-
Notifications
You must be signed in to change notification settings - Fork 479
Closed
Description
Hello,
I have notices that micro-ecc is used in the Espressifs development framework (ESP-IDF, probably also nRF5 SDK).
It's used to verify application images and the bootloader (also in the secure boot process).
I'm kinda curious what the official status of the library is. To be a bit more specific;
- What standpoint do the maintainers have? (experimental status/reasonable stable...)
- How much would you advise to/against using it in products?
- What is the current status of testing and verification? (the content of test/ does basic functionality testing but I'm skeptical that this is enough for cryptographic libraries.
- Are there any research/scientific papers about it? (I found Comparative Study of ECC Libraries
for Embedded Devices and Attacking embedded ECC implementations through cmov side channels - Do you know about any bugs/vulnerabilities that are not fixed?
ThomasWaldmann and peterchen-cp
Metadata
Metadata
Assignees
Labels
No labels