Under the Hardware Attestation Root Certificate Rotation section at https://developer.android.com/privacy-and-security/security-key-attestation#root_certificate_rotation, Google mentions a ML-DSA key being planned for the future:
Google is introducing a new root certificate for Android Key Attestation. This change enhances the security and reliability of the attestation process for sensitive applications. A new root key has been generated for Android Key Attestation (KeyMint). The new root is an ECDSA P-384 key, and an ML-DSA (Post-Quantum Digital Signature Algorithm) key is planned for the future.
(The new ECDSA P-384 key has already been handled at 844060f)
This will likely require AOSP support. ML-DSA is a newly standardized lattice-based digital signature algorithm, so it's not RSA or EC. As a result, our current code from would likely need to be updated in the future, e.g. this only specifies RSA and EC from keymint in the framework: https://github.com/GrapheneOS/Auditor/blob/90/app/src/main/java/app/attestation/auditor/attestation/AuthorizationList.java#L107-L114 (https://source.android.com/docs/security/features/keystore/attestation#authorizationlist-fields)
It's possible that Google will update their new Kotlin-based key attestation library for ML-DSA keys when the time comes. See #320 for moving to using their new library. Our attestation library code is based on a repo that is now deprecated.
Under the Hardware Attestation Root Certificate Rotation section at https://developer.android.com/privacy-and-security/security-key-attestation#root_certificate_rotation, Google mentions a ML-DSA key being planned for the future:
(The new ECDSA P-384 key has already been handled at 844060f)
This will likely require AOSP support. ML-DSA is a newly standardized lattice-based digital signature algorithm, so it's not RSA or EC. As a result, our current code from would likely need to be updated in the future, e.g. this only specifies RSA and EC from keymint in the framework: https://github.com/GrapheneOS/Auditor/blob/90/app/src/main/java/app/attestation/auditor/attestation/AuthorizationList.java#L107-L114 (https://source.android.com/docs/security/features/keystore/attestation#authorizationlist-fields)
It's possible that Google will update their new Kotlin-based key attestation library for ML-DSA keys when the time comes. See #320 for moving to using their new library. Our attestation library code is based on a repo that is now deprecated.