6.10 Sign Command

The Sign command generates a signature over the 32-byte SHA-256 digest of an externally-generated message. The digest of the message is passed into the device as part of the Sign command. The ECC private key in Slot 0 is used to generate the signature. Signing of internal messages is not an option with the device.

If so desired, a monotonic counter can be configured for limited key use with the Sign command.