Details ECC P256-based Secure Unique Device Identifiers, including cryptographic mechanism comparisons, related error messages, and provides verification procedures for ECC P256 configurations in the Trusted Anchor Module.
A Secure Unique Device Identifier (SUDI) is a hardware-based cryptographic identity that
-
leverages the ECC P256 curve for enhanced security,
-
enables migration from legacy RSA-based authentication to stronger ECC-based protocols, and
-
supports secure services such as TLS 1.3 for BootZ, secure Zero-Touch Provisioning (sZTP), and EMSD.
The router automatically checks for ECC p256 capability during TAM initialization and enables the API if available. If ECC p256 is not provisioned or TAM is unreachable, the system falls back to RSA-based keys from the AIKIDO module, maintaining continuity for critical features.
Feature history
The feature history table lists release support for this feature.
|
Feature Name |
Release info |
Description |
|---|---|---|
|
ECC P256-based Secure Unique Device Identifiers |
Release 26.2.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: , Q200 ], (select variants only*) ECC256 enablement enhances device security by migrating identity and attestation workflows to ECCp256-based SUDI via the Trust Anchor Module (TAM). This transition enables the adoption of TLS 1.3 for critical services such as BootZ, secure Zero-Touch Provisioning (sZTP), and EMSD. Operational continuity is ensured through a resilient fallback to legacy RSA-based keys if needed. ECC p256 is automatically enabled when certificates are present; no additional configuration steps are required. *This feature is applicable on:
|