4 ms·
Public key crypto (required for SSL/TLS) is difficult to fit in that RAM footprint. You don't have enough RAM to hold an RSA or DSA key, let alone a certificate
by ianhowson 7y ago
Public key crypto (required for SSL/TLS) is difficult to fit in that RAM footprint. You don't have enough RAM to hold an RSA or DSA key, let alone a certificate chain!
Usually devices of that size will use a dedicated crypto chip to store and manipulate the keys.
Elliptic curve algorithms fit better into that RAM footprint, if you can afford to sacrifice protocol compatibility.
If you can drop the SSL/TLS requirement and fall back to authenticating and encrypting your payloads over HTTP, RC5/SHA might suffice. Hash some unique serial number on your device and use that as a key. Auth is provided with a secret key burned into your device -- but this opens up big risks if your physical device or its firmware are compromised.
- namibj 7y agoSorry, but TLS has PSK cyphers that do not use asymmetric cryptography. They are not used often, as you normally want the benefits of asymmetric cryptography, but they are useful if you can pair devices out-of-band and can store a unique secret key for each communication partner.