itself instead of a digest. See Signing with ML-DSA keys. - NXP AHAB:
MLDSA65andMLDSA87SRK keys with SPSDK signing. See SPSDK signing.
What differs from RSA and EC keys:
- There is no separate hash algorithm. ML-DSA signs the whole message, so the hash algorithm is
NONEand the signature padding isNONE. - ML-DSA keys are HSM keys only. They cannot be software-protected, and they are not available as an exportable token.
- The signature format is the raw FIPS 204 signature. The CMS format is not available.
- Verifying needs a library that implements FIPS 204, for example OpenSSL 3.5 or later.
Hash algorithms
The platform schema defines SHA-256 and SHA-512 as supported hash algorithms. SHA-384 may be available at the implementation level for specific signing operations (CMS, JAR, Windows signing) but is not part of the core schema enum.